HEX
Server: Apache
System: Linux box5936.bluehost.com 5.14.0-162.23.1.9991722448259.nf.el9.x86_64 #1 SMP PREEMPT_DYNAMIC Wed Jul 31 18:11:45 UTC 2024 x86_64
User: aviatjd3 (1318)
PHP: 8.3.32
Disabled: NONE
Upload Files
File: //usr/local/apache/error_log
[Mon Jul 20 06:02:04.744003 2026] [lsapi:notice] [pid 943696:tid 943696] mod_lsapi:  version 1.1-92
[Mon Jul 20 06:02:04.748579 2026] [:notice] [pid 796543:tid 796543] [host root@box5936.bluehost.com] mod_lsapi:  Selfstarter 796543 started
[Mon Jul 20 06:02:04.765022 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: omrobuildingcenter.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.788446 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: entraalnuevomundo.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.807349 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-ea73e5c1.vnl.uel.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.809785 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thepauze.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.810504 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundbathmiami.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.811399 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sardimacmillan.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.812072 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sarahmusica.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.812737 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: membresiabeyou.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.813432 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: representgrace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.822309 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.828929 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: beforeracism.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.833718 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-3568b81f.zbj.ahr.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.844959 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: dnsplumbing.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.845793 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lakebreezegolf.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.846577 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lakebreezegolfclub.gpu.twj.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.893638 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-555c397c.thestudioatfruitland.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.921280 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: boutrosinc.tempo-domain.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.922070 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: boutiquereinc.tempo-domain.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.925938 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: arunavabanerjee.stiqstudio.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.929315 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sitelca-com-co.sitac.com.co:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.939451 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: panova.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.945176 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nextbit-mx.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.946554 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: queridavida.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.947191 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: digi-access.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.948578 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: brisaslapunta.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.952970 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: eco-toner-com-mx.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.955111 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: elespecialista-mx.safe-systems.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.964069 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fkconstructionfunding-info.fkconstructionfunding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.966164 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-a61ebc8c.primefocusfm.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.967867 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: outlookturf.lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.968715 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-991472ff.lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.969582 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hilltopnurseryinc.lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.975240 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: qualitycoatingsinspection.northernstatemedia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.978963 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mail.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.980075 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: link.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.984406 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: silkbyblair.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.985253 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oldracelimited.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:04.985980 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: learnthissecret.oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.025018 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: kingsafety.ca.ksands.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.034069 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: misralrakamia.itdynamix.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.035012 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: dev.sixpackminer.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.036549 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: panel.sixpackminer.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.038656 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: 6packminer.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.039384 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.040006 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: 6packminer-org.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.040679 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: 6packminer-net.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.041385 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer-io.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.042228 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-1f18706a.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.043034 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer-org.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.043787 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sixpackminer-net.alfardanphygital.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.044697 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: abilite-uk.finding-funding.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.055704 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: webhubpro.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.058698 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mnvk-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.060361 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ukstudyagent.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.061159 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nvkart-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.061908 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bacg-finance.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.064516 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-fe5f3c9f.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.065338 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-f881ee98.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.066117 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-f6f4e776.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.066973 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-f3475bc5.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.067772 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-da985395.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.068739 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-b20dbffc.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.069924 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-8515b3f7.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.070604 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-701c1737.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.071454 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-0f976ec9.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.072307 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: uktouragency-com.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.073227 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bacginvest-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.075150 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: estateagentuk.com.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.075842 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: registerbusinessuk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.078131 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: exportsolution-co-uk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.079036 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: accountingco.finance.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.079799 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: technicalseohouse.com.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.080784 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: gua-yhh-mybluehost-me.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.081667 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: companyregistrationuk.doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.122735 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mtredistricting-gov.mtlegnews.gov:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.125894 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-201b05a6.drtoddreiter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.126826 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: longevityperformanceclinic.drtoddreiter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.127627 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: c-control.dexmanager.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.128330 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sauronsoftware.dexmanager.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.141785 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-a3818cc7.curlsnpearlsss.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.144461 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: wildlifeart-net.creekcombatveterans.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.145505 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: tellthetruthtravel.creekcombatveterans.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.146260 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lowemissionsasia-org.creekcombatveterans.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.147158 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hamelrealestate.collectingrealestate.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.162534 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nevelow.bespokesaintlouis.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.171725 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: faidr.auddia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.195417 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: yungmedusa.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.207365 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: willockhall.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.209730 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: karmaminds.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.236254 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: totheyoungerme.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.242008 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: threethirds.co:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.244331 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thexo.blog:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.246703 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thepostalshoppe1.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.268590 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sunsetwaters.com.au:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.269463 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sulfure.ch:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.274659 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: s-o-solutions.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.277608 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sodacitypeaceofmind.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.280618 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sitac.com.co:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.282713 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sheliastransportation.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.289197 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: scottdudekphotography.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.297642 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: saintrhum.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.300733 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sacredpathway.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.306765 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rose-treks.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.308956 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rhs.tev.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.318519 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: qoe.tdd.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.321297 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: qcms.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.327167 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: primefocusfm.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.328205 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lightspeedturf.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.330935 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: peycosoluciones.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.332904 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: passportsnpinot.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.340265 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: northernstatemedia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.344289 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oldraceltd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.346034 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ohq.ryb.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.353758 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nowetsheets.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.358624 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ninilchik.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.361158 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: nextlevellifts.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.367491 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mvg.rfs.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.369041 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mswsupply.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.394195 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lindakingart.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.399845 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: launchrolesville.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.403439 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ksd.oas.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.405219 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: krissywiedenhoff.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.406386 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: saphansiam.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.410957 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jxk.wid.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.415904 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jmfinnfilms.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.421170 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: livingwithhiddenpain.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.430945 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: holistica.com.br:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.432841 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hoggdavis.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.433694 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: heidimortenson.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.434346 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hcresthomes.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.437577 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: doctornovikov.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.454799 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: freestoreministry.org:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.455847 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fpn.adr.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.457486 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fol.ehn.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.461546 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: ffl.tdd.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.466305 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: eym.rfn.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.479213 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: heatherbowman.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.480039 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: drtoddreiter.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.487776 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: curlsnpearlsss.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.496241 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: cleansparkly.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.509726 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bridgetforcongress.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.524900 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: auddia.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.526338 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: matthewkilthaumd.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.539434 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: airportsec.com.ec:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.546765 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bog.vvo.mybluehost.me:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.570370 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oneoilaway.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.571136 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: loveteresa.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.571807 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: teresaharding.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.572448 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: dadviceonline.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.573076 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mlmgamechangers.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.573734 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: myoilsuccesssystem.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.574424 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: joinmlmgamechangers.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.575182 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: frankincenseoils-net.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.575831 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: mlmgamechangersecrets.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.576491 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: operationcoursecreation.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.577150 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: teresahardingmasterclass.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.577834 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: marketinggamechangersonline.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.578608 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: marketinggamechangersecrets.teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.580071 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: besoundful.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.580743 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: alimentamor.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.581400 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rodrigosardi.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.582147 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: fansarogroup.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.583737 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: theupgradables.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.584427 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thegpsapproach.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.585890 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: meditacionmiami.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.586682 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: bgenerationlove.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.587406 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-dad43c4c.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.588339 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-4fba7881.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.589319 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: miamimeditations.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.590898 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: iamsarahmacmillan.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.591835 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: familiaconsciente.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.592649 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: aprendeameditar-co.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.593413 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sarahmacmillan-life.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.594228 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: familiasconscientes.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.594998 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundmeditationmiami.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.595908 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: generationloveproject.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.597164 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: espiritualidadmoderna.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.597941 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundhealingsouthflorida.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.598731 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: soundmeditationsouthflorida.sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.599463 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sergnotes.raya31.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.600470 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jennylouraya.raya31.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.601299 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: locketsandcharms.raya31.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.604330 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: oohlovely.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.605358 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: jenfarley.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.606190 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: cathybuffini.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.607004 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: drawingthedog.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.607884 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: hedgerow-crafts.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.608739 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-a6fcc47f.laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.611185 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thescarystory.lakelopezonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.612082 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thewritinglair.lakelopezonline.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.626592 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: teresarharding.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.627965 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: sarahmacmillan.net:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.633900 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: lvcinc.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.635316 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: laughingliondesignhost.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.649900 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: website-7a50eaec.querenciapartners.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.650919 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: rootsofwisdom.ca.querenciapartners.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.651761 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: thailandtire.greatroadtire.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.705933 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: elementfix.elementconstruction.co.uk:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.727439 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: boracayhaven.com.ph:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.742930 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: globalglow.ca:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.751880 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: callourplace.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.793106 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: demnetworks.com:443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.795901 2026] [ssl:warn] [pid 943696:tid 943696] AH01909: localhost:8443:0 server certificate does NOT include an ID which matches the server name
[Mon Jul 20 06:02:05.808718 2026] [qos:notice] [pid 943696:tid 943696] mod_qos(007): calculated MaxClients/MaxRequestWorkers (max connections): 6144, applied limit: 2048 (QS_MaxClients)
[Mon Jul 20 06:02:06.016631 2026] [http2:info] [pid 943696:tid 943696] AH03090: mod_http2 (v2.0.42, feats=CHPRIO+SHA256+INVHD+DWINS, nghttp2 1.69.0), initializing...
[Mon Jul 20 06:02:06.021182 2026] [mpm_event:notice] [pid 943696:tid 943696] AH00489: Apache/2.4.68 (cPanel) OpenSSL/3.5.5 Apache mod_qos/11.76 mod_bwlimited/1.4 mod_fcgid/2.3.9 mod_rbld2.0 configured -- resuming normal operations
[Mon Jul 20 06:02:06.021197 2026] [core:notice] [pid 943696:tid 943696] AH00094: Command line: '/usr/sbin/httpd'
[Mon Jul 20 06:02:07.070332 2026] [http2:info] [pid 796567:tid 796567] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:02:07.090795 2026] [security2:error] [pid 796567:tid 796734] [client 51.68.111.205:17401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "pscmedicalbilling.com"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVoQAAAjk"]
[Mon Jul 20 06:02:07.090961 2026] [security2:error] [pid 796567:tid 796734] [client 51.68.111.205:17401] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "pscmedicalbilling.com"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVoQAAAjk"]
[Mon Jul 20 06:02:07.092170 2026] [security2:error] [pid 796567:tid 796730] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socalledsam.com"] [uri "/.well-known/about.php"] [unique_id "al4OP7LfyzVz2SrjZpiVnwAAAjU"]
[Mon Jul 20 06:02:07.092801 2026] [security2:error] [pid 796567:tid 796701] [client 185.132.186.67:24237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/cc.php"] [unique_id "al4OP7LfyzVz2SrjZpiVkAAAAhg"]
[Mon Jul 20 06:02:07.093316 2026] [security2:error] [pid 796567:tid 796730] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "socalledsam.com"] [uri "/.well-known/about.php"] [unique_id "al4OP7LfyzVz2SrjZpiVnwAAAjU"]
[Mon Jul 20 06:02:07.099073 2026] [security2:error] [pid 796567:tid 796733] [client 14.224.227.113:50718] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVoAAAAjg"]
[Mon Jul 20 06:02:07.099237 2026] [security2:error] [pid 796567:tid 796709] [client 14.251.3.155:50715] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVlgAAAiA"]
[Mon Jul 20 06:02:07.099217 2026] [security2:error] [pid 796567:tid 796716] [client 14.251.3.155:50707] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVmQAAAic"]
[Mon Jul 20 06:02:07.099333 2026] [security2:error] [pid 796567:tid 796704] [client 46.110.96.34:41500] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVkwAAAhs"]
[Mon Jul 20 06:02:07.099684 2026] [security2:error] [pid 796567:tid 796698] [client 14.251.3.155:50709] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVkQAAAhU"]
[Mon Jul 20 06:02:07.099839 2026] [security2:error] [pid 796567:tid 796737] [client 14.251.3.155:50724] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVogAAAjw"]
[Mon Jul 20 06:02:07.100321 2026] [security2:error] [pid 796567:tid 796748] [client 14.224.227.113:50728] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVqAAAAkc"]
[Mon Jul 20 06:02:07.100408 2026] [security2:error] [pid 796567:tid 796729] [client 14.224.227.113:50710] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVngAAAjQ"]
[Mon Jul 20 06:02:07.100413 2026] [security2:error] [pid 796567:tid 796725] [client 14.251.3.155:50719] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVnAAAAjA"]
[Mon Jul 20 06:02:07.100696 2026] [security2:error] [pid 796567:tid 796713] [client 14.251.3.155:50717] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVmAAAAiQ"]
[Mon Jul 20 06:02:07.100697 2026] [security2:error] [pid 796567:tid 796741] [client 14.224.227.113:50721] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVpAAAAkA"]
[Mon Jul 20 06:02:07.102214 2026] [security2:error] [pid 796567:tid 796745] [client 14.224.227.113:50725] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVpgAAAkQ"]
[Mon Jul 20 06:02:07.102097 2026] [security2:error] [pid 796567:tid 796721] [client 14.251.3.155:50711] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVmgAAAiw"]
[Mon Jul 20 06:02:07.102340 2026] [security2:error] [pid 796567:tid 796706] [client 14.251.3.155:50713] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVlAAAAh0"]
[Mon Jul 20 06:02:07.102919 2026] [security2:error] [pid 796567:tid 796751] [client 14.224.227.113:50712] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OP7LfyzVz2SrjZpiVpwAAAko"]
[Mon Jul 20 06:02:07.107474 2026] [core:error] [pid 796567:tid 796738] [client 14.225.17.146:61507] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:07.107495 2026] [core:error] [pid 796567:tid 796738] [client 14.225.17.146:61507] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:07.118645 2026] [security2:error] [pid 796567:tid 796575] [remote 176.31.139.25:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "tiokubito.cl"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVswACigc"]
[Mon Jul 20 06:02:07.118775 2026] [security2:error] [pid 796567:tid 796815] [client 176.31.139.25:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tiokubito.cl"] [uri "/robots.txt"] [unique_id "al4OP7LfyzVz2SrjZpiVswACigc"]
[Mon Jul 20 06:02:07.141663 2026] [security2:error] [pid 796567:tid 796581] [remote 57.141.18.104:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4OP7LfyzVz2SrjZpiVvAACRA0"]
[Mon Jul 20 06:02:07.151146 2026] [security2:error] [pid 796567:tid 796608] [remote 57.141.18.27:20034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4OP7LfyzVz2SrjZpiV2QACLCg"]
[Mon Jul 20 06:02:07.182327 2026] [security2:error] [pid 796567:tid 796631] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWBgACjD8"]
[Mon Jul 20 06:02:07.182569 2026] [security2:error] [pid 796567:tid 796817] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWBgACjD8"]
[Mon Jul 20 06:02:07.259771 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:61290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIQAAAh4"]
[Mon Jul 20 06:02:07.259941 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:61290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIQAAAh4"]
[Mon Jul 20 06:02:07.261290 2026] [security2:error] [pid 796567:tid 796640] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIAACM0g"]
[Mon Jul 20 06:02:07.261576 2026] [security2:error] [pid 796567:tid 796728] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWIAACM0g"]
[Mon Jul 20 06:02:07.293331 2026] [security2:error] [pid 796567:tid 796729] [client 179.0.122.163:22306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.122.0.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWMgAAAjQ"]
[Mon Jul 20 06:02:07.293513 2026] [security2:error] [pid 796567:tid 796729] [client 179.0.122.163:22306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWMgAAAjQ"]
[Mon Jul 20 06:02:07.302299 2026] [security2:error] [pid 796567:tid 796720] [client 114.119.136.5:39273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/category/magical-realism"] [unique_id "al4OP7LfyzVz2SrjZpiWMQAAAis"], referer: https://omenana.com/category/magical-realism/page/2?filter_by=review_high
[Mon Jul 20 06:02:07.354746 2026] [security2:error] [pid 796567:tid 796803] [client 65.1.132.125:47428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWQgAAAn4"]
[Mon Jul 20 06:02:07.354903 2026] [security2:error] [pid 796567:tid 796803] [client 65.1.132.125:47428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWQgAAAn4"]
[Mon Jul 20 06:02:07.366289 2026] [security2:error] [pid 796567:tid 796814] [client 193.19.109.245:58671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWRwAAAok"]
[Mon Jul 20 06:02:07.388176 2026] [security2:error] [pid 796567:tid 796812] [client 193.19.109.238:29531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWRgAAAoc"]
[Mon Jul 20 06:02:07.404355 2026] [security2:error] [pid 796567:tid 796749] [client 41.173.37.102:5975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWUQAAAkg"]
[Mon Jul 20 06:02:07.404537 2026] [security2:error] [pid 796567:tid 796749] [client 41.173.37.102:5975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWUQAAAkg"]
[Mon Jul 20 06:02:07.413543 2026] [security2:error] [pid 796567:tid 796718] [client 164.100.212.184:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWVQAAAik"]
[Mon Jul 20 06:02:07.413664 2026] [security2:error] [pid 796567:tid 796718] [client 164.100.212.184:50819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWVQAAAik"]
[Mon Jul 20 06:02:07.439976 2026] [security2:error] [pid 796567:tid 796800] [client 178.152.178.232:36324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWYQAAAns"]
[Mon Jul 20 06:02:07.440111 2026] [security2:error] [pid 796567:tid 796800] [client 178.152.178.232:36324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWYQAAAns"]
[Mon Jul 20 06:02:07.451413 2026] [security2:error] [pid 796567:tid 796713] [client 181.224.94.124:12181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWZQAAAiQ"]
[Mon Jul 20 06:02:07.451561 2026] [security2:error] [pid 796567:tid 796713] [client 181.224.94.124:12181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWZQAAAiQ"]
[Mon Jul 20 06:02:07.467446 2026] [security2:error] [pid 796567:tid 796650] [remote 188.166.241.141:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWaQAChVI"]
[Mon Jul 20 06:02:07.568834 2026] [security2:error] [pid 796567:tid 796808] [client 114.119.158.83:30723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.safe-systems.net"] [uri "/nextbit.mx/portafolio/aviato/product-single.html"] [unique_id "al4OP7LfyzVz2SrjZpiWdQAAAoM"], referer: http://www.safe-systems.net/nextbit.mx/portafolio/aviato/checkout.html
[Mon Jul 20 06:02:07.573725 2026] [security2:error] [pid 796567:tid 796819] [client 103.149.16.77:58315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWdgAAAo4"]
[Mon Jul 20 06:02:07.573891 2026] [security2:error] [pid 796567:tid 796819] [client 103.149.16.77:58315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWdgAAAo4"]
[Mon Jul 20 06:02:07.650119 2026] [security2:error] [pid 796567:tid 796822] [client 210.212.97.243:10424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWegAAApE"]
[Mon Jul 20 06:02:07.650289 2026] [security2:error] [pid 796567:tid 796822] [client 210.212.97.243:10424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWegAAApE"]
[Mon Jul 20 06:02:07.654316 2026] [autoindex:error] [pid 796567:tid 796816] [client 194.233.91.21:52295] AH01276: Cannot serve directory /home4/jvcmotor/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:02:07.733402 2026] [security2:error] [pid 796567:tid 796661] [remote 8.217.108.67:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circafabrication.com"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWhgACWl0"]
[Mon Jul 20 06:02:07.765186 2026] [security2:error] [pid 796567:tid 796767] [client 50.116.65.227:12512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OP7LfyzVz2SrjZpiWjQAAAlo"]
[Mon Jul 20 06:02:07.769446 2026] [security2:error] [pid 796567:tid 796820] [client 34.44.142.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWfwAAAo8"]
[Mon Jul 20 06:02:07.783386 2026] [security2:error] [pid 796567:tid 796704] [client 129.222.187.209:4505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWkQAAAhs"]
[Mon Jul 20 06:02:07.784415 2026] [security2:error] [pid 796567:tid 796782] [client 50.116.65.227:12538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OP7LfyzVz2SrjZpiWkAAAAmk"]
[Mon Jul 20 06:02:07.791142 2026] [security2:error] [pid 796567:tid 796704] [client 129.222.187.209:4505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OP7LfyzVz2SrjZpiWkQAAAhs"]
[Mon Jul 20 06:02:07.827408 2026] [security2:error] [pid 796567:tid 796664] [remote 148.113.128.53:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "tiokubito.cl"] [uri "/wp-content/uploads/2024/06/1000173187.jpg"] [unique_id "al4OP7LfyzVz2SrjZpiWlQACKWA"]
[Mon Jul 20 06:02:07.827685 2026] [security2:error] [pid 796567:tid 796718] [client 148.113.128.53:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tiokubito.cl"] [uri "/wp-content/uploads/2024/06/1000173187.jpg"] [unique_id "al4OP7LfyzVz2SrjZpiWlQACKWA"]
[Mon Jul 20 06:02:07.853914 2026] [security2:error] [pid 796567:tid 796665] [remote 188.166.241.141:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OP7LfyzVz2SrjZpiWlwACIWE"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:02:07.865112 2026] [security2:error] [pid 796567:tid 796787] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWawAAAm4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:08.111558 2026] [http2:info] [pid 796928:tid 796928] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:02:08.299973 2026] [security2:error] [pid 796567:tid 796801] [client 173.239.240.10:27823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bnb-engineering.com"] [uri "/wp-login.php"] [unique_id "al4OQLLfyzVz2SrjZpiWrgAAAnw"]
[Mon Jul 20 06:02:08.588929 2026] [security2:error] [pid 796567:tid 796710] [client 72.255.10.154:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiWyAAAAiE"]
[Mon Jul 20 06:02:08.589050 2026] [security2:error] [pid 796567:tid 796710] [client 72.255.10.154:1045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiWyAAAAiE"]
[Mon Jul 20 06:02:08.666121 2026] [security2:error] [pid 796928:tid 797081] [client 35.90.38.209:28620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4OQOsTy9vX-htKvPn4uQAAArA"]
[Mon Jul 20 06:02:08.769313 2026] [security2:error] [pid 796928:tid 797060] [client 112.213.160.112:8215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OQOsTy9vX-htKvPn4vQAAAps"]
[Mon Jul 20 06:02:08.769447 2026] [security2:error] [pid 796928:tid 797060] [client 112.213.160.112:8215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OQOsTy9vX-htKvPn4vQAAAps"]
[Mon Jul 20 06:02:08.790680 2026] [security2:error] [pid 796567:tid 796688] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiW0gACJXg"]
[Mon Jul 20 06:02:08.790912 2026] [security2:error] [pid 796567:tid 796714] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OQLLfyzVz2SrjZpiW0gACJXg"]
[Mon Jul 20 06:02:08.876803 2026] [security2:error] [pid 796567:tid 796691] [remote 57.141.18.57:22890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2950356"] [unique_id "al4OQLLfyzVz2SrjZpiW2AACUHs"]
[Mon Jul 20 06:02:09.046529 2026] [security2:error] [pid 796928:tid 797107] [client 185.132.186.102:54545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/index.php"] [unique_id "al4OQesTy9vX-htKvPn4xgAAAso"]
[Mon Jul 20 06:02:09.072484 2026] [security2:error] [pid 796567:tid 796725] [client 14.225.17.146:61251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWngAAAjA"], referer: http://walkingandtalking.net/wordpress
[Mon Jul 20 06:02:09.370813 2026] [security2:error] [pid 796567:tid 796798] [client 98.159.234.160:30539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OQbLfyzVz2SrjZpiW8gAAAnk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:09.765854 2026] [security2:error] [pid 796567:tid 796823] [client 150.228.148.150:12650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OQbLfyzVz2SrjZpiXBgAAApI"]
[Mon Jul 20 06:02:09.766031 2026] [security2:error] [pid 796567:tid 796823] [client 150.228.148.150:12650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OQbLfyzVz2SrjZpiXBgAAApI"]
[Mon Jul 20 06:02:09.771763 2026] [security2:error] [pid 796567:tid 796794] [client 14.225.17.146:54629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4OQLLfyzVz2SrjZpiWtQAAAnU"], referer: http://iagdevelopments.com/wordpress
[Mon Jul 20 06:02:09.954479 2026] [security2:error] [pid 796928:tid 797138] [client 14.225.17.146:62339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4OQesTy9vX-htKvPn44AAAAuk"], referer: https://walkingandtalking.net/wordpress
[Mon Jul 20 06:02:10.009674 2026] [security2:error] [pid 796567:tid 796816] [client 173.239.254.41:21321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXEwAAAos"]
[Mon Jul 20 06:02:10.052928 2026] [security2:error] [pid 796928:tid 797134] [client 103.95.123.246:18820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn45wAAAuU"]
[Mon Jul 20 06:02:10.053065 2026] [security2:error] [pid 796928:tid 797134] [client 103.95.123.246:18820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn45wAAAuU"]
[Mon Jul 20 06:02:10.085130 2026] [security2:error] [pid 796567:tid 796641] [remote 217.61.143.92:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXGgACdEk"]
[Mon Jul 20 06:02:10.191142 2026] [security2:error] [pid 796567:tid 796734] [client 14.225.17.146:61254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWpAAAAjk"], referer: http://windowtx.com/wordpress
[Mon Jul 20 06:02:10.290829 2026] [security2:error] [pid 796567:tid 796810] [client 52.183.195.200:21699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4OQrLfyzVz2SrjZpiXJQAAAoU"]
[Mon Jul 20 06:02:10.314354 2026] [security2:error] [pid 796567:tid 796645] [remote 217.61.143.92:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXKQACH00"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:02:10.322253 2026] [security2:error] [pid 796567:tid 796819] [client 52.183.195.200:21699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OQrLfyzVz2SrjZpiXKwAAAo4"]
[Mon Jul 20 06:02:10.610473 2026] [security2:error] [pid 796567:tid 796649] [remote 45.90.123.233:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXOwACJ1E"]
[Mon Jul 20 06:02:10.734654 2026] [security2:error] [pid 796567:tid 796819] [client 77.110.127.138:54511] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4OQrLfyzVz2SrjZpiXRAAAAo4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:10.820962 2026] [security2:error] [pid 796567:tid 796710] [client 193.19.109.243:22235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXSwAAAiE"]
[Mon Jul 20 06:02:10.822386 2026] [security2:error] [pid 796567:tid 796713] [client 193.19.109.222:50699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXSgAAAiQ"]
[Mon Jul 20 06:02:10.886793 2026] [security2:error] [pid 796567:tid 796706] [client 14.225.17.146:50347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4OQrLfyzVz2SrjZpiXTAAAAh0"], referer: https://iagdevelopments.com/wordpress
[Mon Jul 20 06:02:10.901215 2026] [security2:error] [pid 796567:tid 796611] [remote 45.90.123.233:54832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4OQrLfyzVz2SrjZpiXTwACdSs"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:02:10.915080 2026] [security2:error] [pid 796928:tid 797169] [client 106.192.104.4:52500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn4-gAAAwg"]
[Mon Jul 20 06:02:10.915211 2026] [security2:error] [pid 796928:tid 797169] [client 106.192.104.4:52500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OQusTy9vX-htKvPn4-gAAAwg"]
[Mon Jul 20 06:02:10.998628 2026] [security2:error] [pid 796567:tid 796822] [client 185.132.186.98:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ab.php"] [unique_id "al4OQrLfyzVz2SrjZpiXWAAAApE"]
[Mon Jul 20 06:02:11.288590 2026] [security2:error] [pid 796928:tid 797086] [client 172.200.24.58:3011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4OQ-sTy9vX-htKvPn5BAAAArU"]
[Mon Jul 20 06:02:11.350207 2026] [security2:error] [pid 796928:tid 797102] [client 172.200.24.58:3011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OQ-sTy9vX-htKvPn5CQAAAsU"]
[Mon Jul 20 06:02:11.400533 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.64:47706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiV0AACYyI"]
[Mon Jul 20 06:02:11.465094 2026] [security2:error] [pid 796567:tid 796762] [client 57.141.18.32:20832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiV0gACVRk"]
[Mon Jul 20 06:02:11.638010 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.72:39798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OP7LfyzVz2SrjZpiWPgACNU8"]
[Mon Jul 20 06:02:11.830948 2026] [security2:error] [pid 796567:tid 796634] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ7LfyzVz2SrjZpiXggACjkI"]
[Mon Jul 20 06:02:11.831146 2026] [security2:error] [pid 796567:tid 796819] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ7LfyzVz2SrjZpiXggACjkI"]
[Mon Jul 20 06:02:11.937023 2026] [security2:error] [pid 796928:tid 797139] [client 18.228.171.129:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ-sTy9vX-htKvPn5GAAAAuo"]
[Mon Jul 20 06:02:11.937208 2026] [security2:error] [pid 796928:tid 797139] [client 18.228.171.129:33790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OQ-sTy9vX-htKvPn5GAAAAuo"]
[Mon Jul 20 06:02:12.224572 2026] [security2:error] [pid 796567:tid 796797] [client 115.246.21.170:20945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXjwAAAng"]
[Mon Jul 20 06:02:12.224737 2026] [security2:error] [pid 796567:tid 796797] [client 115.246.21.170:20945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXjwAAAng"]
[Mon Jul 20 06:02:12.318594 2026] [security2:error] [pid 796928:tid 797153] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OROsTy9vX-htKvPn5GwAAAvg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:12.713255 2026] [security2:error] [pid 796567:tid 796791] [client 47.31.86.100:53911] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXngAAAnI"]
[Mon Jul 20 06:02:12.713376 2026] [security2:error] [pid 796567:tid 796791] [client 47.31.86.100:53911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORLLfyzVz2SrjZpiXngAAAnI"]
[Mon Jul 20 06:02:12.775746 2026] [security2:error] [pid 796567:tid 796797] [client 173.239.240.20:45031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bnb-engineering.com"] [uri "/wp-login.php"] [unique_id "al4ORLLfyzVz2SrjZpiXowAAAng"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:02:12.939898 2026] [security2:error] [pid 796567:tid 796706] [client 185.132.186.75:25211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/about.php"] [unique_id "al4ORLLfyzVz2SrjZpiXswAAAh0"]
[Mon Jul 20 06:02:13.361099 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:31345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OResTy9vX-htKvPn5NgAAAp4"]
[Mon Jul 20 06:02:13.382523 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:31345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OResTy9vX-htKvPn5NgAAAp4"]
[Mon Jul 20 06:02:13.932111 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:56981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4OROsTy9vX-htKvPn5HwAAAvU"], referer: http://xp-design.co/wordpress
[Mon Jul 20 06:02:14.079868 2026] [security2:error] [pid 796567:tid 796814] [client 77.110.127.138:54511] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4ORrLfyzVz2SrjZpiX5QAAAok"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:14.214691 2026] [security2:error] [pid 796928:tid 797148] [client 178.152.178.232:36415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5VgAAAvM"]
[Mon Jul 20 06:02:14.214893 2026] [security2:error] [pid 796928:tid 797148] [client 178.152.178.232:36415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5VgAAAvM"]
[Mon Jul 20 06:02:14.463083 2026] [security2:error] [pid 796928:tid 797141] [client 41.173.37.102:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5XAAAAuw"]
[Mon Jul 20 06:02:14.463251 2026] [security2:error] [pid 796928:tid 797141] [client 41.173.37.102:6584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5XAAAAuw"]
[Mon Jul 20 06:02:14.603345 2026] [security2:error] [pid 796567:tid 796744] [client 57.141.18.72:39810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OQrLfyzVz2SrjZpiXKgACQ04"]
[Mon Jul 20 06:02:14.822401 2026] [security2:error] [pid 796928:tid 797065] [client 3.109.4.218:36408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5awAAAqA"]
[Mon Jul 20 06:02:14.822559 2026] [security2:error] [pid 796928:tid 797065] [client 3.109.4.218:36408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ORusTy9vX-htKvPn5awAAAqA"]
[Mon Jul 20 06:02:14.849795 2026] [security2:error] [pid 796928:tid 796948] [remote 209.42.18.223:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4ORusTy9vX-htKvPn5bAACvBM"]
[Mon Jul 20 06:02:14.889907 2026] [security2:error] [pid 796928:tid 797115] [client 185.132.186.91:34147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "al4ORusTy9vX-htKvPn5bwAAAtI"]
[Mon Jul 20 06:02:15.050207 2026] [security2:error] [pid 796928:tid 796949] [remote 209.42.18.223:54344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OR-sTy9vX-htKvPn5dgAC6BQ"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:02:15.283685 2026] [security2:error] [pid 796567:tid 796759] [client 14.225.17.146:49759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OR7LfyzVz2SrjZpiYDgAAAlI"], referer: http://fkconstructionfunding.com/wordpress
[Mon Jul 20 06:02:15.346683 2026] [security2:error] [pid 796928:tid 797136] [client 14.224.227.113:50714] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5fgAAAuc"]
[Mon Jul 20 06:02:15.372907 2026] [security2:error] [pid 796567:tid 796639] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYGAACIUc"]
[Mon Jul 20 06:02:15.373121 2026] [security2:error] [pid 796567:tid 796710] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYGAACIUc"]
[Mon Jul 20 06:02:15.394743 2026] [security2:error] [pid 796567:tid 796794] [client 14.224.227.113:50708] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYGwAAAnU"]
[Mon Jul 20 06:02:15.395834 2026] [security2:error] [pid 796928:tid 797174] [client 14.224.227.113:50716] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5gQAAAw0"]
[Mon Jul 20 06:02:15.401004 2026] [security2:error] [pid 796928:tid 797144] [client 14.224.227.113:50723] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5ggAAAu8"]
[Mon Jul 20 06:02:15.563389 2026] [security2:error] [pid 796928:tid 797148] [client 14.251.3.155:50753] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5iQAAAvM"]
[Mon Jul 20 06:02:15.576898 2026] [security2:error] [pid 796928:tid 797058] [client 14.251.3.155:50755] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5igAAApk"]
[Mon Jul 20 06:02:15.586844 2026] [security2:error] [pid 796567:tid 796762] [client 14.251.3.155:50751] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYJwAAAlU"]
[Mon Jul 20 06:02:15.599974 2026] [security2:error] [pid 796567:tid 796823] [client 14.251.3.155:50757] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYKgAAApI"]
[Mon Jul 20 06:02:15.621780 2026] [security2:error] [pid 796928:tid 797163] [client 14.224.227.113:50752] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5jgAAAwI"]
[Mon Jul 20 06:02:15.628357 2026] [security2:error] [pid 796928:tid 797073] [client 14.224.227.113:50754] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR-sTy9vX-htKvPn5jwAAAqg"]
[Mon Jul 20 06:02:15.772644 2026] [security2:error] [pid 796567:tid 796795] [client 14.225.17.146:58571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4ORrLfyzVz2SrjZpiX-QAAAnY"], referer: http://entuvy.com/wordpress
[Mon Jul 20 06:02:15.850157 2026] [security2:error] [pid 796567:tid 796800] [client 14.251.3.155:50761] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OR7LfyzVz2SrjZpiYMQAAAns"]
[Mon Jul 20 06:02:15.896722 2026] [security2:error] [pid 796567:tid 796798] [client 103.149.16.77:58802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYNAAAAnk"]
[Mon Jul 20 06:02:15.896856 2026] [security2:error] [pid 796567:tid 796798] [client 103.149.16.77:58802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OR7LfyzVz2SrjZpiYNAAAAnk"]
[Mon Jul 20 06:02:16.075048 2026] [security2:error] [pid 796567:tid 796706] [client 210.212.97.243:10425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYQwAAAh0"]
[Mon Jul 20 06:02:16.075241 2026] [security2:error] [pid 796567:tid 796706] [client 210.212.97.243:10425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYQwAAAh0"]
[Mon Jul 20 06:02:16.153758 2026] [security2:error] [pid 796567:tid 796811] [client 14.251.3.155:50726] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OSLLfyzVz2SrjZpiYRwAAAoY"]
[Mon Jul 20 06:02:16.155168 2026] [security2:error] [pid 796567:tid 796748] [client 14.251.3.155:50722] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OSLLfyzVz2SrjZpiYSAAAAkc"]
[Mon Jul 20 06:02:16.459850 2026] [security2:error] [pid 796567:tid 796747] [client 14.225.17.146:58803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4OSLLfyzVz2SrjZpiYSgAAAkY"], referer: http://alrowad-hub.net/wordpress
[Mon Jul 20 06:02:16.464142 2026] [security2:error] [pid 796567:tid 796784] [client 14.225.17.146:58804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OSLLfyzVz2SrjZpiYSwAAAms"], referer: https://fkconstructionfunding.com/wordpress
[Mon Jul 20 06:02:16.485260 2026] [security2:error] [pid 796567:tid 796807] [client 14.225.17.146:60501] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4OR7LfyzVz2SrjZpiYLgAAAoI"], referer: http://uritems.net/wordpress
[Mon Jul 20 06:02:16.530541 2026] [security2:error] [pid 796928:tid 797060] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSOsTy9vX-htKvPn5oAAAAps"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:16.549704 2026] [security2:error] [pid 796928:tid 797165] [client 50.116.65.227:55244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OSOsTy9vX-htKvPn5sAAAAwQ"]
[Mon Jul 20 06:02:16.564494 2026] [security2:error] [pid 796928:tid 797144] [client 50.116.65.227:55252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OSOsTy9vX-htKvPn5sgAAAu8"]
[Mon Jul 20 06:02:16.749533 2026] [security2:error] [pid 796567:tid 796737] [client 57.141.18.6:48804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ORLLfyzVz2SrjZpiXlAACPGw"]
[Mon Jul 20 06:02:16.830569 2026] [security2:error] [pid 796928:tid 797088] [client 185.132.186.104:61567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/doc.php"] [unique_id "al4OSOsTy9vX-htKvPn5uAAAArc"]
[Mon Jul 20 06:02:16.841996 2026] [security2:error] [pid 796567:tid 796703] [client 164.100.212.184:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYbQAAAho"]
[Mon Jul 20 06:02:16.842162 2026] [security2:error] [pid 796567:tid 796703] [client 164.100.212.184:51380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OSLLfyzVz2SrjZpiYbQAAAho"]
[Mon Jul 20 06:02:17.215465 2026] [security2:error] [pid 796928:tid 797111] [client 14.225.17.146:60447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4OR-sTy9vX-htKvPn5hwAAAs4"], referer: http://detroitcsc.com/wordpress
[Mon Jul 20 06:02:17.284785 2026] [security2:error] [pid 796928:tid 797146] [client 45.146.54.115:45185] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "travelbyfire.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4OSesTy9vX-htKvPn5ygAAAvE"]
[Mon Jul 20 06:02:17.345904 2026] [security2:error] [pid 796928:tid 797107] [client 181.224.94.124:6659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSesTy9vX-htKvPn50AAAAso"]
[Mon Jul 20 06:02:17.346046 2026] [security2:error] [pid 796928:tid 797107] [client 181.224.94.124:6659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSesTy9vX-htKvPn50AAAAso"]
[Mon Jul 20 06:02:17.495040 2026] [security2:error] [pid 796567:tid 796814] [client 129.222.187.209:21099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSbLfyzVz2SrjZpiYjAAAAok"]
[Mon Jul 20 06:02:17.495193 2026] [security2:error] [pid 796567:tid 796814] [client 129.222.187.209:21099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OSbLfyzVz2SrjZpiYjAAAAok"]
[Mon Jul 20 06:02:17.531180 2026] [security2:error] [pid 796928:tid 797146] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSesTy9vX-htKvPn5ywAAAvE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:17.800945 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:54510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4OSbLfyzVz2SrjZpiYnQAAAmY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:17.978599 2026] [security2:error] [pid 796567:tid 796725] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSbLfyzVz2SrjZpiYmAAAAjA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:18.010704 2026] [security2:error] [pid 796928:tid 797116] [client 82.102.18.116:60000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "al4OSusTy9vX-htKvPn55wAAAtM"]
[Mon Jul 20 06:02:18.587417 2026] [security2:error] [pid 796928:tid 797102] [client 14.225.17.146:57095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4OSOsTy9vX-htKvPn5qAAAAsU"], referer: http://outlookturf.com/wordpress
[Mon Jul 20 06:02:18.771818 2026] [security2:error] [pid 796567:tid 796766] [client 185.132.186.59:34527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al4OSrLfyzVz2SrjZpiYyQAAAlk"]
[Mon Jul 20 06:02:18.781563 2026] [security2:error] [pid 796928:tid 797088] [client 103.118.29.185:47844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4OSusTy9vX-htKvPn6AQACtyE"], referer: https://blaizeaccountingservices.com/wp-login.php
[Mon Jul 20 06:02:18.904549 2026] [security2:error] [pid 796567:tid 796759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OSrLfyzVz2SrjZpiYxAAAAlI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:19.226987 2026] [security2:error] [pid 796567:tid 796822] [client 72.255.10.154:2339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY5AAAApE"]
[Mon Jul 20 06:02:19.227173 2026] [security2:error] [pid 796567:tid 796822] [client 72.255.10.154:2339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY5AAAApE"]
[Mon Jul 20 06:02:19.256345 2026] [security2:error] [pid 796928:tid 797097] [client 45.157.112.60:39489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OS-sTy9vX-htKvPn6GQAAAsA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:19.258383 2026] [security2:error] [pid 796567:tid 796747] [client 47.128.120.29:26644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tejasenvironmental.com"] [uri "/robots.txt"] [unique_id "al4OS7LfyzVz2SrjZpiY5wAAAkY"]
[Mon Jul 20 06:02:19.304781 2026] [security2:error] [pid 796928:tid 797167] [client 14.224.227.113:50767] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OS-sTy9vX-htKvPn6HAAAAwY"]
[Mon Jul 20 06:02:19.352152 2026] [security2:error] [pid 796928:tid 797108] [client 82.102.18.116:58758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4OS-sTy9vX-htKvPn6HwAAAss"]
[Mon Jul 20 06:02:19.369915 2026] [security2:error] [pid 796928:tid 797173] [client 158.173.89.95:26937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OS-sTy9vX-htKvPn6IAAAAww"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:19.395323 2026] [security2:error] [pid 796928:tid 797096] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6EQAAAr8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:19.402937 2026] [security2:error] [pid 796567:tid 796590] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY6wACaxY"]
[Mon Jul 20 06:02:19.403103 2026] [security2:error] [pid 796567:tid 796784] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY6wACaxY"]
[Mon Jul 20 06:02:19.467767 2026] [security2:error] [pid 796928:tid 796968] [remote 173.249.4.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4OS-sTy9vX-htKvPn6JAACnic"]
[Mon Jul 20 06:02:19.483238 2026] [security2:error] [pid 796928:tid 797084] [client 74.7.227.179:39166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6GwACsyU"], referer: https://tejasenvironmental.com/p=474663
[Mon Jul 20 06:02:19.523241 2026] [security2:error] [pid 796567:tid 796804] [client 112.213.160.112:30732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY8wAAAn8"]
[Mon Jul 20 06:02:19.523384 2026] [security2:error] [pid 796567:tid 796804] [client 112.213.160.112:30732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OS7LfyzVz2SrjZpiY8wAAAn8"]
[Mon Jul 20 06:02:19.780949 2026] [security2:error] [pid 796928:tid 797081] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6KwAAArA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:19.880255 2026] [security2:error] [pid 796928:tid 796972] [remote 173.249.4.11:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4OS-sTy9vX-htKvPn6PAACvSs"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 06:02:20.019029 2026] [security2:error] [pid 796567:tid 796808] [client 82.102.18.116:58772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4OTLLfyzVz2SrjZpiZDAAAAoM"]
[Mon Jul 20 06:02:20.313114 2026] [security2:error] [pid 796928:tid 797097] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OS-sTy9vX-htKvPn6PgAAAsA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:20.414843 2026] [security2:error] [pid 796567:tid 796701] [client 150.228.148.150:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OTLLfyzVz2SrjZpiZJwAAAhg"]
[Mon Jul 20 06:02:20.429152 2026] [security2:error] [pid 796567:tid 796701] [client 150.228.148.150:19279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OTLLfyzVz2SrjZpiZJwAAAhg"]
[Mon Jul 20 06:02:20.464367 2026] [security2:error] [pid 796928:tid 796973] [remote 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ardhalwafa.com"] [uri "/.well-known/about.php"] [unique_id "al4OTOsTy9vX-htKvPn6WgADCSw"]
[Mon Jul 20 06:02:20.464782 2026] [security2:error] [pid 796928:tid 797170] [client 20.220.225.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ardhalwafa.com"] [uri "/.well-known/about.php"] [unique_id "al4OTOsTy9vX-htKvPn6WgADCSw"]
[Mon Jul 20 06:02:20.579077 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.43:30868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OR7LfyzVz2SrjZpiYJAACNTM"]
[Mon Jul 20 06:02:20.660966 2026] [security2:error] [pid 796928:tid 797126] [client 82.102.18.116:58776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "al4OTOsTy9vX-htKvPn6YQAAAt0"]
[Mon Jul 20 06:02:20.708742 2026] [security2:error] [pid 796928:tid 797093] [client 185.132.186.93:28971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "al4OTOsTy9vX-htKvPn6ZQAAArw"]
[Mon Jul 20 06:02:20.759039 2026] [security2:error] [pid 796928:tid 797111] [client 173.239.240.6:25001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bnb-engineering.com"] [uri "/wp-login.php"] [unique_id "al4OTOsTy9vX-htKvPn6ZgAAAs4"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:02:20.785878 2026] [security2:error] [pid 796567:tid 796813] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OTLLfyzVz2SrjZpiZMQAAAog"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:20.879520 2026] [security2:error] [pid 796567:tid 796656] [remote 124.55.178.99:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4OTLLfyzVz2SrjZpiZPQACMFg"]
[Mon Jul 20 06:02:20.896047 2026] [security2:error] [pid 796928:tid 797124] [client 103.95.123.246:19325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OTOsTy9vX-htKvPn6aAAAAts"]
[Mon Jul 20 06:02:20.896737 2026] [security2:error] [pid 796928:tid 797124] [client 103.95.123.246:19325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OTOsTy9vX-htKvPn6aAAAAts"]
[Mon Jul 20 06:02:20.982885 2026] [security2:error] [pid 796928:tid 797156] [client 14.225.17.146:58891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4OSesTy9vX-htKvPn5yAAAAvs"], referer: http://gearwaterproof.com/wordpress
[Mon Jul 20 06:02:21.329894 2026] [security2:error] [pid 796567:tid 796667] [remote 124.55.178.99:35566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4OTbLfyzVz2SrjZpiZUwACI2M"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:02:21.337648 2026] [security2:error] [pid 796567:tid 796732] [client 82.102.18.116:58790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4OTbLfyzVz2SrjZpiZVAAAAjc"]
[Mon Jul 20 06:02:21.378393 2026] [security2:error] [pid 796928:tid 797103] [client 106.192.104.4:52993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6fQAAAsY"]
[Mon Jul 20 06:02:21.387565 2026] [security2:error] [pid 796928:tid 797103] [client 106.192.104.4:52993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6fQAAAsY"]
[Mon Jul 20 06:02:21.443287 2026] [security2:error] [pid 796928:tid 796979] [remote 199.189.225.40:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OTesTy9vX-htKvPn6fwACwDI"]
[Mon Jul 20 06:02:21.494781 2026] [proxy:error] [pid 796928:tid 797069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:21.494843 2026] [proxy_http:error] [pid 796928:tid 797069] [client 198.235.24.28:60148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:21.496047 2026] [proxy:error] [pid 796928:tid 797069] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:21.496103 2026] [proxy_http:error] [pid 796928:tid 797069] [client 198.235.24.28:60148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:21.837426 2026] [security2:error] [pid 796928:tid 797061] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reydelcalentador.com"] [uri "/wp-admin/install.php"] [unique_id "al4OTesTy9vX-htKvPn6lwAAApw"]
[Mon Jul 20 06:02:21.926232 2026] [security2:error] [pid 796928:tid 796982] [remote 199.189.225.40:33805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OTesTy9vX-htKvPn6nQADAjU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:02:21.991228 2026] [security2:error] [pid 796928:tid 796983] [remote 173.212.252.15:42070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6oAACwjY"]
[Mon Jul 20 06:02:21.991599 2026] [security2:error] [pid 796928:tid 797099] [client 173.212.252.15:42070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OTesTy9vX-htKvPn6oAACwjY"]
[Mon Jul 20 06:02:21.997405 2026] [security2:error] [pid 796928:tid 797140] [client 82.102.18.116:58794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "al4OTesTy9vX-htKvPn6oQAAAus"]
[Mon Jul 20 06:02:22.348721 2026] [security2:error] [pid 796928:tid 797113] [client 14.225.17.146:52955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4OTOsTy9vX-htKvPn6UwAAAtA"], referer: http://margaretspeckogawa.com/wordpress
[Mon Jul 20 06:02:22.353265 2026] [security2:error] [pid 796928:tid 797130] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylg.kng.mybluehost.me"] [uri "/wp-admin/install.php"] [unique_id "al4OTusTy9vX-htKvPn6sAAC4To"]
[Mon Jul 20 06:02:22.459583 2026] [security2:error] [pid 796928:tid 797146] [client 14.225.17.146:52935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4OTOsTy9vX-htKvPn6SQAAAvE"], referer: http://narv.co/wordpress
[Mon Jul 20 06:02:22.657362 2026] [security2:error] [pid 796928:tid 797071] [client 18.228.171.129:11954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6vgAAAqY"]
[Mon Jul 20 06:02:22.657471 2026] [security2:error] [pid 796928:tid 797071] [client 18.228.171.129:11954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6vgAAAqY"]
[Mon Jul 20 06:02:22.659187 2026] [security2:error] [pid 796567:tid 796730] [client 185.132.186.87:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/mar.php"] [unique_id "al4OTrLfyzVz2SrjZpiZlAAAAjU"]
[Mon Jul 20 06:02:22.686461 2026] [security2:error] [pid 796567:tid 796811] [client 82.102.18.116:58806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4OTrLfyzVz2SrjZpiZlQAAAoY"]
[Mon Jul 20 06:02:22.922576 2026] [security2:error] [pid 796928:tid 797179] [client 115.246.21.170:20601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ygAAAxI"]
[Mon Jul 20 06:02:22.922780 2026] [security2:error] [pid 796928:tid 797179] [client 115.246.21.170:20601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ygAAAxI"]
[Mon Jul 20 06:02:22.964643 2026] [security2:error] [pid 796928:tid 796993] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ywAC60A"]
[Mon Jul 20 06:02:22.964906 2026] [security2:error] [pid 796928:tid 797140] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6ywAC60A"]
[Mon Jul 20 06:02:23.005112 2026] [security2:error] [pid 796567:tid 796764] [client 103.153.183.69:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//var/www/html/config.php"] [unique_id "al4OT7LfyzVz2SrjZpiZrwAAAlc"], referer: https://www.reddit.com/
[Mon Jul 20 06:02:23.037835 2026] [security2:error] [pid 796567:tid 796638] [remote 162.19.86.63:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OT7LfyzVz2SrjZpiZsQACR0Y"]
[Mon Jul 20 06:02:23.043337 2026] [security2:error] [pid 796928:tid 797062] [client 14.225.17.146:58405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4OTusTy9vX-htKvPn6wgAAAp0"], referer: http://sesamegreenbeans.com/wordpress
[Mon Jul 20 06:02:23.183629 2026] [security2:error] [pid 796567:tid 796732] [client 47.31.86.100:54339] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZuAAAAjc"]
[Mon Jul 20 06:02:23.183811 2026] [security2:error] [pid 796567:tid 796732] [client 47.31.86.100:54339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZuAAAAjc"]
[Mon Jul 20 06:02:23.247068 2026] [security2:error] [pid 796567:tid 796632] [remote 162.19.86.63:44162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OT7LfyzVz2SrjZpiZvAACOUA"], referer: https://narv.co/wp-login.php
[Mon Jul 20 06:02:23.321268 2026] [security2:error] [pid 796567:tid 796718] [client 82.102.18.116:58810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4OT7LfyzVz2SrjZpiZwgAAAik"]
[Mon Jul 20 06:02:23.391311 2026] [security2:error] [pid 796567:tid 796747] [client 74.208.214.194:41142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OT7LfyzVz2SrjZpiZzAAAAkY"]
[Mon Jul 20 06:02:23.465604 2026] [security2:error] [pid 796567:tid 796589] [remote 179.162.94.250:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.94.162.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZzwAChBU"]
[Mon Jul 20 06:02:23.465845 2026] [security2:error] [pid 796567:tid 796809] [client 179.162.94.250:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OT7LfyzVz2SrjZpiZzwAChBU"]
[Mon Jul 20 06:02:23.483286 2026] [security2:error] [pid 796928:tid 796996] [remote 124.55.178.99:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4OT-sTy9vX-htKvPn62gAC1kM"]
[Mon Jul 20 06:02:23.536058 2026] [security2:error] [pid 796928:tid 797123] [client 14.225.17.146:61689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4OT-sTy9vX-htKvPn61wAAAto"], referer: https://narv.co/wordpress
[Mon Jul 20 06:02:23.888366 2026] [security2:error] [pid 796928:tid 797000] [remote 124.55.178.99:35582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4OT-sTy9vX-htKvPn67QACpkc"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:02:23.952701 2026] [security2:error] [pid 796567:tid 796777] [client 77.110.127.138:54511] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/"] [unique_id "al4OT7LfyzVz2SrjZpiZ3QAAAmQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:23.954144 2026] [security2:error] [pid 796928:tid 797076] [client 82.102.18.116:58820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4OT-sTy9vX-htKvPn68gAAAqs"]
[Mon Jul 20 06:02:23.997034 2026] [security2:error] [pid 796567:tid 796813] [client 14.225.17.146:61449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4OT7LfyzVz2SrjZpiZywAAAog"]
[Mon Jul 20 06:02:24.004205 2026] [proxy:error] [pid 796928:tid 797092] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:24.004277 2026] [proxy_http:error] [pid 796928:tid 797092] [client 87.236.176.17:38139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:24.004993 2026] [proxy:error] [pid 796928:tid 797092] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:02:24.005025 2026] [proxy_http:error] [pid 796928:tid 797092] [client 87.236.176.17:38139] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:02:24.156968 2026] [security2:error] [pid 796928:tid 797147] [client 14.225.17.146:54910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4OT-sTy9vX-htKvPn68AAAAvI"], referer: https://sesamegreenbeans.com/wordpress
[Mon Jul 20 06:02:24.372253 2026] [security2:error] [pid 796567:tid 796780] [client 129.222.187.209:62001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OULLfyzVz2SrjZpiZ8gAAAmc"]
[Mon Jul 20 06:02:24.372413 2026] [security2:error] [pid 796567:tid 796780] [client 129.222.187.209:62001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OULLfyzVz2SrjZpiZ8gAAAmc"]
[Mon Jul 20 06:02:24.387907 2026] [security2:error] [pid 796928:tid 797064] [client 45.61.188.240:49291] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "learnthissecret.com"] [uri "/"] [unique_id "al4OUOsTy9vX-htKvPn7BgAAAp8"]
[Mon Jul 20 06:02:24.552410 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OUOsTy9vX-htKvPn7BAAAAtg"], referer: https://mezzacraft.com/crochet-meetups/
[Mon Jul 20 06:02:24.615577 2026] [security2:error] [pid 796928:tid 797151] [client 185.132.186.80:53039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "al4OUOsTy9vX-htKvPn7EwAAAvY"]
[Mon Jul 20 06:02:24.636884 2026] [security2:error] [pid 796928:tid 797060] [client 82.102.18.116:58828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4OUOsTy9vX-htKvPn7FAAAAps"]
[Mon Jul 20 06:02:24.652965 2026] [security2:error] [pid 796567:tid 796778] [client 45.61.188.240:49322] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "learnthissecret.com"] [uri "/"] [unique_id "al4OULLfyzVz2SrjZpiaAgAAAmU"]
[Mon Jul 20 06:02:24.789279 2026] [core:error] [pid 796567:tid 796808] [client 144.217.135.187:39189] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:24.789301 2026] [core:error] [pid 796567:tid 796808] [client 144.217.135.187:39189] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:25.019216 2026] [security2:error] [pid 796928:tid 797007] [remote 160.187.68.132:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4OUesTy9vX-htKvPn7HwAC-U4"]
[Mon Jul 20 06:02:25.023673 2026] [security2:error] [pid 796928:tid 797006] [remote 47.86.33.52:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4OUOsTy9vX-htKvPn7HgAC_00"]
[Mon Jul 20 06:02:25.060313 2026] [security2:error] [pid 796567:tid 796713] [client 57.141.18.28:30214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OTLLfyzVz2SrjZpiZHAACJCI"]
[Mon Jul 20 06:02:25.196209 2026] [security2:error] [pid 796567:tid 796792] [client 41.173.37.102:7169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaHgAAAnM"]
[Mon Jul 20 06:02:25.196324 2026] [security2:error] [pid 796567:tid 796792] [client 41.173.37.102:7169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaHgAAAnM"]
[Mon Jul 20 06:02:25.208944 2026] [security2:error] [pid 796567:tid 796816] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OUbLfyzVz2SrjZpiaGgAAAos"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:25.316785 2026] [security2:error] [pid 796928:tid 797183] [client 82.102.18.116:58830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4OUesTy9vX-htKvPn7JQAAAxY"]
[Mon Jul 20 06:02:25.359453 2026] [security2:error] [pid 796567:tid 796703] [client 46.110.96.34:55645] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OUbLfyzVz2SrjZpiaJAAAAho"]
[Mon Jul 20 06:02:25.470834 2026] [security2:error] [pid 796928:tid 797010] [remote 160.187.68.132:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4OUesTy9vX-htKvPn7LQAC9FE"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:02:25.644689 2026] [security2:error] [pid 796928:tid 797158] [client 27.96.94.195:37644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OTusTy9vX-htKvPn6twAAAv0"]
[Mon Jul 20 06:02:25.645436 2026] [security2:error] [pid 796567:tid 796800] [client 50.116.65.227:40428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OUbLfyzVz2SrjZpiaNgAAAns"]
[Mon Jul 20 06:02:25.657417 2026] [security2:error] [pid 796928:tid 797103] [client 50.116.65.227:40444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OUesTy9vX-htKvPn7MgAAAsY"]
[Mon Jul 20 06:02:25.747074 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:30330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaPQAAAhw"]
[Mon Jul 20 06:02:25.747182 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:30330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaPQAAAhw"]
[Mon Jul 20 06:02:25.965235 2026] [security2:error] [pid 796567:tid 796669] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaRwACL2U"]
[Mon Jul 20 06:02:25.965447 2026] [security2:error] [pid 796567:tid 796724] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OUbLfyzVz2SrjZpiaRwACL2U"]
[Mon Jul 20 06:02:25.986075 2026] [security2:error] [pid 796928:tid 797098] [client 82.102.18.116:58840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "al4OUesTy9vX-htKvPn7PwAAAsE"]
[Mon Jul 20 06:02:26.329609 2026] [security2:error] [pid 796928:tid 797142] [client 146.75.146.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4OUesTy9vX-htKvPn7NQAAAu0"]
[Mon Jul 20 06:02:26.553603 2026] [security2:error] [pid 796567:tid 796784] [client 185.132.186.104:20679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al4OUrLfyzVz2SrjZpiaYAAAAms"]
[Mon Jul 20 06:02:26.576468 2026] [security2:error] [pid 796567:tid 796795] [client 210.212.97.243:10426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OUrLfyzVz2SrjZpiaYQAAAnY"]
[Mon Jul 20 06:02:26.576586 2026] [security2:error] [pid 796567:tid 796795] [client 210.212.97.243:10426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OUrLfyzVz2SrjZpiaYQAAAnY"]
[Mon Jul 20 06:02:26.663772 2026] [security2:error] [pid 796928:tid 797148] [client 82.102.18.116:58842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4OUusTy9vX-htKvPn7WAAAAvM"]
[Mon Jul 20 06:02:26.751642 2026] [security2:error] [pid 796928:tid 797093] [client 103.149.16.77:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OUusTy9vX-htKvPn7XgAAArw"]
[Mon Jul 20 06:02:26.751767 2026] [security2:error] [pid 796928:tid 797093] [client 103.149.16.77:59301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OUusTy9vX-htKvPn7XgAAArw"]
[Mon Jul 20 06:02:26.762226 2026] [security2:error] [pid 796928:tid 797019] [remote 8.217.108.67:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "circafabrication.com"] [uri "/wp-login.php"] [unique_id "al4OUusTy9vX-htKvPn7XQAC6Fo"], referer: https://circafabrication.com/wp-login.php
[Mon Jul 20 06:02:26.874629 2026] [security2:error] [pid 796567:tid 796579] [remote 198.46.152.106:47224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4OUrLfyzVz2SrjZpiaawACMAs"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:02:27.040207 2026] [security2:error] [pid 796928:tid 797079] [client 57.141.18.119:48150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OTusTy9vX-htKvPn6vAACrj0"]
[Mon Jul 20 06:02:27.290205 2026] [security2:error] [pid 796928:tid 797074] [client 82.102.18.116:58848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4OU-sTy9vX-htKvPn7eAAAAqk"]
[Mon Jul 20 06:02:27.433818 2026] [security2:error] [pid 796928:tid 797124] [client 164.100.212.184:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OU-sTy9vX-htKvPn7ggAAAts"]
[Mon Jul 20 06:02:27.433930 2026] [security2:error] [pid 796928:tid 797124] [client 164.100.212.184:51981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OU-sTy9vX-htKvPn7ggAAAts"]
[Mon Jul 20 06:02:27.680012 2026] [security2:error] [pid 796928:tid 797026] [remote 212.95.34.85:13856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OU-sTy9vX-htKvPn7lAADD2E"]
[Mon Jul 20 06:02:27.868894 2026] [security2:error] [pid 796567:tid 796724] [client 181.224.94.124:20289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OU7LfyzVz2SrjZpiajwAAAi8"]
[Mon Jul 20 06:02:27.869027 2026] [security2:error] [pid 796567:tid 796724] [client 181.224.94.124:20289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OU7LfyzVz2SrjZpiajwAAAi8"]
[Mon Jul 20 06:02:27.876085 2026] [security2:error] [pid 796928:tid 797027] [remote 212.95.34.85:13856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OU-sTy9vX-htKvPn7mgAC02I"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:02:27.931973 2026] [security2:error] [pid 796567:tid 796719] [client 77.110.127.138:54508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/"] [unique_id "al4OU7LfyzVz2SrjZpiakQAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:27.965371 2026] [security2:error] [pid 796928:tid 797058] [client 82.102.18.116:58856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4OU-sTy9vX-htKvPn7nQAAApk"]
[Mon Jul 20 06:02:28.067345 2026] [security2:error] [pid 796928:tid 797028] [remote 91.142.222.105:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OVOsTy9vX-htKvPn7pAAC9GM"]
[Mon Jul 20 06:02:28.133056 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:55350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OVOsTy9vX-htKvPn7pgAAAuw"]
[Mon Jul 20 06:02:28.138027 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:55350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OVOsTy9vX-htKvPn7pgAAAuw"]
[Mon Jul 20 06:02:28.342627 2026] [security2:error] [pid 796928:tid 797032] [remote 91.142.222.105:33862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OVOsTy9vX-htKvPn7rQACuGc"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:02:28.373149 2026] [security2:error] [pid 796928:tid 797033] [remote 47.86.33.52:38738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4OVOsTy9vX-htKvPn7rgAC8mg"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:02:28.509580 2026] [security2:error] [pid 796928:tid 797122] [client 158.173.166.181:27809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OVOsTy9vX-htKvPn7tAAAAtk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:28.590183 2026] [security2:error] [pid 796928:tid 797100] [client 14.225.17.146:64042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4OUusTy9vX-htKvPn7RAAAAsM"], referer: http://aandarealtygroup.com/wordpress
[Mon Jul 20 06:02:28.603118 2026] [security2:error] [pid 796567:tid 796723] [client 82.102.18.116:53714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fineartsfactory.net"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4OVLLfyzVz2SrjZpiatwAAAi4"]
[Mon Jul 20 06:02:28.909353 2026] [security2:error] [pid 796567:tid 796710] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OVLLfyzVz2SrjZpiavQAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:29.032322 2026] [security2:error] [pid 796567:tid 796803] [client 185.132.186.104:37423] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/1.php"] [unique_id "al4OVbLfyzVz2SrjZpiaywAAAn4"]
[Mon Jul 20 06:02:29.032446 2026] [security2:error] [pid 796567:tid 796803] [client 185.132.186.104:37423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/1.php"] [unique_id "al4OVbLfyzVz2SrjZpiaywAAAn4"]
[Mon Jul 20 06:02:29.096524 2026] [security2:error] [pid 796567:tid 796727] [client 14.225.17.146:53813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OU7LfyzVz2SrjZpiahwAAAjI"], referer: http://effingweirdmuseums.com/wordpress
[Mon Jul 20 06:02:29.256111 2026] [security2:error] [pid 796567:tid 796745] [client 144.124.196.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4OVLLfyzVz2SrjZpiaxgAAAkQ"]
[Mon Jul 20 06:02:29.701068 2026] [security2:error] [pid 796567:tid 796781] [client 114.119.142.207:62767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "verdunestate.com"] [uri "/lebanon-beirut/propertyDetail.asp"] [unique_id "al4OVbLfyzVz2SrjZpia6AAAAmg"], referer: http://verdunestate.com/lebanon-beirut/property.asp?p=15&region&area&ListingtypeID&PropertytypeID
[Mon Jul 20 06:02:30.024729 2026] [security2:error] [pid 796567:tid 796728] [client 14.225.17.146:61500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OVbLfyzVz2SrjZpia7QAAAjM"], referer: https://effingweirdmuseums.com/wordpress
[Mon Jul 20 06:02:30.068058 2026] [security2:error] [pid 796928:tid 797041] [remote 5.161.225.162:53694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn79AACuXA"]
[Mon Jul 20 06:02:30.097902 2026] [security2:error] [pid 796928:tid 797152] [client 72.255.10.154:26256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn79wAAAvc"]
[Mon Jul 20 06:02:30.098018 2026] [security2:error] [pid 796928:tid 797152] [client 72.255.10.154:26256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn79wAAAvc"]
[Mon Jul 20 06:02:30.196223 2026] [security2:error] [pid 796567:tid 796704] [client 112.213.160.112:31163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OVrLfyzVz2SrjZpia_AAAAhs"]
[Mon Jul 20 06:02:30.196413 2026] [security2:error] [pid 796567:tid 796704] [client 112.213.160.112:31163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OVrLfyzVz2SrjZpia_AAAAhs"]
[Mon Jul 20 06:02:30.262319 2026] [security2:error] [pid 796928:tid 797042] [remote 5.161.225.162:53694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn7_AAC9HE"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:02:30.350891 2026] [security2:error] [pid 796928:tid 797077] [client 3.77.67.4:31894] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4OVusTy9vX-htKvPn7-wAAAqw"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:02:30.723687 2026] [security2:error] [pid 796928:tid 797047] [remote 167.233.114.32:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn8DAAC_nY"]
[Mon Jul 20 06:02:30.905173 2026] [security2:error] [pid 796928:tid 797049] [remote 167.233.114.32:41560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4OVusTy9vX-htKvPn8FAACw3g"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:02:30.933095 2026] [security2:error] [pid 796928:tid 797110] [client 150.228.148.150:14324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn8FQAAAs0"]
[Mon Jul 20 06:02:30.933248 2026] [security2:error] [pid 796928:tid 797110] [client 150.228.148.150:14324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OVusTy9vX-htKvPn8FQAAAs0"]
[Mon Jul 20 06:02:30.990876 2026] [security2:error] [pid 796928:tid 797072] [client 185.132.186.83:26041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Engine/index.php"] [unique_id "al4OVusTy9vX-htKvPn8FgAAAqc"]
[Mon Jul 20 06:02:31.265593 2026] [security2:error] [pid 796567:tid 796701] [client 179.0.122.163:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.122.0.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OV7LfyzVz2SrjZpibKgAAAhg"]
[Mon Jul 20 06:02:31.265772 2026] [security2:error] [pid 796567:tid 796701] [client 179.0.122.163:21813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OV7LfyzVz2SrjZpibKgAAAhg"]
[Mon Jul 20 06:02:31.451260 2026] [security2:error] [pid 796567:tid 796728] [client 77.110.127.138:54508] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/"] [unique_id "al4OV7LfyzVz2SrjZpibLQAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:31.670659 2026] [security2:error] [pid 796928:tid 796936] [remote 95.217.78.234:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OV-sTy9vX-htKvPn8OwACmwc"]
[Mon Jul 20 06:02:31.674861 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:50492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4OV-sTy9vX-htKvPn8OAAAAvU"], referer: http://katsklar.com/wordpress
[Mon Jul 20 06:02:31.900508 2026] [security2:error] [pid 796928:tid 796939] [remote 95.217.78.234:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OV-sTy9vX-htKvPn8QwADFwo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:02:32.150686 2026] [security2:error] [pid 796928:tid 797157] [client 74.208.214.194:38550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OWOsTy9vX-htKvPn8TgAAAvw"]
[Mon Jul 20 06:02:32.160421 2026] [security2:error] [pid 796928:tid 797173] [client 27.96.94.195:37913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OWOsTy9vX-htKvPn8RgAAAww"]
[Mon Jul 20 06:02:32.225837 2026] [security2:error] [pid 796567:tid 796717] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OWLLfyzVz2SrjZpibRAAAAig"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:32.463520 2026] [security2:error] [pid 796567:tid 796735] [client 57.141.18.46:43338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OU7LfyzVz2SrjZpiakAACOnA"]
[Mon Jul 20 06:02:32.468194 2026] [security2:error] [pid 796567:tid 796581] [remote 45.90.123.233:44790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4OWLLfyzVz2SrjZpibXgACNA0"]
[Mon Jul 20 06:02:32.468348 2026] [security2:error] [pid 796567:tid 796729] [client 45.90.123.233:44790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4OWLLfyzVz2SrjZpibXgACNA0"]
[Mon Jul 20 06:02:32.567919 2026] [security2:error] [pid 796928:tid 797068] [client 103.95.123.246:19829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OWOsTy9vX-htKvPn8VQAAAqM"]
[Mon Jul 20 06:02:32.568116 2026] [security2:error] [pid 796928:tid 797068] [client 103.95.123.246:19829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OWOsTy9vX-htKvPn8VQAAAqM"]
[Mon Jul 20 06:02:32.733519 2026] [security2:error] [pid 796928:tid 797149] [client 13.219.54.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OWOsTy9vX-htKvPn8VgAC9A4"]
[Mon Jul 20 06:02:32.813265 2026] [security2:error] [pid 796928:tid 796948] [remote 45.90.123.233:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4OWOsTy9vX-htKvPn8YwADAxM"]
[Mon Jul 20 06:02:32.940444 2026] [security2:error] [pid 796928:tid 797063] [client 185.132.186.57:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/index.php"] [unique_id "al4OWOsTy9vX-htKvPn8agAAAp4"]
[Mon Jul 20 06:02:33.006849 2026] [security2:error] [pid 796928:tid 796947] [remote 45.90.123.233:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4OWesTy9vX-htKvPn8bQAC-RI"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:02:33.314221 2026] [security2:error] [pid 796567:tid 796686] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibgwACi3Y"]
[Mon Jul 20 06:02:33.314332 2026] [security2:error] [pid 796567:tid 796816] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibgwACi3Y"]
[Mon Jul 20 06:02:33.346206 2026] [security2:error] [pid 796928:tid 797067] [client 18.228.171.129:23322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8eAAAAqI"]
[Mon Jul 20 06:02:33.346327 2026] [security2:error] [pid 796928:tid 797067] [client 18.228.171.129:23322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8eAAAAqI"]
[Mon Jul 20 06:02:33.536302 2026] [security2:error] [pid 796567:tid 796692] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibjwACh3w"]
[Mon Jul 20 06:02:33.536478 2026] [security2:error] [pid 796567:tid 796812] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OWbLfyzVz2SrjZpibjwACh3w"]
[Mon Jul 20 06:02:33.563744 2026] [security2:error] [pid 796928:tid 797147] [client 115.246.21.170:17041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fQAAAvI"]
[Mon Jul 20 06:02:33.563923 2026] [security2:error] [pid 796928:tid 797147] [client 115.246.21.170:17041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fQAAAvI"]
[Mon Jul 20 06:02:33.650444 2026] [security2:error] [pid 796567:tid 796608] [remote 57.141.18.42:54220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6065685"] [unique_id "al4OWbLfyzVz2SrjZpibkgACIig"]
[Mon Jul 20 06:02:33.671833 2026] [security2:error] [pid 796928:tid 797183] [client 106.192.104.4:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fgAAAxY"]
[Mon Jul 20 06:02:33.672008 2026] [security2:error] [pid 796928:tid 797183] [client 106.192.104.4:53541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fgAAAxY"]
[Mon Jul 20 06:02:33.727424 2026] [security2:error] [pid 796928:tid 797167] [client 47.31.86.100:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fwAAAwY"]
[Mon Jul 20 06:02:33.727564 2026] [security2:error] [pid 796928:tid 797167] [client 47.31.86.100:54769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OWesTy9vX-htKvPn8fwAAAwY"]
[Mon Jul 20 06:02:33.885075 2026] [security2:error] [pid 796567:tid 796745] [client 193.19.109.222:40073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4OWbLfyzVz2SrjZpibowAAAkQ"]
[Mon Jul 20 06:02:34.063995 2026] [security2:error] [pid 796928:tid 796933] [remote 217.61.143.92:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4OWusTy9vX-htKvPn8igACowQ"]
[Mon Jul 20 06:02:34.289925 2026] [security2:error] [pid 796928:tid 796963] [remote 217.61.143.92:33422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4OWusTy9vX-htKvPn8lgAC0SI"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:02:34.463209 2026] [security2:error] [pid 796928:tid 796962] [remote 57.141.18.34:40496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3053148"] [unique_id "al4OWusTy9vX-htKvPn8mQADCCE"]
[Mon Jul 20 06:02:34.493825 2026] [security2:error] [pid 796928:tid 797153] [client 14.251.3.155:55567] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OWusTy9vX-htKvPn8nAAAAvg"]
[Mon Jul 20 06:02:34.599318 2026] [security2:error] [pid 796567:tid 796700] [client 50.116.65.227:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OWrLfyzVz2SrjZpibxwAAAhc"]
[Mon Jul 20 06:02:34.610605 2026] [security2:error] [pid 796567:tid 796816] [client 50.116.65.227:38092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OWrLfyzVz2SrjZpibyQAAAos"]
[Mon Jul 20 06:02:34.843202 2026] [security2:error] [pid 796928:tid 797067] [client 14.251.3.155:50771] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OWusTy9vX-htKvPn8ogAAAqI"]
[Mon Jul 20 06:02:34.999132 2026] [security2:error] [pid 796567:tid 796743] [client 129.222.187.209:34314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OWrLfyzVz2SrjZpib2AAAAkI"]
[Mon Jul 20 06:02:35.009376 2026] [security2:error] [pid 796567:tid 796743] [client 129.222.187.209:34314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OWrLfyzVz2SrjZpib2AAAAkI"]
[Mon Jul 20 06:02:35.285193 2026] [security2:error] [pid 796567:tid 796726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OWrLfyzVz2SrjZpib1gAAAjE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:35.456115 2026] [security2:error] [pid 796928:tid 797175] [client 185.132.186.81:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/fm.php"] [unique_id "al4OW-sTy9vX-htKvPn8ugAAAw4"]
[Mon Jul 20 06:02:35.483098 2026] [security2:error] [pid 796928:tid 797099] [client 193.19.109.218:26371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OW-sTy9vX-htKvPn8vQAAAsI"]
[Mon Jul 20 06:02:35.516735 2026] [security2:error] [pid 796928:tid 797149] [client 193.19.109.238:47319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OW-sTy9vX-htKvPn8wQAAAvQ"]
[Mon Jul 20 06:02:35.547453 2026] [security2:error] [pid 796928:tid 797087] [client 193.37.33.1:60817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4OW-sTy9vX-htKvPn8xAAAArY"]
[Mon Jul 20 06:02:35.793449 2026] [security2:error] [pid 796928:tid 797131] [client 178.152.178.232:36053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zQAAAuI"]
[Mon Jul 20 06:02:35.793664 2026] [security2:error] [pid 796928:tid 797131] [client 178.152.178.232:36053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zQAAAuI"]
[Mon Jul 20 06:02:35.804323 2026] [autoindex:error] [pid 796928:tid 797124] [client 14.225.17.146:62179] AH01276: Cannot serve directory /home1/amaliaca/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://amalia-capital.com/wordpress
[Mon Jul 20 06:02:35.804689 2026] [security2:error] [pid 796928:tid 797142] [client 41.173.37.102:7615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zwAAAu0"]
[Mon Jul 20 06:02:35.804823 2026] [security2:error] [pid 796928:tid 797142] [client 41.173.37.102:7615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OW-sTy9vX-htKvPn8zwAAAu0"]
[Mon Jul 20 06:02:36.017507 2026] [security2:error] [pid 796928:tid 797139] [client 14.225.17.146:52807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4OWusTy9vX-htKvPn8kgAAAuo"], referer: http://nomorewetsheets.net/wordpress
[Mon Jul 20 06:02:36.111349 2026] [security2:error] [pid 796567:tid 796818] [client 14.225.17.146:57611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4OWrLfyzVz2SrjZpibwwAAAo0"], referer: http://chestermonty.com/wordpress
[Mon Jul 20 06:02:36.535614 2026] [security2:error] [pid 796928:tid 796971] [remote 124.55.178.99:36076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OXOsTy9vX-htKvPn88AAC-io"]
[Mon Jul 20 06:02:36.535819 2026] [security2:error] [pid 796928:tid 797155] [client 124.55.178.99:36076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OXOsTy9vX-htKvPn88AAC-io"]
[Mon Jul 20 06:02:36.551009 2026] [lsapi:warn] [pid 796928:tid 797150] [client 14.225.17.146:57495] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:36.551038 2026] [lsapi:warn] [pid 796928:tid 797150] [client 14.225.17.146:57495] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:36.553667 2026] [security2:error] [pid 796567:tid 796572] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicBwACbwQ"]
[Mon Jul 20 06:02:36.553874 2026] [security2:error] [pid 796567:tid 796788] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicBwACbwQ"]
[Mon Jul 20 06:02:36.751947 2026] [security2:error] [pid 796928:tid 796972] [remote 152.228.213.32:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4OXOsTy9vX-htKvPn89AACtis"]
[Mon Jul 20 06:02:36.765641 2026] [security2:error] [pid 796567:tid 796796] [client 65.1.132.125:19926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicCgAAAnc"]
[Mon Jul 20 06:02:36.765792 2026] [security2:error] [pid 796567:tid 796796] [client 65.1.132.125:19926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OXLLfyzVz2SrjZpicCgAAAnc"]
[Mon Jul 20 06:02:36.894423 2026] [security2:error] [pid 796928:tid 797122] [client 57.141.18.47:44424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OV-sTy9vX-htKvPn8QgAC2QY"]
[Mon Jul 20 06:02:37.030353 2026] [security2:error] [pid 796567:tid 796712] [client 114.119.129.107:60877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hoomanr.com"] [uri "/web/handbook/handbook4.jpg"] [unique_id "al4OXbLfyzVz2SrjZpicGAAAAiM"], referer: http://hoomanr.com/web/handbook/handbook4.jpg
[Mon Jul 20 06:02:37.064420 2026] [security2:error] [pid 796567:tid 796661] [remote 124.55.178.99:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OXbLfyzVz2SrjZpicGgACHF0"]
[Mon Jul 20 06:02:37.092356 2026] [security2:error] [pid 796928:tid 797140] [client 210.212.97.243:10427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OXesTy9vX-htKvPn9AAAAAus"]
[Mon Jul 20 06:02:37.092541 2026] [security2:error] [pid 796928:tid 797140] [client 210.212.97.243:10427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OXesTy9vX-htKvPn9AAAAAus"]
[Mon Jul 20 06:02:37.110447 2026] [lsapi:warn] [pid 796567:tid 796707] [client 50.116.65.227:38136] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:02:37.110475 2026] [lsapi:warn] [pid 796567:tid 796707] [client 50.116.65.227:38136] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:02:37.124902 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:57495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4OXOsTy9vX-htKvPn82gAAAvU"], referer: http://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:37.127078 2026] [security2:error] [pid 796928:tid 797092] [client 14.225.17.146:64861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4OXesTy9vX-htKvPn8-gAAArs"], referer: https://chestermonty.com/wordpress
[Mon Jul 20 06:02:37.207579 2026] [security2:error] [pid 796928:tid 796974] [remote 152.228.213.32:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4OXesTy9vX-htKvPn9AQAC0i0"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:02:37.326363 2026] [security2:error] [pid 796567:tid 796766] [client 103.149.16.77:59793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OXbLfyzVz2SrjZpicIwAAAlk"]
[Mon Jul 20 06:02:37.326471 2026] [security2:error] [pid 796567:tid 796766] [client 103.149.16.77:59793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OXbLfyzVz2SrjZpicIwAAAlk"]
[Mon Jul 20 06:02:37.395292 2026] [security2:error] [pid 796928:tid 797132] [client 185.132.186.72:36773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/index.php"] [unique_id "al4OXesTy9vX-htKvPn9CwAAAuM"]
[Mon Jul 20 06:02:37.456666 2026] [security2:error] [pid 796928:tid 797069] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OXesTy9vX-htKvPn9BQAAAqQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:37.482009 2026] [security2:error] [pid 796567:tid 796634] [remote 124.55.178.99:36084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OXbLfyzVz2SrjZpicKgACOUI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:02:37.970439 2026] [security2:error] [pid 796928:tid 797159] [client 47.128.112.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.benbayly.co.nz"] [uri "/index.php"] [unique_id "al4OXOsTy9vX-htKvPn89QAC_gU"]
[Mon Jul 20 06:02:37.998919 2026] [security2:error] [pid 796928:tid 797156] [client 114.119.140.50:36465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villa-m-medjugorje.com"] [uri "/terms-conditions/"] [unique_id "al4OXesTy9vX-htKvPn9FAAAAvs"], referer: https://villa-m-medjugorje.com/booking-confirmation/booking-canceled/
[Mon Jul 20 06:02:38.017929 2026] [security2:error] [pid 796928:tid 797099] [client 164.100.212.184:61967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OXusTy9vX-htKvPn9GAAAAsI"]
[Mon Jul 20 06:02:38.018026 2026] [security2:error] [pid 796928:tid 797099] [client 164.100.212.184:61967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OXusTy9vX-htKvPn9GAAAAsI"]
[Mon Jul 20 06:02:38.039159 2026] [lsapi:warn] [pid 796567:tid 796817] [client 14.225.17.146:62782] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:38.039179 2026] [lsapi:warn] [pid 796567:tid 796817] [client 14.225.17.146:62782] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:38.090687 2026] [security2:error] [pid 796567:tid 796817] [client 14.225.17.146:62782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4OXrLfyzVz2SrjZpicQQAAAow"], referer: https://oswegooperatheater.com/wordpress
[Mon Jul 20 06:02:38.299419 2026] [security2:error] [pid 796567:tid 796716] [client 46.110.96.34:19965] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSgAAAic"]
[Mon Jul 20 06:02:38.299419 2026] [security2:error] [pid 796928:tid 797143] [client 46.110.96.34:6158] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9HQAAAu4"]
[Mon Jul 20 06:02:38.299506 2026] [security2:error] [pid 796567:tid 796716] [client 46.110.96.34:19965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSgAAAic"]
[Mon Jul 20 06:02:38.299512 2026] [security2:error] [pid 796928:tid 797143] [client 46.110.96.34:6158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9HQAAAu4"]
[Mon Jul 20 06:02:38.299598 2026] [security2:error] [pid 796567:tid 796821] [client 46.110.96.34:10348] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSwAAApA"]
[Mon Jul 20 06:02:38.299742 2026] [security2:error] [pid 796567:tid 796821] [client 46.110.96.34:10348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicSwAAApA"]
[Mon Jul 20 06:02:38.300377 2026] [security2:error] [pid 796567:tid 796792] [client 46.110.96.34:38347] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicTAAAAnM"]
[Mon Jul 20 06:02:38.300458 2026] [security2:error] [pid 796567:tid 796792] [client 46.110.96.34:38347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicTAAAAnM"]
[Mon Jul 20 06:02:38.380203 2026] [security2:error] [pid 796567:tid 796719] [client 181.224.94.124:9899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicVAAAAio"]
[Mon Jul 20 06:02:38.380356 2026] [security2:error] [pid 796567:tid 796719] [client 181.224.94.124:9899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicVAAAAio"]
[Mon Jul 20 06:02:38.533774 2026] [security2:error] [pid 796928:tid 797131] [client 46.110.96.34:6158] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9JgAAAuI"]
[Mon Jul 20 06:02:38.533859 2026] [security2:error] [pid 796928:tid 797131] [client 46.110.96.34:6158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXusTy9vX-htKvPn9JgAAAuI"]
[Mon Jul 20 06:02:38.535253 2026] [security2:error] [pid 796567:tid 796736] [client 46.110.96.34:10348] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXAAAAjs"]
[Mon Jul 20 06:02:38.535367 2026] [security2:error] [pid 796567:tid 796736] [client 46.110.96.34:10348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXAAAAjs"]
[Mon Jul 20 06:02:38.549140 2026] [security2:error] [pid 796928:tid 797146] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OXusTy9vX-htKvPn9IQAAAvE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:38.557648 2026] [security2:error] [pid 796567:tid 796710] [client 46.110.96.34:19965] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXgAAAiE"]
[Mon Jul 20 06:02:38.557724 2026] [security2:error] [pid 796567:tid 796710] [client 46.110.96.34:19965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicXgAAAiE"]
[Mon Jul 20 06:02:38.664680 2026] [security2:error] [pid 796567:tid 796722] [client 46.110.96.34:38347] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicZQAAAi0"]
[Mon Jul 20 06:02:38.664817 2026] [security2:error] [pid 796567:tid 796722] [client 46.110.96.34:38347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OXrLfyzVz2SrjZpicZQAAAi0"]
[Mon Jul 20 06:02:38.698247 2026] [security2:error] [pid 796567:tid 796795] [client 129.222.187.209:21031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZwAAAnY"]
[Mon Jul 20 06:02:38.699285 2026] [security2:error] [pid 796567:tid 796705] [client 44.245.170.32:24324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZgAAAhw"]
[Mon Jul 20 06:02:38.699381 2026] [security2:error] [pid 796567:tid 796705] [client 44.245.170.32:24324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZgAAAhw"]
[Mon Jul 20 06:02:38.708590 2026] [security2:error] [pid 796567:tid 796795] [client 129.222.187.209:21031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OXrLfyzVz2SrjZpicZwAAAnY"]
[Mon Jul 20 06:02:38.956517 2026] [security2:error] [pid 796567:tid 796745] [client 14.225.17.146:57312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4OXbLfyzVz2SrjZpicOAAAAkQ"], referer: http://retzkolonglogistics.com/wordpress
[Mon Jul 20 06:02:39.089893 2026] [security2:error] [pid 796928:tid 797133] [client 57.141.18.41:56944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OWusTy9vX-htKvPn8hwAC5B4"]
[Mon Jul 20 06:02:39.319594 2026] [security2:error] [pid 796567:tid 796740] [client 185.132.186.66:33487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/wp-conflg.php"] [unique_id "al4OX7LfyzVz2SrjZpicfAAAAj8"]
[Mon Jul 20 06:02:40.848061 2026] [security2:error] [pid 796567:tid 796714] [client 27.96.94.195:37899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OYLLfyzVz2SrjZpicuQAAAiU"]
[Mon Jul 20 06:02:40.864232 2026] [security2:error] [pid 796928:tid 797073] [client 112.213.160.112:30794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OYOsTy9vX-htKvPn9YgAAAqg"]
[Mon Jul 20 06:02:40.864379 2026] [security2:error] [pid 796928:tid 797073] [client 112.213.160.112:30794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OYOsTy9vX-htKvPn9YgAAAqg"]
[Mon Jul 20 06:02:40.916573 2026] [core:error] [pid 796928:tid 797106] [client 205.210.31.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:40.916592 2026] [core:error] [pid 796928:tid 797106] [client 205.210.31.33:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:02:41.085692 2026] [security2:error] [pid 796567:tid 796794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicwQAAAnU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:41.268208 2026] [security2:error] [pid 796567:tid 796768] [client 185.132.186.53:31127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/file.php"] [unique_id "al4OYbLfyzVz2SrjZpic1AAAAls"]
[Mon Jul 20 06:02:41.273937 2026] [security2:error] [pid 796567:tid 796746] [client 14.225.17.146:56028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicxgAAAkU"], referer: http://healthylifegourmet.org/wordpress
[Mon Jul 20 06:02:41.372148 2026] [security2:error] [pid 796567:tid 796625] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OYbLfyzVz2SrjZpic1gACGjk"]
[Mon Jul 20 06:02:41.372286 2026] [security2:error] [pid 796567:tid 796703] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OYbLfyzVz2SrjZpic1gACGjk"]
[Mon Jul 20 06:02:41.500764 2026] [security2:error] [pid 796928:tid 797175] [client 14.225.17.146:55445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4OX-sTy9vX-htKvPn9QQAAAw4"], referer: http://soloceos.com/wordpress
[Mon Jul 20 06:02:41.688433 2026] [security2:error] [pid 796928:tid 797112] [client 72.255.10.154:26235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9hgAAAs8"]
[Mon Jul 20 06:02:41.688573 2026] [security2:error] [pid 796928:tid 797112] [client 72.255.10.154:26235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9hgAAAs8"]
[Mon Jul 20 06:02:41.798518 2026] [security2:error] [pid 796928:tid 797171] [client 150.228.148.150:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9igAAAwo"]
[Mon Jul 20 06:02:41.806193 2026] [security2:error] [pid 796928:tid 797171] [client 150.228.148.150:62457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9igAAAwo"]
[Mon Jul 20 06:02:41.875599 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:52294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicmQAAAhg"], referer: http://ksands.co.uk/wordpress
[Mon Jul 20 06:02:41.920506 2026] [security2:error] [pid 796928:tid 797130] [client 193.37.33.231:40495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abilite.uk"] [uri "/wp-login.php"] [unique_id "al4OYesTy9vX-htKvPn9jQAAAuE"]
[Mon Jul 20 06:02:41.970891 2026] [security2:error] [pid 796928:tid 797100] [client 95.70.205.159:31048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.205.70.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aprendeameditar.co"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9jgAAAsM"]
[Mon Jul 20 06:02:41.971133 2026] [security2:error] [pid 796928:tid 797100] [client 95.70.205.159:31048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aprendeameditar.co"] [uri "/xmlrpc.php"] [unique_id "al4OYesTy9vX-htKvPn9jgAAAsM"]
[Mon Jul 20 06:02:42.014910 2026] [security2:error] [pid 796567:tid 796777] [client 14.225.17.146:56072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicowAAAmQ"], referer: http://alexsandbergmusic.com/wordpress
[Mon Jul 20 06:02:42.328674 2026] [security2:error] [pid 796928:tid 797106] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYusTy9vX-htKvPn9lQAAAsk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:42.455411 2026] [security2:error] [pid 796928:tid 797108] [client 65.1.132.125:19936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OYusTy9vX-htKvPn9ogAAAss"]
[Mon Jul 20 06:02:42.455496 2026] [security2:error] [pid 796928:tid 797108] [client 65.1.132.125:19936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OYusTy9vX-htKvPn9ogAAAss"]
[Mon Jul 20 06:02:42.816431 2026] [security2:error] [pid 796567:tid 796773] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYrLfyzVz2SrjZpic_wAAAmA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:43.195570 2026] [security2:error] [pid 796928:tid 797123] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OYusTy9vX-htKvPn9tQAAAto"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:43.217229 2026] [security2:error] [pid 796928:tid 797073] [client 185.132.186.70:56021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4OY-sTy9vX-htKvPn9xgAAAqg"]
[Mon Jul 20 06:02:43.367105 2026] [security2:error] [pid 796928:tid 797088] [client 50.116.65.227:48574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OY-sTy9vX-htKvPn9zgAAArc"]
[Mon Jul 20 06:02:43.377880 2026] [security2:error] [pid 796567:tid 796738] [client 50.116.65.227:48576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OY7LfyzVz2SrjZpidIAAAAj0"]
[Mon Jul 20 06:02:43.759339 2026] [security2:error] [pid 796928:tid 797180] [client 103.95.123.246:20334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OY-sTy9vX-htKvPn94QAAAxM"]
[Mon Jul 20 06:02:43.760154 2026] [security2:error] [pid 796928:tid 797180] [client 103.95.123.246:20334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OY-sTy9vX-htKvPn94QAAAxM"]
[Mon Jul 20 06:02:43.860185 2026] [security2:error] [pid 796567:tid 796707] [client 106.192.104.4:54007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OY7LfyzVz2SrjZpidOgAAAh4"]
[Mon Jul 20 06:02:43.860310 2026] [security2:error] [pid 796567:tid 796707] [client 106.192.104.4:54007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OY7LfyzVz2SrjZpidOgAAAh4"]
[Mon Jul 20 06:02:43.875183 2026] [security2:error] [pid 796928:tid 797124] [client 124.156.157.91:55064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4OYusTy9vX-htKvPn9mAAAAts"]
[Mon Jul 20 06:02:44.066518 2026] [security2:error] [pid 796928:tid 797168] [client 18.228.171.129:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn97wAAAwc"]
[Mon Jul 20 06:02:44.066627 2026] [security2:error] [pid 796928:tid 797168] [client 18.228.171.129:37888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn97wAAAwc"]
[Mon Jul 20 06:02:44.079720 2026] [security2:error] [pid 796928:tid 797013] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn98QADEFQ"]
[Mon Jul 20 06:02:44.079965 2026] [security2:error] [pid 796928:tid 797177] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn98QADEFQ"]
[Mon Jul 20 06:02:44.141416 2026] [security2:error] [pid 796928:tid 797093] [client 57.141.18.107:51488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OX-sTy9vX-htKvPn9OwACvBo"]
[Mon Jul 20 06:02:44.318362 2026] [security2:error] [pid 796928:tid 797167] [client 115.246.21.170:24557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn99gAAAwY"]
[Mon Jul 20 06:02:44.320094 2026] [security2:error] [pid 796928:tid 797167] [client 115.246.21.170:24557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OZOsTy9vX-htKvPn99gAAAwY"]
[Mon Jul 20 06:02:44.404007 2026] [security2:error] [pid 796567:tid 796797] [client 14.225.17.146:51072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4OY7LfyzVz2SrjZpidOAAAAng"], referer: http://onewingpictures.com/wordpress
[Mon Jul 20 06:02:44.584839 2026] [security2:error] [pid 796567:tid 796617] [remote 8.217.108.67:1452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OZLLfyzVz2SrjZpidVAACaDE"]
[Mon Jul 20 06:02:44.838443 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZLLfyzVz2SrjZpidTwAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:45.085942 2026] [security2:error] [pid 796567:tid 796789] [client 14.225.17.146:56268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4OY7LfyzVz2SrjZpidKQAAAnA"], referer: http://omrobuildingcenter.com/wordpress
[Mon Jul 20 06:02:45.163157 2026] [security2:error] [pid 796567:tid 796725] [client 185.132.186.65:55965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/fm.php"] [unique_id "al4OZbLfyzVz2SrjZpidcAAAAjA"]
[Mon Jul 20 06:02:45.585382 2026] [security2:error] [pid 796567:tid 796750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZbLfyzVz2SrjZpidbAAAAkk"]
[Mon Jul 20 06:02:45.588689 2026] [security2:error] [pid 796928:tid 797064] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZesTy9vX-htKvPn-IQAAAp8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:45.618886 2026] [security2:error] [pid 796567:tid 796687] [remote 5.161.225.162:60788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OZbLfyzVz2SrjZpidgQACPnc"]
[Mon Jul 20 06:02:45.619048 2026] [security2:error] [pid 796567:tid 796739] [client 5.161.225.162:60788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OZbLfyzVz2SrjZpidgQACPnc"]
[Mon Jul 20 06:02:45.851981 2026] [security2:error] [pid 796567:tid 796692] [remote 8.217.108.67:1452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OZbLfyzVz2SrjZpidiAACinw"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:02:45.927128 2026] [security2:error] [pid 796928:tid 797103] [client 129.222.187.209:29930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OZesTy9vX-htKvPn-RgAAAsY"]
[Mon Jul 20 06:02:45.927235 2026] [security2:error] [pid 796928:tid 797103] [client 129.222.187.209:29930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OZesTy9vX-htKvPn-RgAAAsY"]
[Mon Jul 20 06:02:45.968211 2026] [security2:error] [pid 796567:tid 796706] [client 57.141.18.113:28930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OYLLfyzVz2SrjZpicvgACHUA"]
[Mon Jul 20 06:02:46.474958 2026] [security2:error] [pid 796567:tid 796807] [client 41.173.37.102:8040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OZrLfyzVz2SrjZpidmQAAAoI"]
[Mon Jul 20 06:02:46.475075 2026] [security2:error] [pid 796567:tid 796807] [client 41.173.37.102:8040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OZrLfyzVz2SrjZpidmQAAAoI"]
[Mon Jul 20 06:02:46.673428 2026] [security2:error] [pid 796928:tid 797124] [client 173.239.254.41:46723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OZusTy9vX-htKvPn-YgAAAts"]
[Mon Jul 20 06:02:46.684883 2026] [core:error] [pid 796567:tid 796779] [client 14.225.17.146:55628] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wordpress
[Mon Jul 20 06:02:46.684903 2026] [core:error] [pid 796567:tid 796779] [client 14.225.17.146:55628] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wordpress
[Mon Jul 20 06:02:46.725712 2026] [security2:error] [pid 796928:tid 797102] [client 193.19.109.227:46759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OZusTy9vX-htKvPn-ZgAAAsU"]
[Mon Jul 20 06:02:46.726597 2026] [security2:error] [pid 796928:tid 797061] [client 193.19.109.216:42649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4OZusTy9vX-htKvPn-ZwAAApw"]
[Mon Jul 20 06:02:46.911296 2026] [security2:error] [pid 796928:tid 797029] [remote 57.141.18.86:44028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4388353"] [unique_id "al4OZusTy9vX-htKvPn-cQAC6mQ"]
[Mon Jul 20 06:02:47.104385 2026] [security2:error] [pid 796567:tid 796792] [client 185.132.186.80:49953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "al4OZ7LfyzVz2SrjZpiduAAAAnM"]
[Mon Jul 20 06:02:47.134283 2026] [security2:error] [pid 796567:tid 796767] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OZrLfyzVz2SrjZpidpwAAAlo"]
[Mon Jul 20 06:02:47.152238 2026] [security2:error] [pid 796567:tid 796577] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidugACMAk"]
[Mon Jul 20 06:02:47.152456 2026] [security2:error] [pid 796567:tid 796725] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidugACMAk"]
[Mon Jul 20 06:02:47.607449 2026] [security2:error] [pid 796928:tid 797144] [client 210.212.97.243:10428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ-sTy9vX-htKvPn-jAAAAu8"]
[Mon Jul 20 06:02:47.607561 2026] [security2:error] [pid 796928:tid 797144] [client 210.212.97.243:10428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ-sTy9vX-htKvPn-jAAAAu8"]
[Mon Jul 20 06:02:47.619556 2026] [security2:error] [pid 796928:tid 797041] [remote 162.19.86.63:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4OZ-sTy9vX-htKvPn-jwAC83A"]
[Mon Jul 20 06:02:47.722281 2026] [security2:error] [pid 796567:tid 796729] [client 65.1.132.125:30632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidywAAAjQ"]
[Mon Jul 20 06:02:47.722384 2026] [security2:error] [pid 796567:tid 796729] [client 65.1.132.125:30632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OZ7LfyzVz2SrjZpidywAAAjQ"]
[Mon Jul 20 06:02:47.840271 2026] [security2:error] [pid 796928:tid 797042] [remote 162.19.86.63:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4OZ-sTy9vX-htKvPn-lQACw3E"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:02:48.001265 2026] [security2:error] [pid 796567:tid 796786] [client 14.225.17.146:56632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4OZ7LfyzVz2SrjZpidzgAAAm0"], referer: http://longevityperformanceclinic.com/wordpress
[Mon Jul 20 06:02:48.416869 2026] [security2:error] [pid 796567:tid 796666] [remote 188.166.241.141:47226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OaLLfyzVz2SrjZpieFAACOmI"]
[Mon Jul 20 06:02:48.439623 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:60275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-rAAAAxg"]
[Mon Jul 20 06:02:48.439811 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:60275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-rAAAAxg"]
[Mon Jul 20 06:02:48.529058 2026] [security2:error] [pid 796928:tid 797091] [client 164.100.212.184:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-sQAAAro"]
[Mon Jul 20 06:02:48.529207 2026] [security2:error] [pid 796928:tid 797091] [client 164.100.212.184:62523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OaOsTy9vX-htKvPn-sQAAAro"]
[Mon Jul 20 06:02:48.565295 2026] [security2:error] [pid 796928:tid 797114] [client 57.141.18.57:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OY-sTy9vX-htKvPn9wgAC0Uo"]
[Mon Jul 20 06:02:48.787674 2026] [security2:error] [pid 796567:tid 796644] [remote 188.166.241.141:47226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4OaLLfyzVz2SrjZpieHAACMEw"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:02:48.848496 2026] [security2:error] [pid 796928:tid 797059] [client 14.224.227.113:50776] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OaOsTy9vX-htKvPn-uAAAApo"]
[Mon Jul 20 06:02:48.923185 2026] [security2:error] [pid 796567:tid 796767] [client 181.224.94.124:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaLLfyzVz2SrjZpieIwAAAlo"]
[Mon Jul 20 06:02:49.047136 2026] [security2:error] [pid 796567:tid 796722] [client 185.132.186.83:46945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/adminfuns.php7"] [unique_id "al4OabLfyzVz2SrjZpieJgAAAi0"]
[Mon Jul 20 06:02:49.373355 2026] [security2:error] [pid 796567:tid 796665] [remote 152.228.213.32:45480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OabLfyzVz2SrjZpieMAACdmE"]
[Mon Jul 20 06:02:49.425023 2026] [security2:error] [pid 796567:tid 796767] [client 181.224.94.124:58957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaLLfyzVz2SrjZpieIwAAAlo"]
[Mon Jul 20 06:02:49.486325 2026] [security2:error] [pid 796567:tid 796649] [remote 8.217.108.67:1462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OabLfyzVz2SrjZpieNQACT1E"]
[Mon Jul 20 06:02:49.514700 2026] [security2:error] [pid 796928:tid 797071] [client 14.225.17.146:56735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4OaOsTy9vX-htKvPn-nwAAAqY"], referer: http://dadanetnet.net/wordpress
[Mon Jul 20 06:02:49.525506 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:25640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaesTy9vX-htKvPn-1gAAAp4"]
[Mon Jul 20 06:02:49.525711 2026] [security2:error] [pid 796928:tid 797063] [client 129.222.187.209:25640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OaesTy9vX-htKvPn-1gAAAp4"]
[Mon Jul 20 06:02:49.549878 2026] [security2:error] [pid 796567:tid 796585] [remote 152.228.213.32:45480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OabLfyzVz2SrjZpieOAACHxE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:02:50.067816 2026] [security2:error] [pid 796567:tid 796677] [remote 8.217.108.67:1462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OarLfyzVz2SrjZpieQQACe20"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:02:50.084884 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OabLfyzVz2SrjZpieOgAAAl0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:50.201842 2026] [security2:error] [pid 796928:tid 797162] [client 47.128.29.193:35514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "laceycaraccident.com"] [uri "/robots.txt"] [unique_id "al4OausTy9vX-htKvPn-_wAAAwE"]
[Mon Jul 20 06:02:50.999569 2026] [security2:error] [pid 796928:tid 797169] [client 185.132.186.84:48313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/about.php"] [unique_id "al4OausTy9vX-htKvPn_IwAAAwg"]
[Mon Jul 20 06:02:51.299895 2026] [security2:error] [pid 796928:tid 796942] [remote 167.233.114.32:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4Oa-sTy9vX-htKvPn_MwACmg0"]
[Mon Jul 20 06:02:51.571452 2026] [security2:error] [pid 796928:tid 796971] [remote 167.233.114.32:52508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4Oa-sTy9vX-htKvPn_QgACpSo"], referer: https://dlu.cjf.mybluehost.me/blog/wp-login.php
[Mon Jul 20 06:02:51.642849 2026] [security2:error] [pid 796928:tid 797182] [client 112.213.160.112:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oa-sTy9vX-htKvPn_SAAAAxU"]
[Mon Jul 20 06:02:51.642942 2026] [security2:error] [pid 796928:tid 797182] [client 112.213.160.112:31177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oa-sTy9vX-htKvPn_SAAAAxU"]
[Mon Jul 20 06:02:51.816123 2026] [security2:error] [pid 796928:tid 797157] [client 14.251.3.155:59541] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Oa-sTy9vX-htKvPn_VAAAAvw"]
[Mon Jul 20 06:02:52.477139 2026] [security2:error] [pid 796928:tid 797123] [client 150.228.148.150:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_dAAAAto"]
[Mon Jul 20 06:02:52.484608 2026] [security2:error] [pid 796928:tid 797123] [client 150.228.148.150:45821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_dAAAAto"]
[Mon Jul 20 06:02:52.688651 2026] [security2:error] [pid 796928:tid 797141] [client 27.96.94.195:37959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_dgAAAuw"]
[Mon Jul 20 06:02:52.744795 2026] [security2:error] [pid 796567:tid 796711] [client 77.110.127.138:54684] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4ObLLfyzVz2SrjZpiecQAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:52.940271 2026] [security2:error] [pid 796928:tid 797086] [client 185.132.186.68:30067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ini.php"] [unique_id "al4ObOsTy9vX-htKvPn_iQAAArU"]
[Mon Jul 20 06:02:52.969407 2026] [security2:error] [pid 796928:tid 797139] [client 72.255.10.154:26474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_iwAAAuo"]
[Mon Jul 20 06:02:52.969556 2026] [security2:error] [pid 796928:tid 797139] [client 72.255.10.154:26474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ObOsTy9vX-htKvPn_iwAAAuo"]
[Mon Jul 20 06:02:53.214163 2026] [security2:error] [pid 796567:tid 796629] [remote 20.153.140.50:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ObbLfyzVz2SrjZpiefAACRz0"]
[Mon Jul 20 06:02:53.413492 2026] [security2:error] [pid 796928:tid 797105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ObesTy9vX-htKvPn_oAAAAsg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:53.428833 2026] [security2:error] [pid 796567:tid 796749] [client 57.141.18.45:55606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OZ7LfyzVz2SrjZpid0AACSCc"]
[Mon Jul 20 06:02:53.538979 2026] [security2:error] [pid 796928:tid 797000] [remote 102.134.101.35:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ObesTy9vX-htKvPn_qwADAkc"]
[Mon Jul 20 06:02:53.632997 2026] [security2:error] [pid 796567:tid 796641] [remote 20.153.140.50:57340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ObbLfyzVz2SrjZpieiQACQEk"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:02:53.638119 2026] [security2:error] [pid 796928:tid 797089] [client 50.116.65.227:52818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ObesTy9vX-htKvPn_tgAAArg"]
[Mon Jul 20 06:02:53.651764 2026] [security2:error] [pid 796567:tid 796746] [client 50.116.65.227:52820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ObbLfyzVz2SrjZpieiwAAAkU"]
[Mon Jul 20 06:02:53.987011 2026] [security2:error] [pid 796928:tid 797012] [remote 102.134.101.35:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ObesTy9vX-htKvPn_wwAC3VM"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:02:54.188613 2026] [security2:error] [pid 796928:tid 797116] [client 86.98.90.58:44824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPn_1AAAAtM"]
[Mon Jul 20 06:02:54.188831 2026] [security2:error] [pid 796928:tid 797116] [client 86.98.90.58:44824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPn_1AAAAtM"]
[Mon Jul 20 06:02:54.242336 2026] [security2:error] [pid 796928:tid 797078] [client 57.141.18.19:33528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OaOsTy9vX-htKvPn-vQACrXc"]
[Mon Jul 20 06:02:54.372872 2026] [security2:error] [pid 796928:tid 797024] [remote 124.55.178.99:41852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ObusTy9vX-htKvPn_3AAC_l8"]
[Mon Jul 20 06:02:54.554678 2026] [security2:error] [pid 796567:tid 796788] [client 106.192.104.4:54482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieoAAAAm8"]
[Mon Jul 20 06:02:54.559411 2026] [security2:error] [pid 796567:tid 796788] [client 106.192.104.4:54482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieoAAAAm8"]
[Mon Jul 20 06:02:54.712686 2026] [security2:error] [pid 796928:tid 797110] [client 14.225.17.146:56502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4ObesTy9vX-htKvPn_nAAAAs0"], referer: http://alchemygroup.ca/wordpress
[Mon Jul 20 06:02:54.735913 2026] [security2:error] [pid 796567:tid 796811] [client 18.228.171.129:46358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpiepwAAAoY"]
[Mon Jul 20 06:02:54.736049 2026] [security2:error] [pid 796567:tid 796811] [client 18.228.171.129:46358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpiepwAAAoY"]
[Mon Jul 20 06:02:54.805654 2026] [security2:error] [pid 796567:tid 796637] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieqQACg0U"]
[Mon Jul 20 06:02:54.805832 2026] [security2:error] [pid 796567:tid 796808] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ObrLfyzVz2SrjZpieqQACg0U"]
[Mon Jul 20 06:02:54.806883 2026] [security2:error] [pid 796928:tid 797031] [remote 124.55.178.99:41852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ObusTy9vX-htKvPkAAwACr2Y"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:02:54.821609 2026] [security2:error] [pid 796928:tid 797180] [client 47.31.86.100:55578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkABQAAAxM"]
[Mon Jul 20 06:02:54.825434 2026] [security2:error] [pid 796928:tid 797180] [client 47.31.86.100:55578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkABQAAAxM"]
[Mon Jul 20 06:02:54.889338 2026] [security2:error] [pid 796567:tid 796750] [client 185.132.186.68:63961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "al4ObrLfyzVz2SrjZpieqgAAAkk"]
[Mon Jul 20 06:02:54.972141 2026] [security2:error] [pid 796928:tid 797172] [client 77.110.127.138:54677] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4ObusTy9vX-htKvPkADAAAAws"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:54.995412 2026] [security2:error] [pid 796928:tid 797160] [client 115.246.21.170:31104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkADQAAAv8"]
[Mon Jul 20 06:02:54.995525 2026] [security2:error] [pid 796928:tid 797160] [client 115.246.21.170:31104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4ObusTy9vX-htKvPkADQAAAv8"]
[Mon Jul 20 06:02:55.055945 2026] [security2:error] [pid 796928:tid 797041] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAEwADD3A"]
[Mon Jul 20 06:02:55.056129 2026] [security2:error] [pid 796928:tid 797176] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAEwADD3A"]
[Mon Jul 20 06:02:55.153203 2026] [security2:error] [pid 796928:tid 797173] [client 46.110.96.34:26461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4Ob-sTy9vX-htKvPkAGAAAAww"]
[Mon Jul 20 06:02:55.153338 2026] [security2:error] [pid 796928:tid 797173] [client 46.110.96.34:26461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4Ob-sTy9vX-htKvPkAGAAAAww"]
[Mon Jul 20 06:02:55.185111 2026] [security2:error] [pid 796928:tid 797168] [client 103.95.123.246:20837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAGgAAAwc"]
[Mon Jul 20 06:02:55.185247 2026] [security2:error] [pid 796928:tid 797168] [client 103.95.123.246:20837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ob-sTy9vX-htKvPkAGgAAAwc"]
[Mon Jul 20 06:02:55.265203 2026] [security2:error] [pid 796928:tid 797167] [client 57.141.18.93:56214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OausTy9vX-htKvPn-_AADBg8"]
[Mon Jul 20 06:02:55.298321 2026] [security2:error] [pid 796928:tid 797105] [client 98.159.234.160:51481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Ob-sTy9vX-htKvPkAIAAAAsg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:02:55.680265 2026] [security2:error] [pid 796928:tid 797184] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ob-sTy9vX-htKvPkAKQAAAxc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:56.189586 2026] [security2:error] [pid 796928:tid 797056] [remote 47.251.82.1:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OcOsTy9vX-htKvPkAUQACrn8"]
[Mon Jul 20 06:02:56.341721 2026] [security2:error] [pid 796567:tid 796780] [client 179.0.122.163:22050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.122.0.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie1wAAAmc"]
[Mon Jul 20 06:02:56.341967 2026] [security2:error] [pid 796567:tid 796780] [client 179.0.122.163:22050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie1wAAAmc"]
[Mon Jul 20 06:02:56.536601 2026] [security2:error] [pid 796928:tid 797146] [client 14.182.195.220:51962] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4OcOsTy9vX-htKvPkAYQAAAvE"]
[Mon Jul 20 06:02:56.566648 2026] [security2:error] [pid 796928:tid 796937] [remote 47.251.82.1:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.82.251.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OcOsTy9vX-htKvPkAYwADEwg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:02:56.567843 2026] [security2:error] [pid 796567:tid 796799] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OcLLfyzVz2SrjZpie1AAAAno"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:56.654787 2026] [security2:error] [pid 796567:tid 796737] [client 129.222.187.209:37327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie2wAAAjw"]
[Mon Jul 20 06:02:56.659899 2026] [security2:error] [pid 796567:tid 796737] [client 129.222.187.209:37327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OcLLfyzVz2SrjZpie2wAAAjw"]
[Mon Jul 20 06:02:56.737290 2026] [security2:error] [pid 796928:tid 797068] [client 57.141.18.85:63940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oa-sTy9vX-htKvPn_UAACoy8"]
[Mon Jul 20 06:02:56.806648 2026] [security2:error] [pid 796928:tid 797070] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcOsTy9vX-htKvPkAdwAAAqU"]
[Mon Jul 20 06:02:56.839111 2026] [security2:error] [pid 796928:tid 797166] [client 185.132.186.69:42317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/blocks/calendar/index.php"] [unique_id "al4OcOsTy9vX-htKvPkAegAAAwU"]
[Mon Jul 20 06:02:56.922066 2026] [security2:error] [pid 796928:tid 797069] [client 178.152.178.232:36221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OcOsTy9vX-htKvPkAfgAAAqQ"]
[Mon Jul 20 06:02:56.922200 2026] [security2:error] [pid 796928:tid 797069] [client 178.152.178.232:36221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OcOsTy9vX-htKvPkAfgAAAqQ"]
[Mon Jul 20 06:02:57.107313 2026] [security2:error] [pid 796567:tid 796724] [client 41.173.37.102:8461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OcbLfyzVz2SrjZpie4wAAAi8"]
[Mon Jul 20 06:02:57.107394 2026] [security2:error] [pid 796567:tid 796724] [client 41.173.37.102:8461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OcbLfyzVz2SrjZpie4wAAAi8"]
[Mon Jul 20 06:02:57.344730 2026] [security2:error] [pid 796928:tid 797165] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcesTy9vX-htKvPkAiQAAAwQ"]
[Mon Jul 20 06:02:57.599901 2026] [security2:error] [pid 796567:tid 796777] [client 77.110.127.138:54510] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OcbLfyzVz2SrjZpie9AAAAmQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:57.683593 2026] [security2:error] [pid 796567:tid 796706] [client 57.141.18.14:32754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ObLLfyzVz2SrjZpiecgACHSg"]
[Mon Jul 20 06:02:57.734966 2026] [security2:error] [pid 796928:tid 796945] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OcesTy9vX-htKvPkAngADExA"]
[Mon Jul 20 06:02:57.735140 2026] [security2:error] [pid 796928:tid 797180] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OcesTy9vX-htKvPkAngADExA"]
[Mon Jul 20 06:02:57.808550 2026] [security2:error] [pid 796928:tid 797117] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OcesTy9vX-htKvPkAlQAAAtQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:02:57.900336 2026] [security2:error] [pid 796928:tid 797181] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcesTy9vX-htKvPkAowAAAxQ"]
[Mon Jul 20 06:02:57.945276 2026] [security2:error] [pid 796928:tid 797149] [client 14.225.17.146:56679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4OcesTy9vX-htKvPkAnwAAAvQ"], referer: http://myspineworld.com/wordpress
[Mon Jul 20 06:02:58.125657 2026] [security2:error] [pid 796928:tid 797096] [client 210.212.97.243:10429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkAsgAAAr8"]
[Mon Jul 20 06:02:58.125801 2026] [security2:error] [pid 796928:tid 797096] [client 210.212.97.243:10429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkAsgAAAr8"]
[Mon Jul 20 06:02:58.443488 2026] [security2:error] [pid 796928:tid 797137] [client 163.47.8.108:59244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.zonemist.com"] [uri "/.env"] [unique_id "al4OcusTy9vX-htKvPkAxQAAAug"]
[Mon Jul 20 06:02:58.471004 2026] [security2:error] [pid 796567:tid 796602] [remote 47.86.33.52:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OcrLfyzVz2SrjZpifDwACMiI"]
[Mon Jul 20 06:02:58.496660 2026] [security2:error] [pid 796567:tid 796776] [client 3.109.4.218:42900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OcrLfyzVz2SrjZpifEAAAAmM"]
[Mon Jul 20 06:02:58.496784 2026] [security2:error] [pid 796567:tid 796776] [client 3.109.4.218:42900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OcrLfyzVz2SrjZpifEAAAAmM"]
[Mon Jul 20 06:02:58.569321 2026] [security2:error] [pid 796928:tid 797061] [client 46.110.96.34:26461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkAzAAAApw"]
[Mon Jul 20 06:02:58.569425 2026] [security2:error] [pid 796928:tid 797061] [client 46.110.96.34:26461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkAzAAAApw"]
[Mon Jul 20 06:02:58.658181 2026] [security2:error] [pid 796928:tid 797139] [client 46.110.96.34:26461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkA0AAAAuo"]
[Mon Jul 20 06:02:58.658300 2026] [security2:error] [pid 796928:tid 797139] [client 46.110.96.34:26461] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4OcusTy9vX-htKvPkA0AAAAuo"]
[Mon Jul 20 06:02:58.666836 2026] [security2:error] [pid 796928:tid 797162] [client 103.149.16.77:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkA0QAAAwE"]
[Mon Jul 20 06:02:58.666947 2026] [security2:error] [pid 796928:tid 797162] [client 103.149.16.77:60754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OcusTy9vX-htKvPkA0QAAAwE"]
[Mon Jul 20 06:02:58.703903 2026] [security2:error] [pid 796928:tid 797155] [client 57.141.18.105:35008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ObusTy9vX-htKvPn_xQAC-lY"]
[Mon Jul 20 06:02:58.876487 2026] [security2:error] [pid 796928:tid 797166] [client 103.87.138.44:60842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4OcusTy9vX-htKvPkA0gAAAwU"]
[Mon Jul 20 06:02:58.894958 2026] [security2:error] [pid 796928:tid 797184] [client 14.225.17.146:63866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4OcusTy9vX-htKvPkA1AAAAxc"], referer: https://myspineworld.com/wordpress
[Mon Jul 20 06:02:59.125085 2026] [security2:error] [pid 796928:tid 797143] [client 164.100.212.184:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA4gAAAu4"]
[Mon Jul 20 06:02:59.125189 2026] [security2:error] [pid 796928:tid 797143] [client 164.100.212.184:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA4gAAAu4"]
[Mon Jul 20 06:02:59.191306 2026] [security2:error] [pid 796928:tid 796971] [remote 51.158.61.221:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Oc-sTy9vX-htKvPkA5AACpCo"]
[Mon Jul 20 06:02:59.402978 2026] [security2:error] [pid 796928:tid 796935] [remote 51.158.61.221:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Oc-sTy9vX-htKvPkA9wAC-QY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:02:59.425811 2026] [security2:error] [pid 796928:tid 797064] [client 57.141.18.67:24142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ObusTy9vX-htKvPkAAgACn2Q"]
[Mon Jul 20 06:02:59.426387 2026] [security2:error] [pid 796928:tid 797094] [client 181.224.94.124:60581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA-QAAAr0"]
[Mon Jul 20 06:02:59.426558 2026] [security2:error] [pid 796928:tid 797094] [client 181.224.94.124:60581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Oc-sTy9vX-htKvPkA-QAAAr0"]
[Mon Jul 20 06:02:59.973249 2026] [security2:error] [pid 796928:tid 796969] [remote 47.86.33.52:24638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Oc-sTy9vX-htKvPkBCQAC9ig"]
[Mon Jul 20 06:03:00.058286 2026] [security2:error] [pid 796928:tid 796951] [remote 188.166.241.141:37666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBDAADDxY"]
[Mon Jul 20 06:03:00.068079 2026] [security2:error] [pid 796928:tid 797161] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4Oc-sTy9vX-htKvPkBAwADAAU"], referer: http://assasalnazaha.com/wordpress
[Mon Jul 20 06:03:00.143410 2026] [security2:error] [pid 796928:tid 797132] [client 3.67.192.83:61512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBDwAAAuM"]
[Mon Jul 20 06:03:00.166902 2026] [security2:error] [pid 796928:tid 797093] [client 129.222.187.209:3591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OdOsTy9vX-htKvPkBEAAAArw"]
[Mon Jul 20 06:03:00.172844 2026] [security2:error] [pid 796928:tid 797093] [client 129.222.187.209:3591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OdOsTy9vX-htKvPkBEAAAArw"]
[Mon Jul 20 06:03:00.314317 2026] [security2:error] [pid 796928:tid 797111] [client 185.132.186.73:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4OdOsTy9vX-htKvPkBFgAAAs4"]
[Mon Jul 20 06:03:00.456157 2026] [security2:error] [pid 796928:tid 796980] [remote 188.166.241.141:37666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBGAADETM"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 06:03:00.510223 2026] [security2:error] [pid 796567:tid 796579] [remote 47.86.33.52:33882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OdLLfyzVz2SrjZpifVAAChQs"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:03:00.714048 2026] [security2:error] [pid 796928:tid 797140] [client 63.176.132.15:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OdOsTy9vX-htKvPkBIgAAAus"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:03:00.765261 2026] [security2:error] [pid 796928:tid 797170] [client 14.225.17.146:65239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4Oc-sTy9vX-htKvPkA8gAAAwk"], referer: http://phillipbloch.com/wordpress
[Mon Jul 20 06:03:01.004583 2026] [security2:error] [pid 796928:tid 796978] [remote 47.86.33.52:24638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OdesTy9vX-htKvPkBMwAC2jE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:03:01.134188 2026] [security2:error] [pid 796567:tid 796748] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OdLLfyzVz2SrjZpifRwAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:01.442288 2026] [security2:error] [pid 796567:tid 796632] [remote 5.161.225.162:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OdbLfyzVz2SrjZpifdwACOEA"]
[Mon Jul 20 06:03:01.444394 2026] [security2:error] [pid 796928:tid 797131] [client 57.141.18.74:27718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OcOsTy9vX-htKvPkAcAAC4hU"]
[Mon Jul 20 06:03:01.621026 2026] [security2:error] [pid 796567:tid 796609] [remote 5.161.225.162:60940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4OdbLfyzVz2SrjZpiffgAChyk"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:03:01.718135 2026] [security2:error] [pid 796928:tid 797168] [client 14.225.17.146:51725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4OdesTy9vX-htKvPkBSgAAAwc"], referer: http://mtlegnews.gov/wordpress
[Mon Jul 20 06:03:01.731132 2026] [security2:error] [pid 796928:tid 796992] [remote 57.141.18.53:34148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2637480"] [unique_id "al4OdesTy9vX-htKvPkBUQADCz8"]
[Mon Jul 20 06:03:01.788745 2026] [security2:error] [pid 796567:tid 796719] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OdbLfyzVz2SrjZpifgwAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:02.132421 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OdesTy9vX-htKvPkBSQAAAqw"]
[Mon Jul 20 06:03:02.194363 2026] [security2:error] [pid 796928:tid 797133] [client 14.225.17.146:54514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4OdusTy9vX-htKvPkBWwAAAuQ"], referer: http://blaizeaccountingservices.com/wordpress
[Mon Jul 20 06:03:02.251435 2026] [security2:error] [pid 796928:tid 797171] [client 185.132.186.53:58817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "al4OdusTy9vX-htKvPkBaAAAAwo"]
[Mon Jul 20 06:03:02.313917 2026] [security2:error] [pid 796928:tid 797067] [client 112.213.160.112:8294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OdusTy9vX-htKvPkBaQAAAqI"]
[Mon Jul 20 06:03:02.314418 2026] [security2:error] [pid 796928:tid 797067] [client 112.213.160.112:8294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OdusTy9vX-htKvPkBaQAAAqI"]
[Mon Jul 20 06:03:02.444953 2026] [security2:error] [pid 796567:tid 796569] [remote 8.217.108.67:1478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4OdrLfyzVz2SrjZpifoQACkAE"]
[Mon Jul 20 06:03:02.555093 2026] [security2:error] [pid 796928:tid 797165] [client 50.116.65.227:16664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OdusTy9vX-htKvPkBeAAAAwQ"]
[Mon Jul 20 06:03:02.567336 2026] [security2:error] [pid 796928:tid 797122] [client 50.116.65.227:16674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OdusTy9vX-htKvPkBegAAAtk"]
[Mon Jul 20 06:03:02.681384 2026] [security2:error] [pid 796567:tid 796709] [client 27.96.94.195:37985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OdrLfyzVz2SrjZpifpQAAAiA"]
[Mon Jul 20 06:03:02.737478 2026] [security2:error] [pid 796567:tid 796640] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OdrLfyzVz2SrjZpifsQACXkg"]
[Mon Jul 20 06:03:02.737687 2026] [security2:error] [pid 796567:tid 796771] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OdrLfyzVz2SrjZpifsQACXkg"]
[Mon Jul 20 06:03:03.041916 2026] [security2:error] [pid 796928:tid 797092] [client 150.228.148.150:11741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBhwAAArs"]
[Mon Jul 20 06:03:03.057925 2026] [security2:error] [pid 796928:tid 797092] [client 150.228.148.150:11741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBhwAAArs"]
[Mon Jul 20 06:03:03.075651 2026] [security2:error] [pid 796567:tid 796776] [client 49.206.10.250:41016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.10.206.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/xmlrpc.php"] [unique_id "al4Od7LfyzVz2SrjZpifxQAAAmM"]
[Mon Jul 20 06:03:03.075810 2026] [security2:error] [pid 796567:tid 796776] [client 49.206.10.250:41016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "asliceofleadership.com"] [uri "/xmlrpc.php"] [unique_id "al4Od7LfyzVz2SrjZpifxQAAAmM"]
[Mon Jul 20 06:03:03.132653 2026] [security2:error] [pid 796567:tid 796797] [client 50.116.65.227:16688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OdrLfyzVz2SrjZpifugAAAng"]
[Mon Jul 20 06:03:03.274637 2026] [security2:error] [pid 796567:tid 796786] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OdrLfyzVz2SrjZpifsAAAAm0"]
[Mon Jul 20 06:03:03.325564 2026] [security2:error] [pid 796567:tid 796794] [client 50.116.65.227:16704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Od7LfyzVz2SrjZpifyQAAAnU"]
[Mon Jul 20 06:03:03.607891 2026] [security2:error] [pid 796567:tid 796642] [remote 47.128.25.171:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lelandmc.org"] [uri "/robots.txt"] [unique_id "al4Od7LfyzVz2SrjZpif2gACg0o"]
[Mon Jul 20 06:03:03.790343 2026] [security2:error] [pid 796928:tid 797071] [client 86.98.90.58:45755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBpAAAAqY"]
[Mon Jul 20 06:03:03.865504 2026] [security2:error] [pid 796928:tid 797071] [client 86.98.90.58:45755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Od-sTy9vX-htKvPkBpAAAAqY"]
[Mon Jul 20 06:03:03.885127 2026] [security2:error] [pid 796928:tid 797010] [remote 132.148.72.88:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4Od-sTy9vX-htKvPkBpQACrlE"]
[Mon Jul 20 06:03:04.038673 2026] [security2:error] [pid 796928:tid 797178] [client 94.154.43.179:25132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dwk.lce.mybluehost.me"] [uri "/.env"] [unique_id "al4OeOsTy9vX-htKvPkBqwAAAxE"]
[Mon Jul 20 06:03:04.045844 2026] [security2:error] [pid 796567:tid 796822] [client 94.154.43.187:31128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.dwk.lce.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4OeLLfyzVz2SrjZpif7QAAApE"]
[Mon Jul 20 06:03:04.050344 2026] [security2:error] [pid 796567:tid 796725] [client 94.154.43.185:42820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.dwk.lce.mybluehost.me"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4OeLLfyzVz2SrjZpif7gAAAjA"]
[Mon Jul 20 06:03:04.055800 2026] [security2:error] [pid 796928:tid 797174] [client 94.154.43.184:26640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.dwk.lce.mybluehost.me"] [uri "/.env"] [unique_id "al4OeOsTy9vX-htKvPkBrAAAAw0"]
[Mon Jul 20 06:03:04.176879 2026] [security2:error] [pid 796567:tid 796604] [remote 173.212.252.15:48884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OeLLfyzVz2SrjZpif9wACbiQ"]
[Mon Jul 20 06:03:04.177067 2026] [security2:error] [pid 796567:tid 796787] [client 173.212.252.15:48884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OeLLfyzVz2SrjZpif9wACbiQ"]
[Mon Jul 20 06:03:04.204954 2026] [security2:error] [pid 796928:tid 797166] [client 185.132.186.70:52659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/instaall.php"] [unique_id "al4OeOsTy9vX-htKvPkBuwAAAwU"]
[Mon Jul 20 06:03:04.233835 2026] [security2:error] [pid 796928:tid 797161] [client 50.116.65.227:16730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4OeOsTy9vX-htKvPkBvQAAAwA"]
[Mon Jul 20 06:03:04.234853 2026] [security2:error] [pid 796928:tid 797135] [client 50.116.65.227:16738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4OeOsTy9vX-htKvPkBvgAAAuY"]
[Mon Jul 20 06:03:04.246976 2026] [security2:error] [pid 796928:tid 797007] [remote 132.148.72.88:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4OeOsTy9vX-htKvPkBwAADA04"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:03:04.593315 2026] [security2:error] [pid 796567:tid 796778] [client 57.141.18.20:46504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oc7LfyzVz2SrjZpifMQACZWI"]
[Mon Jul 20 06:03:04.851894 2026] [security2:error] [pid 796928:tid 797133] [client 62.150.67.110:22945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4OeOsTy9vX-htKvPkB0gAAAuQ"]
[Mon Jul 20 06:03:05.065211 2026] [security2:error] [pid 796567:tid 796813] [client 47.31.86.100:56219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigGgAAAog"]
[Mon Jul 20 06:03:05.065895 2026] [security2:error] [pid 796567:tid 796813] [client 47.31.86.100:56219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigGgAAAog"]
[Mon Jul 20 06:03:05.412957 2026] [security2:error] [pid 796928:tid 797028] [remote 45.90.123.233:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4OeesTy9vX-htKvPkCAgACrWM"]
[Mon Jul 20 06:03:05.413282 2026] [security2:error] [pid 796928:tid 797132] [client 18.228.171.129:26980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCAQAAAuM"]
[Mon Jul 20 06:03:05.413362 2026] [security2:error] [pid 796928:tid 797132] [client 18.228.171.129:26980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCAQAAAuM"]
[Mon Jul 20 06:03:05.584885 2026] [security2:error] [pid 796928:tid 797100] [client 115.246.21.170:9909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCBwAAAsM"]
[Mon Jul 20 06:03:05.585005 2026] [security2:error] [pid 796928:tid 797100] [client 115.246.21.170:9909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCBwAAAsM"]
[Mon Jul 20 06:03:05.595958 2026] [security2:error] [pid 796567:tid 796622] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigLAACMjY"]
[Mon Jul 20 06:03:05.596120 2026] [security2:error] [pid 796567:tid 796727] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigLAACMjY"]
[Mon Jul 20 06:03:05.665978 2026] [security2:error] [pid 796928:tid 797032] [remote 45.90.123.233:37892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4OeesTy9vX-htKvPkCFQACpWc"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:03:05.685069 2026] [security2:error] [pid 796928:tid 797172] [client 106.192.104.4:48429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCFgAAAws"]
[Mon Jul 20 06:03:05.685308 2026] [security2:error] [pid 796928:tid 797172] [client 106.192.104.4:48429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OeesTy9vX-htKvPkCFgAAAws"]
[Mon Jul 20 06:03:05.862694 2026] [security2:error] [pid 796567:tid 796818] [client 72.255.10.154:2247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigNAAAAo0"]
[Mon Jul 20 06:03:05.862853 2026] [security2:error] [pid 796567:tid 796818] [client 72.255.10.154:2247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OebLfyzVz2SrjZpigNAAAAo0"]
[Mon Jul 20 06:03:06.147367 2026] [security2:error] [pid 796928:tid 797095] [client 185.132.186.84:21309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/function.php"] [unique_id "al4OeusTy9vX-htKvPkCLQAAAr4"]
[Mon Jul 20 06:03:06.290606 2026] [security2:error] [pid 796928:tid 797183] [client 57.141.18.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4OeesTy9vX-htKvPkCGwAAAxY"]
[Mon Jul 20 06:03:06.524813 2026] [security2:error] [pid 796567:tid 796749] [client 103.95.123.246:21337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OerLfyzVz2SrjZpigUQAAAkg"]
[Mon Jul 20 06:03:06.524970 2026] [security2:error] [pid 796567:tid 796749] [client 103.95.123.246:21337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OerLfyzVz2SrjZpigUQAAAkg"]
[Mon Jul 20 06:03:06.638911 2026] [security2:error] [pid 796567:tid 796807] [client 43.173.178.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OerLfyzVz2SrjZpigRgAAAoI"]
[Mon Jul 20 06:03:06.661314 2026] [security2:error] [pid 796928:tid 797156] [client 43.173.176.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OeusTy9vX-htKvPkCLgAAAvs"]
[Mon Jul 20 06:03:06.665288 2026] [security2:error] [pid 796567:tid 796728] [client 43.173.173.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OerLfyzVz2SrjZpigSQAAAjM"]
[Mon Jul 20 06:03:06.666964 2026] [security2:error] [pid 796928:tid 797084] [client 43.173.180.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OeusTy9vX-htKvPkCMAAAArM"]
[Mon Jul 20 06:03:06.667491 2026] [security2:error] [pid 796567:tid 796714] [client 43.173.178.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OerLfyzVz2SrjZpigRwAAAiU"]
[Mon Jul 20 06:03:06.879854 2026] [security2:error] [pid 796928:tid 797122] [client 14.225.17.146:59510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4OeOsTy9vX-htKvPkBuAAAAtk"], referer: http://talknutritionwithlesley.com/wordpress
[Mon Jul 20 06:03:07.002206 2026] [security2:error] [pid 796928:tid 797117] [client 43.173.181.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OeusTy9vX-htKvPkCOwAAAtQ"]
[Mon Jul 20 06:03:07.013928 2026] [security2:error] [pid 796928:tid 797041] [remote 188.166.241.141:37670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4Oe-sTy9vX-htKvPkCSAAC9HA"]
[Mon Jul 20 06:03:07.049086 2026] [security2:error] [pid 796928:tid 797038] [remote 57.141.18.29:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3562735"] [unique_id "al4Oe-sTy9vX-htKvPkCSQAC1m0"]
[Mon Jul 20 06:03:07.228757 2026] [security2:error] [pid 796928:tid 797143] [client 14.224.227.113:59548] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Oe-sTy9vX-htKvPkCUQAAAu4"]
[Mon Jul 20 06:03:07.387599 2026] [security2:error] [pid 796928:tid 797128] [client 129.222.187.209:59414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCWwAAAt8"]
[Mon Jul 20 06:03:07.402062 2026] [security2:error] [pid 796928:tid 797128] [client 129.222.187.209:59414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCWwAAAt8"]
[Mon Jul 20 06:03:07.447767 2026] [security2:error] [pid 796928:tid 797035] [remote 188.166.241.141:37670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4Oe-sTy9vX-htKvPkCXwACyGo"], referer: https://omrobuildingcenter.com/wp-login.php
[Mon Jul 20 06:03:07.719216 2026] [security2:error] [pid 796928:tid 797060] [client 41.173.37.102:8873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCegAAAps"]
[Mon Jul 20 06:03:07.719364 2026] [security2:error] [pid 796928:tid 797060] [client 41.173.37.102:8873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Oe-sTy9vX-htKvPkCegAAAps"]
[Mon Jul 20 06:03:08.091644 2026] [security2:error] [pid 796928:tid 797059] [client 185.132.186.76:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/plugins.php"] [unique_id "al4OfOsTy9vX-htKvPkClAAAApo"]
[Mon Jul 20 06:03:08.131118 2026] [security2:error] [pid 796567:tid 796704] [client 43.172.195.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe7LfyzVz2SrjZpigigAAAhs"]
[Mon Jul 20 06:03:08.208061 2026] [core:error] [pid 796928:tid 797164] [client 20.220.225.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:08.208085 2026] [core:error] [pid 796928:tid 797164] [client 20.220.225.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:08.208248 2026] [security2:error] [pid 796928:tid 797164] [client 20.220.225.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "coaching-certification.secoaches.co"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkCmwAAAwM"]
[Mon Jul 20 06:03:08.213680 2026] [security2:error] [pid 796928:tid 797096] [client 43.173.174.212:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCgQAAAr8"]
[Mon Jul 20 06:03:08.221331 2026] [security2:error] [pid 796567:tid 796749] [client 43.173.173.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe7LfyzVz2SrjZpigkgAAAkg"]
[Mon Jul 20 06:03:08.221364 2026] [security2:error] [pid 796928:tid 797092] [client 43.173.179.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCfAAAArs"]
[Mon Jul 20 06:03:08.234785 2026] [security2:error] [pid 796928:tid 797166] [client 43.173.179.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCfQAAAwU"]
[Mon Jul 20 06:03:08.324487 2026] [security2:error] [pid 796928:tid 797043] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OfOsTy9vX-htKvPkCrAAC7HI"]
[Mon Jul 20 06:03:08.324667 2026] [security2:error] [pid 796928:tid 797141] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OfOsTy9vX-htKvPkCrAAC7HI"]
[Mon Jul 20 06:03:08.607085 2026] [security2:error] [pid 796928:tid 797079] [client 43.172.196.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkCowAAAq4"]
[Mon Jul 20 06:03:08.672115 2026] [security2:error] [pid 796567:tid 796726] [client 210.212.97.243:10430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OfLLfyzVz2SrjZpigtwAAAjE"]
[Mon Jul 20 06:03:08.672320 2026] [security2:error] [pid 796567:tid 796726] [client 210.212.97.243:10430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OfLLfyzVz2SrjZpigtwAAAjE"]
[Mon Jul 20 06:03:08.791178 2026] [security2:error] [pid 796567:tid 796820] [client 45.157.112.60:33761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OfLLfyzVz2SrjZpigvgAAAo8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:08.824149 2026] [security2:error] [pid 796928:tid 797083] [client 158.173.89.95:59235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OfOsTy9vX-htKvPkCuwAAArI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:09.238701 2026] [security2:error] [pid 796567:tid 796817] [client 57.141.18.42:23830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Od7LfyzVz2SrjZpif5QACjEc"]
[Mon Jul 20 06:03:09.258470 2026] [security2:error] [pid 796928:tid 797086] [client 94.154.43.188:53132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jhavoctattoos-com.grndl.com"] [uri "/.env"] [unique_id "al4OfesTy9vX-htKvPkC1AAAArU"]
[Mon Jul 20 06:03:09.305906 2026] [security2:error] [pid 796928:tid 797175] [client 94.154.43.185:57988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.jhavoctattoos.com"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al4OfesTy9vX-htKvPkC1gAAAw4"]
[Mon Jul 20 06:03:09.324240 2026] [security2:error] [pid 796928:tid 797140] [client 14.176.244.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkChQAAAus"]
[Mon Jul 20 06:03:09.325501 2026] [security2:error] [pid 796567:tid 796765] [client 94.154.43.188:53142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.jhavoctattoos.com"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4OfbLfyzVz2SrjZpig5QAAAlg"]
[Mon Jul 20 06:03:09.336621 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC2QAAAxg"]
[Mon Jul 20 06:03:09.336766 2026] [security2:error] [pid 796928:tid 797185] [client 103.149.16.77:61247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC2QAAAxg"]
[Mon Jul 20 06:03:09.342086 2026] [security2:error] [pid 796928:tid 797141] [client 94.154.43.229:48622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.jhavoctattoos.com"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4OfesTy9vX-htKvPkC2gAAAuw"]
[Mon Jul 20 06:03:09.411924 2026] [security2:error] [pid 796928:tid 797146] [client 14.225.17.146:55589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkClgAAAvE"], referer: http://dnsplumbing.com/wordpress
[Mon Jul 20 06:03:09.551847 2026] [security2:error] [pid 796928:tid 797073] [client 13.201.64.214:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC5AAAAqg"]
[Mon Jul 20 06:03:09.551991 2026] [security2:error] [pid 796928:tid 797073] [client 13.201.64.214:64974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC5AAAAqg"]
[Mon Jul 20 06:03:09.723807 2026] [security2:error] [pid 796928:tid 797107] [client 164.100.212.184:52450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC7wAAAso"]
[Mon Jul 20 06:03:09.723921 2026] [security2:error] [pid 796928:tid 797107] [client 164.100.212.184:52450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkC7wAAAso"]
[Mon Jul 20 06:03:09.728709 2026] [security2:error] [pid 796567:tid 796611] [remote 57.141.18.47:50636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5370396"] [unique_id "al4OfbLfyzVz2SrjZpig-wACGCs"]
[Mon Jul 20 06:03:09.818816 2026] [security2:error] [pid 796567:tid 796735] [client 94.154.43.183:57760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.jhavoctattoos.com"] [uri "/.env"] [unique_id "al4OfbLfyzVz2SrjZpihBQAAAjo"]
[Mon Jul 20 06:03:09.872673 2026] [security2:error] [pid 796567:tid 796727] [client 82.102.18.182:41306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "al4OfbLfyzVz2SrjZpihCQAAAjI"]
[Mon Jul 20 06:03:09.900049 2026] [security2:error] [pid 796928:tid 797056] [remote 124.55.178.99:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OfesTy9vX-htKvPkC-wAC4n8"]
[Mon Jul 20 06:03:09.982971 2026] [security2:error] [pid 796928:tid 797156] [client 181.224.94.124:17490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkDAAAAAvs"]
[Mon Jul 20 06:03:09.983130 2026] [security2:error] [pid 796928:tid 797156] [client 181.224.94.124:17490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfesTy9vX-htKvPkDAAAAAvs"]
[Mon Jul 20 06:03:09.999364 2026] [security2:error] [pid 796567:tid 796808] [client 94.154.43.188:53150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jhavoctattoos.com"] [uri "/.env"] [unique_id "al4OfbLfyzVz2SrjZpihEQAAAoM"]
[Mon Jul 20 06:03:10.011909 2026] [security2:error] [pid 796567:tid 796753] [client 185.132.186.82:26797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/atomlib.php"] [unique_id "al4OfrLfyzVz2SrjZpihEwAAAkw"]
[Mon Jul 20 06:03:10.207664 2026] [security2:error] [pid 796567:tid 796759] [client 43.172.194.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfbLfyzVz2SrjZpihCAAAAlI"]
[Mon Jul 20 06:03:10.265494 2026] [security2:error] [pid 796928:tid 797066] [client 43.173.180.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfesTy9vX-htKvPkC-gAAAqE"]
[Mon Jul 20 06:03:10.293574 2026] [security2:error] [pid 796567:tid 796783] [client 43.172.195.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfbLfyzVz2SrjZpihDwAAAmo"]
[Mon Jul 20 06:03:10.318394 2026] [security2:error] [pid 796928:tid 796930] [remote 124.55.178.99:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OfusTy9vX-htKvPkDCQAC6QE"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:03:10.333674 2026] [security2:error] [pid 796928:tid 797116] [client 43.173.182.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfesTy9vX-htKvPkC_wAAAtM"]
[Mon Jul 20 06:03:10.432924 2026] [security2:error] [pid 796567:tid 796763] [client 57.141.18.61:40152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OebLfyzVz2SrjZpigIgACVjM"]
[Mon Jul 20 06:03:10.547915 2026] [security2:error] [pid 796928:tid 797093] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4Oe-sTy9vX-htKvPkCjwAAArw"]
[Mon Jul 20 06:03:10.760784 2026] [security2:error] [pid 796567:tid 796765] [client 129.222.187.209:38341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfrLfyzVz2SrjZpihPwAAAlg"]
[Mon Jul 20 06:03:10.761388 2026] [security2:error] [pid 796928:tid 797068] [client 43.172.198.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfusTy9vX-htKvPkDCwAAAqM"]
[Mon Jul 20 06:03:10.765520 2026] [security2:error] [pid 796567:tid 796765] [client 129.222.187.209:38341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OfrLfyzVz2SrjZpihPwAAAlg"]
[Mon Jul 20 06:03:11.174950 2026] [security2:error] [pid 796928:tid 797131] [client 82.102.18.182:55353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Of-sTy9vX-htKvPkDNQAAAuI"]
[Mon Jul 20 06:03:11.344054 2026] [security2:error] [pid 796567:tid 796749] [client 43.172.194.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OfrLfyzVz2SrjZpihTwAAAkg"]
[Mon Jul 20 06:03:11.451777 2026] [security2:error] [pid 796928:tid 797083] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Of-sTy9vX-htKvPkDOwAAArI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:11.531104 2026] [security2:error] [pid 796928:tid 797142] [client 94.154.43.179:27382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sun.xdu.mybluehost.me"] [uri "/.env"] [unique_id "al4Of-sTy9vX-htKvPkDSQAAAu0"]
[Mon Jul 20 06:03:11.612551 2026] [security2:error] [pid 796567:tid 796675] [remote 8.217.108.67:3670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4Of7LfyzVz2SrjZpihZgACYGs"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:03:11.619233 2026] [security2:error] [pid 796928:tid 797177] [client 94.154.43.186:62686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.sun.xdu.mybluehost.me"] [uri "/.env"] [unique_id "al4Of-sTy9vX-htKvPkDTAAAAxA"]
[Mon Jul 20 06:03:11.811182 2026] [security2:error] [pid 796928:tid 797135] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Of-sTy9vX-htKvPkDTQAAAuY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:11.851777 2026] [security2:error] [pid 796928:tid 797122] [client 82.102.18.182:41338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Of-sTy9vX-htKvPkDWQAAAtk"]
[Mon Jul 20 06:03:11.891949 2026] [security2:error] [pid 796567:tid 796787] [client 50.116.65.227:49622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Of7LfyzVz2SrjZpihcAAAAm4"]
[Mon Jul 20 06:03:11.905086 2026] [security2:error] [pid 796567:tid 796811] [client 50.116.65.227:49628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Of7LfyzVz2SrjZpihcQAAAoY"]
[Mon Jul 20 06:03:11.921179 2026] [security2:error] [pid 796928:tid 797144] [client 185.132.186.55:20783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content.php"] [unique_id "al4Of-sTy9vX-htKvPkDWgAAAu8"]
[Mon Jul 20 06:03:12.484976 2026] [security2:error] [pid 796928:tid 797105] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OgOsTy9vX-htKvPkDcAAAAsg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:12.509633 2026] [security2:error] [pid 796928:tid 797121] [client 82.102.18.182:41344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4OgOsTy9vX-htKvPkDfgAAAtg"]
[Mon Jul 20 06:03:12.610293 2026] [security2:error] [pid 796928:tid 797095] [client 14.225.17.146:64425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4Of-sTy9vX-htKvPkDVwAAAr4"], referer: http://processorstudio.com/wordpress
[Mon Jul 20 06:03:12.742732 2026] [security2:error] [pid 796928:tid 797094] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OgOsTy9vX-htKvPkDiwAAAr0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:12.955721 2026] [security2:error] [pid 796928:tid 797173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OgOsTy9vX-htKvPkDjQAAAww"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:12.979523 2026] [security2:error] [pid 796928:tid 797185] [client 112.213.160.112:8295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OgOsTy9vX-htKvPkDlQAAAxg"]
[Mon Jul 20 06:03:12.979645 2026] [security2:error] [pid 796928:tid 797185] [client 112.213.160.112:8295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OgOsTy9vX-htKvPkDlQAAAxg"]
[Mon Jul 20 06:03:13.177967 2026] [security2:error] [pid 796928:tid 797148] [client 82.102.18.182:41348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "al4OgesTy9vX-htKvPkDpAAAAvM"]
[Mon Jul 20 06:03:13.183569 2026] [security2:error] [pid 796928:tid 797164] [client 27.96.94.195:38211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDmAAAAwM"]
[Mon Jul 20 06:03:13.222920 2026] [security2:error] [pid 796567:tid 796755] [client 158.173.166.181:36781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OgbLfyzVz2SrjZpihlwAAAk4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:13.269434 2026] [security2:error] [pid 796928:tid 797167] [client 14.225.17.146:56365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4OfusTy9vX-htKvPkDAQAAAwY"], referer: http://vinovinhowine.com/wordpress
[Mon Jul 20 06:03:13.325294 2026] [security2:error] [pid 796928:tid 797015] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDrAACrlY"]
[Mon Jul 20 06:03:13.325454 2026] [security2:error] [pid 796928:tid 797079] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDrAACrlY"]
[Mon Jul 20 06:03:13.554851 2026] [security2:error] [pid 796928:tid 797141] [client 86.98.90.58:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDugAAAuw"]
[Mon Jul 20 06:03:13.554965 2026] [security2:error] [pid 796928:tid 797141] [client 86.98.90.58:46484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OgesTy9vX-htKvPkDugAAAuw"]
[Mon Jul 20 06:03:13.580397 2026] [security2:error] [pid 796928:tid 797149] [client 14.225.17.146:50798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4OgesTy9vX-htKvPkDuAAAAvQ"], referer: https://processorstudio.com/wordpress
[Mon Jul 20 06:03:13.666966 2026] [security2:error] [pid 796567:tid 796732] [client 150.228.148.150:55521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OgbLfyzVz2SrjZpihpQAAAjc"]
[Mon Jul 20 06:03:13.667063 2026] [security2:error] [pid 796567:tid 796732] [client 150.228.148.150:55521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OgbLfyzVz2SrjZpihpQAAAjc"]
[Mon Jul 20 06:03:13.806570 2026] [security2:error] [pid 796567:tid 796770] [client 82.102.18.182:59349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4OgbLfyzVz2SrjZpihqgAAAl0"]
[Mon Jul 20 06:03:13.870055 2026] [security2:error] [pid 796928:tid 797079] [client 185.132.186.56:36313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/chosen.php"] [unique_id "al4OgesTy9vX-htKvPkD1AAAAq4"]
[Mon Jul 20 06:03:13.932892 2026] [security2:error] [pid 796567:tid 796785] [client 77.110.127.138:54727] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OgbLfyzVz2SrjZpihrAAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:14.042295 2026] [security2:error] [pid 796928:tid 797094] [client 74.208.214.194:59732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OgusTy9vX-htKvPkD3AAAAr0"]
[Mon Jul 20 06:03:14.045206 2026] [security2:error] [pid 796928:tid 797061] [client 57.141.18.76:31316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OfOsTy9vX-htKvPkCtgACnEo"]
[Mon Jul 20 06:03:14.125511 2026] [security2:error] [pid 796928:tid 797120] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OgusTy9vX-htKvPkD3wAAAtc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:14.164527 2026] [security2:error] [pid 796928:tid 796966] [remote 216.73.216.55:53420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4OgusTy9vX-htKvPkD5QACsSU"]
[Mon Jul 20 06:03:14.441938 2026] [security2:error] [pid 796928:tid 797153] [client 82.102.18.182:41368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "al4OgusTy9vX-htKvPkD6gAAAvg"]
[Mon Jul 20 06:03:14.616692 2026] [core:error] [pid 796928:tid 797160] [client 93.159.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:14.616724 2026] [core:error] [pid 796928:tid 797160] [client 93.159.230.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:14.850041 2026] [security2:error] [pid 796567:tid 796747] [client 57.141.18.108:43966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OfbLfyzVz2SrjZpig7wACRhg"]
[Mon Jul 20 06:03:14.957656 2026] [security2:error] [pid 796567:tid 796627] [remote 173.212.252.15:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OgrLfyzVz2SrjZpih0QACYjs"]
[Mon Jul 20 06:03:15.115199 2026] [security2:error] [pid 796928:tid 797177] [client 82.102.18.182:41370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4Og-sTy9vX-htKvPkEBwAAAxA"]
[Mon Jul 20 06:03:15.248121 2026] [security2:error] [pid 796567:tid 796640] [remote 173.212.252.15:45164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Og7LfyzVz2SrjZpih3gACTEg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:03:15.391248 2026] [security2:error] [pid 796928:tid 797150] [client 47.31.86.100:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Og-sTy9vX-htKvPkEFgAAAvU"]
[Mon Jul 20 06:03:15.391406 2026] [security2:error] [pid 796928:tid 797150] [client 47.31.86.100:56679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Og-sTy9vX-htKvPkEFgAAAvU"]
[Mon Jul 20 06:03:15.742542 2026] [security2:error] [pid 796928:tid 797152] [client 82.102.18.182:31860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Og-sTy9vX-htKvPkEKQAAAvc"]
[Mon Jul 20 06:03:15.820026 2026] [security2:error] [pid 796928:tid 797098] [client 185.132.186.80:32543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Renderer/about.php"] [unique_id "al4Og-sTy9vX-htKvPkELAAAAsE"]
[Mon Jul 20 06:03:16.068138 2026] [security2:error] [pid 796567:tid 796584] [remote 188.166.241.141:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OhLLfyzVz2SrjZpih_gACehA"]
[Mon Jul 20 06:03:16.084297 2026] [security2:error] [pid 796567:tid 796773] [client 15.229.42.239:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpih_QAAAmA"]
[Mon Jul 20 06:03:16.084411 2026] [security2:error] [pid 796567:tid 796773] [client 15.229.42.239:61276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpih_QAAAmA"]
[Mon Jul 20 06:03:16.124604 2026] [security2:error] [pid 796567:tid 796796] [client 57.141.18.58:58054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OfrLfyzVz2SrjZpihNgACdyI"]
[Mon Jul 20 06:03:16.245719 2026] [security2:error] [pid 796567:tid 796597] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpiiBwACFR0"]
[Mon Jul 20 06:03:16.245889 2026] [security2:error] [pid 796567:tid 796698] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OhLLfyzVz2SrjZpiiBwACFR0"]
[Mon Jul 20 06:03:16.262176 2026] [security2:error] [pid 796928:tid 797139] [client 115.246.21.170:28828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OhOsTy9vX-htKvPkEPwAAAuo"]
[Mon Jul 20 06:03:16.262274 2026] [security2:error] [pid 796928:tid 797139] [client 115.246.21.170:28828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OhOsTy9vX-htKvPkEPwAAAuo"]
[Mon Jul 20 06:03:16.319729 2026] [security2:error] [pid 796567:tid 796809] [client 14.225.17.146:59225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4Og7LfyzVz2SrjZpih-AAAAoQ"], referer: http://backandneckpainrelieflaceychiropractor.com/wordpress
[Mon Jul 20 06:03:16.326969 2026] [security2:error] [pid 796928:tid 796932] [remote 188.40.28.4:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4OhOsTy9vX-htKvPkERQADBQM"]
[Mon Jul 20 06:03:16.414363 2026] [security2:error] [pid 796567:tid 796811] [client 82.102.18.182:41396] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4OhLLfyzVz2SrjZpiiEQAAAoY"]
[Mon Jul 20 06:03:16.474450 2026] [security2:error] [pid 796567:tid 796572] [remote 188.166.241.141:34910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OhLLfyzVz2SrjZpiiEgACeQQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:03:16.535198 2026] [security2:error] [pid 796928:tid 796984] [remote 188.40.28.4:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4OhOsTy9vX-htKvPkESAAC4zc"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:03:16.619681 2026] [security2:error] [pid 796928:tid 797058] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OhOsTy9vX-htKvPkESQAAApk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:16.948202 2026] [security2:error] [pid 796567:tid 796734] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OhLLfyzVz2SrjZpiiLQAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:17.085757 2026] [security2:error] [pid 796567:tid 796762] [client 82.102.18.182:9982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4OhbLfyzVz2SrjZpiiMQAAAlU"]
[Mon Jul 20 06:03:17.217210 2026] [security2:error] [pid 796567:tid 796662] [remote 182.77.62.24:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4OhbLfyzVz2SrjZpiiNgACKl4"]
[Mon Jul 20 06:03:17.231621 2026] [security2:error] [pid 796928:tid 797181] [client 14.225.17.146:59208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4Og-sTy9vX-htKvPkELwAAAxQ"], referer: http://partnerselectricalllc.com/wordpress
[Mon Jul 20 06:03:17.421024 2026] [security2:error] [pid 796928:tid 797131] [client 103.95.123.246:17963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OhesTy9vX-htKvPkEYAAAAuI"]
[Mon Jul 20 06:03:17.421156 2026] [security2:error] [pid 796928:tid 797131] [client 103.95.123.246:17963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OhesTy9vX-htKvPkEYAAAAuI"]
[Mon Jul 20 06:03:17.679562 2026] [security2:error] [pid 796567:tid 796810] [client 106.192.104.4:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OhbLfyzVz2SrjZpiiRQAAAoU"]
[Mon Jul 20 06:03:17.679695 2026] [security2:error] [pid 796567:tid 796810] [client 106.192.104.4:55473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OhbLfyzVz2SrjZpiiRQAAAoU"]
[Mon Jul 20 06:03:17.761074 2026] [security2:error] [pid 796928:tid 797115] [client 82.102.18.182:48540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4OhesTy9vX-htKvPkEcgAAAtI"]
[Mon Jul 20 06:03:17.817019 2026] [security2:error] [pid 796928:tid 797070] [client 57.141.18.112:28244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OgOsTy9vX-htKvPkDaQACpRQ"]
[Mon Jul 20 06:03:18.001992 2026] [security2:error] [pid 796928:tid 797133] [client 178.152.178.232:37190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEewAAAuQ"]
[Mon Jul 20 06:03:18.002144 2026] [security2:error] [pid 796928:tid 797133] [client 178.152.178.232:37190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEewAAAuQ"]
[Mon Jul 20 06:03:18.041260 2026] [security2:error] [pid 796928:tid 797140] [client 185.132.186.86:33267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/index.php"] [unique_id "al4OhusTy9vX-htKvPkEfQAAAus"]
[Mon Jul 20 06:03:18.255336 2026] [security2:error] [pid 796928:tid 797068] [client 41.173.37.102:9289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEiQAAAqM"]
[Mon Jul 20 06:03:18.255494 2026] [security2:error] [pid 796928:tid 797068] [client 41.173.37.102:9289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEiQAAAqM"]
[Mon Jul 20 06:03:18.310554 2026] [security2:error] [pid 796928:tid 797121] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OhusTy9vX-htKvPkEhwAAAtg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:18.339931 2026] [security2:error] [pid 796567:tid 796765] [client 14.225.17.146:59989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4OhLLfyzVz2SrjZpiiKAAAAlg"], referer: http://slutilities.com/wordpress
[Mon Jul 20 06:03:18.397780 2026] [security2:error] [pid 796928:tid 797141] [client 82.102.18.182:48542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "al4OhusTy9vX-htKvPkEkgAAAuw"]
[Mon Jul 20 06:03:18.448777 2026] [security2:error] [pid 796567:tid 796668] [remote 182.77.62.24:34014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4OhrLfyzVz2SrjZpiiXAACLmQ"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:03:18.913971 2026] [security2:error] [pid 796928:tid 796967] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEqgAC-SY"]
[Mon Jul 20 06:03:18.914147 2026] [security2:error] [pid 796928:tid 797154] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OhusTy9vX-htKvPkEqgAC-SY"]
[Mon Jul 20 06:03:19.018605 2026] [security2:error] [pid 796928:tid 797155] [client 14.225.17.146:50152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4OhusTy9vX-htKvPkEpAAAAvo"], referer: http://thesoloceos.com/wordpress
[Mon Jul 20 06:03:19.060875 2026] [security2:error] [pid 796928:tid 797132] [client 82.102.18.182:48546] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4Oh-sTy9vX-htKvPkEtAAAAuM"]
[Mon Jul 20 06:03:19.170028 2026] [security2:error] [pid 796928:tid 797108] [client 210.212.97.243:10431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Oh-sTy9vX-htKvPkEtgAAAss"]
[Mon Jul 20 06:03:19.170172 2026] [security2:error] [pid 796928:tid 797108] [client 210.212.97.243:10431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Oh-sTy9vX-htKvPkEtgAAAss"]
[Mon Jul 20 06:03:19.179919 2026] [security2:error] [pid 796928:tid 797061] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Oh-sTy9vX-htKvPkEtQAAApw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:19.621283 2026] [security2:error] [pid 796567:tid 796709] [client 216.73.216.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.mollycahill.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiifwAAAiA"]
[Mon Jul 20 06:03:19.747159 2026] [security2:error] [pid 796567:tid 796718] [client 82.102.18.182:35907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Oh7LfyzVz2SrjZpiihgAAAik"]
[Mon Jul 20 06:03:19.861166 2026] [security2:error] [pid 796567:tid 796737] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4Oh7LfyzVz2SrjZpiiiwAAAjw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:19.952559 2026] [security2:error] [pid 796928:tid 797092] [client 52.109.44.112:9477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Oh-sTy9vX-htKvPkE2AAAArs"]
[Mon Jul 20 06:03:19.984687 2026] [security2:error] [pid 796567:tid 796776] [client 185.132.186.95:58541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/about.php"] [unique_id "al4Oh7LfyzVz2SrjZpiikgAAAmM"]
[Mon Jul 20 06:03:20.029077 2026] [security2:error] [pid 796567:tid 796808] [client 14.225.17.146:53969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiijAAAAoM"], referer: https://thesoloceos.com/wordpress
[Mon Jul 20 06:03:20.090246 2026] [security2:error] [pid 796928:tid 797181] [client 52.109.44.112:9477] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OiOsTy9vX-htKvPkE3gAAAxQ"]
[Mon Jul 20 06:03:20.219405 2026] [security2:error] [pid 796567:tid 796801] [client 103.149.16.77:61745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiioQAAAnw"]
[Mon Jul 20 06:03:20.219584 2026] [security2:error] [pid 796567:tid 796801] [client 103.149.16.77:61745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiioQAAAnw"]
[Mon Jul 20 06:03:20.261633 2026] [security2:error] [pid 796928:tid 797089] [client 164.100.212.184:53015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE4gAAArg"]
[Mon Jul 20 06:03:20.261758 2026] [security2:error] [pid 796928:tid 797089] [client 164.100.212.184:53015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE4gAAArg"]
[Mon Jul 20 06:03:20.381635 2026] [security2:error] [pid 796567:tid 796736] [client 65.1.132.125:27108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiiqwAAAjs"]
[Mon Jul 20 06:03:20.381731 2026] [security2:error] [pid 796567:tid 796736] [client 65.1.132.125:27108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OiLLfyzVz2SrjZpiiqwAAAjs"]
[Mon Jul 20 06:03:20.384702 2026] [security2:error] [pid 796928:tid 797137] [client 82.102.18.182:48568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4OiOsTy9vX-htKvPkE6QAAAug"]
[Mon Jul 20 06:03:20.423530 2026] [security2:error] [pid 796928:tid 797148] [client 52.111.227.28:4801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4OiOsTy9vX-htKvPkE6wAAAvM"]
[Mon Jul 20 06:03:20.476440 2026] [security2:error] [pid 796928:tid 797112] [client 52.111.227.28:4801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4OiOsTy9vX-htKvPkE7wAAAs8"]
[Mon Jul 20 06:03:20.572029 2026] [security2:error] [pid 796928:tid 797125] [client 181.224.94.124:20937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE9AAAAtw"]
[Mon Jul 20 06:03:20.572168 2026] [security2:error] [pid 796928:tid 797125] [client 181.224.94.124:20937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiOsTy9vX-htKvPkE9AAAAtw"]
[Mon Jul 20 06:03:20.650662 2026] [security2:error] [pid 796928:tid 797097] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiOsTy9vX-htKvPkE5wAAAsA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:20.689967 2026] [security2:error] [pid 796928:tid 797178] [client 50.116.65.227:41966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OiOsTy9vX-htKvPkE-QAAAxE"]
[Mon Jul 20 06:03:20.699525 2026] [security2:error] [pid 796928:tid 797180] [client 50.116.65.227:41984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OiOsTy9vX-htKvPkE_AAAAxM"]
[Mon Jul 20 06:03:20.939391 2026] [security2:error] [pid 796928:tid 797087] [client 57.141.18.100:61980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Og-sTy9vX-htKvPkEDAACtjI"]
[Mon Jul 20 06:03:20.957007 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiOsTy9vX-htKvPkFAgAAAtg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:21.008688 2026] [security2:error] [pid 796928:tid 797126] [client 82.102.18.182:48582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.varmath.com"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4OiesTy9vX-htKvPkFCwAAAt0"]
[Mon Jul 20 06:03:21.354208 2026] [security2:error] [pid 796928:tid 797092] [client 72.255.10.154:26242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFEwAAArs"]
[Mon Jul 20 06:03:21.354345 2026] [security2:error] [pid 796928:tid 797092] [client 72.255.10.154:26242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFEwAAArs"]
[Mon Jul 20 06:03:21.435844 2026] [security2:error] [pid 796928:tid 797023] [remote 40.77.167.28:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4OiesTy9vX-htKvPkFFwADCV4"]
[Mon Jul 20 06:03:21.490894 2026] [security2:error] [pid 796928:tid 797151] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OiesTy9vX-htKvPkFGAAAAvY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:21.529924 2026] [security2:error] [pid 796928:tid 797162] [client 129.222.187.209:50079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHQAAAwE"]
[Mon Jul 20 06:03:21.530071 2026] [security2:error] [pid 796928:tid 797162] [client 129.222.187.209:50079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHQAAAwE"]
[Mon Jul 20 06:03:21.588109 2026] [security2:error] [pid 796928:tid 797134] [client 129.222.187.209:45284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHgAAAuU"]
[Mon Jul 20 06:03:21.603516 2026] [security2:error] [pid 796928:tid 797134] [client 129.222.187.209:45284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OiesTy9vX-htKvPkFHgAAAuU"]
[Mon Jul 20 06:03:21.651567 2026] [security2:error] [pid 796567:tid 796733] [client 14.225.17.146:53962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiiigAAAjg"], referer: http://swafforddetailing.com/wordpress
[Mon Jul 20 06:03:21.737660 2026] [security2:error] [pid 796928:tid 797026] [remote 42.200.84.61:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OiesTy9vX-htKvPkFIwADD2E"]
[Mon Jul 20 06:03:21.944404 2026] [security2:error] [pid 796928:tid 797079] [client 185.132.186.63:55155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/customize.php"] [unique_id "al4OiesTy9vX-htKvPkFMAAAAq4"]
[Mon Jul 20 06:03:22.005316 2026] [security2:error] [pid 796928:tid 797169] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OiesTy9vX-htKvPkFLwAAAwg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:22.043211 2026] [security2:error] [pid 796567:tid 796603] [remote 173.249.4.11:24742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4OirLfyzVz2SrjZpii5gACZyM"]
[Mon Jul 20 06:03:22.067287 2026] [security2:error] [pid 796928:tid 797171] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiesTy9vX-htKvPkFKAAAAwo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:22.100010 2026] [security2:error] [pid 796928:tid 797022] [remote 42.200.84.61:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OiusTy9vX-htKvPkFOgACy10"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:03:22.232218 2026] [security2:error] [pid 796928:tid 797105] [client 14.182.195.220:51964] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OiusTy9vX-htKvPkFPwAAAsg"]
[Mon Jul 20 06:03:22.296769 2026] [security2:error] [pid 796928:tid 797009] [remote 130.185.118.215:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OiusTy9vX-htKvPkFRQACvFA"]
[Mon Jul 20 06:03:22.403511 2026] [security2:error] [pid 796567:tid 796728] [client 57.141.18.29:37344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OhLLfyzVz2SrjZpiiGgACMzM"]
[Mon Jul 20 06:03:22.480336 2026] [security2:error] [pid 796928:tid 797005] [remote 130.185.118.215:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4OiusTy9vX-htKvPkFSgACz0w"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 06:03:22.578471 2026] [security2:error] [pid 796928:tid 797035] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4OiusTy9vX-htKvPkFUwACymo"]
[Mon Jul 20 06:03:22.578630 2026] [security2:error] [pid 796928:tid 797035] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.aws/credentials"] [unique_id "al4OiusTy9vX-htKvPkFVgACymo"]
[Mon Jul 20 06:03:22.578646 2026] [security2:error] [pid 796928:tid 797107] [client 34.101.165.107:50324] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jenfarley.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4OiusTy9vX-htKvPkFUwACymo"]
[Mon Jul 20 06:03:22.614233 2026] [security2:error] [pid 796567:tid 796775] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpii8QAAAmI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:22.701707 2026] [security2:error] [pid 796567:tid 796583] [remote 173.249.4.11:24742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4OirLfyzVz2SrjZpijBwACbQ8"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 06:03:22.831964 2026] [security2:error] [pid 796928:tid 797167] [client 57.141.18.30:48660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OhesTy9vX-htKvPkEVQADBiA"]
[Mon Jul 20 06:03:22.881874 2026] [security2:error] [pid 796928:tid 797172] [client 98.94.182.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFZwADC3Y"]
[Mon Jul 20 06:03:23.084430 2026] [security2:error] [pid 796567:tid 796761] [client 74.7.227.179:45974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijFAACVE0"], referer: https://tejasenvironmental.com/p=247175
[Mon Jul 20 06:03:23.124028 2026] [security2:error] [pid 796567:tid 796738] [client 77.110.127.138:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4Oi7LfyzVz2SrjZpijJQAAAj0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:23.184564 2026] [security2:error] [pid 796567:tid 796773] [client 220.181.108.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijDQAAAmA"]
[Mon Jul 20 06:03:23.209159 2026] [security2:error] [pid 796928:tid 797091] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFcAAAAro"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:23.328518 2026] [security2:error] [pid 796928:tid 797053] [remote 72.167.132.114:44736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Oi-sTy9vX-htKvPkFfwAC2Hw"]
[Mon Jul 20 06:03:23.328835 2026] [security2:error] [pid 796928:tid 797121] [client 72.167.132.114:44736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Oi-sTy9vX-htKvPkFfwAC2Hw"]
[Mon Jul 20 06:03:23.335025 2026] [security2:error] [pid 796928:tid 797050] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.env.example"] [unique_id "al4Oi-sTy9vX-htKvPkFgAACynk"]
[Mon Jul 20 06:03:23.335196 2026] [security2:error] [pid 796928:tid 797107] [client 34.101.165.107:50324] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jenfarley.com"] [uri "/.env.example"] [unique_id "al4Oi-sTy9vX-htKvPkFgAACynk"]
[Mon Jul 20 06:03:23.336952 2026] [security2:error] [pid 796928:tid 797054] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env"] [unique_id "al4Oi-sTy9vX-htKvPkFgQACyn0"]
[Mon Jul 20 06:03:23.455215 2026] [security2:error] [pid 796567:tid 796633] [remote 160.187.68.132:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Oi7LfyzVz2SrjZpijLQACJUE"]
[Mon Jul 20 06:03:23.511360 2026] [core:error] [pid 796928:tid 797080] [client 14.225.17.146:59058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wordpress
[Mon Jul 20 06:03:23.511390 2026] [core:error] [pid 796928:tid 797080] [client 14.225.17.146:59058] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wordpress
[Mon Jul 20 06:03:23.648286 2026] [security2:error] [pid 796567:tid 796818] [client 14.225.17.146:58869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijKwAAAo0"], referer: http://taskidsvirginia.com/wordpress
[Mon Jul 20 06:03:23.726321 2026] [security2:error] [pid 796567:tid 796752] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijMwAAAks"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:23.744948 2026] [security2:error] [pid 796567:tid 796712] [client 112.213.160.112:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oi7LfyzVz2SrjZpijPAAAAiM"]
[Mon Jul 20 06:03:23.745113 2026] [security2:error] [pid 796567:tid 796712] [client 112.213.160.112:8646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Oi7LfyzVz2SrjZpijPAAAAiM"]
[Mon Jul 20 06:03:23.883782 2026] [security2:error] [pid 796928:tid 797139] [client 185.132.186.55:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/license.php"] [unique_id "al4Oi-sTy9vX-htKvPkFoQAAAuo"]
[Mon Jul 20 06:03:24.044347 2026] [security2:error] [pid 796928:tid 796930] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFowAC5AE"]
[Mon Jul 20 06:03:24.044510 2026] [security2:error] [pid 796928:tid 797133] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFowAC5AE"]
[Mon Jul 20 06:03:24.054067 2026] [security2:error] [pid 796928:tid 797174] [client 57.141.18.33:64002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OhusTy9vX-htKvPkElAADDUM"]
[Mon Jul 20 06:03:24.176602 2026] [security2:error] [pid 796567:tid 796798] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijQQAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:24.222576 2026] [security2:error] [pid 796928:tid 797107] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFUQACym4"]
[Mon Jul 20 06:03:24.238870 2026] [security2:error] [pid 796928:tid 797098] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYAAAAsE"]
[Mon Jul 20 06:03:24.261840 2026] [security2:error] [pid 796567:tid 796750] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijAwAAAkk"]
[Mon Jul 20 06:03:24.261980 2026] [security2:error] [pid 796928:tid 797134] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYgAAAuU"]
[Mon Jul 20 06:03:24.269592 2026] [security2:error] [pid 796928:tid 797078] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYQAAAq0"]
[Mon Jul 20 06:03:24.272976 2026] [security2:error] [pid 796567:tid 796783] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijAgAAAmo"]
[Mon Jul 20 06:03:24.274516 2026] [security2:error] [pid 796928:tid 797125] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFYwAAAtw"]
[Mon Jul 20 06:03:24.275435 2026] [security2:error] [pid 796567:tid 796706] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OirLfyzVz2SrjZpijBQAAAh0"]
[Mon Jul 20 06:03:24.343784 2026] [security2:error] [pid 796928:tid 797172] [client 150.228.148.150:12768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFsQAAAws"]
[Mon Jul 20 06:03:24.343954 2026] [security2:error] [pid 796928:tid 797172] [client 150.228.148.150:12768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFsQAAAws"]
[Mon Jul 20 06:03:24.400540 2026] [security2:error] [pid 796928:tid 797175] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OiusTy9vX-htKvPkFagAAAw4"]
[Mon Jul 20 06:03:24.424188 2026] [security2:error] [pid 796567:tid 796636] [remote 160.187.68.132:54218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4OjLLfyzVz2SrjZpijVwACHkQ"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:03:24.438000 2026] [security2:error] [pid 796928:tid 797152] [client 27.96.94.195:37700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OjOsTy9vX-htKvPkFrwAAAvc"]
[Mon Jul 20 06:03:24.693058 2026] [security2:error] [pid 796928:tid 797088] [client 46.110.96.34:5298] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OjOsTy9vX-htKvPkFxAAAArc"]
[Mon Jul 20 06:03:24.918142 2026] [security2:error] [pid 796567:tid 796810] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/robots.txt"] [unique_id "al4OjLLfyzVz2SrjZpijYwAAAoU"]
[Mon Jul 20 06:03:25.001806 2026] [security2:error] [pid 796567:tid 796742] [client 57.141.18.64:42784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oh7LfyzVz2SrjZpiifgACQXQ"]
[Mon Jul 20 06:03:25.285411 2026] [security2:error] [pid 796928:tid 796931] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.bak"] [unique_id "al4OjesTy9vX-htKvPkF3gACygI"]
[Mon Jul 20 06:03:25.288543 2026] [security2:error] [pid 796567:tid 796740] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/"] [unique_id "al4OjbLfyzVz2SrjZpijbwAAAj8"]
[Mon Jul 20 06:03:25.493737 2026] [security2:error] [pid 796928:tid 797121] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF2QAAAtg"]
[Mon Jul 20 06:03:25.507147 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF2AAAApw"]
[Mon Jul 20 06:03:25.515874 2026] [security2:error] [pid 796928:tid 797064] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OjesTy9vX-htKvPkF5AAAAp8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:25.710257 2026] [security2:error] [pid 796928:tid 797144] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF5QAAAu8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:25.799422 2026] [security2:error] [pid 796928:tid 797098] [client 47.31.86.100:57121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OjesTy9vX-htKvPkF9AAAAsE"]
[Mon Jul 20 06:03:25.818302 2026] [security2:error] [pid 796928:tid 797098] [client 47.31.86.100:57121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OjesTy9vX-htKvPkF9AAAAsE"]
[Mon Jul 20 06:03:25.837496 2026] [security2:error] [pid 796567:tid 796793] [client 185.132.186.62:26931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al4OjbLfyzVz2SrjZpijgQAAAnQ"]
[Mon Jul 20 06:03:25.837495 2026] [security2:error] [pid 796567:tid 796818] [client 20.200.215.118:40006] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "elevator-data.com"] [uri "/wp-comments-post.php"] [unique_id "al4OjbLfyzVz2SrjZpijfAAAAo0"]
[Mon Jul 20 06:03:25.879358 2026] [security2:error] [pid 796567:tid 796818] [client 20.200.215.118:40006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "elevator-data.com"] [uri "/wp-comments-post.php"] [unique_id "al4OjbLfyzVz2SrjZpijfAAAAo0"]
[Mon Jul 20 06:03:26.007168 2026] [security2:error] [pid 796567:tid 796749] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjbLfyzVz2SrjZpijhQACSHg"]
[Mon Jul 20 06:03:26.007201 2026] [security2:error] [pid 796567:tid 796749] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjbLfyzVz2SrjZpijhQACSHg"]
[Mon Jul 20 06:03:26.058758 2026] [security2:error] [pid 796928:tid 797127] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OjesTy9vX-htKvPkGAAAAAt4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:26.269349 2026] [security2:error] [pid 796928:tid 797092] [client 14.225.17.146:59081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4OjOsTy9vX-htKvPkFwwAAArs"], referer: http://cloudspacesgroup.com/wordpress
[Mon Jul 20 06:03:26.294030 2026] [security2:error] [pid 796928:tid 797150] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjusTy9vX-htKvPkGBgAC9RA"], referer: http://aleishapenny.ca/wordpress
[Mon Jul 20 06:03:26.664198 2026] [security2:error] [pid 796567:tid 796792] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OjrLfyzVz2SrjZpijmgACc24"]
[Mon Jul 20 06:03:26.802584 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:28848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijpAAAAh4"]
[Mon Jul 20 06:03:26.802676 2026] [security2:error] [pid 796567:tid 796707] [client 18.228.171.129:28848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijpAAAAh4"]
[Mon Jul 20 06:03:26.855999 2026] [security2:error] [pid 796567:tid 796760] [client 114.119.153.132:62947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/resource/enhancing-low-carbon-development-greening-economy-policy-dialogue-advisory-services"] [unique_id "al4OjrLfyzVz2SrjZpijpgAAAlM"], referer: http://www.lowemissionsasia.org/resources?qt-resources=1
[Mon Jul 20 06:03:26.904181 2026] [security2:error] [pid 796567:tid 796706] [client 115.246.21.170:33509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijqgAAAh0"]
[Mon Jul 20 06:03:26.904338 2026] [security2:error] [pid 796567:tid 796706] [client 115.246.21.170:33509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijqgAAAh0"]
[Mon Jul 20 06:03:27.139255 2026] [security2:error] [pid 796928:tid 797120] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGJwAC10o"], referer: https://aleishapenny.ca/wordpress
[Mon Jul 20 06:03:27.167318 2026] [security2:error] [pid 796928:tid 796972] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/api/.env"] [unique_id "al4Oj-sTy9vX-htKvPkGLQAC3is"]
[Mon Jul 20 06:03:27.201474 2026] [security2:error] [pid 796928:tid 797168] [client 57.141.18.45:20528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OiesTy9vX-htKvPkFLQADB2c"]
[Mon Jul 20 06:03:27.321689 2026] [security2:error] [pid 796567:tid 796775] [client 14.225.17.146:60223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4OjrLfyzVz2SrjZpijiwAAAmI"], referer: http://musichaven.info/wordpress
[Mon Jul 20 06:03:27.326221 2026] [security2:error] [pid 796928:tid 796954] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.old"] [unique_id "al4Oj-sTy9vX-htKvPkGOQADAhk"]
[Mon Jul 20 06:03:27.354600 2026] [security2:error] [pid 796928:tid 797156] [client 14.225.17.146:64398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4OjesTy9vX-htKvPkF1gAAAvs"], referer: http://fineartsfactory.net/wordpress
[Mon Jul 20 06:03:27.560538 2026] [security2:error] [pid 796567:tid 796757] [client 77.110.127.138:54683] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4Oj7LfyzVz2SrjZpijwQAAAlA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:27.618356 2026] [security2:error] [pid 796928:tid 796974] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/config/.env"] [unique_id "al4Oj-sTy9vX-htKvPkGRgADAi0"]
[Mon Jul 20 06:03:27.643243 2026] [security2:error] [pid 796928:tid 796951] [remote 176.56.118.182:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Oj-sTy9vX-htKvPkGRwAC-RY"]
[Mon Jul 20 06:03:27.770953 2026] [security2:error] [pid 796928:tid 797119] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGPQAAAtY"]
[Mon Jul 20 06:03:27.787118 2026] [security2:error] [pid 796928:tid 797136] [client 185.132.186.60:37317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/lock.php"] [unique_id "al4Oj-sTy9vX-htKvPkGTwAAAuc"]
[Mon Jul 20 06:03:27.805876 2026] [security2:error] [pid 796928:tid 796959] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/backend/.env"] [unique_id "al4Oj-sTy9vX-htKvPkGUAAC3x4"]
[Mon Jul 20 06:03:27.861128 2026] [security2:error] [pid 796928:tid 797080] [client 2a01:4f8:210:1144::2:0] ModSecurity: Warning. Matched phrase "DomainStatsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGMgACrwA"]
[Mon Jul 20 06:03:27.874913 2026] [security2:error] [pid 796928:tid 796977] [remote 176.56.118.182:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Oj-sTy9vX-htKvPkGUwAC7TA"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:03:27.897231 2026] [cgid:error] [pid 796567:tid 796748] [client 199.45.155.92:56808] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: https://www.website-fa490990.threethirds.co:443/cgi-bin
[Mon Jul 20 06:03:27.934083 2026] [security2:error] [pid 796928:tid 796987] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.backup"] [unique_id "al4Oj-sTy9vX-htKvPkGVgAC6zo"]
[Mon Jul 20 06:03:27.996099 2026] [security2:error] [pid 796928:tid 796984] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/graphql"] [unique_id "al4Oj-sTy9vX-htKvPkGXgADETc"]
[Mon Jul 20 06:03:27.998219 2026] [security2:error] [pid 796928:tid 797120] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oj-sTy9vX-htKvPkGVQAAAtc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:28.206502 2026] [security2:error] [pid 796928:tid 797184] [client 14.225.17.146:56080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4OkOsTy9vX-htKvPkGYgAAAxc"], referer: https://musichaven.info/wordpress
[Mon Jul 20 06:03:28.388074 2026] [security2:error] [pid 796928:tid 797133] [client 103.95.123.246:18648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGbQAAAuQ"]
[Mon Jul 20 06:03:28.388237 2026] [security2:error] [pid 796928:tid 797133] [client 103.95.123.246:18648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGbQAAAuQ"]
[Mon Jul 20 06:03:28.427080 2026] [security2:error] [pid 796928:tid 797155] [client 86.98.90.58:47174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGcQAAAvo"]
[Mon Jul 20 06:03:28.427188 2026] [security2:error] [pid 796928:tid 797155] [client 86.98.90.58:47174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGcQAAAvo"]
[Mon Jul 20 06:03:28.511153 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:47578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdQAAAuw"]
[Mon Jul 20 06:03:28.521162 2026] [security2:error] [pid 796928:tid 797141] [client 129.222.187.209:47578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdQAAAuw"]
[Mon Jul 20 06:03:28.594547 2026] [security2:error] [pid 796928:tid 797121] [client 178.152.178.232:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdwAAAtg"]
[Mon Jul 20 06:03:28.594693 2026] [security2:error] [pid 796928:tid 797121] [client 178.152.178.232:37154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGdwAAAtg"]
[Mon Jul 20 06:03:28.618685 2026] [security2:error] [pid 796928:tid 797069] [client 46.110.96.34:36243] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OkOsTy9vX-htKvPkGeQAAAqQ"]
[Mon Jul 20 06:03:28.920575 2026] [security2:error] [pid 796928:tid 797137] [client 41.173.37.102:9705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGiQAAAug"]
[Mon Jul 20 06:03:28.920687 2026] [security2:error] [pid 796928:tid 797137] [client 41.173.37.102:9705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OkOsTy9vX-htKvPkGiQAAAug"]
[Mon Jul 20 06:03:28.929699 2026] [security2:error] [pid 796928:tid 797080] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OkOsTy9vX-htKvPkGfwAAAq8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:29.023394 2026] [security2:error] [pid 796567:tid 796819] [client 57.141.18.15:23080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oi7LfyzVz2SrjZpijHAACjgo"]
[Mon Jul 20 06:03:29.051706 2026] [security2:error] [pid 796928:tid 797113] [client 77.110.127.138:54769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4OkesTy9vX-htKvPkGjgAAAtA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:29.055110 2026] [security2:error] [pid 796928:tid 797119] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkOsTy9vX-htKvPkGegAC1j8"]
[Mon Jul 20 06:03:29.369708 2026] [security2:error] [pid 796567:tid 796785] [client 57.141.18.43:25530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OjLLfyzVz2SrjZpijTgACbEw"]
[Mon Jul 20 06:03:29.431845 2026] [security2:error] [pid 796567:tid 796583] [remote 57.141.18.98:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4OkbLfyzVz2SrjZpikBQACWw8"]
[Mon Jul 20 06:03:29.433380 2026] [security2:error] [pid 796928:tid 796964] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/api/graphql"] [unique_id "al4OkesTy9vX-htKvPkGmwACnCM"]
[Mon Jul 20 06:03:29.467311 2026] [authz_core:error] [pid 796928:tid 797132] [client 34.101.165.107:0] AH01630: client denied by server configuration: /home2/laughio2/public_html/jenfarley/.htpasswd
[Mon Jul 20 06:03:29.581514 2026] [security2:error] [pid 796928:tid 797004] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGsQAC7Es"]
[Mon Jul 20 06:03:29.581835 2026] [security2:error] [pid 796928:tid 797141] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGsQAC7Es"]
[Mon Jul 20 06:03:29.640980 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGtQAAAws"]
[Mon Jul 20 06:03:29.641117 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGtQAAAws"]
[Mon Jul 20 06:03:29.741708 2026] [security2:error] [pid 796928:tid 797185] [client 185.132.186.96:29309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/gold.php"] [unique_id "al4OkesTy9vX-htKvPkGvAAAAxg"]
[Mon Jul 20 06:03:29.745957 2026] [security2:error] [pid 796928:tid 797084] [client 50.116.65.227:11848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OkesTy9vX-htKvPkGvQAAArM"]
[Mon Jul 20 06:03:29.755702 2026] [security2:error] [pid 796567:tid 796745] [client 50.116.65.227:11854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OkbLfyzVz2SrjZpikFAAAAkQ"]
[Mon Jul 20 06:03:29.833475 2026] [security2:error] [pid 796567:tid 796711] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OjrLfyzVz2SrjZpijsgACIg4"]
[Mon Jul 20 06:03:29.950773 2026] [security2:error] [pid 796928:tid 797106] [client 106.192.104.4:55992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGxAAAAsk"]
[Mon Jul 20 06:03:29.950883 2026] [security2:error] [pid 796928:tid 797106] [client 106.192.104.4:55992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OkesTy9vX-htKvPkGxAAAAsk"]
[Mon Jul 20 06:03:30.043772 2026] [security2:error] [pid 796928:tid 797142] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OkesTy9vX-htKvPkGxgAAAu0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:30.277998 2026] [security2:error] [pid 796928:tid 797072] [client 14.225.17.146:59849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Oj-sTy9vX-htKvPkGWQAAAqc"]
[Mon Jul 20 06:03:30.343475 2026] [ssl:error] [pid 796928:tid 797153] [client 104.48.69.105:39116] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:03:30.404506 2026] [security2:error] [pid 796567:tid 796710] [client 77.110.127.138:54768] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OkrLfyzVz2SrjZpikMAAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:30.451294 2026] [security2:error] [pid 796928:tid 797001] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/v1/graphql"] [unique_id "al4OkusTy9vX-htKvPkG3QACnEg"]
[Mon Jul 20 06:03:30.779154 2026] [security2:error] [pid 796928:tid 797070] [client 103.149.16.77:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OkusTy9vX-htKvPkG6QAAAqU"]
[Mon Jul 20 06:03:30.779670 2026] [security2:error] [pid 796928:tid 797070] [client 103.149.16.77:62228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OkusTy9vX-htKvPkG6QAAAqU"]
[Mon Jul 20 06:03:30.829524 2026] [security2:error] [pid 796567:tid 796766] [client 164.100.212.184:53586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OkrLfyzVz2SrjZpikPgAAAlk"]
[Mon Jul 20 06:03:30.829621 2026] [security2:error] [pid 796567:tid 796766] [client 164.100.212.184:53586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OkrLfyzVz2SrjZpikPgAAAlk"]
[Mon Jul 20 06:03:30.944590 2026] [security2:error] [pid 796567:tid 796648] [remote 217.61.143.92:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4OkrLfyzVz2SrjZpikQAACJ1A"]
[Mon Jul 20 06:03:31.065909 2026] [security2:error] [pid 796928:tid 797127] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Ok-sTy9vX-htKvPkG7wAAAt4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:31.119619 2026] [security2:error] [pid 796567:tid 796738] [client 181.224.94.124:46224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok7LfyzVz2SrjZpikRwAAAj0"]
[Mon Jul 20 06:03:31.119724 2026] [security2:error] [pid 796567:tid 796738] [client 181.224.94.124:46224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok7LfyzVz2SrjZpikRwAAAj0"]
[Mon Jul 20 06:03:31.172517 2026] [security2:error] [pid 796567:tid 796704] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkbLfyzVz2SrjZpij_gAAAhs"]
[Mon Jul 20 06:03:31.204199 2026] [security2:error] [pid 796567:tid 796675] [remote 217.61.143.92:47100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4Ok7LfyzVz2SrjZpikSwACUWs"], referer: https://get.learnthissecret.com/wp-login.php
[Mon Jul 20 06:03:31.350375 2026] [security2:error] [pid 796928:tid 797181] [client 3.109.4.218:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok-sTy9vX-htKvPkHBgAAAxQ"]
[Mon Jul 20 06:03:31.350473 2026] [security2:error] [pid 796928:tid 797181] [client 3.109.4.218:60748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ok-sTy9vX-htKvPkHBgAAAxQ"]
[Mon Jul 20 06:03:31.596852 2026] [security2:error] [pid 796567:tid 796786] [client 77.110.127.138:54767] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4Ok7LfyzVz2SrjZpikVQAAAm0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:31.630120 2026] [security2:error] [pid 796928:tid 797030] [remote 57.141.18.56:61772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4Ok-sTy9vX-htKvPkHDwAC8GU"]
[Mon Jul 20 06:03:31.670271 2026] [security2:error] [pid 796567:tid 796774] [client 185.132.186.57:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/atomlib.php"] [unique_id "al4Ok7LfyzVz2SrjZpikXAAAAmE"]
[Mon Jul 20 06:03:31.783887 2026] [security2:error] [pid 796928:tid 797034] [remote 57.141.18.75:22000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4Ok-sTy9vX-htKvPkHFwACwWk"]
[Mon Jul 20 06:03:31.795656 2026] [security2:error] [pid 796928:tid 797075] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ok-sTy9vX-htKvPkHEQAAAqo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:32.017656 2026] [security2:error] [pid 796928:tid 797072] [client 129.222.187.209:64538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OlOsTy9vX-htKvPkHIQAAAqc"]
[Mon Jul 20 06:03:32.023909 2026] [security2:error] [pid 796567:tid 796772] [client 72.255.10.154:26234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OlLLfyzVz2SrjZpikcgAAAl8"]
[Mon Jul 20 06:03:32.024036 2026] [security2:error] [pid 796567:tid 796772] [client 72.255.10.154:26234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OlLLfyzVz2SrjZpikcgAAAl8"]
[Mon Jul 20 06:03:32.032667 2026] [security2:error] [pid 796928:tid 797072] [client 129.222.187.209:64538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OlOsTy9vX-htKvPkHIQAAAqc"]
[Mon Jul 20 06:03:32.145944 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGmgACnEQ"]
[Mon Jul 20 06:03:32.180411 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGnAACnEc"]
[Mon Jul 20 06:03:32.181181 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGoAACnE8"]
[Mon Jul 20 06:03:32.186598 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGnwACnE0"]
[Mon Jul 20 06:03:32.187903 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGpQACnFI"]
[Mon Jul 20 06:03:32.206258 2026] [security2:error] [pid 796928:tid 797059] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGqgAAApo"]
[Mon Jul 20 06:03:32.211683 2026] [security2:error] [pid 796928:tid 797155] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGqwAAAvo"]
[Mon Jul 20 06:03:32.218852 2026] [security2:error] [pid 796928:tid 797061] [client 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkesTy9vX-htKvPkGoQACnFE"]
[Mon Jul 20 06:03:32.254972 2026] [security2:error] [pid 796567:tid 796817] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkbLfyzVz2SrjZpikCgAAAow"]
[Mon Jul 20 06:03:32.296017 2026] [security2:error] [pid 796567:tid 796709] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkbLfyzVz2SrjZpikHAAAAiA"]
[Mon Jul 20 06:03:32.395161 2026] [security2:error] [pid 796928:tid 797087] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OkusTy9vX-htKvPkG5gAAArY"]
[Mon Jul 20 06:03:32.871865 2026] [security2:error] [pid 796928:tid 797152] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlOsTy9vX-htKvPkHLgAAAvc"]
[Mon Jul 20 06:03:33.147536 2026] [security2:error] [pid 796928:tid 797017] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.ssh/id_rsa"] [unique_id "al4OlesTy9vX-htKvPkHTAACylg"]
[Mon Jul 20 06:03:33.147538 2026] [security2:error] [pid 796928:tid 797049] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.ssh/id_dsa"] [unique_id "al4OlesTy9vX-htKvPkHUAACyng"]
[Mon Jul 20 06:03:33.262741 2026] [security2:error] [pid 796928:tid 797180] [client 35.227.39.208:27682] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "tumbletyn.com"] [uri "/wp-json/batch/v1"] [unique_id "al4OlesTy9vX-htKvPkHXQAAAxM"]
[Mon Jul 20 06:03:33.596669 2026] [security2:error] [pid 796567:tid 796790] [client 185.132.186.64:23155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/index.php"] [unique_id "al4OlbLfyzVz2SrjZpikrAAAAnE"]
[Mon Jul 20 06:03:34.128465 2026] [security2:error] [pid 796928:tid 797088] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OlusTy9vX-htKvPkHbgAAArc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:34.197466 2026] [security2:error] [pid 796928:tid 797110] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHWQAAAs0"]
[Mon Jul 20 06:03:34.226553 2026] [security2:error] [pid 796928:tid 797053] [remote 34.101.165.107:50324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHTgACynw"]
[Mon Jul 20 06:03:34.233365 2026] [security2:error] [pid 796928:tid 797136] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHWAAAAuc"]
[Mon Jul 20 06:03:34.233948 2026] [security2:error] [pid 796567:tid 796807] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlbLfyzVz2SrjZpiknQAAAoI"]
[Mon Jul 20 06:03:34.264101 2026] [security2:error] [pid 796928:tid 797146] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHWgAAAvE"]
[Mon Jul 20 06:03:34.282285 2026] [security2:error] [pid 796567:tid 796774] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OlbLfyzVz2SrjZpiknAAAAmE"]
[Mon Jul 20 06:03:34.344181 2026] [security2:error] [pid 796567:tid 796729] [client 77.110.127.138:54768] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 586 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OlrLfyzVz2SrjZpikzAAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:34.387295 2026] [security2:error] [pid 796928:tid 797058] [client 35.227.39.208:27682] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "tumbletyn.com"] [uri "/"] [unique_id "al4OlusTy9vX-htKvPkHgAAAApk"]
[Mon Jul 20 06:03:34.430525 2026] [security2:error] [pid 796567:tid 796746] [client 112.213.160.112:31151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OlrLfyzVz2SrjZpikzwAAAkU"]
[Mon Jul 20 06:03:34.430632 2026] [security2:error] [pid 796567:tid 796746] [client 112.213.160.112:31151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OlrLfyzVz2SrjZpikzwAAAkU"]
[Mon Jul 20 06:03:34.744690 2026] [security2:error] [pid 796928:tid 797040] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHlQADBm8"]
[Mon Jul 20 06:03:34.744843 2026] [security2:error] [pid 796928:tid 797167] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHlQADBm8"]
[Mon Jul 20 06:03:34.818718 2026] [security2:error] [pid 796928:tid 797144] [client 27.96.94.195:38030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHjgAAAu8"]
[Mon Jul 20 06:03:34.861787 2026] [security2:error] [pid 796928:tid 797075] [client 104.28.163.98:29940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "almaz-aura.net"] [uri "/wp-login.php"] [unique_id "al4OlusTy9vX-htKvPkHmgAAAqo"]
[Mon Jul 20 06:03:34.990139 2026] [security2:error] [pid 796928:tid 797082] [client 150.228.148.150:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHogAAArE"]
[Mon Jul 20 06:03:35.000956 2026] [security2:error] [pid 796928:tid 797082] [client 150.228.148.150:46039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OlusTy9vX-htKvPkHogAAArE"]
[Mon Jul 20 06:03:35.155626 2026] [security2:error] [pid 796567:tid 796601] [remote 123.30.154.30:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Ol7LfyzVz2SrjZpik7gACWCE"]
[Mon Jul 20 06:03:35.166712 2026] [security2:error] [pid 796567:tid 796718] [client 77.110.127.138:54684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4Ol7LfyzVz2SrjZpik8AAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:35.415324 2026] [autoindex:error] [pid 796567:tid 796802] [client 14.225.17.146:59432] AH01276: Cannot serve directory /home4/thrninis/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://39ishlife.com/wordpress
[Mon Jul 20 06:03:35.539544 2026] [security2:error] [pid 796567:tid 796777] [client 185.132.186.72:50529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/about.php"] [unique_id "al4Ol7LfyzVz2SrjZpik_wAAAmQ"]
[Mon Jul 20 06:03:35.687020 2026] [security2:error] [pid 796567:tid 796604] [remote 123.30.154.30:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Ol7LfyzVz2SrjZpilAgACUyQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:36.228086 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH0gAAAqs"]
[Mon Jul 20 06:03:36.228268 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:57556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH0gAAAqs"]
[Mon Jul 20 06:03:36.250637 2026] [security2:error] [pid 796928:tid 797069] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OmOsTy9vX-htKvPkH0QAAAqQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:36.426573 2026] [security2:error] [pid 796567:tid 796774] [client 193.19.109.236:45313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4OmLLfyzVz2SrjZpilGwAAAmE"]
[Mon Jul 20 06:03:36.584878 2026] [security2:error] [pid 796928:tid 797087] [client 86.98.90.58:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH3AAAArY"]
[Mon Jul 20 06:03:36.585052 2026] [security2:error] [pid 796928:tid 797087] [client 86.98.90.58:47979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OmOsTy9vX-htKvPkH3AAAArY"]
[Mon Jul 20 06:03:36.642966 2026] [security2:error] [pid 796567:tid 796809] [client 74.208.214.194:45056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OmLLfyzVz2SrjZpilIwAAAoQ"]
[Mon Jul 20 06:03:36.950642 2026] [ssl:error] [pid 796928:tid 797174] [client 104.48.69.105:39128] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:03:37.160642 2026] [security2:error] [pid 796928:tid 797067] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OmesTy9vX-htKvPkH9wAAAqI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:37.354978 2026] [security2:error] [pid 796567:tid 796669] [remote 57.141.18.106:23556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5083626"] [unique_id "al4OmbLfyzVz2SrjZpilQQACSWU"]
[Mon Jul 20 06:03:37.488551 2026] [security2:error] [pid 796567:tid 796705] [client 185.132.186.77:24415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/wincust.php"] [unique_id "al4OmbLfyzVz2SrjZpilTAAAAhw"]
[Mon Jul 20 06:03:37.501271 2026] [security2:error] [pid 796928:tid 797105] [client 15.229.42.239:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAAAAAsg"]
[Mon Jul 20 06:03:37.501394 2026] [security2:error] [pid 796928:tid 797105] [client 15.229.42.239:32560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAAAAAsg"]
[Mon Jul 20 06:03:37.796742 2026] [security2:error] [pid 796928:tid 797111] [client 115.246.21.170:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAgAAAs4"]
[Mon Jul 20 06:03:37.796888 2026] [security2:error] [pid 796928:tid 797111] [client 115.246.21.170:52336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAgAAAs4"]
[Mon Jul 20 06:03:37.880796 2026] [security2:error] [pid 796567:tid 796739] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 853 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OmbLfyzVz2SrjZpilYAAAAj4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:37.917071 2026] [security2:error] [pid 796928:tid 797169] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OmesTy9vX-htKvPkIAQADCFY"]
[Mon Jul 20 06:03:37.936928 2026] [security2:error] [pid 796567:tid 796685] [remote 192.241.143.148:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OmbLfyzVz2SrjZpilZwACbHU"]
[Mon Jul 20 06:03:37.997425 2026] [security2:error] [pid 796928:tid 797143] [client 113.160.97.242:57540] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4OmesTy9vX-htKvPkICwAAAu4"]
[Mon Jul 20 06:03:38.097634 2026] [security2:error] [pid 796567:tid 796576] [remote 192.241.143.148:39610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OmrLfyzVz2SrjZpilbwACXgg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:38.130519 2026] [ssl:error] [pid 796928:tid 797132] [client 104.48.69.105:60508] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:03:38.490541 2026] [lsapi:warn] [pid 796567:tid 796649] [remote 66.93.167.235:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://ali-alghanim.net/
[Mon Jul 20 06:03:39.121603 2026] [security2:error] [pid 796928:tid 797079] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Om-sTy9vX-htKvPkIQAAAAq4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:39.121758 2026] [security2:error] [pid 796928:tid 797079] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Om-sTy9vX-htKvPkIQAAAAq4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:39.149717 2026] [security2:error] [pid 796567:tid 796706] [client 129.222.187.209:34877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilngAAAh0"]
[Mon Jul 20 06:03:39.159948 2026] [security2:error] [pid 796567:tid 796706] [client 129.222.187.209:34877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilngAAAh0"]
[Mon Jul 20 06:03:39.218971 2026] [security2:error] [pid 796567:tid 796805] [client 87.199.196.160:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4Om7LfyzVz2SrjZpilnwAAAoA"], referer: https://www.guidehunting.com/guide-school-and-training-in-utah/
[Mon Jul 20 06:03:39.219110 2026] [security2:error] [pid 796567:tid 796805] [client 87.199.196.160:53701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4Om7LfyzVz2SrjZpilnwAAAoA"], referer: https://www.guidehunting.com/guide-school-and-training-in-utah/
[Mon Jul 20 06:03:39.433983 2026] [security2:error] [pid 796567:tid 796744] [client 185.132.186.83:23391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/alfa-rex.php"] [unique_id "al4Om7LfyzVz2SrjZpilqQAAAkM"]
[Mon Jul 20 06:03:39.505812 2026] [security2:error] [pid 796567:tid 796720] [client 103.95.123.246:19148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrQAAAis"]
[Mon Jul 20 06:03:39.505919 2026] [security2:error] [pid 796567:tid 796720] [client 103.95.123.246:19148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrQAAAis"]
[Mon Jul 20 06:03:39.506847 2026] [security2:error] [pid 796567:tid 796697] [client 41.173.37.102:10125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrgAAAhQ"]
[Mon Jul 20 06:03:39.506918 2026] [security2:error] [pid 796567:tid 796697] [client 41.173.37.102:10125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Om7LfyzVz2SrjZpilrgAAAhQ"]
[Mon Jul 20 06:03:39.692717 2026] [security2:error] [pid 796567:tid 796627] [remote 154.66.198.148:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Om7LfyzVz2SrjZpiltQACbjs"]
[Mon Jul 20 06:03:39.776052 2026] [security2:error] [pid 796567:tid 796792] [client 50.116.65.227:60910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Om7LfyzVz2SrjZpilugAAAnM"]
[Mon Jul 20 06:03:39.789221 2026] [security2:error] [pid 796567:tid 796783] [client 50.116.65.227:60922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Om7LfyzVz2SrjZpiluwAAAmo"]
[Mon Jul 20 06:03:39.925293 2026] [security2:error] [pid 796928:tid 797125] [client 57.141.18.74:31472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OlesTy9vX-htKvPkHXwAC3EE"]
[Mon Jul 20 06:03:39.928606 2026] [security2:error] [pid 796928:tid 797130] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Om-sTy9vX-htKvPkIWQAAAuE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:39.941012 2026] [autoindex:error] [pid 796567:tid 796729] [client 168.144.134.248:60724] AH01276: Cannot serve directory /home4/retzkolo/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:03:40.041542 2026] [security2:error] [pid 796567:tid 796767] [client 103.153.183.69:42838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../etc/nginx/nginx.conf"] [unique_id "al4OnLLfyzVz2SrjZpilyQAAAlo"], referer: https://www.google.com/search?q=8rlm59
[Mon Jul 20 06:03:40.113677 2026] [security2:error] [pid 796567:tid 796646] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OnLLfyzVz2SrjZpilzQACf04"]
[Mon Jul 20 06:03:40.113948 2026] [security2:error] [pid 796567:tid 796804] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OnLLfyzVz2SrjZpilzQACf04"]
[Mon Jul 20 06:03:40.167178 2026] [security2:error] [pid 796928:tid 797147] [client 210.212.97.243:10433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIZQAAAvI"]
[Mon Jul 20 06:03:40.167336 2026] [security2:error] [pid 796928:tid 797147] [client 210.212.97.243:10433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIZQAAAvI"]
[Mon Jul 20 06:03:40.209704 2026] [security2:error] [pid 796928:tid 796950] [remote 182.77.62.24:34012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIaQAC_hU"]
[Mon Jul 20 06:03:40.209817 2026] [security2:error] [pid 796928:tid 797159] [client 182.77.62.24:34012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "villa-m-medjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4OnOsTy9vX-htKvPkIaQAC_hU"]
[Mon Jul 20 06:03:40.375667 2026] [security2:error] [pid 796567:tid 796819] [client 77.110.127.138:54715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 815 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OnLLfyzVz2SrjZpil1gAAAo4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:40.463197 2026] [security2:error] [pid 796928:tid 797140] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OnOsTy9vX-htKvPkIdAAAAus"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:40.617703 2026] [security2:error] [pid 796567:tid 796601] [remote 154.66.198.148:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OnLLfyzVz2SrjZpil3wACjCE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:03:40.705075 2026] [security2:error] [pid 796928:tid 797141] [client 57.141.18.74:20868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OlusTy9vX-htKvPkHcwAC7D0"]
[Mon Jul 20 06:03:40.816108 2026] [security2:error] [pid 796567:tid 796753] [client 14.225.17.146:63089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Om7LfyzVz2SrjZpillgAAAkw"], referer: http://expertcultures.com/wordpress
[Mon Jul 20 06:03:41.268048 2026] [security2:error] [pid 796567:tid 796742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OnLLfyzVz2SrjZpil8QAAAkE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:41.295242 2026] [security2:error] [pid 796928:tid 796939] [remote 202.51.202.242:33400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OnesTy9vX-htKvPkIkgACzwo"]
[Mon Jul 20 06:03:41.329275 2026] [security2:error] [pid 796928:tid 797096] [client 164.100.212.184:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIlgAAAr8"]
[Mon Jul 20 06:03:41.329375 2026] [security2:error] [pid 796928:tid 797096] [client 164.100.212.184:62566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIlgAAAr8"]
[Mon Jul 20 06:03:41.388676 2026] [security2:error] [pid 796928:tid 797123] [client 185.132.186.68:39577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-good.php"] [unique_id "al4OnesTy9vX-htKvPkImwAAAto"]
[Mon Jul 20 06:03:41.400267 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkInQAAAsQ"]
[Mon Jul 20 06:03:41.400422 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:62718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkInQAAAsQ"]
[Mon Jul 20 06:03:41.415140 2026] [security2:error] [pid 796928:tid 797060] [client 106.192.104.4:56481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIngAAAps"]
[Mon Jul 20 06:03:41.424391 2026] [security2:error] [pid 796928:tid 797060] [client 106.192.104.4:56481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIngAAAps"]
[Mon Jul 20 06:03:41.473364 2026] [security2:error] [pid 796928:tid 797166] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OnesTy9vX-htKvPkImgAAAwU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:41.519123 2026] [security2:error] [pid 796567:tid 796719] [client 57.141.18.18:28274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ol7LfyzVz2SrjZpik7AACKgI"]
[Mon Jul 20 06:03:41.705532 2026] [security2:error] [pid 796928:tid 797147] [client 181.224.94.124:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIrgAAAvI"]
[Mon Jul 20 06:03:41.705635 2026] [security2:error] [pid 796928:tid 797147] [client 181.224.94.124:63505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnesTy9vX-htKvPkIrgAAAvI"]
[Mon Jul 20 06:03:41.993541 2026] [autoindex:error] [pid 796567:tid 796733] [client 14.225.17.146:59341] AH01276: Cannot serve directory /home1/tgdhcnmy/public_html/nextlevelpressurewashing/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://nextlevelpressurewashing.com/wordpress
[Mon Jul 20 06:03:42.023496 2026] [security2:error] [pid 796928:tid 797058] [client 57.141.18.52:34976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ol-sTy9vX-htKvPkHsgACmW0"]
[Mon Jul 20 06:03:42.139291 2026] [security2:error] [pid 796928:tid 797172] [client 46.110.96.34:12932] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4OnusTy9vX-htKvPkIwAAAAws"]
[Mon Jul 20 06:03:42.185116 2026] [security2:error] [pid 796928:tid 797179] [client 193.19.109.235:22255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/wp-login.php"] [unique_id "al4OnusTy9vX-htKvPkIvgAAAxI"]
[Mon Jul 20 06:03:42.416470 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:51472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OnrLfyzVz2SrjZpimNwAAAhw"]
[Mon Jul 20 06:03:42.416567 2026] [security2:error] [pid 796567:tid 796705] [client 3.109.4.218:51472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OnrLfyzVz2SrjZpimNwAAAhw"]
[Mon Jul 20 06:03:42.661822 2026] [security2:error] [pid 796928:tid 797175] [client 129.222.187.209:20306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI1wAAAw4"]
[Mon Jul 20 06:03:42.661928 2026] [security2:error] [pid 796928:tid 797175] [client 129.222.187.209:20306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI1wAAAw4"]
[Mon Jul 20 06:03:42.685542 2026] [security2:error] [pid 796928:tid 797142] [client 14.225.17.146:60349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4OnOsTy9vX-htKvPkIeAAAAu0"], referer: http://tacticaltreeoperations.com/wordpress
[Mon Jul 20 06:03:42.697718 2026] [security2:error] [pid 796928:tid 797081] [client 72.255.10.154:26466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI2wAAArA"]
[Mon Jul 20 06:03:42.697853 2026] [security2:error] [pid 796928:tid 797081] [client 72.255.10.154:26466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OnusTy9vX-htKvPkI2wAAArA"]
[Mon Jul 20 06:03:42.859845 2026] [security2:error] [pid 796928:tid 797143] [client 98.159.234.160:51761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OnusTy9vX-htKvPkI4wAAAu4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:43.343832 2026] [security2:error] [pid 796928:tid 797082] [client 14.225.17.146:49717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4OnesTy9vX-htKvPkItAAAArE"], referer: http://sarahholyfield.com/wordpress
[Mon Jul 20 06:03:43.344604 2026] [security2:error] [pid 796928:tid 797080] [client 185.132.186.65:59105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/index.php"] [unique_id "al4On-sTy9vX-htKvPkI8wAAAq8"]
[Mon Jul 20 06:03:43.899379 2026] [security2:error] [pid 796928:tid 797102] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4On-sTy9vX-htKvPkJFwAAAsU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:43.985395 2026] [security2:error] [pid 796928:tid 797093] [client 14.225.17.146:63710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4OnusTy9vX-htKvPkIvwAAArw"], referer: http://bigwormfishing.com/wordpress
[Mon Jul 20 06:03:44.114148 2026] [security2:error] [pid 796567:tid 796779] [client 198.44.157.34:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4OoLLfyzVz2SrjZpimdQAAAmY"]
[Mon Jul 20 06:03:44.114313 2026] [security2:error] [pid 796567:tid 796779] [client 198.44.157.34:40380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4OoLLfyzVz2SrjZpimdQAAAmY"]
[Mon Jul 20 06:03:44.154499 2026] [security2:error] [pid 796928:tid 797158] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OoOsTy9vX-htKvPkJIwAAAv0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:44.248076 2026] [security2:error] [pid 796567:tid 796791] [client 77.110.127.138:54767] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimfgAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.304543 2026] [security2:error] [pid 796567:tid 796748] [client 77.110.127.138:54768] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimggAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.328778 2026] [security2:error] [pid 796928:tid 797139] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OoOsTy9vX-htKvPkJMgAAAuo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:44.376026 2026] [security2:error] [pid 796567:tid 796701] [client 77.110.127.138:54684] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimhAAAAhg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.429495 2026] [security2:error] [pid 796567:tid 796774] [client 77.110.127.138:54767] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OoLLfyzVz2SrjZpimiQAAAmE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:44.599520 2026] [autoindex:error] [pid 796928:tid 797073] [client 194.233.85.87:58846] AH01276: Cannot serve directory /home2/rhstevmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:03:44.650970 2026] [security2:error] [pid 796928:tid 797088] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OoOsTy9vX-htKvPkJOQAAArc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:44.838607 2026] [security2:error] [pid 796928:tid 797099] [client 57.141.18.44:64426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OmusTy9vX-htKvPkIMAACwh4"]
[Mon Jul 20 06:03:44.949187 2026] [security2:error] [pid 796928:tid 797152] [client 14.225.17.146:63525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4On-sTy9vX-htKvPkI-AAAAvc"], referer: http://carolinapressurewashers.com/wordpress
[Mon Jul 20 06:03:45.016054 2026] [security2:error] [pid 796567:tid 796821] [client 52.59.238.198:63306] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4OobLfyzVz2SrjZpimoQAAApA"]
[Mon Jul 20 06:03:45.035085 2026] [security2:error] [pid 796928:tid 797176] [client 14.225.17.146:65495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4OoOsTy9vX-htKvPkJUQAAAw8"], referer: https://bigwormfishing.com/wordpress
[Mon Jul 20 06:03:45.240319 2026] [security2:error] [pid 796567:tid 796728] [client 112.213.160.112:31109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimrAAAAjM"]
[Mon Jul 20 06:03:45.240457 2026] [security2:error] [pid 796567:tid 796728] [client 112.213.160.112:31109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimrAAAAjM"]
[Mon Jul 20 06:03:45.277810 2026] [security2:error] [pid 796567:tid 796707] [client 193.37.33.5:52447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetalkswithkay.com"] [uri "/wp-login.php"] [unique_id "al4OobLfyzVz2SrjZpimrwAAAh4"]
[Mon Jul 20 06:03:45.279689 2026] [security2:error] [pid 796928:tid 797133] [client 185.132.186.86:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al4OoesTy9vX-htKvPkJYgAAAuQ"]
[Mon Jul 20 06:03:45.594598 2026] [security2:error] [pid 796928:tid 797039] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OoesTy9vX-htKvPkJegACnW4"]
[Mon Jul 20 06:03:45.594772 2026] [security2:error] [pid 796928:tid 797062] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OoesTy9vX-htKvPkJegACnW4"]
[Mon Jul 20 06:03:45.698055 2026] [security2:error] [pid 796567:tid 796714] [client 150.228.148.150:52613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimvQAAAiU"]
[Mon Jul 20 06:03:45.705521 2026] [security2:error] [pid 796567:tid 796714] [client 150.228.148.150:52613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OobLfyzVz2SrjZpimvQAAAiU"]
[Mon Jul 20 06:03:45.760438 2026] [security2:error] [pid 796928:tid 797169] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OoesTy9vX-htKvPkJfgAAAwg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:45.762792 2026] [security2:error] [pid 796928:tid 797165] [client 14.225.17.146:52438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4OoesTy9vX-htKvPkJfAAAAwQ"], referer: http://dasmarque.com/wordpress
[Mon Jul 20 06:03:46.089253 2026] [security2:error] [pid 796928:tid 797082] [client 52.59.238.198:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4OoesTy9vX-htKvPkJeQAAArE"]
[Mon Jul 20 06:03:46.091743 2026] [security2:error] [pid 796928:tid 797084] [client 52.59.238.198:45974] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4OoesTy9vX-htKvPkJdgAAArM"]
[Mon Jul 20 06:03:46.583542 2026] [security2:error] [pid 796928:tid 797152] [client 47.31.86.100:57998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OousTy9vX-htKvPkJqQAAAvc"]
[Mon Jul 20 06:03:46.583693 2026] [security2:error] [pid 796928:tid 797152] [client 47.31.86.100:57998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OousTy9vX-htKvPkJqQAAAvc"]
[Mon Jul 20 06:03:46.972441 2026] [core:error] [pid 796567:tid 796700] [client 14.225.17.146:51331] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:46.972467 2026] [core:error] [pid 796567:tid 796700] [client 14.225.17.146:51331] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:03:47.217447 2026] [security2:error] [pid 796567:tid 796741] [client 185.132.186.92:25231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/autoload_classmap.php"] [unique_id "al4Oo7LfyzVz2SrjZpim7QAAAkA"]
[Mon Jul 20 06:03:47.348203 2026] [security2:error] [pid 796567:tid 796734] [client 18.184.179.151:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4OorLfyzVz2SrjZpim2QAAAjk"]
[Mon Jul 20 06:03:47.396188 2026] [security2:error] [pid 796567:tid 796804] [client 18.184.179.151:46922] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4OorLfyzVz2SrjZpim2AAAAn8"]
[Mon Jul 20 06:03:47.410241 2026] [security2:error] [pid 796928:tid 797144] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oo-sTy9vX-htKvPkJywAAAu8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:47.410389 2026] [security2:error] [pid 796928:tid 797144] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oo-sTy9vX-htKvPkJywAAAu8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:47.482186 2026] [security2:error] [pid 796928:tid 797086] [client 14.225.17.146:61155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4OousTy9vX-htKvPkJrwAAArU"], referer: http://idigress.group/wordpress
[Mon Jul 20 06:03:47.782910 2026] [security2:error] [pid 796928:tid 797062] [client 173.72.54.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ0AAAAp0"], referer: https://mollycahill.com/
[Mon Jul 20 06:03:47.794167 2026] [security2:error] [pid 796928:tid 797103] [client 193.37.33.4:24873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ3wAAAsY"]
[Mon Jul 20 06:03:47.806407 2026] [security2:error] [pid 796567:tid 796713] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oo7LfyzVz2SrjZpim_AAAAiQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:47.849018 2026] [security2:error] [pid 796928:tid 797147] [client 103.153.183.69:9492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../etc/apache2/apache2.conf"] [unique_id "al4Oo-sTy9vX-htKvPkJ5AAAAvI"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:03:47.935391 2026] [security2:error] [pid 796567:tid 796753] [client 94.154.43.187:64588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.lzk.wao.mybluehost.me"] [uri "/.env"] [unique_id "al4Oo7LfyzVz2SrjZpinDQAAAkw"]
[Mon Jul 20 06:03:47.963513 2026] [security2:error] [pid 796567:tid 796747] [client 94.154.43.188:60362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lzk.wao.mybluehost.me"] [uri "/.env"] [unique_id "al4Oo7LfyzVz2SrjZpinEAAAAkY"]
[Mon Jul 20 06:03:48.197607 2026] [security2:error] [pid 796928:tid 797136] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OpOsTy9vX-htKvPkJ9AAAAuc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:48.232915 2026] [security2:error] [pid 796567:tid 796795] [client 77.110.127.138:54766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:s. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4OpLLfyzVz2SrjZpinFQAAAnY"]
[Mon Jul 20 06:03:48.240691 2026] [security2:error] [pid 796928:tid 797127] [client 15.229.42.239:32180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkJ9gAAAt4"]
[Mon Jul 20 06:03:48.240803 2026] [security2:error] [pid 796928:tid 797127] [client 15.229.42.239:32180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkJ9gAAAt4"]
[Mon Jul 20 06:03:48.292816 2026] [security2:error] [pid 796567:tid 796751] [client 34.173.238.42:57330] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "fbvrealtors.com"] [uri "/"] [unique_id "al4OpLLfyzVz2SrjZpinFgAAAko"]
[Mon Jul 20 06:03:48.374472 2026] [security2:error] [pid 796928:tid 796965] [remote 188.166.241.141:44916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4OpOsTy9vX-htKvPkJ_QAC9SQ"]
[Mon Jul 20 06:03:48.457328 2026] [security2:error] [pid 796928:tid 797168] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OpOsTy9vX-htKvPkKAwAAAwc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:48.503646 2026] [security2:error] [pid 796928:tid 797180] [client 115.246.21.170:2187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKCQAAAxM"]
[Mon Jul 20 06:03:48.503789 2026] [security2:error] [pid 796928:tid 797180] [client 115.246.21.170:2187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKCQAAAxM"]
[Mon Jul 20 06:03:48.552679 2026] [security2:error] [pid 796928:tid 797151] [client 86.98.90.58:49659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKEAAAAvY"]
[Mon Jul 20 06:03:48.557473 2026] [security2:error] [pid 796928:tid 797151] [client 86.98.90.58:49659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4OpOsTy9vX-htKvPkKEAAAAvY"]
[Mon Jul 20 06:03:48.568987 2026] [security2:error] [pid 796567:tid 796822] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OpLLfyzVz2SrjZpinFAACkTQ"]
[Mon Jul 20 06:03:48.683787 2026] [security2:error] [pid 796928:tid 797171] [client 14.225.17.146:51973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ1AAAAwo"], referer: http://nikkidesigns.net/wordpress
[Mon Jul 20 06:03:48.774534 2026] [security2:error] [pid 796928:tid 797032] [remote 188.166.241.141:44916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4OpOsTy9vX-htKvPkKFwACumc"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 06:03:48.861315 2026] [security2:error] [pid 796928:tid 797099] [client 14.225.17.146:50999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJvgAAAsI"], referer: http://ironcitywellness.com/wordpress
[Mon Jul 20 06:03:48.930703 2026] [security2:error] [pid 796928:tid 797095] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpOsTy9vX-htKvPkKDAAAAr4"]
[Mon Jul 20 06:03:49.045251 2026] [security2:error] [pid 796928:tid 797096] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpOsTy9vX-htKvPkKEgAAAr8"]
[Mon Jul 20 06:03:49.169864 2026] [security2:error] [pid 796928:tid 797155] [client 185.132.186.101:57379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/about.php"] [unique_id "al4OpesTy9vX-htKvPkKMgAAAvo"]
[Mon Jul 20 06:03:49.344195 2026] [security2:error] [pid 796567:tid 796699] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpLLfyzVz2SrjZpinMgAAAhY"]
[Mon Jul 20 06:03:49.375151 2026] [security2:error] [pid 796928:tid 796932] [remote 152.228.213.32:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpesTy9vX-htKvPkKPQADDwM"]
[Mon Jul 20 06:03:49.413773 2026] [security2:error] [pid 796567:tid 796787] [client 57.141.18.55:55808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4On7LfyzVz2SrjZpimSwACbmk"]
[Mon Jul 20 06:03:49.427621 2026] [security2:error] [pid 796928:tid 797098] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OpesTy9vX-htKvPkKOwAAAsE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:49.568792 2026] [security2:error] [pid 796567:tid 796725] [client 14.225.17.146:51956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Oo7LfyzVz2SrjZpinAQAAAjA"], referer: http://according2plant.com/wordpress
[Mon Jul 20 06:03:49.571824 2026] [security2:error] [pid 796928:tid 797089] [client 129.222.187.209:18872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OpesTy9vX-htKvPkKSwAAArg"]
[Mon Jul 20 06:03:49.579595 2026] [security2:error] [pid 796928:tid 797089] [client 129.222.187.209:18872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OpesTy9vX-htKvPkKSwAAArg"]
[Mon Jul 20 06:03:49.589077 2026] [security2:error] [pid 796928:tid 796958] [remote 152.228.213.32:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpesTy9vX-htKvPkKTQACmR0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:49.922515 2026] [autoindex:error] [pid 796928:tid 797173] [client 14.225.17.146:61444] AH01276: Cannot serve directory /home3/thedocz6/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://thedoctorscuisine.com/wordpress
[Mon Jul 20 06:03:49.987519 2026] [autoindex:error] [pid 796928:tid 797184] [client 13.215.47.127:48398] AH01276: Cannot serve directory /home4/curlsnp2/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://curlsnpearlsss.com/wordpress
[Mon Jul 20 06:03:50.086875 2026] [security2:error] [pid 796928:tid 797151] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKdAAAAvY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:50.124373 2026] [security2:error] [pid 796567:tid 796703] [client 18.141.57.241:10996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4OpbLfyzVz2SrjZpinOwAAAho"]
[Mon Jul 20 06:03:50.125024 2026] [security2:error] [pid 796567:tid 796784] [client 41.173.37.102:10551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OprLfyzVz2SrjZpinWAAAAms"]
[Mon Jul 20 06:03:50.125167 2026] [security2:error] [pid 796567:tid 796784] [client 41.173.37.102:10551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OprLfyzVz2SrjZpinWAAAAms"]
[Mon Jul 20 06:03:50.141732 2026] [security2:error] [pid 796567:tid 796804] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpbLfyzVz2SrjZpinOQAAAn8"]
[Mon Jul 20 06:03:50.151026 2026] [security2:error] [pid 796928:tid 797183] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpesTy9vX-htKvPkKLgAAAxY"]
[Mon Jul 20 06:03:50.257189 2026] [security2:error] [pid 796567:tid 796806] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpbLfyzVz2SrjZpinOgAAAoE"]
[Mon Jul 20 06:03:50.269059 2026] [security2:error] [pid 796928:tid 797158] [client 34.101.165.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4OpesTy9vX-htKvPkKLwAAAv0"]
[Mon Jul 20 06:03:50.283513 2026] [security2:error] [pid 796567:tid 796811] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpbLfyzVz2SrjZpinTQAAAoY"]
[Mon Jul 20 06:03:50.315822 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:53217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4OpLLfyzVz2SrjZpinLgAAAn0"], referer: http://mourgroup.com/wordpress
[Mon Jul 20 06:03:50.320920 2026] [security2:error] [pid 796928:tid 797028] [remote 192.241.143.148:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKhgAC32M"]
[Mon Jul 20 06:03:50.356127 2026] [security2:error] [pid 796928:tid 797090] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OpusTy9vX-htKvPkKgAAAArk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:50.503348 2026] [security2:error] [pid 796928:tid 797127] [client 103.95.123.246:19632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKjgAAAt4"]
[Mon Jul 20 06:03:50.503392 2026] [security2:error] [pid 796928:tid 797027] [remote 192.241.143.148:38470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKjwACmmI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:03:50.503500 2026] [security2:error] [pid 796928:tid 797127] [client 103.95.123.246:19632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKjgAAAt4"]
[Mon Jul 20 06:03:50.696688 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKlgAAAws"]
[Mon Jul 20 06:03:50.696819 2026] [security2:error] [pid 796928:tid 797172] [client 210.212.97.243:10434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKlgAAAws"]
[Mon Jul 20 06:03:50.715382 2026] [security2:error] [pid 796928:tid 797008] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKmwADDk8"]
[Mon Jul 20 06:03:50.715710 2026] [security2:error] [pid 796928:tid 797175] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OpusTy9vX-htKvPkKmwADDk8"]
[Mon Jul 20 06:03:50.902755 2026] [security2:error] [pid 796928:tid 797006] [remote 209.42.18.223:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4OpusTy9vX-htKvPkKrAAC400"]
[Mon Jul 20 06:03:50.957275 2026] [security2:error] [pid 796928:tid 797105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpusTy9vX-htKvPkKnAAAAsg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:51.091658 2026] [security2:error] [pid 796928:tid 797011] [remote 209.42.18.223:57118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKuwAC-1I"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:03:51.130364 2026] [security2:error] [pid 796928:tid 797016] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.165.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKuQAC91c"], referer: https://jenfarley.com/login
[Mon Jul 20 06:03:51.178897 2026] [security2:error] [pid 796928:tid 797076] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OpusTy9vX-htKvPkKqwAAAqs"]
[Mon Jul 20 06:03:51.329212 2026] [security2:error] [pid 796928:tid 797173] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKyAAAAww"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:51.377859 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Op7LfyzVz2SrjZpinfwAAAjY"]
[Mon Jul 20 06:03:51.377992 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Op7LfyzVz2SrjZpinfwAAAjY"]
[Mon Jul 20 06:03:51.395681 2026] [security2:error] [pid 796928:tid 797064] [client 193.37.33.1:50943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Op-sTy9vX-htKvPkKyQAAAp8"]
[Mon Jul 20 06:03:51.499767 2026] [security2:error] [pid 796567:tid 796732] [client 57.141.18.105:44920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OobLfyzVz2SrjZpimrgACNzk"]
[Mon Jul 20 06:03:51.699286 2026] [security2:error] [pid 796567:tid 796797] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Op7LfyzVz2SrjZpinfgAAAng"]
[Mon Jul 20 06:03:51.711205 2026] [security2:error] [pid 796928:tid 797138] [client 103.153.183.69:26640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xc0\\xaf..\\xc0\\xafhome/.env"] [unique_id "al4Op-sTy9vX-htKvPkK4AAAAuk"], referer: https://t.co/b0xpmli95u
[Mon Jul 20 06:03:51.949004 2026] [security2:error] [pid 796928:tid 797123] [client 164.100.212.184:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Op-sTy9vX-htKvPkK6gAAAto"]
[Mon Jul 20 06:03:51.949110 2026] [security2:error] [pid 796928:tid 797123] [client 164.100.212.184:65453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Op-sTy9vX-htKvPkK6gAAAto"]
[Mon Jul 20 06:03:52.081382 2026] [proxy:error] [pid 796567:tid 796724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:52.081438 2026] [proxy_http:error] [pid 796567:tid 796724] [client 195.96.139.226:38445] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:52.082659 2026] [proxy:error] [pid 796567:tid 796724] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:52.082695 2026] [proxy_http:error] [pid 796567:tid 796724] [client 195.96.139.226:38445] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:52.151155 2026] [security2:error] [pid 796567:tid 796767] [client 185.132.186.69:58307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/about.php"] [unique_id "al4OqLLfyzVz2SrjZpinmgAAAlo"]
[Mon Jul 20 06:03:52.167709 2026] [security2:error] [pid 796567:tid 796756] [client 103.149.16.77:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinmwAAAk8"]
[Mon Jul 20 06:03:52.167856 2026] [security2:error] [pid 796567:tid 796756] [client 103.149.16.77:63207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinmwAAAk8"]
[Mon Jul 20 06:03:52.271596 2026] [security2:error] [pid 796567:tid 796701] [client 181.224.94.124:45782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinnQAAAhg"]
[Mon Jul 20 06:03:52.271709 2026] [security2:error] [pid 796567:tid 796701] [client 181.224.94.124:45782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqLLfyzVz2SrjZpinnQAAAhg"]
[Mon Jul 20 06:03:52.711606 2026] [security2:error] [pid 796928:tid 797122] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OqOsTy9vX-htKvPkLDwAAAtk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:52.722370 2026] [security2:error] [pid 796928:tid 797039] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.165.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4OqOsTy9vX-htKvPkLFwACpG4"], referer: https://jenfarley.com/wp-admin/
[Mon Jul 20 06:03:52.898894 2026] [security2:error] [pid 796567:tid 796801] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqLLfyzVz2SrjZpinrAAAAnw"]
[Mon Jul 20 06:03:52.972813 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:50508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Op-sTy9vX-htKvPkKxAAAAro"], referer: http://colinkeyphotography.com/wordpress
[Mon Jul 20 06:03:53.011038 2026] [security2:error] [pid 796928:tid 797078] [client 14.225.17.146:61495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Op-sTy9vX-htKvPkK5QAAAq0"], referer: http://headachescarpaltunnelfibromyalgia.com/wordpress
[Mon Jul 20 06:03:53.298089 2026] [security2:error] [pid 796567:tid 796734] [client 129.222.187.209:50700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqbLfyzVz2SrjZpinwQAAAjk"]
[Mon Jul 20 06:03:53.304291 2026] [security2:error] [pid 796567:tid 796734] [client 129.222.187.209:50700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OqbLfyzVz2SrjZpinwQAAAjk"]
[Mon Jul 20 06:03:53.323675 2026] [security2:error] [pid 796928:tid 797147] [client 72.255.10.154:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLJwAAAvI"]
[Mon Jul 20 06:03:53.323831 2026] [security2:error] [pid 796928:tid 797147] [client 72.255.10.154:63489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLJwAAAvI"]
[Mon Jul 20 06:03:53.377251 2026] [security2:error] [pid 796928:tid 797100] [client 106.192.104.4:56979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLKQAAAsM"]
[Mon Jul 20 06:03:53.377386 2026] [security2:error] [pid 796928:tid 797100] [client 106.192.104.4:56979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLKQAAAsM"]
[Mon Jul 20 06:03:53.390176 2026] [security2:error] [pid 796928:tid 797111] [client 14.225.17.146:61430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4OpusTy9vX-htKvPkKmAAAAs4"], referer: http://careysheatingandcooling.com/wordpress
[Mon Jul 20 06:03:53.411627 2026] [security2:error] [pid 796928:tid 797181] [client 14.225.17.146:59257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4Op-sTy9vX-htKvPkK1wAAAxQ"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/wordpress
[Mon Jul 20 06:03:53.447013 2026] [security2:error] [pid 796928:tid 797058] [client 13.201.64.214:17704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLLwAAApk"]
[Mon Jul 20 06:03:53.447122 2026] [security2:error] [pid 796928:tid 797058] [client 13.201.64.214:17704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OqesTy9vX-htKvPkLLwAAApk"]
[Mon Jul 20 06:03:53.451166 2026] [security2:error] [pid 796928:tid 797130] [client 57.141.18.67:55594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oo-sTy9vX-htKvPkJ0gAC4VM"]
[Mon Jul 20 06:03:53.700898 2026] [security2:error] [pid 796567:tid 796813] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqbLfyzVz2SrjZpinyQAAAog"]
[Mon Jul 20 06:03:53.810691 2026] [security2:error] [pid 796928:tid 797138] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OqesTy9vX-htKvPkLQAAAAuk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:53.914608 2026] [security2:error] [pid 796928:tid 797109] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqesTy9vX-htKvPkLOQAAAsw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:54.109616 2026] [security2:error] [pid 796928:tid 797078] [client 185.132.186.58:35447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/fonts/database.php"] [unique_id "al4OqusTy9vX-htKvPkLTQAAAq0"]
[Mon Jul 20 06:03:54.396021 2026] [proxy:error] [pid 796928:tid 797080] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:54.396104 2026] [proxy_http:error] [pid 796928:tid 797080] [client 198.235.24.25:61872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:54.396837 2026] [proxy:error] [pid 796928:tid 797080] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:03:54.396865 2026] [proxy_http:error] [pid 796928:tid 797080] [client 198.235.24.25:61872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:03:54.425821 2026] [security2:error] [pid 796928:tid 797153] [client 13.201.64.214:17714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OqusTy9vX-htKvPkLYQAAAvg"]
[Mon Jul 20 06:03:54.445681 2026] [security2:error] [pid 796928:tid 797144] [client 57.141.18.99:46298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OpOsTy9vX-htKvPkKCAAC7wY"]
[Mon Jul 20 06:03:54.450640 2026] [security2:error] [pid 796928:tid 797015] [remote 34.101.165.107:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.165.101.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4OqusTy9vX-htKvPkLZQADFFY"], referer: https://jenfarley.com/wp-admin/
[Mon Jul 20 06:03:54.552777 2026] [security2:error] [pid 796567:tid 796759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OqrLfyzVz2SrjZpin3QAAAlI"]
[Mon Jul 20 06:03:55.275231 2026] [security2:error] [pid 796567:tid 796748] [client 13.229.83.156:28834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Oq7LfyzVz2SrjZpioBAAAAkc"]
[Mon Jul 20 06:03:55.280168 2026] [security2:error] [pid 796928:tid 797143] [client 14.225.17.146:55668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4OqesTy9vX-htKvPkLSAAAAu4"], referer: http://getgarrison.com/wordpress
[Mon Jul 20 06:03:55.376113 2026] [security2:error] [pid 796928:tid 797145] [client 3.109.4.218:45650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Oq-sTy9vX-htKvPkLlAAAAvA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:03:55.431160 2026] [security2:error] [pid 796928:tid 797155] [client 14.225.17.146:51399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Oq-sTy9vX-htKvPkLjAAAAvo"]
[Mon Jul 20 06:03:55.546569 2026] [security2:error] [pid 796928:tid 797150] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oq-sTy9vX-htKvPkLngAAAvU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:55.701946 2026] [security2:error] [pid 796928:tid 797150] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Oq-sTy9vX-htKvPkLngAAAvU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:55.708687 2026] [security2:error] [pid 796567:tid 796646] [remote 154.66.198.148:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Oq7LfyzVz2SrjZpioDgACWU4"]
[Mon Jul 20 06:03:55.749502 2026] [security2:error] [pid 796928:tid 797183] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oq-sTy9vX-htKvPkLjwAAAxY"]
[Mon Jul 20 06:03:56.057191 2026] [security2:error] [pid 796928:tid 797171] [client 185.132.186.81:39819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ff2.php"] [unique_id "al4OrOsTy9vX-htKvPkLtQAAAwo"]
[Mon Jul 20 06:03:56.057938 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLtgAAAwU"]
[Mon Jul 20 06:03:56.058026 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLtgAAAwU"]
[Mon Jul 20 06:03:56.216402 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.110:37418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OprLfyzVz2SrjZpinWQACcgY"]
[Mon Jul 20 06:03:56.278991 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oq7LfyzVz2SrjZpioEwAAAl0"]
[Mon Jul 20 06:03:56.308555 2026] [security2:error] [pid 796928:tid 797168] [client 150.228.148.150:1126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLygAAAwc"]
[Mon Jul 20 06:03:56.308699 2026] [security2:error] [pid 796928:tid 797168] [client 150.228.148.150:1126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OrOsTy9vX-htKvPkLygAAAwc"]
[Mon Jul 20 06:03:56.332719 2026] [security2:error] [pid 796928:tid 796966] [remote 202.51.202.242:47356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OrOsTy9vX-htKvPkLywACoSU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:03:56.344127 2026] [security2:error] [pid 796567:tid 796716] [client 13.215.47.127:27114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OrLLfyzVz2SrjZpioIgAAAic"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:03:56.494483 2026] [security2:error] [pid 796928:tid 797175] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OrOsTy9vX-htKvPkL1wAAAw4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:56.647895 2026] [security2:error] [pid 796567:tid 796592] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OrLLfyzVz2SrjZpioLgACTRg"]
[Mon Jul 20 06:03:56.648106 2026] [security2:error] [pid 796567:tid 796754] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OrLLfyzVz2SrjZpioLgACTRg"]
[Mon Jul 20 06:03:56.719928 2026] [security2:error] [pid 796928:tid 797078] [client 14.225.17.146:62287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4OrOsTy9vX-htKvPkLxgAAAq0"], referer: http://overloadcomedy.com/wordpress
[Mon Jul 20 06:03:56.740650 2026] [security2:error] [pid 796928:tid 797182] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrOsTy9vX-htKvPkL2wAAAxU"]
[Mon Jul 20 06:03:57.011022 2026] [security2:error] [pid 796567:tid 796762] [client 47.31.86.100:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OrbLfyzVz2SrjZpioPAAAAlU"]
[Mon Jul 20 06:03:57.011239 2026] [security2:error] [pid 796567:tid 796762] [client 47.31.86.100:58429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OrbLfyzVz2SrjZpioPAAAAlU"]
[Mon Jul 20 06:03:57.025424 2026] [security2:error] [pid 796567:tid 796591] [remote 154.66.198.148:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OrbLfyzVz2SrjZpioPQACkhc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:03:57.202597 2026] [security2:error] [pid 796928:tid 797141] [client 114.119.156.181:25673] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/category/tablescapes/holidays-tablescapes/cinco-de-mayo-tablescapes/"] [unique_id "al4OresTy9vX-htKvPkL-QAAAuw"], referer: https://lifeisbetterlakeside.com/lemurs-up-close-and-personal-at-the-alabama-gulf-coast-zoo-part-2/
[Mon Jul 20 06:03:57.253573 2026] [security2:error] [pid 796928:tid 797111] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OresTy9vX-htKvPkL-gAAAs4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:57.393262 2026] [security2:error] [pid 796567:tid 796698] [client 45.157.112.60:24997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OrbLfyzVz2SrjZpioTAAAAhU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:57.738309 2026] [security2:error] [pid 796928:tid 797081] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OresTy9vX-htKvPkMEwAAArA"]
[Mon Jul 20 06:03:57.968421 2026] [security2:error] [pid 796567:tid 796760] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrbLfyzVz2SrjZpioRwAAAlM"]
[Mon Jul 20 06:03:57.999521 2026] [security2:error] [pid 796567:tid 796758] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrbLfyzVz2SrjZpioUwAAAlE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:58.005655 2026] [security2:error] [pid 796928:tid 797059] [client 185.132.186.104:52701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Exception-wp.php"] [unique_id "al4OrusTy9vX-htKvPkMKQAAApo"]
[Mon Jul 20 06:03:58.179846 2026] [security2:error] [pid 796928:tid 797137] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OresTy9vX-htKvPkMHwAAAug"]
[Mon Jul 20 06:03:58.225143 2026] [security2:error] [pid 796928:tid 797116] [client 50.116.65.227:59178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OrusTy9vX-htKvPkMMwAAAtM"]
[Mon Jul 20 06:03:58.236701 2026] [security2:error] [pid 796928:tid 797113] [client 50.116.65.227:59186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OrusTy9vX-htKvPkMNAAAAtA"]
[Mon Jul 20 06:03:58.366547 2026] [security2:error] [pid 796567:tid 796742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrrLfyzVz2SrjZpioZgAAAkE"]
[Mon Jul 20 06:03:58.621697 2026] [security2:error] [pid 796567:tid 796812] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrrLfyzVz2SrjZpiobQAAAoc"]
[Mon Jul 20 06:03:58.638133 2026] [security2:error] [pid 796928:tid 797088] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OrusTy9vX-htKvPkMSwAAArc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:58.724471 2026] [security2:error] [pid 796567:tid 796598] [remote 5.223.65.249:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4OrrLfyzVz2SrjZpiodAACSx4"]
[Mon Jul 20 06:03:58.813050 2026] [security2:error] [pid 796928:tid 797093] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OrusTy9vX-htKvPkMVwAAArw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:58.853188 2026] [security2:error] [pid 796928:tid 797085] [client 15.229.42.239:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.42.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OrusTy9vX-htKvPkMWQAAArQ"]
[Mon Jul 20 06:03:58.853337 2026] [security2:error] [pid 796928:tid 797085] [client 15.229.42.239:55360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OrusTy9vX-htKvPkMWQAAArQ"]
[Mon Jul 20 06:03:58.879510 2026] [security2:error] [pid 796928:tid 797125] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4OrusTy9vX-htKvPkMVQAAAtw"], referer: https://effingweirdmuseums.com/.git/config
[Mon Jul 20 06:03:58.966580 2026] [security2:error] [pid 796567:tid 796735] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OrrLfyzVz2SrjZpiodQAAAjo"]
[Mon Jul 20 06:03:58.988404 2026] [security2:error] [pid 796928:tid 797123] [client 66.249.79.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4OrusTy9vX-htKvPkMTAAC2mk"]
[Mon Jul 20 06:03:59.112938 2026] [security2:error] [pid 796928:tid 797062] [client 115.246.21.170:8008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMbQAAAp0"]
[Mon Jul 20 06:03:59.113080 2026] [security2:error] [pid 796928:tid 797062] [client 115.246.21.170:8008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMbQAAAp0"]
[Mon Jul 20 06:03:59.164910 2026] [security2:error] [pid 796567:tid 796608] [remote 5.223.65.249:56528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4Or7LfyzVz2SrjZpiogwACLCg"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 06:03:59.205978 2026] [security2:error] [pid 796567:tid 796750] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OrrLfyzVz2SrjZpioeQACSUw"]
[Mon Jul 20 06:03:59.221641 2026] [security2:error] [pid 796928:tid 797127] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Or-sTy9vX-htKvPkMbgAAAt4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:03:59.301048 2026] [security2:error] [pid 796928:tid 797130] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or-sTy9vX-htKvPkMbAAAAuE"]
[Mon Jul 20 06:03:59.353901 2026] [security2:error] [pid 796928:tid 797076] [client 77.110.127.138:54677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or-sTy9vX-htKvPkMagAAAqs"]
[Mon Jul 20 06:03:59.589038 2026] [security2:error] [pid 796567:tid 796777] [client 158.173.166.181:26663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Or7LfyzVz2SrjZpiomgAAAmQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:03:59.633889 2026] [security2:error] [pid 796567:tid 796747] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or7LfyzVz2SrjZpiokgAAAkY"]
[Mon Jul 20 06:03:59.675649 2026] [security2:error] [pid 796567:tid 796729] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or7LfyzVz2SrjZpiokQAAAjQ"]
[Mon Jul 20 06:03:59.751561 2026] [security2:error] [pid 796567:tid 796744] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Or7LfyzVz2SrjZpiolwAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:03:59.785025 2026] [security2:error] [pid 796567:tid 796660] [remote 20.173.88.122:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4Or7LfyzVz2SrjZpionwACFVw"]
[Mon Jul 20 06:03:59.902340 2026] [security2:error] [pid 796928:tid 797058] [client 86.98.90.58:50487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMkgAAApk"]
[Mon Jul 20 06:03:59.902486 2026] [security2:error] [pid 796928:tid 797058] [client 86.98.90.58:50487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Or-sTy9vX-htKvPkMkgAAApk"]
[Mon Jul 20 06:03:59.954808 2026] [security2:error] [pid 796928:tid 797163] [client 185.132.186.57:50751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/plugin.php"] [unique_id "al4Or-sTy9vX-htKvPkMnAAAAwI"]
[Mon Jul 20 06:03:59.983783 2026] [security2:error] [pid 796567:tid 796776] [client 158.173.89.95:21809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Or7LfyzVz2SrjZpioqQAAAmM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:00.065594 2026] [security2:error] [pid 796928:tid 797185] [client 57.141.18.110:37426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OqusTy9vX-htKvPkLaAADGGQ"]
[Mon Jul 20 06:04:00.163424 2026] [security2:error] [pid 796567:tid 796676] [remote 20.173.88.122:37814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4OsLLfyzVz2SrjZpiorQACW2w"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:04:00.271978 2026] [security2:error] [pid 796928:tid 797178] [client 129.222.187.209:29321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMogAAAxE"]
[Mon Jul 20 06:04:00.282722 2026] [security2:error] [pid 796928:tid 797178] [client 129.222.187.209:29321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMogAAAxE"]
[Mon Jul 20 06:04:00.356445 2026] [security2:error] [pid 796567:tid 796675] [remote 47.86.33.52:31078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OsLLfyzVz2SrjZpiosAACRWs"]
[Mon Jul 20 06:04:00.512867 2026] [security2:error] [pid 796928:tid 797086] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsOsTy9vX-htKvPkMsAAAArU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:00.595859 2026] [security2:error] [pid 796928:tid 797083] [client 193.19.109.211:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "getgarrison.com"] [uri "/wp-login.php"] [unique_id "al4OsOsTy9vX-htKvPkMswAAArI"]
[Mon Jul 20 06:04:00.741482 2026] [security2:error] [pid 796928:tid 797037] [remote 8.217.108.67:12758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OsOsTy9vX-htKvPkMwgACxmw"]
[Mon Jul 20 06:04:00.773932 2026] [security2:error] [pid 796928:tid 797176] [client 41.173.37.102:10969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMxgAAAw8"]
[Mon Jul 20 06:04:00.774104 2026] [security2:error] [pid 796928:tid 797176] [client 41.173.37.102:10969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OsOsTy9vX-htKvPkMxgAAAw8"]
[Mon Jul 20 06:04:00.782999 2026] [security2:error] [pid 796928:tid 797089] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OsOsTy9vX-htKvPkMwAAAArg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:00.866004 2026] [security2:error] [pid 796567:tid 796669] [remote 47.86.33.52:31078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OsLLfyzVz2SrjZpioxAACdWU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:00.915688 2026] [security2:error] [pid 796928:tid 797109] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMvwAAAsw"]
[Mon Jul 20 06:04:01.047765 2026] [security2:error] [pid 796928:tid 797105] [client 178.152.178.232:36691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM3QAAAsg"]
[Mon Jul 20 06:04:01.047917 2026] [security2:error] [pid 796928:tid 797105] [client 178.152.178.232:36691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM3QAAAsg"]
[Mon Jul 20 06:04:01.105677 2026] [security2:error] [pid 796928:tid 797173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMxQAAAww"]
[Mon Jul 20 06:04:01.134134 2026] [security2:error] [pid 796928:tid 797152] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMygAAAvc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:01.141367 2026] [security2:error] [pid 796928:tid 797147] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkM4gAAAvI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:01.149506 2026] [security2:error] [pid 796928:tid 797113] [client 216.73.217.138:52738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkM3AAC0BM"]
[Mon Jul 20 06:04:01.204622 2026] [security2:error] [pid 796567:tid 796707] [client 210.212.97.243:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio2AAAAh4"]
[Mon Jul 20 06:04:01.204787 2026] [security2:error] [pid 796567:tid 796707] [client 210.212.97.243:10435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio2AAAAh4"]
[Mon Jul 20 06:04:01.246480 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkM2wAAAtg"]
[Mon Jul 20 06:04:01.250570 2026] [security2:error] [pid 796928:tid 797127] [client 14.225.17.146:62355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMvQAAAt4"], referer: http://bruceledewitz.com/wordpress
[Mon Jul 20 06:04:01.253337 2026] [security2:error] [pid 796928:tid 796945] [remote 8.217.108.67:12758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkM6QACmxA"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:04:01.319339 2026] [security2:error] [pid 796567:tid 796671] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio4QACd2c"]
[Mon Jul 20 06:04:01.319550 2026] [security2:error] [pid 796567:tid 796796] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio4QACd2c"]
[Mon Jul 20 06:04:01.379839 2026] [security2:error] [pid 796928:tid 797078] [client 103.95.123.246:20127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM8gAAAq0"]
[Mon Jul 20 06:04:01.379952 2026] [security2:error] [pid 796928:tid 797078] [client 103.95.123.246:20127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OsesTy9vX-htKvPkM8gAAAq0"]
[Mon Jul 20 06:04:01.417294 2026] [security2:error] [pid 796567:tid 796726] [client 27.96.94.195:36944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OsbLfyzVz2SrjZpio1QAAAjE"]
[Mon Jul 20 06:04:01.709796 2026] [security2:error] [pid 796928:tid 797160] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkNAAAAAv8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:01.709948 2026] [security2:error] [pid 796928:tid 797160] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OsesTy9vX-htKvPkNAAAAAv8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:01.757955 2026] [security2:error] [pid 796567:tid 796785] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio2gAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:01.833048 2026] [security2:error] [pid 796567:tid 796762] [client 69.171.231.113:54564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio6AACVQ0"]
[Mon Jul 20 06:04:01.899282 2026] [security2:error] [pid 796567:tid 796804] [client 185.132.186.69:53607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/autoload_classmap.php"] [unique_id "al4OsbLfyzVz2SrjZpio7gAAAn8"]
[Mon Jul 20 06:04:01.931878 2026] [security2:error] [pid 796928:tid 797088] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkNBQACtyo"], referer: http://ali-alghanim.net/wordpress
[Mon Jul 20 06:04:02.154319 2026] [security2:error] [pid 796567:tid 796808] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio2QAAAoM"]
[Mon Jul 20 06:04:02.220363 2026] [security2:error] [pid 796567:tid 796730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsbLfyzVz2SrjZpio5AAAAjU"]
[Mon Jul 20 06:04:02.507357 2026] [security2:error] [pid 796928:tid 797119] [client 164.100.212.184:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNKAAAAtY"]
[Mon Jul 20 06:04:02.507464 2026] [security2:error] [pid 796928:tid 797119] [client 164.100.212.184:49789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNKAAAAtY"]
[Mon Jul 20 06:04:02.520011 2026] [security2:error] [pid 796567:tid 796755] [client 57.141.18.73:41124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OrbLfyzVz2SrjZpioSgACTlI"]
[Mon Jul 20 06:04:02.624483 2026] [security2:error] [pid 796928:tid 797176] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsusTy9vX-htKvPkNIgAAAw8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:02.655209 2026] [security2:error] [pid 796567:tid 796752] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsrLfyzVz2SrjZpipBAAAAks"]
[Mon Jul 20 06:04:02.692828 2026] [security2:error] [pid 796928:tid 796989] [remote 130.185.118.215:40316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNNQAC5Dw"]
[Mon Jul 20 06:04:02.692986 2026] [security2:error] [pid 796928:tid 797133] [client 130.185.118.215:40316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNNQAC5Dw"]
[Mon Jul 20 06:04:02.890620 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNPwAAAsQ"]
[Mon Jul 20 06:04:02.890848 2026] [security2:error] [pid 796928:tid 797101] [client 103.149.16.77:63705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OsusTy9vX-htKvPkNPwAAAsQ"]
[Mon Jul 20 06:04:02.946313 2026] [proxy:error] [pid 796567:tid 796771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:02.946365 2026] [proxy_http:error] [pid 796567:tid 796771] [client 91.92.40.117:40828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:02.946784 2026] [proxy:error] [pid 796567:tid 796771] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:02.946806 2026] [proxy_http:error] [pid 796567:tid 796771] [client 91.92.40.117:40828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:02.946886 2026] [security2:error] [pid 796567:tid 796771] [client 91.92.40.117:40828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.according2plant.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4OsrLfyzVz2SrjZpipEwAAAl4"]
[Mon Jul 20 06:04:03.011201 2026] [security2:error] [pid 796567:tid 796725] [client 193.19.109.236:52427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cygnuswines.co.uk"] [uri "/wp-login.php"] [unique_id "al4Os7LfyzVz2SrjZpipGAAAAjA"]
[Mon Jul 20 06:04:03.135189 2026] [security2:error] [pid 796928:tid 797164] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNTgAAAwM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:03.195655 2026] [security2:error] [pid 796928:tid 797069] [client 181.224.94.124:21486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNVAAAAqQ"]
[Mon Jul 20 06:04:03.195840 2026] [security2:error] [pid 796928:tid 797069] [client 181.224.94.124:21486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNVAAAAqQ"]
[Mon Jul 20 06:04:03.302844 2026] [proxy:error] [pid 796928:tid 797096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:03.302932 2026] [proxy_http:error] [pid 796928:tid 797096] [client 91.92.40.117:40844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:03.304131 2026] [proxy:error] [pid 796928:tid 797096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:03.304165 2026] [proxy_http:error] [pid 796928:tid 797096] [client 91.92.40.117:40844] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:03.304283 2026] [security2:error] [pid 796928:tid 797096] [client 91.92.40.117:40844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.according2plant.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4Os-sTy9vX-htKvPkNWQAAAr8"]
[Mon Jul 20 06:04:03.326277 2026] [security2:error] [pid 796567:tid 796713] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OsrLfyzVz2SrjZpipFQAAAiQ"]
[Mon Jul 20 06:04:03.400799 2026] [security2:error] [pid 796928:tid 797117] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNRwAAAtQ"]
[Mon Jul 20 06:04:03.446225 2026] [security2:error] [pid 796928:tid 797090] [client 47.128.52.83:48528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/news/"] [unique_id "al4Os-sTy9vX-htKvPkNXAAAArk"]
[Mon Jul 20 06:04:03.502967 2026] [security2:error] [pid 796928:tid 797073] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Os-sTy9vX-htKvPkNYAAAAqg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:03.513300 2026] [security2:error] [pid 796928:tid 797020] [remote 144.79.133.30:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Os-sTy9vX-htKvPkNYQACz1s"]
[Mon Jul 20 06:04:03.715960 2026] [security2:error] [pid 796567:tid 796761] [client 13.201.64.214:63250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Os7LfyzVz2SrjZpipQAAAAlQ"]
[Mon Jul 20 06:04:03.716060 2026] [security2:error] [pid 796567:tid 796761] [client 13.201.64.214:63250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Os7LfyzVz2SrjZpipQAAAAlQ"]
[Mon Jul 20 06:04:03.787880 2026] [security2:error] [pid 796928:tid 797127] [client 129.222.187.209:27934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNdQAAAt4"]
[Mon Jul 20 06:04:03.788105 2026] [security2:error] [pid 796928:tid 797127] [client 129.222.187.209:27934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNdQAAAt4"]
[Mon Jul 20 06:04:03.827899 2026] [security2:error] [pid 796928:tid 797095] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Os-sTy9vX-htKvPkNdAAAAr4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:03.839372 2026] [security2:error] [pid 796567:tid 796730] [client 185.132.186.86:29307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/jp.php"] [unique_id "al4Os7LfyzVz2SrjZpipRgAAAjU"]
[Mon Jul 20 06:04:03.955553 2026] [security2:error] [pid 796928:tid 797098] [client 72.255.10.154:26446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNewAAAsE"]
[Mon Jul 20 06:04:03.955697 2026] [security2:error] [pid 796928:tid 797098] [client 72.255.10.154:26446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Os-sTy9vX-htKvPkNewAAAsE"]
[Mon Jul 20 06:04:04.179739 2026] [security2:error] [pid 796928:tid 797133] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNbAAAAuQ"]
[Mon Jul 20 06:04:04.216919 2026] [security2:error] [pid 796928:tid 797008] [remote 192.241.143.148:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNgQADFk8"]
[Mon Jul 20 06:04:04.258174 2026] [security2:error] [pid 796567:tid 796708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Os7LfyzVz2SrjZpipQgAAAh8"]
[Mon Jul 20 06:04:04.337739 2026] [security2:error] [pid 796928:tid 797162] [client 13.201.64.214:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNhgAAAwE"]
[Mon Jul 20 06:04:04.337839 2026] [security2:error] [pid 796928:tid 797162] [client 13.201.64.214:63254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNhgAAAwE"]
[Mon Jul 20 06:04:04.411443 2026] [security2:error] [pid 796928:tid 796993] [remote 192.241.143.148:59262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNigACpUA"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:04:04.468507 2026] [security2:error] [pid 796928:tid 797092] [client 106.192.104.4:57509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNjgAAArs"]
[Mon Jul 20 06:04:04.468695 2026] [security2:error] [pid 796928:tid 797092] [client 106.192.104.4:57509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4OtOsTy9vX-htKvPkNjgAAArs"]
[Mon Jul 20 06:04:04.515961 2026] [security2:error] [pid 796567:tid 796750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipUgAAAkk"]
[Mon Jul 20 06:04:04.542008 2026] [security2:error] [pid 796928:tid 797072] [client 62.150.67.110:24572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4OtOsTy9vX-htKvPkNiwAAAqc"]
[Mon Jul 20 06:04:04.599138 2026] [security2:error] [pid 796567:tid 796735] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipWgAAAjo"]
[Mon Jul 20 06:04:04.686011 2026] [security2:error] [pid 796928:tid 797112] [client 104.234.53.77:39881] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNlwAAAs8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:04.812970 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipYAAAAiU"]
[Mon Jul 20 06:04:04.921273 2026] [security2:error] [pid 796928:tid 797031] [remote 144.79.133.30:42750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4OtOsTy9vX-htKvPkNnQACqmY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:04:05.090698 2026] [security2:error] [pid 796928:tid 797180] [client 14.225.17.146:53968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNTwAAAxM"], referer: http://nwcarvingacademy.com/wordpress
[Mon Jul 20 06:04:05.527201 2026] [security2:error] [pid 796567:tid 796723] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtbLfyzVz2SrjZpipeAAAAi4"]
[Mon Jul 20 06:04:05.557242 2026] [security2:error] [pid 796928:tid 797155] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNuwAAAvo"]
[Mon Jul 20 06:04:05.682042 2026] [security2:error] [pid 796928:tid 797172] [client 57.141.18.8:49672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMowADC3E"]
[Mon Jul 20 06:04:05.709522 2026] [security2:error] [pid 796567:tid 796775] [client 77.110.127.138:54768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OtbLfyzVz2SrjZpipgwAAAmI"]
[Mon Jul 20 06:04:05.776965 2026] [security2:error] [pid 796928:tid 797125] [client 185.132.186.100:24057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-atom.php"] [unique_id "al4OtesTy9vX-htKvPkN3QAAAtw"]
[Mon Jul 20 06:04:05.783436 2026] [security2:error] [pid 796567:tid 796778] [client 173.252.70.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.younutrition.gr"] [uri "/index.php"] [unique_id "al4Os7LfyzVz2SrjZpipMwAAAmU"]
[Mon Jul 20 06:04:05.827352 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4OtbLfyzVz2SrjZpiphAAAAjU"]
[Mon Jul 20 06:04:05.907692 2026] [security2:error] [pid 796928:tid 797076] [client 57.141.18.27:24398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OsOsTy9vX-htKvPkMrQACq1w"]
[Mon Jul 20 06:04:05.964745 2026] [security2:error] [pid 796928:tid 797061] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNygAAApw"]
[Mon Jul 20 06:04:06.205058 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:64624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkN5QAAAro"], referer: https://nwcarvingacademy.com/wordpress
[Mon Jul 20 06:04:06.327496 2026] [security2:error] [pid 796567:tid 796605] [remote 45.90.123.233:48558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpiplQACMiU"]
[Mon Jul 20 06:04:06.400039 2026] [security2:error] [pid 796567:tid 796611] [remote 47.86.33.52:19370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpipmQACHys"]
[Mon Jul 20 06:04:06.494332 2026] [security2:error] [pid 796928:tid 797089] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkN9QAAArg"]
[Mon Jul 20 06:04:06.551228 2026] [security2:error] [pid 796567:tid 796646] [remote 45.90.123.233:48558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpipngACT04"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:06.571809 2026] [security2:error] [pid 796928:tid 797039] [remote 202.51.202.242:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4OtusTy9vX-htKvPkODQACz24"]
[Mon Jul 20 06:04:06.742275 2026] [security2:error] [pid 796928:tid 796986] [remote 47.86.33.52:19360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOHAADFjk"]
[Mon Jul 20 06:04:06.742553 2026] [security2:error] [pid 796928:tid 797183] [client 47.86.33.52:19360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOHAADFjk"]
[Mon Jul 20 06:04:06.760445 2026] [security2:error] [pid 796567:tid 796819] [client 14.225.17.146:61791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4OtLLfyzVz2SrjZpipaAAAAo4"], referer: http://goyalsatyam.com/wordpress
[Mon Jul 20 06:04:06.773839 2026] [security2:error] [pid 796567:tid 796814] [client 112.213.160.112:8244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OtrLfyzVz2SrjZpipogAAAok"]
[Mon Jul 20 06:04:06.773955 2026] [security2:error] [pid 796567:tid 796814] [client 112.213.160.112:8244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OtrLfyzVz2SrjZpipogAAAok"]
[Mon Jul 20 06:04:06.786256 2026] [security2:error] [pid 796567:tid 796603] [remote 47.86.33.52:19370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4OtrLfyzVz2SrjZpipowACJSM"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 06:04:06.795868 2026] [security2:error] [pid 796928:tid 797166] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkODwAAAwU"]
[Mon Jul 20 06:04:06.920852 2026] [security2:error] [pid 796928:tid 797035] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOJgAC72o"]
[Mon Jul 20 06:04:06.921068 2026] [security2:error] [pid 796928:tid 797144] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OtusTy9vX-htKvPkOJgAC72o"]
[Mon Jul 20 06:04:07.086464 2026] [security2:error] [pid 796567:tid 796762] [client 50.116.65.227:53974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Ot7LfyzVz2SrjZpiprwAAAlU"]
[Mon Jul 20 06:04:07.100062 2026] [security2:error] [pid 796567:tid 796737] [client 50.116.65.227:53980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Ot7LfyzVz2SrjZpipsgAAAjw"]
[Mon Jul 20 06:04:07.331138 2026] [security2:error] [pid 796928:tid 797147] [client 57.141.18.52:44950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OsesTy9vX-htKvPkNEQAC8ik"]
[Mon Jul 20 06:04:07.363139 2026] [security2:error] [pid 796928:tid 796958] [remote 202.51.202.242:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4Ot-sTy9vX-htKvPkOPAAC5B0"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 06:04:07.444122 2026] [security2:error] [pid 796928:tid 797177] [client 14.225.17.146:54040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkN2AAAAxA"], referer: http://maplerespiteservices.com/wordpress
[Mon Jul 20 06:04:07.479254 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:25123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOTgAAAuw"]
[Mon Jul 20 06:04:07.479415 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:25123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOTgAAAuw"]
[Mon Jul 20 06:04:07.500695 2026] [security2:error] [pid 796928:tid 797110] [client 47.31.86.100:58877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOUQAAAs0"]
[Mon Jul 20 06:04:07.501183 2026] [security2:error] [pid 796928:tid 797110] [client 47.31.86.100:58877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ot-sTy9vX-htKvPkOUQAAAs0"]
[Mon Jul 20 06:04:07.662351 2026] [security2:error] [pid 796567:tid 796772] [client 14.251.3.155:59560] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Ot7LfyzVz2SrjZpipvQAAAl8"]
[Mon Jul 20 06:04:07.721694 2026] [security2:error] [pid 796928:tid 797152] [client 185.132.186.79:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOWAAAAvc"]
[Mon Jul 20 06:04:07.779954 2026] [security2:error] [pid 796928:tid 797094] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOVQAAAr0"]
[Mon Jul 20 06:04:07.811740 2026] [security2:error] [pid 796928:tid 797106] [client 14.225.17.146:62400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkN7QAAAsk"], referer: http://oldracelimited.com/wordpress
[Mon Jul 20 06:04:07.901220 2026] [security2:error] [pid 796567:tid 796592] [remote 216.73.216.55:29852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4Ot7LfyzVz2SrjZpipxAACaBg"]
[Mon Jul 20 06:04:07.903038 2026] [security2:error] [pid 796928:tid 796935] [remote 20.233.187.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4Ot-sTy9vX-htKvPkOYQADEQY"]
[Mon Jul 20 06:04:08.022067 2026] [security2:error] [pid 796928:tid 797068] [client 14.225.17.146:61828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNswAAAqM"], referer: http://mrbambooplus.com/wordpress
[Mon Jul 20 06:04:08.067426 2026] [access_compat:error] [pid 796567:tid 796752] [client 157.148.43.65:58749] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:08.161004 2026] [security2:error] [pid 796928:tid 797084] [client 14.225.17.146:61878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOZwAAArM"], referer: http://lutheranphilosopher.com/wordpress
[Mon Jul 20 06:04:08.334548 2026] [security2:error] [pid 796928:tid 796973] [remote 20.233.187.228:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4OuOsTy9vX-htKvPkOeAAC7Cw"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:04:08.387869 2026] [security2:error] [pid 796928:tid 797136] [client 57.141.0.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOPQAAAuc"]
[Mon Jul 20 06:04:08.503051 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.93:41872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Os7LfyzVz2SrjZpipJwACcnk"]
[Mon Jul 20 06:04:08.503199 2026] [security2:error] [pid 796928:tid 797145] [client 57.141.18.112:58170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Os-sTy9vX-htKvPkNWwAC8DY"]
[Mon Jul 20 06:04:08.562234 2026] [security2:error] [pid 796928:tid 797086] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOcAAAArU"]
[Mon Jul 20 06:04:08.642401 2026] [security2:error] [pid 796928:tid 797107] [client 104.234.53.77:39881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OuOsTy9vX-htKvPkOiQAAAso"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:08.965888 2026] [security2:error] [pid 796928:tid 797081] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOmAAAArA"]
[Mon Jul 20 06:04:08.990683 2026] [security2:error] [pid 796567:tid 796773] [client 14.225.17.146:62850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4Ot7LfyzVz2SrjZpiptwAAAmA"], referer: http://cephasnext.com/wordpress
[Mon Jul 20 06:04:09.068572 2026] [security2:error] [pid 796928:tid 797137] [client 14.225.17.146:56680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOVAAAAug"], referer: http://ghivs.com/wordpress
[Mon Jul 20 06:04:09.107992 2026] [security2:error] [pid 796928:tid 797150] [client 50.116.65.227:54046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOhQAAAvU"]
[Mon Jul 20 06:04:09.245984 2026] [security2:error] [pid 796928:tid 797168] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuOsTy9vX-htKvPkOpAAAAwc"]
[Mon Jul 20 06:04:09.259990 2026] [lsapi:warn] [pid 796928:tid 797174] [client 34.204.28.244:51701] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.260030 2026] [lsapi:warn] [pid 796928:tid 797174] [client 34.204.28.244:51701] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.346152 2026] [lsapi:warn] [pid 796567:tid 796711] [client 50.116.65.227:14096] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.346183 2026] [lsapi:warn] [pid 796567:tid 796711] [client 50.116.65.227:14096] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:04:09.465286 2026] [security2:error] [pid 796928:tid 797105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuesTy9vX-htKvPkOuAAAAsg"]
[Mon Jul 20 06:04:09.486160 2026] [security2:error] [pid 796928:tid 797068] [client 18.228.171.129:34826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkOxQAAAqM"]
[Mon Jul 20 06:04:09.486282 2026] [security2:error] [pid 796928:tid 797068] [client 18.228.171.129:34826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkOxQAAAqM"]
[Mon Jul 20 06:04:09.540719 2026] [access_compat:error] [pid 796928:tid 797165] [client 183.47.122.163:53165] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:09.669108 2026] [security2:error] [pid 796928:tid 797180] [client 185.132.186.93:22971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/up.php"] [unique_id "al4OuesTy9vX-htKvPkOzgAAAxM"]
[Mon Jul 20 06:04:09.701273 2026] [security2:error] [pid 796567:tid 796770] [client 50.116.65.227:14086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4OubLfyzVz2SrjZpip6gAAAl0"]
[Mon Jul 20 06:04:09.707638 2026] [security2:error] [pid 796928:tid 797155] [client 115.246.21.170:16640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkO0AAAAvo"]
[Mon Jul 20 06:04:09.707765 2026] [security2:error] [pid 796928:tid 797155] [client 115.246.21.170:16640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OuesTy9vX-htKvPkO0AAAAvo"]
[Mon Jul 20 06:04:09.774189 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuesTy9vX-htKvPkOyQAAAtg"]
[Mon Jul 20 06:04:09.805509 2026] [security2:error] [pid 796567:tid 796813] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OubLfyzVz2SrjZpip9wACiBo"]
[Mon Jul 20 06:04:10.116423 2026] [security2:error] [pid 796567:tid 796763] [client 181.238.134.114:23536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4OubLfyzVz2SrjZpiqAAAAAlY"]
[Mon Jul 20 06:04:10.275233 2026] [security2:error] [pid 796928:tid 797095] [client 57.141.18.102:57496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkNpgACvlc"]
[Mon Jul 20 06:04:10.292964 2026] [security2:error] [pid 796928:tid 797119] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkO7AAAAtY"]
[Mon Jul 20 06:04:10.584797 2026] [security2:error] [pid 796928:tid 797164] [client 27.96.94.195:38171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPAwAAAwM"]
[Mon Jul 20 06:04:10.632809 2026] [security2:error] [pid 796928:tid 797041] [remote 130.51.180.8:48510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPDAACzHA"]
[Mon Jul 20 06:04:10.632977 2026] [security2:error] [pid 796928:tid 797109] [client 130.51.180.8:48510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPDAACzHA"]
[Mon Jul 20 06:04:10.696681 2026] [security2:error] [pid 796928:tid 797062] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkO-QAAAp0"]
[Mon Jul 20 06:04:10.724008 2026] [security2:error] [pid 796567:tid 796821] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OurLfyzVz2SrjZpiqFgAAApA"]
[Mon Jul 20 06:04:10.805402 2026] [security2:error] [pid 796928:tid 797080] [client 129.222.187.209:15121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPEwAAAq8"]
[Mon Jul 20 06:04:10.809906 2026] [security2:error] [pid 796928:tid 797080] [client 129.222.187.209:15121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OuusTy9vX-htKvPkPEwAAAq8"]
[Mon Jul 20 06:04:11.059593 2026] [security2:error] [pid 796928:tid 797112] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkPGQAAAs8"]
[Mon Jul 20 06:04:11.074592 2026] [security2:error] [pid 796928:tid 797135] [client 57.141.18.79:39156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OtesTy9vX-htKvPkN4wAC5mk"]
[Mon Jul 20 06:04:11.122393 2026] [security2:error] [pid 796567:tid 796785] [client 77.110.127.138:54766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou7LfyzVz2SrjZpiqKAAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:11.129627 2026] [security2:error] [pid 796928:tid 797139] [client 114.119.132.28:20537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/page/44"] [unique_id "al4Ou-sTy9vX-htKvPkPLAAAAuo"], referer: https://www.thewelloiledlife.com/page/45?hc_location=ufi
[Mon Jul 20 06:04:11.235188 2026] [security2:error] [pid 796928:tid 797117] [client 104.234.53.90:46375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ou-sTy9vX-htKvPkPLQAAAtQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:11.396542 2026] [security2:error] [pid 796928:tid 797086] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ou-sTy9vX-htKvPkPJwAAArU"]
[Mon Jul 20 06:04:11.397652 2026] [security2:error] [pid 796928:tid 797068] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Ou-sTy9vX-htKvPkPMgAAAqM"]
[Mon Jul 20 06:04:11.420136 2026] [security2:error] [pid 796928:tid 797133] [client 41.173.37.102:11404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPOgAAAuQ"]
[Mon Jul 20 06:04:11.420294 2026] [security2:error] [pid 796928:tid 797133] [client 41.173.37.102:11404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPOgAAAuQ"]
[Mon Jul 20 06:04:11.625279 2026] [security2:error] [pid 796928:tid 797141] [client 185.132.186.61:54313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/bypass.php"] [unique_id "al4Ou-sTy9vX-htKvPkPUgAAAuw"]
[Mon Jul 20 06:04:11.773351 2026] [security2:error] [pid 796928:tid 797059] [client 210.212.97.243:10436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWQAAApo"]
[Mon Jul 20 06:04:11.773465 2026] [security2:error] [pid 796928:tid 797059] [client 210.212.97.243:10436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWQAAApo"]
[Mon Jul 20 06:04:11.830723 2026] [security2:error] [pid 796928:tid 797083] [client 86.98.90.58:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWwAAArI"]
[Mon Jul 20 06:04:11.830836 2026] [security2:error] [pid 796928:tid 797083] [client 86.98.90.58:51256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPWwAAArI"]
[Mon Jul 20 06:04:11.869981 2026] [security2:error] [pid 796928:tid 797128] [client 44.245.170.32:40084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ou-sTy9vX-htKvPkPXAAAAt8"]
[Mon Jul 20 06:04:11.972423 2026] [security2:error] [pid 796928:tid 797005] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPXwACyUw"]
[Mon Jul 20 06:04:11.973761 2026] [security2:error] [pid 796928:tid 797106] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ou-sTy9vX-htKvPkPXwACyUw"]
[Mon Jul 20 06:04:11.983042 2026] [security2:error] [pid 796928:tid 797071] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ou-sTy9vX-htKvPkPVAAAAqY"]
[Mon Jul 20 06:04:12.061486 2026] [security2:error] [pid 796928:tid 797061] [client 57.141.18.45:36118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OtusTy9vX-htKvPkOGAACnG8"]
[Mon Jul 20 06:04:12.297290 2026] [security2:error] [pid 796567:tid 796759] [client 103.95.123.246:20643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OvLLfyzVz2SrjZpiqUwAAAlI"]
[Mon Jul 20 06:04:12.297392 2026] [security2:error] [pid 796567:tid 796759] [client 103.95.123.246:20643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4OvLLfyzVz2SrjZpiqUwAAAlI"]
[Mon Jul 20 06:04:12.307068 2026] [security2:error] [pid 796567:tid 796596] [remote 217.61.143.92:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OvLLfyzVz2SrjZpiqVAACkxw"]
[Mon Jul 20 06:04:12.442744 2026] [security2:error] [pid 796567:tid 796764] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvLLfyzVz2SrjZpiqTQAAAlc"]
[Mon Jul 20 06:04:12.453968 2026] [security2:error] [pid 796567:tid 796750] [client 40.77.167.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OvLLfyzVz2SrjZpiqUgACSWA"]
[Mon Jul 20 06:04:12.491677 2026] [security2:error] [pid 796928:tid 797156] [client 104.234.53.64:43741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OvOsTy9vX-htKvPkPcAAAAvs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:12.540978 2026] [security2:error] [pid 796567:tid 796674] [remote 217.61.143.92:34600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OvLLfyzVz2SrjZpiqXQACMGo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:04:12.654071 2026] [security2:error] [pid 796567:tid 796765] [client 57.141.18.98:51152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ot7LfyzVz2SrjZpiptgACWBM"]
[Mon Jul 20 06:04:12.777221 2026] [security2:error] [pid 796928:tid 797074] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvOsTy9vX-htKvPkPdAAAAqk"]
[Mon Jul 20 06:04:12.788364 2026] [security2:error] [pid 796928:tid 797124] [client 57.141.18.95:45826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ot-sTy9vX-htKvPkOSAAC2xM"]
[Mon Jul 20 06:04:13.127659 2026] [security2:error] [pid 796928:tid 797147] [client 164.100.212.184:50041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OvesTy9vX-htKvPkPnQAAAvI"]
[Mon Jul 20 06:04:13.127743 2026] [security2:error] [pid 796928:tid 797147] [client 164.100.212.184:50041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4OvesTy9vX-htKvPkPnQAAAvI"]
[Mon Jul 20 06:04:13.279157 2026] [security2:error] [pid 796928:tid 797125] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkPlQAAAtw"]
[Mon Jul 20 06:04:13.451646 2026] [security2:error] [pid 796567:tid 796702] [client 103.149.16.77:64201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqdQAAAhk"]
[Mon Jul 20 06:04:13.451799 2026] [security2:error] [pid 796567:tid 796702] [client 103.149.16.77:64201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqdQAAAhk"]
[Mon Jul 20 06:04:13.567155 2026] [security2:error] [pid 796928:tid 797085] [client 185.132.186.72:27615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/images/admin.php"] [unique_id "al4OvesTy9vX-htKvPkPtQAAArQ"]
[Mon Jul 20 06:04:13.589926 2026] [security2:error] [pid 796928:tid 797082] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkPqAAAArE"]
[Mon Jul 20 06:04:13.706188 2026] [security2:error] [pid 796567:tid 796706] [client 77.110.127.138:54767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/dkt2tlik92n5.php"] [unique_id "al4OvbLfyzVz2SrjZpiqfQAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:13.740329 2026] [autoindex:error] [pid 796928:tid 797165] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:13.755463 2026] [security2:error] [pid 796567:tid 796704] [client 181.224.94.124:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqgQAAAhs"]
[Mon Jul 20 06:04:13.755556 2026] [security2:error] [pid 796567:tid 796704] [client 181.224.94.124:55045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvbLfyzVz2SrjZpiqgQAAAhs"]
[Mon Jul 20 06:04:13.757639 2026] [autoindex:error] [pid 796928:tid 797105] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:04:13.861853 2026] [security2:error] [pid 796567:tid 796707] [client 104.234.53.94:22641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OvbLfyzVz2SrjZpiqhAAAAh4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:13.867354 2026] [security2:error] [pid 796928:tid 797089] [client 50.116.65.227:33382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4OvesTy9vX-htKvPkP2wAAArg"]
[Mon Jul 20 06:04:13.882487 2026] [security2:error] [pid 796928:tid 797099] [client 50.116.65.227:14208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4OvesTy9vX-htKvPkP3QAAAvY"]
[Mon Jul 20 06:04:13.924078 2026] [security2:error] [pid 796928:tid 797176] [client 77.110.127.138:54677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkPxQAAAw8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:13.991271 2026] [security2:error] [pid 796928:tid 797068] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvesTy9vX-htKvPkP0AAAAqM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.073614 2026] [security2:error] [pid 796928:tid 797109] [client 77.110.127.138:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/frontend/vh6mbu8i2typ.php"] [unique_id "al4OvusTy9vX-htKvPkP5gAAAsw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.119005 2026] [autoindex:error] [pid 796928:tid 797061] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:14.131801 2026] [autoindex:error] [pid 796928:tid 797103] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.283275 2026] [security2:error] [pid 796928:tid 797083] [client 77.110.127.138:55020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkP5wAAArI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.300341 2026] [access_compat:error] [pid 796928:tid 797171] [client 183.47.107.57:48625] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:14.321926 2026] [security2:error] [pid 796928:tid 797087] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkP8QAAArY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.406274 2026] [security2:error] [pid 796928:tid 797113] [client 14.225.17.146:60088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4OvOsTy9vX-htKvPkPeQAAAtA"]
[Mon Jul 20 06:04:14.412698 2026] [security2:error] [pid 796928:tid 797146] [client 129.222.187.209:31539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvusTy9vX-htKvPkQAgAAAvE"]
[Mon Jul 20 06:04:14.420273 2026] [security2:error] [pid 796928:tid 797146] [client 129.222.187.209:31539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OvusTy9vX-htKvPkQAgAAAvE"]
[Mon Jul 20 06:04:14.462651 2026] [access_compat:error] [pid 796928:tid 797167] [client 110.248.25.49:5391] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:14.573663 2026] [security2:error] [pid 796928:tid 797078] [client 77.110.127.138:55011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/frontend/classic/5nvj5ghks9vj.php"] [unique_id "al4OvusTy9vX-htKvPkQDQAAAq0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.579642 2026] [security2:error] [pid 796567:tid 796726] [client 72.255.10.154:26314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OvrLfyzVz2SrjZpiqpgAAAjE"]
[Mon Jul 20 06:04:14.579775 2026] [security2:error] [pid 796567:tid 796726] [client 72.255.10.154:26314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OvrLfyzVz2SrjZpiqpgAAAjE"]
[Mon Jul 20 06:04:14.603022 2026] [autoindex:error] [pid 796928:tid 797135] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/classic/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:14.736298 2026] [autoindex:error] [pid 796928:tid 797184] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/frontend/classic/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.825284 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvrLfyzVz2SrjZpiqqgAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:14.853309 2026] [security2:error] [pid 796928:tid 797141] [client 77.110.127.138:55021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkQDgAAAuw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.020336 2026] [security2:error] [pid 796928:tid 797060] [client 14.225.17.146:50313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4OvusTy9vX-htKvPkQHQAAAps"], referer: http://adastra.love/wordpress
[Mon Jul 20 06:04:15.087102 2026] [security2:error] [pid 796567:tid 796721] [client 77.110.127.138:54715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/baking/feed/i82pgjyuer2d.php"] [unique_id "al4Ov7LfyzVz2SrjZpiqxgAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.259041 2026] [security2:error] [pid 796928:tid 797068] [client 4.218.23.144:30215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Ov-sTy9vX-htKvPkQRAAAAqM"]
[Mon Jul 20 06:04:15.277241 2026] [security2:error] [pid 796928:tid 796977] [remote 57.141.18.32:36636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3503928"] [unique_id "al4Ov-sTy9vX-htKvPkQRwADEzA"]
[Mon Jul 20 06:04:15.341008 2026] [security2:error] [pid 796928:tid 797086] [client 13.201.64.214:48118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQSgAAArU"]
[Mon Jul 20 06:04:15.341104 2026] [security2:error] [pid 796928:tid 797086] [client 13.201.64.214:48118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQSgAAArU"]
[Mon Jul 20 06:04:15.390876 2026] [security2:error] [pid 796928:tid 797061] [client 4.218.23.144:30215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Ov-sTy9vX-htKvPkQTgAAApw"]
[Mon Jul 20 06:04:15.401574 2026] [security2:error] [pid 796567:tid 796724] [client 52.109.16.52:16451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Ov7LfyzVz2SrjZpiq0gAAAi8"]
[Mon Jul 20 06:04:15.411272 2026] [security2:error] [pid 796928:tid 797147] [client 77.110.127.138:55025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ov-sTy9vX-htKvPkQOAAAAvI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.438781 2026] [security2:error] [pid 796928:tid 797084] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ov-sTy9vX-htKvPkQPQAAArM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.453068 2026] [security2:error] [pid 796567:tid 796796] [client 52.109.16.52:16451] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Ov7LfyzVz2SrjZpiq2QAAAnc"]
[Mon Jul 20 06:04:15.466225 2026] [security2:error] [pid 796567:tid 796792] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ov7LfyzVz2SrjZpiqzAAAAnM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:15.515075 2026] [security2:error] [pid 796928:tid 797164] [client 185.132.186.92:57021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/index.php"] [unique_id "al4Ov-sTy9vX-htKvPkQWQAAAwM"]
[Mon Jul 20 06:04:15.562378 2026] [access_compat:error] [pid 796928:tid 797143] [client 183.47.122.226:50519] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:15.735180 2026] [security2:error] [pid 796567:tid 796781] [client 57.141.18.6:53742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OubLfyzVz2SrjZpip_wACaGY"]
[Mon Jul 20 06:04:15.764169 2026] [security2:error] [pid 796928:tid 797066] [client 106.192.104.4:57996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQYwAAAqE"]
[Mon Jul 20 06:04:15.768432 2026] [security2:error] [pid 796928:tid 797066] [client 106.192.104.4:57996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Ov-sTy9vX-htKvPkQYwAAAqE"]
[Mon Jul 20 06:04:16.261735 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4OwOsTy9vX-htKvPkQdgAAAs8"]
[Mon Jul 20 06:04:16.261852 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4OwOsTy9vX-htKvPkQdgAAAs8"]
[Mon Jul 20 06:04:16.265968 2026] [security2:error] [pid 796928:tid 797159] [client 57.141.18.20:23870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OuusTy9vX-htKvPkPCgAC_l8"]
[Mon Jul 20 06:04:16.295864 2026] [security2:error] [pid 796928:tid 797160] [client 50.116.65.227:14294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OwOsTy9vX-htKvPkQegAAAv8"]
[Mon Jul 20 06:04:16.306583 2026] [security2:error] [pid 796928:tid 797088] [client 50.116.65.227:14304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OwOsTy9vX-htKvPkQfAAAArc"]
[Mon Jul 20 06:04:16.328176 2026] [security2:error] [pid 796928:tid 797004] [remote 173.249.4.11:15456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OwOsTy9vX-htKvPkQfwADB0s"]
[Mon Jul 20 06:04:16.561717 2026] [security2:error] [pid 796928:tid 797018] [remote 173.249.4.11:15456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4OwOsTy9vX-htKvPkQkgADAFk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:04:16.616585 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4OwOsTy9vX-htKvPkQkwAAAqU"]
[Mon Jul 20 06:04:16.616717 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4OwOsTy9vX-htKvPkQkwAAAqU"]
[Mon Jul 20 06:04:16.844665 2026] [security2:error] [pid 796567:tid 796786] [client 50.116.65.227:14346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OwLLfyzVz2SrjZpiq-wAAAm0"]
[Mon Jul 20 06:04:16.997474 2026] [security2:error] [pid 796567:tid 796802] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xyn.php"] [unique_id "al4OwLLfyzVz2SrjZpirDAAAAn0"]
[Mon Jul 20 06:04:16.997620 2026] [security2:error] [pid 796567:tid 796802] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xyn.php"] [unique_id "al4OwLLfyzVz2SrjZpirDAAAAn0"]
[Mon Jul 20 06:04:17.027022 2026] [security2:error] [pid 796567:tid 796780] [client 50.116.65.227:14358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4OwLLfyzVz2SrjZpirBwAAAmc"]
[Mon Jul 20 06:04:17.354880 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/patie.php"] [unique_id "al4OwesTy9vX-htKvPkQuAAAAwo"]
[Mon Jul 20 06:04:17.354981 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/patie.php"] [unique_id "al4OwesTy9vX-htKvPkQuAAAAwo"]
[Mon Jul 20 06:04:17.435626 2026] [security2:error] [pid 796928:tid 797084] [client 35.180.166.19:30000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQugAAArM"]
[Mon Jul 20 06:04:17.498572 2026] [security2:error] [pid 796928:tid 797117] [client 185.132.186.71:46927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQvAAAAtQ"]
[Mon Jul 20 06:04:17.596152 2026] [security2:error] [pid 796928:tid 797061] [client 112.213.160.112:8498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQwgAAApw"]
[Mon Jul 20 06:04:17.596299 2026] [security2:error] [pid 796928:tid 797061] [client 112.213.160.112:8498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQwgAAApw"]
[Mon Jul 20 06:04:17.620343 2026] [security2:error] [pid 796928:tid 797006] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQxAAC3E0"]
[Mon Jul 20 06:04:17.620469 2026] [security2:error] [pid 796928:tid 797125] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQxAAC3E0"]
[Mon Jul 20 06:04:17.700016 2026] [security2:error] [pid 796567:tid 796787] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/aa.php"] [unique_id "al4OwbLfyzVz2SrjZpirHAAAAm4"]
[Mon Jul 20 06:04:17.700134 2026] [security2:error] [pid 796567:tid 796787] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/aa.php"] [unique_id "al4OwbLfyzVz2SrjZpirHAAAAm4"]
[Mon Jul 20 06:04:17.717802 2026] [security2:error] [pid 796928:tid 797070] [client 193.37.33.1:47709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQzwAAAqU"]
[Mon Jul 20 06:04:17.735355 2026] [security2:error] [pid 796928:tid 797151] [client 193.19.109.250:58471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQzgAAAvY"]
[Mon Jul 20 06:04:17.933313 2026] [security2:error] [pid 796928:tid 797113] [client 150.228.148.150:23927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQ4gAAAtA"]
[Mon Jul 20 06:04:17.941019 2026] [security2:error] [pid 796928:tid 797113] [client 150.228.148.150:23927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OwesTy9vX-htKvPkQ4gAAAtA"]
[Mon Jul 20 06:04:17.958373 2026] [security2:error] [pid 796928:tid 797169] [client 35.180.166.19:30014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4OwesTy9vX-htKvPkQ5wAAAwg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:04:17.975816 2026] [access_compat:error] [pid 796928:tid 797180] [client 157.148.43.150:43779] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:18.055105 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xwpg.php"] [unique_id "al4OwusTy9vX-htKvPkQ7wAAAvU"]
[Mon Jul 20 06:04:18.055216 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xwpg.php"] [unique_id "al4OwusTy9vX-htKvPkQ7wAAAvU"]
[Mon Jul 20 06:04:18.056190 2026] [security2:error] [pid 796928:tid 797175] [client 57.141.18.111:54358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OvOsTy9vX-htKvPkPewADDkM"]
[Mon Jul 20 06:04:18.062756 2026] [security2:error] [pid 796928:tid 797131] [client 47.31.86.100:59386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OwusTy9vX-htKvPkQ8QAAAuI"]
[Mon Jul 20 06:04:18.062864 2026] [security2:error] [pid 796928:tid 797131] [client 47.31.86.100:59386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OwusTy9vX-htKvPkQ8QAAAuI"]
[Mon Jul 20 06:04:18.076106 2026] [security2:error] [pid 796928:tid 797001] [remote 130.185.118.215:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OwusTy9vX-htKvPkQ8gAC70g"]
[Mon Jul 20 06:04:18.231713 2026] [security2:error] [pid 796928:tid 797125] [client 77.110.127.138:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OwusTy9vX-htKvPkQ9wAAAtw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:18.292597 2026] [security2:error] [pid 796928:tid 797007] [remote 130.185.118.215:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4OwusTy9vX-htKvPkQ_QADBU4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:18.434488 2026] [security2:error] [pid 796928:tid 797159] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ops.php"] [unique_id "al4OwusTy9vX-htKvPkRBgAAAv4"]
[Mon Jul 20 06:04:18.434604 2026] [security2:error] [pid 796928:tid 797159] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ops.php"] [unique_id "al4OwusTy9vX-htKvPkRBgAAAv4"]
[Mon Jul 20 06:04:18.720955 2026] [security2:error] [pid 796928:tid 797180] [client 50.116.65.227:33398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4OwusTy9vX-htKvPkREgAAAxM"]
[Mon Jul 20 06:04:18.733272 2026] [security2:error] [pid 796928:tid 797110] [client 50.116.65.227:14386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4OwusTy9vX-htKvPkRFAAAAs0"]
[Mon Jul 20 06:04:18.812975 2026] [security2:error] [pid 796567:tid 796714] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mac.php"] [unique_id "al4OwrLfyzVz2SrjZpirSAAAAiU"]
[Mon Jul 20 06:04:18.813145 2026] [security2:error] [pid 796567:tid 796714] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mac.php"] [unique_id "al4OwrLfyzVz2SrjZpirSAAAAiU"]
[Mon Jul 20 06:04:19.181569 2026] [security2:error] [pid 796567:tid 796716] [client 14.225.17.146:62231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4OwbLfyzVz2SrjZpirFQAAAic"], referer: http://tntcatholic.com/wordpress
[Mon Jul 20 06:04:19.224599 2026] [security2:error] [pid 796567:tid 796759] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mg.php"] [unique_id "al4Ow7LfyzVz2SrjZpirUwAAAlI"]
[Mon Jul 20 06:04:19.224776 2026] [security2:error] [pid 796567:tid 796759] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mg.php"] [unique_id "al4Ow7LfyzVz2SrjZpirUwAAAlI"]
[Mon Jul 20 06:04:19.449389 2026] [security2:error] [pid 796928:tid 797152] [client 185.132.186.63:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/simple/function.php"] [unique_id "al4Ow-sTy9vX-htKvPkRTQAAAvc"]
[Mon Jul 20 06:04:19.463153 2026] [security2:error] [pid 796567:tid 796824] [client 27.96.94.195:36882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Ow7LfyzVz2SrjZpirVgAAApM"]
[Mon Jul 20 06:04:19.595699 2026] [security2:error] [pid 796928:tid 797168] [client 193.19.109.226:48179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Ow-sTy9vX-htKvPkRUgAAAwc"]
[Mon Jul 20 06:04:19.597834 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-post-data.php"] [unique_id "al4Ow7LfyzVz2SrjZpirXQAAAog"]
[Mon Jul 20 06:04:19.597954 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-post-data.php"] [unique_id "al4Ow7LfyzVz2SrjZpirXQAAAog"]
[Mon Jul 20 06:04:19.604134 2026] [security2:error] [pid 796928:tid 797184] [client 173.239.254.42:40305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Ow-sTy9vX-htKvPkRUQAAAxc"]
[Mon Jul 20 06:04:19.624838 2026] [security2:error] [pid 796928:tid 797058] [client 193.19.109.221:24703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Ow-sTy9vX-htKvPkRUAAAApk"]
[Mon Jul 20 06:04:19.905163 2026] [security2:error] [pid 796567:tid 796801] [client 5.161.177.47:34982] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Ow7LfyzVz2SrjZpirZAAAAnw"], referer: https://windowtx.com
[Mon Jul 20 06:04:20.009061 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/pucci.php"] [unique_id "al4OxLLfyzVz2SrjZpiragAAAmk"]
[Mon Jul 20 06:04:20.009186 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/pucci.php"] [unique_id "al4OxLLfyzVz2SrjZpiragAAAmk"]
[Mon Jul 20 06:04:20.056273 2026] [security2:error] [pid 796928:tid 797161] [client 14.225.17.146:55263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4OwusTy9vX-htKvPkRAAAAAwA"], referer: http://reosportsboats.com/wordpress
[Mon Jul 20 06:04:20.176186 2026] [security2:error] [pid 796928:tid 797155] [client 193.19.109.218:31409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4OxOsTy9vX-htKvPkRcAAAAvo"]
[Mon Jul 20 06:04:20.269504 2026] [security2:error] [pid 796928:tid 797122] [client 18.228.171.129:34130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRdgAAAtk"]
[Mon Jul 20 06:04:20.269695 2026] [security2:error] [pid 796928:tid 797122] [client 18.228.171.129:34130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRdgAAAtk"]
[Mon Jul 20 06:04:20.280636 2026] [security2:error] [pid 796928:tid 797081] [client 115.246.21.170:13726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRegAAArA"]
[Mon Jul 20 06:04:20.280744 2026] [security2:error] [pid 796928:tid 797081] [client 115.246.21.170:13726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRegAAArA"]
[Mon Jul 20 06:04:20.364713 2026] [security2:error] [pid 796567:tid 796707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OxLLfyzVz2SrjZpirdgAAAh4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:20.433040 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/black.php"] [unique_id "al4OxOsTy9vX-htKvPkRggAAAwg"]
[Mon Jul 20 06:04:20.433126 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/black.php"] [unique_id "al4OxOsTy9vX-htKvPkRggAAAwg"]
[Mon Jul 20 06:04:20.466801 2026] [security2:error] [pid 796928:tid 797083] [client 57.141.18.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4OxOsTy9vX-htKvPkRfAAAArI"]
[Mon Jul 20 06:04:20.589953 2026] [security2:error] [pid 796928:tid 797149] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4OxOsTy9vX-htKvPkRdwAC9Bc"]
[Mon Jul 20 06:04:20.703001 2026] [security2:error] [pid 796928:tid 797102] [client 159.138.109.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4OxOsTy9vX-htKvPkRjQACxQI"]
[Mon Jul 20 06:04:20.786498 2026] [security2:error] [pid 796567:tid 796712] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zlece.php"] [unique_id "al4OxLLfyzVz2SrjZpirfQAAAiM"]
[Mon Jul 20 06:04:20.786627 2026] [security2:error] [pid 796567:tid 796712] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zlece.php"] [unique_id "al4OxLLfyzVz2SrjZpirfQAAAiM"]
[Mon Jul 20 06:04:20.963514 2026] [security2:error] [pid 796928:tid 797181] [client 14.225.17.146:61636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4OxOsTy9vX-htKvPkRnAAAAxQ"], referer: https://reosportsboats.com/wordpress
[Mon Jul 20 06:04:21.034652 2026] [security2:error] [pid 796928:tid 797160] [client 74.208.214.194:37008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4OxesTy9vX-htKvPkRqwAAAv8"]
[Mon Jul 20 06:04:21.179645 2026] [security2:error] [pid 796928:tid 797184] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/vssrs.php"] [unique_id "al4OxesTy9vX-htKvPkRtQAAAxc"]
[Mon Jul 20 06:04:21.179774 2026] [security2:error] [pid 796928:tid 797184] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/vssrs.php"] [unique_id "al4OxesTy9vX-htKvPkRtQAAAxc"]
[Mon Jul 20 06:04:21.309215 2026] [security2:error] [pid 796928:tid 797124] [client 129.222.187.209:14002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkRugAAAts"]
[Mon Jul 20 06:04:21.316844 2026] [security2:error] [pid 796928:tid 797124] [client 129.222.187.209:14002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkRugAAAts"]
[Mon Jul 20 06:04:21.459303 2026] [access_compat:error] [pid 796928:tid 797150] [client 101.19.156.87:20072] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:21.519189 2026] [security2:error] [pid 796567:tid 796793] [client 77.110.127.138:55033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxbLfyzVz2SrjZpirjAAAAnQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.525729 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wicked.php"] [unique_id "al4OxbLfyzVz2SrjZpirjQAAAmE"]
[Mon Jul 20 06:04:21.525933 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wicked.php"] [unique_id "al4OxbLfyzVz2SrjZpirjQAAAmE"]
[Mon Jul 20 06:04:21.570974 2026] [security2:error] [pid 796928:tid 797059] [client 77.110.127.138:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkRzQAAApo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.671464 2026] [autoindex:error] [pid 796928:tid 797159] [client 14.225.17.146:52909] AH01276: Cannot serve directory /home4/koaconsu/public_html/wordpress/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://koaconsultants.com/wordpress
[Mon Jul 20 06:04:21.696638 2026] [security2:error] [pid 796928:tid 797119] [client 77.110.127.138:55025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkR1QAAAtY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.768841 2026] [security2:error] [pid 796567:tid 796773] [client 77.110.127.138:55028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxbLfyzVz2SrjZpirkwAAAmA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.821074 2026] [security2:error] [pid 796928:tid 796989] [remote 130.185.118.215:34592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkR4wACpTw"]
[Mon Jul 20 06:04:21.821273 2026] [security2:error] [pid 796928:tid 797070] [client 130.185.118.215:34592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4OxesTy9vX-htKvPkR4wACpTw"]
[Mon Jul 20 06:04:21.824465 2026] [security2:error] [pid 796567:tid 796824] [client 77.110.127.138:54869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxbLfyzVz2SrjZpirlAAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:21.884782 2026] [security2:error] [pid 796567:tid 796799] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/24.php"] [unique_id "al4OxbLfyzVz2SrjZpirlQAAAno"]
[Mon Jul 20 06:04:21.884882 2026] [security2:error] [pid 796567:tid 796799] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/24.php"] [unique_id "al4OxbLfyzVz2SrjZpirlQAAAno"]
[Mon Jul 20 06:04:21.887788 2026] [security2:error] [pid 796928:tid 797156] [client 14.225.17.146:53916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4OxesTy9vX-htKvPkRywAAAvs"], referer: http://aljosour-alarabia.com/wordpress
[Mon Jul 20 06:04:22.001237 2026] [security2:error] [pid 796567:tid 796751] [client 77.110.127.138:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxrLfyzVz2SrjZpiroAAAAko"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:22.073551 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:11855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR8wAAAp8"]
[Mon Jul 20 06:04:22.073678 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:11855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR8wAAAp8"]
[Mon Jul 20 06:04:22.205283 2026] [security2:error] [pid 796928:tid 797095] [client 178.152.178.232:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR-QAAAr4"]
[Mon Jul 20 06:04:22.205456 2026] [security2:error] [pid 796928:tid 797095] [client 178.152.178.232:36278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkR-QAAAr4"]
[Mon Jul 20 06:04:22.246534 2026] [security2:error] [pid 796567:tid 796756] [client 57.141.18.33:23812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OwLLfyzVz2SrjZpiq9AACTwE"]
[Mon Jul 20 06:04:22.247073 2026] [security2:error] [pid 796928:tid 797148] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xacs.php"] [unique_id "al4OxusTy9vX-htKvPkR-wAAAvM"]
[Mon Jul 20 06:04:22.247166 2026] [security2:error] [pid 796928:tid 797148] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xacs.php"] [unique_id "al4OxusTy9vX-htKvPkR-wAAAvM"]
[Mon Jul 20 06:04:22.323955 2026] [security2:error] [pid 796928:tid 797180] [client 193.19.109.220:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4OxusTy9vX-htKvPkR_wAAAxM"]
[Mon Jul 20 06:04:22.375899 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:55045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSAgAAAqw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:22.387695 2026] [security2:error] [pid 796928:tid 797136] [client 210.212.97.243:10437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSAwAAAuc"]
[Mon Jul 20 06:04:22.387861 2026] [security2:error] [pid 796928:tid 797136] [client 210.212.97.243:10437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSAwAAAuc"]
[Mon Jul 20 06:04:22.434139 2026] [security2:error] [pid 796928:tid 797161] [client 185.132.186.54:44333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ext.php"] [unique_id "al4OxusTy9vX-htKvPkSBgAAAwA"]
[Mon Jul 20 06:04:22.542313 2026] [security2:error] [pid 796567:tid 796633] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OxrLfyzVz2SrjZpirrAACN0E"]
[Mon Jul 20 06:04:22.542431 2026] [security2:error] [pid 796567:tid 796732] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OxrLfyzVz2SrjZpirrAACN0E"]
[Mon Jul 20 06:04:22.610280 2026] [security2:error] [pid 796928:tid 797168] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zildan.php"] [unique_id "al4OxusTy9vX-htKvPkSGAAAAwc"]
[Mon Jul 20 06:04:22.610391 2026] [security2:error] [pid 796928:tid 797168] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zildan.php"] [unique_id "al4OxusTy9vX-htKvPkSGAAAAwc"]
[Mon Jul 20 06:04:22.674799 2026] [security2:error] [pid 796928:tid 796979] [remote 130.185.118.215:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OxusTy9vX-htKvPkSHQAC9zI"]
[Mon Jul 20 06:04:22.760060 2026] [security2:error] [pid 796928:tid 797027] [remote 95.217.78.234:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSIQACpWI"]
[Mon Jul 20 06:04:22.760288 2026] [security2:error] [pid 796928:tid 797070] [client 95.217.78.234:39762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4OxusTy9vX-htKvPkSIQACpWI"]
[Mon Jul 20 06:04:22.853400 2026] [security2:error] [pid 796928:tid 797038] [remote 130.185.118.215:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4OxusTy9vX-htKvPkSIwAC3m0"], referer: https://mail.pju.xqs.mybluehost.me/wp-login.php
[Mon Jul 20 06:04:22.963738 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/csa.php"] [unique_id "al4OxusTy9vX-htKvPkSKgAAAwQ"]
[Mon Jul 20 06:04:22.963859 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/csa.php"] [unique_id "al4OxusTy9vX-htKvPkSKgAAAwQ"]
[Mon Jul 20 06:04:23.121709 2026] [security2:error] [pid 796928:tid 797100] [client 57.141.18.3:56866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OwesTy9vX-htKvPkQrAACw1o"]
[Mon Jul 20 06:04:23.176700 2026] [security2:error] [pid 796567:tid 796775] [client 86.98.90.58:52121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirvgAAAmI"]
[Mon Jul 20 06:04:23.177052 2026] [security2:error] [pid 796567:tid 796775] [client 86.98.90.58:52121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirvgAAAmI"]
[Mon Jul 20 06:04:23.268234 2026] [security2:error] [pid 796928:tid 797072] [client 103.95.123.246:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSOwAAAqc"]
[Mon Jul 20 06:04:23.268412 2026] [security2:error] [pid 796928:tid 797072] [client 103.95.123.246:21131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSOwAAAqc"]
[Mon Jul 20 06:04:23.275633 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:58862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4OxrLfyzVz2SrjZpirsQAAAn0"], referer: http://waterproofgoods.com/wordpress
[Mon Jul 20 06:04:23.310447 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/w3llscc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSPwAAAwg"]
[Mon Jul 20 06:04:23.310587 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/w3llscc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSPwAAAwg"]
[Mon Jul 20 06:04:23.696791 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wpx.php"] [unique_id "al4Ox-sTy9vX-htKvPkSWQAAAwQ"]
[Mon Jul 20 06:04:23.696918 2026] [security2:error] [pid 796928:tid 797165] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wpx.php"] [unique_id "al4Ox-sTy9vX-htKvPkSWQAAAwQ"]
[Mon Jul 20 06:04:23.742716 2026] [security2:error] [pid 796928:tid 797138] [client 164.100.212.184:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSXQAAAuk"]
[Mon Jul 20 06:04:23.742840 2026] [security2:error] [pid 796928:tid 797138] [client 164.100.212.184:50618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox-sTy9vX-htKvPkSXQAAAuk"]
[Mon Jul 20 06:04:23.909936 2026] [security2:error] [pid 796567:tid 796787] [client 181.224.94.124:8905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirzgAAAm4"]
[Mon Jul 20 06:04:24.073639 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-css.php"] [unique_id "al4OyOsTy9vX-htKvPkSbwAAAt0"]
[Mon Jul 20 06:04:24.073742 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-css.php"] [unique_id "al4OyOsTy9vX-htKvPkSbwAAAt0"]
[Mon Jul 20 06:04:24.379323 2026] [security2:error] [pid 796928:tid 797138] [client 185.132.186.92:27755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/delpaths.php"] [unique_id "al4OyOsTy9vX-htKvPkSigAAAuk"]
[Mon Jul 20 06:04:24.418561 2026] [security2:error] [pid 796567:tid 796787] [client 181.224.94.124:8905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ox7LfyzVz2SrjZpirzgAAAm4"]
[Mon Jul 20 06:04:24.427286 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/alfa_shell_4.1.php"] [unique_id "al4OyOsTy9vX-htKvPkSiwAAAvU"]
[Mon Jul 20 06:04:24.427435 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/alfa_shell_4.1.php"] [unique_id "al4OyOsTy9vX-htKvPkSiwAAAvU"]
[Mon Jul 20 06:04:24.546690 2026] [security2:error] [pid 796567:tid 796823] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyLLfyzVz2SrjZpir2gAAApI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:24.687534 2026] [security2:error] [pid 796567:tid 796738] [client 14.225.17.146:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Ox7LfyzVz2SrjZpiryAAAAj0"], referer: http://ncsynchro.com/wordpress
[Mon Jul 20 06:04:24.764774 2026] [security2:error] [pid 796928:tid 797181] [client 129.222.187.209:30797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OyOsTy9vX-htKvPkSqwAAAxQ"]
[Mon Jul 20 06:04:24.768417 2026] [security2:error] [pid 796928:tid 797181] [client 129.222.187.209:30797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4OyOsTy9vX-htKvPkSqwAAAxQ"]
[Mon Jul 20 06:04:24.812119 2026] [security2:error] [pid 796928:tid 797089] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ho.php"] [unique_id "al4OyOsTy9vX-htKvPkSsAAAArg"]
[Mon Jul 20 06:04:24.812249 2026] [security2:error] [pid 796928:tid 797089] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ho.php"] [unique_id "al4OyOsTy9vX-htKvPkSsAAAArg"]
[Mon Jul 20 06:04:24.914280 2026] [security2:error] [pid 796567:tid 796671] [remote 98.156.100.191:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4OyLLfyzVz2SrjZpir7wACRmc"]
[Mon Jul 20 06:04:25.099358 2026] [security2:error] [pid 796567:tid 796780] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyLLfyzVz2SrjZpir7AAAAmc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.162406 2026] [security2:error] [pid 796928:tid 797185] [client 57.141.18.48:43236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OwusTy9vX-htKvPkRHAADGHI"]
[Mon Jul 20 06:04:25.175360 2026] [security2:error] [pid 796567:tid 796781] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xy.php"] [unique_id "al4OybLfyzVz2SrjZpir_gAAAmg"]
[Mon Jul 20 06:04:25.175452 2026] [security2:error] [pid 796567:tid 796781] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xy.php"] [unique_id "al4OybLfyzVz2SrjZpir_gAAAmg"]
[Mon Jul 20 06:04:25.178252 2026] [security2:error] [pid 796567:tid 796774] [client 103.149.16.77:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpir_wAAAmE"]
[Mon Jul 20 06:04:25.178344 2026] [security2:error] [pid 796567:tid 796774] [client 103.149.16.77:64672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpir_wAAAmE"]
[Mon Jul 20 06:04:25.396036 2026] [security2:error] [pid 796567:tid 796724] [client 72.255.10.154:2421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpisCAAAAi8"]
[Mon Jul 20 06:04:25.396178 2026] [security2:error] [pid 796567:tid 796724] [client 72.255.10.154:2421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4OybLfyzVz2SrjZpisCAAAAi8"]
[Mon Jul 20 06:04:25.428160 2026] [security2:error] [pid 796928:tid 797145] [client 77.110.127.138:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OyesTy9vX-htKvPkSygAAAvA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.472948 2026] [security2:error] [pid 796567:tid 796699] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OybLfyzVz2SrjZpisAwAAAhY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.482308 2026] [security2:error] [pid 796567:tid 796737] [client 50.116.65.227:34532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4OybLfyzVz2SrjZpisCQAAAjw"]
[Mon Jul 20 06:04:25.493338 2026] [security2:error] [pid 796567:tid 796705] [client 50.116.65.227:34544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4OybLfyzVz2SrjZpisCwAAAhw"]
[Mon Jul 20 06:04:25.530343 2026] [security2:error] [pid 796928:tid 797090] [client 173.239.254.43:63305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4OyesTy9vX-htKvPkS0QAAArk"]
[Mon Jul 20 06:04:25.535231 2026] [security2:error] [pid 796928:tid 797074] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/loader.php"] [unique_id "al4OyesTy9vX-htKvPkS1gAAAqk"]
[Mon Jul 20 06:04:25.535362 2026] [security2:error] [pid 796928:tid 797074] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/loader.php"] [unique_id "al4OyesTy9vX-htKvPkS1gAAAqk"]
[Mon Jul 20 06:04:25.554827 2026] [security2:error] [pid 796567:tid 796794] [client 193.19.109.245:49483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisEAAAAnU"]
[Mon Jul 20 06:04:25.573320 2026] [security2:error] [pid 796567:tid 796762] [client 193.19.109.234:32385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisDwAAAlU"]
[Mon Jul 20 06:04:25.716077 2026] [security2:error] [pid 796928:tid 797121] [client 104.234.53.62:56105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4OyesTy9vX-htKvPkS2AAAAtg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:25.733141 2026] [security2:error] [pid 796567:tid 796572] [remote 98.156.100.191:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisGwACbQQ"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:04:25.851685 2026] [security2:error] [pid 796567:tid 796688] [remote 97.74.87.194:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4OybLfyzVz2SrjZpisHwAChHg"]
[Mon Jul 20 06:04:25.885969 2026] [security2:error] [pid 796567:tid 796796] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OybLfyzVz2SrjZpisFQAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:25.889738 2026] [security2:error] [pid 796928:tid 797155] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/spadex.php"] [unique_id "al4OyesTy9vX-htKvPkS6AAAAvo"]
[Mon Jul 20 06:04:25.889907 2026] [security2:error] [pid 796928:tid 797155] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/spadex.php"] [unique_id "al4OyesTy9vX-htKvPkS6AAAAvo"]
[Mon Jul 20 06:04:26.013988 2026] [security2:error] [pid 796928:tid 797149] [client 104.234.53.62:56105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OyesTy9vX-htKvPkS8AAAAvQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:26.060221 2026] [security2:error] [pid 796928:tid 796935] [remote 72.167.132.114:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4OyusTy9vX-htKvPkS9gAC5QY"]
[Mon Jul 20 06:04:26.260706 2026] [security2:error] [pid 796567:tid 796681] [remote 97.74.87.194:57528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4OyrLfyzVz2SrjZpisNAACjnE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:04:26.260859 2026] [security2:error] [pid 796928:tid 797106] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/2x.php"] [unique_id "al4OyusTy9vX-htKvPkTBgAAAsk"]
[Mon Jul 20 06:04:26.260996 2026] [security2:error] [pid 796928:tid 797106] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/2x.php"] [unique_id "al4OyusTy9vX-htKvPkTBgAAAsk"]
[Mon Jul 20 06:04:26.262489 2026] [security2:error] [pid 796928:tid 796949] [remote 72.167.132.114:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4OyusTy9vX-htKvPkTBQADChQ"], referer: https://snctaxgroup.com/wp-login.php
[Mon Jul 20 06:04:26.331326 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.96:26663] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/1.php"] [unique_id "al4OyrLfyzVz2SrjZpisNwAAAis"]
[Mon Jul 20 06:04:26.331434 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.96:26663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/1.php"] [unique_id "al4OyrLfyzVz2SrjZpisNwAAAis"]
[Mon Jul 20 06:04:26.378174 2026] [security2:error] [pid 796928:tid 797161] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyusTy9vX-htKvPkTAgAAAwA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:26.616863 2026] [security2:error] [pid 796567:tid 796767] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ctex1.php"] [unique_id "al4OyrLfyzVz2SrjZpisPQAAAlo"]
[Mon Jul 20 06:04:26.617048 2026] [security2:error] [pid 796567:tid 796767] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ctex1.php"] [unique_id "al4OyrLfyzVz2SrjZpisPQAAAlo"]
[Mon Jul 20 06:04:26.726126 2026] [security2:error] [pid 796928:tid 797146] [client 104.234.53.70:42359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4OyusTy9vX-htKvPkTHwAAAvE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:26.797228 2026] [proxy:error] [pid 796567:tid 796768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:26.797271 2026] [proxy_http:error] [pid 796567:tid 796768] [client 94.154.43.183:55608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:26.797950 2026] [proxy:error] [pid 796567:tid 796768] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:26.797982 2026] [proxy_http:error] [pid 796567:tid 796768] [client 94.154.43.183:55608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:27.041515 2026] [security2:error] [pid 796928:tid 797059] [client 106.192.104.4:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Oy-sTy9vX-htKvPkTQgAAApo"]
[Mon Jul 20 06:04:27.041768 2026] [security2:error] [pid 796928:tid 797059] [client 106.192.104.4:58481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Oy-sTy9vX-htKvPkTQgAAApo"]
[Mon Jul 20 06:04:27.048089 2026] [proxy:error] [pid 796928:tid 797090] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:27.048165 2026] [proxy_http:error] [pid 796928:tid 797090] [client 94.154.43.183:23808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:27.050216 2026] [proxy:error] [pid 796928:tid 797090] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:04:27.050281 2026] [proxy_http:error] [pid 796928:tid 797090] [client 94.154.43.183:23808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:04:27.077231 2026] [security2:error] [pid 796928:tid 797071] [client 14.225.17.146:56286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4OyusTy9vX-htKvPkTJgAAAqY"], referer: http://maxenengineering.com/wordpress
[Mon Jul 20 06:04:27.099500 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OyusTy9vX-htKvPkTNQAAAqw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:27.146310 2026] [security2:error] [pid 796928:tid 797144] [client 74.7.227.179:55528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Oy-sTy9vX-htKvPkTQQAC718"], referer: https://tejasenvironmental.com/p=2454848
[Mon Jul 20 06:04:27.246276 2026] [security2:error] [pid 796928:tid 797124] [client 193.37.33.5:53751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colt-innovate.com"] [uri "/wp-login.php"] [unique_id "al4Oy-sTy9vX-htKvPkTTAAAAts"]
[Mon Jul 20 06:04:27.335630 2026] [security2:error] [pid 796567:tid 796766] [client 114.119.158.50:45099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/weekly-sales-for-april-15th-thru-april-20th-2019__trashed/jackson-floor-lamp-2000885/"] [unique_id "al4Oy7LfyzVz2SrjZpisUgAAAlk"], referer: https://www.liquidationteam.com/weekly-sales-for-april-15th-thru-april-20th-2019__trashed/jackson-floor-lamp-2000885/
[Mon Jul 20 06:04:27.376538 2026] [security2:error] [pid 796928:tid 797111] [client 57.141.18.119:28158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OxesTy9vX-htKvPkRtgACzjY"]
[Mon Jul 20 06:04:27.440874 2026] [security2:error] [pid 796928:tid 797117] [client 14.225.17.146:64858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4OyusTy9vX-htKvPkTDAAAAtQ"], referer: http://adultdaycarereno.com/wordpress
[Mon Jul 20 06:04:27.529182 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/edorxrr.php"] [unique_id "al4Oy7LfyzVz2SrjZpisXAAAAh8"]
[Mon Jul 20 06:04:27.529322 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/edorxrr.php"] [unique_id "al4Oy7LfyzVz2SrjZpisXAAAAh8"]
[Mon Jul 20 06:04:27.531583 2026] [security2:error] [pid 796928:tid 797084] [client 57.141.18.71:44296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OxesTy9vX-htKvPkRuQACszA"]
[Mon Jul 20 06:04:27.620214 2026] [security2:error] [pid 796567:tid 796750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Oy7LfyzVz2SrjZpisVQAAAkk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:27.823818 2026] [security2:error] [pid 796928:tid 797075] [client 14.225.17.146:51497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4Oy-sTy9vX-htKvPkTcQAAAqo"], referer: http://collectingrealestate.com/wordpress
[Mon Jul 20 06:04:27.902673 2026] [security2:error] [pid 796928:tid 797138] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/miru1.php"] [unique_id "al4Oy-sTy9vX-htKvPkTfgAAAuk"]
[Mon Jul 20 06:04:27.902810 2026] [security2:error] [pid 796928:tid 797138] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/miru1.php"] [unique_id "al4Oy-sTy9vX-htKvPkTfgAAAuk"]
[Mon Jul 20 06:04:27.903372 2026] [security2:error] [pid 796567:tid 796677] [remote 152.228.213.32:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4Oy7LfyzVz2SrjZpisaAACTG0"]
[Mon Jul 20 06:04:28.017839 2026] [security2:error] [pid 796928:tid 797113] [client 104.234.53.82:48525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4OzOsTy9vX-htKvPkThgAAAtA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:28.025677 2026] [security2:error] [pid 796567:tid 796818] [client 14.225.17.146:54124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Oy7LfyzVz2SrjZpisagAAAo0"], referer: https://maxenengineering.com/wordpress
[Mon Jul 20 06:04:28.122584 2026] [security2:error] [pid 796567:tid 796631] [remote 152.228.213.32:36140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4OzLLfyzVz2SrjZpisdgACUT8"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:04:28.200299 2026] [security2:error] [pid 796928:tid 797176] [client 114.119.135.223:45911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4OzOsTy9vX-htKvPkTmgAAAw8"], referer: http://www.xxhjyc.com/online.asp?Page=31406
[Mon Jul 20 06:04:28.270471 2026] [security2:error] [pid 796928:tid 797067] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sump1.php"] [unique_id "al4OzOsTy9vX-htKvPkTnQAAAqI"]
[Mon Jul 20 06:04:28.270568 2026] [security2:error] [pid 796928:tid 797067] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sump1.php"] [unique_id "al4OzOsTy9vX-htKvPkTnQAAAqI"]
[Mon Jul 20 06:04:28.303584 2026] [security2:error] [pid 796928:tid 797071] [client 185.132.186.101:38675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/wp-login.php"] [unique_id "al4OzOsTy9vX-htKvPkTnAAAAqY"]
[Mon Jul 20 06:04:28.305393 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:58273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4OzLLfyzVz2SrjZpiseQAAAn0"], referer: https://adultdaycarereno.com/wordpress
[Mon Jul 20 06:04:28.330812 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:59897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpAAAAqs"]
[Mon Jul 20 06:04:28.341377 2026] [security2:error] [pid 796928:tid 796997] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpQAC-0Q"]
[Mon Jul 20 06:04:28.341490 2026] [security2:error] [pid 796928:tid 797156] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpQAC-0Q"]
[Mon Jul 20 06:04:28.345524 2026] [security2:error] [pid 796928:tid 797076] [client 47.31.86.100:59897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTpAAAAqs"]
[Mon Jul 20 06:04:28.382298 2026] [security2:error] [pid 796928:tid 797084] [client 112.213.160.112:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTqQAAArM"]
[Mon Jul 20 06:04:28.382404 2026] [security2:error] [pid 796928:tid 797084] [client 112.213.160.112:30824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTqQAAArM"]
[Mon Jul 20 06:04:28.535844 2026] [security2:error] [pid 796928:tid 797169] [client 150.228.148.150:49189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTuAAAAwg"]
[Mon Jul 20 06:04:28.556777 2026] [security2:error] [pid 796928:tid 797169] [client 150.228.148.150:49189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4OzOsTy9vX-htKvPkTuAAAAwg"]
[Mon Jul 20 06:04:28.616291 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/file5.php"] [unique_id "al4OzOsTy9vX-htKvPkTvgAAAwo"]
[Mon Jul 20 06:04:28.616406 2026] [security2:error] [pid 796928:tid 797171] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/file5.php"] [unique_id "al4OzOsTy9vX-htKvPkTvgAAAwo"]
[Mon Jul 20 06:04:28.637434 2026] [security2:error] [pid 796928:tid 797093] [client 57.141.18.20:57940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OxusTy9vX-htKvPkSAAACvFc"]
[Mon Jul 20 06:04:28.769357 2026] [security2:error] [pid 796928:tid 797107] [client 14.225.17.146:55969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkTvAAAAso"], referer: http://lifeisbetterlakeside.com/wordpress
[Mon Jul 20 06:04:28.788868 2026] [security2:error] [pid 796567:tid 796791] [client 77.110.127.138:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4OzLLfyzVz2SrjZpisgwAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:28.973260 2026] [security2:error] [pid 796928:tid 797143] [client 180.191.235.27:53212] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 27.235.191.180.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-comments-post.php"] [unique_id "al4OzOsTy9vX-htKvPkT1gAAAu4"]
[Mon Jul 20 06:04:28.973409 2026] [security2:error] [pid 796928:tid 797143] [client 180.191.235.27:53212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "adambergeron.com"] [uri "/wp-comments-post.php"] [unique_id "al4OzOsTy9vX-htKvPkT1gAAAu4"]
[Mon Jul 20 06:04:29.002185 2026] [security2:error] [pid 796928:tid 797180] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkTxQAAAxM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:29.193877 2026] [security2:error] [pid 796928:tid 797145] [client 35.90.38.209:18942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4OzesTy9vX-htKvPkT4AAAAvA"]
[Mon Jul 20 06:04:29.238425 2026] [security2:error] [pid 796928:tid 797078] [client 43.205.139.3:19848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4OyusTy9vX-htKvPkTDgAAAq0"]
[Mon Jul 20 06:04:29.327155 2026] [security2:error] [pid 796928:tid 797113] [client 35.90.38.209:18954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OzesTy9vX-htKvPkT6AAAAtA"]
[Mon Jul 20 06:04:29.328482 2026] [security2:error] [pid 796567:tid 796751] [client 98.159.234.160:39475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4OzbLfyzVz2SrjZpiskQAAAko"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:29.387780 2026] [security2:error] [pid 796928:tid 797130] [client 104.234.53.89:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4OzesTy9vX-htKvPkT6gAAAuE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:29.612604 2026] [core:error] [pid 796928:tid 797106] [client 14.225.17.146:54891] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:04:29.612627 2026] [core:error] [pid 796928:tid 797106] [client 14.225.17.146:54891] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:04:30.085106 2026] [security2:error] [pid 796928:tid 797113] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/0xD.php"] [unique_id "al4OzusTy9vX-htKvPkUGAAAAtA"]
[Mon Jul 20 06:04:30.085241 2026] [security2:error] [pid 796928:tid 797113] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/0xD.php"] [unique_id "al4OzusTy9vX-htKvPkUGAAAAtA"]
[Mon Jul 20 06:04:30.462696 2026] [security2:error] [pid 796928:tid 797183] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fnstall.php"] [unique_id "al4OzusTy9vX-htKvPkUKQAAAxY"]
[Mon Jul 20 06:04:30.462844 2026] [security2:error] [pid 796928:tid 797183] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fnstall.php"] [unique_id "al4OzusTy9vX-htKvPkUKQAAAxY"]
[Mon Jul 20 06:04:30.735708 2026] [security2:error] [pid 796567:tid 796805] [client 104.234.53.90:32771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4OzrLfyzVz2SrjZpiswAAAAoA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:30.812973 2026] [security2:error] [pid 796928:tid 797075] [client 185.132.186.77:61757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/install.php"] [unique_id "al4OzusTy9vX-htKvPkUPwAAAqo"]
[Mon Jul 20 06:04:30.835333 2026] [security2:error] [pid 796567:tid 796718] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/acp.php"] [unique_id "al4OzrLfyzVz2SrjZpiswgAAAik"]
[Mon Jul 20 06:04:30.835499 2026] [security2:error] [pid 796567:tid 796718] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/acp.php"] [unique_id "al4OzrLfyzVz2SrjZpiswgAAAik"]
[Mon Jul 20 06:04:30.841772 2026] [security2:error] [pid 796928:tid 797085] [client 115.246.21.170:5450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OzusTy9vX-htKvPkUQQAAArQ"]
[Mon Jul 20 06:04:30.841885 2026] [security2:error] [pid 796928:tid 797085] [client 115.246.21.170:5450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4OzusTy9vX-htKvPkUQQAAArQ"]
[Mon Jul 20 06:04:31.010228 2026] [security2:error] [pid 796928:tid 797152] [client 57.141.18.26:53622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OyOsTy9vX-htKvPkStgAC91M"]
[Mon Jul 20 06:04:31.049174 2026] [security2:error] [pid 796567:tid 796815] [client 18.228.171.129:55656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.171.228.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz7LfyzVz2SrjZpisygAAAoo"]
[Mon Jul 20 06:04:31.049287 2026] [security2:error] [pid 796567:tid 796815] [client 18.228.171.129:55656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz7LfyzVz2SrjZpisygAAAoo"]
[Mon Jul 20 06:04:31.185618 2026] [security2:error] [pid 796567:tid 796713] [client 14.225.17.146:65152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Oz7LfyzVz2SrjZpiszwAAAiQ"], referer: http://friendlyspreadsheet.com/wordpress
[Mon Jul 20 06:04:31.202337 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mosty.php"] [unique_id "al4Oz-sTy9vX-htKvPkUWAAAAtk"]
[Mon Jul 20 06:04:31.202472 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mosty.php"] [unique_id "al4Oz-sTy9vX-htKvPkUWAAAAtk"]
[Mon Jul 20 06:04:31.248629 2026] [security2:error] [pid 796928:tid 797086] [client 14.225.17.146:58284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkToQAAArU"], referer: http://hilltopnurseryinc.com/wordpress
[Mon Jul 20 06:04:31.382798 2026] [security2:error] [pid 796567:tid 796779] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz7LfyzVz2SrjZpisxwACZgw"]
[Mon Jul 20 06:04:31.581471 2026] [security2:error] [pid 796567:tid 796721] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/6.php"] [unique_id "al4Oz7LfyzVz2SrjZpis4QAAAiw"]
[Mon Jul 20 06:04:31.581597 2026] [security2:error] [pid 796567:tid 796721] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/6.php"] [unique_id "al4Oz7LfyzVz2SrjZpis4QAAAiw"]
[Mon Jul 20 06:04:31.599069 2026] [security2:error] [pid 796928:tid 797154] [client 57.141.18.26:53634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OyesTy9vX-htKvPkS0gAC-R8"]
[Mon Jul 20 06:04:31.694481 2026] [security2:error] [pid 796928:tid 797115] [client 14.225.17.146:51756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4OzesTy9vX-htKvPkT5gAAAtI"], referer: http://secretkeynumerology.com/wordpress
[Mon Jul 20 06:04:31.779798 2026] [security2:error] [pid 796567:tid 796733] [client 136.112.200.207:43536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "bucknutscoffeeco.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Oz7LfyzVz2SrjZpis7wAAAjg"]
[Mon Jul 20 06:04:31.930421 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/32e17094cfindex.php"] [unique_id "al4Oz7LfyzVz2SrjZpis9AAAAig"]
[Mon Jul 20 06:04:31.930565 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/32e17094cfindex.php"] [unique_id "al4Oz7LfyzVz2SrjZpis9AAAAig"]
[Mon Jul 20 06:04:31.950372 2026] [security2:error] [pid 796928:tid 797117] [client 129.222.187.209:64818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz-sTy9vX-htKvPkUggAAAtQ"]
[Mon Jul 20 06:04:31.960744 2026] [security2:error] [pid 796928:tid 797117] [client 129.222.187.209:64818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Oz-sTy9vX-htKvPkUggAAAtQ"]
[Mon Jul 20 06:04:31.962496 2026] [security2:error] [pid 796567:tid 796697] [client 136.112.200.207:43536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "bucknutscoffeeco.com"] [uri "/"] [unique_id "al4Oz7LfyzVz2SrjZpis9gAAAhQ"]
[Mon Jul 20 06:04:31.967521 2026] [security2:error] [pid 796928:tid 796931] [remote 182.77.62.24:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Oz-sTy9vX-htKvPkUgQAC7AI"]
[Mon Jul 20 06:04:32.066296 2026] [security2:error] [pid 796928:tid 797059] [client 14.225.17.146:54245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Oz-sTy9vX-htKvPkUgwAAApo"], referer: https://friendlyspreadsheet.com/wordpress
[Mon Jul 20 06:04:32.284379 2026] [security2:error] [pid 796567:tid 796798] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/qqqa.php"] [unique_id "al4O0LLfyzVz2SrjZpis_wAAAnk"]
[Mon Jul 20 06:04:32.284518 2026] [security2:error] [pid 796567:tid 796798] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/qqqa.php"] [unique_id "al4O0LLfyzVz2SrjZpis_wAAAnk"]
[Mon Jul 20 06:04:32.335636 2026] [security2:error] [pid 796567:tid 796791] [client 50.116.65.227:58798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4O0LLfyzVz2SrjZpitAAAAAnI"]
[Mon Jul 20 06:04:32.347211 2026] [security2:error] [pid 796928:tid 797125] [client 50.116.65.227:11904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4O0OsTy9vX-htKvPkUpQAAAtw"]
[Mon Jul 20 06:04:32.515405 2026] [security2:error] [pid 796928:tid 797003] [remote 182.77.62.24:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4O0OsTy9vX-htKvPkUswACrko"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:04:32.643639 2026] [security2:error] [pid 796928:tid 797130] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/aunmc.php"] [unique_id "al4O0OsTy9vX-htKvPkUvgAAAuE"]
[Mon Jul 20 06:04:32.643772 2026] [security2:error] [pid 796928:tid 797130] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/aunmc.php"] [unique_id "al4O0OsTy9vX-htKvPkUvgAAAuE"]
[Mon Jul 20 06:04:32.664236 2026] [security2:error] [pid 796928:tid 797151] [client 41.173.37.102:12290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwAAAAvY"]
[Mon Jul 20 06:04:32.664372 2026] [security2:error] [pid 796928:tid 797151] [client 41.173.37.102:12290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwAAAAvY"]
[Mon Jul 20 06:04:32.687217 2026] [security2:error] [pid 796928:tid 797128] [client 14.225.17.146:50577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUsgAAAt8"], referer: https://secretkeynumerology.com/wordpress
[Mon Jul 20 06:04:32.687527 2026] [security2:error] [pid 796928:tid 797119] [client 14.225.17.146:50614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUuQAAAtY"], referer: http://momheadquarters.com/wordpress
[Mon Jul 20 06:04:32.764951 2026] [security2:error] [pid 796928:tid 797167] [client 185.132.186.79:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/sunrise/admin.php"] [unique_id "al4O0OsTy9vX-htKvPkUwgAAAwY"]
[Mon Jul 20 06:04:32.812976 2026] [security2:error] [pid 796928:tid 797099] [client 178.152.178.232:37350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwwAAAsI"]
[Mon Jul 20 06:04:32.813138 2026] [security2:error] [pid 796928:tid 797099] [client 178.152.178.232:37350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUwwAAAsI"]
[Mon Jul 20 06:04:32.874625 2026] [security2:error] [pid 796928:tid 797176] [client 77.110.127.138:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUywAAAw8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:32.888403 2026] [security2:error] [pid 796928:tid 797107] [client 210.212.97.243:10438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUzAAAAso"]
[Mon Jul 20 06:04:32.888574 2026] [security2:error] [pid 796928:tid 797107] [client 210.212.97.243:10438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O0OsTy9vX-htKvPkUzAAAAso"]
[Mon Jul 20 06:04:32.928670 2026] [security2:error] [pid 796928:tid 797182] [client 77.110.127.138:55058] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4O0OsTy9vX-htKvPkU0gAAAxU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:33.127603 2026] [security2:error] [pid 796928:tid 796967] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O0esTy9vX-htKvPkU5wADESY"]
[Mon Jul 20 06:04:33.127795 2026] [security2:error] [pid 796928:tid 797178] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O0esTy9vX-htKvPkU5wADESY"]
[Mon Jul 20 06:04:33.381198 2026] [security2:error] [pid 796928:tid 797070] [client 57.141.18.23:31284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oy-sTy9vX-htKvPkTRAACpSc"]
[Mon Jul 20 06:04:33.402931 2026] [security2:error] [pid 796928:tid 797161] [client 14.225.17.146:56930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUtAAAAwA"]
[Mon Jul 20 06:04:33.437538 2026] [security2:error] [pid 796928:tid 797185] [client 14.225.17.146:58957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4Oz-sTy9vX-htKvPkUVAAAAxg"]
[Mon Jul 20 06:04:33.658489 2026] [security2:error] [pid 796567:tid 796715] [client 104.168.59.36:37808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "genlius.com"] [uri "/"] [unique_id "al4O0bLfyzVz2SrjZpitJwAAAiY"]
[Mon Jul 20 06:04:33.846776 2026] [security2:error] [pid 796567:tid 796746] [client 192.236.168.43:45160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.genlius.com"] [uri "/"] [unique_id "al4O0bLfyzVz2SrjZpitLgAAAkU"]
[Mon Jul 20 06:04:33.905664 2026] [security2:error] [pid 796567:tid 796783] [client 57.141.18.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4O0bLfyzVz2SrjZpitLAAAAmo"]
[Mon Jul 20 06:04:33.927589 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/uoocf.php"] [unique_id "al4O0esTy9vX-htKvPkVEQAAAsM"]
[Mon Jul 20 06:04:33.927694 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/uoocf.php"] [unique_id "al4O0esTy9vX-htKvPkVEQAAAsM"]
[Mon Jul 20 06:04:34.027871 2026] [security2:error] [pid 796928:tid 797142] [client 103.95.123.246:17604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVFQAAAu0"]
[Mon Jul 20 06:04:34.027994 2026] [security2:error] [pid 796928:tid 797142] [client 103.95.123.246:17604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVFQAAAu0"]
[Mon Jul 20 06:04:34.084660 2026] [security2:error] [pid 796567:tid 796588] [remote 20.173.88.122:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4O0rLfyzVz2SrjZpitOAACZxQ"]
[Mon Jul 20 06:04:34.271446 2026] [security2:error] [pid 796567:tid 796742] [client 164.100.212.184:51185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitQQAAAkE"]
[Mon Jul 20 06:04:34.271560 2026] [security2:error] [pid 796567:tid 796742] [client 164.100.212.184:51185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitQQAAAkE"]
[Mon Jul 20 06:04:34.309860 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/iywwi.php"] [unique_id "al4O0usTy9vX-htKvPkVIgAAAwY"]
[Mon Jul 20 06:04:34.309989 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/iywwi.php"] [unique_id "al4O0usTy9vX-htKvPkVIgAAAwY"]
[Mon Jul 20 06:04:34.435872 2026] [security2:error] [pid 796928:tid 797158] [client 181.224.94.124:35891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVLgAAAv0"]
[Mon Jul 20 06:04:34.435996 2026] [security2:error] [pid 796928:tid 797158] [client 181.224.94.124:35891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0usTy9vX-htKvPkVLgAAAv0"]
[Mon Jul 20 06:04:34.453880 2026] [security2:error] [pid 796567:tid 796661] [remote 20.173.88.122:53594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4O0rLfyzVz2SrjZpitRQACil0"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 06:04:34.540216 2026] [security2:error] [pid 796567:tid 796767] [client 14.225.17.146:50247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4O0rLfyzVz2SrjZpitQAAAAlo"], referer: http://massagelacey.com/wordpress
[Mon Jul 20 06:04:34.716891 2026] [security2:error] [pid 796928:tid 797157] [client 185.132.186.74:34831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/gifclass.php"] [unique_id "al4O0usTy9vX-htKvPkVQQAAAvw"]
[Mon Jul 20 06:04:34.718461 2026] [security2:error] [pid 796928:tid 797117] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/gqgsa.php"] [unique_id "al4O0usTy9vX-htKvPkVQgAAAtQ"]
[Mon Jul 20 06:04:34.718544 2026] [security2:error] [pid 796928:tid 797117] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/gqgsa.php"] [unique_id "al4O0usTy9vX-htKvPkVQgAAAtQ"]
[Mon Jul 20 06:04:34.784220 2026] [security2:error] [pid 796567:tid 796792] [client 103.149.16.77:65039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitVAAAAnM"]
[Mon Jul 20 06:04:34.784363 2026] [security2:error] [pid 796567:tid 796792] [client 103.149.16.77:65039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O0rLfyzVz2SrjZpitVAAAAnM"]
[Mon Jul 20 06:04:34.903676 2026] [security2:error] [pid 796567:tid 796706] [client 104.234.53.62:31815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4O0rLfyzVz2SrjZpitVQAAAh0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:34.964641 2026] [security2:error] [pid 796928:tid 796993] [remote 47.86.33.52:32326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O0usTy9vX-htKvPkVTgACzUA"]
[Mon Jul 20 06:04:35.021284 2026] [security2:error] [pid 796567:tid 796799] [client 85.204.70.112:60164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4O07LfyzVz2SrjZpitVgAAAno"]
[Mon Jul 20 06:04:35.095764 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/elbzl.php"] [unique_id "al4O0-sTy9vX-htKvPkVWwAAAqQ"]
[Mon Jul 20 06:04:35.095863 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/elbzl.php"] [unique_id "al4O0-sTy9vX-htKvPkVWwAAAqQ"]
[Mon Jul 20 06:04:35.250330 2026] [security2:error] [pid 796567:tid 796754] [client 104.234.53.62:31815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4O07LfyzVz2SrjZpitYQAAAk0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:35.350845 2026] [security2:error] [pid 796928:tid 797005] [remote 47.86.33.52:32326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O0-sTy9vX-htKvPkVaQACr0w"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:04:35.395352 2026] [security2:error] [pid 796928:tid 797163] [client 57.141.18.93:35116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4OzOsTy9vX-htKvPkT0gADAmk"]
[Mon Jul 20 06:04:35.412420 2026] [security2:error] [pid 796928:tid 797135] [client 129.222.187.209:19982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkVbwAAAuY"]
[Mon Jul 20 06:04:35.415211 2026] [security2:error] [pid 796928:tid 797135] [client 129.222.187.209:19982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkVbwAAAuY"]
[Mon Jul 20 06:04:35.443004 2026] [security2:error] [pid 796928:tid 797102] [client 85.204.70.112:60172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkVcQAAAsU"]
[Mon Jul 20 06:04:35.463660 2026] [security2:error] [pid 796567:tid 796715] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/adjig.php"] [unique_id "al4O07LfyzVz2SrjZpitZAAAAiY"]
[Mon Jul 20 06:04:35.463784 2026] [security2:error] [pid 796567:tid 796715] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/adjig.php"] [unique_id "al4O07LfyzVz2SrjZpitZAAAAiY"]
[Mon Jul 20 06:04:35.554421 2026] [security2:error] [pid 796567:tid 796760] [client 86.98.90.58:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O07LfyzVz2SrjZpitZwAAAlM"]
[Mon Jul 20 06:04:35.583453 2026] [security2:error] [pid 796567:tid 796760] [client 86.98.90.58:52887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O07LfyzVz2SrjZpitZwAAAlM"]
[Mon Jul 20 06:04:35.747129 2026] [autoindex:error] [pid 796928:tid 797068] [client 188.166.248.173:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:35.780548 2026] [security2:error] [pid 796928:tid 796948] [remote 98.156.100.191:38664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkViwADFhM"]
[Mon Jul 20 06:04:35.780766 2026] [security2:error] [pid 796928:tid 797183] [client 98.156.100.191:38664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O0-sTy9vX-htKvPkViwADFhM"]
[Mon Jul 20 06:04:35.788221 2026] [security2:error] [pid 796567:tid 796720] [client 14.225.17.146:50631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4O0bLfyzVz2SrjZpitLQAAAis"], referer: http://nurturemarple.co.uk/wordpress
[Mon Jul 20 06:04:35.825708 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/byp.php"] [unique_id "al4O0-sTy9vX-htKvPkVjQAAAs8"]
[Mon Jul 20 06:04:35.825823 2026] [security2:error] [pid 796928:tid 797112] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/byp.php"] [unique_id "al4O0-sTy9vX-htKvPkVjQAAAs8"]
[Mon Jul 20 06:04:36.014052 2026] [security2:error] [pid 796567:tid 796758] [client 72.255.10.154:2417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O1LLfyzVz2SrjZpitdAAAAlE"]
[Mon Jul 20 06:04:36.014261 2026] [security2:error] [pid 796567:tid 796758] [client 72.255.10.154:2417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O1LLfyzVz2SrjZpitdAAAAlE"]
[Mon Jul 20 06:04:36.215819 2026] [security2:error] [pid 796567:tid 796730] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ortasekerli1.php"] [unique_id "al4O1LLfyzVz2SrjZpitfwAAAjU"]
[Mon Jul 20 06:04:36.215908 2026] [security2:error] [pid 796567:tid 796730] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ortasekerli1.php"] [unique_id "al4O1LLfyzVz2SrjZpitfwAAAjU"]
[Mon Jul 20 06:04:36.576914 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/classwithtostring.php"] [unique_id "al4O1OsTy9vX-htKvPkVpQAAAtk"]
[Mon Jul 20 06:04:36.577014 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/classwithtostring.php"] [unique_id "al4O1OsTy9vX-htKvPkVpQAAAtk"]
[Mon Jul 20 06:04:36.903736 2026] [security2:error] [pid 796567:tid 796779] [client 85.204.70.112:60184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4O1LLfyzVz2SrjZpitmQAAAmY"]
[Mon Jul 20 06:04:36.955286 2026] [security2:error] [pid 796567:tid 796749] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/root.php"] [unique_id "al4O1LLfyzVz2SrjZpitmgAAAkg"]
[Mon Jul 20 06:04:36.955386 2026] [security2:error] [pid 796567:tid 796749] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/root.php"] [unique_id "al4O1LLfyzVz2SrjZpitmgAAAkg"]
[Mon Jul 20 06:04:37.131914 2026] [ssl:error] [pid 796567:tid 796777] [client 2.194.133.19:38316] AH02032: Hostname www.perrysnopeep.com provided via SNI and hostname www.forbes.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:04:37.302066 2026] [security2:error] [pid 796928:tid 797083] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4O1esTy9vX-htKvPkVzAAAArI"]
[Mon Jul 20 06:04:37.404567 2026] [security2:error] [pid 796928:tid 797109] [client 43.205.139.3:63372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O1esTy9vX-htKvPkVywAAAsw"]
[Mon Jul 20 06:04:37.420864 2026] [security2:error] [pid 796567:tid 796812] [client 85.204.70.112:60188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4O1bLfyzVz2SrjZpitpwAAAoc"]
[Mon Jul 20 06:04:37.508785 2026] [security2:error] [pid 796928:tid 797168] [client 14.225.17.146:58389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4O1esTy9vX-htKvPkV1AAAAwc"], referer: https://nurturemarple.co.uk/wordpress
[Mon Jul 20 06:04:37.538765 2026] [security2:error] [pid 796567:tid 796766] [client 57.141.18.125:51712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oz7LfyzVz2SrjZpisyQACWW8"]
[Mon Jul 20 06:04:37.592328 2026] [security2:error] [pid 796928:tid 797079] [client 106.192.104.4:58939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O1esTy9vX-htKvPkV4QAAAq4"]
[Mon Jul 20 06:04:37.592456 2026] [security2:error] [pid 796928:tid 797079] [client 106.192.104.4:58939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O1esTy9vX-htKvPkV4QAAAq4"]
[Mon Jul 20 06:04:37.649359 2026] [security2:error] [pid 796928:tid 797089] [client 185.132.186.78:30961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugin.php"] [unique_id "al4O1esTy9vX-htKvPkV5AAAArg"]
[Mon Jul 20 06:04:37.649951 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sym403.php"] [unique_id "al4O1esTy9vX-htKvPkV5QAAAwU"]
[Mon Jul 20 06:04:37.650067 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sym403.php"] [unique_id "al4O1esTy9vX-htKvPkV5QAAAwU"]
[Mon Jul 20 06:04:37.866845 2026] [security2:error] [pid 796567:tid 796702] [client 57.141.18.57:62478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Oz7LfyzVz2SrjZpis2AACGSo"]
[Mon Jul 20 06:04:37.942513 2026] [security2:error] [pid 796928:tid 797170] [client 77.110.127.138:55087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4O1esTy9vX-htKvPkV9gAAAwk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:38.051493 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/v543.php"] [unique_id "al4O1usTy9vX-htKvPkV-wAAAvU"]
[Mon Jul 20 06:04:38.051651 2026] [security2:error] [pid 796928:tid 797150] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/v543.php"] [unique_id "al4O1usTy9vX-htKvPkV-wAAAvU"]
[Mon Jul 20 06:04:38.116284 2026] [security2:error] [pid 796567:tid 796619] [remote 57.141.18.59:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4O1rLfyzVz2SrjZpitxQACcjM"]
[Mon Jul 20 06:04:38.315475 2026] [security2:error] [pid 796567:tid 796775] [client 85.204.70.112:50292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4O1rLfyzVz2SrjZpitywAAAmI"]
[Mon Jul 20 06:04:38.407199 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sixxis.php"] [unique_id "al4O1rLfyzVz2SrjZpit0QAAAko"]
[Mon Jul 20 06:04:38.407281 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sixxis.php"] [unique_id "al4O1rLfyzVz2SrjZpit0QAAAko"]
[Mon Jul 20 06:04:38.428442 2026] [security2:error] [pid 796928:tid 797091] [client 77.110.127.138:55066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O1usTy9vX-htKvPkWEQAAAro"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:38.787856 2026] [security2:error] [pid 796928:tid 797173] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ip.php"] [unique_id "al4O1usTy9vX-htKvPkWKQAAAww"]
[Mon Jul 20 06:04:38.787964 2026] [security2:error] [pid 796928:tid 797173] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ip.php"] [unique_id "al4O1usTy9vX-htKvPkWKQAAAww"]
[Mon Jul 20 06:04:38.817112 2026] [security2:error] [pid 796567:tid 796788] [client 47.31.86.100:60365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O1rLfyzVz2SrjZpit4wAAAm8"]
[Mon Jul 20 06:04:38.830842 2026] [security2:error] [pid 796567:tid 796788] [client 47.31.86.100:60365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O1rLfyzVz2SrjZpit4wAAAm8"]
[Mon Jul 20 06:04:38.834908 2026] [security2:error] [pid 796567:tid 796753] [client 57.141.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4O1rLfyzVz2SrjZpit3gAAAkw"]
[Mon Jul 20 06:04:38.998948 2026] [security2:error] [pid 796928:tid 797145] [client 52.59.238.198:28836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O1usTy9vX-htKvPkWNQAAAvA"]
[Mon Jul 20 06:04:39.100064 2026] [security2:error] [pid 796567:tid 796703] [client 112.213.160.112:8255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7QAAAho"]
[Mon Jul 20 06:04:39.100178 2026] [security2:error] [pid 796567:tid 796703] [client 112.213.160.112:8255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7QAAAho"]
[Mon Jul 20 06:04:39.144296 2026] [security2:error] [pid 796928:tid 797136] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/kq1.php"] [unique_id "al4O1-sTy9vX-htKvPkWPAAAAuc"]
[Mon Jul 20 06:04:39.144389 2026] [security2:error] [pid 796928:tid 797136] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/kq1.php"] [unique_id "al4O1-sTy9vX-htKvPkWPAAAAuc"]
[Mon Jul 20 06:04:39.214643 2026] [security2:error] [pid 796567:tid 796803] [client 150.228.148.150:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7wAAAn4"]
[Mon Jul 20 06:04:39.214860 2026] [security2:error] [pid 796567:tid 796803] [client 150.228.148.150:55447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O17LfyzVz2SrjZpit7wAAAn4"]
[Mon Jul 20 06:04:39.507661 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fw/faiyy.php"] [unique_id "al4O17LfyzVz2SrjZpit-QAAAmE"]
[Mon Jul 20 06:04:39.507793 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fw/faiyy.php"] [unique_id "al4O17LfyzVz2SrjZpit-QAAAmE"]
[Mon Jul 20 06:04:39.530368 2026] [security2:error] [pid 796567:tid 796800] [client 14.225.17.146:65509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpit8gAAAns"], referer: http://latiendadejorge.com.gt/wordpress
[Mon Jul 20 06:04:39.531151 2026] [security2:error] [pid 796928:tid 797097] [client 57.141.18.5:58768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUxgACwDc"]
[Mon Jul 20 06:04:39.532712 2026] [security2:error] [pid 796928:tid 797155] [client 57.141.18.25:31138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O0OsTy9vX-htKvPkUygAC-gA"]
[Mon Jul 20 06:04:39.564588 2026] [security2:error] [pid 796928:tid 797166] [client 63.176.132.15:57904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O1-sTy9vX-htKvPkWUwAAAwU"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:04:39.594157 2026] [security2:error] [pid 796567:tid 796714] [client 185.132.186.86:20261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/bypass.php"] [unique_id "al4O17LfyzVz2SrjZpit_wAAAiU"]
[Mon Jul 20 06:04:39.617147 2026] [security2:error] [pid 796567:tid 796767] [client 77.110.127.138:55060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4O17LfyzVz2SrjZpiuAAAAAlo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:39.670367 2026] [security2:error] [pid 796567:tid 796745] [client 47.128.96.137:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpit9wAAAkQ"]
[Mon Jul 20 06:04:39.739136 2026] [security2:error] [pid 796928:tid 797099] [client 85.204.70.112:50308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4O1-sTy9vX-htKvPkWYAAAAsI"]
[Mon Jul 20 06:04:39.907976 2026] [security2:error] [pid 796567:tid 796792] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/h02ugyh.php"] [unique_id "al4O17LfyzVz2SrjZpiuCgAAAnM"]
[Mon Jul 20 06:04:39.908067 2026] [security2:error] [pid 796567:tid 796792] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/h02ugyh.php"] [unique_id "al4O17LfyzVz2SrjZpiuCgAAAnM"]
[Mon Jul 20 06:04:39.978919 2026] [security2:error] [pid 796567:tid 796711] [client 14.225.17.146:54338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpiuDAAAAiI"], referer: http://grndl.com/wordpress
[Mon Jul 20 06:04:40.205075 2026] [security2:error] [pid 796567:tid 796818] [client 85.204.70.112:50310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4O2LLfyzVz2SrjZpiuFgAAAo0"]
[Mon Jul 20 06:04:40.281484 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-temp.php"] [unique_id "al4O2OsTy9vX-htKvPkWegAAAtk"]
[Mon Jul 20 06:04:40.281599 2026] [security2:error] [pid 796928:tid 797122] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-temp.php"] [unique_id "al4O2OsTy9vX-htKvPkWegAAAtk"]
[Mon Jul 20 06:04:40.292966 2026] [security2:error] [pid 796567:tid 796743] [client 57.141.18.41:21954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O0bLfyzVz2SrjZpitJQACQn8"]
[Mon Jul 20 06:04:40.452009 2026] [security2:error] [pid 796928:tid 797110] [client 77.110.127.138:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O2OsTy9vX-htKvPkWggAAAs0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:40.636111 2026] [security2:error] [pid 796928:tid 797086] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-content/cong.php"] [unique_id "al4O2OsTy9vX-htKvPkWkwAAArU"]
[Mon Jul 20 06:04:40.636249 2026] [security2:error] [pid 796928:tid 797086] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-content/cong.php"] [unique_id "al4O2OsTy9vX-htKvPkWkwAAArU"]
[Mon Jul 20 06:04:40.707387 2026] [security2:error] [pid 796928:tid 797077] [client 85.204.70.112:50316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4O2OsTy9vX-htKvPkWlQAAAqw"]
[Mon Jul 20 06:04:40.805315 2026] [security2:error] [pid 796928:tid 797126] [client 74.208.214.194:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4O2OsTy9vX-htKvPkWlwAAAt0"]
[Mon Jul 20 06:04:41.052702 2026] [security2:error] [pid 796928:tid 797182] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O2OsTy9vX-htKvPkWnwAAAxU"]
[Mon Jul 20 06:04:41.143271 2026] [security2:error] [pid 796928:tid 797146] [client 85.204.70.112:50322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4O2esTy9vX-htKvPkWqAAAAvE"]
[Mon Jul 20 06:04:41.243742 2026] [security2:error] [pid 796928:tid 797152] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4O2esTy9vX-htKvPkWrwAAAvc"]
[Mon Jul 20 06:04:41.243901 2026] [security2:error] [pid 796928:tid 797152] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4O2esTy9vX-htKvPkWrwAAAvc"]
[Mon Jul 20 06:04:41.308505 2026] [security2:error] [pid 796928:tid 797122] [client 18.140.64.130:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWsQAAAtk"]
[Mon Jul 20 06:04:41.308679 2026] [security2:error] [pid 796928:tid 797122] [client 18.140.64.130:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWsQAAAtk"]
[Mon Jul 20 06:04:41.505995 2026] [security2:error] [pid 796567:tid 796784] [client 115.246.21.170:52303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O2bLfyzVz2SrjZpiuTAAAAms"]
[Mon Jul 20 06:04:41.506120 2026] [security2:error] [pid 796567:tid 796784] [client 115.246.21.170:52303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O2bLfyzVz2SrjZpiuTAAAAms"]
[Mon Jul 20 06:04:41.524144 2026] [security2:error] [pid 796928:tid 797064] [client 85.204.70.112:50328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4O2esTy9vX-htKvPkWuAAAAp8"]
[Mon Jul 20 06:04:41.545304 2026] [security2:error] [pid 796567:tid 796708] [client 185.132.186.100:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/update-core.php"] [unique_id "al4O2bLfyzVz2SrjZpiuUwAAAh8"]
[Mon Jul 20 06:04:41.607634 2026] [security2:error] [pid 796928:tid 797175] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/jj.php"] [unique_id "al4O2esTy9vX-htKvPkWvAAAAw4"]
[Mon Jul 20 06:04:41.607738 2026] [security2:error] [pid 796928:tid 797175] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/jj.php"] [unique_id "al4O2esTy9vX-htKvPkWvAAAAw4"]
[Mon Jul 20 06:04:41.716814 2026] [security2:error] [pid 796567:tid 796722] [client 57.141.18.38:47554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O07LfyzVz2SrjZpitWwACLWA"]
[Mon Jul 20 06:04:41.741072 2026] [security2:error] [pid 796567:tid 796721] [client 57.141.18.66:23186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O07LfyzVz2SrjZpitWgACLBw"]
[Mon Jul 20 06:04:41.917735 2026] [security2:error] [pid 796928:tid 797106] [client 85.204.70.112:50338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4O2esTy9vX-htKvPkWxQAAAsk"]
[Mon Jul 20 06:04:41.962944 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al4O2esTy9vX-htKvPkWywAAArA"]
[Mon Jul 20 06:04:41.963106 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al4O2esTy9vX-htKvPkWywAAArA"]
[Mon Jul 20 06:04:42.007827 2026] [security2:error] [pid 796928:tid 797134] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWvgAC5S0"]
[Mon Jul 20 06:04:42.259346 2026] [security2:error] [pid 796928:tid 797086] [client 56.125.35.21:47566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O2esTy9vX-htKvPkWwwAAArU"]
[Mon Jul 20 06:04:42.292971 2026] [security2:error] [pid 796567:tid 796791] [client 14.225.17.146:64088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4O17LfyzVz2SrjZpiuAwAAAnI"], referer: http://www.justinagrayman.com/wordpress
[Mon Jul 20 06:04:42.323817 2026] [security2:error] [pid 796928:tid 797169] [client 14.225.17.146:65436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4O2usTy9vX-htKvPkW0wAAAwg"], referer: http://sarahsnyder.net/wordpress
[Mon Jul 20 06:04:42.352311 2026] [security2:error] [pid 796928:tid 797181] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/txets.php"] [unique_id "al4O2usTy9vX-htKvPkW3gAAAxQ"]
[Mon Jul 20 06:04:42.352436 2026] [security2:error] [pid 796928:tid 797181] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/txets.php"] [unique_id "al4O2usTy9vX-htKvPkW3gAAAxQ"]
[Mon Jul 20 06:04:42.463878 2026] [security2:error] [pid 796567:tid 796812] [client 129.222.187.209:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiudwAAAoc"]
[Mon Jul 20 06:04:42.468621 2026] [security2:error] [pid 796567:tid 796812] [client 129.222.187.209:51164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiudwAAAoc"]
[Mon Jul 20 06:04:42.558868 2026] [security2:error] [pid 796567:tid 796654] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiufAACGVY"]
[Mon Jul 20 06:04:42.559050 2026] [security2:error] [pid 796567:tid 796702] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2rLfyzVz2SrjZpiufAACGVY"]
[Mon Jul 20 06:04:42.743232 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/dex.php"] [unique_id "al4O2usTy9vX-htKvPkW8QAAAwY"]
[Mon Jul 20 06:04:42.743392 2026] [security2:error] [pid 796928:tid 797167] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/dex.php"] [unique_id "al4O2usTy9vX-htKvPkW8QAAAwY"]
[Mon Jul 20 06:04:42.812997 2026] [security2:error] [pid 796567:tid 796784] [client 85.204.70.112:50354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4O2rLfyzVz2SrjZpiujAAAAms"]
[Mon Jul 20 06:04:42.949203 2026] [security2:error] [pid 796567:tid 796771] [client 57.141.18.95:26978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O1LLfyzVz2SrjZpitigACXgQ"]
[Mon Jul 20 06:04:43.147576 2026] [security2:error] [pid 796928:tid 797141] [client 18.141.57.241:55834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O2usTy9vX-htKvPkW6QAAAuw"]
[Mon Jul 20 06:04:43.296990 2026] [security2:error] [pid 796928:tid 797070] [client 41.173.37.102:12720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXDgAAAqU"]
[Mon Jul 20 06:04:43.297099 2026] [security2:error] [pid 796928:tid 797070] [client 41.173.37.102:12720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXDgAAAqU"]
[Mon Jul 20 06:04:43.334058 2026] [security2:error] [pid 796928:tid 797080] [client 85.204.70.112:50358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4O2-sTy9vX-htKvPkXEwAAAq8"]
[Mon Jul 20 06:04:43.410537 2026] [security2:error] [pid 796928:tid 797072] [client 27.96.94.195:37183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGgAAAqc"]
[Mon Jul 20 06:04:43.410774 2026] [security2:error] [pid 796928:tid 797072] [client 27.96.94.195:37183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGgAAAqc"]
[Mon Jul 20 06:04:43.418532 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:55181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4O27LfyzVz2SrjZpiuoQAAAhg"], referer: https://sarahsnyder.net/wordpress
[Mon Jul 20 06:04:43.433911 2026] [security2:error] [pid 796928:tid 797108] [client 178.152.178.232:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGwAAAss"]
[Mon Jul 20 06:04:43.434031 2026] [security2:error] [pid 796928:tid 797108] [client 178.152.178.232:37388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXGwAAAss"]
[Mon Jul 20 06:04:43.502114 2026] [security2:error] [pid 796928:tid 797174] [client 185.132.186.94:40399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "al4O2-sTy9vX-htKvPkXIQAAAw0"]
[Mon Jul 20 06:04:43.519148 2026] [security2:error] [pid 796567:tid 796741] [client 210.212.97.243:10439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O27LfyzVz2SrjZpiurwAAAkA"]
[Mon Jul 20 06:04:43.519303 2026] [security2:error] [pid 796567:tid 796741] [client 210.212.97.243:10439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O27LfyzVz2SrjZpiurwAAAkA"]
[Mon Jul 20 06:04:43.909474 2026] [security2:error] [pid 796928:tid 797070] [client 77.110.127.138:55087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXNgAAAqU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:43.914555 2026] [security2:error] [pid 796928:tid 797033] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXNQAC92g"]
[Mon Jul 20 06:04:43.914867 2026] [security2:error] [pid 796928:tid 797152] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O2-sTy9vX-htKvPkXNQAC92g"]
[Mon Jul 20 06:04:44.004425 2026] [security2:error] [pid 796567:tid 796787] [client 14.225.17.146:63388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4O2bLfyzVz2SrjZpiuWgAAAm4"], referer: http://adirondackengineering.com/wordpress
[Mon Jul 20 06:04:44.200223 2026] [security2:error] [pid 796567:tid 796816] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xpwer1.php"] [unique_id "al4O3LLfyzVz2SrjZpiuywAAAos"]
[Mon Jul 20 06:04:44.200359 2026] [security2:error] [pid 796567:tid 796816] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/xpwer1.php"] [unique_id "al4O3LLfyzVz2SrjZpiuywAAAos"]
[Mon Jul 20 06:04:44.308082 2026] [security2:error] [pid 796567:tid 796735] [client 85.204.70.112:50362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4O3LLfyzVz2SrjZpiuzgAAAjo"]
[Mon Jul 20 06:04:44.368043 2026] [security2:error] [pid 796928:tid 797167] [client 186.194.175.10:34304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4O3OsTy9vX-htKvPkXSQADBk8"]
[Mon Jul 20 06:04:44.530123 2026] [security2:error] [pid 796567:tid 796730] [client 45.157.112.60:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O3LLfyzVz2SrjZpiu1QAAAjU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:44.561232 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/flox.php"] [unique_id "al4O3LLfyzVz2SrjZpiu2gAAAko"]
[Mon Jul 20 06:04:44.561326 2026] [security2:error] [pid 796567:tid 796751] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/flox.php"] [unique_id "al4O3LLfyzVz2SrjZpiu2gAAAko"]
[Mon Jul 20 06:04:44.624682 2026] [security2:error] [pid 796928:tid 797134] [client 46.110.96.34:20695] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4O3OsTy9vX-htKvPkXXgAAAuU"]
[Mon Jul 20 06:04:44.731157 2026] [security2:error] [pid 796928:tid 797061] [client 85.204.70.112:50368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4O3OsTy9vX-htKvPkXZQAAApw"]
[Mon Jul 20 06:04:44.854818 2026] [security2:error] [pid 796567:tid 796824] [client 104.234.53.91:32533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4O3LLfyzVz2SrjZpiu4gAAApM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:44.923757 2026] [security2:error] [pid 796928:tid 797107] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/popo.php"] [unique_id "al4O3OsTy9vX-htKvPkXcQAAAso"]
[Mon Jul 20 06:04:44.923860 2026] [security2:error] [pid 796928:tid 797107] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/popo.php"] [unique_id "al4O3OsTy9vX-htKvPkXcQAAAso"]
[Mon Jul 20 06:04:44.940616 2026] [security2:error] [pid 796928:tid 797090] [client 181.224.94.124:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXcgAAArk"]
[Mon Jul 20 06:04:44.940746 2026] [security2:error] [pid 796928:tid 797090] [client 181.224.94.124:49795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXcgAAArk"]
[Mon Jul 20 06:04:44.976534 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O3LLfyzVz2SrjZpiu4wAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:44.984396 2026] [security2:error] [pid 796928:tid 797137] [client 103.95.123.246:18427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXdgAAAug"]
[Mon Jul 20 06:04:44.985181 2026] [security2:error] [pid 796928:tid 797137] [client 103.95.123.246:18427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O3OsTy9vX-htKvPkXdgAAAug"]
[Mon Jul 20 06:04:45.125019 2026] [security2:error] [pid 796928:tid 797096] [client 85.204.70.112:50378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4O3esTy9vX-htKvPkXewAAAr8"]
[Mon Jul 20 06:04:45.234942 2026] [security2:error] [pid 796928:tid 797102] [client 57.141.18.20:61566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O1usTy9vX-htKvPkWGgACxRQ"]
[Mon Jul 20 06:04:45.267642 2026] [security2:error] [pid 796928:tid 797097] [client 158.173.166.181:45355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O3esTy9vX-htKvPkXhAAAAsA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:45.293516 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/yas.php"] [unique_id "al4O3bLfyzVz2SrjZpiu9wAAAog"]
[Mon Jul 20 06:04:45.293661 2026] [security2:error] [pid 796567:tid 796813] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/yas.php"] [unique_id "al4O3bLfyzVz2SrjZpiu9wAAAog"]
[Mon Jul 20 06:04:45.294600 2026] [security2:error] [pid 796567:tid 796742] [client 14.225.17.146:56154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4O3LLfyzVz2SrjZpiuwwAAAkE"], referer: http://travelbyfire.com/wordpress
[Mon Jul 20 06:04:45.321524 2026] [security2:error] [pid 796928:tid 797117] [client 46.110.96.34:64634] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4O3esTy9vX-htKvPkXhQAAAtQ"]
[Mon Jul 20 06:04:45.321650 2026] [security2:error] [pid 796928:tid 797117] [client 46.110.96.34:64634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4O3esTy9vX-htKvPkXhQAAAtQ"]
[Mon Jul 20 06:04:45.328541 2026] [security2:error] [pid 796928:tid 797120] [client 50.116.65.227:46962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4O3esTy9vX-htKvPkXhgAAAtc"]
[Mon Jul 20 06:04:45.340106 2026] [security2:error] [pid 796928:tid 797184] [client 50.116.65.227:46972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4O3esTy9vX-htKvPkXiAAAAxc"]
[Mon Jul 20 06:04:45.361472 2026] [security2:error] [pid 796928:tid 797103] [client 103.149.16.77:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXiQAAAsY"]
[Mon Jul 20 06:04:45.361601 2026] [security2:error] [pid 796928:tid 797103] [client 103.149.16.77:65414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXiQAAAsY"]
[Mon Jul 20 06:04:45.448059 2026] [security2:error] [pid 796567:tid 796734] [client 185.132.186.96:42949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-mail.php"] [unique_id "al4O3bLfyzVz2SrjZpiu_AAAAjk"]
[Mon Jul 20 06:04:45.650401 2026] [security2:error] [pid 796567:tid 796794] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/file61.php"] [unique_id "al4O3bLfyzVz2SrjZpivDAAAAnU"]
[Mon Jul 20 06:04:45.650477 2026] [security2:error] [pid 796567:tid 796794] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/file61.php"] [unique_id "al4O3bLfyzVz2SrjZpivDAAAAnU"]
[Mon Jul 20 06:04:45.674144 2026] [security2:error] [pid 796928:tid 797142] [client 164.100.212.184:62802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXngAAAu0"]
[Mon Jul 20 06:04:45.674276 2026] [security2:error] [pid 796928:tid 797142] [client 164.100.212.184:62802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4O3esTy9vX-htKvPkXngAAAu0"]
[Mon Jul 20 06:04:45.792421 2026] [security2:error] [pid 796567:tid 796784] [client 104.234.53.91:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4O3bLfyzVz2SrjZpivEgAAAms"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:45.857252 2026] [security2:error] [pid 796567:tid 796703] [client 129.222.187.209:55650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.187.222.129.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3bLfyzVz2SrjZpivFQAAAho"]
[Mon Jul 20 06:04:45.867658 2026] [security2:error] [pid 796567:tid 796703] [client 129.222.187.209:55650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4O3bLfyzVz2SrjZpivFQAAAho"]
[Mon Jul 20 06:04:45.998123 2026] [security2:error] [pid 796928:tid 797154] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/water.php"] [unique_id "al4O3esTy9vX-htKvPkXrgAAAvk"]
[Mon Jul 20 06:04:45.998251 2026] [security2:error] [pid 796928:tid 797154] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/water.php"] [unique_id "al4O3esTy9vX-htKvPkXrgAAAvk"]
[Mon Jul 20 06:04:46.207066 2026] [security2:error] [pid 796928:tid 797095] [client 14.225.17.146:55571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4O3usTy9vX-htKvPkXtgAAAr4"], referer: https://travelbyfire.com/wordpress
[Mon Jul 20 06:04:46.369481 2026] [security2:error] [pid 796567:tid 796820] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/nano.php"] [unique_id "al4O3rLfyzVz2SrjZpivMgAAAo8"]
[Mon Jul 20 06:04:46.369583 2026] [security2:error] [pid 796567:tid 796820] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/nano.php"] [unique_id "al4O3rLfyzVz2SrjZpivMgAAAo8"]
[Mon Jul 20 06:04:46.483556 2026] [security2:error] [pid 796928:tid 797101] [client 104.234.53.89:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4O3usTy9vX-htKvPkXwwAAAsQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:46.561621 2026] [security2:error] [pid 796928:tid 797100] [client 86.98.90.58:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O3usTy9vX-htKvPkXygAAAsM"]
[Mon Jul 20 06:04:46.561987 2026] [security2:error] [pid 796928:tid 797100] [client 86.98.90.58:53715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4O3usTy9vX-htKvPkXygAAAsM"]
[Mon Jul 20 06:04:46.602652 2026] [security2:error] [pid 796567:tid 796799] [client 72.255.10.154:2419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O3rLfyzVz2SrjZpivNgAAAno"]
[Mon Jul 20 06:04:46.602807 2026] [security2:error] [pid 796567:tid 796799] [client 72.255.10.154:2419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O3rLfyzVz2SrjZpivNgAAAno"]
[Mon Jul 20 06:04:46.639877 2026] [security2:error] [pid 796928:tid 797090] [client 85.204.70.112:50384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4O3usTy9vX-htKvPkXzQAAArk"]
[Mon Jul 20 06:04:46.749829 2026] [security2:error] [pid 796928:tid 797073] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/moon.php"] [unique_id "al4O3usTy9vX-htKvPkX0gAAAqg"]
[Mon Jul 20 06:04:46.749930 2026] [security2:error] [pid 796928:tid 797073] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/moon.php"] [unique_id "al4O3usTy9vX-htKvPkX0gAAAqg"]
[Mon Jul 20 06:04:47.024858 2026] [security2:error] [pid 796567:tid 796807] [client 57.141.18.24:33440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O2LLfyzVz2SrjZpiuJwACgk4"]
[Mon Jul 20 06:04:47.026295 2026] [security2:error] [pid 796928:tid 797062] [client 85.204.70.112:50394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.cfy.cnq.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4O3-sTy9vX-htKvPkX2QAAAp0"]
[Mon Jul 20 06:04:47.130554 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-info.php"] [unique_id "al4O3-sTy9vX-htKvPkX3gAAAr4"]
[Mon Jul 20 06:04:47.130650 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-info.php"] [unique_id "al4O3-sTy9vX-htKvPkX3gAAAr4"]
[Mon Jul 20 06:04:47.234462 2026] [autoindex:error] [pid 796928:tid 797146] [client 198.235.24.55:61028] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:04:47.392757 2026] [security2:error] [pid 796567:tid 796781] [client 185.132.186.101:26087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/admin.php"] [unique_id "al4O37LfyzVz2SrjZpivYQAAAmg"]
[Mon Jul 20 06:04:47.475641 2026] [security2:error] [pid 796567:tid 796753] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/2000.php"] [unique_id "al4O37LfyzVz2SrjZpivZAAAAkw"]
[Mon Jul 20 06:04:47.475741 2026] [security2:error] [pid 796567:tid 796753] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/2000.php"] [unique_id "al4O37LfyzVz2SrjZpivZAAAAkw"]
[Mon Jul 20 06:04:47.737320 2026] [security2:error] [pid 796567:tid 796761] [client 77.110.127.138:55060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O37LfyzVz2SrjZpivdQAAAlQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:47.752296 2026] [security2:error] [pid 796928:tid 797138] [client 50.116.65.227:47934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Saigon-Kiss-Street-Food-Tour-Feature-Image.jpg"] [unique_id "al4O3-sTy9vX-htKvPkX_AAAAuk"]
[Mon Jul 20 06:04:47.765651 2026] [security2:error] [pid 796567:tid 796776] [client 50.116.65.227:47082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Saigon-Kiss-Street-Food-Tour-Feature-Image.jpg"] [unique_id "al4O37LfyzVz2SrjZpivdgAAAmM"]
[Mon Jul 20 06:04:47.863176 2026] [security2:error] [pid 796928:tid 797121] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/122.php"] [unique_id "al4O3-sTy9vX-htKvPkYAgAAAtg"]
[Mon Jul 20 06:04:47.863350 2026] [security2:error] [pid 796928:tid 797121] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/122.php"] [unique_id "al4O3-sTy9vX-htKvPkYAgAAAtg"]
[Mon Jul 20 06:04:47.876137 2026] [security2:error] [pid 796567:tid 796755] [client 57.141.18.45:26070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O2bLfyzVz2SrjZpiuVAACTiI"]
[Mon Jul 20 06:04:48.038658 2026] [security2:error] [pid 796567:tid 796818] [client 13.201.64.214:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O4LLfyzVz2SrjZpivgQAAAo0"]
[Mon Jul 20 06:04:48.038801 2026] [security2:error] [pid 796567:tid 796818] [client 13.201.64.214:56848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O4LLfyzVz2SrjZpivgQAAAo0"]
[Mon Jul 20 06:04:48.236814 2026] [security2:error] [pid 796928:tid 797157] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/mds.php"] [unique_id "al4O4OsTy9vX-htKvPkYFgAAAvw"]
[Mon Jul 20 06:04:48.236904 2026] [security2:error] [pid 796928:tid 797157] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/mds.php"] [unique_id "al4O4OsTy9vX-htKvPkYFgAAAvw"]
[Mon Jul 20 06:04:48.639516 2026] [security2:error] [pid 796928:tid 797140] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-blink.php"] [unique_id "al4O4OsTy9vX-htKvPkYKgAAAus"]
[Mon Jul 20 06:04:48.639673 2026] [security2:error] [pid 796928:tid 797140] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-blink.php"] [unique_id "al4O4OsTy9vX-htKvPkYKgAAAus"]
[Mon Jul 20 06:04:48.674249 2026] [ssl:error] [pid 796928:tid 797156] [client 95.74.226.106:19306] AH02032: Hostname www.perrysnopeep.crmpfilms.com provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:04:48.757777 2026] [security2:error] [pid 796928:tid 797080] [client 106.192.104.4:59458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O4OsTy9vX-htKvPkYMQAAAq8"]
[Mon Jul 20 06:04:48.757896 2026] [security2:error] [pid 796928:tid 797080] [client 106.192.104.4:59458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O4OsTy9vX-htKvPkYMQAAAq8"]
[Mon Jul 20 06:04:48.933582 2026] [security2:error] [pid 796928:tid 797075] [client 103.153.183.69:25038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../etc/ssh/sshd_config"] [unique_id "al4O4OsTy9vX-htKvPkYPAAAAqo"], referer: https://t.co/ddzi1kh5xa
[Mon Jul 20 06:04:48.943972 2026] [security2:error] [pid 796567:tid 796814] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4O4LLfyzVz2SrjZpivkAAAAok"]
[Mon Jul 20 06:04:49.004403 2026] [security2:error] [pid 796567:tid 796731] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O4LLfyzVz2SrjZpivoQAAAjY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:49.024922 2026] [security2:error] [pid 796928:tid 797124] [client 158.173.89.95:53245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O4esTy9vX-htKvPkYRQAAAts"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:04:49.039429 2026] [security2:error] [pid 796928:tid 797088] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zc-208.php"] [unique_id "al4O4esTy9vX-htKvPkYRgAAArc"]
[Mon Jul 20 06:04:49.039557 2026] [security2:error] [pid 796928:tid 797088] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zc-208.php"] [unique_id "al4O4esTy9vX-htKvPkYRgAAArc"]
[Mon Jul 20 06:04:49.123897 2026] [security2:error] [pid 796928:tid 797064] [client 57.141.18.125:63354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O2usTy9vX-htKvPkW6gACn14"]
[Mon Jul 20 06:04:49.130000 2026] [security2:error] [pid 796567:tid 796688] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O4bLfyzVz2SrjZpivrAACang"]
[Mon Jul 20 06:04:49.130176 2026] [security2:error] [pid 796567:tid 796783] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O4bLfyzVz2SrjZpivrAACang"]
[Mon Jul 20 06:04:49.196522 2026] [security2:error] [pid 796928:tid 797161] [client 77.110.127.138:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O4esTy9vX-htKvPkYTwAAAwA"], referer: https://mezzacraft.com/contact-me/
[Mon Jul 20 06:04:49.255296 2026] [security2:error] [pid 796928:tid 797106] [client 47.31.86.100:60815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYWgAAAsk"]
[Mon Jul 20 06:04:49.256562 2026] [security2:error] [pid 796928:tid 797115] [client 103.153.183.69:25038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../root/.ssh/id_rsa"] [unique_id "al4O4esTy9vX-htKvPkYWQAAAtI"], referer: https://www.bing.com/search?q=bdwwhf
[Mon Jul 20 06:04:49.260049 2026] [security2:error] [pid 796928:tid 797106] [client 47.31.86.100:60815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYWgAAAsk"]
[Mon Jul 20 06:04:49.344150 2026] [security2:error] [pid 796567:tid 796727] [client 185.132.186.64:53395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/defaults.php"] [unique_id "al4O4bLfyzVz2SrjZpivtgAAAjI"]
[Mon Jul 20 06:04:49.416184 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/sid4.php"] [unique_id "al4O4bLfyzVz2SrjZpivuQAAAmU"]
[Mon Jul 20 06:04:49.416372 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/sid4.php"] [unique_id "al4O4bLfyzVz2SrjZpivuQAAAmU"]
[Mon Jul 20 06:04:49.637071 2026] [security2:error] [pid 796567:tid 796743] [client 57.141.18.51:53360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O27LfyzVz2SrjZpiumgACQmk"]
[Mon Jul 20 06:04:49.806871 2026] [security2:error] [pid 796567:tid 796808] [client 104.234.53.80:44685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4O4bLfyzVz2SrjZpivxAAAAoM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:49.836606 2026] [security2:error] [pid 796928:tid 797176] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O4esTy9vX-htKvPkYawAAAw8"]
[Mon Jul 20 06:04:49.902205 2026] [security2:error] [pid 796928:tid 797175] [client 112.213.160.112:8382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYdQAAAw4"]
[Mon Jul 20 06:04:49.902409 2026] [security2:error] [pid 796928:tid 797175] [client 112.213.160.112:8382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O4esTy9vX-htKvPkYdQAAAw4"]
[Mon Jul 20 06:04:49.951688 2026] [security2:error] [pid 796567:tid 796728] [client 57.141.18.80:60144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O27LfyzVz2SrjZpiupwACM2M"]
[Mon Jul 20 06:04:50.018004 2026] [security2:error] [pid 796928:tid 797064] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wmore1.php"] [unique_id "al4O4usTy9vX-htKvPkYfAAAAp8"]
[Mon Jul 20 06:04:50.018112 2026] [security2:error] [pid 796928:tid 797064] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wmore1.php"] [unique_id "al4O4usTy9vX-htKvPkYfAAAAp8"]
[Mon Jul 20 06:04:50.063710 2026] [security2:error] [pid 796567:tid 796801] [client 14.225.17.146:55747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4O37LfyzVz2SrjZpivaAAAAnw"], referer: http://itdynamix.com/wordpress
[Mon Jul 20 06:04:50.099926 2026] [security2:error] [pid 796928:tid 797126] [client 150.228.148.150:24914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O4usTy9vX-htKvPkYfgAAAt0"]
[Mon Jul 20 06:04:50.115562 2026] [security2:error] [pid 796928:tid 797126] [client 150.228.148.150:24914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O4usTy9vX-htKvPkYfgAAAt0"]
[Mon Jul 20 06:04:50.214791 2026] [security2:error] [pid 796928:tid 797155] [client 77.110.127.138:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O4usTy9vX-htKvPkYiwAAAvo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:50.396021 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/solo1.php"] [unique_id "al4O4usTy9vX-htKvPkYlAAAAsM"]
[Mon Jul 20 06:04:50.396120 2026] [security2:error] [pid 796928:tid 797100] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/solo1.php"] [unique_id "al4O4usTy9vX-htKvPkYlAAAAsM"]
[Mon Jul 20 06:04:50.831727 2026] [security2:error] [pid 796928:tid 797125] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O4usTy9vX-htKvPkYowAAAtw"]
[Mon Jul 20 06:04:51.036675 2026] [security2:error] [pid 796928:tid 797118] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/cong.php"] [unique_id "al4O4-sTy9vX-htKvPkYsQAAAtU"]
[Mon Jul 20 06:04:51.036809 2026] [security2:error] [pid 796928:tid 797118] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/cong.php"] [unique_id "al4O4-sTy9vX-htKvPkYsQAAAtU"]
[Mon Jul 20 06:04:51.052974 2026] [security2:error] [pid 796928:tid 796930] [remote 84.247.172.23:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4O4-sTy9vX-htKvPkYsgACwAE"]
[Mon Jul 20 06:04:51.192168 2026] [security2:error] [pid 796928:tid 797122] [client 14.225.17.146:63215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4O4usTy9vX-htKvPkYrgAAAtk"], referer: https://itdynamix.com/wordpress
[Mon Jul 20 06:04:51.212469 2026] [security2:error] [pid 796928:tid 797152] [client 57.141.18.68:58174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O3OsTy9vX-htKvPkXZAAC91o"]
[Mon Jul 20 06:04:51.267578 2026] [security2:error] [pid 796928:tid 797119] [client 14.225.17.146:56339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4O4-sTy9vX-htKvPkYtAAAAtY"], referer: http://transparentservices.online/wordpress
[Mon Jul 20 06:04:51.292470 2026] [security2:error] [pid 796567:tid 796742] [client 185.132.186.84:25459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "al4O47LfyzVz2SrjZpiwBwAAAkE"]
[Mon Jul 20 06:04:51.447187 2026] [security2:error] [pid 796567:tid 796719] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ashleystrain.com"] [uri "/index.cgi"] [unique_id "al4O47LfyzVz2SrjZpiwDAAAAio"]
[Mon Jul 20 06:04:51.455568 2026] [security2:error] [pid 796928:tid 797131] [client 14.225.17.146:57360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4O4esTy9vX-htKvPkYeQAAAuI"], referer: http://scott-assist.com/wordpress
[Mon Jul 20 06:04:51.468610 2026] [security2:error] [pid 796928:tid 797037] [remote 84.247.172.23:47964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4O4-sTy9vX-htKvPkYwgACsmw"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:04:51.536704 2026] [security2:error] [pid 796567:tid 796603] [remote 192.241.143.148:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4O47LfyzVz2SrjZpiwFQACKSM"]
[Mon Jul 20 06:04:51.637303 2026] [security2:error] [pid 796928:tid 797043] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al4O4-sTy9vX-htKvPkYxwACy3I"]
[Mon Jul 20 06:04:51.638877 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/public/css.php"] [unique_id "al4O47LfyzVz2SrjZpiwGgAAAh8"]
[Mon Jul 20 06:04:51.638953 2026] [security2:error] [pid 796567:tid 796708] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/public/css.php"] [unique_id "al4O47LfyzVz2SrjZpiwGgAAAh8"]
[Mon Jul 20 06:04:51.670001 2026] [security2:error] [pid 796928:tid 797077] [client 103.153.183.69:49848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4O4-sTy9vX-htKvPkYzAAAAqw"], referer: https://www.google.com/
[Mon Jul 20 06:04:51.706000 2026] [security2:error] [pid 796928:tid 797085] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O4-sTy9vX-htKvPkYxAAAArQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:51.706445 2026] [security2:error] [pid 796567:tid 796574] [remote 192.241.143.148:38388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4O47LfyzVz2SrjZpiwHgACkAY"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:04:51.754007 2026] [security2:error] [pid 796928:tid 797078] [client 103.153.183.69:49848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4O4-sTy9vX-htKvPkY1AAAAq0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:04:51.764615 2026] [security2:error] [pid 796567:tid 796776] [client 27.96.94.195:37968] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O47LfyzVz2SrjZpiwGwAAAmM"]
[Mon Jul 20 06:04:51.764771 2026] [security2:error] [pid 796567:tid 796776] [client 27.96.94.195:37968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O47LfyzVz2SrjZpiwGwAAAmM"]
[Mon Jul 20 06:04:51.921803 2026] [security2:error] [pid 796928:tid 797092] [client 57.141.18.102:51340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O3esTy9vX-htKvPkXlgACu0A"]
[Mon Jul 20 06:04:52.029790 2026] [security2:error] [pid 796567:tid 796711] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/output.php"] [unique_id "al4O5LLfyzVz2SrjZpiwKAAAAiI"]
[Mon Jul 20 06:04:52.029905 2026] [security2:error] [pid 796567:tid 796711] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/output.php"] [unique_id "al4O5LLfyzVz2SrjZpiwKAAAAiI"]
[Mon Jul 20 06:04:52.228887 2026] [security2:error] [pid 796928:tid 797168] [client 115.246.21.170:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkY7gAAAwc"]
[Mon Jul 20 06:04:52.228990 2026] [security2:error] [pid 796928:tid 797168] [client 115.246.21.170:28699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkY7gAAAwc"]
[Mon Jul 20 06:04:52.380489 2026] [security2:error] [pid 796567:tid 796726] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-file-120.php"] [unique_id "al4O5LLfyzVz2SrjZpiwNgAAAjE"]
[Mon Jul 20 06:04:52.380591 2026] [security2:error] [pid 796567:tid 796726] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-file-120.php"] [unique_id "al4O5LLfyzVz2SrjZpiwNgAAAjE"]
[Mon Jul 20 06:04:52.597003 2026] [security2:error] [pid 796567:tid 796725] [client 14.225.17.146:55807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4O4bLfyzVz2SrjZpivywAAAjA"], referer: http://idigress.studio/wordpress
[Mon Jul 20 06:04:52.696340 2026] [security2:error] [pid 796928:tid 797078] [client 77.110.127.138:55109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkZAAAAAq0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:52.700648 2026] [security2:error] [pid 796928:tid 797110] [client 56.125.35.21:53268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkY-AAAAs0"]
[Mon Jul 20 06:04:52.719283 2026] [security2:error] [pid 796567:tid 796765] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O5LLfyzVz2SrjZpiwOAACWE4"]
[Mon Jul 20 06:04:52.761186 2026] [security2:error] [pid 796567:tid 796704] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/special.php"] [unique_id "al4O5LLfyzVz2SrjZpiwTgAAAhs"]
[Mon Jul 20 06:04:52.761289 2026] [security2:error] [pid 796567:tid 796704] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/special.php"] [unique_id "al4O5LLfyzVz2SrjZpiwTgAAAhs"]
[Mon Jul 20 06:04:52.785612 2026] [security2:error] [pid 796928:tid 797045] [remote 103.82.22.235:42270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkZAgAC4nQ"]
[Mon Jul 20 06:04:52.785840 2026] [security2:error] [pid 796928:tid 797131] [client 103.82.22.235:42270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O5OsTy9vX-htKvPkZAgAC4nQ"]
[Mon Jul 20 06:04:53.003984 2026] [security2:error] [pid 796928:tid 796960] [remote 72.167.132.114:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O5OsTy9vX-htKvPkZCgACqx8"]
[Mon Jul 20 06:04:53.229112 2026] [security2:error] [pid 796928:tid 796945] [remote 72.167.132.114:52184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O5esTy9vX-htKvPkZFQACyhA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:04:53.255892 2026] [security2:error] [pid 796928:tid 797148] [client 185.132.186.99:48557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/ALFA_DATA/alfacgiapi/bypass.php"] [unique_id "al4O5esTy9vX-htKvPkZFwAAAvM"]
[Mon Jul 20 06:04:53.352692 2026] [security2:error] [pid 796567:tid 796732] [client 104.234.53.69:46067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwbAAAAjc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:53.556272 2026] [security2:error] [pid 796567:tid 796749] [client 178.152.178.232:37514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiweAAAAkg"]
[Mon Jul 20 06:04:53.556398 2026] [security2:error] [pid 796567:tid 796749] [client 178.152.178.232:37514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiweAAAAkg"]
[Mon Jul 20 06:04:53.567007 2026] [security2:error] [pid 796567:tid 796757] [client 57.141.18.7:63436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O37LfyzVz2SrjZpivTgACUCQ"]
[Mon Jul 20 06:04:53.652102 2026] [security2:error] [pid 796567:tid 796674] [remote 40.77.167.247:37960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marscafe.com"] [uri "/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwfgAChmo"]
[Mon Jul 20 06:04:53.677291 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/as.php"] [unique_id "al4O5bLfyzVz2SrjZpiwgAAAAmU"]
[Mon Jul 20 06:04:53.677407 2026] [security2:error] [pid 796567:tid 796778] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/as.php"] [unique_id "al4O5bLfyzVz2SrjZpiwgAAAAmU"]
[Mon Jul 20 06:04:53.749756 2026] [security2:error] [pid 796928:tid 797128] [client 14.224.227.113:55575] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4O5esTy9vX-htKvPkZKwAAAt8"]
[Mon Jul 20 06:04:53.918014 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiwiQAAAkU"]
[Mon Jul 20 06:04:53.918153 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O5bLfyzVz2SrjZpiwiQAAAkU"]
[Mon Jul 20 06:04:53.944193 2026] [security2:error] [pid 796567:tid 796724] [client 24.77.48.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwhQACLxM"]
[Mon Jul 20 06:04:53.977365 2026] [security2:error] [pid 796928:tid 797151] [client 210.212.97.243:10440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O5esTy9vX-htKvPkZOQAAAvY"]
[Mon Jul 20 06:04:53.977519 2026] [security2:error] [pid 796928:tid 797151] [client 210.212.97.243:10440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O5esTy9vX-htKvPkZOQAAAvY"]
[Mon Jul 20 06:04:54.037202 2026] [security2:error] [pid 796928:tid 797111] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/cgi-bin/index.php"] [unique_id "al4O5usTy9vX-htKvPkZOwAAAs4"]
[Mon Jul 20 06:04:54.037346 2026] [security2:error] [pid 796928:tid 797111] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/cgi-bin/index.php"] [unique_id "al4O5usTy9vX-htKvPkZOwAAAs4"]
[Mon Jul 20 06:04:54.329942 2026] [security2:error] [pid 796928:tid 797176] [client 14.225.17.146:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4O5OsTy9vX-htKvPkZCAAAAw8"], referer: http://mazzucelli.com/wordpress
[Mon Jul 20 06:04:54.371226 2026] [security2:error] [pid 796567:tid 796766] [client 57.141.18.17:27812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O37LfyzVz2SrjZpivbgACWRQ"]
[Mon Jul 20 06:04:54.392856 2026] [security2:error] [pid 796567:tid 796775] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/w1px.php"] [unique_id "al4O5rLfyzVz2SrjZpiwnwAAAmI"]
[Mon Jul 20 06:04:54.392970 2026] [security2:error] [pid 796567:tid 796775] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/w1px.php"] [unique_id "al4O5rLfyzVz2SrjZpiwnwAAAmI"]
[Mon Jul 20 06:04:54.453640 2026] [security2:error] [pid 796567:tid 796679] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O5rLfyzVz2SrjZpiwpwACVm8"]
[Mon Jul 20 06:04:54.453817 2026] [security2:error] [pid 796567:tid 796763] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O5rLfyzVz2SrjZpiwpwACVm8"]
[Mon Jul 20 06:04:54.717521 2026] [security2:error] [pid 796567:tid 796814] [client 14.225.17.146:55064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4O5LLfyzVz2SrjZpiwPAAAAok"], referer: http://fluidtemple.org/wordpress
[Mon Jul 20 06:04:54.775704 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/yawa.php"] [unique_id "al4O5usTy9vX-htKvPkZUgAAAwU"]
[Mon Jul 20 06:04:54.775832 2026] [security2:error] [pid 796928:tid 797166] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/yawa.php"] [unique_id "al4O5usTy9vX-htKvPkZUgAAAwU"]
[Mon Jul 20 06:04:55.138108 2026] [security2:error] [pid 796928:tid 797062] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/js.php"] [unique_id "al4O5-sTy9vX-htKvPkZZAAAAp0"]
[Mon Jul 20 06:04:55.138194 2026] [security2:error] [pid 796928:tid 797062] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/js.php"] [unique_id "al4O5-sTy9vX-htKvPkZZAAAAp0"]
[Mon Jul 20 06:04:55.203549 2026] [security2:error] [pid 796928:tid 797117] [client 185.132.186.67:53827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/about.php"] [unique_id "al4O5-sTy9vX-htKvPkZZwAAAtQ"]
[Mon Jul 20 06:04:55.287338 2026] [security2:error] [pid 796928:tid 797151] [client 65.1.132.125:58140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZawAAAvY"]
[Mon Jul 20 06:04:55.287459 2026] [security2:error] [pid 796928:tid 797151] [client 65.1.132.125:58140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZawAAAvY"]
[Mon Jul 20 06:04:55.450465 2026] [security2:error] [pid 796928:tid 797111] [client 181.224.94.124:27658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZcwAAAs4"]
[Mon Jul 20 06:04:55.450596 2026] [security2:error] [pid 796928:tid 797111] [client 181.224.94.124:27658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O5-sTy9vX-htKvPkZcwAAAs4"]
[Mon Jul 20 06:04:55.494719 2026] [security2:error] [pid 796567:tid 796808] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/core.php"] [unique_id "al4O57LfyzVz2SrjZpiw0gAAAoM"]
[Mon Jul 20 06:04:55.494875 2026] [security2:error] [pid 796567:tid 796808] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/core.php"] [unique_id "al4O57LfyzVz2SrjZpiw0gAAAoM"]
[Mon Jul 20 06:04:55.846186 2026] [security2:error] [pid 796928:tid 797119] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/19.php"] [unique_id "al4O5-sTy9vX-htKvPkZgwAAAtY"]
[Mon Jul 20 06:04:55.846309 2026] [security2:error] [pid 796928:tid 797119] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/19.php"] [unique_id "al4O5-sTy9vX-htKvPkZgwAAAtY"]
[Mon Jul 20 06:04:55.973574 2026] [security2:error] [pid 796928:tid 796994] [remote 162.19.86.63:42064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O5-sTy9vX-htKvPkZiwACo0E"]
[Mon Jul 20 06:04:56.224266 2026] [security2:error] [pid 796928:tid 797146] [client 103.149.16.77:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O6OsTy9vX-htKvPkZnwAAAvE"]
[Mon Jul 20 06:04:56.224418 2026] [security2:error] [pid 796928:tid 797146] [client 103.149.16.77:49408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O6OsTy9vX-htKvPkZnwAAAvE"]
[Mon Jul 20 06:04:56.325290 2026] [security2:error] [pid 796928:tid 797131] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O6OsTy9vX-htKvPkZkQAAAuI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:56.411946 2026] [security2:error] [pid 796928:tid 797184] [client 57.141.18.93:62416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O4esTy9vX-htKvPkYbAADF3w"]
[Mon Jul 20 06:04:56.669135 2026] [security2:error] [pid 796567:tid 796722] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/inc.php"] [unique_id "al4O6LLfyzVz2SrjZpixBAAAAi0"]
[Mon Jul 20 06:04:56.669248 2026] [security2:error] [pid 796567:tid 796722] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/inc.php"] [unique_id "al4O6LLfyzVz2SrjZpixBAAAAi0"]
[Mon Jul 20 06:04:57.028700 2026] [security2:error] [pid 796928:tid 796978] [remote 162.19.86.63:42064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O6esTy9vX-htKvPkZxwACzjE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:04:57.038857 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-ppoxua4.php"] [unique_id "al4O6bLfyzVz2SrjZpixFgAAAmE"]
[Mon Jul 20 06:04:57.038970 2026] [security2:error] [pid 796567:tid 796774] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-ppoxua4.php"] [unique_id "al4O6bLfyzVz2SrjZpixFgAAAmE"]
[Mon Jul 20 06:04:57.154550 2026] [security2:error] [pid 796928:tid 797155] [client 185.132.186.100:45807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/about.php"] [unique_id "al4O6esTy9vX-htKvPkZ1gAAAvo"]
[Mon Jul 20 06:04:57.185415 2026] [security2:error] [pid 796567:tid 796704] [client 72.255.10.154:2433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O6bLfyzVz2SrjZpixHwAAAhs"]
[Mon Jul 20 06:04:57.185550 2026] [security2:error] [pid 796567:tid 796704] [client 72.255.10.154:2433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O6bLfyzVz2SrjZpixHwAAAhs"]
[Mon Jul 20 06:04:57.292611 2026] [security2:error] [pid 796567:tid 796800] [client 14.182.195.220:51983] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O6bLfyzVz2SrjZpixJAAAAns"]
[Mon Jul 20 06:04:57.296157 2026] [security2:error] [pid 796567:tid 796731] [client 14.182.195.220:51985] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O6bLfyzVz2SrjZpixJQAAAjY"]
[Mon Jul 20 06:04:57.298718 2026] [security2:error] [pid 796928:tid 797069] [client 14.182.195.220:51984] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O6esTy9vX-htKvPkZ2wAAAqQ"]
[Mon Jul 20 06:04:57.401860 2026] [security2:error] [pid 796928:tid 797105] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al4O6esTy9vX-htKvPkZ3gAAAsg"]
[Mon Jul 20 06:04:57.401987 2026] [security2:error] [pid 796928:tid 797105] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al4O6esTy9vX-htKvPkZ3gAAAsg"]
[Mon Jul 20 06:04:57.734706 2026] [security2:error] [pid 796928:tid 797130] [client 14.225.17.146:52556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4O5usTy9vX-htKvPkZWAAAAuE"], referer: http://worbals.com/wordpress
[Mon Jul 20 06:04:57.757474 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ss.php"] [unique_id "al4O6esTy9vX-htKvPkZ9gAAArA"]
[Mon Jul 20 06:04:57.757594 2026] [security2:error] [pid 796928:tid 797081] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ss.php"] [unique_id "al4O6esTy9vX-htKvPkZ9gAAArA"]
[Mon Jul 20 06:04:57.875263 2026] [security2:error] [pid 796928:tid 797164] [client 57.141.18.11:27912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O4-sTy9vX-htKvPkYvAADAw4"]
[Mon Jul 20 06:04:57.901927 2026] [security2:error] [pid 796567:tid 796740] [client 77.110.127.138:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6bLfyzVz2SrjZpixPQAAAj8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:57.963217 2026] [security2:error] [pid 796928:tid 797117] [client 14.225.17.146:56556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4O6esTy9vX-htKvPkZ8AAAAtQ"]
[Mon Jul 20 06:04:58.013449 2026] [security2:error] [pid 796928:tid 797140] [client 64.71.131.243:47754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4O5-sTy9vX-htKvPkZggAAAus"]
[Mon Jul 20 06:04:58.161769 2026] [security2:error] [pid 796928:tid 797066] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/min.php"] [unique_id "al4O6usTy9vX-htKvPkaCQAAAqE"]
[Mon Jul 20 06:04:58.161917 2026] [security2:error] [pid 796928:tid 797066] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/min.php"] [unique_id "al4O6usTy9vX-htKvPkaCQAAAqE"]
[Mon Jul 20 06:04:58.198419 2026] [security2:error] [pid 796928:tid 797110] [client 104.234.53.57:37283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4O6usTy9vX-htKvPkaDAAAAs0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:04:58.456688 2026] [security2:error] [pid 796567:tid 796786] [client 14.225.17.146:57766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4O6LLfyzVz2SrjZpixEwAAAm0"], referer: http://betterbonddogtraining.com/wordpress
[Mon Jul 20 06:04:58.543702 2026] [security2:error] [pid 796567:tid 796762] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al4O6rLfyzVz2SrjZpixYQAAAlU"]
[Mon Jul 20 06:04:58.543921 2026] [security2:error] [pid 796567:tid 796762] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al4O6rLfyzVz2SrjZpixYQAAAlU"]
[Mon Jul 20 06:04:58.636035 2026] [security2:error] [pid 796928:tid 797058] [client 77.110.127.138:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaIwAAApk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:58.879402 2026] [security2:error] [pid 796928:tid 797117] [client 77.110.127.138:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaKgAAAtQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:58.899132 2026] [security2:error] [pid 796567:tid 796818] [client 3.109.4.218:38894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O6rLfyzVz2SrjZpixfAAAAo0"]
[Mon Jul 20 06:04:58.899297 2026] [security2:error] [pid 796567:tid 796818] [client 3.109.4.218:38894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O6rLfyzVz2SrjZpixfAAAAo0"]
[Mon Jul 20 06:04:58.908672 2026] [security2:error] [pid 796928:tid 797094] [client 103.95.123.246:18875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaKwAAAr0"]
[Mon Jul 20 06:04:58.908812 2026] [security2:error] [pid 796928:tid 797094] [client 103.95.123.246:18875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O6usTy9vX-htKvPkaKwAAAr0"]
[Mon Jul 20 06:04:58.926225 2026] [security2:error] [pid 796928:tid 797102] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/autoload_classmap.php"] [unique_id "al4O6usTy9vX-htKvPkaLAAAAsU"]
[Mon Jul 20 06:04:58.926338 2026] [security2:error] [pid 796928:tid 797102] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/autoload_classmap.php"] [unique_id "al4O6usTy9vX-htKvPkaLAAAAsU"]
[Mon Jul 20 06:04:58.990261 2026] [security2:error] [pid 796567:tid 796761] [client 74.249.226.166:29377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4O6rLfyzVz2SrjZpixgAAAAlQ"]
[Mon Jul 20 06:04:59.043807 2026] [security2:error] [pid 796567:tid 796750] [client 74.249.226.166:29377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4O67LfyzVz2SrjZpixhAAAAkk"]
[Mon Jul 20 06:04:59.087177 2026] [security2:error] [pid 796567:tid 796746] [client 185.132.186.58:35601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/2023/05/404.php"] [unique_id "al4O67LfyzVz2SrjZpixiQAAAkU"]
[Mon Jul 20 06:04:59.195950 2026] [security2:error] [pid 796567:tid 796718] [client 14.225.17.146:57770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4O6bLfyzVz2SrjZpixFQAAAik"], referer: http://webgardensbypaula.com/wordpress
[Mon Jul 20 06:04:59.317548 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-link-zorm.php"] [unique_id "al4O6-sTy9vX-htKvPkaQAAAAqU"]
[Mon Jul 20 06:04:59.317689 2026] [security2:error] [pid 796928:tid 797070] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-link-zorm.php"] [unique_id "al4O6-sTy9vX-htKvPkaQAAAAqU"]
[Mon Jul 20 06:04:59.438616 2026] [security2:error] [pid 796567:tid 796792] [client 57.141.18.9:35768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5bLfyzVz2SrjZpiwYgACc10"]
[Mon Jul 20 06:04:59.634637 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixowAAAi8"]
[Mon Jul 20 06:04:59.634816 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:59946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixowAAAi8"]
[Mon Jul 20 06:04:59.670428 2026] [security2:error] [pid 796928:tid 797167] [client 77.110.127.138:55167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6-sTy9vX-htKvPkaVQAAAwY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:59.694340 2026] [security2:error] [pid 796928:tid 797079] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-link-szoppm.php"] [unique_id "al4O6-sTy9vX-htKvPkaVgAAAq4"]
[Mon Jul 20 06:04:59.694444 2026] [security2:error] [pid 796928:tid 797079] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-link-szoppm.php"] [unique_id "al4O6-sTy9vX-htKvPkaVgAAAq4"]
[Mon Jul 20 06:04:59.695899 2026] [security2:error] [pid 796567:tid 796742] [client 47.31.86.100:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixpQAAAkE"]
[Mon Jul 20 06:04:59.696000 2026] [security2:error] [pid 796567:tid 796742] [client 47.31.86.100:61227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixpQAAAkE"]
[Mon Jul 20 06:04:59.795388 2026] [security2:error] [pid 796567:tid 796610] [remote 217.61.143.92:48604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixrwACKCo"]
[Mon Jul 20 06:04:59.795602 2026] [security2:error] [pid 796567:tid 796717] [client 217.61.143.92:48604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4O67LfyzVz2SrjZpixrwACKCo"]
[Mon Jul 20 06:04:59.795866 2026] [access_compat:error] [pid 796567:tid 796751] [client 183.47.125.206:52045] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:04:59.821615 2026] [security2:error] [pid 796928:tid 797083] [client 77.110.127.138:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O6-sTy9vX-htKvPkaYgAAArI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:04:59.855200 2026] [security2:error] [pid 796928:tid 797098] [client 57.141.18.82:55110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5esTy9vX-htKvPkZJgACwQg"]
[Mon Jul 20 06:04:59.972806 2026] [security2:error] [pid 796567:tid 796576] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al4O67LfyzVz2SrjZpixtQACGgg"]
[Mon Jul 20 06:05:00.077434 2026] [security2:error] [pid 796928:tid 797149] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/albin.php"] [unique_id "al4O7OsTy9vX-htKvPkabgAAAvQ"]
[Mon Jul 20 06:05:00.077543 2026] [security2:error] [pid 796928:tid 797149] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/albin.php"] [unique_id "al4O7OsTy9vX-htKvPkabgAAAvQ"]
[Mon Jul 20 06:05:00.143717 2026] [security2:error] [pid 796928:tid 797071] [client 77.110.127.138:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkabwAAAqY"]
[Mon Jul 20 06:05:00.176582 2026] [security2:error] [pid 796567:tid 796719] [client 195.96.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sk-financial.com"] [uri "/index.php"] [unique_id "al4O7LLfyzVz2SrjZpixuQAAAio"]
[Mon Jul 20 06:05:00.182944 2026] [security2:error] [pid 796567:tid 796738] [client 185.247.137.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sk-financial.com"] [uri "/index.php"] [unique_id "al4O7LLfyzVz2SrjZpixugAAAj0"]
[Mon Jul 20 06:05:00.255304 2026] [access_compat:error] [pid 796928:tid 797122] [client 183.47.107.86:60457] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:00.316528 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:55290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkaeQAAAqw"]
[Mon Jul 20 06:05:00.390961 2026] [security2:error] [pid 796567:tid 796629] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O7LLfyzVz2SrjZpixyQACUD0"]
[Mon Jul 20 06:05:00.391151 2026] [security2:error] [pid 796567:tid 796757] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O7LLfyzVz2SrjZpixyQACUD0"]
[Mon Jul 20 06:05:00.406135 2026] [access_compat:error] [pid 796567:tid 796714] [client 112.90.2.135:44615] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:00.475254 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/cilus.php"] [unique_id "al4O7OsTy9vX-htKvPkaigAAAwg"]
[Mon Jul 20 06:05:00.475350 2026] [security2:error] [pid 796928:tid 797169] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/cilus.php"] [unique_id "al4O7OsTy9vX-htKvPkaigAAAwg"]
[Mon Jul 20 06:05:00.580299 2026] [security2:error] [pid 796928:tid 797067] [client 150.228.148.150:56763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkalAAAAqI"]
[Mon Jul 20 06:05:00.580519 2026] [security2:error] [pid 796928:tid 797067] [client 150.228.148.150:56763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkalAAAAqI"]
[Mon Jul 20 06:05:00.604837 2026] [security2:error] [pid 796928:tid 797094] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O7OsTy9vX-htKvPkaegAAAr0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:00.669920 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkamAAAAwU"]
[Mon Jul 20 06:05:00.670101 2026] [security2:error] [pid 796928:tid 797166] [client 112.213.160.112:8492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O7OsTy9vX-htKvPkamAAAAwU"]
[Mon Jul 20 06:05:00.841026 2026] [security2:error] [pid 796567:tid 796819] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/gptsh.php"] [unique_id "al4O7LLfyzVz2SrjZpix2AAAAo4"]
[Mon Jul 20 06:05:00.841130 2026] [security2:error] [pid 796567:tid 796819] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/gptsh.php"] [unique_id "al4O7LLfyzVz2SrjZpix2AAAAo4"]
[Mon Jul 20 06:05:00.847691 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.24:45840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5rLfyzVz2SrjZpiwpgACNXE"]
[Mon Jul 20 06:05:01.032385 2026] [security2:error] [pid 796567:tid 796812] [client 185.132.186.58:24875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/maint.php"] [unique_id "al4O7bLfyzVz2SrjZpix4QAAAoc"]
[Mon Jul 20 06:05:01.217152 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/rithin.php"] [unique_id "al4O7bLfyzVz2SrjZpix6gAAAig"]
[Mon Jul 20 06:05:01.217264 2026] [security2:error] [pid 796567:tid 796717] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/rithin.php"] [unique_id "al4O7bLfyzVz2SrjZpix6gAAAig"]
[Mon Jul 20 06:05:01.314904 2026] [security2:error] [pid 796928:tid 797072] [client 52.109.124.141:33665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4O7esTy9vX-htKvPkaqgAAAqc"]
[Mon Jul 20 06:05:01.494237 2026] [security2:error] [pid 796928:tid 797067] [client 52.109.124.141:33665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4O7esTy9vX-htKvPkatwAAAqI"]
[Mon Jul 20 06:05:01.577155 2026] [security2:error] [pid 796928:tid 797090] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fffm.php"] [unique_id "al4O7esTy9vX-htKvPkavAAAArk"]
[Mon Jul 20 06:05:01.577365 2026] [security2:error] [pid 796928:tid 797090] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fffm.php"] [unique_id "al4O7esTy9vX-htKvPkavAAAArk"]
[Mon Jul 20 06:05:01.649120 2026] [security2:error] [pid 796928:tid 797170] [client 57.141.18.107:38586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5-sTy9vX-htKvPkZaAADCVY"]
[Mon Jul 20 06:05:01.955087 2026] [security2:error] [pid 796567:tid 796672] [remote 182.77.62.24:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O7bLfyzVz2SrjZpiyCgACdGg"]
[Mon Jul 20 06:05:01.988810 2026] [access_compat:error] [pid 796567:tid 796773] [client 183.47.125.177:52311] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:02.048517 2026] [security2:error] [pid 796928:tid 796942] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4O7usTy9vX-htKvPka1wAC8g0"]
[Mon Jul 20 06:05:02.194947 2026] [security2:error] [pid 796928:tid 797059] [client 57.141.18.56:28628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O5-sTy9vX-htKvPkZgQACmhk"]
[Mon Jul 20 06:05:02.380062 2026] [security2:error] [pid 796928:tid 797001] [remote 72.167.132.114:43660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O7usTy9vX-htKvPka5gAC7kg"]
[Mon Jul 20 06:05:02.482165 2026] [security2:error] [pid 796567:tid 796580] [remote 182.77.62.24:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4O7rLfyzVz2SrjZpiyIgACiAw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:05:02.611340 2026] [security2:error] [pid 796567:tid 796809] [client 52.233.165.60:29168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4O7rLfyzVz2SrjZpiyKgAAAoQ"]
[Mon Jul 20 06:05:02.711900 2026] [security2:error] [pid 796928:tid 796988] [remote 72.167.132.114:43660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O7usTy9vX-htKvPka_AACmjs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:02.757335 2026] [security2:error] [pid 796567:tid 796815] [client 52.233.165.60:29168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4O7rLfyzVz2SrjZpiyLgAAAoo"]
[Mon Jul 20 06:05:02.881719 2026] [security2:error] [pid 796928:tid 797096] [client 115.246.21.170:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O7usTy9vX-htKvPkbBgAAAr8"]
[Mon Jul 20 06:05:02.881840 2026] [security2:error] [pid 796928:tid 797096] [client 115.246.21.170:53167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O7usTy9vX-htKvPkbBgAAAr8"]
[Mon Jul 20 06:05:02.904984 2026] [security2:error] [pid 796928:tid 797139] [client 57.141.18.33:44190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O6OsTy9vX-htKvPkZuAAC6ko"]
[Mon Jul 20 06:05:02.973246 2026] [security2:error] [pid 796928:tid 797078] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/dfre.php"] [unique_id "al4O7usTy9vX-htKvPkbEQAAAq0"]
[Mon Jul 20 06:05:02.973352 2026] [security2:error] [pid 796928:tid 797078] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/dfre.php"] [unique_id "al4O7usTy9vX-htKvPkbEQAAAq0"]
[Mon Jul 20 06:05:03.020061 2026] [security2:error] [pid 796928:tid 797070] [client 14.225.17.146:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4O7usTy9vX-htKvPkbAQAAAqU"], referer: http://savilerowtravel.com/wordpress
[Mon Jul 20 06:05:03.020725 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.63:24595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/bypass.php"] [unique_id "al4O77LfyzVz2SrjZpiyQgAAAis"]
[Mon Jul 20 06:05:03.417598 2026] [security2:error] [pid 796567:tid 796823] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O77LfyzVz2SrjZpiyRAACkgI"]
[Mon Jul 20 06:05:03.486993 2026] [security2:error] [pid 796928:tid 797167] [client 56.125.35.21:36516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O7-sTy9vX-htKvPkbGQAAAwY"]
[Mon Jul 20 06:05:03.546994 2026] [security2:error] [pid 796928:tid 797105] [client 14.225.17.146:65308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4O7-sTy9vX-htKvPkbIgAAAsg"], referer: https://north-woods-engineering.com/wordpress
[Mon Jul 20 06:05:03.795088 2026] [security2:error] [pid 796928:tid 797180] [client 27.96.94.195:37993] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O7-sTy9vX-htKvPkbMwAAAxM"]
[Mon Jul 20 06:05:03.795253 2026] [security2:error] [pid 796928:tid 797180] [client 27.96.94.195:37993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4O7-sTy9vX-htKvPkbMwAAAxM"]
[Mon Jul 20 06:05:03.850841 2026] [security2:error] [pid 796928:tid 797101] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O7-sTy9vX-htKvPkbKwAAAsQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:03.989058 2026] [security2:error] [pid 796928:tid 797040] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al4O7-sTy9vX-htKvPkbNgACsm8"]
[Mon Jul 20 06:05:04.111557 2026] [security2:error] [pid 796928:tid 797163] [client 14.225.17.146:63200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4O7-sTy9vX-htKvPkbNAAAAwI"], referer: https://savilerowtravel.com/wordpress
[Mon Jul 20 06:05:04.163814 2026] [security2:error] [pid 796928:tid 797025] [remote 147.90.209.37:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.209.90.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.benbayly.co.nz"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al4O8OsTy9vX-htKvPkbPgAC8GA"]
[Mon Jul 20 06:05:04.291737 2026] [security2:error] [pid 796567:tid 796761] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/wp-happy.php"] [unique_id "al4O8LLfyzVz2SrjZpiyfwAAAlQ"]
[Mon Jul 20 06:05:04.291871 2026] [security2:error] [pid 796567:tid 796761] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/wp-happy.php"] [unique_id "al4O8LLfyzVz2SrjZpiyfwAAAlQ"]
[Mon Jul 20 06:05:04.400187 2026] [fcgid:warn] [pid 796567:tid 796728] (70014)End of file found: [client 167.94.146.53:11742] mod_fcgid: can't get data from http client
[Mon Jul 20 06:05:04.423157 2026] [security2:error] [pid 796928:tid 797061] [client 57.141.18.98:21196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O6esTy9vX-htKvPkZ_AACnBw"]
[Mon Jul 20 06:05:04.471689 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O8LLfyzVz2SrjZpiyiAAAAkU"]
[Mon Jul 20 06:05:04.471821 2026] [security2:error] [pid 796567:tid 796746] [client 41.173.37.102:13572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O8LLfyzVz2SrjZpiyiAAAAkU"]
[Mon Jul 20 06:05:04.576942 2026] [security2:error] [pid 796567:tid 796705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8LLfyzVz2SrjZpiygwAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:04.641645 2026] [security2:error] [pid 796567:tid 796765] [client 57.141.18.39:20841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O6rLfyzVz2SrjZpixRwACWE8"]
[Mon Jul 20 06:05:04.647272 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/fpr4.php"] [unique_id "al4O8LLfyzVz2SrjZpiykgAAAmk"]
[Mon Jul 20 06:05:04.647365 2026] [security2:error] [pid 796567:tid 796782] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/fpr4.php"] [unique_id "al4O8LLfyzVz2SrjZpiykgAAAmk"]
[Mon Jul 20 06:05:04.971149 2026] [security2:error] [pid 796928:tid 797176] [client 185.132.186.99:35971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/aa.php"] [unique_id "al4O8OsTy9vX-htKvPkbaQAAAw8"]
[Mon Jul 20 06:05:05.100723 2026] [security2:error] [pid 796928:tid 797051] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkbbwADF3o"]
[Mon Jul 20 06:05:05.100875 2026] [security2:error] [pid 796928:tid 797184] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkbbwADF3o"]
[Mon Jul 20 06:05:05.268293 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O8bLfyzVz2SrjZpiyqgAAAjY"]
[Mon Jul 20 06:05:05.268390 2026] [security2:error] [pid 796567:tid 796731] [client 178.152.178.232:37222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O8bLfyzVz2SrjZpiyqgAAAjY"]
[Mon Jul 20 06:05:05.278465 2026] [security2:error] [pid 796928:tid 797061] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/file88.php"] [unique_id "al4O8esTy9vX-htKvPkbeQAAApw"]
[Mon Jul 20 06:05:05.278552 2026] [security2:error] [pid 796928:tid 797061] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/file88.php"] [unique_id "al4O8esTy9vX-htKvPkbeQAAApw"]
[Mon Jul 20 06:05:05.279300 2026] [security2:error] [pid 796928:tid 797073] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8OsTy9vX-htKvPkbagAAAqg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:05.617446 2026] [access_compat:error] [pid 796928:tid 797163] [client 112.111.232.9:8327] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:05:05.654979 2026] [security2:error] [pid 796928:tid 797161] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ccc.php"] [unique_id "al4O8esTy9vX-htKvPkbggAAAwA"]
[Mon Jul 20 06:05:05.655126 2026] [security2:error] [pid 796928:tid 797161] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ccc.php"] [unique_id "al4O8esTy9vX-htKvPkbggAAAwA"]
[Mon Jul 20 06:05:05.822464 2026] [security2:error] [pid 796928:tid 797171] [client 14.182.195.220:51992] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O8esTy9vX-htKvPkbkwAAAwo"]
[Mon Jul 20 06:05:05.833709 2026] [security2:error] [pid 796928:tid 797173] [client 14.182.195.220:51993] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O8esTy9vX-htKvPkblgAAAww"]
[Mon Jul 20 06:05:05.990365 2026] [security2:error] [pid 796928:tid 797149] [client 181.224.94.124:43101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkboAAAAvQ"]
[Mon Jul 20 06:05:05.990637 2026] [security2:error] [pid 796928:tid 797149] [client 181.224.94.124:43101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O8esTy9vX-htKvPkboAAAAvQ"]
[Mon Jul 20 06:05:06.015131 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/777.php"] [unique_id "al4O8usTy9vX-htKvPkbogAAAr4"]
[Mon Jul 20 06:05:06.015238 2026] [security2:error] [pid 796928:tid 797095] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/777.php"] [unique_id "al4O8usTy9vX-htKvPkbogAAAr4"]
[Mon Jul 20 06:05:06.084549 2026] [security2:error] [pid 796567:tid 796749] [client 14.182.195.220:51994] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4O8rLfyzVz2SrjZpiyxQAAAkg"]
[Mon Jul 20 06:05:06.135508 2026] [security2:error] [pid 796928:tid 797058] [client 14.225.17.146:55577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4O8OsTy9vX-htKvPkbWgAAApk"]
[Mon Jul 20 06:05:06.156707 2026] [security2:error] [pid 796928:tid 797157] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8esTy9vX-htKvPkblAAAAvw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:05:06.211201 2026] [security2:error] [pid 796928:tid 797185] [client 158.173.241.141:56503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4O8esTy9vX-htKvPkbngAAAxg"], referer: http://sesamegreenbeans.com/planning-for-rugby-world-cup-france-2023/
[Mon Jul 20 06:05:06.377010 2026] [security2:error] [pid 796567:tid 796700] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/for.php"] [unique_id "al4O8rLfyzVz2SrjZpiy2wAAAhc"]
[Mon Jul 20 06:05:06.377144 2026] [security2:error] [pid 796567:tid 796700] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/for.php"] [unique_id "al4O8rLfyzVz2SrjZpiy2wAAAhc"]
[Mon Jul 20 06:05:06.467611 2026] [security2:error] [pid 796567:tid 796753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8rLfyzVz2SrjZpiy0wAAAkw"]
[Mon Jul 20 06:05:06.734356 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/ssla.php"] [unique_id "al4O8usTy9vX-htKvPkbyQAAAt0"]
[Mon Jul 20 06:05:06.734466 2026] [security2:error] [pid 796928:tid 797126] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/ssla.php"] [unique_id "al4O8usTy9vX-htKvPkbyQAAAt0"]
[Mon Jul 20 06:05:06.892325 2026] [security2:error] [pid 796928:tid 797090] [client 50.116.65.227:18208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4O8usTy9vX-htKvPkbzAAAArk"]
[Mon Jul 20 06:05:06.904351 2026] [security2:error] [pid 796928:tid 797116] [client 50.116.65.227:58160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4O8usTy9vX-htKvPkbzQAAAtM"]
[Mon Jul 20 06:05:06.934926 2026] [security2:error] [pid 796928:tid 797089] [client 185.132.186.94:40601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/index2.php"] [unique_id "al4O8usTy9vX-htKvPkbzgAAArg"]
[Mon Jul 20 06:05:07.098036 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/zc-131.php"] [unique_id "al4O8-sTy9vX-htKvPkb1gAAAqQ"]
[Mon Jul 20 06:05:07.098168 2026] [security2:error] [pid 796928:tid 797069] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ashleystrain.com"] [uri "/zc-131.php"] [unique_id "al4O8-sTy9vX-htKvPkb1gAAAqQ"]
[Mon Jul 20 06:05:07.220320 2026] [security2:error] [pid 796928:tid 797172] [client 103.149.16.77:49809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkb2wAAAws"]
[Mon Jul 20 06:05:07.220414 2026] [security2:error] [pid 796928:tid 797172] [client 103.149.16.77:49809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkb2wAAAws"]
[Mon Jul 20 06:05:07.322025 2026] [security2:error] [pid 796567:tid 796744] [client 210.212.97.243:10441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O87LfyzVz2SrjZpiy_QAAAkM"]
[Mon Jul 20 06:05:07.322179 2026] [security2:error] [pid 796567:tid 796744] [client 210.212.97.243:10441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O87LfyzVz2SrjZpiy_QAAAkM"]
[Mon Jul 20 06:05:07.328693 2026] [security2:error] [pid 796567:tid 796697] [client 57.141.18.13:40138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O7bLfyzVz2SrjZpix9wACFCs"]
[Mon Jul 20 06:05:07.644849 2026] [security2:error] [pid 796928:tid 797059] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O8-sTy9vX-htKvPkb7gAAApo"]
[Mon Jul 20 06:05:07.767685 2026] [security2:error] [pid 796928:tid 797146] [client 72.255.10.154:26387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcBgAAAvE"]
[Mon Jul 20 06:05:07.767824 2026] [security2:error] [pid 796928:tid 797146] [client 72.255.10.154:26387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcBgAAAvE"]
[Mon Jul 20 06:05:07.823893 2026] [security2:error] [pid 796928:tid 797165] [client 103.95.123.246:19265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcCgAAAwQ"]
[Mon Jul 20 06:05:07.824558 2026] [security2:error] [pid 796928:tid 797165] [client 103.95.123.246:19265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O8-sTy9vX-htKvPkcCgAAAwQ"]
[Mon Jul 20 06:05:07.869917 2026] [security2:error] [pid 796928:tid 797123] [client 57.141.18.60:35396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O7esTy9vX-htKvPkaywAC2iE"]
[Mon Jul 20 06:05:08.011957 2026] [security2:error] [pid 796567:tid 796816] [client 120.59.197.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4O87LfyzVz2SrjZpizEwAAAos"]
[Mon Jul 20 06:05:08.176432 2026] [security2:error] [pid 796567:tid 796750] [client 87.167.134.220:60462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4O87LfyzVz2SrjZpizAgAAAkk"]
[Mon Jul 20 06:05:08.765287 2026] [security2:error] [pid 796567:tid 796593] [remote 81.173.115.7:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O9LLfyzVz2SrjZpizOAACGRk"]
[Mon Jul 20 06:05:08.898580 2026] [security2:error] [pid 796567:tid 796762] [client 185.132.186.88:49963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/hello-element/footer.php"] [unique_id "al4O9LLfyzVz2SrjZpizPgAAAlU"]
[Mon Jul 20 06:05:08.988487 2026] [security2:error] [pid 796567:tid 796662] [remote 81.173.115.7:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4O9LLfyzVz2SrjZpizQQACFF4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:09.892539 2026] [security2:error] [pid 796928:tid 797183] [client 13.201.64.214:25594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O9esTy9vX-htKvPkcUQAAAxY"]
[Mon Jul 20 06:05:09.892671 2026] [security2:error] [pid 796928:tid 797183] [client 13.201.64.214:25594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4O9esTy9vX-htKvPkcUQAAAxY"]
[Mon Jul 20 06:05:09.983634 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:60407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O9bLfyzVz2SrjZpizcQAAAi8"]
[Mon Jul 20 06:05:09.983802 2026] [security2:error] [pid 796567:tid 796724] [client 106.192.104.4:60407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4O9bLfyzVz2SrjZpizcQAAAi8"]
[Mon Jul 20 06:05:10.012266 2026] [security2:error] [pid 796567:tid 796719] [client 57.141.18.8:62844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O8LLfyzVz2SrjZpiygAACKlw"]
[Mon Jul 20 06:05:10.117650 2026] [security2:error] [pid 796928:tid 797117] [client 47.31.86.100:61615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.86.31.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcVQAAAtQ"]
[Mon Jul 20 06:05:10.117799 2026] [security2:error] [pid 796928:tid 797117] [client 47.31.86.100:61615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcVQAAAtQ"]
[Mon Jul 20 06:05:10.714733 2026] [security2:error] [pid 796567:tid 796658] [remote 68.178.160.25:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O9rLfyzVz2SrjZpizkAACdVo"]
[Mon Jul 20 06:05:10.846374 2026] [security2:error] [pid 796567:tid 796782] [client 185.132.186.90:57081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/admin.php"] [unique_id "al4O9rLfyzVz2SrjZpizmgAAAmk"]
[Mon Jul 20 06:05:10.866880 2026] [security2:error] [pid 796567:tid 796680] [remote 23.79.233.44:43864] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "drawingthedog.com"] [uri "/"] [unique_id "al4O9rLfyzVz2SrjZpizmwACa3A"]
[Mon Jul 20 06:05:10.891667 2026] [security2:error] [pid 796928:tid 796971] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcbgAC-So"]
[Mon Jul 20 06:05:10.892033 2026] [security2:error] [pid 796928:tid 797154] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O9usTy9vX-htKvPkcbgAC-So"]
[Mon Jul 20 06:05:10.896549 2026] [security2:error] [pid 796928:tid 797169] [client 57.141.18.108:53812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O8esTy9vX-htKvPkbdAADCG4"]
[Mon Jul 20 06:05:11.071956 2026] [security2:error] [pid 796567:tid 796809] [client 193.19.109.223:27709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizowAAAoQ"]
[Mon Jul 20 06:05:11.080435 2026] [security2:error] [pid 796567:tid 796712] [client 193.19.109.241:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizogAAAiM"]
[Mon Jul 20 06:05:11.087188 2026] [security2:error] [pid 796928:tid 797150] [client 77.110.127.138:55324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/install.php"] [unique_id "al4O9-sTy9vX-htKvPkcewAAAvU"]
[Mon Jul 20 06:05:11.119246 2026] [security2:error] [pid 796567:tid 796642] [remote 68.178.160.25:48814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizpwACgko"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:11.142981 2026] [security2:error] [pid 796928:tid 797088] [client 77.110.127.138:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/upgrade.php"] [unique_id "al4O9-sTy9vX-htKvPkcfAAAArc"]
[Mon Jul 20 06:05:11.280914 2026] [security2:error] [pid 796567:tid 796766] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O97LfyzVz2SrjZpizpAAAAlk"]
[Mon Jul 20 06:05:11.336002 2026] [security2:error] [pid 796567:tid 796710] [client 3.109.4.218:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizrwAAAiE"]
[Mon Jul 20 06:05:11.442727 2026] [security2:error] [pid 796928:tid 797179] [client 150.228.148.150:5334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchQAAAxI"]
[Mon Jul 20 06:05:11.442857 2026] [security2:error] [pid 796928:tid 797179] [client 150.228.148.150:5334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchQAAAxI"]
[Mon Jul 20 06:05:11.453202 2026] [security2:error] [pid 796928:tid 797138] [client 112.213.160.112:30824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchwAAAuk"]
[Mon Jul 20 06:05:11.453323 2026] [security2:error] [pid 796928:tid 797138] [client 112.213.160.112:30824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4O9-sTy9vX-htKvPkchwAAAuk"]
[Mon Jul 20 06:05:11.559938 2026] [security2:error] [pid 796567:tid 796786] [client 50.116.65.227:48608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4O97LfyzVz2SrjZpizuAAAAm0"]
[Mon Jul 20 06:05:11.570153 2026] [security2:error] [pid 796567:tid 796776] [client 50.116.65.227:48620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4O97LfyzVz2SrjZpizuQAAAmM"]
[Mon Jul 20 06:05:11.731279 2026] [security2:error] [pid 796928:tid 797182] [client 43.173.182.226:35622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4O9-sTy9vX-htKvPkckgAAAxU"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:11.765501 2026] [security2:error] [pid 796567:tid 796692] [remote 192.241.143.148:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpizxgACjXw"]
[Mon Jul 20 06:05:11.872109 2026] [security2:error] [pid 796567:tid 796622] [remote 95.217.78.234:35870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpiz0QACTTY"]
[Mon Jul 20 06:05:11.948645 2026] [security2:error] [pid 796567:tid 796630] [remote 192.241.143.148:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4O97LfyzVz2SrjZpiz0wACID4"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 06:05:12.025079 2026] [security2:error] [pid 796567:tid 796816] [client 43.172.197.28:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4O-LLfyzVz2SrjZpiz2QAAAos"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:12.118900 2026] [security2:error] [pid 796567:tid 796626] [remote 95.217.78.234:35870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O-LLfyzVz2SrjZpiz3AACIzo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:12.138180 2026] [security2:error] [pid 796567:tid 796697] [client 43.172.195.7:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4O-LLfyzVz2SrjZpiz3QAAAhQ"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:12.215932 2026] [security2:error] [pid 796567:tid 796637] [remote 167.233.114.32:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4O-LLfyzVz2SrjZpiz4wACP0U"]
[Mon Jul 20 06:05:12.242822 2026] [security2:error] [pid 796928:tid 797081] [client 43.173.176.41:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4O-OsTy9vX-htKvPkcpAAAArA"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:05:12.425243 2026] [security2:error] [pid 796567:tid 796603] [remote 167.233.114.32:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4O-LLfyzVz2SrjZpiz8AACOSM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:05:12.547343 2026] [security2:error] [pid 796567:tid 796704] [client 14.225.17.146:59755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4O9rLfyzVz2SrjZpizkgAAAhs"], referer: http://areitoproducciones.com/wordpress
[Mon Jul 20 06:05:12.598625 2026] [security2:error] [pid 796928:tid 797111] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O-OsTy9vX-htKvPkcqAAAAs4"]
[Mon Jul 20 06:05:12.784185 2026] [security2:error] [pid 796928:tid 797109] [client 185.132.186.55:39807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/2index.php"] [unique_id "al4O-OsTy9vX-htKvPkcygAAAsw"]
[Mon Jul 20 06:05:13.011587 2026] [security2:error] [pid 796928:tid 797136] [client 57.141.18.114:20114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O8-sTy9vX-htKvPkb4wAC51M"]
[Mon Jul 20 06:05:13.245888 2026] [security2:error] [pid 796567:tid 796820] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4O-bLfyzVz2SrjZpi0CgAAAo8"], referer: https://duckduckgo.com/?q=pirql
[Mon Jul 20 06:05:13.356164 2026] [security2:error] [pid 796567:tid 796601] [remote 97.74.93.24:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O-bLfyzVz2SrjZpi0FAACYiE"]
[Mon Jul 20 06:05:13.449309 2026] [security2:error] [pid 796567:tid 796782] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/passwd"] [unique_id "al4O-bLfyzVz2SrjZpi0HgAAAmk"], referer: https://www.google.com/search?q=gbsmx5
[Mon Jul 20 06:05:13.626869 2026] [security2:error] [pid 796928:tid 797125] [client 193.19.109.241:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4O-esTy9vX-htKvPkc5gAAAtw"]
[Mon Jul 20 06:05:13.628735 2026] [security2:error] [pid 796567:tid 796823] [client 193.37.33.1:50185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4O-bLfyzVz2SrjZpi0IQAAApI"]
[Mon Jul 20 06:05:13.658496 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:8283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O-bLfyzVz2SrjZpi0JQAAAkk"]
[Mon Jul 20 06:05:13.658634 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:8283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4O-bLfyzVz2SrjZpi0JQAAAkk"]
[Mon Jul 20 06:05:13.667598 2026] [security2:error] [pid 796928:tid 797131] [client 193.19.109.216:58657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4O-esTy9vX-htKvPkc5QAAAuI"]
[Mon Jul 20 06:05:13.669276 2026] [security2:error] [pid 796567:tid 796807] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/shadow"] [unique_id "al4O-bLfyzVz2SrjZpi0JgAAAoI"], referer: https://www.bing.com/search?q=qpc72d
[Mon Jul 20 06:05:13.763732 2026] [security2:error] [pid 796567:tid 796582] [remote 97.74.93.24:52396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4O-bLfyzVz2SrjZpi0KAACfQ4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:13.898888 2026] [security2:error] [pid 796567:tid 796742] [client 51.15.143.46:40722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4O-bLfyzVz2SrjZpi0MAAAAkE"]
[Mon Jul 20 06:05:13.911436 2026] [security2:error] [pid 796928:tid 797151] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4O-esTy9vX-htKvPkc6AAC9g4"]
[Mon Jul 20 06:05:14.031334 2026] [security2:error] [pid 796567:tid 796730] [client 57.141.18.35:32588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9LLfyzVz2SrjZpizJQACNUc"]
[Mon Jul 20 06:05:14.274507 2026] [security2:error] [pid 796567:tid 796704] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O-rLfyzVz2SrjZpi0OgAAAhs"]
[Mon Jul 20 06:05:14.436905 2026] [security2:error] [pid 796567:tid 796717] [client 104.234.53.68:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4O-rLfyzVz2SrjZpi0SgAAAig"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:14.500071 2026] [security2:error] [pid 796928:tid 797071] [client 43.205.139.3:29468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O-OsTy9vX-htKvPkcwQAAAqY"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:05:14.505320 2026] [security2:error] [pid 796567:tid 796736] [client 13.201.64.214:25610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O-rLfyzVz2SrjZpi0TQAAAjs"]
[Mon Jul 20 06:05:14.631860 2026] [security2:error] [pid 796928:tid 797152] [client 193.19.109.249:55889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "abilite.uk"] [uri "/wp-login.php"] [unique_id "al4O-usTy9vX-htKvPkdCwAAAvc"]
[Mon Jul 20 06:05:14.711199 2026] [security2:error] [pid 796567:tid 796796] [client 14.225.17.146:57158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4O-LLfyzVz2SrjZpiz7wAAAnc"], referer: http://qualitycoatingsinspection.com/wordpress
[Mon Jul 20 06:05:14.728324 2026] [security2:error] [pid 796928:tid 797125] [client 185.132.186.59:37623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/plugins.php"] [unique_id "al4O-usTy9vX-htKvPkdEgAAAtw"]
[Mon Jul 20 06:05:14.874245 2026] [security2:error] [pid 796928:tid 797110] [client 178.152.178.232:36903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O-usTy9vX-htKvPkdHAAAAs0"]
[Mon Jul 20 06:05:14.881162 2026] [security2:error] [pid 796928:tid 797110] [client 178.152.178.232:36903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4O-usTy9vX-htKvPkdHAAAAs0"]
[Mon Jul 20 06:05:15.051736 2026] [security2:error] [pid 796928:tid 797063] [client 210.212.97.243:10442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdIQAAAp4"]
[Mon Jul 20 06:05:15.051895 2026] [security2:error] [pid 796928:tid 797063] [client 210.212.97.243:10442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdIQAAAp4"]
[Mon Jul 20 06:05:15.087030 2026] [security2:error] [pid 796928:tid 797131] [client 41.173.37.102:14005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdJAAAAuI"]
[Mon Jul 20 06:05:15.087125 2026] [security2:error] [pid 796928:tid 797131] [client 41.173.37.102:14005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdJAAAAuI"]
[Mon Jul 20 06:05:15.110901 2026] [security2:error] [pid 796928:tid 797173] [client 43.172.197.201:50088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4O--sTy9vX-htKvPkdJQAAAww"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:05:15.166282 2026] [autoindex:error] [pid 796567:tid 796738] [client 147.93.171.188:54546] AH01276: Cannot serve directory /home1/effingwe/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:05:15.256666 2026] [security2:error] [pid 796928:tid 797179] [client 43.173.182.128:36536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4O--sTy9vX-htKvPkdMQAAAxI"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:05:15.271355 2026] [security2:error] [pid 796928:tid 797143] [client 43.172.195.34:35080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4O--sTy9vX-htKvPkdNQAAAu4"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:05:15.287995 2026] [security2:error] [pid 796928:tid 797083] [client 57.141.18.121:62172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9esTy9vX-htKvPkcSQACsgI"]
[Mon Jul 20 06:05:15.367601 2026] [security2:error] [pid 796567:tid 796785] [client 57.141.18.83:59278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9bLfyzVz2SrjZpizZwACbGs"]
[Mon Jul 20 06:05:15.566651 2026] [security2:error] [pid 796928:tid 797059] [client 3.109.4.218:53938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4O--sTy9vX-htKvPkdPgAAApo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:05:15.644682 2026] [security2:error] [pid 796928:tid 797067] [client 13.38.91.115:21424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.91.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdSAAAAqI"]
[Mon Jul 20 06:05:15.644794 2026] [security2:error] [pid 796928:tid 797067] [client 13.38.91.115:21424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdSAAAAqI"]
[Mon Jul 20 06:05:15.788757 2026] [security2:error] [pid 796928:tid 796937] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdTAAC0gg"]
[Mon Jul 20 06:05:15.788872 2026] [security2:error] [pid 796928:tid 797115] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4O--sTy9vX-htKvPkdTAAC0gg"]
[Mon Jul 20 06:05:15.793643 2026] [security2:error] [pid 796567:tid 796702] [client 14.225.17.146:51573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4O-7LfyzVz2SrjZpi0eQAAAhk"], referer: https://qualitycoatingsinspection.com/wordpress
[Mon Jul 20 06:05:16.378678 2026] [security2:error] [pid 796928:tid 797058] [client 98.159.234.160:58493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4O_OsTy9vX-htKvPkdXwAAApk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:16.511952 2026] [security2:error] [pid 796928:tid 797133] [client 181.224.94.124:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O_OsTy9vX-htKvPkdYwAAAuQ"]
[Mon Jul 20 06:05:16.512091 2026] [security2:error] [pid 796928:tid 797133] [client 181.224.94.124:35628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4O_OsTy9vX-htKvPkdYwAAAuQ"]
[Mon Jul 20 06:05:16.848091 2026] [security2:error] [pid 796567:tid 796737] [client 103.153.183.69:35030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/hosts"] [unique_id "al4O_LLfyzVz2SrjZpi0rAAAAjw"], referer: https://www.facebook.com/
[Mon Jul 20 06:05:17.113616 2026] [security2:error] [pid 796928:tid 797126] [client 57.141.18.124:38764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O9-sTy9vX-htKvPkcjgAC3Sg"]
[Mon Jul 20 06:05:17.214073 2026] [security2:error] [pid 796928:tid 797077] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.origine.nz"] [uri "/index.php"] [unique_id "al4O_OsTy9vX-htKvPkdcgACrG0"]
[Mon Jul 20 06:05:17.663770 2026] [security2:error] [pid 796928:tid 797014] [remote 45.90.123.233:40372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4O_esTy9vX-htKvPkdiQACr1U"]
[Mon Jul 20 06:05:17.899483 2026] [security2:error] [pid 796928:tid 797155] [client 103.149.16.77:50356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.16.149.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O_esTy9vX-htKvPkdmgAAAvo"]
[Mon Jul 20 06:05:17.899610 2026] [security2:error] [pid 796928:tid 797155] [client 103.149.16.77:50356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4O_esTy9vX-htKvPkdmgAAAvo"]
[Mon Jul 20 06:05:17.901484 2026] [security2:error] [pid 796928:tid 796982] [remote 45.90.123.233:40372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4O_esTy9vX-htKvPkdnAACwTU"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 06:05:18.096736 2026] [security2:error] [pid 796567:tid 796733] [client 103.153.183.69:35030] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//proc/self/environ"] [unique_id "al4O_rLfyzVz2SrjZpi06QAAAjg"], referer: https://www.google.com/
[Mon Jul 20 06:05:18.241730 2026] [security2:error] [pid 796928:tid 797082] [client 185.132.186.77:51385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/shell.php"] [unique_id "al4O_usTy9vX-htKvPkdrQAAArE"]
[Mon Jul 20 06:05:18.328873 2026] [security2:error] [pid 796928:tid 797064] [client 72.255.10.154:26390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O_usTy9vX-htKvPkdrwAAAp8"]
[Mon Jul 20 06:05:18.328997 2026] [security2:error] [pid 796928:tid 797064] [client 72.255.10.154:26390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4O_usTy9vX-htKvPkdrwAAAp8"]
[Mon Jul 20 06:05:18.769179 2026] [security2:error] [pid 796567:tid 796809] [client 57.141.18.6:38244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O-bLfyzVz2SrjZpi0GwAChFQ"]
[Mon Jul 20 06:05:18.955626 2026] [security2:error] [pid 796928:tid 797071] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4O_usTy9vX-htKvPkdtQAAAqY"]
[Mon Jul 20 06:05:19.318532 2026] [security2:error] [pid 796567:tid 796817] [client 103.95.123.246:19768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O_7LfyzVz2SrjZpi1JAAAAow"]
[Mon Jul 20 06:05:19.318624 2026] [security2:error] [pid 796567:tid 796817] [client 103.95.123.246:19768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4O_7LfyzVz2SrjZpi1JAAAAow"]
[Mon Jul 20 06:05:19.422557 2026] [proxy:error] [pid 796567:tid 796745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.422653 2026] [proxy_http:error] [pid 796567:tid 796745] [client 82.102.18.116:39628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.423780 2026] [proxy:error] [pid 796567:tid 796745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.423856 2026] [proxy_http:error] [pid 796567:tid 796745] [client 82.102.18.116:39628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.497524 2026] [security2:error] [pid 796928:tid 797054] [remote 157.66.26.183:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O_-sTy9vX-htKvPkd1gAC2n0"]
[Mon Jul 20 06:05:19.670276 2026] [security2:error] [pid 796567:tid 796636] [remote 57.141.18.42:36916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2909670"] [unique_id "al4O_7LfyzVz2SrjZpi1MAACP0Q"]
[Mon Jul 20 06:05:19.750395 2026] [proxy:error] [pid 796928:tid 797093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.750463 2026] [proxy_http:error] [pid 796928:tid 797093] [client 82.102.18.116:39654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.751246 2026] [proxy:error] [pid 796928:tid 797093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:19.751280 2026] [proxy_http:error] [pid 796928:tid 797093] [client 82.102.18.116:39654] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:19.957832 2026] [security2:error] [pid 796928:tid 797003] [remote 157.66.26.183:46462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4O_-sTy9vX-htKvPkd_gAC3Uo"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:05:20.040735 2026] [security2:error] [pid 796928:tid 797115] [client 20.1.181.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rentorangegrove.com"] [uri "/index.php"] [unique_id "al4O_-sTy9vX-htKvPkd_QAAAtI"]
[Mon Jul 20 06:05:20.054249 2026] [security2:error] [pid 796567:tid 796810] [client 57.141.18.92:64550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O-rLfyzVz2SrjZpi0WgAChVg"]
[Mon Jul 20 06:05:20.099823 2026] [security2:error] [pid 796567:tid 796812] [client 82.102.18.116:39668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4PALLfyzVz2SrjZpi1QgAAAoc"]
[Mon Jul 20 06:05:20.138560 2026] [security2:error] [pid 796567:tid 796744] [client 104.234.53.84:38633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PALLfyzVz2SrjZpi1QQAAAkM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:20.191391 2026] [security2:error] [pid 796928:tid 797141] [client 185.132.186.99:35587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/content.php"] [unique_id "al4PAOsTy9vX-htKvPkeBwAAAuw"]
[Mon Jul 20 06:05:20.194991 2026] [security2:error] [pid 796567:tid 796727] [client 86.98.90.58:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1RgAAAjI"]
[Mon Jul 20 06:05:20.195132 2026] [security2:error] [pid 796567:tid 796727] [client 86.98.90.58:56261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1RgAAAjI"]
[Mon Jul 20 06:05:20.430409 2026] [security2:error] [pid 796928:tid 797096] [client 82.102.18.116:39670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeFAAAAr8"]
[Mon Jul 20 06:05:20.620779 2026] [security2:error] [pid 796567:tid 796796] [client 74.208.214.194:42838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PALLfyzVz2SrjZpi1VAAAAnc"]
[Mon Jul 20 06:05:20.798444 2026] [security2:error] [pid 796928:tid 797136] [client 103.141.108.143:58027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeHgAAAuc"]
[Mon Jul 20 06:05:20.800529 2026] [proxy:error] [pid 796567:tid 796777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:20.800591 2026] [proxy_http:error] [pid 796567:tid 796777] [client 82.102.18.116:39686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:20.801230 2026] [proxy:error] [pid 796567:tid 796777] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:05:20.801257 2026] [proxy_http:error] [pid 796567:tid 796777] [client 82.102.18.116:39686] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:05:20.821332 2026] [security2:error] [pid 796928:tid 797069] [client 193.19.109.249:33975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PAOsTy9vX-htKvPkeIwAAAqQ"]
[Mon Jul 20 06:05:20.850314 2026] [security2:error] [pid 796928:tid 797173] [client 65.1.132.125:28686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeJwAAAww"]
[Mon Jul 20 06:05:20.850407 2026] [security2:error] [pid 796928:tid 797173] [client 65.1.132.125:28686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeJwAAAww"]
[Mon Jul 20 06:05:20.902894 2026] [security2:error] [pid 796567:tid 796784] [client 106.192.104.4:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1YwAAAms"]
[Mon Jul 20 06:05:20.903018 2026] [security2:error] [pid 796567:tid 796784] [client 106.192.104.4:60900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PALLfyzVz2SrjZpi1YwAAAms"]
[Mon Jul 20 06:05:20.907103 2026] [security2:error] [pid 796928:tid 797071] [client 193.19.109.247:48133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PAOsTy9vX-htKvPkeKQAAAqY"]
[Mon Jul 20 06:05:21.059384 2026] [security2:error] [pid 796567:tid 796759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PALLfyzVz2SrjZpi1XQAAAlI"]
[Mon Jul 20 06:05:21.124711 2026] [security2:error] [pid 796567:tid 796779] [client 57.141.18.19:28498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O-7LfyzVz2SrjZpi0fgACZlo"]
[Mon Jul 20 06:05:21.140952 2026] [security2:error] [pid 796928:tid 797089] [client 82.102.18.116:39698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4PAesTy9vX-htKvPkeOgAAArg"]
[Mon Jul 20 06:05:21.260465 2026] [security2:error] [pid 796928:tid 797076] [client 193.19.109.218:59865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeQgAAAqs"]
[Mon Jul 20 06:05:21.282258 2026] [security2:error] [pid 796928:tid 797141] [client 193.19.109.214:53899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeQQAAAuw"]
[Mon Jul 20 06:05:21.290665 2026] [security2:error] [pid 796928:tid 797140] [client 104.234.53.61:23613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PAesTy9vX-htKvPkePQAAAus"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:21.310813 2026] [security2:error] [pid 796928:tid 797111] [client 193.19.109.228:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeQwAAAs4"]
[Mon Jul 20 06:05:21.453699 2026] [security2:error] [pid 796567:tid 796712] [client 82.102.18.116:39710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4PAbLfyzVz2SrjZpi1fQAAAiM"]
[Mon Jul 20 06:05:21.484693 2026] [security2:error] [pid 796928:tid 797136] [client 103.141.108.143:58027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PAOsTy9vX-htKvPkeHgAAAuc"]
[Mon Jul 20 06:05:21.560774 2026] [security2:error] [pid 796928:tid 797169] [client 104.234.53.61:23613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PAesTy9vX-htKvPkeTwAAAwg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:21.621192 2026] [security2:error] [pid 796928:tid 797158] [client 150.228.148.150:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeVQAAAv0"]
[Mon Jul 20 06:05:21.639674 2026] [security2:error] [pid 796928:tid 797158] [client 150.228.148.150:57087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeVQAAAv0"]
[Mon Jul 20 06:05:21.775208 2026] [security2:error] [pid 796928:tid 797095] [client 82.102.18.116:39714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4PAesTy9vX-htKvPkeWAAAAr4"]
[Mon Jul 20 06:05:21.923569 2026] [security2:error] [pid 796928:tid 796999] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeYwACnEY"]
[Mon Jul 20 06:05:21.923803 2026] [security2:error] [pid 796928:tid 797061] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PAesTy9vX-htKvPkeYwACnEY"]
[Mon Jul 20 06:05:22.119997 2026] [security2:error] [pid 796928:tid 797128] [client 185.132.186.64:37815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/about.php"] [unique_id "al4PAusTy9vX-htKvPkebgAAAt8"]
[Mon Jul 20 06:05:22.134433 2026] [security2:error] [pid 796928:tid 797123] [client 82.102.18.116:39724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4PAusTy9vX-htKvPkebwAAAto"]
[Mon Jul 20 06:05:22.174798 2026] [security2:error] [pid 796928:tid 797113] [client 112.213.160.112:8383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PAusTy9vX-htKvPkedgAAAtA"]
[Mon Jul 20 06:05:22.174904 2026] [security2:error] [pid 796928:tid 797113] [client 112.213.160.112:8383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PAusTy9vX-htKvPkedgAAAtA"]
[Mon Jul 20 06:05:22.452189 2026] [security2:error] [pid 796567:tid 796796] [client 82.102.18.116:39740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4PArLfyzVz2SrjZpi1owAAAnc"]
[Mon Jul 20 06:05:22.779027 2026] [security2:error] [pid 796567:tid 796739] [client 82.102.18.116:39754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4PArLfyzVz2SrjZpi1rAAAAj4"]
[Mon Jul 20 06:05:22.831512 2026] [security2:error] [pid 796928:tid 797170] [client 57.141.18.64:62090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O_esTy9vX-htKvPkdiwADCUQ"]
[Mon Jul 20 06:05:22.850700 2026] [security2:error] [pid 796928:tid 797090] [client 104.234.53.69:52705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PAusTy9vX-htKvPkelAAAArk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:23.090436 2026] [security2:error] [pid 796567:tid 796763] [client 82.102.18.116:39768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4PA7LfyzVz2SrjZpi1uAAAAlY"]
[Mon Jul 20 06:05:23.410069 2026] [security2:error] [pid 796928:tid 797139] [client 82.102.18.116:39784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4PA-sTy9vX-htKvPkerAAAAuo"]
[Mon Jul 20 06:05:23.466614 2026] [security2:error] [pid 796567:tid 796747] [client 57.141.18.86:56178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O_rLfyzVz2SrjZpi09AACRhI"]
[Mon Jul 20 06:05:23.473542 2026] [security2:error] [pid 796567:tid 796788] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PA7LfyzVz2SrjZpi1vwAAAm8"]
[Mon Jul 20 06:05:23.489731 2026] [security2:error] [pid 796928:tid 797050] [remote 57.141.18.102:56516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4PA-sTy9vX-htKvPkesgACzXk"]
[Mon Jul 20 06:05:23.515937 2026] [security2:error] [pid 796567:tid 796823] [client 57.141.18.24:32868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4O_rLfyzVz2SrjZpi0-AACkhs"]
[Mon Jul 20 06:05:23.729233 2026] [security2:error] [pid 796928:tid 797175] [client 82.102.18.116:20207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4PA-sTy9vX-htKvPkevAAAAw4"]
[Mon Jul 20 06:05:24.049532 2026] [security2:error] [pid 796928:tid 797138] [client 104.234.53.80:61041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PA-sTy9vX-htKvPkexwAAAuk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:24.064020 2026] [security2:error] [pid 796928:tid 797167] [client 82.102.18.116:39802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4PBOsTy9vX-htKvPke0AAAAwY"]
[Mon Jul 20 06:05:24.067201 2026] [security2:error] [pid 796567:tid 796809] [client 185.132.186.67:65107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/atomlib.php"] [unique_id "al4PBLLfyzVz2SrjZpi14AAAAoQ"]
[Mon Jul 20 06:05:24.134458 2026] [security2:error] [pid 796928:tid 797074] [client 193.37.33.1:29757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4PBOsTy9vX-htKvPke0gAAAqk"]
[Mon Jul 20 06:05:24.205464 2026] [security2:error] [pid 796928:tid 797158] [client 115.246.21.170:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PBOsTy9vX-htKvPke0wAAAv0"]
[Mon Jul 20 06:05:24.205611 2026] [security2:error] [pid 796928:tid 797158] [client 115.246.21.170:9660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PBOsTy9vX-htKvPke0wAAAv0"]
[Mon Jul 20 06:05:24.328084 2026] [security2:error] [pid 796928:tid 797092] [client 104.234.53.80:61041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PBOsTy9vX-htKvPke2wAAArs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:24.377514 2026] [security2:error] [pid 796567:tid 796596] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PBLLfyzVz2SrjZpi16wACahw"]
[Mon Jul 20 06:05:24.377648 2026] [security2:error] [pid 796567:tid 796783] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PBLLfyzVz2SrjZpi16wACahw"]
[Mon Jul 20 06:05:24.410411 2026] [security2:error] [pid 796928:tid 797071] [client 82.102.18.116:39804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4PBOsTy9vX-htKvPke4QAAAqY"]
[Mon Jul 20 06:05:24.530791 2026] [security2:error] [pid 796928:tid 797059] [client 94.154.43.188:34130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al4PBOsTy9vX-htKvPke6AAAApo"]
[Mon Jul 20 06:05:24.539167 2026] [security2:error] [pid 796928:tid 797134] [client 94.154.43.178:53872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al4PBOsTy9vX-htKvPke6QAAAuU"]
[Mon Jul 20 06:05:24.626111 2026] [security2:error] [pid 796567:tid 796771] [client 74.249.226.166:2690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PBLLfyzVz2SrjZpi19gAAAl4"]
[Mon Jul 20 06:05:24.679073 2026] [security2:error] [pid 796567:tid 796805] [client 74.249.226.166:2690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PBLLfyzVz2SrjZpi1-AAAAoA"]
[Mon Jul 20 06:05:24.690778 2026] [security2:error] [pid 796567:tid 796793] [client 193.19.109.235:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PBLLfyzVz2SrjZpi19wAAAnQ"]
[Mon Jul 20 06:05:24.753013 2026] [security2:error] [pid 796567:tid 796739] [client 82.102.18.116:39810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4PBLLfyzVz2SrjZpi1-gAAAj4"]
[Mon Jul 20 06:05:24.865247 2026] [security2:error] [pid 796567:tid 796707] [client 94.154.43.179:21820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4PBLLfyzVz2SrjZpi2AAAAAh4"]
[Mon Jul 20 06:05:24.872004 2026] [security2:error] [pid 796928:tid 797166] [client 52.237.147.83:11397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PBOsTy9vX-htKvPke9gAAAwU"]
[Mon Jul 20 06:05:24.923072 2026] [security2:error] [pid 796928:tid 797113] [client 52.237.147.83:11397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PBOsTy9vX-htKvPke-gAAAtA"]
[Mon Jul 20 06:05:25.097922 2026] [security2:error] [pid 796567:tid 796788] [client 82.102.18.116:39814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4PBbLfyzVz2SrjZpi2DgAAAm8"]
[Mon Jul 20 06:05:25.134309 2026] [security2:error] [pid 796928:tid 797121] [client 104.234.53.85:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PBesTy9vX-htKvPkfCgAAAtg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:25.292210 2026] [security2:error] [pid 796928:tid 797139] [client 104.196.104.214:32672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "roguedragonstudio.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PBesTy9vX-htKvPkfDAAAAuo"]
[Mon Jul 20 06:05:25.418889 2026] [security2:error] [pid 796928:tid 797134] [client 104.196.104.214:32672] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "roguedragonstudio.com"] [uri "/"] [unique_id "al4PBesTy9vX-htKvPkfDQAAAuU"]
[Mon Jul 20 06:05:25.422813 2026] [security2:error] [pid 796928:tid 797069] [client 82.102.18.116:39822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4PBesTy9vX-htKvPkfDgAAAqQ"]
[Mon Jul 20 06:05:25.612032 2026] [security2:error] [pid 796567:tid 796760] [client 178.152.178.232:36286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2IgAAAlM"]
[Mon Jul 20 06:05:25.612125 2026] [security2:error] [pid 796567:tid 796760] [client 178.152.178.232:36286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2IgAAAlM"]
[Mon Jul 20 06:05:25.626745 2026] [security2:error] [pid 796928:tid 797092] [client 210.212.97.243:10443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PBesTy9vX-htKvPkfGwAAArs"]
[Mon Jul 20 06:05:25.626850 2026] [security2:error] [pid 796928:tid 797092] [client 210.212.97.243:10443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PBesTy9vX-htKvPkfGwAAArs"]
[Mon Jul 20 06:05:25.679084 2026] [security2:error] [pid 796567:tid 796813] [client 41.173.37.102:14431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2JgAAAog"]
[Mon Jul 20 06:05:25.679224 2026] [security2:error] [pid 796567:tid 796813] [client 41.173.37.102:14431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PBbLfyzVz2SrjZpi2JgAAAog"]
[Mon Jul 20 06:05:25.752603 2026] [security2:error] [pid 796928:tid 797123] [client 82.102.18.116:39846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kpb.qlr.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4PBesTy9vX-htKvPkfIQAAAto"]
[Mon Jul 20 06:05:25.843929 2026] [security2:error] [pid 796567:tid 796758] [client 57.141.18.125:63030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PALLfyzVz2SrjZpi1TQACUVw"]
[Mon Jul 20 06:05:25.862459 2026] [security2:error] [pid 796928:tid 797163] [client 186.17.234.147:35080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4PBesTy9vX-htKvPkfIAAAAwI"]
[Mon Jul 20 06:05:26.021730 2026] [security2:error] [pid 796928:tid 797072] [client 185.132.186.96:35043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/install.php"] [unique_id "al4PBusTy9vX-htKvPkfMQAAAqc"]
[Mon Jul 20 06:05:26.081728 2026] [security2:error] [pid 796567:tid 796726] [client 104.234.53.59:21587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PBrLfyzVz2SrjZpi2NAAAAjE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:26.485643 2026] [security2:error] [pid 796928:tid 797046] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PBusTy9vX-htKvPkfQwAC-nU"]
[Mon Jul 20 06:05:26.485819 2026] [security2:error] [pid 796928:tid 797155] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PBusTy9vX-htKvPkfQwAC-nU"]
[Mon Jul 20 06:05:26.623347 2026] [security2:error] [pid 796928:tid 797140] [client 103.153.183.69:44060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4PBusTy9vX-htKvPkfRwAAAus"], referer: https://www.facebook.com/
[Mon Jul 20 06:05:26.658304 2026] [security2:error] [pid 796567:tid 796772] [client 193.19.109.247:21541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "coltinnovate.com"] [uri "/wp-login.php"] [unique_id "al4PBrLfyzVz2SrjZpi2RwAAAl8"]
[Mon Jul 20 06:05:26.741039 2026] [security2:error] [pid 796567:tid 796789] [client 57.141.18.109:38408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PAbLfyzVz2SrjZpi1cwACcDM"]
[Mon Jul 20 06:05:26.768680 2026] [security2:error] [pid 796567:tid 796688] [remote 5.161.225.162:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4PBrLfyzVz2SrjZpi2SQACHng"]
[Mon Jul 20 06:05:27.025948 2026] [security2:error] [pid 796567:tid 796743] [client 181.224.94.124:10639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PB7LfyzVz2SrjZpi2VwAAAkI"]
[Mon Jul 20 06:05:27.026055 2026] [security2:error] [pid 796567:tid 796743] [client 181.224.94.124:10639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PB7LfyzVz2SrjZpi2VwAAAkI"]
[Mon Jul 20 06:05:27.037207 2026] [security2:error] [pid 796567:tid 796610] [remote 5.161.225.162:55042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4PB7LfyzVz2SrjZpi2WAACIyo"], referer: https://roguedragonstudio.com/wp-login.php
[Mon Jul 20 06:05:27.594551 2026] [security2:error] [pid 796928:tid 797179] [client 57.141.18.68:62040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PAusTy9vX-htKvPkecgADEnc"]
[Mon Jul 20 06:05:27.973921 2026] [security2:error] [pid 796928:tid 797095] [client 185.132.186.69:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/hehe.php"] [unique_id "al4PB-sTy9vX-htKvPkfbAAAAr4"]
[Mon Jul 20 06:05:28.139482 2026] [security2:error] [pid 796567:tid 796751] [client 57.141.18.35:21948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PArLfyzVz2SrjZpi1qwACSi4"]
[Mon Jul 20 06:05:28.422238 2026] [security2:error] [pid 796928:tid 796984] [remote 72.167.132.114:34884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PCOsTy9vX-htKvPkffQACojc"]
[Mon Jul 20 06:05:28.664349 2026] [security2:error] [pid 796928:tid 796932] [remote 72.167.132.114:34884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PCOsTy9vX-htKvPkfkwADDAM"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:05:28.837342 2026] [security2:error] [pid 796567:tid 796701] [client 104.234.53.59:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PCLLfyzVz2SrjZpi2oQAAAhg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:28.925656 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PCLLfyzVz2SrjZpi2lgAAAiU"]
[Mon Jul 20 06:05:29.022699 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:63525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4PCOsTy9vX-htKvPkflgAAAro"], referer: http://aljosour-alarabia.com/Wordpress
[Mon Jul 20 06:05:29.531867 2026] [security2:error] [pid 796567:tid 796583] [remote 216.73.216.55:39156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4PCbLfyzVz2SrjZpi2wwACUA8"]
[Mon Jul 20 06:05:29.703806 2026] [security2:error] [pid 796567:tid 796809] [client 72.255.10.154:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.10.255.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4PCbLfyzVz2SrjZpi2ygAAAoQ"]
[Mon Jul 20 06:05:29.703935 2026] [security2:error] [pid 796567:tid 796809] [client 72.255.10.154:52078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4PCbLfyzVz2SrjZpi2ygAAAoQ"]
[Mon Jul 20 06:05:29.882377 2026] [security2:error] [pid 796567:tid 796784] [client 57.141.18.84:34898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PBLLfyzVz2SrjZpi1_QACa0c"]
[Mon Jul 20 06:05:29.924130 2026] [security2:error] [pid 796567:tid 796773] [client 185.132.186.94:36597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/fonts/autoload_classmap.php"] [unique_id "al4PCbLfyzVz2SrjZpi21wAAAmA"]
[Mon Jul 20 06:05:30.088059 2026] [security2:error] [pid 796567:tid 796723] [client 136.67.36.183:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.36.67.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "css.gdz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PCrLfyzVz2SrjZpi24QAAAi4"]
[Mon Jul 20 06:05:30.259537 2026] [security2:error] [pid 796928:tid 797165] [client 74.7.227.179:34524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PCusTy9vX-htKvPkfwwADBCw"], referer: https://tejasenvironmental.com/p=589840
[Mon Jul 20 06:05:30.287542 2026] [security2:error] [pid 796928:tid 797069] [client 136.67.36.183:57664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4PCusTy9vX-htKvPkf0wAAAqQ"]
[Mon Jul 20 06:05:30.298541 2026] [security2:error] [pid 796928:tid 797101] [client 14.225.17.146:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4PCOsTy9vX-htKvPkfggAAAsQ"], referer: http://aandarealtygroup.com/Wordpress
[Mon Jul 20 06:05:30.512733 2026] [security2:error] [pid 796928:tid 797058] [client 50.116.65.227:52342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PCusTy9vX-htKvPkf1wAAApk"]
[Mon Jul 20 06:05:30.702897 2026] [security2:error] [pid 796928:tid 797083] [client 50.116.65.227:52348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PCusTy9vX-htKvPkf3AAAArI"]
[Mon Jul 20 06:05:30.744533 2026] [security2:error] [pid 796928:tid 797174] [client 136.67.36.183:57827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4PCusTy9vX-htKvPkf4QAAAw0"]
[Mon Jul 20 06:05:30.751232 2026] [security2:error] [pid 796567:tid 796802] [client 14.225.17.146:49479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4PCrLfyzVz2SrjZpi27gAAAn0"], referer: http://ccsdifference.com/Wordpress
[Mon Jul 20 06:05:30.803782 2026] [security2:error] [pid 796928:tid 797080] [client 103.95.123.246:20312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PCusTy9vX-htKvPkf4gAAAq8"]
[Mon Jul 20 06:05:30.803887 2026] [security2:error] [pid 796928:tid 797080] [client 103.95.123.246:20312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PCusTy9vX-htKvPkf4gAAAq8"]
[Mon Jul 20 06:05:30.837694 2026] [security2:error] [pid 796928:tid 797127] [client 57.141.18.62:27518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PBesTy9vX-htKvPkfHgAC3gk"]
[Mon Jul 20 06:05:30.988417 2026] [security2:error] [pid 796928:tid 797148] [client 158.173.166.181:37011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PCusTy9vX-htKvPkf8QAAAvM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:31.230663 2026] [security2:error] [pid 796928:tid 797090] [client 136.67.36.183:64900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4PC-sTy9vX-htKvPkgAQAAArk"]
[Mon Jul 20 06:05:31.342007 2026] [security2:error] [pid 796928:tid 797132] [client 103.141.108.143:58569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgCQAAAuM"]
[Mon Jul 20 06:05:31.342133 2026] [security2:error] [pid 796928:tid 797132] [client 103.141.108.143:58569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgCQAAAuM"]
[Mon Jul 20 06:05:31.405041 2026] [autoindex:error] [pid 796928:tid 797167] [client 213.35.113.47:49233] AH01276: Cannot serve directory /home3/alaraycr/public_html/allisonrodrigue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:05:31.418526 2026] [security2:error] [pid 796567:tid 796789] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PC7LfyzVz2SrjZpi3CgAAAnA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:31.545292 2026] [security2:error] [pid 796928:tid 797063] [client 106.192.104.4:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgHgAAAp4"]
[Mon Jul 20 06:05:31.545453 2026] [security2:error] [pid 796928:tid 797063] [client 106.192.104.4:61430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgHgAAAp4"]
[Mon Jul 20 06:05:31.761876 2026] [security2:error] [pid 796928:tid 797172] [client 13.201.64.214:12894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgMgAAAws"]
[Mon Jul 20 06:05:31.761988 2026] [security2:error] [pid 796928:tid 797172] [client 13.201.64.214:12894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PC-sTy9vX-htKvPkgMgAAAws"]
[Mon Jul 20 06:05:31.803440 2026] [security2:error] [pid 796928:tid 797082] [client 14.225.17.146:60015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4PC-sTy9vX-htKvPkgJgAAArE"], referer: https://ccsdifference.com/Wordpress
[Mon Jul 20 06:05:31.829222 2026] [security2:error] [pid 796928:tid 796994] [remote 81.173.115.7:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4PC-sTy9vX-htKvPkgNwADCUE"]
[Mon Jul 20 06:05:31.846393 2026] [security2:error] [pid 796928:tid 797085] [client 185.132.186.75:53063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/slider.php"] [unique_id "al4PC-sTy9vX-htKvPkgOQAAArQ"]
[Mon Jul 20 06:05:31.883388 2026] [security2:error] [pid 796928:tid 797184] [client 136.67.36.183:51258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4PC-sTy9vX-htKvPkgPQAAAxc"]
[Mon Jul 20 06:05:32.029941 2026] [security2:error] [pid 796928:tid 797163] [client 14.225.17.146:51046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4PC-sTy9vX-htKvPkgFQAAAwI"], referer: http://waterproofgoods.com/Wordpress
[Mon Jul 20 06:05:32.039165 2026] [security2:error] [pid 796928:tid 797038] [remote 81.173.115.7:58446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4PDOsTy9vX-htKvPkgSQACq20"], referer: https://website-19aec4aa.spencersadventures.com/wp-login.php
[Mon Jul 20 06:05:32.123253 2026] [security2:error] [pid 796928:tid 797171] [client 57.141.18.93:46682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PBusTy9vX-htKvPkfUgADChg"]
[Mon Jul 20 06:05:32.174133 2026] [security2:error] [pid 796567:tid 796705] [client 150.228.148.150:59955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3JAAAAhw"]
[Mon Jul 20 06:05:32.189591 2026] [security2:error] [pid 796567:tid 796705] [client 150.228.148.150:59955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3JAAAAhw"]
[Mon Jul 20 06:05:32.237314 2026] [security2:error] [pid 796928:tid 796981] [remote 100.42.189.89:32792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PDOsTy9vX-htKvPkgUAAC7DQ"]
[Mon Jul 20 06:05:32.301888 2026] [security2:error] [pid 796928:tid 797064] [client 14.225.17.146:64117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4PC-sTy9vX-htKvPkf9AAAAp8"], referer: http://ravmike.com/Wordpress
[Mon Jul 20 06:05:32.388339 2026] [security2:error] [pid 796928:tid 797081] [client 136.67.36.183:49388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4PDOsTy9vX-htKvPkgXAAAArA"]
[Mon Jul 20 06:05:32.441650 2026] [security2:error] [pid 796928:tid 796954] [remote 100.42.189.89:32792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PDOsTy9vX-htKvPkgYwADBBk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:05:32.546554 2026] [cgid:error] [pid 796567:tid 796814] [client 199.45.154.141:53876] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: https://smtracking.genesismbs.com:443/cgi-bin
[Mon Jul 20 06:05:32.581567 2026] [security2:error] [pid 796928:tid 797083] [client 14.225.17.146:59364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4PDOsTy9vX-htKvPkgVAAAArI"], referer: http://alrowad-hub.net/Wordpress
[Mon Jul 20 06:05:32.675457 2026] [security2:error] [pid 796928:tid 797054] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PDOsTy9vX-htKvPkgbgAC1X0"]
[Mon Jul 20 06:05:32.675643 2026] [security2:error] [pid 796928:tid 797118] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PDOsTy9vX-htKvPkgbgAC1X0"]
[Mon Jul 20 06:05:32.675926 2026] [security2:error] [pid 796567:tid 796721] [client 14.225.17.146:56090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4PDLLfyzVz2SrjZpi3IgAAAiw"], referer: http://talknutritionwithlesley.com/Wordpress
[Mon Jul 20 06:05:32.743620 2026] [security2:error] [pid 796567:tid 796718] [client 136.67.36.183:53548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4PDLLfyzVz2SrjZpi3NQAAAik"]
[Mon Jul 20 06:05:32.806995 2026] [security2:error] [pid 796928:tid 797145] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PDOsTy9vX-htKvPkgYgAAAvA"]
[Mon Jul 20 06:05:32.818718 2026] [security2:error] [pid 796928:tid 797140] [client 45.157.112.60:23877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PDOsTy9vX-htKvPkgcwAAAus"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:32.951187 2026] [security2:error] [pid 796567:tid 796805] [client 112.213.160.112:8277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3PAAAAoA"]
[Mon Jul 20 06:05:32.951297 2026] [security2:error] [pid 796567:tid 796805] [client 112.213.160.112:8277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PDLLfyzVz2SrjZpi3PAAAAoA"]
[Mon Jul 20 06:05:33.063225 2026] [security2:error] [pid 796928:tid 797110] [client 136.67.36.183:60562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4PDesTy9vX-htKvPkggwAAAs0"]
[Mon Jul 20 06:05:33.075112 2026] [security2:error] [pid 796567:tid 796702] [client 86.98.90.58:57079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PDbLfyzVz2SrjZpi3QQAAAhk"]
[Mon Jul 20 06:05:33.075507 2026] [security2:error] [pid 796567:tid 796702] [client 86.98.90.58:57079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PDbLfyzVz2SrjZpi3QQAAAhk"]
[Mon Jul 20 06:05:33.110177 2026] [security2:error] [pid 796928:tid 797120] [client 14.225.17.146:53615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4PDesTy9vX-htKvPkggQAAAtc"], referer: http://mourgroup.com/Wordpress
[Mon Jul 20 06:05:33.182609 2026] [security2:error] [pid 796567:tid 796787] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PDbLfyzVz2SrjZpi3QgAAAm4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:33.194831 2026] [security2:error] [pid 796928:tid 797091] [client 14.225.17.146:64921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4PDesTy9vX-htKvPkghwAAAro"], referer: https://ravmike.com/Wordpress
[Mon Jul 20 06:05:33.219503 2026] [security2:error] [pid 796928:tid 797098] [client 136.67.36.183:63558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4PDesTy9vX-htKvPkgjAAAAsE"]
[Mon Jul 20 06:05:33.360544 2026] [security2:error] [pid 796567:tid 796745] [client 14.225.17.146:50342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4PDbLfyzVz2SrjZpi3RAAAAkQ"], referer: http://careysheatingandcooling.com/Wordpress
[Mon Jul 20 06:05:33.482368 2026] [security2:error] [pid 796567:tid 796804] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PDbLfyzVz2SrjZpi3UAAAAn8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:33.609246 2026] [security2:error] [pid 796567:tid 796815] [client 136.67.36.183:63561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4PDbLfyzVz2SrjZpi3XgAAAoo"]
[Mon Jul 20 06:05:33.796026 2026] [security2:error] [pid 796567:tid 796732] [client 185.132.186.64:47281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/dir.php"] [unique_id "al4PDbLfyzVz2SrjZpi3YQAAAjc"]
[Mon Jul 20 06:05:34.008844 2026] [security2:error] [pid 796928:tid 797077] [client 136.67.36.183:49468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4PDusTy9vX-htKvPkguAAAAqw"]
[Mon Jul 20 06:05:34.200709 2026] [security2:error] [pid 796928:tid 797100] [client 136.67.36.183:56639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4PDusTy9vX-htKvPkgwAAAAsM"]
[Mon Jul 20 06:05:34.291645 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.53:60718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PCbLfyzVz2SrjZpi2rAACY2g"]
[Mon Jul 20 06:05:34.499691 2026] [security2:error] [pid 796928:tid 797117] [client 136.67.36.183:56072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "css.gdz.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4PDusTy9vX-htKvPkg1wAAAtQ"]
[Mon Jul 20 06:05:34.812121 2026] [security2:error] [pid 796567:tid 796761] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PDrLfyzVz2SrjZpi3eAAAAlQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:34.863115 2026] [security2:error] [pid 796567:tid 796721] [client 115.246.21.170:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PDrLfyzVz2SrjZpi3fwAAAiw"]
[Mon Jul 20 06:05:34.864711 2026] [security2:error] [pid 796567:tid 796721] [client 115.246.21.170:58130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PDrLfyzVz2SrjZpi3fwAAAiw"]
[Mon Jul 20 06:05:35.041222 2026] [security2:error] [pid 796928:tid 796940] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PD-sTy9vX-htKvPkg7wACqws"]
[Mon Jul 20 06:05:35.041422 2026] [security2:error] [pid 796928:tid 797076] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PD-sTy9vX-htKvPkg7wACqws"]
[Mon Jul 20 06:05:35.086525 2026] [security2:error] [pid 796567:tid 796780] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PD7LfyzVz2SrjZpi3hQAAAmc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:35.206804 2026] [security2:error] [pid 796928:tid 797045] [remote 5.161.225.162:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4PD-sTy9vX-htKvPkg9QAC9XQ"]
[Mon Jul 20 06:05:35.235947 2026] [security2:error] [pid 796567:tid 796739] [client 158.173.241.141:38169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4PD7LfyzVz2SrjZpi3hAAAAj4"], referer: http://sesamegreenbeans.com/about-sesame-green-beans/
[Mon Jul 20 06:05:35.394285 2026] [security2:error] [pid 796928:tid 796952] [remote 5.161.225.162:43594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4PD-sTy9vX-htKvPkhAQAC7Rc"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:05:35.749705 2026] [security2:error] [pid 796928:tid 797094] [client 185.132.186.63:24607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/atomlib.php"] [unique_id "al4PD-sTy9vX-htKvPkhFAAAAr0"]
[Mon Jul 20 06:05:35.761450 2026] [security2:error] [pid 796567:tid 796747] [client 14.225.17.146:60844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4PDrLfyzVz2SrjZpi3bQAAAkY"], referer: http://vinovinhowine.com/Wordpress
[Mon Jul 20 06:05:35.891144 2026] [security2:error] [pid 796567:tid 796767] [client 93.152.221.118:62506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4PD7LfyzVz2SrjZpi3nAAAAlo"], referer: https://duckduckgo.com/
[Mon Jul 20 06:05:36.197763 2026] [security2:error] [pid 796928:tid 797053] [remote 124.55.178.99:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4PEOsTy9vX-htKvPkhLAACwHw"]
[Mon Jul 20 06:05:36.208255 2026] [security2:error] [pid 796928:tid 797124] [client 210.212.97.243:10444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PEOsTy9vX-htKvPkhLgAAAts"]
[Mon Jul 20 06:05:36.208352 2026] [security2:error] [pid 796928:tid 797124] [client 210.212.97.243:10444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PEOsTy9vX-htKvPkhLgAAAts"]
[Mon Jul 20 06:05:36.215131 2026] [security2:error] [pid 796928:tid 796941] [remote 8.217.229.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nzfoodstory.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PEOsTy9vX-htKvPkhMQACvAw"]
[Mon Jul 20 06:05:36.217346 2026] [security2:error] [pid 796928:tid 797105] [client 93.152.221.118:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4PEOsTy9vX-htKvPkhMgAAAsg"], referer: https://wordpress.org/
[Mon Jul 20 06:05:36.339562 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:14858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PELLfyzVz2SrjZpi3pgAAAmo"]
[Mon Jul 20 06:05:36.339649 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:14858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PELLfyzVz2SrjZpi3pgAAAmo"]
[Mon Jul 20 06:05:36.410121 2026] [security2:error] [pid 796928:tid 797153] [client 14.225.17.146:59080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4PEOsTy9vX-htKvPkhJQAAAvg"], referer: http://mrbambooplus.com/Wordpress
[Mon Jul 20 06:05:36.423413 2026] [security2:error] [pid 796928:tid 796978] [remote 8.217.229.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nzfoodstory.com"] [uri "/"] [unique_id "al4PEOsTy9vX-htKvPkhOwACpzE"]
[Mon Jul 20 06:05:36.615513 2026] [security2:error] [pid 796567:tid 796624] [remote 57.141.18.24:62580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4174419"] [unique_id "al4PELLfyzVz2SrjZpi3sAACgDg"]
[Mon Jul 20 06:05:36.624881 2026] [security2:error] [pid 796928:tid 796950] [remote 124.55.178.99:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4PEOsTy9vX-htKvPkhSQAC1BU"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:05:36.985896 2026] [security2:error] [pid 796928:tid 797035] [remote 8.217.229.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "nzfoodstory.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PEOsTy9vX-htKvPkhWQADE2o"]
[Mon Jul 20 06:05:37.136366 2026] [security2:error] [pid 796928:tid 797068] [client 65.1.132.125:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhYwAAAqM"]
[Mon Jul 20 06:05:37.136442 2026] [security2:error] [pid 796928:tid 797068] [client 65.1.132.125:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhYwAAAqM"]
[Mon Jul 20 06:05:37.148387 2026] [security2:error] [pid 796928:tid 796968] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhZAACnCc"]
[Mon Jul 20 06:05:37.148502 2026] [security2:error] [pid 796928:tid 797061] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhZAACnCc"]
[Mon Jul 20 06:05:37.217792 2026] [security2:error] [pid 796567:tid 796771] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PELLfyzVz2SrjZpi3tgAAAl4"]
[Mon Jul 20 06:05:37.277413 2026] [security2:error] [pid 796928:tid 797147] [client 93.152.221.118:63124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4PEesTy9vX-htKvPkhawAAAvI"], referer: https://www.bing.com/
[Mon Jul 20 06:05:37.570608 2026] [security2:error] [pid 796928:tid 797127] [client 181.224.94.124:55922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhewAAAt4"]
[Mon Jul 20 06:05:37.570725 2026] [security2:error] [pid 796928:tid 797127] [client 181.224.94.124:55922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PEesTy9vX-htKvPkhewAAAt4"]
[Mon Jul 20 06:05:37.699887 2026] [security2:error] [pid 796928:tid 797143] [client 185.132.186.95:63763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/style.php"] [unique_id "al4PEesTy9vX-htKvPkhiQAAAu4"]
[Mon Jul 20 06:05:37.871014 2026] [security2:error] [pid 796928:tid 797064] [client 74.7.241.182:50336] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ace-med.com"] [uri "/robots.txt"] [unique_id "al4PEesTy9vX-htKvPkhkAAAAp8"]
[Mon Jul 20 06:05:38.035359 2026] [security2:error] [pid 796567:tid 796747] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PEbLfyzVz2SrjZpi31QAAAkY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:38.150082 2026] [security2:error] [pid 796928:tid 797008] [remote 152.228.213.32:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PEusTy9vX-htKvPkhoQACvE8"]
[Mon Jul 20 06:05:38.218621 2026] [security2:error] [pid 796928:tid 797182] [client 57.141.18.101:59278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PDesTy9vX-htKvPkgiAADFSA"]
[Mon Jul 20 06:05:38.387174 2026] [security2:error] [pid 796928:tid 797000] [remote 152.228.213.32:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PEusTy9vX-htKvPkhqgAC30c"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:38.806256 2026] [security2:error] [pid 796928:tid 797054] [remote 57.141.18.37:32158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6055825"] [unique_id "al4PEusTy9vX-htKvPkhxAACpH0"]
[Mon Jul 20 06:05:39.083070 2026] [security2:error] [pid 796928:tid 797005] [remote 100.42.189.89:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PE-sTy9vX-htKvPkh2AAC10w"]
[Mon Jul 20 06:05:39.171838 2026] [security2:error] [pid 796928:tid 797109] [client 74.208.214.194:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PE-sTy9vX-htKvPkh3wAAAsw"]
[Mon Jul 20 06:05:39.276112 2026] [security2:error] [pid 796928:tid 797042] [remote 100.42.189.89:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PE-sTy9vX-htKvPkh5gACmnE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:05:39.326512 2026] [security2:error] [pid 796928:tid 797096] [client 158.173.89.95:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PE-sTy9vX-htKvPkh6AAAAr8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:05:39.652770 2026] [security2:error] [pid 796928:tid 797169] [client 185.132.186.72:32537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/libraries/phpmailer/updates.php"] [unique_id "al4PE-sTy9vX-htKvPkh-gAAAwg"]
[Mon Jul 20 06:05:39.755177 2026] [authz_core:error] [pid 796928:tid 797174] [client 43.165.167.69:59804] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini, referer: http://www.upsurgecommunications.com
[Mon Jul 20 06:05:39.763128 2026] [security2:error] [pid 796928:tid 797125] [client 57.141.18.120:52776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PDusTy9vX-htKvPkg4QAC3DM"]
[Mon Jul 20 06:05:40.108978 2026] [security2:error] [pid 796928:tid 797182] [client 14.225.17.146:53727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4PE-sTy9vX-htKvPkh4AAAAxU"], referer: http://walkingandtalking.net/Wordpress
[Mon Jul 20 06:05:40.594333 2026] [security2:error] [pid 796567:tid 796726] [client 14.225.17.146:63497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4PFLLfyzVz2SrjZpi3-wAAAjE"], referer: http://overloadcomedy.com/Wordpress
[Mon Jul 20 06:05:40.994653 2026] [security2:error] [pid 796567:tid 796733] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PFLLfyzVz2SrjZpi4DgAAAjg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:41.002395 2026] [security2:error] [pid 796928:tid 797154] [client 14.225.17.146:58261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4PFOsTy9vX-htKvPkiPAAAAvk"], referer: https://walkingandtalking.net/Wordpress
[Mon Jul 20 06:05:41.355088 2026] [security2:error] [pid 796928:tid 797077] [client 14.225.17.146:58613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4PFOsTy9vX-htKvPkiOgAAAqw"]
[Mon Jul 20 06:05:41.603521 2026] [security2:error] [pid 796928:tid 797125] [client 185.132.186.70:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/nf_tracking.php"] [unique_id "al4PFesTy9vX-htKvPkiYgAAAtw"]
[Mon Jul 20 06:05:41.612659 2026] [security2:error] [pid 796567:tid 796720] [client 50.116.65.227:26908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4PFbLfyzVz2SrjZpi4IwAAAis"]
[Mon Jul 20 06:05:41.624939 2026] [security2:error] [pid 796567:tid 796823] [client 50.116.65.227:58860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4PFbLfyzVz2SrjZpi4JAAAApI"]
[Mon Jul 20 06:05:41.854863 2026] [security2:error] [pid 796567:tid 796762] [client 57.141.18.51:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PEbLfyzVz2SrjZpi3uQACVTo"]
[Mon Jul 20 06:05:42.023107 2026] [security2:error] [pid 796928:tid 797094] [client 74.7.244.13:41674] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "certasit.com"] [uri "/robots.txt"] [unique_id "al4PFusTy9vX-htKvPkibwAAAr0"]
[Mon Jul 20 06:05:42.157661 2026] [security2:error] [pid 796928:tid 797071] [client 103.141.108.143:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkifAAAAqY"]
[Mon Jul 20 06:05:42.158103 2026] [security2:error] [pid 796928:tid 797071] [client 103.141.108.143:59210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkifAAAAqY"]
[Mon Jul 20 06:05:42.211828 2026] [security2:error] [pid 796567:tid 796655] [remote 123.30.154.30:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PFrLfyzVz2SrjZpi4MgACalc"]
[Mon Jul 20 06:05:42.370890 2026] [security2:error] [pid 796567:tid 796800] [client 57.141.18.61:47136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PEbLfyzVz2SrjZpi3ygACezc"]
[Mon Jul 20 06:05:42.372665 2026] [security2:error] [pid 796928:tid 797112] [client 103.95.123.246:20850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkihgAAAs8"]
[Mon Jul 20 06:05:42.372779 2026] [security2:error] [pid 796928:tid 797112] [client 103.95.123.246:20850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkihgAAAs8"]
[Mon Jul 20 06:05:42.532593 2026] [security2:error] [pid 796567:tid 796788] [client 14.225.17.146:59607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4PFbLfyzVz2SrjZpi4EgAAAm8"], referer: http://eduardsales.com/Wordpress
[Mon Jul 20 06:05:42.658944 2026] [security2:error] [pid 796567:tid 796804] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PFrLfyzVz2SrjZpi4OgAAAn8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:42.733706 2026] [security2:error] [pid 796567:tid 796776] [client 106.192.104.4:61917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PFrLfyzVz2SrjZpi4PwAAAmM"]
[Mon Jul 20 06:05:42.733872 2026] [security2:error] [pid 796567:tid 796776] [client 106.192.104.4:61917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PFrLfyzVz2SrjZpi4PwAAAmM"]
[Mon Jul 20 06:05:42.782224 2026] [security2:error] [pid 796928:tid 797093] [client 43.205.139.3:25740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkijAAAArw"]
[Mon Jul 20 06:05:42.813642 2026] [security2:error] [pid 796567:tid 796620] [remote 123.30.154.30:51828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.154.30.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PFrLfyzVz2SrjZpi4QgACGjQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:05:42.968198 2026] [security2:error] [pid 796567:tid 796701] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PFrLfyzVz2SrjZpi4RAAAAhg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:42.979685 2026] [security2:error] [pid 796928:tid 797142] [client 150.228.148.150:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkiqgAAAu0"]
[Mon Jul 20 06:05:42.983341 2026] [security2:error] [pid 796928:tid 797142] [client 150.228.148.150:39256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PFusTy9vX-htKvPkiqgAAAu0"]
[Mon Jul 20 06:05:43.248796 2026] [security2:error] [pid 796928:tid 797172] [client 13.201.64.214:27120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4PF-sTy9vX-htKvPkivwAAAws"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:05:43.256808 2026] [security2:error] [pid 796928:tid 797004] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPkiwAACuUs"]
[Mon Jul 20 06:05:43.257006 2026] [security2:error] [pid 796928:tid 797090] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPkiwAACuUs"]
[Mon Jul 20 06:05:43.353088 2026] [security2:error] [pid 796928:tid 797070] [client 34.34.21.42:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.ala.ppf.mybluehost.me"] [uri "/"] [unique_id "al4PF-sTy9vX-htKvPkixQAAAqU"]
[Mon Jul 20 06:05:43.353199 2026] [security2:error] [pid 796928:tid 797070] [client 34.34.21.42:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.ala.ppf.mybluehost.me"] [uri "/"] [unique_id "al4PF-sTy9vX-htKvPkixQAAAqU"]
[Mon Jul 20 06:05:43.554478 2026] [security2:error] [pid 796567:tid 796792] [client 185.132.186.68:28527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/about.php7"] [unique_id "al4PF7LfyzVz2SrjZpi4VQAAAnM"]
[Mon Jul 20 06:05:43.635993 2026] [security2:error] [pid 796928:tid 797134] [client 45.5.39.171:50217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4PF-sTy9vX-htKvPki0AAAAuU"]
[Mon Jul 20 06:05:43.664058 2026] [security2:error] [pid 796928:tid 797133] [client 112.213.160.112:8451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPki1wAAAuQ"]
[Mon Jul 20 06:05:43.664162 2026] [security2:error] [pid 796928:tid 797133] [client 112.213.160.112:8451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PF-sTy9vX-htKvPki1wAAAuQ"]
[Mon Jul 20 06:05:43.867417 2026] [security2:error] [pid 796928:tid 797038] [remote 14.128.14.9:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PF-sTy9vX-htKvPki4wACom0"]
[Mon Jul 20 06:05:43.968759 2026] [security2:error] [pid 796567:tid 796802] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PF7LfyzVz2SrjZpi4XQAAAn0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:44.234634 2026] [security2:error] [pid 796928:tid 797119] [client 57.141.18.25:56460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PE-sTy9vX-htKvPkhzwAC1kg"]
[Mon Jul 20 06:05:44.431331 2026] [security2:error] [pid 796928:tid 796942] [remote 14.128.14.9:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.14.128.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PGOsTy9vX-htKvPkjCAADAg0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:05:44.797149 2026] [security2:error] [pid 796567:tid 796774] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PGLLfyzVz2SrjZpi4cAAAAmE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:44.961441 2026] [security2:error] [pid 796567:tid 796791] [client 14.225.17.146:58656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4PFrLfyzVz2SrjZpi4LQAAAnI"], referer: http://drewsasburyparkbeachhouse.com/Wordpress
[Mon Jul 20 06:05:45.011797 2026] [security2:error] [pid 796928:tid 797156] [client 57.141.18.87:43922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PE-sTy9vX-htKvPkh_gAC-0Y"]
[Mon Jul 20 06:05:45.094663 2026] [security2:error] [pid 796567:tid 796742] [client 86.98.90.58:57894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4ewAAAkE"]
[Mon Jul 20 06:05:45.094784 2026] [security2:error] [pid 796567:tid 796742] [client 86.98.90.58:57894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4ewAAAkE"]
[Mon Jul 20 06:05:45.312782 2026] [security2:error] [pid 796567:tid 796782] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PGbLfyzVz2SrjZpi4gQAAAmk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:45.465550 2026] [security2:error] [pid 796567:tid 796772] [client 57.141.18.78:44438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PFLLfyzVz2SrjZpi3_gACX00"]
[Mon Jul 20 06:05:45.501871 2026] [security2:error] [pid 796928:tid 797113] [client 115.246.21.170:10895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PGesTy9vX-htKvPkjNAAAAtA"]
[Mon Jul 20 06:05:45.502016 2026] [security2:error] [pid 796928:tid 797113] [client 115.246.21.170:10895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PGesTy9vX-htKvPkjNAAAAtA"]
[Mon Jul 20 06:05:45.663129 2026] [security2:error] [pid 796567:tid 796654] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4jwACSFY"]
[Mon Jul 20 06:05:45.663254 2026] [security2:error] [pid 796567:tid 796749] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PGbLfyzVz2SrjZpi4jwACSFY"]
[Mon Jul 20 06:05:45.922146 2026] [security2:error] [pid 796567:tid 796747] [client 3.109.4.218:55526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4PGbLfyzVz2SrjZpi4lwAAAkY"]
[Mon Jul 20 06:05:46.022068 2026] [security2:error] [pid 796928:tid 797040] [remote 50.28.1.50:41736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjSwAC3m8"]
[Mon Jul 20 06:05:46.216571 2026] [security2:error] [pid 796928:tid 797043] [remote 50.28.1.50:41736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjVAAC93I"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:46.218356 2026] [security2:error] [pid 796567:tid 796781] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PGrLfyzVz2SrjZpi4nAAAAmg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:46.355572 2026] [security2:error] [pid 796928:tid 797073] [client 14.225.17.146:51274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjVQAAAqg"], referer: http://backandneckpainrelieflaceychiropractor.com/Wordpress
[Mon Jul 20 06:05:46.507132 2026] [security2:error] [pid 796928:tid 797068] [client 185.132.186.77:44835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/filefuns.php"] [unique_id "al4PGusTy9vX-htKvPkjZQAAAqM"]
[Mon Jul 20 06:05:46.621778 2026] [security2:error] [pid 796928:tid 796995] [remote 167.233.114.32:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjaQAC-kI"]
[Mon Jul 20 06:05:46.645326 2026] [security2:error] [pid 796928:tid 797105] [client 57.141.18.123:28084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PFesTy9vX-htKvPkiWgACyCI"]
[Mon Jul 20 06:05:46.779120 2026] [security2:error] [pid 796567:tid 796756] [client 74.7.228.17:39500] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4PGrLfyzVz2SrjZpi4sQAAAk8"]
[Mon Jul 20 06:05:46.833062 2026] [security2:error] [pid 796928:tid 797079] [client 14.225.17.146:51726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjawAAAq4"], referer: http://fluidtemple.org/Wordpress
[Mon Jul 20 06:05:46.838792 2026] [security2:error] [pid 796928:tid 797019] [remote 167.233.114.32:39516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4PGusTy9vX-htKvPkjcgACs1o"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:05:46.913623 2026] [security2:error] [pid 796567:tid 796822] [client 41.173.37.102:1359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PGrLfyzVz2SrjZpi4uAAAApE"]
[Mon Jul 20 06:05:46.913724 2026] [security2:error] [pid 796567:tid 796822] [client 41.173.37.102:1359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PGrLfyzVz2SrjZpi4uAAAApE"]
[Mon Jul 20 06:05:46.936177 2026] [security2:error] [pid 796567:tid 796725] [client 74.7.228.17:54416] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.asliceofleadership.com"] [uri "/index.php"] [unique_id "al4PGrLfyzVz2SrjZpi4uQACMEA"], referer: http://www.asliceofleadership.com/robots.txt
[Mon Jul 20 06:05:47.090649 2026] [security2:error] [pid 796567:tid 796704] [client 178.152.178.232:37164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PG7LfyzVz2SrjZpi4vQAAAhs"]
[Mon Jul 20 06:05:47.090758 2026] [security2:error] [pid 796567:tid 796704] [client 178.152.178.232:37164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PG7LfyzVz2SrjZpi4vQAAAhs"]
[Mon Jul 20 06:05:47.156838 2026] [security2:error] [pid 796928:tid 797112] [client 13.201.64.214:27126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4PG-sTy9vX-htKvPkjhAAAAs8"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:05:47.157219 2026] [security2:error] [pid 796928:tid 797125] [client 210.212.97.243:10445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjhQAAAtw"]
[Mon Jul 20 06:05:47.157313 2026] [security2:error] [pid 796928:tid 797125] [client 210.212.97.243:10445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjhQAAAtw"]
[Mon Jul 20 06:05:47.232254 2026] [security2:error] [pid 796567:tid 796804] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PG7LfyzVz2SrjZpi4wAAAAn8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:47.608640 2026] [security2:error] [pid 796928:tid 797157] [client 14.225.17.146:62968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjTwAAAvw"], referer: http://solkeetw.com/Wordpress
[Mon Jul 20 06:05:47.637480 2026] [security2:error] [pid 796567:tid 796714] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PG7LfyzVz2SrjZpi4zQAAAiU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:47.856851 2026] [security2:error] [pid 796928:tid 797077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PG-sTy9vX-htKvPkjlgAAAqw"]
[Mon Jul 20 06:05:47.891816 2026] [security2:error] [pid 796928:tid 797122] [client 57.141.18.39:47815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PFusTy9vX-htKvPkikQAC2X8"]
[Mon Jul 20 06:05:47.956246 2026] [security2:error] [pid 796928:tid 796941] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjtwACwgw"]
[Mon Jul 20 06:05:47.956430 2026] [security2:error] [pid 796928:tid 797099] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PG-sTy9vX-htKvPkjtwACwgw"]
[Mon Jul 20 06:05:48.026302 2026] [security2:error] [pid 796928:tid 797101] [client 193.19.109.244:53631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4PHOsTy9vX-htKvPkjugAAAsQ"]
[Mon Jul 20 06:05:48.118691 2026] [security2:error] [pid 796567:tid 796699] [client 181.224.94.124:16989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PHLLfyzVz2SrjZpi45QAAAhY"]
[Mon Jul 20 06:05:48.118815 2026] [security2:error] [pid 796567:tid 796699] [client 181.224.94.124:16989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PHLLfyzVz2SrjZpi45QAAAhY"]
[Mon Jul 20 06:05:48.119300 2026] [security2:error] [pid 796567:tid 796755] [client 50.116.65.227:59066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PHLLfyzVz2SrjZpi45AAAAk4"]
[Mon Jul 20 06:05:48.128963 2026] [security2:error] [pid 796928:tid 797110] [client 50.116.65.227:59072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PHOsTy9vX-htKvPkjwAAAAs0"]
[Mon Jul 20 06:05:48.431249 2026] [security2:error] [pid 796928:tid 797065] [client 14.177.167.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4PG-sTy9vX-htKvPkjqwAAAqA"]
[Mon Jul 20 06:05:48.455571 2026] [security2:error] [pid 796567:tid 796753] [client 185.132.186.67:45819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/class_api.php"] [unique_id "al4PHLLfyzVz2SrjZpi49QAAAkw"]
[Mon Jul 20 06:05:48.571183 2026] [security2:error] [pid 796567:tid 796692] [remote 152.228.213.32:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PHLLfyzVz2SrjZpi4-wACTXw"]
[Mon Jul 20 06:05:49.152948 2026] [security2:error] [pid 796567:tid 796574] [remote 152.228.213.32:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PHbLfyzVz2SrjZpi5FAACJAY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:05:49.320770 2026] [security2:error] [pid 796567:tid 796819] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PHbLfyzVz2SrjZpi5FwAAAo4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:49.549076 2026] [security2:error] [pid 796567:tid 796810] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PHbLfyzVz2SrjZpi5HgAAAoU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:49.776141 2026] [security2:error] [pid 796567:tid 796728] [client 14.225.17.146:52023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4PHbLfyzVz2SrjZpi5GQAAAjM"], referer: http://uritems.net/Wordpress
[Mon Jul 20 06:05:49.862915 2026] [security2:error] [pid 796928:tid 797082] [client 212.237.120.155:31404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4PHesTy9vX-htKvPkkBwAAArE"]
[Mon Jul 20 06:05:49.920710 2026] [security2:error] [pid 796928:tid 797095] [client 57.141.18.20:47702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGOsTy9vX-htKvPkjDgACvk0"]
[Mon Jul 20 06:05:50.054232 2026] [security2:error] [pid 796567:tid 796821] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PHbLfyzVz2SrjZpi5LAAAApA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:50.406645 2026] [security2:error] [pid 796928:tid 797075] [client 185.132.186.65:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/l.php"] [unique_id "al4PHusTy9vX-htKvPkkKwAAAqo"]
[Mon Jul 20 06:05:50.460197 2026] [security2:error] [pid 796928:tid 797133] [client 14.225.17.146:62213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4PHusTy9vX-htKvPkkHgAAAuQ"], referer: http://maxenengineering.com/Wordpress
[Mon Jul 20 06:05:50.592119 2026] [security2:error] [pid 796567:tid 796739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PHrLfyzVz2SrjZpi5PgAAAj4"]
[Mon Jul 20 06:05:50.783043 2026] [security2:error] [pid 796928:tid 797080] [client 57.141.18.124:54396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGesTy9vX-htKvPkjJwACr0M"]
[Mon Jul 20 06:05:51.390077 2026] [security2:error] [pid 796567:tid 796819] [client 14.225.17.146:52055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4PH7LfyzVz2SrjZpi5ZAAAAo4"], referer: https://maxenengineering.com/Wordpress
[Mon Jul 20 06:05:51.391054 2026] [security2:error] [pid 796567:tid 796765] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PH7LfyzVz2SrjZpi5ZQAAAlg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:51.649637 2026] [security2:error] [pid 796928:tid 797153] [client 57.141.18.47:30098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjVwAC-C4"]
[Mon Jul 20 06:05:51.655023 2026] [security2:error] [pid 796928:tid 797126] [client 57.141.18.55:37026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PGusTy9vX-htKvPkjWQAC3S8"]
[Mon Jul 20 06:05:52.355380 2026] [security2:error] [pid 796928:tid 797131] [client 185.132.186.82:52851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/repeater.php"] [unique_id "al4PIOsTy9vX-htKvPkkqQAAAuI"]
[Mon Jul 20 06:05:52.861005 2026] [security2:error] [pid 796567:tid 796774] [client 193.37.33.4:60821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4PILLfyzVz2SrjZpi5jwAAAmE"]
[Mon Jul 20 06:05:52.992181 2026] [security2:error] [pid 796928:tid 797097] [client 103.141.108.143:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PIOsTy9vX-htKvPkk0wAAAsA"]
[Mon Jul 20 06:05:52.992341 2026] [security2:error] [pid 796928:tid 797097] [client 103.141.108.143:59634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PIOsTy9vX-htKvPkk0wAAAsA"]
[Mon Jul 20 06:05:53.103424 2026] [security2:error] [pid 796928:tid 797137] [client 106.192.104.4:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk2AAAAug"]
[Mon Jul 20 06:05:53.103584 2026] [security2:error] [pid 796928:tid 797137] [client 106.192.104.4:62379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk2AAAAug"]
[Mon Jul 20 06:05:53.157479 2026] [security2:error] [pid 796928:tid 797095] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PIOsTy9vX-htKvPkkxwAAAr4"]
[Mon Jul 20 06:05:53.534883 2026] [security2:error] [pid 796928:tid 797181] [client 43.205.139.3:48906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk4QAAAxQ"]
[Mon Jul 20 06:05:53.570465 2026] [security2:error] [pid 796928:tid 797145] [client 14.225.17.146:52740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4PIOsTy9vX-htKvPkknwAAAvA"], referer: http://alchemygroup.ca/Wordpress
[Mon Jul 20 06:05:53.612309 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:40990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk8gAAAuw"]
[Mon Jul 20 06:05:53.612426 2026] [security2:error] [pid 796928:tid 797141] [client 150.228.148.150:40990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PIesTy9vX-htKvPkk8gAAAuw"]
[Mon Jul 20 06:05:53.641545 2026] [security2:error] [pid 796928:tid 797091] [client 114.119.134.51:28373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/page/8"] [unique_id "al4PIesTy9vX-htKvPkk9wAAAro"], referer: https://www.jenfarley.com/
[Mon Jul 20 06:05:53.659346 2026] [security2:error] [pid 796567:tid 796699] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PIbLfyzVz2SrjZpi5mwAAAhY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:53.663004 2026] [security2:error] [pid 796928:tid 797155] [client 3.67.192.83:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4PIOsTy9vX-htKvPkkxAAAAvo"]
[Mon Jul 20 06:05:53.691937 2026] [security2:error] [pid 796928:tid 797067] [client 3.67.192.83:44294] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4PIOsTy9vX-htKvPkkwgAAAqI"]
[Mon Jul 20 06:05:54.033607 2026] [security2:error] [pid 796928:tid 797056] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklDwAC1X8"]
[Mon Jul 20 06:05:54.033843 2026] [security2:error] [pid 796928:tid 797118] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklDwAC1X8"]
[Mon Jul 20 06:05:54.177943 2026] [security2:error] [pid 796567:tid 796712] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PIrLfyzVz2SrjZpi5rAAAAiM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:54.297414 2026] [security2:error] [pid 796928:tid 797094] [client 185.132.186.100:52831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/wso.php"] [unique_id "al4PIusTy9vX-htKvPklGwAAAr0"]
[Mon Jul 20 06:05:54.362913 2026] [security2:error] [pid 796928:tid 797153] [client 112.213.160.112:8646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklHQAAAvg"]
[Mon Jul 20 06:05:54.363056 2026] [security2:error] [pid 796928:tid 797153] [client 112.213.160.112:8646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PIusTy9vX-htKvPklHQAAAvg"]
[Mon Jul 20 06:05:54.703308 2026] [security2:error] [pid 796567:tid 796704] [client 103.95.123.246:21355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PIrLfyzVz2SrjZpi5wAAAAhs"]
[Mon Jul 20 06:05:54.703397 2026] [security2:error] [pid 796567:tid 796704] [client 103.95.123.246:21355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PIrLfyzVz2SrjZpi5wAAAAhs"]
[Mon Jul 20 06:05:55.072321 2026] [security2:error] [pid 796567:tid 796796] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "botanicapatterndesigns.com"] [uri "/.well-known/about.php"] [unique_id "al4PI7LfyzVz2SrjZpi5zAAAAnc"]
[Mon Jul 20 06:05:55.072422 2026] [security2:error] [pid 796567:tid 796796] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "botanicapatterndesigns.com"] [uri "/.well-known/about.php"] [unique_id "al4PI7LfyzVz2SrjZpi5zAAAAnc"]
[Mon Jul 20 06:05:55.424617 2026] [security2:error] [pid 796928:tid 796938] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4PI-sTy9vX-htKvPklSAAC_wk"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:05:55.522453 2026] [security2:error] [pid 796928:tid 796937] [remote 8.217.108.67:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PI-sTy9vX-htKvPklVAACqgg"]
[Mon Jul 20 06:05:55.587265 2026] [security2:error] [pid 796567:tid 796804] [client 57.141.18.12:45908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PHrLfyzVz2SrjZpi5SgACfxU"]
[Mon Jul 20 06:05:55.627533 2026] [security2:error] [pid 796928:tid 796947] [remote 95.217.78.234:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PI-sTy9vX-htKvPklWwAC7hI"]
[Mon Jul 20 06:05:55.846151 2026] [security2:error] [pid 796928:tid 796949] [remote 95.217.78.234:35556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PI-sTy9vX-htKvPklbgACrBQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:05:55.898326 2026] [security2:error] [pid 796928:tid 797089] [client 57.141.18.21:57900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PHusTy9vX-htKvPkkOwACuA0"]
[Mon Jul 20 06:05:56.253155 2026] [security2:error] [pid 796928:tid 797072] [client 185.132.186.97:23689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/autoload_classmap.php"] [unique_id "al4PJOsTy9vX-htKvPklewAAAqc"]
[Mon Jul 20 06:05:56.346009 2026] [security2:error] [pid 796928:tid 797058] [client 14.225.17.146:55741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4PI-sTy9vX-htKvPklOgAAApk"], referer: http://christiancountytrumpet.com/Wordpress
[Mon Jul 20 06:05:56.437126 2026] [security2:error] [pid 796567:tid 796752] [client 14.225.17.146:64981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4PIrLfyzVz2SrjZpi5wgAAAks"], referer: http://wathenbartlett.co.uk/Wordpress
[Mon Jul 20 06:05:56.497928 2026] [security2:error] [pid 796928:tid 796961] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PJOsTy9vX-htKvPkliAADACA"]
[Mon Jul 20 06:05:56.498073 2026] [security2:error] [pid 796928:tid 797161] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PJOsTy9vX-htKvPkliAADACA"]
[Mon Jul 20 06:05:56.646436 2026] [security2:error] [pid 796928:tid 797173] [client 14.225.17.146:56336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4PJOsTy9vX-htKvPklegAAAww"], referer: http://idigress.group/Wordpress
[Mon Jul 20 06:05:56.648179 2026] [security2:error] [pid 796567:tid 796822] [client 103.77.203.233:56940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PJLLfyzVz2SrjZpi5_gAAApE"]
[Mon Jul 20 06:05:56.648335 2026] [security2:error] [pid 796567:tid 796822] [client 103.77.203.233:56940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PJLLfyzVz2SrjZpi5_gAAApE"]
[Mon Jul 20 06:05:56.746072 2026] [security2:error] [pid 796567:tid 796625] [remote 20.153.140.50:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PJLLfyzVz2SrjZpi6AgACgjk"]
[Mon Jul 20 06:05:56.856032 2026] [security2:error] [pid 796928:tid 796991] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PJOsTy9vX-htKvPkloAAC-T4"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:05:56.871689 2026] [security2:error] [pid 796567:tid 796818] [client 14.182.195.220:51995] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4PJLLfyzVz2SrjZpi6CQAAAo0"]
[Mon Jul 20 06:05:57.100208 2026] [security2:error] [pid 796928:tid 797094] [client 115.246.21.170:51486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklsAAAAr0"]
[Mon Jul 20 06:05:57.100306 2026] [security2:error] [pid 796928:tid 797094] [client 115.246.21.170:51486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklsAAAAr0"]
[Mon Jul 20 06:05:57.189443 2026] [security2:error] [pid 796567:tid 796683] [remote 20.153.140.50:52858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PJbLfyzVz2SrjZpi6FAACYHM"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:05:57.361903 2026] [security2:error] [pid 796928:tid 797175] [client 14.225.17.146:58049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4PJesTy9vX-htKvPkluQAAAw4"], referer: https://wathenbartlett.co.uk/Wordpress
[Mon Jul 20 06:05:57.435366 2026] [security2:error] [pid 796928:tid 797119] [client 50.116.65.227:35222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PJesTy9vX-htKvPklvQAAAtY"]
[Mon Jul 20 06:05:57.447388 2026] [security2:error] [pid 796928:tid 797162] [client 50.116.65.227:35234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PJesTy9vX-htKvPklvgAAAwE"]
[Mon Jul 20 06:05:57.535662 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:1808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklwgAAAp8"]
[Mon Jul 20 06:05:57.535777 2026] [security2:error] [pid 796928:tid 797064] [client 41.173.37.102:1808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPklwgAAAp8"]
[Mon Jul 20 06:05:57.621412 2026] [security2:error] [pid 796567:tid 796771] [client 57.141.18.60:26990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PILLfyzVz2SrjZpi5gAACXho"]
[Mon Jul 20 06:05:57.705566 2026] [security2:error] [pid 796567:tid 796739] [client 210.212.97.243:10446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PJbLfyzVz2SrjZpi6IwAAAj4"]
[Mon Jul 20 06:05:57.705671 2026] [security2:error] [pid 796567:tid 796739] [client 210.212.97.243:10446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PJbLfyzVz2SrjZpi6IwAAAj4"]
[Mon Jul 20 06:05:57.769829 2026] [security2:error] [pid 796928:tid 797104] [client 178.152.178.232:36014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPkl0wAAAsc"]
[Mon Jul 20 06:05:57.769945 2026] [security2:error] [pid 796928:tid 797104] [client 178.152.178.232:36014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PJesTy9vX-htKvPkl0wAAAsc"]
[Mon Jul 20 06:05:57.770254 2026] [security2:error] [pid 796567:tid 796803] [client 14.225.17.146:61041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4PJLLfyzVz2SrjZpi6AAAAAn4"], referer: http://ancestralidadytrance.space/Wordpress
[Mon Jul 20 06:05:58.136203 2026] [security2:error] [pid 796567:tid 796622] [remote 182.77.62.24:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4PJrLfyzVz2SrjZpi6LAACfzY"]
[Mon Jul 20 06:05:58.201496 2026] [security2:error] [pid 796567:tid 796806] [client 185.132.186.83:38481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/contacts.php"] [unique_id "al4PJrLfyzVz2SrjZpi6LgAAAoE"]
[Mon Jul 20 06:05:58.230578 2026] [security2:error] [pid 796928:tid 797084] [client 86.98.90.58:58925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkl7gAAArM"]
[Mon Jul 20 06:05:58.230844 2026] [security2:error] [pid 796928:tid 797084] [client 86.98.90.58:58925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkl7gAAArM"]
[Mon Jul 20 06:05:58.367194 2026] [security2:error] [pid 796928:tid 796936] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4PJusTy9vX-htKvPkl9wAC3Ac"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:05:58.473551 2026] [security2:error] [pid 796567:tid 796614] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PJrLfyzVz2SrjZpi6PAACVy4"]
[Mon Jul 20 06:05:58.473811 2026] [security2:error] [pid 796567:tid 796764] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PJrLfyzVz2SrjZpi6PAACVy4"]
[Mon Jul 20 06:05:58.557235 2026] [security2:error] [pid 796928:tid 797138] [client 57.141.18.10:47672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PIesTy9vX-htKvPkk4AAC6XU"]
[Mon Jul 20 06:05:58.644790 2026] [security2:error] [pid 796928:tid 797117] [client 181.224.94.124:11311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkmBgAAAtQ"]
[Mon Jul 20 06:05:58.644915 2026] [security2:error] [pid 796928:tid 797117] [client 181.224.94.124:11311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PJusTy9vX-htKvPkmBgAAAtQ"]
[Mon Jul 20 06:05:58.724093 2026] [security2:error] [pid 796928:tid 797060] [client 190.115.89.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4PJusTy9vX-htKvPkl_QAAAps"]
[Mon Jul 20 06:05:58.755396 2026] [security2:error] [pid 796567:tid 796677] [remote 57.141.18.35:38908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5852913"] [unique_id "al4PJrLfyzVz2SrjZpi6QgACh20"]
[Mon Jul 20 06:05:58.767437 2026] [security2:error] [pid 796567:tid 796678] [remote 188.166.241.141:36268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PJrLfyzVz2SrjZpi6QwACK24"]
[Mon Jul 20 06:05:59.044166 2026] [security2:error] [pid 796567:tid 796762] [client 104.234.53.78:38015] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6SAAAAlU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:59.044327 2026] [security2:error] [pid 796567:tid 796762] [client 104.234.53.78:38015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6SAAAAlU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:05:59.239276 2026] [security2:error] [pid 796567:tid 796706] [client 216.73.217.138:51662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6SgACHSc"]
[Mon Jul 20 06:05:59.265737 2026] [security2:error] [pid 796928:tid 797039] [remote 20.153.140.50:52874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PJ-sTy9vX-htKvPkmJwACnm4"]
[Mon Jul 20 06:05:59.265886 2026] [security2:error] [pid 796928:tid 797063] [client 20.153.140.50:52874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PJ-sTy9vX-htKvPkmJwACnm4"]
[Mon Jul 20 06:05:59.269836 2026] [security2:error] [pid 796567:tid 796621] [remote 182.77.62.24:40630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6UQACWTU"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:05:59.276957 2026] [security2:error] [pid 796567:tid 796611] [remote 188.166.241.141:36268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6UgACays"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:05:59.294180 2026] [security2:error] [pid 796928:tid 796959] [remote 100.42.189.89:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PJ-sTy9vX-htKvPkmKgACmh4"]
[Mon Jul 20 06:05:59.498795 2026] [security2:error] [pid 796928:tid 797029] [remote 100.42.189.89:33188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PJ-sTy9vX-htKvPkmLgACoWQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:05:59.531960 2026] [security2:error] [pid 796928:tid 796958] [remote 8.217.108.67:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4PJ-sTy9vX-htKvPkmMgACyB0"]
[Mon Jul 20 06:05:59.796403 2026] [security2:error] [pid 796928:tid 797056] [remote 17.241.227.162:43352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.227.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4PJ-sTy9vX-htKvPkmQQACun8"], referer: https://www.savilerowtravel.com/hotels/mexico/la-datcha-villa-cabo-san-lucas/cabo-san-lucas-ladatcha01/
[Mon Jul 20 06:06:00.146374 2026] [security2:error] [pid 796928:tid 797075] [client 185.132.186.55:53681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wsa.php"] [unique_id "al4PKOsTy9vX-htKvPkmVgAAAqo"]
[Mon Jul 20 06:06:00.177866 2026] [security2:error] [pid 796567:tid 796744] [client 57.141.18.27:52166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PI7LfyzVz2SrjZpi5yQACQx8"]
[Mon Jul 20 06:06:00.214453 2026] [security2:error] [pid 796928:tid 796929] [remote 8.217.108.67:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4PKOsTy9vX-htKvPkmWQACzwA"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:06:00.565958 2026] [security2:error] [pid 796928:tid 797134] [client 14.225.17.146:61164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4PJ-sTy9vX-htKvPkmIQAAAuU"], referer: http://alaraycreative.com/Wordpress
[Mon Jul 20 06:06:00.608435 2026] [security2:error] [pid 796928:tid 797085] [client 57.141.18.27:52178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PI-sTy9vX-htKvPklRgACtDY"]
[Mon Jul 20 06:06:00.911295 2026] [security2:error] [pid 796928:tid 797100] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmWgAAAsM"]
[Mon Jul 20 06:06:01.047533 2026] [security2:error] [pid 796928:tid 797048] [remote 8.217.108.67:62250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4PKesTy9vX-htKvPkmegAConc"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 06:06:01.165319 2026] [security2:error] [pid 796928:tid 797092] [client 14.225.17.146:60419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmWwAAArs"], referer: http://kromosenergy.com/Wordpress
[Mon Jul 20 06:06:01.952690 2026] [security2:error] [pid 796928:tid 797062] [client 14.225.17.146:54351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4PJ-sTy9vX-htKvPkmIgAAAp0"]
[Mon Jul 20 06:06:01.969950 2026] [access_compat:error] [pid 796567:tid 796742] [client 183.47.107.100:46131] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:02.032929 2026] [security2:error] [pid 796928:tid 797118] [client 57.141.18.53:61890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJOsTy9vX-htKvPkloQAC1X0"]
[Mon Jul 20 06:06:02.103386 2026] [security2:error] [pid 796928:tid 797095] [client 57.141.18.59:26506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJOsTy9vX-htKvPklowACvmI"]
[Mon Jul 20 06:06:02.107282 2026] [security2:error] [pid 796928:tid 797083] [client 185.132.186.79:53803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "al4PKusTy9vX-htKvPkmqwAAArI"]
[Mon Jul 20 06:06:02.190429 2026] [access_compat:error] [pid 796928:tid 797128] [client 157.148.43.42:51755] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:02.276371 2026] [access_compat:error] [pid 796928:tid 797145] [client 157.148.43.160:59217] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:02.362847 2026] [security2:error] [pid 796567:tid 796790] [client 14.225.17.146:60843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4PKLLfyzVz2SrjZpi6jgAAAnE"], referer: http://bbwipartnerconference.com/Wordpress
[Mon Jul 20 06:06:02.402320 2026] [security2:error] [pid 796928:tid 797107] [client 14.225.17.146:60547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmpgAAAso"], referer: http://younutrition.gr/Wordpress
[Mon Jul 20 06:06:02.558333 2026] [security2:error] [pid 796928:tid 797015] [remote 185.22.228.25:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PKusTy9vX-htKvPkm1AACxlY"]
[Mon Jul 20 06:06:02.582966 2026] [security2:error] [pid 796928:tid 797176] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmqQADDxg"], referer: http://assasalnazaha.com/Wordpress
[Mon Jul 20 06:06:02.588086 2026] [security2:error] [pid 796928:tid 797121] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmtgAAAtg"]
[Mon Jul 20 06:06:02.592924 2026] [security2:error] [pid 796567:tid 796699] [client 57.141.18.93:51902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJbLfyzVz2SrjZpi6FQACFgs"]
[Mon Jul 20 06:06:02.877579 2026] [security2:error] [pid 796567:tid 796636] [remote 152.228.213.32:46844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PKrLfyzVz2SrjZpi60QACjkQ"]
[Mon Jul 20 06:06:02.877814 2026] [security2:error] [pid 796567:tid 796819] [client 152.228.213.32:46844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PKrLfyzVz2SrjZpi60QACjkQ"]
[Mon Jul 20 06:06:03.066646 2026] [security2:error] [pid 796928:tid 797159] [client 14.225.17.146:62535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkm7wAAAv4"], referer: http://falconarrowshop.com/Wordpress
[Mon Jul 20 06:06:03.100036 2026] [security2:error] [pid 796928:tid 797025] [remote 81.173.115.7:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4PK-sTy9vX-htKvPkm_QAC6WA"]
[Mon Jul 20 06:06:03.231683 2026] [security2:error] [pid 796928:tid 797183] [client 57.141.18.25:47214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJesTy9vX-htKvPkl2QADFmM"]
[Mon Jul 20 06:06:03.293632 2026] [security2:error] [pid 796928:tid 797016] [remote 81.173.115.7:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4PK-sTy9vX-htKvPknDwACzFc"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:06:03.480166 2026] [access_compat:error] [pid 796928:tid 797112] [client 157.148.59.84:58515] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:03.615994 2026] [security2:error] [pid 796567:tid 796572] [remote 49.13.1.223:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PK7LfyzVz2SrjZpi64AACbwQ"]
[Mon Jul 20 06:06:03.673411 2026] [security2:error] [pid 796567:tid 796769] [client 103.141.108.143:60059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PK7LfyzVz2SrjZpi65QAAAlw"]
[Mon Jul 20 06:06:03.674180 2026] [security2:error] [pid 796567:tid 796769] [client 103.141.108.143:60059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PK7LfyzVz2SrjZpi65QAAAlw"]
[Mon Jul 20 06:06:03.684959 2026] [security2:error] [pid 796567:tid 796623] [remote 162.19.86.63:45042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PK7LfyzVz2SrjZpi65gACWDc"]
[Mon Jul 20 06:06:03.798919 2026] [security2:error] [pid 796567:tid 796615] [remote 49.13.1.223:35716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PK7LfyzVz2SrjZpi68gACSC8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:03.840134 2026] [security2:error] [pid 796928:tid 797144] [client 106.192.104.4:62855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PK-sTy9vX-htKvPknOAAAAu8"]
[Mon Jul 20 06:06:03.840274 2026] [security2:error] [pid 796928:tid 797144] [client 106.192.104.4:62855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PK-sTy9vX-htKvPknOAAAAu8"]
[Mon Jul 20 06:06:03.883801 2026] [security2:error] [pid 796928:tid 797079] [client 14.173.22.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4PK-sTy9vX-htKvPknKgACrm8"]
[Mon Jul 20 06:06:04.011903 2026] [security2:error] [pid 796928:tid 797085] [client 98.159.234.160:23283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PLOsTy9vX-htKvPknPQAAArQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:04.044542 2026] [security2:error] [pid 796928:tid 797083] [client 185.132.186.55:41805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/firewall.php7"] [unique_id "al4PLOsTy9vX-htKvPknPwAAArI"]
[Mon Jul 20 06:06:04.220216 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:62439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4PK7LfyzVz2SrjZpi64QAAAhg"], referer: http://gearwaterproof.com/Wordpress
[Mon Jul 20 06:06:04.340185 2026] [security2:error] [pid 796567:tid 796708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PK7LfyzVz2SrjZpi69wAAAh8"]
[Mon Jul 20 06:06:04.359060 2026] [security2:error] [pid 796928:tid 797131] [client 57.141.18.88:20220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJ-sTy9vX-htKvPkmGQAC4nQ"]
[Mon Jul 20 06:06:04.410505 2026] [security2:error] [pid 796567:tid 796657] [remote 162.19.86.63:45042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PLLLfyzVz2SrjZpi7AQACflk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:04.471054 2026] [security2:error] [pid 796928:tid 797100] [client 150.228.148.150:24455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknVAAAAsM"]
[Mon Jul 20 06:06:04.478718 2026] [security2:error] [pid 796928:tid 797100] [client 150.228.148.150:24455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknVAAAAsM"]
[Mon Jul 20 06:06:04.690393 2026] [security2:error] [pid 796928:tid 797132] [client 103.95.123.246:17985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknXQAAAuM"]
[Mon Jul 20 06:06:04.690552 2026] [security2:error] [pid 796928:tid 797132] [client 103.95.123.246:17985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PLOsTy9vX-htKvPknXQAAAuM"]
[Mon Jul 20 06:06:04.771506 2026] [security2:error] [pid 796567:tid 796798] [client 57.141.18.109:60022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PJ7LfyzVz2SrjZpi6VQACeUU"]
[Mon Jul 20 06:06:05.080303 2026] [security2:error] [pid 796928:tid 797125] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4PLesTy9vX-htKvPkndgAAAtw"]
[Mon Jul 20 06:06:05.091863 2026] [security2:error] [pid 796928:tid 797128] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-plain.php"] [unique_id "al4PLesTy9vX-htKvPkndwAAAt8"], referer: www.google.com
[Mon Jul 20 06:06:05.105832 2026] [security2:error] [pid 796567:tid 796772] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al4PLbLfyzVz2SrjZpi7EQAAAl8"], referer: www.google.com
[Mon Jul 20 06:06:05.151623 2026] [security2:error] [pid 796928:tid 797118] [client 112.213.160.112:8232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknewAAAtU"]
[Mon Jul 20 06:06:05.151742 2026] [security2:error] [pid 796928:tid 797118] [client 112.213.160.112:8232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknewAAAtU"]
[Mon Jul 20 06:06:05.475198 2026] [security2:error] [pid 796928:tid 797154] [client 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/qywpeqnn.php"] [unique_id "al4PLesTy9vX-htKvPknkgAAAvk"], referer: www.google.com
[Mon Jul 20 06:06:05.574302 2026] [security2:error] [pid 796567:tid 796812] [client 185.242.3.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4PLbLfyzVz2SrjZpi7FgAAAoc"], referer: www.google.com
[Mon Jul 20 06:06:05.648125 2026] [security2:error] [pid 796928:tid 797073] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PLesTy9vX-htKvPknjQAAAqg"]
[Mon Jul 20 06:06:05.682283 2026] [security2:error] [pid 796928:tid 797156] [client 57.141.18.75:61098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmVwAC-3M"]
[Mon Jul 20 06:06:05.794919 2026] [security2:error] [pid 796928:tid 796984] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknqgAC9jc"]
[Mon Jul 20 06:06:05.795058 2026] [security2:error] [pid 796928:tid 797151] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PLesTy9vX-htKvPknqgAC9jc"]
[Mon Jul 20 06:06:05.817880 2026] [security2:error] [pid 796928:tid 796945] [remote 185.22.228.25:39552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.228.22.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PLesTy9vX-htKvPknqwACnhA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:05.840013 2026] [security2:error] [pid 796928:tid 797053] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/themes/seotheme/db.php"] [unique_id "al4PLesTy9vX-htKvPknrAACnXw"], referer: www.google.com
[Mon Jul 20 06:06:05.869235 2026] [access_compat:error] [pid 796567:tid 796715] [client 182.117.61.83:42044] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:05.933888 2026] [security2:error] [pid 796928:tid 796978] [remote 154.61.75.100:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PLesTy9vX-htKvPknsAADCDE"]
[Mon Jul 20 06:06:05.942353 2026] [security2:error] [pid 796928:tid 797066] [client 57.141.18.91:44348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKOsTy9vX-htKvPkmaQACoVs"]
[Mon Jul 20 06:06:05.997234 2026] [security2:error] [pid 796567:tid 796717] [client 185.132.186.73:49407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sodium_compat/index.php"] [unique_id "al4PLbLfyzVz2SrjZpi7PQAAAig"]
[Mon Jul 20 06:06:06.243158 2026] [security2:error] [pid 796928:tid 797032] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-plain.php"] [unique_id "al4PLusTy9vX-htKvPkntgACnGc"], referer: www.google.com
[Mon Jul 20 06:06:06.479207 2026] [security2:error] [pid 796928:tid 796983] [remote 154.61.75.100:58158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PLusTy9vX-htKvPknwwADAjY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:06.483001 2026] [security2:error] [pid 796567:tid 796762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PLbLfyzVz2SrjZpi7OAAAAlU"]
[Mon Jul 20 06:06:06.542896 2026] [security2:error] [pid 796928:tid 797148] [client 104.234.53.93:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PLusTy9vX-htKvPknxwAAAvM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:06.621863 2026] [security2:error] [pid 796567:tid 796809] [client 115.246.21.170:45565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PLrLfyzVz2SrjZpi7XQAAAoQ"]
[Mon Jul 20 06:06:06.623356 2026] [security2:error] [pid 796567:tid 796809] [client 115.246.21.170:45565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PLrLfyzVz2SrjZpi7XQAAAoQ"]
[Mon Jul 20 06:06:06.633048 2026] [security2:error] [pid 796567:tid 796628] [remote 91.142.222.105:44772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PLrLfyzVz2SrjZpi7XAACYzw"]
[Mon Jul 20 06:06:06.750421 2026] [security2:error] [pid 796928:tid 797033] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/vfmzhqxh.php"] [unique_id "al4PLusTy9vX-htKvPkn0wAC-Gg"], referer: www.google.com
[Mon Jul 20 06:06:07.063948 2026] [security2:error] [pid 796567:tid 796594] [remote 91.142.222.105:44772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PL7LfyzVz2SrjZpi7cQACcxo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:07.130534 2026] [security2:error] [pid 796928:tid 797180] [client 103.77.203.233:57018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn3gAAAxM"]
[Mon Jul 20 06:06:07.130661 2026] [security2:error] [pid 796928:tid 797180] [client 103.77.203.233:57018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn3gAAAxM"]
[Mon Jul 20 06:06:07.195455 2026] [security2:error] [pid 796567:tid 796775] [client 50.116.65.227:10462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PL7LfyzVz2SrjZpi7cwAAAmI"]
[Mon Jul 20 06:06:07.209279 2026] [security2:error] [pid 796567:tid 796816] [client 50.116.65.227:10464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PL7LfyzVz2SrjZpi7dAAAAos"]
[Mon Jul 20 06:06:07.261621 2026] [security2:error] [pid 796928:tid 796943] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn5gACuA4"]
[Mon Jul 20 06:06:07.261791 2026] [security2:error] [pid 796928:tid 797089] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PL-sTy9vX-htKvPkn5gACuA4"]
[Mon Jul 20 06:06:07.274867 2026] [security2:error] [pid 796928:tid 796947] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/apikey/apikey.php"] [unique_id "al4PL-sTy9vX-htKvPkn5wAC1BI"]
[Mon Jul 20 06:06:07.346113 2026] [security2:error] [pid 796928:tid 797064] [client 14.225.17.146:61019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4PLesTy9vX-htKvPknsQAAAp8"], referer: http://phillipbloch.com/Wordpress
[Mon Jul 20 06:06:07.487774 2026] [security2:error] [pid 796928:tid 797150] [client 57.141.18.41:64034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKesTy9vX-htKvPkmoQAC9W0"]
[Mon Jul 20 06:06:07.526758 2026] [security2:error] [pid 796928:tid 796942] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4PL-sTy9vX-htKvPkn-AAC-Q0"]
[Mon Jul 20 06:06:07.580827 2026] [security2:error] [pid 796928:tid 797179] [client 57.141.18.28:24432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkmsQADEig"]
[Mon Jul 20 06:06:07.743088 2026] [security2:error] [pid 796567:tid 796701] [client 27.96.94.195:38290] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PL7LfyzVz2SrjZpi7hwAAAhg"]
[Mon Jul 20 06:06:07.743219 2026] [security2:error] [pid 796567:tid 796701] [client 27.96.94.195:38290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PL7LfyzVz2SrjZpi7hwAAAhg"]
[Mon Jul 20 06:06:07.938279 2026] [security2:error] [pid 796567:tid 796781] [client 185.132.186.95:45189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/content.php"] [unique_id "al4PL7LfyzVz2SrjZpi7lAAAAmg"]
[Mon Jul 20 06:06:07.995023 2026] [security2:error] [pid 796928:tid 796948] [remote 57.141.18.17:27472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PKusTy9vX-htKvPkm5wADBxM"]
[Mon Jul 20 06:06:08.137057 2026] [security2:error] [pid 796928:tid 797093] [client 41.173.37.102:2270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBAAAArw"]
[Mon Jul 20 06:06:08.137539 2026] [security2:error] [pid 796928:tid 797093] [client 41.173.37.102:2270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBAAAArw"]
[Mon Jul 20 06:06:08.167224 2026] [security2:error] [pid 796928:tid 797061] [client 86.98.90.58:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBQAAApw"]
[Mon Jul 20 06:06:08.167377 2026] [security2:error] [pid 796928:tid 797061] [client 86.98.90.58:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBQAAApw"]
[Mon Jul 20 06:06:08.179758 2026] [security2:error] [pid 796567:tid 796577] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/apikey/apikey.php.suspected"] [unique_id "al4PMLLfyzVz2SrjZpi7pgACNQk"]
[Mon Jul 20 06:06:08.287570 2026] [security2:error] [pid 796928:tid 797153] [client 210.212.97.243:10447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBgAAAvg"]
[Mon Jul 20 06:06:08.287673 2026] [security2:error] [pid 796928:tid 797153] [client 210.212.97.243:10447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PMOsTy9vX-htKvPkoBgAAAvg"]
[Mon Jul 20 06:06:08.417918 2026] [security2:error] [pid 796928:tid 797050] [remote 57.141.18.98:56980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PK-sTy9vX-htKvPkm-wACoHk"]
[Mon Jul 20 06:06:08.831511 2026] [security2:error] [pid 796567:tid 796641] [remote 185.242.3.184:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.3.242.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/plugins/content/apismtp/apismtp.php.suspected"] [unique_id "al4PMLLfyzVz2SrjZpi73AACbUk"]
[Mon Jul 20 06:06:08.847194 2026] [security2:error] [pid 796567:tid 796743] [client 185.242.3.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4PMLLfyzVz2SrjZpi7ywAAAkI"], referer: www.google.com
[Mon Jul 20 06:06:09.171139 2026] [security2:error] [pid 796567:tid 796769] [client 14.225.17.146:49159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4PMLLfyzVz2SrjZpi7nAAAAlw"], referer: http://nikkidesigns.net/Wordpress
[Mon Jul 20 06:06:09.174413 2026] [security2:error] [pid 796567:tid 796815] [client 181.224.94.124:26510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi79wAAAoo"]
[Mon Jul 20 06:06:09.174561 2026] [security2:error] [pid 796567:tid 796815] [client 181.224.94.124:26510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi79wAAAoo"]
[Mon Jul 20 06:06:09.193871 2026] [security2:error] [pid 796567:tid 796582] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi7-gACbg4"]
[Mon Jul 20 06:06:09.194137 2026] [security2:error] [pid 796567:tid 796787] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PMbLfyzVz2SrjZpi7-gACbg4"]
[Mon Jul 20 06:06:09.252696 2026] [security2:error] [pid 796928:tid 796951] [remote 57.141.18.97:23198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PK-sTy9vX-htKvPknMQAC7RY"]
[Mon Jul 20 06:06:09.903013 2026] [security2:error] [pid 796567:tid 796727] [client 185.132.186.91:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/lv.php"] [unique_id "al4PMbLfyzVz2SrjZpi8MwAAAjI"]
[Mon Jul 20 06:06:10.736658 2026] [fcgid:warn] [pid 796567:tid 796706] (70014)End of file found: [client 66.132.172.198:57494] mod_fcgid: can't get data from http client
[Mon Jul 20 06:06:10.747185 2026] [security2:error] [pid 796928:tid 796962] [remote 57.141.18.2:63756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PLesTy9vX-htKvPknegACoyE"]
[Mon Jul 20 06:06:11.498485 2026] [security2:error] [pid 796567:tid 796736] [client 152.39.234.39:44005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8oAACOyo"], referer: https://www.savilerowtravel.com/perfectly-portugal/
[Mon Jul 20 06:06:11.516954 2026] [security2:error] [pid 796567:tid 796731] [client 104.234.53.67:33745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PM7LfyzVz2SrjZpi8pwAAAjY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:11.587682 2026] [security2:error] [pid 796567:tid 796700] [client 13.221.132.12:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4PMrLfyzVz2SrjZpi8agAAAhc"]
[Mon Jul 20 06:06:11.628470 2026] [security2:error] [pid 796567:tid 796796] [client 13.221.132.12:24152] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/limber-de-leche-milk-ice-pops/"] [unique_id "al4PMrLfyzVz2SrjZpi8ZQAAAnc"]
[Mon Jul 20 06:06:11.634052 2026] [security2:error] [pid 796567:tid 796726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8lAAAAjE"]
[Mon Jul 20 06:06:11.852030 2026] [security2:error] [pid 796567:tid 796782] [client 185.132.186.72:20331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/js1.php"] [unique_id "al4PM7LfyzVz2SrjZpi8ygAAAmk"]
[Mon Jul 20 06:06:11.994412 2026] [security2:error] [pid 796928:tid 796990] [remote 57.141.18.106:41234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PLusTy9vX-htKvPknxAACyj0"]
[Mon Jul 20 06:06:12.047055 2026] [security2:error] [pid 796567:tid 796764] [client 161.30.4.84:43938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.4.30.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/xmlrpc.php"] [unique_id "al4PM7LfyzVz2SrjZpi81AAAAlc"]
[Mon Jul 20 06:06:12.047233 2026] [security2:error] [pid 796567:tid 796764] [client 161.30.4.84:43938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "alaraycreative.com"] [uri "/xmlrpc.php"] [unique_id "al4PM7LfyzVz2SrjZpi81AAAAlc"]
[Mon Jul 20 06:06:12.181962 2026] [core:error] [pid 796567:tid 796739] [client 14.225.17.146:51011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:12.181986 2026] [core:error] [pid 796567:tid 796739] [client 14.225.17.146:51011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:12.225333 2026] [security2:error] [pid 796567:tid 796794] [client 57.141.18.22:59468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PLrLfyzVz2SrjZpi7ZAACdUo"]
[Mon Jul 20 06:06:12.554571 2026] [security2:error] [pid 796567:tid 796793] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi87gAAAnQ"]
[Mon Jul 20 06:06:12.767065 2026] [security2:error] [pid 796567:tid 796731] [client 43.172.196.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi9BgAAAjY"]
[Mon Jul 20 06:06:13.159889 2026] [security2:error] [pid 796567:tid 796705] [client 14.225.17.146:61657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8wQAAAhw"], referer: http://whiteoutcb.com/Wordpress
[Mon Jul 20 06:06:13.325486 2026] [security2:error] [pid 796567:tid 796797] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi9NAAAAng"]
[Mon Jul 20 06:06:13.595623 2026] [security2:error] [pid 796567:tid 796704] [client 57.141.18.47:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PL7LfyzVz2SrjZpi7jQACGy4"]
[Mon Jul 20 06:06:13.815448 2026] [security2:error] [pid 796567:tid 796729] [client 185.132.186.101:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/file.php"] [unique_id "al4PNbLfyzVz2SrjZpi9jAAAAjQ"]
[Mon Jul 20 06:06:13.892379 2026] [security2:error] [pid 796567:tid 796710] [client 14.225.17.146:62333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4PNbLfyzVz2SrjZpi9eQAAAiE"], referer: https://north-woods-engineering.com/Wordpress
[Mon Jul 20 06:06:14.122009 2026] [security2:error] [pid 796567:tid 796761] [client 14.225.17.146:63319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi82QAAAlQ"], referer: http://aberballet.co.uk/Wordpress
[Mon Jul 20 06:06:14.129797 2026] [security2:error] [pid 796567:tid 796759] [client 14.225.17.146:55420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4PNrLfyzVz2SrjZpi9pQAAAlI"], referer: http://thefriendlyspreadsheet.com/Wordpress
[Mon Jul 20 06:06:14.261139 2026] [security2:error] [pid 796567:tid 796753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNbLfyzVz2SrjZpi9igAAAkw"]
[Mon Jul 20 06:06:14.350273 2026] [security2:error] [pid 796567:tid 796783] [client 103.141.108.143:60490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi9xgAAAmo"]
[Mon Jul 20 06:06:14.350411 2026] [security2:error] [pid 796567:tid 796783] [client 103.141.108.143:60490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi9xgAAAmo"]
[Mon Jul 20 06:06:14.547758 2026] [security2:error] [pid 796567:tid 796720] [client 106.192.104.4:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91QAAAis"]
[Mon Jul 20 06:06:14.547886 2026] [security2:error] [pid 796567:tid 796720] [client 106.192.104.4:63353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91QAAAis"]
[Mon Jul 20 06:06:14.587108 2026] [security2:error] [pid 796567:tid 796723] [client 13.215.47.127:47346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91wAAAi4"]
[Mon Jul 20 06:06:14.587273 2026] [security2:error] [pid 796567:tid 796723] [client 13.215.47.127:47346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PNrLfyzVz2SrjZpi91wAAAi4"]
[Mon Jul 20 06:06:14.682040 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PNrLfyzVz2SrjZpi9zAAAAmY"]
[Mon Jul 20 06:06:14.688629 2026] [security2:error] [pid 796567:tid 796816] [client 57.141.18.40:51344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMLLfyzVz2SrjZpi76AACiww"]
[Mon Jul 20 06:06:15.150263 2026] [security2:error] [pid 796567:tid 796770] [client 150.228.148.150:27650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi9_gAAAl0"]
[Mon Jul 20 06:06:15.154056 2026] [security2:error] [pid 796567:tid 796770] [client 150.228.148.150:27650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi9_gAAAl0"]
[Mon Jul 20 06:06:15.284118 2026] [autoindex:error] [pid 796567:tid 796702] [client 167.86.107.171:57374] AH01276: Cannot serve directory /home4/yjgjjlmy/public_html/omrobuildingcenter/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:06:15.448232 2026] [security2:error] [pid 796567:tid 796613] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IQACJS0"]
[Mon Jul 20 06:06:15.448395 2026] [security2:error] [pid 796567:tid 796714] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IQACJS0"]
[Mon Jul 20 06:06:15.464873 2026] [security2:error] [pid 796567:tid 796822] [client 103.95.123.246:18630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IwAAApE"]
[Mon Jul 20 06:06:15.465573 2026] [security2:error] [pid 796567:tid 796822] [client 103.95.123.246:18630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-IwAAApE"]
[Mon Jul 20 06:06:15.490866 2026] [security2:error] [pid 796567:tid 796814] [client 57.141.18.84:55886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMbLfyzVz2SrjZpi8HAACiWw"]
[Mon Jul 20 06:06:15.612311 2026] [security2:error] [pid 796567:tid 796754] [client 57.141.18.78:29644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMbLfyzVz2SrjZpi8KAACTQQ"]
[Mon Jul 20 06:06:15.771156 2026] [security2:error] [pid 796567:tid 796706] [client 185.132.186.78:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "al4PN7LfyzVz2SrjZpi-QgAAAh0"]
[Mon Jul 20 06:06:15.853700 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PN7LfyzVz2SrjZpi-KwAAAmY"]
[Mon Jul 20 06:06:15.891333 2026] [security2:error] [pid 796567:tid 796644] [remote 154.120.133.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.133.120.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4PN7LfyzVz2SrjZpi-TQACREw"]
[Mon Jul 20 06:06:15.940912 2026] [security2:error] [pid 796567:tid 796769] [client 112.213.160.112:31041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-VAAAAlw"]
[Mon Jul 20 06:06:15.941009 2026] [security2:error] [pid 796567:tid 796769] [client 112.213.160.112:31041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PN7LfyzVz2SrjZpi-VAAAAlw"]
[Mon Jul 20 06:06:16.203436 2026] [security2:error] [pid 796567:tid 796749] [client 50.116.65.227:40950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4POLLfyzVz2SrjZpi-awAAAkg"]
[Mon Jul 20 06:06:16.214249 2026] [security2:error] [pid 796567:tid 796713] [client 50.116.65.227:40962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4POLLfyzVz2SrjZpi-bgAAAiQ"]
[Mon Jul 20 06:06:16.220149 2026] [security2:error] [pid 796567:tid 796737] [client 57.141.18.113:47536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PMrLfyzVz2SrjZpi8VgACPFU"]
[Mon Jul 20 06:06:16.239358 2026] [security2:error] [pid 796567:tid 796709] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PN7LfyzVz2SrjZpi-XwAAAiA"]
[Mon Jul 20 06:06:16.406569 2026] [security2:error] [pid 796567:tid 796819] [client 14.225.17.146:50797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4POLLfyzVz2SrjZpi-cAAAAo4"]
[Mon Jul 20 06:06:16.464065 2026] [security2:error] [pid 796567:tid 796635] [remote 154.120.133.86:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.133.120.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4POLLfyzVz2SrjZpi-hAACR0M"], referer: https://benbayly.co.nz/wp-login.php
[Mon Jul 20 06:06:16.652511 2026] [security2:error] [pid 796567:tid 796732] [client 158.173.166.181:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4POLLfyzVz2SrjZpi-igAAAjc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:17.025008 2026] [security2:error] [pid 796567:tid 796742] [client 57.141.18.22:59474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8pAACQVY"]
[Mon Jul 20 06:06:17.222434 2026] [security2:error] [pid 796567:tid 796796] [client 115.246.21.170:1099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-uQAAAnc"]
[Mon Jul 20 06:06:17.224041 2026] [security2:error] [pid 796567:tid 796796] [client 115.246.21.170:1099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-uQAAAnc"]
[Mon Jul 20 06:06:17.345291 2026] [security2:error] [pid 796567:tid 796755] [client 43.173.178.125:39972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4PObLfyzVz2SrjZpi-vwAAAk4"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.362615 2026] [security2:error] [pid 796567:tid 796806] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PObLfyzVz2SrjZpi-twAAAoE"]
[Mon Jul 20 06:06:17.543319 2026] [security2:error] [pid 796567:tid 796800] [client 57.141.18.89:33588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PM7LfyzVz2SrjZpi8zAACe2c"]
[Mon Jul 20 06:06:17.555264 2026] [security2:error] [pid 796567:tid 796793] [client 103.77.203.233:57077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-2QAAAnQ"]
[Mon Jul 20 06:06:17.555824 2026] [security2:error] [pid 796567:tid 796793] [client 103.77.203.233:57077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-2QAAAnQ"]
[Mon Jul 20 06:06:17.680020 2026] [core:error] [pid 796567:tid 796636] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.680044 2026] [core:error] [pid 796567:tid 796636] [remote 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.681940 2026] [security2:error] [pid 796567:tid 796753] [client 43.173.182.189:57748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4PObLfyzVz2SrjZpi-5QAAAkw"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.687772 2026] [core:error] [pid 796567:tid 796570] [remote 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.687790 2026] [core:error] [pid 796567:tid 796570] [remote 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.713659 2026] [security2:error] [pid 796567:tid 796729] [client 185.132.186.82:39539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "al4PObLfyzVz2SrjZpi-6wAAAjQ"]
[Mon Jul 20 06:06:17.719540 2026] [security2:error] [pid 796567:tid 796786] [client 43.172.196.174:37434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4PObLfyzVz2SrjZpi-5wAAAm0"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.728199 2026] [core:error] [pid 796567:tid 796626] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.728496 2026] [core:error] [pid 796567:tid 796626] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.774063 2026] [security2:error] [pid 796567:tid 796646] [remote 103.75.185.95:39606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-8AACYE4"]
[Mon Jul 20 06:06:17.774270 2026] [security2:error] [pid 796567:tid 796773] [client 103.75.185.95:39606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PObLfyzVz2SrjZpi-8AACYE4"]
[Mon Jul 20 06:06:17.777865 2026] [core:error] [pid 796567:tid 796634] [remote 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.777886 2026] [core:error] [pid 796567:tid 796634] [remote 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:17.819734 2026] [security2:error] [pid 796567:tid 796717] [client 50.116.65.227:11936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4PObLfyzVz2SrjZpi-_AAAAig"]
[Mon Jul 20 06:06:17.835556 2026] [security2:error] [pid 796567:tid 796780] [client 50.116.65.227:40996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4PObLfyzVz2SrjZpi-_QAAAik"]
[Mon Jul 20 06:06:17.956114 2026] [security2:error] [pid 796567:tid 796699] [client 43.173.181.77:51038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.181.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PObLfyzVz2SrjZpi_BwAAAhY"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:17.969140 2026] [security2:error] [pid 796567:tid 796597] [remote 5.161.225.162:47258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PObLfyzVz2SrjZpi_DwACgR0"]
[Mon Jul 20 06:06:17.982269 2026] [security2:error] [pid 796567:tid 796805] [client 43.173.182.221:48142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.182.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PObLfyzVz2SrjZpi_EAAAAoA"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:18.055446 2026] [security2:error] [pid 796567:tid 796656] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_EwACe1g"]
[Mon Jul 20 06:06:18.055656 2026] [security2:error] [pid 796567:tid 796800] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_EwACe1g"]
[Mon Jul 20 06:06:18.134177 2026] [security2:error] [pid 796567:tid 796747] [client 57.141.18.62:30914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PNLLfyzVz2SrjZpi88QACRmo"]
[Mon Jul 20 06:06:18.213410 2026] [security2:error] [pid 796567:tid 796637] [remote 5.161.225.162:47258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_HQACSEU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:06:18.226244 2026] [security2:error] [pid 796567:tid 796707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PObLfyzVz2SrjZpi-_gAAAh4"]
[Mon Jul 20 06:06:18.312080 2026] [security2:error] [pid 796567:tid 796717] [client 43.173.180.199:57562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4POrLfyzVz2SrjZpi_JgAAAig"], referer: https://www.savilerowtravel.com/jongomero-3-2/
[Mon Jul 20 06:06:18.428990 2026] [security2:error] [pid 796567:tid 796587] [remote 124.55.178.99:34162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_NwACfhM"]
[Mon Jul 20 06:06:18.613960 2026] [security2:error] [pid 796567:tid 796767] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4POrLfyzVz2SrjZpi_MgAAAlo"]
[Mon Jul 20 06:06:18.728599 2026] [security2:error] [pid 796567:tid 796771] [client 41.173.37.102:2727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_TQAAAl4"]
[Mon Jul 20 06:06:18.728704 2026] [security2:error] [pid 796567:tid 796771] [client 41.173.37.102:2727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_TQAAAl4"]
[Mon Jul 20 06:06:18.846222 2026] [security2:error] [pid 796567:tid 796725] [client 210.212.97.243:10448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_XAAAAjA"]
[Mon Jul 20 06:06:18.846382 2026] [security2:error] [pid 796567:tid 796725] [client 210.212.97.243:10448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4POrLfyzVz2SrjZpi_XAAAAjA"]
[Mon Jul 20 06:06:18.879784 2026] [security2:error] [pid 796567:tid 796680] [remote 124.55.178.99:34162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_XgACR3A"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:06:18.938858 2026] [security2:error] [pid 796567:tid 796625] [remote 124.55.178.99:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4POrLfyzVz2SrjZpi_ZgACiDk"]
[Mon Jul 20 06:06:19.031214 2026] [security2:error] [pid 796567:tid 796717] [client 178.152.178.232:35985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_bgAAAig"]
[Mon Jul 20 06:06:19.031333 2026] [security2:error] [pid 796567:tid 796717] [client 178.152.178.232:35985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_bgAAAig"]
[Mon Jul 20 06:06:19.050695 2026] [security2:error] [pid 796567:tid 796712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4POrLfyzVz2SrjZpi_WwAAAiM"]
[Mon Jul 20 06:06:19.315745 2026] [security2:error] [pid 796567:tid 796609] [remote 5.252.52.249:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PO7LfyzVz2SrjZpi_iwACgyk"]
[Mon Jul 20 06:06:19.366348 2026] [security2:error] [pid 796567:tid 796590] [remote 124.55.178.99:34174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PO7LfyzVz2SrjZpi_kgACJhY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:19.506774 2026] [security2:error] [pid 796567:tid 796796] [client 27.96.94.195:37763] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_nAAAAnc"]
[Mon Jul 20 06:06:19.506913 2026] [security2:error] [pid 796567:tid 796796] [client 27.96.94.195:37763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_nAAAAnc"]
[Mon Jul 20 06:06:19.512008 2026] [security2:error] [pid 796567:tid 796638] [remote 5.252.52.249:44406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PO7LfyzVz2SrjZpi_nQACIUY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:19.569303 2026] [security2:error] [pid 796567:tid 796779] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_hwAAAmY"]
[Mon Jul 20 06:06:19.657958 2026] [security2:error] [pid 796567:tid 796777] [client 185.132.186.85:60573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/autoload_classmap.php"] [unique_id "al4PO7LfyzVz2SrjZpi_owAAAmQ"]
[Mon Jul 20 06:06:19.724205 2026] [security2:error] [pid 796567:tid 796760] [client 181.224.94.124:55672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_pgAAAlM"]
[Mon Jul 20 06:06:19.724377 2026] [security2:error] [pid 796567:tid 796760] [client 181.224.94.124:55672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_pgAAAlM"]
[Mon Jul 20 06:06:19.851911 2026] [security2:error] [pid 796567:tid 796677] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_tgACMG0"]
[Mon Jul 20 06:06:19.852059 2026] [security2:error] [pid 796567:tid 796725] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PO7LfyzVz2SrjZpi_tgACMG0"]
[Mon Jul 20 06:06:19.870569 2026] [security2:error] [pid 796567:tid 796704] [client 14.225.17.146:54308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_rAAAAhs"], referer: http://daseighty.net/Wordpress
[Mon Jul 20 06:06:20.215437 2026] [security2:error] [pid 796567:tid 796811] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_qwAAAoY"]
[Mon Jul 20 06:06:20.343822 2026] [proxy:error] [pid 796567:tid 796804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:20.343881 2026] [proxy_http:error] [pid 796567:tid 796804] [client 198.235.24.147:59458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:20.344981 2026] [proxy:error] [pid 796567:tid 796804] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:20.345006 2026] [proxy_http:error] [pid 796567:tid 796804] [client 198.235.24.147:59458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:20.354816 2026] [security2:error] [pid 796567:tid 796603] [remote 182.77.62.24:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PPLLfyzVz2SrjZpi_4wACJiM"]
[Mon Jul 20 06:06:20.481050 2026] [security2:error] [pid 796567:tid 796784] [client 57.141.18.17:60240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PNrLfyzVz2SrjZpi96QACa2Q"]
[Mon Jul 20 06:06:20.485154 2026] [core:error] [pid 796567:tid 796643] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:20.485209 2026] [core:error] [pid 796567:tid 796643] [remote 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:20.869390 2026] [security2:error] [pid 796567:tid 796809] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PPLLfyzVz2SrjZpi_-QAAAoQ"]
[Mon Jul 20 06:06:20.887465 2026] [security2:error] [pid 796567:tid 796582] [remote 182.77.62.24:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PPLLfyzVz2SrjZpjACgAChw4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:06:21.076819 2026] [security2:error] [pid 796567:tid 796746] [client 86.98.90.58:60458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PPbLfyzVz2SrjZpjAGgAAAkU"]
[Mon Jul 20 06:06:21.077310 2026] [security2:error] [pid 796567:tid 796746] [client 86.98.90.58:60458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PPbLfyzVz2SrjZpjAGgAAAkU"]
[Mon Jul 20 06:06:21.189676 2026] [security2:error] [pid 796567:tid 796716] [client 43.173.173.32:36020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4PPbLfyzVz2SrjZpjAIwAAAic"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.199425 2026] [security2:error] [pid 796567:tid 796763] [client 43.173.179.57:60554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.179.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4PPbLfyzVz2SrjZpjAJAAAAlY"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.370570 2026] [security2:error] [pid 796567:tid 796780] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjAHAAAAmc"]
[Mon Jul 20 06:06:21.515432 2026] [security2:error] [pid 796567:tid 796749] [client 14.225.17.146:50095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjALwAAAkg"], referer: http://sarahsnyder.net/Wordpress
[Mon Jul 20 06:06:21.541728 2026] [security2:error] [pid 796567:tid 796797] [client 43.172.197.103:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4PPbLfyzVz2SrjZpjARgAAAng"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.609828 2026] [security2:error] [pid 796567:tid 796784] [client 185.132.186.62:45593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/wp-conflg.php"] [unique_id "al4PPbLfyzVz2SrjZpjAUAAAAms"]
[Mon Jul 20 06:06:21.652131 2026] [security2:error] [pid 796567:tid 796712] [client 43.172.196.207:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.196.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4PPbLfyzVz2SrjZpjAVQAAAiM"], referer: https://www.savilerowtravel.com/hotels/france/m-lodge-hotel-chalet-spa-a-saint-martin-de-belleville/
[Mon Jul 20 06:06:21.670051 2026] [security2:error] [pid 796567:tid 796597] [remote 192.241.143.148:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PPbLfyzVz2SrjZpjAVwACbh0"]
[Mon Jul 20 06:06:21.701469 2026] [security2:error] [pid 796567:tid 796772] [client 69.171.230.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rentorangegrove.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjARQAAAl8"]
[Mon Jul 20 06:06:21.837061 2026] [security2:error] [pid 796567:tid 796730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjAQgAAAjU"]
[Mon Jul 20 06:06:21.842085 2026] [security2:error] [pid 796567:tid 796651] [remote 192.241.143.148:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PPbLfyzVz2SrjZpjAZgACUFM"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:06:22.498825 2026] [security2:error] [pid 796567:tid 796780] [client 54.244.177.189:30926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4PPrLfyzVz2SrjZpjAlwAAAmc"]
[Mon Jul 20 06:06:22.539848 2026] [security2:error] [pid 796567:tid 796792] [client 14.225.17.146:61637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAjgAAAnM"], referer: https://sarahsnyder.net/Wordpress
[Mon Jul 20 06:06:22.693542 2026] [security2:error] [pid 796567:tid 796742] [client 23.251.146.115:13216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAnQACQU0"]
[Mon Jul 20 06:06:22.697927 2026] [security2:error] [pid 796567:tid 796773] [client 23.251.146.115:58432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAnwACYBQ"]
[Mon Jul 20 06:06:22.802218 2026] [security2:error] [pid 796567:tid 796769] [client 23.251.146.115:13216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjArQACXDk"]
[Mon Jul 20 06:06:22.803663 2026] [security2:error] [pid 796567:tid 796746] [client 23.251.146.115:58432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAsAACRSQ"]
[Mon Jul 20 06:06:22.960939 2026] [security2:error] [pid 796567:tid 796700] [client 57.141.18.2:64692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PObLfyzVz2SrjZpi-sAACF2M"]
[Mon Jul 20 06:06:22.969029 2026] [security2:error] [pid 796567:tid 796821] [client 45.157.112.60:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PPrLfyzVz2SrjZpjAwwAAApA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:23.056889 2026] [security2:error] [pid 796567:tid 796809] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PPrLfyzVz2SrjZpjAxAAAAoQ"]
[Mon Jul 20 06:06:23.072382 2026] [security2:error] [pid 796567:tid 796775] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PP7LfyzVz2SrjZpjAyAAAAmI"]
[Mon Jul 20 06:06:23.215883 2026] [security2:error] [pid 796567:tid 796594] [remote 8.217.108.67:57016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PP7LfyzVz2SrjZpjA1gACFho"]
[Mon Jul 20 06:06:23.556346 2026] [security2:error] [pid 796567:tid 796808] [client 185.132.186.99:53309] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "harborhealth.us"] [uri "/wp-admin/theme-editor.php"] [unique_id "al4PP7LfyzVz2SrjZpjA8QAAAoM"]
[Mon Jul 20 06:06:23.925978 2026] [security2:error] [pid 796567:tid 796790] [client 34.31.203.120:12944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PP7LfyzVz2SrjZpjBDgACcUg"]
[Mon Jul 20 06:06:23.926371 2026] [security2:error] [pid 796567:tid 796783] [client 103.153.183.69:1472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//var/www/html/config.php"] [unique_id "al4PP7LfyzVz2SrjZpjBGQAAAmo"], referer: https://twitter.com/
[Mon Jul 20 06:06:24.031226 2026] [security2:error] [pid 796567:tid 796595] [remote 173.249.4.11:21773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBLQACYxs"]
[Mon Jul 20 06:06:24.037145 2026] [security2:error] [pid 796567:tid 796771] [client 34.31.203.120:12944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PP7LfyzVz2SrjZpjBIQACXkk"]
[Mon Jul 20 06:06:24.047275 2026] [security2:error] [pid 796567:tid 796603] [remote 152.228.213.32:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBLgACiSM"]
[Mon Jul 20 06:06:24.067262 2026] [core:error] [pid 796567:tid 796730] [client 8.229.3.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:24.067291 2026] [core:error] [pid 796567:tid 796730] [client 8.229.3.76:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:24.254092 2026] [security2:error] [pid 796567:tid 796686] [remote 173.249.4.11:21773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBQQACbHY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:06:24.264056 2026] [security2:error] [pid 796567:tid 796607] [remote 152.228.213.32:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBRAACKyc"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:06:24.268046 2026] [security2:error] [pid 796567:tid 796578] [remote 216.73.217.138:27532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4PQLLfyzVz2SrjZpjBPwACRwo"]
[Mon Jul 20 06:06:24.293019 2026] [security2:error] [pid 796567:tid 796822] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PQLLfyzVz2SrjZpjBPgAAApE"]
[Mon Jul 20 06:06:24.352190 2026] [security2:error] [pid 796567:tid 796593] [remote 8.217.108.67:57016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBUAACMxk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:24.369385 2026] [security2:error] [pid 796567:tid 796639] [remote 152.228.213.32:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBVAACMkc"]
[Mon Jul 20 06:06:24.474988 2026] [security2:error] [pid 796567:tid 796801] [client 8.229.3.76:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.3.229.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "beta.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4PQLLfyzVz2SrjZpjBXQAAAnw"]
[Mon Jul 20 06:06:24.595916 2026] [security2:error] [pid 796567:tid 796664] [remote 152.228.213.32:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4PQLLfyzVz2SrjZpjBawACKmA"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:06:24.693952 2026] [security2:error] [pid 796567:tid 796769] [client 8.229.3.76:59126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4PQLLfyzVz2SrjZpjBdgAAAlw"]
[Mon Jul 20 06:06:24.701562 2026] [security2:error] [pid 796567:tid 796807] [client 104.234.53.48:62671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PQLLfyzVz2SrjZpjBbgAAAoI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:24.875626 2026] [security2:error] [pid 796567:tid 796788] [client 8.229.3.76:60685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4PQLLfyzVz2SrjZpjBigAAAm8"]
[Mon Jul 20 06:06:25.061158 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBngAAAiA"]
[Mon Jul 20 06:06:25.061468 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:60932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBngAAAiA"]
[Mon Jul 20 06:06:25.077184 2026] [security2:error] [pid 796567:tid 796655] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBmQACKFc"]
[Mon Jul 20 06:06:25.077456 2026] [security2:error] [pid 796567:tid 796717] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBmQACKFc"]
[Mon Jul 20 06:06:25.102641 2026] [security2:error] [pid 796567:tid 796795] [client 8.229.3.76:62023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjBpQAAAnY"]
[Mon Jul 20 06:06:25.114401 2026] [security2:error] [pid 796567:tid 796739] [client 106.192.104.4:63832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBqAAAAj4"]
[Mon Jul 20 06:06:25.114527 2026] [security2:error] [pid 796567:tid 796739] [client 106.192.104.4:63832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjBqAAAAj4"]
[Mon Jul 20 06:06:25.143594 2026] [security2:error] [pid 796567:tid 796651] [remote 192.241.143.148:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjBrQACilM"]
[Mon Jul 20 06:06:25.280687 2026] [security2:error] [pid 796567:tid 796718] [client 57.141.18.32:49594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PO7LfyzVz2SrjZpi_dAACKXM"]
[Mon Jul 20 06:06:25.301315 2026] [security2:error] [pid 796567:tid 796656] [remote 100.42.189.89:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjBtwACQ1g"]
[Mon Jul 20 06:06:25.304129 2026] [security2:error] [pid 796567:tid 796792] [client 8.229.3.76:56079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjBuAAAAnM"]
[Mon Jul 20 06:06:25.346698 2026] [security2:error] [pid 796567:tid 796657] [remote 192.241.143.148:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjBvgACSVk"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:06:25.456547 2026] [security2:error] [pid 796567:tid 796794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjBpwAAAnU"], referer: 1'"3000
[Mon Jul 20 06:06:25.509666 2026] [security2:error] [pid 796567:tid 796795] [client 185.132.186.53:23007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/abc.php"] [unique_id "al4PQbLfyzVz2SrjZpjB0AAAAnY"]
[Mon Jul 20 06:06:25.523563 2026] [security2:error] [pid 796567:tid 796690] [remote 100.42.189.89:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjB0gACgXo"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 06:06:25.540579 2026] [security2:error] [pid 796567:tid 796779] [client 8.229.3.76:61912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjB1AAAAmY"]
[Mon Jul 20 06:06:25.541199 2026] [security2:error] [pid 796567:tid 796775] [client 40.77.167.79:36379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjBywACYhM"]
[Mon Jul 20 06:06:25.727134 2026] [security2:error] [pid 796567:tid 796730] [client 8.229.3.76:50974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjB7wAAAjU"]
[Mon Jul 20 06:06:25.741951 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:9432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjB8AAAAmA"]
[Mon Jul 20 06:06:25.745610 2026] [security2:error] [pid 796567:tid 796736] [client 104.28.219.194:14358] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.dev.cira.org"] [uri "/.env"] [unique_id "al4PQbLfyzVz2SrjZpjB9gAAAjs"]
[Mon Jul 20 06:06:25.749741 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:9432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PQbLfyzVz2SrjZpjB8AAAAmA"]
[Mon Jul 20 06:06:25.903564 2026] [security2:error] [pid 796567:tid 796733] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjB5wAAAjg"], referer: 1'"3000
[Mon Jul 20 06:06:25.907604 2026] [security2:error] [pid 796567:tid 796808] [client 8.229.3.76:60002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4PQbLfyzVz2SrjZpjCCAAAAoM"]
[Mon Jul 20 06:06:25.950065 2026] [security2:error] [pid 796567:tid 796731] [client 114.119.128.233:42375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/robots.txt"] [unique_id "al4PQbLfyzVz2SrjZpjCDQAAAjY"], referer: http://www.sarakety.com/robots.txt
[Mon Jul 20 06:06:25.969933 2026] [security2:error] [pid 796567:tid 796625] [remote 167.233.114.32:36308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQbLfyzVz2SrjZpjCDwACKzk"]
[Mon Jul 20 06:06:26.051460 2026] [security2:error] [pid 796567:tid 796613] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCFQACZy0"]
[Mon Jul 20 06:06:26.051637 2026] [security2:error] [pid 796567:tid 796780] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCFQACZy0"]
[Mon Jul 20 06:06:26.070686 2026] [security2:error] [pid 796567:tid 796737] [client 50.116.65.227:19620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PQrLfyzVz2SrjZpjCGAAAAjw"]
[Mon Jul 20 06:06:26.080522 2026] [security2:error] [pid 796567:tid 796819] [client 50.116.65.227:19630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PQrLfyzVz2SrjZpjCGQAAAo4"]
[Mon Jul 20 06:06:26.175839 2026] [security2:error] [pid 796567:tid 796746] [client 8.229.3.76:60488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCMgAAAkU"]
[Mon Jul 20 06:06:26.256498 2026] [security2:error] [pid 796567:tid 796699] [client 188.161.209.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4PQbLfyzVz2SrjZpjCDAAAAhY"]
[Mon Jul 20 06:06:26.299458 2026] [security2:error] [pid 796567:tid 796629] [remote 167.233.114.32:36308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCOgACgD0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:06:26.300286 2026] [security2:error] [pid 796567:tid 796600] [remote 84.247.172.23:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCOQACYCA"]
[Mon Jul 20 06:06:26.373212 2026] [security2:error] [pid 796567:tid 796703] [client 8.229.3.76:52225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCRQAAAho"]
[Mon Jul 20 06:06:26.394914 2026] [security2:error] [pid 796567:tid 796807] [client 14.225.17.146:50587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCJgAAAoI"], referer: http://idigress.agency/Wordpress
[Mon Jul 20 06:06:26.414121 2026] [security2:error] [pid 796567:tid 796794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCMwAAAnU"], referer: 1'"3000
[Mon Jul 20 06:06:26.465347 2026] [security2:error] [pid 796567:tid 796590] [remote 95.217.78.234:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCSwACjBY"]
[Mon Jul 20 06:06:26.492331 2026] [security2:error] [pid 796567:tid 796644] [remote 84.247.172.23:52330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCTgACWEw"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:06:26.533031 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/feed/d1psu8ztljg3.php"] [unique_id "al4PQrLfyzVz2SrjZpjCVQAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:26.541700 2026] [security2:error] [pid 796567:tid 796751] [client 8.229.3.76:64774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCXAAAAko"]
[Mon Jul 20 06:06:26.628979 2026] [security2:error] [pid 796567:tid 796748] [client 103.95.123.246:19128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCZAAAAkc"]
[Mon Jul 20 06:06:26.629125 2026] [security2:error] [pid 796567:tid 796748] [client 103.95.123.246:19128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCZAAAAkc"]
[Mon Jul 20 06:06:26.665619 2026] [security2:error] [pid 796567:tid 796731] [client 112.213.160.112:8289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCaQAAAjY"]
[Mon Jul 20 06:06:26.666333 2026] [security2:error] [pid 796567:tid 796731] [client 112.213.160.112:8289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PQrLfyzVz2SrjZpjCaQAAAjY"]
[Mon Jul 20 06:06:26.707665 2026] [security2:error] [pid 796567:tid 796759] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCXgAAAlI"]
[Mon Jul 20 06:06:26.721467 2026] [security2:error] [pid 796567:tid 796653] [remote 95.217.78.234:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCcwACS1U"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:06:26.759795 2026] [security2:error] [pid 796567:tid 796819] [client 104.234.53.48:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCdgAAAo4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:26.822529 2026] [security2:error] [pid 796567:tid 796730] [client 8.229.3.76:55395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4PQrLfyzVz2SrjZpjCeAAAAjU"]
[Mon Jul 20 06:06:27.014585 2026] [security2:error] [pid 796567:tid 796660] [remote 72.167.132.114:42556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4PQrLfyzVz2SrjZpjCiwACGlw"]
[Mon Jul 20 06:06:27.044857 2026] [security2:error] [pid 796567:tid 796814] [client 8.229.3.76:59845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "beta.youpositive.co"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4PQ7LfyzVz2SrjZpjCjwAAAok"]
[Mon Jul 20 06:06:27.225353 2026] [security2:error] [pid 796567:tid 796786] [client 57.141.18.63:28832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PPbLfyzVz2SrjZpjAIQACbRE"]
[Mon Jul 20 06:06:27.253604 2026] [security2:error] [pid 796567:tid 796689] [remote 72.167.132.114:42556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCpAACMXk"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:06:27.333218 2026] [security2:error] [pid 796567:tid 796733] [client 77.110.127.138:55690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCVwAAAjg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.422946 2026] [security2:error] [pid 796567:tid 796818] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCYQAAAo0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.428588 2026] [security2:error] [pid 796567:tid 796749] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCbgAAAkg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.561776 2026] [security2:error] [pid 796567:tid 796736] [client 77.110.127.138:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/testimonials/mx47788438ef.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCzwAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.769774 2026] [security2:error] [pid 796567:tid 796708] [client 77.110.127.138:55662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCzQAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.771361 2026] [security2:error] [pid 796567:tid 796709] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC1gAAAiA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:27.822290 2026] [security2:error] [pid 796567:tid 796790] [client 115.246.21.170:33234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC5QAAAnE"]
[Mon Jul 20 06:06:27.822383 2026] [security2:error] [pid 796567:tid 796790] [client 115.246.21.170:33234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC5QAAAnE"]
[Mon Jul 20 06:06:27.842639 2026] [security2:error] [pid 796567:tid 796706] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjC1AAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.022425 2026] [security2:error] [pid 796567:tid 796791] [client 103.77.203.233:57137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PRLLfyzVz2SrjZpjC-QAAAnI"]
[Mon Jul 20 06:06:28.022537 2026] [security2:error] [pid 796567:tid 796791] [client 103.77.203.233:57137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PRLLfyzVz2SrjZpjC-QAAAnI"]
[Mon Jul 20 06:06:28.270129 2026] [security2:error] [pid 796567:tid 796783] [client 77.110.127.138:55695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/501/k81p0h0fcv2n.php"] [unique_id "al4PRLLfyzVz2SrjZpjDEQAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.358877 2026] [http2:info] [pid 832668:tid 832668] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:06:28.383969 2026] [security2:error] [pid 796567:tid 796817] [client 158.173.89.95:24119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PRLLfyzVz2SrjZpjDKQAAAow"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:28.487990 2026] [security2:error] [pid 796567:tid 796697] [client 77.110.127.138:55667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDEgAAAhQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.499556 2026] [security2:error] [pid 796567:tid 796728] [client 185.132.186.100:61739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/wonder.php"] [unique_id "al4PRLLfyzVz2SrjZpjDNAAAAjM"]
[Mon Jul 20 06:06:28.550921 2026] [security2:error] [pid 832668:tid 832672] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PRGci6KgEEltqA3C24gAAAQE"]
[Mon Jul 20 06:06:28.551086 2026] [security2:error] [pid 832668:tid 832801] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PRGci6KgEEltqA3C24gAAAQE"]
[Mon Jul 20 06:06:28.725120 2026] [security2:error] [pid 796567:tid 796774] [client 14.225.17.146:56305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDNQAAAmE"], referer: http://windowtx.com/Wordpress
[Mon Jul 20 06:06:28.795124 2026] [security2:error] [pid 796567:tid 796795] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDJwAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.833538 2026] [security2:error] [pid 796567:tid 796821] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRLLfyzVz2SrjZpjDJQAAApA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:06:28.950825 2026] [security2:error] [pid 832668:tid 832673] [remote 188.40.28.4:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRGci6KgEEltqA3C27AAAEAI"]
[Mon Jul 20 06:06:29.126897 2026] [security2:error] [pid 832668:tid 832805] [client 27.96.94.195:38281] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C28gAAAAU"]
[Mon Jul 20 06:06:29.127038 2026] [security2:error] [pid 832668:tid 832805] [client 27.96.94.195:38281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C28gAAAAU"]
[Mon Jul 20 06:06:29.157270 2026] [security2:error] [pid 832668:tid 832674] [remote 188.40.28.4:36396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRWci6KgEEltqA3C29QAALQM"], referer: https://vyx.sbv.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:29.329043 2026] [security2:error] [pid 796567:tid 796765] [client 210.212.97.243:10449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PRbLfyzVz2SrjZpjDYAAAAlg"]
[Mon Jul 20 06:06:29.329129 2026] [security2:error] [pid 832668:tid 832834] [client 41.173.37.102:3175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C2-AAAACI"]
[Mon Jul 20 06:06:29.329151 2026] [security2:error] [pid 796567:tid 796765] [client 210.212.97.243:10449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PRbLfyzVz2SrjZpjDYAAAAlg"]
[Mon Jul 20 06:06:29.329230 2026] [security2:error] [pid 832668:tid 832834] [client 41.173.37.102:3175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C2-AAAACI"]
[Mon Jul 20 06:06:29.474863 2026] [security2:error] [pid 832668:tid 832848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRWci6KgEEltqA3C29wAAADA"], referer: 1'"3000
[Mon Jul 20 06:06:29.556967 2026] [core:error] [pid 796567:tid 796730] [client 14.225.17.146:54549] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:29.556995 2026] [core:error] [pid 796567:tid 796730] [client 14.225.17.146:54549] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:29.691076 2026] [security2:error] [pid 832668:tid 832853] [client 178.152.178.232:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C3BwAAADU"]
[Mon Jul 20 06:06:29.691196 2026] [security2:error] [pid 832668:tid 832853] [client 178.152.178.232:37589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PRWci6KgEEltqA3C3BwAAADU"]
[Mon Jul 20 06:06:29.866878 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRbLfyzVz2SrjZpjDfgAAAl0"], referer: 1'"3000
[Mon Jul 20 06:06:29.926390 2026] [security2:error] [pid 796567:tid 796810] [client 14.225.17.146:52944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4PQ7LfyzVz2SrjZpjCvgAAAoU"], referer: http://fineartsfactory.net/Wordpress
[Mon Jul 20 06:06:30.015264 2026] [security2:error] [pid 796567:tid 796710] [client 57.141.18.124:20412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PQLLfyzVz2SrjZpjBUgACISw"]
[Mon Jul 20 06:06:30.264406 2026] [security2:error] [pid 832668:tid 832909] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3FAAAAG0"], referer: 1'"3000
[Mon Jul 20 06:06:30.295191 2026] [security2:error] [pid 796567:tid 796797] [client 181.224.94.124:10194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDpAAAAng"]
[Mon Jul 20 06:06:30.295336 2026] [security2:error] [pid 796567:tid 796797] [client 181.224.94.124:10194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDpAAAAng"]
[Mon Jul 20 06:06:30.327900 2026] [security2:error] [pid 832668:tid 832681] [remote 115.79.143.180:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3HAAAXwo"]
[Mon Jul 20 06:06:30.344930 2026] [security2:error] [pid 832668:tid 832922] [client 74.7.227.179:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3GwAAegg"], referer: https://tejasenvironmental.com/p=537057
[Mon Jul 20 06:06:30.375743 2026] [security2:error] [pid 832668:tid 832680] [remote 45.90.123.233:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3IAAAdQk"]
[Mon Jul 20 06:06:30.457420 2026] [security2:error] [pid 796567:tid 796707] [client 185.132.186.82:59625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/wonder.php"] [unique_id "al4PRrLfyzVz2SrjZpjDrQAAAh4"]
[Mon Jul 20 06:06:30.510894 2026] [security2:error] [pid 796567:tid 796667] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDrgACN2M"]
[Mon Jul 20 06:06:30.511087 2026] [security2:error] [pid 796567:tid 796732] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PRrLfyzVz2SrjZpjDrgACN2M"]
[Mon Jul 20 06:06:30.587393 2026] [security2:error] [pid 832668:tid 832683] [remote 45.90.123.233:38896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3KQAAGgw"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:30.753569 2026] [security2:error] [pid 832668:tid 832684] [remote 115.79.143.180:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4PRmci6KgEEltqA3C3LQAAKw0"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:06:30.789271 2026] [security2:error] [pid 832668:tid 832801] [client 14.225.17.146:56295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3KwAAAAE"], referer: http://mtlegnews.gov/Wordpress
[Mon Jul 20 06:06:31.225830 2026] [security2:error] [pid 832668:tid 832840] [client 14.225.17.146:54176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4PRmci6KgEEltqA3C3MAAAACg"], referer: http://webgardensbypaula.com/Wordpress
[Mon Jul 20 06:06:31.265761 2026] [security2:error] [pid 832668:tid 832880] [client 50.116.65.227:25470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/05/IMG_3889.jpeg"] [unique_id "al4PR2ci6KgEEltqA3C3PAAAAE8"]
[Mon Jul 20 06:06:31.787193 2026] [security2:error] [pid 796567:tid 796595] [remote 20.153.140.50:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PR7LfyzVz2SrjZpjD5gACZhs"]
[Mon Jul 20 06:06:31.929955 2026] [security2:error] [pid 796567:tid 796816] [client 104.234.53.47:29661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PR7LfyzVz2SrjZpjD7AAAAos"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:32.221464 2026] [security2:error] [pid 796567:tid 796614] [remote 20.153.140.50:60518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PSLLfyzVz2SrjZpjD_gACOC4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:06:32.401631 2026] [security2:error] [pid 796567:tid 796821] [client 86.98.90.58:61268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PSLLfyzVz2SrjZpjEBQAAApA"]
[Mon Jul 20 06:06:32.401745 2026] [security2:error] [pid 796567:tid 796821] [client 86.98.90.58:61268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PSLLfyzVz2SrjZpjEBQAAApA"]
[Mon Jul 20 06:06:32.409488 2026] [security2:error] [pid 796567:tid 796740] [client 185.132.186.99:21651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/fix/as.php"] [unique_id "al4PSLLfyzVz2SrjZpjECAAAAj8"]
[Mon Jul 20 06:06:32.469111 2026] [security2:error] [pid 796567:tid 796601] [remote 81.173.115.7:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PSLLfyzVz2SrjZpjECwACkiE"]
[Mon Jul 20 06:06:32.670125 2026] [security2:error] [pid 796567:tid 796659] [remote 81.173.115.7:33484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PSLLfyzVz2SrjZpjEEQACL1s"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:32.798765 2026] [security2:error] [pid 796567:tid 796812] [client 57.141.18.9:21934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PQrLfyzVz2SrjZpjCjAACh3U"]
[Mon Jul 20 06:06:33.017782 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PSLLfyzVz2SrjZpjEGwAAAnI"]
[Mon Jul 20 06:06:33.652318 2026] [security2:error] [pid 832668:tid 832894] [client 34.31.203.120:11712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PSWci6KgEEltqA3C3gwAAXhY"]
[Mon Jul 20 06:06:33.725026 2026] [security2:error] [pid 832668:tid 832896] [client 74.208.214.194:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PSWci6KgEEltqA3C3igAAAGA"]
[Mon Jul 20 06:06:34.358065 2026] [security2:error] [pid 796567:tid 796734] [client 185.132.186.76:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/tox.php"] [unique_id "al4PSrLfyzVz2SrjZpjEWwAAAjk"]
[Mon Jul 20 06:06:34.388150 2026] [security2:error] [pid 832668:tid 832699] [remote 117.0.21.154:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PSmci6KgEEltqA3C3nAAALhw"]
[Mon Jul 20 06:06:34.535688 2026] [security2:error] [pid 796567:tid 796715] [client 114.119.155.96:30633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fkconstructionfunding.com"] [uri "/projects"] [unique_id "al4PSrLfyzVz2SrjZpjEZQAAAiY"], referer: https://fkconstructionfunding.com/latest-news/
[Mon Jul 20 06:06:34.595030 2026] [security2:error] [pid 832668:tid 832702] [remote 72.167.132.114:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PSmci6KgEEltqA3C3qAAAJR8"]
[Mon Jul 20 06:06:34.758291 2026] [security2:error] [pid 832668:tid 832867] [client 34.31.203.120:11712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PSmci6KgEEltqA3C3rAAAQyE"]
[Mon Jul 20 06:06:34.795746 2026] [security2:error] [pid 796567:tid 796658] [remote 157.66.26.183:33546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PSrLfyzVz2SrjZpjEcgACdVo"]
[Mon Jul 20 06:06:34.811534 2026] [security2:error] [pid 832668:tid 832814] [client 196.251.121.187:55385] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.fansarogroup.com"] [uri "/"] [unique_id "al4PSmci6KgEEltqA3C3sgAAAA4"]
[Mon Jul 20 06:06:34.895362 2026] [security2:error] [pid 832668:tid 832890] [client 74.208.214.194:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PSmci6KgEEltqA3C3tgAAAFo"]
[Mon Jul 20 06:06:34.976957 2026] [security2:error] [pid 832668:tid 832707] [remote 72.167.132.114:42572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PSmci6KgEEltqA3C3uQAAdiQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:06:35.094309 2026] [security2:error] [pid 796567:tid 796709] [client 14.225.17.146:63670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4PSbLfyzVz2SrjZpjELAAAAiA"], referer: http://oldracelimited.com/Wordpress
[Mon Jul 20 06:06:35.209006 2026] [security2:error] [pid 832668:tid 832709] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PS2ci6KgEEltqA3C3xAAAJiY"]
[Mon Jul 20 06:06:35.209157 2026] [security2:error] [pid 832668:tid 832838] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PS2ci6KgEEltqA3C3xAAAJiY"]
[Mon Jul 20 06:06:35.293563 2026] [security2:error] [pid 796567:tid 796609] [remote 157.66.26.183:33546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PS7LfyzVz2SrjZpjEigACFik"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:35.874222 2026] [security2:error] [pid 796567:tid 796760] [client 103.141.108.143:61378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PS7LfyzVz2SrjZpjEqQAAAlM"]
[Mon Jul 20 06:06:35.874354 2026] [security2:error] [pid 832668:tid 832710] [remote 173.249.4.11:28345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4PS2ci6KgEEltqA3C3zQAAFic"]
[Mon Jul 20 06:06:35.874413 2026] [security2:error] [pid 796567:tid 796760] [client 103.141.108.143:61378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PS7LfyzVz2SrjZpjEqQAAAlM"]
[Mon Jul 20 06:06:36.054737 2026] [security2:error] [pid 796567:tid 796739] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4PS7LfyzVz2SrjZpjEtwAAAj4"]
[Mon Jul 20 06:06:36.105816 2026] [security2:error] [pid 796567:tid 796738] [client 106.192.104.4:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjExAAAAj0"]
[Mon Jul 20 06:06:36.105937 2026] [security2:error] [pid 796567:tid 796738] [client 106.192.104.4:64333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjExAAAAj0"]
[Mon Jul 20 06:06:36.106064 2026] [security2:error] [pid 796567:tid 796708] [client 104.234.53.54:45689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PTLLfyzVz2SrjZpjEwQAAAh8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:36.255487 2026] [security2:error] [pid 796567:tid 796695] [remote 162.19.86.63:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PTLLfyzVz2SrjZpjEywACJ38"]
[Mon Jul 20 06:06:36.284916 2026] [lsapi:warn] [pid 796567:tid 796644] [remote 198.143.19.78:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://ali-alghanim.net/
[Mon Jul 20 06:06:36.318328 2026] [security2:error] [pid 796567:tid 796721] [client 185.132.186.92:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/index.php"] [unique_id "al4PTLLfyzVz2SrjZpjEzgAAAiw"]
[Mon Jul 20 06:06:36.375549 2026] [security2:error] [pid 832668:tid 832715] [remote 117.0.21.154:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C32gAAaSw"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:06:36.445667 2026] [security2:error] [pid 832668:tid 832717] [remote 173.249.4.11:28345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C33gAATy4"], referer: https://bigwormfishing.com/wp-login.php
[Mon Jul 20 06:06:36.446352 2026] [security2:error] [pid 832668:tid 832716] [remote 5.161.225.162:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C33AAAFy0"]
[Mon Jul 20 06:06:36.457791 2026] [security2:error] [pid 796567:tid 796692] [remote 162.19.86.63:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PTLLfyzVz2SrjZpjE1gACenw"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:06:36.501426 2026] [security2:error] [pid 796567:tid 796740] [client 150.228.148.150:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjE2AAAAj8"]
[Mon Jul 20 06:06:36.511662 2026] [security2:error] [pid 796567:tid 796740] [client 150.228.148.150:50898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PTLLfyzVz2SrjZpjE2AAAAj8"]
[Mon Jul 20 06:06:36.653903 2026] [security2:error] [pid 832668:tid 832914] [client 94.154.43.188:20998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.rrf.lcd.mybluehost.me"] [uri "/.env"] [unique_id "al4PTGci6KgEEltqA3C35AAAAHI"]
[Mon Jul 20 06:06:36.735251 2026] [security2:error] [pid 832668:tid 832720] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PTGci6KgEEltqA3C35gAAEzE"]
[Mon Jul 20 06:06:36.735429 2026] [security2:error] [pid 832668:tid 832819] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PTGci6KgEEltqA3C35gAAEzE"]
[Mon Jul 20 06:06:36.833530 2026] [security2:error] [pid 832668:tid 832884] [client 104.234.53.51:54135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PTGci6KgEEltqA3C37AAAAFQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:36.903298 2026] [security2:error] [pid 832668:tid 832818] [client 14.225.17.146:65026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4PTGci6KgEEltqA3C36QAAABI"], referer: http://thechancersband.com/Wordpress
[Mon Jul 20 06:06:36.990879 2026] [security2:error] [pid 832668:tid 832721] [remote 5.161.225.162:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4PTGci6KgEEltqA3C38wAAKDI"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:06:37.094104 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.107:35240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PR2ci6KgEEltqA3C3OwAATnw"]
[Mon Jul 20 06:06:37.257119 2026] [security2:error] [pid 832668:tid 832913] [client 161.118.195.148:49989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-login.php"] [unique_id "al4PTWci6KgEEltqA3C3-AAAAHE"]
[Mon Jul 20 06:06:37.402239 2026] [security2:error] [pid 832668:tid 832899] [client 112.213.160.112:31112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4AQAAAGM"]
[Mon Jul 20 06:06:37.402429 2026] [security2:error] [pid 832668:tid 832899] [client 112.213.160.112:31112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4AQAAAGM"]
[Mon Jul 20 06:06:37.714464 2026] [security2:error] [pid 832668:tid 832902] [client 103.95.123.246:19607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4EwAAAGY"]
[Mon Jul 20 06:06:37.715084 2026] [security2:error] [pid 832668:tid 832902] [client 103.95.123.246:19607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PTWci6KgEEltqA3C4EwAAAGY"]
[Mon Jul 20 06:06:37.730603 2026] [security2:error] [pid 796567:tid 796736] [client 52.109.124.141:35779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PTbLfyzVz2SrjZpjFCAAAAjs"]
[Mon Jul 20 06:06:37.911281 2026] [security2:error] [pid 796567:tid 796806] [client 52.109.124.141:35779] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PTbLfyzVz2SrjZpjFFAAAAoE"]
[Mon Jul 20 06:06:38.051203 2026] [security2:error] [pid 832668:tid 832827] [client 89.124.113.107:65335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-comments-post.php"] [unique_id "al4PTmci6KgEEltqA3C4GAAAABs"], referer: https://retzkolonglogistics.com/hello-world/
[Mon Jul 20 06:06:38.051324 2026] [security2:error] [pid 832668:tid 832827] [client 89.124.113.107:65335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/wp-comments-post.php"] [unique_id "al4PTmci6KgEEltqA3C4GAAAABs"], referer: https://retzkolonglogistics.com/hello-world/
[Mon Jul 20 06:06:38.133129 2026] [security2:error] [pid 796567:tid 796758] [client 57.141.18.51:42002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PSLLfyzVz2SrjZpjEBgACUWc"]
[Mon Jul 20 06:06:38.299645 2026] [security2:error] [pid 796567:tid 796786] [client 161.118.195.148:50443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PTrLfyzVz2SrjZpjFJAAAAm0"]
[Mon Jul 20 06:06:38.343056 2026] [security2:error] [pid 832668:tid 832878] [client 52.109.16.52:12353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PTmci6KgEEltqA3C4JgAAAE4"]
[Mon Jul 20 06:06:38.392259 2026] [security2:error] [pid 832668:tid 832917] [client 52.109.16.52:12353] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PTmci6KgEEltqA3C4KAAAAHU"]
[Mon Jul 20 06:06:38.498547 2026] [security2:error] [pid 832668:tid 832850] [client 115.246.21.170:42116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PTmci6KgEEltqA3C4LQAAADI"]
[Mon Jul 20 06:06:38.498661 2026] [security2:error] [pid 832668:tid 832850] [client 115.246.21.170:42116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PTmci6KgEEltqA3C4LQAAADI"]
[Mon Jul 20 06:06:38.525876 2026] [security2:error] [pid 796567:tid 796702] [client 103.77.203.233:57195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PTrLfyzVz2SrjZpjFOAAAAhk"]
[Mon Jul 20 06:06:38.526138 2026] [security2:error] [pid 796567:tid 796702] [client 103.77.203.233:57195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PTrLfyzVz2SrjZpjFOAAAAhk"]
[Mon Jul 20 06:06:38.558675 2026] [security2:error] [pid 796567:tid 796771] [client 185.132.186.91:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/dist/default.php"] [unique_id "al4PTrLfyzVz2SrjZpjFOgAAAl4"]
[Mon Jul 20 06:06:38.748758 2026] [security2:error] [pid 796567:tid 796777] [client 57.141.18.46:22102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PSLLfyzVz2SrjZpjEHAACZE4"]
[Mon Jul 20 06:06:38.876404 2026] [security2:error] [pid 796567:tid 796721] [client 161.118.195.148:51168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4PTrLfyzVz2SrjZpjFRgAAAiw"]
[Mon Jul 20 06:06:39.061059 2026] [security2:error] [pid 832668:tid 832919] [client 104.234.53.94:55031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PT2ci6KgEEltqA3C4PgAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:39.255740 2026] [security2:error] [pid 796567:tid 796630] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFVgACWj4"]
[Mon Jul 20 06:06:39.255950 2026] [security2:error] [pid 796567:tid 796767] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFVgACWj4"]
[Mon Jul 20 06:06:39.453121 2026] [security2:error] [pid 796567:tid 796822] [client 161.118.195.148:51525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4PT7LfyzVz2SrjZpjFYAAAApE"]
[Mon Jul 20 06:06:39.477191 2026] [security2:error] [pid 832668:tid 832901] [client 57.141.18.56:20926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PSWci6KgEEltqA3C3fAAAZRU"]
[Mon Jul 20 06:06:39.915734 2026] [security2:error] [pid 832668:tid 832891] [client 210.212.97.243:10450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PT2ci6KgEEltqA3C4XAAAAFs"]
[Mon Jul 20 06:06:39.915846 2026] [security2:error] [pid 832668:tid 832891] [client 210.212.97.243:10450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PT2ci6KgEEltqA3C4XAAAAFs"]
[Mon Jul 20 06:06:39.926179 2026] [security2:error] [pid 796567:tid 796787] [client 41.173.37.102:3613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFcQAAAm4"]
[Mon Jul 20 06:06:39.926251 2026] [security2:error] [pid 796567:tid 796787] [client 41.173.37.102:3613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PT7LfyzVz2SrjZpjFcQAAAm4"]
[Mon Jul 20 06:06:40.203928 2026] [security2:error] [pid 832668:tid 832814] [client 14.225.17.146:52937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4PTmci6KgEEltqA3C4JQAAAA4"], referer: http://narv.co/Wordpress
[Mon Jul 20 06:06:40.294147 2026] [security2:error] [pid 832668:tid 832899] [client 178.152.178.232:37467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PUGci6KgEEltqA3C4bwAAAGM"]
[Mon Jul 20 06:06:40.294316 2026] [security2:error] [pid 832668:tid 832899] [client 178.152.178.232:37467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PUGci6KgEEltqA3C4bwAAAGM"]
[Mon Jul 20 06:06:40.429188 2026] [security2:error] [pid 796567:tid 796801] [client 27.96.94.195:38204] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFgwAAAnw"]
[Mon Jul 20 06:06:40.429310 2026] [security2:error] [pid 796567:tid 796801] [client 27.96.94.195:38204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFgwAAAnw"]
[Mon Jul 20 06:06:40.500239 2026] [security2:error] [pid 796567:tid 796800] [client 185.132.186.65:34745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/tfileman.php"] [unique_id "al4PULLfyzVz2SrjZpjFhgAAAns"]
[Mon Jul 20 06:06:40.745838 2026] [security2:error] [pid 832668:tid 832910] [client 57.141.18.59:36732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PS2ci6KgEEltqA3C3uwAAbiU"]
[Mon Jul 20 06:06:40.818217 2026] [security2:error] [pid 796567:tid 796706] [client 181.224.94.124:60138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFlwAAAh0"]
[Mon Jul 20 06:06:40.818357 2026] [security2:error] [pid 796567:tid 796706] [client 181.224.94.124:60138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PULLfyzVz2SrjZpjFlwAAAh0"]
[Mon Jul 20 06:06:40.831161 2026] [security2:error] [pid 832668:tid 832895] [client 161.118.195.148:51915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/version.php"] [unique_id "al4PUGci6KgEEltqA3C4iAAAAF8"]
[Mon Jul 20 06:06:40.847783 2026] [security2:error] [pid 832668:tid 832875] [client 14.225.17.146:62998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4PUGci6KgEEltqA3C4hgAAAEs"], referer: http://omenana.com/Wordpress
[Mon Jul 20 06:06:41.159325 2026] [security2:error] [pid 796567:tid 796611] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFrwACNis"]
[Mon Jul 20 06:06:41.159527 2026] [security2:error] [pid 796567:tid 796731] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFrwACNis"]
[Mon Jul 20 06:06:41.199669 2026] [security2:error] [pid 796567:tid 796701] [client 14.225.17.146:64089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4PUbLfyzVz2SrjZpjFqAAAAhg"], referer: https://narv.co/Wordpress
[Mon Jul 20 06:06:41.268114 2026] [core:error] [pid 796567:tid 796738] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:41.268154 2026] [core:error] [pid 796567:tid 796738] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:06:41.343926 2026] [security2:error] [pid 832668:tid 832750] [remote 81.173.115.7:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4PUWci6KgEEltqA3C4lwAAWk8"]
[Mon Jul 20 06:06:41.370199 2026] [security2:error] [pid 796567:tid 796584] [remote 188.138.102.156:33624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFuAAChBA"]
[Mon Jul 20 06:06:41.370349 2026] [security2:error] [pid 796567:tid 796809] [client 188.138.102.156:33624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PUbLfyzVz2SrjZpjFuAAChBA"]
[Mon Jul 20 06:06:41.409676 2026] [security2:error] [pid 796567:tid 796772] [client 161.118.195.148:52979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/functions.php"] [unique_id "al4PUbLfyzVz2SrjZpjFugAAAl8"]
[Mon Jul 20 06:06:41.555329 2026] [security2:error] [pid 832668:tid 832751] [remote 81.173.115.7:49042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4PUWci6KgEEltqA3C4nAAAd1A"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:06:41.680322 2026] [security2:error] [pid 832668:tid 832845] [client 207.46.13.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4PUGci6KgEEltqA3C4dAAAAC0"]
[Mon Jul 20 06:06:41.989852 2026] [security2:error] [pid 796567:tid 796794] [client 161.118.195.148:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4PUbLfyzVz2SrjZpjF0wAAAnU"]
[Mon Jul 20 06:06:42.449829 2026] [security2:error] [pid 832668:tid 832827] [client 185.132.186.77:37871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/tiny.php"] [unique_id "al4PUmci6KgEEltqA3C4sgAAABs"]
[Mon Jul 20 06:06:42.566468 2026] [security2:error] [pid 832668:tid 832866] [client 161.118.195.148:53705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/option.php"] [unique_id "al4PUmci6KgEEltqA3C4uAAAAEI"]
[Mon Jul 20 06:06:42.995881 2026] [security2:error] [pid 832668:tid 832834] [client 104.234.53.77:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PUmci6KgEEltqA3C4zQAAACI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:43.142572 2026] [security2:error] [pid 832668:tid 832813] [client 161.118.195.148:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/post.php"] [unique_id "al4PU2ci6KgEEltqA3C41wAAAA0"]
[Mon Jul 20 06:06:43.244558 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.63:49706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PTWci6KgEEltqA3C4EQAALjk"]
[Mon Jul 20 06:06:43.495875 2026] [security2:error] [pid 832668:tid 832826] [client 86.98.90.58:62082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PU2ci6KgEEltqA3C44QAAABo"]
[Mon Jul 20 06:06:43.496272 2026] [security2:error] [pid 832668:tid 832826] [client 86.98.90.58:62082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PU2ci6KgEEltqA3C44QAAABo"]
[Mon Jul 20 06:06:43.713663 2026] [security2:error] [pid 796567:tid 796796] [client 161.118.195.148:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-includes/user.php"] [unique_id "al4PU7LfyzVz2SrjZpjGEAAAAnc"]
[Mon Jul 20 06:06:44.092816 2026] [security2:error] [pid 832668:tid 832771] [remote 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4PVGci6KgEEltqA3C4-QAAHWQ"]
[Mon Jul 20 06:06:44.302846 2026] [security2:error] [pid 832668:tid 832773] [remote 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4PVGci6KgEEltqA3C5AAAAA2Y"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:06:44.390489 2026] [security2:error] [pid 796567:tid 796778] [client 185.132.186.77:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/autoload_classmap.php"] [unique_id "al4PVLLfyzVz2SrjZpjGJQAAAmU"]
[Mon Jul 20 06:06:44.481347 2026] [security2:error] [pid 796567:tid 796705] [client 14.225.17.146:55155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4PVLLfyzVz2SrjZpjGJwAAAhw"], referer: http://momheadquarters.com/Wordpress
[Mon Jul 20 06:06:45.139648 2026] [security2:error] [pid 832668:tid 832861] [client 57.141.18.2:38486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PT2ci6KgEEltqA3C4TgAAPUQ"]
[Mon Jul 20 06:06:45.722025 2026] [security2:error] [pid 832668:tid 832784] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PVWci6KgEEltqA3C5PQAAIHE"]
[Mon Jul 20 06:06:45.722182 2026] [security2:error] [pid 832668:tid 832832] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PVWci6KgEEltqA3C5PQAAIHE"]
[Mon Jul 20 06:06:46.226759 2026] [security2:error] [pid 796567:tid 796724] [client 14.225.17.146:55274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PVLLfyzVz2SrjZpjGOgAAAi8"]
[Mon Jul 20 06:06:46.347298 2026] [security2:error] [pid 832668:tid 832839] [client 185.132.186.88:45721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/themes.php"] [unique_id "al4PVmci6KgEEltqA3C5TwAAACc"]
[Mon Jul 20 06:06:46.373510 2026] [security2:error] [pid 796567:tid 796648] [remote 72.167.132.114:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PVrLfyzVz2SrjZpjGfAACj1A"]
[Mon Jul 20 06:06:46.499129 2026] [security2:error] [pid 796567:tid 796717] [client 14.225.17.146:58560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4PVrLfyzVz2SrjZpjGcAAAAig"], referer: http://transparentservices.online/Wordpress
[Mon Jul 20 06:06:46.613458 2026] [security2:error] [pid 832668:tid 832905] [client 106.192.104.4:64809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PVmci6KgEEltqA3C5XAAAAGk"]
[Mon Jul 20 06:06:46.613556 2026] [security2:error] [pid 832668:tid 832905] [client 106.192.104.4:64809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PVmci6KgEEltqA3C5XAAAAGk"]
[Mon Jul 20 06:06:46.635188 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:61813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PVrLfyzVz2SrjZpjGigAAAiA"]
[Mon Jul 20 06:06:46.635398 2026] [security2:error] [pid 796567:tid 796709] [client 103.141.108.143:61813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PVrLfyzVz2SrjZpjGigAAAiA"]
[Mon Jul 20 06:06:46.641929 2026] [security2:error] [pid 796567:tid 796633] [remote 72.167.132.114:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PVrLfyzVz2SrjZpjGiQACiUE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:06:46.992007 2026] [security2:error] [pid 832668:tid 832787] [remote 57.141.18.40:61816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4PVmci6KgEEltqA3C5ZAAAenQ"]
[Mon Jul 20 06:06:47.002968 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:35476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGngAAAmA"]
[Mon Jul 20 06:06:47.011039 2026] [security2:error] [pid 796567:tid 796773] [client 150.228.148.150:35476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGngAAAmA"]
[Mon Jul 20 06:06:47.039972 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:56197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4PVWci6KgEEltqA3C5NgAAAFE"], referer: http://xp-design.co/Wordpress
[Mon Jul 20 06:06:47.224196 2026] [security2:error] [pid 832668:tid 832914] [client 161.118.195.148:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "new-menus.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4PV2ci6KgEEltqA3C5bAAAAHI"]
[Mon Jul 20 06:06:47.303268 2026] [security2:error] [pid 832668:tid 832808] [client 14.225.17.146:54644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4PV2ci6KgEEltqA3C5aAAAAAg"], referer: http://floorsourcestock.com/Wordpress
[Mon Jul 20 06:06:47.330066 2026] [security2:error] [pid 832668:tid 832919] [client 14.225.17.146:57724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4PVWci6KgEEltqA3C5OwAAAHc"], referer: http://secretkeynumerology.com/Wordpress
[Mon Jul 20 06:06:47.392041 2026] [security2:error] [pid 796567:tid 796603] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGtwACbSM"]
[Mon Jul 20 06:06:47.392226 2026] [security2:error] [pid 796567:tid 796786] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PV7LfyzVz2SrjZpjGtwACbSM"]
[Mon Jul 20 06:06:47.441336 2026] [security2:error] [pid 796567:tid 796769] [client 4.194.217.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/nine2code.php"] [unique_id "al4PV7LfyzVz2SrjZpjGwAAAAlw"]
[Mon Jul 20 06:06:47.505639 2026] [security2:error] [pid 832668:tid 832868] [client 187.16.187.247:59554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.187.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atozgroup.biz"] [uri "/xmlrpc.php"] [unique_id "al4PV2ci6KgEEltqA3C5bwAAAEQ"]
[Mon Jul 20 06:06:47.505833 2026] [security2:error] [pid 832668:tid 832868] [client 187.16.187.247:59554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "atozgroup.biz"] [uri "/xmlrpc.php"] [unique_id "al4PV2ci6KgEEltqA3C5bwAAAEQ"]
[Mon Jul 20 06:06:47.591817 2026] [security2:error] [pid 796567:tid 796702] [client 160.30.136.8:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PV7LfyzVz2SrjZpjGyAAAAhk"]
[Mon Jul 20 06:06:47.711702 2026] [security2:error] [pid 832668:tid 832901] [client 57.141.18.19:24758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PUmci6KgEEltqA3C4owAAZVE"]
[Mon Jul 20 06:06:47.922113 2026] [security2:error] [pid 832668:tid 832826] [client 103.153.183.69:32516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../app/.env"] [unique_id "al4PV2ci6KgEEltqA3C5fwAAABo"], referer: https://www.reddit.com/
[Mon Jul 20 06:06:47.982694 2026] [security2:error] [pid 832668:tid 832905] [client 160.30.136.8:64201] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4PV2ci6KgEEltqA3C5hgAAAGk"]
[Mon Jul 20 06:06:48.014411 2026] [security2:error] [pid 796567:tid 796568] [remote 38.242.157.30:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PWLLfyzVz2SrjZpjG2QACHwA"]
[Mon Jul 20 06:06:48.018824 2026] [security2:error] [pid 796567:tid 796719] [client 4.194.217.15:1648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/num.php"] [unique_id "al4PWLLfyzVz2SrjZpjG3AAAAio"]
[Mon Jul 20 06:06:48.125629 2026] [security2:error] [pid 796567:tid 796790] [client 14.225.17.146:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4PVrLfyzVz2SrjZpjGkQAAAnE"], referer: http://cloudspacesgroup.com/Wordpress
[Mon Jul 20 06:06:48.164093 2026] [security2:error] [pid 832668:tid 832902] [client 112.213.160.112:8356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5jAAAAGY"]
[Mon Jul 20 06:06:48.164221 2026] [security2:error] [pid 832668:tid 832902] [client 112.213.160.112:8356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5jAAAAGY"]
[Mon Jul 20 06:06:48.275337 2026] [security2:error] [pid 832668:tid 832819] [client 185.132.186.67:63301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-themes.php"] [unique_id "al4PWGci6KgEEltqA3C5kAAAABM"]
[Mon Jul 20 06:06:48.337735 2026] [security2:error] [pid 832668:tid 832852] [client 14.225.17.146:53809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4PWGci6KgEEltqA3C5jgAAADQ"], referer: https://secretkeynumerology.com/Wordpress
[Mon Jul 20 06:06:48.388846 2026] [security2:error] [pid 832668:tid 832804] [client 160.30.136.8:62767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWGci6KgEEltqA3C5lwAAAAQ"]
[Mon Jul 20 06:06:48.412724 2026] [security2:error] [pid 796567:tid 796615] [remote 38.242.157.30:60012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PWLLfyzVz2SrjZpjG7gACgi8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:06:48.534363 2026] [security2:error] [pid 832668:tid 832832] [client 103.153.183.69:32516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../srv/.env"] [unique_id "al4PWGci6KgEEltqA3C5oAAAACA"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:06:48.572038 2026] [security2:error] [pid 796567:tid 796808] [client 4.194.217.15:12499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4PWLLfyzVz2SrjZpjG_wAAAoM"]
[Mon Jul 20 06:06:48.621006 2026] [security2:error] [pid 796567:tid 796760] [client 14.225.17.146:58557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4PVrLfyzVz2SrjZpjGcgAAAlM"], referer: http://onewingpictures.com/Wordpress
[Mon Jul 20 06:06:48.621276 2026] [security2:error] [pid 832668:tid 832895] [client 103.95.123.246:20096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5pQAAAF8"]
[Mon Jul 20 06:06:48.621455 2026] [security2:error] [pid 832668:tid 832895] [client 103.95.123.246:20096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PWGci6KgEEltqA3C5pQAAAF8"]
[Mon Jul 20 06:06:48.654910 2026] [security2:error] [pid 796567:tid 796731] [client 46.110.96.34:13506] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4PWLLfyzVz2SrjZpjHCwAAAjY"]
[Mon Jul 20 06:06:48.798990 2026] [security2:error] [pid 832668:tid 832842] [client 160.30.136.8:64975] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4PWGci6KgEEltqA3C5qwAAACo"]
[Mon Jul 20 06:06:49.003096 2026] [security2:error] [pid 796567:tid 796738] [client 103.77.203.233:57257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHIwAAAj0"]
[Mon Jul 20 06:06:49.003231 2026] [security2:error] [pid 796567:tid 796738] [client 103.77.203.233:57257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHIwAAAj0"]
[Mon Jul 20 06:06:49.058927 2026] [security2:error] [pid 832668:tid 832798] [remote 130.185.118.215:37612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PWWci6KgEEltqA3C5tgAAMX8"]
[Mon Jul 20 06:06:49.110803 2026] [security2:error] [pid 796567:tid 796746] [client 115.246.21.170:5091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHLgAAAkU"]
[Mon Jul 20 06:06:49.110897 2026] [security2:error] [pid 796567:tid 796746] [client 115.246.21.170:5091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PWbLfyzVz2SrjZpjHLgAAAkU"]
[Mon Jul 20 06:06:49.120356 2026] [security2:error] [pid 796567:tid 796726] [client 4.194.217.15:5376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/option.php"] [unique_id "al4PWbLfyzVz2SrjZpjHLwAAAjE"]
[Mon Jul 20 06:06:49.217043 2026] [security2:error] [pid 832668:tid 832836] [client 160.30.136.8:64450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWWci6KgEEltqA3C5ugAAACQ"]
[Mon Jul 20 06:06:49.298300 2026] [security2:error] [pid 796567:tid 796751] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PWbLfyzVz2SrjZpjHMwAAAko"]
[Mon Jul 20 06:06:49.318887 2026] [security2:error] [pid 832668:tid 832672] [remote 130.185.118.215:37612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4PWWci6KgEEltqA3C5vAAASAE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:06:49.633964 2026] [security2:error] [pid 796567:tid 796804] [client 160.30.136.8:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWbLfyzVz2SrjZpjHSAAAAn8"]
[Mon Jul 20 06:06:49.662315 2026] [security2:error] [pid 832668:tid 832890] [client 4.194.217.15:10012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/p.php"] [unique_id "al4PWWci6KgEEltqA3C5ywAAAFo"]
[Mon Jul 20 06:06:49.994020 2026] [security2:error] [pid 832668:tid 832674] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PWWci6KgEEltqA3C53AAADQM"]
[Mon Jul 20 06:06:49.994218 2026] [security2:error] [pid 832668:tid 832813] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PWWci6KgEEltqA3C53AAADQM"]
[Mon Jul 20 06:06:50.037584 2026] [security2:error] [pid 832668:tid 832906] [client 160.30.136.8:64065] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4PWmci6KgEEltqA3C54AAAAGo"]
[Mon Jul 20 06:06:50.151398 2026] [security2:error] [pid 832668:tid 832828] [client 103.153.183.69:23634] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//proc/self/environ"] [unique_id "al4PWmci6KgEEltqA3C54wAAABw"], referer: https://twitter.com/
[Mon Jul 20 06:06:50.207079 2026] [security2:error] [pid 832668:tid 832839] [client 185.132.186.64:22343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sodium_compat/src/index.php"] [unique_id "al4PWmci6KgEEltqA3C55QAAACc"]
[Mon Jul 20 06:06:50.268886 2026] [security2:error] [pid 832668:tid 832841] [client 4.194.217.15:6853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/past.php"] [unique_id "al4PWmci6KgEEltqA3C56gAAACk"]
[Mon Jul 20 06:06:50.272930 2026] [security2:error] [pid 796567:tid 796782] [client 193.19.109.219:32867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4PWrLfyzVz2SrjZpjHYQAAAmk"]
[Mon Jul 20 06:06:50.394184 2026] [security2:error] [pid 832668:tid 832679] [remote 20.173.88.122:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4PWmci6KgEEltqA3C57wAAAwg"]
[Mon Jul 20 06:06:50.441897 2026] [security2:error] [pid 796567:tid 796727] [client 210.212.97.243:10451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHaAAAAjI"]
[Mon Jul 20 06:06:50.442006 2026] [security2:error] [pid 796567:tid 796727] [client 210.212.97.243:10451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHaAAAAjI"]
[Mon Jul 20 06:06:50.490541 2026] [security2:error] [pid 796567:tid 796697] [client 98.159.234.160:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PWrLfyzVz2SrjZpjHbgAAAhQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:06:50.610154 2026] [security2:error] [pid 796567:tid 796716] [client 41.173.37.102:4065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHdAAAAic"]
[Mon Jul 20 06:06:50.610287 2026] [security2:error] [pid 796567:tid 796716] [client 41.173.37.102:4065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PWrLfyzVz2SrjZpjHdAAAAic"]
[Mon Jul 20 06:06:50.642395 2026] [security2:error] [pid 796567:tid 796754] [client 14.225.17.146:57433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4PWrLfyzVz2SrjZpjHZQAAAk0"], referer: http://massagelacey.com/Wordpress
[Mon Jul 20 06:06:50.723257 2026] [security2:error] [pid 832668:tid 832678] [remote 20.173.88.122:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4PWmci6KgEEltqA3C6AQAAKwc"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 06:06:50.809884 2026] [security2:error] [pid 832668:tid 832845] [client 4.194.217.15:9820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/php.php"] [unique_id "al4PWmci6KgEEltqA3C6BAAAAC0"]
[Mon Jul 20 06:06:50.810700 2026] [security2:error] [pid 832668:tid 832909] [client 114.119.133.250:33599] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/wp-content/uploads/2019/10/6-Presentation-Exterior-Entry-View-2-700x559.jpg"] [unique_id "al4PWmci6KgEEltqA3C6BQAAAG0"], referer: https://mourgroup.com/portfolio/cafe-sevilla/
[Mon Jul 20 06:06:51.011441 2026] [security2:error] [pid 832668:tid 832684] [remote 20.153.140.50:41106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PWmci6KgEEltqA3C6DQAARg0"]
[Mon Jul 20 06:06:51.351936 2026] [security2:error] [pid 796567:tid 796774] [client 181.224.94.124:51838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PW7LfyzVz2SrjZpjHlQAAAmE"]
[Mon Jul 20 06:06:51.352075 2026] [security2:error] [pid 796567:tid 796774] [client 181.224.94.124:51838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PW7LfyzVz2SrjZpjHlQAAAmE"]
[Mon Jul 20 06:06:51.352233 2026] [security2:error] [pid 796567:tid 796781] [client 4.194.217.15:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/php8.php"] [unique_id "al4PW7LfyzVz2SrjZpjHlAAAAmg"]
[Mon Jul 20 06:06:51.426291 2026] [security2:error] [pid 832668:tid 832689] [remote 20.153.140.50:41106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PW2ci6KgEEltqA3C6GQAAeBI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:06:51.500848 2026] [security2:error] [pid 796567:tid 796808] [client 14.225.17.146:55666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4PW7LfyzVz2SrjZpjHnAAAAoM"], referer: http://travelbyfire.com/Wordpress
[Mon Jul 20 06:06:51.514203 2026] [security2:error] [pid 796567:tid 796796] [client 57.141.18.72:21092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PVbLfyzVz2SrjZpjGWQACdwg"]
[Mon Jul 20 06:06:51.517626 2026] [security2:error] [pid 832668:tid 832922] [client 14.225.17.146:57256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4PWWci6KgEEltqA3C52QAAAHo"], referer: http://ironcitywellness.com/Wordpress
[Mon Jul 20 06:06:51.771959 2026] [security2:error] [pid 832668:tid 832688] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PW2ci6KgEEltqA3C6KwAAaBE"]
[Mon Jul 20 06:06:51.772224 2026] [security2:error] [pid 832668:tid 832904] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PW2ci6KgEEltqA3C6KwAAaBE"]
[Mon Jul 20 06:06:51.859088 2026] [security2:error] [pid 832668:tid 832927] [client 14.225.17.146:55849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4PWmci6KgEEltqA3C57QAAAH8"], referer: http://colinkeyphotography.com/Wordpress
[Mon Jul 20 06:06:51.891310 2026] [security2:error] [pid 796567:tid 796809] [client 4.194.217.15:10037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/phpinfo.php"] [unique_id "al4PW7LfyzVz2SrjZpjHrAAAAoQ"]
[Mon Jul 20 06:06:51.960781 2026] [security2:error] [pid 796567:tid 796760] [client 14.225.17.146:56219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4PWrLfyzVz2SrjZpjHXwAAAlM"], referer: http://superiorcopywriting.com/Wordpress
[Mon Jul 20 06:06:52.100243 2026] [security2:error] [pid 832668:tid 832694] [remote 18.61.192.253:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-login.php"] [unique_id "al4PXGci6KgEEltqA3C6OgAAfBc"]
[Mon Jul 20 06:06:52.167112 2026] [security2:error] [pid 832668:tid 832895] [client 185.132.186.61:48347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/erinyani/asasx.php"] [unique_id "al4PXGci6KgEEltqA3C6PAAAAF8"]
[Mon Jul 20 06:06:52.395465 2026] [security2:error] [pid 796567:tid 796754] [client 14.225.17.146:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4PXLLfyzVz2SrjZpjHuQAAAk0"], referer: https://travelbyfire.com/Wordpress
[Mon Jul 20 06:06:52.482522 2026] [security2:error] [pid 796567:tid 796773] [client 178.152.178.232:36217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PXLLfyzVz2SrjZpjHwQAAAmA"]
[Mon Jul 20 06:06:52.482640 2026] [security2:error] [pid 796567:tid 796773] [client 178.152.178.232:36217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PXLLfyzVz2SrjZpjHwQAAAmA"]
[Mon Jul 20 06:06:52.533421 2026] [security2:error] [pid 832668:tid 832804] [client 14.225.17.146:49158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4PW2ci6KgEEltqA3C6DgAAAAQ"]
[Mon Jul 20 06:06:52.606520 2026] [security2:error] [pid 832668:tid 832759] [remote 18.61.192.253:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-login.php"] [unique_id "al4PXGci6KgEEltqA3C6hwAAflg"], referer: https://retzkolonglogistics.com/wp-login.php
[Mon Jul 20 06:06:52.819811 2026] [security2:error] [pid 796567:tid 796717] [client 50.116.65.227:12064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PXLLfyzVz2SrjZpjH0QAAAig"]
[Mon Jul 20 06:06:52.830067 2026] [security2:error] [pid 796567:tid 796775] [client 50.116.65.227:12076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PXLLfyzVz2SrjZpjH0gAAAmI"]
[Mon Jul 20 06:06:52.862049 2026] [security2:error] [pid 796567:tid 796626] [remote 45.90.123.233:58570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4PXLLfyzVz2SrjZpjH0wACPzo"]
[Mon Jul 20 06:06:53.048008 2026] [security2:error] [pid 796567:tid 796774] [client 193.19.109.226:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4PXbLfyzVz2SrjZpjH2QAAAmE"]
[Mon Jul 20 06:06:53.051841 2026] [security2:error] [pid 796567:tid 796659] [remote 45.90.123.233:58570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4PXbLfyzVz2SrjZpjH2wACLFs"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:06:53.080732 2026] [security2:error] [pid 832668:tid 832910] [client 193.37.33.6:39491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4PXWci6KgEEltqA3C6ngAAAG4"]
[Mon Jul 20 06:06:53.093549 2026] [security2:error] [pid 832668:tid 832890] [client 193.19.109.216:37947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4PXWci6KgEEltqA3C6oQAAAFo"]
[Mon Jul 20 06:06:53.180163 2026] [security2:error] [pid 796567:tid 796808] [client 193.19.109.217:61715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4PXbLfyzVz2SrjZpjH3gAAAoM"]
[Mon Jul 20 06:06:53.289693 2026] [security2:error] [pid 832668:tid 832893] [client 50.116.65.227:12052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4PXGci6KgEEltqA3C6hgAAAF0"]
[Mon Jul 20 06:06:53.302456 2026] [security2:error] [pid 832668:tid 832851] [client 52.140.101.203:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PXWci6KgEEltqA3C6sQAAADM"]
[Mon Jul 20 06:06:53.365420 2026] [security2:error] [pid 832668:tid 832810] [client 50.116.65.227:12094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PXWci6KgEEltqA3C6qAAAAAo"]
[Mon Jul 20 06:06:53.453898 2026] [security2:error] [pid 832668:tid 832826] [client 52.183.195.200:30022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PXWci6KgEEltqA3C6tAAAABo"]
[Mon Jul 20 06:06:53.481088 2026] [security2:error] [pid 832668:tid 832830] [client 52.183.195.200:30022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PXWci6KgEEltqA3C6uwAAAB4"]
[Mon Jul 20 06:06:53.533887 2026] [security2:error] [pid 832668:tid 832889] [client 52.140.101.203:15621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PXWci6KgEEltqA3C6wAAAAFk"]
[Mon Jul 20 06:06:53.550058 2026] [security2:error] [pid 832668:tid 832858] [client 50.116.65.227:12108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PXWci6KgEEltqA3C6swAAADo"]
[Mon Jul 20 06:06:53.611836 2026] [security2:error] [pid 832668:tid 832864] [client 14.225.17.146:57609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4PXWci6KgEEltqA3C6vQAAAEA"], referer: http://koaconsultants.com/Wordpress
[Mon Jul 20 06:06:53.742982 2026] [security2:error] [pid 832668:tid 832848] [client 4.194.217.15:6586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/post.php"] [unique_id "al4PXWci6KgEEltqA3C6ywAAADA"]
[Mon Jul 20 06:06:53.955910 2026] [security2:error] [pid 796567:tid 796697] [client 50.116.65.227:12106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4PXbLfyzVz2SrjZpjH5gAAAhQ"]
[Mon Jul 20 06:06:54.117486 2026] [security2:error] [pid 796567:tid 796708] [client 185.132.186.83:50815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/mariju.php"] [unique_id "al4PXrLfyzVz2SrjZpjH_QAAAh8"]
[Mon Jul 20 06:06:54.286052 2026] [security2:error] [pid 832668:tid 832811] [client 4.194.217.15:12603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4PXmci6KgEEltqA3C64AAAAAs"]
[Mon Jul 20 06:06:54.408002 2026] [security2:error] [pid 796567:tid 796663] [remote 47.86.33.52:8166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PXrLfyzVz2SrjZpjIDAACgF8"]
[Mon Jul 20 06:06:54.408199 2026] [security2:error] [pid 796567:tid 796805] [client 47.86.33.52:8166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PXrLfyzVz2SrjZpjIDAACgF8"]
[Mon Jul 20 06:06:54.503670 2026] [security2:error] [pid 832668:tid 832922] [client 50.116.65.227:12114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PXmci6KgEEltqA3C65wAAAHo"]
[Mon Jul 20 06:06:54.514300 2026] [security2:error] [pid 832668:tid 832815] [client 50.116.65.227:12116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PXmci6KgEEltqA3C66AAAAA8"]
[Mon Jul 20 06:06:54.591910 2026] [security2:error] [pid 796567:tid 796666] [remote 5.161.225.162:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PXrLfyzVz2SrjZpjIEwACHmI"]
[Mon Jul 20 06:06:54.839359 2026] [security2:error] [pid 796567:tid 796740] [client 4.194.217.15:1443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/public/css.php"] [unique_id "al4PXrLfyzVz2SrjZpjIKAAAAj8"]
[Mon Jul 20 06:06:55.086568 2026] [security2:error] [pid 796567:tid 796721] [client 14.225.17.146:57936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4PXrLfyzVz2SrjZpjILgAAAiw"], referer: http://nextlvlmarketingco.com/Wordpress
[Mon Jul 20 06:06:55.381316 2026] [security2:error] [pid 832668:tid 832823] [client 4.194.217.15:7472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/r.php"] [unique_id "al4PX2ci6KgEEltqA3C7AQAAABc"]
[Mon Jul 20 06:06:55.504379 2026] [security2:error] [pid 832668:tid 832819] [client 14.225.17.146:57384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C62gAAABM"], referer: http://blaizeaccountingservices.com/Wordpress
[Mon Jul 20 06:06:55.762521 2026] [security2:error] [pid 796567:tid 796767] [client 57.141.18.69:63256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PWbLfyzVz2SrjZpjHOAACWhU"]
[Mon Jul 20 06:06:55.775639 2026] [security2:error] [pid 832668:tid 832873] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PX2ci6KgEEltqA3C7DAAAAEk"]
[Mon Jul 20 06:06:55.953589 2026] [security2:error] [pid 796567:tid 796753] [client 4.194.217.15:12606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/radio.php"] [unique_id "al4PX7LfyzVz2SrjZpjIVwAAAkw"]
[Mon Jul 20 06:06:55.979048 2026] [security2:error] [pid 832668:tid 832794] [remote 42.200.84.61:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4PX2ci6KgEEltqA3C7GgAAd3s"]
[Mon Jul 20 06:06:56.070051 2026] [security2:error] [pid 832668:tid 832841] [client 185.132.186.70:48829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/waf_defender.php"] [unique_id "al4PYGci6KgEEltqA3C7GwAAACk"]
[Mon Jul 20 06:06:56.317703 2026] [security2:error] [pid 832668:tid 832798] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PYGci6KgEEltqA3C7JgAAJ38"]
[Mon Jul 20 06:06:56.317848 2026] [security2:error] [pid 832668:tid 832839] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PYGci6KgEEltqA3C7JgAAJ38"]
[Mon Jul 20 06:06:56.321780 2026] [security2:error] [pid 832668:tid 832842] [client 14.225.17.146:57875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C68gAAACo"], referer: http://alexsandbergmusic.com/Wordpress
[Mon Jul 20 06:06:56.343464 2026] [security2:error] [pid 796567:tid 796771] [client 57.141.18.69:63268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PWbLfyzVz2SrjZpjHWAACXjk"]
[Mon Jul 20 06:06:56.370232 2026] [security2:error] [pid 832668:tid 832672] [remote 42.200.84.61:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4PYGci6KgEEltqA3C7KgAAIQE"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:06:56.387395 2026] [security2:error] [pid 832668:tid 832813] [client 14.225.17.146:57622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C68AAAAA0"], referer: http://nwcarvingacademy.com/Wordpress
[Mon Jul 20 06:06:56.416532 2026] [proxy:error] [pid 796567:tid 796726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:56.416624 2026] [proxy_http:error] [pid 796567:tid 796726] [client 195.96.139.207:53473] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:56.417667 2026] [proxy:error] [pid 796567:tid 796726] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:06:56.417704 2026] [proxy_http:error] [pid 796567:tid 796726] [client 195.96.139.207:53473] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:06:56.502080 2026] [security2:error] [pid 832668:tid 832907] [client 4.194.217.15:1421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/randkeyword.php7"] [unique_id "al4PYGci6KgEEltqA3C7LgAAAGs"]
[Mon Jul 20 06:06:57.049112 2026] [security2:error] [pid 832668:tid 832827] [client 14.225.17.146:56510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4PX2ci6KgEEltqA3C7DgAAABs"], referer: http://hammadownenterprises.com/Wordpress
[Mon Jul 20 06:06:57.067584 2026] [security2:error] [pid 796567:tid 796817] [client 4.194.217.15:7433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/readme.php"] [unique_id "al4PYbLfyzVz2SrjZpjIhwAAAow"]
[Mon Jul 20 06:06:57.156743 2026] [security2:error] [pid 832668:tid 832857] [client 57.141.18.103:58100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PWmci6KgEEltqA3C6BgAAOQw"]
[Mon Jul 20 06:06:57.436342 2026] [security2:error] [pid 796567:tid 796779] [client 103.141.108.143:62262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjImgAAAmY"]
[Mon Jul 20 06:06:57.436426 2026] [security2:error] [pid 796567:tid 796779] [client 103.141.108.143:62262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjImgAAAmY"]
[Mon Jul 20 06:06:57.459275 2026] [security2:error] [pid 832668:tid 832815] [client 14.225.17.146:54864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4PYWci6KgEEltqA3C7UwAAAA8"], referer: https://nwcarvingacademy.com/Wordpress
[Mon Jul 20 06:06:57.506620 2026] [security2:error] [pid 796567:tid 796768] [client 14.225.17.146:57670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4PX7LfyzVz2SrjZpjINQAAAls"], referer: http://adastra.love/Wordpress
[Mon Jul 20 06:06:57.593314 2026] [security2:error] [pid 796567:tid 796739] [client 150.228.148.150:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIogAAAj4"]
[Mon Jul 20 06:06:57.595133 2026] [security2:error] [pid 796567:tid 796745] [client 106.192.104.4:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIowAAAkQ"]
[Mon Jul 20 06:06:57.601039 2026] [security2:error] [pid 796567:tid 796739] [client 150.228.148.150:20467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIogAAAj4"]
[Mon Jul 20 06:06:57.604661 2026] [security2:error] [pid 796567:tid 796745] [client 106.192.104.4:65304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PYbLfyzVz2SrjZpjIowAAAkQ"]
[Mon Jul 20 06:06:57.610286 2026] [security2:error] [pid 796567:tid 796738] [client 4.194.217.15:9263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/reze.php"] [unique_id "al4PYbLfyzVz2SrjZpjIpAAAAj0"]
[Mon Jul 20 06:06:57.663494 2026] [security2:error] [pid 796567:tid 796593] [remote 5.252.52.249:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4PYbLfyzVz2SrjZpjIpgACOxk"]
[Mon Jul 20 06:06:57.679503 2026] [security2:error] [pid 796567:tid 796614] [remote 5.161.225.162:38680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4PYbLfyzVz2SrjZpjIqAACGy4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:06:57.755935 2026] [security2:error] [pid 832668:tid 832680] [remote 5.252.52.249:37646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4PYWci6KgEEltqA3C7aAAAJgk"]
[Mon Jul 20 06:06:57.904187 2026] [security2:error] [pid 796567:tid 796694] [remote 5.252.52.249:37630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4PYbLfyzVz2SrjZpjIrQACLn4"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 06:06:57.976979 2026] [security2:error] [pid 832668:tid 832678] [remote 5.252.52.249:37646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4PYWci6KgEEltqA3C7cQAAPgc"], referer: https://dnsplumbing.com/wp-login.php
[Mon Jul 20 06:06:58.015501 2026] [security2:error] [pid 832668:tid 832827] [client 185.132.186.60:31697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/cong.php"] [unique_id "al4PYmci6KgEEltqA3C7cwAAABs"]
[Mon Jul 20 06:06:58.028283 2026] [security2:error] [pid 832668:tid 832682] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7dQAAZAs"]
[Mon Jul 20 06:06:58.028399 2026] [security2:error] [pid 832668:tid 832900] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7dQAAZAs"]
[Mon Jul 20 06:06:58.036348 2026] [security2:error] [pid 832668:tid 832684] [remote 20.153.140.50:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eframiproperties.com"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7dAAAIw0"]
[Mon Jul 20 06:06:58.101019 2026] [security2:error] [pid 832668:tid 832828] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PYWci6KgEEltqA3C7bAAAABw"]
[Mon Jul 20 06:06:58.154511 2026] [security2:error] [pid 832668:tid 832921] [client 4.194.217.15:4754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/rh.php"] [unique_id "al4PYmci6KgEEltqA3C7gwAAAHk"]
[Mon Jul 20 06:06:58.176869 2026] [access_compat:error] [pid 832668:tid 832816] [client 183.47.107.78:56397] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:58.253462 2026] [security2:error] [pid 832668:tid 832689] [remote 188.40.28.4:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7hQAAGhI"]
[Mon Jul 20 06:06:58.364791 2026] [security2:error] [pid 832668:tid 832800] [client 14.225.17.146:55033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PYmci6KgEEltqA3C7hAAAAAA"], referer: http://fkconstructionfunding.com/Wordpress
[Mon Jul 20 06:06:58.437129 2026] [security2:error] [pid 832668:tid 832686] [remote 20.153.140.50:60124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eframiproperties.com"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7kAAAHw8"], referer: https://eframiproperties.com/wp-login.php
[Mon Jul 20 06:06:58.463011 2026] [security2:error] [pid 832668:tid 832688] [remote 188.40.28.4:39534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4PYmci6KgEEltqA3C7kgAAXRE"], referer: https://thslogistics.net/wp-login.php
[Mon Jul 20 06:06:58.464438 2026] [security2:error] [pid 796567:tid 796716] [client 104.234.53.86:22167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PYrLfyzVz2SrjZpjIvQAAAic"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:06:58.719229 2026] [security2:error] [pid 832668:tid 832894] [client 4.194.217.15:12596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/rip.php"] [unique_id "al4PYmci6KgEEltqA3C7ngAAAF4"]
[Mon Jul 20 06:06:58.819509 2026] [security2:error] [pid 832668:tid 832911] [client 112.213.160.112:8357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7ogAAAG8"]
[Mon Jul 20 06:06:58.819633 2026] [security2:error] [pid 832668:tid 832911] [client 112.213.160.112:8357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PYmci6KgEEltqA3C7ogAAAG8"]
[Mon Jul 20 06:06:58.837422 2026] [security2:error] [pid 832668:tid 832825] [client 57.141.18.50:61182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PXGci6KgEEltqA3C6hAAAGVQ"]
[Mon Jul 20 06:06:59.030814 2026] [security2:error] [pid 796567:tid 796764] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PYrLfyzVz2SrjZpjIyAAAAlc"]
[Mon Jul 20 06:06:59.259134 2026] [security2:error] [pid 832668:tid 832826] [client 4.194.217.15:4744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/root.php"] [unique_id "al4PY2ci6KgEEltqA3C7xgAAABo"]
[Mon Jul 20 06:06:59.362336 2026] [security2:error] [pid 796567:tid 796725] [client 103.95.123.246:20591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI4gAAAjA"]
[Mon Jul 20 06:06:59.362439 2026] [security2:error] [pid 796567:tid 796725] [client 103.95.123.246:20591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI4gAAAjA"]
[Mon Jul 20 06:06:59.389253 2026] [security2:error] [pid 796567:tid 796814] [client 14.225.17.146:56625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PY7LfyzVz2SrjZpjI2gAAAok"], referer: https://fkconstructionfunding.com/Wordpress
[Mon Jul 20 06:06:59.464311 2026] [security2:error] [pid 832668:tid 832877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PY2ci6KgEEltqA3C7xAAAAE0"]
[Mon Jul 20 06:06:59.631802 2026] [security2:error] [pid 832668:tid 832807] [client 14.225.17.146:57855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4PY2ci6KgEEltqA3C71wAAAAc"], referer: http://retzkolonglogistics.com/Wordpress
[Mon Jul 20 06:06:59.637251 2026] [security2:error] [pid 832668:tid 832924] [client 103.77.203.233:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PY2ci6KgEEltqA3C73gAAAHw"]
[Mon Jul 20 06:06:59.637493 2026] [security2:error] [pid 832668:tid 832924] [client 103.77.203.233:57316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PY2ci6KgEEltqA3C73gAAAHw"]
[Mon Jul 20 06:06:59.694031 2026] [security2:error] [pid 796567:tid 796815] [client 115.246.21.170:26090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI9gAAAoo"]
[Mon Jul 20 06:06:59.694156 2026] [security2:error] [pid 796567:tid 796815] [client 115.246.21.170:26090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PY7LfyzVz2SrjZpjI9gAAAoo"]
[Mon Jul 20 06:06:59.807939 2026] [security2:error] [pid 832668:tid 832866] [client 4.194.217.15:4766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/s.php"] [unique_id "al4PY2ci6KgEEltqA3C75wAAAEI"]
[Mon Jul 20 06:06:59.877979 2026] [security2:error] [pid 796567:tid 796738] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PY7LfyzVz2SrjZpjI7gAAAj0"]
[Mon Jul 20 06:06:59.911494 2026] [access_compat:error] [pid 832668:tid 832850] [client 183.47.125.145:42635] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:06:59.959962 2026] [security2:error] [pid 796567:tid 796776] [client 185.132.186.92:33693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/av.php"] [unique_id "al4PY7LfyzVz2SrjZpjI_wAAAmM"]
[Mon Jul 20 06:07:00.061843 2026] [security2:error] [pid 832668:tid 832875] [client 54.244.177.189:25374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4PZGci6KgEEltqA3C78wAAAEs"]
[Mon Jul 20 06:07:00.211089 2026] [security2:error] [pid 832668:tid 832820] [client 45.116.69.230:57773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C7-QAAABQ"]
[Mon Jul 20 06:07:00.211209 2026] [security2:error] [pid 832668:tid 832820] [client 45.116.69.230:57773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C7-QAAABQ"]
[Mon Jul 20 06:07:00.244719 2026] [security2:error] [pid 796567:tid 796697] [client 43.173.182.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "canqungarments.com"] [uri "/index.php"] [unique_id "al4PX7LfyzVz2SrjZpjIRQAAAhQ"]
[Mon Jul 20 06:07:00.276105 2026] [security2:error] [pid 832668:tid 832856] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZGci6KgEEltqA3C78gAAADg"]
[Mon Jul 20 06:07:00.342593 2026] [security2:error] [pid 832668:tid 832851] [client 57.141.18.31:43996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PXmci6KgEEltqA3C63AAAM3M"]
[Mon Jul 20 06:07:00.350522 2026] [security2:error] [pid 832668:tid 832912] [client 4.194.217.15:4763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sang.php"] [unique_id "al4PZGci6KgEEltqA3C8AgAAAHA"]
[Mon Jul 20 06:07:00.457977 2026] [security2:error] [pid 832668:tid 832862] [client 3.87.179.57:31954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "cryptomeaning.com"] [uri "/"] [unique_id "al4PZGci6KgEEltqA3C8BAAAAD4"]
[Mon Jul 20 06:07:00.738043 2026] [security2:error] [pid 832668:tid 832721] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C8GQAACzI"]
[Mon Jul 20 06:07:00.738310 2026] [security2:error] [pid 832668:tid 832811] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PZGci6KgEEltqA3C8GQAACzI"]
[Mon Jul 20 06:07:00.764813 2026] [security2:error] [pid 832668:tid 832719] [remote 34.21.244.199:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewritinglair.com"] [uri "/wp-login.php"] [unique_id "al4PZGci6KgEEltqA3C8GgAAMTA"]
[Mon Jul 20 06:07:00.903059 2026] [security2:error] [pid 832668:tid 832913] [client 4.194.217.15:9230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/scxy.php"] [unique_id "al4PZGci6KgEEltqA3C8KQAAAHE"]
[Mon Jul 20 06:07:00.976618 2026] [security2:error] [pid 832668:tid 832867] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZGci6KgEEltqA3C8GAAAAEM"]
[Mon Jul 20 06:07:01.007627 2026] [security2:error] [pid 832668:tid 832848] [client 210.212.97.243:10452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8LwAAADA"]
[Mon Jul 20 06:07:01.007719 2026] [security2:error] [pid 832668:tid 832848] [client 210.212.97.243:10452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8LwAAADA"]
[Mon Jul 20 06:07:01.134741 2026] [security2:error] [pid 832668:tid 832724] [remote 34.21.244.199:34894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewritinglair.com"] [uri "/wp-login.php"] [unique_id "al4PZWci6KgEEltqA3C8OgAABzU"], referer: https://thewritinglair.com/wp-login.php
[Mon Jul 20 06:07:01.153116 2026] [security2:error] [pid 832668:tid 832725] [remote 20.153.140.50:60132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8PQAAAjY"]
[Mon Jul 20 06:07:01.153267 2026] [security2:error] [pid 832668:tid 832802] [client 20.153.140.50:60132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8PQAAAjY"]
[Mon Jul 20 06:07:01.197571 2026] [security2:error] [pid 796567:tid 796719] [client 41.173.37.102:4513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJNQAAAio"]
[Mon Jul 20 06:07:01.197700 2026] [security2:error] [pid 796567:tid 796719] [client 41.173.37.102:4513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJNQAAAio"]
[Mon Jul 20 06:07:01.253471 2026] [security2:error] [pid 796567:tid 796729] [client 193.37.33.6:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makeupyourskin.nl"] [uri "/wp-login.php"] [unique_id "al4PZbLfyzVz2SrjZpjJNgAAAjQ"]
[Mon Jul 20 06:07:01.267113 2026] [lsapi:warn] [pid 832668:tid 832852] [client 14.225.17.146:57858] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:01.267137 2026] [lsapi:warn] [pid 832668:tid 832852] [client 14.225.17.146:57858] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:01.285605 2026] [security2:error] [pid 796567:tid 796748] [client 193.19.109.213:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makeupyourskin.nl"] [uri "/wp-login.php"] [unique_id "al4PZbLfyzVz2SrjZpjJOAAAAkc"]
[Mon Jul 20 06:07:01.382686 2026] [security2:error] [pid 796567:tid 796667] [remote 47.86.33.52:57000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJPAACaGM"]
[Mon Jul 20 06:07:01.382887 2026] [security2:error] [pid 796567:tid 796781] [client 47.86.33.52:57000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJPAACaGM"]
[Mon Jul 20 06:07:01.444602 2026] [security2:error] [pid 832668:tid 832903] [client 4.194.217.15:1841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sd.php"] [unique_id "al4PZWci6KgEEltqA3C8UQAAAGc"]
[Mon Jul 20 06:07:01.452390 2026] [security2:error] [pid 832668:tid 832884] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZWci6KgEEltqA3C8QgAAAFQ"]
[Mon Jul 20 06:07:01.514640 2026] [security2:error] [pid 832668:tid 832924] [client 158.173.166.181:45105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PZWci6KgEEltqA3C8VgAAAHw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:01.555936 2026] [security2:error] [pid 796567:tid 796702] [client 14.225.17.146:58731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4PZbLfyzVz2SrjZpjJQAAAAhk"], referer: http://grndl.com/Wordpress
[Mon Jul 20 06:07:01.752773 2026] [security2:error] [pid 796567:tid 796787] [client 193.19.109.229:27949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4PZbLfyzVz2SrjZpjJSgAAAm4"]
[Mon Jul 20 06:07:01.779871 2026] [security2:error] [pid 832668:tid 832819] [client 193.19.109.227:57739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4PZWci6KgEEltqA3C8YQAAABM"]
[Mon Jul 20 06:07:01.863726 2026] [security2:error] [pid 832668:tid 832735] [remote 157.66.26.183:56604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8agAAZEA"]
[Mon Jul 20 06:07:01.863909 2026] [security2:error] [pid 832668:tid 832900] [client 157.66.26.183:56604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PZWci6KgEEltqA3C8agAAZEA"]
[Mon Jul 20 06:07:01.871849 2026] [security2:error] [pid 832668:tid 832868] [client 193.19.109.233:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/wp-login.php"] [unique_id "al4PZWci6KgEEltqA3C8ZAAAAEQ"]
[Mon Jul 20 06:07:01.877516 2026] [security2:error] [pid 796567:tid 796745] [client 181.224.94.124:36297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJTgAAAkQ"]
[Mon Jul 20 06:07:01.877624 2026] [security2:error] [pid 796567:tid 796745] [client 181.224.94.124:36297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PZbLfyzVz2SrjZpjJTgAAAkQ"]
[Mon Jul 20 06:07:01.899522 2026] [security2:error] [pid 796567:tid 796782] [client 185.132.186.73:28893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/glex.php"] [unique_id "al4PZbLfyzVz2SrjZpjJTwAAAmk"]
[Mon Jul 20 06:07:01.987504 2026] [security2:error] [pid 832668:tid 832907] [client 4.194.217.15:9229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sf.php"] [unique_id "al4PZWci6KgEEltqA3C8cgAAAGs"]
[Mon Jul 20 06:07:02.065113 2026] [security2:error] [pid 832668:tid 832846] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZWci6KgEEltqA3C8XwAAAC4"]
[Mon Jul 20 06:07:02.150219 2026] [lsapi:warn] [pid 796567:tid 796747] [client 50.116.65.227:53424] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:07:02.150246 2026] [lsapi:warn] [pid 796567:tid 796747] [client 50.116.65.227:53424] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:07:02.163805 2026] [security2:error] [pid 832668:tid 832852] [client 14.225.17.146:57858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4PZGci6KgEEltqA3C8GwAAADQ"], referer: http://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:02.169415 2026] [security2:error] [pid 832668:tid 832910] [client 178.152.178.232:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8dwAAAG4"]
[Mon Jul 20 06:07:02.169544 2026] [security2:error] [pid 832668:tid 832910] [client 178.152.178.232:37860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8dwAAAG4"]
[Mon Jul 20 06:07:02.256692 2026] [security2:error] [pid 832668:tid 832898] [client 57.141.18.5:41892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PX2ci6KgEEltqA3C7GQAAYnc"]
[Mon Jul 20 06:07:02.386881 2026] [security2:error] [pid 832668:tid 832740] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8hAAAKkU"]
[Mon Jul 20 06:07:02.387072 2026] [security2:error] [pid 832668:tid 832842] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PZmci6KgEEltqA3C8hAAAKkU"]
[Mon Jul 20 06:07:02.539971 2026] [security2:error] [pid 832668:tid 832913] [client 4.194.217.15:4439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/shell.php"] [unique_id "al4PZmci6KgEEltqA3C8igAAAHE"]
[Mon Jul 20 06:07:02.649833 2026] [security2:error] [pid 832668:tid 832919] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZmci6KgEEltqA3C8ggAAAHc"]
[Mon Jul 20 06:07:02.699466 2026] [security2:error] [pid 832668:tid 832909] [client 14.225.17.146:56642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4PZmci6KgEEltqA3C8iQAAAG0"]
[Mon Jul 20 06:07:02.726620 2026] [security2:error] [pid 796567:tid 796779] [client 104.234.53.54:23575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PZrLfyzVz2SrjZpjJcQAAAmY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:02.926828 2026] [security2:error] [pid 796567:tid 796726] [client 94.154.43.185:36960] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.gua.yhh.mybluehost.me"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al4PZrLfyzVz2SrjZpjJegAAAjE"]
[Mon Jul 20 06:07:02.972948 2026] [security2:error] [pid 832668:tid 832868] [client 94.154.43.229:45660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.gua.yhh.mybluehost.me"] [uri "/.env"] [unique_id "al4PZmci6KgEEltqA3C8mAAAAEQ"]
[Mon Jul 20 06:07:02.979847 2026] [security2:error] [pid 832668:tid 832888] [client 94.154.43.229:45668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "gua.yhh.mybluehost.me"] [uri "/.env"] [unique_id "al4PZmci6KgEEltqA3C8mQAAAFg"]
[Mon Jul 20 06:07:02.996707 2026] [security2:error] [pid 832668:tid 832835] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZmci6KgEEltqA3C8kgAAACM"]
[Mon Jul 20 06:07:03.004520 2026] [lsapi:warn] [pid 796567:tid 796714] [client 14.225.17.146:57242] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:03.004536 2026] [lsapi:warn] [pid 796567:tid 796714] [client 14.225.17.146:57242] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:03.062254 2026] [security2:error] [pid 796567:tid 796714] [client 14.225.17.146:57242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJfAAAAiU"], referer: https://oswegooperatheater.com/Wordpress
[Mon Jul 20 06:07:03.171918 2026] [security2:error] [pid 796567:tid 796593] [remote 84.247.172.23:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJiwACPhk"]
[Mon Jul 20 06:07:03.356440 2026] [security2:error] [pid 796567:tid 796763] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJiAAAAlY"]
[Mon Jul 20 06:07:03.375265 2026] [security2:error] [pid 832668:tid 832902] [client 50.116.65.227:53436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PZ2ci6KgEEltqA3C8rwAAAGY"]
[Mon Jul 20 06:07:03.385691 2026] [security2:error] [pid 832668:tid 832917] [client 50.116.65.227:53452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PZ2ci6KgEEltqA3C8sAAAAHU"]
[Mon Jul 20 06:07:03.452250 2026] [security2:error] [pid 796567:tid 796615] [remote 84.247.172.23:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJmAACPC8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:07:03.517984 2026] [security2:error] [pid 796567:tid 796762] [client 193.19.109.249:32007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtlegnews.gov"] [uri "/wp-login.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJnQAAAlU"]
[Mon Jul 20 06:07:03.585206 2026] [security2:error] [pid 832668:tid 832898] [client 193.19.109.250:57937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtlegnews.gov"] [uri "/wp-login.php"] [unique_id "al4PZ2ci6KgEEltqA3C8vAAAAGI"]
[Mon Jul 20 06:07:03.754932 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:64854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4PZWci6KgEEltqA3C8VQAAAFE"], referer: http://hilltopnurseryinc.com/Wordpress
[Mon Jul 20 06:07:03.818447 2026] [security2:error] [pid 832668:tid 832848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZ2ci6KgEEltqA3C8vwAAADA"]
[Mon Jul 20 06:07:03.856127 2026] [security2:error] [pid 796567:tid 796708] [client 185.132.186.68:33301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJrwAAAh8"]
[Mon Jul 20 06:07:03.892448 2026] [security2:error] [pid 832668:tid 832826] [client 4.194.217.15:10993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sid3.php"] [unique_id "al4PZ2ci6KgEEltqA3C8ywAAABo"]
[Mon Jul 20 06:07:03.946202 2026] [security2:error] [pid 832668:tid 832901] [client 57.141.18.63:65534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PYWci6KgEEltqA3C7YQAAZQY"]
[Mon Jul 20 06:07:04.261528 2026] [security2:error] [pid 796567:tid 796757] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PZ7LfyzVz2SrjZpjJtAAAAlA"]
[Mon Jul 20 06:07:04.264765 2026] [access_compat:error] [pid 796567:tid 796700] [client 112.14.1.26:33872] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:07:04.458223 2026] [security2:error] [pid 796567:tid 796809] [client 4.194.217.15:7291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/simple.php"] [unique_id "al4PaLLfyzVz2SrjZpjJzwAAAoQ"]
[Mon Jul 20 06:07:04.568057 2026] [security2:error] [pid 796567:tid 796770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PaLLfyzVz2SrjZpjJywAAAl0"]
[Mon Jul 20 06:07:04.607678 2026] [security2:error] [pid 796567:tid 796656] [remote 188.166.241.141:49760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4PaLLfyzVz2SrjZpjJ0wACXFg"]
[Mon Jul 20 06:07:04.859617 2026] [security2:error] [pid 832668:tid 832817] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PaGci6KgEEltqA3C87AAAABE"]
[Mon Jul 20 06:07:05.000997 2026] [security2:error] [pid 796567:tid 796674] [remote 188.166.241.141:49760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4PabLfyzVz2SrjZpjJ6gACT2o"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:07:05.002095 2026] [security2:error] [pid 796567:tid 796800] [client 4.194.217.15:10984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sitemap.php"] [unique_id "al4PabLfyzVz2SrjZpjJ6wAAAns"]
[Mon Jul 20 06:07:05.171880 2026] [security2:error] [pid 832668:tid 832901] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PaGci6KgEEltqA3C89wAAAGU"]
[Mon Jul 20 06:07:05.551091 2026] [security2:error] [pid 796567:tid 796779] [client 4.194.217.15:10975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/size.php"] [unique_id "al4PabLfyzVz2SrjZpjKAwAAAmY"]
[Mon Jul 20 06:07:05.740205 2026] [security2:error] [pid 796567:tid 796714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PabLfyzVz2SrjZpjKAgAAAiU"]
[Mon Jul 20 06:07:05.802248 2026] [security2:error] [pid 796567:tid 796745] [client 185.132.186.103:44203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Parse/about.php"] [unique_id "al4PabLfyzVz2SrjZpjKFAAAAkQ"]
[Mon Jul 20 06:07:05.967343 2026] [security2:error] [pid 796567:tid 796700] [client 14.225.17.146:65368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4PabLfyzVz2SrjZpjKEgAAAhc"], referer: http://lifeisbetterlakeside.com/Wordpress
[Mon Jul 20 06:07:06.099544 2026] [security2:error] [pid 796567:tid 796746] [client 4.194.217.15:10999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sm.php"] [unique_id "al4ParLfyzVz2SrjZpjKIgAAAkU"]
[Mon Jul 20 06:07:06.225105 2026] [security2:error] [pid 832668:tid 832871] [client 50.116.65.227:28418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4Pamci6KgEEltqA3C9IAAAAEc"]
[Mon Jul 20 06:07:06.237396 2026] [security2:error] [pid 832668:tid 832892] [client 50.116.65.227:53472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4Pamci6KgEEltqA3C9IgAAAGQ"]
[Mon Jul 20 06:07:06.561484 2026] [security2:error] [pid 796567:tid 796817] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ParLfyzVz2SrjZpjKLgAAAow"]
[Mon Jul 20 06:07:06.650170 2026] [security2:error] [pid 796567:tid 796705] [client 4.194.217.15:11003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sql.php"] [unique_id "al4ParLfyzVz2SrjZpjKQQAAAhw"]
[Mon Jul 20 06:07:06.826814 2026] [security2:error] [pid 832668:tid 832751] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pamci6KgEEltqA3C9PQAAS1A"]
[Mon Jul 20 06:07:06.826936 2026] [security2:error] [pid 832668:tid 832875] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pamci6KgEEltqA3C9PQAAS1A"]
[Mon Jul 20 06:07:07.090590 2026] [security2:error] [pid 832668:tid 832907] [client 86.98.90.58:64117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa2ci6KgEEltqA3C9TQAAAGs"]
[Mon Jul 20 06:07:07.090725 2026] [security2:error] [pid 832668:tid 832907] [client 86.98.90.58:64117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa2ci6KgEEltqA3C9TQAAAGs"]
[Mon Jul 20 06:07:07.147053 2026] [security2:error] [pid 832668:tid 832821] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pamci6KgEEltqA3C9RQAAABU"]
[Mon Jul 20 06:07:07.190469 2026] [security2:error] [pid 832668:tid 832859] [client 4.194.217.15:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/ss.php"] [unique_id "al4Pa2ci6KgEEltqA3C9UQAAADs"]
[Mon Jul 20 06:07:07.250685 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9TAAAAC4"]
[Mon Jul 20 06:07:07.255261 2026] [security2:error] [pid 832668:tid 832811] [client 14.225.17.146:56510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4Pamci6KgEEltqA3C9NwAAAAs"]
[Mon Jul 20 06:07:07.523868 2026] [security2:error] [pid 832668:tid 832888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9VQAAAFg"]
[Mon Jul 20 06:07:07.721132 2026] [security2:error] [pid 796567:tid 796720] [client 84.54.44.19:63768] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "84.54.44.19" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKaQAAAis"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 06:07:07.721304 2026] [security2:error] [pid 796567:tid 796720] [client 84.54.44.19:63768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKaQAAAis"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 06:07:07.748293 2026] [security2:error] [pid 796567:tid 796719] [client 185.132.186.81:24167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKbAAAAio"]
[Mon Jul 20 06:07:07.753649 2026] [security2:error] [pid 832668:tid 832909] [client 4.194.217.15:1556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/stats.php"] [unique_id "al4Pa2ci6KgEEltqA3C9YwAAAG0"]
[Mon Jul 20 06:07:08.023558 2026] [security2:error] [pid 796567:tid 796721] [client 13.201.64.214:51860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKdQAAAiw"]
[Mon Jul 20 06:07:08.023742 2026] [security2:error] [pid 796567:tid 796721] [client 13.201.64.214:51860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKdQAAAiw"]
[Mon Jul 20 06:07:08.146385 2026] [security2:error] [pid 832668:tid 832877] [client 104.234.53.69:44949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PbGci6KgEEltqA3C9bwAAAE0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:08.168483 2026] [security2:error] [pid 832668:tid 832858] [client 103.141.108.143:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9cQAAADo"]
[Mon Jul 20 06:07:08.168621 2026] [security2:error] [pid 832668:tid 832858] [client 103.141.108.143:62702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9cQAAADo"]
[Mon Jul 20 06:07:08.207341 2026] [security2:error] [pid 796567:tid 796703] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pa7LfyzVz2SrjZpjKagAAAho"]
[Mon Jul 20 06:07:08.244392 2026] [security2:error] [pid 796567:tid 796767] [client 14.225.17.146:56073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4PbLLfyzVz2SrjZpjKegAAAlo"], referer: http://qualitycoatingsinspection.com/Wordpress
[Mon Jul 20 06:07:08.285029 2026] [security2:error] [pid 796567:tid 796710] [client 150.228.148.150:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PbLLfyzVz2SrjZpjKhAAAAiE"]
[Mon Jul 20 06:07:08.285169 2026] [security2:error] [pid 796567:tid 796710] [client 150.228.148.150:49625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PbLLfyzVz2SrjZpjKhAAAAiE"]
[Mon Jul 20 06:07:08.306923 2026] [security2:error] [pid 832668:tid 832913] [client 4.194.217.15:1560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/sump1.php"] [unique_id "al4PbGci6KgEEltqA3C9eQAAAHE"]
[Mon Jul 20 06:07:08.376293 2026] [security2:error] [pid 832668:tid 832851] [client 14.225.17.146:63912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4Pamci6KgEEltqA3C9NQAAADM"]
[Mon Jul 20 06:07:08.413156 2026] [security2:error] [pid 832668:tid 832813] [client 43.205.139.3:18754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pa2ci6KgEEltqA3C9ZAAAAA0"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:07:08.704470 2026] [security2:error] [pid 832668:tid 832766] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9jgAAWl8"]
[Mon Jul 20 06:07:08.704697 2026] [security2:error] [pid 832668:tid 832890] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9jgAAWl8"]
[Mon Jul 20 06:07:08.846667 2026] [security2:error] [pid 796567:tid 796730] [client 4.194.217.15:5199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system.php"] [unique_id "al4PbLLfyzVz2SrjZpjKlwAAAjU"]
[Mon Jul 20 06:07:08.868737 2026] [security2:error] [pid 832668:tid 832834] [client 106.192.104.4:49416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9mAAAACI"]
[Mon Jul 20 06:07:08.868864 2026] [security2:error] [pid 832668:tid 832834] [client 106.192.104.4:49416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PbGci6KgEEltqA3C9mAAAACI"]
[Mon Jul 20 06:07:09.003868 2026] [security2:error] [pid 832668:tid 832730] [remote 124.55.178.99:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PbGci6KgEEltqA3C9mwAAPDs"]
[Mon Jul 20 06:07:09.069341 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:63909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9XQAAABw"], referer: http://expertcultures.com/Wordpress
[Mon Jul 20 06:07:09.190805 2026] [security2:error] [pid 796567:tid 796776] [client 14.225.17.146:63941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4PbbLfyzVz2SrjZpjKogAAAmM"], referer: https://qualitycoatingsinspection.com/Wordpress
[Mon Jul 20 06:07:09.391801 2026] [security2:error] [pid 796567:tid 796717] [client 4.194.217.15:1543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4PbbLfyzVz2SrjZpjKqgAAAig"]
[Mon Jul 20 06:07:09.579966 2026] [security2:error] [pid 832668:tid 832927] [client 112.213.160.112:8436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9sgAAAH8"]
[Mon Jul 20 06:07:09.580115 2026] [security2:error] [pid 832668:tid 832927] [client 112.213.160.112:8436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9sgAAAH8"]
[Mon Jul 20 06:07:09.610040 2026] [security2:error] [pid 832668:tid 832778] [remote 124.55.178.99:55536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4PbWci6KgEEltqA3C9tAAAEGs"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:07:09.691473 2026] [security2:error] [pid 796567:tid 796817] [client 185.132.186.56:42591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/system_cache.php"] [unique_id "al4PbbLfyzVz2SrjZpjKtAAAAow"]
[Mon Jul 20 06:07:09.724343 2026] [security2:error] [pid 832668:tid 832883] [client 57.141.18.72:26110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PZ2ci6KgEEltqA3C8tgAAUyE"]
[Mon Jul 20 06:07:09.961763 2026] [security2:error] [pid 832668:tid 832837] [client 4.194.217.15:6024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4PbWci6KgEEltqA3C9wwAAACU"]
[Mon Jul 20 06:07:09.977394 2026] [security2:error] [pid 832668:tid 832813] [client 103.77.203.233:57377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9xAAAAA0"]
[Mon Jul 20 06:07:09.977532 2026] [security2:error] [pid 832668:tid 832813] [client 103.77.203.233:57377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PbWci6KgEEltqA3C9xAAAAA0"]
[Mon Jul 20 06:07:10.180508 2026] [security2:error] [pid 832668:tid 832849] [client 50.116.65.227:36890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Pbmci6KgEEltqA3C9ywAAADE"]
[Mon Jul 20 06:07:10.197123 2026] [security2:error] [pid 832668:tid 832896] [client 50.116.65.227:26854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Pbmci6KgEEltqA3C9zAAAAGA"]
[Mon Jul 20 06:07:10.209530 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:17990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PbrLfyzVz2SrjZpjKxQAAAkk"]
[Mon Jul 20 06:07:10.209686 2026] [security2:error] [pid 796567:tid 796750] [client 115.246.21.170:17990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PbrLfyzVz2SrjZpjKxQAAAkk"]
[Mon Jul 20 06:07:10.321643 2026] [security2:error] [pid 832668:tid 832886] [client 14.225.17.146:59530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4PbGci6KgEEltqA3C9iAAAAFY"], referer: http://tacticaltreeoperations.com/Wordpress
[Mon Jul 20 06:07:10.344257 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C91QAAAC8"]
[Mon Jul 20 06:07:10.344381 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C91QAAAC8"]
[Mon Jul 20 06:07:10.354245 2026] [security2:error] [pid 832668:tid 832912] [client 34.31.203.120:48448] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.royalart-lb.com"] [uri "/"] [unique_id "al4Pbmci6KgEEltqA3C91gAAAHA"]
[Mon Jul 20 06:07:10.488797 2026] [security2:error] [pid 832668:tid 832920] [client 45.116.69.230:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C92wAAAHg"]
[Mon Jul 20 06:07:10.488904 2026] [security2:error] [pid 832668:tid 832920] [client 45.116.69.230:58440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pbmci6KgEEltqA3C92wAAAHg"]
[Mon Jul 20 06:07:10.524602 2026] [security2:error] [pid 832668:tid 832897] [client 4.194.217.15:5237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/system_log.php"] [unique_id "al4Pbmci6KgEEltqA3C93QAAAGE"]
[Mon Jul 20 06:07:10.845959 2026] [security2:error] [pid 832668:tid 832785] [remote 192.241.143.148:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Pbmci6KgEEltqA3C97AAAUnI"]
[Mon Jul 20 06:07:10.927947 2026] [security2:error] [pid 796567:tid 796778] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4PbrLfyzVz2SrjZpjK3wAAAmU"]
[Mon Jul 20 06:07:10.982522 2026] [security2:error] [pid 832668:tid 832749] [remote 5.161.225.162:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4Pbmci6KgEEltqA3C98QAAR04"]
[Mon Jul 20 06:07:11.030502 2026] [security2:error] [pid 832668:tid 832787] [remote 192.241.143.148:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Pb2ci6KgEEltqA3C99AAAMXQ"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:07:11.120046 2026] [security2:error] [pid 796567:tid 796788] [client 4.194.217.15:5191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/t.php"] [unique_id "al4Pb7LfyzVz2SrjZpjK8QAAAm8"]
[Mon Jul 20 06:07:11.323316 2026] [security2:error] [pid 796567:tid 796669] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjK-wACh2U"]
[Mon Jul 20 06:07:11.323498 2026] [security2:error] [pid 796567:tid 796812] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjK-wACh2U"]
[Mon Jul 20 06:07:11.354771 2026] [security2:error] [pid 832668:tid 832792] [remote 5.161.225.162:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4Pb2ci6KgEEltqA3C9_QAAAHk"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:07:11.375656 2026] [security2:error] [pid 832668:tid 832885] [client 45.157.112.60:30847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Pb2ci6KgEEltqA3C9_gAAAFU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:11.581842 2026] [security2:error] [pid 796567:tid 796751] [client 210.212.97.243:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.97.212.210.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjLAwAAAko"]
[Mon Jul 20 06:07:11.581947 2026] [security2:error] [pid 796567:tid 796751] [client 210.212.97.243:10453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb7LfyzVz2SrjZpjLAwAAAko"]
[Mon Jul 20 06:07:11.598115 2026] [security2:error] [pid 796567:tid 796722] [client 185.132.186.85:48835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/sky-pro/js.php"] [unique_id "al4Pb7LfyzVz2SrjZpjLBgAAAi0"]
[Mon Jul 20 06:07:11.696626 2026] [security2:error] [pid 832668:tid 832877] [client 4.194.217.15:4262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/term.php"] [unique_id "al4Pb2ci6KgEEltqA3C-CwAAAE0"]
[Mon Jul 20 06:07:11.753345 2026] [security2:error] [pid 796567:tid 796731] [client 57.141.18.107:45776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PabLfyzVz2SrjZpjKBQACNiQ"]
[Mon Jul 20 06:07:11.841470 2026] [security2:error] [pid 832668:tid 832804] [client 41.173.37.102:4976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb2ci6KgEEltqA3C-FAAAAAQ"]
[Mon Jul 20 06:07:11.841631 2026] [security2:error] [pid 832668:tid 832804] [client 41.173.37.102:4976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pb2ci6KgEEltqA3C-FAAAAAQ"]
[Mon Jul 20 06:07:11.966632 2026] [security2:error] [pid 832668:tid 832815] [client 14.224.227.113:54251] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Pb2ci6KgEEltqA3C-GAAAAA8"]
[Mon Jul 20 06:07:12.237421 2026] [security2:error] [pid 832668:tid 832840] [client 4.194.217.15:5205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/test.php"] [unique_id "al4PcGci6KgEEltqA3C-JQAAACg"]
[Mon Jul 20 06:07:12.459832 2026] [security2:error] [pid 832668:tid 832921] [client 181.224.94.124:43729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PcGci6KgEEltqA3C-NwAAAHk"]
[Mon Jul 20 06:07:12.460031 2026] [security2:error] [pid 832668:tid 832921] [client 181.224.94.124:43729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PcGci6KgEEltqA3C-NwAAAHk"]
[Mon Jul 20 06:07:12.682550 2026] [security2:error] [pid 796567:tid 796753] [client 178.152.178.232:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PcLLfyzVz2SrjZpjLMwAAAkw"]
[Mon Jul 20 06:07:12.682684 2026] [security2:error] [pid 796567:tid 796753] [client 178.152.178.232:36811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PcLLfyzVz2SrjZpjLMwAAAkw"]
[Mon Jul 20 06:07:12.709276 2026] [security2:error] [pid 832668:tid 832804] [client 50.116.65.227:26876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PcGci6KgEEltqA3C-RgAAAAQ"]
[Mon Jul 20 06:07:12.709298 2026] [security2:error] [pid 832668:tid 832854] [client 193.37.33.232:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "atozgroup.biz"] [uri "/wp-login.php"] [unique_id "al4PcGci6KgEEltqA3C-QAAAADY"]
[Mon Jul 20 06:07:12.721729 2026] [security2:error] [pid 832668:tid 832889] [client 50.116.65.227:26892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PcGci6KgEEltqA3C-SAAAAFk"]
[Mon Jul 20 06:07:12.777870 2026] [security2:error] [pid 832668:tid 832897] [client 4.194.217.15:6053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/test1.php"] [unique_id "al4PcGci6KgEEltqA3C-TAAAAGE"]
[Mon Jul 20 06:07:12.898219 2026] [security2:error] [pid 796567:tid 796720] [client 14.225.17.146:55651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4PcLLfyzVz2SrjZpjLNwAAAis"], referer: http://ivetstrategies.com/Wordpress
[Mon Jul 20 06:07:12.943643 2026] [security2:error] [pid 832668:tid 832814] [client 43.205.139.3:18764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PcGci6KgEEltqA3C-LgAAAA4"]
[Mon Jul 20 06:07:13.004477 2026] [security2:error] [pid 796567:tid 796633] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PcbLfyzVz2SrjZpjLPgACWkE"]
[Mon Jul 20 06:07:13.004695 2026] [security2:error] [pid 796567:tid 796767] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PcbLfyzVz2SrjZpjLPgACWkE"]
[Mon Jul 20 06:07:13.339376 2026] [security2:error] [pid 832668:tid 832850] [client 4.194.217.15:5235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/tfm.php"] [unique_id "al4PcWci6KgEEltqA3C-ZQAAADI"]
[Mon Jul 20 06:07:13.350682 2026] [security2:error] [pid 832668:tid 832853] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PcGci6KgEEltqA3C-TQAAADU"], referer: http://laceycaraccident.com/identity
[Mon Jul 20 06:07:13.553652 2026] [security2:error] [pid 832668:tid 832862] [client 185.132.186.80:22789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/wp-conflg.php"] [unique_id "al4PcWci6KgEEltqA3C-bQAAAD4"]
[Mon Jul 20 06:07:13.900566 2026] [security2:error] [pid 832668:tid 832842] [client 4.194.217.15:6076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/thebe.php"] [unique_id "al4PcWci6KgEEltqA3C-fwAAACo"]
[Mon Jul 20 06:07:14.067118 2026] [security2:error] [pid 796567:tid 796760] [client 14.225.17.146:49362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4PcLLfyzVz2SrjZpjLIgAAAlM"], referer: http://according2plant.com/Wordpress
[Mon Jul 20 06:07:14.308508 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.10:54144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pa2ci6KgEEltqA3C9aQAATk0"]
[Mon Jul 20 06:07:14.440393 2026] [security2:error] [pid 832668:tid 832911] [client 4.194.217.15:6048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/themes.php"] [unique_id "al4Pcmci6KgEEltqA3C-jgAAAG8"]
[Mon Jul 20 06:07:15.004328 2026] [security2:error] [pid 796567:tid 796725] [client 4.194.217.15:1682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/tiny.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLjQAAAjA"]
[Mon Jul 20 06:07:15.488569 2026] [security2:error] [pid 796567:tid 796598] [remote 57.141.18.45:35610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4417158"] [unique_id "al4Pc7LfyzVz2SrjZpjLoAACih4"]
[Mon Jul 20 06:07:15.576386 2026] [security2:error] [pid 796567:tid 796756] [client 4.194.217.15:1244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/tmp/byp.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLowAAAk8"]
[Mon Jul 20 06:07:15.957362 2026] [security2:error] [pid 832668:tid 832786] [remote 95.217.78.234:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4Pc2ci6KgEEltqA3C-zwAAbXM"]
[Mon Jul 20 06:07:16.173332 2026] [security2:error] [pid 796567:tid 796795] [client 57.141.18.24:47346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PbbLfyzVz2SrjZpjKuQACdkI"]
[Mon Jul 20 06:07:16.177376 2026] [security2:error] [pid 832668:tid 832711] [remote 95.217.78.234:56594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4PdGci6KgEEltqA3C-1QAABCg"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 06:07:16.256426 2026] [security2:error] [pid 832668:tid 832847] [client 104.234.53.73:26749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PdGci6KgEEltqA3C-2gAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:16.475502 2026] [security2:error] [pid 832668:tid 832910] [client 158.173.89.95:20035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PdGci6KgEEltqA3C-5gAAAG4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:16.523714 2026] [security2:error] [pid 796567:tid 796731] [client 185.132.186.73:33485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/waf_defender.php"] [unique_id "al4PdLLfyzVz2SrjZpjLyAAAAjY"]
[Mon Jul 20 06:07:16.627855 2026] [security2:error] [pid 832668:tid 832905] [client 14.225.17.146:56572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Pc2ci6KgEEltqA3C-wQAAAGk"]
[Mon Jul 20 06:07:16.702530 2026] [security2:error] [pid 832668:tid 832835] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PdGci6KgEEltqA3C-2wAAACM"]
[Mon Jul 20 06:07:16.882047 2026] [security2:error] [pid 832668:tid 832892] [client 27.96.94.195:37458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PdGci6KgEEltqA3C-8gAAAFw"]
[Mon Jul 20 06:07:16.882227 2026] [security2:error] [pid 832668:tid 832892] [client 27.96.94.195:37458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PdGci6KgEEltqA3C-8gAAAFw"]
[Mon Jul 20 06:07:17.344889 2026] [security2:error] [pid 832668:tid 832791] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PdWci6KgEEltqA3C_GAAAGXg"]
[Mon Jul 20 06:07:17.345108 2026] [security2:error] [pid 832668:tid 832825] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PdWci6KgEEltqA3C_GAAAGXg"]
[Mon Jul 20 06:07:17.725153 2026] [security2:error] [pid 832668:tid 832895] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PdWci6KgEEltqA3C-_gAAAF8"], referer: http://laceycaraccident.com/sitecore/shell/sitecore.version.xml
[Mon Jul 20 06:07:17.882656 2026] [security2:error] [pid 796567:tid 796782] [client 14.225.17.146:56474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLsgAAAmk"], referer: http://mobilesurvsolutions.com/Wordpress
[Mon Jul 20 06:07:18.035676 2026] [security2:error] [pid 796567:tid 796800] [client 113.160.97.242:50075] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4PdrLfyzVz2SrjZpjMAQAAAns"]
[Mon Jul 20 06:07:18.073313 2026] [core:error] [pid 832668:tid 832812] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.073343 2026] [core:error] [pid 832668:tid 832812] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.077713 2026] [core:error] [pid 832668:tid 832883] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.077731 2026] [core:error] [pid 832668:tid 832883] [client 140.248.75.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:18.471324 2026] [security2:error] [pid 832668:tid 832824] [client 185.132.186.98:63823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/theme.php"] [unique_id "al4Pdmci6KgEEltqA3C_TgAAABg"]
[Mon Jul 20 06:07:18.729591 2026] [security2:error] [pid 796567:tid 796770] [client 86.98.90.58:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGgAAAl0"]
[Mon Jul 20 06:07:18.735450 2026] [security2:error] [pid 796567:tid 796770] [client 86.98.90.58:64875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGgAAAl0"]
[Mon Jul 20 06:07:18.752509 2026] [security2:error] [pid 796567:tid 796759] [client 57.141.18.24:47362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PcLLfyzVz2SrjZpjLFQACUk0"]
[Mon Jul 20 06:07:18.754423 2026] [security2:error] [pid 796567:tid 796798] [client 103.141.108.143:63134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGwAAAnk"]
[Mon Jul 20 06:07:18.754787 2026] [security2:error] [pid 796567:tid 796798] [client 103.141.108.143:63134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMGwAAAnk"]
[Mon Jul 20 06:07:18.834717 2026] [security2:error] [pid 796567:tid 796710] [client 14.225.17.146:64102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4PdLLfyzVz2SrjZpjL3AAAAiE"], referer: http://709fx.com/Wordpress
[Mon Jul 20 06:07:18.970587 2026] [security2:error] [pid 796567:tid 796750] [client 150.228.148.150:62356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMHgAAAkk"]
[Mon Jul 20 06:07:18.972726 2026] [security2:error] [pid 796567:tid 796750] [client 150.228.148.150:62356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PdrLfyzVz2SrjZpjMHgAAAkk"]
[Mon Jul 20 06:07:19.299158 2026] [security2:error] [pid 832668:tid 832916] [client 106.192.104.4:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_bgAAAHQ"]
[Mon Jul 20 06:07:19.299274 2026] [security2:error] [pid 832668:tid 832916] [client 106.192.104.4:49897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_bgAAAHQ"]
[Mon Jul 20 06:07:19.315484 2026] [security2:error] [pid 832668:tid 832874] [client 121.229.156.97:43652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/crochet-tips-tutorials/"] [unique_id "al4Pd2ci6KgEEltqA3C_cQAAAEo"]
[Mon Jul 20 06:07:19.315618 2026] [security2:error] [pid 832668:tid 832874] [client 121.229.156.97:43652] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mezzacraft.com"] [uri "/crochet-tips-tutorials/"] [unique_id "al4Pd2ci6KgEEltqA3C_cQAAAEo"]
[Mon Jul 20 06:07:19.365473 2026] [security2:error] [pid 832668:tid 832731] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_dAAAVjw"]
[Mon Jul 20 06:07:19.365713 2026] [security2:error] [pid 832668:tid 832886] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_dAAAVjw"]
[Mon Jul 20 06:07:19.370745 2026] [security2:error] [pid 832668:tid 832879] [client 57.141.18.10:41478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PcGci6KgEEltqA3C-PQAAT2M"]
[Mon Jul 20 06:07:19.413439 2026] [security2:error] [pid 832668:tid 832913] [client 193.37.33.3:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4Pd2ci6KgEEltqA3C_dgAAAHE"]
[Mon Jul 20 06:07:19.425495 2026] [security2:error] [pid 796567:tid 796716] [client 193.19.109.245:60623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4Pd7LfyzVz2SrjZpjMLwAAAic"]
[Mon Jul 20 06:07:19.653368 2026] [security2:error] [pid 832668:tid 832741] [remote 167.233.114.32:33972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_hgAAHEY"]
[Mon Jul 20 06:07:19.653493 2026] [security2:error] [pid 832668:tid 832828] [client 167.233.114.32:33972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pd2ci6KgEEltqA3C_hgAAHEY"]
[Mon Jul 20 06:07:20.271142 2026] [security2:error] [pid 832668:tid 832873] [client 57.141.18.23:64452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PcWci6KgEEltqA3C-aAAASWU"]
[Mon Jul 20 06:07:20.280164 2026] [security2:error] [pid 796567:tid 796742] [client 112.213.160.112:8443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PeLLfyzVz2SrjZpjMTQAAAkE"]
[Mon Jul 20 06:07:20.280333 2026] [security2:error] [pid 796567:tid 796742] [client 112.213.160.112:8443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PeLLfyzVz2SrjZpjMTQAAAkE"]
[Mon Jul 20 06:07:20.419618 2026] [security2:error] [pid 832668:tid 832907] [client 185.132.186.75:37539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/waf_defender.php"] [unique_id "al4PeGci6KgEEltqA3C_ngAAAGs"]
[Mon Jul 20 06:07:20.541824 2026] [security2:error] [pid 832668:tid 832832] [client 103.77.203.233:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_qwAAACA"]
[Mon Jul 20 06:07:20.551296 2026] [security2:error] [pid 832668:tid 832832] [client 103.77.203.233:57436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_qwAAACA"]
[Mon Jul 20 06:07:20.721851 2026] [security2:error] [pid 796567:tid 796748] [client 185.226.198.7:17356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PeLLfyzVz2SrjZpjMSwAAAkc"], referer: http://laceycaraccident.com/js/NewWindow_2_all.js
[Mon Jul 20 06:07:20.849679 2026] [security2:error] [pid 832668:tid 832858] [client 115.246.21.170:24130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_tQAAADo"]
[Mon Jul 20 06:07:20.849826 2026] [security2:error] [pid 832668:tid 832858] [client 115.246.21.170:24130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PeGci6KgEEltqA3C_tQAAADo"]
[Mon Jul 20 06:07:20.863272 2026] [security2:error] [pid 796567:tid 796653] [remote 130.185.118.215:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4PeLLfyzVz2SrjZpjMZgACgFU"]
[Mon Jul 20 06:07:21.054480 2026] [security2:error] [pid 796567:tid 796606] [remote 130.185.118.215:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4PebLfyzVz2SrjZpjMcAACaCY"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:07:21.216551 2026] [security2:error] [pid 832668:tid 832906] [client 40.77.167.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4PeWci6KgEEltqA3C_ugAAAGo"]
[Mon Jul 20 06:07:21.306188 2026] [security2:error] [pid 796567:tid 796724] [client 50.116.65.227:58520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PebLfyzVz2SrjZpjMewAAAi8"]
[Mon Jul 20 06:07:21.317523 2026] [security2:error] [pid 832668:tid 832909] [client 50.116.65.227:58532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PeWci6KgEEltqA3C_xwAAAG0"]
[Mon Jul 20 06:07:21.636423 2026] [security2:error] [pid 832668:tid 832922] [client 57.141.18.118:31394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pcmci6KgEEltqA3C-nQAAehA"]
[Mon Jul 20 06:07:21.878364 2026] [security2:error] [pid 832668:tid 832900] [client 104.234.53.49:62987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PeWci6KgEEltqA3C_7AAAAGQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:22.030418 2026] [security2:error] [pid 832668:tid 832760] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_8QAAV1k"]
[Mon Jul 20 06:07:22.030592 2026] [security2:error] [pid 832668:tid 832887] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_8QAAV1k"]
[Mon Jul 20 06:07:22.182299 2026] [security2:error] [pid 832668:tid 832913] [client 103.95.123.246:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_9gAAAHE"]
[Mon Jul 20 06:07:22.182422 2026] [security2:error] [pid 832668:tid 832913] [client 103.95.123.246:17568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_9gAAAHE"]
[Mon Jul 20 06:07:22.184302 2026] [security2:error] [pid 796567:tid 796712] [client 45.116.69.230:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMlgAAAiM"]
[Mon Jul 20 06:07:22.184384 2026] [security2:error] [pid 796567:tid 796712] [client 45.116.69.230:58946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMlgAAAiM"]
[Mon Jul 20 06:07:22.188803 2026] [security2:error] [pid 832668:tid 832892] [client 14.225.17.146:53096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4PeWci6KgEEltqA3C_wQAAAFw"], referer: http://intelligentengineeringsolutions.com/Wordpress
[Mon Jul 20 06:07:22.230531 2026] [security2:error] [pid 796567:tid 796766] [client 14.225.17.146:49186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4PebLfyzVz2SrjZpjMbgAAAlk"]
[Mon Jul 20 06:07:22.337488 2026] [security2:error] [pid 832668:tid 832834] [client 185.132.186.67:53247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "al4Pemci6KgEEltqA3C_-wAAACI"]
[Mon Jul 20 06:07:22.356730 2026] [security2:error] [pid 796567:tid 796736] [client 46.201.22.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "memarion.com"] [uri "/wp-login.php"] [unique_id "al4PerLfyzVz2SrjZpjMmgAAAjs"]
[Mon Jul 20 06:07:22.448569 2026] [security2:error] [pid 796567:tid 796743] [client 41.173.37.102:5433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMnwAAAkI"]
[Mon Jul 20 06:07:22.448663 2026] [security2:error] [pid 796567:tid 796743] [client 41.173.37.102:5433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PerLfyzVz2SrjZpjMnwAAAkI"]
[Mon Jul 20 06:07:22.496774 2026] [security2:error] [pid 796567:tid 796776] [client 14.225.17.146:49364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4PebLfyzVz2SrjZpjMkAAAAmM"], referer: http://entuvy.com/Wordpress
[Mon Jul 20 06:07:22.504230 2026] [security2:error] [pid 796567:tid 796784] [client 57.141.18.108:20906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pc7LfyzVz2SrjZpjLpAACa34"]
[Mon Jul 20 06:07:22.736605 2026] [security2:error] [pid 832668:tid 832820] [client 193.56.28.190:26571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/wp-login.php/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3C_9wAAABQ"]
[Mon Jul 20 06:07:22.838412 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAGAAAAGo"]
[Mon Jul 20 06:07:22.838534 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAGAAAAGo"]
[Mon Jul 20 06:07:22.917113 2026] [security2:error] [pid 832668:tid 832827] [client 14.225.17.146:62847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4Pemci6KgEEltqA3DAFAAAABs"], referer: http://jvcmotorsports.com/Wordpress
[Mon Jul 20 06:07:22.972742 2026] [security2:error] [pid 832668:tid 832920] [client 181.224.94.124:29444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAIgAAAHg"]
[Mon Jul 20 06:07:22.972963 2026] [security2:error] [pid 832668:tid 832920] [client 181.224.94.124:29444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pemci6KgEEltqA3DAIgAAAHg"]
[Mon Jul 20 06:07:23.095330 2026] [security2:error] [pid 832668:tid 832785] [remote 74.235.96.117:38046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAKwAAa3I"]
[Mon Jul 20 06:07:23.095637 2026] [security2:error] [pid 832668:tid 832907] [client 74.235.96.117:38046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAKwAAa3I"]
[Mon Jul 20 06:07:23.302609 2026] [security2:error] [pid 832668:tid 832909] [client 27.96.94.195:37504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAPAAAAG0"]
[Mon Jul 20 06:07:23.302741 2026] [security2:error] [pid 832668:tid 832909] [client 27.96.94.195:37504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DAPAAAAG0"]
[Mon Jul 20 06:07:23.467012 2026] [security2:error] [pid 796567:tid 796650] [remote 152.228.213.32:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMtwACH1I"]
[Mon Jul 20 06:07:23.467301 2026] [security2:error] [pid 796567:tid 796708] [client 152.228.213.32:40470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMtwACH1I"]
[Mon Jul 20 06:07:23.491929 2026] [security2:error] [pid 796567:tid 796646] [remote 57.141.18.78:28222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4415964"] [unique_id "al4Pe7LfyzVz2SrjZpjMuAACKk4"]
[Mon Jul 20 06:07:23.627956 2026] [security2:error] [pid 832668:tid 832673] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DATwAAQgI"]
[Mon Jul 20 06:07:23.628200 2026] [security2:error] [pid 832668:tid 832866] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pe2ci6KgEEltqA3DATwAAQgI"]
[Mon Jul 20 06:07:23.831493 2026] [security2:error] [pid 796567:tid 796783] [client 193.56.28.190:53519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/wp-login.php/xmlrpc.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMvQAAAmo"]
[Mon Jul 20 06:07:24.220559 2026] [security2:error] [pid 796567:tid 796740] [client 14.225.17.146:63174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4PfLLfyzVz2SrjZpjMxQAAAj8"], referer: http://collectingrealestate.com/Wordpress
[Mon Jul 20 06:07:24.244483 2026] [security2:error] [pid 832668:tid 832837] [client 104.234.53.69:33121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PfGci6KgEEltqA3DAdQAAACU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:24.248877 2026] [security2:error] [pid 796567:tid 796797] [client 185.226.198.7:17366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pe7LfyzVz2SrjZpjMvgAAAng"], referer: http://laceycaraccident.com/index.jsp
[Mon Jul 20 06:07:24.264240 2026] [security2:error] [pid 832668:tid 832817] [client 57.141.18.114:34914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PdWci6KgEEltqA3C_CgAAETg"]
[Mon Jul 20 06:07:24.708799 2026] [security2:error] [pid 832668:tid 832810] [client 193.19.109.239:61429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4PfGci6KgEEltqA3DAiQAAAAo"]
[Mon Jul 20 06:07:24.888287 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:63120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAPgAAAFE"], referer: http://guidehunting.com/Wordpress
[Mon Jul 20 06:07:24.897677 2026] [security2:error] [pid 832668:tid 832890] [client 14.225.17.146:63002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DALAAAAFo"], referer: http://lelandumc.org/Wordpress
[Mon Jul 20 06:07:24.943874 2026] [security2:error] [pid 796567:tid 796741] [client 193.56.28.190:25703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/wp-login.php/xmlrpc.php"] [unique_id "al4PfLLfyzVz2SrjZpjM2QAAAkA"]
[Mon Jul 20 06:07:25.136655 2026] [security2:error] [pid 832668:tid 832863] [client 57.141.18.28:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pdmci6KgEEltqA3C_QQAAP0U"]
[Mon Jul 20 06:07:25.215794 2026] [security2:error] [pid 832668:tid 832908] [client 50.116.65.227:46618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4PfWci6KgEEltqA3DAnAAAAGw"]
[Mon Jul 20 06:07:25.220352 2026] [security2:error] [pid 796567:tid 796812] [client 14.225.17.146:63302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4PfLLfyzVz2SrjZpjMwwAAAoc"]
[Mon Jul 20 06:07:25.493320 2026] [security2:error] [pid 832668:tid 832812] [client 14.225.17.146:63425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4PfGci6KgEEltqA3DAiAAAAAw"], referer: http://processorstudio.com/Wordpress
[Mon Jul 20 06:07:25.579902 2026] [security2:error] [pid 796567:tid 796745] [client 185.132.186.59:47477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/Simple.php"] [unique_id "al4PfbLfyzVz2SrjZpjM8QAAAkQ"]
[Mon Jul 20 06:07:25.593067 2026] [security2:error] [pid 796567:tid 796608] [remote 31.42.184.154:32900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.184.42.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PfbLfyzVz2SrjZpjM8gACfyg"]
[Mon Jul 20 06:07:25.593445 2026] [security2:error] [pid 796567:tid 796804] [client 31.42.184.154:32900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PfbLfyzVz2SrjZpjM8gACfyg"]
[Mon Jul 20 06:07:25.774718 2026] [security2:error] [pid 832668:tid 832905] [client 14.225.17.146:63824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4PfWci6KgEEltqA3DApQAAAGk"]
[Mon Jul 20 06:07:26.086969 2026] [security2:error] [pid 832668:tid 832910] [client 198.44.157.34:47120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Pfmci6KgEEltqA3DA1QAAAG4"]
[Mon Jul 20 06:07:26.087115 2026] [security2:error] [pid 832668:tid 832910] [client 198.44.157.34:47120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Pfmci6KgEEltqA3DA1QAAAG4"]
[Mon Jul 20 06:07:26.175854 2026] [security2:error] [pid 796567:tid 796697] [client 14.225.17.146:63917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4PfbLfyzVz2SrjZpjM_AAAAhQ"], referer: https://guidehunting.com/Wordpress
[Mon Jul 20 06:07:26.223462 2026] [security2:error] [pid 832668:tid 832816] [client 14.225.17.146:63620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4PfWci6KgEEltqA3DAmAAAABA"], referer: http://sarahholyfield.com/Wordpress
[Mon Jul 20 06:07:26.322647 2026] [security2:error] [pid 796567:tid 796725] [client 193.19.109.234:60647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floorsourcestock.com"] [uri "/wp-login.php"] [unique_id "al4PfrLfyzVz2SrjZpjNBwAAAjA"]
[Mon Jul 20 06:07:26.331940 2026] [security2:error] [pid 796567:tid 796793] [client 193.37.33.2:39813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "floorsourcestock.com"] [uri "/wp-login.php"] [unique_id "al4PfrLfyzVz2SrjZpjNBgAAAnQ"]
[Mon Jul 20 06:07:26.341908 2026] [security2:error] [pid 832668:tid 832804] [client 193.56.28.190:49329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PfWci6KgEEltqA3DAzwAAAAQ"]
[Mon Jul 20 06:07:26.471408 2026] [security2:error] [pid 832668:tid 832900] [client 43.166.240.231:58116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.240.166.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DA-gAAAGQ"]
[Mon Jul 20 06:07:26.471596 2026] [security2:error] [pid 832668:tid 832863] [client 14.225.17.146:64128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DA-QAAAD8"], referer: https://processorstudio.com/Wordpress
[Mon Jul 20 06:07:26.694187 2026] [security2:error] [pid 796567:tid 796812] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../.env"] [unique_id "al4PfrLfyzVz2SrjZpjNHAAAAoc"], referer: https://www.bing.com/search?q=j1ceu7
[Mon Jul 20 06:07:26.836526 2026] [security2:error] [pid 832668:tid 832853] [client 41.140.27.137:24129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DBHwAAADU"]
[Mon Jul 20 06:07:26.858735 2026] [security2:error] [pid 796567:tid 796718] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../var/www/html/.env"] [unique_id "al4PfrLfyzVz2SrjZpjNIQAAAik"], referer: https://t.co/vsuax1xnwx
[Mon Jul 20 06:07:27.242179 2026] [core:error] [pid 832668:tid 832852] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:27.242202 2026] [core:error] [pid 832668:tid 832852] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:27.525366 2026] [security2:error] [pid 832668:tid 832899] [client 185.132.186.102:42695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBiwAAAGM"]
[Mon Jul 20 06:07:27.690516 2026] [security2:error] [pid 796567:tid 796708] [client 193.56.28.190:61175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4Pf7LfyzVz2SrjZpjNKQAAAh8"]
[Mon Jul 20 06:07:27.710326 2026] [security2:error] [pid 832668:tid 832867] [client 14.225.17.146:56809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBggAAAEM"], referer: http://worbals.com/Wordpress
[Mon Jul 20 06:07:27.775826 2026] [security2:error] [pid 796567:tid 796817] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pf7LfyzVz2SrjZpjNJwAAAow"], referer: http://laceycaraccident.com/login.do
[Mon Jul 20 06:07:27.809325 2026] [security2:error] [pid 832668:tid 832726] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pf2ci6KgEEltqA3DBmgAAZzc"]
[Mon Jul 20 06:07:27.809489 2026] [security2:error] [pid 832668:tid 832903] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pf2ci6KgEEltqA3DBmgAAZzc"]
[Mon Jul 20 06:07:27.837371 2026] [security2:error] [pid 796567:tid 796739] [client 57.141.18.114:34916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PeLLfyzVz2SrjZpjMYAACPkM"]
[Mon Jul 20 06:07:27.988697 2026] [proxy:error] [pid 832668:tid 832865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:27.988755 2026] [proxy_http:error] [pid 832668:tid 832865] [client 64.79.224.208:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:27.989461 2026] [proxy:error] [pid 832668:tid 832865] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:27.989502 2026] [proxy_http:error] [pid 832668:tid 832865] [client 64.79.224.208:38438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:28.346795 2026] [security2:error] [pid 796567:tid 796715] [client 14.225.17.146:64229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PfrLfyzVz2SrjZpjNHQAAAiY"], referer: http://nurturemarple.co.uk/Wordpress
[Mon Jul 20 06:07:28.392007 2026] [security2:error] [pid 796567:tid 796711] [client 14.225.17.146:52169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4Pf7LfyzVz2SrjZpjNMgAAAiI"], referer: http://partnerselectricalllc.com/Wordpress
[Mon Jul 20 06:07:28.713843 2026] [security2:error] [pid 832668:tid 832883] [client 14.225.17.146:64253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4Pfmci6KgEEltqA3DBIgAAAFM"], referer: http://amalia-capital.com/Wordpress
[Mon Jul 20 06:07:28.777497 2026] [security2:error] [pid 832668:tid 832804] [client 114.119.153.172:26085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nandansonscharitablefoundation.com"] [uri "/2021/08/"] [unique_id "al4PgGci6KgEEltqA3DB3QAAAAQ"], referer: https://nandansonscharitablefoundation.com/2021/02/06/thank-you-from-baps-swaminarayan-santhsa/
[Mon Jul 20 06:07:28.889062 2026] [security2:error] [pid 832668:tid 832892] [client 50.116.65.227:58650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PgGci6KgEEltqA3DBzwAAAFw"]
[Mon Jul 20 06:07:29.043984 2026] [security2:error] [pid 832668:tid 832885] [client 193.56.28.190:35233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4PgGci6KgEEltqA3DB1gAAAFU"]
[Mon Jul 20 06:07:29.092438 2026] [security2:error] [pid 796567:tid 796706] [client 50.116.65.227:58674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PgLLfyzVz2SrjZpjNVAAAAh0"]
[Mon Jul 20 06:07:29.166978 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.33:55822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pemci6KgEEltqA3C_8wAATjs"]
[Mon Jul 20 06:07:29.345951 2026] [security2:error] [pid 796567:tid 796801] [client 14.225.17.146:56971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4PgbLfyzVz2SrjZpjNWQAAAnw"], referer: https://nurturemarple.co.uk/Wordpress
[Mon Jul 20 06:07:29.441798 2026] [security2:error] [pid 832668:tid 832915] [client 103.141.108.143:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCBAAAAHM"]
[Mon Jul 20 06:07:29.441912 2026] [security2:error] [pid 832668:tid 832915] [client 103.141.108.143:63574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCBAAAAHM"]
[Mon Jul 20 06:07:29.635842 2026] [security2:error] [pid 832668:tid 832882] [client 87.199.196.181:55527] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.196.181" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4PgWci6KgEEltqA3DCDAAAAFI"], referer: https://www.friendlyspreadsheet.com/my-most-used-spreadsheet-contains-no-formulas/
[Mon Jul 20 06:07:29.635915 2026] [security2:error] [pid 832668:tid 832882] [client 87.199.196.181:55527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4PgWci6KgEEltqA3DCDAAAAFI"], referer: https://www.friendlyspreadsheet.com/my-most-used-spreadsheet-contains-no-formulas/
[Mon Jul 20 06:07:29.696414 2026] [security2:error] [pid 832668:tid 832871] [client 150.228.148.150:38329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCDgAAAEc"]
[Mon Jul 20 06:07:29.701504 2026] [security2:error] [pid 832668:tid 832871] [client 150.228.148.150:38329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCDgAAAEc"]
[Mon Jul 20 06:07:29.854949 2026] [security2:error] [pid 832668:tid 832910] [client 106.192.104.4:50363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCFQAAAG4"]
[Mon Jul 20 06:07:29.869511 2026] [security2:error] [pid 832668:tid 832910] [client 106.192.104.4:50363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PgWci6KgEEltqA3DCFQAAAG4"]
[Mon Jul 20 06:07:30.027618 2026] [security2:error] [pid 832668:tid 832857] [client 14.225.17.146:53397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBmwAAADk"], referer: http://cheesewithjam.com/Wordpress
[Mon Jul 20 06:07:30.087321 2026] [security2:error] [pid 796567:tid 796681] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNcQACaHE"]
[Mon Jul 20 06:07:30.087443 2026] [security2:error] [pid 796567:tid 796781] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNcQACaHE"]
[Mon Jul 20 06:07:30.298767 2026] [security2:error] [pid 832668:tid 832927] [client 57.141.18.84:54020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAQwAAf3o"]
[Mon Jul 20 06:07:30.320988 2026] [core:error] [pid 796567:tid 796725] [client 14.225.17.146:60698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:30.321011 2026] [core:error] [pid 796567:tid 796725] [client 14.225.17.146:60698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:30.354839 2026] [security2:error] [pid 832668:tid 832811] [client 35.209.224.174:39260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCLgAAAAs"]
[Mon Jul 20 06:07:30.470395 2026] [security2:error] [pid 832668:tid 832901] [client 185.226.198.5:35326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCHwAAAGU"], referer: http://laceycaraccident.com/favicon-32x32.png
[Mon Jul 20 06:07:30.486462 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.86:57697] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-admin/1.php"] [unique_id "al4Pgmci6KgEEltqA3DCOAAAAAI"]
[Mon Jul 20 06:07:30.486591 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.86:57697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/1.php"] [unique_id "al4Pgmci6KgEEltqA3DCOAAAAAI"]
[Mon Jul 20 06:07:30.629863 2026] [security2:error] [pid 832668:tid 832920] [client 57.141.18.121:38054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAWQAAeAw"]
[Mon Jul 20 06:07:30.688084 2026] [security2:error] [pid 832668:tid 832834] [client 57.141.18.113:44752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pe2ci6KgEEltqA3DAZAAAIgQ"]
[Mon Jul 20 06:07:30.698506 2026] [security2:error] [pid 796567:tid 796764] [client 193.19.109.220:24951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4PgrLfyzVz2SrjZpjNigAAAlc"]
[Mon Jul 20 06:07:30.885983 2026] [security2:error] [pid 832668:tid 832868] [client 74.7.227.179:54936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCSQAARBY"], referer: https://tejasenvironmental.com/p=3792676
[Mon Jul 20 06:07:30.920877 2026] [security2:error] [pid 796567:tid 796678] [remote 91.142.222.105:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PgrLfyzVz2SrjZpjNjgACeW4"]
[Mon Jul 20 06:07:30.935310 2026] [security2:error] [pid 796567:tid 796761] [client 112.213.160.112:30987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNjwAAAlQ"]
[Mon Jul 20 06:07:30.935447 2026] [security2:error] [pid 796567:tid 796761] [client 112.213.160.112:30987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PgrLfyzVz2SrjZpjNjwAAAlQ"]
[Mon Jul 20 06:07:30.991300 2026] [security2:error] [pid 832668:tid 832915] [client 103.77.203.233:57496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pgmci6KgEEltqA3DCUwAAAHM"]
[Mon Jul 20 06:07:30.991419 2026] [security2:error] [pid 832668:tid 832915] [client 103.77.203.233:57496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pgmci6KgEEltqA3DCUwAAAHM"]
[Mon Jul 20 06:07:31.067121 2026] [security2:error] [pid 796567:tid 796733] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../var/www/.env"] [unique_id "al4Pg7LfyzVz2SrjZpjNkwAAAjg"], referer: https://www.google.com/
[Mon Jul 20 06:07:31.083525 2026] [security2:error] [pid 796567:tid 796717] [client 86.98.90.58:60693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNlAAAAig"]
[Mon Jul 20 06:07:31.083616 2026] [security2:error] [pid 796567:tid 796717] [client 86.98.90.58:60693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNlAAAAig"]
[Mon Jul 20 06:07:31.127449 2026] [security2:error] [pid 796567:tid 796815] [client 50.116.65.227:32680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Pg7LfyzVz2SrjZpjNlgAAAoo"]
[Mon Jul 20 06:07:31.138358 2026] [security2:error] [pid 832668:tid 832885] [client 50.116.65.227:32696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Pg2ci6KgEEltqA3DCYgAAAFU"]
[Mon Jul 20 06:07:31.220634 2026] [security2:error] [pid 796567:tid 796706] [client 103.153.183.69:35286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//var/www/html/wp-config.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNlwAAAh0"], referer: https://www.bing.com/search?q=p0vyi4
[Mon Jul 20 06:07:31.423429 2026] [security2:error] [pid 832668:tid 832910] [client 115.246.21.170:55099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg2ci6KgEEltqA3DCdAAAAG4"]
[Mon Jul 20 06:07:31.423559 2026] [security2:error] [pid 832668:tid 832910] [client 115.246.21.170:55099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg2ci6KgEEltqA3DCdAAAAG4"]
[Mon Jul 20 06:07:31.564970 2026] [security2:error] [pid 832668:tid 832810] [client 185.226.198.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pg2ci6KgEEltqA3DCWQAAAAo"], referer: http://laceycaraccident.com/showLogin.cc
[Mon Jul 20 06:07:31.686621 2026] [security2:error] [pid 832668:tid 832886] [client 104.234.53.55:47359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pg2ci6KgEEltqA3DCggAAAFY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:31.872668 2026] [security2:error] [pid 796567:tid 796605] [remote 8.217.108.67:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNqgACGiU"]
[Mon Jul 20 06:07:31.884117 2026] [security2:error] [pid 796567:tid 796765] [client 45.116.69.230:59410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNrAAAAlg"]
[Mon Jul 20 06:07:31.884270 2026] [security2:error] [pid 796567:tid 796765] [client 45.116.69.230:59410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pg7LfyzVz2SrjZpjNrAAAAlg"]
[Mon Jul 20 06:07:32.228076 2026] [security2:error] [pid 832668:tid 832755] [remote 15.206.251.117:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCpQAAaVQ"]
[Mon Jul 20 06:07:32.406724 2026] [security2:error] [pid 832668:tid 832699] [remote 91.142.222.105:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCsAAAARw"]
[Mon Jul 20 06:07:32.491530 2026] [security2:error] [pid 832668:tid 832870] [client 185.132.186.78:55711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/ocean/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCsQAAAEY"]
[Mon Jul 20 06:07:32.666269 2026] [security2:error] [pid 832668:tid 832790] [remote 15.206.251.117:54574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DCwgAAKHc"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:07:32.694520 2026] [security2:error] [pid 832668:tid 832795] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PhGci6KgEEltqA3DCwwAAPnw"]
[Mon Jul 20 06:07:32.694671 2026] [security2:error] [pid 832668:tid 832862] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PhGci6KgEEltqA3DCwwAAPnw"]
[Mon Jul 20 06:07:32.902911 2026] [security2:error] [pid 796567:tid 796606] [remote 8.217.108.67:17900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PhLLfyzVz2SrjZpjNwAAChyY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:07:32.968033 2026] [security2:error] [pid 796567:tid 796736] [client 57.141.18.113:22964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PfrLfyzVz2SrjZpjM_wACO2g"]
[Mon Jul 20 06:07:33.000131 2026] [security2:error] [pid 832668:tid 832738] [remote 91.142.222.105:45978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4PhGci6KgEEltqA3DC2gAAF0M"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:07:33.024391 2026] [security2:error] [pid 796567:tid 796665] [remote 91.142.222.105:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PhbLfyzVz2SrjZpjNwgACQ2E"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:07:33.043121 2026] [security2:error] [pid 832668:tid 832806] [client 46.110.96.34:17651] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4PhWci6KgEEltqA3DC3gAAAAY"]
[Mon Jul 20 06:07:33.043767 2026] [security2:error] [pid 832668:tid 832827] [client 46.110.96.34:38553] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4PhWci6KgEEltqA3DC3wAAABs"]
[Mon Jul 20 06:07:33.146630 2026] [security2:error] [pid 832668:tid 832859] [client 41.173.37.102:5880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC5wAAADs"]
[Mon Jul 20 06:07:33.146725 2026] [security2:error] [pid 832668:tid 832859] [client 41.173.37.102:5880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC5wAAADs"]
[Mon Jul 20 06:07:33.153942 2026] [security2:error] [pid 832668:tid 832747] [remote 220.181.108.146:13299] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4PhWci6KgEEltqA3DC6QAAZUw"]
[Mon Jul 20 06:07:33.342633 2026] [security2:error] [pid 796567:tid 796774] [client 27.96.94.195:37676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNygAAAmE"]
[Mon Jul 20 06:07:33.342731 2026] [security2:error] [pid 796567:tid 796774] [client 27.96.94.195:37676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNygAAAmE"]
[Mon Jul 20 06:07:33.358117 2026] [security2:error] [pid 832668:tid 832842] [client 74.208.214.194:46268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PhWci6KgEEltqA3DC9AAAACo"]
[Mon Jul 20 06:07:33.530810 2026] [security2:error] [pid 796567:tid 796761] [client 181.224.94.124:57139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNzQAAAlQ"]
[Mon Jul 20 06:07:33.530950 2026] [security2:error] [pid 796567:tid 796761] [client 181.224.94.124:57139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PhbLfyzVz2SrjZpjNzQAAAlQ"]
[Mon Jul 20 06:07:33.535860 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:18423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC_wAAAGM"]
[Mon Jul 20 06:07:33.536017 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:18423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DC_wAAAGM"]
[Mon Jul 20 06:07:33.620134 2026] [security2:error] [pid 832668:tid 832886] [client 178.152.178.232:37353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DDAwAAAFY"]
[Mon Jul 20 06:07:33.620268 2026] [security2:error] [pid 832668:tid 832886] [client 178.152.178.232:37353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PhWci6KgEEltqA3DDAwAAAFY"]
[Mon Jul 20 06:07:33.749156 2026] [security2:error] [pid 832668:tid 832908] [client 57.141.18.29:23412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBSAAAbBI"]
[Mon Jul 20 06:07:34.122859 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.115:60678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pf2ci6KgEEltqA3DBfwAAZBs"]
[Mon Jul 20 06:07:34.234970 2026] [security2:error] [pid 796567:tid 796569] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PhrLfyzVz2SrjZpjN3wACegE"]
[Mon Jul 20 06:07:34.235184 2026] [security2:error] [pid 796567:tid 796799] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PhrLfyzVz2SrjZpjN3wACegE"]
[Mon Jul 20 06:07:34.252372 2026] [security2:error] [pid 832668:tid 832782] [remote 119.249.100.50:35717] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4Phmci6KgEEltqA3DDJAAAW28"]
[Mon Jul 20 06:07:34.421287 2026] [security2:error] [pid 832668:tid 832811] [client 104.234.53.90:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Phmci6KgEEltqA3DDLwAAAAs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:34.438680 2026] [security2:error] [pid 832668:tid 832841] [client 185.132.186.77:34629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "al4Phmci6KgEEltqA3DDMAAAACk"]
[Mon Jul 20 06:07:34.644732 2026] [security2:error] [pid 796567:tid 796739] [client 114.119.158.112:38551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.phillipbloch.com"] [uri "/robots.txt"] [unique_id "al4PhrLfyzVz2SrjZpjN7AAAAj4"], referer: http://www.phillipbloch.com/robots.txt
[Mon Jul 20 06:07:34.644844 2026] [security2:error] [pid 832668:tid 832778] [remote 162.19.86.63:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4Phmci6KgEEltqA3DDOQAAQms"]
[Mon Jul 20 06:07:34.758280 2026] [proxy:error] [pid 832668:tid 832753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:34.758318 2026] [proxy_http:error] [pid 832668:tid 832753] [remote 158.222.112.12:56924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:34.759027 2026] [proxy:error] [pid 832668:tid 832753] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:34.759052 2026] [proxy_http:error] [pid 832668:tid 832753] [remote 158.222.112.12:56924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:34.843184 2026] [security2:error] [pid 832668:tid 832774] [remote 162.19.86.63:50734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4Phmci6KgEEltqA3DDSAAAdWc"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:07:34.945072 2026] [security2:error] [pid 832668:tid 832824] [client 185.226.198.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Phmci6KgEEltqA3DDNAAAABg"], referer: http://laceycaraccident.com/solr/#/
[Mon Jul 20 06:07:35.598021 2026] [security2:error] [pid 832668:tid 832814] [client 57.141.18.72:27450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PgGci6KgEEltqA3DB2gAADlw"]
[Mon Jul 20 06:07:35.701902 2026] [security2:error] [pid 832668:tid 832804] [client 14.225.17.146:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4Ph2ci6KgEEltqA3DDbgAAAAQ"], referer: http://betterbonddogtraining.com/Wordpress
[Mon Jul 20 06:07:35.856131 2026] [security2:error] [pid 832668:tid 832802] [client 14.225.17.146:61257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4Phmci6KgEEltqA3DDLgAAAAI"], referer: http://dnsplumbing.com/Wordpress
[Mon Jul 20 06:07:35.859600 2026] [security2:error] [pid 796567:tid 796730] [client 49.13.167.123:7318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4Ph7LfyzVz2SrjZpjODwAAAjU"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:07:35.921797 2026] [security2:error] [pid 796567:tid 796801] [client 14.225.17.146:60054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4PhrLfyzVz2SrjZpjN2AAAAnw"], referer: http://ksands.co.uk/Wordpress
[Mon Jul 20 06:07:36.057371 2026] [security2:error] [pid 796567:tid 796824] [client 114.119.148.169:46035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/crochet-course-farnham-surrey/"] [unique_id "al4PiLLfyzVz2SrjZpjOGwAAApM"], referer: https://www.mezzacraft.com/learn-to-crochet-course-surrey-2020-2
[Mon Jul 20 06:07:36.387485 2026] [security2:error] [pid 832668:tid 832812] [client 185.132.186.102:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/classwithtostring.php"] [unique_id "al4PiGci6KgEEltqA3DDqAAAAAw"]
[Mon Jul 20 06:07:36.469490 2026] [security2:error] [pid 832668:tid 832711] [remote 111.225.214.198:32295] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4PiGci6KgEEltqA3DDrAAANCg"]
[Mon Jul 20 06:07:36.579584 2026] [security2:error] [pid 796567:tid 796757] [client 57.141.18.42:47342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PgbLfyzVz2SrjZpjNaAACUG0"]
[Mon Jul 20 06:07:36.842048 2026] [security2:error] [pid 832668:tid 832862] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PiGci6KgEEltqA3DDwQAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:36.908918 2026] [security2:error] [pid 832668:tid 832821] [client 98.159.234.160:42347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PiGci6KgEEltqA3DD1AAAABU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:37.421349 2026] [security2:error] [pid 832668:tid 832779] [remote 81.173.115.7:40096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4PiWci6KgEEltqA3DEBAAAVGw"]
[Mon Jul 20 06:07:37.447147 2026] [security2:error] [pid 832668:tid 832844] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PiGci6KgEEltqA3DD1wAAACw"], referer: http://laceycaraccident.com/Telerik.Web.UI.WebResource.axd?type=rau
[Mon Jul 20 06:07:37.617546 2026] [security2:error] [pid 832668:tid 832677] [remote 81.173.115.7:40096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4PiWci6KgEEltqA3DEDAAAGQY"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 06:07:37.636369 2026] [security2:error] [pid 832668:tid 832865] [client 57.141.18.91:23556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pgmci6KgEEltqA3DCQwAAQQs"]
[Mon Jul 20 06:07:37.710467 2026] [security2:error] [pid 832668:tid 832905] [client 14.225.17.146:53327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4PiGci6KgEEltqA3DDnAAAAGk"], referer: http://ghivs.com/Wordpress
[Mon Jul 20 06:07:38.124178 2026] [security2:error] [pid 832668:tid 832816] [client 172.190.117.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4Pimci6KgEEltqA3DEIwAAABA"]
[Mon Jul 20 06:07:38.333471 2026] [security2:error] [pid 832668:tid 832713] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pimci6KgEEltqA3DEOAAARSo"]
[Mon Jul 20 06:07:38.333679 2026] [security2:error] [pid 832668:tid 832869] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pimci6KgEEltqA3DEOAAARSo"]
[Mon Jul 20 06:07:38.335269 2026] [security2:error] [pid 832668:tid 832876] [client 185.132.186.55:23961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/av.php"] [unique_id "al4Pimci6KgEEltqA3DEOQAAAEw"]
[Mon Jul 20 06:07:38.662270 2026] [security2:error] [pid 832668:tid 832892] [client 47.129.222.11:51710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pimci6KgEEltqA3DETgAAAFw"]
[Mon Jul 20 06:07:38.816702 2026] [security2:error] [pid 832668:tid 832820] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pimci6KgEEltqA3DEUAAAABQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:39.228613 2026] [security2:error] [pid 832668:tid 832868] [client 57.141.18.56:44536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pg2ci6KgEEltqA3DCjQAARBc"]
[Mon Jul 20 06:07:39.425090 2026] [security2:error] [pid 832668:tid 832866] [client 185.226.198.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pimci6KgEEltqA3DEYgAAAEI"], referer: http://laceycaraccident.com/api/session/properties
[Mon Jul 20 06:07:39.562932 2026] [security2:error] [pid 832668:tid 832807] [client 13.229.223.11:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pi2ci6KgEEltqA3DEegAAAAc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:07:39.904050 2026] [security2:error] [pid 832668:tid 832871] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pi2ci6KgEEltqA3DEkwAAAEc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:40.228147 2026] [security2:error] [pid 832668:tid 832884] [client 103.141.108.143:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DErAAAAFQ"]
[Mon Jul 20 06:07:40.228843 2026] [security2:error] [pid 832668:tid 832884] [client 103.141.108.143:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DErAAAAFQ"]
[Mon Jul 20 06:07:40.289293 2026] [security2:error] [pid 796567:tid 796724] [client 185.132.186.89:32743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/waf_defender.php"] [unique_id "al4PjLLfyzVz2SrjZpjOeAAAAi8"]
[Mon Jul 20 06:07:40.298840 2026] [autoindex:error] [pid 796567:tid 796774] [client 141.98.11.42:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Ahi/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://www.binance.com
[Mon Jul 20 06:07:40.471380 2026] [security2:error] [pid 832668:tid 832910] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PjGci6KgEEltqA3DEtAAAAG4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:40.522585 2026] [security2:error] [pid 832668:tid 832894] [client 106.192.104.4:50859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DEuQAAAF4"]
[Mon Jul 20 06:07:40.527213 2026] [security2:error] [pid 832668:tid 832894] [client 106.192.104.4:50859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DEuQAAAF4"]
[Mon Jul 20 06:07:40.556544 2026] [security2:error] [pid 832668:tid 832899] [client 50.116.65.227:15098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PjGci6KgEEltqA3DEvQAAAGM"]
[Mon Jul 20 06:07:40.559042 2026] [security2:error] [pid 832668:tid 832879] [client 57.141.18.18:50988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PhWci6KgEEltqA3DC4QAATx8"]
[Mon Jul 20 06:07:40.565508 2026] [security2:error] [pid 832668:tid 832892] [client 50.116.65.227:15114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PjGci6KgEEltqA3DEwgAAAFw"]
[Mon Jul 20 06:07:40.639390 2026] [core:error] [pid 796567:tid 796822] [client 198.235.24.58:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:40.639418 2026] [core:error] [pid 796567:tid 796822] [client 198.235.24.58:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:40.738901 2026] [security2:error] [pid 832668:tid 832793] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE0gAAJ3o"]
[Mon Jul 20 06:07:40.739068 2026] [security2:error] [pid 832668:tid 832839] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE0gAAJ3o"]
[Mon Jul 20 06:07:40.748542 2026] [security2:error] [pid 832668:tid 832835] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PjGci6KgEEltqA3DEzwAAACM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:40.787917 2026] [security2:error] [pid 832668:tid 832803] [client 116.179.33.83:23038] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4PjGci6KgEEltqA3DE2AAAAAM"]
[Mon Jul 20 06:07:40.837506 2026] [security2:error] [pid 832668:tid 832877] [client 14.225.17.146:53638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Pimci6KgEEltqA3DEQQAAAE0"], referer: http://healthylifegourmet.org/Wordpress
[Mon Jul 20 06:07:40.848358 2026] [security2:error] [pid 832668:tid 832811] [client 31.50.30.70:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.30.50.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE2gAAAAs"]
[Mon Jul 20 06:07:40.848513 2026] [security2:error] [pid 832668:tid 832811] [client 31.50.30.70:58556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz"] [uri "/xmlrpc.php"] [unique_id "al4PjGci6KgEEltqA3DE2gAAAAs"]
[Mon Jul 20 06:07:41.227274 2026] [security2:error] [pid 832668:tid 832894] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PjWci6KgEEltqA3DE9QAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:41.293674 2026] [security2:error] [pid 832668:tid 832837] [client 50.116.65.227:15148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/03/IMG_3040-1.jpeg"] [unique_id "al4PjWci6KgEEltqA3DFCAAAAEo"]
[Mon Jul 20 06:07:41.358274 2026] [security2:error] [pid 832668:tid 832907] [client 57.141.18.16:55106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PhWci6KgEEltqA3DDGAAAa1Y"]
[Mon Jul 20 06:07:41.440221 2026] [security2:error] [pid 832668:tid 832857] [client 103.77.203.233:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFEwAAADk"]
[Mon Jul 20 06:07:41.440394 2026] [security2:error] [pid 832668:tid 832857] [client 103.77.203.233:57556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFEwAAADk"]
[Mon Jul 20 06:07:41.481036 2026] [security2:error] [pid 832668:tid 832858] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PjWci6KgEEltqA3DFEgAAADo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:41.686822 2026] [security2:error] [pid 832668:tid 832882] [client 112.213.160.112:8507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFKgAAAFI"]
[Mon Jul 20 06:07:41.687608 2026] [security2:error] [pid 832668:tid 832882] [client 112.213.160.112:8507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFKgAAAFI"]
[Mon Jul 20 06:07:41.845373 2026] [security2:error] [pid 832668:tid 832690] [remote 45.90.123.233:38104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFNAAAXxM"]
[Mon Jul 20 06:07:41.845495 2026] [security2:error] [pid 832668:tid 832895] [client 45.90.123.233:38104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PjWci6KgEEltqA3DFNAAAXxM"]
[Mon Jul 20 06:07:42.001035 2026] [security2:error] [pid 832668:tid 832803] [client 115.246.21.170:8618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFOAAAAAM"]
[Mon Jul 20 06:07:42.001149 2026] [security2:error] [pid 832668:tid 832803] [client 115.246.21.170:8618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFOAAAAAM"]
[Mon Jul 20 06:07:42.198995 2026] [security2:error] [pid 796567:tid 796783] [client 202.50.55.150:61871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/.env"] [unique_id "al4PjrLfyzVz2SrjZpjOpwAAAmo"]
[Mon Jul 20 06:07:42.223955 2026] [security2:error] [pid 832668:tid 832911] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DFLQAAAG8"], referer: http://laceycaraccident.com/zabbix/favicon.ico
[Mon Jul 20 06:07:42.232176 2026] [security2:error] [pid 796567:tid 796732] [client 185.132.186.95:52105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Cache/upfile.php"] [unique_id "al4PjrLfyzVz2SrjZpjOqQAAAjc"]
[Mon Jul 20 06:07:42.242169 2026] [security2:error] [pid 832668:tid 832885] [client 57.141.18.0:29892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Phmci6KgEEltqA3DDIwAAVWg"]
[Mon Jul 20 06:07:42.400298 2026] [security2:error] [pid 832668:tid 832823] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pjmci6KgEEltqA3DFWgAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:42.516031 2026] [security2:error] [pid 832668:tid 832869] [client 14.225.17.146:50004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DE7gAAAEU"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/Wordpress
[Mon Jul 20 06:07:42.517149 2026] [security2:error] [pid 832668:tid 832806] [client 202.50.55.150:61889] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/conf/.env"] [unique_id "al4Pjmci6KgEEltqA3DFZgAAAAY"]
[Mon Jul 20 06:07:42.578041 2026] [security2:error] [pid 832668:tid 832913] [client 45.116.69.230:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFaQAAAHE"]
[Mon Jul 20 06:07:42.578147 2026] [security2:error] [pid 832668:tid 832913] [client 45.116.69.230:59858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pjmci6KgEEltqA3DFaQAAAHE"]
[Mon Jul 20 06:07:42.835012 2026] [security2:error] [pid 832668:tid 832834] [client 202.50.55.150:61907] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/wp-content/.env"] [unique_id "al4Pjmci6KgEEltqA3DFcQAAACI"]
[Mon Jul 20 06:07:42.864295 2026] [security2:error] [pid 832668:tid 832919] [client 57.141.18.105:59626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ph2ci6KgEEltqA3DDbwAAd10"]
[Mon Jul 20 06:07:43.084800 2026] [security2:error] [pid 832668:tid 832819] [client 14.225.17.146:49972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DFDwAAABM"], referer: http://bnb-engineering.com/Wordpress
[Mon Jul 20 06:07:43.146203 2026] [security2:error] [pid 832668:tid 832912] [client 202.50.55.150:61925] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/wp-admin/.env"] [unique_id "al4Pj2ci6KgEEltqA3DFjwAAAHA"]
[Mon Jul 20 06:07:43.386314 2026] [security2:error] [pid 832668:tid 832689] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFmQAATxI"]
[Mon Jul 20 06:07:43.386453 2026] [security2:error] [pid 832668:tid 832879] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFmQAATxI"]
[Mon Jul 20 06:07:43.456334 2026] [security2:error] [pid 796567:tid 796730] [client 202.50.55.150:61937] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/library/.env"] [unique_id "al4Pj7LfyzVz2SrjZpjOywAAAjU"]
[Mon Jul 20 06:07:43.526085 2026] [security2:error] [pid 832668:tid 832760] [remote 217.61.143.92:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Pj2ci6KgEEltqA3DFogAAVFk"]
[Mon Jul 20 06:07:43.526903 2026] [security2:error] [pid 832668:tid 832831] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFoAAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:43.636836 2026] [security2:error] [pid 796567:tid 796590] [remote 45.90.123.233:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pj7LfyzVz2SrjZpjO0QACKBY"]
[Mon Jul 20 06:07:43.639474 2026] [proxy:error] [pid 796567:tid 796764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:43.639533 2026] [proxy_http:error] [pid 796567:tid 796764] [client 178.73.242.130:27447] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:43.640241 2026] [proxy:error] [pid 796567:tid 796764] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:43.640268 2026] [proxy_http:error] [pid 796567:tid 796764] [client 178.73.242.130:27447] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:43.718601 2026] [security2:error] [pid 796567:tid 796821] [client 57.141.18.46:62838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PiLLfyzVz2SrjZpjOJAACkE4"]
[Mon Jul 20 06:07:43.752072 2026] [security2:error] [pid 832668:tid 832816] [client 41.173.37.102:6432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFrAAAABA"]
[Mon Jul 20 06:07:43.752183 2026] [security2:error] [pid 832668:tid 832816] [client 41.173.37.102:6432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pj2ci6KgEEltqA3DFrAAAABA"]
[Mon Jul 20 06:07:43.752759 2026] [security2:error] [pid 832668:tid 832852] [client 14.225.17.146:49739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFowAAADQ"], referer: http://mezzacraft.com/Wordpress
[Mon Jul 20 06:07:43.765993 2026] [security2:error] [pid 832668:tid 832864] [client 202.50.55.150:61945] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/new/.env"] [unique_id "al4Pj2ci6KgEEltqA3DFsQAAAEA"]
[Mon Jul 20 06:07:43.783623 2026] [autoindex:error] [pid 796567:tid 796765] [client 49.234.192.248:0] AH01276: Cannot serve directory /home3/elemeqg5/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.elementalkneads.com
[Mon Jul 20 06:07:43.835346 2026] [security2:error] [pid 796567:tid 796573] [remote 45.90.123.233:38106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pj7LfyzVz2SrjZpjO3QACXQU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:07:43.865372 2026] [security2:error] [pid 832668:tid 832698] [remote 156.59.198.136:47252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nurturemarple.co.uk"] [uri "/wp-content/uploads/2016/02/Nurture-Newsletter_Preschool-Room_Apr16.pdf"] [unique_id "al4Pj2ci6KgEEltqA3DFvAAAOBs"]
[Mon Jul 20 06:07:43.884799 2026] [security2:error] [pid 832668:tid 832737] [remote 217.61.143.92:53370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Pj2ci6KgEEltqA3DFvwAAFkI"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:07:43.918063 2026] [security2:error] [pid 832668:tid 832834] [client 14.225.17.146:59180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFuQAAACI"], referer: http://katsklar.com/Wordpress
[Mon Jul 20 06:07:44.051001 2026] [security2:error] [pid 832668:tid 832876] [client 181.224.94.124:2202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PkGci6KgEEltqA3DFxQAAAEw"]
[Mon Jul 20 06:07:44.051124 2026] [security2:error] [pid 832668:tid 832876] [client 181.224.94.124:2202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PkGci6KgEEltqA3DFxQAAAEw"]
[Mon Jul 20 06:07:44.077241 2026] [security2:error] [pid 796567:tid 796798] [client 202.50.55.150:61959] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/vendor/.env"] [unique_id "al4PkLLfyzVz2SrjZpjO5AAAAnk"]
[Mon Jul 20 06:07:44.144787 2026] [security2:error] [pid 796567:tid 796805] [client 74.208.214.194:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PkLLfyzVz2SrjZpjO5wAAAoA"]
[Mon Jul 20 06:07:44.211082 2026] [security2:error] [pid 796567:tid 796585] [remote 217.61.143.92:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4PkLLfyzVz2SrjZpjO6gACkxE"]
[Mon Jul 20 06:07:44.388043 2026] [security2:error] [pid 796567:tid 796752] [client 202.50.55.150:61973] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/old/.env"] [unique_id "al4PkLLfyzVz2SrjZpjO8AAAAks"]
[Mon Jul 20 06:07:44.412295 2026] [security2:error] [pid 832668:tid 832774] [remote 57.141.18.107:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5916983"] [unique_id "al4PkGci6KgEEltqA3DF0wAAYGc"]
[Mon Jul 20 06:07:44.427995 2026] [security2:error] [pid 796567:tid 796741] [client 57.141.18.109:31976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PibLfyzVz2SrjZpjOMAACQE8"]
[Mon Jul 20 06:07:44.446093 2026] [security2:error] [pid 796567:tid 796660] [remote 217.61.143.92:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4PkLLfyzVz2SrjZpjO-AACZVw"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 06:07:44.698404 2026] [security2:error] [pid 796567:tid 796716] [client 202.50.55.150:61981] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/local/.env"] [unique_id "al4PkLLfyzVz2SrjZpjPBAAAAic"]
[Mon Jul 20 06:07:44.708790 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PkGci6KgEEltqA3DF2wAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:44.797733 2026] [security2:error] [pid 796567:tid 796621] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPCQACUTU"]
[Mon Jul 20 06:07:44.797954 2026] [security2:error] [pid 796567:tid 796758] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPCQACUTU"]
[Mon Jul 20 06:07:44.954298 2026] [security2:error] [pid 796567:tid 796711] [client 103.95.123.246:18971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPEAAAAiI"]
[Mon Jul 20 06:07:44.954407 2026] [security2:error] [pid 796567:tid 796711] [client 103.95.123.246:18971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PkLLfyzVz2SrjZpjPEAAAAiI"]
[Mon Jul 20 06:07:45.016899 2026] [security2:error] [pid 796567:tid 796781] [client 202.50.55.150:61994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/api/.env"] [unique_id "al4PkbLfyzVz2SrjZpjPEgAAAmg"]
[Mon Jul 20 06:07:45.018971 2026] [security2:error] [pid 832668:tid 832807] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PkGci6KgEEltqA3DF8QAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:45.019430 2026] [security2:error] [pid 832668:tid 832925] [client 94.154.43.188:48308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al4PkWci6KgEEltqA3DF9wAAAH0"]
[Mon Jul 20 06:07:45.199877 2026] [security2:error] [pid 832668:tid 832895] [client 185.132.186.81:52807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/small.php"] [unique_id "al4PkWci6KgEEltqA3DF_AAAAF8"]
[Mon Jul 20 06:07:45.322369 2026] [security2:error] [pid 796567:tid 796769] [client 94.154.43.184:19772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.scoophouse.com"] [uri "/.env"] [unique_id "al4PkbLfyzVz2SrjZpjPFwAAAlw"]
[Mon Jul 20 06:07:45.342992 2026] [security2:error] [pid 796567:tid 796714] [client 202.50.55.150:62004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/blog/.env"] [unique_id "al4PkbLfyzVz2SrjZpjPGAAAAiU"]
[Mon Jul 20 06:07:45.382293 2026] [security2:error] [pid 832668:tid 832903] [client 172.225.80.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFjAAAAGc"]
[Mon Jul 20 06:07:45.543136 2026] [security2:error] [pid 832668:tid 832829] [client 14.225.17.146:59209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFkgAAAB0"], referer: http://securingmemories.com/Wordpress
[Mon Jul 20 06:07:45.675999 2026] [security2:error] [pid 832668:tid 832906] [client 202.50.55.150:62015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/crm/.env"] [unique_id "al4PkWci6KgEEltqA3DGFgAAAGo"]
[Mon Jul 20 06:07:45.955608 2026] [core:error] [pid 832668:tid 832819] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:45.955633 2026] [core:error] [pid 832668:tid 832819] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:46.011770 2026] [security2:error] [pid 832668:tid 832914] [client 57.141.18.53:34602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pi2ci6KgEEltqA3DEZQAAcho"]
[Mon Jul 20 06:07:46.077291 2026] [security2:error] [pid 832668:tid 832844] [client 57.141.18.44:27008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pi2ci6KgEEltqA3DEZgAALCU"]
[Mon Jul 20 06:07:46.313225 2026] [security2:error] [pid 832668:tid 832909] [client 185.226.198.5:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PkWci6KgEEltqA3DGGQAAAG0"], referer: http://laceycaraccident.com/static/historypage.js
[Mon Jul 20 06:07:46.337714 2026] [security2:error] [pid 832668:tid 832921] [client 202.50.55.150:62039] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/laravel/.env"] [unique_id "al4Pkmci6KgEEltqA3DGPAAAAHk"]
[Mon Jul 20 06:07:46.566071 2026] [security2:error] [pid 796567:tid 796715] [client 14.225.17.146:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4PkLLfyzVz2SrjZpjPDwAAAiY"], referer: http://margaretspeckogawa.com/Wordpress
[Mon Jul 20 06:07:46.602437 2026] [security2:error] [pid 832668:tid 832888] [client 116.204.96.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGSwAAWFY"], referer: https://www.aleishapenny.ca/listing/page/560?paged=560&view=grid
[Mon Jul 20 06:07:46.648465 2026] [security2:error] [pid 832668:tid 832822] [client 202.50.55.150:62053] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/app/.env"] [unique_id "al4Pkmci6KgEEltqA3DGWAAAABY"]
[Mon Jul 20 06:07:46.958225 2026] [security2:error] [pid 796567:tid 796799] [client 202.50.55.150:62064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/app/config/.env"] [unique_id "al4PkrLfyzVz2SrjZpjPPwAAAno"]
[Mon Jul 20 06:07:47.141721 2026] [security2:error] [pid 832668:tid 832898] [client 185.132.186.54:50243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/about.php"] [unique_id "al4Pk2ci6KgEEltqA3DGfQAAAGI"]
[Mon Jul 20 06:07:47.284696 2026] [security2:error] [pid 832668:tid 832896] [client 202.50.55.150:62076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/apps/.env"] [unique_id "al4Pk2ci6KgEEltqA3DGgwAAAGA"]
[Mon Jul 20 06:07:47.407965 2026] [security2:error] [pid 796567:tid 796779] [client 14.225.17.146:53751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPRAAAAmY"], referer: http://adultdaycarereno.com/Wordpress
[Mon Jul 20 06:07:47.513847 2026] [security2:error] [pid 832668:tid 832899] [client 158.173.166.181:59469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Pk2ci6KgEEltqA3DGlAAAAGM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:07:47.590293 2026] [security2:error] [pid 832668:tid 832824] [client 57.141.18.113:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjGci6KgEEltqA3DE0AAAGAE"]
[Mon Jul 20 06:07:47.611067 2026] [security2:error] [pid 796567:tid 796786] [client 202.50.55.150:62087] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/audio/.env"] [unique_id "al4Pk7LfyzVz2SrjZpjPSwAAAm0"]
[Mon Jul 20 06:07:47.814218 2026] [security2:error] [pid 832668:tid 832909] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pk2ci6KgEEltqA3DGngAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:47.817974 2026] [security2:error] [pid 832668:tid 832804] [client 57.141.18.26:28808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjGci6KgEEltqA3DE2wAABCI"]
[Mon Jul 20 06:07:47.843836 2026] [security2:error] [pid 796567:tid 796817] [client 8.229.3.76:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.3.229.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/xmlrpc.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPUQAAAow"]
[Mon Jul 20 06:07:47.843962 2026] [security2:error] [pid 796567:tid 796817] [client 8.229.3.76:56252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "betterbonddogtraining.com"] [uri "/xmlrpc.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPUQAAAow"]
[Mon Jul 20 06:07:47.921857 2026] [security2:error] [pid 832668:tid 832896] [client 202.50.55.150:62101] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/cgi-bin/.env"] [unique_id "al4Pk2ci6KgEEltqA3DGsAAAAGA"]
[Mon Jul 20 06:07:47.983103 2026] [proxy:error] [pid 832668:tid 832834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:47.983207 2026] [proxy_http:error] [pid 832668:tid 832834] [client 24.144.83.208:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:47.984298 2026] [proxy:error] [pid 832668:tid 832834] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:47.984349 2026] [proxy_http:error] [pid 832668:tid 832834] [client 24.144.83.208:56084] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:07:48.072130 2026] [security2:error] [pid 832668:tid 832820] [client 46.110.96.34:59705] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4PlGci6KgEEltqA3DGvAAAABQ"]
[Mon Jul 20 06:07:48.107045 2026] [proxy:error] [pid 832668:tid 832889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:48.107128 2026] [proxy_http:error] [pid 832668:tid 832889] [client 24.144.83.208:56100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:48.107794 2026] [proxy:error] [pid 832668:tid 832889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:07:48.107824 2026] [proxy_http:error] [pid 832668:tid 832889] [client 24.144.83.208:56100] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:48.239854 2026] [security2:error] [pid 832668:tid 832925] [client 202.50.55.150:62114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/backend/.env"] [unique_id "al4PlGci6KgEEltqA3DGyAAAAH0"]
[Mon Jul 20 06:07:48.273403 2026] [security2:error] [pid 832668:tid 832903] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PlGci6KgEEltqA3DGxAAAAGc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:48.277910 2026] [security2:error] [pid 832668:tid 832855] [client 14.225.17.146:59391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGXwAAADc"], referer: http://reosportsboats.com/Wordpress
[Mon Jul 20 06:07:48.296222 2026] [security2:error] [pid 832668:tid 832828] [client 57.141.18.14:33782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjWci6KgEEltqA3DE9AAAHAQ"]
[Mon Jul 20 06:07:48.349394 2026] [security2:error] [pid 832668:tid 832813] [client 193.19.109.224:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PlGci6KgEEltqA3DGzQAAAA0"]
[Mon Jul 20 06:07:48.365706 2026] [security2:error] [pid 832668:tid 832836] [client 193.19.109.247:28721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4PlGci6KgEEltqA3DG0AAAACQ"]
[Mon Jul 20 06:07:48.395248 2026] [security2:error] [pid 832668:tid 832908] [client 14.225.17.146:58713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Pk2ci6KgEEltqA3DGkgAAAGw"], referer: http://headachescarpaltunnelfibromyalgia.com/Wordpress
[Mon Jul 20 06:07:48.412826 2026] [core:error] [pid 832668:tid 832878] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:48.412852 2026] [core:error] [pid 832668:tid 832878] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:07:48.505077 2026] [security2:error] [pid 832668:tid 832847] [client 14.225.17.146:51860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4PlGci6KgEEltqA3DG2wAAAC8"], referer: https://adultdaycarereno.com/Wordpress
[Mon Jul 20 06:07:48.516111 2026] [security2:error] [pid 832668:tid 832891] [client 57.141.18.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Pk2ci6KgEEltqA3DGqgAAAFs"]
[Mon Jul 20 06:07:48.557326 2026] [security2:error] [pid 796567:tid 796721] [client 202.50.55.150:62130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/src/.env"] [unique_id "al4PlLLfyzVz2SrjZpjPYAAAAiw"]
[Mon Jul 20 06:07:48.626196 2026] [security2:error] [pid 796567:tid 796571] [remote 72.167.132.114:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PlLLfyzVz2SrjZpjPYgACWgM"]
[Mon Jul 20 06:07:48.827967 2026] [security2:error] [pid 796567:tid 796598] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PlLLfyzVz2SrjZpjPZgACZR4"]
[Mon Jul 20 06:07:48.828187 2026] [security2:error] [pid 796567:tid 796778] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PlLLfyzVz2SrjZpjPZgACZR4"]
[Mon Jul 20 06:07:48.837198 2026] [security2:error] [pid 796567:tid 796569] [remote 72.167.132.114:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PlLLfyzVz2SrjZpjPaAACSwE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:07:48.868635 2026] [security2:error] [pid 832668:tid 832863] [client 202.50.55.150:62141] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/base/.env"] [unique_id "al4PlGci6KgEEltqA3DG7AAAAD8"]
[Mon Jul 20 06:07:48.900666 2026] [security2:error] [pid 796567:tid 796771] [client 14.225.17.146:49684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Pk7LfyzVz2SrjZpjPRQAAAl4"], referer: http://tntcatholic.com/Wordpress
[Mon Jul 20 06:07:48.994627 2026] [security2:error] [pid 832668:tid 832694] [remote 124.55.178.99:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4PlGci6KgEEltqA3DG9QAAXxc"]
[Mon Jul 20 06:07:49.172476 2026] [security2:error] [pid 832668:tid 832692] [remote 47.128.122.53:27440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/omenana-submissions/embed/"] [unique_id "al4PlWci6KgEEltqA3DG-wAAahU"], referer: https://iapwe.org/
[Mon Jul 20 06:07:49.179607 2026] [security2:error] [pid 832668:tid 832816] [client 202.50.55.150:62154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/core/.env"] [unique_id "al4PlWci6KgEEltqA3DG_AAAABA"]
[Mon Jul 20 06:07:49.210493 2026] [security2:error] [pid 832668:tid 832858] [client 14.225.17.146:59380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4Pk2ci6KgEEltqA3DGrQAAADo"], referer: http://keywayconstructionclt.com/Wordpress
[Mon Jul 20 06:07:49.332036 2026] [security2:error] [pid 796567:tid 796774] [client 14.225.17.146:51886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4PlbLfyzVz2SrjZpjPdAAAAmE"], referer: https://reosportsboats.com/Wordpress
[Mon Jul 20 06:07:49.428472 2026] [security2:error] [pid 832668:tid 832773] [remote 124.55.178.99:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4PlWci6KgEEltqA3DHCgAAaGY"], referer: https://hammadownenterprises.com/wp-login.php
[Mon Jul 20 06:07:49.492380 2026] [security2:error] [pid 832668:tid 832849] [client 202.50.55.150:62167] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/vendor/laravel/.env"] [unique_id "al4PlWci6KgEEltqA3DHEAAAADE"]
[Mon Jul 20 06:07:49.564630 2026] [security2:error] [pid 796567:tid 796757] [client 57.141.18.49:47584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PjrLfyzVz2SrjZpjOqAACUBQ"]
[Mon Jul 20 06:07:49.609858 2026] [security2:error] [pid 796567:tid 796711] [client 50.116.65.227:11128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PlbLfyzVz2SrjZpjPgQAAAiI"]
[Mon Jul 20 06:07:49.620559 2026] [security2:error] [pid 796567:tid 796814] [client 50.116.65.227:11142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PlbLfyzVz2SrjZpjPggAAAok"]
[Mon Jul 20 06:07:49.802380 2026] [security2:error] [pid 796567:tid 796818] [client 202.50.55.150:62185] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/storage/.env"] [unique_id "al4PlbLfyzVz2SrjZpjPhQAAAo0"]
[Mon Jul 20 06:07:49.988620 2026] [security2:error] [pid 796567:tid 796764] [client 47.128.42.240:42150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nurturemarple.co.uk"] [uri "/robots.txt"] [unique_id "al4PlbLfyzVz2SrjZpjPjQAAAlc"]
[Mon Jul 20 06:07:50.112109 2026] [security2:error] [pid 832668:tid 832848] [client 202.50.55.150:62201] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/protected/.env"] [unique_id "al4Plmci6KgEEltqA3DHMwAAADA"]
[Mon Jul 20 06:07:50.194037 2026] [security2:error] [pid 832668:tid 832924] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Plmci6KgEEltqA3DHLAAAAHw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:50.232914 2026] [security2:error] [pid 832668:tid 832901] [client 14.225.17.146:51392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4Plmci6KgEEltqA3DHOQAAAGU"], referer: https://keywayconstructionclt.com/Wordpress
[Mon Jul 20 06:07:50.280967 2026] [security2:error] [pid 796567:tid 796769] [client 14.225.17.146:51373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4PlrLfyzVz2SrjZpjPjgAAAlw"], referer: http://taskidsvirginia.com/Wordpress
[Mon Jul 20 06:07:50.301573 2026] [core:error] [pid 832668:tid 832810] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:50.301600 2026] [core:error] [pid 832668:tid 832810] [client 24.144.83.208:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcontacts.hedgerow-crafts.com/
[Mon Jul 20 06:07:50.303681 2026] [security2:error] [pid 832668:tid 832879] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PlWci6KgEEltqA3DHIgAAAE8"], referer: http://laceycaraccident.com/cgi-bin/authLogin.cgi
[Mon Jul 20 06:07:50.410519 2026] [security2:error] [pid 832668:tid 832832] [client 185.132.186.87:50103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/NewFile.php"] [unique_id "al4Plmci6KgEEltqA3DHRAAAACA"]
[Mon Jul 20 06:07:50.422866 2026] [security2:error] [pid 832668:tid 832887] [client 202.50.55.150:62215] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/newsite/.env"] [unique_id "al4Plmci6KgEEltqA3DHRwAAAFc"]
[Mon Jul 20 06:07:50.589044 2026] [security2:error] [pid 796567:tid 796767] [client 216.73.216.229:31918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PlrLfyzVz2SrjZpjPlgACWlE"]
[Mon Jul 20 06:07:50.650349 2026] [security2:error] [pid 832668:tid 832814] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Plmci6KgEEltqA3DHUAAAAA4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:50.741149 2026] [security2:error] [pid 796567:tid 796741] [client 202.50.55.150:62231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/www/.env"] [unique_id "al4PlrLfyzVz2SrjZpjPmwAAAkA"]
[Mon Jul 20 06:07:50.794456 2026] [security2:error] [pid 796567:tid 796804] [client 216.73.216.229:31918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PlrLfyzVz2SrjZpjPmAACfzE"], referer: https://www.iagdevelopments.com/sitemap.xml
[Mon Jul 20 06:07:50.856434 2026] [security2:error] [pid 832668:tid 832925] [client 103.141.108.143:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Plmci6KgEEltqA3DHWAAAAH0"]
[Mon Jul 20 06:07:50.856602 2026] [security2:error] [pid 832668:tid 832925] [client 103.141.108.143:64474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Plmci6KgEEltqA3DHWAAAAH0"]
[Mon Jul 20 06:07:51.072690 2026] [security2:error] [pid 832668:tid 832822] [client 202.50.55.150:62253] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/sites/all/libraries/mailchimp/.env"] [unique_id "al4Pl2ci6KgEEltqA3DHbAAAABY"]
[Mon Jul 20 06:07:51.100359 2026] [security2:error] [pid 832668:tid 832833] [client 57.141.18.24:38582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pj2ci6KgEEltqA3DFpwAAIVc"]
[Mon Jul 20 06:07:51.309174 2026] [security2:error] [pid 832668:tid 832828] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pl2ci6KgEEltqA3DHcwAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:51.375589 2026] [security2:error] [pid 832668:tid 832693] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pl2ci6KgEEltqA3DHgQAAYxY"]
[Mon Jul 20 06:07:51.375711 2026] [security2:error] [pid 832668:tid 832899] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pl2ci6KgEEltqA3DHgQAAYxY"]
[Mon Jul 20 06:07:51.405516 2026] [security2:error] [pid 832668:tid 832814] [client 202.50.55.150:62275] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/database/.env"] [unique_id "al4Pl2ci6KgEEltqA3DHgwAAAA4"]
[Mon Jul 20 06:07:51.723827 2026] [security2:error] [pid 832668:tid 832834] [client 202.50.55.150:62294] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/public/.env"] [unique_id "al4Pl2ci6KgEEltqA3DHmAAAACI"]
[Mon Jul 20 06:07:51.994539 2026] [security2:error] [pid 796567:tid 796785] [client 50.116.65.227:56902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4Pl7LfyzVz2SrjZpjPvwAAAmw"]
[Mon Jul 20 06:07:52.007677 2026] [security2:error] [pid 796567:tid 796813] [client 50.116.65.227:11188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4PmLLfyzVz2SrjZpjPwAAAAog"]
[Mon Jul 20 06:07:52.011629 2026] [security2:error] [pid 796567:tid 796711] [client 103.77.203.233:57615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPwQAAAiI"]
[Mon Jul 20 06:07:52.011770 2026] [security2:error] [pid 796567:tid 796711] [client 103.77.203.233:57615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPwQAAAiI"]
[Mon Jul 20 06:07:52.035418 2026] [security2:error] [pid 796567:tid 796788] [client 57.141.18.38:27138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PkLLfyzVz2SrjZpjO7QACb0g"]
[Mon Jul 20 06:07:52.045588 2026] [security2:error] [pid 832668:tid 832909] [client 106.192.104.4:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHqQAAAG0"]
[Mon Jul 20 06:07:52.045682 2026] [security2:error] [pid 832668:tid 832909] [client 106.192.104.4:31835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHqQAAAG0"]
[Mon Jul 20 06:07:52.206850 2026] [security2:error] [pid 832668:tid 832857] [client 202.50.55.150:62325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "108.179.215.73"] [uri "/108-179-215-73.unifiedlayer.com/.env"] [unique_id "al4PmGci6KgEEltqA3DHsQAAADk"]
[Mon Jul 20 06:07:52.359021 2026] [security2:error] [pid 796567:tid 796787] [client 112.213.160.112:8478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPxwAAAm4"]
[Mon Jul 20 06:07:52.359173 2026] [security2:error] [pid 796567:tid 796787] [client 112.213.160.112:8478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PmLLfyzVz2SrjZpjPxwAAAm4"]
[Mon Jul 20 06:07:52.360142 2026] [security2:error] [pid 832668:tid 832882] [client 185.132.186.59:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/index.php"] [unique_id "al4PmGci6KgEEltqA3DHtgAAAFI"]
[Mon Jul 20 06:07:52.475896 2026] [security2:error] [pid 832668:tid 832709] [remote 40.77.167.28:58287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.167.77.40.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4PmGci6KgEEltqA3DHwgAAfCY"]
[Mon Jul 20 06:07:52.495685 2026] [security2:error] [pid 832668:tid 832912] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PmGci6KgEEltqA3DHvQAAAHA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:52.581478 2026] [security2:error] [pid 832668:tid 832828] [client 115.246.21.170:7724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHyQAAABw"]
[Mon Jul 20 06:07:52.581617 2026] [security2:error] [pid 832668:tid 832828] [client 115.246.21.170:7724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PmGci6KgEEltqA3DHyQAAABw"]
[Mon Jul 20 06:07:52.732046 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.105:49272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PkWci6KgEEltqA3DF-QAAZGE"]
[Mon Jul 20 06:07:52.857542 2026] [security2:error] [pid 832668:tid 832840] [client 202.50.55.150:62366] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "108.179.215.73"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "al4PmGci6KgEEltqA3DH2QAAACg"]
[Mon Jul 20 06:07:53.211804 2026] [security2:error] [pid 832668:tid 832829] [client 14.225.17.146:52185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4PmGci6KgEEltqA3DHzgAAAB0"], referer: http://thesoloceos.com/Wordpress
[Mon Jul 20 06:07:53.255305 2026] [security2:error] [pid 832668:tid 832906] [client 45.116.69.230:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PmWci6KgEEltqA3DH9AAAAGo"]
[Mon Jul 20 06:07:53.255421 2026] [security2:error] [pid 832668:tid 832906] [client 45.116.69.230:60326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PmWci6KgEEltqA3DH9AAAAGo"]
[Mon Jul 20 06:07:53.344425 2026] [security2:error] [pid 832668:tid 832902] [client 57.141.18.70:27192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PkWci6KgEEltqA3DGFQAAZjg"]
[Mon Jul 20 06:07:53.700339 2026] [security2:error] [pid 832668:tid 832863] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PmWci6KgEEltqA3DIAgAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:53.711471 2026] [security2:error] [pid 832668:tid 832887] [client 14.225.17.146:53250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4Pl2ci6KgEEltqA3DHhwAAAFc"], referer: http://soloceos.com/Wordpress
[Mon Jul 20 06:07:53.782651 2026] [security2:error] [pid 796567:tid 796801] [client 185.226.198.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PmbLfyzVz2SrjZpjP5QAAAnw"], referer: http://laceycaraccident.com/WebInterface/
[Mon Jul 20 06:07:53.881033 2026] [security2:error] [pid 832668:tid 832867] [client 57.141.18.112:62454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGQAAAQ00"]
[Mon Jul 20 06:07:54.182836 2026] [security2:error] [pid 832668:tid 832770] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIJwAANmM"]
[Mon Jul 20 06:07:54.183024 2026] [security2:error] [pid 832668:tid 832854] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIJwAANmM"]
[Mon Jul 20 06:07:54.229165 2026] [security2:error] [pid 832668:tid 832846] [client 103.153.183.69:34824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../srv/.env"] [unique_id "al4Pmmci6KgEEltqA3DIKQAAAC4"], referer: https://www.google.com/search?q=9gecwx
[Mon Jul 20 06:07:54.287391 2026] [security2:error] [pid 796567:tid 796743] [client 185.132.186.99:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/error.php"] [unique_id "al4PmrLfyzVz2SrjZpjQAAAAAkI"]
[Mon Jul 20 06:07:54.359703 2026] [security2:error] [pid 796567:tid 796777] [client 14.225.17.146:51725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4PmrLfyzVz2SrjZpjP9gAAAmQ"], referer: http://grecruit.online/Wordpress
[Mon Jul 20 06:07:54.386043 2026] [security2:error] [pid 796567:tid 796703] [client 41.173.37.102:7077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PmrLfyzVz2SrjZpjQAwAAAho"]
[Mon Jul 20 06:07:54.386178 2026] [security2:error] [pid 796567:tid 796703] [client 41.173.37.102:7077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PmrLfyzVz2SrjZpjQAwAAAho"]
[Mon Jul 20 06:07:54.420267 2026] [security2:error] [pid 796567:tid 796722] [client 14.225.17.146:59442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4PmrLfyzVz2SrjZpjP_wAAAi0"], referer: https://thesoloceos.com/Wordpress
[Mon Jul 20 06:07:54.452536 2026] [security2:error] [pid 832668:tid 832834] [client 14.239.11.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4Pmmci6KgEEltqA3DIJAAAACI"]
[Mon Jul 20 06:07:54.579652 2026] [security2:error] [pid 832668:tid 832894] [client 57.141.18.125:40362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pkmci6KgEEltqA3DGdAAAXhE"]
[Mon Jul 20 06:07:54.595130 2026] [security2:error] [pid 832668:tid 832872] [client 181.224.94.124:51750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIOwAAAEg"]
[Mon Jul 20 06:07:54.595262 2026] [security2:error] [pid 832668:tid 832872] [client 181.224.94.124:51750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pmmci6KgEEltqA3DIOwAAAEg"]
[Mon Jul 20 06:07:55.005419 2026] [security2:error] [pid 832668:tid 832806] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Pmmci6KgEEltqA3DITAAABmQ"], referer: http://aleishapenny.ca/Wordpress
[Mon Jul 20 06:07:55.298170 2026] [security2:error] [pid 832668:tid 832869] [client 178.152.178.232:36671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pm2ci6KgEEltqA3DIYgAAAEU"]
[Mon Jul 20 06:07:55.298268 2026] [security2:error] [pid 832668:tid 832869] [client 178.152.178.232:36671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pm2ci6KgEEltqA3DIYgAAAEU"]
[Mon Jul 20 06:07:55.422232 2026] [security2:error] [pid 796567:tid 796683] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pm7LfyzVz2SrjZpjQGwACJnM"]
[Mon Jul 20 06:07:55.422452 2026] [security2:error] [pid 796567:tid 796715] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pm7LfyzVz2SrjZpjQGwACJnM"]
[Mon Jul 20 06:07:55.468674 2026] [security2:error] [pid 832668:tid 832872] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pm2ci6KgEEltqA3DIZQAAAEg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:55.594123 2026] [security2:error] [pid 832668:tid 832911] [client 14.225.17.146:53302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4Pmmci6KgEEltqA3DIKAAAAG8"], referer: http://goyalsatyam.com/Wordpress
[Mon Jul 20 06:07:55.772092 2026] [security2:error] [pid 796567:tid 796765] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Pm7LfyzVz2SrjZpjQJAACWE0"], referer: https://aleishapenny.ca/Wordpress
[Mon Jul 20 06:07:55.942579 2026] [security2:error] [pid 832668:tid 832922] [client 103.153.183.69:34824] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../home/.env"] [unique_id "al4Pm2ci6KgEEltqA3DIcQAAAHo"], referer: https://www.bing.com/search?q=fgtkq3
[Mon Jul 20 06:07:55.959207 2026] [security2:error] [pid 832668:tid 832781] [remote 188.166.241.141:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4Pm2ci6KgEEltqA3DIcwAAV24"]
[Mon Jul 20 06:07:56.053315 2026] [security2:error] [pid 832668:tid 832840] [client 163.172.182.64:51036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5016.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4PnGci6KgEEltqA3DIegAAACg"]
[Mon Jul 20 06:07:56.189914 2026] [security2:error] [pid 832668:tid 832808] [client 57.141.18.27:26488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PlGci6KgEEltqA3DG1AAACEw"]
[Mon Jul 20 06:07:56.238209 2026] [security2:error] [pid 796567:tid 796706] [client 185.132.186.97:60205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/admin-footer.php"] [unique_id "al4PnLLfyzVz2SrjZpjQLwAAAh0"]
[Mon Jul 20 06:07:56.309192 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:19489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PnGci6KgEEltqA3DIkgAAAGM"]
[Mon Jul 20 06:07:56.309298 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:19489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PnGci6KgEEltqA3DIkgAAAGM"]
[Mon Jul 20 06:07:56.352777 2026] [security2:error] [pid 832668:tid 832796] [remote 188.166.241.141:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4PnGci6KgEEltqA3DIlgAAGX0"], referer: https://gescontrols.com/wp-login.php
[Mon Jul 20 06:07:56.564223 2026] [security2:error] [pid 832668:tid 832897] [client 14.225.17.146:51287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIgwAAAGE"], referer: http://areitoproducciones.com/Wordpress
[Mon Jul 20 06:07:56.603484 2026] [security2:error] [pid 832668:tid 832814] [client 185.226.198.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIhAAAAA4"], referer: http://laceycaraccident.com/console
[Mon Jul 20 06:07:56.713948 2026] [security2:error] [pid 832668:tid 832835] [client 57.141.18.61:55536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PlGci6KgEEltqA3DG5wAAIxA"]
[Mon Jul 20 06:07:56.951227 2026] [security2:error] [pid 832668:tid 832802] [client 50.116.65.227:11268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIrwAAAAI"]
[Mon Jul 20 06:07:57.148827 2026] [security2:error] [pid 832668:tid 832820] [client 50.116.65.227:11282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4PnGci6KgEEltqA3DIvQAAABQ"]
[Mon Jul 20 06:07:57.345404 2026] [security2:error] [pid 832668:tid 832866] [client 57.141.18.108:36330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PlWci6KgEEltqA3DHAQAAQhs"]
[Mon Jul 20 06:07:57.515143 2026] [security2:error] [pid 832668:tid 832724] [remote 45.150.79.142:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PnWci6KgEEltqA3DI3AAABTU"]
[Mon Jul 20 06:07:57.539904 2026] [security2:error] [pid 832668:tid 832856] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PnWci6KgEEltqA3DI2gAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:07:57.679887 2026] [security2:error] [pid 832668:tid 832710] [remote 45.150.79.142:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PnWci6KgEEltqA3DI4QAADCc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:07:58.180939 2026] [security2:error] [pid 832668:tid 832864] [client 185.132.186.64:64523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-search-function.php"] [unique_id "al4Pnmci6KgEEltqA3DI9QAAAEA"]
[Mon Jul 20 06:07:58.527638 2026] [security2:error] [pid 832668:tid 832907] [client 14.225.17.146:51342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4PnWci6KgEEltqA3DIyQAAAGs"], referer: http://detroitcsc.com/Wordpress
[Mon Jul 20 06:07:58.640681 2026] [security2:error] [pid 796567:tid 796708] [client 50.116.65.227:11346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PnrLfyzVz2SrjZpjQZQAAAh8"]
[Mon Jul 20 06:07:58.652134 2026] [security2:error] [pid 796567:tid 796824] [client 50.116.65.227:11356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PnrLfyzVz2SrjZpjQZgAAApM"]
[Mon Jul 20 06:07:58.791070 2026] [security2:error] [pid 832668:tid 832889] [client 14.225.17.146:51463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4PnWci6KgEEltqA3DI2QAAAFk"], referer: http://northbrookcpa.ca/Wordpress
[Mon Jul 20 06:07:59.438081 2026] [security2:error] [pid 832668:tid 832731] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pn2ci6KgEEltqA3DJKAAAcDw"]
[Mon Jul 20 06:07:59.438222 2026] [security2:error] [pid 832668:tid 832912] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Pn2ci6KgEEltqA3DJKAAAcDw"]
[Mon Jul 20 06:07:59.740317 2026] [security2:error] [pid 832668:tid 832718] [remote 130.51.180.8:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Pn2ci6KgEEltqA3DJOwAAby8"]
[Mon Jul 20 06:07:59.867798 2026] [security2:error] [pid 796567:tid 796742] [client 45.157.112.60:57469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Pn7LfyzVz2SrjZpjQiAAAAkE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:00.017117 2026] [security2:error] [pid 832668:tid 832694] [remote 130.51.180.8:58106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4PoGci6KgEEltqA3DJRAAAVRc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:08:00.033898 2026] [security2:error] [pid 832668:tid 832851] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pn2ci6KgEEltqA3DJQQAAADM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:00.041543 2026] [security2:error] [pid 832668:tid 832906] [client 185.226.198.4:16108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "al4PoGci6KgEEltqA3DJRQAAAGo"]
[Mon Jul 20 06:08:00.128641 2026] [security2:error] [pid 832668:tid 832840] [client 185.132.186.58:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/themes/index.php"] [unique_id "al4PoGci6KgEEltqA3DJTAAAACg"]
[Mon Jul 20 06:08:00.171954 2026] [security2:error] [pid 832668:tid 832887] [client 114.119.155.185:63825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "securingmemories.com"] [uri "/index.php/privacy-policy/"] [unique_id "al4PoGci6KgEEltqA3DJTQAAAFc"], referer: https://securingmemories.com/index.php/2020/11/02/i-know-what-youre-thinking
[Mon Jul 20 06:08:00.241203 2026] [core:error] [pid 832668:tid 832905] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:00.241222 2026] [core:error] [pid 832668:tid 832905] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:00.654470 2026] [security2:error] [pid 796567:tid 796750] [client 57.141.18.35:25154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PmLLfyzVz2SrjZpjP2wACSSQ"]
[Mon Jul 20 06:08:00.778356 2026] [security2:error] [pid 832668:tid 832892] [client 14.225.17.146:64320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4Pn2ci6KgEEltqA3DJNgAAAFw"], referer: http://mcg.homes/Wordpress
[Mon Jul 20 06:08:00.785809 2026] [security2:error] [pid 832668:tid 832765] [remote 103.28.36.200:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PoGci6KgEEltqA3DJcAAAG14"]
[Mon Jul 20 06:08:00.806740 2026] [security2:error] [pid 832668:tid 832914] [client 14.225.17.146:51465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4Pn2ci6KgEEltqA3DJPwAAAHI"], referer: http://idigress.studio/Wordpress
[Mon Jul 20 06:08:01.228809 2026] [security2:error] [pid 832668:tid 832781] [remote 103.28.36.200:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PoWci6KgEEltqA3DJkAAAOG4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:08:01.324033 2026] [security2:error] [pid 796567:tid 796697] [client 114.119.135.199:46315] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emil.manasyan.uk"] [uri "/robots.txt"] [unique_id "al4PobLfyzVz2SrjZpjQrwAAAhQ"], referer: https://emil.manasyan.uk/robots.txt
[Mon Jul 20 06:08:01.347966 2026] [security2:error] [pid 832668:tid 832895] [client 57.141.18.92:27516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PmWci6KgEEltqA3DICgAAX10"]
[Mon Jul 20 06:08:01.450414 2026] [security2:error] [pid 832668:tid 832859] [client 103.141.108.143:64931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PoWci6KgEEltqA3DJlAAAADs"]
[Mon Jul 20 06:08:01.450537 2026] [security2:error] [pid 832668:tid 832859] [client 103.141.108.143:64931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PoWci6KgEEltqA3DJlAAAADs"]
[Mon Jul 20 06:08:01.696475 2026] [security2:error] [pid 832668:tid 832784] [remote 8.217.108.67:25900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PoWci6KgEEltqA3DJowAARHE"]
[Mon Jul 20 06:08:01.843485 2026] [security2:error] [pid 832668:tid 832822] [client 185.226.198.5:42512] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "al4PoWci6KgEEltqA3DJqAAAABY"]
[Mon Jul 20 06:08:02.047767 2026] [security2:error] [pid 796567:tid 796682] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PorLfyzVz2SrjZpjQwwACfHI"]
[Mon Jul 20 06:08:02.047911 2026] [security2:error] [pid 796567:tid 796801] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PorLfyzVz2SrjZpjQwwACfHI"]
[Mon Jul 20 06:08:02.052660 2026] [core:error] [pid 796567:tid 796775] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:02.052676 2026] [core:error] [pid 796567:tid 796775] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:02.074128 2026] [security2:error] [pid 832668:tid 832866] [client 185.132.186.87:49957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-files.php"] [unique_id "al4Pomci6KgEEltqA3DJuAAAAEI"]
[Mon Jul 20 06:08:02.259608 2026] [security2:error] [pid 832668:tid 832711] [remote 152.228.213.32:42934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4Pomci6KgEEltqA3DJwwAAbig"]
[Mon Jul 20 06:08:02.473989 2026] [security2:error] [pid 832668:tid 832680] [remote 152.228.213.32:42934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4Pomci6KgEEltqA3DJygAAOQk"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 06:08:02.476726 2026] [security2:error] [pid 832668:tid 832825] [client 103.77.203.233:57677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJzAAAABk"]
[Mon Jul 20 06:08:02.478031 2026] [security2:error] [pid 832668:tid 832825] [client 103.77.203.233:57677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJzAAAABk"]
[Mon Jul 20 06:08:02.506545 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:60425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4Pomci6KgEEltqA3DJxwAAAFQ"], referer: http://adirondackengineering.com/Wordpress
[Mon Jul 20 06:08:02.507937 2026] [security2:error] [pid 832668:tid 832684] [remote 8.217.108.67:25900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Pomci6KgEEltqA3DJ0AAAIg0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:08:02.618284 2026] [security2:error] [pid 832668:tid 832804] [client 106.192.104.4:52138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJ2QAAAAQ"]
[Mon Jul 20 06:08:02.618460 2026] [security2:error] [pid 832668:tid 832804] [client 106.192.104.4:52138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pomci6KgEEltqA3DJ2QAAAAQ"]
[Mon Jul 20 06:08:02.665147 2026] [proxy:error] [pid 832668:tid 832806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.665201 2026] [proxy_http:error] [pid 832668:tid 832806] [client 94.154.43.186:43400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.666548 2026] [proxy:error] [pid 832668:tid 832806] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.666602 2026] [proxy_http:error] [pid 832668:tid 832806] [client 94.154.43.186:43400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.670118 2026] [security2:error] [pid 832668:tid 832889] [client 94.154.43.188:24122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.samueldcohen.com"] [uri "/.env"] [unique_id "al4Pomci6KgEEltqA3DJ4wAAAFk"]
[Mon Jul 20 06:08:02.821129 2026] [proxy:error] [pid 832668:tid 832840] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.821212 2026] [proxy_http:error] [pid 832668:tid 832840] [client 94.154.43.183:43890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.822037 2026] [proxy:error] [pid 832668:tid 832840] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:02.822089 2026] [proxy_http:error] [pid 832668:tid 832840] [client 94.154.43.183:43890] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:02.918405 2026] [security2:error] [pid 832668:tid 832894] [client 14.225.17.146:60538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Pomci6KgEEltqA3DJ5wAAAF4"], referer: http://savilerowtravel.com/Wordpress
[Mon Jul 20 06:08:03.102525 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Po2ci6KgEEltqA3DJ9gAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:03.102638 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Po2ci6KgEEltqA3DJ9gAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:03.133062 2026] [security2:error] [pid 832668:tid 832891] [client 112.213.160.112:31226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Po2ci6KgEEltqA3DJ-QAAAFs"]
[Mon Jul 20 06:08:03.133215 2026] [security2:error] [pid 832668:tid 832891] [client 112.213.160.112:31226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Po2ci6KgEEltqA3DJ-QAAAFs"]
[Mon Jul 20 06:08:03.138686 2026] [security2:error] [pid 796567:tid 796750] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PorLfyzVz2SrjZpjQ0AACSTY"], referer: http://ali-alghanim.net/Wordpress
[Mon Jul 20 06:08:03.199635 2026] [security2:error] [pid 832668:tid 832907] [client 14.225.17.146:61522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJqwAAAGs"], referer: http://mazzucelli.com/Wordpress
[Mon Jul 20 06:08:03.299849 2026] [security2:error] [pid 796567:tid 796769] [client 115.246.21.170:4147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ3QAAAlw"]
[Mon Jul 20 06:08:03.299947 2026] [security2:error] [pid 796567:tid 796769] [client 115.246.21.170:4147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ3QAAAlw"]
[Mon Jul 20 06:08:03.441231 2026] [security2:error] [pid 832668:tid 832824] [client 185.226.198.5:42518] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "al4Po2ci6KgEEltqA3DKCgAAABg"]
[Mon Jul 20 06:08:03.852172 2026] [security2:error] [pid 796567:tid 796793] [client 45.116.69.230:60783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ6AAAAnQ"]
[Mon Jul 20 06:08:03.852305 2026] [security2:error] [pid 796567:tid 796793] [client 45.116.69.230:60783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Po7LfyzVz2SrjZpjQ6AAAAnQ"]
[Mon Jul 20 06:08:04.006719 2026] [security2:error] [pid 832668:tid 832824] [client 47.128.52.93:18870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/news/"] [unique_id "al4PpGci6KgEEltqA3DKOgAAABg"]
[Mon Jul 20 06:08:04.023104 2026] [security2:error] [pid 796567:tid 796720] [client 185.132.186.59:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/functions.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ6QAAAis"]
[Mon Jul 20 06:08:04.138639 2026] [security2:error] [pid 832668:tid 832822] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PpGci6KgEEltqA3DKQgAAABY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:04.192667 2026] [security2:error] [pid 832668:tid 832811] [client 14.225.17.146:61305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Po2ci6KgEEltqA3DKOAAAAAs"], referer: https://savilerowtravel.com/Wordpress
[Mon Jul 20 06:08:04.265953 2026] [security2:error] [pid 796567:tid 796804] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ7AAAAn8"]
[Mon Jul 20 06:08:04.281827 2026] [security2:error] [pid 796567:tid 796772] [client 57.141.18.108:60290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PnbLfyzVz2SrjZpjQPAACXys"]
[Mon Jul 20 06:08:04.353270 2026] [security2:error] [pid 796567:tid 796634] [remote 45.90.123.233:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ-AACYUI"]
[Mon Jul 20 06:08:04.363307 2026] [security2:error] [pid 832668:tid 832832] [client 14.225.17.146:61532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJrgAAACA"], referer: http://dollpassionista.com/Wordpress
[Mon Jul 20 06:08:04.391268 2026] [security2:error] [pid 796567:tid 796742] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ9AAAAkE"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:04.559251 2026] [security2:error] [pid 796567:tid 796602] [remote 45.90.123.233:57602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PpLLfyzVz2SrjZpjRAAACkSI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:08:04.580248 2026] [security2:error] [pid 832668:tid 832731] [remote 103.94.134.160:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.134.94.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKXwAAETw"]
[Mon Jul 20 06:08:04.580410 2026] [security2:error] [pid 832668:tid 832817] [client 103.94.134.160:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ashleystrain.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKXwAAETw"]
[Mon Jul 20 06:08:04.624952 2026] [security2:error] [pid 796567:tid 796747] [client 15.204.254.129:53040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "thewritinglair.com"] [uri "/"] [unique_id "al4PpLLfyzVz2SrjZpjRBQAAAkY"]
[Mon Jul 20 06:08:04.769663 2026] [security2:error] [pid 796567:tid 796781] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjRCQAAAmg"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:04.964446 2026] [security2:error] [pid 832668:tid 832873] [client 41.173.37.102:7542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKeAAAAEk"]
[Mon Jul 20 06:08:04.964592 2026] [security2:error] [pid 832668:tid 832873] [client 41.173.37.102:7542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PpGci6KgEEltqA3DKeAAAAEk"]
[Mon Jul 20 06:08:05.081703 2026] [security2:error] [pid 832668:tid 832694] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKgAAAAhc"]
[Mon Jul 20 06:08:05.081894 2026] [security2:error] [pid 832668:tid 832802] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKgAAAAhc"]
[Mon Jul 20 06:08:05.082924 2026] [security2:error] [pid 832668:tid 832869] [client 57.141.18.121:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PnWci6KgEEltqA3DI6QAARSA"]
[Mon Jul 20 06:08:05.094667 2026] [security2:error] [pid 832668:tid 832914] [client 181.224.94.124:58132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKggAAAHI"]
[Mon Jul 20 06:08:05.094786 2026] [security2:error] [pid 832668:tid 832914] [client 181.224.94.124:58132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKggAAAHI"]
[Mon Jul 20 06:08:05.199205 2026] [security2:error] [pid 832668:tid 832924] [client 158.173.89.95:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PpWci6KgEEltqA3DKhwAAAHw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:05.449932 2026] [security2:error] [pid 832668:tid 832872] [client 14.225.17.146:61144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4PpWci6KgEEltqA3DKjAAAAEg"], referer: https://dollpassionista.com/Wordpress
[Mon Jul 20 06:08:05.462372 2026] [security2:error] [pid 796567:tid 796795] [client 14.225.17.146:61589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ_AAAAnY"]
[Mon Jul 20 06:08:05.980564 2026] [security2:error] [pid 832668:tid 832858] [client 185.132.186.98:21515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Canonical.php"] [unique_id "al4PpWci6KgEEltqA3DKsQAAADo"]
[Mon Jul 20 06:08:05.986830 2026] [security2:error] [pid 832668:tid 832769] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKsgAAT2I"]
[Mon Jul 20 06:08:05.987037 2026] [security2:error] [pid 832668:tid 832879] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PpWci6KgEEltqA3DKsgAAT2I"]
[Mon Jul 20 06:08:06.035239 2026] [security2:error] [pid 796567:tid 796711] [client 185.226.198.5:30040] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al4PprLfyzVz2SrjZpjRGAAAAiI"]
[Mon Jul 20 06:08:06.079442 2026] [security2:error] [pid 796567:tid 796700] [client 14.225.17.146:61087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4PpLLfyzVz2SrjZpjQ-wAAAhc"], referer: http://maplerespiteservices.com/Wordpress
[Mon Jul 20 06:08:06.246397 2026] [security2:error] [pid 832668:tid 832899] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ppmci6KgEEltqA3DKyAAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:06.368689 2026] [core:error] [pid 796567:tid 796802] [client 14.225.17.146:62657] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:06.368714 2026] [core:error] [pid 796567:tid 796802] [client 14.225.17.146:62657] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:06.455224 2026] [security2:error] [pid 832668:tid 832777] [remote 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Ppmci6KgEEltqA3DK1QAAFGo"]
[Mon Jul 20 06:08:06.455420 2026] [security2:error] [pid 832668:tid 832820] [client 5.161.225.162:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Ppmci6KgEEltqA3DK1QAAFGo"]
[Mon Jul 20 06:08:06.475167 2026] [security2:error] [pid 832668:tid 832922] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Ppmci6KgEEltqA3DK0QAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:06.575380 2026] [security2:error] [pid 796567:tid 796618] [remote 154.66.198.148:31076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4PprLfyzVz2SrjZpjRJQACeTI"]
[Mon Jul 20 06:08:06.672844 2026] [security2:error] [pid 832668:tid 832855] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ppmci6KgEEltqA3DK3wAAADc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:06.927693 2026] [security2:error] [pid 832668:tid 832891] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Ppmci6KgEEltqA3DK7wAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:07.287458 2026] [security2:error] [pid 832668:tid 832735] [remote 57.141.18.72:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4Pp2ci6KgEEltqA3DK_wAASEA"]
[Mon Jul 20 06:08:07.337410 2026] [security2:error] [pid 832668:tid 832882] [client 185.226.198.7:23652] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "al4Pp2ci6KgEEltqA3DLAwAAAFI"]
[Mon Jul 20 06:08:07.394325 2026] [security2:error] [pid 796567:tid 796637] [remote 154.66.198.148:31076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRPgACV0U"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:08:07.577453 2026] [security2:error] [pid 796567:tid 796679] [remote 188.166.241.141:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRQAACaW8"]
[Mon Jul 20 06:08:07.726886 2026] [security2:error] [pid 832668:tid 832883] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pp2ci6KgEEltqA3DLFAAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:07.773046 2026] [security2:error] [pid 796567:tid 796806] [client 103.95.123.246:20010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRQgAAAoE"]
[Mon Jul 20 06:08:07.773184 2026] [security2:error] [pid 796567:tid 796806] [client 103.95.123.246:20010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRQgAAAoE"]
[Mon Jul 20 06:08:07.898299 2026] [security2:error] [pid 832668:tid 832894] [client 50.116.65.227:15882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Pp2ci6KgEEltqA3DLHgAAAF4"]
[Mon Jul 20 06:08:07.909065 2026] [security2:error] [pid 832668:tid 832838] [client 50.116.65.227:15896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Pp2ci6KgEEltqA3DLIAAAACY"]
[Mon Jul 20 06:08:07.920816 2026] [security2:error] [pid 796567:tid 796741] [client 185.132.186.70:57273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/autoload_classmap.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRSgAAAkA"]
[Mon Jul 20 06:08:07.984408 2026] [security2:error] [pid 796567:tid 796662] [remote 188.166.241.141:57138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRTwACS14"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:08:08.014137 2026] [security2:error] [pid 796567:tid 796726] [client 14.225.17.146:64623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4PprLfyzVz2SrjZpjRIwAAAjE"], referer: http://inspirespublishing.com/Wordpress
[Mon Jul 20 06:08:08.082833 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.124:44994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJmwAAZHI"]
[Mon Jul 20 06:08:08.140155 2026] [security2:error] [pid 832668:tid 832831] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PqGci6KgEEltqA3DLKgAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:08.387586 2026] [security2:error] [pid 832668:tid 832876] [client 57.141.18.108:41602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PoWci6KgEEltqA3DJpgAATD4"]
[Mon Jul 20 06:08:08.670543 2026] [security2:error] [pid 832668:tid 832839] [client 185.226.198.7:23662] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLVgAAACc"]
[Mon Jul 20 06:08:08.670636 2026] [security2:error] [pid 832668:tid 832828] [client 185.226.198.6:22080] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLVwAAABw"]
[Mon Jul 20 06:08:08.679337 2026] [security2:error] [pid 832668:tid 832850] [client 185.226.198.4:14724] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLWAAAADI"]
[Mon Jul 20 06:08:08.686879 2026] [security2:error] [pid 796567:tid 796810] [client 185.226.198.7:23668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRXwAAAoU"]
[Mon Jul 20 06:08:08.687801 2026] [security2:error] [pid 832668:tid 832901] [client 185.226.198.5:30056] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLWwAAAGU"]
[Mon Jul 20 06:08:08.696802 2026] [security2:error] [pid 832668:tid 832810] [client 185.226.198.5:30072] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXQAAAAo"]
[Mon Jul 20 06:08:08.696803 2026] [security2:error] [pid 832668:tid 832816] [client 185.226.198.6:22092] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXAAAABA"]
[Mon Jul 20 06:08:08.700381 2026] [security2:error] [pid 832668:tid 832900] [client 185.226.198.5:30074] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXgAAAGQ"]
[Mon Jul 20 06:08:08.703242 2026] [security2:error] [pid 796567:tid 796707] [client 185.226.198.6:22094] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYAAAAh4"]
[Mon Jul 20 06:08:08.711427 2026] [security2:error] [pid 832668:tid 832888] [client 185.226.198.4:14738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLXwAAAFg"]
[Mon Jul 20 06:08:08.714297 2026] [security2:error] [pid 796567:tid 796761] [client 185.226.198.5:30086] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYQAAAlQ"]
[Mon Jul 20 06:08:08.716219 2026] [security2:error] [pid 796567:tid 796804] [client 185.226.198.7:23676] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYgAAAn8"]
[Mon Jul 20 06:08:08.720518 2026] [security2:error] [pid 796567:tid 796791] [client 185.226.198.4:14754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRYwAAAnI"]
[Mon Jul 20 06:08:08.720987 2026] [security2:error] [pid 796567:tid 796709] [client 185.226.198.7:23678] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZAAAAiA"]
[Mon Jul 20 06:08:08.721876 2026] [security2:error] [pid 796567:tid 796699] [client 185.226.198.4:14762] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZQAAAhY"]
[Mon Jul 20 06:08:08.724266 2026] [security2:error] [pid 796567:tid 796815] [client 185.226.198.4:14766] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZgAAAoo"]
[Mon Jul 20 06:08:08.724619 2026] [security2:error] [pid 796567:tid 796772] [client 185.226.198.6:22098] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRZwAAAl8"]
[Mon Jul 20 06:08:08.727804 2026] [security2:error] [pid 796567:tid 796746] [client 185.226.198.7:23688] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRaAAAAkU"]
[Mon Jul 20 06:08:08.728920 2026] [security2:error] [pid 796567:tid 796774] [client 185.226.198.6:22108] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRaQAAAmE"]
[Mon Jul 20 06:08:08.732236 2026] [security2:error] [pid 796567:tid 796801] [client 185.226.198.7:23692] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRagAAAnw"]
[Mon Jul 20 06:08:08.734831 2026] [security2:error] [pid 796567:tid 796714] [client 185.226.198.4:14778] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRawAAAiU"]
[Mon Jul 20 06:08:08.734930 2026] [security2:error] [pid 796567:tid 796742] [client 185.226.198.5:30100] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbAAAAkE"]
[Mon Jul 20 06:08:08.740010 2026] [security2:error] [pid 796567:tid 796735] [client 185.226.198.7:23708] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbQAAAjo"]
[Mon Jul 20 06:08:08.740667 2026] [security2:error] [pid 832668:tid 832877] [client 185.226.198.5:30106] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYAAAAE0"]
[Mon Jul 20 06:08:08.741589 2026] [security2:error] [pid 832668:tid 832831] [client 185.226.198.6:22110] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYQAAAB8"]
[Mon Jul 20 06:08:08.743397 2026] [security2:error] [pid 796567:tid 796779] [client 185.226.198.7:23724] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbgAAAmY"]
[Mon Jul 20 06:08:08.744131 2026] [security2:error] [pid 796567:tid 796805] [client 185.226.198.7:23730] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRbwAAAoA"]
[Mon Jul 20 06:08:08.745304 2026] [security2:error] [pid 796567:tid 796771] [client 185.226.198.4:14790] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcAAAAl4"]
[Mon Jul 20 06:08:08.745354 2026] [security2:error] [pid 796567:tid 796783] [client 185.226.198.6:22126] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcQAAAmo"]
[Mon Jul 20 06:08:08.745811 2026] [security2:error] [pid 832668:tid 832867] [client 185.226.198.6:22134] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYgAAAEM"]
[Mon Jul 20 06:08:08.750912 2026] [security2:error] [pid 796567:tid 796706] [client 185.226.198.7:23736] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcgAAAh0"]
[Mon Jul 20 06:08:08.751437 2026] [security2:error] [pid 796567:tid 796730] [client 185.226.198.4:14798] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRcwAAAjU"]
[Mon Jul 20 06:08:08.754362 2026] [security2:error] [pid 796567:tid 796708] [client 185.226.198.6:22142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdAAAAh8"]
[Mon Jul 20 06:08:08.755235 2026] [security2:error] [pid 832668:tid 832854] [client 185.226.198.4:14814] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLYwAAADY"]
[Mon Jul 20 06:08:08.755944 2026] [security2:error] [pid 796567:tid 796756] [client 185.226.198.5:30120] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdQAAAk8"]
[Mon Jul 20 06:08:08.759801 2026] [security2:error] [pid 796567:tid 796797] [client 185.226.198.4:14824] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdgAAAng"]
[Mon Jul 20 06:08:08.760357 2026] [security2:error] [pid 796567:tid 796757] [client 185.226.198.5:30132] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRdwAAAlA"]
[Mon Jul 20 06:08:08.761855 2026] [security2:error] [pid 832668:tid 832801] [client 185.226.198.5:30142] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLZQAAAAE"]
[Mon Jul 20 06:08:08.762667 2026] [security2:error] [pid 832668:tid 832837] [client 185.226.198.4:14830] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLZgAAACU"]
[Mon Jul 20 06:08:08.763513 2026] [security2:error] [pid 796567:tid 796823] [client 185.226.198.6:22152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjReQAAApI"]
[Mon Jul 20 06:08:08.770587 2026] [security2:error] [pid 796567:tid 796824] [client 185.226.198.6:22170] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRewAAApM"]
[Mon Jul 20 06:08:08.770605 2026] [security2:error] [pid 796567:tid 796813] [client 185.226.198.6:22158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRegAAAog"]
[Mon Jul 20 06:08:08.770666 2026] [security2:error] [pid 796567:tid 796739] [client 185.226.198.5:30146] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRfAAAAj4"]
[Mon Jul 20 06:08:08.772294 2026] [security2:error] [pid 832668:tid 832879] [client 185.226.198.5:30150] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLZwAAAE8"]
[Mon Jul 20 06:08:08.772422 2026] [security2:error] [pid 796567:tid 796818] [client 185.226.198.7:23742] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRfQAAAo0"]
[Mon Jul 20 06:08:08.772957 2026] [security2:error] [pid 796567:tid 796765] [client 185.226.198.5:30152] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "al4PqLLfyzVz2SrjZpjRfgAAAlg"]
[Mon Jul 20 06:08:08.788252 2026] [security2:error] [pid 832668:tid 832893] [client 185.226.198.7:23746] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLagAAAF0"]
[Mon Jul 20 06:08:08.797874 2026] [security2:error] [pid 832668:tid 832824] [client 185.226.198.6:22186] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "al4PqGci6KgEEltqA3DLawAAABg"]
[Mon Jul 20 06:08:09.099852 2026] [security2:error] [pid 832668:tid 832869] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLgAAAAEU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:09.139955 2026] [security2:error] [pid 832668:tid 832823] [client 57.141.18.110:38182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pomci6KgEEltqA3DJ6AAAFww"]
[Mon Jul 20 06:08:09.408228 2026] [security2:error] [pid 832668:tid 832690] [remote 78.46.157.202:33658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLmAAAEBM"]
[Mon Jul 20 06:08:09.547805 2026] [security2:error] [pid 832668:tid 832807] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLoAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:09.547930 2026] [security2:error] [pid 832668:tid 832807] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLoAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:09.615062 2026] [security2:error] [pid 832668:tid 832704] [remote 78.46.157.202:33658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4PqWci6KgEEltqA3DLowAAKSE"], referer: https://thedoctorscuisine.com/wp-login.php
[Mon Jul 20 06:08:09.722125 2026] [security2:error] [pid 796567:tid 796775] [client 106.49.57.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRNAACYgQ"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91singularity-studio-escala-1-4-malenia/
[Mon Jul 20 06:08:09.875950 2026] [security2:error] [pid 832668:tid 832839] [client 185.132.186.54:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/aks.php"] [unique_id "al4PqWci6KgEEltqA3DLvAAAACc"]
[Mon Jul 20 06:08:09.922728 2026] [security2:error] [pid 832668:tid 832671] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PqWci6KgEEltqA3DLwAAAEgA"]
[Mon Jul 20 06:08:09.922928 2026] [security2:error] [pid 832668:tid 832818] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PqWci6KgEEltqA3DLwAAAEgA"]
[Mon Jul 20 06:08:10.010395 2026] [security2:error] [pid 832668:tid 832896] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PqWci6KgEEltqA3DLwQAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:10.056832 2026] [security2:error] [pid 796567:tid 796734] [client 185.226.198.6:22198] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "al4PqrLfyzVz2SrjZpjRjwAAAjk"]
[Mon Jul 20 06:08:10.354639 2026] [security2:error] [pid 832668:tid 832870] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pqmci6KgEEltqA3DL4wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:10.801835 2026] [security2:error] [pid 832668:tid 832826] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Pqmci6KgEEltqA3DL8QAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:10.901474 2026] [security2:error] [pid 832668:tid 832847] [client 57.141.18.100:30524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PpGci6KgEEltqA3DKYAAALy0"]
[Mon Jul 20 06:08:10.965208 2026] [security2:error] [pid 832668:tid 832825] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pqmci6KgEEltqA3DL_QAAABk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:11.008408 2026] [security2:error] [pid 796567:tid 796676] [remote 173.212.252.15:39102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PqrLfyzVz2SrjZpjRpgACIGw"]
[Mon Jul 20 06:08:11.008579 2026] [security2:error] [pid 796567:tid 796709] [client 173.212.252.15:39102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PqrLfyzVz2SrjZpjRpgACIGw"]
[Mon Jul 20 06:08:11.200782 2026] [security2:error] [pid 832668:tid 832836] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Pq2ci6KgEEltqA3DMCgAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:11.341587 2026] [security2:error] [pid 832668:tid 832730] [remote 194.164.192.228:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pq2ci6KgEEltqA3DMFwAAeTs"]
[Mon Jul 20 06:08:11.540919 2026] [security2:error] [pid 832668:tid 832769] [remote 194.164.192.228:45274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Pq2ci6KgEEltqA3DMIgAALWI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:08:11.738696 2026] [security2:error] [pid 796567:tid 796809] [client 57.141.18.9:21914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PpbLfyzVz2SrjZpjRFAAChDQ"]
[Mon Jul 20 06:08:11.750883 2026] [security2:error] [pid 796567:tid 796710] [client 185.226.198.7:23754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "al4Pq7LfyzVz2SrjZpjRuwAAAiE"]
[Mon Jul 20 06:08:11.820109 2026] [security2:error] [pid 832668:tid 832810] [client 185.132.186.58:39759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/litespeed.php"] [unique_id "al4Pq2ci6KgEEltqA3DMNgAAAAo"]
[Mon Jul 20 06:08:12.077712 2026] [security2:error] [pid 832668:tid 832865] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PrGci6KgEEltqA3DMPgAAAEE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:12.266343 2026] [security2:error] [pid 796567:tid 796794] [client 57.141.18.122:23716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PprLfyzVz2SrjZpjRHgACdWs"]
[Mon Jul 20 06:08:12.382489 2026] [security2:error] [pid 832668:tid 832814] [client 103.141.108.143:65386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMSAAAAA4"]
[Mon Jul 20 06:08:12.382579 2026] [security2:error] [pid 832668:tid 832814] [client 103.141.108.143:65386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMSAAAAA4"]
[Mon Jul 20 06:08:12.422638 2026] [security2:error] [pid 832668:tid 832875] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PrGci6KgEEltqA3DMRgAAAEs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:12.753072 2026] [security2:error] [pid 832668:tid 832914] [client 14.225.17.146:56485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DLzQAAAHI"], referer: http://nextlevelpressurewashing.com/Wordpress
[Mon Jul 20 06:08:12.843544 2026] [security2:error] [pid 832668:tid 832752] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZQAAPFE"]
[Mon Jul 20 06:08:12.843674 2026] [security2:error] [pid 832668:tid 832860] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZQAAPFE"]
[Mon Jul 20 06:08:12.852460 2026] [security2:error] [pid 832668:tid 832922] [client 106.192.104.4:34190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZgAAAHo"]
[Mon Jul 20 06:08:12.852553 2026] [security2:error] [pid 832668:tid 832922] [client 106.192.104.4:34190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4PrGci6KgEEltqA3DMZgAAAHo"]
[Mon Jul 20 06:08:13.019961 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.26:63546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pp2ci6KgEEltqA3DK9AAALn0"]
[Mon Jul 20 06:08:13.036143 2026] [security2:error] [pid 832668:tid 832863] [client 103.77.203.233:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMcAAAAD8"]
[Mon Jul 20 06:08:13.036335 2026] [security2:error] [pid 832668:tid 832863] [client 103.77.203.233:57738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMcAAAAD8"]
[Mon Jul 20 06:08:13.230857 2026] [security2:error] [pid 796567:tid 796770] [client 57.141.18.52:20802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pp7LfyzVz2SrjZpjRNQACXWI"]
[Mon Jul 20 06:08:13.425449 2026] [security2:error] [pid 832668:tid 832758] [remote 209.42.18.223:41614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMgwAAQ1c"]
[Mon Jul 20 06:08:13.425661 2026] [security2:error] [pid 832668:tid 832867] [client 209.42.18.223:41614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMgwAAQ1c"]
[Mon Jul 20 06:08:13.773464 2026] [security2:error] [pid 832668:tid 832834] [client 185.132.186.77:40441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/img/about.php"] [unique_id "al4PrWci6KgEEltqA3DMoAAAACI"]
[Mon Jul 20 06:08:13.885139 2026] [security2:error] [pid 796567:tid 796771] [client 112.213.160.112:30756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PrbLfyzVz2SrjZpjR7gAAAl4"]
[Mon Jul 20 06:08:13.885275 2026] [security2:error] [pid 796567:tid 796771] [client 112.213.160.112:30756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PrbLfyzVz2SrjZpjR7gAAAl4"]
[Mon Jul 20 06:08:13.920261 2026] [security2:error] [pid 832668:tid 832876] [client 115.246.21.170:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMpgAAAEw"]
[Mon Jul 20 06:08:13.920394 2026] [security2:error] [pid 832668:tid 832876] [client 115.246.21.170:46438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PrWci6KgEEltqA3DMpgAAAEw"]
[Mon Jul 20 06:08:13.985902 2026] [security2:error] [pid 796567:tid 796747] [client 35.209.224.174:39182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4PrbLfyzVz2SrjZpjR7wAAAkY"]
[Mon Jul 20 06:08:14.039726 2026] [security2:error] [pid 832668:tid 832823] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Prmci6KgEEltqA3DMrwAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:14.278686 2026] [security2:error] [pid 832668:tid 832910] [client 185.226.198.4:14836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "al4Prmci6KgEEltqA3DMwAAAAG4"]
[Mon Jul 20 06:08:14.515903 2026] [security2:error] [pid 796567:tid 796614] [remote 45.90.123.233:33370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4PrrLfyzVz2SrjZpjSAwACNC4"]
[Mon Jul 20 06:08:14.653962 2026] [security2:error] [pid 796567:tid 796722] [client 45.116.69.230:61248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PrrLfyzVz2SrjZpjSCAAAAi0"]
[Mon Jul 20 06:08:14.654077 2026] [security2:error] [pid 796567:tid 796722] [client 45.116.69.230:61248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PrrLfyzVz2SrjZpjSCAAAAi0"]
[Mon Jul 20 06:08:14.739500 2026] [security2:error] [pid 796567:tid 796628] [remote 45.90.123.233:33370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4PrrLfyzVz2SrjZpjSDAAChjw"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:08:14.955547 2026] [security2:error] [pid 832668:tid 832870] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Prmci6KgEEltqA3DM3wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:14.955714 2026] [security2:error] [pid 832668:tid 832870] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Prmci6KgEEltqA3DM3wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:15.171566 2026] [security2:error] [pid 796567:tid 796726] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PrrLfyzVz2SrjZpjSEAACMR4"]
[Mon Jul 20 06:08:15.171595 2026] [security2:error] [pid 796567:tid 796726] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PrrLfyzVz2SrjZpjSEAACMR4"]
[Mon Jul 20 06:08:15.324266 2026] [security2:error] [pid 832668:tid 832921] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pr2ci6KgEEltqA3DM8QAAAHk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:15.511870 2026] [security2:error] [pid 796567:tid 796725] [client 41.173.37.102:7989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSIAAAAjA"]
[Mon Jul 20 06:08:15.511980 2026] [security2:error] [pid 796567:tid 796725] [client 41.173.37.102:7989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSIAAAAjA"]
[Mon Jul 20 06:08:15.620841 2026] [security2:error] [pid 832668:tid 832847] [client 181.224.94.124:61330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNBwAAAC8"]
[Mon Jul 20 06:08:15.620975 2026] [security2:error] [pid 832668:tid 832847] [client 181.224.94.124:61330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNBwAAAC8"]
[Mon Jul 20 06:08:15.703844 2026] [security2:error] [pid 832668:tid 832927] [client 185.132.186.78:55683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-feed-index.php"] [unique_id "al4Pr2ci6KgEEltqA3DNDQAAAH8"]
[Mon Jul 20 06:08:15.736912 2026] [security2:error] [pid 832668:tid 832871] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pr2ci6KgEEltqA3DNDwAAAEc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:15.800490 2026] [security2:error] [pid 832668:tid 832707] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNFgAAPyQ"]
[Mon Jul 20 06:08:15.800623 2026] [security2:error] [pid 832668:tid 832863] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNFgAAPyQ"]
[Mon Jul 20 06:08:15.950585 2026] [security2:error] [pid 832668:tid 832907] [client 178.152.178.232:37150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNHAAAAGs"]
[Mon Jul 20 06:08:15.955299 2026] [security2:error] [pid 832668:tid 832907] [client 178.152.178.232:37150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pr2ci6KgEEltqA3DNHAAAAGs"]
[Mon Jul 20 06:08:16.005453 2026] [security2:error] [pid 832668:tid 832864] [client 57.141.18.49:56942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PqWci6KgEEltqA3DLuAAAQEk"]
[Mon Jul 20 06:08:16.065422 2026] [security2:error] [pid 832668:tid 832840] [client 185.226.198.7:35850] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "al4PsGci6KgEEltqA3DNJQAAACg"]
[Mon Jul 20 06:08:16.162696 2026] [security2:error] [pid 832668:tid 832821] [client 34.138.198.0:27450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNIwAAABU"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.276823 2026] [security2:error] [pid 832668:tid 832857] [client 14.225.17.146:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4Prmci6KgEEltqA3DM3gAAADk"], referer: http://elitetax-mi.com/Wordpress
[Mon Jul 20 06:08:16.281678 2026] [security2:error] [pid 796567:tid 796622] [remote 20.153.140.50:43254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PsLLfyzVz2SrjZpjSNwACajY"]
[Mon Jul 20 06:08:16.295038 2026] [security2:error] [pid 832668:tid 832811] [client 57.141.18.107:22562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DL3wAACzo"]
[Mon Jul 20 06:08:16.348731 2026] [security2:error] [pid 832668:tid 832910] [client 34.138.198.0:27498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.198.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/wp-config.php"] [unique_id "al4PsGci6KgEEltqA3DNOgAAAG4"]
[Mon Jul 20 06:08:16.377871 2026] [security2:error] [pid 796567:tid 796768] [client 34.138.198.0:27516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSNgAAAls"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.406774 2026] [security2:error] [pid 832668:tid 832917] [client 34.138.198.0:27456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env"] [unique_id "al4PsGci6KgEEltqA3DNQAAAAHU"]
[Mon Jul 20 06:08:16.423508 2026] [security2:error] [pid 796567:tid 796708] [client 34.138.198.0:27528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSOgAAAh8"]
[Mon Jul 20 06:08:16.428309 2026] [security2:error] [pid 832668:tid 832852] [client 34.138.198.0:27530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNNwAAADQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.448073 2026] [security2:error] [pid 832668:tid 832888] [client 34.138.198.0:27536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNOAAAAFg"]
[Mon Jul 20 06:08:16.453420 2026] [security2:error] [pid 832668:tid 832815] [client 34.138.198.0:27548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNPQAAAA8"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.516701 2026] [security2:error] [pid 796567:tid 796806] [client 158.173.241.141:51185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSOQACgQo"]
[Mon Jul 20 06:08:16.518220 2026] [security2:error] [pid 796567:tid 796813] [client 34.138.198.0:27464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.backup"] [unique_id "al4PsLLfyzVz2SrjZpjSQQAAAog"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.528038 2026] [security2:error] [pid 796567:tid 796756] [client 34.138.198.0:27560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.bak"] [unique_id "al4PsLLfyzVz2SrjZpjSRAAAAk8"]
[Mon Jul 20 06:08:16.532739 2026] [security2:error] [pid 832668:tid 832713] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PsGci6KgEEltqA3DNRwAAVyo"]
[Mon Jul 20 06:08:16.532936 2026] [security2:error] [pid 832668:tid 832887] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PsGci6KgEEltqA3DNRwAAVyo"]
[Mon Jul 20 06:08:16.546614 2026] [security2:error] [pid 832668:tid 832802] [client 57.141.18.33:45432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DL5wAAAlA"]
[Mon Jul 20 06:08:16.555161 2026] [security2:error] [pid 832668:tid 832905] [client 34.138.198.0:27506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNQgAAAGk"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.624051 2026] [security2:error] [pid 796567:tid 796784] [client 34.138.198.0:27466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSQgAAAms"]
[Mon Jul 20 06:08:16.625161 2026] [security2:error] [pid 796567:tid 796809] [client 34.138.198.0:27482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsLLfyzVz2SrjZpjSQwAAAoQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.656171 2026] [security2:error] [pid 832668:tid 832915] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PsGci6KgEEltqA3DNSgAAAHM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:16.658781 2026] [security2:error] [pid 796567:tid 796691] [remote 20.153.140.50:43254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4PsLLfyzVz2SrjZpjSRgACd3s"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:08:16.695371 2026] [security2:error] [pid 832668:tid 832908] [client 57.141.18.45:57218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pqmci6KgEEltqA3DL9gAAbBc"]
[Mon Jul 20 06:08:16.811865 2026] [security2:error] [pid 796567:tid 796820] [client 34.138.198.0:27590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/wp-config.php.bak"] [unique_id "al4PsLLfyzVz2SrjZpjSTAAAAo8"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:16.860045 2026] [security2:error] [pid 796567:tid 796741] [client 14.225.17.146:62009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSEgAAAkA"], referer: http://outlookturf.com/Wordpress
[Mon Jul 20 06:08:16.894600 2026] [security2:error] [pid 832668:tid 832819] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PsGci6KgEEltqA3DNVwAAABM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:17.117298 2026] [security2:error] [pid 832668:tid 832926] [client 34.138.198.0:27574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsWci6KgEEltqA3DNXwAAAH4"]
[Mon Jul 20 06:08:17.118818 2026] [security2:error] [pid 796567:tid 796777] [client 34.138.198.0:27596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsbLfyzVz2SrjZpjSUgAAAmQ"]
[Mon Jul 20 06:08:17.198697 2026] [security2:error] [pid 832668:tid 832852] [client 50.116.65.227:45494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4PsWci6KgEEltqA3DNbQAAADQ"]
[Mon Jul 20 06:08:17.201381 2026] [security2:error] [pid 832668:tid 832865] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PsWci6KgEEltqA3DNZwAAAEE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:17.211878 2026] [security2:error] [pid 796567:tid 796720] [client 50.116.65.227:29592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4PsbLfyzVz2SrjZpjSVAAAAis"]
[Mon Jul 20 06:08:17.375016 2026] [security2:error] [pid 796567:tid 796726] [client 52.47.76.32:13650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PsbLfyzVz2SrjZpjSXAAAAjE"]
[Mon Jul 20 06:08:17.375204 2026] [security2:error] [pid 796567:tid 796726] [client 52.47.76.32:13650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PsbLfyzVz2SrjZpjSXAAAAjE"]
[Mon Jul 20 06:08:17.432148 2026] [security2:error] [pid 832668:tid 832806] [client 50.116.65.227:29606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4PsWci6KgEEltqA3DNegAAAAY"]
[Mon Jul 20 06:08:17.443521 2026] [security2:error] [pid 832668:tid 832838] [client 50.116.65.227:29618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4PsWci6KgEEltqA3DNewAAACY"]
[Mon Jul 20 06:08:17.464454 2026] [security2:error] [pid 832668:tid 832915] [client 185.226.198.6:20536] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "al4PsWci6KgEEltqA3DNfgAAAHM"]
[Mon Jul 20 06:08:17.477899 2026] [security2:error] [pid 796567:tid 796753] [client 34.138.198.0:27610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PsbLfyzVz2SrjZpjSXQAAAkw"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:17.607612 2026] [security2:error] [pid 832668:tid 832901] [client 185.132.186.77:34461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wpn.php"] [unique_id "al4PsWci6KgEEltqA3DNgwAAAGU"]
[Mon Jul 20 06:08:17.999614 2026] [security2:error] [pid 832668:tid 832896] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PsWci6KgEEltqA3DNnAAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:18.082847 2026] [security2:error] [pid 832668:tid 832855] [client 74.208.214.194:60244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Psmci6KgEEltqA3DNoQAAADc"]
[Mon Jul 20 06:08:18.305436 2026] [security2:error] [pid 796567:tid 796782] [client 164.100.212.184:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PsrLfyzVz2SrjZpjSbgAAAmk"]
[Mon Jul 20 06:08:18.305555 2026] [security2:error] [pid 796567:tid 796782] [client 164.100.212.184:61410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PsrLfyzVz2SrjZpjSbgAAAmk"]
[Mon Jul 20 06:08:18.344300 2026] [security2:error] [pid 832668:tid 832858] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Psmci6KgEEltqA3DNrQAAADo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:18.497813 2026] [security2:error] [pid 796567:tid 796791] [client 57.141.18.60:46378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PrbLfyzVz2SrjZpjR3wACcgg"]
[Mon Jul 20 06:08:18.813845 2026] [security2:error] [pid 832668:tid 832845] [client 103.95.123.246:20539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Psmci6KgEEltqA3DNyAAAAC0"]
[Mon Jul 20 06:08:18.813997 2026] [security2:error] [pid 832668:tid 832845] [client 103.95.123.246:20539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4Psmci6KgEEltqA3DNyAAAAC0"]
[Mon Jul 20 06:08:18.884180 2026] [security2:error] [pid 832668:tid 832921] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Psmci6KgEEltqA3DNxQAAAHk"]
[Mon Jul 20 06:08:18.997328 2026] [security2:error] [pid 832668:tid 832871] [client 14.225.17.146:50343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4Psmci6KgEEltqA3DNtgAAAEc"], referer: http://carolinapressurewashers.com/Wordpress
[Mon Jul 20 06:08:19.175388 2026] [security2:error] [pid 832668:tid 832906] [client 57.141.18.12:33718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PrWci6KgEEltqA3DMkgAAag0"]
[Mon Jul 20 06:08:19.260848 2026] [security2:error] [pid 832668:tid 832862] [client 114.119.157.24:61703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elementconstruction.co.uk"] [uri "/609-2/"] [unique_id "al4Ps2ci6KgEEltqA3DN6QAAAD4"], referer: https://elementconstruction.co.uk/shop
[Mon Jul 20 06:08:19.287624 2026] [security2:error] [pid 832668:tid 832864] [client 50.116.65.227:30172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Ps2ci6KgEEltqA3DN6wAAAEA"]
[Mon Jul 20 06:08:19.300377 2026] [security2:error] [pid 832668:tid 832908] [client 50.116.65.227:30836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Ps2ci6KgEEltqA3DN7QAAAGw"]
[Mon Jul 20 06:08:19.363434 2026] [security2:error] [pid 832668:tid 832847] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Ps2ci6KgEEltqA3DN6AAAAC8"]
[Mon Jul 20 06:08:19.501679 2026] [security2:error] [pid 832668:tid 832911] [client 103.153.183.69:10494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4Ps2ci6KgEEltqA3DN9wAAAG8"], referer: https://www.google.com/search?q=1pagch
[Mon Jul 20 06:08:19.556813 2026] [security2:error] [pid 832668:tid 832816] [client 185.226.198.6:20538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "al4Ps2ci6KgEEltqA3DN-wAAABA"]
[Mon Jul 20 06:08:19.732989 2026] [security2:error] [pid 832668:tid 832818] [client 34.138.198.0:27640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Ps2ci6KgEEltqA3DN_QAAABI"]
[Mon Jul 20 06:08:19.735039 2026] [security2:error] [pid 832668:tid 832917] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ps2ci6KgEEltqA3DN_wAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:19.744401 2026] [security2:error] [pid 796567:tid 796745] [client 34.138.198.0:27614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Ps7LfyzVz2SrjZpjSkQAAAkQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:19.911308 2026] [security2:error] [pid 832668:tid 832888] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ps2ci6KgEEltqA3DOCQAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:19.911475 2026] [security2:error] [pid 832668:tid 832888] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ps2ci6KgEEltqA3DOCQAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:20.045709 2026] [security2:error] [pid 796567:tid 796761] [client 34.138.198.0:27634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Ps7LfyzVz2SrjZpjSnQAAAlQ"]
[Mon Jul 20 06:08:20.231619 2026] [security2:error] [pid 796567:tid 796751] [client 14.225.17.146:62053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4PsrLfyzVz2SrjZpjSdgAAAko"], referer: http://samdothan.org/Wordpress
[Mon Jul 20 06:08:20.232647 2026] [security2:error] [pid 832668:tid 832869] [client 34.138.198.0:27618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtGci6KgEEltqA3DOFAAAAEU"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:20.237037 2026] [security2:error] [pid 796567:tid 796747] [client 34.138.198.0:27680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtLLfyzVz2SrjZpjSpgAAAkY"]
[Mon Jul 20 06:08:20.298474 2026] [security2:error] [pid 796567:tid 796712] [client 34.138.198.0:27670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtLLfyzVz2SrjZpjSqQAAAiM"]
[Mon Jul 20 06:08:20.299610 2026] [security2:error] [pid 832668:tid 832723] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.bak"] [unique_id "al4PtGci6KgEEltqA3DOHwAAfjQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:20.354606 2026] [security2:error] [pid 832668:tid 832835] [client 34.138.198.0:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/.env.old"] [unique_id "al4PtGci6KgEEltqA3DOIgAAACM"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:20.383955 2026] [security2:error] [pid 832668:tid 832860] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4PtGci6KgEEltqA3DOIAAAADw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:20.459781 2026] [security2:error] [pid 832668:tid 832876] [client 57.141.18.54:47198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Prmci6KgEEltqA3DM2QAATCY"]
[Mon Jul 20 06:08:20.474347 2026] [security2:error] [pid 832668:tid 832678] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PtGci6KgEEltqA3DOJwAAPQc"]
[Mon Jul 20 06:08:20.474494 2026] [security2:error] [pid 832668:tid 832861] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PtGci6KgEEltqA3DOJwAAPQc"]
[Mon Jul 20 06:08:20.510150 2026] [security2:error] [pid 832668:tid 832883] [client 34.138.198.0:27642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PtGci6KgEEltqA3DOJQAAAFM"]
[Mon Jul 20 06:08:20.688270 2026] [security2:error] [pid 832668:tid 832924] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PtGci6KgEEltqA3DONwAAAHw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:20.854245 2026] [security2:error] [pid 832668:tid 832903] [client 103.153.183.69:10494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4PtGci6KgEEltqA3DOPgAAAGc"], referer: https://twitter.com/
[Mon Jul 20 06:08:20.866630 2026] [security2:error] [pid 796567:tid 796780] [client 57.141.18.110:56434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSHAACZ1s"]
[Mon Jul 20 06:08:20.878466 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.82:57996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pr7LfyzVz2SrjZpjSHQACY2A"]
[Mon Jul 20 06:08:21.316355 2026] [security2:error] [pid 796567:tid 796779] [client 185.226.198.6:20548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "al4PtbLfyzVz2SrjZpjS1QAAAmY"]
[Mon Jul 20 06:08:21.651025 2026] [security2:error] [pid 796567:tid 796751] [client 185.132.186.90:30581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/classwithtostring.php"] [unique_id "al4PtbLfyzVz2SrjZpjS3gAAAko"]
[Mon Jul 20 06:08:21.686277 2026] [security2:error] [pid 832668:tid 832803] [client 14.225.17.146:50396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4PtGci6KgEEltqA3DOHAAAAAM"], referer: http://slutilities.com/Wordpress
[Mon Jul 20 06:08:21.797069 2026] [security2:error] [pid 832668:tid 832868] [client 57.141.18.14:48876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PsGci6KgEEltqA3DNSwAARDw"]
[Mon Jul 20 06:08:21.970286 2026] [security2:error] [pid 796567:tid 796733] [client 103.178.3.191:40654] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PtbLfyzVz2SrjZpjS6QAAAjg"]
[Mon Jul 20 06:08:22.008177 2026] [security2:error] [pid 796567:tid 796697] [client 14.225.17.146:57977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PtbLfyzVz2SrjZpjS6gAAAhQ"], referer: http://iagdevelopments.com/Wordpress
[Mon Jul 20 06:08:22.111926 2026] [security2:error] [pid 796567:tid 796733] [client 103.178.3.191:40654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PtbLfyzVz2SrjZpjS6QAAAjg"]
[Mon Jul 20 06:08:22.316969 2026] [security2:error] [pid 832668:tid 832920] [client 57.141.18.61:33076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PsWci6KgEEltqA3DNZQAAeFQ"]
[Mon Jul 20 06:08:22.991571 2026] [security2:error] [pid 832668:tid 832870] [client 103.141.108.143:49443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ptmci6KgEEltqA3DOlAAAAEY"]
[Mon Jul 20 06:08:22.992969 2026] [security2:error] [pid 832668:tid 832870] [client 103.141.108.143:49443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ptmci6KgEEltqA3DOlAAAAEY"]
[Mon Jul 20 06:08:23.026536 2026] [security2:error] [pid 796567:tid 796715] [client 14.225.17.146:57126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4PtrLfyzVz2SrjZpjTBwAAAiY"], referer: https://iagdevelopments.com/Wordpress
[Mon Jul 20 06:08:23.099590 2026] [security2:error] [pid 832668:tid 832826] [client 185.226.198.4:44612] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "laceycaraccident.com"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "al4Pt2ci6KgEEltqA3DOmwAAABo"]
[Mon Jul 20 06:08:23.373142 2026] [security2:error] [pid 832668:tid 832901] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Pt2ci6KgEEltqA3DOqQAAAGU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:23.390684 2026] [security2:error] [pid 832668:tid 832718] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOrQAAQS8"]
[Mon Jul 20 06:08:23.390856 2026] [security2:error] [pid 832668:tid 832865] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOrQAAQS8"]
[Mon Jul 20 06:08:23.522619 2026] [security2:error] [pid 832668:tid 832873] [client 103.77.203.233:57827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOtgAAAEk"]
[Mon Jul 20 06:08:23.522761 2026] [security2:error] [pid 832668:tid 832873] [client 103.77.203.233:57827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt2ci6KgEEltqA3DOtgAAAEk"]
[Mon Jul 20 06:08:23.639868 2026] [security2:error] [pid 832668:tid 832694] [remote 91.142.222.105:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Pt2ci6KgEEltqA3DOvAAANxc"]
[Mon Jul 20 06:08:23.696791 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4Ptmci6KgEEltqA3DObwAAVB0"], referer: http://ardhalwafaa.com/Wordpress
[Mon Jul 20 06:08:23.752432 2026] [security2:error] [pid 832668:tid 832893] [client 103.178.3.191:40703] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pt2ci6KgEEltqA3DOwQAAAF0"]
[Mon Jul 20 06:08:23.876662 2026] [security2:error] [pid 832668:tid 832893] [client 103.178.3.191:40703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pt2ci6KgEEltqA3DOwQAAAF0"]
[Mon Jul 20 06:08:23.992384 2026] [security2:error] [pid 832668:tid 832761] [remote 91.142.222.105:49126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Pt2ci6KgEEltqA3DOzAAABVo"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:08:23.995553 2026] [security2:error] [pid 796567:tid 796801] [client 106.192.104.4:53178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt7LfyzVz2SrjZpjTKgAAAnw"]
[Mon Jul 20 06:08:23.995669 2026] [security2:error] [pid 796567:tid 796801] [client 106.192.104.4:53178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pt7LfyzVz2SrjZpjTKgAAAnw"]
[Mon Jul 20 06:08:23.995719 2026] [security2:error] [pid 832668:tid 832922] [client 57.141.18.41:46272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Psmci6KgEEltqA3DNzQAAeiU"]
[Mon Jul 20 06:08:24.132540 2026] [security2:error] [pid 832668:tid 832822] [client 98.159.234.160:40461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PuGci6KgEEltqA3DO1AAAABY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:24.339238 2026] [security2:error] [pid 796567:tid 796744] [client 57.141.18.87:33890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ps7LfyzVz2SrjZpjSfgACQ2Y"]
[Mon Jul 20 06:08:24.378277 2026] [security2:error] [pid 832668:tid 832860] [client 115.246.21.170:6282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PuGci6KgEEltqA3DO4QAAADw"]
[Mon Jul 20 06:08:24.378390 2026] [security2:error] [pid 832668:tid 832860] [client 115.246.21.170:6282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PuGci6KgEEltqA3DO4QAAADw"]
[Mon Jul 20 06:08:24.443113 2026] [security2:error] [pid 832668:tid 832858] [client 14.225.17.146:60297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Pt2ci6KgEEltqA3DOyAAAADo"], referer: http://laceycaraccident.com/Wordpress
[Mon Jul 20 06:08:24.481969 2026] [security2:error] [pid 796567:tid 796822] [client 112.213.160.112:30745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PuLLfyzVz2SrjZpjTOQAAApE"]
[Mon Jul 20 06:08:24.482084 2026] [security2:error] [pid 796567:tid 796822] [client 112.213.160.112:30745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PuLLfyzVz2SrjZpjTOQAAApE"]
[Mon Jul 20 06:08:24.520517 2026] [security2:error] [pid 832668:tid 832898] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PuGci6KgEEltqA3DO6wAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.109509 2026] [security2:error] [pid 832668:tid 832887] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4PuWci6KgEEltqA3DPBQAAAFc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.194869 2026] [security2:error] [pid 832668:tid 832882] [client 57.141.18.23:53056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ps2ci6KgEEltqA3DOCwAAUho"]
[Mon Jul 20 06:08:25.225702 2026] [security2:error] [pid 796567:tid 796707] [client 185.226.198.6:29430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4PuLLfyzVz2SrjZpjTQAAAAh4"], referer: http://laceycaraccident.com/sugar_version.json
[Mon Jul 20 06:08:25.238262 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:60291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4Pt2ci6KgEEltqA3DOywAAABw"], referer: http://39ishlife.com/Wordpress
[Mon Jul 20 06:08:25.242382 2026] [core:error] [pid 832668:tid 832816] [client 14.225.17.146:55556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wordpress
[Mon Jul 20 06:08:25.242406 2026] [core:error] [pid 832668:tid 832816] [client 14.225.17.146:55556] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wordpress
[Mon Jul 20 06:08:25.290668 2026] [security2:error] [pid 832668:tid 832817] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PuWci6KgEEltqA3DPGAAAABE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.312046 2026] [security2:error] [pid 832668:tid 832805] [client 45.116.69.230:61707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PuWci6KgEEltqA3DPGwAAAAU"]
[Mon Jul 20 06:08:25.313036 2026] [security2:error] [pid 832668:tid 832805] [client 45.116.69.230:61707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4PuWci6KgEEltqA3DPGwAAAAU"]
[Mon Jul 20 06:08:25.466782 2026] [security2:error] [pid 832668:tid 832884] [client 103.178.3.191:40743] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PuWci6KgEEltqA3DPJQAAAFQ"]
[Mon Jul 20 06:08:25.617338 2026] [security2:error] [pid 832668:tid 832884] [client 103.178.3.191:40743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PuWci6KgEEltqA3DPJQAAAFQ"]
[Mon Jul 20 06:08:25.618889 2026] [security2:error] [pid 832668:tid 832847] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4PuWci6KgEEltqA3DPKwAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:25.999551 2026] [security2:error] [pid 796567:tid 796709] [client 14.225.17.146:55453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4PubLfyzVz2SrjZpjTWwAAAiA"], referer: http://longevityperformanceclinic.com/Wordpress
[Mon Jul 20 06:08:26.146680 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:8438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PurLfyzVz2SrjZpjTZgAAAmo"]
[Mon Jul 20 06:08:26.146758 2026] [security2:error] [pid 832668:tid 832913] [client 181.224.94.124:39321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPRwAAAHE"]
[Mon Jul 20 06:08:26.146807 2026] [security2:error] [pid 796567:tid 796783] [client 41.173.37.102:8438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PurLfyzVz2SrjZpjTZgAAAmo"]
[Mon Jul 20 06:08:26.146867 2026] [security2:error] [pid 832668:tid 832913] [client 181.224.94.124:39321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPRwAAAHE"]
[Mon Jul 20 06:08:26.304269 2026] [security2:error] [pid 832668:tid 832817] [client 14.225.17.146:55775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4Pumci6KgEEltqA3DPRAAAABE"]
[Mon Jul 20 06:08:26.340902 2026] [security2:error] [pid 796567:tid 796806] [client 14.225.17.146:58035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4PurLfyzVz2SrjZpjTawAAAoE"], referer: https://39ishlife.com/Wordpress
[Mon Jul 20 06:08:26.379714 2026] [security2:error] [pid 832668:tid 832869] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pumci6KgEEltqA3DPVQAAAEU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:26.446148 2026] [security2:error] [pid 796567:tid 796770] [client 57.141.18.42:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PtbLfyzVz2SrjZpjS0AACXSk"]
[Mon Jul 20 06:08:26.503124 2026] [security2:error] [pid 832668:tid 832796] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPWgAAEn0"]
[Mon Jul 20 06:08:26.503300 2026] [security2:error] [pid 832668:tid 832818] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPWgAAEn0"]
[Mon Jul 20 06:08:26.566264 2026] [security2:error] [pid 832668:tid 832918] [client 178.152.178.232:36018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPXAAAAHY"]
[Mon Jul 20 06:08:26.566407 2026] [security2:error] [pid 832668:tid 832918] [client 178.152.178.232:36018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pumci6KgEEltqA3DPXAAAAHY"]
[Mon Jul 20 06:08:26.612230 2026] [security2:error] [pid 796567:tid 796777] [client 185.132.186.60:37791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/iR7SzrsOUEP.php"] [unique_id "al4PurLfyzVz2SrjZpjTfQAAAmQ"]
[Mon Jul 20 06:08:26.757922 2026] [security2:error] [pid 796567:tid 796708] [client 57.141.18.51:60748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PtbLfyzVz2SrjZpjS4gACH0M"]
[Mon Jul 20 06:08:26.792327 2026] [security2:error] [pid 796567:tid 796701] [client 103.178.3.191:40783] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PurLfyzVz2SrjZpjThgAAAhg"]
[Mon Jul 20 06:08:26.915276 2026] [security2:error] [pid 796567:tid 796701] [client 103.178.3.191:40783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PurLfyzVz2SrjZpjThgAAAhg"]
[Mon Jul 20 06:08:27.176385 2026] [security2:error] [pid 832668:tid 832684] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdAAAfg0"]
[Mon Jul 20 06:08:27.176530 2026] [security2:error] [pid 832668:tid 832926] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdAAAfg0"]
[Mon Jul 20 06:08:27.223852 2026] [security2:error] [pid 832668:tid 832856] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdwAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:27.223972 2026] [security2:error] [pid 832668:tid 832856] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pu2ci6KgEEltqA3DPdwAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:27.579924 2026] [security2:error] [pid 832668:tid 832849] [client 50.116.65.227:30942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Pu2ci6KgEEltqA3DPggAAADE"]
[Mon Jul 20 06:08:27.589924 2026] [security2:error] [pid 832668:tid 832815] [client 50.116.65.227:30944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Pu2ci6KgEEltqA3DPgwAAAA8"]
[Mon Jul 20 06:08:27.872513 2026] [security2:error] [pid 832668:tid 832916] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPkAAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:27.896879 2026] [security2:error] [pid 832668:tid 832899] [client 34.138.198.0:62096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.backup"] [unique_id "al4Pu2ci6KgEEltqA3DPlgAAAGM"]
[Mon Jul 20 06:08:27.898460 2026] [security2:error] [pid 832668:tid 832892] [client 34.138.198.0:62106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env"] [unique_id "al4Pu2ci6KgEEltqA3DPmQAAAFw"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:27.906199 2026] [security2:error] [pid 832668:tid 832836] [client 34.138.198.0:62174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.rtkenergypartners.com"] [uri "/wp-config.php.bak"] [unique_id "al4Pu2ci6KgEEltqA3DPoAAAACQ"]
[Mon Jul 20 06:08:27.994745 2026] [security2:error] [pid 832668:tid 832911] [client 34.138.198.0:62160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.198.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.rtkenergypartners.com"] [uri "/wp-config.php"] [unique_id "al4Pu2ci6KgEEltqA3DPqAAAAG8"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.033954 2026] [security2:error] [pid 832668:tid 832876] [client 34.138.198.0:62222] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.bak"] [unique_id "al4PvGci6KgEEltqA3DPqQAAAEw"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.040156 2026] [security2:error] [pid 832668:tid 832845] [client 34.138.198.0:62130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPlwAAAC0"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.042577 2026] [security2:error] [pid 832668:tid 832921] [client 34.138.198.0:62112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPmgAAAHk"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.043432 2026] [security2:error] [pid 832668:tid 832807] [client 34.138.198.0:62186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPnQAAAAc"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.043834 2026] [security2:error] [pid 832668:tid 832868] [client 34.138.198.0:62132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPmwAAAEQ"]
[Mon Jul 20 06:08:28.048078 2026] [security2:error] [pid 832668:tid 832814] [client 34.138.198.0:62154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPnAAAAA4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.057938 2026] [security2:error] [pid 832668:tid 832918] [client 34.138.198.0:62126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPmAAAAHY"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.133958 2026] [security2:error] [pid 832668:tid 832850] [client 34.138.198.0:62230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpQAAADI"]
[Mon Jul 20 06:08:28.135413 2026] [security2:error] [pid 832668:tid 832866] [client 34.138.198.0:62258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpgAAAEI"]
[Mon Jul 20 06:08:28.135728 2026] [security2:error] [pid 832668:tid 832846] [client 34.138.198.0:62246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpwAAAC4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.136120 2026] [security2:error] [pid 832668:tid 832894] [client 34.138.198.0:62198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu2ci6KgEEltqA3DPpAAAAF4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.140400 2026] [security2:error] [pid 796567:tid 796756] [client 34.138.198.0:62236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pu7LfyzVz2SrjZpjTtwAAAk8"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.175280 2026] [security2:error] [pid 832668:tid 832812] [client 34.138.198.0:62210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvGci6KgEEltqA3DPrgAAAAw"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:28.330851 2026] [security2:error] [pid 796567:tid 796811] [client 14.225.17.146:55452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4PurLfyzVz2SrjZpjTjQAAAoY"], referer: http://scott-assist.com/Wordpress
[Mon Jul 20 06:08:28.337771 2026] [security2:error] [pid 796567:tid 796742] [client 103.178.3.191:40816] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvLLfyzVz2SrjZpjTxwAAAkE"]
[Mon Jul 20 06:08:28.480115 2026] [security2:error] [pid 796567:tid 796742] [client 103.178.3.191:40816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvLLfyzVz2SrjZpjTxwAAAkE"]
[Mon Jul 20 06:08:28.502213 2026] [security2:error] [pid 832668:tid 832825] [client 185.132.186.93:34557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section-boolean.php"] [unique_id "al4PvGci6KgEEltqA3DPxAAAABk"]
[Mon Jul 20 06:08:28.521815 2026] [security2:error] [pid 832668:tid 832888] [client 185.61.219.192:28311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "oohlovely.com"] [uri "/xmlrpc.php"] [unique_id "al4Pu2ci6KgEEltqA3DPgQAAWBY"]
[Mon Jul 20 06:08:28.546200 2026] [security2:error] [pid 796567:tid 796612] [remote 57.141.18.37:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3187007"] [unique_id "al4PvLLfyzVz2SrjZpjT0AACYSw"]
[Mon Jul 20 06:08:28.643545 2026] [security2:error] [pid 796567:tid 796728] [client 164.100.212.184:59198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PvLLfyzVz2SrjZpjT1AAAAjM"]
[Mon Jul 20 06:08:28.643671 2026] [security2:error] [pid 796567:tid 796728] [client 164.100.212.184:59198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4PvLLfyzVz2SrjZpjT1AAAAjM"]
[Mon Jul 20 06:08:29.175798 2026] [core:error] [pid 832668:tid 832850] [client 14.225.17.146:53942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wordpress
[Mon Jul 20 06:08:29.175826 2026] [core:error] [pid 832668:tid 832850] [client 14.225.17.146:53942] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wordpress
[Mon Jul 20 06:08:29.219478 2026] [security2:error] [pid 832668:tid 832877] [client 57.141.18.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP4gAAAE0"]
[Mon Jul 20 06:08:29.232027 2026] [security2:error] [pid 832668:tid 832803] [client 57.141.18.18:32486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PuGci6KgEEltqA3DOzwAAA18"]
[Mon Jul 20 06:08:29.321275 2026] [security2:error] [pid 832668:tid 832904] [client 34.138.198.0:62272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP6AAAAGg"], referer: https://www.rtkenergypartners.com/.env.local
[Mon Jul 20 06:08:29.334502 2026] [security2:error] [pid 832668:tid 832811] [client 34.138.198.0:62294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP6QAAAAs"], referer: https://www.rtkenergypartners.com/.env.sample
[Mon Jul 20 06:08:29.405039 2026] [security2:error] [pid 832668:tid 832906] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PvWci6KgEEltqA3DP8QAAAGo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:29.511479 2026] [security2:error] [pid 832668:tid 832901] [client 34.138.198.0:62352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP8AAAAGU"], referer: https://www.rtkenergypartners.com/.env.save
[Mon Jul 20 06:08:29.549435 2026] [security2:error] [pid 796567:tid 796810] [client 34.138.198.0:62400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjT9wAAAoU"], referer: https://www.rtkenergypartners.com/.dev.vars
[Mon Jul 20 06:08:29.610956 2026] [security2:error] [pid 832668:tid 832862] [client 57.141.18.25:39782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PuGci6KgEEltqA3DO4wAAPmQ"]
[Mon Jul 20 06:08:29.614358 2026] [security2:error] [pid 796567:tid 796738] [client 34.138.198.0:62410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjT_AAAAj0"], referer: https://www.rtkenergypartners.com/config.yaml
[Mon Jul 20 06:08:29.621840 2026] [security2:error] [pid 832668:tid 832853] [client 34.138.198.0:62362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP_QAAADU"], referer: https://www.rtkenergypartners.com/api/config
[Mon Jul 20 06:08:29.624291 2026] [security2:error] [pid 832668:tid 832842] [client 34.138.198.0:62306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DP-gAAACo"], referer: https://www.rtkenergypartners.com/.env.test
[Mon Jul 20 06:08:29.644759 2026] [security2:error] [pid 832668:tid 832825] [client 34.138.198.0:62278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DQAAAAABk"], referer: https://www.rtkenergypartners.com/.npmrc
[Mon Jul 20 06:08:29.747842 2026] [ssl:error] [pid 832668:tid 832883] [client 104.48.69.105:58172] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:08:29.750457 2026] [security2:error] [pid 832668:tid 832916] [client 34.138.198.0:62378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DQAQAAAHQ"], referer: https://www.rtkenergypartners.com/.env.production
[Mon Jul 20 06:08:29.804577 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PvWci6KgEEltqA3DQBAAAAC8"]
[Mon Jul 20 06:08:29.804707 2026] [security2:error] [pid 832668:tid 832847] [client 103.95.123.246:21047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PvWci6KgEEltqA3DQBAAAAC8"]
[Mon Jul 20 06:08:29.875887 2026] [security2:error] [pid 832668:tid 832892] [client 103.178.3.191:40880] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvWci6KgEEltqA3DQCQAAAFw"]
[Mon Jul 20 06:08:29.917850 2026] [security2:error] [pid 796567:tid 796731] [client 34.138.198.0:62336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjUAwAAAjY"], referer: https://www.rtkenergypartners.com/.git/config
[Mon Jul 20 06:08:29.924928 2026] [security2:error] [pid 796567:tid 796794] [client 34.138.198.0:62320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvbLfyzVz2SrjZpjUBAAAAnU"], referer: https://www.rtkenergypartners.com/.aws/credentials
[Mon Jul 20 06:08:29.974179 2026] [security2:error] [pid 832668:tid 832878] [client 34.138.198.0:62388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PvWci6KgEEltqA3DQCgAAAE4"], referer: https://www.rtkenergypartners.com/.git/HEAD
[Mon Jul 20 06:08:29.980569 2026] [security2:error] [pid 832668:tid 832812] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4PvWci6KgEEltqA3DQCwAAAAw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:30.001921 2026] [security2:error] [pid 832668:tid 832892] [client 103.178.3.191:40880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PvWci6KgEEltqA3DQCQAAAFw"]
[Mon Jul 20 06:08:30.129081 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:57063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4Pvmci6KgEEltqA3DQFgAAAAg"]
[Mon Jul 20 06:08:30.129309 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:57063] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4Pvmci6KgEEltqA3DQFgAAAAg"]
[Mon Jul 20 06:08:30.270690 2026] [security2:error] [pid 796567:tid 796719] [client 14.225.17.146:63351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4PvrLfyzVz2SrjZpjUEgAAAio"], referer: http://dasmarque.com/Wordpress
[Mon Jul 20 06:08:30.379432 2026] [security2:error] [pid 832668:tid 832866] [client 27.96.94.195:37687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQIQAAAEI"]
[Mon Jul 20 06:08:30.379539 2026] [security2:error] [pid 832668:tid 832866] [client 27.96.94.195:37687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQIQAAAEI"]
[Mon Jul 20 06:08:30.412879 2026] [security2:error] [pid 796567:tid 796727] [client 57.141.18.69:22328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PubLfyzVz2SrjZpjTRwACMiQ"]
[Mon Jul 20 06:08:30.484632 2026] [security2:error] [pid 832668:tid 832922] [client 185.132.186.87:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/functions.php"] [unique_id "al4Pvmci6KgEEltqA3DQIwAAAHo"]
[Mon Jul 20 06:08:30.631500 2026] [security2:error] [pid 832668:tid 832834] [client 54.196.52.99:16666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.52.196.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQNAAAACI"]
[Mon Jul 20 06:08:30.631649 2026] [security2:error] [pid 832668:tid 832834] [client 54.196.52.99:16666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pvmci6KgEEltqA3DQNAAAACI"]
[Mon Jul 20 06:08:30.889700 2026] [security2:error] [pid 832668:tid 832691] [remote 162.19.86.63:57145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Pvmci6KgEEltqA3DQPwAANRQ"]
[Mon Jul 20 06:08:30.955470 2026] [security2:error] [pid 796567:tid 796709] [client 191.237.250.106:29814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4PvrLfyzVz2SrjZpjUMAAAAiA"]
[Mon Jul 20 06:08:30.955597 2026] [security2:error] [pid 796567:tid 796709] [client 191.237.250.106:29814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4PvrLfyzVz2SrjZpjUMAAAAiA"]
[Mon Jul 20 06:08:30.995289 2026] [security2:error] [pid 796567:tid 796627] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PvrLfyzVz2SrjZpjUNAACaTs"]
[Mon Jul 20 06:08:30.995449 2026] [security2:error] [pid 796567:tid 796782] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PvrLfyzVz2SrjZpjUNAACaTs"]
[Mon Jul 20 06:08:30.998282 2026] [security2:error] [pid 796567:tid 796817] [client 57.141.18.102:57882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PubLfyzVz2SrjZpjTVwACjC8"]
[Mon Jul 20 06:08:31.127621 2026] [security2:error] [pid 832668:tid 832701] [remote 162.19.86.63:57145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Pv2ci6KgEEltqA3DQSAAAYR4"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:08:31.440855 2026] [security2:error] [pid 796567:tid 796814] [client 103.178.3.191:40916] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUQwAAAok"]
[Mon Jul 20 06:08:31.447530 2026] [security2:error] [pid 832668:tid 832810] [client 14.225.17.146:53154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4Pvmci6KgEEltqA3DQEQAAAAo"], referer: http://dadanetnet.net/Wordpress
[Mon Jul 20 06:08:31.559884 2026] [security2:error] [pid 796567:tid 796814] [client 103.178.3.191:40916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUQwAAAok"]
[Mon Jul 20 06:08:31.665501 2026] [security2:error] [pid 832668:tid 832852] [client 57.141.18.35:31448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pumci6KgEEltqA3DPVwAANEo"]
[Mon Jul 20 06:08:31.689013 2026] [security2:error] [pid 832668:tid 832883] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Pv2ci6KgEEltqA3DQVwAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:31.810949 2026] [security2:error] [pid 796567:tid 796808] [client 193.19.109.251:46731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUWAAAAoM"]
[Mon Jul 20 06:08:31.830690 2026] [security2:error] [pid 796567:tid 796798] [client 193.19.109.231:44089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUVwAAAnk"]
[Mon Jul 20 06:08:31.986595 2026] [security2:error] [pid 832668:tid 832831] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Pv2ci6KgEEltqA3DQXgAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:32.204902 2026] [security2:error] [pid 796567:tid 796736] [client 191.237.250.106:37593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/x.php"] [unique_id "al4PwLLfyzVz2SrjZpjUZgAAAjs"]
[Mon Jul 20 06:08:32.205008 2026] [security2:error] [pid 796567:tid 796736] [client 191.237.250.106:37593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/x.php"] [unique_id "al4PwLLfyzVz2SrjZpjUZgAAAjs"]
[Mon Jul 20 06:08:32.370775 2026] [security2:error] [pid 832668:tid 832803] [client 74.208.214.194:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4PwGci6KgEEltqA3DQcwAAAAM"]
[Mon Jul 20 06:08:32.480734 2026] [security2:error] [pid 796567:tid 796704] [client 185.132.186.66:31567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/db.php"] [unique_id "al4PwLLfyzVz2SrjZpjUcQAAAhs"]
[Mon Jul 20 06:08:32.730999 2026] [security2:error] [pid 832668:tid 832898] [client 34.138.198.0:62424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQewAAAGI"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:32.827602 2026] [security2:error] [pid 796567:tid 796819] [client 34.138.198.0:62430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwLLfyzVz2SrjZpjUfgAAAo4"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:32.865387 2026] [security2:error] [pid 796567:tid 796799] [client 191.237.250.106:16320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/mgrr.php"] [unique_id "al4PwLLfyzVz2SrjZpjUhgAAAno"]
[Mon Jul 20 06:08:32.865487 2026] [security2:error] [pid 796567:tid 796799] [client 191.237.250.106:16320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/mgrr.php"] [unique_id "al4PwLLfyzVz2SrjZpjUhgAAAno"]
[Mon Jul 20 06:08:32.963919 2026] [security2:error] [pid 796567:tid 796651] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.bak"] [unique_id "al4PwLLfyzVz2SrjZpjUiQACFFM"]
[Mon Jul 20 06:08:33.124869 2026] [security2:error] [pid 832668:tid 832840] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQhgAAKAU"]
[Mon Jul 20 06:08:33.124906 2026] [security2:error] [pid 832668:tid 832840] [client 2603:1026:900:6::6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQhgAAKAU"]
[Mon Jul 20 06:08:33.251764 2026] [security2:error] [pid 832668:tid 832891] [client 34.138.198.0:62434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwWci6KgEEltqA3DQjwAAAFs"]
[Mon Jul 20 06:08:33.381826 2026] [security2:error] [pid 832668:tid 832805] [client 104.234.53.71:27973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PwWci6KgEEltqA3DQnQAAAAU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:33.504830 2026] [security2:error] [pid 832668:tid 832854] [client 14.224.227.113:58323] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4PwWci6KgEEltqA3DQpQAAADY"]
[Mon Jul 20 06:08:33.568479 2026] [security2:error] [pid 832668:tid 832924] [client 103.178.3.191:40957] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PwWci6KgEEltqA3DQqgAAAHw"]
[Mon Jul 20 06:08:33.675091 2026] [security2:error] [pid 832668:tid 832919] [client 103.141.108.143:49892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PwWci6KgEEltqA3DQsAAAAHc"]
[Mon Jul 20 06:08:33.675304 2026] [security2:error] [pid 832668:tid 832919] [client 103.141.108.143:49892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PwWci6KgEEltqA3DQsAAAAHc"]
[Mon Jul 20 06:08:33.691033 2026] [security2:error] [pid 832668:tid 832905] [client 34.138.198.0:62456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwWci6KgEEltqA3DQqwAAAGk"], referer: https://www.rtkenergypartners.com/.pypirc
[Mon Jul 20 06:08:33.720490 2026] [security2:error] [pid 832668:tid 832924] [client 103.178.3.191:40957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4PwWci6KgEEltqA3DQqgAAAHw"]
[Mon Jul 20 06:08:33.742424 2026] [security2:error] [pid 796567:tid 796745] [client 158.173.166.181:57887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4PwbLfyzVz2SrjZpjUsgAAAkQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:33.781589 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/stdin.php"] [unique_id "al4PwWci6KgEEltqA3DQwQAAAHk"]
[Mon Jul 20 06:08:33.781685 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/stdin.php"] [unique_id "al4PwWci6KgEEltqA3DQwQAAAHk"]
[Mon Jul 20 06:08:33.957489 2026] [security2:error] [pid 832668:tid 832899] [client 34.138.198.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PwWci6KgEEltqA3DQyAAAAGM"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:34.028545 2026] [security2:error] [pid 796567:tid 796710] [client 34.138.198.0:62440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwbLfyzVz2SrjZpjUuQAAAiE"], referer: https://www.rtkenergypartners.com/.env.dist
[Mon Jul 20 06:08:34.047332 2026] [security2:error] [pid 796567:tid 796707] [client 103.77.203.233:57913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjUvAAAAh4"]
[Mon Jul 20 06:08:34.047831 2026] [security2:error] [pid 796567:tid 796707] [client 103.77.203.233:57913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjUvAAAAh4"]
[Mon Jul 20 06:08:34.082653 2026] [security2:error] [pid 832668:tid 832761] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pwmci6KgEEltqA3DQ0AAAVVo"]
[Mon Jul 20 06:08:34.082803 2026] [security2:error] [pid 832668:tid 832885] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Pwmci6KgEEltqA3DQ0AAAVVo"]
[Mon Jul 20 06:08:34.254198 2026] [security2:error] [pid 832668:tid 832888] [client 173.239.254.42:48029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Pwmci6KgEEltqA3DQ1wAAAFg"]
[Mon Jul 20 06:08:34.265044 2026] [security2:error] [pid 796567:tid 796709] [client 193.19.109.227:52869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4PwrLfyzVz2SrjZpjU0AAAAiA"]
[Mon Jul 20 06:08:34.312323 2026] [security2:error] [pid 796567:tid 796737] [client 193.19.109.241:23167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4PwrLfyzVz2SrjZpjU0QAAAjw"]
[Mon Jul 20 06:08:34.368827 2026] [security2:error] [pid 832668:tid 832874] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ2AAAAEo"]
[Mon Jul 20 06:08:34.400368 2026] [security2:error] [pid 832668:tid 832826] [client 104.234.53.71:27973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Pwmci6KgEEltqA3DQ3gAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:34.415701 2026] [security2:error] [pid 796567:tid 796813] [client 14.225.17.146:62264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4PwLLfyzVz2SrjZpjUgQAAAog"], referer: http://eframiproperties.com/Wordpress
[Mon Jul 20 06:08:34.420836 2026] [security2:error] [pid 832668:tid 832840] [client 34.138.198.0:62462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ2wAAACg"]
[Mon Jul 20 06:08:34.478009 2026] [security2:error] [pid 832668:tid 832854] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ3wAAADY"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:34.627981 2026] [security2:error] [pid 796567:tid 796697] [client 34.138.198.0:62476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rtkenergypartners.com"] [uri "/.env.old"] [unique_id "al4PwrLfyzVz2SrjZpjU4AAAAhQ"]
[Mon Jul 20 06:08:34.630606 2026] [security2:error] [pid 832668:tid 832903] [client 34.138.198.0:62464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ7AAAAGc"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:34.744553 2026] [security2:error] [pid 832668:tid 832900] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DQ-AAAAGQ"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:34.789722 2026] [security2:error] [pid 796567:tid 796717] [client 34.138.198.0:62490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU5AAAAig"], referer: https://www.google.com/search?q=www.rtkenergypartners.com
[Mon Jul 20 06:08:34.875306 2026] [security2:error] [pid 796567:tid 796784] [client 34.138.198.0:62498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU5wAAAms"], referer: https://www.rtkenergypartners.com/.netrc
[Mon Jul 20 06:08:34.938581 2026] [security2:error] [pid 796567:tid 796812] [client 57.141.18.26:63154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PvrLfyzVz2SrjZpjUFQACh24"]
[Mon Jul 20 06:08:34.968910 2026] [security2:error] [pid 832668:tid 832924] [client 34.138.198.0:62504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pwmci6KgEEltqA3DRBAAAAHw"]
[Mon Jul 20 06:08:34.976829 2026] [security2:error] [pid 796567:tid 796722] [client 115.246.21.170:46841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjU8wAAAi0"]
[Mon Jul 20 06:08:34.976983 2026] [security2:error] [pid 796567:tid 796722] [client 115.246.21.170:46841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PwrLfyzVz2SrjZpjU8wAAAi0"]
[Mon Jul 20 06:08:34.991138 2026] [security2:error] [pid 796567:tid 796791] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU7wAAAnI"], referer: https://www.google.com/search?q=www.rtkenergypartners.faadenergy.com
[Mon Jul 20 06:08:35.054946 2026] [security2:error] [pid 796567:tid 796701] [client 57.141.18.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU7gAAAhg"]
[Mon Jul 20 06:08:35.082886 2026] [security2:error] [pid 832668:tid 832833] [client 103.178.3.191:41029] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pw2ci6KgEEltqA3DREwAAACE"]
[Mon Jul 20 06:08:35.122018 2026] [security2:error] [pid 796567:tid 796706] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.rtkenergypartners.faadenergy.com"] [uri "/index.php"] [unique_id "al4Pw7LfyzVz2SrjZpjU9gAAAh0"]
[Mon Jul 20 06:08:35.164449 2026] [security2:error] [pid 832668:tid 832861] [client 112.213.160.112:30730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRGQAAAD0"]
[Mon Jul 20 06:08:35.164602 2026] [security2:error] [pid 832668:tid 832861] [client 112.213.160.112:30730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRGQAAAD0"]
[Mon Jul 20 06:08:35.166009 2026] [security2:error] [pid 796567:tid 796789] [client 191.237.250.106:29792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/BDKR28.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVAQAAAnA"]
[Mon Jul 20 06:08:35.166170 2026] [security2:error] [pid 796567:tid 796789] [client 191.237.250.106:29792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/BDKR28.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVAQAAAnA"]
[Mon Jul 20 06:08:35.236488 2026] [security2:error] [pid 796567:tid 796797] [client 193.19.109.249:44413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVBQAAAng"]
[Mon Jul 20 06:08:35.239128 2026] [security2:error] [pid 832668:tid 832833] [client 103.178.3.191:41029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4Pw2ci6KgEEltqA3DREwAAACE"]
[Mon Jul 20 06:08:35.581416 2026] [security2:error] [pid 832668:tid 832923] [client 57.141.18.10:32936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pvmci6KgEEltqA3DQRAAAe3o"]
[Mon Jul 20 06:08:35.622802 2026] [security2:error] [pid 796567:tid 796795] [client 34.138.198.0:62520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVEAAAAnY"], referer: https://www.rtkenergypartners.com/.env.production.local
[Mon Jul 20 06:08:35.778504 2026] [security2:error] [pid 832668:tid 832815] [client 44.245.170.32:20954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Pw2ci6KgEEltqA3DRQAAAAA8"]
[Mon Jul 20 06:08:35.787212 2026] [security2:error] [pid 796567:tid 796757] [client 52.109.124.141:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Pw7LfyzVz2SrjZpjVFwAAAlA"]
[Mon Jul 20 06:08:35.910761 2026] [security2:error] [pid 832668:tid 832916] [client 45.116.69.230:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRSAAAAHQ"]
[Mon Jul 20 06:08:35.910861 2026] [security2:error] [pid 832668:tid 832916] [client 45.116.69.230:62187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw2ci6KgEEltqA3DRSAAAAHQ"]
[Mon Jul 20 06:08:35.935626 2026] [security2:error] [pid 796567:tid 796785] [client 185.132.186.85:25717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-dependency-float.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVHAAAAmw"]
[Mon Jul 20 06:08:35.974797 2026] [security2:error] [pid 796567:tid 796779] [client 52.109.124.141:33872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Pw7LfyzVz2SrjZpjVHgAAAmY"]
[Mon Jul 20 06:08:36.208887 2026] [security2:error] [pid 796567:tid 796776] [client 57.141.18.105:59812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pv7LfyzVz2SrjZpjUTAACY1U"]
[Mon Jul 20 06:08:36.227380 2026] [security2:error] [pid 796567:tid 796700] [client 34.138.198.0:56802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PxLLfyzVz2SrjZpjVJgAAAhc"], referer: https://www.rtkenergypartners.com/.env.development.local
[Mon Jul 20 06:08:36.250602 2026] [security2:error] [pid 796567:tid 796777] [client 34.138.198.0:56808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PxLLfyzVz2SrjZpjVJwAAAmQ"], referer: https://www.rtkenergypartners.com/secrets.yaml
[Mon Jul 20 06:08:36.520124 2026] [security2:error] [pid 832668:tid 832844] [client 74.7.227.179:48664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRXQAALH0"], referer: https://tejasenvironmental.com/p=617389
[Mon Jul 20 06:08:36.541982 2026] [security2:error] [pid 832668:tid 832833] [client 104.234.53.91:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4PxGci6KgEEltqA3DRbQAAACE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:36.564889 2026] [security2:error] [pid 796567:tid 796805] [client 104.28.219.194:51160] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/.env"] [unique_id "al4PxLLfyzVz2SrjZpjVOQAAAoA"]
[Mon Jul 20 06:08:36.678939 2026] [security2:error] [pid 832668:tid 832889] [client 104.28.219.194:51163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRcgAAAFk"]
[Mon Jul 20 06:08:36.679661 2026] [security2:error] [pid 832668:tid 832924] [client 104.28.219.194:51168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRcAAAAHw"]
[Mon Jul 20 06:08:36.683343 2026] [security2:error] [pid 832668:tid 832883] [client 104.28.219.194:51172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DRcwAAAFM"]
[Mon Jul 20 06:08:36.688551 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:44878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRdgAAAA0"]
[Mon Jul 20 06:08:36.688643 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:44878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRdgAAAA0"]
[Mon Jul 20 06:08:36.711962 2026] [security2:error] [pid 796567:tid 796740] [client 43.205.139.3:22992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVHwAAAj8"]
[Mon Jul 20 06:08:36.716637 2026] [security2:error] [pid 796567:tid 796701] [client 104.28.219.194:51160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4PxLLfyzVz2SrjZpjVPAAAAhg"]
[Mon Jul 20 06:08:36.808557 2026] [security2:error] [pid 832668:tid 832922] [client 34.138.198.0:56816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4PxGci6KgEEltqA3DReAAAAHo"], referer: https://www.rtkenergypartners.com/config.yml
[Mon Jul 20 06:08:36.818363 2026] [security2:error] [pid 832668:tid 832812] [client 41.173.37.102:8879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRfQAAAAw"]
[Mon Jul 20 06:08:36.818478 2026] [security2:error] [pid 832668:tid 832812] [client 41.173.37.102:8879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4PxGci6KgEEltqA3DRfQAAAAw"]
[Mon Jul 20 06:08:36.885893 2026] [security2:error] [pid 832668:tid 832684] [remote 68.178.160.25:39016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4PxGci6KgEEltqA3DRgQAAew0"]
[Mon Jul 20 06:08:37.099416 2026] [security2:error] [pid 796567:tid 796635] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVVgACdUM"]
[Mon Jul 20 06:08:37.099609 2026] [security2:error] [pid 796567:tid 796794] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVVgACdUM"]
[Mon Jul 20 06:08:37.196152 2026] [security2:error] [pid 796567:tid 796803] [client 52.109.44.112:35147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4PxbLfyzVz2SrjZpjVXAAAAn4"]
[Mon Jul 20 06:08:37.225144 2026] [security2:error] [pid 796567:tid 796806] [client 13.229.223.11:61478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4PxbLfyzVz2SrjZpjVYAAAAoE"]
[Mon Jul 20 06:08:37.308847 2026] [security2:error] [pid 832668:tid 832926] [client 191.237.250.106:11259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/001.php"] [unique_id "al4PxWci6KgEEltqA3DRiAAAAH4"]
[Mon Jul 20 06:08:37.309001 2026] [security2:error] [pid 832668:tid 832926] [client 191.237.250.106:11259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/001.php"] [unique_id "al4PxWci6KgEEltqA3DRiAAAAH4"]
[Mon Jul 20 06:08:37.335600 2026] [security2:error] [pid 796567:tid 796746] [client 52.109.44.112:35147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4PxbLfyzVz2SrjZpjVawAAAkU"]
[Mon Jul 20 06:08:37.375658 2026] [ssl:error] [pid 796567:tid 796753] [client 104.48.69.105:58180] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:08:37.411396 2026] [security2:error] [pid 832668:tid 832792] [remote 68.178.160.25:39016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4PxWci6KgEEltqA3DRjgAAcXk"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 06:08:37.428906 2026] [security2:error] [pid 796567:tid 796763] [client 114.119.134.3:53667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "recruitinginsight.us"] [uri "/page/28/"] [unique_id "al4PxbLfyzVz2SrjZpjVcQAAAlY"], referer: https://recruitinginsight.us/page/28/?et_blog
[Mon Jul 20 06:08:37.491830 2026] [ssl:error] [pid 796567:tid 796792] [client 104.48.69.105:58186] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:08:37.555404 2026] [security2:error] [pid 832668:tid 832846] [client 57.141.18.105:59822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PwGci6KgEEltqA3DQhQAALmg"]
[Mon Jul 20 06:08:37.671532 2026] [security2:error] [pid 832668:tid 832839] [client 13.201.64.214:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PxWci6KgEEltqA3DRlwAAACc"]
[Mon Jul 20 06:08:37.671723 2026] [security2:error] [pid 832668:tid 832839] [client 13.201.64.214:36090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PxWci6KgEEltqA3DRlwAAACc"]
[Mon Jul 20 06:08:37.743003 2026] [security2:error] [pid 796567:tid 796767] [client 178.152.178.232:37354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVfAAAAlo"]
[Mon Jul 20 06:08:37.743131 2026] [security2:error] [pid 796567:tid 796767] [client 178.152.178.232:37354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVfAAAAlo"]
[Mon Jul 20 06:08:37.832118 2026] [security2:error] [pid 796567:tid 796677] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVgAACKW0"]
[Mon Jul 20 06:08:37.832250 2026] [security2:error] [pid 796567:tid 796718] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PxbLfyzVz2SrjZpjVgAACKW0"]
[Mon Jul 20 06:08:38.009868 2026] [security2:error] [pid 796567:tid 796761] [client 57.141.18.93:60042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PwbLfyzVz2SrjZpjUnAACVAc"]
[Mon Jul 20 06:08:38.488643 2026] [security2:error] [pid 832668:tid 832845] [client 13.229.223.11:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Pxmci6KgEEltqA3DRuQAAAC0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:08:39.183727 2026] [security2:error] [pid 796567:tid 796820] [client 57.141.18.53:39178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PwrLfyzVz2SrjZpjU1wACjzA"]
[Mon Jul 20 06:08:39.260898 2026] [security2:error] [pid 832668:tid 832887] [client 193.19.109.242:31961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4Px2ci6KgEEltqA3DRzQAAAFc"]
[Mon Jul 20 06:08:39.291067 2026] [security2:error] [pid 832668:tid 832894] [client 164.100.212.184:63041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Px2ci6KgEEltqA3DR0AAAAF4"]
[Mon Jul 20 06:08:39.291164 2026] [security2:error] [pid 832668:tid 832894] [client 164.100.212.184:63041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4Px2ci6KgEEltqA3DR0AAAAF4"]
[Mon Jul 20 06:08:40.062206 2026] [security2:error] [pid 832668:tid 832892] [client 191.237.250.106:59139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/dZ3wP5.php"] [unique_id "al4PyGci6KgEEltqA3DR9gAAAFw"]
[Mon Jul 20 06:08:40.062308 2026] [security2:error] [pid 832668:tid 832892] [client 191.237.250.106:59139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/dZ3wP5.php"] [unique_id "al4PyGci6KgEEltqA3DR9gAAAFw"]
[Mon Jul 20 06:08:40.680790 2026] [security2:error] [pid 832668:tid 832889] [client 103.95.123.246:17460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PyGci6KgEEltqA3DSDQAAAFk"]
[Mon Jul 20 06:08:40.683422 2026] [security2:error] [pid 832668:tid 832889] [client 103.95.123.246:17460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4PyGci6KgEEltqA3DSDQAAAFk"]
[Mon Jul 20 06:08:40.688037 2026] [security2:error] [pid 832668:tid 832685] [remote 152.228.213.32:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4PyGci6KgEEltqA3DSDAAAFQ4"]
[Mon Jul 20 06:08:40.927918 2026] [security2:error] [pid 796567:tid 796778] [client 57.141.18.89:49720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pw7LfyzVz2SrjZpjVHQACZS8"]
[Mon Jul 20 06:08:41.086815 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yup.php"] [unique_id "al4PyWci6KgEEltqA3DSGAAAAHk"]
[Mon Jul 20 06:08:41.086947 2026] [security2:error] [pid 832668:tid 832921] [client 191.237.250.106:59140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yup.php"] [unique_id "al4PyWci6KgEEltqA3DSGAAAAHk"]
[Mon Jul 20 06:08:41.120135 2026] [proxy:error] [pid 796567:tid 796783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:41.120205 2026] [proxy_http:error] [pid 796567:tid 796783] [client 185.247.137.40:37661] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:41.120702 2026] [proxy:error] [pid 796567:tid 796783] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:41.120736 2026] [proxy_http:error] [pid 796567:tid 796783] [client 185.247.137.40:37661] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:41.208452 2026] [security2:error] [pid 796567:tid 796702] [client 216.144.249.201:37698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/"] [unique_id "al4PybLfyzVz2SrjZpjV_gAAAhk"]
[Mon Jul 20 06:08:41.208564 2026] [security2:error] [pid 796567:tid 796702] [client 216.144.249.201:37698] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/"] [unique_id "al4PybLfyzVz2SrjZpjV_gAAAhk"]
[Mon Jul 20 06:08:41.257626 2026] [security2:error] [pid 832668:tid 832701] [remote 120.46.94.180:44522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.94.46.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4PyWci6KgEEltqA3DSHwAAQx4"]
[Mon Jul 20 06:08:41.308966 2026] [security2:error] [pid 796567:tid 796766] [client 15.237.142.234:54884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWAgAAAlk"]
[Mon Jul 20 06:08:41.309089 2026] [security2:error] [pid 796567:tid 796766] [client 15.237.142.234:54884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWAgAAAlk"]
[Mon Jul 20 06:08:41.480835 2026] [security2:error] [pid 796567:tid 796693] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWDwACJn0"]
[Mon Jul 20 06:08:41.480968 2026] [security2:error] [pid 796567:tid 796715] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4PybLfyzVz2SrjZpjWDwACJn0"]
[Mon Jul 20 06:08:41.483471 2026] [security2:error] [pid 796567:tid 796699] [client 216.144.249.201:37700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env"] [unique_id "al4PybLfyzVz2SrjZpjWEAAAAhY"]
[Mon Jul 20 06:08:41.667390 2026] [security2:error] [pid 832668:tid 832682] [remote 152.228.213.32:37972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4PyWci6KgEEltqA3DSOgAAdAs"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:08:41.725082 2026] [security2:error] [pid 832668:tid 832909] [client 191.237.250.106:19436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/X.php"] [unique_id "al4PyWci6KgEEltqA3DSOwAAAG0"]
[Mon Jul 20 06:08:41.725191 2026] [security2:error] [pid 832668:tid 832909] [client 191.237.250.106:19436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/X.php"] [unique_id "al4PyWci6KgEEltqA3DSOwAAAG0"]
[Mon Jul 20 06:08:41.821405 2026] [security2:error] [pid 832668:tid 832702] [remote 95.217.78.234:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4PyWci6KgEEltqA3DSPAAAER8"]
[Mon Jul 20 06:08:42.048301 2026] [security2:error] [pid 832668:tid 832731] [remote 95.217.78.234:37228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Pymci6KgEEltqA3DSRgAASjw"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:08:42.183878 2026] [security2:error] [pid 832668:tid 832801] [client 191.237.250.106:29770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/1polka.php"] [unique_id "al4Pymci6KgEEltqA3DSTQAAAAE"]
[Mon Jul 20 06:08:42.183998 2026] [security2:error] [pid 832668:tid 832801] [client 191.237.250.106:29770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/1polka.php"] [unique_id "al4Pymci6KgEEltqA3DSTQAAAAE"]
[Mon Jul 20 06:08:42.251090 2026] [security2:error] [pid 832668:tid 832829] [client 216.144.249.201:37770] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/app/.env"] [unique_id "al4Pymci6KgEEltqA3DSUwAAAB0"]
[Mon Jul 20 06:08:42.252352 2026] [security2:error] [pid 832668:tid 832878] [client 216.144.249.201:37728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env.bak"] [unique_id "al4Pymci6KgEEltqA3DSVQAAAE4"]
[Mon Jul 20 06:08:42.253940 2026] [security2:error] [pid 796567:tid 796785] [client 216.144.249.201:37736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env.backup"] [unique_id "al4PyrLfyzVz2SrjZpjWMAAAAmw"]
[Mon Jul 20 06:08:42.254179 2026] [security2:error] [pid 796567:tid 796752] [client 216.144.249.201:37820] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/wp/.env"] [unique_id "al4PyrLfyzVz2SrjZpjWMQAAAks"]
[Mon Jul 20 06:08:42.269444 2026] [security2:error] [pid 832668:tid 832854] [client 216.144.249.201:37990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4Pymci6KgEEltqA3DSXQAAADY"]
[Mon Jul 20 06:08:42.269575 2026] [security2:error] [pid 832668:tid 832854] [client 216.144.249.201:37990] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4Pymci6KgEEltqA3DSXQAAADY"]
[Mon Jul 20 06:08:42.326206 2026] [security2:error] [pid 832668:tid 832818] [client 216.144.249.201:37962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/key.json"] [unique_id "al4Pymci6KgEEltqA3DSYgAAABI"]
[Mon Jul 20 06:08:42.326445 2026] [security2:error] [pid 796567:tid 796776] [client 216.144.249.201:37792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/api/.env"] [unique_id "al4PyrLfyzVz2SrjZpjWNgAAAmM"]
[Mon Jul 20 06:08:42.326586 2026] [security2:error] [pid 832668:tid 832818] [client 216.144.249.201:37962] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/key.json"] [unique_id "al4Pymci6KgEEltqA3DSYgAAABI"]
[Mon Jul 20 06:08:42.329170 2026] [security2:error] [pid 832668:tid 832834] [client 216.144.249.201:37808] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/public/.env"] [unique_id "al4Pymci6KgEEltqA3DSYwAAACI"]
[Mon Jul 20 06:08:42.329876 2026] [security2:error] [pid 832668:tid 832912] [client 216.144.249.201:37892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/api/config"] [unique_id "al4Pymci6KgEEltqA3DSZQAAAHA"]
[Mon Jul 20 06:08:42.329977 2026] [security2:error] [pid 832668:tid 832912] [client 216.144.249.201:37892] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/api/config"] [unique_id "al4Pymci6KgEEltqA3DSZQAAAHA"]
[Mon Jul 20 06:08:42.331230 2026] [security2:error] [pid 832668:tid 832806] [client 216.144.249.201:38068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "scarlettshirt.com"] [uri "/wp-config.php.bak"] [unique_id "al4Pymci6KgEEltqA3DSZwAAAAY"]
[Mon Jul 20 06:08:42.333026 2026] [security2:error] [pid 832668:tid 832861] [client 216.144.249.201:37984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/token.json"] [unique_id "al4Pymci6KgEEltqA3DSaQAAAD0"]
[Mon Jul 20 06:08:42.333116 2026] [security2:error] [pid 832668:tid 832861] [client 216.144.249.201:37984] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/token.json"] [unique_id "al4Pymci6KgEEltqA3DSaQAAAD0"]
[Mon Jul 20 06:08:42.356080 2026] [security2:error] [pid 832668:tid 832841] [client 216.144.249.201:37812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/laravel/.env"] [unique_id "al4Pymci6KgEEltqA3DSbwAAACk"]
[Mon Jul 20 06:08:42.356082 2026] [security2:error] [pid 832668:tid 832839] [client 216.144.249.201:37786] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/backend/.env"] [unique_id "al4Pymci6KgEEltqA3DSbgAAACc"]
[Mon Jul 20 06:08:42.384192 2026] [security2:error] [pid 832668:tid 832690] [remote 120.46.94.180:44522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.94.46.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Pymci6KgEEltqA3DSdAAAFBM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:08:42.401663 2026] [security2:error] [pid 796567:tid 796645] [remote 57.141.18.31:23666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PxbLfyzVz2SrjZpjVZAACVU0"]
[Mon Jul 20 06:08:42.407864 2026] [security2:error] [pid 796567:tid 796700] [client 216.144.249.201:38066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.249.144.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "scarlettshirt.com"] [uri "/wp-config.php"] [unique_id "al4PyrLfyzVz2SrjZpjWQwAAAhc"]
[Mon Jul 20 06:08:42.471482 2026] [security2:error] [pid 796567:tid 796741] [client 14.225.17.146:65244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4PyLLfyzVz2SrjZpjV4gAAAkA"], referer: http://itdynamix.com/Wordpress
[Mon Jul 20 06:08:42.485859 2026] [security2:error] [pid 796567:tid 796724] [client 216.144.249.201:37942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/credentials.json"] [unique_id "al4PyrLfyzVz2SrjZpjWRgAAAi8"]
[Mon Jul 20 06:08:42.485951 2026] [security2:error] [pid 796567:tid 796724] [client 216.144.249.201:37942] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/credentials.json"] [unique_id "al4PyrLfyzVz2SrjZpjWRgAAAi8"]
[Mon Jul 20 06:08:42.487170 2026] [security2:error] [pid 796567:tid 796709] [client 216.144.249.201:38076] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/web.config"] [unique_id "al4PyrLfyzVz2SrjZpjWRAAAAiA"]
[Mon Jul 20 06:08:42.491865 2026] [security2:error] [pid 796567:tid 796760] [client 216.144.249.201:37752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "scarlettshirt.com"] [uri "/.env.old"] [unique_id "al4PyrLfyzVz2SrjZpjWSQAAAlM"]
[Mon Jul 20 06:08:42.508650 2026] [security2:error] [pid 832668:tid 832873] [client 216.144.249.201:38080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scarlettshirt.com"] [uri "/.env.development"] [unique_id "al4Pymci6KgEEltqA3DSigAAAEk"]
[Mon Jul 20 06:08:42.508741 2026] [security2:error] [pid 832668:tid 832873] [client 216.144.249.201:38080] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "scarlettshirt.com"] [uri "/.env.development"] [unique_id "al4Pymci6KgEEltqA3DSigAAAEk"]
[Mon Jul 20 06:08:42.990246 2026] [security2:error] [pid 832668:tid 832822] [client 191.237.250.106:29804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/gec.php"] [unique_id "al4Pymci6KgEEltqA3DStgAAABY"]
[Mon Jul 20 06:08:42.990359 2026] [security2:error] [pid 832668:tid 832822] [client 191.237.250.106:29804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/gec.php"] [unique_id "al4Pymci6KgEEltqA3DStgAAABY"]
[Mon Jul 20 06:08:43.080090 2026] [security2:error] [pid 832668:tid 832726] [remote 156.59.198.136:19074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bigwormfishing.com"] [uri "/wp-content/uploads/css/CheapFishingTackletheSmartWay.pdf"] [unique_id "al4Py2ci6KgEEltqA3DSwgAAMjc"]
[Mon Jul 20 06:08:43.486087 2026] [security2:error] [pid 832668:tid 832917] [client 14.225.17.146:50677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DS0gAAAHU"], referer: https://itdynamix.com/Wordpress
[Mon Jul 20 06:08:43.772042 2026] [security2:error] [pid 832668:tid 832903] [client 57.141.18.4:45238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pxmci6KgEEltqA3DRtwAAZ3I"]
[Mon Jul 20 06:08:44.137393 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:29769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sky.php"] [unique_id "al4PzGci6KgEEltqA3DTHgAAADI"]
[Mon Jul 20 06:08:44.137551 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:29769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sky.php"] [unique_id "al4PzGci6KgEEltqA3DTHgAAADI"]
[Mon Jul 20 06:08:44.310027 2026] [security2:error] [pid 832668:tid 832829] [client 103.141.108.143:50340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTMAAAAB0"]
[Mon Jul 20 06:08:44.310230 2026] [security2:error] [pid 832668:tid 832829] [client 103.141.108.143:50340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTMAAAAB0"]
[Mon Jul 20 06:08:44.585774 2026] [security2:error] [pid 832668:tid 832911] [client 103.77.203.233:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTSQAAAG8"]
[Mon Jul 20 06:08:44.585988 2026] [security2:error] [pid 832668:tid 832911] [client 103.77.203.233:57974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTSQAAAG8"]
[Mon Jul 20 06:08:44.660055 2026] [security2:error] [pid 832668:tid 832802] [client 14.225.17.146:65334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DS0QAAAAI"], referer: http://effingweirdmuseums.com/Wordpress
[Mon Jul 20 06:08:44.719627 2026] [security2:error] [pid 832668:tid 832873] [client 193.19.109.251:40583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTVgAAAEk"]
[Mon Jul 20 06:08:44.756782 2026] [security2:error] [pid 832668:tid 832825] [client 193.19.109.226:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTWAAAABk"]
[Mon Jul 20 06:08:44.765580 2026] [security2:error] [pid 832668:tid 832801] [client 193.19.109.228:20857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTVQAAAAE"]
[Mon Jul 20 06:08:44.835037 2026] [security2:error] [pid 832668:tid 832885] [client 193.19.109.243:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4PzGci6KgEEltqA3DTXgAAAFU"]
[Mon Jul 20 06:08:44.899368 2026] [security2:error] [pid 832668:tid 832860] [client 57.141.18.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "uninursity.com"] [uri "/index.php"] [unique_id "al4PyWci6KgEEltqA3DSKQAAADw"]
[Mon Jul 20 06:08:44.933168 2026] [security2:error] [pid 832668:tid 832775] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTaQAAemg"]
[Mon Jul 20 06:08:44.933303 2026] [security2:error] [pid 832668:tid 832922] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4PzGci6KgEEltqA3DTaQAAemg"]
[Mon Jul 20 06:08:45.005721 2026] [security2:error] [pid 832668:tid 832849] [client 185.132.186.68:59847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/PHPMailer/index.php"] [unique_id "al4PzWci6KgEEltqA3DTdAAAADE"]
[Mon Jul 20 06:08:45.119417 2026] [security2:error] [pid 832668:tid 832904] [client 14.225.17.146:65364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DS8QAAAGg"], referer: http://cephasnext.com/Wordpress
[Mon Jul 20 06:08:45.235481 2026] [security2:error] [pid 832668:tid 832918] [client 14.225.17.146:52951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4PzGci6KgEEltqA3DTLwAAAHY"], referer: http://techtradeinc.com/Wordpress
[Mon Jul 20 06:08:45.301378 2026] [security2:error] [pid 832668:tid 832838] [client 14.225.17.146:64995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DTCAAAACY"], referer: http://chestermonty.com/Wordpress
[Mon Jul 20 06:08:45.306379 2026] [security2:error] [pid 832668:tid 832821] [client 191.237.250.106:37599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fffm.php"] [unique_id "al4PzWci6KgEEltqA3DTkQAAABU"]
[Mon Jul 20 06:08:45.306542 2026] [security2:error] [pid 832668:tid 832821] [client 191.237.250.106:37599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fffm.php"] [unique_id "al4PzWci6KgEEltqA3DTkQAAABU"]
[Mon Jul 20 06:08:45.567494 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:64992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4Py2ci6KgEEltqA3DTCwAAAFQ"], referer: http://dereckcastellon.com/Wordpress
[Mon Jul 20 06:08:45.647256 2026] [security2:error] [pid 832668:tid 832815] [client 14.225.17.146:50691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTrQAAAA8"], referer: https://effingweirdmuseums.com/Wordpress
[Mon Jul 20 06:08:45.695137 2026] [security2:error] [pid 832668:tid 832888] [client 115.246.21.170:14443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DTugAAAFg"]
[Mon Jul 20 06:08:45.695248 2026] [security2:error] [pid 832668:tid 832888] [client 115.246.21.170:14443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DTugAAAFg"]
[Mon Jul 20 06:08:45.760247 2026] [security2:error] [pid 832668:tid 832885] [client 14.191.253.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTjAAAAFU"]
[Mon Jul 20 06:08:45.766516 2026] [security2:error] [pid 832668:tid 832787] [remote 152.228.213.32:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4PzWci6KgEEltqA3DTwQAADnQ"]
[Mon Jul 20 06:08:45.901196 2026] [security2:error] [pid 832668:tid 832908] [client 112.213.160.112:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DT0QAAAGw"]
[Mon Jul 20 06:08:45.901307 2026] [security2:error] [pid 832668:tid 832908] [client 112.213.160.112:8220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4PzWci6KgEEltqA3DT0QAAAGw"]
[Mon Jul 20 06:08:46.020100 2026] [security2:error] [pid 832668:tid 832850] [client 52.109.56.130:2371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Pzmci6KgEEltqA3DT3AAAADI"]
[Mon Jul 20 06:08:46.093822 2026] [security2:error] [pid 832668:tid 832874] [client 94.154.43.187:31266] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.rrf.lcd.mybluehost.me"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4Pzmci6KgEEltqA3DT5AAAAEo"]
[Mon Jul 20 06:08:46.105315 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:23512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sixxis.php"] [unique_id "al4Pzmci6KgEEltqA3DT5gAAAF8"]
[Mon Jul 20 06:08:46.105421 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:23512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/sixxis.php"] [unique_id "al4Pzmci6KgEEltqA3DT5gAAAF8"]
[Mon Jul 20 06:08:46.168874 2026] [security2:error] [pid 832668:tid 832824] [client 106.192.104.4:54192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DT8AAAABg"]
[Mon Jul 20 06:08:46.169003 2026] [security2:error] [pid 832668:tid 832824] [client 106.192.104.4:54192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DT8AAAABg"]
[Mon Jul 20 06:08:46.197687 2026] [security2:error] [pid 832668:tid 832854] [client 179.127.139.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4PzGci6KgEEltqA3DTUgAAADY"]
[Mon Jul 20 06:08:46.251531 2026] [security2:error] [pid 832668:tid 832819] [client 52.109.56.130:2371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Pzmci6KgEEltqA3DT9wAAABM"]
[Mon Jul 20 06:08:46.337783 2026] [security2:error] [pid 832668:tid 832918] [client 14.225.17.146:56058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4Pzmci6KgEEltqA3DT9AAAAHY"], referer: https://chestermonty.com/Wordpress
[Mon Jul 20 06:08:46.522043 2026] [security2:error] [pid 832668:tid 832853] [client 14.225.17.146:50695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4PzGci6KgEEltqA3DTSgAAADU"], referer: http://nomorewetsheets.net/Wordpress
[Mon Jul 20 06:08:46.624648 2026] [security2:error] [pid 832668:tid 832836] [client 191.237.250.106:37629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yj09.php"] [unique_id "al4Pzmci6KgEEltqA3DUEAAAACQ"]
[Mon Jul 20 06:08:46.624764 2026] [security2:error] [pid 832668:tid 832836] [client 191.237.250.106:37629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/yj09.php"] [unique_id "al4Pzmci6KgEEltqA3DUEAAAACQ"]
[Mon Jul 20 06:08:46.649823 2026] [security2:error] [pid 832668:tid 832876] [client 45.116.69.230:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DUFQAAAEw"]
[Mon Jul 20 06:08:46.649955 2026] [security2:error] [pid 832668:tid 832876] [client 45.116.69.230:62668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Pzmci6KgEEltqA3DUFQAAAEw"]
[Mon Jul 20 06:08:46.840433 2026] [security2:error] [pid 832668:tid 832919] [client 57.141.18.61:42744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pymci6KgEEltqA3DSSgAAd2w"]
[Mon Jul 20 06:08:47.011120 2026] [security2:error] [pid 832668:tid 832859] [client 185.132.186.94:21611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/PHPMailer/purna.php"] [unique_id "al4Pz2ci6KgEEltqA3DULAAAADs"]
[Mon Jul 20 06:08:47.069912 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:28764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/f900.php"] [unique_id "al4Pz2ci6KgEEltqA3DUMQAAACg"]
[Mon Jul 20 06:08:47.070050 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:28764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/f900.php"] [unique_id "al4Pz2ci6KgEEltqA3DUMQAAACg"]
[Mon Jul 20 06:08:47.078942 2026] [security2:error] [pid 832668:tid 832812] [client 52.109.4.7:33538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Pz2ci6KgEEltqA3DUMgAAAAw"]
[Mon Jul 20 06:08:47.083551 2026] [security2:error] [pid 832668:tid 832892] [client 173.239.254.42:26491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.254.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "colt-innovate.com"] [uri "/wp-login.php"] [unique_id "al4Pz2ci6KgEEltqA3DUNgAAAFw"]
[Mon Jul 20 06:08:47.140918 2026] [security2:error] [pid 832668:tid 832819] [client 52.109.4.7:33538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Pz2ci6KgEEltqA3DUPAAAABM"]
[Mon Jul 20 06:08:47.221003 2026] [security2:error] [pid 832668:tid 832874] [client 181.224.94.124:50874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUSAAAAEo"]
[Mon Jul 20 06:08:47.221172 2026] [security2:error] [pid 832668:tid 832874] [client 181.224.94.124:50874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUSAAAAEo"]
[Mon Jul 20 06:08:47.547357 2026] [security2:error] [pid 832668:tid 832877] [client 41.173.37.102:9329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUawAAAE0"]
[Mon Jul 20 06:08:47.547477 2026] [security2:error] [pid 832668:tid 832877] [client 41.173.37.102:9329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUawAAAE0"]
[Mon Jul 20 06:08:47.755058 2026] [security2:error] [pid 832668:tid 832722] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUewAAMzM"]
[Mon Jul 20 06:08:47.755258 2026] [security2:error] [pid 832668:tid 832851] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUewAAMzM"]
[Mon Jul 20 06:08:47.913998 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ups.php"] [unique_id "al4Pz2ci6KgEEltqA3DUkgAAAC4"]
[Mon Jul 20 06:08:47.914088 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:50656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ups.php"] [unique_id "al4Pz2ci6KgEEltqA3DUkgAAAC4"]
[Mon Jul 20 06:08:47.923497 2026] [security2:error] [pid 832668:tid 832818] [client 57.141.18.80:61010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Py2ci6KgEEltqA3DSywAAEiM"]
[Mon Jul 20 06:08:47.925308 2026] [security2:error] [pid 832668:tid 832907] [client 50.116.65.227:11510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4Pz2ci6KgEEltqA3DUlQAAAGs"]
[Mon Jul 20 06:08:47.928913 2026] [security2:error] [pid 832668:tid 832833] [client 14.225.17.146:56083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4Pzmci6KgEEltqA3DT-wAAACE"], referer: http://recruitinginsight.us/Wordpress
[Mon Jul 20 06:08:47.931800 2026] [security2:error] [pid 832668:tid 832894] [client 14.225.17.146:65280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Pzmci6KgEEltqA3DUJAAAAF4"], referer: http://ncsynchro.com/Wordpress
[Mon Jul 20 06:08:47.965393 2026] [security2:error] [pid 832668:tid 832821] [client 178.152.178.232:36093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUmAAAABU"]
[Mon Jul 20 06:08:47.969135 2026] [security2:error] [pid 832668:tid 832821] [client 178.152.178.232:36093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Pz2ci6KgEEltqA3DUmAAAABU"]
[Mon Jul 20 06:08:48.070317 2026] [security2:error] [pid 832668:tid 832868] [client 42.60.14.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4Pz2ci6KgEEltqA3DUjwAAAEQ"]
[Mon Jul 20 06:08:48.074856 2026] [security2:error] [pid 832668:tid 832835] [client 191.37.45.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DT1QAAACM"]
[Mon Jul 20 06:08:48.357040 2026] [security2:error] [pid 832668:tid 832767] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DUrgAAeGA"]
[Mon Jul 20 06:08:48.357192 2026] [security2:error] [pid 832668:tid 832920] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DUrgAAeGA"]
[Mon Jul 20 06:08:48.404323 2026] [security2:error] [pid 832668:tid 832884] [client 191.237.250.106:57045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k.php"] [unique_id "al4P0Gci6KgEEltqA3DUswAAAFQ"]
[Mon Jul 20 06:08:48.404515 2026] [security2:error] [pid 832668:tid 832884] [client 191.237.250.106:57045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k.php"] [unique_id "al4P0Gci6KgEEltqA3DUswAAAFQ"]
[Mon Jul 20 06:08:48.445634 2026] [security2:error] [pid 832668:tid 832903] [client 45.157.112.60:39947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P0Gci6KgEEltqA3DUtgAAAGc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:48.551651 2026] [security2:error] [pid 832668:tid 832862] [client 14.225.17.146:55203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4Pz2ci6KgEEltqA3DUUAAAAD4"], referer: http://lutheranphilosopher.com/Wordpress
[Mon Jul 20 06:08:48.873148 2026] [security2:error] [pid 832668:tid 832859] [client 191.237.250.106:50439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k2.php"] [unique_id "al4P0Gci6KgEEltqA3DU2QAAADs"]
[Mon Jul 20 06:08:48.873249 2026] [security2:error] [pid 832668:tid 832859] [client 191.237.250.106:50439] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/k2.php"] [unique_id "al4P0Gci6KgEEltqA3DU2QAAADs"]
[Mon Jul 20 06:08:48.976277 2026] [security2:error] [pid 832668:tid 832813] [client 66.249.73.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4P0Gci6KgEEltqA3DU2gAAAA0"]
[Mon Jul 20 06:08:48.995676 2026] [security2:error] [pid 832668:tid 832734] [remote 5.161.225.162:38062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DU5gAATD8"]
[Mon Jul 20 06:08:48.995856 2026] [security2:error] [pid 832668:tid 832876] [client 5.161.225.162:38062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4P0Gci6KgEEltqA3DU5gAATD8"]
[Mon Jul 20 06:08:49.016901 2026] [security2:error] [pid 832668:tid 832872] [client 185.132.186.86:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/interactivity-api/interactivity-api-class.php"] [unique_id "al4P0Wci6KgEEltqA3DU6AAAAEg"]
[Mon Jul 20 06:08:49.033408 2026] [security2:error] [pid 832668:tid 832915] [client 57.141.18.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4P0Gci6KgEEltqA3DU1wAAAHM"]
[Mon Jul 20 06:08:49.212336 2026] [security2:error] [pid 832668:tid 832886] [client 114.119.145.225:55401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4P0Wci6KgEEltqA3DU-gAAAFY"], referer: https://www.new-menus.com/index.php?action=stats%3Bcollapse%3D201209
[Mon Jul 20 06:08:49.267036 2026] [security2:error] [pid 832668:tid 832922] [client 191.237.250.106:27205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w.php"] [unique_id "al4P0Wci6KgEEltqA3DU_QAAAHo"]
[Mon Jul 20 06:08:49.267131 2026] [security2:error] [pid 832668:tid 832922] [client 191.237.250.106:27205] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w.php"] [unique_id "al4P0Wci6KgEEltqA3DU_QAAAHo"]
[Mon Jul 20 06:08:49.411811 2026] [security2:error] [pid 832668:tid 832677] [remote 152.228.213.32:37984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4P0Wci6KgEEltqA3DVFwAAJAY"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 06:08:49.534740 2026] [security2:error] [pid 832668:tid 832848] [client 103.153.183.69:22040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../root/.ssh/id_rsa"] [unique_id "al4P0Wci6KgEEltqA3DVIwAAADA"], referer: https://www.bing.com/search?q=abk46k
[Mon Jul 20 06:08:49.685706 2026] [security2:error] [pid 832668:tid 832866] [client 104.194.200.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4P0Wci6KgEEltqA3DU_gAAAEI"]
[Mon Jul 20 06:08:49.809476 2026] [security2:error] [pid 832668:tid 832832] [client 191.237.250.106:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fpwch.php"] [unique_id "al4P0Wci6KgEEltqA3DVNwAAACA"]
[Mon Jul 20 06:08:49.809625 2026] [security2:error] [pid 832668:tid 832832] [client 191.237.250.106:57025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/fpwch.php"] [unique_id "al4P0Wci6KgEEltqA3DVNwAAACA"]
[Mon Jul 20 06:08:49.910631 2026] [security2:error] [pid 832668:tid 832908] [client 164.100.212.184:50462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P0Wci6KgEEltqA3DVPgAAAGw"]
[Mon Jul 20 06:08:49.910722 2026] [security2:error] [pid 832668:tid 832908] [client 164.100.212.184:50462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P0Wci6KgEEltqA3DVPgAAAGw"]
[Mon Jul 20 06:08:50.135880 2026] [security2:error] [pid 832668:tid 832896] [client 27.96.94.195:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P0mci6KgEEltqA3DVUwAAAGA"]
[Mon Jul 20 06:08:50.135999 2026] [security2:error] [pid 832668:tid 832896] [client 27.96.94.195:37885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P0mci6KgEEltqA3DVUwAAAGA"]
[Mon Jul 20 06:08:50.159207 2026] [security2:error] [pid 832668:tid 832871] [client 57.141.18.111:52652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTsQAARzU"]
[Mon Jul 20 06:08:50.198218 2026] [security2:error] [pid 832668:tid 832849] [client 3.109.4.218:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4P0mci6KgEEltqA3DVWQAAADE"]
[Mon Jul 20 06:08:50.354177 2026] [security2:error] [pid 832668:tid 832913] [client 57.141.18.19:25698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4PzWci6KgEEltqA3DTvAAAcR4"]
[Mon Jul 20 06:08:50.368340 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:32065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w2025.php"] [unique_id "al4P0mci6KgEEltqA3DVYgAAACg"]
[Mon Jul 20 06:08:50.368444 2026] [security2:error] [pid 832668:tid 832840] [client 191.237.250.106:32065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w2025.php"] [unique_id "al4P0mci6KgEEltqA3DVYgAAACg"]
[Mon Jul 20 06:08:51.018857 2026] [security2:error] [pid 832668:tid 832859] [client 185.132.186.64:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/class-wp-widddget-pages.php"] [unique_id "al4P02ci6KgEEltqA3DVkQAAADs"]
[Mon Jul 20 06:08:51.218703 2026] [security2:error] [pid 832668:tid 832871] [client 43.205.139.3:48980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4P02ci6KgEEltqA3DVmgAAAEc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:08:51.477025 2026] [security2:error] [pid 832668:tid 832918] [client 191.237.250.106:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/FWAZ.php"] [unique_id "al4P02ci6KgEEltqA3DVvAAAAHY"]
[Mon Jul 20 06:08:51.477109 2026] [security2:error] [pid 832668:tid 832918] [client 191.237.250.106:50645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/FWAZ.php"] [unique_id "al4P02ci6KgEEltqA3DVvAAAAHY"]
[Mon Jul 20 06:08:51.639434 2026] [security2:error] [pid 832668:tid 832827] [client 103.95.123.246:18239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DVxwAAABs"]
[Mon Jul 20 06:08:51.639555 2026] [security2:error] [pid 832668:tid 832827] [client 103.95.123.246:18239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DVxwAAABs"]
[Mon Jul 20 06:08:51.945205 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:21410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/qterm.php"] [unique_id "al4P02ci6KgEEltqA3DV2gAAAF8"]
[Mon Jul 20 06:08:51.945312 2026] [security2:error] [pid 832668:tid 832895] [client 191.237.250.106:21410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/qterm.php"] [unique_id "al4P02ci6KgEEltqA3DV2gAAAF8"]
[Mon Jul 20 06:08:52.004446 2026] [security2:error] [pid 832668:tid 832756] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DV3QAANlU"]
[Mon Jul 20 06:08:52.004682 2026] [security2:error] [pid 832668:tid 832854] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P02ci6KgEEltqA3DV3QAANlU"]
[Mon Jul 20 06:08:52.125891 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.65:42488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Pz2ci6KgEEltqA3DUaAAATjs"]
[Mon Jul 20 06:08:52.537431 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:11248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/blurbs.php"] [unique_id "al4P1Gci6KgEEltqA3DWCQAAAEI"]
[Mon Jul 20 06:08:52.537523 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:11248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/blurbs.php"] [unique_id "al4P1Gci6KgEEltqA3DWCQAAAEI"]
[Mon Jul 20 06:08:52.612204 2026] [security2:error] [pid 832668:tid 832819] [client 57.141.18.111:52658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P0Gci6KgEEltqA3DUmgAAE24"]
[Mon Jul 20 06:08:52.753905 2026] [security2:error] [pid 832668:tid 832900] [client 104.234.53.74:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4P1Gci6KgEEltqA3DWFwAAAGQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:52.890491 2026] [security2:error] [pid 832668:tid 832735] [remote 57.141.18.16:33482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4339893"] [unique_id "al4P1Gci6KgEEltqA3DWKAAAMEA"]
[Mon Jul 20 06:08:52.982380 2026] [security2:error] [pid 832668:tid 832831] [client 57.141.18.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4P1Gci6KgEEltqA3DWJwAAAB8"]
[Mon Jul 20 06:08:53.001567 2026] [security2:error] [pid 832668:tid 832854] [client 185.132.186.56:29189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al4P1Wci6KgEEltqA3DWMQAAADY"]
[Mon Jul 20 06:08:53.122755 2026] [security2:error] [pid 832668:tid 832806] [client 193.19.109.220:40817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "truthmedicalaesthetics.com"] [uri "/wp-login.php"] [unique_id "al4P1Wci6KgEEltqA3DWOgAAAAY"]
[Mon Jul 20 06:08:53.182956 2026] [security2:error] [pid 832668:tid 832868] [client 86.98.90.58:7867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P1Wci6KgEEltqA3DWRQAAAEQ"]
[Mon Jul 20 06:08:53.183148 2026] [security2:error] [pid 832668:tid 832868] [client 86.98.90.58:7867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P1Wci6KgEEltqA3DWRQAAAEQ"]
[Mon Jul 20 06:08:53.373359 2026] [security2:error] [pid 832668:tid 832902] [client 191.237.250.106:30130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/v543.php"] [unique_id "al4P1Wci6KgEEltqA3DWTwAAAGY"]
[Mon Jul 20 06:08:53.373457 2026] [security2:error] [pid 832668:tid 832902] [client 191.237.250.106:30130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/v543.php"] [unique_id "al4P1Wci6KgEEltqA3DWTwAAAGY"]
[Mon Jul 20 06:08:53.600677 2026] [security2:error] [pid 832668:tid 832808] [client 142.250.32.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "memarion.com"] [uri "/index.php"] [unique_id "al4P0Wci6KgEEltqA3DVJgAACEE"]
[Mon Jul 20 06:08:53.736288 2026] [core:error] [pid 832668:tid 832805] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:53.736311 2026] [core:error] [pid 832668:tid 832805] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:54.269798 2026] [security2:error] [pid 832668:tid 832817] [client 193.19.109.219:30363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4P1mci6KgEEltqA3DWkgAAABE"]
[Mon Jul 20 06:08:54.317830 2026] [security2:error] [pid 832668:tid 832896] [client 50.116.65.227:55158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4P1mci6KgEEltqA3DWmQAAAGA"]
[Mon Jul 20 06:08:54.327942 2026] [security2:error] [pid 832668:tid 832858] [client 50.116.65.227:55164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4P1mci6KgEEltqA3DWmwAAADo"]
[Mon Jul 20 06:08:54.455054 2026] [security2:error] [pid 832668:tid 832831] [client 38.20.252.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4P1mci6KgEEltqA3DWjAAAHwA"]
[Mon Jul 20 06:08:54.708126 2026] [security2:error] [pid 832668:tid 832920] [client 14.225.17.146:53814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4P1Gci6KgEEltqA3DWGAAAAHg"], referer: http://www.justinagrayman.com/Wordpress
[Mon Jul 20 06:08:55.080838 2026] [security2:error] [pid 832668:tid 832887] [client 103.77.203.233:58034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW1gAAAFc"]
[Mon Jul 20 06:08:55.080963 2026] [security2:error] [pid 832668:tid 832887] [client 103.77.203.233:58034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW1gAAAFc"]
[Mon Jul 20 06:08:55.142991 2026] [security2:error] [pid 832668:tid 832901] [client 38.68.180.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4P1mci6KgEEltqA3DW0AAAZRc"]
[Mon Jul 20 06:08:55.187409 2026] [security2:error] [pid 832668:tid 832906] [client 103.141.108.143:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW4gAAAGo"]
[Mon Jul 20 06:08:55.187798 2026] [security2:error] [pid 832668:tid 832906] [client 103.141.108.143:50788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DW4gAAAGo"]
[Mon Jul 20 06:08:55.486743 2026] [security2:error] [pid 832668:tid 832809] [client 191.237.250.106:29315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w3lls.php"] [unique_id "al4P12ci6KgEEltqA3DW-QAAAAk"]
[Mon Jul 20 06:08:55.486844 2026] [security2:error] [pid 832668:tid 832809] [client 191.237.250.106:29315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/w3lls.php"] [unique_id "al4P12ci6KgEEltqA3DW-QAAAAk"]
[Mon Jul 20 06:08:55.536777 2026] [security2:error] [pid 832668:tid 832902] [client 158.173.89.95:58121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P12ci6KgEEltqA3DXAAAAAGY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:08:55.643532 2026] [security2:error] [pid 832668:tid 832765] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DXCAAAXF4"]
[Mon Jul 20 06:08:55.643706 2026] [security2:error] [pid 832668:tid 832892] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P12ci6KgEEltqA3DXCAAAXF4"]
[Mon Jul 20 06:08:55.797621 2026] [core:error] [pid 832668:tid 832822] [client 14.225.17.146:57815] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wordpress
[Mon Jul 20 06:08:55.797647 2026] [core:error] [pid 832668:tid 832822] [client 14.225.17.146:57815] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wordpress
[Mon Jul 20 06:08:56.020874 2026] [security2:error] [pid 832668:tid 832849] [client 106.192.104.4:54637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXIgAAADE"]
[Mon Jul 20 06:08:56.020981 2026] [security2:error] [pid 832668:tid 832849] [client 106.192.104.4:54637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXIgAAADE"]
[Mon Jul 20 06:08:56.065041 2026] [security2:error] [pid 832668:tid 832924] [client 103.162.57.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4P1Wci6KgEEltqA3DWSQAAAHw"]
[Mon Jul 20 06:08:56.329764 2026] [security2:error] [pid 832668:tid 832923] [client 43.205.139.3:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4P2Gci6KgEEltqA3DXLQAAAHs"]
[Mon Jul 20 06:08:56.348376 2026] [security2:error] [pid 832668:tid 832840] [client 115.246.21.170:65466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXPgAAACg"]
[Mon Jul 20 06:08:56.348481 2026] [security2:error] [pid 832668:tid 832840] [client 115.246.21.170:65466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXPgAAACg"]
[Mon Jul 20 06:08:56.428970 2026] [security2:error] [pid 832668:tid 832803] [client 185.132.186.87:28897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/colors.min.php"] [unique_id "al4P2Gci6KgEEltqA3DXSQAAAAM"]
[Mon Jul 20 06:08:56.626146 2026] [security2:error] [pid 832668:tid 832907] [client 112.213.160.112:2971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXWwAAAGs"]
[Mon Jul 20 06:08:56.626264 2026] [security2:error] [pid 832668:tid 832907] [client 112.213.160.112:2971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Gci6KgEEltqA3DXWwAAAGs"]
[Mon Jul 20 06:08:56.820160 2026] [proxy:error] [pid 832668:tid 832876] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.820200 2026] [proxy_http:error] [pid 832668:tid 832876] [client 94.154.43.187:53178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:56.820896 2026] [proxy:error] [pid 832668:tid 832876] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.820930 2026] [proxy_http:error] [pid 832668:tid 832876] [client 94.154.43.187:53178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:56.831879 2026] [proxy:error] [pid 832668:tid 832833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.831938 2026] [proxy_http:error] [pid 832668:tid 832833] [client 94.154.43.177:55514] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:56.832499 2026] [proxy:error] [pid 832668:tid 832833] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:08:56.832536 2026] [proxy_http:error] [pid 832668:tid 832833] [client 94.154.43.177:55514] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:08:57.132982 2026] [security2:error] [pid 832668:tid 832825] [client 14.225.17.146:57452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4P12ci6KgEEltqA3DW_gAAABk"], referer: http://olearyplumbingllc.com/Wordpress
[Mon Jul 20 06:08:57.173462 2026] [security2:error] [pid 832668:tid 832836] [client 57.141.18.22:42772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P1Gci6KgEEltqA3DWLAAAJA4"]
[Mon Jul 20 06:08:57.261210 2026] [security2:error] [pid 832668:tid 832854] [client 45.116.69.230:63148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXmgAAADY"]
[Mon Jul 20 06:08:57.261311 2026] [security2:error] [pid 832668:tid 832854] [client 45.116.69.230:63148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXmgAAADY"]
[Mon Jul 20 06:08:57.313150 2026] [security2:error] [pid 832668:tid 832801] [client 104.234.53.85:26069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4P2Wci6KgEEltqA3DXnQAAAAE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:08:57.626576 2026] [security2:error] [pid 832668:tid 832872] [client 191.237.250.106:11234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-ws68.php"] [unique_id "al4P2Wci6KgEEltqA3DXuAAAAEg"]
[Mon Jul 20 06:08:57.626683 2026] [security2:error] [pid 832668:tid 832872] [client 191.237.250.106:11234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/wp-ws68.php"] [unique_id "al4P2Wci6KgEEltqA3DXuAAAAEg"]
[Mon Jul 20 06:08:57.749713 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXyAAAAA0"]
[Mon Jul 20 06:08:57.749837 2026] [security2:error] [pid 832668:tid 832813] [client 181.224.94.124:53459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P2Wci6KgEEltqA3DXyAAAAA0"]
[Mon Jul 20 06:08:57.866419 2026] [security2:error] [pid 832668:tid 832909] [client 103.153.183.69:42152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..%ef%bc%8fvar/www/html/config.php"] [unique_id "al4P2Wci6KgEEltqA3DXygAAAG0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:08:58.124968 2026] [core:error] [pid 832668:tid 832879] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.124990 2026] [core:error] [pid 832668:tid 832879] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.168026 2026] [security2:error] [pid 832668:tid 832911] [client 41.173.37.102:9769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DX5AAAAG8"]
[Mon Jul 20 06:08:58.168127 2026] [security2:error] [pid 832668:tid 832911] [client 41.173.37.102:9769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DX5AAAAG8"]
[Mon Jul 20 06:08:58.286612 2026] [core:error] [pid 832668:tid 832863] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.286643 2026] [core:error] [pid 832668:tid 832863] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.287462 2026] [core:error] [pid 832668:tid 832892] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.287480 2026] [core:error] [pid 832668:tid 832892] [client 207.241.173.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:08:58.406875 2026] [security2:error] [pid 832668:tid 832896] [client 185.132.186.81:24127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control-repository.php"] [unique_id "al4P2mci6KgEEltqA3DYBgAAAGA"]
[Mon Jul 20 06:08:58.441487 2026] [security2:error] [pid 832668:tid 832797] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYCwAAB34"]
[Mon Jul 20 06:08:58.441744 2026] [security2:error] [pid 832668:tid 832807] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYCwAAB34"]
[Mon Jul 20 06:08:58.475072 2026] [security2:error] [pid 832668:tid 832872] [client 178.152.178.232:37689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYDQAAAEg"]
[Mon Jul 20 06:08:58.475234 2026] [security2:error] [pid 832668:tid 832872] [client 178.152.178.232:37689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYDQAAAEg"]
[Mon Jul 20 06:08:58.503247 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:58242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/xyn.php"] [unique_id "al4P2mci6KgEEltqA3DYDgAAADI"]
[Mon Jul 20 06:08:58.503336 2026] [security2:error] [pid 832668:tid 832850] [client 191.237.250.106:58242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/xyn.php"] [unique_id "al4P2mci6KgEEltqA3DYDgAAADI"]
[Mon Jul 20 06:08:58.649195 2026] [security2:error] [pid 832668:tid 832855] [client 193.19.109.230:45465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "steadfastwolfproductions.com"] [uri "/wp-login.php"] [unique_id "al4P2mci6KgEEltqA3DYFQAAADc"]
[Mon Jul 20 06:08:58.856286 2026] [security2:error] [pid 832668:tid 832785] [remote 192.241.143.148:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYIQAAaXI"]
[Mon Jul 20 06:08:58.856447 2026] [security2:error] [pid 832668:tid 832905] [client 192.241.143.148:54886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYIQAAaXI"]
[Mon Jul 20 06:08:58.972014 2026] [security2:error] [pid 832668:tid 832770] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYLwAAPWM"]
[Mon Jul 20 06:08:58.972197 2026] [security2:error] [pid 832668:tid 832861] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P2mci6KgEEltqA3DYLwAAPWM"]
[Mon Jul 20 06:08:58.979866 2026] [security2:error] [pid 832668:tid 832872] [client 14.224.227.113:61767] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4P2mci6KgEEltqA3DYMAAAAEg"]
[Mon Jul 20 06:08:59.235813 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:57397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4P22ci6KgEEltqA3DYPAAAABw"], referer: http://musichaven.info/Wordpress
[Mon Jul 20 06:08:59.871393 2026] [security2:error] [pid 832668:tid 832835] [client 103.153.183.69:52892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../etc/nginx/nginx.conf"] [unique_id "al4P22ci6KgEEltqA3DYdwAAACM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:09:00.008122 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:21419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/green3.php"] [unique_id "al4P3Gci6KgEEltqA3DYgwAAAEI"]
[Mon Jul 20 06:09:00.008232 2026] [security2:error] [pid 832668:tid 832866] [client 191.237.250.106:21419] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/green3.php"] [unique_id "al4P3Gci6KgEEltqA3DYgwAAAEI"]
[Mon Jul 20 06:09:00.021380 2026] [security2:error] [pid 832668:tid 832872] [client 103.153.183.69:52892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../etc/apache2/apache2.conf"] [unique_id "al4P3Gci6KgEEltqA3DYhQAAAEg"], referer: https://www.google.com/
[Mon Jul 20 06:09:00.159024 2026] [security2:error] [pid 832668:tid 832813] [client 193.19.109.243:33125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYjQAAAA0"]
[Mon Jul 20 06:09:00.178567 2026] [security2:error] [pid 832668:tid 832824] [client 193.19.109.247:38607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYkAAAABg"]
[Mon Jul 20 06:09:00.358707 2026] [security2:error] [pid 832668:tid 832832] [client 14.225.17.146:57709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4P3Gci6KgEEltqA3DYlQAAACA"], referer: https://musichaven.info/Wordpress
[Mon Jul 20 06:09:00.434033 2026] [security2:error] [pid 832668:tid 832747] [remote 103.161.172.221:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYnwAANUw"]
[Mon Jul 20 06:09:00.539378 2026] [security2:error] [pid 832668:tid 832890] [client 164.100.212.184:58342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Gci6KgEEltqA3DYqAAAAFo"]
[Mon Jul 20 06:09:00.539530 2026] [security2:error] [pid 832668:tid 832890] [client 164.100.212.184:58342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Gci6KgEEltqA3DYqAAAAFo"]
[Mon Jul 20 06:09:00.631947 2026] [access_compat:error] [pid 832668:tid 832807] [client 112.90.2.210:52179] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:09:00.806120 2026] [security2:error] [pid 832668:tid 832833] [client 14.225.17.146:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4P22ci6KgEEltqA3DYNgAAACE"], referer: http://bigwormfishing.com/Wordpress
[Mon Jul 20 06:09:00.819499 2026] [security2:error] [pid 832668:tid 832719] [remote 103.161.172.221:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4P3Gci6KgEEltqA3DYxQAADzA"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:09:00.955950 2026] [security2:error] [pid 832668:tid 832902] [client 185.132.186.75:36285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-react-refresh-runtime.min-soap.php"] [unique_id "al4P3Gci6KgEEltqA3DY0wAAAGY"]
[Mon Jul 20 06:09:01.569599 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:29318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ccc.php"] [unique_id "al4P3Wci6KgEEltqA3DY_QAAAC4"]
[Mon Jul 20 06:09:01.569759 2026] [security2:error] [pid 832668:tid 832846] [client 191.237.250.106:29318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/ccc.php"] [unique_id "al4P3Wci6KgEEltqA3DY_QAAAC4"]
[Mon Jul 20 06:09:01.703281 2026] [security2:error] [pid 832668:tid 832812] [client 27.96.94.195:38041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Wci6KgEEltqA3DZCgAAAAw"]
[Mon Jul 20 06:09:01.703414 2026] [security2:error] [pid 832668:tid 832812] [client 27.96.94.195:38041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P3Wci6KgEEltqA3DZCgAAAAw"]
[Mon Jul 20 06:09:01.774633 2026] [security2:error] [pid 832668:tid 832702] [remote 57.141.18.38:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3966302"] [unique_id "al4P3Wci6KgEEltqA3DZDAAAIR8"]
[Mon Jul 20 06:09:01.801985 2026] [security2:error] [pid 832668:tid 832914] [client 14.225.17.146:55884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4P3Wci6KgEEltqA3DZCAAAAHI"], referer: https://bigwormfishing.com/Wordpress
[Mon Jul 20 06:09:01.885220 2026] [security2:error] [pid 832668:tid 832900] [client 57.141.18.101:34934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2Wci6KgEEltqA3DXngAAZGE"]
[Mon Jul 20 06:09:02.078178 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:19406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/get.php"] [unique_id "al4P3mci6KgEEltqA3DZKwAAAAg"]
[Mon Jul 20 06:09:02.078312 2026] [security2:error] [pid 832668:tid 832808] [client 191.237.250.106:19406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/get.php"] [unique_id "al4P3mci6KgEEltqA3DZKwAAAAg"]
[Mon Jul 20 06:09:02.482727 2026] [security2:error] [pid 832668:tid 832871] [client 191.237.250.106:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/images.php"] [unique_id "al4P3mci6KgEEltqA3DZYwAAAEc"]
[Mon Jul 20 06:09:02.482878 2026] [security2:error] [pid 832668:tid 832871] [client 191.237.250.106:62286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/images.php"] [unique_id "al4P3mci6KgEEltqA3DZYwAAAEc"]
[Mon Jul 20 06:09:02.499999 2026] [security2:error] [pid 832668:tid 832866] [client 103.95.123.246:18805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZQAAAEI"]
[Mon Jul 20 06:09:02.500129 2026] [security2:error] [pid 832668:tid 832866] [client 103.95.123.246:18805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZQAAAEI"]
[Mon Jul 20 06:09:02.511404 2026] [security2:error] [pid 832668:tid 832706] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZwAAISM"]
[Mon Jul 20 06:09:02.511559 2026] [security2:error] [pid 832668:tid 832833] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZZwAAISM"]
[Mon Jul 20 06:09:02.590855 2026] [security2:error] [pid 832668:tid 832764] [remote 188.40.28.4:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZbQAAAV0"]
[Mon Jul 20 06:09:02.591127 2026] [security2:error] [pid 832668:tid 832801] [client 188.40.28.4:33822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4P3mci6KgEEltqA3DZbQAAAV0"]
[Mon Jul 20 06:09:02.636137 2026] [security2:error] [pid 832668:tid 832809] [client 57.141.18.0:57614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2Wci6KgEEltqA3DX2QAACSQ"]
[Mon Jul 20 06:09:02.819241 2026] [access_compat:error] [pid 832668:tid 832922] [client 183.47.107.119:47159] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:09:02.945820 2026] [security2:error] [pid 832668:tid 832846] [client 66.249.66.200:64747] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "50.116.64.39"] [uri "/robots.txt"] [unique_id "al4P3mci6KgEEltqA3DZjgAAAC4"]
[Mon Jul 20 06:09:02.993154 2026] [security2:error] [pid 832668:tid 832924] [client 185.132.186.73:56161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/module.audio-video.riff-set.php"] [unique_id "al4P3mci6KgEEltqA3DZkAAAAHw"]
[Mon Jul 20 06:09:03.223999 2026] [security2:error] [pid 832668:tid 832903] [client 57.141.18.22:38052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2mci6KgEEltqA3DYDwAAZzc"]
[Mon Jul 20 06:09:03.340306 2026] [security2:error] [pid 832668:tid 832913] [client 193.37.33.232:21819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4P32ci6KgEEltqA3DZsAAAAHE"]
[Mon Jul 20 06:09:03.496378 2026] [security2:error] [pid 832668:tid 832911] [client 104.234.53.93:46559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4P32ci6KgEEltqA3DZvgAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:03.581683 2026] [security2:error] [pid 832668:tid 832846] [client 50.116.65.227:16836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZtwAAAC4"]
[Mon Jul 20 06:09:03.615456 2026] [security2:error] [pid 832668:tid 832834] [client 57.141.18.19:60852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P2mci6KgEEltqA3DYMQAAIi0"]
[Mon Jul 20 06:09:03.627119 2026] [security2:error] [pid 832668:tid 832854] [client 191.237.250.106:50465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/alls.php"] [unique_id "al4P32ci6KgEEltqA3DZzgAAADY"]
[Mon Jul 20 06:09:03.627287 2026] [security2:error] [pid 832668:tid 832854] [client 191.237.250.106:50465] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/alls.php"] [unique_id "al4P32ci6KgEEltqA3DZzgAAADY"]
[Mon Jul 20 06:09:03.671782 2026] [security2:error] [pid 832668:tid 832808] [client 14.225.17.146:55713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZxAAAAAg"]
[Mon Jul 20 06:09:03.740002 2026] [proxy:error] [pid 832668:tid 832892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:03.740074 2026] [proxy_http:error] [pid 832668:tid 832892] [client 20.74.45.95:56323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:03.740930 2026] [proxy:error] [pid 832668:tid 832892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:03.740980 2026] [proxy_http:error] [pid 832668:tid 832892] [client 20.74.45.95:56323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:03.770943 2026] [security2:error] [pid 832668:tid 832884] [client 14.225.17.146:52574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZ1AAAAFQ"], referer: http://claysharecon.com/Wordpress
[Mon Jul 20 06:09:03.779577 2026] [security2:error] [pid 832668:tid 832920] [client 50.116.65.227:16838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4P32ci6KgEEltqA3DZywAAAHg"]
[Mon Jul 20 06:09:04.153735 2026] [security2:error] [pid 832668:tid 832820] [client 57.141.18.49:36126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P22ci6KgEEltqA3DYZwAAFBo"]
[Mon Jul 20 06:09:04.362064 2026] [security2:error] [pid 832668:tid 832687] [remote 188.166.241.141:57774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4P4Gci6KgEEltqA3DaBQAAThA"]
[Mon Jul 20 06:09:04.411816 2026] [security2:error] [pid 832668:tid 832918] [client 14.225.17.146:55174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4P3Wci6KgEEltqA3DZFwAAAHY"], referer: http://bruceledewitz.com/Wordpress
[Mon Jul 20 06:09:04.777396 2026] [security2:error] [pid 832668:tid 832870] [client 57.141.18.21:35170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P3Gci6KgEEltqA3DYowAARns"]
[Mon Jul 20 06:09:04.850437 2026] [security2:error] [pid 832668:tid 832720] [remote 188.166.241.141:57774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4P4Gci6KgEEltqA3DaLAAATTE"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:09:05.236419 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:8692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaVQAAABg"]
[Mon Jul 20 06:09:05.236531 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:8692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaVQAAABg"]
[Mon Jul 20 06:09:05.505176 2026] [security2:error] [pid 832668:tid 832858] [client 191.237.250.106:50653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/coffexium.php"] [unique_id "al4P4Wci6KgEEltqA3DaaAAAADo"]
[Mon Jul 20 06:09:05.505285 2026] [security2:error] [pid 832668:tid 832858] [client 191.237.250.106:50653] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "verdunestate.twz.oin.mybluehost.me"] [uri "/coffexium.php"] [unique_id "al4P4Wci6KgEEltqA3DaaAAAADo"]
[Mon Jul 20 06:09:05.551212 2026] [security2:error] [pid 832668:tid 832867] [client 103.77.203.233:58097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DabQAAAEM"]
[Mon Jul 20 06:09:05.560731 2026] [security2:error] [pid 832668:tid 832867] [client 103.77.203.233:58097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DabQAAAEM"]
[Mon Jul 20 06:09:05.671860 2026] [security2:error] [pid 832668:tid 832758] [remote 5.56.58.49:48492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P4Wci6KgEEltqA3DacQAAPVc"]
[Mon Jul 20 06:09:05.834209 2026] [security2:error] [pid 832668:tid 832808] [client 103.141.108.143:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaggAAAAg"]
[Mon Jul 20 06:09:05.834313 2026] [security2:error] [pid 832668:tid 832808] [client 103.141.108.143:51240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P4Wci6KgEEltqA3DaggAAAAg"]
[Mon Jul 20 06:09:05.889341 2026] [security2:error] [pid 832668:tid 832703] [remote 5.56.58.49:48492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.58.56.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P4Wci6KgEEltqA3DahgAAIiA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:06.091944 2026] [security2:error] [pid 832668:tid 832805] [client 57.141.18.113:44506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P3Wci6KgEEltqA3DZDgAABXE"]
[Mon Jul 20 06:09:06.161451 2026] [security2:error] [pid 832668:tid 832728] [remote 152.228.213.32:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3DanAAAcjk"]
[Mon Jul 20 06:09:06.252034 2026] [fcgid:warn] [pid 832668:tid 832909] (70014)End of file found: [client 185.247.137.38:35479] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:06.264823 2026] [security2:error] [pid 832668:tid 832846] [client 50.116.65.227:59418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4P4mci6KgEEltqA3DaqQAAAC4"]
[Mon Jul 20 06:09:06.276634 2026] [security2:error] [pid 832668:tid 832872] [client 50.116.65.227:16882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4P4mci6KgEEltqA3DaqwAAABw"]
[Mon Jul 20 06:09:06.316594 2026] [security2:error] [pid 832668:tid 832706] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3DasQAALCM"]
[Mon Jul 20 06:09:06.316776 2026] [security2:error] [pid 832668:tid 832844] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3DasQAALCM"]
[Mon Jul 20 06:09:06.461467 2026] [security2:error] [pid 832668:tid 832764] [remote 152.228.213.32:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3DavAAADV0"], referer: https://mail.gpm.vvo.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:06.562534 2026] [security2:error] [pid 832668:tid 832825] [client 104.234.53.70:33109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4P4mci6KgEEltqA3DaxwAAABk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:06.638345 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.98:40451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/tinymce/utils/license.php"] [unique_id "al4P4mci6KgEEltqA3DazAAAAAI"]
[Mon Jul 20 06:09:06.806755 2026] [security2:error] [pid 832668:tid 832675] [remote 20.173.88.122:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3Da4QAADAQ"]
[Mon Jul 20 06:09:06.833495 2026] [security2:error] [pid 832668:tid 832741] [remote 194.164.192.228:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3Da5QAAF0Y"]
[Mon Jul 20 06:09:06.833714 2026] [security2:error] [pid 832668:tid 832808] [client 115.246.21.170:18242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3Da5AAAAAg"]
[Mon Jul 20 06:09:06.833909 2026] [security2:error] [pid 832668:tid 832808] [client 115.246.21.170:18242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P4mci6KgEEltqA3Da5AAAAAg"]
[Mon Jul 20 06:09:06.872389 2026] [fcgid:warn] [pid 832668:tid 832892] (70014)End of file found: [client 66.132.195.123:9602] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:06.916510 2026] [security2:error] [pid 832668:tid 832853] [client 57.141.18.29:45828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P3mci6KgEEltqA3DZdAAANW8"]
[Mon Jul 20 06:09:06.917450 2026] [security2:error] [pid 832668:tid 832763] [remote 162.19.86.63:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P4mci6KgEEltqA3Da6AAAPlw"]
[Mon Jul 20 06:09:07.027140 2026] [security2:error] [pid 832668:tid 832740] [remote 194.164.192.228:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3Da8wAAXkU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:07.093341 2026] [security2:error] [pid 832668:tid 832817] [client 14.225.17.146:58816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3Da7wAAABE"], referer: http://omrobuildingcenter.com/Wordpress
[Mon Jul 20 06:09:07.136422 2026] [security2:error] [pid 832668:tid 832796] [remote 20.173.88.122:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3Da-wAACn0"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:09:07.150739 2026] [security2:error] [pid 832668:tid 832860] [client 94.154.43.186:52224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "holistichealthmassagenz.com"] [uri "/.env"] [unique_id "al4P42ci6KgEEltqA3Da_AAAADw"]
[Mon Jul 20 06:09:07.157450 2026] [security2:error] [pid 832668:tid 832708] [remote 162.19.86.63:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3Da_QAANyU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:09:07.159311 2026] [proxy:error] [pid 832668:tid 832852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:07.159342 2026] [proxy_http:error] [pid 832668:tid 832852] [client 94.154.43.185:28640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:07.159782 2026] [proxy:error] [pid 832668:tid 832852] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:07.159802 2026] [proxy_http:error] [pid 832668:tid 832852] [client 94.154.43.185:28640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:07.189783 2026] [security2:error] [pid 832668:tid 832868] [client 106.192.104.4:55129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbAgAAAEQ"]
[Mon Jul 20 06:09:07.189884 2026] [security2:error] [pid 832668:tid 832868] [client 106.192.104.4:55129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbAgAAAEQ"]
[Mon Jul 20 06:09:07.248744 2026] [security2:error] [pid 832668:tid 832781] [remote 57.141.18.94:46856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2968118"] [unique_id "al4P42ci6KgEEltqA3DbBwAAPW4"]
[Mon Jul 20 06:09:07.328153 2026] [security2:error] [pid 832668:tid 832827] [client 112.213.160.112:30945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbEAAAABs"]
[Mon Jul 20 06:09:07.328316 2026] [security2:error] [pid 832668:tid 832827] [client 112.213.160.112:30945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbEAAAABs"]
[Mon Jul 20 06:09:07.373372 2026] [security2:error] [pid 832668:tid 832906] [client 14.225.17.146:65435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4P42ci6KgEEltqA3Da-gAAAGo"], referer: http://latiendadejorge.com.gt/Wordpress
[Mon Jul 20 06:09:07.407006 2026] [security2:error] [pid 832668:tid 832806] [client 104.234.53.52:23179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4P42ci6KgEEltqA3DbDAAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:07.684574 2026] [security2:error] [pid 832668:tid 832850] [client 14.225.17.146:54609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3DaqAAAADI"], referer: http://mollycahill.com/Wordpress
[Mon Jul 20 06:09:07.958659 2026] [security2:error] [pid 832668:tid 832903] [client 45.116.69.230:63626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbQgAAAGc"]
[Mon Jul 20 06:09:07.958768 2026] [security2:error] [pid 832668:tid 832903] [client 45.116.69.230:63626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P42ci6KgEEltqA3DbQgAAAGc"]
[Mon Jul 20 06:09:08.008213 2026] [security2:error] [pid 832668:tid 832904] [client 104.234.53.52:23179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4P42ci6KgEEltqA3DbQQAAAGg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:08.327794 2026] [security2:error] [pid 832668:tid 832801] [client 57.141.18.108:39586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4Gci6KgEEltqA3DZ7wAAAQo"]
[Mon Jul 20 06:09:08.382174 2026] [security2:error] [pid 832668:tid 832896] [client 57.141.18.31:55664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4Gci6KgEEltqA3DZ8wAAYA8"]
[Mon Jul 20 06:09:08.678763 2026] [security2:error] [pid 832668:tid 832923] [client 181.224.94.124:14435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbfgAAAHs"]
[Mon Jul 20 06:09:08.678922 2026] [security2:error] [pid 832668:tid 832923] [client 181.224.94.124:14435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbfgAAAHs"]
[Mon Jul 20 06:09:08.745643 2026] [security2:error] [pid 832668:tid 832820] [client 41.173.37.102:10209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbggAAABQ"]
[Mon Jul 20 06:09:08.745789 2026] [security2:error] [pid 832668:tid 832820] [client 41.173.37.102:10209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbggAAABQ"]
[Mon Jul 20 06:09:08.998478 2026] [security2:error] [pid 832668:tid 832809] [client 178.152.178.232:35905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbkwAAAAk"]
[Mon Jul 20 06:09:08.998597 2026] [security2:error] [pid 832668:tid 832809] [client 178.152.178.232:35905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Gci6KgEEltqA3DbkwAAAAk"]
[Mon Jul 20 06:09:09.049195 2026] [security2:error] [pid 832668:tid 832895] [client 14.225.17.146:64888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P5Gci6KgEEltqA3DbiwAAAF8"], referer: http://sesamegreenbeans.com/Wordpress
[Mon Jul 20 06:09:09.187759 2026] [security2:error] [pid 832668:tid 832742] [remote 217.61.143.92:38510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3DbmgAAIkc"]
[Mon Jul 20 06:09:09.193947 2026] [security2:error] [pid 832668:tid 832755] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3DbmwAAOFQ"]
[Mon Jul 20 06:09:09.194091 2026] [security2:error] [pid 832668:tid 832856] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3DbmwAAOFQ"]
[Mon Jul 20 06:09:09.216203 2026] [security2:error] [pid 832668:tid 832797] [remote 124.55.178.99:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3DbngAAan4"]
[Mon Jul 20 06:09:09.555897 2026] [security2:error] [pid 832668:tid 832784] [remote 217.61.143.92:38510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3DbzQAAcHE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:09:09.606443 2026] [security2:error] [pid 832668:tid 832750] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3Db1QAABE8"]
[Mon Jul 20 06:09:09.606585 2026] [security2:error] [pid 832668:tid 832804] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P5Wci6KgEEltqA3Db1QAABE8"]
[Mon Jul 20 06:09:09.684393 2026] [security2:error] [pid 832668:tid 832728] [remote 124.55.178.99:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P5Wci6KgEEltqA3Db2gAAejk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:09.685115 2026] [security2:error] [pid 832668:tid 832878] [client 185.132.186.97:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/options.php"] [unique_id "al4P5Wci6KgEEltqA3Db2wAAAE4"]
[Mon Jul 20 06:09:10.057251 2026] [security2:error] [pid 832668:tid 832910] [client 66.249.64.6:61397] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "umatha.art"] [uri "/robots.txt"] [unique_id "al4P5mci6KgEEltqA3Db_wAAAG4"]
[Mon Jul 20 06:09:10.110489 2026] [security2:error] [pid 832668:tid 832848] [client 14.225.17.146:58633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P5Wci6KgEEltqA3Db8wAAADA"], referer: https://sesamegreenbeans.com/Wordpress
[Mon Jul 20 06:09:10.604070 2026] [security2:error] [pid 832668:tid 832890] [client 14.225.17.146:58598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4P5mci6KgEEltqA3DcFgAAAFo"], referer: http://myspineworld.com/Wordpress
[Mon Jul 20 06:09:10.635176 2026] [security2:error] [pid 832668:tid 832911] [client 57.141.18.108:39600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3DatAAAb0M"]
[Mon Jul 20 06:09:10.832508 2026] [security2:error] [pid 832668:tid 832833] [client 57.141.18.106:36536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P4mci6KgEEltqA3DaxAAAIT0"]
[Mon Jul 20 06:09:11.173205 2026] [security2:error] [pid 832668:tid 832919] [client 164.100.212.184:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P52ci6KgEEltqA3DcUwAAAHc"]
[Mon Jul 20 06:09:11.173310 2026] [security2:error] [pid 832668:tid 832919] [client 164.100.212.184:53455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P52ci6KgEEltqA3DcUwAAAHc"]
[Mon Jul 20 06:09:11.354778 2026] [security2:error] [pid 832668:tid 832922] [client 50.116.65.227:58842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2025/02/IMG_9124.jpeg"] [unique_id "al4P52ci6KgEEltqA3DcYwAAADU"]
[Mon Jul 20 06:09:11.546085 2026] [security2:error] [pid 832668:tid 832920] [client 57.141.18.53:65386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P42ci6KgEEltqA3DbEwAAeCc"]
[Mon Jul 20 06:09:11.561023 2026] [security2:error] [pid 832668:tid 832905] [client 193.19.109.240:21861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4P52ci6KgEEltqA3DceQAAAGk"]
[Mon Jul 20 06:09:11.573797 2026] [security2:error] [pid 832668:tid 832916] [client 14.225.17.146:57349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DcbQAAAHQ"], referer: https://myspineworld.com/Wordpress
[Mon Jul 20 06:09:11.591184 2026] [security2:error] [pid 832668:tid 832891] [client 193.19.109.244:49669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4P52ci6KgEEltqA3DcegAAAFs"]
[Mon Jul 20 06:09:11.872684 2026] [security2:error] [pid 832668:tid 832863] [client 85.254.64.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DcjwAAAD8"]
[Mon Jul 20 06:09:12.346658 2026] [security2:error] [pid 832668:tid 832868] [client 104.234.53.86:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4P6Gci6KgEEltqA3DcrwAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:12.542062 2026] [security2:error] [pid 832668:tid 832853] [client 98.159.234.160:50671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P6Gci6KgEEltqA3DcyAAAADU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:12.662085 2026] [security2:error] [pid 832668:tid 832802] [client 185.132.186.101:27197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/wp-load.php"] [unique_id "al4P6Gci6KgEEltqA3DcygAAAAI"]
[Mon Jul 20 06:09:12.820532 2026] [security2:error] [pid 832668:tid 832907] [client 57.141.18.83:55766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P5Gci6KgEEltqA3DbdQAAazQ"]
[Mon Jul 20 06:09:12.873582 2026] [security2:error] [pid 832668:tid 832865] [client 57.141.18.60:65448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P5Gci6KgEEltqA3DbgQAAQQ4"]
[Mon Jul 20 06:09:13.011383 2026] [security2:error] [pid 832668:tid 832704] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3Dc5AAAcCE"]
[Mon Jul 20 06:09:13.011518 2026] [security2:error] [pid 832668:tid 832912] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3Dc5AAAcCE"]
[Mon Jul 20 06:09:13.174398 2026] [security2:error] [pid 832668:tid 832840] [client 57.141.18.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc5QAAACg"]
[Mon Jul 20 06:09:13.200314 2026] [security2:error] [pid 832668:tid 832875] [client 14.225.17.146:65508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc6wAAAEs"], referer: http://friendlyspreadsheet.com/Wordpress
[Mon Jul 20 06:09:13.555662 2026] [core:error] [pid 832668:tid 832912] [client 205.210.31.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:13.555684 2026] [core:error] [pid 832668:tid 832912] [client 205.210.31.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:13.559410 2026] [security2:error] [pid 832668:tid 832851] [client 103.95.123.246:19279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3DdEAAAADM"]
[Mon Jul 20 06:09:13.559493 2026] [security2:error] [pid 832668:tid 832851] [client 103.95.123.246:19279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P6Wci6KgEEltqA3DdEAAAADM"]
[Mon Jul 20 06:09:13.827808 2026] [security2:error] [pid 832668:tid 832867] [client 193.19.109.247:25885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cathyspeed.org"] [uri "/wp-login.php"] [unique_id "al4P6Wci6KgEEltqA3DdKAAAAEM"]
[Mon Jul 20 06:09:14.192239 2026] [security2:error] [pid 832668:tid 832881] [client 14.225.17.146:65471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc6AAAAFE"], referer: http://getgarrison.com/Wordpress
[Mon Jul 20 06:09:14.224902 2026] [security2:error] [pid 832668:tid 832911] [client 14.225.17.146:65476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdQAAAAG8"], referer: https://friendlyspreadsheet.com/Wordpress
[Mon Jul 20 06:09:14.586211 2026] [security2:error] [pid 832668:tid 832855] [client 57.141.18.45:58174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P5mci6KgEEltqA3DcKAAAN0o"]
[Mon Jul 20 06:09:14.641818 2026] [security2:error] [pid 832668:tid 832825] [client 185.132.186.71:55179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/cc.php"] [unique_id "al4P6mci6KgEEltqA3DdYAAAABk"]
[Mon Jul 20 06:09:14.697507 2026] [security2:error] [pid 832668:tid 832921] [client 193.19.109.215:41583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4P6mci6KgEEltqA3DdYwAAAHk"]
[Mon Jul 20 06:09:15.023838 2026] [security2:error] [pid 832668:tid 832674] [remote 103.82.22.235:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P62ci6KgEEltqA3DdgQAAFQM"]
[Mon Jul 20 06:09:15.343445 2026] [security2:error] [pid 832668:tid 832890] [client 57.141.18.33:41158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DcWgAAWhY"]
[Mon Jul 20 06:09:15.950247 2026] [security2:error] [pid 832668:tid 832698] [remote 154.66.198.148:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4P62ci6KgEEltqA3DdtwAAKBs"]
[Mon Jul 20 06:09:15.988662 2026] [security2:error] [pid 832668:tid 832829] [client 103.77.203.233:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P62ci6KgEEltqA3DdvAAAAB0"]
[Mon Jul 20 06:09:15.989142 2026] [security2:error] [pid 832668:tid 832829] [client 103.77.203.233:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P62ci6KgEEltqA3DdvAAAAB0"]
[Mon Jul 20 06:09:16.168839 2026] [security2:error] [pid 832668:tid 832813] [client 57.141.18.20:39132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P52ci6KgEEltqA3DckAAADT4"]
[Mon Jul 20 06:09:16.217275 2026] [security2:error] [pid 832668:tid 832888] [client 86.98.90.58:9495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3DdygAAAFg"]
[Mon Jul 20 06:09:16.217527 2026] [security2:error] [pid 832668:tid 832888] [client 86.98.90.58:9495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3DdygAAAFg"]
[Mon Jul 20 06:09:16.243401 2026] [security2:error] [pid 832668:tid 832807] [client 14.225.17.146:65484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdXQAAAAc"], referer: http://swafforddetailing.com/Wordpress
[Mon Jul 20 06:09:16.366197 2026] [security2:error] [pid 832668:tid 832744] [remote 103.82.22.235:47274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4P7Gci6KgEEltqA3Dd0wAAPEk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:09:16.659790 2026] [security2:error] [pid 832668:tid 832847] [client 185.132.186.55:26455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/aahana/worksec.php"] [unique_id "al4P7Gci6KgEEltqA3Dd5gAAAC8"]
[Mon Jul 20 06:09:16.664431 2026] [security2:error] [pid 832668:tid 832823] [client 103.141.108.143:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3Dd5wAAABc"]
[Mon Jul 20 06:09:16.665202 2026] [security2:error] [pid 832668:tid 832823] [client 103.141.108.143:51692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Gci6KgEEltqA3Dd5wAAABc"]
[Mon Jul 20 06:09:16.731958 2026] [security2:error] [pid 832668:tid 832803] [client 57.141.18.119:50310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6Gci6KgEEltqA3DctwAAAzU"]
[Mon Jul 20 06:09:16.970599 2026] [security2:error] [pid 832668:tid 832909] [client 104.234.53.65:45107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4P7Gci6KgEEltqA3DeAgAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:17.102932 2026] [security2:error] [pid 832668:tid 832797] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeEAAAAX4"]
[Mon Jul 20 06:09:17.103063 2026] [security2:error] [pid 832668:tid 832801] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeEAAAAX4"]
[Mon Jul 20 06:09:17.174335 2026] [security2:error] [pid 832668:tid 832758] [remote 154.66.198.148:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4P7Wci6KgEEltqA3DeFwAAQlc"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:09:17.518848 2026] [security2:error] [pid 832668:tid 832700] [remote 20.153.140.50:40874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeLQAAHx0"]
[Mon Jul 20 06:09:17.519062 2026] [security2:error] [pid 832668:tid 832831] [client 20.153.140.50:40874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeLQAAHx0"]
[Mon Jul 20 06:09:17.565429 2026] [security2:error] [pid 832668:tid 832805] [client 115.246.21.170:19416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeMwAAAAU"]
[Mon Jul 20 06:09:17.565539 2026] [security2:error] [pid 832668:tid 832805] [client 115.246.21.170:19416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeMwAAAAU"]
[Mon Jul 20 06:09:17.601787 2026] [security2:error] [pid 832668:tid 832902] [client 106.192.104.4:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeOAAAAGY"]
[Mon Jul 20 06:09:17.601934 2026] [security2:error] [pid 832668:tid 832902] [client 106.192.104.4:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeOAAAAGY"]
[Mon Jul 20 06:09:17.679406 2026] [security2:error] [pid 832668:tid 832806] [client 57.141.18.26:35700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6Wci6KgEEltqA3Dc9QAABnI"]
[Mon Jul 20 06:09:17.714435 2026] [security2:error] [pid 832668:tid 832832] [client 27.96.94.195:37310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeQgAAACA"]
[Mon Jul 20 06:09:17.714554 2026] [security2:error] [pid 832668:tid 832832] [client 27.96.94.195:37310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P7Wci6KgEEltqA3DeQgAAACA"]
[Mon Jul 20 06:09:18.066683 2026] [security2:error] [pid 832668:tid 832834] [client 112.213.160.112:8193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeWwAAACI"]
[Mon Jul 20 06:09:18.066841 2026] [security2:error] [pid 832668:tid 832834] [client 112.213.160.112:8193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeWwAAACI"]
[Mon Jul 20 06:09:18.149254 2026] [security2:error] [pid 832668:tid 832773] [remote 162.19.86.63:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DeYQAAMGY"]
[Mon Jul 20 06:09:18.190128 2026] [security2:error] [pid 832668:tid 832730] [remote 217.61.143.92:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DeZwAAbDs"]
[Mon Jul 20 06:09:18.398019 2026] [security2:error] [pid 832668:tid 832695] [remote 162.19.86.63:50566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DedQAANhg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:18.517098 2026] [security2:error] [pid 832668:tid 832684] [remote 217.61.143.92:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DegQAADg0"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:09:18.603023 2026] [security2:error] [pid 832668:tid 832915] [client 45.116.69.230:64114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeiAAAAHM"]
[Mon Jul 20 06:09:18.603202 2026] [security2:error] [pid 832668:tid 832915] [client 45.116.69.230:64114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DeiAAAAHM"]
[Mon Jul 20 06:09:18.712081 2026] [security2:error] [pid 832668:tid 832863] [client 185.132.186.73:46045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al4P7mci6KgEEltqA3DejwAAAD8"]
[Mon Jul 20 06:09:18.770951 2026] [security2:error] [pid 832668:tid 832893] [client 57.141.18.117:42570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdUAAAXTM"]
[Mon Jul 20 06:09:18.835230 2026] [security2:error] [pid 832668:tid 832805] [client 181.224.94.124:40478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DemwAAAAU"]
[Mon Jul 20 06:09:18.835315 2026] [security2:error] [pid 832668:tid 832805] [client 181.224.94.124:40478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P7mci6KgEEltqA3DemwAAAAU"]
[Mon Jul 20 06:09:19.068465 2026] [security2:error] [pid 832668:tid 832856] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4P72ci6KgEEltqA3DerwAAADg"], referer: https://twitter.com/
[Mon Jul 20 06:09:19.198624 2026] [security2:error] [pid 832668:tid 832912] [client 57.141.18.85:51094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P6mci6KgEEltqA3DdagAAcFw"]
[Mon Jul 20 06:09:19.392079 2026] [security2:error] [pid 832668:tid 832802] [client 41.173.37.102:10643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P72ci6KgEEltqA3DeygAAAAI"]
[Mon Jul 20 06:09:19.392191 2026] [security2:error] [pid 832668:tid 832802] [client 41.173.37.102:10643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P72ci6KgEEltqA3DeygAAAAI"]
[Mon Jul 20 06:09:19.614122 2026] [security2:error] [pid 832668:tid 832853] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4P72ci6KgEEltqA3De2wAAADU"], referer: https://duckduckgo.com/?q=aqc7m
[Mon Jul 20 06:09:20.093843 2026] [security2:error] [pid 832668:tid 832676] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3De_wAAeQU"]
[Mon Jul 20 06:09:20.094005 2026] [security2:error] [pid 832668:tid 832921] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3De_wAAeQU"]
[Mon Jul 20 06:09:20.228144 2026] [security2:error] [pid 832668:tid 832701] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfCAAALB4"]
[Mon Jul 20 06:09:20.228290 2026] [security2:error] [pid 832668:tid 832844] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfCAAALB4"]
[Mon Jul 20 06:09:20.268024 2026] [security2:error] [pid 832668:tid 832819] [client 103.153.183.69:40772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../etc/ssh/sshd_config"] [unique_id "al4P8Gci6KgEEltqA3DfDAAAABM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:09:20.312723 2026] [security2:error] [pid 832668:tid 832828] [client 178.152.178.232:37574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfEQAAABw"]
[Mon Jul 20 06:09:20.312838 2026] [security2:error] [pid 832668:tid 832828] [client 178.152.178.232:37574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Gci6KgEEltqA3DfEQAAABw"]
[Mon Jul 20 06:09:20.342307 2026] [security2:error] [pid 832668:tid 832862] [client 158.173.166.181:60671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4P8Gci6KgEEltqA3DfGAAAAD4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:20.353497 2026] [security2:error] [pid 832668:tid 832913] [client 104.234.53.92:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4P8Gci6KgEEltqA3DfFwAAAHE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:20.538185 2026] [security2:error] [pid 832668:tid 832809] [client 57.141.18.10:59568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P7Gci6KgEEltqA3Dd1gAACQs"]
[Mon Jul 20 06:09:21.364646 2026] [security2:error] [pid 832668:tid 832824] [client 57.141.18.119:50312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P7Wci6KgEEltqA3DeIwAAGDg"]
[Mon Jul 20 06:09:21.510431 2026] [security2:error] [pid 832668:tid 832907] [client 103.153.183.69:40772] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../root/.ssh/id_rsa"] [unique_id "al4P8Wci6KgEEltqA3DfcQAAAGs"], referer: https://www.facebook.com/
[Mon Jul 20 06:09:21.733200 2026] [security2:error] [pid 832668:tid 832916] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4P8Wci6KgEEltqA3DfeQAAAHQ"], referer: https://t.co/u468s1ncte
[Mon Jul 20 06:09:21.752841 2026] [security2:error] [pid 832668:tid 832829] [client 164.100.212.184:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Wci6KgEEltqA3DfewAAAB0"]
[Mon Jul 20 06:09:21.752927 2026] [security2:error] [pid 832668:tid 832829] [client 164.100.212.184:59899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P8Wci6KgEEltqA3DfewAAAB0"]
[Mon Jul 20 06:09:21.766927 2026] [security2:error] [pid 832668:tid 832689] [remote 47.86.33.52:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P8Wci6KgEEltqA3DfegAATRI"]
[Mon Jul 20 06:09:22.209606 2026] [security2:error] [pid 832668:tid 832861] [client 57.141.18.85:51108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P7mci6KgEEltqA3DeYgAAPWY"]
[Mon Jul 20 06:09:22.257763 2026] [security2:error] [pid 832668:tid 832890] [client 185.132.186.55:58779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/class_api.php"] [unique_id "al4P8mci6KgEEltqA3DfpwAAAFo"]
[Mon Jul 20 06:09:22.272258 2026] [security2:error] [pid 832668:tid 832842] [client 104.234.53.57:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4P8mci6KgEEltqA3DfqQAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:22.435138 2026] [security2:error] [pid 832668:tid 832775] [remote 154.66.198.148:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4P8mci6KgEEltqA3DftQAALWg"]
[Mon Jul 20 06:09:22.503999 2026] [security2:error] [pid 832668:tid 832922] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4P8mci6KgEEltqA3DfvQAAAHo"], referer: https://duckduckgo.com/?q=yesgu
[Mon Jul 20 06:09:23.096414 2026] [security2:error] [pid 832668:tid 832899] [client 57.141.18.5:49984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P72ci6KgEEltqA3DetQAAY0w"]
[Mon Jul 20 06:09:23.264658 2026] [security2:error] [pid 832668:tid 832710] [remote 154.66.198.148:39644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3Df7gAAYic"], referer: https://claysharecon.com/wp-login.php
[Mon Jul 20 06:09:23.281610 2026] [security2:error] [pid 832668:tid 832908] [client 50.116.65.227:54968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4P82ci6KgEEltqA3Df8gAAAGw"]
[Mon Jul 20 06:09:23.292321 2026] [security2:error] [pid 832668:tid 832927] [client 50.116.65.227:54976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4P82ci6KgEEltqA3Df8wAAAH8"]
[Mon Jul 20 06:09:23.419109 2026] [security2:error] [pid 832668:tid 832731] [remote 47.86.33.52:20528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3Df-gAAQDw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:23.486563 2026] [security2:error] [pid 832668:tid 832863] [client 103.153.183.69:3470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4P82ci6KgEEltqA3DgBAAAAD8"], referer: https://duckduckgo.com/?q=wre76
[Mon Jul 20 06:09:23.525599 2026] [security2:error] [pid 832668:tid 832691] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P82ci6KgEEltqA3DgBgAALhQ"]
[Mon Jul 20 06:09:23.525800 2026] [security2:error] [pid 832668:tid 832846] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P82ci6KgEEltqA3DgBgAALhQ"]
[Mon Jul 20 06:09:23.718901 2026] [security2:error] [pid 832668:tid 832697] [remote 100.42.189.89:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3DgGwAANBo"]
[Mon Jul 20 06:09:23.916245 2026] [security2:error] [pid 832668:tid 832768] [remote 100.42.189.89:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4P82ci6KgEEltqA3DgLwAAP2E"], referer: https://uninursity.com/wp-login.php
[Mon Jul 20 06:09:23.963778 2026] [security2:error] [pid 832668:tid 832849] [client 74.208.214.194:46506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4P82ci6KgEEltqA3DgNQAAADE"]
[Mon Jul 20 06:09:24.206419 2026] [security2:error] [pid 832668:tid 832920] [client 185.132.186.88:62541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4P9Gci6KgEEltqA3DgSgAAAHg"]
[Mon Jul 20 06:09:24.266478 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.6:49400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8Gci6KgEEltqA3DfAAAATjU"]
[Mon Jul 20 06:09:24.636364 2026] [security2:error] [pid 832668:tid 832810] [client 103.95.123.246:19766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P9Gci6KgEEltqA3DgZQAAAAo"]
[Mon Jul 20 06:09:24.636550 2026] [security2:error] [pid 832668:tid 832810] [client 103.95.123.246:19766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P9Gci6KgEEltqA3DgZQAAAAo"]
[Mon Jul 20 06:09:25.469988 2026] [security2:error] [pid 832668:tid 832813] [client 57.141.18.76:30334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8Wci6KgEEltqA3DfXwAADS8"]
[Mon Jul 20 06:09:26.158053 2026] [security2:error] [pid 832668:tid 832814] [client 185.132.186.88:62745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/class-core-upgrader-first.php"] [unique_id "al4P9mci6KgEEltqA3Dg3AAAAA4"]
[Mon Jul 20 06:09:26.471149 2026] [security2:error] [pid 832668:tid 832888] [client 103.77.203.233:58643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3Dg8wAAAFg"]
[Mon Jul 20 06:09:26.471427 2026] [security2:error] [pid 832668:tid 832888] [client 103.77.203.233:58643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3Dg8wAAAFg"]
[Mon Jul 20 06:09:26.837864 2026] [security2:error] [pid 832668:tid 832846] [client 5.161.194.92:44506] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4P9mci6KgEEltqA3Dg8AAAAC4"], referer: https://windowtx.com
[Mon Jul 20 06:09:26.838782 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:10201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3DhFwAAABg"]
[Mon Jul 20 06:09:26.838888 2026] [security2:error] [pid 832668:tid 832824] [client 86.98.90.58:10201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P9mci6KgEEltqA3DhFwAAABg"]
[Mon Jul 20 06:09:27.073301 2026] [security2:error] [pid 832668:tid 832818] [client 57.141.18.9:48908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8mci6KgEEltqA3DfwQAAEjM"]
[Mon Jul 20 06:09:27.088812 2026] [security2:error] [pid 832668:tid 832914] [client 57.141.18.52:38428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P8mci6KgEEltqA3DfwgAAcmI"]
[Mon Jul 20 06:09:27.376137 2026] [security2:error] [pid 832668:tid 832918] [client 103.141.108.143:52152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhOQAAAHY"]
[Mon Jul 20 06:09:27.376980 2026] [security2:error] [pid 832668:tid 832918] [client 103.141.108.143:52152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhOQAAAHY"]
[Mon Jul 20 06:09:27.622979 2026] [security2:error] [pid 832668:tid 832815] [client 57.141.18.44:50600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P82ci6KgEEltqA3Df6AAAD2o"]
[Mon Jul 20 06:09:27.956948 2026] [security2:error] [pid 832668:tid 832682] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhagAAMgs"]
[Mon Jul 20 06:09:27.957052 2026] [security2:error] [pid 832668:tid 832850] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P92ci6KgEEltqA3DhagAAMgs"]
[Mon Jul 20 06:09:28.106572 2026] [security2:error] [pid 832668:tid 832919] [client 115.246.21.170:26368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhdwAAAHc"]
[Mon Jul 20 06:09:28.106709 2026] [security2:error] [pid 832668:tid 832919] [client 115.246.21.170:26368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhdwAAAHc"]
[Mon Jul 20 06:09:28.108861 2026] [security2:error] [pid 832668:tid 832901] [client 185.132.186.55:22361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/wp-css.php"] [unique_id "al4P-Gci6KgEEltqA3DheAAAAGU"]
[Mon Jul 20 06:09:28.122836 2026] [security2:error] [pid 832668:tid 832810] [client 182.189.46.35:41927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4P-Gci6KgEEltqA3DhcgAAAAo"]
[Mon Jul 20 06:09:28.679418 2026] [security2:error] [pid 832668:tid 832864] [client 106.192.104.4:43648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhogAAAEA"]
[Mon Jul 20 06:09:28.679528 2026] [security2:error] [pid 832668:tid 832864] [client 106.192.104.4:43648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhogAAAEA"]
[Mon Jul 20 06:09:28.786437 2026] [security2:error] [pid 832668:tid 832870] [client 112.213.160.112:8523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhqwAAAEY"]
[Mon Jul 20 06:09:28.786537 2026] [security2:error] [pid 832668:tid 832870] [client 112.213.160.112:8523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Gci6KgEEltqA3DhqwAAAEY"]
[Mon Jul 20 06:09:29.089228 2026] [security2:error] [pid 832668:tid 832917] [client 57.141.18.111:24496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P9Gci6KgEEltqA3DgegAAdXI"]
[Mon Jul 20 06:09:29.221133 2026] [security2:error] [pid 832668:tid 832888] [client 45.116.69.230:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DhxwAAAFg"]
[Mon Jul 20 06:09:29.221232 2026] [security2:error] [pid 832668:tid 832888] [client 45.116.69.230:64601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DhxwAAAFg"]
[Mon Jul 20 06:09:29.361297 2026] [security2:error] [pid 832668:tid 832849] [client 181.224.94.124:47554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3Dh1QAAADE"]
[Mon Jul 20 06:09:29.361412 2026] [security2:error] [pid 832668:tid 832849] [client 181.224.94.124:47554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3Dh1QAAADE"]
[Mon Jul 20 06:09:29.393783 2026] [security2:error] [pid 832668:tid 832689] [remote 51.158.61.221:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh1gAAJBI"]
[Mon Jul 20 06:09:29.424681 2026] [security2:error] [pid 832668:tid 832694] [remote 217.61.143.92:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh2QAAHRc"]
[Mon Jul 20 06:09:29.591890 2026] [security2:error] [pid 832668:tid 832783] [remote 51.158.61.221:38676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh4AAAPHA"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 06:09:29.649454 2026] [security2:error] [pid 832668:tid 832766] [remote 217.61.143.92:47830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4P-Wci6KgEEltqA3Dh5QAADF8"], referer: https://thesoloceos.com/wp-login.php
[Mon Jul 20 06:09:29.941408 2026] [security2:error] [pid 832668:tid 832924] [client 41.173.37.102:11076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DiAAAAAHw"]
[Mon Jul 20 06:09:29.941565 2026] [security2:error] [pid 832668:tid 832924] [client 41.173.37.102:11076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4P-Wci6KgEEltqA3DiAAAAAHw"]
[Mon Jul 20 06:09:30.058322 2026] [security2:error] [pid 832668:tid 832849] [client 185.132.186.81:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/goto.php"] [unique_id "al4P-mci6KgEEltqA3DiCwAAADE"]
[Mon Jul 20 06:09:30.177492 2026] [security2:error] [pid 832668:tid 832767] [remote 216.73.216.55:37554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4P-mci6KgEEltqA3DiEQAAPmA"]
[Mon Jul 20 06:09:30.376373 2026] [security2:error] [pid 832668:tid 832868] [client 57.141.18.113:51540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P9mci6KgEEltqA3Dg2QAARAk"]
[Mon Jul 20 06:09:30.400228 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiKAAAAGo"]
[Mon Jul 20 06:09:30.400317 2026] [security2:error] [pid 832668:tid 832906] [client 178.152.178.232:37055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiKAAAAGo"]
[Mon Jul 20 06:09:30.496051 2026] [security2:error] [pid 832668:tid 832834] [client 103.153.183.69:64028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/passwd"] [unique_id "al4P-mci6KgEEltqA3DiLwAAACI"], referer: https://www.google.com/
[Mon Jul 20 06:09:30.523976 2026] [security2:error] [pid 832668:tid 832876] [client 103.153.183.69:64028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/shadow"] [unique_id "al4P-mci6KgEEltqA3DiMgAAAEw"], referer: https://twitter.com/
[Mon Jul 20 06:09:30.605833 2026] [security2:error] [pid 832668:tid 832838] [client 57.141.18.46:49176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P9mci6KgEEltqA3Dg7gAAJgM"]
[Mon Jul 20 06:09:30.644564 2026] [security2:error] [pid 832668:tid 832747] [remote 104.131.116.82:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4P-mci6KgEEltqA3DiNQAAYkw"]
[Mon Jul 20 06:09:30.752871 2026] [security2:error] [pid 832668:tid 832705] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiQQAAOyI"]
[Mon Jul 20 06:09:30.753108 2026] [security2:error] [pid 832668:tid 832859] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiQQAAOyI"]
[Mon Jul 20 06:09:30.856906 2026] [security2:error] [pid 832668:tid 832786] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiSwAAJHM"]
[Mon Jul 20 06:09:30.857130 2026] [security2:error] [pid 832668:tid 832836] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4P-mci6KgEEltqA3DiSwAAJHM"]
[Mon Jul 20 06:09:30.883458 2026] [security2:error] [pid 832668:tid 832722] [remote 104.131.116.82:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4P-mci6KgEEltqA3DiTgAAWjM"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:09:31.664969 2026] [security2:error] [pid 832668:tid 832816] [client 57.141.18.90:41418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P92ci6KgEEltqA3DhMwAAEAc"]
[Mon Jul 20 06:09:31.669051 2026] [security2:error] [pid 832668:tid 832914] [client 103.153.183.69:64028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/hosts"] [unique_id "al4P-2ci6KgEEltqA3DiiwAAAHI"], referer: https://duckduckgo.com/?q=soo1z
[Mon Jul 20 06:09:31.716725 2026] [security2:error] [pid 832668:tid 832819] [client 103.153.183.69:64028] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//....//proc/self/environ"] [unique_id "al4P-2ci6KgEEltqA3DikAAAABM"], referer: https://twitter.com/
[Mon Jul 20 06:09:31.824071 2026] [security2:error] [pid 832668:tid 832922] [client 50.116.65.227:52166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4P-2ci6KgEEltqA3DilwAAAHo"]
[Mon Jul 20 06:09:31.835408 2026] [security2:error] [pid 832668:tid 832866] [client 50.116.65.227:52178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4P-2ci6KgEEltqA3DimAAAAEI"]
[Mon Jul 20 06:09:31.976476 2026] [security2:error] [pid 832668:tid 832871] [client 185.132.186.72:27071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/xboom.php"] [unique_id "al4P-2ci6KgEEltqA3DioAAAAEc"]
[Mon Jul 20 06:09:32.345465 2026] [security2:error] [pid 832668:tid 832826] [client 164.100.212.184:64043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Gci6KgEEltqA3DivQAAABo"]
[Mon Jul 20 06:09:32.345590 2026] [security2:error] [pid 832668:tid 832826] [client 164.100.212.184:64043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Gci6KgEEltqA3DivQAAABo"]
[Mon Jul 20 06:09:32.472927 2026] [security2:error] [pid 832668:tid 832910] [client 14.225.17.146:63818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4P_Gci6KgEEltqA3DitgAAAG4"], referer: http://inspirespublishing.com/WORDPRESS
[Mon Jul 20 06:09:32.488953 2026] [security2:error] [pid 832668:tid 832858] [client 57.141.18.27:42202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P92ci6KgEEltqA3DhZwAAOlM"]
[Mon Jul 20 06:09:32.570813 2026] [security2:error] [pid 832668:tid 832869] [client 192.236.168.43:55216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.tntcatholic.com"] [uri "/"] [unique_id "al4P_Gci6KgEEltqA3Di0wAAAEU"]
[Mon Jul 20 06:09:33.059381 2026] [security2:error] [pid 832668:tid 832896] [client 57.141.18.15:41554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P-Gci6KgEEltqA3DhjgAAYFY"]
[Mon Jul 20 06:09:33.073571 2026] [security2:error] [pid 832668:tid 832872] [client 74.208.214.194:46624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4P_Wci6KgEEltqA3Di_gAAAEg"]
[Mon Jul 20 06:09:33.692040 2026] [security2:error] [pid 832668:tid 832760] [remote 188.166.241.141:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P_Wci6KgEEltqA3DjMQAAH1k"]
[Mon Jul 20 06:09:33.892801 2026] [security2:error] [pid 832668:tid 832861] [client 27.96.94.195:37615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Wci6KgEEltqA3DjPgAAAD0"]
[Mon Jul 20 06:09:33.892913 2026] [security2:error] [pid 832668:tid 832861] [client 27.96.94.195:37615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4P_Wci6KgEEltqA3DjPgAAAD0"]
[Mon Jul 20 06:09:33.937594 2026] [security2:error] [pid 832668:tid 832890] [client 185.132.186.70:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "al4P_Wci6KgEEltqA3DjQAAAAFo"]
[Mon Jul 20 06:09:34.001227 2026] [security2:error] [pid 832668:tid 832849] [client 14.225.17.146:49860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P_Wci6KgEEltqA3DjOQAAADE"], referer: http://sesamegreenbeans.com/WORDPRESS
[Mon Jul 20 06:09:34.031692 2026] [security2:error] [pid 832668:tid 832903] [client 57.141.18.65:26928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P-Wci6KgEEltqA3Dh2gAAZy8"]
[Mon Jul 20 06:09:34.086129 2026] [security2:error] [pid 832668:tid 832709] [remote 188.166.241.141:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4P_mci6KgEEltqA3DjUgAALSY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:09:34.100870 2026] [security2:error] [pid 832668:tid 832675] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P_mci6KgEEltqA3DjUwAAVgQ"]
[Mon Jul 20 06:09:34.100998 2026] [security2:error] [pid 832668:tid 832886] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4P_mci6KgEEltqA3DjUwAAVgQ"]
[Mon Jul 20 06:09:34.644856 2026] [security2:error] [pid 832668:tid 832903] [client 94.154.43.186:24594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "samueldcohen.com"] [uri "/.env"] [unique_id "al4P_mci6KgEEltqA3DjeAAAAGc"]
[Mon Jul 20 06:09:35.008979 2026] [security2:error] [pid 832668:tid 832862] [client 14.225.17.146:53391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4P_mci6KgEEltqA3DjiAAAAD4"], referer: https://sesamegreenbeans.com/WORDPRESS
[Mon Jul 20 06:09:35.523796 2026] [security2:error] [pid 832668:tid 832914] [client 103.153.183.69:12042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../home/ubuntu/.ssh/id_rsa"] [unique_id "al4P_2ci6KgEEltqA3DjwgAAAHI"], referer: https://www.google.com/search?q=z3ycm4
[Mon Jul 20 06:09:35.572981 2026] [security2:error] [pid 832668:tid 832890] [client 14.225.17.146:56553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4P_2ci6KgEEltqA3DjuQAAAFo"], referer: http://talknutritionwithlesley.com/WORDPRESS
[Mon Jul 20 06:09:35.731668 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:20252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P_2ci6KgEEltqA3Dj0wAAAGM"]
[Mon Jul 20 06:09:35.731788 2026] [security2:error] [pid 832668:tid 832899] [client 103.95.123.246:20252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4P_2ci6KgEEltqA3Dj0wAAAGM"]
[Mon Jul 20 06:09:35.889786 2026] [security2:error] [pid 832668:tid 832877] [client 185.132.186.93:44297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/Sanskrit.php"] [unique_id "al4P_2ci6KgEEltqA3Dj4QAAAE0"]
[Mon Jul 20 06:09:36.162529 2026] [security2:error] [pid 832668:tid 832690] [remote 152.228.213.32:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QAGci6KgEEltqA3Dj8wAAfhM"]
[Mon Jul 20 06:09:36.217396 2026] [security2:error] [pid 832668:tid 832901] [client 14.225.17.146:64476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4QAGci6KgEEltqA3Dj9AAAAGU"], referer: http://techtradeinc.com/WORDPRESS
[Mon Jul 20 06:09:36.289249 2026] [security2:error] [pid 832668:tid 832789] [remote 157.180.59.124:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.59.180.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3Dj_QAAFHY"]
[Mon Jul 20 06:09:36.289496 2026] [security2:error] [pid 832668:tid 832820] [client 157.180.59.124:59044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3Dj_QAAFHY"]
[Mon Jul 20 06:09:36.346800 2026] [security2:error] [pid 832668:tid 832801] [client 57.141.18.13:63352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P-2ci6KgEEltqA3DihwAAATY"]
[Mon Jul 20 06:09:36.384441 2026] [security2:error] [pid 832668:tid 832729] [remote 152.228.213.32:42658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QAGci6KgEEltqA3DkCAAAZzo"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:09:36.776858 2026] [security2:error] [pid 832668:tid 832904] [client 57.141.18.58:35286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_Gci6KgEEltqA3DirgAAaEE"]
[Mon Jul 20 06:09:36.808194 2026] [security2:error] [pid 832668:tid 832802] [client 14.225.17.146:59321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4P_2ci6KgEEltqA3DjzAAAAAI"], referer: http://mourgroup.com/WORDPRESS
[Mon Jul 20 06:09:36.934303 2026] [security2:error] [pid 832668:tid 832909] [client 103.77.203.233:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3DkMwAAAG0"]
[Mon Jul 20 06:09:36.934433 2026] [security2:error] [pid 832668:tid 832909] [client 103.77.203.233:59371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QAGci6KgEEltqA3DkMwAAAG0"]
[Mon Jul 20 06:09:37.394823 2026] [security2:error] [pid 832668:tid 832836] [client 57.141.18.64:36610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_Gci6KgEEltqA3Di4wAAJDU"]
[Mon Jul 20 06:09:37.409985 2026] [security2:error] [pid 832668:tid 832883] [client 145.239.10.137:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "howtoacecollegeandmasterlife.com"] [uri "/vb_cache.php"] [unique_id "al4QAWci6KgEEltqA3DkWQAAAFM"], referer: http://howtoacecollegeandmasterlife.com/vb_cache.php
[Mon Jul 20 06:09:37.763228 2026] [security2:error] [pid 832668:tid 832805] [client 182.189.46.35:33028] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ccsdifference.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al4QAWci6KgEEltqA3DkbwAAAAU"]
[Mon Jul 20 06:09:37.817732 2026] [security2:error] [pid 832668:tid 832843] [client 86.98.90.58:11029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAWci6KgEEltqA3DkcwAAACs"]
[Mon Jul 20 06:09:37.817868 2026] [security2:error] [pid 832668:tid 832843] [client 86.98.90.58:11029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAWci6KgEEltqA3DkcwAAACs"]
[Mon Jul 20 06:09:37.834373 2026] [security2:error] [pid 832668:tid 832829] [client 185.132.186.73:51981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-fmfile.php"] [unique_id "al4QAWci6KgEEltqA3DkdAAAAB0"]
[Mon Jul 20 06:09:38.167843 2026] [security2:error] [pid 832668:tid 832876] [client 57.141.18.29:59796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_Wci6KgEEltqA3DjHwAATDk"]
[Mon Jul 20 06:09:38.241475 2026] [security2:error] [pid 832668:tid 832927] [client 103.141.108.143:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkkAAAAH8"]
[Mon Jul 20 06:09:38.241679 2026] [security2:error] [pid 832668:tid 832927] [client 103.141.108.143:52601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkkAAAAH8"]
[Mon Jul 20 06:09:38.687070 2026] [security2:error] [pid 832668:tid 832816] [client 50.116.65.227:12760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4QAmci6KgEEltqA3DkuAAAABA"]
[Mon Jul 20 06:09:38.698691 2026] [security2:error] [pid 832668:tid 832801] [client 50.116.65.227:52252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4QAmci6KgEEltqA3DkugAAAAE"]
[Mon Jul 20 06:09:38.737052 2026] [security2:error] [pid 832668:tid 832822] [client 115.246.21.170:37965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkvgAAABY"]
[Mon Jul 20 06:09:38.738635 2026] [security2:error] [pid 832668:tid 832822] [client 115.246.21.170:37965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QAmci6KgEEltqA3DkvgAAABY"]
[Mon Jul 20 06:09:38.876556 2026] [security2:error] [pid 832668:tid 832848] [client 14.225.17.146:52888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4QAmci6KgEEltqA3DktwAAADA"], referer: http://thesoloceos.com/WORDPRESS
[Mon Jul 20 06:09:39.066890 2026] [security2:error] [pid 832668:tid 832827] [client 57.141.18.114:26780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_mci6KgEEltqA3DjcgAAG20"]
[Mon Jul 20 06:09:39.172909 2026] [security2:error] [pid 832668:tid 832693] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk2QAAHxY"]
[Mon Jul 20 06:09:39.173169 2026] [security2:error] [pid 832668:tid 832831] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk2QAAHxY"]
[Mon Jul 20 06:09:39.178888 2026] [security2:error] [pid 832668:tid 832910] [client 143.110.169.139:54900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4QAmci6KgEEltqA3DkygAAAG4"], referer: https://hilltopnurseryinc.com/
[Mon Jul 20 06:09:39.197543 2026] [security2:error] [pid 832668:tid 832913] [client 14.225.17.146:62956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4QAWci6KgEEltqA3DkOQAAAHE"], referer: http://younutrition.gr/WORDPRESS
[Mon Jul 20 06:09:39.284127 2026] [security2:error] [pid 832668:tid 832712] [remote 57.141.18.33:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4QA2ci6KgEEltqA3Dk5QAAeyk"]
[Mon Jul 20 06:09:39.352906 2026] [security2:error] [pid 832668:tid 832875] [client 14.225.17.146:61004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4QA2ci6KgEEltqA3Dk3AAAAEs"], referer: http://ghivs.com/WORDPRESS
[Mon Jul 20 06:09:39.380989 2026] [security2:error] [pid 832668:tid 832902] [client 57.141.18.53:58714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4P_mci6KgEEltqA3DjmAAAZi0"]
[Mon Jul 20 06:09:39.475281 2026] [security2:error] [pid 832668:tid 832904] [client 112.213.160.112:8419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk9QAAAGg"]
[Mon Jul 20 06:09:39.475381 2026] [security2:error] [pid 832668:tid 832904] [client 112.213.160.112:8419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3Dk9QAAAGg"]
[Mon Jul 20 06:09:39.535653 2026] [security2:error] [pid 832668:tid 832817] [client 45.157.112.60:21593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QA2ci6KgEEltqA3Dk-gAAABE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:39.715881 2026] [security2:error] [pid 832668:tid 832900] [client 113.161.215.49:32996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4QA2ci6KgEEltqA3DlAQAAAGQ"], referer: https://thewelloiledlife.com/
[Mon Jul 20 06:09:39.778115 2026] [security2:error] [pid 832668:tid 832918] [client 106.192.104.4:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlFwAAAHY"]
[Mon Jul 20 06:09:39.778224 2026] [security2:error] [pid 832668:tid 832918] [client 106.192.104.4:56556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlFwAAAHY"]
[Mon Jul 20 06:09:39.792264 2026] [security2:error] [pid 832668:tid 832898] [client 35.90.38.209:11686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlFAAAAGI"]
[Mon Jul 20 06:09:39.888721 2026] [security2:error] [pid 832668:tid 832848] [client 14.225.17.146:62146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4QA2ci6KgEEltqA3DlDwAAADA"], referer: https://thesoloceos.com/WORDPRESS
[Mon Jul 20 06:09:39.911103 2026] [security2:error] [pid 832668:tid 832897] [client 45.116.69.230:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIQAAAGE"]
[Mon Jul 20 06:09:39.911201 2026] [security2:error] [pid 832668:tid 832897] [client 45.116.69.230:65080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIQAAAGE"]
[Mon Jul 20 06:09:39.921146 2026] [security2:error] [pid 832668:tid 832865] [client 181.224.94.124:8758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIwAAAEE"]
[Mon Jul 20 06:09:39.921255 2026] [security2:error] [pid 832668:tid 832865] [client 181.224.94.124:8758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QA2ci6KgEEltqA3DlIwAAAEE"]
[Mon Jul 20 06:09:40.089981 2026] [security2:error] [pid 832668:tid 832813] [client 182.189.46.35:33030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QA2ci6KgEEltqA3DlDgAAAA0"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:40.507286 2026] [security2:error] [pid 832668:tid 832815] [client 74.7.227.179:49448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QBGci6KgEEltqA3DlPgAAD3Y"], referer: https://tejasenvironmental.com/p=3328864
[Mon Jul 20 06:09:40.554783 2026] [security2:error] [pid 832668:tid 832831] [client 41.173.37.102:11527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QBGci6KgEEltqA3DlSgAAAB8"]
[Mon Jul 20 06:09:40.554915 2026] [security2:error] [pid 832668:tid 832831] [client 41.173.37.102:11527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QBGci6KgEEltqA3DlSgAAAB8"]
[Mon Jul 20 06:09:40.981194 2026] [security2:error] [pid 832668:tid 832838] [client 35.90.38.209:11700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4QBGci6KgEEltqA3DldAAAACY"]
[Mon Jul 20 06:09:41.276431 2026] [security2:error] [pid 832668:tid 832785] [remote 188.40.28.4:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QBWci6KgEEltqA3DliQAAD3I"]
[Mon Jul 20 06:09:41.338048 2026] [security2:error] [pid 832668:tid 832882] [client 185.132.186.100:52759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.trash7309/index.php"] [unique_id "al4QBWci6KgEEltqA3DlkAAAAFI"]
[Mon Jul 20 06:09:41.437995 2026] [security2:error] [pid 832668:tid 832791] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmgAAVXg"]
[Mon Jul 20 06:09:41.438179 2026] [security2:error] [pid 832668:tid 832885] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmgAAVXg"]
[Mon Jul 20 06:09:41.447209 2026] [security2:error] [pid 832668:tid 832753] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmwAARVI"]
[Mon Jul 20 06:09:41.447362 2026] [security2:error] [pid 832668:tid 832869] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QBWci6KgEEltqA3DlmwAARVI"]
[Mon Jul 20 06:09:41.486114 2026] [security2:error] [pid 832668:tid 832778] [remote 188.40.28.4:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QBWci6KgEEltqA3DlngAAWWs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:41.500392 2026] [security2:error] [pid 832668:tid 832849] [client 173.239.224.21:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "partnerselectricalllc.com"] [uri "/wp-login.php"] [unique_id "al4QBWci6KgEEltqA3DlnAAAADE"]
[Mon Jul 20 06:09:41.607620 2026] [security2:error] [pid 832668:tid 832888] [client 57.141.18.121:35194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QAWci6KgEEltqA3DkYAAAWHw"]
[Mon Jul 20 06:09:41.818278 2026] [security2:error] [pid 832668:tid 832819] [client 44.245.170.32:11612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4QBWci6KgEEltqA3DlswAAABM"]
[Mon Jul 20 06:09:42.353125 2026] [security2:error] [pid 832668:tid 832862] [client 35.90.38.209:47682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4QBmci6KgEEltqA3Dl1gAAAD4"]
[Mon Jul 20 06:09:42.572482 2026] [security2:error] [pid 832668:tid 832858] [client 50.116.65.227:22780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QBmci6KgEEltqA3Dl6gAAADo"]
[Mon Jul 20 06:09:42.582993 2026] [security2:error] [pid 832668:tid 832861] [client 50.116.65.227:22784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QBmci6KgEEltqA3Dl6wAAAD0"]
[Mon Jul 20 06:09:42.616056 2026] [security2:error] [pid 832668:tid 832893] [client 57.141.18.20:24962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QAmci6KgEEltqA3DkrAAAXW8"]
[Mon Jul 20 06:09:42.745683 2026] [core:error] [pid 832668:tid 832911] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:42.745709 2026] [core:error] [pid 832668:tid 832911] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:09:42.936959 2026] [security2:error] [pid 832668:tid 832836] [client 164.100.212.184:64634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QBmci6KgEEltqA3DmCwAAACQ"]
[Mon Jul 20 06:09:42.937085 2026] [security2:error] [pid 832668:tid 832836] [client 164.100.212.184:64634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QBmci6KgEEltqA3DmCwAAACQ"]
[Mon Jul 20 06:09:42.942864 2026] [security2:error] [pid 832668:tid 832825] [client 44.245.170.32:11618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4QBmci6KgEEltqA3DmDQAAABk"]
[Mon Jul 20 06:09:43.069288 2026] [security2:error] [pid 832668:tid 832818] [client 14.225.17.146:50787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4QBWci6KgEEltqA3DlpQAAABI"], referer: http://guidehunting.com/WORDPRESS
[Mon Jul 20 06:09:43.095700 2026] [security2:error] [pid 832668:tid 832826] [client 182.189.46.35:33032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QBmci6KgEEltqA3DmCgAAABo"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:43.286488 2026] [security2:error] [pid 832668:tid 832870] [client 185.132.186.54:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmKwAAAEY"]
[Mon Jul 20 06:09:43.493519 2026] [security2:error] [pid 832668:tid 832886] [client 44.245.170.32:11620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4QB2ci6KgEEltqA3DmQAAAAFY"]
[Mon Jul 20 06:09:43.534143 2026] [security2:error] [pid 832668:tid 832698] [remote 217.61.143.92:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4QB2ci6KgEEltqA3DmRQAAVBs"]
[Mon Jul 20 06:09:43.597303 2026] [security2:error] [pid 832668:tid 832738] [remote 57.141.18.58:23700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4409190"] [unique_id "al4QB2ci6KgEEltqA3DmSgAAWUM"]
[Mon Jul 20 06:09:43.845922 2026] [security2:error] [pid 832668:tid 832787] [remote 217.61.143.92:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4QB2ci6KgEEltqA3DmYgAAIHQ"], referer: https://file.learnthissecret.com/wp-login.php
[Mon Jul 20 06:09:44.011512 2026] [security2:error] [pid 832668:tid 832919] [client 57.141.18.35:57514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBGci6KgEEltqA3DlJwAAdx8"]
[Mon Jul 20 06:09:44.126991 2026] [security2:error] [pid 832668:tid 832874] [client 14.225.17.146:49272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmZAAAAEo"], referer: https://guidehunting.com/WORDPRESS
[Mon Jul 20 06:09:44.190633 2026] [security2:error] [pid 832668:tid 832861] [client 14.232.238.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmaQAAAD0"]
[Mon Jul 20 06:09:44.297260 2026] [security2:error] [pid 832668:tid 832802] [client 44.245.170.32:11628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4QCGci6KgEEltqA3DmfwAAAAI"]
[Mon Jul 20 06:09:44.465605 2026] [security2:error] [pid 832668:tid 832672] [remote 47.86.33.52:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4QCGci6KgEEltqA3DmkQAATwE"]
[Mon Jul 20 06:09:44.613463 2026] [security2:error] [pid 832668:tid 832754] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QCGci6KgEEltqA3DmnQAAGVM"]
[Mon Jul 20 06:09:44.613660 2026] [security2:error] [pid 832668:tid 832825] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QCGci6KgEEltqA3DmnQAAGVM"]
[Mon Jul 20 06:09:44.771493 2026] [security2:error] [pid 832668:tid 832891] [client 57.141.18.80:49664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBGci6KgEEltqA3DlZwAAWwY"]
[Mon Jul 20 06:09:45.170975 2026] [security2:error] [pid 832668:tid 832791] [remote 47.86.33.52:17720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4QCWci6KgEEltqA3DmxwAAV3g"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:09:45.234222 2026] [security2:error] [pid 832668:tid 832891] [client 185.132.186.89:49811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ioxi/ioxi/dropdown.php"] [unique_id "al4QCWci6KgEEltqA3DmzAAAAFs"]
[Mon Jul 20 06:09:45.265610 2026] [security2:error] [pid 832668:tid 832900] [client 104.168.114.154:45064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "tntcatholic.com"] [uri "/"] [unique_id "al4QCWci6KgEEltqA3Dm0QAAAGQ"]
[Mon Jul 20 06:09:45.469636 2026] [security2:error] [pid 832668:tid 832845] [client 182.189.46.35:33034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QCWci6KgEEltqA3Dm0wAAAC0"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:45.715937 2026] [security2:error] [pid 832668:tid 832926] [client 104.234.53.54:41525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QCWci6KgEEltqA3Dm_AAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:45.778504 2026] [security2:error] [pid 832668:tid 832914] [client 57.141.18.9:46556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBWci6KgEEltqA3DltQAAcno"]
[Mon Jul 20 06:09:45.783888 2026] [security2:error] [pid 832668:tid 832878] [client 57.141.18.58:20494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBWci6KgEEltqA3DluwAATkY"]
[Mon Jul 20 06:09:45.933901 2026] [security2:error] [pid 832668:tid 832831] [client 57.141.18.87:36004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QBmci6KgEEltqA3DlvwAAHzk"]
[Mon Jul 20 06:09:46.462720 2026] [security2:error] [pid 832668:tid 832919] [client 14.225.17.146:50001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4QCWci6KgEEltqA3Dm8gAAAHc"], referer: http://kromosenergy.com/WORDPRESS
[Mon Jul 20 06:09:46.770521 2026] [security2:error] [pid 832668:tid 832835] [client 14.225.17.146:50128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnVAAAACM"], referer: http://keywayconstructionclt.com/WORDPRESS
[Mon Jul 20 06:09:47.248245 2026] [security2:error] [pid 832668:tid 832926] [client 192.236.168.43:58734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.tntcatholic.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnhQAAAH4"]
[Mon Jul 20 06:09:47.274465 2026] [security2:error] [pid 832668:tid 832823] [client 103.95.123.246:20763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnigAAABc"]
[Mon Jul 20 06:09:47.274575 2026] [security2:error] [pid 832668:tid 832823] [client 103.95.123.246:20763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnigAAABc"]
[Mon Jul 20 06:09:47.300351 2026] [security2:error] [pid 832668:tid 832920] [client 104.168.114.154:45580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.website-66dd6fc3.nextlvlmarketingco.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnjQAAAHg"]
[Mon Jul 20 06:09:47.428209 2026] [security2:error] [pid 832668:tid 832845] [client 192.236.168.43:58794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-66dd6fc3.nextlvlmarketingco.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnlwAAAC0"]
[Mon Jul 20 06:09:47.492233 2026] [security2:error] [pid 832668:tid 832899] [client 57.141.18.112:26820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QB2ci6KgEEltqA3DmVwAAYz4"]
[Mon Jul 20 06:09:47.528927 2026] [security2:error] [pid 832668:tid 832894] [client 103.77.203.233:59911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnngAAAF4"]
[Mon Jul 20 06:09:47.529067 2026] [security2:error] [pid 832668:tid 832894] [client 103.77.203.233:59911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QC2ci6KgEEltqA3DnngAAAF4"]
[Mon Jul 20 06:09:47.643468 2026] [security2:error] [pid 832668:tid 832917] [client 192.236.168.43:58838] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.poopscoopuniversity.com"] [uri "/"] [unique_id "al4QC2ci6KgEEltqA3DnpQAAAHU"]
[Mon Jul 20 06:09:47.645545 2026] [security2:error] [pid 832668:tid 832831] [client 14.225.17.146:59545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4QC2ci6KgEEltqA3DnogAAAB8"], referer: https://keywayconstructionclt.com/WORDPRESS
[Mon Jul 20 06:09:47.693668 2026] [security2:error] [pid 832668:tid 832916] [client 14.225.17.146:53716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnJwAAAHQ"], referer: http://colinkeyphotography.com/WORDPRESS
[Mon Jul 20 06:09:47.700467 2026] [security2:error] [pid 832668:tid 832876] [client 104.234.53.74:52323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QC2ci6KgEEltqA3DnqQAAAEw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:47.741082 2026] [security2:error] [pid 832668:tid 832801] [client 185.132.186.67:63473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/memberfuns.php"] [unique_id "al4QC2ci6KgEEltqA3DnsQAAAAE"]
[Mon Jul 20 06:09:47.762085 2026] [security2:error] [pid 832668:tid 832874] [client 14.225.17.146:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnMwAAAEo"], referer: http://hammadownenterprises.com/WORDPRESS
[Mon Jul 20 06:09:47.798516 2026] [security2:error] [pid 832668:tid 832924] [client 158.173.89.95:35067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QC2ci6KgEEltqA3DnugAAAHw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:09:48.006594 2026] [security2:error] [pid 832668:tid 832887] [client 182.189.46.35:33035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QC2ci6KgEEltqA3DnuwAAAFc"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:48.262879 2026] [security2:error] [pid 832668:tid 832847] [client 14.225.17.146:50113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnUwAAAC8"], referer: http://careysheatingandcooling.com/WORDPRESS
[Mon Jul 20 06:09:48.900635 2026] [security2:error] [pid 832668:tid 832920] [client 103.141.108.143:53060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDGci6KgEEltqA3DoGgAAAHg"]
[Mon Jul 20 06:09:48.901230 2026] [security2:error] [pid 832668:tid 832920] [client 103.141.108.143:53060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDGci6KgEEltqA3DoGgAAAHg"]
[Mon Jul 20 06:09:48.933866 2026] [security2:error] [pid 832668:tid 832818] [client 14.225.17.146:49717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4QDGci6KgEEltqA3Dn-gAAABI"], referer: http://securingmemories.com/WORDPRESS
[Mon Jul 20 06:09:49.051236 2026] [security2:error] [pid 832668:tid 832893] [client 57.141.18.63:45348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QCWci6KgEEltqA3Dm9wAAXS8"]
[Mon Jul 20 06:09:49.216063 2026] [security2:error] [pid 832668:tid 832811] [client 14.225.17.146:59588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4QDWci6KgEEltqA3DoIwAAAAs"], referer: http://goyalsatyam.com/WORDPRESS
[Mon Jul 20 06:09:49.425118 2026] [security2:error] [pid 832668:tid 832883] [client 115.246.21.170:21310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoPgAAAFM"]
[Mon Jul 20 06:09:49.425205 2026] [security2:error] [pid 832668:tid 832883] [client 115.246.21.170:21310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoPgAAAFM"]
[Mon Jul 20 06:09:49.451137 2026] [security2:error] [pid 832668:tid 832810] [client 86.98.90.58:11726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoQAAAAAo"]
[Mon Jul 20 06:09:49.451362 2026] [security2:error] [pid 832668:tid 832810] [client 86.98.90.58:11726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoQAAAAAo"]
[Mon Jul 20 06:09:49.698990 2026] [security2:error] [pid 832668:tid 832809] [client 185.132.186.83:44831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/infos.php"] [unique_id "al4QDWci6KgEEltqA3DoTgAAAAk"]
[Mon Jul 20 06:09:49.788770 2026] [security2:error] [pid 832668:tid 832709] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoWAAAJiY"]
[Mon Jul 20 06:09:49.788923 2026] [security2:error] [pid 832668:tid 832838] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QDWci6KgEEltqA3DoWAAAJiY"]
[Mon Jul 20 06:09:49.878275 2026] [security2:error] [pid 832668:tid 832839] [client 57.141.18.122:50920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QCmci6KgEEltqA3DnUAAAJyI"]
[Mon Jul 20 06:09:49.933270 2026] [security2:error] [pid 832668:tid 832828] [client 104.234.53.66:50353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QDWci6KgEEltqA3DoYwAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:50.168467 2026] [security2:error] [pid 832668:tid 832801] [client 112.213.160.112:30983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DodgAAAAE"]
[Mon Jul 20 06:09:50.168611 2026] [security2:error] [pid 832668:tid 832801] [client 112.213.160.112:30983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DodgAAAAE"]
[Mon Jul 20 06:09:50.385869 2026] [security2:error] [pid 832668:tid 832891] [client 14.225.17.146:60254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DodAAAAFs"], referer: http://recruitinginsight.us/WORDPRESS
[Mon Jul 20 06:09:50.403578 2026] [security2:error] [pid 832668:tid 832827] [client 14.225.17.146:58708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DoiQAAABs"], referer: http://friendlyspreadsheet.com/WORDPRESS
[Mon Jul 20 06:09:50.432518 2026] [security2:error] [pid 832668:tid 832871] [client 181.224.94.124:65176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DokAAAAEc"]
[Mon Jul 20 06:09:50.432637 2026] [security2:error] [pid 832668:tid 832871] [client 181.224.94.124:65176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DokAAAAEc"]
[Mon Jul 20 06:09:50.459360 2026] [security2:error] [pid 832668:tid 832898] [client 14.225.17.146:60249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DocwAAAGI"], referer: http://webgardensbypaula.com/WORDPRESS
[Mon Jul 20 06:09:50.552721 2026] [security2:error] [pid 832668:tid 832925] [client 45.116.69.230:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DolwAAAH0"]
[Mon Jul 20 06:09:50.552851 2026] [security2:error] [pid 832668:tid 832925] [client 45.116.69.230:49173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QDmci6KgEEltqA3DolwAAAH0"]
[Mon Jul 20 06:09:50.733175 2026] [security2:error] [pid 832668:tid 832707] [remote 162.19.86.63:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QDmci6KgEEltqA3DopgAAVCQ"]
[Mon Jul 20 06:09:50.775217 2026] [security2:error] [pid 832668:tid 832804] [client 14.225.17.146:58393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DonQAAAAQ"], referer: http://nextlvlmarketingco.com/WORDPRESS
[Mon Jul 20 06:09:50.923821 2026] [proxy:error] [pid 832668:tid 832846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:50.923862 2026] [proxy_http:error] [pid 832668:tid 832846] [client 8.229.28.226:47808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:50.924553 2026] [proxy:error] [pid 832668:tid 832846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:50.924582 2026] [proxy_http:error] [pid 832668:tid 832846] [client 8.229.28.226:47808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:50.941973 2026] [security2:error] [pid 832668:tid 832781] [remote 162.19.86.63:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QDmci6KgEEltqA3DowQAAF24"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:09:51.056341 2026] [security2:error] [pid 832668:tid 832819] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DotwAAABM"]
[Mon Jul 20 06:09:51.167854 2026] [security2:error] [pid 832668:tid 832710] [remote 110.249.201.119:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2021/11/final-letter-congressional-districts-plan-submission.pdf"] [unique_id "al4QD2ci6KgEEltqA3Do1AAAZyc"]
[Mon Jul 20 06:09:51.190426 2026] [security2:error] [pid 832668:tid 832920] [client 41.173.37.102:11968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do2QAAAHg"]
[Mon Jul 20 06:09:51.190528 2026] [security2:error] [pid 832668:tid 832920] [client 41.173.37.102:11968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do2QAAAHg"]
[Mon Jul 20 06:09:51.223384 2026] [security2:error] [pid 832668:tid 832917] [client 104.234.53.66:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QD2ci6KgEEltqA3Do1gAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:51.357827 2026] [security2:error] [pid 832668:tid 832808] [client 14.225.17.146:59439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4QD2ci6KgEEltqA3Do4gAAAAg"], referer: https://friendlyspreadsheet.com/WORDPRESS
[Mon Jul 20 06:09:51.646958 2026] [security2:error] [pid 832668:tid 832894] [client 185.132.186.64:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/modules/file.php"] [unique_id "al4QD2ci6KgEEltqA3Do-QAAAF4"]
[Mon Jul 20 06:09:51.769041 2026] [security2:error] [pid 832668:tid 832842] [client 106.192.104.4:57060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do_gAAACo"]
[Mon Jul 20 06:09:51.769187 2026] [security2:error] [pid 832668:tid 832842] [client 106.192.104.4:57060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QD2ci6KgEEltqA3Do_gAAACo"]
[Mon Jul 20 06:09:51.891593 2026] [security2:error] [pid 832668:tid 832678] [remote 124.55.178.99:43064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QD2ci6KgEEltqA3DpEAAARwc"]
[Mon Jul 20 06:09:52.067543 2026] [security2:error] [pid 832668:tid 832754] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpIwAAQVM"]
[Mon Jul 20 06:09:52.067796 2026] [security2:error] [pid 832668:tid 832865] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpIwAAQVM"]
[Mon Jul 20 06:09:52.200664 2026] [security2:error] [pid 832668:tid 832682] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpMgAAOgs"]
[Mon Jul 20 06:09:52.200907 2026] [security2:error] [pid 832668:tid 832858] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QEGci6KgEEltqA3DpMgAAOgs"]
[Mon Jul 20 06:09:52.203867 2026] [security2:error] [pid 832668:tid 832872] [client 57.141.18.71:54116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QDGci6KgEEltqA3DoAgAASHc"]
[Mon Jul 20 06:09:52.353056 2026] [security2:error] [pid 832668:tid 832676] [remote 124.55.178.99:43064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QEGci6KgEEltqA3DpPgAARwU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:52.545470 2026] [security2:error] [pid 832668:tid 832865] [client 50.116.65.227:52632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QEGci6KgEEltqA3DpTQAAAEE"]
[Mon Jul 20 06:09:52.559001 2026] [security2:error] [pid 832668:tid 832821] [client 50.116.65.227:52646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QEGci6KgEEltqA3DpTgAAABU"]
[Mon Jul 20 06:09:52.585539 2026] [security2:error] [pid 832668:tid 832840] [client 14.225.17.146:53632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4QD2ci6KgEEltqA3Do5wAAACg"]
[Mon Jul 20 06:09:53.476007 2026] [security2:error] [pid 832668:tid 832823] [client 182.189.46.35:33038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QEWci6KgEEltqA3DpigAAABc"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:53.522554 2026] [security2:error] [pid 832668:tid 832903] [client 164.100.212.184:59248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QEWci6KgEEltqA3DplAAAAGc"]
[Mon Jul 20 06:09:53.522688 2026] [security2:error] [pid 832668:tid 832903] [client 164.100.212.184:59248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QEWci6KgEEltqA3DplAAAAGc"]
[Mon Jul 20 06:09:53.596003 2026] [security2:error] [pid 832668:tid 832844] [client 57.141.18.84:53690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DoeQAALGg"]
[Mon Jul 20 06:09:53.614996 2026] [security2:error] [pid 832668:tid 832809] [client 185.132.186.80:32101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/x.php"] [unique_id "al4QEWci6KgEEltqA3DpmQAAAAk"]
[Mon Jul 20 06:09:53.652709 2026] [security2:error] [pid 832668:tid 832860] [client 47.128.56.199:15304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "theshakespeareconspiracy.com"] [uri "/robots.txt"] [unique_id "al4QEWci6KgEEltqA3DpnAAAADw"]
[Mon Jul 20 06:09:53.862001 2026] [security2:error] [pid 832668:tid 832745] [remote 57.141.18.25:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4QEWci6KgEEltqA3DpqAAAWko"]
[Mon Jul 20 06:09:54.038182 2026] [security2:error] [pid 832668:tid 832761] [remote 8.217.108.67:55958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4QEmci6KgEEltqA3DptAAAaVo"]
[Mon Jul 20 06:09:54.189388 2026] [security2:error] [pid 832668:tid 832828] [client 14.225.17.146:51829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpUAAAABw"], referer: http://vinovinhowine.com/WORDPRESS
[Mon Jul 20 06:09:54.367604 2026] [security2:error] [pid 832668:tid 832921] [client 57.141.18.24:51296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QDmci6KgEEltqA3DowwAAeUw"]
[Mon Jul 20 06:09:54.417337 2026] [security2:error] [pid 832668:tid 832836] [client 14.225.17.146:54810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpZgAAACQ"], referer: http://blaizeaccountingservices.com/WORDPRESS
[Mon Jul 20 06:09:54.559148 2026] [http2:info] [pid 843279:tid 843279] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:09:55.084789 2026] [security2:error] [pid 843279:tid 843298] [remote 192.241.143.148:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CNpwAAqhE"]
[Mon Jul 20 06:09:55.152436 2026] [security2:error] [pid 843279:tid 843301] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QE_qvKNcW5yy5T2CNrQAAsRQ"]
[Mon Jul 20 06:09:55.152636 2026] [security2:error] [pid 843279:tid 843454] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QE_qvKNcW5yy5T2CNrQAAsRQ"]
[Mon Jul 20 06:09:55.198518 2026] [security2:error] [pid 832668:tid 832736] [remote 57.141.18.60:43486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpNQAAEUE"]
[Mon Jul 20 06:09:55.286795 2026] [security2:error] [pid 832668:tid 832689] [remote 57.141.18.54:54976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QEGci6KgEEltqA3DpRwAAaxI"]
[Mon Jul 20 06:09:55.286813 2026] [security2:error] [pid 843279:tid 843308] [remote 192.241.143.148:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CNuwAA3Bs"], referer: https://soloceos.com/wp-login.php
[Mon Jul 20 06:09:55.566266 2026] [security2:error] [pid 843279:tid 843534] [client 185.132.186.81:47219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/wp.php"] [unique_id "al4QE_qvKNcW5yy5T2CNywAAAQA"]
[Mon Jul 20 06:09:55.584344 2026] [security2:error] [pid 843279:tid 843317] [remote 192.241.143.148:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CN0AAA6CQ"]
[Mon Jul 20 06:09:55.773292 2026] [security2:error] [pid 843279:tid 843324] [remote 192.241.143.148:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QE_qvKNcW5yy5T2CN4gAAoys"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:09:55.876073 2026] [security2:error] [pid 832668:tid 832842] [client 104.234.53.47:35253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QE2ci6KgEEltqA3Dp1wAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:09:55.912261 2026] [security2:error] [pid 843279:tid 843438] [client 14.225.17.146:53260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QE_qvKNcW5yy5T2CN2gAAAKE"]
[Mon Jul 20 06:09:55.936153 2026] [security2:error] [pid 843279:tid 843478] [client 50.116.65.227:48248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QE_qvKNcW5yy5T2CN7QAAAMk"]
[Mon Jul 20 06:09:55.949669 2026] [security2:error] [pid 843279:tid 843483] [client 50.116.65.227:52686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QE_qvKNcW5yy5T2CN7gAAAM4"]
[Mon Jul 20 06:09:56.072574 2026] [security2:error] [pid 843279:tid 843495] [client 182.189.46.35:33039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4QFPqvKNcW5yy5T2CN8QAAANo"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:09:56.166161 2026] [security2:error] [pid 843279:tid 843498] [client 94.154.43.178:36164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "rrf.lcd.mybluehost.me"] [uri "/.env"] [unique_id "al4QFPqvKNcW5yy5T2COBgAAAN0"]
[Mon Jul 20 06:09:56.323597 2026] [security2:error] [pid 832668:tid 832760] [remote 57.141.18.89:38636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QEWci6KgEEltqA3DpkQAAfFk"]
[Mon Jul 20 06:09:56.328925 2026] [security2:error] [pid 843279:tid 843493] [client 14.225.17.146:59432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4QFPqvKNcW5yy5T2COFQAAANg"], referer: http://momheadquarters.com/WORDPRESS
[Mon Jul 20 06:09:57.053350 2026] [security2:error] [pid 843279:tid 843418] [client 192.236.168.43:33156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.absolutehomeinspections-net.nextlvlmarketingco.com"] [uri "/wp-json/batch/v1"] [unique_id "al4QFfqvKNcW5yy5T2CORAAAAI0"]
[Mon Jul 20 06:09:57.130998 2026] [security2:error] [pid 843279:tid 843454] [client 66.249.93.99:54324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4QFPqvKNcW5yy5T2COOQAAALE"]
[Mon Jul 20 06:09:57.401412 2026] [fcgid:warn] [pid 843279:tid 843443] (70014)End of file found: [client 80.87.206.20:55576] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.401897 2026] [fcgid:warn] [pid 843279:tid 843432] (70014)End of file found: [client 80.87.206.20:55572] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.402464 2026] [fcgid:warn] [pid 843279:tid 843449] (70014)End of file found: [client 80.87.206.20:55574] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.403805 2026] [fcgid:warn] [pid 843279:tid 843424] (70014)End of file found: [client 80.87.206.20:55570] mod_fcgid: can't get data from http client
[Mon Jul 20 06:09:57.516012 2026] [security2:error] [pid 843279:tid 843514] [client 185.132.186.97:54103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/options-writing.php"] [unique_id "al4QFfqvKNcW5yy5T2COaAAAAOw"]
[Mon Jul 20 06:09:57.954724 2026] [security2:error] [pid 843279:tid 843452] [client 103.77.203.233:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QFfqvKNcW5yy5T2COmgAAAK8"]
[Mon Jul 20 06:09:57.954861 2026] [security2:error] [pid 843279:tid 843452] [client 103.77.203.233:60436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QFfqvKNcW5yy5T2COmgAAAK8"]
[Mon Jul 20 06:09:58.082511 2026] [security2:error] [pid 843279:tid 843512] [client 57.141.18.38:64352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QE_qvKNcW5yy5T2CNwAAA6h0"]
[Mon Jul 20 06:09:58.277165 2026] [security2:error] [pid 843279:tid 843290] [remote 157.66.26.183:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QFvqvKNcW5yy5T2COrAAAoQk"]
[Mon Jul 20 06:09:58.284464 2026] [security2:error] [pid 843279:tid 843432] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2COogAAAJs"]
[Mon Jul 20 06:09:58.550284 2026] [security2:error] [pid 843279:tid 843447] [client 57.141.18.50:58336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QE_qvKNcW5yy5T2CN6AAAqi8"]
[Mon Jul 20 06:09:58.760355 2026] [security2:error] [pid 843279:tid 843304] [remote 157.66.26.183:51278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QFvqvKNcW5yy5T2COzQABARc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:09:58.816645 2026] [security2:error] [pid 843279:tid 843464] [client 103.95.123.246:21297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QFvqvKNcW5yy5T2CO3AAAALs"]
[Mon Jul 20 06:09:58.817468 2026] [security2:error] [pid 843279:tid 843464] [client 103.95.123.246:21297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QFvqvKNcW5yy5T2CO3AAAALs"]
[Mon Jul 20 06:09:59.423555 2026] [proxy:error] [pid 843279:tid 843489] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:59.423612 2026] [proxy_http:error] [pid 843279:tid 843489] [client 8.229.28.226:60868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:59.425141 2026] [proxy:error] [pid 843279:tid 843489] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:09:59.425184 2026] [proxy_http:error] [pid 843279:tid 843489] [client 8.229.28.226:60868] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:09:59.451692 2026] [security2:error] [pid 843279:tid 843490] [client 185.132.186.85:46943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/options-reading.php"] [unique_id "al4QF_qvKNcW5yy5T2CPDwAAANU"]
[Mon Jul 20 06:09:59.578412 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPEgAAAPI"]
[Mon Jul 20 06:09:59.578576 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:53511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPEgAAAPI"]
[Mon Jul 20 06:09:59.607118 2026] [security2:error] [pid 843279:tid 843415] [client 57.141.18.97:27348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFPqvKNcW5yy5T2COPgAAil8"]
[Mon Jul 20 06:09:59.642657 2026] [security2:error] [pid 843279:tid 843463] [client 14.225.17.146:58140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2COxAAAALo"], referer: http://travelbyfire.com/WORDPRESS
[Mon Jul 20 06:09:59.781701 2026] [security2:error] [pid 843279:tid 843473] [client 57.141.18.26:60832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFfqvKNcW5yy5T2CORgAAxGM"]
[Mon Jul 20 06:09:59.939710 2026] [security2:error] [pid 843279:tid 843483] [client 115.246.21.170:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPMQAAAM4"]
[Mon Jul 20 06:09:59.939905 2026] [security2:error] [pid 843279:tid 843483] [client 115.246.21.170:61328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QF_qvKNcW5yy5T2CPMQAAAM4"]
[Mon Jul 20 06:09:59.947345 2026] [security2:error] [pid 843279:tid 843518] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "joulecommunications.com"] [uri "/index.php"] [unique_id "al4QFfqvKNcW5yy5T2COmwAAAPA"]
[Mon Jul 20 06:10:00.303543 2026] [security2:error] [pid 843279:tid 843513] [client 98.159.234.160:28643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QGPqvKNcW5yy5T2CPRwAAAOs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:00.333577 2026] [security2:error] [pid 843279:tid 843430] [client 57.141.18.116:31674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFfqvKNcW5yy5T2COcQAAmXM"]
[Mon Jul 20 06:10:00.408151 2026] [security2:error] [pid 843279:tid 843372] [remote 160.187.68.132:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QGPqvKNcW5yy5T2CPVAAA9Vs"]
[Mon Jul 20 06:10:00.444072 2026] [security2:error] [pid 843279:tid 843516] [client 104.234.53.81:24583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QGPqvKNcW5yy5T2CPSgAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:00.485527 2026] [security2:error] [pid 843279:tid 843382] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPZgAAoGU"]
[Mon Jul 20 06:10:00.485689 2026] [security2:error] [pid 843279:tid 843437] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPZgAAoGU"]
[Mon Jul 20 06:10:00.584225 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:12480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPcAAAAQA"]
[Mon Jul 20 06:10:00.584493 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:12480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPcAAAAQA"]
[Mon Jul 20 06:10:00.586386 2026] [security2:error] [pid 843279:tid 843495] [client 14.225.17.146:61384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2CO1QAAANo"], referer: http://mobilesurvsolutions.com/WORDPRESS
[Mon Jul 20 06:10:00.743406 2026] [security2:error] [pid 843279:tid 843477] [client 14.225.17.146:52859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4QGPqvKNcW5yy5T2CPeAAAAMg"], referer: https://travelbyfire.com/WORDPRESS
[Mon Jul 20 06:10:00.830616 2026] [security2:error] [pid 843279:tid 843456] [client 112.213.160.112:30724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPhQAAALM"]
[Mon Jul 20 06:10:00.830706 2026] [security2:error] [pid 843279:tid 843456] [client 112.213.160.112:30724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPhQAAALM"]
[Mon Jul 20 06:10:00.890121 2026] [security2:error] [pid 843279:tid 843392] [remote 160.187.68.132:33858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QGPqvKNcW5yy5T2CPiQAA9W8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:00.953353 2026] [security2:error] [pid 843279:tid 843432] [client 181.224.94.124:44564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPkQAAAJs"]
[Mon Jul 20 06:10:00.953513 2026] [security2:error] [pid 843279:tid 843432] [client 181.224.94.124:44564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QGPqvKNcW5yy5T2CPkQAAAJs"]
[Mon Jul 20 06:10:01.090538 2026] [security2:error] [pid 843279:tid 843482] [client 57.141.18.92:27744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QFvqvKNcW5yy5T2COvgAAzRg"]
[Mon Jul 20 06:10:01.222194 2026] [security2:error] [pid 843279:tid 843498] [client 104.234.53.81:24583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QGfqvKNcW5yy5T2CPqwAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:01.391591 2026] [security2:error] [pid 843279:tid 843438] [client 45.116.69.230:49676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CPwgAAAKE"]
[Mon Jul 20 06:10:01.391719 2026] [security2:error] [pid 843279:tid 843438] [client 45.116.69.230:49676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CPwgAAAKE"]
[Mon Jul 20 06:10:01.398951 2026] [security2:error] [pid 843279:tid 843451] [client 185.132.186.83:37797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wsad.php"] [unique_id "al4QGfqvKNcW5yy5T2CPwwAAAK4"]
[Mon Jul 20 06:10:01.862799 2026] [core:error] [pid 843279:tid 843477] [client 14.225.17.146:52045] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:01.862831 2026] [core:error] [pid 843279:tid 843477] [client 14.225.17.146:52045] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:01.957698 2026] [security2:error] [pid 843279:tid 843501] [client 41.173.37.102:12418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CP6wAAAOA"]
[Mon Jul 20 06:10:01.957814 2026] [security2:error] [pid 843279:tid 843501] [client 41.173.37.102:12418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QGfqvKNcW5yy5T2CP6wAAAOA"]
[Mon Jul 20 06:10:01.981970 2026] [security2:error] [pid 843279:tid 843459] [client 57.141.18.31:49372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QF_qvKNcW5yy5T2CO6gAAtiw"]
[Mon Jul 20 06:10:02.112491 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:57564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CP8wAAALA"]
[Mon Jul 20 06:10:02.112653 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:57564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CP8wAAALA"]
[Mon Jul 20 06:10:02.683049 2026] [security2:error] [pid 843279:tid 843419] [client 14.225.17.146:64392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4QGfqvKNcW5yy5T2CPsgAAAI4"], referer: http://windowtx.com/WORDPRESS
[Mon Jul 20 06:10:02.729037 2026] [security2:error] [pid 843279:tid 843326] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQIAAArS0"]
[Mon Jul 20 06:10:02.729222 2026] [security2:error] [pid 843279:tid 843450] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQIAAArS0"]
[Mon Jul 20 06:10:02.843009 2026] [security2:error] [pid 843279:tid 843366] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQJwAAr1U"]
[Mon Jul 20 06:10:02.843210 2026] [security2:error] [pid 843279:tid 843452] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QGvqvKNcW5yy5T2CQJwAAr1U"]
[Mon Jul 20 06:10:02.878229 2026] [access_compat:error] [pid 843279:tid 843475] [client 183.47.122.163:54687] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:10:03.385866 2026] [security2:error] [pid 843279:tid 843380] [remote 57.141.18.79:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5490371"] [unique_id "al4QG_qvKNcW5yy5T2CQVwAAsmM"]
[Mon Jul 20 06:10:03.390116 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.83:54775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QG_qvKNcW5yy5T2CQVQAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:03.414136 2026] [security2:error] [pid 843279:tid 843474] [client 185.132.186.101:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/nation.php"] [unique_id "al4QG_qvKNcW5yy5T2CQXQAAAMU"]
[Mon Jul 20 06:10:03.435443 2026] [security2:error] [pid 843279:tid 843456] [client 50.116.65.227:50118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QG_qvKNcW5yy5T2CQXwAAALM"]
[Mon Jul 20 06:10:03.445474 2026] [security2:error] [pid 843279:tid 843431] [client 50.116.65.227:50126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QG_qvKNcW5yy5T2CQYgAAAJo"]
[Mon Jul 20 06:10:03.580662 2026] [security2:error] [pid 843279:tid 843417] [client 14.225.17.146:60528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4QG_qvKNcW5yy5T2CQWAAAAIw"], referer: http://elitetax-mi.com/WORDPRESS
[Mon Jul 20 06:10:03.992931 2026] [security2:error] [pid 843279:tid 843361] [remote 124.55.178.99:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QG_qvKNcW5yy5T2CQjgAA8FA"]
[Mon Jul 20 06:10:04.164412 2026] [security2:error] [pid 843279:tid 843512] [client 164.100.212.184:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QHPqvKNcW5yy5T2CQoQAAAOo"]
[Mon Jul 20 06:10:04.164510 2026] [security2:error] [pid 843279:tid 843512] [client 164.100.212.184:64961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QHPqvKNcW5yy5T2CQoQAAAOo"]
[Mon Jul 20 06:10:04.253674 2026] [security2:error] [pid 843279:tid 843516] [client 57.141.18.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QHPqvKNcW5yy5T2CQnAAAAO4"]
[Mon Jul 20 06:10:04.435622 2026] [security2:error] [pid 843279:tid 843449] [client 14.225.17.146:60882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4QG_qvKNcW5yy5T2CQSgAAAKw"], referer: http://betterbonddogtraining.com/WORDPRESS
[Mon Jul 20 06:10:04.547200 2026] [security2:error] [pid 843279:tid 843423] [client 57.141.18.119:37574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QGfqvKNcW5yy5T2CPxAAAkh0"]
[Mon Jul 20 06:10:04.566738 2026] [security2:error] [pid 843279:tid 843348] [remote 124.55.178.99:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QHPqvKNcW5yy5T2CQxwAA8UM"], referer: https://sarakety.com/wp-login.php
[Mon Jul 20 06:10:05.197261 2026] [security2:error] [pid 843279:tid 843474] [client 213.230.116.128:58991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marscafe.com"] [uri "/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRBgAAAMU"]
[Mon Jul 20 06:10:05.375150 2026] [security2:error] [pid 843279:tid 843493] [client 185.132.186.91:37681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/codemirror/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CREgAAANg"]
[Mon Jul 20 06:10:05.702866 2026] [security2:error] [pid 843279:tid 843325] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRMgAAuCw"]
[Mon Jul 20 06:10:05.703116 2026] [security2:error] [pid 843279:tid 843461] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRMgAAuCw"]
[Mon Jul 20 06:10:05.776678 2026] [security2:error] [pid 843279:tid 843473] [client 195.2.79.165:58137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.79.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QHfqvKNcW5yy5T2CROQAAAMQ"], referer: https://thslogistics.net/
[Mon Jul 20 06:10:05.831647 2026] [security2:error] [pid 843279:tid 843410] [client 104.234.53.61:32085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRNgAAAIU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:05.927056 2026] [security2:error] [pid 843279:tid 843467] [client 14.225.17.146:51978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRFQAAAL4"], referer: http://uritems.net/WORDPRESS
[Mon Jul 20 06:10:05.999969 2026] [security2:error] [pid 843279:tid 843534] [client 27.96.94.195:36852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRSwAAAQA"]
[Mon Jul 20 06:10:06.000167 2026] [security2:error] [pid 843279:tid 843534] [client 27.96.94.195:36852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QHfqvKNcW5yy5T2CRSwAAAQA"]
[Mon Jul 20 06:10:06.030841 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.61:32085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QHvqvKNcW5yy5T2CRTgAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:06.244797 2026] [core:error] [pid 843279:tid 843483] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:06.244826 2026] [core:error] [pid 843279:tid 843483] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:06.293216 2026] [security2:error] [pid 843279:tid 843416] [client 158.173.166.181:64251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QHvqvKNcW5yy5T2CRagAAAIs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:06.475893 2026] [security2:error] [pid 843279:tid 843437] [client 66.249.88.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nandansonscharitablefoundation.com"] [uri "/index.php"] [unique_id "al4QHPqvKNcW5yy5T2CQwAAAAKA"]
[Mon Jul 20 06:10:06.728226 2026] [security2:error] [pid 843279:tid 843534] [client 14.225.17.146:60454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CReQAAAQA"]
[Mon Jul 20 06:10:07.104907 2026] [security2:error] [pid 843279:tid 843380] [remote 8.217.108.67:41660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CRtAAA8WM"], referer: https://giftofgiving-usa.org/wp-login.php
[Mon Jul 20 06:10:07.131367 2026] [security2:error] [pid 843279:tid 843376] [remote 124.55.178.99:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CRtgAAil8"]
[Mon Jul 20 06:10:07.223769 2026] [security2:error] [pid 843279:tid 843355] [remote 130.185.118.215:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CRvgAAlUo"]
[Mon Jul 20 06:10:07.317424 2026] [security2:error] [pid 843279:tid 843451] [client 185.132.186.104:39277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp_class_datlib.php"] [unique_id "al4QH_qvKNcW5yy5T2CRygAAAK4"]
[Mon Jul 20 06:10:07.592995 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:61538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRdwAAANs"], referer: http://ravmike.com/WORDPRESS
[Mon Jul 20 06:10:07.594693 2026] [security2:error] [pid 843279:tid 843357] [remote 124.55.178.99:35268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CR2QAAmUw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:07.604718 2026] [security2:error] [pid 843279:tid 843360] [remote 130.185.118.215:46966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QH_qvKNcW5yy5T2CR2wAA8E8"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:07.710343 2026] [security2:error] [pid 843279:tid 843507] [client 66.249.79.166:48429] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.heroesoftomorrow.us"] [uri "/robots.txt"] [unique_id "al4QH_qvKNcW5yy5T2CR7AAAAOU"]
[Mon Jul 20 06:10:08.068894 2026] [security2:error] [pid 843279:tid 843440] [client 57.141.18.66:27636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QHPqvKNcW5yy5T2CQ1wAAo20"]
[Mon Jul 20 06:10:08.194665 2026] [security2:error] [pid 843279:tid 843491] [client 14.225.17.146:61534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRdQAAANY"], referer: http://ksands.co.uk/WORDPRESS
[Mon Jul 20 06:10:08.259883 2026] [security2:error] [pid 843279:tid 843530] [client 14.225.17.146:60535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRjwAAAPw"], referer: http://headachescarpaltunnelfibromyalgia.com/WORDPRESS
[Mon Jul 20 06:10:08.451700 2026] [security2:error] [pid 843279:tid 843471] [client 103.77.203.233:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSHgAAAMI"]
[Mon Jul 20 06:10:08.452114 2026] [security2:error] [pid 843279:tid 843471] [client 103.77.203.233:60964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSHgAAAMI"]
[Mon Jul 20 06:10:08.616953 2026] [security2:error] [pid 843279:tid 843520] [client 14.225.17.146:61272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4QIPqvKNcW5yy5T2CSIQAAAPI"], referer: https://ravmike.com/WORDPRESS
[Mon Jul 20 06:10:08.698647 2026] [security2:error] [pid 843279:tid 843523] [client 57.141.18.84:34440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QHfqvKNcW5yy5T2CRFwAA9Xc"]
[Mon Jul 20 06:10:08.767449 2026] [security2:error] [pid 843279:tid 843395] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNAAAjXI"]
[Mon Jul 20 06:10:08.767680 2026] [security2:error] [pid 843279:tid 843418] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNAAAjXI"]
[Mon Jul 20 06:10:08.776189 2026] [security2:error] [pid 843279:tid 843294] [remote 38.242.157.30:33342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNwABAg0"]
[Mon Jul 20 06:10:08.776394 2026] [security2:error] [pid 843279:tid 843536] [client 38.242.157.30:33342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIPqvKNcW5yy5T2CSNwABAg0"]
[Mon Jul 20 06:10:08.957083 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4QIPqvKNcW5yy5T2CSRgAA6n4"]
[Mon Jul 20 06:10:08.957391 2026] [security2:error] [pid 843279:tid 843512] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4QIPqvKNcW5yy5T2CSRgAA6n4"]
[Mon Jul 20 06:10:09.076166 2026] [security2:error] [pid 843279:tid 843461] [client 14.225.17.146:60597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4QHvqvKNcW5yy5T2CRfwAAALg"], referer: http://onewingpictures.com/WORDPRESS
[Mon Jul 20 06:10:09.260536 2026] [security2:error] [pid 843279:tid 843422] [client 185.132.186.76:47091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/tinymce/langs/about.php"] [unique_id "al4QIfqvKNcW5yy5T2CSYwAAAJE"]
[Mon Jul 20 06:10:09.549494 2026] [security2:error] [pid 843279:tid 843325] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/media.php"] [unique_id "al4QIfqvKNcW5yy5T2CSgwABASw"]
[Mon Jul 20 06:10:09.549719 2026] [security2:error] [pid 843279:tid 843535] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/media.php"] [unique_id "al4QIfqvKNcW5yy5T2CSgwABASw"]
[Mon Jul 20 06:10:09.736838 2026] [security2:error] [pid 843279:tid 843303] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/images.php"] [unique_id "al4QIfqvKNcW5yy5T2CShgAAtxY"]
[Mon Jul 20 06:10:09.737054 2026] [security2:error] [pid 843279:tid 843460] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/images.php"] [unique_id "al4QIfqvKNcW5yy5T2CShgAAtxY"]
[Mon Jul 20 06:10:09.804846 2026] [security2:error] [pid 843279:tid 843418] [client 43.173.181.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CSbwAAAI0"]
[Mon Jul 20 06:10:09.932580 2026] [security2:error] [pid 843279:tid 843416] [client 193.19.109.212:59797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4QIfqvKNcW5yy5T2CSlQAAAIs"]
[Mon Jul 20 06:10:09.965033 2026] [security2:error] [pid 843279:tid 843461] [client 193.19.109.227:47287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4QIfqvKNcW5yy5T2CSlgAAALg"]
[Mon Jul 20 06:10:09.989138 2026] [security2:error] [pid 843279:tid 843288] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/gecko.php"] [unique_id "al4QIfqvKNcW5yy5T2CSoQAArgc"]
[Mon Jul 20 06:10:09.989418 2026] [security2:error] [pid 843279:tid 843451] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/gecko.php"] [unique_id "al4QIfqvKNcW5yy5T2CSoQAArgc"]
[Mon Jul 20 06:10:10.095085 2026] [security2:error] [pid 843279:tid 843425] [client 14.225.17.146:64609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CScQAAAJQ"], referer: http://idigress.studio/WORDPRESS
[Mon Jul 20 06:10:10.114654 2026] [security2:error] [pid 843279:tid 843511] [client 57.141.18.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CSnwAAAOk"]
[Mon Jul 20 06:10:10.178439 2026] [security2:error] [pid 843279:tid 843304] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/82.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqQAAyBc"]
[Mon Jul 20 06:10:10.178639 2026] [security2:error] [pid 843279:tid 843477] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/82.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqQAAyBc"]
[Mon Jul 20 06:10:10.184588 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:17897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqgAAAMo"]
[Mon Jul 20 06:10:10.184704 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:17897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSqgAAAMo"]
[Mon Jul 20 06:10:10.273920 2026] [security2:error] [pid 843279:tid 843494] [client 57.141.18.94:59344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QH_qvKNcW5yy5T2CRvwAA2T0"]
[Mon Jul 20 06:10:10.346246 2026] [security2:error] [pid 843279:tid 843517] [client 103.141.108.143:53983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CStgAAAO8"]
[Mon Jul 20 06:10:10.347285 2026] [security2:error] [pid 843279:tid 843517] [client 103.141.108.143:53983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CStgAAAO8"]
[Mon Jul 20 06:10:10.455847 2026] [security2:error] [pid 843279:tid 843327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QIvqvKNcW5yy5T2CSxQAAly4"]
[Mon Jul 20 06:10:10.456033 2026] [security2:error] [pid 843279:tid 843428] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QIvqvKNcW5yy5T2CSxQAAly4"]
[Mon Jul 20 06:10:10.608882 2026] [security2:error] [pid 843279:tid 843530] [client 115.246.21.170:21729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSzQAAAPw"]
[Mon Jul 20 06:10:10.609008 2026] [security2:error] [pid 843279:tid 843530] [client 115.246.21.170:21729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CSzQAAAPw"]
[Mon Jul 20 06:10:10.704226 2026] [security2:error] [pid 843279:tid 843468] [client 103.153.183.69:27498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.koaconsultants.com"] [uri "/....//....//....//....//....//var/www/html/wp-config.php"] [unique_id "al4QIvqvKNcW5yy5T2CS0wAAAL8"], referer: https://twitter.com/
[Mon Jul 20 06:10:10.835421 2026] [security2:error] [pid 843279:tid 843331] [remote 74.235.96.117:36242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CS3gAAzTI"]
[Mon Jul 20 06:10:10.835732 2026] [security2:error] [pid 843279:tid 843482] [client 74.235.96.117:36242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QIvqvKNcW5yy5T2CS3gAAzTI"]
[Mon Jul 20 06:10:11.015088 2026] [security2:error] [pid 843279:tid 843493] [client 50.116.65.227:31532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QI_qvKNcW5yy5T2CS7gAAANg"]
[Mon Jul 20 06:10:11.028810 2026] [security2:error] [pid 843279:tid 843471] [client 50.116.65.227:57428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QI_qvKNcW5yy5T2CS8AAAAMI"]
[Mon Jul 20 06:10:11.121837 2026] [security2:error] [pid 843279:tid 843343] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/adminner.php"] [unique_id "al4QI_qvKNcW5yy5T2CS8gAA5j4"]
[Mon Jul 20 06:10:11.122023 2026] [security2:error] [pid 843279:tid 843508] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/adminner.php"] [unique_id "al4QI_qvKNcW5yy5T2CS8gAA5j4"]
[Mon Jul 20 06:10:11.203553 2026] [security2:error] [pid 843279:tid 843492] [client 185.132.186.95:20181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/autoload_classmap/wso.php"] [unique_id "al4QI_qvKNcW5yy5T2CS9wAAANc"]
[Mon Jul 20 06:10:11.404595 2026] [security2:error] [pid 843279:tid 843344] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTBwAA6T8"]
[Mon Jul 20 06:10:11.404775 2026] [security2:error] [pid 843279:tid 843511] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTBwAA6T8"]
[Mon Jul 20 06:10:11.496562 2026] [security2:error] [pid 843279:tid 843514] [client 181.224.94.124:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTEwAAAOw"]
[Mon Jul 20 06:10:11.496665 2026] [security2:error] [pid 843279:tid 843514] [client 181.224.94.124:49208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTEwAAAOw"]
[Mon Jul 20 06:10:11.537333 2026] [security2:error] [pid 843279:tid 843414] [client 112.213.160.112:31163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTFgAAAIk"]
[Mon Jul 20 06:10:11.537444 2026] [security2:error] [pid 843279:tid 843414] [client 112.213.160.112:31163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTFgAAAIk"]
[Mon Jul 20 06:10:11.561917 2026] [security2:error] [pid 843279:tid 843450] [client 57.141.18.96:60738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIPqvKNcW5yy5T2CSJgAArWw"]
[Mon Jul 20 06:10:11.599655 2026] [security2:error] [pid 843279:tid 843520] [client 86.98.90.58:13252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTGQAAAPI"]
[Mon Jul 20 06:10:11.599789 2026] [security2:error] [pid 843279:tid 843520] [client 86.98.90.58:13252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QI_qvKNcW5yy5T2CTGQAAAPI"]
[Mon Jul 20 06:10:11.723965 2026] [security2:error] [pid 843279:tid 843515] [client 37.236.31.34:46368] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4QI_qvKNcW5yy5T2CTIwAAAO0"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 06:10:11.858358 2026] [security2:error] [pid 843279:tid 843481] [client 104.234.53.94:44591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QI_qvKNcW5yy5T2CTMwAAAMw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:11.888652 2026] [security2:error] [pid 843279:tid 843354] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QI_qvKNcW5yy5T2CTNQAAvUk"]
[Mon Jul 20 06:10:11.888917 2026] [security2:error] [pid 843279:tid 843466] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QI_qvKNcW5yy5T2CTNQAAvUk"]
[Mon Jul 20 06:10:12.028704 2026] [security2:error] [pid 843279:tid 843508] [client 45.116.69.230:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTQgAAAOY"]
[Mon Jul 20 06:10:12.028806 2026] [security2:error] [pid 843279:tid 843508] [client 45.116.69.230:50173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTQgAAAOY"]
[Mon Jul 20 06:10:12.241521 2026] [security2:error] [pid 843279:tid 843412] [client 87.199.196.160:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4QJPqvKNcW5yy5T2CTTwAAAIc"], referer: https://www.friendlyspreadsheet.com/guide-to-getting-pros/
[Mon Jul 20 06:10:12.241661 2026] [security2:error] [pid 843279:tid 843412] [client 87.199.196.160:64740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-comments-post.php"] [unique_id "al4QJPqvKNcW5yy5T2CTTwAAAIc"], referer: https://www.friendlyspreadsheet.com/guide-to-getting-pros/
[Mon Jul 20 06:10:12.259860 2026] [security2:error] [pid 843279:tid 843364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJPqvKNcW5yy5T2CTVAAA91M"]
[Mon Jul 20 06:10:12.260123 2026] [security2:error] [pid 843279:tid 843525] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJPqvKNcW5yy5T2CTVAAA91M"]
[Mon Jul 20 06:10:12.260684 2026] [security2:error] [pid 843279:tid 843433] [client 14.225.17.146:54207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4QJPqvKNcW5yy5T2CTSAAAAJw"], referer: http://lutheranphilosopher.com/WORDPRESS
[Mon Jul 20 06:10:12.457035 2026] [security2:error] [pid 843279:tid 843371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/blurbs.php"] [unique_id "al4QJPqvKNcW5yy5T2CTZwAAjVo"]
[Mon Jul 20 06:10:12.457252 2026] [security2:error] [pid 843279:tid 843418] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/blurbs.php"] [unique_id "al4QJPqvKNcW5yy5T2CTZwAAjVo"]
[Mon Jul 20 06:10:12.531023 2026] [security2:error] [pid 843279:tid 843502] [client 41.173.37.102:12862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTbgAAAOE"]
[Mon Jul 20 06:10:12.531149 2026] [security2:error] [pid 843279:tid 843502] [client 41.173.37.102:12862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTbgAAAOE"]
[Mon Jul 20 06:10:12.671128 2026] [security2:error] [pid 843279:tid 843293] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/bajah.php"] [unique_id "al4QJPqvKNcW5yy5T2CTgAAApQw"]
[Mon Jul 20 06:10:12.671335 2026] [security2:error] [pid 843279:tid 843442] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/bajah.php"] [unique_id "al4QJPqvKNcW5yy5T2CTgAAApQw"]
[Mon Jul 20 06:10:12.827001 2026] [security2:error] [pid 843279:tid 843457] [client 57.141.18.61:21240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIfqvKNcW5yy5T2CShQAAtBQ"]
[Mon Jul 20 06:10:12.872259 2026] [security2:error] [pid 843279:tid 843529] [client 178.152.178.232:36977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTiwAAAPs"]
[Mon Jul 20 06:10:12.872375 2026] [security2:error] [pid 843279:tid 843529] [client 178.152.178.232:36977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QJPqvKNcW5yy5T2CTiwAAAPs"]
[Mon Jul 20 06:10:12.919011 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/a.php"] [unique_id "al4QJPqvKNcW5yy5T2CTlAABBH4"]
[Mon Jul 20 06:10:12.919222 2026] [security2:error] [pid 843279:tid 843538] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/a.php"] [unique_id "al4QJPqvKNcW5yy5T2CTlAABBH4"]
[Mon Jul 20 06:10:13.111594 2026] [security2:error] [pid 843279:tid 843317] [remote 8.217.108.67:26046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QJfqvKNcW5yy5T2CTogAA9CQ"]
[Mon Jul 20 06:10:13.166843 2026] [security2:error] [pid 843279:tid 843422] [client 185.132.186.57:46267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-atomx.php"] [unique_id "al4QJfqvKNcW5yy5T2CTpQAAAJE"]
[Mon Jul 20 06:10:13.213031 2026] [security2:error] [pid 843279:tid 843517] [client 27.85.1.30:20005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTpwAAAO8"]
[Mon Jul 20 06:10:13.362618 2026] [security2:error] [pid 843279:tid 843402] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTtwAAtHk"]
[Mon Jul 20 06:10:13.362784 2026] [security2:error] [pid 843279:tid 843457] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTtwAAtHk"]
[Mon Jul 20 06:10:13.382245 2026] [security2:error] [pid 843279:tid 843444] [client 92.77.225.20:41488] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTtAAAAKc"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 06:10:13.416940 2026] [security2:error] [pid 843279:tid 843535] [client 14.225.17.146:62654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4QJPqvKNcW5yy5T2CTTgAAAQE"], referer: http://northbrookcpa.ca/WORDPRESS
[Mon Jul 20 06:10:13.503761 2026] [security2:error] [pid 843279:tid 843330] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTwAAA0TE"]
[Mon Jul 20 06:10:13.503925 2026] [security2:error] [pid 843279:tid 843486] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QJfqvKNcW5yy5T2CTwAAA0TE"]
[Mon Jul 20 06:10:13.508569 2026] [security2:error] [pid 843279:tid 843500] [client 27.85.1.30:19129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTwQAAAN8"]
[Mon Jul 20 06:10:13.797409 2026] [security2:error] [pid 843279:tid 843419] [client 27.85.1.30:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CT0AAAAI4"]
[Mon Jul 20 06:10:14.041443 2026] [security2:error] [pid 843279:tid 843300] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/edit.php"] [unique_id "al4QJvqvKNcW5yy5T2CT5wAA1xM"]
[Mon Jul 20 06:10:14.041601 2026] [security2:error] [pid 843279:tid 843492] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/edit.php"] [unique_id "al4QJvqvKNcW5yy5T2CT5wAA1xM"]
[Mon Jul 20 06:10:14.044048 2026] [security2:error] [pid 843279:tid 843503] [client 57.141.18.80:46818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIvqvKNcW5yy5T2CS1QAA4jU"]
[Mon Jul 20 06:10:14.124070 2026] [security2:error] [pid 843279:tid 843509] [client 27.85.1.30:34312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CT7wAAAOc"]
[Mon Jul 20 06:10:14.140698 2026] [security2:error] [pid 843279:tid 843479] [client 57.141.18.101:59370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QIvqvKNcW5yy5T2CS3wAAygY"]
[Mon Jul 20 06:10:14.170954 2026] [security2:error] [pid 843279:tid 843442] [client 193.37.33.232:29055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.33.37.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4QJvqvKNcW5yy5T2CT8gAAAKU"]
[Mon Jul 20 06:10:14.230876 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/hosty.php"] [unique_id "al4QJvqvKNcW5yy5T2CT_AAAzh8"]
[Mon Jul 20 06:10:14.231081 2026] [security2:error] [pid 843279:tid 843483] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/hosty.php"] [unique_id "al4QJvqvKNcW5yy5T2CT_AAAzh8"]
[Mon Jul 20 06:10:14.321813 2026] [security2:error] [pid 843279:tid 843292] [remote 8.217.108.67:26046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QJvqvKNcW5yy5T2CUAAAAmQs"], referer: https://zoa.jji.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:14.418585 2026] [security2:error] [pid 843279:tid 843336] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBgAAvzc"]
[Mon Jul 20 06:10:14.418808 2026] [security2:error] [pid 843279:tid 843468] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/k.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBgAAvzc"]
[Mon Jul 20 06:10:14.424556 2026] [security2:error] [pid 843279:tid 843497] [client 27.85.1.30:23940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBwAAANw"]
[Mon Jul 20 06:10:14.554039 2026] [security2:error] [pid 843279:tid 843420] [client 106.192.104.4:58069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUEgAAAI8"]
[Mon Jul 20 06:10:14.554231 2026] [security2:error] [pid 843279:tid 843420] [client 106.192.104.4:58069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUEgAAAI8"]
[Mon Jul 20 06:10:14.606540 2026] [security2:error] [pid 843279:tid 843331] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QJvqvKNcW5yy5T2CUFwAAuTI"]
[Mon Jul 20 06:10:14.606797 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QJvqvKNcW5yy5T2CUFwAAuTI"]
[Mon Jul 20 06:10:14.624741 2026] [security2:error] [pid 843279:tid 843535] [client 14.225.17.146:61767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUBAAAAQE"], referer: http://idigress.agency/WORDPRESS
[Mon Jul 20 06:10:14.757160 2026] [security2:error] [pid 843279:tid 843432] [client 27.85.1.30:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUJAAAAJs"]
[Mon Jul 20 06:10:14.801946 2026] [security2:error] [pid 843279:tid 843339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file5.php"] [unique_id "al4QJvqvKNcW5yy5T2CUJwAAiDo"]
[Mon Jul 20 06:10:14.802151 2026] [security2:error] [pid 843279:tid 843413] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file5.php"] [unique_id "al4QJvqvKNcW5yy5T2CUJwAAiDo"]
[Mon Jul 20 06:10:14.802469 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUKAAAALc"]
[Mon Jul 20 06:10:14.802585 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:49165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QJvqvKNcW5yy5T2CUKAAAALc"]
[Mon Jul 20 06:10:14.946209 2026] [security2:error] [pid 843279:tid 843502] [client 14.225.17.146:54086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTrgAAAOE"], referer: http://amalia-capital.com/WORDPRESS
[Mon Jul 20 06:10:15.022133 2026] [security2:error] [pid 843279:tid 843358] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/222.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUOwAA7E0"]
[Mon Jul 20 06:10:15.022396 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/222.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUOwAA7E0"]
[Mon Jul 20 06:10:15.098174 2026] [security2:error] [pid 843279:tid 843448] [client 185.132.186.61:28095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin-footer.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUQQAAAKs"]
[Mon Jul 20 06:10:15.107851 2026] [security2:error] [pid 843279:tid 843427] [client 27.85.1.30:23451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUQwAAAJY"]
[Mon Jul 20 06:10:15.215396 2026] [security2:error] [pid 843279:tid 843357] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/test.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUTgAAkkw"]
[Mon Jul 20 06:10:15.215612 2026] [security2:error] [pid 843279:tid 843423] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/test.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUTgAAkkw"]
[Mon Jul 20 06:10:15.395854 2026] [security2:error] [pid 843279:tid 843461] [client 27.85.1.30:34946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUWgAAALg"]
[Mon Jul 20 06:10:15.414120 2026] [security2:error] [pid 843279:tid 843315] [remote 194.164.192.228:33700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUXAAA1yI"]
[Mon Jul 20 06:10:15.414331 2026] [security2:error] [pid 843279:tid 843419] [client 104.234.53.53:64587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUVAAAAI4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:15.414337 2026] [security2:error] [pid 843279:tid 843492] [client 194.164.192.228:33700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUXAAA1yI"]
[Mon Jul 20 06:10:15.645049 2026] [security2:error] [pid 843279:tid 843350] [remote 182.77.62.24:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUdwAArkU"]
[Mon Jul 20 06:10:15.652660 2026] [security2:error] [pid 843279:tid 843457] [client 14.225.17.146:63489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUZwAAALQ"], referer: http://olearyplumbingllc.com/WORDPRESS
[Mon Jul 20 06:10:15.680602 2026] [security2:error] [pid 843279:tid 843518] [client 27.85.1.30:40553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUfQAAAPA"]
[Mon Jul 20 06:10:15.742988 2026] [security2:error] [pid 843279:tid 843418] [client 50.116.65.227:31538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_d9d7fe47/wp-cron.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUgwAAAI0"]
[Mon Jul 20 06:10:15.784550 2026] [security2:error] [pid 843279:tid 843390] [remote 110.249.201.89:61808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/"] [unique_id "al4QJ_qvKNcW5yy5T2CUhAAAwG0"]
[Mon Jul 20 06:10:15.812674 2026] [security2:error] [pid 843279:tid 843459] [client 212.47.238.7:34902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail-box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4QJ_qvKNcW5yy5T2CUhgAAALY"]
[Mon Jul 20 06:10:15.991795 2026] [security2:error] [pid 843279:tid 843464] [client 27.85.1.30:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUmgAAALs"]
[Mon Jul 20 06:10:16.001734 2026] [security2:error] [pid 843279:tid 843480] [client 92.209.171.215:8533] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4QJ_qvKNcW5yy5T2CUlwAAAMs"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 06:10:16.180003 2026] [security2:error] [pid 843279:tid 843387] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QKPqvKNcW5yy5T2CUqwABBGo"]
[Mon Jul 20 06:10:16.180183 2026] [security2:error] [pid 843279:tid 843538] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QKPqvKNcW5yy5T2CUqwABBGo"]
[Mon Jul 20 06:10:16.244274 2026] [security2:error] [pid 843279:tid 843491] [client 74.208.214.194:42734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QKPqvKNcW5yy5T2CUswAAANY"]
[Mon Jul 20 06:10:16.262432 2026] [security2:error] [pid 843279:tid 843348] [remote 182.77.62.24:56646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QKPqvKNcW5yy5T2CUtAAA3UM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:16.313474 2026] [security2:error] [pid 843279:tid 843459] [client 27.85.1.30:54412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CUugAAALY"]
[Mon Jul 20 06:10:16.452557 2026] [security2:error] [pid 843279:tid 843393] [remote 91.142.222.105:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4QKPqvKNcW5yy5T2CUvwAAvHA"]
[Mon Jul 20 06:10:16.494388 2026] [security2:error] [pid 843279:tid 843414] [client 57.141.18.15:25152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QJfqvKNcW5yy5T2CTrwAAiX8"]
[Mon Jul 20 06:10:16.521541 2026] [proxy:error] [pid 843279:tid 843453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:16.521576 2026] [proxy_http:error] [pid 843279:tid 843453] [client 20.74.45.95:59509] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:16.522159 2026] [proxy:error] [pid 843279:tid 843453] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:16.522185 2026] [proxy_http:error] [pid 843279:tid 843453] [client 20.74.45.95:59509] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:16.565468 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QKPqvKNcW5yy5T2CUzAAA9n4"]
[Mon Jul 20 06:10:16.565657 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/aaa.php"] [unique_id "al4QKPqvKNcW5yy5T2CUzAAA9n4"]
[Mon Jul 20 06:10:16.634190 2026] [security2:error] [pid 843279:tid 843468] [client 27.85.1.30:1050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CU0AAAAL8"]
[Mon Jul 20 06:10:16.768374 2026] [security2:error] [pid 843279:tid 843283] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QKPqvKNcW5yy5T2CU5AAAowI"]
[Mon Jul 20 06:10:16.768554 2026] [security2:error] [pid 843279:tid 843440] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QKPqvKNcW5yy5T2CU5AAAowI"]
[Mon Jul 20 06:10:16.958034 2026] [security2:error] [pid 843279:tid 843306] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/mac.php"] [unique_id "al4QKPqvKNcW5yy5T2CU7wAAjxk"]
[Mon Jul 20 06:10:16.958235 2026] [security2:error] [pid 843279:tid 843420] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/mac.php"] [unique_id "al4QKPqvKNcW5yy5T2CU7wAAjxk"]
[Mon Jul 20 06:10:16.963976 2026] [security2:error] [pid 843279:tid 843528] [client 27.85.1.30:30209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CU8AAAAPo"]
[Mon Jul 20 06:10:16.973233 2026] [security2:error] [pid 843279:tid 843444] [client 121.188.194.82:59418] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "sarakety.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al4QKPqvKNcW5yy5T2CU8wAAAKc"]
[Mon Jul 20 06:10:17.053296 2026] [security2:error] [pid 843279:tid 843496] [client 185.132.186.100:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/wp-conflg.php"] [unique_id "al4QKfqvKNcW5yy5T2CU-gAAANs"]
[Mon Jul 20 06:10:17.287845 2026] [security2:error] [pid 843279:tid 843499] [client 27.85.1.30:62891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.1.85.27.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4QKfqvKNcW5yy5T2CVDwAAAN4"]
[Mon Jul 20 06:10:17.314300 2026] [security2:error] [pid 843279:tid 843309] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/chosen.php"] [unique_id "al4QKfqvKNcW5yy5T2CVFQAAvBw"]
[Mon Jul 20 06:10:17.314463 2026] [security2:error] [pid 843279:tid 843465] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/chosen.php"] [unique_id "al4QKfqvKNcW5yy5T2CVFQAAvBw"]
[Mon Jul 20 06:10:17.459414 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QKfqvKNcW5yy5T2CVIQAAAN0"]
[Mon Jul 20 06:10:17.459590 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QKfqvKNcW5yy5T2CVIQAAAN0"]
[Mon Jul 20 06:10:17.571359 2026] [security2:error] [pid 843279:tid 843499] [client 104.234.53.53:64587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVJgAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:17.615898 2026] [security2:error] [pid 843279:tid 843531] [client 14.225.17.146:63427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CUoQAAAP0"], referer: http://alexsandbergmusic.com/WORDPRESS
[Mon Jul 20 06:10:17.740850 2026] [security2:error] [pid 843279:tid 843491] [client 13.215.47.127:35236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVMgAAANY"]
[Mon Jul 20 06:10:17.825689 2026] [security2:error] [pid 843279:tid 843313] [remote 91.142.222.105:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVOwAAiSA"], referer: https://mail.legallyknownaszacharyhoy999.com/wp-login.php
[Mon Jul 20 06:10:18.023704 2026] [security2:error] [pid 843279:tid 843470] [client 57.141.18.89:26452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QJvqvKNcW5yy5T2CUCwAAwRs"]
[Mon Jul 20 06:10:18.076627 2026] [security2:error] [pid 843279:tid 843292] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/cream1.php"] [unique_id "al4QKvqvKNcW5yy5T2CVUAAA3As"]
[Mon Jul 20 06:10:18.076777 2026] [security2:error] [pid 843279:tid 843497] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/cream1.php"] [unique_id "al4QKvqvKNcW5yy5T2CVUAAA3As"]
[Mon Jul 20 06:10:18.103847 2026] [security2:error] [pid 843279:tid 843514] [client 14.225.17.146:63473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4QKPqvKNcW5yy5T2CU5wAAAOw"], referer: http://wathenbartlett.co.uk/WORDPRESS
[Mon Jul 20 06:10:18.282977 2026] [security2:error] [pid 843279:tid 843530] [client 121.188.194.82:59420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QKfqvKNcW5yy5T2CVQQAAAPw"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:18.328205 2026] [security2:error] [pid 843279:tid 843478] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-content/uploads/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVYwAAyTI"]
[Mon Jul 20 06:10:18.597765 2026] [security2:error] [pid 843279:tid 843454] [client 186.216.45.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVZQAAALE"]
[Mon Jul 20 06:10:18.613480 2026] [security2:error] [pid 843279:tid 843351] [remote 81.173.115.7:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "katsklar.com"] [uri "/wp-login.php"] [unique_id "al4QKvqvKNcW5yy5T2CVgQAA9UY"]
[Mon Jul 20 06:10:18.669161 2026] [security2:error] [pid 843279:tid 843469] [client 104.234.53.61:64781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QKvqvKNcW5yy5T2CVfgAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:18.725206 2026] [autoindex:error] [pid 843279:tid 843372] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:18.725792 2026] [security2:error] [pid 843279:tid 843489] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/Text/"] [unique_id "al4QKvqvKNcW5yy5T2CVhwAA1Fs"]
[Mon Jul 20 06:10:18.857784 2026] [security2:error] [pid 843279:tid 843534] [client 104.234.53.61:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QKvqvKNcW5yy5T2CVmwAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:18.884472 2026] [security2:error] [pid 843279:tid 843349] [remote 81.173.115.7:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "katsklar.com"] [uri "/wp-login.php"] [unique_id "al4QKvqvKNcW5yy5T2CVnQAAhUQ"], referer: https://katsklar.com/wp-login.php
[Mon Jul 20 06:10:18.913798 2026] [security2:error] [pid 843279:tid 843384] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/dr.php"] [unique_id "al4QKvqvKNcW5yy5T2CVoQAA9Gc"]
[Mon Jul 20 06:10:18.913971 2026] [security2:error] [pid 843279:tid 843522] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/dr.php"] [unique_id "al4QKvqvKNcW5yy5T2CVoQAA9Gc"]
[Mon Jul 20 06:10:18.920685 2026] [security2:error] [pid 843279:tid 843524] [client 103.77.203.233:61502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QKvqvKNcW5yy5T2CVowAAAPY"]
[Mon Jul 20 06:10:18.920803 2026] [security2:error] [pid 843279:tid 843524] [client 103.77.203.233:61502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QKvqvKNcW5yy5T2CVowAAAPY"]
[Mon Jul 20 06:10:18.981949 2026] [security2:error] [pid 843279:tid 843315] [remote 57.141.18.79:28768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5703786"] [unique_id "al4QKvqvKNcW5yy5T2CVpwAAuiI"]
[Mon Jul 20 06:10:19.004847 2026] [security2:error] [pid 843279:tid 843441] [client 185.132.186.61:49565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/XxX.php"] [unique_id "al4QK_qvKNcW5yy5T2CVqgAAAKQ"]
[Mon Jul 20 06:10:19.090802 2026] [security2:error] [pid 843279:tid 843483] [client 54.204.158.117:26956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.158.204.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QK_qvKNcW5yy5T2CVsAAAAM4"]
[Mon Jul 20 06:10:19.091033 2026] [security2:error] [pid 843279:tid 843483] [client 54.204.158.117:26956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QK_qvKNcW5yy5T2CVsAAAAM4"]
[Mon Jul 20 06:10:19.095157 2026] [security2:error] [pid 843279:tid 843472] [client 14.225.17.146:62510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4QK_qvKNcW5yy5T2CVrAAAAMM"], referer: https://wathenbartlett.co.uk/WORDPRESS
[Mon Jul 20 06:10:19.138194 2026] [security2:error] [pid 843279:tid 843500] [client 47.129.222.11:14946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QK_qvKNcW5yy5T2CVtwAAAN8"]
[Mon Jul 20 06:10:19.149156 2026] [security2:error] [pid 843279:tid 843368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/x.php"] [unique_id "al4QK_qvKNcW5yy5T2CVugAA3Fc"]
[Mon Jul 20 06:10:19.149443 2026] [security2:error] [pid 843279:tid 843497] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/x.php"] [unique_id "al4QK_qvKNcW5yy5T2CVugAA3Fc"]
[Mon Jul 20 06:10:19.349882 2026] [security2:error] [pid 843279:tid 843400] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/155.php"] [unique_id "al4QK_qvKNcW5yy5T2CVyAAA1Hc"]
[Mon Jul 20 06:10:19.350044 2026] [security2:error] [pid 843279:tid 843489] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/155.php"] [unique_id "al4QK_qvKNcW5yy5T2CVyAAA1Hc"]
[Mon Jul 20 06:10:19.548377 2026] [security2:error] [pid 843279:tid 843382] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ops.php"] [unique_id "al4QK_qvKNcW5yy5T2CV1QAAtGU"]
[Mon Jul 20 06:10:19.548572 2026] [security2:error] [pid 843279:tid 843457] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ops.php"] [unique_id "al4QK_qvKNcW5yy5T2CV1QAAtGU"]
[Mon Jul 20 06:10:19.731579 2026] [security2:error] [pid 843279:tid 843528] [client 66.249.73.64:55523] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ericsnotary.com"] [uri "/robots.txt"] [unique_id "al4QK_qvKNcW5yy5T2CV5gAAAPo"]
[Mon Jul 20 06:10:19.736819 2026] [security2:error] [pid 843279:tid 843379] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file31.php"] [unique_id "al4QK_qvKNcW5yy5T2CV5wAAsmI"]
[Mon Jul 20 06:10:19.736941 2026] [security2:error] [pid 843279:tid 843455] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file31.php"] [unique_id "al4QK_qvKNcW5yy5T2CV5wAAsmI"]
[Mon Jul 20 06:10:19.893215 2026] [security2:error] [pid 843279:tid 843430] [client 121.188.194.82:59426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QK_qvKNcW5yy5T2CV1AAAAJk"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:19.928877 2026] [security2:error] [pid 843279:tid 843395] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file6.php"] [unique_id "al4QK_qvKNcW5yy5T2CV_gAAnHI"]
[Mon Jul 20 06:10:19.929079 2026] [security2:error] [pid 843279:tid 843433] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file6.php"] [unique_id "al4QK_qvKNcW5yy5T2CV_gAAnHI"]
[Mon Jul 20 06:10:20.079401 2026] [security2:error] [pid 843279:tid 843522] [client 13.229.223.11:34240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QLPqvKNcW5yy5T2CWCQAAAPQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:10:20.432854 2026] [autoindex:error] [pid 843279:tid 843301] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:20.433439 2026] [security2:error] [pid 843279:tid 843430] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/assets/"] [unique_id "al4QLPqvKNcW5yy5T2CWJQAAmRQ"]
[Mon Jul 20 06:10:20.453232 2026] [security2:error] [pid 843279:tid 843480] [client 104.234.53.67:41703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QLPqvKNcW5yy5T2CWJgAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:20.536542 2026] [core:error] [pid 843279:tid 843524] [client 185.247.137.2:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:20.536561 2026] [core:error] [pid 843279:tid 843524] [client 185.247.137.2:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:20.621599 2026] [security2:error] [pid 843279:tid 843394] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/adminfuns.php"] [unique_id "al4QLPqvKNcW5yy5T2CWOAAAw3E"]
[Mon Jul 20 06:10:20.621820 2026] [security2:error] [pid 843279:tid 843472] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/adminfuns.php"] [unique_id "al4QLPqvKNcW5yy5T2CWOAAAw3E"]
[Mon Jul 20 06:10:20.746110 2026] [security2:error] [pid 843279:tid 843498] [client 103.153.183.69:4640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/shadow"] [unique_id "al4QLPqvKNcW5yy5T2CWQQAAAN0"], referer: https://www.google.com/search?q=bzqj9a
[Mon Jul 20 06:10:20.756984 2026] [security2:error] [pid 843279:tid 843469] [client 14.225.17.146:62335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4QLPqvKNcW5yy5T2CWPQAAAMA"], referer: http://thefriendlyspreadsheet.com/WORDPRESS
[Mon Jul 20 06:10:20.790529 2026] [security2:error] [pid 843279:tid 843428] [client 14.225.17.146:62334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4QLPqvKNcW5yy5T2CWPAAAAJc"], referer: http://collectingrealestate.com/WORDPRESS
[Mon Jul 20 06:10:20.829927 2026] [security2:error] [pid 843279:tid 843330] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/goods.php"] [unique_id "al4QLPqvKNcW5yy5T2CWTQAAoTE"]
[Mon Jul 20 06:10:20.830123 2026] [security2:error] [pid 843279:tid 843438] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/goods.php"] [unique_id "al4QLPqvKNcW5yy5T2CWTQAAoTE"]
[Mon Jul 20 06:10:20.947211 2026] [security2:error] [pid 843279:tid 843430] [client 185.132.186.85:48697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ubh/install.php"] [unique_id "al4QLPqvKNcW5yy5T2CWWgAAAJk"]
[Mon Jul 20 06:10:21.018828 2026] [security2:error] [pid 843279:tid 843297] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/100.php"] [unique_id "al4QLfqvKNcW5yy5T2CWYwABAhA"]
[Mon Jul 20 06:10:21.019022 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/100.php"] [unique_id "al4QLfqvKNcW5yy5T2CWYwABAhA"]
[Mon Jul 20 06:10:21.150446 2026] [security2:error] [pid 843279:tid 843431] [client 50.116.65.227:28648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QLfqvKNcW5yy5T2CWaQAAAJo"]
[Mon Jul 20 06:10:21.163487 2026] [security2:error] [pid 843279:tid 843456] [client 50.116.65.227:28662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QLfqvKNcW5yy5T2CWagAAALM"]
[Mon Jul 20 06:10:21.203785 2026] [security2:error] [pid 843279:tid 843508] [client 103.141.108.143:54445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWbgAAAOY"]
[Mon Jul 20 06:10:21.203923 2026] [security2:error] [pid 843279:tid 843508] [client 103.141.108.143:54445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWbgAAAOY"]
[Mon Jul 20 06:10:21.235621 2026] [security2:error] [pid 843279:tid 843479] [client 115.246.21.170:22296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWegAAAMo"]
[Mon Jul 20 06:10:21.235772 2026] [security2:error] [pid 843279:tid 843479] [client 115.246.21.170:22296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWegAAAMo"]
[Mon Jul 20 06:10:21.237898 2026] [security2:error] [pid 843279:tid 843320] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWfAAA6Sc"]
[Mon Jul 20 06:10:21.238162 2026] [security2:error] [pid 843279:tid 843511] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWfAAA6Sc"]
[Mon Jul 20 06:10:21.426432 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWjgAA7B8"]
[Mon Jul 20 06:10:21.426652 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/about.php"] [unique_id "al4QLfqvKNcW5yy5T2CWjgAA7B8"]
[Mon Jul 20 06:10:21.501281 2026] [security2:error] [pid 843279:tid 843513] [client 103.95.123.246:18619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWlAAAAOs"]
[Mon Jul 20 06:10:21.501472 2026] [security2:error] [pid 843279:tid 843513] [client 103.95.123.246:18619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QLfqvKNcW5yy5T2CWlAAAAOs"]
[Mon Jul 20 06:10:21.583126 2026] [security2:error] [pid 843279:tid 843439] [client 121.188.194.82:59428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QLfqvKNcW5yy5T2CWcAAAAKI"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:21.593008 2026] [security2:error] [pid 843279:tid 843502] [client 14.225.17.146:63955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4QK_qvKNcW5yy5T2CWAgAAAOE"], referer: https://north-woods-engineering.com/WORDPRESS
[Mon Jul 20 06:10:21.614829 2026] [security2:error] [pid 843279:tid 843292] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWmgAAsws"]
[Mon Jul 20 06:10:21.615044 2026] [security2:error] [pid 843279:tid 843456] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWmgAAsws"]
[Mon Jul 20 06:10:21.816028 2026] [security2:error] [pid 843279:tid 843341] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWsQAAmTw"]
[Mon Jul 20 06:10:21.816221 2026] [security2:error] [pid 843279:tid 843430] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/admin.php"] [unique_id "al4QLfqvKNcW5yy5T2CWsQAAmTw"]
[Mon Jul 20 06:10:21.817174 2026] [security2:error] [pid 843279:tid 843299] [remote 78.46.157.202:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4QLfqvKNcW5yy5T2CWrgAAlBI"]
[Mon Jul 20 06:10:21.829551 2026] [security2:error] [pid 843279:tid 843424] [client 57.141.18.86:28722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QKfqvKNcW5yy5T2CVSAAAky4"]
[Mon Jul 20 06:10:22.036937 2026] [security2:error] [pid 843279:tid 843316] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/themes.php"] [unique_id "al4QLvqvKNcW5yy5T2CWwAAApiM"]
[Mon Jul 20 06:10:22.037143 2026] [security2:error] [pid 843279:tid 843443] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/themes.php"] [unique_id "al4QLvqvKNcW5yy5T2CWwAAApiM"]
[Mon Jul 20 06:10:22.131185 2026] [security2:error] [pid 843279:tid 843459] [client 86.98.90.58:14007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWyQAAALY"]
[Mon Jul 20 06:10:22.131582 2026] [security2:error] [pid 843279:tid 843459] [client 86.98.90.58:14007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWyQAAALY"]
[Mon Jul 20 06:10:22.150372 2026] [security2:error] [pid 843279:tid 843321] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWzQAAryg"]
[Mon Jul 20 06:10:22.150511 2026] [security2:error] [pid 843279:tid 843452] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CWzQAAryg"]
[Mon Jul 20 06:10:22.232455 2026] [security2:error] [pid 843279:tid 843504] [client 104.234.53.89:60577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW1wAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:22.233347 2026] [security2:error] [pid 843279:tid 843426] [client 112.213.160.112:31065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW2AAAAJU"]
[Mon Jul 20 06:10:22.233436 2026] [security2:error] [pid 843279:tid 843426] [client 112.213.160.112:31065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW2AAAAJU"]
[Mon Jul 20 06:10:22.291392 2026] [security2:error] [pid 843279:tid 843367] [remote 78.46.157.202:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4QLvqvKNcW5yy5T2CW3QAA9VY"], referer: https://mail.innspace.ca/wp-login.php
[Mon Jul 20 06:10:22.308294 2026] [security2:error] [pid 843279:tid 843502] [client 114.119.166.95:45353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ferrellroofing.com"] [uri "/commercial-roofing"] [unique_id "al4QLvqvKNcW5yy5T2CW4QAAAOE"], referer: https://www.ferrellroofing.com/commercial-roofing
[Mon Jul 20 06:10:22.352374 2026] [security2:error] [pid 843279:tid 843496] [client 57.141.18.91:63548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVcQAA2y0"]
[Mon Jul 20 06:10:22.380608 2026] [autoindex:error] [pid 843279:tid 843340] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:22.381275 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/blocks/details/"] [unique_id "al4QLvqvKNcW5yy5T2CW5AAA3Ts"]
[Mon Jul 20 06:10:22.419009 2026] [core:error] [pid 843279:tid 843508] [client 14.225.17.146:50384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WORDPRESS
[Mon Jul 20 06:10:22.419026 2026] [core:error] [pid 843279:tid 843508] [client 14.225.17.146:50384] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WORDPRESS
[Mon Jul 20 06:10:22.484989 2026] [security2:error] [pid 843279:tid 843456] [client 181.224.94.124:60538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW6wAAALM"]
[Mon Jul 20 06:10:22.485151 2026] [security2:error] [pid 843279:tid 843456] [client 181.224.94.124:60538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW6wAAALM"]
[Mon Jul 20 06:10:22.701445 2026] [security2:error] [pid 843279:tid 843449] [client 45.116.69.230:50669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW_gAAAKw"]
[Mon Jul 20 06:10:22.701543 2026] [security2:error] [pid 843279:tid 843449] [client 45.116.69.230:50669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QLvqvKNcW5yy5T2CW_gAAAKw"]
[Mon Jul 20 06:10:22.847238 2026] [security2:error] [pid 843279:tid 843434] [client 57.141.18.107:45054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QKvqvKNcW5yy5T2CVngAAnUA"]
[Mon Jul 20 06:10:22.899408 2026] [security2:error] [pid 843279:tid 843487] [client 185.132.186.55:44733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Registry-private.php"] [unique_id "al4QLvqvKNcW5yy5T2CXFAAAANI"]
[Mon Jul 20 06:10:23.156067 2026] [security2:error] [pid 843279:tid 843483] [client 41.173.37.102:13312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXLgAAAM4"]
[Mon Jul 20 06:10:23.156224 2026] [security2:error] [pid 843279:tid 843483] [client 41.173.37.102:13312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXLgAAAM4"]
[Mon Jul 20 06:10:23.248775 2026] [security2:error] [pid 843279:tid 843517] [client 20.197.195.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW9QAA70k"]
[Mon Jul 20 06:10:23.248810 2026] [security2:error] [pid 843279:tid 843517] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW9QAA70k"]
[Mon Jul 20 06:10:23.285461 2026] [security2:error] [pid 843279:tid 843436] [client 121.188.194.82:59432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QLvqvKNcW5yy5T2CXGQAAAJ8"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:23.349202 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:62182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CWygAAAK4"], referer: http://sarahholyfield.com/WORDPRESS
[Mon Jul 20 06:10:23.379343 2026] [security2:error] [pid 843279:tid 843293] [remote 52.167.144.168:9890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4QL_qvKNcW5yy5T2CXOwAAmAw"]
[Mon Jul 20 06:10:23.503606 2026] [security2:error] [pid 843279:tid 843281] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/.well-known/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXSwAAjQA"]
[Mon Jul 20 06:10:23.503787 2026] [security2:error] [pid 843279:tid 843418] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/.well-known/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXSwAAjQA"]
[Mon Jul 20 06:10:23.546033 2026] [security2:error] [pid 843279:tid 843538] [client 178.152.178.232:36004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXTgAAAQQ"]
[Mon Jul 20 06:10:23.546162 2026] [security2:error] [pid 843279:tid 843538] [client 178.152.178.232:36004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXTgAAAQQ"]
[Mon Jul 20 06:10:23.714064 2026] [security2:error] [pid 843279:tid 843404] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXYwAAx3s"]
[Mon Jul 20 06:10:23.714236 2026] [security2:error] [pid 843279:tid 843476] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4QL_qvKNcW5yy5T2CXYwAAx3s"]
[Mon Jul 20 06:10:23.935342 2026] [security2:error] [pid 843279:tid 843282] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wefile.php"] [unique_id "al4QL_qvKNcW5yy5T2CXbwABAAE"]
[Mon Jul 20 06:10:23.935498 2026] [security2:error] [pid 843279:tid 843534] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wefile.php"] [unique_id "al4QL_qvKNcW5yy5T2CXbwABAAE"]
[Mon Jul 20 06:10:23.950816 2026] [security2:error] [pid 843279:tid 843330] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXcQAArjE"]
[Mon Jul 20 06:10:23.950971 2026] [security2:error] [pid 843279:tid 843451] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QL_qvKNcW5yy5T2CXcQAArjE"]
[Mon Jul 20 06:10:23.975269 2026] [security2:error] [pid 843279:tid 843436] [client 193.19.109.247:23679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "qatestep20-132996.com"] [uri "/wp-login.php"] [unique_id "al4QL_qvKNcW5yy5T2CXcwAAAJ8"]
[Mon Jul 20 06:10:24.154704 2026] [security2:error] [pid 843279:tid 843290] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgAAA7Ak"]
[Mon Jul 20 06:10:24.154906 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/filemanager.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgAAA7Ak"]
[Mon Jul 20 06:10:24.174625 2026] [security2:error] [pid 843279:tid 843323] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgQAAkSo"]
[Mon Jul 20 06:10:24.174793 2026] [security2:error] [pid 843279:tid 843422] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXgQAAkSo"]
[Mon Jul 20 06:10:24.285697 2026] [security2:error] [pid 843279:tid 843479] [client 13.229.223.11:34242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXhwAAAMo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:10:24.379181 2026] [autoindex:error] [pid 843279:tid 843296] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:24.379764 2026] [security2:error] [pid 843279:tid 843537] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4QMPqvKNcW5yy5T2CXjQABAw8"]
[Mon Jul 20 06:10:24.629945 2026] [autoindex:error] [pid 843279:tid 843300] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:24.630627 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-admin/js/"] [unique_id "al4QMPqvKNcW5yy5T2CXngABAhM"]
[Mon Jul 20 06:10:24.639047 2026] [security2:error] [pid 843279:tid 843450] [client 106.192.104.4:58544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXpgAAAK0"]
[Mon Jul 20 06:10:24.639202 2026] [security2:error] [pid 843279:tid 843450] [client 106.192.104.4:58544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXpgAAAK0"]
[Mon Jul 20 06:10:24.749741 2026] [security2:error] [pid 843279:tid 843284] [remote 173.212.252.15:46484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXsQAA_AM"]
[Mon Jul 20 06:10:24.750056 2026] [security2:error] [pid 843279:tid 843530] [client 173.212.252.15:46484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QMPqvKNcW5yy5T2CXsQAA_AM"]
[Mon Jul 20 06:10:24.837992 2026] [security2:error] [pid 843279:tid 843319] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-admin/css/colour.php"] [unique_id "al4QMPqvKNcW5yy5T2CXtAAAmyY"]
[Mon Jul 20 06:10:24.838170 2026] [security2:error] [pid 843279:tid 843432] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-admin/css/colour.php"] [unique_id "al4QMPqvKNcW5yy5T2CXtAAAmyY"]
[Mon Jul 20 06:10:24.850521 2026] [security2:error] [pid 843279:tid 843518] [client 185.132.186.68:39513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-modules-packages.min-meta.php"] [unique_id "al4QMPqvKNcW5yy5T2CXtQAAAPA"]
[Mon Jul 20 06:10:24.903179 2026] [security2:error] [pid 843279:tid 843463] [client 121.188.194.82:59434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXmwAAALo"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:24.926395 2026] [security2:error] [pid 843279:tid 843433] [client 193.19.109.233:42699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXvgAAAJw"]
[Mon Jul 20 06:10:24.942988 2026] [security2:error] [pid 843279:tid 843501] [client 193.19.109.219:41879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4QMPqvKNcW5yy5T2CXugAAAOA"]
[Mon Jul 20 06:10:25.025803 2026] [security2:error] [pid 843279:tid 843335] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/8.php"] [unique_id "al4QMfqvKNcW5yy5T2CXxwAA7TY"]
[Mon Jul 20 06:10:25.025993 2026] [security2:error] [pid 843279:tid 843515] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/8.php"] [unique_id "al4QMfqvKNcW5yy5T2CXxwAA7TY"]
[Mon Jul 20 06:10:25.220237 2026] [security2:error] [pid 843279:tid 843339] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QMfqvKNcW5yy5T2CX0wABAjo"]
[Mon Jul 20 06:10:25.220418 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QMfqvKNcW5yy5T2CX0wABAjo"]
[Mon Jul 20 06:10:25.227738 2026] [security2:error] [pid 843279:tid 843489] [client 103.153.183.69:4640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/hosts"] [unique_id "al4QMfqvKNcW5yy5T2CX1AAAANQ"], referer: https://t.co/8aijbcelyv
[Mon Jul 20 06:10:25.254889 2026] [security2:error] [pid 843279:tid 843491] [client 57.141.18.49:20254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QLPqvKNcW5yy5T2CWVwAA1hE"]
[Mon Jul 20 06:10:25.362201 2026] [security2:error] [pid 843279:tid 843425] [client 164.100.212.184:64092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QMfqvKNcW5yy5T2CX5QAAAJQ"]
[Mon Jul 20 06:10:25.362287 2026] [security2:error] [pid 843279:tid 843425] [client 164.100.212.184:64092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QMfqvKNcW5yy5T2CX5QAAAJQ"]
[Mon Jul 20 06:10:25.525470 2026] [security2:error] [pid 843279:tid 843322] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/f6.php"] [unique_id "al4QMfqvKNcW5yy5T2CX9gAAryk"]
[Mon Jul 20 06:10:25.525660 2026] [security2:error] [pid 843279:tid 843452] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/f6.php"] [unique_id "al4QMfqvKNcW5yy5T2CX9gAAryk"]
[Mon Jul 20 06:10:25.658477 2026] [security2:error] [pid 843279:tid 843524] [client 50.116.65.227:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4QMfqvKNcW5yy5T2CYCQAAAPY"]
[Mon Jul 20 06:10:25.673404 2026] [security2:error] [pid 843279:tid 843476] [client 50.116.65.227:28706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4QMfqvKNcW5yy5T2CYCgAAAQI"]
[Mon Jul 20 06:10:26.156108 2026] [security2:error] [pid 843279:tid 843504] [client 87.199.196.181:64249] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "87.199.196.181" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4QMvqvKNcW5yy5T2CYLAAAAOM"], referer: https://www.guidehunting.com/guide-school-and-training-in-kentucky/
[Mon Jul 20 06:10:26.156246 2026] [security2:error] [pid 843279:tid 843504] [client 87.199.196.181:64249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4QMvqvKNcW5yy5T2CYLAAAAOM"], referer: https://www.guidehunting.com/guide-school-and-training-in-kentucky/
[Mon Jul 20 06:10:26.423683 2026] [security2:error] [pid 843279:tid 843462] [client 57.141.18.102:57422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QLvqvKNcW5yy5T2CW1QAAuVs"]
[Mon Jul 20 06:10:26.547064 2026] [security2:error] [pid 843279:tid 843467] [client 121.188.194.82:59436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4QMvqvKNcW5yy5T2CYLQAAAL4"], referer: http://sarakety.com/wp-login.php
[Mon Jul 20 06:10:26.571438 2026] [security2:error] [pid 843279:tid 843522] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QMvqvKNcW5yy5T2CYQQAAAPQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:26.639199 2026] [security2:error] [pid 843279:tid 843387] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QMvqvKNcW5yy5T2CYUgABBGo"]
[Mon Jul 20 06:10:26.639348 2026] [security2:error] [pid 843279:tid 843538] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QMvqvKNcW5yy5T2CYUgABBGo"]
[Mon Jul 20 06:10:26.709727 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:61947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4QMPqvKNcW5yy5T2CXrgAAAJM"], referer: http://narv.co/WORDPRESS
[Mon Jul 20 06:10:26.787438 2026] [security2:error] [pid 843279:tid 843433] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QMvqvKNcW5yy5T2CYXAAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:26.787508 2026] [security2:error] [pid 843279:tid 843513] [client 185.132.186.53:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/bypass.php"] [unique_id "al4QMvqvKNcW5yy5T2CYXwAAAOs"]
[Mon Jul 20 06:10:26.823608 2026] [security2:error] [pid 843279:tid 843391] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QMvqvKNcW5yy5T2CYYQAA824"]
[Mon Jul 20 06:10:26.823933 2026] [security2:error] [pid 843279:tid 843521] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QMvqvKNcW5yy5T2CYYQAA824"]
[Mon Jul 20 06:10:27.013276 2026] [security2:error] [pid 843279:tid 843383] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QM_qvKNcW5yy5T2CYcAAAomY"]
[Mon Jul 20 06:10:27.013571 2026] [security2:error] [pid 843279:tid 843439] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/inputs.php"] [unique_id "al4QM_qvKNcW5yy5T2CYcAAAomY"]
[Mon Jul 20 06:10:27.096540 2026] [security2:error] [pid 843279:tid 843477] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QM_qvKNcW5yy5T2CYcQAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:27.201626 2026] [security2:error] [pid 843279:tid 843407] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/classwithtostring.php"] [unique_id "al4QM_qvKNcW5yy5T2CYhAAAjH4"]
[Mon Jul 20 06:10:27.201831 2026] [security2:error] [pid 843279:tid 843417] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/classwithtostring.php"] [unique_id "al4QM_qvKNcW5yy5T2CYhAAAjH4"]
[Mon Jul 20 06:10:27.377348 2026] [security2:error] [pid 843279:tid 843449] [client 27.96.94.195:37589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QM_qvKNcW5yy5T2CYlgAAAKw"]
[Mon Jul 20 06:10:27.377461 2026] [security2:error] [pid 843279:tid 843449] [client 27.96.94.195:37589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QM_qvKNcW5yy5T2CYlgAAAKw"]
[Mon Jul 20 06:10:27.399178 2026] [security2:error] [pid 843279:tid 843301] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/themes/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYmgAA9RQ"]
[Mon Jul 20 06:10:27.399404 2026] [security2:error] [pid 843279:tid 843523] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/themes/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYmgAA9RQ"]
[Mon Jul 20 06:10:27.582913 2026] [security2:error] [pid 843279:tid 843437] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QM_qvKNcW5yy5T2CYpgAAAKA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:27.664308 2026] [security2:error] [pid 843279:tid 843317] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-blog.php"] [unique_id "al4QM_qvKNcW5yy5T2CYsgAAliQ"]
[Mon Jul 20 06:10:27.664474 2026] [security2:error] [pid 843279:tid 843427] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-blog.php"] [unique_id "al4QM_qvKNcW5yy5T2CYsgAAliQ"]
[Mon Jul 20 06:10:27.846193 2026] [security2:error] [pid 843279:tid 843462] [client 14.225.17.146:57147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYrgAAALk"], referer: https://narv.co/WORDPRESS
[Mon Jul 20 06:10:27.914137 2026] [autoindex:error] [pid 843279:tid 843397] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:27.914772 2026] [security2:error] [pid 843279:tid 843459] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/js/jquery/"] [unique_id "al4QM_qvKNcW5yy5T2CYwQAAtnQ"]
[Mon Jul 20 06:10:28.155294 2026] [security2:error] [pid 843279:tid 843422] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QNPqvKNcW5yy5T2CYywAAAJE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:28.185664 2026] [security2:error] [pid 843279:tid 843450] [client 50.116.65.227:59334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QNPqvKNcW5yy5T2CY2wAAAK0"]
[Mon Jul 20 06:10:28.201047 2026] [security2:error] [pid 843279:tid 843457] [client 50.116.65.227:28722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4QNPqvKNcW5yy5T2CY3AAAALQ"]
[Mon Jul 20 06:10:28.214352 2026] [security2:error] [pid 843279:tid 843507] [client 103.153.183.69:4640] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//proc/self/environ"] [unique_id "al4QNPqvKNcW5yy5T2CY3QAAAOU"], referer: https://www.facebook.com/
[Mon Jul 20 06:10:28.220036 2026] [security2:error] [pid 843279:tid 843302] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QNPqvKNcW5yy5T2CY4AAA3RU"]
[Mon Jul 20 06:10:28.220230 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-content/admin.php"] [unique_id "al4QNPqvKNcW5yy5T2CY4AAA3RU"]
[Mon Jul 20 06:10:28.380230 2026] [security2:error] [pid 843279:tid 843429] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QNPqvKNcW5yy5T2CY8wAAAJg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:28.451508 2026] [security2:error] [pid 843279:tid 843288] [remote 5.161.225.162:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4QNPqvKNcW5yy5T2CY-AAAjAc"]
[Mon Jul 20 06:10:28.472820 2026] [security2:error] [pid 843279:tid 843418] [client 57.141.18.46:51736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QMPqvKNcW5yy5T2CXfQAAjQU"]
[Mon Jul 20 06:10:28.694314 2026] [security2:error] [pid 843279:tid 843513] [client 185.132.186.62:20659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/content-index.php"] [unique_id "al4QNPqvKNcW5yy5T2CZDAAAAOs"]
[Mon Jul 20 06:10:29.192224 2026] [security2:error] [pid 843279:tid 843447] [client 45.157.112.60:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QNfqvKNcW5yy5T2CZKgAAAKo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:29.293667 2026] [security2:error] [pid 843279:tid 843510] [client 14.225.17.146:55387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4QNfqvKNcW5yy5T2CZIwAAAOg"]
[Mon Jul 20 06:10:29.319445 2026] [security2:error] [pid 843279:tid 843507] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QNfqvKNcW5yy5T2CZPAAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:29.319683 2026] [security2:error] [pid 843279:tid 843507] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QNfqvKNcW5yy5T2CZPAAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:29.329663 2026] [proxy:error] [pid 843279:tid 843473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:29.329700 2026] [proxy_http:error] [pid 843279:tid 843473] [client 185.247.137.170:60047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:29.330484 2026] [proxy:error] [pid 843279:tid 843473] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:29.330514 2026] [proxy_http:error] [pid 843279:tid 843473] [client 185.247.137.170:60047] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:29.333395 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:62850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYoAAAAJM"], referer: http://qualitycoatingsinspection.com/WORDPRESS
[Mon Jul 20 06:10:29.402408 2026] [security2:error] [pid 843279:tid 843418] [client 103.77.203.233:62043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QNfqvKNcW5yy5T2CZSQAAAI0"]
[Mon Jul 20 06:10:29.402636 2026] [security2:error] [pid 843279:tid 843418] [client 103.77.203.233:62043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QNfqvKNcW5yy5T2CZSQAAAI0"]
[Mon Jul 20 06:10:29.915012 2026] [security2:error] [pid 843279:tid 843357] [remote 5.161.225.162:57736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4QNfqvKNcW5yy5T2CZbwAAtkw"], referer: https://daseighty.net/wp-login.php
[Mon Jul 20 06:10:30.127625 2026] [proxy:error] [pid 843279:tid 843520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:30.127698 2026] [proxy_http:error] [pid 843279:tid 843520] [client 205.210.31.46:62564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:30.128380 2026] [proxy:error] [pid 843279:tid 843520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:10:30.128422 2026] [proxy_http:error] [pid 843279:tid 843520] [client 205.210.31.46:62564] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:10:30.283713 2026] [security2:error] [pid 843279:tid 843411] [client 57.141.18.25:63492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QMfqvKNcW5yy5T2CYEAAAhj4"]
[Mon Jul 20 06:10:30.355924 2026] [security2:error] [pid 843279:tid 843382] [remote 5.161.225.162:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4QNvqvKNcW5yy5T2CZngAA-2U"]
[Mon Jul 20 06:10:30.362435 2026] [security2:error] [pid 843279:tid 843495] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZlQAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:30.419545 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:61755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZjwAAAKQ"], referer: https://qualitycoatingsinspection.com/WORDPRESS
[Mon Jul 20 06:10:30.490096 2026] [security2:error] [pid 843279:tid 843338] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ms-edit.php"] [unique_id "al4QNvqvKNcW5yy5T2CZpgAA_zk"]
[Mon Jul 20 06:10:30.490243 2026] [security2:error] [pid 843279:tid 843533] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ms-edit.php"] [unique_id "al4QNvqvKNcW5yy5T2CZpgAA_zk"]
[Mon Jul 20 06:10:30.507185 2026] [security2:error] [pid 843279:tid 843501] [client 57.141.18.63:54878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QMfqvKNcW5yy5T2CYHgAA4DA"]
[Mon Jul 20 06:10:30.690153 2026] [security2:error] [pid 843279:tid 843436] [client 50.116.65.227:23822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QNvqvKNcW5yy5T2CZtQAAAJ8"]
[Mon Jul 20 06:10:30.696167 2026] [security2:error] [pid 843279:tid 843396] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/cgi-bin/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZtgAAr3M"]
[Mon Jul 20 06:10:30.696367 2026] [security2:error] [pid 843279:tid 843452] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/cgi-bin/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZtgAAr3M"]
[Mon Jul 20 06:10:30.700011 2026] [security2:error] [pid 843279:tid 843460] [client 50.116.65.227:23830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QNvqvKNcW5yy5T2CZtwAAALc"]
[Mon Jul 20 06:10:30.712802 2026] [security2:error] [pid 843279:tid 843362] [remote 5.161.225.162:51310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4QNvqvKNcW5yy5T2CZuQAAv1E"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 06:10:30.761798 2026] [core:error] [pid 843279:tid 843484] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:30.761830 2026] [core:error] [pid 843279:tid 843484] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:30.916955 2026] [autoindex:error] [pid 843279:tid 843408] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:30.918088 2026] [security2:error] [pid 843279:tid 843520] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/css/dist/"] [unique_id "al4QNvqvKNcW5yy5T2CZ0AAA8n8"]
[Mon Jul 20 06:10:31.009930 2026] [security2:error] [pid 843279:tid 843507] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ2AAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:31.212107 2026] [security2:error] [pid 843279:tid 843513] [client 185.132.186.65:38023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin/controller/extension/extension/alfa.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ6QAAAOs"]
[Mon Jul 20 06:10:31.255342 2026] [security2:error] [pid 843279:tid 843473] [client 66.249.70.104:56706] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.hardman.international"] [uri "/robots.txt"] [unique_id "al4QN_qvKNcW5yy5T2CZ7AAAAMQ"]
[Mon Jul 20 06:10:31.289525 2026] [security2:error] [pid 843279:tid 843443] [client 50.116.65.227:23858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ3gAAAKY"]
[Mon Jul 20 06:10:31.295632 2026] [security2:error] [pid 843279:tid 843406] [remote 45.90.123.233:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ7wAAzn0"]
[Mon Jul 20 06:10:31.368484 2026] [security2:error] [pid 843279:tid 843431] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ8AAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:31.504883 2026] [security2:error] [pid 843279:tid 843290] [remote 45.90.123.233:58388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CaCwAApAk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:31.524055 2026] [security2:error] [pid 843279:tid 843526] [client 50.116.65.227:23870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ8gAAAPg"]
[Mon Jul 20 06:10:31.544187 2026] [security2:error] [pid 843279:tid 843497] [client 57.141.18.69:38018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QM_qvKNcW5yy5T2CYdgAA3AA"]
[Mon Jul 20 06:10:31.555526 2026] [security2:error] [pid 843279:tid 843412] [client 114.119.146.114:21881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oswegooperatheater.com"] [uri "/tag/alan-martin"] [unique_id "al4QN_qvKNcW5yy5T2CaEAAAAIc"], referer: https://oswegooperatheater.com/tag/theatre
[Mon Jul 20 06:10:31.721965 2026] [security2:error] [pid 843279:tid 843522] [client 66.249.73.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.goyalsatyam.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CaEQAAAPQ"]
[Mon Jul 20 06:10:31.779997 2026] [security2:error] [pid 843279:tid 843297] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/BDKR28WP.php"] [unique_id "al4QN_qvKNcW5yy5T2CaJwAAsxA"]
[Mon Jul 20 06:10:31.780198 2026] [security2:error] [pid 843279:tid 843456] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/BDKR28WP.php"] [unique_id "al4QN_qvKNcW5yy5T2CaJwAAsxA"]
[Mon Jul 20 06:10:31.800648 2026] [security2:error] [pid 843279:tid 843491] [client 115.246.21.170:54000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.21.246.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaLAAAANY"]
[Mon Jul 20 06:10:31.800797 2026] [security2:error] [pid 843279:tid 843491] [client 115.246.21.170:54000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "pscmedicalbilling.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaLAAAANY"]
[Mon Jul 20 06:10:31.802221 2026] [security2:error] [pid 843279:tid 843457] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QN_qvKNcW5yy5T2CaKgAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:31.873810 2026] [security2:error] [pid 843279:tid 843454] [client 103.141.108.143:54897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaNAAAALE"]
[Mon Jul 20 06:10:31.874148 2026] [security2:error] [pid 843279:tid 843454] [client 103.141.108.143:54897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QN_qvKNcW5yy5T2CaNAAAALE"]
[Mon Jul 20 06:10:31.960023 2026] [security2:error] [pid 843279:tid 843450] [client 14.225.17.146:53116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ9AAAAK0"], referer: http://bruceledewitz.com/WORDPRESS
[Mon Jul 20 06:10:32.032484 2026] [autoindex:error] [pid 843279:tid 843288] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:32.033213 2026] [security2:error] [pid 843279:tid 843463] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/l10n/"] [unique_id "al4QOPqvKNcW5yy5T2CaRAAAugc"]
[Mon Jul 20 06:10:32.081545 2026] [security2:error] [pid 843279:tid 843434] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QOPqvKNcW5yy5T2CaQgAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:32.144555 2026] [security2:error] [pid 843279:tid 843307] [remote 192.241.143.148:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CaTgAAnBo"]
[Mon Jul 20 06:10:32.271086 2026] [security2:error] [pid 843279:tid 843484] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-content/uploads/index.php"] [unique_id "al4QOPqvKNcW5yy5T2CaVAAAzy8"]
[Mon Jul 20 06:10:32.287679 2026] [security2:error] [pid 843279:tid 843423] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CaWwAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:32.335149 2026] [security2:error] [pid 843279:tid 843363] [remote 192.241.143.148:34762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CaYgAA-lI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:32.487744 2026] [security2:error] [pid 843279:tid 843366] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/abcd.php"] [unique_id "al4QOPqvKNcW5yy5T2CaeQAAi1U"]
[Mon Jul 20 06:10:32.487926 2026] [security2:error] [pid 843279:tid 843416] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/abcd.php"] [unique_id "al4QOPqvKNcW5yy5T2CaeQAAi1U"]
[Mon Jul 20 06:10:32.541534 2026] [security2:error] [pid 843279:tid 843495] [client 150.228.148.150:6111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CafwAAANo"]
[Mon Jul 20 06:10:32.546313 2026] [security2:error] [pid 843279:tid 843495] [client 150.228.148.150:6111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CafwAAANo"]
[Mon Jul 20 06:10:32.582520 2026] [security2:error] [pid 843279:tid 843425] [client 181.224.94.124:10078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CagAAAAJQ"]
[Mon Jul 20 06:10:32.582663 2026] [security2:error] [pid 843279:tid 843425] [client 181.224.94.124:10078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CagAAAAJQ"]
[Mon Jul 20 06:10:32.695422 2026] [security2:error] [pid 843279:tid 843367] [remote 173.249.4.11:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CahgAA_FY"]
[Mon Jul 20 06:10:32.783836 2026] [security2:error] [pid 843279:tid 843451] [client 193.19.109.243:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CajgAAAK4"]
[Mon Jul 20 06:10:32.784082 2026] [security2:error] [pid 843279:tid 843493] [client 193.19.109.246:57247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4QOPqvKNcW5yy5T2CajQAAANg"]
[Mon Jul 20 06:10:32.929826 2026] [security2:error] [pid 843279:tid 843429] [client 57.141.18.120:45690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QNPqvKNcW5yy5T2CZFQAAmDw"]
[Mon Jul 20 06:10:32.949362 2026] [security2:error] [pid 843279:tid 843533] [client 103.95.123.246:19164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CangAAAP8"]
[Mon Jul 20 06:10:32.949488 2026] [security2:error] [pid 843279:tid 843533] [client 103.95.123.246:19164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CangAAAP8"]
[Mon Jul 20 06:10:32.953362 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:14830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaogAAAQA"]
[Mon Jul 20 06:10:32.953470 2026] [security2:error] [pid 843279:tid 843534] [client 86.98.90.58:14830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaogAAAQA"]
[Mon Jul 20 06:10:32.999172 2026] [security2:error] [pid 843279:tid 843356] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaqwAAh0s"]
[Mon Jul 20 06:10:32.999432 2026] [security2:error] [pid 843279:tid 843412] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOPqvKNcW5yy5T2CaqwAAh0s"]
[Mon Jul 20 06:10:33.012926 2026] [security2:error] [pid 843279:tid 843449] [client 57.141.18.104:32904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QNPqvKNcW5yy5T2CZGwAArDo"]
[Mon Jul 20 06:10:33.032053 2026] [security2:error] [pid 843279:tid 843477] [client 112.213.160.112:8647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CarQAAAMg"]
[Mon Jul 20 06:10:33.032215 2026] [security2:error] [pid 843279:tid 843477] [client 112.213.160.112:8647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CarQAAAMg"]
[Mon Jul 20 06:10:33.185654 2026] [security2:error] [pid 843279:tid 843520] [client 185.132.186.99:65017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/system_cache.php%20"] [unique_id "al4QOfqvKNcW5yy5T2CatgAAAPI"]
[Mon Jul 20 06:10:33.355189 2026] [security2:error] [pid 843279:tid 843448] [client 45.116.69.230:51167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CavQAAAKs"]
[Mon Jul 20 06:10:33.355439 2026] [security2:error] [pid 843279:tid 843448] [client 45.116.69.230:51167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2CavQAAAKs"]
[Mon Jul 20 06:10:33.442151 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QOfqvKNcW5yy5T2CavwAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:33.732397 2026] [security2:error] [pid 843279:tid 843473] [client 41.173.37.102:13750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2Ca3gAAAMQ"]
[Mon Jul 20 06:10:33.733506 2026] [security2:error] [pid 843279:tid 843473] [client 41.173.37.102:13750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QOfqvKNcW5yy5T2Ca3gAAAMQ"]
[Mon Jul 20 06:10:34.010212 2026] [security2:error] [pid 843279:tid 843450] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca9wAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.138103 2026] [security2:error] [pid 843279:tid 843364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file15.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca-wABAVM"]
[Mon Jul 20 06:10:34.138349 2026] [security2:error] [pid 843279:tid 843535] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file15.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca-wABAVM"]
[Mon Jul 20 06:10:34.208144 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca_gAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.208368 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2Ca_gAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.325925 2026] [security2:error] [pid 843279:tid 843408] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/jp.php"] [unique_id "al4QOvqvKNcW5yy5T2CbDQAAkX8"]
[Mon Jul 20 06:10:34.326139 2026] [security2:error] [pid 843279:tid 843422] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/jp.php"] [unique_id "al4QOvqvKNcW5yy5T2CbDQAAkX8"]
[Mon Jul 20 06:10:34.502989 2026] [security2:error] [pid 843279:tid 843496] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QOvqvKNcW5yy5T2CbGQAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.548049 2026] [security2:error] [pid 843279:tid 843301] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/f35.php"] [unique_id "al4QOvqvKNcW5yy5T2CbIgAA7BQ"]
[Mon Jul 20 06:10:34.548280 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/f35.php"] [unique_id "al4QOvqvKNcW5yy5T2CbIgAA7BQ"]
[Mon Jul 20 06:10:34.578763 2026] [security2:error] [pid 843279:tid 843462] [client 57.141.18.34:37030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QNvqvKNcW5yy5T2CZgAAAuUg"]
[Mon Jul 20 06:10:34.608897 2026] [security2:error] [pid 843279:tid 843392] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbJAAAq28"]
[Mon Jul 20 06:10:34.609087 2026] [security2:error] [pid 843279:tid 843448] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbJAAAq28"]
[Mon Jul 20 06:10:34.691347 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QOvqvKNcW5yy5T2CbLgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:34.737178 2026] [security2:error] [pid 843279:tid 843282] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-load.php"] [unique_id "al4QOvqvKNcW5yy5T2CbMQAAvQE"]
[Mon Jul 20 06:10:34.737385 2026] [security2:error] [pid 843279:tid 843466] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-load.php"] [unique_id "al4QOvqvKNcW5yy5T2CbMQAAvQE"]
[Mon Jul 20 06:10:34.806293 2026] [security2:error] [pid 843279:tid 843305] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbOQABABg"]
[Mon Jul 20 06:10:34.806566 2026] [security2:error] [pid 843279:tid 843534] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QOvqvKNcW5yy5T2CbOQABABg"]
[Mon Jul 20 06:10:34.870110 2026] [security2:error] [pid 843279:tid 843426] [client 14.225.17.146:62296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4QOfqvKNcW5yy5T2CazQAAAJU"], referer: http://iagdevelopments.com/WORDPRESS
[Mon Jul 20 06:10:34.938163 2026] [security2:error] [pid 843279:tid 843318] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/xyn.php"] [unique_id "al4QOvqvKNcW5yy5T2CbQAAAkyU"]
[Mon Jul 20 06:10:34.938373 2026] [security2:error] [pid 843279:tid 843424] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/xyn.php"] [unique_id "al4QOvqvKNcW5yy5T2CbQAAAkyU"]
[Mon Jul 20 06:10:34.986433 2026] [security2:error] [pid 843279:tid 843537] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QOvqvKNcW5yy5T2CbPwAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.132838 2026] [security2:error] [pid 843279:tid 843467] [client 185.132.186.55:57845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/modern/colors.css.php"] [unique_id "al4QO_qvKNcW5yy5T2CbUwAAAL4"]
[Mon Jul 20 06:10:35.142380 2026] [autoindex:error] [pid 843279:tid 843405] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:35.142963 2026] [security2:error] [pid 843279:tid 843432] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-includes/assets/"] [unique_id "al4QO_qvKNcW5yy5T2CbUgAAm3w"]
[Mon Jul 20 06:10:35.193437 2026] [security2:error] [pid 843279:tid 843309] [remote 173.212.252.15:40672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbWwAA7Rw"]
[Mon Jul 20 06:10:35.241550 2026] [security2:error] [pid 843279:tid 843459] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbYQAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.656993 2026] [security2:error] [pid 843279:tid 843308] [remote 173.212.252.15:40672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbgwAAvxs"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:10:35.741448 2026] [security2:error] [pid 843279:tid 843414] [client 106.192.104.4:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QO_qvKNcW5yy5T2CbhwAAAIk"]
[Mon Jul 20 06:10:35.741619 2026] [security2:error] [pid 843279:tid 843414] [client 106.192.104.4:59045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QO_qvKNcW5yy5T2CbhwAAAIk"]
[Mon Jul 20 06:10:35.757691 2026] [security2:error] [pid 843279:tid 843448] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QO_qvKNcW5yy5T2CbhQAAAKs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.762473 2026] [security2:error] [pid 843279:tid 843519] [client 57.141.18.42:20988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CZ2QAA8Vo"]
[Mon Jul 20 06:10:35.822834 2026] [security2:error] [pid 843279:tid 843452] [client 14.225.17.146:54566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4QO_qvKNcW5yy5T2CbiAAAAK8"], referer: https://iagdevelopments.com/WORDPRESS
[Mon Jul 20 06:10:35.925221 2026] [security2:error] [pid 843279:tid 843426] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QO_qvKNcW5yy5T2CbmQAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:35.994125 2026] [autoindex:error] [pid 843279:tid 843292] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:35.994849 2026] [security2:error] [pid 843279:tid 843447] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al4QO_qvKNcW5yy5T2CbmgAAqgs"]
[Mon Jul 20 06:10:36.000976 2026] [security2:error] [pid 843279:tid 843432] [client 164.100.212.184:54813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbnQAAAJs"]
[Mon Jul 20 06:10:36.001064 2026] [security2:error] [pid 843279:tid 843432] [client 164.100.212.184:54813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbnQAAAJs"]
[Mon Jul 20 06:10:36.177482 2026] [security2:error] [pid 843279:tid 843430] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QPPqvKNcW5yy5T2CbpgAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:36.188121 2026] [security2:error] [pid 843279:tid 843376] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ccc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbsgAAhV8"]
[Mon Jul 20 06:10:36.188361 2026] [security2:error] [pid 843279:tid 843410] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ccc.php"] [unique_id "al4QPPqvKNcW5yy5T2CbsgAAhV8"]
[Mon Jul 20 06:10:36.470700 2026] [security2:error] [pid 843279:tid 843500] [client 57.141.18.84:45536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QN_qvKNcW5yy5T2CaGwAA3yw"]
[Mon Jul 20 06:10:36.490013 2026] [security2:error] [pid 843279:tid 843529] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPPqvKNcW5yy5T2CbwwAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:36.732590 2026] [core:error] [pid 843279:tid 843491] [client 14.225.17.146:63873] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WORDPRESS
[Mon Jul 20 06:10:36.732613 2026] [core:error] [pid 843279:tid 843491] [client 14.225.17.146:63873] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WORDPRESS
[Mon Jul 20 06:10:36.763289 2026] [security2:error] [pid 843279:tid 843365] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/w.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb4QAAklQ"]
[Mon Jul 20 06:10:36.763428 2026] [security2:error] [pid 843279:tid 843423] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/w.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb4QAAklQ"]
[Mon Jul 20 06:10:36.957559 2026] [security2:error] [pid 843279:tid 843326] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb7wAApy0"]
[Mon Jul 20 06:10:36.957809 2026] [security2:error] [pid 843279:tid 843444] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb7wAApy0"]
[Mon Jul 20 06:10:37.081405 2026] [security2:error] [pid 843279:tid 843529] [client 185.132.186.91:61567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/adminfus.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb9AAAAPs"]
[Mon Jul 20 06:10:37.131026 2026] [security2:error] [pid 843279:tid 843454] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb-QAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.131225 2026] [security2:error] [pid 843279:tid 843454] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb-QAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.149147 2026] [security2:error] [pid 843279:tid 843343] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/FWAZ.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb_QAAxz4"]
[Mon Jul 20 06:10:37.149329 2026] [security2:error] [pid 843279:tid 843476] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/FWAZ.php"] [unique_id "al4QPfqvKNcW5yy5T2Cb_QAAxz4"]
[Mon Jul 20 06:10:37.240740 2026] [security2:error] [pid 843279:tid 843359] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QPfqvKNcW5yy5T2CcAQAA5k4"]
[Mon Jul 20 06:10:37.240902 2026] [security2:error] [pid 843279:tid 843508] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QPfqvKNcW5yy5T2CcAQAA5k4"]
[Mon Jul 20 06:10:37.256160 2026] [security2:error] [pid 843279:tid 843315] [remote 173.249.4.11:14290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2CcAgAAoiI"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:10:37.301250 2026] [security2:error] [pid 843279:tid 843502] [client 74.7.175.151:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4QPfqvKNcW5yy5T2CcCQAAAOE"]
[Mon Jul 20 06:10:37.304167 2026] [security2:error] [pid 843279:tid 843484] [client 74.7.175.151:52270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4QPfqvKNcW5yy5T2CcAwAAz1s"]
[Mon Jul 20 06:10:37.326436 2026] [security2:error] [pid 843279:tid 843419] [client 57.141.18.83:46554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QOPqvKNcW5yy5T2CaYAAAjjY"]
[Mon Jul 20 06:10:37.367728 2026] [security2:error] [pid 843279:tid 843368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/miru1.php"] [unique_id "al4QPfqvKNcW5yy5T2CcDQAAv1c"]
[Mon Jul 20 06:10:37.368000 2026] [security2:error] [pid 843279:tid 843468] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/miru1.php"] [unique_id "al4QPfqvKNcW5yy5T2CcDQAAv1c"]
[Mon Jul 20 06:10:37.440060 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcDAAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.586997 2026] [security2:error] [pid 843279:tid 843504] [client 14.225.17.146:54368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcCwAAAOM"], referer: http://www.justinagrayman.com/WORDPRESS
[Mon Jul 20 06:10:37.629485 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:63871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcGwAAAIU"], referer: http://adultdaycarereno.com/WORDPRESS
[Mon Jul 20 06:10:37.709900 2026] [security2:error] [pid 843279:tid 843518] [client 14.225.17.146:63862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb2AAAAPA"], referer: http://entuvy.com/WORDPRESS
[Mon Jul 20 06:10:37.780766 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2CcOQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:37.926301 2026] [security2:error] [pid 843279:tid 843407] [remote 5.161.225.162:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QPfqvKNcW5yy5T2CcSgAAun4"]
[Mon Jul 20 06:10:38.329577 2026] [security2:error] [pid 843279:tid 843392] [remote 162.19.86.63:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcYAAA3G8"]
[Mon Jul 20 06:10:38.470013 2026] [security2:error] [pid 843279:tid 843515] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QPvqvKNcW5yy5T2CcZgAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:38.472293 2026] [security2:error] [pid 843279:tid 843513] [client 193.19.109.234:38507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcbwAAAOs"]
[Mon Jul 20 06:10:38.508139 2026] [security2:error] [pid 843279:tid 843317] [remote 162.19.86.63:43964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcegAA2SQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:10:38.516240 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:64974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4QPvqvKNcW5yy5T2CcbgAAAJM"], referer: https://adultdaycarereno.com/WORDPRESS
[Mon Jul 20 06:10:38.640978 2026] [security2:error] [pid 843279:tid 843281] [remote 192.241.143.148:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcgwAA4wA"]
[Mon Jul 20 06:10:38.749600 2026] [security2:error] [pid 843279:tid 843488] [client 14.225.17.146:54329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4QPfqvKNcW5yy5T2CcFgAAANM"], referer: http://mazzucelli.com/WORDPRESS
[Mon Jul 20 06:10:38.853085 2026] [security2:error] [pid 843279:tid 843291] [remote 192.241.143.148:34768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4QPvqvKNcW5yy5T2CcmAAA3Qo"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:10:38.911851 2026] [security2:error] [pid 843279:tid 843405] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/aa.php"] [unique_id "al4QPvqvKNcW5yy5T2CcnwAAnXw"]
[Mon Jul 20 06:10:38.912115 2026] [security2:error] [pid 843279:tid 843434] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/aa.php"] [unique_id "al4QPvqvKNcW5yy5T2CcnwAAnXw"]
[Mon Jul 20 06:10:39.054668 2026] [security2:error] [pid 843279:tid 843449] [client 158.173.89.95:44787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QP_qvKNcW5yy5T2CcqgAAAKw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:39.054959 2026] [security2:error] [pid 843279:tid 843484] [client 185.132.186.53:63869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/media-widget-vide02.php"] [unique_id "al4QP_qvKNcW5yy5T2CcqQAAAM8"]
[Mon Jul 20 06:10:39.100364 2026] [security2:error] [pid 843279:tid 843300] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/122.php"] [unique_id "al4QP_qvKNcW5yy5T2CcrAAA-xM"]
[Mon Jul 20 06:10:39.100564 2026] [security2:error] [pid 843279:tid 843529] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/122.php"] [unique_id "al4QP_qvKNcW5yy5T2CcrAAA-xM"]
[Mon Jul 20 06:10:39.167145 2026] [security2:error] [pid 843279:tid 843453] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2CcsgAAALA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:39.204281 2026] [security2:error] [pid 843279:tid 843312] [remote 124.55.178.99:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2CcuAAA8h8"]
[Mon Jul 20 06:10:39.268621 2026] [security2:error] [pid 843279:tid 843334] [remote 57.141.18.110:26924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4QP_qvKNcW5yy5T2CcvgAAsTU"]
[Mon Jul 20 06:10:39.288973 2026] [security2:error] [pid 843279:tid 843371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/get.php"] [unique_id "al4QP_qvKNcW5yy5T2CcwQAA_Fo"]
[Mon Jul 20 06:10:39.289182 2026] [security2:error] [pid 843279:tid 843530] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/get.php"] [unique_id "al4QP_qvKNcW5yy5T2CcwQAA_Fo"]
[Mon Jul 20 06:10:39.300992 2026] [security2:error] [pid 843279:tid 843307] [remote 202.51.202.242:43558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2CcvwAAuRo"]
[Mon Jul 20 06:10:39.478775 2026] [security2:error] [pid 843279:tid 843469] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QP_qvKNcW5yy5T2CczgAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:39.510829 2026] [security2:error] [pid 843279:tid 843531] [client 27.96.94.195:37230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc2QAAAP0"]
[Mon Jul 20 06:10:39.510977 2026] [security2:error] [pid 843279:tid 843531] [client 27.96.94.195:37230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc2QAAAP0"]
[Mon Jul 20 06:10:39.784738 2026] [security2:error] [pid 843279:tid 843523] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc8AAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:39.890220 2026] [security2:error] [pid 843279:tid 843478] [client 103.77.203.233:62577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc_QAAAMk"]
[Mon Jul 20 06:10:39.890491 2026] [security2:error] [pid 843279:tid 843478] [client 103.77.203.233:62577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc_QAAAMk"]
[Mon Jul 20 06:10:39.950647 2026] [security2:error] [pid 843279:tid 843443] [client 14.225.17.146:54332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4QPvqvKNcW5yy5T2CcVAAAAKY"]
[Mon Jul 20 06:10:40.182726 2026] [security2:error] [pid 843279:tid 843496] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QQPqvKNcW5yy5T2CdFQAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:40.189073 2026] [security2:error] [pid 843279:tid 843442] [client 185.63.81.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QP_qvKNcW5yy5T2Cc0AAAAKU"]
[Mon Jul 20 06:10:40.201582 2026] [security2:error] [pid 843279:tid 843351] [remote 124.55.178.99:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdHgAAuUY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:10:40.386930 2026] [security2:error] [pid 843279:tid 843443] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdKgAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:40.437392 2026] [security2:error] [pid 843279:tid 843357] [remote 45.150.79.142:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdLwAAk0w"]
[Mon Jul 20 06:10:40.510350 2026] [security2:error] [pid 843279:tid 843346] [remote 110.249.202.73:55076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2000-commission/2000-commission-maps-and-population-tables/"] [unique_id "al4QQPqvKNcW5yy5T2CdNgAA50E"]
[Mon Jul 20 06:10:40.598941 2026] [security2:error] [pid 843279:tid 843337] [remote 45.150.79.142:40394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdPwAAiDg"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:40.675082 2026] [security2:error] [pid 843279:tid 843360] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/as.php"] [unique_id "al4QQPqvKNcW5yy5T2CdQgAAuU8"]
[Mon Jul 20 06:10:40.675330 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/as.php"] [unique_id "al4QQPqvKNcW5yy5T2CdQgAAuU8"]
[Mon Jul 20 06:10:40.677931 2026] [security2:error] [pid 843279:tid 843507] [client 57.141.18.67:52888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QO_qvKNcW5yy5T2CbggAA5T0"]
[Mon Jul 20 06:10:40.880379 2026] [security2:error] [pid 843279:tid 843382] [remote 5.161.225.162:51322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QQPqvKNcW5yy5T2CdUwAAz2U"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:41.466528 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQfqvKNcW5yy5T2CdfQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:41.466730 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQfqvKNcW5yy5T2CdfQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:41.679915 2026] [security2:error] [pid 843279:tid 843448] [client 50.116.65.227:23862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4QQfqvKNcW5yy5T2CdjQAAAKs"]
[Mon Jul 20 06:10:41.684480 2026] [security2:error] [pid 843279:tid 843434] [client 14.225.17.146:57137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4QQPqvKNcW5yy5T2CdHQAAAJ0"]
[Mon Jul 20 06:10:41.880283 2026] [security2:error] [pid 843279:tid 843521] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdlAAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:41.938015 2026] [security2:error] [pid 843279:tid 843421] [client 50.116.65.227:23874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4QQfqvKNcW5yy5T2CdoQAAAJA"]
[Mon Jul 20 06:10:41.949079 2026] [security2:error] [pid 843279:tid 843535] [client 50.116.65.227:55694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4QQfqvKNcW5yy5T2CdowAAAQE"]
[Mon Jul 20 06:10:41.980918 2026] [security2:error] [pid 843279:tid 843479] [client 57.141.18.119:39138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QPPqvKNcW5yy5T2Cb7gAAyk0"]
[Mon Jul 20 06:10:42.043578 2026] [security2:error] [pid 843279:tid 843513] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQvqvKNcW5yy5T2CdpwAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:42.180706 2026] [security2:error] [pid 843279:tid 843388] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ccou.php"] [unique_id "al4QQvqvKNcW5yy5T2CdtAAA02s"]
[Mon Jul 20 06:10:42.180900 2026] [security2:error] [pid 843279:tid 843488] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ccou.php"] [unique_id "al4QQvqvKNcW5yy5T2CdtAAA02s"]
[Mon Jul 20 06:10:42.276832 2026] [security2:error] [pid 843279:tid 843473] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QQvqvKNcW5yy5T2CdtQAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:42.319726 2026] [security2:error] [pid 843279:tid 843493] [client 193.19.109.227:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/wp-login.php"] [unique_id "al4QQvqvKNcW5yy5T2CduQAAANg"]
[Mon Jul 20 06:10:42.355730 2026] [security2:error] [pid 843279:tid 843411] [client 13.201.64.214:25262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2CdvwAAAIY"]
[Mon Jul 20 06:10:42.355878 2026] [security2:error] [pid 843279:tid 843411] [client 13.201.64.214:25262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2CdvwAAAIY"]
[Mon Jul 20 06:10:42.394499 2026] [security2:error] [pid 843279:tid 843402] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/w3lls.php"] [unique_id "al4QQvqvKNcW5yy5T2CdwwAA43k"]
[Mon Jul 20 06:10:42.394680 2026] [security2:error] [pid 843279:tid 843504] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/w3lls.php"] [unique_id "al4QQvqvKNcW5yy5T2CdwwAA43k"]
[Mon Jul 20 06:10:42.584360 2026] [security2:error] [pid 843279:tid 843296] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/test1.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd0QAA-g8"]
[Mon Jul 20 06:10:42.584705 2026] [security2:error] [pid 843279:tid 843528] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/test1.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd0QAA-g8"]
[Mon Jul 20 06:10:42.619715 2026] [security2:error] [pid 843279:tid 843479] [client 185.132.186.83:46767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/blocks/group/wp-style.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd1AAAAMo"]
[Mon Jul 20 06:10:42.645334 2026] [security2:error] [pid 843279:tid 843443] [client 103.141.108.143:55353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd2gAAAKY"]
[Mon Jul 20 06:10:42.645722 2026] [security2:error] [pid 843279:tid 843443] [client 103.141.108.143:55353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd2gAAAKY"]
[Mon Jul 20 06:10:42.803191 2026] [security2:error] [pid 843279:tid 843394] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/database.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd4QAA5XE"]
[Mon Jul 20 06:10:42.803425 2026] [security2:error] [pid 843279:tid 843507] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/database.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd4QAA5XE"]
[Mon Jul 20 06:10:42.925202 2026] [security2:error] [pid 843279:tid 843334] [remote 147.50.252.213:40080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd7wABBDU"]
[Mon Jul 20 06:10:43.009061 2026] [security2:error] [pid 843279:tid 843462] [client 14.225.17.146:50339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd6AAAALk"], referer: http://chestermonty.com/WORDPRESS
[Mon Jul 20 06:10:43.026948 2026] [security2:error] [pid 843279:tid 843519] [client 14.225.17.146:57131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdgQAAAPE"]
[Mon Jul 20 06:10:43.030418 2026] [security2:error] [pid 843279:tid 843421] [client 14.225.17.146:65130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4QQvqvKNcW5yy5T2Cd4wAAAJA"], referer: http://mezzacraft.com/WORDPRESS
[Mon Jul 20 06:10:43.050118 2026] [security2:error] [pid 843279:tid 843320] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd9gAA4Cc"]
[Mon Jul 20 06:10:43.050349 2026] [security2:error] [pid 843279:tid 843501] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd9gAA4Cc"]
[Mon Jul 20 06:10:43.108206 2026] [security2:error] [pid 843279:tid 843530] [client 181.224.94.124:4289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd_AAAAPw"]
[Mon Jul 20 06:10:43.108333 2026] [security2:error] [pid 843279:tid 843530] [client 181.224.94.124:4289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd_AAAAPw"]
[Mon Jul 20 06:10:43.218356 2026] [security2:error] [pid 843279:tid 843431] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeAgAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.250797 2026] [security2:error] [pid 843279:tid 843461] [client 57.141.18.79:58802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QPvqvKNcW5yy5T2CccQAAuGA"]
[Mon Jul 20 06:10:43.314485 2026] [security2:error] [pid 843279:tid 843426] [client 50.116.65.227:55708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2Cd_gAAAJU"]
[Mon Jul 20 06:10:43.337622 2026] [security2:error] [pid 843279:tid 843418] [client 150.228.148.150:30228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeBwAAAI0"]
[Mon Jul 20 06:10:43.344044 2026] [security2:error] [pid 843279:tid 843418] [client 150.228.148.150:30228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeBwAAAI0"]
[Mon Jul 20 06:10:43.365125 2026] [security2:error] [pid 843279:tid 843460] [client 74.7.227.179:34510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeAwAAt1I"], referer: https://tejasenvironmental.com/p=437209
[Mon Jul 20 06:10:43.418507 2026] [security2:error] [pid 843279:tid 843327] [remote 147.50.252.213:40080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeEAAA7i4"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:10:43.453233 2026] [security2:error] [pid 843279:tid 843457] [client 50.116.65.227:55724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeBgAAALQ"]
[Mon Jul 20 06:10:43.467348 2026] [security2:error] [pid 843279:tid 843454] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeDQAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.638930 2026] [security2:error] [pid 843279:tid 843470] [client 86.98.90.58:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeIgAAAME"]
[Mon Jul 20 06:10:43.639123 2026] [security2:error] [pid 843279:tid 843470] [client 86.98.90.58:15603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeIgAAAME"]
[Mon Jul 20 06:10:43.679664 2026] [security2:error] [pid 843279:tid 843447] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeJAAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.766766 2026] [security2:error] [pid 843279:tid 843340] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLQAAqzs"]
[Mon Jul 20 06:10:43.767067 2026] [security2:error] [pid 843279:tid 843448] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLQAAqzs"]
[Mon Jul 20 06:10:43.774999 2026] [security2:error] [pid 843279:tid 843386] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLgAAiWk"]
[Mon Jul 20 06:10:43.775176 2026] [security2:error] [pid 843279:tid 843414] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/file.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeLgAAiWk"]
[Mon Jul 20 06:10:43.787130 2026] [security2:error] [pid 843279:tid 843507] [client 112.213.160.112:8272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeMQAAAOU"]
[Mon Jul 20 06:10:43.787237 2026] [security2:error] [pid 843279:tid 843507] [client 112.213.160.112:8272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeMQAAAOU"]
[Mon Jul 20 06:10:43.987021 2026] [security2:error] [pid 843279:tid 843349] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/777.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeQwAA7kQ"]
[Mon Jul 20 06:10:43.987314 2026] [security2:error] [pid 843279:tid 843516] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/777.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeQwAA7kQ"]
[Mon Jul 20 06:10:43.988384 2026] [security2:error] [pid 843279:tid 843497] [client 14.225.17.146:57155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeNQAAANw"], referer: https://chestermonty.com/WORDPRESS
[Mon Jul 20 06:10:43.996618 2026] [security2:error] [pid 843279:tid 843426] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QQ_qvKNcW5yy5T2CePAAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:43.998567 2026] [security2:error] [pid 843279:tid 843393] [remote 194.164.192.228:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeRQAAuHA"]
[Mon Jul 20 06:10:44.014999 2026] [security2:error] [pid 843279:tid 843454] [client 50.116.65.227:23888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4QRPqvKNcW5yy5T2CeSQAAALE"]
[Mon Jul 20 06:10:44.026685 2026] [security2:error] [pid 843279:tid 843491] [client 50.116.65.227:55750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4QRPqvKNcW5yy5T2CeSwAAANY"]
[Mon Jul 20 06:10:44.050644 2026] [security2:error] [pid 843279:tid 843476] [client 57.141.18.108:40122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QP_qvKNcW5yy5T2CcrwAAxyo"]
[Mon Jul 20 06:10:44.055479 2026] [security2:error] [pid 843279:tid 843479] [client 193.19.109.247:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifetalkswithkay.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeTAAAAMo"]
[Mon Jul 20 06:10:44.104948 2026] [security2:error] [pid 843279:tid 843431] [client 45.116.69.230:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeUAAAAJo"]
[Mon Jul 20 06:10:44.105121 2026] [security2:error] [pid 843279:tid 843431] [client 45.116.69.230:51650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeUAAAAJo"]
[Mon Jul 20 06:10:44.186317 2026] [security2:error] [pid 843279:tid 843337] [remote 194.164.192.228:35404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeWgAAwzg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:44.202354 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeXAAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:44.223668 2026] [security2:error] [pid 843279:tid 843319] [remote 91.142.222.105:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CeYQAAsCY"]
[Mon Jul 20 06:10:44.230636 2026] [security2:error] [pid 843279:tid 843342] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ssixta.php"] [unique_id "al4QRPqvKNcW5yy5T2CeYgAAlz0"]
[Mon Jul 20 06:10:44.230845 2026] [security2:error] [pid 843279:tid 843428] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ssixta.php"] [unique_id "al4QRPqvKNcW5yy5T2CeYgAAlz0"]
[Mon Jul 20 06:10:44.267212 2026] [security2:error] [pid 843279:tid 843515] [client 103.95.123.246:19629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZQAAAO0"]
[Mon Jul 20 06:10:44.267356 2026] [security2:error] [pid 843279:tid 843515] [client 103.95.123.246:19629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZQAAAO0"]
[Mon Jul 20 06:10:44.313623 2026] [security2:error] [pid 843279:tid 843422] [client 41.173.37.102:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZwAAAJE"]
[Mon Jul 20 06:10:44.313760 2026] [security2:error] [pid 843279:tid 843422] [client 41.173.37.102:14204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CeZwAAAJE"]
[Mon Jul 20 06:10:44.419580 2026] [security2:error] [pid 843279:tid 843369] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/1c.php"] [unique_id "al4QRPqvKNcW5yy5T2CebAAAuVg"]
[Mon Jul 20 06:10:44.419854 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/1c.php"] [unique_id "al4QRPqvKNcW5yy5T2CebAAAuVg"]
[Mon Jul 20 06:10:44.565489 2026] [security2:error] [pid 843279:tid 843481] [client 14.225.17.146:49302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4QQ_qvKNcW5yy5T2CeIwAAAMw"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WORDPRESS
[Mon Jul 20 06:10:44.602099 2026] [security2:error] [pid 843279:tid 843505] [client 185.132.186.53:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/buy.php"] [unique_id "al4QRPqvKNcW5yy5T2CegAAAAOQ"]
[Mon Jul 20 06:10:44.650845 2026] [security2:error] [pid 843279:tid 843359] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/test2.php"] [unique_id "al4QRPqvKNcW5yy5T2CeggAAqk4"]
[Mon Jul 20 06:10:44.651086 2026] [security2:error] [pid 843279:tid 843447] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/test2.php"] [unique_id "al4QRPqvKNcW5yy5T2CeggAAqk4"]
[Mon Jul 20 06:10:44.747973 2026] [security2:error] [pid 843279:tid 843465] [client 178.152.178.232:36710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CehAAAALw"]
[Mon Jul 20 06:10:44.748089 2026] [security2:error] [pid 843279:tid 843465] [client 178.152.178.232:36710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QRPqvKNcW5yy5T2CehAAAALw"]
[Mon Jul 20 06:10:44.809951 2026] [security2:error] [pid 843279:tid 843451] [client 74.208.214.194:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QRPqvKNcW5yy5T2CeiwAAAK4"]
[Mon Jul 20 06:10:44.898838 2026] [security2:error] [pid 843279:tid 843350] [remote 91.142.222.105:60304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4QRPqvKNcW5yy5T2CejAAAm0U"], referer: https://travelbyfire.com/wp-login.php
[Mon Jul 20 06:10:44.960133 2026] [security2:error] [pid 843279:tid 843390] [remote 57.141.18.92:64462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4QRPqvKNcW5yy5T2CekQAAjW0"]
[Mon Jul 20 06:10:45.137504 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRfqvKNcW5yy5T2CengAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.137626 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRfqvKNcW5yy5T2CengAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.160938 2026] [security2:error] [pid 843279:tid 843293] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CeoAAAtAw"]
[Mon Jul 20 06:10:45.161128 2026] [security2:error] [pid 843279:tid 843457] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CeoAAAtAw"]
[Mon Jul 20 06:10:45.401812 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QRfqvKNcW5yy5T2CesAAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.565333 2026] [security2:error] [pid 843279:tid 843353] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CewgAAsEg"]
[Mon Jul 20 06:10:45.565546 2026] [security2:error] [pid 843279:tid 843453] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CewgAAsEg"]
[Mon Jul 20 06:10:45.703662 2026] [security2:error] [pid 843279:tid 843481] [client 43.205.139.3:21238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QRfqvKNcW5yy5T2CevgAAAMw"]
[Mon Jul 20 06:10:45.744145 2026] [security2:error] [pid 843279:tid 843492] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRfqvKNcW5yy5T2CezwAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:45.814575 2026] [security2:error] [pid 843279:tid 843290] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/buy.php"] [unique_id "al4QRfqvKNcW5yy5T2Ce1wAA-gk"]
[Mon Jul 20 06:10:45.814778 2026] [security2:error] [pid 843279:tid 843528] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/buy.php"] [unique_id "al4QRfqvKNcW5yy5T2Ce1wAA-gk"]
[Mon Jul 20 06:10:46.001872 2026] [security2:error] [pid 843279:tid 843285] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ssend.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce5AAArQQ"]
[Mon Jul 20 06:10:46.002081 2026] [security2:error] [pid 843279:tid 843450] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ssend.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce5AAArQQ"]
[Mon Jul 20 06:10:46.017634 2026] [security2:error] [pid 843279:tid 843441] [client 57.141.18.73:30776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQPqvKNcW5yy5T2CdVAAApA4"]
[Mon Jul 20 06:10:46.179502 2026] [security2:error] [pid 843279:tid 843529] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce6gAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:46.179573 2026] [security2:error] [pid 843279:tid 843462] [client 106.192.104.4:59515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce8wAAALk"]
[Mon Jul 20 06:10:46.194522 2026] [security2:error] [pid 843279:tid 843462] [client 106.192.104.4:59515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce8wAAALk"]
[Mon Jul 20 06:10:46.202867 2026] [security2:error] [pid 843279:tid 843465] [client 193.19.109.248:54193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2Ce9QAAALw"]
[Mon Jul 20 06:10:46.512334 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfGAAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:46.515518 2026] [security2:error] [pid 843279:tid 843320] [remote 91.142.222.105:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfFgAA0Cc"]
[Mon Jul 20 06:10:46.544621 2026] [security2:error] [pid 843279:tid 843449] [client 57.141.18.60:39946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdcwAArGQ"]
[Mon Jul 20 06:10:46.561929 2026] [security2:error] [pid 843279:tid 843528] [client 164.100.212.184:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfHgAAAPo"]
[Mon Jul 20 06:10:46.562087 2026] [security2:error] [pid 843279:tid 843528] [client 164.100.212.184:55393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfHgAAAPo"]
[Mon Jul 20 06:10:46.747439 2026] [security2:error] [pid 843279:tid 843497] [client 3.109.4.218:26150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfLQAAANw"]
[Mon Jul 20 06:10:46.747552 2026] [security2:error] [pid 843279:tid 843497] [client 3.109.4.218:26150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QRvqvKNcW5yy5T2CfLQAAANw"]
[Mon Jul 20 06:10:46.749880 2026] [security2:error] [pid 843279:tid 843513] [client 103.153.183.69:13850] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/.env"] [unique_id "al4QRvqvKNcW5yy5T2CfMAAAAOs"], referer: https://www.reddit.com/
[Mon Jul 20 06:10:46.754425 2026] [security2:error] [pid 843279:tid 843363] [remote 216.73.216.55:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4QRvqvKNcW5yy5T2CfMQAA3lI"]
[Mon Jul 20 06:10:46.789344 2026] [security2:error] [pid 843279:tid 843308] [remote 5.252.52.249:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfNAAAwRs"]
[Mon Jul 20 06:10:46.944375 2026] [security2:error] [pid 843279:tid 843475] [client 57.141.18.12:20248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQfqvKNcW5yy5T2CdjAAAxnM"]
[Mon Jul 20 06:10:46.970425 2026] [security2:error] [pid 843279:tid 843299] [remote 5.252.52.249:41876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QRvqvKNcW5yy5T2CfPQAAiBI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:47.177783 2026] [security2:error] [pid 843279:tid 843478] [client 185.132.186.87:24395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/templates/beez3/av.php"] [unique_id "al4QR_qvKNcW5yy5T2CfSgAAAMk"]
[Mon Jul 20 06:10:47.245423 2026] [security2:error] [pid 843279:tid 843473] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QR_qvKNcW5yy5T2CfSAAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:47.342587 2026] [security2:error] [pid 843279:tid 843341] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/item.php"] [unique_id "al4QR_qvKNcW5yy5T2CfXwAA-zw"]
[Mon Jul 20 06:10:47.342811 2026] [security2:error] [pid 843279:tid 843529] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/item.php"] [unique_id "al4QR_qvKNcW5yy5T2CfXwAA-zw"]
[Mon Jul 20 06:10:47.451684 2026] [core:error] [pid 843279:tid 843437] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:47.451704 2026] [core:error] [pid 843279:tid 843437] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:10:47.536402 2026] [security2:error] [pid 843279:tid 843515] [client 14.225.17.146:52981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4QR_qvKNcW5yy5T2CfUgAAAO0"], referer: http://aljosour-alarabia.com/WORDPRESS
[Mon Jul 20 06:10:47.580218 2026] [security2:error] [pid 843279:tid 843440] [client 190.173.33.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4QR_qvKNcW5yy5T2CfVgAAozs"]
[Mon Jul 20 06:10:47.637143 2026] [security2:error] [pid 843279:tid 843447] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QR_qvKNcW5yy5T2CfdwAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:47.736372 2026] [security2:error] [pid 843279:tid 843337] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QR_qvKNcW5yy5T2CfgwAA7zg"]
[Mon Jul 20 06:10:47.736662 2026] [security2:error] [pid 843279:tid 843517] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QR_qvKNcW5yy5T2CfgwAA7zg"]
[Mon Jul 20 06:10:47.745876 2026] [security2:error] [pid 843279:tid 843527] [client 114.119.153.97:36075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4QR_qvKNcW5yy5T2CfhAAAAPk"], referer: http://www.thecreole.com?p=50750
[Mon Jul 20 06:10:47.869152 2026] [security2:error] [pid 843279:tid 843439] [client 57.141.18.97:24192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QQvqvKNcW5yy5T2CdzAAAonw"]
[Mon Jul 20 06:10:48.080235 2026] [security2:error] [pid 843279:tid 843418] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QSPqvKNcW5yy5T2CfnwAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.149639 2026] [security2:error] [pid 843279:tid 843382] [remote 91.142.222.105:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2CfrwAAk2U"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 06:10:48.190660 2026] [security2:error] [pid 843279:tid 843335] [remote 157.66.26.183:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2CfswAAvzY"]
[Mon Jul 20 06:10:48.401232 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2CfyQAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.663081 2026] [security2:error] [pid 843279:tid 843364] [remote 157.66.26.183:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf0wAAjVM"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:10:48.732350 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf3QAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.732456 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf3QAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:48.854364 2026] [security2:error] [pid 843279:tid 843355] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ss.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf5gAAp0o"]
[Mon Jul 20 06:10:48.854495 2026] [security2:error] [pid 843279:tid 843444] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ss.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf5gAAp0o"]
[Mon Jul 20 06:10:48.953970 2026] [security2:error] [pid 843279:tid 843424] [client 193.19.109.236:20831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.109.19.193.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf8wAAAJM"]
[Mon Jul 20 06:10:49.103375 2026] [security2:error] [pid 843279:tid 843400] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/hypo.php"] [unique_id "al4QSfqvKNcW5yy5T2Cf-AAAxnc"]
[Mon Jul 20 06:10:49.103595 2026] [security2:error] [pid 843279:tid 843475] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/hypo.php"] [unique_id "al4QSfqvKNcW5yy5T2Cf-AAAxnc"]
[Mon Jul 20 06:10:49.128635 2026] [security2:error] [pid 843279:tid 843503] [client 185.132.186.62:48571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-wolf-widget.php"] [unique_id "al4QSfqvKNcW5yy5T2Cf-wAAAOI"]
[Mon Jul 20 06:10:49.234076 2026] [security2:error] [pid 843279:tid 843535] [client 27.96.94.195:37285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QSfqvKNcW5yy5T2CgAwAAAQE"]
[Mon Jul 20 06:10:49.234231 2026] [security2:error] [pid 843279:tid 843535] [client 27.96.94.195:37285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QSfqvKNcW5yy5T2CgAwAAAQE"]
[Mon Jul 20 06:10:49.326743 2026] [security2:error] [pid 843279:tid 843282] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/users.php"] [unique_id "al4QSfqvKNcW5yy5T2CgDQAA9gE"]
[Mon Jul 20 06:10:49.326919 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/users.php"] [unique_id "al4QSfqvKNcW5yy5T2CgDQAA9gE"]
[Mon Jul 20 06:10:49.464401 2026] [security2:error] [pid 843279:tid 843413] [client 98.159.234.160:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QSfqvKNcW5yy5T2CgGQAAAIg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:49.535880 2026] [security2:error] [pid 843279:tid 843527] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QSfqvKNcW5yy5T2CgGgAAAPk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:49.555029 2026] [security2:error] [pid 843279:tid 843380] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/177.php"] [unique_id "al4QSfqvKNcW5yy5T2CgHQAAsGM"]
[Mon Jul 20 06:10:49.555257 2026] [security2:error] [pid 843279:tid 843453] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/177.php"] [unique_id "al4QSfqvKNcW5yy5T2CgHQAAsGM"]
[Mon Jul 20 06:10:49.713674 2026] [security2:error] [pid 843279:tid 843478] [client 50.116.65.227:37536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QSfqvKNcW5yy5T2CgKgAAAMk"]
[Mon Jul 20 06:10:49.724422 2026] [security2:error] [pid 843279:tid 843502] [client 50.116.65.227:37538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QSfqvKNcW5yy5T2CgKwAAAOE"]
[Mon Jul 20 06:10:49.744380 2026] [security2:error] [pid 843279:tid 843397] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/config.php"] [unique_id "al4QSfqvKNcW5yy5T2CgLwAA23Q"]
[Mon Jul 20 06:10:49.744589 2026] [security2:error] [pid 843279:tid 843496] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/config.php"] [unique_id "al4QSfqvKNcW5yy5T2CgLwAA23Q"]
[Mon Jul 20 06:10:49.888668 2026] [security2:error] [pid 843279:tid 843443] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QSfqvKNcW5yy5T2CgPAAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:49.911971 2026] [security2:error] [pid 843279:tid 843526] [client 44.245.170.32:15526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QSfqvKNcW5yy5T2CgPwAAAPg"]
[Mon Jul 20 06:10:49.972757 2026] [security2:error] [pid 843279:tid 843307] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/gettest.php"] [unique_id "al4QSfqvKNcW5yy5T2CgSQAAkxo"]
[Mon Jul 20 06:10:49.972994 2026] [security2:error] [pid 843279:tid 843424] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/gettest.php"] [unique_id "al4QSfqvKNcW5yy5T2CgSQAAkxo"]
[Mon Jul 20 06:10:50.161644 2026] [security2:error] [pid 843279:tid 843303] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/min.php"] [unique_id "al4QSvqvKNcW5yy5T2CgUgAAlBY"]
[Mon Jul 20 06:10:50.161867 2026] [security2:error] [pid 843279:tid 843425] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/min.php"] [unique_id "al4QSvqvKNcW5yy5T2CgUgAAlBY"]
[Mon Jul 20 06:10:50.195646 2026] [security2:error] [pid 843279:tid 843502] [client 50.116.65.227:37562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QSvqvKNcW5yy5T2CgXAAAAOE"]
[Mon Jul 20 06:10:50.205484 2026] [security2:error] [pid 843279:tid 843377] [remote 144.79.133.30:33396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgYAAA1mA"]
[Mon Jul 20 06:10:50.205690 2026] [security2:error] [pid 843279:tid 843491] [client 144.79.133.30:33396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgYAAA1mA"]
[Mon Jul 20 06:10:50.209427 2026] [security2:error] [pid 843279:tid 843428] [client 50.116.65.227:37564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QSvqvKNcW5yy5T2CgYQAAAJc"]
[Mon Jul 20 06:10:50.238941 2026] [security2:error] [pid 843279:tid 843469] [client 57.141.18.83:23694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QRPqvKNcW5yy5T2CefwAAwAU"]
[Mon Jul 20 06:10:50.286525 2026] [security2:error] [pid 843279:tid 843501] [client 35.90.38.209:29954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QSvqvKNcW5yy5T2CgcQAAAOA"]
[Mon Jul 20 06:10:50.350072 2026] [security2:error] [pid 843279:tid 843396] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/3PJcpMFsD8B.php"] [unique_id "al4QSvqvKNcW5yy5T2CgdwAAt3M"]
[Mon Jul 20 06:10:50.350284 2026] [security2:error] [pid 843279:tid 843460] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/3PJcpMFsD8B.php"] [unique_id "al4QSvqvKNcW5yy5T2CgdwAAt3M"]
[Mon Jul 20 06:10:50.426923 2026] [security2:error] [pid 843279:tid 843430] [client 14.225.17.146:56443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4QSPqvKNcW5yy5T2Cf1wAAAJk"], referer: http://superiorcopywriting.com/WORDPRESS
[Mon Jul 20 06:10:50.428723 2026] [security2:error] [pid 843279:tid 843422] [client 103.77.203.233:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgfwAAAJE"]
[Mon Jul 20 06:10:50.428887 2026] [security2:error] [pid 843279:tid 843422] [client 103.77.203.233:63110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QSvqvKNcW5yy5T2CgfwAAAJE"]
[Mon Jul 20 06:10:50.537511 2026] [security2:error] [pid 843279:tid 843367] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/dvjul.php"] [unique_id "al4QSvqvKNcW5yy5T2CgigAA4FY"]
[Mon Jul 20 06:10:50.537731 2026] [security2:error] [pid 843279:tid 843501] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/dvjul.php"] [unique_id "al4QSvqvKNcW5yy5T2CgigAA4FY"]
[Mon Jul 20 06:10:50.565163 2026] [security2:error] [pid 843279:tid 843477] [client 34.230.176.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4QSvqvKNcW5yy5T2CggAAAAMg"]
[Mon Jul 20 06:10:50.615592 2026] [security2:error] [pid 843279:tid 843414] [client 57.141.18.73:63374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QRPqvKNcW5yy5T2CeiAAAiTc"]
[Mon Jul 20 06:10:50.710578 2026] [security2:error] [pid 843279:tid 843452] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QSvqvKNcW5yy5T2CgkgAAAK8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:50.730220 2026] [security2:error] [pid 843279:tid 843313] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/biufile.php"] [unique_id "al4QSvqvKNcW5yy5T2CgowAAxiA"]
[Mon Jul 20 06:10:50.730469 2026] [security2:error] [pid 843279:tid 843475] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/biufile.php"] [unique_id "al4QSvqvKNcW5yy5T2CgowAAxiA"]
[Mon Jul 20 06:10:50.795373 2026] [security2:error] [pid 843279:tid 843498] [client 3.253.146.161:60926] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4QSvqvKNcW5yy5T2CgiQAAAN0"]
[Mon Jul 20 06:10:50.931223 2026] [security2:error] [pid 843279:tid 843412] [client 44.245.170.32:15530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QSvqvKNcW5yy5T2CgvQAAAIc"]
[Mon Jul 20 06:10:50.951693 2026] [security2:error] [pid 843279:tid 843370] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/av.php"] [unique_id "al4QSvqvKNcW5yy5T2CgwQAAm1k"]
[Mon Jul 20 06:10:50.951853 2026] [security2:error] [pid 843279:tid 843432] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/av.php"] [unique_id "al4QSvqvKNcW5yy5T2CgwQAAm1k"]
[Mon Jul 20 06:10:51.022035 2026] [security2:error] [pid 843279:tid 843481] [client 35.90.38.209:24266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QS_qvKNcW5yy5T2CgxAAAAMw"]
[Mon Jul 20 06:10:51.102982 2026] [security2:error] [pid 843279:tid 843477] [client 185.132.186.80:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/install.php"] [unique_id "al4QS_qvKNcW5yy5T2CgxgAAAMg"]
[Mon Jul 20 06:10:51.170726 2026] [security2:error] [pid 843279:tid 843405] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/coffexium.php"] [unique_id "al4QS_qvKNcW5yy5T2CgygAA9nw"]
[Mon Jul 20 06:10:51.170932 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/coffexium.php"] [unique_id "al4QS_qvKNcW5yy5T2CgygAA9nw"]
[Mon Jul 20 06:10:51.351188 2026] [security2:error] [pid 843279:tid 843369] [remote 91.142.222.105:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg3QAArFg"]
[Mon Jul 20 06:10:51.359783 2026] [security2:error] [pid 843279:tid 843389] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/app.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg3wAAkWw"]
[Mon Jul 20 06:10:51.359948 2026] [security2:error] [pid 843279:tid 843422] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/app.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg3wAAkWw"]
[Mon Jul 20 06:10:51.408009 2026] [security2:error] [pid 843279:tid 843497] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg4QAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:51.576989 2026] [security2:error] [pid 843279:tid 843360] [remote 160.187.68.132:36526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg6wAApk8"]
[Mon Jul 20 06:10:51.681126 2026] [security2:error] [pid 843279:tid 843474] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg7gAAAMU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:51.721832 2026] [security2:error] [pid 843279:tid 843478] [client 3.109.4.218:37562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg-QAAAMk"]
[Mon Jul 20 06:10:51.721944 2026] [security2:error] [pid 843279:tid 843478] [client 3.109.4.218:37562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg-QAAAMk"]
[Mon Jul 20 06:10:51.982505 2026] [security2:error] [pid 843279:tid 843467] [client 158.173.166.181:27731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QS_qvKNcW5yy5T2ChFgAAAL4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:10:52.062206 2026] [security2:error] [pid 843279:tid 843407] [remote 160.187.68.132:36526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QTPqvKNcW5yy5T2ChHQAA7n4"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:10:52.309520 2026] [security2:error] [pid 843279:tid 843495] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTPqvKNcW5yy5T2ChMAAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:52.506495 2026] [security2:error] [pid 843279:tid 843510] [client 57.141.18.113:35864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QRvqvKNcW5yy5T2CfDQAA6DU"]
[Mon Jul 20 06:10:52.581224 2026] [security2:error] [pid 843279:tid 843465] [client 52.91.65.34:58742] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "gertoger.org"] [uri "/wp-content/uploads/2018/01/GERtoGER-Geotourism-Mongolia-_-Mongolian-Nomadic-Homestays-1.jpg"] [unique_id "al4QTPqvKNcW5yy5T2ChQAAAALw"]
[Mon Jul 20 06:10:52.770373 2026] [security2:error] [pid 843279:tid 843474] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QTPqvKNcW5yy5T2ChUgAAAMU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:52.957130 2026] [security2:error] [pid 843279:tid 843295] [remote 91.142.222.105:47268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QTPqvKNcW5yy5T2ChawAA5A4"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:10:53.324045 2026] [security2:error] [pid 843279:tid 843537] [client 57.141.18.91:51152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QR_qvKNcW5yy5T2CfRwABAyk"]
[Mon Jul 20 06:10:53.327730 2026] [security2:error] [pid 843279:tid 843307] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/core.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhgAA3Ro"]
[Mon Jul 20 06:10:53.327991 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/core.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhgAA3Ro"]
[Mon Jul 20 06:10:53.329767 2026] [security2:error] [pid 843279:tid 843477] [client 103.141.108.143:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhwAAAMg"]
[Mon Jul 20 06:10:53.330999 2026] [security2:error] [pid 843279:tid 843477] [client 103.141.108.143:55812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChhwAAAMg"]
[Mon Jul 20 06:10:53.621325 2026] [security2:error] [pid 843279:tid 843503] [client 181.224.94.124:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChmQAAAOI"]
[Mon Jul 20 06:10:53.621484 2026] [security2:error] [pid 843279:tid 843503] [client 181.224.94.124:4300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChmQAAAOI"]
[Mon Jul 20 06:10:53.668884 2026] [security2:error] [pid 843279:tid 843492] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTfqvKNcW5yy5T2ChoAAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:53.702009 2026] [security2:error] [pid 843279:tid 843507] [client 45.141.148.148:54866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zarbeautyworld.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg8QAAAOU"]
[Mon Jul 20 06:10:53.753599 2026] [security2:error] [pid 843279:tid 843289] [remote 5.161.225.162:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e36532c6.faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4QTfqvKNcW5yy5T2ChpwAA5gg"]
[Mon Jul 20 06:10:53.756619 2026] [security2:error] [pid 843279:tid 843308] [remote 124.55.178.99:55784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChqAAApRs"]
[Mon Jul 20 06:10:53.756715 2026] [security2:error] [pid 843279:tid 843442] [client 124.55.178.99:55784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QTfqvKNcW5yy5T2ChqAAApRs"]
[Mon Jul 20 06:10:53.828370 2026] [security2:error] [pid 843279:tid 843447] [client 114.119.144.7:60679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiandcitystreets.com"] [uri "/robots.txt"] [unique_id "al4QTfqvKNcW5yy5T2ChsAAAAKo"], referer: http://acaiandcitystreets.com/robots.txt
[Mon Jul 20 06:10:54.366693 2026] [security2:error] [pid 843279:tid 843465] [client 86.98.90.58:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch6wAAALw"]
[Mon Jul 20 06:10:54.370851 2026] [security2:error] [pid 843279:tid 843465] [client 86.98.90.58:16380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch6wAAALw"]
[Mon Jul 20 06:10:54.447224 2026] [security2:error] [pid 843279:tid 843513] [client 150.228.148.150:10370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch8gAAAOs"]
[Mon Jul 20 06:10:54.478998 2026] [security2:error] [pid 843279:tid 843513] [client 150.228.148.150:10370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch8gAAAOs"]
[Mon Jul 20 06:10:54.501204 2026] [security2:error] [pid 843279:tid 843356] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch-QAA8Us"]
[Mon Jul 20 06:10:54.501443 2026] [security2:error] [pid 843279:tid 843519] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch-QAA8Us"]
[Mon Jul 20 06:10:54.526656 2026] [security2:error] [pid 843279:tid 843450] [client 112.213.160.112:31186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch_gAAAK0"]
[Mon Jul 20 06:10:54.526900 2026] [security2:error] [pid 843279:tid 843450] [client 112.213.160.112:31186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch_gAAAK0"]
[Mon Jul 20 06:10:54.602016 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTvqvKNcW5yy5T2CiAQAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:54.602197 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QTvqvKNcW5yy5T2CiAQAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:54.718110 2026] [security2:error] [pid 843279:tid 843442] [client 185.132.186.66:50757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugins/function.php"] [unique_id "al4QTvqvKNcW5yy5T2CiDAAAAKU"]
[Mon Jul 20 06:10:54.843398 2026] [security2:error] [pid 843279:tid 843415] [client 45.116.69.230:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiFgAAAIo"]
[Mon Jul 20 06:10:54.843516 2026] [security2:error] [pid 843279:tid 843415] [client 45.116.69.230:52141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiFgAAAIo"]
[Mon Jul 20 06:10:54.885306 2026] [security2:error] [pid 843279:tid 843469] [client 41.173.37.102:14657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiGAAAAMA"]
[Mon Jul 20 06:10:54.885447 2026] [security2:error] [pid 843279:tid 843469] [client 41.173.37.102:14657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QTvqvKNcW5yy5T2CiGAAAAMA"]
[Mon Jul 20 06:10:55.010912 2026] [security2:error] [pid 843279:tid 843439] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QTvqvKNcW5yy5T2CiHgAAAKI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:55.099346 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:19885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.123.95.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiJwAAAMo"]
[Mon Jul 20 06:10:55.099974 2026] [security2:error] [pid 843279:tid 843479] [client 103.95.123.246:19885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elementconstruction.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiJwAAAMo"]
[Mon Jul 20 06:10:55.414578 2026] [security2:error] [pid 843279:tid 843385] [remote 8.217.108.67:57214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiPgAAx2g"]
[Mon Jul 20 06:10:55.414793 2026] [security2:error] [pid 843279:tid 843476] [client 8.217.108.67:57214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiPgAAx2g"]
[Mon Jul 20 06:10:55.555070 2026] [security2:error] [pid 843279:tid 843436] [client 57.141.18.87:32894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QSfqvKNcW5yy5T2CgDgAAn30"]
[Mon Jul 20 06:10:55.710860 2026] [security2:error] [pid 843279:tid 843407] [remote 100.42.191.181:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.191.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiVgAAwH4"]
[Mon Jul 20 06:10:55.711153 2026] [security2:error] [pid 843279:tid 843469] [client 100.42.191.181:35560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiVgAAwH4"]
[Mon Jul 20 06:10:55.748087 2026] [security2:error] [pid 843279:tid 843390] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiWQAA0W0"]
[Mon Jul 20 06:10:55.748264 2026] [security2:error] [pid 843279:tid 843486] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QT_qvKNcW5yy5T2CiWQAA0W0"]
[Mon Jul 20 06:10:55.843127 2026] [security2:error] [pid 843279:tid 843310] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/header.php"] [unique_id "al4QT_qvKNcW5yy5T2CiZgAA3R0"]
[Mon Jul 20 06:10:55.843331 2026] [security2:error] [pid 843279:tid 843498] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/header.php"] [unique_id "al4QT_qvKNcW5yy5T2CiZgAA3R0"]
[Mon Jul 20 06:10:56.032512 2026] [security2:error] [pid 843279:tid 843374] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/als.php"] [unique_id "al4QUPqvKNcW5yy5T2CieQAA5F0"]
[Mon Jul 20 06:10:56.032821 2026] [security2:error] [pid 843279:tid 843505] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/als.php"] [unique_id "al4QUPqvKNcW5yy5T2CieQAA5F0"]
[Mon Jul 20 06:10:56.222972 2026] [security2:error] [pid 843279:tid 843290] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CijQABAQk"]
[Mon Jul 20 06:10:56.223175 2026] [security2:error] [pid 843279:tid 843535] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CijQABAQk"]
[Mon Jul 20 06:10:56.454072 2026] [security2:error] [pid 843279:tid 843431] [client 14.225.17.146:53874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4QT_qvKNcW5yy5T2CiJAAAAJo"], referer: http://phillipbloch.com/WORDPRESS
[Mon Jul 20 06:10:56.625503 2026] [security2:error] [pid 843279:tid 843516] [client 14.225.17.146:56301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4QUPqvKNcW5yy5T2CipwAAAO4"], referer: http://nextlevelpressurewashing.com/WORDPRESS
[Mon Jul 20 06:10:56.653123 2026] [security2:error] [pid 843279:tid 843522] [client 185.132.186.53:58995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/header.php"] [unique_id "al4QUPqvKNcW5yy5T2CitAAAAPQ"]
[Mon Jul 20 06:10:56.775705 2026] [security2:error] [pid 843279:tid 843460] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QUPqvKNcW5yy5T2CiugAAALc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:56.787096 2026] [security2:error] [pid 843279:tid 843464] [client 57.141.18.61:21832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QSvqvKNcW5yy5T2CgoQAAu3A"]
[Mon Jul 20 06:10:56.826619 2026] [security2:error] [pid 843279:tid 843451] [client 106.192.104.4:60001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CiwQAAAK4"]
[Mon Jul 20 06:10:56.826800 2026] [security2:error] [pid 843279:tid 843451] [client 106.192.104.4:60001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QUPqvKNcW5yy5T2CiwQAAAK4"]
[Mon Jul 20 06:10:56.955209 2026] [security2:error] [pid 843279:tid 843339] [remote 5.161.225.162:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e36532c6.faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4QUPqvKNcW5yy5T2CizQAAzjo"], referer: https://website-e36532c6.faadenergy.com/wp-login.php
[Mon Jul 20 06:10:57.081073 2026] [security2:error] [pid 843279:tid 843537] [client 14.225.17.146:53877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4QTvqvKNcW5yy5T2Ch_wAAAQM"], referer: http://overloadcomedy.com/WORDPRESS
[Mon Jul 20 06:10:57.093674 2026] [security2:error] [pid 843279:tid 843403] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/simple.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci2QAAqno"]
[Mon Jul 20 06:10:57.093950 2026] [security2:error] [pid 843279:tid 843447] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/simple.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci2QAAqno"]
[Mon Jul 20 06:10:57.116409 2026] [security2:error] [pid 843279:tid 843286] [remote 95.217.78.234:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci2wAA2wU"]
[Mon Jul 20 06:10:57.173887 2026] [security2:error] [pid 843279:tid 843497] [client 164.100.212.184:57417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci4AAAANw"]
[Mon Jul 20 06:10:57.173996 2026] [security2:error] [pid 843279:tid 843497] [client 164.100.212.184:57417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci4AAAANw"]
[Mon Jul 20 06:10:57.352453 2026] [security2:error] [pid 843279:tid 843396] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/init.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci7wAAinM"]
[Mon Jul 20 06:10:57.352715 2026] [security2:error] [pid 843279:tid 843415] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/init.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci7wAAinM"]
[Mon Jul 20 06:10:57.362376 2026] [security2:error] [pid 843279:tid 843499] [client 14.225.17.146:63131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci3gAAAN4"], referer: http://soloceos.com/WORDPRESS
[Mon Jul 20 06:10:57.385802 2026] [security2:error] [pid 843279:tid 843528] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci6AAAAPo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:57.386124 2026] [security2:error] [pid 843279:tid 843316] [remote 95.217.78.234:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci9QAAziM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:10:57.491103 2026] [security2:error] [pid 843279:tid 843521] [client 57.141.18.46:39908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QS_qvKNcW5yy5T2Cg6QAA81s"]
[Mon Jul 20 06:10:57.539475 2026] [security2:error] [pid 843279:tid 843371] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/fpwch.php"] [unique_id "al4QUfqvKNcW5yy5T2CjAAAAiFo"]
[Mon Jul 20 06:10:57.539640 2026] [security2:error] [pid 843279:tid 843413] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/fpwch.php"] [unique_id "al4QUfqvKNcW5yy5T2CjAAAAiFo"]
[Mon Jul 20 06:10:57.697667 2026] [security2:error] [pid 843279:tid 843440] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QUfqvKNcW5yy5T2CjEAAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:57.727683 2026] [security2:error] [pid 843279:tid 843349] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/domvf.php"] [unique_id "al4QUfqvKNcW5yy5T2CjEwAAz0Q"]
[Mon Jul 20 06:10:57.727897 2026] [security2:error] [pid 843279:tid 843484] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/domvf.php"] [unique_id "al4QUfqvKNcW5yy5T2CjEwAAz0Q"]
[Mon Jul 20 06:10:57.855214 2026] [security2:error] [pid 843279:tid 843446] [client 45.141.148.148:54874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "zarbeautyworld.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4QUPqvKNcW5yy5T2CiiwAAAKk"], referer: https://zarbeautyworld.twz.oin.mybluehost.me/contact
[Mon Jul 20 06:10:57.954950 2026] [security2:error] [pid 843279:tid 843327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp.php"] [unique_id "al4QUfqvKNcW5yy5T2CjIwABAi4"]
[Mon Jul 20 06:10:57.955112 2026] [security2:error] [pid 843279:tid 843536] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp.php"] [unique_id "al4QUfqvKNcW5yy5T2CjIwABAi4"]
[Mon Jul 20 06:10:58.041342 2026] [security2:error] [pid 843279:tid 843478] [client 196.251.121.187:64441] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "aviationsynergy.aero"] [uri "/wp-json/batch/v1"] [unique_id "al4QUvqvKNcW5yy5T2CjKQAAAMk"]
[Mon Jul 20 06:10:58.237681 2026] [security2:error] [pid 843279:tid 843287] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjOgAAsgY"]
[Mon Jul 20 06:10:58.237921 2026] [security2:error] [pid 843279:tid 843455] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjOgAAsgY"]
[Mon Jul 20 06:10:58.273297 2026] [security2:error] [pid 843279:tid 843366] [remote 51.222.168.118:37988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "taskidsvirginia.com"] [uri "/casino-711-nl-volledige-handleiding-aanmelden-bonussen-berekenen-veilig-spelen/"] [unique_id "al4QUvqvKNcW5yy5T2CjPQAAt1U"]
[Mon Jul 20 06:10:58.273495 2026] [security2:error] [pid 843279:tid 843460] [client 51.222.168.118:37988] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "taskidsvirginia.com"] [uri "/casino-711-nl-volledige-handleiding-aanmelden-bonussen-berekenen-veilig-spelen/"] [unique_id "al4QUvqvKNcW5yy5T2CjPQAAt1U"]
[Mon Jul 20 06:10:58.411617 2026] [security2:error] [pid 843279:tid 843418] [client 57.141.18.22:22960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QTPqvKNcW5yy5T2ChZgAAjQ0"]
[Mon Jul 20 06:10:58.619916 2026] [security2:error] [pid 843279:tid 843343] [remote 162.19.86.63:43764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QUvqvKNcW5yy5T2CjWAAA2D4"]
[Mon Jul 20 06:10:58.693857 2026] [security2:error] [pid 843279:tid 843459] [client 14.225.17.146:63155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4QUfqvKNcW5yy5T2Ci3wAAALY"], referer: http://reosportsboats.com/WORDPRESS
[Mon Jul 20 06:10:58.715417 2026] [security2:error] [pid 843279:tid 843514] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QUvqvKNcW5yy5T2CjVgAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:58.770063 2026] [autoindex:error] [pid 843279:tid 843453] [client 65.49.1.46:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:10:58.826565 2026] [security2:error] [pid 843279:tid 843360] [remote 162.19.86.63:43764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QUvqvKNcW5yy5T2CjcAAAuU8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:10:58.927067 2026] [security2:error] [pid 843279:tid 843354] [remote 182.77.62.24:35248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjdgAA50k"]
[Mon Jul 20 06:10:58.927283 2026] [security2:error] [pid 843279:tid 843509] [client 182.77.62.24:35248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QUvqvKNcW5yy5T2CjdgAA50k"]
[Mon Jul 20 06:10:58.948625 2026] [security2:error] [pid 843279:tid 843364] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/class.php"] [unique_id "al4QUvqvKNcW5yy5T2CjfQABAVM"]
[Mon Jul 20 06:10:58.948883 2026] [security2:error] [pid 843279:tid 843535] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/class.php"] [unique_id "al4QUvqvKNcW5yy5T2CjfQABAVM"]
[Mon Jul 20 06:10:59.083744 2026] [security2:error] [pid 843279:tid 843414] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QU_qvKNcW5yy5T2CjiQAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:10:59.173120 2026] [security2:error] [pid 843279:tid 843288] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/echkm.php"] [unique_id "al4QU_qvKNcW5yy5T2CjlwAAuQc"]
[Mon Jul 20 06:10:59.173336 2026] [security2:error] [pid 843279:tid 843462] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/echkm.php"] [unique_id "al4QU_qvKNcW5yy5T2CjlwAAuQc"]
[Mon Jul 20 06:10:59.425101 2026] [security2:error] [pid 843279:tid 843400] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/lib.php"] [unique_id "al4QU_qvKNcW5yy5T2CjogAA0nc"]
[Mon Jul 20 06:10:59.425274 2026] [security2:error] [pid 843279:tid 843487] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/lib.php"] [unique_id "al4QU_qvKNcW5yy5T2CjogAA0nc"]
[Mon Jul 20 06:10:59.611705 2026] [security2:error] [pid 843279:tid 843428] [client 14.225.17.146:56156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjqQAAAJc"], referer: https://reosportsboats.com/WORDPRESS
[Mon Jul 20 06:10:59.617661 2026] [security2:error] [pid 843279:tid 843355] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/login.php"] [unique_id "al4QU_qvKNcW5yy5T2CjsAAA7Eo"]
[Mon Jul 20 06:10:59.617845 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/login.php"] [unique_id "al4QU_qvKNcW5yy5T2CjsAAA7Eo"]
[Mon Jul 20 06:10:59.658410 2026] [security2:error] [pid 843279:tid 843453] [client 185.132.186.71:63547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wordpress/wp-content/uploads/install.php"] [unique_id "al4QU_qvKNcW5yy5T2CjsgAAALA"]
[Mon Jul 20 06:10:59.688703 2026] [security2:error] [pid 843279:tid 843521] [client 54.158.124.211:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjmAAAAPM"]
[Mon Jul 20 06:10:59.691673 2026] [security2:error] [pid 843279:tid 843499] [client 54.158.124.211:21442] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/robots.txt"] [unique_id "al4QU_qvKNcW5yy5T2CjkwAAAN4"]
[Mon Jul 20 06:10:59.856912 2026] [security2:error] [pid 843279:tid 843402] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/sites.php"] [unique_id "al4QU_qvKNcW5yy5T2CjxgAA8nk"]
[Mon Jul 20 06:10:59.857228 2026] [security2:error] [pid 843279:tid 843520] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/sites.php"] [unique_id "al4QU_qvKNcW5yy5T2CjxgAA8nk"]
[Mon Jul 20 06:11:00.052800 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:57061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjzAAAAKQ"], referer: http://39ishlife.com/WORDPRESS
[Mon Jul 20 06:11:00.069663 2026] [security2:error] [pid 843279:tid 843425] [client 14.225.17.146:56158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4QUvqvKNcW5yy5T2CjVAAAAJQ"], referer: http://dadanetnet.net/WORDPRESS
[Mon Jul 20 06:11:00.112833 2026] [security2:error] [pid 843279:tid 843393] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/a2.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj3wAAlXA"]
[Mon Jul 20 06:11:00.113097 2026] [security2:error] [pid 843279:tid 843426] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/a2.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj3wAAlXA"]
[Mon Jul 20 06:11:00.250701 2026] [security2:error] [pid 843279:tid 843464] [client 14.225.17.146:56011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4QU_qvKNcW5yy5T2CjpAAAALs"], referer: http://waterproofgoods.com/WORDPRESS
[Mon Jul 20 06:11:00.275722 2026] [security2:error] [pid 843279:tid 843532] [client 14.225.17.146:56054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4QUfqvKNcW5yy5T2CjDAAAAP4"], referer: http://gearwaterproof.com/WORDPRESS
[Mon Jul 20 06:11:00.301326 2026] [security2:error] [pid 843279:tid 843381] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/d61.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj9gAA8mQ"]
[Mon Jul 20 06:11:00.301581 2026] [security2:error] [pid 843279:tid 843520] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/d61.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj9gAA8mQ"]
[Mon Jul 20 06:11:00.346333 2026] [security2:error] [pid 843279:tid 843526] [client 57.141.18.41:50330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QTvqvKNcW5yy5T2CiFAAA-Hw"]
[Mon Jul 20 06:11:00.617865 2026] [security2:error] [pid 843279:tid 843492] [client 50.116.65.227:20762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QVPqvKNcW5yy5T2CkCwAAANc"]
[Mon Jul 20 06:11:00.628496 2026] [security2:error] [pid 843279:tid 843462] [client 50.116.65.227:19838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QVPqvKNcW5yy5T2CkDQAAALk"]
[Mon Jul 20 06:11:00.716271 2026] [security2:error] [pid 843279:tid 843378] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/info.php"] [unique_id "al4QVPqvKNcW5yy5T2CkFQAA4mE"]
[Mon Jul 20 06:11:00.716536 2026] [security2:error] [pid 843279:tid 843503] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/info.php"] [unique_id "al4QVPqvKNcW5yy5T2CkFQAA4mE"]
[Mon Jul 20 06:11:00.766174 2026] [security2:error] [pid 843279:tid 843514] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QVPqvKNcW5yy5T2CkEwAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:00.879857 2026] [security2:error] [pid 843279:tid 843488] [client 3.87.117.29:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj3gAAANM"]
[Mon Jul 20 06:11:00.903769 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QVPqvKNcW5yy5T2CkLgAAAJA"]
[Mon Jul 20 06:11:00.903926 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:63646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QVPqvKNcW5yy5T2CkLgAAAJA"]
[Mon Jul 20 06:11:00.914973 2026] [security2:error] [pid 843279:tid 843413] [client 3.87.117.29:13186] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4QVPqvKNcW5yy5T2Cj2QAAAIg"]
[Mon Jul 20 06:11:00.919915 2026] [security2:error] [pid 843279:tid 843309] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QVPqvKNcW5yy5T2CkMAAApBw"]
[Mon Jul 20 06:11:00.920111 2026] [security2:error] [pid 843279:tid 843441] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/11.php"] [unique_id "al4QVPqvKNcW5yy5T2CkMAAApBw"]
[Mon Jul 20 06:11:00.972728 2026] [security2:error] [pid 843279:tid 843464] [client 14.225.17.146:55269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2CkKgAAALs"], referer: https://39ishlife.com/WORDPRESS
[Mon Jul 20 06:11:01.047529 2026] [security2:error] [pid 843279:tid 843474] [client 57.141.18.107:53256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QT_qvKNcW5yy5T2CiPQAAxVQ"]
[Mon Jul 20 06:11:01.098655 2026] [security2:error] [pid 843279:tid 843404] [remote 57.141.18.32:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3096972"] [unique_id "al4QVfqvKNcW5yy5T2CkPAAA-Hs"]
[Mon Jul 20 06:11:01.107947 2026] [security2:error] [pid 843279:tid 843359] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/v2.php"] [unique_id "al4QVfqvKNcW5yy5T2CkPwAA504"]
[Mon Jul 20 06:11:01.109087 2026] [security2:error] [pid 843279:tid 843509] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/v2.php"] [unique_id "al4QVfqvKNcW5yy5T2CkPwAA504"]
[Mon Jul 20 06:11:01.178193 2026] [security2:error] [pid 843279:tid 843527] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkRQAAAPk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.256717 2026] [security2:error] [pid 843279:tid 843313] [remote 217.61.143.92:39040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkTgAA_iA"]
[Mon Jul 20 06:11:01.354078 2026] [security2:error] [pid 843279:tid 843337] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/panel.php"] [unique_id "al4QVfqvKNcW5yy5T2CkXQAAujg"]
[Mon Jul 20 06:11:01.354352 2026] [security2:error] [pid 843279:tid 843463] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/panel.php"] [unique_id "al4QVfqvKNcW5yy5T2CkXQAAujg"]
[Mon Jul 20 06:11:01.393397 2026] [security2:error] [pid 843279:tid 843294] [remote 8.217.108.67:43270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkYAAA1Q0"]
[Mon Jul 20 06:11:01.494117 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QVfqvKNcW5yy5T2CkaQAAAN0"]
[Mon Jul 20 06:11:01.494260 2026] [security2:error] [pid 843279:tid 843498] [client 27.96.94.195:37460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QVfqvKNcW5yy5T2CkaQAAAN0"]
[Mon Jul 20 06:11:01.501483 2026] [security2:error] [pid 843279:tid 843342] [remote 217.61.143.92:39040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkagAAyD0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:11:01.542558 2026] [security2:error] [pid 843279:tid 843346] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/dex.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbAAA50E"]
[Mon Jul 20 06:11:01.542852 2026] [security2:error] [pid 843279:tid 843509] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/dex.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbAAA50E"]
[Mon Jul 20 06:11:01.553452 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.553628 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkbgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.682305 2026] [security2:error] [pid 843279:tid 843343] [remote 72.167.132.114:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QVfqvKNcW5yy5T2CkdQAAij4"]
[Mon Jul 20 06:11:01.730514 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "origine.nz"] [uri "/1.php"] [unique_id "al4QVfqvKNcW5yy5T2CkegAAuh8"]
[Mon Jul 20 06:11:01.730603 2026] [security2:error] [pid 843279:tid 843312] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/1.php"] [unique_id "al4QVfqvKNcW5yy5T2CkegAAuh8"]
[Mon Jul 20 06:11:01.730795 2026] [security2:error] [pid 843279:tid 843463] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/1.php"] [unique_id "al4QVfqvKNcW5yy5T2CkegAAuh8"]
[Mon Jul 20 06:11:01.929610 2026] [security2:error] [pid 843279:tid 843369] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/ms.php"] [unique_id "al4QVfqvKNcW5yy5T2CkiwAA9lg"]
[Mon Jul 20 06:11:01.929892 2026] [security2:error] [pid 843279:tid 843524] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/ms.php"] [unique_id "al4QVfqvKNcW5yy5T2CkiwAA9lg"]
[Mon Jul 20 06:11:01.964866 2026] [security2:error] [pid 843279:tid 843420] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QVfqvKNcW5yy5T2CkiQAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:01.992170 2026] [security2:error] [pid 843279:tid 843490] [client 82.135.202.97:35490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.202.135.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/books/books_3.php"] [unique_id "al4QVfqvKNcW5yy5T2CkjwAAANU"]
[Mon Jul 20 06:11:02.090095 2026] [security2:error] [pid 843279:tid 843391] [remote 72.167.132.114:52360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CklgAA_24"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:11:02.167623 2026] [security2:error] [pid 843279:tid 843512] [client 57.141.18.23:64728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QUPqvKNcW5yy5T2CingAA6jE"]
[Mon Jul 20 06:11:02.232988 2026] [autoindex:error] [pid 843279:tid 843379] [remote 20.197.195.24:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/Origine/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:11:02.233608 2026] [security2:error] [pid 843279:tid 843450] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "origine.nz"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4QVvqvKNcW5yy5T2CknAAArWI"]
[Mon Jul 20 06:11:02.248179 2026] [security2:error] [pid 843279:tid 843345] [remote 188.40.28.4:44854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CkoQAAkkA"]
[Mon Jul 20 06:11:02.404821 2026] [security2:error] [pid 843279:tid 843412] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CkswAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:02.451144 2026] [security2:error] [pid 843279:tid 843361] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/memberfuns.php"] [unique_id "al4QVvqvKNcW5yy5T2CktwAA01A"]
[Mon Jul 20 06:11:02.451275 2026] [security2:error] [pid 843279:tid 843488] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/memberfuns.php"] [unique_id "al4QVvqvKNcW5yy5T2CktwAA01A"]
[Mon Jul 20 06:11:02.460305 2026] [security2:error] [pid 843279:tid 843401] [remote 188.40.28.4:44854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2CkuAAAsXg"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:11:02.516356 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:56146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2CkFgAAAK4"], referer: http://koaconsultants.com/WORDPRESS
[Mon Jul 20 06:11:02.670101 2026] [security2:error] [pid 843279:tid 843353] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/0.php"] [unique_id "al4QVvqvKNcW5yy5T2CkxQAAq0g"]
[Mon Jul 20 06:11:02.670323 2026] [security2:error] [pid 843279:tid 843448] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/0.php"] [unique_id "al4QVvqvKNcW5yy5T2CkxQAAq0g"]
[Mon Jul 20 06:11:02.857761 2026] [security2:error] [pid 843279:tid 843380] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/BDKR28.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck4AAAymM"]
[Mon Jul 20 06:11:02.857977 2026] [security2:error] [pid 843279:tid 843479] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/BDKR28.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck4AAAymM"]
[Mon Jul 20 06:11:02.959029 2026] [security2:error] [pid 843279:tid 843447] [client 144.217.244.188:52442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck1AAAAKo"]
[Mon Jul 20 06:11:02.982154 2026] [security2:error] [pid 843279:tid 843314] [remote 103.187.169.251:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck7AAAzyE"]
[Mon Jul 20 06:11:03.023137 2026] [security2:error] [pid 843279:tid 843440] [client 14.225.17.146:57715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2Ck4wAAAKM"]
[Mon Jul 20 06:11:03.080772 2026] [security2:error] [pid 843279:tid 843285] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/green1.php"] [unique_id "al4QV_qvKNcW5yy5T2Ck-QAA7AQ"]
[Mon Jul 20 06:11:03.081004 2026] [security2:error] [pid 843279:tid 843514] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/green1.php"] [unique_id "al4QV_qvKNcW5yy5T2Ck-QAA7AQ"]
[Mon Jul 20 06:11:03.272421 2026] [security2:error] [pid 843279:tid 843381] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/nc4.php"] [unique_id "al4QV_qvKNcW5yy5T2ClBAAA7mQ"]
[Mon Jul 20 06:11:03.272615 2026] [security2:error] [pid 843279:tid 843516] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/nc4.php"] [unique_id "al4QV_qvKNcW5yy5T2ClBAAA7mQ"]
[Mon Jul 20 06:11:03.510260 2026] [security2:error] [pid 843279:tid 843281] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/a1.php"] [unique_id "al4QV_qvKNcW5yy5T2ClGwAAhQA"]
[Mon Jul 20 06:11:03.510486 2026] [security2:error] [pid 843279:tid 843410] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/a1.php"] [unique_id "al4QV_qvKNcW5yy5T2ClGwAAhQA"]
[Mon Jul 20 06:11:03.577779 2026] [security2:error] [pid 843279:tid 843519] [client 14.225.17.146:57483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CklwAAAPE"], referer: http://samdothan.org/WORDPRESS
[Mon Jul 20 06:11:03.646738 2026] [security2:error] [pid 843279:tid 843320] [remote 103.187.169.251:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4QV_qvKNcW5yy5T2ClJwAAsSc"], referer: https://adambergeron.com/wp-login.php
[Mon Jul 20 06:11:03.698673 2026] [security2:error] [pid 843279:tid 843316] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/eee.php"] [unique_id "al4QV_qvKNcW5yy5T2ClLAAAkCM"]
[Mon Jul 20 06:11:03.698870 2026] [security2:error] [pid 843279:tid 843421] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/eee.php"] [unique_id "al4QV_qvKNcW5yy5T2ClLAAAkCM"]
[Mon Jul 20 06:11:03.795405 2026] [security2:error] [pid 843279:tid 843447] [client 14.225.17.146:54962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4QV_qvKNcW5yy5T2ClKAAAAKo"], referer: http://christiancountytrumpet.com/WORDPRESS
[Mon Jul 20 06:11:03.812084 2026] [security2:error] [pid 843279:tid 843309] [remote 216.73.216.55:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4QV_qvKNcW5yy5T2ClOwAAwBw"]
[Mon Jul 20 06:11:03.828725 2026] [security2:error] [pid 843279:tid 843444] [client 14.225.17.146:57463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CkywAAAKc"], referer: http://daseighty.net/WORDPRESS
[Mon Jul 20 06:11:03.927208 2026] [security2:error] [pid 843279:tid 843368] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-aothait.php"] [unique_id "al4QV_qvKNcW5yy5T2ClRAAAtlc"]
[Mon Jul 20 06:11:03.927386 2026] [security2:error] [pid 843279:tid 843459] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/wp-aothait.php"] [unique_id "al4QV_qvKNcW5yy5T2ClRAAAtlc"]
[Mon Jul 20 06:11:03.968895 2026] [security2:error] [pid 843279:tid 843537] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QV_qvKNcW5yy5T2ClQAAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.147051 2026] [security2:error] [pid 843279:tid 843327] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/config.json.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVgAA1C4"]
[Mon Jul 20 06:11:04.147275 2026] [security2:error] [pid 843279:tid 843489] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/config.json.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVgAA1C4"]
[Mon Jul 20 06:11:04.179021 2026] [security2:error] [pid 843279:tid 843428] [client 103.141.108.143:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVwAAAJc"]
[Mon Jul 20 06:11:04.179154 2026] [security2:error] [pid 843279:tid 843428] [client 103.141.108.143:56280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClVwAAAJc"]
[Mon Jul 20 06:11:04.179341 2026] [security2:error] [pid 843279:tid 843411] [client 181.224.94.124:6819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClWAAAAIY"]
[Mon Jul 20 06:11:04.179468 2026] [security2:error] [pid 843279:tid 843411] [client 181.224.94.124:6819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QWPqvKNcW5yy5T2ClWAAAAIY"]
[Mon Jul 20 06:11:04.209681 2026] [security2:error] [pid 843279:tid 843526] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QWPqvKNcW5yy5T2ClWgAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.307266 2026] [security2:error] [pid 843279:tid 843470] [client 66.249.73.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CkygAAAME"]
[Mon Jul 20 06:11:04.349703 2026] [security2:error] [pid 843279:tid 843375] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/2PJcpMFsD8B.php"] [unique_id "al4QWPqvKNcW5yy5T2ClagAAr14"]
[Mon Jul 20 06:11:04.349921 2026] [security2:error] [pid 843279:tid 843452] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/2PJcpMFsD8B.php"] [unique_id "al4QWPqvKNcW5yy5T2ClagAAr14"]
[Mon Jul 20 06:11:04.423081 2026] [security2:error] [pid 843279:tid 843323] [remote 202.51.202.242:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QWPqvKNcW5yy5T2ClcAAAoCo"]
[Mon Jul 20 06:11:04.524766 2026] [security2:error] [pid 843279:tid 843464] [client 104.234.53.71:43643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QWPqvKNcW5yy5T2CldAAAALs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.563833 2026] [security2:error] [pid 843279:tid 843342] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/k2.php"] [unique_id "al4QWPqvKNcW5yy5T2ClfAAAlD0"]
[Mon Jul 20 06:11:04.564001 2026] [security2:error] [pid 843279:tid 843425] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/k2.php"] [unique_id "al4QWPqvKNcW5yy5T2ClfAAAlD0"]
[Mon Jul 20 06:11:04.712801 2026] [security2:error] [pid 843279:tid 843469] [client 185.132.186.82:40213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/server.php"] [unique_id "al4QWPqvKNcW5yy5T2ClhQAAAMA"]
[Mon Jul 20 06:11:04.774220 2026] [security2:error] [pid 843279:tid 843343] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/uiuvs58l.php"] [unique_id "al4QWPqvKNcW5yy5T2CljQAAmT4"]
[Mon Jul 20 06:11:04.774412 2026] [security2:error] [pid 843279:tid 843430] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/uiuvs58l.php"] [unique_id "al4QWPqvKNcW5yy5T2CljQAAmT4"]
[Mon Jul 20 06:11:04.826554 2026] [security2:error] [pid 843279:tid 843414] [client 104.234.53.71:43643] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QWPqvKNcW5yy5T2CllAAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:04.975440 2026] [security2:error] [pid 843279:tid 843385] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/40p9ixjd.php"] [unique_id "al4QWPqvKNcW5yy5T2ClpAAA7Wg"]
[Mon Jul 20 06:11:04.975570 2026] [security2:error] [pid 843279:tid 843515] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/40p9ixjd.php"] [unique_id "al4QWPqvKNcW5yy5T2ClpAAA7Wg"]
[Mon Jul 20 06:11:05.056166 2026] [security2:error] [pid 843279:tid 843443] [client 86.98.90.58:17138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClqgAAAKY"]
[Mon Jul 20 06:11:05.056530 2026] [security2:error] [pid 843279:tid 843443] [client 86.98.90.58:17138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClqgAAAKY"]
[Mon Jul 20 06:11:05.154418 2026] [security2:error] [pid 843279:tid 843330] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClrwAAijE"]
[Mon Jul 20 06:11:05.154546 2026] [security2:error] [pid 843279:tid 843415] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClrwAAijE"]
[Mon Jul 20 06:11:05.221520 2026] [security2:error] [pid 843279:tid 843457] [client 150.228.148.150:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2CltQAAALQ"]
[Mon Jul 20 06:11:05.221710 2026] [security2:error] [pid 843279:tid 843457] [client 150.228.148.150:61606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2CltQAAALQ"]
[Mon Jul 20 06:11:05.313832 2026] [security2:error] [pid 843279:tid 843528] [client 112.213.160.112:8633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClwQAAAPo"]
[Mon Jul 20 06:11:05.314061 2026] [security2:error] [pid 843279:tid 843528] [client 112.213.160.112:8633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2ClwQAAAPo"]
[Mon Jul 20 06:11:05.450409 2026] [security2:error] [pid 843279:tid 843461] [client 45.116.69.230:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1gAAALg"]
[Mon Jul 20 06:11:05.450564 2026] [security2:error] [pid 843279:tid 843461] [client 45.116.69.230:52645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1gAAALg"]
[Mon Jul 20 06:11:05.475897 2026] [security2:error] [pid 843279:tid 843329] [remote 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/uiuvs58l.update.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1wAA6zA"]
[Mon Jul 20 06:11:05.476175 2026] [security2:error] [pid 843279:tid 843513] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "origine.nz"] [uri "/uiuvs58l.update.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl1wAA6zA"]
[Mon Jul 20 06:11:05.516273 2026] [security2:error] [pid 843279:tid 843418] [client 41.173.37.102:1153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl3AAAAI0"]
[Mon Jul 20 06:11:05.516383 2026] [security2:error] [pid 843279:tid 843418] [client 41.173.37.102:1153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl3AAAAI0"]
[Mon Jul 20 06:11:05.647190 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:52728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4QWfqvKNcW5yy5T2ClrAAAAK4"]
[Mon Jul 20 06:11:05.803187 2026] [security2:error] [pid 843279:tid 843510] [client 57.141.18.9:51176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QVPqvKNcW5yy5T2Cj2wAA6CI"]
[Mon Jul 20 06:11:05.858496 2026] [security2:error] [pid 843279:tid 843290] [remote 111.225.148.180:28712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/08/combined-august-30-2022-predeadline-comment.pdf"] [unique_id "al4QWfqvKNcW5yy5T2Cl8AAA4Qk"]
[Mon Jul 20 06:11:05.984839 2026] [security2:error] [pid 843279:tid 843291] [remote 202.51.202.242:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QWfqvKNcW5yy5T2Cl9gAAqgo"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:11:06.333026 2026] [security2:error] [pid 843279:tid 843402] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmGAAA_3k"]
[Mon Jul 20 06:11:06.333191 2026] [security2:error] [pid 843279:tid 843533] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmGAAA_3k"]
[Mon Jul 20 06:11:06.466207 2026] [proxy:error] [pid 843279:tid 843495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:06.466247 2026] [proxy_http:error] [pid 843279:tid 843495] [client 198.235.24.57:61392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:06.467551 2026] [proxy:error] [pid 843279:tid 843495] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:06.467581 2026] [proxy_http:error] [pid 843279:tid 843495] [client 198.235.24.57:61392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:06.932328 2026] [security2:error] [pid 843279:tid 843468] [client 14.225.17.146:52788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4QWvqvKNcW5yy5T2CmOQAAAL8"], referer: http://swafforddetailing.com/WORDPRESS
[Mon Jul 20 06:11:06.933709 2026] [security2:error] [pid 843279:tid 843304] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmSQAAhhc"]
[Mon Jul 20 06:11:06.933928 2026] [security2:error] [pid 843279:tid 843411] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QWvqvKNcW5yy5T2CmSQAAhhc"]
[Mon Jul 20 06:11:07.062036 2026] [security2:error] [pid 843279:tid 843423] [client 178.152.178.232:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmUQAAAJI"]
[Mon Jul 20 06:11:07.062181 2026] [security2:error] [pid 843279:tid 843423] [client 178.152.178.232:36428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmUQAAAJI"]
[Mon Jul 20 06:11:07.570130 2026] [security2:error] [pid 843279:tid 843292] [remote 160.187.68.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4QW_qvKNcW5yy5T2CmdQAA2Qs"]
[Mon Jul 20 06:11:07.742439 2026] [security2:error] [pid 843279:tid 843519] [client 185.132.186.69:37677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/autoload_classmap/install.php"] [unique_id "al4QW_qvKNcW5yy5T2CmhgAAAPE"]
[Mon Jul 20 06:11:07.777702 2026] [security2:error] [pid 843279:tid 843414] [client 164.100.212.184:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmigAAAIk"]
[Mon Jul 20 06:11:07.777810 2026] [security2:error] [pid 843279:tid 843414] [client 164.100.212.184:50711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QW_qvKNcW5yy5T2CmigAAAIk"]
[Mon Jul 20 06:11:07.911822 2026] [security2:error] [pid 843279:tid 843537] [client 103.153.183.69:61444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../var/www/html/.env"] [unique_id "al4QW_qvKNcW5yy5T2CmmAAAAQM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:07.921656 2026] [security2:error] [pid 843279:tid 843509] [client 57.141.18.59:58922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QVvqvKNcW5yy5T2CklQAA51M"]
[Mon Jul 20 06:11:08.097526 2026] [security2:error] [pid 843279:tid 843484] [client 50.116.65.227:20812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4QXPqvKNcW5yy5T2CmpgAAAM8"]
[Mon Jul 20 06:11:08.098504 2026] [security2:error] [pid 843279:tid 843487] [client 50.116.65.227:19950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QXPqvKNcW5yy5T2CmpwAAANI"]
[Mon Jul 20 06:11:08.109193 2026] [security2:error] [pid 843279:tid 843466] [client 50.116.65.227:19974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QXPqvKNcW5yy5T2CmqgAAAL0"]
[Mon Jul 20 06:11:08.109204 2026] [security2:error] [pid 843279:tid 843490] [client 50.116.65.227:19962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4QXPqvKNcW5yy5T2CmqQAAAQQ"]
[Mon Jul 20 06:11:08.223787 2026] [security2:error] [pid 843279:tid 843419] [client 52.167.144.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QW_qvKNcW5yy5T2CmngAAAI4"]
[Mon Jul 20 06:11:08.444016 2026] [security2:error] [pid 843279:tid 843485] [client 106.192.104.4:60484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2CmygAAANA"]
[Mon Jul 20 06:11:08.445366 2026] [security2:error] [pid 843279:tid 843485] [client 106.192.104.4:60484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2CmygAAANA"]
[Mon Jul 20 06:11:08.465346 2026] [security2:error] [pid 843279:tid 843343] [remote 160.187.68.132:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4QXPqvKNcW5yy5T2CmzgAAsT4"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:11:08.759084 2026] [security2:error] [pid 843279:tid 843384] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2Cm4wABBGc"]
[Mon Jul 20 06:11:08.759276 2026] [security2:error] [pid 843279:tid 843538] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QXPqvKNcW5yy5T2Cm4wABBGc"]
[Mon Jul 20 06:11:08.992518 2026] [security2:error] [pid 843279:tid 843432] [client 104.234.53.70:33089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QXPqvKNcW5yy5T2Cm9wAAAJs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:09.104663 2026] [security2:error] [pid 843279:tid 843455] [client 57.141.18.81:47018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QV_qvKNcW5yy5T2Ck-gAAshM"]
[Mon Jul 20 06:11:09.307281 2026] [security2:error] [pid 843279:tid 843533] [client 14.225.17.146:54600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4QW_qvKNcW5yy5T2CmdgAAAP8"], referer: http://maplerespiteservices.com/WORDPRESS
[Mon Jul 20 06:11:09.403723 2026] [security2:error] [pid 843279:tid 843465] [client 57.141.18.14:22664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QV_qvKNcW5yy5T2ClHgAAvAg"]
[Mon Jul 20 06:11:09.718232 2026] [security2:error] [pid 843279:tid 843516] [client 104.234.53.73:39011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QXfqvKNcW5yy5T2CnHQAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:09.916616 2026] [security2:error] [pid 843279:tid 843475] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QXfqvKNcW5yy5T2CnLwAAAMY"]
[Mon Jul 20 06:11:10.101377 2026] [security2:error] [pid 843279:tid 843400] [remote 152.228.213.32:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnTgAAy3c"]
[Mon Jul 20 06:11:10.101605 2026] [security2:error] [pid 843279:tid 843480] [client 152.228.213.32:39906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnTgAAy3c"]
[Mon Jul 20 06:11:10.227483 2026] [security2:error] [pid 843279:tid 843411] [client 103.153.183.69:19140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8froot/.ssh/id_rsa"] [unique_id "al4QXvqvKNcW5yy5T2CnVgAAAIY"], referer: https://twitter.com/
[Mon Jul 20 06:11:10.357215 2026] [security2:error] [pid 843279:tid 843408] [remote 38.242.157.30:49180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnYQAA3H8"]
[Mon Jul 20 06:11:10.357419 2026] [security2:error] [pid 843279:tid 843497] [client 38.242.157.30:49180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4QXvqvKNcW5yy5T2CnYQAA3H8"]
[Mon Jul 20 06:11:11.020812 2026] [security2:error] [pid 843279:tid 843478] [client 57.141.18.102:35518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QWPqvKNcW5yy5T2ClowAAyVg"]
[Mon Jul 20 06:11:11.147010 2026] [security2:error] [pid 843279:tid 843340] [remote 72.167.132.114:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnoQAAuDs"]
[Mon Jul 20 06:11:11.147229 2026] [security2:error] [pid 843279:tid 843461] [client 72.167.132.114:33568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnoQAAuDs"]
[Mon Jul 20 06:11:11.481127 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnsgAAAJk"]
[Mon Jul 20 06:11:11.481329 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QX_qvKNcW5yy5T2CnsgAAAJk"]
[Mon Jul 20 06:11:11.540492 2026] [security2:error] [pid 843279:tid 843433] [client 103.153.183.69:61444] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../var/www/.env"] [unique_id "al4QX_qvKNcW5yy5T2CntgAAAJw"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:11.699040 2026] [security2:error] [pid 843279:tid 843527] [client 2.50.103.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QXfqvKNcW5yy5T2CnLgAAAPk"]
[Mon Jul 20 06:11:11.795960 2026] [security2:error] [pid 843279:tid 843528] [client 185.132.186.75:39759] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "al4QX_qvKNcW5yy5T2CnyAAAAPo"]
[Mon Jul 20 06:11:11.796088 2026] [security2:error] [pid 843279:tid 843528] [client 185.132.186.75:39759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "al4QX_qvKNcW5yy5T2CnyAAAAPo"]
[Mon Jul 20 06:11:12.033126 2026] [security2:error] [pid 843279:tid 843366] [remote 81.173.115.7:41692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QYPqvKNcW5yy5T2Cn2gAAy1U"]
[Mon Jul 20 06:11:12.033286 2026] [security2:error] [pid 843279:tid 843480] [client 81.173.115.7:41692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QYPqvKNcW5yy5T2Cn2gAAy1U"]
[Mon Jul 20 06:11:12.054150 2026] [security2:error] [pid 843279:tid 843459] [client 57.141.18.42:54358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QWvqvKNcW5yy5T2CmCgAAtiE"]
[Mon Jul 20 06:11:12.360333 2026] [security2:error] [pid 843279:tid 843419] [client 40.77.179.244:39490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "juniper3medical.com"] [uri "/index.php"] [unique_id "al4QYPqvKNcW5yy5T2Cn8QAAjlY"]
[Mon Jul 20 06:11:12.733914 2026] [security2:error] [pid 843279:tid 843520] [client 104.234.53.60:33315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QYPqvKNcW5yy5T2CoGQAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:14.126544 2026] [security2:error] [pid 843279:tid 843408] [remote 81.173.115.7:39962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4QYvqvKNcW5yy5T2CojQAA_X8"]
[Mon Jul 20 06:11:14.257248 2026] [security2:error] [pid 843279:tid 843479] [client 66.249.65.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4QYPqvKNcW5yy5T2CoIwAAAMo"]
[Mon Jul 20 06:11:14.398897 2026] [security2:error] [pid 843279:tid 843393] [remote 216.73.216.55:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4QYvqvKNcW5yy5T2CoqAAA33A"]
[Mon Jul 20 06:11:14.501991 2026] [security2:error] [pid 843279:tid 843296] [remote 81.173.115.7:39962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4QYvqvKNcW5yy5T2CosQAA4w8"], referer: https://north-woods-engineering.com/wp-login.php
[Mon Jul 20 06:11:14.533253 2026] [security2:error] [pid 843279:tid 843430] [client 14.225.17.146:49245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CokQAAAJk"], referer: http://carolinapressurewashers.com/WORDPRESS
[Mon Jul 20 06:11:14.737639 2026] [security2:error] [pid 843279:tid 843473] [client 181.224.94.124:38435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2CowwAAAMQ"]
[Mon Jul 20 06:11:14.737812 2026] [security2:error] [pid 843279:tid 843473] [client 181.224.94.124:38435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2CowwAAAMQ"]
[Mon Jul 20 06:11:14.891879 2026] [security2:error] [pid 843279:tid 843479] [client 103.141.108.143:56754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2Co0wAAAMo"]
[Mon Jul 20 06:11:14.892006 2026] [security2:error] [pid 843279:tid 843479] [client 103.141.108.143:56754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QYvqvKNcW5yy5T2Co0wAAAMo"]
[Mon Jul 20 06:11:14.984528 2026] [security2:error] [pid 843279:tid 843486] [client 47.128.55.158:53068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mollycahill.com"] [uri "/robots.txt"] [unique_id "al4QYvqvKNcW5yy5T2Co3AAAANE"]
[Mon Jul 20 06:11:15.012841 2026] [security2:error] [pid 843279:tid 843351] [remote 81.173.115.7:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co3gAAyUY"]
[Mon Jul 20 06:11:15.153878 2026] [security2:error] [pid 843279:tid 843317] [remote 84.247.172.23:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co6QAAzyQ"]
[Mon Jul 20 06:11:15.224314 2026] [security2:error] [pid 843279:tid 843320] [remote 81.173.115.7:39970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co7AAAzic"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 06:11:15.245645 2026] [security2:error] [pid 843279:tid 843454] [client 63.179.149.246:28378] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/bistec-encebollado-puerto-rican-steak-and-onions"] [unique_id "al4QY_qvKNcW5yy5T2Co7gAAALE"]
[Mon Jul 20 06:11:15.356212 2026] [security2:error] [pid 843279:tid 843486] [client 185.132.186.93:55753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ubh/av.php"] [unique_id "al4QY_qvKNcW5yy5T2Co9gAAANE"]
[Mon Jul 20 06:11:15.383032 2026] [security2:error] [pid 843279:tid 843359] [remote 84.247.172.23:54714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2Co-QAAxU4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:11:15.520882 2026] [security2:error] [pid 843279:tid 843498] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QY_qvKNcW5yy5T2Co_AAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:15.675822 2026] [security2:error] [pid 843279:tid 843455] [client 14.225.17.146:55979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CovgAAALI"], referer: http://retzkolonglogistics.com/WORDPRESS
[Mon Jul 20 06:11:15.706571 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QY_qvKNcW5yy5T2CpEAAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:15.709523 2026] [security2:error] [pid 843279:tid 843425] [client 150.228.148.150:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpEQAAAJQ"]
[Mon Jul 20 06:11:15.710164 2026] [security2:error] [pid 843279:tid 843425] [client 150.228.148.150:16900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpEQAAAJQ"]
[Mon Jul 20 06:11:15.822988 2026] [security2:error] [pid 843279:tid 843314] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpGgABASE"]
[Mon Jul 20 06:11:15.823140 2026] [security2:error] [pid 843279:tid 843535] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpGgABASE"]
[Mon Jul 20 06:11:15.945173 2026] [security2:error] [pid 843279:tid 843538] [client 112.213.160.112:30747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpLwAAAQQ"]
[Mon Jul 20 06:11:15.945293 2026] [security2:error] [pid 843279:tid 843538] [client 112.213.160.112:30747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QY_qvKNcW5yy5T2CpLwAAAQQ"]
[Mon Jul 20 06:11:16.113543 2026] [security2:error] [pid 843279:tid 843513] [client 86.98.90.58:17935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpPwAAAOs"]
[Mon Jul 20 06:11:16.113797 2026] [security2:error] [pid 843279:tid 843513] [client 86.98.90.58:17935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpPwAAAOs"]
[Mon Jul 20 06:11:16.147784 2026] [security2:error] [pid 843279:tid 843531] [client 50.116.65.227:60478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QZPqvKNcW5yy5T2CpQQAAAP0"]
[Mon Jul 20 06:11:16.160179 2026] [security2:error] [pid 843279:tid 843410] [client 41.173.37.102:1619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpQwAAAIU"]
[Mon Jul 20 06:11:16.160303 2026] [security2:error] [pid 843279:tid 843410] [client 41.173.37.102:1619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpQwAAAIU"]
[Mon Jul 20 06:11:16.161401 2026] [security2:error] [pid 843279:tid 843426] [client 50.116.65.227:15680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QZPqvKNcW5yy5T2CpQgAAAJU"]
[Mon Jul 20 06:11:16.168725 2026] [security2:error] [pid 843279:tid 843423] [client 45.116.69.230:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpRAAAAJI"]
[Mon Jul 20 06:11:16.168891 2026] [security2:error] [pid 843279:tid 843423] [client 45.116.69.230:53136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpRAAAAJI"]
[Mon Jul 20 06:11:16.266623 2026] [security2:error] [pid 843279:tid 843508] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpPgAAAOY"]
[Mon Jul 20 06:11:16.362099 2026] [security2:error] [pid 843279:tid 843486] [client 63.177.52.239:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QY_qvKNcW5yy5T2CpIAAAANE"]
[Mon Jul 20 06:11:16.369219 2026] [security2:error] [pid 843279:tid 843529] [client 63.177.52.239:62090] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/bistec-encebollado-puerto-rican-steak-and-onions"] [unique_id "al4QY_qvKNcW5yy5T2CpHAAAAPs"]
[Mon Jul 20 06:11:16.630795 2026] [security2:error] [pid 843279:tid 843532] [client 178.152.178.232:35842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpagAAAP4"]
[Mon Jul 20 06:11:16.630974 2026] [security2:error] [pid 843279:tid 843532] [client 178.152.178.232:35842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpagAAAP4"]
[Mon Jul 20 06:11:16.738193 2026] [security2:error] [pid 843279:tid 843476] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QZPqvKNcW5yy5T2CpbAAAAMc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:16.837338 2026] [security2:error] [pid 843279:tid 843433] [client 151.244.158.67:63536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpbQAAAJw"]
[Mon Jul 20 06:11:16.977103 2026] [security2:error] [pid 843279:tid 843309] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpggAA2xw"]
[Mon Jul 20 06:11:16.977293 2026] [security2:error] [pid 843279:tid 843496] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QZPqvKNcW5yy5T2CpggAA2xw"]
[Mon Jul 20 06:11:16.998761 2026] [security2:error] [pid 843279:tid 843412] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZPqvKNcW5yy5T2CphgAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:17.072167 2026] [security2:error] [pid 843279:tid 843461] [client 14.225.17.146:64175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4QY_qvKNcW5yy5T2Co7wAAALg"], referer: http://tacticaltreeoperations.com/WORDPRESS
[Mon Jul 20 06:11:17.355881 2026] [security2:error] [pid 843279:tid 843416] [client 185.132.186.68:27351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/anas.php"] [unique_id "al4QZfqvKNcW5yy5T2CpogAAAIs"]
[Mon Jul 20 06:11:17.379211 2026] [security2:error] [pid 843279:tid 843353] [remote 182.77.62.24:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QZfqvKNcW5yy5T2CppQAA5Ug"]
[Mon Jul 20 06:11:17.444031 2026] [security2:error] [pid 843279:tid 843473] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QZfqvKNcW5yy5T2CppwAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:17.591584 2026] [security2:error] [pid 843279:tid 843503] [client 114.119.136.8:38509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "momheadquarters.com"] [uri "/robots.txt"] [unique_id "al4QZfqvKNcW5yy5T2CpwAAAAOI"], referer: http://momheadquarters.com/robots.txt
[Mon Jul 20 06:11:17.604780 2026] [security2:error] [pid 843279:tid 843302] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QZfqvKNcW5yy5T2CpwgAAsRU"]
[Mon Jul 20 06:11:17.604985 2026] [security2:error] [pid 843279:tid 843454] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QZfqvKNcW5yy5T2CpwgAAsRU"]
[Mon Jul 20 06:11:17.730632 2026] [security2:error] [pid 843279:tid 843518] [client 52.59.238.198:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpfQAAAPA"]
[Mon Jul 20 06:11:17.783883 2026] [security2:error] [pid 843279:tid 843489] [client 52.59.238.198:55048] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/bistec-encebollado-puerto-rican-steak-and-onions/"] [unique_id "al4QZPqvKNcW5yy5T2CpdwAAANQ"]
[Mon Jul 20 06:11:17.808330 2026] [security2:error] [pid 843279:tid 843433] [client 50.116.65.227:15724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QZfqvKNcW5yy5T2CpzwAAAJw"]
[Mon Jul 20 06:11:17.821267 2026] [security2:error] [pid 843279:tid 843524] [client 50.116.65.227:15738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QZfqvKNcW5yy5T2Cp0gAAAPY"]
[Mon Jul 20 06:11:18.408917 2026] [security2:error] [pid 843279:tid 843460] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAQAAALc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:18.413863 2026] [security2:error] [pid 843279:tid 843476] [client 164.100.212.184:51298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAgAAAMc"]
[Mon Jul 20 06:11:18.413958 2026] [security2:error] [pid 843279:tid 843476] [client 164.100.212.184:51298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAgAAAMc"]
[Mon Jul 20 06:11:18.454270 2026] [security2:error] [pid 843279:tid 843439] [client 23.251.146.115:1264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqAAAAonI"]
[Mon Jul 20 06:11:18.457182 2026] [security2:error] [pid 843279:tid 843531] [client 23.251.146.115:1904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2Cp_gAA_XQ"]
[Mon Jul 20 06:11:18.503220 2026] [security2:error] [pid 843279:tid 843495] [client 57.141.18.75:63364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QYPqvKNcW5yy5T2CoFAAA2i8"]
[Mon Jul 20 06:11:18.557018 2026] [security2:error] [pid 843279:tid 843488] [client 14.225.17.146:55728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpdQAAANM"], referer: http://nurturemarple.co.uk/WORDPRESS
[Mon Jul 20 06:11:18.576257 2026] [security2:error] [pid 843279:tid 843415] [client 23.251.146.115:1264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqDwAAijo"]
[Mon Jul 20 06:11:18.599106 2026] [security2:error] [pid 843279:tid 843437] [client 23.251.146.115:1904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqEQAAoAA"]
[Mon Jul 20 06:11:18.612819 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZvqvKNcW5yy5T2CqGwAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:18.630840 2026] [security2:error] [pid 843279:tid 843465] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZvqvKNcW5yy5T2CqGwAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:18.841707 2026] [security2:error] [pid 843279:tid 843536] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqKwAAAQI"]
[Mon Jul 20 06:11:18.877700 2026] [security2:error] [pid 843279:tid 843535] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqLQAAAQE"]
[Mon Jul 20 06:11:18.948841 2026] [security2:error] [pid 843279:tid 843534] [client 198.44.157.34:40310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqPgAAAQA"]
[Mon Jul 20 06:11:18.948975 2026] [security2:error] [pid 843279:tid 843534] [client 198.44.157.34:40310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4QZvqvKNcW5yy5T2CqPgAAAQA"]
[Mon Jul 20 06:11:18.959883 2026] [security2:error] [pid 843279:tid 843531] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqOQAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:19.050007 2026] [security2:error] [pid 843279:tid 843413] [client 50.116.65.227:15774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqIQAAAIg"]
[Mon Jul 20 06:11:19.134170 2026] [security2:error] [pid 843279:tid 843519] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqWAAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:19.242527 2026] [security2:error] [pid 843279:tid 843352] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqXwAA7kc"]
[Mon Jul 20 06:11:19.242810 2026] [security2:error] [pid 843279:tid 843516] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqXwAA7kc"]
[Mon Jul 20 06:11:19.310905 2026] [security2:error] [pid 843279:tid 843520] [client 50.116.65.227:52180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqUwAAAPI"]
[Mon Jul 20 06:11:19.434887 2026] [security2:error] [pid 843279:tid 843524] [client 45.157.112.60:36893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqcQAAAPY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:19.471540 2026] [security2:error] [pid 843279:tid 843476] [client 106.192.104.4:60992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqfQAAAMc"]
[Mon Jul 20 06:11:19.471659 2026] [security2:error] [pid 843279:tid 843476] [client 106.192.104.4:60992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqfQAAAMc"]
[Mon Jul 20 06:11:19.499611 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:64243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqbwAAAJM"], referer: https://nurturemarple.co.uk/WORDPRESS
[Mon Jul 20 06:11:19.529109 2026] [security2:error] [pid 843279:tid 843489] [client 23.251.146.115:12320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqcgAA1CE"]
[Mon Jul 20 06:11:19.652600 2026] [security2:error] [pid 843279:tid 843501] [client 23.251.146.115:12320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqhwAA4Es"]
[Mon Jul 20 06:11:19.951451 2026] [security2:error] [pid 843279:tid 843521] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqmgAAAPM"]
[Mon Jul 20 06:11:19.975861 2026] [security2:error] [pid 843279:tid 843425] [client 107.175.132.21:50150] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "mail.tripppconsulting.com"] [uri "/"] [unique_id "al4QZ_qvKNcW5yy5T2CqpwAAAJQ"]
[Mon Jul 20 06:11:20.190316 2026] [security2:error] [pid 843279:tid 843300] [remote 182.77.62.24:53862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QaPqvKNcW5yy5T2CqwAAAixM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:11:20.210435 2026] [security2:error] [pid 843279:tid 843493] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QaPqvKNcW5yy5T2CqtgAAANg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:20.272722 2026] [security2:error] [pid 843279:tid 843432] [client 57.141.18.90:44582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CotgAAmyk"]
[Mon Jul 20 06:11:20.367567 2026] [security2:error] [pid 843279:tid 843443] [client 185.132.186.74:30899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/shell.php"] [unique_id "al4QaPqvKNcW5yy5T2Cq0QAAAKY"]
[Mon Jul 20 06:11:20.400153 2026] [security2:error] [pid 843279:tid 843428] [client 57.141.18.0:24482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QYvqvKNcW5yy5T2CovAAAl3Y"]
[Mon Jul 20 06:11:20.495161 2026] [security2:error] [pid 843279:tid 843459] [client 14.225.17.146:64255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqTwAAALY"], referer: http://scott-assist.com/WORDPRESS
[Mon Jul 20 06:11:20.745186 2026] [security2:error] [pid 843279:tid 843472] [client 14.225.17.146:64276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqVwAAAMM"], referer: http://cephasnext.com/WORDPRESS
[Mon Jul 20 06:11:20.854645 2026] [security2:error] [pid 843279:tid 843413] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QaPqvKNcW5yy5T2Cq_QAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:20.925124 2026] [security2:error] [pid 843279:tid 843473] [client 74.7.230.6:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/robots.txt"] [unique_id "al4QaPqvKNcW5yy5T2CrAwAAAMQ"]
[Mon Jul 20 06:11:20.941250 2026] [security2:error] [pid 843279:tid 843477] [client 74.7.230.6:55774] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.maxenengineering.com"] [uri "/robots.txt"] [unique_id "al4QaPqvKNcW5yy5T2Cq_gAAyDM"]
[Mon Jul 20 06:11:21.138522 2026] [security2:error] [pid 843279:tid 843431] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QafqvKNcW5yy5T2CrDgAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:21.314941 2026] [security2:error] [pid 843279:tid 843402] [remote 130.51.180.8:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QafqvKNcW5yy5T2CrHwAA53k"]
[Mon Jul 20 06:11:21.464580 2026] [security2:error] [pid 843279:tid 843522] [client 14.225.17.146:64207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4QZ_qvKNcW5yy5T2CqZQAAAPQ"], referer: http://expertcultures.com/WORDPRESS
[Mon Jul 20 06:11:21.488680 2026] [security2:error] [pid 843279:tid 843295] [remote 130.51.180.8:35558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QafqvKNcW5yy5T2CrNAAAhQ4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:11:21.726097 2026] [security2:error] [pid 843279:tid 843328] [remote 92.222.104.201:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "puppoopatrol.com"] [uri "/wp-sitemap.xml"] [unique_id "al4QafqvKNcW5yy5T2CrTQAA8y8"]
[Mon Jul 20 06:11:21.726295 2026] [security2:error] [pid 843279:tid 843521] [client 92.222.104.201:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "puppoopatrol.com"] [uri "/wp-sitemap.xml"] [unique_id "al4QafqvKNcW5yy5T2CrTQAA8y8"]
[Mon Jul 20 06:11:21.892241 2026] [security2:error] [pid 843279:tid 843454] [client 27.96.94.195:37702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QafqvKNcW5yy5T2CrYgAAALE"]
[Mon Jul 20 06:11:21.892373 2026] [security2:error] [pid 843279:tid 843454] [client 27.96.94.195:37702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QafqvKNcW5yy5T2CrYgAAALE"]
[Mon Jul 20 06:11:21.978856 2026] [security2:error] [pid 843279:tid 843508] [client 14.225.17.146:55110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4QafqvKNcW5yy5T2CrMwAAAOY"]
[Mon Jul 20 06:11:22.021078 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2CqwgAApGw"], referer: http://aleishapenny.ca/WORDPRESS
[Mon Jul 20 06:11:22.114363 2026] [security2:error] [pid 843279:tid 843416] [client 103.77.203.233:64726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QavqvKNcW5yy5T2CreAAAAIs"]
[Mon Jul 20 06:11:22.114720 2026] [security2:error] [pid 843279:tid 843416] [client 103.77.203.233:64726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QavqvKNcW5yy5T2CreAAAAIs"]
[Mon Jul 20 06:11:22.416719 2026] [security2:error] [pid 843279:tid 843419] [client 57.141.18.120:38604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZPqvKNcW5yy5T2CpcgAAjk8"]
[Mon Jul 20 06:11:22.446069 2026] [security2:error] [pid 843279:tid 843530] [client 14.225.17.146:65499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2CqrQAAAPw"], referer: http://balticsteelmgmt.com/WORDPRESS
[Mon Jul 20 06:11:22.550137 2026] [security2:error] [pid 843279:tid 843470] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QavqvKNcW5yy5T2CrkgAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:22.623057 2026] [security2:error] [pid 843279:tid 843457] [client 57.141.18.99:38360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZfqvKNcW5yy5T2CpigAAtCY"]
[Mon Jul 20 06:11:22.799776 2026] [security2:error] [pid 843279:tid 843511] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4QavqvKNcW5yy5T2CrmwAA6Sw"], referer: https://aleishapenny.ca/WORDPRESS
[Mon Jul 20 06:11:22.799776 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QavqvKNcW5yy5T2CrpAAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:22.818081 2026] [security2:error] [pid 843279:tid 843502] [client 57.141.18.63:30510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZfqvKNcW5yy5T2CplAAA4TU"]
[Mon Jul 20 06:11:23.314843 2026] [security2:error] [pid 843279:tid 843416] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qa_qvKNcW5yy5T2CrzwAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:23.383682 2026] [security2:error] [pid 843279:tid 843503] [client 185.132.186.82:35067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/erinyani/default.php"] [unique_id "al4Qa_qvKNcW5yy5T2Cr2wAAAOI"]
[Mon Jul 20 06:11:23.457242 2026] [security2:error] [pid 843279:tid 843533] [client 3.109.4.218:14676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Qa_qvKNcW5yy5T2Cr3wAAAP8"]
[Mon Jul 20 06:11:23.497724 2026] [core:error] [pid 843279:tid 843504] [client 14.225.17.146:59992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:23.497744 2026] [core:error] [pid 843279:tid 843504] [client 14.225.17.146:59992] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:24.026707 2026] [security2:error] [pid 843279:tid 843484] [client 57.141.18.37:65102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QZvqvKNcW5yy5T2CqFwAAzys"]
[Mon Jul 20 06:11:24.189453 2026] [security2:error] [pid 843279:tid 843456] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsHQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.189624 2026] [security2:error] [pid 843279:tid 843456] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsHQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.219835 2026] [security2:error] [pid 843279:tid 843443] [client 74.7.228.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsFAAAAKY"], referer: https://www.maxenengineering.com/use-of-concrete-cutting-equipment/
[Mon Jul 20 06:11:24.473426 2026] [security2:error] [pid 843279:tid 843504] [client 14.225.17.146:60264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsLAAAAOM"], referer: http://fkconstructionfunding.com/WORDPRESS
[Mon Jul 20 06:11:24.504223 2026] [security2:error] [pid 843279:tid 843521] [client 65.1.132.125:12478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsOgAAAPM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:11:24.572176 2026] [security2:error] [pid 843279:tid 843537] [client 14.225.17.146:55233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsMwAAAQM"]
[Mon Jul 20 06:11:24.626116 2026] [security2:error] [pid 843279:tid 843513] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsPgAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.966488 2026] [security2:error] [pid 843279:tid 843485] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QbPqvKNcW5yy5T2CsaAAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:24.971375 2026] [security2:error] [pid 843279:tid 843495] [client 50.116.65.227:29158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QbPqvKNcW5yy5T2CsagAAANo"]
[Mon Jul 20 06:11:24.987016 2026] [security2:error] [pid 843279:tid 843427] [client 50.116.65.227:52230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QbPqvKNcW5yy5T2CsbAAAAJY"]
[Mon Jul 20 06:11:25.348515 2026] [security2:error] [pid 843279:tid 843511] [client 181.224.94.124:10329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CsiQAAAOk"]
[Mon Jul 20 06:11:25.348634 2026] [security2:error] [pid 843279:tid 843511] [client 181.224.94.124:10329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CsiQAAAOk"]
[Mon Jul 20 06:11:25.466278 2026] [security2:error] [pid 843279:tid 843455] [client 103.141.108.143:57218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CskgAAALI"]
[Mon Jul 20 06:11:25.466454 2026] [security2:error] [pid 843279:tid 843455] [client 103.141.108.143:57218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QbfqvKNcW5yy5T2CskgAAALI"]
[Mon Jul 20 06:11:25.544624 2026] [security2:error] [pid 843279:tid 843418] [client 14.225.17.146:55453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QbfqvKNcW5yy5T2CsiwAAAI0"], referer: https://fkconstructionfunding.com/WORDPRESS
[Mon Jul 20 06:11:25.676167 2026] [security2:error] [pid 843279:tid 843486] [client 57.141.18.111:30134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2CqyAAA0Rw"]
[Mon Jul 20 06:11:25.754702 2026] [security2:error] [pid 843279:tid 843424] [client 14.225.17.146:60239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsKgAAAJM"], referer: http://omrobuildingcenter.com/WORDPRESS
[Mon Jul 20 06:11:25.942047 2026] [security2:error] [pid 843279:tid 843389] [remote 212.95.34.85:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QbfqvKNcW5yy5T2CssgAAj2w"]
[Mon Jul 20 06:11:26.078843 2026] [security2:error] [pid 843279:tid 843317] [remote 20.87.239.85:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2CswAAA_yQ"]
[Mon Jul 20 06:11:26.151251 2026] [security2:error] [pid 843279:tid 843308] [remote 212.95.34.85:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2CsxwAA7xs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:11:26.172800 2026] [security2:error] [pid 843279:tid 843299] [remote 5.161.225.162:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2CsyQAA5hI"]
[Mon Jul 20 06:11:26.299632 2026] [security2:error] [pid 843279:tid 843448] [client 57.141.18.122:59510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QaPqvKNcW5yy5T2Cq9wAAqzA"]
[Mon Jul 20 06:11:26.414157 2026] [security2:error] [pid 843279:tid 843526] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs1AAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:26.596063 2026] [security2:error] [pid 843279:tid 843334] [remote 20.87.239.85:9541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs6wAAzzU"], referer: https://website-e4de5cd0.epu.kzx.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:11:26.609222 2026] [security2:error] [pid 843279:tid 843313] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs7QAA0yA"]
[Mon Jul 20 06:11:26.609381 2026] [security2:error] [pid 843279:tid 843488] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs7QAA0yA"]
[Mon Jul 20 06:11:26.691049 2026] [security2:error] [pid 843279:tid 843431] [client 112.213.160.112:30876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs-wAAAJo"]
[Mon Jul 20 06:11:26.691186 2026] [security2:error] [pid 843279:tid 843431] [client 112.213.160.112:30876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2Cs-wAAAJo"]
[Mon Jul 20 06:11:26.719389 2026] [security2:error] [pid 843279:tid 843475] [client 14.225.17.146:49331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4QbvqvKNcW5yy5T2CsxAAAAMY"], referer: http://idigress.group/WORDPRESS
[Mon Jul 20 06:11:26.853127 2026] [security2:error] [pid 843279:tid 843434] [client 41.173.37.102:2095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtAgAAAJ0"]
[Mon Jul 20 06:11:26.853249 2026] [security2:error] [pid 843279:tid 843434] [client 41.173.37.102:2095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtAgAAAJ0"]
[Mon Jul 20 06:11:26.874887 2026] [security2:error] [pid 843279:tid 843478] [client 150.228.148.150:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtBQAAAMk"]
[Mon Jul 20 06:11:26.875001 2026] [security2:error] [pid 843279:tid 843478] [client 150.228.148.150:57920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtBQAAAMk"]
[Mon Jul 20 06:11:26.877694 2026] [security2:error] [pid 843279:tid 843489] [client 45.116.69.230:53638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtCAAAANQ"]
[Mon Jul 20 06:11:26.877793 2026] [security2:error] [pid 843279:tid 843489] [client 45.116.69.230:53638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QbvqvKNcW5yy5T2CtCAAAANQ"]
[Mon Jul 20 06:11:26.900809 2026] [security2:error] [pid 843279:tid 843416] [client 66.249.70.32:56580] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "gitec.org"] [uri "/robots.txt"] [unique_id "al4QbvqvKNcW5yy5T2CtDAAAAIs"]
[Mon Jul 20 06:11:26.915829 2026] [security2:error] [pid 843279:tid 843500] [client 185.132.186.75:48387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/index.php"] [unique_id "al4QbvqvKNcW5yy5T2CtEQAAAN8"]
[Mon Jul 20 06:11:27.133500 2026] [security2:error] [pid 843279:tid 843367] [remote 5.161.225.162:35088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtKAAAjFY"], referer: https://michiganhomecaregroup.com/wp-login.php
[Mon Jul 20 06:11:27.588866 2026] [security2:error] [pid 843279:tid 843371] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRgAA6lo"]
[Mon Jul 20 06:11:27.589021 2026] [security2:error] [pid 843279:tid 843512] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRgAA6lo"]
[Mon Jul 20 06:11:27.592277 2026] [security2:error] [pid 843279:tid 843486] [client 86.98.90.58:18668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRQAAANE"]
[Mon Jul 20 06:11:27.592374 2026] [security2:error] [pid 843279:tid 843486] [client 86.98.90.58:18668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtRQAAANE"]
[Mon Jul 20 06:11:27.645077 2026] [security2:error] [pid 843279:tid 843410] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtSAAAAIU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:27.652205 2026] [security2:error] [pid 843279:tid 843505] [client 57.141.18.31:47876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QavqvKNcW5yy5T2CrfAAA5Ho"]
[Mon Jul 20 06:11:27.904425 2026] [security2:error] [pid 843279:tid 843472] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtVAAAAMM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:28.098598 2026] [security2:error] [pid 843279:tid 843390] [remote 152.228.213.32:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4QcPqvKNcW5yy5T2CtcwAA-20"]
[Mon Jul 20 06:11:28.203471 2026] [security2:error] [pid 843279:tid 843522] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtbwAAAPQ"]
[Mon Jul 20 06:11:28.244663 2026] [security2:error] [pid 843279:tid 843387] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CtewAA72o"]
[Mon Jul 20 06:11:28.244931 2026] [security2:error] [pid 843279:tid 843517] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CtewAA72o"]
[Mon Jul 20 06:11:28.304885 2026] [security2:error] [pid 843279:tid 843315] [remote 152.228.213.32:45000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4QcPqvKNcW5yy5T2CtfQAA7iI"], referer: https://musichaven.info/wp-login.php
[Mon Jul 20 06:11:28.358275 2026] [security2:error] [pid 843279:tid 843413] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QcPqvKNcW5yy5T2CtfwAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:28.433033 2026] [security2:error] [pid 843279:tid 843504] [client 158.173.89.95:40299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QcPqvKNcW5yy5T2CtigAAAOM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:28.903296 2026] [security2:error] [pid 843279:tid 843499] [client 185.132.186.79:37127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/xex.php"] [unique_id "al4QcPqvKNcW5yy5T2CttQAAAN4"]
[Mon Jul 20 06:11:28.913937 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CttwAAALc"]
[Mon Jul 20 06:11:28.914061 2026] [security2:error] [pid 843279:tid 843460] [client 164.100.212.184:56189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QcPqvKNcW5yy5T2CttwAAALc"]
[Mon Jul 20 06:11:29.363563 2026] [security2:error] [pid 843279:tid 843504] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QcfqvKNcW5yy5T2Ct1wAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:29.397947 2026] [core:error] [pid 843279:tid 843434] [client 14.225.17.146:59940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:29.397969 2026] [core:error] [pid 843279:tid 843434] [client 14.225.17.146:59940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:29.567067 2026] [security2:error] [pid 843279:tid 843475] [client 74.208.214.194:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QcfqvKNcW5yy5T2Ct8wAAAMY"]
[Mon Jul 20 06:11:29.763830 2026] [security2:error] [pid 843279:tid 843308] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QcfqvKNcW5yy5T2CuBQABAhs"]
[Mon Jul 20 06:11:29.764027 2026] [security2:error] [pid 843279:tid 843536] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QcfqvKNcW5yy5T2CuBQABAhs"]
[Mon Jul 20 06:11:29.918603 2026] [security2:error] [pid 843279:tid 843535] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2CuBAAAAQE"]
[Mon Jul 20 06:11:29.966824 2026] [security2:error] [pid 843279:tid 843398] [remote 110.249.202.189:14778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/lsd-legal-memo-prisoner-reallocation-final-august-2021.pdf"] [unique_id "al4QcfqvKNcW5yy5T2CuFQAAtHU"]
[Mon Jul 20 06:11:30.383246 2026] [security2:error] [pid 843279:tid 843509] [client 106.192.104.4:61519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOAAAAOc"]
[Mon Jul 20 06:11:30.383357 2026] [security2:error] [pid 843279:tid 843509] [client 106.192.104.4:61519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOAAAAOc"]
[Mon Jul 20 06:11:30.561110 2026] [security2:error] [pid 843279:tid 843418] [client 14.225.17.146:53393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2CtwwAAAI0"], referer: http://sarahsnyder.net/WORDPRESS
[Mon Jul 20 06:11:30.572462 2026] [security2:error] [pid 843279:tid 843470] [client 57.141.18.34:49660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QbPqvKNcW5yy5T2CsSwAAwTQ"]
[Mon Jul 20 06:11:30.642161 2026] [security2:error] [pid 843279:tid 843492] [client 14.225.17.146:60313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOwAAANc"], referer: http://longevityperformanceclinic.com/WORDPRESS
[Mon Jul 20 06:11:30.654905 2026] [security2:error] [pid 843279:tid 843463] [client 82.215.102.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtowAAALo"]
[Mon Jul 20 06:11:30.665338 2026] [security2:error] [pid 843279:tid 843448] [client 14.225.17.146:53311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtsgAAAKs"], referer: http://bigwormfishing.com/WORDPRESS
[Mon Jul 20 06:11:30.818380 2026] [security2:error] [pid 843279:tid 843537] [client 14.225.17.146:60311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOgAAAQM"], referer: http://hilltopnurseryinc.com/WORDPRESS
[Mon Jul 20 06:11:30.843267 2026] [security2:error] [pid 843279:tid 843530] [client 185.132.186.56:43117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/about.php"] [unique_id "al4QcvqvKNcW5yy5T2CuZwAAAPw"]
[Mon Jul 20 06:11:31.399607 2026] [security2:error] [pid 843279:tid 843440] [client 14.225.17.146:63051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CukAAAAKM"], referer: http://grndl.com/WORDPRESS
[Mon Jul 20 06:11:31.501509 2026] [security2:error] [pid 843279:tid 843499] [client 74.208.214.194:48910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Qc_qvKNcW5yy5T2CulwAAAN4"]
[Mon Jul 20 06:11:31.624500 2026] [security2:error] [pid 843279:tid 843463] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qc_qvKNcW5yy5T2CumgAAALo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:31.672302 2026] [security2:error] [pid 843279:tid 843442] [client 14.225.17.146:63043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CulgAAAKU"], referer: https://bigwormfishing.com/WORDPRESS
[Mon Jul 20 06:11:31.697211 2026] [security2:error] [pid 843279:tid 843513] [client 14.225.17.146:63111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CunAAAAOs"], referer: https://sarahsnyder.net/WORDPRESS
[Mon Jul 20 06:11:31.799010 2026] [security2:error] [pid 843279:tid 843468] [client 14.225.17.146:60116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2CuEgAAAL8"], referer: http://fluidtemple.org/WORDPRESS
[Mon Jul 20 06:11:32.179781 2026] [security2:error] [pid 843279:tid 843495] [client 57.141.18.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QdPqvKNcW5yy5T2CuwwAAANo"]
[Mon Jul 20 06:11:32.356037 2026] [security2:error] [pid 843279:tid 843493] [client 14.225.17.146:55187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CucAAAANg"], referer: http://cloudspacesgroup.com/WORDPRESS
[Mon Jul 20 06:11:32.383335 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu5AAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:32.383497 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu5AAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:32.524872 2026] [security2:error] [pid 843279:tid 843290] [remote 209.97.182.179:60542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.182.97.209.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu6wAAjwk"]
[Mon Jul 20 06:11:32.525118 2026] [security2:error] [pid 843279:tid 843420] [client 209.97.182.179:60542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2Cu6wAAjwk"]
[Mon Jul 20 06:11:32.539356 2026] [security2:error] [pid 843279:tid 843513] [client 50.116.65.227:15434] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4QdPqvKNcW5yy5T2Cu9AAAAOs"]
[Mon Jul 20 06:11:32.547468 2026] [security2:error] [pid 843279:tid 843456] [client 14.225.17.146:60268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuOQAAALM"], referer: http://oldracelimited.com/WORDPRESS
[Mon Jul 20 06:11:32.553291 2026] [security2:error] [pid 843279:tid 843443] [client 50.116.65.227:31678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4QdPqvKNcW5yy5T2Cu9wAAAKY"]
[Mon Jul 20 06:11:32.794097 2026] [security2:error] [pid 843279:tid 843446] [client 185.132.186.70:44365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/install.php"] [unique_id "al4QdPqvKNcW5yy5T2CvBgAAAKk"]
[Mon Jul 20 06:11:32.814428 2026] [security2:error] [pid 843279:tid 843462] [client 103.77.203.233:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2CvCAAAALk"]
[Mon Jul 20 06:11:32.815689 2026] [security2:error] [pid 843279:tid 843462] [client 103.77.203.233:65265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QdPqvKNcW5yy5T2CvCAAAALk"]
[Mon Jul 20 06:11:32.946849 2026] [security2:error] [pid 843279:tid 843532] [client 50.116.65.227:31694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4QdPqvKNcW5yy5T2CvAwAAAP4"]
[Mon Jul 20 06:11:33.156660 2026] [security2:error] [pid 843279:tid 843420] [client 50.116.65.227:31708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4QdPqvKNcW5yy5T2CvFAAAAI8"]
[Mon Jul 20 06:11:33.234371 2026] [security2:error] [pid 843279:tid 843417] [client 57.141.18.22:62068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qb_qvKNcW5yy5T2CtTgAAjC0"]
[Mon Jul 20 06:11:33.339764 2026] [security2:error] [pid 843279:tid 843446] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvLwAAAKk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:33.344317 2026] [security2:error] [pid 843279:tid 843479] [client 27.96.94.195:37743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QdfqvKNcW5yy5T2CvOAAAAMo"]
[Mon Jul 20 06:11:33.344457 2026] [security2:error] [pid 843279:tid 843479] [client 27.96.94.195:37743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QdfqvKNcW5yy5T2CvOAAAAMo"]
[Mon Jul 20 06:11:33.475609 2026] [security2:error] [pid 843279:tid 843510] [client 170.106.142.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvNAAA6Hw"]
[Mon Jul 20 06:11:33.482380 2026] [security2:error] [pid 843279:tid 843423] [client 14.225.17.146:55191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CucQAAAJI"], referer: http://adastra.love/WORDPRESS
[Mon Jul 20 06:11:33.561111 2026] [security2:error] [pid 843279:tid 843434] [client 52.167.144.168:9411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvPQAAnRg"]
[Mon Jul 20 06:11:33.784546 2026] [security2:error] [pid 843279:tid 843292] [remote 84.247.172.23:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QdfqvKNcW5yy5T2CvYgAAmws"]
[Mon Jul 20 06:11:33.792827 2026] [security2:error] [pid 843279:tid 843452] [client 57.141.18.51:42976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QcPqvKNcW5yy5T2CtgAAArwU"]
[Mon Jul 20 06:11:33.939816 2026] [security2:error] [pid 843279:tid 843535] [client 142.93.64.197:40864] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4QdfqvKNcW5yy5T2CveAAAAQE"]
[Mon Jul 20 06:11:33.986005 2026] [security2:error] [pid 843279:tid 843327] [remote 84.247.172.23:40998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QdfqvKNcW5yy5T2CvfwAAoy4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:11:34.027465 2026] [security2:error] [pid 843279:tid 843514] [client 142.93.64.197:45784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4QdvqvKNcW5yy5T2CvgQAAAOw"]
[Mon Jul 20 06:11:34.052522 2026] [security2:error] [pid 843279:tid 843463] [client 103.153.183.69:56846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//var/www/html/config.php"] [unique_id "al4QdvqvKNcW5yy5T2CvhwAAALo"], referer: https://www.facebook.com/
[Mon Jul 20 06:11:34.295589 2026] [security2:error] [pid 843279:tid 843355] [remote 154.66.198.148:19178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdvqvKNcW5yy5T2CvnQAA2Uo"]
[Mon Jul 20 06:11:34.295855 2026] [security2:error] [pid 843279:tid 843494] [client 154.66.198.148:19178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QdvqvKNcW5yy5T2CvnQAA2Uo"]
[Mon Jul 20 06:11:34.322913 2026] [security2:error] [pid 843279:tid 843537] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QdvqvKNcW5yy5T2CvowAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:34.376729 2026] [security2:error] [pid 843279:tid 843513] [client 103.153.183.69:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//var/www/html/configuration.php"] [unique_id "al4QdvqvKNcW5yy5T2CvqQAAAOs"], referer: https://www.bing.com/search?q=q7awxx
[Mon Jul 20 06:11:34.424573 2026] [security2:error] [pid 843279:tid 843536] [client 174.138.89.209:44958] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4QdvqvKNcW5yy5T2CvrAAAAQI"]
[Mon Jul 20 06:11:34.460663 2026] [security2:error] [pid 843279:tid 843524] [client 57.141.18.31:47882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QcfqvKNcW5yy5T2Ct0AAA9mY"]
[Mon Jul 20 06:11:34.719612 2026] [security2:error] [pid 843279:tid 843428] [client 185.132.186.70:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/upload/install.php"] [unique_id "al4QdvqvKNcW5yy5T2CvwQAAAJc"]
[Mon Jul 20 06:11:34.761020 2026] [security2:error] [pid 843279:tid 843486] [client 103.153.183.69:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../app/.env"] [unique_id "al4QdvqvKNcW5yy5T2CvwgAAANE"], referer: https://t.co/huedcyk2vi
[Mon Jul 20 06:11:34.820860 2026] [security2:error] [pid 843279:tid 843442] [client 103.153.183.69:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../srv/.env"] [unique_id "al4QdvqvKNcW5yy5T2CvxwAAAKU"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:34.893673 2026] [security2:error] [pid 843279:tid 843538] [client 103.153.183.69:56862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/.env"] [unique_id "al4QdvqvKNcW5yy5T2CvzwAAAQQ"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:11:35.291570 2026] [security2:error] [pid 843279:tid 843414] [client 74.7.228.25:53202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "intelligentengineeringsolutions.com"] [uri "/robots.txt"] [unique_id "al4Qd_qvKNcW5yy5T2Cv-QAAAIk"]
[Mon Jul 20 06:11:35.372415 2026] [security2:error] [pid 843279:tid 843467] [client 57.141.18.61:36796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QcvqvKNcW5yy5T2CuIAAAvlc"]
[Mon Jul 20 06:11:35.552242 2026] [security2:error] [pid 843279:tid 843421] [client 14.225.17.146:64437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4QdfqvKNcW5yy5T2CvOwAAAJA"], referer: http://dollpassionista.com/WORDPRESS
[Mon Jul 20 06:11:35.585286 2026] [security2:error] [pid 843279:tid 843514] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwGQAAAOw"], referer: http://intelligentengineeringsolutions.com/robots.txt
[Mon Jul 20 06:11:35.602476 2026] [security2:error] [pid 843279:tid 843524] [client 74.7.228.25:41184] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/robots.txt"] [unique_id "al4Qd_qvKNcW5yy5T2CwEAAA9l4"], referer: http://intelligentengineeringsolutions.com/robots.txt
[Mon Jul 20 06:11:35.610391 2026] [security2:error] [pid 843279:tid 843517] [client 180.191.126.129:25657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.126.191.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apolloinfrastructureholdings.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwIQAAAO8"]
[Mon Jul 20 06:11:35.610553 2026] [security2:error] [pid 843279:tid 843517] [client 180.191.126.129:25657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apolloinfrastructureholdings.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwIQAAAO8"]
[Mon Jul 20 06:11:35.901356 2026] [security2:error] [pid 843279:tid 843502] [client 181.224.94.124:24069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwQwAAAOE"]
[Mon Jul 20 06:11:35.901521 2026] [security2:error] [pid 843279:tid 843502] [client 181.224.94.124:24069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qd_qvKNcW5yy5T2CwQwAAAOE"]
[Mon Jul 20 06:11:35.913641 2026] [security2:error] [pid 843279:tid 843474] [client 50.116.65.227:31790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Qd_qvKNcW5yy5T2CwRQAAAMU"]
[Mon Jul 20 06:11:35.927400 2026] [security2:error] [pid 843279:tid 843421] [client 50.116.65.227:31796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Qd_qvKNcW5yy5T2CwSAAAAJA"]
[Mon Jul 20 06:11:36.090282 2026] [security2:error] [pid 843279:tid 843407] [remote 119.94.178.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.178.94.119.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "apolloinfrastructureholdings.online"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwUAAAhX4"]
[Mon Jul 20 06:11:36.090652 2026] [security2:error] [pid 843279:tid 843410] [client 119.94.178.137:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "apolloinfrastructureholdings.online"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwUAAAhX4"]
[Mon Jul 20 06:11:36.220160 2026] [security2:error] [pid 843279:tid 843493] [client 103.141.108.143:57687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwXQAAANg"]
[Mon Jul 20 06:11:36.220328 2026] [security2:error] [pid 843279:tid 843493] [client 103.141.108.143:57687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QePqvKNcW5yy5T2CwXQAAANg"]
[Mon Jul 20 06:11:36.437320 2026] [security2:error] [pid 843279:tid 843431] [client 14.225.17.146:64003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwXwAAAJo"], referer: http://adirondackengineering.com/WORDPRESS
[Mon Jul 20 06:11:36.593687 2026] [security2:error] [pid 843279:tid 843412] [client 14.225.17.146:53600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwZAAAAIc"], referer: https://dollpassionista.com/WORDPRESS
[Mon Jul 20 06:11:36.616584 2026] [security2:error] [pid 843279:tid 843461] [client 170.62.100.241:50402] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "adirondackengineering.com"] [uri "/wp-content/plugins/miniorange-login-openid/readme.txt"] [unique_id "al4QePqvKNcW5yy5T2CwigAAALg"]
[Mon Jul 20 06:11:36.810766 2026] [security2:error] [pid 843279:tid 843511] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QePqvKNcW5yy5T2CwjQAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:36.877420 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:49787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4Qd_qvKNcW5yy5T2Cv_QAAANs"], referer: http://thechancersband.com/WORDPRESS
[Mon Jul 20 06:11:37.080392 2026] [security2:error] [pid 843279:tid 843501] [client 57.141.18.107:46184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qc_qvKNcW5yy5T2CujgAA4Bc"]
[Mon Jul 20 06:11:37.181966 2026] [security2:error] [pid 843279:tid 843329] [remote 57.141.18.72:35938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6001418"] [unique_id "al4QefqvKNcW5yy5T2CwvgAAsDA"]
[Mon Jul 20 06:11:37.242631 2026] [security2:error] [pid 843279:tid 843470] [client 150.228.148.150:31375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwxQAAAME"]
[Mon Jul 20 06:11:37.242770 2026] [security2:error] [pid 843279:tid 843470] [client 150.228.148.150:31375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwxQAAAME"]
[Mon Jul 20 06:11:37.330016 2026] [security2:error] [pid 843279:tid 843327] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyAAAny4"]
[Mon Jul 20 06:11:37.330218 2026] [security2:error] [pid 843279:tid 843436] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyAAAny4"]
[Mon Jul 20 06:11:37.351337 2026] [security2:error] [pid 843279:tid 843412] [client 112.213.160.112:31216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyQAAAIc"]
[Mon Jul 20 06:11:37.351429 2026] [security2:error] [pid 843279:tid 843412] [client 112.213.160.112:31216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwyQAAAIc"]
[Mon Jul 20 06:11:37.406087 2026] [security2:error] [pid 843279:tid 843420] [client 45.116.69.230:54143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwzAAAAI8"]
[Mon Jul 20 06:11:37.406209 2026] [security2:error] [pid 843279:tid 843420] [client 45.116.69.230:54143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwzAAAAI8"]
[Mon Jul 20 06:11:37.414525 2026] [security2:error] [pid 843279:tid 843426] [client 41.173.37.102:2557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwywAAAJU"]
[Mon Jul 20 06:11:37.414695 2026] [security2:error] [pid 843279:tid 843426] [client 41.173.37.102:2557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2CwywAAAJU"]
[Mon Jul 20 06:11:37.671004 2026] [http2:info] [pid 858085:tid 858085] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:11:37.876807 2026] [security2:error] [pid 843279:tid 843421] [client 86.98.90.58:19396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2Cw9wAAAJA"]
[Mon Jul 20 06:11:37.877035 2026] [security2:error] [pid 843279:tid 843421] [client 86.98.90.58:19396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QefqvKNcW5yy5T2Cw9wAAAJA"]
[Mon Jul 20 06:11:37.958736 2026] [security2:error] [pid 843279:tid 843418] [client 111.225.149.104:33212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "timespans.org"] [uri "/robots.txt"] [unique_id "al4QefqvKNcW5yy5T2Cw_AAAAI0"]
[Mon Jul 20 06:11:37.991673 2026] [security2:error] [pid 858085:tid 858224] [client 185.132.186.88:52325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-head.php"] [unique_id "al4QeTAtbv2vrjByhUphNAAAAAg"]
[Mon Jul 20 06:11:38.152461 2026] [security2:error] [pid 843279:tid 843513] [client 52.167.144.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Qd_qvKNcW5yy5T2Cv_gAAAOs"]
[Mon Jul 20 06:11:38.210733 2026] [security2:error] [pid 843279:tid 843301] [remote 173.212.252.15:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4QevqvKNcW5yy5T2CxCQAAxxQ"]
[Mon Jul 20 06:11:38.232098 2026] [security2:error] [pid 843279:tid 843456] [client 37.139.53.5:59269] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxDAAAALM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.232191 2026] [security2:error] [pid 843279:tid 843456] [client 37.139.53.5:59269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxDAAAALM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.232284 2026] [security2:error] [pid 843279:tid 843475] [client 37.139.53.5:59268] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxCwAAAMY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.232399 2026] [security2:error] [pid 843279:tid 843475] [client 37.139.53.5:59268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4QevqvKNcW5yy5T2CxCwAAAMY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:38.263894 2026] [security2:error] [pid 843279:tid 843345] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QevqvKNcW5yy5T2CxDgAAvEA"]
[Mon Jul 20 06:11:38.264147 2026] [security2:error] [pid 843279:tid 843465] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QevqvKNcW5yy5T2CxDgAAvEA"]
[Mon Jul 20 06:11:38.407737 2026] [security2:error] [pid 843279:tid 843343] [remote 173.212.252.15:35106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4QevqvKNcW5yy5T2CxGQAA3D4"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:11:38.533185 2026] [security2:error] [pid 858085:tid 858226] [client 178.152.178.232:37420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphQwAAAAo"]
[Mon Jul 20 06:11:38.533371 2026] [security2:error] [pid 858085:tid 858226] [client 178.152.178.232:37420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphQwAAAAo"]
[Mon Jul 20 06:11:38.816718 2026] [security2:error] [pid 858085:tid 858089] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphUAAALAI"]
[Mon Jul 20 06:11:38.816906 2026] [security2:error] [pid 858085:tid 858260] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphUAAALAI"]
[Mon Jul 20 06:11:38.958796 2026] [security2:error] [pid 843279:tid 843348] [remote 192.241.143.148:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4QevqvKNcW5yy5T2CxPQAA8UM"]
[Mon Jul 20 06:11:38.990229 2026] [security2:error] [pid 858085:tid 858264] [client 170.62.100.241:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.100.62.170.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-content/plugins/miniorange-login-openid/mo-openid-social-login-functions.php"] [unique_id "al4QejAtbv2vrjByhUphVAAAADA"]
[Mon Jul 20 06:11:39.059441 2026] [security2:error] [pid 858085:tid 858281] [client 74.7.227.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QejAtbv2vrjByhUphUwAAAEE"], referer: https://www.maxenengineering.com/importance-of-soil-compaction-in-construction-and-how-it-is-done/
[Mon Jul 20 06:11:39.152430 2026] [security2:error] [pid 843279:tid 843289] [remote 192.241.143.148:50892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxTQAAvwg"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:11:39.181039 2026] [security2:error] [pid 858085:tid 858277] [client 158.173.166.181:44833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QezAtbv2vrjByhUphYAAAAD0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:39.225833 2026] [security2:error] [pid 843279:tid 843428] [client 142.147.108.203:23377] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSwAAAJc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:39.232390 2026] [security2:error] [pid 843279:tid 843426] [client 74.7.228.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSQAAAJU"], referer: https://www.maxenengineering.com/use-of-concrete-cutting-equipment/
[Mon Jul 20 06:11:39.426840 2026] [security2:error] [pid 843279:tid 843472] [client 130.44.202.223:64317] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxUgAAAMM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:39.485254 2026] [security2:error] [pid 843279:tid 843402] [remote 103.57.220.209:38084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.220.57.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxVAAA0Xk"]
[Mon Jul 20 06:11:39.485477 2026] [security2:error] [pid 843279:tid 843486] [client 103.57.220.209:38084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxVAAA0Xk"]
[Mon Jul 20 06:11:39.537205 2026] [security2:error] [pid 858085:tid 858307] [client 164.100.212.184:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QezAtbv2vrjByhUphbQAAAFs"]
[Mon Jul 20 06:11:39.537340 2026] [security2:error] [pid 858085:tid 858307] [client 164.100.212.184:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QezAtbv2vrjByhUphbQAAAFs"]
[Mon Jul 20 06:11:39.754736 2026] [security2:error] [pid 843279:tid 843449] [client 34.221.76.50:40296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxbwAAAKw"]
[Mon Jul 20 06:11:39.791880 2026] [security2:error] [pid 843279:tid 843484] [client 50.116.65.227:55462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Qe_qvKNcW5yy5T2CxdAAAAM8"]
[Mon Jul 20 06:11:39.799894 2026] [security2:error] [pid 858085:tid 858241] [client 43.205.139.3:48860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QejAtbv2vrjByhUphRAAAABk"]
[Mon Jul 20 06:11:39.808018 2026] [security2:error] [pid 858085:tid 858217] [client 50.116.65.227:44646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4QezAtbv2vrjByhUphfQAAAAE"]
[Mon Jul 20 06:11:39.809551 2026] [security2:error] [pid 843279:tid 843346] [remote 20.173.88.122:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxcwAApEE"]
[Mon Jul 20 06:11:39.842581 2026] [security2:error] [pid 843279:tid 843532] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxdQAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:39.935926 2026] [security2:error] [pid 843279:tid 843463] [client 185.132.186.72:36863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/admin-footer.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxegAAALo"]
[Mon Jul 20 06:11:40.120364 2026] [security2:error] [pid 843279:tid 843451] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QfPqvKNcW5yy5T2CxgQAAAK4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:40.142742 2026] [security2:error] [pid 843279:tid 843380] [remote 20.173.88.122:40158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QfPqvKNcW5yy5T2CxhwAAt2M"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:11:40.264205 2026] [security2:error] [pid 858085:tid 858104] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QfDAtbv2vrjByhUphkgAAVRE"]
[Mon Jul 20 06:11:40.264437 2026] [security2:error] [pid 858085:tid 858301] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QfDAtbv2vrjByhUphkgAAVRE"]
[Mon Jul 20 06:11:40.370230 2026] [security2:error] [pid 843279:tid 843469] [client 57.141.18.22:62110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QdvqvKNcW5yy5T2CvpgAAwEs"]
[Mon Jul 20 06:11:40.501222 2026] [security2:error] [pid 858085:tid 858283] [client 14.225.17.146:64746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4QfDAtbv2vrjByhUphlgAAAEM"], referer: http://margaretspeckogawa.com/WORDPRESS
[Mon Jul 20 06:11:40.637551 2026] [security2:error] [pid 843279:tid 843444] [client 103.153.183.69:63998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8fhome/deploy/.ssh/id_rsa"] [unique_id "al4QfPqvKNcW5yy5T2CxpAAAAKc"], referer: https://www.reddit.com/
[Mon Jul 20 06:11:40.639486 2026] [security2:error] [pid 843279:tid 843535] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QfPqvKNcW5yy5T2CxpQAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:41.293533 2026] [security2:error] [pid 843279:tid 843472] [client 130.44.202.223:64317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxUgAAAMM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:41.293588 2026] [security2:error] [pid 843279:tid 843472] [client 130.44.202.223:64317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxUgAAAMM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:41.464972 2026] [security2:error] [pid 843279:tid 843461] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QffqvKNcW5yy5T2CxzgAAALg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:41.506981 2026] [security2:error] [pid 843279:tid 843498] [client 103.153.183.69:63998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8fhome/ec2-user/.ssh/id_rsa"] [unique_id "al4QffqvKNcW5yy5T2Cx0AAAAN0"], referer: https://twitter.com/
[Mon Jul 20 06:11:41.561162 2026] [security2:error] [pid 858085:tid 858258] [client 136.67.14.254:53539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.14.67.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUphzQAAACo"]
[Mon Jul 20 06:11:41.561276 2026] [security2:error] [pid 858085:tid 858258] [client 136.67.14.254:53539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "according2plant.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUphzQAAACo"]
[Mon Jul 20 06:11:41.669569 2026] [core:error] [pid 858085:tid 858239] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:41.669590 2026] [core:error] [pid 858085:tid 858239] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:11:41.719517 2026] [security2:error] [pid 858085:tid 858259] [client 98.159.234.160:36751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QfTAtbv2vrjByhUph3QAAACs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:11:41.815995 2026] [security2:error] [pid 858085:tid 858291] [client 106.192.104.4:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUph4AAAAEs"]
[Mon Jul 20 06:11:41.822620 2026] [security2:error] [pid 858085:tid 858291] [client 106.192.104.4:62024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QfTAtbv2vrjByhUph4AAAAEs"]
[Mon Jul 20 06:11:41.885864 2026] [security2:error] [pid 843279:tid 843445] [client 185.132.186.76:37013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/wp-conflg.php"] [unique_id "al4QffqvKNcW5yy5T2Cx5wAAAKg"]
[Mon Jul 20 06:11:41.910363 2026] [security2:error] [pid 843279:tid 843297] [remote 5.161.225.162:39740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4QffqvKNcW5yy5T2Cx6AAAyBA"]
[Mon Jul 20 06:11:42.032871 2026] [security2:error] [pid 843279:tid 843534] [client 57.141.18.55:65070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwTwABAGA"]
[Mon Jul 20 06:11:42.141769 2026] [security2:error] [pid 843279:tid 843442] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QfvqvKNcW5yy5T2Cx8wAAAKU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:42.229208 2026] [security2:error] [pid 843279:tid 843428] [client 142.147.108.203:23377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSwAAAJc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:42.229283 2026] [security2:error] [pid 843279:tid 843428] [client 142.147.108.203:23377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Qe_qvKNcW5yy5T2CxSwAAAJc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:11:42.240679 2026] [security2:error] [pid 858085:tid 858235] [client 216.73.217.138:41384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QfjAtbv2vrjByhUph7AAAEx0"]
[Mon Jul 20 06:11:42.793249 2026] [security2:error] [pid 843279:tid 843481] [client 57.141.18.47:52592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QePqvKNcW5yy5T2CwlAAAzGs"]
[Mon Jul 20 06:11:42.862275 2026] [security2:error] [pid 843279:tid 843293] [remote 5.161.225.162:39740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4QfvqvKNcW5yy5T2CyIAAA_gw"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:11:43.098253 2026] [security2:error] [pid 843279:tid 843446] [client 47.128.61.169:12114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.polishedpicture.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4Qf_qvKNcW5yy5T2CyLAAAAKk"]
[Mon Jul 20 06:11:43.286763 2026] [security2:error] [pid 843279:tid 843410] [client 65.1.132.125:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyOQAAAIU"]
[Mon Jul 20 06:11:43.429775 2026] [security2:error] [pid 858085:tid 858319] [client 103.77.203.233:49421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QfzAtbv2vrjByhUpiLgAAAGc"]
[Mon Jul 20 06:11:43.429898 2026] [security2:error] [pid 858085:tid 858319] [client 103.77.203.233:49421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QfzAtbv2vrjByhUpiLgAAAGc"]
[Mon Jul 20 06:11:43.442440 2026] [security2:error] [pid 843279:tid 843457] [client 57.141.18.113:23554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QefqvKNcW5yy5T2Cw3gAAtFs"]
[Mon Jul 20 06:11:43.469978 2026] [security2:error] [pid 843279:tid 843470] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyQwAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:43.470123 2026] [security2:error] [pid 843279:tid 843470] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyQwAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:43.831162 2026] [security2:error] [pid 843279:tid 843514] [client 185.132.186.64:20051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/makeasmtp.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyWAAAAOw"]
[Mon Jul 20 06:11:44.024766 2026] [security2:error] [pid 843279:tid 843434] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Qf_qvKNcW5yy5T2CyYQAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:44.322272 2026] [security2:error] [pid 858085:tid 858327] [client 13.201.64.214:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QgDAtbv2vrjByhUpiUwAAAG8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:11:44.464280 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QgPqvKNcW5yy5T2CyggAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:44.683000 2026] [security2:error] [pid 858085:tid 858343] [client 50.116.65.227:44696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QgDAtbv2vrjByhUpiXwAAAH8"]
[Mon Jul 20 06:11:44.693874 2026] [security2:error] [pid 843279:tid 843494] [client 50.116.65.227:44702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QgPqvKNcW5yy5T2CyjAAAANk"]
[Mon Jul 20 06:11:45.319589 2026] [security2:error] [pid 843279:tid 843461] [client 27.96.94.195:38196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QgfqvKNcW5yy5T2CytgAAALg"]
[Mon Jul 20 06:11:45.319934 2026] [security2:error] [pid 843279:tid 843461] [client 27.96.94.195:38196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QgfqvKNcW5yy5T2CytgAAALg"]
[Mon Jul 20 06:11:45.371709 2026] [security2:error] [pid 843279:tid 843477] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QgfqvKNcW5yy5T2CysgAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:45.465469 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:58445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4QgPqvKNcW5yy5T2CyeAAAAIU"], referer: http://getgarrison.com/WORDPRESS
[Mon Jul 20 06:11:45.614936 2026] [security2:error] [pid 843279:tid 843511] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QgfqvKNcW5yy5T2CyxgAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:45.785265 2026] [security2:error] [pid 843279:tid 843447] [client 185.132.186.87:63705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp-sup.php"] [unique_id "al4QgfqvKNcW5yy5T2Cy1AAAAKo"]
[Mon Jul 20 06:11:45.856839 2026] [security2:error] [pid 858085:tid 858342] [client 57.141.18.27:46696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QezAtbv2vrjByhUphewAAfgs"]
[Mon Jul 20 06:11:46.057078 2026] [security2:error] [pid 843279:tid 843319] [remote 88.99.30.91:38436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.30.99.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QgvqvKNcW5yy5T2Cy5wAA-yY"]
[Mon Jul 20 06:11:46.248369 2026] [security2:error] [pid 843279:tid 843313] [remote 88.99.30.91:38436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.30.99.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QgvqvKNcW5yy5T2Cy7wAA1CA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:11:46.306907 2026] [security2:error] [pid 843279:tid 843509] [client 14.225.17.146:54100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4QgPqvKNcW5yy5T2CygwAAAOc"], referer: http://outlookturf.com/WORDPRESS
[Mon Jul 20 06:11:46.360302 2026] [security2:error] [pid 843279:tid 843475] [client 139.28.219.68:39194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "skiboutiques.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4QgvqvKNcW5yy5T2Cy8wAAAMY"]
[Mon Jul 20 06:11:46.402076 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiqQAAAEo"]
[Mon Jul 20 06:11:46.402171 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:47166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiqQAAAEo"]
[Mon Jul 20 06:11:46.557392 2026] [security2:error] [pid 843279:tid 843419] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QgvqvKNcW5yy5T2Cy_QAAAI4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:46.862659 2026] [proxy:error] [pid 858085:tid 858272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:46.862699 2026] [proxy_http:error] [pid 858085:tid 858272] [client 198.235.24.45:64180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:46.863133 2026] [proxy:error] [pid 858085:tid 858272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:11:46.863156 2026] [proxy_http:error] [pid 858085:tid 858272] [client 198.235.24.45:64180] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:11:46.937222 2026] [security2:error] [pid 858085:tid 858226] [client 87.236.176.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4QgjAtbv2vrjByhUpivgAAAAo"]
[Mon Jul 20 06:11:46.953511 2026] [security2:error] [pid 843279:tid 843488] [client 195.96.139.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4QgvqvKNcW5yy5T2CzDwAAANM"]
[Mon Jul 20 06:11:46.961610 2026] [security2:error] [pid 858085:tid 858230] [client 103.141.108.143:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiwwAAAA4"]
[Mon Jul 20 06:11:46.962238 2026] [security2:error] [pid 858085:tid 858230] [client 103.141.108.143:58408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QgjAtbv2vrjByhUpiwwAAAA4"]
[Mon Jul 20 06:11:46.965322 2026] [security2:error] [pid 843279:tid 843434] [client 139.28.219.68:43300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/xmlrpc.php"] [unique_id "al4QgvqvKNcW5yy5T2CzGQAAAJ0"]
[Mon Jul 20 06:11:47.371282 2026] [security2:error] [pid 858085:tid 858159] [remote 192.241.143.148:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QgzAtbv2vrjByhUpi1AAAGkg"]
[Mon Jul 20 06:11:47.371475 2026] [security2:error] [pid 858085:tid 858242] [client 192.241.143.148:40928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QgzAtbv2vrjByhUpi1AAAGkg"]
[Mon Jul 20 06:11:47.426009 2026] [security2:error] [pid 858085:tid 858271] [client 46.110.96.34:41170] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4QgzAtbv2vrjByhUpi1wAAADc"]
[Mon Jul 20 06:11:47.457054 2026] [security2:error] [pid 858085:tid 858225] [client 14.224.227.113:58334] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4QgzAtbv2vrjByhUpi2gAAAAk"]
[Mon Jul 20 06:11:47.598652 2026] [security2:error] [pid 858085:tid 858260] [client 50.116.65.227:55482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QgzAtbv2vrjByhUpi4gAAACw"]
[Mon Jul 20 06:11:47.608023 2026] [security2:error] [pid 843279:tid 843441] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzPwAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:47.609156 2026] [security2:error] [pid 858085:tid 858272] [client 50.116.65.227:44760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4QgzAtbv2vrjByhUpi5AAAADg"]
[Mon Jul 20 06:11:47.728588 2026] [security2:error] [pid 858085:tid 858276] [client 185.132.186.85:57583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wordpress/wp-includes/class-wp-http-ixr-client-view.php"] [unique_id "al4QgzAtbv2vrjByhUpi7QAAADw"]
[Mon Jul 20 06:11:47.851676 2026] [security2:error] [pid 858085:tid 858255] [client 57.141.18.50:23568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QfjAtbv2vrjByhUph-gAAJyA"]
[Mon Jul 20 06:11:47.975138 2026] [security2:error] [pid 843279:tid 843447] [client 41.173.37.102:3009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzUwAAAKo"]
[Mon Jul 20 06:11:47.975303 2026] [security2:error] [pid 843279:tid 843447] [client 41.173.37.102:3009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzUwAAAKo"]
[Mon Jul 20 06:11:48.009510 2026] [security2:error] [pid 858085:tid 858165] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9wAAek4"]
[Mon Jul 20 06:11:48.009678 2026] [security2:error] [pid 858085:tid 858338] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9wAAek4"]
[Mon Jul 20 06:11:48.020651 2026] [security2:error] [pid 858085:tid 858249] [client 150.228.148.150:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9gAAACE"]
[Mon Jul 20 06:11:48.020815 2026] [security2:error] [pid 858085:tid 858249] [client 150.228.148.150:6554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi9gAAACE"]
[Mon Jul 20 06:11:48.072325 2026] [security2:error] [pid 858085:tid 858230] [client 112.213.160.112:30954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi-wAAAA4"]
[Mon Jul 20 06:11:48.072537 2026] [security2:error] [pid 858085:tid 858230] [client 112.213.160.112:30954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi-wAAAA4"]
[Mon Jul 20 06:11:48.107441 2026] [security2:error] [pid 858085:tid 858342] [client 86.98.90.58:20182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_gAAAH4"]
[Mon Jul 20 06:11:48.107635 2026] [security2:error] [pid 858085:tid 858342] [client 86.98.90.58:20182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_gAAAH4"]
[Mon Jul 20 06:11:48.116011 2026] [security2:error] [pid 858085:tid 858269] [client 45.116.69.230:54646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_QAAADU"]
[Mon Jul 20 06:11:48.116193 2026] [security2:error] [pid 858085:tid 858269] [client 45.116.69.230:54646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpi_QAAADU"]
[Mon Jul 20 06:11:48.380977 2026] [security2:error] [pid 843279:tid 843435] [client 74.7.241.147:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4Qg_qvKNcW5yy5T2CzSAAAAJ4"]
[Mon Jul 20 06:11:48.382980 2026] [security2:error] [pid 843279:tid 843450] [client 74.7.241.147:36056] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "overloadcomedy.com"] [uri "/robots.txt"] [unique_id "al4Qg_qvKNcW5yy5T2CzRAAArXM"]
[Mon Jul 20 06:11:48.600341 2026] [security2:error] [pid 858085:tid 858239] [client 74.7.227.179:43060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QhDAtbv2vrjByhUpjEAAAF1Y"], referer: https://tejasenvironmental.com/p=3235839
[Mon Jul 20 06:11:48.839344 2026] [lsapi:warn] [pid 843279:tid 843494] [client 14.225.17.146:50088] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:48.839379 2026] [lsapi:warn] [pid 843279:tid 843494] [client 14.225.17.146:50088] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:48.873645 2026] [security2:error] [pid 858085:tid 858181] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpjKAAAVl4"]
[Mon Jul 20 06:11:48.873867 2026] [security2:error] [pid 858085:tid 858302] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QhDAtbv2vrjByhUpjKAAAVl4"]
[Mon Jul 20 06:11:49.008540 2026] [security2:error] [pid 858085:tid 858328] [client 14.225.17.146:49980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4QgzAtbv2vrjByhUpi0gAAAHA"], referer: http://bnb-engineering.com/WORDPRESS
[Mon Jul 20 06:11:49.020342 2026] [security2:error] [pid 843279:tid 843412] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QhPqvKNcW5yy5T2CzggAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:49.269906 2026] [security2:error] [pid 843279:tid 843434] [client 43.205.139.3:47564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzlAAAAJ0"]
[Mon Jul 20 06:11:49.270112 2026] [security2:error] [pid 843279:tid 843434] [client 43.205.139.3:47564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzlAAAAJ0"]
[Mon Jul 20 06:11:49.271075 2026] [security2:error] [pid 843279:tid 843501] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QhfqvKNcW5yy5T2CzlQAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:49.369762 2026] [lsapi:warn] [pid 858085:tid 858339] [client 50.116.65.227:41438] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:49.369787 2026] [lsapi:warn] [pid 858085:tid 858339] [client 50.116.65.227:41438] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:49.384024 2026] [security2:error] [pid 843279:tid 843494] [client 14.225.17.146:50088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4QhPqvKNcW5yy5T2CzXgAAANk"], referer: http://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:49.512520 2026] [security2:error] [pid 843279:tid 843356] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzpgAAlUs"]
[Mon Jul 20 06:11:49.512739 2026] [security2:error] [pid 843279:tid 843426] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QhfqvKNcW5yy5T2CzpgAAlUs"]
[Mon Jul 20 06:11:49.523127 2026] [security2:error] [pid 858085:tid 858185] [remote 5.161.225.162:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QhTAtbv2vrjByhUpjTgAATWI"]
[Mon Jul 20 06:11:49.692764 2026] [security2:error] [pid 858085:tid 858275] [client 185.132.186.56:63187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/bypass.php"] [unique_id "al4QhTAtbv2vrjByhUpjWQAAADs"]
[Mon Jul 20 06:11:49.759494 2026] [security2:error] [pid 858085:tid 858281] [client 139.28.219.68:43316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/xmlrpc.php"] [unique_id "al4QhTAtbv2vrjByhUpjXgAAAEE"]
[Mon Jul 20 06:11:49.759593 2026] [security2:error] [pid 858085:tid 858281] [client 139.28.219.68:43316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "skiboutiques.com"] [uri "/xmlrpc.php"] [unique_id "al4QhTAtbv2vrjByhUpjXgAAAEE"]
[Mon Jul 20 06:11:50.126477 2026] [security2:error] [pid 858085:tid 858232] [client 164.100.212.184:54561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjawAAABA"]
[Mon Jul 20 06:11:50.126613 2026] [security2:error] [pid 858085:tid 858232] [client 164.100.212.184:54561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjawAAABA"]
[Mon Jul 20 06:11:50.287768 2026] [security2:error] [pid 858085:tid 858295] [client 57.141.18.13:60328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgDAtbv2vrjByhUpiXQAATzM"]
[Mon Jul 20 06:11:50.388701 2026] [lsapi:warn] [pid 843279:tid 843526] [client 14.225.17.146:59362] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:50.388726 2026] [lsapi:warn] [pid 843279:tid 843526] [client 14.225.17.146:59362] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:50.436428 2026] [security2:error] [pid 843279:tid 843526] [client 14.225.17.146:59362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4QhvqvKNcW5yy5T2CzxwAAAPg"], referer: https://oswegooperatheater.com/WORDPRESS
[Mon Jul 20 06:11:50.669201 2026] [security2:error] [pid 843279:tid 843423] [client 142.250.32.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4QhfqvKNcW5yy5T2CzkwAAAJI"]
[Mon Jul 20 06:11:50.699125 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:54049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4QhTAtbv2vrjByhUpjVQAAABM"], referer: http://musichaven.info/WORDPRESS
[Mon Jul 20 06:11:50.747372 2026] [security2:error] [pid 858085:tid 858266] [client 57.141.18.87:42206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgTAtbv2vrjByhUpiawAAMjU"]
[Mon Jul 20 06:11:50.770464 2026] [security2:error] [pid 858085:tid 858192] [remote 5.161.225.162:38630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QhjAtbv2vrjByhUpjggAAZWk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:11:50.841478 2026] [security2:error] [pid 858085:tid 858194] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjhgAAcGs"]
[Mon Jul 20 06:11:50.841667 2026] [security2:error] [pid 858085:tid 858328] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QhjAtbv2vrjByhUpjhgAAcGs"]
[Mon Jul 20 06:11:50.850086 2026] [security2:error] [pid 843279:tid 843420] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QhvqvKNcW5yy5T2Cz3AAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:50.850246 2026] [security2:error] [pid 843279:tid 843420] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QhvqvKNcW5yy5T2Cz3AAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.011655 2026] [security2:error] [pid 843279:tid 843472] [client 57.141.18.10:65132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgfqvKNcW5yy5T2CywQAAw04"]
[Mon Jul 20 06:11:51.133232 2026] [security2:error] [pid 843279:tid 843452] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz5wAAAK8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.352380 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz9wAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.608709 2026] [security2:error] [pid 843279:tid 843441] [client 14.225.17.146:59227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz_gAAAKQ"], referer: https://musichaven.info/WORDPRESS
[Mon Jul 20 06:11:51.629338 2026] [security2:error] [pid 858085:tid 858238] [client 185.132.186.57:31289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-t.api.php"] [unique_id "al4QhzAtbv2vrjByhUpjpQAAABY"]
[Mon Jul 20 06:11:51.644992 2026] [security2:error] [pid 843279:tid 843471] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Qh_qvKNcW5yy5T2Cz_wAAAMI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:51.908717 2026] [security2:error] [pid 843279:tid 843529] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qh_qvKNcW5yy5T2C0DQAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:52.077351 2026] [security2:error] [pid 843279:tid 843488] [client 106.192.104.4:62493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QiPqvKNcW5yy5T2C0FwAAANM"]
[Mon Jul 20 06:11:52.077517 2026] [security2:error] [pid 843279:tid 843488] [client 106.192.104.4:62493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QiPqvKNcW5yy5T2C0FwAAANM"]
[Mon Jul 20 06:11:52.149117 2026] [security2:error] [pid 843279:tid 843493] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QiPqvKNcW5yy5T2C0GAAAANg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:52.166310 2026] [security2:error] [pid 843279:tid 843467] [client 57.141.18.4:40070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QgvqvKNcW5yy5T2CzAgAAvko"]
[Mon Jul 20 06:11:52.441846 2026] [security2:error] [pid 843279:tid 843411] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QiPqvKNcW5yy5T2C0JgAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.155421 2026] [security2:error] [pid 843279:tid 843441] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QifqvKNcW5yy5T2C0SQAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.378200 2026] [security2:error] [pid 843279:tid 843467] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QifqvKNcW5yy5T2C0WQAAAL4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.570107 2026] [security2:error] [pid 858085:tid 858328] [client 185.132.186.55:34705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/edit.php"] [unique_id "al4QiTAtbv2vrjByhUpj8gAAAHA"]
[Mon Jul 20 06:11:53.653301 2026] [security2:error] [pid 843279:tid 843515] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QifqvKNcW5yy5T2C0aAAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.653456 2026] [security2:error] [pid 843279:tid 843515] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QifqvKNcW5yy5T2C0aAAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:53.896283 2026] [security2:error] [pid 843279:tid 843436] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QifqvKNcW5yy5T2C0cwAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:54.007085 2026] [security2:error] [pid 858085:tid 858223] [client 57.141.18.99:56484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhDAtbv2vrjByhUpjIAAAB1o"]
[Mon Jul 20 06:11:54.101483 2026] [security2:error] [pid 843279:tid 843521] [client 103.77.203.233:49973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QivqvKNcW5yy5T2C0fAAAAPM"]
[Mon Jul 20 06:11:54.101616 2026] [security2:error] [pid 843279:tid 843521] [client 103.77.203.233:49973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QivqvKNcW5yy5T2C0fAAAAPM"]
[Mon Jul 20 06:11:54.387967 2026] [security2:error] [pid 858085:tid 858096] [remote 110.249.201.49:43416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2023/01/HDP7_CommissionCompetitivenessMetric.pdf"] [unique_id "al4QijAtbv2vrjByhUpkEwAAXAk"]
[Mon Jul 20 06:11:54.520210 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QivqvKNcW5yy5T2C0mAAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:54.611344 2026] [security2:error] [pid 843279:tid 843472] [client 50.116.65.227:59948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QivqvKNcW5yy5T2C0nQAAAMM"]
[Mon Jul 20 06:11:54.623279 2026] [security2:error] [pid 843279:tid 843449] [client 50.116.65.227:41480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4QivqvKNcW5yy5T2C0nwAAAMA"]
[Mon Jul 20 06:11:54.689285 2026] [security2:error] [pid 843279:tid 843492] [client 57.141.18.60:49692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhfqvKNcW5yy5T2CznAAA1w0"]
[Mon Jul 20 06:11:55.035538 2026] [security2:error] [pid 843279:tid 843422] [client 57.141.18.23:35100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhfqvKNcW5yy5T2CzrwAAkVI"]
[Mon Jul 20 06:11:55.175968 2026] [security2:error] [pid 843279:tid 843459] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0sQAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:55.345464 2026] [security2:error] [pid 843279:tid 843522] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0uwAAAPQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:55.431280 2026] [security2:error] [pid 843279:tid 843431] [client 57.141.18.67:53128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhvqvKNcW5yy5T2CzxAAAmhc"]
[Mon Jul 20 06:11:55.449032 2026] [security2:error] [pid 858085:tid 858275] [client 50.116.65.227:41496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QizAtbv2vrjByhUpkPAAAADs"]
[Mon Jul 20 06:11:55.460719 2026] [security2:error] [pid 858085:tid 858227] [client 50.116.65.227:41502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QizAtbv2vrjByhUpkPQAAAAs"]
[Mon Jul 20 06:11:55.512400 2026] [security2:error] [pid 858085:tid 858302] [client 185.132.186.96:50693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/info.php"] [unique_id "al4QizAtbv2vrjByhUpkQgAAAFY"]
[Mon Jul 20 06:11:55.744577 2026] [security2:error] [pid 858085:tid 858218] [client 14.225.17.146:59124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4QizAtbv2vrjByhUpkRAAAAAI"], referer: http://ccsdifference.com/WORDPRESS
[Mon Jul 20 06:11:55.779154 2026] [security2:error] [pid 843279:tid 843288] [remote 144.79.133.30:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0zwAApAc"]
[Mon Jul 20 06:11:55.779352 2026] [security2:error] [pid 843279:tid 843441] [client 144.79.133.30:53996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4Qi_qvKNcW5yy5T2C0zwAApAc"]
[Mon Jul 20 06:11:55.915245 2026] [security2:error] [pid 843279:tid 843470] [client 57.141.18.116:44520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QhvqvKNcW5yy5T2Cz2wAAwSY"]
[Mon Jul 20 06:11:56.078887 2026] [security2:error] [pid 843279:tid 843481] [client 50.116.65.227:41520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Qi_qvKNcW5yy5T2C02AAAAMw"]
[Mon Jul 20 06:11:56.118346 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:59695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4QijAtbv2vrjByhUpkHwAAAEk"]
[Mon Jul 20 06:11:56.235628 2026] [security2:error] [pid 843279:tid 843477] [client 14.225.17.146:59561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4QjPqvKNcW5yy5T2C04gAAAMg"], referer: http://taskidsvirginia.com/WORDPRESS
[Mon Jul 20 06:11:56.291742 2026] [security2:error] [pid 843279:tid 843456] [client 50.116.65.227:41530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4QjPqvKNcW5yy5T2C05gAAALM"]
[Mon Jul 20 06:11:56.564765 2026] [lsapi:warn] [pid 843279:tid 843534] [client 116.76.196.216:17177] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:56.564785 2026] [lsapi:warn] [pid 843279:tid 843534] [client 116.76.196.216:17177] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:11:56.739568 2026] [security2:error] [pid 843279:tid 843323] [remote 5.161.225.162:34366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QjPqvKNcW5yy5T2C1AAAA9io"]
[Mon Jul 20 06:11:56.791896 2026] [security2:error] [pid 858085:tid 858265] [client 14.225.17.146:52336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4QjDAtbv2vrjByhUpkVwAAADE"], referer: https://ccsdifference.com/WORDPRESS
[Mon Jul 20 06:11:56.977802 2026] [security2:error] [pid 858085:tid 858292] [client 181.224.94.124:47490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QjDAtbv2vrjByhUpkYQAAAEw"]
[Mon Jul 20 06:11:56.977947 2026] [security2:error] [pid 858085:tid 858292] [client 181.224.94.124:47490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QjDAtbv2vrjByhUpkYQAAAEw"]
[Mon Jul 20 06:11:57.065157 2026] [security2:error] [pid 843279:tid 843423] [client 14.225.17.146:53670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4QivqvKNcW5yy5T2C0ngAAAJI"], referer: http://mrbambooplus.com/WORDPRESS
[Mon Jul 20 06:11:57.073824 2026] [security2:error] [pid 843279:tid 843457] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QjPqvKNcW5yy5T2C1CQAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:57.425072 2026] [security2:error] [pid 843279:tid 843469] [client 185.132.186.65:37507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/autoload_classmap.php"] [unique_id "al4QjfqvKNcW5yy5T2C1GQAAAMA"]
[Mon Jul 20 06:11:57.437795 2026] [security2:error] [pid 843279:tid 843483] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QjfqvKNcW5yy5T2C1GgAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:57.592819 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QjfqvKNcW5yy5T2C1HAAAAJQ"]
[Mon Jul 20 06:11:57.649928 2026] [security2:error] [pid 858085:tid 858251] [client 103.141.108.143:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjTAtbv2vrjByhUpkdAAAACM"]
[Mon Jul 20 06:11:57.650071 2026] [security2:error] [pid 858085:tid 858251] [client 103.141.108.143:59079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjTAtbv2vrjByhUpkdAAAACM"]
[Mon Jul 20 06:11:57.815633 2026] [security2:error] [pid 843279:tid 843414] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QjfqvKNcW5yy5T2C1JwAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:57.821173 2026] [security2:error] [pid 858085:tid 858277] [client 14.225.17.146:52163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4QjDAtbv2vrjByhUpkUwAAAD0"], referer: http://whiteoutcb.com/WORDPRESS
[Mon Jul 20 06:11:58.161769 2026] [security2:error] [pid 843279:tid 843531] [client 57.141.18.92:65164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QiPqvKNcW5yy5T2C0OAAA_Ss"]
[Mon Jul 20 06:11:58.180191 2026] [security2:error] [pid 843279:tid 843347] [remote 5.161.225.162:34366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QjvqvKNcW5yy5T2C1PQAAr0I"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:11:58.470854 2026] [security2:error] [pid 858085:tid 858121] [remote 100.42.189.89:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpkigAAQyI"]
[Mon Jul 20 06:11:58.528086 2026] [security2:error] [pid 858085:tid 858303] [client 41.173.37.102:3467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkjQAAAFc"]
[Mon Jul 20 06:11:58.528209 2026] [security2:error] [pid 858085:tid 858303] [client 41.173.37.102:3467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkjQAAAFc"]
[Mon Jul 20 06:11:58.529414 2026] [security2:error] [pid 858085:tid 858122] [remote 192.241.143.148:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpkjwAAVCM"]
[Mon Jul 20 06:11:58.591927 2026] [security2:error] [pid 858085:tid 858124] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkkQAANCU"]
[Mon Jul 20 06:11:58.592130 2026] [security2:error] [pid 858085:tid 858268] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkkQAANCU"]
[Mon Jul 20 06:11:58.657372 2026] [security2:error] [pid 843279:tid 843440] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QjvqvKNcW5yy5T2C1TgAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:58.664367 2026] [security2:error] [pid 858085:tid 858127] [remote 100.42.189.89:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpklwAACyg"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:11:58.717335 2026] [security2:error] [pid 858085:tid 858326] [client 45.116.69.230:55145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkmgAAAG4"]
[Mon Jul 20 06:11:58.717334 2026] [security2:error] [pid 858085:tid 858128] [remote 192.241.143.148:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4QjjAtbv2vrjByhUpkmwAAaCk"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:11:58.717477 2026] [security2:error] [pid 858085:tid 858326] [client 45.116.69.230:55145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkmgAAAG4"]
[Mon Jul 20 06:11:58.753355 2026] [security2:error] [pid 843279:tid 843399] [remote 45.90.123.233:39374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-login.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UQAAn3Y"]
[Mon Jul 20 06:11:58.783082 2026] [security2:error] [pid 843279:tid 843454] [client 86.98.90.58:20891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.90.98.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UgAAALE"]
[Mon Jul 20 06:11:58.783214 2026] [security2:error] [pid 843279:tid 843454] [client 86.98.90.58:20891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UgAAALE"]
[Mon Jul 20 06:11:58.798951 2026] [security2:error] [pid 843279:tid 843475] [client 150.228.148.150:47707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.148.228.150.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UwAAAMY"]
[Mon Jul 20 06:11:58.802179 2026] [security2:error] [pid 843279:tid 843475] [client 150.228.148.150:47707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4QjvqvKNcW5yy5T2C1UwAAAMY"]
[Mon Jul 20 06:11:58.805396 2026] [security2:error] [pid 858085:tid 858130] [remote 20.153.140.50:57412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpknQAAdCs"]
[Mon Jul 20 06:11:58.805674 2026] [security2:error] [pid 858085:tid 858332] [client 20.153.140.50:57412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpknQAAdCs"]
[Mon Jul 20 06:11:58.820191 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkoAAAABE"]
[Mon Jul 20 06:11:58.820354 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QjjAtbv2vrjByhUpkoAAAABE"]
[Mon Jul 20 06:11:58.947626 2026] [security2:error] [pid 858085:tid 858261] [client 57.141.18.0:32582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QiTAtbv2vrjByhUpj_AAALQE"]
[Mon Jul 20 06:11:58.995761 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.52:23978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QiTAtbv2vrjByhUpj_gAAHAM"]
[Mon Jul 20 06:11:59.087421 2026] [security2:error] [pid 843279:tid 843283] [remote 45.90.123.233:39374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-login.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1YAAA2QI"], referer: https://ferrellroofing.com/wp-login.php
[Mon Jul 20 06:11:59.329355 2026] [security2:error] [pid 858085:tid 858291] [client 144.76.19.75:50176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QjzAtbv2vrjByhUpkugAAAEs"]
[Mon Jul 20 06:11:59.379356 2026] [security2:error] [pid 843279:tid 843511] [client 185.132.186.78:26741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/navi.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1ZgAAAOk"]
[Mon Jul 20 06:11:59.459307 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1aQAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:59.465193 2026] [security2:error] [pid 843279:tid 843476] [client 178.152.178.232:37821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1awAAAMc"]
[Mon Jul 20 06:11:59.465287 2026] [security2:error] [pid 843279:tid 843476] [client 178.152.178.232:37821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1awAAAMc"]
[Mon Jul 20 06:11:59.480471 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1aQAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:59.511925 2026] [security2:error] [pid 843279:tid 843346] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1bgABBEE"]
[Mon Jul 20 06:11:59.512154 2026] [security2:error] [pid 843279:tid 843538] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1bgABBEE"]
[Mon Jul 20 06:11:59.747410 2026] [security2:error] [pid 843279:tid 843523] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Qj_qvKNcW5yy5T2C1dgAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:11:59.791482 2026] [security2:error] [pid 858085:tid 858231] [client 57.141.18.73:63860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QijAtbv2vrjByhUpkIAAADwc"]
[Mon Jul 20 06:12:00.064975 2026] [security2:error] [pid 843279:tid 843362] [remote 187.127.191.163:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.191.127.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1fwAA1VE"]
[Mon Jul 20 06:12:00.066315 2026] [security2:error] [pid 858085:tid 858148] [remote 20.153.140.50:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk3gAAaD0"]
[Mon Jul 20 06:12:00.155832 2026] [security2:error] [pid 843279:tid 843531] [client 3.109.4.218:19198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1hwAAAP0"]
[Mon Jul 20 06:12:00.155994 2026] [security2:error] [pid 843279:tid 843531] [client 3.109.4.218:19198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1hwAAAP0"]
[Mon Jul 20 06:12:00.206183 2026] [security2:error] [pid 858085:tid 858147] [remote 109.123.245.117:45202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.245.123.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk4wAAEDw"]
[Mon Jul 20 06:12:00.216659 2026] [security2:error] [pid 843279:tid 843326] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1jAABAS0"]
[Mon Jul 20 06:12:00.216923 2026] [security2:error] [pid 843279:tid 843535] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1jAABAS0"]
[Mon Jul 20 06:12:00.300429 2026] [security2:error] [pid 858085:tid 858272] [client 57.141.18.79:42608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QizAtbv2vrjByhUpkMgAAOBE"]
[Mon Jul 20 06:12:00.384153 2026] [security2:error] [pid 858085:tid 858153] [remote 109.123.245.117:45202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.245.123.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk7QAAT0I"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:12:00.440500 2026] [security2:error] [pid 843279:tid 843516] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1lQAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:00.453221 2026] [security2:error] [pid 843279:tid 843309] [remote 187.127.191.163:44906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.191.127.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1lwAAwBw"], referer: https://maa.hws.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:00.467133 2026] [security2:error] [pid 858085:tid 858155] [remote 20.153.140.50:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk7gAALEQ"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:12:00.719765 2026] [security2:error] [pid 843279:tid 843488] [client 164.100.212.184:64915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1pAAAANM"]
[Mon Jul 20 06:12:00.719918 2026] [security2:error] [pid 843279:tid 843488] [client 164.100.212.184:64915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QkPqvKNcW5yy5T2C1pAAAANM"]
[Mon Jul 20 06:12:00.800042 2026] [security2:error] [pid 858085:tid 858159] [remote 8.217.108.67:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QkDAtbv2vrjByhUpk-gAAaUg"]
[Mon Jul 20 06:12:00.925925 2026] [security2:error] [pid 843279:tid 843509] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QkPqvKNcW5yy5T2C1rQAAAOc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:01.013957 2026] [security2:error] [pid 843279:tid 843298] [remote 47.86.33.52:59520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4QkPqvKNcW5yy5T2C1sgAArxE"]
[Mon Jul 20 06:12:01.053048 2026] [security2:error] [pid 843279:tid 843508] [client 57.141.18.56:24532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjPqvKNcW5yy5T2C06QAA5l8"]
[Mon Jul 20 06:12:01.117593 2026] [security2:error] [pid 858085:tid 858308] [client 114.119.146.230:48409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mollycahill.com"] [uri "/molly-cahill-blog/instagram-mindset"] [unique_id "al4QkTAtbv2vrjByhUplCAAAAFw"], referer: https://www.mollycahill.com/molly-cahill-blog/tag/instagram%2Bcoaching
[Mon Jul 20 06:12:01.325698 2026] [security2:error] [pid 858085:tid 858290] [client 57.141.18.55:20188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjDAtbv2vrjByhUpkUgAAShM"]
[Mon Jul 20 06:12:01.329569 2026] [security2:error] [pid 843279:tid 843493] [client 185.132.186.78:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/require-dynamic-blocks.php"] [unique_id "al4QkfqvKNcW5yy5T2C1uQAAANg"]
[Mon Jul 20 06:12:01.371702 2026] [security2:error] [pid 858085:tid 858164] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QkTAtbv2vrjByhUplIgAAe00"]
[Mon Jul 20 06:12:01.371896 2026] [security2:error] [pid 858085:tid 858339] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QkTAtbv2vrjByhUplIgAAe00"]
[Mon Jul 20 06:12:01.392573 2026] [security2:error] [pid 858085:tid 858154] [remote 5.161.225.162:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QkTAtbv2vrjByhUplIwAAf0M"]
[Mon Jul 20 06:12:01.481686 2026] [security2:error] [pid 858085:tid 858171] [remote 8.217.108.67:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QkTAtbv2vrjByhUplKAAARlQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:01.600883 2026] [security2:error] [pid 843279:tid 843514] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QkfqvKNcW5yy5T2C1vgAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:02.023518 2026] [security2:error] [pid 858085:tid 858229] [client 216.73.216.78:65222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/index.php"] [unique_id "al4QkDAtbv2vrjByhUpk8gAADRQ"]
[Mon Jul 20 06:12:02.384528 2026] [security2:error] [pid 858085:tid 858181] [remote 5.161.225.162:59850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4QkjAtbv2vrjByhUplTAAAEF4"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:12:02.397290 2026] [security2:error] [pid 858085:tid 858238] [client 50.116.65.227:45058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QkjAtbv2vrjByhUplTgAAABY"]
[Mon Jul 20 06:12:02.409272 2026] [security2:error] [pid 843279:tid 843460] [client 50.116.65.227:25210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QkvqvKNcW5yy5T2C16QAAALc"]
[Mon Jul 20 06:12:02.463054 2026] [security2:error] [pid 858085:tid 858218] [client 57.141.18.61:58214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjTAtbv2vrjByhUpkawAAAhc"]
[Mon Jul 20 06:12:02.829169 2026] [security2:error] [pid 843279:tid 843457] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QkvqvKNcW5yy5T2C19gAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:03.202146 2026] [security2:error] [pid 858085:tid 858296] [client 106.192.104.4:63000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QkzAtbv2vrjByhUplgAAAAFA"]
[Mon Jul 20 06:12:03.202270 2026] [security2:error] [pid 858085:tid 858296] [client 106.192.104.4:63000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QkzAtbv2vrjByhUplgAAAAFA"]
[Mon Jul 20 06:12:03.277492 2026] [security2:error] [pid 843279:tid 843449] [client 185.132.186.56:41565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/xp.php%20"] [unique_id "al4Qk_qvKNcW5yy5T2C2AwAAAKw"]
[Mon Jul 20 06:12:03.508397 2026] [security2:error] [pid 858085:tid 858328] [client 103.153.183.69:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../root/.bash_history"] [unique_id "al4QkzAtbv2vrjByhUpliQAAAHA"], referer: https://www.google.com/search?q=m6jj3c
[Mon Jul 20 06:12:03.540677 2026] [security2:error] [pid 843279:tid 843454] [client 14.225.17.146:52063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Qk_qvKNcW5yy5T2C2BQAAALE"], referer: http://lifeisbetterlakeside.com/WORDPRESS
[Mon Jul 20 06:12:03.615209 2026] [security2:error] [pid 858085:tid 858329] [client 18.142.226.106:25930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cryptomeaning.com"] [uri "/ethereum-vs-bitcoin-an-in-depth-comparison-of-two-crypto-giants/"] [unique_id "al4QkzAtbv2vrjByhUplkQAAAHE"], referer: https://cryptomeaning.com/unraveling-the-feline-frenzy-a-deep-dive-into-ethereum-crypto-kitties/
[Mon Jul 20 06:12:03.629071 2026] [security2:error] [pid 858085:tid 858301] [client 57.141.18.122:47774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjjAtbv2vrjByhUpknwAAVSw"]
[Mon Jul 20 06:12:03.833084 2026] [security2:error] [pid 858085:tid 858325] [client 57.141.18.54:29200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjzAtbv2vrjByhUpksgAAbTE"]
[Mon Jul 20 06:12:04.048072 2026] [security2:error] [pid 858085:tid 858298] [client 57.141.18.71:50012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QjzAtbv2vrjByhUpkwgAAUjY"]
[Mon Jul 20 06:12:04.147453 2026] [security2:error] [pid 858085:tid 858192] [remote 95.217.78.234:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplsQAAd2k"]
[Mon Jul 20 06:12:04.147628 2026] [security2:error] [pid 858085:tid 858335] [client 95.217.78.234:46296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplsQAAd2k"]
[Mon Jul 20 06:12:04.376144 2026] [security2:error] [pid 858085:tid 858200] [remote 20.153.140.50:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QlDAtbv2vrjByhUplwQAAfHE"]
[Mon Jul 20 06:12:04.441010 2026] [autoindex:error] [pid 858085:tid 858341] [client 205.210.31.46:60970] AH01276: Cannot serve directory /home2/yapvjbmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.yap.vjb.mybluehost.me/
[Mon Jul 20 06:12:04.456505 2026] [security2:error] [pid 843279:tid 843508] [client 50.116.65.227:25248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QlPqvKNcW5yy5T2C2KAAAAOY"]
[Mon Jul 20 06:12:04.466354 2026] [security2:error] [pid 843279:tid 843431] [client 50.116.65.227:25250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QlPqvKNcW5yy5T2C2KQAAAJo"]
[Mon Jul 20 06:12:04.590956 2026] [security2:error] [pid 858085:tid 858277] [client 103.77.203.233:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplzAAAAD0"]
[Mon Jul 20 06:12:04.591140 2026] [security2:error] [pid 858085:tid 858277] [client 103.77.203.233:50508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QlDAtbv2vrjByhUplzAAAAD0"]
[Mon Jul 20 06:12:04.614273 2026] [security2:error] [pid 858085:tid 858203] [remote 216.73.217.138:19219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4QlDAtbv2vrjByhUplzQAAbXQ"]
[Mon Jul 20 06:12:04.849211 2026] [autoindex:error] [pid 858085:tid 858331] [client 43.164.190.124:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:12:04.995334 2026] [security2:error] [pid 858085:tid 858166] [remote 20.153.140.50:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QlDAtbv2vrjByhUpl6AAADk8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:05.152794 2026] [security2:error] [pid 858085:tid 858309] [client 57.141.18.98:39246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QkDAtbv2vrjByhUpk9QAAXUU"]
[Mon Jul 20 06:12:05.237140 2026] [security2:error] [pid 858085:tid 858233] [client 185.132.186.61:20713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/bypass.php"] [unique_id "al4QlTAtbv2vrjByhUpl8QAAABE"]
[Mon Jul 20 06:12:05.455131 2026] [security2:error] [pid 858085:tid 858292] [client 14.225.17.146:61226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4QlTAtbv2vrjByhUpl9AAAAEw"], referer: http://xp-design.co/WORDPRESS
[Mon Jul 20 06:12:05.631704 2026] [security2:error] [pid 858085:tid 858258] [client 57.141.18.96:21170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QkTAtbv2vrjByhUplFAAAKk4"]
[Mon Jul 20 06:12:06.202993 2026] [security2:error] [pid 858085:tid 858252] [client 14.225.17.146:61317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4QlDAtbv2vrjByhUplwwAAACQ"], referer: http://grecruit.online/WORDPRESS
[Mon Jul 20 06:12:06.243739 2026] [security2:error] [pid 843279:tid 843317] [remote 5.161.225.162:34350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2agAAhSQ"]
[Mon Jul 20 06:12:06.243954 2026] [security2:error] [pid 843279:tid 843410] [client 5.161.225.162:34350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2agAAhSQ"]
[Mon Jul 20 06:12:06.275660 2026] [security2:error] [pid 843279:tid 843415] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QlvqvKNcW5yy5T2C2bAAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:06.464838 2026] [security2:error] [pid 843279:tid 843389] [remote 47.86.33.52:6186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2dQAAzmw"]
[Mon Jul 20 06:12:06.465043 2026] [security2:error] [pid 843279:tid 843483] [client 47.86.33.52:6186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4QlvqvKNcW5yy5T2C2dQAAzmw"]
[Mon Jul 20 06:12:06.499875 2026] [security2:error] [pid 843279:tid 843534] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QlvqvKNcW5yy5T2C2cwAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:06.543053 2026] [core:error] [pid 858085:tid 858305] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:06.543081 2026] [core:error] [pid 858085:tid 858305] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:06.682955 2026] [security2:error] [pid 858085:tid 858271] [client 57.141.18.94:52884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QkjAtbv2vrjByhUplOwAAN1A"]
[Mon Jul 20 06:12:06.715049 2026] [security2:error] [pid 843279:tid 843455] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QlvqvKNcW5yy5T2C2fAAAALI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:06.755285 2026] [security2:error] [pid 858085:tid 858201] [remote 130.51.180.8:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4QljAtbv2vrjByhUpmJQAALnI"]
[Mon Jul 20 06:12:07.043417 2026] [security2:error] [pid 843279:tid 843425] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2iwAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:07.142213 2026] [security2:error] [pid 843279:tid 843425] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2iwAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:07.150739 2026] [security2:error] [pid 843279:tid 843454] [client 185.132.186.81:55573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/bypass_1.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2jgAAALE"]
[Mon Jul 20 06:12:07.309623 2026] [security2:error] [pid 858085:tid 858240] [client 14.225.17.146:58093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4QljAtbv2vrjByhUpmFAAAABg"], referer: http://dnsplumbing.com/WORDPRESS
[Mon Jul 20 06:12:07.467838 2026] [security2:error] [pid 858085:tid 858116] [remote 130.51.180.8:41890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4QlzAtbv2vrjByhUpmQgAAPR0"], referer: https://adultdaycarereno.com/wp-login.php
[Mon Jul 20 06:12:07.525211 2026] [security2:error] [pid 843279:tid 843524] [client 181.224.94.124:24483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2nAAAAPY"]
[Mon Jul 20 06:12:07.525356 2026] [security2:error] [pid 843279:tid 843524] [client 181.224.94.124:24483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2nAAAAPY"]
[Mon Jul 20 06:12:07.712976 2026] [security2:error] [pid 843279:tid 843477] [client 103.153.183.69:13644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8fhome/admin/.ssh/id_rsa"] [unique_id "al4Ql_qvKNcW5yy5T2C2ogAAAMg"], referer: https://t.co/y0btos585h
[Mon Jul 20 06:12:07.924055 2026] [security2:error] [pid 858085:tid 858122] [remote 160.187.68.132:35862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QlzAtbv2vrjByhUpmUAAARiM"]
[Mon Jul 20 06:12:08.411959 2026] [security2:error] [pid 858085:tid 858295] [client 52.59.238.198:15912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmXwAAAE8"]
[Mon Jul 20 06:12:08.412060 2026] [security2:error] [pid 858085:tid 858295] [client 52.59.238.198:15912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmXwAAAE8"]
[Mon Jul 20 06:12:08.434410 2026] [security2:error] [pid 858085:tid 858120] [remote 160.187.68.132:35862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4QmDAtbv2vrjByhUpmYAAAIiE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:12:08.461656 2026] [security2:error] [pid 858085:tid 858293] [client 103.141.108.143:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmZQAAAE0"]
[Mon Jul 20 06:12:08.462086 2026] [security2:error] [pid 858085:tid 858293] [client 103.141.108.143:59562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QmDAtbv2vrjByhUpmZQAAAE0"]
[Mon Jul 20 06:12:08.520619 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.50:41004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QlDAtbv2vrjByhUplqwAADTg"]
[Mon Jul 20 06:12:08.802608 2026] [security2:error] [pid 843279:tid 843502] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QmPqvKNcW5yy5T2C2xQAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:08.898436 2026] [security2:error] [pid 858085:tid 858253] [client 45.157.112.60:59055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QmDAtbv2vrjByhUpmewAAACU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:09.017964 2026] [security2:error] [pid 843279:tid 843530] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QmfqvKNcW5yy5T2C2zgAAAPw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:09.158927 2026] [security2:error] [pid 843279:tid 843497] [client 41.173.37.102:3930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QmfqvKNcW5yy5T2C20wAAANw"]
[Mon Jul 20 06:12:09.159025 2026] [security2:error] [pid 843279:tid 843497] [client 41.173.37.102:3930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QmfqvKNcW5yy5T2C20wAAANw"]
[Mon Jul 20 06:12:09.270250 2026] [security2:error] [pid 858085:tid 858135] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmkAAABDA"]
[Mon Jul 20 06:12:09.270380 2026] [security2:error] [pid 858085:tid 858220] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmkAAABDA"]
[Mon Jul 20 06:12:09.344270 2026] [security2:error] [pid 843279:tid 843503] [client 57.141.18.2:42668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QlPqvKNcW5yy5T2C2PAAA4m0"]
[Mon Jul 20 06:12:09.530150 2026] [security2:error] [pid 858085:tid 858294] [client 112.213.160.112:30966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmoQAAAE4"]
[Mon Jul 20 06:12:09.530283 2026] [security2:error] [pid 858085:tid 858294] [client 112.213.160.112:30966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QmTAtbv2vrjByhUpmoQAAAE4"]
[Mon Jul 20 06:12:09.548496 2026] [core:error] [pid 858085:tid 858230] [client 87.236.176.216:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:09.548524 2026] [core:error] [pid 858085:tid 858230] [client 87.236.176.216:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:09.581766 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:62651] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WORDPRESS
[Mon Jul 20 06:12:09.581801 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:62651] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WORDPRESS
[Mon Jul 20 06:12:09.592907 2026] [security2:error] [pid 858085:tid 858255] [client 50.116.65.227:38626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QmTAtbv2vrjByhUpmqAAAACc"]
[Mon Jul 20 06:12:09.608461 2026] [security2:error] [pid 858085:tid 858257] [client 50.116.65.227:19092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4QmTAtbv2vrjByhUpmrgAAADU"]
[Mon Jul 20 06:12:09.808111 2026] [security2:error] [pid 858085:tid 858271] [client 103.153.183.69:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4QmTAtbv2vrjByhUpmsgAAADc"], referer: https://www.google.com/search?q=hrt92o
[Mon Jul 20 06:12:09.834710 2026] [security2:error] [pid 843279:tid 843521] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QmfqvKNcW5yy5T2C26gAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:10.093839 2026] [security2:error] [pid 858085:tid 858261] [client 185.132.186.69:41777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/elementskit.php"] [unique_id "al4QmjAtbv2vrjByhUpmtwAAAC0"]
[Mon Jul 20 06:12:10.121989 2026] [security2:error] [pid 858085:tid 858098] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmuAAAUAs"]
[Mon Jul 20 06:12:10.122181 2026] [security2:error] [pid 858085:tid 858296] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmuAAAUAs"]
[Mon Jul 20 06:12:10.323288 2026] [security2:error] [pid 858085:tid 858248] [client 14.225.17.146:61322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4QmDAtbv2vrjByhUpmdAAAACA"], referer: http://eduardsales.com/WORDPRESS
[Mon Jul 20 06:12:10.491987 2026] [security2:error] [pid 858085:tid 858222] [client 45.116.69.230:55658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmzQAAAAY"]
[Mon Jul 20 06:12:10.492098 2026] [security2:error] [pid 858085:tid 858222] [client 45.116.69.230:55658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QmjAtbv2vrjByhUpmzQAAAAY"]
[Mon Jul 20 06:12:10.606289 2026] [security2:error] [pid 843279:tid 843437] [client 57.141.18.94:52900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QlvqvKNcW5yy5T2C2ZAAAoC8"]
[Mon Jul 20 06:12:10.745812 2026] [security2:error] [pid 843279:tid 843532] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QmvqvKNcW5yy5T2C3IQAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:10.861017 2026] [security2:error] [pid 843279:tid 843446] [client 192.161.164.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2rgAAqVQ"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91-the-summer-plans-studio-escala-1-6-ayanami-rei/
[Mon Jul 20 06:12:10.988374 2026] [security2:error] [pid 843279:tid 843450] [client 104.234.53.71:23529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QmvqvKNcW5yy5T2C3JQAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:11.007279 2026] [security2:error] [pid 858085:tid 858110] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm9wAARRc"]
[Mon Jul 20 06:12:11.007447 2026] [security2:error] [pid 858085:tid 858285] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm9wAARRc"]
[Mon Jul 20 06:12:11.042146 2026] [security2:error] [pid 858085:tid 858332] [client 65.1.132.125:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm-QAAAHQ"]
[Mon Jul 20 06:12:11.042261 2026] [security2:error] [pid 858085:tid 858332] [client 65.1.132.125:26570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpm-QAAAHQ"]
[Mon Jul 20 06:12:11.056395 2026] [security2:error] [pid 858085:tid 858315] [client 57.141.18.43:20504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QljAtbv2vrjByhUpmHwAAYw4"]
[Mon Jul 20 06:12:11.059319 2026] [security2:error] [pid 858085:tid 858179] [remote 72.167.132.114:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpm-wAAPVw"]
[Mon Jul 20 06:12:11.156930 2026] [fcgid:warn] [pid 858085:tid 858264] (70014)End of file found: [client 66.132.172.219:18734] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:11.259189 2026] [security2:error] [pid 858085:tid 858219] [client 164.100.212.184:52512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.212.100.164.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnDAAAAAM"]
[Mon Jul 20 06:12:11.259301 2026] [security2:error] [pid 858085:tid 858219] [client 164.100.212.184:52512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnDAAAAAM"]
[Mon Jul 20 06:12:11.398886 2026] [security2:error] [pid 858085:tid 858185] [remote 72.167.132.114:43306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpnEQAAFGI"], referer: https://alaraycreative.com/wp-login.php
[Mon Jul 20 06:12:11.540262 2026] [security2:error] [pid 843279:tid 843401] [remote 47.86.33.52:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3PAAAong"]
[Mon Jul 20 06:12:11.540501 2026] [security2:error] [pid 843279:tid 843439] [client 47.86.33.52:59506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3PAAAong"]
[Mon Jul 20 06:12:11.676312 2026] [security2:error] [pid 858085:tid 858134] [remote 57.141.18.88:33968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2896560"] [unique_id "al4QmzAtbv2vrjByhUpnIQAAGS8"]
[Mon Jul 20 06:12:11.720421 2026] [security2:error] [pid 858085:tid 858189] [remote 173.212.252.15:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpnIgAAV2Y"]
[Mon Jul 20 06:12:11.756714 2026] [security2:error] [pid 843279:tid 843485] [client 57.141.18.25:52330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2jQAA0E8"]
[Mon Jul 20 06:12:11.860791 2026] [security2:error] [pid 858085:tid 858145] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnJwAAEjo"]
[Mon Jul 20 06:12:11.861034 2026] [security2:error] [pid 858085:tid 858234] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QmzAtbv2vrjByhUpnJwAAEjo"]
[Mon Jul 20 06:12:11.902649 2026] [security2:error] [pid 858085:tid 858138] [remote 173.212.252.15:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QmzAtbv2vrjByhUpnKwAAADM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:12:12.002461 2026] [security2:error] [pid 843279:tid 843430] [client 104.234.53.71:23529] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3SgAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:12.050128 2026] [security2:error] [pid 858085:tid 858258] [client 185.132.186.94:59337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-rss-database.php"] [unique_id "al4QnDAtbv2vrjByhUpnMAAAACo"]
[Mon Jul 20 06:12:12.125207 2026] [security2:error] [pid 858085:tid 858320] [client 103.153.183.69:12248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4QnDAtbv2vrjByhUpnMQAAAGg"], referer: https://t.co/9g09peono2
[Mon Jul 20 06:12:12.601620 2026] [security2:error] [pid 843279:tid 843471] [client 57.141.18.13:44296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ql_qvKNcW5yy5T2C2rAAAwno"]
[Mon Jul 20 06:12:12.718083 2026] [security2:error] [pid 858085:tid 858200] [remote 160.187.68.132:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4QnDAtbv2vrjByhUpnTwAAa3E"]
[Mon Jul 20 06:12:13.460180 2026] [security2:error] [pid 858085:tid 858284] [client 57.141.18.61:63198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QmDAtbv2vrjByhUpmbwAARCc"]
[Mon Jul 20 06:12:13.787105 2026] [security2:error] [pid 843279:tid 843473] [client 106.192.104.4:63487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QnfqvKNcW5yy5T2C3ggAAAMQ"]
[Mon Jul 20 06:12:13.787213 2026] [security2:error] [pid 843279:tid 843473] [client 106.192.104.4:63487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QnfqvKNcW5yy5T2C3ggAAAMQ"]
[Mon Jul 20 06:12:13.803645 2026] [security2:error] [pid 858085:tid 858214] [remote 160.187.68.132:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4QnTAtbv2vrjByhUpnhQAANn8"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:12:13.999327 2026] [security2:error] [pid 858085:tid 858265] [client 185.132.186.69:28599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/kur.php"] [unique_id "al4QnTAtbv2vrjByhUpnjQAAADE"]
[Mon Jul 20 06:12:14.142225 2026] [security2:error] [pid 858085:tid 858287] [client 57.141.18.42:32106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QmTAtbv2vrjByhUpmkgAARwQ"]
[Mon Jul 20 06:12:14.222954 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:52094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4QnvqvKNcW5yy5T2C3jAAAANs"], referer: http://jvcmotorsports.com/WORDPRESS
[Mon Jul 20 06:12:14.241377 2026] [security2:error] [pid 843279:tid 843536] [client 57.141.18.114:27868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QmfqvKNcW5yy5T2C22AABAko"]
[Mon Jul 20 06:12:14.342329 2026] [security2:error] [pid 843279:tid 843414] [client 82.102.18.116:57524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QnvqvKNcW5yy5T2C3kwAAAIk"]
[Mon Jul 20 06:12:14.988324 2026] [security2:error] [pid 858085:tid 858254] [client 82.102.18.116:57534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QnjAtbv2vrjByhUpnzQAAACY"]
[Mon Jul 20 06:12:15.051697 2026] [security2:error] [pid 858085:tid 858229] [client 65.1.132.125:26574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QnzAtbv2vrjByhUpn0AAAAA0"]
[Mon Jul 20 06:12:15.254959 2026] [security2:error] [pid 858085:tid 858307] [client 103.77.203.233:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QnzAtbv2vrjByhUpn2QAAAFs"]
[Mon Jul 20 06:12:15.255245 2026] [security2:error] [pid 858085:tid 858307] [client 103.77.203.233:51049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QnzAtbv2vrjByhUpn2QAAAFs"]
[Mon Jul 20 06:12:15.563411 2026] [security2:error] [pid 858085:tid 858234] [client 74.125.213.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnmAAAABI"]
[Mon Jul 20 06:12:15.875053 2026] [security2:error] [pid 858085:tid 858137] [remote 217.61.143.92:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4QnzAtbv2vrjByhUpoBwAAcDI"]
[Mon Jul 20 06:12:15.938221 2026] [security2:error] [pid 843279:tid 843535] [client 185.132.186.82:58779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/click.php"] [unique_id "al4Qn_qvKNcW5yy5T2C3wAAAAQE"]
[Mon Jul 20 06:12:15.946702 2026] [security2:error] [pid 858085:tid 858332] [client 14.225.17.146:62686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnywAAAHQ"], referer: http://ancestralidadytrance.space/WORDPRESS
[Mon Jul 20 06:12:16.146995 2026] [security2:error] [pid 858085:tid 858094] [remote 217.61.143.92:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4QoDAtbv2vrjByhUpoEgAAIQc"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 06:12:16.361173 2026] [security2:error] [pid 858085:tid 858232] [client 13.229.223.11:40452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QoDAtbv2vrjByhUpoHwAAABA"]
[Mon Jul 20 06:12:16.361297 2026] [security2:error] [pid 858085:tid 858232] [client 13.229.223.11:40452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QoDAtbv2vrjByhUpoHwAAABA"]
[Mon Jul 20 06:12:16.468554 2026] [security2:error] [pid 858085:tid 858304] [client 65.1.132.125:26584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QoDAtbv2vrjByhUpoKwAAAFg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:12:16.728955 2026] [security2:error] [pid 843279:tid 843436] [client 57.141.18.22:58300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qm_qvKNcW5yy5T2C3QgAAn0c"]
[Mon Jul 20 06:12:17.264426 2026] [security2:error] [pid 858085:tid 858257] [client 104.234.53.56:35109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QoTAtbv2vrjByhUpoWwAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:17.746987 2026] [security2:error] [pid 858085:tid 858325] [client 50.116.65.227:38664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QoTAtbv2vrjByhUpohAAAAG0"]
[Mon Jul 20 06:12:17.760847 2026] [security2:error] [pid 858085:tid 858271] [client 50.116.65.227:19156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QoTAtbv2vrjByhUpohQAAADc"]
[Mon Jul 20 06:12:17.859576 2026] [security2:error] [pid 858085:tid 858314] [client 82.102.18.116:57536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QoTAtbv2vrjByhUpoiQAAAGI"]
[Mon Jul 20 06:12:17.859718 2026] [security2:error] [pid 858085:tid 858314] [client 82.102.18.116:57536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4QoTAtbv2vrjByhUpoiQAAAGI"]
[Mon Jul 20 06:12:17.863418 2026] [security2:error] [pid 858085:tid 858319] [client 185.132.186.64:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-customize-manager-client.php"] [unique_id "al4QoTAtbv2vrjByhUpoigAAAGc"]
[Mon Jul 20 06:12:18.097975 2026] [security2:error] [pid 858085:tid 858251] [client 181.224.94.124:2180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpolQAAACM"]
[Mon Jul 20 06:12:18.098119 2026] [security2:error] [pid 858085:tid 858251] [client 181.224.94.124:2180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpolQAAACM"]
[Mon Jul 20 06:12:18.134403 2026] [security2:error] [pid 858085:tid 858304] [client 104.234.53.56:35109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QojAtbv2vrjByhUpolgAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:18.378775 2026] [security2:error] [pid 843279:tid 843511] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ferrellroofing.com"] [uri "/index.php"] [unique_id "al4QofqvKNcW5yy5T2C33AAAAOk"]
[Mon Jul 20 06:12:18.445836 2026] [security2:error] [pid 858085:tid 858331] [client 57.141.18.35:29604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QnTAtbv2vrjByhUpnegAAc0U"]
[Mon Jul 20 06:12:18.566592 2026] [security2:error] [pid 858085:tid 858279] [client 158.173.89.95:40017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QojAtbv2vrjByhUposwAAAD8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:18.850183 2026] [security2:error] [pid 858085:tid 858237] [client 27.96.94.195:37556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpowAAAABU"]
[Mon Jul 20 06:12:18.873247 2026] [security2:error] [pid 858085:tid 858237] [client 27.96.94.195:37556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QojAtbv2vrjByhUpowAAAABU"]
[Mon Jul 20 06:12:18.880212 2026] [security2:error] [pid 858085:tid 858305] [client 57.141.18.7:59042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnjgAAWQU"]
[Mon Jul 20 06:12:18.882271 2026] [security2:error] [pid 843279:tid 843451] [client 14.225.17.146:54207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4QoPqvKNcW5yy5T2C3ygAAAK4"], referer: http://drewsasburyparkbeachhouse.com/WORDPRESS
[Mon Jul 20 06:12:19.163799 2026] [security2:error] [pid 858085:tid 858270] [client 103.141.108.143:60023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo0AAAADY"]
[Mon Jul 20 06:12:19.163909 2026] [security2:error] [pid 858085:tid 858270] [client 103.141.108.143:60023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo0AAAADY"]
[Mon Jul 20 06:12:19.181866 2026] [security2:error] [pid 843279:tid 843450] [client 216.244.66.243:55096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4Qo_qvKNcW5yy5T2C4EAAAAK0"]
[Mon Jul 20 06:12:19.181981 2026] [security2:error] [pid 843279:tid 843450] [client 216.244.66.243:55096] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4Qo_qvKNcW5yy5T2C4EAAAAK0"]
[Mon Jul 20 06:12:19.298206 2026] [security2:error] [pid 858085:tid 858211] [remote 110.249.201.94:19254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2010-commission/"] [unique_id "al4QozAtbv2vrjByhUpo2QAAYHw"]
[Mon Jul 20 06:12:19.530829 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.116:37802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QnjAtbv2vrjByhUpnuAAAFBU"]
[Mon Jul 20 06:12:19.808193 2026] [security2:error] [pid 858085:tid 858266] [client 41.173.37.102:4380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo9AAAADI"]
[Mon Jul 20 06:12:19.808315 2026] [security2:error] [pid 858085:tid 858266] [client 41.173.37.102:4380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QozAtbv2vrjByhUpo9AAAADI"]
[Mon Jul 20 06:12:19.820244 2026] [security2:error] [pid 858085:tid 858253] [client 185.132.186.70:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-modules-packages.min-boolean.php"] [unique_id "al4QozAtbv2vrjByhUpo9wAAACU"]
[Mon Jul 20 06:12:19.834072 2026] [security2:error] [pid 843279:tid 843289] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qo_qvKNcW5yy5T2C4IwAA3gg"]
[Mon Jul 20 06:12:19.834219 2026] [security2:error] [pid 843279:tid 843499] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Qo_qvKNcW5yy5T2C4IwAA3gg"]
[Mon Jul 20 06:12:20.016848 2026] [security2:error] [pid 858085:tid 858315] [client 14.225.17.146:51991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4QozAtbv2vrjByhUpo8AAAAGM"], referer: http://floorsourcestock.com/WORDPRESS
[Mon Jul 20 06:12:20.138623 2026] [security2:error] [pid 858085:tid 858221] [client 45.116.69.230:56167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppBgAAAAU"]
[Mon Jul 20 06:12:20.138761 2026] [security2:error] [pid 858085:tid 858221] [client 45.116.69.230:56167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppBgAAAAU"]
[Mon Jul 20 06:12:20.248686 2026] [security2:error] [pid 858085:tid 858303] [client 112.213.160.112:31231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppEAAAAFc"]
[Mon Jul 20 06:12:20.248832 2026] [security2:error] [pid 858085:tid 858303] [client 112.213.160.112:31231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QpDAtbv2vrjByhUppEAAAAFc"]
[Mon Jul 20 06:12:20.618237 2026] [security2:error] [pid 858085:tid 858111] [remote 47.86.33.52:15538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4QpDAtbv2vrjByhUppJAAAARg"], referer: https://mail.indiraskitchenllc.com/wp-login.php
[Mon Jul 20 06:12:20.788301 2026] [security2:error] [pid 843279:tid 843282] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QpPqvKNcW5yy5T2C4QAAA-gE"]
[Mon Jul 20 06:12:20.788614 2026] [security2:error] [pid 843279:tid 843528] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QpPqvKNcW5yy5T2C4QAAA-gE"]
[Mon Jul 20 06:12:20.858758 2026] [fcgid:warn] [pid 843279:tid 843493] (70014)End of file found: [client 93.174.93.12:60000] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:21.035289 2026] [security2:error] [pid 858085:tid 858125] [remote 81.173.115.7:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppNwAAMSY"]
[Mon Jul 20 06:12:21.136505 2026] [security2:error] [pid 858085:tid 858238] [client 57.141.18.123:32312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QoDAtbv2vrjByhUpoMAAAFko"]
[Mon Jul 20 06:12:21.214477 2026] [security2:error] [pid 858085:tid 858128] [remote 103.255.134.61:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "test.koaconsultants.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppRQAAWyk"]
[Mon Jul 20 06:12:21.227963 2026] [security2:error] [pid 858085:tid 858135] [remote 81.173.115.7:33816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppSQAARjA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:12:21.272499 2026] [autoindex:error] [pid 843279:tid 843510] [client 43.153.48.240:0] AH01276: Cannot serve directory /home1/itdynami/public_html/misralrakamia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:12:21.342859 2026] [security2:error] [pid 858085:tid 858315] [client 178.152.178.232:36663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppUAAAAGM"]
[Mon Jul 20 06:12:21.349289 2026] [security2:error] [pid 858085:tid 858315] [client 178.152.178.232:36663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppUAAAAGM"]
[Mon Jul 20 06:12:21.764772 2026] [security2:error] [pid 858085:tid 858094] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppZwAAfAc"]
[Mon Jul 20 06:12:21.764975 2026] [security2:error] [pid 858085:tid 858340] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QpTAtbv2vrjByhUppZwAAfAc"]
[Mon Jul 20 06:12:21.765945 2026] [security2:error] [pid 858085:tid 858318] [client 185.132.186.102:26099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/error.php"] [unique_id "al4QpTAtbv2vrjByhUppaAAAAGY"]
[Mon Jul 20 06:12:21.799580 2026] [security2:error] [pid 858085:tid 858342] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QpTAtbv2vrjByhUppPwAAAH4"]
[Mon Jul 20 06:12:21.814998 2026] [security2:error] [pid 858085:tid 858103] [remote 103.255.134.61:34398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "test.koaconsultants.com"] [uri "/wp-login.php"] [unique_id "al4QpTAtbv2vrjByhUppawAAERA"], referer: https://test.koaconsultants.com/wp-login.php
[Mon Jul 20 06:12:21.816906 2026] [security2:error] [pid 843279:tid 843462] [client 3.85.28.216:63106] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/avocado-crema-crema-de-aguacate"] [unique_id "al4QpfqvKNcW5yy5T2C4TAAAALk"]
[Mon Jul 20 06:12:21.846475 2026] [security2:error] [pid 843279:tid 843485] [client 3.109.4.218:52670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QpfqvKNcW5yy5T2C4XwAAANA"]
[Mon Jul 20 06:12:21.846706 2026] [security2:error] [pid 843279:tid 843485] [client 3.109.4.218:52670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QpfqvKNcW5yy5T2C4XwAAANA"]
[Mon Jul 20 06:12:21.911586 2026] [security2:error] [pid 858085:tid 858239] [client 192.149.70.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4QpDAtbv2vrjByhUppCwAAABc"]
[Mon Jul 20 06:12:21.932100 2026] [security2:error] [pid 858085:tid 858323] [client 57.141.18.6:27758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QoTAtbv2vrjByhUpoXgAAaxQ"]
[Mon Jul 20 06:12:22.116117 2026] [security2:error] [pid 843279:tid 843425] [client 46.110.96.34:55004] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4QpvqvKNcW5yy5T2C4awAAAJQ"]
[Mon Jul 20 06:12:22.116202 2026] [security2:error] [pid 843279:tid 843425] [client 46.110.96.34:55004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "50.116.64.34"] [uri "/wpad.dat"] [unique_id "al4QpvqvKNcW5yy5T2C4awAAAJQ"]
[Mon Jul 20 06:12:22.377351 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.51:57150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QoTAtbv2vrjByhUpogAAAd2I"]
[Mon Jul 20 06:12:22.409929 2026] [security2:error] [pid 843279:tid 843463] [client 45.61.188.240:63716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mcg.homes"] [uri "/"] [unique_id "al4QpvqvKNcW5yy5T2C4bwAAALo"]
[Mon Jul 20 06:12:22.419126 2026] [security2:error] [pid 858085:tid 858303] [client 14.225.17.146:61766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUppfwAAAFc"], referer: http://omenana.com/WORDPRESS
[Mon Jul 20 06:12:22.421842 2026] [security2:error] [pid 858085:tid 858149] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QpjAtbv2vrjByhUppigAAbT4"]
[Mon Jul 20 06:12:22.422030 2026] [security2:error] [pid 858085:tid 858325] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QpjAtbv2vrjByhUppigAAbT4"]
[Mon Jul 20 06:12:22.470077 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4QpDAtbv2vrjByhUppMAAAABk"], referer: http://bbwipartnerconference.com/WORDPRESS
[Mon Jul 20 06:12:22.543934 2026] [security2:error] [pid 858085:tid 858292] [client 14.225.17.146:63470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4QpDAtbv2vrjByhUppHgAAAEw"], referer: http://areitoproducciones.com/WORDPRESS
[Mon Jul 20 06:12:22.708104 2026] [security2:error] [pid 843279:tid 843521] [client 45.61.188.240:63774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mcg.homes"] [uri "/"] [unique_id "al4QpvqvKNcW5yy5T2C4dwAAAPM"]
[Mon Jul 20 06:12:22.735189 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.32:53448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QojAtbv2vrjByhUpokQAAKWY"]
[Mon Jul 20 06:12:23.019907 2026] [security2:error] [pid 843279:tid 843424] [client 57.141.18.0:24146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QovqvKNcW5yy5T2C38QAAkyg"]
[Mon Jul 20 06:12:23.240516 2026] [core:error] [pid 858085:tid 858292] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:23.240538 2026] [core:error] [pid 858085:tid 858292] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:23.455441 2026] [security2:error] [pid 858085:tid 858332] [client 104.234.53.78:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4QpzAtbv2vrjByhUpp1wAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:23.582680 2026] [security2:error] [pid 843279:tid 843448] [client 14.225.17.146:51216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4QpvqvKNcW5yy5T2C4aAAAAKs"], referer: http://detroitcsc.com/WORDPRESS
[Mon Jul 20 06:12:23.612702 2026] [security2:error] [pid 858085:tid 858290] [client 54.198.0.135:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUpppAAAAEo"]
[Mon Jul 20 06:12:23.617508 2026] [security2:error] [pid 858085:tid 858229] [client 54.198.0.135:28172] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/avocado-crema-crema-de-aguacate/"] [unique_id "al4QpjAtbv2vrjByhUppoAAAAA0"]
[Mon Jul 20 06:12:23.729842 2026] [security2:error] [pid 858085:tid 858296] [client 185.132.186.90:36077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ALFA_DATA/alfacgiapi/all.php"] [unique_id "al4QpzAtbv2vrjByhUpp5wAAAFA"]
[Mon Jul 20 06:12:24.310994 2026] [security2:error] [pid 843279:tid 843473] [client 57.141.18.11:54672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qo_qvKNcW5yy5T2C4HgAAxHM"]
[Mon Jul 20 06:12:24.375529 2026] [security2:error] [pid 843279:tid 843446] [client 50.116.65.227:36278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QqPqvKNcW5yy5T2C4nAAAAKk"]
[Mon Jul 20 06:12:24.386434 2026] [security2:error] [pid 843279:tid 843414] [client 50.116.65.227:36286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QqPqvKNcW5yy5T2C4nQAAAIk"]
[Mon Jul 20 06:12:24.470075 2026] [security2:error] [pid 858085:tid 858279] [client 14.225.17.146:62103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUppmwAAAD8"], referer: http://partnerselectricalllc.com/WORDPRESS
[Mon Jul 20 06:12:24.629348 2026] [security2:error] [pid 858085:tid 858222] [client 57.141.18.23:59260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QozAtbv2vrjByhUpo-QAABns"]
[Mon Jul 20 06:12:24.662359 2026] [security2:error] [pid 843279:tid 843492] [client 14.225.17.146:62467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4QqPqvKNcW5yy5T2C4nwAAANc"], referer: http://according2plant.com/WORDPRESS
[Mon Jul 20 06:12:24.686258 2026] [security2:error] [pid 843279:tid 843538] [client 158.173.166.181:52757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QqPqvKNcW5yy5T2C4qAAAAQQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:24.762394 2026] [security2:error] [pid 858085:tid 858256] [client 106.192.104.4:63972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QqDAtbv2vrjByhUpqIgAAACg"]
[Mon Jul 20 06:12:24.771818 2026] [security2:error] [pid 858085:tid 858256] [client 106.192.104.4:63972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QqDAtbv2vrjByhUpqIgAAACg"]
[Mon Jul 20 06:12:24.996076 2026] [security2:error] [pid 858085:tid 858212] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QqDAtbv2vrjByhUpqLAAAD30"]
[Mon Jul 20 06:12:25.132282 2026] [security2:error] [pid 843279:tid 843498] [client 57.141.18.22:57142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpPqvKNcW5yy5T2C4MAAA3Uk"]
[Mon Jul 20 06:12:25.267461 2026] [security2:error] [pid 843279:tid 843460] [client 57.141.18.108:46522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpPqvKNcW5yy5T2C4NgAAt1I"]
[Mon Jul 20 06:12:25.463018 2026] [security2:error] [pid 858085:tid 858100] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QqTAtbv2vrjByhUpqPwAAMg0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:12:25.487739 2026] [security2:error] [pid 858085:tid 858167] [remote 18.61.192.253:36944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QqTAtbv2vrjByhUpqQgAASFA"]
[Mon Jul 20 06:12:25.546239 2026] [security2:error] [pid 858085:tid 858262] [client 14.225.17.146:61906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4QpzAtbv2vrjByhUpp7gAAAC4"], referer: http://nwcarvingacademy.com/WORDPRESS
[Mon Jul 20 06:12:25.676394 2026] [security2:error] [pid 843279:tid 843444] [client 185.132.186.88:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/autoload_classmap.php"] [unique_id "al4QqfqvKNcW5yy5T2C4xAAAAKc"]
[Mon Jul 20 06:12:25.881660 2026] [security2:error] [pid 858085:tid 858251] [client 103.77.203.233:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QqTAtbv2vrjByhUpqYQAAACM"]
[Mon Jul 20 06:12:25.882426 2026] [security2:error] [pid 858085:tid 858251] [client 103.77.203.233:51584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QqTAtbv2vrjByhUpqYQAAACM"]
[Mon Jul 20 06:12:25.901741 2026] [security2:error] [pid 858085:tid 858252] [client 57.141.18.18:57940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpTAtbv2vrjByhUppTgAAJC4"]
[Mon Jul 20 06:12:25.914952 2026] [security2:error] [pid 843279:tid 843430] [client 50.116.65.227:15206] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4QqfqvKNcW5yy5T2C4zgAAAJk"]
[Mon Jul 20 06:12:25.929559 2026] [security2:error] [pid 843279:tid 843465] [client 50.116.65.227:36322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4QqfqvKNcW5yy5T2C4zwAAAOY"]
[Mon Jul 20 06:12:26.004114 2026] [security2:error] [pid 858085:tid 858121] [remote 57.141.18.47:39630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3874665"] [unique_id "al4QqTAtbv2vrjByhUpqaQAADSI"]
[Mon Jul 20 06:12:26.339802 2026] [security2:error] [pid 858085:tid 858128] [remote 18.61.192.253:36944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4QqjAtbv2vrjByhUpqegAAXik"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:12:26.394716 2026] [security2:error] [pid 843279:tid 843299] [remote 192.241.143.148:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QqvqvKNcW5yy5T2C43AAA5BI"]
[Mon Jul 20 06:12:26.421572 2026] [security2:error] [pid 858085:tid 858143] [remote 209.133.215.178:59240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.215.133.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QqjAtbv2vrjByhUpqfwAANzg"]
[Mon Jul 20 06:12:26.608526 2026] [security2:error] [pid 858085:tid 858139] [remote 209.133.215.178:59240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.215.133.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4QqjAtbv2vrjByhUpqhAAASjQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:12:26.615313 2026] [security2:error] [pid 843279:tid 843288] [remote 192.241.143.148:34872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QqvqvKNcW5yy5T2C43wAAuAc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:26.773550 2026] [security2:error] [pid 858085:tid 858243] [client 14.225.17.146:58156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4QqTAtbv2vrjByhUpqMAAAABs"], referer: http://laceycaraccident.com/WORDPRESS
[Mon Jul 20 06:12:26.800961 2026] [security2:error] [pid 843279:tid 843434] [client 14.225.17.146:60734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4QqvqvKNcW5yy5T2C43gAAAJ0"], referer: https://nwcarvingacademy.com/WORDPRESS
[Mon Jul 20 06:12:27.051616 2026] [security2:error] [pid 843279:tid 843489] [client 57.141.18.74:56066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpvqvKNcW5yy5T2C4bgAA1A8"]
[Mon Jul 20 06:12:27.470262 2026] [security2:error] [pid 858085:tid 858315] [client 57.141.18.121:22068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QpjAtbv2vrjByhUppqwAAY1k"]
[Mon Jul 20 06:12:27.528801 2026] [security2:error] [pid 843279:tid 843496] [client 14.225.17.146:61966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4QqfqvKNcW5yy5T2C4zQAAANs"], referer: http://aberballet.co.uk/WORDPRESS
[Mon Jul 20 06:12:27.620400 2026] [security2:error] [pid 858085:tid 858296] [client 185.132.186.104:27293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "al4QqzAtbv2vrjByhUpquAAAAFA"]
[Mon Jul 20 06:12:27.839541 2026] [security2:error] [pid 858085:tid 858294] [client 98.159.234.160:42429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4QqzAtbv2vrjByhUpqxAAAAE4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:28.139137 2026] [security2:error] [pid 858085:tid 858267] [client 216.73.217.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpqygAAADM"]
[Mon Jul 20 06:12:28.309342 2026] [security2:error] [pid 843279:tid 843419] [client 27.96.94.195:38243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QrPqvKNcW5yy5T2C5DQAAAI4"]
[Mon Jul 20 06:12:28.309475 2026] [security2:error] [pid 843279:tid 843419] [client 27.96.94.195:38243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QrPqvKNcW5yy5T2C5DQAAAI4"]
[Mon Jul 20 06:12:28.579201 2026] [autoindex:error] [pid 858085:tid 858243] [client 205.210.31.50:65466] AH01276: Cannot serve directory /home2/zajlqimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.zaj.lqi.mybluehost.me/
[Mon Jul 20 06:12:28.649290 2026] [security2:error] [pid 858085:tid 858216] [client 181.224.94.124:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QrDAtbv2vrjByhUpq-AAAAAA"]
[Mon Jul 20 06:12:28.649444 2026] [security2:error] [pid 858085:tid 858216] [client 181.224.94.124:63717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QrDAtbv2vrjByhUpq-AAAAAA"]
[Mon Jul 20 06:12:29.580897 2026] [security2:error] [pid 858085:tid 858246] [client 185.132.186.88:49667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/repairs.php"] [unique_id "al4QrTAtbv2vrjByhUprFQAAAB4"]
[Mon Jul 20 06:12:29.638693 2026] [security2:error] [pid 843279:tid 843342] [remote 160.187.68.132:44330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4QrfqvKNcW5yy5T2C5MwAA7T0"]
[Mon Jul 20 06:12:29.871728 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QrfqvKNcW5yy5T2C5PgAAAPI"]
[Mon Jul 20 06:12:29.872119 2026] [security2:error] [pid 843279:tid 843520] [client 103.141.108.143:60492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QrfqvKNcW5yy5T2C5PgAAAPI"]
[Mon Jul 20 06:12:29.929409 2026] [security2:error] [pid 858085:tid 858220] [client 57.141.18.111:56362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqTAtbv2vrjByhUpqRQAABBI"]
[Mon Jul 20 06:12:30.144843 2026] [security2:error] [pid 858085:tid 858323] [client 14.225.17.146:49955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpq-gAAAGs"], referer: http://eframiproperties.com/WORDPRESS
[Mon Jul 20 06:12:30.263245 2026] [security2:error] [pid 843279:tid 843510] [client 216.73.217.138:12796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QrvqvKNcW5yy5T2C5SAAA6Fg"]
[Mon Jul 20 06:12:30.332851 2026] [security2:error] [pid 858085:tid 858301] [client 65.21.32.180:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4QrjAtbv2vrjByhUprLwAAAFU"]
[Mon Jul 20 06:12:30.361856 2026] [security2:error] [pid 858085:tid 858260] [client 57.141.18.74:55950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqTAtbv2vrjByhUpqYAAALB4"]
[Mon Jul 20 06:12:30.392125 2026] [security2:error] [pid 843279:tid 843471] [client 41.173.37.102:4853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5TQAAAMI"]
[Mon Jul 20 06:12:30.392269 2026] [security2:error] [pid 843279:tid 843471] [client 41.173.37.102:4853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5TQAAAMI"]
[Mon Jul 20 06:12:30.410665 2026] [security2:error] [pid 858085:tid 858196] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrjAtbv2vrjByhUprOQAAL20"]
[Mon Jul 20 06:12:30.410833 2026] [security2:error] [pid 858085:tid 858263] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrjAtbv2vrjByhUprOQAAL20"]
[Mon Jul 20 06:12:30.480811 2026] [security2:error] [pid 858085:tid 858208] [remote 154.0.166.254:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QrjAtbv2vrjByhUprPQAAd3k"]
[Mon Jul 20 06:12:30.504689 2026] [security2:error] [pid 858085:tid 858241] [client 57.141.18.12:22196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqjAtbv2vrjByhUpqcAAAGSE"]
[Mon Jul 20 06:12:30.851548 2026] [security2:error] [pid 858085:tid 858288] [client 57.141.18.64:44364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqjAtbv2vrjByhUpqeQAASCg"]
[Mon Jul 20 06:12:30.862325 2026] [security2:error] [pid 843279:tid 843451] [client 45.116.69.230:56684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5WwAAAK4"]
[Mon Jul 20 06:12:30.862457 2026] [security2:error] [pid 843279:tid 843451] [client 45.116.69.230:56684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5WwAAAK4"]
[Mon Jul 20 06:12:30.929320 2026] [security2:error] [pid 843279:tid 843466] [client 112.213.160.112:31012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5XAAAAL0"]
[Mon Jul 20 06:12:30.929451 2026] [security2:error] [pid 843279:tid 843466] [client 112.213.160.112:31012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QrvqvKNcW5yy5T2C5XAAAAL0"]
[Mon Jul 20 06:12:30.967739 2026] [security2:error] [pid 858085:tid 858163] [remote 154.0.166.254:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4QrjAtbv2vrjByhUprVwAAbEw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:12:31.076415 2026] [security2:error] [pid 843279:tid 843406] [remote 47.86.33.52:15096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5YQAAvn0"]
[Mon Jul 20 06:12:31.187590 2026] [security2:error] [pid 858085:tid 858275] [client 104.234.53.89:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4QrzAtbv2vrjByhUprYwAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:31.213298 2026] [proxy:error] [pid 858085:tid 858296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:31.213347 2026] [proxy_http:error] [pid 858085:tid 858296] [client 8.229.28.226:54204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:31.214186 2026] [proxy:error] [pid 858085:tid 858296] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:31.214219 2026] [proxy_http:error] [pid 858085:tid 858296] [client 8.229.28.226:54204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:31.215585 2026] [security2:error] [pid 858085:tid 858333] [client 47.128.117.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QrjAtbv2vrjByhUprUQAAAHU"]
[Mon Jul 20 06:12:31.325576 2026] [security2:error] [pid 858085:tid 858100] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUprcwAAGQ0"]
[Mon Jul 20 06:12:31.325745 2026] [security2:error] [pid 858085:tid 858241] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUprcwAAGQ0"]
[Mon Jul 20 06:12:31.361598 2026] [security2:error] [pid 843279:tid 843372] [remote 160.187.68.132:44330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5ZgAA_ls"], referer: https://solkeetw.com/wp-login.php
[Mon Jul 20 06:12:31.476491 2026] [security2:error] [pid 858085:tid 858277] [client 178.152.178.232:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUpreAAAAD0"]
[Mon Jul 20 06:12:31.476638 2026] [security2:error] [pid 858085:tid 858277] [client 178.152.178.232:37154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QrzAtbv2vrjByhUpreAAAAD0"]
[Mon Jul 20 06:12:31.515446 2026] [security2:error] [pid 843279:tid 843455] [client 74.208.214.194:42486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5bAAAALI"]
[Mon Jul 20 06:12:31.517280 2026] [security2:error] [pid 858085:tid 858280] [client 185.132.186.59:57729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/smilies/simi.php"] [unique_id "al4QrzAtbv2vrjByhUprewAAAEA"]
[Mon Jul 20 06:12:31.753430 2026] [security2:error] [pid 858085:tid 858340] [client 57.141.18.75:23422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QqzAtbv2vrjByhUpqogAAfBQ"]
[Mon Jul 20 06:12:32.437110 2026] [security2:error] [pid 843279:tid 843328] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5fAAA_y8"]
[Mon Jul 20 06:12:32.437275 2026] [security2:error] [pid 843279:tid 843533] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5fAAA_y8"]
[Mon Jul 20 06:12:32.456966 2026] [security2:error] [pid 858085:tid 858321] [client 14.225.17.146:51037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4QsDAtbv2vrjByhUprogAAAGk"], referer: http://alrowad-hub.net/WORDPRESS
[Mon Jul 20 06:12:32.671389 2026] [security2:error] [pid 843279:tid 843425] [client 3.109.4.218:53762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5iwAAAJQ"]
[Mon Jul 20 06:12:32.671548 2026] [security2:error] [pid 843279:tid 843425] [client 3.109.4.218:53762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QsPqvKNcW5yy5T2C5iwAAAJQ"]
[Mon Jul 20 06:12:32.955737 2026] [security2:error] [pid 843279:tid 843462] [client 14.225.17.146:50621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5bwAAALk"], referer: http://alaraycreative.com/WORDPRESS
[Mon Jul 20 06:12:32.993843 2026] [security2:error] [pid 858085:tid 858098] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QsDAtbv2vrjByhUprxwAAMAs"]
[Mon Jul 20 06:12:32.994142 2026] [security2:error] [pid 858085:tid 858264] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QsDAtbv2vrjByhUprxwAAMAs"]
[Mon Jul 20 06:12:33.029332 2026] [security2:error] [pid 843279:tid 843424] [client 94.154.43.178:32340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.muamoicosmetics.com"] [uri "/.env"] [unique_id "al4QsfqvKNcW5yy5T2C5lAAAAJM"]
[Mon Jul 20 06:12:33.182509 2026] [security2:error] [pid 858085:tid 858146] [remote 3.7.185.37:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4QsTAtbv2vrjByhUprzwAAbjs"]
[Mon Jul 20 06:12:33.185865 2026] [security2:error] [pid 858085:tid 858304] [client 57.141.18.48:23858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpq4AAAWEs"]
[Mon Jul 20 06:12:33.292201 2026] [security2:error] [pid 858085:tid 858262] [client 57.141.18.121:22080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QrDAtbv2vrjByhUpq7wAALkQ"]
[Mon Jul 20 06:12:33.462947 2026] [security2:error] [pid 858085:tid 858257] [client 185.132.186.65:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin.php"] [unique_id "al4QsTAtbv2vrjByhUpr4gAAACk"]
[Mon Jul 20 06:12:33.467554 2026] [security2:error] [pid 858085:tid 858340] [client 50.116.65.227:11482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QsTAtbv2vrjByhUpr4wAAAHw"]
[Mon Jul 20 06:12:33.481831 2026] [security2:error] [pid 858085:tid 858299] [client 50.116.65.227:11498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QsTAtbv2vrjByhUpr5AAAAFM"]
[Mon Jul 20 06:12:33.492111 2026] [ssl:error] [pid 858085:tid 858254] [client 98.88.137.2:5576] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname autodiscover.ugx.lqn.mybluehost.me provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:12:33.611729 2026] [security2:error] [pid 858085:tid 858159] [remote 3.7.185.37:51022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4QsTAtbv2vrjByhUpr7gAAGEg"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:12:33.790610 2026] [security2:error] [pid 858085:tid 858227] [client 50.116.65.227:57086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QsTAtbv2vrjByhUpr_AAAAAs"]
[Mon Jul 20 06:12:33.804713 2026] [security2:error] [pid 843279:tid 843515] [client 50.116.65.227:11510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QsfqvKNcW5yy5T2C5pgAAAO0"]
[Mon Jul 20 06:12:34.120005 2026] [security2:error] [pid 858085:tid 858220] [client 66.249.64.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.indiraskitchenllc.com"] [uri "/index.php"] [unique_id "al4QsDAtbv2vrjByhUprtAAABDQ"]
[Mon Jul 20 06:12:34.149413 2026] [security2:error] [pid 843279:tid 843400] [remote 47.86.33.52:15096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QsvqvKNcW5yy5T2C5sgAA4nc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:34.177534 2026] [security2:error] [pid 858085:tid 858276] [client 13.201.64.214:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QsjAtbv2vrjByhUpsCQAAADw"]
[Mon Jul 20 06:12:34.177656 2026] [security2:error] [pid 858085:tid 858276] [client 13.201.64.214:46456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4QsjAtbv2vrjByhUpsCQAAADw"]
[Mon Jul 20 06:12:34.522542 2026] [proxy:error] [pid 858085:tid 858340] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:34.522591 2026] [proxy_http:error] [pid 858085:tid 858340] [client 23.180.120.147:33334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:34.524196 2026] [proxy:error] [pid 858085:tid 858340] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:34.524261 2026] [proxy_http:error] [pid 858085:tid 858340] [client 23.180.120.147:33334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:34.951928 2026] [security2:error] [pid 858085:tid 858301] [client 13.201.64.214:46468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QsjAtbv2vrjByhUpsPgAAAFU"]
[Mon Jul 20 06:12:35.001872 2026] [security2:error] [pid 843279:tid 843361] [remote 208.109.9.173:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4QsvqvKNcW5yy5T2C5yQAA1VA"]
[Mon Jul 20 06:12:35.093955 2026] [security2:error] [pid 858085:tid 858251] [client 188.253.17.6:39322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4QsjAtbv2vrjByhUpsHwAAACM"], referer: https://mezzacraft.com/why-i-dont-sell-my-crochet-creations-for-a-living/
[Mon Jul 20 06:12:35.157211 2026] [security2:error] [pid 843279:tid 843413] [client 114.119.144.29:29523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ksands.co.uk"] [uri "/security-services-in-brazil/"] [unique_id "al4Qs_qvKNcW5yy5T2C5zQAAAIg"], referer: https://ksands.co.uk/safety-security-services/resilience-and-continuity-consultancy/
[Mon Jul 20 06:12:35.162198 2026] [security2:error] [pid 843279:tid 843424] [client 54.169.146.187:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C5zAAAAJM"]
[Mon Jul 20 06:12:35.162288 2026] [security2:error] [pid 843279:tid 843424] [client 54.169.146.187:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C5zAAAAJM"]
[Mon Jul 20 06:12:35.273741 2026] [security2:error] [pid 858085:tid 858281] [client 74.208.214.194:45932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4QszAtbv2vrjByhUpsSgAAAEE"]
[Mon Jul 20 06:12:35.411020 2026] [security2:error] [pid 858085:tid 858279] [client 185.132.186.78:20863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-header.php%20"] [unique_id "al4QszAtbv2vrjByhUpsUwAAAD8"]
[Mon Jul 20 06:12:35.435778 2026] [security2:error] [pid 843279:tid 843294] [remote 208.109.9.173:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4Qs_qvKNcW5yy5T2C51wAApg0"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 06:12:35.741294 2026] [security2:error] [pid 858085:tid 858226] [client 13.217.4.236:48336] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "206"] [hostname "elespecialista.mx"] [uri "/index.html"] [unique_id "al4QszAtbv2vrjByhUpsXwAAAAo"]
[Mon Jul 20 06:12:35.775142 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.62:48036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QrzAtbv2vrjByhUprbAAAd1o"]
[Mon Jul 20 06:12:35.778983 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C54QAAALA"]
[Mon Jul 20 06:12:35.779129 2026] [security2:error] [pid 843279:tid 843453] [client 106.192.104.4:64466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Qs_qvKNcW5yy5T2C54QAAALA"]
[Mon Jul 20 06:12:35.881057 2026] [security2:error] [pid 843279:tid 843475] [client 14.225.17.146:50984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4Qs_qvKNcW5yy5T2C53AAAAMY"], referer: http://transparentservices.online/WORDPRESS
[Mon Jul 20 06:12:36.032334 2026] [security2:error] [pid 843279:tid 843480] [client 57.141.18.9:30868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qr_qvKNcW5yy5T2C5aQAAy24"]
[Mon Jul 20 06:12:36.053556 2026] [security2:error] [pid 858085:tid 858330] [client 18.208.166.180:63294] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "elespecialista.mx"] [uri "/favicon.ico"] [unique_id "al4QtDAtbv2vrjByhUpscgAAAHI"]
[Mon Jul 20 06:12:36.294002 2026] [security2:error] [pid 843279:tid 843415] [client 3.109.4.218:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QtPqvKNcW5yy5T2C5-wAAAIo"]
[Mon Jul 20 06:12:36.424148 2026] [security2:error] [pid 858085:tid 858214] [remote 47.128.99.94:17732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/roleta-online-editavel-2024-01-29-id-33127.pdf"] [unique_id "al4QtDAtbv2vrjByhUpshAAAGn8"]
[Mon Jul 20 06:12:36.434747 2026] [security2:error] [pid 858085:tid 858342] [client 14.225.17.146:54771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4QtDAtbv2vrjByhUpseAAAAH4"], referer: http://ivetstrategies.com/WORDPRESS
[Mon Jul 20 06:12:36.482240 2026] [security2:error] [pid 843279:tid 843533] [client 103.77.203.233:52118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QtPqvKNcW5yy5T2C6BgAAAP8"]
[Mon Jul 20 06:12:36.482578 2026] [security2:error] [pid 843279:tid 843533] [client 103.77.203.233:52118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QtPqvKNcW5yy5T2C6BgAAAP8"]
[Mon Jul 20 06:12:37.124396 2026] [security2:error] [pid 858085:tid 858289] [client 57.141.18.59:61644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QsDAtbv2vrjByhUpruwAASTc"]
[Mon Jul 20 06:12:37.193607 2026] [security2:error] [pid 843279:tid 843469] [client 3.109.4.218:53786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QtfqvKNcW5yy5T2C6EQAAAMA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:12:37.372527 2026] [security2:error] [pid 858085:tid 858303] [client 185.132.186.83:33557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/file.php%20"] [unique_id "al4QtTAtbv2vrjByhUpssAAAAFc"]
[Mon Jul 20 06:12:37.534839 2026] [security2:error] [pid 843279:tid 843438] [client 57.141.18.84:29398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QsfqvKNcW5yy5T2C5mAAAoVw"]
[Mon Jul 20 06:12:37.637666 2026] [security2:error] [pid 858085:tid 858233] [client 14.225.17.146:54893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QtTAtbv2vrjByhUpstwAAABE"], referer: http://maxenengineering.com/WORDPRESS
[Mon Jul 20 06:12:37.881821 2026] [security2:error] [pid 843279:tid 843511] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4QtPqvKNcW5yy5T2C59gAA6Q4"], referer: http://assasalnazaha.com/WORDPRESS
[Mon Jul 20 06:12:37.970481 2026] [security2:error] [pid 858085:tid 858301] [client 34.221.76.50:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4QtTAtbv2vrjByhUpsogAAAFU"]
[Mon Jul 20 06:12:37.977914 2026] [security2:error] [pid 843279:tid 843459] [client 34.221.76.50:38500] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-meatballs-in-sofrito-sauce-recipe/"] [unique_id "al4QtfqvKNcW5yy5T2C6EAAAALY"]
[Mon Jul 20 06:12:38.329794 2026] [proxy:error] [pid 858085:tid 858286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:38.329840 2026] [proxy_http:error] [pid 858085:tid 858286] [client 8.229.28.226:35608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:38.330422 2026] [proxy:error] [pid 858085:tid 858286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:38.330452 2026] [proxy_http:error] [pid 858085:tid 858286] [client 8.229.28.226:35608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:38.673968 2026] [security2:error] [pid 843279:tid 843531] [client 14.225.17.146:64684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4QtvqvKNcW5yy5T2C6PAAAAP0"], referer: https://maxenengineering.com/WORDPRESS
[Mon Jul 20 06:12:38.743953 2026] [security2:error] [pid 858085:tid 858331] [client 57.141.18.20:30432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QsjAtbv2vrjByhUpsDgAAc1Y"]
[Mon Jul 20 06:12:39.017841 2026] [security2:error] [pid 843279:tid 843302] [remote 188.40.28.4:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6SgAAmRU"]
[Mon Jul 20 06:12:39.185291 2026] [security2:error] [pid 843279:tid 843439] [client 181.224.94.124:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6UAAAAKI"]
[Mon Jul 20 06:12:39.185429 2026] [security2:error] [pid 843279:tid 843439] [client 181.224.94.124:35858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6UAAAAKI"]
[Mon Jul 20 06:12:39.194535 2026] [security2:error] [pid 858085:tid 858254] [client 27.96.94.195:37947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QtzAtbv2vrjByhUptHAAAACY"]
[Mon Jul 20 06:12:39.194645 2026] [security2:error] [pid 858085:tid 858254] [client 27.96.94.195:37947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QtzAtbv2vrjByhUptHAAAACY"]
[Mon Jul 20 06:12:39.214396 2026] [security2:error] [pid 843279:tid 843333] [remote 188.40.28.4:38700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6UgAAyzQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:39.504085 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:63934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4QtjAtbv2vrjByhUps9AAAABM"], referer: http://massagelacey.com/WORDPRESS
[Mon Jul 20 06:12:39.663756 2026] [security2:error] [pid 858085:tid 858332] [client 57.141.18.15:44466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QszAtbv2vrjByhUpsRAAAdFc"]
[Mon Jul 20 06:12:39.764585 2026] [security2:error] [pid 858085:tid 858152] [remote 57.141.18.72:32318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5991539"] [unique_id "al4QtzAtbv2vrjByhUptNAAAD0E"]
[Mon Jul 20 06:12:39.856338 2026] [security2:error] [pid 858085:tid 858284] [client 185.132.186.87:29113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.tmb/doc.php"] [unique_id "al4QtzAtbv2vrjByhUptOwAAAEQ"]
[Mon Jul 20 06:12:40.306634 2026] [security2:error] [pid 858085:tid 858271] [client 14.225.17.146:59060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4QuDAtbv2vrjByhUptUAAAADc"], referer: http://katsklar.com/WORDPRESS
[Mon Jul 20 06:12:40.596909 2026] [security2:error] [pid 843279:tid 843464] [client 103.141.108.143:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QuPqvKNcW5yy5T2C6dQAAALs"]
[Mon Jul 20 06:12:40.597034 2026] [security2:error] [pid 843279:tid 843464] [client 103.141.108.143:60964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QuPqvKNcW5yy5T2C6dQAAALs"]
[Mon Jul 20 06:12:40.602247 2026] [fcgid:warn] [pid 858085:tid 858299] (70014)End of file found: [client 64.225.75.246:55094] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:40.813109 2026] [security2:error] [pid 843279:tid 843507] [client 17.246.19.86:58564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.suretybonds-california.com"] [uri "/index.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6ZwAAAOU"]
[Mon Jul 20 06:12:40.828449 2026] [security2:error] [pid 858085:tid 858328] [client 14.225.17.146:54932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4QtjAtbv2vrjByhUps-wAAAHA"], referer: http://worbals.com/WORDPRESS
[Mon Jul 20 06:12:40.927065 2026] [fcgid:warn] [pid 843279:tid 843467] (70014)End of file found: [client 64.225.75.246:55108] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:40.963889 2026] [security2:error] [pid 843279:tid 843438] [client 14.225.17.146:63866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6YgAAAKE"], referer: http://alchemygroup.ca/WORDPRESS
[Mon Jul 20 06:12:40.995551 2026] [security2:error] [pid 858085:tid 858217] [client 41.173.37.102:5310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QuDAtbv2vrjByhUptfgAAAAE"]
[Mon Jul 20 06:12:40.995686 2026] [security2:error] [pid 858085:tid 858217] [client 41.173.37.102:5310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QuDAtbv2vrjByhUptfgAAAAE"]
[Mon Jul 20 06:12:41.107762 2026] [security2:error] [pid 858085:tid 858247] [client 52.28.162.93:48226] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4QuDAtbv2vrjByhUptfAAAAB8"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:12:41.233799 2026] [security2:error] [pid 858085:tid 858089] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptnAAAIwI"]
[Mon Jul 20 06:12:41.233952 2026] [security2:error] [pid 858085:tid 858251] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptnAAAIwI"]
[Mon Jul 20 06:12:41.327833 2026] [security2:error] [pid 858085:tid 858331] [client 14.225.17.146:63895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4QuTAtbv2vrjByhUptmgAAAHM"], referer: http://mcg.homes/WORDPRESS
[Mon Jul 20 06:12:41.467340 2026] [security2:error] [pid 858085:tid 858266] [client 50.116.65.227:49118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QuTAtbv2vrjByhUptqgAAADI"]
[Mon Jul 20 06:12:41.481764 2026] [security2:error] [pid 843279:tid 843451] [client 50.116.65.227:48340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4QufqvKNcW5yy5T2C6lAAAAOo"]
[Mon Jul 20 06:12:41.511795 2026] [security2:error] [pid 843279:tid 843481] [client 45.116.69.230:57213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QufqvKNcW5yy5T2C6lQAAAMw"]
[Mon Jul 20 06:12:41.511906 2026] [security2:error] [pid 843279:tid 843481] [client 45.116.69.230:57213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QufqvKNcW5yy5T2C6lQAAAMw"]
[Mon Jul 20 06:12:41.593233 2026] [core:error] [pid 858085:tid 858234] [client 14.225.17.146:54410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:41.593253 2026] [core:error] [pid 858085:tid 858234] [client 14.225.17.146:54410] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:41.704627 2026] [security2:error] [pid 843279:tid 843428] [client 104.234.53.59:46653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4QufqvKNcW5yy5T2C6mgAAAJc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:41.714698 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptuwAAABE"]
[Mon Jul 20 06:12:41.714815 2026] [security2:error] [pid 858085:tid 858233] [client 112.213.160.112:8617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUptuwAAABE"]
[Mon Jul 20 06:12:41.731103 2026] [security2:error] [pid 858085:tid 858254] [client 103.153.183.69:59794] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..%ef%bc%8f..%ef%bc%8fproc/self/environ"] [unique_id "al4QuTAtbv2vrjByhUptvwAAACY"], referer: https://twitter.com/
[Mon Jul 20 06:12:41.807005 2026] [security2:error] [pid 843279:tid 843447] [client 185.132.186.80:27313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-editor.php"] [unique_id "al4QufqvKNcW5yy5T2C6nAAAAKo"]
[Mon Jul 20 06:12:41.841375 2026] [security2:error] [pid 858085:tid 858250] [client 5.35.93.45:37052] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cja.jby.mybluehost.me"] [uri "/wp-comments-post.php"] [unique_id "al4QuTAtbv2vrjByhUptwQAAACI"]
[Mon Jul 20 06:12:41.884766 2026] [security2:error] [pid 858085:tid 858250] [client 5.35.93.45:37052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "cja.jby.mybluehost.me"] [uri "/wp-comments-post.php"] [unique_id "al4QuTAtbv2vrjByhUptwQAAACI"]
[Mon Jul 20 06:12:41.895331 2026] [security2:error] [pid 858085:tid 858099] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUpt0AAAKww"]
[Mon Jul 20 06:12:41.895552 2026] [security2:error] [pid 858085:tid 858259] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QuTAtbv2vrjByhUpt0AAAKww"]
[Mon Jul 20 06:12:42.140385 2026] [security2:error] [pid 858085:tid 858338] [client 57.141.18.8:55428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QtTAtbv2vrjByhUpsrgAAehg"]
[Mon Jul 20 06:12:42.576372 2026] [security2:error] [pid 858085:tid 858324] [client 14.225.17.146:63920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4QuTAtbv2vrjByhUpttwAAAGw"], referer: http://processorstudio.com/WORDPRESS
[Mon Jul 20 06:12:42.720474 2026] [security2:error] [pid 858085:tid 858260] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QujAtbv2vrjByhUpt4wAAACw"]
[Mon Jul 20 06:12:43.056848 2026] [security2:error] [pid 843279:tid 843303] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Qu_qvKNcW5yy5T2C6xQAA_hY"]
[Mon Jul 20 06:12:43.057097 2026] [security2:error] [pid 843279:tid 843532] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Qu_qvKNcW5yy5T2C6xQAA_hY"]
[Mon Jul 20 06:12:43.430787 2026] [security2:error] [pid 858085:tid 858266] [client 14.225.17.146:50766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4QuzAtbv2vrjByhUpuKQAAADI"], referer: https://processorstudio.com/WORDPRESS
[Mon Jul 20 06:12:43.492952 2026] [security2:error] [pid 858085:tid 858104] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuLwAAWRE"]
[Mon Jul 20 06:12:43.493217 2026] [security2:error] [pid 858085:tid 858305] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuLwAAWRE"]
[Mon Jul 20 06:12:43.567325 2026] [security2:error] [pid 858085:tid 858148] [remote 103.255.134.61:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QuzAtbv2vrjByhUpuNAAAXj0"]
[Mon Jul 20 06:12:43.620531 2026] [security2:error] [pid 843279:tid 843436] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Qu_qvKNcW5yy5T2C60QAAAJ8"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:12:43.624173 2026] [security2:error] [pid 858085:tid 858281] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QuzAtbv2vrjByhUpuLAAAAEE"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:12:43.626272 2026] [security2:error] [pid 858085:tid 858262] [client 14.225.17.146:54402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4QuTAtbv2vrjByhUptzQAAAC4"], referer: http://nomorewetsheets.net/WORDPRESS
[Mon Jul 20 06:12:43.657146 2026] [security2:error] [pid 858085:tid 858233] [client 13.201.64.214:65272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuOQAAABE"]
[Mon Jul 20 06:12:43.657233 2026] [security2:error] [pid 858085:tid 858233] [client 13.201.64.214:65272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QuzAtbv2vrjByhUpuOQAAABE"]
[Mon Jul 20 06:12:43.725123 2026] [security2:error] [pid 858085:tid 858274] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QuzAtbv2vrjByhUpuEgAAADo"]
[Mon Jul 20 06:12:43.786046 2026] [security2:error] [pid 843279:tid 843469] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4QuvqvKNcW5yy5T2C6uQAAwAM"], referer: http://ardhalwafaa.com/WORDPRESS
[Mon Jul 20 06:12:43.801593 2026] [security2:error] [pid 858085:tid 858223] [client 185.132.186.85:62507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine-session.php"] [unique_id "al4QuzAtbv2vrjByhUpuRQAAAAc"]
[Mon Jul 20 06:12:43.962891 2026] [security2:error] [pid 843279:tid 843437] [client 57.141.18.95:36134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qt_qvKNcW5yy5T2C6WQAAoGA"]
[Mon Jul 20 06:12:44.242495 2026] [access_compat:error] [pid 843279:tid 843472] [client 64.225.75.246:55146] AH01797: client denied by server configuration: proxy:http://127.0.0.1:8080/server-status
[Mon Jul 20 06:12:44.277287 2026] [security2:error] [pid 843279:tid 843375] [remote 110.249.201.190:18292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/comments-predeadline-5pm-Nov-7-s-z.pdf"] [unique_id "al4QvPqvKNcW5yy5T2C68QAAuF4"]
[Mon Jul 20 06:12:44.455561 2026] [security2:error] [pid 858085:tid 858291] [client 57.141.18.84:29406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QtzAtbv2vrjByhUptNQAASzU"]
[Mon Jul 20 06:12:44.460973 2026] [security2:error] [pid 843279:tid 843495] [client 34.21.84.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4QvPqvKNcW5yy5T2C69gAAANo"]
[Mon Jul 20 06:12:44.567782 2026] [security2:error] [pid 858085:tid 858274] [client 34.21.84.81:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.84.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4QvDAtbv2vrjByhUpubQAAADo"]
[Mon Jul 20 06:12:44.897487 2026] [security2:error] [pid 858085:tid 858294] [client 34.21.84.81:61906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4QvDAtbv2vrjByhUpuegAAAE4"]
[Mon Jul 20 06:12:44.904076 2026] [security2:error] [pid 858085:tid 858157] [remote 103.255.134.61:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QvDAtbv2vrjByhUpuewAAKkY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:44.924858 2026] [security2:error] [pid 843279:tid 843484] [client 14.225.17.146:50376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4Qu_qvKNcW5yy5T2C63wAAAM8"], referer: http://nikkidesigns.net/WORDPRESS
[Mon Jul 20 06:12:44.953706 2026] [security2:error] [pid 858085:tid 858337] [client 57.141.18.10:62026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QuDAtbv2vrjByhUptUgAAeTM"]
[Mon Jul 20 06:12:45.196496 2026] [security2:error] [pid 858085:tid 858238] [client 34.21.84.81:51157] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4QvTAtbv2vrjByhUpuigAAABY"]
[Mon Jul 20 06:12:45.321193 2026] [security2:error] [pid 843279:tid 843497] [client 104.234.53.86:23181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4QvfqvKNcW5yy5T2C7EAAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:45.468134 2026] [security2:error] [pid 858085:tid 858289] [client 34.21.84.81:57017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4QvTAtbv2vrjByhUpulQAAAEk"]
[Mon Jul 20 06:12:45.723030 2026] [security2:error] [pid 843279:tid 843471] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QvfqvKNcW5yy5T2C7CQAAAMI"]
[Mon Jul 20 06:12:45.800988 2026] [security2:error] [pid 858085:tid 858229] [client 34.21.84.81:59585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4QvTAtbv2vrjByhUpuqgAAAA0"]
[Mon Jul 20 06:12:45.949108 2026] [security2:error] [pid 843279:tid 843473] [client 13.215.47.127:20922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QvfqvKNcW5yy5T2C7HQAAAMQ"]
[Mon Jul 20 06:12:46.106895 2026] [security2:error] [pid 858085:tid 858286] [client 34.21.84.81:49403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4QvjAtbv2vrjByhUpuswAAAEY"]
[Mon Jul 20 06:12:46.136431 2026] [security2:error] [pid 843279:tid 843486] [client 13.201.64.214:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QvvqvKNcW5yy5T2C7IgAAANE"]
[Mon Jul 20 06:12:46.136538 2026] [security2:error] [pid 843279:tid 843486] [client 13.201.64.214:65286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QvvqvKNcW5yy5T2C7IgAAANE"]
[Mon Jul 20 06:12:46.359534 2026] [security2:error] [pid 843279:tid 843461] [client 34.21.84.81:59108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4QvvqvKNcW5yy5T2C7KwAAALg"]
[Mon Jul 20 06:12:46.527068 2026] [security2:error] [pid 858085:tid 858225] [client 14.225.17.146:54480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4QvjAtbv2vrjByhUpuzQAAAAk"]
[Mon Jul 20 06:12:46.663262 2026] [security2:error] [pid 858085:tid 858223] [client 34.21.84.81:52825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4QvjAtbv2vrjByhUpu2QAAAAc"]
[Mon Jul 20 06:12:46.679314 2026] [security2:error] [pid 858085:tid 858219] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QvjAtbv2vrjByhUpuuAAAAAM"]
[Mon Jul 20 06:12:46.715436 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:62463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4QvDAtbv2vrjByhUpudQAAADY"], referer: http://fineartsfactory.net/WORDPRESS
[Mon Jul 20 06:12:46.724431 2026] [security2:error] [pid 858085:tid 858325] [client 14.225.17.146:57123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4QvTAtbv2vrjByhUpujwAAAG0"], referer: http://709fx.com/WORDPRESS
[Mon Jul 20 06:12:46.935760 2026] [security2:error] [pid 858085:tid 858240] [client 47.129.222.11:33116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4QvjAtbv2vrjByhUpu6gAAABg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:12:47.000886 2026] [security2:error] [pid 858085:tid 858226] [client 34.21.84.81:59116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4QvzAtbv2vrjByhUpu8gAAAAo"]
[Mon Jul 20 06:12:47.019576 2026] [security2:error] [pid 858085:tid 858216] [client 103.153.183.69:64728] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../root/.ssh/id_rsa"] [unique_id "al4QvzAtbv2vrjByhUpu9QAAAAA"], referer: https://www.google.com/search?q=9j9c23
[Mon Jul 20 06:12:47.022612 2026] [security2:error] [pid 858085:tid 858319] [client 57.141.18.82:57388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QujAtbv2vrjByhUpt7AAAZ1g"]
[Mon Jul 20 06:12:47.120688 2026] [security2:error] [pid 858085:tid 858304] [client 103.77.203.233:52662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QvzAtbv2vrjByhUpu-QAAAFg"]
[Mon Jul 20 06:12:47.120884 2026] [security2:error] [pid 858085:tid 858304] [client 103.77.203.233:52662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QvzAtbv2vrjByhUpu-QAAAFg"]
[Mon Jul 20 06:12:47.131946 2026] [security2:error] [pid 843279:tid 843449] [client 14.225.17.146:57195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4QvfqvKNcW5yy5T2C7EgAAAKw"], referer: http://ironcitywellness.com/WORDPRESS
[Mon Jul 20 06:12:47.278488 2026] [security2:error] [pid 858085:tid 858229] [client 34.21.84.81:53578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4QvzAtbv2vrjByhUpvAgAAAA0"]
[Mon Jul 20 06:12:47.358212 2026] [cgid:error] [pid 858085:tid 858218] [client 66.132.172.182:19230] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: https://www.website-fa490990.threethirds.co:443/cgi-bin
[Mon Jul 20 06:12:47.532697 2026] [security2:error] [pid 858085:tid 858322] [client 34.21.84.81:51207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4QvzAtbv2vrjByhUpvEwAAAGo"]
[Mon Jul 20 06:12:47.555113 2026] [security2:error] [pid 858085:tid 858307] [client 57.141.18.92:53900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QujAtbv2vrjByhUpuCwAAWys"]
[Mon Jul 20 06:12:47.793942 2026] [security2:error] [pid 843279:tid 843413] [client 34.21.84.81:60912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "grndl.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Qv_qvKNcW5yy5T2C7QAAAAIg"]
[Mon Jul 20 06:12:48.533417 2026] [security2:error] [pid 843279:tid 843464] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7UAAAALs"]
[Mon Jul 20 06:12:48.629205 2026] [security2:error] [pid 858085:tid 858314] [client 106.192.104.4:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QwDAtbv2vrjByhUpvOAAAAGI"]
[Mon Jul 20 06:12:48.629326 2026] [security2:error] [pid 858085:tid 858314] [client 106.192.104.4:64977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QwDAtbv2vrjByhUpvOAAAAGI"]
[Mon Jul 20 06:12:48.695174 2026] [security2:error] [pid 843279:tid 843472] [client 114.119.156.209:38153] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hoomanr.com"] [uri "/robots.txt"] [unique_id "al4QwPqvKNcW5yy5T2C7XAAAAMM"], referer: http://www.hoomanr.com/robots.txt
[Mon Jul 20 06:12:48.792458 2026] [security2:error] [pid 858085:tid 858336] [client 57.141.18.8:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvDAtbv2vrjByhUpuWAAAeFQ"]
[Mon Jul 20 06:12:48.861425 2026] [security2:error] [pid 858085:tid 858155] [remote 20.173.88.122:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4QwDAtbv2vrjByhUpvRwAAbUQ"]
[Mon Jul 20 06:12:49.028791 2026] [security2:error] [pid 843279:tid 843445] [client 74.7.227.179:36704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7ZgAAqE0"], referer: https://tejasenvironmental.com/p=1271672
[Mon Jul 20 06:12:49.282851 2026] [security2:error] [pid 843279:tid 843520] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7YwAAAPI"]
[Mon Jul 20 06:12:49.471836 2026] [security2:error] [pid 843279:tid 843530] [client 57.141.18.60:62894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvPqvKNcW5yy5T2C7AgAA_BM"]
[Mon Jul 20 06:12:49.675353 2026] [security2:error] [pid 858085:tid 858225] [client 171.60.139.123:51328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvdgAAAAk"]
[Mon Jul 20 06:12:49.675510 2026] [security2:error] [pid 858085:tid 858225] [client 171.60.139.123:51328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvdgAAAAk"]
[Mon Jul 20 06:12:49.734416 2026] [security2:error] [pid 858085:tid 858329] [client 181.224.94.124:4273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvfQAAAHE"]
[Mon Jul 20 06:12:49.734589 2026] [security2:error] [pid 858085:tid 858329] [client 181.224.94.124:4273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QwTAtbv2vrjByhUpvfQAAAHE"]
[Mon Jul 20 06:12:49.794150 2026] [fcgid:warn] [pid 858085:tid 858254] (70014)End of file found: [client 93.174.93.12:60000] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:49.804070 2026] [security2:error] [pid 858085:tid 858149] [remote 72.167.132.114:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QwTAtbv2vrjByhUpvhAAAQz4"]
[Mon Jul 20 06:12:49.883814 2026] [security2:error] [pid 858085:tid 858233] [client 57.141.18.96:22840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvTAtbv2vrjByhUpumwAAEWk"]
[Mon Jul 20 06:12:49.989671 2026] [security2:error] [pid 858085:tid 858267] [client 50.116.65.227:33236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QwTAtbv2vrjByhUpvlAAAADM"]
[Mon Jul 20 06:12:50.001128 2026] [security2:error] [pid 858085:tid 858288] [client 50.116.65.227:51092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4QwTAtbv2vrjByhUpvlgAAAEg"]
[Mon Jul 20 06:12:50.137675 2026] [security2:error] [pid 858085:tid 858280] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwTAtbv2vrjByhUpvcwAAAEA"]
[Mon Jul 20 06:12:50.160545 2026] [security2:error] [pid 858085:tid 858174] [remote 72.167.132.114:46058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4QwjAtbv2vrjByhUpvowAAH1c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:12:50.169672 2026] [security2:error] [pid 858085:tid 858229] [client 27.96.94.195:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QwjAtbv2vrjByhUpvpAAAAA0"]
[Mon Jul 20 06:12:50.169822 2026] [security2:error] [pid 858085:tid 858229] [client 27.96.94.195:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QwjAtbv2vrjByhUpvpAAAAA0"]
[Mon Jul 20 06:12:50.472268 2026] [core:error] [pid 858085:tid 858319] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.472292 2026] [core:error] [pid 858085:tid 858319] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.472945 2026] [core:error] [pid 843279:tid 843434] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.472960 2026] [core:error] [pid 843279:tid 843434] [client 140.248.75.77:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:50.616302 2026] [security2:error] [pid 858085:tid 858305] [client 14.225.17.146:56377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvsQAAAFk"], referer: http://savilerowtravel.com/WORDPRESS
[Mon Jul 20 06:12:50.636635 2026] [security2:error] [pid 858085:tid 858323] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvrQAAa10"]
[Mon Jul 20 06:12:50.642161 2026] [security2:error] [pid 858085:tid 858323] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvrgAAa2c"]
[Mon Jul 20 06:12:50.731077 2026] [security2:error] [pid 858085:tid 858105] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.gitconfig"] [unique_id "al4QwjAtbv2vrjByhUpv0AAAOxI"]
[Mon Jul 20 06:12:50.731102 2026] [security2:error] [pid 858085:tid 858177] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/rclone.conf"] [unique_id "al4QwjAtbv2vrjByhUpv0QAAO1o"]
[Mon Jul 20 06:12:50.731273 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.gitconfig"] [unique_id "al4QwjAtbv2vrjByhUpv0AAAOxI"]
[Mon Jul 20 06:12:50.731339 2026] [security2:error] [pid 858085:tid 858191] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/.git/HEAD"] [unique_id "al4QwjAtbv2vrjByhUpv0gAAO2g"]
[Mon Jul 20 06:12:50.731611 2026] [security2:error] [pid 858085:tid 858199] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-json"] [unique_id "al4QwjAtbv2vrjByhUpv0wAAO3A"]
[Mon Jul 20 06:12:50.976603 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzQAAO28"]
[Mon Jul 20 06:12:50.999697 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpv1AAAOx4"]
[Mon Jul 20 06:12:51.000429 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzAAAOy8"]
[Mon Jul 20 06:12:51.014321 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzwAAOxw"]
[Mon Jul 20 06:12:51.022404 2026] [security2:error] [pid 858085:tid 858275] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvzgAAOyw"]
[Mon Jul 20 06:12:51.080513 2026] [security2:error] [pid 843279:tid 843518] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QwvqvKNcW5yy5T2C7lwAAAPA"]
[Mon Jul 20 06:12:51.129267 2026] [security2:error] [pid 858085:tid 858276] [client 185.132.186.57:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/install.php"] [unique_id "al4QwzAtbv2vrjByhUpv-wAAADw"]
[Mon Jul 20 06:12:51.211416 2026] [security2:error] [pid 858085:tid 858328] [client 57.141.18.80:43988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvzAtbv2vrjByhUpu8wAAcAg"]
[Mon Jul 20 06:12:51.369736 2026] [security2:error] [pid 858085:tid 858126] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.bak"] [unique_id "al4QwzAtbv2vrjByhUpwCgAAYic"]
[Mon Jul 20 06:12:51.369945 2026] [security2:error] [pid 858085:tid 858089] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.backup"] [unique_id "al4QwzAtbv2vrjByhUpwCQAAYgI"]
[Mon Jul 20 06:12:51.379803 2026] [security2:error] [pid 858085:tid 858219] [client 103.141.108.143:61432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwBwAAAAM"]
[Mon Jul 20 06:12:51.379946 2026] [security2:error] [pid 858085:tid 858219] [client 103.141.108.143:61432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwBwAAAAM"]
[Mon Jul 20 06:12:51.407411 2026] [security2:error] [pid 858085:tid 858279] [client 14.225.17.146:57324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwBgAAAD8"], referer: http://dasmarque.com/WORDPRESS
[Mon Jul 20 06:12:51.430245 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:56394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwBQAAAEk"], referer: http://cheesewithjam.com/WORDPRESS
[Mon Jul 20 06:12:51.450381 2026] [security2:error] [pid 843279:tid 843480] [client 57.141.18.22:62058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qv_qvKNcW5yy5T2C7NwAAy3A"]
[Mon Jul 20 06:12:51.452202 2026] [fcgid:warn] [pid 843279:tid 843476] (70014)End of file found: [client 66.132.172.109:38552] mod_fcgid: can't get data from http client
[Mon Jul 20 06:12:51.473860 2026] [security2:error] [pid 858085:tid 858163] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env"] [unique_id "al4QwzAtbv2vrjByhUpwEwAAYkw"]
[Mon Jul 20 06:12:51.549589 2026] [security2:error] [pid 858085:tid 858143] [remote 81.173.115.7:52748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QwzAtbv2vrjByhUpwGAAAVTg"]
[Mon Jul 20 06:12:51.577135 2026] [security2:error] [pid 858085:tid 858283] [client 64.225.75.246:55070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.uwannaempanada.com"] [uri "/.env"] [unique_id "al4QwzAtbv2vrjByhUpwGwAAAEM"]
[Mon Jul 20 06:12:51.621394 2026] [security2:error] [pid 858085:tid 858334] [client 14.225.17.146:65310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwFwAAAHY"], referer: http://intelligentengineeringsolutions.com/WORDPRESS
[Mon Jul 20 06:12:51.627631 2026] [security2:error] [pid 843279:tid 843534] [client 41.173.37.102:5761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qw_qvKNcW5yy5T2C7qQAAAQA"]
[Mon Jul 20 06:12:51.627813 2026] [security2:error] [pid 843279:tid 843534] [client 41.173.37.102:5761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Qw_qvKNcW5yy5T2C7qQAAAQA"]
[Mon Jul 20 06:12:51.643219 2026] [security2:error] [pid 858085:tid 858231] [client 57.141.18.78:39996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QvzAtbv2vrjByhUpvCAAADyM"]
[Mon Jul 20 06:12:51.662108 2026] [security2:error] [pid 858085:tid 858314] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwCAAAYnY"]
[Mon Jul 20 06:12:51.678746 2026] [security2:error] [pid 858085:tid 858292] [client 14.225.17.146:56452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwDwAAAEw"], referer: https://savilerowtravel.com/WORDPRESS
[Mon Jul 20 06:12:51.714155 2026] [security2:error] [pid 843279:tid 843512] [client 50.116.65.227:51124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Qw_qvKNcW5yy5T2C7qgAAAOo"]
[Mon Jul 20 06:12:51.725492 2026] [security2:error] [pid 843279:tid 843497] [client 50.116.65.227:51136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Qw_qvKNcW5yy5T2C7qwAAANw"]
[Mon Jul 20 06:12:51.742683 2026] [security2:error] [pid 858085:tid 858314] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwFgAAYng"]
[Mon Jul 20 06:12:51.755733 2026] [security2:error] [pid 858085:tid 858212] [remote 81.173.115.7:52748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4QwzAtbv2vrjByhUpwJQAANn0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:12:51.774847 2026] [security2:error] [pid 858085:tid 858314] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwFAAAYig"]
[Mon Jul 20 06:12:51.817920 2026] [security2:error] [pid 858085:tid 858142] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/backend/.env"] [unique_id "al4QwzAtbv2vrjByhUpwLAAAcTc"]
[Mon Jul 20 06:12:51.819251 2026] [security2:error] [pid 858085:tid 858099] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/api/.env"] [unique_id "al4QwzAtbv2vrjByhUpwLQAAcQw"]
[Mon Jul 20 06:12:51.822361 2026] [security2:error] [pid 858085:tid 858107] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwLgAAIxQ"]
[Mon Jul 20 06:12:51.822527 2026] [security2:error] [pid 858085:tid 858251] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QwzAtbv2vrjByhUpwLgAAIxQ"]
[Mon Jul 20 06:12:51.832243 2026] [security2:error] [pid 858085:tid 858111] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/config/.env"] [unique_id "al4QwzAtbv2vrjByhUpwMAAAcRg"]
[Mon Jul 20 06:12:51.844384 2026] [autoindex:error] [pid 843279:tid 843436] [client 151.243.11.245:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:12:52.038240 2026] [security2:error] [pid 858085:tid 858116] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.old"] [unique_id "al4QxDAtbv2vrjByhUpwPQAAcR0"]
[Mon Jul 20 06:12:52.080326 2026] [security2:error] [pid 858085:tid 858329] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwKwAAcRY"]
[Mon Jul 20 06:12:52.168411 2026] [security2:error] [pid 858085:tid 858343] [client 14.225.17.146:65375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpv3AAAAH8"], referer: http://effingweirdmuseums.com/WORDPRESS
[Mon Jul 20 06:12:52.250300 2026] [security2:error] [pid 858085:tid 858224] [client 50.116.65.227:51174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QxDAtbv2vrjByhUpwVAAAAAg"]
[Mon Jul 20 06:12:52.252494 2026] [security2:error] [pid 858085:tid 858118] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/graphql"] [unique_id "al4QxDAtbv2vrjByhUpwVQAAER8"]
[Mon Jul 20 06:12:52.261573 2026] [security2:error] [pid 858085:tid 858341] [client 50.116.65.227:51178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QxDAtbv2vrjByhUpwVgAAAH0"]
[Mon Jul 20 06:12:52.305929 2026] [security2:error] [pid 843279:tid 843471] [client 45.116.69.230:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QxPqvKNcW5yy5T2C7uQAAAMI"]
[Mon Jul 20 06:12:52.306112 2026] [security2:error] [pid 843279:tid 843471] [client 45.116.69.230:58008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QxPqvKNcW5yy5T2C7uQAAAMI"]
[Mon Jul 20 06:12:52.315551 2026] [security2:error] [pid 843279:tid 843440] [client 57.141.18.52:62650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwPqvKNcW5yy5T2C7UQAAo0k"]
[Mon Jul 20 06:12:52.366833 2026] [security2:error] [pid 858085:tid 858275] [client 57.141.18.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwTAAAADs"]
[Mon Jul 20 06:12:52.384700 2026] [security2:error] [pid 858085:tid 858246] [client 112.213.160.112:8461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwXgAAAB4"]
[Mon Jul 20 06:12:52.384836 2026] [security2:error] [pid 858085:tid 858246] [client 112.213.160.112:8461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwXgAAAB4"]
[Mon Jul 20 06:12:52.456893 2026] [security2:error] [pid 858085:tid 858233] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwTgAAES4"]
[Mon Jul 20 06:12:52.509655 2026] [security2:error] [pid 858085:tid 858098] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwZgAAZgs"]
[Mon Jul 20 06:12:52.509897 2026] [security2:error] [pid 858085:tid 858318] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwZgAAZgs"]
[Mon Jul 20 06:12:52.534211 2026] [security2:error] [pid 858085:tid 858280] [client 14.225.17.146:65518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpv8wAAAEA"], referer: http://slutilities.com/WORDPRESS
[Mon Jul 20 06:12:52.662166 2026] [security2:error] [pid 843279:tid 843485] [client 14.225.17.146:50771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4QxPqvKNcW5yy5T2C7ugAAANA"]
[Mon Jul 20 06:12:52.851594 2026] [security2:error] [pid 858085:tid 858184] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/api/graphql"] [unique_id "al4QxDAtbv2vrjByhUpwfQAAe2E"]
[Mon Jul 20 06:12:52.874221 2026] [security2:error] [pid 858085:tid 858273] [client 178.152.178.232:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwhAAAADk"]
[Mon Jul 20 06:12:52.874346 2026] [security2:error] [pid 858085:tid 858273] [client 178.152.178.232:37707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4QxDAtbv2vrjByhUpwhAAAADk"]
[Mon Jul 20 06:12:52.948422 2026] [security2:error] [pid 843279:tid 843323] [remote 72.167.132.114:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4QxPqvKNcW5yy5T2C7zgAA2Co"]
[Mon Jul 20 06:12:53.089398 2026] [security2:error] [pid 843279:tid 843473] [client 14.225.17.146:57381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C70gAAAMQ"], referer: http://claysharecon.com/WORDPRESS
[Mon Jul 20 06:12:53.095224 2026] [security2:error] [pid 843279:tid 843459] [client 14.225.17.146:57377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4QxPqvKNcW5yy5T2C70QAAALY"], referer: https://effingweirdmuseums.com/WORDPRESS
[Mon Jul 20 06:12:53.100819 2026] [security2:error] [pid 858085:tid 858154] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.htpasswd"] [unique_id "al4QxTAtbv2vrjByhUpwkwAAe0M"]
[Mon Jul 20 06:12:53.100826 2026] [security2:error] [pid 858085:tid 858173] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.npmrc"] [unique_id "al4QxTAtbv2vrjByhUpwlQAAe1Y"]
[Mon Jul 20 06:12:53.101079 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.htpasswd"] [unique_id "al4QxTAtbv2vrjByhUpwkwAAe0M"]
[Mon Jul 20 06:12:53.101108 2026] [security2:error] [pid 858085:tid 858154] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_ed25519"] [unique_id "al4QxTAtbv2vrjByhUpwmgAAe0M"]
[Mon Jul 20 06:12:53.101178 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.npmrc"] [unique_id "al4QxTAtbv2vrjByhUpwlQAAe1Y"]
[Mon Jul 20 06:12:53.103249 2026] [security2:error] [pid 858085:tid 858145] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_rsa"] [unique_id "al4QxTAtbv2vrjByhUpwmQAAezo"]
[Mon Jul 20 06:12:53.103468 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_ed25519"] [unique_id "al4QxTAtbv2vrjByhUpwmgAAe0M"]
[Mon Jul 20 06:12:53.112868 2026] [security2:error] [pid 843279:tid 843455] [client 185.132.186.71:40319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/adminfusm.php"] [unique_id "al4QxfqvKNcW5yy5T2C71gAAALI"]
[Mon Jul 20 06:12:53.120880 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwfAAAe0Q"]
[Mon Jul 20 06:12:53.123806 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwfgAAew4"]
[Mon Jul 20 06:12:53.130977 2026] [security2:error] [pid 858085:tid 858162] [remote 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwgAAAe0s"]
[Mon Jul 20 06:12:53.279829 2026] [security2:error] [pid 843279:tid 843341] [remote 72.167.132.114:56478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4QxfqvKNcW5yy5T2C73gAA_jw"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:12:53.381512 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwlgAAexM"]
[Mon Jul 20 06:12:53.391343 2026] [security2:error] [pid 858085:tid 858139] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/v1/graphql"] [unique_id "al4QxTAtbv2vrjByhUpwrwAAezQ"]
[Mon Jul 20 06:12:53.401663 2026] [security2:error] [pid 858085:tid 858164] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_dsa"] [unique_id "al4QxTAtbv2vrjByhUpwswAAe00"]
[Mon Jul 20 06:12:53.414284 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwmAAAe2Y"]
[Mon Jul 20 06:12:53.491301 2026] [security2:error] [pid 858085:tid 858254] [client 14.225.17.146:63658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwAQAAACY"], referer: http://itdynamix.com/WORDPRESS
[Mon Jul 20 06:12:53.493606 2026] [security2:error] [pid 858085:tid 858179] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/id_dsa"] [unique_id "al4QxTAtbv2vrjByhUpwtwAAe1w"]
[Mon Jul 20 06:12:53.494353 2026] [security2:error] [pid 858085:tid 858138] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/id_rsa"] [unique_id "al4QxTAtbv2vrjByhUpwvAAAezM"]
[Mon Jul 20 06:12:53.521302 2026] [security2:error] [pid 858085:tid 858340] [client 14.225.17.146:65265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwMwAAAHw"], referer: http://tntcatholic.com/WORDPRESS
[Mon Jul 20 06:12:53.689058 2026] [security2:error] [pid 858085:tid 858268] [client 57.141.18.28:32002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwTAtbv2vrjByhUpvaQAANDk"]
[Mon Jul 20 06:12:53.773626 2026] [security2:error] [pid 843279:tid 843450] [client 14.225.17.146:56448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C75gAAAK0"], referer: http://falconarrowshop.com/WORDPRESS
[Mon Jul 20 06:12:53.786902 2026] [security2:error] [pid 843279:tid 843444] [client 35.90.38.209:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxfqvKNcW5yy5T2C78gAAAKc"]
[Mon Jul 20 06:12:53.884870 2026] [security2:error] [pid 843279:tid 843364] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QxfqvKNcW5yy5T2C79AAAklM"]
[Mon Jul 20 06:12:53.885042 2026] [security2:error] [pid 843279:tid 843423] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4QxfqvKNcW5yy5T2C79AAAklM"]
[Mon Jul 20 06:12:54.099605 2026] [security2:error] [pid 858085:tid 858308] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwwwAAAFw"]
[Mon Jul 20 06:12:54.131023 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwsgAAe0I"]
[Mon Jul 20 06:12:54.139590 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwsAAAeyA"]
[Mon Jul 20 06:12:54.139898 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwsQAAe1E"]
[Mon Jul 20 06:12:54.192323 2026] [security2:error] [pid 843279:tid 843410] [client 103.145.233.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C7-QAAAIU"]
[Mon Jul 20 06:12:54.240557 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwuwAAe2o"]
[Mon Jul 20 06:12:54.248079 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwugAAe0E"]
[Mon Jul 20 06:12:54.262851 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwuAAAe14"]
[Mon Jul 20 06:12:54.275352 2026] [security2:error] [pid 858085:tid 858339] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxTAtbv2vrjByhUpwuQAAe2Q"]
[Mon Jul 20 06:12:54.299622 2026] [security2:error] [pid 858085:tid 858247] [client 35.90.38.209:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxjAtbv2vrjByhUpw4QAAAB8"]
[Mon Jul 20 06:12:54.334898 2026] [security2:error] [pid 858085:tid 858330] [client 57.141.18.21:31750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpvogAAclU"]
[Mon Jul 20 06:12:54.350857 2026] [security2:error] [pid 858085:tid 858208] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/privatekey.key"] [unique_id "al4QxjAtbv2vrjByhUpw5gAAWXk"]
[Mon Jul 20 06:12:54.410871 2026] [security2:error] [pid 843279:tid 843427] [client 104.234.53.88:22385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4QxvqvKNcW5yy5T2C8AwAAAJY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:12:54.443604 2026] [security2:error] [pid 858085:tid 858117] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/key.pem"] [unique_id "al4QxjAtbv2vrjByhUpw6wAAWR4"]
[Mon Jul 20 06:12:54.494421 2026] [security2:error] [pid 843279:tid 843440] [client 14.225.17.146:53861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4QxvqvKNcW5yy5T2C8AAAAAKM"], referer: https://itdynamix.com/WORDPRESS
[Mon Jul 20 06:12:54.549667 2026] [security2:error] [pid 858085:tid 858314] [client 14.225.17.146:58693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw2QAAAGI"], referer: http://mollycahill.com/WORDPRESS
[Mon Jul 20 06:12:54.603176 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw4wAAWSE"]
[Mon Jul 20 06:12:54.607637 2026] [security2:error] [pid 858085:tid 858232] [client 13.201.64.214:55280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QxjAtbv2vrjByhUpw9gAAABA"]
[Mon Jul 20 06:12:54.607826 2026] [security2:error] [pid 858085:tid 858232] [client 13.201.64.214:55280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4QxjAtbv2vrjByhUpw9gAAABA"]
[Mon Jul 20 06:12:54.699659 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw7AAAWW8"]
[Mon Jul 20 06:12:54.719703 2026] [security2:error] [pid 858085:tid 858095] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.openclaw/.env"] [unique_id "al4QxjAtbv2vrjByhUpxAAAAWQg"]
[Mon Jul 20 06:12:54.727539 2026] [security2:error] [pid 843279:tid 843455] [client 35.90.38.209:42084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxvqvKNcW5yy5T2C8DwAAALI"]
[Mon Jul 20 06:12:54.836799 2026] [security2:error] [pid 858085:tid 858264] [client 103.153.183.69:38758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4QxjAtbv2vrjByhUpxDAAAADA"], referer: https://www.bing.com/search?q=2wt9n6
[Mon Jul 20 06:12:54.859157 2026] [security2:error] [pid 858085:tid 858325] [client 54.244.177.189:20814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4QxjAtbv2vrjByhUpxDQAAAG0"]
[Mon Jul 20 06:12:54.908563 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw-QAAWXs"]
[Mon Jul 20 06:12:54.921051 2026] [security2:error] [pid 858085:tid 858166] [remote 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw-wAAWU8"]
[Mon Jul 20 06:12:54.948992 2026] [security2:error] [pid 858085:tid 858305] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw_wAAWXw"]
[Mon Jul 20 06:12:54.960246 2026] [security2:error] [pid 858085:tid 858206] [remote 57.141.18.45:47902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4031319"] [unique_id "al4QxjAtbv2vrjByhUpxEQAAGXc"]
[Mon Jul 20 06:12:55.127073 2026] [security2:error] [pid 843279:tid 843480] [client 185.132.186.56:63245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/adminfusm.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8GQAAAMs"]
[Mon Jul 20 06:12:55.171953 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.94:30266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwjAtbv2vrjByhUpv5QAACX8"]
[Mon Jul 20 06:12:55.530406 2026] [security2:error] [pid 858085:tid 858269] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxKwAANTc"]
[Mon Jul 20 06:12:55.651960 2026] [security2:error] [pid 858085:tid 858116] [remote 20.173.88.122:35896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4QxzAtbv2vrjByhUpxPgAALR0"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:12:55.710170 2026] [security2:error] [pid 843279:tid 843336] [remote 45.90.123.233:52382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8IgAAvzc"]
[Mon Jul 20 06:12:55.776759 2026] [security2:error] [pid 858085:tid 858109] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.hermes/.env"] [unique_id "al4QxzAtbv2vrjByhUpxRQAAThY"]
[Mon Jul 20 06:12:55.833079 2026] [security2:error] [pid 843279:tid 843521] [client 14.225.17.146:53891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8IQAAAPM"], referer: http://secretkeynumerology.com/WORDPRESS
[Mon Jul 20 06:12:55.887005 2026] [security2:error] [pid 858085:tid 858294] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxPQAATnI"]
[Mon Jul 20 06:12:55.902841 2026] [security2:error] [pid 843279:tid 843372] [remote 45.90.123.233:52382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Qx_qvKNcW5yy5T2C8KQAAwls"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:12:56.048625 2026] [security2:error] [pid 858085:tid 858294] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxRAAATmw"]
[Mon Jul 20 06:12:56.071953 2026] [security2:error] [pid 843279:tid 843492] [client 14.225.17.146:65260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4QxvqvKNcW5yy5T2C7_gAAANc"], referer: http://aandarealtygroup.com/WORDPRESS
[Mon Jul 20 06:12:56.160987 2026] [security2:error] [pid 858085:tid 858325] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxPwAAAG0"]
[Mon Jul 20 06:12:56.278978 2026] [security2:error] [pid 858085:tid 858297] [client 57.141.18.81:47110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QwzAtbv2vrjByhUpwLwAAUVA"]
[Mon Jul 20 06:12:56.410048 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.56:60848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qw_qvKNcW5yy5T2C7sAAAlG8"]
[Mon Jul 20 06:12:56.556603 2026] [security2:error] [pid 858085:tid 858184] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.bash_profile"] [unique_id "al4QyDAtbv2vrjByhUpxeAAAHmE"]
[Mon Jul 20 06:12:56.556818 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.bash_profile"] [unique_id "al4QyDAtbv2vrjByhUpxeAAAHmE"]
[Mon Jul 20 06:12:56.557975 2026] [security2:error] [pid 858085:tid 858150] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.mcp.json"] [unique_id "al4QyDAtbv2vrjByhUpxfAAAHj8"]
[Mon Jul 20 06:12:56.558137 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.mcp.json"] [unique_id "al4QyDAtbv2vrjByhUpxfAAAHj8"]
[Mon Jul 20 06:12:56.611862 2026] [core:error] [pid 858085:tid 858223] [client 151.243.11.245:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:56.611894 2026] [core:error] [pid 858085:tid 858223] [client 151.243.11.245:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:12:56.639591 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxbgAAHgc"]
[Mon Jul 20 06:12:56.736686 2026] [security2:error] [pid 858085:tid 858248] [client 57.141.18.56:60858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxDAtbv2vrjByhUpwWAAAIAk"]
[Mon Jul 20 06:12:56.751880 2026] [security2:error] [pid 858085:tid 858209] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mtredistricting.gov"] [uri "/wp-config.php.old"] [unique_id "al4QyDAtbv2vrjByhUpxiQAAHno"]
[Mon Jul 20 06:12:56.826812 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxewAAHkg"]
[Mon Jul 20 06:12:56.862898 2026] [security2:error] [pid 858085:tid 858247] [client 14.225.17.146:54893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxhgAAAB8"], referer: https://secretkeynumerology.com/WORDPRESS
[Mon Jul 20 06:12:56.934372 2026] [security2:error] [pid 858085:tid 858246] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxhQAAHhE"]
[Mon Jul 20 06:12:57.084610 2026] [security2:error] [pid 843279:tid 843399] [remote 162.19.86.63:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4QyfqvKNcW5yy5T2C8VAAArHY"]
[Mon Jul 20 06:12:57.138329 2026] [security2:error] [pid 858085:tid 858269] [client 185.132.186.60:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/js1.php"] [unique_id "al4QyTAtbv2vrjByhUpxlgAAADU"]
[Mon Jul 20 06:12:57.159657 2026] [security2:error] [pid 858085:tid 858162] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.env.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxlwAAR0s"]
[Mon Jul 20 06:12:57.166760 2026] [security2:error] [pid 858085:tid 858123] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/core/.env"] [unique_id "al4QyTAtbv2vrjByhUpxmQAAJCQ"]
[Mon Jul 20 06:12:57.179978 2026] [security2:error] [pid 858085:tid 858147] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/config.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxmAAAJDw"]
[Mon Jul 20 06:12:57.276289 2026] [security2:error] [pid 858085:tid 858139] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/config/.env.php"] [unique_id "al4QyTAtbv2vrjByhUpxnwAATDQ"]
[Mon Jul 20 06:12:57.276343 2026] [security2:error] [pid 858085:tid 858164] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/configuration.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxoAAATE0"]
[Mon Jul 20 06:12:57.277465 2026] [security2:error] [pid 858085:tid 858189] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/laravel/.env"] [unique_id "al4QyTAtbv2vrjByhUpxowAATGY"]
[Mon Jul 20 06:12:57.293985 2026] [security2:error] [pid 843279:tid 843375] [remote 162.19.86.63:34566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4QyfqvKNcW5yy5T2C8WQAAv14"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:12:57.501583 2026] [security2:error] [pid 858085:tid 858144] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mtredistricting.gov"] [uri "/wp-config.php.bak"] [unique_id "al4QyTAtbv2vrjByhUpxtgAATDk"]
[Mon Jul 20 06:12:57.524391 2026] [security2:error] [pid 858085:tid 858292] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxogAATBM"]
[Mon Jul 20 06:12:57.640351 2026] [security2:error] [pid 858085:tid 858190] [remote 72.167.132.114:35802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QyTAtbv2vrjByhUpxvgAAemc"]
[Mon Jul 20 06:12:57.661764 2026] [proxy:error] [pid 858085:tid 858273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:57.661862 2026] [proxy_http:error] [pid 858085:tid 858273] [client 205.210.31.154:63998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:57.662882 2026] [proxy:error] [pid 858085:tid 858273] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:12:57.662926 2026] [proxy_http:error] [pid 858085:tid 858273] [client 205.210.31.154:63998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:12:57.693270 2026] [security2:error] [pid 858085:tid 858288] [client 103.77.203.233:53200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QyTAtbv2vrjByhUpxwwAAAEg"]
[Mon Jul 20 06:12:57.693469 2026] [security2:error] [pid 858085:tid 858288] [client 103.77.203.233:53200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4QyTAtbv2vrjByhUpxwwAAAEg"]
[Mon Jul 20 06:12:57.751031 2026] [security2:error] [pid 858085:tid 858292] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxtQAATF8"]
[Mon Jul 20 06:12:57.864147 2026] [security2:error] [pid 858085:tid 858319] [client 104.155.181.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxvwAAAGc"]
[Mon Jul 20 06:12:57.961571 2026] [security2:error] [pid 858085:tid 858168] [remote 72.167.132.114:35802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4QyTAtbv2vrjByhUpxzgAAdFE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:12:57.970774 2026] [security2:error] [pid 858085:tid 858152] [remote 114.119.145.212:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "flowmetersupply.com"] [uri "/robots.txt"] [unique_id "al4QyTAtbv2vrjByhUpx0gAAXkE"], referer: https://flowmetersupply.com/robots.txt
[Mon Jul 20 06:12:57.998830 2026] [security2:error] [pid 843279:tid 843513] [client 57.141.18.26:29636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C76AAA6yA"]
[Mon Jul 20 06:12:58.178964 2026] [security2:error] [pid 858085:tid 858108] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/web/.env"] [unique_id "al4QyjAtbv2vrjByhUpx5AAAfRU"]
[Mon Jul 20 06:12:58.179210 2026] [security2:error] [pid 858085:tid 858341] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/web/.env"] [unique_id "al4QyjAtbv2vrjByhUpx5AAAfRU"]
[Mon Jul 20 06:12:58.203632 2026] [security2:error] [pid 858085:tid 858203] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.swp"] [unique_id "al4QyjAtbv2vrjByhUpx5QAALHQ"]
[Mon Jul 20 06:12:58.204212 2026] [security2:error] [pid 858085:tid 858131] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/public/.env"] [unique_id "al4QyjAtbv2vrjByhUpx6AAALCw"]
[Mon Jul 20 06:12:58.219152 2026] [security2:error] [pid 858085:tid 858303] [client 50.116.65.227:33248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4QyjAtbv2vrjByhUpx6gAAAFc"]
[Mon Jul 20 06:12:58.230143 2026] [security2:error] [pid 843279:tid 843514] [client 50.116.65.227:51232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4QyvqvKNcW5yy5T2C8cQAAAJQ"]
[Mon Jul 20 06:12:58.308505 2026] [security2:error] [pid 858085:tid 858120] [remote 20.153.140.50:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4QyjAtbv2vrjByhUpx6wAAASE"]
[Mon Jul 20 06:12:58.384173 2026] [security2:error] [pid 843279:tid 843530] [client 57.141.18.60:22996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxfqvKNcW5yy5T2C79QAA_AU"]
[Mon Jul 20 06:12:58.554612 2026] [security2:error] [pid 858085:tid 858299] [client 64.225.75.246:53020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxygAAAFM"]
[Mon Jul 20 06:12:58.668028 2026] [security2:error] [pid 858085:tid 858319] [client 103.153.183.69:38758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4QyjAtbv2vrjByhUpyBAAAAGc"], referer: https://t.co/ng3pmp36x4
[Mon Jul 20 06:12:58.734587 2026] [security2:error] [pid 858085:tid 858089] [remote 20.153.140.50:36144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4QyjAtbv2vrjByhUpyBwAAUAI"], referer: https://pscmedicalbilling.com/wp-login.php
[Mon Jul 20 06:12:58.861979 2026] [security2:error] [pid 858085:tid 858266] [client 57.141.18.30:55530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxjAtbv2vrjByhUpw5wAAMmA"]
[Mon Jul 20 06:12:58.865586 2026] [security2:error] [pid 843279:tid 843501] [client 74.7.228.25:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4QyvqvKNcW5yy5T2C8gQAAAOA"]
[Mon Jul 20 06:12:58.876359 2026] [security2:error] [pid 858085:tid 858295] [client 74.7.228.25:52850] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/robots.txt"] [unique_id "al4QyjAtbv2vrjByhUpyCwAAT08"]
[Mon Jul 20 06:12:59.080079 2026] [security2:error] [pid 858085:tid 858218] [client 106.192.104.4:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QyzAtbv2vrjByhUpyLAAAAAI"]
[Mon Jul 20 06:12:59.080234 2026] [security2:error] [pid 858085:tid 858218] [client 106.192.104.4:65461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4QyzAtbv2vrjByhUpyLAAAAAI"]
[Mon Jul 20 06:12:59.111918 2026] [security2:error] [pid 843279:tid 843476] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4QyvqvKNcW5yy5T2C8igAAAMc"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:12:59.113508 2026] [security2:error] [pid 858085:tid 858255] [client 185.132.186.99:20761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/wp-includes/assets/script-loader-packages.min.php"] [unique_id "al4QyzAtbv2vrjByhUpyLgAAACc"]
[Mon Jul 20 06:12:59.124487 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyFwAAHEw"]
[Mon Jul 20 06:12:59.175495 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyGgAAHAo"]
[Mon Jul 20 06:12:59.230987 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyIAAAHCg"]
[Mon Jul 20 06:12:59.249109 2026] [security2:error] [pid 843279:tid 843511] [client 45.157.112.60:41909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Qy_qvKNcW5yy5T2C8kwAAAOk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:12:59.296895 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyKQAAHBQ"]
[Mon Jul 20 06:12:59.300743 2026] [security2:error] [pid 858085:tid 858121] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/env.js"] [unique_id "al4QyzAtbv2vrjByhUpyNQAAHCI"]
[Mon Jul 20 06:12:59.394150 2026] [security2:error] [pid 858085:tid 858259] [client 64.225.75.246:53030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyEgAAACs"]
[Mon Jul 20 06:12:59.446765 2026] [security2:error] [pid 858085:tid 858246] [client 14.225.17.146:65318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxzwAAAB4"], referer: http://dereckcastellon.com/WORDPRESS
[Mon Jul 20 06:12:59.451998 2026] [security2:error] [pid 858085:tid 858244] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyMAAAHA0"]
[Mon Jul 20 06:12:59.577988 2026] [security2:error] [pid 858085:tid 858128] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/api/v2/settings"] [unique_id "al4QyzAtbv2vrjByhUpyRAAAJCk"]
[Mon Jul 20 06:12:59.578205 2026] [security2:error] [pid 858085:tid 858252] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/api/v2/settings"] [unique_id "al4QyzAtbv2vrjByhUpyRAAAJCk"]
[Mon Jul 20 06:12:59.688556 2026] [security2:error] [pid 858085:tid 858135] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/manifest.webmanifest"] [unique_id "al4QyzAtbv2vrjByhUpyTAAAZDA"]
[Mon Jul 20 06:12:59.688821 2026] [security2:error] [pid 858085:tid 858316] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/manifest.webmanifest"] [unique_id "al4QyzAtbv2vrjByhUpyTAAAZDA"]
[Mon Jul 20 06:12:59.707436 2026] [security2:error] [pid 858085:tid 858197] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/api/v1/config"] [unique_id "al4QyzAtbv2vrjByhUpyUAAAZG4"]
[Mon Jul 20 06:12:59.707688 2026] [security2:error] [pid 858085:tid 858316] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/api/v1/config"] [unique_id "al4QyzAtbv2vrjByhUpyUAAAZG4"]
[Mon Jul 20 06:12:59.756454 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.116:37820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QxzAtbv2vrjByhUpxJQAAFHg"]
[Mon Jul 20 06:12:59.879286 2026] [security2:error] [pid 858085:tid 858184] [remote 89.42.136.2:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QyzAtbv2vrjByhUpyWQAAAGE"]
[Mon Jul 20 06:12:59.919974 2026] [security2:error] [pid 858085:tid 858333] [client 14.225.17.146:56348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4QyjAtbv2vrjByhUpyHQAAAHU"], referer: http://walkingandtalking.net/WORDPRESS
[Mon Jul 20 06:12:59.921972 2026] [security2:error] [pid 858085:tid 858316] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyTQAAZCs"]
[Mon Jul 20 06:13:00.077902 2026] [security2:error] [pid 858085:tid 858343] [client 64.225.75.246:53016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxgQAAAH8"]
[Mon Jul 20 06:13:00.141672 2026] [security2:error] [pid 858085:tid 858306] [client 171.60.139.123:51975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpybwAAAFo"]
[Mon Jul 20 06:13:00.141834 2026] [security2:error] [pid 858085:tid 858306] [client 171.60.139.123:51975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpybwAAAFo"]
[Mon Jul 20 06:13:00.219323 2026] [security2:error] [pid 858085:tid 858094] [remote 89.42.136.2:52422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4QzDAtbv2vrjByhUpycQAAOQc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:13:00.237887 2026] [security2:error] [pid 858085:tid 858337] [client 181.224.94.124:3868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpydAAAAHk"]
[Mon Jul 20 06:13:00.238004 2026] [security2:error] [pid 858085:tid 858337] [client 181.224.94.124:3868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4QzDAtbv2vrjByhUpydAAAAHk"]
[Mon Jul 20 06:13:00.320026 2026] [security2:error] [pid 858085:tid 858279] [client 64.225.75.246:53042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpySwAAAD8"]
[Mon Jul 20 06:13:00.577566 2026] [security2:error] [pid 858085:tid 858293] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyegAATUM"]
[Mon Jul 20 06:13:00.578509 2026] [security2:error] [pid 858085:tid 858293] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpydwAATRE"]
[Mon Jul 20 06:13:00.595686 2026] [security2:error] [pid 858085:tid 858139] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/health"] [unique_id "al4QzDAtbv2vrjByhUpyiAAATTQ"]
[Mon Jul 20 06:13:00.742959 2026] [security2:error] [pid 858085:tid 858309] [client 57.141.18.11:31554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyDAtbv2vrjByhUpxZgAAXS4"]
[Mon Jul 20 06:13:00.793117 2026] [security2:error] [pid 858085:tid 858293] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpygwAATTw"]
[Mon Jul 20 06:13:00.869839 2026] [security2:error] [pid 858085:tid 858238] [client 66.249.64.104:37182] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "jeffjaegerlaw.com"] [uri "/robots.txt"] [unique_id "al4QzDAtbv2vrjByhUpymQAAABY"]
[Mon Jul 20 06:13:00.990858 2026] [security2:error] [pid 843279:tid 843420] [client 14.225.17.146:56186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4QzPqvKNcW5yy5T2C8wQAAAI8"], referer: https://walkingandtalking.net/WORDPRESS
[Mon Jul 20 06:13:01.041502 2026] [security2:error] [pid 858085:tid 858254] [client 185.132.186.66:30815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/blocks/file/wp-style.php"] [unique_id "al4QzTAtbv2vrjByhUpypQAAACY"]
[Mon Jul 20 06:13:01.184428 2026] [security2:error] [pid 858085:tid 858342] [client 64.225.75.246:53054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyiwAAAH4"]
[Mon Jul 20 06:13:01.266013 2026] [security2:error] [pid 858085:tid 858194] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/actuator"] [unique_id "al4QzTAtbv2vrjByhUpyuwAAAWs"]
[Mon Jul 20 06:13:01.334839 2026] [security2:error] [pid 843279:tid 843428] [client 50.116.65.227:11266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4QzfqvKNcW5yy5T2C8zQAAAJc"]
[Mon Jul 20 06:13:01.346901 2026] [security2:error] [pid 843279:tid 843484] [client 50.116.65.227:11276] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4QzfqvKNcW5yy5T2C8zgAAAM8"]
[Mon Jul 20 06:13:01.378642 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyrQAAAVc"]
[Mon Jul 20 06:13:01.388791 2026] [security2:error] [pid 843279:tid 843518] [client 27.96.94.195:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QzfqvKNcW5yy5T2C8zwAAAPA"]
[Mon Jul 20 06:13:01.389415 2026] [security2:error] [pid 843279:tid 843518] [client 27.96.94.195:37058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4QzfqvKNcW5yy5T2C8zwAAAPA"]
[Mon Jul 20 06:13:01.398962 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyqwAAARM"]
[Mon Jul 20 06:13:01.483773 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyuAAAAWk"]
[Mon Jul 20 06:13:01.511076 2026] [security2:error] [pid 858085:tid 858217] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyugAAAV8"]
[Mon Jul 20 06:13:01.690519 2026] [security2:error] [pid 858085:tid 858235] [client 57.141.18.62:25226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxngAAE1k"]
[Mon Jul 20 06:13:01.764788 2026] [security2:error] [pid 858085:tid 858308] [client 14.225.17.146:58054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyjAAAAFw"], referer: http://ncsynchro.com/WORDPRESS
[Mon Jul 20 06:13:02.012920 2026] [security2:error] [pid 858085:tid 858325] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpyxQAAAG0"]
[Mon Jul 20 06:13:02.081828 2026] [security2:error] [pid 858085:tid 858193] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/phpinfo.php"] [unique_id "al4QzjAtbv2vrjByhUpy5QAAK2o"]
[Mon Jul 20 06:13:02.081986 2026] [security2:error] [pid 858085:tid 858259] [client 34.179.180.209:40604] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/phpinfo.php"] [unique_id "al4QzjAtbv2vrjByhUpy5QAAK2o"]
[Mon Jul 20 06:13:02.113852 2026] [security2:error] [pid 858085:tid 858259] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzTAtbv2vrjByhUpy3gAAKx4"]
[Mon Jul 20 06:13:02.114503 2026] [security2:error] [pid 858085:tid 858298] [client 103.141.108.143:61906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy5wAAAFI"]
[Mon Jul 20 06:13:02.115027 2026] [security2:error] [pid 858085:tid 858298] [client 103.141.108.143:61906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy5wAAAFI"]
[Mon Jul 20 06:13:02.161249 2026] [security2:error] [pid 858085:tid 858198] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/actuator/mappings"] [unique_id "al4QzjAtbv2vrjByhUpy7AAABm8"]
[Mon Jul 20 06:13:02.161430 2026] [security2:error] [pid 858085:tid 858120] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/info.php"] [unique_id "al4QzjAtbv2vrjByhUpy6wAABiE"]
[Mon Jul 20 06:13:02.161505 2026] [security2:error] [pid 858085:tid 858136] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/pi.php"] [unique_id "al4QzjAtbv2vrjByhUpy6gAABjE"]
[Mon Jul 20 06:13:02.176106 2026] [security2:error] [pid 858085:tid 858299] [client 41.173.37.102:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy7QAAAFM"]
[Mon Jul 20 06:13:02.176197 2026] [security2:error] [pid 858085:tid 858299] [client 41.173.37.102:6257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpy7QAAAFM"]
[Mon Jul 20 06:13:02.216236 2026] [security2:error] [pid 858085:tid 858265] [client 57.141.18.56:56482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyTAtbv2vrjByhUpxxgAAMU4"]
[Mon Jul 20 06:13:02.351470 2026] [security2:error] [pid 858085:tid 858126] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/test.php"] [unique_id "al4QzjAtbv2vrjByhUpy-QAAdCc"]
[Mon Jul 20 06:13:02.364975 2026] [security2:error] [pid 858085:tid 858134] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/i.php"] [unique_id "al4QzjAtbv2vrjByhUpy_AAAdC8"]
[Mon Jul 20 06:13:02.461517 2026] [security2:error] [pid 858085:tid 858206] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/app_dev.php"] [unique_id "al4QzjAtbv2vrjByhUpzAQAAdHc"]
[Mon Jul 20 06:13:02.461561 2026] [security2:error] [pid 858085:tid 858202] [remote 34.179.180.209:40604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.180.179.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/app_dev.php/_profiler"] [unique_id "al4QzjAtbv2vrjByhUpzAgAAdHM"]
[Mon Jul 20 06:13:02.579201 2026] [security2:error] [pid 858085:tid 858332] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzjAtbv2vrjByhUpy-gAAdAI"]
[Mon Jul 20 06:13:02.582408 2026] [security2:error] [pid 858085:tid 858332] [client 34.179.180.209:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4QzjAtbv2vrjByhUpy-AAAdAg"]
[Mon Jul 20 06:13:02.876583 2026] [security2:error] [pid 858085:tid 858163] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpzGwAALEw"]
[Mon Jul 20 06:13:02.876767 2026] [security2:error] [pid 858085:tid 858260] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzjAtbv2vrjByhUpzGwAALEw"]
[Mon Jul 20 06:13:03.016902 2026] [security2:error] [pid 858085:tid 858310] [client 185.132.186.78:64727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/mu-plugins/admin.php"] [unique_id "al4QzzAtbv2vrjByhUpzHgAAAF4"]
[Mon Jul 20 06:13:03.038536 2026] [security2:error] [pid 858085:tid 858097] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIAAAEAo"]
[Mon Jul 20 06:13:03.038740 2026] [security2:error] [pid 858085:tid 858232] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIAAAEAo"]
[Mon Jul 20 06:13:03.080227 2026] [security2:error] [pid 858085:tid 858274] [client 45.116.69.230:58680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIgAAADo"]
[Mon Jul 20 06:13:03.080407 2026] [security2:error] [pid 858085:tid 858274] [client 45.116.69.230:58680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzIgAAADo"]
[Mon Jul 20 06:13:03.123563 2026] [security2:error] [pid 858085:tid 858272] [client 112.213.160.112:31030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzJAAAADg"]
[Mon Jul 20 06:13:03.123715 2026] [security2:error] [pid 858085:tid 858272] [client 112.213.160.112:31030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4QzzAtbv2vrjByhUpzJAAAADg"]
[Mon Jul 20 06:13:03.317560 2026] [proxy:error] [pid 858085:tid 858224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:13:03.317638 2026] [proxy_http:error] [pid 858085:tid 858224] [client 205.210.31.168:63658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:13:03.318062 2026] [proxy:error] [pid 858085:tid 858224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:13:03.318102 2026] [proxy_http:error] [pid 858085:tid 858224] [client 205.210.31.168:63658] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:13:03.691916 2026] [security2:error] [pid 843279:tid 843469] [client 178.152.178.232:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9GwAAAMA"]
[Mon Jul 20 06:13:03.692042 2026] [security2:error] [pid 843279:tid 843469] [client 178.152.178.232:36813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9GwAAAMA"]
[Mon Jul 20 06:13:03.710568 2026] [security2:error] [pid 858085:tid 858321] [client 14.225.17.146:57088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4QzzAtbv2vrjByhUpzQgAAAGk"], referer: http://mtlegnews.gov/WORDPRESS
[Mon Jul 20 06:13:03.998035 2026] [security2:error] [pid 858085:tid 858276] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4QzzAtbv2vrjByhUpzOgAAADw"]
[Mon Jul 20 06:13:04.107409 2026] [security2:error] [pid 843279:tid 843535] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9FgABATM"], referer: http://ali-alghanim.net/WORDPRESS
[Mon Jul 20 06:13:04.283139 2026] [security2:error] [pid 858085:tid 858312] [client 57.141.18.58:45276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QyzAtbv2vrjByhUpyRgAAYC0"]
[Mon Jul 20 06:13:04.460888 2026] [security2:error] [pid 858085:tid 858245] [client 64.23.150.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.nyradigitalsolutions.com"] [uri "/index.php"] [unique_id "al4Q0DAtbv2vrjByhUpzcgAAAB0"], referer: https://mail.nyradigitalsolutions.com/
[Mon Jul 20 06:13:04.473062 2026] [security2:error] [pid 858085:tid 858094] [remote 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0DAtbv2vrjByhUpzdQAATQc"]
[Mon Jul 20 06:13:04.473309 2026] [security2:error] [pid 858085:tid 858293] [client 2804:3b04:a02b:c100:d023:583d:e0ab:c768:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0DAtbv2vrjByhUpzdQAATQc"]
[Mon Jul 20 06:13:04.503875 2026] [security2:error] [pid 858085:tid 858265] [client 64.225.75.246:53082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.75.225.64.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.uwannaempanada.com"] [uri "/info.php"] [unique_id "al4Q0DAtbv2vrjByhUpzeAAAADE"]
[Mon Jul 20 06:13:04.608071 2026] [security2:error] [pid 843279:tid 843412] [client 57.141.18.58:45284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qy_qvKNcW5yy5T2C8pgAAhyU"]
[Mon Jul 20 06:13:04.750033 2026] [security2:error] [pid 858085:tid 858146] [remote 182.77.62.24:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q0DAtbv2vrjByhUpziAAAGTs"]
[Mon Jul 20 06:13:04.763691 2026] [security2:error] [pid 858085:tid 858155] [remote 115.74.105.156:41726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q0DAtbv2vrjByhUpzigAAYUQ"]
[Mon Jul 20 06:13:04.799525 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.60:34964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpybAAAd0o"]
[Mon Jul 20 06:13:04.871415 2026] [security2:error] [pid 858085:tid 858298] [client 50.116.65.227:37900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q0DAtbv2vrjByhUpzlQAAAFI"]
[Mon Jul 20 06:13:04.881672 2026] [security2:error] [pid 858085:tid 858302] [client 50.116.65.227:11310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q0DAtbv2vrjByhUpzlgAAAEY"]
[Mon Jul 20 06:13:04.988509 2026] [security2:error] [pid 858085:tid 858227] [client 185.132.186.88:45747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/class-IXR-cilent.php"] [unique_id "al4Q0DAtbv2vrjByhUpzmQAAAAs"]
[Mon Jul 20 06:13:05.033826 2026] [security2:error] [pid 843279:tid 843536] [client 57.141.18.19:40632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzPqvKNcW5yy5T2C8tAABAm4"]
[Mon Jul 20 06:13:05.125573 2026] [security2:error] [pid 858085:tid 858282] [client 14.225.17.146:57128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4QzjAtbv2vrjByhUpzCAAAAEI"], referer: http://healthylifegourmet.org/WORDPRESS
[Mon Jul 20 06:13:05.182277 2026] [security2:error] [pid 858085:tid 858133] [remote 115.74.105.156:41726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q0TAtbv2vrjByhUpzpwAALC4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:13:05.310960 2026] [security2:error] [pid 858085:tid 858151] [remote 182.77.62.24:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q0TAtbv2vrjByhUpzrAAAMUA"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:13:05.383620 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.53:64364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzDAtbv2vrjByhUpyjgAAFE0"]
[Mon Jul 20 06:13:05.708056 2026] [security2:error] [pid 858085:tid 858258] [client 43.205.139.3:46142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0TAtbv2vrjByhUpzyAAAACo"]
[Mon Jul 20 06:13:05.708220 2026] [security2:error] [pid 858085:tid 858258] [client 43.205.139.3:46142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q0TAtbv2vrjByhUpzyAAAACo"]
[Mon Jul 20 06:13:06.064402 2026] [security2:error] [pid 843279:tid 843520] [client 57.141.18.115:35408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzfqvKNcW5yy5T2C8zAAA8k0"]
[Mon Jul 20 06:13:06.215651 2026] [security2:error] [pid 858085:tid 858297] [client 14.225.17.146:56299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz2gAAAFE"], referer: http://myspineworld.com/WORDPRESS
[Mon Jul 20 06:13:06.485338 2026] [security2:error] [pid 858085:tid 858252] [client 17.241.219.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mezzacraft.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz5gAAACQ"]
[Mon Jul 20 06:13:06.529892 2026] [security2:error] [pid 843279:tid 843489] [client 57.141.18.49:50210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzfqvKNcW5yy5T2C83QAA1Bs"]
[Mon Jul 20 06:13:06.662223 2026] [security2:error] [pid 858085:tid 858286] [client 50.116.65.227:37912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q0jAtbv2vrjByhUpz_QAAAEY"]
[Mon Jul 20 06:13:06.677010 2026] [security2:error] [pid 858085:tid 858275] [client 50.116.65.227:11332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q0jAtbv2vrjByhUpz_gAAADs"]
[Mon Jul 20 06:13:06.763454 2026] [security2:error] [pid 843279:tid 843446] [client 57.141.18.85:34110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4QzvqvKNcW5yy5T2C85gAAqVw"]
[Mon Jul 20 06:13:06.779156 2026] [security2:error] [pid 858085:tid 858326] [client 14.225.17.146:58031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Q0TAtbv2vrjByhUpzoQAAAG4"], referer: http://lelandumc.org/WORDPRESS
[Mon Jul 20 06:13:06.939393 2026] [security2:error] [pid 858085:tid 858302] [client 17.241.227.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUp0AwAAAFY"]
[Mon Jul 20 06:13:06.960801 2026] [security2:error] [pid 858085:tid 858255] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz9gAAACc"]
[Mon Jul 20 06:13:07.229479 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:58040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0GAAAABM"], referer: https://myspineworld.com/WORDPRESS
[Mon Jul 20 06:13:07.859420 2026] [security2:error] [pid 858085:tid 858238] [client 158.173.89.95:53653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q0zAtbv2vrjByhUp0QgAAABY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:07.945480 2026] [security2:error] [pid 858085:tid 858330] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0LQAAAHI"]
[Mon Jul 20 06:13:08.052702 2026] [security2:error] [pid 843279:tid 843472] [client 57.141.18.82:25394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Qz_qvKNcW5yy5T2C9GQAAwxU"]
[Mon Jul 20 06:13:08.079075 2026] [security2:error] [pid 858085:tid 858204] [remote 194.164.192.228:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q1DAtbv2vrjByhUp0TAAAfHU"]
[Mon Jul 20 06:13:08.165849 2026] [security2:error] [pid 858085:tid 858269] [client 14.225.17.146:56258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4Q0TAtbv2vrjByhUpz1gAAADU"], referer: http://latiendadejorge.com.gt/WORDPRESS
[Mon Jul 20 06:13:08.187146 2026] [security2:error] [pid 843279:tid 843436] [client 50.116.65.227:37918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q1PqvKNcW5yy5T2C9ewAAAJ8"]
[Mon Jul 20 06:13:08.197162 2026] [security2:error] [pid 843279:tid 843498] [client 50.116.65.227:11348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Q1PqvKNcW5yy5T2C9fQAAAOs"]
[Mon Jul 20 06:13:08.215679 2026] [security2:error] [pid 858085:tid 858266] [client 13.201.64.214:32380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Q1DAtbv2vrjByhUp0UwAAADI"]
[Mon Jul 20 06:13:08.254935 2026] [security2:error] [pid 843279:tid 843470] [client 158.173.166.181:22245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9fwAAAME"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:08.316930 2026] [security2:error] [pid 858085:tid 858294] [client 103.77.203.233:53737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1DAtbv2vrjByhUp0VwAAAE4"]
[Mon Jul 20 06:13:08.317138 2026] [security2:error] [pid 858085:tid 858294] [client 103.77.203.233:53737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1DAtbv2vrjByhUp0VwAAAE4"]
[Mon Jul 20 06:13:08.356806 2026] [security2:error] [pid 858085:tid 858231] [client 14.225.17.146:57924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0IAAAAA8"]
[Mon Jul 20 06:13:08.508172 2026] [security2:error] [pid 858085:tid 858116] [remote 194.164.192.228:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Q1DAtbv2vrjByhUp0XQAABh0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:13:08.736465 2026] [security2:error] [pid 858085:tid 858201] [remote 111.225.149.135:23670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2021/10/dac-commments-predeadline-july-2021.pdf"] [unique_id "al4Q1DAtbv2vrjByhUp0aQAAKnI"]
[Mon Jul 20 06:13:08.868428 2026] [security2:error] [pid 843279:tid 843528] [client 104.234.53.85:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9kwAAAPo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:09.004507 2026] [security2:error] [pid 843279:tid 843502] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9hwAAAOE"]
[Mon Jul 20 06:13:09.067726 2026] [security2:error] [pid 858085:tid 858289] [client 185.132.186.80:38953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/about/function.php%20"] [unique_id "al4Q1TAtbv2vrjByhUp0dgAAAEk"]
[Mon Jul 20 06:13:09.141770 2026] [security2:error] [pid 858085:tid 858276] [client 13.201.64.214:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Q1TAtbv2vrjByhUp0egAAADw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:13:09.274148 2026] [security2:error] [pid 858085:tid 858337] [client 14.225.17.146:58103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4Q0zAtbv2vrjByhUp0QAAAAHk"], referer: http://solkeetw.com/WORDPRESS
[Mon Jul 20 06:13:09.449963 2026] [security2:error] [pid 858085:tid 858293] [client 104.28.159.66:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "onpoint-evsolutions.com"] [uri "/wp-login.php"] [unique_id "al4Q1TAtbv2vrjByhUp0gwAAAE0"]
[Mon Jul 20 06:13:09.451853 2026] [security2:error] [pid 858085:tid 858324] [client 104.28.159.66:48311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "atozgroup.biz"] [uri "/wp-login.php"] [unique_id "al4Q1TAtbv2vrjByhUp0hQAAAGw"]
[Mon Jul 20 06:13:09.912897 2026] [security2:error] [pid 843279:tid 843463] [client 50.116.65.227:35722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9oQAAALo"]
[Mon Jul 20 06:13:10.027148 2026] [security2:error] [pid 858085:tid 858230] [client 14.225.17.146:52596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4Q1TAtbv2vrjByhUp0kQAAAA4"], referer: http://backandneckpainrelieflaceychiropractor.com/WORDPRESS
[Mon Jul 20 06:13:10.572404 2026] [security2:error] [pid 843279:tid 843315] [remote 97.74.87.194:33892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9xAAAwCI"]
[Mon Jul 20 06:13:10.669375 2026] [security2:error] [pid 843279:tid 843468] [client 50.116.65.227:35734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9twAAAL8"]
[Mon Jul 20 06:13:10.797496 2026] [security2:error] [pid 858085:tid 858303] [client 171.60.139.123:52435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1jAtbv2vrjByhUp0yQAAAFc"]
[Mon Jul 20 06:13:10.797603 2026] [security2:error] [pid 858085:tid 858303] [client 171.60.139.123:52435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1jAtbv2vrjByhUp0yQAAAFc"]
[Mon Jul 20 06:13:10.804769 2026] [security2:error] [pid 843279:tid 843480] [client 181.224.94.124:19011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9ygAAAMs"]
[Mon Jul 20 06:13:10.804908 2026] [security2:error] [pid 843279:tid 843480] [client 181.224.94.124:19011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9ygAAAMs"]
[Mon Jul 20 06:13:10.827022 2026] [security2:error] [pid 858085:tid 858247] [client 57.141.18.46:23818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q0jAtbv2vrjByhUpz7QAAH1k"]
[Mon Jul 20 06:13:10.842124 2026] [security2:error] [pid 843279:tid 843528] [client 50.116.65.227:35772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Q1vqvKNcW5yy5T2C9xgAAAPo"]
[Mon Jul 20 06:13:10.925983 2026] [security2:error] [pid 858085:tid 858154] [remote 205.196.217.58:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4Q1jAtbv2vrjByhUp0zgAAXUM"]
[Mon Jul 20 06:13:10.999199 2026] [security2:error] [pid 843279:tid 843407] [remote 97.74.87.194:33892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4Q1vqvKNcW5yy5T2C90gAAk34"], referer: https://fbvrealtors.com/wp-login.php
[Mon Jul 20 06:13:11.012350 2026] [security2:error] [pid 843279:tid 843465] [client 185.132.186.94:41819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/install.php"] [unique_id "al4Q1_qvKNcW5yy5T2C90wAAALw"]
[Mon Jul 20 06:13:11.019294 2026] [security2:error] [pid 858085:tid 858228] [client 50.116.65.227:35788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Q1jAtbv2vrjByhUp0ywAAAAw"]
[Mon Jul 20 06:13:11.128978 2026] [security2:error] [pid 858085:tid 858189] [remote 205.196.217.58:47736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.217.196.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4Q1zAtbv2vrjByhUp02QAAVWY"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 06:13:11.156253 2026] [security2:error] [pid 843279:tid 843371] [remote 47.242.45.34:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.45.242.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4Q1_qvKNcW5yy5T2C91wAA7Fo"]
[Mon Jul 20 06:13:11.156472 2026] [security2:error] [pid 843279:tid 843514] [client 47.242.45.34:58194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-5ab144f7.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4Q1_qvKNcW5yy5T2C91wAA7Fo"]
[Mon Jul 20 06:13:11.183502 2026] [security2:error] [pid 858085:tid 858274] [client 106.192.104.4:49599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1zAtbv2vrjByhUp03AAAADo"]
[Mon Jul 20 06:13:11.183648 2026] [security2:error] [pid 858085:tid 858274] [client 106.192.104.4:49599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q1zAtbv2vrjByhUp03AAAADo"]
[Mon Jul 20 06:13:11.623838 2026] [security2:error] [pid 843279:tid 843532] [client 114.119.152.108:54919] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/grantees"] [unique_id "al4Q1_qvKNcW5yy5T2C95QAAAP4"], referer: https://adambergeron.com/grantees?topic%5B0%5D=26&topic%5B1%5D=123&topic%5B2%5D=35
[Mon Jul 20 06:13:11.666084 2026] [security2:error] [pid 843279:tid 843450] [client 57.141.18.79:29012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q0vqvKNcW5yy5T2C9YwAArWk"]
[Mon Jul 20 06:13:11.666084 2026] [security2:error] [pid 858085:tid 858157] [remote 216.73.217.138:33152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Q1zAtbv2vrjByhUp07AAALEY"]
[Mon Jul 20 06:13:11.972890 2026] [security2:error] [pid 843279:tid 843511] [client 104.234.53.64:45283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Q1_qvKNcW5yy5T2C96AAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:12.370339 2026] [security2:error] [pid 858085:tid 858269] [client 27.96.94.195:38279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1FQAAADU"]
[Mon Jul 20 06:13:12.371071 2026] [security2:error] [pid 858085:tid 858269] [client 27.96.94.195:38279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1FQAAADU"]
[Mon Jul 20 06:13:12.495416 2026] [security2:error] [pid 858085:tid 858227] [client 64.225.75.246:37856] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/"] [unique_id "al4Q2DAtbv2vrjByhUp1GAAAAAs"]
[Mon Jul 20 06:13:12.825930 2026] [security2:error] [pid 858085:tid 858252] [client 41.173.37.102:6938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KAAAACQ"]
[Mon Jul 20 06:13:12.826078 2026] [security2:error] [pid 858085:tid 858252] [client 41.173.37.102:6938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KAAAACQ"]
[Mon Jul 20 06:13:12.870410 2026] [security2:error] [pid 858085:tid 858316] [client 103.141.108.143:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KQAAAGQ"]
[Mon Jul 20 06:13:12.870967 2026] [security2:error] [pid 858085:tid 858316] [client 103.141.108.143:62386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2DAtbv2vrjByhUp1KQAAAGQ"]
[Mon Jul 20 06:13:12.958879 2026] [security2:error] [pid 858085:tid 858256] [client 185.132.186.79:53049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/PHPMailer/xleet.php"] [unique_id "al4Q2DAtbv2vrjByhUp1LQAAACg"]
[Mon Jul 20 06:13:12.979917 2026] [fcgid:warn] [pid 843279:tid 843446] (70014)End of file found: [client 206.189.19.19:47978] mod_fcgid: can't get data from http client
[Mon Jul 20 06:13:13.229370 2026] [security2:error] [pid 843279:tid 843457] [client 103.153.183.69:13446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fvar/www/html/.env"] [unique_id "al4Q2fqvKNcW5yy5T2C-CAAAALQ"], referer: https://www.reddit.com/
[Mon Jul 20 06:13:13.496807 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.65:50370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1PqvKNcW5yy5T2C9jwAAlAg"]
[Mon Jul 20 06:13:13.561495 2026] [security2:error] [pid 858085:tid 858274] [client 114.119.139.123:63723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.secretkeynumerology.com"] [uri "/wpautoterms/terms-and-conditions-2"] [unique_id "al4Q2TAtbv2vrjByhUp1UQAAADo"], referer: https://www.secretkeynumerology.com/wpautoterms/terms-and-conditions-2
[Mon Jul 20 06:13:13.597846 2026] [security2:error] [pid 858085:tid 858134] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1UwAAVi8"]
[Mon Jul 20 06:13:13.597994 2026] [security2:error] [pid 858085:tid 858302] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1UwAAVi8"]
[Mon Jul 20 06:13:13.609920 2026] [security2:error] [pid 843279:tid 843420] [client 103.153.183.69:13446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fvar/www/.env"] [unique_id "al4Q2fqvKNcW5yy5T2C-DwAAAI8"], referer: https://www.bing.com/search?q=u93koc
[Mon Jul 20 06:13:13.643843 2026] [security2:error] [pid 858085:tid 858087] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1VwAAaAA"]
[Mon Jul 20 06:13:13.643997 2026] [security2:error] [pid 858085:tid 858320] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1VwAAaAA"]
[Mon Jul 20 06:13:13.654146 2026] [security2:error] [pid 858085:tid 858291] [client 64.225.75.246:37872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/"] [unique_id "al4Q2TAtbv2vrjByhUp1WAAAAEs"]
[Mon Jul 20 06:13:13.793439 2026] [security2:error] [pid 858085:tid 858297] [client 112.213.160.112:8360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1aQAAAFE"]
[Mon Jul 20 06:13:13.793533 2026] [security2:error] [pid 858085:tid 858297] [client 112.213.160.112:8360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1aQAAAFE"]
[Mon Jul 20 06:13:13.813832 2026] [security2:error] [pid 858085:tid 858334] [client 45.116.69.230:59206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1bQAAAHY"]
[Mon Jul 20 06:13:13.813911 2026] [security2:error] [pid 858085:tid 858334] [client 45.116.69.230:59206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q2TAtbv2vrjByhUp1bQAAAHY"]
[Mon Jul 20 06:13:13.894955 2026] [security2:error] [pid 843279:tid 843300] [remote 62.193.192.55:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q2fqvKNcW5yy5T2C-FAAAqxM"]
[Mon Jul 20 06:13:14.023392 2026] [security2:error] [pid 858085:tid 858241] [client 50.116.65.227:32318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4Q2jAtbv2vrjByhUp1dAAAABk"]
[Mon Jul 20 06:13:14.035044 2026] [security2:error] [pid 858085:tid 858322] [client 50.116.65.227:35814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4Q2jAtbv2vrjByhUp1dgAAAGo"]
[Mon Jul 20 06:13:14.057180 2026] [security2:error] [pid 858085:tid 858259] [client 104.234.53.90:38179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Q2jAtbv2vrjByhUp1eQAAACs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:14.075691 2026] [security2:error] [pid 843279:tid 843329] [remote 62.193.192.55:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4Q2vqvKNcW5yy5T2C-FwAAhTA"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:13:14.111263 2026] [security2:error] [pid 843279:tid 843493] [client 57.141.18.75:37972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9pQAA2HY"]
[Mon Jul 20 06:13:14.220755 2026] [security2:error] [pid 858085:tid 858309] [client 98.159.234.160:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q2jAtbv2vrjByhUp1ggAAAF0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:14.495183 2026] [security2:error] [pid 858085:tid 858294] [client 64.225.75.246:37886] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Q2jAtbv2vrjByhUp1kwAAAE4"]
[Mon Jul 20 06:13:14.544602 2026] [security2:error] [pid 858085:tid 858246] [client 57.141.18.116:52792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1TAtbv2vrjByhUp0mQAAHkk"]
[Mon Jul 20 06:13:14.748388 2026] [security2:error] [pid 843279:tid 843472] [client 57.141.18.123:35356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1fqvKNcW5yy5T2C9uAAAw0I"]
[Mon Jul 20 06:13:14.854485 2026] [security2:error] [pid 858085:tid 858253] [client 43.156.36.169:37046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Q2jAtbv2vrjByhUp1mAAAACU"]
[Mon Jul 20 06:13:14.905709 2026] [security2:error] [pid 858085:tid 858259] [client 185.132.186.74:47831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/doc.php"] [unique_id "al4Q2jAtbv2vrjByhUp1pgAAACs"]
[Mon Jul 20 06:13:15.186230 2026] [security2:error] [pid 858085:tid 858342] [client 57.141.18.45:44564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1jAtbv2vrjByhUp0uAAAfls"]
[Mon Jul 20 06:13:15.586134 2026] [security2:error] [pid 843279:tid 843434] [client 64.225.75.246:37894] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "www.uwannaempanada.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Q2_qvKNcW5yy5T2C-PwAAAJ0"]
[Mon Jul 20 06:13:15.906415 2026] [security2:error] [pid 843279:tid 843441] [client 57.141.18.88:61604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1_qvKNcW5yy5T2C93wAApCg"]
[Mon Jul 20 06:13:16.269956 2026] [security2:error] [pid 843279:tid 843474] [client 158.173.241.141:21283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-SwAAAMU"], referer: http://sesamegreenbeans.com/tag/Japan/
[Mon Jul 20 06:13:16.303932 2026] [security2:error] [pid 858085:tid 858237] [client 57.141.18.123:35370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q1zAtbv2vrjByhUp07wAAFTk"]
[Mon Jul 20 06:13:16.666157 2026] [security2:error] [pid 843279:tid 843428] [client 65.1.132.125:18412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-WwAAAJc"]
[Mon Jul 20 06:13:16.666309 2026] [security2:error] [pid 843279:tid 843428] [client 65.1.132.125:18412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-WwAAAJc"]
[Mon Jul 20 06:13:16.810209 2026] [security2:error] [pid 858085:tid 858335] [client 57.141.18.94:40812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2DAtbv2vrjByhUp1CgAAd10"]
[Mon Jul 20 06:13:16.848909 2026] [security2:error] [pid 843279:tid 843503] [client 185.132.186.56:29569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/f35_SpaceTn.php"] [unique_id "al4Q3PqvKNcW5yy5T2C-YwAAAOI"]
[Mon Jul 20 06:13:16.954220 2026] [security2:error] [pid 858085:tid 858328] [client 50.116.65.227:32328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q3DAtbv2vrjByhUp2DwAAAHA"]
[Mon Jul 20 06:13:16.966247 2026] [security2:error] [pid 858085:tid 858224] [client 50.116.65.227:35828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q3DAtbv2vrjByhUp2EAAAAAg"]
[Mon Jul 20 06:13:17.184137 2026] [security2:error] [pid 858085:tid 858231] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "darkknightsolutions.com"] [uri "/index.php"] [unique_id "al4Q2jAtbv2vrjByhUp1owAAAA8"]
[Mon Jul 20 06:13:17.520351 2026] [security2:error] [pid 858085:tid 858238] [client 57.141.18.0:48022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2DAtbv2vrjByhUp1JQAAFiA"]
[Mon Jul 20 06:13:17.794393 2026] [security2:error] [pid 858085:tid 858179] [remote 72.167.132.114:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q3TAtbv2vrjByhUp2NwAAV1w"]
[Mon Jul 20 06:13:18.018828 2026] [security2:error] [pid 843279:tid 843468] [client 64.225.75.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.uwannaempanada.com"] [uri "/index.php"] [unique_id "al4Q3fqvKNcW5yy5T2C-cAAAAL8"]
[Mon Jul 20 06:13:18.088985 2026] [security2:error] [pid 858085:tid 858169] [remote 72.167.132.114:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q3jAtbv2vrjByhUp2QwAAXlI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:13:18.281261 2026] [security2:error] [pid 858085:tid 858218] [client 57.141.18.98:29858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2TAtbv2vrjByhUp1WgAAAl4"]
[Mon Jul 20 06:13:18.563821 2026] [autoindex:error] [pid 858085:tid 858269] [client 198.235.24.173:61874] AH01276: Cannot serve directory /home2/oejeekmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.oej.eek.mybluehost.me/
[Mon Jul 20 06:13:18.804296 2026] [security2:error] [pid 858085:tid 858324] [client 185.132.186.72:33777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/sunrise/bypass.php"] [unique_id "al4Q3jAtbv2vrjByhUp2dgAAAGw"]
[Mon Jul 20 06:13:18.913866 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3vqvKNcW5yy5T2C-kAAAAJk"]
[Mon Jul 20 06:13:18.914037 2026] [security2:error] [pid 843279:tid 843430] [client 103.77.203.233:54286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q3vqvKNcW5yy5T2C-kAAAAJk"]
[Mon Jul 20 06:13:18.990185 2026] [security2:error] [pid 858085:tid 858288] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4Q3jAtbv2vrjByhUp2fgAAAEg"], referer: https://www.google.com/
[Mon Jul 20 06:13:19.460196 2026] [security2:error] [pid 858085:tid 858263] [client 104.234.53.56:31803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Q3zAtbv2vrjByhUp2jQAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:19.588142 2026] [security2:error] [pid 858085:tid 858305] [client 57.141.18.83:42022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2jAtbv2vrjByhUp1oQAAWRY"]
[Mon Jul 20 06:13:19.705395 2026] [security2:error] [pid 858085:tid 858204] [remote 57.141.18.26:27582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5970053"] [unique_id "al4Q3zAtbv2vrjByhUp2owAADXU"]
[Mon Jul 20 06:13:20.094248 2026] [security2:error] [pid 843279:tid 843423] [client 57.141.18.96:41146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2_qvKNcW5yy5T2C-KwAAknA"]
[Mon Jul 20 06:13:20.610015 2026] [security2:error] [pid 858085:tid 858262] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q3zAtbv2vrjByhUp2swAAAC4"]
[Mon Jul 20 06:13:20.689993 2026] [security2:error] [pid 858085:tid 858291] [client 104.234.53.56:31803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q4DAtbv2vrjByhUp24AAAAEs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:21.031291 2026] [security2:error] [pid 858085:tid 858226] [client 57.141.18.8:43342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q2zAtbv2vrjByhUp14wAACjI"]
[Mon Jul 20 06:13:21.052718 2026] [security2:error] [pid 858085:tid 858130] [remote 5.161.225.162:34938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Q4TAtbv2vrjByhUp28gAAbys"]
[Mon Jul 20 06:13:21.147015 2026] [security2:error] [pid 858085:tid 858239] [client 57.141.18.33:53096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3DAtbv2vrjByhUp16wAAFxA"]
[Mon Jul 20 06:13:21.272739 2026] [security2:error] [pid 843279:tid 843464] [client 57.141.18.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-xQAAALs"]
[Mon Jul 20 06:13:21.302657 2026] [security2:error] [pid 858085:tid 858281] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q4TAtbv2vrjByhUp28wAAAEE"]
[Mon Jul 20 06:13:21.320886 2026] [security2:error] [pid 843279:tid 843527] [client 181.224.94.124:45407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-yAAAAPk"]
[Mon Jul 20 06:13:21.321057 2026] [security2:error] [pid 843279:tid 843527] [client 181.224.94.124:45407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-yAAAAPk"]
[Mon Jul 20 06:13:21.348563 2026] [security2:error] [pid 858085:tid 858229] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3BAAAAA0"], referer: https://www.bing.com/search?q=o958a9
[Mon Jul 20 06:13:21.459466 2026] [security2:error] [pid 858085:tid 858279] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3DAAAAD8"], referer: https://www.bing.com/search?q=g2hrym
[Mon Jul 20 06:13:21.460079 2026] [security2:error] [pid 858085:tid 858246] [client 145.239.10.137:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sumnn.com"] [uri "/class.php"] [unique_id "al4Q4TAtbv2vrjByhUp3DQAAAB4"], referer: http://sumnn.com/class.php
[Mon Jul 20 06:13:21.508636 2026] [security2:error] [pid 843279:tid 843495] [client 171.60.139.123:52899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-ywAAANo"]
[Mon Jul 20 06:13:21.508815 2026] [security2:error] [pid 843279:tid 843495] [client 171.60.139.123:52899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-ywAAANo"]
[Mon Jul 20 06:13:21.559182 2026] [security2:error] [pid 858085:tid 858218] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3GAAAAAI"], referer: https://www.reddit.com/
[Mon Jul 20 06:13:21.596765 2026] [security2:error] [pid 858085:tid 858230] [client 57.141.18.113:44196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3DAtbv2vrjByhUp2BAAADko"]
[Mon Jul 20 06:13:21.661007 2026] [security2:error] [pid 858085:tid 858226] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..../..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4Q4TAtbv2vrjByhUp3JAAAAAo"], referer: https://www.reddit.com/
[Mon Jul 20 06:13:21.765270 2026] [security2:error] [pid 858085:tid 858101] [remote 5.161.225.162:34938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Q4TAtbv2vrjByhUp3KgAAQg4"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:13:21.831019 2026] [security2:error] [pid 858085:tid 858313] [client 185.132.186.67:34779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/fixed.php"] [unique_id "al4Q4TAtbv2vrjByhUp3MgAAAGE"]
[Mon Jul 20 06:13:21.831458 2026] [security2:error] [pid 858085:tid 858253] [client 57.141.18.93:35044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3DAtbv2vrjByhUp2DQAAJUg"]
[Mon Jul 20 06:13:22.036408 2026] [access_compat:error] [pid 843279:tid 843442] [client 206.189.19.19:49194] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Mon Jul 20 06:13:22.300983 2026] [security2:error] [pid 843279:tid 843443] [client 106.192.104.4:50099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4vqvKNcW5yy5T2C-4gAAAKY"]
[Mon Jul 20 06:13:22.301105 2026] [security2:error] [pid 843279:tid 843443] [client 106.192.104.4:50099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4vqvKNcW5yy5T2C-4gAAAKY"]
[Mon Jul 20 06:13:22.354432 2026] [security2:error] [pid 843279:tid 843483] [client 50.116.65.227:43000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q4vqvKNcW5yy5T2C-4wAAAM4"]
[Mon Jul 20 06:13:22.365654 2026] [security2:error] [pid 843279:tid 843496] [client 50.116.65.227:52616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Q4vqvKNcW5yy5T2C-5QAAANs"]
[Mon Jul 20 06:13:22.380063 2026] [core:error] [pid 843279:tid 843476] [client 181.41.206.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:22.380100 2026] [core:error] [pid 843279:tid 843476] [client 181.41.206.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:22.530162 2026] [security2:error] [pid 858085:tid 858340] [client 57.141.18.25:63932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3TAtbv2vrjByhUp2MgAAfBs"]
[Mon Jul 20 06:13:22.608140 2026] [security2:error] [pid 843279:tid 843538] [client 57.141.18.79:55706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3fqvKNcW5yy5T2C-dgABBBQ"]
[Mon Jul 20 06:13:22.613910 2026] [security2:error] [pid 843279:tid 843481] [client 57.141.18.29:31490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3fqvKNcW5yy5T2C-dQAAzHw"]
[Mon Jul 20 06:13:22.676546 2026] [security2:error] [pid 858085:tid 858276] [client 57.141.18.12:43206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3TAtbv2vrjByhUp2PAAAPDw"]
[Mon Jul 20 06:13:22.973238 2026] [security2:error] [pid 858085:tid 858301] [client 14.182.195.220:52056] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Q4jAtbv2vrjByhUp3XgAAAFU"]
[Mon Jul 20 06:13:23.463305 2026] [security2:error] [pid 858085:tid 858242] [client 41.173.37.102:7444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gAAAABo"]
[Mon Jul 20 06:13:23.463402 2026] [security2:error] [pid 858085:tid 858242] [client 41.173.37.102:7444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gAAAABo"]
[Mon Jul 20 06:13:23.475697 2026] [security2:error] [pid 843279:tid 843487] [client 27.96.94.195:37294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4_qvKNcW5yy5T2C_CAAAANI"]
[Mon Jul 20 06:13:23.476255 2026] [security2:error] [pid 843279:tid 843487] [client 27.96.94.195:37294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4_qvKNcW5yy5T2C_CAAAANI"]
[Mon Jul 20 06:13:23.487695 2026] [security2:error] [pid 843279:tid 843425] [client 57.141.18.29:31498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3vqvKNcW5yy5T2C-jgAAlHs"]
[Mon Jul 20 06:13:23.649181 2026] [security2:error] [pid 858085:tid 858284] [client 103.141.108.143:62867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3jAAAAEQ"]
[Mon Jul 20 06:13:23.649493 2026] [security2:error] [pid 858085:tid 858284] [client 103.141.108.143:62867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q4zAtbv2vrjByhUp3jAAAAEQ"]
[Mon Jul 20 06:13:23.769733 2026] [security2:error] [pid 858085:tid 858330] [client 185.132.186.83:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/themes.php"] [unique_id "al4Q4zAtbv2vrjByhUp3kQAAAHI"]
[Mon Jul 20 06:13:23.833121 2026] [security2:error] [pid 858085:tid 858302] [client 104.28.249.140:42898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adastra.love"] [uri "/graphql"] [unique_id "al4Q4zAtbv2vrjByhUp3lAAAAFY"]
[Mon Jul 20 06:13:23.889789 2026] [security2:error] [pid 858085:tid 858269] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gQAAADU"], referer: http://adastra.love/rclone.conf
[Mon Jul 20 06:13:24.236299 2026] [security2:error] [pid 858085:tid 858141] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3swAAYDY"]
[Mon Jul 20 06:13:24.236516 2026] [security2:error] [pid 858085:tid 858312] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3swAAYDY"]
[Mon Jul 20 06:13:24.271071 2026] [security2:error] [pid 858085:tid 858277] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3nwAAAD0"]
[Mon Jul 20 06:13:24.299400 2026] [security2:error] [pid 858085:tid 858294] [client 57.141.18.79:51418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q3zAtbv2vrjByhUp2sAAATgo"]
[Mon Jul 20 06:13:24.344285 2026] [security2:error] [pid 843279:tid 843447] [client 104.28.249.140:42891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.env.example"] [unique_id "al4Q5PqvKNcW5yy5T2C_LAAAAKo"]
[Mon Jul 20 06:13:24.381585 2026] [security2:error] [pid 843279:tid 843439] [client 112.213.160.112:30906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5PqvKNcW5yy5T2C_LgAAAKI"]
[Mon Jul 20 06:13:24.381728 2026] [security2:error] [pid 843279:tid 843439] [client 112.213.160.112:30906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5PqvKNcW5yy5T2C_LgAAAKI"]
[Mon Jul 20 06:13:24.441436 2026] [security2:error] [pid 858085:tid 858198] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3vAAAKm8"]
[Mon Jul 20 06:13:24.441567 2026] [security2:error] [pid 858085:tid 858258] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3vAAAKm8"]
[Mon Jul 20 06:13:24.477431 2026] [security2:error] [pid 858085:tid 858303] [client 45.116.69.230:59723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3wQAAAFc"]
[Mon Jul 20 06:13:24.478988 2026] [security2:error] [pid 858085:tid 858303] [client 45.116.69.230:59723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5DAtbv2vrjByhUp3wQAAAFc"]
[Mon Jul 20 06:13:24.528111 2026] [security2:error] [pid 858085:tid 858310] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3rwAAAF4"], referer: http://adastra.love/.gitlab-ci.yml
[Mon Jul 20 06:13:24.632592 2026] [security2:error] [pid 858085:tid 858337] [client 104.28.249.140:42895] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adastra.love"] [uri "/api/graphql"] [unique_id "al4Q5DAtbv2vrjByhUp3zQAAAHk"]
[Mon Jul 20 06:13:24.671798 2026] [security2:error] [pid 858085:tid 858333] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3uAAAAHU"], referer: http://adastra.love/.git/config
[Mon Jul 20 06:13:24.687666 2026] [security2:error] [pid 858085:tid 858095] [remote 192.178.4.102:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ashleystrain.com"] [uri "/"] [unique_id "al4Q5DAtbv2vrjByhUp30QAAZAg"]
[Mon Jul 20 06:13:24.776727 2026] [security2:error] [pid 858085:tid 858341] [client 57.141.18.10:52338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4DAtbv2vrjByhUp20wAAfSk"]
[Mon Jul 20 06:13:24.800361 2026] [security2:error] [pid 858085:tid 858330] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5DAtbv2vrjByhUp3wwAAAHI"], referer: http://adastra.love/.gitconfig
[Mon Jul 20 06:13:24.833099 2026] [security2:error] [pid 858085:tid 858288] [client 57.141.18.77:38860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4DAtbv2vrjByhUp21AAASH4"]
[Mon Jul 20 06:13:25.020858 2026] [security2:error] [pid 858085:tid 858202] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env.bak"] [unique_id "al4Q5TAtbv2vrjByhUp33gAAIHM"], referer: http://adastra.love/.env.bak
[Mon Jul 20 06:13:25.157662 2026] [security2:error] [pid 843279:tid 843515] [client 104.28.249.140:42889] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "adastra.love"] [uri "/v1/graphql"] [unique_id "al4Q5fqvKNcW5yy5T2C_PQAAAO0"]
[Mon Jul 20 06:13:25.249550 2026] [security2:error] [pid 843279:tid 843517] [client 57.141.18.14:42102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4PqvKNcW5yy5T2C-vwAA72c"]
[Mon Jul 20 06:13:25.319352 2026] [security2:error] [pid 843279:tid 843329] [remote 188.40.28.4:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Q5fqvKNcW5yy5T2C_QwABATA"]
[Mon Jul 20 06:13:25.329460 2026] [security2:error] [pid 858085:tid 858222] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp36QAAAAY"]
[Mon Jul 20 06:13:25.398316 2026] [security2:error] [pid 858085:tid 858315] [client 14.225.17.146:56886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp39AAAAGM"], referer: http://northbrookcpa.ca/WordPress
[Mon Jul 20 06:13:25.436957 2026] [security2:error] [pid 858085:tid 858292] [client 103.153.183.69:20330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4Q5TAtbv2vrjByhUp3_AAAAEw"], referer: https://twitter.com/
[Mon Jul 20 06:13:25.587687 2026] [security2:error] [pid 843279:tid 843390] [remote 188.40.28.4:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Q5fqvKNcW5yy5T2C_SgAAvG0"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:13:25.698141 2026] [security2:error] [pid 858085:tid 858211] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env"] [unique_id "al4Q5TAtbv2vrjByhUp4FAAAN3w"], referer: http://adastra.love/.env
[Mon Jul 20 06:13:25.709071 2026] [security2:error] [pid 858085:tid 858339] [client 185.132.186.65:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/fix/bypass.php"] [unique_id "al4Q5TAtbv2vrjByhUp4FwAAAHs"]
[Mon Jul 20 06:13:25.842382 2026] [security2:error] [pid 858085:tid 858297] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp4CQAAAFE"], referer: http://adastra.love/.env.local
[Mon Jul 20 06:13:25.961209 2026] [security2:error] [pid 858085:tid 858295] [client 14.225.17.146:49180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp4HAAAAE8"], referer: http://dnsplumbing.com/WordPress
[Mon Jul 20 06:13:25.986888 2026] [security2:error] [pid 843279:tid 843432] [client 57.141.18.79:51430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4fqvKNcW5yy5T2C-zgAAmyI"]
[Mon Jul 20 06:13:26.132501 2026] [security2:error] [pid 858085:tid 858137] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/api/.env"] [unique_id "al4Q5jAtbv2vrjByhUp4MAAASzI"], referer: http://adastra.love/api/.env
[Mon Jul 20 06:13:26.201247 2026] [security2:error] [pid 843279:tid 843523] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5fqvKNcW5yy5T2C_VQAAAPU"], referer: http://adastra.love/.env.production
[Mon Jul 20 06:13:26.284092 2026] [security2:error] [pid 858085:tid 858103] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/backend/.env"] [unique_id "al4Q5jAtbv2vrjByhUp4OAAAJhA"], referer: http://adastra.love/backend/.env
[Mon Jul 20 06:13:26.435881 2026] [security2:error] [pid 858085:tid 858118] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env.old"] [unique_id "al4Q5jAtbv2vrjByhUp4QQAAdx8"], referer: http://adastra.love/.env.old
[Mon Jul 20 06:13:26.435889 2026] [security2:error] [pid 858085:tid 858148] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.env.backup"] [unique_id "al4Q5jAtbv2vrjByhUp4QgAAdz0"], referer: http://adastra.love/.env.backup
[Mon Jul 20 06:13:26.475925 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:55783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Q5vqvKNcW5yy5T2C_WAAAAIU"], referer: http://savilerowtravel.com/WordPress
[Mon Jul 20 06:13:26.785342 2026] [security2:error] [pid 858085:tid 858343] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4TAAAAH8"]
[Mon Jul 20 06:13:26.884596 2026] [security2:error] [pid 858085:tid 858300] [client 193.37.33.186:54441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "realscapetours.com"] [uri "/wp-login.php"] [unique_id "al4Q5jAtbv2vrjByhUp4ZwAAAFQ"]
[Mon Jul 20 06:13:26.919879 2026] [security2:error] [pid 858085:tid 858316] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4UwAAAGQ"], referer: http://adastra.love/admin/.env
[Mon Jul 20 06:13:27.053250 2026] [security2:error] [pid 858085:tid 858123] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/config/.env"] [unique_id "al4Q5zAtbv2vrjByhUp4cAAAHSQ"], referer: http://adastra.love/config/.env
[Mon Jul 20 06:13:27.053321 2026] [security2:error] [pid 858085:tid 858247] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4YgAAAB8"], referer: http://adastra.love/secrets.yml
[Mon Jul 20 06:13:27.235396 2026] [security2:error] [pid 843279:tid 843527] [client 104.28.249.140:42904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/firebase-adminsdk.json"] [unique_id "al4Q5_qvKNcW5yy5T2C_dQAAAPk"]
[Mon Jul 20 06:13:27.434104 2026] [security2:error] [pid 858085:tid 858267] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4gwAAADM"]
[Mon Jul 20 06:13:27.488763 2026] [security2:error] [pid 858085:tid 858335] [client 2.50.155.88:55182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.155.50.2.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4kQAAAHc"]
[Mon Jul 20 06:13:27.488902 2026] [security2:error] [pid 858085:tid 858335] [client 2.50.155.88:55182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4kQAAAHc"]
[Mon Jul 20 06:13:27.493297 2026] [security2:error] [pid 858085:tid 858338] [client 14.225.17.146:49454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4igAAAHo"], referer: https://savilerowtravel.com/WordPress
[Mon Jul 20 06:13:27.655836 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.107:41368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4zAtbv2vrjByhUp3bwAAHDM"]
[Mon Jul 20 06:13:27.660991 2026] [security2:error] [pid 858085:tid 858297] [client 185.132.186.53:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/category-double.php"] [unique_id "al4Q5zAtbv2vrjByhUp4oQAAAFE"]
[Mon Jul 20 06:13:27.723615 2026] [security2:error] [pid 858085:tid 858234] [client 14.225.17.146:49617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4oAAAABI"], referer: http://katsklar.com/WordPress
[Mon Jul 20 06:13:27.731417 2026] [security2:error] [pid 858085:tid 858239] [client 104.28.249.140:42936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/terraform.tfstate"] [unique_id "al4Q5zAtbv2vrjByhUp4pgAAABc"]
[Mon Jul 20 06:13:27.822376 2026] [security2:error] [pid 858085:tid 858294] [client 3.109.4.218:52820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4rAAAAE4"]
[Mon Jul 20 06:13:27.822485 2026] [security2:error] [pid 858085:tid 858294] [client 3.109.4.218:52820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q5zAtbv2vrjByhUp4rAAAAE4"]
[Mon Jul 20 06:13:27.926290 2026] [security2:error] [pid 858085:tid 858276] [client 57.141.18.17:50352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4zAtbv2vrjByhUp3gwAAPFc"]
[Mon Jul 20 06:13:27.999482 2026] [security2:error] [pid 858085:tid 858223] [client 104.28.249.140:42887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.ssh/id_ecdsa"] [unique_id "al4Q5zAtbv2vrjByhUp4vwAAAAc"]
[Mon Jul 20 06:13:27.999560 2026] [security2:error] [pid 858085:tid 858223] [client 104.28.249.140:42887] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adastra.love"] [uri "/.ssh/id_ecdsa"] [unique_id "al4Q5zAtbv2vrjByhUp4vwAAAAc"]
[Mon Jul 20 06:13:28.100718 2026] [security2:error] [pid 858085:tid 858301] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4swAAAFU"]
[Mon Jul 20 06:13:28.228345 2026] [security2:error] [pid 843279:tid 843525] [client 57.141.18.13:22616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q4_qvKNcW5yy5T2C_HQAA92E"]
[Mon Jul 20 06:13:28.232096 2026] [security2:error] [pid 843279:tid 843464] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5_qvKNcW5yy5T2C_hQAAALs"], referer: http://adastra.love/.npmrc
[Mon Jul 20 06:13:28.234842 2026] [security2:error] [pid 858085:tid 858270] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4vAAAADY"], referer: http://adastra.love/.boto
[Mon Jul 20 06:13:28.260904 2026] [authz_core:error] [pid 858085:tid 858224] [client 104.28.249.140:0] AH01630: client denied by server configuration: /home3/adastrb8/public_html/.htpasswd, referer: http://adastra.love/.htpasswd
[Mon Jul 20 06:13:28.381368 2026] [security2:error] [pid 858085:tid 858230] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6DAtbv2vrjByhUp4yQAAAA4"], referer: http://adastra.love/.s3cfg
[Mon Jul 20 06:13:28.543632 2026] [security2:error] [pid 858085:tid 858131] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.ssh/id_rsa"] [unique_id "al4Q6DAtbv2vrjByhUp48gAAEyw"], referer: http://adastra.love/.ssh/id_rsa
[Mon Jul 20 06:13:28.691967 2026] [security2:error] [pid 843279:tid 843492] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_kQAAANc"], referer: http://adastra.love/.svn/entries
[Mon Jul 20 06:13:28.723834 2026] [security2:error] [pid 858085:tid 858237] [client 50.116.65.227:52676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Q6DAtbv2vrjByhUp4_gAAABU"]
[Mon Jul 20 06:13:28.733931 2026] [security2:error] [pid 843279:tid 843512] [client 50.116.65.227:52686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Q6PqvKNcW5yy5T2C_mAAAAOo"]
[Mon Jul 20 06:13:28.838727 2026] [security2:error] [pid 858085:tid 858117] [remote 173.212.252.15:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Q6DAtbv2vrjByhUp5AwAAbx4"]
[Mon Jul 20 06:13:28.866673 2026] [security2:error] [pid 843279:tid 843476] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_lgAAAMc"], referer: http://adastra.love/docker-compose.yaml
[Mon Jul 20 06:13:28.870647 2026] [security2:error] [pid 843279:tid 843436] [client 104.28.249.140:42921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/id_ed25519"] [unique_id "al4Q6PqvKNcW5yy5T2C_nAAAAJ8"]
[Mon Jul 20 06:13:28.875447 2026] [security2:error] [pid 858085:tid 858261] [client 74.208.214.194:37818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Q6DAtbv2vrjByhUp5CgAAAC0"]
[Mon Jul 20 06:13:28.882415 2026] [security2:error] [pid 858085:tid 858275] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6DAtbv2vrjByhUp49wAAADs"], referer: http://adastra.love/.ssh/id_ed25519
[Mon Jul 20 06:13:29.039659 2026] [security2:error] [pid 858085:tid 858199] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.ssh/id_dsa"] [unique_id "al4Q6TAtbv2vrjByhUp5FQAAe3A"], referer: http://adastra.love/.ssh/id_dsa
[Mon Jul 20 06:13:29.100278 2026] [security2:error] [pid 843279:tid 843438] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_nQAAAKE"]
[Mon Jul 20 06:13:29.105109 2026] [security2:error] [pid 858085:tid 858095] [remote 41.186.86.12:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5GgAAWAg"]
[Mon Jul 20 06:13:29.126968 2026] [security2:error] [pid 858085:tid 858128] [remote 173.212.252.15:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5HAAABCk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:13:29.134784 2026] [security2:error] [pid 858085:tid 858292] [client 114.119.142.140:33037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zonemist.com"] [uri "/wp-content/uploads/2020/04/Untitled.001.jpeg"] [unique_id "al4Q6TAtbv2vrjByhUp5HgAAAEw"], referer: https://www.zonemist.com/zonemist-generators/sea-water-anolyte-generators/
[Mon Jul 20 06:13:29.244169 2026] [security2:error] [pid 858085:tid 858318] [client 104.234.53.52:25105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Q6TAtbv2vrjByhUp5IAAAAGY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:29.325203 2026] [security2:error] [pid 858085:tid 858323] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5GQAAAGs"], referer: http://adastra.love/.ssh/authorized_keys
[Mon Jul 20 06:13:29.487151 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.34:44100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp34AAAFAI"]
[Mon Jul 20 06:13:29.494140 2026] [security2:error] [pid 858085:tid 858248] [client 103.77.203.233:54829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6TAtbv2vrjByhUp5PQAAACA"]
[Mon Jul 20 06:13:29.494422 2026] [security2:error] [pid 858085:tid 858248] [client 103.77.203.233:54829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6TAtbv2vrjByhUp5PQAAACA"]
[Mon Jul 20 06:13:29.583858 2026] [security2:error] [pid 858085:tid 858284] [client 57.141.18.94:61582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5TAtbv2vrjByhUp36gAARH8"]
[Mon Jul 20 06:13:29.606598 2026] [security2:error] [pid 858085:tid 858274] [client 185.132.186.70:47481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/admin.php"] [unique_id "al4Q6TAtbv2vrjByhUp5SgAAADo"]
[Mon Jul 20 06:13:29.679603 2026] [security2:error] [pid 843279:tid 843518] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6fqvKNcW5yy5T2C_rAAAAPA"], referer: http://adastra.love/.ssh/config
[Mon Jul 20 06:13:29.696533 2026] [security2:error] [pid 858085:tid 858091] [remote 41.186.86.12:20689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5TwAAUgQ"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:13:29.708998 2026] [security2:error] [pid 858085:tid 858280] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5NAAAAEA"], referer: http://adastra.love/server.key
[Mon Jul 20 06:13:29.715200 2026] [security2:error] [pid 858085:tid 858096] [remote 45.90.123.233:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5UQAAHQk"]
[Mon Jul 20 06:13:29.773948 2026] [security2:error] [pid 858085:tid 858289] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5QQAAAEk"], referer: http://adastra.love/.ssh/known_hosts
[Mon Jul 20 06:13:29.847946 2026] [security2:error] [pid 858085:tid 858288] [client 206.189.19.19:60818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/.env"] [unique_id "al4Q6TAtbv2vrjByhUp5WQAAAEg"]
[Mon Jul 20 06:13:29.870160 2026] [security2:error] [pid 858085:tid 858272] [client 104.234.53.52:25105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5WgAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:29.947119 2026] [security2:error] [pid 858085:tid 858211] [remote 45.90.123.233:59314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4Q6TAtbv2vrjByhUp5XwAATnw"], referer: https://709fx.com/wp-login.php
[Mon Jul 20 06:13:29.960454 2026] [security2:error] [pid 858085:tid 858217] [client 104.28.249.140:42932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/ssl/server.key"] [unique_id "al4Q6TAtbv2vrjByhUp5YAAAAAE"]
[Mon Jul 20 06:13:30.004831 2026] [security2:error] [pid 843279:tid 843446] [client 14.225.17.146:56953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_oQAAAKk"], referer: http://travelbyfire.com/WordPress
[Mon Jul 20 06:13:30.073602 2026] [security2:error] [pid 858085:tid 858145] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/id_dsa"] [unique_id "al4Q6jAtbv2vrjByhUp5ZwAALDo"], referer: http://adastra.love/id_dsa
[Mon Jul 20 06:13:30.073760 2026] [security2:error] [pid 858085:tid 858188] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/id_rsa"] [unique_id "al4Q6jAtbv2vrjByhUp5aAAALGU"], referer: http://adastra.love/id_rsa
[Mon Jul 20 06:13:30.091681 2026] [ssl:error] [pid 858085:tid 858237] [client 104.48.69.105:42316] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:13:30.163386 2026] [autoindex:error] [pid 858085:tid 858235] [client 66.249.89.7:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:13:30.403135 2026] [security2:error] [pid 858085:tid 858286] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5bQAAAEY"], referer: http://adastra.love/id_ecdsa
[Mon Jul 20 06:13:30.541871 2026] [security2:error] [pid 858085:tid 858292] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5fgAAAEw"], referer: http://adastra.love/localhost.key
[Mon Jul 20 06:13:30.552083 2026] [security2:error] [pid 858085:tid 858277] [client 104.28.249.140:42908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.openclaw/openclaw.json"] [unique_id "al4Q6jAtbv2vrjByhUp5jQAAAD0"]
[Mon Jul 20 06:13:30.553825 2026] [security2:error] [pid 858085:tid 858197] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/key.pem"] [unique_id "al4Q6jAtbv2vrjByhUp5jgAAa24"], referer: http://adastra.love/key.pem
[Mon Jul 20 06:13:30.603775 2026] [security2:error] [pid 858085:tid 858268] [client 57.141.18.12:22448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4NAAANGE"]
[Mon Jul 20 06:13:30.678495 2026] [security2:error] [pid 858085:tid 858234] [client 14.225.17.146:49632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5JwAAABI"], referer: http://goyalsatyam.com/WordPress
[Mon Jul 20 06:13:30.710954 2026] [security2:error] [pid 858085:tid 858240] [client 57.141.18.53:22252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5jAtbv2vrjByhUp4OQAAGHg"]
[Mon Jul 20 06:13:30.911083 2026] [security2:error] [pid 858085:tid 858319] [client 104.28.249.140:42501] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/.hermes/.env"] [unique_id "al4Q6jAtbv2vrjByhUp5rQAAAGc"]
[Mon Jul 20 06:13:31.006776 2026] [security2:error] [pid 858085:tid 858248] [client 14.225.17.146:52632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5rwAAACA"], referer: https://travelbyfire.com/WordPress
[Mon Jul 20 06:13:31.021815 2026] [security2:error] [pid 843279:tid 843484] [client 14.225.17.146:49531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4Q6fqvKNcW5yy5T2C_pgAAAM8"], referer: http://soloceos.com/WordPress
[Mon Jul 20 06:13:31.032021 2026] [security2:error] [pid 858085:tid 858232] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5oAAAABA"], referer: http://adastra.love/host.key
[Mon Jul 20 06:13:31.059879 2026] [security2:error] [pid 858085:tid 858292] [client 50.116.65.227:31520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q6zAtbv2vrjByhUp5ugAAAEw"]
[Mon Jul 20 06:13:31.074849 2026] [security2:error] [pid 858085:tid 858277] [client 50.116.65.227:47514] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q6zAtbv2vrjByhUp5vgAAAD0"]
[Mon Jul 20 06:13:31.118157 2026] [security2:error] [pid 858085:tid 858231] [client 104.28.249.140:42918] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/.codex/config.toml"] [unique_id "al4Q6zAtbv2vrjByhUp5xAAAAA8"]
[Mon Jul 20 06:13:31.201046 2026] [security2:error] [pid 858085:tid 858176] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/privatekey.key"] [unique_id "al4Q6zAtbv2vrjByhUp5zAAAe1k"], referer: http://adastra.love/privatekey.key
[Mon Jul 20 06:13:31.352071 2026] [security2:error] [pid 858085:tid 858104] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/.openclaw/.env"] [unique_id "al4Q6zAtbv2vrjByhUp51wAAexE"], referer: http://adastra.love/.openclaw/.env
[Mon Jul 20 06:13:31.372015 2026] [security2:error] [pid 843279:tid 843430] [client 103.153.183.69:4880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..%ef%bc%8f..%ef%bc%8fvar/www/html/wp-config.php"] [unique_id "al4Q6_qvKNcW5yy5T2C_0gAAAJk"], referer: https://www.bing.com/search?q=fct02d
[Mon Jul 20 06:13:31.392803 2026] [security2:error] [pid 858085:tid 858225] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp5vQAAAAk"], referer: http://adastra.love/private-key
[Mon Jul 20 06:13:31.445901 2026] [security2:error] [pid 858085:tid 858222] [client 14.225.17.146:60111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4Q6TAtbv2vrjByhUp5NQAAAAY"], referer: http://areitoproducciones.com/WordPress
[Mon Jul 20 06:13:31.545841 2026] [security2:error] [pid 858085:tid 858337] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp50AAAAHk"], referer: http://adastra.love/ssl/localhost.key
[Mon Jul 20 06:13:31.549290 2026] [security2:error] [pid 858085:tid 858287] [client 185.132.186.103:61227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/blog/signatur.php"] [unique_id "al4Q6zAtbv2vrjByhUp53wAAAEc"]
[Mon Jul 20 06:13:31.696100 2026] [security2:error] [pid 858085:tid 858280] [client 74.208.214.194:37824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Q6zAtbv2vrjByhUp57gAAAEA"]
[Mon Jul 20 06:13:31.896129 2026] [security2:error] [pid 858085:tid 858340] [client 181.224.94.124:29152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6zAtbv2vrjByhUp6AwAAAHw"]
[Mon Jul 20 06:13:31.896254 2026] [security2:error] [pid 858085:tid 858340] [client 181.224.94.124:29152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q6zAtbv2vrjByhUp6AwAAAHw"]
[Mon Jul 20 06:13:31.926236 2026] [security2:error] [pid 858085:tid 858288] [client 46.110.96.34:20248] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4Q6zAtbv2vrjByhUp6BQAAAEg"]
[Mon Jul 20 06:13:32.027710 2026] [security2:error] [pid 858085:tid 858219] [client 57.141.18.43:29940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q5zAtbv2vrjByhUp4qQAAA0Y"]
[Mon Jul 20 06:13:32.032889 2026] [security2:error] [pid 858085:tid 858328] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp58wAAAHA"], referer: http://adastra.love/.aider.conf.yml
[Mon Jul 20 06:13:32.153669 2026] [security2:error] [pid 858085:tid 858249] [client 171.60.139.123:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7DAtbv2vrjByhUp6EQAAACE"]
[Mon Jul 20 06:13:32.153794 2026] [security2:error] [pid 858085:tid 858249] [client 171.60.139.123:53372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7DAtbv2vrjByhUp6EQAAACE"]
[Mon Jul 20 06:13:32.154032 2026] [security2:error] [pid 843279:tid 843524] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q6_qvKNcW5yy5T2C_4QAAAPY"]
[Mon Jul 20 06:13:32.169610 2026] [security2:error] [pid 843279:tid 843525] [client 104.234.53.55:44955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Q7PqvKNcW5yy5T2C_6QAAAPc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:32.635136 2026] [security2:error] [pid 843279:tid 843479] [client 104.28.249.140:15606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adastra.love"] [uri "/wp-config.php.bak"] [unique_id "al4Q7PqvKNcW5yy5T2C_8gAAAMo"]
[Mon Jul 20 06:13:32.721473 2026] [security2:error] [pid 843279:tid 843435] [client 14.225.17.146:55156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Q7PqvKNcW5yy5T2C_8AAAAJ4"], referer: http://tntcatholic.com/WordPress
[Mon Jul 20 06:13:32.755328 2026] [security2:error] [pid 858085:tid 858269] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7DAtbv2vrjByhUp6JAAAADU"], referer: http://adastra.love/.hermes/config.yaml
[Mon Jul 20 06:13:32.902237 2026] [security2:error] [pid 843279:tid 843359] [remote 123.207.84.151:34124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.84.207.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4Q7PqvKNcW5yy5T2C_9wAAhk4"]
[Mon Jul 20 06:13:32.922480 2026] [security2:error] [pid 858085:tid 858334] [client 37.139.53.5:52058] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.5" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7DAtbv2vrjByhUp6QwAAAHY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:32.922589 2026] [security2:error] [pid 858085:tid 858334] [client 37.139.53.5:52058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7DAtbv2vrjByhUp6QwAAAHY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:32.968415 2026] [security2:error] [pid 843279:tid 843463] [client 57.141.18.20:28814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6PqvKNcW5yy5T2C_oAAAujw"]
[Mon Jul 20 06:13:32.982024 2026] [security2:error] [pid 843279:tid 843482] [client 104.28.249.140:15608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "adastra.love"] [uri "/wp-config.php.old"] [unique_id "al4Q7PqvKNcW5yy5T2C_-QAAAM0"]
[Mon Jul 20 06:13:33.164745 2026] [security2:error] [pid 858085:tid 858230] [client 106.192.104.4:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7TAtbv2vrjByhUp6VQAAAA4"]
[Mon Jul 20 06:13:33.164923 2026] [security2:error] [pid 858085:tid 858230] [client 106.192.104.4:50596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7TAtbv2vrjByhUp6VQAAAA4"]
[Mon Jul 20 06:13:33.211923 2026] [core:error] [pid 858085:tid 858325] [client 14.225.17.146:63338] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WordPress
[Mon Jul 20 06:13:33.211950 2026] [core:error] [pid 858085:tid 858325] [client 14.225.17.146:63338] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WordPress
[Mon Jul 20 06:13:33.220589 2026] [security2:error] [pid 843279:tid 843449] [client 77.75.76.161:13377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jmq.beb.mybluehost.me"] [uri "/website_9cef8506/category/news/"] [unique_id "al4Q7fqvKNcW5yy5T2DABAAAAKw"]
[Mon Jul 20 06:13:33.220717 2026] [security2:error] [pid 843279:tid 843449] [client 77.75.76.161:13377] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jmq.beb.mybluehost.me"] [uri "/website_9cef8506/category/news/"] [unique_id "al4Q7fqvKNcW5yy5T2DABAAAAKw"]
[Mon Jul 20 06:13:33.265626 2026] [security2:error] [pid 858085:tid 858165] [remote 110.249.202.3:21034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/meeting-info/"] [unique_id "al4Q7TAtbv2vrjByhUp6XAAASE4"]
[Mon Jul 20 06:13:33.346010 2026] [security2:error] [pid 843279:tid 843534] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7fqvKNcW5yy5T2C__wAAAQA"], referer: http://adastra.love/.bashrc
[Mon Jul 20 06:13:33.381024 2026] [security2:error] [pid 843279:tid 843377] [remote 123.207.84.151:34124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.84.207.123.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4Q7fqvKNcW5yy5T2DABwAA42A"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:13:33.454963 2026] [security2:error] [pid 858085:tid 858272] [client 104.28.249.140:42929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/storage/logs/laravel.log"] [unique_id "al4Q7TAtbv2vrjByhUp6aQAAADg"]
[Mon Jul 20 06:13:33.455072 2026] [security2:error] [pid 858085:tid 858272] [client 104.28.249.140:42929] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adastra.love"] [uri "/storage/logs/laravel.log"] [unique_id "al4Q7TAtbv2vrjByhUp6aQAAADg"]
[Mon Jul 20 06:13:33.475366 2026] [security2:error] [pid 858085:tid 858258] [client 185.132.186.66:35671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/db.php"] [unique_id "al4Q7TAtbv2vrjByhUp6awAAACo"]
[Mon Jul 20 06:13:33.530650 2026] [security2:error] [pid 858085:tid 858332] [client 104.28.249.140:42913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/.env.php.bak"] [unique_id "al4Q7TAtbv2vrjByhUp6bQAAAHQ"]
[Mon Jul 20 06:13:33.675603 2026] [security2:error] [pid 858085:tid 858214] [remote 188.166.241.141:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Q7TAtbv2vrjByhUp6fwAAPH8"]
[Mon Jul 20 06:13:33.723551 2026] [security2:error] [pid 843279:tid 843526] [client 104.28.249.140:21557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/config/.env.php"] [unique_id "al4Q7fqvKNcW5yy5T2DAFgAAAPg"]
[Mon Jul 20 06:13:33.877203 2026] [security2:error] [pid 858085:tid 858333] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6eAAAAHU"], referer: http://adastra.love/.bash_profile
[Mon Jul 20 06:13:33.878479 2026] [security2:error] [pid 843279:tid 843439] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7fqvKNcW5yy5T2DAEQAAAKI"], referer: http://adastra.love/.zshrc
[Mon Jul 20 06:13:34.065684 2026] [security2:error] [pid 858085:tid 858209] [remote 188.166.241.141:46052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4Q7jAtbv2vrjByhUp6oAAAC3o"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:13:34.092855 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.13:22180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5fAAABTI"]
[Mon Jul 20 06:13:34.093030 2026] [security2:error] [pid 858085:tid 858338] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6kAAAAHo"], referer: http://adastra.love/.profile
[Mon Jul 20 06:13:34.121805 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:7898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ogAAACU"]
[Mon Jul 20 06:13:34.121912 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:7898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ogAAACU"]
[Mon Jul 20 06:13:34.122332 2026] [security2:error] [pid 858085:tid 858238] [client 170.199.228.120:16191] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ngAAABY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:34.140965 2026] [security2:error] [pid 843279:tid 843499] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q7fqvKNcW5yy5T2DAIAAAAN4"]
[Mon Jul 20 06:13:34.146199 2026] [security2:error] [pid 858085:tid 858313] [client 132.145.20.138:0] ModSecurity: Warning. Matched phrase "Scanbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6gQAAAGE"]
[Mon Jul 20 06:13:34.147895 2026] [security2:error] [pid 858085:tid 858327] [client 132.145.20.138:56152] ModSecurity: Warning. Matched phrase "Scanbot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whiteoutcb.com"] [uri "/"] [unique_id "al4Q7TAtbv2vrjByhUp6ewAAAG8"]
[Mon Jul 20 06:13:34.161046 2026] [security2:error] [pid 843279:tid 843365] [remote 154.66.198.148:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Q7vqvKNcW5yy5T2DAKAAA0lQ"]
[Mon Jul 20 06:13:34.177704 2026] [security2:error] [pid 858085:tid 858263] [client 14.225.17.146:53148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp59QAAAC8"], referer: http://talknutritionwithlesley.com/WordPress
[Mon Jul 20 06:13:34.197884 2026] [security2:error] [pid 858085:tid 858267] [client 104.28.249.140:15603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/configuration.php.bak"] [unique_id "al4Q7jAtbv2vrjByhUp6qQAAADM"]
[Mon Jul 20 06:13:34.283223 2026] [security2:error] [pid 843279:tid 843525] [client 103.141.108.143:63350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7vqvKNcW5yy5T2DALgAAAPc"]
[Mon Jul 20 06:13:34.284210 2026] [security2:error] [pid 858085:tid 858233] [client 198.44.157.34:46394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.157.44.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6sQAAABE"]
[Mon Jul 20 06:13:34.284293 2026] [security2:error] [pid 858085:tid 858233] [client 198.44.157.34:46394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp6sQAAABE"]
[Mon Jul 20 06:13:34.284434 2026] [security2:error] [pid 843279:tid 843525] [client 103.141.108.143:63350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7vqvKNcW5yy5T2DALgAAAPc"]
[Mon Jul 20 06:13:34.315258 2026] [security2:error] [pid 858085:tid 858160] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/core/.env"] [unique_id "al4Q7jAtbv2vrjByhUp6tgAAIEk"], referer: http://adastra.love/core/.env
[Mon Jul 20 06:13:34.440943 2026] [security2:error] [pid 858085:tid 858284] [client 104.28.249.140:21563] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/.env.swp"] [unique_id "al4Q7jAtbv2vrjByhUp6wQAAAEQ"]
[Mon Jul 20 06:13:34.441886 2026] [security2:error] [pid 858085:tid 858259] [client 104.28.249.140:21575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.249.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/config.php.bak"] [unique_id "al4Q7jAtbv2vrjByhUp6wgAAACs"]
[Mon Jul 20 06:13:34.467699 2026] [security2:error] [pid 858085:tid 858135] [remote 104.28.249.140:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "adastra.love"] [uri "/laravel/.env"] [unique_id "al4Q7jAtbv2vrjByhUp6xgAAYzA"], referer: http://adastra.love/laravel/.env
[Mon Jul 20 06:13:34.599796 2026] [security2:error] [pid 858085:tid 858238] [client 170.199.228.120:16191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ngAAABY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:34.599841 2026] [security2:error] [pid 858085:tid 858238] [client 170.199.228.120:16191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Q7jAtbv2vrjByhUp6ngAAABY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:13:34.716535 2026] [security2:error] [pid 858085:tid 858184] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp61wAAHmE"]
[Mon Jul 20 06:13:34.716759 2026] [security2:error] [pid 858085:tid 858246] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp61wAAHmE"]
[Mon Jul 20 06:13:34.792810 2026] [security2:error] [pid 858085:tid 858326] [client 57.141.18.49:52564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6jAtbv2vrjByhUp5qwAAbko"]
[Mon Jul 20 06:13:34.935934 2026] [security2:error] [pid 858085:tid 858286] [client 57.141.18.78:26204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp5tgAARks"]
[Mon Jul 20 06:13:35.000793 2026] [security2:error] [pid 858085:tid 858253] [client 112.213.160.112:8253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp65QAAACU"]
[Mon Jul 20 06:13:35.000906 2026] [security2:error] [pid 858085:tid 858253] [client 112.213.160.112:8253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7jAtbv2vrjByhUp65QAAACU"]
[Mon Jul 20 06:13:35.067709 2026] [security2:error] [pid 858085:tid 858249] [client 206.189.19.19:60842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q7jAtbv2vrjByhUp64AAAACE"]
[Mon Jul 20 06:13:35.112284 2026] [security2:error] [pid 858085:tid 858103] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66gAAIBA"]
[Mon Jul 20 06:13:35.112416 2026] [security2:error] [pid 858085:tid 858248] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66gAAIBA"]
[Mon Jul 20 06:13:35.122377 2026] [security2:error] [pid 858085:tid 858292] [client 45.116.69.230:60240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66wAAAEw"]
[Mon Jul 20 06:13:35.122475 2026] [security2:error] [pid 858085:tid 858292] [client 45.116.69.230:60240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7zAtbv2vrjByhUp66wAAAEw"]
[Mon Jul 20 06:13:35.357576 2026] [security2:error] [pid 843279:tid 843352] [remote 154.66.198.148:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Q7_qvKNcW5yy5T2DASwAAkEc"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:13:35.420158 2026] [security2:error] [pid 858085:tid 858257] [client 185.132.186.88:21119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/security.php"] [unique_id "al4Q7zAtbv2vrjByhUp7AQAAACk"]
[Mon Jul 20 06:13:35.612907 2026] [security2:error] [pid 858085:tid 858273] [client 57.141.18.41:30640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp55wAAORs"]
[Mon Jul 20 06:13:35.759219 2026] [security2:error] [pid 858085:tid 858293] [client 206.189.19.19:60844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q7zAtbv2vrjByhUp7CQAAAE0"]
[Mon Jul 20 06:13:35.760029 2026] [security2:error] [pid 843279:tid 843418] [client 178.152.178.232:37436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVQAAAI0"]
[Mon Jul 20 06:13:35.760139 2026] [security2:error] [pid 843279:tid 843418] [client 178.152.178.232:37436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVQAAAI0"]
[Mon Jul 20 06:13:35.798098 2026] [security2:error] [pid 843279:tid 843420] [client 27.96.94.195:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVgAAAI8"]
[Mon Jul 20 06:13:35.798269 2026] [security2:error] [pid 843279:tid 843420] [client 27.96.94.195:37442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q7_qvKNcW5yy5T2DAVgAAAI8"]
[Mon Jul 20 06:13:35.852041 2026] [security2:error] [pid 858085:tid 858265] [client 57.141.18.53:30362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q6zAtbv2vrjByhUp5-QAAMSo"]
[Mon Jul 20 06:13:35.926883 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:53254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4Q7zAtbv2vrjByhUp7DwAAAEk"], referer: http://massagelacey.com/WordPress
[Mon Jul 20 06:13:36.167476 2026] [security2:error] [pid 858085:tid 858280] [client 104.234.53.77:38709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7MgAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:36.399559 2026] [security2:error] [pid 858085:tid 858225] [client 206.189.19.19:60850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7NAAAAAk"]
[Mon Jul 20 06:13:36.627529 2026] [security2:error] [pid 858085:tid 858156] [remote 8.217.108.67:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q8DAtbv2vrjByhUp7UQAAEUU"]
[Mon Jul 20 06:13:36.801061 2026] [ssl:error] [pid 858085:tid 858220] [client 104.48.69.105:42328] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:13:36.854350 2026] [security2:error] [pid 858085:tid 858303] [client 14.225.17.146:60275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7WQAAAFc"]
[Mon Jul 20 06:13:36.921523 2026] [security2:error] [pid 858085:tid 858312] [client 57.141.18.76:34094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7DAtbv2vrjByhUp6QgAAYBc"]
[Mon Jul 20 06:13:37.034845 2026] [security2:error] [pid 858085:tid 858311] [client 206.189.19.19:60866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7XAAAAF8"]
[Mon Jul 20 06:13:37.234016 2026] [security2:error] [pid 843279:tid 843536] [client 14.225.17.146:49906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAfgAAAQI"], referer: http://claysharecon.com/WordPress
[Mon Jul 20 06:13:37.248909 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.73:55846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6YQAAHHA"]
[Mon Jul 20 06:13:37.365606 2026] [security2:error] [pid 843279:tid 843464] [client 185.132.186.55:32671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/include/install.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAgwAAALs"]
[Mon Jul 20 06:13:37.540601 2026] [security2:error] [pid 858085:tid 858183] [remote 8.217.108.67:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q8TAtbv2vrjByhUp7gAAAImA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:13:37.635357 2026] [security2:error] [pid 858085:tid 858282] [client 57.141.18.77:50046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7TAtbv2vrjByhUp6hQAAQhY"]
[Mon Jul 20 06:13:37.664153 2026] [security2:error] [pid 843279:tid 843497] [client 206.189.19.19:60880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAhwAAANw"]
[Mon Jul 20 06:13:37.895651 2026] [ssl:error] [pid 858085:tid 858308] [client 104.48.69.105:42336] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:13:37.986515 2026] [security2:error] [pid 858085:tid 858236] [client 57.141.18.22:57896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7jAtbv2vrjByhUp6nwAAFCY"]
[Mon Jul 20 06:13:38.301768 2026] [core:error] [pid 858085:tid 858304] [client 158.173.167.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:38.301793 2026] [core:error] [pid 858085:tid 858304] [client 158.173.167.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:13:38.342431 2026] [security2:error] [pid 843279:tid 843494] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q8vqvKNcW5yy5T2DAlQAAANk"]
[Mon Jul 20 06:13:38.434358 2026] [security2:error] [pid 858085:tid 858233] [client 113.160.97.242:57604] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Q8jAtbv2vrjByhUp7qwAAABE"]
[Mon Jul 20 06:13:38.783856 2026] [security2:error] [pid 858085:tid 858237] [client 65.1.132.125:55018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8jAtbv2vrjByhUp7vwAAABU"]
[Mon Jul 20 06:13:38.783952 2026] [security2:error] [pid 858085:tid 858237] [client 65.1.132.125:55018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8jAtbv2vrjByhUp7vwAAABU"]
[Mon Jul 20 06:13:39.154443 2026] [security2:error] [pid 858085:tid 858264] [client 57.141.18.59:32924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q7zAtbv2vrjByhUp67gAAMGI"]
[Mon Jul 20 06:13:39.258066 2026] [security2:error] [pid 858085:tid 858325] [client 50.116.65.227:35010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q8zAtbv2vrjByhUp75AAAAG0"]
[Mon Jul 20 06:13:39.271651 2026] [security2:error] [pid 858085:tid 858258] [client 50.116.65.227:57394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Q8zAtbv2vrjByhUp75gAAACo"]
[Mon Jul 20 06:13:39.312615 2026] [security2:error] [pid 858085:tid 858277] [client 185.132.186.104:48463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/gm.php"] [unique_id "al4Q8zAtbv2vrjByhUp76wAAAD0"]
[Mon Jul 20 06:13:39.332735 2026] [security2:error] [pid 858085:tid 858303] [client 14.225.17.146:53599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4Q8zAtbv2vrjByhUp71wAAAFc"], referer: http://myspineworld.com/WordPress
[Mon Jul 20 06:13:39.453718 2026] [security2:error] [pid 858085:tid 858287] [client 50.116.65.227:57408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Q8zAtbv2vrjByhUp78AAAAEc"]
[Mon Jul 20 06:13:39.463906 2026] [security2:error] [pid 843279:tid 843413] [client 50.116.65.227:57412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Q8_qvKNcW5yy5T2DAugAAAIg"]
[Mon Jul 20 06:13:39.955674 2026] [security2:error] [pid 858085:tid 858289] [client 103.77.203.233:55369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8zAtbv2vrjByhUp8CAAAAEk"]
[Mon Jul 20 06:13:39.955796 2026] [security2:error] [pid 858085:tid 858289] [client 103.77.203.233:55369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q8zAtbv2vrjByhUp8CAAAAEk"]
[Mon Jul 20 06:13:40.152729 2026] [security2:error] [pid 858085:tid 858327] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Q8zAtbv2vrjByhUp8BgAAAG8"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:13:40.238679 2026] [security2:error] [pid 843279:tid 843444] [client 104.234.53.86:32325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA0AAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:40.252436 2026] [security2:error] [pid 843279:tid 843311] [remote 217.61.143.92:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA0QAAtx4"]
[Mon Jul 20 06:13:40.329339 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:63386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Q9DAtbv2vrjByhUp8FQAAABk"], referer: https://myspineworld.com/WordPress
[Mon Jul 20 06:13:40.489474 2026] [security2:error] [pid 843279:tid 843396] [remote 217.61.143.92:48796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA2AAA_3M"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:13:40.566884 2026] [security2:error] [pid 858085:tid 858341] [client 57.141.18.82:25340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8DAtbv2vrjByhUp7UwAAfV8"]
[Mon Jul 20 06:13:40.738432 2026] [security2:error] [pid 858085:tid 858217] [client 14.225.17.146:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Q8zAtbv2vrjByhUp77wAAAAE"], referer: http://iagdevelopments.com/WordPress
[Mon Jul 20 06:13:40.832897 2026] [security2:error] [pid 843279:tid 843430] [client 57.141.18.57:44444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8PqvKNcW5yy5T2DAdwAAmRw"]
[Mon Jul 20 06:13:40.871142 2026] [security2:error] [pid 843279:tid 843317] [remote 217.61.143.92:48810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA5gAA8SQ"]
[Mon Jul 20 06:13:40.871374 2026] [security2:error] [pid 843279:tid 843519] [client 217.61.143.92:48810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q9PqvKNcW5yy5T2DA5gAA8SQ"]
[Mon Jul 20 06:13:41.066595 2026] [security2:error] [pid 858085:tid 858337] [client 57.141.18.94:46424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8TAtbv2vrjByhUp7bwAAeWs"]
[Mon Jul 20 06:13:41.278731 2026] [security2:error] [pid 843279:tid 843449] [client 185.132.186.71:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-language-pack.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA7gAAAKw"]
[Mon Jul 20 06:13:41.345659 2026] [security2:error] [pid 843279:tid 843486] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA7AAAANE"]
[Mon Jul 20 06:13:41.688835 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:50959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Q9TAtbv2vrjByhUp8YwAAADY"], referer: https://iagdevelopments.com/WordPress
[Mon Jul 20 06:13:41.762780 2026] [security2:error] [pid 858085:tid 858294] [client 206.189.19.19:42420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.19.189.206.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/info.php"] [unique_id "al4Q9TAtbv2vrjByhUp8dgAAAE4"]
[Mon Jul 20 06:13:41.763110 2026] [security2:error] [pid 843279:tid 843461] [client 57.141.18.22:56384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8fqvKNcW5yy5T2DAkQAAuAg"]
[Mon Jul 20 06:13:41.924566 2026] [security2:error] [pid 843279:tid 843447] [client 57.141.18.92:32306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8vqvKNcW5yy5T2DAnAAAqhE"]
[Mon Jul 20 06:13:42.292071 2026] [security2:error] [pid 843279:tid 843472] [client 14.225.17.146:57633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4Q9vqvKNcW5yy5T2DA_wAAAMM"], referer: http://xp-design.co/WordPress
[Mon Jul 20 06:13:42.434871 2026] [security2:error] [pid 843279:tid 843466] [client 181.224.94.124:38962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9vqvKNcW5yy5T2DBDwAAAL0"]
[Mon Jul 20 06:13:42.435027 2026] [security2:error] [pid 843279:tid 843466] [client 181.224.94.124:38962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9vqvKNcW5yy5T2DBDwAAAL0"]
[Mon Jul 20 06:13:42.750327 2026] [security2:error] [pid 843279:tid 843422] [client 57.141.18.17:37230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q8_qvKNcW5yy5T2DAtwAAkUI"]
[Mon Jul 20 06:13:43.021015 2026] [security2:error] [pid 843279:tid 843533] [client 171.60.139.123:53847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBKAAAAP8"]
[Mon Jul 20 06:13:43.024507 2026] [security2:error] [pid 843279:tid 843533] [client 171.60.139.123:53847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBKAAAAP8"]
[Mon Jul 20 06:13:43.222476 2026] [security2:error] [pid 858085:tid 858286] [client 185.132.186.58:32795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/content-type.php"] [unique_id "al4Q9zAtbv2vrjByhUp8uQAAAEY"]
[Mon Jul 20 06:13:43.271204 2026] [security2:error] [pid 843279:tid 843530] [client 14.225.17.146:50975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA9gAAAPw"], referer: http://cephasnext.com/WordPress
[Mon Jul 20 06:13:43.497866 2026] [security2:error] [pid 858085:tid 858253] [client 14.225.17.146:53836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Q9zAtbv2vrjByhUp8wAAAACU"], referer: http://sesamegreenbeans.com/WordPress
[Mon Jul 20 06:13:43.671962 2026] [security2:error] [pid 858085:tid 858303] [client 57.141.18.121:62622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q9DAtbv2vrjByhUp8HQAAVzk"]
[Mon Jul 20 06:13:43.770138 2026] [security2:error] [pid 843279:tid 843437] [client 175.44.42.146:54526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBMwAAALM"], referer: http://www.osdzc.com/
[Mon Jul 20 06:13:43.801458 2026] [security2:error] [pid 858085:tid 858247] [client 106.192.104.4:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9zAtbv2vrjByhUp83wAAAB8"]
[Mon Jul 20 06:13:43.805450 2026] [security2:error] [pid 858085:tid 858247] [client 106.192.104.4:51090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Q9zAtbv2vrjByhUp83wAAAB8"]
[Mon Jul 20 06:13:43.998972 2026] [security2:error] [pid 843279:tid 843476] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBOgAAAMc"]
[Mon Jul 20 06:13:44.034865 2026] [security2:error] [pid 843279:tid 843414] [client 99.245.0.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Q9_qvKNcW5yy5T2DBOAAAiUo"]
[Mon Jul 20 06:13:44.408562 2026] [security2:error] [pid 843279:tid 843440] [client 57.141.18.84:22762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q9fqvKNcW5yy5T2DA6gAAoyE"]
[Mon Jul 20 06:13:44.463568 2026] [security2:error] [pid 858085:tid 858143] [remote 52.167.144.168:9915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4Q-DAtbv2vrjByhUp9DgAAHjg"]
[Mon Jul 20 06:13:44.527806 2026] [security2:error] [pid 858085:tid 858265] [client 14.225.17.146:64807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Q-DAtbv2vrjByhUp9CwAAADE"], referer: https://sesamegreenbeans.com/WordPress
[Mon Jul 20 06:13:44.677563 2026] [security2:error] [pid 858085:tid 858340] [client 14.225.17.146:52921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4Q9zAtbv2vrjByhUp8xAAAAHw"], referer: http://hammadownenterprises.com/WordPress
[Mon Jul 20 06:13:44.709968 2026] [security2:error] [pid 843279:tid 843392] [remote 173.249.4.11:35752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q-PqvKNcW5yy5T2DBSwAAuG8"]
[Mon Jul 20 06:13:44.710151 2026] [security2:error] [pid 843279:tid 843461] [client 173.249.4.11:35752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Q-PqvKNcW5yy5T2DBSwAAuG8"]
[Mon Jul 20 06:13:44.754916 2026] [security2:error] [pid 858085:tid 858324] [client 41.173.37.102:8349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-DAtbv2vrjByhUp9HAAAAGw"]
[Mon Jul 20 06:13:44.755036 2026] [security2:error] [pid 858085:tid 858324] [client 41.173.37.102:8349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-DAtbv2vrjByhUp9HAAAAGw"]
[Mon Jul 20 06:13:44.994878 2026] [security2:error] [pid 858085:tid 858339] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q-DAtbv2vrjByhUp9IwAAAHs"]
[Mon Jul 20 06:13:45.032701 2026] [security2:error] [pid 858085:tid 858310] [client 103.141.108.143:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9LQAAAF4"]
[Mon Jul 20 06:13:45.032913 2026] [security2:error] [pid 858085:tid 858310] [client 103.141.108.143:63830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9LQAAAF4"]
[Mon Jul 20 06:13:45.173646 2026] [security2:error] [pid 858085:tid 858227] [client 185.132.186.72:58041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-walker-comment-client.php"] [unique_id "al4Q-TAtbv2vrjByhUp9OgAAAAs"]
[Mon Jul 20 06:13:45.374946 2026] [security2:error] [pid 858085:tid 858090] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9SgAAZgM"]
[Mon Jul 20 06:13:45.375106 2026] [security2:error] [pid 858085:tid 858318] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9SgAAZgM"]
[Mon Jul 20 06:13:45.614642 2026] [security2:error] [pid 858085:tid 858343] [client 14.225.17.146:54086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9SAAAAH8"], referer: http://tacticaltreeoperations.com/WordPress
[Mon Jul 20 06:13:45.664880 2026] [security2:error] [pid 858085:tid 858265] [client 112.213.160.112:31066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WAAAADE"]
[Mon Jul 20 06:13:45.665001 2026] [security2:error] [pid 858085:tid 858265] [client 112.213.160.112:31066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WAAAADE"]
[Mon Jul 20 06:13:45.725892 2026] [security2:error] [pid 858085:tid 858307] [client 45.116.69.230:60767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WgAAAFs"]
[Mon Jul 20 06:13:45.726006 2026] [security2:error] [pid 858085:tid 858307] [client 45.116.69.230:60767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WgAAAFs"]
[Mon Jul 20 06:13:45.871421 2026] [security2:error] [pid 843279:tid 843351] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-fqvKNcW5yy5T2DBaQAA00Y"]
[Mon Jul 20 06:13:45.871613 2026] [security2:error] [pid 843279:tid 843488] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Q-fqvKNcW5yy5T2DBaQAA00Y"]
[Mon Jul 20 06:13:46.009172 2026] [security2:error] [pid 858085:tid 858223] [client 27.96.94.195:37680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9cQAAAAc"]
[Mon Jul 20 06:13:46.009354 2026] [security2:error] [pid 858085:tid 858223] [client 27.96.94.195:37680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9cQAAAAc"]
[Mon Jul 20 06:13:46.030233 2026] [lsapi:warn] [pid 858085:tid 858245] [client 14.225.17.146:60923] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:46.030267 2026] [lsapi:warn] [pid 858085:tid 858245] [client 14.225.17.146:60923] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:46.038372 2026] [security2:error] [pid 858085:tid 858290] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9ZAAAAEo"]
[Mon Jul 20 06:13:46.040011 2026] [security2:error] [pid 843279:tid 843530] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-fqvKNcW5yy5T2DBZwAAAPw"], referer: http://adastra.love/dashboard
[Mon Jul 20 06:13:46.125080 2026] [lsapi:warn] [pid 858085:tid 858238] [client 50.116.65.227:57506] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:46.125120 2026] [lsapi:warn] [pid 858085:tid 858238] [client 50.116.65.227:57506] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:46.140237 2026] [security2:error] [pid 858085:tid 858245] [client 14.225.17.146:60923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Q-jAtbv2vrjByhUp9cwAAAB0"], referer: http://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:46.150460 2026] [security2:error] [pid 858085:tid 858283] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9bAAAAEM"], referer: http://adastra.love/admin
[Mon Jul 20 06:13:46.161998 2026] [security2:error] [pid 858085:tid 858335] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9bQAAAHc"], referer: http://adastra.love/login
[Mon Jul 20 06:13:46.256060 2026] [security2:error] [pid 858085:tid 858308] [client 104.28.249.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9bwAAAFw"], referer: http://adastra.love/console
[Mon Jul 20 06:13:46.485422 2026] [security2:error] [pid 843279:tid 843458] [client 216.73.217.138:56706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Q-vqvKNcW5yy5T2DBdgAAtQw"]
[Mon Jul 20 06:13:46.619315 2026] [security2:error] [pid 858085:tid 858282] [client 178.152.178.232:36752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9kQAAAEI"]
[Mon Jul 20 06:13:46.619464 2026] [security2:error] [pid 858085:tid 858282] [client 178.152.178.232:36752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Q-jAtbv2vrjByhUp9kQAAAEI"]
[Mon Jul 20 06:13:47.040495 2026] [security2:error] [pid 843279:tid 843422] [client 185.132.186.77:59303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/about/goods.php"] [unique_id "al4Q-_qvKNcW5yy5T2DBlgAAAJE"]
[Mon Jul 20 06:13:47.052114 2026] [lsapi:warn] [pid 858085:tid 858294] [client 14.225.17.146:54148] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:47.052136 2026] [lsapi:warn] [pid 858085:tid 858294] [client 14.225.17.146:54148] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:47.125822 2026] [lsapi:warn] [pid 858085:tid 858314] [client 50.116.65.227:57534] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:47.125849 2026] [lsapi:warn] [pid 858085:tid 858314] [client 50.116.65.227:57534] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:13:47.136438 2026] [security2:error] [pid 858085:tid 858294] [client 14.225.17.146:54148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp9rwAAAE4"], referer: https://oswegooperatheater.com/WordPress
[Mon Jul 20 06:13:47.334860 2026] [security2:error] [pid 843279:tid 843474] [client 50.116.65.227:35050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4Q-_qvKNcW5yy5T2DBmwAAAMU"]
[Mon Jul 20 06:13:47.343139 2026] [security2:error] [pid 858085:tid 858245] [client 14.225.17.146:53456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp9uwAAAB0"], referer: http://mcg.homes/WordPress
[Mon Jul 20 06:13:47.346538 2026] [security2:error] [pid 843279:tid 843417] [client 50.116.65.227:57550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4Q-_qvKNcW5yy5T2DBnAAAAIw"]
[Mon Jul 20 06:13:47.389951 2026] [security2:error] [pid 858085:tid 858326] [client 14.225.17.146:64931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4Q-TAtbv2vrjByhUp9WQAAAG4"], referer: http://koaconsultants.com/WordPress
[Mon Jul 20 06:13:47.832619 2026] [security2:error] [pid 858085:tid 858341] [client 45.157.112.60:21303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Q-zAtbv2vrjByhUp92gAAAH0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:48.011601 2026] [security2:error] [pid 858085:tid 858301] [client 14.225.17.146:59474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp92wAAAFU"], referer: http://detroitcsc.com/WordPress
[Mon Jul 20 06:13:48.432426 2026] [security2:error] [pid 843279:tid 843411] [client 63.135.161.174:26827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.161.135.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4Q_PqvKNcW5yy5T2DBuAAAAIY"], referer: https://www.bing.com/
[Mon Jul 20 06:13:48.487002 2026] [security2:error] [pid 843279:tid 843523] [client 52.233.165.60:3584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Q_PqvKNcW5yy5T2DBuwAAAPU"]
[Mon Jul 20 06:13:48.524490 2026] [security2:error] [pid 843279:tid 843452] [client 14.225.17.146:54136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4Q-vqvKNcW5yy5T2DBkgAAAK8"], referer: http://reosportsboats.com/WordPress
[Mon Jul 20 06:13:48.565611 2026] [security2:error] [pid 858085:tid 858312] [client 14.225.17.146:53109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4Q-jAtbv2vrjByhUp9pwAAAGA"], referer: http://swafforddetailing.com/WordPress
[Mon Jul 20 06:13:48.635674 2026] [security2:error] [pid 843279:tid 843431] [client 52.233.165.60:3584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Q_PqvKNcW5yy5T2DBvgAAAJo"]
[Mon Jul 20 06:13:48.842843 2026] [security2:error] [pid 858085:tid 858341] [client 185.132.186.61:48625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/file/function.php"] [unique_id "al4Q_DAtbv2vrjByhUp-CgAAAH0"]
[Mon Jul 20 06:13:48.893832 2026] [security2:error] [pid 858085:tid 858322] [client 51.143.183.75:24257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Q_DAtbv2vrjByhUp-EwAAAGo"]
[Mon Jul 20 06:13:49.026952 2026] [security2:error] [pid 858085:tid 858226] [client 51.143.183.75:24257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Q_TAtbv2vrjByhUp-HgAAAAo"]
[Mon Jul 20 06:13:49.043178 2026] [security2:error] [pid 858085:tid 858284] [client 50.116.65.227:11544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Q_TAtbv2vrjByhUp-IAAAAEQ"]
[Mon Jul 20 06:13:49.053170 2026] [security2:error] [pid 858085:tid 858245] [client 50.116.65.227:11558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Q_TAtbv2vrjByhUp-IgAAAB0"]
[Mon Jul 20 06:13:49.489446 2026] [security2:error] [pid 858085:tid 858231] [client 14.225.17.146:53488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-NQAAAA8"], referer: https://reosportsboats.com/WordPress
[Mon Jul 20 06:13:49.568352 2026] [security2:error] [pid 858085:tid 858095] [remote 162.19.86.63:42812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-QAAAZAg"]
[Mon Jul 20 06:13:49.576142 2026] [security2:error] [pid 858085:tid 858092] [remote 152.228.213.32:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-PwAAKQU"]
[Mon Jul 20 06:13:49.584361 2026] [security2:error] [pid 858085:tid 858267] [client 43.205.139.3:38144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_TAtbv2vrjByhUp-RwAAADM"]
[Mon Jul 20 06:13:49.584457 2026] [security2:error] [pid 858085:tid 858267] [client 43.205.139.3:38144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_TAtbv2vrjByhUp-RwAAADM"]
[Mon Jul 20 06:13:49.761652 2026] [security2:error] [pid 858085:tid 858334] [client 206.189.19.19:35058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/"] [unique_id "al4Q_TAtbv2vrjByhUp-VAAAAHY"]
[Mon Jul 20 06:13:49.763977 2026] [security2:error] [pid 858085:tid 858111] [remote 152.228.213.32:39242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-UgAADhg"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:13:49.785142 2026] [security2:error] [pid 858085:tid 858091] [remote 162.19.86.63:42812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4Q_TAtbv2vrjByhUp-VQAAWQQ"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:13:50.075293 2026] [security2:error] [pid 843279:tid 843473] [client 14.225.17.146:58543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Q_PqvKNcW5yy5T2DBvwAAAMQ"], referer: http://colinkeyphotography.com/WordPress
[Mon Jul 20 06:13:50.414051 2026] [security2:error] [pid 858085:tid 858293] [client 74.7.230.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-NgAAAE0"]
[Mon Jul 20 06:13:50.425862 2026] [security2:error] [pid 858085:tid 858319] [client 74.7.230.53:44466] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "abilite.uk"] [uri "/robots.txt"] [unique_id "al4Q_TAtbv2vrjByhUp-MQAAZ3U"]
[Mon Jul 20 06:13:50.515353 2026] [security2:error] [pid 858085:tid 858283] [client 103.77.203.233:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_jAtbv2vrjByhUp-eQAAAEM"]
[Mon Jul 20 06:13:50.515524 2026] [security2:error] [pid 858085:tid 858283] [client 103.77.203.233:55910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Q_jAtbv2vrjByhUp-eQAAAEM"]
[Mon Jul 20 06:13:50.544635 2026] [security2:error] [pid 858085:tid 858320] [client 114.119.144.64:52899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.koaconsultants.com"] [uri "/robots.txt"] [unique_id "al4Q_jAtbv2vrjByhUp-fAAAAGg"], referer: http://www.koaconsultants.com/robots.txt
[Mon Jul 20 06:13:50.641956 2026] [security2:error] [pid 843279:tid 843485] [client 185.132.186.53:23159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/function/goods.php"] [unique_id "al4Q_vqvKNcW5yy5T2DB6wAAANA"]
[Mon Jul 20 06:13:50.660958 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.69:43088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp9tgAABVw"]
[Mon Jul 20 06:13:50.769317 2026] [security2:error] [pid 843279:tid 843513] [client 206.189.19.19:35066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/"] [unique_id "al4Q_vqvKNcW5yy5T2DB8gAAAOs"]
[Mon Jul 20 06:13:50.807368 2026] [security2:error] [pid 858085:tid 858277] [client 63.135.161.171:22467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.161.135.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4Q_jAtbv2vrjByhUp-iQAAAD0"]
[Mon Jul 20 06:13:50.996022 2026] [security2:error] [pid 858085:tid 858289] [client 14.225.17.146:58432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4Q_jAtbv2vrjByhUp-kQAAAEk"], referer: http://eduardsales.com/WordPress
[Mon Jul 20 06:13:51.179965 2026] [security2:error] [pid 843279:tid 843510] [client 14.225.17.146:50221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Q__qvKNcW5yy5T2DB-wAAAOg"], referer: http://alaraycreative.com/WordPress
[Mon Jul 20 06:13:51.440118 2026] [security2:error] [pid 858085:tid 858251] [client 57.141.18.76:34576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q-zAtbv2vrjByhUp93QAAI14"]
[Mon Jul 20 06:13:51.583494 2026] [security2:error] [pid 858085:tid 858283] [client 104.28.249.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q_zAtbv2vrjByhUp-qAAAAEM"], referer: http://adastra.love/app
[Mon Jul 20 06:13:51.598293 2026] [security2:error] [pid 858085:tid 858315] [client 104.28.249.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4Q_zAtbv2vrjByhUp-qgAAAGM"], referer: http://adastra.love/settings
[Mon Jul 20 06:13:51.769847 2026] [security2:error] [pid 858085:tid 858275] [client 206.189.19.19:35068] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/wp-json/batch/v1"] [unique_id "al4Q_zAtbv2vrjByhUp-wQAAADs"]
[Mon Jul 20 06:13:51.827209 2026] [security2:error] [pid 858085:tid 858269] [client 57.141.18.95:52458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_DAtbv2vrjByhUp98AAANXc"]
[Mon Jul 20 06:13:51.903020 2026] [autoindex:error] [pid 843279:tid 843470] [client 167.86.82.167:51748] AH01276: Cannot serve directory /home1/zanjanfr/public_html/terrapro/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:13:52.127732 2026] [security2:error] [pid 858085:tid 858238] [client 14.225.17.146:58471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-LgAAABY"], referer: http://gearwaterproof.com/WordPress
[Mon Jul 20 06:13:52.303895 2026] [security2:error] [pid 858085:tid 858297] [client 74.7.227.179:39966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RADAtbv2vrjByhUp-4gAAURI"], referer: https://tejasenvironmental.com/p=721097
[Mon Jul 20 06:13:52.349041 2026] [security2:error] [pid 858085:tid 858281] [client 57.141.18.100:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_DAtbv2vrjByhUp-CwAAQR4"]
[Mon Jul 20 06:13:52.410109 2026] [security2:error] [pid 843279:tid 843457] [client 66.249.73.68:52408] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "w.saphansiam.org"] [uri "/robots.txt"] [unique_id "al4RAPqvKNcW5yy5T2DCGQAAALQ"]
[Mon Jul 20 06:13:52.438542 2026] [security2:error] [pid 858085:tid 858277] [client 185.132.186.64:44693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/bypass.php"] [unique_id "al4RADAtbv2vrjByhUp-7QAAAD0"]
[Mon Jul 20 06:13:52.530803 2026] [security2:error] [pid 858085:tid 858282] [client 158.173.166.181:21279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RADAtbv2vrjByhUp-8wAAAEI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:52.600733 2026] [security2:error] [pid 858085:tid 858259] [client 51.68.236.64:15187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4RADAtbv2vrjByhUp-_QAAACs"]
[Mon Jul 20 06:13:52.600844 2026] [security2:error] [pid 858085:tid 858259] [client 51.68.236.64:15187] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4RADAtbv2vrjByhUp-_QAAACs"]
[Mon Jul 20 06:13:52.769909 2026] [security2:error] [pid 858085:tid 858271] [client 206.189.19.19:35070] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/wp-json/batch/v1"] [unique_id "al4RADAtbv2vrjByhUp_BQAAADc"]
[Mon Jul 20 06:13:52.941859 2026] [security2:error] [pid 858085:tid 858339] [client 181.224.94.124:6956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RADAtbv2vrjByhUp_DgAAAHs"]
[Mon Jul 20 06:13:52.942047 2026] [security2:error] [pid 858085:tid 858339] [client 181.224.94.124:6956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RADAtbv2vrjByhUp_DgAAAHs"]
[Mon Jul 20 06:13:53.049786 2026] [security2:error] [pid 858085:tid 858314] [client 57.141.18.80:39062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_TAtbv2vrjByhUp-PAAAYg8"]
[Mon Jul 20 06:13:53.094933 2026] [security2:error] [pid 843279:tid 843411] [client 14.225.17.146:53493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4Q_vqvKNcW5yy5T2DB9wAAAIY"], referer: http://younutrition.gr/WordPress
[Mon Jul 20 06:13:53.566399 2026] [security2:error] [pid 858085:tid 858248] [client 14.225.17.146:59338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4RADAtbv2vrjByhUp-1gAAACA"], referer: http://headachescarpaltunnelfibromyalgia.com/WordPress
[Mon Jul 20 06:13:53.588244 2026] [security2:error] [pid 843279:tid 843419] [client 57.141.18.118:37402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_vqvKNcW5yy5T2DB4AAAjmQ"]
[Mon Jul 20 06:13:53.768846 2026] [security2:error] [pid 858085:tid 858312] [client 171.60.139.123:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RATAtbv2vrjByhUp_NgAAAGA"]
[Mon Jul 20 06:13:53.768974 2026] [security2:error] [pid 858085:tid 858312] [client 171.60.139.123:54323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RATAtbv2vrjByhUp_NgAAAGA"]
[Mon Jul 20 06:13:53.867194 2026] [security2:error] [pid 858085:tid 858333] [client 104.234.53.50:39445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RATAtbv2vrjByhUp_PwAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:54.239972 2026] [security2:error] [pid 858085:tid 858253] [client 185.132.186.84:21247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_WAAAACU"]
[Mon Jul 20 06:13:54.265935 2026] [security2:error] [pid 858085:tid 858252] [client 57.141.18.94:33050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Q_jAtbv2vrjByhUp-jwAAJFM"]
[Mon Jul 20 06:13:54.438014 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_XAAAAAU"]
[Mon Jul 20 06:13:54.758454 2026] [security2:error] [pid 858085:tid 858315] [client 106.192.104.4:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RAjAtbv2vrjByhUp_gQAAAGM"]
[Mon Jul 20 06:13:54.758555 2026] [security2:error] [pid 858085:tid 858315] [client 106.192.104.4:51785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RAjAtbv2vrjByhUp_gQAAAGM"]
[Mon Jul 20 06:13:54.825505 2026] [security2:error] [pid 858085:tid 858341] [client 104.234.53.47:49799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RAjAtbv2vrjByhUp_hAAAAH0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:55.219470 2026] [security2:error] [pid 858085:tid 858255] [client 50.116.65.227:36564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RAzAtbv2vrjByhUp_ngAAACc"]
[Mon Jul 20 06:13:55.231417 2026] [security2:error] [pid 858085:tid 858306] [client 206.189.19.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.awj.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_jAAAAFo"]
[Mon Jul 20 06:13:55.235696 2026] [security2:error] [pid 843279:tid 843420] [client 50.116.65.227:11678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RA_qvKNcW5yy5T2DCUAAAAI8"]
[Mon Jul 20 06:13:55.381326 2026] [security2:error] [pid 843279:tid 843427] [client 14.225.17.146:60000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4RA_qvKNcW5yy5T2DCUQAAAJY"], referer: http://alchemygroup.ca/WordPress
[Mon Jul 20 06:13:55.389348 2026] [security2:error] [pid 858085:tid 858260] [client 41.173.37.102:8807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_qgAAACw"]
[Mon Jul 20 06:13:55.389458 2026] [security2:error] [pid 858085:tid 858260] [client 41.173.37.102:8807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_qgAAACw"]
[Mon Jul 20 06:13:55.732280 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:64314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vAAAAHU"]
[Mon Jul 20 06:13:55.732865 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:64314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vAAAAHU"]
[Mon Jul 20 06:13:55.758454 2026] [security2:error] [pid 858085:tid 858122] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vgAAHSM"]
[Mon Jul 20 06:13:55.758573 2026] [security2:error] [pid 858085:tid 858245] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RAzAtbv2vrjByhUp_vgAAHSM"]
[Mon Jul 20 06:13:55.928693 2026] [security2:error] [pid 858085:tid 858253] [client 104.234.53.47:52495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RAzAtbv2vrjByhUp_xQAAACU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:13:55.941520 2026] [security2:error] [pid 858085:tid 858318] [client 57.141.18.106:55998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RADAtbv2vrjByhUp--AAAZig"]
[Mon Jul 20 06:13:56.030708 2026] [security2:error] [pid 858085:tid 858302] [client 185.132.186.104:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-network-query-stat.php"] [unique_id "al4RBDAtbv2vrjByhUp_ywAAAFY"]
[Mon Jul 20 06:13:56.359470 2026] [security2:error] [pid 858085:tid 858339] [client 14.225.17.146:58993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_hQAAAHs"], referer: http://phillipbloch.com/WordPress
[Mon Jul 20 06:13:56.363608 2026] [security2:error] [pid 858085:tid 858338] [client 112.213.160.112:30893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RBDAtbv2vrjByhUp_4AAAAHo"]
[Mon Jul 20 06:13:56.363710 2026] [security2:error] [pid 858085:tid 858338] [client 112.213.160.112:30893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RBDAtbv2vrjByhUp_4AAAAHo"]
[Mon Jul 20 06:13:56.363896 2026] [security2:error] [pid 843279:tid 843524] [client 45.116.69.230:61274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCbgAAAPY"]
[Mon Jul 20 06:13:56.364000 2026] [security2:error] [pid 843279:tid 843524] [client 45.116.69.230:61274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCbgAAAPY"]
[Mon Jul 20 06:13:56.544825 2026] [security2:error] [pid 858085:tid 858142] [remote 103.75.185.95:44058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4RBDAtbv2vrjByhUp_6QAADzc"]
[Mon Jul 20 06:13:56.551249 2026] [security2:error] [pid 843279:tid 843305] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCcwAArxg"]
[Mon Jul 20 06:13:56.551408 2026] [security2:error] [pid 843279:tid 843452] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RBPqvKNcW5yy5T2DCcwAArxg"]
[Mon Jul 20 06:13:56.558938 2026] [security2:error] [pid 858085:tid 858290] [client 57.141.18.85:26078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RATAtbv2vrjByhUp_HAAASiU"]
[Mon Jul 20 06:13:56.901535 2026] [security2:error] [pid 858085:tid 858289] [client 57.141.18.49:63666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RATAtbv2vrjByhUp_LAAASWQ"]
[Mon Jul 20 06:13:57.242656 2026] [security2:error] [pid 858085:tid 858140] [remote 110.249.202.99:53114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/REV-legal-memo-litigation-background-criteria-june-2020.pdf"] [unique_id "al4RBTAtbv2vrjByhUqAEAAAQjU"]
[Mon Jul 20 06:13:57.303847 2026] [security2:error] [pid 858085:tid 858302] [client 158.173.89.95:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RBTAtbv2vrjByhUqAFAAAAFY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:57.527737 2026] [security2:error] [pid 858085:tid 858141] [remote 103.75.185.95:44058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4RBTAtbv2vrjByhUqAJQAAPTY"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:13:57.608100 2026] [security2:error] [pid 858085:tid 858273] [client 57.141.18.13:48400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_WQAAOXY"]
[Mon Jul 20 06:13:57.652213 2026] [security2:error] [pid 858085:tid 858226] [client 27.96.94.195:37055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RBTAtbv2vrjByhUqANwAAAAo"]
[Mon Jul 20 06:13:57.652377 2026] [security2:error] [pid 858085:tid 858226] [client 27.96.94.195:37055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RBTAtbv2vrjByhUqANwAAAAo"]
[Mon Jul 20 06:13:57.703042 2026] [security2:error] [pid 858085:tid 858316] [client 14.225.17.146:58804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4RBTAtbv2vrjByhUqAGwAAAGQ"], referer: http://webgardensbypaula.com/WordPress
[Mon Jul 20 06:13:57.704284 2026] [security2:error] [pid 858085:tid 858249] [client 14.225.17.146:53362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4RBTAtbv2vrjByhUqAIAAAACE"], referer: http://ccsdifference.com/WordPress
[Mon Jul 20 06:13:57.828416 2026] [security2:error] [pid 843279:tid 843443] [client 185.132.186.74:59641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al4RBfqvKNcW5yy5T2DCigAAAKY"]
[Mon Jul 20 06:13:57.832816 2026] [security2:error] [pid 858085:tid 858176] [remote 100.42.189.89:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4RBTAtbv2vrjByhUqAPAAANVk"]
[Mon Jul 20 06:13:57.853308 2026] [security2:error] [pid 858085:tid 858267] [client 57.141.18.38:36138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RAjAtbv2vrjByhUp_bgAAM34"]
[Mon Jul 20 06:13:57.933294 2026] [security2:error] [pid 843279:tid 843489] [client 103.153.183.69:3802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fsrv/.env"] [unique_id "al4RBfqvKNcW5yy5T2DCiwAAANQ"], referer: https://twitter.com/
[Mon Jul 20 06:13:58.024866 2026] [security2:error] [pid 843279:tid 843536] [client 103.153.183.69:3802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fhome/.env"] [unique_id "al4RBvqvKNcW5yy5T2DCjQAAAQI"], referer: https://duckduckgo.com/?q=8xmzn
[Mon Jul 20 06:13:58.103846 2026] [security2:error] [pid 858085:tid 858129] [remote 100.42.189.89:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4RBjAtbv2vrjByhUqARgAAACo"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 06:13:58.629099 2026] [security2:error] [pid 858085:tid 858317] [client 57.141.18.86:29370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RAzAtbv2vrjByhUp_qQAAZXo"]
[Mon Jul 20 06:13:58.735854 2026] [security2:error] [pid 843279:tid 843432] [client 14.225.17.146:64838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4RBvqvKNcW5yy5T2DCpwAAAJs"], referer: https://ccsdifference.com/WordPress
[Mon Jul 20 06:13:58.926905 2026] [security2:error] [pid 858085:tid 858326] [client 50.116.65.227:56626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RBjAtbv2vrjByhUqAcAAAAG4"]
[Mon Jul 20 06:13:58.935507 2026] [security2:error] [pid 858085:tid 858238] [client 50.116.65.227:56634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RBjAtbv2vrjByhUqAcQAAABY"]
[Mon Jul 20 06:13:59.451493 2026] [security2:error] [pid 858085:tid 858322] [client 57.141.18.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAhQAAAGo"]
[Mon Jul 20 06:13:59.721103 2026] [security2:error] [pid 858085:tid 858279] [client 98.159.234.160:29495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RBzAtbv2vrjByhUqAoQAAAD8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:13:59.805945 2026] [security2:error] [pid 858085:tid 858275] [client 57.141.18.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAmwAAADs"]
[Mon Jul 20 06:13:59.825559 2026] [security2:error] [pid 843279:tid 843462] [client 57.141.18.103:51902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBPqvKNcW5yy5T2DCbwAAuUI"]
[Mon Jul 20 06:14:00.529445 2026] [security2:error] [pid 858085:tid 858216] [client 43.205.139.3:14470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RCDAtbv2vrjByhUqAzQAAAAA"]
[Mon Jul 20 06:14:00.529557 2026] [security2:error] [pid 858085:tid 858216] [client 43.205.139.3:14470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RCDAtbv2vrjByhUqAzQAAAAA"]
[Mon Jul 20 06:14:00.548969 2026] [security2:error] [pid 858085:tid 858114] [remote 51.222.168.34:33632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.californiaperfumecompany.com"] [uri "/collector/cal_questions.html"] [unique_id "al4RCDAtbv2vrjByhUqAzgAAaBs"]
[Mon Jul 20 06:14:00.549208 2026] [security2:error] [pid 858085:tid 858320] [client 51.222.168.34:33632] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.californiaperfumecompany.com"] [uri "/collector/cal_questions.html"] [unique_id "al4RCDAtbv2vrjByhUqAzgAAaBs"]
[Mon Jul 20 06:14:00.640853 2026] [security2:error] [pid 858085:tid 858298] [client 185.132.186.59:49487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/plugin-install.php"] [unique_id "al4RCDAtbv2vrjByhUqA0QAAAFI"]
[Mon Jul 20 06:14:00.982563 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RCPqvKNcW5yy5T2DC3QAAAJA"]
[Mon Jul 20 06:14:00.982674 2026] [security2:error] [pid 843279:tid 843421] [client 103.77.203.233:56455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RCPqvKNcW5yy5T2DC3QAAAJA"]
[Mon Jul 20 06:14:01.058962 2026] [security2:error] [pid 858085:tid 858232] [client 14.225.17.146:52410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqA3wAAABA"], referer: http://cheesewithjam.com/WordPress
[Mon Jul 20 06:14:01.107166 2026] [security2:error] [pid 858085:tid 858301] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqA2wAAAFU"]
[Mon Jul 20 06:14:01.206422 2026] [security2:error] [pid 858085:tid 858163] [remote 91.142.222.105:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4RCTAtbv2vrjByhUqA_gAAc0w"]
[Mon Jul 20 06:14:01.430179 2026] [security2:error] [pid 843279:tid 843470] [client 14.225.17.146:61621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4RCPqvKNcW5yy5T2DCzwAAAME"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WordPress
[Mon Jul 20 06:14:01.524322 2026] [security2:error] [pid 858085:tid 858192] [remote 91.142.222.105:43272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4RCTAtbv2vrjByhUqBFwAAaWk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:14:01.698047 2026] [security2:error] [pid 843279:tid 843446] [client 14.225.17.146:64845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4RB_qvKNcW5yy5T2DCvgAAAKk"], referer: http://guidehunting.com/WordPress
[Mon Jul 20 06:14:01.775669 2026] [security2:error] [pid 858085:tid 858230] [client 14.225.17.146:51401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4RCTAtbv2vrjByhUqBAAAAAA4"], referer: http://waterproofgoods.com/WordPress
[Mon Jul 20 06:14:02.446643 2026] [security2:error] [pid 858085:tid 858231] [client 185.132.186.104:42503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-session-tokens-https.php"] [unique_id "al4RCjAtbv2vrjByhUqBUAAAAA8"]
[Mon Jul 20 06:14:02.451134 2026] [security2:error] [pid 843279:tid 843427] [client 76.179.33.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RCvqvKNcW5yy5T2DDBAAAAJY"], referer: https://www.secretkeynumerology.com/8-ball/
[Mon Jul 20 06:14:02.477805 2026] [security2:error] [pid 858085:tid 858343] [client 50.116.65.227:19780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4RCjAtbv2vrjByhUqBUwAAAH8"]
[Mon Jul 20 06:14:02.492426 2026] [security2:error] [pid 858085:tid 858233] [client 50.116.65.227:56716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4RCjAtbv2vrjByhUqBVgAAAC8"]
[Mon Jul 20 06:14:02.555709 2026] [security2:error] [pid 843279:tid 843410] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4RCvqvKNcW5yy5T2DDBwAAhXA"], referer: http://assasalnazaha.com/WordPress
[Mon Jul 20 06:14:02.612608 2026] [security2:error] [pid 858085:tid 858290] [client 14.225.17.146:51883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4RCjAtbv2vrjByhUqBRwAAAEo"], referer: http://latiendadejorge.com.gt/WordPress
[Mon Jul 20 06:14:02.871227 2026] [security2:error] [pid 858085:tid 858316] [client 14.225.17.146:52457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RCjAtbv2vrjByhUqBWwAAAGQ"], referer: https://guidehunting.com/WordPress
[Mon Jul 20 06:14:03.187848 2026] [security2:error] [pid 843279:tid 843521] [client 104.234.53.64:33457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RC_qvKNcW5yy5T2DDJQAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:03.508357 2026] [security2:error] [pid 843279:tid 843457] [client 181.224.94.124:13184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RC_qvKNcW5yy5T2DDLwAAALQ"]
[Mon Jul 20 06:14:03.508492 2026] [security2:error] [pid 843279:tid 843457] [client 181.224.94.124:13184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RC_qvKNcW5yy5T2DDLwAAALQ"]
[Mon Jul 20 06:14:03.713411 2026] [security2:error] [pid 858085:tid 858332] [client 57.141.18.22:43138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAjQAAdEE"]
[Mon Jul 20 06:14:03.740886 2026] [security2:error] [pid 858085:tid 858308] [client 14.225.17.146:64387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBnAAAAFw"], referer: http://processorstudio.com/WordPress
[Mon Jul 20 06:14:04.009709 2026] [security2:error] [pid 858085:tid 858260] [client 57.141.18.28:44752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAnAAALAA"]
[Mon Jul 20 06:14:04.023933 2026] [security2:error] [pid 858085:tid 858337] [client 57.141.18.46:26504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RBzAtbv2vrjByhUqAngAAeRY"]
[Mon Jul 20 06:14:04.249026 2026] [security2:error] [pid 858085:tid 858284] [client 185.132.186.101:47913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/load.php"] [unique_id "al4RDDAtbv2vrjByhUqBtAAAAEQ"]
[Mon Jul 20 06:14:04.328237 2026] [security2:error] [pid 858085:tid 858287] [client 14.225.17.146:52404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBoAAAAEc"], referer: http://onewingpictures.com/WordPress
[Mon Jul 20 06:14:04.351907 2026] [security2:error] [pid 858085:tid 858250] [client 47.128.56.171:11304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musichaven.info"] [uri "/robots.txt"] [unique_id "al4RDDAtbv2vrjByhUqBuQAAACI"]
[Mon Jul 20 06:14:04.352272 2026] [security2:error] [pid 843279:tid 843478] [client 57.141.18.55:55134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCPqvKNcW5yy5T2DCwwAAyWI"]
[Mon Jul 20 06:14:04.498983 2026] [security2:error] [pid 843279:tid 843420] [client 171.60.139.123:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RDPqvKNcW5yy5T2DDSgAAAI8"]
[Mon Jul 20 06:14:04.499139 2026] [security2:error] [pid 843279:tid 843420] [client 171.60.139.123:54804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RDPqvKNcW5yy5T2DDSgAAAI8"]
[Mon Jul 20 06:14:04.520713 2026] [security2:error] [pid 858085:tid 858304] [client 57.141.18.40:56578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqAtwAAWAg"]
[Mon Jul 20 06:14:04.597295 2026] [security2:error] [pid 843279:tid 843467] [client 14.225.17.146:51547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4RDPqvKNcW5yy5T2DDTAAAAL4"], referer: https://processorstudio.com/WordPress
[Mon Jul 20 06:14:04.688519 2026] [security2:error] [pid 858085:tid 858318] [client 57.141.18.100:59230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqAwwAAZgQ"]
[Mon Jul 20 06:14:04.799077 2026] [security2:error] [pid 858085:tid 858293] [client 14.225.17.146:64330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBpAAAAE0"]
[Mon Jul 20 06:14:05.145642 2026] [security2:error] [pid 858085:tid 858241] [client 57.141.18.81:42218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCDAtbv2vrjByhUqA5gAAGTg"]
[Mon Jul 20 06:14:05.441783 2026] [security2:error] [pid 858085:tid 858319] [client 57.141.18.87:60646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCTAtbv2vrjByhUqBEgAAZ0I"]
[Mon Jul 20 06:14:05.482491 2026] [core:error] [pid 858085:tid 858193] [remote 205.210.31.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webmail.ardhalwafaa.com/
[Mon Jul 20 06:14:05.482511 2026] [core:error] [pid 858085:tid 858193] [remote 205.210.31.50:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://webmail.ardhalwafaa.com/
[Mon Jul 20 06:14:06.013960 2026] [security2:error] [pid 858085:tid 858317] [client 14.225.17.146:64456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4RDTAtbv2vrjByhUqB_gAAAGU"], referer: http://lifeisbetterlakeside.com/WordPress
[Mon Jul 20 06:14:06.044039 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:9267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCDAAAACU"]
[Mon Jul 20 06:14:06.044167 2026] [security2:error] [pid 858085:tid 858253] [client 41.173.37.102:9267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCDAAAACU"]
[Mon Jul 20 06:14:06.067345 2026] [security2:error] [pid 858085:tid 858320] [client 185.132.186.64:36377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/firewall.php7"] [unique_id "al4RDjAtbv2vrjByhUqCEQAAAGg"]
[Mon Jul 20 06:14:06.136445 2026] [security2:error] [pid 843279:tid 843504] [client 106.192.104.4:52445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RDvqvKNcW5yy5T2DDdQAAAOM"]
[Mon Jul 20 06:14:06.136537 2026] [security2:error] [pid 843279:tid 843504] [client 106.192.104.4:52445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RDvqvKNcW5yy5T2DDdQAAAOM"]
[Mon Jul 20 06:14:06.156125 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.63:45350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCjAtbv2vrjByhUqBMgAACV4"]
[Mon Jul 20 06:14:06.274016 2026] [security2:error] [pid 843279:tid 843309] [remote 57.141.18.15:24088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5168046"] [unique_id "al4RDvqvKNcW5yy5T2DDdwAA8Bw"]
[Mon Jul 20 06:14:06.364788 2026] [security2:error] [pid 858085:tid 858191] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCIwAAR2g"]
[Mon Jul 20 06:14:06.364968 2026] [security2:error] [pid 858085:tid 858287] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCIwAAR2g"]
[Mon Jul 20 06:14:06.590411 2026] [security2:error] [pid 858085:tid 858286] [client 103.141.108.143:64810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCKwAAAEY"]
[Mon Jul 20 06:14:06.590566 2026] [security2:error] [pid 858085:tid 858286] [client 103.141.108.143:64810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RDjAtbv2vrjByhUqCKwAAAEY"]
[Mon Jul 20 06:14:07.132554 2026] [security2:error] [pid 843279:tid 843523] [client 112.213.160.112:8220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDlgAAAPU"]
[Mon Jul 20 06:14:07.132703 2026] [security2:error] [pid 843279:tid 843523] [client 112.213.160.112:8220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDlgAAAPU"]
[Mon Jul 20 06:14:07.150559 2026] [security2:error] [pid 858085:tid 858326] [client 114.119.141.100:64927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4RDzAtbv2vrjByhUqCRAAAAG4"], referer: https://newstral.com/en/article/en/981559845/memorial-allen-fireall
[Mon Jul 20 06:14:07.194362 2026] [security2:error] [pid 843279:tid 843419] [client 45.116.69.230:61790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDmgAAAI4"]
[Mon Jul 20 06:14:07.194461 2026] [security2:error] [pid 843279:tid 843419] [client 45.116.69.230:61790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDmgAAAI4"]
[Mon Jul 20 06:14:07.290109 2026] [security2:error] [pid 843279:tid 843289] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDnwAApgg"]
[Mon Jul 20 06:14:07.290269 2026] [security2:error] [pid 843279:tid 843443] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RD_qvKNcW5yy5T2DDnwAApgg"]
[Mon Jul 20 06:14:07.377535 2026] [security2:error] [pid 843279:tid 843466] [client 57.141.18.62:27446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RC_qvKNcW5yy5T2DDKQAAvVE"]
[Mon Jul 20 06:14:07.576425 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:51531] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:07.576460 2026] [core:error] [pid 858085:tid 858327] [client 14.225.17.146:51531] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:07.611692 2026] [security2:error] [pid 858085:tid 858336] [client 57.141.18.41:39660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RCzAtbv2vrjByhUqBlQAAeCo"]
[Mon Jul 20 06:14:07.840220 2026] [security2:error] [pid 843279:tid 843411] [client 14.225.17.146:52219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4RD_qvKNcW5yy5T2DDqQAAAIY"], referer: http://ncsynchro.com/WordPress
[Mon Jul 20 06:14:08.168314 2026] [security2:error] [pid 858085:tid 858262] [client 13.38.42.252:19272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.42.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4REDAtbv2vrjByhUqCeAAAAC4"]
[Mon Jul 20 06:14:08.186740 2026] [security2:error] [pid 843279:tid 843494] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4RDvqvKNcW5yy5T2DDiQAAANk"]
[Mon Jul 20 06:14:08.254064 2026] [security2:error] [pid 858085:tid 858156] [remote 182.77.62.24:38796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4REDAtbv2vrjByhUqChAAAFEU"]
[Mon Jul 20 06:14:08.254213 2026] [security2:error] [pid 858085:tid 858236] [client 182.77.62.24:38796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4REDAtbv2vrjByhUqChAAAFEU"]
[Mon Jul 20 06:14:08.327328 2026] [security2:error] [pid 858085:tid 858229] [client 185.132.186.76:33771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/crystal/lrs_dage.php"] [unique_id "al4REDAtbv2vrjByhUqCjwAAAA0"]
[Mon Jul 20 06:14:08.438811 2026] [security2:error] [pid 858085:tid 858310] [client 14.225.17.146:58392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4RDjAtbv2vrjByhUqCMwAAAF4"], referer: http://fluidtemple.org/WordPress
[Mon Jul 20 06:14:08.746599 2026] [security2:error] [pid 858085:tid 858264] [client 13.38.42.252:19286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.42.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4REDAtbv2vrjByhUqCpQAAADA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:14:09.498951 2026] [security2:error] [pid 843279:tid 843427] [client 14.225.17.146:51619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4REPqvKNcW5yy5T2DDtAAAAJY"], referer: http://balticsteelmgmt.com/WordPress
[Mon Jul 20 06:14:09.499429 2026] [security2:error] [pid 858085:tid 858295] [client 110.249.202.93:10450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/robots.txt"] [unique_id "al4RETAtbv2vrjByhUqCyAAAAE8"]
[Mon Jul 20 06:14:09.587566 2026] [security2:error] [pid 843279:tid 843475] [client 57.141.18.114:53448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RDfqvKNcW5yy5T2DDYwAAxh4"]
[Mon Jul 20 06:14:09.740464 2026] [security2:error] [pid 843279:tid 843310] [remote 147.50.252.213:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4REfqvKNcW5yy5T2DD3QAA7R0"]
[Mon Jul 20 06:14:09.899827 2026] [security2:error] [pid 843279:tid 843524] [client 14.225.17.146:53319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4REfqvKNcW5yy5T2DD2gAAAPY"], referer: http://grecruit.online/WordPress
[Mon Jul 20 06:14:10.203532 2026] [security2:error] [pid 843279:tid 843314] [remote 147.50.252.213:46672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4REvqvKNcW5yy5T2DD7wABASE"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:14:10.464176 2026] [security2:error] [pid 858085:tid 858304] [client 50.116.65.227:43686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4REjAtbv2vrjByhUqDBwAAAFg"]
[Mon Jul 20 06:14:10.477208 2026] [security2:error] [pid 858085:tid 858298] [client 50.116.65.227:52852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4REjAtbv2vrjByhUqDCAAAAAA"]
[Mon Jul 20 06:14:10.499260 2026] [security2:error] [pid 858085:tid 858269] [client 104.234.53.71:33271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4REjAtbv2vrjByhUqDAwAAADU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:10.932879 2026] [security2:error] [pid 858085:tid 858339] [client 14.225.17.146:60778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4REjAtbv2vrjByhUqDEwAAAHs"], referer: http://thefriendlyspreadsheet.com/WordPress
[Mon Jul 20 06:14:10.999091 2026] [security2:error] [pid 843279:tid 843419] [client 14.225.17.146:51471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4REfqvKNcW5yy5T2DD0QAAAI4"], referer: http://bigwormfishing.com/WordPress
[Mon Jul 20 06:14:11.249816 2026] [security2:error] [pid 858085:tid 858232] [client 185.132.186.96:21549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/pdf.php"] [unique_id "al4REzAtbv2vrjByhUqDJwAAABA"]
[Mon Jul 20 06:14:11.304112 2026] [security2:error] [pid 843279:tid 843445] [client 27.96.94.195:38243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEFgAAAKg"]
[Mon Jul 20 06:14:11.304262 2026] [security2:error] [pid 843279:tid 843445] [client 27.96.94.195:38243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEFgAAAKg"]
[Mon Jul 20 06:14:11.352160 2026] [security2:error] [pid 858085:tid 858228] [client 14.225.17.146:53357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4RETAtbv2vrjByhUqC3gAAAAw"], referer: http://idigress.group/WordPress
[Mon Jul 20 06:14:11.406251 2026] [security2:error] [pid 858085:tid 858302] [client 43.205.139.3:40696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4REzAtbv2vrjByhUqDMgAAAFY"]
[Mon Jul 20 06:14:11.406359 2026] [security2:error] [pid 858085:tid 858302] [client 43.205.139.3:40696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4REzAtbv2vrjByhUqDMgAAAFY"]
[Mon Jul 20 06:14:11.495503 2026] [security2:error] [pid 843279:tid 843457] [client 14.225.17.146:62746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4RE_qvKNcW5yy5T2DEIAAAALQ"], referer: http://friendlyspreadsheet.com/WordPress
[Mon Jul 20 06:14:11.589139 2026] [security2:error] [pid 858085:tid 858327] [client 14.225.17.146:60628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4REzAtbv2vrjByhUqDOwAAAG8"], referer: http://nikkidesigns.net/WordPress
[Mon Jul 20 06:14:11.677447 2026] [security2:error] [pid 843279:tid 843429] [client 103.77.203.233:57069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEJAAAAJg"]
[Mon Jul 20 06:14:11.677598 2026] [security2:error] [pid 843279:tid 843429] [client 103.77.203.233:57069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RE_qvKNcW5yy5T2DEJAAAAJg"]
[Mon Jul 20 06:14:11.770016 2026] [security2:error] [pid 858085:tid 858338] [client 57.141.18.43:32396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RDzAtbv2vrjByhUqCUgAAeg0"]
[Mon Jul 20 06:14:11.913811 2026] [security2:error] [pid 858085:tid 858226] [client 57.141.18.2:29390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RDzAtbv2vrjByhUqCVgAACgE"]
[Mon Jul 20 06:14:11.978822 2026] [security2:error] [pid 858085:tid 858341] [client 14.225.17.146:60753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4REzAtbv2vrjByhUqDSgAAAH0"], referer: https://bigwormfishing.com/WordPress
[Mon Jul 20 06:14:12.310224 2026] [security2:error] [pid 858085:tid 858342] [client 57.141.18.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RFDAtbv2vrjByhUqDXQAAAH4"]
[Mon Jul 20 06:14:12.418279 2026] [security2:error] [pid 843279:tid 843518] [client 57.141.18.100:59250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RD_qvKNcW5yy5T2DDsQAA8DM"]
[Mon Jul 20 06:14:12.674485 2026] [security2:error] [pid 858085:tid 858318] [client 14.225.17.146:60494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4RFDAtbv2vrjByhUqDhAAAAGY"], referer: https://friendlyspreadsheet.com/WordPress
[Mon Jul 20 06:14:13.048168 2026] [security2:error] [pid 858085:tid 858237] [client 185.132.186.75:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/as.php"] [unique_id "al4RFTAtbv2vrjByhUqDsAAAABU"]
[Mon Jul 20 06:14:13.236913 2026] [security2:error] [pid 858085:tid 858329] [client 57.141.18.105:38894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REDAtbv2vrjByhUqCqQAAcTs"]
[Mon Jul 20 06:14:13.299387 2026] [security2:error] [pid 858085:tid 858249] [client 57.141.18.68:23040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REDAtbv2vrjByhUqCtgAAIV8"]
[Mon Jul 20 06:14:14.073684 2026] [security2:error] [pid 858085:tid 858230] [client 181.224.94.124:61200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RFjAtbv2vrjByhUqD8wAAAA4"]
[Mon Jul 20 06:14:14.073808 2026] [security2:error] [pid 858085:tid 858230] [client 181.224.94.124:61200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RFjAtbv2vrjByhUqD8wAAAA4"]
[Mon Jul 20 06:14:14.473115 2026] [security2:error] [pid 858085:tid 858087] [remote 57.141.18.82:32386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4RFjAtbv2vrjByhUqEDAAAZQA"]
[Mon Jul 20 06:14:14.847815 2026] [security2:error] [pid 858085:tid 858256] [client 185.132.186.91:61889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/item.php"] [unique_id "al4RFjAtbv2vrjByhUqEJgAAACg"]
[Mon Jul 20 06:14:15.152726 2026] [security2:error] [pid 843279:tid 843449] [client 171.60.139.123:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RF_qvKNcW5yy5T2DEcQAAAKw"]
[Mon Jul 20 06:14:15.152921 2026] [security2:error] [pid 843279:tid 843449] [client 171.60.139.123:55286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RF_qvKNcW5yy5T2DEcQAAAKw"]
[Mon Jul 20 06:14:15.239004 2026] [security2:error] [pid 843279:tid 843421] [client 57.141.18.103:37238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REvqvKNcW5yy5T2DEBAAAkEs"]
[Mon Jul 20 06:14:15.370166 2026] [security2:error] [pid 858085:tid 858301] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqEOgAAAFU"]
[Mon Jul 20 06:14:15.504489 2026] [security2:error] [pid 858085:tid 858323] [client 49.13.163.121:47037] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4RFTAtbv2vrjByhUqD7AAAAGs"]
[Mon Jul 20 06:14:15.658343 2026] [security2:error] [pid 843279:tid 843484] [client 57.141.18.114:53458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RE_qvKNcW5yy5T2DEEAAAzxk"]
[Mon Jul 20 06:14:15.678055 2026] [security2:error] [pid 858085:tid 858250] [client 14.225.17.146:64547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4RFjAtbv2vrjByhUqD_gAAACI"], referer: http://inspirespublishing.com/WordPress
[Mon Jul 20 06:14:15.753849 2026] [security2:error] [pid 858085:tid 858223] [client 14.225.17.146:61433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqEQQAAAAc"], referer: http://aljosour-alarabia.com/WordPress
[Mon Jul 20 06:14:15.794557 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.45:43838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4REzAtbv2vrjByhUqDKQAACUI"]
[Mon Jul 20 06:14:15.853371 2026] [security2:error] [pid 858085:tid 858175] [remote 152.228.213.32:40540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RFzAtbv2vrjByhUqEXwAAD1g"]
[Mon Jul 20 06:14:15.898862 2026] [security2:error] [pid 858085:tid 858245] [client 14.225.17.146:62913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqETwAAAB0"], referer: http://worbals.com/WordPress
[Mon Jul 20 06:14:16.013109 2026] [security2:error] [pid 858085:tid 858111] [remote 193.70.112.205:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4RFzAtbv2vrjByhUqEaAAAEhg"]
[Mon Jul 20 06:14:16.048540 2026] [security2:error] [pid 858085:tid 858195] [remote 152.228.213.32:40540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RGDAtbv2vrjByhUqEcAAATWw"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:14:16.512970 2026] [security2:error] [pid 858085:tid 858310] [client 106.192.104.4:52950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEigAAAF4"]
[Mon Jul 20 06:14:16.513103 2026] [security2:error] [pid 858085:tid 858310] [client 106.192.104.4:52950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEigAAAF4"]
[Mon Jul 20 06:14:16.522984 2026] [security2:error] [pid 858085:tid 858204] [remote 193.70.112.205:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4RGDAtbv2vrjByhUqEjAAAanU"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:14:16.600008 2026] [security2:error] [pid 843279:tid 843450] [client 14.225.17.146:64492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4RF_qvKNcW5yy5T2DEcgAAAK0"], referer: http://dadanetnet.net/WordPress
[Mon Jul 20 06:14:16.645137 2026] [security2:error] [pid 858085:tid 858222] [client 185.132.186.67:52955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/wp-conflg.php"] [unique_id "al4RGDAtbv2vrjByhUqEkwAAAAY"]
[Mon Jul 20 06:14:16.645889 2026] [security2:error] [pid 843279:tid 843533] [client 41.173.37.102:9722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RGPqvKNcW5yy5T2DEkAAAAP8"]
[Mon Jul 20 06:14:16.645996 2026] [security2:error] [pid 843279:tid 843533] [client 41.173.37.102:9722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RGPqvKNcW5yy5T2DEkAAAAP8"]
[Mon Jul 20 06:14:16.808416 2026] [security2:error] [pid 858085:tid 858320] [client 57.141.18.69:47288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFDAtbv2vrjByhUqDbQAAaGI"]
[Mon Jul 20 06:14:16.892860 2026] [security2:error] [pid 858085:tid 858334] [client 14.225.17.146:61554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4RGDAtbv2vrjByhUqEngAAAHY"], referer: http://solkeetw.com/WordPress
[Mon Jul 20 06:14:16.901627 2026] [security2:error] [pid 858085:tid 858163] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEpQAATkw"]
[Mon Jul 20 06:14:16.901824 2026] [security2:error] [pid 858085:tid 858294] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGDAtbv2vrjByhUqEpQAATkw"]
[Mon Jul 20 06:14:16.944694 2026] [security2:error] [pid 843279:tid 843448] [client 14.225.17.146:62706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4RGPqvKNcW5yy5T2DEjgAAAKs"], referer: http://healthylifegourmet.org/WordPress
[Mon Jul 20 06:14:17.070641 2026] [security2:error] [pid 843279:tid 843513] [client 57.141.18.57:31124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFPqvKNcW5yy5T2DEPQAA6wU"]
[Mon Jul 20 06:14:17.211937 2026] [security2:error] [pid 843279:tid 843437] [client 103.141.108.143:65291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEnAAAAKA"]
[Mon Jul 20 06:14:17.212980 2026] [security2:error] [pid 843279:tid 843437] [client 103.141.108.143:65291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEnAAAAKA"]
[Mon Jul 20 06:14:17.719266 2026] [security2:error] [pid 858085:tid 858302] [client 50.116.65.227:52966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RGTAtbv2vrjByhUqE0gAAAFY"]
[Mon Jul 20 06:14:17.730635 2026] [security2:error] [pid 858085:tid 858230] [client 50.116.65.227:52974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RGTAtbv2vrjByhUqE1AAAAA4"]
[Mon Jul 20 06:14:17.796031 2026] [security2:error] [pid 858085:tid 858301] [client 112.213.160.112:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE2wAAAFU"]
[Mon Jul 20 06:14:17.796165 2026] [security2:error] [pid 858085:tid 858301] [client 112.213.160.112:8663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE2wAAAFU"]
[Mon Jul 20 06:14:17.813065 2026] [security2:error] [pid 843279:tid 843473] [client 45.116.69.230:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEpQAAAMQ"]
[Mon Jul 20 06:14:17.813248 2026] [security2:error] [pid 843279:tid 843473] [client 45.116.69.230:62312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RGfqvKNcW5yy5T2DEpQAAAMQ"]
[Mon Jul 20 06:14:17.977844 2026] [security2:error] [pid 858085:tid 858162] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE4QAAEUs"]
[Mon Jul 20 06:14:17.977965 2026] [security2:error] [pid 858085:tid 858233] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RGTAtbv2vrjByhUqE4QAAEUs"]
[Mon Jul 20 06:14:18.064065 2026] [security2:error] [pid 858085:tid 858253] [client 65.1.132.125:56258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RGjAtbv2vrjByhUqE5QAAACU"]
[Mon Jul 20 06:14:18.064194 2026] [security2:error] [pid 858085:tid 858253] [client 65.1.132.125:56258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RGjAtbv2vrjByhUqE5QAAACU"]
[Mon Jul 20 06:14:18.067730 2026] [security2:error] [pid 843279:tid 843338] [remote 173.249.4.11:31029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4RGvqvKNcW5yy5T2DEqAAAsTk"]
[Mon Jul 20 06:14:18.199919 2026] [security2:error] [pid 858085:tid 858336] [client 50.116.65.227:43694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RGjAtbv2vrjByhUqE6AAAAHg"]
[Mon Jul 20 06:14:18.212446 2026] [security2:error] [pid 858085:tid 858261] [client 50.116.65.227:52986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RGjAtbv2vrjByhUqE6wAAAC0"]
[Mon Jul 20 06:14:18.414644 2026] [security2:error] [pid 843279:tid 843404] [remote 173.249.4.11:31029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4RGvqvKNcW5yy5T2DEuAAA7Xs"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:14:18.425281 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.77:24566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFTAtbv2vrjByhUqD2AAAKX4"]
[Mon Jul 20 06:14:18.451199 2026] [security2:error] [pid 858085:tid 858269] [client 185.132.186.86:44657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/install.php"] [unique_id "al4RGjAtbv2vrjByhUqE9wAAADU"]
[Mon Jul 20 06:14:18.468100 2026] [security2:error] [pid 843279:tid 843485] [client 14.225.17.146:64667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4RGfqvKNcW5yy5T2DElwAAANA"], referer: http://chestermonty.com/WordPress
[Mon Jul 20 06:14:18.799237 2026] [security2:error] [pid 858085:tid 858216] [client 57.141.18.95:21428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFjAtbv2vrjByhUqD9AAAAD0"]
[Mon Jul 20 06:14:19.333309 2026] [security2:error] [pid 843279:tid 843490] [client 57.141.18.25:43468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFvqvKNcW5yy5T2DEXgAA1XQ"]
[Mon Jul 20 06:14:19.364627 2026] [core:error] [pid 843279:tid 843532] [client 205.210.31.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:19.364653 2026] [core:error] [pid 843279:tid 843532] [client 205.210.31.131:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:19.404690 2026] [security2:error] [pid 858085:tid 858222] [client 14.225.17.146:52064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFKAAAAAY"], referer: https://chestermonty.com/WordPress
[Mon Jul 20 06:14:19.491953 2026] [security2:error] [pid 858085:tid 858260] [client 27.96.94.195:37957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RGzAtbv2vrjByhUqFMQAAACw"]
[Mon Jul 20 06:14:19.492073 2026] [security2:error] [pid 858085:tid 858260] [client 27.96.94.195:37957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RGzAtbv2vrjByhUqFMQAAACw"]
[Mon Jul 20 06:14:19.522936 2026] [security2:error] [pid 858085:tid 858278] [client 14.225.17.146:54213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFMAAAAD4"], referer: http://grndl.com/WordPress
[Mon Jul 20 06:14:20.243539 2026] [security2:error] [pid 858085:tid 858217] [client 185.132.186.91:63541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/db.php"] [unique_id "al4RHDAtbv2vrjByhUqFZgAAAAE"]
[Mon Jul 20 06:14:20.717149 2026] [security2:error] [pid 858085:tid 858290] [client 57.141.18.29:31628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RFzAtbv2vrjByhUqEYgAASg0"]
[Mon Jul 20 06:14:20.891121 2026] [security2:error] [pid 843279:tid 843422] [client 32.193.54.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.koaconsultants.com"] [uri "/index.php"] [unique_id "al4RHPqvKNcW5yy5T2DE4QAAAJE"]
[Mon Jul 20 06:14:21.090630 2026] [security2:error] [pid 843279:tid 843519] [client 13.201.64.214:41942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RHfqvKNcW5yy5T2DE7wAAAPE"]
[Mon Jul 20 06:14:21.090756 2026] [security2:error] [pid 843279:tid 843519] [client 13.201.64.214:41942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RHfqvKNcW5yy5T2DE7wAAAPE"]
[Mon Jul 20 06:14:21.380028 2026] [security2:error] [pid 843279:tid 843367] [remote 57.141.18.69:32858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4RHfqvKNcW5yy5T2DE_gAAqVY"]
[Mon Jul 20 06:14:21.615769 2026] [security2:error] [pid 858085:tid 858328] [client 104.234.53.91:31023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RHTAtbv2vrjByhUqFpAAAAHA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:21.946209 2026] [security2:error] [pid 858085:tid 858173] [remote 111.225.149.201:38310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2022/01/map-comments-october-30-2021-predeadline.pdf"] [unique_id "al4RHTAtbv2vrjByhUqFvAAAKVY"]
[Mon Jul 20 06:14:21.952926 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.61:35578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGTAtbv2vrjByhUqEvwAADWM"]
[Mon Jul 20 06:14:22.045553 2026] [security2:error] [pid 858085:tid 858232] [client 185.132.186.103:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/fan.php"] [unique_id "al4RHjAtbv2vrjByhUqFxQAAABA"]
[Mon Jul 20 06:14:22.340196 2026] [security2:error] [pid 858085:tid 858301] [client 13.201.64.214:41954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RHjAtbv2vrjByhUqF3QAAAFU"]
[Mon Jul 20 06:14:22.340274 2026] [security2:error] [pid 858085:tid 858301] [client 13.201.64.214:41954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RHjAtbv2vrjByhUqF3QAAAFU"]
[Mon Jul 20 06:14:22.355207 2026] [security2:error] [pid 858085:tid 858314] [client 104.234.53.91:31023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RHjAtbv2vrjByhUqF3AAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:22.360865 2026] [security2:error] [pid 843279:tid 843426] [client 103.77.203.233:57612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RHvqvKNcW5yy5T2DFDwAAAJU"]
[Mon Jul 20 06:14:22.361189 2026] [security2:error] [pid 843279:tid 843426] [client 103.77.203.233:57612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RHvqvKNcW5yy5T2DFDwAAAJU"]
[Mon Jul 20 06:14:22.673290 2026] [security2:error] [pid 858085:tid 858194] [remote 216.73.216.55:47397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4RHjAtbv2vrjByhUqF9wAAGWs"]
[Mon Jul 20 06:14:22.787916 2026] [security2:error] [pid 858085:tid 858228] [client 57.141.18.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqF9gAAAAw"]
[Mon Jul 20 06:14:23.405912 2026] [core:error] [pid 858085:tid 858336] [client 185.253.160.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:23.405945 2026] [core:error] [pid 858085:tid 858336] [client 185.253.160.17:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:23.649133 2026] [security2:error] [pid 858085:tid 858240] [client 57.141.18.8:55240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFGgAAGFc"]
[Mon Jul 20 06:14:23.831041 2026] [security2:error] [pid 858085:tid 858319] [client 57.141.18.58:59100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFJQAAZzw"]
[Mon Jul 20 06:14:23.839596 2026] [security2:error] [pid 858085:tid 858296] [client 185.132.186.100:49047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/colors.php"] [unique_id "al4RHzAtbv2vrjByhUqGhgAAAFA"]
[Mon Jul 20 06:14:24.190683 2026] [security2:error] [pid 858085:tid 858263] [client 57.141.18.58:59104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RGzAtbv2vrjByhUqFQQAALxY"]
[Mon Jul 20 06:14:24.337851 2026] [security2:error] [pid 858085:tid 858264] [client 14.225.17.146:51236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqF-AAAADA"], referer: http://vinovinhowine.com/WordPress
[Mon Jul 20 06:14:24.610984 2026] [security2:error] [pid 858085:tid 858245] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4RIDAtbv2vrjByhUqG1AAAAB0"], referer: https://www.google.com/
[Mon Jul 20 06:14:24.611737 2026] [security2:error] [pid 858085:tid 858265] [client 181.224.94.124:22861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RIDAtbv2vrjByhUqG1QAAADE"]
[Mon Jul 20 06:14:24.611828 2026] [security2:error] [pid 858085:tid 858265] [client 181.224.94.124:22861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RIDAtbv2vrjByhUqG1QAAADE"]
[Mon Jul 20 06:14:24.643056 2026] [security2:error] [pid 858085:tid 858252] [client 14.225.17.146:64135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4RIDAtbv2vrjByhUqGxQAAACQ"], referer: http://ksands.co.uk/WordPress
[Mon Jul 20 06:14:24.752966 2026] [security2:error] [pid 858085:tid 858233] [client 104.234.53.56:48813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RIDAtbv2vrjByhUqG2AAAABE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:25.017557 2026] [security2:error] [pid 858085:tid 858327] [client 177.4.176.37:28123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4RIDAtbv2vrjByhUqG5QAAAG8"]
[Mon Jul 20 06:14:25.222715 2026] [security2:error] [pid 858085:tid 858301] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4RITAtbv2vrjByhUqHCgAAAFU"], referer: https://www.google.com/
[Mon Jul 20 06:14:25.307730 2026] [security2:error] [pid 843279:tid 843315] [remote 57.141.18.119:20822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHfqvKNcW5yy5T2DE7gAA2yI"]
[Mon Jul 20 06:14:25.598181 2026] [security2:error] [pid 858085:tid 858327] [client 74.208.214.194:60664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RITAtbv2vrjByhUqHJAAAAG8"]
[Mon Jul 20 06:14:25.621596 2026] [security2:error] [pid 858085:tid 858242] [client 50.116.65.227:58056] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4RITAtbv2vrjByhUqHJgAAABo"]
[Mon Jul 20 06:14:25.632758 2026] [security2:error] [pid 858085:tid 858295] [client 50.116.65.227:53310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4RITAtbv2vrjByhUqHKgAAAE8"]
[Mon Jul 20 06:14:25.636633 2026] [security2:error] [pid 858085:tid 858241] [client 185.132.186.77:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/mah.php"] [unique_id "al4RITAtbv2vrjByhUqHKwAAABk"]
[Mon Jul 20 06:14:25.646225 2026] [security2:error] [pid 858085:tid 858273] [client 14.225.17.146:52075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGIAAAADk"], referer: http://bruceledewitz.com/WordPress
[Mon Jul 20 06:14:25.648125 2026] [security2:error] [pid 858085:tid 858261] [client 104.234.53.56:48813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RITAtbv2vrjByhUqHLAAAAC0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:25.768019 2026] [security2:error] [pid 858085:tid 858210] [remote 50.28.1.50:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4RITAtbv2vrjByhUqHPQAAD3s"]
[Mon Jul 20 06:14:25.852494 2026] [security2:error] [pid 858085:tid 858282] [client 171.60.139.123:55767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RITAtbv2vrjByhUqHQgAAAEI"]
[Mon Jul 20 06:14:25.852660 2026] [security2:error] [pid 858085:tid 858282] [client 171.60.139.123:55767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RITAtbv2vrjByhUqHQgAAAEI"]
[Mon Jul 20 06:14:26.007123 2026] [security2:error] [pid 858085:tid 858262] [client 74.7.227.151:44870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4RITAtbv2vrjByhUqHGQAALho"], referer: https://overloadcomedy.com/wp-content/uploads/essential-addons-elementor/eael-4528.js?ver=1760353471
[Mon Jul 20 06:14:26.063211 2026] [security2:error] [pid 858085:tid 858316] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4RIjAtbv2vrjByhUqHTwAAAGQ"], referer: https://duckduckgo.com/?q=px7e3
[Mon Jul 20 06:14:26.128868 2026] [security2:error] [pid 858085:tid 858273] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/passwd"] [unique_id "al4RIjAtbv2vrjByhUqHVgAAADk"], referer: https://www.bing.com/search?q=b2ad22
[Mon Jul 20 06:14:26.237296 2026] [security2:error] [pid 858085:tid 858101] [remote 50.28.1.50:43096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4RIjAtbv2vrjByhUqHYAAAQw4"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:14:26.275450 2026] [security2:error] [pid 858085:tid 858258] [client 104.234.53.74:45195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RIjAtbv2vrjByhUqHYwAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:26.324608 2026] [security2:error] [pid 858085:tid 858310] [client 74.7.230.3:39688] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "mazzucelli.com"] [uri "/robots.txt"] [unique_id "al4RIjAtbv2vrjByhUqHaQAAAF4"]
[Mon Jul 20 06:14:26.503780 2026] [security2:error] [pid 858085:tid 858280] [client 57.141.18.35:55612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqFzwAAQEY"]
[Mon Jul 20 06:14:26.729323 2026] [security2:error] [pid 858085:tid 858230] [client 57.141.18.44:34810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHjAtbv2vrjByhUqF4AAADhs"]
[Mon Jul 20 06:14:27.269690 2026] [security2:error] [pid 858085:tid 858335] [client 74.7.230.3:37476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4RIjAtbv2vrjByhUqHcwAAd3Y"]
[Mon Jul 20 06:14:27.272043 2026] [security2:error] [pid 858085:tid 858335] [client 74.7.230.3:37476] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4RIjAtbv2vrjByhUqHcAAAdxE"], referer: http://mazzucelli.com/robots.txt
[Mon Jul 20 06:14:27.289872 2026] [security2:error] [pid 858085:tid 858235] [client 104.234.53.83:46807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RIzAtbv2vrjByhUqHvgAAABM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:27.298992 2026] [security2:error] [pid 858085:tid 858265] [client 41.173.37.102:10170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHwQAAADE"]
[Mon Jul 20 06:14:27.299078 2026] [security2:error] [pid 858085:tid 858265] [client 41.173.37.102:10170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHwQAAADE"]
[Mon Jul 20 06:14:27.433642 2026] [security2:error] [pid 858085:tid 858250] [client 185.132.186.66:57097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/waf_defender.php"] [unique_id "al4RIzAtbv2vrjByhUqHygAAACI"]
[Mon Jul 20 06:14:27.449402 2026] [security2:error] [pid 858085:tid 858133] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHywAAUy4"]
[Mon Jul 20 06:14:27.449569 2026] [security2:error] [pid 858085:tid 858299] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqHywAAUy4"]
[Mon Jul 20 06:14:27.609886 2026] [security2:error] [pid 858085:tid 858338] [client 57.141.18.73:60120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGKQAAel8"]
[Mon Jul 20 06:14:27.748200 2026] [security2:error] [pid 858085:tid 858228] [client 57.141.18.27:51222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGLQAADH4"]
[Mon Jul 20 06:14:27.797704 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH7gAAAHU"]
[Mon Jul 20 06:14:27.797815 2026] [security2:error] [pid 858085:tid 858333] [client 103.141.108.143:49377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH7gAAAHU"]
[Mon Jul 20 06:14:27.806744 2026] [security2:error] [pid 858085:tid 858264] [client 106.192.104.4:53493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH8QAAADA"]
[Mon Jul 20 06:14:27.806840 2026] [security2:error] [pid 858085:tid 858264] [client 106.192.104.4:53493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RIzAtbv2vrjByhUqH8QAAADA"]
[Mon Jul 20 06:14:28.110531 2026] [security2:error] [pid 858085:tid 858243] [client 50.116.65.227:53338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RJDAtbv2vrjByhUqIDAAAABs"]
[Mon Jul 20 06:14:28.120402 2026] [security2:error] [pid 858085:tid 858329] [client 50.116.65.227:53350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RJDAtbv2vrjByhUqIDgAAAHE"]
[Mon Jul 20 06:14:28.155810 2026] [security2:error] [pid 858085:tid 858224] [client 57.141.18.14:31724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RHzAtbv2vrjByhUqGfgAACFg"]
[Mon Jul 20 06:14:28.193441 2026] [security2:error] [pid 858085:tid 858124] [remote 100.42.189.89:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIFAAAcyU"]
[Mon Jul 20 06:14:28.259118 2026] [security2:error] [pid 858085:tid 858190] [remote 47.86.33.52:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIIQAAJmc"]
[Mon Jul 20 06:14:28.390653 2026] [security2:error] [pid 858085:tid 858187] [remote 18.61.192.253:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIKQAAU2Q"]
[Mon Jul 20 06:14:28.427491 2026] [security2:error] [pid 858085:tid 858156] [remote 100.42.189.89:51294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIMAAAdkU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:14:28.465165 2026] [security2:error] [pid 858085:tid 858245] [client 112.213.160.112:8291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqINgAAAB0"]
[Mon Jul 20 06:14:28.465272 2026] [security2:error] [pid 858085:tid 858245] [client 112.213.160.112:8291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqINgAAAB0"]
[Mon Jul 20 06:14:28.536230 2026] [security2:error] [pid 858085:tid 858316] [client 45.116.69.230:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIPAAAAGQ"]
[Mon Jul 20 06:14:28.536390 2026] [security2:error] [pid 858085:tid 858316] [client 45.116.69.230:62841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIPAAAAGQ"]
[Mon Jul 20 06:14:28.671987 2026] [security2:error] [pid 858085:tid 858273] [client 50.116.65.227:53358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqINwAAADk"]
[Mon Jul 20 06:14:28.695584 2026] [security2:error] [pid 858085:tid 858307] [client 57.141.18.22:26772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RIDAtbv2vrjByhUqGtAAAW1w"]
[Mon Jul 20 06:14:28.728579 2026] [security2:error] [pid 858085:tid 858145] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIUwAAcTo"]
[Mon Jul 20 06:14:28.728774 2026] [security2:error] [pid 858085:tid 858329] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RJDAtbv2vrjByhUqIUwAAcTo"]
[Mon Jul 20 06:14:28.872307 2026] [security2:error] [pid 858085:tid 858115] [remote 18.61.192.253:39810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIYAAADRw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:14:28.918403 2026] [security2:error] [pid 858085:tid 858263] [client 50.116.65.227:53362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqITQAAAC8"]
[Mon Jul 20 06:14:28.953793 2026] [security2:error] [pid 858085:tid 858210] [remote 5.161.225.162:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4RJDAtbv2vrjByhUqIZQAABHs"]
[Mon Jul 20 06:14:28.979071 2026] [security2:error] [pid 858085:tid 858321] [client 14.225.17.146:64059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4RIzAtbv2vrjByhUqH3QAAAGk"], referer: http://cloudspacesgroup.com/WordPress
[Mon Jul 20 06:14:29.136411 2026] [security2:error] [pid 858085:tid 858167] [remote 47.86.33.52:46032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIbAAAWFA"], referer: https://mail.grndl.com/wp-login.php
[Mon Jul 20 06:14:29.231503 2026] [security2:error] [pid 858085:tid 858259] [client 185.132.186.88:34427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/ectoplasm/content.php"] [unique_id "al4RJTAtbv2vrjByhUqIfQAAACs"]
[Mon Jul 20 06:14:29.243885 2026] [security2:error] [pid 858085:tid 858141] [remote 5.161.225.162:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIfwAAAjY"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:14:29.271948 2026] [security2:error] [pid 858085:tid 858258] [client 14.225.17.146:60726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4RJTAtbv2vrjByhUqIegAAACo"], referer: http://daseighty.net/WordPress
[Mon Jul 20 06:14:29.274199 2026] [security2:error] [pid 858085:tid 858095] [remote 124.55.178.99:54444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIgAAARwg"]
[Mon Jul 20 06:14:29.306153 2026] [security2:error] [pid 858085:tid 858294] [client 14.225.17.146:51167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4RIzAtbv2vrjByhUqH3AAAAE4"], referer: http://superiorcopywriting.com/WordPress
[Mon Jul 20 06:14:29.653872 2026] [security2:error] [pid 858085:tid 858328] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/shadow"] [unique_id "al4RJTAtbv2vrjByhUqIoAAAAHA"], referer: https://twitter.com/
[Mon Jul 20 06:14:29.688442 2026] [security2:error] [pid 858085:tid 858131] [remote 124.55.178.99:54444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJTAtbv2vrjByhUqIpAAAGSw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:14:30.551030 2026] [security2:error] [pid 858085:tid 858325] [client 14.225.17.146:51020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqIZwAAAG0"], referer: http://adirondackengineering.com/WordPress
[Mon Jul 20 06:14:30.649388 2026] [security2:error] [pid 858085:tid 858152] [remote 72.167.132.114:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJjAtbv2vrjByhUqI5AAAZ0E"]
[Mon Jul 20 06:14:30.733569 2026] [security2:error] [pid 858085:tid 858258] [client 27.96.94.195:37865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI7wAAACo"]
[Mon Jul 20 06:14:30.733720 2026] [security2:error] [pid 858085:tid 858258] [client 27.96.94.195:37865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI7wAAACo"]
[Mon Jul 20 06:14:30.736713 2026] [security2:error] [pid 858085:tid 858217] [client 178.152.178.232:36567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI8AAAAAE"]
[Mon Jul 20 06:14:30.736829 2026] [security2:error] [pid 858085:tid 858217] [client 178.152.178.232:36567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RJjAtbv2vrjByhUqI8AAAAAE"]
[Mon Jul 20 06:14:30.767294 2026] [security2:error] [pid 858085:tid 858270] [client 34.201.171.57:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4RJjAtbv2vrjByhUqI1AAAADY"]
[Mon Jul 20 06:14:30.770509 2026] [security2:error] [pid 858085:tid 858286] [client 34.201.171.57:59210] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-stuffed-shells-caracoles-rellenos"] [unique_id "al4RJjAtbv2vrjByhUqIzQAAAEY"]
[Mon Jul 20 06:14:30.813436 2026] [security2:error] [pid 858085:tid 858278] [client 14.225.17.146:50098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4RJjAtbv2vrjByhUqI4wAAAD4"], referer: http://partnerselectricalllc.com/WordPress
[Mon Jul 20 06:14:30.899034 2026] [core:error] [pid 858085:tid 858252] [client 158.173.74.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:30.899057 2026] [core:error] [pid 858085:tid 858252] [client 158.173.74.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:30.916645 2026] [security2:error] [pid 858085:tid 858195] [remote 72.167.132.114:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJjAtbv2vrjByhUqJAgAAXmw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:14:31.025617 2026] [security2:error] [pid 858085:tid 858251] [client 185.132.186.79:58923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/install.php"] [unique_id "al4RJzAtbv2vrjByhUqJDQAAACM"]
[Mon Jul 20 06:14:31.091884 2026] [security2:error] [pid 858085:tid 858238] [client 103.153.183.69:45262] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/hosts"] [unique_id "al4RJzAtbv2vrjByhUqJEQAAABY"], referer: https://www.google.com/search?q=roehh4
[Mon Jul 20 06:14:31.896651 2026] [security2:error] [pid 858085:tid 858207] [remote 20.153.140.50:60860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RJzAtbv2vrjByhUqJUwAAZ3g"]
[Mon Jul 20 06:14:31.988593 2026] [security2:error] [pid 858085:tid 858203] [remote 45.90.123.233:38430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4RJzAtbv2vrjByhUqJXAAANHQ"]
[Mon Jul 20 06:14:32.000378 2026] [security2:error] [pid 858085:tid 858272] [client 103.153.183.69:45262] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//....//proc/self/environ"] [unique_id "al4RJzAtbv2vrjByhUqJXwAAADg"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:14:32.195819 2026] [security2:error] [pid 858085:tid 858159] [remote 45.90.123.233:38430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4RKDAtbv2vrjByhUqJbQAAXUg"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:14:32.432649 2026] [security2:error] [pid 858085:tid 858311] [client 57.141.18.125:42930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RIzAtbv2vrjByhUqH0QAAX2I"]
[Mon Jul 20 06:14:32.434162 2026] [security2:error] [pid 858085:tid 858315] [client 181.123.115.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJawAAAGM"]
[Mon Jul 20 06:14:32.448110 2026] [security2:error] [pid 858085:tid 858165] [remote 20.153.140.50:60860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RKDAtbv2vrjByhUqJiAAACE4"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:14:32.821348 2026] [security2:error] [pid 858085:tid 858234] [client 185.132.186.77:25453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/thickbox/about.php"] [unique_id "al4RKDAtbv2vrjByhUqJowAAABI"]
[Mon Jul 20 06:14:32.891007 2026] [security2:error] [pid 858085:tid 858320] [client 110.249.202.27:40156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4RKDAtbv2vrjByhUqJqgAAAGg"]
[Mon Jul 20 06:14:32.905669 2026] [security2:error] [pid 858085:tid 858218] [client 103.77.203.233:58160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RKDAtbv2vrjByhUqJqwAAAAI"]
[Mon Jul 20 06:14:32.905802 2026] [security2:error] [pid 858085:tid 858218] [client 103.77.203.233:58160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RKDAtbv2vrjByhUqJqwAAAAI"]
[Mon Jul 20 06:14:33.060187 2026] [security2:error] [pid 858085:tid 858283] [client 74.208.214.194:60670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RKTAtbv2vrjByhUqJtQAAAEM"]
[Mon Jul 20 06:14:33.200423 2026] [security2:error] [pid 858085:tid 858249] [client 57.141.18.60:41596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJDAtbv2vrjByhUqIMwAAIW4"]
[Mon Jul 20 06:14:33.280503 2026] [security2:error] [pid 858085:tid 858286] [client 3.149.57.90:24828] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJnAAAAEY"], referer: https://windowtx.com
[Mon Jul 20 06:14:33.364709 2026] [security2:error] [pid 858085:tid 858329] [client 65.1.132.125:16604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RKTAtbv2vrjByhUqJzQAAAHE"]
[Mon Jul 20 06:14:33.364857 2026] [security2:error] [pid 858085:tid 858329] [client 65.1.132.125:16604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RKTAtbv2vrjByhUqJzQAAAHE"]
[Mon Jul 20 06:14:33.466290 2026] [security2:error] [pid 858085:tid 858311] [client 103.153.183.69:10532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4RKTAtbv2vrjByhUqJ1QAAAF8"], referer: https://www.google.com/search?q=9vaucj
[Mon Jul 20 06:14:33.622068 2026] [security2:error] [pid 858085:tid 858281] [client 103.153.183.69:10532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4RKTAtbv2vrjByhUqJ4AAAAEE"], referer: https://www.facebook.com/
[Mon Jul 20 06:14:34.158597 2026] [security2:error] [pid 858085:tid 858096] [remote 18.61.192.253:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4RKjAtbv2vrjByhUqKFAAAIQk"]
[Mon Jul 20 06:14:34.280622 2026] [security2:error] [pid 858085:tid 858267] [client 57.141.18.32:60350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJTAtbv2vrjByhUqIjwAAMzg"]
[Mon Jul 20 06:14:34.532190 2026] [security2:error] [pid 858085:tid 858260] [client 100.26.198.54:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4RKTAtbv2vrjByhUqJ8AAAACw"]
[Mon Jul 20 06:14:34.543594 2026] [security2:error] [pid 858085:tid 858253] [client 100.26.198.54:40438] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-stuffed-shells-caracoles-rellenos/"] [unique_id "al4RKTAtbv2vrjByhUqJ5AAAACU"]
[Mon Jul 20 06:14:34.631427 2026] [security2:error] [pid 858085:tid 858224] [client 185.132.186.73:56559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/content.php"] [unique_id "al4RKjAtbv2vrjByhUqKLwAAAAg"]
[Mon Jul 20 06:14:34.641359 2026] [security2:error] [pid 858085:tid 858116] [remote 18.61.192.253:45128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4RKjAtbv2vrjByhUqKMAAAZR0"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:14:34.720969 2026] [security2:error] [pid 858085:tid 858308] [client 57.141.18.15:65236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJTAtbv2vrjByhUqItgAAXBs"]
[Mon Jul 20 06:14:34.874628 2026] [security2:error] [pid 858085:tid 858218] [client 50.116.65.227:10090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2025/02/IMG_9124.jpeg"] [unique_id "al4RKjAtbv2vrjByhUqKRwAAAFQ"]
[Mon Jul 20 06:14:35.107809 2026] [security2:error] [pid 858085:tid 858338] [client 181.224.94.124:51191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RKzAtbv2vrjByhUqKZAAAAHo"]
[Mon Jul 20 06:14:35.107920 2026] [security2:error] [pid 858085:tid 858338] [client 181.224.94.124:51191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RKzAtbv2vrjByhUqKZAAAAHo"]
[Mon Jul 20 06:14:35.177210 2026] [security2:error] [pid 858085:tid 858218] [client 50.116.65.227:21770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RKzAtbv2vrjByhUqKcQAAAAI"]
[Mon Jul 20 06:14:35.191773 2026] [security2:error] [pid 858085:tid 858279] [client 50.116.65.227:10138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RKzAtbv2vrjByhUqKdQAAAD8"]
[Mon Jul 20 06:14:35.230873 2026] [security2:error] [pid 858085:tid 858206] [remote 72.167.132.114:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4RKzAtbv2vrjByhUqKeQAACnc"]
[Mon Jul 20 06:14:35.445105 2026] [security2:error] [pid 858085:tid 858203] [remote 72.167.132.114:46428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4RKzAtbv2vrjByhUqKjgAAK3Q"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:14:35.833221 2026] [security2:error] [pid 858085:tid 858334] [client 57.141.18.46:31482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJzAtbv2vrjByhUqJFAAAdjA"]
[Mon Jul 20 06:14:35.847713 2026] [security2:error] [pid 858085:tid 858257] [client 103.112.236.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RKzAtbv2vrjByhUqKlAAAKTo"]
[Mon Jul 20 06:14:36.097218 2026] [security2:error] [pid 858085:tid 858276] [client 57.141.18.56:51022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RJzAtbv2vrjByhUqJLwAAPGk"]
[Mon Jul 20 06:14:36.429406 2026] [security2:error] [pid 858085:tid 858221] [client 185.132.186.86:49561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/icascreenshots.php"] [unique_id "al4RLDAtbv2vrjByhUqK6AAAAAU"]
[Mon Jul 20 06:14:36.449775 2026] [security2:error] [pid 858085:tid 858304] [client 158.173.166.181:58187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RLDAtbv2vrjByhUqK6QAAAFg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:36.528804 2026] [security2:error] [pid 858085:tid 858274] [client 171.60.139.123:56252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RLDAtbv2vrjByhUqK8QAAADo"]
[Mon Jul 20 06:14:36.528920 2026] [security2:error] [pid 858085:tid 858274] [client 171.60.139.123:56252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RLDAtbv2vrjByhUqK8QAAADo"]
[Mon Jul 20 06:14:36.821875 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:55992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4RLDAtbv2vrjByhUqK9wAAADY"]
[Mon Jul 20 06:14:36.831244 2026] [security2:error] [pid 858085:tid 858328] [client 45.157.112.60:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RLDAtbv2vrjByhUqLBQAAAHA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:36.880723 2026] [security2:error] [pid 858085:tid 858248] [client 57.141.18.74:43846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJagAAIH0"]
[Mon Jul 20 06:14:37.059586 2026] [security2:error] [pid 858085:tid 858288] [client 57.141.18.95:30266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJewAASHs"]
[Mon Jul 20 06:14:37.342196 2026] [security2:error] [pid 858085:tid 858244] [client 57.141.18.56:51032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKDAtbv2vrjByhUqJkAAAHAg"]
[Mon Jul 20 06:14:37.877196 2026] [security2:error] [pid 858085:tid 858218] [client 50.116.65.227:10172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RLTAtbv2vrjByhUqLZgAAAAI"]
[Mon Jul 20 06:14:37.889540 2026] [security2:error] [pid 858085:tid 858283] [client 50.116.65.227:10186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RLTAtbv2vrjByhUqLZwAAAEM"]
[Mon Jul 20 06:14:37.990199 2026] [security2:error] [pid 858085:tid 858100] [remote 172.56.220.104:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.220.56.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLTAtbv2vrjByhUqLbAAABA0"]
[Mon Jul 20 06:14:37.990348 2026] [security2:error] [pid 858085:tid 858220] [client 172.56.220.104:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLTAtbv2vrjByhUqLbAAABA0"]
[Mon Jul 20 06:14:38.016909 2026] [security2:error] [pid 858085:tid 858236] [client 41.173.37.102:10623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLcAAAABQ"]
[Mon Jul 20 06:14:38.017038 2026] [security2:error] [pid 858085:tid 858236] [client 41.173.37.102:10623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLcAAAABQ"]
[Mon Jul 20 06:14:38.225129 2026] [security2:error] [pid 858085:tid 858277] [client 106.192.104.4:53957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLiAAAAD0"]
[Mon Jul 20 06:14:38.225251 2026] [security2:error] [pid 858085:tid 858277] [client 106.192.104.4:53957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLiAAAAD0"]
[Mon Jul 20 06:14:38.233113 2026] [security2:error] [pid 858085:tid 858330] [client 185.132.186.67:30959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/upgrade/bypass.php"] [unique_id "al4RLjAtbv2vrjByhUqLiQAAAHI"]
[Mon Jul 20 06:14:38.455579 2026] [security2:error] [pid 858085:tid 858258] [client 103.141.108.143:49868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLnQAAACo"]
[Mon Jul 20 06:14:38.456139 2026] [security2:error] [pid 858085:tid 858258] [client 103.141.108.143:49868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RLjAtbv2vrjByhUqLnQAAACo"]
[Mon Jul 20 06:14:38.858930 2026] [security2:error] [pid 858085:tid 858339] [client 47.128.122.122:25006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLswAAe0Q"]
[Mon Jul 20 06:14:39.029019 2026] [security2:error] [pid 858085:tid 858297] [client 14.225.17.146:54698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLxAAAAFE"], referer: http://dereckcastellon.com/WordPress
[Mon Jul 20 06:14:39.176596 2026] [security2:error] [pid 858085:tid 858298] [client 45.116.69.230:63363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1AAAAFI"]
[Mon Jul 20 06:14:39.176682 2026] [security2:error] [pid 858085:tid 858298] [client 45.116.69.230:63363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1AAAAFI"]
[Mon Jul 20 06:14:39.217215 2026] [security2:error] [pid 858085:tid 858307] [client 112.213.160.112:31145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1wAAAFs"]
[Mon Jul 20 06:14:39.217330 2026] [security2:error] [pid 858085:tid 858307] [client 112.213.160.112:31145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqL1wAAAFs"]
[Mon Jul 20 06:14:39.234809 2026] [security2:error] [pid 858085:tid 858299] [client 57.141.18.19:36714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKjAtbv2vrjByhUqKJgAAU34"]
[Mon Jul 20 06:14:39.239376 2026] [security2:error] [pid 858085:tid 858331] [client 57.141.18.6:61170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKjAtbv2vrjByhUqKJQAAc1Y"]
[Mon Jul 20 06:14:39.538177 2026] [security2:error] [pid 858085:tid 858168] [remote 162.19.86.63:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RLzAtbv2vrjByhUqL9AAAGFE"]
[Mon Jul 20 06:14:39.730764 2026] [security2:error] [pid 858085:tid 858214] [remote 162.19.86.63:51912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RLzAtbv2vrjByhUqMAQAAcn8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:14:39.845995 2026] [security2:error] [pid 858085:tid 858102] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqMEQAAUg8"]
[Mon Jul 20 06:14:39.846159 2026] [security2:error] [pid 858085:tid 858298] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RLzAtbv2vrjByhUqMEQAAUg8"]
[Mon Jul 20 06:14:40.037853 2026] [security2:error] [pid 858085:tid 858267] [client 57.141.18.94:27438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RKzAtbv2vrjByhUqKcgAAM0M"]
[Mon Jul 20 06:14:40.043382 2026] [security2:error] [pid 858085:tid 858238] [client 185.132.186.67:35795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rk2.php"] [unique_id "al4RMDAtbv2vrjByhUqMGwAAABY"]
[Mon Jul 20 06:14:40.271365 2026] [security2:error] [pid 858085:tid 858302] [client 66.249.73.200:39832] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.grant-mechanical.com"] [uri "/robots.txt"] [unique_id "al4RMDAtbv2vrjByhUqMKQAAAFY"]
[Mon Jul 20 06:14:40.794727 2026] [security2:error] [pid 858085:tid 858257] [client 14.225.17.146:62329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4RLzAtbv2vrjByhUqL0AAAACk"], referer: http://according2plant.com/WordPress
[Mon Jul 20 06:14:41.140703 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:54792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4RMDAtbv2vrjByhUqMZgAAABk"]
[Mon Jul 20 06:14:41.251368 2026] [security2:error] [pid 858085:tid 858152] [remote 97.74.93.24:34456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4RMTAtbv2vrjByhUqMfQAAX0E"]
[Mon Jul 20 06:14:41.595796 2026] [security2:error] [pid 858085:tid 858331] [client 178.152.178.232:36326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RMTAtbv2vrjByhUqMmwAAAHM"]
[Mon Jul 20 06:14:41.595892 2026] [security2:error] [pid 858085:tid 858331] [client 178.152.178.232:36326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RMTAtbv2vrjByhUqMmwAAAHM"]
[Mon Jul 20 06:14:41.735238 2026] [security2:error] [pid 858085:tid 858244] [client 52.109.124.141:12320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4RMTAtbv2vrjByhUqMpAAAABw"]
[Mon Jul 20 06:14:41.853030 2026] [security2:error] [pid 858085:tid 858264] [client 185.132.186.66:64203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/ocean/alam.php"] [unique_id "al4RMTAtbv2vrjByhUqMsAAAADA"]
[Mon Jul 20 06:14:41.934371 2026] [security2:error] [pid 858085:tid 858306] [client 52.109.124.141:12320] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4RMTAtbv2vrjByhUqMuAAAAFo"]
[Mon Jul 20 06:14:41.953812 2026] [security2:error] [pid 858085:tid 858200] [remote 97.74.93.24:34456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4RMTAtbv2vrjByhUqMugAAVHE"], referer: https://mail.sk-financial.com/wp-login.php
[Mon Jul 20 06:14:41.956355 2026] [security2:error] [pid 858085:tid 858258] [client 14.225.17.146:61883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4RMDAtbv2vrjByhUqMMAAAACo"], referer: http://omenana.com/WordPress
[Mon Jul 20 06:14:42.052917 2026] [security2:error] [pid 858085:tid 858243] [client 57.141.18.5:58198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLTAtbv2vrjByhUqLKAAAGxg"]
[Mon Jul 20 06:14:42.177970 2026] [security2:error] [pid 858085:tid 858260] [client 52.59.238.198:22212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqMygAAACw"]
[Mon Jul 20 06:14:42.215270 2026] [security2:error] [pid 858085:tid 858223] [client 14.225.17.146:59055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4RMDAtbv2vrjByhUqMRQAAAAc"], referer: http://margaretspeckogawa.com/WordPress
[Mon Jul 20 06:14:42.320160 2026] [security2:error] [pid 858085:tid 858234] [client 57.141.18.37:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLTAtbv2vrjByhUqLRAAAEl8"]
[Mon Jul 20 06:14:42.329560 2026] [security2:error] [pid 858085:tid 858270] [client 52.111.227.28:33026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4RMjAtbv2vrjByhUqM1wAAADY"]
[Mon Jul 20 06:14:42.411245 2026] [security2:error] [pid 858085:tid 858221] [client 52.111.227.28:33026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4RMjAtbv2vrjByhUqM4QAAAAU"]
[Mon Jul 20 06:14:42.459039 2026] [security2:error] [pid 858085:tid 858171] [remote 95.217.78.234:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqM5gAAP1Q"]
[Mon Jul 20 06:14:42.696253 2026] [security2:error] [pid 858085:tid 858147] [remote 95.217.78.234:35882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqM-AAAMzw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:14:42.763638 2026] [security2:error] [pid 858085:tid 858287] [client 34.34.225.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earle-brown.org"] [uri "/index.php"] [unique_id "al4RLzAtbv2vrjByhUqMGgAARy0"]
[Mon Jul 20 06:14:42.768557 2026] [security2:error] [pid 858085:tid 858236] [client 63.179.149.246:42650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RMjAtbv2vrjByhUqM_AAAABQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:14:42.892228 2026] [security2:error] [pid 858085:tid 858217] [client 50.116.65.227:22596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RMjAtbv2vrjByhUqNCgAAAAE"]
[Mon Jul 20 06:14:42.904652 2026] [security2:error] [pid 858085:tid 858322] [client 50.116.65.227:50620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4RMjAtbv2vrjByhUqNCwAAAGo"]
[Mon Jul 20 06:14:43.198955 2026] [security2:error] [pid 858085:tid 858090] [remote 34.34.225.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "earle-brown.org"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNFAAAcQM"]
[Mon Jul 20 06:14:43.269742 2026] [security2:error] [pid 858085:tid 858290] [client 14.225.17.146:59160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4RMTAtbv2vrjByhUqMsQAAAEo"], referer: http://blaizeaccountingservices.com/WordPress
[Mon Jul 20 06:14:43.487183 2026] [security2:error] [pid 858085:tid 858337] [client 103.77.203.233:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RMzAtbv2vrjByhUqNNQAAAHk"]
[Mon Jul 20 06:14:43.487312 2026] [security2:error] [pid 858085:tid 858337] [client 103.77.203.233:58935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RMzAtbv2vrjByhUqNNQAAAHk"]
[Mon Jul 20 06:14:43.551633 2026] [security2:error] [pid 858085:tid 858281] [client 57.141.18.106:64896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLugAAQQc"]
[Mon Jul 20 06:14:43.649568 2026] [security2:error] [pid 858085:tid 858221] [client 185.132.186.100:42767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/b.php"] [unique_id "al4RMzAtbv2vrjByhUqNSAAAAAU"]
[Mon Jul 20 06:14:43.668224 2026] [security2:error] [pid 858085:tid 858287] [client 14.225.17.146:64010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNPAAAAEc"], referer: http://nextlevelpressurewashing.com/WordPress
[Mon Jul 20 06:14:43.719253 2026] [security2:error] [pid 858085:tid 858224] [client 14.225.17.146:65048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNRwAAAAg"]
[Mon Jul 20 06:14:43.738099 2026] [security2:error] [pid 858085:tid 858249] [client 57.141.18.116:53442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RLjAtbv2vrjByhUqLyAAAIT8"]
[Mon Jul 20 06:14:44.156501 2026] [security2:error] [pid 858085:tid 858287] [client 185.192.69.16:33231] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/000.php"] [unique_id "al4RNDAtbv2vrjByhUqNcgAAAEc"]
[Mon Jul 20 06:14:44.196189 2026] [security2:error] [pid 858085:tid 858183] [remote 173.249.4.11:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNeAAAGWA"]
[Mon Jul 20 06:14:44.251566 2026] [security2:error] [pid 858085:tid 858248] [client 3.109.4.218:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNeQAAACA"]
[Mon Jul 20 06:14:44.251744 2026] [security2:error] [pid 858085:tid 858248] [client 3.109.4.218:56006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNeQAAACA"]
[Mon Jul 20 06:14:44.423362 2026] [security2:error] [pid 858085:tid 858212] [remote 152.228.213.32:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNjAAAV30"]
[Mon Jul 20 06:14:44.504172 2026] [security2:error] [pid 858085:tid 858233] [client 14.225.17.146:64004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNgAAAABE"], referer: http://secretkeynumerology.com/WordPress
[Mon Jul 20 06:14:44.606031 2026] [security2:error] [pid 858085:tid 858264] [client 185.192.69.22:21193] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-admin/css/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNmAAAADA"]
[Mon Jul 20 06:14:44.618280 2026] [security2:error] [pid 858085:tid 858210] [remote 152.228.213.32:52162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNmQAAf3s"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:14:44.664604 2026] [security2:error] [pid 858085:tid 858268] [client 27.96.94.195:38099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNoAAAADQ"]
[Mon Jul 20 06:14:44.665833 2026] [security2:error] [pid 858085:tid 858268] [client 27.96.94.195:38099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RNDAtbv2vrjByhUqNoAAAADQ"]
[Mon Jul 20 06:14:44.686007 2026] [security2:error] [pid 858085:tid 858099] [remote 152.53.111.131:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNogAALgw"]
[Mon Jul 20 06:14:44.862848 2026] [security2:error] [pid 858085:tid 858274] [client 14.225.17.146:54582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNjQAAADo"], referer: http://backandneckpainrelieflaceychiropractor.com/WordPress
[Mon Jul 20 06:14:44.930612 2026] [security2:error] [pid 858085:tid 858164] [remote 152.53.111.131:34464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4RNDAtbv2vrjByhUqNuwAAJU0"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 06:14:45.054962 2026] [security2:error] [pid 858085:tid 858343] [client 185.192.69.32:35773] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-content/plugins/index.php"] [unique_id "al4RNTAtbv2vrjByhUqNyQAAAH8"]
[Mon Jul 20 06:14:45.128055 2026] [security2:error] [pid 858085:tid 858296] [client 98.159.234.160:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RNTAtbv2vrjByhUqN0wAAAFA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:45.244682 2026] [security2:error] [pid 858085:tid 858186] [remote 173.249.4.11:5314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RNTAtbv2vrjByhUqN3AAAEmM"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 06:14:45.459863 2026] [security2:error] [pid 858085:tid 858223] [client 185.132.186.72:26889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/past.php"] [unique_id "al4RNTAtbv2vrjByhUqN9QAAAAc"]
[Mon Jul 20 06:14:45.527201 2026] [security2:error] [pid 858085:tid 858218] [client 14.225.17.146:50772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RNTAtbv2vrjByhUqN6wAAAAI"], referer: https://secretkeynumerology.com/WordPress
[Mon Jul 20 06:14:45.549485 2026] [security2:error] [pid 858085:tid 858225] [client 185.192.69.18:22033] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-content/index.php"] [unique_id "al4RNTAtbv2vrjByhUqOAQAAAAk"]
[Mon Jul 20 06:14:45.601342 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:36105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RNTAtbv2vrjByhUqOAwAAAEo"]
[Mon Jul 20 06:14:45.601499 2026] [security2:error] [pid 858085:tid 858290] [client 181.224.94.124:36105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RNTAtbv2vrjByhUqOAwAAAEo"]
[Mon Jul 20 06:14:45.916015 2026] [security2:error] [pid 858085:tid 858142] [remote 57.141.18.30:65178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5942486"] [unique_id "al4RNTAtbv2vrjByhUqOGwAAGzc"]
[Mon Jul 20 06:14:46.004792 2026] [security2:error] [pid 858085:tid 858269] [client 185.192.69.28:62055] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "wathenbartlett.co.uk"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4RNjAtbv2vrjByhUqOHwAAADU"]
[Mon Jul 20 06:14:46.039275 2026] [security2:error] [pid 858085:tid 858237] [client 14.225.17.146:62402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNoQAAABU"], referer: http://momheadquarters.com/WordPress
[Mon Jul 20 06:14:46.530531 2026] [security2:error] [pid 858085:tid 858273] [client 14.225.17.146:49357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4RNTAtbv2vrjByhUqN_QAAADk"], referer: http://ancestralidadytrance.space/WordPress
[Mon Jul 20 06:14:46.663391 2026] [security2:error] [pid 858085:tid 858292] [client 158.173.89.95:31269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RNjAtbv2vrjByhUqOVgAAAEw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:14:46.769256 2026] [security2:error] [pid 858085:tid 858173] [remote 157.66.26.183:44856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RNjAtbv2vrjByhUqOXQAAcVY"]
[Mon Jul 20 06:14:46.769478 2026] [security2:error] [pid 858085:tid 858329] [client 157.66.26.183:44856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RNjAtbv2vrjByhUqOXQAAcVY"]
[Mon Jul 20 06:14:47.212562 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.80:36582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RMjAtbv2vrjByhUqM3AAADXU"]
[Mon Jul 20 06:14:47.242616 2026] [security2:error] [pid 858085:tid 858262] [client 171.60.139.123:56737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RNzAtbv2vrjByhUqOhgAAAC4"]
[Mon Jul 20 06:14:47.242764 2026] [security2:error] [pid 858085:tid 858262] [client 171.60.139.123:56737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RNzAtbv2vrjByhUqOhgAAAC4"]
[Mon Jul 20 06:14:47.263021 2026] [security2:error] [pid 858085:tid 858236] [client 185.132.186.58:44555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/as.php"] [unique_id "al4RNzAtbv2vrjByhUqOiAAAABQ"]
[Mon Jul 20 06:14:47.305885 2026] [security2:error] [pid 858085:tid 858250] [client 57.141.18.45:40212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RMjAtbv2vrjByhUqM5QAAImE"]
[Mon Jul 20 06:14:47.417901 2026] [security2:error] [pid 858085:tid 858238] [client 50.116.65.227:50696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RNzAtbv2vrjByhUqOlAAAABY"]
[Mon Jul 20 06:14:47.427297 2026] [security2:error] [pid 858085:tid 858288] [client 50.116.65.227:50706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RNzAtbv2vrjByhUqOlgAAAEg"]
[Mon Jul 20 06:14:47.820931 2026] [security2:error] [pid 858085:tid 858102] [remote 5.161.225.162:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4RNzAtbv2vrjByhUqOvgAAGg8"]
[Mon Jul 20 06:14:47.821131 2026] [security2:error] [pid 858085:tid 858241] [client 14.225.17.146:63828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4RNzAtbv2vrjByhUqOmgAAABk"]
[Mon Jul 20 06:14:47.938836 2026] [security2:error] [pid 858085:tid 858098] [remote 81.173.115.7:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RNzAtbv2vrjByhUqOxAAAVQs"]
[Mon Jul 20 06:14:47.983795 2026] [security2:error] [pid 858085:tid 858136] [remote 57.141.18.74:41256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5326337"] [unique_id "al4RNzAtbv2vrjByhUqOxQAAPDE"]
[Mon Jul 20 06:14:48.122993 2026] [security2:error] [pid 858085:tid 858197] [remote 81.173.115.7:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RODAtbv2vrjByhUqO0AAAG24"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:14:48.263847 2026] [security2:error] [pid 858085:tid 858222] [client 52.167.144.166:57306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daseighty.net"] [uri "/gallery/main.php"] [unique_id "al4RODAtbv2vrjByhUqO3AAAAAY"]
[Mon Jul 20 06:14:48.421810 2026] [security2:error] [pid 858085:tid 858320] [client 114.119.154.65:36129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toddnielsen.com"] [uri "/virtual-ceocoo-service/"] [unique_id "al4RODAtbv2vrjByhUqO6AAAAGg"], referer: http://toddnielsen.com/leadership-traits-2/leadership-trait-to-ponder-simplicity
[Mon Jul 20 06:14:48.572856 2026] [security2:error] [pid 858085:tid 858241] [client 41.173.37.102:11069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO9AAAABk"]
[Mon Jul 20 06:14:48.572948 2026] [security2:error] [pid 858085:tid 858241] [client 41.173.37.102:11069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO9AAAABk"]
[Mon Jul 20 06:14:48.650506 2026] [security2:error] [pid 858085:tid 858198] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO-QAAWG8"]
[Mon Jul 20 06:14:48.650744 2026] [security2:error] [pid 858085:tid 858304] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqO-QAAWG8"]
[Mon Jul 20 06:14:48.784033 2026] [security2:error] [pid 858085:tid 858280] [client 104.234.53.52:33875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RODAtbv2vrjByhUqO_AAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:48.850394 2026] [security2:error] [pid 858085:tid 858112] [remote 152.228.213.32:52170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqPEgAAXBk"]
[Mon Jul 20 06:14:48.850533 2026] [security2:error] [pid 858085:tid 858308] [client 152.228.213.32:52170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RODAtbv2vrjByhUqPEgAAXBk"]
[Mon Jul 20 06:14:49.038167 2026] [security2:error] [pid 858085:tid 858295] [client 104.234.53.52:33875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ROTAtbv2vrjByhUqPJQAAAE8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:49.066908 2026] [security2:error] [pid 858085:tid 858342] [client 185.132.186.102:58491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/sst.php"] [unique_id "al4ROTAtbv2vrjByhUqPKQAAAH4"]
[Mon Jul 20 06:14:49.144024 2026] [security2:error] [pid 858085:tid 858271] [client 46.110.96.34:18088] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4ROTAtbv2vrjByhUqPLgAAADc"]
[Mon Jul 20 06:14:49.147979 2026] [security2:error] [pid 858085:tid 858288] [client 103.141.108.143:50347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPMAAAAEg"]
[Mon Jul 20 06:14:49.148627 2026] [security2:error] [pid 858085:tid 858288] [client 103.141.108.143:50347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPMAAAAEg"]
[Mon Jul 20 06:14:49.355792 2026] [security2:error] [pid 858085:tid 858340] [client 14.225.17.146:57204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqO3QAAAHw"], referer: http://getgarrison.com/WordPress
[Mon Jul 20 06:14:49.441037 2026] [security2:error] [pid 858085:tid 858275] [client 57.141.18.113:21940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RMzAtbv2vrjByhUqNXwAAO0A"]
[Mon Jul 20 06:14:49.784730 2026] [security2:error] [pid 858085:tid 858317] [client 45.116.69.230:63898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPXwAAAGU"]
[Mon Jul 20 06:14:49.784837 2026] [security2:error] [pid 858085:tid 858317] [client 45.116.69.230:63898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPXwAAAGU"]
[Mon Jul 20 06:14:49.960473 2026] [security2:error] [pid 858085:tid 858260] [client 112.213.160.112:8553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPbQAAACw"]
[Mon Jul 20 06:14:49.960605 2026] [security2:error] [pid 858085:tid 858260] [client 112.213.160.112:8553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4ROTAtbv2vrjByhUqPbQAAACw"]
[Mon Jul 20 06:14:50.034145 2026] [security2:error] [pid 858085:tid 858281] [client 57.141.18.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ROTAtbv2vrjByhUqPagAAAEE"]
[Mon Jul 20 06:14:50.069853 2026] [security2:error] [pid 858085:tid 858187] [remote 5.161.225.162:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ROjAtbv2vrjByhUqPdgAAQ2Q"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:14:50.093506 2026] [security2:error] [pid 858085:tid 858156] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4ROjAtbv2vrjByhUqPegAAakU"]
[Mon Jul 20 06:14:50.339142 2026] [security2:error] [pid 858085:tid 858119] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4ROjAtbv2vrjByhUqPkQAAciA"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 06:14:50.406079 2026] [security2:error] [pid 858085:tid 858339] [client 106.192.104.4:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlAAAAHs"]
[Mon Jul 20 06:14:50.406179 2026] [security2:error] [pid 858085:tid 858339] [client 106.192.104.4:54496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlAAAAHs"]
[Mon Jul 20 06:14:50.518103 2026] [security2:error] [pid 858085:tid 858159] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlwAABkg"]
[Mon Jul 20 06:14:50.518248 2026] [security2:error] [pid 858085:tid 858222] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ROjAtbv2vrjByhUqPlwAABkg"]
[Mon Jul 20 06:14:50.807702 2026] [security2:error] [pid 858085:tid 858224] [client 57.141.18.63:64848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNDAtbv2vrjByhUqNvgAACFs"]
[Mon Jul 20 06:14:50.875351 2026] [security2:error] [pid 858085:tid 858324] [client 185.132.186.62:62543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/edit-tags.php"] [unique_id "al4ROjAtbv2vrjByhUqPtAAAAGw"]
[Mon Jul 20 06:14:51.220601 2026] [security2:error] [pid 858085:tid 858121] [remote 78.46.157.202:35796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqPzAAAWCI"]
[Mon Jul 20 06:14:51.433616 2026] [security2:error] [pid 858085:tid 858089] [remote 78.46.157.202:35796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP4wAAAAI"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:14:51.454395 2026] [security2:error] [pid 858085:tid 858326] [client 57.141.18.114:23990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNTAtbv2vrjByhUqN_AAAbnI"]
[Mon Jul 20 06:14:51.511081 2026] [security2:error] [pid 858085:tid 858087] [remote 152.228.213.32:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP5wAAUAA"]
[Mon Jul 20 06:14:51.511303 2026] [security2:error] [pid 858085:tid 858253] [client 50.116.65.227:57810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ROzAtbv2vrjByhUqP6QAAACU"]
[Mon Jul 20 06:14:51.522961 2026] [security2:error] [pid 858085:tid 858236] [client 50.116.65.227:34620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ROzAtbv2vrjByhUqP6gAAAGE"]
[Mon Jul 20 06:14:51.642816 2026] [security2:error] [pid 858085:tid 858312] [client 27.96.94.195:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ROzAtbv2vrjByhUqP7wAAAGA"]
[Mon Jul 20 06:14:51.643595 2026] [security2:error] [pid 858085:tid 858312] [client 27.96.94.195:37194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ROzAtbv2vrjByhUqP7wAAAGA"]
[Mon Jul 20 06:14:51.671373 2026] [security2:error] [pid 858085:tid 858098] [remote 167.233.114.32:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP8wAAZws"]
[Mon Jul 20 06:14:51.716377 2026] [security2:error] [pid 858085:tid 858193] [remote 152.228.213.32:52186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqP9wAAdWo"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:14:51.876702 2026] [security2:error] [pid 858085:tid 858106] [remote 167.233.114.32:35142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ROzAtbv2vrjByhUqQCAAAIxM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:14:52.146104 2026] [security2:error] [pid 858085:tid 858299] [client 14.225.17.146:54519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4ROjAtbv2vrjByhUqPtgAAAFM"], referer: http://christiancountytrumpet.com/WordPress
[Mon Jul 20 06:14:52.449501 2026] [security2:error] [pid 858085:tid 858223] [client 57.141.18.92:63312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNjAtbv2vrjByhUqOQgAAB0Q"]
[Mon Jul 20 06:14:52.455046 2026] [security2:error] [pid 858085:tid 858310] [client 57.141.18.3:63888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNjAtbv2vrjByhUqOQQAAXiM"]
[Mon Jul 20 06:14:52.676327 2026] [security2:error] [pid 858085:tid 858276] [client 185.132.186.71:54113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wsax.php"] [unique_id "al4RPDAtbv2vrjByhUqQSAAAADw"]
[Mon Jul 20 06:14:52.724920 2026] [security2:error] [pid 858085:tid 858301] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4RPDAtbv2vrjByhUqQTwAAAFU"]
[Mon Jul 20 06:14:52.774223 2026] [security2:error] [pid 858085:tid 858309] [client 70.115.45.82:43988] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4RPDAtbv2vrjByhUqQSgAAAF0"]
[Mon Jul 20 06:14:52.809276 2026] [security2:error] [pid 858085:tid 858305] [client 57.141.18.95:40538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNjAtbv2vrjByhUqOZgAAWXk"]
[Mon Jul 20 06:14:52.914551 2026] [security2:error] [pid 858085:tid 858258] [client 57.141.18.83:64508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNzAtbv2vrjByhUqOcwAAKjo"]
[Mon Jul 20 06:14:53.001551 2026] [core:error] [pid 858085:tid 858283] [client 79.127.181.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:53.001579 2026] [core:error] [pid 858085:tid 858283] [client 79.127.181.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:53.086704 2026] [security2:error] [pid 858085:tid 858342] [client 104.234.53.63:57319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RPDAtbv2vrjByhUqQZQAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:53.374103 2026] [security2:error] [pid 858085:tid 858149] [remote 117.0.21.154:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQhgAAQT4"]
[Mon Jul 20 06:14:53.445626 2026] [security2:error] [pid 858085:tid 858250] [client 57.141.18.65:29260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RNzAtbv2vrjByhUqOrgAAIlU"]
[Mon Jul 20 06:14:53.467842 2026] [security2:error] [pid 858085:tid 858132] [remote 5.161.225.162:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQmQAAdy0"]
[Mon Jul 20 06:14:53.719632 2026] [security2:error] [pid 858085:tid 858334] [client 14.225.17.146:63954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4RPTAtbv2vrjByhUqQeQAAAHY"]
[Mon Jul 20 06:14:53.878030 2026] [security2:error] [pid 858085:tid 858213] [remote 117.0.21.154:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQuwAAf34"], referer: https://mail.holistichealthmassagenz.com/wp-login.php
[Mon Jul 20 06:14:53.895119 2026] [security2:error] [pid 858085:tid 858148] [remote 5.161.225.162:44440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQvAAAHD0"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:14:53.959714 2026] [security2:error] [pid 858085:tid 858242] [client 57.141.18.4:62366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqO3gAAGgw"]
[Mon Jul 20 06:14:53.963891 2026] [security2:error] [pid 858085:tid 858159] [remote 72.167.132.114:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RPTAtbv2vrjByhUqQxAAAW0g"]
[Mon Jul 20 06:14:54.033037 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RPjAtbv2vrjByhUqQywAAADo"]
[Mon Jul 20 06:14:54.033450 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:59584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RPjAtbv2vrjByhUqQywAAADo"]
[Mon Jul 20 06:14:54.174982 2026] [security2:error] [pid 858085:tid 858330] [client 85.204.70.96:33812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4RPjAtbv2vrjByhUqQzgAAAHI"]
[Mon Jul 20 06:14:54.200525 2026] [security2:error] [pid 858085:tid 858234] [client 57.141.18.14:38384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqO6QAAEhc"]
[Mon Jul 20 06:14:54.358805 2026] [security2:error] [pid 858085:tid 858262] [client 14.224.227.113:55614] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4RPjAtbv2vrjByhUqQ3wAAAC4"]
[Mon Jul 20 06:14:54.397706 2026] [security2:error] [pid 858085:tid 858192] [remote 72.167.132.114:35022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RPjAtbv2vrjByhUqQ4gAAf2k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:14:54.460035 2026] [security2:error] [pid 858085:tid 858236] [client 85.204.70.96:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.karimnawfal.com"] [uri "/xmlrpc.php"] [unique_id "al4RPjAtbv2vrjByhUqQ6QAAABQ"]
[Mon Jul 20 06:14:54.475583 2026] [security2:error] [pid 858085:tid 858302] [client 185.132.186.77:59845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/bless.php%20"] [unique_id "al4RPjAtbv2vrjByhUqQ7AAAAFY"]
[Mon Jul 20 06:14:54.549076 2026] [security2:error] [pid 858085:tid 858328] [client 57.141.18.76:36068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RODAtbv2vrjByhUqPJAAAcE8"]
[Mon Jul 20 06:14:54.805966 2026] [security2:error] [pid 858085:tid 858246] [client 14.225.17.146:57380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqRAwAAAB4"], referer: http://dasmarque.com/WordPress
[Mon Jul 20 06:14:55.014646 2026] [security2:error] [pid 858085:tid 858296] [client 85.204.70.96:33826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqRHAAAAFA"]
[Mon Jul 20 06:14:55.034437 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.0:63952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROTAtbv2vrjByhUqPVgAAKTs"]
[Mon Jul 20 06:14:55.186400 2026] [security2:error] [pid 858085:tid 858258] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqRBwAAACo"]
[Mon Jul 20 06:14:55.236257 2026] [security2:error] [pid 858085:tid 858219] [client 178.152.178.232:36065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqRNQAAAAM"]
[Mon Jul 20 06:14:55.236450 2026] [security2:error] [pid 858085:tid 858219] [client 178.152.178.232:36065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqRNQAAAAM"]
[Mon Jul 20 06:14:55.276585 2026] [security2:error] [pid 858085:tid 858220] [client 43.205.139.3:36822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqROQAAAAQ"]
[Mon Jul 20 06:14:55.276705 2026] [security2:error] [pid 858085:tid 858220] [client 43.205.139.3:36822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RPzAtbv2vrjByhUqROQAAAAQ"]
[Mon Jul 20 06:14:55.286330 2026] [security2:error] [pid 858085:tid 858277] [client 85.204.70.96:33836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqROwAAAD0"]
[Mon Jul 20 06:14:55.352826 2026] [security2:error] [pid 858085:tid 858341] [client 57.141.18.90:36100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROjAtbv2vrjByhUqPcwAAfVw"]
[Mon Jul 20 06:14:55.489390 2026] [security2:error] [pid 858085:tid 858293] [client 74.7.227.179:53194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RPzAtbv2vrjByhUqRQgAATVk"], referer: https://tejasenvironmental.com/p=141246
[Mon Jul 20 06:14:55.491816 2026] [security2:error] [pid 858085:tid 858327] [client 70.115.45.82:44506] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/2025/12/23/the-last-fisher-of-oporoza-by-tomilola-adejumo/"] [unique_id "al4RPjAtbv2vrjByhUqQ_wAAAG8"]
[Mon Jul 20 06:14:55.545329 2026] [security2:error] [pid 858085:tid 858320] [client 85.204.70.96:33852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqRUwAAAGg"]
[Mon Jul 20 06:14:55.693454 2026] [security2:error] [pid 858085:tid 858337] [client 44.245.170.32:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4RPzAtbv2vrjByhUqRYAAAAHk"]
[Mon Jul 20 06:14:55.790543 2026] [security2:error] [pid 858085:tid 858270] [client 14.225.17.146:65347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4RPTAtbv2vrjByhUqQegAAADY"], referer: http://drewsasburyparkbeachhouse.com/WordPress
[Mon Jul 20 06:14:55.816117 2026] [security2:error] [pid 858085:tid 858330] [client 85.204.70.96:33866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4RPzAtbv2vrjByhUqRZQAAAHI"]
[Mon Jul 20 06:14:56.011132 2026] [security2:error] [pid 858085:tid 858280] [client 3.75.183.99:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRdAAAAEA"]
[Mon Jul 20 06:14:56.081714 2026] [security2:error] [pid 858085:tid 858323] [client 85.204.70.96:33876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqReAAAAGs"]
[Mon Jul 20 06:14:56.146333 2026] [security2:error] [pid 858085:tid 858325] [client 181.224.94.124:46889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRegAAAG0"]
[Mon Jul 20 06:14:56.146464 2026] [security2:error] [pid 858085:tid 858325] [client 181.224.94.124:46889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRegAAAG0"]
[Mon Jul 20 06:14:56.208453 2026] [security2:error] [pid 858085:tid 858282] [client 14.225.17.146:56436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqQ5AAAAEI"], referer: http://qualitycoatingsinspection.com/WordPress
[Mon Jul 20 06:14:56.231925 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.44:42952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROzAtbv2vrjByhUqPygAADRo"]
[Mon Jul 20 06:14:56.289267 2026] [security2:error] [pid 858085:tid 858234] [client 185.132.186.67:34699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/system_cache.php"] [unique_id "al4RQDAtbv2vrjByhUqRgwAAABI"]
[Mon Jul 20 06:14:56.337019 2026] [security2:error] [pid 858085:tid 858241] [client 104.234.53.63:57319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRhwAAABk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:56.348788 2026] [security2:error] [pid 858085:tid 858310] [client 85.204.70.96:33886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqRiQAAAF4"]
[Mon Jul 20 06:14:56.436325 2026] [security2:error] [pid 858085:tid 858240] [client 57.141.18.74:37178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROzAtbv2vrjByhUqP2wAAGEY"]
[Mon Jul 20 06:14:56.583997 2026] [security2:error] [pid 858085:tid 858329] [client 63.179.149.246:24052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRpAAAAHE"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:14:56.584646 2026] [security2:error] [pid 858085:tid 858251] [client 51.161.37.89:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "technicalseohouse.com"] [uri "/sitemap_index.xml"] [unique_id "al4RQDAtbv2vrjByhUqRogAAACM"]
[Mon Jul 20 06:14:56.596430 2026] [security2:error] [pid 858085:tid 858327] [client 51.161.37.89:15684] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "technicalseohouse.com"] [uri "/sitemap_index.xml"] [unique_id "al4RQDAtbv2vrjByhUqRnQAAbxg"]
[Mon Jul 20 06:14:56.623019 2026] [security2:error] [pid 858085:tid 858312] [client 85.204.70.96:33902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqRqAAAAGA"]
[Mon Jul 20 06:14:56.716688 2026] [security2:error] [pid 858085:tid 858339] [client 82.156.3.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RQDAtbv2vrjByhUqRmAAAexk"]
[Mon Jul 20 06:14:56.803687 2026] [security2:error] [pid 858085:tid 858149] [remote 100.42.189.89:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRtAAAJT4"]
[Mon Jul 20 06:14:56.803812 2026] [security2:error] [pid 858085:tid 858253] [client 100.42.189.89:39364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4RQDAtbv2vrjByhUqRtAAAJT4"]
[Mon Jul 20 06:14:56.896221 2026] [security2:error] [pid 858085:tid 858281] [client 85.204.70.96:33908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4RQDAtbv2vrjByhUqRwgAAAEE"]
[Mon Jul 20 06:14:56.929496 2026] [security2:error] [pid 858085:tid 858276] [client 104.234.53.48:39133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RQDAtbv2vrjByhUqRxgAAADw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:56.950433 2026] [security2:error] [pid 858085:tid 858249] [client 51.161.37.89:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "technicalseohouse.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RQDAtbv2vrjByhUqRwwAAACE"]
[Mon Jul 20 06:14:56.951958 2026] [security2:error] [pid 858085:tid 858216] [client 57.141.18.89:33910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ROzAtbv2vrjByhUqQBwAAAHs"]
[Mon Jul 20 06:14:56.955723 2026] [security2:error] [pid 858085:tid 858254] [client 51.161.37.89:15696] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "technicalseohouse.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RQDAtbv2vrjByhUqRvwAAJmc"]
[Mon Jul 20 06:14:56.981455 2026] [autoindex:error] [pid 858085:tid 858240] [client 198.235.24.40:59316] AH01276: Cannot serve directory /home3/represh9/public_html/representgrace/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://representgrace.representgrace.com/
[Mon Jul 20 06:14:57.037847 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.037873 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.116937 2026] [security2:error] [pid 858085:tid 858242] [client 14.225.17.146:63948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4RPzAtbv2vrjByhUqRQAAAABo"], referer: http://outlookturf.com/WordPress
[Mon Jul 20 06:14:57.166198 2026] [security2:error] [pid 858085:tid 858234] [client 14.225.17.146:65253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4RQTAtbv2vrjByhUqRzwAAABI"], referer: https://qualitycoatingsinspection.com/WordPress
[Mon Jul 20 06:14:57.190582 2026] [core:error] [pid 858085:tid 858276] [client 14.225.17.146:54933] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.190607 2026] [core:error] [pid 858085:tid 858276] [client 14.225.17.146:54933] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.193581 2026] [security2:error] [pid 858085:tid 858305] [client 85.204.70.96:33922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqR4QAAAFk"]
[Mon Jul 20 06:14:57.343563 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.343580 2026] [core:error] [pid 858085:tid 858324] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.343637 2026] [core:error] [pid 858085:tid 858325] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.343650 2026] [core:error] [pid 858085:tid 858325] [client 23.137.105.72:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:57.459178 2026] [security2:error] [pid 858085:tid 858235] [client 85.204.70.96:33924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqR_gAAABM"]
[Mon Jul 20 06:14:57.467014 2026] [autoindex:error] [pid 858085:tid 858256] [client 91.90.122.10:19844] AH01276: Cannot serve directory /home3/kybxxpmy/public_html/website_0ad88c1f/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:14:57.538321 2026] [security2:error] [pid 858085:tid 858159] [remote 100.42.189.89:39386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RQTAtbv2vrjByhUqSBgAAR0g"]
[Mon Jul 20 06:14:57.538449 2026] [security2:error] [pid 858085:tid 858287] [client 100.42.189.89:39386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RQTAtbv2vrjByhUqSBgAAR0g"]
[Mon Jul 20 06:14:57.718689 2026] [security2:error] [pid 858085:tid 858223] [client 85.204.70.96:33926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqSFAAAAAc"]
[Mon Jul 20 06:14:57.988330 2026] [security2:error] [pid 858085:tid 858234] [client 85.204.70.96:33936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4RQTAtbv2vrjByhUqSKgAAABI"]
[Mon Jul 20 06:14:58.090803 2026] [security2:error] [pid 858085:tid 858313] [client 185.132.186.63:51973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/files.php"] [unique_id "al4RQjAtbv2vrjByhUqSNwAAAGE"]
[Mon Jul 20 06:14:58.156841 2026] [security2:error] [pid 858085:tid 858273] [client 171.60.139.123:57228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RQjAtbv2vrjByhUqSPQAAADk"]
[Mon Jul 20 06:14:58.156963 2026] [security2:error] [pid 858085:tid 858273] [client 171.60.139.123:57228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RQjAtbv2vrjByhUqSPQAAADk"]
[Mon Jul 20 06:14:58.254455 2026] [security2:error] [pid 858085:tid 858322] [client 85.204.70.96:33948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4RQjAtbv2vrjByhUqSTAAAAGo"]
[Mon Jul 20 06:14:58.315981 2026] [security2:error] [pid 858085:tid 858221] [client 57.141.18.55:44546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPTAtbv2vrjByhUqQbgAABUA"]
[Mon Jul 20 06:14:58.527649 2026] [security2:error] [pid 858085:tid 858248] [client 85.204.70.96:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4RQjAtbv2vrjByhUqSWQAAACA"]
[Mon Jul 20 06:14:58.608147 2026] [security2:error] [pid 858085:tid 858229] [client 14.225.17.146:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4RQjAtbv2vrjByhUqSVQAAAA0"], referer: http://betterbonddogtraining.com/WordPress
[Mon Jul 20 06:14:58.800535 2026] [security2:error] [pid 858085:tid 858221] [client 85.204.70.96:33962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4RQjAtbv2vrjByhUqSawAAAAU"]
[Mon Jul 20 06:14:58.850201 2026] [security2:error] [pid 858085:tid 858103] [remote 57.141.18.37:27032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6349154"] [unique_id "al4RQjAtbv2vrjByhUqSbwAAcxA"]
[Mon Jul 20 06:14:59.066945 2026] [security2:error] [pid 858085:tid 858326] [client 85.204.70.96:33968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.karimnawfal.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4RQzAtbv2vrjByhUqSggAAAG4"]
[Mon Jul 20 06:14:59.090804 2026] [core:error] [pid 858085:tid 858228] [client 205.210.31.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:59.090826 2026] [core:error] [pid 858085:tid 858228] [client 205.210.31.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:14:59.170632 2026] [security2:error] [pid 858085:tid 858230] [client 41.173.37.102:11526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSjQAAAA4"]
[Mon Jul 20 06:14:59.170735 2026] [security2:error] [pid 858085:tid 858230] [client 41.173.37.102:11526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSjQAAAA4"]
[Mon Jul 20 06:14:59.193337 2026] [security2:error] [pid 858085:tid 858106] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSkwAACBM"]
[Mon Jul 20 06:14:59.193537 2026] [security2:error] [pid 858085:tid 858224] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSkwAACBM"]
[Mon Jul 20 06:14:59.223052 2026] [security2:error] [pid 858085:tid 858096] [remote 113.160.142.119:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4RQzAtbv2vrjByhUqSmAAATQk"]
[Mon Jul 20 06:14:59.446561 2026] [security2:error] [pid 858085:tid 858227] [client 57.141.18.49:22278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqQzAAACwc"]
[Mon Jul 20 06:14:59.478960 2026] [security2:error] [pid 858085:tid 858320] [client 104.234.53.64:23661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RQzAtbv2vrjByhUqSpwAAAGg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:14:59.501119 2026] [security2:error] [pid 858085:tid 858286] [client 14.225.17.146:55141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4RQzAtbv2vrjByhUqSnQAAAEY"], referer: http://thesoloceos.com/WordPress
[Mon Jul 20 06:14:59.735520 2026] [security2:error] [pid 858085:tid 858322] [client 85.208.96.194:30344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4RQzAtbv2vrjByhUqSvQAAAGo"]
[Mon Jul 20 06:14:59.735626 2026] [security2:error] [pid 858085:tid 858322] [client 85.208.96.194:30344] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4RQzAtbv2vrjByhUqSvQAAAGo"]
[Mon Jul 20 06:14:59.749498 2026] [security2:error] [pid 858085:tid 858240] [client 65.1.132.125:52490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RQzAtbv2vrjByhUqSwwAAABg"]
[Mon Jul 20 06:14:59.870494 2026] [security2:error] [pid 858085:tid 858229] [client 103.141.108.143:50831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSywAAAA0"]
[Mon Jul 20 06:14:59.871854 2026] [security2:error] [pid 858085:tid 858229] [client 103.141.108.143:50831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RQzAtbv2vrjByhUqSywAAAA0"]
[Mon Jul 20 06:14:59.893810 2026] [security2:error] [pid 858085:tid 858320] [client 185.132.186.90:45361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/tflow/admin-footer.php"] [unique_id "al4RQzAtbv2vrjByhUqSzAAAAGg"]
[Mon Jul 20 06:15:00.126764 2026] [security2:error] [pid 858085:tid 858138] [remote 113.160.142.119:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4RRDAtbv2vrjByhUqS2QAAYjM"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 06:15:00.132650 2026] [security2:error] [pid 858085:tid 858275] [client 85.208.96.196:13678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/diffuser-options-for-young-living-premium-starter-kit/"] [unique_id "al4RRDAtbv2vrjByhUqS3AAAADs"]
[Mon Jul 20 06:15:00.132746 2026] [security2:error] [pid 858085:tid 858275] [client 85.208.96.196:13678] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/diffuser-options-for-young-living-premium-starter-kit/"] [unique_id "al4RRDAtbv2vrjByhUqS3AAAADs"]
[Mon Jul 20 06:15:00.171861 2026] [security2:error] [pid 858085:tid 858175] [remote 188.166.241.141:39076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4RRDAtbv2vrjByhUqS4AAAclg"]
[Mon Jul 20 06:15:00.446140 2026] [security2:error] [pid 858085:tid 858343] [client 57.141.18.90:32512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPjAtbv2vrjByhUqRFgAAfw8"]
[Mon Jul 20 06:15:00.489373 2026] [security2:error] [pid 858085:tid 858335] [client 45.116.69.230:64431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqS-gAAAHc"]
[Mon Jul 20 06:15:00.489671 2026] [security2:error] [pid 858085:tid 858335] [client 45.116.69.230:64431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqS-gAAAHc"]
[Mon Jul 20 06:15:00.523788 2026] [security2:error] [pid 858085:tid 858218] [client 14.225.17.146:58643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqS9QAAAAI"], referer: https://thesoloceos.com/WordPress
[Mon Jul 20 06:15:00.557541 2026] [security2:error] [pid 858085:tid 858156] [remote 188.166.241.141:39076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4RRDAtbv2vrjByhUqTAQAAfUU"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:15:00.619181 2026] [security2:error] [pid 858085:tid 858267] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqS0QAAMzU"], referer: http://ardhalwafaa.com/WordPress
[Mon Jul 20 06:15:00.627021 2026] [security2:error] [pid 858085:tid 858338] [client 106.192.104.4:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTDQAAAHo"]
[Mon Jul 20 06:15:00.627150 2026] [security2:error] [pid 858085:tid 858338] [client 106.192.104.4:54970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTDQAAAHo"]
[Mon Jul 20 06:15:00.692342 2026] [security2:error] [pid 858085:tid 858316] [client 50.116.65.227:29988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4RRDAtbv2vrjByhUqTEwAAAGQ"]
[Mon Jul 20 06:15:00.706817 2026] [security2:error] [pid 858085:tid 858303] [client 50.116.65.227:22852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4RRDAtbv2vrjByhUqTGAAAAFc"]
[Mon Jul 20 06:15:00.730626 2026] [security2:error] [pid 858085:tid 858259] [client 112.213.160.112:8513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.160.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTHwAAACs"]
[Mon Jul 20 06:15:00.730798 2026] [security2:error] [pid 858085:tid 858259] [client 112.213.160.112:8513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4RRDAtbv2vrjByhUqTHwAAACs"]
[Mon Jul 20 06:15:01.299158 2026] [security2:error] [pid 858085:tid 858100] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RRTAtbv2vrjByhUqTTAAAbQ0"]
[Mon Jul 20 06:15:01.299346 2026] [security2:error] [pid 858085:tid 858325] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RRTAtbv2vrjByhUqTTAAAbQ0"]
[Mon Jul 20 06:15:01.451158 2026] [security2:error] [pid 858085:tid 858151] [remote 5.161.225.162:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RRTAtbv2vrjByhUqTWgAAJkA"]
[Mon Jul 20 06:15:01.534388 2026] [security2:error] [pid 858085:tid 858199] [remote 47.86.33.52:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4RRTAtbv2vrjByhUqTXgAABXA"]
[Mon Jul 20 06:15:01.595943 2026] [security2:error] [pid 858085:tid 858304] [client 57.141.18.24:62682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RPzAtbv2vrjByhUqRbQAAWDI"]
[Mon Jul 20 06:15:01.699434 2026] [security2:error] [pid 858085:tid 858337] [client 185.132.186.80:61401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/footer-default.php"] [unique_id "al4RRTAtbv2vrjByhUqTbQAAAHk"]
[Mon Jul 20 06:15:01.789842 2026] [security2:error] [pid 858085:tid 858105] [remote 5.161.225.162:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RRTAtbv2vrjByhUqTdwAAARI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:01.937300 2026] [security2:error] [pid 858085:tid 858309] [client 14.225.17.146:56370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqS-QAAAF0"], referer: http://eframiproperties.com/WordPress
[Mon Jul 20 06:15:02.253885 2026] [security2:error] [pid 858085:tid 858302] [client 57.141.18.81:25284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQDAtbv2vrjByhUqRqgAAVkM"]
[Mon Jul 20 06:15:02.323560 2026] [security2:error] [pid 858085:tid 858220] [client 57.141.18.45:29026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQDAtbv2vrjByhUqRqQAABHE"]
[Mon Jul 20 06:15:02.617721 2026] [security2:error] [pid 858085:tid 858252] [client 14.225.17.146:57660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4RRjAtbv2vrjByhUqTugAAACQ"], referer: http://alrowad-hub.net/WordPress
[Mon Jul 20 06:15:02.713726 2026] [security2:error] [pid 858085:tid 858317] [client 57.141.18.30:49840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQTAtbv2vrjByhUqR6AAAZXg"]
[Mon Jul 20 06:15:02.766218 2026] [security2:error] [pid 858085:tid 858219] [client 27.96.94.195:37943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT2wAAAAM"]
[Mon Jul 20 06:15:02.766357 2026] [security2:error] [pid 858085:tid 858219] [client 27.96.94.195:37943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT2wAAAAM"]
[Mon Jul 20 06:15:02.789537 2026] [security2:error] [pid 858085:tid 858319] [client 178.152.178.232:36832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT3gAAAGc"]
[Mon Jul 20 06:15:02.789692 2026] [security2:error] [pid 858085:tid 858319] [client 178.152.178.232:36832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RRjAtbv2vrjByhUqT3gAAAGc"]
[Mon Jul 20 06:15:02.828246 2026] [security2:error] [pid 858085:tid 858231] [client 14.225.17.146:50862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4RRTAtbv2vrjByhUqTMwAAAA8"], referer: http://amalia-capital.com/WordPress
[Mon Jul 20 06:15:02.986421 2026] [security2:error] [pid 858085:tid 858256] [client 66.249.65.39:37484] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.treehousecraft.com"] [uri "/robots.txt"] [unique_id "al4RRjAtbv2vrjByhUqT-AAAACg"]
[Mon Jul 20 06:15:03.309650 2026] [security2:error] [pid 858085:tid 858118] [remote 45.90.123.233:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUGQAACB8"]
[Mon Jul 20 06:15:03.389548 2026] [security2:error] [pid 858085:tid 858190] [remote 47.86.33.52:9720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUIgAAJ2c"], referer: https://technicalseohouse.com/wp-login.php
[Mon Jul 20 06:15:03.458165 2026] [security2:error] [pid 858085:tid 858210] [remote 188.40.28.4:45624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUJQAABns"]
[Mon Jul 20 06:15:03.493853 2026] [security2:error] [pid 858085:tid 858225] [client 57.141.18.23:28070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQjAtbv2vrjByhUqSSAAACTc"]
[Mon Jul 20 06:15:03.592964 2026] [security2:error] [pid 858085:tid 858182] [remote 124.55.178.99:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RRzAtbv2vrjByhUqUMAAALl8"]
[Mon Jul 20 06:15:03.688340 2026] [security2:error] [pid 858085:tid 858340] [client 185.132.186.67:54585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/about.php"] [unique_id "al4RRzAtbv2vrjByhUqUNQAAAHw"]
[Mon Jul 20 06:15:03.961538 2026] [security2:error] [pid 858085:tid 858273] [client 104.234.53.60:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RRzAtbv2vrjByhUqUVgAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:04.045239 2026] [security2:error] [pid 858085:tid 858119] [remote 124.55.178.99:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUWgAAbiA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:04.052459 2026] [security2:error] [pid 858085:tid 858300] [client 57.141.18.22:64280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQjAtbv2vrjByhUqScwAAVCw"]
[Mon Jul 20 06:15:04.128615 2026] [security2:error] [pid 858085:tid 858187] [remote 45.90.123.233:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUXQAAVWQ"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:15:04.143474 2026] [security2:error] [pid 858085:tid 858178] [remote 188.40.28.4:45624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUXgAAbVs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:15:04.148306 2026] [security2:error] [pid 858085:tid 858336] [client 43.205.139.3:26246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RSDAtbv2vrjByhUqUXwAAAHg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:15:04.555992 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:60143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RSDAtbv2vrjByhUqUggAAADo"]
[Mon Jul 20 06:15:04.556101 2026] [security2:error] [pid 858085:tid 858274] [client 103.77.203.233:60143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RSDAtbv2vrjByhUqUggAAADo"]
[Mon Jul 20 06:15:04.687546 2026] [security2:error] [pid 858085:tid 858307] [client 57.141.18.80:40058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RQzAtbv2vrjByhUqSrgAAWxo"]
[Mon Jul 20 06:15:05.240627 2026] [security2:error] [pid 858085:tid 858154] [remote 173.212.252.15:34234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4RSTAtbv2vrjByhUqUwgAAL0M"]
[Mon Jul 20 06:15:05.418047 2026] [security2:error] [pid 858085:tid 858252] [client 27.34.73.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4RRzAtbv2vrjByhUqUDQAAACQ"]
[Mon Jul 20 06:15:05.497239 2026] [security2:error] [pid 858085:tid 858277] [client 185.132.186.78:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-meta-request.php"] [unique_id "al4RSTAtbv2vrjByhUqU2wAAAD0"]
[Mon Jul 20 06:15:05.683492 2026] [security2:error] [pid 858085:tid 858257] [client 57.141.18.79:31618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqTBwAAKXw"]
[Mon Jul 20 06:15:05.844735 2026] [security2:error] [pid 858085:tid 858229] [client 57.141.18.97:62798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRDAtbv2vrjByhUqTJAAADUg"]
[Mon Jul 20 06:15:05.866803 2026] [security2:error] [pid 858085:tid 858335] [client 14.225.17.146:56390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4RSDAtbv2vrjByhUqUjgAAAHc"], referer: http://idigress.studio/WordPress
[Mon Jul 20 06:15:06.022328 2026] [security2:error] [pid 858085:tid 858342] [client 14.225.17.146:57577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU-wAAAH4"], referer: http://aandarealtygroup.com/WordPress
[Mon Jul 20 06:15:06.153945 2026] [security2:error] [pid 858085:tid 858143] [remote 115.74.105.156:38762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RSjAtbv2vrjByhUqVFwAATDg"]
[Mon Jul 20 06:15:06.158124 2026] [security2:error] [pid 858085:tid 858234] [client 57.141.18.15:49952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRTAtbv2vrjByhUqTNgAAEgw"]
[Mon Jul 20 06:15:06.288667 2026] [security2:error] [pid 858085:tid 858243] [client 65.1.132.125:52498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVJgAAABs"]
[Mon Jul 20 06:15:06.288804 2026] [security2:error] [pid 858085:tid 858243] [client 65.1.132.125:52498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVJgAAABs"]
[Mon Jul 20 06:15:06.314877 2026] [security2:error] [pid 858085:tid 858333] [client 50.116.65.227:22954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RSjAtbv2vrjByhUqVJwAAAHU"]
[Mon Jul 20 06:15:06.325074 2026] [security2:error] [pid 858085:tid 858319] [client 50.116.65.227:22964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RSjAtbv2vrjByhUqVKAAAAGc"]
[Mon Jul 20 06:15:06.691818 2026] [security2:error] [pid 858085:tid 858334] [client 57.141.18.53:21224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRTAtbv2vrjByhUqThAAAdgY"]
[Mon Jul 20 06:15:06.695905 2026] [security2:error] [pid 858085:tid 858310] [client 181.224.94.124:34670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVQwAAAF4"]
[Mon Jul 20 06:15:06.696036 2026] [security2:error] [pid 858085:tid 858310] [client 181.224.94.124:34670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RSjAtbv2vrjByhUqVQwAAAF4"]
[Mon Jul 20 06:15:07.533499 2026] [security2:error] [pid 858085:tid 858260] [client 14.225.17.146:57581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU_AAAACw"], referer: http://nomorewetsheets.net/WordPress
[Mon Jul 20 06:15:07.637259 2026] [security2:error] [pid 858085:tid 858208] [remote 57.141.18.121:29402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RRjAtbv2vrjByhUqT7AAADnk"]
[Mon Jul 20 06:15:07.667157 2026] [security2:error] [pid 858085:tid 858235] [client 14.225.17.146:57983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4RSjAtbv2vrjByhUqVQQAAABM"], referer: http://entuvy.com/WordPress
[Mon Jul 20 06:15:07.888767 2026] [http2:info] [pid 871012:tid 871012] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:15:07.911166 2026] [security2:error] [pid 871012:tid 871147] [client 185.132.186.100:52959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/cloud.php"] [unique_id "al4RS7wiU-Jh5ncAILE9vQAAAQ4"]
[Mon Jul 20 06:15:07.931953 2026] [security2:error] [pid 858085:tid 858222] [client 14.225.17.146:58341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU7AAAAAY"], referer: http://keywayconstructionclt.com/WordPress
[Mon Jul 20 06:15:08.115524 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:56451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4RS7wiU-Jh5ncAILE9vgAAARE"]
[Mon Jul 20 06:15:08.233472 2026] [security2:error] [pid 871012:tid 871040] [remote 72.167.132.114:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTLwiU-Jh5ncAILE9-gABJRo"]
[Mon Jul 20 06:15:08.532816 2026] [security2:error] [pid 871012:tid 871051] [remote 72.167.132.114:49410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTLwiU-Jh5ncAILE-FgABLCU"], referer: https://rcq.nst.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:08.558806 2026] [security2:error] [pid 871012:tid 871169] [client 50.116.65.227:30016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RTLwiU-Jh5ncAILE-GAAAASQ"]
[Mon Jul 20 06:15:08.569270 2026] [security2:error] [pid 871012:tid 871159] [client 50.116.65.227:22990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RTLwiU-Jh5ncAILE-GQAAASA"]
[Mon Jul 20 06:15:08.746102 2026] [security2:error] [pid 871012:tid 871262] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-DAAAAYE"]
[Mon Jul 20 06:15:08.842942 2026] [security2:error] [pid 871012:tid 871176] [client 14.225.17.146:56443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-LwAAASs"], referer: https://keywayconstructionclt.com/WordPress
[Mon Jul 20 06:15:08.933234 2026] [security2:error] [pid 871012:tid 871267] [client 171.60.139.123:57727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RTLwiU-Jh5ncAILE-QAAAAYY"]
[Mon Jul 20 06:15:08.933385 2026] [security2:error] [pid 871012:tid 871267] [client 171.60.139.123:57727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RTLwiU-Jh5ncAILE-QAAAAYY"]
[Mon Jul 20 06:15:09.655664 2026] [security2:error] [pid 858085:tid 858170] [remote 57.141.18.107:52686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSDAtbv2vrjByhUqUjQAAelM"]
[Mon Jul 20 06:15:09.710847 2026] [security2:error] [pid 871012:tid 871259] [client 185.132.186.62:60553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/edit-widgets/bypass.php"] [unique_id "al4RTbwiU-Jh5ncAILE-eAAAAX4"]
[Mon Jul 20 06:15:09.780028 2026] [security2:error] [pid 871012:tid 871224] [client 23.94.28.190:56366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mezzacraft.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "al4RTbwiU-Jh5ncAILE-gwAAAVs"]
[Mon Jul 20 06:15:09.792607 2026] [security2:error] [pid 871012:tid 871097] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-hgABI1M"]
[Mon Jul 20 06:15:09.792768 2026] [security2:error] [pid 871012:tid 871168] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-hgABI1M"]
[Mon Jul 20 06:15:09.847502 2026] [security2:error] [pid 871012:tid 871204] [client 14.225.17.146:57931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-QQAAAUc"], referer: http://mobilesurvsolutions.com/WordPress
[Mon Jul 20 06:15:09.897051 2026] [security2:error] [pid 871012:tid 871267] [client 41.173.37.102:11975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-jwAAAYY"]
[Mon Jul 20 06:15:09.897155 2026] [security2:error] [pid 871012:tid 871267] [client 41.173.37.102:11975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RTbwiU-Jh5ncAILE-jwAAAYY"]
[Mon Jul 20 06:15:10.162536 2026] [security2:error] [pid 858085:tid 858088] [remote 57.141.18.92:36454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqUuwAAOAE"]
[Mon Jul 20 06:15:10.292797 2026] [security2:error] [pid 871012:tid 871113] [remote 160.187.68.132:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTrwiU-Jh5ncAILE-qgABEmM"]
[Mon Jul 20 06:15:10.368969 2026] [security2:error] [pid 871012:tid 871159] [client 66.249.64.232:37685] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "50.116.65.227"] [uri "/robots.txt"] [unique_id "al4RTrwiU-Jh5ncAILE-tAAAARo"]
[Mon Jul 20 06:15:10.534364 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RTrwiU-Jh5ncAILE-wQAAARU"]
[Mon Jul 20 06:15:10.535372 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RTrwiU-Jh5ncAILE-wQAAARU"]
[Mon Jul 20 06:15:10.844299 2026] [security2:error] [pid 858085:tid 858152] [remote 57.141.18.101:35676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU4AAAL0E"]
[Mon Jul 20 06:15:10.980429 2026] [security2:error] [pid 871012:tid 871138] [remote 160.187.68.132:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RTrwiU-Jh5ncAILE-7wABb3w"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:11.126209 2026] [security2:error] [pid 858085:tid 858139] [remote 57.141.18.32:28050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSTAtbv2vrjByhUqU9wAAbzQ"]
[Mon Jul 20 06:15:11.227333 2026] [security2:error] [pid 871012:tid 871168] [client 45.116.69.230:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE--gAAASM"]
[Mon Jul 20 06:15:11.227434 2026] [security2:error] [pid 871012:tid 871168] [client 45.116.69.230:64972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE--gAAASM"]
[Mon Jul 20 06:15:11.310222 2026] [security2:error] [pid 871012:tid 871017] [remote 194.164.192.228:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4RT7wiU-Jh5ncAILE_AAABEQM"]
[Mon Jul 20 06:15:11.337005 2026] [security2:error] [pid 871012:tid 871270] [client 14.225.17.146:57134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4RTrwiU-Jh5ncAILE-nQAAAYk"]
[Mon Jul 20 06:15:11.373546 2026] [security2:error] [pid 871012:tid 871246] [client 106.192.104.4:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE_CAAAAXE"]
[Mon Jul 20 06:15:11.373730 2026] [security2:error] [pid 871012:tid 871246] [client 106.192.104.4:55470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RT7wiU-Jh5ncAILE_CAAAAXE"]
[Mon Jul 20 06:15:11.428842 2026] [security2:error] [pid 871012:tid 871187] [client 158.173.241.141:47053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE-_AAAATY"], referer: http://sesamegreenbeans.com/planning-for-rugby-world-cup-france-2023/
[Mon Jul 20 06:15:11.469380 2026] [security2:error] [pid 871012:tid 871225] [client 185.132.186.74:47131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/ubh/adminfus.php"] [unique_id "al4RT7wiU-Jh5ncAILE_EAAAAVw"]
[Mon Jul 20 06:15:11.497396 2026] [security2:error] [pid 871012:tid 871028] [remote 194.164.192.228:50712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4RT7wiU-Jh5ncAILE_EwABaQ4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:15:11.692876 2026] [security2:error] [pid 871012:tid 871159] [client 74.208.214.194:37696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RT7wiU-Jh5ncAILE_FwAAARo"]
[Mon Jul 20 06:15:11.751569 2026] [security2:error] [pid 871012:tid 871020] [remote 182.77.62.24:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RT7wiU-Jh5ncAILE_HAABQwY"]
[Mon Jul 20 06:15:11.953910 2026] [security2:error] [pid 871012:tid 871169] [client 34.223.60.244:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE_JAAAASQ"]
[Mon Jul 20 06:15:12.079906 2026] [security2:error] [pid 871012:tid 871181] [client 50.116.65.227:26540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4RULwiU-Jh5ncAILE_NwAAATA"]
[Mon Jul 20 06:15:12.091773 2026] [security2:error] [pid 871012:tid 871202] [client 50.116.65.227:29992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4RULwiU-Jh5ncAILE_OAAAAT4"]
[Mon Jul 20 06:15:12.266484 2026] [security2:error] [pid 871012:tid 871054] [remote 182.77.62.24:47674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RULwiU-Jh5ncAILE_RwABKig"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:12.519208 2026] [security2:error] [pid 871012:tid 871067] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RULwiU-Jh5ncAILE_WgABhTU"]
[Mon Jul 20 06:15:12.519348 2026] [security2:error] [pid 871012:tid 871266] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RULwiU-Jh5ncAILE_WgABhTU"]
[Mon Jul 20 06:15:12.702195 2026] [proxy:error] [pid 871012:tid 871260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.706572 2026] [proxy_http:error] [pid 871012:tid 871260] [client 137.184.90.71:44340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:12.708345 2026] [proxy:error] [pid 871012:tid 871260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.708413 2026] [proxy_http:error] [pid 871012:tid 871260] [client 137.184.90.71:44340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:12.742615 2026] [security2:error] [pid 858085:tid 858149] [remote 57.141.18.56:39234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RSjAtbv2vrjByhUqVUwAAIj4"]
[Mon Jul 20 06:15:12.754039 2026] [proxy:error] [pid 871012:tid 871206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.754114 2026] [proxy_http:error] [pid 871012:tid 871206] [client 137.184.90.71:44348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.thechancersband.com/
[Mon Jul 20 06:15:12.754696 2026] [proxy:error] [pid 871012:tid 871206] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:12.754722 2026] [proxy_http:error] [pid 871012:tid 871206] [client 137.184.90.71:44348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.thechancersband.com/
[Mon Jul 20 06:15:12.841526 2026] [security2:error] [pid 871012:tid 871182] [client 114.119.144.42:21849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "itekphonerepair.com"] [uri "/"] [unique_id "al4RULwiU-Jh5ncAILE_eAAAATE"], referer: https://moitruongxanh.top/ceua/jjworld%E7%AB%9E%E6%8A%80%E4%B8%96%E7%95%8C-0e07494507/
[Mon Jul 20 06:15:12.871980 2026] [core:error] [pid 871012:tid 871229] [client 137.184.90.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:12.872002 2026] [core:error] [pid 871012:tid 871229] [client 137.184.90.71:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:13.232641 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.85:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/pki-validation/webdb.php"] [unique_id "al4RUbwiU-Jh5ncAILE_lAAAAVQ"]
[Mon Jul 20 06:15:13.325095 2026] [security2:error] [pid 871012:tid 871248] [client 13.215.47.127:15370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RUbwiU-Jh5ncAILE_oAAAAXM"]
[Mon Jul 20 06:15:13.392215 2026] [security2:error] [pid 871012:tid 871150] [client 27.96.94.195:38092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_pgAAARE"]
[Mon Jul 20 06:15:13.392351 2026] [security2:error] [pid 871012:tid 871150] [client 27.96.94.195:38092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_pgAAARE"]
[Mon Jul 20 06:15:13.440978 2026] [security2:error] [pid 871012:tid 871257] [client 50.116.65.227:30004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4RUbwiU-Jh5ncAILE_qgAAAXw"]
[Mon Jul 20 06:15:13.443580 2026] [security2:error] [pid 871012:tid 871186] [client 14.225.17.146:57990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE_KAAAATU"], referer: http://recruitinginsight.us/WordPress
[Mon Jul 20 06:15:13.483239 2026] [security2:error] [pid 871012:tid 871202] [client 178.152.178.232:36976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_qwAAAUU"]
[Mon Jul 20 06:15:13.490461 2026] [security2:error] [pid 871012:tid 871202] [client 178.152.178.232:36976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RUbwiU-Jh5ncAILE_qwAAAUU"]
[Mon Jul 20 06:15:13.826276 2026] [security2:error] [pid 871012:tid 871196] [client 14.225.17.146:58716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4RUbwiU-Jh5ncAILE_vQAAAT8"], referer: http://whiteoutcb.com/WordPress
[Mon Jul 20 06:15:14.061468 2026] [security2:error] [pid 871012:tid 871215] [client 14.225.17.146:52816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RULwiU-Jh5ncAILE_VgAAAVI"], referer: http://nurturemarple.co.uk/WordPress
[Mon Jul 20 06:15:14.134291 2026] [security2:error] [pid 871012:tid 871148] [client 57.141.18.60:43622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RS7wiU-Jh5ncAILE9wgABD38"]
[Mon Jul 20 06:15:14.278210 2026] [security2:error] [pid 871012:tid 871265] [client 13.229.83.156:61934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RUrwiU-Jh5ncAILE_9AAAAYQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:15:14.298037 2026] [security2:error] [pid 871012:tid 871199] [client 57.141.18.97:44594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE96gABQhQ"]
[Mon Jul 20 06:15:14.529850 2026] [security2:error] [pid 871012:tid 871204] [client 14.225.17.146:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_5QAAAUc"]
[Mon Jul 20 06:15:14.582490 2026] [security2:error] [pid 871012:tid 871230] [client 52.167.144.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_9QABYXI"]
[Mon Jul 20 06:15:14.591670 2026] [security2:error] [pid 871012:tid 871185] [client 50.116.65.227:30026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_7AAAATQ"]
[Mon Jul 20 06:15:14.721058 2026] [security2:error] [pid 871012:tid 871146] [client 57.141.18.14:43656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTLwiU-Jh5ncAILE-FQABDSQ"]
[Mon Jul 20 06:15:14.811566 2026] [security2:error] [pid 871012:tid 871262] [client 50.116.65.227:30036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILFABQAAAYE"]
[Mon Jul 20 06:15:15.034209 2026] [security2:error] [pid 871012:tid 871258] [client 14.225.17.146:56946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILFAFgAAAX0"], referer: https://nurturemarple.co.uk/WordPress
[Mon Jul 20 06:15:15.087292 2026] [security2:error] [pid 871012:tid 871253] [client 185.132.186.83:44291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/wp-login.php"] [unique_id "al4RU7wiU-Jh5ncAILFAJAAAAXg"]
[Mon Jul 20 06:15:15.116130 2026] [security2:error] [pid 871012:tid 871182] [client 103.77.203.233:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RU7wiU-Jh5ncAILFAJgAAATE"]
[Mon Jul 20 06:15:15.116467 2026] [security2:error] [pid 871012:tid 871182] [client 103.77.203.233:60703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RU7wiU-Jh5ncAILFAJgAAATE"]
[Mon Jul 20 06:15:15.282259 2026] [security2:error] [pid 871012:tid 871171] [client 57.141.18.125:49564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTbwiU-Jh5ncAILE-UQABJj0"]
[Mon Jul 20 06:15:15.577640 2026] [security2:error] [pid 858085:tid 858156] [remote 8.217.108.67:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4RUzAtbv2vrjByhUqVXAAAcEU"]
[Mon Jul 20 06:15:15.703436 2026] [security2:error] [pid 871012:tid 871245] [client 57.141.18.87:22538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTbwiU-Jh5ncAILE-dQABcE4"]
[Mon Jul 20 06:15:15.762201 2026] [security2:error] [pid 871012:tid 871217] [client 14.225.17.146:55002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILE_9wAAAVQ"], referer: http://sarahsnyder.net/WordPress
[Mon Jul 20 06:15:15.886745 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:26558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RU7wiU-Jh5ncAILFAWgAAAXg"]
[Mon Jul 20 06:15:15.897208 2026] [security2:error] [pid 871012:tid 871265] [client 50.116.65.227:30054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RU7wiU-Jh5ncAILFAWwAAATE"]
[Mon Jul 20 06:15:15.979381 2026] [security2:error] [pid 871012:tid 871169] [client 57.141.18.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RU7wiU-Jh5ncAILFAVgAAASQ"]
[Mon Jul 20 06:15:16.011563 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:30058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RVLwiU-Jh5ncAILFAYwAAATo"]
[Mon Jul 20 06:15:16.023509 2026] [security2:error] [pid 871012:tid 871250] [client 50.116.65.227:30062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RVLwiU-Jh5ncAILFAZAAAAXU"]
[Mon Jul 20 06:15:16.495208 2026] [security2:error] [pid 871012:tid 871192] [client 57.141.18.15:47464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RTrwiU-Jh5ncAILE-xQABO20"]
[Mon Jul 20 06:15:16.717774 2026] [security2:error] [pid 871012:tid 871261] [client 14.225.17.146:57095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4RVLwiU-Jh5ncAILFAiQAAAYA"], referer: https://sarahsnyder.net/WordPress
[Mon Jul 20 06:15:16.822211 2026] [proxy:error] [pid 871012:tid 871243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822254 2026] [proxy_http:error] [pid 871012:tid 871243] [client 94.154.43.188:38424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.822320 2026] [proxy:error] [pid 871012:tid 871148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822360 2026] [proxy_http:error] [pid 871012:tid 871148] [client 94.154.43.188:38436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.822760 2026] [proxy:error] [pid 871012:tid 871148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822781 2026] [proxy_http:error] [pid 871012:tid 871148] [client 94.154.43.188:38436] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.822857 2026] [proxy:error] [pid 871012:tid 871243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:16.822883 2026] [proxy_http:error] [pid 871012:tid 871243] [client 94.154.43.188:38424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:16.888822 2026] [security2:error] [pid 871012:tid 871186] [client 185.132.186.81:40951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/admin.php"] [unique_id "al4RVLwiU-Jh5ncAILFAqAAAATU"]
[Mon Jul 20 06:15:16.898809 2026] [security2:error] [pid 871012:tid 871208] [client 57.141.18.117:25440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RT7wiU-Jh5ncAILE-8QABS34"]
[Mon Jul 20 06:15:17.111618 2026] [security2:error] [pid 871012:tid 871170] [client 14.225.17.146:57339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4RVLwiU-Jh5ncAILFArwAAASU"], referer: http://samdothan.org/WordPress
[Mon Jul 20 06:15:17.145764 2026] [security2:error] [pid 871012:tid 871100] [remote 57.141.18.37:64276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2887329"] [unique_id "al4RVbwiU-Jh5ncAILFAvAABMVY"]
[Mon Jul 20 06:15:17.254147 2026] [security2:error] [pid 871012:tid 871181] [client 181.224.94.124:26117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAwwAAATA"]
[Mon Jul 20 06:15:17.254253 2026] [security2:error] [pid 871012:tid 871181] [client 181.224.94.124:26117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAwwAAATA"]
[Mon Jul 20 06:15:17.277237 2026] [security2:error] [pid 871012:tid 871209] [client 13.201.64.214:35046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAxgAAAUw"]
[Mon Jul 20 06:15:17.277353 2026] [security2:error] [pid 871012:tid 871209] [client 13.201.64.214:35046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RVbwiU-Jh5ncAILFAxgAAAUw"]
[Mon Jul 20 06:15:17.472591 2026] [security2:error] [pid 871012:tid 871155] [client 114.119.154.39:36871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nwcarvingacademy.com"] [uri "/classes/videos.html"] [unique_id "al4RVbwiU-Jh5ncAILFA0QAAARY"], referer: http://www.nwcarvingacademy.com/classes/videos.html
[Mon Jul 20 06:15:17.996685 2026] [security2:error] [pid 871012:tid 871188] [client 57.141.18.22:26628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RULwiU-Jh5ncAILE_QAABNyU"]
[Mon Jul 20 06:15:18.473897 2026] [security2:error] [pid 871012:tid 871267] [client 57.141.18.66:50274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RULwiU-Jh5ncAILE_ZwABhjc"]
[Mon Jul 20 06:15:18.513246 2026] [security2:error] [pid 871012:tid 871175] [client 14.225.17.146:57823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4RVbwiU-Jh5ncAILFAxwAAASo"], referer: http://lutheranphilosopher.com/WordPress
[Mon Jul 20 06:15:18.523821 2026] [security2:error] [pid 871012:tid 871179] [client 14.225.17.146:58275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFBEAAAAS4"], referer: https://north-woods-engineering.com/WordPress
[Mon Jul 20 06:15:18.566851 2026] [core:error] [pid 871012:tid 871240] [client 14.225.17.146:58491] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:18.566872 2026] [core:error] [pid 871012:tid 871240] [client 14.225.17.146:58491] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:18.579861 2026] [security2:error] [pid 871012:tid 871236] [client 14.225.17.146:58241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFA-gAAAWc"]
[Mon Jul 20 06:15:18.867786 2026] [security2:error] [pid 871012:tid 871169] [client 14.225.17.146:58420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFBKwAAASQ"], referer: http://laceycaraccident.com/WordPress
[Mon Jul 20 06:15:19.141701 2026] [security2:error] [pid 871012:tid 871176] [client 185.132.186.87:59061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/item.php"] [unique_id "al4RV7wiU-Jh5ncAILFBRQAAASs"]
[Mon Jul 20 06:15:19.155538 2026] [autoindex:error] [pid 871012:tid 871208] [client 167.86.107.171:65343] AH01276: Cannot serve directory /home2/santabea/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:15:19.482062 2026] [security2:error] [pid 871012:tid 871157] [client 57.141.18.13:57624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RUbwiU-Jh5ncAILE_tQABGFg"]
[Mon Jul 20 06:15:19.649295 2026] [security2:error] [pid 871012:tid 871226] [client 171.60.139.123:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RV7wiU-Jh5ncAILFBbAAAAV0"]
[Mon Jul 20 06:15:19.649457 2026] [security2:error] [pid 871012:tid 871226] [client 171.60.139.123:58216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RV7wiU-Jh5ncAILFBbAAAAV0"]
[Mon Jul 20 06:15:20.167015 2026] [security2:error] [pid 871012:tid 871041] [remote 5.161.225.162:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RWLwiU-Jh5ncAILFBkAABgRs"]
[Mon Jul 20 06:15:20.437138 2026] [security2:error] [pid 871012:tid 871064] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrQABGzI"]
[Mon Jul 20 06:15:20.437295 2026] [security2:error] [pid 871012:tid 871160] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrQABGzI"]
[Mon Jul 20 06:15:20.458580 2026] [security2:error] [pid 871012:tid 871070] [remote 115.74.105.156:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrwABZjg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:15:20.469440 2026] [security2:error] [pid 871012:tid 871154] [client 41.173.37.102:12426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrgAAARU"]
[Mon Jul 20 06:15:20.469551 2026] [security2:error] [pid 871012:tid 871154] [client 41.173.37.102:12426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBrgAAARU"]
[Mon Jul 20 06:15:20.506025 2026] [security2:error] [pid 871012:tid 871172] [client 14.225.17.146:58764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4RV7wiU-Jh5ncAILFBYwAAASc"], referer: http://intelligentengineeringsolutions.com/WordPress
[Mon Jul 20 06:15:20.692266 2026] [security2:error] [pid 871012:tid 871184] [client 57.141.18.4:39480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RUrwiU-Jh5ncAILFABwABM3c"]
[Mon Jul 20 06:15:20.805503 2026] [security2:error] [pid 871012:tid 871266] [client 158.173.166.181:58613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RWLwiU-Jh5ncAILFByQAAAYU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:20.881151 2026] [security2:error] [pid 871012:tid 871150] [client 13.201.64.214:57550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBzwAAARE"]
[Mon Jul 20 06:15:20.881250 2026] [security2:error] [pid 871012:tid 871150] [client 13.201.64.214:57550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RWLwiU-Jh5ncAILFBzwAAARE"]
[Mon Jul 20 06:15:20.924121 2026] [security2:error] [pid 871012:tid 871140] [remote 173.212.252.15:39194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4RWLwiU-Jh5ncAILFB1AABiH4"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 06:15:20.946457 2026] [security2:error] [pid 871012:tid 871167] [client 185.132.186.65:44721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/xsec.php"] [unique_id "al4RWLwiU-Jh5ncAILFB1gAAASI"]
[Mon Jul 20 06:15:21.041476 2026] [security2:error] [pid 871012:tid 871228] [client 104.234.53.47:32273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RWbwiU-Jh5ncAILFB3wAAAV8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:21.292227 2026] [security2:error] [pid 871012:tid 871199] [client 14.225.17.146:56775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4RWLwiU-Jh5ncAILFBgQAAAUI"], referer: http://effingweirdmuseums.com/WordPress
[Mon Jul 20 06:15:21.304095 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFB9AAAARU"]
[Mon Jul 20 06:15:21.304194 2026] [security2:error] [pid 871012:tid 871154] [client 103.141.108.143:51802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFB9AAAARU"]
[Mon Jul 20 06:15:21.695202 2026] [proxy:warn] [pid 871012:tid 871251] [client 45.205.1.223:55066] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 06:15:21.722386 2026] [core:error] [pid 871012:tid 871212] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:21.722409 2026] [core:error] [pid 871012:tid 871212] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:21.722543 2026] [security2:error] [pid 871012:tid 871212] [client 45.205.1.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4RWbwiU-Jh5ncAILFCGAAAAU8"]
[Mon Jul 20 06:15:21.726528 2026] [security2:error] [pid 871012:tid 871251] [client 45.205.1.223:55066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/400.shtml"] [unique_id "al4RWbwiU-Jh5ncAILFCEwAAAXY"]
[Mon Jul 20 06:15:21.915239 2026] [security2:error] [pid 871012:tid 871104] [remote 5.161.225.162:59782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RWbwiU-Jh5ncAILFCLQABD1o"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:15:21.938231 2026] [security2:error] [pid 871012:tid 871191] [client 45.116.69.230:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFCLgAAATo"]
[Mon Jul 20 06:15:21.938346 2026] [security2:error] [pid 871012:tid 871191] [client 45.116.69.230:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RWbwiU-Jh5ncAILFCLgAAATo"]
[Mon Jul 20 06:15:22.172835 2026] [security2:error] [pid 871012:tid 871215] [client 14.225.17.146:57437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4RWrwiU-Jh5ncAILFCPAAAAVI"], referer: https://effingweirdmuseums.com/WordPress
[Mon Jul 20 06:15:22.259909 2026] [security2:error] [pid 871012:tid 871234] [client 14.225.17.146:57165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4RWbwiU-Jh5ncAILFB4QAAAWU"], referer: http://sarahholyfield.com/WordPress
[Mon Jul 20 06:15:22.319668 2026] [security2:error] [pid 871012:tid 871216] [client 106.192.104.4:55971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RWrwiU-Jh5ncAILFCSQAAAVM"]
[Mon Jul 20 06:15:22.319814 2026] [security2:error] [pid 871012:tid 871216] [client 106.192.104.4:55971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RWrwiU-Jh5ncAILFCSQAAAVM"]
[Mon Jul 20 06:15:22.774707 2026] [security2:error] [pid 871012:tid 871256] [client 185.132.186.83:40653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/Marvins.php"] [unique_id "al4RWrwiU-Jh5ncAILFCZgAAAXs"]
[Mon Jul 20 06:15:22.838761 2026] [security2:error] [pid 871012:tid 871153] [client 57.141.18.96:54448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RVLwiU-Jh5ncAILFAigABFEY"]
[Mon Jul 20 06:15:23.035768 2026] [security2:error] [pid 871012:tid 871136] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RW7wiU-Jh5ncAILFCfwABIno"]
[Mon Jul 20 06:15:23.035924 2026] [security2:error] [pid 871012:tid 871167] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RW7wiU-Jh5ncAILFCfwABIno"]
[Mon Jul 20 06:15:23.247285 2026] [security2:error] [pid 871012:tid 871154] [client 52.109.124.141:14338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4RW7wiU-Jh5ncAILFCiAAAARU"]
[Mon Jul 20 06:15:23.257589 2026] [security2:error] [pid 871012:tid 871177] [client 51.15.140.81:43454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5024.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4RW7wiU-Jh5ncAILFCigAAASw"]
[Mon Jul 20 06:15:23.409852 2026] [security2:error] [pid 871012:tid 871258] [client 104.234.53.65:20805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RW7wiU-Jh5ncAILFClAAAAX0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:23.428422 2026] [security2:error] [pid 871012:tid 871235] [client 52.109.124.141:14338] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4RW7wiU-Jh5ncAILFCmQAAAWY"]
[Mon Jul 20 06:15:23.953266 2026] [security2:error] [pid 871012:tid 871254] [client 14.225.17.146:57758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4RWrwiU-Jh5ncAILFCfAAAAXk"], referer: http://retzkolonglogistics.com/WordPress
[Mon Jul 20 06:15:24.178201 2026] [security2:error] [pid 871012:tid 871189] [client 50.116.65.227:58002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RXLwiU-Jh5ncAILFC2wAAATg"]
[Mon Jul 20 06:15:24.188226 2026] [security2:error] [pid 871012:tid 871243] [client 50.116.65.227:25038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RXLwiU-Jh5ncAILFC3wAAAW4"]
[Mon Jul 20 06:15:24.282949 2026] [security2:error] [pid 871012:tid 871146] [client 57.141.18.56:60736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RVrwiU-Jh5ncAILFA-AABDWA"]
[Mon Jul 20 06:15:24.309825 2026] [security2:error] [pid 871012:tid 871270] [client 27.96.94.195:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RXLwiU-Jh5ncAILFC8AAAAYk"]
[Mon Jul 20 06:15:24.310422 2026] [security2:error] [pid 871012:tid 871270] [client 27.96.94.195:37524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RXLwiU-Jh5ncAILFC8AAAAYk"]
[Mon Jul 20 06:15:24.552584 2026] [security2:error] [pid 871012:tid 871226] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RXLwiU-Jh5ncAILFC7QAAAV0"]
[Mon Jul 20 06:15:24.580994 2026] [security2:error] [pid 871012:tid 871213] [client 185.132.186.69:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd-1/kurd.php"] [unique_id "al4RXLwiU-Jh5ncAILFDBAAAAVA"]
[Mon Jul 20 06:15:24.919198 2026] [proxy:warn] [pid 871012:tid 871178] [client 45.205.1.223:55070] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 06:15:24.941698 2026] [core:error] [pid 871012:tid 871260] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:24.941718 2026] [core:error] [pid 871012:tid 871260] [client 45.205.1.223:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:24.941836 2026] [security2:error] [pid 871012:tid 871260] [client 45.205.1.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4RXLwiU-Jh5ncAILFDHwAAAX8"]
[Mon Jul 20 06:15:24.943394 2026] [security2:error] [pid 871012:tid 871178] [client 45.205.1.223:55070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/400.shtml"] [unique_id "al4RXLwiU-Jh5ncAILFDHAAAAS0"]
[Mon Jul 20 06:15:25.157192 2026] [security2:error] [pid 871012:tid 871259] [client 14.225.17.146:58123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4RW7wiU-Jh5ncAILFCrwAAAX4"], referer: http://709fx.com/WordPress
[Mon Jul 20 06:15:25.264242 2026] [security2:error] [pid 871012:tid 871081] [remote 188.166.241.141:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RXbwiU-Jh5ncAILFDOgABcUM"]
[Mon Jul 20 06:15:25.633802 2026] [security2:error] [pid 871012:tid 871171] [client 103.77.203.233:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RXbwiU-Jh5ncAILFDVwAAASY"]
[Mon Jul 20 06:15:25.633920 2026] [security2:error] [pid 871012:tid 871171] [client 103.77.203.233:61260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RXbwiU-Jh5ncAILFDVwAAASY"]
[Mon Jul 20 06:15:25.689937 2026] [security2:error] [pid 871012:tid 871089] [remote 188.166.241.141:35698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RXbwiU-Jh5ncAILFDYAABXUs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:15:25.770965 2026] [security2:error] [pid 871012:tid 871147] [client 57.141.18.22:33464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RV7wiU-Jh5ncAILFBWAABDkI"]
[Mon Jul 20 06:15:26.000476 2026] [security2:error] [pid 871012:tid 871261] [client 45.157.112.60:48777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RXbwiU-Jh5ncAILFDewAAAYA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:26.157061 2026] [core:error] [pid 871012:tid 871213] [client 14.225.17.146:64414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WordPress
[Mon Jul 20 06:15:26.157108 2026] [core:error] [pid 871012:tid 871213] [client 14.225.17.146:64414] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WordPress
[Mon Jul 20 06:15:26.360309 2026] [security2:error] [pid 871012:tid 871194] [client 63.177.52.239:22868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDjwAAAT0"]
[Mon Jul 20 06:15:26.360447 2026] [security2:error] [pid 871012:tid 871194] [client 63.177.52.239:22868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDjwAAAT0"]
[Mon Jul 20 06:15:26.376624 2026] [security2:error] [pid 871012:tid 871269] [client 185.132.186.93:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/tflow/install.php"] [unique_id "al4RXrwiU-Jh5ncAILFDkAAAAYg"]
[Mon Jul 20 06:15:26.423596 2026] [security2:error] [pid 871012:tid 871055] [remote 103.187.169.251:54994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDlwABgyk"]
[Mon Jul 20 06:15:26.423770 2026] [security2:error] [pid 871012:tid 871264] [client 103.187.169.251:54994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RXrwiU-Jh5ncAILFDlwABgyk"]
[Mon Jul 20 06:15:26.808105 2026] [security2:error] [pid 871012:tid 871266] [client 180.102.110.173:48804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/how-to-create-textures-with-acrylic-paint-a-guide-for-artists/"] [unique_id "al4RXrwiU-Jh5ncAILFDvAAAAYU"]
[Mon Jul 20 06:15:26.808251 2026] [security2:error] [pid 871012:tid 871266] [client 180.102.110.173:48804] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/how-to-create-textures-with-acrylic-paint-a-guide-for-artists/"] [unique_id "al4RXrwiU-Jh5ncAILFDvAAAAYU"]
[Mon Jul 20 06:15:26.817493 2026] [security2:error] [pid 871012:tid 871219] [client 57.141.18.59:54472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RWLwiU-Jh5ncAILFBqwABVh8"]
[Mon Jul 20 06:15:26.944395 2026] [security2:error] [pid 871012:tid 871208] [client 14.225.17.146:64608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RXrwiU-Jh5ncAILFDsgAAAUs"], referer: http://mezzacraft.com/WordPress
[Mon Jul 20 06:15:26.957058 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:64385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4RXbwiU-Jh5ncAILFDagAAARE"], referer: http://ravmike.com/WordPress
[Mon Jul 20 06:15:27.388363 2026] [security2:error] [pid 871012:tid 871220] [client 104.234.53.48:62503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RX7wiU-Jh5ncAILFD4QAAAVc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:27.574440 2026] [security2:error] [pid 871012:tid 871234] [client 104.234.53.48:62503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RX7wiU-Jh5ncAILFD9gAAAWU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:27.756629 2026] [security2:error] [pid 871012:tid 871225] [client 181.224.94.124:29548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RX7wiU-Jh5ncAILFECQAAAVw"]
[Mon Jul 20 06:15:27.756801 2026] [security2:error] [pid 871012:tid 871225] [client 181.224.94.124:29548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RX7wiU-Jh5ncAILFECQAAAVw"]
[Mon Jul 20 06:15:27.865934 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:49278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4RX7wiU-Jh5ncAILFECwAAARE"], referer: https://ravmike.com/WordPress
[Mon Jul 20 06:15:27.910092 2026] [security2:error] [pid 871012:tid 871154] [client 50.116.65.227:58012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4RX7wiU-Jh5ncAILFEDgAAARU"]
[Mon Jul 20 06:15:27.914307 2026] [security2:error] [pid 871012:tid 871224] [client 14.225.17.146:64323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4RX7wiU-Jh5ncAILFECgAAAVs"]
[Mon Jul 20 06:15:27.928166 2026] [security2:error] [pid 871012:tid 871180] [client 57.141.18.22:33474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RWbwiU-Jh5ncAILFCIgABL18"]
[Mon Jul 20 06:15:28.174994 2026] [security2:error] [pid 871012:tid 871237] [client 185.132.186.94:34555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/languages/radio.php"] [unique_id "al4RYLwiU-Jh5ncAILFEHAAAAWg"]
[Mon Jul 20 06:15:28.215197 2026] [security2:error] [pid 871012:tid 871202] [client 13.201.64.214:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RYLwiU-Jh5ncAILFEIgAAAUU"]
[Mon Jul 20 06:15:28.215288 2026] [security2:error] [pid 871012:tid 871202] [client 13.201.64.214:34210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RYLwiU-Jh5ncAILFEIgAAAUU"]
[Mon Jul 20 06:15:29.751514 2026] [security2:error] [pid 871012:tid 871145] [client 57.141.18.15:23934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RW7wiU-Jh5ncAILFCmgABDHg"]
[Mon Jul 20 06:15:29.964519 2026] [security2:error] [pid 871012:tid 871269] [client 14.225.17.146:60155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4RYbwiU-Jh5ncAILFEgAAAAYg"], referer: http://transparentservices.online/WordPress
[Mon Jul 20 06:15:29.974811 2026] [security2:error] [pid 871012:tid 871168] [client 185.132.186.60:29499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/fileman.php"] [unique_id "al4RYbwiU-Jh5ncAILFEpgAAASM"]
[Mon Jul 20 06:15:30.067776 2026] [security2:error] [pid 871012:tid 871198] [client 104.234.53.86:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RYrwiU-Jh5ncAILFEsgAAAUE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:30.366818 2026] [security2:error] [pid 871012:tid 871143] [client 171.60.139.123:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RYrwiU-Jh5ncAILFE0AAAAQo"]
[Mon Jul 20 06:15:30.368608 2026] [security2:error] [pid 871012:tid 871143] [client 171.60.139.123:58712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RYrwiU-Jh5ncAILFE0AAAAQo"]
[Mon Jul 20 06:15:30.871117 2026] [security2:error] [pid 871012:tid 871114] [remote 20.153.140.50:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4RYrwiU-Jh5ncAILFE9wABD2Q"]
[Mon Jul 20 06:15:31.055726 2026] [security2:error] [pid 871012:tid 871197] [client 41.173.37.102:12880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RY7wiU-Jh5ncAILFFCAAAAUA"]
[Mon Jul 20 06:15:31.055857 2026] [security2:error] [pid 871012:tid 871197] [client 41.173.37.102:12880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RY7wiU-Jh5ncAILFFCAAAAUA"]
[Mon Jul 20 06:15:31.141122 2026] [security2:error] [pid 871012:tid 871213] [client 98.159.234.160:55213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RY7wiU-Jh5ncAILFFCwAAAVA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:31.146498 2026] [security2:error] [pid 871012:tid 871151] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RYrwiU-Jh5ncAILFFBQABEhw"]
[Mon Jul 20 06:15:31.437573 2026] [security2:error] [pid 871012:tid 871050] [remote 20.153.140.50:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4RY7wiU-Jh5ncAILFFHgABPiQ"], referer: https://soloceos.com/wp-login.php
[Mon Jul 20 06:15:31.459311 2026] [security2:error] [pid 871012:tid 871201] [client 57.141.18.12:56460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RXbwiU-Jh5ncAILFDKwABREA"]
[Mon Jul 20 06:15:31.483432 2026] [security2:error] [pid 871012:tid 871226] [client 50.116.65.227:40908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RY7wiU-Jh5ncAILFFIwAAAV0"]
[Mon Jul 20 06:15:31.494476 2026] [security2:error] [pid 871012:tid 871202] [client 50.116.65.227:33584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4RY7wiU-Jh5ncAILFFJQAAAUU"]
[Mon Jul 20 06:15:31.769884 2026] [security2:error] [pid 871012:tid 871184] [client 185.132.186.77:44917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/wp-ss.php"] [unique_id "al4RY7wiU-Jh5ncAILFFPwAAATM"]
[Mon Jul 20 06:15:32.009813 2026] [security2:error] [pid 871012:tid 871269] [client 103.141.108.143:52299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFUgAAAYg"]
[Mon Jul 20 06:15:32.010430 2026] [security2:error] [pid 871012:tid 871269] [client 103.141.108.143:52299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFUgAAAYg"]
[Mon Jul 20 06:15:32.399526 2026] [core:error] [pid 871012:tid 871175] [client 14.225.17.146:55184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:32.399556 2026] [core:error] [pid 871012:tid 871175] [client 14.225.17.146:55184] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:15:32.402425 2026] [security2:error] [pid 871012:tid 871251] [client 67.203.61.163:38966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RZLwiU-Jh5ncAILFFbAAAAXY"], referer: https://mourgroup.com/
[Mon Jul 20 06:15:32.557575 2026] [security2:error] [pid 871012:tid 871241] [client 45.116.69.230:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFegAAAWw"]
[Mon Jul 20 06:15:32.557727 2026] [security2:error] [pid 871012:tid 871241] [client 45.116.69.230:49643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RZLwiU-Jh5ncAILFFegAAAWw"]
[Mon Jul 20 06:15:33.165950 2026] [security2:error] [pid 871012:tid 871145] [client 106.192.104.4:56470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFFowAAAQw"]
[Mon Jul 20 06:15:33.166190 2026] [security2:error] [pid 871012:tid 871145] [client 106.192.104.4:56470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFFowAAAQw"]
[Mon Jul 20 06:15:33.202339 2026] [security2:error] [pid 871012:tid 871187] [client 14.225.17.146:60001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4RY7wiU-Jh5ncAILFFLAAAATY"], referer: http://nwcarvingacademy.com/WordPress
[Mon Jul 20 06:15:33.571938 2026] [security2:error] [pid 871012:tid 871143] [client 185.132.186.69:42065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/xsec1.php"] [unique_id "al4RZbwiU-Jh5ncAILFFwgAAAQo"]
[Mon Jul 20 06:15:33.803645 2026] [security2:error] [pid 871012:tid 871061] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFF2AABdS8"]
[Mon Jul 20 06:15:33.803844 2026] [security2:error] [pid 871012:tid 871250] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RZbwiU-Jh5ncAILFF2AABdS8"]
[Mon Jul 20 06:15:33.987745 2026] [security2:error] [pid 871012:tid 871161] [client 185.163.52.152:12424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RZbwiU-Jh5ncAILFF5wAAARw"], referer: https://mourgroup.com/
[Mon Jul 20 06:15:34.183163 2026] [security2:error] [pid 871012:tid 871196] [client 57.141.18.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFF7wAAAT8"]
[Mon Jul 20 06:15:34.267958 2026] [security2:error] [pid 871012:tid 871240] [client 14.225.17.146:53170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFF7QAAAWs"], referer: https://nwcarvingacademy.com/WordPress
[Mon Jul 20 06:15:34.484134 2026] [security2:error] [pid 871012:tid 871212] [client 57.141.18.2:52368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RYLwiU-Jh5ncAILFEEAABT1Q"]
[Mon Jul 20 06:15:34.500154 2026] [security2:error] [pid 871012:tid 871143] [client 14.225.17.146:55348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFGCgAAAQo"], referer: http://39ishlife.com/WordPress
[Mon Jul 20 06:15:34.540150 2026] [security2:error] [pid 871012:tid 871103] [remote 173.212.252.15:45206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RZrwiU-Jh5ncAILFGFgABY1k"]
[Mon Jul 20 06:15:34.734443 2026] [security2:error] [pid 871012:tid 871101] [remote 8.217.108.67:28798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4RZrwiU-Jh5ncAILFGKAABSFc"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:15:34.775375 2026] [security2:error] [pid 871012:tid 871264] [client 104.234.53.59:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RZrwiU-Jh5ncAILFGMQAAAYM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:34.775767 2026] [security2:error] [pid 871012:tid 871244] [client 178.152.178.232:36442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RZrwiU-Jh5ncAILFGMgAAAW8"]
[Mon Jul 20 06:15:34.775849 2026] [security2:error] [pid 871012:tid 871244] [client 178.152.178.232:36442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RZrwiU-Jh5ncAILFGMgAAAW8"]
[Mon Jul 20 06:15:35.382064 2026] [security2:error] [pid 871012:tid 871223] [client 185.132.186.78:58023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin.php%20"] [unique_id "al4RZ7wiU-Jh5ncAILFGXAAAAVo"]
[Mon Jul 20 06:15:35.407777 2026] [security2:error] [pid 871012:tid 871224] [client 14.225.17.146:49448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4RZ7wiU-Jh5ncAILFGWQAAAVs"], referer: https://39ishlife.com/WordPress
[Mon Jul 20 06:15:35.783037 2026] [security2:error] [pid 871012:tid 871252] [client 57.141.18.79:21826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RYbwiU-Jh5ncAILFEdQABdzM"]
[Mon Jul 20 06:15:36.093005 2026] [security2:error] [pid 871012:tid 871145] [client 14.225.17.146:52667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4RZ7wiU-Jh5ncAILFGiwAAAQw"], referer: http://nextlvlmarketingco.com/WordPress
[Mon Jul 20 06:15:36.120786 2026] [security2:error] [pid 871012:tid 871268] [client 158.173.89.95:35961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RaLwiU-Jh5ncAILFGmQAAAYc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:15:36.202626 2026] [security2:error] [pid 871012:tid 871175] [client 103.77.203.233:61828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RaLwiU-Jh5ncAILFGoAAAASo"]
[Mon Jul 20 06:15:36.202805 2026] [security2:error] [pid 871012:tid 871175] [client 103.77.203.233:61828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RaLwiU-Jh5ncAILFGoAAAASo"]
[Mon Jul 20 06:15:36.321059 2026] [security2:error] [pid 871012:tid 871154] [client 13.229.223.11:44070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RaLwiU-Jh5ncAILFGqAAAARU"]
[Mon Jul 20 06:15:36.362959 2026] [security2:error] [pid 871012:tid 871104] [remote 100.42.189.89:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RaLwiU-Jh5ncAILFGrQABbFo"]
[Mon Jul 20 06:15:36.554117 2026] [security2:error] [pid 871012:tid 871092] [remote 100.42.189.89:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RaLwiU-Jh5ncAILFGvgABO04"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:15:36.691159 2026] [security2:error] [pid 871012:tid 871237] [client 14.225.17.146:63589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4RaLwiU-Jh5ncAILFGtwAAAWg"], referer: http://maxenengineering.com/WordPress
[Mon Jul 20 06:15:37.059145 2026] [security2:error] [pid 871012:tid 871206] [client 14.225.17.146:60261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4RZ7wiU-Jh5ncAILFGbQAAAUk"], referer: http://windowtx.com/WordPress
[Mon Jul 20 06:15:37.061538 2026] [security2:error] [pid 871012:tid 871062] [remote 45.90.123.233:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4RabwiU-Jh5ncAILFG6gABXzA"]
[Mon Jul 20 06:15:37.169028 2026] [security2:error] [pid 871012:tid 871237] [client 185.132.186.63:35353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/hong1.php"] [unique_id "al4RabwiU-Jh5ncAILFG_gAAAWg"]
[Mon Jul 20 06:15:37.413931 2026] [security2:error] [pid 871012:tid 871060] [remote 45.90.123.233:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4RabwiU-Jh5ncAILFHEAABUi4"], referer: https://mail.cathybuffini.com/wp-login.php
[Mon Jul 20 06:15:37.444074 2026] [security2:error] [pid 871012:tid 871144] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4RaLwiU-Jh5ncAILFG1gABCwU"], referer: http://ali-alghanim.net/WordPress
[Mon Jul 20 06:15:37.685870 2026] [security2:error] [pid 871012:tid 871157] [client 14.225.17.146:63188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4RabwiU-Jh5ncAILFHFAAAARg"], referer: https://maxenengineering.com/WordPress
[Mon Jul 20 06:15:38.043410 2026] [security2:error] [pid 871012:tid 871180] [client 18.141.57.241:43366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4RabwiU-Jh5ncAILFHCQAAAS8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:15:38.289583 2026] [security2:error] [pid 871012:tid 871205] [client 181.224.94.124:37409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RarwiU-Jh5ncAILFHRwAAAUg"]
[Mon Jul 20 06:15:38.289727 2026] [security2:error] [pid 871012:tid 871205] [client 181.224.94.124:37409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RarwiU-Jh5ncAILFHRwAAAUg"]
[Mon Jul 20 06:15:38.683138 2026] [security2:error] [pid 871012:tid 871168] [client 103.153.183.69:13918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/....//....//....//....//....//var/www/html/config.php"] [unique_id "al4RarwiU-Jh5ncAILFHYQAAASM"], referer: https://duckduckgo.com/?q=fcw6a
[Mon Jul 20 06:15:38.754065 2026] [security2:error] [pid 871012:tid 871244] [client 14.225.17.146:50341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4RabwiU-Jh5ncAILFG-wAAAW8"], referer: http://ironcitywellness.com/WordPress
[Mon Jul 20 06:15:38.970670 2026] [security2:error] [pid 871012:tid 871243] [client 185.132.186.61:39279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/byps.php"] [unique_id "al4RarwiU-Jh5ncAILFHegAAAW4"]
[Mon Jul 20 06:15:39.092128 2026] [security2:error] [pid 871012:tid 871240] [client 64.7.220.66:57107] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4RarwiU-Jh5ncAILFHeAAAAWs"]
[Mon Jul 20 06:15:39.144362 2026] [security2:error] [pid 871012:tid 871192] [client 13.201.64.214:38636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHhQAAATs"]
[Mon Jul 20 06:15:39.144530 2026] [security2:error] [pid 871012:tid 871192] [client 13.201.64.214:38636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHhQAAATs"]
[Mon Jul 20 06:15:39.194759 2026] [security2:error] [pid 871012:tid 871177] [client 14.225.17.146:63549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4RabwiU-Jh5ncAILFHCAAAASw"], referer: http://narv.co/WordPress
[Mon Jul 20 06:15:39.302820 2026] [security2:error] [pid 871012:tid 871161] [client 50.116.65.227:31578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ra7wiU-Jh5ncAILFHmAAAARw"]
[Mon Jul 20 06:15:39.314992 2026] [security2:error] [pid 871012:tid 871169] [client 50.116.65.227:56588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ra7wiU-Jh5ncAILFHmwAAARQ"]
[Mon Jul 20 06:15:39.735927 2026] [security2:error] [pid 871012:tid 871118] [remote 152.228.213.32:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHugABLWg"]
[Mon Jul 20 06:15:39.921879 2026] [security2:error] [pid 871012:tid 871016] [remote 152.228.213.32:41928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHzQABcwI"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:15:40.129136 2026] [security2:error] [pid 871012:tid 871219] [client 74.208.214.194:44760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RbLwiU-Jh5ncAILFH1QAAAVY"]
[Mon Jul 20 06:15:40.216035 2026] [security2:error] [pid 871012:tid 871241] [client 14.225.17.146:63321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4RbLwiU-Jh5ncAILFH0QAAAWw"], referer: https://narv.co/WordPress
[Mon Jul 20 06:15:40.888841 2026] [security2:error] [pid 871012:tid 871180] [client 14.225.17.146:63113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHpQAAAS8"], referer: http://expertcultures.com/WordPress
[Mon Jul 20 06:15:41.141250 2026] [security2:error] [pid 871012:tid 871237] [client 104.234.53.78:48025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RbbwiU-Jh5ncAILFIKgAAAWg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:41.201513 2026] [security2:error] [pid 871012:tid 871232] [client 51.158.58.168:56778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5028.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4RbbwiU-Jh5ncAILFILwAAAWM"]
[Mon Jul 20 06:15:41.220337 2026] [security2:error] [pid 871012:tid 871159] [client 171.60.139.123:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIMQAAARo"]
[Mon Jul 20 06:15:41.220508 2026] [security2:error] [pid 871012:tid 871159] [client 171.60.139.123:59210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIMQAAARo"]
[Mon Jul 20 06:15:41.232102 2026] [security2:error] [pid 871012:tid 871188] [client 57.141.18.50:65392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RZrwiU-Jh5ncAILFGNgABN2Y"]
[Mon Jul 20 06:15:41.334536 2026] [security2:error] [pid 871012:tid 871204] [client 161.123.181.219:33139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4RbbwiU-Jh5ncAILFINQAAAUc"]
[Mon Jul 20 06:15:41.442812 2026] [proxy:error] [pid 871012:tid 871270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:41.442905 2026] [proxy_http:error] [pid 871012:tid 871270] [client 205.210.31.50:64880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:41.443952 2026] [proxy:error] [pid 871012:tid 871270] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:15:41.443998 2026] [proxy_http:error] [pid 871012:tid 871270] [client 205.210.31.50:64880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:15:41.546822 2026] [security2:error] [pid 871012:tid 871212] [client 114.119.148.10:58637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bandsir.com"] [uri "/novel/add_tag_counter/1131"] [unique_id "al4RbbwiU-Jh5ncAILFIUAAAAU8"], referer: https://www.bandsir.com/novel/add_tag_counter/1131?category_id=111000
[Mon Jul 20 06:15:41.641897 2026] [security2:error] [pid 871012:tid 871247] [client 14.225.17.146:59934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4RbLwiU-Jh5ncAILFH1gAAAXI"], referer: http://olearyplumbingllc.com/WordPress
[Mon Jul 20 06:15:41.710186 2026] [security2:error] [pid 871012:tid 871177] [client 41.173.37.102:13325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIXwAAASw"]
[Mon Jul 20 06:15:41.710290 2026] [security2:error] [pid 871012:tid 871177] [client 41.173.37.102:13325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIXwAAASw"]
[Mon Jul 20 06:15:41.751183 2026] [security2:error] [pid 871012:tid 871125] [remote 68.178.160.25:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIYAABM28"]
[Mon Jul 20 06:15:41.751403 2026] [security2:error] [pid 871012:tid 871184] [client 68.178.160.25:56186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIYAABM28"]
[Mon Jul 20 06:15:41.844273 2026] [security2:error] [pid 871012:tid 871181] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RbbwiU-Jh5ncAILFIVQABMHc"]
[Mon Jul 20 06:15:42.518561 2026] [security2:error] [pid 871012:tid 871250] [client 14.225.17.146:49933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4RbrwiU-Jh5ncAILFIlgAAAXU"], referer: http://mtlegnews.gov/WordPress
[Mon Jul 20 06:15:42.741422 2026] [security2:error] [pid 871012:tid 871197] [client 103.141.108.143:52783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RbrwiU-Jh5ncAILFIrAAAAUA"]
[Mon Jul 20 06:15:42.741779 2026] [security2:error] [pid 871012:tid 871197] [client 103.141.108.143:52783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RbrwiU-Jh5ncAILFIrAAAAUA"]
[Mon Jul 20 06:15:42.865977 2026] [security2:error] [pid 871012:tid 871243] [client 185.132.186.73:24149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/crystal/sad.php"] [unique_id "al4RbrwiU-Jh5ncAILFItQAAAW4"]
[Mon Jul 20 06:15:42.872815 2026] [security2:error] [pid 871012:tid 871214] [client 14.225.17.146:56645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4RbbwiU-Jh5ncAILFISgAAAVE"], referer: http://ghivs.com/WordPress
[Mon Jul 20 06:15:43.095329 2026] [security2:error] [pid 871012:tid 871180] [client 14.225.17.146:56862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RbrwiU-Jh5ncAILFItAAAAS8"]
[Mon Jul 20 06:15:43.153963 2026] [security2:error] [pid 871012:tid 871229] [client 57.141.18.74:22590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RaLwiU-Jh5ncAILFG3AABYAg"]
[Mon Jul 20 06:15:43.167626 2026] [security2:error] [pid 871012:tid 871153] [client 104.234.53.76:33143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Rb7wiU-Jh5ncAILFIzQAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:43.216915 2026] [security2:error] [pid 871012:tid 871230] [client 45.116.69.230:50187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI0QAAAWE"]
[Mon Jul 20 06:15:43.217062 2026] [security2:error] [pid 871012:tid 871230] [client 45.116.69.230:50187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI0QAAAWE"]
[Mon Jul 20 06:15:43.428352 2026] [security2:error] [pid 871012:tid 871112] [remote 167.233.114.32:34392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI6QABSmI"]
[Mon Jul 20 06:15:43.428473 2026] [security2:error] [pid 871012:tid 871207] [client 167.233.114.32:34392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI6QABSmI"]
[Mon Jul 20 06:15:43.445093 2026] [security2:error] [pid 871012:tid 871179] [client 14.225.17.146:53843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI2QAAAS4"]
[Mon Jul 20 06:15:43.800451 2026] [security2:error] [pid 871012:tid 871236] [client 106.192.104.4:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFJAQAAAWc"]
[Mon Jul 20 06:15:43.800592 2026] [security2:error] [pid 871012:tid 871236] [client 106.192.104.4:56982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rb7wiU-Jh5ncAILFJAQAAAWc"]
[Mon Jul 20 06:15:43.845995 2026] [security2:error] [pid 871012:tid 871257] [client 14.225.17.146:56834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI6gAAAXw"], referer: http://uritems.net/WordPress
[Mon Jul 20 06:15:43.887842 2026] [security2:error] [pid 871012:tid 871155] [client 216.73.217.138:50118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFI_AABFkY"]
[Mon Jul 20 06:15:44.181370 2026] [security2:error] [pid 871012:tid 871219] [client 142.252.156.67:12666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RcLwiU-Jh5ncAILFJHgABVhA"], referer: https://mourgroup.com/
[Mon Jul 20 06:15:44.198959 2026] [security2:error] [pid 871012:tid 871216] [client 14.225.17.146:59944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4Rb7wiU-Jh5ncAILFJDQAAAVM"], referer: http://falconarrowshop.com/WordPress
[Mon Jul 20 06:15:44.369016 2026] [security2:error] [pid 871012:tid 871130] [remote 124.55.178.99:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4RcLwiU-Jh5ncAILFJOwABbnQ"]
[Mon Jul 20 06:15:44.509939 2026] [security2:error] [pid 871012:tid 871031] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RcLwiU-Jh5ncAILFJRgABfxE"]
[Mon Jul 20 06:15:44.510096 2026] [security2:error] [pid 871012:tid 871260] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RcLwiU-Jh5ncAILFJRgABfxE"]
[Mon Jul 20 06:15:44.603862 2026] [security2:error] [pid 871012:tid 871109] [remote 8.217.108.67:23166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RcLwiU-Jh5ncAILFJTwABgl8"]
[Mon Jul 20 06:15:44.662011 2026] [security2:error] [pid 871012:tid 871198] [client 185.132.186.102:46453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-packages.min.php"] [unique_id "al4RcLwiU-Jh5ncAILFJWQAAAUE"]
[Mon Jul 20 06:15:44.814514 2026] [security2:error] [pid 871012:tid 871035] [remote 124.55.178.99:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4RcLwiU-Jh5ncAILFJZAABORU"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:15:45.485031 2026] [security2:error] [pid 871012:tid 871162] [client 178.152.178.232:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RcbwiU-Jh5ncAILFJlAAAAR0"]
[Mon Jul 20 06:15:45.485130 2026] [security2:error] [pid 871012:tid 871162] [client 178.152.178.232:36851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RcbwiU-Jh5ncAILFJlAAAAR0"]
[Mon Jul 20 06:15:45.552937 2026] [security2:error] [pid 871012:tid 871232] [client 14.225.17.146:50920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4RcLwiU-Jh5ncAILFJIAAAAWM"], referer: http://slutilities.com/WordPress
[Mon Jul 20 06:15:45.813315 2026] [security2:error] [pid 871012:tid 871156] [client 57.141.18.70:53354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ra7wiU-Jh5ncAILFHvQABF0A"]
[Mon Jul 20 06:15:45.860660 2026] [security2:error] [pid 871012:tid 871169] [client 14.225.17.146:50923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4RcLwiU-Jh5ncAILFJKAAAASQ"], referer: http://aberballet.co.uk/WordPress
[Mon Jul 20 06:15:46.188039 2026] [security2:error] [pid 871012:tid 871204] [client 50.116.65.227:56724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RcrwiU-Jh5ncAILFJ0AAAAUc"]
[Mon Jul 20 06:15:46.196115 2026] [security2:error] [pid 871012:tid 871150] [client 14.224.227.113:54305] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4RcrwiU-Jh5ncAILFJ0QAAARE"]
[Mon Jul 20 06:15:46.197878 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:56736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RcrwiU-Jh5ncAILFJ0wAAAXg"]
[Mon Jul 20 06:15:46.440696 2026] [security2:error] [pid 871012:tid 871232] [client 185.132.186.90:38097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/patterns/content-type.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ6wAAAWM"]
[Mon Jul 20 06:15:46.473868 2026] [security2:error] [pid 871012:tid 871244] [client 27.96.94.195:37677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ8AAAAW8"]
[Mon Jul 20 06:15:46.474028 2026] [security2:error] [pid 871012:tid 871244] [client 27.96.94.195:37677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ8AAAAW8"]
[Mon Jul 20 06:15:46.693582 2026] [security2:error] [pid 871012:tid 871263] [client 50.116.65.227:31594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RcrwiU-Jh5ncAILFJ-wAAAYI"]
[Mon Jul 20 06:15:46.704473 2026] [security2:error] [pid 871012:tid 871259] [client 50.116.65.227:56764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4RcrwiU-Jh5ncAILFJ_QAAAU8"]
[Mon Jul 20 06:15:46.722429 2026] [security2:error] [pid 871012:tid 871188] [client 50.116.65.227:56760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ8wAAATc"]
[Mon Jul 20 06:15:46.822346 2026] [security2:error] [pid 871012:tid 871257] [client 14.225.17.146:54014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4RcbwiU-Jh5ncAILFJeAAAAXw"], referer: http://maplerespiteservices.com/WordPress
[Mon Jul 20 06:15:46.852189 2026] [security2:error] [pid 871012:tid 871238] [client 103.77.203.233:62380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFKBQAAAWk"]
[Mon Jul 20 06:15:46.852369 2026] [security2:error] [pid 871012:tid 871238] [client 103.77.203.233:62380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RcrwiU-Jh5ncAILFKBQAAAWk"]
[Mon Jul 20 06:15:46.918235 2026] [security2:error] [pid 871012:tid 871268] [client 50.116.65.227:56774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFJ_wAAAYc"]
[Mon Jul 20 06:15:47.012676 2026] [security2:error] [pid 871012:tid 871095] [remote 188.138.102.156:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKFgABKFE"]
[Mon Jul 20 06:15:47.213864 2026] [security2:error] [pid 871012:tid 871123] [remote 188.138.102.156:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKLQABUG0"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:15:47.992728 2026] [security2:error] [pid 871012:tid 871118] [remote 103.28.36.106:35064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKYAABKWg"]
[Mon Jul 20 06:15:48.096912 2026] [security2:error] [pid 871012:tid 871267] [client 14.225.17.146:53653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFKAQAAAYY"], referer: http://wathenbartlett.co.uk/WordPress
[Mon Jul 20 06:15:48.256823 2026] [security2:error] [pid 871012:tid 871218] [client 185.132.186.60:43111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/class.php"] [unique_id "al4RdLwiU-Jh5ncAILFKfAAAAVU"]
[Mon Jul 20 06:15:48.277000 2026] [security2:error] [pid 871012:tid 871024] [remote 81.173.115.7:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RdLwiU-Jh5ncAILFKfwABgQo"]
[Mon Jul 20 06:15:48.405372 2026] [security2:error] [pid 871012:tid 871031] [remote 103.28.36.106:35064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4RdLwiU-Jh5ncAILFKiQABWhE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:15:48.489066 2026] [security2:error] [pid 871012:tid 871109] [remote 81.173.115.7:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RdLwiU-Jh5ncAILFKjQABdV8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:48.613046 2026] [ssl:error] [pid 871012:tid 871197] [client 66.132.224.229:15818] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.emsbodystorm.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:15:48.653663 2026] [security2:error] [pid 871012:tid 871194] [client 57.141.18.85:61502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RbrwiU-Jh5ncAILFItwABPVw"]
[Mon Jul 20 06:15:48.787652 2026] [security2:error] [pid 871012:tid 871263] [client 181.224.94.124:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RdLwiU-Jh5ncAILFKrQAAAYI"]
[Mon Jul 20 06:15:48.787765 2026] [security2:error] [pid 871012:tid 871263] [client 181.224.94.124:30275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RdLwiU-Jh5ncAILFKrQAAAYI"]
[Mon Jul 20 06:15:48.986506 2026] [security2:error] [pid 871012:tid 871184] [client 14.225.17.146:53512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4RdLwiU-Jh5ncAILFKtwAAATM"], referer: https://wathenbartlett.co.uk/WordPress
[Mon Jul 20 06:15:49.022889 2026] [security2:error] [pid 871012:tid 871228] [client 14.225.17.146:53747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKHQAAAV8"], referer: http://mollycahill.com/WordPress
[Mon Jul 20 06:15:49.036070 2026] [security2:error] [pid 871012:tid 871153] [client 14.225.17.146:53802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFKDQAAARQ"]
[Mon Jul 20 06:15:49.308763 2026] [security2:error] [pid 871012:tid 871269] [client 14.225.17.146:53811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKKgAAAYg"], referer: http://jvcmotorsports.com/WordPress
[Mon Jul 20 06:15:49.386013 2026] [security2:error] [pid 871012:tid 871247] [client 104.234.53.55:31731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RdbwiU-Jh5ncAILFK9wAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:49.658567 2026] [security2:error] [pid 871012:tid 871063] [remote 8.217.108.67:23166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RdbwiU-Jh5ncAILFLBgABRjE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:15:49.796693 2026] [security2:error] [pid 871012:tid 871220] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RdbwiU-Jh5ncAILFLBwABV1A"], referer: http://aleishapenny.ca/WordPress
[Mon Jul 20 06:15:50.045262 2026] [security2:error] [pid 871012:tid 871242] [client 69.91.188.157:23984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4RdbwiU-Jh5ncAILFLIAABbU0"]
[Mon Jul 20 06:15:50.061368 2026] [security2:error] [pid 871012:tid 871211] [client 185.132.186.83:63789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-phpmailer-beta.php"] [unique_id "al4RdrwiU-Jh5ncAILFLOQAAAU4"]
[Mon Jul 20 06:15:50.173256 2026] [security2:error] [pid 871012:tid 871015] [remote 31.207.36.13:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLQQABZQE"]
[Mon Jul 20 06:15:50.183793 2026] [security2:error] [pid 871012:tid 871238] [client 65.1.132.125:17568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RdrwiU-Jh5ncAILFLQgAAAWk"]
[Mon Jul 20 06:15:50.183942 2026] [security2:error] [pid 871012:tid 871238] [client 65.1.132.125:17568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RdrwiU-Jh5ncAILFLQgAAAWk"]
[Mon Jul 20 06:15:50.487960 2026] [security2:error] [pid 871012:tid 871107] [remote 31.207.36.13:43114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLXwABJF0"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 06:15:50.592657 2026] [security2:error] [pid 871012:tid 871143] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4RdrwiU-Jh5ncAILFLXgABCmg"], referer: https://aleishapenny.ca/WordPress
[Mon Jul 20 06:15:50.596772 2026] [security2:error] [pid 871012:tid 871066] [remote 192.241.143.148:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLZQABUzQ"]
[Mon Jul 20 06:15:50.723295 2026] [security2:error] [pid 871012:tid 871237] [client 57.141.18.78:43928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RcbwiU-Jh5ncAILFJfAABaBY"]
[Mon Jul 20 06:15:50.762309 2026] [security2:error] [pid 871012:tid 871056] [remote 192.241.143.148:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4RdrwiU-Jh5ncAILFLdQABVSo"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 06:15:50.980834 2026] [security2:error] [pid 871012:tid 871221] [client 220.181.108.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4RdrwiU-Jh5ncAILFLbgAAAVg"]
[Mon Jul 20 06:15:51.190824 2026] [security2:error] [pid 871012:tid 871017] [remote 217.61.143.92:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLmgABOgM"]
[Mon Jul 20 06:15:51.423276 2026] [security2:error] [pid 871012:tid 871043] [remote 217.61.143.92:35414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLrAABIR0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:15:51.564630 2026] [security2:error] [pid 871012:tid 871222] [client 57.141.18.97:45948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RcbwiU-Jh5ncAILFJugABWQ8"]
[Mon Jul 20 06:15:51.863593 2026] [security2:error] [pid 871012:tid 871237] [client 185.132.186.81:44109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ms-file.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLzAAAAWg"]
[Mon Jul 20 06:15:51.907313 2026] [security2:error] [pid 871012:tid 871163] [client 171.60.139.123:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLzwAAAR4"]
[Mon Jul 20 06:15:51.907453 2026] [security2:error] [pid 871012:tid 871163] [client 171.60.139.123:59700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLzwAAAR4"]
[Mon Jul 20 06:15:52.299645 2026] [security2:error] [pid 871012:tid 871151] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ReLwiU-Jh5ncAILFL3QABEic"]
[Mon Jul 20 06:15:52.412433 2026] [security2:error] [pid 871012:tid 871185] [client 41.173.37.102:13776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ReLwiU-Jh5ncAILFL-gAAATQ"]
[Mon Jul 20 06:15:52.412534 2026] [security2:error] [pid 871012:tid 871185] [client 41.173.37.102:13776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4ReLwiU-Jh5ncAILFL-gAAATQ"]
[Mon Jul 20 06:15:52.572245 2026] [security2:error] [pid 871012:tid 871226] [client 172.56.252.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4ReLwiU-Jh5ncAILFL3AAAAV0"]
[Mon Jul 20 06:15:52.629367 2026] [security2:error] [pid 871012:tid 871168] [client 57.141.18.73:43442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RcrwiU-Jh5ncAILFKDAABI0o"]
[Mon Jul 20 06:15:53.198069 2026] [security2:error] [pid 871012:tid 871188] [client 77.110.127.138:58766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/feed/2bb5ei2h6jqd.php"] [unique_id "al4RebwiU-Jh5ncAILFMOQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:53.404839 2026] [security2:error] [pid 871012:tid 871160] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMQAAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:53.413378 2026] [security2:error] [pid 871012:tid 871267] [client 103.141.108.143:53270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMWwAAAYY"]
[Mon Jul 20 06:15:53.413523 2026] [security2:error] [pid 871012:tid 871267] [client 103.141.108.143:53270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMWwAAAYY"]
[Mon Jul 20 06:15:53.492618 2026] [security2:error] [pid 871012:tid 871143] [client 14.225.17.146:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4Rd7wiU-Jh5ncAILFLqwAAAQo"], referer: http://dollpassionista.com/WordPress
[Mon Jul 20 06:15:53.676984 2026] [security2:error] [pid 871012:tid 871212] [client 57.141.18.117:58336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rc7wiU-Jh5ncAILFKWgABTzk"]
[Mon Jul 20 06:15:53.724504 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.54:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "al4RebwiU-Jh5ncAILFMcwAAAVQ"]
[Mon Jul 20 06:15:53.833791 2026] [security2:error] [pid 871012:tid 871097] [remote 100.42.189.89:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RebwiU-Jh5ncAILFMgQABf1M"]
[Mon Jul 20 06:15:53.897691 2026] [security2:error] [pid 871012:tid 871242] [client 45.116.69.230:50728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMigAAAW0"]
[Mon Jul 20 06:15:53.897795 2026] [security2:error] [pid 871012:tid 871242] [client 45.116.69.230:50728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RebwiU-Jh5ncAILFMigAAAW0"]
[Mon Jul 20 06:15:54.097006 2026] [security2:error] [pid 871012:tid 871131] [remote 100.42.189.89:39958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMlQABS3U"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:54.185263 2026] [security2:error] [pid 871012:tid 871229] [client 14.225.17.146:59368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4RerwiU-Jh5ncAILFMkAAAAWA"], referer: http://ivetstrategies.com/WordPress
[Mon Jul 20 06:15:54.207048 2026] [security2:error] [pid 871012:tid 871175] [client 77.110.127.138:58881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMTAAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:54.249404 2026] [security2:error] [pid 871012:tid 871196] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMUgAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:15:54.369361 2026] [security2:error] [pid 871012:tid 871066] [remote 192.241.143.148:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMqgABhzQ"]
[Mon Jul 20 06:15:54.438613 2026] [security2:error] [pid 871012:tid 871256] [client 106.192.104.4:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RerwiU-Jh5ncAILFMsgAAAXs"]
[Mon Jul 20 06:15:54.438701 2026] [security2:error] [pid 871012:tid 871256] [client 106.192.104.4:57558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RerwiU-Jh5ncAILFMsgAAAXs"]
[Mon Jul 20 06:15:54.505630 2026] [security2:error] [pid 871012:tid 871155] [client 14.225.17.146:59308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4RerwiU-Jh5ncAILFMpgAAARY"], referer: https://dollpassionista.com/WordPress
[Mon Jul 20 06:15:54.531622 2026] [security2:error] [pid 871012:tid 871056] [remote 192.241.143.148:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMugABZio"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:15:54.851231 2026] [security2:error] [pid 871012:tid 871126] [remote 68.178.160.25:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4RerwiU-Jh5ncAILFMzgABanA"]
[Mon Jul 20 06:15:55.144180 2026] [security2:error] [pid 871012:tid 871082] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Re7wiU-Jh5ncAILFM6QABc0Q"]
[Mon Jul 20 06:15:55.144363 2026] [security2:error] [pid 871012:tid 871248] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Re7wiU-Jh5ncAILFM6QABc0Q"]
[Mon Jul 20 06:15:55.167075 2026] [security2:error] [pid 871012:tid 871026] [remote 91.142.222.105:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFM6wABQAw"]
[Mon Jul 20 06:15:55.263585 2026] [security2:error] [pid 871012:tid 871200] [client 110.249.201.65:39290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.drawingthedog.com"] [uri "/robots.txt"] [unique_id "al4Re7wiU-Jh5ncAILFM9AAAAUM"]
[Mon Jul 20 06:15:55.271644 2026] [security2:error] [pid 871012:tid 871092] [remote 68.178.160.25:37462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFM8wABUU4"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:15:55.423995 2026] [security2:error] [pid 871012:tid 871067] [remote 91.142.222.105:36734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFNBAABFDU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:15:55.451735 2026] [security2:error] [pid 871012:tid 871266] [client 50.116.65.227:56724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Re7wiU-Jh5ncAILFNBQAAAYU"]
[Mon Jul 20 06:15:55.462010 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:56726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Re7wiU-Jh5ncAILFNCQAAATo"]
[Mon Jul 20 06:15:55.524123 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.85:39215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/av.php"] [unique_id "al4Re7wiU-Jh5ncAILFNDwAAAVQ"]
[Mon Jul 20 06:15:55.633832 2026] [security2:error] [pid 871012:tid 871228] [client 50.116.65.227:54812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Re7wiU-Jh5ncAILFNEwAAAV8"]
[Mon Jul 20 06:15:55.645514 2026] [security2:error] [pid 871012:tid 871163] [client 50.116.65.227:56728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Re7wiU-Jh5ncAILFNFAAAAQ4"]
[Mon Jul 20 06:15:55.780271 2026] [security2:error] [pid 871012:tid 871186] [client 185.223.152.55:51061] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "avatrip.co"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4Re7wiU-Jh5ncAILFNHgAAATU"]
[Mon Jul 20 06:15:55.835646 2026] [security2:error] [pid 871012:tid 871045] [remote 103.173.227.188:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.227.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Re7wiU-Jh5ncAILFNIAABJR8"]
[Mon Jul 20 06:15:56.079604 2026] [security2:error] [pid 871012:tid 871151] [client 178.152.178.232:36157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RfLwiU-Jh5ncAILFNRwAAARI"]
[Mon Jul 20 06:15:56.079698 2026] [security2:error] [pid 871012:tid 871151] [client 178.152.178.232:36157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RfLwiU-Jh5ncAILFNRwAAARI"]
[Mon Jul 20 06:15:56.211633 2026] [security2:error] [pid 871012:tid 871249] [client 104.234.53.75:48441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RfLwiU-Jh5ncAILFNlAAAAXQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:56.240106 2026] [security2:error] [pid 871012:tid 871016] [remote 103.173.227.188:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.227.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RfLwiU-Jh5ncAILFNpQABXQI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:56.916331 2026] [security2:error] [pid 871012:tid 871212] [client 14.225.17.146:59320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Re7wiU-Jh5ncAILFNNAAAAU8"], referer: http://adultdaycarereno.com/WordPress
[Mon Jul 20 06:15:57.153580 2026] [security2:error] [pid 871012:tid 871135] [remote 47.86.33.52:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RfbwiU-Jh5ncAILFOGgABI3k"]
[Mon Jul 20 06:15:57.260694 2026] [security2:error] [pid 871012:tid 871203] [client 104.234.53.78:40989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RfbwiU-Jh5ncAILFOIgAAAUY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:15:57.269870 2026] [security2:error] [pid 871012:tid 871193] [client 103.77.203.233:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOIwAAATw"]
[Mon Jul 20 06:15:57.269955 2026] [security2:error] [pid 871012:tid 871193] [client 103.77.203.233:62938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOIwAAATw"]
[Mon Jul 20 06:15:57.305160 2026] [security2:error] [pid 871012:tid 871259] [client 185.132.186.78:28557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/chosen.php%20"] [unique_id "al4RfbwiU-Jh5ncAILFOJAAAAX4"]
[Mon Jul 20 06:15:57.449267 2026] [security2:error] [pid 871012:tid 871181] [client 27.96.94.195:36967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOMwAAATA"]
[Mon Jul 20 06:15:57.450011 2026] [security2:error] [pid 871012:tid 871181] [client 27.96.94.195:36967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RfbwiU-Jh5ncAILFOMwAAATA"]
[Mon Jul 20 06:15:57.819481 2026] [security2:error] [pid 871012:tid 871147] [client 14.225.17.146:59439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4RfbwiU-Jh5ncAILFOTgAAAQ4"], referer: https://adultdaycarereno.com/WordPress
[Mon Jul 20 06:15:58.248039 2026] [security2:error] [pid 871012:tid 871251] [client 14.225.17.146:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4RfLwiU-Jh5ncAILFNtgAAAXY"], referer: http://itdynamix.com/WordPress
[Mon Jul 20 06:15:58.339700 2026] [security2:error] [pid 871012:tid 871082] [remote 188.40.28.4:46416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RfrwiU-Jh5ncAILFOeAABKUQ"]
[Mon Jul 20 06:15:58.339910 2026] [security2:error] [pid 871012:tid 871174] [client 188.40.28.4:46416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RfrwiU-Jh5ncAILFOeAABKUQ"]
[Mon Jul 20 06:15:58.473753 2026] [security2:error] [pid 871012:tid 871092] [remote 47.86.33.52:7298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RfrwiU-Jh5ncAILFOgAABMk4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:15:58.691806 2026] [security2:error] [pid 871012:tid 871145] [client 57.141.18.101:36200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RebwiU-Jh5ncAILFMgAABDE0"]
[Mon Jul 20 06:15:58.719702 2026] [autoindex:error] [pid 871012:tid 871169] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/
[Mon Jul 20 06:15:58.876422 2026] [security2:error] [pid 871012:tid 871136] [remote 34.21.244.199:12020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RfrwiU-Jh5ncAILFOrQABW3o"]
[Mon Jul 20 06:15:59.054507 2026] [security2:error] [pid 871012:tid 871239] [client 103.153.183.69:60730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../srv/.env"] [unique_id "al4Rf7wiU-Jh5ncAILFOvAAAAWo"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:15:59.143285 2026] [security2:error] [pid 871012:tid 871200] [client 185.132.186.53:52899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/bs1.php"] [unique_id "al4Rf7wiU-Jh5ncAILFOyAAAAUM"]
[Mon Jul 20 06:15:59.219422 2026] [security2:error] [pid 871012:tid 871255] [client 168.144.240.66:49804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "nvkdigital.co.uk"] [uri "/license.txt"] [unique_id "al4Rf7wiU-Jh5ncAILFO1AAAAXo"]
[Mon Jul 20 06:15:59.241179 2026] [security2:error] [pid 871012:tid 871019] [remote 34.21.244.199:12020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Rf7wiU-Jh5ncAILFO1QABOQU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:15:59.266434 2026] [security2:error] [pid 871012:tid 871253] [client 14.225.17.146:52300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Rf7wiU-Jh5ncAILFOvgAAAXg"], referer: https://itdynamix.com/WordPress
[Mon Jul 20 06:15:59.311499 2026] [security2:error] [pid 871012:tid 871164] [client 181.224.94.124:55584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rf7wiU-Jh5ncAILFO2QAAAR8"]
[Mon Jul 20 06:15:59.311583 2026] [security2:error] [pid 871012:tid 871164] [client 181.224.94.124:55584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rf7wiU-Jh5ncAILFO2QAAAR8"]
[Mon Jul 20 06:15:59.734504 2026] [core:error] [pid 871012:tid 871178] [client 14.225.17.146:59849] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WordPress
[Mon Jul 20 06:15:59.734528 2026] [core:error] [pid 871012:tid 871178] [client 14.225.17.146:59849] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WordPress
[Mon Jul 20 06:15:59.945453 2026] [security2:error] [pid 871012:tid 871076] [remote 217.61.143.92:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4Rf7wiU-Jh5ncAILFPEwABXj4"]
[Mon Jul 20 06:16:00.153901 2026] [core:error] [pid 871012:tid 871253] [client 104.223.85.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:00.153920 2026] [core:error] [pid 871012:tid 871253] [client 104.223.85.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:00.175924 2026] [security2:error] [pid 871012:tid 871085] [remote 217.61.143.92:52832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4RgLwiU-Jh5ncAILFPJAABLEc"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:16:00.762254 2026] [security2:error] [pid 871012:tid 871263] [client 57.141.18.22:61572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Re7wiU-Jh5ncAILFNPgABgjo"]
[Mon Jul 20 06:16:00.780155 2026] [security2:error] [pid 871012:tid 871153] [client 74.7.227.179:44522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RgLwiU-Jh5ncAILFPTwABFFU"], referer: https://tejasenvironmental.com/p=8744
[Mon Jul 20 06:16:00.946106 2026] [security2:error] [pid 871012:tid 871171] [client 185.132.186.55:39135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "al4RgLwiU-Jh5ncAILFPaAAAASY"]
[Mon Jul 20 06:16:01.014268 2026] [security2:error] [pid 871012:tid 871194] [client 3.109.4.218:39144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RgbwiU-Jh5ncAILFPbQAAAT0"]
[Mon Jul 20 06:16:01.014377 2026] [security2:error] [pid 871012:tid 871194] [client 3.109.4.218:39144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RgbwiU-Jh5ncAILFPbQAAAT0"]
[Mon Jul 20 06:16:01.454606 2026] [security2:error] [pid 871012:tid 871164] [client 70.189.175.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4RgbwiU-Jh5ncAILFPhgAAAR8"]
[Mon Jul 20 06:16:01.675344 2026] [security2:error] [pid 871012:tid 871188] [client 57.141.18.123:37916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RfLwiU-Jh5ncAILFN-wABNwE"]
[Mon Jul 20 06:16:01.825396 2026] [security2:error] [pid 871012:tid 871263] [client 103.153.183.69:60730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../home/.env"] [unique_id "al4RgbwiU-Jh5ncAILFPtQAAAYI"], referer: https://www.google.com/search?q=fiqdgg
[Mon Jul 20 06:16:01.889315 2026] [security2:error] [pid 871012:tid 871235] [client 104.234.53.80:35759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RgbwiU-Jh5ncAILFPrgAAAWY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:02.204378 2026] [security2:error] [pid 871012:tid 871145] [client 14.225.17.146:52467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFPywAAAQw"], referer: http://mazzucelli.com/WordPress
[Mon Jul 20 06:16:02.688706 2026] [security2:error] [pid 871012:tid 871016] [remote 20.153.140.50:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RgrwiU-Jh5ncAILFP-wABUAI"]
[Mon Jul 20 06:16:02.755968 2026] [security2:error] [pid 871012:tid 871188] [client 104.234.53.80:35759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RgrwiU-Jh5ncAILFQBQAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:02.766247 2026] [security2:error] [pid 871012:tid 871177] [client 185.132.186.90:30447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/network.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCAAAASw"]
[Mon Jul 20 06:16:02.799865 2026] [security2:error] [pid 871012:tid 871220] [client 171.60.139.123:60209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCwAAAVc"]
[Mon Jul 20 06:16:02.800013 2026] [security2:error] [pid 871012:tid 871220] [client 171.60.139.123:60209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCwAAAVc"]
[Mon Jul 20 06:16:02.859296 2026] [security2:error] [pid 871012:tid 871257] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RgrwiU-Jh5ncAILFQBgABfDI"]
[Mon Jul 20 06:16:02.883855 2026] [security2:error] [pid 871012:tid 871265] [client 57.141.18.96:39034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RfbwiU-Jh5ncAILFOYgABhFo"]
[Mon Jul 20 06:16:03.040601 2026] [security2:error] [pid 871012:tid 871266] [client 41.173.37.102:14222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQJQAAAYU"]
[Mon Jul 20 06:16:03.040689 2026] [security2:error] [pid 871012:tid 871266] [client 41.173.37.102:14222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQJQAAAYU"]
[Mon Jul 20 06:16:03.076907 2026] [security2:error] [pid 871012:tid 871240] [client 14.225.17.146:52316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFQHQAAAWs"], referer: http://fkconstructionfunding.com/WordPress
[Mon Jul 20 06:16:03.094563 2026] [security2:error] [pid 871012:tid 871019] [remote 20.153.140.50:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQJgABTwU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:16:03.901292 2026] [security2:error] [pid 871012:tid 871181] [client 57.141.18.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQZAAAATA"]
[Mon Jul 20 06:16:03.945165 2026] [security2:error] [pid 871012:tid 871182] [client 14.225.17.146:52513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFPzAAAATE"], referer: http://fineartsfactory.net/WordPress
[Mon Jul 20 06:16:04.062377 2026] [security2:error] [pid 871012:tid 871163] [client 14.225.17.146:50970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQdgAAAR4"], referer: https://fkconstructionfunding.com/WordPress
[Mon Jul 20 06:16:04.131095 2026] [security2:error] [pid 871012:tid 871157] [client 103.141.108.143:53752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQjwAAARg"]
[Mon Jul 20 06:16:04.132297 2026] [security2:error] [pid 871012:tid 871157] [client 103.141.108.143:53752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQjwAAARg"]
[Mon Jul 20 06:16:04.572863 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtQAAAX8"]
[Mon Jul 20 06:16:04.572991 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtQAAAX8"]
[Mon Jul 20 06:16:04.615207 2026] [security2:error] [pid 871012:tid 871164] [client 106.192.104.4:58048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtwAAAR8"]
[Mon Jul 20 06:16:04.615368 2026] [security2:error] [pid 871012:tid 871164] [client 106.192.104.4:58048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4RhLwiU-Jh5ncAILFQtwAAAR8"]
[Mon Jul 20 06:16:04.731666 2026] [security2:error] [pid 871012:tid 871186] [client 104.234.53.53:43715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RhLwiU-Jh5ncAILFQvQAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:04.776662 2026] [security2:error] [pid 871012:tid 871189] [client 185.132.186.93:42875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/page.php"] [unique_id "al4RhLwiU-Jh5ncAILFQxAAAATg"]
[Mon Jul 20 06:16:04.954783 2026] [security2:error] [pid 871012:tid 871174] [client 14.225.17.146:61665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4RgrwiU-Jh5ncAILFQCQAAASk"], referer: http://www.justinagrayman.com/WordPress
[Mon Jul 20 06:16:05.186790 2026] [security2:error] [pid 871012:tid 871156] [client 50.116.65.227:39516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RhbwiU-Jh5ncAILFQ5wAAARc"]
[Mon Jul 20 06:16:05.201759 2026] [security2:error] [pid 871012:tid 871260] [client 50.116.65.227:37112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4RhbwiU-Jh5ncAILFQ6gAAARY"]
[Mon Jul 20 06:16:05.306483 2026] [security2:error] [pid 871012:tid 871207] [client 104.234.53.55:57419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RhbwiU-Jh5ncAILFQ8wAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:05.526813 2026] [security2:error] [pid 871012:tid 871147] [client 54.81.157.232:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4RhLwiU-Jh5ncAILFQ1wAAAQ4"]
[Mon Jul 20 06:16:05.529319 2026] [security2:error] [pid 871012:tid 871266] [client 54.81.157.232:29486] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/pollo-frito-en-freidora-de-aire-air-fryer-fried-chicken"] [unique_id "al4RhLwiU-Jh5ncAILFQ1AAAAYU"]
[Mon Jul 20 06:16:05.768827 2026] [security2:error] [pid 871012:tid 871206] [client 14.225.17.146:52589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4RhbwiU-Jh5ncAILFRGAAAAUk"], referer: http://mourgroup.com/WordPress
[Mon Jul 20 06:16:05.769102 2026] [security2:error] [pid 871012:tid 871096] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RhbwiU-Jh5ncAILFRIwABWVI"]
[Mon Jul 20 06:16:05.769308 2026] [security2:error] [pid 871012:tid 871222] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RhbwiU-Jh5ncAILFRIwABWVI"]
[Mon Jul 20 06:16:05.775166 2026] [security2:error] [pid 871012:tid 871235] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4RhbwiU-Jh5ncAILFRJAAAAWY"], referer: https://www.google.com/
[Mon Jul 20 06:16:06.043375 2026] [security2:error] [pid 871012:tid 871154] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/.env"] [unique_id "al4RhrwiU-Jh5ncAILFROQAAARU"], referer: https://twitter.com/
[Mon Jul 20 06:16:06.181206 2026] [security2:error] [pid 871012:tid 871229] [client 57.141.18.60:35750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RgbwiU-Jh5ncAILFPiQABYBA"]
[Mon Jul 20 06:16:06.547374 2026] [security2:error] [pid 871012:tid 871179] [client 65.1.132.125:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRWwAAAS4"]
[Mon Jul 20 06:16:06.547473 2026] [security2:error] [pid 871012:tid 871179] [client 65.1.132.125:33588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRWwAAAS4"]
[Mon Jul 20 06:16:06.664174 2026] [security2:error] [pid 871012:tid 871188] [client 178.152.178.232:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRZgAAATc"]
[Mon Jul 20 06:16:06.664278 2026] [security2:error] [pid 871012:tid 871188] [client 178.152.178.232:37220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RhrwiU-Jh5ncAILFRZgAAATc"]
[Mon Jul 20 06:16:06.702812 2026] [security2:error] [pid 871012:tid 871153] [client 104.234.53.55:36403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4RhrwiU-Jh5ncAILFRagAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:06.758166 2026] [security2:error] [pid 871012:tid 871261] [client 185.132.186.98:26973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/index.php"] [unique_id "al4RhrwiU-Jh5ncAILFRawAAAYA"]
[Mon Jul 20 06:16:06.995639 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:06.995721 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.51:60520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:06.996553 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:06.996583 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.51:60520] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:07.219090 2026] [security2:error] [pid 871012:tid 871125] [remote 57.141.18.45:29074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4110925"] [unique_id "al4Rh7wiU-Jh5ncAILFRmAABEG8"]
[Mon Jul 20 06:16:07.838881 2026] [security2:error] [pid 871012:tid 871213] [client 103.77.203.233:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rh7wiU-Jh5ncAILFRwgAAAVA"]
[Mon Jul 20 06:16:07.839020 2026] [security2:error] [pid 871012:tid 871213] [client 103.77.203.233:63485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rh7wiU-Jh5ncAILFRwgAAAVA"]
[Mon Jul 20 06:16:07.979495 2026] [security2:error] [pid 871012:tid 871148] [client 158.173.166.181:27983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Rh7wiU-Jh5ncAILFR0AAAAQ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:08.034923 2026] [security2:error] [pid 871012:tid 871197] [client 14.225.17.146:58517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4RhrwiU-Jh5ncAILFRVgAAAUA"], referer: http://bnb-engineering.com/WordPress
[Mon Jul 20 06:16:08.135318 2026] [security2:error] [pid 871012:tid 871089] [remote 192.241.143.148:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RiLwiU-Jh5ncAILFR4gABX0s"]
[Mon Jul 20 06:16:08.219797 2026] [security2:error] [pid 871012:tid 871180] [client 3.87.117.29:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4Rh7wiU-Jh5ncAILFRqQAAAS8"]
[Mon Jul 20 06:16:08.268915 2026] [security2:error] [pid 871012:tid 871177] [client 3.87.117.29:39516] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pollo-frito-en-freidora-de-aire-air-fryer-fried-chicken/"] [unique_id "al4Rh7wiU-Jh5ncAILFRpQAAASw"]
[Mon Jul 20 06:16:08.307738 2026] [security2:error] [pid 871012:tid 871058] [remote 192.241.143.148:54908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RiLwiU-Jh5ncAILFR8AABPSw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:16:08.421518 2026] [security2:error] [pid 871012:tid 871198] [client 27.96.94.195:37507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RiLwiU-Jh5ncAILFR-QAAAUE"]
[Mon Jul 20 06:16:08.421659 2026] [security2:error] [pid 871012:tid 871198] [client 27.96.94.195:37507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RiLwiU-Jh5ncAILFR-QAAAUE"]
[Mon Jul 20 06:16:08.491973 2026] [security2:error] [pid 871012:tid 871144] [client 57.141.18.124:38362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rg7wiU-Jh5ncAILFQVwABC30"]
[Mon Jul 20 06:16:08.759507 2026] [security2:error] [pid 871012:tid 871222] [client 185.132.186.95:42969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/chosen.php"] [unique_id "al4RiLwiU-Jh5ncAILFSGgAAAVk"]
[Mon Jul 20 06:16:09.393009 2026] [security2:error] [pid 871012:tid 871118] [remote 57.141.18.9:64262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4297331"] [unique_id "al4RibwiU-Jh5ncAILFSQAABL2g"]
[Mon Jul 20 06:16:09.430335 2026] [security2:error] [pid 871012:tid 871182] [client 57.141.18.117:33582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RhLwiU-Jh5ncAILFQrAABMWw"]
[Mon Jul 20 06:16:09.756923 2026] [security2:error] [pid 871012:tid 871036] [remote 216.73.217.138:25567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RibwiU-Jh5ncAILFSVQABSRY"]
[Mon Jul 20 06:16:09.820497 2026] [security2:error] [pid 871012:tid 871197] [client 181.224.94.124:4281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RibwiU-Jh5ncAILFSYgAAAUA"]
[Mon Jul 20 06:16:09.820606 2026] [security2:error] [pid 871012:tid 871197] [client 181.224.94.124:4281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RibwiU-Jh5ncAILFSYgAAAUA"]
[Mon Jul 20 06:16:10.080418 2026] [security2:error] [pid 871012:tid 871081] [remote 57.141.18.18:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5629755"] [unique_id "al4RirwiU-Jh5ncAILFSdwABW0M"]
[Mon Jul 20 06:16:10.287362 2026] [security2:error] [pid 871012:tid 871159] [client 14.225.17.146:61375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSeQAAARo"], referer: http://oldracelimited.com/WordPress
[Mon Jul 20 06:16:10.322015 2026] [security2:error] [pid 871012:tid 871225] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/uploads/"] [unique_id "al4RirwiU-Jh5ncAILFShAAAAVw"]
[Mon Jul 20 06:16:10.528388 2026] [security2:error] [pid 871012:tid 871254] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RirwiU-Jh5ncAILFSmgAAAXk"]
[Mon Jul 20 06:16:10.571730 2026] [security2:error] [pid 871012:tid 871234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSiQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:10.621451 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:25070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSlgAAAXg"]
[Mon Jul 20 06:16:10.691928 2026] [security2:error] [pid 871012:tid 871180] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/"] [unique_id "al4RirwiU-Jh5ncAILFSsgAAAS8"]
[Mon Jul 20 06:16:10.752011 2026] [security2:error] [pid 871012:tid 871251] [client 185.132.186.99:50219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al4RirwiU-Jh5ncAILFSuAAAAXY"]
[Mon Jul 20 06:16:10.784563 2026] [core:error] [pid 871012:tid 871209] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:10.784587 2026] [core:error] [pid 871012:tid 871209] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:10.787838 2026] [security2:error] [pid 871012:tid 871267] [client 50.116.65.227:25082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4RirwiU-Jh5ncAILFSrAAAAYY"]
[Mon Jul 20 06:16:10.881009 2026] [security2:error] [pid 871012:tid 871168] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4RirwiU-Jh5ncAILFSygAAASM"], referer: https://duckduckgo.com/?q=lv2g7
[Mon Jul 20 06:16:10.916260 2026] [security2:error] [pid 871012:tid 871157] [client 103.153.183.69:27650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4RirwiU-Jh5ncAILFSywAAARg"], referer: https://www.google.com/
[Mon Jul 20 06:16:10.936358 2026] [security2:error] [pid 871012:tid 871236] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RirwiU-Jh5ncAILFSyQAAAWc"]
[Mon Jul 20 06:16:11.081924 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/css/"] [unique_id "al4Ri7wiU-Jh5ncAILFS1AAAATQ"]
[Mon Jul 20 06:16:11.263301 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ri7wiU-Jh5ncAILFS4QAAAWE"]
[Mon Jul 20 06:16:11.448077 2026] [proxy:error] [pid 871012:tid 871226] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.448161 2026] [proxy_http:error] [pid 871012:tid 871226] [client 85.204.70.96:49620] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.448888 2026] [proxy:error] [pid 871012:tid 871226] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.448917 2026] [proxy_http:error] [pid 871012:tid 871226] [client 85.204.70.96:49620] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.477326 2026] [security2:error] [pid 871012:tid 871250] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/ID3/"] [unique_id "al4Ri7wiU-Jh5ncAILFS9AAAAXU"]
[Mon Jul 20 06:16:11.676405 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ri7wiU-Jh5ncAILFS_gAAATI"]
[Mon Jul 20 06:16:11.715342 2026] [proxy:error] [pid 871012:tid 871257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.715427 2026] [proxy_http:error] [pid 871012:tid 871257] [client 85.204.70.96:49636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.715993 2026] [proxy:error] [pid 871012:tid 871257] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:11.716025 2026] [proxy_http:error] [pid 871012:tid 871257] [client 85.204.70.96:49636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:11.878562 2026] [security2:error] [pid 871012:tid 871154] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/IXR/"] [unique_id "al4Ri7wiU-Jh5ncAILFTEgAAARU"]
[Mon Jul 20 06:16:11.926396 2026] [security2:error] [pid 871012:tid 871242] [client 43.135.130.202:33124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.130.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4Ri7wiU-Jh5ncAILFTFQAAAW0"]
[Mon Jul 20 06:16:11.975017 2026] [security2:error] [pid 871012:tid 871236] [client 85.204.70.96:49642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4Ri7wiU-Jh5ncAILFTGgAAAWc"]
[Mon Jul 20 06:16:12.043168 2026] [security2:error] [pid 871012:tid 871260] [client 65.1.132.125:33598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RjLwiU-Jh5ncAILFTJgAAAX8"]
[Mon Jul 20 06:16:12.043261 2026] [security2:error] [pid 871012:tid 871260] [client 65.1.132.125:33598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RjLwiU-Jh5ncAILFTJgAAAX8"]
[Mon Jul 20 06:16:12.077453 2026] [security2:error] [pid 871012:tid 871187] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjLwiU-Jh5ncAILFTIQAAATY"]
[Mon Jul 20 06:16:12.253557 2026] [security2:error] [pid 871012:tid 871161] [client 85.204.70.96:49654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RjLwiU-Jh5ncAILFTOAAAARw"]
[Mon Jul 20 06:16:12.270434 2026] [security2:error] [pid 871012:tid 871189] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/Requests/"] [unique_id "al4RjLwiU-Jh5ncAILFTPAAAATg"]
[Mon Jul 20 06:16:12.517147 2026] [proxy:error] [pid 871012:tid 871228] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:12.517230 2026] [proxy_http:error] [pid 871012:tid 871228] [client 85.204.70.96:49668] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:12.517859 2026] [proxy:error] [pid 871012:tid 871228] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:16:12.517891 2026] [proxy_http:error] [pid 871012:tid 871228] [client 85.204.70.96:49668] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:16:12.528489 2026] [security2:error] [pid 871012:tid 871173] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjLwiU-Jh5ncAILFTSwAAASg"]
[Mon Jul 20 06:16:12.675313 2026] [security2:error] [pid 871012:tid 871235] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/SimplePie/"] [unique_id "al4RjLwiU-Jh5ncAILFTVwAAAWY"]
[Mon Jul 20 06:16:12.759634 2026] [security2:error] [pid 871012:tid 871267] [client 185.132.186.86:35739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/admin-footer.php"] [unique_id "al4RjLwiU-Jh5ncAILFTYAAAAYY"]
[Mon Jul 20 06:16:12.785493 2026] [security2:error] [pid 871012:tid 871182] [client 85.204.70.96:55260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4RjLwiU-Jh5ncAILFTaAAAATE"]
[Mon Jul 20 06:16:12.808276 2026] [security2:error] [pid 871012:tid 871222] [client 14.225.17.146:60572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTQgAAAVk"], referer: http://overloadcomedy.com/WordPress
[Mon Jul 20 06:16:12.868450 2026] [security2:error] [pid 871012:tid 871200] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjLwiU-Jh5ncAILFTbAAAAUM"]
[Mon Jul 20 06:16:12.886459 2026] [security2:error] [pid 871012:tid 871190] [client 66.249.69.32:49619] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "bundleofjoyandpoop.com"] [uri "/robots.txt"] [unique_id "al4RjLwiU-Jh5ncAILFTdQAAATk"]
[Mon Jul 20 06:16:13.024307 2026] [security2:error] [pid 871012:tid 871257] [client 50.116.65.227:47492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4RjbwiU-Jh5ncAILFTfwAAAXw"]
[Mon Jul 20 06:16:13.025096 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/Text/"] [unique_id "al4RjbwiU-Jh5ncAILFTfgAAAWk"]
[Mon Jul 20 06:16:13.038805 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:25108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4RjbwiU-Jh5ncAILFTgQAAAS0"]
[Mon Jul 20 06:16:13.052484 2026] [security2:error] [pid 871012:tid 871241] [client 85.204.70.96:55270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFThQAAAWw"]
[Mon Jul 20 06:16:13.176867 2026] [security2:error] [pid 871012:tid 871197] [client 45.157.112.60:25209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RjbwiU-Jh5ncAILFTjwAAAUA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:13.233447 2026] [security2:error] [pid 871012:tid 871243] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjbwiU-Jh5ncAILFTkQAAAW4"]
[Mon Jul 20 06:16:13.264863 2026] [security2:error] [pid 871012:tid 871204] [client 14.225.17.146:60818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTdgAAAUc"], referer: http://carolinapressurewashers.com/WordPress
[Mon Jul 20 06:16:13.318565 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.96:55282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFTngAAAVU"]
[Mon Jul 20 06:16:13.382400 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/mu-plugins-old/"] [unique_id "al4RjbwiU-Jh5ncAILFTpAAAAXs"]
[Mon Jul 20 06:16:13.457301 2026] [security2:error] [pid 871012:tid 871206] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RjbwiU-Jh5ncAILFToQABSRw"]
[Mon Jul 20 06:16:13.575013 2026] [security2:error] [pid 871012:tid 871234] [client 85.204.70.96:55288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFTsQAAAWU"]
[Mon Jul 20 06:16:13.597068 2026] [security2:error] [pid 871012:tid 871229] [client 171.60.139.123:60709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RjbwiU-Jh5ncAILFTtAAAAWA"]
[Mon Jul 20 06:16:13.597234 2026] [security2:error] [pid 871012:tid 871229] [client 171.60.139.123:60709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RjbwiU-Jh5ncAILFTtAAAAWA"]
[Mon Jul 20 06:16:13.619834 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjbwiU-Jh5ncAILFTrwAAAUA"]
[Mon Jul 20 06:16:13.639634 2026] [security2:error] [pid 871012:tid 871192] [client 50.116.65.227:25130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4RjbwiU-Jh5ncAILFTtQAAATs"]
[Mon Jul 20 06:16:13.649253 2026] [security2:error] [pid 871012:tid 871221] [client 50.116.65.227:25146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4RjbwiU-Jh5ncAILFTtwAAAVg"]
[Mon Jul 20 06:16:13.791556 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/themes/classic/inc/"] [unique_id "al4RjbwiU-Jh5ncAILFTwQAAAWk"]
[Mon Jul 20 06:16:13.832213 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.96:55292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4RjbwiU-Jh5ncAILFTxgAAAXs"]
[Mon Jul 20 06:16:13.942512 2026] [security2:error] [pid 871012:tid 871253] [client 35.254.54.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTMQAAAXg"]
[Mon Jul 20 06:16:14.021407 2026] [security2:error] [pid 871012:tid 871211] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjbwiU-Jh5ncAILFT2AAAAU4"]
[Mon Jul 20 06:16:14.095572 2026] [security2:error] [pid 871012:tid 871193] [client 85.204.70.96:55302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFT4wAAATw"]
[Mon Jul 20 06:16:14.182880 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "al4RjrwiU-Jh5ncAILFT6QAAARk"]
[Mon Jul 20 06:16:14.255139 2026] [security2:error] [pid 871012:tid 871225] [client 14.225.17.146:51458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFTgAAAAVw"], referer: http://collectingrealestate.com/WordPress
[Mon Jul 20 06:16:14.361103 2026] [security2:error] [pid 871012:tid 871240] [client 85.204.70.96:55314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFT-wAAAWs"]
[Mon Jul 20 06:16:14.410425 2026] [security2:error] [pid 871012:tid 871194] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjrwiU-Jh5ncAILFT_QAAAT0"]
[Mon Jul 20 06:16:14.591140 2026] [security2:error] [pid 871012:tid 871222] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/mu-plugins/"] [unique_id "al4RjrwiU-Jh5ncAILFUFwAAAVk"]
[Mon Jul 20 06:16:14.620957 2026] [security2:error] [pid 871012:tid 871227] [client 85.204.70.96:55322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFUGQAAAV4"]
[Mon Jul 20 06:16:14.764526 2026] [security2:error] [pid 871012:tid 871206] [client 185.132.186.94:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/modules/mod_simplefileuploadv1.3/elements/admin-footer.php"] [unique_id "al4RjrwiU-Jh5ncAILFUIQAAAUk"]
[Mon Jul 20 06:16:14.823404 2026] [security2:error] [pid 871012:tid 871252] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RjrwiU-Jh5ncAILFUIgAAAXc"]
[Mon Jul 20 06:16:14.881973 2026] [security2:error] [pid 871012:tid 871143] [client 85.204.70.96:55338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4RjrwiU-Jh5ncAILFULwAAAQo"]
[Mon Jul 20 06:16:14.976778 2026] [security2:error] [pid 871012:tid 871247] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al4RjrwiU-Jh5ncAILFUPAAAAXI"]
[Mon Jul 20 06:16:14.982237 2026] [security2:error] [pid 871012:tid 871242] [client 103.141.108.143:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RjrwiU-Jh5ncAILFUPQAAAW0"]
[Mon Jul 20 06:16:14.982984 2026] [security2:error] [pid 871012:tid 871242] [client 103.141.108.143:54249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RjrwiU-Jh5ncAILFUPQAAAW0"]
[Mon Jul 20 06:16:15.042658 2026] [security2:error] [pid 871012:tid 871238] [client 50.116.65.227:47494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Rj7wiU-Jh5ncAILFUPwAAAWk"]
[Mon Jul 20 06:16:15.054944 2026] [security2:error] [pid 871012:tid 871256] [client 50.116.65.227:25168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4Rj7wiU-Jh5ncAILFUQgAAAXU"]
[Mon Jul 20 06:16:15.134299 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUSgAAAX8"]
[Mon Jul 20 06:16:15.134408 2026] [security2:error] [pid 871012:tid 871260] [client 45.116.69.230:51800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUSgAAAX8"]
[Mon Jul 20 06:16:15.148315 2026] [security2:error] [pid 871012:tid 871202] [client 85.204.70.96:55354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUUgAAAUU"]
[Mon Jul 20 06:16:15.166319 2026] [security2:error] [pid 871012:tid 871186] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rj7wiU-Jh5ncAILFUSAAAATU"]
[Mon Jul 20 06:16:15.204634 2026] [security2:error] [pid 871012:tid 871270] [client 57.141.18.115:43640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RibwiU-Jh5ncAILFSagABiXA"]
[Mon Jul 20 06:16:15.306237 2026] [security2:error] [pid 871012:tid 871217] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/blocks/"] [unique_id "al4Rj7wiU-Jh5ncAILFUVwAAAVQ"]
[Mon Jul 20 06:16:15.381480 2026] [security2:error] [pid 871012:tid 871226] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUUwAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:15.413227 2026] [security2:error] [pid 871012:tid 871187] [client 85.204.70.96:55366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUZAAAATY"]
[Mon Jul 20 06:16:15.418641 2026] [security2:error] [pid 871012:tid 871239] [client 106.192.104.4:34208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.104.192.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUaAAAAWo"]
[Mon Jul 20 06:16:15.418745 2026] [security2:error] [pid 871012:tid 871239] [client 106.192.104.4:34208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "worbals.com"] [uri "/xmlrpc.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUaAAAAWo"]
[Mon Jul 20 06:16:15.527431 2026] [security2:error] [pid 871012:tid 871199] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rj7wiU-Jh5ncAILFUbQAAAUI"]
[Mon Jul 20 06:16:15.538474 2026] [security2:error] [pid 871012:tid 871251] [client 98.159.234.160:50053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUdwAAAXY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:15.679359 2026] [security2:error] [pid 871012:tid 871268] [client 85.204.70.96:55378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUfwAAAYc"]
[Mon Jul 20 06:16:15.684289 2026] [security2:error] [pid 871012:tid 871194] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/certificates/"] [unique_id "al4Rj7wiU-Jh5ncAILFUgAAAAT0"]
[Mon Jul 20 06:16:15.785335 2026] [security2:error] [pid 871012:tid 871173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUdAAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:15.883835 2026] [security2:error] [pid 871012:tid 871191] [client 14.225.17.146:60591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFTsgAAATo"], referer: http://adastra.love/WordPress
[Mon Jul 20 06:16:15.924474 2026] [security2:error] [pid 871012:tid 871175] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rj7wiU-Jh5ncAILFUlQAAASo"]
[Mon Jul 20 06:16:15.943544 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.96:55380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.str.cly.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Rj7wiU-Jh5ncAILFUmQAAAR4"]
[Mon Jul 20 06:16:16.088962 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/customize/"] [unique_id "al4RkLwiU-Jh5ncAILFUqAAAAWE"]
[Mon Jul 20 06:16:16.253423 2026] [core:error] [pid 871012:tid 871259] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.253457 2026] [core:error] [pid 871012:tid 871259] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.270507 2026] [core:error] [pid 871012:tid 871155] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.270528 2026] [core:error] [pid 871012:tid 871155] [client 140.248.75.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:16.318303 2026] [security2:error] [pid 871012:tid 871193] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkLwiU-Jh5ncAILFUwAAAATw"]
[Mon Jul 20 06:16:16.349897 2026] [security2:error] [pid 871012:tid 871172] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rj7wiU-Jh5ncAILFUogAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:16.476894 2026] [security2:error] [pid 871012:tid 871246] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/fonts/"] [unique_id "al4RkLwiU-Jh5ncAILFUzQAAAXE"]
[Mon Jul 20 06:16:16.547404 2026] [security2:error] [pid 871012:tid 871087] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU0gABf0k"]
[Mon Jul 20 06:16:16.547582 2026] [security2:error] [pid 871012:tid 871260] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU0gABf0k"]
[Mon Jul 20 06:16:16.663639 2026] [security2:error] [pid 871012:tid 871195] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkLwiU-Jh5ncAILFU2AAAAT4"]
[Mon Jul 20 06:16:16.764738 2026] [security2:error] [pid 871012:tid 871147] [client 185.132.186.77:25865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/info.php"] [unique_id "al4RkLwiU-Jh5ncAILFU5wAAAQ4"]
[Mon Jul 20 06:16:16.804089 2026] [security2:error] [pid 871012:tid 871172] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/images/"] [unique_id "al4RkLwiU-Jh5ncAILFU6QAAASc"]
[Mon Jul 20 06:16:16.813331 2026] [security2:error] [pid 871012:tid 871214] [client 41.173.37.102:14636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU6gAAAVE"]
[Mon Jul 20 06:16:16.813406 2026] [security2:error] [pid 871012:tid 871214] [client 41.173.37.102:14636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RkLwiU-Jh5ncAILFU6gAAAVE"]
[Mon Jul 20 06:16:16.935504 2026] [security2:error] [pid 871012:tid 871240] [client 74.208.214.194:36550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RkLwiU-Jh5ncAILFU8wAAAWs"]
[Mon Jul 20 06:16:17.037343 2026] [security2:error] [pid 871012:tid 871182] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkLwiU-Jh5ncAILFU_gAAATE"]
[Mon Jul 20 06:16:17.187903 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/.well-known/"] [unique_id "al4RkbwiU-Jh5ncAILFVCwAAARA"]
[Mon Jul 20 06:16:17.201093 2026] [security2:error] [pid 871012:tid 871270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkLwiU-Jh5ncAILFU7gAAAYk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:17.277887 2026] [security2:error] [pid 871012:tid 871185] [client 178.152.178.232:36168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RkbwiU-Jh5ncAILFVDwAAATQ"]
[Mon Jul 20 06:16:17.278028 2026] [security2:error] [pid 871012:tid 871185] [client 178.152.178.232:36168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RkbwiU-Jh5ncAILFVDwAAATQ"]
[Mon Jul 20 06:16:17.370464 2026] [security2:error] [pid 871012:tid 871147] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkbwiU-Jh5ncAILFVEgAAAQ4"]
[Mon Jul 20 06:16:17.429086 2026] [security2:error] [pid 871012:tid 871232] [client 104.234.53.91:21469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RkbwiU-Jh5ncAILFVGAAAAWM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:17.509259 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/ALFA_DATA/"] [unique_id "al4RkbwiU-Jh5ncAILFVJAAAATI"]
[Mon Jul 20 06:16:17.734646 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkbwiU-Jh5ncAILFVNwAAARA"]
[Mon Jul 20 06:16:17.839228 2026] [security2:error] [pid 871012:tid 871024] [remote 47.86.33.52:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4RkbwiU-Jh5ncAILFVQgABaQo"]
[Mon Jul 20 06:16:17.888669 2026] [security2:error] [pid 871012:tid 871226] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/.well-knownold/"] [unique_id "al4RkbwiU-Jh5ncAILFVRwAAAV0"]
[Mon Jul 20 06:16:17.946028 2026] [security2:error] [pid 871012:tid 871189] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkbwiU-Jh5ncAILFVOQAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:18.073701 2026] [security2:error] [pid 871012:tid 871198] [client 57.141.18.74:30916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjLwiU-Jh5ncAILFTPwABQQs"]
[Mon Jul 20 06:16:18.135456 2026] [security2:error] [pid 871012:tid 871170] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkrwiU-Jh5ncAILFVYQAAASU"]
[Mon Jul 20 06:16:18.296334 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/.well-known/acme-challenge/"] [unique_id "al4RkrwiU-Jh5ncAILFVbAAAATQ"]
[Mon Jul 20 06:16:18.352182 2026] [security2:error] [pid 871012:tid 871256] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkrwiU-Jh5ncAILFVZAAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:18.353453 2026] [security2:error] [pid 871012:tid 871143] [client 103.77.203.233:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RkrwiU-Jh5ncAILFVcgAAAQo"]
[Mon Jul 20 06:16:18.353884 2026] [security2:error] [pid 871012:tid 871143] [client 103.77.203.233:64037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RkrwiU-Jh5ncAILFVcgAAAQo"]
[Mon Jul 20 06:16:18.531324 2026] [security2:error] [pid 871012:tid 871221] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkrwiU-Jh5ncAILFVfAAAAVg"]
[Mon Jul 20 06:16:18.648514 2026] [security2:error] [pid 871012:tid 871056] [remote 47.86.33.52:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4RkrwiU-Jh5ncAILFVkwABfyo"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:16:18.682593 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/cgi-bin/"] [unique_id "al4RkrwiU-Jh5ncAILFVlwAAAUk"]
[Mon Jul 20 06:16:18.753446 2026] [security2:error] [pid 871012:tid 871238] [client 185.132.186.90:45685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/XML/content.php"] [unique_id "al4RkrwiU-Jh5ncAILFVmgAAAWk"]
[Mon Jul 20 06:16:18.851399 2026] [security2:error] [pid 871012:tid 871230] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RkrwiU-Jh5ncAILFVkAAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:18.925321 2026] [security2:error] [pid 871012:tid 871214] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RkrwiU-Jh5ncAILFVpwAAAVE"]
[Mon Jul 20 06:16:19.080242 2026] [security2:error] [pid 871012:tid 871260] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/index/"] [unique_id "al4Rk7wiU-Jh5ncAILFVvQAAAX8"]
[Mon Jul 20 06:16:19.086711 2026] [security2:error] [pid 871012:tid 871159] [client 57.141.18.6:59280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFThwABGnU"]
[Mon Jul 20 06:16:19.268594 2026] [security2:error] [pid 871012:tid 871217] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rk7wiU-Jh5ncAILFV1AAAAVQ"]
[Mon Jul 20 06:16:19.293179 2026] [security2:error] [pid 871012:tid 871254] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4Rk7wiU-Jh5ncAILFVuwAAAXk"]
[Mon Jul 20 06:16:19.325678 2026] [security2:error] [pid 871012:tid 871209] [client 14.225.17.146:62860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4RkbwiU-Jh5ncAILFVSgAAAUw"], referer: http://bbwipartnerconference.com/WordPress
[Mon Jul 20 06:16:19.411382 2026] [security2:error] [pid 871012:tid 871251] [client 27.96.94.195:36996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Rk7wiU-Jh5ncAILFV4AAAAXY"]
[Mon Jul 20 06:16:19.411562 2026] [security2:error] [pid 871012:tid 871251] [client 27.96.94.195:36996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4Rk7wiU-Jh5ncAILFV4AAAAXY"]
[Mon Jul 20 06:16:19.419193 2026] [security2:error] [pid 871012:tid 871174] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/id/"] [unique_id "al4Rk7wiU-Jh5ncAILFV4gAAASk"]
[Mon Jul 20 06:16:19.502301 2026] [security2:error] [pid 871012:tid 871262] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rk7wiU-Jh5ncAILFV0gAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:19.578165 2026] [security2:error] [pid 871012:tid 871243] [client 14.225.17.146:62858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4RkbwiU-Jh5ncAILFVTQAAAW4"], referer: http://careysheatingandcooling.com/WordPress
[Mon Jul 20 06:16:19.642408 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rk7wiU-Jh5ncAILFV9AAAAUs"]
[Mon Jul 20 06:16:19.787780 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/www/"] [unique_id "al4Rk7wiU-Jh5ncAILFWAwAAAUk"]
[Mon Jul 20 06:16:19.918166 2026] [security2:error] [pid 871012:tid 871233] [client 57.141.18.80:33322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjbwiU-Jh5ncAILFTyQABZDg"]
[Mon Jul 20 06:16:19.978462 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rk7wiU-Jh5ncAILFWCgAAATI"]
[Mon Jul 20 06:16:20.173541 2026] [security2:error] [pid 871012:tid 871241] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/web/"] [unique_id "al4RlLwiU-Jh5ncAILFWHQAAAWw"]
[Mon Jul 20 06:16:20.229055 2026] [security2:error] [pid 871012:tid 871152] [client 57.141.18.116:43008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RjrwiU-Jh5ncAILFT5wABE0M"]
[Mon Jul 20 06:16:20.277315 2026] [security2:error] [pid 871012:tid 871035] [remote 124.55.178.99:38560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RlLwiU-Jh5ncAILFWLQABFRU"]
[Mon Jul 20 06:16:20.355271 2026] [security2:error] [pid 871012:tid 871194] [client 181.224.94.124:26677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RlLwiU-Jh5ncAILFWNAAAAT0"]
[Mon Jul 20 06:16:20.355417 2026] [security2:error] [pid 871012:tid 871194] [client 181.224.94.124:26677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RlLwiU-Jh5ncAILFWNAAAAT0"]
[Mon Jul 20 06:16:20.444425 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlLwiU-Jh5ncAILFWNQAAAVU"]
[Mon Jul 20 06:16:20.449106 2026] [security2:error] [pid 871012:tid 871252] [client 50.116.65.227:29324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4RlLwiU-Jh5ncAILFWNwAAAXc"]
[Mon Jul 20 06:16:20.460870 2026] [security2:error] [pid 871012:tid 871220] [client 50.116.65.227:54822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4RlLwiU-Jh5ncAILFWOAAAAV4"]
[Mon Jul 20 06:16:20.595833 2026] [security2:error] [pid 871012:tid 871221] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/uploads/"] [unique_id "al4RlLwiU-Jh5ncAILFWRgAAAVg"]
[Mon Jul 20 06:16:20.758130 2026] [security2:error] [pid 871012:tid 871159] [client 185.132.186.68:27829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/pomo/item.php"] [unique_id "al4RlLwiU-Jh5ncAILFWWAAAARo"]
[Mon Jul 20 06:16:20.780348 2026] [security2:error] [pid 871012:tid 871117] [remote 124.55.178.99:38560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RlLwiU-Jh5ncAILFWXAABX2c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:16:20.835618 2026] [security2:error] [pid 871012:tid 871143] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlLwiU-Jh5ncAILFWWgAAAQo"]
[Mon Jul 20 06:16:20.879919 2026] [security2:error] [pid 871012:tid 871155] [client 57.141.18.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rentorangegrove.com"] [uri "/index.php"] [unique_id "al4RlLwiU-Jh5ncAILFWSwAAARY"]
[Mon Jul 20 06:16:20.986934 2026] [security2:error] [pid 871012:tid 871242] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/upload/"] [unique_id "al4RlLwiU-Jh5ncAILFWaAAAAW0"]
[Mon Jul 20 06:16:20.987358 2026] [security2:error] [pid 871012:tid 871085] [remote 51.158.61.221:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RlLwiU-Jh5ncAILFWaQABNEc"]
[Mon Jul 20 06:16:21.192615 2026] [security2:error] [pid 871012:tid 871071] [remote 130.185.118.215:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWgwABhjk"]
[Mon Jul 20 06:16:21.209532 2026] [security2:error] [pid 871012:tid 871202] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlbwiU-Jh5ncAILFWggAAAUU"]
[Mon Jul 20 06:16:21.243942 2026] [security2:error] [pid 871012:tid 871097] [remote 51.158.61.221:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWiAABQ1M"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:16:21.387347 2026] [security2:error] [pid 871012:tid 871034] [remote 130.185.118.215:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWlAABNhQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:16:21.394682 2026] [security2:error] [pid 871012:tid 871241] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/uploads/"] [unique_id "al4RlbwiU-Jh5ncAILFWlQAAAWw"]
[Mon Jul 20 06:16:21.576299 2026] [security2:error] [pid 871012:tid 871207] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlbwiU-Jh5ncAILFWowAAAUo"]
[Mon Jul 20 06:16:21.713734 2026] [security2:error] [pid 871012:tid 871149] [client 216.73.217.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.poopscoopuniversity.com"] [uri "/index.php"] [unique_id "al4RlLwiU-Jh5ncAILFWOgABEHg"]
[Mon Jul 20 06:16:21.719122 2026] [security2:error] [pid 871012:tid 871179] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Admin/uploads/"] [unique_id "al4RlbwiU-Jh5ncAILFWsgAAAS4"]
[Mon Jul 20 06:16:21.724035 2026] [security2:error] [pid 871012:tid 871129] [remote 57.141.18.20:37874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3296202"] [unique_id "al4RlbwiU-Jh5ncAILFWswABJ3M"]
[Mon Jul 20 06:16:21.800526 2026] [security2:error] [pid 871012:tid 871216] [client 14.225.17.146:64597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4RlbwiU-Jh5ncAILFWdAAAAVM"], referer: http://idigress.agency/WordPress
[Mon Jul 20 06:16:21.927853 2026] [security2:error] [pid 871012:tid 871147] [client 57.141.18.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4RlbwiU-Jh5ncAILFWiQAAAQ4"]
[Mon Jul 20 06:16:21.928335 2026] [security2:error] [pid 871012:tid 871162] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlbwiU-Jh5ncAILFWvwAAAR0"]
[Mon Jul 20 06:16:21.963154 2026] [security2:error] [pid 871012:tid 871108] [remote 154.66.198.148:2754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlbwiU-Jh5ncAILFWwgABf14"]
[Mon Jul 20 06:16:22.061911 2026] [security2:error] [pid 871012:tid 871155] [client 14.225.17.146:52130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4RlbwiU-Jh5ncAILFWvQAAARY"], referer: http://longevityperformanceclinic.com/WordPress
[Mon Jul 20 06:16:22.084655 2026] [security2:error] [pid 871012:tid 871248] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/"] [unique_id "al4RlrwiU-Jh5ncAILFW2AAAAXM"]
[Mon Jul 20 06:16:22.319507 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlrwiU-Jh5ncAILFW7gAAAXs"]
[Mon Jul 20 06:16:22.392175 2026] [security2:error] [pid 871012:tid 871161] [client 57.141.18.67:55730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RkLwiU-Jh5ncAILFUwwABHAQ"]
[Mon Jul 20 06:16:22.483265 2026] [security2:error] [pid 871012:tid 871092] [remote 38.242.157.30:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFW-gABak4"]
[Mon Jul 20 06:16:22.487349 2026] [security2:error] [pid 871012:tid 871198] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/images/"] [unique_id "al4RlrwiU-Jh5ncAILFW_AAAAUE"]
[Mon Jul 20 06:16:22.668305 2026] [security2:error] [pid 871012:tid 871227] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlrwiU-Jh5ncAILFXEAAAAV4"]
[Mon Jul 20 06:16:22.708242 2026] [security2:error] [pid 871012:tid 871019] [remote 38.242.157.30:37684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXFwABKgU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:22.750266 2026] [security2:error] [pid 871012:tid 871082] [remote 51.158.61.221:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXIAABXEQ"]
[Mon Jul 20 06:16:22.757109 2026] [security2:error] [pid 871012:tid 871256] [client 185.132.186.79:35597] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-content/1.php%20"] [unique_id "al4RlrwiU-Jh5ncAILFXIQAAAXs"]
[Mon Jul 20 06:16:22.757270 2026] [security2:error] [pid 871012:tid 871256] [client 185.132.186.79:35597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/1.php%20"] [unique_id "al4RlrwiU-Jh5ncAILFXIQAAAXs"]
[Mon Jul 20 06:16:22.792271 2026] [security2:error] [pid 871012:tid 871045] [remote 154.66.198.148:2754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXJQABSh8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:22.809369 2026] [security2:error] [pid 871012:tid 871252] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/assets/"] [unique_id "al4RlrwiU-Jh5ncAILFXJwAAAXc"]
[Mon Jul 20 06:16:22.953486 2026] [security2:error] [pid 871012:tid 871195] [client 13.201.64.214:57100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RlrwiU-Jh5ncAILFXLQAAAT4"]
[Mon Jul 20 06:16:22.953576 2026] [security2:error] [pid 871012:tid 871195] [client 13.201.64.214:57100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RlrwiU-Jh5ncAILFXLQAAAT4"]
[Mon Jul 20 06:16:22.970742 2026] [security2:error] [pid 871012:tid 871057] [remote 51.158.61.221:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4RlrwiU-Jh5ncAILFXLwABGCs"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:16:23.031368 2026] [security2:error] [pid 871012:tid 871254] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RlrwiU-Jh5ncAILFXMAAAAXk"]
[Mon Jul 20 06:16:23.181117 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXAgABNh0"]
[Mon Jul 20 06:16:23.181446 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCAABNms"]
[Mon Jul 20 06:16:23.181536 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDwABNhg"]
[Mon Jul 20 06:16:23.181661 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCwABNhM"]
[Mon Jul 20 06:16:23.181740 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDAABNjA"]
[Mon Jul 20 06:16:23.183905 2026] [security2:error] [pid 871012:tid 871143] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "al4Rl7wiU-Jh5ncAILFXPwAAAQo"]
[Mon Jul 20 06:16:23.193627 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDQABNgI"]
[Mon Jul 20 06:16:23.202333 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXBAABNjU"]
[Mon Jul 20 06:16:23.202616 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXAwABNgM"]
[Mon Jul 20 06:16:23.206058 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCgABNno"]
[Mon Jul 20 06:16:23.215810 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXCQABNgw"]
[Mon Jul 20 06:16:23.223376 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFXDgABNgA"]
[Mon Jul 20 06:16:23.372274 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rl7wiU-Jh5ncAILFXUQAAAUs"]
[Mon Jul 20 06:16:23.512004 2026] [security2:error] [pid 871012:tid 871263] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/upload/image/"] [unique_id "al4Rl7wiU-Jh5ncAILFXXQAAAYI"]
[Mon Jul 20 06:16:23.733820 2026] [security2:error] [pid 871012:tid 871225] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rl7wiU-Jh5ncAILFXawAAAVw"]
[Mon Jul 20 06:16:23.826950 2026] [security2:error] [pid 871012:tid 871222] [client 14.225.17.146:61139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4RlrwiU-Jh5ncAILFW9gAAAVk"], referer: http://scott-assist.com/WordPress
[Mon Jul 20 06:16:23.891038 2026] [security2:error] [pid 871012:tid 871216] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/assets/images/"] [unique_id "al4Rl7wiU-Jh5ncAILFXhAAAAVM"]
[Mon Jul 20 06:16:23.983695 2026] [security2:error] [pid 871012:tid 871089] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env"] [unique_id "al4Rl7wiU-Jh5ncAILFXigABeEs"]
[Mon Jul 20 06:16:24.036541 2026] [security2:error] [pid 871012:tid 871058] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.guidehunting.com"] [uri "/graphql"] [unique_id "al4RmLwiU-Jh5ncAILFXkAABNiw"]
[Mon Jul 20 06:16:24.037561 2026] [security2:error] [pid 871012:tid 871139] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env.old"] [unique_id "al4RmLwiU-Jh5ncAILFXjwABNn0"]
[Mon Jul 20 06:16:24.061215 2026] [security2:error] [pid 871012:tid 871071] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.guidehunting.com"] [uri "/.env.production"] [unique_id "al4RmLwiU-Jh5ncAILFXmgABQzk"]
[Mon Jul 20 06:16:24.061422 2026] [security2:error] [pid 871012:tid 871127] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/backend/.env"] [unique_id "al4RmLwiU-Jh5ncAILFXlQABQ3E"]
[Mon Jul 20 06:16:24.061438 2026] [security2:error] [pid 871012:tid 871115] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/api/.env"] [unique_id "al4RmLwiU-Jh5ncAILFXmAABQ2U"]
[Mon Jul 20 06:16:24.062369 2026] [security2:error] [pid 871012:tid 871095] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env.backup"] [unique_id "al4RmLwiU-Jh5ncAILFXmQABQ1E"]
[Mon Jul 20 06:16:24.062383 2026] [security2:error] [pid 871012:tid 871060] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/config/.env"] [unique_id "al4RmLwiU-Jh5ncAILFXmwABQy4"]
[Mon Jul 20 06:16:24.084302 2026] [security2:error] [pid 871012:tid 871244] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXiQABbwg"]
[Mon Jul 20 06:16:24.125261 2026] [security2:error] [pid 871012:tid 871260] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmLwiU-Jh5ncAILFXoQAAAX8"]
[Mon Jul 20 06:16:24.288642 2026] [security2:error] [pid 871012:tid 871212] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Public/"] [unique_id "al4RmLwiU-Jh5ncAILFXrQAAAU8"]
[Mon Jul 20 06:16:24.378311 2026] [security2:error] [pid 871012:tid 871200] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXlgABQ2M"]
[Mon Jul 20 06:16:24.378534 2026] [security2:error] [pid 871012:tid 871200] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXlAABQzM"]
[Mon Jul 20 06:16:24.394233 2026] [security2:error] [pid 871012:tid 871042] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.guidehunting.com"] [uri "/api/graphql"] [unique_id "al4RmLwiU-Jh5ncAILFXuQABIxw"]
[Mon Jul 20 06:16:24.452008 2026] [security2:error] [pid 871012:tid 871229] [client 41.173.37.102:1295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvwAAAWA"]
[Mon Jul 20 06:16:24.452133 2026] [security2:error] [pid 871012:tid 871229] [client 41.173.37.102:1295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvwAAAWA"]
[Mon Jul 20 06:16:24.475770 2026] [security2:error] [pid 871012:tid 871255] [client 171.60.139.123:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXwAAAAXo"]
[Mon Jul 20 06:16:24.475886 2026] [security2:error] [pid 871012:tid 871255] [client 171.60.139.123:61195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RmLwiU-Jh5ncAILFXwAAAAXo"]
[Mon Jul 20 06:16:24.539641 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:56146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmLwiU-Jh5ncAILFXwQAAARk"]
[Mon Jul 20 06:16:24.737788 2026] [security2:error] [pid 871012:tid 871162] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXuwABHVs"]
[Mon Jul 20 06:16:24.739120 2026] [security2:error] [pid 871012:tid 871162] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvQABHTc"]
[Mon Jul 20 06:16:24.740155 2026] [security2:error] [pid 871012:tid 871162] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXvAABHQo"]
[Mon Jul 20 06:16:24.759504 2026] [security2:error] [pid 871012:tid 871195] [client 185.132.186.87:40815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/wp-atom.php"] [unique_id "al4RmLwiU-Jh5ncAILFX0wAAAT4"]
[Mon Jul 20 06:16:24.793908 2026] [security2:error] [pid 871012:tid 871025] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.env.bak"] [unique_id "al4RmLwiU-Jh5ncAILFX1QABRgs"]
[Mon Jul 20 06:16:24.843287 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/vendor/"] [unique_id "al4RmLwiU-Jh5ncAILFX2wAAAR4"]
[Mon Jul 20 06:16:25.026040 2026] [security2:error] [pid 871012:tid 871102] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.guidehunting.com"] [uri "/v1/graphql"] [unique_id "al4RmbwiU-Jh5ncAILFX7QABRlg"]
[Mon Jul 20 06:16:25.040404 2026] [security2:error] [pid 871012:tid 871229] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmLwiU-Jh5ncAILFX6QAAAWA"]
[Mon Jul 20 06:16:25.081051 2026] [security2:error] [pid 871012:tid 871018] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/.boto"] [unique_id "al4RmbwiU-Jh5ncAILFX_AABRgQ"]
[Mon Jul 20 06:16:25.081236 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.guidehunting.com"] [uri "/.boto"] [unique_id "al4RmbwiU-Jh5ncAILFX_AABRgQ"]
[Mon Jul 20 06:16:25.081905 2026] [authz_core:error] [pid 871012:tid 871056] [remote 35.245.65.174:33064] AH01630: client denied by server configuration: /home4/guidehun/public_html/.htpasswd
[Mon Jul 20 06:16:25.098069 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFX1AABRmw"]
[Mon Jul 20 06:16:25.186467 2026] [security2:error] [pid 871012:tid 871270] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/local/"] [unique_id "al4RmbwiU-Jh5ncAILFYEQAAAYk"]
[Mon Jul 20 06:16:25.230775 2026] [security2:error] [pid 871012:tid 871196] [client 14.225.17.146:52064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXdQAAAT8"], referer: http://alexsandbergmusic.com/WordPress
[Mon Jul 20 06:16:25.379891 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX7wABRjQ"]
[Mon Jul 20 06:16:25.380593 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX7gABRhE"]
[Mon Jul 20 06:16:25.386205 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX8AABRj8"]
[Mon Jul 20 06:16:25.435277 2026] [security2:error] [pid 871012:tid 871144] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmbwiU-Jh5ncAILFYKAAAAQs"]
[Mon Jul 20 06:16:25.583276 2026] [security2:error] [pid 871012:tid 871171] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/modules/"] [unique_id "al4RmbwiU-Jh5ncAILFYMgAAASY"]
[Mon Jul 20 06:16:25.697386 2026] [security2:error] [pid 871012:tid 871155] [client 104.234.53.59:24167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RmbwiU-Jh5ncAILFYQQAAARY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:25.723320 2026] [security2:error] [pid 871012:tid 871252] [client 103.141.108.143:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYRgAAAXc"]
[Mon Jul 20 06:16:25.723515 2026] [security2:error] [pid 871012:tid 871252] [client 103.141.108.143:54733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYRgAAAXc"]
[Mon Jul 20 06:16:25.776644 2026] [security2:error] [pid 871012:tid 871198] [client 45.116.69.230:52326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYTAAAAUE"]
[Mon Jul 20 06:16:25.776798 2026] [security2:error] [pid 871012:tid 871198] [client 45.116.69.230:52326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RmbwiU-Jh5ncAILFYTAAAAUE"]
[Mon Jul 20 06:16:25.813863 2026] [security2:error] [pid 871012:tid 871223] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmbwiU-Jh5ncAILFYSwAAAVo"]
[Mon Jul 20 06:16:25.985588 2026] [security2:error] [pid 871012:tid 871215] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Site/"] [unique_id "al4RmbwiU-Jh5ncAILFYWgAAAVI"]
[Mon Jul 20 06:16:26.126671 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX9wABRhc"]
[Mon Jul 20 06:16:26.131860 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX-QABRi0"]
[Mon Jul 20 06:16:26.132270 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX_gABRlQ"]
[Mon Jul 20 06:16:26.133213 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX-AABRhA"]
[Mon Jul 20 06:16:26.137174 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX_QABRgc"]
[Mon Jul 20 06:16:26.154906 2026] [security2:error] [pid 871012:tid 871203] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmbwiU-Jh5ncAILFX-wABRnY"]
[Mon Jul 20 06:16:26.207275 2026] [security2:error] [pid 871012:tid 871110] [remote 188.166.241.141:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RmrwiU-Jh5ncAILFYZwABiWA"]
[Mon Jul 20 06:16:26.221061 2026] [security2:error] [pid 871012:tid 871239] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmrwiU-Jh5ncAILFYZQAAAWo"]
[Mon Jul 20 06:16:26.225115 2026] [security2:error] [pid 871012:tid 871026] [remote 57.141.18.28:24674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3396212"] [unique_id "al4RmrwiU-Jh5ncAILFYYwABbQw"]
[Mon Jul 20 06:16:26.262499 2026] [security2:error] [pid 871012:tid 871214] [client 14.225.17.146:54392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXhwAAAVE"], referer: http://mrbambooplus.com/WordPress
[Mon Jul 20 06:16:26.321763 2026] [security2:error] [pid 871012:tid 871159] [client 158.173.89.95:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RmrwiU-Jh5ncAILFYbgAAARo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:26.380974 2026] [security2:error] [pid 871012:tid 871078] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/id_rsa"] [unique_id "al4RmrwiU-Jh5ncAILFYfAABYUA"]
[Mon Jul 20 06:16:26.381194 2026] [security2:error] [pid 871012:tid 871078] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.guidehunting.com"] [uri "/.ssh/config"] [unique_id "al4RmrwiU-Jh5ncAILFYgAABYUA"]
[Mon Jul 20 06:16:26.382120 2026] [security2:error] [pid 871012:tid 871064] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.ssh/id_dsa"] [unique_id "al4RmrwiU-Jh5ncAILFYewABYTI"]
[Mon Jul 20 06:16:26.382778 2026] [security2:error] [pid 871012:tid 871133] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.ssh/id_rsa"] [unique_id "al4RmrwiU-Jh5ncAILFYdwABYXc"]
[Mon Jul 20 06:16:26.382934 2026] [security2:error] [pid 871012:tid 871080] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/id_dsa"] [unique_id "al4RmrwiU-Jh5ncAILFYfgABYUI"]
[Mon Jul 20 06:16:26.403067 2026] [security2:error] [pid 871012:tid 871248] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/system/"] [unique_id "al4RmrwiU-Jh5ncAILFYggAAAXM"]
[Mon Jul 20 06:16:26.568684 2026] [security2:error] [pid 871012:tid 871111] [remote 188.166.241.141:45858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4RmrwiU-Jh5ncAILFYjQABEmE"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 06:16:26.627293 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmrwiU-Jh5ncAILFYjwAAARk"]
[Mon Jul 20 06:16:26.679154 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYdgABYRU"]
[Mon Jul 20 06:16:26.679387 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYeQABYTg"]
[Mon Jul 20 06:16:26.679621 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYfwABYRo"]
[Mon Jul 20 06:16:26.679957 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYfQABYSM"]
[Mon Jul 20 06:16:26.681612 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYegABYSc"]
[Mon Jul 20 06:16:26.684276 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYdQABYUM"]
[Mon Jul 20 06:16:26.688013 2026] [security2:error] [pid 871012:tid 871230] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RmrwiU-Jh5ncAILFYeAABYSk"]
[Mon Jul 20 06:16:26.728219 2026] [security2:error] [pid 871012:tid 871071] [remote 173.212.252.15:52048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4RmrwiU-Jh5ncAILFYoQABRDk"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:16:26.761968 2026] [security2:error] [pid 871012:tid 871208] [client 185.132.186.70:35037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/pomo/plugins.php"] [unique_id "al4RmrwiU-Jh5ncAILFYpAAAAUs"]
[Mon Jul 20 06:16:26.789122 2026] [security2:error] [pid 871012:tid 871223] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/template/"] [unique_id "al4RmrwiU-Jh5ncAILFYqQAAAVo"]
[Mon Jul 20 06:16:26.852311 2026] [security2:error] [pid 871012:tid 871206] [client 57.141.18.22:24956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RlLwiU-Jh5ncAILFWXwABST4"]
[Mon Jul 20 06:16:27.037233 2026] [security2:error] [pid 871012:tid 871219] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RmrwiU-Jh5ncAILFYvgAAAVY"]
[Mon Jul 20 06:16:27.073687 2026] [security2:error] [pid 871012:tid 871144] [client 13.229.223.11:39748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFYygAAAQs"]
[Mon Jul 20 06:16:27.073844 2026] [security2:error] [pid 871012:tid 871144] [client 13.229.223.11:39748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFYygAAAQs"]
[Mon Jul 20 06:16:27.188965 2026] [security2:error] [pid 871012:tid 871266] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/shop/"] [unique_id "al4Rm7wiU-Jh5ncAILFY0gAAAYU"]
[Mon Jul 20 06:16:27.383787 2026] [security2:error] [pid 871012:tid 871107] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFY3wABRV0"]
[Mon Jul 20 06:16:27.383898 2026] [security2:error] [pid 871012:tid 871202] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFY3wABRV0"]
[Mon Jul 20 06:16:27.410458 2026] [security2:error] [pid 871012:tid 871270] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rm7wiU-Jh5ncAILFY3QAAAYk"]
[Mon Jul 20 06:16:27.589923 2026] [security2:error] [pid 871012:tid 871228] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/files/"] [unique_id "al4Rm7wiU-Jh5ncAILFY8AAAAV8"]
[Mon Jul 20 06:16:27.812419 2026] [security2:error] [pid 871012:tid 871268] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rm7wiU-Jh5ncAILFY_QAAAYc"]
[Mon Jul 20 06:16:27.865535 2026] [security2:error] [pid 871012:tid 871151] [client 77.110.127.138:59020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/baking/feed/"] [unique_id "al4Rm7wiU-Jh5ncAILFZAwAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:27.966850 2026] [security2:error] [pid 871012:tid 871183] [client 178.152.178.232:36535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFZDQAAATI"]
[Mon Jul 20 06:16:27.966973 2026] [security2:error] [pid 871012:tid 871183] [client 178.152.178.232:36535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rm7wiU-Jh5ncAILFZDQAAATI"]
[Mon Jul 20 06:16:27.976958 2026] [security2:error] [pid 871012:tid 871192] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/editor/"] [unique_id "al4Rm7wiU-Jh5ncAILFZEgAAATs"]
[Mon Jul 20 06:16:28.051038 2026] [security2:error] [pid 871012:tid 871130] [remote 188.138.102.156:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RnLwiU-Jh5ncAILFZGgABPXQ"]
[Mon Jul 20 06:16:28.082474 2026] [security2:error] [pid 871012:tid 871154] [client 50.116.65.227:29340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4RnLwiU-Jh5ncAILFZHgAAARU"]
[Mon Jul 20 06:16:28.093525 2026] [security2:error] [pid 871012:tid 871252] [client 50.116.65.227:55042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4RnLwiU-Jh5ncAILFZIAAAAXc"]
[Mon Jul 20 06:16:28.166469 2026] [security2:error] [pid 871012:tid 871214] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnLwiU-Jh5ncAILFZIwAAAVE"]
[Mon Jul 20 06:16:28.270415 2026] [security2:error] [pid 871012:tid 871019] [remote 188.138.102.156:44272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4RnLwiU-Jh5ncAILFZMwABhQU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:16:28.368100 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/include/"] [unique_id "al4RnLwiU-Jh5ncAILFZOAAAAXQ"]
[Mon Jul 20 06:16:28.551349 2026] [security2:error] [pid 871012:tid 871252] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnLwiU-Jh5ncAILFZPwAAAXc"]
[Mon Jul 20 06:16:28.691657 2026] [security2:error] [pid 871012:tid 871212] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/Assets/"] [unique_id "al4RnLwiU-Jh5ncAILFZUQAAAU8"]
[Mon Jul 20 06:16:28.820009 2026] [security2:error] [pid 871012:tid 871270] [client 14.225.17.146:51360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4RnLwiU-Jh5ncAILFZSwAAAYk"], referer: http://thechancersband.com/WordPress
[Mon Jul 20 06:16:28.880733 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:64596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RnLwiU-Jh5ncAILFZXgAAAYI"]
[Mon Jul 20 06:16:28.881183 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:64596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RnLwiU-Jh5ncAILFZXgAAAYI"]
[Mon Jul 20 06:16:28.933461 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnLwiU-Jh5ncAILFZXAAAAXQ"]
[Mon Jul 20 06:16:29.088998 2026] [security2:error] [pid 871012:tid 871212] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/images/stories/"] [unique_id "al4RnbwiU-Jh5ncAILFZdgAAAU8"]
[Mon Jul 20 06:16:29.319424 2026] [security2:error] [pid 871012:tid 871189] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnbwiU-Jh5ncAILFZiAAAATg"]
[Mon Jul 20 06:16:29.478403 2026] [security2:error] [pid 871012:tid 871247] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/plugins/"] [unique_id "al4RnbwiU-Jh5ncAILFZlQAAAXI"]
[Mon Jul 20 06:16:29.499852 2026] [security2:error] [pid 871012:tid 871190] [client 57.141.18.7:21546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXMwABOSI"]
[Mon Jul 20 06:16:29.631352 2026] [security2:error] [pid 871012:tid 871182] [client 57.141.18.10:59890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rl7wiU-Jh5ncAILFXSQABMSA"]
[Mon Jul 20 06:16:29.663464 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnbwiU-Jh5ncAILFZqgAAAXQ"]
[Mon Jul 20 06:16:29.804694 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/php/"] [unique_id "al4RnbwiU-Jh5ncAILFZtQAAAWk"]
[Mon Jul 20 06:16:29.837100 2026] [security2:error] [pid 871012:tid 871181] [client 14.225.17.146:64001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4RnLwiU-Jh5ncAILFZVQAAATA"], referer: http://musichaven.info/WordPress
[Mon Jul 20 06:16:30.024437 2026] [security2:error] [pid 871012:tid 871250] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnbwiU-Jh5ncAILFZwQAAAXU"]
[Mon Jul 20 06:16:30.042898 2026] [security2:error] [pid 871012:tid 871138] [remote 100.42.189.89:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RnrwiU-Jh5ncAILFZygABUXw"]
[Mon Jul 20 06:16:30.174982 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/css/"] [unique_id "al4RnrwiU-Jh5ncAILFZ1wAAARA"]
[Mon Jul 20 06:16:30.291221 2026] [security2:error] [pid 871012:tid 871073] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/privatekey.key"] [unique_id "al4RnrwiU-Jh5ncAILFZ3gABfDs"]
[Mon Jul 20 06:16:30.291409 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.guidehunting.com"] [uri "/privatekey.key"] [unique_id "al4RnrwiU-Jh5ncAILFZ3gABfDs"]
[Mon Jul 20 06:16:30.292745 2026] [security2:error] [pid 871012:tid 871055] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/key.pem"] [unique_id "al4RnrwiU-Jh5ncAILFZ3QABfCk"]
[Mon Jul 20 06:16:30.295398 2026] [security2:error] [pid 871012:tid 871071] [remote 100.42.189.89:40340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ4AABZzk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:16:30.363451 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnrwiU-Jh5ncAILFZ4gAAAUA"]
[Mon Jul 20 06:16:30.382107 2026] [security2:error] [pid 871012:tid 871076] [remote 35.245.65.174:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.guidehunting.com"] [uri "/.openclaw/.env"] [unique_id "al4RnrwiU-Jh5ncAILFZ6QABfD4"]
[Mon Jul 20 06:16:30.508285 2026] [security2:error] [pid 871012:tid 871234] [client 27.96.94.195:37604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ-wAAAWU"]
[Mon Jul 20 06:16:30.508435 2026] [security2:error] [pid 871012:tid 871234] [client 27.96.94.195:37604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ-wAAAWU"]
[Mon Jul 20 06:16:30.510521 2026] [security2:error] [pid 871012:tid 871267] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "al4RnrwiU-Jh5ncAILFZ-gAAAYY"]
[Mon Jul 20 06:16:30.619195 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ3AABfEM"]
[Mon Jul 20 06:16:30.619544 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ2QABfBo"]
[Mon Jul 20 06:16:30.620668 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ2wABfCc"]
[Mon Jul 20 06:16:30.620948 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ2gABfCM"]
[Mon Jul 20 06:16:30.733430 2026] [security2:error] [pid 871012:tid 871237] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RnrwiU-Jh5ncAILFaEwAAAWg"]
[Mon Jul 20 06:16:30.749546 2026] [ssl:error] [pid 871012:tid 871183] [client 54.86.115.253:2563] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mielsantaengracia.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:16:30.755308 2026] [security2:error] [pid 871012:tid 871163] [client 14.225.17.146:51170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFaFAAAAR4"], referer: https://musichaven.info/WordPress
[Mon Jul 20 06:16:30.871320 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:32367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFaOAAAAYA"]
[Mon Jul 20 06:16:30.871455 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:32367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RnrwiU-Jh5ncAILFaOAAAAYA"]
[Mon Jul 20 06:16:30.884826 2026] [security2:error] [pid 871012:tid 871160] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/cache/"] [unique_id "al4RnrwiU-Jh5ncAILFaOQAAARs"]
[Mon Jul 20 06:16:30.948667 2026] [security2:error] [pid 871012:tid 871240] [client 57.141.18.7:21548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RmLwiU-Jh5ncAILFXugABa2Q"]
[Mon Jul 20 06:16:31.014308 2026] [security2:error] [pid 871012:tid 871252] [client 14.225.17.146:51256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ0wAAAXc"], referer: http://techtradeinc.com/WordPress
[Mon Jul 20 06:16:31.107863 2026] [security2:error] [pid 871012:tid 871188] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rn7wiU-Jh5ncAILFaWAAAATc"]
[Mon Jul 20 06:16:31.144077 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ7QABfAg"]
[Mon Jul 20 06:16:31.144923 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ6AABfCw"]
[Mon Jul 20 06:16:31.145034 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ7AABfGI"]
[Mon Jul 20 06:16:31.145176 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ6wABfCU"]
[Mon Jul 20 06:16:31.149590 2026] [security2:error] [pid 871012:tid 871257] [client 35.245.65.174:33064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZ6gABfHE"]
[Mon Jul 20 06:16:31.306720 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/maint/"] [unique_id "al4Rn7wiU-Jh5ncAILFabQAAATQ"]
[Mon Jul 20 06:16:31.422593 2026] [security2:error] [pid 871012:tid 871149] [client 14.251.3.155:61270] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Rn7wiU-Jh5ncAILFadQAAARA"]
[Mon Jul 20 06:16:31.534457 2026] [security2:error] [pid 871012:tid 871156] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rn7wiU-Jh5ncAILFafQAAARc"]
[Mon Jul 20 06:16:31.688586 2026] [security2:error] [pid 871012:tid 871254] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/akismet/"] [unique_id "al4Rn7wiU-Jh5ncAILFaoQAAAXk"]
[Mon Jul 20 06:16:31.824850 2026] [security2:error] [pid 871012:tid 871209] [client 57.141.18.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4RnbwiU-Jh5ncAILFZwwAAAUw"]
[Mon Jul 20 06:16:31.940383 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rn7wiU-Jh5ncAILFatgAAAXs"]
[Mon Jul 20 06:16:31.998758 2026] [security2:error] [pid 871012:tid 871193] [client 185.132.186.89:47597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/install.php"] [unique_id "al4Rn7wiU-Jh5ncAILFawAAAATw"]
[Mon Jul 20 06:16:32.092634 2026] [security2:error] [pid 871012:tid 871186] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/assets/"] [unique_id "al4RoLwiU-Jh5ncAILFazgAAATU"]
[Mon Jul 20 06:16:32.210658 2026] [security2:error] [pid 871012:tid 871225] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gaantfootball.co.uk"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFZzQAAAVw"]
[Mon Jul 20 06:16:32.324743 2026] [security2:error] [pid 871012:tid 871247] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RoLwiU-Jh5ncAILFa4wAAAXI"]
[Mon Jul 20 06:16:32.494327 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/block-patterns/"] [unique_id "al4RoLwiU-Jh5ncAILFa8gAAAXQ"]
[Mon Jul 20 06:16:32.557154 2026] [security2:error] [pid 871012:tid 871107] [remote 162.19.86.63:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RoLwiU-Jh5ncAILFa9wABFl0"]
[Mon Jul 20 06:16:32.557329 2026] [security2:error] [pid 871012:tid 871155] [client 162.19.86.63:44012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RoLwiU-Jh5ncAILFa9wABFl0"]
[Mon Jul 20 06:16:32.589056 2026] [security2:error] [pid 871012:tid 871194] [client 14.225.17.146:50574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFa7QAAAT0"], referer: http://taskidsvirginia.com/WordPress
[Mon Jul 20 06:16:32.684124 2026] [security2:error] [pid 871012:tid 871178] [client 57.141.18.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFa9gAAAS0"]
[Mon Jul 20 06:16:32.717348 2026] [security2:error] [pid 871012:tid 871144] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RoLwiU-Jh5ncAILFbAgAAAQs"]
[Mon Jul 20 06:16:32.884183 2026] [security2:error] [pid 871012:tid 871226] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/block-supports/"] [unique_id "al4RoLwiU-Jh5ncAILFbFQAAAV0"]
[Mon Jul 20 06:16:32.894760 2026] [autoindex:error] [pid 871012:tid 871214] [client 213.35.113.47:0] AH01276: Cannot serve directory /home3/ancestx0/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:16:33.113343 2026] [security2:error] [pid 871012:tid 871200] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RobwiU-Jh5ncAILFbHgAAAUM"]
[Mon Jul 20 06:16:33.282667 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/html-api/"] [unique_id "al4RobwiU-Jh5ncAILFbQAAAAUA"]
[Mon Jul 20 06:16:33.524472 2026] [security2:error] [pid 871012:tid 871175] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RobwiU-Jh5ncAILFbTwAAASo"]
[Mon Jul 20 06:16:33.667859 2026] [security2:error] [pid 871012:tid 871232] [client 3.109.4.218:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RobwiU-Jh5ncAILFbXQAAAWM"]
[Mon Jul 20 06:16:33.667976 2026] [security2:error] [pid 871012:tid 871232] [client 3.109.4.218:43998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4RobwiU-Jh5ncAILFbXQAAAWM"]
[Mon Jul 20 06:16:33.694514 2026] [security2:error] [pid 871012:tid 871236] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/js/"] [unique_id "al4RobwiU-Jh5ncAILFbYgAAAWc"]
[Mon Jul 20 06:16:33.924468 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RobwiU-Jh5ncAILFbeQAAAVU"]
[Mon Jul 20 06:16:34.001193 2026] [security2:error] [pid 871012:tid 871185] [client 185.132.186.96:48719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/gecko-old.php"] [unique_id "al4RorwiU-Jh5ncAILFbfgAAATQ"]
[Mon Jul 20 06:16:34.024334 2026] [security2:error] [pid 871012:tid 871235] [client 14.225.17.146:64202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFawgAAAWY"], referer: http://floorsourcestock.com/WordPress
[Mon Jul 20 06:16:34.082473 2026] [security2:error] [pid 871012:tid 871229] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/php-compat/"] [unique_id "al4RorwiU-Jh5ncAILFbggAAAWA"]
[Mon Jul 20 06:16:34.196708 2026] [autoindex:error] [pid 871012:tid 871197] [client 213.35.113.47:0] AH01276: Cannot serve directory /home3/ancestx0/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:16:34.206355 2026] [security2:error] [pid 871012:tid 871196] [client 77.110.127.138:59041] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/baking/feed/"] [unique_id "al4RorwiU-Jh5ncAILFbjQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:34.268193 2026] [security2:error] [pid 871012:tid 871192] [client 14.225.17.146:50625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4RorwiU-Jh5ncAILFbfwAAATs"], referer: http://hilltopnurseryinc.com/WordPress
[Mon Jul 20 06:16:34.337415 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RorwiU-Jh5ncAILFbmwAAARA"]
[Mon Jul 20 06:16:34.484248 2026] [security2:error] [pid 871012:tid 871181] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/PHPMailer/"] [unique_id "al4RorwiU-Jh5ncAILFbswAAATA"]
[Mon Jul 20 06:16:34.557998 2026] [security2:error] [pid 871012:tid 871182] [client 136.108.4.202:46970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "ivetstrategies.com"] [uri "/wp-json/batch/v1"] [unique_id "al4RorwiU-Jh5ncAILFbtgAAATE"]
[Mon Jul 20 06:16:34.617733 2026] [security2:error] [pid 871012:tid 871233] [client 136.108.4.202:46970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ivetstrategies.com"] [uri "/"] [unique_id "al4RorwiU-Jh5ncAILFbvQAAAWQ"]
[Mon Jul 20 06:16:34.667686 2026] [security2:error] [pid 871012:tid 871156] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RorwiU-Jh5ncAILFbvwAAARc"]
[Mon Jul 20 06:16:34.719952 2026] [security2:error] [pid 871012:tid 871261] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RorwiU-Jh5ncAILFbuwABgEw"]
[Mon Jul 20 06:16:34.807046 2026] [security2:error] [pid 871012:tid 871149] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/pomo/"] [unique_id "al4RorwiU-Jh5ncAILFbygAAARA"]
[Mon Jul 20 06:16:34.807115 2026] [security2:error] [pid 871012:tid 871250] [client 50.116.65.227:54436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RorwiU-Jh5ncAILFbywAAAXU"]
[Mon Jul 20 06:16:34.816834 2026] [security2:error] [pid 871012:tid 871266] [client 50.116.65.227:40202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4RorwiU-Jh5ncAILFbzgAAAYU"]
[Mon Jul 20 06:16:34.873671 2026] [security2:error] [pid 871012:tid 871230] [client 14.225.17.146:51132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4RoLwiU-Jh5ncAILFbEAAAAWE"], referer: http://securingmemories.com/WordPress
[Mon Jul 20 06:16:35.023712 2026] [security2:error] [pid 871012:tid 871158] [client 171.60.139.123:61697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb4wAAARk"]
[Mon Jul 20 06:16:35.023943 2026] [security2:error] [pid 871012:tid 871158] [client 171.60.139.123:61697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb4wAAARk"]
[Mon Jul 20 06:16:35.028575 2026] [security2:error] [pid 871012:tid 871225] [client 41.173.37.102:1741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb5AAAAVw"]
[Mon Jul 20 06:16:35.028684 2026] [security2:error] [pid 871012:tid 871225] [client 41.173.37.102:1741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb5AAAAVw"]
[Mon Jul 20 06:16:35.034883 2026] [security2:error] [pid 871012:tid 871205] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RorwiU-Jh5ncAILFb4QAAAUg"]
[Mon Jul 20 06:16:35.205215 2026] [security2:error] [pid 871012:tid 871181] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/random_compat/"] [unique_id "al4Ro7wiU-Jh5ncAILFb-gAAATA"]
[Mon Jul 20 06:16:35.285335 2026] [security2:error] [pid 871012:tid 871207] [client 213.35.113.47:54617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.113.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ancestralidadytrance.space"] [uri "/wp-login.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb_AAAAUo"]
[Mon Jul 20 06:16:35.416167 2026] [security2:error] [pid 871012:tid 871184] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ro7wiU-Jh5ncAILFcDQAAATM"]
[Mon Jul 20 06:16:35.437160 2026] [security2:error] [pid 871012:tid 871249] [client 23.94.28.190:63585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mezzacraft.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "al4Ro7wiU-Jh5ncAILFcEAAAAXQ"]
[Mon Jul 20 06:16:35.485553 2026] [security2:error] [pid 871012:tid 871203] [client 136.108.4.202:46970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4RorwiU-Jh5ncAILFb3QAAAUY"], referer: http://ivetstrategies.com/wp-json/batch/v1
[Mon Jul 20 06:16:35.584107 2026] [security2:error] [pid 871012:tid 871266] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/rest-api/"] [unique_id "al4Ro7wiU-Jh5ncAILFcOAAAAYU"]
[Mon Jul 20 06:16:35.586402 2026] [security2:error] [pid 871012:tid 871220] [client 57.141.18.70:27000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RnbwiU-Jh5ncAILFZYgABVyE"]
[Mon Jul 20 06:16:35.694969 2026] [security2:error] [pid 871012:tid 871206] [client 57.141.18.59:46250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RnbwiU-Jh5ncAILFZZgABSSs"]
[Mon Jul 20 06:16:35.772411 2026] [security2:error] [pid 871012:tid 871226] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Ro7wiU-Jh5ncAILFcRAAAAV0"]
[Mon Jul 20 06:16:35.913011 2026] [security2:error] [pid 871012:tid 871259] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/sitemaps/"] [unique_id "al4Ro7wiU-Jh5ncAILFcWQAAAX4"]
[Mon Jul 20 06:16:36.065612 2026] [security2:error] [pid 871012:tid 871191] [client 14.225.17.146:50242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb8gAAATo"], referer: http://walkingandtalking.net/WordPress
[Mon Jul 20 06:16:36.130353 2026] [security2:error] [pid 871012:tid 871161] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpLwiU-Jh5ncAILFcZwAAARw"]
[Mon Jul 20 06:16:36.280408 2026] [security2:error] [pid 871012:tid 871197] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4RpLwiU-Jh5ncAILFceQAAAUA"]
[Mon Jul 20 06:16:36.444423 2026] [security2:error] [pid 871012:tid 871257] [client 45.116.69.230:52866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFcjQAAAXw"]
[Mon Jul 20 06:16:36.444539 2026] [security2:error] [pid 871012:tid 871257] [client 45.116.69.230:52866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFcjQAAAXw"]
[Mon Jul 20 06:16:36.462006 2026] [security2:error] [pid 871012:tid 871119] [remote 156.59.198.135:59556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/wp-content/uploads/2025/09/Aosta-Drinks-Menu.pdf"] [unique_id "al4RpLwiU-Jh5ncAILFckQABFmk"]
[Mon Jul 20 06:16:36.463365 2026] [security2:error] [pid 871012:tid 871175] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpLwiU-Jh5ncAILFciQAAASo"]
[Mon Jul 20 06:16:36.474255 2026] [security2:error] [pid 871012:tid 871217] [client 103.141.108.143:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFckAAAAVQ"]
[Mon Jul 20 06:16:36.474451 2026] [security2:error] [pid 871012:tid 871217] [client 103.141.108.143:55224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RpLwiU-Jh5ncAILFckAAAAVQ"]
[Mon Jul 20 06:16:36.603606 2026] [security2:error] [pid 871012:tid 871240] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/style-engine/"] [unique_id "al4RpLwiU-Jh5ncAILFcngAAAWs"]
[Mon Jul 20 06:16:36.785469 2026] [security2:error] [pid 871012:tid 871160] [client 14.225.17.146:50179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Ro7wiU-Jh5ncAILFb9gAAARs"], referer: http://lelandumc.org/WordPress
[Mon Jul 20 06:16:36.823656 2026] [security2:error] [pid 871012:tid 871223] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpLwiU-Jh5ncAILFcuwAAAVo"]
[Mon Jul 20 06:16:36.832284 2026] [security2:error] [pid 871012:tid 871161] [client 50.116.65.227:54448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4RpLwiU-Jh5ncAILFcwwAAARw"]
[Mon Jul 20 06:16:36.848701 2026] [security2:error] [pid 871012:tid 871236] [client 50.116.65.227:40284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4RpLwiU-Jh5ncAILFcxAAAAWc"]
[Mon Jul 20 06:16:36.913992 2026] [security2:error] [pid 871012:tid 871151] [client 119.18.1.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4RpLwiU-Jh5ncAILFcmQAAARI"], referer: https://aosta.nz/
[Mon Jul 20 06:16:36.937193 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:50278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4Ro7wiU-Jh5ncAILFcEgAAAWk"], referer: http://omrobuildingcenter.com/WordPress
[Mon Jul 20 06:16:36.978773 2026] [http2:info] [pid 874439:tid 874439] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:16:36.981170 2026] [security2:error] [pid 871012:tid 871170] [client 14.225.17.146:55694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4RpLwiU-Jh5ncAILFczwAAASU"], referer: https://walkingandtalking.net/WordPress
[Mon Jul 20 06:16:37.000206 2026] [security2:error] [pid 871012:tid 871153] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/theme-compat/"] [unique_id "al4RpLwiU-Jh5ncAILFc0gAAARQ"]
[Mon Jul 20 06:16:37.099363 2026] [security2:error] [pid 871012:tid 871052] [remote 216.73.216.55:26430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4RpbwiU-Jh5ncAILFc3AABKCY"]
[Mon Jul 20 06:16:37.227207 2026] [security2:error] [pid 871012:tid 871164] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpbwiU-Jh5ncAILFc5AAAAR8"]
[Mon Jul 20 06:16:37.391895 2026] [security2:error] [pid 871012:tid 871168] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-includes/widgets/"] [unique_id "al4RpbwiU-Jh5ncAILFc7QAAASM"]
[Mon Jul 20 06:16:37.476925 2026] [security2:error] [pid 871012:tid 871147] [client 57.141.18.118:63280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RnrwiU-Jh5ncAILFaHgABDmo"]
[Mon Jul 20 06:16:37.497859 2026] [security2:error] [pid 871012:tid 871087] [remote 115.74.105.156:38772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RpbwiU-Jh5ncAILFc8QABhkk"]
[Mon Jul 20 06:16:37.552571 2026] [security2:error] [pid 874439:tid 874441] [remote 8.217.108.67:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RpY6ZSrFvCrJJhtT5pwAAAQE"]
[Mon Jul 20 06:16:37.627340 2026] [security2:error] [pid 871012:tid 871188] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpbwiU-Jh5ncAILFc-QAAATc"]
[Mon Jul 20 06:16:37.787224 2026] [security2:error] [pid 871012:tid 871161] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "al4RpbwiU-Jh5ncAILFdAgAAARw"]
[Mon Jul 20 06:16:38.032586 2026] [security2:error] [pid 871012:tid 871159] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RpbwiU-Jh5ncAILFdDAAAARo"]
[Mon Jul 20 06:16:38.038868 2026] [security2:error] [pid 871012:tid 871121] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RprwiU-Jh5ncAILFdDgABSWs"]
[Mon Jul 20 06:16:38.039090 2026] [security2:error] [pid 871012:tid 871206] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RprwiU-Jh5ncAILFdDgABSWs"]
[Mon Jul 20 06:16:38.184445 2026] [security2:error] [pid 871012:tid 871186] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/css/colors/"] [unique_id "al4RprwiU-Jh5ncAILFdGAAAATU"]
[Mon Jul 20 06:16:38.231140 2026] [security2:error] [pid 871012:tid 871225] [client 14.225.17.146:50671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4RpLwiU-Jh5ncAILFcpQAAAVw"], referer: http://kromosenergy.com/WordPress
[Mon Jul 20 06:16:38.388306 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RprwiU-Jh5ncAILFdIAAAAXQ"]
[Mon Jul 20 06:16:38.474102 2026] [security2:error] [pid 871012:tid 871150] [client 14.225.17.146:55888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4RpbwiU-Jh5ncAILFc4wAAARE"], referer: http://elitetax-mi.com/WordPress
[Mon Jul 20 06:16:38.528849 2026] [security2:error] [pid 871012:tid 871266] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/images/slider/"] [unique_id "al4RprwiU-Jh5ncAILFdLAAAAYU"]
[Mon Jul 20 06:16:38.553636 2026] [security2:error] [pid 874439:tid 874446] [remote 8.217.108.67:29322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Rpo6ZSrFvCrJJhtT50QAAXQY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:16:38.566842 2026] [security2:error] [pid 871012:tid 871259] [client 103.217.239.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4RpbwiU-Jh5ncAILFc2AAAAX4"]
[Mon Jul 20 06:16:38.580459 2026] [security2:error] [pid 871012:tid 871178] [client 103.217.239.26:49680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/22518.php"] [unique_id "al4RpbwiU-Jh5ncAILFc0wABLRA"]
[Mon Jul 20 06:16:38.623861 2026] [security2:error] [pid 874439:tid 874652] [client 178.152.178.232:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rpo6ZSrFvCrJJhtT50gAAAFM"]
[Mon Jul 20 06:16:38.623978 2026] [security2:error] [pid 874439:tid 874652] [client 178.152.178.232:37856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rpo6ZSrFvCrJJhtT50gAAAFM"]
[Mon Jul 20 06:16:38.711282 2026] [security2:error] [pid 871012:tid 871228] [client 57.141.18.67:25620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rn7wiU-Jh5ncAILFasgABXzs"]
[Mon Jul 20 06:16:38.741428 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RprwiU-Jh5ncAILFdMwAAAUs"]
[Mon Jul 20 06:16:38.881002 2026] [security2:error] [pid 871012:tid 871164] [client 104.234.53.80:28225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RprwiU-Jh5ncAILFdPQAAAR8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:38.887313 2026] [security2:error] [pid 871012:tid 871238] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "al4RprwiU-Jh5ncAILFdPgAAAWk"]
[Mon Jul 20 06:16:39.129379 2026] [security2:error] [pid 871012:tid 871267] [client 85.204.70.92:38090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rp7wiU-Jh5ncAILFdRgAAAYY"]
[Mon Jul 20 06:16:39.131057 2026] [security2:error] [pid 874439:tid 874689] [client 77.110.127.138:59061] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/baking/feed/"] [unique_id "al4Rp46ZSrFvCrJJhtT54AAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:39.316054 2026] [security2:error] [pid 871012:tid 871201] [client 185.132.186.90:47115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/wp-login.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUAAAAUQ"]
[Mon Jul 20 06:16:39.392514 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:65150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUwAAAYI"]
[Mon Jul 20 06:16:39.392801 2026] [security2:error] [pid 871012:tid 871263] [client 103.77.203.233:65150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUwAAAYI"]
[Mon Jul 20 06:16:39.596544 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/sites/default/files/"] [unique_id "al4Rp7wiU-Jh5ncAILFdZQAAARk"]
[Mon Jul 20 06:16:39.706389 2026] [security2:error] [pid 871012:tid 871176] [client 14.251.3.155:61271] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Rp7wiU-Jh5ncAILFdcgAAASs"]
[Mon Jul 20 06:16:39.813770 2026] [security2:error] [pid 871012:tid 871261] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rp7wiU-Jh5ncAILFddQAAAYA"]
[Mon Jul 20 06:16:39.835289 2026] [security2:error] [pid 871012:tid 871084] [remote 38.242.157.30:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdeQABLkY"]
[Mon Jul 20 06:16:39.835442 2026] [security2:error] [pid 871012:tid 871179] [client 38.242.157.30:37278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdeQABLkY"]
[Mon Jul 20 06:16:39.975027 2026] [security2:error] [pid 871012:tid 871269] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/controller/extension/extension/"] [unique_id "al4Rp7wiU-Jh5ncAILFdfQAAAYg"]
[Mon Jul 20 06:16:40.153323 2026] [security2:error] [pid 871012:tid 871203] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqLwiU-Jh5ncAILFdhAAAAUY"]
[Mon Jul 20 06:16:40.174566 2026] [security2:error] [pid 871012:tid 871255] [client 57.141.18.91:48926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RobwiU-Jh5ncAILFbOgABemw"]
[Mon Jul 20 06:16:40.293930 2026] [security2:error] [pid 871012:tid 871158] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "al4RqLwiU-Jh5ncAILFdkAAAARk"]
[Mon Jul 20 06:16:40.462024 2026] [security2:error] [pid 874439:tid 874607] [client 104.234.53.61:42967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4RqI6ZSrFvCrJJhtT5-AAAACY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:40.522426 2026] [security2:error] [pid 871012:tid 871239] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqLwiU-Jh5ncAILFdnAAAAWo"]
[Mon Jul 20 06:16:40.563604 2026] [security2:error] [pid 871012:tid 871270] [client 57.141.18.35:31616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RobwiU-Jh5ncAILFbXAABiQk"]
[Mon Jul 20 06:16:40.689002 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/components/"] [unique_id "al4RqLwiU-Jh5ncAILFdrgAAAVU"]
[Mon Jul 20 06:16:40.692620 2026] [security2:error] [pid 874439:tid 874642] [client 104.234.53.61:42967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RqI6ZSrFvCrJJhtT6AgAAAEk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:40.923333 2026] [security2:error] [pid 871012:tid 871144] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqLwiU-Jh5ncAILFduAAAAQs"]
[Mon Jul 20 06:16:41.092823 2026] [security2:error] [pid 871012:tid 871193] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/admin/uploads/images/"] [unique_id "al4RqbwiU-Jh5ncAILFdwAAAATw"]
[Mon Jul 20 06:16:41.190640 2026] [security2:error] [pid 874439:tid 874667] [client 74.208.214.194:52840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6DwAAAGI"]
[Mon Jul 20 06:16:41.314254 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqbwiU-Jh5ncAILFdzgAAAT8"]
[Mon Jul 20 06:16:41.320999 2026] [security2:error] [pid 874439:tid 874688] [client 185.132.186.75:28435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/autoload_classmap.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6GAAAAHc"]
[Mon Jul 20 06:16:41.408881 2026] [security2:error] [pid 874439:tid 874646] [client 181.224.94.124:61626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6GgAAAE0"]
[Mon Jul 20 06:16:41.409055 2026] [security2:error] [pid 874439:tid 874646] [client 181.224.94.124:61626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RqY6ZSrFvCrJJhtT6GgAAAE0"]
[Mon Jul 20 06:16:41.460090 2026] [security2:error] [pid 871012:tid 871215] [client 57.141.18.92:53102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RorwiU-Jh5ncAILFbtAABUgw"]
[Mon Jul 20 06:16:41.484464 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "al4RqbwiU-Jh5ncAILFd1gAAAXQ"]
[Mon Jul 20 06:16:41.706162 2026] [ssl:error] [pid 871012:tid 871192] [client 54.86.115.253:1955] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname webdisk.ithurtsuntilyoudie.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:16:41.711265 2026] [security2:error] [pid 871012:tid 871259] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqbwiU-Jh5ncAILFd4AAAAX4"]
[Mon Jul 20 06:16:41.889731 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/fonts/"] [unique_id "al4RqbwiU-Jh5ncAILFd7gAAAUk"]
[Mon Jul 20 06:16:41.925485 2026] [security2:error] [pid 871012:tid 871085] [remote 115.74.105.156:38772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RqbwiU-Jh5ncAILFd8wABZEc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:16:42.050450 2026] [security2:error] [pid 874439:tid 874464] [remote 20.173.88.122:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6MQAAGRg"]
[Mon Jul 20 06:16:42.077394 2026] [security2:error] [pid 871012:tid 871179] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqrwiU-Jh5ncAILFd-QAAAS4"]
[Mon Jul 20 06:16:42.219948 2026] [security2:error] [pid 871012:tid 871208] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "al4RqrwiU-Jh5ncAILFeBwAAAUs"]
[Mon Jul 20 06:16:42.401358 2026] [security2:error] [pid 874439:tid 874468] [remote 20.173.88.122:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6PQAAOBw"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 06:16:42.439432 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqrwiU-Jh5ncAILFeEAAAAR4"]
[Mon Jul 20 06:16:42.537727 2026] [security2:error] [pid 874439:tid 874642] [client 63.176.132.15:12890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6QwAAAEk"]
[Mon Jul 20 06:16:42.537886 2026] [security2:error] [pid 874439:tid 874642] [client 63.176.132.15:12890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6QwAAAEk"]
[Mon Jul 20 06:16:42.581619 2026] [security2:error] [pid 871012:tid 871229] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "al4RqrwiU-Jh5ncAILFeGgAAAWA"]
[Mon Jul 20 06:16:42.654048 2026] [security2:error] [pid 871012:tid 871212] [client 50.116.65.227:28062] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4RqrwiU-Jh5ncAILFeJAAAAU8"]
[Mon Jul 20 06:16:42.664815 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:46752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4RqrwiU-Jh5ncAILFeJgAAAS0"]
[Mon Jul 20 06:16:42.671067 2026] [security2:error] [pid 871012:tid 871202] [client 190.44.20.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4RqrwiU-Jh5ncAILFeEwAAAUU"]
[Mon Jul 20 06:16:42.679441 2026] [security2:error] [pid 874439:tid 874640] [client 190.44.20.234:36140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/22518.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6QgAARx0"]
[Mon Jul 20 06:16:42.763484 2026] [security2:error] [pid 871012:tid 871159] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RqrwiU-Jh5ncAILFeKgAAARo"]
[Mon Jul 20 06:16:42.912035 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wordpress/"] [unique_id "al4RqrwiU-Jh5ncAILFeNQAAAT8"]
[Mon Jul 20 06:16:43.130327 2026] [security2:error] [pid 871012:tid 871150] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rq7wiU-Jh5ncAILFeOAAAARE"]
[Mon Jul 20 06:16:43.290003 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/images/"] [unique_id "al4Rq7wiU-Jh5ncAILFeRAAAAWE"]
[Mon Jul 20 06:16:43.338967 2026] [security2:error] [pid 874439:tid 874690] [client 185.132.186.84:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-nav-widgets.php"] [unique_id "al4Rq46ZSrFvCrJJhtT6WAAAAHk"]
[Mon Jul 20 06:16:43.517097 2026] [security2:error] [pid 871012:tid 871256] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rq7wiU-Jh5ncAILFeTQAAAXs"]
[Mon Jul 20 06:16:43.682441 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "al4Rq7wiU-Jh5ncAILFeWgAAATI"]
[Mon Jul 20 06:16:43.920354 2026] [security2:error] [pid 871012:tid 871263] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rq7wiU-Jh5ncAILFeYgAAAYI"]
[Mon Jul 20 06:16:44.085895 2026] [security2:error] [pid 871012:tid 871249] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "al4RrLwiU-Jh5ncAILFeaAAAAXQ"]
[Mon Jul 20 06:16:44.157840 2026] [security2:error] [pid 874439:tid 874481] [remote 217.61.143.92:40114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RrI6ZSrFvCrJJhtT6cgAAVyk"]
[Mon Jul 20 06:16:44.158099 2026] [security2:error] [pid 874439:tid 874656] [client 217.61.143.92:40114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RrI6ZSrFvCrJJhtT6cgAAVyk"]
[Mon Jul 20 06:16:44.269380 2026] [security2:error] [pid 871012:tid 871162] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrLwiU-Jh5ncAILFecAAAAR0"]
[Mon Jul 20 06:16:44.399245 2026] [security2:error] [pid 874439:tid 874582] [client 57.141.18.61:43238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RpY6ZSrFvCrJJhtT5pgAADX8"]
[Mon Jul 20 06:16:44.409262 2026] [security2:error] [pid 871012:tid 871222] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/js/"] [unique_id "al4RrLwiU-Jh5ncAILFeegAAAVk"]
[Mon Jul 20 06:16:44.553368 2026] [security2:error] [pid 874439:tid 874687] [client 45.61.188.240:57953] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/"] [unique_id "al4RrI6ZSrFvCrJJhtT6gQAAAHY"]
[Mon Jul 20 06:16:44.623429 2026] [security2:error] [pid 871012:tid 871239] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrLwiU-Jh5ncAILFefwAAAWo"]
[Mon Jul 20 06:16:44.672981 2026] [security2:error] [pid 871012:tid 871198] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RrLwiU-Jh5ncAILFeeAABQVU"]
[Mon Jul 20 06:16:44.775207 2026] [security2:error] [pid 871012:tid 871168] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "al4RrLwiU-Jh5ncAILFehgAAASM"]
[Mon Jul 20 06:16:44.817254 2026] [security2:error] [pid 874439:tid 874638] [client 45.61.188.240:57991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/"] [unique_id "al4RrI6ZSrFvCrJJhtT6jwAAAEU"]
[Mon Jul 20 06:16:44.954430 2026] [security2:error] [pid 871012:tid 871265] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrLwiU-Jh5ncAILFekAAAAYQ"]
[Mon Jul 20 06:16:45.093457 2026] [security2:error] [pid 871012:tid 871218] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "al4RrbwiU-Jh5ncAILFelAAAAVU"]
[Mon Jul 20 06:16:45.313332 2026] [security2:error] [pid 871012:tid 871166] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrbwiU-Jh5ncAILFemgAAASE"]
[Mon Jul 20 06:16:45.351373 2026] [security2:error] [pid 871012:tid 871179] [client 185.132.186.101:64849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "al4RrbwiU-Jh5ncAILFenwAAAS4"]
[Mon Jul 20 06:16:45.385705 2026] [security2:error] [pid 874439:tid 874489] [remote 47.128.28.81:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "innovativecleaningsvs.com"] [uri "/robots.txt"] [unique_id "al4RrY6ZSrFvCrJJhtT6pQAASzE"]
[Mon Jul 20 06:16:45.446718 2026] [security2:error] [pid 874439:tid 874490] [remote 100.42.189.89:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6qAAAYjI"]
[Mon Jul 20 06:16:45.460150 2026] [security2:error] [pid 871012:tid 871208] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RrbwiU-Jh5ncAILFemQABS3o"]
[Mon Jul 20 06:16:45.483840 2026] [security2:error] [pid 871012:tid 871195] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/meta/"] [unique_id "al4RrbwiU-Jh5ncAILFeqAAAAT4"]
[Mon Jul 20 06:16:45.601936 2026] [security2:error] [pid 871012:tid 871152] [client 188.232.28.208:36424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4RrbwiU-Jh5ncAILFeqQAAARM"]
[Mon Jul 20 06:16:45.618093 2026] [security2:error] [pid 871012:tid 871068] [remote 154.66.198.148:18512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4RrbwiU-Jh5ncAILFetQABWjY"]
[Mon Jul 20 06:16:45.645717 2026] [security2:error] [pid 874439:tid 874491] [remote 100.42.189.89:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6rwAAGzM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:16:45.667973 2026] [security2:error] [pid 874439:tid 874624] [client 41.173.37.102:2195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6sAAAADc"]
[Mon Jul 20 06:16:45.668115 2026] [security2:error] [pid 874439:tid 874624] [client 41.173.37.102:2195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6sAAAADc"]
[Mon Jul 20 06:16:45.731240 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrbwiU-Jh5ncAILFeugAAAT8"]
[Mon Jul 20 06:16:45.850588 2026] [security2:error] [pid 874439:tid 874688] [client 170.0.244.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6uwAAAHc"]
[Mon Jul 20 06:16:45.894361 2026] [security2:error] [pid 871012:tid 871185] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/network/"] [unique_id "al4RrbwiU-Jh5ncAILFewAAAATQ"]
[Mon Jul 20 06:16:45.910848 2026] [security2:error] [pid 874439:tid 874594] [client 171.60.139.123:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6wwAAABk"]
[Mon Jul 20 06:16:45.911041 2026] [security2:error] [pid 874439:tid 874594] [client 171.60.139.123:62201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RrY6ZSrFvCrJJhtT6wwAAABk"]
[Mon Jul 20 06:16:45.962325 2026] [security2:error] [pid 871012:tid 871151] [client 57.141.18.32:25640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rp7wiU-Jh5ncAILFdUQABEjQ"]
[Mon Jul 20 06:16:46.116137 2026] [security2:error] [pid 871012:tid 871194] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrrwiU-Jh5ncAILFexgAAAT0"]
[Mon Jul 20 06:16:46.261684 2026] [security2:error] [pid 871012:tid 871033] [remote 154.66.198.148:18512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4RrrwiU-Jh5ncAILFe1wABhxM"], referer: https://sbinframx.com/wp-login.php
[Mon Jul 20 06:16:46.276022 2026] [security2:error] [pid 871012:tid 871166] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/user/"] [unique_id "al4RrrwiU-Jh5ncAILFe2AAAASE"]
[Mon Jul 20 06:16:46.466351 2026] [security2:error] [pid 871012:tid 871230] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrrwiU-Jh5ncAILFe4QAAAWE"]
[Mon Jul 20 06:16:46.605205 2026] [security2:error] [pid 871012:tid 871152] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/"] [unique_id "al4RrrwiU-Jh5ncAILFe5wAAARM"]
[Mon Jul 20 06:16:46.657391 2026] [security2:error] [pid 874439:tid 874597] [client 57.141.18.99:27224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rp46ZSrFvCrJJhtT57wAAHAk"]
[Mon Jul 20 06:16:46.822297 2026] [security2:error] [pid 871012:tid 871196] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RrrwiU-Jh5ncAILFe8QAAAT8"]
[Mon Jul 20 06:16:46.856413 2026] [security2:error] [pid 874439:tid 874620] [client 104.234.53.72:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Rro6ZSrFvCrJJhtT64QAAADM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:46.987346 2026] [security2:error] [pid 871012:tid 871156] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/plugins/"] [unique_id "al4RrrwiU-Jh5ncAILFe-wAAARc"]
[Mon Jul 20 06:16:47.210365 2026] [security2:error] [pid 871012:tid 871206] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rr7wiU-Jh5ncAILFfAAAAAUk"]
[Mon Jul 20 06:16:47.229830 2026] [security2:error] [pid 871012:tid 871183] [client 103.141.108.143:55713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfAwAAATI"]
[Mon Jul 20 06:16:47.230095 2026] [security2:error] [pid 871012:tid 871183] [client 103.141.108.143:55713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfAwAAATI"]
[Mon Jul 20 06:16:47.253005 2026] [security2:error] [pid 871012:tid 871233] [client 45.116.69.230:53400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfBAAAAWQ"]
[Mon Jul 20 06:16:47.253175 2026] [security2:error] [pid 871012:tid 871233] [client 45.116.69.230:53400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfBAAAAWQ"]
[Mon Jul 20 06:16:47.349385 2026] [security2:error] [pid 874439:tid 874506] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4Rr46ZSrFvCrJJhtT69AAAe0I"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:47.353437 2026] [security2:error] [pid 874439:tid 874595] [client 185.132.186.98:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/install.php"] [unique_id "al4Rr46ZSrFvCrJJhtT69wAAABo"]
[Mon Jul 20 06:16:47.396429 2026] [security2:error] [pid 871012:tid 871201] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/themes/"] [unique_id "al4Rr7wiU-Jh5ncAILFfDAAAAUQ"]
[Mon Jul 20 06:16:47.401549 2026] [security2:error] [pid 874439:tid 874649] [client 57.141.18.96:44592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RqI6ZSrFvCrJJhtT6BQAAUA8"]
[Mon Jul 20 06:16:47.571936 2026] [security2:error] [pid 871012:tid 871097] [remote 20.153.140.50:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfGgABaVM"]
[Mon Jul 20 06:16:47.641433 2026] [security2:error] [pid 871012:tid 871267] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rr7wiU-Jh5ncAILFfGwAAAYY"]
[Mon Jul 20 06:16:47.678418 2026] [security2:error] [pid 874439:tid 874601] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rr46ZSrFvCrJJhtT6_wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:47.778619 2026] [security2:error] [pid 871012:tid 871175] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfDgABKhU"]
[Mon Jul 20 06:16:47.792210 2026] [security2:error] [pid 871012:tid 871163] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/includes/"] [unique_id "al4Rr7wiU-Jh5ncAILFfHwAAAR4"]
[Mon Jul 20 06:16:47.969501 2026] [security2:error] [pid 871012:tid 871088] [remote 20.153.140.50:37540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4Rr7wiU-Jh5ncAILFfLQABF0o"], referer: https://detroitcsc.com/wp-login.php
[Mon Jul 20 06:16:48.046343 2026] [security2:error] [pid 871012:tid 871151] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4Rr7wiU-Jh5ncAILFfLgAAARI"]
[Mon Jul 20 06:16:48.204066 2026] [security2:error] [pid 871012:tid 871183] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-admin/"] [unique_id "al4RsLwiU-Jh5ncAILFfNwAAATI"]
[Mon Jul 20 06:16:48.425417 2026] [security2:error] [pid 871012:tid 871263] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RsLwiU-Jh5ncAILFfOQAAAYI"]
[Mon Jul 20 06:16:48.571573 2026] [security2:error] [pid 871012:tid 871149] [client 57.141.18.21:40508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RqbwiU-Jh5ncAILFd6QABEGo"]
[Mon Jul 20 06:16:48.576468 2026] [security2:error] [pid 871012:tid 871180] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "tscript.co.uk"] [uri "/wp-content/upgrade/"] [unique_id "al4RsLwiU-Jh5ncAILFfRQAAAS8"]
[Mon Jul 20 06:16:48.749445 2026] [security2:error] [pid 874439:tid 874517] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7MAAAW00"]
[Mon Jul 20 06:16:48.749689 2026] [security2:error] [pid 874439:tid 874660] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7MAAAW00"]
[Mon Jul 20 06:16:48.760631 2026] [security2:error] [pid 871012:tid 871261] [client 85.204.70.92:43350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tscript.co.uk"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4RsLwiU-Jh5ncAILFfTQAAAYA"]
[Mon Jul 20 06:16:48.785772 2026] [security2:error] [pid 874439:tid 874518] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7MgAAAE4"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:48.875590 2026] [security2:error] [pid 874439:tid 874622] [client 57.141.18.103:51976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rqo6ZSrFvCrJJhtT6NwAANRk"]
[Mon Jul 20 06:16:49.032356 2026] [security2:error] [pid 871012:tid 871244] [client 104.234.53.75:50117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4RsbwiU-Jh5ncAILFfVwAAAW8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:49.138584 2026] [security2:error] [pid 874439:tid 874522] [remote 160.187.68.132:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4RsY6ZSrFvCrJJhtT7QAAAMlI"]
[Mon Jul 20 06:16:49.364904 2026] [security2:error] [pid 871012:tid 871187] [client 185.132.186.101:44963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/install.php"] [unique_id "al4RsbwiU-Jh5ncAILFfYwAAATY"]
[Mon Jul 20 06:16:49.643181 2026] [security2:error] [pid 874439:tid 874525] [remote 160.187.68.132:56486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4RsY6ZSrFvCrJJhtT7UAAASVU"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:16:49.794052 2026] [security2:error] [pid 871012:tid 871249] [client 50.116.65.227:50348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4RsbwiU-Jh5ncAILFfgQAAAXQ"]
[Mon Jul 20 06:16:49.796113 2026] [security2:error] [pid 874439:tid 874528] [remote 217.61.143.92:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RsY6ZSrFvCrJJhtT7VQAAB1g"]
[Mon Jul 20 06:16:49.804022 2026] [security2:error] [pid 874439:tid 874639] [client 50.116.65.227:19118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4RsY6ZSrFvCrJJhtT7VwAAAEY"]
[Mon Jul 20 06:16:49.842649 2026] [security2:error] [pid 871012:tid 871186] [client 103.77.203.233:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RsbwiU-Jh5ncAILFfggAAATU"]
[Mon Jul 20 06:16:49.842786 2026] [security2:error] [pid 871012:tid 871186] [client 103.77.203.233:49324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RsbwiU-Jh5ncAILFfggAAATU"]
[Mon Jul 20 06:16:50.041696 2026] [security2:error] [pid 874439:tid 874533] [remote 217.61.143.92:45262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Rso6ZSrFvCrJJhtT7awAAGF0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:50.229457 2026] [security2:error] [pid 874439:tid 874534] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4Rso6ZSrFvCrJJhtT7cQAAZl4"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:50.253482 2026] [security2:error] [pid 874439:tid 874569] [client 104.234.53.81:65047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Rso6ZSrFvCrJJhtT7cgAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:50.434905 2026] [security2:error] [pid 871012:tid 871255] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RsrwiU-Jh5ncAILFftAABegA"]
[Mon Jul 20 06:16:50.516640 2026] [security2:error] [pid 874439:tid 874650] [client 57.141.18.15:64806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rq46ZSrFvCrJJhtT6awAAUSc"]
[Mon Jul 20 06:16:51.341709 2026] [security2:error] [pid 874439:tid 874640] [client 185.132.186.73:40681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/providers/doc.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7qAAAAEc"]
[Mon Jul 20 06:16:51.396490 2026] [security2:error] [pid 874439:tid 874549] [remote 100.42.189.89:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7rQAAP20"]
[Mon Jul 20 06:16:51.544886 2026] [security2:error] [pid 874439:tid 874570] [client 57.141.18.112:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RrI6ZSrFvCrJJhtT6hwAAAS0"]
[Mon Jul 20 06:16:51.612795 2026] [security2:error] [pid 874439:tid 874550] [remote 100.42.189.89:40602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7sgAAQ24"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:16:51.676165 2026] [security2:error] [pid 874439:tid 874552] [remote 17.22.237.241:52468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.237.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7tgAACHA"], referer: https://www.savilerowtravel.com/south-africa-holidays/group-132/
[Mon Jul 20 06:16:51.855217 2026] [security2:error] [pid 874439:tid 874553] [remote 195.26.244.42:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7uQAANnE"]
[Mon Jul 20 06:16:51.926460 2026] [security2:error] [pid 874439:tid 874580] [client 181.224.94.124:34638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7vAAAAAs"]
[Mon Jul 20 06:16:51.926650 2026] [security2:error] [pid 874439:tid 874580] [client 181.224.94.124:34638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4Rs46ZSrFvCrJJhtT7vAAAAAs"]
[Mon Jul 20 06:16:52.095795 2026] [security2:error] [pid 874439:tid 874556] [remote 72.167.132.114:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7xQAAZ3Q"]
[Mon Jul 20 06:16:52.145271 2026] [security2:error] [pid 874439:tid 874558] [remote 195.26.244.42:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7yAAAIHY"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 06:16:52.207076 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7zgAAADk"]
[Mon Jul 20 06:16:52.207256 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:37386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RtI6ZSrFvCrJJhtT7zgAAADk"]
[Mon Jul 20 06:16:52.340629 2026] [security2:error] [pid 874439:tid 874561] [remote 72.167.132.114:39302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4RtI6ZSrFvCrJJhtT70wAALHk"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 06:16:52.905981 2026] [security2:error] [pid 871012:tid 871257] [client 104.234.53.51:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RtLwiU-Jh5ncAILFgGQAAAXw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:53.168196 2026] [security2:error] [pid 874439:tid 874625] [client 57.141.18.2:39444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rro6ZSrFvCrJJhtT6yQAAODk"]
[Mon Jul 20 06:16:53.287857 2026] [security2:error] [pid 871012:tid 871261] [client 35.245.65.174:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4RtLwiU-Jh5ncAILFgGgABgH8"]
[Mon Jul 20 06:16:53.343396 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.65:58903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ws.php"] [unique_id "al4RtbwiU-Jh5ncAILFgLAAAAXo"]
[Mon Jul 20 06:16:53.360862 2026] [security2:error] [pid 874439:tid 874629] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RtY6ZSrFvCrJJhtT78gAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:53.464225 2026] [security2:error] [pid 871012:tid 871107] [remote 202.51.202.242:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RtbwiU-Jh5ncAILFgLgABHF0"]
[Mon Jul 20 06:16:54.001482 2026] [security2:error] [pid 871012:tid 871084] [remote 202.51.202.242:48900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RtbwiU-Jh5ncAILFgRwABc0Y"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:54.353130 2026] [security2:error] [pid 874439:tid 874594] [client 57.141.18.122:53300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rr46ZSrFvCrJJhtT67QAAGUA"]
[Mon Jul 20 06:16:54.410401 2026] [security2:error] [pid 871012:tid 871171] [client 158.173.166.181:44213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RtrwiU-Jh5ncAILFgXAAAASY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:16:54.517783 2026] [core:error] [pid 871012:tid 871251] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.517809 2026] [core:error] [pid 871012:tid 871251] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.527108 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.527132 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.536210 2026] [core:error] [pid 871012:tid 871160] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:54.536232 2026] [core:error] [pid 871012:tid 871160] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.079952 2026] [core:error] [pid 874439:tid 874644] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.079974 2026] [core:error] [pid 874439:tid 874644] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.135055 2026] [core:error] [pid 871012:tid 871205] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.135079 2026] [core:error] [pid 871012:tid 871205] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:16:55.342870 2026] [security2:error] [pid 874439:tid 874599] [client 57.141.18.118:37706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rr46ZSrFvCrJJhtT7EAAAHkc"]
[Mon Jul 20 06:16:55.351202 2026] [security2:error] [pid 874439:tid 874607] [client 185.132.186.97:42107] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/1.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8ZAAAACY"]
[Mon Jul 20 06:16:55.368978 2026] [security2:error] [pid 871012:tid 871250] [client 104.234.53.80:34649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Rt7wiU-Jh5ncAILFgmAAAAXU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:55.389108 2026] [security2:error] [pid 874439:tid 874607] [client 185.132.186.97:42107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/rest-api/1.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8ZAAAACY"]
[Mon Jul 20 06:16:55.591500 2026] [security2:error] [pid 871012:tid 871090] [remote 154.66.198.148:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Rt7wiU-Jh5ncAILFgoQABKUw"]
[Mon Jul 20 06:16:55.904765 2026] [security2:error] [pid 874439:tid 874604] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8dgAAIxo"]
[Mon Jul 20 06:16:56.210340 2026] [security2:error] [pid 871012:tid 871133] [remote 57.141.18.42:32868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5504138"] [unique_id "al4RuLwiU-Jh5ncAILFgsgABhnc"]
[Mon Jul 20 06:16:56.247948 2026] [security2:error] [pid 874439:tid 874672] [client 41.173.37.102:2633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8iQAAAGc"]
[Mon Jul 20 06:16:56.248056 2026] [security2:error] [pid 874439:tid 874672] [client 41.173.37.102:2633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8iQAAAGc"]
[Mon Jul 20 06:16:56.310449 2026] [security2:error] [pid 871012:tid 871194] [client 104.234.53.80:34649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4RuLwiU-Jh5ncAILFguwAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:56.447968 2026] [security2:error] [pid 871012:tid 871080] [remote 154.66.198.148:32262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RuLwiU-Jh5ncAILFgwgABQkI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:16:56.455357 2026] [security2:error] [pid 874439:tid 874598] [client 171.60.139.123:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8jwAAAB0"]
[Mon Jul 20 06:16:56.455570 2026] [security2:error] [pid 874439:tid 874598] [client 171.60.139.123:62698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RuI6ZSrFvCrJJhtT8jwAAAB0"]
[Mon Jul 20 06:16:56.472573 2026] [security2:error] [pid 871012:tid 871211] [client 14.225.17.146:59093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RuLwiU-Jh5ncAILFguAAAAU4"], referer: http://secretkeynumerology.com/wp
[Mon Jul 20 06:16:56.533460 2026] [security2:error] [pid 874439:tid 874588] [client 14.225.17.146:49397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8UAAAABM"], referer: http://dereckcastellon.com/wp
[Mon Jul 20 06:16:56.600303 2026] [security2:error] [pid 874439:tid 874645] [client 57.141.18.91:52844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RsI6ZSrFvCrJJhtT7OQAATFE"]
[Mon Jul 20 06:16:56.842391 2026] [security2:error] [pid 874439:tid 874690] [client 14.225.17.146:50360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8VAAAAHk"], referer: http://superiorcopywriting.com/wp
[Mon Jul 20 06:16:57.391195 2026] [security2:error] [pid 874439:tid 874625] [client 185.132.186.66:53619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/fonts/class_api.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8sAAAADg"]
[Mon Jul 20 06:16:57.505311 2026] [security2:error] [pid 874439:tid 874648] [client 14.225.17.146:59237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8rQAAAE8"], referer: https://secretkeynumerology.com/wp
[Mon Jul 20 06:16:57.910815 2026] [security2:error] [pid 874439:tid 874645] [client 103.141.108.143:56193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8wwAAAEw"]
[Mon Jul 20 06:16:57.911243 2026] [security2:error] [pid 874439:tid 874645] [client 103.141.108.143:56193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8wwAAAEw"]
[Mon Jul 20 06:16:57.942337 2026] [security2:error] [pid 874439:tid 874677] [client 45.116.69.230:53936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8xAAAAGw"]
[Mon Jul 20 06:16:57.942473 2026] [security2:error] [pid 874439:tid 874677] [client 45.116.69.230:53936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RuY6ZSrFvCrJJhtT8xAAAAGw"]
[Mon Jul 20 06:16:58.164293 2026] [security2:error] [pid 874439:tid 874481] [remote 173.249.4.11:50387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT8zAAAfik"]
[Mon Jul 20 06:16:58.164608 2026] [security2:error] [pid 874439:tid 874695] [client 173.249.4.11:50387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT8zAAAfik"]
[Mon Jul 20 06:16:58.209802 2026] [security2:error] [pid 871012:tid 871226] [client 14.225.17.146:62515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4RuLwiU-Jh5ncAILFgzQAAAV0"], referer: http://myspineworld.com/wp
[Mon Jul 20 06:16:58.232369 2026] [security2:error] [pid 874439:tid 874578] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT8xwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:16:58.232958 2026] [security2:error] [pid 874439:tid 874483] [remote 173.249.4.11:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturalsolutionsurbanforestry.com"] [uri "/wp-login.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT80wAAVCs"]
[Mon Jul 20 06:16:58.429276 2026] [security2:error] [pid 874439:tid 874676] [client 50.116.65.227:19308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Ruo6ZSrFvCrJJhtT82wAAAGs"]
[Mon Jul 20 06:16:58.438921 2026] [security2:error] [pid 874439:tid 874484] [remote 57.141.18.99:23640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5257534"] [unique_id "al4Ruo6ZSrFvCrJJhtT83AAACCw"]
[Mon Jul 20 06:16:58.439963 2026] [security2:error] [pid 874439:tid 874633] [client 50.116.65.227:19312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Ruo6ZSrFvCrJJhtT83QAAAEA"]
[Mon Jul 20 06:16:58.472833 2026] [security2:error] [pid 874439:tid 874486] [remote 173.249.4.11:54814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturalsolutionsurbanforestry.com"] [uri "/wp-login.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT83wAATS4"], referer: https://naturalsolutionsurbanforestry.com/wp-login.php
[Mon Jul 20 06:16:58.763991 2026] [security2:error] [pid 874439:tid 874663] [client 104.234.53.88:22725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT87gAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:58.985464 2026] [security2:error] [pid 874439:tid 874669] [client 50.116.65.227:44308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ruo6ZSrFvCrJJhtT8_AAAAGQ"]
[Mon Jul 20 06:16:58.999502 2026] [security2:error] [pid 874439:tid 874650] [client 50.116.65.227:39420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4Ruo6ZSrFvCrJJhtT8_gAAAFE"]
[Mon Jul 20 06:16:59.027317 2026] [security2:error] [pid 871012:tid 871222] [client 50.116.65.227:19330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4RurwiU-Jh5ncAILFhLgAAAVk"]
[Mon Jul 20 06:16:59.194177 2026] [security2:error] [pid 871012:tid 871197] [client 14.225.17.146:55184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhNgAAAUA"], referer: https://myspineworld.com/wp
[Mon Jul 20 06:16:59.246662 2026] [security2:error] [pid 874439:tid 874578] [client 50.116.65.227:39426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Ru46ZSrFvCrJJhtT8_wAAAAk"]
[Mon Jul 20 06:16:59.308565 2026] [security2:error] [pid 871012:tid 871045] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhQwABTB8"]
[Mon Jul 20 06:16:59.308705 2026] [security2:error] [pid 871012:tid 871209] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhQwABTB8"]
[Mon Jul 20 06:16:59.409079 2026] [security2:error] [pid 871012:tid 871223] [client 185.132.186.78:46917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/shop.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhSQAAAVo"]
[Mon Jul 20 06:16:59.631759 2026] [security2:error] [pid 871012:tid 871236] [client 104.234.53.81:24683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhWAAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:16:59.938574 2026] [security2:error] [pid 871012:tid 871228] [client 14.225.17.146:61841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhXQAAAV8"], referer: http://whiteoutcb.com/wp
[Mon Jul 20 06:16:59.973785 2026] [security2:error] [pid 874439:tid 874629] [client 45.146.54.116:46727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.54.146.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "marscafe.com"] [uri "/wp-login.php"] [unique_id "al4Ru46ZSrFvCrJJhtT9GgAAADw"]
[Mon Jul 20 06:17:00.017957 2026] [security2:error] [pid 874439:tid 874588] [client 178.152.178.232:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9HwAAABM"]
[Mon Jul 20 06:17:00.018119 2026] [security2:error] [pid 874439:tid 874588] [client 178.152.178.232:36278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9HwAAABM"]
[Mon Jul 20 06:17:00.300144 2026] [security2:error] [pid 874439:tid 874604] [client 15.237.142.234:19458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9JgAAACM"]
[Mon Jul 20 06:17:00.300286 2026] [security2:error] [pid 874439:tid 874604] [client 15.237.142.234:19458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9JgAAACM"]
[Mon Jul 20 06:17:00.449368 2026] [security2:error] [pid 874439:tid 874690] [client 103.77.203.233:49899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9MAAAAHk"]
[Mon Jul 20 06:17:00.449523 2026] [security2:error] [pid 874439:tid 874690] [client 103.77.203.233:49899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9MAAAAHk"]
[Mon Jul 20 06:17:00.587235 2026] [security2:error] [pid 874439:tid 874654] [client 104.234.53.90:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9MwAAAFU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:00.879354 2026] [security2:error] [pid 874439:tid 874659] [client 35.162.140.124:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4Ruo6ZSrFvCrJJhtT80gAAAFo"]
[Mon Jul 20 06:17:00.894847 2026] [security2:error] [pid 874439:tid 874655] [client 35.162.140.124:60291] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/"] [unique_id "al4Ruo6ZSrFvCrJJhtT8zgAAAFY"]
[Mon Jul 20 06:17:01.145517 2026] [cgid:error] [pid 871012:tid 871151] [client 37.27.55.110:21928] AH01265: stderr from /home1/jedalill/public_html/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 06:17:01.204670 2026] [security2:error] [pid 874439:tid 874591] [client 57.141.18.100:50186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RtY6ZSrFvCrJJhtT8DQAAFgM"]
[Mon Jul 20 06:17:01.229527 2026] [security2:error] [pid 871012:tid 871221] [client 14.225.17.146:65360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4RvbwiU-Jh5ncAILFhmgAAAVg"], referer: http://windowtx.com/wp
[Mon Jul 20 06:17:01.415214 2026] [security2:error] [pid 874439:tid 874690] [client 185.132.186.81:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd-1/dedi1.php"] [unique_id "al4RvY6ZSrFvCrJJhtT9VwAAAHk"]
[Mon Jul 20 06:17:01.494393 2026] [security2:error] [pid 874439:tid 874620] [client 14.225.17.146:63350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4RvY6ZSrFvCrJJhtT9UwAAADM"], referer: http://outlookturf.com/wp
[Mon Jul 20 06:17:01.554621 2026] [security2:error] [pid 871012:tid 871246] [client 98.159.234.160:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RvbwiU-Jh5ncAILFhsgAAAXE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:01.704939 2026] [security2:error] [pid 874439:tid 874638] [client 35.162.140.124:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4RvI6ZSrFvCrJJhtT9QQAAAEU"], referer: https://youpositive.co/?rnd=1784549818004
[Mon Jul 20 06:17:01.707502 2026] [security2:error] [pid 874439:tid 874648] [client 35.162.140.124:60291] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/ar/"] [unique_id "al4RvI6ZSrFvCrJJhtT9PgAAAE8"], referer: https://youpositive.co/?rnd=1784549818004
[Mon Jul 20 06:17:01.730819 2026] [security2:error] [pid 871012:tid 871076] [remote 115.79.143.180:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4RvbwiU-Jh5ncAILFhuAABYj4"]
[Mon Jul 20 06:17:01.844538 2026] [security2:error] [pid 871012:tid 871163] [client 45.157.112.60:58297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4RvbwiU-Jh5ncAILFhuwAAAR4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:02.178948 2026] [security2:error] [pid 871012:tid 871024] [remote 115.79.143.180:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4RvrwiU-Jh5ncAILFhzQABRQo"], referer: https://slutilities.com/wp-login.php
[Mon Jul 20 06:17:02.402827 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:63874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9eQAAABc"], referer: http://idigress.group/wp
[Mon Jul 20 06:17:02.447010 2026] [security2:error] [pid 874439:tid 874660] [client 57.141.18.126:59984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rto6ZSrFvCrJJhtT8SAAAWxM"]
[Mon Jul 20 06:17:02.452356 2026] [security2:error] [pid 871012:tid 871195] [client 181.224.94.124:60210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RvrwiU-Jh5ncAILFh3QAAAT4"]
[Mon Jul 20 06:17:02.452486 2026] [security2:error] [pid 871012:tid 871195] [client 181.224.94.124:60210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RvrwiU-Jh5ncAILFh3QAAAT4"]
[Mon Jul 20 06:17:02.503932 2026] [security2:error] [pid 874439:tid 874689] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9gwAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:02.688301 2026] [security2:error] [pid 874439:tid 874512] [remote 57.141.18.21:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3802589"] [unique_id "al4Rvo6ZSrFvCrJJhtT9lgAAEUg"]
[Mon Jul 20 06:17:02.845501 2026] [security2:error] [pid 871012:tid 871053] [remote 192.241.143.148:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4RvrwiU-Jh5ncAILFh7wABdic"]
[Mon Jul 20 06:17:03.088138 2026] [security2:error] [pid 871012:tid 871063] [remote 192.241.143.148:46986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4Rv7wiU-Jh5ncAILFh-wABXjE"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:17:03.185344 2026] [security2:error] [pid 874439:tid 874634] [client 57.141.18.35:35826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rt46ZSrFvCrJJhtT8bAAAQRQ"]
[Mon Jul 20 06:17:03.409681 2026] [security2:error] [pid 874439:tid 874608] [client 185.132.186.67:24593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/setting.php"] [unique_id "al4Rv46ZSrFvCrJJhtT9rAAAACc"]
[Mon Jul 20 06:17:04.087689 2026] [security2:error] [pid 874439:tid 874645] [client 14.225.17.146:55038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9fQAAAEw"], referer: http://areitoproducciones.com/wp
[Mon Jul 20 06:17:04.710173 2026] [security2:error] [pid 871012:tid 871124] [remote 152.228.213.32:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4RwLwiU-Jh5ncAILFiWAABPG4"]
[Mon Jul 20 06:17:04.845075 2026] [security2:error] [pid 871012:tid 871179] [client 57.141.18.29:43188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RuLwiU-Jh5ncAILFg3AABLjc"]
[Mon Jul 20 06:17:04.927546 2026] [security2:error] [pid 871012:tid 871037] [remote 152.228.213.32:36480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4RwLwiU-Jh5ncAILFiZgABWxc"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:17:05.056593 2026] [security2:error] [pid 874439:tid 874608] [client 74.7.227.179:43710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4RwI6ZSrFvCrJJhtT95QAAJ1U"], referer: https://tejasenvironmental.com/p=156629
[Mon Jul 20 06:17:05.182766 2026] [security2:error] [pid 871012:tid 871160] [client 14.225.17.146:65279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4RwLwiU-Jh5ncAILFiXwAAARs"], referer: http://carolinapressurewashers.com/wp
[Mon Jul 20 06:17:05.337735 2026] [security2:error] [pid 874439:tid 874655] [client 185.132.186.67:56195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/smilies/admin.php"] [unique_id "al4RwY6ZSrFvCrJJhtT98QAAAFY"]
[Mon Jul 20 06:17:05.433543 2026] [security2:error] [pid 871012:tid 871237] [client 57.141.18.106:37758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RubwiU-Jh5ncAILFg-wABaEM"]
[Mon Jul 20 06:17:05.791971 2026] [security2:error] [pid 871012:tid 871154] [client 14.225.17.146:65466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4RwbwiU-Jh5ncAILFiggAAARU"], referer: http://hilltopnurseryinc.com/wp
[Mon Jul 20 06:17:06.015553 2026] [security2:error] [pid 871012:tid 871187] [client 57.141.18.50:48048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RurwiU-Jh5ncAILFhFAABNjM"]
[Mon Jul 20 06:17:06.129233 2026] [security2:error] [pid 871012:tid 871234] [client 14.225.17.146:55630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4RwLwiU-Jh5ncAILFiSgAAAWU"], referer: http://vinovinhowine.com/wp
[Mon Jul 20 06:17:06.200486 2026] [security2:error] [pid 874439:tid 874653] [client 50.116.65.227:44316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Rwo6ZSrFvCrJJhtT-GgAAAFQ"]
[Mon Jul 20 06:17:06.213778 2026] [security2:error] [pid 871012:tid 871186] [client 50.116.65.227:39636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4RwrwiU-Jh5ncAILFiowAAASU"]
[Mon Jul 20 06:17:06.515562 2026] [security2:error] [pid 874439:tid 874655] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rwo6ZSrFvCrJJhtT-IgAAVmA"]
[Mon Jul 20 06:17:06.812023 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:65188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4RwrwiU-Jh5ncAILFiuAAAAWk"]
[Mon Jul 20 06:17:06.829758 2026] [security2:error] [pid 874439:tid 874539] [remote 57.141.18.97:26170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5276127"] [unique_id "al4Rwo6ZSrFvCrJJhtT-KwAAJGM"]
[Mon Jul 20 06:17:06.873321 2026] [security2:error] [pid 871012:tid 871198] [client 41.173.37.102:3060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RwrwiU-Jh5ncAILFiygAAAUE"]
[Mon Jul 20 06:17:06.873424 2026] [security2:error] [pid 871012:tid 871198] [client 41.173.37.102:3060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RwrwiU-Jh5ncAILFiygAAAUE"]
[Mon Jul 20 06:17:07.215143 2026] [security2:error] [pid 871012:tid 871197] [client 171.60.139.123:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi2QAAAUA"]
[Mon Jul 20 06:17:07.215288 2026] [security2:error] [pid 871012:tid 871197] [client 171.60.139.123:63203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi2QAAAUA"]
[Mon Jul 20 06:17:07.253641 2026] [security2:error] [pid 871012:tid 871180] [client 185.132.186.91:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/light/as.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi3AAAAS8"]
[Mon Jul 20 06:17:07.332487 2026] [security2:error] [pid 871012:tid 871255] [client 57.141.18.95:57904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ru7wiU-Jh5ncAILFhUgABegk"]
[Mon Jul 20 06:17:07.453744 2026] [security2:error] [pid 871012:tid 871162] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi2gAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:07.589452 2026] [security2:error] [pid 871012:tid 871083] [remote 173.249.4.11:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi7QABQ0U"]
[Mon Jul 20 06:17:07.965479 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:54885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Rw46ZSrFvCrJJhtT-UgAAABc"], referer: http://effingweirdmuseums.com/wp
[Mon Jul 20 06:17:08.122829 2026] [security2:error] [pid 871012:tid 871018] [remote 173.249.4.11:42709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4RxLwiU-Jh5ncAILFjAQABJwQ"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 06:17:08.307268 2026] [security2:error] [pid 871012:tid 871154] [client 14.225.17.146:65128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4RxLwiU-Jh5ncAILFjBQAAARU"], referer: http://techtradeinc.com/wp
[Mon Jul 20 06:17:08.628892 2026] [security2:error] [pid 871012:tid 871250] [client 14.225.17.146:55562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi7AAAAXU"], referer: http://ncsynchro.com/wp
[Mon Jul 20 06:17:08.680343 2026] [security2:error] [pid 871012:tid 871221] [client 104.210.140.133:61184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mtredistricting.gov"] [uri "/index.php"] [unique_id "al4RxLwiU-Jh5ncAILFjDAABWB8"]
[Mon Jul 20 06:17:08.715304 2026] [security2:error] [pid 871012:tid 871224] [client 114.119.135.84:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.theablesea.com"] [uri "/robots.txt"] [unique_id "al4RxLwiU-Jh5ncAILFjGQAAAVs"], referer: http://www.theablesea.com/robots.txt
[Mon Jul 20 06:17:08.719935 2026] [security2:error] [pid 871012:tid 871179] [client 45.116.69.230:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RxLwiU-Jh5ncAILFjGgAAAS4"]
[Mon Jul 20 06:17:08.720090 2026] [security2:error] [pid 871012:tid 871179] [client 45.116.69.230:54503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4RxLwiU-Jh5ncAILFjGgAAAS4"]
[Mon Jul 20 06:17:08.731167 2026] [security2:error] [pid 874439:tid 874674] [client 103.141.108.143:56692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-egAAAGk"]
[Mon Jul 20 06:17:08.731291 2026] [security2:error] [pid 874439:tid 874674] [client 103.141.108.143:56692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-egAAAGk"]
[Mon Jul 20 06:17:08.784020 2026] [security2:error] [pid 874439:tid 874548] [remote 5.161.225.162:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-ewAAcmw"]
[Mon Jul 20 06:17:08.796409 2026] [security2:error] [pid 874439:tid 874654] [client 57.141.18.6:59580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RvY6ZSrFvCrJJhtT9XwAAVUI"]
[Mon Jul 20 06:17:08.890671 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:56314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-fAAAAA0"], referer: https://effingweirdmuseums.com/wp
[Mon Jul 20 06:17:08.892512 2026] [security2:error] [pid 871012:tid 871222] [client 45.61.188.240:61791] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.superiorcopywriting.com"] [uri "/"] [unique_id "al4RxLwiU-Jh5ncAILFjIAAAAVk"]
[Mon Jul 20 06:17:08.993244 2026] [security2:error] [pid 874439:tid 874553] [remote 5.161.225.162:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RxI6ZSrFvCrJJhtT-iwAAOXE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:09.111061 2026] [security2:error] [pid 874439:tid 874585] [client 185.132.186.97:39733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/user/header.php"] [unique_id "al4RxY6ZSrFvCrJJhtT-kAAAABA"]
[Mon Jul 20 06:17:09.161574 2026] [security2:error] [pid 874439:tid 874644] [client 45.61.188.240:61830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.superiorcopywriting.com"] [uri "/"] [unique_id "al4RxY6ZSrFvCrJJhtT-kgAAAEs"]
[Mon Jul 20 06:17:09.340415 2026] [security2:error] [pid 871012:tid 871265] [client 57.141.18.59:33762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RvrwiU-Jh5ncAILFhyQABhDk"]
[Mon Jul 20 06:17:09.646108 2026] [security2:error] [pid 874439:tid 874581] [client 57.141.18.31:53292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rvo6ZSrFvCrJJhtT9iwAADEQ"]
[Mon Jul 20 06:17:10.083706 2026] [security2:error] [pid 874439:tid 874560] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-uwAAXHg"]
[Mon Jul 20 06:17:10.083902 2026] [security2:error] [pid 874439:tid 874661] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-uwAAXHg"]
[Mon Jul 20 06:17:10.275437 2026] [security2:error] [pid 871012:tid 871236] [client 57.141.18.88:37014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rv7wiU-Jh5ncAILFh_AABZwU"]
[Mon Jul 20 06:17:10.363107 2026] [security2:error] [pid 871012:tid 871221] [client 216.38.230.126:50068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4RxrwiU-Jh5ncAILFjSwAAAVg"]
[Mon Jul 20 06:17:10.371420 2026] [security2:error] [pid 871012:tid 871218] [client 57.141.18.113:23770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rv7wiU-Jh5ncAILFiAQABVSs"]
[Mon Jul 20 06:17:10.706588 2026] [security2:error] [pid 874439:tid 874632] [client 14.225.17.146:56454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4RxY6ZSrFvCrJJhtT-oQAAAD8"], referer: http://hammadownenterprises.com/wp
[Mon Jul 20 06:17:10.912109 2026] [security2:error] [pid 874439:tid 874598] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-3QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:10.933912 2026] [security2:error] [pid 874439:tid 874671] [client 185.132.186.91:62565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/about.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-5wAAAGY"]
[Mon Jul 20 06:17:11.122825 2026] [security2:error] [pid 874439:tid 874679] [client 178.152.178.232:36428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9AAAAG4"]
[Mon Jul 20 06:17:11.122910 2026] [security2:error] [pid 874439:tid 874679] [client 178.152.178.232:36428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9AAAAG4"]
[Mon Jul 20 06:17:11.176702 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9QAAAGw"]
[Mon Jul 20 06:17:11.176839 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:50456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Rx46ZSrFvCrJJhtT-9QAAAGw"]
[Mon Jul 20 06:17:11.361413 2026] [security2:error] [pid 874439:tid 874453] [remote 72.167.132.114:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4Rx46ZSrFvCrJJhtT_AAAAeA0"]
[Mon Jul 20 06:17:11.425690 2026] [security2:error] [pid 874439:tid 874586] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rx46ZSrFvCrJJhtT--gAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:11.622857 2026] [security2:error] [pid 874439:tid 874454] [remote 72.167.132.114:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4Rx46ZSrFvCrJJhtT_EgAAJQ4"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 06:17:11.720583 2026] [security2:error] [pid 874439:tid 874683] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rx46ZSrFvCrJJhtT_DwAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:11.829306 2026] [security2:error] [pid 874439:tid 874607] [client 14.225.17.146:56255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-vgAAACY"], referer: http://according2plant.com/wp
[Mon Jul 20 06:17:12.258828 2026] [core:error] [pid 874439:tid 874629] [client 14.225.17.146:58029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:12.258853 2026] [core:error] [pid 874439:tid 874629] [client 14.225.17.146:58029] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:12.270932 2026] [security2:error] [pid 871012:tid 871170] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Rx7wiU-Jh5ncAILFjfQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:12.431167 2026] [security2:error] [pid 874439:tid 874659] [client 14.224.227.113:54321] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4RyI6ZSrFvCrJJhtT_QQAAAFo"]
[Mon Jul 20 06:17:12.674174 2026] [security2:error] [pid 874439:tid 874696] [client 57.141.18.53:22328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RwY6ZSrFvCrJJhtT9_wAAf1s"]
[Mon Jul 20 06:17:12.715601 2026] [security2:error] [pid 871012:tid 871181] [client 185.132.186.100:29327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-api.php"] [unique_id "al4RyLwiU-Jh5ncAILFjoQAAATA"]
[Mon Jul 20 06:17:12.749853 2026] [security2:error] [pid 874439:tid 874615] [client 114.119.133.35:49337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worbals.com"] [uri "/you-need-to-understand-the-role-of-a-legal-transcriptionist/"] [unique_id "al4RyI6ZSrFvCrJJhtT_TgAAAC4"], referer: https://worbals.com/one-of-the-amazing-wonders-of-the-digital-marketing-world-content-pyramid/
[Mon Jul 20 06:17:12.832873 2026] [security2:error] [pid 874439:tid 874472] [remote 95.217.78.234:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RyI6ZSrFvCrJJhtT_VQAAayA"]
[Mon Jul 20 06:17:12.839019 2026] [security2:error] [pid 871012:tid 871215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RyLwiU-Jh5ncAILFjlgAAAVI"]
[Mon Jul 20 06:17:12.979991 2026] [security2:error] [pid 871012:tid 871202] [client 181.224.94.124:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RyLwiU-Jh5ncAILFjsAAAAUU"]
[Mon Jul 20 06:17:12.980115 2026] [security2:error] [pid 871012:tid 871202] [client 181.224.94.124:36465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4RyLwiU-Jh5ncAILFjsAAAAUU"]
[Mon Jul 20 06:17:12.995467 2026] [security2:error] [pid 871012:tid 871190] [client 14.225.17.146:56465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4RyLwiU-Jh5ncAILFjpQAAATk"], referer: http://omrobuildingcenter.com/wp
[Mon Jul 20 06:17:13.065717 2026] [security2:error] [pid 874439:tid 874521] [remote 95.217.78.234:48006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_XQAAcVE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:13.100359 2026] [security2:error] [pid 871012:tid 871268] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4RyLwiU-Jh5ncAILFjrAAAAYc"]
[Mon Jul 20 06:17:13.244720 2026] [security2:error] [pid 871012:tid 871168] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4RybwiU-Jh5ncAILFjtQAAASM"]
[Mon Jul 20 06:17:13.417977 2026] [security2:error] [pid 874439:tid 874573] [client 27.96.94.195:37358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_bgAAAAQ"]
[Mon Jul 20 06:17:13.418120 2026] [security2:error] [pid 874439:tid 874573] [client 27.96.94.195:37358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_bgAAAAQ"]
[Mon Jul 20 06:17:14.145455 2026] [security2:error] [pid 874439:tid 874541] [remote 152.228.213.32:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_lQAARmU"]
[Mon Jul 20 06:17:14.164224 2026] [security2:error] [pid 874439:tid 874695] [client 14.225.17.146:50768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4RyI6ZSrFvCrJJhtT_TQAAAH4"], referer: http://phillipbloch.com/wp
[Mon Jul 20 06:17:14.348648 2026] [security2:error] [pid 874439:tid 874567] [remote 152.228.213.32:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_oAAAJH8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:17:14.363246 2026] [security2:error] [pid 871012:tid 871160] [client 57.141.18.59:57546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rw7wiU-Jh5ncAILFi5wABGw8"]
[Mon Jul 20 06:17:14.492530 2026] [security2:error] [pid 874439:tid 874617] [client 44.245.170.32:14940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_sQAAADA"]
[Mon Jul 20 06:17:14.512994 2026] [security2:error] [pid 871012:tid 871236] [client 185.132.186.82:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/install.php"] [unique_id "al4RyrwiU-Jh5ncAILFj9AAAAWc"]
[Mon Jul 20 06:17:14.585558 2026] [security2:error] [pid 874439:tid 874696] [client 35.90.38.209:37912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ryo6ZSrFvCrJJhtT_sgAAAH8"]
[Mon Jul 20 06:17:14.865510 2026] [security2:error] [pid 871012:tid 871184] [client 14.225.17.146:52893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4RybwiU-Jh5ncAILFjxwAAATM"], referer: http://goyalsatyam.com/wp
[Mon Jul 20 06:17:15.219469 2026] [security2:error] [pid 874439:tid 874573] [client 50.116.65.227:16666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Ry46ZSrFvCrJJhtT_ygAAAAQ"]
[Mon Jul 20 06:17:15.230618 2026] [security2:error] [pid 874439:tid 874619] [client 50.116.65.227:56844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4Ry46ZSrFvCrJJhtT_ywAAACk"]
[Mon Jul 20 06:17:15.422865 2026] [security2:error] [pid 871012:tid 871156] [client 14.225.17.146:56538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4Ry7wiU-Jh5ncAILFkBgAAARc"], referer: http://www.justinagrayman.com/wp
[Mon Jul 20 06:17:15.855482 2026] [core:error] [pid 871012:tid 871236] [client 173.252.82.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:15.855508 2026] [core:error] [pid 871012:tid 871236] [client 173.252.82.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:16.192258 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.64:29356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RxY6ZSrFvCrJJhtT-owAATnY"]
[Mon Jul 20 06:17:16.315002 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.58:56735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css.php"] [unique_id "al4RzI6ZSrFvCrJJhtT_7gAAAFQ"]
[Mon Jul 20 06:17:16.564168 2026] [security2:error] [pid 874439:tid 874594] [client 82.102.18.116:42734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4RzI6ZSrFvCrJJhtQAAwAAABk"]
[Mon Jul 20 06:17:16.920482 2026] [security2:error] [pid 874439:tid 874633] [client 82.102.18.116:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4RzI6ZSrFvCrJJhtQAGgAAAEA"]
[Mon Jul 20 06:17:17.119334 2026] [security2:error] [pid 874439:tid 874643] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4RzI6ZSrFvCrJJhtQAHwAASks"]
[Mon Jul 20 06:17:17.231237 2026] [security2:error] [pid 874439:tid 874665] [client 82.102.18.116:42750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4RzY6ZSrFvCrJJhtQALAAAAGA"]
[Mon Jul 20 06:17:17.505937 2026] [security2:error] [pid 874439:tid 874692] [client 41.173.37.102:3495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAPAAAAHs"]
[Mon Jul 20 06:17:17.506046 2026] [security2:error] [pid 874439:tid 874692] [client 41.173.37.102:3495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAPAAAAHs"]
[Mon Jul 20 06:17:17.558154 2026] [security2:error] [pid 874439:tid 874671] [client 82.102.18.116:42756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4RzY6ZSrFvCrJJhtQAQAAAAGY"]
[Mon Jul 20 06:17:17.565490 2026] [security2:error] [pid 874439:tid 874661] [client 57.141.18.87:27036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rxo6ZSrFvCrJJhtT-6AAAXEA"]
[Mon Jul 20 06:17:17.755026 2026] [security2:error] [pid 874439:tid 874527] [remote 45.90.123.233:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4RzY6ZSrFvCrJJhtQATAAAJFc"]
[Mon Jul 20 06:17:17.887112 2026] [security2:error] [pid 874439:tid 874663] [client 82.102.18.116:42758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4RzY6ZSrFvCrJJhtQAVQAAAF4"]
[Mon Jul 20 06:17:17.949137 2026] [security2:error] [pid 874439:tid 874595] [client 171.60.139.123:63701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAWQAAABo"]
[Mon Jul 20 06:17:17.949251 2026] [security2:error] [pid 874439:tid 874595] [client 171.60.139.123:63701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAWQAAABo"]
[Mon Jul 20 06:17:18.112457 2026] [security2:error] [pid 874439:tid 874633] [client 158.173.89.95:64535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAZAAAAEA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:18.115993 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:54969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4Ry46ZSrFvCrJJhtT_2AAAAG0"], referer: http://drewsasburyparkbeachhouse.com/wp
[Mon Jul 20 06:17:18.117588 2026] [security2:error] [pid 874439:tid 874589] [client 185.132.186.93:47399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/db.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAZQAAABQ"]
[Mon Jul 20 06:17:18.180615 2026] [security2:error] [pid 874439:tid 874540] [remote 45.90.123.233:49934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAaAAATWQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:18.200857 2026] [security2:error] [pid 871012:tid 871254] [client 82.102.18.116:58128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4RzrwiU-Jh5ncAILFkhAAAAXk"]
[Mon Jul 20 06:17:18.416873 2026] [security2:error] [pid 871012:tid 871259] [client 113.160.97.242:50198] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4RzrwiU-Jh5ncAILFkiwAAAX4"]
[Mon Jul 20 06:17:18.530686 2026] [security2:error] [pid 874439:tid 874693] [client 82.102.18.116:58138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4Rzo6ZSrFvCrJJhtQAdwAAAHw"]
[Mon Jul 20 06:17:18.663574 2026] [security2:error] [pid 874439:tid 874656] [client 14.225.17.146:57155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAcwAAAFc"], referer: http://sesamegreenbeans.com/wp
[Mon Jul 20 06:17:18.810432 2026] [security2:error] [pid 874439:tid 874696] [client 14.167.202.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Rzo6ZSrFvCrJJhtQAZwAAAH8"]
[Mon Jul 20 06:17:18.854013 2026] [security2:error] [pid 874439:tid 874580] [client 82.102.18.116:58140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4Rzo6ZSrFvCrJJhtQAiQAAAAs"]
[Mon Jul 20 06:17:19.193683 2026] [security2:error] [pid 874439:tid 874629] [client 82.102.18.116:58148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Rz46ZSrFvCrJJhtQAnQAAADw"]
[Mon Jul 20 06:17:19.349962 2026] [security2:error] [pid 874439:tid 874634] [client 45.116.69.230:55031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz46ZSrFvCrJJhtQAnwAAAEE"]
[Mon Jul 20 06:17:19.350058 2026] [security2:error] [pid 874439:tid 874634] [client 45.116.69.230:55031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz46ZSrFvCrJJhtQAnwAAAEE"]
[Mon Jul 20 06:17:19.362243 2026] [security2:error] [pid 871012:tid 871212] [client 103.141.108.143:57181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkrQAAAU8"]
[Mon Jul 20 06:17:19.362560 2026] [security2:error] [pid 871012:tid 871212] [client 103.141.108.143:57181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkrQAAAU8"]
[Mon Jul 20 06:17:19.491969 2026] [security2:error] [pid 874439:tid 874575] [client 57.141.18.48:51844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_YQAABiE"]
[Mon Jul 20 06:17:19.515041 2026] [security2:error] [pid 871012:tid 871218] [client 82.102.18.116:58160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Rz7wiU-Jh5ncAILFkuQAAAVU"]
[Mon Jul 20 06:17:19.693939 2026] [security2:error] [pid 871012:tid 871164] [client 14.225.17.146:58277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Rz7wiU-Jh5ncAILFktwAAAR8"], referer: https://sesamegreenbeans.com/wp
[Mon Jul 20 06:17:19.838623 2026] [security2:error] [pid 871012:tid 871161] [client 82.102.18.116:62340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Rz7wiU-Jh5ncAILFkxgAAARw"]
[Mon Jul 20 06:17:19.858873 2026] [security2:error] [pid 871012:tid 871201] [client 104.234.53.48:53669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkyAAAAUQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:19.908958 2026] [security2:error] [pid 871012:tid 871171] [client 32.198.12.77:43486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkyQAAASY"]
[Mon Jul 20 06:17:19.918647 2026] [security2:error] [pid 871012:tid 871181] [client 185.132.186.58:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-customize-manager-interpreter.php"] [unique_id "al4Rz7wiU-Jh5ncAILFkzAAAATA"]
[Mon Jul 20 06:17:20.108679 2026] [security2:error] [pid 871012:tid 871119] [remote 91.142.222.105:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4R0LwiU-Jh5ncAILFk1QABfWk"]
[Mon Jul 20 06:17:20.151814 2026] [security2:error] [pid 874439:tid 874669] [client 82.102.18.116:58172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4R0I6ZSrFvCrJJhtQAwgAAAGQ"]
[Mon Jul 20 06:17:20.242105 2026] [security2:error] [pid 874439:tid 874649] [client 13.221.132.12:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.132.221.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4R0I6ZSrFvCrJJhtQAxQAAAFA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:17:20.291286 2026] [security2:error] [pid 874439:tid 874598] [client 57.141.18.116:55204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RyY6ZSrFvCrJJhtT_hwAAHWI"]
[Mon Jul 20 06:17:20.331905 2026] [security2:error] [pid 874439:tid 874557] [remote 124.55.178.99:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4R0I6ZSrFvCrJJhtQAyAAAT3U"]
[Mon Jul 20 06:17:20.346119 2026] [security2:error] [pid 871012:tid 871115] [remote 91.142.222.105:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4R0LwiU-Jh5ncAILFk3wABcWU"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:17:20.461864 2026] [security2:error] [pid 874439:tid 874634] [client 82.102.18.116:58174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4R0I6ZSrFvCrJJhtQAzgAAAEE"]
[Mon Jul 20 06:17:20.680975 2026] [security2:error] [pid 874439:tid 874444] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA2gAAegQ"]
[Mon Jul 20 06:17:20.681161 2026] [security2:error] [pid 874439:tid 874691] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA2gAAegQ"]
[Mon Jul 20 06:17:20.799266 2026] [security2:error] [pid 874439:tid 874659] [client 82.102.18.116:58182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4R0I6ZSrFvCrJJhtQA3gAAAFo"]
[Mon Jul 20 06:17:20.886333 2026] [security2:error] [pid 874439:tid 874446] [remote 124.55.178.99:52328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA3wAAVwY"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:17:21.120171 2026] [security2:error] [pid 874439:tid 874589] [client 82.102.18.116:58198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4R0Y6ZSrFvCrJJhtQA6wAAABQ"]
[Mon Jul 20 06:17:21.445757 2026] [security2:error] [pid 874439:tid 874613] [client 82.102.18.116:58214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.iwv.oao.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4R0Y6ZSrFvCrJJhtQA_wAAACw"]
[Mon Jul 20 06:17:21.691653 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:51011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R0Y6ZSrFvCrJJhtQBCQAAACA"]
[Mon Jul 20 06:17:21.691801 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:51011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R0Y6ZSrFvCrJJhtQBCQAAACA"]
[Mon Jul 20 06:17:21.716457 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.83:30409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/bypass.php"] [unique_id "al4R0Y6ZSrFvCrJJhtQBDgAAAFQ"]
[Mon Jul 20 06:17:22.017804 2026] [security2:error] [pid 874439:tid 874617] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA0QAAADA"], referer: http://eduardsales.com/wp
[Mon Jul 20 06:17:22.189492 2026] [security2:error] [pid 874439:tid 874511] [remote 57.141.18.5:58778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4R0o6ZSrFvCrJJhtQBHwAAbEc"]
[Mon Jul 20 06:17:22.598193 2026] [security2:error] [pid 871012:tid 871267] [client 57.141.18.116:55222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ry7wiU-Jh5ncAILFkJQABhlE"]
[Mon Jul 20 06:17:22.672842 2026] [security2:error] [pid 874439:tid 874647] [client 50.116.65.227:60006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4R0o6ZSrFvCrJJhtQBMwAAAE4"]
[Mon Jul 20 06:17:22.683728 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:52356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4R0rwiU-Jh5ncAILFlOgAAAS0"]
[Mon Jul 20 06:17:22.913779 2026] [core:error] [pid 871012:tid 871206] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.913809 2026] [core:error] [pid 871012:tid 871206] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914275 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914289 2026] [core:error] [pid 871012:tid 871187] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914578 2026] [core:error] [pid 871012:tid 871202] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.914592 2026] [core:error] [pid 871012:tid 871202] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.937278 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:22.937297 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:23.236338 2026] [security2:error] [pid 871012:tid 871250] [client 57.141.18.73:63070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RzLwiU-Jh5ncAILFkPgABdUA"]
[Mon Jul 20 06:17:23.392411 2026] [security2:error] [pid 874439:tid 874472] [remote 156.67.31.167:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4R046ZSrFvCrJJhtQBUwAARiA"]
[Mon Jul 20 06:17:23.404801 2026] [security2:error] [pid 874439:tid 874470] [remote 154.66.198.148:11108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R046ZSrFvCrJJhtQBVAAAXx4"]
[Mon Jul 20 06:17:23.489388 2026] [security2:error] [pid 871012:tid 871252] [client 185.132.186.99:31279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/fm.php7"] [unique_id "al4R07wiU-Jh5ncAILFlYAAAAXc"]
[Mon Jul 20 06:17:23.503490 2026] [security2:error] [pid 874439:tid 874613] [client 181.224.94.124:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R046ZSrFvCrJJhtQBWwAAACw"]
[Mon Jul 20 06:17:23.503631 2026] [security2:error] [pid 874439:tid 874613] [client 181.224.94.124:21067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R046ZSrFvCrJJhtQBWwAAACw"]
[Mon Jul 20 06:17:23.677655 2026] [core:error] [pid 874439:tid 874690] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:23.677675 2026] [core:error] [pid 874439:tid 874690] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:23.826110 2026] [security2:error] [pid 874439:tid 874614] [client 104.234.53.67:55527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4R046ZSrFvCrJJhtQBcQAAAC0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:23.869159 2026] [security2:error] [pid 874439:tid 874475] [remote 156.67.31.167:45688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4R046ZSrFvCrJJhtQBdQAAJyM"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:17:24.021764 2026] [security2:error] [pid 871012:tid 871112] [remote 50.28.1.50:45458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R1LwiU-Jh5ncAILFleAABfWI"]
[Mon Jul 20 06:17:24.036795 2026] [security2:error] [pid 874439:tid 874655] [client 103.153.183.69:14660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..../..../..../..../..../etc/nginx/nginx.conf"] [unique_id "al4R1I6ZSrFvCrJJhtQBewAAAFY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:17:24.234208 2026] [security2:error] [pid 871012:tid 871114] [remote 50.28.1.50:45458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R1LwiU-Jh5ncAILFlgQABXmQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:17:24.285710 2026] [security2:error] [pid 874439:tid 874483] [remote 154.66.198.148:11096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4R1I6ZSrFvCrJJhtQBiAAAICs"]
[Mon Jul 20 06:17:24.538178 2026] [security2:error] [pid 874439:tid 874567] [remote 154.66.198.148:11108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R1I6ZSrFvCrJJhtQBlAAAS38"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:24.555446 2026] [security2:error] [pid 874439:tid 874576] [client 57.141.18.95:58244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4RzY6ZSrFvCrJJhtQAMQAABxk"]
[Mon Jul 20 06:17:24.653847 2026] [security2:error] [pid 871012:tid 871213] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R1LwiU-Jh5ncAILFlhwAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:24.803972 2026] [security2:error] [pid 874439:tid 874484] [remote 45.90.123.233:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1I6ZSrFvCrJJhtQBnQAAQCw"]
[Mon Jul 20 06:17:24.878889 2026] [security2:error] [pid 874439:tid 874656] [client 45.61.188.240:64600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "superiorcopywriting.com"] [uri "/"] [unique_id "al4R1I6ZSrFvCrJJhtQBogAAAFc"]
[Mon Jul 20 06:17:25.025941 2026] [security2:error] [pid 874439:tid 874564] [remote 45.90.123.233:53276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBsgAAfHw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:25.034873 2026] [security2:error] [pid 874439:tid 874493] [remote 20.153.140.50:55352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBsQAAHTU"]
[Mon Jul 20 06:17:25.131378 2026] [security2:error] [pid 874439:tid 874458] [remote 154.66.198.148:11096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBugAAIxI"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:17:25.160639 2026] [security2:error] [pid 874439:tid 874601] [client 45.61.188.240:64641] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "superiorcopywriting.com"] [uri "/"] [unique_id "al4R1Y6ZSrFvCrJJhtQBvAAAACA"]
[Mon Jul 20 06:17:25.293418 2026] [security2:error] [pid 874439:tid 874642] [client 14.225.17.146:57316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBvwAAAEk"], referer: http://ravmike.com/wp
[Mon Jul 20 06:17:25.317949 2026] [security2:error] [pid 874439:tid 874496] [remote 160.187.68.132:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBwwAAaDg"]
[Mon Jul 20 06:17:25.391352 2026] [security2:error] [pid 874439:tid 874672] [client 14.225.17.146:57322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBwgAAAGc"], referer: http://alrowad-hub.net/wp
[Mon Jul 20 06:17:25.424796 2026] [security2:error] [pid 874439:tid 874449] [remote 20.153.140.50:55352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBygAAawk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:25.806431 2026] [security2:error] [pid 874439:tid 874693] [client 103.153.183.69:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fhome/www-data/.ssh/id_rsa"] [unique_id "al4R1Y6ZSrFvCrJJhtQB5AAAAHw"], referer: https://duckduckgo.com/?q=fkezl
[Mon Jul 20 06:17:26.197402 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:57402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4R1rwiU-Jh5ncAILFl0wAAAWk"], referer: https://ravmike.com/wp
[Mon Jul 20 06:17:26.380730 2026] [security2:error] [pid 874439:tid 874630] [client 185.132.186.100:40299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/count.php"] [unique_id "al4R1o6ZSrFvCrJJhtQB_QAAAD0"]
[Mon Jul 20 06:17:26.385403 2026] [security2:error] [pid 874439:tid 874459] [remote 160.187.68.132:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4R1o6ZSrFvCrJJhtQB_AAAcxM"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 06:17:26.472288 2026] [security2:error] [pid 871012:tid 871244] [client 57.141.18.13:58672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rz7wiU-Jh5ncAILFksAABb2w"]
[Mon Jul 20 06:17:26.632960 2026] [core:error] [pid 874439:tid 874620] [client 14.225.17.146:56966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:26.632980 2026] [core:error] [pid 874439:tid 874620] [client 14.225.17.146:56966] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:26.683803 2026] [security2:error] [pid 874439:tid 874667] [client 57.141.18.81:60458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Rz46ZSrFvCrJJhtQAsAAAYlw"]
[Mon Jul 20 06:17:26.703507 2026] [security2:error] [pid 874439:tid 874581] [client 74.208.214.194:46278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4R1o6ZSrFvCrJJhtQCEgAAAAw"]
[Mon Jul 20 06:17:26.943146 2026] [security2:error] [pid 871012:tid 871214] [client 14.225.17.146:56897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4R1rwiU-Jh5ncAILFl7gAAAVE"], referer: http://kromosenergy.com/wp
[Mon Jul 20 06:17:27.265994 2026] [security2:error] [pid 874439:tid 874664] [client 14.225.17.146:60515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4R146ZSrFvCrJJhtQCMQAAAF8"], referer: http://39ishlife.com/wp
[Mon Jul 20 06:17:27.290816 2026] [security2:error] [pid 871012:tid 871178] [client 14.225.17.146:60509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFl-wAAAS0"], referer: http://savilerowtravel.com/wp
[Mon Jul 20 06:17:27.320979 2026] [security2:error] [pid 871012:tid 871223] [client 14.225.17.146:64490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFl_wAAAVo"], referer: http://mourgroup.com/wp
[Mon Jul 20 06:17:27.321652 2026] [security2:error] [pid 871012:tid 871224] [client 14.225.17.146:60519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFl_AAAAVs"], referer: http://qualitycoatingsinspection.com/wp
[Mon Jul 20 06:17:27.490042 2026] [security2:error] [pid 874439:tid 874539] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R146ZSrFvCrJJhtQCQQAAbWM"]
[Mon Jul 20 06:17:27.490250 2026] [security2:error] [pid 874439:tid 874678] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R146ZSrFvCrJJhtQCQQAAbWM"]
[Mon Jul 20 06:17:27.624173 2026] [security2:error] [pid 874439:tid 874635] [client 57.141.18.100:49440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R0I6ZSrFvCrJJhtQA2wAAQgU"]
[Mon Jul 20 06:17:27.922492 2026] [security2:error] [pid 874439:tid 874692] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R146ZSrFvCrJJhtQCRwAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:28.102428 2026] [security2:error] [pid 874439:tid 874586] [client 41.173.37.102:3926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCaAAAABE"]
[Mon Jul 20 06:17:28.102537 2026] [security2:error] [pid 874439:tid 874586] [client 41.173.37.102:3926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCaAAAABE"]
[Mon Jul 20 06:17:28.178526 2026] [security2:error] [pid 874439:tid 874599] [client 185.132.186.53:36659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-error_log.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCawAAAB4"]
[Mon Jul 20 06:17:28.313944 2026] [security2:error] [pid 874439:tid 874621] [client 104.234.53.61:42487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCbgAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:28.316936 2026] [security2:error] [pid 874439:tid 874618] [client 14.225.17.146:64841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCbQAAADE"], referer: https://39ishlife.com/wp
[Mon Jul 20 06:17:28.360388 2026] [security2:error] [pid 874439:tid 874642] [client 14.225.17.146:64779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCbAAAAEk"], referer: https://qualitycoatingsinspection.com/wp
[Mon Jul 20 06:17:28.586257 2026] [security2:error] [pid 871012:tid 871247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmKQAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:28.635052 2026] [security2:error] [pid 871012:tid 871075] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/api/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmRgABCz0"]
[Mon Jul 20 06:17:28.638102 2026] [security2:error] [pid 871012:tid 871100] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/backend/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmSAABdVY"]
[Mon Jul 20 06:17:28.638960 2026] [security2:error] [pid 871012:tid 871101] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/.env.backup"] [unique_id "al4R2LwiU-Jh5ncAILFmSQABdVc"]
[Mon Jul 20 06:17:28.641967 2026] [security2:error] [pid 871012:tid 871023] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.env.bak"] [unique_id "al4R2LwiU-Jh5ncAILFmSgABdQk"]
[Mon Jul 20 06:17:28.642977 2026] [security2:error] [pid 871012:tid 871035] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/admin/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmSwABdRU"]
[Mon Jul 20 06:17:28.646631 2026] [security2:error] [pid 871012:tid 871060] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.env.old"] [unique_id "al4R2LwiU-Jh5ncAILFmTQABdS4"]
[Mon Jul 20 06:17:28.678362 2026] [security2:error] [pid 871012:tid 871030] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/config/.env"] [unique_id "al4R2LwiU-Jh5ncAILFmUAABdRA"]
[Mon Jul 20 06:17:28.678551 2026] [security2:error] [pid 874439:tid 874688] [client 13.229.83.156:46304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCigAAAHc"]
[Mon Jul 20 06:17:28.678707 2026] [security2:error] [pid 874439:tid 874688] [client 13.229.83.156:46304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCigAAAHc"]
[Mon Jul 20 06:17:28.689879 2026] [security2:error] [pid 874439:tid 874670] [client 14.225.17.146:49231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCewAAAGU"], referer: https://savilerowtravel.com/wp
[Mon Jul 20 06:17:28.720779 2026] [security2:error] [pid 874439:tid 874609] [client 103.153.183.69:38028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f..\\xef\\xbc\\x8fhome/git/.ssh/id_rsa"] [unique_id "al4R2I6ZSrFvCrJJhtQCjQAAACg"], referer: https://www.google.com/
[Mon Jul 20 06:17:28.764708 2026] [security2:error] [pid 874439:tid 874661] [client 171.60.139.123:64197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCkAAAAFw"]
[Mon Jul 20 06:17:28.764846 2026] [security2:error] [pid 874439:tid 874661] [client 171.60.139.123:64197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCkAAAAFw"]
[Mon Jul 20 06:17:28.798913 2026] [security2:error] [pid 871012:tid 871236] [client 13.223.141.79:59584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.verdunestate.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmQwAAAWc"]
[Mon Jul 20 06:17:28.854176 2026] [security2:error] [pid 871012:tid 871197] [client 14.225.17.146:49290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmRQAAAUA"], referer: http://ironcitywellness.com/wp
[Mon Jul 20 06:17:28.953655 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmTgABdWo"]
[Mon Jul 20 06:17:28.954271 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmTAABdRo"]
[Mon Jul 20 06:17:28.980216 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmUwABdTo"]
[Mon Jul 20 06:17:28.990542 2026] [security2:error] [pid 871012:tid 871250] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmUgABdSc"]
[Mon Jul 20 06:17:29.105942 2026] [security2:error] [pid 874439:tid 874689] [client 57.141.18.100:49456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R0o6ZSrFvCrJJhtQBFgAAeBU"]
[Mon Jul 20 06:17:29.518726 2026] [security2:error] [pid 874439:tid 874473] [remote 217.61.143.92:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCqQAAaCE"]
[Mon Jul 20 06:17:29.738915 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmbgABQmM"]
[Mon Jul 20 06:17:29.754543 2026] [security2:error] [pid 874439:tid 874635] [client 14.225.17.146:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4R146ZSrFvCrJJhtQCVwAAAEI"], referer: http://mobilesurvsolutions.com/wp
[Mon Jul 20 06:17:29.789816 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdQABQlw"]
[Mon Jul 20 06:17:29.790069 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdwABQg4"]
[Mon Jul 20 06:17:29.790224 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmcwABQnk"]
[Mon Jul 20 06:17:29.790484 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmeAABQh8"]
[Mon Jul 20 06:17:29.791649 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdAABQmg"]
[Mon Jul 20 06:17:29.791843 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmdgABQkY"]
[Mon Jul 20 06:17:29.791997 2026] [security2:error] [pid 871012:tid 871199] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmcgABQgQ"]
[Mon Jul 20 06:17:29.817431 2026] [security2:error] [pid 874439:tid 874551] [remote 57.141.18.91:20892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5168046"] [unique_id "al4R2Y6ZSrFvCrJJhtQCsgAAc28"]
[Mon Jul 20 06:17:29.829540 2026] [security2:error] [pid 874439:tid 874556] [remote 217.61.143.92:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCtQAAIXQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:29.914442 2026] [security2:error] [pid 874439:tid 874649] [client 104.234.53.61:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCtgAAAFA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:29.980949 2026] [security2:error] [pid 871012:tid 871147] [client 103.141.108.143:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R2bwiU-Jh5ncAILFmlAAAAQ4"]
[Mon Jul 20 06:17:29.981979 2026] [security2:error] [pid 871012:tid 871147] [client 103.141.108.143:57660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R2bwiU-Jh5ncAILFmlAAAAQ4"]
[Mon Jul 20 06:17:29.983580 2026] [security2:error] [pid 871012:tid 871198] [client 185.132.186.65:60909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/class_update_plugins.php"] [unique_id "al4R2bwiU-Jh5ncAILFmlQAAAUE"]
[Mon Jul 20 06:17:30.011143 2026] [security2:error] [pid 871012:tid 871258] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmiwAAAX0"]
[Mon Jul 20 06:17:30.032514 2026] [security2:error] [pid 874439:tid 874614] [client 45.116.69.230:55568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R2o6ZSrFvCrJJhtQCvAAAAC0"]
[Mon Jul 20 06:17:30.032604 2026] [security2:error] [pid 874439:tid 874614] [client 45.116.69.230:55568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R2o6ZSrFvCrJJhtQCvAAAAC0"]
[Mon Jul 20 06:17:30.222828 2026] [security2:error] [pid 871012:tid 871269] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2bwiU-Jh5ncAILFmigAAAYg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:30.544324 2026] [security2:error] [pid 874439:tid 874584] [client 50.116.65.227:19344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R2o6ZSrFvCrJJhtQC6AAAAA8"]
[Mon Jul 20 06:17:30.555577 2026] [security2:error] [pid 874439:tid 874664] [client 50.116.65.227:34104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R2o6ZSrFvCrJJhtQC6gAAAF8"]
[Mon Jul 20 06:17:30.560302 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQCzAAAWHc"], referer: https://guidehunting.com/.env.local
[Mon Jul 20 06:17:30.653695 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC1QAAWHU"], referer: https://guidehunting.com/.npmrc
[Mon Jul 20 06:17:30.656654 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC0QAAWHg"], referer: https://guidehunting.com/.docker/config.json
[Mon Jul 20 06:17:30.657014 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC1AAAWH4"], referer: https://guidehunting.com/firebase-adminsdk.json
[Mon Jul 20 06:17:30.657163 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC0gAAWHo"], referer: https://guidehunting.com/credentials.json
[Mon Jul 20 06:17:30.659307 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC0wAAWGI"], referer: https://guidehunting.com/secrets.yml
[Mon Jul 20 06:17:30.695006 2026] [security2:error] [pid 874439:tid 874673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC4AAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:30.867914 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC6wAAWAo"], referer: https://guidehunting.com/key.json
[Mon Jul 20 06:17:30.869804 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC7QAAWHc"], referer: https://guidehunting.com/serviceAccountKey.json
[Mon Jul 20 06:17:30.869954 2026] [security2:error] [pid 874439:tid 874657] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQC7AAAWAI"], referer: https://guidehunting.com/service-account.json
[Mon Jul 20 06:17:30.981560 2026] [security2:error] [pid 874439:tid 874685] [client 82.102.18.116:53832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4R2o6ZSrFvCrJJhtQDCAAAAHQ"]
[Mon Jul 20 06:17:31.094576 2026] [security2:error] [pid 874439:tid 874596] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R2o6ZSrFvCrJJhtQDAAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:31.219976 2026] [security2:error] [pid 874439:tid 874572] [client 193.36.225.138:24945] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "newoffice.ca"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4R246ZSrFvCrJJhtQDEgAAAAM"]
[Mon Jul 20 06:17:31.328179 2026] [security2:error] [pid 874439:tid 874605] [client 82.102.18.116:53840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.ferrarimenezes.com"] [uri "/xmlrpc.php"] [unique_id "al4R246ZSrFvCrJJhtQDGwAAACQ"]
[Mon Jul 20 06:17:31.416528 2026] [security2:error] [pid 874439:tid 874479] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R246ZSrFvCrJJhtQDKQAAOic"]
[Mon Jul 20 06:17:31.416694 2026] [security2:error] [pid 874439:tid 874627] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R246ZSrFvCrJJhtQDKQAAOic"]
[Mon Jul 20 06:17:31.452402 2026] [security2:error] [pid 874439:tid 874584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDFwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:31.768948 2026] [security2:error] [pid 871012:tid 871090] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/.boto"] [unique_id "al4R27wiU-Jh5ncAILFmyAABP0w"]
[Mon Jul 20 06:17:31.769202 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/.boto"] [unique_id "al4R27wiU-Jh5ncAILFmyAABP0w"]
[Mon Jul 20 06:17:31.772023 2026] [security2:error] [pid 871012:tid 871014] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.ssh/id_rsa"] [unique_id "al4R27wiU-Jh5ncAILFmyQABPwA"]
[Mon Jul 20 06:17:31.772571 2026] [authz_core:error] [pid 871012:tid 871052] [remote 35.245.65.174:33432] AH01630: client denied by server configuration: /home4/guidehun/public_html/.htpasswd
[Mon Jul 20 06:17:31.789745 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.83:29689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/av.php"] [unique_id "al4R246ZSrFvCrJJhtQDQgAAAFQ"]
[Mon Jul 20 06:17:31.814096 2026] [security2:error] [pid 871012:tid 871215] [client 82.102.18.116:62336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4R27wiU-Jh5ncAILFm0AAAAVI"]
[Mon Jul 20 06:17:31.841875 2026] [security2:error] [pid 871012:tid 871239] [client 57.141.18.27:51696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R1LwiU-Jh5ncAILFlngABaiQ"]
[Mon Jul 20 06:17:31.915300 2026] [security2:error] [pid 874439:tid 874665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDOAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:32.033043 2026] [security2:error] [pid 874439:tid 874637] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDOQAARCs"], referer: https://guidehunting.com/rclone.conf
[Mon Jul 20 06:17:32.060615 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmxQABPy0"]
[Mon Jul 20 06:17:32.063008 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmxgABPzA"]
[Mon Jul 20 06:17:32.070777 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmzQABP18"]
[Mon Jul 20 06:17:32.073146 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmygABP3E"]
[Mon Jul 20 06:17:32.086583 2026] [security2:error] [pid 874439:tid 874672] [client 178.152.178.232:37686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDUwAAAGc"]
[Mon Jul 20 06:17:32.086665 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmzAABP0E"]
[Mon Jul 20 06:17:32.086822 2026] [security2:error] [pid 874439:tid 874672] [client 178.152.178.232:37686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDUwAAAGc"]
[Mon Jul 20 06:17:32.088543 2026] [security2:error] [pid 871012:tid 871196] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R27wiU-Jh5ncAILFmywABP3o"]
[Mon Jul 20 06:17:32.098209 2026] [security2:error] [pid 874439:tid 874637] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDPwAARCg"], referer: https://guidehunting.com/z9x8c7v6b5-debug-trigger-guidehunting.com
[Mon Jul 20 06:17:32.098864 2026] [security2:error] [pid 874439:tid 874637] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDPgAARH8"], referer: https://guidehunting.com/secrets.json
[Mon Jul 20 06:17:32.138419 2026] [security2:error] [pid 874439:tid 874603] [client 82.102.18.116:53856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4R3I6ZSrFvCrJJhtQDWAAAACI"]
[Mon Jul 20 06:17:32.148221 2026] [security2:error] [pid 874439:tid 874689] [client 74.208.214.194:46292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDWgAAAHg"]
[Mon Jul 20 06:17:32.186960 2026] [security2:error] [pid 874439:tid 874663] [client 103.77.203.233:51569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDXQAAAF4"]
[Mon Jul 20 06:17:32.189148 2026] [security2:error] [pid 874439:tid 874663] [client 103.77.203.233:51569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDXQAAAF4"]
[Mon Jul 20 06:17:32.250262 2026] [security2:error] [pid 874439:tid 874492] [remote 72.167.132.114:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDYgAABjQ"]
[Mon Jul 20 06:17:32.261651 2026] [security2:error] [pid 874439:tid 874631] [client 57.141.18.58:48078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R1Y6ZSrFvCrJJhtQBtgAAPjs"]
[Mon Jul 20 06:17:32.381761 2026] [security2:error] [pid 871012:tid 871133] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.ssh/id_dsa"] [unique_id "al4R3LwiU-Jh5ncAILFm2AABNXc"]
[Mon Jul 20 06:17:32.473351 2026] [security2:error] [pid 874439:tid 874509] [remote 72.167.132.114:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDeQAAVEU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:32.479819 2026] [security2:error] [pid 874439:tid 874648] [client 82.102.18.116:53870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4R3I6ZSrFvCrJJhtQDegAAAE8"]
[Mon Jul 20 06:17:32.510778 2026] [security2:error] [pid 874439:tid 874681] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDaQAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:32.618545 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:54656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4R246ZSrFvCrJJhtQDCwAAAE4"], referer: http://headachescarpaltunnelfibromyalgia.com/wp
[Mon Jul 20 06:17:32.640074 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDbgAAHTc"], referer: https://guidehunting.com/.s3cfg
[Mon Jul 20 06:17:32.644311 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcAAAHT0"], referer: https://guidehunting.com/.ssh/id_ed25519
[Mon Jul 20 06:17:32.644471 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcwAAHT4"], referer: https://guidehunting.com/.vscode/launch.json
[Mon Jul 20 06:17:32.644711 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDbwAAHXY"], referer: https://guidehunting.com/.svn/entries
[Mon Jul 20 06:17:32.644864 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcQAAHTo"], referer: https://guidehunting.com/terraform.tfstate
[Mon Jul 20 06:17:32.645971 2026] [security2:error] [pid 874439:tid 874598] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDcgAAHQw"], referer: https://guidehunting.com/docker-compose.yaml
[Mon Jul 20 06:17:32.683491 2026] [security2:error] [pid 871012:tid 871186] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R3LwiU-Jh5ncAILFm2QABNUc"]
[Mon Jul 20 06:17:32.790360 2026] [security2:error] [pid 874439:tid 874589] [client 82.102.18.116:53874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4R3I6ZSrFvCrJJhtQDjQAAABQ"]
[Mon Jul 20 06:17:33.024461 2026] [security2:error] [pid 874439:tid 874584] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDhwAAD00"]
[Mon Jul 20 06:17:33.128073 2026] [security2:error] [pid 871012:tid 871182] [client 82.102.18.116:53876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4R3bwiU-Jh5ncAILFm6AAAATE"]
[Mon Jul 20 06:17:33.261145 2026] [security2:error] [pid 871012:tid 871174] [client 46.110.96.34:61718] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4R3bwiU-Jh5ncAILFm7AAAASk"]
[Mon Jul 20 06:17:33.261163 2026] [security2:error] [pid 874439:tid 874592] [client 46.110.96.34:36182] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4R3Y6ZSrFvCrJJhtQDpQAAABc"]
[Mon Jul 20 06:17:33.366233 2026] [security2:error] [pid 874439:tid 874635] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDnwAAQgE"], referer: https://guidehunting.com/.ssh/id_ecdsa
[Mon Jul 20 06:17:33.367646 2026] [security2:error] [pid 871012:tid 871153] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R3bwiU-Jh5ncAILFm5gABFHw"]
[Mon Jul 20 06:17:33.407529 2026] [security2:error] [pid 871012:tid 871221] [client 129.151.80.191:38564] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "perrysnopeep.com"] [uri "/index.html"] [unique_id "al4R3bwiU-Jh5ncAILFm-AAAAVg"]
[Mon Jul 20 06:17:33.447931 2026] [security2:error] [pid 874439:tid 874690] [client 82.102.18.116:36075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4R3Y6ZSrFvCrJJhtQDsAAAAHk"]
[Mon Jul 20 06:17:33.543547 2026] [security2:error] [pid 871012:tid 871153] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R3bwiU-Jh5ncAILFm7QABFA0"]
[Mon Jul 20 06:17:33.597306 2026] [security2:error] [pid 874439:tid 874615] [client 185.132.186.95:32877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/templates/beez5/error.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDtwAAAC4"]
[Mon Jul 20 06:17:33.702729 2026] [security2:error] [pid 874439:tid 874463] [remote 152.228.213.32:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDvQAARBc"]
[Mon Jul 20 06:17:33.762848 2026] [security2:error] [pid 871012:tid 871161] [client 82.102.18.116:38537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4R3bwiU-Jh5ncAILFnBAAAARw"]
[Mon Jul 20 06:17:33.905245 2026] [security2:error] [pid 874439:tid 874529] [remote 152.228.213.32:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDwQAAB1k"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:17:34.055460 2026] [security2:error] [pid 874439:tid 874589] [client 181.224.94.124:6549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R3o6ZSrFvCrJJhtQDygAAABQ"]
[Mon Jul 20 06:17:34.055561 2026] [security2:error] [pid 874439:tid 874589] [client 181.224.94.124:6549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R3o6ZSrFvCrJJhtQDygAAABQ"]
[Mon Jul 20 06:17:34.109885 2026] [security2:error] [pid 874439:tid 874596] [client 82.102.18.116:53900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4R3o6ZSrFvCrJJhtQD0gAAABs"]
[Mon Jul 20 06:17:34.434206 2026] [security2:error] [pid 871012:tid 871263] [client 82.102.18.116:53906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4R3rwiU-Jh5ncAILFnGwAAAYI"]
[Mon Jul 20 06:17:34.560026 2026] [security2:error] [pid 874439:tid 874630] [client 14.225.17.146:64476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4R3o6ZSrFvCrJJhtQD0wAAAD0"], referer: http://adastra.love/wp
[Mon Jul 20 06:17:34.585332 2026] [security2:error] [pid 871012:tid 871155] [client 104.234.53.89:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4R3rwiU-Jh5ncAILFnIQAAARY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:34.746568 2026] [security2:error] [pid 874439:tid 874611] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3o6ZSrFvCrJJhtQD2AAAKko"], referer: https://guidehunting.com/.ssh/config
[Mon Jul 20 06:17:34.748561 2026] [security2:error] [pid 874439:tid 874611] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R3o6ZSrFvCrJJhtQD2QAAKkI"], referer: https://guidehunting.com/.ssh/authorized_keys
[Mon Jul 20 06:17:34.750528 2026] [security2:error] [pid 871012:tid 871261] [client 82.102.18.116:53920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4R3rwiU-Jh5ncAILFnJQAAAYA"]
[Mon Jul 20 06:17:34.864258 2026] [security2:error] [pid 871012:tid 871225] [client 14.225.17.146:58664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4R3bwiU-Jh5ncAILFm5wAAAVw"], referer: http://bigwormfishing.com/wp
[Mon Jul 20 06:17:34.984938 2026] [security2:error] [pid 871012:tid 871170] [client 57.141.18.67:63220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R17wiU-Jh5ncAILFmIgABJRI"]
[Mon Jul 20 06:17:35.099913 2026] [security2:error] [pid 874439:tid 874575] [client 82.102.18.116:53926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4R346ZSrFvCrJJhtQEBAAAAAY"]
[Mon Jul 20 06:17:35.397126 2026] [security2:error] [pid 874439:tid 874599] [client 185.132.186.103:42175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/admin-footer.php"] [unique_id "al4R346ZSrFvCrJJhtQEJgAAAB4"]
[Mon Jul 20 06:17:35.429905 2026] [security2:error] [pid 874439:tid 874604] [client 57.141.18.30:41706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2I6ZSrFvCrJJhtQCcgAAI18"]
[Mon Jul 20 06:17:35.445186 2026] [security2:error] [pid 874439:tid 874660] [client 14.225.17.146:49762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDuQAAAFs"], referer: http://ccsdifference.com/wp
[Mon Jul 20 06:17:35.455344 2026] [security2:error] [pid 874439:tid 874648] [client 82.102.18.116:53938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4R346ZSrFvCrJJhtQEKwAAAE8"]
[Mon Jul 20 06:17:35.775432 2026] [security2:error] [pid 871012:tid 871214] [client 82.102.18.116:15653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4R37wiU-Jh5ncAILFnPwAAAVE"]
[Mon Jul 20 06:17:35.877098 2026] [security2:error] [pid 871012:tid 871167] [client 57.141.18.10:54542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2LwiU-Jh5ncAILFmXAABIn8"]
[Mon Jul 20 06:17:35.925351 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:52886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4R346ZSrFvCrJJhtQEPQAAAEM"], referer: https://bigwormfishing.com/wp
[Mon Jul 20 06:17:36.090562 2026] [security2:error] [pid 871012:tid 871254] [client 82.102.18.116:53942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4R4LwiU-Jh5ncAILFnRQAAAXk"]
[Mon Jul 20 06:17:36.201558 2026] [security2:error] [pid 874439:tid 874592] [client 77.110.127.138:59396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4R4I6ZSrFvCrJJhtQEYwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:36.244453 2026] [security2:error] [pid 871012:tid 871083] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/key.pem"] [unique_id "al4R4LwiU-Jh5ncAILFnSAABc0U"]
[Mon Jul 20 06:17:36.244621 2026] [security2:error] [pid 871012:tid 871248] [client 35.245.65.174:33432] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/key.pem"] [unique_id "al4R4LwiU-Jh5ncAILFnSAABc0U"]
[Mon Jul 20 06:17:36.263426 2026] [security2:error] [pid 871012:tid 871105] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/privatekey.key"] [unique_id "al4R4LwiU-Jh5ncAILFnSQABdls"]
[Mon Jul 20 06:17:36.299620 2026] [security2:error] [pid 871012:tid 871096] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/id_rsa"] [unique_id "al4R4LwiU-Jh5ncAILFnSwABGFI"]
[Mon Jul 20 06:17:36.299789 2026] [security2:error] [pid 871012:tid 871048] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/id_dsa"] [unique_id "al4R4LwiU-Jh5ncAILFnSgABGCI"]
[Mon Jul 20 06:17:36.400356 2026] [security2:error] [pid 874439:tid 874596] [client 82.102.18.116:53954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.ferrarimenezes.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4R4I6ZSrFvCrJJhtQEhQAAABs"]
[Mon Jul 20 06:17:36.604203 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTAABGDE"]
[Mon Jul 20 06:17:36.604374 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTwABGHQ"]
[Mon Jul 20 06:17:36.604632 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnUAABGAY"]
[Mon Jul 20 06:17:36.604734 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTQABGGQ"]
[Mon Jul 20 06:17:36.604908 2026] [security2:error] [pid 871012:tid 871157] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R4LwiU-Jh5ncAILFnTgABGCk"]
[Mon Jul 20 06:17:36.625413 2026] [security2:error] [pid 874439:tid 874692] [client 57.141.18.75:36682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2Y6ZSrFvCrJJhtQCqgAAe2w"]
[Mon Jul 20 06:17:36.666576 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:53273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4R4I6ZSrFvCrJJhtQEhwAAAE4"], referer: https://ccsdifference.com/wp
[Mon Jul 20 06:17:37.202166 2026] [security2:error] [pid 874439:tid 874587] [client 185.132.186.86:49509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/firewall.php7"] [unique_id "al4R4Y6ZSrFvCrJJhtQEsQAAABI"]
[Mon Jul 20 06:17:37.472847 2026] [security2:error] [pid 871012:tid 871152] [client 57.141.18.8:58030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R2rwiU-Jh5ncAILFmpAABExc"]
[Mon Jul 20 06:17:37.542644 2026] [security2:error] [pid 874439:tid 874536] [remote 47.86.33.52:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQEygAAMmA"]
[Mon Jul 20 06:17:37.906031 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQE4QAAAE8"]
[Mon Jul 20 06:17:37.906172 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQE4QAAAE8"]
[Mon Jul 20 06:17:38.031073 2026] [security2:error] [pid 874439:tid 874684] [client 44.240.37.43:60258] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQE2AAAAEU"]
[Mon Jul 20 06:17:38.043069 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE6AAAAFw"]
[Mon Jul 20 06:17:38.043175 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE6AAAAFw"]
[Mon Jul 20 06:17:38.112980 2026] [security2:error] [pid 871012:tid 871110] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFnfgABZWA"]
[Mon Jul 20 06:17:38.113787 2026] [security2:error] [pid 871012:tid 871234] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFnfgABZWA"]
[Mon Jul 20 06:17:38.227599 2026] [security2:error] [pid 874439:tid 874654] [client 50.116.65.227:19360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4R4o6ZSrFvCrJJhtQE8wAAAFU"]
[Mon Jul 20 06:17:38.241368 2026] [security2:error] [pid 874439:tid 874599] [client 50.116.65.227:34304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4R4o6ZSrFvCrJJhtQE9AAAAB4"]
[Mon Jul 20 06:17:38.286340 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:6582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sql.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE9gAAAHc"]
[Mon Jul 20 06:17:38.286437 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:6582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sql.php"] [unique_id "al4R4o6ZSrFvCrJJhtQE9gAAAHc"]
[Mon Jul 20 06:17:38.519433 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFBwAAACw"]
[Mon Jul 20 06:17:38.519560 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFBwAAACw"]
[Mon Jul 20 06:17:38.639687 2026] [security2:error] [pid 874439:tid 874623] [client 20.63.63.128:7023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reop1.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFDAAAADY"]
[Mon Jul 20 06:17:38.639866 2026] [security2:error] [pid 874439:tid 874623] [client 20.63.63.128:7023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reop1.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFDAAAADY"]
[Mon Jul 20 06:17:38.681013 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:55411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4R4Y6ZSrFvCrJJhtQErgAAAHY"], referer: http://tntcatholic.com/wp
[Mon Jul 20 06:17:38.756419 2026] [security2:error] [pid 871012:tid 871249] [client 41.173.37.102:4367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFniwAAAXQ"]
[Mon Jul 20 06:17:38.756528 2026] [security2:error] [pid 871012:tid 871249] [client 41.173.37.102:4367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R4rwiU-Jh5ncAILFniwAAAXQ"]
[Mon Jul 20 06:17:38.787185 2026] [security2:error] [pid 874439:tid 874685] [client 104.234.53.84:48487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFGQAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:38.809827 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:7022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj18.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFGgAAAGI"]
[Mon Jul 20 06:17:38.809951 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:7022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj18.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFGgAAAGI"]
[Mon Jul 20 06:17:38.813461 2026] [security2:error] [pid 874439:tid 874601] [client 34.211.13.134:48226] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFDwAAACA"]
[Mon Jul 20 06:17:38.967643 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj15.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFJAAAAE0"]
[Mon Jul 20 06:17:38.967743 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/trusj15.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFJAAAAE0"]
[Mon Jul 20 06:17:38.998636 2026] [security2:error] [pid 874439:tid 874688] [client 185.132.186.92:56729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFKQAAAHc"]
[Mon Jul 20 06:17:39.072095 2026] [security2:error] [pid 874439:tid 874475] [remote 47.86.33.52:7388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4R446ZSrFvCrJJhtQFLgAAayM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:17:39.109029 2026] [security2:error] [pid 874439:tid 874664] [client 20.63.63.128:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/rft8.php"] [unique_id "al4R446ZSrFvCrJJhtQFMwAAAF8"]
[Mon Jul 20 06:17:39.109123 2026] [security2:error] [pid 874439:tid 874664] [client 20.63.63.128:6584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/rft8.php"] [unique_id "al4R446ZSrFvCrJJhtQFMwAAAF8"]
[Mon Jul 20 06:17:39.230689 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ai.php"] [unique_id "al4R47wiU-Jh5ncAILFnlAAAAXc"]
[Mon Jul 20 06:17:39.230796 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ai.php"] [unique_id "al4R47wiU-Jh5ncAILFnlAAAAXc"]
[Mon Jul 20 06:17:39.350394 2026] [security2:error] [pid 874439:tid 874662] [client 57.141.18.51:50456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R3I6ZSrFvCrJJhtQDbQAAXQk"]
[Mon Jul 20 06:17:39.406577 2026] [security2:error] [pid 871012:tid 871193] [client 20.63.63.128:6557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-rdf.php"] [unique_id "al4R47wiU-Jh5ncAILFnmAAAATw"]
[Mon Jul 20 06:17:39.406732 2026] [security2:error] [pid 871012:tid 871193] [client 20.63.63.128:6557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-rdf.php"] [unique_id "al4R47wiU-Jh5ncAILFnmAAAATw"]
[Mon Jul 20 06:17:39.566263 2026] [security2:error] [pid 871012:tid 871229] [client 20.63.63.128:6581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fx.php"] [unique_id "al4R47wiU-Jh5ncAILFnngAAAWA"]
[Mon Jul 20 06:17:39.566379 2026] [security2:error] [pid 871012:tid 871229] [client 20.63.63.128:6581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fx.php"] [unique_id "al4R47wiU-Jh5ncAILFnngAAAWA"]
[Mon Jul 20 06:17:39.693429 2026] [security2:error] [pid 874439:tid 874578] [client 171.60.139.123:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R446ZSrFvCrJJhtQFUgAAAAk"]
[Mon Jul 20 06:17:39.693565 2026] [security2:error] [pid 874439:tid 874578] [client 171.60.139.123:64704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R446ZSrFvCrJJhtQFUgAAAAk"]
[Mon Jul 20 06:17:39.728732 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R446ZSrFvCrJJhtQFVwAAAD0"]
[Mon Jul 20 06:17:39.728841 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6549] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R446ZSrFvCrJJhtQFVwAAAD0"]
[Mon Jul 20 06:17:39.901224 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:7002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dropdown.php"] [unique_id "al4R47wiU-Jh5ncAILFnpQAAAUg"]
[Mon Jul 20 06:17:39.901331 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:7002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dropdown.php"] [unique_id "al4R47wiU-Jh5ncAILFnpQAAAUg"]
[Mon Jul 20 06:17:39.905743 2026] [security2:error] [pid 874439:tid 874563] [remote 152.228.213.32:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4R446ZSrFvCrJJhtQFYgAAYXs"]
[Mon Jul 20 06:17:40.096787 2026] [security2:error] [pid 874439:tid 874493] [remote 152.228.213.32:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFagAAMzU"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:17:40.115487 2026] [security2:error] [pid 874439:tid 874632] [client 20.63.63.128:6990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file11.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFbgAAAD8"]
[Mon Jul 20 06:17:40.115570 2026] [security2:error] [pid 874439:tid 874632] [client 20.63.63.128:6990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file11.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFbgAAAD8"]
[Mon Jul 20 06:17:40.173656 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:55537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4R4o6ZSrFvCrJJhtQFFAAAAG0"], referer: http://inspirespublishing.com/wp
[Mon Jul 20 06:17:40.245255 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:7000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/png.php"] [unique_id "al4R5LwiU-Jh5ncAILFnqwAAAT0"]
[Mon Jul 20 06:17:40.245368 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:7000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/png.php"] [unique_id "al4R5LwiU-Jh5ncAILFnqwAAAT0"]
[Mon Jul 20 06:17:40.274879 2026] [security2:error] [pid 871012:tid 871180] [client 35.236.255.199:60503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.255.236.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "redneckrising.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnrQAAAS8"]
[Mon Jul 20 06:17:40.275027 2026] [security2:error] [pid 871012:tid 871180] [client 35.236.255.199:60503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "redneckrising.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnrQAAAS8"]
[Mon Jul 20 06:17:40.399010 2026] [security2:error] [pid 871012:tid 871122] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/graphql"] [unique_id "al4R5LwiU-Jh5ncAILFntAABTmw"]
[Mon Jul 20 06:17:40.421893 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-slss.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFggAAAD0"]
[Mon Jul 20 06:17:40.422015 2026] [security2:error] [pid 874439:tid 874630] [client 20.63.63.128:6538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-slss.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFggAAAD0"]
[Mon Jul 20 06:17:40.452165 2026] [security2:error] [pid 874439:tid 874674] [client 57.141.18.87:42386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R3Y6ZSrFvCrJJhtQDpgAAaUE"]
[Mon Jul 20 06:17:40.467177 2026] [security2:error] [pid 871012:tid 871129] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/.openclaw/openclaw.json"] [unique_id "al4R5LwiU-Jh5ncAILFnvAABNnM"]
[Mon Jul 20 06:17:40.467346 2026] [security2:error] [pid 871012:tid 871187] [client 35.245.65.174:33432] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/.openclaw/openclaw.json"] [unique_id "al4R5LwiU-Jh5ncAILFnvAABNnM"]
[Mon Jul 20 06:17:40.468695 2026] [security2:error] [pid 871012:tid 871031] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.openclaw/.env"] [unique_id "al4R5LwiU-Jh5ncAILFnvQABNhE"]
[Mon Jul 20 06:17:40.605293 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:6984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ah25.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFkgAAAF4"]
[Mon Jul 20 06:17:40.605453 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:6984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ah25.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFkgAAAF4"]
[Mon Jul 20 06:17:40.695407 2026] [security2:error] [pid 871012:tid 871167] [client 45.116.69.230:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnyAAAASI"]
[Mon Jul 20 06:17:40.695561 2026] [security2:error] [pid 871012:tid 871167] [client 45.116.69.230:56100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnyAAAASI"]
[Mon Jul 20 06:17:40.734607 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ccou.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFmwAAAEI"]
[Mon Jul 20 06:17:40.734775 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:6546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ccou.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFmwAAAEI"]
[Mon Jul 20 06:17:40.742050 2026] [security2:error] [pid 871012:tid 871057] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFntwABNis"]
[Mon Jul 20 06:17:40.787104 2026] [security2:error] [pid 871012:tid 871186] [client 103.141.108.143:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnygAAATU"]
[Mon Jul 20 06:17:40.787201 2026] [security2:error] [pid 871012:tid 871186] [client 103.141.108.143:58372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R5LwiU-Jh5ncAILFnygAAATU"]
[Mon Jul 20 06:17:40.799245 2026] [security2:error] [pid 874439:tid 874620] [client 185.132.186.76:64513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/about.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFnQAAADM"]
[Mon Jul 20 06:17:40.857613 2026] [security2:error] [pid 871012:tid 871224] [client 20.63.63.128:7011] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1.php"] [unique_id "al4R5LwiU-Jh5ncAILFnzwAAAVs"]
[Mon Jul 20 06:17:40.857785 2026] [security2:error] [pid 871012:tid 871224] [client 20.63.63.128:7011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1.php"] [unique_id "al4R5LwiU-Jh5ncAILFnzwAAAVs"]
[Mon Jul 20 06:17:40.857920 2026] [security2:error] [pid 871012:tid 871224] [client 20.63.63.128:7011] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/1.php"] [unique_id "al4R5LwiU-Jh5ncAILFnzwAAAVs"]
[Mon Jul 20 06:17:40.877395 2026] [security2:error] [pid 874439:tid 874648] [client 14.225.17.146:60130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4R446ZSrFvCrJJhtQFTQAAAE8"], referer: http://cloudspacesgroup.com/wp
[Mon Jul 20 06:17:41.064630 2026] [security2:error] [pid 871012:tid 871173] [client 20.63.63.128:7003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/900.php"] [unique_id "al4R5bwiU-Jh5ncAILFn1AAAASg"]
[Mon Jul 20 06:17:41.064741 2026] [security2:error] [pid 871012:tid 871173] [client 20.63.63.128:7003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/900.php"] [unique_id "al4R5bwiU-Jh5ncAILFn1AAAASg"]
[Mon Jul 20 06:17:41.124824 2026] [security2:error] [pid 871012:tid 871066] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnuAABNjQ"]
[Mon Jul 20 06:17:41.126308 2026] [security2:error] [pid 871012:tid 871117] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnuQABNmc"]
[Mon Jul 20 06:17:41.171015 2026] [security2:error] [pid 871012:tid 871081] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnvgABNkM"]
[Mon Jul 20 06:17:41.173087 2026] [security2:error] [pid 874439:tid 874495] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhgAADjc"], referer: https://guidehunting.com/.ssh/known_hosts
[Mon Jul 20 06:17:41.177365 2026] [security2:error] [pid 874439:tid 874532] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhQAADlw"], referer: https://guidehunting.com/private-key
[Mon Jul 20 06:17:41.177409 2026] [security2:error] [pid 874439:tid 874458] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhAAADhI"], referer: https://guidehunting.com/server.key
[Mon Jul 20 06:17:41.177864 2026] [security2:error] [pid 874439:tid 874549] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFgwAADm0"], referer: https://guidehunting.com/id_ed25519
[Mon Jul 20 06:17:41.186454 2026] [security2:error] [pid 871012:tid 871042] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnuwABNhw"]
[Mon Jul 20 06:17:41.188429 2026] [security2:error] [pid 874439:tid 874503] [remote 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFhwAADj8"], referer: https://guidehunting.com/id_ecdsa
[Mon Jul 20 06:17:41.198153 2026] [security2:error] [pid 874439:tid 874624] [client 20.63.63.128:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file59.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFsQAAADc"]
[Mon Jul 20 06:17:41.198255 2026] [security2:error] [pid 874439:tid 874624] [client 20.63.63.128:60994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file59.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFsQAAADc"]
[Mon Jul 20 06:17:41.302108 2026] [security2:error] [pid 871012:tid 871052] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnxAABKSY"]
[Mon Jul 20 06:17:41.302149 2026] [security2:error] [pid 871012:tid 871054] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnxgABKSg"]
[Mon Jul 20 06:17:41.302242 2026] [security2:error] [pid 871012:tid 871050] [remote 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5LwiU-Jh5ncAILFnxQABKSQ"]
[Mon Jul 20 06:17:41.420491 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amxloxxr.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFtgAAAHI"]
[Mon Jul 20 06:17:41.420613 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amxloxxr.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFtgAAAHI"]
[Mon Jul 20 06:17:41.560095 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:7012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aboutc.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFwAAAAEI"]
[Mon Jul 20 06:17:41.560211 2026] [security2:error] [pid 874439:tid 874635] [client 20.63.63.128:7012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aboutc.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFwAAAAEI"]
[Mon Jul 20 06:17:41.727181 2026] [security2:error] [pid 874439:tid 874593] [client 104.234.53.87:56257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFwgAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:41.758949 2026] [security2:error] [pid 871012:tid 871158] [client 168.144.100.227:55140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.100.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/xmlrpc.php"] [unique_id "al4R5bwiU-Jh5ncAILFn6QAAARk"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:41.794221 2026] [security2:error] [pid 874439:tid 874638] [client 20.63.63.128:6580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless18.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFywAAAEU"]
[Mon Jul 20 06:17:41.794323 2026] [security2:error] [pid 874439:tid 874638] [client 20.63.63.128:6580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless18.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQFywAAAEU"]
[Mon Jul 20 06:17:41.911388 2026] [security2:error] [pid 874439:tid 874602] [client 158.173.166.181:28055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R5Y6ZSrFvCrJJhtQF1AAAACE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:41.951358 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5AABGnA"]
[Mon Jul 20 06:17:41.954621 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn4wABGjg"]
[Mon Jul 20 06:17:41.970467 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5QABGkc"]
[Mon Jul 20 06:17:41.990231 2026] [security2:error] [pid 871012:tid 871144] [client 20.63.63.128:6544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/crgio.php"] [unique_id "al4R5bwiU-Jh5ncAILFn8wAAAQs"]
[Mon Jul 20 06:17:41.990331 2026] [security2:error] [pid 871012:tid 871144] [client 20.63.63.128:6544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/crgio.php"] [unique_id "al4R5bwiU-Jh5ncAILFn8wAAAQs"]
[Mon Jul 20 06:17:41.996363 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5gABGjM"]
[Mon Jul 20 06:17:41.996698 2026] [security2:error] [pid 871012:tid 871159] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5bwiU-Jh5ncAILFn5wABGmE"]
[Mon Jul 20 06:17:42.039445 2026] [security2:error] [pid 871012:tid 871080] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFn9gABQUI"]
[Mon Jul 20 06:17:42.039582 2026] [security2:error] [pid 871012:tid 871198] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFn9gABQUI"]
[Mon Jul 20 06:17:42.052489 2026] [security2:error] [pid 871012:tid 871088] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/api/graphql"] [unique_id "al4R5rwiU-Jh5ncAILFn9wABQEo"]
[Mon Jul 20 06:17:42.108511 2026] [security2:error] [pid 874439:tid 874576] [client 104.234.53.87:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF2gAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:42.138122 2026] [security2:error] [pid 871012:tid 871248] [client 20.63.63.128:7036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-act.php"] [unique_id "al4R5rwiU-Jh5ncAILFn-wAAAXM"]
[Mon Jul 20 06:17:42.138238 2026] [security2:error] [pid 871012:tid 871248] [client 20.63.63.128:7036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-act.php"] [unique_id "al4R5rwiU-Jh5ncAILFn-wAAAXM"]
[Mon Jul 20 06:17:42.254787 2026] [security2:error] [pid 874439:tid 874595] [client 103.203.57.3:58758] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.65.228"] [uri "/index.cgi"] [unique_id "al4R5o6ZSrFvCrJJhtQF6QAAABo"]
[Mon Jul 20 06:17:42.312972 2026] [security2:error] [pid 871012:tid 871211] [client 65.1.132.125:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoAQAAAU4"]
[Mon Jul 20 06:17:42.313104 2026] [security2:error] [pid 871012:tid 871211] [client 65.1.132.125:33976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoAQAAAU4"]
[Mon Jul 20 06:17:42.399170 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new4.php"] [unique_id "al4R5rwiU-Jh5ncAILFoDQAAAR8"]
[Mon Jul 20 06:17:42.399293 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new4.php"] [unique_id "al4R5rwiU-Jh5ncAILFoDQAAAR8"]
[Mon Jul 20 06:17:42.478410 2026] [security2:error] [pid 874439:tid 874665] [client 178.152.178.232:36711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF8QAAAGA"]
[Mon Jul 20 06:17:42.478542 2026] [security2:error] [pid 874439:tid 874665] [client 178.152.178.232:36711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF8QAAAGA"]
[Mon Jul 20 06:17:42.502382 2026] [security2:error] [pid 874439:tid 874643] [client 57.141.18.101:21984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R346ZSrFvCrJJhtQECgAASn4"]
[Mon Jul 20 06:17:42.594243 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-the.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF9AAAAE8"]
[Mon Jul 20 06:17:42.594359 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:6571] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-the.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF9AAAAE8"]
[Mon Jul 20 06:17:42.597578 2026] [security2:error] [pid 871012:tid 871155] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R5rwiU-Jh5ncAILFoAwABFn0"]
[Mon Jul 20 06:17:42.611998 2026] [security2:error] [pid 871012:tid 871152] [client 185.132.186.104:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/file/incpb.php"] [unique_id "al4R5rwiU-Jh5ncAILFoEQAAARM"]
[Mon Jul 20 06:17:42.658011 2026] [security2:error] [pid 871012:tid 871016] [remote 35.245.65.174:33432] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/v1/graphql"] [unique_id "al4R5rwiU-Jh5ncAILFoFQABOQI"]
[Mon Jul 20 06:17:42.736348 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atkno.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGAgAAAB0"]
[Mon Jul 20 06:17:42.736450 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atkno.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGAgAAAB0"]
[Mon Jul 20 06:17:42.762140 2026] [security2:error] [pid 871012:tid 871169] [client 103.77.203.233:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoGgAAASQ"]
[Mon Jul 20 06:17:42.762268 2026] [security2:error] [pid 871012:tid 871169] [client 103.77.203.233:52127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R5rwiU-Jh5ncAILFoGgAAASQ"]
[Mon Jul 20 06:17:42.821995 2026] [security2:error] [pid 874439:tid 874614] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF7AAALUQ"], referer: http://ardhalwafaa.com/wp
[Mon Jul 20 06:17:42.882827 2026] [security2:error] [pid 871012:tid 871178] [client 57.141.18.70:20798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R37wiU-Jh5ncAILFnPAABLWo"]
[Mon Jul 20 06:17:42.893527 2026] [security2:error] [pid 874439:tid 874578] [client 20.63.63.128:6530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mass.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDAAAAAk"]
[Mon Jul 20 06:17:42.893661 2026] [security2:error] [pid 874439:tid 874578] [client 20.63.63.128:6530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mass.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDAAAAAk"]
[Mon Jul 20 06:17:42.896132 2026] [security2:error] [pid 871012:tid 871086] [remote 57.141.18.57:27214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4R5rwiU-Jh5ncAILFoHwABRkg"]
[Mon Jul 20 06:17:42.939862 2026] [security2:error] [pid 874439:tid 874561] [remote 192.241.143.148:49192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDwAASHk"]
[Mon Jul 20 06:17:42.940046 2026] [security2:error] [pid 874439:tid 874641] [client 192.241.143.148:49192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R5o6ZSrFvCrJJhtQGDwAASHk"]
[Mon Jul 20 06:17:42.950767 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF-gAAVWo"], referer: https://guidehunting.com/webpack-stats.json
[Mon Jul 20 06:17:42.950968 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF-wAAVW4"], referer: https://guidehunting.com/_next/static/buildManifest.js
[Mon Jul 20 06:17:42.952230 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF-QAAVXQ"], referer: https://guidehunting.com/asset-manifest.json
[Mon Jul 20 06:17:42.969187 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF_gAAVQc"], referer: https://guidehunting.com/manifest.json
[Mon Jul 20 06:17:42.973574 2026] [security2:error] [pid 874439:tid 874577] [client 57.141.18.0:31142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R346ZSrFvCrJJhtQENgAACGE"]
[Mon Jul 20 06:17:42.984370 2026] [security2:error] [pid 874439:tid 874654] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R5o6ZSrFvCrJJhtQF_QAAVUo"], referer: https://guidehunting.com/build-manifest.json
[Mon Jul 20 06:17:43.097307 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wefile.php"] [unique_id "al4R546ZSrFvCrJJhtQGFAAAAEY"]
[Mon Jul 20 06:17:43.097423 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wefile.php"] [unique_id "al4R546ZSrFvCrJJhtQGFAAAAEY"]
[Mon Jul 20 06:17:43.228918 2026] [security2:error] [pid 874439:tid 874582] [client 20.63.63.128:6574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/min.php"] [unique_id "al4R546ZSrFvCrJJhtQGGAAAAA0"]
[Mon Jul 20 06:17:43.229028 2026] [security2:error] [pid 874439:tid 874582] [client 20.63.63.128:6574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/min.php"] [unique_id "al4R546ZSrFvCrJJhtQGGAAAAA0"]
[Mon Jul 20 06:17:43.389069 2026] [security2:error] [pid 874439:tid 874586] [client 20.63.63.128:6550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sid3.php"] [unique_id "al4R546ZSrFvCrJJhtQGIQAAABE"]
[Mon Jul 20 06:17:43.389154 2026] [security2:error] [pid 874439:tid 874586] [client 20.63.63.128:6550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sid3.php"] [unique_id "al4R546ZSrFvCrJJhtQGIQAAABE"]
[Mon Jul 20 06:17:43.523357 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fileas.php"] [unique_id "al4R546ZSrFvCrJJhtQGJgAAACw"]
[Mon Jul 20 06:17:43.523465 2026] [security2:error] [pid 874439:tid 874613] [client 20.63.63.128:6999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fileas.php"] [unique_id "al4R546ZSrFvCrJJhtQGJgAAACw"]
[Mon Jul 20 06:17:43.660905 2026] [security2:error] [pid 874439:tid 874657] [client 20.63.63.128:7016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless24.php"] [unique_id "al4R546ZSrFvCrJJhtQGLAAAAFg"]
[Mon Jul 20 06:17:43.661007 2026] [security2:error] [pid 874439:tid 874657] [client 20.63.63.128:7016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless24.php"] [unique_id "al4R546ZSrFvCrJJhtQGLAAAAFg"]
[Mon Jul 20 06:17:43.864274 2026] [security2:error] [pid 874439:tid 874629] [client 20.63.63.128:7018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fun.php"] [unique_id "al4R546ZSrFvCrJJhtQGOQAAADw"]
[Mon Jul 20 06:17:43.864390 2026] [security2:error] [pid 874439:tid 874629] [client 20.63.63.128:7018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fun.php"] [unique_id "al4R546ZSrFvCrJJhtQGOQAAADw"]
[Mon Jul 20 06:17:44.002009 2026] [security2:error] [pid 871012:tid 871208] [client 104.234.53.49:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4R6LwiU-Jh5ncAILFoOQAAAUs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:44.021579 2026] [security2:error] [pid 874439:tid 874628] [client 57.141.18.22:47002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R4I6ZSrFvCrJJhtQEowAAO1o"]
[Mon Jul 20 06:17:44.026730 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/drykl.php"] [unique_id "al4R6LwiU-Jh5ncAILFoOwAAAXc"]
[Mon Jul 20 06:17:44.026871 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:6542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/drykl.php"] [unique_id "al4R6LwiU-Jh5ncAILFoOwAAAXc"]
[Mon Jul 20 06:17:44.106099 2026] [security2:error] [pid 874439:tid 874677] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R546ZSrFvCrJJhtQGMwAAbEM"], referer: https://guidehunting.com/_next/build-manifest.json
[Mon Jul 20 06:17:44.161439 2026] [security2:error] [pid 874439:tid 874603] [client 20.63.63.128:6539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGSwAAACI"]
[Mon Jul 20 06:17:44.161528 2026] [security2:error] [pid 874439:tid 874603] [client 20.63.63.128:6539] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGSwAAACI"]
[Mon Jul 20 06:17:44.341323 2026] [security2:error] [pid 871012:tid 871172] [client 20.63.63.128:6233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mifta.php"] [unique_id "al4R6LwiU-Jh5ncAILFoRAAAASc"]
[Mon Jul 20 06:17:44.341440 2026] [security2:error] [pid 871012:tid 871172] [client 20.63.63.128:6233] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mifta.php"] [unique_id "al4R6LwiU-Jh5ncAILFoRAAAASc"]
[Mon Jul 20 06:17:44.383195 2026] [security2:error] [pid 871012:tid 871267] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R6LwiU-Jh5ncAILFoPwABhmI"]
[Mon Jul 20 06:17:44.409892 2026] [security2:error] [pid 874439:tid 874616] [client 185.132.186.71:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/stories/themes.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGUwAAAC8"]
[Mon Jul 20 06:17:44.542540 2026] [security2:error] [pid 871012:tid 871257] [client 20.63.63.128:7017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/class-t.api.php"] [unique_id "al4R6LwiU-Jh5ncAILFoSgAAAXw"]
[Mon Jul 20 06:17:44.542644 2026] [security2:error] [pid 871012:tid 871257] [client 20.63.63.128:7017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/class-t.api.php"] [unique_id "al4R6LwiU-Jh5ncAILFoSgAAAXw"]
[Mon Jul 20 06:17:44.613986 2026] [security2:error] [pid 874439:tid 874621] [client 181.224.94.124:9333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGXAAAADQ"]
[Mon Jul 20 06:17:44.614179 2026] [security2:error] [pid 874439:tid 874621] [client 181.224.94.124:9333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGXAAAADQ"]
[Mon Jul 20 06:17:44.678561 2026] [security2:error] [pid 874439:tid 874579] [client 20.63.63.128:7021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vgtyu.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGYQAAAAo"]
[Mon Jul 20 06:17:44.678705 2026] [security2:error] [pid 874439:tid 874579] [client 20.63.63.128:7021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vgtyu.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGYQAAAAo"]
[Mon Jul 20 06:17:44.702257 2026] [security2:error] [pid 871012:tid 871175] [client 57.141.18.99:46816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R4bwiU-Jh5ncAILFndwABKgQ"]
[Mon Jul 20 06:17:44.935647 2026] [security2:error] [pid 871012:tid 871163] [client 20.63.63.128:6209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atomlib.php"] [unique_id "al4R6LwiU-Jh5ncAILFoVwAAAR4"]
[Mon Jul 20 06:17:44.935778 2026] [security2:error] [pid 871012:tid 871163] [client 20.63.63.128:6209] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/atomlib.php"] [unique_id "al4R6LwiU-Jh5ncAILFoVwAAAR4"]
[Mon Jul 20 06:17:45.018717 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:63651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGWgAAABc"], referer: http://uritems.net/wp
[Mon Jul 20 06:17:45.054931 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.055012 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.9:61204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.055659 2026] [proxy:error] [pid 871012:tid 871234] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.055690 2026] [proxy_http:error] [pid 871012:tid 871234] [client 205.210.31.9:61204] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.060421 2026] [security2:error] [pid 874439:tid 874593] [client 20.63.63.128:6590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-access.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGdQAAABg"]
[Mon Jul 20 06:17:45.060532 2026] [security2:error] [pid 874439:tid 874593] [client 20.63.63.128:6590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-access.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGdQAAABg"]
[Mon Jul 20 06:17:45.069237 2026] [proxy:error] [pid 874439:tid 874600] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.069282 2026] [proxy_http:error] [pid 874439:tid 874600] [client 205.210.31.9:61220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.069811 2026] [proxy:error] [pid 874439:tid 874600] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:17:45.069835 2026] [proxy_http:error] [pid 874439:tid 874600] [client 205.210.31.9:61220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:17:45.235432 2026] [security2:error] [pid 874439:tid 874665] [client 20.63.63.128:6573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-update.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGhAAAAGA"]
[Mon Jul 20 06:17:45.235530 2026] [security2:error] [pid 874439:tid 874665] [client 20.63.63.128:6573] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-update.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGhAAAAGA"]
[Mon Jul 20 06:17:45.239970 2026] [core:error] [pid 874439:tid 874651] [client 14.225.17.146:63738] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:45.239984 2026] [core:error] [pid 874439:tid 874651] [client 14.225.17.146:63738] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:17:45.315741 2026] [security2:error] [pid 874439:tid 874599] [client 77.110.127.138:59448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4R6Y6ZSrFvCrJJhtQGiwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:45.419170 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/erty.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGjgAAAEY"]
[Mon Jul 20 06:17:45.419264 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/erty.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGjgAAAEY"]
[Mon Jul 20 06:17:45.602382 2026] [security2:error] [pid 871012:tid 871150] [client 20.63.63.128:6222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R6bwiU-Jh5ncAILFoagAAARE"]
[Mon Jul 20 06:17:45.602524 2026] [security2:error] [pid 871012:tid 871150] [client 20.63.63.128:6222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R6bwiU-Jh5ncAILFoagAAARE"]
[Mon Jul 20 06:17:45.688108 2026] [security2:error] [pid 874439:tid 874573] [client 14.225.17.146:63746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGnQAAAAQ"], referer: http://xp-design.co/wp
[Mon Jul 20 06:17:45.690067 2026] [security2:error] [pid 874439:tid 874629] [client 14.225.17.146:56744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGpgAAADw"], referer: http://walkingandtalking.net/wp
[Mon Jul 20 06:17:45.722572 2026] [security2:error] [pid 871012:tid 871248] [client 14.225.17.146:56801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4R6bwiU-Jh5ncAILFoaAAAAXM"], referer: http://slutilities.com/wp
[Mon Jul 20 06:17:45.760635 2026] [security2:error] [pid 874439:tid 874694] [client 20.63.63.128:6997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGsgAAAH0"]
[Mon Jul 20 06:17:45.760740 2026] [security2:error] [pid 874439:tid 874694] [client 20.63.63.128:6997] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGsgAAAH0"]
[Mon Jul 20 06:17:45.805658 2026] [security2:error] [pid 874439:tid 874660] [client 57.141.18.22:47014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R446ZSrFvCrJJhtQFKwAAW1E"]
[Mon Jul 20 06:17:45.982440 2026] [security2:error] [pid 871012:tid 871217] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4R6LwiU-Jh5ncAILFoSQAAAVQ"]
[Mon Jul 20 06:17:45.993675 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless5.php"] [unique_id "al4R6bwiU-Jh5ncAILFocQAAAR8"]
[Mon Jul 20 06:17:45.993843 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless5.php"] [unique_id "al4R6bwiU-Jh5ncAILFocQAAAR8"]
[Mon Jul 20 06:17:46.008908 2026] [security2:error] [pid 874439:tid 874608] [client 57.141.18.6:25192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R446ZSrFvCrJJhtQFOwAAJyY"]
[Mon Jul 20 06:17:46.166606 2026] [security2:error] [pid 874439:tid 874625] [client 20.63.63.128:6578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/t.php"] [unique_id "al4R6o6ZSrFvCrJJhtQGygAAADg"]
[Mon Jul 20 06:17:46.166723 2026] [security2:error] [pid 874439:tid 874625] [client 20.63.63.128:6578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/t.php"] [unique_id "al4R6o6ZSrFvCrJJhtQGygAAADg"]
[Mon Jul 20 06:17:46.200061 2026] [security2:error] [pid 874439:tid 874656] [client 185.132.186.72:42381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/theme-compat/footer-embed-function.php"] [unique_id "al4R6o6ZSrFvCrJJhtQGzQAAAFc"]
[Mon Jul 20 06:17:46.301104 2026] [security2:error] [pid 874439:tid 874525] [remote 81.173.115.7:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG0QAAB1U"]
[Mon Jul 20 06:17:46.361834 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:7009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xoot.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG0gAAAFw"]
[Mon Jul 20 06:17:46.361972 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:7009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xoot.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG0gAAAFw"]
[Mon Jul 20 06:17:46.522375 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:6260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xqq.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG3QAAABw"]
[Mon Jul 20 06:17:46.522514 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:6260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xqq.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG3QAAABw"]
[Mon Jul 20 06:17:46.558068 2026] [security2:error] [pid 871012:tid 871157] [client 14.225.17.146:56727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4R6rwiU-Jh5ncAILFofgAAARg"], referer: https://walkingandtalking.net/wp
[Mon Jul 20 06:17:46.590291 2026] [security2:error] [pid 874439:tid 874495] [remote 81.173.115.7:53748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG3wAADDc"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:17:46.686722 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-load.php"] [unique_id "al4R6rwiU-Jh5ncAILFohgAAAT4"]
[Mon Jul 20 06:17:46.686836 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6235] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-load.php"] [unique_id "al4R6rwiU-Jh5ncAILFohgAAAT4"]
[Mon Jul 20 06:17:46.690787 2026] [security2:error] [pid 871012:tid 871218] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R5rwiU-Jh5ncAILFoHgAAAVU"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:46.829813 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:61018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG7wAAAFc"]
[Mon Jul 20 06:17:46.829920 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:61018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG7wAAAFc"]
[Mon Jul 20 06:17:46.850537 2026] [security2:error] [pid 874439:tid 874645] [client 49.13.134.145:57758] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG6AAAAEw"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:17:46.914121 2026] [security2:error] [pid 874439:tid 874594] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG4AAAGVw"], referer: https://guidehunting.com/ssilko3
[Mon Jul 20 06:17:46.985346 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:6554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/i.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG9QAAADM"]
[Mon Jul 20 06:17:46.985431 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:6554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/i.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG9QAAADM"]
[Mon Jul 20 06:17:47.129921 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:6534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms-edit.php"] [unique_id "al4R646ZSrFvCrJJhtQG_QAAAGo"]
[Mon Jul 20 06:17:47.130041 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:6534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms-edit.php"] [unique_id "al4R646ZSrFvCrJJhtQG_QAAAGo"]
[Mon Jul 20 06:17:47.264320 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/v2.php"] [unique_id "al4R646ZSrFvCrJJhtQHBwAAABI"]
[Mon Jul 20 06:17:47.264454 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/v2.php"] [unique_id "al4R646ZSrFvCrJJhtQHBwAAABI"]
[Mon Jul 20 06:17:47.330899 2026] [security2:error] [pid 874439:tid 874612] [client 57.141.18.35:28860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R5I6ZSrFvCrJJhtQFpgAAKzA"]
[Mon Jul 20 06:17:47.397076 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:6535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new.php"] [unique_id "al4R646ZSrFvCrJJhtQHEQAAAGg"]
[Mon Jul 20 06:17:47.397174 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:6535] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/new.php"] [unique_id "al4R646ZSrFvCrJJhtQHEQAAAGg"]
[Mon Jul 20 06:17:47.428075 2026] [security2:error] [pid 871012:tid 871197] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R6rwiU-Jh5ncAILFokAAAAUA"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:47.483434 2026] [security2:error] [pid 874439:tid 874642] [client 50.116.65.227:20844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R646ZSrFvCrJJhtQHFQAAAEk"]
[Mon Jul 20 06:17:47.488307 2026] [security2:error] [pid 874439:tid 874687] [client 27.96.94.195:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R646ZSrFvCrJJhtQHFAAAAHY"]
[Mon Jul 20 06:17:47.488466 2026] [security2:error] [pid 874439:tid 874687] [client 27.96.94.195:37027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R646ZSrFvCrJJhtQHFAAAAHY"]
[Mon Jul 20 06:17:47.494974 2026] [security2:error] [pid 874439:tid 874595] [client 50.116.65.227:33054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R646ZSrFvCrJJhtQHFwAAABo"]
[Mon Jul 20 06:17:47.533818 2026] [security2:error] [pid 874439:tid 874684] [client 20.63.63.128:6558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/network/edit.php"] [unique_id "al4R646ZSrFvCrJJhtQHGgAAAHM"]
[Mon Jul 20 06:17:47.533947 2026] [security2:error] [pid 874439:tid 874684] [client 20.63.63.128:6558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-admin/network/edit.php"] [unique_id "al4R646ZSrFvCrJJhtQHGgAAAHM"]
[Mon Jul 20 06:17:47.691662 2026] [security2:error] [pid 871012:tid 871247] [client 20.63.63.128:6562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pouhg.php"] [unique_id "al4R67wiU-Jh5ncAILFopQAAAXI"]
[Mon Jul 20 06:17:47.691785 2026] [security2:error] [pid 871012:tid 871247] [client 20.63.63.128:6562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pouhg.php"] [unique_id "al4R67wiU-Jh5ncAILFopQAAAXI"]
[Mon Jul 20 06:17:47.886300 2026] [security2:error] [pid 871012:tid 871216] [client 20.63.63.128:6537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/cilus.php"] [unique_id "al4R67wiU-Jh5ncAILFoqAAAAVM"]
[Mon Jul 20 06:17:47.886401 2026] [security2:error] [pid 871012:tid 871216] [client 20.63.63.128:6537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/cilus.php"] [unique_id "al4R67wiU-Jh5ncAILFoqAAAAVM"]
[Mon Jul 20 06:17:48.004535 2026] [security2:error] [pid 874439:tid 874676] [client 185.132.186.74:29587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/firewall.php7"] [unique_id "al4R7I6ZSrFvCrJJhtQHRAAAAGs"]
[Mon Jul 20 06:17:48.038348 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file4.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSAAAAB0"]
[Mon Jul 20 06:17:48.038437 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:6556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file4.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSAAAAB0"]
[Mon Jul 20 06:17:48.172877 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:7035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/samll.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSgAAAAs"]
[Mon Jul 20 06:17:48.172957 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:7035] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/samll.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHSgAAAAs"]
[Mon Jul 20 06:17:48.208694 2026] [security2:error] [pid 871012:tid 871164] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R67wiU-Jh5ncAILFopgAAAR8"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:48.225120 2026] [security2:error] [pid 871012:tid 871152] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R67wiU-Jh5ncAILFoqQABE0Q"]
[Mon Jul 20 06:17:48.322945 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/Okxob.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHTwAAAFU"]
[Mon Jul 20 06:17:48.323032 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/Okxob.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHTwAAAFU"]
[Mon Jul 20 06:17:48.392374 2026] [security2:error] [pid 871012:tid 871227] [client 34.85.238.37:53274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.238.85.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fjy.yvs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R7LwiU-Jh5ncAILFouwAAAV4"]
[Mon Jul 20 06:17:48.465800 2026] [security2:error] [pid 874439:tid 874609] [client 20.63.63.128:60993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ok.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHWAAAACg"]
[Mon Jul 20 06:17:48.465902 2026] [security2:error] [pid 874439:tid 874609] [client 20.63.63.128:60993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ok.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHWAAAACg"]
[Mon Jul 20 06:17:48.568075 2026] [security2:error] [pid 874439:tid 874603] [client 46.110.96.34:9303] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7I6ZSrFvCrJJhtQHWwAAACI"]
[Mon Jul 20 06:17:48.568937 2026] [security2:error] [pid 871012:tid 871195] [client 46.110.96.34:23648] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7LwiU-Jh5ncAILFovwAAAT4"]
[Mon Jul 20 06:17:48.568979 2026] [security2:error] [pid 874439:tid 874649] [client 46.110.96.34:42077] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7I6ZSrFvCrJJhtQHXAAAAFA"]
[Mon Jul 20 06:17:48.598872 2026] [security2:error] [pid 871012:tid 871241] [client 20.63.63.128:6231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wuasr.php"] [unique_id "al4R7LwiU-Jh5ncAILFowQAAAWw"]
[Mon Jul 20 06:17:48.598970 2026] [security2:error] [pid 871012:tid 871241] [client 20.63.63.128:6231] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wuasr.php"] [unique_id "al4R7LwiU-Jh5ncAILFowQAAAWw"]
[Mon Jul 20 06:17:48.698000 2026] [security2:error] [pid 874439:tid 874556] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHZgAAQXQ"]
[Mon Jul 20 06:17:48.698163 2026] [security2:error] [pid 874439:tid 874634] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHZgAAQXQ"]
[Mon Jul 20 06:17:48.708700 2026] [security2:error] [pid 874439:tid 874608] [client 34.85.238.37:52096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4R7I6ZSrFvCrJJhtQHZwAAACc"]
[Mon Jul 20 06:17:48.780535 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:7014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless11.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHbgAAAAE"]
[Mon Jul 20 06:17:48.780633 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:7014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bless11.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHbgAAAAE"]
[Mon Jul 20 06:17:48.845499 2026] [security2:error] [pid 871012:tid 871268] [client 104.234.53.63:41739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4R7LwiU-Jh5ncAILFoxAAAAYc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:48.962451 2026] [security2:error] [pid 874439:tid 874680] [client 34.85.238.37:60360] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4R7I6ZSrFvCrJJhtQHewAAAG8"]
[Mon Jul 20 06:17:48.990371 2026] [security2:error] [pid 874439:tid 874616] [client 20.63.63.128:7020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-block.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHfgAAAC8"]
[Mon Jul 20 06:17:48.990528 2026] [security2:error] [pid 874439:tid 874616] [client 20.63.63.128:7020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-block.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHfgAAAC8"]
[Mon Jul 20 06:17:48.999989 2026] [security2:error] [pid 871012:tid 871237] [client 168.144.100.227:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "get.learnthissecret.com"] [uri "/index.php"] [unique_id "al4R7LwiU-Jh5ncAILFovQAAAWg"], referer: https://sisthemaspa.it/settori/retail//blog//wp-login.php
[Mon Jul 20 06:17:49.135254 2026] [security2:error] [pid 871012:tid 871207] [client 104.234.53.63:41739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R7bwiU-Jh5ncAILFozAAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:49.148150 2026] [security2:error] [pid 871012:tid 871228] [client 20.63.63.128:7032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aevly.php"] [unique_id "al4R7bwiU-Jh5ncAILFozgAAAV8"]
[Mon Jul 20 06:17:49.148259 2026] [security2:error] [pid 871012:tid 871228] [client 20.63.63.128:7032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aevly.php"] [unique_id "al4R7bwiU-Jh5ncAILFozgAAAV8"]
[Mon Jul 20 06:17:49.193695 2026] [security2:error] [pid 874439:tid 874604] [client 187.190.23.31:4610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHigAAI3g"]
[Mon Jul 20 06:17:49.201035 2026] [core:error] [pid 874439:tid 874596] [client 103.153.183.69:44022] AH10244: invalid URI path (/%2e./%2e./etc/passwd?_=oyuc8fnu&v=93r2e), referer: https://news.ycombinator.com/
[Mon Jul 20 06:17:49.202872 2026] [security2:error] [pid 874439:tid 874582] [client 127.0.0.1:44954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4R7Y6ZSrFvCrJJhtQHkQAAAA0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:17:49.281329 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:6552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hello.php"] [unique_id "al4R7bwiU-Jh5ncAILFo1QAAAT8"]
[Mon Jul 20 06:17:49.281436 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:6552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hello.php"] [unique_id "al4R7bwiU-Jh5ncAILFo1QAAAT8"]
[Mon Jul 20 06:17:49.346765 2026] [security2:error] [pid 874439:tid 874645] [client 41.173.37.102:4800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHnAAAAEw"]
[Mon Jul 20 06:17:49.346960 2026] [security2:error] [pid 874439:tid 874645] [client 41.173.37.102:4800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHnAAAAEw"]
[Mon Jul 20 06:17:49.374052 2026] [security2:error] [pid 874439:tid 874664] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHggAAXxs"], referer: https://guidehunting.com/ssilko4
[Mon Jul 20 06:17:49.412455 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:7015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-links-opml.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHogAAACk"]
[Mon Jul 20 06:17:49.412539 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:7015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-links-opml.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHogAAACk"]
[Mon Jul 20 06:17:49.415620 2026] [security2:error] [pid 871012:tid 871186] [client 34.85.238.37:64845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4R7bwiU-Jh5ncAILFo2gAAATU"]
[Mon Jul 20 06:17:49.418801 2026] [security2:error] [pid 874439:tid 874612] [client 46.110.96.34:63883] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7Y6ZSrFvCrJJhtQHpAAAACs"]
[Mon Jul 20 06:17:49.457126 2026] [security2:error] [pid 874439:tid 874647] [client 46.110.96.34:51113] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7Y6ZSrFvCrJJhtQHqQAAAE4"]
[Mon Jul 20 06:17:49.568696 2026] [security2:error] [pid 874439:tid 874677] [client 46.110.96.34:61756] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R7Y6ZSrFvCrJJhtQHsAAAAGw"]
[Mon Jul 20 06:17:49.603294 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/forbidals.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHsQAAAFU"]
[Mon Jul 20 06:17:49.603391 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:7037] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/forbidals.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHsQAAAFU"]
[Mon Jul 20 06:17:49.715145 2026] [security2:error] [pid 874439:tid 874595] [client 34.85.238.37:64307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4R7Y6ZSrFvCrJJhtQHuwAAABo"]
[Mon Jul 20 06:17:49.807153 2026] [security2:error] [pid 874439:tid 874655] [client 185.132.186.102:21201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/home/O-Simple.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHwgAAAFY"]
[Mon Jul 20 06:17:49.807156 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file30.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHwwAAADA"]
[Mon Jul 20 06:17:49.807247 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file30.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHwwAAADA"]
[Mon Jul 20 06:17:49.831285 2026] [security2:error] [pid 874439:tid 874531] [remote 5.161.225.162:57268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHxwAASFs"]
[Mon Jul 20 06:17:49.831421 2026] [security2:error] [pid 874439:tid 874641] [client 5.161.225.162:57268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHxwAASFs"]
[Mon Jul 20 06:17:49.965331 2026] [security2:error] [pid 874439:tid 874606] [client 20.63.63.128:6239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xda.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHzAAAACU"]
[Mon Jul 20 06:17:49.965463 2026] [security2:error] [pid 874439:tid 874606] [client 20.63.63.128:6239] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xda.php"] [unique_id "al4R7Y6ZSrFvCrJJhtQHzAAAACU"]
[Mon Jul 20 06:17:50.051439 2026] [security2:error] [pid 874439:tid 874645] [client 34.85.238.37:56467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4R7o6ZSrFvCrJJhtQH2AAAAEw"]
[Mon Jul 20 06:17:50.081546 2026] [security2:error] [pid 874439:tid 874640] [client 14.225.17.146:64269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHdAAAAEc"], referer: http://keywayconstructionclt.com/wp
[Mon Jul 20 06:17:50.106510 2026] [security2:error] [pid 874439:tid 874671] [client 20.63.63.128:6566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/z.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH3AAAAGY"]
[Mon Jul 20 06:17:50.106646 2026] [security2:error] [pid 874439:tid 874671] [client 20.63.63.128:6566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/z.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH3AAAAGY"]
[Mon Jul 20 06:17:50.190912 2026] [security2:error] [pid 874439:tid 874609] [client 14.182.134.81:46311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH4AAAKCA"]
[Mon Jul 20 06:17:50.260705 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/b.php"] [unique_id "al4R7rwiU-Jh5ncAILFo7gAAAR8"]
[Mon Jul 20 06:17:50.260879 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6265] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/b.php"] [unique_id "al4R7rwiU-Jh5ncAILFo7gAAAR8"]
[Mon Jul 20 06:17:50.295809 2026] [security2:error] [pid 874439:tid 874624] [client 113.172.54.19:60553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH6QAANyU"]
[Mon Jul 20 06:17:50.388414 2026] [security2:error] [pid 874439:tid 874649] [client 20.63.63.128:6532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9QAAAFA"]
[Mon Jul 20 06:17:50.388584 2026] [security2:error] [pid 874439:tid 874649] [client 20.63.63.128:6532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9QAAAFA"]
[Mon Jul 20 06:17:50.443024 2026] [security2:error] [pid 874439:tid 874694] [client 171.60.139.123:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9wAAAH0"]
[Mon Jul 20 06:17:50.443199 2026] [security2:error] [pid 874439:tid 874694] [client 171.60.139.123:65204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH9wAAAH0"]
[Mon Jul 20 06:17:50.488466 2026] [security2:error] [pid 874439:tid 874578] [client 41.237.101.92:55684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH-AAACXI"]
[Mon Jul 20 06:17:50.493566 2026] [security2:error] [pid 874439:tid 874643] [client 57.141.18.76:43230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6I6ZSrFvCrJJhtQGTwAASic"]
[Mon Jul 20 06:17:50.522705 2026] [security2:error] [pid 871012:tid 871148] [client 34.85.238.37:61348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4R7rwiU-Jh5ncAILFo9wAAAQ8"]
[Mon Jul 20 06:17:50.525994 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:60965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/app.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH_QAAACk"]
[Mon Jul 20 06:17:50.526098 2026] [security2:error] [pid 874439:tid 874610] [client 20.63.63.128:60965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/app.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH_QAAACk"]
[Mon Jul 20 06:17:50.593042 2026] [security2:error] [pid 874439:tid 874647] [client 77.110.127.138:59488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4R7o6ZSrFvCrJJhtQIBgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:17:50.687869 2026] [security2:error] [pid 874439:tid 874637] [client 14.225.17.146:53161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIAwAAAEQ"], referer: http://momheadquarters.com/wp
[Mon Jul 20 06:17:50.773485 2026] [security2:error] [pid 874439:tid 874595] [client 20.63.63.128:6227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-png.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIEgAAABo"]
[Mon Jul 20 06:17:50.773632 2026] [security2:error] [pid 874439:tid 874595] [client 20.63.63.128:6227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-png.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIEgAAABo"]
[Mon Jul 20 06:17:50.781491 2026] [security2:error] [pid 874439:tid 874597] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH8AAAABw"]
[Mon Jul 20 06:17:50.837245 2026] [security2:error] [pid 871012:tid 871149] [client 14.225.17.146:56665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4R7bwiU-Jh5ncAILFo4QAAARA"]
[Mon Jul 20 06:17:50.861675 2026] [security2:error] [pid 874439:tid 874614] [client 34.85.238.37:59715] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4R7o6ZSrFvCrJJhtQIHAAAAC0"]
[Mon Jul 20 06:17:50.879796 2026] [security2:error] [pid 874439:tid 874576] [client 45.157.112.60:43293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIHQAAAAc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:50.925266 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lib.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIIAAAAG0"]
[Mon Jul 20 06:17:50.925376 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lib.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIIAAAAG0"]
[Mon Jul 20 06:17:51.085866 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sys.php"] [unique_id "al4R746ZSrFvCrJJhtQIJwAAAHI"]
[Mon Jul 20 06:17:51.086020 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:6575] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sys.php"] [unique_id "al4R746ZSrFvCrJJhtQIJwAAAHI"]
[Mon Jul 20 06:17:51.187197 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:65047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIKgAAAHY"], referer: https://keywayconstructionclt.com/wp
[Mon Jul 20 06:17:51.264707 2026] [security2:error] [pid 874439:tid 874669] [client 34.85.238.37:49765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4R746ZSrFvCrJJhtQINwAAAGQ"]
[Mon Jul 20 06:17:51.284915 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:6555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/la.php"] [unique_id "al4R746ZSrFvCrJJhtQIOAAAAHA"]
[Mon Jul 20 06:17:51.285024 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:6555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/la.php"] [unique_id "al4R746ZSrFvCrJJhtQIOAAAAHA"]
[Mon Jul 20 06:17:51.374336 2026] [security2:error] [pid 874439:tid 874598] [client 45.116.69.230:56685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIQAAAAB0"]
[Mon Jul 20 06:17:51.374441 2026] [security2:error] [pid 874439:tid 874598] [client 45.116.69.230:56685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIQAAAAB0"]
[Mon Jul 20 06:17:51.375326 2026] [security2:error] [pid 874439:tid 874693] [client 84.233.195.150:49466] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R746ZSrFvCrJJhtQIQQAAAHw"]
[Mon Jul 20 06:17:51.409618 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:61002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/tires.php"] [unique_id "al4R746ZSrFvCrJJhtQISAAAAC0"]
[Mon Jul 20 06:17:51.409723 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:61002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/tires.php"] [unique_id "al4R746ZSrFvCrJJhtQISAAAAC0"]
[Mon Jul 20 06:17:51.464905 2026] [security2:error] [pid 874439:tid 874597] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIPQAAABw"]
[Mon Jul 20 06:17:51.554744 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lv.php"] [unique_id "al4R746ZSrFvCrJJhtQIUgAAACc"]
[Mon Jul 20 06:17:51.554924 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lv.php"] [unique_id "al4R746ZSrFvCrJJhtQIUgAAACc"]
[Mon Jul 20 06:17:51.607655 2026] [security2:error] [pid 871012:tid 871233] [client 185.132.186.72:33059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/class-wp-translation-file-mo-event.php"] [unique_id "al4R77wiU-Jh5ncAILFpEgAAAWQ"]
[Mon Jul 20 06:17:51.645067 2026] [security2:error] [pid 871012:tid 871243] [client 34.85.238.37:65317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4R77wiU-Jh5ncAILFpFQAAAW4"]
[Mon Jul 20 06:17:51.661273 2026] [security2:error] [pid 874439:tid 874655] [client 103.141.108.143:59045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIXAAAAFY"]
[Mon Jul 20 06:17:51.661441 2026] [security2:error] [pid 874439:tid 874655] [client 103.141.108.143:59045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R746ZSrFvCrJJhtQIXAAAAFY"]
[Mon Jul 20 06:17:51.735128 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:7001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/myfile.php"] [unique_id "al4R746ZSrFvCrJJhtQIYAAAAE8"]
[Mon Jul 20 06:17:51.735268 2026] [security2:error] [pid 874439:tid 874648] [client 20.63.63.128:7001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/myfile.php"] [unique_id "al4R746ZSrFvCrJJhtQIYAAAAE8"]
[Mon Jul 20 06:17:51.862255 2026] [security2:error] [pid 874439:tid 874669] [client 84.233.195.157:64532] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R746ZSrFvCrJJhtQIaAAAAGQ"]
[Mon Jul 20 06:17:51.866200 2026] [security2:error] [pid 871012:tid 871202] [client 20.63.63.128:6545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/06.php"] [unique_id "al4R77wiU-Jh5ncAILFpIAAAAUU"]
[Mon Jul 20 06:17:51.866307 2026] [security2:error] [pid 871012:tid 871202] [client 20.63.63.128:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/06.php"] [unique_id "al4R77wiU-Jh5ncAILFpIAAAAUU"]
[Mon Jul 20 06:17:51.955386 2026] [security2:error] [pid 874439:tid 874629] [client 34.85.238.37:65063] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4R746ZSrFvCrJJhtQIbgAAADw"]
[Mon Jul 20 06:17:51.996040 2026] [security2:error] [pid 874439:tid 874643] [client 20.63.63.128:7033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fs.php"] [unique_id "al4R746ZSrFvCrJJhtQIcQAAAEo"]
[Mon Jul 20 06:17:51.996182 2026] [security2:error] [pid 874439:tid 874643] [client 20.63.63.128:7033] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fs.php"] [unique_id "al4R746ZSrFvCrJJhtQIcQAAAEo"]
[Mon Jul 20 06:17:52.102064 2026] [security2:error] [pid 871012:tid 871208] [client 14.225.17.146:56807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4R7bwiU-Jh5ncAILFo5gAAAUs"], referer: http://webgardensbypaula.com/wp
[Mon Jul 20 06:17:52.129589 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:6228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/asasx.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIegAAAAE"]
[Mon Jul 20 06:17:52.129742 2026] [security2:error] [pid 874439:tid 874570] [client 20.63.63.128:6228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/asasx.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIegAAAAE"]
[Mon Jul 20 06:17:52.260588 2026] [security2:error] [pid 874439:tid 874652] [client 34.85.238.37:58008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fjy.yvs.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4R8I6ZSrFvCrJJhtQIfwAAAFM"]
[Mon Jul 20 06:17:52.290951 2026] [security2:error] [pid 874439:tid 874621] [client 57.141.18.87:29082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGswAANEU"]
[Mon Jul 20 06:17:52.304198 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:60952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIgAAAAF4"]
[Mon Jul 20 06:17:52.304354 2026] [security2:error] [pid 874439:tid 874663] [client 20.63.63.128:60952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIgAAAAF4"]
[Mon Jul 20 06:17:52.328479 2026] [security2:error] [pid 874439:tid 874584] [client 84.233.195.153:59585] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R8I6ZSrFvCrJJhtQIgwAAAA8"]
[Mon Jul 20 06:17:52.410487 2026] [security2:error] [pid 874439:tid 874580] [client 103.70.86.152:30136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIhgAAC2M"]
[Mon Jul 20 06:17:52.417228 2026] [security2:error] [pid 874439:tid 874488] [remote 192.241.143.148:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIjQAATjA"]
[Mon Jul 20 06:17:52.441306 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-good.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIjwAAAB4"]
[Mon Jul 20 06:17:52.441401 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7010] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-good.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIjwAAAB4"]
[Mon Jul 20 06:17:52.443595 2026] [security2:error] [pid 874439:tid 874534] [remote 57.141.18.24:55092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6432167"] [unique_id "al4R8I6ZSrFvCrJJhtQIkAAAAF4"]
[Mon Jul 20 06:17:52.458013 2026] [security2:error] [pid 874439:tid 874622] [client 57.141.18.10:44792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6Y6ZSrFvCrJJhtQGugAANTo"]
[Mon Jul 20 06:17:52.583848 2026] [security2:error] [pid 874439:tid 874604] [client 20.63.63.128:6216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/scxy.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIngAAACM"]
[Mon Jul 20 06:17:52.583954 2026] [security2:error] [pid 874439:tid 874604] [client 20.63.63.128:6216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/scxy.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIngAAACM"]
[Mon Jul 20 06:17:52.602786 2026] [security2:error] [pid 874439:tid 874555] [remote 192.241.143.148:59542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8I6ZSrFvCrJJhtQInwAAWHM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:52.678397 2026] [security2:error] [pid 874439:tid 874684] [client 14.225.17.146:52995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQIFQAAAHM"], referer: http://nurturemarple.co.uk/wp
[Mon Jul 20 06:17:52.687107 2026] [security2:error] [pid 871012:tid 871017] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R8LwiU-Jh5ncAILFpNwABZQM"]
[Mon Jul 20 06:17:52.687265 2026] [security2:error] [pid 871012:tid 871234] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R8LwiU-Jh5ncAILFpNwABZQM"]
[Mon Jul 20 06:17:52.769014 2026] [security2:error] [pid 871012:tid 871201] [client 20.63.63.128:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wmore1.php"] [unique_id "al4R8LwiU-Jh5ncAILFpOwAAAUQ"]
[Mon Jul 20 06:17:52.769162 2026] [security2:error] [pid 871012:tid 871201] [client 20.63.63.128:61045] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wmore1.php"] [unique_id "al4R8LwiU-Jh5ncAILFpOwAAAUQ"]
[Mon Jul 20 06:17:52.823334 2026] [security2:error] [pid 874439:tid 874683] [client 84.233.195.152:65082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/"] [unique_id "al4R8I6ZSrFvCrJJhtQIsQAAAHI"]
[Mon Jul 20 06:17:52.930608 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:6264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R8I6ZSrFvCrJJhtQItgAAAAs"]
[Mon Jul 20 06:17:52.930713 2026] [security2:error] [pid 874439:tid 874580] [client 20.63.63.128:6264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/like.php"] [unique_id "al4R8I6ZSrFvCrJJhtQItgAAAAs"]
[Mon Jul 20 06:17:53.005706 2026] [security2:error] [pid 874439:tid 874665] [client 98.159.234.160:49157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQIwgAAAGA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:17:53.062579 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:60964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQIxAAAAHc"]
[Mon Jul 20 06:17:53.062661 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:60964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/x.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQIxAAAAHc"]
[Mon Jul 20 06:17:53.128773 2026] [security2:error] [pid 871012:tid 871159] [client 178.152.178.232:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpRQAAARo"]
[Mon Jul 20 06:17:53.128894 2026] [security2:error] [pid 871012:tid 871159] [client 178.152.178.232:37885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpRQAAARo"]
[Mon Jul 20 06:17:53.155357 2026] [security2:error] [pid 871012:tid 871218] [client 50.116.65.227:26008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R8LwiU-Jh5ncAILFpPQAAAVU"]
[Mon Jul 20 06:17:53.213545 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:6979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xa.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI0AAAABs"]
[Mon Jul 20 06:17:53.213681 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:6979] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xa.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI0AAAABs"]
[Mon Jul 20 06:17:53.294965 2026] [security2:error] [pid 871012:tid 871198] [client 103.77.203.233:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpSgAAAUE"]
[Mon Jul 20 06:17:53.295134 2026] [security2:error] [pid 871012:tid 871198] [client 103.77.203.233:52688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpSgAAAUE"]
[Mon Jul 20 06:17:53.362443 2026] [security2:error] [pid 874439:tid 874696] [client 20.63.63.128:6559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kolda.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI2gAAAH8"]
[Mon Jul 20 06:17:53.362599 2026] [security2:error] [pid 874439:tid 874696] [client 20.63.63.128:6559] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kolda.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI2gAAAH8"]
[Mon Jul 20 06:17:53.368047 2026] [security2:error] [pid 871012:tid 871150] [client 50.116.65.227:26024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R8bwiU-Jh5ncAILFpSAAAARE"]
[Mon Jul 20 06:17:53.390946 2026] [security2:error] [pid 871012:tid 871016] [remote 57.141.18.34:20366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6432167"] [unique_id "al4R8bwiU-Jh5ncAILFpTgABcgI"]
[Mon Jul 20 06:17:53.469792 2026] [security2:error] [pid 874439:tid 874572] [client 57.141.18.22:63550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R6o6ZSrFvCrJJhtQG7gAAAz8"]
[Mon Jul 20 06:17:53.478333 2026] [security2:error] [pid 871012:tid 871249] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R8bwiU-Jh5ncAILFpRwABdH0"]
[Mon Jul 20 06:17:53.495207 2026] [security2:error] [pid 874439:tid 874641] [client 20.63.63.128:6585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-aothait.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI5gAAAEg"]
[Mon Jul 20 06:17:53.495321 2026] [security2:error] [pid 874439:tid 874641] [client 20.63.63.128:6585] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-aothait.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI5gAAAEg"]
[Mon Jul 20 06:17:53.518918 2026] [security2:error] [pid 874439:tid 874553] [remote 162.19.86.63:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI6QAAK3E"]
[Mon Jul 20 06:17:53.625720 2026] [security2:error] [pid 871012:tid 871121] [remote 5.161.225.162:57274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpVgABMWs"]
[Mon Jul 20 06:17:53.626038 2026] [security2:error] [pid 871012:tid 871182] [client 5.161.225.162:57274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4R8bwiU-Jh5ncAILFpVgABMWs"]
[Mon Jul 20 06:17:53.650461 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ftde.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI9wAAAB4"]
[Mon Jul 20 06:17:53.650569 2026] [security2:error] [pid 874439:tid 874599] [client 20.63.63.128:7024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ftde.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI9wAAAB4"]
[Mon Jul 20 06:17:53.728122 2026] [security2:error] [pid 874439:tid 874538] [remote 162.19.86.63:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI_AAACWI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:17:53.782542 2026] [security2:error] [pid 874439:tid 874644] [client 20.63.63.128:6560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vx.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJAwAAAEs"]
[Mon Jul 20 06:17:53.782649 2026] [security2:error] [pid 874439:tid 874644] [client 20.63.63.128:6560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/vx.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJAwAAAEs"]
[Mon Jul 20 06:17:53.875093 2026] [security2:error] [pid 874439:tid 874641] [client 185.132.186.81:37639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/vars-soap.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJDgAAAEg"]
[Mon Jul 20 06:17:53.979667 2026] [security2:error] [pid 871012:tid 871186] [client 20.63.63.128:6551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/a5.php"] [unique_id "al4R8bwiU-Jh5ncAILFpXQAAATU"]
[Mon Jul 20 06:17:53.979773 2026] [security2:error] [pid 871012:tid 871186] [client 20.63.63.128:6551] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/a5.php"] [unique_id "al4R8bwiU-Jh5ncAILFpXQAAATU"]
[Mon Jul 20 06:17:54.124568 2026] [security2:error] [pid 874439:tid 874466] [remote 65.109.34.160:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.34.109.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJGAAAVRo"]
[Mon Jul 20 06:17:54.161804 2026] [security2:error] [pid 871012:tid 871240] [client 20.63.63.128:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-sing.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZQAAAWs"]
[Mon Jul 20 06:17:54.161944 2026] [security2:error] [pid 871012:tid 871240] [client 20.63.63.128:60936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-sing.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZQAAAWs"]
[Mon Jul 20 06:17:54.200720 2026] [security2:error] [pid 871012:tid 871263] [client 14.225.17.146:50995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4R8LwiU-Jh5ncAILFpNAAAAYI"], referer: http://grecruit.online/wp
[Mon Jul 20 06:17:54.289087 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/database.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZgAAAU4"]
[Mon Jul 20 06:17:54.289198 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:61029] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/database.php"] [unique_id "al4R8rwiU-Jh5ncAILFpZgAAAU4"]
[Mon Jul 20 06:17:54.365362 2026] [security2:error] [pid 874439:tid 874627] [client 14.225.17.146:59572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJGgAAADo"], referer: https://nurturemarple.co.uk/wp
[Mon Jul 20 06:17:54.375861 2026] [security2:error] [pid 874439:tid 874552] [remote 65.109.34.160:48292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.34.109.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJIQAAWXA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:54.420896 2026] [security2:error] [pid 874439:tid 874456] [remote 57.141.18.8:37802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4R8o6ZSrFvCrJJhtQJJAAAARA"]
[Mon Jul 20 06:17:54.445305 2026] [security2:error] [pid 874439:tid 874690] [client 14.225.17.146:65013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIsgAAAHk"], referer: http://amalia-capital.com/wp
[Mon Jul 20 06:17:54.455958 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/explorer/index_.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJKQAAAC0"]
[Mon Jul 20 06:17:54.456054 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6215] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/explorer/index_.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJKQAAAC0"]
[Mon Jul 20 06:17:54.536007 2026] [security2:error] [pid 874439:tid 874472] [remote 20.153.140.50:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJKwAAVCA"]
[Mon Jul 20 06:17:54.584891 2026] [security2:error] [pid 874439:tid 874636] [client 57.141.18.40:27358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R646ZSrFvCrJJhtQHLQAAQ2k"]
[Mon Jul 20 06:17:54.591357 2026] [security2:error] [pid 871012:tid 871160] [client 20.63.63.128:6250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-at.php"] [unique_id "al4R8rwiU-Jh5ncAILFpcQAAARs"]
[Mon Jul 20 06:17:54.591441 2026] [security2:error] [pid 871012:tid 871160] [client 20.63.63.128:6250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-at.php"] [unique_id "al4R8rwiU-Jh5ncAILFpcQAAARs"]
[Mon Jul 20 06:17:54.669283 2026] [security2:error] [pid 874439:tid 874573] [client 14.225.17.146:53413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJIAAAAAQ"], referer: http://aljosour-alarabia.com/wp
[Mon Jul 20 06:17:54.786165 2026] [security2:error] [pid 871012:tid 871220] [client 20.63.63.128:7004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-wz.php"] [unique_id "al4R8rwiU-Jh5ncAILFpewAAAVc"]
[Mon Jul 20 06:17:54.786306 2026] [security2:error] [pid 871012:tid 871220] [client 20.63.63.128:7004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-wz.php"] [unique_id "al4R8rwiU-Jh5ncAILFpewAAAVc"]
[Mon Jul 20 06:17:54.880144 2026] [security2:error] [pid 874439:tid 874581] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJLgAADCU"], referer: https://guidehunting.com/ssilko5
[Mon Jul 20 06:17:54.988982 2026] [security2:error] [pid 874439:tid 874476] [remote 20.153.140.50:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJQQAAIiQ"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:17:54.993459 2026] [security2:error] [pid 874439:tid 874654] [client 50.116.65.227:56810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4R8o6ZSrFvCrJJhtQJQwAAAFU"]
[Mon Jul 20 06:17:54.999831 2026] [security2:error] [pid 871012:tid 871198] [client 20.63.63.128:7039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-ver.php"] [unique_id "al4R8rwiU-Jh5ncAILFphAAAAUE"]
[Mon Jul 20 06:17:54.999928 2026] [security2:error] [pid 871012:tid 871198] [client 20.63.63.128:7039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-ver.php"] [unique_id "al4R8rwiU-Jh5ncAILFphAAAAUE"]
[Mon Jul 20 06:17:55.006142 2026] [security2:error] [pid 871012:tid 871200] [client 50.116.65.227:26096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4R87wiU-Jh5ncAILFphQAAARE"]
[Mon Jul 20 06:17:55.047274 2026] [security2:error] [pid 874439:tid 874631] [client 123.21.68.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIrQAAAD4"]
[Mon Jul 20 06:17:55.128022 2026] [security2:error] [pid 874439:tid 874576] [client 181.224.94.124:6360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJSgAAAAc"]
[Mon Jul 20 06:17:55.128273 2026] [security2:error] [pid 874439:tid 874576] [client 181.224.94.124:6360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJSgAAAAc"]
[Mon Jul 20 06:17:55.182045 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp5.php"] [unique_id "al4R87wiU-Jh5ncAILFpkAAAAR8"]
[Mon Jul 20 06:17:55.182177 2026] [security2:error] [pid 871012:tid 871164] [client 20.63.63.128:6217] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp5.php"] [unique_id "al4R87wiU-Jh5ncAILFpkAAAAR8"]
[Mon Jul 20 06:17:55.186378 2026] [security2:error] [pid 871012:tid 871190] [client 50.116.65.227:26114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4R87wiU-Jh5ncAILFpkQAAATk"]
[Mon Jul 20 06:17:55.198269 2026] [security2:error] [pid 871012:tid 871265] [client 50.116.65.227:26122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4R87wiU-Jh5ncAILFpkgAAAYQ"]
[Mon Jul 20 06:17:55.205046 2026] [security2:error] [pid 871012:tid 871084] [remote 100.42.189.89:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFpkwABYkY"]
[Mon Jul 20 06:17:55.228532 2026] [security2:error] [pid 874439:tid 874567] [remote 8.217.108.67:59208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJTgAAHX8"]
[Mon Jul 20 06:17:55.228756 2026] [security2:error] [pid 874439:tid 874598] [client 8.217.108.67:59208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJTgAAHX8"]
[Mon Jul 20 06:17:55.252180 2026] [security2:error] [pid 871012:tid 871215] [client 57.141.18.22:63560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R7LwiU-Jh5ncAILFotwABUh0"]
[Mon Jul 20 06:17:55.268993 2026] [security2:error] [pid 874439:tid 874665] [client 14.225.17.146:65060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJCQAAAGA"], referer: http://chestermonty.com/wp
[Mon Jul 20 06:17:55.309798 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-pp.php"] [unique_id "al4R846ZSrFvCrJJhtQJVQAAACc"]
[Mon Jul 20 06:17:55.309921 2026] [security2:error] [pid 874439:tid 874608] [client 20.63.63.128:6225] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-pp.php"] [unique_id "al4R846ZSrFvCrJJhtQJVQAAACc"]
[Mon Jul 20 06:17:55.436884 2026] [security2:error] [pid 871012:tid 871107] [remote 100.42.189.89:41216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFpmAABS10"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:17:55.437021 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/w3lls.php"] [unique_id "al4R87wiU-Jh5ncAILFplwAAAT4"]
[Mon Jul 20 06:17:55.437128 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:6561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/w3lls.php"] [unique_id "al4R87wiU-Jh5ncAILFplwAAAT4"]
[Mon Jul 20 06:17:55.559701 2026] [security2:error] [pid 871012:tid 871035] [remote 57.141.18.87:42036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4R87wiU-Jh5ncAILFpngABIhU"]
[Mon Jul 20 06:17:55.584793 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:6547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sbhu.php"] [unique_id "al4R87wiU-Jh5ncAILFpoAAAAT0"]
[Mon Jul 20 06:17:55.584881 2026] [security2:error] [pid 871012:tid 871194] [client 20.63.63.128:6547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sbhu.php"] [unique_id "al4R87wiU-Jh5ncAILFpoAAAAT0"]
[Mon Jul 20 06:17:55.654262 2026] [security2:error] [pid 874439:tid 874684] [client 185.132.186.78:54579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/av.php"] [unique_id "al4R846ZSrFvCrJJhtQJaQAAAHM"]
[Mon Jul 20 06:17:55.673476 2026] [security2:error] [pid 871012:tid 871128] [remote 72.167.132.114:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFppgABa3I"]
[Mon Jul 20 06:17:55.695517 2026] [security2:error] [pid 874439:tid 874638] [client 103.153.183.69:60012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/passwd"] [unique_id "al4R846ZSrFvCrJJhtQJbAAAAEU"], referer: https://www.reddit.com/
[Mon Jul 20 06:17:55.717623 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4R846ZSrFvCrJJhtQJbgAAAE0"]
[Mon Jul 20 06:17:55.717765 2026] [security2:error] [pid 874439:tid 874646] [client 20.63.63.128:6271] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4R846ZSrFvCrJJhtQJbgAAAE0"]
[Mon Jul 20 06:17:55.774289 2026] [security2:error] [pid 874439:tid 874558] [remote 124.55.178.99:57838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJcAAAQ3Y"]
[Mon Jul 20 06:17:55.774474 2026] [security2:error] [pid 874439:tid 874636] [client 124.55.178.99:57838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R846ZSrFvCrJJhtQJcAAAQ3Y"]
[Mon Jul 20 06:17:55.780418 2026] [security2:error] [pid 874439:tid 874571] [client 104.234.53.82:42547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4R846ZSrFvCrJJhtQJcgAAAAI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:55.793497 2026] [security2:error] [pid 874439:tid 874583] [client 57.141.18.48:42004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R7I6ZSrFvCrJJhtQHaQAADgc"]
[Mon Jul 20 06:17:55.888683 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/favicon.php"] [unique_id "al4R87wiU-Jh5ncAILFprwAAARo"]
[Mon Jul 20 06:17:55.888805 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/favicon.php"] [unique_id "al4R87wiU-Jh5ncAILFprwAAARo"]
[Mon Jul 20 06:17:55.939264 2026] [security2:error] [pid 871012:tid 871063] [remote 72.167.132.114:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4R87wiU-Jh5ncAILFpsAABWDE"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:17:56.060652 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:6579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/txets.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJgwAAAE4"]
[Mon Jul 20 06:17:56.060774 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:6579] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/txets.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJgwAAAE4"]
[Mon Jul 20 06:17:56.160595 2026] [security2:error] [pid 874439:tid 874610] [client 14.225.17.146:51790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJMwAAACk"], referer: http://709fx.com/wp
[Mon Jul 20 06:17:56.228203 2026] [security2:error] [pid 874439:tid 874589] [client 20.63.63.128:6531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-su.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJjQAAABQ"]
[Mon Jul 20 06:17:56.228301 2026] [security2:error] [pid 874439:tid 874589] [client 20.63.63.128:6531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-su.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJjQAAABQ"]
[Mon Jul 20 06:17:56.314661 2026] [security2:error] [pid 874439:tid 874634] [client 14.225.17.146:54153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJjgAAAEE"], referer: https://chestermonty.com/wp
[Mon Jul 20 06:17:56.324197 2026] [security2:error] [pid 874439:tid 874644] [client 14.225.17.146:53729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJNwAAAEs"], referer: http://adirondackengineering.com/wp
[Mon Jul 20 06:17:56.358090 2026] [core:error] [pid 874439:tid 874569] [client 14.225.17.146:59352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/wp
[Mon Jul 20 06:17:56.358126 2026] [core:error] [pid 874439:tid 874569] [client 14.225.17.146:59352] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/wp
[Mon Jul 20 06:17:56.367127 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:61007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff.php"] [unique_id "al4R9LwiU-Jh5ncAILFptwAAAXc"]
[Mon Jul 20 06:17:56.367215 2026] [security2:error] [pid 871012:tid 871252] [client 20.63.63.128:61007] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff.php"] [unique_id "al4R9LwiU-Jh5ncAILFptwAAAXc"]
[Mon Jul 20 06:17:56.506388 2026] [security2:error] [pid 874439:tid 874575] [client 20.63.63.128:6565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reze.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJoAAAAAY"]
[Mon Jul 20 06:17:56.506494 2026] [security2:error] [pid 874439:tid 874575] [client 20.63.63.128:6565] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/reze.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJoAAAAAY"]
[Mon Jul 20 06:17:56.647555 2026] [security2:error] [pid 871012:tid 871267] [client 20.63.63.128:61043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/666.php"] [unique_id "al4R9LwiU-Jh5ncAILFpvwAAAYY"]
[Mon Jul 20 06:17:56.647677 2026] [security2:error] [pid 871012:tid 871267] [client 20.63.63.128:61043] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/666.php"] [unique_id "al4R9LwiU-Jh5ncAILFpvwAAAYY"]
[Mon Jul 20 06:17:56.787150 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:6978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wehrman.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJsgAAADI"]
[Mon Jul 20 06:17:56.787258 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:6978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wehrman.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJsgAAADI"]
[Mon Jul 20 06:17:56.880159 2026] [security2:error] [pid 874439:tid 874660] [client 103.153.183.69:60012] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/shadow"] [unique_id "al4R9I6ZSrFvCrJJhtQJvAAAAFs"], referer: https://www.bing.com/search?q=wud1ut
[Mon Jul 20 06:17:56.886696 2026] [security2:error] [pid 871012:tid 871028] [remote 57.141.18.7:38292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4R9LwiU-Jh5ncAILFpyAABKA4"]
[Mon Jul 20 06:17:56.949498 2026] [security2:error] [pid 874439:tid 874583] [client 20.63.63.128:6263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-conflg.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJvgAAAA4"]
[Mon Jul 20 06:17:56.949573 2026] [security2:error] [pid 874439:tid 874583] [client 20.63.63.128:6263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-conflg.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJvgAAAA4"]
[Mon Jul 20 06:17:57.084183 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:6243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff1.php"] [unique_id "al4R9bwiU-Jh5ncAILFp1QAAAUg"]
[Mon Jul 20 06:17:57.084282 2026] [security2:error] [pid 871012:tid 871205] [client 20.63.63.128:6243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ff1.php"] [unique_id "al4R9bwiU-Jh5ncAILFp1QAAAUg"]
[Mon Jul 20 06:17:57.180026 2026] [security2:error] [pid 874439:tid 874596] [client 114.119.153.158:28593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/tours/golf-in-the-algarve/"] [unique_id "al4R9Y6ZSrFvCrJJhtQJyAAAABs"], referer: https://www.savilerowtravel.com/destinations/portugal
[Mon Jul 20 06:17:57.195815 2026] [security2:error] [pid 871012:tid 871244] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R9LwiU-Jh5ncAILFpygABbzU"]
[Mon Jul 20 06:17:57.243156 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fff.php"] [unique_id "al4R9bwiU-Jh5ncAILFp4AAAARM"]
[Mon Jul 20 06:17:57.243316 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:61021] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/fff.php"] [unique_id "al4R9bwiU-Jh5ncAILFp4AAAARM"]
[Mon Jul 20 06:17:57.318034 2026] [security2:error] [pid 874439:tid 874670] [client 57.141.18.72:60050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R7o6ZSrFvCrJJhtQH8gAAZSI"]
[Mon Jul 20 06:17:57.383312 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amax.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ2QAAAEY"]
[Mon Jul 20 06:17:57.383427 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:61019] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/amax.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ2QAAAEY"]
[Mon Jul 20 06:17:57.448607 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ3AAAADM"]
[Mon Jul 20 06:17:57.448732 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64038] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ3AAAADM"]
[Mon Jul 20 06:17:57.461451 2026] [security2:error] [pid 871012:tid 871154] [client 185.132.186.63:34753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/style.php%20"] [unique_id "al4R9bwiU-Jh5ncAILFp4gAAARU"]
[Mon Jul 20 06:17:57.524455 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:61026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-firewall.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ4wAAAH4"]
[Mon Jul 20 06:17:57.524539 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:61026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-firewall.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ4wAAAH4"]
[Mon Jul 20 06:17:57.526199 2026] [security2:error] [pid 874439:tid 874445] [remote 45.90.123.233:56734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ5AAATwU"]
[Mon Jul 20 06:17:57.526344 2026] [security2:error] [pid 874439:tid 874648] [client 45.90.123.233:56734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ5AAATwU"]
[Mon Jul 20 06:17:57.573719 2026] [security2:error] [pid 874439:tid 874643] [client 46.110.96.34:10165] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ5wAAAEo"]
[Mon Jul 20 06:17:57.591726 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R9bwiU-Jh5ncAILFp5gAAAU4"]
[Mon Jul 20 06:17:57.591875 2026] [security2:error] [pid 871012:tid 871211] [client 20.63.63.128:63945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4R9bwiU-Jh5ncAILFp5gAAAU4"]
[Mon Jul 20 06:17:57.604349 2026] [security2:error] [pid 874439:tid 874692] [client 46.110.96.34:48608] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ6gAAAHs"]
[Mon Jul 20 06:17:57.636923 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:51768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4R9I6ZSrFvCrJJhtQJhgAAAFQ"], referer: http://cephasnext.com/wp
[Mon Jul 20 06:17:57.656767 2026] [security2:error] [pid 871012:tid 871233] [client 20.63.63.128:6577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/appt.php"] [unique_id "al4R9bwiU-Jh5ncAILFp6gAAAWQ"]
[Mon Jul 20 06:17:57.656865 2026] [security2:error] [pid 871012:tid 871233] [client 20.63.63.128:6577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/appt.php"] [unique_id "al4R9bwiU-Jh5ncAILFp6gAAAWQ"]
[Mon Jul 20 06:17:57.719792 2026] [security2:error] [pid 874439:tid 874672] [client 46.110.96.34:60293] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ8wAAAGc"]
[Mon Jul 20 06:17:57.788446 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:6232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-thi.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-AAAAG8"]
[Mon Jul 20 06:17:57.788536 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:6232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-thi.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-AAAAG8"]
[Mon Jul 20 06:17:57.792664 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/sql.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-gAAABs"]
[Mon Jul 20 06:17:57.792729 2026] [security2:error] [pid 874439:tid 874596] [client 20.63.63.128:64028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/sql.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQJ-gAAABs"]
[Mon Jul 20 06:17:57.942418 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/jj.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKBgAAAG0"]
[Mon Jul 20 06:17:57.942514 2026] [security2:error] [pid 874439:tid 874678] [client 20.63.63.128:6270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/jj.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKBgAAAG0"]
[Mon Jul 20 06:17:57.997492 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/1index.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKCQAAACs"]
[Mon Jul 20 06:17:57.997612 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:64014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/1index.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKCQAAACs"]
[Mon Jul 20 06:17:58.100438 2026] [security2:error] [pid 874439:tid 874622] [client 20.63.63.128:6218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/333.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKDwAAADU"]
[Mon Jul 20 06:17:58.100548 2026] [security2:error] [pid 874439:tid 874622] [client 20.63.63.128:6218] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/333.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKDwAAADU"]
[Mon Jul 20 06:17:58.247301 2026] [security2:error] [pid 874439:tid 874668] [client 20.63.63.128:6536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/albin.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKHwAAAGM"]
[Mon Jul 20 06:17:58.247388 2026] [security2:error] [pid 874439:tid 874668] [client 20.63.63.128:6536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/albin.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKHwAAAGM"]
[Mon Jul 20 06:17:58.281900 2026] [security2:error] [pid 874439:tid 874569] [client 173.252.87.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKGgAAAAA"]
[Mon Jul 20 06:17:58.307643 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/reop1.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJAAAAE4"]
[Mon Jul 20 06:17:58.307733 2026] [security2:error] [pid 874439:tid 874647] [client 20.63.63.128:63994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/reop1.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJAAAAE4"]
[Mon Jul 20 06:17:58.342823 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.87:29092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIWQAAaEk"]
[Mon Jul 20 06:17:58.358065 2026] [security2:error] [pid 874439:tid 874610] [client 104.234.53.84:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJgAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:17:58.396844 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/66.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJwAAAEE"]
[Mon Jul 20 06:17:58.396953 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/66.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKJwAAAEE"]
[Mon Jul 20 06:17:58.443421 2026] [security2:error] [pid 874439:tid 874618] [client 57.141.18.106:43218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R746ZSrFvCrJJhtQIWgAAMRg"]
[Mon Jul 20 06:17:58.467969 2026] [security2:error] [pid 874439:tid 874589] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKFwAAFG8"], referer: https://guidehunting.com/ssilko6
[Mon Jul 20 06:17:58.523462 2026] [security2:error] [pid 874439:tid 874669] [client 20.63.63.128:6257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/motu.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKLwAAAGQ"]
[Mon Jul 20 06:17:58.523569 2026] [security2:error] [pid 874439:tid 874669] [client 20.63.63.128:6257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/motu.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKLwAAAGQ"]
[Mon Jul 20 06:17:58.649475 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/trusj18.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKOAAAADI"]
[Mon Jul 20 06:17:58.649618 2026] [security2:error] [pid 874439:tid 874619] [client 20.63.63.128:63939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/trusj18.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKOAAAADI"]
[Mon Jul 20 06:17:58.704253 2026] [security2:error] [pid 874439:tid 874503] [remote 41.186.86.12:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKOwAAJD8"]
[Mon Jul 20 06:17:58.739205 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kj.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKPgAAABI"]
[Mon Jul 20 06:17:58.739285 2026] [security2:error] [pid 874439:tid 874587] [client 20.63.63.128:6543] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/kj.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKPgAAABI"]
[Mon Jul 20 06:17:58.806573 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/trusj15.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRAAAAGU"]
[Mon Jul 20 06:17:58.806685 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/trusj15.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRAAAAGU"]
[Mon Jul 20 06:17:58.827072 2026] [security2:error] [pid 874439:tid 874657] [client 27.96.94.195:38202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRwAAAFg"]
[Mon Jul 20 06:17:58.827842 2026] [security2:error] [pid 874439:tid 874657] [client 27.96.94.195:38202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRwAAAFg"]
[Mon Jul 20 06:17:58.871127 2026] [security2:error] [pid 874439:tid 874653] [client 20.63.63.128:6992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp4.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKSQAAAFQ"]
[Mon Jul 20 06:17:58.871225 2026] [security2:error] [pid 874439:tid 874653] [client 20.63.63.128:6992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp4.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKSQAAAFQ"]
[Mon Jul 20 06:17:58.940740 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/rft8.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKTwAAADQ"]
[Mon Jul 20 06:17:58.940866 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:64041] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/rft8.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKTwAAADQ"]
[Mon Jul 20 06:17:59.015860 2026] [security2:error] [pid 874439:tid 874577] [client 57.141.18.2:20246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8I6ZSrFvCrJJhtQIeQAACFw"]
[Mon Jul 20 06:17:59.057370 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:6211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file61.php"] [unique_id "al4R946ZSrFvCrJJhtQKVAAAACs"]
[Mon Jul 20 06:17:59.057512 2026] [security2:error] [pid 874439:tid 874612] [client 20.63.63.128:6211] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/file61.php"] [unique_id "al4R946ZSrFvCrJJhtQKVAAAACs"]
[Mon Jul 20 06:17:59.087234 2026] [security2:error] [pid 871012:tid 871182] [client 20.63.63.128:63959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/ai.php"] [unique_id "al4R97wiU-Jh5ncAILFp_wAAATE"]
[Mon Jul 20 06:17:59.087377 2026] [security2:error] [pid 871012:tid 871182] [client 20.63.63.128:63959] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/ai.php"] [unique_id "al4R97wiU-Jh5ncAILFp_wAAATE"]
[Mon Jul 20 06:17:59.098360 2026] [security2:error] [pid 874439:tid 874661] [client 112.208.70.94:45642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4R946ZSrFvCrJJhtQKVgAAAFw"]
[Mon Jul 20 06:17:59.098498 2026] [security2:error] [pid 874439:tid 874661] [client 112.208.70.94:45642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4R946ZSrFvCrJJhtQKVgAAAFw"]
[Mon Jul 20 06:17:59.118219 2026] [security2:error] [pid 874439:tid 874684] [client 41.83.32.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKRgAAcyE"]
[Mon Jul 20 06:17:59.191894 2026] [security2:error] [pid 874439:tid 874537] [remote 41.186.86.12:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4R946ZSrFvCrJJhtQKXAAAcmE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:17:59.268727 2026] [security2:error] [pid 874439:tid 874677] [client 20.63.63.128:6244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp.php"] [unique_id "al4R946ZSrFvCrJJhtQKYAAAAGw"]
[Mon Jul 20 06:17:59.268865 2026] [security2:error] [pid 874439:tid 874677] [client 20.63.63.128:6244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp.php"] [unique_id "al4R946ZSrFvCrJJhtQKYAAAAGw"]
[Mon Jul 20 06:17:59.328402 2026] [security2:error] [pid 871012:tid 871061] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqEwABNy8"]
[Mon Jul 20 06:17:59.328594 2026] [security2:error] [pid 871012:tid 871188] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqEwABNy8"]
[Mon Jul 20 06:17:59.346245 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-rdf.php"] [unique_id "al4R946ZSrFvCrJJhtQKZgAAAB0"]
[Mon Jul 20 06:17:59.346397 2026] [security2:error] [pid 874439:tid 874598] [client 20.63.63.128:64015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-rdf.php"] [unique_id "al4R946ZSrFvCrJJhtQKZgAAAB0"]
[Mon Jul 20 06:17:59.392901 2026] [security2:error] [pid 871012:tid 871234] [client 20.63.63.128:61001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-trackback.php"] [unique_id "al4R97wiU-Jh5ncAILFqFAAAAWU"]
[Mon Jul 20 06:17:59.393017 2026] [security2:error] [pid 871012:tid 871234] [client 20.63.63.128:61001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-trackback.php"] [unique_id "al4R97wiU-Jh5ncAILFqFAAAAWU"]
[Mon Jul 20 06:17:59.427730 2026] [security2:error] [pid 874439:tid 874442] [remote 47.86.33.52:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R946ZSrFvCrJJhtQKaAAANwI"]
[Mon Jul 20 06:17:59.496809 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/fx.php"] [unique_id "al4R97wiU-Jh5ncAILFqFQAAARM"]
[Mon Jul 20 06:17:59.497198 2026] [security2:error] [pid 871012:tid 871152] [client 20.63.63.128:63941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/fx.php"] [unique_id "al4R97wiU-Jh5ncAILFqFQAAARM"]
[Mon Jul 20 06:17:59.515920 2026] [security2:error] [pid 874439:tid 874591] [client 20.63.63.128:6246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/db.php"] [unique_id "al4R946ZSrFvCrJJhtQKagAAABY"]
[Mon Jul 20 06:17:59.516060 2026] [security2:error] [pid 874439:tid 874591] [client 20.63.63.128:6246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/db.php"] [unique_id "al4R946ZSrFvCrJJhtQKagAAABY"]
[Mon Jul 20 06:17:59.677622 2026] [security2:error] [pid 871012:tid 871161] [client 20.63.63.128:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/NewFile.php"] [unique_id "al4R97wiU-Jh5ncAILFqGgAAARw"]
[Mon Jul 20 06:17:59.677707 2026] [security2:error] [pid 871012:tid 871161] [client 20.63.63.128:60974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/NewFile.php"] [unique_id "al4R97wiU-Jh5ncAILFqGgAAARw"]
[Mon Jul 20 06:17:59.744122 2026] [security2:error] [pid 874439:tid 874574] [client 20.63.63.128:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKdgAAAAU"]
[Mon Jul 20 06:17:59.744199 2026] [security2:error] [pid 874439:tid 874574] [client 20.63.63.128:64048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKdgAAAAU"]
[Mon Jul 20 06:17:59.831579 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKfAAAADA"]
[Mon Jul 20 06:17:59.831658 2026] [security2:error] [pid 874439:tid 874617] [client 20.63.63.128:6528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/xxx.php"] [unique_id "al4R946ZSrFvCrJJhtQKfAAAADA"]
[Mon Jul 20 06:17:59.846657 2026] [security2:error] [pid 874439:tid 874466] [remote 47.86.33.52:25064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4R946ZSrFvCrJJhtQKfQAAbho"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:17:59.920761 2026] [security2:error] [pid 871012:tid 871238] [client 41.173.37.102:5236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqIQAAAWk"]
[Mon Jul 20 06:17:59.920864 2026] [security2:error] [pid 871012:tid 871238] [client 41.173.37.102:5236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4R97wiU-Jh5ncAILFqIQAAAWk"]
[Mon Jul 20 06:17:59.964994 2026] [security2:error] [pid 874439:tid 874682] [client 20.63.63.128:61042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms.php"] [unique_id "al4R946ZSrFvCrJJhtQKhAAAAHE"]
[Mon Jul 20 06:17:59.965096 2026] [security2:error] [pid 874439:tid 874682] [client 20.63.63.128:61042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/ms.php"] [unique_id "al4R946ZSrFvCrJJhtQKhAAAAHE"]
[Mon Jul 20 06:18:00.143161 2026] [security2:error] [pid 871012:tid 871214] [client 20.63.63.128:6238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mini.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJgAAAVE"]
[Mon Jul 20 06:18:00.143299 2026] [security2:error] [pid 871012:tid 871214] [client 20.63.63.128:6238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/mini.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJgAAAVE"]
[Mon Jul 20 06:18:00.146813 2026] [security2:error] [pid 871012:tid 871166] [client 20.63.63.128:64016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/dropdown.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJwAAASE"]
[Mon Jul 20 06:18:00.146896 2026] [security2:error] [pid 871012:tid 871166] [client 20.63.63.128:64016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/dropdown.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJwAAASE"]
[Mon Jul 20 06:18:00.287889 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:6563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/first.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKkAAAAEA"]
[Mon Jul 20 06:18:00.288023 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:6563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/first.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKkAAAAEA"]
[Mon Jul 20 06:18:00.293032 2026] [security2:error] [pid 871012:tid 871147] [client 185.132.186.76:38591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/files.php"] [unique_id "al4R-LwiU-Jh5ncAILFqMAAAAQ4"]
[Mon Jul 20 06:18:00.361963 2026] [security2:error] [pid 871012:tid 871220] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJAABVxA"]
[Mon Jul 20 06:18:00.396460 2026] [security2:error] [pid 874439:tid 874602] [client 57.141.18.77:64328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQI3gAAIXk"]
[Mon Jul 20 06:18:00.497652 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/0okj.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKngAAAD4"]
[Mon Jul 20 06:18:00.497777 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:61014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/0okj.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKngAAAD4"]
[Mon Jul 20 06:18:00.506584 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/file11.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKnwAAAHc"]
[Mon Jul 20 06:18:00.506725 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/file11.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKnwAAAHc"]
[Mon Jul 20 06:18:00.516943 2026] [security2:error] [pid 871012:tid 871252] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqMQAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:00.586523 2026] [security2:error] [pid 874439:tid 874476] [remote 72.167.132.114:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKpwAANiQ"]
[Mon Jul 20 06:18:00.604147 2026] [security2:error] [pid 871012:tid 871202] [client 104.234.53.91:56839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqNQAAAUU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:00.683368 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/grsiuk.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKrAAAAFU"]
[Mon Jul 20 06:18:00.683491 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:57820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/grsiuk.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKrAAAAFU"]
[Mon Jul 20 06:18:00.711304 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:63938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/png.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKsAAAABw"]
[Mon Jul 20 06:18:00.711427 2026] [security2:error] [pid 874439:tid 874597] [client 20.63.63.128:63938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/png.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKsAAAABw"]
[Mon Jul 20 06:18:00.765781 2026] [security2:error] [pid 874439:tid 874486] [remote 188.138.102.156:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKtAAASS4"]
[Mon Jul 20 06:18:00.812094 2026] [security2:error] [pid 871012:tid 871189] [client 20.63.63.128:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/shell20211028.php"] [unique_id "al4R-LwiU-Jh5ncAILFqPQAAATg"]
[Mon Jul 20 06:18:00.812212 2026] [security2:error] [pid 871012:tid 871189] [client 20.63.63.128:60934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/shell20211028.php"] [unique_id "al4R-LwiU-Jh5ncAILFqPQAAATg"]
[Mon Jul 20 06:18:00.904592 2026] [security2:error] [pid 874439:tid 874691] [client 57.141.18.3:38574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8Y6ZSrFvCrJJhtQJDwAAehE"]
[Mon Jul 20 06:18:00.905125 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-slss.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKvQAAAEA"]
[Mon Jul 20 06:18:00.905216 2026] [security2:error] [pid 874439:tid 874633] [client 20.63.63.128:63970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-slss.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKvQAAAEA"]
[Mon Jul 20 06:18:00.967008 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:6568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/revealability.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKwwAAAGI"]
[Mon Jul 20 06:18:00.967138 2026] [security2:error] [pid 874439:tid 874667] [client 20.63.63.128:6568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/revealability.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKwwAAAGI"]
[Mon Jul 20 06:18:00.976959 2026] [security2:error] [pid 874439:tid 874480] [remote 188.138.102.156:46544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKxgAALSg"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:18:00.987450 2026] [security2:error] [pid 874439:tid 874470] [remote 72.167.132.114:50244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4R-I6ZSrFvCrJJhtQKxQAAFB4"], referer: https://mrbambooplus.com/wp-login.php
[Mon Jul 20 06:18:01.090319 2026] [security2:error] [pid 874439:tid 874601] [client 20.63.63.128:61009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/btx25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzAAAACA"]
[Mon Jul 20 06:18:01.090420 2026] [security2:error] [pid 874439:tid 874601] [client 20.63.63.128:61009] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/btx25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzAAAACA"]
[Mon Jul 20 06:18:01.124641 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:64026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/ah25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzwAAAD4"]
[Mon Jul 20 06:18:01.124736 2026] [security2:error] [pid 874439:tid 874631] [client 20.63.63.128:64026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/ah25.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQKzwAAAD4"]
[Mon Jul 20 06:18:01.178019 2026] [security2:error] [pid 871012:tid 871224] [client 171.60.139.123:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R-bwiU-Jh5ncAILFqQgAAAVs"]
[Mon Jul 20 06:18:01.178146 2026] [security2:error] [pid 871012:tid 871224] [client 171.60.139.123:49334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4R-bwiU-Jh5ncAILFqQgAAAVs"]
[Mon Jul 20 06:18:01.221214 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bthil.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK3AAAAFw"]
[Mon Jul 20 06:18:01.221297 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:6583] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bthil.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK3AAAAFw"]
[Mon Jul 20 06:18:01.337185 2026] [security2:error] [pid 874439:tid 874655] [client 104.234.53.90:32807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK5AAAAFY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:01.379895 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/ccou.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6AAAADM"]
[Mon Jul 20 06:18:01.379984 2026] [security2:error] [pid 874439:tid 874620] [client 20.63.63.128:64040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/ccou.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6AAAADM"]
[Mon Jul 20 06:18:01.391437 2026] [security2:error] [pid 874439:tid 874576] [client 20.63.63.128:6981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hplfuns.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6gAAAAc"]
[Mon Jul 20 06:18:01.391562 2026] [security2:error] [pid 874439:tid 874576] [client 20.63.63.128:6981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/hplfuns.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6gAAAAc"]
[Mon Jul 20 06:18:01.490559 2026] [security2:error] [pid 874439:tid 874584] [client 57.141.18.114:27928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R8o6ZSrFvCrJJhtQJLQAADzE"]
[Mon Jul 20 06:18:01.520369 2026] [security2:error] [pid 874439:tid 874660] [client 20.63.63.128:57547] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "webdisk.theablesea.com"] [uri "/1.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK7wAAAFs"]
[Mon Jul 20 06:18:01.520481 2026] [security2:error] [pid 874439:tid 874660] [client 20.63.63.128:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/1.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK7wAAAFs"]
[Mon Jul 20 06:18:01.520580 2026] [security2:error] [pid 874439:tid 874660] [client 20.63.63.128:57547] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/1.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK7wAAAFs"]
[Mon Jul 20 06:18:01.538287 2026] [security2:error] [pid 871012:tid 871208] [client 20.63.63.128:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/error.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTQAAAUs"]
[Mon Jul 20 06:18:01.538391 2026] [security2:error] [pid 871012:tid 871208] [client 20.63.63.128:57814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/error.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTQAAAUs"]
[Mon Jul 20 06:18:01.545535 2026] [security2:error] [pid 874439:tid 874581] [client 14.225.17.146:59333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK4wAAAAw"]
[Mon Jul 20 06:18:01.655915 2026] [security2:error] [pid 871012:tid 871222] [client 20.63.63.128:57581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/900.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTgAAAVk"]
[Mon Jul 20 06:18:01.656034 2026] [security2:error] [pid 871012:tid 871222] [client 20.63.63.128:57581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/900.php"] [unique_id "al4R-bwiU-Jh5ncAILFqTgAAAVk"]
[Mon Jul 20 06:18:01.670550 2026] [security2:error] [pid 874439:tid 874645] [client 20.63.63.128:6254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK9gAAAEw"]
[Mon Jul 20 06:18:01.670629 2026] [security2:error] [pid 874439:tid 874645] [client 20.63.63.128:6254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/edit.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK9gAAAEw"]
[Mon Jul 20 06:18:01.800326 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/file59.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLAgAAAAA"]
[Mon Jul 20 06:18:01.801164 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:57557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/file59.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLAgAAAAA"]
[Mon Jul 20 06:18:01.827395 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pass4.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLBQAAAFw"]
[Mon Jul 20 06:18:01.827496 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:60958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/pass4.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLBQAAAFw"]
[Mon Jul 20 06:18:01.889821 2026] [security2:error] [pid 874439:tid 874624] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK8wAAN08"], referer: https://guidehunting.com/ssilko7
[Mon Jul 20 06:18:01.941543 2026] [security2:error] [pid 874439:tid 874627] [client 20.63.63.128:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/amxloxxr.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLDQAAADo"]
[Mon Jul 20 06:18:01.941713 2026] [security2:error] [pid 874439:tid 874627] [client 20.63.63.128:64051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/amxloxxr.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLDQAAADo"]
[Mon Jul 20 06:18:01.957217 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sadcut1.php"] [unique_id "al4R-bwiU-Jh5ncAILFqWQAAARo"]
[Mon Jul 20 06:18:01.957327 2026] [security2:error] [pid 871012:tid 871159] [client 20.63.63.128:61051] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/sadcut1.php"] [unique_id "al4R-bwiU-Jh5ncAILFqWQAAARo"]
[Mon Jul 20 06:18:02.070635 2026] [security2:error] [pid 874439:tid 874625] [client 45.116.69.230:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEQAAADg"]
[Mon Jul 20 06:18:02.070890 2026] [security2:error] [pid 874439:tid 874625] [client 45.116.69.230:57207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEQAAADg"]
[Mon Jul 20 06:18:02.094710 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:6267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bgymj.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEwAAAEY"]
[Mon Jul 20 06:18:02.094744 2026] [security2:error] [pid 874439:tid 874695] [client 185.132.186.53:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/av.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEgAAAH4"]
[Mon Jul 20 06:18:02.094861 2026] [security2:error] [pid 874439:tid 874639] [client 20.63.63.128:6267] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/bgymj.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLEwAAAEY"]
[Mon Jul 20 06:18:02.112674 2026] [security2:error] [pid 874439:tid 874572] [client 20.63.63.128:64027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/aboutc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLFQAAAAM"]
[Mon Jul 20 06:18:02.112788 2026] [security2:error] [pid 874439:tid 874572] [client 20.63.63.128:64027] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/aboutc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLFQAAAAM"]
[Mon Jul 20 06:18:02.162569 2026] [security2:error] [pid 874439:tid 874613] [client 3.109.4.218:16572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLGAAAACw"]
[Mon Jul 20 06:18:02.250781 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yas.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLIgAAAC0"]
[Mon Jul 20 06:18:02.250880 2026] [security2:error] [pid 874439:tid 874614] [client 20.63.63.128:6252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yas.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLIgAAAC0"]
[Mon Jul 20 06:18:02.290878 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:64058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/bless18.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLJQAAAGg"]
[Mon Jul 20 06:18:02.291092 2026] [security2:error] [pid 874439:tid 874673] [client 20.63.63.128:64058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/bless18.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLJQAAAGg"]
[Mon Jul 20 06:18:02.328724 2026] [security2:error] [pid 874439:tid 874608] [client 50.116.65.227:55346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R-o6ZSrFvCrJJhtQLJwAAACc"]
[Mon Jul 20 06:18:02.342745 2026] [security2:error] [pid 874439:tid 874583] [client 50.116.65.227:60458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4R-o6ZSrFvCrJJhtQLKAAAAHE"]
[Mon Jul 20 06:18:02.380158 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:7000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dx.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLLQAAADQ"]
[Mon Jul 20 06:18:02.380249 2026] [security2:error] [pid 874439:tid 874621] [client 20.63.63.128:7000] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/dx.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLLQAAADQ"]
[Mon Jul 20 06:18:02.462058 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/crgio.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLMwAAAGU"]
[Mon Jul 20 06:18:02.462157 2026] [security2:error] [pid 874439:tid 874670] [client 20.63.63.128:64057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/crgio.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLMwAAAGU"]
[Mon Jul 20 06:18:02.528500 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:7034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yellow.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLOQAAAHI"]
[Mon Jul 20 06:18:02.528603 2026] [security2:error] [pid 874439:tid 874683] [client 20.63.63.128:7034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/yellow.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLOQAAAHI"]
[Mon Jul 20 06:18:02.624786 2026] [security2:error] [pid 871012:tid 871235] [client 20.63.63.128:63940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-act.php"] [unique_id "al4R-rwiU-Jh5ncAILFqZwAAAWY"]
[Mon Jul 20 06:18:02.624925 2026] [security2:error] [pid 871012:tid 871235] [client 20.63.63.128:63940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-act.php"] [unique_id "al4R-rwiU-Jh5ncAILFqZwAAAWY"]
[Mon Jul 20 06:18:02.653944 2026] [security2:error] [pid 874439:tid 874671] [client 103.141.108.143:59548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLQAAAAGY"]
[Mon Jul 20 06:18:02.654086 2026] [security2:error] [pid 874439:tid 874671] [client 103.141.108.143:59548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLQAAAAGY"]
[Mon Jul 20 06:18:02.678312 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-der.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLRAAAAEE"]
[Mon Jul 20 06:18:02.678456 2026] [security2:error] [pid 874439:tid 874634] [client 20.63.63.128:6245] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/wp-der.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLRAAAAEE"]
[Mon Jul 20 06:18:02.745072 2026] [security2:error] [pid 871012:tid 871174] [client 57.141.18.99:23678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R87wiU-Jh5ncAILFpqQABKVk"]
[Mon Jul 20 06:18:02.809554 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/new4.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLUgAAAFc"]
[Mon Jul 20 06:18:02.809672 2026] [security2:error] [pid 874439:tid 874656] [client 20.63.63.128:63943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/new4.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLUgAAAFc"]
[Mon Jul 20 06:18:02.840552 2026] [security2:error] [pid 874439:tid 874607] [client 20.63.63.128:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lala.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLVAAAACY"]
[Mon Jul 20 06:18:02.840644 2026] [security2:error] [pid 874439:tid 874607] [client 20.63.63.128:60961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/lala.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLVAAAACY"]
[Mon Jul 20 06:18:02.953894 2026] [security2:error] [pid 874439:tid 874691] [client 20.63.63.128:63993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-the.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLWgAAAHo"]
[Mon Jul 20 06:18:02.953984 2026] [security2:error] [pid 874439:tid 874691] [client 20.63.63.128:63993] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-the.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLWgAAAHo"]
[Mon Jul 20 06:18:02.976656 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:59690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQK6wAAAA0"], referer: http://ghivs.com/wp
[Mon Jul 20 06:18:02.995996 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:61032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aa.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLXgAAAGo"]
[Mon Jul 20 06:18:02.996092 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:61032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.thefriendlyspreadsheet.com"] [uri "/aa.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLXgAAAGo"]
[Mon Jul 20 06:18:03.017429 2026] [security2:error] [pid 874439:tid 874620] [client 14.225.17.146:53718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4R-o6ZSrFvCrJJhtQLVgAAADM"], referer: http://scott-assist.com/wp
[Mon Jul 20 06:18:03.088279 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/atkno.php"] [unique_id "al4R-46ZSrFvCrJJhtQLZwAAAHc"]
[Mon Jul 20 06:18:03.088364 2026] [security2:error] [pid 874439:tid 874688] [client 20.63.63.128:63958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/atkno.php"] [unique_id "al4R-46ZSrFvCrJJhtQLZwAAAHc"]
[Mon Jul 20 06:18:03.213328 2026] [security2:error] [pid 874439:tid 874678] [client 3.109.4.218:16582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.4.109.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4R-46ZSrFvCrJJhtQLcQAAAG0"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:18:03.285494 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/mass.php"] [unique_id "al4R-46ZSrFvCrJJhtQLdAAAABk"]
[Mon Jul 20 06:18:03.285598 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:63999] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/mass.php"] [unique_id "al4R-46ZSrFvCrJJhtQLdAAAABk"]
[Mon Jul 20 06:18:03.339064 2026] [security2:error] [pid 874439:tid 874614] [client 47.128.99.8:24204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.muamoicosmetics.com"] [uri "/robots.txt"] [unique_id "al4R-46ZSrFvCrJJhtQLdgAAAC0"]
[Mon Jul 20 06:18:03.366062 2026] [security2:error] [pid 874439:tid 874566] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLeAAAMX4"]
[Mon Jul 20 06:18:03.366187 2026] [security2:error] [pid 874439:tid 874618] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLeAAAMX4"]
[Mon Jul 20 06:18:03.417034 2026] [security2:error] [pid 874439:tid 874584] [client 20.63.63.128:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wefile.php"] [unique_id "al4R-46ZSrFvCrJJhtQLegAAAA8"]
[Mon Jul 20 06:18:03.417142 2026] [security2:error] [pid 874439:tid 874584] [client 20.63.63.128:63975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wefile.php"] [unique_id "al4R-46ZSrFvCrJJhtQLegAAAA8"]
[Mon Jul 20 06:18:03.551629 2026] [security2:error] [pid 874439:tid 874659] [client 20.63.63.128:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/min.php"] [unique_id "al4R-46ZSrFvCrJJhtQLhgAAAFo"]
[Mon Jul 20 06:18:03.551801 2026] [security2:error] [pid 874439:tid 874659] [client 20.63.63.128:64004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/min.php"] [unique_id "al4R-46ZSrFvCrJJhtQLhgAAAFo"]
[Mon Jul 20 06:18:03.689329 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/sid3.php"] [unique_id "al4R-46ZSrFvCrJJhtQLigAAAFw"]
[Mon Jul 20 06:18:03.689435 2026] [security2:error] [pid 874439:tid 874661] [client 20.63.63.128:63950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/sid3.php"] [unique_id "al4R-46ZSrFvCrJJhtQLigAAAFw"]
[Mon Jul 20 06:18:03.734989 2026] [security2:error] [pid 871012:tid 871206] [client 57.141.18.105:58868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9LwiU-Jh5ncAILFpxQABSWM"]
[Mon Jul 20 06:18:03.747245 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:53252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkAAAACA"]
[Mon Jul 20 06:18:03.747368 2026] [security2:error] [pid 874439:tid 874601] [client 103.77.203.233:53252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkAAAACA"]
[Mon Jul 20 06:18:03.797882 2026] [security2:error] [pid 874439:tid 874581] [client 178.152.178.232:36239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkgAAAAw"]
[Mon Jul 20 06:18:03.797980 2026] [security2:error] [pid 874439:tid 874581] [client 178.152.178.232:36239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4R-46ZSrFvCrJJhtQLkgAAAAw"]
[Mon Jul 20 06:18:03.853944 2026] [security2:error] [pid 871012:tid 871192] [client 20.63.63.128:57537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/fileas.php"] [unique_id "al4R-7wiU-Jh5ncAILFqgQAAATs"]
[Mon Jul 20 06:18:03.854052 2026] [security2:error] [pid 871012:tid 871192] [client 20.63.63.128:57537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/fileas.php"] [unique_id "al4R-7wiU-Jh5ncAILFqgQAAATs"]
[Mon Jul 20 06:18:03.897166 2026] [security2:error] [pid 874439:tid 874626] [client 185.132.186.93:21273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/about.php"] [unique_id "al4R-46ZSrFvCrJJhtQLlQAAADk"]
[Mon Jul 20 06:18:04.015569 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/bless24.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLoAAAABk"]
[Mon Jul 20 06:18:04.015715 2026] [security2:error] [pid 874439:tid 874594] [client 20.63.63.128:64061] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/bless24.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLoAAAABk"]
[Mon Jul 20 06:18:04.077959 2026] [security2:error] [pid 874439:tid 874608] [client 54.204.130.104:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLgQAAACc"]
[Mon Jul 20 06:18:04.079603 2026] [security2:error] [pid 874439:tid 874651] [client 54.204.130.104:26474] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/category/food/holiday-recipes"] [unique_id "al4R-46ZSrFvCrJJhtQLfgAAAFI"]
[Mon Jul 20 06:18:04.167540 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/fun.php"] [unique_id "al4R_LwiU-Jh5ncAILFqkgAAAT8"]
[Mon Jul 20 06:18:04.167666 2026] [security2:error] [pid 871012:tid 871196] [client 20.63.63.128:63980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/fun.php"] [unique_id "al4R_LwiU-Jh5ncAILFqkgAAAT8"]
[Mon Jul 20 06:18:04.320849 2026] [security2:error] [pid 871012:tid 871238] [client 20.63.63.128:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/drykl.php"] [unique_id "al4R_LwiU-Jh5ncAILFqmgAAAWk"]
[Mon Jul 20 06:18:04.320981 2026] [security2:error] [pid 871012:tid 871238] [client 20.63.63.128:63988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/drykl.php"] [unique_id "al4R_LwiU-Jh5ncAILFqmgAAAWk"]
[Mon Jul 20 06:18:04.408151 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqiAABIng"]
[Mon Jul 20 06:18:04.408356 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqiwABIkA"]
[Mon Jul 20 06:18:04.408468 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqigABIlA"]
[Mon Jul 20 06:18:04.409597 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqjQABIlY"]
[Mon Jul 20 06:18:04.410461 2026] [security2:error] [pid 871012:tid 871167] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqiQABIj0"]
[Mon Jul 20 06:18:04.523590 2026] [security2:error] [pid 871012:tid 871212] [client 20.63.63.128:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R_LwiU-Jh5ncAILFqowAAAU8"]
[Mon Jul 20 06:18:04.523710 2026] [security2:error] [pid 871012:tid 871212] [client 20.63.63.128:64003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4R_LwiU-Jh5ncAILFqowAAAU8"]
[Mon Jul 20 06:18:04.654671 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.7:60278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9Y6ZSrFvCrJJhtQKAQAAAk0"]
[Mon Jul 20 06:18:04.686206 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/mifta.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLxQAAAH4"]
[Mon Jul 20 06:18:04.686314 2026] [security2:error] [pid 874439:tid 874695] [client 20.63.63.128:63936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/mifta.php"] [unique_id "al4R_I6ZSrFvCrJJhtQLxQAAAH4"]
[Mon Jul 20 06:18:04.837486 2026] [security2:error] [pid 874439:tid 874651] [client 20.63.63.128:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/class-t.api.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL0AAAAFI"]
[Mon Jul 20 06:18:04.837624 2026] [security2:error] [pid 874439:tid 874651] [client 20.63.63.128:64003] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/class-t.api.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL0AAAAFI"]
[Mon Jul 20 06:18:04.970888 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:63960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/vgtyu.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL1gAAAGo"]
[Mon Jul 20 06:18:04.971016 2026] [security2:error] [pid 874439:tid 874675] [client 20.63.63.128:63960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/vgtyu.php"] [unique_id "al4R_I6ZSrFvCrJJhtQL1gAAAGo"]
[Mon Jul 20 06:18:05.051303 2026] [security2:error] [pid 871012:tid 871178] [client 34.207.130.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4R_LwiU-Jh5ncAILFqlwAAAS0"]
[Mon Jul 20 06:18:05.089678 2026] [security2:error] [pid 874439:tid 874646] [client 57.141.18.13:28344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKIgAATUI"]
[Mon Jul 20 06:18:05.103238 2026] [security2:error] [pid 874439:tid 874637] [client 34.207.130.29:30424] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/category/food/holiday-recipes/"] [unique_id "al4R_I6ZSrFvCrJJhtQLsAAAAEQ"]
[Mon Jul 20 06:18:05.138923 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:64059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/atomlib.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL3QAAAHA"]
[Mon Jul 20 06:18:05.139069 2026] [security2:error] [pid 874439:tid 874681] [client 20.63.63.128:64059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/atomlib.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL3QAAAHA"]
[Mon Jul 20 06:18:05.292669 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-access.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL4gAAAAA"]
[Mon Jul 20 06:18:05.292791 2026] [security2:error] [pid 874439:tid 874569] [client 20.63.63.128:63978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-access.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL4gAAAAA"]
[Mon Jul 20 06:18:05.422019 2026] [security2:error] [pid 871012:tid 871148] [client 20.63.63.128:64049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-update.php"] [unique_id "al4R_bwiU-Jh5ncAILFqxQAAAQ8"]
[Mon Jul 20 06:18:05.422138 2026] [security2:error] [pid 871012:tid 871148] [client 20.63.63.128:64049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-update.php"] [unique_id "al4R_bwiU-Jh5ncAILFqxQAAAQ8"]
[Mon Jul 20 06:18:05.530209 2026] [security2:error] [pid 871012:tid 871268] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFqvgAAAYc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:05.578459 2026] [security2:error] [pid 871012:tid 871169] [client 20.63.63.128:63954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/erty.php"] [unique_id "al4R_bwiU-Jh5ncAILFqzQAAASQ"]
[Mon Jul 20 06:18:05.578564 2026] [security2:error] [pid 871012:tid 871169] [client 20.63.63.128:63954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/erty.php"] [unique_id "al4R_bwiU-Jh5ncAILFqzQAAASQ"]
[Mon Jul 20 06:18:05.607273 2026] [security2:error] [pid 874439:tid 874592] [client 57.141.18.7:60288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R9o6ZSrFvCrJJhtQKQQAAF0o"]
[Mon Jul 20 06:18:05.626421 2026] [security2:error] [pid 871012:tid 871255] [client 14.225.17.146:52402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4R-7wiU-Jh5ncAILFqbgAAAXo"], referer: http://bruceledewitz.com/wp
[Mon Jul 20 06:18:05.641282 2026] [security2:error] [pid 871012:tid 871214] [client 216.73.217.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFqygABURU"]
[Mon Jul 20 06:18:05.663319 2026] [security2:error] [pid 871012:tid 871234] [client 181.224.94.124:38529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R_bwiU-Jh5ncAILFq0gAAAWU"]
[Mon Jul 20 06:18:05.663465 2026] [security2:error] [pid 871012:tid 871234] [client 181.224.94.124:38529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4R_bwiU-Jh5ncAILFq0gAAAWU"]
[Mon Jul 20 06:18:05.672799 2026] [lsapi:warn] [pid 874439:tid 874508] [remote 86.24.97.244:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:18:05.709256 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:57577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R_bwiU-Jh5ncAILFq1QAAAT4"]
[Mon Jul 20 06:18:05.709345 2026] [security2:error] [pid 871012:tid 871195] [client 20.63.63.128:57577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4R_bwiU-Jh5ncAILFq1QAAAT4"]
[Mon Jul 20 06:18:05.839296 2026] [security2:error] [pid 871012:tid 871243] [client 20.63.63.128:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/like.php"] [unique_id "al4R_bwiU-Jh5ncAILFq2gAAAW4"]
[Mon Jul 20 06:18:05.839437 2026] [security2:error] [pid 871012:tid 871243] [client 20.63.63.128:64039] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/like.php"] [unique_id "al4R_bwiU-Jh5ncAILFq2gAAAW4"]
[Mon Jul 20 06:18:05.849168 2026] [security2:error] [pid 874439:tid 874461] [remote 8.217.108.67:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL-gAAGBU"]
[Mon Jul 20 06:18:05.950385 2026] [security2:error] [pid 874439:tid 874644] [client 14.225.17.146:59917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLeQAAAEs"], referer: http://gearwaterproof.com/wp
[Mon Jul 20 06:18:05.957442 2026] [security2:error] [pid 874439:tid 874651] [client 216.73.217.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL-QAAUkc"]
[Mon Jul 20 06:18:05.983297 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/bless5.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQMBAAAAFU"]
[Mon Jul 20 06:18:05.983394 2026] [security2:error] [pid 874439:tid 874654] [client 20.63.63.128:64022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/bless5.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQMBAAAAFU"]
[Mon Jul 20 06:18:06.047198 2026] [security2:error] [pid 871012:tid 871265] [client 104.234.53.50:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4R_rwiU-Jh5ncAILFq5AAAAYQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:06.158006 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:64047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/t.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMDQAAAG8"]
[Mon Jul 20 06:18:06.158106 2026] [security2:error] [pid 874439:tid 874680] [client 20.63.63.128:64047] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/t.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMDQAAAG8"]
[Mon Jul 20 06:18:06.285851 2026] [security2:error] [pid 871012:tid 871157] [client 20.63.63.128:57561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.63.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/xoot.php"] [unique_id "al4R_rwiU-Jh5ncAILFq7gAAARg"]
[Mon Jul 20 06:18:06.285990 2026] [security2:error] [pid 871012:tid 871157] [client 20.63.63.128:57561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webdisk.theablesea.com"] [uri "/xoot.php"] [unique_id "al4R_rwiU-Jh5ncAILFq7gAAARg"]
[Mon Jul 20 06:18:06.398308 2026] [security2:error] [pid 871012:tid 871147] [client 14.225.17.146:50984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4R_rwiU-Jh5ncAILFq5QAAAQ4"], referer: http://itdynamix.com/wp
[Mon Jul 20 06:18:06.531529 2026] [security2:error] [pid 874439:tid 874608] [client 14.225.17.146:52558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMEAAAACc"], referer: http://fineartsfactory.net/wp
[Mon Jul 20 06:18:06.669996 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.76:43725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/id3/wp-work.php"] [unique_id "al4R_rwiU-Jh5ncAILFq_QAAAXo"]
[Mon Jul 20 06:18:06.991361 2026] [security2:error] [pid 871012:tid 871233] [client 158.173.89.95:20815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4R_rwiU-Jh5ncAILFrDgAAAWQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:07.038793 2026] [security2:error] [pid 871012:tid 871207] [client 57.141.18.20:58208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-LwiU-Jh5ncAILFqJQABSjA"]
[Mon Jul 20 06:18:07.047781 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4R_o6ZSrFvCrJJhtQMHgAAAD8"]
[Mon Jul 20 06:18:07.254554 2026] [security2:error] [pid 874439:tid 874574] [client 128.1.120.248:51490] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^%{tx.allowed_request_content_type}$" against "TX:0" required. [file "/etc/httpd/modsecurity.d/01_asl_content.conf"] [line "64"] [id "391213"] [msg "Atomicorp.com WAF Rules: Request content type is not allowed by policy"] [data "video/x-msvideo"] [severity "WARNING"] [hostname "cira.org"] [uri "/"] [unique_id "al4R_46ZSrFvCrJJhtQMMgAAAAU"]
[Mon Jul 20 06:18:07.254675 2026] [security2:error] [pid 874439:tid 874574] [client 128.1.120.248:51490] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "cira.org"] [uri "/"] [unique_id "al4R_46ZSrFvCrJJhtQMMgAAAAU"]
[Mon Jul 20 06:18:07.277860 2026] [security2:error] [pid 871012:tid 871231] [client 14.225.17.146:64970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4R_rwiU-Jh5ncAILFq4gAAAWI"], referer: http://betterbonddogtraining.com/wp
[Mon Jul 20 06:18:07.298071 2026] [security2:error] [pid 874439:tid 874521] [remote 8.217.108.67:46674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4R_46ZSrFvCrJJhtQMNgAAa1E"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:18:07.435952 2026] [security2:error] [pid 871012:tid 871256] [client 14.225.17.146:59857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrEwAAAXs"], referer: https://itdynamix.com/wp
[Mon Jul 20 06:18:07.706324 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQAAAIjs"], referer: https://guidehunting.com/login
[Mon Jul 20 06:18:07.706501 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQQAAIkw"], referer: https://guidehunting.com/dashboard
[Mon Jul 20 06:18:07.726495 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMRAAAInY"], referer: https://guidehunting.com/settings
[Mon Jul 20 06:18:07.726660 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQgAAIg8"], referer: https://guidehunting.com/app
[Mon Jul 20 06:18:07.727981 2026] [security2:error] [pid 874439:tid 874603] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMQwAAIms"], referer: https://guidehunting.com/console
[Mon Jul 20 06:18:07.764728 2026] [security2:error] [pid 871012:tid 871185] [client 35.245.65.174:33432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrGwABNB8"]
[Mon Jul 20 06:18:07.829141 2026] [security2:error] [pid 871012:tid 871171] [client 14.225.17.146:52643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4R_rwiU-Jh5ncAILFrDAAAASY"], referer: http://idigress.agency/wp
[Mon Jul 20 06:18:08.260459 2026] [security2:error] [pid 871012:tid 871160] [client 57.141.18.88:63922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-bwiU-Jh5ncAILFqRgABGyg"]
[Mon Jul 20 06:18:08.468401 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.87:32207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/WordPressCore/gecko.php"] [unique_id "al4SALwiU-Jh5ncAILFrNAAAAXo"]
[Mon Jul 20 06:18:08.534217 2026] [security2:error] [pid 874439:tid 874685] [client 104.234.53.79:54887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMgwAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:08.575851 2026] [security2:error] [pid 874439:tid 874620] [client 27.96.94.195:37803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMkAAAADM"]
[Mon Jul 20 06:18:08.576066 2026] [security2:error] [pid 874439:tid 874620] [client 27.96.94.195:37803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMkAAAADM"]
[Mon Jul 20 06:18:08.682675 2026] [security2:error] [pid 871012:tid 871115] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SALwiU-Jh5ncAILFrOQABMWU"]
[Mon Jul 20 06:18:08.778569 2026] [security2:error] [pid 874439:tid 874662] [client 57.141.18.51:35168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-Y6ZSrFvCrJJhtQLCQAAXSY"]
[Mon Jul 20 06:18:08.886119 2026] [security2:error] [pid 874439:tid 874632] [client 104.234.53.79:54887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMmgAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:08.894367 2026] [security2:error] [pid 871012:tid 871242] [client 14.225.17.146:61894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrIgAAAW0"], referer: http://sarahholyfield.com/wp
[Mon Jul 20 06:18:09.060526 2026] [security2:error] [pid 874439:tid 874488] [remote 35.245.65.174:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.65.245.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4SAI6ZSrFvCrJJhtQMpAAALzA"], referer: https://www.guidehunting.com/login
[Mon Jul 20 06:18:09.100059 2026] [security2:error] [pid 871012:tid 871218] [client 74.7.227.179:56412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrRwABVW4"], referer: https://tejasenvironmental.com/p=905261
[Mon Jul 20 06:18:09.171838 2026] [security2:error] [pid 874439:tid 874594] [client 14.225.17.146:52663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMpgAAABk"], referer: http://transparentservices.online/wp
[Mon Jul 20 06:18:09.235062 2026] [security2:error] [pid 871012:tid 871031] [remote 162.19.86.63:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SAbwiU-Jh5ncAILFrUwABNxE"]
[Mon Jul 20 06:18:09.329289 2026] [security2:error] [pid 874439:tid 874616] [client 35.245.65.174:33448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMqAAAL14"], referer: https://guidehunting.com/admin
[Mon Jul 20 06:18:09.416694 2026] [security2:error] [pid 871012:tid 871132] [remote 47.86.33.52:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SAbwiU-Jh5ncAILFrVwABRHY"]
[Mon Jul 20 06:18:09.446306 2026] [security2:error] [pid 871012:tid 871057] [remote 162.19.86.63:47726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SAbwiU-Jh5ncAILFrWQABGCs"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:18:09.451726 2026] [security2:error] [pid 874439:tid 874569] [client 14.225.17.146:54027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4R_46ZSrFvCrJJhtQMXAAAAAA"], referer: http://swafforddetailing.com/wp
[Mon Jul 20 06:18:09.520987 2026] [proxy:error] [pid 871012:tid 871224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:18:09.521066 2026] [proxy_http:error] [pid 871012:tid 871224] [client 23.180.120.147:40246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:18:09.521784 2026] [proxy:error] [pid 871012:tid 871224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:18:09.521828 2026] [proxy_http:error] [pid 871012:tid 871224] [client 23.180.120.147:40246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:18:09.743400 2026] [security2:error] [pid 871012:tid 871158] [client 66.249.70.130:50816] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.umatha.art"] [uri "/robots.txt"] [unique_id "al4SAbwiU-Jh5ncAILFrZgAAARk"]
[Mon Jul 20 06:18:09.948120 2026] [security2:error] [pid 874439:tid 874497] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SAY6ZSrFvCrJJhtQM0wAAPDk"]
[Mon Jul 20 06:18:09.948302 2026] [security2:error] [pid 874439:tid 874629] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SAY6ZSrFvCrJJhtQM0wAAPDk"]
[Mon Jul 20 06:18:10.039822 2026] [security2:error] [pid 874439:tid 874692] [client 57.141.18.11:60458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLcgAAe3M"]
[Mon Jul 20 06:18:10.097191 2026] [security2:error] [pid 874439:tid 874624] [client 57.141.18.10:38224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R-46ZSrFvCrJJhtQLbwAAN2Q"]
[Mon Jul 20 06:18:10.116094 2026] [security2:error] [pid 871012:tid 871259] [client 50.116.65.227:57452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SArwiU-Jh5ncAILFrawAAAX4"]
[Mon Jul 20 06:18:10.129170 2026] [security2:error] [pid 871012:tid 871255] [client 50.116.65.227:28106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SArwiU-Jh5ncAILFrbAAAAXo"]
[Mon Jul 20 06:18:10.273607 2026] [security2:error] [pid 874439:tid 874613] [client 185.132.186.88:35551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/baxa1.php7"] [unique_id "al4SAo6ZSrFvCrJJhtQM6gAAACw"]
[Mon Jul 20 06:18:10.556529 2026] [security2:error] [pid 871012:tid 871189] [client 104.222.171.226:30774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrRAABOAc"]
[Mon Jul 20 06:18:10.719813 2026] [security2:error] [pid 871012:tid 871050] [remote 47.86.33.52:8852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SArwiU-Jh5ncAILFrfQABfCQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:18:11.036493 2026] [security2:error] [pid 874439:tid 874608] [client 14.225.17.146:61799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMyQAAACc"]
[Mon Jul 20 06:18:11.037386 2026] [security2:error] [pid 871012:tid 871193] [client 14.225.17.146:52632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4SAbwiU-Jh5ncAILFrUQAAATw"], referer: http://aandarealtygroup.com/wp
[Mon Jul 20 06:18:11.201455 2026] [security2:error] [pid 871012:tid 871093] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SA7wiU-Jh5ncAILFrjAABck8"]
[Mon Jul 20 06:18:11.368242 2026] [security2:error] [pid 874439:tid 874514] [remote 35.245.65.174:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.65.245.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4SA46ZSrFvCrJJhtQNKwAAL0o"], referer: https://www.guidehunting.com/wp-admin/
[Mon Jul 20 06:18:11.570097 2026] [security2:error] [pid 874439:tid 874681] [client 14.225.17.146:52429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4SAY6ZSrFvCrJJhtQMwAAAAHA"], referer: http://narv.co/wp
[Mon Jul 20 06:18:11.902374 2026] [security2:error] [pid 874439:tid 874596] [client 171.60.139.123:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SA46ZSrFvCrJJhtQNTAAAABs"]
[Mon Jul 20 06:18:11.902520 2026] [security2:error] [pid 874439:tid 874596] [client 171.60.139.123:49853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SA46ZSrFvCrJJhtQNTAAAABs"]
[Mon Jul 20 06:18:11.954015 2026] [security2:error] [pid 871012:tid 871160] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SA7wiU-Jh5ncAILFrkwAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:12.070864 2026] [security2:error] [pid 874439:tid 874595] [client 185.132.186.89:38119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-taxonomy.editor.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNVQAAABo"]
[Mon Jul 20 06:18:12.112142 2026] [security2:error] [pid 871012:tid 871222] [client 112.208.70.94:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SBLwiU-Jh5ncAILFrowAAAVk"]
[Mon Jul 20 06:18:12.112269 2026] [security2:error] [pid 871012:tid 871222] [client 112.208.70.94:45838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SBLwiU-Jh5ncAILFrowAAAVk"]
[Mon Jul 20 06:18:12.131717 2026] [security2:error] [pid 874439:tid 874545] [remote 35.245.65.174:33448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.65.245.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNVgAADmk"], referer: https://www.guidehunting.com/wp-admin/
[Mon Jul 20 06:18:12.250552 2026] [security2:error] [pid 874439:tid 874535] [remote 45.90.123.233:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNZAAAcl8"]
[Mon Jul 20 06:18:12.337047 2026] [security2:error] [pid 874439:tid 874658] [client 63.176.132.15:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SA46ZSrFvCrJJhtQNOgAAAFk"]
[Mon Jul 20 06:18:12.391634 2026] [security2:error] [pid 874439:tid 874636] [client 63.176.132.15:12278] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/ensalada-de-coditos-puerto-rican-macaroni-salad/"] [unique_id "al4SA46ZSrFvCrJJhtQNNgAAAEM"]
[Mon Jul 20 06:18:12.535744 2026] [security2:error] [pid 871012:tid 871159] [client 57.141.18.70:47766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFq0QABGjo"]
[Mon Jul 20 06:18:12.626050 2026] [security2:error] [pid 874439:tid 874629] [client 14.225.17.146:51562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNcQAAADw"], referer: https://narv.co/wp
[Mon Jul 20 06:18:12.650370 2026] [security2:error] [pid 874439:tid 874580] [client 57.141.18.7:60294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_Y6ZSrFvCrJJhtQL_wAAC3A"]
[Mon Jul 20 06:18:12.692738 2026] [autoindex:error] [pid 874439:tid 874646] [client 43.165.125.66:59536] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:18:12.704695 2026] [security2:error] [pid 874439:tid 874659] [client 45.116.69.230:57958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNfQAAAFo"]
[Mon Jul 20 06:18:12.704842 2026] [security2:error] [pid 874439:tid 874659] [client 45.116.69.230:57958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SBI6ZSrFvCrJJhtQNfQAAAFo"]
[Mon Jul 20 06:18:12.725801 2026] [security2:error] [pid 871012:tid 871173] [client 57.141.18.78:34394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_bwiU-Jh5ncAILFq4QABKAY"]
[Mon Jul 20 06:18:13.093012 2026] [security2:error] [pid 874439:tid 874644] [client 103.141.108.143:60032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNjgAAAEs"]
[Mon Jul 20 06:18:13.093738 2026] [security2:error] [pid 874439:tid 874644] [client 103.141.108.143:60032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNjgAAAEs"]
[Mon Jul 20 06:18:13.434121 2026] [security2:error] [pid 871012:tid 871078] [remote 45.90.123.233:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr0AABE0A"]
[Mon Jul 20 06:18:13.434263 2026] [security2:error] [pid 871012:tid 871152] [client 45.90.123.233:55064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr0AABE0A"]
[Mon Jul 20 06:18:13.444922 2026] [security2:error] [pid 871012:tid 871250] [client 173.239.224.43:46993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4SBbwiU-Jh5ncAILFrzgAAAXU"]
[Mon Jul 20 06:18:13.869715 2026] [security2:error] [pid 874439:tid 874621] [client 185.132.186.100:22431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/dedi1.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNsQAAADQ"]
[Mon Jul 20 06:18:13.920730 2026] [security2:error] [pid 871012:tid 871023] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr3AABLgk"]
[Mon Jul 20 06:18:13.920890 2026] [security2:error] [pid 871012:tid 871179] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SBbwiU-Jh5ncAILFr3AABLgk"]
[Mon Jul 20 06:18:14.274815 2026] [security2:error] [pid 871012:tid 871186] [client 57.141.18.96:64664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4R_7wiU-Jh5ncAILFrHwABNTU"]
[Mon Jul 20 06:18:14.365075 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:53809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SBo6ZSrFvCrJJhtQN3AAAAGw"]
[Mon Jul 20 06:18:14.365195 2026] [security2:error] [pid 874439:tid 874677] [client 103.77.203.233:53809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SBo6ZSrFvCrJJhtQN3AAAAGw"]
[Mon Jul 20 06:18:14.378734 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:51829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4SBo6ZSrFvCrJJhtQNzQAAAFQ"], referer: http://taskidsvirginia.com/wp
[Mon Jul 20 06:18:14.741206 2026] [security2:error] [pid 874439:tid 874656] [client 14.225.17.146:51665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNjwAAAFc"], referer: http://laceycaraccident.com/wp
[Mon Jul 20 06:18:14.882072 2026] [security2:error] [pid 871012:tid 871144] [client 57.141.18.46:53510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrKQABCyE"]
[Mon Jul 20 06:18:15.147920 2026] [security2:error] [pid 871012:tid 871214] [client 57.141.18.119:30790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SALwiU-Jh5ncAILFrNwABUSw"]
[Mon Jul 20 06:18:15.500885 2026] [security2:error] [pid 871012:tid 871191] [client 57.141.18.72:44020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SAbwiU-Jh5ncAILFrSwABOgU"]
[Mon Jul 20 06:18:15.657588 2026] [security2:error] [pid 874439:tid 874678] [client 185.132.186.104:21257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/wp-conflg.php"] [unique_id "al4SB46ZSrFvCrJJhtQOGAAAAG0"]
[Mon Jul 20 06:18:16.194321 2026] [security2:error] [pid 871012:tid 871258] [client 181.224.94.124:20910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SCLwiU-Jh5ncAILFsEAAAAX0"]
[Mon Jul 20 06:18:16.194434 2026] [security2:error] [pid 871012:tid 871258] [client 181.224.94.124:20910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SCLwiU-Jh5ncAILFsEAAAAX0"]
[Mon Jul 20 06:18:16.220891 2026] [security2:error] [pid 871012:tid 871218] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SCLwiU-Jh5ncAILFsCwAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:16.642387 2026] [security2:error] [pid 874439:tid 874612] [client 57.141.18.125:58548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SAo6ZSrFvCrJJhtQM-wAAK00"]
[Mon Jul 20 06:18:16.654138 2026] [security2:error] [pid 874439:tid 874599] [client 180.153.197.207:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SCI6ZSrFvCrJJhtQOSgAAHnE"], referer: https://www.aleishapenny.ca/listing/page/564?paged=1&view=grid&posts_per_page=48
[Mon Jul 20 06:18:17.406094 2026] [security2:error] [pid 874439:tid 874691] [client 66.249.65.168:53263] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "colliersgroup.com"] [uri "/robots.txt"] [unique_id "al4SCY6ZSrFvCrJJhtQOdAAAAHo"]
[Mon Jul 20 06:18:17.450907 2026] [security2:error] [pid 871012:tid 871182] [client 185.132.186.104:30437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/blog.php"] [unique_id "al4SCbwiU-Jh5ncAILFsNwAAATE"]
[Mon Jul 20 06:18:17.494460 2026] [security2:error] [pid 871012:tid 871145] [client 57.141.18.115:21310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SA7wiU-Jh5ncAILFrlAABDEI"]
[Mon Jul 20 06:18:17.637716 2026] [security2:error] [pid 874439:tid 874472] [remote 20.153.140.50:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SCY6ZSrFvCrJJhtQOewAAbCA"]
[Mon Jul 20 06:18:17.764690 2026] [security2:error] [pid 871012:tid 871135] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SCbwiU-Jh5ncAILFsOQABank"]
[Mon Jul 20 06:18:17.838792 2026] [security2:error] [pid 874439:tid 874635] [client 50.116.65.227:57484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SCY6ZSrFvCrJJhtQOiAAAAEI"]
[Mon Jul 20 06:18:17.849428 2026] [security2:error] [pid 874439:tid 874671] [client 50.116.65.227:28226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SCY6ZSrFvCrJJhtQOigAAAGY"]
[Mon Jul 20 06:18:18.019624 2026] [security2:error] [pid 874439:tid 874454] [remote 45.90.123.233:55076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOkgAAGQ4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:18.031772 2026] [security2:error] [pid 874439:tid 874492] [remote 20.153.140.50:56476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOlAAALjQ"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:18:18.103356 2026] [security2:error] [pid 871012:tid 871152] [client 216.73.217.138:43142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SCrwiU-Jh5ncAILFsQAABE2g"]
[Mon Jul 20 06:18:18.125584 2026] [security2:error] [pid 874439:tid 874449] [remote 45.90.123.233:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOmwAAOgk"]
[Mon Jul 20 06:18:18.184862 2026] [security2:error] [pid 874439:tid 874644] [client 14.225.17.146:61430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4SCY6ZSrFvCrJJhtQOhAAAAEs"], referer: http://idigress.studio/wp
[Mon Jul 20 06:18:18.243531 2026] [security2:error] [pid 871012:tid 871038] [remote 103.255.134.61:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SCrwiU-Jh5ncAILFsSAABQhg"]
[Mon Jul 20 06:18:18.362328 2026] [security2:error] [pid 874439:tid 874470] [remote 45.90.123.233:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOrwAAWR4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:18.750808 2026] [security2:error] [pid 874439:tid 874628] [client 104.234.53.65:29957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOvgAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:19.135717 2026] [security2:error] [pid 874439:tid 874488] [remote 68.178.160.25:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4SC46ZSrFvCrJJhtQO6AAAPDA"]
[Mon Jul 20 06:18:19.247685 2026] [security2:error] [pid 874439:tid 874606] [client 185.132.186.97:59931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/about/install.php"] [unique_id "al4SC46ZSrFvCrJJhtQO7AAAACU"]
[Mon Jul 20 06:18:19.520768 2026] [security2:error] [pid 874439:tid 874501] [remote 68.178.160.25:46850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4SC46ZSrFvCrJJhtQO-wAAOz0"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:18:19.697238 2026] [security2:error] [pid 874439:tid 874658] [client 27.96.94.195:37104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SC46ZSrFvCrJJhtQPBQAAAFk"]
[Mon Jul 20 06:18:19.697428 2026] [security2:error] [pid 874439:tid 874658] [client 27.96.94.195:37104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SC46ZSrFvCrJJhtQPBQAAAFk"]
[Mon Jul 20 06:18:20.052201 2026] [security2:error] [pid 874439:tid 874598] [client 14.225.17.146:51930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4SCY6ZSrFvCrJJhtQOjQAAAB0"], referer: http://cheesewithjam.com/wp
[Mon Jul 20 06:18:20.063034 2026] [security2:error] [pid 874439:tid 874596] [client 57.141.18.24:27950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SBY6ZSrFvCrJJhtQNowAAGw8"]
[Mon Jul 20 06:18:20.273346 2026] [security2:error] [pid 871012:tid 871109] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4SDLwiU-Jh5ncAILFsfAABhl8"]
[Mon Jul 20 06:18:20.300741 2026] [security2:error] [pid 874439:tid 874623] [client 14.225.17.146:63089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPLgAAADY"], referer: http://careysheatingandcooling.com/wp
[Mon Jul 20 06:18:20.362738 2026] [security2:error] [pid 871012:tid 871030] [remote 103.255.134.61:45046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4SDLwiU-Jh5ncAILFsfwABKBA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:18:20.538122 2026] [security2:error] [pid 871012:tid 871081] [remote 182.77.62.24:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SDLwiU-Jh5ncAILFshQABU0M"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:18:20.541541 2026] [security2:error] [pid 874439:tid 874527] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPSAAAYlc"]
[Mon Jul 20 06:18:20.541712 2026] [security2:error] [pid 874439:tid 874667] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPSAAAYlc"]
[Mon Jul 20 06:18:21.052920 2026] [security2:error] [pid 874439:tid 874691] [client 185.132.186.98:44211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/bypass.php"] [unique_id "al4SDY6ZSrFvCrJJhtQPYAAAAHo"]
[Mon Jul 20 06:18:21.069835 2026] [security2:error] [pid 874439:tid 874672] [client 114.119.155.126:46785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cloudspacesgroup.com"] [uri "/robots.txt"] [unique_id "al4SDY6ZSrFvCrJJhtQPYwAAAGc"], referer: http://cloudspacesgroup.com/robots.txt
[Mon Jul 20 06:18:21.864625 2026] [security2:error] [pid 871012:tid 871222] [client 104.234.53.78:28103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SDbwiU-Jh5ncAILFsoQAAAVk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:22.076946 2026] [security2:error] [pid 874439:tid 874475] [remote 124.55.178.99:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SDo6ZSrFvCrJJhtQPoAAADSM"]
[Mon Jul 20 06:18:22.165873 2026] [security2:error] [pid 874439:tid 874608] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SDY6ZSrFvCrJJhtQPmgAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:22.278602 2026] [security2:error] [pid 871012:tid 871111] [remote 216.73.216.55:4863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SDrwiU-Jh5ncAILFspwABJGE"]
[Mon Jul 20 06:18:22.284436 2026] [security2:error] [pid 874439:tid 874476] [remote 57.141.18.91:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4SDo6ZSrFvCrJJhtQPrQAACyQ"]
[Mon Jul 20 06:18:22.504531 2026] [security2:error] [pid 871012:tid 871167] [client 171.60.139.123:50362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SDrwiU-Jh5ncAILFsrQAAASI"]
[Mon Jul 20 06:18:22.504725 2026] [security2:error] [pid 871012:tid 871167] [client 171.60.139.123:50362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SDrwiU-Jh5ncAILFsrQAAASI"]
[Mon Jul 20 06:18:22.517308 2026] [security2:error] [pid 874439:tid 874492] [remote 124.55.178.99:57834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SDo6ZSrFvCrJJhtQPwgAALDQ"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:18:22.589802 2026] [security2:error] [pid 874439:tid 874620] [client 57.141.18.58:49988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCI6ZSrFvCrJJhtQOSQAAM2o"]
[Mon Jul 20 06:18:22.811158 2026] [security2:error] [pid 871012:tid 871164] [client 57.141.18.47:40692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCLwiU-Jh5ncAILFsIwABHzA"]
[Mon Jul 20 06:18:22.971373 2026] [security2:error] [pid 874439:tid 874595] [client 104.234.53.72:43815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SDo6ZSrFvCrJJhtQP4QAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:23.046226 2026] [security2:error] [pid 871012:tid 871076] [remote 182.77.62.24:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SD7wiU-Jh5ncAILFsvAABLj4"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:18:23.441346 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:58657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SD46ZSrFvCrJJhtQP9AAAACU"]
[Mon Jul 20 06:18:23.441439 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:58657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SD46ZSrFvCrJJhtQP9AAAACU"]
[Mon Jul 20 06:18:23.706695 2026] [security2:error] [pid 874439:tid 874661] [client 14.225.17.146:61559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4SD46ZSrFvCrJJhtQP-AAAAFw"], referer: http://elitetax-mi.com/wp
[Mon Jul 20 06:18:23.805053 2026] [security2:error] [pid 871012:tid 871246] [client 51.15.140.81:56698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4SD7wiU-Jh5ncAILFs1wAAAXE"]
[Mon Jul 20 06:18:23.866950 2026] [security2:error] [pid 874439:tid 874587] [client 57.141.18.22:32930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOmAAAEnw"]
[Mon Jul 20 06:18:23.912165 2026] [security2:error] [pid 874439:tid 874687] [client 185.132.186.96:46393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/chosen.php"] [unique_id "al4SD46ZSrFvCrJJhtQQDAAAAHY"]
[Mon Jul 20 06:18:23.935981 2026] [security2:error] [pid 871012:tid 871134] [remote 194.164.192.228:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SD7wiU-Jh5ncAILFs2AABJ3g"]
[Mon Jul 20 06:18:24.118968 2026] [security2:error] [pid 874439:tid 874612] [client 13.201.64.214:63170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQGQAAACs"]
[Mon Jul 20 06:18:24.119106 2026] [security2:error] [pid 874439:tid 874612] [client 13.201.64.214:63170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQGQAAACs"]
[Mon Jul 20 06:18:24.145291 2026] [security2:error] [pid 871012:tid 871075] [remote 194.164.192.228:35202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SELwiU-Jh5ncAILFs3gABVz0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:18:24.250157 2026] [security2:error] [pid 874439:tid 874591] [client 103.141.108.143:60507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQJgAAABY"]
[Mon Jul 20 06:18:24.250281 2026] [security2:error] [pid 874439:tid 874591] [client 103.141.108.143:60507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQJgAAABY"]
[Mon Jul 20 06:18:24.448245 2026] [security2:error] [pid 871012:tid 871201] [client 57.141.18.97:59060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCrwiU-Jh5ncAILFsVQABRFU"]
[Mon Jul 20 06:18:24.550149 2026] [security2:error] [pid 871012:tid 871044] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SELwiU-Jh5ncAILFs6AABhh4"]
[Mon Jul 20 06:18:24.550443 2026] [security2:error] [pid 871012:tid 871267] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SELwiU-Jh5ncAILFs6AABhh4"]
[Mon Jul 20 06:18:24.764276 2026] [security2:error] [pid 874439:tid 874685] [client 57.141.18.22:32940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SCo6ZSrFvCrJJhtQOzQAAdDc"]
[Mon Jul 20 06:18:24.852058 2026] [security2:error] [pid 874439:tid 874633] [client 103.77.203.233:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQSAAAAEA"]
[Mon Jul 20 06:18:24.852192 2026] [security2:error] [pid 874439:tid 874633] [client 103.77.203.233:54351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQSAAAAEA"]
[Mon Jul 20 06:18:24.978404 2026] [security2:error] [pid 874439:tid 874609] [client 178.152.178.232:35842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQVQAAACg"]
[Mon Jul 20 06:18:24.985269 2026] [security2:error] [pid 874439:tid 874609] [client 178.152.178.232:35842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQVQAAACg"]
[Mon Jul 20 06:18:25.052533 2026] [security2:error] [pid 871012:tid 871174] [client 77.110.127.138:59648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SELwiU-Jh5ncAILFs8AAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.104408 2026] [security2:error] [pid 871012:tid 871186] [client 77.110.127.138:59589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/charity/6b4akeh9ddzd.php"] [unique_id "al4SEbwiU-Jh5ncAILFs-gAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.106694 2026] [security2:error] [pid 871012:tid 871166] [client 77.110.127.138:59672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4SEbwiU-Jh5ncAILFs-wAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.302051 2026] [security2:error] [pid 871012:tid 871157] [client 14.225.17.146:63063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtAgAAARg"], referer: http://alaraycreative.com/wp
[Mon Jul 20 06:18:25.339801 2026] [security2:error] [pid 871012:tid 871141] [remote 100.42.189.89:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SEbwiU-Jh5ncAILFtBgABYn8"]
[Mon Jul 20 06:18:25.347362 2026] [security2:error] [pid 871012:tid 871215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFs-AAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.441420 2026] [security2:error] [pid 874439:tid 874653] [client 77.110.127.138:59623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQbgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.443408 2026] [security2:error] [pid 871012:tid 871198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtAwAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.472448 2026] [security2:error] [pid 874439:tid 874614] [client 112.208.70.94:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQggAAAC0"]
[Mon Jul 20 06:18:25.472578 2026] [security2:error] [pid 874439:tid 874614] [client 112.208.70.94:42049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQggAAAC0"]
[Mon Jul 20 06:18:25.487225 2026] [security2:error] [pid 874439:tid 874678] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQdQAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:25.550526 2026] [security2:error] [pid 871012:tid 871058] [remote 100.42.189.89:41524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SEbwiU-Jh5ncAILFtDQABcyw"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:18:25.760889 2026] [security2:error] [pid 874439:tid 874662] [client 185.132.186.104:29467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/av.php"] [unique_id "al4SEY6ZSrFvCrJJhtQQjAAAAF0"]
[Mon Jul 20 06:18:25.897579 2026] [security2:error] [pid 874439:tid 874644] [client 57.141.18.106:25802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDI6ZSrFvCrJJhtQPMwAAS28"]
[Mon Jul 20 06:18:26.021642 2026] [security2:error] [pid 874439:tid 874594] [client 14.225.17.146:49951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQTQAAABk"], referer: http://massagelacey.com/wp
[Mon Jul 20 06:18:26.218445 2026] [security2:error] [pid 874439:tid 874667] [client 14.225.17.146:52066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQIgAAAGI"], referer: http://mollycahill.com/wp
[Mon Jul 20 06:18:26.241440 2026] [security2:error] [pid 874439:tid 874540] [remote 192.241.143.148:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQqgAAPmQ"]
[Mon Jul 20 06:18:26.275126 2026] [security2:error] [pid 871012:tid 871176] [client 57.141.18.102:51366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDLwiU-Jh5ncAILFsiQABKwc"]
[Mon Jul 20 06:18:26.278479 2026] [security2:error] [pid 874439:tid 874691] [client 14.225.17.146:52075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQOAAAAHo"], referer: http://margaretspeckogawa.com/wp
[Mon Jul 20 06:18:26.343330 2026] [security2:error] [pid 874439:tid 874643] [client 77.110.127.138:59659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/cowl/dyh555y8ulcg.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQtQAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:26.419361 2026] [security2:error] [pid 874439:tid 874644] [client 50.116.65.227:21954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SEo6ZSrFvCrJJhtQQwwAAAEs"]
[Mon Jul 20 06:18:26.433461 2026] [security2:error] [pid 874439:tid 874582] [client 50.116.65.227:48584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SEo6ZSrFvCrJJhtQQyAAAAA0"]
[Mon Jul 20 06:18:26.452436 2026] [security2:error] [pid 874439:tid 874464] [remote 192.241.143.148:32856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQzgAAOhg"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:18:26.901243 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:49914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQ4gAAAEM"], referer: http://oldracelimited.com/wp
[Mon Jul 20 06:18:26.964288 2026] [security2:error] [pid 874439:tid 874651] [client 57.141.18.50:31092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDY6ZSrFvCrJJhtQPgwAAUno"]
[Mon Jul 20 06:18:27.106384 2026] [security2:error] [pid 874439:tid 874662] [client 181.224.94.124:34307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SE46ZSrFvCrJJhtQQ9QAAAF0"]
[Mon Jul 20 06:18:27.106519 2026] [security2:error] [pid 874439:tid 874662] [client 181.224.94.124:34307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SE46ZSrFvCrJJhtQQ9QAAAF0"]
[Mon Jul 20 06:18:27.409761 2026] [security2:error] [pid 871012:tid 871194] [client 172.59.220.76:1305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtIQABPUU"]
[Mon Jul 20 06:18:27.438065 2026] [security2:error] [pid 874439:tid 874654] [client 57.141.18.70:64962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SDo6ZSrFvCrJJhtQPpAAAVSA"]
[Mon Jul 20 06:18:27.445342 2026] [security2:error] [pid 871012:tid 871194] [client 172.59.220.76:1305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4SEbwiU-Jh5ncAILFtIAABPQw"]
[Mon Jul 20 06:18:27.454078 2026] [security2:error] [pid 874439:tid 874629] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQuAAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.586250 2026] [security2:error] [pid 874439:tid 874677] [client 77.110.127.138:59624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQvgAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.713951 2026] [security2:error] [pid 874439:tid 874638] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQzAAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.735258 2026] [security2:error] [pid 874439:tid 874669] [client 185.132.186.73:44885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/interactivity-api/interactivity-api-xml.php"] [unique_id "al4SE46ZSrFvCrJJhtQRHgAAAGQ"]
[Mon Jul 20 06:18:27.745421 2026] [security2:error] [pid 871012:tid 871145] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SErwiU-Jh5ncAILFtOwAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:27.756426 2026] [security2:error] [pid 874439:tid 874475] [remote 152.228.213.32:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SE46ZSrFvCrJJhtQRHwAALCM"]
[Mon Jul 20 06:18:27.946490 2026] [security2:error] [pid 874439:tid 874454] [remote 152.228.213.32:38108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SE46ZSrFvCrJJhtQRLwAADQ4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:28.254302 2026] [security2:error] [pid 871012:tid 871155] [client 57.141.18.23:21746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SD7wiU-Jh5ncAILFsvQABFgY"]
[Mon Jul 20 06:18:28.413491 2026] [security2:error] [pid 871012:tid 871234] [client 57.141.18.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtbgAAAWU"]
[Mon Jul 20 06:18:28.483946 2026] [security2:error] [pid 874439:tid 874602] [client 104.234.53.70:33723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRXgAAACE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:28.580645 2026] [security2:error] [pid 871012:tid 871203] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtZAAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:28.758900 2026] [security2:error] [pid 874439:tid 874625] [client 114.119.139.107:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/robots.txt"] [unique_id "al4SFI6ZSrFvCrJJhtQRcAAAADg"], referer: http://lakelopezonline.com/robots.txt
[Mon Jul 20 06:18:28.884699 2026] [security2:error] [pid 874439:tid 874582] [client 77.110.127.138:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/img_4196-2/mme2a5ginrc1.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRgAAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.098077 2026] [security2:error] [pid 871012:tid 871086] [remote 154.66.198.148:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SFbwiU-Jh5ncAILFtggABZEg"]
[Mon Jul 20 06:18:29.188950 2026] [security2:error] [pid 871012:tid 871199] [client 77.110.127.138:59681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtegAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.191709 2026] [security2:error] [pid 874439:tid 874693] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRigAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.193784 2026] [security2:error] [pid 871012:tid 871242] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtfQAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.223891 2026] [security2:error] [pid 874439:tid 874645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRlgAAAEw"]
[Mon Jul 20 06:18:29.230067 2026] [security2:error] [pid 874439:tid 874576] [client 14.225.17.146:54365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRRAAAAAc"], referer: http://intelligentengineeringsolutions.com/wp
[Mon Jul 20 06:18:29.266893 2026] [security2:error] [pid 874439:tid 874610] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFY6ZSrFvCrJJhtQRmAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:29.278989 2026] [security2:error] [pid 874439:tid 874604] [client 216.73.216.78:10513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/index.php"] [unique_id "al4SE46ZSrFvCrJJhtQRLAAAIyg"]
[Mon Jul 20 06:18:29.534746 2026] [ssl:error] [pid 874439:tid 874691] [client 104.48.69.105:60302] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:29.539888 2026] [security2:error] [pid 874439:tid 874653] [client 185.132.186.53:25127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/colour.php"] [unique_id "al4SFY6ZSrFvCrJJhtQRxAAAAFQ"]
[Mon Jul 20 06:18:29.635010 2026] [security2:error] [pid 874439:tid 874570] [client 14.225.17.146:62355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4SFY6ZSrFvCrJJhtQRvQAAAAE"]
[Mon Jul 20 06:18:29.980518 2026] [security2:error] [pid 871012:tid 871223] [client 66.249.93.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4SFbwiU-Jh5ncAILFtjwAAAVo"]
[Mon Jul 20 06:18:29.997820 2026] [security2:error] [pid 871012:tid 871144] [client 104.234.53.55:20659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SFbwiU-Jh5ncAILFtmQAAAQs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:30.052941 2026] [security2:error] [pid 874439:tid 874628] [client 14.225.17.146:62673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4SFY6ZSrFvCrJJhtQR1gAAADs"], referer: http://ksands.co.uk/wp
[Mon Jul 20 06:18:30.117809 2026] [security2:error] [pid 871012:tid 871156] [client 68.235.52.68:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SFrwiU-Jh5ncAILFtnwAAARc"]
[Mon Jul 20 06:18:30.117920 2026] [security2:error] [pid 871012:tid 871156] [client 68.235.52.68:56126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SFrwiU-Jh5ncAILFtnwAAARc"]
[Mon Jul 20 06:18:30.231267 2026] [security2:error] [pid 874439:tid 874672] [client 158.173.166.181:60253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SFo6ZSrFvCrJJhtQR6AAAAGc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:30.251642 2026] [security2:error] [pid 874439:tid 874605] [client 57.141.18.76:30520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQQgAAJCI"]
[Mon Jul 20 06:18:30.323060 2026] [security2:error] [pid 874439:tid 874676] [client 57.141.18.107:61696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SEI6ZSrFvCrJJhtQQRQAAazA"]
[Mon Jul 20 06:18:30.389623 2026] [security2:error] [pid 874439:tid 874685] [client 14.225.17.146:61986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4SFI6ZSrFvCrJJhtQRjQAAAHQ"], referer: http://detroitcsc.com/wp
[Mon Jul 20 06:18:30.394550 2026] [security2:error] [pid 871012:tid 871090] [remote 154.66.198.148:13382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SFrwiU-Jh5ncAILFtrQABXkw"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:18:30.607896 2026] [security2:error] [pid 871012:tid 871167] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SFrwiU-Jh5ncAILFtrAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:30.930503 2026] [security2:error] [pid 874439:tid 874537] [remote 20.153.140.50:35638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SFo6ZSrFvCrJJhtQSEwAAL2E"]
[Mon Jul 20 06:18:31.127018 2026] [security2:error] [pid 874439:tid 874532] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSHQAABVw"]
[Mon Jul 20 06:18:31.127202 2026] [security2:error] [pid 874439:tid 874574] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSHQAABVw"]
[Mon Jul 20 06:18:31.357798 2026] [security2:error] [pid 874439:tid 874692] [client 185.132.186.66:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/elp.php"] [unique_id "al4SF46ZSrFvCrJJhtQSLAAAAHs"]
[Mon Jul 20 06:18:31.366055 2026] [security2:error] [pid 874439:tid 874466] [remote 20.153.140.50:35638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SF46ZSrFvCrJJhtQSLQAAABo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:31.421663 2026] [security2:error] [pid 874439:tid 874461] [remote 45.90.123.233:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SF46ZSrFvCrJJhtQSMwAAIBU"]
[Mon Jul 20 06:18:31.467104 2026] [security2:error] [pid 874439:tid 874612] [client 54.81.157.232:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SFo6ZSrFvCrJJhtQSDQAAACs"]
[Mon Jul 20 06:18:31.497203 2026] [security2:error] [pid 874439:tid 874598] [client 54.81.157.232:15810] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pegao-puerto-rican-crispy-rice/"] [unique_id "al4SFo6ZSrFvCrJJhtQSCAAAAB0"]
[Mon Jul 20 06:18:31.638301 2026] [security2:error] [pid 874439:tid 874469] [remote 45.90.123.233:52444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SF46ZSrFvCrJJhtQSPAAAMx0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:31.783402 2026] [security2:error] [pid 874439:tid 874604] [client 27.96.94.195:37688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSQQAAACM"]
[Mon Jul 20 06:18:31.783586 2026] [security2:error] [pid 874439:tid 874604] [client 27.96.94.195:37688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SF46ZSrFvCrJJhtQSQQAAACM"]
[Mon Jul 20 06:18:31.830261 2026] [security2:error] [pid 871012:tid 871034] [remote 47.86.33.52:41156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SF7wiU-Jh5ncAILFtzwABMhQ"]
[Mon Jul 20 06:18:32.020441 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.95:38012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SEo6ZSrFvCrJJhtQQwgAATn0"]
[Mon Jul 20 06:18:32.177223 2026] [security2:error] [pid 871012:tid 871148] [client 145.223.130.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt3AABD0c"]
[Mon Jul 20 06:18:32.552134 2026] [security2:error] [pid 871012:tid 871210] [client 77.110.127.138:59663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt5AAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:32.589395 2026] [security2:error] [pid 871012:tid 871221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt6AAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:32.811449 2026] [security2:error] [pid 871012:tid 871161] [client 114.119.146.145:57631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "massagelacey.com"] [uri "/robots.txt"] [unique_id "al4SGLwiU-Jh5ncAILFt8gAAARw"], referer: https://massagelacey.com/robots.txt
[Mon Jul 20 06:18:32.861961 2026] [security2:error] [pid 871012:tid 871239] [client 54.158.124.211:45766] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt3wAAAWo"]
[Mon Jul 20 06:18:32.884874 2026] [security2:error] [pid 871012:tid 871103] [remote 5.161.225.162:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4SGLwiU-Jh5ncAILFt9AABglk"]
[Mon Jul 20 06:18:32.973160 2026] [security2:error] [pid 871012:tid 871159] [client 57.141.18.38:61634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SE7wiU-Jh5ncAILFtRgABGnU"]
[Mon Jul 20 06:18:33.042578 2026] [core:error] [pid 874439:tid 874679] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.042601 2026] [core:error] [pid 874439:tid 874679] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.079485 2026] [security2:error] [pid 874439:tid 874627] [client 171.60.139.123:51060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSgwAAADo"]
[Mon Jul 20 06:18:33.079645 2026] [security2:error] [pid 874439:tid 874627] [client 171.60.139.123:51060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSgwAAADo"]
[Mon Jul 20 06:18:33.141251 2026] [security2:error] [pid 871012:tid 871049] [remote 5.161.225.162:37580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4SGbwiU-Jh5ncAILFuBAABKiM"], referer: https://karimnawfal.com/wp-login.php
[Mon Jul 20 06:18:33.182262 2026] [security2:error] [pid 874439:tid 874594] [client 185.132.186.96:40595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-background-position-control-variable.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSiwAAABk"]
[Mon Jul 20 06:18:33.204065 2026] [core:error] [pid 874439:tid 874639] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.204096 2026] [core:error] [pid 874439:tid 874639] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.227773 2026] [security2:error] [pid 874439:tid 874651] [client 14.224.227.113:55629] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SGY6ZSrFvCrJJhtQSkwAAAFI"]
[Mon Jul 20 06:18:33.229460 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.229479 2026] [core:error] [pid 874439:tid 874657] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.229569 2026] [core:error] [pid 874439:tid 874643] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.229589 2026] [core:error] [pid 874439:tid 874643] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.239858 2026] [security2:error] [pid 874439:tid 874610] [client 14.224.227.113:55631] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SGY6ZSrFvCrJJhtQSlgAAACk"]
[Mon Jul 20 06:18:33.285823 2026] [security2:error] [pid 871012:tid 871172] [client 14.224.227.113:55633] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SGbwiU-Jh5ncAILFuCAAAASc"]
[Mon Jul 20 06:18:33.338176 2026] [security2:error] [pid 874439:tid 874581] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4SGI6ZSrFvCrJJhtQScwAADH8"], referer: http://ali-alghanim.net/wp
[Mon Jul 20 06:18:33.411345 2026] [security2:error] [pid 874439:tid 874676] [client 37.59.204.159:44386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "innspace.ca"] [uri "/robots.txt"] [unique_id "al4SGY6ZSrFvCrJJhtQSpAAAAGs"]
[Mon Jul 20 06:18:33.411489 2026] [security2:error] [pid 874439:tid 874676] [client 37.59.204.159:44386] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "innspace.ca"] [uri "/robots.txt"] [unique_id "al4SGY6ZSrFvCrJJhtQSpAAAAGs"]
[Mon Jul 20 06:18:33.759940 2026] [security2:error] [pid 871012:tid 871224] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGbwiU-Jh5ncAILFuFAAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:33.763962 2026] [security2:error] [pid 871012:tid 871254] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGbwiU-Jh5ncAILFuFQAAAXk"], referer: https://mezzacraft.com/about-mezzacraft-crochet/
[Mon Jul 20 06:18:33.802387 2026] [security2:error] [pid 874439:tid 874638] [client 77.110.127.138:59721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/contact-me/feed/0uk8ftfxb98i.php"] [unique_id "al4SGY6ZSrFvCrJJhtQSwwAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:33.830106 2026] [core:error] [pid 874439:tid 874672] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.830128 2026] [core:error] [pid 874439:tid 874672] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:33.910229 2026] [security2:error] [pid 871012:tid 871240] [client 57.141.18.37:25930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFLwiU-Jh5ncAILFtaQABaxs"]
[Mon Jul 20 06:18:33.983554 2026] [autoindex:error] [pid 874439:tid 874633] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:18:34.096634 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS1gAAACU"]
[Mon Jul 20 06:18:34.096799 2026] [security2:error] [pid 874439:tid 874606] [client 45.116.69.230:59200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS1gAAACU"]
[Mon Jul 20 06:18:34.116854 2026] [security2:error] [pid 871012:tid 871144] [client 50.116.65.227:59868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuKAAAAQs"]
[Mon Jul 20 06:18:34.122301 2026] [security2:error] [pid 874439:tid 874653] [client 14.224.227.113:58376] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4SGo6ZSrFvCrJJhtQS1wAAAFQ"]
[Mon Jul 20 06:18:34.127733 2026] [security2:error] [pid 871012:tid 871147] [client 50.116.65.227:35124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuKQAAAQ4"]
[Mon Jul 20 06:18:34.264849 2026] [security2:error] [pid 874439:tid 874548] [remote 216.73.216.55:34545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4SGo6ZSrFvCrJJhtQS3AAAWGw"]
[Mon Jul 20 06:18:34.338021 2026] [security2:error] [pid 871012:tid 871251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SGbwiU-Jh5ncAILFuJAAAAXY"]
[Mon Jul 20 06:18:34.452774 2026] [security2:error] [pid 871012:tid 871171] [client 103.141.108.143:60982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SGrwiU-Jh5ncAILFuMAAAASY"]
[Mon Jul 20 06:18:34.452893 2026] [security2:error] [pid 871012:tid 871171] [client 103.141.108.143:60982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SGrwiU-Jh5ncAILFuMAAAASY"]
[Mon Jul 20 06:18:34.526699 2026] [security2:error] [pid 874439:tid 874603] [client 14.225.17.146:51396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS3gAAACI"], referer: http://tacticaltreeoperations.com/wp
[Mon Jul 20 06:18:34.656951 2026] [security2:error] [pid 874439:tid 874522] [remote 57.141.18.86:64558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2898939"] [unique_id "al4SGo6ZSrFvCrJJhtQS7wAADVI"]
[Mon Jul 20 06:18:34.749516 2026] [security2:error] [pid 871012:tid 871203] [client 15.235.98.122:22774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "innspace.ca"] [uri "/"] [unique_id "al4SGrwiU-Jh5ncAILFuPgAAAUY"]
[Mon Jul 20 06:18:34.749626 2026] [security2:error] [pid 871012:tid 871203] [client 15.235.98.122:22774] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "innspace.ca"] [uri "/"] [unique_id "al4SGrwiU-Jh5ncAILFuPgAAAUY"]
[Mon Jul 20 06:18:34.791792 2026] [security2:error] [pid 871012:tid 871231] [client 57.141.18.72:21698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFbwiU-Jh5ncAILFtgQABYlo"]
[Mon Jul 20 06:18:34.923105 2026] [security2:error] [pid 871012:tid 871215] [client 74.208.214.194:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SGrwiU-Jh5ncAILFuQwAAAVI"]
[Mon Jul 20 06:18:34.924952 2026] [security2:error] [pid 871012:tid 871152] [client 50.116.65.227:59872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuRAAAARM"]
[Mon Jul 20 06:18:34.935723 2026] [security2:error] [pid 871012:tid 871224] [client 50.116.65.227:35164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SGrwiU-Jh5ncAILFuRgAAAQ8"]
[Mon Jul 20 06:18:35.107640 2026] [security2:error] [pid 871012:tid 871067] [remote 5.252.52.249:37852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4SG7wiU-Jh5ncAILFuTgABDDU"]
[Mon Jul 20 06:18:35.125511 2026] [security2:error] [pid 874439:tid 874612] [client 185.132.186.83:23647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/images/include.php"] [unique_id "al4SG46ZSrFvCrJJhtQTAwAAACs"]
[Mon Jul 20 06:18:35.146256 2026] [security2:error] [pid 871012:tid 871060] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuTwABMC4"]
[Mon Jul 20 06:18:35.146470 2026] [security2:error] [pid 871012:tid 871181] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuTwABMC4"]
[Mon Jul 20 06:18:35.515321 2026] [security2:error] [pid 874439:tid 874647] [client 103.77.203.233:54885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SG46ZSrFvCrJJhtQTHgAAAE4"]
[Mon Jul 20 06:18:35.515432 2026] [security2:error] [pid 874439:tid 874647] [client 103.77.203.233:54885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SG46ZSrFvCrJJhtQTHgAAAE4"]
[Mon Jul 20 06:18:35.610319 2026] [security2:error] [pid 871012:tid 871216] [client 178.152.178.232:37524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuWgAAAVM"]
[Mon Jul 20 06:18:35.610427 2026] [security2:error] [pid 871012:tid 871216] [client 178.152.178.232:37524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SG7wiU-Jh5ncAILFuWgAAAVM"]
[Mon Jul 20 06:18:35.897007 2026] [security2:error] [pid 871012:tid 871154] [client 57.141.18.74:22710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFrwiU-Jh5ncAILFtogABFVE"]
[Mon Jul 20 06:18:36.290126 2026] [security2:error] [pid 874439:tid 874628] [client 57.141.18.122:39116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SFo6ZSrFvCrJJhtQSCQAAOxg"]
[Mon Jul 20 06:18:36.370307 2026] [security2:error] [pid 871012:tid 871258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SG7wiU-Jh5ncAILFuXwAAAX0"]
[Mon Jul 20 06:18:36.678962 2026] [core:error] [pid 874439:tid 874641] [client 14.225.17.146:50610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wp
[Mon Jul 20 06:18:36.678984 2026] [core:error] [pid 874439:tid 874641] [client 14.225.17.146:50610] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wp
[Mon Jul 20 06:18:36.813483 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.24:58428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SF46ZSrFvCrJJhtQSJgAAP1o"]
[Mon Jul 20 06:18:36.931411 2026] [security2:error] [pid 874439:tid 874634] [client 185.132.186.75:42789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/av.php.php"] [unique_id "al4SHI6ZSrFvCrJJhtQTWAAAAEE"]
[Mon Jul 20 06:18:36.942546 2026] [security2:error] [pid 874439:tid 874532] [remote 57.141.18.56:32544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3042932"] [unique_id "al4SHI6ZSrFvCrJJhtQTWQAAHVw"]
[Mon Jul 20 06:18:37.009425 2026] [security2:error] [pid 871012:tid 871035] [remote 5.252.52.249:37852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4SHbwiU-Jh5ncAILFueAABcxU"], referer: https://stepupstepmom.com/wp-login.php
[Mon Jul 20 06:18:37.014193 2026] [security2:error] [pid 871012:tid 871155] [client 57.141.18.35:48772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SF7wiU-Jh5ncAILFtyQABFjY"]
[Mon Jul 20 06:18:37.147800 2026] [security2:error] [pid 874439:tid 874645] [client 18.140.64.130:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTZQAAAEw"]
[Mon Jul 20 06:18:37.210533 2026] [ssl:error] [pid 874439:tid 874628] [client 104.48.69.105:60312] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:37.300128 2026] [security2:error] [pid 874439:tid 874609] [client 181.224.94.124:42960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTcAAAACg"]
[Mon Jul 20 06:18:37.300306 2026] [security2:error] [pid 874439:tid 874609] [client 181.224.94.124:42960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTcAAAACg"]
[Mon Jul 20 06:18:37.384692 2026] [security2:error] [pid 871012:tid 871021] [remote 154.66.198.148:16064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SHbwiU-Jh5ncAILFugAABLQc"]
[Mon Jul 20 06:18:37.524569 2026] [security2:error] [pid 871012:tid 871169] [client 57.141.18.29:57908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SF7wiU-Jh5ncAILFt2AABJHs"]
[Mon Jul 20 06:18:38.097645 2026] [security2:error] [pid 871012:tid 871106] [remote 81.173.115.7:44814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SHrwiU-Jh5ncAILFukAABOlw"]
[Mon Jul 20 06:18:38.097804 2026] [security2:error] [pid 871012:tid 871191] [client 81.173.115.7:44814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SHrwiU-Jh5ncAILFukAABOlw"]
[Mon Jul 20 06:18:38.114843 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.107:57764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SGI6ZSrFvCrJJhtQSbAAAaDE"]
[Mon Jul 20 06:18:38.181823 2026] [security2:error] [pid 874439:tid 874608] [client 18.140.64.130:11508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SHo6ZSrFvCrJJhtQTnAAAACc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:18:38.202439 2026] [core:error] [pid 874439:tid 874626] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:38.202458 2026] [core:error] [pid 874439:tid 874626] [client 137.184.44.103:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:38.216669 2026] [autoindex:error] [pid 874439:tid 874618] [client 188.166.209.66:49970] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:18:38.243416 2026] [security2:error] [pid 871012:tid 871026] [remote 154.66.198.148:16064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SHrwiU-Jh5ncAILFulAABbgw"], referer: https://amalia-capital.com/wp-login.php
[Mon Jul 20 06:18:38.286570 2026] [ssl:error] [pid 874439:tid 874591] [client 104.48.69.105:39900] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:38.380151 2026] [security2:error] [pid 871012:tid 871256] [client 57.141.18.73:27496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SGLwiU-Jh5ncAILFt9QABe0o"]
[Mon Jul 20 06:18:38.703028 2026] [security2:error] [pid 874439:tid 874626] [client 185.132.186.94:56855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd-1/install.php"] [unique_id "al4SHo6ZSrFvCrJJhtQTuwAAADk"]
[Mon Jul 20 06:18:39.117779 2026] [security2:error] [pid 874439:tid 874623] [client 104.234.53.78:53819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SH46ZSrFvCrJJhtQT0QAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:39.167973 2026] [security2:error] [pid 871012:tid 871038] [remote 18.61.192.253:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4SH7wiU-Jh5ncAILFupwABcBg"]
[Mon Jul 20 06:18:39.168229 2026] [security2:error] [pid 871012:tid 871245] [client 18.61.192.253:53138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4SH7wiU-Jh5ncAILFupwABcBg"]
[Mon Jul 20 06:18:39.259893 2026] [security2:error] [pid 874439:tid 874643] [client 14.225.17.146:55708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTiwAAAEo"], referer: http://iagdevelopments.com/wp
[Mon Jul 20 06:18:39.624070 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:42406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SH46ZSrFvCrJJhtQT6gAAAHY"]
[Mon Jul 20 06:18:39.624198 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:42406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SH46ZSrFvCrJJhtQT6gAAAHY"]
[Mon Jul 20 06:18:39.664322 2026] [core:error] [pid 871012:tid 871165] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:39.664345 2026] [core:error] [pid 871012:tid 871165] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:39.967339 2026] [security2:error] [pid 871012:tid 871086] [remote 103.82.22.235:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SH7wiU-Jh5ncAILFuxAABfEg"]
[Mon Jul 20 06:18:40.161084 2026] [security2:error] [pid 874439:tid 874691] [client 14.225.17.146:60552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4SHo6ZSrFvCrJJhtQTswAAAHo"], referer: http://olearyplumbingllc.com/wp
[Mon Jul 20 06:18:40.221838 2026] [security2:error] [pid 874439:tid 874604] [client 14.225.17.146:64137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4SII6ZSrFvCrJJhtQUBQAAACM"], referer: https://iagdevelopments.com/wp
[Mon Jul 20 06:18:40.544340 2026] [security2:error] [pid 871012:tid 871268] [client 14.175.181.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4SHrwiU-Jh5ncAILFuoQAAAYc"]
[Mon Jul 20 06:18:40.563200 2026] [security2:error] [pid 874439:tid 874647] [client 185.132.186.69:40525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/imgareaselect/wp-login.php"] [unique_id "al4SII6ZSrFvCrJJhtQUHgAAAE4"]
[Mon Jul 20 06:18:40.595769 2026] [security2:error] [pid 871012:tid 871031] [remote 103.82.22.235:34862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SILwiU-Jh5ncAILFu0QABWhE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:18:40.680889 2026] [security2:error] [pid 871012:tid 871061] [remote 115.74.105.156:60870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SILwiU-Jh5ncAILFu1AABHS8"]
[Mon Jul 20 06:18:40.686567 2026] [security2:error] [pid 874439:tid 874526] [remote 194.164.192.228:37154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SII6ZSrFvCrJJhtQUMgAAb1Y"]
[Mon Jul 20 06:18:40.686758 2026] [security2:error] [pid 874439:tid 874680] [client 194.164.192.228:37154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4SII6ZSrFvCrJJhtQUMgAAb1Y"]
[Mon Jul 20 06:18:40.814608 2026] [security2:error] [pid 871012:tid 871132] [remote 173.212.252.15:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SILwiU-Jh5ncAILFu2QABdnY"]
[Mon Jul 20 06:18:40.892953 2026] [security2:error] [pid 874439:tid 874693] [client 57.141.18.13:38806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SGo6ZSrFvCrJJhtQS-gAAfDc"]
[Mon Jul 20 06:18:41.113526 2026] [security2:error] [pid 874439:tid 874509] [remote 20.153.140.50:49700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUTAAAWkU"]
[Mon Jul 20 06:18:41.138879 2026] [security2:error] [pid 874439:tid 874452] [remote 100.42.189.89:41710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUTQAANgw"]
[Mon Jul 20 06:18:41.159306 2026] [security2:error] [pid 871012:tid 871030] [remote 173.212.252.15:54042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SIbwiU-Jh5ncAILFu5AABTxA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:18:41.342026 2026] [security2:error] [pid 874439:tid 874683] [client 45.157.112.60:57161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUUgAAAHI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:41.360104 2026] [security2:error] [pid 874439:tid 874534] [remote 100.42.189.89:41710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUVAAAMl4"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 06:18:41.499822 2026] [security2:error] [pid 874439:tid 874473] [remote 5.161.225.162:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUYAAAOSE"]
[Mon Jul 20 06:18:41.592234 2026] [security2:error] [pid 874439:tid 874640] [client 50.116.65.227:33616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SIY6ZSrFvCrJJhtQUZgAAAEc"]
[Mon Jul 20 06:18:41.606782 2026] [security2:error] [pid 874439:tid 874644] [client 50.116.65.227:33622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SIY6ZSrFvCrJJhtQUZwAAAEs"]
[Mon Jul 20 06:18:41.652859 2026] [security2:error] [pid 874439:tid 874605] [client 57.141.18.57:47692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SG46ZSrFvCrJJhtQTKwAAJDk"]
[Mon Jul 20 06:18:41.677290 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:50116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4SII6ZSrFvCrJJhtQUPQAAAHY"]
[Mon Jul 20 06:18:41.710135 2026] [security2:error] [pid 871012:tid 871240] [client 14.251.3.155:55656] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SIbwiU-Jh5ncAILFu7wAAAWs"]
[Mon Jul 20 06:18:41.717292 2026] [security2:error] [pid 871012:tid 871178] [client 14.224.227.113:55655] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SIbwiU-Jh5ncAILFu8AAAAS0"]
[Mon Jul 20 06:18:41.718499 2026] [security2:error] [pid 874439:tid 874501] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUbAAAOj0"]
[Mon Jul 20 06:18:41.718698 2026] [security2:error] [pid 874439:tid 874627] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUbAAAOj0"]
[Mon Jul 20 06:18:41.747136 2026] [security2:error] [pid 874439:tid 874539] [remote 5.161.225.162:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4SIY6ZSrFvCrJJhtQUbgAAemM"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 06:18:41.753111 2026] [security2:error] [pid 874439:tid 874574] [client 14.224.227.113:55657] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SIY6ZSrFvCrJJhtQUbwAAAAU"]
[Mon Jul 20 06:18:42.497646 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SIo6ZSrFvCrJJhtQUjQAAAAI"]
[Mon Jul 20 06:18:42.745632 2026] [security2:error] [pid 871012:tid 871222] [client 50.116.65.227:44272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SIrwiU-Jh5ncAILFvAQAAAVk"]
[Mon Jul 20 06:18:42.757910 2026] [security2:error] [pid 874439:tid 874615] [client 50.116.65.227:33668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SIo6ZSrFvCrJJhtQUpAAAAC4"]
[Mon Jul 20 06:18:42.982687 2026] [security2:error] [pid 871012:tid 871160] [client 104.234.53.58:39379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SIrwiU-Jh5ncAILFvCgAAARs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:43.055012 2026] [security2:error] [pid 871012:tid 871236] [client 216.73.217.138:33816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SIrwiU-Jh5ncAILFvBwABZ08"]
[Mon Jul 20 06:18:43.240664 2026] [security2:error] [pid 874439:tid 874586] [client 50.116.65.227:33660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4SIo6ZSrFvCrJJhtQUmgAAABE"]
[Mon Jul 20 06:18:43.374945 2026] [security2:error] [pid 874439:tid 874678] [client 185.132.186.57:35433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/upload/bilder/cong.php"] [unique_id "al4SI46ZSrFvCrJJhtQUwwAAAG0"]
[Mon Jul 20 06:18:43.609696 2026] [security2:error] [pid 874439:tid 874622] [client 57.141.18.114:43226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SHY6ZSrFvCrJJhtQThQAANR8"]
[Mon Jul 20 06:18:43.721722 2026] [security2:error] [pid 874439:tid 874679] [client 171.60.139.123:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SI46ZSrFvCrJJhtQU0gAAAG4"]
[Mon Jul 20 06:18:43.721907 2026] [security2:error] [pid 874439:tid 874679] [client 171.60.139.123:51774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SI46ZSrFvCrJJhtQU0gAAAG4"]
[Mon Jul 20 06:18:43.784730 2026] [security2:error] [pid 874439:tid 874587] [client 14.225.17.146:56156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUyQAAABI"], referer: http://nwcarvingacademy.com/wp
[Mon Jul 20 06:18:43.844499 2026] [security2:error] [pid 874439:tid 874631] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUzQAAPmE"], referer: http://aleishapenny.ca/wp
[Mon Jul 20 06:18:43.856894 2026] [security2:error] [pid 874439:tid 874603] [client 57.141.18.20:52040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SHY6ZSrFvCrJJhtQTjQAAInU"]
[Mon Jul 20 06:18:43.961816 2026] [security2:error] [pid 874439:tid 874573] [client 98.159.234.160:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SI46ZSrFvCrJJhtQU3QAAAAQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:44.015676 2026] [security2:error] [pid 871012:tid 871238] [client 14.225.17.146:50644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4SI7wiU-Jh5ncAILFvLQAAAWk"], referer: http://dasmarque.com/wp
[Mon Jul 20 06:18:44.034568 2026] [security2:error] [pid 874439:tid 874673] [client 50.116.65.227:33684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUvAAAAGg"]
[Mon Jul 20 06:18:44.471833 2026] [security2:error] [pid 874439:tid 874508] [remote 57.141.18.56:32564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2898939"] [unique_id "al4SJI6ZSrFvCrJJhtQU-gAANUQ"]
[Mon Jul 20 06:18:44.660764 2026] [security2:error] [pid 874439:tid 874674] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVAAAAaX4"], referer: https://aleishapenny.ca/wp
[Mon Jul 20 06:18:44.738127 2026] [security2:error] [pid 874439:tid 874489] [remote 45.90.123.233:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVDgAADTE"]
[Mon Jul 20 06:18:44.755335 2026] [security2:error] [pid 874439:tid 874583] [client 45.116.69.230:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVEQAAAA4"]
[Mon Jul 20 06:18:44.757158 2026] [security2:error] [pid 874439:tid 874583] [client 45.116.69.230:59739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVEQAAAA4"]
[Mon Jul 20 06:18:44.929362 2026] [security2:error] [pid 871012:tid 871113] [remote 160.187.68.132:36474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJLwiU-Jh5ncAILFvRwABfGM"]
[Mon Jul 20 06:18:44.943042 2026] [security2:error] [pid 874439:tid 874481] [remote 45.90.123.233:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVGwAAQSk"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 06:18:45.086600 2026] [security2:error] [pid 874439:tid 874610] [client 14.225.17.146:62016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVFgAAACk"], referer: https://nwcarvingacademy.com/wp
[Mon Jul 20 06:18:45.100208 2026] [security2:error] [pid 871012:tid 871185] [client 103.141.108.143:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SJbwiU-Jh5ncAILFvUQAAATQ"]
[Mon Jul 20 06:18:45.100893 2026] [security2:error] [pid 871012:tid 871185] [client 103.141.108.143:61454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SJbwiU-Jh5ncAILFvUQAAATQ"]
[Mon Jul 20 06:18:45.156308 2026] [security2:error] [pid 874439:tid 874627] [client 14.225.17.146:55684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVHgAAADo"]
[Mon Jul 20 06:18:45.335688 2026] [security2:error] [pid 874439:tid 874586] [client 14.225.17.146:60666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVKQAAABE"], referer: http://nextlvlmarketingco.com/wp
[Mon Jul 20 06:18:45.447881 2026] [security2:error] [pid 874439:tid 874670] [client 14.225.17.146:60574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVHwAAAGU"], referer: http://backandneckpainrelieflaceychiropractor.com/wp
[Mon Jul 20 06:18:45.458699 2026] [security2:error] [pid 871012:tid 871087] [remote 160.187.68.132:36474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJbwiU-Jh5ncAILFvVgABLUk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:45.463022 2026] [security2:error] [pid 874439:tid 874591] [client 57.141.18.31:21596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SH46ZSrFvCrJJhtQT5wAAFhA"]
[Mon Jul 20 06:18:45.530673 2026] [security2:error] [pid 874439:tid 874598] [client 27.96.94.195:37136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVOgAAAB0"]
[Mon Jul 20 06:18:45.530809 2026] [security2:error] [pid 874439:tid 874598] [client 27.96.94.195:37136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVOgAAAB0"]
[Mon Jul 20 06:18:45.552258 2026] [security2:error] [pid 874439:tid 874440] [remote 167.233.114.32:42036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVQAAAdgA"]
[Mon Jul 20 06:18:45.579134 2026] [security2:error] [pid 874439:tid 874621] [client 14.225.17.146:50680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU4gAAADQ"], referer: http://blaizeaccountingservices.com/wp
[Mon Jul 20 06:18:45.806186 2026] [security2:error] [pid 874439:tid 874450] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVRwAAfAo"]
[Mon Jul 20 06:18:45.806318 2026] [security2:error] [pid 874439:tid 874693] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVRwAAfAo"]
[Mon Jul 20 06:18:45.887863 2026] [security2:error] [pid 874439:tid 874567] [remote 167.233.114.32:42036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVSgAAe38"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:45.969409 2026] [security2:error] [pid 874439:tid 874623] [client 14.225.17.146:61969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU9AAAADY"]
[Mon Jul 20 06:18:45.977543 2026] [security2:error] [pid 874439:tid 874669] [client 103.77.203.233:55465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVUQAAAGQ"]
[Mon Jul 20 06:18:45.977743 2026] [security2:error] [pid 874439:tid 874669] [client 103.77.203.233:55465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SJY6ZSrFvCrJJhtQVUQAAAGQ"]
[Mon Jul 20 06:18:46.030926 2026] [security2:error] [pid 874439:tid 874688] [client 57.141.18.2:42632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SII6ZSrFvCrJJhtQUDwAAd0E"]
[Mon Jul 20 06:18:46.209282 2026] [security2:error] [pid 871012:tid 871172] [client 185.132.186.98:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/pass.php"] [unique_id "al4SJrwiU-Jh5ncAILFvawAAASc"]
[Mon Jul 20 06:18:46.223966 2026] [security2:error] [pid 874439:tid 874564] [remote 20.153.140.50:58650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVWwAAQnw"]
[Mon Jul 20 06:18:46.254859 2026] [security2:error] [pid 871012:tid 871235] [client 74.208.214.194:49020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SJrwiU-Jh5ncAILFvbwAAAWY"]
[Mon Jul 20 06:18:46.318154 2026] [security2:error] [pid 874439:tid 874574] [client 178.152.178.232:36097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVYAAAAAU"]
[Mon Jul 20 06:18:46.318311 2026] [security2:error] [pid 874439:tid 874574] [client 178.152.178.232:36097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVYAAAAAU"]
[Mon Jul 20 06:18:46.569130 2026] [core:error] [pid 874439:tid 874690] [client 14.225.17.146:55824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:46.569152 2026] [core:error] [pid 874439:tid 874690] [client 14.225.17.146:55824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:18:46.703699 2026] [security2:error] [pid 874439:tid 874504] [remote 20.153.140.50:58650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVbQAAEkA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:46.761357 2026] [security2:error] [pid 871012:tid 871162] [client 104.234.53.78:55125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SJrwiU-Jh5ncAILFvewAAAR0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:46.787590 2026] [security2:error] [pid 871012:tid 871258] [client 57.141.18.104:47654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SIbwiU-Jh5ncAILFu4QABfT8"]
[Mon Jul 20 06:18:47.038966 2026] [security2:error] [pid 871012:tid 871183] [client 14.225.17.146:55700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4SJbwiU-Jh5ncAILFvVQAAATI"], referer: http://maplerespiteservices.com/wp
[Mon Jul 20 06:18:47.146844 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:55932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4SJo6ZSrFvCrJJhtQVaAAAAA0"], referer: http://waterproofgoods.com/wp
[Mon Jul 20 06:18:47.826780 2026] [security2:error] [pid 871012:tid 871169] [client 181.224.94.124:7695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvnQAAASQ"]
[Mon Jul 20 06:18:47.826893 2026] [security2:error] [pid 871012:tid 871169] [client 181.224.94.124:7695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvnQAAASQ"]
[Mon Jul 20 06:18:47.981837 2026] [security2:error] [pid 871012:tid 871204] [client 185.132.186.77:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/l10n/class-wp-translations-interface.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvoAAAAUc"]
[Mon Jul 20 06:18:48.026780 2026] [security2:error] [pid 871012:tid 871176] [client 57.141.18.120:47658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SIrwiU-Jh5ncAILFu9wABK2U"]
[Mon Jul 20 06:18:48.343285 2026] [security2:error] [pid 871012:tid 871035] [remote 81.173.115.7:45210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SKLwiU-Jh5ncAILFvpwABRRU"]
[Mon Jul 20 06:18:48.349685 2026] [security2:error] [pid 871012:tid 871163] [client 14.225.17.146:56202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4SJ7wiU-Jh5ncAILFvjwAAAR4"], referer: http://retzkolonglogistics.com/wp
[Mon Jul 20 06:18:48.786817 2026] [security2:error] [pid 871012:tid 871063] [remote 81.173.115.7:45210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SKLwiU-Jh5ncAILFvtQABeDE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:18:49.201356 2026] [autoindex:error] [pid 874439:tid 874668] [client 146.112.163.57:27143] AH01276: Cannot serve directory /home2/yfqjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:18:49.254074 2026] [security2:error] [pid 874439:tid 874694] [client 57.141.18.41:55698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SI46ZSrFvCrJJhtQUxQAAfTY"]
[Mon Jul 20 06:18:49.298193 2026] [ssl:error] [pid 874439:tid 874619] [client 54.86.115.253:27203] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.skiboutiques.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:18:49.593968 2026] [security2:error] [pid 871012:tid 871029] [remote 173.212.252.15:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4SKbwiU-Jh5ncAILFvxQABPQ8"]
[Mon Jul 20 06:18:49.770463 2026] [security2:error] [pid 874439:tid 874571] [client 185.132.186.74:48017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/about5.php"] [unique_id "al4SKY6ZSrFvCrJJhtQWAgAAAAI"]
[Mon Jul 20 06:18:49.774727 2026] [security2:error] [pid 871012:tid 871196] [client 57.141.18.78:65494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SI7wiU-Jh5ncAILFvKAABPzA"]
[Mon Jul 20 06:18:49.977795 2026] [security2:error] [pid 871012:tid 871098] [remote 173.212.252.15:53282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4SKbwiU-Jh5ncAILFv0QABG1Q"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:18:50.039934 2026] [security2:error] [pid 874439:tid 874653] [client 57.141.18.84:41874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU3wAAVA0"]
[Mon Jul 20 06:18:50.354042 2026] [security2:error] [pid 874439:tid 874586] [client 50.116.65.227:55168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SKo6ZSrFvCrJJhtQWHAAAABE"]
[Mon Jul 20 06:18:50.368979 2026] [security2:error] [pid 874439:tid 874659] [client 50.116.65.227:29192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SKo6ZSrFvCrJJhtQWHQAAAFo"]
[Mon Jul 20 06:18:50.422137 2026] [security2:error] [pid 874439:tid 874651] [client 57.141.18.20:29938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQU8gAAUno"]
[Mon Jul 20 06:18:50.437342 2026] [security2:error] [pid 871012:tid 871222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SKrwiU-Jh5ncAILFv1QAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:50.684837 2026] [security2:error] [pid 874439:tid 874640] [client 57.141.18.77:50334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJI6ZSrFvCrJJhtQVCgAARx0"]
[Mon Jul 20 06:18:51.012918 2026] [security2:error] [pid 874439:tid 874574] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SKo6ZSrFvCrJJhtQWMAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:51.028124 2026] [security2:error] [pid 874439:tid 874598] [client 124.243.178.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4SKI6ZSrFvCrJJhtQVsgAAHW0"]
[Mon Jul 20 06:18:51.046264 2026] [security2:error] [pid 874439:tid 874670] [client 114.119.144.132:56851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lutheranphilosopher.com"] [uri "/apps/members/membersList%3Bjsessionid=FE2B321CE0CEF378F3DBE62DAD1F077C"] [unique_id "al4SK46ZSrFvCrJJhtQWQgAAAGU"], referer: https://www.lutheranphilosopher.com/apps/members/membersList%3Bjsessionid=822B28D6867DCAC2CFBA9C8AF108AD91?offset=1&q&sort=DISPLAY_NAME&view=list
[Mon Jul 20 06:18:51.416393 2026] [security2:error] [pid 874439:tid 874524] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/price-table.js"] [unique_id "al4SK46ZSrFvCrJJhtQWUwAAZFQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.440040 2026] [security2:error] [pid 871012:tid 871071] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/jquery-migrate.js"] [unique_id "al4SK7wiU-Jh5ncAILFv-gABDDk"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.440879 2026] [security2:error] [pid 874439:tid 874456] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/owl.carousel.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWVQAAABA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.442626 2026] [security2:error] [pid 871012:tid 871064] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/js/v4-shims.js"] [unique_id "al4SK7wiU-Jh5ncAILFv-wABaTI"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.443323 2026] [security2:error] [pid 871012:tid 871120] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/jquery.js"] [unique_id "al4SK7wiU-Jh5ncAILFv_AABP2o"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.444280 2026] [security2:error] [pid 871012:tid 871082] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/allscripts.js"] [unique_id "al4SK7wiU-Jh5ncAILFv_QABcUQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.454852 2026] [security2:error] [pid 874439:tid 874521] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/wp-social/assets/js/front-main.js"] [unique_id "al4SK46ZSrFvCrJJhtQWWAAAaVE"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.455693 2026] [security2:error] [pid 874439:tid 874440] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/wp-social/assets/js/social-front.js"] [unique_id "al4SK46ZSrFvCrJJhtQWWQAAaQA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.459970 2026] [security2:error] [pid 871012:tid 871033] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/js-cookie/js.cookie.js"] [unique_id "al4SK7wiU-Jh5ncAILFv_wABShM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.461550 2026] [security2:error] [pid 871012:tid 871119] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widget-scripts.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAAABG2k"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.476536 2026] [security2:error] [pid 874439:tid 874554] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/jquery.easing.1.3.js"] [unique_id "al4SK46ZSrFvCrJJhtQWWwAAJXI"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.477504 2026] [security2:error] [pid 871012:tid 871086] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/wp-util.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAQABR0g"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.477862 2026] [security2:error] [pid 871012:tid 871065] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/frontend/woocommerce.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAgABdDM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.480661 2026] [security2:error] [pid 871012:tid 871102] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/themes/hello-elementor/assets/js/hello-frontend.js"] [unique_id "al4SK7wiU-Jh5ncAILFwAwABR1g"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483225 2026] [security2:error] [pid 871012:tid 871124] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/hooks.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBQABR24"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483226 2026] [security2:error] [pid 874439:tid 874486] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/i18n.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXAAAey4"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483483 2026] [security2:error] [pid 871012:tid 871025] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/underscore.min.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBAABRws"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.483816 2026] [security2:error] [pid 874439:tid 874484] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/frontend.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXQAANCw"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.485885 2026] [security2:error] [pid 874439:tid 874470] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/gum-elementor-addon/js/jquery.superslides.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXwAAex4"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.486112 2026] [security2:error] [pid 874439:tid 874484] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-consent-mode-86cb52dcb9f2b27ed244.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYAAANCw"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.486896 2026] [security2:error] [pid 874439:tid 874492] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/cookiez/assets/build/banner.js"] [unique_id "al4SK46ZSrFvCrJJhtQWXgAAezQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.488187 2026] [security2:error] [pid 871012:tid 871122] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/webpack.runtime.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBgABGGw"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.489729 2026] [security2:error] [pid 874439:tid 874450] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/ui/autocomplete.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYgAANAo"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.490056 2026] [security2:error] [pid 874439:tid 874499] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/lib/swiper/v8/swiper.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYQAANDs"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.491677 2026] [security2:error] [pid 874439:tid 874490] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/a11y.js"] [unique_id "al4SK46ZSrFvCrJJhtQWYwAANDI"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.492455 2026] [security2:error] [pid 871012:tid 871031] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/js/tourfic-scripts.min.js"] [unique_id "al4SK7wiU-Jh5ncAILFwBwABCxE"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.492716 2026] [security2:error] [pid 874439:tid 874567] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widgets/nav-menu.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZAAAGX8"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.493136 2026] [security2:error] [pid 871012:tid 871061] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementskit-lite/widgets/init/assets/js/widgets/core.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCAABCy8"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.496282 2026] [security2:error] [pid 874439:tid 874479] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/frontend-modules.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZQAAGSc"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.496888 2026] [security2:error] [pid 871012:tid 871132] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/js/elements-handlers.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCQABMXY"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.500050 2026] [security2:error] [pid 871012:tid 871015] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/metform/public/assets/lib/cute-alert/cute-alert.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCgABKwE"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.500773 2026] [security2:error] [pid 874439:tid 874487] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/lib/sticky/jquery.sticky.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZgAASy8"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.503085 2026] [security2:error] [pid 874439:tid 874477] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/wp-whatsapp-chat/build/frontend/js/index.js"] [unique_id "al4SK46ZSrFvCrJJhtQWagAAOSU"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.503147 2026] [security2:error] [pid 871012:tid 871057] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/flatpickr/flatpickr.min.js"] [unique_id "al4SK7wiU-Jh5ncAILFwCwABKys"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.503147 2026] [security2:error] [pid 874439:tid 874547] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/sourcebuster/sourcebuster.js"] [unique_id "al4SK46ZSrFvCrJJhtQWZwAAS2s"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.504306 2026] [security2:error] [pid 874439:tid 874496] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/slick/slick.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWaQAAOTg"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.506493 2026] [security2:error] [pid 871012:tid 871129] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/ui/menu.js"] [unique_id "al4SK7wiU-Jh5ncAILFwDAABOHM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.507199 2026] [security2:error] [pid 874439:tid 874459] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/leaflet/leaflet.js"] [unique_id "al4SK46ZSrFvCrJJhtQWawAAfxM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.508851 2026] [security2:error] [pid 874439:tid 874564] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/js/frontend.js"] [unique_id "al4SK46ZSrFvCrJJhtQWbAAAf3w"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.509032 2026] [security2:error] [pid 871012:tid 871030] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor-pro/assets/js/webpack-pro.runtime.js"] [unique_id "al4SK7wiU-Jh5ncAILFwDQABaBA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.509168 2026] [security2:error] [pid 874439:tid 874694] [client 104.234.53.76:45053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SK46ZSrFvCrJJhtQWbQAAAH0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:51.514025 2026] [security2:error] [pid 874439:tid 874516] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/range-slider/al-range-slider.js"] [unique_id "al4SK46ZSrFvCrJJhtQWbgAAY0w"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.515977 2026] [security2:error] [pid 874439:tid 874510] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/fancybox/jquery.fancybox.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWbwAAaEY"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.567638 2026] [security2:error] [pid 871012:tid 871257] [client 185.132.186.62:52067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/maint/lint-branch.php"] [unique_id "al4SK7wiU-Jh5ncAILFwDwAAAXw"]
[Mon Jul 20 06:18:51.735555 2026] [security2:error] [pid 874439:tid 874531] [remote 81.173.115.7:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4SK46ZSrFvCrJJhtQWdQAAdFs"]
[Mon Jul 20 06:18:51.843599 2026] [security2:error] [pid 871012:tid 871108] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/woocommerce/assets/js/jquery-blockui/jquery.blockUI.js"] [unique_id "al4SK7wiU-Jh5ncAILFwEgABHV4"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.890358 2026] [security2:error] [pid 874439:tid 874504] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/dist/dom-ready.js"] [unique_id "al4SK46ZSrFvCrJJhtQWfgAAAUA"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.897540 2026] [security2:error] [pid 874439:tid 874515] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/tourfic/assets/app/libs/notyf/notyf.min.js"] [unique_id "al4SK46ZSrFvCrJJhtQWfwAALUs"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.921456 2026] [security2:error] [pid 871012:tid 871081] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/jquery/ui/core.js"] [unique_id "al4SK7wiU-Jh5ncAILFwFgABKUM"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:51.929643 2026] [security2:error] [pid 874439:tid 874526] [remote 81.173.115.7:46022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4SK46ZSrFvCrJJhtQWggAAYlY"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:18:52.082109 2026] [security2:error] [pid 871012:tid 871161] [client 57.141.18.59:53262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJrwiU-Jh5ncAILFvZgABHD0"]
[Mon Jul 20 06:18:52.086172 2026] [security2:error] [pid 874439:tid 874671] [client 14.225.17.146:56543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWQwAAAGY"], referer: http://ancestralidadytrance.space/wp
[Mon Jul 20 06:18:52.336464 2026] [security2:error] [pid 874439:tid 874493] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/google-site-kit/dist/assets/js/googlesitekit-events-provider-woocommerce-454120fdf8df4537b59f.js"] [unique_id "al4SLI6ZSrFvCrJJhtQWlwAAGzU"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:52.343710 2026] [security2:error] [pid 871012:tid 871066] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/woocommerce-analytics/build/woocommerce-analytics-client.js"] [unique_id "al4SLLwiU-Jh5ncAILFwHQABhzQ"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:52.352344 2026] [security2:error] [pid 874439:tid 874463] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWmAAAORc"]
[Mon Jul 20 06:18:52.352547 2026] [security2:error] [pid 874439:tid 874626] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWmAAAORc"]
[Mon Jul 20 06:18:52.406946 2026] [security2:error] [pid 874439:tid 874605] [client 104.234.53.92:20285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWlAAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:52.461698 2026] [security2:error] [pid 874439:tid 874522] [remote 173.249.4.11:14695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWoAAAT1I"]
[Mon Jul 20 06:18:52.467367 2026] [security2:error] [pid 874439:tid 874591] [client 14.225.17.146:56428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4SKo6ZSrFvCrJJhtQWLAAAABY"], referer: http://soloceos.com/wp
[Mon Jul 20 06:18:52.618823 2026] [security2:error] [pid 871012:tid 871166] [client 50.116.65.227:29248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SLLwiU-Jh5ncAILFwIgAAASE"]
[Mon Jul 20 06:18:52.632719 2026] [security2:error] [pid 871012:tid 871220] [client 50.116.65.227:29262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SLLwiU-Jh5ncAILFwIwAAAVc"]
[Mon Jul 20 06:18:52.806835 2026] [security2:error] [pid 871012:tid 871059] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/wp-emoji.js"] [unique_id "al4SLLwiU-Jh5ncAILFwJgABSy0"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:52.823487 2026] [security2:error] [pid 874439:tid 874606] [client 27.96.94.195:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWrwAAACU"]
[Mon Jul 20 06:18:52.823584 2026] [security2:error] [pid 874439:tid 874606] [client 27.96.94.195:37948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWrwAAACU"]
[Mon Jul 20 06:18:52.862072 2026] [security2:error] [pid 874439:tid 874696] [client 112.208.70.94:42823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWsQAAAH8"]
[Mon Jul 20 06:18:52.862216 2026] [security2:error] [pid 874439:tid 874696] [client 112.208.70.94:42823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWsQAAAH8"]
[Mon Jul 20 06:18:52.958226 2026] [security2:error] [pid 874439:tid 874610] [client 14.225.17.146:56632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWSQAAACk"], referer: http://nomorewetsheets.net/wp
[Mon Jul 20 06:18:52.980581 2026] [security2:error] [pid 874439:tid 874659] [client 14.225.17.146:61480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWTgAAAFo"], referer: http://aberballet.co.uk/wp
[Mon Jul 20 06:18:53.162069 2026] [security2:error] [pid 874439:tid 874482] [remote 124.243.178.186:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-includes/js/twemoji.js"] [unique_id "al4SLY6ZSrFvCrJJhtQWyAAAFyo"], referer: https://paultoursafari.com/give-back/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 06:18:53.280849 2026] [security2:error] [pid 874439:tid 874627] [client 57.141.18.14:37870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJ46ZSrFvCrJJhtQVkAAAOhE"]
[Mon Jul 20 06:18:53.295119 2026] [security2:error] [pid 871012:tid 871149] [client 57.141.18.99:39862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SJ7wiU-Jh5ncAILFviwABECE"]
[Mon Jul 20 06:18:53.374726 2026] [security2:error] [pid 874439:tid 874674] [client 104.234.53.92:20285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SLY6ZSrFvCrJJhtQWywAAAGk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:53.381760 2026] [security2:error] [pid 874439:tid 874631] [client 185.132.186.87:51281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/cong.php"] [unique_id "al4SLY6ZSrFvCrJJhtQWzgAAAD4"]
[Mon Jul 20 06:18:53.678034 2026] [security2:error] [pid 874439:tid 874679] [client 14.225.17.146:61851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQW2gAAAG4"], referer: http://fkconstructionfunding.com/wp
[Mon Jul 20 06:18:54.104065 2026] [security2:error] [pid 871012:tid 871190] [client 57.141.18.60:21490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKLwiU-Jh5ncAILFvrgABOSI"]
[Mon Jul 20 06:18:54.393417 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXAQAAAAI"]
[Mon Jul 20 06:18:54.393529 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:52296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXAQAAAAI"]
[Mon Jul 20 06:18:54.527650 2026] [security2:error] [pid 874439:tid 874635] [client 43.161.234.148:40804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4SLo6ZSrFvCrJJhtQXCwAAAEI"]
[Mon Jul 20 06:18:54.644799 2026] [security2:error] [pid 874439:tid 874514] [remote 100.42.189.89:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXFwAATko"]
[Mon Jul 20 06:18:54.654491 2026] [security2:error] [pid 874439:tid 874572] [client 57.141.18.84:41890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKY6ZSrFvCrJJhtQV1gAAA24"]
[Mon Jul 20 06:18:54.701267 2026] [security2:error] [pid 874439:tid 874654] [client 14.225.17.146:64847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXEAAAAFU"], referer: https://fkconstructionfunding.com/wp
[Mon Jul 20 06:18:54.718291 2026] [security2:error] [pid 874439:tid 874537] [remote 57.141.18.34:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5107369"] [unique_id "al4SLo6ZSrFvCrJJhtQXHgAAHWE"]
[Mon Jul 20 06:18:54.844203 2026] [security2:error] [pid 874439:tid 874562] [remote 100.42.189.89:41900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXIgAAVHo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:18:54.873278 2026] [security2:error] [pid 871012:tid 871261] [client 57.141.18.31:23636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKbwiU-Jh5ncAILFvwQABgH4"]
[Mon Jul 20 06:18:55.145500 2026] [security2:error] [pid 874439:tid 874577] [client 14.225.17.146:62568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXGwAAAAg"], referer: http://overloadcomedy.com/wp
[Mon Jul 20 06:18:55.181615 2026] [security2:error] [pid 874439:tid 874572] [client 185.132.186.96:37489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/db.php"] [unique_id "al4SL46ZSrFvCrJJhtQXNwAAAAM"]
[Mon Jul 20 06:18:55.339614 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:64017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4SL46ZSrFvCrJJhtQXPAAAAG0"], referer: http://thefriendlyspreadsheet.com/wp
[Mon Jul 20 06:18:55.393963 2026] [security2:error] [pid 874439:tid 874669] [client 45.116.69.230:60274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXRQAAAGQ"]
[Mon Jul 20 06:18:55.394077 2026] [security2:error] [pid 874439:tid 874669] [client 45.116.69.230:60274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXRQAAAGQ"]
[Mon Jul 20 06:18:55.509318 2026] [security2:error] [pid 871012:tid 871224] [client 57.141.18.62:55952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SKbwiU-Jh5ncAILFv0AABWxk"]
[Mon Jul 20 06:18:55.631403 2026] [security2:error] [pid 874439:tid 874695] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4SL46ZSrFvCrJJhtQXWQAAAH4"]
[Mon Jul 20 06:18:55.664506 2026] [security2:error] [pid 874439:tid 874587] [client 14.225.17.146:62016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQW5wAAABI"], referer: http://fluidtemple.org/wp
[Mon Jul 20 06:18:55.833631 2026] [security2:error] [pid 874439:tid 874696] [client 103.141.108.143:61927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXZgAAAH8"]
[Mon Jul 20 06:18:55.833742 2026] [security2:error] [pid 874439:tid 874696] [client 103.141.108.143:61927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SL46ZSrFvCrJJhtQXZgAAAH8"]
[Mon Jul 20 06:18:56.160386 2026] [security2:error] [pid 874439:tid 874586] [client 103.153.183.69:30384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../.env"] [unique_id "al4SMI6ZSrFvCrJJhtQXggAAABE"], referer: https://duckduckgo.com/?q=hyeps
[Mon Jul 20 06:18:56.169442 2026] [security2:error] [pid 874439:tid 874598] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SMI6ZSrFvCrJJhtQXhAAAAB0"]
[Mon Jul 20 06:18:56.220554 2026] [security2:error] [pid 874439:tid 874492] [remote 159.65.81.207:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXhgAAUzQ"]
[Mon Jul 20 06:18:56.284266 2026] [security2:error] [pid 871012:tid 871094] [remote 152.228.213.32:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tumbletyn.com"] [uri "/wp-login.php"] [unique_id "al4SMLwiU-Jh5ncAILFwbQABP1A"]
[Mon Jul 20 06:18:56.370896 2026] [security2:error] [pid 874439:tid 874631] [client 158.173.89.95:35039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXjAAAAD4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:18:56.413927 2026] [security2:error] [pid 874439:tid 874477] [remote 159.65.81.207:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXkgAAGCU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:18:56.420028 2026] [security2:error] [pid 874439:tid 874637] [client 103.77.203.233:56027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXlAAAAEQ"]
[Mon Jul 20 06:18:56.420160 2026] [security2:error] [pid 874439:tid 874637] [client 103.77.203.233:56027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXlAAAAEQ"]
[Mon Jul 20 06:18:56.467887 2026] [security2:error] [pid 871012:tid 871037] [remote 152.228.213.32:41870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tumbletyn.com"] [uri "/wp-login.php"] [unique_id "al4SMLwiU-Jh5ncAILFwbgABVRc"], referer: https://tumbletyn.com/wp-login.php
[Mon Jul 20 06:18:56.468642 2026] [security2:error] [pid 874439:tid 874496] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXmQAAWjg"]
[Mon Jul 20 06:18:56.468775 2026] [security2:error] [pid 874439:tid 874659] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXmQAAWjg"]
[Mon Jul 20 06:18:56.484654 2026] [security2:error] [pid 874439:tid 874677] [client 14.225.17.146:61954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQW5AAAAGw"], referer: http://talknutritionwithlesley.com/wp
[Mon Jul 20 06:18:56.514335 2026] [security2:error] [pid 874439:tid 874638] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SMI6ZSrFvCrJJhtQXnAAAAEU"]
[Mon Jul 20 06:18:56.670267 2026] [security2:error] [pid 874439:tid 874682] [client 57.141.18.103:39880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWRgAAcWY"]
[Mon Jul 20 06:18:56.856859 2026] [security2:error] [pid 874439:tid 874578] [client 14.225.17.146:54870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXrAAAAAk"], referer: http://katsklar.com/wp
[Mon Jul 20 06:18:56.859935 2026] [security2:error] [pid 874439:tid 874614] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4SMI6ZSrFvCrJJhtQXsQAAAC0"]
[Mon Jul 20 06:18:56.986724 2026] [security2:error] [pid 874439:tid 874575] [client 185.132.186.58:41453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/buy.php"] [unique_id "al4SMI6ZSrFvCrJJhtQXvAAAAAY"]
[Mon Jul 20 06:18:57.210652 2026] [security2:error] [pid 874439:tid 874671] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SMY6ZSrFvCrJJhtQX0gAAAGY"]
[Mon Jul 20 06:18:57.233175 2026] [security2:error] [pid 874439:tid 874687] [client 57.141.18.107:55692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SK46ZSrFvCrJJhtQWeAAAdmg"]
[Mon Jul 20 06:18:57.344622 2026] [security2:error] [pid 871012:tid 871204] [client 177.42.58.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4SMbwiU-Jh5ncAILFweAAAAUc"]
[Mon Jul 20 06:18:57.462808 2026] [security2:error] [pid 871012:tid 871200] [client 178.152.178.232:37449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwggAAAUM"]
[Mon Jul 20 06:18:57.462978 2026] [security2:error] [pid 871012:tid 871200] [client 178.152.178.232:37449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwggAAAUM"]
[Mon Jul 20 06:18:57.550129 2026] [security2:error] [pid 874439:tid 874650] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4SMY6ZSrFvCrJJhtQX-wAAAFE"]
[Mon Jul 20 06:18:57.754863 2026] [security2:error] [pid 874439:tid 874655] [client 14.225.17.146:64075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4SMY6ZSrFvCrJJhtQYAAAAAFY"], referer: http://daseighty.net/wp
[Mon Jul 20 06:18:57.755988 2026] [security2:error] [pid 874439:tid 874688] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMY6ZSrFvCrJJhtQX1AAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:57.758515 2026] [security2:error] [pid 871012:tid 871183] [client 68.235.52.68:50928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwjQAAATI"]
[Mon Jul 20 06:18:57.758592 2026] [security2:error] [pid 871012:tid 871183] [client 68.235.52.68:50928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SMbwiU-Jh5ncAILFwjQAAATI"]
[Mon Jul 20 06:18:57.801940 2026] [security2:error] [pid 874439:tid 874641] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMY6ZSrFvCrJJhtQX1wAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:57.896665 2026] [security2:error] [pid 874439:tid 874657] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4SMY6ZSrFvCrJJhtQYDgAAAFg"]
[Mon Jul 20 06:18:57.961039 2026] [security2:error] [pid 874439:tid 874634] [client 50.116.65.227:55176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SMY6ZSrFvCrJJhtQYEgAAAEE"]
[Mon Jul 20 06:18:57.972467 2026] [security2:error] [pid 871012:tid 871178] [client 50.116.65.227:29406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SMbwiU-Jh5ncAILFwkAAAARk"]
[Mon Jul 20 06:18:58.141182 2026] [security2:error] [pid 874439:tid 874670] [client 57.141.18.112:35844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLI6ZSrFvCrJJhtQWqQAAZRQ"]
[Mon Jul 20 06:18:58.270861 2026] [security2:error] [pid 871012:tid 871234] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SMrwiU-Jh5ncAILFwngAAAWU"]
[Mon Jul 20 06:18:58.355673 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:7738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYIwAAAEw"]
[Mon Jul 20 06:18:58.355819 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:7738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYIwAAAEw"]
[Mon Jul 20 06:18:58.383194 2026] [security2:error] [pid 874439:tid 874621] [client 104.234.53.69:47289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYJAAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:18:58.385073 2026] [security2:error] [pid 871012:tid 871253] [client 57.141.18.63:38374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLLwiU-Jh5ncAILFwJwABeCc"]
[Mon Jul 20 06:18:58.610302 2026] [security2:error] [pid 874439:tid 874574] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SMo6ZSrFvCrJJhtQYMQAAAAU"]
[Mon Jul 20 06:18:58.770577 2026] [security2:error] [pid 874439:tid 874631] [client 185.132.186.64:61785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/db.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYQgAAAD4"]
[Mon Jul 20 06:18:58.866849 2026] [security2:error] [pid 874439:tid 874693] [client 57.141.18.2:65234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLY6ZSrFvCrJJhtQWzAAAfA8"]
[Mon Jul 20 06:18:58.909706 2026] [security2:error] [pid 871012:tid 871137] [remote 97.74.87.194:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4SMrwiU-Jh5ncAILFwrAABK3s"]
[Mon Jul 20 06:18:58.938456 2026] [security2:error] [pid 874439:tid 874597] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SMo6ZSrFvCrJJhtQYVQAAABw"]
[Mon Jul 20 06:18:59.012612 2026] [security2:error] [pid 871012:tid 871227] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMrwiU-Jh5ncAILFwqwAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:59.130055 2026] [security2:error] [pid 874439:tid 874453] [remote 20.173.88.122:56506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SM46ZSrFvCrJJhtQYXwAASw0"]
[Mon Jul 20 06:18:59.159027 2026] [security2:error] [pid 874439:tid 874655] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SMo6ZSrFvCrJJhtQYVgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:18:59.261870 2026] [security2:error] [pid 874439:tid 874603] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4SM46ZSrFvCrJJhtQYaAAAACI"]
[Mon Jul 20 06:18:59.467181 2026] [security2:error] [pid 874439:tid 874536] [remote 20.173.88.122:56506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SM46ZSrFvCrJJhtQYeAAAAmA"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:18:59.481700 2026] [security2:error] [pid 871012:tid 871029] [remote 97.74.87.194:34550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4SM7wiU-Jh5ncAILFwuQABhA8"], referer: https://justinagrayman.com/wp-login.php
[Mon Jul 20 06:18:59.595814 2026] [security2:error] [pid 874439:tid 874638] [client 57.141.18.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SM46ZSrFvCrJJhtQYdwAAAEU"]
[Mon Jul 20 06:18:59.596356 2026] [security2:error] [pid 874439:tid 874667] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4SM46ZSrFvCrJJhtQYhAAAAGI"]
[Mon Jul 20 06:18:59.621976 2026] [security2:error] [pid 871012:tid 871231] [client 14.225.17.146:64021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4SMrwiU-Jh5ncAILFwqgAAAWI"], referer: http://processorstudio.com/wp
[Mon Jul 20 06:18:59.797817 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.22:30836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQW-gAAP2Q"]
[Mon Jul 20 06:18:59.927925 2026] [security2:error] [pid 871012:tid 871167] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SM7wiU-Jh5ncAILFwwgAAASI"]
[Mon Jul 20 06:19:00.117845 2026] [security2:error] [pid 874439:tid 874612] [client 57.141.18.22:30850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXEgAAK3E"]
[Mon Jul 20 06:19:00.124801 2026] [security2:error] [pid 871012:tid 871224] [client 114.119.147.74:58501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hammadownenterprises.com"] [uri "/projects-item/construction-of-clark-meadow-lane"] [unique_id "al4SNLwiU-Jh5ncAILFwyQAAAVs"], referer: https://hammadownenterprises.com/projects-item/construction-of-clark-meadow-lane
[Mon Jul 20 06:19:00.197926 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.105:55954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SLo6ZSrFvCrJJhtQXGQAAaBw"]
[Mon Jul 20 06:19:00.276113 2026] [security2:error] [pid 871012:tid 871270] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SNLwiU-Jh5ncAILFwzwAAAYk"]
[Mon Jul 20 06:19:00.561847 2026] [security2:error] [pid 874439:tid 874675] [client 185.132.186.101:45193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/function/install.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYtwAAAGo"]
[Mon Jul 20 06:19:00.563971 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:59205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYtQAAAEM"], referer: https://processorstudio.com/wp
[Mon Jul 20 06:19:00.611892 2026] [security2:error] [pid 874439:tid 874650] [client 143.244.57.90:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4SNI6ZSrFvCrJJhtQYugAAAFE"]
[Mon Jul 20 06:19:00.925646 2026] [security2:error] [pid 874439:tid 874450] [remote 216.73.216.55:4868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4SNI6ZSrFvCrJJhtQY0wAAVAo"]
[Mon Jul 20 06:19:00.950288 2026] [security2:error] [pid 874439:tid 874619] [client 57.141.18.19:47220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SL46ZSrFvCrJJhtQXSQAAMmk"]
[Mon Jul 20 06:19:00.967118 2026] [security2:error] [pid 874439:tid 874499] [remote 154.0.166.254:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4SNI6ZSrFvCrJJhtQY1QAAWjs"]
[Mon Jul 20 06:19:01.091021 2026] [security2:error] [pid 874439:tid 874609] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYvwAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:01.364003 2026] [security2:error] [pid 874439:tid 874615] [client 93.177.118.251:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "wesmclucas.com"] [uri "/xmlrpc.php"] [unique_id "al4SMY6ZSrFvCrJJhtQXwAAALlY"]
[Mon Jul 20 06:19:01.464896 2026] [security2:error] [pid 871012:tid 871213] [client 57.141.18.52:34696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SL7wiU-Jh5ncAILFwZQABUEk"]
[Mon Jul 20 06:19:01.468550 2026] [security2:error] [pid 874439:tid 874672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYxQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:01.475404 2026] [security2:error] [pid 874439:tid 874567] [remote 154.0.166.254:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4SNY6ZSrFvCrJJhtQY9QAADn8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:19:01.755261 2026] [security2:error] [pid 874439:tid 874520] [remote 167.233.114.32:57706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4SNY6ZSrFvCrJJhtQZBQAAKFA"]
[Mon Jul 20 06:19:01.848463 2026] [security2:error] [pid 871012:tid 871209] [client 158.173.241.141:26689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4SNbwiU-Jh5ncAILFw9wAAAUw"], referer: http://sesamegreenbeans.com/tag/south-africa/
[Mon Jul 20 06:19:01.960182 2026] [security2:error] [pid 874439:tid 874451] [remote 167.233.114.32:57706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4SNY6ZSrFvCrJJhtQZDQAAQws"], referer: https://colinkeyphotography.com/wp-login.php
[Mon Jul 20 06:19:02.107003 2026] [security2:error] [pid 871012:tid 871152] [client 158.173.241.141:56551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4SNbwiU-Jh5ncAILFxAwAAARM"], referer: http://sesamegreenbeans.com/nine-days-south-africa-ix/
[Mon Jul 20 06:19:02.297416 2026] [security2:error] [pid 874439:tid 874671] [client 50.116.65.227:39064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SNo6ZSrFvCrJJhtQZLQAAAGY"]
[Mon Jul 20 06:19:02.307417 2026] [security2:error] [pid 874439:tid 874583] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZEQAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:02.310376 2026] [security2:error] [pid 874439:tid 874573] [client 50.116.65.227:39068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SNo6ZSrFvCrJJhtQZLwAAAAQ"]
[Mon Jul 20 06:19:02.364218 2026] [security2:error] [pid 874439:tid 874628] [client 185.132.186.104:50809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/tflow/av.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZNAAAADs"]
[Mon Jul 20 06:19:02.441440 2026] [security2:error] [pid 874439:tid 874668] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZJAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:02.586420 2026] [security2:error] [pid 874439:tid 874571] [client 50.116.65.227:14786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNo6ZSrFvCrJJhtQZQQAAAAI"]
[Mon Jul 20 06:19:02.600097 2026] [security2:error] [pid 874439:tid 874653] [client 50.116.65.227:39106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNo6ZSrFvCrJJhtQZQgAAAFQ"]
[Mon Jul 20 06:19:02.701308 2026] [security2:error] [pid 874439:tid 874587] [client 104.234.53.80:45255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZQwAAABI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:02.795824 2026] [security2:error] [pid 871012:tid 871252] [client 14.225.17.146:55182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4SNLwiU-Jh5ncAILFw2AAAAXc"], referer: http://floorsourcestock.com/wp
[Mon Jul 20 06:19:02.818574 2026] [security2:error] [pid 871012:tid 871172] [client 50.116.65.227:14794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNrwiU-Jh5ncAILFxGAAAASc"]
[Mon Jul 20 06:19:02.830552 2026] [security2:error] [pid 874439:tid 874682] [client 50.116.65.227:39138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SNo6ZSrFvCrJJhtQZSQAAAHE"]
[Mon Jul 20 06:19:02.901521 2026] [security2:error] [pid 871012:tid 871267] [client 50.116.65.227:39122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SNrwiU-Jh5ncAILFxFwAAAYY"]
[Mon Jul 20 06:19:02.919871 2026] [security2:error] [pid 874439:tid 874687] [client 104.234.53.80:45255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZUQAAAHY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:02.974508 2026] [security2:error] [pid 871012:tid 871129] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SNrwiU-Jh5ncAILFxHwABQnM"]
[Mon Jul 20 06:19:02.974708 2026] [security2:error] [pid 871012:tid 871199] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SNrwiU-Jh5ncAILFxHwABQnM"]
[Mon Jul 20 06:19:03.051427 2026] [security2:error] [pid 874439:tid 874641] [client 14.225.17.146:63804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYuQAAAEg"], referer: http://mrbambooplus.com/wp
[Mon Jul 20 06:19:03.134140 2026] [security2:error] [pid 874439:tid 874638] [client 50.116.65.227:39156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SNo6ZSrFvCrJJhtQZUwAAAEU"]
[Mon Jul 20 06:19:03.614778 2026] [security2:error] [pid 874439:tid 874693] [client 113.160.142.119:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4SN46ZSrFvCrJJhtQZdgAAAHw"]
[Mon Jul 20 06:19:03.614969 2026] [security2:error] [pid 874439:tid 874693] [client 113.160.142.119:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4SN46ZSrFvCrJJhtQZdgAAAHw"]
[Mon Jul 20 06:19:03.674725 2026] [security2:error] [pid 871012:tid 871228] [client 57.141.18.86:49994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SMrwiU-Jh5ncAILFwmAABXzY"]
[Mon Jul 20 06:19:03.907200 2026] [security2:error] [pid 874439:tid 874644] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SN46ZSrFvCrJJhtQZcgAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:03.969594 2026] [security2:error] [pid 874439:tid 874605] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SN46ZSrFvCrJJhtQZfwAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:04.171543 2026] [security2:error] [pid 871012:tid 871212] [client 185.132.186.98:58253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/dist/bypass.php"] [unique_id "al4SOLwiU-Jh5ncAILFxRQAAAU8"]
[Mon Jul 20 06:19:04.268360 2026] [security2:error] [pid 871012:tid 871168] [client 14.225.17.146:65257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4SN7wiU-Jh5ncAILFxJQAAASM"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/wp
[Mon Jul 20 06:19:04.403558 2026] [security2:error] [pid 874439:tid 874608] [client 57.141.18.96:24592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SM46ZSrFvCrJJhtQYXAAAJ3g"]
[Mon Jul 20 06:19:04.416216 2026] [security2:error] [pid 871012:tid 871154] [client 185.223.152.44:50729] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "giftsurprizo.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4SOLwiU-Jh5ncAILFxSAAAARU"]
[Mon Jul 20 06:19:04.782127 2026] [security2:error] [pid 874439:tid 874587] [client 103.153.183.69:15676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../var/www/html/.env"] [unique_id "al4SOI6ZSrFvCrJJhtQZuwAAABI"], referer: https://www.reddit.com/
[Mon Jul 20 06:19:04.790134 2026] [security2:error] [pid 874439:tid 874622] [client 14.225.17.146:63468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZsgAAADU"], referer: https://north-woods-engineering.com/wp
[Mon Jul 20 06:19:04.809839 2026] [security2:error] [pid 874439:tid 874678] [client 103.153.183.69:15676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../var/www/.env"] [unique_id "al4SOI6ZSrFvCrJJhtQZvQAAAG0"], referer: https://www.google.com/search?q=uudfzk
[Mon Jul 20 06:19:04.834718 2026] [security2:error] [pid 874439:tid 874614] [client 103.153.183.69:15676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//var/www/html/wp-config.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZvgAAAC0"], referer: https://www.facebook.com/
[Mon Jul 20 06:19:04.884266 2026] [security2:error] [pid 871012:tid 871204] [client 104.234.53.67:28001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SOLwiU-Jh5ncAILFxYAAAAUc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:04.977210 2026] [security2:error] [pid 874439:tid 874603] [client 27.96.94.195:37043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZyQAAACI"]
[Mon Jul 20 06:19:04.977392 2026] [security2:error] [pid 874439:tid 874603] [client 27.96.94.195:37043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SOI6ZSrFvCrJJhtQZyQAAACI"]
[Mon Jul 20 06:19:05.055418 2026] [security2:error] [pid 874439:tid 874578] [client 50.116.65.227:14798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SOY6ZSrFvCrJJhtQZzwAAAAk"]
[Mon Jul 20 06:19:05.063814 2026] [security2:error] [pid 874439:tid 874540] [remote 192.241.143.148:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ0gAAGmQ"]
[Mon Jul 20 06:19:05.066060 2026] [security2:error] [pid 871012:tid 871240] [client 50.116.65.227:39244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SObwiU-Jh5ncAILFxZAAAAWs"]
[Mon Jul 20 06:19:05.105671 2026] [security2:error] [pid 871012:tid 871198] [client 171.60.139.123:52801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SObwiU-Jh5ncAILFxZgAAAUE"]
[Mon Jul 20 06:19:05.105800 2026] [security2:error] [pid 871012:tid 871198] [client 171.60.139.123:52801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SObwiU-Jh5ncAILFxZgAAAUE"]
[Mon Jul 20 06:19:05.184726 2026] [security2:error] [pid 871012:tid 871244] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SOLwiU-Jh5ncAILFxYgAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:05.226652 2026] [security2:error] [pid 874439:tid 874549] [remote 192.241.143.148:55524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ4wAAKW0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:19:05.240511 2026] [security2:error] [pid 874439:tid 874696] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "waltzingdogsllc.com"] [uri "/.well-known/about.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ5QAAAH8"]
[Mon Jul 20 06:19:05.240690 2026] [security2:error] [pid 874439:tid 874696] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "waltzingdogsllc.com"] [uri "/.well-known/about.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ5QAAAH8"]
[Mon Jul 20 06:19:05.376706 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ2QAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:05.392628 2026] [security2:error] [pid 871012:tid 871220] [client 57.141.18.69:41414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNLwiU-Jh5ncAILFwzAABV0U"]
[Mon Jul 20 06:19:05.516527 2026] [security2:error] [pid 874439:tid 874677] [client 34.147.16.58:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.eloisetate.com"] [uri "/"] [unique_id "al4SOY6ZSrFvCrJJhtQZ9gAAAGw"]
[Mon Jul 20 06:19:05.516620 2026] [security2:error] [pid 874439:tid 874677] [client 34.147.16.58:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.eloisetate.com"] [uri "/"] [unique_id "al4SOY6ZSrFvCrJJhtQZ9gAAAGw"]
[Mon Jul 20 06:19:05.673195 2026] [security2:error] [pid 874439:tid 874632] [client 57.141.18.125:32564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNI6ZSrFvCrJJhtQYsgAAPwA"]
[Mon Jul 20 06:19:05.866011 2026] [security2:error] [pid 871012:tid 871016] [remote 152.228.213.32:47982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SObwiU-Jh5ncAILFxiAABPQI"]
[Mon Jul 20 06:19:05.993193 2026] [security2:error] [pid 874439:tid 874659] [client 185.132.186.53:50875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/testt.php"] [unique_id "al4SOY6ZSrFvCrJJhtQaFAAAAFo"]
[Mon Jul 20 06:19:06.117177 2026] [security2:error] [pid 871012:tid 871072] [remote 152.228.213.32:47982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4SOrwiU-Jh5ncAILFxjgABNjo"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:19:06.275193 2026] [security2:error] [pid 874439:tid 874638] [client 45.116.69.230:60817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaKQAAAEU"]
[Mon Jul 20 06:19:06.275315 2026] [security2:error] [pid 874439:tid 874638] [client 45.116.69.230:60817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaKQAAAEU"]
[Mon Jul 20 06:19:06.354689 2026] [security2:error] [pid 874439:tid 874593] [client 57.141.18.30:46408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNY6ZSrFvCrJJhtQY4AAAGBM"]
[Mon Jul 20 06:19:06.395507 2026] [security2:error] [pid 874439:tid 874591] [client 14.225.17.146:50928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4SOY6ZSrFvCrJJhtQZ8gAAABY"], referer: http://dnsplumbing.com/wp
[Mon Jul 20 06:19:06.557849 2026] [security2:error] [pid 871012:tid 871240] [client 103.141.108.143:62406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SOrwiU-Jh5ncAILFxkgAAAWs"]
[Mon Jul 20 06:19:06.557988 2026] [security2:error] [pid 871012:tid 871240] [client 103.141.108.143:62406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SOrwiU-Jh5ncAILFxkgAAAWs"]
[Mon Jul 20 06:19:06.639088 2026] [security2:error] [pid 874439:tid 874670] [client 57.141.18.18:52344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SNY6ZSrFvCrJJhtQZAAAAZVs"]
[Mon Jul 20 06:19:06.639984 2026] [security2:error] [pid 874439:tid 874608] [client 112.208.70.94:43248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaRAAAACc"]
[Mon Jul 20 06:19:06.640107 2026] [security2:error] [pid 874439:tid 874608] [client 112.208.70.94:43248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaRAAAACc"]
[Mon Jul 20 06:19:06.916486 2026] [security2:error] [pid 874439:tid 874600] [client 103.77.203.233:56597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaTgAAAB8"]
[Mon Jul 20 06:19:06.916719 2026] [security2:error] [pid 874439:tid 874600] [client 103.77.203.233:56597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaTgAAAB8"]
[Mon Jul 20 06:19:07.175846 2026] [security2:error] [pid 874439:tid 874502] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SO46ZSrFvCrJJhtQaZgAAKT4"]
[Mon Jul 20 06:19:07.176038 2026] [security2:error] [pid 874439:tid 874610] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SO46ZSrFvCrJJhtQaZgAAKT4"]
[Mon Jul 20 06:19:07.451276 2026] [security2:error] [pid 871012:tid 871255] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SO7wiU-Jh5ncAILFxogAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:07.477699 2026] [security2:error] [pid 874439:tid 874645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SO46ZSrFvCrJJhtQaagAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:07.637419 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:57832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4SOo6ZSrFvCrJJhtQaOAAAAHY"], referer: http://adultdaycarereno.com/wp
[Mon Jul 20 06:19:07.794017 2026] [security2:error] [pid 874439:tid 874633] [client 185.132.186.61:49115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/goods.php"] [unique_id "al4SO46ZSrFvCrJJhtQajQAAAEA"]
[Mon Jul 20 06:19:08.050609 2026] [security2:error] [pid 871012:tid 871206] [client 14.225.17.146:63472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4SObwiU-Jh5ncAILFxiQAAAUk"], referer: http://jvcmotorsports.com/wp
[Mon Jul 20 06:19:08.150340 2026] [security2:error] [pid 874439:tid 874577] [client 178.152.178.232:36977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQaoQAAAAg"]
[Mon Jul 20 06:19:08.150496 2026] [security2:error] [pid 874439:tid 874577] [client 178.152.178.232:36977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQaoQAAAAg"]
[Mon Jul 20 06:19:08.223698 2026] [security2:error] [pid 874439:tid 874601] [client 57.141.18.0:30440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SN46ZSrFvCrJJhtQZZgAAIBs"]
[Mon Jul 20 06:19:08.542244 2026] [security2:error] [pid 874439:tid 874646] [client 14.225.17.146:54855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4SPI6ZSrFvCrJJhtQatAAAAE0"], referer: https://adultdaycarereno.com/wp
[Mon Jul 20 06:19:08.887997 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:56182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa0gAAAEw"]
[Mon Jul 20 06:19:08.888136 2026] [security2:error] [pid 874439:tid 874645] [client 181.224.94.124:56182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa0gAAAEw"]
[Mon Jul 20 06:19:09.093969 2026] [security2:error] [pid 874439:tid 874690] [client 104.234.53.63:53455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa2QAAAHk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:09.437911 2026] [lsapi:warn] [pid 871012:tid 871173] [client 14.225.17.146:55479] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wp
[Mon Jul 20 06:19:09.437931 2026] [lsapi:warn] [pid 871012:tid 871173] [client 14.225.17.146:55479] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wp
[Mon Jul 20 06:19:09.513419 2026] [security2:error] [pid 874439:tid 874692] [client 104.234.53.63:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SPY6ZSrFvCrJJhtQbAQAAAHs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:09.578874 2026] [security2:error] [pid 871012:tid 871217] [client 185.132.186.66:55611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/sad.php"] [unique_id "al4SPbwiU-Jh5ncAILFx1wAAAVQ"]
[Mon Jul 20 06:19:09.873857 2026] [security2:error] [pid 871012:tid 871235] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SPbwiU-Jh5ncAILFx2gAAAWY"]
[Mon Jul 20 06:19:09.944674 2026] [lsapi:warn] [pid 874439:tid 874678] [client 50.116.65.227:38236] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:19:09.944715 2026] [lsapi:warn] [pid 874439:tid 874678] [client 50.116.65.227:38236] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:19:09.960223 2026] [security2:error] [pid 871012:tid 871173] [client 14.225.17.146:55479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4SPLwiU-Jh5ncAILFxvwAAASg"], referer: http://oswegooperatheater.com/wp
[Mon Jul 20 06:19:09.998966 2026] [security2:error] [pid 874439:tid 874666] [client 14.225.17.146:55449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4SPI6ZSrFvCrJJhtQa1gAAAGE"], referer: http://musichaven.info/wp
[Mon Jul 20 06:19:10.134394 2026] [security2:error] [pid 874439:tid 874670] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SPY6ZSrFvCrJJhtQbEwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:10.203193 2026] [security2:error] [pid 874439:tid 874601] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SPY6ZSrFvCrJJhtQbGgAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:10.516897 2026] [security2:error] [pid 871012:tid 871223] [client 34.34.17.27:57344] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.almadisplay.ca"] [uri "/"] [unique_id "al4SPrwiU-Jh5ncAILFx6QAAAVo"]
[Mon Jul 20 06:19:10.516973 2026] [security2:error] [pid 871012:tid 871223] [client 34.34.17.27:57344] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.almadisplay.ca"] [uri "/"] [unique_id "al4SPrwiU-Jh5ncAILFx6QAAAVo"]
[Mon Jul 20 06:19:10.861685 2026] [lsapi:warn] [pid 874439:tid 874649] [client 14.225.17.146:65435] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wp
[Mon Jul 20 06:19:10.861702 2026] [lsapi:warn] [pid 874439:tid 874649] [client 14.225.17.146:65435] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wp
[Mon Jul 20 06:19:10.906561 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:65434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4SPo6ZSrFvCrJJhtQbVAAAAEM"], referer: https://musichaven.info/wp
[Mon Jul 20 06:19:10.913689 2026] [security2:error] [pid 874439:tid 874649] [client 14.225.17.146:65435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4SPo6ZSrFvCrJJhtQbVQAAAFA"], referer: https://oswegooperatheater.com/wp
[Mon Jul 20 06:19:11.014390 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.82:25568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SOY6ZSrFvCrJJhtQaDQAATi4"]
[Mon Jul 20 06:19:11.130829 2026] [security2:error] [pid 874439:tid 874676] [client 52.59.238.198:48558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbZAAAAGs"]
[Mon Jul 20 06:19:11.360656 2026] [security2:error] [pid 874439:tid 874484] [remote 162.19.86.63:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbdgAAcCw"]
[Mon Jul 20 06:19:11.374352 2026] [security2:error] [pid 874439:tid 874650] [client 185.132.186.62:40251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/wp-conflg.php"] [unique_id "al4SP46ZSrFvCrJJhtQbeAAAAFE"]
[Mon Jul 20 06:19:11.545565 2026] [security2:error] [pid 874439:tid 874545] [remote 162.19.86.63:47658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbgwAAfWk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:11.706667 2026] [security2:error] [pid 874439:tid 874646] [client 63.176.132.15:31468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbigAAAE0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:19:11.800297 2026] [security2:error] [pid 871012:tid 871199] [client 50.116.65.227:38294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SP7wiU-Jh5ncAILFx_QAAAUI"]
[Mon Jul 20 06:19:11.810956 2026] [security2:error] [pid 874439:tid 874695] [client 50.116.65.227:38308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SP46ZSrFvCrJJhtQbkgAAAH4"]
[Mon Jul 20 06:19:11.905341 2026] [security2:error] [pid 874439:tid 874592] [client 104.234.53.62:49711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SP46ZSrFvCrJJhtQbmgAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:12.107334 2026] [security2:error] [pid 874439:tid 874609] [client 34.74.185.202:55723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SQI6ZSrFvCrJJhtQbsQAAACg"]
[Mon Jul 20 06:19:12.204832 2026] [security2:error] [pid 874439:tid 874635] [client 57.141.18.76:52934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SO46ZSrFvCrJJhtQaVQAAQkw"]
[Mon Jul 20 06:19:12.219440 2026] [security2:error] [pid 874439:tid 874502] [remote 20.153.140.50:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4SQI6ZSrFvCrJJhtQbuQAADj4"]
[Mon Jul 20 06:19:12.443689 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.34:40340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SO46ZSrFvCrJJhtQacwAAaDI"]
[Mon Jul 20 06:19:12.650588 2026] [security2:error] [pid 874439:tid 874452] [remote 20.153.140.50:50406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4SQI6ZSrFvCrJJhtQb2gAAUgw"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:19:12.819136 2026] [security2:error] [pid 874439:tid 874607] [client 50.116.65.227:37594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SQI6ZSrFvCrJJhtQb4AAAACY"]
[Mon Jul 20 06:19:12.830306 2026] [security2:error] [pid 874439:tid 874652] [client 50.116.65.227:38324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4SQI6ZSrFvCrJJhtQb4QAAAFM"]
[Mon Jul 20 06:19:12.915907 2026] [security2:error] [pid 874439:tid 874632] [client 104.158.101.130:54744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4SQI6ZSrFvCrJJhtQb6AAAAD8"]
[Mon Jul 20 06:19:13.026368 2026] [security2:error] [pid 874439:tid 874586] [client 74.7.227.179:33392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SQI6ZSrFvCrJJhtQb5wAAEWw"], referer: https://tejasenvironmental.com/p=920849
[Mon Jul 20 06:19:13.037441 2026] [security2:error] [pid 874439:tid 874629] [client 34.74.185.202:50598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SQY6ZSrFvCrJJhtQb8wAAADw"]
[Mon Jul 20 06:19:13.181869 2026] [security2:error] [pid 874439:tid 874614] [client 185.132.186.79:46117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/wp-includes/assets/script-loader-packages.php"] [unique_id "al4SQY6ZSrFvCrJJhtQb_QAAAC0"]
[Mon Jul 20 06:19:13.603761 2026] [security2:error] [pid 874439:tid 874539] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SQY6ZSrFvCrJJhtQcGwAAMmM"]
[Mon Jul 20 06:19:13.603959 2026] [security2:error] [pid 874439:tid 874619] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SQY6ZSrFvCrJJhtQcGwAAMmM"]
[Mon Jul 20 06:19:13.683067 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.44:35842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPI6ZSrFvCrJJhtQauwAAAio"]
[Mon Jul 20 06:19:13.746625 2026] [security2:error] [pid 871012:tid 871160] [client 14.251.3.155:55669] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SQbwiU-Jh5ncAILFyKAAAARs"]
[Mon Jul 20 06:19:13.814195 2026] [security2:error] [pid 871012:tid 871246] [client 34.74.185.202:61102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SQbwiU-Jh5ncAILFyKQAAAXE"]
[Mon Jul 20 06:19:14.059796 2026] [security2:error] [pid 874439:tid 874661] [client 74.208.214.194:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SQo6ZSrFvCrJJhtQcNAAAAFw"]
[Mon Jul 20 06:19:14.097059 2026] [security2:error] [pid 871012:tid 871161] [client 14.225.17.146:65272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4SQbwiU-Jh5ncAILFyEwAAARw"], referer: http://entuvy.com/wp
[Mon Jul 20 06:19:14.171053 2026] [security2:error] [pid 874439:tid 874682] [client 57.141.18.8:56858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPY6ZSrFvCrJJhtQa3gAAcQY"]
[Mon Jul 20 06:19:14.226074 2026] [security2:error] [pid 871012:tid 871222] [client 158.173.166.181:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SQrwiU-Jh5ncAILFyOQAAAVk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:14.330310 2026] [security2:error] [pid 871012:tid 871268] [client 57.141.18.10:55498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPbwiU-Jh5ncAILFxxQABhyc"]
[Mon Jul 20 06:19:14.332570 2026] [security2:error] [pid 871012:tid 871233] [client 57.141.18.31:50824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPbwiU-Jh5ncAILFxxwABZCY"]
[Mon Jul 20 06:19:14.450359 2026] [security2:error] [pid 871012:tid 871237] [client 34.74.185.202:55613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SQrwiU-Jh5ncAILFyPQAAAWg"]
[Mon Jul 20 06:19:14.694107 2026] [security2:error] [pid 874439:tid 874641] [client 50.116.65.227:37604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SQo6ZSrFvCrJJhtQcXAAAAEg"]
[Mon Jul 20 06:19:14.705146 2026] [security2:error] [pid 871012:tid 871170] [client 50.116.65.227:38366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SQrwiU-Jh5ncAILFyRQAAASo"]
[Mon Jul 20 06:19:14.800440 2026] [security2:error] [pid 871012:tid 871254] [client 14.225.17.146:55192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4SQbwiU-Jh5ncAILFyJgAAAXk"], referer: http://travelbyfire.com/wp
[Mon Jul 20 06:19:14.802000 2026] [security2:error] [pid 874439:tid 874582] [client 77.110.127.138:59964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4SQo6ZSrFvCrJJhtQcZwAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:14.950674 2026] [security2:error] [pid 874439:tid 874611] [client 77.110.127.138:59967] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/cake-recipe/feed/"] [unique_id "al4SQo6ZSrFvCrJJhtQccAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:14.985685 2026] [security2:error] [pid 874439:tid 874609] [client 90.254.155.226:53000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4SQo6ZSrFvCrJJhtQccwAAACg"]
[Mon Jul 20 06:19:14.987219 2026] [security2:error] [pid 874439:tid 874687] [client 185.132.186.80:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/login.php"] [unique_id "al4SQo6ZSrFvCrJJhtQcdAAAAHY"]
[Mon Jul 20 06:19:15.002286 2026] [security2:error] [pid 874439:tid 874648] [client 87.18.141.108:42414] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4SQo6ZSrFvCrJJhtQcdwAAAE8"]
[Mon Jul 20 06:19:15.079230 2026] [security2:error] [pid 874439:tid 874673] [client 213.196.104.179:53807] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4SQ46ZSrFvCrJJhtQcgAAAAGg"]
[Mon Jul 20 06:19:15.101239 2026] [security2:error] [pid 871012:tid 871251] [client 14.187.227.208:41036] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyUQAAAXY"]
[Mon Jul 20 06:19:15.156666 2026] [security2:error] [pid 874439:tid 874536] [remote 176.56.118.182:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SQ46ZSrFvCrJJhtQchgAAG2A"]
[Mon Jul 20 06:19:15.215319 2026] [security2:error] [pid 871012:tid 871150] [client 57.141.18.105:49620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SPrwiU-Jh5ncAILFx4gABESA"]
[Mon Jul 20 06:19:15.264853 2026] [security2:error] [pid 874439:tid 874607] [client 176.102.194.224:41014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQcjgAAACY"]
[Mon Jul 20 06:19:15.265275 2026] [security2:error] [pid 874439:tid 874639] [client 24.141.218.37:38808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQcjQAAAEY"]
[Mon Jul 20 06:19:15.327148 2026] [security2:error] [pid 874439:tid 874575] [client 94.134.181.70:24253] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4SQ46ZSrFvCrJJhtQckAAAAAY"]
[Mon Jul 20 06:19:15.354782 2026] [security2:error] [pid 874439:tid 874696] [client 87.10.98.33:57244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQclAAAAH8"]
[Mon Jul 20 06:19:15.393272 2026] [security2:error] [pid 871012:tid 871249] [client 89.115.22.45:41482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4SQ7wiU-Jh5ncAILFyWwAAAXQ"]
[Mon Jul 20 06:19:15.393831 2026] [security2:error] [pid 874439:tid 874540] [remote 176.56.118.182:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SQ46ZSrFvCrJJhtQclwAAcWQ"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:15.423951 2026] [security2:error] [pid 871012:tid 871207] [client 86.146.184.240:60226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyXQAAAUo"]
[Mon Jul 20 06:19:15.430847 2026] [security2:error] [pid 871012:tid 871224] [client 216.244.66.243:52896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/auth/login"] [unique_id "al4SQ7wiU-Jh5ncAILFyXgAAAVs"]
[Mon Jul 20 06:19:15.430934 2026] [security2:error] [pid 871012:tid 871224] [client 216.244.66.243:52896] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/auth/login"] [unique_id "al4SQ7wiU-Jh5ncAILFyXgAAAVs"]
[Mon Jul 20 06:19:15.442278 2026] [security2:error] [pid 874439:tid 874649] [client 45.45.237.8:50462] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.git/HEAD"] [unique_id "al4SQ46ZSrFvCrJJhtQcmgAAAFA"]
[Mon Jul 20 06:19:15.463515 2026] [security2:error] [pid 871012:tid 871201] [client 190.69.45.223:54326] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyXwAAAUQ"]
[Mon Jul 20 06:19:15.489591 2026] [security2:error] [pid 874439:tid 874648] [client 34.74.185.202:52294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SQ46ZSrFvCrJJhtQcnwAAAE8"]
[Mon Jul 20 06:19:15.549087 2026] [security2:error] [pid 874439:tid 874681] [client 190.89.84.189:6051] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4SQ46ZSrFvCrJJhtQcpgAAAHA"]
[Mon Jul 20 06:19:15.662983 2026] [security2:error] [pid 871012:tid 871173] [client 81.213.218.124:39482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4SQ7wiU-Jh5ncAILFyZQAAASg"]
[Mon Jul 20 06:19:15.727869 2026] [security2:error] [pid 874439:tid 874678] [client 14.225.17.146:58078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4SQ46ZSrFvCrJJhtQctAAAAG0"], referer: https://travelbyfire.com/wp
[Mon Jul 20 06:19:15.766891 2026] [security2:error] [pid 871012:tid 871194] [client 93.38.25.239:33284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4SQ7wiU-Jh5ncAILFyZwAAAT0"]
[Mon Jul 20 06:19:15.782425 2026] [security2:error] [pid 874439:tid 874606] [client 171.60.139.123:53325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcwAAAACU"]
[Mon Jul 20 06:19:15.782538 2026] [security2:error] [pid 874439:tid 874606] [client 171.60.139.123:53325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcwAAAACU"]
[Mon Jul 20 06:19:15.809268 2026] [security2:error] [pid 871012:tid 871212] [client 37.202.11.102:46394] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamawcubgee.woff2"] [unique_id "al4SQ7wiU-Jh5ncAILFyaAAAAU8"]
[Mon Jul 20 06:19:15.869726 2026] [security2:error] [pid 874439:tid 874607] [client 65.1.132.125:27410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcywAAACY"]
[Mon Jul 20 06:19:15.869865 2026] [security2:error] [pid 874439:tid 874607] [client 65.1.132.125:27410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcywAAACY"]
[Mon Jul 20 06:19:15.878785 2026] [security2:error] [pid 874439:tid 874650] [client 87.216.97.139:34216] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4SQ46ZSrFvCrJJhtQczAAAAFE"]
[Mon Jul 20 06:19:15.887944 2026] [security2:error] [pid 874439:tid 874592] [client 103.99.162.124:10121] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4SQ46ZSrFvCrJJhtQczQAAABc"]
[Mon Jul 20 06:19:15.895916 2026] [security2:error] [pid 871012:tid 871042] [remote 220.181.108.90:16670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/index.php/store-share/"] [unique_id "al4SQ7wiU-Jh5ncAILFyagABXhw"]
[Mon Jul 20 06:19:16.020877 2026] [security2:error] [pid 874439:tid 874605] [client 45.45.237.8:50448] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.well-known/security.txt"] [unique_id "al4SRI6ZSrFvCrJJhtQc0gAAACQ"]
[Mon Jul 20 06:19:16.026554 2026] [security2:error] [pid 874439:tid 874521] [remote 81.173.115.7:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc2AAAR1E"]
[Mon Jul 20 06:19:16.039562 2026] [security2:error] [pid 874439:tid 874629] [client 89.242.146.38:55936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4SRI6ZSrFvCrJJhtQc2QAAADw"]
[Mon Jul 20 06:19:16.076311 2026] [security2:error] [pid 874439:tid 874609] [client 45.45.237.8:50462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/.env"] [unique_id "al4SRI6ZSrFvCrJJhtQc3wAAACg"]
[Mon Jul 20 06:19:16.096483 2026] [security2:error] [pid 874439:tid 874694] [client 82.37.76.155:60280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4SRI6ZSrFvCrJJhtQc4AAAAH0"]
[Mon Jul 20 06:19:16.121407 2026] [security2:error] [pid 874439:tid 874664] [client 57.141.18.88:24618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SP46ZSrFvCrJJhtQbbQAAXwE"]
[Mon Jul 20 06:19:16.144112 2026] [security2:error] [pid 871012:tid 871149] [client 5.49.120.104:37810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4SRLwiU-Jh5ncAILFycwAAARA"]
[Mon Jul 20 06:19:16.221077 2026] [security2:error] [pid 874439:tid 874658] [client 90.14.145.153:33254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQc7gAAAFk"]
[Mon Jul 20 06:19:16.239309 2026] [security2:error] [pid 874439:tid 874688] [client 81.173.161.212:46356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4SRI6ZSrFvCrJJhtQc8AAAAHc"]
[Mon Jul 20 06:19:16.239672 2026] [security2:error] [pid 874439:tid 874481] [remote 81.173.115.7:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc8QAAJik"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:19:16.253665 2026] [security2:error] [pid 871012:tid 871265] [client 80.244.47.31:44706] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4SRLwiU-Jh5ncAILFydgAAAYQ"]
[Mon Jul 20 06:19:16.264089 2026] [security2:error] [pid 874439:tid 874675] [client 86.172.60.13:41772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQc9AAAAGo"]
[Mon Jul 20 06:19:16.293374 2026] [security2:error] [pid 874439:tid 874661] [client 86.147.30.54:38206] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQc9wAAAFw"]
[Mon Jul 20 06:19:16.369134 2026] [security2:error] [pid 874439:tid 874645] [client 34.74.185.202:64137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SRI6ZSrFvCrJJhtQc_AAAAEw"]
[Mon Jul 20 06:19:16.373936 2026] [security2:error] [pid 874439:tid 874593] [client 27.96.94.195:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc_QAAABg"]
[Mon Jul 20 06:19:16.374029 2026] [security2:error] [pid 874439:tid 874593] [client 27.96.94.195:37826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQc_QAAABg"]
[Mon Jul 20 06:19:16.751572 2026] [security2:error] [pid 874439:tid 874581] [client 45.116.69.230:61348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQdDgAAAAw"]
[Mon Jul 20 06:19:16.751677 2026] [security2:error] [pid 874439:tid 874581] [client 45.116.69.230:61348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SRI6ZSrFvCrJJhtQdDgAAAAw"]
[Mon Jul 20 06:19:16.777857 2026] [security2:error] [pid 874439:tid 874600] [client 177.130.118.6:42550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdFQAAAB8"]
[Mon Jul 20 06:19:16.777935 2026] [security2:error] [pid 874439:tid 874695] [client 95.251.203.116:57010] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdFAAAAH4"]
[Mon Jul 20 06:19:16.795421 2026] [security2:error] [pid 871012:tid 871213] [client 185.132.186.99:47567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/network.php"] [unique_id "al4SRLwiU-Jh5ncAILFyfQAAAVA"]
[Mon Jul 20 06:19:16.824931 2026] [security2:error] [pid 874439:tid 874666] [client 37.66.146.207:9746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdFwAAAGE"]
[Mon Jul 20 06:19:16.848378 2026] [security2:error] [pid 874439:tid 874614] [client 95.25.142.145:19514] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4SRI6ZSrFvCrJJhtQdGQAAAC0"]
[Mon Jul 20 06:19:16.881869 2026] [security2:error] [pid 874439:tid 874672] [client 95.214.186.53:37146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4SRI6ZSrFvCrJJhtQdGwAAAGc"]
[Mon Jul 20 06:19:17.158732 2026] [security2:error] [pid 874439:tid 874660] [client 2.121.236.140:39868] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4SRY6ZSrFvCrJJhtQdKwAAAFs"]
[Mon Jul 20 06:19:17.166311 2026] [security2:error] [pid 874439:tid 874650] [client 45.45.237.8:50448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/.env.bak"] [unique_id "al4SRY6ZSrFvCrJJhtQdLAAAAFE"]
[Mon Jul 20 06:19:17.167154 2026] [security2:error] [pid 874439:tid 874619] [client 84.82.70.57:35810] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdLQAAADI"]
[Mon Jul 20 06:19:17.189323 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:50462] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.env.development"] [unique_id "al4SRY6ZSrFvCrJJhtQdMAAAADc"]
[Mon Jul 20 06:19:17.262999 2026] [security2:error] [pid 871012:tid 871221] [client 57.141.18.102:44720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQLwiU-Jh5ncAILFyAgABWA4"]
[Mon Jul 20 06:19:17.278996 2026] [security2:error] [pid 874439:tid 874605] [client 190.71.186.101:51770] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdNgAAACQ"]
[Mon Jul 20 06:19:17.326310 2026] [security2:error] [pid 871012:tid 871254] [client 81.47.145.211:44984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbnka.woff2"] [unique_id "al4SRbwiU-Jh5ncAILFyhQAAAXk"]
[Mon Jul 20 06:19:17.375635 2026] [security2:error] [pid 874439:tid 874636] [client 103.141.108.143:62886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdPgAAAEM"]
[Mon Jul 20 06:19:17.375928 2026] [security2:error] [pid 874439:tid 874636] [client 103.141.108.143:62886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdPgAAAEM"]
[Mon Jul 20 06:19:17.385792 2026] [security2:error] [pid 874439:tid 874653] [client 90.167.51.8:19828] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4SRY6ZSrFvCrJJhtQdPwAAAFQ"]
[Mon Jul 20 06:19:17.398303 2026] [security2:error] [pid 874439:tid 874681] [client 109.252.8.177:1315] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdQgAAAHA"]
[Mon Jul 20 06:19:17.506821 2026] [security2:error] [pid 874439:tid 874664] [client 103.77.203.233:57214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdSAAAAF8"]
[Mon Jul 20 06:19:17.506975 2026] [security2:error] [pid 874439:tid 874664] [client 103.77.203.233:57214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdSAAAAF8"]
[Mon Jul 20 06:19:17.509596 2026] [security2:error] [pid 871012:tid 871252] [client 34.74.185.202:63221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SRbwiU-Jh5ncAILFyigAAAXc"]
[Mon Jul 20 06:19:17.557604 2026] [security2:error] [pid 871012:tid 871195] [client 95.19.188.2:47148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4SRbwiU-Jh5ncAILFyjAAAAT4"]
[Mon Jul 20 06:19:17.618823 2026] [security2:error] [pid 874439:tid 874581] [client 45.45.237.8:50476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/.env.backup"] [unique_id "al4SRY6ZSrFvCrJJhtQdTgAAAAw"]
[Mon Jul 20 06:19:17.659851 2026] [security2:error] [pid 874439:tid 874668] [client 86.74.35.50:39244] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdVAAAAGM"]
[Mon Jul 20 06:19:17.713335 2026] [security2:error] [pid 874439:tid 874655] [client 105.157.215.226:59236] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4SRY6ZSrFvCrJJhtQdVwAAAFY"]
[Mon Jul 20 06:19:17.780546 2026] [security2:error] [pid 871012:tid 871103] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SRbwiU-Jh5ncAILFylgABFlk"]
[Mon Jul 20 06:19:17.780718 2026] [security2:error] [pid 871012:tid 871155] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SRbwiU-Jh5ncAILFylgABFlk"]
[Mon Jul 20 06:19:17.793118 2026] [security2:error] [pid 871012:tid 871160] [client 78.192.199.101:57550] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4SRbwiU-Jh5ncAILFymAAAARs"]
[Mon Jul 20 06:19:17.923096 2026] [security2:error] [pid 871012:tid 871269] [client 45.45.237.8:50780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/keys.json"] [unique_id "al4SRbwiU-Jh5ncAILFynQAAAYg"]
[Mon Jul 20 06:19:17.923218 2026] [security2:error] [pid 871012:tid 871269] [client 45.45.237.8:50780] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/keys.json"] [unique_id "al4SRbwiU-Jh5ncAILFynQAAAYg"]
[Mon Jul 20 06:19:17.924572 2026] [security2:error] [pid 871012:tid 871241] [client 45.45.237.8:50734] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/serviceAccountKey.json"] [unique_id "al4SRbwiU-Jh5ncAILFymwAAAWw"]
[Mon Jul 20 06:19:17.924718 2026] [security2:error] [pid 874439:tid 874586] [client 45.45.237.8:50642] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/config.yml"] [unique_id "al4SRY6ZSrFvCrJJhtQdYwAAABE"]
[Mon Jul 20 06:19:17.924816 2026] [security2:error] [pid 871012:tid 871224] [client 45.45.237.8:50766] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/key.json"] [unique_id "al4SRbwiU-Jh5ncAILFyngAAAVs"]
[Mon Jul 20 06:19:17.924915 2026] [security2:error] [pid 871012:tid 871201] [client 45.45.237.8:50726] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/service_account.json"] [unique_id "al4SRbwiU-Jh5ncAILFyoAAAAUQ"]
[Mon Jul 20 06:19:17.924915 2026] [security2:error] [pid 871012:tid 871261] [client 45.45.237.8:50802] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4SRbwiU-Jh5ncAILFyoQAAAYA"]
[Mon Jul 20 06:19:17.925069 2026] [security2:error] [pid 874439:tid 874669] [client 45.45.237.8:50838] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/actuator/env"] [unique_id "al4SRY6ZSrFvCrJJhtQdawAAAGQ"]
[Mon Jul 20 06:19:17.943051 2026] [security2:error] [pid 871012:tid 871246] [client 79.117.198.39:59526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4SRbwiU-Jh5ncAILFypAAAAXE"]
[Mon Jul 20 06:19:18.015169 2026] [security2:error] [pid 871012:tid 871165] [client 79.117.162.242:46722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4SRrwiU-Jh5ncAILFypQAAASA"]
[Mon Jul 20 06:19:18.025144 2026] [security2:error] [pid 874439:tid 874691] [client 45.45.237.8:50582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/public/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQdegAAAHo"]
[Mon Jul 20 06:19:18.025520 2026] [security2:error] [pid 874439:tid 874607] [client 45.45.237.8:50564] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.env.test"] [unique_id "al4SRo6ZSrFvCrJJhtQddgAAACY"]
[Mon Jul 20 06:19:18.025656 2026] [security2:error] [pid 874439:tid 874657] [client 45.45.237.8:50568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/backend/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQdeQAAAFg"]
[Mon Jul 20 06:19:18.025715 2026] [security2:error] [pid 874439:tid 874602] [client 45.45.237.8:50598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/laravel/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQdewAAACE"]
[Mon Jul 20 06:19:18.025737 2026] [security2:error] [pid 874439:tid 874582] [client 45.45.237.8:50580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/api/.env"] [unique_id "al4SRo6ZSrFvCrJJhtQddwAAAA0"]
[Mon Jul 20 06:19:18.025738 2026] [security2:error] [pid 871012:tid 871199] [client 45.45.237.8:50608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/wp/.env"] [unique_id "al4SRrwiU-Jh5ncAILFypwAAAUI"]
[Mon Jul 20 06:19:18.026174 2026] [security2:error] [pid 874439:tid 874676] [client 45.45.237.8:50548] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.env.prod"] [unique_id "al4SRo6ZSrFvCrJJhtQdeAAAAGs"]
[Mon Jul 20 06:19:18.026463 2026] [security2:error] [pid 874439:tid 874650] [client 45.45.237.8:50976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/aws-exports.js"] [unique_id "al4SRo6ZSrFvCrJJhtQdgQAAAFE"]
[Mon Jul 20 06:19:18.026553 2026] [security2:error] [pid 874439:tid 874650] [client 45.45.237.8:50976] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/aws-exports.js"] [unique_id "al4SRo6ZSrFvCrJJhtQdgQAAAFE"]
[Mon Jul 20 06:19:18.027046 2026] [security2:error] [pid 871012:tid 871220] [client 45.45.237.8:50932] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/serverless.yml"] [unique_id "al4SRrwiU-Jh5ncAILFyrgAAAVc"]
[Mon Jul 20 06:19:18.027696 2026] [security2:error] [pid 874439:tid 874658] [client 45.45.237.8:50994] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/amplifyconfiguration.json"] [unique_id "al4SRo6ZSrFvCrJJhtQdgwAAAFk"]
[Mon Jul 20 06:19:18.027708 2026] [security2:error] [pid 874439:tid 874692] [client 45.45.237.8:50956] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/.aws/credentials"] [unique_id "al4SRo6ZSrFvCrJJhtQdfwAAAHs"]
[Mon Jul 20 06:19:18.027875 2026] [security2:error] [pid 874439:tid 874635] [client 45.45.237.8:50936] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; Baiduspider\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.baidu\\\\.com\\\\/search\\\\/spider\\\\.html\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "9"] [id "901012"] [msg "Baidu Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/terraform.tfstate"] [unique_id "al4SRo6ZSrFvCrJJhtQdfgAAAEI"]
[Mon Jul 20 06:19:18.028306 2026] [security2:error] [pid 874439:tid 874675] [client 45.45.237.8:51094] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; YandexBot\\\\/3\\\\.0; \\\\+http:\\\\/\\\\/yandex\\\\.com\\\\/bots\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/othercrawler.conf"] [line "3"] [id "901008"] [msg "Yandex Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sumnn.com"] [uri "/debug/vars"] [unique_id "al4SRo6ZSrFvCrJJhtQdhwAAAGo"]
[Mon Jul 20 06:19:18.028492 2026] [security2:error] [pid 871012:tid 871222] [client 45.45.237.8:51106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/app/.env"] [unique_id "al4SRrwiU-Jh5ncAILFyswAAAVk"]
[Mon Jul 20 06:19:18.028727 2026] [security2:error] [pid 871012:tid 871194] [client 45.45.237.8:50868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "sumnn.com"] [uri "/wp-config.php.bak"] [unique_id "al4SRrwiU-Jh5ncAILFytwAAAT0"]
[Mon Jul 20 06:19:18.029433 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:50876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "sumnn.com"] [uri "/web.config"] [unique_id "al4SRo6ZSrFvCrJJhtQdiwAAADc"]
[Mon Jul 20 06:19:18.031089 2026] [security2:error] [pid 874439:tid 874589] [client 45.45.237.8:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.237.45.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sumnn.com"] [uri "/wp-config.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdigAAABQ"]
[Mon Jul 20 06:19:18.053152 2026] [security2:error] [pid 871012:tid 871266] [client 152.249.210.239:44828] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4SRrwiU-Jh5ncAILFyuAAAAYU"]
[Mon Jul 20 06:19:18.080869 2026] [security2:error] [pid 874439:tid 874477] [remote 20.153.140.50:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdkQAAGCU"]
[Mon Jul 20 06:19:18.110604 2026] [security2:error] [pid 874439:tid 874685] [client 45.45.237.8:50462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/.env.old"] [unique_id "al4SRo6ZSrFvCrJJhtQdlAAAAHQ"]
[Mon Jul 20 06:19:18.110742 2026] [security2:error] [pid 874439:tid 874685] [client 45.45.237.8:50462] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/.env.old"] [unique_id "al4SRo6ZSrFvCrJJhtQdlAAAAHQ"]
[Mon Jul 20 06:19:18.153011 2026] [security2:error] [pid 874439:tid 874577] [client 66.249.73.4:39782] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ithurtsuntilyoudie.com"] [uri "/robots.txt"] [unique_id "al4SRo6ZSrFvCrJJhtQdlgAAAAg"]
[Mon Jul 20 06:19:18.170271 2026] [security2:error] [pid 874439:tid 874632] [client 102.203.137.16:34698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4SRo6ZSrFvCrJJhtQdmgAAAD8"]
[Mon Jul 20 06:19:18.215971 2026] [security2:error] [pid 871012:tid 871192] [client 186.129.21.194:44450] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4SRrwiU-Jh5ncAILFyvwAAATs"]
[Mon Jul 20 06:19:18.290285 2026] [security2:error] [pid 874439:tid 874684] [client 34.74.185.202:61008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SRo6ZSrFvCrJJhtQdnwAAAHM"]
[Mon Jul 20 06:19:18.344704 2026] [security2:error] [pid 874439:tid 874688] [client 45.45.237.8:50506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/.git/config"] [unique_id "al4SRo6ZSrFvCrJJhtQdpQAAAHc"]
[Mon Jul 20 06:19:18.344829 2026] [security2:error] [pid 874439:tid 874688] [client 45.45.237.8:50506] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/.git/config"] [unique_id "al4SRo6ZSrFvCrJJhtQdpQAAAHc"]
[Mon Jul 20 06:19:18.375133 2026] [security2:error] [pid 871012:tid 871208] [client 57.141.18.101:41422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQbwiU-Jh5ncAILFyGwABSzM"]
[Mon Jul 20 06:19:18.496834 2026] [security2:error] [pid 874439:tid 874446] [remote 20.153.140.50:43844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdrAAALwY"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:19:18.497492 2026] [security2:error] [pid 874439:tid 874589] [client 34.221.76.50:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdrQAAABQ"]
[Mon Jul 20 06:19:18.536206 2026] [security2:error] [pid 874439:tid 874575] [client 77.110.127.138:60000] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4SRo6ZSrFvCrJJhtQdrwAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:18.605246 2026] [security2:error] [pid 874439:tid 874651] [client 185.132.186.100:49041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/alfa.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdtgAAAFI"]
[Mon Jul 20 06:19:18.718837 2026] [security2:error] [pid 871012:tid 871245] [client 77.110.127.138:60002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/cake-recipe/feed/"] [unique_id "al4SRrwiU-Jh5ncAILFyzgAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:18.879625 2026] [security2:error] [pid 871012:tid 871176] [client 34.74.185.202:63935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SRrwiU-Jh5ncAILFy0QAAASs"]
[Mon Jul 20 06:19:19.067982 2026] [security2:error] [pid 871012:tid 871184] [client 136.65.156.78:18426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "appelmanimages.com"] [uri "/wp-json/batch/v1"] [unique_id "al4SR7wiU-Jh5ncAILFy1AAAATM"]
[Mon Jul 20 06:19:19.113495 2026] [security2:error] [pid 871012:tid 871191] [client 136.65.156.78:18426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "appelmanimages.com"] [uri "/"] [unique_id "al4SR7wiU-Jh5ncAILFy1gAAATo"]
[Mon Jul 20 06:19:19.275419 2026] [security2:error] [pid 874439:tid 874598] [client 103.153.183.69:26396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../app/.env"] [unique_id "al4SR46ZSrFvCrJJhtQd6QAAAB0"], referer: https://t.co/91v3mtsfcm
[Mon Jul 20 06:19:19.342052 2026] [security2:error] [pid 871012:tid 871227] [client 112.208.70.94:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SR7wiU-Jh5ncAILFy3gAAAV4"]
[Mon Jul 20 06:19:19.342160 2026] [security2:error] [pid 871012:tid 871227] [client 112.208.70.94:43668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SR7wiU-Jh5ncAILFy3gAAAV4"]
[Mon Jul 20 06:19:19.417304 2026] [security2:error] [pid 874439:tid 874600] [client 181.224.94.124:33923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SR46ZSrFvCrJJhtQd8AAAAB8"]
[Mon Jul 20 06:19:19.417413 2026] [security2:error] [pid 874439:tid 874600] [client 181.224.94.124:33923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SR46ZSrFvCrJJhtQd8AAAAB8"]
[Mon Jul 20 06:19:19.488924 2026] [security2:error] [pid 874439:tid 874625] [client 34.74.185.202:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SR46ZSrFvCrJJhtQd_wAAADg"]
[Mon Jul 20 06:19:19.645907 2026] [security2:error] [pid 874439:tid 874601] [client 105.67.131.91:54808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff"] [unique_id "al4SR46ZSrFvCrJJhtQeDQAAACA"]
[Mon Jul 20 06:19:19.758623 2026] [security2:error] [pid 874439:tid 874662] [client 216.244.66.243:37550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/next"] [unique_id "al4SR46ZSrFvCrJJhtQeFAAAAF0"]
[Mon Jul 20 06:19:19.758758 2026] [security2:error] [pid 874439:tid 874662] [client 216.244.66.243:37550] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/next"] [unique_id "al4SR46ZSrFvCrJJhtQeFAAAAF0"]
[Mon Jul 20 06:19:19.794392 2026] [security2:error] [pid 871012:tid 871148] [client 57.141.18.64:44946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQ7wiU-Jh5ncAILFyTgABDz0"]
[Mon Jul 20 06:19:20.036241 2026] [security2:error] [pid 874439:tid 874648] [client 50.116.65.227:29168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SSI6ZSrFvCrJJhtQeIgAAAE8"]
[Mon Jul 20 06:19:20.048726 2026] [security2:error] [pid 871012:tid 871188] [client 50.116.65.227:15024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SSLwiU-Jh5ncAILFy8AAAASE"]
[Mon Jul 20 06:19:20.162706 2026] [autoindex:error] [pid 874439:tid 874574] [client 205.210.31.33:62336] AH01276: Cannot serve directory /home1/rhzsqgmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:19:20.192024 2026] [security2:error] [pid 874439:tid 874635] [client 103.153.183.69:26396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../srv/.env"] [unique_id "al4SSI6ZSrFvCrJJhtQeKwAAAEI"], referer: https://www.google.com/search?q=ecftvf
[Mon Jul 20 06:19:20.219049 2026] [security2:error] [pid 874439:tid 874696] [client 34.74.185.202:59311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SSI6ZSrFvCrJJhtQeMAAAAH8"]
[Mon Jul 20 06:19:20.220029 2026] [security2:error] [pid 874439:tid 874691] [client 103.153.183.69:26396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/.env"] [unique_id "al4SSI6ZSrFvCrJJhtQeMQAAAHo"], referer: https://t.co/swx4o69x0p
[Mon Jul 20 06:19:20.391722 2026] [security2:error] [pid 874439:tid 874573] [client 185.132.186.75:49597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al4SSI6ZSrFvCrJJhtQePwAAAAQ"]
[Mon Jul 20 06:19:20.447362 2026] [security2:error] [pid 874439:tid 874591] [client 57.141.18.83:28364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SQ46ZSrFvCrJJhtQcsgAAFi4"]
[Mon Jul 20 06:19:20.768097 2026] [security2:error] [pid 874439:tid 874592] [client 14.225.17.146:58858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SSI6ZSrFvCrJJhtQeUQAAABc"]
[Mon Jul 20 06:19:20.783272 2026] [security2:error] [pid 874439:tid 874660] [client 104.234.53.60:44163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SSI6ZSrFvCrJJhtQebQAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:20.871524 2026] [security2:error] [pid 874439:tid 874510] [remote 188.166.241.141:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SSI6ZSrFvCrJJhtQecgAAc0Y"]
[Mon Jul 20 06:19:20.913898 2026] [security2:error] [pid 874439:tid 874682] [client 34.74.185.202:60033] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.aljosour-alarabia.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SSI6ZSrFvCrJJhtQeegAAAHE"]
[Mon Jul 20 06:19:21.156621 2026] [security2:error] [pid 871012:tid 871164] [client 14.225.17.146:57633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4SR7wiU-Jh5ncAILFy7wAAAR8"], referer: http://mcg.homes/wp
[Mon Jul 20 06:19:21.219879 2026] [security2:error] [pid 874439:tid 874688] [client 50.116.65.227:15072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SSY6ZSrFvCrJJhtQejgAAAHc"]
[Mon Jul 20 06:19:21.232482 2026] [security2:error] [pid 874439:tid 874600] [client 50.116.65.227:15088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SSY6ZSrFvCrJJhtQekAAAAB8"]
[Mon Jul 20 06:19:21.232824 2026] [security2:error] [pid 874439:tid 874496] [remote 188.166.241.141:39912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SSY6ZSrFvCrJJhtQekQAARDg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:21.371303 2026] [security2:error] [pid 874439:tid 874630] [client 57.141.18.16:52724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRI6ZSrFvCrJJhtQdBgAAPQc"]
[Mon Jul 20 06:19:21.483448 2026] [security2:error] [pid 874439:tid 874587] [client 50.116.65.227:29180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SSY6ZSrFvCrJJhtQenwAAABI"]
[Mon Jul 20 06:19:21.496848 2026] [security2:error] [pid 871012:tid 871261] [client 50.116.65.227:15102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SSbwiU-Jh5ncAILFzDgAAAYA"]
[Mon Jul 20 06:19:21.685321 2026] [security2:error] [pid 874439:tid 874652] [client 104.234.53.81:32767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SSY6ZSrFvCrJJhtQeswAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:21.724108 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:51046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sumnn.com"] [uri "/graphql"] [unique_id "al4SSY6ZSrFvCrJJhtQeuQAAADc"]
[Mon Jul 20 06:19:21.724227 2026] [security2:error] [pid 874439:tid 874624] [client 45.45.237.8:51046] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sumnn.com"] [uri "/graphql"] [unique_id "al4SSY6ZSrFvCrJJhtQeuQAAADc"]
[Mon Jul 20 06:19:21.814868 2026] [security2:error] [pid 874439:tid 874578] [client 14.225.17.146:57667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SSY6ZSrFvCrJJhtQeqwAAAAk"], referer: http://falconarrowshop.com/wp
[Mon Jul 20 06:19:21.922694 2026] [security2:error] [pid 874439:tid 874575] [client 51.68.111.241:18191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atozgroup.biz"] [uri "/robots.txt"] [unique_id "al4SSY6ZSrFvCrJJhtQexQAAAAY"]
[Mon Jul 20 06:19:21.922820 2026] [security2:error] [pid 874439:tid 874575] [client 51.68.111.241:18191] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "atozgroup.biz"] [uri "/robots.txt"] [unique_id "al4SSY6ZSrFvCrJJhtQexQAAAAY"]
[Mon Jul 20 06:19:21.933169 2026] [security2:error] [pid 874439:tid 874641] [client 57.141.18.126:44424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdIQAASGg"]
[Mon Jul 20 06:19:22.131695 2026] [security2:error] [pid 874439:tid 874640] [client 57.141.18.56:25452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdMwAARww"]
[Mon Jul 20 06:19:22.200923 2026] [security2:error] [pid 874439:tid 874666] [client 185.132.186.92:29387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wikindex.php"] [unique_id "al4SSo6ZSrFvCrJJhtQe1AAAAGE"]
[Mon Jul 20 06:19:22.341998 2026] [security2:error] [pid 874439:tid 874650] [client 47.128.121.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4SSI6ZSrFvCrJJhtQeeAAAAFE"]
[Mon Jul 20 06:19:22.425499 2026] [security2:error] [pid 871012:tid 871171] [client 86.147.190.227:50494] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4SSrwiU-Jh5ncAILFzJwAAASY"]
[Mon Jul 20 06:19:22.672607 2026] [security2:error] [pid 871012:tid 871144] [client 77.110.127.138:60029] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/baking/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4SSrwiU-Jh5ncAILFzLAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:22.690268 2026] [security2:error] [pid 874439:tid 874654] [client 191.7.154.2:18835] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4SSo6ZSrFvCrJJhtQe_QAAAFU"]
[Mon Jul 20 06:19:22.733040 2026] [security2:error] [pid 874439:tid 874644] [client 57.141.18.62:23616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRY6ZSrFvCrJJhtQdWgAAS10"]
[Mon Jul 20 06:19:22.943095 2026] [security2:error] [pid 874439:tid 874443] [remote 152.228.213.32:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SSo6ZSrFvCrJJhtQfDAAACwM"]
[Mon Jul 20 06:19:23.140886 2026] [security2:error] [pid 874439:tid 874473] [remote 152.228.213.32:52392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SS46ZSrFvCrJJhtQfGgAAZSE"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:23.262616 2026] [security2:error] [pid 874439:tid 874673] [client 57.141.18.7:29612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdngAAaAI"]
[Mon Jul 20 06:19:23.275544 2026] [security2:error] [pid 871012:tid 871163] [client 57.141.18.16:52732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRrwiU-Jh5ncAILFywQABHn4"]
[Mon Jul 20 06:19:23.291622 2026] [security2:error] [pid 874439:tid 874615] [client 77.110.127.138:60036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/cake-recipe/feed/"] [unique_id "al4SS46ZSrFvCrJJhtQfHwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:23.385370 2026] [security2:error] [pid 871012:tid 871243] [client 216.244.66.243:37558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/prev"] [unique_id "al4SS7wiU-Jh5ncAILFzQgAAAW4"]
[Mon Jul 20 06:19:23.385501 2026] [security2:error] [pid 871012:tid 871243] [client 216.244.66.243:37558] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/prev"] [unique_id "al4SS7wiU-Jh5ncAILFzQgAAAW4"]
[Mon Jul 20 06:19:23.560491 2026] [proxy:error] [pid 874439:tid 874659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:19:23.560570 2026] [proxy_http:error] [pid 874439:tid 874659] [client 205.210.31.22:61162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:19:23.561379 2026] [proxy:error] [pid 874439:tid 874659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:19:23.561414 2026] [proxy_http:error] [pid 874439:tid 874659] [client 205.210.31.22:61162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:19:23.653065 2026] [security2:error] [pid 874439:tid 874682] [client 91.186.254.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SSY6ZSrFvCrJJhtQewQAAAHE"]
[Mon Jul 20 06:19:23.862220 2026] [security2:error] [pid 874439:tid 874692] [client 57.141.18.22:44952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SRo6ZSrFvCrJJhtQdxwAAeyI"]
[Mon Jul 20 06:19:24.004535 2026] [security2:error] [pid 871012:tid 871255] [client 185.132.186.77:52081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/seoo/alfa.php"] [unique_id "al4STLwiU-Jh5ncAILFzVgAAAXo"]
[Mon Jul 20 06:19:24.211936 2026] [security2:error] [pid 874439:tid 874472] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4STI6ZSrFvCrJJhtQfTgAAJiA"]
[Mon Jul 20 06:19:24.212140 2026] [security2:error] [pid 874439:tid 874607] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4STI6ZSrFvCrJJhtQfTgAAJiA"]
[Mon Jul 20 06:19:24.381339 2026] [security2:error] [pid 874439:tid 874604] [client 57.141.18.17:44266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SR46ZSrFvCrJJhtQd_QAAI3Q"]
[Mon Jul 20 06:19:24.497146 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.67:27612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SR46ZSrFvCrJJhtQeCAAAAmQ"]
[Mon Jul 20 06:19:24.497516 2026] [security2:error] [pid 874439:tid 874678] [client 57.141.18.109:42274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SR46ZSrFvCrJJhtQeCQAAbUQ"]
[Mon Jul 20 06:19:24.787289 2026] [security2:error] [pid 874439:tid 874609] [client 14.225.17.146:58700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4SS46ZSrFvCrJJhtQfJgAAACg"], referer: http://mazzucelli.com/wp
[Mon Jul 20 06:19:25.351340 2026] [security2:error] [pid 874439:tid 874594] [client 5.24.182.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mezzacraft.com"] [uri "/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfjQAAABk"], referer: android-app://com.pinterest/
[Mon Jul 20 06:19:25.549786 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:36860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4STY6ZSrFvCrJJhtQfqgAAADk"]
[Mon Jul 20 06:19:25.549934 2026] [security2:error] [pid 874439:tid 874626] [client 27.96.94.195:36860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4STY6ZSrFvCrJJhtQfqgAAADk"]
[Mon Jul 20 06:19:25.704957 2026] [security2:error] [pid 874439:tid 874645] [client 104.234.53.84:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4STY6ZSrFvCrJJhtQftAAAAEw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:25.761439 2026] [security2:error] [pid 874439:tid 874666] [client 14.225.17.146:57189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4STI6ZSrFvCrJJhtQfVgAAAGE"], referer: http://alchemygroup.ca/wp
[Mon Jul 20 06:19:25.799309 2026] [security2:error] [pid 874439:tid 874695] [client 185.132.186.69:56551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/Cache/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfugAAAH4"]
[Mon Jul 20 06:19:26.201926 2026] [security2:error] [pid 874439:tid 874636] [client 14.225.17.146:58041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4STo6ZSrFvCrJJhtQfxwAAAEM"], referer: http://friendlyspreadsheet.com/wp
[Mon Jul 20 06:19:26.277023 2026] [security2:error] [pid 871012:tid 871175] [client 57.141.18.46:30420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SSbwiU-Jh5ncAILFzEQABKj8"]
[Mon Jul 20 06:19:26.293046 2026] [security2:error] [pid 874439:tid 874496] [remote 173.212.252.15:46834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4STo6ZSrFvCrJJhtQf1AAAbTg"]
[Mon Jul 20 06:19:26.544961 2026] [security2:error] [pid 874439:tid 874499] [remote 173.212.252.15:46834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4STo6ZSrFvCrJJhtQf3QAARzs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:26.567020 2026] [security2:error] [pid 874439:tid 874604] [client 171.60.139.123:53841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4STo6ZSrFvCrJJhtQf3wAAACM"]
[Mon Jul 20 06:19:26.567150 2026] [security2:error] [pid 874439:tid 874604] [client 171.60.139.123:53841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4STo6ZSrFvCrJJhtQf3wAAACM"]
[Mon Jul 20 06:19:26.744321 2026] [security2:error] [pid 871012:tid 871214] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4STrwiU-Jh5ncAILFzfAAAAVE"]
[Mon Jul 20 06:19:26.747050 2026] [security2:error] [pid 874439:tid 874649] [client 184.154.76.35:58482] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4STo6ZSrFvCrJJhtQf2AAAAFA"]
[Mon Jul 20 06:19:26.837506 2026] [security2:error] [pid 874439:tid 874599] [client 57.141.18.53:49142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SSo6ZSrFvCrJJhtQezgAAHkM"]
[Mon Jul 20 06:19:27.273119 2026] [security2:error] [pid 874439:tid 874652] [client 14.225.17.146:57153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4ST46ZSrFvCrJJhtQgIQAAAFM"], referer: https://friendlyspreadsheet.com/wp
[Mon Jul 20 06:19:27.406261 2026] [security2:error] [pid 871012:tid 871253] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ST7wiU-Jh5ncAILFziQAAAXg"]
[Mon Jul 20 06:19:27.407618 2026] [security2:error] [pid 874439:tid 874604] [client 184.154.76.35:55540] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4ST46ZSrFvCrJJhtQgGAAAACM"]
[Mon Jul 20 06:19:27.461487 2026] [security2:error] [pid 871012:tid 871149] [client 45.116.69.230:61870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ST7wiU-Jh5ncAILFzkAAAARA"]
[Mon Jul 20 06:19:27.461600 2026] [security2:error] [pid 871012:tid 871149] [client 45.116.69.230:61870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ST7wiU-Jh5ncAILFzkAAAARA"]
[Mon Jul 20 06:19:27.600261 2026] [security2:error] [pid 874439:tid 874648] [client 185.132.186.79:20793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/about.php"] [unique_id "al4ST46ZSrFvCrJJhtQgSAAAAE8"]
[Mon Jul 20 06:19:27.688441 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:57280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4STo6ZSrFvCrJJhtQf7wAAAE4"], referer: http://nikkidesigns.net/wp
[Mon Jul 20 06:19:27.800138 2026] [cgid:error] [pid 874439:tid 874635] [client 158.173.77.85:46207] AH01265: stderr from /home4/safesys1/public_html/allweb/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 06:19:27.888471 2026] [security2:error] [pid 874439:tid 874650] [client 14.225.17.146:60510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ST46ZSrFvCrJJhtQgQwAAAFE"]
[Mon Jul 20 06:19:27.895416 2026] [security2:error] [pid 874439:tid 874593] [client 57.141.18.105:61806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SS46ZSrFvCrJJhtQfHQAAGA8"]
[Mon Jul 20 06:19:28.004334 2026] [security2:error] [pid 871012:tid 871190] [client 184.154.76.35:55542] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-admin/css/forms.min.css"] [unique_id "al4ST7wiU-Jh5ncAILFzmwAAATk"]
[Mon Jul 20 06:19:28.004592 2026] [security2:error] [pid 874439:tid 874536] [remote 5.252.52.249:40302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgZQAAKGA"]
[Mon Jul 20 06:19:28.004771 2026] [security2:error] [pid 874439:tid 874609] [client 5.252.52.249:40302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgZQAAKGA"]
[Mon Jul 20 06:19:28.042511 2026] [security2:error] [pid 874439:tid 874660] [client 103.141.108.143:63365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgaQAAAFs"]
[Mon Jul 20 06:19:28.042606 2026] [security2:error] [pid 874439:tid 874660] [client 103.141.108.143:63365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgaQAAAFs"]
[Mon Jul 20 06:19:28.132668 2026] [security2:error] [pid 874439:tid 874610] [client 103.77.203.233:57798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgcgAAACk"]
[Mon Jul 20 06:19:28.132912 2026] [security2:error] [pid 874439:tid 874610] [client 103.77.203.233:57798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgcgAAACk"]
[Mon Jul 20 06:19:28.493508 2026] [security2:error] [pid 871012:tid 871124] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzogABQ24"]
[Mon Jul 20 06:19:28.493698 2026] [security2:error] [pid 871012:tid 871200] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzogABQ24"]
[Mon Jul 20 06:19:28.754340 2026] [security2:error] [pid 871012:tid 871132] [remote 91.142.222.105:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SULwiU-Jh5ncAILFzqQABDHY"]
[Mon Jul 20 06:19:28.860785 2026] [security2:error] [pid 871012:tid 871164] [client 178.152.178.232:36145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzqwAAAR8"]
[Mon Jul 20 06:19:28.860892 2026] [security2:error] [pid 871012:tid 871164] [client 178.152.178.232:36145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SULwiU-Jh5ncAILFzqwAAAR8"]
[Mon Jul 20 06:19:29.051756 2026] [security2:error] [pid 874439:tid 874624] [client 57.141.18.3:54508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STI6ZSrFvCrJJhtQfUAAAN00"]
[Mon Jul 20 06:19:29.069254 2026] [security2:error] [pid 871012:tid 871031] [remote 91.142.222.105:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SUbwiU-Jh5ncAILFzrQABFRE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:19:29.300791 2026] [security2:error] [pid 874439:tid 874638] [client 50.116.65.227:18454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SUY6ZSrFvCrJJhtQgvQAAAEU"]
[Mon Jul 20 06:19:29.311247 2026] [security2:error] [pid 874439:tid 874608] [client 50.116.65.227:42696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SUY6ZSrFvCrJJhtQgvwAAACc"]
[Mon Jul 20 06:19:29.405661 2026] [security2:error] [pid 874439:tid 874635] [client 185.132.186.62:43297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/as.php"] [unique_id "al4SUY6ZSrFvCrJJhtQgywAAAEI"]
[Mon Jul 20 06:19:29.616972 2026] [security2:error] [pid 874439:tid 874667] [client 104.234.53.48:56285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SUY6ZSrFvCrJJhtQg2gAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:29.626915 2026] [security2:error] [pid 874439:tid 874633] [client 57.141.18.9:25998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STI6ZSrFvCrJJhtQfaQAAQH4"]
[Mon Jul 20 06:19:29.937448 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:12391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SUbwiU-Jh5ncAILFzwAAAAYA"]
[Mon Jul 20 06:19:29.937559 2026] [security2:error] [pid 871012:tid 871261] [client 181.224.94.124:12391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SUbwiU-Jh5ncAILFzwAAAAYA"]
[Mon Jul 20 06:19:30.197614 2026] [security2:error] [pid 871012:tid 871159] [client 98.159.234.160:37821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SUrwiU-Jh5ncAILFzywAAARo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:30.241106 2026] [security2:error] [pid 874439:tid 874581] [client 45.157.112.60:21333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SUo6ZSrFvCrJJhtQg8wAAAAw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:30.266122 2026] [security2:error] [pid 874439:tid 874639] [client 57.141.18.92:43404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfnQAARnw"]
[Mon Jul 20 06:19:30.493775 2026] [security2:error] [pid 874439:tid 874607] [client 14.225.17.146:57058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4SUY6ZSrFvCrJJhtQgrQAAACY"], referer: http://dadanetnet.net/wp
[Mon Jul 20 06:19:30.575270 2026] [security2:error] [pid 874439:tid 874600] [client 14.224.227.113:55672] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SUo6ZSrFvCrJJhtQhAwAAAB8"]
[Mon Jul 20 06:19:30.645073 2026] [security2:error] [pid 874439:tid 874664] [client 57.141.18.78:31118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STY6ZSrFvCrJJhtQfvAAAXxA"]
[Mon Jul 20 06:19:30.951029 2026] [security2:error] [pid 871012:tid 871243] [client 190.245.141.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SUrwiU-Jh5ncAILFz4AABbl8"]
[Mon Jul 20 06:19:30.983665 2026] [security2:error] [pid 874439:tid 874576] [client 57.141.18.117:41158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4STo6ZSrFvCrJJhtQf0wAABwg"]
[Mon Jul 20 06:19:31.081759 2026] [security2:error] [pid 874439:tid 874670] [client 50.116.65.227:42758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SU46ZSrFvCrJJhtQhJQAAAGU"]
[Mon Jul 20 06:19:31.094601 2026] [security2:error] [pid 874439:tid 874571] [client 50.116.65.227:42764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SU46ZSrFvCrJJhtQhKQAAAAI"]
[Mon Jul 20 06:19:31.188835 2026] [security2:error] [pid 871012:tid 871261] [client 185.132.186.57:52479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/about.php"] [unique_id "al4SU7wiU-Jh5ncAILFz8QAAAYA"]
[Mon Jul 20 06:19:31.195349 2026] [security2:error] [pid 874439:tid 874507] [remote 100.42.189.89:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SU46ZSrFvCrJJhtQhLwAAIkM"]
[Mon Jul 20 06:19:31.438554 2026] [security2:error] [pid 874439:tid 874449] [remote 100.42.189.89:42300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SU46ZSrFvCrJJhtQhPQAASgk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:19:32.122229 2026] [security2:error] [pid 874439:tid 874683] [client 104.234.53.92:61857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhbgAAAHI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:32.149120 2026] [security2:error] [pid 874439:tid 874673] [client 74.208.214.194:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhcAAAAGg"]
[Mon Jul 20 06:19:32.225866 2026] [security2:error] [pid 874439:tid 874600] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SU46ZSrFvCrJJhtQhZQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:32.619642 2026] [security2:error] [pid 874439:tid 874500] [remote 152.228.213.32:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhjgAABjw"]
[Mon Jul 20 06:19:32.673618 2026] [security2:error] [pid 874439:tid 874607] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhhgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:32.728687 2026] [security2:error] [pid 874439:tid 874659] [client 14.225.17.146:64766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhjQAAAFo"], referer: http://maxenengineering.com/wp
[Mon Jul 20 06:19:32.782004 2026] [security2:error] [pid 871012:tid 871193] [client 114.119.155.13:32501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "latiendadejorge.com.gt"] [uri "/product/teami-superfood-cleanser/"] [unique_id "al4SVLwiU-Jh5ncAILF0HwAAATw"], referer: https://sexyzeed.com/tigsc374/teami-productos-para-la-cara
[Mon Jul 20 06:19:32.808615 2026] [security2:error] [pid 871012:tid 871148] [client 112.208.70.94:44048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SVLwiU-Jh5ncAILF0IAAAAQ8"]
[Mon Jul 20 06:19:32.808736 2026] [security2:error] [pid 871012:tid 871148] [client 112.208.70.94:44048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SVLwiU-Jh5ncAILF0IAAAAQ8"]
[Mon Jul 20 06:19:32.849620 2026] [security2:error] [pid 874439:tid 874464] [remote 152.228.213.32:52218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhlAAAWRg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:19:32.961209 2026] [security2:error] [pid 874439:tid 874695] [client 57.141.18.85:56404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SUI6ZSrFvCrJJhtQgigAAfko"]
[Mon Jul 20 06:19:32.969674 2026] [security2:error] [pid 871012:tid 871194] [client 57.141.18.102:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SULwiU-Jh5ncAILFzowABPQs"]
[Mon Jul 20 06:19:32.989468 2026] [security2:error] [pid 874439:tid 874573] [client 185.132.186.81:23801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/simi.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhmQAAAAQ"]
[Mon Jul 20 06:19:33.014214 2026] [security2:error] [pid 874439:tid 874529] [remote 34.21.244.199:30380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4SVY6ZSrFvCrJJhtQhmgAAK1k"]
[Mon Jul 20 06:19:33.512459 2026] [security2:error] [pid 874439:tid 874687] [client 57.141.18.64:25446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SUY6ZSrFvCrJJhtQgqwAAdhk"]
[Mon Jul 20 06:19:33.598856 2026] [security2:error] [pid 874439:tid 874453] [remote 34.21.244.199:30380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4SVY6ZSrFvCrJJhtQhuAAAQA0"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:19:33.733049 2026] [security2:error] [pid 874439:tid 874572] [client 14.225.17.146:49487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SVY6ZSrFvCrJJhtQhuQAAAAM"], referer: https://maxenengineering.com/wp
[Mon Jul 20 06:19:33.785608 2026] [security2:error] [pid 871012:tid 871269] [client 184.154.76.35:55628] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "al4SVbwiU-Jh5ncAILF0RgAAAYg"]
[Mon Jul 20 06:19:34.046315 2026] [security2:error] [pid 874439:tid 874672] [client 184.154.76.35:55640] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-includes/js/underscore.min.js"] [unique_id "al4SVo6ZSrFvCrJJhtQh0wAAAGc"]
[Mon Jul 20 06:19:34.292622 2026] [security2:error] [pid 874439:tid 874624] [client 184.154.76.35:55654] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-admin/css/l10n.min.css"] [unique_id "al4SVo6ZSrFvCrJJhtQh4wAAADc"]
[Mon Jul 20 06:19:34.399500 2026] [security2:error] [pid 874439:tid 874591] [client 43.205.139.3:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh6gAAABY"]
[Mon Jul 20 06:19:34.399626 2026] [security2:error] [pid 874439:tid 874591] [client 43.205.139.3:53222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh6gAAABY"]
[Mon Jul 20 06:19:34.487201 2026] [security2:error] [pid 874439:tid 874634] [client 104.234.53.72:47609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh7AAAAEE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:34.523033 2026] [security2:error] [pid 874439:tid 874580] [client 103.160.213.205:25984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.213.160.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/wp-login.php"] [unique_id "al4SVo6ZSrFvCrJJhtQh7gAAAAs"]
[Mon Jul 20 06:19:34.698715 2026] [security2:error] [pid 874439:tid 874602] [client 184.154.76.35:55668] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/wp-includes/css/buttons.min.css"] [unique_id "al4SVo6ZSrFvCrJJhtQh_QAAACE"]
[Mon Jul 20 06:19:34.738007 2026] [security2:error] [pid 871012:tid 871149] [client 57.141.18.70:61866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SUrwiU-Jh5ncAILFz0AABEEE"]
[Mon Jul 20 06:19:34.780831 2026] [lsapi:error] [pid 871012:tid 871116] [remote 80.210.17.232:52592] [host jenfarley.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://jenfarley.com/about/
[Mon Jul 20 06:19:34.780882 2026] [lsapi:error] [pid 871012:tid 871116] [remote 80.210.17.232:52592] [host jenfarley.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://jenfarley.com/about/
[Mon Jul 20 06:19:34.780894 2026] [lsapi:error] [pid 871012:tid 871116] [remote 80.210.17.232:52592] [host jenfarley.com] Client error on sending request(POST /?wc-ajax=get_refreshed_fragments HTTP/2.0); uri(/?wc-ajax=get_refreshed_fragments) content-length(18): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://jenfarley.com/about/
[Mon Jul 20 06:19:34.798888 2026] [security2:error] [pid 874439:tid 874577] [client 185.132.186.77:22863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/images/chosen.php"] [unique_id "al4SVo6ZSrFvCrJJhtQiBQAAAAg"]
[Mon Jul 20 06:19:34.846277 2026] [security2:error] [pid 871012:tid 871067] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SVrwiU-Jh5ncAILF0VAABUTU"]
[Mon Jul 20 06:19:34.846532 2026] [security2:error] [pid 871012:tid 871214] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SVrwiU-Jh5ncAILF0VAABUTU"]
[Mon Jul 20 06:19:34.945693 2026] [security2:error] [pid 874439:tid 874616] [client 110.249.201.131:15162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karimnawfal.com"] [uri "/robots.txt"] [unique_id "al4SVo6ZSrFvCrJJhtQiDgAAAC8"]
[Mon Jul 20 06:19:35.212935 2026] [security2:error] [pid 874439:tid 874626] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SVo6ZSrFvCrJJhtQiDQAAADk"]
[Mon Jul 20 06:19:35.215522 2026] [security2:error] [pid 871012:tid 871153] [client 184.154.76.35:55680] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4SVrwiU-Jh5ncAILF0WAAAARQ"]
[Mon Jul 20 06:19:35.596945 2026] [security2:error] [pid 871012:tid 871040] [remote 199.189.225.40:45469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SV7wiU-Jh5ncAILF0agABLRo"]
[Mon Jul 20 06:19:35.767016 2026] [security2:error] [pid 874439:tid 874456] [remote 62.193.192.55:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SV46ZSrFvCrJJhtQiRQAANxA"]
[Mon Jul 20 06:19:35.782697 2026] [security2:error] [pid 871012:tid 871058] [remote 199.189.225.40:45469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SV7wiU-Jh5ncAILF0cwABMCw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:35.937690 2026] [security2:error] [pid 874439:tid 874468] [remote 62.193.192.55:44944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SV46ZSrFvCrJJhtQiTgAAIhw"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:19:36.027917 2026] [security2:error] [pid 874439:tid 874651] [client 14.225.17.146:49660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4SV46ZSrFvCrJJhtQiQQAAAFI"], referer: http://securingmemories.com/wp
[Mon Jul 20 06:19:36.422391 2026] [security2:error] [pid 871012:tid 871247] [client 57.141.18.81:39822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SU7wiU-Jh5ncAILFz9wABchI"]
[Mon Jul 20 06:19:36.440681 2026] [security2:error] [pid 874439:tid 874507] [remote 100.42.189.89:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SWI6ZSrFvCrJJhtQiXwAAS0M"]
[Mon Jul 20 06:19:36.455961 2026] [security2:error] [pid 871012:tid 871241] [client 27.96.94.195:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SWLwiU-Jh5ncAILF0hgAAAWw"]
[Mon Jul 20 06:19:36.456069 2026] [security2:error] [pid 871012:tid 871241] [client 27.96.94.195:37240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SWLwiU-Jh5ncAILF0hgAAAWw"]
[Mon Jul 20 06:19:36.605291 2026] [security2:error] [pid 874439:tid 874612] [client 185.132.186.72:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/gold.php"] [unique_id "al4SWI6ZSrFvCrJJhtQiawAAACs"]
[Mon Jul 20 06:19:36.649946 2026] [security2:error] [pid 874439:tid 874449] [remote 100.42.189.89:55268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SWI6ZSrFvCrJJhtQidAAAZwk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:19:36.835390 2026] [security2:error] [pid 871012:tid 871148] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SWLwiU-Jh5ncAILF0jQAAAQ8"]
[Mon Jul 20 06:19:36.837827 2026] [security2:error] [pid 874439:tid 874599] [client 184.154.76.35:55694] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4SWI6ZSrFvCrJJhtQiaAAAAB4"]
[Mon Jul 20 06:19:36.876141 2026] [security2:error] [pid 874439:tid 874603] [client 3.67.192.83:58020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SWI6ZSrFvCrJJhtQieAAAACI"]
[Mon Jul 20 06:19:36.876302 2026] [security2:error] [pid 874439:tid 874603] [client 3.67.192.83:58020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SWI6ZSrFvCrJJhtQieAAAACI"]
[Mon Jul 20 06:19:36.880981 2026] [security2:error] [pid 871012:tid 871137] [remote 5.161.225.162:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4SWLwiU-Jh5ncAILF0lAABNHs"]
[Mon Jul 20 06:19:37.017834 2026] [security2:error] [pid 874439:tid 874639] [client 57.141.18.69:41100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SVI6ZSrFvCrJJhtQhdAAARjA"]
[Mon Jul 20 06:19:37.199401 2026] [security2:error] [pid 871012:tid 871182] [client 171.60.139.123:54346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SWbwiU-Jh5ncAILF0mgAAATE"]
[Mon Jul 20 06:19:37.199498 2026] [security2:error] [pid 871012:tid 871182] [client 171.60.139.123:54346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SWbwiU-Jh5ncAILF0mgAAATE"]
[Mon Jul 20 06:19:37.328613 2026] [security2:error] [pid 871012:tid 871055] [remote 5.161.225.162:46438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4SWbwiU-Jh5ncAILF0ngABhyk"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 06:19:37.444853 2026] [security2:error] [pid 874439:tid 874656] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SWY6ZSrFvCrJJhtQikQAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:37.871024 2026] [security2:error] [pid 874439:tid 874631] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SWY6ZSrFvCrJJhtQisAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:37.968958 2026] [security2:error] [pid 871012:tid 871146] [client 50.116.65.227:18478] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SWbwiU-Jh5ncAILF0qwAAAQ0"]
[Mon Jul 20 06:19:37.982725 2026] [security2:error] [pid 871012:tid 871211] [client 50.116.65.227:42812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4SWbwiU-Jh5ncAILF0rAAAAU4"]
[Mon Jul 20 06:19:38.137039 2026] [security2:error] [pid 874439:tid 874672] [client 45.116.69.230:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQixgAAAGc"]
[Mon Jul 20 06:19:38.137195 2026] [security2:error] [pid 874439:tid 874672] [client 45.116.69.230:62410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQixgAAAGc"]
[Mon Jul 20 06:19:38.214330 2026] [security2:error] [pid 871012:tid 871227] [client 57.141.18.78:37966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SVbwiU-Jh5ncAILF0MQABXjw"]
[Mon Jul 20 06:19:38.417370 2026] [security2:error] [pid 874439:tid 874639] [client 185.132.186.66:57139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Requests/Text/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi2AAAAEY"]
[Mon Jul 20 06:19:38.598666 2026] [security2:error] [pid 874439:tid 874680] [client 103.77.203.233:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi5AAAAG8"]
[Mon Jul 20 06:19:38.598832 2026] [security2:error] [pid 874439:tid 874680] [client 103.77.203.233:58440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi5AAAAG8"]
[Mon Jul 20 06:19:38.708181 2026] [security2:error] [pid 871012:tid 871177] [client 103.141.108.143:63848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SWrwiU-Jh5ncAILF0xwAAASw"]
[Mon Jul 20 06:19:38.708294 2026] [security2:error] [pid 871012:tid 871177] [client 103.141.108.143:63848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SWrwiU-Jh5ncAILF0xwAAASw"]
[Mon Jul 20 06:19:38.941484 2026] [security2:error] [pid 874439:tid 874660] [client 3.149.57.90:12428] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQi1gAAAFs"], referer: https://windowtx.com
[Mon Jul 20 06:19:39.018983 2026] [security2:error] [pid 871012:tid 871064] [remote 100.42.189.89:42400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF01wABVDI"]
[Mon Jul 20 06:19:39.019156 2026] [security2:error] [pid 871012:tid 871217] [client 100.42.189.89:42400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF01wABVDI"]
[Mon Jul 20 06:19:39.025973 2026] [security2:error] [pid 874439:tid 874474] [remote 81.173.115.7:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjAAAAfSI"]
[Mon Jul 20 06:19:39.047248 2026] [security2:error] [pid 874439:tid 874691] [client 34.73.38.214:57267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjAQAAAHo"]
[Mon Jul 20 06:19:39.067946 2026] [security2:error] [pid 871012:tid 871157] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SWrwiU-Jh5ncAILF00AAAARg"]
[Mon Jul 20 06:19:39.070504 2026] [security2:error] [pid 871012:tid 871159] [client 184.154.76.35:41658] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4SWrwiU-Jh5ncAILF0zQAAARo"]
[Mon Jul 20 06:19:39.152428 2026] [security2:error] [pid 871012:tid 871264] [client 34.73.38.214:57405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SW7wiU-Jh5ncAILF02QAAAYM"]
[Mon Jul 20 06:19:39.165714 2026] [security2:error] [pid 874439:tid 874626] [client 104.234.53.69:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SW46ZSrFvCrJJhtQjBwAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:39.173328 2026] [security2:error] [pid 874439:tid 874532] [remote 38.242.157.30:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjCQAAIFw"]
[Mon Jul 20 06:19:39.218410 2026] [security2:error] [pid 874439:tid 874466] [remote 81.173.115.7:49114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjDQAAJxo"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:19:39.266958 2026] [security2:error] [pid 874439:tid 874453] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SW46ZSrFvCrJJhtQjDwAAYg0"]
[Mon Jul 20 06:19:39.267179 2026] [security2:error] [pid 874439:tid 874667] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SW46ZSrFvCrJJhtQjDwAAYg0"]
[Mon Jul 20 06:19:39.272543 2026] [security2:error] [pid 874439:tid 874674] [client 34.73.38.214:57443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjEQAAAGk"]
[Mon Jul 20 06:19:39.272933 2026] [security2:error] [pid 871012:tid 871175] [client 57.141.18.37:30414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SVrwiU-Jh5ncAILF0TwABKlo"]
[Mon Jul 20 06:19:39.400136 2026] [security2:error] [pid 871012:tid 871229] [client 34.73.38.214:57483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SW7wiU-Jh5ncAILF06gAAAWA"]
[Mon Jul 20 06:19:39.435927 2026] [security2:error] [pid 874439:tid 874469] [remote 38.242.157.30:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjGAAAGB0"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:19:39.473939 2026] [security2:error] [pid 874439:tid 874540] [remote 72.167.132.114:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SW46ZSrFvCrJJhtQjGQAAfmQ"]
[Mon Jul 20 06:19:39.487451 2026] [security2:error] [pid 871012:tid 871209] [client 178.152.178.232:37242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF07AAAAUw"]
[Mon Jul 20 06:19:39.487579 2026] [security2:error] [pid 871012:tid 871209] [client 178.152.178.232:37242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SW7wiU-Jh5ncAILF07AAAAUw"]
[Mon Jul 20 06:19:39.513473 2026] [security2:error] [pid 871012:tid 871208] [client 14.225.17.146:53042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4SWrwiU-Jh5ncAILF0uwAAAUs"], referer: http://collectingrealestate.com/wp
[Mon Jul 20 06:19:39.533889 2026] [security2:error] [pid 871012:tid 871260] [client 34.73.38.214:57526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SW7wiU-Jh5ncAILF07wAAAX8"]
[Mon Jul 20 06:19:39.640568 2026] [security2:error] [pid 871012:tid 871086] [remote 78.46.157.202:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SW7wiU-Jh5ncAILF08QABZUg"]
[Mon Jul 20 06:19:39.656870 2026] [security2:error] [pid 874439:tid 874615] [client 34.73.38.214:57567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjIgAAAC4"]
[Mon Jul 20 06:19:39.779910 2026] [security2:error] [pid 874439:tid 874685] [client 34.73.38.214:57622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjLgAAAHQ"]
[Mon Jul 20 06:19:39.834658 2026] [security2:error] [pid 871012:tid 871031] [remote 78.46.157.202:56824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SW7wiU-Jh5ncAILF0_AABaRE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:39.896101 2026] [security2:error] [pid 874439:tid 874667] [client 34.73.38.214:57682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SW46ZSrFvCrJJhtQjMwAAAGI"]
[Mon Jul 20 06:19:40.014786 2026] [security2:error] [pid 874439:tid 874603] [client 184.154.76.35:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/readme.html"] [unique_id "al4SXI6ZSrFvCrJJhtQjPgAAACI"]
[Mon Jul 20 06:19:40.016578 2026] [security2:error] [pid 874439:tid 874659] [client 34.73.38.214:57727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.rzj.zfx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SXI6ZSrFvCrJJhtQjPwAAAFo"]
[Mon Jul 20 06:19:40.020170 2026] [security2:error] [pid 874439:tid 874631] [client 184.154.76.35:41664] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "falconarrowshop.com"] [uri "/readme.html"] [unique_id "al4SW46ZSrFvCrJJhtQjOgAAAD4"]
[Mon Jul 20 06:19:40.072834 2026] [security2:error] [pid 874439:tid 874651] [client 50.116.65.227:53368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SXI6ZSrFvCrJJhtQjQQAAAFI"]
[Mon Jul 20 06:19:40.083789 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:53370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SXLwiU-Jh5ncAILF1AgAAATo"]
[Mon Jul 20 06:19:40.124594 2026] [security2:error] [pid 874439:tid 874565] [remote 72.167.132.114:39634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjSAAAQH0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:19:40.176696 2026] [security2:error] [pid 874439:tid 874653] [client 57.141.18.58:48894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SV46ZSrFvCrJJhtQiLgAAVHU"]
[Mon Jul 20 06:19:40.216933 2026] [security2:error] [pid 871012:tid 871225] [client 185.132.186.84:49787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/mu-plugins/index.php"] [unique_id "al4SXLwiU-Jh5ncAILF1BAAAAVw"]
[Mon Jul 20 06:19:40.345648 2026] [security2:error] [pid 874439:tid 874587] [client 57.141.18.2:46066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SV46ZSrFvCrJJhtQiNQAAEks"]
[Mon Jul 20 06:19:40.363644 2026] [security2:error] [pid 871012:tid 871176] [client 127.0.0.1:50878] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4SXLwiU-Jh5ncAILF1DQAAASs"], referer: https://www.google.com/
[Mon Jul 20 06:19:40.435789 2026] [security2:error] [pid 874439:tid 874552] [remote 217.61.143.92:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjWgAAHHA"]
[Mon Jul 20 06:19:40.439237 2026] [security2:error] [pid 874439:tid 874676] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXI6ZSrFvCrJJhtQjXAAAAGs"]
[Mon Jul 20 06:19:40.456682 2026] [security2:error] [pid 874439:tid 874635] [client 181.224.94.124:52242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjYgAAAEI"]
[Mon Jul 20 06:19:40.456800 2026] [security2:error] [pid 874439:tid 874635] [client 181.224.94.124:52242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjYgAAAEI"]
[Mon Jul 20 06:19:40.547038 2026] [security2:error] [pid 874439:tid 874510] [remote 217.61.143.92:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjZwAAA0Y"]
[Mon Jul 20 06:19:40.547217 2026] [security2:error] [pid 874439:tid 874572] [client 217.61.143.92:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjZwAAA0Y"]
[Mon Jul 20 06:19:40.642557 2026] [security2:error] [pid 874439:tid 874649] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXI6ZSrFvCrJJhtQjaQAAAFA"]
[Mon Jul 20 06:19:40.666070 2026] [security2:error] [pid 874439:tid 874459] [remote 217.61.143.92:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjawAAPhM"], referer: https://fluidtemple.org/wp-login.php
[Mon Jul 20 06:19:40.887519 2026] [security2:error] [pid 874439:tid 874648] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXI6ZSrFvCrJJhtQjbwAAAE8"]
[Mon Jul 20 06:19:41.058725 2026] [security2:error] [pid 871012:tid 871223] [client 54.169.146.187:25820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "curlsnpearlsss.com"] [uri "/wprm_print/rellenos-de-yuca-stuffed-cassava"] [unique_id "al4SXbwiU-Jh5ncAILF1GwAAAVo"], referer: https://curlsnpearlsss.com/rellenos-de-yuca-stuffed-cassava/
[Mon Jul 20 06:19:41.090939 2026] [security2:error] [pid 874439:tid 874669] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjeAAAAGQ"]
[Mon Jul 20 06:19:41.231526 2026] [security2:error] [pid 874439:tid 874650] [client 57.141.18.94:60030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SWI6ZSrFvCrJJhtQiZAAAUQs"]
[Mon Jul 20 06:19:41.303219 2026] [security2:error] [pid 874439:tid 874642] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjigAAAEk"]
[Mon Jul 20 06:19:41.479181 2026] [security2:error] [pid 874439:tid 874575] [client 14.225.17.146:60044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjZgAAAAY"], referer: http://claysharecon.com/wp
[Mon Jul 20 06:19:41.502677 2026] [security2:error] [pid 874439:tid 874622] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjmAAAADU"]
[Mon Jul 20 06:19:41.519465 2026] [security2:error] [pid 871012:tid 871202] [client 14.225.17.146:49708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4SW7wiU-Jh5ncAILF0-QAAAUU"]
[Mon Jul 20 06:19:41.767861 2026] [security2:error] [pid 874439:tid 874581] [client 217.156.66.198:51948] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=///"] [hostname "www.drawingthedog.com"] [uri "/"] [unique_id "al4SXY6ZSrFvCrJJhtQjowAAAAw"]
[Mon Jul 20 06:19:42.012734 2026] [security2:error] [pid 871012:tid 871191] [client 185.132.186.101:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sitemaps/abcd.php"] [unique_id "al4SXrwiU-Jh5ncAILF1QwAAATo"]
[Mon Jul 20 06:19:42.242110 2026] [core:error] [pid 874439:tid 874654] [client 14.225.17.146:52903] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wp
[Mon Jul 20 06:19:42.242133 2026] [core:error] [pid 874439:tid 874654] [client 14.225.17.146:52903] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wp
[Mon Jul 20 06:19:42.345605 2026] [security2:error] [pid 874439:tid 874675] [client 57.141.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4SXo6ZSrFvCrJJhtQjtgAAAGo"]
[Mon Jul 20 06:19:42.452638 2026] [security2:error] [pid 874439:tid 874635] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SXo6ZSrFvCrJJhtQjwQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:42.498144 2026] [security2:error] [pid 874439:tid 874463] [remote 75.119.135.239:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.135.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj0AAANRc"]
[Mon Jul 20 06:19:42.572284 2026] [security2:error] [pid 874439:tid 874482] [remote 47.86.33.52:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj1AAAJSo"]
[Mon Jul 20 06:19:42.696949 2026] [security2:error] [pid 874439:tid 874501] [remote 75.119.135.239:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.135.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj3gAAUT0"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:19:42.878545 2026] [cgid:error] [pid 874439:tid 874680] [client 66.132.172.143:40292] AH01265: stderr from /home1/asliceo1/public_html/frontecinc/cgi-bin/: attempt to invoke directory as script, referer: https://www.frontecinc.asliceofleadership.com:443/cgi-bin
[Mon Jul 20 06:19:42.957922 2026] [security2:error] [pid 871012:tid 871199] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1VwAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:43.073959 2026] [security2:error] [pid 871012:tid 871250] [client 14.225.17.146:60405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1WAAAAXU"], referer: http://mtlegnews.gov/wp
[Mon Jul 20 06:19:43.135930 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:60426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SXo6ZSrFvCrJJhtQj7QAAAFQ"], referer: http://longevityperformanceclinic.com/wp
[Mon Jul 20 06:19:43.174910 2026] [security2:error] [pid 874439:tid 874668] [client 57.141.18.108:23372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQiywAAYzw"]
[Mon Jul 20 06:19:43.200888 2026] [security2:error] [pid 874439:tid 874607] [client 57.141.18.119:61296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SWo6ZSrFvCrJJhtQizwAAJjY"]
[Mon Jul 20 06:19:43.755866 2026] [security2:error] [pid 871012:tid 871259] [client 14.225.17.146:60324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1SAAAAX4"], referer: http://reosportsboats.com/wp
[Mon Jul 20 06:19:43.896251 2026] [security2:error] [pid 871012:tid 871222] [client 14.225.17.146:50094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1TQAAAVk"], referer: http://sarahsnyder.net/wp
[Mon Jul 20 06:19:44.019909 2026] [security2:error] [pid 874439:tid 874619] [client 57.141.18.59:46588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SW46ZSrFvCrJJhtQjCwAAMiQ"]
[Mon Jul 20 06:19:44.293472 2026] [security2:error] [pid 871012:tid 871251] [client 57.141.18.62:38244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SW7wiU-Jh5ncAILF07gABdgQ"]
[Mon Jul 20 06:19:44.710163 2026] [security2:error] [pid 874439:tid 874475] [remote 97.74.87.194:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkYAAAVyM"]
[Mon Jul 20 06:19:44.728327 2026] [security2:error] [pid 874439:tid 874549] [remote 47.86.33.52:57180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkYQAAeW0"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 06:19:44.836616 2026] [security2:error] [pid 871012:tid 871183] [client 185.132.186.67:27585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/rk2.php"] [unique_id "al4SYLwiU-Jh5ncAILF1igAAATI"]
[Mon Jul 20 06:19:44.927142 2026] [security2:error] [pid 874439:tid 874626] [client 14.225.17.146:60145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkYgAAADk"], referer: https://sarahsnyder.net/wp
[Mon Jul 20 06:19:45.024411 2026] [security2:error] [pid 874439:tid 874652] [client 14.225.17.146:63312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkZwAAAFM"], referer: https://reosportsboats.com/wp
[Mon Jul 20 06:19:45.064879 2026] [security2:error] [pid 874439:tid 874609] [client 57.141.18.0:43824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXI6ZSrFvCrJJhtQjSQAAKAE"]
[Mon Jul 20 06:19:45.117667 2026] [security2:error] [pid 874439:tid 874481] [remote 97.74.87.194:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4SYY6ZSrFvCrJJhtQkcwAAGSk"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:19:45.430851 2026] [security2:error] [pid 874439:tid 874600] [client 14.225.17.146:55512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkbQAAAB8"]
[Mon Jul 20 06:19:45.533502 2026] [security2:error] [pid 871012:tid 871101] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SYbwiU-Jh5ncAILF1oQABbVc"]
[Mon Jul 20 06:19:45.533679 2026] [security2:error] [pid 871012:tid 871242] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SYbwiU-Jh5ncAILF1oQABbVc"]
[Mon Jul 20 06:19:45.567801 2026] [security2:error] [pid 871012:tid 871258] [client 158.173.89.95:57779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SYbwiU-Jh5ncAILF1owAAAX0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:45.640157 2026] [security2:error] [pid 874439:tid 874622] [client 14.225.17.146:49519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkPgAAADU"], referer: http://expertcultures.com/wp
[Mon Jul 20 06:19:45.988471 2026] [security2:error] [pid 874439:tid 874657] [client 57.141.18.64:46202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXY6ZSrFvCrJJhtQjdwAAWDg"]
[Mon Jul 20 06:19:46.478994 2026] [security2:error] [pid 871012:tid 871246] [client 66.249.69.65:40176] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "2sweetchicks.com"] [uri "/robots.txt"] [unique_id "al4SYrwiU-Jh5ncAILF1xAAAAXE"]
[Mon Jul 20 06:19:46.567472 2026] [security2:error] [pid 874439:tid 874599] [client 57.141.18.57:48916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXY6ZSrFvCrJJhtQjmwAAHk8"]
[Mon Jul 20 06:19:46.820315 2026] [autoindex:error] [pid 871012:tid 871174] [client 198.235.24.5:60984] AH01276: Cannot serve directory /home2/qxmjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:19:46.910853 2026] [security2:error] [pid 871012:tid 871233] [client 50.116.65.227:53986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SYrwiU-Jh5ncAILF13wAAAWQ"]
[Mon Jul 20 06:19:46.922622 2026] [security2:error] [pid 874439:tid 874677] [client 50.116.65.227:53524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4SYo6ZSrFvCrJJhtQkxwAAAGw"]
[Mon Jul 20 06:19:47.104947 2026] [security2:error] [pid 871012:tid 871190] [client 185.132.186.72:45999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/widgets/class-wp-widget-search-interpreter.php"] [unique_id "al4SY7wiU-Jh5ncAILF15QAAATk"]
[Mon Jul 20 06:19:47.271964 2026] [security2:error] [pid 871012:tid 871155] [client 27.96.94.195:36878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SY7wiU-Jh5ncAILF16QAAARY"]
[Mon Jul 20 06:19:47.272652 2026] [security2:error] [pid 871012:tid 871155] [client 27.96.94.195:36878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SY7wiU-Jh5ncAILF16QAAARY"]
[Mon Jul 20 06:19:47.515438 2026] [security2:error] [pid 871012:tid 871172] [client 14.225.17.146:56817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4SYbwiU-Jh5ncAILF1mwAAASc"], referer: http://latiendadejorge.com.gt/wp
[Mon Jul 20 06:19:47.620425 2026] [security2:error] [pid 874439:tid 874682] [client 14.225.17.146:63711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4SY46ZSrFvCrJJhtQk2wAAAHE"], referer: http://thesoloceos.com/wp
[Mon Jul 20 06:19:47.712622 2026] [security2:error] [pid 874439:tid 874577] [client 34.74.185.202:50352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SY46ZSrFvCrJJhtQk8wAAAAg"]
[Mon Jul 20 06:19:47.732931 2026] [security2:error] [pid 874439:tid 874518] [remote 81.173.115.7:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SY46ZSrFvCrJJhtQk9QAAGk4"]
[Mon Jul 20 06:19:47.820185 2026] [security2:error] [pid 874439:tid 874680] [client 171.60.139.123:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SY46ZSrFvCrJJhtQk_gAAAG8"]
[Mon Jul 20 06:19:47.820282 2026] [security2:error] [pid 874439:tid 874680] [client 171.60.139.123:54846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SY46ZSrFvCrJJhtQk_gAAAG8"]
[Mon Jul 20 06:19:48.009394 2026] [security2:error] [pid 874439:tid 874558] [remote 188.138.102.156:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4SY46ZSrFvCrJJhtQlDwAAY3Y"]
[Mon Jul 20 06:19:48.018630 2026] [security2:error] [pid 874439:tid 874491] [remote 81.173.115.7:53688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlEQAAETM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:48.047854 2026] [security2:error] [pid 871012:tid 871162] [client 112.208.70.94:44408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF1_AAAAR0"]
[Mon Jul 20 06:19:48.047957 2026] [security2:error] [pid 871012:tid 871162] [client 112.208.70.94:44408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF1_AAAAR0"]
[Mon Jul 20 06:19:48.178768 2026] [security2:error] [pid 871012:tid 871173] [client 57.141.18.52:40606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SXrwiU-Jh5ncAILF1XwABKDM"]
[Mon Jul 20 06:19:48.250039 2026] [security2:error] [pid 874439:tid 874563] [remote 188.138.102.156:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlGgAAXXs"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 06:19:48.256188 2026] [security2:error] [pid 874439:tid 874652] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlEwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:48.266837 2026] [security2:error] [pid 874439:tid 874573] [client 93.84.97.4:34034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4SZI6ZSrFvCrJJhtQlHAAAAAQ"]
[Mon Jul 20 06:19:48.296007 2026] [security2:error] [pid 874439:tid 874614] [client 14.225.17.146:53964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4SY46ZSrFvCrJJhtQk2QAAAC0"], referer: http://nextlevelpressurewashing.com/wp
[Mon Jul 20 06:19:48.395762 2026] [security2:error] [pid 874439:tid 874603] [client 65.1.132.125:45846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlJAAAACI"]
[Mon Jul 20 06:19:48.450851 2026] [security2:error] [pid 874439:tid 874645] [client 93.84.97.4:57626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4SZI6ZSrFvCrJJhtQlKAAAAEw"]
[Mon Jul 20 06:19:48.490965 2026] [security2:error] [pid 874439:tid 874622] [client 34.74.185.202:63448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SZI6ZSrFvCrJJhtQlLgAAADU"]
[Mon Jul 20 06:19:48.660299 2026] [security2:error] [pid 874439:tid 874694] [client 14.225.17.146:63207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlIgAAAH0"], referer: http://guidehunting.com/wp
[Mon Jul 20 06:19:48.727891 2026] [security2:error] [pid 871012:tid 871254] [client 43.205.139.3:19988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF2DwAAAXk"]
[Mon Jul 20 06:19:48.727993 2026] [security2:error] [pid 871012:tid 871254] [client 43.205.139.3:19988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SZLwiU-Jh5ncAILF2DwAAAXk"]
[Mon Jul 20 06:19:48.733108 2026] [security2:error] [pid 871012:tid 871270] [client 14.225.17.146:59993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4SZLwiU-Jh5ncAILF2CAAAAYk"], referer: https://thesoloceos.com/wp
[Mon Jul 20 06:19:48.761746 2026] [security2:error] [pid 874439:tid 874612] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlNAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:48.862193 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:62945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlRwAAAE0"]
[Mon Jul 20 06:19:48.862343 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:62945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlRwAAAE0"]
[Mon Jul 20 06:19:48.908923 2026] [security2:error] [pid 874439:tid 874576] [client 185.132.186.76:42187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/chosen.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlSgAAAAc"]
[Mon Jul 20 06:19:49.143001 2026] [security2:error] [pid 874439:tid 874596] [client 57.141.18.23:20022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SX46ZSrFvCrJJhtQkHwAAG1w"]
[Mon Jul 20 06:19:49.300204 2026] [security2:error] [pid 874439:tid 874652] [client 103.77.203.233:59171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlYAAAAFM"]
[Mon Jul 20 06:19:49.300319 2026] [security2:error] [pid 874439:tid 874652] [client 103.77.203.233:59171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlYAAAAFM"]
[Mon Jul 20 06:19:49.341556 2026] [security2:error] [pid 871012:tid 871203] [client 34.74.185.202:52813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SZbwiU-Jh5ncAILF2HQAAAUY"]
[Mon Jul 20 06:19:49.383120 2026] [security2:error] [pid 871012:tid 871193] [client 103.141.108.143:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SZbwiU-Jh5ncAILF2HgAAATw"]
[Mon Jul 20 06:19:49.383226 2026] [security2:error] [pid 871012:tid 871193] [client 103.141.108.143:64324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SZbwiU-Jh5ncAILF2HgAAATw"]
[Mon Jul 20 06:19:49.456406 2026] [security2:error] [pid 871012:tid 871155] [client 13.201.64.214:27830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4SZbwiU-Jh5ncAILF2HwAAARY"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:19:49.719219 2026] [security2:error] [pid 874439:tid 874696] [client 47.128.113.66:51402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "3dprintrecycling.com"] [uri "/robots.txt"] [unique_id "al4SZY6ZSrFvCrJJhtQlgAAAAH8"]
[Mon Jul 20 06:19:49.745987 2026] [security2:error] [pid 874439:tid 874663] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/static../etc/passwd"] [unique_id "al4SZY6ZSrFvCrJJhtQlgQAAAF4"], referer: https://www.google.com/
[Mon Jul 20 06:19:49.758202 2026] [security2:error] [pid 874439:tid 874571] [client 57.141.18.98:64700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkUgAAAnE"]
[Mon Jul 20 06:19:49.766107 2026] [security2:error] [pid 874439:tid 874641] [client 34.74.185.202:62985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SZY6ZSrFvCrJJhtQlhAAAAEg"]
[Mon Jul 20 06:19:49.773645 2026] [security2:error] [pid 874439:tid 874609] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/static../.env"] [unique_id "al4SZY6ZSrFvCrJJhtQlhQAAACg"], referer: https://twitter.com/
[Mon Jul 20 06:19:49.807022 2026] [security2:error] [pid 871012:tid 871253] [client 50.116.65.227:18702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SZbwiU-Jh5ncAILF2JQAAAXg"]
[Mon Jul 20 06:19:49.810100 2026] [security2:error] [pid 874439:tid 874570] [client 14.225.17.146:63224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlcQAAAAE"], referer: https://guidehunting.com/wp
[Mon Jul 20 06:19:49.814050 2026] [security2:error] [pid 874439:tid 874569] [client 57.141.18.85:39958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SYI6ZSrFvCrJJhtQkXQAAAAA"]
[Mon Jul 20 06:19:49.819266 2026] [security2:error] [pid 874439:tid 874676] [client 50.116.65.227:18708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SZY6ZSrFvCrJJhtQliAAAAGs"]
[Mon Jul 20 06:19:49.894277 2026] [security2:error] [pid 874439:tid 874561] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQljwAAInk"]
[Mon Jul 20 06:19:49.894459 2026] [security2:error] [pid 874439:tid 874603] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZY6ZSrFvCrJJhtQljwAAInk"]
[Mon Jul 20 06:19:50.198301 2026] [security2:error] [pid 871012:tid 871250] [client 178.152.178.232:37278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SZrwiU-Jh5ncAILF2MwAAAXU"]
[Mon Jul 20 06:19:50.198448 2026] [security2:error] [pid 871012:tid 871250] [client 178.152.178.232:37278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SZrwiU-Jh5ncAILF2MwAAAXU"]
[Mon Jul 20 06:19:50.653656 2026] [security2:error] [pid 871012:tid 871249] [client 57.141.18.110:57578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SYbwiU-Jh5ncAILF1qAABdFE"]
[Mon Jul 20 06:19:50.720259 2026] [security2:error] [pid 874439:tid 874594] [client 185.132.186.53:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/autoload_classmap.php"] [unique_id "al4SZo6ZSrFvCrJJhtQlsgAAABk"]
[Mon Jul 20 06:19:50.867120 2026] [security2:error] [pid 871012:tid 871226] [client 34.74.185.202:50848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SZrwiU-Jh5ncAILF2QQAAAV0"]
[Mon Jul 20 06:19:51.107631 2026] [security2:error] [pid 871012:tid 871242] [client 171.61.165.146:27907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2RQAAAW0"]
[Mon Jul 20 06:19:51.107850 2026] [security2:error] [pid 871012:tid 871242] [client 171.61.165.146:27907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2RQAAAW0"]
[Mon Jul 20 06:19:51.432399 2026] [security2:error] [pid 874439:tid 874595] [client 181.224.94.124:3568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl0wAAABo"]
[Mon Jul 20 06:19:51.432498 2026] [security2:error] [pid 874439:tid 874595] [client 181.224.94.124:3568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl0wAAABo"]
[Mon Jul 20 06:19:51.768875 2026] [security2:error] [pid 871012:tid 871124] [remote 45.90.123.233:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2VAABM24"]
[Mon Jul 20 06:19:51.774743 2026] [security2:error] [pid 874439:tid 874680] [client 34.74.185.202:57243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SZ46ZSrFvCrJJhtQl6gAAAG8"]
[Mon Jul 20 06:19:51.999545 2026] [security2:error] [pid 871012:tid 871051] [remote 45.90.123.233:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4SZ7wiU-Jh5ncAILF2YQABVCU"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:19:52.186315 2026] [security2:error] [pid 871012:tid 871160] [client 77.222.116.8:57166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "partnerselectricalllc.com"] [uri "/"] [unique_id "al4SaLwiU-Jh5ncAILF2ZwAAARs"]
[Mon Jul 20 06:19:52.259097 2026] [security2:error] [pid 871012:tid 871227] [client 54.184.226.94:64705] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2ZAAAAV4"]
[Mon Jul 20 06:19:52.428869 2026] [security2:error] [pid 871012:tid 871059] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.gitconfig"] [unique_id "al4SaLwiU-Jh5ncAILF2ewABdC0"]
[Mon Jul 20 06:19:52.451476 2026] [security2:error] [pid 871012:tid 871123] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.aws/config"] [unique_id "al4SaLwiU-Jh5ncAILF2gAABdG0"]
[Mon Jul 20 06:19:52.503590 2026] [security2:error] [pid 874439:tid 874676] [client 185.132.186.103:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/block-template-utils-other.php"] [unique_id "al4SaI6ZSrFvCrJJhtQmEgAAAGs"]
[Mon Jul 20 06:19:52.531006 2026] [security2:error] [pid 874439:tid 874635] [client 104.234.53.74:25193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SaI6ZSrFvCrJJhtQmFQAAAEI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:52.534673 2026] [security2:error] [pid 874439:tid 874615] [client 57.141.18.113:50390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SY46ZSrFvCrJJhtQk5gAALlc"]
[Mon Jul 20 06:19:52.614550 2026] [security2:error] [pid 874439:tid 874625] [client 77.222.116.8:57179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "partnerselectricalllc.com"] [uri "/_profiler/empty/search/results"] [unique_id "al4SaI6ZSrFvCrJJhtQmGQAAADg"]
[Mon Jul 20 06:19:52.705611 2026] [security2:error] [pid 871012:tid 871108] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.env"] [unique_id "al4SaLwiU-Jh5ncAILF2hQABdF4"]
[Mon Jul 20 06:19:52.914537 2026] [security2:error] [pid 874439:tid 874573] [client 34.74.185.202:53132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SaI6ZSrFvCrJJhtQmKAAAAAQ"]
[Mon Jul 20 06:19:53.072471 2026] [security2:error] [pid 874439:tid 874655] [client 57.141.18.123:41232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZI6ZSrFvCrJJhtQlFAAAVhQ"]
[Mon Jul 20 06:19:53.270623 2026] [security2:error] [pid 871012:tid 871109] [remote 57.141.18.75:48376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3566199"] [unique_id "al4SabwiU-Jh5ncAILF2mAABXF8"]
[Mon Jul 20 06:19:53.272383 2026] [security2:error] [pid 871012:tid 871266] [client 104.234.53.59:26393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SabwiU-Jh5ncAILF2mQAAAYU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:53.457925 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2fQABdHc"]
[Mon Jul 20 06:19:53.492575 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2eAABdCQ"]
[Mon Jul 20 06:19:53.515376 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2dgABdE0"]
[Mon Jul 20 06:19:53.545118 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2egABdDY"]
[Mon Jul 20 06:19:53.559766 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2dwABdAc"]
[Mon Jul 20 06:19:53.565125 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2gQABdDk"]
[Mon Jul 20 06:19:53.574672 2026] [security2:error] [pid 874439:tid 874685] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4SaY6ZSrFvCrJJhtQmOgAAdFU"], referer: http://assasalnazaha.com/wp
[Mon Jul 20 06:19:53.596347 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2fAABdEc"]
[Mon Jul 20 06:19:53.611109 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2eQABdEs"]
[Mon Jul 20 06:19:53.712147 2026] [security2:error] [pid 874439:tid 874651] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SaY6ZSrFvCrJJhtQmRQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:53.765416 2026] [security2:error] [pid 871012:tid 871224] [client 144.24.3.91:22591] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "thelastgamestandingexp.com"] [uri "/project-horned-owl-review"] [unique_id "al4SabwiU-Jh5ncAILF2owAAAVs"]
[Mon Jul 20 06:19:53.765558 2026] [security2:error] [pid 871012:tid 871224] [client 144.24.3.91:22591] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thelastgamestandingexp.com"] [uri "/project-horned-owl-review"] [unique_id "al4SabwiU-Jh5ncAILF2owAAAVs"]
[Mon Jul 20 06:19:53.831842 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2jQABdFk"]
[Mon Jul 20 06:19:53.832493 2026] [security2:error] [pid 871012:tid 871072] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.backup"] [unique_id "al4SabwiU-Jh5ncAILF2pgABdDo"]
[Mon Jul 20 06:19:53.864811 2026] [security2:error] [pid 871012:tid 871249] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2lAABdCI"]
[Mon Jul 20 06:19:53.927934 2026] [security2:error] [pid 871012:tid 871054] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.bak"] [unique_id "al4SabwiU-Jh5ncAILF2rQABLig"]
[Mon Jul 20 06:19:53.928124 2026] [security2:error] [pid 871012:tid 871179] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.bak"] [unique_id "al4SabwiU-Jh5ncAILF2rQABLig"]
[Mon Jul 20 06:19:54.161872 2026] [security2:error] [pid 874439:tid 874654] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/files../etc/passwd"] [unique_id "al4Sao6ZSrFvCrJJhtQmbAAAAFU"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:19:54.210489 2026] [security2:error] [pid 871012:tid 871202] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2tAAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:54.608618 2026] [security2:error] [pid 874439:tid 874581] [client 57.141.18.98:41802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZY6ZSrFvCrJJhtQlfQAADC0"]
[Mon Jul 20 06:19:54.673490 2026] [security2:error] [pid 874439:tid 874627] [client 34.74.185.202:63956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Sao6ZSrFvCrJJhtQmhQAAADo"]
[Mon Jul 20 06:19:54.710170 2026] [security2:error] [pid 871012:tid 871041] [remote 216.222.198.186:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.222.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4SarwiU-Jh5ncAILF2vwABKRs"]
[Mon Jul 20 06:19:54.872119 2026] [security2:error] [pid 874439:tid 874647] [client 14.225.17.146:53881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sao6ZSrFvCrJJhtQmhwAAAE4"], referer: http://lifeisbetterlakeside.com/wp
[Mon Jul 20 06:19:54.918713 2026] [security2:error] [pid 871012:tid 871154] [client 103.153.183.69:11594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../root/.bash_history"] [unique_id "al4SarwiU-Jh5ncAILF2xQAAARU"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:19:54.941757 2026] [security2:error] [pid 871012:tid 871078] [remote 216.222.198.186:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.198.222.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4SarwiU-Jh5ncAILF2xgABU0A"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 06:19:55.054492 2026] [security2:error] [pid 871012:tid 871191] [client 50.116.65.227:53550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4Sa7wiU-Jh5ncAILF2zwAAATo"]
[Mon Jul 20 06:19:55.068409 2026] [security2:error] [pid 874439:tid 874595] [client 50.116.65.227:18750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4Sa46ZSrFvCrJJhtQmngAAABE"]
[Mon Jul 20 06:19:55.116745 2026] [security2:error] [pid 874439:tid 874650] [client 14.225.17.146:56749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sao6ZSrFvCrJJhtQmjwAAAFE"], referer: http://mezzacraft.com/wp
[Mon Jul 20 06:19:55.309164 2026] [security2:error] [pid 874439:tid 874592] [client 185.132.186.78:38975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/alam.php"] [unique_id "al4Sa46ZSrFvCrJJhtQmrQAAABc"]
[Mon Jul 20 06:19:55.328486 2026] [security2:error] [pid 874439:tid 874622] [client 14.225.17.146:53836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Sa46ZSrFvCrJJhtQmoAAAADU"], referer: http://samdothan.org/wp
[Mon Jul 20 06:19:55.520297 2026] [security2:error] [pid 874439:tid 874647] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/files../.env"] [unique_id "al4Sa46ZSrFvCrJJhtQmvwAAAE4"], referer: https://duckduckgo.com/?q=j63fh
[Mon Jul 20 06:19:55.609551 2026] [security2:error] [pid 871012:tid 871211] [client 57.141.18.5:52720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZrwiU-Jh5ncAILF2PAABTkQ"]
[Mon Jul 20 06:19:55.874579 2026] [security2:error] [pid 874439:tid 874600] [client 57.141.18.38:36836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZo6ZSrFvCrJJhtQlvwAAH2c"]
[Mon Jul 20 06:19:55.963662 2026] [security2:error] [pid 874439:tid 874641] [client 34.74.185.202:63585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Sa46ZSrFvCrJJhtQm0gAAAEg"]
[Mon Jul 20 06:19:56.050430 2026] [security2:error] [pid 874439:tid 874695] [client 57.141.18.31:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZ46ZSrFvCrJJhtQlywAAfmU"]
[Mon Jul 20 06:19:56.186975 2026] [security2:error] [pid 874439:tid 874510] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SbI6ZSrFvCrJJhtQm5QAAFkY"]
[Mon Jul 20 06:19:56.187280 2026] [security2:error] [pid 874439:tid 874591] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SbI6ZSrFvCrJJhtQm5QAAFkY"]
[Mon Jul 20 06:19:56.275016 2026] [security2:error] [pid 871012:tid 871084] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.old"] [unique_id "al4SbLwiU-Jh5ncAILF27QABe0Y"]
[Mon Jul 20 06:19:56.276616 2026] [security2:error] [pid 871012:tid 871043] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/api/.env"] [unique_id "al4SbLwiU-Jh5ncAILF27AABex0"]
[Mon Jul 20 06:19:56.284837 2026] [security2:error] [pid 874439:tid 874450] [remote 57.141.18.105:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4SbI6ZSrFvCrJJhtQm8QAACQo"]
[Mon Jul 20 06:19:56.302259 2026] [security2:error] [pid 874439:tid 874661] [client 57.141.18.118:47276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl2wAAXGs"]
[Mon Jul 20 06:19:56.327074 2026] [security2:error] [pid 874439:tid 874597] [client 14.225.17.146:56819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Sa46ZSrFvCrJJhtQmnQAAABw"], referer: http://northbrookcpa.ca/wp
[Mon Jul 20 06:19:56.639357 2026] [security2:error] [pid 874439:tid 874569] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/assets../etc/passwd"] [unique_id "al4SbI6ZSrFvCrJJhtQnDAAAAAA"], referer: https://www.facebook.com/
[Mon Jul 20 06:19:56.666047 2026] [security2:error] [pid 874439:tid 874611] [client 57.141.18.85:26400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SZ46ZSrFvCrJJhtQl9QAAKlA"]
[Mon Jul 20 06:19:56.749979 2026] [security2:error] [pid 871012:tid 871251] [client 34.74.185.202:58139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SbLwiU-Jh5ncAILF2-AAAAXY"]
[Mon Jul 20 06:19:56.795955 2026] [security2:error] [pid 874439:tid 874591] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/assets../.env"] [unique_id "al4SbI6ZSrFvCrJJhtQnEwAAABY"], referer: https://duckduckgo.com/?q=aiv3l
[Mon Jul 20 06:19:56.843268 2026] [security2:error] [pid 874439:tid 874618] [client 104.234.53.63:54329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SbI6ZSrFvCrJJhtQnFQAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:57.008740 2026] [security2:error] [pid 874439:tid 874648] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/uploads../.env"] [unique_id "al4SbY6ZSrFvCrJJhtQnHAAAAE8"], referer: https://www.bing.com/search?q=gpht2h
[Mon Jul 20 06:19:57.025143 2026] [security2:error] [pid 871012:tid 871180] [client 57.141.18.22:28030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SaLwiU-Jh5ncAILF2bgABL3E"]
[Mon Jul 20 06:19:57.108032 2026] [security2:error] [pid 871012:tid 871181] [client 185.132.186.103:37759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/adminfusm.php"] [unique_id "al4SbbwiU-Jh5ncAILF3CAAAATA"]
[Mon Jul 20 06:19:57.129475 2026] [security2:error] [pid 871012:tid 871140] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifeisbetterlakeside.com"] [uri "/graphql"] [unique_id "al4SbbwiU-Jh5ncAILF3CQABXH4"]
[Mon Jul 20 06:19:57.131869 2026] [security2:error] [pid 874439:tid 874676] [client 56.125.35.21:31796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SbI6ZSrFvCrJJhtQm_QAAAGs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:19:57.186484 2026] [security2:error] [pid 871012:tid 871164] [client 14.225.17.146:53284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4Sa7wiU-Jh5ncAILF25wAAAR8"], referer: http://lutheranphilosopher.com/wp
[Mon Jul 20 06:19:57.234740 2026] [security2:error] [pid 874439:tid 874526] [remote 188.166.241.141:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnJwAADFY"]
[Mon Jul 20 06:19:57.252263 2026] [security2:error] [pid 871012:tid 871138] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/backend/.env"] [unique_id "al4SbbwiU-Jh5ncAILF3EQABJXw"]
[Mon Jul 20 06:19:57.252293 2026] [security2:error] [pid 871012:tid 871017] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/serviceAccountKey.json"] [unique_id "al4SbbwiU-Jh5ncAILF3GgABJQM"]
[Mon Jul 20 06:19:57.252296 2026] [security2:error] [pid 871012:tid 871137] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/config/.env"] [unique_id "al4SbbwiU-Jh5ncAILF3FQABJXs"]
[Mon Jul 20 06:19:57.252301 2026] [security2:error] [pid 871012:tid 871114] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.docker/config.json"] [unique_id "al4SbbwiU-Jh5ncAILF3GwABJWQ"]
[Mon Jul 20 06:19:57.252333 2026] [security2:error] [pid 871012:tid 871062] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.npmrc"] [unique_id "al4SbbwiU-Jh5ncAILF3HAABJTA"]
[Mon Jul 20 06:19:57.252453 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/backend/.env"] [unique_id "al4SbbwiU-Jh5ncAILF3EQABJXw"]
[Mon Jul 20 06:19:57.252685 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/serviceAccountKey.json"] [unique_id "al4SbbwiU-Jh5ncAILF3GgABJQM"]
[Mon Jul 20 06:19:57.301432 2026] [security2:error] [pid 874439:tid 874602] [client 103.153.183.69:5972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/media../.env"] [unique_id "al4SbY6ZSrFvCrJJhtQnKwAAACE"], referer: https://t.co/n35fe4djkj
[Mon Jul 20 06:19:57.434797 2026] [security2:error] [pid 874439:tid 874682] [client 57.141.18.10:33294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SaI6ZSrFvCrJJhtQmHQAAcRs"]
[Mon Jul 20 06:19:57.498833 2026] [security2:error] [pid 874439:tid 874604] [client 35.245.239.138:56367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uwl.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnMwAAACM"]
[Mon Jul 20 06:19:57.619426 2026] [security2:error] [pid 874439:tid 874569] [client 35.245.239.138:56367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SbY6ZSrFvCrJJhtQnPgAAAAA"]
[Mon Jul 20 06:19:57.627860 2026] [security2:error] [pid 874439:tid 874539] [remote 188.166.241.141:40816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnQQAAemM"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 06:19:57.659931 2026] [security2:error] [pid 871012:tid 871106] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifeisbetterlakeside.com"] [uri "/api/graphql"] [unique_id "al4SbbwiU-Jh5ncAILF3IQABJVw"]
[Mon Jul 20 06:19:57.775692 2026] [security2:error] [pid 871012:tid 871172] [client 57.141.18.90:40190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SabwiU-Jh5ncAILF2lQABJ1I"]
[Mon Jul 20 06:19:57.782646 2026] [security2:error] [pid 874439:tid 874688] [client 34.74.185.202:65401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SbY6ZSrFvCrJJhtQnTgAAAHc"]
[Mon Jul 20 06:19:57.783630 2026] [authz_core:error] [pid 871012:tid 871075] [remote 104.28.251.190:64862] AH01630: client denied by server configuration: /home3/lakesix0/public_html/.htpasswd
[Mon Jul 20 06:19:57.837411 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3EwABJRQ"]
[Mon Jul 20 06:19:57.838641 2026] [core:error] [pid 874439:tid 874570] [client 74.7.241.135:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:19:57.838675 2026] [core:error] [pid 874439:tid 874570] [client 74.7.241.135:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:19:57.838841 2026] [security2:error] [pid 874439:tid 874570] [client 74.7.241.135:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elementfix.co.uk"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnUwAAAAE"]
[Mon Jul 20 06:19:57.844499 2026] [security2:error] [pid 874439:tid 874637] [client 74.7.241.135:33176] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "elementfix.co.uk"] [uri "/robots.txt"] [unique_id "al4SbY6ZSrFvCrJJhtQnUAAAAEQ"]
[Mon Jul 20 06:19:57.891831 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3FgABJXQ"]
[Mon Jul 20 06:19:57.981306 2026] [security2:error] [pid 871012:tid 871149] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3JwAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:58.033990 2026] [security2:error] [pid 871012:tid 871026] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.vscode/launch.json"] [unique_id "al4SbrwiU-Jh5ncAILF3LgABJQw"]
[Mon Jul 20 06:19:58.034060 2026] [security2:error] [pid 871012:tid 871077] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "lifeisbetterlakeside.com"] [uri "/v1/graphql"] [unique_id "al4SbrwiU-Jh5ncAILF3LQABJT8"]
[Mon Jul 20 06:19:58.034159 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/.vscode/launch.json"] [unique_id "al4SbrwiU-Jh5ncAILF3LgABJQw"]
[Mon Jul 20 06:19:58.043759 2026] [security2:error] [pid 874439:tid 874675] [client 14.225.17.146:53217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnNQAAAGo"]
[Mon Jul 20 06:19:58.096810 2026] [security2:error] [pid 871012:tid 871064] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.ssh/id_rsa"] [unique_id "al4SbrwiU-Jh5ncAILF3MgABJTI"]
[Mon Jul 20 06:19:58.102466 2026] [security2:error] [pid 874439:tid 874503] [remote 116.179.32.215:5588] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4Sbo6ZSrFvCrJJhtQnYwAAXD8"]
[Mon Jul 20 06:19:58.127094 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3FwABJU4"]
[Mon Jul 20 06:19:58.131384 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3GAABJTM"]
[Mon Jul 20 06:19:58.168642 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3EgABJXo"]
[Mon Jul 20 06:19:58.172671 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3GQABJXI"]
[Mon Jul 20 06:19:58.176476 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3FAABJTE"]
[Mon Jul 20 06:19:58.251486 2026] [security2:error] [pid 874439:tid 874684] [client 34.74.185.202:50514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Sbo6ZSrFvCrJJhtQndAAAAHM"]
[Mon Jul 20 06:19:58.386566 2026] [security2:error] [pid 871012:tid 871152] [client 35.245.239.138:63197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SbrwiU-Jh5ncAILF3QAAAARM"]
[Mon Jul 20 06:19:58.389851 2026] [security2:error] [pid 871012:tid 871240] [client 27.96.94.195:37377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SbrwiU-Jh5ncAILF3QQAAAWs"]
[Mon Jul 20 06:19:58.389962 2026] [security2:error] [pid 871012:tid 871240] [client 27.96.94.195:37377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SbrwiU-Jh5ncAILF3QQAAAWs"]
[Mon Jul 20 06:19:58.449510 2026] [security2:error] [pid 874439:tid 874584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQncgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:58.502242 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3JAABJW8"]
[Mon Jul 20 06:19:58.565235 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:55358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQngwAAAAI"]
[Mon Jul 20 06:19:58.565373 2026] [security2:error] [pid 874439:tid 874571] [client 171.60.139.123:55358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQngwAAAAI"]
[Mon Jul 20 06:19:58.567171 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3JQABJUo"]
[Mon Jul 20 06:19:58.628955 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3LAABJUI"]
[Mon Jul 20 06:19:58.649350 2026] [security2:error] [pid 871012:tid 871205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3RgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:58.726653 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3KwABJWA"]
[Mon Jul 20 06:19:58.740150 2026] [security2:error] [pid 871012:tid 871170] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3MwABJRg"]
[Mon Jul 20 06:19:58.804971 2026] [security2:error] [pid 874439:tid 874680] [client 104.234.53.55:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQnnQAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:19:58.828820 2026] [security2:error] [pid 874439:tid 874611] [client 45.231.86.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQnlQAAACo"]
[Mon Jul 20 06:19:58.917828 2026] [security2:error] [pid 874439:tid 874649] [client 158.173.166.181:46513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Sbo6ZSrFvCrJJhtQnpQAAAFA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:19:58.926072 2026] [security2:error] [pid 871012:tid 871265] [client 185.132.186.68:52225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/sodium_compat/lib/widget-group.php"] [unique_id "al4SbrwiU-Jh5ncAILF3UQAAAYQ"]
[Mon Jul 20 06:19:58.947798 2026] [security2:error] [pid 871012:tid 871033] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/id_dsa"] [unique_id "al4SbrwiU-Jh5ncAILF3UgABVRM"]
[Mon Jul 20 06:19:58.948172 2026] [security2:error] [pid 871012:tid 871087] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.ssh/id_dsa"] [unique_id "al4SbrwiU-Jh5ncAILF3UwABVUk"]
[Mon Jul 20 06:19:59.007738 2026] [security2:error] [pid 871012:tid 871102] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.ssh/config"] [unique_id "al4Sb7wiU-Jh5ncAILF3XgABVVg"]
[Mon Jul 20 06:19:59.009145 2026] [security2:error] [pid 871012:tid 871132] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/id_rsa"] [unique_id "al4Sb7wiU-Jh5ncAILF3WwABVXY"]
[Mon Jul 20 06:19:59.192798 2026] [security2:error] [pid 871012:tid 871059] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/server.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3agABVS0"]
[Mon Jul 20 06:19:59.194706 2026] [security2:error] [pid 871012:tid 871057] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/key.pem"] [unique_id "al4Sb7wiU-Jh5ncAILF3bAABVSs"]
[Mon Jul 20 06:19:59.194711 2026] [security2:error] [pid 871012:tid 871042] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/privatekey.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3aQABVRw"]
[Mon Jul 20 06:19:59.200261 2026] [security2:error] [pid 871012:tid 871105] [remote 119.249.100.176:26094] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4Sb7wiU-Jh5ncAILF3bQABEVs"]
[Mon Jul 20 06:19:59.250857 2026] [security2:error] [pid 871012:tid 871207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3WgAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.299147 2026] [security2:error] [pid 871012:tid 871163] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3XwAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.396130 2026] [security2:error] [pid 874439:tid 874654] [client 34.74.185.202:55175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.arrazoado.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Sb46ZSrFvCrJJhtQnvgAAAFU"]
[Mon Jul 20 06:19:59.397647 2026] [security2:error] [pid 871012:tid 871197] [client 57.141.18.39:29231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SarwiU-Jh5ncAILF2wAABQGs"]
[Mon Jul 20 06:19:59.437252 2026] [security2:error] [pid 871012:tid 871204] [client 57.141.18.61:20354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SarwiU-Jh5ncAILF2wgABR1M"]
[Mon Jul 20 06:19:59.504590 2026] [security2:error] [pid 871012:tid 871055] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/localhost.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3egABVSk"]
[Mon Jul 20 06:19:59.514000 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:63462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnxAAAAE0"]
[Mon Jul 20 06:19:59.514142 2026] [security2:error] [pid 874439:tid 874646] [client 45.116.69.230:63462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnxAAAAE0"]
[Mon Jul 20 06:19:59.517846 2026] [security2:error] [pid 874439:tid 874626] [client 57.141.18.59:26962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sao6ZSrFvCrJJhtQmjgAAORE"]
[Mon Jul 20 06:19:59.540518 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3VAABVUg"]
[Mon Jul 20 06:19:59.542349 2026] [security2:error] [pid 874439:tid 874630] [client 14.225.17.146:65092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnQwAAAD0"], referer: http://partnerselectricalllc.com/wp
[Mon Jul 20 06:19:59.552012 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3VQABVQg"]
[Mon Jul 20 06:19:59.566912 2026] [security2:error] [pid 871012:tid 871083] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/host.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3gQABVUU"]
[Mon Jul 20 06:19:59.567185 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/host.key"] [unique_id "al4Sb7wiU-Jh5ncAILF3gQABVUU"]
[Mon Jul 20 06:19:59.573420 2026] [security2:error] [pid 871012:tid 871149] [client 173.230.133.164:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3dgAAARA"]
[Mon Jul 20 06:19:59.575971 2026] [security2:error] [pid 871012:tid 871209] [client 173.230.133.164:56356] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/"] [unique_id "al4Sb7wiU-Jh5ncAILF3dAAAAUw"]
[Mon Jul 20 06:19:59.577221 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3XQABVSc"]
[Mon Jul 20 06:19:59.602446 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3XAABVW4"]
[Mon Jul 20 06:19:59.623398 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3YgABVSU"]
[Mon Jul 20 06:19:59.632212 2026] [security2:error] [pid 874439:tid 874691] [client 35.245.239.138:53865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Sb46ZSrFvCrJJhtQn0QAAAHo"]
[Mon Jul 20 06:19:59.745371 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3aAABVQY"]
[Mon Jul 20 06:19:59.814592 2026] [security2:error] [pid 871012:tid 871218] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3awABVW0"]
[Mon Jul 20 06:19:59.937509 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnzQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.962538 2026] [security2:error] [pid 871012:tid 871216] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3gwAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:19:59.989503 2026] [security2:error] [pid 874439:tid 874608] [client 103.77.203.233:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQn5QAAACc"]
[Mon Jul 20 06:19:59.989637 2026] [security2:error] [pid 874439:tid 874608] [client 103.77.203.233:59781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Sb46ZSrFvCrJJhtQn5QAAACc"]
[Mon Jul 20 06:20:00.038648 2026] [security2:error] [pid 874439:tid 874586] [client 173.230.133.164:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4Sb46ZSrFvCrJJhtQn2wAAABE"]
[Mon Jul 20 06:20:00.053590 2026] [security2:error] [pid 871012:tid 871202] [client 173.230.133.164:59914] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4Sb7wiU-Jh5ncAILF3jQAAAUU"]
[Mon Jul 20 06:20:00.087449 2026] [security2:error] [pid 871012:tid 871165] [client 103.141.108.143:64799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ScLwiU-Jh5ncAILF3kAAAASA"]
[Mon Jul 20 06:20:00.087584 2026] [security2:error] [pid 871012:tid 871165] [client 103.141.108.143:64799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ScLwiU-Jh5ncAILF3kAAAASA"]
[Mon Jul 20 06:20:00.141332 2026] [security2:error] [pid 874439:tid 874678] [client 35.245.239.138:58067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ScI6ZSrFvCrJJhtQn8QAAAG0"]
[Mon Jul 20 06:20:00.269987 2026] [security2:error] [pid 871012:tid 871050] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.continue/config.json"] [unique_id "al4ScLwiU-Jh5ncAILF3lQABgiQ"]
[Mon Jul 20 06:20:00.270243 2026] [security2:error] [pid 871012:tid 871263] [client 104.28.251.190:64862] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/.continue/config.json"] [unique_id "al4ScLwiU-Jh5ncAILF3lQABgiQ"]
[Mon Jul 20 06:20:00.287422 2026] [security2:error] [pid 874439:tid 874475] [remote 119.249.100.241:2687] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4ScI6ZSrFvCrJJhtQn_wAANSM"]
[Mon Jul 20 06:20:00.581938 2026] [security2:error] [pid 874439:tid 874643] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQn-wAAAEo"]
[Mon Jul 20 06:20:00.597235 2026] [security2:error] [pid 874439:tid 874631] [client 34.208.80.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoCAAAAD4"]
[Mon Jul 20 06:20:00.602619 2026] [security2:error] [pid 874439:tid 874445] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoEAAAUQU"]
[Mon Jul 20 06:20:00.602825 2026] [security2:error] [pid 874439:tid 874650] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoEAAAUQU"]
[Mon Jul 20 06:20:00.605775 2026] [security2:error] [pid 871012:tid 871166] [client 34.208.80.94:60798] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/"] [unique_id "al4ScLwiU-Jh5ncAILF3nAAAASE"]
[Mon Jul 20 06:20:00.619666 2026] [security2:error] [pid 874439:tid 874676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQn_AAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:00.687174 2026] [security2:error] [pid 871012:tid 871085] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.openclaw/.env"] [unique_id "al4ScLwiU-Jh5ncAILF3nwABc0c"]
[Mon Jul 20 06:20:00.724633 2026] [security2:error] [pid 871012:tid 871247] [client 185.132.186.64:23717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/raw.php"] [unique_id "al4ScLwiU-Jh5ncAILF3oQAAAXI"]
[Mon Jul 20 06:20:00.725797 2026] [security2:error] [pid 874439:tid 874574] [client 35.245.239.138:63442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ScI6ZSrFvCrJJhtQoHwAAAAU"]
[Mon Jul 20 06:20:00.746555 2026] [security2:error] [pid 871012:tid 871016] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/.hermes/auth.json"] [unique_id "al4ScLwiU-Jh5ncAILF3qAABcwI"]
[Mon Jul 20 06:20:00.747293 2026] [security2:error] [pid 871012:tid 871103] [remote 104.28.251.190:64862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.hermes/.env"] [unique_id "al4ScLwiU-Jh5ncAILF3pQABc1k"]
[Mon Jul 20 06:20:00.765825 2026] [security2:error] [pid 871012:tid 871173] [client 14.225.17.146:59662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3cAAAASg"], referer: http://eframiproperties.com/wp
[Mon Jul 20 06:20:00.849012 2026] [security2:error] [pid 874439:tid 874584] [client 50.116.65.227:29460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4ScI6ZSrFvCrJJhtQoLgAAAEs"]
[Mon Jul 20 06:20:00.866188 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3mQABczY"]
[Mon Jul 20 06:20:00.887736 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3mgABc00"]
[Mon Jul 20 06:20:00.889337 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3mwABcwc"]
[Mon Jul 20 06:20:01.024918 2026] [security2:error] [pid 874439:tid 874600] [client 34.208.80.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoKQAAAB8"]
[Mon Jul 20 06:20:01.028363 2026] [security2:error] [pid 871012:tid 871163] [client 34.208.80.94:50822] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4ScLwiU-Jh5ncAILF3rQAAAR4"]
[Mon Jul 20 06:20:01.233627 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:44827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoUAAAAHY"]
[Mon Jul 20 06:20:01.233765 2026] [security2:error] [pid 874439:tid 874687] [client 112.208.70.94:44827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoUAAAAHY"]
[Mon Jul 20 06:20:01.249896 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3owABc0s"]
[Mon Jul 20 06:20:01.278224 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3pAABc3M"]
[Mon Jul 20 06:20:01.281912 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoRAAAAFw"]
[Mon Jul 20 06:20:01.360309 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3qgABcwo"]
[Mon Jul 20 06:20:01.389570 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3pgABczo"]
[Mon Jul 20 06:20:01.396771 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3pwABcyI"]
[Mon Jul 20 06:20:01.477999 2026] [security2:error] [pid 874439:tid 874695] [client 181.224.94.124:11257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoYwAAAH4"]
[Mon Jul 20 06:20:01.478427 2026] [security2:error] [pid 874439:tid 874695] [client 181.224.94.124:11257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoYwAAAH4"]
[Mon Jul 20 06:20:01.479454 2026] [security2:error] [pid 871012:tid 871257] [client 135.132.71.159:24014] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "maxenengineering.com"] [uri "/wp-content/plugins/kirki/readme.txt"] [unique_id "al4ScbwiU-Jh5ncAILF3uwAAAXw"]
[Mon Jul 20 06:20:01.481310 2026] [security2:error] [pid 871012:tid 871248] [client 104.28.251.190:64862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ScLwiU-Jh5ncAILF3qQABcyg"]
[Mon Jul 20 06:20:01.614585 2026] [security2:error] [pid 871012:tid 871199] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScbwiU-Jh5ncAILF3tgAAAUI"]
[Mon Jul 20 06:20:01.697894 2026] [security2:error] [pid 874439:tid 874581] [client 35.245.239.138:63297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ScY6ZSrFvCrJJhtQocQAAAAw"]
[Mon Jul 20 06:20:01.815992 2026] [security2:error] [pid 874439:tid 874591] [client 14.182.195.220:52125] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ScY6ZSrFvCrJJhtQofgAAABY"]
[Mon Jul 20 06:20:01.816577 2026] [security2:error] [pid 874439:tid 874652] [client 14.182.195.220:52126] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ScY6ZSrFvCrJJhtQogAAAAFM"]
[Mon Jul 20 06:20:01.819767 2026] [security2:error] [pid 874439:tid 874646] [client 14.182.195.220:52124] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ScY6ZSrFvCrJJhtQogQAAAE0"]
[Mon Jul 20 06:20:01.853819 2026] [security2:error] [pid 874439:tid 874603] [client 171.61.165.146:15397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQohQAAACI"]
[Mon Jul 20 06:20:01.853926 2026] [security2:error] [pid 874439:tid 874603] [client 171.61.165.146:15397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQohQAAACI"]
[Mon Jul 20 06:20:01.967481 2026] [security2:error] [pid 874439:tid 874578] [client 178.152.178.232:37130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQokwAAAAk"]
[Mon Jul 20 06:20:01.967646 2026] [security2:error] [pid 874439:tid 874578] [client 178.152.178.232:37130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ScY6ZSrFvCrJJhtQokwAAAAk"]
[Mon Jul 20 06:20:02.037892 2026] [security2:error] [pid 871012:tid 871219] [client 14.225.17.146:60037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3ewAAAVY"], referer: http://healthylifegourmet.org/wp
[Mon Jul 20 06:20:02.272397 2026] [security2:error] [pid 874439:tid 874683] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQojQAAAHI"]
[Mon Jul 20 06:20:02.402759 2026] [security2:error] [pid 871012:tid 871029] [remote 57.141.18.41:26880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbbwiU-Jh5ncAILF3HQABNA8"]
[Mon Jul 20 06:20:02.450512 2026] [security2:error] [pid 874439:tid 874648] [client 77.110.127.138:60410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/xmlrpc.php"] [unique_id "al4Sco6ZSrFvCrJJhtQougAAAE8"]
[Mon Jul 20 06:20:02.470319 2026] [security2:error] [pid 874439:tid 874580] [client 35.245.239.138:60782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Sco6ZSrFvCrJJhtQowQAAAAs"]
[Mon Jul 20 06:20:02.541557 2026] [security2:error] [pid 874439:tid 874652] [client 185.132.186.78:40727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/js/jcrop/about.php"] [unique_id "al4Sco6ZSrFvCrJJhtQoxAAAAFM"]
[Mon Jul 20 06:20:02.598468 2026] [security2:error] [pid 874439:tid 874624] [client 57.141.18.55:52036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnOwAAN1c"]
[Mon Jul 20 06:20:02.642304 2026] [security2:error] [pid 874439:tid 874693] [client 57.141.18.40:32704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnOgAAfCs"]
[Mon Jul 20 06:20:02.666665 2026] [security2:error] [pid 874439:tid 874582] [client 20.199.97.14:2688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Sco6ZSrFvCrJJhtQozQAAAA0"]
[Mon Jul 20 06:20:02.804586 2026] [security2:error] [pid 874439:tid 874658] [client 57.141.18.64:46156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbY6ZSrFvCrJJhtQnTAAAWSU"]
[Mon Jul 20 06:20:02.819007 2026] [security2:error] [pid 874439:tid 874642] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQoywAAAEk"], referer: 1'"3000
[Mon Jul 20 06:20:02.819126 2026] [security2:error] [pid 874439:tid 874573] [client 20.199.97.14:2688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Sco6ZSrFvCrJJhtQo3wAAAAQ"]
[Mon Jul 20 06:20:03.088254 2026] [security2:error] [pid 874439:tid 874687] [client 50.116.65.227:55654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Sc46ZSrFvCrJJhtQo9gAAAHY"]
[Mon Jul 20 06:20:03.100939 2026] [security2:error] [pid 874439:tid 874649] [client 50.116.65.227:29480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4Sc46ZSrFvCrJJhtQo-AAAAFA"]
[Mon Jul 20 06:20:03.123586 2026] [security2:error] [pid 871012:tid 871095] [remote 57.141.18.28:36480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SbrwiU-Jh5ncAILF3OgABP1E"]
[Mon Jul 20 06:20:03.415803 2026] [security2:error] [pid 874439:tid 874646] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQo8QAAAE0"], referer: 1'"3000
[Mon Jul 20 06:20:03.485833 2026] [security2:error] [pid 874439:tid 874532] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-config.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpGgAAA1w"]
[Mon Jul 20 06:20:03.485832 2026] [security2:error] [pid 874439:tid 874508] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-config.php.old"] [unique_id "al4Sc46ZSrFvCrJJhtQpHAAAA0Q"]
[Mon Jul 20 06:20:03.486249 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-config.php.old"] [unique_id "al4Sc46ZSrFvCrJJhtQpHAAAA0Q"]
[Mon Jul 20 06:20:03.487558 2026] [security2:error] [pid 874439:tid 874508] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/core/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpIAAAA0Q"]
[Mon Jul 20 06:20:03.487561 2026] [security2:error] [pid 874439:tid 874472] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/laravel/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpIgAAAyA"]
[Mon Jul 20 06:20:03.488814 2026] [security2:error] [pid 874439:tid 874565] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpIQAAA30"]
[Mon Jul 20 06:20:03.527279 2026] [security2:error] [pid 874439:tid 874532] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/config/.env.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpHwAAA1w"]
[Mon Jul 20 06:20:03.692444 2026] [security2:error] [pid 874439:tid 874692] [client 104.234.53.53:63883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpKQAAAHs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:03.850701 2026] [security2:error] [pid 874439:tid 874650] [client 35.245.239.138:56698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Sc46ZSrFvCrJJhtQpQgAAAFE"]
[Mon Jul 20 06:20:03.855120 2026] [security2:error] [pid 874439:tid 874481] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/web/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpQwAAAyk"]
[Mon Jul 20 06:20:03.913696 2026] [security2:error] [pid 874439:tid 874547] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/config.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpTgAAA2s"]
[Mon Jul 20 06:20:03.913790 2026] [security2:error] [pid 874439:tid 874511] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/configuration.php.bak"] [unique_id "al4Sc46ZSrFvCrJJhtQpUQAAA0c"]
[Mon Jul 20 06:20:03.914422 2026] [security2:error] [pid 874439:tid 874554] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/public/.env"] [unique_id "al4Sc46ZSrFvCrJJhtQpTwAAA3I"]
[Mon Jul 20 06:20:03.914838 2026] [security2:error] [pid 874439:tid 874479] [remote 104.28.251.190:64759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "lifeisbetterlakeside.com"] [uri "/.env.swp"] [unique_id "al4Sc46ZSrFvCrJJhtQpUAAAAyc"]
[Mon Jul 20 06:20:04.000172 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpEAAAAyQ"]
[Mon Jul 20 06:20:04.062375 2026] [security2:error] [pid 874439:tid 874657] [client 50.116.65.227:29508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpZwAAAFg"]
[Mon Jul 20 06:20:04.065507 2026] [security2:error] [pid 874439:tid 874675] [client 14.225.17.146:59524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQowAAAAGo"], referer: http://recruitinginsight.us/wp
[Mon Jul 20 06:20:04.086647 2026] [security2:error] [pid 874439:tid 874582] [client 14.225.17.146:59109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpXAAAAA0"]
[Mon Jul 20 06:20:04.087990 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpHQAAAyM"]
[Mon Jul 20 06:20:04.122013 2026] [security2:error] [pid 874439:tid 874633] [client 104.234.53.53:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpbwAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:04.140821 2026] [security2:error] [pid 874439:tid 874690] [client 57.141.18.5:47738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sb46ZSrFvCrJJhtQnswAAeWA"]
[Mon Jul 20 06:20:04.146541 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpHgAAAy4"]
[Mon Jul 20 06:20:04.146886 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpIwAAA3E"]
[Mon Jul 20 06:20:04.181467 2026] [security2:error] [pid 874439:tid 874680] [client 50.116.65.227:29516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4SdI6ZSrFvCrJJhtQpeAAAADc"]
[Mon Jul 20 06:20:04.196865 2026] [http2:info] [pid 884009:tid 884009] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:20:04.200615 2026] [autoindex:error] [pid 874439:tid 874644] [client 67.205.140.53:0] AH01276: Cannot serve directory /home4/elemeph8/public_html/elementfix/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:04.224029 2026] [security2:error] [pid 874439:tid 874572] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpJAAAA3k"]
[Mon Jul 20 06:20:04.280482 2026] [security2:error] [pid 871012:tid 871028] [remote 57.141.18.39:29247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sb7wiU-Jh5ncAILF3fwABNQ4"]
[Mon Jul 20 06:20:04.390700 2026] [security2:error] [pid 874439:tid 874676] [client 185.132.186.103:53581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/includes/admin.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpfwAAAGs"]
[Mon Jul 20 06:20:04.466425 2026] [security2:error] [pid 874439:tid 874546] [remote 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpUwAAA2o"]
[Mon Jul 20 06:20:04.548990 2026] [security2:error] [pid 874439:tid 874509] [remote 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpTQAAA0U"]
[Mon Jul 20 06:20:04.630853 2026] [security2:error] [pid 874439:tid 874467] [remote 34.21.244.199:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpjwAAKRs"]
[Mon Jul 20 06:20:04.740338 2026] [security2:error] [pid 874439:tid 874666] [client 34.207.130.29:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpSwAAAGE"]
[Mon Jul 20 06:20:04.743993 2026] [security2:error] [pid 874439:tid 874599] [client 34.207.130.29:51640] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4Sc46ZSrFvCrJJhtQpRwAAAB4"]
[Mon Jul 20 06:20:04.755037 2026] [security2:error] [pid 874439:tid 874584] [client 14.225.17.146:59971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpjgAAAA8"], referer: http://koaconsultants.com/wp
[Mon Jul 20 06:20:05.229456 2026] [security2:error] [pid 884009:tid 884017] [remote 95.217.78.234:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SdRKaHUf6J8d3elJB2wAApQY"]
[Mon Jul 20 06:20:05.246723 2026] [security2:error] [pid 874439:tid 874518] [remote 34.21.244.199:33554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SdY6ZSrFvCrJJhtQpuQAAcU4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:05.362244 2026] [security2:error] [pid 874439:tid 874637] [client 57.141.18.9:47916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScI6ZSrFvCrJJhtQoEQAARGc"]
[Mon Jul 20 06:20:05.382897 2026] [security2:error] [pid 874439:tid 874642] [client 34.74.185.202:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SdY6ZSrFvCrJJhtQpvwAAAEk"]
[Mon Jul 20 06:20:05.412218 2026] [security2:error] [pid 884009:tid 884174] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SdRKaHUf6J8d3elJBzwAAAKY"], referer: 1'"3000
[Mon Jul 20 06:20:05.465771 2026] [security2:error] [pid 884009:tid 884021] [remote 95.217.78.234:51164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SdRKaHUf6J8d3elJB5AAAyAo"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:05.588424 2026] [security2:error] [pid 874439:tid 874651] [client 35.245.239.138:56484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SdY6ZSrFvCrJJhtQpzAAAAFI"]
[Mon Jul 20 06:20:05.813985 2026] [security2:error] [pid 884009:tid 884217] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SdRKaHUf6J8d3elJB6AAAANE"], referer: 1'"3000
[Mon Jul 20 06:20:05.852111 2026] [security2:error] [pid 874439:tid 874585] [client 57.141.18.14:34136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoSAAAEFA"]
[Mon Jul 20 06:20:06.080833 2026] [security2:error] [pid 884009:tid 884238] [client 14.225.17.146:52542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4SdhKaHUf6J8d3elJB9AAAAOY"], referer: http://grndl.com/wp
[Mon Jul 20 06:20:06.184905 2026] [security2:error] [pid 884009:tid 884262] [client 185.132.186.63:26055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/chosen.php"] [unique_id "al4SdhKaHUf6J8d3elJB-gAAAP4"]
[Mon Jul 20 06:20:06.352616 2026] [security2:error] [pid 874439:tid 874607] [client 57.141.18.40:32720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQodwAAJgc"]
[Mon Jul 20 06:20:06.366042 2026] [security2:error] [pid 884009:tid 884258] [client 34.74.185.202:61738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SdhKaHUf6J8d3elJCAwAAAPo"]
[Mon Jul 20 06:20:06.402286 2026] [security2:error] [pid 874439:tid 874611] [client 57.141.18.88:39650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ScY6ZSrFvCrJJhtQoiAAAKgM"]
[Mon Jul 20 06:20:06.438500 2026] [security2:error] [pid 874439:tid 874636] [client 50.116.65.227:29534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4Sdo6ZSrFvCrJJhtQp6wAAAAE"]
[Mon Jul 20 06:20:06.477783 2026] [security2:error] [pid 874439:tid 874655] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SdY6ZSrFvCrJJhtQp1gAAVhg"]
[Mon Jul 20 06:20:06.705705 2026] [security2:error] [pid 884009:tid 884028] [remote 5.161.225.162:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SdhKaHUf6J8d3elJCEQAA5xE"]
[Mon Jul 20 06:20:06.764509 2026] [security2:error] [pid 884009:tid 884030] [remote 72.167.132.114:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4SdhKaHUf6J8d3elJCFwAAkRM"]
[Mon Jul 20 06:20:06.774071 2026] [security2:error] [pid 874439:tid 874545] [remote 57.141.18.113:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5561908"] [unique_id "al4Sdo6ZSrFvCrJJhtQp_QAAf2k"]
[Mon Jul 20 06:20:06.803541 2026] [security2:error] [pid 884009:tid 884032] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SdhKaHUf6J8d3elJCHAAAxxU"]
[Mon Jul 20 06:20:06.803767 2026] [security2:error] [pid 884009:tid 884207] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SdhKaHUf6J8d3elJCHAAAxxU"]
[Mon Jul 20 06:20:06.873920 2026] [security2:error] [pid 884009:tid 884188] [client 34.74.185.202:63953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SdhKaHUf6J8d3elJCHwAAALQ"]
[Mon Jul 20 06:20:06.874346 2026] [security2:error] [pid 884009:tid 884213] [client 114.119.144.64:59241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "amberhillstyle.com"] [uri "/robots.txt"] [unique_id "al4SdhKaHUf6J8d3elJCIAAAAM0"], referer: http://amberhillstyle.com/robots.txt
[Mon Jul 20 06:20:06.979496 2026] [security2:error] [pid 884009:tid 884035] [remote 72.167.132.114:40374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4SdhKaHUf6J8d3elJCJgAA1Rg"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:20:07.027903 2026] [security2:error] [pid 884009:tid 884034] [remote 5.161.225.162:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4SdxKaHUf6J8d3elJCKAAA1hc"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:20:07.035553 2026] [security2:error] [pid 874439:tid 874694] [client 57.141.18.33:58726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQoyQAAfUk"]
[Mon Jul 20 06:20:07.051689 2026] [security2:error] [pid 874439:tid 874612] [client 35.245.239.138:62813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Sd46ZSrFvCrJJhtQqBgAAACs"]
[Mon Jul 20 06:20:07.175409 2026] [security2:error] [pid 874439:tid 874562] [remote 72.167.132.114:40384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqDgAASno"]
[Mon Jul 20 06:20:07.385416 2026] [security2:error] [pid 874439:tid 874664] [client 57.141.18.22:36760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sco6ZSrFvCrJJhtQo5wAAX0o"]
[Mon Jul 20 06:20:07.500937 2026] [security2:error] [pid 874439:tid 874459] [remote 72.167.132.114:40384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqHAAAcRM"], referer: https://ncsynchro.com/wp-login.php
[Mon Jul 20 06:20:07.687634 2026] [security2:error] [pid 884009:tid 884148] [client 34.74.185.202:54745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SdxKaHUf6J8d3elJCQQAAAI0"]
[Mon Jul 20 06:20:07.827386 2026] [security2:error] [pid 874439:tid 874647] [client 57.141.18.108:37390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sc46ZSrFvCrJJhtQpDQAATg8"]
[Mon Jul 20 06:20:07.846892 2026] [security2:error] [pid 884009:tid 884147] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SdxKaHUf6J8d3elJCPQAAAIw"]
[Mon Jul 20 06:20:07.986291 2026] [security2:error] [pid 884009:tid 884176] [client 185.132.186.55:38689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/2021/wp-works.php"] [unique_id "al4SdxKaHUf6J8d3elJCUAAAAKg"]
[Mon Jul 20 06:20:08.143141 2026] [security2:error] [pid 884009:tid 884263] [client 47.128.61.212:63398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "querenciapartners.com"] [uri "/robots.txt"] [unique_id "al4SeBKaHUf6J8d3elJCUgAAAP8"]
[Mon Jul 20 06:20:08.247251 2026] [security2:error] [pid 874439:tid 874653] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqWwAAAFQ"], referer: 1'"3000
[Mon Jul 20 06:20:08.344409 2026] [security2:error] [pid 884009:tid 884229] [client 68.235.52.68:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SeBKaHUf6J8d3elJCWQAAAN0"]
[Mon Jul 20 06:20:08.344513 2026] [security2:error] [pid 884009:tid 884229] [client 68.235.52.68:60216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4SeBKaHUf6J8d3elJCWQAAAN0"]
[Mon Jul 20 06:20:08.497665 2026] [security2:error] [pid 874439:tid 874520] [remote 142.93.10.93:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqegAAMlA"]
[Mon Jul 20 06:20:08.497914 2026] [security2:error] [pid 874439:tid 874619] [client 142.93.10.93:46162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqegAAMlA"]
[Mon Jul 20 06:20:08.653931 2026] [security2:error] [pid 874439:tid 874592] [client 57.141.18.15:44408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdI6ZSrFvCrJJhtQpYQAAF2Y"]
[Mon Jul 20 06:20:08.756691 2026] [security2:error] [pid 874439:tid 874655] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqgAAAAFY"], referer: 1'"3000
[Mon Jul 20 06:20:08.946890 2026] [security2:error] [pid 874439:tid 874648] [client 34.74.185.202:50331] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SeI6ZSrFvCrJJhtQqmgAAAE8"]
[Mon Jul 20 06:20:09.078513 2026] [security2:error] [pid 884009:tid 884155] [client 35.245.239.138:58973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SeRKaHUf6J8d3elJCeAAAAJQ"]
[Mon Jul 20 06:20:09.189600 2026] [security2:error] [pid 874439:tid 874629] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeI6ZSrFvCrJJhtQqnQAAADw"], referer: 1'"3000
[Mon Jul 20 06:20:09.226899 2026] [cgid:error] [pid 874439:tid 874636] [client 66.132.195.34:63894] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: https://www.smtracking.genesismbs.com:443/cgi-bin
[Mon Jul 20 06:20:09.244978 2026] [security2:error] [pid 884009:tid 884162] [client 57.141.18.60:64348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdBKaHUf6J8d3elJByQAAmwM"]
[Mon Jul 20 06:20:09.363433 2026] [security2:error] [pid 884009:tid 884146] [client 171.60.139.123:55865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SeRKaHUf6J8d3elJCigAAAIs"]
[Mon Jul 20 06:20:09.363568 2026] [security2:error] [pid 884009:tid 884146] [client 171.60.139.123:55865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SeRKaHUf6J8d3elJCigAAAIs"]
[Mon Jul 20 06:20:09.407298 2026] [security2:error] [pid 874439:tid 874669] [client 14.225.17.146:59797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4Sd46ZSrFvCrJJhtQqXAAAAGQ"], referer: http://thechancersband.com/wp
[Mon Jul 20 06:20:09.575392 2026] [security2:error] [pid 874439:tid 874625] [client 77.110.127.138:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqtAAAADg"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.575528 2026] [security2:error] [pid 874439:tid 874625] [client 77.110.127.138:60434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqtAAAADg"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.576540 2026] [security2:error] [pid 874439:tid 874576] [client 77.110.127.138:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqswAAAAc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.576658 2026] [security2:error] [pid 874439:tid 874576] [client 77.110.127.138:60435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqswAAAAc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.581634 2026] [security2:error] [pid 884009:tid 884181] [client 34.74.185.202:50781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SeRKaHUf6J8d3elJClgAAAK0"]
[Mon Jul 20 06:20:09.645130 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:60448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoAAAAO8"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.645279 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:60448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoAAAAO8"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.645617 2026] [security2:error] [pid 884009:tid 884236] [client 77.110.127.138:60449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoQAAAOQ"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.645736 2026] [security2:error] [pid 884009:tid 884236] [client 77.110.127.138:60449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SeRKaHUf6J8d3elJCoQAAAOQ"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:20:09.690482 2026] [security2:error] [pid 874439:tid 874654] [client 77.110.127.138:60438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/501/amp/xlnlverl5yxp.php"] [unique_id "al4SeY6ZSrFvCrJJhtQqxgAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:09.747964 2026] [security2:error] [pid 884009:tid 884183] [client 57.141.18.101:37768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdRKaHUf6J8d3elJB2gAArwU"]
[Mon Jul 20 06:20:09.798897 2026] [security2:error] [pid 884009:tid 884211] [client 185.132.186.81:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/media-new.php"] [unique_id "al4SeRKaHUf6J8d3elJCrQAAAMs"]
[Mon Jul 20 06:20:10.012640 2026] [security2:error] [pid 884009:tid 884144] [client 34.74.185.202:50796] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SehKaHUf6J8d3elJCvQAAAIk"]
[Mon Jul 20 06:20:10.088688 2026] [security2:error] [pid 874439:tid 874607] [client 50.116.65.227:42864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Seo6ZSrFvCrJJhtQq3gAAACY"]
[Mon Jul 20 06:20:10.099114 2026] [security2:error] [pid 884009:tid 884168] [client 50.116.65.227:42872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SehKaHUf6J8d3elJCvwAAAKE"]
[Mon Jul 20 06:20:10.183318 2026] [security2:error] [pid 884009:tid 884141] [client 45.116.69.230:63992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJCwgAAAIY"]
[Mon Jul 20 06:20:10.183460 2026] [security2:error] [pid 884009:tid 884141] [client 45.116.69.230:63992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJCwgAAAIY"]
[Mon Jul 20 06:20:10.254507 2026] [security2:error] [pid 874439:tid 874634] [client 14.182.195.220:52129] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Seo6ZSrFvCrJJhtQq6gAAAEE"]
[Mon Jul 20 06:20:10.255824 2026] [security2:error] [pid 874439:tid 874592] [client 14.182.195.220:52128] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4Seo6ZSrFvCrJJhtQq6wAAABc"]
[Mon Jul 20 06:20:10.276359 2026] [security2:error] [pid 884009:tid 884206] [client 14.182.195.220:52130] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SehKaHUf6J8d3elJCxAAAAMY"]
[Mon Jul 20 06:20:10.387136 2026] [security2:error] [pid 874439:tid 874625] [client 35.245.239.138:65292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "uwl.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Seo6ZSrFvCrJJhtQq7wAAADg"]
[Mon Jul 20 06:20:10.393386 2026] [security2:error] [pid 884009:tid 884199] [client 34.74.185.202:54976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SehKaHUf6J8d3elJCzwAAAL8"]
[Mon Jul 20 06:20:10.459160 2026] [security2:error] [pid 884009:tid 884248] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeRKaHUf6J8d3elJCpAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:10.490552 2026] [security2:error] [pid 884009:tid 884253] [client 77.110.127.138:60439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeRKaHUf6J8d3elJCqQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:10.509637 2026] [security2:error] [pid 874439:tid 874659] [client 104.234.53.88:37041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq8wAAAFo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:10.535064 2026] [security2:error] [pid 874439:tid 874666] [client 103.77.203.233:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.203.77.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq9AAAAGE"]
[Mon Jul 20 06:20:10.535273 2026] [security2:error] [pid 874439:tid 874666] [client 103.77.203.233:60351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq9AAAAGE"]
[Mon Jul 20 06:20:10.650010 2026] [security2:error] [pid 884009:tid 884153] [client 14.225.17.146:62020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4SeRKaHUf6J8d3elJCegAAAJI"], referer: http://bnb-engineering.com/wp
[Mon Jul 20 06:20:10.791068 2026] [security2:error] [pid 874439:tid 874675] [client 103.141.108.143:65284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq_AAAAGo"]
[Mon Jul 20 06:20:10.792136 2026] [security2:error] [pid 874439:tid 874675] [client 103.141.108.143:65284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq_AAAAGo"]
[Mon Jul 20 06:20:10.806846 2026] [security2:error] [pid 884009:tid 884065] [remote 91.142.222.105:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SehKaHUf6J8d3elJC2wAArjY"]
[Mon Jul 20 06:20:10.895199 2026] [security2:error] [pid 884009:tid 884066] [remote 57.141.18.70:63252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4SehKaHUf6J8d3elJC3wAArzc"]
[Mon Jul 20 06:20:10.954988 2026] [security2:error] [pid 884009:tid 884209] [client 13.229.223.11:35160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJC4QAAAMk"]
[Mon Jul 20 06:20:10.955137 2026] [security2:error] [pid 884009:tid 884209] [client 13.229.223.11:35160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SehKaHUf6J8d3elJC4QAAAMk"]
[Mon Jul 20 06:20:11.020552 2026] [security2:error] [pid 874439:tid 874575] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SeY6ZSrFvCrJJhtQq1AAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.068533 2026] [security2:error] [pid 884009:tid 884215] [client 34.74.185.202:55148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SexKaHUf6J8d3elJC5wAAAM8"]
[Mon Jul 20 06:20:11.071346 2026] [security2:error] [pid 874439:tid 874646] [client 50.116.65.227:51238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Se46ZSrFvCrJJhtQrCwAAAE0"]
[Mon Jul 20 06:20:11.078929 2026] [security2:error] [pid 884009:tid 884068] [remote 91.142.222.105:48422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SexKaHUf6J8d3elJC5gAAoTk"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:20:11.082113 2026] [security2:error] [pid 874439:tid 874637] [client 50.116.65.227:42880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Se46ZSrFvCrJJhtQrDAAAADw"]
[Mon Jul 20 06:20:11.149205 2026] [autoindex:error] [pid 874439:tid 874619] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:11.231126 2026] [security2:error] [pid 874439:tid 874544] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Se46ZSrFvCrJJhtQrGgAAKWg"]
[Mon Jul 20 06:20:11.231290 2026] [security2:error] [pid 874439:tid 874610] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Se46ZSrFvCrJJhtQrGgAAKWg"]
[Mon Jul 20 06:20:11.339255 2026] [autoindex:error] [pid 884009:tid 884166] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.380591 2026] [security2:error] [pid 884009:tid 884260] [client 57.141.0.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4SehKaHUf6J8d3elJC2gAAAPw"]
[Mon Jul 20 06:20:11.382935 2026] [security2:error] [pid 884009:tid 884199] [client 77.110.127.138:60460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/js/aagjkqj7r4y9.php"] [unique_id "al4SexKaHUf6J8d3elJC-QAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.582566 2026] [security2:error] [pid 874439:tid 874653] [client 14.225.17.146:52760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4Seo6ZSrFvCrJJhtQq3QAAAFQ"], referer: http://solkeetw.com/wp
[Mon Jul 20 06:20:11.606139 2026] [security2:error] [pid 884009:tid 884224] [client 185.132.186.102:51329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/media-new.php"] [unique_id "al4SexKaHUf6J8d3elJDCAAAANg"]
[Mon Jul 20 06:20:11.630368 2026] [security2:error] [pid 884009:tid 884165] [client 77.110.127.138:60436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SexKaHUf6J8d3elJC8QAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.631702 2026] [security2:error] [pid 884009:tid 884198] [client 178.152.178.232:37720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SexKaHUf6J8d3elJDCQAAAL4"]
[Mon Jul 20 06:20:11.631840 2026] [security2:error] [pid 884009:tid 884198] [client 178.152.178.232:37720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SexKaHUf6J8d3elJDCQAAAL4"]
[Mon Jul 20 06:20:11.668879 2026] [security2:error] [pid 874439:tid 874589] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Se46ZSrFvCrJJhtQrHwAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:11.687215 2026] [security2:error] [pid 874439:tid 874455] [remote 57.141.18.22:50060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5417502"] [unique_id "al4Se46ZSrFvCrJJhtQrMAAASg8"]
[Mon Jul 20 06:20:11.714170 2026] [security2:error] [pid 884009:tid 884256] [client 34.74.185.202:55906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SexKaHUf6J8d3elJDDgAAAPg"]
[Mon Jul 20 06:20:11.930022 2026] [security2:error] [pid 884009:tid 884208] [client 50.116.65.227:42908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4SexKaHUf6J8d3elJDFQAAAIw"]
[Mon Jul 20 06:20:11.971946 2026] [security2:error] [pid 884009:tid 884210] [client 34.74.185.202:63330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SexKaHUf6J8d3elJDFwAAAMo"]
[Mon Jul 20 06:20:12.047027 2026] [security2:error] [pid 874439:tid 874612] [client 181.224.94.124:6528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SfI6ZSrFvCrJJhtQrRgAAACs"]
[Mon Jul 20 06:20:12.047197 2026] [security2:error] [pid 874439:tid 874612] [client 181.224.94.124:6528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SfI6ZSrFvCrJJhtQrRgAAACs"]
[Mon Jul 20 06:20:12.083244 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.90:44446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SdxKaHUf6J8d3elJCOwAA9xw"]
[Mon Jul 20 06:20:12.281588 2026] [security2:error] [pid 874439:tid 874630] [client 14.225.17.146:54191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4Seo6ZSrFvCrJJhtQrAAAAAD0"], referer: http://bbwipartnerconference.com/wp
[Mon Jul 20 06:20:12.380540 2026] [autoindex:error] [pid 874439:tid 874615] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:12.381603 2026] [autoindex:error] [pid 874439:tid 874587] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.449272 2026] [security2:error] [pid 874439:tid 874618] [client 77.110.127.138:60464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/js/integrations/pqmqe4uwxwye.php"] [unique_id "al4SfI6ZSrFvCrJJhtQrYQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.603679 2026] [security2:error] [pid 884009:tid 884202] [client 171.61.165.146:14416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SfBKaHUf6J8d3elJDLgAAAMI"]
[Mon Jul 20 06:20:12.603854 2026] [security2:error] [pid 884009:tid 884202] [client 171.61.165.146:14416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SfBKaHUf6J8d3elJDLgAAAMI"]
[Mon Jul 20 06:20:12.693580 2026] [security2:error] [pid 884009:tid 884241] [client 34.74.185.202:51441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SfBKaHUf6J8d3elJDNAAAAOk"]
[Mon Jul 20 06:20:12.800626 2026] [security2:error] [pid 884009:tid 884232] [client 57.141.18.22:33428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SeBKaHUf6J8d3elJCYAAA4CM"]
[Mon Jul 20 06:20:12.801837 2026] [security2:error] [pid 884009:tid 884266] [client 77.110.127.138:60466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfBKaHUf6J8d3elJDJQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.844857 2026] [security2:error] [pid 884009:tid 884204] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfBKaHUf6J8d3elJDKAAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:12.869174 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:52323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4SexKaHUf6J8d3elJC9AAAAIk"], referer: http://alexsandbergmusic.com/wp
[Mon Jul 20 06:20:13.070879 2026] [security2:error] [pid 884009:tid 884267] [client 34.74.185.202:58755] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.awj.kzx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SfRKaHUf6J8d3elJDVAAAAQM"]
[Mon Jul 20 06:20:13.136509 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SfRKaHUf6J8d3elJDVwAAANg"]
[Mon Jul 20 06:20:13.136634 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SfRKaHUf6J8d3elJDVwAAANg"]
[Mon Jul 20 06:20:13.141675 2026] [security2:error] [pid 884009:tid 884206] [client 77.110.127.138:60473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/js/integrations/stripe/56w8agrny1hp.php"] [unique_id "al4SfRKaHUf6J8d3elJDWQAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:13.183977 2026] [autoindex:error] [pid 884009:tid 884213] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/stripe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:13.197652 2026] [autoindex:error] [pid 874439:tid 874683] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/js/integrations/stripe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:20:13.385189 2026] [security2:error] [pid 884009:tid 884219] [client 50.116.65.227:42940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4SfRKaHUf6J8d3elJDYwAAANs"]
[Mon Jul 20 06:20:13.402731 2026] [security2:error] [pid 874439:tid 874608] [client 185.132.186.96:45819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/class_api.php"] [unique_id "al4SfY6ZSrFvCrJJhtQrhAAAACc"]
[Mon Jul 20 06:20:13.500666 2026] [security2:error] [pid 874439:tid 874607] [client 77.110.127.138:60414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfY6ZSrFvCrJJhtQrdgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:13.539510 2026] [security2:error] [pid 874439:tid 874661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SfY6ZSrFvCrJJhtQreAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:14.525830 2026] [security2:error] [pid 874439:tid 874657] [client 14.225.17.146:61748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Sfo6ZSrFvCrJJhtQrtgAAAFg"], referer: http://omenana.com/wp
[Mon Jul 20 06:20:14.710634 2026] [security2:error] [pid 874439:tid 874648] [client 157.55.39.61:58900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4Sfo6ZSrFvCrJJhtQruAAAT30"]
[Mon Jul 20 06:20:15.030174 2026] [security2:error] [pid 884009:tid 884242] [client 34.74.185.202:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SfxKaHUf6J8d3elJDoAAAAOo"]
[Mon Jul 20 06:20:15.201956 2026] [security2:error] [pid 874439:tid 874654] [client 185.132.186.100:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/2021/themes.php"] [unique_id "al4Sf46ZSrFvCrJJhtQr3QAAAFU"]
[Mon Jul 20 06:20:15.442262 2026] [security2:error] [pid 884009:tid 884201] [client 34.74.185.202:50838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SfxKaHUf6J8d3elJDsAAAAME"]
[Mon Jul 20 06:20:15.723409 2026] [security2:error] [pid 884009:tid 884188] [client 34.74.185.202:63344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SfxKaHUf6J8d3elJDuwAAALQ"]
[Mon Jul 20 06:20:15.758011 2026] [security2:error] [pid 884009:tid 884172] [client 98.159.234.160:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SfxKaHUf6J8d3elJDvQAAAKQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:15.981454 2026] [security2:error] [pid 884009:tid 884160] [client 57.141.18.41:25892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SexKaHUf6J8d3elJDBgAAmT0"]
[Mon Jul 20 06:20:16.071567 2026] [security2:error] [pid 884009:tid 884164] [client 104.234.53.51:40859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SgBKaHUf6J8d3elJDygAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:16.101643 2026] [security2:error] [pid 874439:tid 874606] [client 14.225.17.146:52328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4SfY6ZSrFvCrJJhtQrrAAAACU"], referer: http://dollpassionista.com/wp
[Mon Jul 20 06:20:16.190683 2026] [security2:error] [pid 884009:tid 884198] [client 14.225.17.146:51686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4SfxKaHUf6J8d3elJDngAAAL4"], referer: http://getgarrison.com/wp
[Mon Jul 20 06:20:16.210773 2026] [security2:error] [pid 874439:tid 874600] [client 34.74.185.202:63424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SgI6ZSrFvCrJJhtQr_QAAAB8"]
[Mon Jul 20 06:20:16.440734 2026] [security2:error] [pid 884009:tid 884252] [client 50.116.65.227:42998] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/01/IMG_8522.jpeg"] [unique_id "al4SgBKaHUf6J8d3elJD3QAAAPQ"]
[Mon Jul 20 06:20:16.641910 2026] [security2:error] [pid 884009:tid 884244] [client 34.74.185.202:65333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SgBKaHUf6J8d3elJD5AAAAOw"]
[Mon Jul 20 06:20:16.679486 2026] [security2:error] [pid 874439:tid 874688] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SgI6ZSrFvCrJJhtQsAgAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:16.701476 2026] [security2:error] [pid 874439:tid 874639] [client 74.7.227.179:34500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SgI6ZSrFvCrJJhtQsFAAARnw"], referer: https://tejasenvironmental.com/p=821518
[Mon Jul 20 06:20:16.751822 2026] [security2:error] [pid 884009:tid 884172] [client 173.239.218.6:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "arrazoado.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4SgBKaHUf6J8d3elJD5wAAAKQ"]
[Mon Jul 20 06:20:16.988624 2026] [security2:error] [pid 874439:tid 874695] [client 34.74.185.202:56960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SgI6ZSrFvCrJJhtQsJQAAAH4"]
[Mon Jul 20 06:20:17.006172 2026] [security2:error] [pid 874439:tid 874675] [client 185.132.186.59:38635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/admin/install.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsJwAAAGo"]
[Mon Jul 20 06:20:17.140994 2026] [security2:error] [pid 884009:tid 884219] [client 14.225.17.146:51869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4SgBKaHUf6J8d3elJD8AAAANM"], referer: https://dollpassionista.com/wp
[Mon Jul 20 06:20:17.295323 2026] [security2:error] [pid 884009:tid 884220] [client 34.74.185.202:52511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SgRKaHUf6J8d3elJD-QAAANQ"]
[Mon Jul 20 06:20:17.448521 2026] [security2:error] [pid 874439:tid 874449] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsNwAAKwk"]
[Mon Jul 20 06:20:17.448690 2026] [security2:error] [pid 874439:tid 874612] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsNwAAKwk"]
[Mon Jul 20 06:20:17.673790 2026] [security2:error] [pid 884009:tid 884179] [client 77.110.127.138:60492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SgRKaHUf6J8d3elJEAgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:17.673898 2026] [security2:error] [pid 884009:tid 884179] [client 77.110.127.138:60492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SgRKaHUf6J8d3elJEAgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:17.856188 2026] [security2:error] [pid 884009:tid 884232] [client 114.119.141.112:40401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/category-s/26.htm"] [unique_id "al4SgRKaHUf6J8d3elJEEAAAAOA"], referer: http://www.sarakety.com/Chimney-12-18-Months-p/121zsqz01.htm
[Mon Jul 20 06:20:17.935418 2026] [security2:error] [pid 884009:tid 884239] [client 34.74.185.202:51954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SgRKaHUf6J8d3elJEFAAAAOc"]
[Mon Jul 20 06:20:17.972764 2026] [security2:error] [pid 884009:tid 884166] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SgRKaHUf6J8d3elJD-AAAAJ8"]
[Mon Jul 20 06:20:17.995058 2026] [security2:error] [pid 884009:tid 884187] [client 3.85.28.216:61412] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pegao-puerto-rican-crispy-rice/"] [unique_id "al4SgRKaHUf6J8d3elJD9gAAALM"]
[Mon Jul 20 06:20:18.090986 2026] [security2:error] [pid 884009:tid 884126] [remote 57.141.18.48:48420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2596330"] [unique_id "al4SghKaHUf6J8d3elJEHgAAhXM"]
[Mon Jul 20 06:20:18.102041 2026] [security2:error] [pid 884009:tid 884165] [client 57.141.18.22:33458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SfRKaHUf6J8d3elJDagAAnks"]
[Mon Jul 20 06:20:18.296637 2026] [security2:error] [pid 874439:tid 874602] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQsTwAAITU"]
[Mon Jul 20 06:20:18.414916 2026] [security2:error] [pid 874439:tid 874602] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsSwAAIQU"]
[Mon Jul 20 06:20:18.490392 2026] [security2:error] [pid 884009:tid 884151] [client 34.74.185.202:54783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SghKaHUf6J8d3elJEKQAAAJA"]
[Mon Jul 20 06:20:18.666923 2026] [security2:error] [pid 884009:tid 884216] [client 50.116.65.227:51250] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SghKaHUf6J8d3elJELwAAANA"]
[Mon Jul 20 06:20:18.678724 2026] [security2:error] [pid 884009:tid 884156] [client 50.116.65.227:43002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SghKaHUf6J8d3elJEMQAAAJU"]
[Mon Jul 20 06:20:18.727628 2026] [security2:error] [pid 874439:tid 874687] [client 14.225.17.146:60677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsNAAAAHY"], referer: http://wathenbartlett.co.uk/wp
[Mon Jul 20 06:20:18.816553 2026] [security2:error] [pid 874439:tid 874571] [client 185.132.186.79:21215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/plugin.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQsdgAAAAI"]
[Mon Jul 20 06:20:18.867565 2026] [security2:error] [pid 884009:tid 884178] [client 34.74.185.202:51733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SghKaHUf6J8d3elJEOAAAAKo"]
[Mon Jul 20 06:20:19.099169 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQseAAAJTc"]
[Mon Jul 20 06:20:19.369737 2026] [security2:error] [pid 874439:tid 874619] [client 34.74.185.202:63564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Sg46ZSrFvCrJJhtQsjQAAADI"]
[Mon Jul 20 06:20:19.474580 2026] [security2:error] [pid 874439:tid 874614] [client 14.225.17.146:61473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4SgY6ZSrFvCrJJhtQsMQAAAC0"], referer: http://younutrition.gr/wp
[Mon Jul 20 06:20:19.565817 2026] [security2:error] [pid 884009:tid 884148] [client 104.234.53.89:23265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SgxKaHUf6J8d3elJEZgAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:19.675193 2026] [security2:error] [pid 884009:tid 884210] [client 45.157.112.60:33107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SgxKaHUf6J8d3elJEawAAAMo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:19.738814 2026] [security2:error] [pid 884009:tid 884176] [client 14.225.17.146:51728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4SghKaHUf6J8d3elJEJQAAAKg"]
[Mon Jul 20 06:20:19.760444 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:51592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4SghKaHUf6J8d3elJEKAAAAJ0"], referer: http://christiancountytrumpet.com/wp
[Mon Jul 20 06:20:19.761043 2026] [security2:error] [pid 884009:tid 884259] [client 14.225.17.146:52758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SgxKaHUf6J8d3elJEbAAAAPs"], referer: https://wathenbartlett.co.uk/wp
[Mon Jul 20 06:20:19.854886 2026] [security2:error] [pid 884009:tid 884204] [client 34.74.185.202:59537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SgxKaHUf6J8d3elJEdAAAAMQ"]
[Mon Jul 20 06:20:20.055009 2026] [security2:error] [pid 884009:tid 884208] [client 50.116.65.227:50468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ShBKaHUf6J8d3elJEfgAAAMg"]
[Mon Jul 20 06:20:20.066708 2026] [security2:error] [pid 884009:tid 884173] [client 50.116.65.227:50476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ShBKaHUf6J8d3elJEgAAAAKU"]
[Mon Jul 20 06:20:20.099548 2026] [security2:error] [pid 884009:tid 884236] [client 27.96.94.195:37304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEgwAAAOQ"]
[Mon Jul 20 06:20:20.099707 2026] [security2:error] [pid 884009:tid 884236] [client 27.96.94.195:37304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEgwAAAOQ"]
[Mon Jul 20 06:20:20.265550 2026] [security2:error] [pid 884009:tid 884247] [client 171.60.139.123:56377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEigAAAO8"]
[Mon Jul 20 06:20:20.265704 2026] [security2:error] [pid 884009:tid 884247] [client 171.60.139.123:56377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ShBKaHUf6J8d3elJEigAAAO8"]
[Mon Jul 20 06:20:20.624234 2026] [security2:error] [pid 884009:tid 884189] [client 185.132.186.62:58867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-scripts-query.php"] [unique_id "al4ShBKaHUf6J8d3elJEpgAAALU"]
[Mon Jul 20 06:20:20.624854 2026] [security2:error] [pid 884009:tid 884230] [client 50.116.65.227:50504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEmAAAAN4"]
[Mon Jul 20 06:20:20.630402 2026] [security2:error] [pid 874439:tid 874586] [client 34.74.185.202:59980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.balticsteelmgmt.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ShI6ZSrFvCrJJhtQsvgAAABE"]
[Mon Jul 20 06:20:20.708961 2026] [security2:error] [pid 884009:tid 884141] [client 57.141.18.49:23750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SgBKaHUf6J8d3elJD2AAAhmM"]
[Mon Jul 20 06:20:20.741445 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEmgAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:20.757487 2026] [security2:error] [pid 884009:tid 884162] [client 15.237.142.234:34778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ShBKaHUf6J8d3elJErAAAAJs"]
[Mon Jul 20 06:20:20.799963 2026] [security2:error] [pid 884009:tid 884034] [remote 192.241.143.148:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ShBKaHUf6J8d3elJErQAAkRc"]
[Mon Jul 20 06:20:20.816999 2026] [security2:error] [pid 884009:tid 884153] [client 50.116.65.227:50520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEpwAAAJI"]
[Mon Jul 20 06:20:20.927261 2026] [security2:error] [pid 874439:tid 874688] [client 45.116.69.230:64522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ShI6ZSrFvCrJJhtQswgAAAHc"]
[Mon Jul 20 06:20:20.927370 2026] [security2:error] [pid 874439:tid 874688] [client 45.116.69.230:64522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ShI6ZSrFvCrJJhtQswgAAAHc"]
[Mon Jul 20 06:20:21.001441 2026] [security2:error] [pid 884009:tid 884044] [remote 192.241.143.148:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ShRKaHUf6J8d3elJEvwAAvCE"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:20:21.010600 2026] [security2:error] [pid 884009:tid 884184] [client 77.110.127.138:60523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ShRKaHUf6J8d3elJEwQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.010701 2026] [security2:error] [pid 884009:tid 884184] [client 77.110.127.138:60523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ShRKaHUf6J8d3elJEwQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.343498 2026] [security2:error] [pid 884009:tid 884164] [client 50.116.65.227:50530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/11/IMG_2111.jpeg"] [unique_id "al4ShRKaHUf6J8d3elJE3gAAAJ0"]
[Mon Jul 20 06:20:21.373108 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQsggAAJTE"]
[Mon Jul 20 06:20:21.448825 2026] [security2:error] [pid 884009:tid 884154] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJEzwAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.459399 2026] [security2:error] [pid 874439:tid 874490] [remote 57.141.18.12:32188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SgI6ZSrFvCrJJhtQsIAAAOTI"]
[Mon Jul 20 06:20:21.505378 2026] [security2:error] [pid 884009:tid 884175] [client 15.237.142.234:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ShRKaHUf6J8d3elJE7QAAAKc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:20:21.555884 2026] [security2:error] [pid 884009:tid 884218] [client 57.141.18.13:50942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SgBKaHUf6J8d3elJD7wAA0mc"]
[Mon Jul 20 06:20:21.631474 2026] [security2:error] [pid 884009:tid 884259] [client 77.110.127.138:60530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJE0wAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:21.657458 2026] [security2:error] [pid 884009:tid 884230] [client 14.225.17.146:63159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJE7wAAAN4"], referer: http://ivetstrategies.com/wp
[Mon Jul 20 06:20:21.660337 2026] [security2:error] [pid 884009:tid 884191] [client 103.141.108.143:49373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ShRKaHUf6J8d3elJE_QAAALc"]
[Mon Jul 20 06:20:21.660455 2026] [security2:error] [pid 884009:tid 884191] [client 103.141.108.143:49373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ShRKaHUf6J8d3elJE_QAAALc"]
[Mon Jul 20 06:20:21.750456 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQshwAAJSY"]
[Mon Jul 20 06:20:22.065961 2026] [security2:error] [pid 884009:tid 884076] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFJQAA0EE"]
[Mon Jul 20 06:20:22.066148 2026] [security2:error] [pid 884009:tid 884216] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFJQAA0EE"]
[Mon Jul 20 06:20:22.142822 2026] [security2:error] [pid 884009:tid 884258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJFDQAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:22.429552 2026] [security2:error] [pid 884009:tid 884160] [client 185.132.186.89:51765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/item.php"] [unique_id "al4ShhKaHUf6J8d3elJFPgAAAJk"]
[Mon Jul 20 06:20:22.451183 2026] [security2:error] [pid 874439:tid 874606] [client 104.28.251.190:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQsowAAJQE"]
[Mon Jul 20 06:20:22.488245 2026] [security2:error] [pid 884009:tid 884206] [client 178.152.178.232:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFRgAAAMY"]
[Mon Jul 20 06:20:22.495140 2026] [security2:error] [pid 884009:tid 884206] [client 178.152.178.232:36559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFRgAAAMY"]
[Mon Jul 20 06:20:22.535820 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:60535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJFHQAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:22.568950 2026] [security2:error] [pid 884009:tid 884231] [client 181.224.94.124:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFTAAAAN8"]
[Mon Jul 20 06:20:22.569069 2026] [security2:error] [pid 884009:tid 884231] [client 181.224.94.124:63075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4ShhKaHUf6J8d3elJFTAAAAN8"]
[Mon Jul 20 06:20:22.614662 2026] [security2:error] [pid 884009:tid 884218] [client 103.153.183.69:18302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/apache2/apache2.conf"] [unique_id "al4ShhKaHUf6J8d3elJFUQAAANI"], referer: https://t.co/04z1t837ro
[Mon Jul 20 06:20:22.691475 2026] [security2:error] [pid 884009:tid 884250] [client 104.234.53.65:35675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFVQAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:22.755697 2026] [security2:error] [pid 884009:tid 884220] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFPAAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:23.042302 2026] [autoindex:error] [pid 884009:tid 884268] [client 34.85.238.37:51896] AH01276: Cannot serve directory /home2/flhkrvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:23.134059 2026] [security2:error] [pid 884009:tid 884115] [remote 192.241.143.148:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFhAAA42g"]
[Mon Jul 20 06:20:23.296493 2026] [security2:error] [pid 884009:tid 884118] [remote 192.241.143.148:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFjAAA1Gs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:23.317539 2026] [security2:error] [pid 884009:tid 884119] [remote 104.28.251.190:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFiAAAlWw"], referer: https://lifeisbetterlakeside.com/wp-admin/
[Mon Jul 20 06:20:23.321537 2026] [security2:error] [pid 884009:tid 884124] [remote 104.28.251.190:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-login.php"] [unique_id "al4ShxKaHUf6J8d3elJFjgAAlXE"], referer: https://lifeisbetterlakeside.com/wp-admin/
[Mon Jul 20 06:20:23.484802 2026] [security2:error] [pid 884009:tid 884185] [client 171.61.165.146:26690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShxKaHUf6J8d3elJFpAAAALE"]
[Mon Jul 20 06:20:23.484966 2026] [security2:error] [pid 884009:tid 884185] [client 171.61.165.146:26690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4ShxKaHUf6J8d3elJFpAAAALE"]
[Mon Jul 20 06:20:23.633923 2026] [security2:error] [pid 884009:tid 884232] [client 34.85.238.37:51896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.238.85.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "flh.krv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ShxKaHUf6J8d3elJFtQAAAOA"]
[Mon Jul 20 06:20:23.646374 2026] [security2:error] [pid 874439:tid 874540] [remote 57.141.18.21:45734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sgo6ZSrFvCrJJhtQscAAAEGQ"]
[Mon Jul 20 06:20:23.761870 2026] [security2:error] [pid 884009:tid 884154] [client 14.225.17.146:64699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFKwAAAJM"], referer: http://lelandumc.org/wp
[Mon Jul 20 06:20:23.778643 2026] [security2:error] [pid 874439:tid 874630] [client 23.236.222.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4Sg46ZSrFvCrJJhtQsigAAAD0"]
[Mon Jul 20 06:20:23.800018 2026] [security2:error] [pid 884009:tid 884174] [client 34.85.238.37:54936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ShxKaHUf6J8d3elJFugAAAKY"]
[Mon Jul 20 06:20:23.976162 2026] [security2:error] [pid 884009:tid 884227] [client 104.234.53.94:24259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ShxKaHUf6J8d3elJFwwAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:23.987632 2026] [security2:error] [pid 884009:tid 884226] [client 34.85.238.37:54237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ShxKaHUf6J8d3elJFxgAAANo"]
[Mon Jul 20 06:20:24.204906 2026] [security2:error] [pid 884009:tid 884200] [client 34.85.238.37:59257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJF3QAAAMA"]
[Mon Jul 20 06:20:24.242460 2026] [security2:error] [pid 884009:tid 884163] [client 185.132.186.86:52425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/pages.php"] [unique_id "al4SiBKaHUf6J8d3elJF4AAAAJw"]
[Mon Jul 20 06:20:24.493027 2026] [security2:error] [pid 884009:tid 884159] [client 34.85.238.37:57404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJF6QAAAJg"]
[Mon Jul 20 06:20:24.708673 2026] [security2:error] [pid 884009:tid 884248] [client 34.85.238.37:51818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJF-wAAAPA"]
[Mon Jul 20 06:20:24.762934 2026] [security2:error] [pid 884009:tid 884150] [client 57.141.18.13:50958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShBKaHUf6J8d3elJEfQAAjxE"]
[Mon Jul 20 06:20:24.879615 2026] [security2:error] [pid 884009:tid 884213] [client 34.85.238.37:56904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SiBKaHUf6J8d3elJGBwAAAM0"]
[Mon Jul 20 06:20:25.201574 2026] [security2:error] [pid 884009:tid 884235] [client 34.85.238.37:63216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGIAAAAOM"]
[Mon Jul 20 06:20:25.416484 2026] [security2:error] [pid 884009:tid 884266] [client 34.73.38.214:50260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGNAAAAQI"]
[Mon Jul 20 06:20:25.432510 2026] [security2:error] [pid 884009:tid 884210] [client 34.85.238.37:63216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGNwAAAMo"]
[Mon Jul 20 06:20:25.541558 2026] [security2:error] [pid 884009:tid 884250] [client 34.73.38.214:50437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGQwAAAPI"]
[Mon Jul 20 06:20:25.545462 2026] [security2:error] [pid 884009:tid 884259] [client 68.235.52.68:55958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGRAAAAPs"]
[Mon Jul 20 06:20:25.545537 2026] [security2:error] [pid 884009:tid 884259] [client 68.235.52.68:55958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGRAAAAPs"]
[Mon Jul 20 06:20:25.632888 2026] [security2:error] [pid 884009:tid 884186] [client 50.116.65.227:49020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SiRKaHUf6J8d3elJGTAAAALI"]
[Mon Jul 20 06:20:25.644705 2026] [security2:error] [pid 884009:tid 884176] [client 50.116.65.227:50558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4SiRKaHUf6J8d3elJGTQAAAO8"]
[Mon Jul 20 06:20:25.650438 2026] [security2:error] [pid 884009:tid 884204] [client 34.85.238.37:55719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGTgAAAMQ"]
[Mon Jul 20 06:20:25.658044 2026] [security2:error] [pid 884009:tid 884218] [client 112.208.70.94:45634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGTwAAANI"]
[Mon Jul 20 06:20:25.658203 2026] [security2:error] [pid 884009:tid 884218] [client 112.208.70.94:45634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SiRKaHUf6J8d3elJGTwAAANI"]
[Mon Jul 20 06:20:25.658650 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:50498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGUAAAAQQ"]
[Mon Jul 20 06:20:25.698402 2026] [security2:error] [pid 884009:tid 884245] [client 57.141.18.45:53674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJExAAA7R8"]
[Mon Jul 20 06:20:25.714302 2026] [autoindex:error] [pid 884009:tid 884165] [client 146.190.134.17:0] AH01276: Cannot serve directory /home1/nodoqpmy/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:20:25.757126 2026] [security2:error] [pid 884009:tid 884080] [remote 5.161.225.162:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SiRKaHUf6J8d3elJGVAABAUU"]
[Mon Jul 20 06:20:25.804998 2026] [security2:error] [pid 884009:tid 884222] [client 34.73.38.214:50558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGXQAAANY"]
[Mon Jul 20 06:20:25.851130 2026] [security2:error] [pid 884009:tid 884207] [client 34.85.238.37:51353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGYgAAAMc"]
[Mon Jul 20 06:20:25.957088 2026] [security2:error] [pid 884009:tid 884257] [client 34.73.38.214:50606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SiRKaHUf6J8d3elJGZwAAAPk"]
[Mon Jul 20 06:20:26.015771 2026] [security2:error] [pid 884009:tid 884224] [client 34.85.238.37:53461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "flh.krv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGawAAANg"]
[Mon Jul 20 06:20:26.049459 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.57:44817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/module.audio-license.php"] [unique_id "al4SihKaHUf6J8d3elJGbwAAAME"]
[Mon Jul 20 06:20:26.071884 2026] [security2:error] [pid 884009:tid 884225] [client 57.141.18.109:42062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShRKaHUf6J8d3elJE4wAA2S4"]
[Mon Jul 20 06:20:26.074370 2026] [security2:error] [pid 884009:tid 884188] [client 34.73.38.214:50650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGcAAAALQ"]
[Mon Jul 20 06:20:26.200117 2026] [security2:error] [pid 884009:tid 884218] [client 34.73.38.214:50696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGfAAAANI"]
[Mon Jul 20 06:20:26.310499 2026] [security2:error] [pid 884009:tid 884238] [client 34.73.38.214:50739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGiQAAAOY"]
[Mon Jul 20 06:20:26.426416 2026] [security2:error] [pid 884009:tid 884202] [client 34.73.38.214:50772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGlgAAAMI"]
[Mon Jul 20 06:20:26.545030 2026] [security2:error] [pid 884009:tid 884162] [client 34.73.38.214:50800] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGmwAAAJs"]
[Mon Jul 20 06:20:26.651588 2026] [security2:error] [pid 884009:tid 884154] [client 34.73.38.214:50839] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sarahmusica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SihKaHUf6J8d3elJGrAAAAJM"]
[Mon Jul 20 06:20:26.653582 2026] [security2:error] [pid 884009:tid 884118] [remote 157.180.59.124:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.59.180.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4SihKaHUf6J8d3elJGqgAA_Ws"]
[Mon Jul 20 06:20:26.759301 2026] [security2:error] [pid 884009:tid 884120] [remote 5.161.225.162:59630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SihKaHUf6J8d3elJGtgAA-m0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:26.899512 2026] [security2:error] [pid 884009:tid 884133] [remote 157.180.59.124:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.59.180.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4SihKaHUf6J8d3elJGxwAAqno"], referer: https://website-5ab144f7.uritems.net/wp-login.php
[Mon Jul 20 06:20:26.904549 2026] [security2:error] [pid 884009:tid 884206] [client 103.153.183.69:46272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/public../.env"] [unique_id "al4SihKaHUf6J8d3elJGyAAAAMY"], referer: https://www.facebook.com/
[Mon Jul 20 06:20:27.017026 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.80:39436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFNwAA00w"]
[Mon Jul 20 06:20:27.227691 2026] [security2:error] [pid 884009:tid 884207] [client 34.73.38.214:50900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG5gAAAMc"]
[Mon Jul 20 06:20:27.245629 2026] [security2:error] [pid 884009:tid 884241] [client 14.225.17.146:61013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4SiRKaHUf6J8d3elJGYwAAAOk"], referer: http://colinkeyphotography.com/wp
[Mon Jul 20 06:20:27.321873 2026] [core:error] [pid 884009:tid 884258] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:27.321899 2026] [core:error] [pid 884009:tid 884258] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:27.338541 2026] [security2:error] [pid 884009:tid 884212] [client 34.73.38.214:51032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG7QAAAMw"]
[Mon Jul 20 06:20:27.400121 2026] [security2:error] [pid 884009:tid 884268] [client 14.225.17.146:60643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4SihKaHUf6J8d3elJGxQAAAQQ"], referer: http://onewingpictures.com/wp
[Mon Jul 20 06:20:27.458692 2026] [security2:error] [pid 884009:tid 884206] [client 34.73.38.214:51068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG-gAAAMY"]
[Mon Jul 20 06:20:27.575363 2026] [security2:error] [pid 884009:tid 884189] [client 34.73.38.214:51107] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJG_wAAALU"]
[Mon Jul 20 06:20:27.682044 2026] [security2:error] [pid 884009:tid 884171] [client 34.73.38.214:51128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJHDAAAAKM"]
[Mon Jul 20 06:20:27.719728 2026] [security2:error] [pid 884009:tid 884141] [client 57.141.18.125:23096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ShhKaHUf6J8d3elJFcQAAhmA"]
[Mon Jul 20 06:20:27.788416 2026] [security2:error] [pid 884009:tid 884221] [client 34.73.38.214:51154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJHFAAAANU"]
[Mon Jul 20 06:20:27.846052 2026] [security2:error] [pid 884009:tid 884182] [client 185.132.186.67:20791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/classwithtostring.php%20"] [unique_id "al4SixKaHUf6J8d3elJHFgAAAK4"]
[Mon Jul 20 06:20:27.908573 2026] [security2:error] [pid 884009:tid 884258] [client 34.73.38.214:51185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SixKaHUf6J8d3elJHGAAAAPo"]
[Mon Jul 20 06:20:28.021996 2026] [security2:error] [pid 884009:tid 884185] [client 34.73.38.214:51219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SjBKaHUf6J8d3elJHJAAAALE"]
[Mon Jul 20 06:20:28.033684 2026] [security2:error] [pid 884009:tid 884032] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SjBKaHUf6J8d3elJHJQAA7RU"]
[Mon Jul 20 06:20:28.033835 2026] [security2:error] [pid 884009:tid 884245] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SjBKaHUf6J8d3elJHJQAA7RU"]
[Mon Jul 20 06:20:28.158580 2026] [security2:error] [pid 884009:tid 884219] [client 34.73.38.214:51256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.sardimacmillan.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SjBKaHUf6J8d3elJHMQAAANM"]
[Mon Jul 20 06:20:28.186094 2026] [security2:error] [pid 884009:tid 884174] [client 14.225.17.146:54413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4SihKaHUf6J8d3elJGaAAAAKY"], referer: http://worbals.com/wp
[Mon Jul 20 06:20:28.763844 2026] [security2:error] [pid 884009:tid 884194] [client 104.234.53.76:55397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SjBKaHUf6J8d3elJHXwAAALo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:28.802893 2026] [security2:error] [pid 884009:tid 884218] [client 74.7.175.149:40258] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "elite-pk.com"] [uri "/robots.txt"] [unique_id "al4SjBKaHUf6J8d3elJHYgAAANI"]
[Mon Jul 20 06:20:28.985385 2026] [security2:error] [pid 884009:tid 884067] [remote 103.90.234.13:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjBKaHUf6J8d3elJHawAAvjg"]
[Mon Jul 20 06:20:29.308832 2026] [security2:error] [pid 884009:tid 884221] [client 114.119.158.234:47549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mazzucelli.com"] [uri "/pub-type/article"] [unique_id "al4SjRKaHUf6J8d3elJHjgAAANU"], referer: https://mazzucelli.com/pub-type/article/page/1
[Mon Jul 20 06:20:29.321691 2026] [security2:error] [pid 884009:tid 884144] [client 57.141.18.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4SjBKaHUf6J8d3elJHRAAAAIk"]
[Mon Jul 20 06:20:29.409156 2026] [security2:error] [pid 884009:tid 884207] [client 103.153.183.69:46272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/resources../.env"] [unique_id "al4SjRKaHUf6J8d3elJHlwAAAMc"], referer: https://t.co/8upezausu7
[Mon Jul 20 06:20:29.459135 2026] [security2:error] [pid 884009:tid 884050] [remote 103.90.234.13:51842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHnAAA6Sc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:29.497263 2026] [security2:error] [pid 884009:tid 884213] [client 104.234.53.56:39229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SjRKaHUf6J8d3elJHlQAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:29.524017 2026] [security2:error] [pid 884009:tid 884206] [client 103.153.183.69:46272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/etc/passwd"] [unique_id "al4SjRKaHUf6J8d3elJHogAAAMY"], referer: https://www.google.com/
[Mon Jul 20 06:20:29.554691 2026] [security2:error] [pid 884009:tid 884217] [client 52.187.75.220:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SjRKaHUf6J8d3elJHowAAANE"]
[Mon Jul 20 06:20:29.572329 2026] [security2:error] [pid 884009:tid 884257] [client 50.116.65.227:36710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SjRKaHUf6J8d3elJHpwAAAPk"]
[Mon Jul 20 06:20:29.582526 2026] [security2:error] [pid 884009:tid 884179] [client 50.116.65.227:36722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SjRKaHUf6J8d3elJHqgAAAKs"]
[Mon Jul 20 06:20:29.583021 2026] [security2:error] [pid 884009:tid 884159] [client 52.109.68.130:3264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SjRKaHUf6J8d3elJHqAAAAJg"]
[Mon Jul 20 06:20:29.654307 2026] [security2:error] [pid 884009:tid 884221] [client 185.132.186.89:49661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/function.php"] [unique_id "al4SjRKaHUf6J8d3elJHrgAAANU"]
[Mon Jul 20 06:20:29.687530 2026] [security2:error] [pid 884009:tid 884174] [client 104.234.53.56:39229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHsAAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:29.687599 2026] [security2:error] [pid 884009:tid 884097] [remote 152.228.213.32:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHrwAAjFY"]
[Mon Jul 20 06:20:29.733658 2026] [security2:error] [pid 884009:tid 884229] [client 193.148.56.61:63861] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SjRKaHUf6J8d3elJHtwAAAN0"]
[Mon Jul 20 06:20:29.740645 2026] [security2:error] [pid 884009:tid 884167] [client 52.109.68.130:3264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SjRKaHUf6J8d3elJHuAAAAKA"]
[Mon Jul 20 06:20:29.743886 2026] [security2:error] [pid 884009:tid 884197] [client 52.187.75.220:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SjRKaHUf6J8d3elJHuQAAAL0"]
[Mon Jul 20 06:20:29.920553 2026] [security2:error] [pid 884009:tid 884072] [remote 152.228.213.32:36318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SjRKaHUf6J8d3elJHxwAAlj0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:30.135123 2026] [security2:error] [pid 884009:tid 884262] [client 173.252.70.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "darkknightsolutions.com"] [uri "/index.php"] [unique_id "al4SjBKaHUf6J8d3elJHQwAAAP4"]
[Mon Jul 20 06:20:30.807975 2026] [core:error] [pid 884009:tid 884242] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:30.807997 2026] [core:error] [pid 884009:tid 884242] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:30.845087 2026] [security2:error] [pid 884009:tid 884220] [client 27.96.94.195:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFAAAANQ"]
[Mon Jul 20 06:20:30.845202 2026] [security2:error] [pid 884009:tid 884220] [client 27.96.94.195:37624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFAAAANQ"]
[Mon Jul 20 06:20:30.881434 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.125:23114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SiRKaHUf6J8d3elJGUwAAtkc"]
[Mon Jul 20 06:20:30.914696 2026] [security2:error] [pid 884009:tid 884155] [client 171.60.139.123:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFgAAAJQ"]
[Mon Jul 20 06:20:30.914817 2026] [security2:error] [pid 884009:tid 884155] [client 171.60.139.123:56879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SjhKaHUf6J8d3elJIFgAAAJQ"]
[Mon Jul 20 06:20:31.201104 2026] [security2:error] [pid 884009:tid 884180] [client 52.109.108.111:33921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SjxKaHUf6J8d3elJINQAAAKw"]
[Mon Jul 20 06:20:31.360951 2026] [security2:error] [pid 884009:tid 884144] [client 52.109.108.111:33921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SjxKaHUf6J8d3elJIQAAAAIk"]
[Mon Jul 20 06:20:31.381022 2026] [security2:error] [pid 884009:tid 884151] [client 163.172.182.64:32868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4SjxKaHUf6J8d3elJIQgAAAJA"]
[Mon Jul 20 06:20:31.456056 2026] [security2:error] [pid 884009:tid 884240] [client 185.132.186.62:40835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/js/doc.php"] [unique_id "al4SjxKaHUf6J8d3elJIRQAAAOg"]
[Mon Jul 20 06:20:31.803224 2026] [security2:error] [pid 884009:tid 884148] [client 193.148.56.61:49507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SjxKaHUf6J8d3elJIbQAAAI0"]
[Mon Jul 20 06:20:31.836072 2026] [security2:error] [pid 884009:tid 884156] [client 77.110.127.138:60556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SjxKaHUf6J8d3elJIUgAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:31.885987 2026] [security2:error] [pid 884009:tid 884213] [client 216.73.217.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.robiem.com"] [uri "/index.php"] [unique_id "al4SjxKaHUf6J8d3elJIawAAAM0"]
[Mon Jul 20 06:20:32.096552 2026] [security2:error] [pid 884009:tid 884250] [client 57.141.18.20:50480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SihKaHUf6J8d3elJGzQAA8nY"]
[Mon Jul 20 06:20:32.137949 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:65082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIfAAAAPk"]
[Mon Jul 20 06:20:32.138073 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:65082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIfAAAAPk"]
[Mon Jul 20 06:20:32.269952 2026] [security2:error] [pid 884009:tid 884023] [remote 162.19.86.63:35960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4SkBKaHUf6J8d3elJIjQAA9gw"]
[Mon Jul 20 06:20:32.337642 2026] [security2:error] [pid 884009:tid 884256] [client 103.141.108.143:49872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIlwAAAPg"]
[Mon Jul 20 06:20:32.338417 2026] [security2:error] [pid 884009:tid 884256] [client 103.141.108.143:49872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIlwAAAPg"]
[Mon Jul 20 06:20:32.453972 2026] [security2:error] [pid 884009:tid 884065] [remote 162.19.86.63:35960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4SkBKaHUf6J8d3elJImwAA4DY"], referer: https://get.learnthissecret.com/wp-login.php
[Mon Jul 20 06:20:32.674003 2026] [security2:error] [pid 884009:tid 884178] [client 57.141.18.76:23012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SixKaHUf6J8d3elJG-QAAqgg"]
[Mon Jul 20 06:20:32.738238 2026] [security2:error] [pid 884009:tid 884067] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIpQAA2Dg"]
[Mon Jul 20 06:20:32.738403 2026] [security2:error] [pid 884009:tid 884224] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkBKaHUf6J8d3elJIpQAA2Dg"]
[Mon Jul 20 06:20:32.842607 2026] [security2:error] [pid 884009:tid 884188] [client 193.148.56.61:50482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SkBKaHUf6J8d3elJIuQAAALQ"]
[Mon Jul 20 06:20:32.950980 2026] [security2:error] [pid 884009:tid 884153] [client 57.141.18.60:45102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SixKaHUf6J8d3elJHBgAAkhc"]
[Mon Jul 20 06:20:33.113830 2026] [security2:error] [pid 884009:tid 884168] [client 181.224.94.124:21349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SkRKaHUf6J8d3elJIwgAAAKE"]
[Mon Jul 20 06:20:33.113941 2026] [security2:error] [pid 884009:tid 884168] [client 181.224.94.124:21349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SkRKaHUf6J8d3elJIwgAAAKE"]
[Mon Jul 20 06:20:33.159733 2026] [security2:error] [pid 884009:tid 884194] [client 185.132.186.97:41813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/comfunctions.php"] [unique_id "al4SkRKaHUf6J8d3elJIxQAAALo"]
[Mon Jul 20 06:20:33.504995 2026] [security2:error] [pid 884009:tid 884188] [client 34.90.235.227:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.sih.bgd.mybluehost.me"] [uri "/"] [unique_id "al4SkRKaHUf6J8d3elJI4QAAALQ"]
[Mon Jul 20 06:20:33.505071 2026] [security2:error] [pid 884009:tid 884188] [client 34.90.235.227:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.sih.bgd.mybluehost.me"] [uri "/"] [unique_id "al4SkRKaHUf6J8d3elJI4QAAALQ"]
[Mon Jul 20 06:20:33.764273 2026] [security2:error] [pid 884009:tid 884159] [client 50.116.65.227:29314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SkRKaHUf6J8d3elJI9QAAAJg"]
[Mon Jul 20 06:20:33.774598 2026] [security2:error] [pid 884009:tid 884240] [client 50.116.65.227:36758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SkRKaHUf6J8d3elJI9wAAAMo"]
[Mon Jul 20 06:20:33.898012 2026] [security2:error] [pid 884009:tid 884172] [client 193.148.56.61:51722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SkRKaHUf6J8d3elJJBwAAAKQ"]
[Mon Jul 20 06:20:34.394033 2026] [security2:error] [pid 884009:tid 884187] [client 171.61.165.146:31146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkhKaHUf6J8d3elJJKgAAALM"]
[Mon Jul 20 06:20:34.400476 2026] [security2:error] [pid 884009:tid 884187] [client 171.61.165.146:31146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SkhKaHUf6J8d3elJJKgAAALM"]
[Mon Jul 20 06:20:34.764720 2026] [security2:error] [pid 884009:tid 884212] [client 185.132.186.91:40047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-error-module.php"] [unique_id "al4SkhKaHUf6J8d3elJJTwAAAMw"]
[Mon Jul 20 06:20:34.850114 2026] [security2:error] [pid 884009:tid 884137] [remote 57.141.18.50:29218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4SkhKaHUf6J8d3elJJWgAA434"]
[Mon Jul 20 06:20:34.916538 2026] [security2:error] [pid 884009:tid 884183] [client 193.148.56.61:52826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.laceycaraccident.com"] [uri "/wp-content/plugins/wp_nlzxfca/wp_nlzxfca.php"] [unique_id "al4SkhKaHUf6J8d3elJJYAAAAK8"]
[Mon Jul 20 06:20:35.069383 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:60567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkhKaHUf6J8d3elJJRAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.108264 2026] [security2:error] [pid 884009:tid 884211] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkhKaHUf6J8d3elJJRQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.224117 2026] [security2:error] [pid 884009:tid 884202] [client 57.141.18.9:42378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SjRKaHUf6J8d3elJHzgAAwlc"]
[Mon Jul 20 06:20:35.816033 2026] [security2:error] [pid 884009:tid 884215] [client 77.110.127.138:60585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkxKaHUf6J8d3elJJiAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.849186 2026] [security2:error] [pid 884009:tid 884240] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SkxKaHUf6J8d3elJJjQAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:35.962672 2026] [security2:error] [pid 884009:tid 884156] [client 158.173.89.95:36683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SkxKaHUf6J8d3elJJpgAAAJU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:36.063151 2026] [core:error] [pid 884009:tid 884056] [remote 157.55.39.225:2664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:36.063171 2026] [core:error] [pid 884009:tid 884056] [remote 157.55.39.225:2664] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:36.380788 2026] [security2:error] [pid 884009:tid 884154] [client 185.132.186.61:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/adminfus.php"] [unique_id "al4SlBKaHUf6J8d3elJJyQAAAJM"]
[Mon Jul 20 06:20:36.577304 2026] [security2:error] [pid 884009:tid 884225] [client 41.173.37.102:5809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ2gAAANk"]
[Mon Jul 20 06:20:36.577500 2026] [security2:error] [pid 884009:tid 884225] [client 41.173.37.102:5809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ2gAAANk"]
[Mon Jul 20 06:20:36.705939 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:60593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlBKaHUf6J8d3elJJ0QAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:36.734129 2026] [security2:error] [pid 884009:tid 884189] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlBKaHUf6J8d3elJJ0gAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:36.790685 2026] [security2:error] [pid 884009:tid 884245] [client 36.68.54.12:7029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.54.68.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ7gAAAO0"]
[Mon Jul 20 06:20:36.790884 2026] [security2:error] [pid 884009:tid 884245] [client 36.68.54.12:7029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4SlBKaHUf6J8d3elJJ7gAAAO0"]
[Mon Jul 20 06:20:36.986898 2026] [security2:error] [pid 884009:tid 884057] [remote 57.141.18.125:53368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4SlBKaHUf6J8d3elJJ_wAAhS4"]
[Mon Jul 20 06:20:37.015902 2026] [security2:error] [pid 884009:tid 884184] [client 74.208.214.194:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SlRKaHUf6J8d3elJKAQAAALA"]
[Mon Jul 20 06:20:37.193524 2026] [proxy:error] [pid 884009:tid 884267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.193555 2026] [proxy_http:error] [pid 884009:tid 884267] [client 94.154.43.185:39990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.193992 2026] [proxy:error] [pid 884009:tid 884267] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.194015 2026] [proxy_http:error] [pid 884009:tid 884267] [client 94.154.43.185:39990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.212955 2026] [proxy:error] [pid 884009:tid 884212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.213012 2026] [proxy_http:error] [pid 884009:tid 884212] [client 94.154.43.179:23140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.213628 2026] [proxy:error] [pid 884009:tid 884212] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:20:37.213660 2026] [proxy_http:error] [pid 884009:tid 884212] [client 94.154.43.179:23140] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:20:37.272308 2026] [security2:error] [pid 884009:tid 884208] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlRKaHUf6J8d3elJKCgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:37.299990 2026] [security2:error] [pid 884009:tid 884246] [client 77.110.127.138:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SlRKaHUf6J8d3elJKCwAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:37.487840 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.82:54330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SkBKaHUf6J8d3elJIswAAtjs"]
[Mon Jul 20 06:20:37.537622 2026] [security2:error] [pid 884009:tid 884250] [client 57.141.18.91:34268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SkBKaHUf6J8d3elJItwAA8kU"]
[Mon Jul 20 06:20:37.562068 2026] [security2:error] [pid 884009:tid 884266] [client 74.208.214.194:56122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SlRKaHUf6J8d3elJKSwAAAQI"]
[Mon Jul 20 06:20:37.982964 2026] [security2:error] [pid 884009:tid 884145] [client 185.132.186.70:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/adminfus.php"] [unique_id "al4SlRKaHUf6J8d3elJKawAAAIo"]
[Mon Jul 20 06:20:38.139467 2026] [security2:error] [pid 884009:tid 884165] [client 112.208.70.94:42071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKcQAAAJ4"]
[Mon Jul 20 06:20:38.139577 2026] [security2:error] [pid 884009:tid 884165] [client 112.208.70.94:42071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKcQAAAJ4"]
[Mon Jul 20 06:20:38.646872 2026] [security2:error] [pid 884009:tid 884011] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKkgAAvwA"]
[Mon Jul 20 06:20:38.647068 2026] [security2:error] [pid 884009:tid 884199] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SlhKaHUf6J8d3elJKkgAAvwA"]
[Mon Jul 20 06:20:38.675546 2026] [security2:error] [pid 884009:tid 884015] [remote 124.55.178.99:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SlhKaHUf6J8d3elJKlAAAjQQ"]
[Mon Jul 20 06:20:39.091199 2026] [security2:error] [pid 884009:tid 884018] [remote 124.55.178.99:44744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SlxKaHUf6J8d3elJKswAAoAc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:39.165320 2026] [security2:error] [pid 884009:tid 884140] [client 50.116.65.227:52882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SlxKaHUf6J8d3elJKtQAAAIU"]
[Mon Jul 20 06:20:39.175919 2026] [security2:error] [pid 884009:tid 884155] [client 50.116.65.227:52886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SlxKaHUf6J8d3elJKuAAAAJQ"]
[Mon Jul 20 06:20:39.619603 2026] [security2:error] [pid 884009:tid 884198] [client 185.132.186.71:20719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/litespeed.php"] [unique_id "al4SlxKaHUf6J8d3elJKzgAAAL4"]
[Mon Jul 20 06:20:39.712172 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SlxKaHUf6J8d3elJKzAAAANM"]
[Mon Jul 20 06:20:39.963402 2026] [security2:error] [pid 884009:tid 884200] [client 57.141.18.88:50814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SkxKaHUf6J8d3elJJewAAwBo"]
[Mon Jul 20 06:20:40.436943 2026] [security2:error] [pid 884009:tid 884261] [client 77.110.127.138:60627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmBKaHUf6J8d3elJK9QAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:40.476638 2026] [security2:error] [pid 884009:tid 884224] [client 45.95.169.104:25698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SmBKaHUf6J8d3elJLEQAAANg"]
[Mon Jul 20 06:20:40.554769 2026] [security2:error] [pid 884009:tid 884039] [remote 20.153.140.50:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SmBKaHUf6J8d3elJLFgABAhw"]
[Mon Jul 20 06:20:40.864222 2026] [security2:error] [pid 884009:tid 884170] [client 57.141.18.90:38528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlBKaHUf6J8d3elJJwgAAoj4"]
[Mon Jul 20 06:20:40.956638 2026] [security2:error] [pid 884009:tid 884084] [remote 20.153.140.50:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SmBKaHUf6J8d3elJLOQAAoEk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:41.228226 2026] [security2:error] [pid 884009:tid 884174] [client 185.132.186.96:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/images/as.php"] [unique_id "al4SmRKaHUf6J8d3elJLSwAAAKY"]
[Mon Jul 20 06:20:41.338302 2026] [security2:error] [pid 884009:tid 884189] [client 77.110.127.138:60656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmRKaHUf6J8d3elJLQgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:41.666820 2026] [security2:error] [pid 884009:tid 884222] [client 98.92.1.119:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4SmBKaHUf6J8d3elJLIAAAANY"]
[Mon Jul 20 06:20:41.699270 2026] [security2:error] [pid 884009:tid 884232] [client 98.92.1.119:26852] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/ensalada-de-coditos-puerto-rican-macaroni-salad/"] [unique_id "al4SmBKaHUf6J8d3elJLGwAAAOA"]
[Mon Jul 20 06:20:41.735782 2026] [security2:error] [pid 884009:tid 884168] [client 171.60.139.123:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLcgAAAKE"]
[Mon Jul 20 06:20:41.735911 2026] [security2:error] [pid 884009:tid 884168] [client 171.60.139.123:57391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLcgAAAKE"]
[Mon Jul 20 06:20:41.751229 2026] [security2:error] [pid 884009:tid 884257] [client 27.96.94.195:36896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLdAAAAPk"]
[Mon Jul 20 06:20:41.751358 2026] [security2:error] [pid 884009:tid 884257] [client 27.96.94.195:36896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SmRKaHUf6J8d3elJLdAAAAPk"]
[Mon Jul 20 06:20:41.771696 2026] [security2:error] [pid 884009:tid 884265] [client 77.110.127.138:60666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmRKaHUf6J8d3elJLZAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:41.942929 2026] [security2:error] [pid 884009:tid 884149] [client 50.116.65.227:36256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SmRKaHUf6J8d3elJLiAAAAI4"]
[Mon Jul 20 06:20:41.956081 2026] [security2:error] [pid 884009:tid 884191] [client 50.116.65.227:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4SmRKaHUf6J8d3elJLiwAAALc"]
[Mon Jul 20 06:20:42.032098 2026] [security2:error] [pid 884009:tid 884205] [client 57.141.18.87:42678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlRKaHUf6J8d3elJKMgAAxVU"]
[Mon Jul 20 06:20:42.072556 2026] [security2:error] [pid 884009:tid 884117] [remote 57.141.18.2:21496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3688465"] [unique_id "al4SmhKaHUf6J8d3elJLlAAAyGo"]
[Mon Jul 20 06:20:42.265462 2026] [security2:error] [pid 884009:tid 884163] [client 103.153.183.69:23316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../etc/ssh/sshd_config"] [unique_id "al4SmhKaHUf6J8d3elJLmQAAAJw"], referer: https://www.google.com/
[Mon Jul 20 06:20:42.293091 2026] [security2:error] [pid 884009:tid 884161] [client 103.153.183.69:23316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../root/.ssh/id_rsa"] [unique_id "al4SmhKaHUf6J8d3elJLnQAAAJo"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:20:42.330120 2026] [security2:error] [pid 884009:tid 884184] [client 77.110.127.138:60675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmRKaHUf6J8d3elJLjQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:42.804217 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SmhKaHUf6J8d3elJLvgAAAPI"]
[Mon Jul 20 06:20:42.804325 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:49227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SmhKaHUf6J8d3elJLvgAAAPI"]
[Mon Jul 20 06:20:42.848302 2026] [security2:error] [pid 884009:tid 884198] [client 77.110.127.138:60683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLtgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:42.854428 2026] [security2:error] [pid 884009:tid 884222] [client 185.132.186.87:43331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/setup-config.php"] [unique_id "al4SmhKaHUf6J8d3elJLwwAAANY"]
[Mon Jul 20 06:20:43.028177 2026] [security2:error] [pid 884009:tid 884231] [client 103.141.108.143:50355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL3gAAAN8"]
[Mon Jul 20 06:20:43.028264 2026] [security2:error] [pid 884009:tid 884231] [client 103.141.108.143:50355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL3gAAAN8"]
[Mon Jul 20 06:20:43.112217 2026] [security2:error] [pid 884009:tid 884265] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLowAAAQE"]
[Mon Jul 20 06:20:43.349325 2026] [security2:error] [pid 884009:tid 884045] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL7gAAxCI"]
[Mon Jul 20 06:20:43.349442 2026] [security2:error] [pid 884009:tid 884204] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJL7gAAxCI"]
[Mon Jul 20 06:20:43.364167 2026] [security2:error] [pid 884009:tid 884206] [client 57.141.18.41:43074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlhKaHUf6J8d3elJKrAAAxhI"]
[Mon Jul 20 06:20:43.665989 2026] [security2:error] [pid 884009:tid 884195] [client 181.224.94.124:26761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMCwAAALs"]
[Mon Jul 20 06:20:43.666114 2026] [security2:error] [pid 884009:tid 884195] [client 181.224.94.124:26761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMCwAAALs"]
[Mon Jul 20 06:20:43.763648 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:60699] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4SmxKaHUf6J8d3elJMDgAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:43.884226 2026] [security2:error] [pid 884009:tid 884158] [client 178.152.178.232:36563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMGQAAAJc"]
[Mon Jul 20 06:20:43.884335 2026] [security2:error] [pid 884009:tid 884158] [client 178.152.178.232:36563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SmxKaHUf6J8d3elJMGQAAAJc"]
[Mon Jul 20 06:20:43.946454 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.62:27152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SlxKaHUf6J8d3elJKxwAAthQ"]
[Mon Jul 20 06:20:44.227070 2026] [security2:error] [pid 884009:tid 884043] [remote 162.19.86.63:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMPQAAyyA"]
[Mon Jul 20 06:20:44.392687 2026] [security2:error] [pid 884009:tid 884071] [remote 217.61.143.92:43858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnBKaHUf6J8d3elJMRwAA9jw"]
[Mon Jul 20 06:20:44.392887 2026] [security2:error] [pid 884009:tid 884254] [client 217.61.143.92:43858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnBKaHUf6J8d3elJMRwAA9jw"]
[Mon Jul 20 06:20:44.419849 2026] [core:error] [pid 884009:tid 884263] [client 14.225.17.146:50357] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wp
[Mon Jul 20 06:20:44.419881 2026] [core:error] [pid 884009:tid 884263] [client 14.225.17.146:50357] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Wp
[Mon Jul 20 06:20:44.443874 2026] [security2:error] [pid 884009:tid 884039] [remote 162.19.86.63:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMUAAAxBw"], referer: https://oldracelimited.com/wp-login.php
[Mon Jul 20 06:20:44.456490 2026] [security2:error] [pid 884009:tid 884159] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SnBKaHUf6J8d3elJMQgAAAJg"]
[Mon Jul 20 06:20:44.474593 2026] [security2:error] [pid 884009:tid 884227] [client 185.132.186.95:60411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/alam.php"] [unique_id "al4SnBKaHUf6J8d3elJMUgAAANs"]
[Mon Jul 20 06:20:44.568983 2026] [security2:error] [pid 884009:tid 884258] [client 57.141.18.66:29358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmBKaHUf6J8d3elJK-QAA-g4"]
[Mon Jul 20 06:20:44.639246 2026] [security2:error] [pid 884009:tid 884207] [client 104.234.53.80:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMWQAAAMc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:44.848974 2026] [security2:error] [pid 884009:tid 884176] [client 158.173.166.181:38087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SnBKaHUf6J8d3elJMawAAAKg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:20:44.915950 2026] [security2:error] [pid 884009:tid 884227] [client 45.95.169.104:23362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMbwAAANs"]
[Mon Jul 20 06:20:44.934877 2026] [security2:error] [pid 884009:tid 884084] [remote 97.74.87.194:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SnBKaHUf6J8d3elJMcAAAqkk"]
[Mon Jul 20 06:20:45.319982 2026] [security2:error] [pid 884009:tid 884074] [remote 97.74.87.194:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SnRKaHUf6J8d3elJMlQAAjj8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:20:45.386947 2026] [security2:error] [pid 884009:tid 884204] [client 171.61.165.146:30990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SnRKaHUf6J8d3elJMnQAAAMQ"]
[Mon Jul 20 06:20:45.387062 2026] [security2:error] [pid 884009:tid 884204] [client 171.61.165.146:30990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SnRKaHUf6J8d3elJMnQAAAMQ"]
[Mon Jul 20 06:20:45.839522 2026] [security2:error] [pid 884009:tid 884153] [client 14.225.17.146:50662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4SnRKaHUf6J8d3elJMmwAAAJI"], referer: http://backandneckpainrelieflaceychiropractor.com/Wp
[Mon Jul 20 06:20:45.876879 2026] [security2:error] [pid 884009:tid 884093] [remote 100.42.189.89:43252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4SnRKaHUf6J8d3elJMzAAAzFI"]
[Mon Jul 20 06:20:46.091070 2026] [security2:error] [pid 884009:tid 884194] [client 185.132.186.87:44809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/cong.php"] [unique_id "al4SnhKaHUf6J8d3elJM6wAAALo"]
[Mon Jul 20 06:20:46.177548 2026] [security2:error] [pid 884009:tid 884185] [client 186.194.46.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4SnRKaHUf6J8d3elJMwwAAALE"]
[Mon Jul 20 06:20:46.214354 2026] [security2:error] [pid 884009:tid 884138] [remote 100.42.189.89:43252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4SnhKaHUf6J8d3elJM9gAAjX8"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:20:46.245644 2026] [security2:error] [pid 884009:tid 884225] [client 14.225.17.146:50606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4SnRKaHUf6J8d3elJM1gAAANk"], referer: http://mrbambooplus.com/Wp
[Mon Jul 20 06:20:46.459063 2026] [security2:error] [pid 884009:tid 884143] [client 57.141.18.25:32236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLkwAAiEQ"]
[Mon Jul 20 06:20:46.517309 2026] [security2:error] [pid 884009:tid 884127] [remote 103.255.134.61:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SnhKaHUf6J8d3elJNBgAAn3Q"]
[Mon Jul 20 06:20:46.567873 2026] [security2:error] [pid 884009:tid 884237] [client 57.141.18.19:33842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLmgAA5VE"]
[Mon Jul 20 06:20:46.579880 2026] [security2:error] [pid 884009:tid 884029] [remote 20.153.140.50:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnhKaHUf6J8d3elJNEAAAohI"]
[Mon Jul 20 06:20:46.580033 2026] [security2:error] [pid 884009:tid 884170] [client 20.153.140.50:49542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SnhKaHUf6J8d3elJNEAAAohI"]
[Mon Jul 20 06:20:46.817622 2026] [security2:error] [pid 884009:tid 884168] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4SnhKaHUf6J8d3elJNLAAAAKE"], referer: https://www.reddit.com/
[Mon Jul 20 06:20:47.082147 2026] [security2:error] [pid 884009:tid 884220] [client 57.141.18.33:34880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLzAAA1GQ"]
[Mon Jul 20 06:20:47.094491 2026] [security2:error] [pid 884009:tid 884114] [remote 103.255.134.61:44394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4SnxKaHUf6J8d3elJNOAAApWc"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:20:47.161659 2026] [security2:error] [pid 884009:tid 884161] [client 57.141.18.117:62902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmhKaHUf6J8d3elJLzQAAmlc"]
[Mon Jul 20 06:20:47.224016 2026] [security2:error] [pid 884009:tid 884239] [client 41.173.37.102:6738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNQAAAAOc"]
[Mon Jul 20 06:20:47.224124 2026] [security2:error] [pid 884009:tid 884239] [client 41.173.37.102:6738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNQAAAAOc"]
[Mon Jul 20 06:20:47.567652 2026] [security2:error] [pid 884009:tid 884162] [client 104.234.53.90:43847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNXQAAAJs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:47.699298 2026] [security2:error] [pid 884009:tid 884161] [client 185.132.186.93:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/block-bindings/imagess.php"] [unique_id "al4SnxKaHUf6J8d3elJNbQAAAJo"]
[Mon Jul 20 06:20:47.699581 2026] [security2:error] [pid 884009:tid 884039] [remote 152.228.213.32:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4SnxKaHUf6J8d3elJNagAAwhw"]
[Mon Jul 20 06:20:47.752989 2026] [security2:error] [pid 884009:tid 884243] [client 14.225.17.146:64226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNSAAAAOs"], referer: http://overloadcomedy.com/Wp
[Mon Jul 20 06:20:47.905275 2026] [security2:error] [pid 884009:tid 884081] [remote 152.228.213.32:37132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4SnxKaHUf6J8d3elJNjgAAokY"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 06:20:47.934955 2026] [security2:error] [pid 884009:tid 884156] [client 68.235.52.68:47784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNkwAAAJU"]
[Mon Jul 20 06:20:47.935058 2026] [security2:error] [pid 884009:tid 884156] [client 68.235.52.68:47784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4SnxKaHUf6J8d3elJNkwAAAJU"]
[Mon Jul 20 06:20:47.970316 2026] [security2:error] [pid 884009:tid 884208] [client 77.110.127.138:60743] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4SnxKaHUf6J8d3elJNmQAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:48.046106 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.108:56054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SmxKaHUf6J8d3elJMIAAAwTo"]
[Mon Jul 20 06:20:48.181725 2026] [security2:error] [pid 884009:tid 884077] [remote 38.242.157.30:33122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4SoBKaHUf6J8d3elJNqQAA40I"]
[Mon Jul 20 06:20:48.193117 2026] [security2:error] [pid 884009:tid 884203] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNYQAAAMM"]
[Mon Jul 20 06:20:48.365351 2026] [security2:error] [pid 884009:tid 884122] [remote 38.242.157.30:33122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4SoBKaHUf6J8d3elJNuAAA528"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:20:48.555512 2026] [security2:error] [pid 884009:tid 884251] [client 136.107.64.51:52148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4SnBKaHUf6J8d3elJMMAAAAPM"]
[Mon Jul 20 06:20:48.669506 2026] [security2:error] [pid 884009:tid 884219] [client 136.107.64.51:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SoBKaHUf6J8d3elJNyQAAANM"]
[Mon Jul 20 06:20:48.807039 2026] [security2:error] [pid 884009:tid 884170] [client 77.110.127.138:60752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4SoBKaHUf6J8d3elJN1gAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:49.048992 2026] [security2:error] [pid 884009:tid 884222] [client 57.141.18.16:38868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnRKaHUf6J8d3elJMfQAA1mk"]
[Mon Jul 20 06:20:49.182693 2026] [security2:error] [pid 884009:tid 884174] [client 136.107.64.51:56199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SoRKaHUf6J8d3elJN8QAAAKY"]
[Mon Jul 20 06:20:49.266059 2026] [security2:error] [pid 884009:tid 884015] [remote 182.77.62.24:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SoRKaHUf6J8d3elJN-QAA9wQ"]
[Mon Jul 20 06:20:49.293721 2026] [security2:error] [pid 884009:tid 884011] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SoRKaHUf6J8d3elJN_wAA0wA"]
[Mon Jul 20 06:20:49.294040 2026] [security2:error] [pid 884009:tid 884219] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SoRKaHUf6J8d3elJN_wAA0wA"]
[Mon Jul 20 06:20:49.312165 2026] [security2:error] [pid 884009:tid 884223] [client 185.132.186.72:62347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/pwnd/adminfus.php"] [unique_id "al4SoRKaHUf6J8d3elJOBAAAANc"]
[Mon Jul 20 06:20:49.793779 2026] [security2:error] [pid 884009:tid 884051] [remote 182.77.62.24:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4SoRKaHUf6J8d3elJOOAAA_Cg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:20:49.796546 2026] [security2:error] [pid 884009:tid 884182] [client 136.107.64.51:53679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SoRKaHUf6J8d3elJOOgAAAK4"]
[Mon Jul 20 06:20:49.811473 2026] [security2:error] [pid 884009:tid 884184] [client 57.141.18.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SoRKaHUf6J8d3elJOLgAAALA"]
[Mon Jul 20 06:20:49.843157 2026] [security2:error] [pid 884009:tid 884219] [client 50.116.65.227:34196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SoRKaHUf6J8d3elJOOwAAANM"]
[Mon Jul 20 06:20:49.856912 2026] [security2:error] [pid 884009:tid 884158] [client 50.116.65.227:34198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SoRKaHUf6J8d3elJOPAAAAJc"]
[Mon Jul 20 06:20:50.020993 2026] [security2:error] [pid 884009:tid 884179] [client 15.204.80.170:51048] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "gearwaterproof.com"] [uri "/"] [unique_id "al4SohKaHUf6J8d3elJORgAAAKs"]
[Mon Jul 20 06:20:50.030062 2026] [security2:error] [pid 884009:tid 884247] [client 57.141.18.55:56772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnhKaHUf6J8d3elJM8QAA72A"]
[Mon Jul 20 06:20:50.038971 2026] [security2:error] [pid 884009:tid 884253] [client 57.141.18.2:59346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnhKaHUf6J8d3elJM8wAA9XU"]
[Mon Jul 20 06:20:50.062412 2026] [security2:error] [pid 884009:tid 884173] [client 14.225.17.146:62440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4SoRKaHUf6J8d3elJOQAAAAKU"], referer: http://aberballet.co.uk/Wp
[Mon Jul 20 06:20:50.170009 2026] [security2:error] [pid 884009:tid 884143] [client 112.208.70.94:42516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SohKaHUf6J8d3elJOVAAAAIg"]
[Mon Jul 20 06:20:50.170209 2026] [security2:error] [pid 884009:tid 884143] [client 112.208.70.94:42516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SohKaHUf6J8d3elJOVAAAAIg"]
[Mon Jul 20 06:20:50.284964 2026] [security2:error] [pid 884009:tid 884242] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/etc/passwd"] [unique_id "al4SohKaHUf6J8d3elJOXwAAAOo"], referer: https://twitter.com/
[Mon Jul 20 06:20:50.293243 2026] [security2:error] [pid 884009:tid 884149] [client 50.116.65.227:34166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4SoRKaHUf6J8d3elJN9wAAAI4"]
[Mon Jul 20 06:20:50.408841 2026] [security2:error] [pid 884009:tid 884187] [client 57.141.18.107:63688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnhKaHUf6J8d3elJNFAAAsyI"]
[Mon Jul 20 06:20:50.431511 2026] [security2:error] [pid 884009:tid 884175] [client 14.225.17.146:62314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJN4QAAAKc"], referer: http://phillipbloch.com/Wp
[Mon Jul 20 06:20:50.489177 2026] [security2:error] [pid 884009:tid 884163] [client 14.225.17.146:50608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJN1QAAAJw"], referer: http://nurturemarple.co.uk/Wp
[Mon Jul 20 06:20:50.499513 2026] [security2:error] [pid 884009:tid 884245] [client 136.107.64.51:50613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SohKaHUf6J8d3elJOdwAAAO0"]
[Mon Jul 20 06:20:50.672687 2026] [security2:error] [pid 884009:tid 884252] [client 14.225.17.146:55978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOdQAAAPQ"], referer: http://margaretspeckogawa.com/Wp
[Mon Jul 20 06:20:50.676660 2026] [security2:error] [pid 884009:tid 884172] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOUQAAAKQ"]
[Mon Jul 20 06:20:50.835878 2026] [security2:error] [pid 884009:tid 884151] [client 50.116.65.227:49452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4SohKaHUf6J8d3elJOlAAAAJA"]
[Mon Jul 20 06:20:50.847789 2026] [security2:error] [pid 884009:tid 884210] [client 50.116.65.227:34264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4SohKaHUf6J8d3elJOlgAAAMo"]
[Mon Jul 20 06:20:50.853950 2026] [security2:error] [pid 884009:tid 884233] [client 57.141.18.105:22738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SnxKaHUf6J8d3elJNNQAA4RQ"]
[Mon Jul 20 06:20:50.897213 2026] [security2:error] [pid 884009:tid 884263] [client 50.116.65.227:34240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOYgAAAP8"]
[Mon Jul 20 06:20:50.915220 2026] [security2:error] [pid 884009:tid 884160] [client 136.107.64.51:61261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SohKaHUf6J8d3elJOnQAAAJk"]
[Mon Jul 20 06:20:50.930867 2026] [security2:error] [pid 884009:tid 884071] [remote 147.50.252.213:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SohKaHUf6J8d3elJOoAABBDw"]
[Mon Jul 20 06:20:50.935866 2026] [security2:error] [pid 884009:tid 884192] [client 185.132.186.61:47159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/default-filters-edit.php"] [unique_id "al4SohKaHUf6J8d3elJOogAAALg"]
[Mon Jul 20 06:20:51.016763 2026] [security2:error] [pid 884009:tid 884190] [client 50.116.65.227:34252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOgAAAALY"]
[Mon Jul 20 06:20:51.224278 2026] [security2:error] [pid 884009:tid 884191] [client 50.116.65.227:34274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SoxKaHUf6J8d3elJOrAAAALc"]
[Mon Jul 20 06:20:51.398542 2026] [security2:error] [pid 884009:tid 884233] [client 136.107.64.51:57093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SoxKaHUf6J8d3elJOzgAAAOE"]
[Mon Jul 20 06:20:51.408899 2026] [core:error] [pid 884009:tid 884239] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.408922 2026] [core:error] [pid 884009:tid 884239] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.411790 2026] [core:error] [pid 884009:tid 884254] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.411816 2026] [core:error] [pid 884009:tid 884254] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:51.433968 2026] [security2:error] [pid 884009:tid 884196] [client 14.225.17.146:55753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4SoxKaHUf6J8d3elJOuAAAALw"], referer: https://nurturemarple.co.uk/Wp
[Mon Jul 20 06:20:51.436354 2026] [security2:error] [pid 884009:tid 884046] [remote 147.50.252.213:55788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO1AAA5SM"], referer: https://amalia-capital.com/wp-login.php
[Mon Jul 20 06:20:51.466895 2026] [security2:error] [pid 884009:tid 884184] [client 14.225.17.146:55764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4SoxKaHUf6J8d3elJOtwAAALA"], referer: http://dadanetnet.net/Wp
[Mon Jul 20 06:20:51.570836 2026] [security2:error] [pid 884009:tid 884053] [remote 81.173.115.7:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO4gAAwyo"]
[Mon Jul 20 06:20:51.767736 2026] [security2:error] [pid 884009:tid 884064] [remote 81.173.115.7:45612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO7QAA5zU"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:20:51.772383 2026] [security2:error] [pid 884009:tid 884220] [client 136.107.64.51:53826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SoxKaHUf6J8d3elJO7wAAANQ"]
[Mon Jul 20 06:20:51.778785 2026] [security2:error] [pid 884009:tid 884097] [remote 167.233.114.32:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJO7gAA6lY"]
[Mon Jul 20 06:20:51.801036 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:60785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4SoxKaHUf6J8d3elJO9QAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:51.812425 2026] [security2:error] [pid 884009:tid 884217] [client 57.141.18.91:44892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJNmwAA0Vw"]
[Mon Jul 20 06:20:51.902933 2026] [security2:error] [pid 884009:tid 884072] [remote 173.212.252.15:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SoxKaHUf6J8d3elJPCwAAzj0"]
[Mon Jul 20 06:20:52.040434 2026] [security2:error] [pid 884009:tid 884220] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4SpBKaHUf6J8d3elJPGwAAANQ"], referer: https://twitter.com/
[Mon Jul 20 06:20:52.102950 2026] [security2:error] [pid 884009:tid 884121] [remote 167.233.114.32:57692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SpBKaHUf6J8d3elJPHQAA4G4"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:52.163968 2026] [security2:error] [pid 884009:tid 884179] [client 136.107.64.51:59932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SpBKaHUf6J8d3elJPIQAAAKs"]
[Mon Jul 20 06:20:52.361837 2026] [security2:error] [pid 884009:tid 884117] [remote 173.212.252.15:46420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4SpBKaHUf6J8d3elJPKgAAzmo"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:20:52.402205 2026] [security2:error] [pid 884009:tid 884216] [client 104.234.53.90:50539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SpBKaHUf6J8d3elJPMAAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:52.429933 2026] [security2:error] [pid 884009:tid 884266] [client 57.141.18.45:30994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SoBKaHUf6J8d3elJN0QABAlg"]
[Mon Jul 20 06:20:52.502122 2026] [security2:error] [pid 884009:tid 884255] [client 171.60.139.123:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SpBKaHUf6J8d3elJPPQAAAPc"]
[Mon Jul 20 06:20:52.502297 2026] [security2:error] [pid 884009:tid 884255] [client 171.60.139.123:57896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SpBKaHUf6J8d3elJPPQAAAPc"]
[Mon Jul 20 06:20:52.541109 2026] [security2:error] [pid 884009:tid 884223] [client 136.107.64.51:59098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SpBKaHUf6J8d3elJPPwAAANc"]
[Mon Jul 20 06:20:52.545065 2026] [security2:error] [pid 884009:tid 884212] [client 185.132.186.94:30463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/install.php"] [unique_id "al4SpBKaHUf6J8d3elJPQAAAAMw"]
[Mon Jul 20 06:20:52.569482 2026] [security2:error] [pid 884009:tid 884239] [client 103.153.183.69:60670] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/.env"] [unique_id "al4SpBKaHUf6J8d3elJPQQAAAOc"], referer: https://www.bing.com/search?q=n2iwn9
[Mon Jul 20 06:20:52.619828 2026] [security2:error] [pid 884009:tid 884227] [client 77.110.127.138:60796] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4SpBKaHUf6J8d3elJPQwAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:52.795721 2026] [security2:error] [pid 884009:tid 884156] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SpBKaHUf6J8d3elJPFwAAAJU"]
[Mon Jul 20 06:20:52.930822 2026] [security2:error] [pid 884009:tid 884207] [client 136.107.64.51:52501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SpBKaHUf6J8d3elJPXAAAAMc"]
[Mon Jul 20 06:20:53.084642 2026] [security2:error] [pid 884009:tid 884157] [client 104.234.53.63:32443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SpBKaHUf6J8d3elJPXgAAAJY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:53.443323 2026] [security2:error] [pid 884009:tid 884170] [client 136.107.64.51:58718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "sergebrunstinteriors.twz.oin.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SpRKaHUf6J8d3elJPgAAAAKI"]
[Mon Jul 20 06:20:53.559466 2026] [security2:error] [pid 884009:tid 884254] [client 45.116.69.230:49789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPhgAAAPY"]
[Mon Jul 20 06:20:53.559606 2026] [security2:error] [pid 884009:tid 884254] [client 45.116.69.230:49789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPhgAAAPY"]
[Mon Jul 20 06:20:53.562694 2026] [security2:error] [pid 884009:tid 884163] [client 104.234.53.63:32443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SpRKaHUf6J8d3elJPhwAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:53.619397 2026] [security2:error] [pid 884009:tid 884262] [client 103.141.108.143:50828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPjwAAAP4"]
[Mon Jul 20 06:20:53.620196 2026] [security2:error] [pid 884009:tid 884262] [client 103.141.108.143:50828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPjwAAAP4"]
[Mon Jul 20 06:20:53.669522 2026] [security2:error] [pid 884009:tid 884184] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPZwAAsBM"], referer: http://ardhalwafaa.com/Wp
[Mon Jul 20 06:20:53.695482 2026] [core:error] [pid 884009:tid 884210] [client 14.225.17.146:61822] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:53.695512 2026] [core:error] [pid 884009:tid 884210] [client 14.225.17.146:61822] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:20:53.874698 2026] [security2:error] [pid 884009:tid 884148] [client 57.141.18.103:63608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SohKaHUf6J8d3elJOWwAAjWQ"]
[Mon Jul 20 06:20:53.944924 2026] [security2:error] [pid 884009:tid 884061] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPqwAArDI"]
[Mon Jul 20 06:20:53.945151 2026] [security2:error] [pid 884009:tid 884180] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SpRKaHUf6J8d3elJPqwAArDI"]
[Mon Jul 20 06:20:54.014012 2026] [security2:error] [pid 884009:tid 884213] [client 27.96.94.195:37591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPswAAAM0"]
[Mon Jul 20 06:20:54.014193 2026] [security2:error] [pid 884009:tid 884213] [client 27.96.94.195:37591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPswAAAM0"]
[Mon Jul 20 06:20:54.032700 2026] [security2:error] [pid 884009:tid 884045] [remote 182.77.62.24:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SphKaHUf6J8d3elJPtAAA7CI"]
[Mon Jul 20 06:20:54.149488 2026] [security2:error] [pid 884009:tid 884251] [client 185.132.186.75:28925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/av.php"] [unique_id "al4SphKaHUf6J8d3elJPxQAAAPM"]
[Mon Jul 20 06:20:54.186270 2026] [security2:error] [pid 884009:tid 884145] [client 181.224.94.124:55111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPzgAAAIo"]
[Mon Jul 20 06:20:54.186389 2026] [security2:error] [pid 884009:tid 884145] [client 181.224.94.124:55111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJPzgAAAIo"]
[Mon Jul 20 06:20:54.263483 2026] [security2:error] [pid 884009:tid 884160] [client 104.234.53.89:50651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SphKaHUf6J8d3elJP1wAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:54.485180 2026] [security2:error] [pid 884009:tid 884222] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPmgAAANY"]
[Mon Jul 20 06:20:54.668967 2026] [security2:error] [pid 884009:tid 884065] [remote 182.77.62.24:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SphKaHUf6J8d3elJP9gAA6jY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:20:54.691085 2026] [security2:error] [pid 884009:tid 884167] [client 178.152.178.232:37015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJP_QAAAKA"]
[Mon Jul 20 06:20:54.691181 2026] [security2:error] [pid 884009:tid 884167] [client 178.152.178.232:37015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SphKaHUf6J8d3elJP_QAAAKA"]
[Mon Jul 20 06:20:55.108491 2026] [security2:error] [pid 884009:tid 884103] [remote 194.164.192.228:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4SpxKaHUf6J8d3elJQGQAA0Fw"]
[Mon Jul 20 06:20:55.123216 2026] [security2:error] [pid 884009:tid 884227] [client 14.225.17.146:56476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQEwAAANs"], referer: http://daseighty.net/Wp
[Mon Jul 20 06:20:55.299760 2026] [security2:error] [pid 884009:tid 884089] [remote 194.164.192.228:37940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4SpxKaHUf6J8d3elJQKgAA-k4"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 06:20:55.352263 2026] [security2:error] [pid 884009:tid 884207] [client 158.173.241.141:52951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQHgAAAMc"], referer: http://sesamegreenbeans.com/tag/south-africa/
[Mon Jul 20 06:20:55.391733 2026] [security2:error] [pid 884009:tid 884057] [remote 18.61.192.253:58632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SpxKaHUf6J8d3elJQMgAA7y4"]
[Mon Jul 20 06:20:55.391961 2026] [security2:error] [pid 884009:tid 884247] [client 18.61.192.253:58632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SpxKaHUf6J8d3elJQMgAA7y4"]
[Mon Jul 20 06:20:55.611103 2026] [security2:error] [pid 884009:tid 884242] [client 14.225.17.146:61884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQNwAAAOo"], referer: http://39ishlife.com/Wp
[Mon Jul 20 06:20:55.770634 2026] [security2:error] [pid 884009:tid 884205] [client 185.132.186.88:52977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/autoload_classmap/about.php"] [unique_id "al4SpxKaHUf6J8d3elJQUwAAAMU"]
[Mon Jul 20 06:20:55.828521 2026] [security2:error] [pid 884009:tid 884249] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SpxKaHUf6J8d3elJQTAAAAPE"]
[Mon Jul 20 06:20:56.239002 2026] [security2:error] [pid 884009:tid 884229] [client 77.110.127.138:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4SqBKaHUf6J8d3elJQdwAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:20:56.318176 2026] [security2:error] [pid 884009:tid 884199] [client 57.141.18.62:48520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SpBKaHUf6J8d3elJPSQAAvwY"]
[Mon Jul 20 06:20:56.330235 2026] [security2:error] [pid 884009:tid 884194] [client 14.225.17.146:56188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQdAAAALo"], referer: http://lutheranphilosopher.com/Wp
[Mon Jul 20 06:20:56.538282 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:62540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQigAAAJ0"], referer: https://39ishlife.com/Wp
[Mon Jul 20 06:20:56.688361 2026] [security2:error] [pid 884009:tid 884162] [client 171.61.165.146:28995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqBKaHUf6J8d3elJQnQAAAJs"]
[Mon Jul 20 06:20:56.688524 2026] [security2:error] [pid 884009:tid 884162] [client 171.61.165.146:28995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqBKaHUf6J8d3elJQnQAAAJs"]
[Mon Jul 20 06:20:56.947109 2026] [security2:error] [pid 884009:tid 884024] [remote 122.8.47.155:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.47.8.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wesmclucas.com"] [uri "/wp-login.php"] [unique_id "al4SqBKaHUf6J8d3elJQuwAAzg0"]
[Mon Jul 20 06:20:57.203783 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.49:54736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPhQAAwRI"]
[Mon Jul 20 06:20:57.379178 2026] [security2:error] [pid 884009:tid 884267] [client 185.132.186.59:55229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-configs.php"] [unique_id "al4SqRKaHUf6J8d3elJQ1wAAAQM"]
[Mon Jul 20 06:20:57.464492 2026] [security2:error] [pid 884009:tid 884206] [client 104.234.53.50:54533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SqRKaHUf6J8d3elJQ2wAAAMY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:57.587534 2026] [security2:error] [pid 884009:tid 884218] [client 45.95.169.104:23364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SqRKaHUf6J8d3elJQ5wAAANI"]
[Mon Jul 20 06:20:57.757317 2026] [security2:error] [pid 884009:tid 884243] [client 41.173.37.102:7207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SqRKaHUf6J8d3elJQ-QAAAOs"]
[Mon Jul 20 06:20:57.757456 2026] [security2:error] [pid 884009:tid 884243] [client 41.173.37.102:7207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SqRKaHUf6J8d3elJQ-QAAAOs"]
[Mon Jul 20 06:20:57.758803 2026] [security2:error] [pid 884009:tid 884199] [client 14.225.17.146:62545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SqRKaHUf6J8d3elJQ7QAAAL8"], referer: http://wathenbartlett.co.uk/Wp
[Mon Jul 20 06:20:58.141300 2026] [security2:error] [pid 884009:tid 884154] [client 57.141.18.76:29334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SphKaHUf6J8d3elJP3wAAkw8"]
[Mon Jul 20 06:20:58.172225 2026] [security2:error] [pid 884009:tid 884151] [client 57.141.18.81:37396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SphKaHUf6J8d3elJP4QAAkBw"]
[Mon Jul 20 06:20:58.307408 2026] [security2:error] [pid 884009:tid 884143] [client 104.234.53.85:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRGAAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:20:58.396375 2026] [security2:error] [pid 884009:tid 884060] [remote 104.248.157.6:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.157.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4SqhKaHUf6J8d3elJRIAAA6DE"]
[Mon Jul 20 06:20:58.668615 2026] [security2:error] [pid 884009:tid 884245] [client 14.225.17.146:62039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRKgAAAO0"], referer: https://wathenbartlett.co.uk/Wp
[Mon Jul 20 06:20:58.774146 2026] [security2:error] [pid 884009:tid 884076] [remote 104.248.157.6:47014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.157.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4SqhKaHUf6J8d3elJRQgAAjUE"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:20:58.848676 2026] [security2:error] [pid 884009:tid 884232] [client 14.225.17.146:64611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4SqRKaHUf6J8d3elJQygAAAOA"], referer: http://transparentservices.online/Wp
[Mon Jul 20 06:20:58.908556 2026] [security2:error] [pid 884009:tid 884106] [remote 154.66.198.148:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4SqhKaHUf6J8d3elJRUQAAj18"]
[Mon Jul 20 06:20:58.987121 2026] [security2:error] [pid 884009:tid 884165] [client 185.132.186.92:35393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRVAAAAJ4"]
[Mon Jul 20 06:20:59.216413 2026] [security2:error] [pid 884009:tid 884248] [client 50.116.65.227:59528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SqxKaHUf6J8d3elJRXwAAAPA"]
[Mon Jul 20 06:20:59.227631 2026] [security2:error] [pid 884009:tid 884221] [client 50.116.65.227:47268] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4SqxKaHUf6J8d3elJRYQAAAMY"]
[Mon Jul 20 06:20:59.398541 2026] [security2:error] [pid 884009:tid 884220] [client 216.73.217.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theprocess.oldcartsconsulting.com"] [uri "/index.php"] [unique_id "al4SpRKaHUf6J8d3elJPbQAAANQ"]
[Mon Jul 20 06:20:59.580913 2026] [security2:error] [pid 884009:tid 884258] [client 50.116.65.227:47296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SqxKaHUf6J8d3elJRgwAAAPo"]
[Mon Jul 20 06:20:59.595263 2026] [security2:error] [pid 884009:tid 884216] [client 50.116.65.227:47308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SqxKaHUf6J8d3elJRhAAAANA"]
[Mon Jul 20 06:20:59.735155 2026] [security2:error] [pid 884009:tid 884093] [remote 154.66.198.148:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4SqxKaHUf6J8d3elJRiwAAq1I"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:20:59.909202 2026] [security2:error] [pid 884009:tid 884229] [client 14.225.17.146:61924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4SqRKaHUf6J8d3elJQ5AAAAN0"], referer: http://adastra.love/Wp
[Mon Jul 20 06:20:59.960733 2026] [security2:error] [pid 884009:tid 884013] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqxKaHUf6J8d3elJRnwAA3AI"]
[Mon Jul 20 06:20:59.960922 2026] [security2:error] [pid 884009:tid 884228] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SqxKaHUf6J8d3elJRnwAA3AI"]
[Mon Jul 20 06:21:00.358251 2026] [security2:error] [pid 884009:tid 884223] [client 57.141.18.95:58800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQpAAA13w"]
[Mon Jul 20 06:21:00.494135 2026] [security2:error] [pid 884009:tid 884193] [client 57.141.18.106:31852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SqBKaHUf6J8d3elJQvgAAuXQ"]
[Mon Jul 20 06:21:00.535099 2026] [security2:error] [pid 884009:tid 884011] [remote 97.74.87.194:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SrBKaHUf6J8d3elJR0wAA0AA"]
[Mon Jul 20 06:21:00.576700 2026] [security2:error] [pid 884009:tid 884251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJRvwAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:00.595038 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.62:57671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/widgets/bless2.php"] [unique_id "al4SrBKaHUf6J8d3elJR1QAAAME"]
[Mon Jul 20 06:21:00.612210 2026] [security2:error] [pid 884009:tid 884153] [client 45.95.169.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJRzQAAAJI"]
[Mon Jul 20 06:21:00.625038 2026] [security2:error] [pid 884009:tid 884172] [client 14.225.17.146:55288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJR0gAAAKQ"], referer: http://ncsynchro.com/Wp
[Mon Jul 20 06:21:00.936467 2026] [security2:error] [pid 884009:tid 884040] [remote 97.74.87.194:39964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4SrBKaHUf6J8d3elJR6QAA0h0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:01.134546 2026] [security2:error] [pid 884009:tid 884216] [client 77.110.127.138:60809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4SrRKaHUf6J8d3elJR8wAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:01.153411 2026] [security2:error] [pid 884009:tid 884051] [remote 57.141.18.67:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4SrRKaHUf6J8d3elJR9QAA4Sg"]
[Mon Jul 20 06:21:01.182703 2026] [core:error] [pid 884009:tid 884147] [client 14.225.17.146:55325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wp
[Mon Jul 20 06:21:01.182729 2026] [core:error] [pid 884009:tid 884147] [client 14.225.17.146:55325] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Wp
[Mon Jul 20 06:21:01.526678 2026] [security2:error] [pid 884009:tid 884147] [client 98.159.234.160:20027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SrRKaHUf6J8d3elJSDQAAAIw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:01.762210 2026] [security2:error] [pid 884009:tid 884180] [client 14.182.195.220:52135] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SrRKaHUf6J8d3elJSGwAAAKw"]
[Mon Jul 20 06:21:02.057478 2026] [security2:error] [pid 884009:tid 884173] [client 114.119.134.79:40903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nevelow.com"] [uri "/managing-health-care/"] [unique_id "al4SrhKaHUf6J8d3elJSNwAAAKU"], referer: https://nevelow.com/category/launching/
[Mon Jul 20 06:21:02.202412 2026] [security2:error] [pid 884009:tid 884187] [client 185.132.186.100:42421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/network/about.php"] [unique_id "al4SrhKaHUf6J8d3elJSRAAAALM"]
[Mon Jul 20 06:21:02.278274 2026] [security2:error] [pid 884009:tid 884183] [client 50.116.65.227:59536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4SrhKaHUf6J8d3elJSSgAAAK8"]
[Mon Jul 20 06:21:02.281481 2026] [security2:error] [pid 884009:tid 884265] [client 14.225.17.146:55252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4SrBKaHUf6J8d3elJR4QAAAQE"]
[Mon Jul 20 06:21:02.463011 2026] [security2:error] [pid 884009:tid 884195] [client 57.141.18.91:64084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SqhKaHUf6J8d3elJRUwAAu1w"]
[Mon Jul 20 06:21:02.524850 2026] [security2:error] [pid 884009:tid 884224] [client 45.95.169.104:40256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.169.95.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4SrhKaHUf6J8d3elJSZgAAANg"]
[Mon Jul 20 06:21:02.680003 2026] [security2:error] [pid 884009:tid 884247] [client 104.234.53.57:54853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SrhKaHUf6J8d3elJSeQAAAO8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:02.951425 2026] [security2:error] [pid 884009:tid 884160] [client 14.225.17.146:55306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4SrRKaHUf6J8d3elJR9AAAAJk"], referer: http://superiorcopywriting.com/Wp
[Mon Jul 20 06:21:03.024401 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:58415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSjwAAAME"]
[Mon Jul 20 06:21:03.024548 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:58415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSjwAAAME"]
[Mon Jul 20 06:21:03.063017 2026] [security2:error] [pid 884009:tid 884228] [client 50.116.65.227:59548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SrxKaHUf6J8d3elJSkAAAANw"]
[Mon Jul 20 06:21:03.075025 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:47386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SrxKaHUf6J8d3elJSkwAAAMw"]
[Mon Jul 20 06:21:03.143897 2026] [security2:error] [pid 884009:tid 884214] [client 112.208.70.94:42983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSlgAAAM4"]
[Mon Jul 20 06:21:03.144062 2026] [security2:error] [pid 884009:tid 884214] [client 112.208.70.94:42983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJSlgAAAM4"]
[Mon Jul 20 06:21:03.578513 2026] [security2:error] [pid 884009:tid 884201] [client 114.119.141.100:63345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4SrxKaHUf6J8d3elJSvQAAAME"], referer: https://newstral.com/en/article/en/1132411982/drug-use-leads-to-bowen-man-s-crime
[Mon Jul 20 06:21:03.814356 2026] [security2:error] [pid 884009:tid 884174] [client 185.132.186.83:36579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/item.php"] [unique_id "al4SrxKaHUf6J8d3elJSzwAAAKY"]
[Mon Jul 20 06:21:03.923950 2026] [security2:error] [pid 884009:tid 884183] [client 27.96.94.195:37155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJS2wAAAK8"]
[Mon Jul 20 06:21:03.924061 2026] [security2:error] [pid 884009:tid 884183] [client 27.96.94.195:37155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SrxKaHUf6J8d3elJS2wAAAK8"]
[Mon Jul 20 06:21:04.246348 2026] [security2:error] [pid 884009:tid 884266] [client 45.116.69.230:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS8AAAAQI"]
[Mon Jul 20 06:21:04.246453 2026] [security2:error] [pid 884009:tid 884266] [client 45.116.69.230:50326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS8AAAAQI"]
[Mon Jul 20 06:21:04.301622 2026] [security2:error] [pid 884009:tid 884149] [client 103.141.108.143:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS9QAAAI4"]
[Mon Jul 20 06:21:04.302588 2026] [security2:error] [pid 884009:tid 884149] [client 103.141.108.143:51304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJS9QAAAI4"]
[Mon Jul 20 06:21:04.505045 2026] [security2:error] [pid 884009:tid 884237] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SsBKaHUf6J8d3elJS9AAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:04.635897 2026] [security2:error] [pid 884009:tid 884182] [client 114.119.153.53:21707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bruceledewitz.com"] [uri "/history-and-reason-reveal-truth-and-that-is-why-politics-is-not-war/"] [unique_id "al4SsBKaHUf6J8d3elJTEgAAAK4"], referer: https://bruceledewitz.com/blog/
[Mon Jul 20 06:21:04.650355 2026] [security2:error] [pid 884009:tid 884132] [remote 43.241.64.180:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.64.241.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTFAAAjXk"]
[Mon Jul 20 06:21:04.650678 2026] [security2:error] [pid 884009:tid 884148] [client 43.241.64.180:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTFAAAjXk"]
[Mon Jul 20 06:21:04.711697 2026] [security2:error] [pid 884009:tid 884243] [client 181.224.94.124:17093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTGgAAAOs"]
[Mon Jul 20 06:21:04.711834 2026] [security2:error] [pid 884009:tid 884243] [client 181.224.94.124:17093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SsBKaHUf6J8d3elJTGgAAAOs"]
[Mon Jul 20 06:21:04.718148 2026] [security2:error] [pid 884009:tid 884186] [client 77.110.127.138:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpfkQABJaS'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4SsBKaHUf6J8d3elJTGwAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:04.917660 2026] [security2:error] [pid 884009:tid 884232] [client 34.73.38.214:63250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SsBKaHUf6J8d3elJTKQAAAOA"]
[Mon Jul 20 06:21:05.072603 2026] [security2:error] [pid 884009:tid 884226] [client 34.73.38.214:54966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTMQAAANo"]
[Mon Jul 20 06:21:05.213516 2026] [security2:error] [pid 884009:tid 884242] [client 34.73.38.214:56991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTPAAAAOo"]
[Mon Jul 20 06:21:05.330699 2026] [security2:error] [pid 884009:tid 884239] [client 34.73.38.214:59706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTRgAAAOc"]
[Mon Jul 20 06:21:05.367967 2026] [security2:error] [pid 884009:tid 884018] [remote 156.59.198.135:50206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/menu/wp-content/uploads/2026/03/Aosta-lunch-MAR26.pdf"] [unique_id "al4SsRKaHUf6J8d3elJTRwAAlwc"]
[Mon Jul 20 06:21:05.389322 2026] [security2:error] [pid 884009:tid 884203] [client 57.141.18.59:59884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SrRKaHUf6J8d3elJSNQAAwwM"]
[Mon Jul 20 06:21:05.427744 2026] [security2:error] [pid 884009:tid 884191] [client 185.132.186.103:22933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Text/Diff/Engine/theme.php"] [unique_id "al4SsRKaHUf6J8d3elJTTwAAALc"]
[Mon Jul 20 06:21:05.438308 2026] [security2:error] [pid 884009:tid 884170] [client 34.73.38.214:61428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTUQAAAKI"]
[Mon Jul 20 06:21:05.457233 2026] [security2:error] [pid 884009:tid 884268] [client 57.141.18.48:28300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SrhKaHUf6J8d3elJSNgABBBY"]
[Mon Jul 20 06:21:05.597406 2026] [security2:error] [pid 884009:tid 884265] [client 34.73.38.214:63220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTZgAAAQE"]
[Mon Jul 20 06:21:05.704873 2026] [security2:error] [pid 884009:tid 884223] [client 34.73.38.214:65059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTagAAANc"]
[Mon Jul 20 06:21:05.730894 2026] [security2:error] [pid 884009:tid 884253] [client 54.162.148.64:23042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.148.162.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SsRKaHUf6J8d3elJTaQAAAPU"]
[Mon Jul 20 06:21:05.845121 2026] [security2:error] [pid 884009:tid 884231] [client 34.73.38.214:51026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTdAAAAN8"]
[Mon Jul 20 06:21:05.962000 2026] [security2:error] [pid 884009:tid 884191] [client 34.73.38.214:54273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundhealingsouthflorida.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTggAAALc"]
[Mon Jul 20 06:21:05.980329 2026] [security2:error] [pid 884009:tid 884201] [client 34.73.38.214:61610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SsRKaHUf6J8d3elJTgwAAAME"]
[Mon Jul 20 06:21:06.109882 2026] [security2:error] [pid 884009:tid 884176] [client 34.73.38.214:56793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTkAAAAKg"]
[Mon Jul 20 06:21:06.159647 2026] [security2:error] [pid 884009:tid 884259] [client 34.201.171.57:42770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.171.201.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4SshKaHUf6J8d3elJTjwAAAPs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:21:06.268137 2026] [security2:error] [pid 884009:tid 884215] [client 34.73.38.214:60987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTmwAAAM8"]
[Mon Jul 20 06:21:06.300769 2026] [security2:error] [pid 884009:tid 884209] [client 57.141.18.65:39830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SrxKaHUf6J8d3elJSjgAAyS0"]
[Mon Jul 20 06:21:06.428370 2026] [security2:error] [pid 884009:tid 884194] [client 34.73.38.214:63639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTrwAAALo"]
[Mon Jul 20 06:21:06.518258 2026] [security2:error] [pid 884009:tid 884230] [client 50.116.65.227:59558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SshKaHUf6J8d3elJTtgAAAN4"]
[Mon Jul 20 06:21:06.529710 2026] [security2:error] [pid 884009:tid 884217] [client 50.116.65.227:47398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SshKaHUf6J8d3elJTuAAAANE"]
[Mon Jul 20 06:21:06.545376 2026] [security2:error] [pid 884009:tid 884149] [client 34.73.38.214:49863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTugAAAI4"]
[Mon Jul 20 06:21:06.560390 2026] [security2:error] [pid 884009:tid 884239] [client 114.119.159.26:24699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jvcmotorsports.com"] [uri "/cart/"] [unique_id "al4SshKaHUf6J8d3elJTvAAAAOc"], referer: https://jvcmotorsports.com?action=yith-woocompare-add-product&id=5646
[Mon Jul 20 06:21:06.658009 2026] [security2:error] [pid 884009:tid 884259] [client 34.73.38.214:53371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTvwAAAPs"]
[Mon Jul 20 06:21:06.796024 2026] [security2:error] [pid 884009:tid 884143] [client 34.73.38.214:55948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJTxQAAAIg"]
[Mon Jul 20 06:21:06.933356 2026] [security2:error] [pid 884009:tid 884174] [client 34.73.38.214:60748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SshKaHUf6J8d3elJT1QAAAKY"]
[Mon Jul 20 06:21:07.039261 2026] [security2:error] [pid 884009:tid 884260] [client 104.234.53.76:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SsxKaHUf6J8d3elJT3wAAAPw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:07.049869 2026] [security2:error] [pid 884009:tid 884253] [client 185.132.186.90:38511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/.well-known/acme-challenge/mah.php"] [unique_id "al4SsxKaHUf6J8d3elJT4AAAAPU"]
[Mon Jul 20 06:21:07.050627 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:63064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SsxKaHUf6J8d3elJT4gAAAQQ"]
[Mon Jul 20 06:21:07.124182 2026] [security2:error] [pid 884009:tid 884218] [client 14.225.17.146:54571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4SsRKaHUf6J8d3elJTTAAAANI"], referer: http://nomorewetsheets.net/Wp
[Mon Jul 20 06:21:07.178135 2026] [security2:error] [pid 884009:tid 884251] [client 14.225.17.146:49321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJT5gAAAPM"], referer: http://musichaven.info/Wp
[Mon Jul 20 06:21:07.180673 2026] [security2:error] [pid 884009:tid 884186] [client 34.73.38.214:50734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SsxKaHUf6J8d3elJT7QAAALI"]
[Mon Jul 20 06:21:07.296481 2026] [security2:error] [pid 884009:tid 884144] [client 34.73.38.214:55144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.soundbathmiami.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SsxKaHUf6J8d3elJT8wAAAIk"]
[Mon Jul 20 06:21:07.299707 2026] [security2:error] [pid 884009:tid 884058] [remote 57.141.18.113:62136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3831221"] [unique_id "al4SsxKaHUf6J8d3elJT9AAA6S8"]
[Mon Jul 20 06:21:07.300966 2026] [security2:error] [pid 884009:tid 884171] [client 57.141.18.4:20606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SsBKaHUf6J8d3elJS7AAAo0U"]
[Mon Jul 20 06:21:07.337282 2026] [security2:error] [pid 884009:tid 884262] [client 171.61.165.146:19904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsxKaHUf6J8d3elJT9gAAAP4"]
[Mon Jul 20 06:21:07.338521 2026] [security2:error] [pid 884009:tid 884262] [client 171.61.165.146:19904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SsxKaHUf6J8d3elJT9gAAAP4"]
[Mon Jul 20 06:21:07.383975 2026] [security2:error] [pid 884009:tid 884191] [client 14.225.17.146:57570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJT6QAAALc"]
[Mon Jul 20 06:21:07.901554 2026] [security2:error] [pid 884009:tid 884163] [client 104.234.53.71:29999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SsxKaHUf6J8d3elJULAAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:08.086071 2026] [security2:error] [pid 884009:tid 884214] [client 14.225.17.146:54690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUOwAAAM4"], referer: https://musichaven.info/Wp
[Mon Jul 20 06:21:08.313907 2026] [security2:error] [pid 884009:tid 884168] [client 41.173.37.102:7623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4StBKaHUf6J8d3elJUWQAAAKE"]
[Mon Jul 20 06:21:08.314042 2026] [security2:error] [pid 884009:tid 884168] [client 41.173.37.102:7623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4StBKaHUf6J8d3elJUWQAAAKE"]
[Mon Jul 20 06:21:08.549380 2026] [security2:error] [pid 884009:tid 884208] [client 57.141.18.120:51846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SsRKaHUf6J8d3elJTSQAAyC4"]
[Mon Jul 20 06:21:08.654177 2026] [security2:error] [pid 884009:tid 884152] [client 185.132.186.103:57029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/shell.php"] [unique_id "al4StBKaHUf6J8d3elJUdgAAAJE"]
[Mon Jul 20 06:21:09.076401 2026] [security2:error] [pid 884009:tid 884172] [client 104.234.53.52:58809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4StRKaHUf6J8d3elJUngAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:09.105033 2026] [security2:error] [pid 884009:tid 884162] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUhgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:09.200036 2026] [security2:error] [pid 884009:tid 884215] [client 50.116.65.227:24666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StRKaHUf6J8d3elJUpwAAAM8"]
[Mon Jul 20 06:21:09.200771 2026] [security2:error] [pid 884009:tid 884185] [client 50.116.65.227:24684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StRKaHUf6J8d3elJUqQAAALE"]
[Mon Jul 20 06:21:09.200772 2026] [security2:error] [pid 884009:tid 884254] [client 50.116.65.227:24668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StRKaHUf6J8d3elJUqAAAAPY"]
[Mon Jul 20 06:21:09.205849 2026] [security2:error] [pid 884009:tid 884239] [client 124.156.119.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUGgAAAOc"]
[Mon Jul 20 06:21:09.206582 2026] [security2:error] [pid 884009:tid 884209] [client 43.173.78.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUBwAAAMk"]
[Mon Jul 20 06:21:09.206899 2026] [security2:error] [pid 884009:tid 884220] [client 43.156.21.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUHwAAANQ"]
[Mon Jul 20 06:21:09.232614 2026] [security2:error] [pid 884009:tid 884157] [client 124.156.160.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUNwAAAJY"]
[Mon Jul 20 06:21:09.232914 2026] [security2:error] [pid 884009:tid 884205] [client 43.173.73.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJUJgAAAMU"]
[Mon Jul 20 06:21:09.232914 2026] [security2:error] [pid 884009:tid 884260] [client 43.134.185.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUPwAAAPw"]
[Mon Jul 20 06:21:09.316124 2026] [security2:error] [pid 884009:tid 884170] [client 77.110.127.138:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpUVvV1ePP'%20OR%20635=(SELECT%20635%20FROM%20PG_SLEEP(15))--"] [unique_id "al4StRKaHUf6J8d3elJUsQAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:09.433464 2026] [security2:error] [pid 884009:tid 884224] [client 14.225.17.146:54456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUbwAAANg"]
[Mon Jul 20 06:21:09.568727 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:55689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4StRKaHUf6J8d3elJUsgAAAJo"], referer: http://soloceos.com/Wp
[Mon Jul 20 06:21:09.813099 2026] [security2:error] [pid 884009:tid 884265] [client 45.157.112.60:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4StRKaHUf6J8d3elJU0QAAAQE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:09.820808 2026] [security2:error] [pid 884009:tid 884215] [client 4.194.217.15:7469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/nine2code.php"] [unique_id "al4StRKaHUf6J8d3elJU0gAAAM8"]
[Mon Jul 20 06:21:10.021051 2026] [security2:error] [pid 884009:tid 884221] [client 57.141.18.4:47294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SshKaHUf6J8d3elJTzAAA1Ro"]
[Mon Jul 20 06:21:10.094020 2026] [security2:error] [pid 884009:tid 884187] [client 14.225.17.146:65307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4StRKaHUf6J8d3elJUwQAAALM"]
[Mon Jul 20 06:21:10.269874 2026] [security2:error] [pid 884009:tid 884260] [client 185.132.186.75:37185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh-library.php"] [unique_id "al4SthKaHUf6J8d3elJU_wAAAPw"]
[Mon Jul 20 06:21:10.363812 2026] [security2:error] [pid 884009:tid 884164] [client 57.141.18.7:41118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SsxKaHUf6J8d3elJT7AAAnR8"]
[Mon Jul 20 06:21:10.392998 2026] [security2:error] [pid 884009:tid 884176] [client 4.194.217.15:12008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/num.php"] [unique_id "al4SthKaHUf6J8d3elJVBwAAAKg"]
[Mon Jul 20 06:21:10.400854 2026] [core:error] [pid 884009:tid 884174] [client 205.210.31.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:10.400876 2026] [core:error] [pid 884009:tid 884174] [client 205.210.31.49:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:10.432822 2026] [security2:error] [pid 884009:tid 884061] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SthKaHUf6J8d3elJVDgAAzDI"]
[Mon Jul 20 06:21:10.433025 2026] [security2:error] [pid 884009:tid 884212] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SthKaHUf6J8d3elJVDgAAzDI"]
[Mon Jul 20 06:21:10.445622 2026] [security2:error] [pid 884009:tid 884254] [client 14.225.17.146:55469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4SthKaHUf6J8d3elJU9wAAAPY"]
[Mon Jul 20 06:21:10.464238 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:58036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SthKaHUf6J8d3elJVEgAAAOw"]
[Mon Jul 20 06:21:10.476284 2026] [security2:error] [pid 884009:tid 884258] [client 50.116.65.227:58040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SthKaHUf6J8d3elJVFgAAAPo"]
[Mon Jul 20 06:21:10.943988 2026] [security2:error] [pid 884009:tid 884205] [client 4.194.217.15:11995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4SthKaHUf6J8d3elJVPQAAAMU"]
[Mon Jul 20 06:21:11.174179 2026] [security2:error] [pid 884009:tid 884195] [client 50.116.65.227:24686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4StxKaHUf6J8d3elJVYgAAALs"]
[Mon Jul 20 06:21:11.177625 2026] [security2:error] [pid 884009:tid 884200] [client 43.173.74.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVUQAAAMA"]
[Mon Jul 20 06:21:11.179608 2026] [security2:error] [pid 884009:tid 884168] [client 101.32.14.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVVQAAAKE"]
[Mon Jul 20 06:21:11.209557 2026] [security2:error] [pid 884009:tid 884177] [client 43.134.142.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVWQAAAKk"]
[Mon Jul 20 06:21:11.318716 2026] [security2:error] [pid 884009:tid 884145] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVYwAAAIo"]
[Mon Jul 20 06:21:11.486031 2026] [security2:error] [pid 884009:tid 884154] [client 4.194.217.15:7427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/option.php"] [unique_id "al4StxKaHUf6J8d3elJVewAAAJM"]
[Mon Jul 20 06:21:11.619093 2026] [security2:error] [pid 884009:tid 884150] [client 57.141.18.39:54377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4StBKaHUf6J8d3elJUZQAAjx4"]
[Mon Jul 20 06:21:11.885426 2026] [security2:error] [pid 884009:tid 884202] [client 185.132.186.62:61311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/ms-users.php"] [unique_id "al4StxKaHUf6J8d3elJVlwAAAMI"]
[Mon Jul 20 06:21:11.965707 2026] [security2:error] [pid 884009:tid 884223] [client 14.225.17.146:63641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVhgAAANc"], referer: http://securingmemories.com/Wp
[Mon Jul 20 06:21:12.044806 2026] [security2:error] [pid 884009:tid 884175] [client 4.194.217.15:12574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/p.php"] [unique_id "al4SuBKaHUf6J8d3elJVqQAAAKc"]
[Mon Jul 20 06:21:12.586790 2026] [security2:error] [pid 884009:tid 884238] [client 4.194.217.15:12600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/past.php"] [unique_id "al4SuBKaHUf6J8d3elJV0QAAAOY"]
[Mon Jul 20 06:21:12.625183 2026] [security2:error] [pid 884009:tid 884190] [client 14.225.17.146:58188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJVwAAAALY"]
[Mon Jul 20 06:21:12.699623 2026] [security2:error] [pid 884009:tid 884104] [remote 51.79.215.219:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4SuBKaHUf6J8d3elJV0wAApl0"]
[Mon Jul 20 06:21:13.155899 2026] [security2:error] [pid 884009:tid 884113] [remote 51.79.215.219:47688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.215.79.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4SuRKaHUf6J8d3elJV-QAAp2Y"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:21:13.172561 2026] [autoindex:error] [pid 884009:tid 884226] [client 147.93.171.185:63379] AH01276: Cannot serve directory /home1/aberball/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:21:13.176292 2026] [security2:error] [pid 884009:tid 884220] [client 4.194.217.15:12599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/php.php"] [unique_id "al4SuRKaHUf6J8d3elJV-gAAANQ"]
[Mon Jul 20 06:21:13.325882 2026] [fcgid:warn] [pid 884009:tid 884213] (70014)End of file found: [client 66.132.172.131:16214] mod_fcgid: can't get data from http client
[Mon Jul 20 06:21:13.369135 2026] [security2:error] [pid 884009:tid 884154] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJV-AAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:13.508399 2026] [security2:error] [pid 884009:tid 884236] [client 185.132.186.83:24549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/js/cc.php"] [unique_id "al4SuRKaHUf6J8d3elJWCgAAAOQ"]
[Mon Jul 20 06:21:13.578642 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpYCtJrgIc')%20OR%20518=(SELECT%20518%20FROM%20PG_SLEEP(15))--"] [unique_id "al4SuRKaHUf6J8d3elJWEwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:13.591570 2026] [security2:error] [pid 884009:tid 884148] [client 171.60.139.123:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SuRKaHUf6J8d3elJWFwAAAI0"]
[Mon Jul 20 06:21:13.591684 2026] [security2:error] [pid 884009:tid 884148] [client 171.60.139.123:58928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SuRKaHUf6J8d3elJWFwAAAI0"]
[Mon Jul 20 06:21:13.740212 2026] [security2:error] [pid 884009:tid 884267] [client 4.194.217.15:12019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/php8.php"] [unique_id "al4SuRKaHUf6J8d3elJWHwAAAQM"]
[Mon Jul 20 06:21:13.776945 2026] [autoindex:error] [pid 884009:tid 884175] [client 66.132.172.131:16224] AH01276: Cannot serve directory /home4/gpmvvomy/funnels.allandbeckson.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:21:14.149728 2026] [security2:error] [pid 884009:tid 884173] [client 57.141.18.111:24302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVWAAApVw"]
[Mon Jul 20 06:21:14.159824 2026] [security2:error] [pid 884009:tid 884246] [client 14.225.17.146:63584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWRAAAAO4"], referer: http://claysharecon.com/Wp
[Mon Jul 20 06:21:14.199778 2026] [security2:error] [pid 884009:tid 884153] [client 14.225.17.146:58130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJVtAAAAJI"], referer: http://outlookturf.com/Wp
[Mon Jul 20 06:21:14.320516 2026] [security2:error] [pid 884009:tid 884245] [client 4.194.217.15:12585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/phpinfo.php"] [unique_id "al4SuhKaHUf6J8d3elJWVAAAAO0"]
[Mon Jul 20 06:21:14.341293 2026] [security2:error] [pid 884009:tid 884188] [client 14.225.17.146:58265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJV5AAAALQ"], referer: http://detroitcsc.com/Wp
[Mon Jul 20 06:21:14.640039 2026] [security2:error] [pid 884009:tid 884209] [client 45.95.169.104:57516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWWwAAAMk"]
[Mon Jul 20 06:21:14.724204 2026] [core:error] [pid 884009:tid 884220] [client 103.153.183.69:4102] AH10244: invalid URI path (/%2e%2e/etc/passwd?_=2tiol3ps&v=epb6f), referer: https://twitter.com/
[Mon Jul 20 06:21:14.727443 2026] [security2:error] [pid 884009:tid 884153] [client 127.0.0.1:20248] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4SuhKaHUf6J8d3elJWaQAAAJI"], referer: https://twitter.com/
[Mon Jul 20 06:21:14.749219 2026] [security2:error] [pid 884009:tid 884154] [client 104.234.53.72:40397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWbAAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:14.787825 2026] [security2:error] [pid 884009:tid 884178] [client 45.116.69.230:50865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SuhKaHUf6J8d3elJWcgAAAKo"]
[Mon Jul 20 06:21:14.787972 2026] [security2:error] [pid 884009:tid 884178] [client 45.116.69.230:50865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SuhKaHUf6J8d3elJWcgAAAKo"]
[Mon Jul 20 06:21:14.833101 2026] [security2:error] [pid 884009:tid 884163] [client 57.141.18.63:23322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4StxKaHUf6J8d3elJVhQAAnCs"]
[Mon Jul 20 06:21:15.034834 2026] [security2:error] [pid 884009:tid 884247] [client 27.96.94.195:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjAAAAO8"]
[Mon Jul 20 06:21:15.034963 2026] [security2:error] [pid 884009:tid 884247] [client 27.96.94.195:37552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjAAAAO8"]
[Mon Jul 20 06:21:15.041596 2026] [security2:error] [pid 884009:tid 884187] [client 14.225.17.146:65174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJV6QAAALM"], referer: http://itdynamix.com/Wp
[Mon Jul 20 06:21:15.076027 2026] [security2:error] [pid 884009:tid 884208] [client 103.141.108.143:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjwAAAMg"]
[Mon Jul 20 06:21:15.076580 2026] [security2:error] [pid 884009:tid 884180] [client 4.194.217.15:11973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/post.php"] [unique_id "al4SuxKaHUf6J8d3elJWkAAAAKw"]
[Mon Jul 20 06:21:15.076854 2026] [security2:error] [pid 884009:tid 884208] [client 103.141.108.143:51793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWjwAAAMg"]
[Mon Jul 20 06:21:15.167200 2026] [security2:error] [pid 884009:tid 884234] [client 185.132.186.94:29989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/Requests/library/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJWkgAAAOI"]
[Mon Jul 20 06:21:15.236064 2026] [security2:error] [pid 884009:tid 884252] [client 181.224.94.124:21476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWoAAAAPQ"]
[Mon Jul 20 06:21:15.236245 2026] [security2:error] [pid 884009:tid 884252] [client 181.224.94.124:21476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJWoAAAAPQ"]
[Mon Jul 20 06:21:15.330921 2026] [security2:error] [pid 884009:tid 884190] [client 45.95.169.104:57526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJWkQAAALY"]
[Mon Jul 20 06:21:15.411625 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:36146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SuxKaHUf6J8d3elJWsgAAAOw"]
[Mon Jul 20 06:21:15.422818 2026] [security2:error] [pid 884009:tid 884228] [client 50.116.65.227:58114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4SuxKaHUf6J8d3elJWswAAANw"]
[Mon Jul 20 06:21:15.498414 2026] [security2:error] [pid 884009:tid 884218] [client 103.153.183.69:44380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env"] [unique_id "al4SuxKaHUf6J8d3elJWvAAAANI"], referer: https://twitter.com/
[Mon Jul 20 06:21:15.605872 2026] [security2:error] [pid 884009:tid 884202] [client 45.95.169.104:57540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJWsAAAAMI"]
[Mon Jul 20 06:21:15.642168 2026] [security2:error] [pid 884009:tid 884056] [remote 100.42.189.89:43586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJWxAAA0S0"]
[Mon Jul 20 06:21:15.663266 2026] [security2:error] [pid 884009:tid 884138] [remote 130.185.118.215:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJWyAAAln8"]
[Mon Jul 20 06:21:15.669509 2026] [security2:error] [pid 884009:tid 884159] [client 4.194.217.15:7457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4SuxKaHUf6J8d3elJWywAAAJg"]
[Mon Jul 20 06:21:15.809117 2026] [security2:error] [pid 884009:tid 884194] [client 14.225.17.146:55139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJWzQAAALo"], referer: http://christiancountytrumpet.com/Wp
[Mon Jul 20 06:21:15.838724 2026] [security2:error] [pid 884009:tid 884110] [remote 100.42.189.89:43586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJW4AAAkGM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:21:15.848932 2026] [security2:error] [pid 884009:tid 884039] [remote 130.185.118.215:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4SuxKaHUf6J8d3elJW4QAA_xw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:21:15.854693 2026] [security2:error] [pid 884009:tid 884208] [client 178.152.178.232:36646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJW4gAAAMg"]
[Mon Jul 20 06:21:15.854850 2026] [security2:error] [pid 884009:tid 884208] [client 178.152.178.232:36646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SuxKaHUf6J8d3elJW4gAAAMg"]
[Mon Jul 20 06:21:15.924836 2026] [security2:error] [pid 884009:tid 884207] [client 45.95.169.104:57546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJW0wAAAMc"]
[Mon Jul 20 06:21:16.055381 2026] [security2:error] [pid 884009:tid 884249] [client 104.234.53.59:59231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4SvBKaHUf6J8d3elJW9wAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:16.059540 2026] [security2:error] [pid 884009:tid 884183] [client 14.225.17.146:51004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4SuxKaHUf6J8d3elJW5wAAAK8"], referer: https://itdynamix.com/Wp
[Mon Jul 20 06:21:16.178964 2026] [security2:error] [pid 884009:tid 884150] [client 112.208.70.94:43458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SvBKaHUf6J8d3elJXAQAAAI8"]
[Mon Jul 20 06:21:16.179121 2026] [security2:error] [pid 884009:tid 884150] [client 112.208.70.94:43458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SvBKaHUf6J8d3elJXAQAAAI8"]
[Mon Jul 20 06:21:16.196406 2026] [security2:error] [pid 884009:tid 884210] [client 57.141.18.60:31938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuBKaHUf6J8d3elJV6gAAylY"]
[Mon Jul 20 06:21:16.223217 2026] [security2:error] [pid 884009:tid 884168] [client 4.194.217.15:4736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/public/css.php"] [unique_id "al4SvBKaHUf6J8d3elJXBwAAAKE"]
[Mon Jul 20 06:21:16.291297 2026] [security2:error] [pid 884009:tid 884203] [client 57.141.18.41:48610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJV7gAAw04"]
[Mon Jul 20 06:21:16.401254 2026] [security2:error] [pid 884009:tid 884265] [client 14.251.3.155:55713] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SvBKaHUf6J8d3elJXFAAAAQE"]
[Mon Jul 20 06:21:16.451442 2026] [security2:error] [pid 884009:tid 884250] [client 45.95.169.104:57558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXCQAAAPI"]
[Mon Jul 20 06:21:16.467808 2026] [security2:error] [pid 884009:tid 884263] [client 57.141.18.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXDgAAAP8"]
[Mon Jul 20 06:21:16.650301 2026] [security2:error] [pid 884009:tid 884140] [client 45.95.169.104:57556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXGwAAAIU"]
[Mon Jul 20 06:21:16.764513 2026] [security2:error] [pid 884009:tid 884201] [client 4.194.217.15:12002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/r.php"] [unique_id "al4SvBKaHUf6J8d3elJXMwAAAME"]
[Mon Jul 20 06:21:16.781360 2026] [security2:error] [pid 884009:tid 884203] [client 185.132.186.65:51199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/interactivity-api/about.php"] [unique_id "al4SvBKaHUf6J8d3elJXNgAAAMM"]
[Mon Jul 20 06:21:17.224894 2026] [security2:error] [pid 884009:tid 884206] [client 57.141.18.95:22660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJWMQAAxk8"]
[Mon Jul 20 06:21:17.244021 2026] [security2:error] [pid 884009:tid 884237] [client 57.141.18.2:40962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuRKaHUf6J8d3elJWNwAA5Uc"]
[Mon Jul 20 06:21:17.307111 2026] [security2:error] [pid 884009:tid 884204] [client 4.194.217.15:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/radio.php"] [unique_id "al4SvRKaHUf6J8d3elJXaAAAAMQ"]
[Mon Jul 20 06:21:17.386561 2026] [security2:error] [pid 884009:tid 884194] [client 74.7.227.179:57090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXXgAAunI"], referer: https://tejasenvironmental.com/p=735184
[Mon Jul 20 06:21:17.527427 2026] [security2:error] [pid 884009:tid 884231] [client 45.95.169.104:57562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXaQAAAN8"]
[Mon Jul 20 06:21:17.572970 2026] [security2:error] [pid 884009:tid 884213] [client 45.95.169.104:57598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXawAAAM0"]
[Mon Jul 20 06:21:17.645351 2026] [security2:error] [pid 884009:tid 884196] [client 45.95.169.104:57572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXcwAAALw"]
[Mon Jul 20 06:21:17.669657 2026] [security2:error] [pid 884009:tid 884162] [client 45.95.169.104:57586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXeAAAAJs"]
[Mon Jul 20 06:21:17.682206 2026] [security2:error] [pid 884009:tid 884265] [client 14.225.17.146:65327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXfwAAAQE"], referer: http://getgarrison.com/Wp
[Mon Jul 20 06:21:17.827584 2026] [security2:error] [pid 884009:tid 884191] [client 14.225.17.146:57855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJW8gAAALc"], referer: http://aandarealtygroup.com/Wp
[Mon Jul 20 06:21:17.866576 2026] [security2:error] [pid 884009:tid 884210] [client 57.141.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXhwAAAMo"]
[Mon Jul 20 06:21:17.881527 2026] [security2:error] [pid 884009:tid 884228] [client 4.194.217.15:11978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/randkeyword.php7"] [unique_id "al4SvRKaHUf6J8d3elJXlgAAANw"]
[Mon Jul 20 06:21:17.882829 2026] [security2:error] [pid 884009:tid 884160] [client 45.95.169.104:57606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SvRKaHUf6J8d3elJXhQAAAJk"]
[Mon Jul 20 06:21:18.063191 2026] [security2:error] [pid 884009:tid 884158] [client 14.225.17.146:58026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXKgAAAJc"], referer: http://alaraycreative.com/Wp
[Mon Jul 20 06:21:18.250783 2026] [security2:error] [pid 884009:tid 884166] [client 57.141.18.109:24450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWcQAAnx0"]
[Mon Jul 20 06:21:18.288065 2026] [security2:error] [pid 884009:tid 884164] [client 171.61.165.146:15500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJXwQAAAJ0"]
[Mon Jul 20 06:21:18.288238 2026] [security2:error] [pid 884009:tid 884164] [client 171.61.165.146:15500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJXwQAAAJ0"]
[Mon Jul 20 06:21:18.301626 2026] [security2:error] [pid 884009:tid 884185] [client 57.141.18.22:27834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SuhKaHUf6J8d3elJWdwAAsXo"]
[Mon Jul 20 06:21:18.418880 2026] [security2:error] [pid 884009:tid 884174] [client 185.132.186.64:45567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/css/file.php"] [unique_id "al4SvhKaHUf6J8d3elJXzAAAAKY"]
[Mon Jul 20 06:21:18.473766 2026] [security2:error] [pid 884009:tid 884157] [client 4.194.217.15:12006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/readme.php"] [unique_id "al4SvhKaHUf6J8d3elJX0QAAAJY"]
[Mon Jul 20 06:21:18.808348 2026] [security2:error] [pid 884009:tid 884015] [remote 147.50.252.213:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SvhKaHUf6J8d3elJX7AAAswQ"]
[Mon Jul 20 06:21:18.934144 2026] [security2:error] [pid 884009:tid 884221] [client 41.173.37.102:8036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJX-QAAANU"]
[Mon Jul 20 06:21:18.934222 2026] [security2:error] [pid 884009:tid 884221] [client 41.173.37.102:8036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SvhKaHUf6J8d3elJX-QAAANU"]
[Mon Jul 20 06:21:19.025332 2026] [security2:error] [pid 884009:tid 884189] [client 4.194.217.15:12014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/reze.php"] [unique_id "al4SvxKaHUf6J8d3elJYCAAAALU"]
[Mon Jul 20 06:21:19.269575 2026] [security2:error] [pid 884009:tid 884180] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/deploy/.ssh/id_rsa"] [unique_id "al4SvxKaHUf6J8d3elJYKQAAAKw"], referer: https://www.google.com/
[Mon Jul 20 06:21:19.297940 2026] [security2:error] [pid 884009:tid 884238] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4SvxKaHUf6J8d3elJYKgAAAOY"], referer: https://www.reddit.com/
[Mon Jul 20 06:21:19.316374 2026] [security2:error] [pid 884009:tid 884101] [remote 147.50.252.213:44774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4SvxKaHUf6J8d3elJYKwAAjVo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:21:19.325768 2026] [security2:error] [pid 884009:tid 884261] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/www-data/.ssh/id_rsa"] [unique_id "al4SvxKaHUf6J8d3elJYLAAAAP0"], referer: https://t.co/arq0ebe4k3
[Mon Jul 20 06:21:19.443819 2026] [security2:error] [pid 884009:tid 884215] [client 82.102.18.116:56076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4SvxKaHUf6J8d3elJYOAAAAM8"]
[Mon Jul 20 06:21:19.570265 2026] [security2:error] [pid 884009:tid 884144] [client 4.194.217.15:9274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/rh.php"] [unique_id "al4SvxKaHUf6J8d3elJYRAAAAIk"]
[Mon Jul 20 06:21:19.640631 2026] [security2:error] [pid 884009:tid 884156] [client 93.152.221.118:49356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4SvxKaHUf6J8d3elJYSgAAAJU"]
[Mon Jul 20 06:21:19.694251 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.81:38572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXFgAA0xg"]
[Mon Jul 20 06:21:19.768854 2026] [security2:error] [pid 884009:tid 884196] [client 82.102.18.116:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.southernswinggolfco.com"] [uri "/xmlrpc.php"] [unique_id "al4SvxKaHUf6J8d3elJYWwAAALw"]
[Mon Jul 20 06:21:19.783409 2026] [security2:error] [pid 884009:tid 884176] [client 50.116.65.227:20958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SvxKaHUf6J8d3elJYXAAAAKg"]
[Mon Jul 20 06:21:19.795561 2026] [security2:error] [pid 884009:tid 884249] [client 50.116.65.227:20960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SvxKaHUf6J8d3elJYXQAAAPE"]
[Mon Jul 20 06:21:19.973823 2026] [security2:error] [pid 884009:tid 884242] [client 57.141.18.43:41922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvBKaHUf6J8d3elJXMgAA6j4"]
[Mon Jul 20 06:21:20.015122 2026] [security2:error] [pid 884009:tid 884172] [client 93.152.221.118:49786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4SwBKaHUf6J8d3elJYdQAAAKQ"]
[Mon Jul 20 06:21:20.033997 2026] [security2:error] [pid 884009:tid 884268] [client 185.132.186.79:55111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/classic-editor/alam.php"] [unique_id "al4SwBKaHUf6J8d3elJYeAAAAQQ"]
[Mon Jul 20 06:21:20.114392 2026] [security2:error] [pid 884009:tid 884159] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYaAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:20.181191 2026] [security2:error] [pid 884009:tid 884222] [client 4.194.217.15:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/rip.php"] [unique_id "al4SwBKaHUf6J8d3elJYhgAAANY"]
[Mon Jul 20 06:21:20.193899 2026] [security2:error] [pid 884009:tid 884216] [client 14.225.17.146:64055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYGQAAANA"]
[Mon Jul 20 06:21:20.250838 2026] [security2:error] [pid 884009:tid 884143] [client 193.47.62.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYgAAAiCc"], referer: http://nzfoodstory.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:21:20.257943 2026] [security2:error] [pid 884009:tid 884262] [client 82.102.18.116:56084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SwBKaHUf6J8d3elJYiwAAAP4"]
[Mon Jul 20 06:21:20.627179 2026] [security2:error] [pid 884009:tid 884268] [client 82.102.18.116:56094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SwBKaHUf6J8d3elJYqwAAAQQ"]
[Mon Jul 20 06:21:20.739358 2026] [security2:error] [pid 884009:tid 884214] [client 4.194.217.15:1416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/root.php"] [unique_id "al4SwBKaHUf6J8d3elJYtwAAAM4"]
[Mon Jul 20 06:21:20.950795 2026] [security2:error] [pid 884009:tid 884165] [client 82.102.18.116:56106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SwBKaHUf6J8d3elJYywAAAJ4"]
[Mon Jul 20 06:21:21.007361 2026] [security2:error] [pid 884009:tid 884052] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SwRKaHUf6J8d3elJY0gABAik"]
[Mon Jul 20 06:21:21.007519 2026] [security2:error] [pid 884009:tid 884266] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SwRKaHUf6J8d3elJY0gABAik"]
[Mon Jul 20 06:21:21.123971 2026] [core:error] [pid 884009:tid 884268] [client 103.153.183.69:11562] AH10244: invalid URI path (/%2e%2e/.env?_=parirvul&v=sk7vh), referer: https://t.co/unafqwh6am
[Mon Jul 20 06:21:21.168080 2026] [security2:error] [pid 884009:tid 884267] [client 93.152.221.118:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4SwRKaHUf6J8d3elJY3wAAAQM"]
[Mon Jul 20 06:21:21.255132 2026] [security2:error] [pid 884009:tid 884221] [client 14.225.17.146:58414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYSwAAANU"], referer: http://ironcitywellness.com/Wp
[Mon Jul 20 06:21:21.274291 2026] [security2:error] [pid 884009:tid 884156] [client 82.102.18.116:63308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4SwRKaHUf6J8d3elJY7wAAAJU"]
[Mon Jul 20 06:21:21.313095 2026] [security2:error] [pid 884009:tid 884168] [client 4.194.217.15:7450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/s.php"] [unique_id "al4SwRKaHUf6J8d3elJY8gAAAKE"]
[Mon Jul 20 06:21:21.445735 2026] [security2:error] [pid 884009:tid 884149] [client 77.110.127.138:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpHWFmZkzP'))%20OR%20928=(SELECT%20928%20FROM%20PG_SLEEP(15))--"] [unique_id "al4SwRKaHUf6J8d3elJY9QAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:21.611599 2026] [security2:error] [pid 884009:tid 884171] [client 82.102.18.116:56122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SwRKaHUf6J8d3elJZBAAAAKM"]
[Mon Jul 20 06:21:21.652292 2026] [security2:error] [pid 884009:tid 884140] [client 185.132.186.68:63337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wordpress/wp-admin/includes/admin-filters.php"] [unique_id "al4SwRKaHUf6J8d3elJZBwAAAIU"]
[Mon Jul 20 06:21:21.779005 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:65272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYvgAAAIk"], referer: http://retzkolonglogistics.com/Wp
[Mon Jul 20 06:21:21.854206 2026] [security2:error] [pid 884009:tid 884245] [client 4.194.217.15:1437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sang.php"] [unique_id "al4SwRKaHUf6J8d3elJZFgAAAO0"]
[Mon Jul 20 06:21:21.949547 2026] [security2:error] [pid 884009:tid 884206] [client 82.102.18.116:56136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4SwRKaHUf6J8d3elJZHwAAAMY"]
[Mon Jul 20 06:21:22.268238 2026] [security2:error] [pid 884009:tid 884210] [client 82.102.18.116:56138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4SwhKaHUf6J8d3elJZPwAAAMo"]
[Mon Jul 20 06:21:22.331533 2026] [security2:error] [pid 884009:tid 884018] [remote 91.142.222.105:54874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SwhKaHUf6J8d3elJZQwAArwc"]
[Mon Jul 20 06:21:22.331722 2026] [security2:error] [pid 884009:tid 884183] [client 91.142.222.105:54874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SwhKaHUf6J8d3elJZQwAArwc"]
[Mon Jul 20 06:21:22.394261 2026] [security2:error] [pid 884009:tid 884152] [client 57.141.18.103:39018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYDgAAkSY"]
[Mon Jul 20 06:21:22.395647 2026] [security2:error] [pid 884009:tid 884163] [client 4.194.217.15:7473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/scxy.php"] [unique_id "al4SwhKaHUf6J8d3elJZRwAAAJw"]
[Mon Jul 20 06:21:22.587845 2026] [security2:error] [pid 884009:tid 884242] [client 82.102.18.116:56152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SwhKaHUf6J8d3elJZWQAAAOo"]
[Mon Jul 20 06:21:22.810169 2026] [security2:error] [pid 884009:tid 884186] [client 50.116.65.227:58816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SwhKaHUf6J8d3elJZbAAAALI"]
[Mon Jul 20 06:21:22.821560 2026] [security2:error] [pid 884009:tid 884175] [client 50.116.65.227:20992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SwhKaHUf6J8d3elJZbwAAAKc"]
[Mon Jul 20 06:21:22.901953 2026] [security2:error] [pid 884009:tid 884233] [client 82.102.18.116:56158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SwhKaHUf6J8d3elJZcgAAAOE"]
[Mon Jul 20 06:21:22.974386 2026] [security2:error] [pid 884009:tid 884241] [client 4.194.217.15:7447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sd.php"] [unique_id "al4SwhKaHUf6J8d3elJZdgAAAOk"]
[Mon Jul 20 06:21:23.049677 2026] [security2:error] [pid 884009:tid 884212] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/git/.ssh/id_rsa"] [unique_id "al4SwxKaHUf6J8d3elJZfgAAAMw"], referer: https://t.co/cnk1sjj716
[Mon Jul 20 06:21:23.128422 2026] [security2:error] [pid 884009:tid 884150] [client 57.141.18.14:30440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SvxKaHUf6J8d3elJYYwAAj1Y"]
[Mon Jul 20 06:21:23.198292 2026] [security2:error] [pid 884009:tid 884199] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../home/admin/.ssh/id_rsa"] [unique_id "al4SwxKaHUf6J8d3elJZjgAAAL8"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:21:23.232684 2026] [security2:error] [pid 884009:tid 884253] [client 82.102.18.116:56174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZkQAAAPU"]
[Mon Jul 20 06:21:23.258030 2026] [security2:error] [pid 884009:tid 884157] [client 185.132.186.96:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/content.php"] [unique_id "al4SwxKaHUf6J8d3elJZlQAAAJY"]
[Mon Jul 20 06:21:23.285006 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.104:27552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYdgAAwTM"]
[Mon Jul 20 06:21:23.317658 2026] [security2:error] [pid 884009:tid 884188] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/passwd"] [unique_id "al4SwxKaHUf6J8d3elJZmwAAALQ"], referer: https://www.bing.com/search?q=pewasl
[Mon Jul 20 06:21:23.428058 2026] [security2:error] [pid 884009:tid 884222] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/shadow"] [unique_id "al4SwxKaHUf6J8d3elJZpgAAANY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:21:23.517717 2026] [security2:error] [pid 884009:tid 884218] [client 4.194.217.15:1439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sf.php"] [unique_id "al4SwxKaHUf6J8d3elJZsgAAANI"]
[Mon Jul 20 06:21:23.553853 2026] [security2:error] [pid 884009:tid 884236] [client 82.102.18.116:56188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZuAAAAOQ"]
[Mon Jul 20 06:21:23.560315 2026] [security2:error] [pid 884009:tid 884253] [client 103.153.183.69:11694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/hosts"] [unique_id "al4SwxKaHUf6J8d3elJZuQAAAPU"], referer: https://www.reddit.com/
[Mon Jul 20 06:21:23.697210 2026] [security2:error] [pid 884009:tid 884168] [client 14.225.17.146:64147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4SwhKaHUf6J8d3elJZOQAAAKE"], referer: http://uritems.net/Wp
[Mon Jul 20 06:21:23.808930 2026] [security2:error] [pid 884009:tid 884266] [client 34.73.38.214:54089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZywAAAQI"]
[Mon Jul 20 06:21:23.870571 2026] [security2:error] [pid 884009:tid 884238] [client 82.102.18.116:56202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4SwxKaHUf6J8d3elJZ0QAAAOY"]
[Mon Jul 20 06:21:23.986373 2026] [security2:error] [pid 884009:tid 884183] [client 34.74.185.202:57900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4SwxKaHUf6J8d3elJZ2QAAAK8"]
[Mon Jul 20 06:21:24.031878 2026] [security2:error] [pid 884009:tid 884153] [client 34.73.38.214:49384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJZ3wAAAJI"]
[Mon Jul 20 06:21:24.068653 2026] [security2:error] [pid 884009:tid 884144] [client 4.194.217.15:6546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/shell.php"] [unique_id "al4SxBKaHUf6J8d3elJZ4gAAAIk"]
[Mon Jul 20 06:21:24.095338 2026] [security2:error] [pid 884009:tid 884173] [client 57.141.18.65:40506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwBKaHUf6J8d3elJYuAAApTs"]
[Mon Jul 20 06:21:24.123961 2026] [security2:error] [pid 884009:tid 884178] [client 14.225.17.146:58952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4SwhKaHUf6J8d3elJZYwAAAKo"], referer: http://ghivs.com/Wp
[Mon Jul 20 06:21:24.219617 2026] [security2:error] [pid 884009:tid 884185] [client 82.102.18.116:56214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJZ9QAAALE"]
[Mon Jul 20 06:21:24.237920 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:59433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJZ-QAAAME"]
[Mon Jul 20 06:21:24.238012 2026] [security2:error] [pid 884009:tid 884201] [client 171.60.139.123:59433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJZ-QAAAME"]
[Mon Jul 20 06:21:24.475088 2026] [security2:error] [pid 884009:tid 884220] [client 34.73.38.214:50230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaDAAAANQ"]
[Mon Jul 20 06:21:24.563301 2026] [security2:error] [pid 884009:tid 884187] [client 14.225.17.146:57500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZkgAAALM"], referer: http://effingweirdmuseums.com/Wp
[Mon Jul 20 06:21:24.563787 2026] [security2:error] [pid 884009:tid 884174] [client 82.102.18.116:56220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaEgAAAKY"]
[Mon Jul 20 06:21:24.721165 2026] [security2:error] [pid 884009:tid 884152] [client 34.73.38.214:52675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaHgAAAJE"]
[Mon Jul 20 06:21:24.799972 2026] [security2:error] [pid 884009:tid 884265] [client 4.194.217.15:1431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sid3.php"] [unique_id "al4SxBKaHUf6J8d3elJaIwAAAQE"]
[Mon Jul 20 06:21:24.807801 2026] [security2:error] [pid 884009:tid 884256] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaEwAA-CQ"], referer: http://assasalnazaha.com/Wp
[Mon Jul 20 06:21:24.870976 2026] [security2:error] [pid 884009:tid 884191] [client 185.132.186.53:23819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/fm.php%20"] [unique_id "al4SxBKaHUf6J8d3elJaLAAAALc"]
[Mon Jul 20 06:21:24.883032 2026] [security2:error] [pid 884009:tid 884234] [client 34.73.38.214:50632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaLgAAAOI"]
[Mon Jul 20 06:21:24.889150 2026] [security2:error] [pid 884009:tid 884254] [client 82.102.18.116:7013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SxBKaHUf6J8d3elJaMQAAAPY"]
[Mon Jul 20 06:21:24.930933 2026] [security2:error] [pid 884009:tid 884223] [client 18.140.64.130:23998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJaQgAAANc"]
[Mon Jul 20 06:21:24.931034 2026] [security2:error] [pid 884009:tid 884223] [client 18.140.64.130:23998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SxBKaHUf6J8d3elJaQgAAANc"]
[Mon Jul 20 06:21:25.171270 2026] [security2:error] [pid 884009:tid 884214] [client 34.73.38.214:64018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJafgAAAM4"]
[Mon Jul 20 06:21:25.189389 2026] [security2:error] [pid 884009:tid 884243] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaTQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:25.233384 2026] [security2:error] [pid 884009:tid 884156] [client 14.225.17.146:64198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZxgAAAJU"], referer: http://cephasnext.com/Wp
[Mon Jul 20 06:21:25.240251 2026] [security2:error] [pid 884009:tid 884212] [client 82.102.18.116:56232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.southernswinggolfco.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJaiAAAAMw"]
[Mon Jul 20 06:21:25.341900 2026] [security2:error] [pid 884009:tid 884232] [client 4.194.217.15:7434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/simple.php"] [unique_id "al4SxRKaHUf6J8d3elJakwAAAOA"]
[Mon Jul 20 06:21:25.360298 2026] [security2:error] [pid 884009:tid 884202] [client 34.74.185.202:52124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJalQAAAMI"]
[Mon Jul 20 06:21:25.453102 2026] [security2:error] [pid 884009:tid 884159] [client 34.73.38.214:51843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJaoAAAAJg"]
[Mon Jul 20 06:21:25.465459 2026] [security2:error] [pid 884009:tid 884180] [client 57.141.18.112:28778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwhKaHUf6J8d3elJZSAAArBI"]
[Mon Jul 20 06:21:25.495393 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJapQAAALk"]
[Mon Jul 20 06:21:25.495492 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJapQAAALk"]
[Mon Jul 20 06:21:25.517524 2026] [security2:error] [pid 884009:tid 884207] [client 14.225.17.146:58861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJangAAAMc"], referer: https://effingweirdmuseums.com/Wp
[Mon Jul 20 06:21:25.546273 2026] [security2:error] [pid 884009:tid 884025] [remote 67.193.12.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJalAAAow4"], referer: https://www.aleishapenny.ca/
[Mon Jul 20 06:21:25.716164 2026] [security2:error] [pid 884009:tid 884267] [client 34.73.38.214:50084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJasQAAAQM"]
[Mon Jul 20 06:21:25.757144 2026] [security2:error] [pid 884009:tid 884225] [client 181.224.94.124:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.94.224.181.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJasgAAANk"]
[Mon Jul 20 06:21:25.757313 2026] [security2:error] [pid 884009:tid 884225] [client 181.224.94.124:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "709fx.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJasgAAANk"]
[Mon Jul 20 06:21:25.862981 2026] [security2:error] [pid 884009:tid 884260] [client 103.141.108.143:52265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJatAAAAPw"]
[Mon Jul 20 06:21:25.863109 2026] [security2:error] [pid 884009:tid 884260] [client 103.141.108.143:52265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4SxRKaHUf6J8d3elJatAAAAPw"]
[Mon Jul 20 06:21:25.894217 2026] [security2:error] [pid 884009:tid 884165] [client 4.194.217.15:6903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sitemap.php"] [unique_id "al4SxRKaHUf6J8d3elJauQAAAJ4"]
[Mon Jul 20 06:21:25.943895 2026] [security2:error] [pid 884009:tid 884246] [client 14.225.17.146:58878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJZ-AAAAO4"], referer: http://swafforddetailing.com/Wp
[Mon Jul 20 06:21:25.944535 2026] [security2:error] [pid 884009:tid 884194] [client 34.73.38.214:50729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SxRKaHUf6J8d3elJavgAAALo"]
[Mon Jul 20 06:21:26.115028 2026] [security2:error] [pid 884009:tid 884147] [client 27.96.94.195:37203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJazgAAAIw"]
[Mon Jul 20 06:21:26.115153 2026] [security2:error] [pid 884009:tid 884147] [client 27.96.94.195:37203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJazgAAAIw"]
[Mon Jul 20 06:21:26.120327 2026] [security2:error] [pid 884009:tid 884078] [remote 91.142.222.105:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJazQAAykM"]
[Mon Jul 20 06:21:26.173209 2026] [security2:error] [pid 884009:tid 884162] [client 57.141.18.24:21320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZfQAAm1o"]
[Mon Jul 20 06:21:26.237957 2026] [security2:error] [pid 884009:tid 884168] [client 34.73.38.214:52502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.supportinghands22.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4SxhKaHUf6J8d3elJa2AAAAKE"]
[Mon Jul 20 06:21:26.255359 2026] [security2:error] [pid 884009:tid 884189] [client 14.225.17.146:57446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaJAAAALU"], referer: http://blaizeaccountingservices.com/Wp
[Mon Jul 20 06:21:26.259675 2026] [security2:error] [pid 884009:tid 884172] [client 74.208.214.194:38146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SxhKaHUf6J8d3elJa3QAAAKQ"]
[Mon Jul 20 06:21:26.317041 2026] [security2:error] [pid 884009:tid 884184] [client 57.141.18.32:33282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SwxKaHUf6J8d3elJZiwAAsC0"]
[Mon Jul 20 06:21:26.439141 2026] [security2:error] [pid 884009:tid 884191] [client 4.194.217.15:6541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/size.php"] [unique_id "al4SxhKaHUf6J8d3elJa6gAAALc"]
[Mon Jul 20 06:21:26.440503 2026] [security2:error] [pid 884009:tid 884104] [remote 91.142.222.105:36316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJa6QAAul0"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 06:21:26.458822 2026] [security2:error] [pid 884009:tid 884177] [client 93.152.221.118:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grant-mechanical.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJa7wAAAKk"], referer: https://wordpress.org/
[Mon Jul 20 06:21:26.476725 2026] [security2:error] [pid 884009:tid 884158] [client 185.132.186.53:37469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/goods.php"] [unique_id "al4SxhKaHUf6J8d3elJa8AAAAJc"]
[Mon Jul 20 06:21:26.557640 2026] [security2:error] [pid 884009:tid 884166] [client 158.173.89.95:52685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SxhKaHUf6J8d3elJa_wAAAJ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:26.734882 2026] [security2:error] [pid 884009:tid 884141] [client 178.152.178.232:36003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbDgAAAIY"]
[Mon Jul 20 06:21:26.734986 2026] [security2:error] [pid 884009:tid 884141] [client 178.152.178.232:36003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbDgAAAIY"]
[Mon Jul 20 06:21:26.765513 2026] [security2:error] [pid 884009:tid 884263] [client 93.152.221.118:54722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grant-mechanical.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbFgAAAP8"]
[Mon Jul 20 06:21:26.792308 2026] [security2:error] [pid 884009:tid 884069] [remote 188.40.28.4:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbGAAAmzo"]
[Mon Jul 20 06:21:26.792643 2026] [security2:error] [pid 884009:tid 884103] [remote 188.166.241.141:36906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbGgAA9Vw"]
[Mon Jul 20 06:21:26.800256 2026] [security2:error] [pid 884009:tid 884251] [client 14.225.17.146:57478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4SxhKaHUf6J8d3elJa3gAAAPM"], referer: http://gearwaterproof.com/Wp
[Mon Jul 20 06:21:26.839771 2026] [security2:error] [pid 884009:tid 884099] [remote 78.46.157.202:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbHgAAiVg"]
[Mon Jul 20 06:21:26.840103 2026] [security2:error] [pid 884009:tid 884099] [remote 124.55.178.99:53376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbIQAA7Vg"]
[Mon Jul 20 06:21:26.840215 2026] [security2:error] [pid 884009:tid 884245] [client 124.55.178.99:53376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SxhKaHUf6J8d3elJbIQAA7Vg"]
[Mon Jul 20 06:21:26.845157 2026] [security2:error] [pid 884009:tid 884165] [client 34.74.185.202:56418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4SxhKaHUf6J8d3elJbIgAAAJ4"]
[Mon Jul 20 06:21:26.848494 2026] [security2:error] [pid 884009:tid 884081] [remote 20.153.140.50:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbIAAAq0Y"]
[Mon Jul 20 06:21:26.998484 2026] [security2:error] [pid 884009:tid 884100] [remote 188.40.28.4:60000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4SxhKaHUf6J8d3elJbKQAAxVk"], referer: https://crimargroup.com/wp-login.php
[Mon Jul 20 06:21:27.022526 2026] [security2:error] [pid 884009:tid 884185] [client 4.194.217.15:1449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sm.php"] [unique_id "al4SxxKaHUf6J8d3elJbLgAAALE"]
[Mon Jul 20 06:21:27.036563 2026] [security2:error] [pid 884009:tid 884023] [remote 78.46.157.202:56370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbMwAA3ww"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:21:27.171017 2026] [security2:error] [pid 884009:tid 884172] [client 77.110.127.138:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4SxxKaHUf6J8d3elJbPgAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:27.186343 2026] [security2:error] [pid 884009:tid 884049] [remote 188.166.241.141:36906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbQAAA3iY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:21:27.199408 2026] [security2:error] [pid 884009:tid 884170] [client 104.234.53.79:20903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4SxxKaHUf6J8d3elJbOAAAAKI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:27.232030 2026] [security2:error] [pid 884009:tid 884110] [remote 20.153.140.50:49468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbRwAA5WM"], referer: https://spencersadventures.com/wp-login.php
[Mon Jul 20 06:21:27.391229 2026] [security2:error] [pid 884009:tid 884186] [client 103.153.183.69:11694] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//proc/self/environ"] [unique_id "al4SxxKaHUf6J8d3elJbUwAAALI"], referer: https://www.facebook.com/
[Mon Jul 20 06:21:27.426743 2026] [security2:error] [pid 884009:tid 884218] [client 57.141.18.38:63838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxBKaHUf6J8d3elJaBgAA0i4"]
[Mon Jul 20 06:21:27.474707 2026] [security2:error] [pid 884009:tid 884236] [client 104.234.53.79:20903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4SxxKaHUf6J8d3elJbVwAAAOQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:27.596567 2026] [security2:error] [pid 884009:tid 884250] [client 4.194.217.15:7428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sql.php"] [unique_id "al4SxxKaHUf6J8d3elJbawAAAPI"]
[Mon Jul 20 06:21:27.705355 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:57362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbZgAAAKk"], referer: http://longevityperformanceclinic.com/Wp
[Mon Jul 20 06:21:27.977231 2026] [security2:error] [pid 884009:tid 884256] [client 34.74.185.202:51843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4SxxKaHUf6J8d3elJbfgAAAPg"]
[Mon Jul 20 06:21:28.087410 2026] [security2:error] [pid 884009:tid 884166] [client 185.132.186.103:51337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp-2019.php"] [unique_id "al4SyBKaHUf6J8d3elJbigAAAJ8"]
[Mon Jul 20 06:21:28.113614 2026] [security2:error] [pid 884009:tid 884178] [client 93.152.221.118:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4SyBKaHUf6J8d3elJbkAAAAKo"]
[Mon Jul 20 06:21:28.151355 2026] [security2:error] [pid 884009:tid 884215] [client 4.194.217.15:1444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/ss.php"] [unique_id "al4SyBKaHUf6J8d3elJblwAAAM8"]
[Mon Jul 20 06:21:28.187219 2026] [security2:error] [pid 884009:tid 884163] [client 14.225.17.146:58810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4SyBKaHUf6J8d3elJbjAAAAJw"], referer: http://travelbyfire.com/Wp
[Mon Jul 20 06:21:28.462383 2026] [security2:error] [pid 884009:tid 884265] [client 93.152.221.118:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4SyBKaHUf6J8d3elJbrQAAAQE"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:21:28.505974 2026] [security2:error] [pid 884009:tid 884182] [client 57.141.18.92:35852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJamgAArhE"]
[Mon Jul 20 06:21:28.509959 2026] [security2:error] [pid 884009:tid 884143] [client 57.141.18.109:26820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxRKaHUf6J8d3elJamwAAiCA"]
[Mon Jul 20 06:21:28.733699 2026] [security2:error] [pid 884009:tid 884195] [client 4.194.217.15:6887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/stats.php"] [unique_id "al4SyBKaHUf6J8d3elJbxQAAALs"]
[Mon Jul 20 06:21:28.801441 2026] [security2:error] [pid 884009:tid 884180] [client 43.205.139.3:62190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SyBKaHUf6J8d3elJbywAAAKw"]
[Mon Jul 20 06:21:28.801561 2026] [security2:error] [pid 884009:tid 884180] [client 43.205.139.3:62190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4SyBKaHUf6J8d3elJbywAAAKw"]
[Mon Jul 20 06:21:28.845065 2026] [security2:error] [pid 884009:tid 884153] [client 34.74.185.202:61879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4SyBKaHUf6J8d3elJb0gAAAJI"]
[Mon Jul 20 06:21:29.064104 2026] [security2:error] [pid 884009:tid 884213] [client 14.225.17.146:58923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb3QAAAM0"], referer: https://travelbyfire.com/Wp
[Mon Jul 20 06:21:29.074079 2026] [security2:error] [pid 884009:tid 884207] [client 14.225.17.146:58872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyBKaHUf6J8d3elJb1QAAAMc"], referer: http://fkconstructionfunding.com/Wp
[Mon Jul 20 06:21:29.317454 2026] [security2:error] [pid 884009:tid 884179] [client 4.194.217.15:6897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/sump1.php"] [unique_id "al4SyRKaHUf6J8d3elJb9wAAAKs"]
[Mon Jul 20 06:21:29.356669 2026] [security2:error] [pid 884009:tid 884239] [client 112.208.70.94:43855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_AAAAOc"]
[Mon Jul 20 06:21:29.356796 2026] [security2:error] [pid 884009:tid 884239] [client 112.208.70.94:43855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_AAAAOc"]
[Mon Jul 20 06:21:29.389330 2026] [security2:error] [pid 884009:tid 884166] [client 50.116.65.227:15224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb6gAAAJ8"]
[Mon Jul 20 06:21:29.450035 2026] [security2:error] [pid 884009:tid 884170] [client 171.61.165.146:18762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_wAAAKI"]
[Mon Jul 20 06:21:29.450217 2026] [security2:error] [pid 884009:tid 884170] [client 171.61.165.146:18762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJb_wAAAKI"]
[Mon Jul 20 06:21:29.502769 2026] [security2:error] [pid 884009:tid 884165] [client 41.173.37.102:8447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJcAgAAAJ4"]
[Mon Jul 20 06:21:29.502914 2026] [security2:error] [pid 884009:tid 884165] [client 41.173.37.102:8447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4SyRKaHUf6J8d3elJcAgAAAJ4"]
[Mon Jul 20 06:21:29.580676 2026] [security2:error] [pid 884009:tid 884184] [client 50.116.65.227:15226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb_QAAALA"]
[Mon Jul 20 06:21:29.585972 2026] [security2:error] [pid 884009:tid 884257] [client 34.74.185.202:50254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4SyRKaHUf6J8d3elJcBwAAAPk"]
[Mon Jul 20 06:21:29.702407 2026] [security2:error] [pid 884009:tid 884167] [client 185.132.186.104:38701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/SimplePie/info.php"] [unique_id "al4SyRKaHUf6J8d3elJcEwAAAKA"]
[Mon Jul 20 06:21:29.789788 2026] [security2:error] [pid 884009:tid 884258] [client 57.141.18.20:38590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxhKaHUf6J8d3elJbFQAA-lI"]
[Mon Jul 20 06:21:29.845375 2026] [security2:error] [pid 884009:tid 884122] [remote 167.233.114.32:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SyRKaHUf6J8d3elJcHgAA7m8"]
[Mon Jul 20 06:21:29.853646 2026] [security2:error] [pid 884009:tid 884166] [client 50.116.65.227:15234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4SyRKaHUf6J8d3elJcIAAAAJ8"]
[Mon Jul 20 06:21:29.864383 2026] [security2:error] [pid 884009:tid 884201] [client 50.116.65.227:15236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4SyRKaHUf6J8d3elJcIwAAAME"]
[Mon Jul 20 06:21:29.899352 2026] [security2:error] [pid 884009:tid 884256] [client 4.194.217.15:1459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system.php"] [unique_id "al4SyRKaHUf6J8d3elJcJwAAAPg"]
[Mon Jul 20 06:21:30.038534 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.100:20136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbLwAA0wQ"]
[Mon Jul 20 06:21:30.108724 2026] [security2:error] [pid 884009:tid 884168] [client 14.225.17.146:58993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJcKQAAAKE"], referer: https://fkconstructionfunding.com/Wp
[Mon Jul 20 06:21:30.126886 2026] [security2:error] [pid 884009:tid 884023] [remote 167.233.114.32:37746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJcTwAAjww"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:21:30.221901 2026] [security2:error] [pid 884009:tid 884178] [client 104.234.53.75:24617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4SyhKaHUf6J8d3elJcZQAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:30.331870 2026] [security2:error] [pid 884009:tid 884114] [remote 188.95.113.76:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJcmQAAw2c"]
[Mon Jul 20 06:21:30.351372 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.114:62152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbTwAA90Q"]
[Mon Jul 20 06:21:30.359968 2026] [security2:error] [pid 884009:tid 884023] [remote 38.242.157.30:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJczQAA1gw"]
[Mon Jul 20 06:21:30.382225 2026] [security2:error] [pid 884009:tid 884018] [remote 5.161.225.162:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "careysheatingandcooling.com"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJc0AAAwgc"]
[Mon Jul 20 06:21:30.490840 2026] [security2:error] [pid 884009:tid 884176] [client 4.194.217.15:6900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4SyhKaHUf6J8d3elJdEQAAAKg"]
[Mon Jul 20 06:21:30.562743 2026] [security2:error] [pid 884009:tid 884121] [remote 38.242.157.30:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdHwAAom4"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:21:30.564130 2026] [security2:error] [pid 884009:tid 884135] [remote 188.95.113.76:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdIAAA9Hw"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 06:21:30.634610 2026] [security2:error] [pid 884009:tid 884105] [remote 47.128.48.165:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "atyourconveniencehealth.com"] [uri "/robots.txt"] [unique_id "al4SyhKaHUf6J8d3elJdKAAA8l4"]
[Mon Jul 20 06:21:30.743883 2026] [security2:error] [pid 884009:tid 884067] [remote 5.161.225.162:44586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "careysheatingandcooling.com"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdLgAA4Tg"], referer: https://careysheatingandcooling.com/wp-login.php
[Mon Jul 20 06:21:30.749157 2026] [security2:error] [pid 884009:tid 884245] [client 14.224.227.113:54372] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4SyhKaHUf6J8d3elJdLwAAAO0"]
[Mon Jul 20 06:21:30.769613 2026] [security2:error] [pid 884009:tid 884229] [client 50.116.65.227:33476] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SyhKaHUf6J8d3elJdMgAAAN0"]
[Mon Jul 20 06:21:30.780003 2026] [security2:error] [pid 884009:tid 884171] [client 50.116.65.227:15266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4SyhKaHUf6J8d3elJdNAAAAKM"]
[Mon Jul 20 06:21:30.801095 2026] [security2:error] [pid 884009:tid 884240] [client 34.74.185.202:50276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4SyhKaHUf6J8d3elJdNwAAAOg"]
[Mon Jul 20 06:21:30.811795 2026] [security2:error] [pid 884009:tid 884151] [client 57.141.18.22:25834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SxxKaHUf6J8d3elJbeAAAkHY"]
[Mon Jul 20 06:21:30.852986 2026] [security2:error] [pid 884009:tid 884093] [remote 95.217.78.234:34956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4SyhKaHUf6J8d3elJdOwAA6VI"]
[Mon Jul 20 06:21:31.045127 2026] [security2:error] [pid 884009:tid 884238] [client 4.194.217.15:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4SyxKaHUf6J8d3elJdSwAAAOY"]
[Mon Jul 20 06:21:31.080558 2026] [security2:error] [pid 884009:tid 884047] [remote 95.217.78.234:34956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4SyxKaHUf6J8d3elJdTQAA2CQ"], referer: https://according2plant.com/wp-login.php
[Mon Jul 20 06:21:31.143797 2026] [security2:error] [pid 884009:tid 884074] [remote 45.90.123.233:37904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdUQAAqD8"]
[Mon Jul 20 06:21:31.144051 2026] [security2:error] [pid 884009:tid 884176] [client 45.90.123.233:37904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdUQAAqD8"]
[Mon Jul 20 06:21:31.197968 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:57663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4SyhKaHUf6J8d3elJdKwAAAJ0"], referer: http://onewingpictures.com/Wp
[Mon Jul 20 06:21:31.320346 2026] [security2:error] [pid 884009:tid 884173] [client 185.132.186.65:42881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/assets/images/cloud.php"] [unique_id "al4SyxKaHUf6J8d3elJdYgAAAKU"]
[Mon Jul 20 06:21:31.339347 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:60972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SyxKaHUf6J8d3elJdZAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:31.339440 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:60972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4SyxKaHUf6J8d3elJdZAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:31.430595 2026] [security2:error] [pid 884009:tid 884211] [client 34.74.185.202:61322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4SyxKaHUf6J8d3elJdagAAAMs"]
[Mon Jul 20 06:21:31.446505 2026] [security2:error] [pid 884009:tid 884179] [client 74.208.214.194:38160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4SyxKaHUf6J8d3elJdbQAAAKs"]
[Mon Jul 20 06:21:31.588726 2026] [security2:error] [pid 884009:tid 884190] [client 158.173.166.181:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4SyxKaHUf6J8d3elJddQAAALY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:31.591806 2026] [security2:error] [pid 884009:tid 884227] [client 4.194.217.15:1927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/system_log.php"] [unique_id "al4SyxKaHUf6J8d3elJddgAAANs"]
[Mon Jul 20 06:21:31.672682 2026] [security2:error] [pid 884009:tid 884015] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdewAAoQQ"]
[Mon Jul 20 06:21:31.672864 2026] [security2:error] [pid 884009:tid 884168] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4SyxKaHUf6J8d3elJdewAAoQQ"]
[Mon Jul 20 06:21:32.075394 2026] [security2:error] [pid 884009:tid 884127] [remote 216.73.217.138:3235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4SzBKaHUf6J8d3elJdmQAA8XQ"]
[Mon Jul 20 06:21:32.133424 2026] [security2:error] [pid 884009:tid 884173] [client 4.194.217.15:9951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/t.php"] [unique_id "al4SzBKaHUf6J8d3elJdmwAAAKU"]
[Mon Jul 20 06:21:32.265550 2026] [security2:error] [pid 884009:tid 884267] [client 57.141.18.54:34614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJb4QABA3I"]
[Mon Jul 20 06:21:32.350084 2026] [security2:error] [pid 884009:tid 884183] [client 34.74.185.202:54031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4SzBKaHUf6J8d3elJdrAAAAK8"]
[Mon Jul 20 06:21:32.454030 2026] [security2:error] [pid 884009:tid 884205] [client 14.251.3.155:61285] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4SzBKaHUf6J8d3elJdugAAAMU"]
[Mon Jul 20 06:21:32.757468 2026] [security2:error] [pid 884009:tid 884151] [client 4.194.217.15:1946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/term.php"] [unique_id "al4SzBKaHUf6J8d3elJd0QAAAJA"]
[Mon Jul 20 06:21:32.768478 2026] [core:error] [pid 884009:tid 884228] [client 103.153.183.69:33978] AH10244: invalid URI path (/%2e%2e/.env?_=kuccc95i&v=g4acr), referer: https://t.co/r3gn8iifs1
[Mon Jul 20 06:21:32.926003 2026] [security2:error] [pid 884009:tid 884222] [client 185.132.186.61:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/log.php"] [unique_id "al4SzBKaHUf6J8d3elJd4gAAANY"]
[Mon Jul 20 06:21:33.143840 2026] [security2:error] [pid 884009:tid 884257] [client 108.174.8.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4SyhKaHUf6J8d3elJc7gAA-Rk"]
[Mon Jul 20 06:21:33.217395 2026] [security2:error] [pid 884009:tid 884180] [client 57.141.18.47:36128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJcJgAArDk"]
[Mon Jul 20 06:21:33.313158 2026] [security2:error] [pid 884009:tid 884199] [client 57.141.18.78:24008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SyRKaHUf6J8d3elJcLwAAv3k"]
[Mon Jul 20 06:21:33.317448 2026] [security2:error] [pid 884009:tid 884161] [client 4.194.217.15:6875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/test.php"] [unique_id "al4SzRKaHUf6J8d3elJeAQAAAJo"]
[Mon Jul 20 06:21:33.722086 2026] [security2:error] [pid 884009:tid 884237] [client 34.74.185.202:62858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4SzRKaHUf6J8d3elJeJwAAAOU"]
[Mon Jul 20 06:21:33.902326 2026] [security2:error] [pid 884009:tid 884167] [client 4.194.217.15:9924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/test1.php"] [unique_id "al4SzRKaHUf6J8d3elJeNwAAAKA"]
[Mon Jul 20 06:21:33.941631 2026] [security2:error] [pid 884009:tid 884121] [remote 152.228.213.32:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzRKaHUf6J8d3elJePAAA6W4"]
[Mon Jul 20 06:21:33.941769 2026] [security2:error] [pid 884009:tid 884241] [client 152.228.213.32:58046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzRKaHUf6J8d3elJePAAA6W4"]
[Mon Jul 20 06:21:34.276017 2026] [security2:error] [pid 884009:tid 884055] [remote 97.74.93.24:47460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SzhKaHUf6J8d3elJeWAAAvSw"]
[Mon Jul 20 06:21:34.536116 2026] [security2:error] [pid 884009:tid 884233] [client 185.132.186.66:30067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-react-refresh-runtime-num.php"] [unique_id "al4SzhKaHUf6J8d3elJebQAAAOE"]
[Mon Jul 20 06:21:34.601449 2026] [security2:error] [pid 884009:tid 884253] [client 4.194.217.15:1958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/tfm.php"] [unique_id "al4SzhKaHUf6J8d3elJedAAAAPU"]
[Mon Jul 20 06:21:34.608411 2026] [security2:error] [pid 884009:tid 884058] [remote 109.123.245.117:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.245.123.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJecwAA_y8"]
[Mon Jul 20 06:21:34.608613 2026] [security2:error] [pid 884009:tid 884263] [client 109.123.245.117:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJecwAA_y8"]
[Mon Jul 20 06:21:34.695290 2026] [security2:error] [pid 884009:tid 884074] [remote 91.142.222.105:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SzhKaHUf6J8d3elJeegAAoz8"]
[Mon Jul 20 06:21:34.760924 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:49444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4SzhKaHUf6J8d3elJedQAAAJo"], referer: http://nextlvlmarketingco.com/Wp
[Mon Jul 20 06:21:34.780457 2026] [security2:error] [pid 884009:tid 884053] [remote 97.74.93.24:47460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4SzhKaHUf6J8d3elJefgAA0Co"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:21:34.904372 2026] [security2:error] [pid 884009:tid 884259] [client 171.60.139.123:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJegwAAAPs"]
[Mon Jul 20 06:21:34.904503 2026] [security2:error] [pid 884009:tid 884259] [client 171.60.139.123:59933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4SzhKaHUf6J8d3elJegwAAAPs"]
[Mon Jul 20 06:21:34.928485 2026] [proxy:error] [pid 884009:tid 884255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:34.928518 2026] [proxy_http:error] [pid 884009:tid 884255] [client 159.65.202.56:39586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:21:34.929216 2026] [proxy:error] [pid 884009:tid 884255] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:34.929241 2026] [proxy_http:error] [pid 884009:tid 884255] [client 159.65.202.56:39586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:21:35.025177 2026] [security2:error] [pid 884009:tid 884254] [client 34.74.185.202:58659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4SzxKaHUf6J8d3elJekAAAAPY"]
[Mon Jul 20 06:21:35.065854 2026] [security2:error] [pid 884009:tid 884103] [remote 91.142.222.105:57124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4SzxKaHUf6J8d3elJelgAAq1w"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:21:35.184841 2026] [security2:error] [pid 884009:tid 884145] [client 4.194.217.15:9920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/thebe.php"] [unique_id "al4SzxKaHUf6J8d3elJeoQAAAIo"]
[Mon Jul 20 06:21:35.218184 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:35.218281 2026] [proxy_http:error] [pid 884009:tid 884208] [client 159.65.202.56:39602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dadanetnet.net/
[Mon Jul 20 06:21:35.219963 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:21:35.220024 2026] [proxy_http:error] [pid 884009:tid 884208] [client 159.65.202.56:39602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.dadanetnet.net/
[Mon Jul 20 06:21:35.258856 2026] [security2:error] [pid 884009:tid 884212] [client 52.109.124.141:28746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SzxKaHUf6J8d3elJepAAAAMw"]
[Mon Jul 20 06:21:35.352028 2026] [security2:error] [pid 884009:tid 884239] [client 52.109.124.141:30656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4SzxKaHUf6J8d3elJesQAAAOc"]
[Mon Jul 20 06:21:35.438823 2026] [security2:error] [pid 884009:tid 884156] [client 52.109.124.141:28746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SzxKaHUf6J8d3elJexQAAAJU"]
[Mon Jul 20 06:21:35.533355 2026] [security2:error] [pid 884009:tid 884228] [client 52.109.124.141:30656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4SzxKaHUf6J8d3elJezAAAANw"]
[Mon Jul 20 06:21:35.761393 2026] [security2:error] [pid 884009:tid 884208] [client 4.194.217.15:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/themes.php"] [unique_id "al4SzxKaHUf6J8d3elJe3gAAAMg"]
[Mon Jul 20 06:21:35.859793 2026] [core:error] [pid 884009:tid 884267] [client 159.65.202.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:35.859815 2026] [core:error] [pid 884009:tid 884267] [client 159.65.202.56:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:21:35.890917 2026] [security2:error] [pid 884009:tid 884176] [client 77.110.127.138:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4SzxKaHUf6J8d3elJe6wAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:36.084416 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJe-wAAALk"]
[Mon Jul 20 06:21:36.084505 2026] [security2:error] [pid 884009:tid 884193] [client 45.116.69.230:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJe-wAAALk"]
[Mon Jul 20 06:21:36.168496 2026] [security2:error] [pid 884009:tid 884252] [client 185.132.186.75:37137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/script-loader-react-refresh-entry.min-object.php"] [unique_id "al4S0BKaHUf6J8d3elJe_wAAAPQ"]
[Mon Jul 20 06:21:36.325293 2026] [security2:error] [pid 884009:tid 884232] [client 4.194.217.15:1737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/tiny.php"] [unique_id "al4S0BKaHUf6J8d3elJfBgAAAOA"]
[Mon Jul 20 06:21:36.400785 2026] [security2:error] [pid 884009:tid 884173] [client 34.74.185.202:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S0BKaHUf6J8d3elJfCAAAAKU"]
[Mon Jul 20 06:21:36.404644 2026] [security2:error] [pid 884009:tid 884186] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4SzxKaHUf6J8d3elJe8QAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:36.497008 2026] [security2:error] [pid 884009:tid 884244] [client 103.141.108.143:52746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfEgAAAOw"]
[Mon Jul 20 06:21:36.497352 2026] [security2:error] [pid 884009:tid 884244] [client 103.141.108.143:52746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfEgAAAOw"]
[Mon Jul 20 06:21:36.549730 2026] [security2:error] [pid 884009:tid 884144] [client 57.141.18.30:55976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzRKaHUf6J8d3elJd_AAAiWY"]
[Mon Jul 20 06:21:36.715304 2026] [security2:error] [pid 884009:tid 884170] [client 57.141.18.126:63920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzRKaHUf6J8d3elJeAgAAojc"]
[Mon Jul 20 06:21:36.865887 2026] [security2:error] [pid 884009:tid 884175] [client 34.73.38.214:54317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S0BKaHUf6J8d3elJfNwAAAKc"]
[Mon Jul 20 06:21:36.867032 2026] [security2:error] [pid 884009:tid 884228] [client 4.194.217.15:1730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/tmp/byp.php"] [unique_id "al4S0BKaHUf6J8d3elJfOAAAANw"]
[Mon Jul 20 06:21:36.917830 2026] [security2:error] [pid 884009:tid 884232] [client 34.74.185.202:63550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.bzm.ppv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S0BKaHUf6J8d3elJfPAAAAOA"]
[Mon Jul 20 06:21:36.945790 2026] [security2:error] [pid 884009:tid 884235] [client 27.96.94.195:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfQQAAAOM"]
[Mon Jul 20 06:21:36.945905 2026] [security2:error] [pid 884009:tid 884235] [client 27.96.94.195:37522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S0BKaHUf6J8d3elJfQQAAAOM"]
[Mon Jul 20 06:21:37.783442 2026] [security2:error] [pid 884009:tid 884144] [client 185.132.186.61:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/aw.php"] [unique_id "al4S0RKaHUf6J8d3elJfeAAAAIk"]
[Mon Jul 20 06:21:37.846196 2026] [security2:error] [pid 884009:tid 884203] [client 34.73.38.214:56996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S0RKaHUf6J8d3elJfgQAAAMM"]
[Mon Jul 20 06:21:37.917459 2026] [security2:error] [pid 884009:tid 884191] [client 14.225.17.146:53112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4S0BKaHUf6J8d3elJfKAAAALc"], referer: http://elitetax-mi.com/Wp
[Mon Jul 20 06:21:38.016593 2026] [security2:error] [pid 884009:tid 884168] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S0RKaHUf6J8d3elJffQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:38.216413 2026] [security2:error] [pid 884009:tid 884226] [client 104.234.53.62:31589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfnwAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:38.281873 2026] [security2:error] [pid 884009:tid 884104] [remote 217.61.143.92:48906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfoQAAyV0"]
[Mon Jul 20 06:21:38.320794 2026] [security2:error] [pid 884009:tid 884175] [client 50.116.65.227:33492] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S0hKaHUf6J8d3elJfowAAAKc"]
[Mon Jul 20 06:21:38.332832 2026] [security2:error] [pid 884009:tid 884199] [client 50.116.65.227:15326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S0hKaHUf6J8d3elJfpQAAAME"]
[Mon Jul 20 06:21:38.590396 2026] [security2:error] [pid 884009:tid 884126] [remote 217.61.143.92:48906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfuwAAsnM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:38.626575 2026] [security2:error] [pid 884009:tid 884046] [remote 209.42.18.223:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJfvQAA9yM"]
[Mon Jul 20 06:21:38.842901 2026] [security2:error] [pid 884009:tid 884069] [remote 209.42.18.223:56982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4S0hKaHUf6J8d3elJf2gAA5Do"], referer: https://mail.transamericagrid.com/wp-login.php
[Mon Jul 20 06:21:39.389763 2026] [security2:error] [pid 884009:tid 884238] [client 14.225.17.146:49546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4S0RKaHUf6J8d3elJfegAAAOY"], referer: http://maplerespiteservices.com/Wp
[Mon Jul 20 06:21:39.403854 2026] [security2:error] [pid 884009:tid 884162] [client 185.132.186.61:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/update/gely.php"] [unique_id "al4S0xKaHUf6J8d3elJgBAAAAJs"]
[Mon Jul 20 06:21:39.458531 2026] [security2:error] [pid 884009:tid 884210] [client 77.110.127.138:60996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4S0xKaHUf6J8d3elJgCgAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:39.473414 2026] [security2:error] [pid 884009:tid 884190] [client 34.73.38.214:51727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S0xKaHUf6J8d3elJgDAAAALY"]
[Mon Jul 20 06:21:39.640581 2026] [security2:error] [pid 884009:tid 884260] [client 57.141.18.47:36132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzxKaHUf6J8d3elJe0gAA_A0"]
[Mon Jul 20 06:21:39.787655 2026] [security2:error] [pid 884009:tid 884112] [remote 100.42.189.89:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4S0xKaHUf6J8d3elJgJwAAvmU"]
[Mon Jul 20 06:21:39.812985 2026] [security2:error] [pid 884009:tid 884212] [client 57.141.18.23:41992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4SzxKaHUf6J8d3elJe5AAAzC4"]
[Mon Jul 20 06:21:39.839786 2026] [core:error] [pid 884009:tid 884231] [client 14.225.17.146:55389] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wp
[Mon Jul 20 06:21:39.839809 2026] [core:error] [pid 884009:tid 884231] [client 14.225.17.146:55389] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Wp
[Mon Jul 20 06:21:40.018194 2026] [security2:error] [pid 884009:tid 884133] [remote 100.42.189.89:43906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgSAAA0Xo"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:21:40.088104 2026] [security2:error] [pid 884009:tid 884256] [client 41.173.37.102:8863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgUAAAAPg"]
[Mon Jul 20 06:21:40.088252 2026] [security2:error] [pid 884009:tid 884256] [client 41.173.37.102:8863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgUAAAAPg"]
[Mon Jul 20 06:21:40.111655 2026] [security2:error] [pid 884009:tid 884209] [client 40.77.167.152:55831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgPgAAyX0"]
[Mon Jul 20 06:21:40.162873 2026] [security2:error] [pid 884009:tid 884258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgNgAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:40.226996 2026] [security2:error] [pid 884009:tid 884187] [client 104.234.53.87:27737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgTQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:40.252800 2026] [security2:error] [pid 884009:tid 884203] [client 171.61.165.146:16181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgWwAAAMM"]
[Mon Jul 20 06:21:40.252907 2026] [security2:error] [pid 884009:tid 884203] [client 171.61.165.146:16181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1BKaHUf6J8d3elJgWwAAAMM"]
[Mon Jul 20 06:21:40.288190 2026] [security2:error] [pid 884009:tid 884079] [remote 188.138.102.156:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgXgAA_EQ"]
[Mon Jul 20 06:21:40.375823 2026] [security2:error] [pid 884009:tid 884156] [client 50.116.65.227:59192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S1BKaHUf6J8d3elJgYgAAAJU"]
[Mon Jul 20 06:21:40.386253 2026] [security2:error] [pid 884009:tid 884201] [client 50.116.65.227:59204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S1BKaHUf6J8d3elJgYwAAAME"]
[Mon Jul 20 06:21:40.482364 2026] [security2:error] [pid 884009:tid 884107] [remote 188.138.102.156:58184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgawAA0WA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:21:40.523469 2026] [security2:error] [pid 884009:tid 884182] [client 14.225.17.146:55471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgMgAAAK4"], referer: http://carolinapressurewashers.com/Wp
[Mon Jul 20 06:21:40.726184 2026] [security2:error] [pid 884009:tid 884224] [client 34.73.38.214:53152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S1BKaHUf6J8d3elJghgAAANg"]
[Mon Jul 20 06:21:40.815467 2026] [security2:error] [pid 884009:tid 884147] [client 104.234.53.87:27737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4S1BKaHUf6J8d3elJgiAAAAIw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:41.011929 2026] [security2:error] [pid 884009:tid 884217] [client 185.132.186.88:44211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/c99shell.php"] [unique_id "al4S1RKaHUf6J8d3elJgmgAAANE"]
[Mon Jul 20 06:21:41.260869 2026] [security2:error] [pid 884009:tid 884179] [client 14.225.17.146:55358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4S0xKaHUf6J8d3elJgLgAAAKs"], referer: http://dnsplumbing.com/Wp
[Mon Jul 20 06:21:41.266355 2026] [security2:error] [pid 884009:tid 884026] [remote 81.173.115.7:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4S1RKaHUf6J8d3elJgsQAAmw8"]
[Mon Jul 20 06:21:41.382362 2026] [security2:error] [pid 884009:tid 884252] [client 57.141.18.115:37548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S0RKaHUf6J8d3elJfYAAA9AM"]
[Mon Jul 20 06:21:41.454926 2026] [security2:error] [pid 884009:tid 884170] [client 185.192.69.18:55357] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/000.php"] [unique_id "al4S1RKaHUf6J8d3elJguwAAAKI"]
[Mon Jul 20 06:21:41.508882 2026] [security2:error] [pid 884009:tid 884129] [remote 81.173.115.7:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4S1RKaHUf6J8d3elJgwAAAtnY"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:21:41.554384 2026] [security2:error] [pid 884009:tid 884214] [client 40.77.167.152:55831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgjAAAzhY"]
[Mon Jul 20 06:21:41.866984 2026] [security2:error] [pid 884009:tid 884182] [client 77.110.127.138:61021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgzAAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:41.907862 2026] [security2:error] [pid 884009:tid 884240] [client 185.192.69.19:52385] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-admin/css/index.php"] [unique_id "al4S1RKaHUf6J8d3elJg4gAAAOg"]
[Mon Jul 20 06:21:42.139664 2026] [security2:error] [pid 884009:tid 884088] [remote 152.228.213.32:47944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJg-QAAhk0"]
[Mon Jul 20 06:21:42.139925 2026] [security2:error] [pid 884009:tid 884141] [client 152.228.213.32:47944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJg-QAAhk0"]
[Mon Jul 20 06:21:42.267489 2026] [security2:error] [pid 884009:tid 884263] [client 57.141.18.82:55130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S0hKaHUf6J8d3elJfrwAA_y8"]
[Mon Jul 20 06:21:42.360305 2026] [security2:error] [pid 884009:tid 884183] [client 185.192.69.33:39277] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-content/plugins/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhCwAAAK8"]
[Mon Jul 20 06:21:42.398517 2026] [security2:error] [pid 884009:tid 884070] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhEAAAuTs"]
[Mon Jul 20 06:21:42.398704 2026] [security2:error] [pid 884009:tid 884193] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhEAAAuTs"]
[Mon Jul 20 06:21:42.418162 2026] [security2:error] [pid 884009:tid 884144] [client 74.7.230.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgyAAAAIk"]
[Mon Jul 20 06:21:42.418183 2026] [security2:error] [pid 884009:tid 884144] [client 74.7.230.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgyAAAAIk"]
[Mon Jul 20 06:21:42.428877 2026] [security2:error] [pid 884009:tid 884230] [client 74.7.230.29:56142] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/robots.txt"] [unique_id "al4S1RKaHUf6J8d3elJgwwAA3jE"]
[Mon Jul 20 06:21:42.446693 2026] [security2:error] [pid 884009:tid 884017] [remote 84.247.172.23:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4S1hKaHUf6J8d3elJhEwAA_QY"]
[Mon Jul 20 06:21:42.540825 2026] [security2:error] [pid 884009:tid 884232] [client 57.141.18.31:41934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S0hKaHUf6J8d3elJf0wAA4Fw"]
[Mon Jul 20 06:21:42.552555 2026] [security2:error] [pid 884009:tid 884174] [client 34.73.38.214:53539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S1hKaHUf6J8d3elJhGgAAAKY"]
[Mon Jul 20 06:21:42.620011 2026] [security2:error] [pid 884009:tid 884215] [client 185.132.186.73:51699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/pridmag/admin-footer.php"] [unique_id "al4S1hKaHUf6J8d3elJhHwAAAM8"]
[Mon Jul 20 06:21:42.667596 2026] [security2:error] [pid 884009:tid 884256] [client 74.7.230.29:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhIAAAAPg"], referer: https://processorstudio.com/robots.txt
[Mon Jul 20 06:21:42.712545 2026] [security2:error] [pid 884009:tid 884221] [client 74.7.230.29:56146] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/robots.txt"] [unique_id "al4S1hKaHUf6J8d3elJhHAAA1VU"], referer: https://processorstudio.com/robots.txt
[Mon Jul 20 06:21:42.748473 2026] [security2:error] [pid 884009:tid 884127] [remote 84.247.172.23:50958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4S1hKaHUf6J8d3elJhJQAAnHQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:21:42.815159 2026] [security2:error] [pid 884009:tid 884216] [client 185.192.69.16:42477] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-content/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhLAAAANA"]
[Mon Jul 20 06:21:42.824602 2026] [security2:error] [pid 884009:tid 884222] [client 112.208.70.94:44267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhKwAAANY"]
[Mon Jul 20 06:21:42.824760 2026] [security2:error] [pid 884009:tid 884222] [client 112.208.70.94:44267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S1hKaHUf6J8d3elJhKwAAANY"]
[Mon Jul 20 06:21:43.183346 2026] [security2:error] [pid 884009:tid 884234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhNgAAAOI"]
[Mon Jul 20 06:21:43.271057 2026] [security2:error] [pid 884009:tid 884167] [client 185.192.69.14:58731] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "genesismbs.com"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4S1xKaHUf6J8d3elJhUwAAAKA"]
[Mon Jul 20 06:21:43.344695 2026] [security2:error] [pid 884009:tid 884163] [client 34.73.38.214:52016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S1xKaHUf6J8d3elJhWgAAAJw"]
[Mon Jul 20 06:21:43.392830 2026] [security2:error] [pid 884009:tid 884175] [client 14.225.17.146:60223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4S1xKaHUf6J8d3elJhVQAAAKc"], referer: http://hammadownenterprises.com/Wp
[Mon Jul 20 06:21:43.570811 2026] [security2:error] [pid 884009:tid 884207] [client 34.73.38.214:53227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S1xKaHUf6J8d3elJhZQAAAMc"]
[Mon Jul 20 06:21:43.691142 2026] [fcgid:warn] [pid 884009:tid 884212] (70014)End of file found: [client 199.45.155.75:46296] mod_fcgid: can't get data from http client
[Mon Jul 20 06:21:43.852481 2026] [security2:error] [pid 884009:tid 884170] [client 14.225.17.146:55656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4S1hKaHUf6J8d3elJhCQAAAKI"], referer: http://olearyplumbingllc.com/Wp
[Mon Jul 20 06:21:44.060204 2026] [security2:error] [pid 884009:tid 884257] [client 34.73.38.214:57886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S2BKaHUf6J8d3elJhkQAAAPk"]
[Mon Jul 20 06:21:44.232850 2026] [security2:error] [pid 884009:tid 884152] [client 185.132.186.91:30687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/uploads/lala.php"] [unique_id "al4S2BKaHUf6J8d3elJhngAAAJE"]
[Mon Jul 20 06:21:44.332591 2026] [security2:error] [pid 884009:tid 884108] [remote 47.86.33.52:1892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S2BKaHUf6J8d3elJhqgAAjWE"]
[Mon Jul 20 06:21:44.338703 2026] [security2:error] [pid 884009:tid 884233] [client 34.73.38.214:63379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S2BKaHUf6J8d3elJhsAAAAOE"]
[Mon Jul 20 06:21:44.439022 2026] [security2:error] [pid 884009:tid 884061] [remote 130.51.180.8:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4S2BKaHUf6J8d3elJhuQAAuDI"]
[Mon Jul 20 06:21:44.530597 2026] [security2:error] [pid 884009:tid 884268] [client 57.141.18.33:37360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgZwABBDk"]
[Mon Jul 20 06:21:44.646700 2026] [security2:error] [pid 884009:tid 884114] [remote 130.51.180.8:43952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4S2BKaHUf6J8d3elJhwQAA5Gc"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:21:44.817477 2026] [security2:error] [pid 884009:tid 884174] [client 34.73.38.214:57820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S2BKaHUf6J8d3elJh1QAAAKY"]
[Mon Jul 20 06:21:44.939406 2026] [security2:error] [pid 884009:tid 884216] [client 104.234.53.66:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4S2BKaHUf6J8d3elJh4QAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:44.977666 2026] [fcgid:warn] [pid 884009:tid 884248] (70014)End of file found: [client 66.132.195.70:57698] mod_fcgid: can't get data from http client
[Mon Jul 20 06:21:45.039888 2026] [security2:error] [pid 884009:tid 884167] [client 77.110.127.138:61037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJhxQAAAKA"]
[Mon Jul 20 06:21:45.053970 2026] [security2:error] [pid 884009:tid 884140] [client 34.73.38.214:56669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S2RKaHUf6J8d3elJh5gAAAIU"]
[Mon Jul 20 06:21:45.094131 2026] [security2:error] [pid 884009:tid 884186] [client 57.141.18.8:54888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgiQAAsn4"]
[Mon Jul 20 06:21:45.099479 2026] [security2:error] [pid 884009:tid 884253] [client 57.141.18.85:40406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1BKaHUf6J8d3elJgiwAA9U4"]
[Mon Jul 20 06:21:45.409691 2026] [security2:error] [pid 884009:tid 884245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJh2gAAAO0"]
[Mon Jul 20 06:21:45.489159 2026] [security2:error] [pid 884009:tid 884206] [client 66.249.74.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.oohlovely.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJh5AAAAMY"]
[Mon Jul 20 06:21:45.536775 2026] [security2:error] [pid 884009:tid 884246] [client 103.153.183.69:32172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/etc/passwd"] [unique_id "al4S2RKaHUf6J8d3elJiFwAAAO4"], referer: https://www.reddit.com/
[Mon Jul 20 06:21:45.547456 2026] [security2:error] [pid 884009:tid 884242] [client 77.110.127.138:61008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJh-gAAAOo"]
[Mon Jul 20 06:21:45.607203 2026] [security2:error] [pid 884009:tid 884160] [client 34.73.38.214:58394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S2RKaHUf6J8d3elJiHgAAAJk"]
[Mon Jul 20 06:21:45.618462 2026] [security2:error] [pid 884009:tid 884162] [client 171.60.139.123:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S2RKaHUf6J8d3elJiIAAAAJs"]
[Mon Jul 20 06:21:45.618572 2026] [security2:error] [pid 884009:tid 884162] [client 171.60.139.123:60450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S2RKaHUf6J8d3elJiIAAAAJs"]
[Mon Jul 20 06:21:45.719636 2026] [security2:error] [pid 884009:tid 884166] [client 14.225.17.146:55741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4S1xKaHUf6J8d3elJhhQAAAJ8"], referer: http://fluidtemple.org/Wp
[Mon Jul 20 06:21:45.758188 2026] [security2:error] [pid 884009:tid 884204] [client 57.141.18.52:39144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S1RKaHUf6J8d3elJgxwAAxFI"]
[Mon Jul 20 06:21:45.805010 2026] [security2:error] [pid 884009:tid 884164] [client 34.73.38.214:53412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S2RKaHUf6J8d3elJiOQAAAJ0"]
[Mon Jul 20 06:21:45.847869 2026] [security2:error] [pid 884009:tid 884238] [client 185.132.186.79:54207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/IXR/db.php"] [unique_id "al4S2RKaHUf6J8d3elJiPQAAAOY"]
[Mon Jul 20 06:21:45.857010 2026] [security2:error] [pid 884009:tid 884201] [client 14.225.17.146:60429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiMwAAAME"], referer: http://iagdevelopments.com/Wp
[Mon Jul 20 06:21:45.901635 2026] [security2:error] [pid 884009:tid 884219] [client 14.225.17.146:55804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4S1xKaHUf6J8d3elJhigAAANM"], referer: http://areitoproducciones.com/Wp
[Mon Jul 20 06:21:45.929941 2026] [security2:error] [pid 884009:tid 884017] [remote 47.86.33.52:1892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S2RKaHUf6J8d3elJiRAAA3wY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:45.935044 2026] [security2:error] [pid 884009:tid 884229] [client 103.153.183.69:32172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e/.env"] [unique_id "al4S2RKaHUf6J8d3elJiSAAAAN0"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:21:46.024886 2026] [security2:error] [pid 884009:tid 884165] [client 114.119.147.42:26735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hedgerow-crafts.com"] [uri "/2019/02"] [unique_id "al4S2hKaHUf6J8d3elJiTwAAAJ4"], referer: https://www.hedgerow-crafts.com/img_1927/
[Mon Jul 20 06:21:46.196159 2026] [security2:error] [pid 884009:tid 884262] [client 14.251.3.155:54397] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4S2hKaHUf6J8d3elJiWAAAAP4"]
[Mon Jul 20 06:21:46.334397 2026] [security2:error] [pid 884009:tid 884202] [client 35.90.38.209:61434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4S2hKaHUf6J8d3elJiYQAAAMI"]
[Mon Jul 20 06:21:46.379714 2026] [security2:error] [pid 884009:tid 884230] [client 44.245.170.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cryptomeaning.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJhrQAAAN4"]
[Mon Jul 20 06:21:46.429211 2026] [security2:error] [pid 884009:tid 884263] [client 50.116.65.227:45976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4S2hKaHUf6J8d3elJiZQAAAP8"]
[Mon Jul 20 06:21:46.441422 2026] [security2:error] [pid 884009:tid 884186] [client 50.116.65.227:59322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4S2hKaHUf6J8d3elJiZgAAALI"]
[Mon Jul 20 06:21:46.500037 2026] [security2:error] [pid 884009:tid 884196] [client 34.73.38.214:53084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tco.chi.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S2hKaHUf6J8d3elJibgAAALw"]
[Mon Jul 20 06:21:46.735589 2026] [security2:error] [pid 884009:tid 884158] [client 34.73.38.214:57959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S2hKaHUf6J8d3elJihAAAAJc"]
[Mon Jul 20 06:21:46.743441 2026] [security2:error] [pid 884009:tid 884201] [client 45.116.69.230:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S2hKaHUf6J8d3elJigAAAAME"]
[Mon Jul 20 06:21:46.743579 2026] [security2:error] [pid 884009:tid 884201] [client 45.116.69.230:52454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S2hKaHUf6J8d3elJigAAAAME"]
[Mon Jul 20 06:21:46.755579 2026] [security2:error] [pid 884009:tid 884163] [client 14.225.17.146:49819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJh8gAAAJw"], referer: http://eduardsales.com/Wp
[Mon Jul 20 06:21:46.874123 2026] [security2:error] [pid 884009:tid 884159] [client 14.225.17.146:50147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4S2hKaHUf6J8d3elJihwAAAJg"], referer: https://iagdevelopments.com/Wp
[Mon Jul 20 06:21:47.136914 2026] [security2:error] [pid 884009:tid 884082] [remote 95.217.78.234:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4S2xKaHUf6J8d3elJipwAAoEc"]
[Mon Jul 20 06:21:47.180911 2026] [security2:error] [pid 884009:tid 884239] [client 103.141.108.143:53221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJirAAAAOc"]
[Mon Jul 20 06:21:47.181184 2026] [security2:error] [pid 884009:tid 884239] [client 103.141.108.143:53221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJirAAAAOc"]
[Mon Jul 20 06:21:47.391644 2026] [security2:error] [pid 884009:tid 884040] [remote 95.217.78.234:50670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4S2xKaHUf6J8d3elJiuwAA0h0"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 06:21:47.453006 2026] [security2:error] [pid 884009:tid 884263] [client 185.132.186.60:63667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/install.php"] [unique_id "al4S2xKaHUf6J8d3elJivgAAAP8"]
[Mon Jul 20 06:21:47.577062 2026] [security2:error] [pid 884009:tid 884240] [client 46.110.96.34:64610] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4S2xKaHUf6J8d3elJizgAAAOg"]
[Mon Jul 20 06:21:47.577401 2026] [security2:error] [pid 884009:tid 884193] [client 34.73.38.214:57210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S2xKaHUf6J8d3elJizwAAALk"]
[Mon Jul 20 06:21:47.594213 2026] [security2:error] [pid 884009:tid 884230] [client 13.229.223.11:30032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi0gAAAN4"]
[Mon Jul 20 06:21:47.594329 2026] [security2:error] [pid 884009:tid 884230] [client 13.229.223.11:30032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi0gAAAN4"]
[Mon Jul 20 06:21:47.645093 2026] [security2:error] [pid 884009:tid 884256] [client 178.152.178.232:36445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi1gAAAPg"]
[Mon Jul 20 06:21:47.645215 2026] [security2:error] [pid 884009:tid 884256] [client 178.152.178.232:36445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S2xKaHUf6J8d3elJi1gAAAPg"]
[Mon Jul 20 06:21:47.929857 2026] [security2:error] [pid 884009:tid 884232] [client 14.224.227.113:58410] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4S2xKaHUf6J8d3elJi7AAAAOA"]
[Mon Jul 20 06:21:48.037964 2026] [security2:error] [pid 884009:tid 884249] [client 114.119.142.73:47885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "massagelacey.com"] [uri "/ptsd-and-massage-therapy-in-lacey-wa/"] [unique_id "al4S3BKaHUf6J8d3elJi-QAAAPE"], referer: https://massagelacey.com/category/massage/page/6/
[Mon Jul 20 06:21:48.244993 2026] [security2:error] [pid 884009:tid 884145] [client 104.234.53.65:31339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4S3BKaHUf6J8d3elJjBwAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:48.288349 2026] [security2:error] [pid 884009:tid 884258] [client 14.225.17.146:50369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4S2xKaHUf6J8d3elJisgAAAPo"], referer: http://intelligentengineeringsolutions.com/Wp
[Mon Jul 20 06:21:48.320377 2026] [security2:error] [pid 884009:tid 884166] [client 77.110.127.138:61031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S3BKaHUf6J8d3elJjDQAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:48.320490 2026] [security2:error] [pid 884009:tid 884166] [client 77.110.127.138:61031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S3BKaHUf6J8d3elJjDQAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:48.545802 2026] [security2:error] [pid 884009:tid 884142] [client 34.73.38.214:50823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S3BKaHUf6J8d3elJjIQAAAIc"]
[Mon Jul 20 06:21:48.636775 2026] [security2:error] [pid 884009:tid 884222] [client 57.141.18.53:52262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2BKaHUf6J8d3elJhkgAA1jc"]
[Mon Jul 20 06:21:48.808968 2026] [security2:error] [pid 884009:tid 884223] [client 104.234.53.52:41793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4S3BKaHUf6J8d3elJjOQAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:49.063019 2026] [security2:error] [pid 884009:tid 884242] [client 185.132.186.77:29697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/plugins/wp-theme-editor/include.php%20"] [unique_id "al4S3RKaHUf6J8d3elJjTQAAAOo"]
[Mon Jul 20 06:21:49.150487 2026] [security2:error] [pid 884009:tid 884202] [client 27.96.94.195:37622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S3RKaHUf6J8d3elJjVwAAAMI"]
[Mon Jul 20 06:21:49.150579 2026] [security2:error] [pid 884009:tid 884202] [client 27.96.94.195:37622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S3RKaHUf6J8d3elJjVwAAAMI"]
[Mon Jul 20 06:21:49.432994 2026] [security2:error] [pid 884009:tid 884176] [client 34.73.38.214:52986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S3RKaHUf6J8d3elJjcAAAAKg"]
[Mon Jul 20 06:21:49.770635 2026] [security2:error] [pid 884009:tid 884199] [client 98.159.234.160:29811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S3RKaHUf6J8d3elJjhAAAAL8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:49.831682 2026] [security2:error] [pid 884009:tid 884183] [client 104.234.53.64:46135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4S3RKaHUf6J8d3elJjjAAAAK8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:21:49.937298 2026] [security2:error] [pid 884009:tid 884243] [client 57.141.18.20:33526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiBwAA63M"]
[Mon Jul 20 06:21:49.990900 2026] [security2:error] [pid 884009:tid 884220] [client 34.73.38.214:60650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S3RKaHUf6J8d3elJjmQAAANQ"]
[Mon Jul 20 06:21:50.051615 2026] [security2:error] [pid 884009:tid 884156] [client 50.116.65.227:29736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S3hKaHUf6J8d3elJjnAAAAJU"]
[Mon Jul 20 06:21:50.062721 2026] [security2:error] [pid 884009:tid 884203] [client 50.116.65.227:29750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S3hKaHUf6J8d3elJjnQAAAMM"]
[Mon Jul 20 06:21:50.179631 2026] [security2:error] [pid 884009:tid 884212] [client 57.141.18.49:26992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiGQAAzE0"]
[Mon Jul 20 06:21:50.360300 2026] [security2:error] [pid 884009:tid 884217] [client 57.141.18.104:36734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2RKaHUf6J8d3elJiKAAA0SI"]
[Mon Jul 20 06:21:50.621729 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:52910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjZQAAAIk"], referer: http://scott-assist.com/Wp
[Mon Jul 20 06:21:50.666285 2026] [security2:error] [pid 884009:tid 884225] [client 185.132.186.71:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/top.php"] [unique_id "al4S3hKaHUf6J8d3elJj2QAAANk"]
[Mon Jul 20 06:21:50.718051 2026] [security2:error] [pid 884009:tid 884196] [client 41.173.37.102:9280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S3hKaHUf6J8d3elJj2wAAALw"]
[Mon Jul 20 06:21:50.718176 2026] [security2:error] [pid 884009:tid 884196] [client 41.173.37.102:9280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S3hKaHUf6J8d3elJj2wAAALw"]
[Mon Jul 20 06:21:50.744290 2026] [security2:error] [pid 884009:tid 884140] [client 34.73.38.214:55614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S3hKaHUf6J8d3elJj3wAAAIU"]
[Mon Jul 20 06:21:50.876214 2026] [security2:error] [pid 884009:tid 884120] [remote 45.90.123.233:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S3hKaHUf6J8d3elJj7gAAv20"]
[Mon Jul 20 06:21:50.933939 2026] [security2:error] [pid 884009:tid 884195] [client 34.74.185.202:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4S3hKaHUf6J8d3elJj9AAAALs"]
[Mon Jul 20 06:21:51.081607 2026] [security2:error] [pid 884009:tid 884182] [client 34.73.38.214:51268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S3xKaHUf6J8d3elJj_AAAAK4"]
[Mon Jul 20 06:21:51.083809 2026] [security2:error] [pid 884009:tid 884037] [remote 45.90.123.233:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S3xKaHUf6J8d3elJj_QAA6Ro"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:51.126175 2026] [security2:error] [pid 884009:tid 884236] [client 14.225.17.146:64887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJj-gAAAOQ"], referer: http://grndl.com/Wp
[Mon Jul 20 06:21:51.252095 2026] [security2:error] [pid 884009:tid 884229] [client 14.225.17.146:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4S3hKaHUf6J8d3elJj9gAAAN0"], referer: http://dollpassionista.com/Wp
[Mon Jul 20 06:21:51.296487 2026] [security2:error] [pid 884009:tid 884192] [client 171.61.165.146:28243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S3xKaHUf6J8d3elJkGAAAALg"]
[Mon Jul 20 06:21:51.296665 2026] [security2:error] [pid 884009:tid 884192] [client 171.61.165.146:28243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S3xKaHUf6J8d3elJkGAAAALg"]
[Mon Jul 20 06:21:51.424407 2026] [security2:error] [pid 884009:tid 884168] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkFgAAAKE"]
[Mon Jul 20 06:21:51.506377 2026] [security2:error] [pid 884009:tid 884142] [client 14.225.17.146:63333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjkwAAAIc"], referer: http://idigress.group/Wp
[Mon Jul 20 06:21:51.523966 2026] [security2:error] [pid 884009:tid 884160] [client 34.73.38.214:56556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.tff.hws.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S3xKaHUf6J8d3elJkJQAAAJk"]
[Mon Jul 20 06:21:51.583719 2026] [security2:error] [pid 884009:tid 884164] [client 14.225.17.146:56843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkHwAAAJ0"], referer: http://koaconsultants.com/Wp
[Mon Jul 20 06:21:51.664168 2026] [security2:error] [pid 884009:tid 884248] [client 57.141.18.2:49222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2hKaHUf6J8d3elJikAAA8BA"]
[Mon Jul 20 06:21:51.842025 2026] [security2:error] [pid 884009:tid 884151] [client 34.74.185.202:60121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S3xKaHUf6J8d3elJkPwAAAJA"]
[Mon Jul 20 06:21:51.880175 2026] [security2:error] [pid 884009:tid 884059] [remote 81.173.115.7:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S3xKaHUf6J8d3elJkRQAAszA"]
[Mon Jul 20 06:21:52.074528 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkXAAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.074647 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkXAAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.075043 2026] [security2:error] [pid 884009:tid 884031] [remote 81.173.115.7:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S4BKaHUf6J8d3elJkXQAA8BQ"], referer: https://str.cly.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:52.170530 2026] [security2:error] [pid 884009:tid 884171] [client 34.74.185.202:65358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S4BKaHUf6J8d3elJkaAAAAKM"]
[Mon Jul 20 06:21:52.180151 2026] [security2:error] [pid 884009:tid 884138] [remote 188.166.241.141:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S4BKaHUf6J8d3elJkawAAkX8"]
[Mon Jul 20 06:21:52.180307 2026] [security2:error] [pid 884009:tid 884152] [client 188.166.241.141:58924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4S4BKaHUf6J8d3elJkawAAkX8"]
[Mon Jul 20 06:21:52.229205 2026] [security2:error] [pid 884009:tid 884192] [client 77.110.127.138:61099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkbwAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.229301 2026] [security2:error] [pid 884009:tid 884192] [client 77.110.127.138:61099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkbwAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.234868 2026] [security2:error] [pid 884009:tid 884148] [client 14.225.17.146:63808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4S4BKaHUf6J8d3elJkWgAAAI0"], referer: https://dollpassionista.com/Wp
[Mon Jul 20 06:21:52.276638 2026] [security2:error] [pid 884009:tid 884265] [client 185.132.186.69:37123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/css/dist/install.php"] [unique_id "al4S4BKaHUf6J8d3elJkeAAAAQE"]
[Mon Jul 20 06:21:52.333785 2026] [security2:error] [pid 884009:tid 884194] [client 57.141.18.64:33742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S2xKaHUf6J8d3elJiygAAuk8"]
[Mon Jul 20 06:21:52.371460 2026] [security2:error] [pid 884009:tid 884144] [client 14.225.17.146:63878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4S4BKaHUf6J8d3elJkVwAAAIk"], referer: http://massagelacey.com/Wp
[Mon Jul 20 06:21:52.616104 2026] [security2:error] [pid 884009:tid 884214] [client 14.225.17.146:58590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4S4BKaHUf6J8d3elJkgwAAAM4"], referer: http://keywayconstructionclt.com/Wp
[Mon Jul 20 06:21:52.880538 2026] [security2:error] [pid 884009:tid 884160] [client 77.110.127.138:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkpwAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.880645 2026] [security2:error] [pid 884009:tid 884160] [client 77.110.127.138:61106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4BKaHUf6J8d3elJkpwAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:52.915883 2026] [security2:error] [pid 884009:tid 884243] [client 50.116.65.227:40892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4S4BKaHUf6J8d3elJkqwAAAOs"]
[Mon Jul 20 06:21:52.927218 2026] [security2:error] [pid 884009:tid 884184] [client 50.116.65.227:29832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4S4BKaHUf6J8d3elJkrQAAALA"]
[Mon Jul 20 06:21:52.949294 2026] [security2:error] [pid 884009:tid 884074] [remote 100.42.189.89:44062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4S4BKaHUf6J8d3elJkrgAApT8"]
[Mon Jul 20 06:21:53.072268 2026] [security2:error] [pid 884009:tid 884085] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S4RKaHUf6J8d3elJkswAAjEo"]
[Mon Jul 20 06:21:53.072407 2026] [security2:error] [pid 884009:tid 884147] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S4RKaHUf6J8d3elJkswAAjEo"]
[Mon Jul 20 06:21:53.117371 2026] [security2:error] [pid 884009:tid 884267] [client 77.110.127.138:61108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJktgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.117471 2026] [security2:error] [pid 884009:tid 884267] [client 77.110.127.138:61108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJktgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.151951 2026] [security2:error] [pid 884009:tid 884053] [remote 100.42.189.89:44062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4S4RKaHUf6J8d3elJkvQAAoio"], referer: https://jvcmotorsports.com/wp-login.php
[Mon Jul 20 06:21:53.168634 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJkwAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.168769 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJkwAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.223152 2026] [security2:error] [pid 884009:tid 884240] [client 14.225.17.146:49990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJksAAAAOg"], referer: http://oldracelimited.com/Wp
[Mon Jul 20 06:21:53.319575 2026] [security2:error] [pid 884009:tid 884261] [client 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4S4RKaHUf6J8d3elJkzgAAAP0"]
[Mon Jul 20 06:21:53.334521 2026] [security2:error] [pid 884009:tid 884217] [client 77.110.127.138:61110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk0QAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.334618 2026] [security2:error] [pid 884009:tid 884217] [client 77.110.127.138:61110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk0QAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.412941 2026] [security2:error] [pid 884009:tid 884196] [client 34.74.185.202:49683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S4RKaHUf6J8d3elJk3gAAALw"]
[Mon Jul 20 06:21:53.423024 2026] [security2:error] [pid 884009:tid 884244] [client 57.141.18.107:24620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3BKaHUf6J8d3elJjLAAA7Cw"]
[Mon Jul 20 06:21:53.490247 2026] [security2:error] [pid 884009:tid 884266] [client 14.225.17.146:56900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk4AAAAQI"], referer: https://keywayconstructionclt.com/Wp
[Mon Jul 20 06:21:53.515929 2026] [security2:error] [pid 884009:tid 884145] [client 77.110.127.138:61112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk5AAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.516025 2026] [security2:error] [pid 884009:tid 884145] [client 77.110.127.138:61112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S4RKaHUf6J8d3elJk5AAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:53.563162 2026] [security2:error] [pid 884009:tid 884214] [client 50.116.65.227:29854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk2AAAAM4"]
[Mon Jul 20 06:21:53.706348 2026] [security2:error] [pid 884009:tid 884147] [client 171.22.217.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk2QAAAIw"]
[Mon Jul 20 06:21:53.733149 2026] [security2:error] [pid 884009:tid 884247] [client 171.22.217.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk2wAAAO8"]
[Mon Jul 20 06:21:53.733982 2026] [security2:error] [pid 884009:tid 884181] [client 14.225.17.146:56798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk5gAAAK0"], referer: http://bbwipartnerconference.com/Wp
[Mon Jul 20 06:21:53.749549 2026] [security2:error] [pid 884009:tid 884265] [client 50.116.65.227:29864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4S4RKaHUf6J8d3elJk6AAAAQE"]
[Mon Jul 20 06:21:53.817472 2026] [security2:error] [pid 884009:tid 884201] [client 57.141.18.4:63342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjXAAAwQs"]
[Mon Jul 20 06:21:53.820191 2026] [security2:error] [pid 884009:tid 884154] [client 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4S4RKaHUf6J8d3elJlAwAAAJM"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:21:53.869029 2026] [security2:error] [pid 884009:tid 884171] [client 34.74.185.202:52831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S4RKaHUf6J8d3elJlCAAAAKM"]
[Mon Jul 20 06:21:53.892179 2026] [security2:error] [pid 884009:tid 884180] [client 185.132.186.64:32343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/style-engine/dedi1.php"] [unique_id "al4S4RKaHUf6J8d3elJlCgAAAKw"]
[Mon Jul 20 06:21:53.952338 2026] [security2:error] [pid 884009:tid 884213] [client 50.116.65.227:40904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4S4RKaHUf6J8d3elJlEgAAAM0"]
[Mon Jul 20 06:21:53.962740 2026] [security2:error] [pid 884009:tid 884168] [client 50.116.65.227:29894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4S4RKaHUf6J8d3elJlFAAAAKE"]
[Mon Jul 20 06:21:54.306574 2026] [http2:info] [pid 915741:tid 915741] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:21:54.400862 2026] [security2:error] [pid 884009:tid 884237] [client 57.141.18.12:33226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjfQAA5V8"]
[Mon Jul 20 06:21:54.569234 2026] [security2:error] [pid 915741:tid 915743] [remote 188.40.28.4:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4S4q-615n1P-attmyuMAABjwE"]
[Mon Jul 20 06:21:54.673402 2026] [security2:error] [pid 884009:tid 884166] [client 57.141.18.51:63390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjlwAAn2w"]
[Mon Jul 20 06:21:54.747284 2026] [security2:error] [pid 884009:tid 884141] [client 57.141.18.43:50208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3RKaHUf6J8d3elJjmAAAhmo"]
[Mon Jul 20 06:21:54.851216 2026] [security2:error] [pid 915741:tid 915745] [remote 188.40.28.4:35858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4S4q-615n1P-attmyuNQABngM"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:21:54.957601 2026] [security2:error] [pid 915741:tid 915880] [client 34.74.185.202:49462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S4q-615n1P-attmyuOwAAAZg"]
[Mon Jul 20 06:21:55.093263 2026] [security2:error] [pid 915741:tid 915879] [client 14.225.17.146:49963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4S4q-615n1P-attmyuPAAAAZc"], referer: http://northbrookcpa.ca/Wp
[Mon Jul 20 06:21:55.103315 2026] [autoindex:error] [pid 915741:tid 915900] [client 171.22.217.12:0] AH01276: Cannot serve directory /home3/soloceos/public_html/wp-content/themes/Divi/includes/builder/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:21:55.111604 2026] [autoindex:error] [pid 884009:tid 884218] [client 171.22.217.12:0] AH01276: Cannot serve directory /home3/soloceos/public_html/wp-content/themes/Divi/includes/builder/frontend-builder/assets/vendors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:21:55.249464 2026] [security2:error] [pid 884009:tid 884193] [client 34.73.38.214:56125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S4xKaHUf6J8d3elJlgQAAALk"]
[Mon Jul 20 06:21:55.367540 2026] [security2:error] [pid 884009:tid 884250] [client 57.141.18.76:57522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3hKaHUf6J8d3elJj0wAA8h8"]
[Mon Jul 20 06:21:55.502519 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.90:27233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/adminfusm.php"] [unique_id "al4S4xKaHUf6J8d3elJlkwAAAME"]
[Mon Jul 20 06:21:55.519151 2026] [security2:error] [pid 884009:tid 884140] [client 14.225.17.146:57007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4S4hKaHUf6J8d3elJlRwAAAIU"], referer: http://idigress.agency/Wp
[Mon Jul 20 06:21:55.620226 2026] [security2:error] [pid 884009:tid 884253] [client 57.141.18.119:26974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3hKaHUf6J8d3elJj7AAA9T0"]
[Mon Jul 20 06:21:55.815221 2026] [security2:error] [pid 884009:tid 884199] [client 34.73.38.214:61306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S4xKaHUf6J8d3elJlqQAAAL8"]
[Mon Jul 20 06:21:56.075019 2026] [security2:error] [pid 915741:tid 915929] [client 112.208.70.94:44677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S5K-615n1P-attmyuVwAAAck"]
[Mon Jul 20 06:21:56.075162 2026] [security2:error] [pid 915741:tid 915929] [client 112.208.70.94:44677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S5K-615n1P-attmyuVwAAAck"]
[Mon Jul 20 06:21:56.134686 2026] [security2:error] [pid 884009:tid 884176] [client 34.74.185.202:59377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S5BKaHUf6J8d3elJlvQAAAKg"]
[Mon Jul 20 06:21:56.362544 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:53979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4S5BKaHUf6J8d3elJlwQAAAKk"], referer: http://mcg.homes/Wp
[Mon Jul 20 06:21:56.376093 2026] [security2:error] [pid 884009:tid 884183] [client 171.60.139.123:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S5BKaHUf6J8d3elJlzQAAAK8"]
[Mon Jul 20 06:21:56.376224 2026] [security2:error] [pid 884009:tid 884183] [client 171.60.139.123:60959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S5BKaHUf6J8d3elJlzQAAAK8"]
[Mon Jul 20 06:21:56.436480 2026] [security2:error] [pid 915741:tid 915976] [client 34.73.38.214:64537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S5K-615n1P-attmyuaAAAAfg"]
[Mon Jul 20 06:21:56.548531 2026] [security2:error] [pid 884009:tid 884185] [client 57.141.18.2:24532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkQQAAsVc"]
[Mon Jul 20 06:21:56.549205 2026] [security2:error] [pid 915741:tid 915759] [remote 47.86.33.52:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S5K-615n1P-attmyucAABwxE"]
[Mon Jul 20 06:21:56.563634 2026] [security2:error] [pid 884009:tid 884162] [client 57.141.18.111:44928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S3xKaHUf6J8d3elJkSQAAmxE"]
[Mon Jul 20 06:21:56.650697 2026] [security2:error] [pid 915741:tid 915954] [client 113.44.115.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4S5K-615n1P-attmyuXAAB4gw"], referer: https://www.aleishapenny.ca/listing/page/258?paged=258&view=list
[Mon Jul 20 06:21:57.017870 2026] [security2:error] [pid 884009:tid 884074] [remote 8.217.108.67:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S5RKaHUf6J8d3elJl5gAAjz8"]
[Mon Jul 20 06:21:57.094714 2026] [security2:error] [pid 915741:tid 915883] [client 34.74.185.202:55888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S5a-615n1P-attmyuegAAAZs"]
[Mon Jul 20 06:21:57.126344 2026] [security2:error] [pid 915741:tid 915884] [client 185.132.186.74:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/click.php"] [unique_id "al4S5a-615n1P-attmyufAAAAZw"]
[Mon Jul 20 06:21:57.146235 2026] [security2:error] [pid 884009:tid 884223] [client 52.187.75.220:22850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4S5RKaHUf6J8d3elJl7QAAANc"]
[Mon Jul 20 06:21:57.219064 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:59583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S5RKaHUf6J8d3elJl8wAAAQQ"]
[Mon Jul 20 06:21:57.330380 2026] [security2:error] [pid 884009:tid 884267] [client 52.187.75.220:22850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4S5RKaHUf6J8d3elJl-AAAAQM"]
[Mon Jul 20 06:21:57.456230 2026] [security2:error] [pid 915741:tid 915892] [client 45.116.69.230:52989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyujgAAAaQ"]
[Mon Jul 20 06:21:57.456704 2026] [security2:error] [pid 915741:tid 915892] [client 45.116.69.230:52989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyujgAAAaQ"]
[Mon Jul 20 06:21:57.579054 2026] [security2:error] [pid 884009:tid 884247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S5RKaHUf6J8d3elJl8QAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:57.781241 2026] [security2:error] [pid 915741:tid 915937] [client 34.74.185.202:59288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S5a-615n1P-attmyumgAAAdE"]
[Mon Jul 20 06:21:57.861737 2026] [security2:error] [pid 915741:tid 915939] [client 103.141.108.143:53695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyunAAAAdM"]
[Mon Jul 20 06:21:57.861888 2026] [security2:error] [pid 915741:tid 915939] [client 103.141.108.143:53695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S5a-615n1P-attmyunAAAAdM"]
[Mon Jul 20 06:21:57.956760 2026] [security2:error] [pid 915741:tid 915770] [remote 47.86.33.52:2390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S5a-615n1P-attmyunwAB6Rw"], referer: https://mail.yok.mqz.mybluehost.me/wp-login.php
[Mon Jul 20 06:21:58.009871 2026] [security2:error] [pid 884009:tid 884199] [client 34.73.38.214:49883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S5hKaHUf6J8d3elJmFwAAAL8"]
[Mon Jul 20 06:21:58.123162 2026] [security2:error] [pid 884009:tid 884127] [remote 8.217.108.67:24700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S5hKaHUf6J8d3elJmHQAA93Q"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:21:58.151503 2026] [security2:error] [pid 884009:tid 884065] [remote 148.251.82.243:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.82.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4S5hKaHUf6J8d3elJmHwAAljY"]
[Mon Jul 20 06:21:58.336452 2026] [security2:error] [pid 884009:tid 884143] [client 34.74.185.202:61777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S5hKaHUf6J8d3elJmJgAAAIg"]
[Mon Jul 20 06:21:58.356719 2026] [security2:error] [pid 884009:tid 884115] [remote 148.251.82.243:40780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.82.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4S5hKaHUf6J8d3elJmKgAA9mg"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 06:21:58.486539 2026] [security2:error] [pid 884009:tid 884206] [client 45.157.112.60:29877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S5hKaHUf6J8d3elJmMgAAAMY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:21:58.740756 2026] [security2:error] [pid 915741:tid 915898] [client 185.132.186.88:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/template-less.php"] [unique_id "al4S5q-615n1P-attmyuvgAAAao"]
[Mon Jul 20 06:21:58.758986 2026] [security2:error] [pid 884009:tid 884220] [client 57.141.18.61:40446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S4hKaHUf6J8d3elJlLwAA1C4"]
[Mon Jul 20 06:21:58.959326 2026] [security2:error] [pid 915741:tid 915953] [client 52.109.20.47:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4S5a-615n1P-attmyuoAAAAeE"]
[Mon Jul 20 06:21:58.984050 2026] [security2:error] [pid 915741:tid 915779] [remote 41.186.86.12:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4S5q-615n1P-attmyuxgACDSU"]
[Mon Jul 20 06:21:58.984852 2026] [security2:error] [pid 884009:tid 884167] [client 34.74.185.202:61125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S5hKaHUf6J8d3elJmSgAAAKA"]
[Mon Jul 20 06:21:58.987891 2026] [security2:error] [pid 915741:tid 915920] [client 52.109.20.47:38280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4S5q-615n1P-attmyuxwAAAcA"]
[Mon Jul 20 06:21:59.201769 2026] [security2:error] [pid 884009:tid 884266] [client 57.141.18.5:48042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S4hKaHUf6J8d3elJlWAABAmY"]
[Mon Jul 20 06:21:59.359957 2026] [security2:error] [pid 884009:tid 884201] [client 77.110.127.138:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S5xKaHUf6J8d3elJmXQAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:59.360065 2026] [security2:error] [pid 884009:tid 884201] [client 77.110.127.138:61138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S5xKaHUf6J8d3elJmXQAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:21:59.443832 2026] [security2:error] [pid 915741:tid 915915] [client 178.152.178.232:37396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S56-615n1P-attmyu0wAAAbs"]
[Mon Jul 20 06:21:59.450960 2026] [security2:error] [pid 915741:tid 915915] [client 178.152.178.232:37396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S56-615n1P-attmyu0wAAAbs"]
[Mon Jul 20 06:21:59.473774 2026] [security2:error] [pid 915741:tid 915781] [remote 41.186.86.12:4842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4S56-615n1P-attmyu1gAB1yc"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 06:21:59.960128 2026] [security2:error] [pid 884009:tid 884152] [client 34.73.38.214:61676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S5xKaHUf6J8d3elJmgAAAAJE"]
[Mon Jul 20 06:21:59.991439 2026] [security2:error] [pid 884009:tid 884261] [client 57.141.18.64:39490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S4xKaHUf6J8d3elJlhAAA_Rg"]
[Mon Jul 20 06:22:00.061152 2026] [security2:error] [pid 915741:tid 915955] [client 34.74.185.202:53145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S6K-615n1P-attmyu5QAAAeM"]
[Mon Jul 20 06:22:00.119932 2026] [security2:error] [pid 884009:tid 884255] [client 34.73.38.214:63913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4S6BKaHUf6J8d3elJmiwAAAPc"]
[Mon Jul 20 06:22:00.244897 2026] [security2:error] [pid 915741:tid 915962] [client 27.96.94.195:37799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S6K-615n1P-attmyu6wAAAeo"]
[Mon Jul 20 06:22:00.245026 2026] [security2:error] [pid 915741:tid 915962] [client 27.96.94.195:37799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S6K-615n1P-attmyu6wAAAeo"]
[Mon Jul 20 06:22:00.346052 2026] [security2:error] [pid 884009:tid 884228] [client 185.132.186.66:20531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/pomo/alfa-rex.php"] [unique_id "al4S6BKaHUf6J8d3elJmmAAAANw"]
[Mon Jul 20 06:22:00.519883 2026] [security2:error] [pid 884009:tid 884260] [client 34.74.185.202:57510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.cfy.cnq.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S6BKaHUf6J8d3elJmoAAAAPw"]
[Mon Jul 20 06:22:00.828808 2026] [security2:error] [pid 915741:tid 915953] [client 95.217.114.145:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4S6K-615n1P-attmyu9gAAAeE"]
[Mon Jul 20 06:22:00.953629 2026] [security2:error] [pid 915741:tid 915792] [remote 103.187.169.251:52438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4S6K-615n1P-attmyvBAABvDI"]
[Mon Jul 20 06:22:01.094673 2026] [security2:error] [pid 884009:tid 884195] [client 14.225.17.146:60057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4S6BKaHUf6J8d3elJmtwAAALs"], referer: http://laceycaraccident.com/Wp
[Mon Jul 20 06:22:01.166569 2026] [security2:error] [pid 884009:tid 884265] [client 104.234.53.62:48505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4S6RKaHUf6J8d3elJmxQAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:01.223674 2026] [security2:error] [pid 884009:tid 884140] [client 34.73.38.214:60701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S6RKaHUf6J8d3elJmygAAAIU"]
[Mon Jul 20 06:22:01.226385 2026] [security2:error] [pid 884009:tid 884157] [client 34.73.38.214:60767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4S6RKaHUf6J8d3elJmywAAAJY"]
[Mon Jul 20 06:22:01.303363 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:9703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S6a-615n1P-attmyvCQAAAfU"]
[Mon Jul 20 06:22:01.303508 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:9703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S6a-615n1P-attmyvCQAAAfU"]
[Mon Jul 20 06:22:01.363174 2026] [security2:error] [pid 915741:tid 915793] [remote 103.187.169.251:52438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvCwABzzM"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:22:01.389222 2026] [security2:error] [pid 915741:tid 915794] [remote 113.160.142.119:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvDAAB0TQ"]
[Mon Jul 20 06:22:01.418041 2026] [security2:error] [pid 915741:tid 915795] [remote 97.74.93.24:39678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvDgAB6TU"]
[Mon Jul 20 06:22:01.433130 2026] [security2:error] [pid 915741:tid 915956] [client 14.225.17.146:63840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4S6a-615n1P-attmyvCAAAAeQ"], referer: http://lifeisbetterlakeside.com/Wp
[Mon Jul 20 06:22:01.787853 2026] [security2:error] [pid 915741:tid 915932] [client 50.116.65.227:60028] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S6a-615n1P-attmyvFwAAAcw"]
[Mon Jul 20 06:22:01.801965 2026] [security2:error] [pid 884009:tid 884238] [client 50.116.65.227:56886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4S6RKaHUf6J8d3elJm4wAAALE"]
[Mon Jul 20 06:22:01.857917 2026] [security2:error] [pid 915741:tid 915799] [remote 97.74.93.24:39678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvGwAB6jk"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 06:22:01.888704 2026] [security2:error] [pid 915741:tid 915800] [remote 113.160.142.119:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4S6a-615n1P-attmyvHgABtDo"], referer: https://iagdevelopments.com/wp-login.php
[Mon Jul 20 06:22:01.963610 2026] [security2:error] [pid 915741:tid 915889] [client 185.132.186.66:20141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/abcd.php"] [unique_id "al4S6a-615n1P-attmyvIAAAAaE"]
[Mon Jul 20 06:22:02.036119 2026] [security2:error] [pid 884009:tid 884209] [client 57.141.18.84:37316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5RKaHUf6J8d3elJl-wAAyS8"]
[Mon Jul 20 06:22:02.088325 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4S6a-615n1P-attmyvHwAAAds"]
[Mon Jul 20 06:22:02.222103 2026] [security2:error] [pid 884009:tid 884156] [client 171.61.165.146:29108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S6hKaHUf6J8d3elJm9QAAAJU"]
[Mon Jul 20 06:22:02.222294 2026] [security2:error] [pid 884009:tid 884156] [client 171.61.165.146:29108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S6hKaHUf6J8d3elJm9QAAAJU"]
[Mon Jul 20 06:22:02.459242 2026] [security2:error] [pid 915741:tid 915937] [client 34.73.38.214:54380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4S6q-615n1P-attmyvNgAAAdE"]
[Mon Jul 20 06:22:02.464375 2026] [security2:error] [pid 915741:tid 915961] [client 34.73.38.214:60401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S6q-615n1P-attmyvNwAAAek"]
[Mon Jul 20 06:22:02.599699 2026] [security2:error] [pid 915741:tid 915957] [client 57.141.18.50:36468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5a-615n1P-attmyuoQAB5R0"]
[Mon Jul 20 06:22:02.821997 2026] [security2:error] [pid 884009:tid 884166] [client 57.141.18.123:47854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5hKaHUf6J8d3elJmHAAAn00"]
[Mon Jul 20 06:22:02.970722 2026] [security2:error] [pid 884009:tid 884230] [client 34.73.38.214:53272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S6hKaHUf6J8d3elJnEQAAAN4"]
[Mon Jul 20 06:22:03.312792 2026] [security2:error] [pid 884009:tid 884235] [client 34.73.38.214:60717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4S6xKaHUf6J8d3elJnIwAAAOM"]
[Mon Jul 20 06:22:03.571954 2026] [security2:error] [pid 884009:tid 884197] [client 185.132.186.84:22159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/colors/blue/admin-footer.php"] [unique_id "al4S6xKaHUf6J8d3elJnMgAAAL0"]
[Mon Jul 20 06:22:03.637375 2026] [security2:error] [pid 915741:tid 915918] [client 57.141.18.51:64692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5q-615n1P-attmyuwwABviQ"]
[Mon Jul 20 06:22:03.763215 2026] [security2:error] [pid 915741:tid 915924] [client 114.119.133.182:33125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.geo-ver.ca"] [uri "/robots.txt"] [unique_id "al4S66-615n1P-attmyvUwAAAcQ"], referer: http://www.geo-ver.ca/robots.txt
[Mon Jul 20 06:22:03.798881 2026] [security2:error] [pid 915741:tid 915809] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S66-615n1P-attmyvVAABzkM"]
[Mon Jul 20 06:22:03.799145 2026] [security2:error] [pid 915741:tid 915934] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S66-615n1P-attmyvVAABzkM"]
[Mon Jul 20 06:22:03.998794 2026] [security2:error] [pid 884009:tid 884232] [client 34.73.38.214:60776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thepauze.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S6xKaHUf6J8d3elJnRQAAAOA"]
[Mon Jul 20 06:22:04.063286 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7K-615n1P-attmyvWwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:04.063404 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7K-615n1P-attmyvWwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:04.465355 2026] [security2:error] [pid 884009:tid 884213] [client 57.141.18.62:54882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S5xKaHUf6J8d3elJmegAAzVA"]
[Mon Jul 20 06:22:04.524031 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.33:45726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S56-615n1P-attmyu4gACBCo"]
[Mon Jul 20 06:22:04.603039 2026] [security2:error] [pid 884009:tid 884209] [client 34.73.38.214:61783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4S7BKaHUf6J8d3elJnYgAAAMk"]
[Mon Jul 20 06:22:05.116119 2026] [security2:error] [pid 915741:tid 915883] [client 34.73.38.214:62459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4S7a-615n1P-attmyvxgAAAZs"]
[Mon Jul 20 06:22:05.179882 2026] [security2:error] [pid 915741:tid 915907] [client 14.225.17.146:60138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4S7K-615n1P-attmyvwQAAAbM"], referer: http://sesamegreenbeans.com/Wp
[Mon Jul 20 06:22:05.249041 2026] [security2:error] [pid 884009:tid 884259] [client 57.141.18.103:23890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S6BKaHUf6J8d3elJmpwAA-38"]
[Mon Jul 20 06:22:05.718242 2026] [security2:error] [pid 915741:tid 915761] [remote 182.77.62.24:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gearwaterproof.com"] [uri "/wp-login.php"] [unique_id "al4S7a-615n1P-attmyv1AABvBM"]
[Mon Jul 20 06:22:05.952436 2026] [security2:error] [pid 884009:tid 884158] [client 127.0.0.1:33958] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4S7RKaHUf6J8d3elJnnQAAAJc"], referer: https://www.google.com/
[Mon Jul 20 06:22:06.074335 2026] [security2:error] [pid 915741:tid 915873] [client 185.132.186.79:52793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentytwo/bypass.php"] [unique_id "al4S7q-615n1P-attmyv6wAAAZE"]
[Mon Jul 20 06:22:06.220724 2026] [security2:error] [pid 915741:tid 915985] [client 14.225.17.146:59336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4S7q-615n1P-attmyv6gAAAgE"], referer: http://thechancersband.com/Wp
[Mon Jul 20 06:22:06.240183 2026] [security2:error] [pid 915741:tid 915899] [client 14.225.17.146:59332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4S7q-615n1P-attmyv6QAAAas"], referer: https://sesamegreenbeans.com/Wp
[Mon Jul 20 06:22:06.244561 2026] [security2:error] [pid 915741:tid 915757] [remote 182.77.62.24:36464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gearwaterproof.com"] [uri "/wp-login.php"] [unique_id "al4S7q-615n1P-attmyv8AAB3g8"], referer: https://gearwaterproof.com/wp-login.php
[Mon Jul 20 06:22:06.396080 2026] [security2:error] [pid 915741:tid 915981] [client 34.73.38.214:62797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4S7q-615n1P-attmywAQAAAf0"]
[Mon Jul 20 06:22:06.625105 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7q-615n1P-attmywCgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:06.625263 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:61165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S7q-615n1P-attmywCgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:07.129431 2026] [security2:error] [pid 915741:tid 915982] [client 171.60.139.123:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywHAAAAf4"]
[Mon Jul 20 06:22:07.129552 2026] [security2:error] [pid 915741:tid 915982] [client 171.60.139.123:61473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywHAAAAf4"]
[Mon Jul 20 06:22:07.235601 2026] [security2:error] [pid 884009:tid 884203] [client 57.141.18.76:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S6hKaHUf6J8d3elJnBwAAwws"]
[Mon Jul 20 06:22:07.418462 2026] [security2:error] [pid 884009:tid 884235] [client 34.73.38.214:59313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4S7xKaHUf6J8d3elJn2gAAAOM"]
[Mon Jul 20 06:22:07.432732 2026] [security2:error] [pid 915741:tid 915930] [client 14.225.17.146:59253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4S7a-615n1P-attmyv3AAAAco"], referer: http://xp-design.co/Wp
[Mon Jul 20 06:22:07.485339 2026] [security2:error] [pid 915741:tid 915941] [client 139.28.219.68:36772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "socialputty.co"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywOQAAAdU"]
[Mon Jul 20 06:22:07.485509 2026] [security2:error] [pid 915741:tid 915941] [client 139.28.219.68:36772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "socialputty.co"] [uri "/xmlrpc.php"] [unique_id "al4S76-615n1P-attmywOQAAAdU"]
[Mon Jul 20 06:22:07.598760 2026] [security2:error] [pid 884009:tid 884115] [remote 57.141.18.42:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2998026"] [unique_id "al4S7xKaHUf6J8d3elJn4QAAqmg"]
[Mon Jul 20 06:22:07.666351 2026] [security2:error] [pid 915741:tid 915939] [client 14.225.17.146:59426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywMQAAAdM"], referer: http://windowtx.com/Wp
[Mon Jul 20 06:22:07.746089 2026] [security2:error] [pid 884009:tid 884233] [client 57.141.18.29:21200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S6xKaHUf6J8d3elJnJAAA4SY"]
[Mon Jul 20 06:22:07.836437 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywOwAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:07.877965 2026] [security2:error] [pid 915741:tid 915985] [client 185.132.186.58:25945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-admin/css/elementskit.php"] [unique_id "al4S76-615n1P-attmywQAAAAgE"]
[Mon Jul 20 06:22:07.920619 2026] [security2:error] [pid 915741:tid 915910] [client 14.225.17.146:53477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4S7q-615n1P-attmywAgAAAbY"], referer: http://slutilities.com/Wp
[Mon Jul 20 06:22:07.979594 2026] [security2:error] [pid 915741:tid 915921] [client 57.141.18.50:36472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S66-615n1P-attmyvUQABwUI"]
[Mon Jul 20 06:22:08.228330 2026] [security2:error] [pid 915741:tid 915928] [client 57.141.18.56:39790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7K-615n1P-attmyvVwAByEQ"]
[Mon Jul 20 06:22:08.270148 2026] [security2:error] [pid 915741:tid 915963] [client 34.73.38.214:63032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4S8K-615n1P-attmywUAAAAes"]
[Mon Jul 20 06:22:08.334670 2026] [fcgid:warn] [pid 915741:tid 915951] (70014)End of file found: [client 66.132.172.201:58794] mod_fcgid: can't get data from http client
[Mon Jul 20 06:22:08.615313 2026] [security2:error] [pid 884009:tid 884268] [client 103.141.108.143:54173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S8BKaHUf6J8d3elJoBAAAAQQ"]
[Mon Jul 20 06:22:08.615574 2026] [security2:error] [pid 884009:tid 884268] [client 103.141.108.143:54173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S8BKaHUf6J8d3elJoBAAAAQQ"]
[Mon Jul 20 06:22:08.831193 2026] [security2:error] [pid 915741:tid 915962] [client 13.201.64.214:37404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4S8K-615n1P-attmywagAAAeo"]
[Mon Jul 20 06:22:08.842562 2026] [security2:error] [pid 915741:tid 915972] [client 112.208.70.94:45059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywawAAAfQ"]
[Mon Jul 20 06:22:08.842734 2026] [security2:error] [pid 915741:tid 915972] [client 112.208.70.94:45059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywawAAAfQ"]
[Mon Jul 20 06:22:08.843211 2026] [security2:error] [pid 884009:tid 884236] [client 66.249.68.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.zzzwillowzzz.com"] [uri "/index.php"] [unique_id "al4S7xKaHUf6J8d3elJnyQAA5BM"]
[Mon Jul 20 06:22:08.862926 2026] [security2:error] [pid 915741:tid 915918] [client 45.116.69.230:53512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywbAAAAb4"]
[Mon Jul 20 06:22:08.863124 2026] [security2:error] [pid 915741:tid 915918] [client 45.116.69.230:53512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S8K-615n1P-attmywbAAAAb4"]
[Mon Jul 20 06:22:08.899803 2026] [security2:error] [pid 884009:tid 884221] [client 34.73.38.214:63616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4S8BKaHUf6J8d3elJoDgAAANU"]
[Mon Jul 20 06:22:08.941368 2026] [security2:error] [pid 884009:tid 884244] [client 50.116.65.227:46886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S8BKaHUf6J8d3elJoEQAAAOw"]
[Mon Jul 20 06:22:08.952278 2026] [security2:error] [pid 915741:tid 915988] [client 50.116.65.227:46900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S8K-615n1P-attmywcQAAAgQ"]
[Mon Jul 20 06:22:08.991407 2026] [security2:error] [pid 915741:tid 915932] [client 103.153.183.69:61772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env%00.php"] [unique_id "al4S8K-615n1P-attmywdwAAAcw"], referer: https://www.facebook.com/
[Mon Jul 20 06:22:09.024746 2026] [security2:error] [pid 915741:tid 915893] [client 57.141.18.5:62736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7K-615n1P-attmyvdwABpU4"]
[Mon Jul 20 06:22:09.087381 2026] [security2:error] [pid 915741:tid 915983] [client 50.116.65.227:26114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4S8a-615n1P-attmywfAAAAf8"]
[Mon Jul 20 06:22:09.097688 2026] [security2:error] [pid 884009:tid 884177] [client 50.116.65.227:46902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4S8RKaHUf6J8d3elJoGwAAAMA"]
[Mon Jul 20 06:22:09.171445 2026] [security2:error] [pid 884009:tid 884247] [client 14.225.17.146:60046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4S7xKaHUf6J8d3elJn7wAAAO8"], referer: http://mourgroup.com/Wp
[Mon Jul 20 06:22:09.450201 2026] [security2:error] [pid 915741:tid 915800] [remote 192.241.143.148:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4S8a-615n1P-attmywjAAB_Do"]
[Mon Jul 20 06:22:09.580852 2026] [security2:error] [pid 915741:tid 915947] [client 66.249.89.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4S8a-615n1P-attmywhgAB2zY"], referer: https://tiokubito.cl/producto/preventa-happy-life-one-piece-monkey-d-luffy/
[Mon Jul 20 06:22:09.600558 2026] [security2:error] [pid 915741:tid 915939] [client 103.153.183.69:22108] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/..\\xef\\xbc\\x8f../etc/passwd"] [unique_id "al4S8a-615n1P-attmywkgAAAdM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:22:09.622985 2026] [security2:error] [pid 915741:tid 915768] [remote 192.241.143.148:37726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4S8a-615n1P-attmywlAABoRo"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:22:09.693420 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.97:54245] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "harborhealth.us"] [uri "/js/1.php7"] [unique_id "al4S8RKaHUf6J8d3elJoNAAAAME"]
[Mon Jul 20 06:22:09.693534 2026] [security2:error] [pid 884009:tid 884201] [client 185.132.186.97:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/js/1.php7"] [unique_id "al4S8RKaHUf6J8d3elJoNAAAAME"]
[Mon Jul 20 06:22:09.737549 2026] [core:error] [pid 915741:tid 915916] [client 103.153.183.69:22108] AH10244: invalid URI path (/.%2e/etc/passwd?_=xefuj0ft&v=366l3), referer: https://t.co/euaya6jspt
[Mon Jul 20 06:22:09.740781 2026] [security2:error] [pid 915741:tid 915918] [client 127.0.0.1:15548] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4S8a-615n1P-attmywmQAAAb4"], referer: https://t.co/euaya6jspt
[Mon Jul 20 06:22:09.948273 2026] [security2:error] [pid 884009:tid 884248] [client 13.201.64.214:37414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4S8RKaHUf6J8d3elJoPwAAAPA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:10.337349 2026] [security2:error] [pid 915741:tid 915803] [remote 192.241.143.148:37730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4S8q-615n1P-attmywpQAB0T0"]
[Mon Jul 20 06:22:10.364551 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.102:29900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7a-615n1P-attmyv3QAB5BQ"]
[Mon Jul 20 06:22:10.408641 2026] [security2:error] [pid 884009:tid 884182] [client 34.73.38.214:61847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4S8hKaHUf6J8d3elJoXAAAAK4"]
[Mon Jul 20 06:22:10.530237 2026] [security2:error] [pid 915741:tid 915778] [remote 192.241.143.148:37730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4S8q-615n1P-attmywrAABpiQ"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 06:22:10.530773 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S8q-615n1P-attmywogAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:10.576359 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:61688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoYAAAAJo"], referer: http://processorstudio.com/Wp
[Mon Jul 20 06:22:10.627027 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:59952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoWwAAAKk"], referer: http://savilerowtravel.com/Wp
[Mon Jul 20 06:22:10.687120 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S8q-615n1P-attmywsgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:10.687248 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:61185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S8q-615n1P-attmywsgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:10.741596 2026] [security2:error] [pid 915741:tid 915878] [client 34.73.38.214:63273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.thewelloiledlife.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4S8q-615n1P-attmywtgAAAZY"]
[Mon Jul 20 06:22:11.368992 2026] [security2:error] [pid 884009:tid 884038] [remote 156.59.198.136:22472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsafety.ca"] [uri "/wp-content/uploads/2025/08/KSS-Sustainability-Policy.docx-1.pdf"] [unique_id "al4S8xKaHUf6J8d3elJogwAAkxs"]
[Mon Jul 20 06:22:11.430041 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:52547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4S86-615n1P-attmyw1QAAAdI"], referer: https://processorstudio.com/Wp
[Mon Jul 20 06:22:11.500864 2026] [security2:error] [pid 884009:tid 884193] [client 185.132.186.90:36211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes/twentytwentyfour/install.php"] [unique_id "al4S8xKaHUf6J8d3elJoiQAAALk"]
[Mon Jul 20 06:22:11.650193 2026] [security2:error] [pid 915741:tid 915987] [client 14.225.17.146:52216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4S86-615n1P-attmyw1gAAAgM"], referer: https://savilerowtravel.com/Wp
[Mon Jul 20 06:22:11.739402 2026] [security2:error] [pid 915741:tid 915877] [client 68.235.52.68:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4S86-615n1P-attmyw3AAAAZU"]
[Mon Jul 20 06:22:11.739548 2026] [security2:error] [pid 915741:tid 915877] [client 68.235.52.68:50564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4S86-615n1P-attmyw3AAAAZU"]
[Mon Jul 20 06:22:11.777668 2026] [security2:error] [pid 915741:tid 915969] [client 14.225.17.146:61707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4S86-615n1P-attmyw2QAAAfE"], referer: http://thefriendlyspreadsheet.com/Wp
[Mon Jul 20 06:22:11.880151 2026] [security2:error] [pid 884009:tid 884060] [remote 152.228.213.32:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4S8xKaHUf6J8d3elJongAA5jE"]
[Mon Jul 20 06:22:11.992451 2026] [security2:error] [pid 884009:tid 884144] [client 41.173.37.102:10121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S8xKaHUf6J8d3elJoowAAAIk"]
[Mon Jul 20 06:22:11.992569 2026] [security2:error] [pid 884009:tid 884144] [client 41.173.37.102:10121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S8xKaHUf6J8d3elJoowAAAIk"]
[Mon Jul 20 06:22:12.082462 2026] [security2:error] [pid 884009:tid 884048] [remote 152.228.213.32:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4S9BKaHUf6J8d3elJopQAA6CU"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:22:12.265120 2026] [security2:error] [pid 884009:tid 884216] [client 57.141.18.38:58338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S7xKaHUf6J8d3elJn5gAA0BI"]
[Mon Jul 20 06:22:12.354164 2026] [security2:error] [pid 915741:tid 915923] [client 57.141.18.88:40484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywRQABwwQ"]
[Mon Jul 20 06:22:12.379810 2026] [security2:error] [pid 884009:tid 884174] [client 14.225.17.146:50999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoWgAAAKY"], referer: http://mollycahill.com/Wp
[Mon Jul 20 06:22:12.488143 2026] [security2:error] [pid 915741:tid 915991] [client 57.141.18.37:26120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S76-615n1P-attmywRgACByk"]
[Mon Jul 20 06:22:12.624810 2026] [security2:error] [pid 884009:tid 884115] [remote 188.166.241.141:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S9BKaHUf6J8d3elJotwAA0mg"]
[Mon Jul 20 06:22:12.680520 2026] [security2:error] [pid 915741:tid 915919] [client 51.91.255.78:36234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyxAQAAAb8"]
[Mon Jul 20 06:22:12.827483 2026] [security2:error] [pid 915741:tid 915985] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyw_AAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:12.836185 2026] [security2:error] [pid 884009:tid 884266] [client 57.141.18.49:64770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8BKaHUf6J8d3elJn_AABAm0"]
[Mon Jul 20 06:22:12.872943 2026] [security2:error] [pid 915741:tid 915824] [remote 5.223.65.249:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9K-615n1P-attmyxFAAB9lI"]
[Mon Jul 20 06:22:13.000024 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:52558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyxEwAAAfU"], referer: http://alexsandbergmusic.com/Wp
[Mon Jul 20 06:22:13.056242 2026] [security2:error] [pid 884009:tid 884043] [remote 188.166.241.141:51792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S9RKaHUf6J8d3elJoxQAA4yA"], referer: https://mail.ait.afz.mybluehost.me/wp-login.php
[Mon Jul 20 06:22:13.103812 2026] [security2:error] [pid 884009:tid 884094] [remote 202.51.202.242:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4S9RKaHUf6J8d3elJoxgAA21M"]
[Mon Jul 20 06:22:13.278094 2026] [security2:error] [pid 915741:tid 915828] [remote 5.223.65.249:41794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9a-615n1P-attmyxJgAB3lY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:13.291815 2026] [security2:error] [pid 915741:tid 915884] [client 171.61.165.146:19630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9a-615n1P-attmyxJwAAAZw"]
[Mon Jul 20 06:22:13.291924 2026] [security2:error] [pid 915741:tid 915884] [client 171.61.165.146:19630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9a-615n1P-attmyxJwAAAZw"]
[Mon Jul 20 06:22:13.320722 2026] [security2:error] [pid 884009:tid 884179] [client 14.225.17.146:61723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4S8xKaHUf6J8d3elJooAAAAKs"], referer: http://alchemygroup.ca/Wp
[Mon Jul 20 06:22:13.324893 2026] [security2:error] [pid 915741:tid 915982] [client 185.132.186.90:25583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/assets/min.php"] [unique_id "al4S9a-615n1P-attmyxKgAAAf4"]
[Mon Jul 20 06:22:13.372970 2026] [security2:error] [pid 915741:tid 915835] [remote 192.241.143.148:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9a-615n1P-attmyxLQACBF0"]
[Mon Jul 20 06:22:13.432703 2026] [security2:error] [pid 915741:tid 915920] [client 14.225.17.146:58631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4S9K-615n1P-attmyw-QAAAcA"], referer: http://alrowad-hub.net/Wp
[Mon Jul 20 06:22:13.558510 2026] [security2:error] [pid 915741:tid 915836] [remote 192.241.143.148:40412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S9a-615n1P-attmyxMgABnl4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:13.759734 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S9a-615n1P-attmyxNgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:13.759845 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S9a-615n1P-attmyxNgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:13.792490 2026] [security2:error] [pid 884009:tid 884241] [client 57.141.18.21:30066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8RKaHUf6J8d3elJoJAAA6TI"]
[Mon Jul 20 06:22:13.797063 2026] [security2:error] [pid 915741:tid 915951] [client 57.141.18.95:27808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8a-615n1P-attmywgQAB3zU"]
[Mon Jul 20 06:22:14.462062 2026] [security2:error] [pid 884009:tid 884110] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9hKaHUf6J8d3elJpBgAAzmM"]
[Mon Jul 20 06:22:14.462181 2026] [security2:error] [pid 884009:tid 884214] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4S9hKaHUf6J8d3elJpBgAAzmM"]
[Mon Jul 20 06:22:14.564692 2026] [security2:error] [pid 915741:tid 915929] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxRAAAAck"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:14.570933 2026] [security2:error] [pid 915741:tid 915883] [client 103.153.183.69:18642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../var/www/html/.env"] [unique_id "al4S9q-615n1P-attmyxSgAAAZs"], referer: https://twitter.com/
[Mon Jul 20 06:22:14.773966 2026] [security2:error] [pid 915741:tid 915998] [client 103.153.183.69:18642] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../var/www/.env"] [unique_id "al4S9q-615n1P-attmyxUQAAAg4"], referer: https://t.co/01esdha803
[Mon Jul 20 06:22:14.803977 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.90:29620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoXQAA93U"]
[Mon Jul 20 06:22:14.912640 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.78:39372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8q-615n1P-attmywqgAB-j8"]
[Mon Jul 20 06:22:14.988480 2026] [security2:error] [pid 915741:tid 915992] [client 103.153.183.69:18642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//var/www/html/wp-config.php"] [unique_id "al4S9q-615n1P-attmyxXAAAAgg"], referer: https://twitter.com/
[Mon Jul 20 06:22:15.012743 2026] [security2:error] [pid 884009:tid 884190] [client 57.141.18.3:54888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8hKaHUf6J8d3elJoZgAAtjc"]
[Mon Jul 20 06:22:15.021836 2026] [security2:error] [pid 915741:tid 915857] [remote 57.141.18.60:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5017581"] [unique_id "al4S96-615n1P-attmyxXgAB-3M"]
[Mon Jul 20 06:22:15.062395 2026] [security2:error] [pid 915741:tid 915934] [client 50.116.65.227:46964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4S96-615n1P-attmyxYQAAAc4"]
[Mon Jul 20 06:22:15.066120 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:52108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxUwAAAds"], referer: http://recruitinginsight.us/Wp
[Mon Jul 20 06:22:15.123679 2026] [security2:error] [pid 915741:tid 915894] [client 185.132.186.97:47321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al4S96-615n1P-attmyxZQAAAaY"]
[Mon Jul 20 06:22:15.245483 2026] [security2:error] [pid 884009:tid 884123] [remote 202.51.202.242:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4S9xKaHUf6J8d3elJpIQAAv3A"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:22:15.854536 2026] [security2:error] [pid 915741:tid 915930] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S96-615n1P-attmyxfAAAAco"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:15.938325 2026] [security2:error] [pid 884009:tid 884219] [client 57.141.18.85:59704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S8xKaHUf6J8d3elJokgAA0yo"]
[Mon Jul 20 06:22:16.698775 2026] [security2:error] [pid 884009:tid 884171] [client 158.173.89.95:20103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S-BKaHUf6J8d3elJpZAAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:16.795673 2026] [security2:error] [pid 915741:tid 915957] [client 134.19.178.167:34068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.178.19.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4S-K-615n1P-attmyxmAAAAeU"]
[Mon Jul 20 06:22:16.795820 2026] [security2:error] [pid 915741:tid 915957] [client 134.19.178.167:34068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4S-K-615n1P-attmyxmAAAAeU"]
[Mon Jul 20 06:22:16.948628 2026] [security2:error] [pid 915741:tid 915903] [client 14.225.17.146:52435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4S-K-615n1P-attmyxngAAAa8"], referer: http://walkingandtalking.net/Wp
[Mon Jul 20 06:22:16.953138 2026] [security2:error] [pid 915741:tid 915970] [client 185.132.186.93:37609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/backup/autoload_classmap.php"] [unique_id "al4S-K-615n1P-attmyxowAAAfI"]
[Mon Jul 20 06:22:17.731785 2026] [security2:error] [pid 915741:tid 915961] [client 50.116.65.227:26144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4S-a-615n1P-attmyxwAAAAek"]
[Mon Jul 20 06:22:17.745275 2026] [security2:error] [pid 884009:tid 884207] [client 50.116.65.227:47002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4S-RKaHUf6J8d3elJpjQAAAMc"]
[Mon Jul 20 06:22:17.765868 2026] [security2:error] [pid 915741:tid 915889] [client 171.60.139.123:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S-a-615n1P-attmyxxgAAAaE"]
[Mon Jul 20 06:22:17.765993 2026] [security2:error] [pid 915741:tid 915889] [client 171.60.139.123:61975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4S-a-615n1P-attmyxxgAAAaE"]
[Mon Jul 20 06:22:17.826474 2026] [security2:error] [pid 915741:tid 915948] [client 14.225.17.146:52516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4S-a-615n1P-attmyxxwAAAdw"], referer: https://walkingandtalking.net/Wp
[Mon Jul 20 06:22:17.883458 2026] [security2:error] [pid 915741:tid 915874] [client 14.225.17.146:52478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4S-a-615n1P-attmyxvQAAAZI"], referer: http://ksands.co.uk/Wp
[Mon Jul 20 06:22:18.271697 2026] [security2:error] [pid 884009:tid 884155] [client 77.110.127.138:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S-hKaHUf6J8d3elJppAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:18.271820 2026] [security2:error] [pid 884009:tid 884155] [client 77.110.127.138:61215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S-hKaHUf6J8d3elJppAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:18.287435 2026] [security2:error] [pid 884009:tid 884261] [client 158.173.166.181:54029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4S-hKaHUf6J8d3elJppgAAAP0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:18.293575 2026] [security2:error] [pid 915741:tid 915995] [client 50.116.65.227:47008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4S-q-615n1P-attmyx4wAAAgs"]
[Mon Jul 20 06:22:18.306899 2026] [security2:error] [pid 915741:tid 915873] [client 50.116.65.227:47024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4S-q-615n1P-attmyx5AAAAZE"]
[Mon Jul 20 06:22:18.411559 2026] [core:error] [pid 915741:tid 915956] [client 198.235.24.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:18.411579 2026] [core:error] [pid 915741:tid 915956] [client 198.235.24.174:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:18.585500 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.107:42486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxRQABtXc"]
[Mon Jul 20 06:22:18.648844 2026] [security2:error] [pid 915741:tid 915890] [client 57.141.18.83:25914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxSAABomA"]
[Mon Jul 20 06:22:18.722007 2026] [security2:error] [pid 915741:tid 915868] [remote 81.173.115.7:36486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S-q-615n1P-attmyx8wAB3X4"]
[Mon Jul 20 06:22:18.774862 2026] [security2:error] [pid 915741:tid 915920] [client 185.132.186.103:33681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/uploads/uploads.php"] [unique_id "al4S-q-615n1P-attmyx9QAAAcA"]
[Mon Jul 20 06:22:18.799452 2026] [security2:error] [pid 884009:tid 884174] [client 45.116.69.230:54054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S-hKaHUf6J8d3elJpugAAAKY"]
[Mon Jul 20 06:22:18.799579 2026] [security2:error] [pid 884009:tid 884174] [client 45.116.69.230:54054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4S-hKaHUf6J8d3elJpugAAAKY"]
[Mon Jul 20 06:22:18.951145 2026] [security2:error] [pid 915741:tid 915744] [remote 81.173.115.7:36486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4S-q-615n1P-attmyx9wAB1AI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:22:19.019843 2026] [security2:error] [pid 915741:tid 915918] [client 57.141.18.124:53962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9q-615n1P-attmyxUAABvnQ"]
[Mon Jul 20 06:22:19.025009 2026] [security2:error] [pid 884009:tid 884229] [client 14.225.17.146:52084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4S-BKaHUf6J8d3elJpYwAAAN0"], referer: http://talknutritionwithlesley.com/Wp
[Mon Jul 20 06:22:19.307094 2026] [security2:error] [pid 884009:tid 884237] [client 103.141.108.143:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S-xKaHUf6J8d3elJpywAAAOU"]
[Mon Jul 20 06:22:19.307234 2026] [security2:error] [pid 884009:tid 884237] [client 103.141.108.143:54654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4S-xKaHUf6J8d3elJpywAAAOU"]
[Mon Jul 20 06:22:19.350026 2026] [security2:error] [pid 915741:tid 915987] [client 14.225.17.146:52432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4S-6-615n1P-attmyx_gAAAgM"], referer: http://jvcmotorsports.com/Wp
[Mon Jul 20 06:22:19.387982 2026] [security2:error] [pid 915741:tid 915819] [remote 162.19.86.63:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S-6-615n1P-attmyyDgABlE0"]
[Mon Jul 20 06:22:19.544268 2026] [security2:error] [pid 915741:tid 915892] [client 57.141.18.83:25926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S96-615n1P-attmyxbgABpG8"]
[Mon Jul 20 06:22:19.600315 2026] [security2:error] [pid 915741:tid 915751] [remote 162.19.86.63:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4S-6-615n1P-attmyyFgAB-Ak"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:22:20.100556 2026] [core:error] [pid 915741:tid 915907] [client 14.225.17.146:60898] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:20.100594 2026] [core:error] [pid 915741:tid 915907] [client 14.225.17.146:60898] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:20.158681 2026] [security2:error] [pid 884009:tid 884205] [client 178.152.178.232:37193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S_BKaHUf6J8d3elJp8AAAAMU"]
[Mon Jul 20 06:22:20.158836 2026] [security2:error] [pid 884009:tid 884205] [client 178.152.178.232:37193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4S_BKaHUf6J8d3elJp8AAAAMU"]
[Mon Jul 20 06:22:20.329980 2026] [security2:error] [pid 884009:tid 884164] [client 57.141.18.38:48142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S9xKaHUf6J8d3elJpQAAAnUE"]
[Mon Jul 20 06:22:20.603137 2026] [security2:error] [pid 915741:tid 915992] [client 185.132.186.64:55749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/file.php"] [unique_id "al4S_K-615n1P-attmyyPAAAAgg"]
[Mon Jul 20 06:22:20.637022 2026] [security2:error] [pid 915741:tid 915981] [client 57.141.18.48:22192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-K-615n1P-attmyxjwAB_WY"]
[Mon Jul 20 06:22:20.806526 2026] [security2:error] [pid 915741:tid 915905] [client 14.225.17.146:61389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4S-6-615n1P-attmyyDwAAAbE"], referer: http://momheadquarters.com/Wp
[Mon Jul 20 06:22:21.172331 2026] [security2:error] [pid 884009:tid 884258] [client 54.244.177.189:47018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4S_RKaHUf6J8d3elJqFAAAAPo"]
[Mon Jul 20 06:22:21.250643 2026] [security2:error] [pid 884009:tid 884252] [client 77.110.127.138:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_RKaHUf6J8d3elJqGgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:21.250729 2026] [security2:error] [pid 884009:tid 884252] [client 77.110.127.138:61226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_RKaHUf6J8d3elJqGgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:21.335382 2026] [security2:error] [pid 884009:tid 884238] [client 74.7.227.179:33688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4S_RKaHUf6J8d3elJqFQAA5ks"], referer: https://tejasenvironmental.com/p=110265
[Mon Jul 20 06:22:21.484690 2026] [security2:error] [pid 884009:tid 884175] [client 57.141.18.48:22200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-RKaHUf6J8d3elJpdwAApws"]
[Mon Jul 20 06:22:21.866876 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S_a-615n1P-attmyyXgAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:22.015380 2026] [security2:error] [pid 915741:tid 915913] [client 27.96.94.195:37906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyyeQAAAbk"]
[Mon Jul 20 06:22:22.015541 2026] [security2:error] [pid 915741:tid 915913] [client 27.96.94.195:37906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyyeQAAAbk"]
[Mon Jul 20 06:22:22.041671 2026] [security2:error] [pid 915741:tid 915910] [client 74.208.214.194:40714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4S_q-615n1P-attmyyegAAAbY"]
[Mon Jul 20 06:22:22.116151 2026] [security2:error] [pid 915741:tid 915950] [client 57.141.18.48:22212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-a-615n1P-attmyxuwAB3nY"]
[Mon Jul 20 06:22:22.135166 2026] [security2:error] [pid 915741:tid 915772] [remote 57.141.18.114:34902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6035871"] [unique_id "al4S_q-615n1P-attmyyfgACDB4"]
[Mon Jul 20 06:22:22.436779 2026] [security2:error] [pid 915741:tid 915918] [client 185.132.186.63:60055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-content/themes.php"] [unique_id "al4S_q-615n1P-attmyykwAAAb4"]
[Mon Jul 20 06:22:22.613779 2026] [security2:error] [pid 915741:tid 915940] [client 41.173.37.102:10536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyymwAAAdQ"]
[Mon Jul 20 06:22:22.613928 2026] [security2:error] [pid 915741:tid 915940] [client 41.173.37.102:10536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4S_q-615n1P-attmyymwAAAdQ"]
[Mon Jul 20 06:22:22.634105 2026] [security2:error] [pid 915741:tid 915774] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S_q-615n1P-attmyynAABpyA"]
[Mon Jul 20 06:22:22.907614 2026] [security2:error] [pid 915741:tid 915927] [client 14.225.17.146:61770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4S_a-615n1P-attmyyUgAAAcc"], referer: https://north-woods-engineering.com/Wp
[Mon Jul 20 06:22:23.086492 2026] [security2:error] [pid 915741:tid 915976] [client 14.225.17.146:51835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4S_q-615n1P-attmyyjAAAAfg"], referer: http://idigress.studio/Wp
[Mon Jul 20 06:22:23.173565 2026] [security2:error] [pid 915741:tid 915808] [remote 160.187.68.132:39080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4S_6-615n1P-attmyytAAB9UI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:23.240532 2026] [security2:error] [pid 884009:tid 884234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S_hKaHUf6J8d3elJqVgAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:23.553674 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S_xKaHUf6J8d3elJqfAAAANg"]
[Mon Jul 20 06:22:23.553786 2026] [security2:error] [pid 884009:tid 884224] [client 112.208.70.94:45471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4S_xKaHUf6J8d3elJqfAAAANg"]
[Mon Jul 20 06:22:23.852589 2026] [security2:error] [pid 884009:tid 884265] [client 77.110.127.138:61252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_xKaHUf6J8d3elJqjQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:23.852689 2026] [security2:error] [pid 884009:tid 884265] [client 77.110.127.138:61252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4S_xKaHUf6J8d3elJqjQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:23.895778 2026] [security2:error] [pid 915741:tid 915945] [client 14.225.17.146:51687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4S_q-615n1P-attmyynQAAAdk"], referer: http://collectingrealestate.com/Wp
[Mon Jul 20 06:22:23.985816 2026] [security2:error] [pid 884009:tid 884242] [client 57.141.18.89:31364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S-xKaHUf6J8d3elJpzAAA6ho"]
[Mon Jul 20 06:22:24.141274 2026] [security2:error] [pid 915741:tid 915879] [client 50.116.65.227:26408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4TAK-615n1P-attmyy0wAAAZc"]
[Mon Jul 20 06:22:24.143274 2026] [security2:error] [pid 884009:tid 884229] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4S_xKaHUf6J8d3elJqhwAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:24.152507 2026] [security2:error] [pid 915741:tid 915949] [client 50.116.65.227:48912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4TAK-615n1P-attmyy1AAAAaw"]
[Mon Jul 20 06:22:24.221361 2026] [security2:error] [pid 884009:tid 884217] [client 171.61.165.146:10040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqmwAAANE"]
[Mon Jul 20 06:22:24.221563 2026] [security2:error] [pid 884009:tid 884217] [client 171.61.165.146:10040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqmwAAANE"]
[Mon Jul 20 06:22:24.353031 2026] [security2:error] [pid 915741:tid 915930] [client 103.59.160.95:63580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy2AAAAco"]
[Mon Jul 20 06:22:24.381190 2026] [security2:error] [pid 884009:tid 884020] [remote 20.153.140.50:58614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqpAAAzQk"]
[Mon Jul 20 06:22:24.381419 2026] [security2:error] [pid 884009:tid 884213] [client 20.153.140.50:58614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqpAAAzQk"]
[Mon Jul 20 06:22:24.454616 2026] [security2:error] [pid 884009:tid 884148] [client 103.59.160.95:63589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4TABKaHUf6J8d3elJqqAAAAI0"]
[Mon Jul 20 06:22:24.566788 2026] [security2:error] [pid 915741:tid 915934] [client 103.59.160.95:63580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.160.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/xmlrpc.php"] [unique_id "al4TAK-615n1P-attmyy4wAAAc4"]
[Mon Jul 20 06:22:24.668627 2026] [security2:error] [pid 884009:tid 884236] [client 103.59.160.95:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.160.59.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/xmlrpc.php"] [unique_id "al4TABKaHUf6J8d3elJqtQAAAOQ"]
[Mon Jul 20 06:22:25.004965 2026] [security2:error] [pid 915741:tid 915994] [client 14.225.17.146:62957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4S_6-615n1P-attmyysQAAAgo"], referer: http://narv.co/Wp
[Mon Jul 20 06:22:25.045632 2026] [security2:error] [pid 884009:tid 884107] [remote 93.177.75.10:51354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.75.177.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4TABKaHUf6J8d3elJqvwAAqmA"], referer: https://aviationsynergy.aero/
[Mon Jul 20 06:22:25.052691 2026] [security2:error] [pid 884009:tid 884172] [client 57.141.18.37:30304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_BKaHUf6J8d3elJp-wAApDA"]
[Mon Jul 20 06:22:25.113974 2026] [security2:error] [pid 915741:tid 915923] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy8QABwys"], referer: http://aleishapenny.ca/Wp
[Mon Jul 20 06:22:25.131588 2026] [security2:error] [pid 915741:tid 915792] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TAa-615n1P-attmyy-QAB2TI"]
[Mon Jul 20 06:22:25.132283 2026] [security2:error] [pid 915741:tid 915945] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TAa-615n1P-attmyy-QAB2TI"]
[Mon Jul 20 06:22:25.202147 2026] [security2:error] [pid 915741:tid 915878] [client 103.153.183.69:49412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4TAa-615n1P-attmyy_wAAAZY"], referer: https://www.google.com/search?q=9mhjo7
[Mon Jul 20 06:22:25.266808 2026] [security2:error] [pid 884009:tid 884185] [client 119.74.54.159:38826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4TARKaHUf6J8d3elJqyAAAALE"]
[Mon Jul 20 06:22:25.300546 2026] [security2:error] [pid 915741:tid 915973] [client 185.132.186.68:40855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "al4TAa-615n1P-attmyzCQAAAfU"]
[Mon Jul 20 06:22:25.306313 2026] [lsapi:warn] [pid 915741:tid 915954] [client 14.225.17.146:62965] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:25.306342 2026] [lsapi:warn] [pid 915741:tid 915954] [client 14.225.17.146:62965] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:25.315100 2026] [security2:error] [pid 915741:tid 915764] [remote 117.0.21.154:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4TAa-615n1P-attmyzCAAB2hY"]
[Mon Jul 20 06:22:25.440852 2026] [security2:error] [pid 915741:tid 915911] [client 103.59.160.95:64116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TAa-615n1P-attmyzFwAAAbc"]
[Mon Jul 20 06:22:25.522668 2026] [security2:error] [pid 915741:tid 915883] [client 74.7.228.53:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4TAa-615n1P-attmyzIAAAAZs"]
[Mon Jul 20 06:22:25.532939 2026] [security2:error] [pid 915741:tid 915974] [client 74.7.228.53:45914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.processorstudio.com"] [uri "/robots.txt"] [unique_id "al4TAa-615n1P-attmyzGAAB9jc"]
[Mon Jul 20 06:22:25.563225 2026] [security2:error] [pid 915741:tid 915871] [client 113.169.53.224:51360] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4TAa-615n1P-attmyzJQAAAY8"]
[Mon Jul 20 06:22:25.617448 2026] [security2:error] [pid 884009:tid 884184] [client 103.59.160.95:64131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TARKaHUf6J8d3elJq3AAAALA"]
[Mon Jul 20 06:22:25.657148 2026] [security2:error] [pid 915741:tid 915938] [client 45.13.6.125:54376] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4TAa-615n1P-attmyzKQAAAdI"]
[Mon Jul 20 06:22:25.717500 2026] [security2:error] [pid 915741:tid 915909] [client 82.39.10.58:44278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4TAa-615n1P-attmyzKwAAAbU"]
[Mon Jul 20 06:22:25.725865 2026] [security2:error] [pid 884009:tid 884200] [client 84.70.126.40:48114] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4TARKaHUf6J8d3elJq4QAAAMA"]
[Mon Jul 20 06:22:25.764561 2026] [security2:error] [pid 915741:tid 915969] [client 66.131.17.83:57504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4TAa-615n1P-attmyzLQAAAfE"]
[Mon Jul 20 06:22:25.792958 2026] [security2:error] [pid 884009:tid 884240] [client 14.225.17.146:63063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4TABKaHUf6J8d3elJqoAAAAOg"], referer: http://chestermonty.com/Wp
[Mon Jul 20 06:22:25.859776 2026] [security2:error] [pid 915741:tid 915900] [client 86.202.104.235:59434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4TAa-615n1P-attmyzMAAAAaw"]
[Mon Jul 20 06:22:25.880994 2026] [lsapi:warn] [pid 915741:tid 915985] [client 50.116.65.227:48938] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:22:25.881016 2026] [lsapi:warn] [pid 915741:tid 915985] [client 50.116.65.227:48938] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:22:25.896633 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:62965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy7AAAAeI"], referer: http://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:25.949024 2026] [security2:error] [pid 915741:tid 915889] [client 76.70.92.140:48536] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4TAa-615n1P-attmyzOQAAAaE"]
[Mon Jul 20 06:22:25.985564 2026] [security2:error] [pid 915741:tid 915970] [client 187.136.224.75:4697] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4TAa-615n1P-attmyzPwAAAfI"]
[Mon Jul 20 06:22:25.992258 2026] [security2:error] [pid 884009:tid 884246] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TARKaHUf6J8d3elJq5QAA7nY"], referer: https://aleishapenny.ca/Wp
[Mon Jul 20 06:22:26.043400 2026] [security2:error] [pid 884009:tid 884168] [client 79.16.35.47:45772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4TAhKaHUf6J8d3elJq8gAAAKE"]
[Mon Jul 20 06:22:26.048236 2026] [security2:error] [pid 915741:tid 915956] [client 14.225.17.146:63292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4TAa-615n1P-attmyzMgAAAeQ"], referer: https://narv.co/Wp
[Mon Jul 20 06:22:26.115782 2026] [security2:error] [pid 915741:tid 915958] [client 57.141.18.40:65440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_a-615n1P-attmyyYwAB5hc"]
[Mon Jul 20 06:22:26.202205 2026] [security2:error] [pid 915741:tid 915876] [client 3.75.183.99:40144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TAq-615n1P-attmyzSAAAAZQ"]
[Mon Jul 20 06:22:26.202369 2026] [security2:error] [pid 915741:tid 915876] [client 3.75.183.99:40144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TAq-615n1P-attmyzSAAAAZQ"]
[Mon Jul 20 06:22:26.235662 2026] [security2:error] [pid 915741:tid 915804] [remote 117.0.21.154:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4TAq-615n1P-attmyzSQABkT4"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 06:22:26.284616 2026] [security2:error] [pid 915741:tid 915882] [client 2.82.223.226:41422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4TAq-615n1P-attmyzTQAAAZo"]
[Mon Jul 20 06:22:26.293394 2026] [security2:error] [pid 884009:tid 884165] [client 47.128.114.143:26400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.allergyantidotes.com"] [uri "/robots.txt"] [unique_id "al4TAhKaHUf6J8d3elJq-wAAAJ4"]
[Mon Jul 20 06:22:26.407857 2026] [security2:error] [pid 884009:tid 884143] [client 103.59.160.95:64513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TAhKaHUf6J8d3elJrAgAAAIg"]
[Mon Jul 20 06:22:26.504785 2026] [security2:error] [pid 915741:tid 915979] [client 103.59.160.95:64588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TAq-615n1P-attmyzWQAAAfs"]
[Mon Jul 20 06:22:26.700587 2026] [lsapi:warn] [pid 915741:tid 915982] [client 14.225.17.146:60959] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:26.700609 2026] [lsapi:warn] [pid 915741:tid 915982] [client 14.225.17.146:60959] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:26.712009 2026] [security2:error] [pid 915741:tid 915968] [client 14.225.17.146:63151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4TAq-615n1P-attmyzXgAAAfA"], referer: https://chestermonty.com/Wp
[Mon Jul 20 06:22:26.753705 2026] [security2:error] [pid 915741:tid 915982] [client 14.225.17.146:60959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4TAq-615n1P-attmyzYQAAAf4"], referer: https://oswegooperatheater.com/Wp
[Mon Jul 20 06:22:26.790337 2026] [security2:error] [pid 884009:tid 884161] [client 14.225.17.146:54485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4TAhKaHUf6J8d3elJrDAAAAJo"], referer: http://friendlyspreadsheet.com/Wp
[Mon Jul 20 06:22:26.827049 2026] [security2:error] [pid 915741:tid 915947] [client 50.116.65.227:26422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Feature-Image.jpg"] [unique_id "al4TAq-615n1P-attmyzZwAAAds"]
[Mon Jul 20 06:22:26.840854 2026] [security2:error] [pid 915741:tid 915902] [client 50.116.65.227:48954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Feature-Image.jpg"] [unique_id "al4TAq-615n1P-attmyzaAAAAa4"]
[Mon Jul 20 06:22:26.869066 2026] [fcgid:warn] [pid 915741:tid 915930] (70014)End of file found: [client 66.132.172.201:22056] mod_fcgid: can't get data from http client
[Mon Jul 20 06:22:27.185867 2026] [security2:error] [pid 915741:tid 915906] [client 14.225.17.146:49901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4TAq-615n1P-attmyzbQAAAbI"], referer: http://maxenengineering.com/Wp
[Mon Jul 20 06:22:27.235676 2026] [security2:error] [pid 915741:tid 915883] [client 38.159.162.81:34952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4TA6-615n1P-attmyzewAAAZs"]
[Mon Jul 20 06:22:27.259303 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.109:29924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_q-615n1P-attmyymgAB-iU"]
[Mon Jul 20 06:22:27.272178 2026] [security2:error] [pid 915741:tid 915911] [client 103.59.160.95:64992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TA6-615n1P-attmyzfAAAAbc"]
[Mon Jul 20 06:22:27.345139 2026] [security2:error] [pid 915741:tid 915992] [client 103.59.160.95:65034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TA6-615n1P-attmyzggAAAgg"]
[Mon Jul 20 06:22:27.458431 2026] [lsapi:warn] [pid 915741:tid 915806] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 06:22:27.524327 2026] [lsapi:warn] [pid 915741:tid 915778] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 06:22:27.546816 2026] [lsapi:warn] [pid 915741:tid 915807] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 06:22:27.685231 2026] [security2:error] [pid 915741:tid 915962] [client 14.225.17.146:63061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyziwAAAeo"], referer: https://friendlyspreadsheet.com/Wp
[Mon Jul 20 06:22:27.690301 2026] [security2:error] [pid 915741:tid 915828] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.rzj.zfx.mybluehost.me"] [uri "/.env.old"] [unique_id "al4TA6-615n1P-attmyzkQABkFY"]
[Mon Jul 20 06:22:27.947542 2026] [security2:error] [pid 915741:tid 915771] [remote 154.61.75.100:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4TA6-615n1P-attmyzoQAB_x0"]
[Mon Jul 20 06:22:28.040740 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:60775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyzmAAAAfU"], referer: http://mezzacraft.com/Wp
[Mon Jul 20 06:22:28.051066 2026] [security2:error] [pid 915741:tid 915982] [client 14.225.17.146:63279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyzngAAAf4"], referer: http://taskidsvirginia.com/Wp
[Mon Jul 20 06:22:28.124276 2026] [security2:error] [pid 915741:tid 915945] [client 185.132.186.68:26173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/load.php"] [unique_id "al4TBK-615n1P-attmyzqwAAAdk"]
[Mon Jul 20 06:22:28.144689 2026] [security2:error] [pid 884009:tid 884246] [client 103.59.160.95:65355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TBBKaHUf6J8d3elJrRAAAAO4"]
[Mon Jul 20 06:22:28.146922 2026] [security2:error] [pid 884009:tid 884202] [client 57.141.18.101:54914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4S_xKaHUf6J8d3elJqbQAAwhw"]
[Mon Jul 20 06:22:28.159642 2026] [security2:error] [pid 915741:tid 915937] [client 14.225.17.146:63346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4TBK-615n1P-attmyzpQAAAdE"], referer: https://maxenengineering.com/Wp
[Mon Jul 20 06:22:28.204358 2026] [security2:error] [pid 915741:tid 915995] [client 103.59.160.95:65376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TBK-615n1P-attmyzrQAAAgs"]
[Mon Jul 20 06:22:28.450088 2026] [security2:error] [pid 915741:tid 915842] [remote 154.61.75.100:42294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4TBK-615n1P-attmyzuQABnmQ"], referer: https://grndl.com/wp-login.php
[Mon Jul 20 06:22:28.470717 2026] [security2:error] [pid 915741:tid 915906] [client 77.110.127.138:61271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TBK-615n1P-attmyzrwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.584832 2026] [security2:error] [pid 884009:tid 884156] [client 171.60.139.123:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TBBKaHUf6J8d3elJrUQAAAJU"]
[Mon Jul 20 06:22:28.584968 2026] [security2:error] [pid 884009:tid 884156] [client 171.60.139.123:62489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TBBKaHUf6J8d3elJrUQAAAJU"]
[Mon Jul 20 06:22:28.751325 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61278] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4TBK-615n1P-attmyzwgAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.909285 2026] [security2:error] [pid 884009:tid 884264] [client 77.110.127.138:61280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TBBKaHUf6J8d3elJrZQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.909400 2026] [security2:error] [pid 884009:tid 884264] [client 77.110.127.138:61280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TBBKaHUf6J8d3elJrZQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:28.968821 2026] [security2:error] [pid 915741:tid 915903] [client 57.141.18.54:48446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy1QABryw"]
[Mon Jul 20 06:22:29.042897 2026] [security2:error] [pid 915741:tid 915882] [client 103.153.183.69:23704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//var/www/html/config.php"] [unique_id "al4TBa-615n1P-attmyz1AAAAZo"], referer: https://t.co/wkz1vkhiqw
[Mon Jul 20 06:22:29.053909 2026] [security2:error] [pid 884009:tid 884199] [client 103.59.160.95:49385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrbQAAAL8"]
[Mon Jul 20 06:22:29.082046 2026] [security2:error] [pid 884009:tid 884225] [client 103.59.160.95:49421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrbwAAANk"]
[Mon Jul 20 06:22:29.457625 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:63268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyznQAAAeI"], referer: http://guidehunting.com/Wp
[Mon Jul 20 06:22:29.475852 2026] [security2:error] [pid 915741:tid 915935] [client 57.141.18.76:47154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TAK-615n1P-attmyy6QABzy0"]
[Mon Jul 20 06:22:29.499622 2026] [security2:error] [pid 915741:tid 915937] [client 45.116.69.230:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TBa-615n1P-attmyz7AAAAdE"]
[Mon Jul 20 06:22:29.500242 2026] [security2:error] [pid 915741:tid 915937] [client 45.116.69.230:54599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TBa-615n1P-attmyz7AAAAdE"]
[Mon Jul 20 06:22:29.527076 2026] [security2:error] [pid 915741:tid 915890] [client 14.225.17.146:63081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4TA6-615n1P-attmyzjAAAAaI"], referer: http://partnerselectricalllc.com/Wp
[Mon Jul 20 06:22:29.578021 2026] [lsapi:warn] [pid 915741:tid 915857] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:22:29.716048 2026] [lsapi:warn] [pid 915741:tid 915813] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:22:29.723917 2026] [lsapi:warn] [pid 915741:tid 915748] [remote 18.217.226.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:22:29.876703 2026] [core:error] [pid 884009:tid 884144] [client 198.235.24.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:29.876726 2026] [core:error] [pid 884009:tid 884144] [client 198.235.24.53:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:29.889011 2026] [security2:error] [pid 884009:tid 884220] [client 103.59.160.95:49785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrvgAAANQ"]
[Mon Jul 20 06:22:29.938973 2026] [security2:error] [pid 884009:tid 884261] [client 185.132.186.80:32499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/ID3/chosen.php"] [unique_id "al4TBRKaHUf6J8d3elJrwAAAAP0"]
[Mon Jul 20 06:22:29.939676 2026] [security2:error] [pid 884009:tid 884149] [client 103.59.160.95:49786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TBRKaHUf6J8d3elJrwgAAAI4"]
[Mon Jul 20 06:22:30.063383 2026] [security2:error] [pid 915741:tid 915930] [client 103.141.108.143:55122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmyz_gAAAco"]
[Mon Jul 20 06:22:30.063490 2026] [security2:error] [pid 915741:tid 915930] [client 103.141.108.143:55122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmyz_gAAAco"]
[Mon Jul 20 06:22:30.094202 2026] [security2:error] [pid 915741:tid 915947] [client 77.110.127.138:61288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TBa-615n1P-attmyz9QAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:30.164166 2026] [core:error] [pid 915741:tid 915938] [client 103.153.183.69:35200] AH10244: invalid URI path (/%2e./etc/passwd?_=1mr0sxrq&v=re4ov), referer: https://www.google.com/
[Mon Jul 20 06:22:30.167087 2026] [security2:error] [pid 915741:tid 915990] [client 127.0.0.1:25270] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TBq-615n1P-attmy0BAAAAgY"], referer: https://www.google.com/
[Mon Jul 20 06:22:30.431682 2026] [core:error] [pid 915741:tid 915957] [client 103.153.183.69:35216] AH10244: invalid URI path (/../../../etc/passwd?_=mkjq29j9&v=9u3sq), referer: https://www.bing.com/search?q=j4tdfc
[Mon Jul 20 06:22:30.434913 2026] [security2:error] [pid 884009:tid 884268] [client 127.0.0.1:25276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TBhKaHUf6J8d3elJr5wAAAQQ"], referer: https://www.bing.com/search?q=j4tdfc
[Mon Jul 20 06:22:30.579960 2026] [security2:error] [pid 915741:tid 915900] [client 178.152.178.232:35983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmy0HgAAAaw"]
[Mon Jul 20 06:22:30.580112 2026] [security2:error] [pid 915741:tid 915900] [client 178.152.178.232:35983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TBq-615n1P-attmy0HgAAAaw"]
[Mon Jul 20 06:22:30.628300 2026] [security2:error] [pid 915741:tid 915891] [client 14.225.17.146:61314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4TBq-615n1P-attmy0DgAAAaM"], referer: https://guidehunting.com/Wp
[Mon Jul 20 06:22:30.676525 2026] [security2:error] [pid 915741:tid 915942] [client 154.29.87.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vtv.zzt.mybluehost.me"] [uri "/index.php"] [unique_id "al4TBq-615n1P-attmy0GgAAAdY"]
[Mon Jul 20 06:22:30.798701 2026] [security2:error] [pid 915741:tid 915935] [client 103.59.160.95:50136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TBq-615n1P-attmy0JwAAAc8"]
[Mon Jul 20 06:22:30.798722 2026] [security2:error] [pid 915741:tid 915985] [client 103.59.160.95:50178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TBq-615n1P-attmy0KAAAAgE"]
[Mon Jul 20 06:22:30.846433 2026] [security2:error] [pid 915741:tid 915906] [client 14.225.17.146:49944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4TBq-615n1P-attmy0GwAAAbI"], referer: http://healthylifegourmet.org/Wp
[Mon Jul 20 06:22:31.536209 2026] [security2:error] [pid 915741:tid 915969] [client 168.144.240.66:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "prontomc.co.uk"] [uri "/license.txt"] [unique_id "al4TB6-615n1P-attmy0RAAAAfE"]
[Mon Jul 20 06:22:31.691386 2026] [security2:error] [pid 915741:tid 915987] [client 103.59.160.95:50680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TB6-615n1P-attmy0SgAAAgM"]
[Mon Jul 20 06:22:31.765700 2026] [security2:error] [pid 884009:tid 884200] [client 185.132.186.67:58287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.186.132.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "harborhealth.us"] [uri "/wp-includes/class-wp-theme-float.php"] [unique_id "al4TBxKaHUf6J8d3elJsGgAAAMA"]
[Mon Jul 20 06:22:31.785797 2026] [security2:error] [pid 884009:tid 884190] [client 103.153.183.69:23720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//var/www/html/configuration.php"] [unique_id "al4TBxKaHUf6J8d3elJsHAAAALY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:22:31.822894 2026] [security2:error] [pid 884009:tid 884258] [client 66.249.73.66:63920] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "w.saphansiam.org"] [uri "/robots.txt"] [unique_id "al4TBxKaHUf6J8d3elJsHgAAAPo"]
[Mon Jul 20 06:22:32.059789 2026] [core:error] [pid 915741:tid 915933] [client 103.153.183.69:35218] AH10244: invalid URI path (/../../../../etc/passwd?_=bcs5jg30&v=ki7zf), referer: https://www.reddit.com/
[Mon Jul 20 06:22:32.063001 2026] [security2:error] [pid 915741:tid 915902] [client 127.0.0.1:25280] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TCK-615n1P-attmy0WwAAAa4"], referer: https://www.reddit.com/
[Mon Jul 20 06:22:32.082848 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.48:40324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TAq-615n1P-attmyzbgABqEg"]
[Mon Jul 20 06:22:32.189418 2026] [security2:error] [pid 915741:tid 915921] [client 103.59.160.95:50695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TCK-615n1P-attmy0XQAAAcE"]
[Mon Jul 20 06:22:32.209350 2026] [security2:error] [pid 915741:tid 915915] [client 103.153.183.69:23722] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../app/.env"] [unique_id "al4TCK-615n1P-attmy0XgAAAbs"], referer: https://t.co/00fyu8er5x
[Mon Jul 20 06:22:32.380547 2026] [fcgid:warn] [pid 915741:tid 915946] (70014)End of file found: [client 66.132.172.201:22062] mod_fcgid: can't get data from http client
[Mon Jul 20 06:22:32.449094 2026] [core:error] [pid 915741:tid 915874] [client 103.153.183.69:35230] AH10244: invalid URI path (/../.env?_=35dq137n&v=c1my6), referer: https://www.google.com/search?q=ypld9y
[Mon Jul 20 06:22:32.552150 2026] [security2:error] [pid 884009:tid 884205] [client 103.59.160.95:51110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TCBKaHUf6J8d3elJsRQAAAMU"]
[Mon Jul 20 06:22:32.656496 2026] [security2:error] [pid 915741:tid 915750] [remote 182.77.62.24:34466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TCK-615n1P-attmy0cgAB1Qg"]
[Mon Jul 20 06:22:32.656703 2026] [security2:error] [pid 915741:tid 915941] [client 182.77.62.24:34466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TCK-615n1P-attmy0cgAB1Qg"]
[Mon Jul 20 06:22:32.665256 2026] [security2:error] [pid 915741:tid 915755] [remote 100.42.189.89:44502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4TCK-615n1P-attmy0cwACCg0"]
[Mon Jul 20 06:22:32.777361 2026] [security2:error] [pid 884009:tid 884213] [client 103.153.183.69:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/.env"] [unique_id "al4TCBKaHUf6J8d3elJsSwAAAM0"], referer: https://www.reddit.com/
[Mon Jul 20 06:22:32.833893 2026] [security2:error] [pid 884009:tid 884179] [client 77.110.127.138:61303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TCBKaHUf6J8d3elJsSAAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:32.868917 2026] [security2:error] [pid 884009:tid 884264] [client 103.153.183.69:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4TCBKaHUf6J8d3elJsUQAAAQA"], referer: https://duckduckgo.com/?q=rnkcp
[Mon Jul 20 06:22:32.975495 2026] [security2:error] [pid 884009:tid 884266] [client 103.153.183.69:31982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4TCBKaHUf6J8d3elJsWgAAAQI"], referer: https://www.google.com/
[Mon Jul 20 06:22:33.017312 2026] [security2:error] [pid 884009:tid 884255] [client 77.110.127.138:61304] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4TCRKaHUf6J8d3elJsXAAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:33.063887 2026] [security2:error] [pid 884009:tid 884194] [client 103.59.160.95:51275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TCRKaHUf6J8d3elJsXgAAALo"]
[Mon Jul 20 06:22:33.095932 2026] [security2:error] [pid 915741:tid 915972] [client 14.225.17.146:61128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4TB6-615n1P-attmy0RwAAAfQ"], referer: http://reosportsboats.com/Wp
[Mon Jul 20 06:22:33.222772 2026] [security2:error] [pid 915741:tid 915757] [remote 100.42.189.89:44502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4TCa-615n1P-attmy0igABug8"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 06:22:33.266930 2026] [security2:error] [pid 884009:tid 884190] [client 77.110.127.138:61307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TCRKaHUf6J8d3elJsYgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:33.267091 2026] [security2:error] [pid 884009:tid 884190] [client 77.110.127.138:61307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TCRKaHUf6J8d3elJsYgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:33.296509 2026] [security2:error] [pid 915741:tid 915876] [client 41.173.37.102:10957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TCa-615n1P-attmy0iwAAAZQ"]
[Mon Jul 20 06:22:33.296599 2026] [security2:error] [pid 915741:tid 915876] [client 41.173.37.102:10957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TCa-615n1P-attmy0iwAAAZQ"]
[Mon Jul 20 06:22:33.503721 2026] [security2:error] [pid 884009:tid 884250] [client 103.59.160.95:51385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TCRKaHUf6J8d3elJsbwAAAPI"]
[Mon Jul 20 06:22:33.568822 2026] [security2:error] [pid 915741:tid 915884] [client 57.141.18.106:24024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBK-615n1P-attmyzugABnGk"]
[Mon Jul 20 06:22:33.570837 2026] [security2:error] [pid 915741:tid 915955] [client 185.132.186.64:34417] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TCa-615n1P-attmy0mAAAAeM"]
[Mon Jul 20 06:22:33.905376 2026] [security2:error] [pid 915741:tid 915899] [client 57.141.18.49:63862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBK-615n1P-attmyzxQABq1Q"]
[Mon Jul 20 06:22:33.905629 2026] [security2:error] [pid 915741:tid 915967] [client 103.59.160.95:51686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TCa-615n1P-attmy0pQAAAe8"]
[Mon Jul 20 06:22:33.973179 2026] [core:error] [pid 915741:tid 915879] [client 14.225.17.146:63168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:33.973209 2026] [core:error] [pid 915741:tid 915879] [client 14.225.17.146:63168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:22:34.053793 2026] [security2:error] [pid 915741:tid 915990] [client 14.225.17.146:61674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4TCa-615n1P-attmy0qQAAAgY"], referer: https://reosportsboats.com/Wp
[Mon Jul 20 06:22:34.296346 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:49951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4TCa-615n1P-attmy0iAAAAeI"]
[Mon Jul 20 06:22:34.412921 2026] [security2:error] [pid 915741:tid 915980] [client 103.59.160.95:51846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TCq-615n1P-attmy0xQAAAfw"]
[Mon Jul 20 06:22:34.543054 2026] [security2:error] [pid 915741:tid 915959] [client 57.141.18.43:32262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBa-615n1P-attmyz6wAB5wc"]
[Mon Jul 20 06:22:34.704648 2026] [security2:error] [pid 915741:tid 915916] [client 77.110.127.138:61318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TCq-615n1P-attmy0xgAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:34.787027 2026] [security2:error] [pid 915741:tid 915941] [client 103.59.160.95:52012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TCq-615n1P-attmy01QAAAdU"]
[Mon Jul 20 06:22:34.882911 2026] [proxy:error] [pid 871012:tid 871116] (70007)The timeout specified has expired: [remote 80.210.17.232:52592] AH01095: prefetch request body failed to 127.0.0.1:8443 (127.0.0.1) from 80.210.17.232 (), referer: https://jenfarley.com/about/
[Mon Jul 20 06:22:34.903857 2026] [security2:error] [pid 915741:tid 915785] [remote 162.19.86.63:32814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TCq-615n1P-attmy02gAB3is"]
[Mon Jul 20 06:22:34.910033 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.98:24608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TBa-615n1P-attmyz8QAB3HI"]
[Mon Jul 20 06:22:34.918649 2026] [security2:error] [pid 915741:tid 915944] [client 50.116.65.227:47568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TCq-615n1P-attmy02wAAAdg"]
[Mon Jul 20 06:22:34.930933 2026] [security2:error] [pid 915741:tid 915947] [client 50.116.65.227:26362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TCq-615n1P-attmy03AAAAes"]
[Mon Jul 20 06:22:34.944144 2026] [security2:error] [pid 915741:tid 915986] [client 27.96.94.195:37655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TCq-615n1P-attmy03gAAAgI"]
[Mon Jul 20 06:22:34.944271 2026] [security2:error] [pid 915741:tid 915986] [client 27.96.94.195:37655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TCq-615n1P-attmy03gAAAgI"]
[Mon Jul 20 06:22:35.076653 2026] [security2:error] [pid 915741:tid 915930] [client 198.98.59.181:59953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.59.98.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.coachpops.org"] [uri "/wp-login.php"] [unique_id "al4TC6-615n1P-attmy04gAAAco"]
[Mon Jul 20 06:22:35.110424 2026] [security2:error] [pid 915741:tid 915792] [remote 162.19.86.63:32814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TC6-615n1P-attmy05AAB4TI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:22:35.120803 2026] [security2:error] [pid 884009:tid 884261] [client 171.61.165.146:21734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJstQAAAP0"]
[Mon Jul 20 06:22:35.120929 2026] [security2:error] [pid 884009:tid 884261] [client 171.61.165.146:21734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJstQAAAP0"]
[Mon Jul 20 06:22:35.311473 2026] [security2:error] [pid 915741:tid 915937] [client 98.159.234.160:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TC6-615n1P-attmy07QAAAdE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:35.383967 2026] [security2:error] [pid 884009:tid 884151] [client 103.59.160.95:52223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TCxKaHUf6J8d3elJswQAAAJA"]
[Mon Jul 20 06:22:35.412203 2026] [security2:error] [pid 915741:tid 915918] [client 185.132.186.86:64061] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TC6-615n1P-attmy09gAAAb4"]
[Mon Jul 20 06:22:35.487758 2026] [security2:error] [pid 884009:tid 884048] [remote 47.86.33.52:11598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TCxKaHUf6J8d3elJsxgAAjSU"]
[Mon Jul 20 06:22:35.806984 2026] [security2:error] [pid 884009:tid 884039] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJs1QAA3Bw"]
[Mon Jul 20 06:22:35.807147 2026] [security2:error] [pid 884009:tid 884228] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TCxKaHUf6J8d3elJs1QAA3Bw"]
[Mon Jul 20 06:22:35.986140 2026] [security2:error] [pid 884009:tid 884127] [remote 47.86.33.52:11598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TCxKaHUf6J8d3elJs4AAAiXQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:22:36.013852 2026] [security2:error] [pid 884009:tid 884253] [client 77.110.127.138:61323] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cake-recipe/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4TDBKaHUf6J8d3elJs5wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:36.125717 2026] [security2:error] [pid 915741:tid 915875] [client 14.225.17.146:54631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4TCq-615n1P-attmy0ywAAAZM"], referer: http://eframiproperties.com/Wp
[Mon Jul 20 06:22:36.171549 2026] [security2:error] [pid 915741:tid 915898] [client 77.110.127.138:61328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDK-615n1P-attmy1AgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:36.171694 2026] [security2:error] [pid 915741:tid 915898] [client 77.110.127.138:61328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDK-615n1P-attmy1AgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:36.503079 2026] [security2:error] [pid 915741:tid 915983] [client 57.141.18.13:59718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TB6-615n1P-attmy0PAAB_3Q"]
[Mon Jul 20 06:22:36.579718 2026] [security2:error] [pid 915741:tid 915793] [remote 47.86.33.52:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4TDK-615n1P-attmy1HQABvzM"]
[Mon Jul 20 06:22:36.613861 2026] [security2:error] [pid 915741:tid 915888] [client 104.234.53.63:57987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TDK-615n1P-attmy1FgAAAaA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:37.149020 2026] [security2:error] [pid 915741:tid 915928] [client 57.141.18.106:59066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TCK-615n1P-attmy0XwAByAs"]
[Mon Jul 20 06:22:37.167472 2026] [security2:error] [pid 884009:tid 884178] [client 77.110.127.138:61301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TDBKaHUf6J8d3elJtCgAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:37.261891 2026] [security2:error] [pid 915741:tid 915876] [client 185.132.186.64:25553] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TDa-615n1P-attmy1PAAAAZQ"]
[Mon Jul 20 06:22:37.351141 2026] [security2:error] [pid 915741:tid 915991] [client 104.28.159.66:49960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.159.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "santabear.space"] [uri "/wp-login.php"] [unique_id "al4TDa-615n1P-attmy1PQAAAgc"]
[Mon Jul 20 06:22:37.738448 2026] [security2:error] [pid 915741:tid 915901] [client 50.116.65.227:26398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TDa-615n1P-attmy1UQAAAa0"]
[Mon Jul 20 06:22:37.750062 2026] [security2:error] [pid 915741:tid 915931] [client 50.116.65.227:26402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TDa-615n1P-attmy1UgAAAcs"]
[Mon Jul 20 06:22:37.772015 2026] [security2:error] [pid 915741:tid 915911] [client 112.208.70.94:45967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TDa-615n1P-attmy1VgAAAbc"]
[Mon Jul 20 06:22:37.772144 2026] [security2:error] [pid 915741:tid 915911] [client 112.208.70.94:45967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TDa-615n1P-attmy1VgAAAbc"]
[Mon Jul 20 06:22:37.785515 2026] [security2:error] [pid 915741:tid 915958] [client 166.88.169.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tgs.lfg.mybluehost.me"] [uri "/index.php"] [unique_id "al4TDa-615n1P-attmy1QwAAAeY"]
[Mon Jul 20 06:22:37.849187 2026] [security2:error] [pid 915741:tid 915783] [remote 154.66.198.148:22794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TDa-615n1P-attmy1WAAB_Sk"]
[Mon Jul 20 06:22:37.911458 2026] [security2:error] [pid 884009:tid 884213] [client 93.177.75.10:65497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4TDRKaHUf6J8d3elJtPQAAAM0"], referer: https://aviationsynergy.aero/
[Mon Jul 20 06:22:38.074922 2026] [security2:error] [pid 884009:tid 884233] [client 77.110.127.138:61337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDhKaHUf6J8d3elJtRwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:38.075037 2026] [security2:error] [pid 884009:tid 884233] [client 77.110.127.138:61337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TDhKaHUf6J8d3elJtRwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:38.128495 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:55448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4TDa-615n1P-attmy1OwAAAd0"], referer: http://mobilesurvsolutions.com/Wp
[Mon Jul 20 06:22:38.315262 2026] [security2:error] [pid 884009:tid 884166] [client 50.116.65.227:26436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TDhKaHUf6J8d3elJtSgAAAJ8"]
[Mon Jul 20 06:22:38.451571 2026] [security2:error] [pid 915741:tid 915823] [remote 47.86.33.52:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4TDq-615n1P-attmy1cQABwlE"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:22:38.494695 2026] [security2:error] [pid 884009:tid 884172] [client 50.116.65.227:26450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TDhKaHUf6J8d3elJtVwAAAKQ"]
[Mon Jul 20 06:22:38.505349 2026] [security2:error] [pid 915741:tid 915807] [remote 154.66.198.148:22794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TDq-615n1P-attmy1cwABnEE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:22:38.535043 2026] [security2:error] [pid 915741:tid 915994] [client 57.141.18.96:47462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TCa-615n1P-attmy0lgACCnY"]
[Mon Jul 20 06:22:38.761175 2026] [security2:error] [pid 884009:tid 884248] [client 14.225.17.146:61778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4TDhKaHUf6J8d3elJtZAAAAPA"], referer: http://dereckcastellon.com/Wp
[Mon Jul 20 06:22:38.799832 2026] [security2:error] [pid 915741:tid 915983] [client 13.201.64.214:51762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TDq-615n1P-attmy1gwAAAf8"]
[Mon Jul 20 06:22:38.916466 2026] [security2:error] [pid 884009:tid 884176] [client 57.141.18.121:25682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TCRKaHUf6J8d3elJseQAAqDk"]
[Mon Jul 20 06:22:39.002682 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:61313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TDq-615n1P-attmy1ggAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:39.124630 2026] [security2:error] [pid 915741:tid 915929] [client 185.132.186.87:41643] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "harborhealth.us"] [uri "/images/c99.php"] [unique_id "al4TD6-615n1P-attmy1jAAAAck"]
[Mon Jul 20 06:22:39.164278 2026] [security2:error] [pid 915741:tid 915883] [client 35.162.140.124:49167] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thecreole.com"] [uri "/index.cgi"] [unique_id "al4TD6-615n1P-attmy1iwAAAZs"]
[Mon Jul 20 06:22:39.280985 2026] [security2:error] [pid 915741:tid 915886] [client 13.201.64.214:51764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1kwAAAZ4"]
[Mon Jul 20 06:22:39.281091 2026] [security2:error] [pid 915741:tid 915886] [client 13.201.64.214:51764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1kwAAAZ4"]
[Mon Jul 20 06:22:39.349572 2026] [security2:error] [pid 915741:tid 915981] [client 171.60.139.123:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1mAAAAf0"]
[Mon Jul 20 06:22:39.349707 2026] [security2:error] [pid 915741:tid 915981] [client 171.60.139.123:63007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TD6-615n1P-attmy1mAAAAf0"]
[Mon Jul 20 06:22:39.483792 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TD6-615n1P-attmy1oAAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:39.483892 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:61352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TD6-615n1P-attmy1oAAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:39.570855 2026] [security2:error] [pid 884009:tid 884268] [client 57.141.18.12:58186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TChKaHUf6J8d3elJslwABBEs"]
[Mon Jul 20 06:22:39.681161 2026] [security2:error] [pid 884009:tid 884220] [client 57.141.18.33:36902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TChKaHUf6J8d3elJsoAAA1Bs"]
[Mon Jul 20 06:22:39.880677 2026] [security2:error] [pid 915741:tid 915994] [client 43.205.139.3:21282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TD6-615n1P-attmy1qQAAAgo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:39.971839 2026] [security2:error] [pid 915741:tid 915967] [client 74.208.214.194:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TD6-615n1P-attmy1rgAAAe8"]
[Mon Jul 20 06:22:39.979447 2026] [security2:error] [pid 915741:tid 915919] [client 77.110.127.138:61319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TD6-615n1P-attmy1pwAAAb8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:40.167040 2026] [security2:error] [pid 884009:tid 884218] [client 114.119.157.124:40857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "russianlanguagetutor.com"] [uri "/mistakes-to-avoid-when-choosing-a-russian-language-teacher-online"] [unique_id "al4TEBKaHUf6J8d3elJtmQAAANI"], referer: https://russianlanguagetutor.com/mistakes-to-avoid-when-choosing-a-russian-language-teacher-online
[Mon Jul 20 06:22:40.250994 2026] [security2:error] [pid 915741:tid 915872] [client 45.116.69.230:55117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy1xAAAAZA"]
[Mon Jul 20 06:22:40.251151 2026] [security2:error] [pid 915741:tid 915872] [client 45.116.69.230:55117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy1xAAAAZA"]
[Mon Jul 20 06:22:40.353481 2026] [security2:error] [pid 915741:tid 915908] [client 57.141.18.98:37970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TC6-615n1P-attmy06QABtBY"]
[Mon Jul 20 06:22:40.470416 2026] [security2:error] [pid 915741:tid 915874] [client 50.116.65.227:34496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TEK-615n1P-attmy10gAAAZI"]
[Mon Jul 20 06:22:40.480843 2026] [security2:error] [pid 915741:tid 915903] [client 50.116.65.227:23598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TEK-615n1P-attmy11AAAAeg"]
[Mon Jul 20 06:22:40.785821 2026] [security2:error] [pid 915741:tid 915975] [client 178.152.178.232:37415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy13wAAAfc"]
[Mon Jul 20 06:22:40.785917 2026] [security2:error] [pid 915741:tid 915975] [client 178.152.178.232:37415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy13wAAAfc"]
[Mon Jul 20 06:22:40.815331 2026] [security2:error] [pid 915741:tid 915893] [client 57.141.18.75:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TC6-615n1P-attmy0_QABpVw"]
[Mon Jul 20 06:22:40.945908 2026] [security2:error] [pid 915741:tid 915994] [client 103.141.108.143:55598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy15wAAAgo"]
[Mon Jul 20 06:22:40.946550 2026] [security2:error] [pid 915741:tid 915994] [client 103.141.108.143:55598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TEK-615n1P-attmy15wAAAgo"]
[Mon Jul 20 06:22:41.437179 2026] [security2:error] [pid 884009:tid 884240] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJtxgAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:41.467287 2026] [security2:error] [pid 915741:tid 915943] [client 14.225.17.146:63124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4TEK-615n1P-attmy1sgAAAdc"]
[Mon Jul 20 06:22:41.536026 2026] [security2:error] [pid 915741:tid 915911] [client 114.119.149.232:30087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4TEa-615n1P-attmy2CAAAAbc"], referer: https://newstral.com/en/article/en/1151935704/la-rice-crop-off-to-good-start-prices-up
[Mon Jul 20 06:22:41.696113 2026] [security2:error] [pid 884009:tid 884189] [client 14.225.17.146:63682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJt2wAAALU"], referer: http://nextlevelpressurewashing.com/Wp
[Mon Jul 20 06:22:41.928364 2026] [security2:error] [pid 915741:tid 915945] [client 57.141.18.50:52660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDK-615n1P-attmy1KgAB2U4"]
[Mon Jul 20 06:22:41.976559 2026] [security2:error] [pid 915741:tid 915921] [client 77.110.127.138:61362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TEa-615n1P-attmy2FAAAAcE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.097375 2026] [security2:error] [pid 884009:tid 884224] [client 77.110.127.138:61364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEhKaHUf6J8d3elJt7wAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.097503 2026] [security2:error] [pid 884009:tid 884224] [client 77.110.127.138:61364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEhKaHUf6J8d3elJt7wAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.147507 2026] [security2:error] [pid 884009:tid 884244] [client 14.225.17.146:63689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJt3wAAAOw"], referer: http://waterproofgoods.com/Wp
[Mon Jul 20 06:22:42.246772 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEq-615n1P-attmy2IgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.246882 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TEq-615n1P-attmy2IgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.599729 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.38:51796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDa-615n1P-attmy1QgABnUM"]
[Mon Jul 20 06:22:42.618038 2026] [security2:error] [pid 884009:tid 884200] [client 66.249.66.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4TEhKaHUf6J8d3elJt_wAAAMA"]
[Mon Jul 20 06:22:42.759691 2026] [security2:error] [pid 884009:tid 884206] [client 77.110.127.138:61369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TEhKaHUf6J8d3elJt-wAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:42.885287 2026] [security2:error] [pid 915741:tid 915906] [client 14.225.17.146:63242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4TEq-615n1P-attmy2NwAAAbI"], referer: http://dasmarque.com/Wp
[Mon Jul 20 06:22:43.307949 2026] [security2:error] [pid 915741:tid 915922] [client 50.116.65.227:34518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4TE6-615n1P-attmy2WAAAAcI"]
[Mon Jul 20 06:22:43.319209 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.50:52662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDq-615n1P-attmy1aQACBCo"]
[Mon Jul 20 06:22:43.320266 2026] [security2:error] [pid 915741:tid 915981] [client 50.116.65.227:23644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4TE6-615n1P-attmy2WQAAAZM"]
[Mon Jul 20 06:22:43.499160 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2VwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:43.547393 2026] [security2:error] [pid 915741:tid 915913] [client 57.141.18.92:29042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDq-615n1P-attmy1bQABuUA"]
[Mon Jul 20 06:22:43.591522 2026] [security2:error] [pid 915741:tid 915925] [client 34.74.185.202:51841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4TE6-615n1P-attmy2YgAAAcU"]
[Mon Jul 20 06:22:43.676459 2026] [security2:error] [pid 915741:tid 915900] [client 77.110.127.138:61372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2XAAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:43.863885 2026] [security2:error] [pid 915741:tid 915813] [remote 162.19.86.63:41171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4TE6-615n1P-attmy2aQAB60c"]
[Mon Jul 20 06:22:43.942293 2026] [security2:error] [pid 915741:tid 915926] [client 77.110.127.138:61313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2YwAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:43.965805 2026] [security2:error] [pid 884009:tid 884229] [client 41.173.37.102:11382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TExKaHUf6J8d3elJuLgAAAN0"]
[Mon Jul 20 06:22:43.965901 2026] [security2:error] [pid 884009:tid 884229] [client 41.173.37.102:11382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TExKaHUf6J8d3elJuLgAAAN0"]
[Mon Jul 20 06:22:43.972007 2026] [security2:error] [pid 915741:tid 915923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2ZgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:44.076197 2026] [security2:error] [pid 915741:tid 915869] [remote 162.19.86.63:41171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4TFK-615n1P-attmy2cgABwH8"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 06:22:44.197596 2026] [security2:error] [pid 915741:tid 915996] [client 34.74.185.202:52247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TFK-615n1P-attmy2dAAAAgw"]
[Mon Jul 20 06:22:44.231033 2026] [security2:error] [pid 884009:tid 884217] [client 57.141.18.22:29842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TDxKaHUf6J8d3elJtdgAA0Uo"]
[Mon Jul 20 06:22:44.523466 2026] [security2:error] [pid 884009:tid 884176] [client 14.225.17.146:61204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4TFBKaHUf6J8d3elJuMwAAAKg"], referer: http://hilltopnurseryinc.com/Wp
[Mon Jul 20 06:22:44.628082 2026] [security2:error] [pid 915741:tid 915865] [remote 81.173.115.7:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TFK-615n1P-attmy2kwACCXs"]
[Mon Jul 20 06:22:44.669333 2026] [security2:error] [pid 884009:tid 884263] [client 77.110.127.138:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TFBKaHUf6J8d3elJuRQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:44.669461 2026] [security2:error] [pid 884009:tid 884263] [client 77.110.127.138:61379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TFBKaHUf6J8d3elJuRQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:44.800401 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:58649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2RwAAAds"], referer: http://ccsdifference.com/Wp
[Mon Jul 20 06:22:44.817872 2026] [security2:error] [pid 915741:tid 915744] [remote 81.173.115.7:33066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TFK-615n1P-attmy2nAABvAI"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:22:44.874507 2026] [security2:error] [pid 915741:tid 915924] [client 34.74.185.202:54586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TFK-615n1P-attmy2oAAAAcQ"]
[Mon Jul 20 06:22:45.113516 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:61319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TFK-615n1P-attmy2mAAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:45.316272 2026] [security2:error] [pid 915741:tid 915969] [client 216.73.217.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy2sQAAAfE"]
[Mon Jul 20 06:22:45.353013 2026] [security2:error] [pid 915741:tid 915955] [client 27.96.94.195:37898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TFa-615n1P-attmy2tQAAAeM"]
[Mon Jul 20 06:22:45.353158 2026] [security2:error] [pid 915741:tid 915955] [client 27.96.94.195:37898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TFa-615n1P-attmy2tQAAAeM"]
[Mon Jul 20 06:22:45.443552 2026] [security2:error] [pid 884009:tid 884189] [client 216.73.217.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4TFRKaHUf6J8d3elJuVgAAALU"], referer: https://processorstudio.com/sitemap.xml
[Mon Jul 20 06:22:45.491255 2026] [security2:error] [pid 915741:tid 915957] [client 57.141.18.12:58188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TEK-615n1P-attmy1zwAB5QA"]
[Mon Jul 20 06:22:45.679621 2026] [security2:error] [pid 915741:tid 915932] [client 34.74.185.202:56477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TFa-615n1P-attmy2zgAAAcw"]
[Mon Jul 20 06:22:45.680627 2026] [security2:error] [pid 915741:tid 915884] [client 14.225.17.146:60782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4TFK-615n1P-attmy2bgAAAZw"], referer: http://nwcarvingacademy.com/Wp
[Mon Jul 20 06:22:45.774612 2026] [security2:error] [pid 884009:tid 884178] [client 57.141.18.78:26874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TEBKaHUf6J8d3elJtsQAAqiA"]
[Mon Jul 20 06:22:45.841717 2026] [security2:error] [pid 915741:tid 915929] [client 14.225.17.146:62836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy2yQAAAck"], referer: https://ccsdifference.com/Wp
[Mon Jul 20 06:22:45.992153 2026] [security2:error] [pid 915741:tid 915959] [client 34.74.185.202:51456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TFa-615n1P-attmy22wAAAec"]
[Mon Jul 20 06:22:46.018573 2026] [security2:error] [pid 884009:tid 884158] [client 171.61.165.146:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuaQAAAJc"]
[Mon Jul 20 06:22:46.018697 2026] [security2:error] [pid 884009:tid 884158] [client 171.61.165.146:26608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuaQAAAJc"]
[Mon Jul 20 06:22:46.159590 2026] [ssl:error] [pid 884009:tid 884220] [client 199.45.154.150:53418] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.poopscoopmarketing.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:22:46.160015 2026] [security2:error] [pid 884009:tid 884171] [client 45.157.112.60:65053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TFhKaHUf6J8d3elJubAAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:22:46.162362 2026] [security2:error] [pid 915741:tid 915908] [client 50.116.65.227:34522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TFq-615n1P-attmy25wAAAbQ"]
[Mon Jul 20 06:22:46.172190 2026] [security2:error] [pid 884009:tid 884211] [client 50.116.65.227:23712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TFhKaHUf6J8d3elJubQAAAI4"]
[Mon Jul 20 06:22:46.270801 2026] [security2:error] [pid 915741:tid 915990] [client 14.225.17.146:51445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy25QAAAgY"], referer: http://adirondackengineering.com/Wp
[Mon Jul 20 06:22:46.402929 2026] [security2:error] [pid 884009:tid 884260] [client 57.141.18.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TFhKaHUf6J8d3elJudAAAAPw"]
[Mon Jul 20 06:22:46.582917 2026] [security2:error] [pid 884009:tid 884067] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuggAA9zg"]
[Mon Jul 20 06:22:46.583066 2026] [security2:error] [pid 884009:tid 884255] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TFhKaHUf6J8d3elJuggAA9zg"]
[Mon Jul 20 06:22:46.637846 2026] [security2:error] [pid 915741:tid 915915] [client 103.153.183.69:39968] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..\\xe0\\x80\\xaf../etc/passwd"] [unique_id "al4TFq-615n1P-attmy2_gAAAbs"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:22:46.639417 2026] [security2:error] [pid 915741:tid 915897] [client 14.224.227.113:54413] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4TFq-615n1P-attmy2_wAAAak"]
[Mon Jul 20 06:22:46.699507 2026] [security2:error] [pid 884009:tid 884197] [client 57.141.18.40:22940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TERKaHUf6J8d3elJt3QAAvQ4"]
[Mon Jul 20 06:22:46.739220 2026] [security2:error] [pid 884009:tid 884175] [client 14.225.17.146:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4TFhKaHUf6J8d3elJufgAAAKc"], referer: https://nwcarvingacademy.com/Wp
[Mon Jul 20 06:22:46.822264 2026] [security2:error] [pid 915741:tid 915931] [client 34.74.185.202:59389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TFq-615n1P-attmy3CgAAAcs"]
[Mon Jul 20 06:22:47.073007 2026] [security2:error] [pid 884009:tid 884170] [client 34.74.185.202:63024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TFxKaHUf6J8d3elJunAAAAKI"]
[Mon Jul 20 06:22:47.084706 2026] [core:error] [pid 884009:tid 884140] [client 103.153.183.69:23236] AH10244: invalid URI path (/../../.env?_=iprphgyb&v=8awcg), referer: https://duckduckgo.com/?q=iehr5
[Mon Jul 20 06:22:47.368636 2026] [security2:error] [pid 884009:tid 884151] [client 14.225.17.146:51349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4TFRKaHUf6J8d3elJuZgAAAJA"], referer: http://solkeetw.com/Wp
[Mon Jul 20 06:22:47.405780 2026] [security2:error] [pid 884009:tid 884171] [client 50.116.65.227:23740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TFxKaHUf6J8d3elJuqQAAAKM"]
[Mon Jul 20 06:22:47.416129 2026] [security2:error] [pid 915741:tid 915911] [client 50.116.65.227:23752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TF6-615n1P-attmy3IgAAAbc"]
[Mon Jul 20 06:22:47.721118 2026] [security2:error] [pid 915741:tid 915808] [remote 45.90.123.233:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TF6-615n1P-attmy3LQAByUI"]
[Mon Jul 20 06:22:47.721412 2026] [security2:error] [pid 915741:tid 915929] [client 45.90.123.233:42096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TF6-615n1P-attmy3LQAByUI"]
[Mon Jul 20 06:22:47.730989 2026] [core:error] [pid 915741:tid 915878] [client 103.153.183.69:23240] AH10244: invalid URI path (/../../.env?_=bor5t3vg&v=9bztk), referer: https://www.bing.com/search?q=zkwjx8
[Mon Jul 20 06:22:47.742188 2026] [security2:error] [pid 915741:tid 915934] [client 57.141.18.76:35678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TEq-615n1P-attmy2LwABzmM"]
[Mon Jul 20 06:22:48.011729 2026] [security2:error] [pid 884009:tid 884259] [client 34.74.185.202:63024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TGBKaHUf6J8d3elJuvgAAAPs"]
[Mon Jul 20 06:22:48.028179 2026] [security2:error] [pid 915741:tid 915995] [client 14.225.17.146:51385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy26QAAAgs"], referer: http://according2plant.com/Wp
[Mon Jul 20 06:22:48.184039 2026] [security2:error] [pid 915741:tid 915882] [client 104.234.53.94:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TGK-615n1P-attmy3SQAAAZo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:48.367307 2026] [security2:error] [pid 915741:tid 915992] [client 57.141.18.126:60156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TE6-615n1P-attmy2TQACCHA"]
[Mon Jul 20 06:22:48.408767 2026] [security2:error] [pid 884009:tid 884243] [client 77.110.127.138:61381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TGBKaHUf6J8d3elJuwwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:48.442546 2026] [security2:error] [pid 884009:tid 884037] [remote 20.153.140.50:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4TGBKaHUf6J8d3elJuyQAA_Ro"]
[Mon Jul 20 06:22:48.538586 2026] [security2:error] [pid 884009:tid 884142] [client 57.141.18.115:44602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TExKaHUf6J8d3elJuGwAAh34"]
[Mon Jul 20 06:22:48.570304 2026] [security2:error] [pid 884009:tid 884163] [client 74.125.213.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4TFhKaHUf6J8d3elJugAAAAJw"]
[Mon Jul 20 06:22:48.583342 2026] [security2:error] [pid 915741:tid 915880] [client 14.225.17.146:56276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy3FQAAAZg"], referer: http://mtlegnews.gov/Wp
[Mon Jul 20 06:22:48.599359 2026] [security2:error] [pid 884009:tid 884092] [remote 8.217.108.67:54822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4TGBKaHUf6J8d3elJu0AAAuFE"]
[Mon Jul 20 06:22:48.874927 2026] [security2:error] [pid 884009:tid 884224] [client 57.141.18.111:61286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TExKaHUf6J8d3elJuKwAA2EA"]
[Mon Jul 20 06:22:48.904094 2026] [security2:error] [pid 884009:tid 884117] [remote 20.153.140.50:33432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4TGBKaHUf6J8d3elJu4AAApWo"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 06:22:48.991290 2026] [security2:error] [pid 915741:tid 915919] [client 34.73.38.214:61427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TGK-615n1P-attmy3YgAAAb8"]
[Mon Jul 20 06:22:49.232031 2026] [security2:error] [pid 915741:tid 915925] [client 14.225.17.146:51525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy3EgAAAcU"], referer: http://latiendadejorge.com.gt/Wp
[Mon Jul 20 06:22:49.244977 2026] [security2:error] [pid 884009:tid 884165] [client 34.74.185.202:65439] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TGRKaHUf6J8d3elJu9QAAAJ4"]
[Mon Jul 20 06:22:49.265062 2026] [security2:error] [pid 915741:tid 915791] [remote 192.241.143.148:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TGa-615n1P-attmy3bwABxzE"]
[Mon Jul 20 06:22:49.367276 2026] [security2:error] [pid 884009:tid 884238] [client 68.235.52.68:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TGRKaHUf6J8d3elJu-wAAAOY"]
[Mon Jul 20 06:22:49.367383 2026] [security2:error] [pid 884009:tid 884238] [client 68.235.52.68:46192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TGRKaHUf6J8d3elJu-wAAAOY"]
[Mon Jul 20 06:22:49.458132 2026] [security2:error] [pid 915741:tid 915754] [remote 192.241.143.148:54274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TGa-615n1P-attmy3fAABsQw"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:22:49.580595 2026] [security2:error] [pid 884009:tid 884240] [client 57.141.18.22:29864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFBKaHUf6J8d3elJuQwAA6CQ"]
[Mon Jul 20 06:22:49.678058 2026] [security2:error] [pid 915741:tid 915957] [client 14.225.17.146:50676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4TGK-615n1P-attmy3UQAAAeU"], referer: http://whiteoutcb.com/Wp
[Mon Jul 20 06:22:49.842530 2026] [security2:error] [pid 915741:tid 915968] [client 57.141.18.23:54742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFK-615n1P-attmy2oQAB8H4"]
[Mon Jul 20 06:22:49.911947 2026] [security2:error] [pid 884009:tid 884191] [client 103.153.183.69:9700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/.env"] [unique_id "al4TGRKaHUf6J8d3elJvCQAAALc"], referer: https://www.facebook.com/
[Mon Jul 20 06:22:50.131175 2026] [security2:error] [pid 915741:tid 915955] [client 34.74.185.202:63622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TGq-615n1P-attmy3ngAAAeM"]
[Mon Jul 20 06:22:50.207086 2026] [security2:error] [pid 915741:tid 915905] [client 34.73.38.214:54500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TGq-615n1P-attmy3owAAAbE"]
[Mon Jul 20 06:22:50.240660 2026] [security2:error] [pid 884009:tid 884174] [client 171.60.139.123:63524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TGhKaHUf6J8d3elJvEAAAAKY"]
[Mon Jul 20 06:22:50.240843 2026] [security2:error] [pid 884009:tid 884174] [client 171.60.139.123:63524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TGhKaHUf6J8d3elJvEAAAAKY"]
[Mon Jul 20 06:22:50.363325 2026] [security2:error] [pid 915741:tid 915874] [client 57.141.18.56:47760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy2vgABkgg"]
[Mon Jul 20 06:22:50.597074 2026] [security2:error] [pid 915741:tid 915879] [client 14.225.17.146:50651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4TGq-615n1P-attmy3qQAAAZc"], referer: http://grecruit.online/Wp
[Mon Jul 20 06:22:50.716276 2026] [security2:error] [pid 915741:tid 915951] [client 3.75.183.99:33818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TGq-615n1P-attmy3vgAAAd8"]
[Mon Jul 20 06:22:50.814381 2026] [security2:error] [pid 915741:tid 915971] [client 57.141.18.98:27778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy21QAB824"]
[Mon Jul 20 06:22:50.968205 2026] [security2:error] [pid 915741:tid 915954] [client 57.141.18.100:50818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFa-615n1P-attmy23QAB4l0"]
[Mon Jul 20 06:22:51.058532 2026] [security2:error] [pid 884009:tid 884221] [client 45.116.69.230:55660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TGxKaHUf6J8d3elJvLgAAANU"]
[Mon Jul 20 06:22:51.058661 2026] [security2:error] [pid 884009:tid 884221] [client 45.116.69.230:55660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TGxKaHUf6J8d3elJvLgAAANU"]
[Mon Jul 20 06:22:51.066902 2026] [security2:error] [pid 915741:tid 915923] [client 34.74.185.202:53176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TG6-615n1P-attmy3zQAAAcM"]
[Mon Jul 20 06:22:51.135059 2026] [security2:error] [pid 915741:tid 915897] [client 50.116.65.227:36842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4TG6-615n1P-attmy3zgAAAak"]
[Mon Jul 20 06:22:51.146524 2026] [security2:error] [pid 915741:tid 915950] [client 50.116.65.227:26234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4TG6-615n1P-attmy3zwAAAd4"]
[Mon Jul 20 06:22:51.278422 2026] [security2:error] [pid 915741:tid 915874] [client 34.73.38.214:54552] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TG6-615n1P-attmy30QAAAZI"]
[Mon Jul 20 06:22:51.332907 2026] [security2:error] [pid 915741:tid 915891] [client 57.141.18.25:52494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFq-615n1P-attmy27wABow8"]
[Mon Jul 20 06:22:51.521648 2026] [security2:error] [pid 915741:tid 915995] [client 104.234.53.54:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TG6-615n1P-attmy33wAAAgs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:51.605058 2026] [security2:error] [pid 915741:tid 915913] [client 103.141.108.143:56061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TG6-615n1P-attmy35wAAAbk"]
[Mon Jul 20 06:22:51.605236 2026] [security2:error] [pid 915741:tid 915913] [client 103.141.108.143:56061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TG6-615n1P-attmy35wAAAbk"]
[Mon Jul 20 06:22:51.614057 2026] [security2:error] [pid 915741:tid 915904] [client 108.59.114.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy33AAAAbA"]
[Mon Jul 20 06:22:51.734974 2026] [security2:error] [pid 915741:tid 915875] [client 54.169.146.187:64916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TG6-615n1P-attmy37AAAAZM"]
[Mon Jul 20 06:22:51.821648 2026] [security2:error] [pid 884009:tid 884205] [client 63.179.149.246:19882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TGxKaHUf6J8d3elJvSgAAAMU"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:52.110903 2026] [security2:error] [pid 884009:tid 884201] [client 34.73.38.214:52911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4THBKaHUf6J8d3elJvWgAAAME"]
[Mon Jul 20 06:22:52.274530 2026] [security2:error] [pid 884009:tid 884067] [remote 8.217.108.67:54822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4THBKaHUf6J8d3elJvaAABAjg"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:22:52.397161 2026] [security2:error] [pid 884009:tid 884077] [remote 72.167.132.114:38530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4THBKaHUf6J8d3elJvbQAAhUI"]
[Mon Jul 20 06:22:52.439354 2026] [security2:error] [pid 915741:tid 915929] [client 34.73.38.214:58255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4THK-615n1P-attmy3_gAAAck"]
[Mon Jul 20 06:22:52.446992 2026] [security2:error] [pid 915741:tid 915931] [client 34.74.185.202:53195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4THK-615n1P-attmy3_wAAAcs"]
[Mon Jul 20 06:22:52.532430 2026] [security2:error] [pid 915741:tid 915993] [client 66.249.68.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mzsassy.com"] [uri "/index.php"] [unique_id "al4TGq-615n1P-attmy3rwACCRI"]
[Mon Jul 20 06:22:52.562186 2026] [security2:error] [pid 884009:tid 884176] [client 57.141.18.120:43242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TFxKaHUf6J8d3elJutgAAqAI"]
[Mon Jul 20 06:22:52.567971 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:42375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4THK-615n1P-attmy4CgAAAeI"]
[Mon Jul 20 06:22:52.568122 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:42375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4THK-615n1P-attmy4CgAAAeI"]
[Mon Jul 20 06:22:52.600869 2026] [security2:error] [pid 915741:tid 915943] [client 47.129.222.11:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4THK-615n1P-attmy4DQAAAdc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:22:52.635710 2026] [security2:error] [pid 915741:tid 915983] [client 78.46.190.63:62588] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4THK-615n1P-attmy4CQAAAf8"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:22:52.731033 2026] [security2:error] [pid 884009:tid 884234] [client 77.110.127.138:61388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THBKaHUf6J8d3elJvWQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:52.766249 2026] [security2:error] [pid 884009:tid 884087] [remote 72.167.132.114:38530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4THBKaHUf6J8d3elJvhQAA4Uw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:22:52.775299 2026] [security2:error] [pid 884009:tid 884224] [client 77.110.127.138:61394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THBKaHUf6J8d3elJvYgAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:52.897181 2026] [security2:error] [pid 884009:tid 884259] [client 77.110.127.138:61397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THBKaHUf6J8d3elJvhwAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:52.897276 2026] [security2:error] [pid 884009:tid 884259] [client 77.110.127.138:61397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THBKaHUf6J8d3elJvhwAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:53.235526 2026] [security2:error] [pid 884009:tid 884257] [client 34.73.38.214:49437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4THRKaHUf6J8d3elJvlgAAAPk"]
[Mon Jul 20 06:22:53.317098 2026] [security2:error] [pid 884009:tid 884240] [client 77.110.127.138:61399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THRKaHUf6J8d3elJvkgAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:53.379967 2026] [security2:error] [pid 884009:tid 884252] [client 34.74.185.202:59817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.crmpfilms.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4THRKaHUf6J8d3elJvnQAAAPQ"]
[Mon Jul 20 06:22:53.699765 2026] [security2:error] [pid 915741:tid 915964] [client 34.73.38.214:57543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4THa-615n1P-attmy4LwAAAew"]
[Mon Jul 20 06:22:53.888251 2026] [security2:error] [pid 884009:tid 884244] [client 104.234.53.63:37805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4THRKaHUf6J8d3elJvtAAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:54.015004 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THa-615n1P-attmy4MQAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.093788 2026] [security2:error] [pid 915741:tid 915924] [client 34.73.38.214:56987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4PgAAAcQ"]
[Mon Jul 20 06:22:54.106995 2026] [security2:error] [pid 884009:tid 884149] [client 77.110.127.138:61403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THRKaHUf6J8d3elJvugAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.182220 2026] [security2:error] [pid 915741:tid 915818] [remote 152.228.213.32:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4THq-615n1P-attmy4PwACB0w"]
[Mon Jul 20 06:22:54.240083 2026] [security2:error] [pid 915741:tid 915912] [client 34.73.38.214:51811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4RgAAAbg"]
[Mon Jul 20 06:22:54.285999 2026] [security2:error] [pid 915741:tid 915876] [client 77.110.127.138:61405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THq-615n1P-attmy4PQAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.316190 2026] [security2:error] [pid 915741:tid 915965] [client 178.152.178.232:36934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4TAAAAe0"]
[Mon Jul 20 06:22:54.323101 2026] [security2:error] [pid 915741:tid 915965] [client 178.152.178.232:36934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4TAAAAe0"]
[Mon Jul 20 06:22:54.387958 2026] [security2:error] [pid 884009:tid 884255] [client 34.73.38.214:53194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4THhKaHUf6J8d3elJvygAAAPc"]
[Mon Jul 20 06:22:54.413489 2026] [security2:error] [pid 915741:tid 915998] [client 57.141.18.26:27770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TGa-615n1P-attmy3hQACDjY"]
[Mon Jul 20 06:22:54.520022 2026] [security2:error] [pid 884009:tid 884239] [client 34.73.38.214:58807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vbb.yvf.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4THhKaHUf6J8d3elJv0AAAAOc"]
[Mon Jul 20 06:22:54.573651 2026] [security2:error] [pid 915741:tid 915884] [client 41.173.37.102:11810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4WAAAAZw"]
[Mon Jul 20 06:22:54.573737 2026] [security2:error] [pid 915741:tid 915884] [client 41.173.37.102:11810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4THq-615n1P-attmy4WAAAAZw"]
[Mon Jul 20 06:22:54.585176 2026] [security2:error] [pid 915741:tid 915910] [client 77.110.127.138:61407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THq-615n1P-attmy4TgAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:54.612403 2026] [security2:error] [pid 915741:tid 915780] [remote 152.228.213.32:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4THq-615n1P-attmy4WwAB-CY"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:22:54.672143 2026] [security2:error] [pid 915741:tid 915890] [client 34.73.38.214:63490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4YAAAAaI"]
[Mon Jul 20 06:22:54.790000 2026] [security2:error] [pid 915741:tid 915929] [client 34.73.38.214:57724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4ZgAAAck"]
[Mon Jul 20 06:22:54.887926 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.12:53236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TGq-615n1P-attmy3oAABqBQ"]
[Mon Jul 20 06:22:54.905450 2026] [security2:error] [pid 915741:tid 915948] [client 34.73.38.214:63490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4THq-615n1P-attmy4agAAAdw"]
[Mon Jul 20 06:22:54.995349 2026] [security2:error] [pid 915741:tid 915843] [remote 72.167.132.114:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4THq-615n1P-attmy4bQABo2U"]
[Mon Jul 20 06:22:55.050926 2026] [security2:error] [pid 884009:tid 884225] [client 77.110.127.138:61413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THhKaHUf6J8d3elJv2gAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.082841 2026] [security2:error] [pid 884009:tid 884252] [client 34.73.38.214:57842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4THxKaHUf6J8d3elJv4gAAAPQ"]
[Mon Jul 20 06:22:55.155769 2026] [security2:error] [pid 884009:tid 884236] [client 104.234.53.63:37805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4THxKaHUf6J8d3elJv5wAAAOQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:22:55.222917 2026] [security2:error] [pid 915741:tid 915867] [remote 72.167.132.114:38542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TH6-615n1P-attmy4egABuH0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:22:55.230971 2026] [security2:error] [pid 915741:tid 915978] [client 34.73.38.214:57063] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TH6-615n1P-attmy4ewAAAfo"]
[Mon Jul 20 06:22:55.319323 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TH6-615n1P-attmy4fwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.319410 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TH6-615n1P-attmy4fwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.383461 2026] [security2:error] [pid 915741:tid 915923] [client 34.73.38.214:56175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TH6-615n1P-attmy4hAAAAcM"]
[Mon Jul 20 06:22:55.531427 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THxKaHUf6J8d3elJv-wAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.531545 2026] [security2:error] [pid 884009:tid 884164] [client 77.110.127.138:61418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4THxKaHUf6J8d3elJv-wAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.548266 2026] [security2:error] [pid 915741:tid 915950] [client 34.73.38.214:49196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TH6-615n1P-attmy4jwAAAd4"]
[Mon Jul 20 06:22:55.601030 2026] [security2:error] [pid 884009:tid 884254] [client 77.110.127.138:61416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THxKaHUf6J8d3elJv9AAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.700946 2026] [security2:error] [pid 884009:tid 884159] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4THxKaHUf6J8d3elJv-gAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:55.751036 2026] [security2:error] [pid 915741:tid 915987] [client 57.141.18.32:51598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy3ywACAyU"]
[Mon Jul 20 06:22:55.766884 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:61117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4THxKaHUf6J8d3elJwBAAAAQQ"]
[Mon Jul 20 06:22:55.984511 2026] [security2:error] [pid 884009:tid 884186] [client 34.73.38.214:62882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4THxKaHUf6J8d3elJwDwAAALI"]
[Mon Jul 20 06:22:56.047885 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4lAAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:56.142212 2026] [security2:error] [pid 915741:tid 915916] [client 34.73.38.214:52946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TIK-615n1P-attmy4qgAAAbw"]
[Mon Jul 20 06:22:56.165170 2026] [security2:error] [pid 915741:tid 915932] [client 57.141.18.8:60262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy30wABzCk"]
[Mon Jul 20 06:22:56.348198 2026] [security2:error] [pid 915741:tid 915971] [client 34.73.38.214:59273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vergotek.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TIK-615n1P-attmy4sQAAAfM"]
[Mon Jul 20 06:22:56.372548 2026] [security2:error] [pid 915741:tid 915889] [client 57.141.18.87:28300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TG6-615n1P-attmy33gABoRk"]
[Mon Jul 20 06:22:56.536215 2026] [security2:error] [pid 915741:tid 915984] [client 77.110.127.138:61423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4rQAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:56.739255 2026] [security2:error] [pid 915741:tid 915831] [remote 91.142.222.105:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4TIK-615n1P-attmy4wgABlVk"]
[Mon Jul 20 06:22:56.816680 2026] [security2:error] [pid 915741:tid 915886] [client 14.225.17.146:64474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4wwAAAZ4"], referer: http://katsklar.com/Wp
[Mon Jul 20 06:22:56.855144 2026] [security2:error] [pid 915741:tid 915817] [remote 188.166.241.141:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4TIK-615n1P-attmy4xQABlEs"]
[Mon Jul 20 06:22:57.035479 2026] [security2:error] [pid 915741:tid 915819] [remote 91.142.222.105:35574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4TIa-615n1P-attmy4zQAB100"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:22:57.198172 2026] [security2:error] [pid 884009:tid 884021] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwRQAArgo"]
[Mon Jul 20 06:22:57.198388 2026] [security2:error] [pid 884009:tid 884182] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwRQAArgo"]
[Mon Jul 20 06:22:57.253880 2026] [security2:error] [pid 884009:tid 884200] [client 57.141.18.37:60506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4THBKaHUf6J8d3elJvgwAAwEU"]
[Mon Jul 20 06:22:57.294727 2026] [security2:error] [pid 915741:tid 915822] [remote 188.166.241.141:36384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4TIa-615n1P-attmy41gAB7lA"], referer: https://rtkenergypartners.com/wp-login.php
[Mon Jul 20 06:22:57.358356 2026] [security2:error] [pid 915741:tid 915902] [client 77.110.127.138:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy41wAAAa4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.358553 2026] [security2:error] [pid 915741:tid 915902] [client 77.110.127.138:61398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy41wAAAa4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.523211 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy44wAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.523365 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TIa-615n1P-attmy44wAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.549057 2026] [security2:error] [pid 915741:tid 915891] [client 50.116.65.227:26246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TIa-615n1P-attmy45QAAAaM"]
[Mon Jul 20 06:22:57.559734 2026] [security2:error] [pid 915741:tid 915945] [client 50.116.65.227:26258] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TIa-615n1P-attmy45gAAAdk"]
[Mon Jul 20 06:22:57.585196 2026] [security2:error] [pid 915741:tid 915940] [client 77.110.127.138:61432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4TIa-615n1P-attmy46QAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:57.660736 2026] [security2:error] [pid 884009:tid 884029] [remote 151.240.255.102:43331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwRAAA1BI"], referer: https://www.thewelloiledlife.com/free-shipping-on-young-livings-premium-starter-kit/
[Mon Jul 20 06:22:57.894642 2026] [security2:error] [pid 915741:tid 915884] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4uwAAAZw"]
[Mon Jul 20 06:22:57.946984 2026] [security2:error] [pid 884009:tid 884160] [client 57.141.18.85:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4THRKaHUf6J8d3elJvogAAmR4"]
[Mon Jul 20 06:22:57.977669 2026] [security2:error] [pid 884009:tid 884246] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwXAAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:58.000169 2026] [security2:error] [pid 884009:tid 884236] [client 171.61.165.146:14016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwYwAAAOQ"]
[Mon Jul 20 06:22:58.000302 2026] [security2:error] [pid 884009:tid 884236] [client 171.61.165.146:14016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TIRKaHUf6J8d3elJwYwAAAOQ"]
[Mon Jul 20 06:22:58.234843 2026] [security2:error] [pid 915741:tid 915993] [client 14.225.17.146:64416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4TIK-615n1P-attmy4rAAAAgk"], referer: http://www.justinagrayman.com/Wp
[Mon Jul 20 06:22:58.430516 2026] [security2:error] [pid 915741:tid 915933] [client 50.116.65.227:36850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TIq-615n1P-attmy5DQAAAc0"]
[Mon Jul 20 06:22:58.440670 2026] [security2:error] [pid 915741:tid 915997] [client 50.116.65.227:26286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TIq-615n1P-attmy5DwAAAcQ"]
[Mon Jul 20 06:22:58.818804 2026] [security2:error] [pid 884009:tid 884180] [client 14.225.17.146:64415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwXgAAAKw"]
[Mon Jul 20 06:22:58.945035 2026] [security2:error] [pid 884009:tid 884015] [remote 81.173.115.7:45474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TIhKaHUf6J8d3elJwgwAAyQQ"]
[Mon Jul 20 06:22:58.945290 2026] [security2:error] [pid 884009:tid 884209] [client 81.173.115.7:45474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TIhKaHUf6J8d3elJwgwAAyQQ"]
[Mon Jul 20 06:22:59.025003 2026] [security2:error] [pid 915741:tid 915961] [client 57.141.18.16:62890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4THq-615n1P-attmy4YwAB6Uc"]
[Mon Jul 20 06:22:59.201428 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TI6-615n1P-attmy5OAAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.201531 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TI6-615n1P-attmy5OAAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.361562 2026] [security2:error] [pid 884009:tid 884239] [client 77.110.127.138:61437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TIxKaHUf6J8d3elJwiwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.375959 2026] [security2:error] [pid 915741:tid 915947] [client 47.128.30.14:63668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hollinbankfarm.com"] [uri "/robots.txt"] [unique_id "al4TI6-615n1P-attmy5QwAAAds"]
[Mon Jul 20 06:22:59.397414 2026] [security2:error] [pid 915741:tid 915946] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TI6-615n1P-attmy5NgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.469029 2026] [security2:error] [pid 884009:tid 884163] [client 77.110.127.138:61416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4TIxKaHUf6J8d3elJwlgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:22:59.512437 2026] [security2:error] [pid 915741:tid 915994] [client 57.141.18.97:35576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4cgACCn8"]
[Mon Jul 20 06:22:59.718769 2026] [security2:error] [pid 884009:tid 884176] [client 27.96.94.195:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TIxKaHUf6J8d3elJwnQAAAKg"]
[Mon Jul 20 06:22:59.718966 2026] [security2:error] [pid 884009:tid 884176] [client 27.96.94.195:37826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TIxKaHUf6J8d3elJwnQAAAKg"]
[Mon Jul 20 06:23:00.177195 2026] [security2:error] [pid 915741:tid 915964] [client 57.141.18.61:53396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4mQAB7AI"]
[Mon Jul 20 06:23:00.196134 2026] [security2:error] [pid 915741:tid 915874] [client 57.141.18.73:53992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TH6-615n1P-attmy4nAABkkU"]
[Mon Jul 20 06:23:00.277725 2026] [security2:error] [pid 884009:tid 884244] [client 104.234.53.84:45115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TJBKaHUf6J8d3elJwrwAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:00.797353 2026] [security2:error] [pid 915741:tid 915905] [client 171.60.139.123:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TJK-615n1P-attmy5hQAAAbE"]
[Mon Jul 20 06:23:00.797493 2026] [security2:error] [pid 915741:tid 915905] [client 171.60.139.123:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TJK-615n1P-attmy5hQAAAbE"]
[Mon Jul 20 06:23:00.891886 2026] [security2:error] [pid 915741:tid 915970] [client 14.225.17.146:62494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4TI6-615n1P-attmy5NwAAAfI"], referer: http://vinovinhowine.com/Wp
[Mon Jul 20 06:23:01.179862 2026] [security2:error] [pid 884009:tid 884264] [client 57.141.18.5:61178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIBKaHUf6J8d3elJwNAABAAc"]
[Mon Jul 20 06:23:01.610712 2026] [security2:error] [pid 884009:tid 884161] [client 57.141.18.117:20252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIRKaHUf6J8d3elJwSwAAmjQ"]
[Mon Jul 20 06:23:01.648465 2026] [security2:error] [pid 915741:tid 915899] [client 57.141.18.42:36564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIa-615n1P-attmy42QABqyw"]
[Mon Jul 20 06:23:01.793254 2026] [security2:error] [pid 884009:tid 884249] [client 104.234.53.69:42243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TJRKaHUf6J8d3elJw3wAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:01.907412 2026] [security2:error] [pid 915741:tid 915923] [client 178.152.178.232:36325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TJa-615n1P-attmy5twAAAcM"]
[Mon Jul 20 06:23:01.907538 2026] [security2:error] [pid 915741:tid 915923] [client 178.152.178.232:36325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TJa-615n1P-attmy5twAAAcM"]
[Mon Jul 20 06:23:02.110954 2026] [security2:error] [pid 884009:tid 884150] [client 104.234.53.69:42243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TJhKaHUf6J8d3elJw8wAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:02.262607 2026] [security2:error] [pid 884009:tid 884043] [remote 57.141.18.100:57492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3520689"] [unique_id "al4TJhKaHUf6J8d3elJw9QAAzSA"]
[Mon Jul 20 06:23:02.352054 2026] [security2:error] [pid 915741:tid 915952] [client 103.141.108.143:56535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TJq-615n1P-attmy5zQAAAeA"]
[Mon Jul 20 06:23:02.352555 2026] [security2:error] [pid 915741:tid 915952] [client 103.141.108.143:56535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TJq-615n1P-attmy5zQAAAeA"]
[Mon Jul 20 06:23:02.413884 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.39:47153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIq-615n1P-attmy4_wAB3Go"]
[Mon Jul 20 06:23:02.430531 2026] [security2:error] [pid 915741:tid 915895] [client 57.141.18.9:51728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIq-615n1P-attmy4_AABpyE"]
[Mon Jul 20 06:23:03.174937 2026] [security2:error] [pid 915741:tid 915829] [remote 152.228.213.32:38794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TJ6-615n1P-attmy5_gAB_lc"]
[Mon Jul 20 06:23:03.175135 2026] [security2:error] [pid 915741:tid 915982] [client 152.228.213.32:38794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TJ6-615n1P-attmy5_gAB_lc"]
[Mon Jul 20 06:23:03.258777 2026] [security2:error] [pid 884009:tid 884255] [client 57.141.18.26:22582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TIhKaHUf6J8d3elJwhwAA9yE"]
[Mon Jul 20 06:23:04.093664 2026] [security2:error] [pid 915741:tid 915965] [client 45.116.69.230:56191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6XAAAAe0"]
[Mon Jul 20 06:23:04.093782 2026] [security2:error] [pid 915741:tid 915965] [client 45.116.69.230:56191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6XAAAAe0"]
[Mon Jul 20 06:23:04.346030 2026] [security2:error] [pid 915741:tid 915942] [client 158.173.166.181:50473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TKK-615n1P-attmy6ZAAAAdY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:04.502975 2026] [security2:error] [pid 884009:tid 884115] [remote 217.113.60.80:38192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4TKBKaHUf6J8d3elJxMwAAv2g"]
[Mon Jul 20 06:23:04.595669 2026] [security2:error] [pid 915741:tid 915954] [client 57.141.18.124:42464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TJK-615n1P-attmy5dgAB4nc"]
[Mon Jul 20 06:23:04.632584 2026] [proxy:error] [pid 884009:tid 884150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:04.632638 2026] [proxy_http:error] [pid 884009:tid 884150] [client 20.74.45.95:60574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:04.633772 2026] [proxy:error] [pid 884009:tid 884150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:04.633821 2026] [proxy_http:error] [pid 884009:tid 884150] [client 20.74.45.95:60574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:04.861403 2026] [security2:error] [pid 915741:tid 915854] [remote 130.185.118.215:41948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6hgACDnA"]
[Mon Jul 20 06:23:04.861633 2026] [security2:error] [pid 915741:tid 915998] [client 130.185.118.215:41948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4TKK-615n1P-attmy6hgACDnA"]
[Mon Jul 20 06:23:04.938095 2026] [security2:error] [pid 884009:tid 884017] [remote 217.113.60.80:38192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4TKBKaHUf6J8d3elJxRgAA8AY"], referer: https://mail.factsandminds.com/wp-login.php
[Mon Jul 20 06:23:05.242443 2026] [security2:error] [pid 915741:tid 915924] [client 41.173.37.102:12241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TKa-615n1P-attmy6mQAAAcQ"]
[Mon Jul 20 06:23:05.242722 2026] [security2:error] [pid 915741:tid 915924] [client 41.173.37.102:12241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TKa-615n1P-attmy6mQAAAcQ"]
[Mon Jul 20 06:23:05.982592 2026] [security2:error] [pid 915741:tid 915897] [client 104.234.53.69:55959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TKa-615n1P-attmy6vwAAAak"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:06.111218 2026] [security2:error] [pid 884009:tid 884142] [client 50.116.65.227:52540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TKhKaHUf6J8d3elJxawAAAIc"]
[Mon Jul 20 06:23:06.121699 2026] [security2:error] [pid 884009:tid 884201] [client 50.116.65.227:59112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TKhKaHUf6J8d3elJxbQAAAME"]
[Mon Jul 20 06:23:06.265536 2026] [autoindex:error] [pid 884009:tid 884241] [client 147.93.171.187:59822] AH01276: Cannot serve directory /home4/vnluelmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:23:06.278469 2026] [security2:error] [pid 915741:tid 915905] [client 77.110.127.138:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TKq-615n1P-attmy6ygAAAbE"]
[Mon Jul 20 06:23:06.278556 2026] [security2:error] [pid 915741:tid 915905] [client 77.110.127.138:61444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TKq-615n1P-attmy6ygAAAbE"]
[Mon Jul 20 06:23:06.300774 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TKq-615n1P-attmy6zQAAAaA"]
[Mon Jul 20 06:23:06.300929 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TKq-615n1P-attmy6zQAAAaA"]
[Mon Jul 20 06:23:06.320104 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4TKq-615n1P-attmy6zwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:06.407053 2026] [security2:error] [pid 915741:tid 915954] [client 103.153.183.69:8858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/%2e%2e%2f%2e%2e%2fetc%2fpasswd"] [unique_id "al4TKq-615n1P-attmy62gAAAeI"], referer: https://twitter.com/
[Mon Jul 20 06:23:06.435052 2026] [security2:error] [pid 915741:tid 915916] [client 103.153.183.69:8858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/etc/passwd"] [unique_id "al4TKq-615n1P-attmy63AAAAbw"], referer: https://t.co/3aa6qah2aa
[Mon Jul 20 06:23:06.676893 2026] [security2:error] [pid 915741:tid 915955] [client 50.116.65.227:59116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TKq-615n1P-attmy65wAAAeM"]
[Mon Jul 20 06:23:06.679302 2026] [security2:error] [pid 915741:tid 915876] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy6zgAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:06.687739 2026] [security2:error] [pid 915741:tid 915956] [client 50.116.65.227:59124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TKq-615n1P-attmy66AAAAeQ"]
[Mon Jul 20 06:23:06.871599 2026] [security2:error] [pid 915741:tid 915977] [client 14.225.17.146:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4TKa-615n1P-attmy6sgAAAfk"], referer: http://ravmike.com/Wp
[Mon Jul 20 06:23:06.889613 2026] [autoindex:error] [pid 884009:tid 884248] [client 143.244.47.86:9829] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:06.977074 2026] [security2:error] [pid 884009:tid 884138] [remote 217.61.143.92:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4TKhKaHUf6J8d3elJxkwAApX8"]
[Mon Jul 20 06:23:07.021601 2026] [security2:error] [pid 884009:tid 884171] [client 14.225.17.146:65489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4TKhKaHUf6J8d3elJxkAAAAKM"]
[Mon Jul 20 06:23:07.166568 2026] [security2:error] [pid 915741:tid 915908] [client 77.110.127.138:61460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy63gAAAbQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:07.209724 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TK6-615n1P-attmy6_gAAAZc"]
[Mon Jul 20 06:23:07.209885 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:61461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TK6-615n1P-attmy6_gAAAZc"]
[Mon Jul 20 06:23:07.287413 2026] [security2:error] [pid 884009:tid 884222] [client 158.173.89.95:59365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TKxKaHUf6J8d3elJxowAAANY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:07.315817 2026] [security2:error] [pid 915741:tid 915906] [client 74.208.214.194:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TK6-615n1P-attmy7BAAAAbI"]
[Mon Jul 20 06:23:07.448720 2026] [security2:error] [pid 915741:tid 915903] [client 14.225.17.146:62650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy6xwAAAa8"], referer: http://cloudspacesgroup.com/Wp
[Mon Jul 20 06:23:07.450870 2026] [security2:error] [pid 915741:tid 915888] [client 20.245.75.247:14976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TK6-615n1P-attmy7BgAAAaA"]
[Mon Jul 20 06:23:07.466665 2026] [security2:error] [pid 884009:tid 884226] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TKxKaHUf6J8d3elJxnwAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:07.470557 2026] [security2:error] [pid 915741:tid 915939] [client 20.245.75.247:14976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TK6-615n1P-attmy7CgAAAdM"]
[Mon Jul 20 06:23:07.528111 2026] [security2:error] [pid 884009:tid 884230] [client 57.141.18.109:43166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TJxKaHUf6J8d3elJxFwAA3hI"]
[Mon Jul 20 06:23:07.792543 2026] [security2:error] [pid 915741:tid 915801] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HAABoTs"]
[Mon Jul 20 06:23:07.792742 2026] [security2:error] [pid 915741:tid 915889] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HAABoTs"]
[Mon Jul 20 06:23:07.795891 2026] [security2:error] [pid 884009:tid 884177] [client 14.225.17.146:49403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4TKxKaHUf6J8d3elJxtwAAAKk"], referer: https://ravmike.com/Wp
[Mon Jul 20 06:23:07.801563 2026] [security2:error] [pid 915741:tid 915971] [client 57.141.18.100:45280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TJ6-615n1P-attmy6RwAB81I"]
[Mon Jul 20 06:23:07.855268 2026] [security2:error] [pid 915741:tid 915907] [client 171.61.165.146:19032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HgAAAbM"]
[Mon Jul 20 06:23:07.856295 2026] [security2:error] [pid 915741:tid 915907] [client 171.61.165.146:19032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TK6-615n1P-attmy7HgAAAbM"]
[Mon Jul 20 06:23:07.951198 2026] [security2:error] [pid 915741:tid 915952] [client 103.153.183.69:8858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.koaconsultants.com"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/.env"] [unique_id "al4TK6-615n1P-attmy7IQAAAeA"], referer: https://www.bing.com/search?q=9iz5lx
[Mon Jul 20 06:23:08.004092 2026] [security2:error] [pid 884009:tid 884228] [client 27.96.94.195:37468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TLBKaHUf6J8d3elJxxgAAANw"]
[Mon Jul 20 06:23:08.004199 2026] [security2:error] [pid 884009:tid 884228] [client 27.96.94.195:37468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TLBKaHUf6J8d3elJxxgAAANw"]
[Mon Jul 20 06:23:08.017999 2026] [security2:error] [pid 884009:tid 884231] [client 104.234.53.52:27635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TLBKaHUf6J8d3elJxxwAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:08.067688 2026] [security2:error] [pid 915741:tid 915848] [remote 188.166.241.141:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7LwAB6mo"]
[Mon Jul 20 06:23:08.127147 2026] [security2:error] [pid 884009:tid 884074] [remote 217.61.143.92:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4TLBKaHUf6J8d3elJxyQAAqz8"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:23:08.298756 2026] [security2:error] [pid 884009:tid 884236] [client 57.141.18.5:56362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKBKaHUf6J8d3elJxKwAA5Fw"]
[Mon Jul 20 06:23:08.301596 2026] [security2:error] [pid 884009:tid 884243] [client 52.109.4.7:22082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TLBKaHUf6J8d3elJx1gAAAOs"]
[Mon Jul 20 06:23:08.371106 2026] [security2:error] [pid 884009:tid 884151] [client 52.109.4.7:22082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TLBKaHUf6J8d3elJx2gAAAJA"]
[Mon Jul 20 06:23:08.436708 2026] [security2:error] [pid 915741:tid 915775] [remote 188.166.241.141:53040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7OAABwCE"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 06:23:08.463337 2026] [security2:error] [pid 915741:tid 915845] [remote 82.223.97.42:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7OQABy2c"]
[Mon Jul 20 06:23:08.672947 2026] [security2:error] [pid 915741:tid 915773] [remote 82.223.97.42:49092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TLK-615n1P-attmy7QgAB9B8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:08.865394 2026] [security2:error] [pid 915741:tid 915953] [client 14.225.17.146:59489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy66QAAAeE"], referer: http://younutrition.gr/Wp
[Mon Jul 20 06:23:08.874990 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:08.875030 2026] [proxy_http:error] [pid 884009:tid 884208] [client 143.244.47.86:33076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:08.875650 2026] [proxy:error] [pid 884009:tid 884208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:08.875675 2026] [proxy_http:error] [pid 884009:tid 884208] [client 143.244.47.86:33076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:09.014335 2026] [security2:error] [pid 915741:tid 915795] [remote 199.189.225.40:34605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TLa-615n1P-attmy7VwAByjU"]
[Mon Jul 20 06:23:09.211165 2026] [security2:error] [pid 915741:tid 915821] [remote 199.189.225.40:34605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TLa-615n1P-attmy7XQABl08"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:23:09.346355 2026] [proxy:error] [pid 915741:tid 915937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:09.346404 2026] [proxy_http:error] [pid 915741:tid 915937] [client 143.244.47.86:63849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:09.347235 2026] [proxy:error] [pid 915741:tid 915937] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:09.347278 2026] [proxy_http:error] [pid 915741:tid 915937] [client 143.244.47.86:63849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:09.587719 2026] [security2:error] [pid 884009:tid 884203] [client 14.225.17.146:49400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4TLRKaHUf6J8d3elJx-AAAAMM"], referer: http://aljosour-alarabia.com/Wp
[Mon Jul 20 06:23:09.642268 2026] [security2:error] [pid 884009:tid 884228] [client 104.234.53.91:46261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TLRKaHUf6J8d3elJyEAAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:09.869173 2026] [autoindex:error] [pid 915741:tid 915970] [client 143.244.47.86:22118] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:10.147942 2026] [security2:error] [pid 915741:tid 915976] [client 34.73.38.214:53305] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TLq-615n1P-attmy7jgAAAfg"]
[Mon Jul 20 06:23:10.346944 2026] [security2:error] [pid 915741:tid 915981] [client 57.141.18.113:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy6wwAB_RU"]
[Mon Jul 20 06:23:10.347464 2026] [security2:error] [pid 915741:tid 915942] [client 34.73.38.214:51612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TLq-615n1P-attmy7mAAAAdY"]
[Mon Jul 20 06:23:10.467756 2026] [security2:error] [pid 915741:tid 915879] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.amagicbutton.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7lAAAAZc"]
[Mon Jul 20 06:23:10.936736 2026] [security2:error] [pid 915741:tid 915877] [client 104.234.53.57:25455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TLq-615n1P-attmy7xQAAAZU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:10.937703 2026] [security2:error] [pid 915741:tid 915929] [client 34.73.38.214:62301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TLq-615n1P-attmy7xgAAAck"]
[Mon Jul 20 06:23:11.035504 2026] [security2:error] [pid 884009:tid 884167] [client 57.141.18.118:41534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKhKaHUf6J8d3elJxgQAAoFo"]
[Mon Jul 20 06:23:11.139108 2026] [security2:error] [pid 915741:tid 915940] [client 57.141.18.46:37946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy66gAB1Ag"]
[Mon Jul 20 06:23:11.196842 2026] [security2:error] [pid 915741:tid 915779] [remote 217.113.60.80:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy70QAB-CU"]
[Mon Jul 20 06:23:11.224060 2026] [security2:error] [pid 915741:tid 915783] [remote 167.233.114.32:53652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy70wAB5ik"]
[Mon Jul 20 06:23:11.261573 2026] [security2:error] [pid 884009:tid 884154] [client 57.141.18.107:53634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKhKaHUf6J8d3elJxjwAAk3U"]
[Mon Jul 20 06:23:11.401295 2026] [security2:error] [pid 915741:tid 915767] [remote 167.233.114.32:53652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy73gABlxk"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:23:11.438905 2026] [security2:error] [pid 915741:tid 915938] [client 34.73.38.214:57380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TL6-615n1P-attmy73wAAAdI"]
[Mon Jul 20 06:23:11.462355 2026] [security2:error] [pid 915741:tid 915865] [remote 217.113.60.80:42814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4TL6-615n1P-attmy74AABrXs"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:23:11.510925 2026] [autoindex:error] [pid 884009:tid 884229] [client 143.244.47.86:10949] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:11.516630 2026] [security2:error] [pid 915741:tid 915908] [client 171.60.139.123:64548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TL6-615n1P-attmy75AAAAbQ"]
[Mon Jul 20 06:23:11.516718 2026] [security2:error] [pid 915741:tid 915908] [client 171.60.139.123:64548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TL6-615n1P-attmy75AAAAbQ"]
[Mon Jul 20 06:23:11.528254 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.119:63982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TKq-615n1P-attmy68QAB3G0"]
[Mon Jul 20 06:23:11.681063 2026] [security2:error] [pid 915741:tid 915973] [client 116.179.33.12:53754] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4TL6-615n1P-attmy77gAAAfU"]
[Mon Jul 20 06:23:11.689849 2026] [security2:error] [pid 915741:tid 915894] [client 34.73.38.214:53166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TL6-615n1P-attmy78AAAAaY"]
[Mon Jul 20 06:23:11.835886 2026] [security2:error] [pid 884009:tid 884180] [client 104.234.53.88:50551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TLxKaHUf6J8d3elJyYAAAAKw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:11.909426 2026] [security2:error] [pid 915741:tid 915974] [client 14.225.17.146:49173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7kAAAAfY"], referer: http://bigwormfishing.com/Wp
[Mon Jul 20 06:23:12.194149 2026] [security2:error] [pid 915741:tid 915901] [client 34.73.38.214:60484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TMK-615n1P-attmy8DgAAAa0"]
[Mon Jul 20 06:23:12.266834 2026] [core:error] [pid 915741:tid 915890] [client 31.40.204.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:12.266860 2026] [core:error] [pid 915741:tid 915890] [client 31.40.204.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:12.550201 2026] [security2:error] [pid 915741:tid 915912] [client 178.152.178.232:37327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8JgAAAbg"]
[Mon Jul 20 06:23:12.557063 2026] [security2:error] [pid 915741:tid 915912] [client 178.152.178.232:37327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8JgAAAbg"]
[Mon Jul 20 06:23:12.569281 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:56723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TMBKaHUf6J8d3elJyfQAAAPI"]
[Mon Jul 20 06:23:12.569379 2026] [security2:error] [pid 884009:tid 884250] [client 45.116.69.230:56723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TMBKaHUf6J8d3elJyfQAAAPI"]
[Mon Jul 20 06:23:12.692908 2026] [security2:error] [pid 915741:tid 915883] [client 34.73.38.214:63922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TMK-615n1P-attmy8LQAAAZs"]
[Mon Jul 20 06:23:12.781895 2026] [security2:error] [pid 915741:tid 915946] [client 14.225.17.146:63601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TMK-615n1P-attmy8JwAAAdo"], referer: http://secretkeynumerology.com/Wp
[Mon Jul 20 06:23:12.866874 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:63696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4TMK-615n1P-attmy8LwAAAfU"], referer: https://bigwormfishing.com/Wp
[Mon Jul 20 06:23:12.908799 2026] [security2:error] [pid 915741:tid 915992] [client 57.141.18.107:53636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLK-615n1P-attmy7QQACCHY"]
[Mon Jul 20 06:23:12.978719 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8OQAAAZA"]
[Mon Jul 20 06:23:12.980002 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:56999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TMK-615n1P-attmy8OQAAAZA"]
[Mon Jul 20 06:23:13.041862 2026] [security2:error] [pid 915741:tid 915959] [client 104.234.53.91:48687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TMa-615n1P-attmy8PQAAAec"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:13.091445 2026] [security2:error] [pid 915741:tid 915926] [client 34.73.38.214:65373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TMa-615n1P-attmy8QQAAAcY"]
[Mon Jul 20 06:23:13.334180 2026] [security2:error] [pid 915741:tid 915879] [client 34.73.38.214:55730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TMa-615n1P-attmy8RgAAAZc"]
[Mon Jul 20 06:23:13.571552 2026] [security2:error] [pid 884009:tid 884268] [client 34.73.38.214:63313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TMRKaHUf6J8d3elJymQAAAQQ"]
[Mon Jul 20 06:23:13.658868 2026] [security2:error] [pid 915741:tid 915963] [client 50.116.65.227:11464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TMa-615n1P-attmy8WgAAAes"]
[Mon Jul 20 06:23:13.666558 2026] [security2:error] [pid 915741:tid 915980] [client 14.225.17.146:65478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4TL6-615n1P-attmy77AAAAfw"], referer: http://tntcatholic.com/Wp
[Mon Jul 20 06:23:13.670558 2026] [security2:error] [pid 915741:tid 915968] [client 50.116.65.227:25840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TMa-615n1P-attmy8WwAAAc0"]
[Mon Jul 20 06:23:13.713951 2026] [security2:error] [pid 915741:tid 915882] [client 104.234.53.55:47909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TMa-615n1P-attmy8YAAAAZo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:13.753536 2026] [security2:error] [pid 915741:tid 915964] [client 57.141.18.113:53494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLa-615n1P-attmy7dAAB7Bo"]
[Mon Jul 20 06:23:13.781742 2026] [security2:error] [pid 915741:tid 915992] [client 34.73.38.214:55295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TMa-615n1P-attmy8YwAAAgg"]
[Mon Jul 20 06:23:13.786492 2026] [security2:error] [pid 915741:tid 915895] [client 77.110.127.138:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4TMa-615n1P-attmy8ZAAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:13.882940 2026] [security2:error] [pid 915741:tid 915914] [client 14.225.17.146:56229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TMa-615n1P-attmy8YQAAAbo"], referer: https://secretkeynumerology.com/Wp
[Mon Jul 20 06:23:13.918656 2026] [security2:error] [pid 884009:tid 884206] [client 34.73.38.214:56514] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.wcn.ktk.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TMRKaHUf6J8d3elJyrAAAAMY"]
[Mon Jul 20 06:23:13.927440 2026] [security2:error] [pid 915741:tid 915916] [client 103.169.209.130:52952] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4TMa-615n1P-attmy8awAAAbw"]
[Mon Jul 20 06:23:14.089161 2026] [security2:error] [pid 915741:tid 915850] [remote 100.42.189.89:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8bwACBmw"]
[Mon Jul 20 06:23:14.286037 2026] [security2:error] [pid 915741:tid 915957] [client 54.169.146.187:31220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8cQAAAeU"]
[Mon Jul 20 06:23:14.324891 2026] [security2:error] [pid 884009:tid 884239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TMRKaHUf6J8d3elJypwAAAOc"]
[Mon Jul 20 06:23:14.429065 2026] [security2:error] [pid 915741:tid 915776] [remote 100.42.189.89:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8dAABuSI"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:23:14.752049 2026] [security2:error] [pid 915741:tid 915936] [client 57.141.18.112:54170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7tAAB0EY"]
[Mon Jul 20 06:23:14.967588 2026] [security2:error] [pid 915741:tid 915991] [client 57.141.18.87:62552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TLq-615n1P-attmy7wQACBxs"]
[Mon Jul 20 06:23:15.006413 2026] [security2:error] [pid 915741:tid 915790] [remote 98.156.100.191:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TMq-615n1P-attmy8lAABpTA"]
[Mon Jul 20 06:23:15.225657 2026] [security2:error] [pid 915741:tid 915913] [client 77.110.127.138:61516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TM6-615n1P-attmy8qgAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:15.225770 2026] [security2:error] [pid 915741:tid 915913] [client 77.110.127.138:61516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TM6-615n1P-attmy8qgAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:15.374073 2026] [security2:error] [pid 915741:tid 915759] [remote 57.141.18.63:28442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3520689"] [unique_id "al4TM6-615n1P-attmy8sgAB0xE"]
[Mon Jul 20 06:23:15.467080 2026] [security2:error] [pid 915741:tid 915950] [client 67.1.105.214:43520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4TM6-615n1P-attmy8vQAAAd4"]
[Mon Jul 20 06:23:15.476095 2026] [security2:error] [pid 915741:tid 915933] [client 54.204.158.117:15978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.158.204.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TM6-615n1P-attmy8vAAAAc0"]
[Mon Jul 20 06:23:15.644087 2026] [security2:error] [pid 915741:tid 915984] [client 68.151.204.91:58744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4TM6-615n1P-attmy8ygAAAgA"]
[Mon Jul 20 06:23:15.651575 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TM6-615n1P-attmy8ugAAAZM"]
[Mon Jul 20 06:23:15.727922 2026] [security2:error] [pid 915741:tid 915937] [client 57.141.18.39:46779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TL6-615n1P-attmy75QAB0QU"]
[Mon Jul 20 06:23:15.784393 2026] [security2:error] [pid 884009:tid 884109] [remote 110.249.202.234:37040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/wp-content/uploads/2025/09/Aosta-Drinks-Menu.pdf"] [unique_id "al4TMxKaHUf6J8d3elJy7AAAm2I"]
[Mon Jul 20 06:23:15.810036 2026] [security2:error] [pid 915741:tid 915896] [client 50.116.65.227:25870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TM6-615n1P-attmy8zgAAAag"]
[Mon Jul 20 06:23:15.819979 2026] [security2:error] [pid 915741:tid 915981] [client 50.116.65.227:25892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TM6-615n1P-attmy80QAAAf0"]
[Mon Jul 20 06:23:15.861096 2026] [security2:error] [pid 915741:tid 915936] [client 184.161.128.34:33714] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4TM6-615n1P-attmy81AAAAdA"]
[Mon Jul 20 06:23:15.900551 2026] [security2:error] [pid 915741:tid 915902] [client 129.222.247.80:6519] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4TM6-615n1P-attmy81wAAAa4"]
[Mon Jul 20 06:23:15.914429 2026] [security2:error] [pid 915741:tid 915894] [client 41.173.37.102:12675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TM6-615n1P-attmy82AAAAaY"]
[Mon Jul 20 06:23:15.914513 2026] [security2:error] [pid 915741:tid 915894] [client 41.173.37.102:12675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TM6-615n1P-attmy82AAAAaY"]
[Mon Jul 20 06:23:16.033157 2026] [security2:error] [pid 915741:tid 915905] [client 177.253.131.51:51990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4TNK-615n1P-attmy85gAAAbE"]
[Mon Jul 20 06:23:16.042854 2026] [security2:error] [pid 915741:tid 915920] [client 147.12.209.239:57116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4TNK-615n1P-attmy86AAAAcA"]
[Mon Jul 20 06:23:16.183859 2026] [security2:error] [pid 884009:tid 884247] [client 141.98.143.70:13761] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff"] [unique_id "al4TNBKaHUf6J8d3elJy_gAAAO8"]
[Mon Jul 20 06:23:16.206524 2026] [security2:error] [pid 915741:tid 915915] [client 112.201.205.242:37636] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4TNK-615n1P-attmy88gAAAbs"]
[Mon Jul 20 06:23:16.232430 2026] [security2:error] [pid 915741:tid 915876] [client 179.6.57.59:15831] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4TNK-615n1P-attmy89QAAAZQ"]
[Mon Jul 20 06:23:16.305784 2026] [security2:error] [pid 915741:tid 915877] [client 181.94.227.115:25479] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4TNK-615n1P-attmy8-wAAAZU"]
[Mon Jul 20 06:23:16.332364 2026] [security2:error] [pid 915741:tid 915883] [client 170.79.52.73:24817] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamawcubgee.woff2"] [unique_id "al4TNK-615n1P-attmy8_AAAAZs"]
[Mon Jul 20 06:23:16.349018 2026] [security2:error] [pid 884009:tid 884230] [client 104.234.53.83:54657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TNBKaHUf6J8d3elJzAQAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:16.357370 2026] [security2:error] [pid 884009:tid 884220] [client 196.234.134.214:50058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4TNBKaHUf6J8d3elJzAwAAANQ"]
[Mon Jul 20 06:23:16.374809 2026] [security2:error] [pid 915741:tid 915908] [client 200.53.206.216:56982] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4TNK-615n1P-attmy8_wAAAbQ"]
[Mon Jul 20 06:23:16.404854 2026] [security2:error] [pid 884009:tid 884226] [client 18.141.57.241:39152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TNBKaHUf6J8d3elJzAgAAANo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:23:16.431641 2026] [security2:error] [pid 884009:tid 884259] [client 171.250.160.8:3387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4TNBKaHUf6J8d3elJzCAAAAPs"]
[Mon Jul 20 06:23:16.482825 2026] [security2:error] [pid 915741:tid 915944] [client 77.110.127.138:61521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpAIAEPg2A'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4TNK-615n1P-attmy9BgAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.500778 2026] [security2:error] [pid 915741:tid 915931] [client 185.18.224.125:36286] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4TNK-615n1P-attmy9CAAAAcs"]
[Mon Jul 20 06:23:16.527704 2026] [security2:error] [pid 884009:tid 884176] [client 188.26.194.222:33208] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4TNBKaHUf6J8d3elJzEQAAAKg"]
[Mon Jul 20 06:23:16.544635 2026] [security2:error] [pid 915741:tid 915970] [client 91.182.175.182:35426] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4TNK-615n1P-attmy9DgAAAfI"]
[Mon Jul 20 06:23:16.564540 2026] [security2:error] [pid 915741:tid 915871] [client 57.141.18.84:25292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMK-615n1P-attmy8HwABj2k"]
[Mon Jul 20 06:23:16.572556 2026] [security2:error] [pid 915741:tid 915946] [client 103.113.194.63:55298] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4TNK-615n1P-attmy9EQAAAdo"]
[Mon Jul 20 06:23:16.636629 2026] [security2:error] [pid 915741:tid 915880] [client 77.110.127.138:61522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNK-615n1P-attmy9FQAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.636734 2026] [security2:error] [pid 915741:tid 915880] [client 77.110.127.138:61522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNK-615n1P-attmy9FQAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.642964 2026] [security2:error] [pid 915741:tid 915918] [client 138.97.119.106:39698] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4TNK-615n1P-attmy9FwAAAb4"]
[Mon Jul 20 06:23:16.726623 2026] [security2:error] [pid 915741:tid 915934] [client 86.108.23.14:49566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4TNK-615n1P-attmy9GQAAAc4"]
[Mon Jul 20 06:23:16.757208 2026] [security2:error] [pid 884009:tid 884146] [client 200.149.47.32:39701] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4TNBKaHUf6J8d3elJzFQAAAIs"]
[Mon Jul 20 06:23:16.760542 2026] [security2:error] [pid 884009:tid 884229] [client 116.204.140.26:37834] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4TNBKaHUf6J8d3elJzFgAAAN0"]
[Mon Jul 20 06:23:16.780139 2026] [security2:error] [pid 884009:tid 884209] [client 14.225.17.146:65269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4TMxKaHUf6J8d3elJy4AAAAMk"], referer: http://headachescarpaltunnelfibromyalgia.com/Wp
[Mon Jul 20 06:23:16.787573 2026] [security2:error] [pid 884009:tid 884167] [client 77.110.127.138:61524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php8zEBHZM7'%20OR%2051=(SELECT%2051%20FROM%20PG_SLEEP(15))--"] [unique_id "al4TNBKaHUf6J8d3elJzGAAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:16.813254 2026] [security2:error] [pid 884009:tid 884257] [client 203.20.108.16:58806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4TNBKaHUf6J8d3elJzGQAAAPk"]
[Mon Jul 20 06:23:16.872417 2026] [security2:error] [pid 884009:tid 884267] [client 203.9.211.159:14580] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4TNBKaHUf6J8d3elJzHAAAAQM"]
[Mon Jul 20 06:23:16.940794 2026] [security2:error] [pid 915741:tid 915917] [client 180.191.16.119:35467] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4TNK-615n1P-attmy9JwAAAb0"]
[Mon Jul 20 06:23:16.942615 2026] [security2:error] [pid 884009:tid 884198] [client 185.244.152.34:61621] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4TNBKaHUf6J8d3elJzHwAAAL4"]
[Mon Jul 20 06:23:16.949920 2026] [security2:error] [pid 915741:tid 915835] [remote 98.156.100.191:33430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TNK-615n1P-attmy9JAAByF0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:16.973248 2026] [security2:error] [pid 915741:tid 915962] [client 77.137.23.14:41858] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4TNK-615n1P-attmy9KwAAAeo"]
[Mon Jul 20 06:23:17.085776 2026] [security2:error] [pid 915741:tid 915963] [client 197.38.175.37:36594] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4TNa-615n1P-attmy9NAAAAes"]
[Mon Jul 20 06:23:17.103532 2026] [security2:error] [pid 884009:tid 884268] [client 77.110.127.138:61528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNRKaHUf6J8d3elJzJwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:17.103660 2026] [security2:error] [pid 884009:tid 884268] [client 77.110.127.138:61528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNRKaHUf6J8d3elJzJwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:17.112628 2026] [security2:error] [pid 884009:tid 884264] [client 136.158.50.9:7284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4TNRKaHUf6J8d3elJzKAAAAQA"]
[Mon Jul 20 06:23:17.145087 2026] [core:error] [pid 884009:tid 884216] [client 103.153.183.69:59766] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=0py8g0oi&v=qjscu), referer: https://www.reddit.com/
[Mon Jul 20 06:23:17.147485 2026] [security2:error] [pid 884009:tid 884149] [client 127.0.0.1:52978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TNRKaHUf6J8d3elJzKwAAAI4"], referer: https://www.reddit.com/
[Mon Jul 20 06:23:17.163377 2026] [security2:error] [pid 915741:tid 915986] [client 103.157.10.91:27115] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbnka.woff2"] [unique_id "al4TNa-615n1P-attmy9OgAAAgI"]
[Mon Jul 20 06:23:17.270817 2026] [security2:error] [pid 915741:tid 915971] [client 185.117.151.113:61553] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4TNa-615n1P-attmy9QAAAAfM"]
[Mon Jul 20 06:23:17.305619 2026] [security2:error] [pid 884009:tid 884251] [client 65.1.132.125:57436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TNRKaHUf6J8d3elJzMQAAAPM"]
[Mon Jul 20 06:23:17.305721 2026] [security2:error] [pid 884009:tid 884251] [client 65.1.132.125:57436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TNRKaHUf6J8d3elJzMQAAAPM"]
[Mon Jul 20 06:23:17.375866 2026] [security2:error] [pid 884009:tid 884233] [client 51.39.233.148:3404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf"] [unique_id "al4TNRKaHUf6J8d3elJzNQAAAOE"]
[Mon Jul 20 06:23:17.379992 2026] [security2:error] [pid 915741:tid 915929] [client 152.58.200.19:53366] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4TNa-615n1P-attmy9RgAAAck"]
[Mon Jul 20 06:23:17.384960 2026] [security2:error] [pid 915741:tid 915950] [client 176.236.235.14:6892] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4TNa-615n1P-attmy9RwAAAd4"]
[Mon Jul 20 06:23:17.487497 2026] [security2:error] [pid 915741:tid 915969] [client 27.96.94.195:36935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TNa-615n1P-attmy9TgAAAfE"]
[Mon Jul 20 06:23:17.487612 2026] [security2:error] [pid 915741:tid 915969] [client 27.96.94.195:36935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TNa-615n1P-attmy9TgAAAfE"]
[Mon Jul 20 06:23:17.537586 2026] [security2:error] [pid 915741:tid 915924] [client 84.54.66.146:4381] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4TNa-615n1P-attmy9UgAAAcQ"]
[Mon Jul 20 06:23:17.551181 2026] [security2:error] [pid 915741:tid 915891] [client 34.90.66.217:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.olearyplumbingllc.com"] [uri "/"] [unique_id "al4TNa-615n1P-attmy9VQAAAaM"]
[Mon Jul 20 06:23:17.551266 2026] [security2:error] [pid 915741:tid 915891] [client 34.90.66.217:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.olearyplumbingllc.com"] [uri "/"] [unique_id "al4TNa-615n1P-attmy9VQAAAaM"]
[Mon Jul 20 06:23:17.573305 2026] [security2:error] [pid 915741:tid 915928] [client 77.110.127.138:61536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpW65qqIxh')%20OR%20826=(SELECT%20826%20FROM%20PG_SLEEP(15))--"] [unique_id "al4TNa-615n1P-attmy9WAAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:17.696993 2026] [security2:error] [pid 915741:tid 915892] [client 102.67.231.58:41526] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4TNa-615n1P-attmy9WwAAAaQ"]
[Mon Jul 20 06:23:17.800775 2026] [security2:error] [pid 884009:tid 884166] [client 156.221.146.9:50118] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4TNRKaHUf6J8d3elJzRAAAAJ8"]
[Mon Jul 20 06:23:17.855862 2026] [security2:error] [pid 884009:tid 884232] [client 180.149.232.175:37932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4TNRKaHUf6J8d3elJzRQAAAOA"]
[Mon Jul 20 06:23:17.914618 2026] [security2:error] [pid 915741:tid 915872] [client 103.130.239.219:16518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4TNa-615n1P-attmy9XwAAAZA"]
[Mon Jul 20 06:23:17.942236 2026] [core:error] [pid 915741:tid 915966] [client 103.153.183.69:59772] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.env?_=90etvjgf&v=3k2va), referer: https://news.ycombinator.com/
[Mon Jul 20 06:23:17.973366 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.22:46600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMa-615n1P-attmy8VgABln8"]
[Mon Jul 20 06:23:18.019820 2026] [security2:error] [pid 915741:tid 915961] [client 115.135.199.52:40263] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufc5qw54a.woff2"] [unique_id "al4TNq-615n1P-attmy9aAAAAek"]
[Mon Jul 20 06:23:18.043519 2026] [security2:error] [pid 915741:tid 915954] [client 82.215.111.155:14548] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4TNq-615n1P-attmy9bAAAAeI"]
[Mon Jul 20 06:23:18.103042 2026] [security2:error] [pid 915741:tid 915996] [client 197.70.51.105:50660] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4TNq-615n1P-attmy9cgAAAgw"]
[Mon Jul 20 06:23:18.217255 2026] [security2:error] [pid 915741:tid 915925] [client 91.188.149.75:60296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4TNq-615n1P-attmy9dwAAAcU"]
[Mon Jul 20 06:23:18.388660 2026] [security2:error] [pid 884009:tid 884181] [client 77.110.127.138:61541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNhKaHUf6J8d3elJzWQAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:18.388762 2026] [security2:error] [pid 884009:tid 884181] [client 77.110.127.138:61541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNhKaHUf6J8d3elJzWQAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:18.428289 2026] [security2:error] [pid 884009:tid 884083] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzWwAA4kg"]
[Mon Jul 20 06:23:18.428775 2026] [security2:error] [pid 884009:tid 884234] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzWwAA4kg"]
[Mon Jul 20 06:23:18.666885 2026] [security2:error] [pid 884009:tid 884257] [client 171.61.165.146:18157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzaAAAAPk"]
[Mon Jul 20 06:23:18.667019 2026] [security2:error] [pid 884009:tid 884257] [client 171.61.165.146:18157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TNhKaHUf6J8d3elJzaAAAAPk"]
[Mon Jul 20 06:23:18.763797 2026] [security2:error] [pid 915741:tid 915785] [remote 57.141.18.17:32164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4TNq-615n1P-attmy9lgAB3ys"]
[Mon Jul 20 06:23:18.773357 2026] [security2:error] [pid 915741:tid 915979] [client 139.135.192.36:27089] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4TNq-615n1P-attmy9lwAAAfs"]
[Mon Jul 20 06:23:18.802806 2026] [security2:error] [pid 884009:tid 884241] [client 103.6.123.207:46132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4TNhKaHUf6J8d3elJzawAAAOk"]
[Mon Jul 20 06:23:18.809186 2026] [security2:error] [pid 915741:tid 915949] [client 192.236.168.43:41002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.narulatrucking.com"] [uri "/"] [unique_id "al4TNq-615n1P-attmy9mAAAAd0"]
[Mon Jul 20 06:23:18.810364 2026] [security2:error] [pid 884009:tid 884158] [client 57.141.18.89:60786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMhKaHUf6J8d3elJyvAAAlwQ"]
[Mon Jul 20 06:23:18.862604 2026] [security2:error] [pid 915741:tid 915837] [remote 72.167.132.114:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TNq-615n1P-attmy9mgABmV8"]
[Mon Jul 20 06:23:18.888020 2026] [security2:error] [pid 915741:tid 915922] [client 77.110.127.138:61550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNq-615n1P-attmy9nQAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:18.888114 2026] [security2:error] [pid 915741:tid 915922] [client 77.110.127.138:61550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TNq-615n1P-attmy9nQAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:19.033868 2026] [security2:error] [pid 915741:tid 915997] [client 103.91.129.66:36890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4TN6-615n1P-attmy9qwAAAg0"]
[Mon Jul 20 06:23:19.072262 2026] [security2:error] [pid 915741:tid 915913] [client 14.225.17.146:57865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4TNq-615n1P-attmy9hAAAAbk"]
[Mon Jul 20 06:23:19.082772 2026] [security2:error] [pid 915741:tid 915862] [remote 72.167.132.114:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TN6-615n1P-attmy9rwAB7Hg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:19.117828 2026] [security2:error] [pid 915741:tid 915956] [client 112.208.70.94:43213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TN6-615n1P-attmy9sQAAAeQ"]
[Mon Jul 20 06:23:19.117947 2026] [security2:error] [pid 915741:tid 915956] [client 112.208.70.94:43213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TN6-615n1P-attmy9sQAAAeQ"]
[Mon Jul 20 06:23:19.268109 2026] [security2:error] [pid 884009:tid 884242] [client 104.168.114.154:55120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "narulatrucking.com"] [uri "/"] [unique_id "al4TNxKaHUf6J8d3elJzeQAAAOo"]
[Mon Jul 20 06:23:19.303930 2026] [security2:error] [pid 915741:tid 915873] [client 103.238.110.113:5332] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4TN6-615n1P-attmy9ugAAAZE"]
[Mon Jul 20 06:23:19.358514 2026] [security2:error] [pid 884009:tid 884252] [client 104.168.114.154:55144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.narulatrucking.com"] [uri "/"] [unique_id "al4TNxKaHUf6J8d3elJzfwAAAPQ"]
[Mon Jul 20 06:23:19.404508 2026] [security2:error] [pid 915741:tid 915917] [client 45.115.42.85:60392] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4TN6-615n1P-attmy9wgAAAb0"]
[Mon Jul 20 06:23:19.701716 2026] [security2:error] [pid 915741:tid 915980] [client 98.159.234.160:30479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TN6-615n1P-attmy9zAAAAfw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:19.774131 2026] [security2:error] [pid 884009:tid 884153] [client 57.141.18.91:42778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TMxKaHUf6J8d3elJy6QAAkgg"]
[Mon Jul 20 06:23:19.975638 2026] [security2:error] [pid 915741:tid 915910] [client 104.234.53.74:59791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TN6-615n1P-attmy92gAAAbY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:20.073227 2026] [security2:error] [pid 915741:tid 915904] [client 32.198.12.77:27148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TOK-615n1P-attmy93gAAAbA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:23:20.370278 2026] [security2:error] [pid 915741:tid 915882] [client 57.141.18.48:39722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNK-615n1P-attmy89wABmjM"]
[Mon Jul 20 06:23:20.452505 2026] [security2:error] [pid 884009:tid 884192] [client 160.177.31.32:50346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4TOBKaHUf6J8d3elJzogAAALg"]
[Mon Jul 20 06:23:20.689294 2026] [security2:error] [pid 915741:tid 915905] [client 57.141.18.104:37328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNK-615n1P-attmy9EwABsXU"]
[Mon Jul 20 06:23:20.816977 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.37:24620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNK-615n1P-attmy9GgAB3F4"]
[Mon Jul 20 06:23:21.241923 2026] [security2:error] [pid 915741:tid 915964] [client 52.47.76.32:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TOa-615n1P-attmy-FwAAAew"]
[Mon Jul 20 06:23:21.242045 2026] [security2:error] [pid 915741:tid 915964] [client 52.47.76.32:54044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TOa-615n1P-attmy-FwAAAew"]
[Mon Jul 20 06:23:21.315085 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TOa-615n1P-attmy-HQAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.315216 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TOa-615n1P-attmy-HQAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.613019 2026] [security2:error] [pid 915741:tid 915914] [client 34.74.185.202:58174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4TOa-615n1P-attmy-KgAAAbo"]
[Mon Jul 20 06:23:21.635189 2026] [security2:error] [pid 915741:tid 915895] [client 57.141.18.44:54200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNa-615n1P-attmy9SAABp1E"]
[Mon Jul 20 06:23:21.689560 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TORKaHUf6J8d3elJzygAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.689691 2026] [security2:error] [pid 884009:tid 884232] [client 77.110.127.138:61561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TORKaHUf6J8d3elJzygAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:21.799417 2026] [autoindex:error] [pid 884009:tid 884054] [remote 143.244.47.86:43591] AH01276: Cannot serve directory /home1/zbqbutmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:21.824934 2026] [security2:error] [pid 884009:tid 884109] [remote 152.228.213.32:39614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4TORKaHUf6J8d3elJz1AAA2mI"]
[Mon Jul 20 06:23:21.871419 2026] [security2:error] [pid 915741:tid 915992] [client 14.225.17.146:57916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4TN6-615n1P-attmy90gAAAgg"], referer: http://webgardensbypaula.com/Wp
[Mon Jul 20 06:23:21.937432 2026] [security2:error] [pid 915741:tid 915970] [client 50.116.65.227:33046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TOa-615n1P-attmy-OQAAAfI"]
[Mon Jul 20 06:23:21.948086 2026] [security2:error] [pid 884009:tid 884181] [client 50.116.65.227:31156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TORKaHUf6J8d3elJz3AAAAL8"]
[Mon Jul 20 06:23:21.996503 2026] [security2:error] [pid 884009:tid 884266] [client 74.7.227.179:54008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4TORKaHUf6J8d3elJz1gABAkk"], referer: https://tejasenvironmental.com/p=539057
[Mon Jul 20 06:23:22.096229 2026] [security2:error] [pid 884009:tid 884137] [remote 152.228.213.32:39614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4TOhKaHUf6J8d3elJz4gAAvn4"], referer: https://bigwormfishing.com/wp-login.php
[Mon Jul 20 06:23:22.174064 2026] [security2:error] [pid 915741:tid 915896] [client 104.234.53.58:32395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TOq-615n1P-attmy-RwAAAag"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:22.195330 2026] [security2:error] [pid 915741:tid 915930] [client 77.110.127.138:61563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phput023jUN'))%20OR%20175=(SELECT%20175%20FROM%20PG_SLEEP(15))--"] [unique_id "al4TOq-615n1P-attmy-SAAAAco"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:22.200045 2026] [security2:error] [pid 884009:tid 884012] [remote 98.156.100.191:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TOhKaHUf6J8d3elJz5QAAnQE"]
[Mon Jul 20 06:23:22.219862 2026] [security2:error] [pid 915741:tid 915928] [client 34.74.185.202:49207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TOq-615n1P-attmy-SgAAAcg"]
[Mon Jul 20 06:23:22.251230 2026] [security2:error] [pid 915741:tid 915876] [client 171.60.139.123:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TOq-615n1P-attmy-TAAAAZQ"]
[Mon Jul 20 06:23:22.251373 2026] [security2:error] [pid 915741:tid 915876] [client 171.60.139.123:65064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TOq-615n1P-attmy-TAAAAZQ"]
[Mon Jul 20 06:23:22.317800 2026] [security2:error] [pid 915741:tid 915993] [client 57.141.18.78:27430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TNq-615n1P-attmy9cQACCR0"]
[Mon Jul 20 06:23:22.463019 2026] [security2:error] [pid 884009:tid 884128] [remote 98.156.100.191:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4TOhKaHUf6J8d3elJz8wAA6XU"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:23:22.604515 2026] [security2:error] [pid 915741:tid 915941] [client 66.102.122.221:34470] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4TOq-615n1P-attmy-XAAAAdU"]
[Mon Jul 20 06:23:23.154868 2026] [security2:error] [pid 915741:tid 915918] [client 114.119.150.215:43775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dasmarque.com"] [uri "/"] [unique_id "al4TO6-615n1P-attmy-ewAAAb4"], referer: https://kriesi.at/support/topic/product-zoom-available-for-propulsion
[Mon Jul 20 06:23:23.209552 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:61569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TO6-615n1P-attmy-fAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:23.209736 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:61569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TO6-615n1P-attmy-fAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:23.221056 2026] [security2:error] [pid 915741:tid 915919] [client 45.116.69.230:57272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-fQAAAb8"]
[Mon Jul 20 06:23:23.221184 2026] [security2:error] [pid 915741:tid 915919] [client 45.116.69.230:57272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-fQAAAb8"]
[Mon Jul 20 06:23:23.307021 2026] [security2:error] [pid 915741:tid 915928] [client 34.74.185.202:65419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TO6-615n1P-attmy-iAAAAcg"]
[Mon Jul 20 06:23:23.336614 2026] [security2:error] [pid 915741:tid 915880] [client 57.141.18.111:56190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TN6-615n1P-attmy9tAABmGE"]
[Mon Jul 20 06:23:23.371955 2026] [security2:error] [pid 915741:tid 915960] [client 14.225.17.146:57907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4TOK-615n1P-attmy-AwAAAeg"], referer: http://drewsasburyparkbeachhouse.com/Wp
[Mon Jul 20 06:23:23.465047 2026] [security2:error] [pid 915741:tid 915925] [client 14.225.17.146:58205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4TOa-615n1P-attmy-PQAAAcU"], referer: http://inspirespublishing.com/Wp
[Mon Jul 20 06:23:23.514775 2026] [security2:error] [pid 884009:tid 884228] [client 178.152.178.232:36454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TOxKaHUf6J8d3elJ0GAAAANw"]
[Mon Jul 20 06:23:23.521290 2026] [security2:error] [pid 884009:tid 884228] [client 178.152.178.232:36454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TOxKaHUf6J8d3elJ0GAAAANw"]
[Mon Jul 20 06:23:23.607316 2026] [security2:error] [pid 915741:tid 915979] [client 14.182.195.220:52151] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4TO6-615n1P-attmy-lAAAAfs"]
[Mon Jul 20 06:23:23.700906 2026] [security2:error] [pid 915741:tid 915962] [client 103.141.108.143:57474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-mgAAAeo"]
[Mon Jul 20 06:23:23.701010 2026] [security2:error] [pid 915741:tid 915962] [client 103.141.108.143:57474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TO6-615n1P-attmy-mgAAAeo"]
[Mon Jul 20 06:23:23.889775 2026] [security2:error] [pid 915741:tid 915942] [client 57.141.18.114:56168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TN6-615n1P-attmy90QAB1kE"]
[Mon Jul 20 06:23:24.412908 2026] [security2:error] [pid 915741:tid 915898] [client 45.56.185.237:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4TPK-615n1P-attmy-rQABqhM"]
[Mon Jul 20 06:23:24.453214 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:65404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4TOq-615n1P-attmy-XwAAAd0"], referer: http://fineartsfactory.net/Wp
[Mon Jul 20 06:23:24.526034 2026] [security2:error] [pid 884009:tid 884263] [client 50.116.65.227:31216] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TPBKaHUf6J8d3elJ0QgAAAP8"]
[Mon Jul 20 06:23:24.533082 2026] [security2:error] [pid 915741:tid 915899] [client 34.74.185.202:62424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TPK-615n1P-attmy-wAAAAas"]
[Mon Jul 20 06:23:24.536432 2026] [security2:error] [pid 884009:tid 884249] [client 50.116.65.227:31226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TPBKaHUf6J8d3elJ0RAAAAPE"]
[Mon Jul 20 06:23:24.587624 2026] [security2:error] [pid 915741:tid 915790] [remote 20.153.140.50:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TPK-615n1P-attmy-wgAB5jA"]
[Mon Jul 20 06:23:24.687823 2026] [security2:error] [pid 915741:tid 915922] [client 57.141.18.78:27438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TOK-615n1P-attmy99gABwjQ"]
[Mon Jul 20 06:23:24.958328 2026] [security2:error] [pid 884009:tid 884153] [client 77.110.127.138:61580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4TPBKaHUf6J8d3elJ0VAAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:24.983115 2026] [security2:error] [pid 915741:tid 915797] [remote 20.153.140.50:53814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TPK-615n1P-attmy-0QABmjc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:23:25.111437 2026] [security2:error] [pid 915741:tid 915963] [client 77.110.127.138:61584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy-2wAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:25.111542 2026] [security2:error] [pid 915741:tid 915963] [client 77.110.127.138:61584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy-2wAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:25.443302 2026] [security2:error] [pid 915741:tid 915903] [client 34.74.185.202:51947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TPa-615n1P-attmy-6gAAAa8"]
[Mon Jul 20 06:23:25.665791 2026] [security2:error] [pid 884009:tid 884254] [client 57.141.18.124:29096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TORKaHUf6J8d3elJz1QAA9gY"]
[Mon Jul 20 06:23:25.950055 2026] [security2:error] [pid 884009:tid 884185] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4TPRKaHUf6J8d3elJ0bQAAALE"]
[Mon Jul 20 06:23:25.980125 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy_CAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:25.980268 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TPa-615n1P-attmy_CAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:26.178209 2026] [security2:error] [pid 915741:tid 915991] [client 77.110.127.138:61588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4TPq-615n1P-attmy_FQAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:26.529485 2026] [security2:error] [pid 915741:tid 915965] [client 104.234.53.70:36307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TPq-615n1P-attmy_IwAAAe0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:26.568376 2026] [security2:error] [pid 884009:tid 884238] [client 41.173.37.102:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TPhKaHUf6J8d3elJ0igAAAOY"]
[Mon Jul 20 06:23:26.568472 2026] [security2:error] [pid 884009:tid 884238] [client 41.173.37.102:13078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TPhKaHUf6J8d3elJ0igAAAOY"]
[Mon Jul 20 06:23:26.673672 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:62274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TPq-615n1P-attmy_LAAAAbc"]
[Mon Jul 20 06:23:26.744076 2026] [core:error] [pid 884009:tid 884235] [client 103.153.183.69:59782] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.env?_=fme9a9hf&v=w088g), referer: https://twitter.com/
[Mon Jul 20 06:23:27.466220 2026] [security2:error] [pid 884009:tid 884198] [client 57.141.18.7:32918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TOxKaHUf6J8d3elJ0JwAAvjM"]
[Mon Jul 20 06:23:27.629220 2026] [security2:error] [pid 915741:tid 915956] [client 34.74.185.202:62277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TP6-615n1P-attmy_WQAAAeQ"]
[Mon Jul 20 06:23:27.950522 2026] [security2:error] [pid 915741:tid 915880] [client 57.141.18.108:40256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPK-615n1P-attmy-tgABmBA"]
[Mon Jul 20 06:23:27.957980 2026] [security2:error] [pid 915741:tid 915810] [remote 103.255.134.61:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4TP6-615n1P-attmy_YgABvUQ"]
[Mon Jul 20 06:23:28.095157 2026] [security2:error] [pid 915741:tid 915984] [client 34.74.185.202:60231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TQK-615n1P-attmy_ZgAAAgA"]
[Mon Jul 20 06:23:28.303663 2026] [security2:error] [pid 915741:tid 915841] [remote 57.141.18.105:48706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/2529028"] [unique_id "al4TQK-615n1P-attmy_bQABsmM"]
[Mon Jul 20 06:23:28.362674 2026] [security2:error] [pid 915741:tid 915883] [client 77.110.127.138:61592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4TQK-615n1P-attmy_bgAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:28.377707 2026] [security2:error] [pid 915741:tid 915962] [client 57.141.18.72:48630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPK-615n1P-attmy-xgAB6jk"]
[Mon Jul 20 06:23:28.457393 2026] [security2:error] [pid 915741:tid 915985] [client 27.96.94.195:37654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.94.96.27.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TQK-615n1P-attmy_dwAAAgE"]
[Mon Jul 20 06:23:28.457536 2026] [security2:error] [pid 915741:tid 915985] [client 27.96.94.195:37654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4TQK-615n1P-attmy_dwAAAgE"]
[Mon Jul 20 06:23:28.559312 2026] [security2:error] [pid 884009:tid 884176] [client 34.74.185.202:59388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TQBKaHUf6J8d3elJ03wAAAKg"]
[Mon Jul 20 06:23:28.600038 2026] [security2:error] [pid 915741:tid 915873] [client 104.234.53.67:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TQK-615n1P-attmy_fQAAAZE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:28.645220 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.76:52758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPa-615n1P-attmy-1QABqBE"]
[Mon Jul 20 06:23:28.804494 2026] [security2:error] [pid 915741:tid 915882] [client 14.225.17.146:57637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4TP6-615n1P-attmy_QwAAAZo"], referer: http://expertcultures.com/Wp
[Mon Jul 20 06:23:28.860422 2026] [security2:error] [pid 915741:tid 915837] [remote 103.124.95.115:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4TQK-615n1P-attmy_iwABpV8"]
[Mon Jul 20 06:23:28.875080 2026] [security2:error] [pid 915741:tid 915877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_cwAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:28.898617 2026] [security2:error] [pid 915741:tid 915778] [remote 103.255.134.61:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4TQK-615n1P-attmy_kAABliQ"], referer: https://swafforddetailing.com/wp-login.php
[Mon Jul 20 06:23:28.951396 2026] [security2:error] [pid 915741:tid 915908] [client 34.74.185.202:51802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TQK-615n1P-attmy_kwAAAbQ"]
[Mon Jul 20 06:23:29.094993 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:61597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TQa-615n1P-attmy_mgAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:29.095127 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:61597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TQa-615n1P-attmy_mgAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:29.112411 2026] [security2:error] [pid 915741:tid 915950] [client 57.141.18.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_gQAAAd4"]
[Mon Jul 20 06:23:29.124566 2026] [security2:error] [pid 915741:tid 915818] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_nAAB0Uw"]
[Mon Jul 20 06:23:29.124708 2026] [security2:error] [pid 915741:tid 915937] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_nAAB0Uw"]
[Mon Jul 20 06:23:29.321898 2026] [security2:error] [pid 915741:tid 915765] [remote 103.124.95.115:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.95.124.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4TQa-615n1P-attmy_pAABuxc"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:23:29.326961 2026] [security2:error] [pid 915741:tid 915905] [client 14.225.17.146:58613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4TP6-615n1P-attmy_TQAAAbE"], referer: http://sarahsnyder.net/Wp
[Mon Jul 20 06:23:29.412108 2026] [security2:error] [pid 915741:tid 915896] [client 34.74.185.202:49532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TQa-615n1P-attmy_rAAAAag"]
[Mon Jul 20 06:23:29.420645 2026] [security2:error] [pid 915741:tid 915883] [client 77.110.127.138:61598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQa-615n1P-attmy_ngAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:29.491982 2026] [security2:error] [pid 915741:tid 915990] [client 171.61.165.146:31883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_swAAAgY"]
[Mon Jul 20 06:23:29.492172 2026] [security2:error] [pid 915741:tid 915990] [client 171.61.165.146:31883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TQa-615n1P-attmy_swAAAgY"]
[Mon Jul 20 06:23:29.613015 2026] [security2:error] [pid 915741:tid 915748] [remote 47.86.33.52:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TQa-615n1P-attmy_tQAB7AY"]
[Mon Jul 20 06:23:29.773478 2026] [security2:error] [pid 884009:tid 884207] [client 34.74.185.202:53935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TQRKaHUf6J8d3elJ1DQAAAMc"]
[Mon Jul 20 06:23:29.841232 2026] [security2:error] [pid 915741:tid 915980] [client 57.141.18.94:21602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPq-615n1P-attmy_GgAB_Cw"]
[Mon Jul 20 06:23:29.863349 2026] [security2:error] [pid 884009:tid 884263] [client 77.110.127.138:61602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQRKaHUf6J8d3elJ1BwAAAP8"]
[Mon Jul 20 06:23:29.969924 2026] [ssl:error] [pid 915741:tid 915902] [client 104.48.69.105:49142] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:23:30.053185 2026] [security2:error] [pid 884009:tid 884161] [client 34.74.185.202:57329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.dienerranch.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TQhKaHUf6J8d3elJ1GQAAAJo"]
[Mon Jul 20 06:23:30.128365 2026] [security2:error] [pid 915741:tid 915787] [remote 47.86.33.52:14396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TQq-615n1P-attmy_xwABsC0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:30.204198 2026] [security2:error] [pid 915741:tid 915992] [client 74.208.214.194:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TQq-615n1P-attmy_ywAAAgg"]
[Mon Jul 20 06:23:30.271443 2026] [security2:error] [pid 884009:tid 884237] [client 158.173.241.141:30587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TQhKaHUf6J8d3elJ1GgAAAOU"], referer: http://sesamegreenbeans.com/nine-days-south-africa-v/
[Mon Jul 20 06:23:30.293728 2026] [security2:error] [pid 915741:tid 915959] [client 14.225.17.146:57812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_yAAAAec"], referer: https://sarahsnyder.net/Wp
[Mon Jul 20 06:23:30.429958 2026] [security2:error] [pid 915741:tid 915892] [client 77.110.127.138:61612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_xgAAAaQ"]
[Mon Jul 20 06:23:30.439247 2026] [security2:error] [pid 915741:tid 915940] [client 57.141.18.0:20582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TPq-615n1P-attmy_OQAB1Dg"]
[Mon Jul 20 06:23:30.452962 2026] [security2:error] [pid 915741:tid 915884] [client 14.225.17.146:58476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_hAAAAZw"], referer: http://cheesewithjam.com/Wp
[Mon Jul 20 06:23:30.629063 2026] [security2:error] [pid 915741:tid 915942] [client 57.141.18.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_zwAAAdY"]
[Mon Jul 20 06:23:30.940053 2026] [security2:error] [pid 915741:tid 915962] [client 50.116.65.227:47238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TQq-615n1P-attmy_8QAAAeo"]
[Mon Jul 20 06:23:30.952217 2026] [security2:error] [pid 884009:tid 884168] [client 50.116.65.227:59900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TQhKaHUf6J8d3elJ1PQAAAKE"]
[Mon Jul 20 06:23:31.167271 2026] [security2:error] [pid 915741:tid 915987] [client 57.141.18.28:38518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TP6-615n1P-attmy_VAACAzw"]
[Mon Jul 20 06:23:31.392229 2026] [security2:error] [pid 884009:tid 884158] [client 14.225.17.146:59162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4TQxKaHUf6J8d3elJ1RAAAAJc"], referer: http://thesoloceos.com/Wp
[Mon Jul 20 06:23:31.567044 2026] [security2:error] [pid 915741:tid 915982] [client 209.87.169.176:42009] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "querenciapartners.com"] [uri "/"] [unique_id "al4TQ6-615n1P-attmzACgAAAf4"], referer: http://qpcanada.com/
[Mon Jul 20 06:23:31.786760 2026] [security2:error] [pid 915741:tid 915889] [client 14.225.17.146:58491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4TQ6-615n1P-attmzAGgAAAaE"], referer: http://adultdaycarereno.com/Wp
[Mon Jul 20 06:23:31.800025 2026] [security2:error] [pid 915741:tid 915929] [client 14.225.17.146:57533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_3QAAAck"]
[Mon Jul 20 06:23:31.946911 2026] [security2:error] [pid 915741:tid 915984] [client 50.116.65.227:47256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TQ6-615n1P-attmzAJAAAAgA"]
[Mon Jul 20 06:23:31.958070 2026] [security2:error] [pid 915741:tid 915885] [client 50.116.65.227:59948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4TQ6-615n1P-attmzAJQAAAZ0"]
[Mon Jul 20 06:23:32.005107 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzAJwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.005200 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzAJwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.084252 2026] [security2:error] [pid 915741:tid 915872] [client 57.141.18.68:48598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_fwABkFY"]
[Mon Jul 20 06:23:32.155931 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:61618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzALQAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.156038 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:61618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRK-615n1P-attmzALQAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:32.342780 2026] [security2:error] [pid 915741:tid 915996] [client 57.141.18.33:32590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQK-615n1P-attmy_jwACDE8"]
[Mon Jul 20 06:23:32.374250 2026] [security2:error] [pid 915741:tid 915954] [client 14.225.17.146:58464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzAMQAAAeI"], referer: https://thesoloceos.com/Wp
[Mon Jul 20 06:23:32.527652 2026] [security2:error] [pid 915741:tid 915941] [client 185.198.240.141:52337] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "querenciapartners.com"] [uri "/"] [unique_id "al4TRK-615n1P-attmzARgAAAdU"], referer: http://qpcanada.com/wp-includes/css/buttons.css
[Mon Jul 20 06:23:32.694463 2026] [security2:error] [pid 915741:tid 915968] [client 14.225.17.146:58181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzATQAAAfA"], referer: https://adultdaycarereno.com/Wp
[Mon Jul 20 06:23:32.850674 2026] [security2:error] [pid 915741:tid 915963] [client 171.60.139.123:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TRK-615n1P-attmzAUgAAAes"]
[Mon Jul 20 06:23:32.850786 2026] [security2:error] [pid 915741:tid 915963] [client 171.60.139.123:49193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TRK-615n1P-attmzAUgAAAes"]
[Mon Jul 20 06:23:32.853676 2026] [security2:error] [pid 884009:tid 884234] [client 112.208.70.94:43637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TRBKaHUf6J8d3elJ1hAAAAOI"]
[Mon Jul 20 06:23:32.853768 2026] [security2:error] [pid 884009:tid 884234] [client 112.208.70.94:43637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TRBKaHUf6J8d3elJ1hAAAAOI"]
[Mon Jul 20 06:23:33.265797 2026] [security2:error] [pid 915741:tid 915936] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAWQAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:33.274742 2026] [security2:error] [pid 884009:tid 884155] [client 45.157.112.60:24885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TRRKaHUf6J8d3elJ1mAAAAJQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:33.365454 2026] [security2:error] [pid 915741:tid 915938] [client 173.239.214.12:61985] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "querenciapartners.com"] [uri "/"] [unique_id "al4TRa-615n1P-attmzAZgAAAdI"], referer: http://qpcanada.com/media/system/js/core.js
[Mon Jul 20 06:23:33.408051 2026] [security2:error] [pid 915741:tid 915970] [client 57.141.18.35:20468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQa-615n1P-attmy_uwAB8kA"]
[Mon Jul 20 06:23:33.443164 2026] [security2:error] [pid 884009:tid 884091] [remote 162.19.86.63:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TRRKaHUf6J8d3elJ1nQAAoFA"]
[Mon Jul 20 06:23:33.443304 2026] [security2:error] [pid 884009:tid 884167] [client 162.19.86.63:50479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TRRKaHUf6J8d3elJ1nQAAoFA"]
[Mon Jul 20 06:23:34.043595 2026] [security2:error] [pid 915741:tid 915939] [client 57.141.18.76:52768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQq-615n1P-attmy_3AAB014"]
[Mon Jul 20 06:23:34.055354 2026] [security2:error] [pid 915741:tid 915809] [remote 192.241.143.148:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TRq-615n1P-attmzAmgABuEM"]
[Mon Jul 20 06:23:34.165059 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:61630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAowAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.165172 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:61630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAowAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.249010 2026] [security2:error] [pid 915741:tid 915850] [remote 192.241.143.148:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TRq-615n1P-attmzApAABqGw"], referer: https://friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:34.285834 2026] [security2:error] [pid 915741:tid 915989] [client 103.141.108.143:58014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzApgAAAgU"]
[Mon Jul 20 06:23:34.285938 2026] [security2:error] [pid 915741:tid 915989] [client 103.141.108.143:58014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzApgAAAgU"]
[Mon Jul 20 06:23:34.322586 2026] [security2:error] [pid 915741:tid 915974] [client 77.110.127.138:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAqwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.322685 2026] [security2:error] [pid 915741:tid 915974] [client 77.110.127.138:61631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAqwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.349255 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:61598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArAAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.349400 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:61598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArAAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.401718 2026] [security2:error] [pid 915741:tid 915946] [client 77.110.127.138:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.401867 2026] [security2:error] [pid 915741:tid 915946] [client 77.110.127.138:61600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzArgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.466675 2026] [security2:error] [pid 884009:tid 884212] [client 77.110.127.138:61602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1vgAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.466790 2026] [security2:error] [pid 884009:tid 884212] [client 77.110.127.138:61602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1vgAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.518059 2026] [security2:error] [pid 915741:tid 915917] [client 77.110.127.138:61601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAsgAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.518245 2026] [security2:error] [pid 915741:tid 915917] [client 77.110.127.138:61601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAsgAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.528948 2026] [security2:error] [pid 915741:tid 915978] [client 14.225.17.146:57727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAZAAAAfo"], referer: http://sarahholyfield.com/Wp
[Mon Jul 20 06:23:34.571099 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:61609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1xwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.571244 2026] [security2:error] [pid 884009:tid 884151] [client 77.110.127.138:61609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRhKaHUf6J8d3elJ1xwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.632658 2026] [security2:error] [pid 915741:tid 915938] [client 77.110.127.138:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAuAAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.632852 2026] [security2:error] [pid 915741:tid 915938] [client 77.110.127.138:61610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TRq-615n1P-attmzAuAAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:34.667530 2026] [security2:error] [pid 915741:tid 915914] [client 178.152.178.232:37463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAugAAAbo"]
[Mon Jul 20 06:23:34.667629 2026] [security2:error] [pid 915741:tid 915914] [client 178.152.178.232:37463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAugAAAbo"]
[Mon Jul 20 06:23:34.702167 2026] [security2:error] [pid 915741:tid 915994] [client 45.116.69.230:58056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAvAAAAgo"]
[Mon Jul 20 06:23:34.702330 2026] [security2:error] [pid 915741:tid 915994] [client 45.116.69.230:58056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TRq-615n1P-attmzAvAAAAgo"]
[Mon Jul 20 06:23:35.015993 2026] [security2:error] [pid 915741:tid 915977] [client 57.141.18.7:59902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TQ6-615n1P-attmzABgAB-Qc"]
[Mon Jul 20 06:23:35.186966 2026] [security2:error] [pid 884009:tid 884155] [client 46.110.96.34:17733] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4TRxKaHUf6J8d3elJ13AAAAJQ"]
[Mon Jul 20 06:23:35.339957 2026] [security2:error] [pid 884009:tid 884240] [client 104.234.53.52:50953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TRxKaHUf6J8d3elJ14gAAAOg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:35.509453 2026] [security2:error] [pid 915741:tid 915987] [client 14.225.17.146:58844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAYAAAAgM"]
[Mon Jul 20 06:23:35.527754 2026] [security2:error] [pid 915741:tid 915743] [remote 20.153.140.50:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4TR6-615n1P-attmzA2gAB9gE"]
[Mon Jul 20 06:23:35.790820 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TR6-615n1P-attmzA2wAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:35.832092 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.23:34478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzANQAB5D8"]
[Mon Jul 20 06:23:35.852075 2026] [security2:error] [pid 915741:tid 915933] [client 77.110.127.138:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TR6-615n1P-attmzA7QAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:35.852209 2026] [security2:error] [pid 915741:tid 915933] [client 77.110.127.138:61633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TR6-615n1P-attmzA7QAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:35.925274 2026] [security2:error] [pid 915741:tid 915747] [remote 20.153.140.50:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4TR6-615n1P-attmzA8QABkwU"], referer: https://superiorcopywriting.com/wp-login.php
[Mon Jul 20 06:23:35.927563 2026] [security2:error] [pid 915741:tid 915990] [client 57.141.18.41:47726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRK-615n1P-attmzAQQACBhw"]
[Mon Jul 20 06:23:36.384300 2026] [security2:error] [pid 915741:tid 915981] [client 114.119.128.23:56669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thierry-henry.fr"] [uri "/wed-2019/amp/"] [unique_id "al4TSK-615n1P-attmzBDAAAAf0"], referer: https://thierry-henry.fr/episode28-laplace/amp/
[Mon Jul 20 06:23:36.397283 2026] [security2:error] [pid 884009:tid 884268] [client 14.224.227.113:55726] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4TSBKaHUf6J8d3elJ2DAAAAQQ"]
[Mon Jul 20 06:23:36.573923 2026] [ssl:error] [pid 884009:tid 884165] [client 104.48.69.105:49146] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:23:36.670433 2026] [security2:error] [pid 884009:tid 884043] [remote 45.90.123.233:46558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4TSBKaHUf6J8d3elJ2GwAAwyA"]
[Mon Jul 20 06:23:36.719028 2026] [security2:error] [pid 915741:tid 915881] [client 14.225.17.146:57089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBEQAAAZk"], referer: http://falconarrowshop.com/Wp
[Mon Jul 20 06:23:36.776958 2026] [security2:error] [pid 915741:tid 915995] [client 14.225.17.146:57361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBEwAAAgs"]
[Mon Jul 20 06:23:36.873741 2026] [security2:error] [pid 884009:tid 884019] [remote 45.90.123.233:46558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4TSBKaHUf6J8d3elJ2IwAAwQg"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 06:23:37.026822 2026] [security2:error] [pid 915741:tid 915961] [client 77.110.127.138:61620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TSa-615n1P-attmzBJAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:37.026929 2026] [security2:error] [pid 915741:tid 915961] [client 77.110.127.138:61620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TSa-615n1P-attmzBJAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:37.035315 2026] [security2:error] [pid 915741:tid 915946] [client 14.225.17.146:58422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "goyalsatyam.com"] [uri "/index.php"] [unique_id "al4TR6-615n1P-attmzA4QAAAdo"], referer: http://goyalsatyam.com/Wp
[Mon Jul 20 06:23:37.147722 2026] [security2:error] [pid 884009:tid 884219] [client 41.173.37.102:13704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TSRKaHUf6J8d3elJ2MwAAANM"]
[Mon Jul 20 06:23:37.147869 2026] [security2:error] [pid 884009:tid 884219] [client 41.173.37.102:13704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TSRKaHUf6J8d3elJ2MwAAANM"]
[Mon Jul 20 06:23:37.276262 2026] [security2:error] [pid 915741:tid 915892] [client 57.141.18.20:59220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRa-615n1P-attmzAagABpHY"]
[Mon Jul 20 06:23:37.293854 2026] [security2:error] [pid 915741:tid 915962] [client 127.0.0.1:20602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TSa-615n1P-attmzBNAAAAeo"], referer: https://t.co/5st0lvavmo
[Mon Jul 20 06:23:37.379488 2026] [security2:error] [pid 915741:tid 915768] [remote 85.204.69.248:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBNgABqxo"]
[Mon Jul 20 06:23:37.611550 2026] [security2:error] [pid 915741:tid 915810] [remote 188.166.241.141:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBSQABzkQ"]
[Mon Jul 20 06:23:37.625703 2026] [security2:error] [pid 915741:tid 915804] [remote 85.204.69.248:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBSwAB_D4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:37.649827 2026] [ssl:error] [pid 915741:tid 915924] [client 104.48.69.105:49162] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:23:37.761088 2026] [security2:error] [pid 884009:tid 884077] [remote 57.141.18.25:59418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3579229"] [unique_id "al4TSRKaHUf6J8d3elJ2SgAA7UI"]
[Mon Jul 20 06:23:37.881936 2026] [security2:error] [pid 915741:tid 915950] [client 216.38.230.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBRQAB3n8"]
[Mon Jul 20 06:23:37.883032 2026] [security2:error] [pid 915741:tid 915948] [client 57.141.18.95:48434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRq-615n1P-attmzAlQAB3CM"]
[Mon Jul 20 06:23:37.978589 2026] [security2:error] [pid 915741:tid 915759] [remote 188.166.241.141:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4TSa-615n1P-attmzBWAAB5BE"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:23:38.366870 2026] [security2:error] [pid 915741:tid 915947] [client 57.141.18.38:33286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TRq-615n1P-attmzAtAAB2yI"]
[Mon Jul 20 06:23:38.389960 2026] [security2:error] [pid 915741:tid 915936] [client 14.225.17.146:49780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBNwAAAdA"], referer: http://entuvy.com/Wp
[Mon Jul 20 06:23:38.885265 2026] [security2:error] [pid 915741:tid 915894] [client 14.225.17.146:53062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBOQAAAaY"], referer: http://kromosenergy.com/Wp
[Mon Jul 20 06:23:38.932247 2026] [security2:error] [pid 884009:tid 884183] [client 113.160.97.242:57665] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4TShKaHUf6J8d3elJ2cAAAAK8"]
[Mon Jul 20 06:23:39.026830 2026] [security2:error] [pid 915741:tid 915968] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.cel.bdi.mybluehost.me"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBAQAAAfA"]
[Mon Jul 20 06:23:39.680339 2026] [security2:error] [pid 915741:tid 915896] [client 14.225.17.146:49541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4TS6-615n1P-attmzBmQAAAag"], referer: http://bruceledewitz.com/Wp
[Mon Jul 20 06:23:39.739471 2026] [security2:error] [pid 884009:tid 884134] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2kwAAtXs"]
[Mon Jul 20 06:23:39.739661 2026] [security2:error] [pid 884009:tid 884189] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2kwAAtXs"]
[Mon Jul 20 06:23:39.937058 2026] [security2:error] [pid 884009:tid 884237] [client 143.244.48.150:59934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2lgAAAOU"], referer: https://recruitinginsight.us/2020/03/24/protect-your-recruiting-infrastructure/
[Mon Jul 20 06:23:39.937108 2026] [security2:error] [pid 884009:tid 884237] [client 143.244.48.150:59934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4TSxKaHUf6J8d3elJ2lgAAAOU"], referer: https://recruitinginsight.us/2020/03/24/protect-your-recruiting-infrastructure/
[Mon Jul 20 06:23:39.976356 2026] [security2:error] [pid 884009:tid 884196] [client 82.102.18.116:11170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TSxKaHUf6J8d3elJ2mQAAALw"]
[Mon Jul 20 06:23:39.986736 2026] [security2:error] [pid 915741:tid 915904] [client 57.141.18.39:25269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSK-615n1P-attmzBBgABsBI"]
[Mon Jul 20 06:23:40.204710 2026] [security2:error] [pid 915741:tid 915780] [remote 45.90.123.233:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TTK-615n1P-attmzBxAACBSY"]
[Mon Jul 20 06:23:40.257458 2026] [security2:error] [pid 915741:tid 915877] [client 50.116.65.227:21080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4TTK-615n1P-attmzByQAAAZU"]
[Mon Jul 20 06:23:40.267699 2026] [security2:error] [pid 915741:tid 915890] [client 50.116.65.227:58916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Kota-88-Feature-Image.jpg"] [unique_id "al4TTK-615n1P-attmzBygAAAaI"]
[Mon Jul 20 06:23:40.399557 2026] [security2:error] [pid 915741:tid 915851] [remote 45.90.123.233:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TTK-615n1P-attmzBzwABpW0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:23:40.537729 2026] [security2:error] [pid 884009:tid 884030] [remote 117.0.21.154:60024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TTBKaHUf6J8d3elJ2rQAA8hM"]
[Mon Jul 20 06:23:40.577411 2026] [security2:error] [pid 915741:tid 915891] [client 171.61.165.146:32960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TTK-615n1P-attmzB2gAAAaM"]
[Mon Jul 20 06:23:40.577565 2026] [security2:error] [pid 915741:tid 915891] [client 171.61.165.146:32960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TTK-615n1P-attmzB2gAAAaM"]
[Mon Jul 20 06:23:40.650063 2026] [security2:error] [pid 884009:tid 884194] [client 82.102.18.116:38870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TTBKaHUf6J8d3elJ2tQAAALo"]
[Mon Jul 20 06:23:40.684769 2026] [security2:error] [pid 884009:tid 884220] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TTBKaHUf6J8d3elJ2qwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:40.693212 2026] [security2:error] [pid 915741:tid 915888] [client 14.225.17.146:53207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzB1gAAAaA"], referer: http://samdothan.org/Wp
[Mon Jul 20 06:23:41.017589 2026] [security2:error] [pid 884009:tid 884066] [remote 117.0.21.154:60024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TTRKaHUf6J8d3elJ2wQABAjc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:41.248923 2026] [security2:error] [pid 915741:tid 915881] [client 57.141.18.61:43856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSa-615n1P-attmzBTgABmVo"]
[Mon Jul 20 06:23:41.492389 2026] [security2:error] [pid 915741:tid 915855] [remote 20.153.140.50:58664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TTa-615n1P-attmzB-QAB4XE"]
[Mon Jul 20 06:23:41.492644 2026] [security2:error] [pid 915741:tid 915953] [client 20.153.140.50:58664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TTa-615n1P-attmzB-QAB4XE"]
[Mon Jul 20 06:23:41.649145 2026] [security2:error] [pid 915741:tid 915984] [client 14.225.17.146:49710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzB6wAAAgA"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/Wp
[Mon Jul 20 06:23:41.792591 2026] [autoindex:error] [pid 884009:tid 884249] [client 64.227.107.201:39922] AH01276: Cannot serve directory /home2/bzmppvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:23:42.108227 2026] [security2:error] [pid 915741:tid 915981] [client 57.141.18.22:55238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSq-615n1P-attmzBcQAB_Xg"]
[Mon Jul 20 06:23:42.478097 2026] [security2:error] [pid 884009:tid 884157] [client 57.141.18.1:23400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TShKaHUf6J8d3elJ2cQAAlh0"]
[Mon Jul 20 06:23:42.520362 2026] [security2:error] [pid 884009:tid 884227] [client 103.153.183.69:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../root/.bash_history"] [unique_id "al4TThKaHUf6J8d3elJ3DgAAANs"], referer: https://www.reddit.com/
[Mon Jul 20 06:23:42.562373 2026] [security2:error] [pid 884009:tid 884205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TThKaHUf6J8d3elJ3CAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:42.623832 2026] [security2:error] [pid 884009:tid 884122] [remote 72.167.132.114:33244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4TThKaHUf6J8d3elJ3EQAA528"]
[Mon Jul 20 06:23:42.680828 2026] [security2:error] [pid 915741:tid 915827] [remote 20.153.140.50:58678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4TTq-615n1P-attmzCLAAB6lU"]
[Mon Jul 20 06:23:42.711362 2026] [security2:error] [pid 884009:tid 884189] [client 50.116.65.227:58952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TThKaHUf6J8d3elJ3FgAAALU"]
[Mon Jul 20 06:23:42.722578 2026] [security2:error] [pid 884009:tid 884175] [client 50.116.65.227:58956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TThKaHUf6J8d3elJ3GAAAAKc"]
[Mon Jul 20 06:23:42.749499 2026] [security2:error] [pid 884009:tid 884142] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4TThKaHUf6J8d3elJ3AQAAhzQ"], referer: http://ali-alghanim.net/Wp
[Mon Jul 20 06:23:42.870620 2026] [security2:error] [pid 884009:tid 884019] [remote 72.167.132.114:33244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4TThKaHUf6J8d3elJ3HwAAtgg"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:23:42.932506 2026] [security2:error] [pid 915741:tid 915939] [client 57.141.18.97:37770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TS6-615n1P-attmzBqwAB02U"]
[Mon Jul 20 06:23:43.019297 2026] [security2:error] [pid 884009:tid 884216] [client 57.141.18.37:37948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TSxKaHUf6J8d3elJ2kgAA0EQ"]
[Mon Jul 20 06:23:43.021375 2026] [security2:error] [pid 884009:tid 884150] [client 77.110.127.138:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TTxKaHUf6J8d3elJ3JAAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:43.021475 2026] [security2:error] [pid 884009:tid 884150] [client 77.110.127.138:61652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TTxKaHUf6J8d3elJ3JAAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:43.065725 2026] [security2:error] [pid 915741:tid 915809] [remote 20.153.140.50:58678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4TT6-615n1P-attmzCOQACAUM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:23:43.201814 2026] [security2:error] [pid 915741:tid 915952] [client 57.141.18.96:58156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TS6-615n1P-attmzBtgAB4HU"]
[Mon Jul 20 06:23:43.339994 2026] [security2:error] [pid 884009:tid 884263] [client 82.102.18.116:38882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TTxKaHUf6J8d3elJ3LwAAAP8"]
[Mon Jul 20 06:23:43.340148 2026] [security2:error] [pid 884009:tid 884263] [client 82.102.18.116:38882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "falconarrowshop.com"] [uri "/"] [unique_id "al4TTxKaHUf6J8d3elJ3LwAAAP8"]
[Mon Jul 20 06:23:43.391337 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TT6-615n1P-attmzCQQAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:43.453252 2026] [security2:error] [pid 915741:tid 915918] [client 57.141.18.111:62226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzBwAABvgg"]
[Mon Jul 20 06:23:43.603265 2026] [security2:error] [pid 884009:tid 884195] [client 171.60.139.123:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TTxKaHUf6J8d3elJ3MwAAALs"]
[Mon Jul 20 06:23:43.603401 2026] [security2:error] [pid 884009:tid 884195] [client 171.60.139.123:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TTxKaHUf6J8d3elJ3MwAAALs"]
[Mon Jul 20 06:23:43.650706 2026] [security2:error] [pid 915741:tid 915972] [client 57.141.18.1:23420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TTK-615n1P-attmzByAAB9Dw"]
[Mon Jul 20 06:23:44.243413 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUK-615n1P-attmzCfwAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:44.243528 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:61662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUK-615n1P-attmzCfwAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:44.421301 2026] [security2:error] [pid 915741:tid 915966] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TUK-615n1P-attmzCfQAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:44.845598 2026] [security2:error] [pid 915741:tid 915919] [client 14.225.17.146:52944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4TT6-615n1P-attmzCXgAAAb8"], referer: http://betterbonddogtraining.com/Wp
[Mon Jul 20 06:23:44.967496 2026] [security2:error] [pid 884009:tid 884033] [remote 167.233.114.32:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TUBKaHUf6J8d3elJ3VQAAsxY"]
[Mon Jul 20 06:23:44.978335 2026] [security2:error] [pid 915741:tid 915896] [client 103.141.108.143:58702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TUK-615n1P-attmzCqwAAAag"]
[Mon Jul 20 06:23:44.978658 2026] [security2:error] [pid 915741:tid 915896] [client 103.141.108.143:58702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TUK-615n1P-attmzCqwAAAag"]
[Mon Jul 20 06:23:45.157807 2026] [security2:error] [pid 884009:tid 884080] [remote 167.233.114.32:50308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TURKaHUf6J8d3elJ3XAAA4kU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:23:45.665154 2026] [security2:error] [pid 915741:tid 915908] [client 104.234.53.86:54673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TUa-615n1P-attmzCzAAAAbQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:45.690167 2026] [security2:error] [pid 884009:tid 884163] [client 45.116.69.230:58714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TURKaHUf6J8d3elJ3bAAAAJw"]
[Mon Jul 20 06:23:45.690286 2026] [security2:error] [pid 884009:tid 884163] [client 45.116.69.230:58714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TURKaHUf6J8d3elJ3bAAAAJw"]
[Mon Jul 20 06:23:45.890799 2026] [security2:error] [pid 884009:tid 884183] [client 103.153.183.69:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/nginx/nginx.conf"] [unique_id "al4TURKaHUf6J8d3elJ3bwAAAK8"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:23:46.103206 2026] [security2:error] [pid 884009:tid 884207] [client 103.153.183.69:64640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../etc/apache2/apache2.conf"] [unique_id "al4TUhKaHUf6J8d3elJ3cwAAAMc"], referer: https://t.co/321boh8yal
[Mon Jul 20 06:23:46.172654 2026] [security2:error] [pid 915741:tid 915895] [client 77.110.127.138:61669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUq-615n1P-attmzC7AAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:46.172801 2026] [security2:error] [pid 915741:tid 915895] [client 77.110.127.138:61669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TUq-615n1P-attmzC7AAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:46.229858 2026] [security2:error] [pid 884009:tid 884148] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4TUBKaHUf6J8d3elJ3RwAAAI0"]
[Mon Jul 20 06:23:46.337613 2026] [security2:error] [pid 915741:tid 915928] [client 18.140.64.130:65138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TUq-615n1P-attmzC9gAAAcg"]
[Mon Jul 20 06:23:46.337715 2026] [security2:error] [pid 915741:tid 915928] [client 18.140.64.130:65138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4TUq-615n1P-attmzC9gAAAcg"]
[Mon Jul 20 06:23:46.492533 2026] [security2:error] [pid 915741:tid 915955] [client 52.109.124.141:23937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TUq-615n1P-attmzC_wAAAeM"]
[Mon Jul 20 06:23:46.555733 2026] [security2:error] [pid 915741:tid 915933] [client 57.141.18.100:54152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TTq-615n1P-attmzCMQABzSc"]
[Mon Jul 20 06:23:46.556038 2026] [security2:error] [pid 884009:tid 884257] [client 57.141.18.75:20948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TThKaHUf6J8d3elJ3IAAA-Wg"]
[Mon Jul 20 06:23:46.558422 2026] [security2:error] [pid 884009:tid 884200] [client 77.110.127.138:61670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TUhKaHUf6J8d3elJ3dwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:46.590986 2026] [security2:error] [pid 884009:tid 884216] [client 14.225.17.146:55570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4TURKaHUf6J8d3elJ3ZQAAANA"], referer: http://nikkidesigns.net/Wp
[Mon Jul 20 06:23:46.673035 2026] [security2:error] [pid 915741:tid 915973] [client 52.109.124.141:23937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TUq-615n1P-attmzDCgAAAfU"]
[Mon Jul 20 06:23:47.137816 2026] [security2:error] [pid 915741:tid 915987] [client 57.141.18.107:25582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TT6-615n1P-attmzCVwACAzA"]
[Mon Jul 20 06:23:47.199442 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TUq-615n1P-attmzDGgAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:47.308485 2026] [proxy:error] [pid 915741:tid 915929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:47.308545 2026] [proxy_http:error] [pid 915741:tid 915929] [client 205.210.31.50:63080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:47.309045 2026] [proxy:error] [pid 915741:tid 915929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:23:47.309093 2026] [proxy_http:error] [pid 915741:tid 915929] [client 205.210.31.50:63080] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:23:47.359807 2026] [security2:error] [pid 915741:tid 915924] [client 50.116.65.227:21094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4TU6-615n1P-attmzDMwAAAcQ"]
[Mon Jul 20 06:23:47.452534 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TU6-615n1P-attmzDOgAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:47.452654 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:61674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TU6-615n1P-attmzDOgAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:47.580553 2026] [security2:error] [pid 915741:tid 915948] [client 14.225.17.146:60419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4TU6-615n1P-attmzDNgAAAdw"], referer: http://ivetstrategies.com/Wp
[Mon Jul 20 06:23:47.709820 2026] [security2:error] [pid 915741:tid 915846] [remote 57.141.18.75:33206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4TU6-615n1P-attmzDVQABuGg"]
[Mon Jul 20 06:23:47.816176 2026] [security2:error] [pid 915741:tid 915901] [client 41.173.37.102:14124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TU6-615n1P-attmzDWAAAAa0"]
[Mon Jul 20 06:23:47.816302 2026] [security2:error] [pid 915741:tid 915901] [client 41.173.37.102:14124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TU6-615n1P-attmzDWAAAAa0"]
[Mon Jul 20 06:23:47.857129 2026] [security2:error] [pid 915741:tid 915902] [client 50.116.65.227:21096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TU6-615n1P-attmzDWwAAAa4"]
[Mon Jul 20 06:23:47.868104 2026] [security2:error] [pid 915741:tid 915980] [client 50.116.65.227:59018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4TU6-615n1P-attmzDXAAAAfw"]
[Mon Jul 20 06:23:48.057251 2026] [core:error] [pid 915741:tid 915966] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.057275 2026] [core:error] [pid 915741:tid 915966] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.105326 2026] [core:error] [pid 915741:tid 915927] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.105354 2026] [core:error] [pid 915741:tid 915927] [client 157.52.92.28:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:23:48.135681 2026] [security2:error] [pid 915741:tid 915963] [client 52.109.108.111:20420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4TVK-615n1P-attmzDcgAAAes"]
[Mon Jul 20 06:23:48.160626 2026] [core:error] [pid 915741:tid 915992] [client 103.153.183.69:45564] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=9z8y2wxa&v=rwo8n), referer: https://www.reddit.com/
[Mon Jul 20 06:23:48.164033 2026] [security2:error] [pid 915741:tid 915974] [client 127.0.0.1:42028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TVK-615n1P-attmzDdwAAAfY"], referer: https://www.reddit.com/
[Mon Jul 20 06:23:48.206528 2026] [security2:error] [pid 884009:tid 884123] [remote 192.241.143.148:45028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nAAAjnA"]
[Mon Jul 20 06:23:48.206737 2026] [security2:error] [pid 884009:tid 884149] [client 192.241.143.148:45028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nAAAjnA"]
[Mon Jul 20 06:23:48.244912 2026] [security2:error] [pid 884009:tid 884221] [client 77.110.127.138:61679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.245031 2026] [security2:error] [pid 884009:tid 884221] [client 77.110.127.138:61679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVBKaHUf6J8d3elJ3nQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.294166 2026] [security2:error] [pid 915741:tid 915996] [client 52.109.108.111:20420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4TVK-615n1P-attmzDfQAAAgw"]
[Mon Jul 20 06:23:48.458049 2026] [lsapi:warn] [pid 915741:tid 915742] [remote 20.169.78.128:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:23:48.510257 2026] [security2:error] [pid 915741:tid 915934] [client 34.162.230.222:1376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDhgAAAc4"]
[Mon Jul 20 06:23:48.522026 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDgAAAAbo"]
[Mon Jul 20 06:23:48.522227 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDgAAAAbo"]
[Mon Jul 20 06:23:48.522262 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDgAAAAbo"]
[Mon Jul 20 06:23:48.628128 2026] [security2:error] [pid 915741:tid 915861] [remote 217.61.143.92:33988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TVK-615n1P-attmzDlwACBXc"]
[Mon Jul 20 06:23:48.864729 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDrQAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.864845 2026] [security2:error] [pid 915741:tid 915948] [client 77.110.127.138:61684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVK-615n1P-attmzDrQAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:48.882391 2026] [security2:error] [pid 915741:tid 915802] [remote 57.141.18.116:31530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4TVK-615n1P-attmzDqgABvTw"]
[Mon Jul 20 06:23:48.922888 2026] [security2:error] [pid 915741:tid 915783] [remote 217.61.143.92:33988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TVK-615n1P-attmzDtgACByk"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:23:48.954839 2026] [security2:error] [pid 884009:tid 884151] [client 57.141.18.80:27936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TURKaHUf6J8d3elJ3XgAAkBs"]
[Mon Jul 20 06:23:49.189273 2026] [security2:error] [pid 915741:tid 915929] [client 14.225.17.146:50186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDdQAAAck"], referer: http://ancestralidadytrance.space/Wp
[Mon Jul 20 06:23:49.191114 2026] [security2:error] [pid 884009:tid 884140] [client 57.141.18.80:27950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TURKaHUf6J8d3elJ3awAAhUI"]
[Mon Jul 20 06:23:49.239447 2026] [security2:error] [pid 915741:tid 915926] [client 14.225.17.146:50129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDfgAAAcY"], referer: http://techtradeinc.com/Wp
[Mon Jul 20 06:23:49.465728 2026] [security2:error] [pid 915741:tid 915944] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVa-615n1P-attmzDvgAAAdg"]
[Mon Jul 20 06:23:49.465947 2026] [security2:error] [pid 915741:tid 915944] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVa-615n1P-attmzDvgAAAdg"]
[Mon Jul 20 06:23:49.465985 2026] [security2:error] [pid 915741:tid 915944] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVa-615n1P-attmzDvgAAAdg"]
[Mon Jul 20 06:23:49.481702 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.107:25590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TUa-615n1P-attmzC2wACBA4"]
[Mon Jul 20 06:23:49.639781 2026] [security2:error] [pid 915741:tid 915849] [remote 173.212.252.15:35024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TVa-615n1P-attmzDzgAB42s"]
[Mon Jul 20 06:23:49.789845 2026] [security2:error] [pid 884009:tid 884262] [client 112.208.70.94:44012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TVRKaHUf6J8d3elJ3vwAAAP4"]
[Mon Jul 20 06:23:49.789956 2026] [security2:error] [pid 884009:tid 884262] [client 112.208.70.94:44012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TVRKaHUf6J8d3elJ3vwAAAP4"]
[Mon Jul 20 06:23:49.838883 2026] [security2:error] [pid 915741:tid 915844] [remote 173.212.252.15:35024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TVa-615n1P-attmzD1QAB9mY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:23:49.876529 2026] [security2:error] [pid 884009:tid 884198] [client 57.141.18.106:22104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TUhKaHUf6J8d3elJ3dgAAvnM"]
[Mon Jul 20 06:23:50.057465 2026] [security2:error] [pid 915741:tid 915953] [client 14.225.17.146:60403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDpAAAAeE"], referer: http://mazzucelli.com/Wp
[Mon Jul 20 06:23:50.349167 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD_AAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.349268 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:61689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD_AAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.363474 2026] [security2:error] [pid 915741:tid 915774] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVq-615n1P-attmzD_QAB_iA"]
[Mon Jul 20 06:23:50.363699 2026] [security2:error] [pid 915741:tid 915982] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVq-615n1P-attmzD_QAB_iA"]
[Mon Jul 20 06:23:50.374210 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD8gAAAbo"]
[Mon Jul 20 06:23:50.374393 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD8gAAAbo"]
[Mon Jul 20 06:23:50.374427 2026] [security2:error] [pid 915741:tid 915914] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzD8gAAAbo"]
[Mon Jul 20 06:23:50.511530 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzECwAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.511639 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TVq-615n1P-attmzECwAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.623275 2026] [security2:error] [pid 915741:tid 915976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TVq-615n1P-attmzEAwAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:50.639183 2026] [security2:error] [pid 915741:tid 915944] [client 158.173.166.181:42867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TVq-615n1P-attmzEEAAAAdg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:50.699456 2026] [security2:error] [pid 915741:tid 915986] [client 14.225.17.146:60465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4TVK-615n1P-attmzDnQAAAgI"], referer: http://floorsourcestock.com/Wp
[Mon Jul 20 06:23:51.214368 2026] [security2:error] [pid 915741:tid 915763] [remote 173.212.252.15:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TV6-615n1P-attmzELgABoBU"]
[Mon Jul 20 06:23:51.363582 2026] [security2:error] [pid 884009:tid 884243] [client 171.61.165.146:25152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVxKaHUf6J8d3elJ37wAAAOs"]
[Mon Jul 20 06:23:51.363738 2026] [security2:error] [pid 884009:tid 884243] [client 171.61.165.146:25152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TVxKaHUf6J8d3elJ37wAAAOs"]
[Mon Jul 20 06:23:51.403975 2026] [security2:error] [pid 915741:tid 915866] [remote 173.212.252.15:56352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4TV6-615n1P-attmzEPQABknw"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:23:51.404368 2026] [security2:error] [pid 915741:tid 915889] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEKgAAAaE"]
[Mon Jul 20 06:23:51.404509 2026] [security2:error] [pid 915741:tid 915889] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEKgAAAaE"]
[Mon Jul 20 06:23:51.404542 2026] [security2:error] [pid 915741:tid 915889] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEKgAAAaE"]
[Mon Jul 20 06:23:51.955614 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEWQAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:51.955707 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TV6-615n1P-attmzEWQAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:52.055733 2026] [security2:error] [pid 915741:tid 915954] [client 50.116.65.227:60128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TWK-615n1P-attmzEXwAAAeI"]
[Mon Jul 20 06:23:52.066897 2026] [security2:error] [pid 915741:tid 915933] [client 50.116.65.227:60132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TWK-615n1P-attmzEYgAAAc0"]
[Mon Jul 20 06:23:52.348716 2026] [security2:error] [pid 915741:tid 915995] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWK-615n1P-attmzEaAAAAgs"]
[Mon Jul 20 06:23:52.348921 2026] [security2:error] [pid 915741:tid 915995] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWK-615n1P-attmzEaAAAAgs"]
[Mon Jul 20 06:23:52.348956 2026] [security2:error] [pid 915741:tid 915995] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWK-615n1P-attmzEaAAAAgs"]
[Mon Jul 20 06:23:52.436854 2026] [fcgid:warn] [pid 915741:tid 915968] (70014)End of file found: [client 66.132.172.216:49484] mod_fcgid: can't get data from http client
[Mon Jul 20 06:23:52.458157 2026] [security2:error] [pid 884009:tid 884191] [client 57.141.18.91:20964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVRKaHUf6J8d3elJ3rQAAtxw"]
[Mon Jul 20 06:23:52.497325 2026] [security2:error] [pid 915741:tid 915927] [client 14.225.17.146:49855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4TVq-615n1P-attmzEEwAAAcc"], referer: http://tacticaltreeoperations.com/Wp
[Mon Jul 20 06:23:52.667800 2026] [security2:error] [pid 915741:tid 915986] [client 50.116.65.227:60150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TWK-615n1P-attmzEewAAAgI"]
[Mon Jul 20 06:23:52.750435 2026] [security2:error] [pid 884009:tid 884263] [client 14.225.17.146:55583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4TVxKaHUf6J8d3elJ37QAAAP8"], referer: http://bnb-engineering.com/Wp
[Mon Jul 20 06:23:52.835946 2026] [security2:error] [pid 915741:tid 915967] [client 104.234.53.90:25543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TWK-615n1P-attmzEiAAAAe8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:52.856990 2026] [security2:error] [pid 884009:tid 884144] [client 50.116.65.227:60164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TWBKaHUf6J8d3elJ4FQAAAIk"]
[Mon Jul 20 06:23:53.120994 2026] [security2:error] [pid 884009:tid 884195] [client 77.110.127.138:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWRKaHUf6J8d3elJ4HQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:53.121161 2026] [security2:error] [pid 884009:tid 884195] [client 77.110.127.138:61695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWRKaHUf6J8d3elJ4HQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:53.264392 2026] [security2:error] [pid 884009:tid 884121] [remote 147.50.252.213:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4TWRKaHUf6J8d3elJ4HwAA824"]
[Mon Jul 20 06:23:53.280806 2026] [security2:error] [pid 915741:tid 915997] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWa-615n1P-attmzElAAAAg0"]
[Mon Jul 20 06:23:53.280969 2026] [security2:error] [pid 915741:tid 915997] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWa-615n1P-attmzElAAAAg0"]
[Mon Jul 20 06:23:53.281004 2026] [security2:error] [pid 915741:tid 915997] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWa-615n1P-attmzElAAAAg0"]
[Mon Jul 20 06:23:53.521870 2026] [security2:error] [pid 915741:tid 915767] [remote 81.173.115.7:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4TWa-615n1P-attmzEsgABkRk"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:23:53.632461 2026] [security2:error] [pid 915741:tid 915813] [remote 152.228.213.32:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4TWa-615n1P-attmzEtAAB7Uc"]
[Mon Jul 20 06:23:53.769598 2026] [security2:error] [pid 915741:tid 915943] [client 104.234.53.49:55791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TWa-615n1P-attmzEwAAAAdc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:53.773534 2026] [security2:error] [pid 884009:tid 884034] [remote 147.50.252.213:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4TWRKaHUf6J8d3elJ4KAAArxc"], referer: https://supportinghands22.org/wp-login.php
[Mon Jul 20 06:23:54.030120 2026] [security2:error] [pid 915741:tid 915937] [client 57.141.18.89:41516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVq-615n1P-attmzEDAAB0RE"]
[Mon Jul 20 06:23:54.309204 2026] [security2:error] [pid 915741:tid 915996] [client 171.60.139.123:50235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TWq-615n1P-attmzE4wAAAgw"]
[Mon Jul 20 06:23:54.309322 2026] [security2:error] [pid 915741:tid 915996] [client 171.60.139.123:50235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TWq-615n1P-attmzE4wAAAgw"]
[Mon Jul 20 06:23:54.324170 2026] [security2:error] [pid 915741:tid 915970] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWq-615n1P-attmzE1AAAAfI"]
[Mon Jul 20 06:23:54.324326 2026] [security2:error] [pid 915741:tid 915970] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWq-615n1P-attmzE1AAAAfI"]
[Mon Jul 20 06:23:54.324358 2026] [security2:error] [pid 915741:tid 915970] [client 124.217.14.133:49940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4TWq-615n1P-attmzE1AAAAfI"]
[Mon Jul 20 06:23:54.367791 2026] [security2:error] [pid 884009:tid 884186] [client 57.141.18.2:40598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVhKaHUf6J8d3elJ34QAAsnU"]
[Mon Jul 20 06:23:54.484048 2026] [security2:error] [pid 915741:tid 915859] [remote 81.173.115.7:52852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4TWq-615n1P-attmzE8QAB3nU"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:23:54.584634 2026] [security2:error] [pid 884009:tid 884187] [client 77.110.127.138:61699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWhKaHUf6J8d3elJ4OgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:54.584728 2026] [security2:error] [pid 884009:tid 884187] [client 77.110.127.138:61699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWhKaHUf6J8d3elJ4OgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:54.654662 2026] [security2:error] [pid 915741:tid 915864] [remote 152.228.213.32:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4TWq-615n1P-attmzE9QABxno"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:23:55.001213 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWxKaHUf6J8d3elJ4TAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:55.001317 2026] [security2:error] [pid 884009:tid 884203] [client 77.110.127.138:61701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TWxKaHUf6J8d3elJ4TAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:55.510244 2026] [security2:error] [pid 884009:tid 884175] [client 57.141.18.70:24868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TVxKaHUf6J8d3elJ4BQAApwo"]
[Mon Jul 20 06:23:55.666218 2026] [security2:error] [pid 915741:tid 915874] [client 103.141.108.143:59264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TW6-615n1P-attmzFIgAAAZI"]
[Mon Jul 20 06:23:55.666336 2026] [security2:error] [pid 915741:tid 915874] [client 103.141.108.143:59264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TW6-615n1P-attmzFIgAAAZI"]
[Mon Jul 20 06:23:55.669341 2026] [security2:error] [pid 915741:tid 915979] [client 57.141.18.37:54954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWK-615n1P-attmzEbgAB-2Q"]
[Mon Jul 20 06:23:55.861896 2026] [security2:error] [pid 884009:tid 884103] [remote 100.42.189.89:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TWxKaHUf6J8d3elJ4ZQAAr1w"]
[Mon Jul 20 06:23:56.071364 2026] [security2:error] [pid 884009:tid 884045] [remote 100.42.189.89:58726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TXBKaHUf6J8d3elJ4aAAAwSI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:23:56.294943 2026] [security2:error] [pid 915741:tid 915975] [client 45.116.69.230:59229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFSwAAAfc"]
[Mon Jul 20 06:23:56.295047 2026] [security2:error] [pid 915741:tid 915975] [client 45.116.69.230:59229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFSwAAAfc"]
[Mon Jul 20 06:23:56.454966 2026] [security2:error] [pid 915741:tid 915956] [client 178.152.178.232:35955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFUwAAAeQ"]
[Mon Jul 20 06:23:56.455088 2026] [security2:error] [pid 915741:tid 915956] [client 178.152.178.232:35955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TXK-615n1P-attmzFUwAAAeQ"]
[Mon Jul 20 06:23:57.031628 2026] [security2:error] [pid 915741:tid 915898] [client 57.141.18.23:28370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWa-615n1P-attmzEsQABqkM"]
[Mon Jul 20 06:23:57.268254 2026] [security2:error] [pid 915741:tid 915955] [client 14.225.17.146:50478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4TW6-615n1P-attmzFLwAAAeM"], referer: http://omrobuildingcenter.com/Wp
[Mon Jul 20 06:23:57.342774 2026] [security2:error] [pid 884009:tid 884096] [remote 57.141.18.74:22978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4TXRKaHUf6J8d3elJ4iwAAvVU"]
[Mon Jul 20 06:23:57.437810 2026] [security2:error] [pid 884009:tid 884258] [client 14.225.17.146:50465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4TWxKaHUf6J8d3elJ4YwAAAPo"], referer: http://careysheatingandcooling.com/Wp
[Mon Jul 20 06:23:57.564855 2026] [security2:error] [pid 915741:tid 915912] [client 57.141.18.96:62746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWq-615n1P-attmzE1wABuAg"]
[Mon Jul 20 06:23:57.784856 2026] [security2:error] [pid 915741:tid 915922] [client 50.116.65.227:50364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TXa-615n1P-attmzFnAAAAcI"]
[Mon Jul 20 06:23:57.794606 2026] [security2:error] [pid 915741:tid 915876] [client 50.116.65.227:60210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TXa-615n1P-attmzFnQAAAZQ"]
[Mon Jul 20 06:23:57.828396 2026] [security2:error] [pid 915741:tid 915916] [client 50.116.65.227:60226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/09/IMG_7359-1-scaled.jpeg"] [unique_id "al4TXa-615n1P-attmzFoAAAAbw"]
[Mon Jul 20 06:23:57.940410 2026] [security2:error] [pid 884009:tid 884204] [client 57.141.18.28:44258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWhKaHUf6J8d3elJ4OQAAxHo"]
[Mon Jul 20 06:23:58.116882 2026] [security2:error] [pid 884009:tid 884191] [client 57.141.18.22:48574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWhKaHUf6J8d3elJ4QgAAtx0"]
[Mon Jul 20 06:23:58.179474 2026] [security2:error] [pid 884009:tid 884244] [client 158.173.89.95:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TXhKaHUf6J8d3elJ4mAAAAOw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:23:58.464502 2026] [security2:error] [pid 915741:tid 915944] [client 41.173.37.102:14555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TXq-615n1P-attmzFvwAAAdg"]
[Mon Jul 20 06:23:58.464609 2026] [security2:error] [pid 915741:tid 915944] [client 41.173.37.102:14555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TXq-615n1P-attmzFvwAAAdg"]
[Mon Jul 20 06:23:58.611016 2026] [security2:error] [pid 884009:tid 884150] [client 104.234.53.69:59111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TXhKaHUf6J8d3elJ4oQAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:58.678853 2026] [security2:error] [pid 915741:tid 915898] [client 14.224.227.113:55729] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4TXq-615n1P-attmzF0QAAAao"]
[Mon Jul 20 06:23:59.153399 2026] [security2:error] [pid 884009:tid 884257] [client 57.141.18.113:50636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TWxKaHUf6J8d3elJ4YQAA-UY"]
[Mon Jul 20 06:23:59.451957 2026] [security2:error] [pid 915741:tid 915966] [client 14.225.17.146:56810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4TX6-615n1P-attmzF6wAAAe4"], referer: http://myspineworld.com/Wp
[Mon Jul 20 06:23:59.542488 2026] [security2:error] [pid 915741:tid 915897] [client 14.225.17.146:56762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFrwAAAak"], referer: http://colinkeyphotography.com/Wp
[Mon Jul 20 06:23:59.619791 2026] [security2:error] [pid 884009:tid 884203] [client 104.234.53.69:59111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TXxKaHUf6J8d3elJ4uwAAAMM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:23:59.831724 2026] [security2:error] [pid 915741:tid 915910] [client 57.141.18.16:28518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXK-615n1P-attmzFUQABtl0"]
[Mon Jul 20 06:23:59.861875 2026] [security2:error] [pid 915741:tid 915988] [client 14.225.17.146:54162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFuAAAAgQ"], referer: http://709fx.com/Wp
[Mon Jul 20 06:23:59.969405 2026] [security2:error] [pid 884009:tid 884172] [client 77.110.127.138:61711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TXxKaHUf6J8d3elJ4yAAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:23:59.969508 2026] [security2:error] [pid 884009:tid 884172] [client 77.110.127.138:61711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TXxKaHUf6J8d3elJ4yAAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.229710 2026] [autoindex:error] [pid 915741:tid 915965] [client 185.132.186.76:45851] AH01276: Cannot serve directory /var/www/html/.well-known/acme-challenge/: No matching DirectoryIndex (index.cgi,index.php,index.html,index.htm) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:00.327668 2026] [security2:error] [pid 915741:tid 915905] [client 57.141.18.110:25928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXK-615n1P-attmzFaAABsXM"]
[Mon Jul 20 06:24:00.384478 2026] [security2:error] [pid 884009:tid 884149] [client 14.225.17.146:54226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ40QAAAI4"], referer: http://lelandumc.org/Wp
[Mon Jul 20 06:24:00.449666 2026] [security2:error] [pid 884009:tid 884197] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ4ywAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.555395 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.48:20282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXa-615n1P-attmzFgwAB-iQ"]
[Mon Jul 20 06:24:00.635372 2026] [security2:error] [pid 884009:tid 884210] [client 14.225.17.146:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ40wAAAMo"], referer: https://myspineworld.com/Wp
[Mon Jul 20 06:24:00.851669 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TYK-615n1P-attmzGQwAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.851805 2026] [security2:error] [pid 915741:tid 915893] [client 77.110.127.138:61731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TYK-615n1P-attmzGQwAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:00.969133 2026] [security2:error] [pid 915741:tid 915833] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TYK-615n1P-attmzGRwACBFs"]
[Mon Jul 20 06:24:00.969715 2026] [security2:error] [pid 915741:tid 915988] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TYK-615n1P-attmzGRwACBFs"]
[Mon Jul 20 06:24:00.976928 2026] [security2:error] [pid 884009:tid 884146] [client 186.14.157.105:33354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4TYBKaHUf6J8d3elJ44AAAAIs"]
[Mon Jul 20 06:24:01.302499 2026] [security2:error] [pid 915741:tid 915941] [client 57.141.18.116:24492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFrAAB1XI"]
[Mon Jul 20 06:24:01.320998 2026] [core:error] [pid 915741:tid 915918] [client 103.153.183.69:8928] AH10244: invalid URI path (/%2e./%2e./.env?_=y4j0cls5&v=7oqmy), referer: https://t.co/tryd7mbc7q
[Mon Jul 20 06:24:01.579909 2026] [security2:error] [pid 915741:tid 915768] [remote 193.70.112.205:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4TYa-615n1P-attmzGagABuxo"]
[Mon Jul 20 06:24:01.673698 2026] [security2:error] [pid 884009:tid 884260] [client 50.116.65.227:54548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TYRKaHUf6J8d3elJ49wAAAPw"]
[Mon Jul 20 06:24:01.684406 2026] [security2:error] [pid 884009:tid 884142] [client 50.116.65.227:54550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TYRKaHUf6J8d3elJ4-AAAAIc"]
[Mon Jul 20 06:24:01.733433 2026] [security2:error] [pid 884009:tid 884177] [client 57.141.18.80:20572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXhKaHUf6J8d3elJ4ngAAqUw"]
[Mon Jul 20 06:24:01.733565 2026] [security2:error] [pid 915741:tid 915931] [client 57.141.18.24:32276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TXq-615n1P-attmzFwAAByzM"]
[Mon Jul 20 06:24:01.799810 2026] [security2:error] [pid 884009:tid 884173] [client 57.141.18.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TYRKaHUf6J8d3elJ49QAAAKU"]
[Mon Jul 20 06:24:01.822830 2026] [security2:error] [pid 915741:tid 915804] [remote 193.70.112.205:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4TYa-615n1P-attmzGcAABmD4"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:24:02.417802 2026] [security2:error] [pid 915741:tid 915935] [client 57.141.18.60:25710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TX6-615n1P-attmzF7QABz2g"]
[Mon Jul 20 06:24:02.615280 2026] [security2:error] [pid 915741:tid 915950] [client 14.225.17.146:54321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4TYa-615n1P-attmzGTQAAAd4"], referer: http://amalia-capital.com/Wp
[Mon Jul 20 06:24:02.855715 2026] [security2:error] [pid 884009:tid 884089] [remote 72.167.132.114:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TYhKaHUf6J8d3elJ5IQAA1E4"]
[Mon Jul 20 06:24:03.065154 2026] [security2:error] [pid 884009:tid 884092] [remote 72.167.132.114:36870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TYxKaHUf6J8d3elJ5JwAAvlE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:03.149007 2026] [security2:error] [pid 915741:tid 915986] [client 104.234.53.69:59749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TY6-615n1P-attmzGqQAAAgI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:03.493322 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGwAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.493401 2026] [security2:error] [pid 915741:tid 915890] [client 77.110.127.138:61753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGwAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.646574 2026] [security2:error] [pid 884009:tid 884194] [client 77.110.127.138:61761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/charity/"] [unique_id "al4TYxKaHUf6J8d3elJ5NAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.766348 2026] [security2:error] [pid 915741:tid 915889] [client 57.141.18.124:60992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYK-615n1P-attmzGNgABoT8"]
[Mon Jul 20 06:24:03.806827 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGzQAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.806936 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TY6-615n1P-attmzGzQAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:03.813373 2026] [security2:error] [pid 915741:tid 915964] [client 114.119.140.113:60039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nextbit.mx"] [uri "/robots.txt"] [unique_id "al4TY6-615n1P-attmzGzgAAAew"], referer: https://www.nextbit.mx/robots.txt
[Mon Jul 20 06:24:03.896341 2026] [autoindex:error] [pid 915741:tid 915936] [client 199.45.155.104:48698] AH01276: Cannot serve directory /home4/gpmvvomy/funnels.allandbeckson.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:04.075279 2026] [security2:error] [pid 915741:tid 915898] [client 171.61.165.146:18147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TZK-615n1P-attmzG5AAAAao"]
[Mon Jul 20 06:24:04.075405 2026] [security2:error] [pid 915741:tid 915898] [client 171.61.165.146:18147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TZK-615n1P-attmzG5AAAAao"]
[Mon Jul 20 06:24:04.157154 2026] [security2:error] [pid 915741:tid 915990] [client 104.234.53.69:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TZK-615n1P-attmzG5gAAAgY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:04.441328 2026] [security2:error] [pid 915741:tid 915937] [client 57.141.18.7:50840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYa-615n1P-attmzGWQAB0WA"]
[Mon Jul 20 06:24:04.742417 2026] [security2:error] [pid 884009:tid 884192] [client 57.141.18.69:49796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYRKaHUf6J8d3elJ47wAAuGw"]
[Mon Jul 20 06:24:05.107351 2026] [security2:error] [pid 915741:tid 915927] [client 171.60.139.123:50879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHGwAAAcc"]
[Mon Jul 20 06:24:05.107503 2026] [security2:error] [pid 915741:tid 915927] [client 171.60.139.123:50879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHGwAAAcc"]
[Mon Jul 20 06:24:05.122976 2026] [security2:error] [pid 915741:tid 915853] [remote 95.217.78.234:48816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4TZa-615n1P-attmzHHAABu28"]
[Mon Jul 20 06:24:05.282578 2026] [security2:error] [pid 884009:tid 884161] [client 50.116.65.227:32758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4TZRKaHUf6J8d3elJ5WwAAAJo"]
[Mon Jul 20 06:24:05.292984 2026] [security2:error] [pid 884009:tid 884251] [client 50.116.65.227:54610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/BabaChew-Feature-Image.jpg"] [unique_id "al4TZRKaHUf6J8d3elJ5XAAAAMg"]
[Mon Jul 20 06:24:05.429632 2026] [security2:error] [pid 915741:tid 915843] [remote 113.160.142.119:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4TZa-615n1P-attmzHLQAB92U"]
[Mon Jul 20 06:24:05.760937 2026] [security2:error] [pid 915741:tid 915752] [remote 95.217.78.234:48816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4TZa-615n1P-attmzHPAACCQo"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:24:05.769979 2026] [security2:error] [pid 884009:tid 884074] [remote 162.19.86.63:37816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZRKaHUf6J8d3elJ5awAArj8"]
[Mon Jul 20 06:24:05.770155 2026] [security2:error] [pid 884009:tid 884182] [client 162.19.86.63:37816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZRKaHUf6J8d3elJ5awAArj8"]
[Mon Jul 20 06:24:05.823797 2026] [security2:error] [pid 915741:tid 915994] [client 50.116.65.227:32766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TZa-615n1P-attmzHQgAAAgo"]
[Mon Jul 20 06:24:05.833942 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.59:45862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYq-615n1P-attmzGkAAB7VU"]
[Mon Jul 20 06:24:05.834687 2026] [security2:error] [pid 915741:tid 915990] [client 50.116.65.227:54634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4TZa-615n1P-attmzHQwAAAbM"]
[Mon Jul 20 06:24:05.900599 2026] [security2:error] [pid 915741:tid 915897] [client 57.141.18.45:53300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYq-615n1P-attmzGlQABqR8"]
[Mon Jul 20 06:24:05.902482 2026] [security2:error] [pid 884009:tid 884211] [client 57.141.18.108:25608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TYhKaHUf6J8d3elJ5FwAAyxA"]
[Mon Jul 20 06:24:05.966896 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:44431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHTAAAAeI"]
[Mon Jul 20 06:24:05.967048 2026] [security2:error] [pid 915741:tid 915954] [client 112.208.70.94:44431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TZa-615n1P-attmzHTAAAAeI"]
[Mon Jul 20 06:24:06.034697 2026] [security2:error] [pid 915741:tid 915794] [remote 113.160.142.119:52642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4TZq-615n1P-attmzHUwABsTQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:24:06.300700 2026] [security2:error] [pid 915741:tid 915892] [client 103.141.108.143:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TZq-615n1P-attmzHYwAAAaQ"]
[Mon Jul 20 06:24:06.300890 2026] [security2:error] [pid 915741:tid 915892] [client 103.141.108.143:59741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TZq-615n1P-attmzHYwAAAaQ"]
[Mon Jul 20 06:24:06.767642 2026] [security2:error] [pid 884009:tid 884165] [client 178.152.178.232:36725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.178.152.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hAAAAJ4"]
[Mon Jul 20 06:24:06.767791 2026] [security2:error] [pid 884009:tid 884165] [client 178.152.178.232:36725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hAAAAJ4"]
[Mon Jul 20 06:24:06.832807 2026] [security2:error] [pid 884009:tid 884174] [client 77.110.127.138:61797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:06.832940 2026] [security2:error] [pid 884009:tid 884174] [client 77.110.127.138:61797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZhKaHUf6J8d3elJ5hQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:06.985015 2026] [security2:error] [pid 915741:tid 915988] [client 77.110.127.138:61798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/charity/"] [unique_id "al4TZq-615n1P-attmzHfQAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:07.044286 2026] [security2:error] [pid 915741:tid 915976] [client 57.141.18.105:37590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TY6-615n1P-attmzG3AAB-DY"]
[Mon Jul 20 06:24:07.131851 2026] [security2:error] [pid 915741:tid 915967] [client 57.141.18.13:33466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TY6-615n1P-attmzG4gAB730"]
[Mon Jul 20 06:24:07.136432 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZ6-615n1P-attmzHiAAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:07.136545 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TZ6-615n1P-attmzHiAAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:07.286284 2026] [security2:error] [pid 915741:tid 915840] [remote 47.86.33.52:32160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TZ6-615n1P-attmzHkgAB2WI"]
[Mon Jul 20 06:24:07.701543 2026] [security2:error] [pid 884009:tid 884202] [client 68.235.52.68:43800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TZxKaHUf6J8d3elJ5mgAAAMI"]
[Mon Jul 20 06:24:07.701685 2026] [security2:error] [pid 884009:tid 884202] [client 68.235.52.68:43800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TZxKaHUf6J8d3elJ5mgAAAMI"]
[Mon Jul 20 06:24:07.739432 2026] [security2:error] [pid 915741:tid 915871] [client 104.234.53.93:52259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TZ6-615n1P-attmzHpQAAAY8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:07.858279 2026] [security2:error] [pid 915741:tid 915952] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4TZ6-615n1P-attmzHpwAAAeA"]
[Mon Jul 20 06:24:07.859254 2026] [security2:error] [pid 915741:tid 915757] [remote 100.42.189.89:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHrAABoA8"]
[Mon Jul 20 06:24:07.859438 2026] [security2:error] [pid 915741:tid 915888] [client 100.42.189.89:45596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHrAABoA8"]
[Mon Jul 20 06:24:07.954137 2026] [security2:error] [pid 915741:tid 915928] [client 45.116.69.230:59770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHswAAAcg"]
[Mon Jul 20 06:24:07.954260 2026] [security2:error] [pid 915741:tid 915928] [client 45.116.69.230:59770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TZ6-615n1P-attmzHswAAAcg"]
[Mon Jul 20 06:24:08.316149 2026] [security2:error] [pid 915741:tid 915987] [client 190.114.42.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4TaK-615n1P-attmzHuwAAAgM"]
[Mon Jul 20 06:24:08.544625 2026] [security2:error] [pid 915741:tid 915998] [client 163.172.166.82:50320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4TaK-615n1P-attmzHyQAAAg4"]
[Mon Jul 20 06:24:08.659735 2026] [security2:error] [pid 915741:tid 915992] [client 57.141.18.20:57998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZa-615n1P-attmzHOQACCEc"]
[Mon Jul 20 06:24:08.734990 2026] [security2:error] [pid 915741:tid 915995] [client 47.128.47.111:43426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/robots.txt"] [unique_id "al4TaK-615n1P-attmzH2wAAAgs"]
[Mon Jul 20 06:24:08.996440 2026] [security2:error] [pid 884009:tid 884236] [client 57.141.18.81:38444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZhKaHUf6J8d3elJ5dQAA5Dk"]
[Mon Jul 20 06:24:09.024276 2026] [autoindex:error] [pid 915741:tid 915954] [client 104.168.28.15:40074] AH01276: Cannot serve directory /home2/hsdrromy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:09.032926 2026] [security2:error] [pid 884009:tid 884164] [client 41.173.37.102:14984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TaRKaHUf6J8d3elJ5vgAAAJ0"]
[Mon Jul 20 06:24:09.033080 2026] [security2:error] [pid 884009:tid 884164] [client 41.173.37.102:14984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TaRKaHUf6J8d3elJ5vgAAAJ0"]
[Mon Jul 20 06:24:09.093981 2026] [security2:error] [pid 884009:tid 884219] [client 114.119.134.106:64127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musichaven.info"] [uri "/category/research/"] [unique_id "al4TaRKaHUf6J8d3elJ5wAAAANM"], referer: https://www.musichaven.info/how-music-therapy-helps-women-suffering-from-domestic-violence/
[Mon Jul 20 06:24:09.094591 2026] [security2:error] [pid 915741:tid 915754] [remote 103.255.134.61:55604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4Taa-615n1P-attmzH6AABvQw"]
[Mon Jul 20 06:24:09.252083 2026] [security2:error] [pid 915741:tid 915943] [client 57.141.18.48:44292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZq-615n1P-attmzHZgAB13s"]
[Mon Jul 20 06:24:09.332401 2026] [security2:error] [pid 915741:tid 915938] [client 103.175.18.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Taa-615n1P-attmzH6QAB0kM"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91iron-knight-studio-escala-1-6-kamado-nezuko/
[Mon Jul 20 06:24:09.915953 2026] [security2:error] [pid 915741:tid 915834] [remote 47.86.33.52:32160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Taa-615n1P-attmzIEwABrlw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:10.363470 2026] [security2:error] [pid 884009:tid 884153] [client 57.141.18.116:30192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZxKaHUf6J8d3elJ5kgAAkhE"]
[Mon Jul 20 06:24:10.704502 2026] [security2:error] [pid 915741:tid 915927] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.epu.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4TZa-615n1P-attmzHTwAAAcc"]
[Mon Jul 20 06:24:10.734702 2026] [security2:error] [pid 884009:tid 884211] [client 77.110.127.138:61840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TahKaHUf6J8d3elJ57wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:10.734805 2026] [security2:error] [pid 884009:tid 884211] [client 77.110.127.138:61840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TahKaHUf6J8d3elJ57wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:10.736414 2026] [security2:error] [pid 915741:tid 915978] [client 57.141.18.17:36076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZ6-615n1P-attmzHsgAB-jM"]
[Mon Jul 20 06:24:10.793673 2026] [security2:error] [pid 915741:tid 915910] [client 98.159.234.160:25997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Taq-615n1P-attmzIRgAAAbY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:10.807626 2026] [security2:error] [pid 915741:tid 915975] [client 57.141.18.19:34988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TZ6-615n1P-attmzHtAAB9zI"]
[Mon Jul 20 06:24:10.896032 2026] [security2:error] [pid 915741:tid 915971] [client 77.110.127.138:61842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Taq-615n1P-attmzISAAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:10.896143 2026] [security2:error] [pid 915741:tid 915971] [client 77.110.127.138:61842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Taq-615n1P-attmzISAAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:11.048527 2026] [security2:error] [pid 915741:tid 915912] [client 77.110.127.138:61843] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/charity/"] [unique_id "al4Ta6-615n1P-attmzITAAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:11.336823 2026] [security2:error] [pid 915741:tid 915872] [client 66.249.89.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4Ta6-615n1P-attmzIUgABkE8"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91kawaii-studio-escala-1-6-fern-2/
[Mon Jul 20 06:24:11.582302 2026] [security2:error] [pid 884009:tid 884134] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TaxKaHUf6J8d3elJ5_wAA8ns"]
[Mon Jul 20 06:24:11.582458 2026] [security2:error] [pid 884009:tid 884250] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TaxKaHUf6J8d3elJ5_wAA8ns"]
[Mon Jul 20 06:24:11.862474 2026] [security2:error] [pid 915741:tid 915949] [client 57.141.18.26:47406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taa-615n1P-attmzH4wAB3UA"]
[Mon Jul 20 06:24:11.914564 2026] [security2:error] [pid 915741:tid 915876] [client 104.234.53.71:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Ta6-615n1P-attmzIiAAAAZQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:11.917158 2026] [security2:error] [pid 884009:tid 884087] [remote 152.228.213.32:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TaxKaHUf6J8d3elJ6FQAApUw"]
[Mon Jul 20 06:24:12.115559 2026] [security2:error] [pid 884009:tid 884031] [remote 152.228.213.32:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TbBKaHUf6J8d3elJ6HgAArxQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:12.262608 2026] [security2:error] [pid 915741:tid 915913] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.factsandminds.com"] [uri "/index.php"] [unique_id "al4Taq-615n1P-attmzIMAAAAbk"]
[Mon Jul 20 06:24:12.313539 2026] [security2:error] [pid 884009:tid 884181] [client 50.116.65.227:24306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TbBKaHUf6J8d3elJ6JQAAAK0"]
[Mon Jul 20 06:24:12.323799 2026] [security2:error] [pid 915741:tid 915976] [client 50.116.65.227:24312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TbK-615n1P-attmzImQAAAfg"]
[Mon Jul 20 06:24:12.463239 2026] [security2:error] [pid 915741:tid 915857] [remote 20.153.140.50:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzIowAB4HM"]
[Mon Jul 20 06:24:12.669898 2026] [security2:error] [pid 915741:tid 915931] [client 57.141.18.54:21132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taa-615n1P-attmzIEAAByz8"]
[Mon Jul 20 06:24:12.748116 2026] [security2:error] [pid 915741:tid 915744] [remote 100.42.189.89:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzItwAB5QI"]
[Mon Jul 20 06:24:12.871870 2026] [security2:error] [pid 915741:tid 915840] [remote 20.153.140.50:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzIwwABp2I"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:12.960678 2026] [security2:error] [pid 915741:tid 915803] [remote 100.42.189.89:58960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TbK-615n1P-attmzIzAACAz0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:13.109595 2026] [security2:error] [pid 915741:tid 915920] [client 57.141.18.123:30486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taq-615n1P-attmzILAABwBs"]
[Mon Jul 20 06:24:13.215435 2026] [security2:error] [pid 915741:tid 915915] [client 50.116.65.227:41990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Tba-615n1P-attmzI3QAAAbs"]
[Mon Jul 20 06:24:13.226445 2026] [security2:error] [pid 915741:tid 915952] [client 50.116.65.227:24348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Battle-of-Laksa-Feature-Image.jpg"] [unique_id "al4Tba-615n1P-attmzI3gAAAgY"]
[Mon Jul 20 06:24:13.360907 2026] [security2:error] [pid 915741:tid 915908] [client 34.74.185.202:49190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tba-615n1P-attmzI6AAAAbQ"]
[Mon Jul 20 06:24:13.539624 2026] [security2:error] [pid 915741:tid 915912] [client 192.236.168.43:52562] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "webgardensbypaula.com"] [uri "/"] [unique_id "al4Tba-615n1P-attmzI8QAAAbg"]
[Mon Jul 20 06:24:13.614869 2026] [security2:error] [pid 884009:tid 884238] [client 171.61.165.146:9391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TbRKaHUf6J8d3elJ6SgAAAOY"]
[Mon Jul 20 06:24:13.614999 2026] [security2:error] [pid 884009:tid 884238] [client 171.61.165.146:9391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TbRKaHUf6J8d3elJ6SgAAAOY"]
[Mon Jul 20 06:24:13.686265 2026] [security2:error] [pid 915741:tid 915892] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "undefeatedthe.com"] [uri "/.well-known/about.php"] [unique_id "al4Tba-615n1P-attmzI-AAAAaQ"]
[Mon Jul 20 06:24:13.686334 2026] [security2:error] [pid 915741:tid 915892] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "undefeatedthe.com"] [uri "/.well-known/about.php"] [unique_id "al4Tba-615n1P-attmzI-AAAAaQ"]
[Mon Jul 20 06:24:13.687241 2026] [security2:error] [pid 915741:tid 915959] [client 57.141.18.60:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Taq-615n1P-attmzIQgAB52c"]
[Mon Jul 20 06:24:13.864378 2026] [security2:error] [pid 915741:tid 915960] [client 34.74.185.202:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tba-615n1P-attmzJBQAAAeg"]
[Mon Jul 20 06:24:14.250230 2026] [security2:error] [pid 915741:tid 915918] [client 34.74.185.202:50992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tbq-615n1P-attmzJFAAAAb4"]
[Mon Jul 20 06:24:14.307209 2026] [security2:error] [pid 915741:tid 915917] [client 104.168.114.154:38918] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.webgardensbypaula.com"] [uri "/"] [unique_id "al4Tbq-615n1P-attmzJFgAAAb0"]
[Mon Jul 20 06:24:14.699804 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tbq-615n1P-attmzJKQAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:14.699927 2026] [security2:error] [pid 915741:tid 915872] [client 77.110.127.138:61870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tbq-615n1P-attmzJKQAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:14.793204 2026] [security2:error] [pid 915741:tid 915891] [client 34.74.185.202:57763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tbq-615n1P-attmzJKwAAAaM"]
[Mon Jul 20 06:24:15.000328 2026] [security2:error] [pid 884009:tid 884209] [client 77.110.127.138:61872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbhKaHUf6J8d3elJ6dAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.000427 2026] [security2:error] [pid 884009:tid 884209] [client 77.110.127.138:61872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbhKaHUf6J8d3elJ6dAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.105455 2026] [security2:error] [pid 915741:tid 915900] [client 34.74.185.202:62745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tb6-615n1P-attmzJOwAAAaw"]
[Mon Jul 20 06:24:15.215456 2026] [security2:error] [pid 915741:tid 915981] [client 77.110.127.138:61873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJQQAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.216103 2026] [security2:error] [pid 915741:tid 915981] [client 77.110.127.138:61873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJQQAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.249044 2026] [security2:error] [pid 915741:tid 915972] [client 104.168.59.36:44872] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-be93471d.zanjan-fromer.com"] [uri "/"] [unique_id "al4Tb6-615n1P-attmzJQgAAAfQ"]
[Mon Jul 20 06:24:15.445301 2026] [security2:error] [pid 884009:tid 884257] [client 77.110.127.138:61874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6fQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.445403 2026] [security2:error] [pid 884009:tid 884257] [client 77.110.127.138:61874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6fQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.493146 2026] [security2:error] [pid 915741:tid 915986] [client 77.110.127.138:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJTAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.493246 2026] [security2:error] [pid 915741:tid 915986] [client 77.110.127.138:61875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJTAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.603711 2026] [security2:error] [pid 884009:tid 884144] [client 77.110.127.138:61876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6hAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.603831 2026] [security2:error] [pid 884009:tid 884144] [client 77.110.127.138:61876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TbxKaHUf6J8d3elJ6hAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:15.651290 2026] [security2:error] [pid 915741:tid 915929] [client 34.74.185.202:59932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tb6-615n1P-attmzJVQAAAck"]
[Mon Jul 20 06:24:15.767979 2026] [security2:error] [pid 915741:tid 915893] [client 171.60.139.123:51631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tb6-615n1P-attmzJWgAAAaU"]
[Mon Jul 20 06:24:15.768095 2026] [security2:error] [pid 915741:tid 915893] [client 171.60.139.123:51631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tb6-615n1P-attmzJWgAAAaU"]
[Mon Jul 20 06:24:15.781168 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJXAAAAaY"]
[Mon Jul 20 06:24:15.781309 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJXAAAAaY"]
[Mon Jul 20 06:24:15.891381 2026] [security2:error] [pid 915741:tid 915788] [remote 154.66.198.148:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tb6-615n1P-attmzJZwAB7y4"]
[Mon Jul 20 06:24:15.939812 2026] [security2:error] [pid 915741:tid 915982] [client 77.110.127.138:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJbAAAAf4"]
[Mon Jul 20 06:24:15.939948 2026] [security2:error] [pid 915741:tid 915982] [client 77.110.127.138:61881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tb6-615n1P-attmzJbAAAAf4"]
[Mon Jul 20 06:24:15.968746 2026] [security2:error] [pid 915741:tid 915874] [client 34.74.185.202:65447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tb6-615n1P-attmzJbwAAAZI"]
[Mon Jul 20 06:24:16.275087 2026] [security2:error] [pid 915741:tid 915889] [client 104.234.53.51:22655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TcK-615n1P-attmzJfwAAAaE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:16.297466 2026] [security2:error] [pid 915741:tid 915917] [client 34.74.185.202:55767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TcK-615n1P-attmzJgQAAAb0"]
[Mon Jul 20 06:24:16.416625 2026] [security2:error] [pid 915741:tid 915922] [client 57.141.18.96:61190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tba-615n1P-attmzI6QABwho"]
[Mon Jul 20 06:24:16.447227 2026] [security2:error] [pid 915741:tid 915779] [remote 154.66.198.148:51154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TcK-615n1P-attmzJiQABsCU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:16.538288 2026] [security2:error] [pid 884009:tid 884147] [client 84.233.195.150:64726] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4TcBKaHUf6J8d3elJ6nQAAAIw"]
[Mon Jul 20 06:24:16.665125 2026] [security2:error] [pid 915741:tid 915963] [client 34.74.185.202:55375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TcK-615n1P-attmzJlAAAAes"]
[Mon Jul 20 06:24:16.976570 2026] [security2:error] [pid 884009:tid 884262] [client 57.141.18.8:54974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TbRKaHUf6J8d3elJ6XAAA_jI"]
[Mon Jul 20 06:24:17.000879 2026] [security2:error] [pid 915741:tid 915885] [client 84.233.195.157:53442] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4Tca-615n1P-attmzJpAAAAZ0"]
[Mon Jul 20 06:24:17.037538 2026] [security2:error] [pid 884009:tid 884231] [client 57.141.18.125:20432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TbhKaHUf6J8d3elJ6YAAA33U"]
[Mon Jul 20 06:24:17.081013 2026] [security2:error] [pid 915741:tid 915968] [client 34.74.185.202:52867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tca-615n1P-attmzJqwAAAfA"]
[Mon Jul 20 06:24:17.310961 2026] [security2:error] [pid 915741:tid 915920] [client 103.141.108.143:60203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tca-615n1P-attmzJtAAAAcA"]
[Mon Jul 20 06:24:17.311045 2026] [security2:error] [pid 915741:tid 915920] [client 103.141.108.143:60203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tca-615n1P-attmzJtAAAAcA"]
[Mon Jul 20 06:24:17.475665 2026] [security2:error] [pid 915741:tid 915940] [client 84.233.195.153:54978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4Tca-615n1P-attmzJtwAAAdQ"]
[Mon Jul 20 06:24:17.601947 2026] [security2:error] [pid 915741:tid 915904] [client 34.74.185.202:58750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tca-615n1P-attmzJxQAAAbA"]
[Mon Jul 20 06:24:17.672433 2026] [security2:error] [pid 915741:tid 915996] [client 57.141.18.114:51182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tbq-615n1P-attmzJJgACDGg"]
[Mon Jul 20 06:24:17.733092 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:60300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TcRKaHUf6J8d3elJ6ugAAAPk"]
[Mon Jul 20 06:24:17.733251 2026] [security2:error] [pid 884009:tid 884257] [client 45.116.69.230:60300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TcRKaHUf6J8d3elJ6ugAAAPk"]
[Mon Jul 20 06:24:17.741651 2026] [security2:error] [pid 915741:tid 915981] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJsgAB_U8"], referer: http://ardhalwafaa.com/WP
[Mon Jul 20 06:24:17.805816 2026] [security2:error] [pid 915741:tid 915922] [client 14.225.17.146:53755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJygAAAcI"], referer: http://thefriendlyspreadsheet.com/WP
[Mon Jul 20 06:24:17.819304 2026] [security2:error] [pid 884009:tid 884141] [client 114.119.137.95:49477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2023/02/postdeadline-dac-comments-february-10-2023.pdf"] [unique_id "al4TcRKaHUf6J8d3elJ6vAAAAIY"], referer: https://mtredistricting.gov/document-library/
[Mon Jul 20 06:24:17.956085 2026] [security2:error] [pid 915741:tid 915971] [client 84.233.195.151:52599] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "fkconstructionfunding.com"] [uri "/"] [unique_id "al4Tca-615n1P-attmzJ2AAAAfM"]
[Mon Jul 20 06:24:17.988634 2026] [security2:error] [pid 915741:tid 915967] [client 14.225.17.146:59625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJ1QAAAe8"], referer: http://nikkidesigns.net/WP
[Mon Jul 20 06:24:18.003801 2026] [security2:error] [pid 915741:tid 915966] [client 34.74.185.202:51018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eliteeventsleaders.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tcq-615n1P-attmzJ2wAAAe4"]
[Mon Jul 20 06:24:18.132795 2026] [security2:error] [pid 915741:tid 915902] [client 14.225.17.146:59675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJ2QAAAa4"], referer: http://ksands.co.uk/WP
[Mon Jul 20 06:24:18.393444 2026] [security2:error] [pid 915741:tid 915965] [client 104.234.53.66:37557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Tcq-615n1P-attmzJ7QAAAe0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:18.539989 2026] [security2:error] [pid 884009:tid 884165] [client 57.141.18.31:30612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TbxKaHUf6J8d3elJ6ggAAnjQ"]
[Mon Jul 20 06:24:18.614778 2026] [security2:error] [pid 915741:tid 915988] [client 104.168.59.36:45840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.website-be93471d.zanjan-fromer.com"] [uri "/"] [unique_id "al4Tcq-615n1P-attmzJ_gAAAgQ"]
[Mon Jul 20 06:24:18.634615 2026] [security2:error] [pid 915741:tid 915970] [client 57.141.18.71:50482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tb6-615n1P-attmzJUQAB8jc"]
[Mon Jul 20 06:24:18.705142 2026] [security2:error] [pid 915741:tid 915943] [client 37.139.53.21:59547] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.21" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tcq-615n1P-attmzKAQAAAdc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:18.705246 2026] [security2:error] [pid 915741:tid 915943] [client 37.139.53.21:59547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tcq-615n1P-attmzKAQAAAdc"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:18.731797 2026] [security2:error] [pid 915741:tid 915940] [client 14.225.17.146:59979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4Tcq-615n1P-attmzJ-wAAAdQ"], referer: http://alexsandbergmusic.com/WP
[Mon Jul 20 06:24:19.194244 2026] [security2:error] [pid 915741:tid 915908] [client 18.140.64.130:17938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Tc6-615n1P-attmzKGAAAAbQ"]
[Mon Jul 20 06:24:19.715376 2026] [security2:error] [pid 915741:tid 915965] [client 41.173.37.102:1448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKLAAAAe0"]
[Mon Jul 20 06:24:19.715501 2026] [security2:error] [pid 915741:tid 915965] [client 41.173.37.102:1448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKLAAAAe0"]
[Mon Jul 20 06:24:19.828198 2026] [security2:error] [pid 915741:tid 915987] [client 149.20.243.159:58675] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKLQAAAgM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:19.857693 2026] [security2:error] [pid 915741:tid 915872] [client 112.208.70.94:44838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKMQAAAZA"]
[Mon Jul 20 06:24:19.857852 2026] [security2:error] [pid 915741:tid 915872] [client 112.208.70.94:44838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tc6-615n1P-attmzKMQAAAZA"]
[Mon Jul 20 06:24:19.882902 2026] [security2:error] [pid 915741:tid 915935] [client 77.110.127.138:61892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKMwAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:19.883014 2026] [security2:error] [pid 915741:tid 915935] [client 77.110.127.138:61892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKMwAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.126397 2026] [security2:error] [pid 915741:tid 915896] [client 57.141.18.3:57080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJpQABqCg"]
[Mon Jul 20 06:24:20.165812 2026] [security2:error] [pid 884009:tid 884227] [client 18.140.64.130:17950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4TdBKaHUf6J8d3elJ6_QAAANs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:24:20.274772 2026] [security2:error] [pid 915741:tid 915997] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TdK-615n1P-attmzKOwAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.491922 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TdK-615n1P-attmzKWwAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.492056 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:61895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TdK-615n1P-attmzKWwAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:20.829242 2026] [security2:error] [pid 915741:tid 915804] [remote 51.158.61.221:35626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4TdK-615n1P-attmzKcwAB_j4"]
[Mon Jul 20 06:24:20.829530 2026] [security2:error] [pid 915741:tid 915982] [client 51.158.61.221:35626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4TdK-615n1P-attmzKcwAB_j4"]
[Mon Jul 20 06:24:20.904785 2026] [security2:error] [pid 884009:tid 884118] [remote 57.141.18.32:30642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TcRKaHUf6J8d3elJ6twAA42s"]
[Mon Jul 20 06:24:20.975664 2026] [security2:error] [pid 915741:tid 915973] [client 50.116.65.227:16302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TdK-615n1P-attmzKeQAAAfU"]
[Mon Jul 20 06:24:20.987012 2026] [security2:error] [pid 915741:tid 915895] [client 50.116.65.227:59814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4TdK-615n1P-attmzKegAAAac"]
[Mon Jul 20 06:24:21.014310 2026] [security2:error] [pid 915741:tid 915956] [client 114.119.132.58:21313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jennylouraya.com"] [uri "/gepettos-and-whole-foods-flower-hill"] [unique_id "al4Tda-615n1P-attmzKewAAAeQ"], referer: https://www.jennylouraya.com/2013/page/7
[Mon Jul 20 06:24:21.151372 2026] [security2:error] [pid 915741:tid 915955] [client 57.141.18.63:22256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tca-615n1P-attmzJ1wAB4wo"]
[Mon Jul 20 06:24:21.302979 2026] [security2:error] [pid 915741:tid 915917] [client 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzKlwAAAb0"]
[Mon Jul 20 06:24:21.635793 2026] [security2:error] [pid 915741:tid 915980] [client 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzKuAAAAfw"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:24:21.908175 2026] [security2:error] [pid 915741:tid 915881] [client 50.116.65.227:59826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Tda-615n1P-attmzKzQAAAZk"]
[Mon Jul 20 06:24:21.910037 2026] [security2:error] [pid 915741:tid 915837] [remote 152.228.213.32:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzKzAAB4V8"]
[Mon Jul 20 06:24:21.918451 2026] [security2:error] [pid 915741:tid 915945] [client 50.116.65.227:59834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Tda-615n1P-attmzKzwAAAdk"]
[Mon Jul 20 06:24:21.933442 2026] [security2:error] [pid 915741:tid 915892] [client 216.73.217.138:44922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Tda-615n1P-attmzKyQABpFw"]
[Mon Jul 20 06:24:21.993918 2026] [security2:error] [pid 915741:tid 915788] [remote 84.247.172.23:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tda-615n1P-attmzK0wABky4"]
[Mon Jul 20 06:24:22.064949 2026] [security2:error] [pid 915741:tid 915941] [client 57.141.18.82:54570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tcq-615n1P-attmzJ_wAB1TQ"]
[Mon Jul 20 06:24:22.137461 2026] [security2:error] [pid 915741:tid 915768] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tdq-615n1P-attmzK5AABnRo"]
[Mon Jul 20 06:24:22.137599 2026] [security2:error] [pid 915741:tid 915885] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tdq-615n1P-attmzK5AABnRo"]
[Mon Jul 20 06:24:22.150895 2026] [security2:error] [pid 915741:tid 915838] [remote 152.228.213.32:39364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tdq-615n1P-attmzK5QAB9mA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:24:22.174338 2026] [security2:error] [pid 915741:tid 915964] [client 74.7.227.179:52498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK3QAB7G0"], referer: https://tejasenvironmental.com/p=2588833
[Mon Jul 20 06:24:22.233280 2026] [security2:error] [pid 915741:tid 915954] [client 104.234.53.92:28857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Tdq-615n1P-attmzK4wAAAeI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:22.262077 2026] [security2:error] [pid 915741:tid 915790] [remote 84.247.172.23:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Tdq-615n1P-attmzK8AAB5DA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:24:22.615998 2026] [security2:error] [pid 915741:tid 915987] [client 149.20.243.159:58675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKLQAAAgM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:22.616057 2026] [security2:error] [pid 915741:tid 915987] [client 149.20.243.159:58675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4Tc6-615n1P-attmzKLQAAAgM"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:24:22.647714 2026] [security2:error] [pid 915741:tid 915950] [client 74.7.241.180:39618] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "teresaharding.com"] [uri "/cgi-sys/404.html"] [unique_id "al4Tdq-615n1P-attmzLEAAAAd4"]
[Mon Jul 20 06:24:22.674095 2026] [security2:error] [pid 915741:tid 915915] [client 104.234.53.92:28857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tdq-615n1P-attmzLFAAAAbs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:22.738855 2026] [security2:error] [pid 915741:tid 915936] [client 14.225.17.146:59810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK-QAAAdA"], referer: http://mollycahill.com/WP
[Mon Jul 20 06:24:23.186865 2026] [security2:error] [pid 915741:tid 915900] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzLMgAAAaw"]
[Mon Jul 20 06:24:23.189036 2026] [security2:error] [pid 915741:tid 915892] [client 189.175.47.15:33006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLOAAAAaQ"]
[Mon Jul 20 06:24:23.272923 2026] [security2:error] [pid 884009:tid 884081] [remote 57.141.18.110:50298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TcxKaHUf6J8d3elJ68AAAmkY"]
[Mon Jul 20 06:24:23.307400 2026] [security2:error] [pid 915741:tid 915926] [client 158.173.241.141:58503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLOgABxnA"]
[Mon Jul 20 06:24:23.400181 2026] [security2:error] [pid 915741:tid 915791] [remote 124.55.178.99:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Td6-615n1P-attmzLSwABvjE"]
[Mon Jul 20 06:24:23.612901 2026] [security2:error] [pid 915741:tid 915916] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLXgAAAbw"], referer: http://adultdaycarereno.com/WP
[Mon Jul 20 06:24:23.827349 2026] [security2:error] [pid 915741:tid 915831] [remote 124.55.178.99:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Td6-615n1P-attmzLdAABzlk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:24.088080 2026] [security2:error] [pid 915741:tid 915877] [client 57.141.18.113:49758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TdK-615n1P-attmzKUwABlQE"]
[Mon Jul 20 06:24:24.316532 2026] [core:error] [pid 915741:tid 915971] [client 14.225.17.146:52429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:24.316550 2026] [core:error] [pid 915741:tid 915971] [client 14.225.17.146:52429] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:24.493087 2026] [security2:error] [pid 915741:tid 915966] [client 138.199.60.178:56834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLnAAAAe4"], referer: https://lifeisbetterlakeside.com
[Mon Jul 20 06:24:24.568290 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:51769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLrwAAAd0"], referer: https://adultdaycarereno.com/WP
[Mon Jul 20 06:24:24.570442 2026] [security2:error] [pid 915741:tid 915978] [client 171.61.165.146:18948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TeK-615n1P-attmzLtgAAAfo"]
[Mon Jul 20 06:24:24.570536 2026] [security2:error] [pid 915741:tid 915978] [client 171.61.165.146:18948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TeK-615n1P-attmzLtgAAAfo"]
[Mon Jul 20 06:24:24.631148 2026] [security2:error] [pid 915741:tid 915939] [client 57.141.18.83:35090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TdK-615n1P-attmzKdAAB0w0"]
[Mon Jul 20 06:24:24.719795 2026] [security2:error] [pid 915741:tid 915905] [client 45.157.112.60:24839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TeK-615n1P-attmzLvAAAAbE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:24.789814 2026] [security2:error] [pid 915741:tid 915907] [client 43.134.44.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLpwAAAbM"], referer: https://www.savilerowtravel.com/hotels/austria/the-elizabeth-arthotel-2/me-02-hotel-elisabeth-2011
[Mon Jul 20 06:24:24.849267 2026] [security2:error] [pid 915741:tid 915942] [client 114.119.166.95:60709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "new-menus.com"] [uri "/robots.txt"] [unique_id "al4TeK-615n1P-attmzLyAAAAdY"], referer: http://new-menus.com/robots.txt
[Mon Jul 20 06:24:24.994124 2026] [security2:error] [pid 915741:tid 915980] [client 50.116.65.227:16312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4TeK-615n1P-attmzL2wAAAfw"]
[Mon Jul 20 06:24:25.005627 2026] [security2:error] [pid 915741:tid 915924] [client 50.116.65.227:59848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4Tea-615n1P-attmzL3AAAAcQ"]
[Mon Jul 20 06:24:25.051460 2026] [security2:error] [pid 915741:tid 915785] [remote 100.42.189.89:45752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Tea-615n1P-attmzL3gABmys"]
[Mon Jul 20 06:24:25.091865 2026] [security2:error] [pid 915741:tid 915943] [client 77.110.127.138:61920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzL5gAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.092012 2026] [security2:error] [pid 915741:tid 915943] [client 77.110.127.138:61920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzL5gAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.256709 2026] [security2:error] [pid 915741:tid 915807] [remote 100.42.189.89:45752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Tea-615n1P-attmzL6wAB6kE"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:24:25.375320 2026] [security2:error] [pid 915741:tid 915935] [client 57.141.18.101:42670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tda-615n1P-attmzKnQABzxM"]
[Mon Jul 20 06:24:25.652397 2026] [security2:error] [pid 915741:tid 915992] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tea-615n1P-attmzL7wAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.885110 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzMHgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.885192 2026] [security2:error] [pid 915741:tid 915951] [client 77.110.127.138:61928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tea-615n1P-attmzMHgAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:25.980492 2026] [security2:error] [pid 915741:tid 915897] [client 57.141.18.46:43422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tda-615n1P-attmzKygABqS0"]
[Mon Jul 20 06:24:26.001911 2026] [security2:error] [pid 915741:tid 915994] [client 104.234.53.90:28653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Teq-615n1P-attmzMJAAAAgo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:26.055082 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMKgAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.055187 2026] [security2:error] [pid 915741:tid 915875] [client 77.110.127.138:61932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMKgAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.176432 2026] [security2:error] [pid 915741:tid 915930] [client 57.141.18.42:48426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK1AABygY"]
[Mon Jul 20 06:24:26.213543 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMPwAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.213919 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:61934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMPwAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.389955 2026] [security2:error] [pid 915741:tid 915967] [client 171.60.139.123:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Teq-615n1P-attmzMSwAAAe8"]
[Mon Jul 20 06:24:26.390112 2026] [security2:error] [pid 915741:tid 915967] [client 171.60.139.123:52198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Teq-615n1P-attmzMSwAAAe8"]
[Mon Jul 20 06:24:26.398990 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMTAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.399113 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:61935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMTAAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.569980 2026] [authz_core:error] [pid 915741:tid 915907] [client 66.132.195.57:41114] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:24:26.578382 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.31:37616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzK_QABtQU"]
[Mon Jul 20 06:24:26.737365 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:61904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMawAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.737525 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:61904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMawAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.795732 2026] [security2:error] [pid 915741:tid 915888] [client 77.110.127.138:61903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMbwAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.795846 2026] [security2:error] [pid 915741:tid 915888] [client 77.110.127.138:61903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMbwAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.820448 2026] [security2:error] [pid 915741:tid 915941] [client 57.141.18.14:23998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tdq-615n1P-attmzLDgAB1V0"]
[Mon Jul 20 06:24:26.849328 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:61905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMdAAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.849448 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:61905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Teq-615n1P-attmzMdAAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:26.858874 2026] [security2:error] [pid 915741:tid 915911] [client 104.234.53.68:56445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Teq-615n1P-attmzMbgAAAbc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:27.019157 2026] [security2:error] [pid 915741:tid 915891] [client 34.74.185.202:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Te6-615n1P-attmzMggAAAaM"]
[Mon Jul 20 06:24:27.316223 2026] [autoindex:error] [pid 915741:tid 915815] [remote 2a06:98c0:3600::103:0] AH01276: Cannot serve directory /home2/rzsjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:24:27.719838 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Te6-615n1P-attmzMxwAAAZ4"]
[Mon Jul 20 06:24:27.719964 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:60674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Te6-615n1P-attmzMxwAAAZ4"]
[Mon Jul 20 06:24:27.789461 2026] [proxy:error] [pid 915741:tid 915895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:27.789539 2026] [proxy_http:error] [pid 915741:tid 915895] [client 34.73.38.214:60675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:27.790023 2026] [proxy:error] [pid 915741:tid 915895] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:27.790055 2026] [proxy_http:error] [pid 915741:tid 915895] [client 34.73.38.214:60675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:27.841853 2026] [core:error] [pid 915741:tid 915942] [client 66.132.195.57:41132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:27.841880 2026] [core:error] [pid 915741:tid 915942] [client 66.132.195.57:41132] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:27.925093 2026] [security2:error] [pid 915741:tid 915959] [client 34.74.185.202:50117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Te6-615n1P-attmzM1wAAAec"]
[Mon Jul 20 06:24:27.926859 2026] [security2:error] [pid 915741:tid 915898] [client 104.234.53.68:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Te6-615n1P-attmzM1QAAAao"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:27.954782 2026] [security2:error] [pid 915741:tid 915921] [client 57.141.18.72:47138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Td6-615n1P-attmzLdwABwT0"]
[Mon Jul 20 06:24:27.984939 2026] [security2:error] [pid 915741:tid 915825] [remote 47.86.33.52:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Te6-615n1P-attmzM4wAB6FM"]
[Mon Jul 20 06:24:28.024182 2026] [security2:error] [pid 915741:tid 915887] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4Te6-615n1P-attmzMqQABnwM"], referer: http://ali-alghanim.net/WP
[Mon Jul 20 06:24:28.103883 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:60996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Teq-615n1P-attmzMRAAAAdI"], referer: http://windowtx.com/WP
[Mon Jul 20 06:24:28.163185 2026] [security2:error] [pid 915741:tid 915845] [remote 160.187.68.132:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TfK-615n1P-attmzM9gAB9Gc"]
[Mon Jul 20 06:24:28.417888 2026] [security2:error] [pid 915741:tid 915881] [client 45.116.69.230:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TfK-615n1P-attmzM_gAAAZk"]
[Mon Jul 20 06:24:28.417990 2026] [security2:error] [pid 915741:tid 915881] [client 45.116.69.230:60824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TfK-615n1P-attmzM_gAAAZk"]
[Mon Jul 20 06:24:28.639512 2026] [security2:error] [pid 915741:tid 915771] [remote 160.187.68.132:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TfK-615n1P-attmzNFAAByR0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:28.716888 2026] [security2:error] [pid 915741:tid 915994] [client 186.87.10.144:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzM-wAAAgo"]
[Mon Jul 20 06:24:28.736158 2026] [security2:error] [pid 915741:tid 915915] [client 57.141.18.106:35282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TeK-615n1P-attmzLrQABuz4"]
[Mon Jul 20 06:24:28.863894 2026] [security2:error] [pid 915741:tid 915940] [client 77.110.127.138:61943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TfK-615n1P-attmzNKAAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:28.863994 2026] [security2:error] [pid 915741:tid 915940] [client 77.110.127.138:61943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TfK-615n1P-attmzNKAAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:28.952401 2026] [core:error] [pid 915741:tid 915899] [client 103.153.183.69:8686] AH10244: invalid URI path (/%2e./%2e./etc/passwd?_=ap77v5fg&v=bsjfe), referer: https://twitter.com/
[Mon Jul 20 06:24:28.955467 2026] [security2:error] [pid 915741:tid 915952] [client 127.0.0.1:15840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4TfK-615n1P-attmzNOAAAAeA"], referer: https://twitter.com/
[Mon Jul 20 06:24:29.045385 2026] [security2:error] [pid 915741:tid 915962] [client 104.234.53.54:58217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tfa-615n1P-attmzNQQAAAeo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:29.067142 2026] [proxy:error] [pid 915741:tid 915893] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:29.067205 2026] [proxy_http:error] [pid 915741:tid 915893] [client 34.73.38.214:52122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:29.067768 2026] [proxy:error] [pid 915741:tid 915893] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:29.067796 2026] [proxy_http:error] [pid 915741:tid 915893] [client 34.73.38.214:52122] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:29.163614 2026] [security2:error] [pid 915741:tid 915875] [client 148.251.126.195:44466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzNOwAAAZM"]
[Mon Jul 20 06:24:29.180845 2026] [security2:error] [pid 915741:tid 915979] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzNNAAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:29.345508 2026] [security2:error] [pid 915741:tid 915996] [client 34.74.185.202:62566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tfa-615n1P-attmzNXQAAAgw"]
[Mon Jul 20 06:24:29.362845 2026] [security2:error] [pid 915741:tid 915995] [client 34.74.185.202:55294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tfa-615n1P-attmzNXwAAAgs"]
[Mon Jul 20 06:24:29.462738 2026] [security2:error] [pid 915741:tid 915945] [client 57.141.18.61:53224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tea-615n1P-attmzL6AAB2Qw"]
[Mon Jul 20 06:24:29.656575 2026] [security2:error] [pid 915741:tid 915753] [remote 47.86.33.52:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Tfa-615n1P-attmzNdgAByQs"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:24:29.802416 2026] [security2:error] [pid 915741:tid 915916] [client 77.110.127.138:61944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tfa-615n1P-attmzNfwAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:29.802557 2026] [security2:error] [pid 915741:tid 915916] [client 77.110.127.138:61944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tfa-615n1P-attmzNfwAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:29.858085 2026] [security2:error] [pid 915741:tid 915924] [client 103.153.183.69:23540] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/ubuntu/.ssh/id_rsa"] [unique_id "al4Tfa-615n1P-attmzNggAAAcQ"], referer: https://www.bing.com/search?q=qyqejj
[Mon Jul 20 06:24:29.863109 2026] [security2:error] [pid 915741:tid 915955] [client 57.141.18.18:43346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tea-615n1P-attmzMEQAB4zQ"]
[Mon Jul 20 06:24:30.357683 2026] [security2:error] [pid 915741:tid 915880] [client 41.173.37.102:1887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tfq-615n1P-attmzNuAAAAZg"]
[Mon Jul 20 06:24:30.357822 2026] [security2:error] [pid 915741:tid 915880] [client 41.173.37.102:1887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tfq-615n1P-attmzNuAAAAZg"]
[Mon Jul 20 06:24:30.494998 2026] [security2:error] [pid 915741:tid 915900] [client 14.225.17.146:53706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4TfK-615n1P-attmzNIgAAAaw"]
[Mon Jul 20 06:24:30.726492 2026] [core:error] [pid 915741:tid 915911] [client 103.153.183.69:8694] AH10244: invalid URI path (/.%2e/.%2e/etc/passwd?_=legur6y1&v=1lgco), referer: https://www.facebook.com/
[Mon Jul 20 06:24:30.729737 2026] [security2:error] [pid 915741:tid 915973] [client 127.0.0.1:15858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4Tfq-615n1P-attmzN4AAAAfU"], referer: https://www.facebook.com/
[Mon Jul 20 06:24:30.731826 2026] [security2:error] [pid 915741:tid 915966] [client 34.74.185.202:58226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tfq-615n1P-attmzN4gAAAe4"]
[Mon Jul 20 06:24:30.734016 2026] [security2:error] [pid 915741:tid 915885] [client 34.74.185.202:58194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tfq-615n1P-attmzN5AAAAZ0"]
[Mon Jul 20 06:24:30.824717 2026] [security2:error] [pid 915741:tid 915877] [client 14.225.17.146:51818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4Tfa-615n1P-attmzNbQAAAZU"], referer: http://lutheranphilosopher.com/WP
[Mon Jul 20 06:24:30.882192 2026] [proxy:error] [pid 915741:tid 915992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:30.882285 2026] [proxy_http:error] [pid 915741:tid 915992] [client 34.73.38.214:63840] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:30.883552 2026] [proxy:error] [pid 915741:tid 915992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:30.883605 2026] [proxy_http:error] [pid 915741:tid 915992] [client 34.73.38.214:63840] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:30.927847 2026] [security2:error] [pid 915741:tid 915941] [client 72.63.213.42:11844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4Tfq-615n1P-attmzNwQAB1R8"], referer: https://www.thewelloiledlife.com/tag/sleepessence/
[Mon Jul 20 06:24:31.031383 2026] [security2:error] [pid 915741:tid 915786] [remote 192.241.143.148:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tf6-615n1P-attmzN8QAB9Cw"]
[Mon Jul 20 06:24:31.052746 2026] [security2:error] [pid 915741:tid 915988] [client 77.110.127.138:61947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzN8wAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.052901 2026] [security2:error] [pid 915741:tid 915988] [client 77.110.127.138:61947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzN8wAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.058430 2026] [security2:error] [pid 915741:tid 915915] [client 148.251.126.195:44478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4Tfq-615n1P-attmzN7AAAAbs"]
[Mon Jul 20 06:24:31.225684 2026] [security2:error] [pid 915741:tid 915867] [remote 192.241.143.148:47380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tf6-615n1P-attmzOBQABlH0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:31.336394 2026] [security2:error] [pid 915741:tid 915966] [client 77.110.127.138:61948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzODAAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.336516 2026] [security2:error] [pid 915741:tid 915966] [client 77.110.127.138:61948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tf6-615n1P-attmzODAAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.434869 2026] [security2:error] [pid 915741:tid 915910] [client 50.116.65.227:41940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Tf6-615n1P-attmzOEgAAAbY"]
[Mon Jul 20 06:24:31.444886 2026] [security2:error] [pid 915741:tid 915974] [client 50.116.65.227:41954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Tf6-615n1P-attmzOEwAAAfY"]
[Mon Jul 20 06:24:31.628566 2026] [security2:error] [pid 915741:tid 915988] [client 34.74.185.202:56505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tf6-615n1P-attmzOJQAAAgQ"]
[Mon Jul 20 06:24:31.674939 2026] [security2:error] [pid 915741:tid 915989] [client 14.225.17.146:61371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Tf6-615n1P-attmzOFAAAAgU"], referer: http://according2plant.com/WP
[Mon Jul 20 06:24:31.737317 2026] [security2:error] [pid 915741:tid 915918] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tf6-615n1P-attmzOGgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:31.986500 2026] [security2:error] [pid 915741:tid 915979] [client 34.74.185.202:61855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tf6-615n1P-attmzORgAAAfs"]
[Mon Jul 20 06:24:31.994985 2026] [security2:error] [pid 915741:tid 915884] [client 57.141.18.49:44788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Te6-615n1P-attmzM0AABnCQ"]
[Mon Jul 20 06:24:32.132569 2026] [security2:error] [pid 915741:tid 915818] [remote 152.228.213.32:34760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOTQACCUw"]
[Mon Jul 20 06:24:32.218388 2026] [security2:error] [pid 915741:tid 915995] [client 34.74.185.202:50025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4TgK-615n1P-attmzOXAAAAgs"]
[Mon Jul 20 06:24:32.312331 2026] [security2:error] [pid 915741:tid 915752] [remote 152.228.213.32:34760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOagABkgo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:24:32.519624 2026] [security2:error] [pid 915741:tid 915978] [client 148.251.126.195:44494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzObQAAAfo"]
[Mon Jul 20 06:24:32.543095 2026] [security2:error] [pid 915741:tid 915765] [remote 78.46.157.202:35780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOeQAB9hc"]
[Mon Jul 20 06:24:32.623581 2026] [security2:error] [pid 915741:tid 915866] [remote 47.86.33.52:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOgAAB2Hw"]
[Mon Jul 20 06:24:32.637430 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:32.637517 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:55028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:32.638542 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:32.638575 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:55028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:32.720604 2026] [security2:error] [pid 915741:tid 915957] [client 68.235.52.68:43162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOigAAAeU"]
[Mon Jul 20 06:24:32.720710 2026] [security2:error] [pid 915741:tid 915957] [client 68.235.52.68:43162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOigAAAeU"]
[Mon Jul 20 06:24:32.728332 2026] [security2:error] [pid 915741:tid 915886] [client 68.235.52.68:43160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOjAAAAZ4"]
[Mon Jul 20 06:24:32.728430 2026] [security2:error] [pid 915741:tid 915886] [client 68.235.52.68:43160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOjAAAAZ4"]
[Mon Jul 20 06:24:32.729226 2026] [security2:error] [pid 915741:tid 915760] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOiwACChI"]
[Mon Jul 20 06:24:32.729426 2026] [security2:error] [pid 915741:tid 915994] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOiwACChI"]
[Mon Jul 20 06:24:32.760765 2026] [security2:error] [pid 915741:tid 915829] [remote 78.46.157.202:35780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOkAABkVc"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:24:32.814934 2026] [security2:error] [pid 915741:tid 915920] [client 112.208.70.94:45228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOmAAAAcA"]
[Mon Jul 20 06:24:32.815158 2026] [security2:error] [pid 915741:tid 915920] [client 112.208.70.94:45228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TgK-615n1P-attmzOmAAAAcA"]
[Mon Jul 20 06:24:32.853636 2026] [security2:error] [pid 915741:tid 915750] [remote 103.255.134.61:39908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4TgK-615n1P-attmzOmQAB-Qg"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:24:32.947472 2026] [security2:error] [pid 915741:tid 915927] [client 34.74.185.202:65143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TgK-615n1P-attmzOmwAAAcc"]
[Mon Jul 20 06:24:33.101045 2026] [security2:error] [pid 915741:tid 915877] [client 14.225.17.146:62900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOegAAAZU"], referer: http://drewsasburyparkbeachhouse.com/WP
[Mon Jul 20 06:24:33.131967 2026] [security2:error] [pid 915741:tid 915871] [client 57.141.18.109:56244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tfa-615n1P-attmzNRQABj3k"]
[Mon Jul 20 06:24:33.187927 2026] [security2:error] [pid 915741:tid 915958] [client 148.251.126.195:44502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOnAAAAeY"]
[Mon Jul 20 06:24:33.294385 2026] [security2:error] [pid 915741:tid 915787] [remote 147.50.252.213:34716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tga-615n1P-attmzOtQACBi0"]
[Mon Jul 20 06:24:33.294539 2026] [security2:error] [pid 915741:tid 915990] [client 147.50.252.213:34716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tga-615n1P-attmzOtQACBi0"]
[Mon Jul 20 06:24:33.567412 2026] [security2:error] [pid 915741:tid 915900] [client 34.74.185.202:55475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tga-615n1P-attmzOxQAAAaw"]
[Mon Jul 20 06:24:33.776981 2026] [security2:error] [pid 915741:tid 915969] [client 57.141.18.100:25802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tfa-615n1P-attmzNdwAB8TU"]
[Mon Jul 20 06:24:33.875139 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO3AAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:33.875236 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO3AAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:33.948603 2026] [security2:error] [pid 915741:tid 915950] [client 77.110.127.138:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO4gAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:33.948698 2026] [security2:error] [pid 915741:tid 915950] [client 77.110.127.138:61956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tga-615n1P-attmzO4gAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.026262 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzO6wAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.026359 2026] [security2:error] [pid 915741:tid 915939] [client 77.110.127.138:61957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzO6wAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.030238 2026] [security2:error] [pid 915741:tid 915881] [client 34.74.185.202:58086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tgq-615n1P-attmzO7AAAAZk"]
[Mon Jul 20 06:24:34.277775 2026] [security2:error] [pid 915741:tid 915971] [client 14.225.17.146:62899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "outlookturf.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOewAAAfM"], referer: http://outlookturf.com/WP
[Mon Jul 20 06:24:34.443738 2026] [security2:error] [pid 915741:tid 915944] [client 77.83.36.161:29860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4Tgq-615n1P-attmzPCQAAAdg"]
[Mon Jul 20 06:24:34.465902 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPDAAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.466000 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:61961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPDAAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:34.485778 2026] [security2:error] [pid 915741:tid 915890] [client 34.74.185.202:55340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tgq-615n1P-attmzPDQAAAaI"]
[Mon Jul 20 06:24:34.652020 2026] [security2:error] [pid 915741:tid 915978] [client 34.74.185.202:58100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tgq-615n1P-attmzPGQAAAfo"]
[Mon Jul 20 06:24:34.666441 2026] [security2:error] [pid 915741:tid 915891] [client 77.110.127.138:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPGgAAAaM"]
[Mon Jul 20 06:24:34.666537 2026] [security2:error] [pid 915741:tid 915891] [client 77.110.127.138:61962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPGgAAAaM"]
[Mon Jul 20 06:24:34.825347 2026] [security2:error] [pid 915741:tid 915934] [client 77.110.127.138:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPKgAAAc4"]
[Mon Jul 20 06:24:34.825488 2026] [security2:error] [pid 915741:tid 915934] [client 77.110.127.138:61964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tgq-615n1P-attmzPKgAAAc4"]
[Mon Jul 20 06:24:35.006085 2026] [core:error] [pid 915741:tid 915892] [client 14.225.17.146:61373] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WP
[Mon Jul 20 06:24:35.006115 2026] [core:error] [pid 915741:tid 915892] [client 14.225.17.146:61373] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WP
[Mon Jul 20 06:24:35.095317 2026] [security2:error] [pid 915741:tid 915982] [client 77.83.36.161:30230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4Tg6-615n1P-attmzPRwAAAf4"]
[Mon Jul 20 06:24:35.392611 2026] [core:error] [pid 915741:tid 915924] [client 14.225.17.146:63358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:35.392631 2026] [core:error] [pid 915741:tid 915924] [client 14.225.17.146:63358] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:35.413425 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.25:27638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tf6-615n1P-attmzOCgABnU0"]
[Mon Jul 20 06:24:35.610015 2026] [security2:error] [pid 915741:tid 915945] [client 34.74.185.202:49866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tg6-615n1P-attmzPbwAAAdk"]
[Mon Jul 20 06:24:35.640641 2026] [security2:error] [pid 915741:tid 915877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tg6-615n1P-attmzPXQAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:35.747251 2026] [security2:error] [pid 915741:tid 915965] [client 77.83.36.161:30579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4Tg6-615n1P-attmzPdwAAAe0"]
[Mon Jul 20 06:24:35.812047 2026] [security2:error] [pid 915741:tid 915901] [client 34.74.185.202:54398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tg6-615n1P-attmzPfgAAAa0"]
[Mon Jul 20 06:24:35.973652 2026] [security2:error] [pid 915741:tid 915962] [client 171.61.165.146:22150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tg6-615n1P-attmzPlAAAAeo"]
[Mon Jul 20 06:24:35.973765 2026] [security2:error] [pid 915741:tid 915962] [client 171.61.165.146:22150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tg6-615n1P-attmzPlAAAAeo"]
[Mon Jul 20 06:24:35.990243 2026] [security2:error] [pid 915741:tid 915926] [client 34.73.38.214:57900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tg6-615n1P-attmzPlQAAAcY"]
[Mon Jul 20 06:24:36.078604 2026] [security2:error] [pid 915741:tid 915937] [client 34.74.185.202:51868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ThK-615n1P-attmzPmwAAAdE"]
[Mon Jul 20 06:24:36.431765 2026] [security2:error] [pid 915741:tid 915926] [client 74.208.214.194:44708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ThK-615n1P-attmzPtwAAAcY"]
[Mon Jul 20 06:24:36.469305 2026] [security2:error] [pid 915741:tid 915902] [client 14.225.17.146:61477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4ThK-615n1P-attmzPrQAAAa4"], referer: http://eframiproperties.com/WP
[Mon Jul 20 06:24:36.573308 2026] [security2:error] [pid 915741:tid 915969] [client 34.74.185.202:50949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ThK-615n1P-attmzPywAAAfE"]
[Mon Jul 20 06:24:36.962033 2026] [security2:error] [pid 915741:tid 915998] [client 171.60.139.123:52722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ThK-615n1P-attmzP6wAAAg4"]
[Mon Jul 20 06:24:36.962174 2026] [security2:error] [pid 915741:tid 915998] [client 171.60.139.123:52722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4ThK-615n1P-attmzP6wAAAg4"]
[Mon Jul 20 06:24:37.099240 2026] [security2:error] [pid 915741:tid 915876] [client 14.225.17.146:63388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4Tg6-615n1P-attmzPcwAAAZQ"], referer: http://slutilities.com/WP
[Mon Jul 20 06:24:37.109351 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.114:20500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TgK-615n1P-attmzOiAABtWM"]
[Mon Jul 20 06:24:37.197050 2026] [security2:error] [pid 915741:tid 915753] [remote 47.86.33.52:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4Tha-615n1P-attmzP_gABsAs"], referer: https://hammadownenterprises.com/wp-login.php
[Mon Jul 20 06:24:37.234092 2026] [security2:error] [pid 915741:tid 915905] [client 34.74.185.202:50483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQBQAAAbE"]
[Mon Jul 20 06:24:37.366090 2026] [security2:error] [pid 915741:tid 915898] [client 14.225.17.146:55117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzP-AAAAao"], referer: http://guidehunting.com/WP
[Mon Jul 20 06:24:37.436856 2026] [security2:error] [pid 915741:tid 915896] [client 34.74.185.202:50591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQHQAAAag"]
[Mon Jul 20 06:24:37.598110 2026] [security2:error] [pid 915741:tid 915871] [client 65.1.132.125:10782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Tha-615n1P-attmzQLQAAAY8"]
[Mon Jul 20 06:24:37.677854 2026] [security2:error] [pid 915741:tid 915943] [client 34.73.38.214:58960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQPAAAAdc"]
[Mon Jul 20 06:24:37.764524 2026] [security2:error] [pid 915741:tid 915977] [client 14.225.17.146:55586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzQMgAAAfk"], referer: http://fluidtemple.org/WP
[Mon Jul 20 06:24:37.768815 2026] [security2:error] [pid 915741:tid 915878] [client 34.74.185.202:50585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.eql.eda.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tha-615n1P-attmzQQgAAAZY"]
[Mon Jul 20 06:24:37.917237 2026] [security2:error] [pid 915741:tid 915799] [remote 104.244.79.40:60074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Tha-615n1P-attmzQSwABpjk"]
[Mon Jul 20 06:24:38.083384 2026] [security2:error] [pid 915741:tid 915921] [client 57.141.18.48:33656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tga-615n1P-attmzO1QABwSo"]
[Mon Jul 20 06:24:38.084182 2026] [security2:error] [pid 915741:tid 915914] [client 77.110.127.138:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Thq-615n1P-attmzQWgAAAbo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:38.084313 2026] [security2:error] [pid 915741:tid 915914] [client 77.110.127.138:61988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Thq-615n1P-attmzQWgAAAbo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:38.130318 2026] [security2:error] [pid 915741:tid 915767] [remote 104.244.79.40:60074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.79.244.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Thq-615n1P-attmzQYQAB1hk"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:24:38.219690 2026] [security2:error] [pid 915741:tid 915905] [client 34.74.185.202:49600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Thq-615n1P-attmzQbgAAAbE"]
[Mon Jul 20 06:24:38.415143 2026] [security2:error] [pid 915741:tid 915909] [client 14.225.17.146:55348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQagAAAbU"], referer: http://floorsourcestock.com/WP
[Mon Jul 20 06:24:38.432561 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Thq-615n1P-attmzQggAAAZA"]
[Mon Jul 20 06:24:38.433466 2026] [security2:error] [pid 915741:tid 915872] [client 103.141.108.143:61140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Thq-615n1P-attmzQggAAAZA"]
[Mon Jul 20 06:24:38.468252 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:54967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQawAAAdI"], referer: https://guidehunting.com/WP
[Mon Jul 20 06:24:38.704643 2026] [security2:error] [pid 915741:tid 915894] [client 34.73.38.214:60582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Thq-615n1P-attmzQngAAAaY"]
[Mon Jul 20 06:24:38.758976 2026] [security2:error] [pid 915741:tid 915984] [client 14.225.17.146:55428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzQDwAAAgA"], referer: http://detroitcsc.com/WP
[Mon Jul 20 06:24:38.917289 2026] [security2:error] [pid 915741:tid 915962] [client 34.74.185.202:58372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Thq-615n1P-attmzQqAAAAeo"]
[Mon Jul 20 06:24:38.968316 2026] [security2:error] [pid 915741:tid 915862] [remote 57.141.18.22:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2937685"] [unique_id "al4Thq-615n1P-attmzQrQABkXg"]
[Mon Jul 20 06:24:39.120119 2026] [security2:error] [pid 915741:tid 915871] [client 45.116.69.230:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Th6-615n1P-attmzQvQAAAY8"]
[Mon Jul 20 06:24:39.120199 2026] [security2:error] [pid 915741:tid 915871] [client 45.116.69.230:61345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Th6-615n1P-attmzQvQAAAY8"]
[Mon Jul 20 06:24:39.289617 2026] [authz_core:error] [pid 915741:tid 915918] [client 66.132.195.57:50170] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:24:39.418680 2026] [security2:error] [pid 915741:tid 915924] [client 34.74.185.202:63220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Th6-615n1P-attmzQ0wAAAcQ"]
[Mon Jul 20 06:24:39.533575 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Th6-615n1P-attmzQ2AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:39.533689 2026] [security2:error] [pid 915741:tid 915937] [client 77.110.127.138:61995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Th6-615n1P-attmzQ2AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:39.941574 2026] [security2:error] [pid 915741:tid 915952] [client 65.1.132.125:10798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Th6-615n1P-attmzQ9gAAAeA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:24:40.168715 2026] [security2:error] [pid 915741:tid 915901] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Th6-615n1P-attmzQ7wAAAa0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:40.201253 2026] [security2:error] [pid 915741:tid 915804] [remote 18.61.192.253:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TiK-615n1P-attmzRDwAB_j4"]
[Mon Jul 20 06:24:40.220075 2026] [security2:error] [pid 915741:tid 915994] [client 57.141.18.89:56180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tg6-615n1P-attmzPeQACCmc"]
[Mon Jul 20 06:24:40.311552 2026] [core:error] [pid 915741:tid 915911] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.311570 2026] [core:error] [pid 915741:tid 915911] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.336312 2026] [core:error] [pid 915741:tid 915943] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.336349 2026] [core:error] [pid 915741:tid 915943] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:40.441853 2026] [security2:error] [pid 915741:tid 915962] [client 14.225.17.146:54854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRMAAAAeo"], referer: http://eduardsales.com/WP
[Mon Jul 20 06:24:40.476773 2026] [security2:error] [pid 915741:tid 915939] [client 34.74.185.202:65129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.entraalnuevomundo.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TiK-615n1P-attmzRNwAAAdM"]
[Mon Jul 20 06:24:40.520987 2026] [security2:error] [pid 915741:tid 915880] [client 34.73.38.214:63936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TiK-615n1P-attmzRPgAAAZg"]
[Mon Jul 20 06:24:40.698896 2026] [security2:error] [pid 915741:tid 915774] [remote 18.61.192.253:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TiK-615n1P-attmzRVgABqyA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:40.904479 2026] [security2:error] [pid 915741:tid 915962] [client 50.116.65.227:57388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TiK-615n1P-attmzRYwAAAeo"]
[Mon Jul 20 06:24:40.916089 2026] [security2:error] [pid 915741:tid 915939] [client 50.116.65.227:57394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TiK-615n1P-attmzRZAAAAdM"]
[Mon Jul 20 06:24:41.009102 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:2325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tia-615n1P-attmzRagAAAfU"]
[Mon Jul 20 06:24:41.009213 2026] [security2:error] [pid 915741:tid 915973] [client 41.173.37.102:2325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tia-615n1P-attmzRagAAAfU"]
[Mon Jul 20 06:24:41.048716 2026] [security2:error] [pid 915741:tid 915878] [client 14.225.17.146:55077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRXQAAAZY"], referer: http://soloceos.com/WP
[Mon Jul 20 06:24:41.154580 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:62005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tia-615n1P-attmzRfwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:41.154739 2026] [security2:error] [pid 915741:tid 915955] [client 77.110.127.138:62005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tia-615n1P-attmzRfwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:41.160601 2026] [security2:error] [pid 915741:tid 915976] [client 14.225.17.146:61839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4Tia-615n1P-attmzRbgAAAfg"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WP
[Mon Jul 20 06:24:41.311136 2026] [security2:error] [pid 915741:tid 915832] [remote 173.212.252.15:46264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Tia-615n1P-attmzRkgAB61o"]
[Mon Jul 20 06:24:41.317694 2026] [security2:error] [pid 915741:tid 915882] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRaQAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:41.525008 2026] [security2:error] [pid 915741:tid 915747] [remote 173.212.252.15:46264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4Tia-615n1P-attmzRoAABzgU"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 06:24:41.560271 2026] [security2:error] [pid 915741:tid 915956] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4Tia-615n1P-attmzRpAAAAeQ"], referer: https://duckduckgo.com/?q=ptse6
[Mon Jul 20 06:24:41.624955 2026] [autoindex:error] [pid 915741:tid 915890] [client 159.89.124.33:52868] AH01276: Cannot serve directory /home2/jworalmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:24:41.642274 2026] [security2:error] [pid 915741:tid 915908] [client 14.225.17.146:54968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Tia-615n1P-attmzRngAAAbQ"], referer: http://colinkeyphotography.com/WP
[Mon Jul 20 06:24:41.718243 2026] [security2:error] [pid 915741:tid 915880] [client 158.173.166.181:41499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tia-615n1P-attmzRtwAAAZg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:41.851369 2026] [security2:error] [pid 915741:tid 915945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tia-615n1P-attmzRrAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.026772 2026] [security2:error] [pid 915741:tid 915933] [client 57.141.18.48:65532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tha-615n1P-attmzQOwABzVE"]
[Mon Jul 20 06:24:42.491133 2026] [security2:error] [pid 915741:tid 915996] [client 57.141.18.92:56950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQXwACDFU"]
[Mon Jul 20 06:24:42.556864 2026] [security2:error] [pid 915741:tid 915961] [client 57.141.18.78:54520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Thq-615n1P-attmzQbQAB6UY"]
[Mon Jul 20 06:24:42.594000 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSAQAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.594125 2026] [security2:error] [pid 915741:tid 915873] [client 77.110.127.138:62017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSAQAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.621475 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tiq-615n1P-attmzR8QAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.763599 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:62019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSEgAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.763716 2026] [security2:error] [pid 915741:tid 915871] [client 77.110.127.138:62019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tiq-615n1P-attmzSEgAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:42.787023 2026] [security2:error] [pid 915741:tid 915937] [client 34.73.38.214:56130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tiq-615n1P-attmzSFAAAAdE"]
[Mon Jul 20 06:24:42.857594 2026] [security2:error] [pid 915741:tid 915801] [remote 81.173.115.7:38736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tiq-615n1P-attmzSGgAByTs"]
[Mon Jul 20 06:24:42.903901 2026] [security2:error] [pid 915741:tid 915963] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4Tiq-615n1P-attmzSHAAAAes"], referer: https://twitter.com/
[Mon Jul 20 06:24:42.934302 2026] [security2:error] [pid 915741:tid 915942] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4Tiq-615n1P-attmzSHgAAAdY"], referer: https://www.bing.com/search?q=1tsvvy
[Mon Jul 20 06:24:43.010395 2026] [core:error] [pid 915741:tid 915934] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:43.010423 2026] [core:error] [pid 915741:tid 915934] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:24:43.042306 2026] [security2:error] [pid 915741:tid 915995] [client 14.225.17.146:63482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4Tiq-615n1P-attmzSJgAAAgs"], referer: http://daseighty.net/WP
[Mon Jul 20 06:24:43.053323 2026] [security2:error] [pid 915741:tid 915830] [remote 81.173.115.7:38736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Ti6-615n1P-attmzSLAACA1g"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:43.076399 2026] [security2:error] [pid 915741:tid 915900] [client 35.221.62.63:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.62.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kiakahaconstruction.com"] [uri "/xmlrpc.php"] [unique_id "al4Ti6-615n1P-attmzSLgAAAaw"]
[Mon Jul 20 06:24:43.319156 2026] [security2:error] [pid 915741:tid 915813] [remote 78.46.157.202:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Ti6-615n1P-attmzSSgABk0c"]
[Mon Jul 20 06:24:43.336832 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSTgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.336967 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSTgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.341205 2026] [security2:error] [pid 915741:tid 915877] [client 35.221.62.63:64939] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSTwAAAZU"]
[Mon Jul 20 06:24:43.356987 2026] [security2:error] [pid 915741:tid 915742] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ti6-615n1P-attmzSUgAB_gA"]
[Mon Jul 20 06:24:43.357150 2026] [security2:error] [pid 915741:tid 915982] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ti6-615n1P-attmzSUgAB_gA"]
[Mon Jul 20 06:24:43.458148 2026] [security2:error] [pid 915741:tid 915913] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSRAAAAbk"]
[Mon Jul 20 06:24:43.529924 2026] [security2:error] [pid 915741:tid 915845] [remote 78.46.157.202:55812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Ti6-615n1P-attmzSYwAB5Gc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:43.570059 2026] [security2:error] [pid 915741:tid 915936] [client 34.198.201.66:45116] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSZAAAAdA"], referer: https://windowtx.com
[Mon Jul 20 06:24:43.582966 2026] [security2:error] [pid 915741:tid 915884] [client 35.221.62.63:56511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSZgAAAZw"]
[Mon Jul 20 06:24:43.653329 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:62025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSbwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.653438 2026] [security2:error] [pid 915741:tid 915978] [client 77.110.127.138:62025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSbwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.814447 2026] [security2:error] [pid 915741:tid 915909] [client 57.141.18.23:34502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Th6-615n1P-attmzQ0gABtQ0"]
[Mon Jul 20 06:24:43.870095 2026] [security2:error] [pid 915741:tid 915949] [client 35.221.62.63:52530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSjAAAAd0"]
[Mon Jul 20 06:24:43.891838 2026] [security2:error] [pid 915741:tid 915892] [client 34.73.38.214:52564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ti6-615n1P-attmzSjwAAAaQ"]
[Mon Jul 20 06:24:43.926236 2026] [security2:error] [pid 915741:tid 915964] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSdAAAAew"]
[Mon Jul 20 06:24:43.980851 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSngAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:43.980996 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ti6-615n1P-attmzSngAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.050549 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSogAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.050697 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSogAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.183204 2026] [security2:error] [pid 915741:tid 915929] [client 104.234.53.49:45515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4TjK-615n1P-attmzSqwAAAck"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:44.184525 2026] [security2:error] [pid 915741:tid 915918] [client 35.221.62.63:56595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzSrAAAAb4"]
[Mon Jul 20 06:24:44.358303 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:62029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSwwAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.358386 2026] [security2:error] [pid 915741:tid 915915] [client 77.110.127.138:62029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzSwwAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.432442 2026] [security2:error] [pid 915741:tid 915905] [client 35.221.62.63:52469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzSyQAAAbE"]
[Mon Jul 20 06:24:44.558049 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.22:49102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzSvwABnS0"]
[Mon Jul 20 06:24:44.563099 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:62031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzS1gAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.564781 2026] [security2:error] [pid 915741:tid 915989] [client 77.110.127.138:62031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TjK-615n1P-attmzS1gAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:44.675074 2026] [security2:error] [pid 915741:tid 915880] [client 35.221.62.63:52707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzS3wAAAZg"]
[Mon Jul 20 06:24:44.725277 2026] [security2:error] [pid 915741:tid 915933] [client 14.225.17.146:63815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzSyAAAAc0"], referer: http://transparentservices.online/WP
[Mon Jul 20 06:24:44.815332 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.86:51050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TiK-615n1P-attmzRHgACBBc"]
[Mon Jul 20 06:24:44.939044 2026] [security2:error] [pid 915741:tid 915955] [client 35.221.62.63:58000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TjK-615n1P-attmzS8wAAAeM"]
[Mon Jul 20 06:24:44.977146 2026] [security2:error] [pid 915741:tid 915942] [client 104.234.53.77:52467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TjK-615n1P-attmzS-QAAAdY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:45.106658 2026] [security2:error] [pid 915741:tid 915897] [client 65.1.132.125:10814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4Tja-615n1P-attmzTBwAAAak"]
[Mon Jul 20 06:24:45.163457 2026] [security2:error] [pid 915741:tid 915893] [client 14.225.17.146:63314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4TjK-615n1P-attmzS-gAAAaU"], referer: http://dereckcastellon.com/WP
[Mon Jul 20 06:24:45.239777 2026] [security2:error] [pid 915741:tid 915892] [client 35.221.62.63:64219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTEwAAAaQ"]
[Mon Jul 20 06:24:45.507944 2026] [security2:error] [pid 915741:tid 915964] [client 35.221.62.63:55386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTLQAAAew"]
[Mon Jul 20 06:24:45.533455 2026] [security2:error] [pid 915741:tid 915991] [client 34.73.38.214:54691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTLwAAAgc"]
[Mon Jul 20 06:24:45.843287 2026] [security2:error] [pid 915741:tid 915966] [client 35.221.62.63:52824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tja-615n1P-attmzTRgAAAe4"]
[Mon Jul 20 06:24:46.085776 2026] [security2:error] [pid 915741:tid 915981] [client 104.234.53.84:53047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Tjq-615n1P-attmzTWgAAAf0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:46.143783 2026] [security2:error] [pid 915741:tid 915907] [client 65.1.132.125:10826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4Tjq-615n1P-attmzTXQAAAbM"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:24:46.144303 2026] [security2:error] [pid 915741:tid 915912] [client 35.221.62.63:49329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tjq-615n1P-attmzTXAAAAbg"]
[Mon Jul 20 06:24:46.221679 2026] [security2:error] [pid 915741:tid 915901] [client 14.225.17.146:51614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4Tjq-615n1P-attmzTYgAAAa0"], referer: http://dasmarque.com/WP
[Mon Jul 20 06:24:46.254141 2026] [security2:error] [pid 915741:tid 915984] [client 77.110.127.138:62037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTaAAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.254256 2026] [security2:error] [pid 915741:tid 915984] [client 77.110.127.138:62037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTaAAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.404690 2026] [security2:error] [pid 915741:tid 915956] [client 35.221.62.63:58370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kiakahaconstruction.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tjq-615n1P-attmzTdQAAAeQ"]
[Mon Jul 20 06:24:46.409686 2026] [security2:error] [pid 915741:tid 915947] [client 77.110.127.138:62038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTdgAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.409781 2026] [security2:error] [pid 915741:tid 915947] [client 77.110.127.138:62038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tjq-615n1P-attmzTdgAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:46.425126 2026] [security2:error] [pid 915741:tid 915979] [client 57.141.18.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4Tjq-615n1P-attmzTaQAAAfs"]
[Mon Jul 20 06:24:46.961684 2026] [security2:error] [pid 915741:tid 915977] [client 8.228.127.164:61049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.127.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardsales.com"] [uri "/xmlrpc.php"] [unique_id "al4Tjq-615n1P-attmzTmgAAAfk"]
[Mon Jul 20 06:24:46.961804 2026] [security2:error] [pid 915741:tid 915977] [client 8.228.127.164:61049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eduardsales.com"] [uri "/xmlrpc.php"] [unique_id "al4Tjq-615n1P-attmzTmgAAAfk"]
[Mon Jul 20 06:24:46.984159 2026] [security2:error] [pid 915741:tid 915919] [client 50.116.65.227:57506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4Tjq-615n1P-attmzTnQAAAb8"]
[Mon Jul 20 06:24:46.985340 2026] [security2:error] [pid 915741:tid 915950] [client 14.225.17.146:63904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4Tjq-615n1P-attmzTWQAAAd4"], referer: http://dnsplumbing.com/WP
[Mon Jul 20 06:24:47.052651 2026] [security2:error] [pid 915741:tid 915873] [client 34.73.38.214:58403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tj6-615n1P-attmzTqQAAAZE"]
[Mon Jul 20 06:24:47.203934 2026] [security2:error] [pid 915741:tid 915941] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/git/.ssh/id_rsa"] [unique_id "al4Tj6-615n1P-attmzTtgAAAdU"], referer: https://www.google.com/search?q=nxafjw
[Mon Jul 20 06:24:47.244599 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.54:42124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSMAABliQ"]
[Mon Jul 20 06:24:47.284947 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:62043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tj6-615n1P-attmzTuwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:47.285081 2026] [security2:error] [pid 915741:tid 915879] [client 77.110.127.138:62043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tj6-615n1P-attmzTuwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:47.482231 2026] [security2:error] [pid 915741:tid 915943] [client 14.225.17.146:54384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Tj6-615n1P-attmzTwwAAAdc"], referer: http://northbrookcpa.ca/WP
[Mon Jul 20 06:24:47.614472 2026] [security2:error] [pid 915741:tid 915906] [client 171.60.139.123:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT0gAAAbI"]
[Mon Jul 20 06:24:47.614580 2026] [security2:error] [pid 915741:tid 915906] [client 171.60.139.123:53246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT0gAAAbI"]
[Mon Jul 20 06:24:47.620648 2026] [security2:error] [pid 915741:tid 915910] [client 50.116.65.227:57508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Tj6-615n1P-attmzTuQAAAbY"]
[Mon Jul 20 06:24:47.949845 2026] [security2:error] [pid 915741:tid 915871] [client 50.116.65.227:57524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Tj6-615n1P-attmzT1AAAAY8"]
[Mon Jul 20 06:24:47.962338 2026] [security2:error] [pid 915741:tid 915993] [client 57.141.18.14:21692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ti6-615n1P-attmzSbgACCR0"]
[Mon Jul 20 06:24:47.977849 2026] [security2:error] [pid 915741:tid 915947] [client 112.208.70.94:45637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT8gAAAds"]
[Mon Jul 20 06:24:47.978029 2026] [security2:error] [pid 915741:tid 915947] [client 112.208.70.94:45637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tj6-615n1P-attmzT8gAAAds"]
[Mon Jul 20 06:24:48.095618 2026] [security2:error] [pid 915741:tid 915922] [client 34.73.38.214:58081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TkK-615n1P-attmzUAQAAAcI"]
[Mon Jul 20 06:24:48.397184 2026] [security2:error] [pid 915741:tid 915953] [client 57.141.18.15:51720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzSsAAB4SI"]
[Mon Jul 20 06:24:48.772859 2026] [security2:error] [pid 915741:tid 915903] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../home/admin/.ssh/id_rsa"] [unique_id "al4TkK-615n1P-attmzUPgAAAa8"], referer: https://duckduckgo.com/?q=fz9pz
[Mon Jul 20 06:24:48.922403 2026] [security2:error] [pid 915741:tid 915962] [client 57.141.18.35:61396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TjK-615n1P-attmzS5AAB6jc"]
[Mon Jul 20 06:24:49.087681 2026] [security2:error] [pid 915741:tid 915924] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/passwd"] [unique_id "al4Tka-615n1P-attmzUXgAAAcQ"], referer: https://www.google.com/search?q=jx5j8x
[Mon Jul 20 06:24:49.185186 2026] [security2:error] [pid 915741:tid 915922] [client 103.141.108.143:61614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUbAAAAcI"]
[Mon Jul 20 06:24:49.185310 2026] [security2:error] [pid 915741:tid 915922] [client 103.141.108.143:61614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUbAAAAcI"]
[Mon Jul 20 06:24:49.265129 2026] [security2:error] [pid 915741:tid 915840] [remote 81.173.115.7:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4Tka-615n1P-attmzUdQABtWI"]
[Mon Jul 20 06:24:49.278328 2026] [security2:error] [pid 915741:tid 915953] [client 103.153.183.69:1880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/shadow"] [unique_id "al4Tka-615n1P-attmzUdgAAAeE"], referer: https://t.co/npoa030pbs
[Mon Jul 20 06:24:49.457365 2026] [security2:error] [pid 915741:tid 915880] [client 34.73.38.214:58579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tka-615n1P-attmzUgQAAAZg"]
[Mon Jul 20 06:24:49.470100 2026] [security2:error] [pid 915741:tid 915803] [remote 81.173.115.7:48888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4Tka-615n1P-attmzUggABxj0"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 06:24:49.481768 2026] [security2:error] [pid 915741:tid 915950] [client 158.173.89.95:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tka-615n1P-attmzUgwAAAd4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:24:49.625288 2026] [security2:error] [pid 915741:tid 915968] [client 57.141.18.22:65024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tja-615n1P-attmzTJgAB8Ek"]
[Mon Jul 20 06:24:49.702420 2026] [security2:error] [pid 915741:tid 915945] [client 45.116.69.230:61862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUmwAAAdk"]
[Mon Jul 20 06:24:49.702525 2026] [security2:error] [pid 915741:tid 915945] [client 45.116.69.230:61862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUmwAAAdk"]
[Mon Jul 20 06:24:49.834991 2026] [security2:error] [pid 915741:tid 915951] [client 34.74.185.202:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tka-615n1P-attmzUpAAAAd8"]
[Mon Jul 20 06:24:50.030770 2026] [security2:error] [pid 915741:tid 915942] [client 14.225.17.146:51364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUTQAAAdY"], referer: http://travelbyfire.com/WP
[Mon Jul 20 06:24:50.107125 2026] [security2:error] [pid 915741:tid 915990] [client 57.141.18.85:51990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tja-615n1P-attmzTTAACBjw"]
[Mon Jul 20 06:24:50.157224 2026] [security2:error] [pid 915741:tid 915957] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzT_QAAAeU"]
[Mon Jul 20 06:24:50.271639 2026] [security2:error] [pid 915741:tid 915876] [client 34.74.185.202:60849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tkq-615n1P-attmzUyQAAAZQ"]
[Mon Jul 20 06:24:50.377919 2026] [security2:error] [pid 915741:tid 915910] [client 77.110.127.138:62056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU0QAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.378034 2026] [security2:error] [pid 915741:tid 915910] [client 77.110.127.138:62056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU0QAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.405765 2026] [security2:error] [pid 915741:tid 915989] [client 34.74.185.202:58381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tkq-615n1P-attmzU1AAAAgU"]
[Mon Jul 20 06:24:50.531454 2026] [security2:error] [pid 915741:tid 915896] [client 34.74.185.202:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Tkq-615n1P-attmzU5AAAAag"]
[Mon Jul 20 06:24:50.550381 2026] [security2:error] [pid 915741:tid 915745] [remote 57.141.18.22:53372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4Tkq-615n1P-attmzU6AAB0wM"]
[Mon Jul 20 06:24:50.558612 2026] [security2:error] [pid 915741:tid 915956] [client 77.110.127.138:62057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU6wAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.558687 2026] [security2:error] [pid 915741:tid 915956] [client 77.110.127.138:62057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tkq-615n1P-attmzU6wAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:50.834425 2026] [security2:error] [pid 915741:tid 915947] [client 14.225.17.146:54432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUOQAAAds"], referer: http://jvcmotorsports.com/WP
[Mon Jul 20 06:24:50.899417 2026] [security2:error] [pid 915741:tid 915973] [client 34.74.185.202:57674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tkq-615n1P-attmzVEAAAAfU"]
[Mon Jul 20 06:24:50.921156 2026] [security2:error] [pid 915741:tid 915927] [client 14.225.17.146:51512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4Tkq-615n1P-attmzVDgAAAcc"], referer: https://travelbyfire.com/WP
[Mon Jul 20 06:24:50.966489 2026] [security2:error] [pid 915741:tid 915838] [remote 57.141.18.115:35750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4Tkq-615n1P-attmzVFQABkmA"]
[Mon Jul 20 06:24:50.983778 2026] [security2:error] [pid 915741:tid 915970] [client 34.73.38.214:58880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.aljosour-alarabia.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tkq-615n1P-attmzVFwAAAfI"]
[Mon Jul 20 06:24:51.036274 2026] [security2:error] [pid 915741:tid 915943] [client 34.74.185.202:62688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVHgAAAdc"]
[Mon Jul 20 06:24:51.196537 2026] [security2:error] [pid 915741:tid 915976] [client 77.110.127.138:62060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tk6-615n1P-attmzVKgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:51.196634 2026] [security2:error] [pid 915741:tid 915976] [client 77.110.127.138:62060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tk6-615n1P-attmzVKgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:51.248677 2026] [security2:error] [pid 915741:tid 915974] [client 34.74.185.202:60251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVMAAAAfY"]
[Mon Jul 20 06:24:51.455932 2026] [security2:error] [pid 915741:tid 915919] [client 104.234.53.90:41199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tk6-615n1P-attmzVQAAAAb8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:51.552107 2026] [security2:error] [pid 915741:tid 915945] [client 46.110.96.34:8554] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4Tk6-615n1P-attmzVUQAAAdk"]
[Mon Jul 20 06:24:51.618034 2026] [security2:error] [pid 915741:tid 915896] [client 41.173.37.102:2752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tk6-615n1P-attmzVWQAAAag"]
[Mon Jul 20 06:24:51.618123 2026] [security2:error] [pid 915741:tid 915896] [client 41.173.37.102:2752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tk6-615n1P-attmzVWQAAAag"]
[Mon Jul 20 06:24:51.728861 2026] [security2:error] [pid 915741:tid 915976] [client 34.74.185.202:50889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVcgAAAfg"]
[Mon Jul 20 06:24:51.952233 2026] [security2:error] [pid 915741:tid 915996] [client 34.74.185.202:55026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tk6-615n1P-attmzVgwAAAgw"]
[Mon Jul 20 06:24:52.087177 2026] [security2:error] [pid 915741:tid 915947] [client 34.74.185.202:52364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzVmQAAAds"]
[Mon Jul 20 06:24:52.122319 2026] [security2:error] [pid 915741:tid 915773] [remote 91.142.222.105:39808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4TlK-615n1P-attmzVnwAB1R8"]
[Mon Jul 20 06:24:52.138600 2026] [security2:error] [pid 915741:tid 915927] [client 34.74.185.202:58889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzVoQAAAcc"]
[Mon Jul 20 06:24:52.370607 2026] [security2:error] [pid 915741:tid 915745] [remote 91.142.222.105:39808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4TlK-615n1P-attmzVygABwQM"], referer: https://joulecommunications.com/wp-login.php
[Mon Jul 20 06:24:52.421452 2026] [security2:error] [pid 915741:tid 915942] [client 34.74.185.202:63149] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzV0gAAAdY"]
[Mon Jul 20 06:24:52.539385 2026] [security2:error] [pid 915741:tid 915995] [client 57.141.18.91:24236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUJgACC1Q"]
[Mon Jul 20 06:24:52.569350 2026] [security2:error] [pid 915741:tid 915957] [client 34.74.185.202:51617] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzV4wAAAeU"]
[Mon Jul 20 06:24:52.608423 2026] [security2:error] [pid 915741:tid 915973] [client 14.225.17.146:62479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4TlK-615n1P-attmzVuAAAAfU"], referer: http://hilltopnurseryinc.com/WP
[Mon Jul 20 06:24:52.716635 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TlK-615n1P-attmzV9wAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:52.716733 2026] [security2:error] [pid 915741:tid 915998] [client 77.110.127.138:62065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TlK-615n1P-attmzV9wAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:52.718043 2026] [security2:error] [pid 915741:tid 915936] [client 57.141.18.60:59736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TkK-615n1P-attmzUOgAB0Bk"]
[Mon Jul 20 06:24:52.761160 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:52.761245 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:61439] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:52.761834 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:52.761872 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:61439] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:52.881336 2026] [security2:error] [pid 915741:tid 915931] [client 34.74.185.202:64895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TlK-615n1P-attmzWDwAAAcs"]
[Mon Jul 20 06:24:52.964869 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.115:30076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUUgABlgI"]
[Mon Jul 20 06:24:53.121497 2026] [security2:error] [pid 915741:tid 915916] [client 34.74.185.202:52634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWIAAAAbw"]
[Mon Jul 20 06:24:53.265099 2026] [security2:error] [pid 915741:tid 915971] [client 77.110.127.138:62067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TlK-615n1P-attmzWEQAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:53.270309 2026] [security2:error] [pid 915741:tid 915920] [client 57.141.18.8:34500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUewABwDs"]
[Mon Jul 20 06:24:53.307232 2026] [security2:error] [pid 915741:tid 915979] [client 34.74.185.202:49958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWLwAAAfs"]
[Mon Jul 20 06:24:53.333311 2026] [security2:error] [pid 915741:tid 915886] [client 77.110.127.138:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tla-615n1P-attmzWNQAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:53.333412 2026] [security2:error] [pid 915741:tid 915886] [client 77.110.127.138:62069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tla-615n1P-attmzWNQAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:53.654606 2026] [security2:error] [pid 915741:tid 915989] [client 34.74.185.202:61971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWRwAAAgU"]
[Mon Jul 20 06:24:53.670303 2026] [security2:error] [pid 915741:tid 915993] [client 57.141.18.66:28472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUrAACCUc"]
[Mon Jul 20 06:24:53.689709 2026] [security2:error] [pid 915741:tid 915881] [client 34.74.185.202:54582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tla-615n1P-attmzWSgAAAZk"]
[Mon Jul 20 06:24:53.805951 2026] [security2:error] [pid 915741:tid 915873] [client 57.141.18.53:58234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tka-615n1P-attmzUrwABkUw"]
[Mon Jul 20 06:24:53.968142 2026] [security2:error] [pid 915741:tid 915823] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tla-615n1P-attmzWWgAB5lE"]
[Mon Jul 20 06:24:53.968326 2026] [security2:error] [pid 915741:tid 915958] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4Tla-615n1P-attmzWWgAB5lE"]
[Mon Jul 20 06:24:54.163400 2026] [security2:error] [pid 915741:tid 915934] [client 34.74.185.202:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWZQAAAc4"]
[Mon Jul 20 06:24:54.214141 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tlq-615n1P-attmzWagAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:54.214228 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tlq-615n1P-attmzWagAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:54.295819 2026] [security2:error] [pid 915741:tid 915914] [client 57.141.18.56:46618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tkq-615n1P-attmzVAgABul4"]
[Mon Jul 20 06:24:54.371818 2026] [security2:error] [pid 915741:tid 915905] [client 34.74.185.202:64849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWgAAAAbE"]
[Mon Jul 20 06:24:54.545546 2026] [security2:error] [pid 915741:tid 915938] [client 14.225.17.146:50863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4TlK-615n1P-attmzVmAAAAdI"], referer: http://aandarealtygroup.com/WP
[Mon Jul 20 06:24:54.662403 2026] [security2:error] [pid 915741:tid 915969] [client 77.110.127.138:62076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tlq-615n1P-attmzWcwAAAfE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:54.689607 2026] [security2:error] [pid 915741:tid 915988] [client 57.141.18.96:56888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tk6-615n1P-attmzVJAACBBo"]
[Mon Jul 20 06:24:54.809541 2026] [security2:error] [pid 915741:tid 915992] [client 34.74.185.202:50201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.fansarogroup.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWngAAAgg"]
[Mon Jul 20 06:24:54.858101 2026] [security2:error] [pid 915741:tid 915984] [client 14.251.3.155:55742] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Tlq-615n1P-attmzWpAAAAgA"]
[Mon Jul 20 06:24:54.893638 2026] [security2:error] [pid 915741:tid 915940] [client 34.74.185.202:54062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tlq-615n1P-attmzWqQAAAdQ"]
[Mon Jul 20 06:24:55.062975 2026] [proxy:error] [pid 915741:tid 915892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:55.063076 2026] [proxy_http:error] [pid 915741:tid 915892] [client 34.73.38.214:64888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:55.063857 2026] [proxy:error] [pid 915741:tid 915892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:55.063909 2026] [proxy_http:error] [pid 915741:tid 915892] [client 34.73.38.214:64888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:55.204347 2026] [security2:error] [pid 915741:tid 915882] [client 34.74.185.202:62591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tl6-615n1P-attmzWvAAAAZo"]
[Mon Jul 20 06:24:55.489415 2026] [core:error] [pid 915741:tid 915946] [client 14.225.17.146:62264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WP
[Mon Jul 20 06:24:55.489442 2026] [core:error] [pid 915741:tid 915946] [client 14.225.17.146:62264] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WP
[Mon Jul 20 06:24:55.528393 2026] [security2:error] [pid 915741:tid 915973] [client 93.152.221.118:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Tl6-615n1P-attmzW1QAAAfU"], referer: https://www.facebook.com/
[Mon Jul 20 06:24:55.638974 2026] [security2:error] [pid 915741:tid 915757] [remote 160.187.68.132:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tl6-615n1P-attmzW5AAB6A8"]
[Mon Jul 20 06:24:55.744656 2026] [security2:error] [pid 915741:tid 915782] [remote 17.241.219.182:55794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.219.241.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tl6-615n1P-attmzW6QAB7ig"], referer: https://mezzacraft.com/mosaic-crochet-course-walton-on-thames-monday-daytimes-4-11-24/
[Mon Jul 20 06:24:55.787056 2026] [lsapi:warn] [pid 915741:tid 915903] [client 14.225.17.146:56453] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WP
[Mon Jul 20 06:24:55.787086 2026] [lsapi:warn] [pid 915741:tid 915903] [client 14.225.17.146:56453] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WP
[Mon Jul 20 06:24:55.824935 2026] [security2:error] [pid 915741:tid 915907] [client 93.152.221.118:62397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Tl6-615n1P-attmzW8QAAAbM"]
[Mon Jul 20 06:24:56.136218 2026] [proxy:error] [pid 915741:tid 915917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:56.136294 2026] [proxy_http:error] [pid 915741:tid 915917] [client 34.73.38.214:52740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:56.136933 2026] [proxy:error] [pid 915741:tid 915917] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:56.136961 2026] [proxy_http:error] [pid 915741:tid 915917] [client 34.73.38.214:52740] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:56.165295 2026] [security2:error] [pid 915741:tid 915984] [client 34.74.185.202:62778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TmK-615n1P-attmzXDwAAAgA"]
[Mon Jul 20 06:24:56.225940 2026] [security2:error] [pid 915741:tid 915961] [client 14.225.17.146:56452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXDAAAAek"], referer: http://inspirespublishing.com/WP
[Mon Jul 20 06:24:56.313724 2026] [lsapi:warn] [pid 915741:tid 915991] [client 50.116.65.227:50532] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:56.313757 2026] [lsapi:warn] [pid 915741:tid 915991] [client 50.116.65.227:50532] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:56.329684 2026] [security2:error] [pid 915741:tid 915903] [client 14.225.17.146:56453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Tl6-615n1P-attmzWvwAAAa8"], referer: http://oswegooperatheater.com/WP
[Mon Jul 20 06:24:56.448310 2026] [security2:error] [pid 915741:tid 915749] [remote 160.187.68.132:34906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TmK-615n1P-attmzXKwACCwc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:56.511314 2026] [security2:error] [pid 915741:tid 915905] [client 74.7.228.17:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "zzzwillowzzz.com"] [uri "/robots.txt"] [unique_id "al4TmK-615n1P-attmzXMAAAAbE"]
[Mon Jul 20 06:24:56.531676 2026] [security2:error] [pid 915741:tid 915889] [client 14.225.17.146:64379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4Tlq-615n1P-attmzWrgAAAaE"], referer: http://xp-design.co/WP
[Mon Jul 20 06:24:56.631178 2026] [security2:error] [pid 915741:tid 915949] [client 34.74.185.202:57535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TmK-615n1P-attmzXOQAAAd0"]
[Mon Jul 20 06:24:56.654730 2026] [security2:error] [pid 915741:tid 915896] [client 104.234.53.85:30031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4TmK-615n1P-attmzXOwAAAag"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:56.792552 2026] [security2:error] [pid 915741:tid 915915] [client 57.141.18.105:30092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tla-615n1P-attmzWRgABuzg"]
[Mon Jul 20 06:24:57.085455 2026] [security2:error] [pid 915741:tid 915935] [client 34.74.185.202:55110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tma-615n1P-attmzXVgAAAc8"]
[Mon Jul 20 06:24:57.190302 2026] [lsapi:warn] [pid 915741:tid 915884] [client 14.225.17.146:56623] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WP
[Mon Jul 20 06:24:57.190325 2026] [lsapi:warn] [pid 915741:tid 915884] [client 14.225.17.146:56623] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WP
[Mon Jul 20 06:24:57.250535 2026] [security2:error] [pid 915741:tid 915884] [client 14.225.17.146:56623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXWwAAAZw"], referer: https://oswegooperatheater.com/WP
[Mon Jul 20 06:24:57.558642 2026] [security2:error] [pid 915741:tid 915993] [client 14.225.17.146:62429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXEgAAAgk"], referer: http://phillipbloch.com/WP
[Mon Jul 20 06:24:57.625869 2026] [security2:error] [pid 915741:tid 915929] [client 34.74.185.202:52812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tma-615n1P-attmzXdgAAAck"]
[Mon Jul 20 06:24:57.684830 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:62465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Tma-615n1P-attmzXeQAAAbc"]
[Mon Jul 20 06:24:57.790363 2026] [security2:error] [pid 915741:tid 915944] [client 14.225.17.146:56017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXdQAAAdg"], referer: http://careysheatingandcooling.com/WP
[Mon Jul 20 06:24:57.942401 2026] [security2:error] [pid 915741:tid 915806] [remote 103.82.22.235:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tma-615n1P-attmzXkQACA0A"]
[Mon Jul 20 06:24:57.994915 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:57.994960 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:56270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:57.995402 2026] [proxy:error] [pid 915741:tid 915993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:24:57.995425 2026] [proxy_http:error] [pid 915741:tid 915993] [client 34.73.38.214:56270] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:24:58.296838 2026] [security2:error] [pid 915741:tid 915902] [client 171.60.139.123:53791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tmq-615n1P-attmzXuwAAAa4"]
[Mon Jul 20 06:24:58.296947 2026] [security2:error] [pid 915741:tid 915902] [client 171.60.139.123:53791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tmq-615n1P-attmzXuwAAAa4"]
[Mon Jul 20 06:24:58.335142 2026] [security2:error] [pid 915741:tid 915957] [client 93.152.221.118:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzXvwAAAeU"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:24:58.341073 2026] [security2:error] [pid 915741:tid 915968] [client 77.110.127.138:62088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzXqQAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:58.383368 2026] [security2:error] [pid 915741:tid 915932] [client 104.234.53.53:42835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Tmq-615n1P-attmzXugAAAcw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:58.422319 2026] [security2:error] [pid 915741:tid 915987] [client 34.74.185.202:52448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tmq-615n1P-attmzXxAAAAgM"]
[Mon Jul 20 06:24:58.451878 2026] [security2:error] [pid 915741:tid 915827] [remote 103.82.22.235:46592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzXxgABnVU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:24:58.590849 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:54456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Tmq-615n1P-attmzX1AAAAbc"]
[Mon Jul 20 06:24:58.641808 2026] [security2:error] [pid 915741:tid 915872] [client 57.141.18.35:51378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tl6-615n1P-attmzW3gABkH0"]
[Mon Jul 20 06:24:58.693872 2026] [security2:error] [pid 915741:tid 915917] [client 104.234.53.53:42835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzX2wAAAb0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:24:58.789575 2026] [lsapi:warn] [pid 915741:tid 915945] [client 35.233.110.193:56364] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:58.789593 2026] [lsapi:warn] [pid 915741:tid 915945] [client 35.233.110.193:56364] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:24:58.796817 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tmq-615n1P-attmzX3wAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:58.796905 2026] [security2:error] [pid 915741:tid 915972] [client 77.110.127.138:62090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tmq-615n1P-attmzX3wAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:58.848113 2026] [security2:error] [pid 915741:tid 915945] [client 35.233.110.193:56364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzX3gAAAdk"]
[Mon Jul 20 06:24:58.948993 2026] [security2:error] [pid 915741:tid 915845] [remote 72.167.132.114:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tmq-615n1P-attmzX7AABpWc"]
[Mon Jul 20 06:24:59.140694 2026] [security2:error] [pid 915741:tid 915966] [client 35.233.110.193:56364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.110.233.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/xmlrpc.php"] [unique_id "al4Tm6-615n1P-attmzX_wAAAe4"]
[Mon Jul 20 06:24:59.182913 2026] [security2:error] [pid 915741:tid 915990] [client 57.141.18.91:24280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tl6-615n1P-attmzW-gACBn8"]
[Mon Jul 20 06:24:59.246158 2026] [security2:error] [pid 915741:tid 915837] [remote 72.167.132.114:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tm6-615n1P-attmzYBQABsl8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:24:59.264713 2026] [security2:error] [pid 915741:tid 915916] [client 34.74.185.202:51660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYBwAAAbw"]
[Mon Jul 20 06:24:59.326515 2026] [security2:error] [pid 915741:tid 915900] [client 34.74.185.202:51289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYDAAAAaw"]
[Mon Jul 20 06:24:59.389394 2026] [security2:error] [pid 915741:tid 915905] [client 34.73.38.214:59279] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYFgAAAbE"]
[Mon Jul 20 06:24:59.475481 2026] [security2:error] [pid 915741:tid 915920] [client 14.225.17.146:62496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4Tm6-615n1P-attmzYBgAAAcA"], referer: http://amalia-capital.com/WP
[Mon Jul 20 06:24:59.536025 2026] [security2:error] [pid 915741:tid 915934] [client 57.141.18.114:44202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXHwABziA"]
[Mon Jul 20 06:24:59.603778 2026] [security2:error] [pid 915741:tid 915928] [client 77.110.127.138:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYLwAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.603883 2026] [security2:error] [pid 915741:tid 915928] [client 77.110.127.138:62093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYLwAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.623093 2026] [security2:error] [pid 915741:tid 915955] [client 14.225.17.146:64536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Tm6-615n1P-attmzYCQAAAeM"]
[Mon Jul 20 06:24:59.692462 2026] [security2:error] [pid 915741:tid 915954] [client 34.74.185.202:56372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYNQAAAeI"]
[Mon Jul 20 06:24:59.851319 2026] [security2:error] [pid 915741:tid 915957] [client 77.110.127.138:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYOwAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.851443 2026] [security2:error] [pid 915741:tid 915957] [client 77.110.127.138:62094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tm6-615n1P-attmzYOwAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:24:59.863525 2026] [security2:error] [pid 915741:tid 915958] [client 57.141.18.85:29274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TmK-615n1P-attmzXPgAB5ic"]
[Mon Jul 20 06:24:59.934402 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:62155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tm6-615n1P-attmzYPQAAAZ4"]
[Mon Jul 20 06:24:59.934509 2026] [security2:error] [pid 915741:tid 915886] [client 103.141.108.143:62155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tm6-615n1P-attmzYPQAAAZ4"]
[Mon Jul 20 06:24:59.950892 2026] [security2:error] [pid 915741:tid 915805] [remote 72.252.198.245:55576] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4Tm6-615n1P-attmzYPgABnD8"]
[Mon Jul 20 06:24:59.968020 2026] [security2:error] [pid 915741:tid 915941] [client 35.233.110.193:55598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Tm6-615n1P-attmzYPwAAAdU"]
[Mon Jul 20 06:25:00.053780 2026] [security2:error] [pid 915741:tid 915877] [client 14.225.17.146:56343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzXwwAAAZU"], referer: http://margaretspeckogawa.com/WP
[Mon Jul 20 06:25:00.081468 2026] [security2:error] [pid 915741:tid 915998] [client 34.74.185.202:58748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYRwAAAg4"]
[Mon Jul 20 06:25:00.165267 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.72:37176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXVQAB5B4"]
[Mon Jul 20 06:25:00.283507 2026] [security2:error] [pid 915741:tid 915984] [client 45.116.69.230:62388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TnK-615n1P-attmzYWwAAAgA"]
[Mon Jul 20 06:25:00.283642 2026] [security2:error] [pid 915741:tid 915984] [client 45.116.69.230:62388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TnK-615n1P-attmzYWwAAAgA"]
[Mon Jul 20 06:25:00.407551 2026] [security2:error] [pid 915741:tid 915906] [client 34.74.185.202:54462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiasconscientes.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYZAAAAbI"]
[Mon Jul 20 06:25:00.408112 2026] [security2:error] [pid 915741:tid 915930] [client 14.225.17.146:56367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4TnK-615n1P-attmzYTQAAAco"], referer: http://maxenengineering.com/WP
[Mon Jul 20 06:25:00.545885 2026] [security2:error] [pid 915741:tid 915931] [client 74.208.214.194:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TnK-615n1P-attmzYawAAAcs"]
[Mon Jul 20 06:25:00.642138 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.56:33008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tma-615n1P-attmzXawAB7Xc"]
[Mon Jul 20 06:25:00.813381 2026] [security2:error] [pid 915741:tid 915911] [client 34.74.185.202:52516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYgQAAAbc"]
[Mon Jul 20 06:25:00.823951 2026] [security2:error] [pid 915741:tid 915973] [client 35.233.110.193:52543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TnK-615n1P-attmzYhQAAAfU"]
[Mon Jul 20 06:25:00.905434 2026] [security2:error] [pid 915741:tid 915984] [client 216.73.216.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYgAAAAgA"], referer: https://www.effingweirdmuseums.com/sitemap.xml
[Mon Jul 20 06:25:01.072974 2026] [security2:error] [pid 915741:tid 915818] [remote 176.56.118.182:33576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tna-615n1P-attmzYnQABqUw"]
[Mon Jul 20 06:25:01.140182 2026] [security2:error] [pid 915741:tid 915920] [client 34.74.185.202:49938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.familiaconsciente.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tna-615n1P-attmzYogAAAcA"]
[Mon Jul 20 06:25:01.214402 2026] [security2:error] [pid 915741:tid 915878] [client 57.141.18.126:63606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzXpAABlkk"]
[Mon Jul 20 06:25:01.237280 2026] [security2:error] [pid 915741:tid 915895] [client 14.225.17.146:62009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Tna-615n1P-attmzYoQAAAac"]
[Mon Jul 20 06:25:01.309673 2026] [security2:error] [pid 915741:tid 915864] [remote 176.56.118.182:33576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tna-615n1P-attmzYsAABono"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:01.349005 2026] [security2:error] [pid 915741:tid 915951] [client 14.225.17.146:56249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Tna-615n1P-attmzYrgAAAd8"], referer: https://maxenengineering.com/WP
[Mon Jul 20 06:25:01.445427 2026] [security2:error] [pid 915741:tid 915956] [client 35.233.110.193:61567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tna-615n1P-attmzYtgAAAeQ"]
[Mon Jul 20 06:25:01.560174 2026] [security2:error] [pid 915741:tid 915893] [client 34.73.38.214:50021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tna-615n1P-attmzYvAAAAaU"]
[Mon Jul 20 06:25:01.807016 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tna-615n1P-attmzY1AAAAaA"]
[Mon Jul 20 06:25:01.807131 2026] [security2:error] [pid 915741:tid 915888] [client 112.208.70.94:42141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tna-615n1P-attmzY1AAAAaA"]
[Mon Jul 20 06:25:02.053716 2026] [security2:error] [pid 915741:tid 915887] [client 57.141.18.22:38612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tmq-615n1P-attmzX5gABnxA"]
[Mon Jul 20 06:25:02.301907 2026] [security2:error] [pid 915741:tid 915939] [client 41.173.37.102:3193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tnq-615n1P-attmzZBgAAAdM"]
[Mon Jul 20 06:25:02.301994 2026] [security2:error] [pid 915741:tid 915939] [client 41.173.37.102:3193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Tnq-615n1P-attmzZBgAAAdM"]
[Mon Jul 20 06:25:02.385110 2026] [security2:error] [pid 915741:tid 915872] [client 35.233.110.193:55877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tnq-615n1P-attmzZDwAAAZA"]
[Mon Jul 20 06:25:02.454261 2026] [security2:error] [pid 915741:tid 915956] [client 34.73.38.214:57221] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tnq-615n1P-attmzZFgAAAeQ"]
[Mon Jul 20 06:25:02.514723 2026] [security2:error] [pid 915741:tid 915927] [client 57.141.18.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZDQAAAcc"]
[Mon Jul 20 06:25:02.665008 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:62100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZIgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:02.665164 2026] [security2:error] [pid 915741:tid 915952] [client 77.110.127.138:62100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZIgAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:02.812980 2026] [security2:error] [pid 915741:tid 915886] [client 187.94.223.220:33945] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZMwAAAZ4"]
[Mon Jul 20 06:25:03.010024 2026] [security2:error] [pid 915741:tid 915876] [client 14.225.17.146:62608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZPAAAAZQ"], referer: http://headachescarpaltunnelfibromyalgia.com/WP
[Mon Jul 20 06:25:03.016518 2026] [security2:error] [pid 915741:tid 915886] [client 187.94.223.220:33945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tnq-615n1P-attmzZMwAAAZ4"]
[Mon Jul 20 06:25:03.040051 2026] [security2:error] [pid 915741:tid 915940] [client 35.233.110.193:49719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tn6-615n1P-attmzZSwAAAdQ"]
[Mon Jul 20 06:25:03.073371 2026] [security2:error] [pid 915741:tid 915950] [client 77.110.127.138:62103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZJAAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:03.148664 2026] [security2:error] [pid 915741:tid 915939] [client 116.179.32.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZQQAAAdM"]
[Mon Jul 20 06:25:03.379013 2026] [security2:error] [pid 915741:tid 915896] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.llr.lqn.mybluehost.me"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZSQAAAag"]
[Mon Jul 20 06:25:03.452306 2026] [security2:error] [pid 915741:tid 915955] [client 57.141.18.22:38652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYdwAB4xc"]
[Mon Jul 20 06:25:03.478279 2026] [security2:error] [pid 915741:tid 915872] [client 3.85.191.173:23340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.191.85.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Tn6-615n1P-attmzZaQAAAZA"]
[Mon Jul 20 06:25:03.507737 2026] [security2:error] [pid 915741:tid 915897] [client 43.135.115.233:35540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.115.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/mcd/mcd_quiz.php"] [unique_id "al4Tn6-615n1P-attmzZagAAAak"]
[Mon Jul 20 06:25:03.513114 2026] [security2:error] [pid 915741:tid 915982] [client 57.141.18.13:48906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYeAAB_nQ"]
[Mon Jul 20 06:25:03.650226 2026] [security2:error] [pid 915741:tid 915938] [client 57.141.18.38:54324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TnK-615n1P-attmzYigAB0lI"]
[Mon Jul 20 06:25:03.694093 2026] [security2:error] [pid 915741:tid 915873] [client 98.159.234.160:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tn6-615n1P-attmzZfQAAAZE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:03.780224 2026] [security2:error] [pid 915741:tid 915940] [client 34.73.38.214:63186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tn6-615n1P-attmzZjAAAAdQ"]
[Mon Jul 20 06:25:03.948855 2026] [security2:error] [pid 915741:tid 915965] [client 14.225.17.146:64361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4Tn6-615n1P-attmzZlAAAAe0"], referer: http://nextlvlmarketingco.com/WP
[Mon Jul 20 06:25:03.988938 2026] [security2:error] [pid 915741:tid 915913] [client 35.233.110.193:51369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tn6-615n1P-attmzZmwAAAbk"]
[Mon Jul 20 06:25:04.461199 2026] [security2:error] [pid 915741:tid 915931] [client 3.85.28.216:54886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ToK-615n1P-attmzZwgAAAcs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:25:04.486983 2026] [security2:error] [pid 915741:tid 915872] [client 51.68.236.91:31857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "think-islam.com"] [uri "/robots.txt"] [unique_id "al4ToK-615n1P-attmzZygAAAZA"]
[Mon Jul 20 06:25:04.487120 2026] [security2:error] [pid 915741:tid 915872] [client 51.68.236.91:31857] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "think-islam.com"] [uri "/robots.txt"] [unique_id "al4ToK-615n1P-attmzZygAAAZA"]
[Mon Jul 20 06:25:04.592812 2026] [security2:error] [pid 915741:tid 915868] [remote 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ToK-615n1P-attmzZ1AAByn4"]
[Mon Jul 20 06:25:04.593016 2026] [security2:error] [pid 915741:tid 915930] [client 2607:fb92:d82:c071:6811:72b1:148d:8de3:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "aleishapenny.ca"] [uri "/xmlrpc.php"] [unique_id "al4ToK-615n1P-attmzZ1AAByn4"]
[Mon Jul 20 06:25:04.809676 2026] [security2:error] [pid 915741:tid 915920] [client 57.141.18.21:48446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzY9QABwHI"]
[Mon Jul 20 06:25:04.832544 2026] [security2:error] [pid 915741:tid 915986] [client 34.73.38.214:53443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ToK-615n1P-attmzZ5wAAAgI"]
[Mon Jul 20 06:25:04.852088 2026] [security2:error] [pid 915741:tid 915926] [client 35.233.110.193:54888] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ToK-615n1P-attmzZ6gAAAcY"]
[Mon Jul 20 06:25:04.875264 2026] [security2:error] [pid 915741:tid 915901] [client 57.141.18.39:25607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZBQABrXU"]
[Mon Jul 20 06:25:05.217031 2026] [security2:error] [pid 915741:tid 915976] [client 57.141.18.74:45588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tnq-615n1P-attmzZJQAB-Eo"]
[Mon Jul 20 06:25:05.460089 2026] [security2:error] [pid 915741:tid 915933] [client 223.185.13.213:6453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Toa-615n1P-attmzaDQAAAc0"]
[Mon Jul 20 06:25:05.460239 2026] [security2:error] [pid 915741:tid 915933] [client 223.185.13.213:6453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Toa-615n1P-attmzaDQAAAc0"]
[Mon Jul 20 06:25:05.642724 2026] [security2:error] [pid 915741:tid 915939] [client 35.233.110.193:61647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Toa-615n1P-attmzaFQAAAdM"]
[Mon Jul 20 06:25:05.803220 2026] [security2:error] [pid 915741:tid 915915] [client 34.73.38.214:60651] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Toa-615n1P-attmzaIAAAAbs"]
[Mon Jul 20 06:25:05.890792 2026] [security2:error] [pid 915741:tid 915949] [client 14.225.17.146:62799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4Toa-615n1P-attmzaKAAAAd0"]
[Mon Jul 20 06:25:05.973241 2026] [security2:error] [pid 915741:tid 915982] [client 14.225.17.146:62111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4ToK-615n1P-attmzZtQAAAf4"], referer: http://swafforddetailing.com/WP
[Mon Jul 20 06:25:06.221318 2026] [security2:error] [pid 915741:tid 915928] [client 57.141.18.92:32852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tn6-615n1P-attmzZcgAByHk"]
[Mon Jul 20 06:25:06.286394 2026] [security2:error] [pid 915741:tid 915988] [client 104.234.53.83:55021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Toq-615n1P-attmzaSwAAAgQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:06.431868 2026] [security2:error] [pid 915741:tid 915881] [client 35.233.110.193:53619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Toq-615n1P-attmzaWwAAAZk"]
[Mon Jul 20 06:25:06.461045 2026] [security2:error] [pid 915741:tid 915814] [remote 72.167.132.114:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Toq-615n1P-attmzaXAAB3kg"]
[Mon Jul 20 06:25:06.557600 2026] [security2:error] [pid 915741:tid 915913] [client 57.141.18.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Toq-615n1P-attmzaWQAAAbk"]
[Mon Jul 20 06:25:06.641091 2026] [security2:error] [pid 915741:tid 915750] [remote 97.74.87.194:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4Toq-615n1P-attmzaZwAB4gg"]
[Mon Jul 20 06:25:06.641236 2026] [security2:error] [pid 915741:tid 915954] [client 97.74.87.194:54208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4Toq-615n1P-attmzaZwAB4gg"]
[Mon Jul 20 06:25:06.651248 2026] [security2:error] [pid 915741:tid 915953] [client 57.141.18.44:48044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ToK-615n1P-attmzZqgAB4RY"]
[Mon Jul 20 06:25:06.676269 2026] [security2:error] [pid 915741:tid 915877] [client 57.141.18.50:47646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ToK-615n1P-attmzZsAABlVM"]
[Mon Jul 20 06:25:06.704425 2026] [security2:error] [pid 915741:tid 915874] [client 34.73.38.214:59060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Toq-615n1P-attmzaawAAAZI"]
[Mon Jul 20 06:25:06.728224 2026] [security2:error] [pid 915741:tid 915774] [remote 72.167.132.114:48514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4Toq-615n1P-attmzabAAByCA"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:25:06.835199 2026] [security2:error] [pid 915741:tid 915755] [remote 209.42.18.223:45788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Toq-615n1P-attmzacAABpA0"]
[Mon Jul 20 06:25:07.008219 2026] [security2:error] [pid 915741:tid 915897] [client 14.225.17.146:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4Toq-615n1P-attmzaeQAAAak"], referer: http://entuvy.com/WP
[Mon Jul 20 06:25:07.023012 2026] [security2:error] [pid 915741:tid 915955] [client 35.233.110.193:64926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4To6-615n1P-attmzahQAAAeM"]
[Mon Jul 20 06:25:07.026840 2026] [security2:error] [pid 915741:tid 915810] [remote 209.42.18.223:45788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4To6-615n1P-attmzagwAB3kQ"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:25:07.160795 2026] [security2:error] [pid 915741:tid 915866] [remote 173.249.4.11:29590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4To6-615n1P-attmzakwAB1nw"]
[Mon Jul 20 06:25:07.201781 2026] [proxy:error] [pid 915741:tid 915933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:07.201856 2026] [proxy_http:error] [pid 915741:tid 915933] [client 34.73.38.214:63251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:07.202447 2026] [proxy:error] [pid 915741:tid 915933] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:07.202472 2026] [proxy_http:error] [pid 915741:tid 915933] [client 34.73.38.214:63251] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:07.232052 2026] [security2:error] [pid 915741:tid 915873] [client 14.225.17.146:49240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzalQAAAZE"], referer: http://collectingrealestate.com/WP
[Mon Jul 20 06:25:07.298562 2026] [security2:error] [pid 915741:tid 915932] [client 104.234.53.94:45017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4To6-615n1P-attmzamQAAAcw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:07.368076 2026] [security2:error] [pid 915741:tid 915909] [client 178.20.43.173:50512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.43.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4To6-615n1P-attmzaoAAAAbU"], referer: https://retzkolonglogistics.com/
[Mon Jul 20 06:25:07.376312 2026] [security2:error] [pid 915741:tid 915830] [remote 173.249.4.11:29590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4To6-615n1P-attmzaoQABt1g"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:25:07.717586 2026] [security2:error] [pid 915741:tid 915988] [client 35.233.110.193:51935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4To6-615n1P-attmzauQAAAgQ"]
[Mon Jul 20 06:25:07.914209 2026] [security2:error] [pid 915741:tid 915890] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzawAAAAaI"]
[Mon Jul 20 06:25:08.076971 2026] [security2:error] [pid 915741:tid 915953] [client 50.116.65.227:46164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzazAAAAeE"]
[Mon Jul 20 06:25:08.214649 2026] [security2:error] [pid 915741:tid 915933] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.makeupyourskin.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzaxQAAAc0"]
[Mon Jul 20 06:25:08.286881 2026] [security2:error] [pid 915741:tid 915957] [client 50.116.65.227:46166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4TpK-615n1P-attmza4AAAAeU"]
[Mon Jul 20 06:25:08.318592 2026] [security2:error] [pid 915741:tid 915946] [client 34.73.38.214:55675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TpK-615n1P-attmza7gAAAdo"]
[Mon Jul 20 06:25:08.333178 2026] [security2:error] [pid 915741:tid 915897] [client 35.233.110.193:62828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TpK-615n1P-attmza8QAAAak"]
[Mon Jul 20 06:25:08.926811 2026] [security2:error] [pid 915741:tid 915900] [client 171.60.139.123:54330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TpK-615n1P-attmzbHQAAAaw"]
[Mon Jul 20 06:25:08.926955 2026] [security2:error] [pid 915741:tid 915900] [client 171.60.139.123:54330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TpK-615n1P-attmzbHQAAAaw"]
[Mon Jul 20 06:25:08.992719 2026] [security2:error] [pid 915741:tid 915919] [client 57.141.18.123:53054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Toq-615n1P-attmzafwABvyM"]
[Mon Jul 20 06:25:09.108899 2026] [security2:error] [pid 915741:tid 915885] [client 57.141.18.61:22194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4To6-615n1P-attmzaiwABnSc"]
[Mon Jul 20 06:25:09.195993 2026] [security2:error] [pid 915741:tid 915941] [client 34.73.38.214:65247] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Tpa-615n1P-attmzbMAAAAdU"]
[Mon Jul 20 06:25:09.201217 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:09.201278 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:65407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:09.201853 2026] [proxy:error] [pid 915741:tid 915901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:09.201880 2026] [proxy_http:error] [pid 915741:tid 915901] [client 34.73.38.214:65407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:09.602873 2026] [security2:error] [pid 915741:tid 915881] [client 14.225.17.146:49482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4Tpa-615n1P-attmzbQwAAAZk"], referer: http://cheesewithjam.com/WP
[Mon Jul 20 06:25:10.172790 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.52:25876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TpK-615n1P-attmza4gAB7SI"]
[Mon Jul 20 06:25:10.261568 2026] [security2:error] [pid 915741:tid 915902] [client 14.225.17.146:49247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbZwAAAa4"], referer: http://nomorewetsheets.net/WP
[Mon Jul 20 06:25:10.571802 2026] [security2:error] [pid 915741:tid 915908] [client 103.141.108.143:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbmAAAAbQ"]
[Mon Jul 20 06:25:10.572993 2026] [security2:error] [pid 915741:tid 915908] [client 103.141.108.143:62656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbmAAAAbQ"]
[Mon Jul 20 06:25:10.722291 2026] [security2:error] [pid 915741:tid 915953] [client 103.153.183.69:1196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..\\\\/..\\\\/etc/passwd"] [unique_id "al4Tpq-615n1P-attmzbnwAAAeE"], referer: https://www.reddit.com/
[Mon Jul 20 06:25:10.802836 2026] [security2:error] [pid 915741:tid 915995] [client 77.110.127.138:62126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbkwAAAgs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:10.807451 2026] [security2:error] [pid 915741:tid 915875] [client 57.141.18.4:36546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TpK-615n1P-attmzbEwABkxw"]
[Mon Jul 20 06:25:10.824655 2026] [proxy:error] [pid 915741:tid 915996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:10.824735 2026] [proxy_http:error] [pid 915741:tid 915996] [client 34.73.38.214:61540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:10.825411 2026] [proxy:error] [pid 915741:tid 915996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:10.825454 2026] [proxy_http:error] [pid 915741:tid 915996] [client 34.73.38.214:61540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:10.848088 2026] [security2:error] [pid 915741:tid 915882] [client 34.73.38.214:58304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.arrazoado.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Tpq-615n1P-attmzbpgAAAZo"]
[Mon Jul 20 06:25:10.861023 2026] [security2:error] [pid 915741:tid 915893] [client 45.116.69.230:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbqAAAAaU"]
[Mon Jul 20 06:25:10.861149 2026] [security2:error] [pid 915741:tid 915893] [client 45.116.69.230:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tpq-615n1P-attmzbqAAAAaU"]
[Mon Jul 20 06:25:11.071729 2026] [security2:error] [pid 915741:tid 915989] [client 14.225.17.146:59626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbrQAAAgU"], referer: http://709fx.com/WP
[Mon Jul 20 06:25:11.232293 2026] [security2:error] [pid 915741:tid 915972] [client 57.141.18.65:61246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tpa-615n1P-attmzbOgAB9Fk"]
[Mon Jul 20 06:25:11.270200 2026] [security2:error] [pid 915741:tid 915906] [client 77.110.127.138:62134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzbtwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:11.418481 2026] [proxy:error] [pid 915741:tid 915909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:11.418535 2026] [proxy_http:error] [pid 915741:tid 915909] [client 34.73.38.214:51285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:11.419512 2026] [proxy:error] [pid 915741:tid 915909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:11.419544 2026] [proxy_http:error] [pid 915741:tid 915909] [client 34.73.38.214:51285] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:11.552319 2026] [security2:error] [pid 915741:tid 915951] [client 104.234.53.92:38319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Tp6-615n1P-attmzb6wAAAd8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:11.824477 2026] [security2:error] [pid 915741:tid 915961] [client 57.141.18.12:54724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tpa-615n1P-attmzbXQAB6Wc"]
[Mon Jul 20 06:25:12.253155 2026] [security2:error] [pid 915741:tid 915983] [client 34.73.38.214:65206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TqK-615n1P-attmzcLwAAAf8"]
[Mon Jul 20 06:25:12.344761 2026] [security2:error] [pid 915741:tid 915957] [client 57.141.18.34:58730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tpq-615n1P-attmzbgwAB5Vo"]
[Mon Jul 20 06:25:12.534794 2026] [security2:error] [pid 915741:tid 915841] [remote 173.212.252.15:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4TqK-615n1P-attmzcQAABk2M"]
[Mon Jul 20 06:25:12.773489 2026] [security2:error] [pid 915741:tid 915890] [client 74.208.214.194:57160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TqK-615n1P-attmzcVQAAAaI"]
[Mon Jul 20 06:25:12.782363 2026] [security2:error] [pid 915741:tid 915918] [client 62.150.67.110:62782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4TqK-615n1P-attmzcKAAAAb4"]
[Mon Jul 20 06:25:12.792991 2026] [security2:error] [pid 915741:tid 915816] [remote 173.212.252.15:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4TqK-615n1P-attmzcVwABo0o"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:25:12.827809 2026] [security2:error] [pid 915741:tid 915881] [client 114.119.130.221:38643] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/robots.txt"] [unique_id "al4TqK-615n1P-attmzcWQAAAZk"], referer: http://locketsandcharms.com/robots.txt
[Mon Jul 20 06:25:12.995167 2026] [security2:error] [pid 915741:tid 915984] [client 41.173.37.102:3605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TqK-615n1P-attmzcYwAAAgA"]
[Mon Jul 20 06:25:12.995279 2026] [security2:error] [pid 915741:tid 915984] [client 41.173.37.102:3605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4TqK-615n1P-attmzcYwAAAgA"]
[Mon Jul 20 06:25:13.491679 2026] [security2:error] [pid 915741:tid 915983] [client 34.73.38.214:55708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Tqa-615n1P-attmzchwAAAf8"]
[Mon Jul 20 06:25:13.552401 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzckAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:13.552513 2026] [security2:error] [pid 915741:tid 915887] [client 77.110.127.138:62146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzckAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:13.591509 2026] [security2:error] [pid 915741:tid 915944] [client 14.225.17.146:54992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzcFAAAAdg"], referer: http://idigress.group/WP
[Mon Jul 20 06:25:13.649614 2026] [security2:error] [pid 915741:tid 915989] [client 57.141.18.22:27636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzb6AACBSQ"]
[Mon Jul 20 06:25:13.689046 2026] [security2:error] [pid 915741:tid 915885] [client 14.225.17.146:51217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcjQAAAZ0"], referer: http://solkeetw.com/WP
[Mon Jul 20 06:25:13.691399 2026] [security2:error] [pid 915741:tid 915995] [client 104.234.53.50:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Tqa-615n1P-attmzclwAAAgs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:13.703351 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzcmgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:13.703452 2026] [security2:error] [pid 915741:tid 915996] [client 77.110.127.138:62148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tqa-615n1P-attmzcmgAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:14.028204 2026] [security2:error] [pid 915741:tid 915959] [client 57.141.18.112:20106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tp6-615n1P-attmzcEgAB5xQ"]
[Mon Jul 20 06:25:14.166774 2026] [security2:error] [pid 915741:tid 915994] [client 77.110.127.138:62144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcjAAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:14.268687 2026] [security2:error] [pid 915741:tid 915807] [remote 103.75.185.95:35396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tqq-615n1P-attmzcyAABpkE"]
[Mon Jul 20 06:25:14.268978 2026] [security2:error] [pid 915741:tid 915894] [client 103.75.185.95:35396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Tqq-615n1P-attmzcyAABpkE"]
[Mon Jul 20 06:25:15.018371 2026] [security2:error] [pid 915741:tid 915763] [remote 103.75.185.95:41072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4Tq6-615n1P-attmzdCQABwRU"]
[Mon Jul 20 06:25:15.042743 2026] [security2:error] [pid 915741:tid 915905] [client 57.141.18.33:48956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcbQABsRo"]
[Mon Jul 20 06:25:15.143283 2026] [security2:error] [pid 915741:tid 915958] [client 57.141.18.112:20112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqa-615n1P-attmzcewAB5mY"]
[Mon Jul 20 06:25:15.187297 2026] [security2:error] [pid 915741:tid 915892] [client 45.157.112.60:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tq6-615n1P-attmzdEQAAAaQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:15.208253 2026] [security2:error] [pid 915741:tid 915989] [client 112.208.70.94:42586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tq6-615n1P-attmzdEgAAAgU"]
[Mon Jul 20 06:25:15.208364 2026] [security2:error] [pid 915741:tid 915989] [client 112.208.70.94:42586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tq6-615n1P-attmzdEgAAAgU"]
[Mon Jul 20 06:25:15.391963 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:62156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdJgAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:15.392109 2026] [security2:error] [pid 915741:tid 915987] [client 77.110.127.138:62156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdJgAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:15.424506 2026] [security2:error] [pid 915741:tid 915932] [client 14.225.17.146:59450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4Tqq-615n1P-attmzcvQAAAcw"], referer: http://backandneckpainrelieflaceychiropractor.com/WP
[Mon Jul 20 06:25:15.478562 2026] [security2:error] [pid 915741:tid 915991] [client 34.73.38.214:55590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tq6-615n1P-attmzdMwAAAgc"]
[Mon Jul 20 06:25:15.487384 2026] [cgid:error] [pid 915741:tid 915877] [client 66.132.186.171:25792] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: http://www.smtracking.genesismbs.com:80/cgi-bin
[Mon Jul 20 06:25:15.538384 2026] [security2:error] [pid 915741:tid 915760] [remote 103.75.185.95:41072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4Tq6-615n1P-attmzdNQABkhI"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 06:25:15.866396 2026] [security2:error] [pid 915741:tid 915914] [client 62.197.45.116:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.45.197.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.maxenengineering.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdSgAAAbo"], referer: https://www.maxenengineering.com/complete-construction-equipment-under-one-roof/
[Mon Jul 20 06:25:15.866501 2026] [security2:error] [pid 915741:tid 915914] [client 62.197.45.116:53333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.maxenengineering.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tq6-615n1P-attmzdSgAAAbo"], referer: https://www.maxenengineering.com/complete-construction-equipment-under-one-roof/
[Mon Jul 20 06:25:16.035336 2026] [security2:error] [pid 915741:tid 915920] [client 34.73.38.214:53220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4TrK-615n1P-attmzdWAAAAcA"]
[Mon Jul 20 06:25:16.070856 2026] [security2:error] [pid 915741:tid 915965] [client 57.141.18.111:24068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqq-615n1P-attmzcxAAB7VM"]
[Mon Jul 20 06:25:16.155403 2026] [security2:error] [pid 915741:tid 915998] [client 57.141.18.4:36568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tqq-615n1P-attmzc0gACDi4"]
[Mon Jul 20 06:25:16.218842 2026] [security2:error] [pid 915741:tid 915921] [client 50.116.65.227:58050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4TrK-615n1P-attmzdYgAAAcE"]
[Mon Jul 20 06:25:16.228282 2026] [security2:error] [pid 915741:tid 915913] [client 50.116.65.227:58058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4TrK-615n1P-attmzdYwAAAbk"]
[Mon Jul 20 06:25:16.446783 2026] [security2:error] [pid 915741:tid 915932] [client 185.132.186.96:48305] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "harborhealth.us"] [uri "/wordpress/wp-admin/includes/"] [unique_id "al4TrK-615n1P-attmzdegAAAcw"]
[Mon Jul 20 06:25:16.616493 2026] [security2:error] [pid 915741:tid 915993] [client 77.110.127.138:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdjAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.616593 2026] [security2:error] [pid 915741:tid 915993] [client 77.110.127.138:62159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdjAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767841 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:62161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlwAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767843 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767944 2026] [security2:error] [pid 915741:tid 915970] [client 77.110.127.138:62161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlwAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.767944 2026] [security2:error] [pid 915741:tid 915894] [client 77.110.127.138:62160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TrK-615n1P-attmzdlgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:16.920574 2026] [security2:error] [pid 915741:tid 915808] [remote 100.42.189.89:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4TrK-615n1P-attmzdpwABlEI"]
[Mon Jul 20 06:25:16.935672 2026] [security2:error] [pid 915741:tid 915758] [remote 91.142.222.105:57132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4TrK-615n1P-attmzdpQABwRA"]
[Mon Jul 20 06:25:16.982721 2026] [security2:error] [pid 915741:tid 915956] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TrK-615n1P-attmzdnQAAAeQ"]
[Mon Jul 20 06:25:17.001453 2026] [security2:error] [pid 915741:tid 915933] [client 34.73.38.214:56882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Tra-615n1P-attmzdrAAAAc0"]
[Mon Jul 20 06:25:17.168509 2026] [security2:error] [pid 915741:tid 915809] [remote 91.142.222.105:57132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4Tra-615n1P-attmzdswACDkM"], referer: https://blaizeaccountingservices.com/wp-login.php
[Mon Jul 20 06:25:17.175413 2026] [security2:error] [pid 915741:tid 915742] [remote 100.42.189.89:46348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4Tra-615n1P-attmzdtAAB1wA"], referer: https://royalart-lb.com/wp-login.php
[Mon Jul 20 06:25:17.448794 2026] [security2:error] [pid 915741:tid 915901] [client 14.225.17.146:58443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzdvAAAAa0"]
[Mon Jul 20 06:25:17.655387 2026] [security2:error] [pid 915741:tid 915927] [client 77.110.127.138:62164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzdywAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:17.986148 2026] [security2:error] [pid 915741:tid 915976] [client 187.94.223.220:34189] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tra-615n1P-attmzd7wAAAfg"]
[Mon Jul 20 06:25:18.060114 2026] [security2:error] [pid 915741:tid 915953] [client 104.234.53.71:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Trq-615n1P-attmzd9AAAAeE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:18.145740 2026] [security2:error] [pid 915741:tid 915976] [client 187.94.223.220:34189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tra-615n1P-attmzd7wAAAfg"]
[Mon Jul 20 06:25:18.428650 2026] [core:error] [pid 915741:tid 915934] [client 14.225.17.146:58432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:18.428672 2026] [core:error] [pid 915741:tid 915934] [client 14.225.17.146:58432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:18.498167 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Trq-615n1P-attmzeHgAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:18.498283 2026] [security2:error] [pid 915741:tid 915903] [client 77.110.127.138:62165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Trq-615n1P-attmzeHgAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:18.527101 2026] [security2:error] [pid 915741:tid 915912] [client 57.141.18.22:45698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TrK-615n1P-attmzdiwABuFE"]
[Mon Jul 20 06:25:18.711401 2026] [security2:error] [pid 915741:tid 915865] [remote 154.66.198.148:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4Trq-615n1P-attmzeKQACCns"]
[Mon Jul 20 06:25:18.929449 2026] [security2:error] [pid 915741:tid 915998] [client 14.225.17.146:51092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4Trq-615n1P-attmzeNQAAAg4"], referer: http://sarahholyfield.com/WP
[Mon Jul 20 06:25:19.076237 2026] [security2:error] [pid 915741:tid 915908] [client 57.141.18.14:47066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzdtgABtBg"]
[Mon Jul 20 06:25:19.142212 2026] [security2:error] [pid 915741:tid 915974] [client 34.73.38.214:50795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Tr6-615n1P-attmzeWwAAAfY"]
[Mon Jul 20 06:25:19.243193 2026] [security2:error] [pid 915741:tid 915754] [remote 154.66.198.148:58606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4Tr6-615n1P-attmzeZQABzgw"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:25:19.550987 2026] [security2:error] [pid 915741:tid 915857] [remote 20.89.80.94:26824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4Tr6-615n1P-attmzegAAB7nM"]
[Mon Jul 20 06:25:19.570305 2026] [security2:error] [pid 915741:tid 915899] [client 14.225.17.146:58257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4Trq-615n1P-attmzeFgAAAas"], referer: http://idigress.agency/WP
[Mon Jul 20 06:25:19.688077 2026] [security2:error] [pid 915741:tid 915990] [client 171.60.139.123:54850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tr6-615n1P-attmzejQAAAgY"]
[Mon Jul 20 06:25:19.688389 2026] [security2:error] [pid 915741:tid 915990] [client 171.60.139.123:54850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Tr6-615n1P-attmzejQAAAgY"]
[Mon Jul 20 06:25:19.919994 2026] [security2:error] [pid 915741:tid 915777] [remote 20.89.80.94:26824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4Tr6-615n1P-attmzeoQAB9iM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:25:19.951948 2026] [security2:error] [pid 915741:tid 915971] [client 57.141.18.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Tr6-615n1P-attmzemQAAAfM"]
[Mon Jul 20 06:25:20.100328 2026] [security2:error] [pid 915741:tid 915993] [client 14.225.17.146:63740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4Tra-615n1P-attmzd8wAAAgk"], referer: http://www.justinagrayman.com/WP
[Mon Jul 20 06:25:20.259513 2026] [security2:error] [pid 915741:tid 915987] [client 34.73.38.214:53476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TsK-615n1P-attmzewQAAAgM"]
[Mon Jul 20 06:25:20.396740 2026] [security2:error] [pid 915741:tid 915894] [client 104.234.53.50:47959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4TsK-615n1P-attmzezQAAAaY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:20.589551 2026] [security2:error] [pid 915741:tid 915896] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4TsK-615n1P-attmze0gAAAag"]
[Mon Jul 20 06:25:20.661622 2026] [security2:error] [pid 915741:tid 915819] [remote 81.173.115.7:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TsK-615n1P-attmze4wACCE0"]
[Mon Jul 20 06:25:21.378466 2026] [security2:error] [pid 915741:tid 915759] [remote 57.141.18.49:33050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tr6-615n1P-attmzeegABkhE"]
[Mon Jul 20 06:25:21.519581 2026] [http2:info] [pid 925208:tid 925208] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:25:21.542959 2026] [security2:error] [pid 925208:tid 925347] [client 34.73.38.214:60324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TscRX7OrFkv0FyuIMkwAAAAk"]
[Mon Jul 20 06:25:21.565850 2026] [security2:error] [pid 915741:tid 915989] [client 57.141.18.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4Trq-615n1P-attmzeMgAAAgU"]
[Mon Jul 20 06:25:21.591422 2026] [security2:error] [pid 925208:tid 925359] [client 54.244.177.189:32636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4TscRX7OrFkv0FyuIMpAAAABU"]
[Mon Jul 20 06:25:21.591423 2026] [security2:error] [pid 925208:tid 925363] [client 34.221.76.50:65156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4TscRX7OrFkv0FyuIMowAAABk"]
[Mon Jul 20 06:25:21.803506 2026] [security2:error] [pid 925208:tid 925348] [client 103.141.108.143:63120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM1gAAAAo"]
[Mon Jul 20 06:25:21.803726 2026] [security2:error] [pid 925208:tid 925348] [client 103.141.108.143:63120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM1gAAAAo"]
[Mon Jul 20 06:25:21.853299 2026] [security2:error] [pid 925208:tid 925449] [client 34.73.38.214:50574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4TscRX7OrFkv0FyuIM3AAAAG8"]
[Mon Jul 20 06:25:21.862925 2026] [security2:error] [pid 925208:tid 925371] [client 45.116.69.230:63506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM3wAAACE"]
[Mon Jul 20 06:25:21.863084 2026] [security2:error] [pid 925208:tid 925371] [client 45.116.69.230:63506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TscRX7OrFkv0FyuIM3wAAACE"]
[Mon Jul 20 06:25:21.867304 2026] [security2:error] [pid 925208:tid 925239] [remote 81.173.115.7:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4TscRX7OrFkv0FyuIM4AAADh4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:25:21.942195 2026] [security2:error] [pid 915741:tid 915839] [remote 57.141.18.49:33054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tr6-615n1P-attmzeqQABumE"]
[Mon Jul 20 06:25:22.180115 2026] [security2:error] [pid 925208:tid 925423] [client 185.68.184.237:57576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.184.68.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuIM-AAAAFU"], referer: https://amberhillstyle.com/cgi-sys/suspendedpage.cgi
[Mon Jul 20 06:25:22.180143 2026] [security2:error] [pid 925208:tid 925249] [remote 38.242.157.30:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4TssRX7OrFkv0FyuIM-QAAHyg"]
[Mon Jul 20 06:25:22.201038 2026] [security2:error] [pid 925208:tid 925356] [client 187.94.223.220:34269] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TssRX7OrFkv0FyuIM-wAAABI"]
[Mon Jul 20 06:25:22.370141 2026] [security2:error] [pid 925208:tid 925356] [client 187.94.223.220:34269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TssRX7OrFkv0FyuIM-wAAABI"]
[Mon Jul 20 06:25:22.501352 2026] [security2:error] [pid 925208:tid 925262] [remote 38.242.157.30:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4TssRX7OrFkv0FyuINEgAABjU"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:25:22.759001 2026] [security2:error] [pid 925208:tid 925373] [client 34.73.38.214:61840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TssRX7OrFkv0FyuINHwAAACM"]
[Mon Jul 20 06:25:22.779679 2026] [security2:error] [pid 925208:tid 925362] [client 104.234.53.55:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4TssRX7OrFkv0FyuINIAAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:23.314406 2026] [security2:error] [pid 925208:tid 925401] [client 43.135.107.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Ts8RX7OrFkv0FyuINTwAAAD8"]
[Mon Jul 20 06:25:23.573481 2026] [security2:error] [pid 925208:tid 925458] [client 41.173.37.102:3814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.37.173.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINaAAAAHg"]
[Mon Jul 20 06:25:23.573565 2026] [security2:error] [pid 925208:tid 925458] [client 41.173.37.102:3814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drawingthedog.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINaAAAAHg"]
[Mon Jul 20 06:25:23.726392 2026] [security2:error] [pid 925208:tid 925355] [client 57.141.18.110:51426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TscRX7OrFkv0FyuIMngAAEQU"]
[Mon Jul 20 06:25:23.770987 2026] [security2:error] [pid 925208:tid 925424] [client 34.73.38.214:53151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.awj.kzx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ts8RX7OrFkv0FyuINdQAAAFY"]
[Mon Jul 20 06:25:23.898475 2026] [security2:error] [pid 925208:tid 925306] [remote 72.167.132.114:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINeAAAUWE"]
[Mon Jul 20 06:25:23.898697 2026] [security2:error] [pid 925208:tid 925419] [client 72.167.132.114:43804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4Ts8RX7OrFkv0FyuINeAAAUWE"]
[Mon Jul 20 06:25:23.973235 2026] [security2:error] [pid 925208:tid 925453] [client 57.141.18.109:31008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TscRX7OrFkv0FyuIM6AAAcyE"]
[Mon Jul 20 06:25:24.076500 2026] [security2:error] [pid 925208:tid 925361] [client 57.141.18.88:40810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TscRX7OrFkv0FyuIM8gAAFyU"]
[Mon Jul 20 06:25:24.097912 2026] [security2:error] [pid 925208:tid 925317] [remote 192.241.143.148:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TtMRX7OrFkv0FyuINkQAACGw"]
[Mon Jul 20 06:25:24.308516 2026] [security2:error] [pid 925208:tid 925324] [remote 192.241.143.148:49876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4TtMRX7OrFkv0FyuINpgAAInM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:24.578267 2026] [security2:error] [pid 925208:tid 925331] [remote 15.206.251.117:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TtMRX7OrFkv0FyuINtwAAHHo"]
[Mon Jul 20 06:25:24.764494 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TtMRX7OrFkv0FyuINwAAALn0"], referer: http://aleishapenny.ca/WP
[Mon Jul 20 06:25:24.771155 2026] [security2:error] [pid 925208:tid 925408] [client 146.75.222.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuINKgAAAEY"]
[Mon Jul 20 06:25:24.913456 2026] [security2:error] [pid 925208:tid 925358] [client 57.141.18.91:41938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuINKQAAFEA"]
[Mon Jul 20 06:25:24.928372 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.110:51440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TssRX7OrFkv0FyuINLQAATkI"]
[Mon Jul 20 06:25:25.061438 2026] [security2:error] [pid 925208:tid 925396] [client 57.141.18.50:64466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ts8RX7OrFkv0FyuINQAAAOkg"]
[Mon Jul 20 06:25:25.156805 2026] [security2:error] [pid 925208:tid 925220] [remote 15.206.251.117:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4TtcRX7OrFkv0FyuIN4wAABgs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:25:25.267962 2026] [security2:error] [pid 925208:tid 925457] [client 14.225.17.146:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIN4AAAAHc"], referer: http://ncsynchro.com/WP
[Mon Jul 20 06:25:25.288125 2026] [security2:error] [pid 925208:tid 925341] [client 57.141.18.49:33062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ts8RX7OrFkv0FyuINUQAAA04"]
[Mon Jul 20 06:25:25.297820 2026] [proxy:error] [pid 925208:tid 925401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.297857 2026] [proxy_http:error] [pid 925208:tid 925401] [client 205.210.31.2:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.298275 2026] [proxy:error] [pid 925208:tid 925401] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.298296 2026] [proxy_http:error] [pid 925208:tid 925401] [client 205.210.31.2:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.298987 2026] [proxy:error] [pid 925208:tid 925386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.299095 2026] [proxy_http:error] [pid 925208:tid 925386] [client 205.210.31.2:60950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.300223 2026] [proxy:error] [pid 925208:tid 925386] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:25:25.300262 2026] [proxy_http:error] [pid 925208:tid 925386] [client 205.210.31.2:60950] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:25:25.514553 2026] [security2:error] [pid 925208:tid 925365] [client 87.199.196.160:52830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.justinagrayman.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOBgAAABs"], referer: https://www.justinagrayman.com/bw-2/
[Mon Jul 20 06:25:25.514688 2026] [security2:error] [pid 925208:tid 925365] [client 87.199.196.160:52830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.justinagrayman.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOBgAAABs"], referer: https://www.justinagrayman.com/bw-2/
[Mon Jul 20 06:25:25.536039 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOCgAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.536130 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:62167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOCgAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.659835 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIODAAALhg"], referer: https://aleishapenny.ca/WP
[Mon Jul 20 06:25:25.707622 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOIwAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.707740 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOIwAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:25.834484 2026] [security2:error] [pid 925208:tid 925344] [client 74.7.227.179:42498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIOIQAABis"], referer: https://tejasenvironmental.com/p=894903
[Mon Jul 20 06:25:25.927985 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:62201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOMQAAAD8"]
[Mon Jul 20 06:25:25.928091 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:62201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtcRX7OrFkv0FyuIOMQAAAD8"]
[Mon Jul 20 06:25:26.039823 2026] [security2:error] [pid 925208:tid 925263] [remote 5.161.225.162:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TtsRX7OrFkv0FyuIOOQAABzY"]
[Mon Jul 20 06:25:26.204990 2026] [security2:error] [pid 925208:tid 925465] [client 57.141.18.33:29378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtMRX7OrFkv0FyuINkwAAf20"]
[Mon Jul 20 06:25:26.312861 2026] [security2:error] [pid 925208:tid 925274] [remote 5.161.225.162:38252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TtsRX7OrFkv0FyuIOTAAAIkE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:26.539192 2026] [security2:error] [pid 925208:tid 925405] [client 77.110.127.138:62196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIOEwAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:26.824302 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOcwAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:26.824418 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOcwAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:26.843527 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:32560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TtsRX7OrFkv0FyuIOdgAAADg"]
[Mon Jul 20 06:25:26.843635 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:32560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TtsRX7OrFkv0FyuIOdgAAADg"]
[Mon Jul 20 06:25:26.880455 2026] [security2:error] [pid 925208:tid 925409] [client 45.217.95.181:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOawAAAEc"]
[Mon Jul 20 06:25:26.926826 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOfAAAACk"]
[Mon Jul 20 06:25:26.926945 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TtsRX7OrFkv0FyuIOfAAAACk"]
[Mon Jul 20 06:25:27.158068 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOegAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:27.174095 2026] [security2:error] [pid 925208:tid 925414] [client 150.109.154.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOggAATFo"], referer: https://www.aleishapenny.ca/listing/page/132?view=list&paged=1&posts_per_page=24
[Mon Jul 20 06:25:27.201229 2026] [security2:error] [pid 925208:tid 925464] [client 57.141.18.123:27104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIN5AAAfhQ"]
[Mon Jul 20 06:25:27.320615 2026] [security2:error] [pid 925208:tid 925392] [client 112.208.70.94:42989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOpwAAADY"]
[Mon Jul 20 06:25:27.320821 2026] [security2:error] [pid 925208:tid 925392] [client 112.208.70.94:42989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOpwAAADY"]
[Mon Jul 20 06:25:27.321936 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:64207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOnQAAAE0"], referer: http://maplerespiteservices.com/WP
[Mon Jul 20 06:25:27.425509 2026] [security2:error] [pid 925208:tid 925434] [client 57.141.18.42:24576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtcRX7OrFkv0FyuIN9AAAYBw"]
[Mon Jul 20 06:25:27.488941 2026] [security2:error] [pid 925208:tid 925301] [remote 81.173.115.7:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOtQAASlw"]
[Mon Jul 20 06:25:27.516407 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOuAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:27.516507 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOuAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:27.702900 2026] [security2:error] [pid 925208:tid 925313] [remote 81.173.115.7:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOwwAAT2g"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:25:27.760464 2026] [security2:error] [pid 925208:tid 925390] [client 14.225.17.146:64362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOPAAAADQ"], referer: http://secretkeynumerology.com/WP
[Mon Jul 20 06:25:27.761591 2026] [security2:error] [pid 925208:tid 925442] [client 13.201.64.214:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOxgAAAGg"]
[Mon Jul 20 06:25:27.761685 2026] [security2:error] [pid 925208:tid 925442] [client 13.201.64.214:56336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOxgAAAGg"]
[Mon Jul 20 06:25:27.884698 2026] [security2:error] [pid 925208:tid 925465] [client 158.173.166.181:22261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tt8RX7OrFkv0FyuIOzQAAAH8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:28.103248 2026] [security2:error] [pid 925208:tid 925333] [remote 5.161.225.162:38266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIO3wAALnw"]
[Mon Jul 20 06:25:28.268663 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIO6wAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.268800 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIO6wAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.324794 2026] [security2:error] [pid 925208:tid 925273] [remote 5.161.225.162:38266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIO9AAACkA"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:25:28.457265 2026] [security2:error] [pid 925208:tid 925227] [remote 20.153.140.50:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIPAgAAFBI"]
[Mon Jul 20 06:25:28.483764 2026] [security2:error] [pid 925208:tid 925440] [client 57.141.18.103:31888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TtsRX7OrFkv0FyuIOVQAAZkc"]
[Mon Jul 20 06:25:28.520413 2026] [security2:error] [pid 925208:tid 925395] [client 192.178.16.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4Tt8RX7OrFkv0FyuIO1wAAOXQ"], referer: https://packerjanitorial.com/checkout/order-pay/34096/
[Mon Jul 20 06:25:28.637270 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPDQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.637373 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPDQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.786738 2026] [security2:error] [pid 925208:tid 925441] [client 14.225.17.146:58599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4TuMRX7OrFkv0FyuIPCAAAAGc"], referer: https://secretkeynumerology.com/WP
[Mon Jul 20 06:25:28.843786 2026] [security2:error] [pid 925208:tid 925347] [client 14.225.17.146:58665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4TuMRX7OrFkv0FyuIPGQAAAAk"]
[Mon Jul 20 06:25:28.853434 2026] [security2:error] [pid 925208:tid 925221] [remote 20.153.140.50:37946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4TuMRX7OrFkv0FyuIPIgAAKQw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:25:28.870694 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPJgAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:28.870804 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TuMRX7OrFkv0FyuIPJgAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.144313 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPPgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.144404 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPPgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.430692 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:62219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4TucRX7OrFkv0FyuIPRAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.549428 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPYQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.549523 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPYQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.736788 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPdwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.736895 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TucRX7OrFkv0FyuIPdwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:29.744544 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:58565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4TuMRX7OrFkv0FyuIO7AAAACM"]
[Mon Jul 20 06:25:30.121704 2026] [security2:error] [pid 925208:tid 925401] [client 34.74.185.202:50225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4TusRX7OrFkv0FyuIPlAAAAD8"]
[Mon Jul 20 06:25:30.401568 2026] [security2:error] [pid 925208:tid 925454] [client 77.110.127.138:62227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPqgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.401668 2026] [security2:error] [pid 925208:tid 925454] [client 77.110.127.138:62227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPqgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.537296 2026] [security2:error] [pid 925208:tid 925449] [client 171.60.139.123:55366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TusRX7OrFkv0FyuIPtQAAAG8"]
[Mon Jul 20 06:25:30.537408 2026] [security2:error] [pid 925208:tid 925449] [client 171.60.139.123:55366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TusRX7OrFkv0FyuIPtQAAAG8"]
[Mon Jul 20 06:25:30.539869 2026] [security2:error] [pid 925208:tid 925437] [client 34.74.185.202:57311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4TusRX7OrFkv0FyuIPtgAAAGM"]
[Mon Jul 20 06:25:30.569872 2026] [security2:error] [pid 925208:tid 925339] [client 187.94.223.220:34390] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPuQAAAAE"]
[Mon Jul 20 06:25:30.665803 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:58591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4TusRX7OrFkv0FyuIPtwAAACM"], referer: http://effingweirdmuseums.com/WP
[Mon Jul 20 06:25:30.714682 2026] [security2:error] [pid 925208:tid 925339] [client 187.94.223.220:34390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "factsandminds.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPuQAAAAE"]
[Mon Jul 20 06:25:30.747507 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPwgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.747600 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPwgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.819635 2026] [security2:error] [pid 925208:tid 925418] [client 34.74.185.202:56629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4TusRX7OrFkv0FyuIPyQAAAFA"]
[Mon Jul 20 06:25:30.832441 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPygAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:30.832604 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TusRX7OrFkv0FyuIPygAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:31.151563 2026] [security2:error] [pid 925208:tid 925365] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TusRX7OrFkv0FyuIP4QAAABs"]
[Mon Jul 20 06:25:31.175809 2026] [security2:error] [pid 925208:tid 925409] [client 136.107.64.51:54419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sgmachinehouston.com"] [uri "/xmlrpc.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP6QAAAEc"]
[Mon Jul 20 06:25:31.175910 2026] [security2:error] [pid 925208:tid 925409] [client 136.107.64.51:54419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sgmachinehouston.com"] [uri "/xmlrpc.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP6QAAAEc"]
[Mon Jul 20 06:25:31.214205 2026] [security2:error] [pid 925208:tid 925430] [client 34.74.185.202:61508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Tu8RX7OrFkv0FyuIP6wAAAFw"]
[Mon Jul 20 06:25:31.536617 2026] [security2:error] [pid 925208:tid 925427] [client 14.225.17.146:58514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP5QAAAFk"]
[Mon Jul 20 06:25:31.571846 2026] [security2:error] [pid 925208:tid 925399] [client 14.225.17.146:59235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Tu8RX7OrFkv0FyuIQBwAAAD0"], referer: https://effingweirdmuseums.com/WP
[Mon Jul 20 06:25:31.883976 2026] [security2:error] [pid 925208:tid 925338] [client 34.74.185.202:54101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Tu8RX7OrFkv0FyuIQLAAAAAA"]
[Mon Jul 20 06:25:32.015707 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQNwAAACc"]
[Mon Jul 20 06:25:32.016781 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:63594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQNwAAACc"]
[Mon Jul 20 06:25:32.317913 2026] [security2:error] [pid 925208:tid 925358] [client 45.116.69.230:64028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQRQAAABQ"]
[Mon Jul 20 06:25:32.318111 2026] [security2:error] [pid 925208:tid 925358] [client 45.116.69.230:64028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQRQAAABQ"]
[Mon Jul 20 06:25:32.422180 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:3988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQSgAAAD8"]
[Mon Jul 20 06:25:32.422345 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:3988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4TvMRX7OrFkv0FyuIQSgAAAD8"]
[Mon Jul 20 06:25:32.572571 2026] [security2:error] [pid 925208:tid 925465] [client 14.225.17.146:58925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Tu8RX7OrFkv0FyuIP5wAAAH8"], referer: http://tntcatholic.com/WP
[Mon Jul 20 06:25:32.758292 2026] [security2:error] [pid 925208:tid 925396] [client 34.74.185.202:52886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4TvMRX7OrFkv0FyuIQcAAAADo"]
[Mon Jul 20 06:25:32.847990 2026] [security2:error] [pid 925208:tid 925394] [client 14.225.17.146:57805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQaQAAADg"], referer: http://longevityperformanceclinic.com/WP
[Mon Jul 20 06:25:33.395803 2026] [security2:error] [pid 925208:tid 925341] [client 34.74.185.202:49938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4TvcRX7OrFkv0FyuIQpAAAAAM"]
[Mon Jul 20 06:25:34.075872 2026] [security2:error] [pid 925208:tid 925409] [client 14.225.17.146:57250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQegAAAEc"], referer: http://christiancountytrumpet.com/WP
[Mon Jul 20 06:25:34.240967 2026] [security2:error] [pid 925208:tid 925375] [client 57.141.18.66:29270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQQgAAJX4"]
[Mon Jul 20 06:25:34.243596 2026] [security2:error] [pid 925208:tid 925347] [client 34.74.185.202:54005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4TvsRX7OrFkv0FyuIQ5AAAAAk"]
[Mon Jul 20 06:25:34.296252 2026] [security2:error] [pid 925208:tid 925374] [client 104.234.53.55:25607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4TvsRX7OrFkv0FyuIQ5gAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:34.309188 2026] [core:error] [pid 925208:tid 925446] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.309217 2026] [core:error] [pid 925208:tid 925446] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339692 2026] [core:error] [pid 925208:tid 925359] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339724 2026] [core:error] [pid 925208:tid 925359] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339797 2026] [core:error] [pid 925208:tid 925356] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.339816 2026] [core:error] [pid 925208:tid 925356] [client 94.154.43.177:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.341147 2026] [core:error] [pid 925208:tid 925400] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.341164 2026] [core:error] [pid 925208:tid 925400] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.354609 2026] [core:error] [pid 925208:tid 925457] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.354626 2026] [core:error] [pid 925208:tid 925457] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:25:34.549256 2026] [security2:error] [pid 925208:tid 925342] [client 57.141.18.8:29988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TvMRX7OrFkv0FyuIQTwAABEI"]
[Mon Jul 20 06:25:34.558739 2026] [security2:error] [pid 925208:tid 925285] [remote 81.173.115.7:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4TvsRX7OrFkv0FyuIRFgAAb0w"]
[Mon Jul 20 06:25:34.565838 2026] [security2:error] [pid 925208:tid 925392] [client 34.74.185.202:53998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4TvsRX7OrFkv0FyuIRGgAAADY"]
[Mon Jul 20 06:25:34.793699 2026] [security2:error] [pid 925208:tid 925289] [remote 81.173.115.7:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4TvsRX7OrFkv0FyuIRJwAADlA"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:25:34.917646 2026] [security2:error] [pid 925208:tid 925463] [client 74.208.214.194:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4TvsRX7OrFkv0FyuIRLgAAAH0"]
[Mon Jul 20 06:25:34.953963 2026] [security2:error] [pid 925208:tid 925406] [client 14.225.17.146:64058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4TvcRX7OrFkv0FyuIQsQAAAEQ"], referer: http://carolinapressurewashers.com/WP
[Mon Jul 20 06:25:35.017475 2026] [security2:error] [pid 925208:tid 925302] [remote 124.55.178.99:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRNwAAI10"]
[Mon Jul 20 06:25:35.113708 2026] [security2:error] [pid 925208:tid 925418] [client 34.74.185.202:54968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Tv8RX7OrFkv0FyuIRSAAAAFA"]
[Mon Jul 20 06:25:35.436457 2026] [security2:error] [pid 925208:tid 925405] [client 14.225.17.146:57568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRSwAAAEM"]
[Mon Jul 20 06:25:35.461318 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRRAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.469640 2026] [security2:error] [pid 925208:tid 925316] [remote 124.55.178.99:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRYwAAKGs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:35.641917 2026] [security2:error] [pid 925208:tid 925330] [remote 87.106.67.224:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRcgAAd3k"]
[Mon Jul 20 06:25:35.734888 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRegAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.735007 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRegAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.878895 2026] [security2:error] [pid 925208:tid 925328] [remote 87.106.67.224:34578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRjAAAKHc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:25:35.903649 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRkwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:35.903746 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRkwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:36.117343 2026] [security2:error] [pid 925208:tid 925363] [client 14.225.17.146:59074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4TvsRX7OrFkv0FyuIRKgAAABk"], referer: http://oldracelimited.com/WP
[Mon Jul 20 06:25:36.496607 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:59017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIRsQAAACM"], referer: http://falconarrowshop.com/WP
[Mon Jul 20 06:25:36.542666 2026] [security2:error] [pid 925208:tid 925351] [client 34.74.185.202:53570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4TwMRX7OrFkv0FyuIRzgAAAA0"]
[Mon Jul 20 06:25:36.713384 2026] [security2:error] [pid 925208:tid 925433] [client 14.224.227.113:55746] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4TwMRX7OrFkv0FyuIR3QAAAF8"]
[Mon Jul 20 06:25:37.040293 2026] [security2:error] [pid 925208:tid 925408] [client 34.74.185.202:53742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4TwcRX7OrFkv0FyuIR7wAAAEY"]
[Mon Jul 20 06:25:37.089015 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62261] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4TwcRX7OrFkv0FyuIR8wAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:37.101553 2026] [security2:error] [pid 925208:tid 925435] [client 66.249.68.169:63936] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.bokkunst.com"] [uri "/robots.txt"] [unique_id "al4TwcRX7OrFkv0FyuIR9AAAAGE"]
[Mon Jul 20 06:25:37.185048 2026] [security2:error] [pid 925208:tid 925404] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4TwcRX7OrFkv0FyuIR8QAAAEI"]
[Mon Jul 20 06:25:37.404038 2026] [security2:error] [pid 925208:tid 925252] [remote 57.141.18.2:23098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3480050"] [unique_id "al4TwcRX7OrFkv0FyuISAQAAYys"]
[Mon Jul 20 06:25:37.417624 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:26543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TwcRX7OrFkv0FyuISBAAAAC0"]
[Mon Jul 20 06:25:37.417726 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:26543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4TwcRX7OrFkv0FyuISBAAAAC0"]
[Mon Jul 20 06:25:37.854303 2026] [security2:error] [pid 925208:tid 925395] [client 57.141.18.96:23932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tv8RX7OrFkv0FyuIRjQAAOT4"]
[Mon Jul 20 06:25:38.011520 2026] [security2:error] [pid 925208:tid 925423] [client 14.225.17.146:58920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIR3wAAAFU"], referer: http://whiteoutcb.com/WP
[Mon Jul 20 06:25:38.186395 2026] [security2:error] [pid 925208:tid 925420] [client 158.173.89.95:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4TwsRX7OrFkv0FyuISSQAAAFI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:38.202715 2026] [security2:error] [pid 925208:tid 925355] [client 57.141.18.109:21088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIRsAAAEQ0"]
[Mon Jul 20 06:25:38.230622 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISTwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.230727 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISTwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.383398 2026] [security2:error] [pid 925208:tid 925381] [client 77.110.127.138:62267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISVAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.383535 2026] [security2:error] [pid 925208:tid 925381] [client 77.110.127.138:62267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TwsRX7OrFkv0FyuISVAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:38.503243 2026] [security2:error] [pid 925208:tid 925441] [client 34.74.185.202:53581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.frontecinc.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4TwsRX7OrFkv0FyuISXAAAAGc"]
[Mon Jul 20 06:25:38.647132 2026] [security2:error] [pid 925208:tid 925429] [client 14.225.17.146:57423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4TwMRX7OrFkv0FyuIR2AAAAFs"], referer: http://itdynamix.com/WP
[Mon Jul 20 06:25:39.457827 2026] [security2:error] [pid 925208:tid 925386] [client 91.92.41.115:50659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "darkknightsolutions.com"] [uri "/.env"] [unique_id "al4Tw8RX7OrFkv0FyuISogAAADA"]
[Mon Jul 20 06:25:39.729243 2026] [security2:error] [pid 925208:tid 925414] [client 14.225.17.146:57147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Tw8RX7OrFkv0FyuISrAAAAEw"], referer: https://itdynamix.com/WP
[Mon Jul 20 06:25:40.269917 2026] [security2:error] [pid 925208:tid 925362] [client 112.208.70.94:43398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TxMRX7OrFkv0FyuIS1AAAABg"]
[Mon Jul 20 06:25:40.270055 2026] [security2:error] [pid 925208:tid 925362] [client 112.208.70.94:43398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4TxMRX7OrFkv0FyuIS1AAAABg"]
[Mon Jul 20 06:25:40.327697 2026] [security2:error] [pid 925208:tid 925375] [client 14.225.17.146:57114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4Tw8RX7OrFkv0FyuISnwAAACU"], referer: http://claysharecon.com/WP
[Mon Jul 20 06:25:40.845525 2026] [security2:error] [pid 925208:tid 925245] [remote 147.50.252.213:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxMRX7OrFkv0FyuITAgAAKyQ"]
[Mon Jul 20 06:25:41.303975 2026] [security2:error] [pid 925208:tid 925235] [remote 147.50.252.213:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxcRX7OrFkv0FyuITHwAAIho"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:41.376470 2026] [security2:error] [pid 925208:tid 925436] [client 77.110.127.138:62277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4TxcRX7OrFkv0FyuITLAAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:41.555103 2026] [security2:error] [pid 925208:tid 925408] [client 14.225.17.146:57644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4TxMRX7OrFkv0FyuIS0wAAAEY"], referer: http://elitetax-mi.com/WP
[Mon Jul 20 06:25:41.651450 2026] [security2:error] [pid 925208:tid 925385] [client 171.60.139.123:55888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TxcRX7OrFkv0FyuITQAAAAC8"]
[Mon Jul 20 06:25:41.651567 2026] [security2:error] [pid 925208:tid 925385] [client 171.60.139.123:55888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4TxcRX7OrFkv0FyuITQAAAAC8"]
[Mon Jul 20 06:25:41.733285 2026] [security2:error] [pid 925208:tid 925324] [remote 81.173.115.7:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxcRX7OrFkv0FyuITRgAAaXM"]
[Mon Jul 20 06:25:41.949691 2026] [security2:error] [pid 925208:tid 925279] [remote 81.173.115.7:41862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TxcRX7OrFkv0FyuITWQAAK0Y"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:42.165798 2026] [security2:error] [pid 925208:tid 925439] [client 14.225.17.146:57677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4TxMRX7OrFkv0FyuITBgAAAGU"], referer: http://iagdevelopments.com/WP
[Mon Jul 20 06:25:42.434664 2026] [security2:error] [pid 925208:tid 925396] [client 74.7.175.191:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4TxsRX7OrFkv0FyuITdgAAADo"]
[Mon Jul 20 06:25:42.436424 2026] [security2:error] [pid 925208:tid 925400] [client 74.7.175.191:45488] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phillipbloch.com"] [uri "/robots.txt"] [unique_id "al4TxsRX7OrFkv0FyuITcwAAPj0"]
[Mon Jul 20 06:25:42.549640 2026] [security2:error] [pid 925208:tid 925351] [client 62.150.67.110:63683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4TxcRX7OrFkv0FyuITWwAAAA0"]
[Mon Jul 20 06:25:42.637649 2026] [security2:error] [pid 925208:tid 925431] [client 57.141.18.15:20246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TxMRX7OrFkv0FyuITBAAAXSc"]
[Mon Jul 20 06:25:42.818436 2026] [security2:error] [pid 925208:tid 925401] [client 68.235.52.68:54442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmAAAAD8"]
[Mon Jul 20 06:25:42.818549 2026] [security2:error] [pid 925208:tid 925401] [client 68.235.52.68:54442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmAAAAD8"]
[Mon Jul 20 06:25:42.832718 2026] [security2:error] [pid 925208:tid 925354] [client 77.110.127.138:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TxsRX7OrFkv0FyuITmQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:42.832826 2026] [security2:error] [pid 925208:tid 925354] [client 77.110.127.138:62281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TxsRX7OrFkv0FyuITmQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:42.836715 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:64061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmwAAACc"]
[Mon Jul 20 06:25:42.837036 2026] [security2:error] [pid 925208:tid 925377] [client 103.141.108.143:64061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4TxsRX7OrFkv0FyuITmwAAACc"]
[Mon Jul 20 06:25:42.853400 2026] [security2:error] [pid 925208:tid 925302] [remote 97.74.93.24:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4TxsRX7OrFkv0FyuITnAAAM10"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:25:43.056187 2026] [security2:error] [pid 925208:tid 925361] [client 45.116.69.230:64541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuITtAAAABc"]
[Mon Jul 20 06:25:43.056283 2026] [security2:error] [pid 925208:tid 925361] [client 45.116.69.230:64541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuITtAAAABc"]
[Mon Jul 20 06:25:43.095846 2026] [security2:error] [pid 925208:tid 925460] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuITrgAAAHo"], referer: https://iagdevelopments.com/WP
[Mon Jul 20 06:25:43.473034 2026] [security2:error] [pid 925208:tid 925333] [remote 103.118.29.185:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT1QAAYXw"]
[Mon Jul 20 06:25:43.512806 2026] [security2:error] [pid 925208:tid 925434] [client 14.225.17.146:49655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT0AAAAGA"], referer: http://friendlyspreadsheet.com/WP
[Mon Jul 20 06:25:43.621197 2026] [security2:error] [pid 925208:tid 925318] [remote 97.74.93.24:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT6AAAMW0"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:25:43.628890 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT6QAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:43.628999 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT6QAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:43.887832 2026] [security2:error] [pid 925208:tid 925326] [remote 103.118.29.185:45994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT-AAADnU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:43.906149 2026] [security2:error] [pid 925208:tid 925360] [client 65.1.132.125:33668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT-QAAABY"]
[Mon Jul 20 06:25:43.906267 2026] [security2:error] [pid 925208:tid 925360] [client 65.1.132.125:33668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT-QAAABY"]
[Mon Jul 20 06:25:44.082329 2026] [security2:error] [pid 925208:tid 925454] [client 14.225.17.146:53486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuIT9wAAAHQ"], referer: http://samdothan.org/WP
[Mon Jul 20 06:25:44.451384 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TyMRX7OrFkv0FyuIUJgAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:44.451487 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TyMRX7OrFkv0FyuIUJgAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:44.456051 2026] [security2:error] [pid 925208:tid 925427] [client 14.225.17.146:58958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4TyMRX7OrFkv0FyuIUGgAAAFk"], referer: https://friendlyspreadsheet.com/WP
[Mon Jul 20 06:25:44.819558 2026] [security2:error] [pid 925208:tid 925388] [client 57.141.18.98:28488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TxsRX7OrFkv0FyuITlwAAMkQ"]
[Mon Jul 20 06:25:45.121084 2026] [security2:error] [pid 925208:tid 925246] [remote 173.212.252.15:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TycRX7OrFkv0FyuIUYgAAWCU"]
[Mon Jul 20 06:25:45.133531 2026] [security2:error] [pid 925208:tid 925380] [client 57.141.18.95:53632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tx8RX7OrFkv0FyuITuQAAKiY"]
[Mon Jul 20 06:25:45.233970 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TycRX7OrFkv0FyuIUZwAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:45.234097 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TycRX7OrFkv0FyuIUZwAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:45.390578 2026] [security2:error] [pid 925208:tid 925252] [remote 173.212.252.15:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4TycRX7OrFkv0FyuIUcgAADCs"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:25:45.560295 2026] [security2:error] [pid 925208:tid 925349] [client 14.225.17.146:57599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4TycRX7OrFkv0FyuIUgwAAAAs"], referer: http://retzkolonglogistics.com/WP
[Mon Jul 20 06:25:46.023248 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIUowAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.023346 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIUowAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.537109 2026] [security2:error] [pid 925208:tid 925437] [client 57.141.18.19:64602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TyMRX7OrFkv0FyuIUQAAAYyQ"]
[Mon Jul 20 06:25:46.606443 2026] [security2:error] [pid 925208:tid 925359] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4TysRX7OrFkv0FyuIUvgAAABU"]
[Mon Jul 20 06:25:46.737450 2026] [security2:error] [pid 925208:tid 925285] [remote 57.141.18.120:26608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2771386"] [unique_id "al4TysRX7OrFkv0FyuIU1gAAPUw"]
[Mon Jul 20 06:25:46.838914 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU5AAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.839001 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:62296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU5AAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.995939 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU8wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:46.996042 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TysRX7OrFkv0FyuIU8wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.106772 2026] [security2:error] [pid 925208:tid 925449] [client 54.39.89.128:17422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4Ty8RX7OrFkv0FyuIU-wAAAG8"]
[Mon Jul 20 06:25:47.106889 2026] [security2:error] [pid 925208:tid 925449] [client 54.39.89.128:17422] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4Ty8RX7OrFkv0FyuIU-wAAAG8"]
[Mon Jul 20 06:25:47.155889 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIU_gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.155986 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIU_gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.308938 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVCQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.309037 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVCQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.507881 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVEQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.507992 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVEQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.660243 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:62303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVHgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.660343 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:62303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVHgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:47.756740 2026] [security2:error] [pid 925208:tid 925427] [client 104.234.53.73:49019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVIwAAAFk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:47.821325 2026] [security2:error] [pid 925208:tid 925436] [client 77.110.127.138:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVJwAAAGI"]
[Mon Jul 20 06:25:47.821449 2026] [security2:error] [pid 925208:tid 925436] [client 77.110.127.138:62304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVJwAAAGI"]
[Mon Jul 20 06:25:47.835372 2026] [security2:error] [pid 925208:tid 925386] [client 57.141.18.50:57398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TycRX7OrFkv0FyuIUkQAAMH4"]
[Mon Jul 20 06:25:47.973346 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVLQAAAHs"]
[Mon Jul 20 06:25:47.973447 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVLQAAAHs"]
[Mon Jul 20 06:25:48.125581 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVNQAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.125703 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVNQAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.243981 2026] [security2:error] [pid 925208:tid 925377] [client 57.141.18.24:40824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TysRX7OrFkv0FyuIUugAAJ0M"]
[Mon Jul 20 06:25:48.285169 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVQwAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.285258 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVQwAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.371917 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:55859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVPAAAAAA"], referer: http://mobilesurvsolutions.com/WP
[Mon Jul 20 06:25:48.442264 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVUAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.442364 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVUAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.601209 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVXAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.601295 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVXAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.752872 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVbQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.752982 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVbQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.916903 2026] [security2:error] [pid 925208:tid 925375] [client 77.110.127.138:62312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVdQAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:48.917015 2026] [security2:error] [pid 925208:tid 925375] [client 77.110.127.138:62312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzMRX7OrFkv0FyuIVdQAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.034422 2026] [security2:error] [pid 925208:tid 925239] [remote 45.90.123.233:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TzcRX7OrFkv0FyuIVfQAADR4"]
[Mon Jul 20 06:25:49.072841 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVggAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.072920 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVggAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.238126 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVjgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.238271 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:62316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVjgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.246097 2026] [security2:error] [pid 925208:tid 925246] [remote 45.90.123.233:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4TzcRX7OrFkv0FyuIVjwAAVCU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:49.393971 2026] [security2:error] [pid 925208:tid 925346] [client 57.141.18.72:41444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVDQAACEE"]
[Mon Jul 20 06:25:49.835706 2026] [security2:error] [pid 925208:tid 925418] [client 14.225.17.146:55440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVVQAAAFA"], referer: http://cloudspacesgroup.com/WP
[Mon Jul 20 06:25:49.837990 2026] [security2:error] [pid 925208:tid 925386] [client 14.225.17.146:55427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4TzcRX7OrFkv0FyuIVsQAAADA"], referer: http://taskidsvirginia.com/WP
[Mon Jul 20 06:25:49.921264 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVxgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.921360 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzcRX7OrFkv0FyuIVxgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:49.947267 2026] [security2:error] [pid 925208:tid 925451] [client 57.141.18.115:46458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ty8RX7OrFkv0FyuIVKQAAcXU"]
[Mon Jul 20 06:25:50.353045 2026] [security2:error] [pid 925208:tid 925379] [client 57.141.18.83:55510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVRAAAKRA"]
[Mon Jul 20 06:25:50.354870 2026] [security2:error] [pid 925208:tid 925238] [remote 173.212.252.15:50306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4TzsRX7OrFkv0FyuIV7wAACh0"]
[Mon Jul 20 06:25:50.527232 2026] [security2:error] [pid 925208:tid 925372] [client 14.225.17.146:55835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4TzsRX7OrFkv0FyuIV8wAAACI"], referer: http://katsklar.com/WP
[Mon Jul 20 06:25:50.652299 2026] [security2:error] [pid 925208:tid 925302] [remote 173.212.252.15:50306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4TzsRX7OrFkv0FyuIWAgAABV0"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:25:50.693394 2026] [security2:error] [pid 925208:tid 925400] [client 57.141.18.45:32362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TzMRX7OrFkv0FyuIVZQAAPl8"]
[Mon Jul 20 06:25:50.762453 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzsRX7OrFkv0FyuIWCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:50.762554 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4TzsRX7OrFkv0FyuIWCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:51.035536 2026] [security2:error] [pid 925208:tid 925344] [client 104.234.53.75:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWJwAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:51.358230 2026] [security2:error] [pid 925208:tid 925261] [remote 124.55.178.99:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWQQAAJzQ"]
[Mon Jul 20 06:25:51.404333 2026] [security2:error] [pid 925208:tid 925341] [client 98.159.234.160:51207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWSgAAAAM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:25:51.462810 2026] [security2:error] [pid 925208:tid 925417] [client 57.141.18.46:37320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4TzcRX7OrFkv0FyuIVsAAAT3Y"]
[Mon Jul 20 06:25:51.665657 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWYAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:51.665778 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWYAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:51.799143 2026] [security2:error] [pid 925208:tid 925305] [remote 124.55.178.99:59332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWZwAASGA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:25:52.309773 2026] [security2:error] [pid 925208:tid 925412] [client 171.60.139.123:56398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWiwAAAEo"]
[Mon Jul 20 06:25:52.309863 2026] [security2:error] [pid 925208:tid 925412] [client 171.60.139.123:56398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWiwAAAEo"]
[Mon Jul 20 06:25:52.453574 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0MRX7OrFkv0FyuIWmAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:52.453682 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0MRX7OrFkv0FyuIWmAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:52.652520 2026] [security2:error] [pid 925208:tid 925458] [client 104.234.53.87:64725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4T0MRX7OrFkv0FyuIWoQAAAHg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:52.745236 2026] [core:error] [pid 925208:tid 925386] [client 103.153.183.69:61178] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e/.env?_=to4fqwfm&v=hvu01), referer: https://www.google.com/search?q=5s7po7
[Mon Jul 20 06:25:52.752901 2026] [security2:error] [pid 925208:tid 925240] [remote 72.167.132.114:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4T0MRX7OrFkv0FyuIWqwAAAx8"]
[Mon Jul 20 06:25:52.794600 2026] [security2:error] [pid 925208:tid 925413] [client 112.208.70.94:43798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWtQAAAEs"]
[Mon Jul 20 06:25:52.794693 2026] [security2:error] [pid 925208:tid 925413] [client 112.208.70.94:43798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T0MRX7OrFkv0FyuIWtQAAAEs"]
[Mon Jul 20 06:25:52.990091 2026] [security2:error] [pid 925208:tid 925410] [client 103.153.183.69:19002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../var/www/html/.env"] [unique_id "al4T0MRX7OrFkv0FyuIWyAAAAEg"], referer: https://www.google.com/
[Mon Jul 20 06:25:52.991259 2026] [security2:error] [pid 925208:tid 925250] [remote 72.167.132.114:57068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4T0MRX7OrFkv0FyuIWxwAAWik"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:25:53.096437 2026] [security2:error] [pid 925208:tid 925347] [client 103.153.183.69:19002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../var/www/.env"] [unique_id "al4T0cRX7OrFkv0FyuIW0wAAAAk"], referer: https://t.co/wuwnc3mavz
[Mon Jul 20 06:25:53.241585 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW3wAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.241714 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW3wAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.260812 2026] [core:error] [pid 925208:tid 925374] [client 103.153.183.69:61192] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e/etc/passwd?_=z2dznur3&v=tajne), referer: https://news.ycombinator.com/
[Mon Jul 20 06:25:53.263147 2026] [security2:error] [pid 925208:tid 925458] [client 127.0.0.1:42552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4T0cRX7OrFkv0FyuIW4wAAAHg"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:25:53.351135 2026] [security2:error] [pid 925208:tid 925443] [client 104.234.53.87:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4T0cRX7OrFkv0FyuIW5gAAAGk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:53.379399 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW6QAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.379512 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T0cRX7OrFkv0FyuIW6QAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:53.446598 2026] [security2:error] [pid 925208:tid 925406] [client 103.141.108.143:64529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIW8QAAAEQ"]
[Mon Jul 20 06:25:53.446845 2026] [security2:error] [pid 925208:tid 925406] [client 103.141.108.143:64529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIW8QAAAEQ"]
[Mon Jul 20 06:25:53.593473 2026] [core:error] [pid 925208:tid 925434] [client 103.153.183.69:61204] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e/%u002e%u002e/.env?_=i3fuk6m5&v=rrb8j), referer: https://twitter.com/
[Mon Jul 20 06:25:53.638787 2026] [security2:error] [pid 925208:tid 925402] [client 57.141.18.31:21282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Tz8RX7OrFkv0FyuIWdwAAQBc"]
[Mon Jul 20 06:25:53.700849 2026] [security2:error] [pid 925208:tid 925456] [client 45.116.69.230:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIXAwAAAHY"]
[Mon Jul 20 06:25:53.700938 2026] [security2:error] [pid 925208:tid 925456] [client 45.116.69.230:65060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T0cRX7OrFkv0FyuIXAwAAAHY"]
[Mon Jul 20 06:25:53.749439 2026] [security2:error] [pid 925208:tid 925356] [client 57.141.18.46:49554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T0MRX7OrFkv0FyuIWhAAAEm4"]
[Mon Jul 20 06:25:54.328130 2026] [security2:error] [pid 925208:tid 925378] [client 50.116.65.227:27656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4T0sRX7OrFkv0FyuIXOgAAACg"]
[Mon Jul 20 06:25:54.331415 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:60563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXLwAAAE0"]
[Mon Jul 20 06:25:54.485658 2026] [security2:error] [pid 925208:tid 925462] [client 103.153.183.69:19002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//var/www/html/wp-config.php"] [unique_id "al4T0sRX7OrFkv0FyuIXQwAAAHw"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:25:54.636518 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:50303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXQQAAADE"], referer: http://mtlegnews.gov/WP
[Mon Jul 20 06:25:55.179495 2026] [security2:error] [pid 925208:tid 925406] [client 14.225.17.146:49941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXYQAAAEQ"], referer: http://webgardensbypaula.com/WP
[Mon Jul 20 06:25:55.288563 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXiQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.288670 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXiQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.509191 2026] [security2:error] [pid 925208:tid 925459] [client 57.141.18.116:45140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T0cRX7OrFkv0FyuIXBAAAeSg"]
[Mon Jul 20 06:25:55.511097 2026] [security2:error] [pid 925208:tid 925210] [remote 156.67.31.167:43500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXjgAABgE"]
[Mon Jul 20 06:25:55.511283 2026] [security2:error] [pid 925208:tid 925344] [client 156.67.31.167:43500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXjgAABgE"]
[Mon Jul 20 06:25:55.668048 2026] [security2:error] [pid 925208:tid 925266] [remote 8.217.108.67:21680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXoAAALDk"]
[Mon Jul 20 06:25:55.668390 2026] [security2:error] [pid 925208:tid 925382] [client 8.217.108.67:21680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T08RX7OrFkv0FyuIXoAAALDk"]
[Mon Jul 20 06:25:55.755574 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4T08RX7OrFkv0FyuIXpAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.910027 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXqwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.910442 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T08RX7OrFkv0FyuIXqwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:55.920191 2026] [security2:error] [pid 925208:tid 925348] [client 104.234.53.71:47309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4T08RX7OrFkv0FyuIXrwAAAAo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:25:55.925012 2026] [security2:error] [pid 925208:tid 925429] [client 14.225.17.146:60573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4T08RX7OrFkv0FyuIXpQAAAFs"], referer: http://ivetstrategies.com/WP
[Mon Jul 20 06:25:56.129272 2026] [security2:error] [pid 925208:tid 925436] [client 57.141.18.91:37136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T0sRX7OrFkv0FyuIXOwAAYkU"]
[Mon Jul 20 06:25:56.539177 2026] [security2:error] [pid 925208:tid 925359] [client 14.225.17.146:50414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4T08RX7OrFkv0FyuIXfgAAABU"]
[Mon Jul 20 06:25:56.549844 2026] [security2:error] [pid 925208:tid 925320] [remote 5.161.225.162:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T1MRX7OrFkv0FyuIX6AAAPm8"]
[Mon Jul 20 06:25:56.905888 2026] [security2:error] [pid 925208:tid 925415] [client 47.129.222.11:25548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T1MRX7OrFkv0FyuIYEQAAAE0"]
[Mon Jul 20 06:25:57.151313 2026] [security2:error] [pid 925208:tid 925240] [remote 5.161.225.162:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T1cRX7OrFkv0FyuIYOQAAaB8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:25:57.272880 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.27:64578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T08RX7OrFkv0FyuIXgAAAThg"]
[Mon Jul 20 06:25:57.341945 2026] [security2:error] [pid 925208:tid 925363] [client 14.225.17.146:50628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4T1MRX7OrFkv0FyuIX3AAAABk"], referer: http://nextlevelpressurewashing.com/WP
[Mon Jul 20 06:25:57.405539 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T1cRX7OrFkv0FyuIYRQAAAE0"]
[Mon Jul 20 06:25:57.645975 2026] [security2:error] [pid 925208:tid 925381] [client 34.48.79.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4T1cRX7OrFkv0FyuIYRAAAACs"]
[Mon Jul 20 06:25:57.816503 2026] [security2:error] [pid 925208:tid 925438] [client 34.48.79.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.79.48.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/xmlrpc.php"] [unique_id "al4T1cRX7OrFkv0FyuIYawAAAGQ"]
[Mon Jul 20 06:25:57.874835 2026] [security2:error] [pid 925208:tid 925412] [client 47.129.222.11:25560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T1cRX7OrFkv0FyuIYcgAAAEo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:25:58.057853 2026] [security2:error] [pid 925208:tid 925464] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYeQAAAH4"]
[Mon Jul 20 06:25:58.100687 2026] [security2:error] [pid 925208:tid 925411] [client 223.185.13.213:5435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T1sRX7OrFkv0FyuIYgAAAAEk"]
[Mon Jul 20 06:25:58.100827 2026] [security2:error] [pid 925208:tid 925411] [client 223.185.13.213:5435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T1sRX7OrFkv0FyuIYgAAAAEk"]
[Mon Jul 20 06:25:58.329817 2026] [security2:error] [pid 925208:tid 925342] [client 14.225.17.146:50084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4T1sRX7OrFkv0FyuIYjgAAAAQ"], referer: http://chestermonty.com/WP
[Mon Jul 20 06:25:58.338560 2026] [security2:error] [pid 925208:tid 925447] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYlwAAAG0"]
[Mon Jul 20 06:25:58.518004 2026] [security2:error] [pid 925208:tid 925464] [client 77.110.127.138:62351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T1sRX7OrFkv0FyuIYpgAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:58.518110 2026] [security2:error] [pid 925208:tid 925464] [client 77.110.127.138:62351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T1sRX7OrFkv0FyuIYpgAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:25:58.576713 2026] [security2:error] [pid 925208:tid 925411] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYrgAAAEk"]
[Mon Jul 20 06:25:58.884181 2026] [security2:error] [pid 925208:tid 925458] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T1sRX7OrFkv0FyuIYyQAAAHg"]
[Mon Jul 20 06:25:58.895964 2026] [security2:error] [pid 925208:tid 925401] [client 57.141.18.28:56964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1MRX7OrFkv0FyuIYBQAAP38"]
[Mon Jul 20 06:25:59.003757 2026] [security2:error] [pid 925208:tid 925248] [remote 217.61.143.92:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIYzgAAGSc"]
[Mon Jul 20 06:25:59.054196 2026] [security2:error] [pid 925208:tid 925303] [remote 124.55.178.99:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY0gAAdV4"]
[Mon Jul 20 06:25:59.146567 2026] [security2:error] [pid 925208:tid 925364] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIY5AAAABo"]
[Mon Jul 20 06:25:59.155662 2026] [security2:error] [pid 925208:tid 925298] [remote 117.0.21.154:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY4AAAGFk"]
[Mon Jul 20 06:25:59.246240 2026] [security2:error] [pid 925208:tid 925237] [remote 217.61.143.92:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY8gAAShw"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 06:25:59.318411 2026] [security2:error] [pid 925208:tid 925402] [client 14.225.17.146:54169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4T18RX7OrFkv0FyuIY7gAAAEA"], referer: https://chestermonty.com/WP
[Mon Jul 20 06:25:59.325512 2026] [security2:error] [pid 925208:tid 925370] [client 57.141.18.70:58930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1cRX7OrFkv0FyuIYOgAAIBs"]
[Mon Jul 20 06:25:59.382764 2026] [security2:error] [pid 925208:tid 925344] [client 103.153.183.69:41374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//var/www/html/config.php"] [unique_id "al4T18RX7OrFkv0FyuIY_gAAAAY"], referer: https://www.reddit.com/
[Mon Jul 20 06:25:59.392916 2026] [security2:error] [pid 925208:tid 925352] [client 65.1.132.125:26590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIY_QAAAA4"]
[Mon Jul 20 06:25:59.424113 2026] [security2:error] [pid 925208:tid 925382] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZAAAAACw"]
[Mon Jul 20 06:25:59.458300 2026] [security2:error] [pid 925208:tid 925242] [remote 47.86.33.52:1380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIZAQAAbiE"]
[Mon Jul 20 06:25:59.555587 2026] [security2:error] [pid 925208:tid 925262] [remote 124.55.178.99:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4T18RX7OrFkv0FyuIZCAAAGDU"], referer: https://snctaxgroup.com/wp-login.php
[Mon Jul 20 06:25:59.645071 2026] [security2:error] [pid 925208:tid 925464] [client 14.225.17.146:54201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4T18RX7OrFkv0FyuIY-gAAAH4"], referer: http://overloadcomedy.com/WP
[Mon Jul 20 06:25:59.712096 2026] [security2:error] [pid 925208:tid 925426] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZFwAAAFg"]
[Mon Jul 20 06:25:59.742682 2026] [security2:error] [pid 925208:tid 925412] [client 85.204.70.92:40462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZGAAAAEo"]
[Mon Jul 20 06:25:59.950995 2026] [security2:error] [pid 925208:tid 925402] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T18RX7OrFkv0FyuIZKgAAAEA"]
[Mon Jul 20 06:26:00.250941 2026] [security2:error] [pid 925208:tid 925437] [client 57.141.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZMwAAAGM"]
[Mon Jul 20 06:26:00.266018 2026] [security2:error] [pid 925208:tid 925386] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZQwAAADA"]
[Mon Jul 20 06:26:00.311689 2026] [security2:error] [pid 925208:tid 925276] [remote 117.0.21.154:34424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T2MRX7OrFkv0FyuIZSAAAVEM"], referer: https://zlp.omk.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:00.312812 2026] [security2:error] [pid 925208:tid 925347] [client 85.204.70.92:40474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4T2MRX7OrFkv0FyuIZRAAAAAk"]
[Mon Jul 20 06:26:00.369609 2026] [security2:error] [pid 925208:tid 925389] [client 57.141.18.66:53138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1sRX7OrFkv0FyuIYkwAAMz4"]
[Mon Jul 20 06:26:00.525382 2026] [security2:error] [pid 925208:tid 925438] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZVQAAAGQ"]
[Mon Jul 20 06:26:00.544291 2026] [security2:error] [pid 925208:tid 925355] [client 13.201.64.214:20068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4T2MRX7OrFkv0FyuIZVwAAABE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:26:00.834207 2026] [security2:error] [pid 925208:tid 925464] [client 34.48.79.16:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thescarystory.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZdQAAAH4"]
[Mon Jul 20 06:26:00.961823 2026] [security2:error] [pid 925208:tid 925459] [client 57.141.18.33:60928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T1sRX7OrFkv0FyuIYwQAAeSQ"]
[Mon Jul 20 06:26:00.996262 2026] [security2:error] [pid 925208:tid 925385] [client 85.204.70.92:40486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T2MRX7OrFkv0FyuIZgwAAAC8"]
[Mon Jul 20 06:26:01.068146 2026] [security2:error] [pid 925208:tid 925430] [client 148.230.189.107:38477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZfQAAAFw"]
[Mon Jul 20 06:26:01.077877 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZiQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.077977 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZiQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.081872 2026] [proxy:error] [pid 925208:tid 925432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:01.081941 2026] [proxy_http:error] [pid 925208:tid 925432] [client 34.73.38.214:56458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:01.082413 2026] [proxy:error] [pid 925208:tid 925432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:01.082443 2026] [proxy_http:error] [pid 925208:tid 925432] [client 34.73.38.214:56458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:01.313331 2026] [security2:error] [pid 925208:tid 925441] [client 14.225.17.146:64192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4T18RX7OrFkv0FyuIZDQAAAGc"], referer: http://nwcarvingacademy.com/WP
[Mon Jul 20 06:26:01.324488 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZpwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.324614 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZpwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.539401 2026] [security2:error] [pid 925208:tid 925360] [client 85.204.70.92:40502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T2cRX7OrFkv0FyuIZsgAAABY"]
[Mon Jul 20 06:26:01.671567 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:56985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4T2cRX7OrFkv0FyuIZsAAAAC4"], referer: http://lifeisbetterlakeside.com/WP
[Mon Jul 20 06:26:01.704577 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZxAAAABw"]
[Mon Jul 20 06:26:01.704684 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZxAAAABw"]
[Mon Jul 20 06:26:01.841633 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZ0gAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.841722 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2cRX7OrFkv0FyuIZ0gAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:01.895368 2026] [security2:error] [pid 925208:tid 925215] [remote 47.86.33.52:1380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T2cRX7OrFkv0FyuIZ1AAAKgY"], referer: https://zbj.ahr.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:02.067389 2026] [security2:error] [pid 925208:tid 925370] [client 85.204.70.92:40510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T2sRX7OrFkv0FyuIZ5gAAACA"]
[Mon Jul 20 06:26:02.310628 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ9wAAABE"]
[Mon Jul 20 06:26:02.310913 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ9wAAABE"]
[Mon Jul 20 06:26:02.422762 2026] [security2:error] [pid 925208:tid 925439] [client 34.74.185.202:59094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaAQAAAGU"]
[Mon Jul 20 06:26:02.447519 2026] [security2:error] [pid 925208:tid 925375] [client 14.225.17.146:54272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ6gAAACU"], referer: https://nwcarvingacademy.com/WP
[Mon Jul 20 06:26:02.525374 2026] [security2:error] [pid 925208:tid 925339] [client 57.141.18.79:34056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZRgAAARU"]
[Mon Jul 20 06:26:02.533633 2026] [security2:error] [pid 925208:tid 925396] [client 13.201.64.214:20082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaCgAAADo"]
[Mon Jul 20 06:26:02.533764 2026] [security2:error] [pid 925208:tid 925396] [client 13.201.64.214:20082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaCgAAADo"]
[Mon Jul 20 06:26:02.585312 2026] [security2:error] [pid 925208:tid 925429] [client 85.204.70.92:40516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4T2sRX7OrFkv0FyuIaDQAAAFs"]
[Mon Jul 20 06:26:02.862923 2026] [security2:error] [pid 925208:tid 925380] [client 171.60.139.123:56908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaKQAAACo"]
[Mon Jul 20 06:26:02.863026 2026] [security2:error] [pid 925208:tid 925380] [client 171.60.139.123:56908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T2sRX7OrFkv0FyuIaKQAAACo"]
[Mon Jul 20 06:26:02.907285 2026] [security2:error] [pid 925208:tid 925405] [client 34.74.185.202:59067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T2sRX7OrFkv0FyuIaKgAAAEM"]
[Mon Jul 20 06:26:03.046632 2026] [security2:error] [pid 925208:tid 925295] [remote 5.161.225.162:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4T28RX7OrFkv0FyuIaMgAAPVY"]
[Mon Jul 20 06:26:03.118117 2026] [security2:error] [pid 925208:tid 925425] [client 85.204.70.92:40520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIaRAAAAFc"]
[Mon Jul 20 06:26:03.171574 2026] [security2:error] [pid 925208:tid 925214] [remote 104.131.116.82:44762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T28RX7OrFkv0FyuIaSAAANQU"]
[Mon Jul 20 06:26:03.171891 2026] [security2:error] [pid 925208:tid 925391] [client 104.131.116.82:44762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T28RX7OrFkv0FyuIaSAAANQU"]
[Mon Jul 20 06:26:03.212018 2026] [security2:error] [pid 925208:tid 925412] [client 57.141.18.25:35386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T2MRX7OrFkv0FyuIZeAAASnQ"]
[Mon Jul 20 06:26:03.303285 2026] [security2:error] [pid 925208:tid 925284] [remote 5.161.225.162:47466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4T28RX7OrFkv0FyuIaUgAAGUs"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 06:26:03.410538 2026] [security2:error] [pid 925208:tid 925401] [client 34.74.185.202:56542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIaXgAAAD8"]
[Mon Jul 20 06:26:03.656488 2026] [security2:error] [pid 925208:tid 925422] [client 85.204.70.92:40532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIacgAAAFQ"]
[Mon Jul 20 06:26:03.757106 2026] [proxy:error] [pid 925208:tid 925417] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:03.757179 2026] [proxy_http:error] [pid 925208:tid 925417] [client 34.73.38.214:49453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:03.757834 2026] [proxy:error] [pid 925208:tid 925417] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:03.757865 2026] [proxy_http:error] [pid 925208:tid 925417] [client 34.73.38.214:49453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:03.797307 2026] [security2:error] [pid 925208:tid 925370] [client 45.157.112.60:35737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4T28RX7OrFkv0FyuIafgAAACA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:03.831405 2026] [security2:error] [pid 925208:tid 925440] [client 14.225.17.146:54294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ7AAAAGY"], referer: http://alrowad-hub.net/WP
[Mon Jul 20 06:26:03.984854 2026] [security2:error] [pid 925208:tid 925446] [client 34.74.185.202:61732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T28RX7OrFkv0FyuIalQAAAGw"]
[Mon Jul 20 06:26:04.079507 2026] [security2:error] [pid 925208:tid 925378] [client 103.141.108.143:65005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIamgAAACg"]
[Mon Jul 20 06:26:04.079620 2026] [security2:error] [pid 925208:tid 925378] [client 103.141.108.143:65005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIamgAAACg"]
[Mon Jul 20 06:26:04.146009 2026] [security2:error] [pid 925208:tid 925429] [client 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4T3MRX7OrFkv0FyuIaoQAAAFs"]
[Mon Jul 20 06:26:04.179376 2026] [security2:error] [pid 925208:tid 925421] [client 85.204.70.92:40540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIapgAAAFM"]
[Mon Jul 20 06:26:04.215790 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIarAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.215944 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIarAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.328778 2026] [security2:error] [pid 925208:tid 925396] [client 34.74.185.202:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIasgAAADo"]
[Mon Jul 20 06:26:04.347997 2026] [security2:error] [pid 925208:tid 925433] [client 52.109.124.141:21825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4T3MRX7OrFkv0FyuIaswAAAF8"]
[Mon Jul 20 06:26:04.361243 2026] [security2:error] [pid 925208:tid 925360] [client 45.116.69.230:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIatwAAABY"]
[Mon Jul 20 06:26:04.361357 2026] [security2:error] [pid 925208:tid 925360] [client 45.116.69.230:49178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T3MRX7OrFkv0FyuIatwAAABY"]
[Mon Jul 20 06:26:04.366572 2026] [security2:error] [pid 925208:tid 925399] [client 77.110.127.138:62413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4T3MRX7OrFkv0FyuIauQAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.418320 2026] [security2:error] [pid 925208:tid 925376] [client 77.110.127.138:62363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIavwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.418425 2026] [security2:error] [pid 925208:tid 925376] [client 77.110.127.138:62363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3MRX7OrFkv0FyuIavwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:04.511849 2026] [security2:error] [pid 925208:tid 925391] [client 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4T3MRX7OrFkv0FyuIaywAAADU"], referer: https://thescarystory.com/wp-login.php
[Mon Jul 20 06:26:04.527237 2026] [security2:error] [pid 925208:tid 925434] [client 52.109.124.141:21825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4T3MRX7OrFkv0FyuIazQAAAGA"]
[Mon Jul 20 06:26:04.648512 2026] [proxy:error] [pid 925208:tid 925397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.648561 2026] [proxy_http:error] [pid 925208:tid 925397] [client 94.154.43.187:63690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:04.649568 2026] [proxy:error] [pid 925208:tid 925397] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.649605 2026] [proxy_http:error] [pid 925208:tid 925397] [client 94.154.43.187:63690] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:04.670290 2026] [security2:error] [pid 925208:tid 925464] [client 14.225.17.146:53978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4T28RX7OrFkv0FyuIaTgAAAH4"], referer: http://alaraycreative.com/WP
[Mon Jul 20 06:26:04.700716 2026] [security2:error] [pid 925208:tid 925354] [client 85.204.70.92:44374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIa4gAAABA"]
[Mon Jul 20 06:26:04.721137 2026] [security2:error] [pid 925208:tid 925415] [client 34.74.185.202:60181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIa5gAAAE0"]
[Mon Jul 20 06:26:04.760756 2026] [security2:error] [pid 925208:tid 925462] [client 57.141.18.22:57578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T2sRX7OrFkv0FyuIZ8wAAfDw"]
[Mon Jul 20 06:26:04.763366 2026] [security2:error] [pid 925208:tid 925360] [client 50.116.65.227:52264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4T3MRX7OrFkv0FyuIa6wAAABY"]
[Mon Jul 20 06:26:04.773308 2026] [security2:error] [pid 925208:tid 925373] [client 50.116.65.227:52270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4T3MRX7OrFkv0FyuIa7AAAACM"]
[Mon Jul 20 06:26:04.901486 2026] [security2:error] [pid 925208:tid 925352] [client 52.109.44.112:9408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4T3MRX7OrFkv0FyuIa8QAAAA4"]
[Mon Jul 20 06:26:04.967419 2026] [security2:error] [pid 925208:tid 925422] [client 34.74.185.202:57394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T3MRX7OrFkv0FyuIa-QAAAFQ"]
[Mon Jul 20 06:26:04.987330 2026] [proxy:error] [pid 925208:tid 925381] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.987400 2026] [proxy_http:error] [pid 925208:tid 925381] [client 94.154.43.178:16892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:04.988180 2026] [proxy:error] [pid 925208:tid 925381] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:04.988215 2026] [proxy_http:error] [pid 925208:tid 925381] [client 94.154.43.178:16892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:05.037202 2026] [security2:error] [pid 925208:tid 925355] [client 52.109.44.112:9408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4T3cRX7OrFkv0FyuIbBAAAABE"]
[Mon Jul 20 06:26:05.163074 2026] [security2:error] [pid 925208:tid 925350] [client 14.225.17.146:64035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4T3cRX7OrFkv0FyuIbAAAAAAw"], referer: http://kromosenergy.com/WP
[Mon Jul 20 06:26:05.223695 2026] [security2:error] [pid 925208:tid 925450] [client 85.204.70.92:44388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T3cRX7OrFkv0FyuIbGgAAAHA"]
[Mon Jul 20 06:26:05.263362 2026] [security2:error] [pid 925208:tid 925438] [client 112.208.70.94:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T3cRX7OrFkv0FyuIbHgAAAGQ"]
[Mon Jul 20 06:26:05.263455 2026] [security2:error] [pid 925208:tid 925438] [client 112.208.70.94:44198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T3cRX7OrFkv0FyuIbHgAAAGQ"]
[Mon Jul 20 06:26:05.491547 2026] [security2:error] [pid 925208:tid 925317] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4T3cRX7OrFkv0FyuIbLgAAemw"]
[Mon Jul 20 06:26:05.519330 2026] [security2:error] [pid 925208:tid 925409] [client 34.74.185.202:62406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T3cRX7OrFkv0FyuIbMQAAAEc"]
[Mon Jul 20 06:26:05.598589 2026] [security2:error] [pid 925208:tid 925274] [remote 124.55.178.99:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4T3cRX7OrFkv0FyuIbNwAAJkE"]
[Mon Jul 20 06:26:05.742829 2026] [security2:error] [pid 925208:tid 925379] [client 85.204.70.92:44392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T3cRX7OrFkv0FyuIbRwAAACk"]
[Mon Jul 20 06:26:05.788403 2026] [security2:error] [pid 925208:tid 925362] [client 14.225.17.146:63999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4T3MRX7OrFkv0FyuIapQAAABg"], referer: https://north-woods-engineering.com/WP
[Mon Jul 20 06:26:06.011962 2026] [security2:error] [pid 925208:tid 925287] [remote 81.173.115.7:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbYAAAIE4"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:26:06.044251 2026] [security2:error] [pid 925208:tid 925421] [client 34.74.185.202:61993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbZQAAAFM"]
[Mon Jul 20 06:26:06.047375 2026] [security2:error] [pid 925208:tid 925294] [remote 124.55.178.99:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbZgAAdlU"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:26:06.076690 2026] [security2:error] [pid 925208:tid 925373] [client 103.153.183.69:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//var/www/html/configuration.php"] [unique_id "al4T3sRX7OrFkv0FyuIbaAAAACM"], referer: https://www.reddit.com/
[Mon Jul 20 06:26:06.160029 2026] [security2:error] [pid 925208:tid 925230] [remote 162.19.86.63:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbdAAABBU"]
[Mon Jul 20 06:26:06.233325 2026] [security2:error] [pid 925208:tid 925420] [client 57.141.18.21:53424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T28RX7OrFkv0FyuIakwAAUkU"]
[Mon Jul 20 06:26:06.255492 2026] [security2:error] [pid 925208:tid 925243] [remote 162.19.86.63:39757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbfQAAHSI"]
[Mon Jul 20 06:26:06.274943 2026] [security2:error] [pid 925208:tid 925437] [client 34.74.185.202:58402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbfwAAAGM"]
[Mon Jul 20 06:26:06.285448 2026] [security2:error] [pid 925208:tid 925374] [client 85.204.70.92:44406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbgAAAACQ"]
[Mon Jul 20 06:26:06.392585 2026] [security2:error] [pid 925208:tid 925238] [remote 162.19.86.63:54752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIbjQAAAR0"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:26:06.416013 2026] [security2:error] [pid 925208:tid 925424] [client 57.141.18.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbfgAAAFY"]
[Mon Jul 20 06:26:06.454009 2026] [security2:error] [pid 925208:tid 925388] [client 77.110.127.138:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3sRX7OrFkv0FyuIbkAAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:06.454120 2026] [security2:error] [pid 925208:tid 925388] [client 77.110.127.138:62419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T3sRX7OrFkv0FyuIbkAAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:06.505286 2026] [security2:error] [pid 925208:tid 925217] [remote 162.19.86.63:39757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T3sRX7OrFkv0FyuIblAAAKgg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:06.628505 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:62421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpdRvx2fFv'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4T3sRX7OrFkv0FyuIboAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:06.814511 2026] [security2:error] [pid 925208:tid 925376] [client 85.204.70.92:44422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbtAAAACY"]
[Mon Jul 20 06:26:06.816151 2026] [security2:error] [pid 925208:tid 925398] [client 34.74.185.202:55531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbtQAAADw"]
[Mon Jul 20 06:26:06.988153 2026] [security2:error] [pid 925208:tid 925435] [client 34.74.185.202:60959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T3sRX7OrFkv0FyuIbuwAAAGE"]
[Mon Jul 20 06:26:06.997560 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:06.997633 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:58510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:06.998226 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:06.998253 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:58510] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:07.018765 2026] [security2:error] [pid 925208:tid 925444] [client 14.225.17.146:57006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbugAAAGo"], referer: http://ancestralidadytrance.space/WP
[Mon Jul 20 06:26:07.028764 2026] [security2:error] [pid 925208:tid 925393] [client 104.210.140.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mcandmac.com"] [uri "/index.php"] [unique_id "al4T28RX7OrFkv0FyuIadQAANyE"]
[Mon Jul 20 06:26:07.057866 2026] [core:error] [pid 925208:tid 925450] [client 103.153.183.69:13358] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e%u002e%u002f%u002e%u002e%u002fetc%u002fpasswd?_=14q9kmch&v=mswc6), referer: https://www.google.com/search?q=34cdsg
[Mon Jul 20 06:26:07.061614 2026] [security2:error] [pid 925208:tid 925432] [client 127.0.0.1:11640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4T38RX7OrFkv0FyuIbwQAAAF4"], referer: https://www.google.com/search?q=34cdsg
[Mon Jul 20 06:26:07.065393 2026] [security2:error] [pid 925208:tid 925350] [client 14.225.17.146:54228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4T3cRX7OrFkv0FyuIbWgAAAAw"], referer: http://mourgroup.com/WP
[Mon Jul 20 06:26:07.116667 2026] [security2:error] [pid 925208:tid 925387] [client 51.161.65.172:59016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "asliceofleadership.com"] [uri "/"] [unique_id "al4T38RX7OrFkv0FyuIbxgAAADE"]
[Mon Jul 20 06:26:07.116777 2026] [security2:error] [pid 925208:tid 925387] [client 51.161.65.172:59016] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "asliceofleadership.com"] [uri "/"] [unique_id "al4T38RX7OrFkv0FyuIbxgAAADE"]
[Mon Jul 20 06:26:07.190124 2026] [security2:error] [pid 925208:tid 925412] [client 57.141.18.78:37684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T3MRX7OrFkv0FyuIa7QAASmA"]
[Mon Jul 20 06:26:07.334780 2026] [security2:error] [pid 925208:tid 925344] [client 85.204.70.92:44430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIb2QAAAAY"]
[Mon Jul 20 06:26:07.449677 2026] [security2:error] [pid 925208:tid 925376] [client 34.74.185.202:49650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIb5gAAACY"]
[Mon Jul 20 06:26:07.566093 2026] [security2:error] [pid 925208:tid 925372] [client 34.74.185.202:56851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIb8gAAACI"]
[Mon Jul 20 06:26:07.578014 2026] [security2:error] [pid 925208:tid 925266] [remote 217.61.143.92:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIb8wAAPDk"]
[Mon Jul 20 06:26:07.671263 2026] [security2:error] [pid 925208:tid 925400] [client 14.225.17.146:54197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIb8AAAAD4"], referer: http://39ishlife.com/WP
[Mon Jul 20 06:26:07.680967 2026] [security2:error] [pid 925208:tid 925333] [remote 100.42.189.89:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIb_wAARnw"]
[Mon Jul 20 06:26:07.804950 2026] [security2:error] [pid 925208:tid 925460] [client 14.225.17.146:54003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbqAAAAHo"], referer: http://ravmike.com/WP
[Mon Jul 20 06:26:07.813470 2026] [security2:error] [pid 925208:tid 925225] [remote 217.61.143.92:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIcCwAAHBA"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:26:07.861603 2026] [security2:error] [pid 925208:tid 925383] [client 85.204.70.92:44438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T38RX7OrFkv0FyuIcDgAAAC0"]
[Mon Jul 20 06:26:07.928166 2026] [security2:error] [pid 925208:tid 925311] [remote 100.42.189.89:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4T38RX7OrFkv0FyuIcDwAAGmY"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:26:08.014036 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:08.014137 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:64072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:08.015270 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:08.015322 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:64072] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:08.018029 2026] [security2:error] [pid 925208:tid 925439] [client 34.74.185.202:56789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcFAAAAGU"]
[Mon Jul 20 06:26:08.306734 2026] [security2:error] [pid 925208:tid 925462] [client 34.74.185.202:57264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcNQAAAHw"]
[Mon Jul 20 06:26:08.310847 2026] [security2:error] [pid 925208:tid 925438] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcJwAAAGQ"]
[Mon Jul 20 06:26:08.362529 2026] [security2:error] [pid 925208:tid 925397] [client 14.225.17.146:56930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIb0wAAADs"], referer: http://getgarrison.com/WP
[Mon Jul 20 06:26:08.379174 2026] [security2:error] [pid 925208:tid 925449] [client 85.204.70.92:44452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcQQAAAG8"]
[Mon Jul 20 06:26:08.412375 2026] [security2:error] [pid 925208:tid 925448] [client 14.225.17.146:54105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4T3sRX7OrFkv0FyuIbuAAAAG4"], referer: http://olearyplumbingllc.com/WP
[Mon Jul 20 06:26:08.436939 2026] [security2:error] [pid 925208:tid 925395] [client 34.74.185.202:60511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcRgAAADk"]
[Mon Jul 20 06:26:08.619816 2026] [security2:error] [pid 925208:tid 925402] [client 14.225.17.146:54466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcTAAAAEA"], referer: https://39ishlife.com/WP
[Mon Jul 20 06:26:08.722208 2026] [security2:error] [pid 925208:tid 925431] [client 34.74.185.202:56345] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcYgAAAF0"]
[Mon Jul 20 06:26:08.758764 2026] [security2:error] [pid 925208:tid 925388] [client 14.225.17.146:54525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcXAAAADI"], referer: https://ravmike.com/WP
[Mon Jul 20 06:26:08.854900 2026] [security2:error] [pid 925208:tid 925421] [client 34.74.185.202:56999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcbwAAAFM"]
[Mon Jul 20 06:26:08.861221 2026] [security2:error] [pid 925208:tid 925418] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcXwAAAFA"]
[Mon Jul 20 06:26:08.870574 2026] [security2:error] [pid 925208:tid 925410] [client 14.225.17.146:54569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcRwAAAEg"]
[Mon Jul 20 06:26:08.911985 2026] [security2:error] [pid 925208:tid 925463] [client 85.204.70.92:44468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4T4MRX7OrFkv0FyuIcdgAAAH0"]
[Mon Jul 20 06:26:08.924032 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:54540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcYQAAACM"], referer: http://narv.co/WP
[Mon Jul 20 06:26:09.099136 2026] [security2:error] [pid 925208:tid 925377] [client 34.74.185.202:63790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcewAAACc"]
[Mon Jul 20 06:26:09.143606 2026] [security2:error] [pid 925208:tid 925346] [client 223.185.13.213:12083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T4cRX7OrFkv0FyuIcggAAAAg"]
[Mon Jul 20 06:26:09.143702 2026] [security2:error] [pid 925208:tid 925346] [client 223.185.13.213:12083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T4cRX7OrFkv0FyuIcggAAAAg"]
[Mon Jul 20 06:26:09.331293 2026] [security2:error] [pid 925208:tid 925406] [client 34.74.185.202:51450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIclwAAAEQ"]
[Mon Jul 20 06:26:09.376247 2026] [security2:error] [pid 925208:tid 925340] [client 34.73.38.214:60458] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcmQAAAAI"]
[Mon Jul 20 06:26:09.668137 2026] [security2:error] [pid 925208:tid 925373] [client 34.74.185.202:60338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcqgAAACM"]
[Mon Jul 20 06:26:09.718763 2026] [security2:error] [pid 925208:tid 925385] [client 34.74.185.202:61892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.glx.ehd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T4cRX7OrFkv0FyuIcsAAAAC8"]
[Mon Jul 20 06:26:09.904611 2026] [security2:error] [pid 925208:tid 925230] [remote 188.166.241.141:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T4cRX7OrFkv0FyuIcvQAAfRU"]
[Mon Jul 20 06:26:09.942802 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.14:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIb5QAAaHU"]
[Mon Jul 20 06:26:09.976039 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4cRX7OrFkv0FyuIcwwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:09.976169 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4cRX7OrFkv0FyuIcwwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.027312 2026] [security2:error] [pid 925208:tid 925306] [remote 124.55.178.99:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIcxgAAeGE"]
[Mon Jul 20 06:26:10.033170 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:54069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4T4cRX7OrFkv0FyuIcuQAAADE"], referer: https://narv.co/WP
[Mon Jul 20 06:26:10.134273 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIcygAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.134405 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIcygAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.227936 2026] [security2:error] [pid 925208:tid 925425] [client 14.225.17.146:54595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcZQAAAFc"], referer: http://cephasnext.com/WP
[Mon Jul 20 06:26:10.255543 2026] [security2:error] [pid 925208:tid 925410] [client 34.74.185.202:49816] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIc2wAAAEg"]
[Mon Jul 20 06:26:10.285022 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc3gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.285163 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc3gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.333828 2026] [security2:error] [pid 925208:tid 925447] [client 57.141.18.3:27608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T38RX7OrFkv0FyuIcCQAAbWs"]
[Mon Jul 20 06:26:10.337713 2026] [security2:error] [pid 925208:tid 925217] [remote 188.166.241.141:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc4gAAWAg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:10.442300 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc6QAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.442400 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc6QAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.458646 2026] [security2:error] [pid 925208:tid 925463] [client 34.73.38.214:49296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIc7AAAAH0"]
[Mon Jul 20 06:26:10.482717 2026] [security2:error] [pid 925208:tid 925303] [remote 124.55.178.99:59776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc8QAAbl4"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:26:10.487559 2026] [security2:error] [pid 925208:tid 925402] [client 104.234.53.88:51995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc7QAAAEA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:10.548542 2026] [security2:error] [pid 925208:tid 925377] [client 34.74.185.202:63314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIc9wAAACc"]
[Mon Jul 20 06:26:10.607052 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc_AAAAF4"]
[Mon Jul 20 06:26:10.607245 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIc_AAAAF4"]
[Mon Jul 20 06:26:10.642738 2026] [security2:error] [pid 925208:tid 925214] [remote 202.51.202.242:38330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T4sRX7OrFkv0FyuIc_gAAKQU"]
[Mon Jul 20 06:26:10.778522 2026] [security2:error] [pid 925208:tid 925425] [client 77.110.127.138:62439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdDAAAAFc"]
[Mon Jul 20 06:26:10.778613 2026] [security2:error] [pid 925208:tid 925425] [client 77.110.127.138:62439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdDAAAAFc"]
[Mon Jul 20 06:26:10.835336 2026] [security2:error] [pid 925208:tid 925433] [client 34.74.185.202:53562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T4sRX7OrFkv0FyuIdFAAAAF8"]
[Mon Jul 20 06:26:10.896224 2026] [security2:error] [pid 925208:tid 925444] [client 57.141.18.33:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcRAAAalE"]
[Mon Jul 20 06:26:10.951458 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdHAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:10.951572 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T4sRX7OrFkv0FyuIdHAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:11.000119 2026] [security2:error] [pid 925208:tid 925368] [client 57.141.18.22:20600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4MRX7OrFkv0FyuIcSAAAHkg"]
[Mon Jul 20 06:26:11.185943 2026] [security2:error] [pid 925208:tid 925401] [client 104.234.53.65:42667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4T48RX7OrFkv0FyuIdKwAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:11.620680 2026] [security2:error] [pid 925208:tid 925382] [client 14.225.17.146:50050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4T4cRX7OrFkv0FyuIcnAAAACw"], referer: http://younutrition.gr/WP
[Mon Jul 20 06:26:11.774363 2026] [security2:error] [pid 925208:tid 925422] [client 57.141.18.25:35390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4cRX7OrFkv0FyuIcjgAAVAo"]
[Mon Jul 20 06:26:11.832526 2026] [security2:error] [pid 925208:tid 925364] [client 14.225.17.146:54222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4T4sRX7OrFkv0FyuIc0wAAABo"], referer: http://superiorcopywriting.com/WP
[Mon Jul 20 06:26:12.706010 2026] [security2:error] [pid 925208:tid 925412] [client 34.73.38.214:61168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T5MRX7OrFkv0FyuIdmwAAAEo"]
[Mon Jul 20 06:26:12.897366 2026] [security2:error] [pid 925208:tid 925393] [client 57.141.18.110:24640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4sRX7OrFkv0FyuIczQAANw4"]
[Mon Jul 20 06:26:12.923627 2026] [security2:error] [pid 925208:tid 925339] [client 104.234.53.57:62651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4T5MRX7OrFkv0FyuIdqwAAAAE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:13.051430 2026] [security2:error] [pid 925208:tid 925344] [client 57.141.18.116:22858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T4sRX7OrFkv0FyuIc3wAABlM"]
[Mon Jul 20 06:26:13.109625 2026] [security2:error] [pid 925208:tid 925403] [client 136.108.37.179:49262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ahirestaurant-co-nz.dbn.vkf.mybluehost.me"] [uri "/index.php"] [unique_id "al4T5MRX7OrFkv0FyuIdpgAAAEE"]
[Mon Jul 20 06:26:13.190719 2026] [security2:error] [pid 925208:tid 925364] [client 136.108.37.179:49262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ahirestaurant-co-nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdvQAAABo"]
[Mon Jul 20 06:26:13.190878 2026] [security2:error] [pid 925208:tid 925364] [client 136.108.37.179:49262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ahirestaurant-co-nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdvQAAABo"]
[Mon Jul 20 06:26:13.330190 2026] [security2:error] [pid 925208:tid 925432] [client 171.60.139.123:57430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdzQAAAF4"]
[Mon Jul 20 06:26:13.330290 2026] [security2:error] [pid 925208:tid 925432] [client 171.60.139.123:57430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T5cRX7OrFkv0FyuIdzQAAAF4"]
[Mon Jul 20 06:26:13.378825 2026] [security2:error] [pid 925208:tid 925437] [client 14.225.17.146:49157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4T48RX7OrFkv0FyuIdSgAAAGM"], referer: http://fineartsfactory.net/WP
[Mon Jul 20 06:26:13.413967 2026] [security2:error] [pid 925208:tid 925299] [remote 57.141.18.41:26668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4966246"] [unique_id "al4T5cRX7OrFkv0FyuId1QAAK1o"]
[Mon Jul 20 06:26:13.681127 2026] [security2:error] [pid 925208:tid 925450] [client 50.116.65.227:54566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4T5cRX7OrFkv0FyuId5gAAAHA"]
[Mon Jul 20 06:26:13.690966 2026] [security2:error] [pid 925208:tid 925461] [client 50.116.65.227:54578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4T5cRX7OrFkv0FyuId6AAAAHs"]
[Mon Jul 20 06:26:13.851131 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5cRX7OrFkv0FyuId_AAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:13.851286 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5cRX7OrFkv0FyuId_AAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.005139 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.005262 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.006629 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDgAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.006757 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeDgAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.156888 2026] [security2:error] [pid 925208:tid 925421] [client 57.141.18.88:26036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T48RX7OrFkv0FyuIdMQAAUyg"]
[Mon Jul 20 06:26:14.161573 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.161652 2026] [security2:error] [pid 925208:tid 925458] [client 77.110.127.138:62462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.162083 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHwAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.162169 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeHwAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.313938 2026] [security2:error] [pid 925208:tid 925452] [client 77.110.127.138:62464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeLAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.314075 2026] [security2:error] [pid 925208:tid 925452] [client 77.110.127.138:62464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeLAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.476830 2026] [security2:error] [pid 925208:tid 925411] [client 34.73.38.214:56981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T5sRX7OrFkv0FyuIeOwAAAEk"]
[Mon Jul 20 06:26:14.481132 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIePAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.481253 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIePAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.517346 2026] [security2:error] [pid 925208:tid 925360] [client 158.173.166.181:29653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4T5sRX7OrFkv0FyuIeQQAAABY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:14.575290 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:62468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeRQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.575422 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:62468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeRQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.645825 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeUAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.645949 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeUAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.697250 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeVQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.697372 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T5sRX7OrFkv0FyuIeVQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.782664 2026] [security2:error] [pid 925208:tid 925405] [client 103.141.108.143:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeWgAAAEM"]
[Mon Jul 20 06:26:14.782890 2026] [security2:error] [pid 925208:tid 925405] [client 103.141.108.143:65478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeWgAAAEM"]
[Mon Jul 20 06:26:14.876589 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpXm8zdKXe'%20OR%20314=(SELECT%20314%20FROM%20PG_SLEEP(15))--"] [unique_id "al4T5sRX7OrFkv0FyuIeXwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:14.923278 2026] [security2:error] [pid 925208:tid 925367] [client 45.116.69.230:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeYwAAAB0"]
[Mon Jul 20 06:26:14.923382 2026] [security2:error] [pid 925208:tid 925367] [client 45.116.69.230:49690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T5sRX7OrFkv0FyuIeYwAAAB0"]
[Mon Jul 20 06:26:15.307431 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIegwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.307548 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIegwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.335267 2026] [security2:error] [pid 925208:tid 925309] [remote 173.249.4.11:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T58RX7OrFkv0FyuIehwAAIWQ"]
[Mon Jul 20 06:26:15.397660 2026] [security2:error] [pid 925208:tid 925461] [client 34.73.38.214:50718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T58RX7OrFkv0FyuIeiQAAAHs"]
[Mon Jul 20 06:26:15.567966 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIemAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.568372 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIemAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.702313 2026] [security2:error] [pid 925208:tid 925318] [remote 173.249.4.11:42598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T58RX7OrFkv0FyuIepwAAGW0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:15.726711 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIeqQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.726859 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIeqQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.752895 2026] [security2:error] [pid 925208:tid 925378] [client 5.133.192.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "amorlis.com"] [uri "/index.php"] [unique_id "al4T5MRX7OrFkv0FyuIdiwAAKEc"]
[Mon Jul 20 06:26:15.915405 2026] [security2:error] [pid 925208:tid 925377] [client 14.225.17.146:49493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuId0gAAACc"], referer: http://onewingpictures.com/WP
[Mon Jul 20 06:26:15.952137 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:62486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIetQAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.952240 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:62486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T58RX7OrFkv0FyuIetQAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:15.972889 2026] [security2:error] [pid 925208:tid 925371] [client 34.73.38.214:57516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T58RX7OrFkv0FyuIetwAAACE"]
[Mon Jul 20 06:26:16.055505 2026] [security2:error] [pid 925208:tid 925449] [client 57.141.18.95:50098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5MRX7OrFkv0FyuIdngAAb1g"]
[Mon Jul 20 06:26:16.073305 2026] [security2:error] [pid 925208:tid 925346] [client 77.110.127.138:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6MRX7OrFkv0FyuIevwAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:16.073398 2026] [security2:error] [pid 925208:tid 925346] [client 77.110.127.138:62487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6MRX7OrFkv0FyuIevwAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:16.300298 2026] [security2:error] [pid 925208:tid 925342] [client 57.141.18.102:25422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuIdtAAABH0"]
[Mon Jul 20 06:26:16.350548 2026] [security2:error] [pid 925208:tid 925423] [client 104.234.53.80:20453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4T6MRX7OrFkv0FyuIe1AAAAFU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:16.672564 2026] [security2:error] [pid 925208:tid 925370] [client 34.73.38.214:59787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T6MRX7OrFkv0FyuIe7AAAACA"]
[Mon Jul 20 06:26:16.734105 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php32WfhYog')%20OR%20249=(SELECT%20249%20FROM%20PG_SLEEP(15))--"] [unique_id "al4T6MRX7OrFkv0FyuIe8QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:16.971874 2026] [security2:error] [pid 925208:tid 925442] [client 14.225.17.146:49801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4T58RX7OrFkv0FyuIeiAAAAGg"], referer: http://myspineworld.com/WP
[Mon Jul 20 06:26:17.040188 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.57:28574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuId5AAATgY"]
[Mon Jul 20 06:26:17.098384 2026] [security2:error] [pid 925208:tid 925405] [client 104.234.53.65:24387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4T6cRX7OrFkv0FyuIfEwAAAEM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:17.206812 2026] [security2:error] [pid 925208:tid 925355] [client 20.226.66.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "pilarazuaga.com"] [uri "/.well-known/about.php"] [unique_id "al4T6cRX7OrFkv0FyuIfGwAAABE"]
[Mon Jul 20 06:26:17.206943 2026] [security2:error] [pid 925208:tid 925355] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "pilarazuaga.com"] [uri "/.well-known/about.php"] [unique_id "al4T6cRX7OrFkv0FyuIfGwAAABE"]
[Mon Jul 20 06:26:17.376379 2026] [security2:error] [pid 925208:tid 925366] [client 57.141.18.22:20608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T5cRX7OrFkv0FyuIeCQAAHEI"]
[Mon Jul 20 06:26:17.480275 2026] [security2:error] [pid 925208:tid 925347] [client 14.225.17.146:49789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4T58RX7OrFkv0FyuIehQAAAAk"], referer: http://latiendadejorge.com.gt/WP
[Mon Jul 20 06:26:17.621648 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfOQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:17.621773 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfOQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:17.673857 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfPgAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:17.673947 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:62465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T6cRX7OrFkv0FyuIfPgAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:18.016361 2026] [security2:error] [pid 925208:tid 925342] [client 14.225.17.146:52763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfUgAAAAQ"], referer: https://myspineworld.com/WP
[Mon Jul 20 06:26:18.248073 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpCxzyy7bY'))%20OR%20649=(SELECT%20649%20FROM%20PG_SLEEP(15))--"] [unique_id "al4T6sRX7OrFkv0FyuIfegAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:18.285358 2026] [security2:error] [pid 925208:tid 925424] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfVwAAAFY"]
[Mon Jul 20 06:26:18.293940 2026] [security2:error] [pid 925208:tid 925369] [client 70.115.45.82:35544] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/author/admin-2/"] [unique_id "al4T6cRX7OrFkv0FyuIfVQAAAB8"]
[Mon Jul 20 06:26:18.380369 2026] [security2:error] [pid 925208:tid 925464] [client 112.208.70.94:44595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T6sRX7OrFkv0FyuIfjQAAAH4"]
[Mon Jul 20 06:26:18.380485 2026] [security2:error] [pid 925208:tid 925464] [client 112.208.70.94:44595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T6sRX7OrFkv0FyuIfjQAAAH4"]
[Mon Jul 20 06:26:18.465015 2026] [security2:error] [pid 925208:tid 925357] [client 34.73.38.214:49937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T6sRX7OrFkv0FyuIfkwAAABM"]
[Mon Jul 20 06:26:19.236585 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf1wAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.236730 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf1wAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.286907 2026] [security2:error] [pid 925208:tid 925302] [remote 95.217.78.234:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T68RX7OrFkv0FyuIf2wAAG10"]
[Mon Jul 20 06:26:19.295379 2026] [security2:error] [pid 925208:tid 925373] [client 14.225.17.146:59822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4T68RX7OrFkv0FyuIfxAAAACM"]
[Mon Jul 20 06:26:19.387265 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf6gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.387368 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:62513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T68RX7OrFkv0FyuIf6gAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.470779 2026] [security2:error] [pid 925208:tid 925421] [client 14.225.17.146:52407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4T6MRX7OrFkv0FyuIfBwAAAFM"], referer: http://gearwaterproof.com/WP
[Mon Jul 20 06:26:19.517582 2026] [security2:error] [pid 925208:tid 925308] [remote 95.217.78.234:53554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T68RX7OrFkv0FyuIf9QAAamM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:19.788349 2026] [security2:error] [pid 925208:tid 925375] [client 57.141.18.117:31836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6MRX7OrFkv0FyuIewQAAJUM"]
[Mon Jul 20 06:26:19.845988 2026] [security2:error] [pid 925208:tid 925441] [client 77.110.127.138:62518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4T68RX7OrFkv0FyuIgFQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:19.877765 2026] [security2:error] [pid 925208:tid 925462] [client 223.185.13.213:6255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T68RX7OrFkv0FyuIgFwAAAHw"]
[Mon Jul 20 06:26:19.877933 2026] [security2:error] [pid 925208:tid 925462] [client 223.185.13.213:6255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T68RX7OrFkv0FyuIgFwAAAHw"]
[Mon Jul 20 06:26:20.142323 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7MRX7OrFkv0FyuIgQgAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.142488 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7MRX7OrFkv0FyuIgQgAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.403739 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:20.403830 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60781] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:20.404415 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:20.404441 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60781] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:20.494290 2026] [security2:error] [pid 925208:tid 925433] [client 34.73.38.214:56785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4T7MRX7OrFkv0FyuIgiwAAAF8"]
[Mon Jul 20 06:26:20.562106 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4T7MRX7OrFkv0FyuIgkQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.624149 2026] [security2:error] [pid 925208:tid 925365] [client 77.110.127.138:62496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4T7MRX7OrFkv0FyuIglQAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.698738 2026] [security2:error] [pid 925208:tid 925341] [client 57.141.18.17:45912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfDQAAAxo"]
[Mon Jul 20 06:26:20.755928 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgjwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.951484 2026] [security2:error] [pid 925208:tid 925462] [client 103.153.183.69:6550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../srv/.env"] [unique_id "al4T7MRX7OrFkv0FyuIguwAAAHw"], referer: https://www.google.com/
[Mon Jul 20 06:26:20.973238 2026] [security2:error] [pid 925208:tid 925464] [client 77.110.127.138:62469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgpAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:20.976028 2026] [security2:error] [pid 925208:tid 925417] [client 14.225.17.146:52651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4T68RX7OrFkv0FyuIf-wAAAE8"], referer: http://massagelacey.com/WP
[Mon Jul 20 06:26:20.978266 2026] [security2:error] [pid 925208:tid 925380] [client 103.153.183.69:6550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/.env"] [unique_id "al4T7MRX7OrFkv0FyuIgwAAAACo"], referer: https://twitter.com/
[Mon Jul 20 06:26:21.128300 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIgzQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.128422 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIgzQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.178515 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIg0wAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.178621 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:62481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7cRX7OrFkv0FyuIg0wAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.367101 2026] [security2:error] [pid 925208:tid 925381] [client 34.73.38.214:60490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4T7cRX7OrFkv0FyuIg3gAAACs"]
[Mon Jul 20 06:26:21.370678 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:21.370745 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:21.371432 2026] [proxy:error] [pid 925208:tid 925429] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:21.371457 2026] [proxy_http:error] [pid 925208:tid 925429] [client 34.73.38.214:60645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:21.376407 2026] [access_compat:error] [pid 925208:tid 925269] [remote 117.156.187.59:6682] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 06:26:21.412669 2026] [security2:error] [pid 925208:tid 925423] [client 114.119.158.46:39553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/"] [unique_id "al4T7cRX7OrFkv0FyuIg5AAAAFU"], referer: https://codeczz.com/meh/d2aea4d0d88addb598818b9cdcd98bd08e96818aa5d7b8dd8489f209050081cfa3.html
[Mon Jul 20 06:26:21.520067 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIg1AAAAAM"]
[Mon Jul 20 06:26:21.701292 2026] [access_compat:error] [pid 925208:tid 925274] [remote 117.156.187.59:6682] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/favicon.ico, referer: https://www.new-menus.com/index.php?PHPSESSID=tqqgionc3fgvd2k0e2tbmulo85&topic=12.msg348;topicseen
[Mon Jul 20 06:26:21.805824 2026] [security2:error] [pid 925208:tid 925356] [client 57.141.18.62:21544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6cRX7OrFkv0FyuIfVAAAEjI"]
[Mon Jul 20 06:26:21.807550 2026] [security2:error] [pid 925208:tid 925220] [remote 103.187.169.251:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T7cRX7OrFkv0FyuIhEwAAKgs"]
[Mon Jul 20 06:26:21.812491 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T7cRX7OrFkv0FyuIhFAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:21.835269 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:62480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIg9AAAAGk"]
[Mon Jul 20 06:26:22.199500 2026] [security2:error] [pid 925208:tid 925286] [remote 103.187.169.251:36676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T7sRX7OrFkv0FyuIhYAAAf00"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:22.245580 2026] [security2:error] [pid 925208:tid 925461] [client 57.141.18.118:36928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6sRX7OrFkv0FyuIfkQAAe0k"]
[Mon Jul 20 06:26:22.280526 2026] [security2:error] [pid 925208:tid 925442] [client 14.225.17.146:52697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgLQAAAGg"], referer: http://mrbambooplus.com/WP
[Mon Jul 20 06:26:22.320100 2026] [security2:error] [pid 925208:tid 925411] [client 57.141.18.96:34818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T6sRX7OrFkv0FyuIflAAASUs"]
[Mon Jul 20 06:26:22.502197 2026] [security2:error] [pid 925208:tid 925400] [client 50.116.65.227:22524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIhfQAAAD4"]
[Mon Jul 20 06:26:22.713259 2026] [security2:error] [pid 925208:tid 925377] [client 50.116.65.227:22532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIhrwAAACc"]
[Mon Jul 20 06:26:22.732248 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh0QAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:22.732408 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh0QAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:22.811412 2026] [security2:error] [pid 925208:tid 925404] [client 14.225.17.146:59976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIg3QAAAEI"], referer: http://expertcultures.com/WP
[Mon Jul 20 06:26:22.837363 2026] [security2:error] [pid 925208:tid 925344] [client 34.73.38.214:52738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.bzm.ppv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4T7sRX7OrFkv0FyuIh3QAAAAY"]
[Mon Jul 20 06:26:22.865564 2026] [security2:error] [pid 925208:tid 925426] [client 104.234.53.90:21083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4AAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:22.870882 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:22.870938 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:64944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:22.871429 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:22.871455 2026] [proxy_http:error] [pid 925208:tid 925405] [client 34.73.38.214:64944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:22.886003 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4wAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:22.886113 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4wAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.008641 2026] [security2:error] [pid 925208:tid 925355] [client 57.141.18.123:53318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T68RX7OrFkv0FyuIf0QAAEUg"]
[Mon Jul 20 06:26:23.026134 2026] [ssl:error] [pid 925208:tid 925455] [client 66.132.172.178:56868] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.kromosenergy.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:26:23.171905 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIh5wAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.174136 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIh8QAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.366054 2026] [security2:error] [pid 925208:tid 925342] [client 14.225.17.146:60067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIh4gAAAAQ"]
[Mon Jul 20 06:26:23.505217 2026] [security2:error] [pid 925208:tid 925378] [client 14.225.17.146:60182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiBgAAACg"], referer: http://thesoloceos.com/WP
[Mon Jul 20 06:26:23.665497 2026] [security2:error] [pid 925208:tid 925400] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiEgAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.740973 2026] [core:error] [pid 925208:tid 925388] [client 103.153.183.69:48128] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%u002e./%u002e./.env?_=cz21y9yy&v=xqmcf), referer: https://www.google.com/search?q=vfdtar
[Mon Jul 20 06:26:23.780888 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62545] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T78RX7OrFkv0FyuIiOwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.859947 2026] [security2:error] [pid 925208:tid 925338] [client 104.234.53.49:25089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiRQAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:23.922300 2026] [proxy:error] [pid 925208:tid 925424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:23.922353 2026] [proxy_http:error] [pid 925208:tid 925424] [client 34.73.38.214:64321] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:23.922836 2026] [proxy:error] [pid 925208:tid 925424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:23.922863 2026] [proxy_http:error] [pid 925208:tid 925424] [client 34.73.38.214:64321] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:23.940628 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T78RX7OrFkv0FyuIiVAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:23.940776 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T78RX7OrFkv0FyuIiVAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.094567 2026] [security2:error] [pid 925208:tid 925288] [remote 192.241.143.148:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiaAAAA08"]
[Mon Jul 20 06:26:24.102558 2026] [security2:error] [pid 925208:tid 925212] [remote 20.153.140.50:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiZwAAFQM"]
[Mon Jul 20 06:26:24.146728 2026] [security2:error] [pid 925208:tid 925448] [client 171.60.139.123:57948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T8MRX7OrFkv0FyuIibQAAAG4"]
[Mon Jul 20 06:26:24.146909 2026] [security2:error] [pid 925208:tid 925448] [client 171.60.139.123:57948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T8MRX7OrFkv0FyuIibQAAAG4"]
[Mon Jul 20 06:26:24.148182 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiTAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.210409 2026] [security2:error] [pid 925208:tid 925309] [remote 152.228.213.32:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIidQAAPGQ"]
[Mon Jul 20 06:26:24.261922 2026] [security2:error] [pid 925208:tid 925460] [client 57.141.18.64:41772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgTQAAenU"]
[Mon Jul 20 06:26:24.267313 2026] [security2:error] [pid 925208:tid 925302] [remote 192.241.143.148:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiewAAQ10"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:24.374493 2026] [security2:error] [pid 925208:tid 925379] [client 114.119.128.46:45255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "keyq8.com"] [uri "/products/%D9%85%D9%81%D8%A7%D8%AA%D9%8A%D8%AD-%D8%B4%D8%A7%D8%B1%D8%A8-%D8%B4%D9%88%D8%AA%D8%B1"] [unique_id "al4T8MRX7OrFkv0FyuIihQAAACk"], referer: https://keyq8.com/products/%D9%85%D9%81%D8%A7%D8%AA%D9%8A%D8%AD-%D8%B4%D8%A7%D8%B1%D8%A8-%D8%B4%D9%88%D8%AA%D8%B1
[Mon Jul 20 06:26:24.438844 2026] [security2:error] [pid 925208:tid 925301] [remote 152.228.213.32:33670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIiiwAAXVw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:24.497139 2026] [security2:error] [pid 925208:tid 925369] [client 14.225.17.146:53747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIifQAAAB8"], referer: https://thesoloceos.com/WP
[Mon Jul 20 06:26:24.517946 2026] [security2:error] [pid 925208:tid 925217] [remote 20.153.140.50:38726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4T8MRX7OrFkv0FyuIikAAAGgg"], referer: https://narv.co/wp-login.php
[Mon Jul 20 06:26:24.541209 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8MRX7OrFkv0FyuIikQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.541323 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8MRX7OrFkv0FyuIikQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.657690 2026] [security2:error] [pid 925208:tid 925388] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIijQAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:24.739547 2026] [security2:error] [pid 925208:tid 925410] [client 34.73.38.214:64185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4T8MRX7OrFkv0FyuIiqwAAAEg"]
[Mon Jul 20 06:26:24.894804 2026] [security2:error] [pid 925208:tid 925440] [client 5.62.145.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIhEQAAAGY"]
[Mon Jul 20 06:26:25.001980 2026] [security2:error] [pid 925208:tid 925373] [client 57.141.18.49:42512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7MRX7OrFkv0FyuIgtAAAI2U"]
[Mon Jul 20 06:26:25.140015 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIivQAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.217831 2026] [security2:error] [pid 925208:tid 925402] [client 57.141.18.11:47906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7cRX7OrFkv0FyuIgywAAQHY"]
[Mon Jul 20 06:26:25.220721 2026] [security2:error] [pid 925208:tid 925362] [client 14.225.17.146:60233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiMAAAABg"], referer: http://reosportsboats.com/WP
[Mon Jul 20 06:26:25.222837 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4AAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.222948 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4AAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.233928 2026] [security2:error] [pid 925208:tid 925380] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIiwwAAKhk"], referer: http://assasalnazaha.com/WP
[Mon Jul 20 06:26:25.277179 2026] [security2:error] [pid 925208:tid 925462] [client 43.205.139.3:10062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4QAAAHw"]
[Mon Jul 20 06:26:25.277278 2026] [security2:error] [pid 925208:tid 925462] [client 43.205.139.3:10062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi4QAAAHw"]
[Mon Jul 20 06:26:25.287257 2026] [security2:error] [pid 925208:tid 925376] [client 104.234.53.90:35035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4T8cRX7OrFkv0FyuIi5AAAACY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:25.431476 2026] [security2:error] [pid 925208:tid 925409] [client 39.48.81.23:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi6wAAAEc"]
[Mon Jul 20 06:26:25.431651 2026] [security2:error] [pid 925208:tid 925409] [client 39.48.81.23:49432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi6wAAAEc"]
[Mon Jul 20 06:26:25.463460 2026] [security2:error] [pid 925208:tid 925395] [client 103.141.108.143:49560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi8wAAADk"]
[Mon Jul 20 06:26:25.463970 2026] [security2:error] [pid 925208:tid 925395] [client 103.141.108.143:49560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi8wAAADk"]
[Mon Jul 20 06:26:25.510882 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIi5gAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.576555 2026] [security2:error] [pid 925208:tid 925437] [client 45.116.69.230:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi-QAAAGM"]
[Mon Jul 20 06:26:25.576651 2026] [security2:error] [pid 925208:tid 925437] [client 45.116.69.230:50220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T8cRX7OrFkv0FyuIi-QAAAGM"]
[Mon Jul 20 06:26:25.598516 2026] [security2:error] [pid 925208:tid 925312] [remote 162.19.86.63:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8cRX7OrFkv0FyuIi-wAAG2c"]
[Mon Jul 20 06:26:25.714270 2026] [security2:error] [pid 925208:tid 925296] [remote 57.141.18.6:50228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4T8cRX7OrFkv0FyuIjBAAAMFc"]
[Mon Jul 20 06:26:25.829066 2026] [security2:error] [pid 925208:tid 925239] [remote 162.19.86.63:34612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T8cRX7OrFkv0FyuIjDwAAXB4"], referer: https://zoa.jji.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:25.897395 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:62558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T8cRX7OrFkv0FyuIjEwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.948406 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIjGQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:25.948523 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8cRX7OrFkv0FyuIjGQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.051462 2026] [security2:error] [pid 925208:tid 925341] [client 14.225.17.146:60041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIjCwAAAAM"], referer: http://sesamegreenbeans.com/WP
[Mon Jul 20 06:26:26.065528 2026] [security2:error] [pid 925208:tid 925241] [remote 57.141.18.91:64824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4606669"] [unique_id "al4T8sRX7OrFkv0FyuIjJgAABSA"]
[Mon Jul 20 06:26:26.070171 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:53584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIioQAAAE0"], referer: http://alchemygroup.ca/WP
[Mon Jul 20 06:26:26.074020 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIjEAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.104986 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjJwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.105116 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjJwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.125804 2026] [security2:error] [pid 925208:tid 925372] [client 14.225.17.146:65175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjHgAAACI"], referer: https://reosportsboats.com/WP
[Mon Jul 20 06:26:26.141885 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8cRX7OrFkv0FyuIjGwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.421570 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjSwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.421670 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:62564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjSwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.565704 2026] [security2:error] [pid 925208:tid 925446] [client 34.73.38.214:52699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4T8sRX7OrFkv0FyuIjUwAAAGw"]
[Mon Jul 20 06:26:26.590394 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjVQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.590517 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjVQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.603033 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjTgAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.660801 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjTwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.688350 2026] [security2:error] [pid 925208:tid 925385] [client 57.141.18.6:42920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T7sRX7OrFkv0FyuIhrgAAL34"]
[Mon Jul 20 06:26:26.778462 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjaAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.778567 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T8sRX7OrFkv0FyuIjaAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:26.910318 2026] [security2:error] [pid 925208:tid 925350] [client 49.51.243.156:58036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.243.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjcgAAAAw"]
[Mon Jul 20 06:26:27.026808 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjhAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.026901 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjhAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.088327 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjjgAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.088444 2026] [security2:error] [pid 925208:tid 925396] [client 77.110.127.138:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjjgAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.103016 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjcwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.139599 2026] [security2:error] [pid 925208:tid 925389] [client 14.225.17.146:52496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjegAAADM"], referer: https://sesamegreenbeans.com/WP
[Mon Jul 20 06:26:27.303021 2026] [security2:error] [pid 925208:tid 925464] [client 57.141.18.31:45918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIh-QAAfiY"]
[Mon Jul 20 06:26:27.372548 2026] [security2:error] [pid 925208:tid 925353] [client 74.7.227.179:55216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjoQAAD0s"], referer: https://tejasenvironmental.com/p=8401
[Mon Jul 20 06:26:27.384203 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjmwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.414276 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjswAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.414361 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T88RX7OrFkv0FyuIjswAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.495437 2026] [security2:error] [pid 925208:tid 925286] [remote 173.249.4.11:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T88RX7OrFkv0FyuIjwAAAU00"]
[Mon Jul 20 06:26:27.680953 2026] [security2:error] [pid 925208:tid 925388] [client 51.15.143.46:33566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4T88RX7OrFkv0FyuIj0QAAADI"]
[Mon Jul 20 06:26:27.795470 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjxAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:27.833496 2026] [security2:error] [pid 925208:tid 925293] [remote 173.249.4.11:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4T88RX7OrFkv0FyuIj4AAAI1Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:28.020983 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9MRX7OrFkv0FyuIj7gAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.021133 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9MRX7OrFkv0FyuIj7gAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.034821 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:10392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4T9MRX7OrFkv0FyuIj8gAAAD8"]
[Mon Jul 20 06:26:28.034928 2026] [security2:error] [pid 925208:tid 925401] [client 171.61.165.146:10392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4T9MRX7OrFkv0FyuIj8gAAAD8"]
[Mon Jul 20 06:26:28.107623 2026] [security2:error] [pid 925208:tid 925360] [client 57.141.18.117:54338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T78RX7OrFkv0FyuIiMwAAFic"]
[Mon Jul 20 06:26:28.214499 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIj8AAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.226963 2026] [security2:error] [pid 925208:tid 925249] [remote 124.55.178.99:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T9MRX7OrFkv0FyuIj_gAAZig"]
[Mon Jul 20 06:26:28.281259 2026] [security2:error] [pid 925208:tid 925444] [client 104.234.53.75:34781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4T9MRX7OrFkv0FyuIkCQAAAGo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:28.488262 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4T9MRX7OrFkv0FyuIkGAAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.531015 2026] [security2:error] [pid 925208:tid 925465] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkDgAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:28.623622 2026] [security2:error] [pid 925208:tid 925349] [client 158.173.89.95:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4T9MRX7OrFkv0FyuIkIgAAAAs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:28.649711 2026] [security2:error] [pid 925208:tid 925224] [remote 124.55.178.99:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T9MRX7OrFkv0FyuIkJQAAcA8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:28.696501 2026] [security2:error] [pid 925208:tid 925419] [client 14.225.17.146:52017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4T88RX7OrFkv0FyuIjpAAAAFE"], referer: http://dadanetnet.net/WP
[Mon Jul 20 06:26:28.734864 2026] [security2:error] [pid 925208:tid 925353] [client 34.73.38.214:59909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4T9MRX7OrFkv0FyuIkMQAAAA8"]
[Mon Jul 20 06:26:28.933634 2026] [security2:error] [pid 925208:tid 925455] [client 57.141.18.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkOwAAAHU"]
[Mon Jul 20 06:26:28.960093 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkMAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.264291 2026] [security2:error] [pid 925208:tid 925431] [client 77.110.127.138:62590] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4T9cRX7OrFkv0FyuIkXQAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.314372 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkXgAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.314494 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkXgAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.512267 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.33:55600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T8MRX7OrFkv0FyuIivAAAaGM"]
[Mon Jul 20 06:26:29.715495 2026] [security2:error] [pid 925208:tid 925419] [client 34.73.38.214:59675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4T9cRX7OrFkv0FyuIkhgAAAFE"]
[Mon Jul 20 06:26:29.779964 2026] [security2:error] [pid 925208:tid 925354] [client 127.0.0.1:49170] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4T9cRX7OrFkv0FyuIkjQAAABA"], referer: https://www.bing.com/search?q=fjg0ph
[Mon Jul 20 06:26:29.897571 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkmAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.897673 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9cRX7OrFkv0FyuIkmAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:29.925026 2026] [security2:error] [pid 925208:tid 925329] [remote 66.94.101.63:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T9cRX7OrFkv0FyuIkmgAAa3g"]
[Mon Jul 20 06:26:30.185783 2026] [security2:error] [pid 925208:tid 925388] [client 14.225.17.146:64858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aberballet.co.uk"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkHAAAADI"], referer: http://aberballet.co.uk/WP
[Mon Jul 20 06:26:30.604818 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9sRX7OrFkv0FyuIkzgAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:30.604923 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T9sRX7OrFkv0FyuIkzgAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:30.629487 2026] [security2:error] [pid 925208:tid 925442] [client 223.185.13.213:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T9sRX7OrFkv0FyuIk0AAAAGg"]
[Mon Jul 20 06:26:30.630135 2026] [security2:error] [pid 925208:tid 925442] [client 223.185.13.213:32533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T9sRX7OrFkv0FyuIk0AAAAGg"]
[Mon Jul 20 06:26:30.853532 2026] [security2:error] [pid 925208:tid 925367] [client 57.141.18.119:20626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjOgAAHUY"]
[Mon Jul 20 06:26:30.953147 2026] [security2:error] [pid 925208:tid 925344] [client 74.208.214.194:51248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4T9sRX7OrFkv0FyuIk6gAAAAY"]
[Mon Jul 20 06:26:31.036433 2026] [security2:error] [pid 925208:tid 925395] [client 50.116.65.227:13544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4T98RX7OrFkv0FyuIk7wAAADk"]
[Mon Jul 20 06:26:31.046178 2026] [security2:error] [pid 925208:tid 925415] [client 50.116.65.227:13556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4T98RX7OrFkv0FyuIk8QAAAE0"]
[Mon Jul 20 06:26:31.083124 2026] [security2:error] [pid 925208:tid 925416] [client 34.73.38.214:61794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4T98RX7OrFkv0FyuIk9QAAAE4"]
[Mon Jul 20 06:26:31.092279 2026] [security2:error] [pid 925208:tid 925462] [client 14.225.17.146:64898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4T9cRX7OrFkv0FyuIkbQAAAHw"], referer: http://lelandumc.org/WP
[Mon Jul 20 06:26:31.464393 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:62597] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/cowl/"] [unique_id "al4T98RX7OrFkv0FyuIlGQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:31.519307 2026] [security2:error] [pid 925208:tid 925422] [client 57.141.18.80:50326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T8sRX7OrFkv0FyuIjdAAAVDg"]
[Mon Jul 20 06:26:31.714673 2026] [security2:error] [pid 925208:tid 925357] [client 112.208.70.94:45004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T98RX7OrFkv0FyuIlLwAAABM"]
[Mon Jul 20 06:26:31.714816 2026] [security2:error] [pid 925208:tid 925357] [client 112.208.70.94:45004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4T98RX7OrFkv0FyuIlLwAAABM"]
[Mon Jul 20 06:26:31.976812 2026] [security2:error] [pid 925208:tid 925248] [remote 91.142.222.105:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4T98RX7OrFkv0FyuIlPAAAJSc"]
[Mon Jul 20 06:26:32.080880 2026] [security2:error] [pid 925208:tid 925341] [client 77.110.127.138:62525] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4T-MRX7OrFkv0FyuIlSAAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.181021 2026] [security2:error] [pid 925208:tid 925240] [remote 66.94.101.63:41038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T-MRX7OrFkv0FyuIlTQAAah8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:32.218923 2026] [security2:error] [pid 925208:tid 925406] [client 106.219.188.178:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4T-MRX7OrFkv0FyuIlTwAAAEQ"]
[Mon Jul 20 06:26:32.219094 2026] [security2:error] [pid 925208:tid 925406] [client 106.219.188.178:10290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4T-MRX7OrFkv0FyuIlTwAAAEQ"]
[Mon Jul 20 06:26:32.232553 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlVgAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.232658 2026] [security2:error] [pid 925208:tid 925415] [client 77.110.127.138:62600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlVgAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.305697 2026] [security2:error] [pid 925208:tid 925276] [remote 91.142.222.105:43678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4T-MRX7OrFkv0FyuIlYQAARkM"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 06:26:32.529375 2026] [security2:error] [pid 925208:tid 925445] [client 110.249.201.196:19750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sesamegreenbeans.com"] [uri "/robots.txt"] [unique_id "al4T-MRX7OrFkv0FyuIldAAAAGs"]
[Mon Jul 20 06:26:32.737243 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlhgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.737344 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-MRX7OrFkv0FyuIlhgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:32.815239 2026] [security2:error] [pid 925208:tid 925365] [client 34.73.38.214:59194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4T-MRX7OrFkv0FyuIljwAAABs"]
[Mon Jul 20 06:26:33.187067 2026] [security2:error] [pid 925208:tid 925398] [client 57.141.18.22:25006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T9MRX7OrFkv0FyuIkKAAAPCQ"]
[Mon Jul 20 06:26:33.384514 2026] [ssl:error] [pid 925208:tid 925412] [client 2.192.26.217:44302] AH02032: Hostname www.petpawo.com provided via SNI and hostname www.bbcgoodfood.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:26:33.409499 2026] [security2:error] [pid 925208:tid 925445] [client 14.225.17.146:61264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlvAAAAGs"], referer: http://processorstudio.com/WP
[Mon Jul 20 06:26:33.422435 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-cRX7OrFkv0FyuIlvwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:33.422534 2026] [security2:error] [pid 925208:tid 925429] [client 77.110.127.138:62584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-cRX7OrFkv0FyuIlvwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:33.904738 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62608] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/cowl/"] [unique_id "al4T-cRX7OrFkv0FyuIl8QAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:34.055705 2026] [security2:error] [pid 925208:tid 925439] [client 77.110.127.138:62609] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4T-sRX7OrFkv0FyuImAwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:34.260784 2026] [security2:error] [pid 925208:tid 925418] [client 14.225.17.146:63095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4T-sRX7OrFkv0FyuImEgAAAFA"], referer: https://processorstudio.com/WP
[Mon Jul 20 06:26:34.263207 2026] [security2:error] [pid 925208:tid 925410] [client 34.73.38.214:62129] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4T-sRX7OrFkv0FyuImFQAAAEg"]
[Mon Jul 20 06:26:34.647866 2026] [security2:error] [pid 925208:tid 925344] [client 171.60.139.123:58454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T-sRX7OrFkv0FyuImMgAAAAY"]
[Mon Jul 20 06:26:34.648012 2026] [security2:error] [pid 925208:tid 925344] [client 171.60.139.123:58454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4T-sRX7OrFkv0FyuImMgAAAAY"]
[Mon Jul 20 06:26:34.859180 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-sRX7OrFkv0FyuImSAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:34.859270 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-sRX7OrFkv0FyuImSAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:35.011943 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-8RX7OrFkv0FyuImUgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:35.012037 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:62614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T-8RX7OrFkv0FyuImUgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:35.160033 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:52025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlpQAAAAA"], referer: http://dollpassionista.com/WP
[Mon Jul 20 06:26:35.229995 2026] [security2:error] [pid 925208:tid 925258] [remote 192.241.143.148:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T-8RX7OrFkv0FyuImbQAABjE"]
[Mon Jul 20 06:26:35.311635 2026] [security2:error] [pid 925208:tid 925348] [client 14.225.17.146:64968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImZgAAAAo"], referer: http://keywayconstructionclt.com/WP
[Mon Jul 20 06:26:35.407613 2026] [security2:error] [pid 925208:tid 925301] [remote 192.241.143.148:42326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4T-8RX7OrFkv0FyuImeAAAQ1w"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:35.428305 2026] [security2:error] [pid 925208:tid 925363] [client 57.141.18.59:50568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T9sRX7OrFkv0FyuIk4gAAGRw"]
[Mon Jul 20 06:26:35.791066 2026] [security2:error] [pid 925208:tid 925396] [client 39.48.81.23:50059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T-8RX7OrFkv0FyuImmAAAADo"]
[Mon Jul 20 06:26:35.791263 2026] [security2:error] [pid 925208:tid 925396] [client 39.48.81.23:50059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4T-8RX7OrFkv0FyuImmAAAADo"]
[Mon Jul 20 06:26:36.157910 2026] [security2:error] [pid 925208:tid 925359] [client 34.73.38.214:62133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4T_MRX7OrFkv0FyuImtQAAABU"]
[Mon Jul 20 06:26:36.163803 2026] [security2:error] [pid 925208:tid 925440] [client 103.141.108.143:50049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImsgAAAGY"]
[Mon Jul 20 06:26:36.163915 2026] [security2:error] [pid 925208:tid 925440] [client 103.141.108.143:50049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImsgAAAGY"]
[Mon Jul 20 06:26:36.167407 2026] [security2:error] [pid 925208:tid 925401] [client 14.225.17.146:61676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImogAAAD8"], referer: https://dollpassionista.com/WP
[Mon Jul 20 06:26:36.190786 2026] [security2:error] [pid 925208:tid 925376] [client 14.225.17.146:63101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4T_MRX7OrFkv0FyuImrwAAACY"], referer: https://keywayconstructionclt.com/WP
[Mon Jul 20 06:26:36.362950 2026] [security2:error] [pid 925208:tid 925355] [client 45.116.69.230:50739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImyAAAABE"]
[Mon Jul 20 06:26:36.363054 2026] [security2:error] [pid 925208:tid 925355] [client 45.116.69.230:50739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4T_MRX7OrFkv0FyuImyAAAABE"]
[Mon Jul 20 06:26:36.436341 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_MRX7OrFkv0FyuImzgAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:36.436442 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:62622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_MRX7OrFkv0FyuImzgAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:36.880871 2026] [security2:error] [pid 925208:tid 925308] [remote 5.161.225.162:32774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4T_MRX7OrFkv0FyuIm5wAAU2M"]
[Mon Jul 20 06:26:36.965625 2026] [security2:error] [pid 925208:tid 925413] [client 14.225.17.146:52122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIluwAAAEs"], referer: http://areitoproducciones.com/WP
[Mon Jul 20 06:26:37.042369 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:62627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/cowl/"] [unique_id "al4T_cRX7OrFkv0FyuIm8wAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:37.101536 2026] [security2:error] [pid 925208:tid 925383] [client 57.141.18.68:36266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-MRX7OrFkv0FyuIlZwAALRY"]
[Mon Jul 20 06:26:37.307872 2026] [security2:error] [pid 925208:tid 925281] [remote 5.161.225.162:32774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4T_cRX7OrFkv0FyuInDAAATkg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:26:37.595868 2026] [security2:error] [pid 925208:tid 925362] [client 104.234.53.67:21935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4T_cRX7OrFkv0FyuInJQAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:37.805966 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.12:44282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlowAAVxg"]
[Mon Jul 20 06:26:38.186232 2026] [security2:error] [pid 925208:tid 925384] [client 14.225.17.146:61383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T_sRX7OrFkv0FyuInVAAAAC4"], referer: http://fkconstructionfunding.com/WP
[Mon Jul 20 06:26:38.301033 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.84:53938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIlzQAATTY"]
[Mon Jul 20 06:26:38.373248 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInbwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.373363 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:62635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInbwAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.537283 2026] [security2:error] [pid 925208:tid 925352] [client 77.110.127.138:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInegAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.537383 2026] [security2:error] [pid 925208:tid 925352] [client 77.110.127.138:62636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_sRX7OrFkv0FyuInegAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:38.604550 2026] [security2:error] [pid 925208:tid 925304] [remote 74.235.96.117:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4T_sRX7OrFkv0FyuInewAAIV8"]
[Mon Jul 20 06:26:38.677635 2026] [security2:error] [pid 925208:tid 925356] [client 14.225.17.146:63295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4T_cRX7OrFkv0FyuInSgAAABI"], referer: http://aljosour-alarabia.com/WP
[Mon Jul 20 06:26:38.725434 2026] [security2:error] [pid 925208:tid 925423] [client 57.141.18.104:30916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-cRX7OrFkv0FyuIl9gAAVXs"]
[Mon Jul 20 06:26:38.765386 2026] [security2:error] [pid 925208:tid 925396] [client 153.51.237.35:1250] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4T_sRX7OrFkv0FyuInjAAAADo"]
[Mon Jul 20 06:26:38.902236 2026] [security2:error] [pid 925208:tid 925418] [client 34.73.38.214:62108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4T_sRX7OrFkv0FyuInmQAAAFA"]
[Mon Jul 20 06:26:39.168132 2026] [security2:error] [pid 925208:tid 925340] [client 14.225.17.146:55197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4T_8RX7OrFkv0FyuInqQAAAAI"], referer: https://fkconstructionfunding.com/WP
[Mon Jul 20 06:26:39.278450 2026] [security2:error] [pid 925208:tid 925240] [remote 74.235.96.117:38826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4T_8RX7OrFkv0FyuInswAAdB8"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 06:26:39.422640 2026] [security2:error] [pid 925208:tid 925361] [client 57.141.18.37:36990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-sRX7OrFkv0FyuImLQAAFx0"]
[Mon Jul 20 06:26:39.553281 2026] [security2:error] [pid 925208:tid 925311] [remote 202.51.202.242:39272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4T_8RX7OrFkv0FyuInxQAAPWY"]
[Mon Jul 20 06:26:39.984901 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_8RX7OrFkv0FyuIn5QAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:39.985022 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:62647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4T_8RX7OrFkv0FyuIn5QAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.146980 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn8QAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.147088 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:62653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn8QAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.307005 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn_gAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.307126 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIn_gAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.458163 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoDQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.458253 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:62656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoDQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.525796 2026] [security2:error] [pid 925208:tid 925338] [client 57.141.18.97:24200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImkAAAAEc"]
[Mon Jul 20 06:26:40.721679 2026] [security2:error] [pid 925208:tid 925381] [client 57.141.18.4:47902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T-8RX7OrFkv0FyuImnQAAK2o"]
[Mon Jul 20 06:26:40.877799 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoMQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.877901 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:62661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAMRX7OrFkv0FyuIoMQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:40.890474 2026] [security2:error] [pid 925208:tid 925438] [client 98.159.234.160:65337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UAMRX7OrFkv0FyuIoNQAAAGQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:41.042109 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoPgAAAAE"]
[Mon Jul 20 06:26:41.042205 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:62664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoPgAAAAE"]
[Mon Jul 20 06:26:41.201628 2026] [security2:error] [pid 925208:tid 925294] [remote 124.55.178.99:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAcRX7OrFkv0FyuIoRwAAOlU"]
[Mon Jul 20 06:26:41.202079 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoSAAAADY"]
[Mon Jul 20 06:26:41.202161 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UAcRX7OrFkv0FyuIoSAAAADY"]
[Mon Jul 20 06:26:41.363361 2026] [security2:error] [pid 925208:tid 925437] [client 50.116.65.227:27536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UAcRX7OrFkv0FyuIoVQAAAGM"]
[Mon Jul 20 06:26:41.373389 2026] [security2:error] [pid 925208:tid 925464] [client 50.116.65.227:27546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UAcRX7OrFkv0FyuIoVwAAAH4"]
[Mon Jul 20 06:26:41.410220 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:55219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4UAcRX7OrFkv0FyuIoQgAAADE"], referer: http://talknutritionwithlesley.com/WP
[Mon Jul 20 06:26:41.411642 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UAcRX7OrFkv0FyuIoRgAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:41.503744 2026] [security2:error] [pid 925208:tid 925448] [client 34.73.38.214:61121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UAcRX7OrFkv0FyuIoXQAAAG4"]
[Mon Jul 20 06:26:41.704849 2026] [security2:error] [pid 925208:tid 925268] [remote 124.55.178.99:51186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAcRX7OrFkv0FyuIocgAAOTs"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:26:41.717042 2026] [security2:error] [pid 925208:tid 925443] [client 223.185.13.213:6253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UAcRX7OrFkv0FyuIodAAAAGk"]
[Mon Jul 20 06:26:41.717139 2026] [security2:error] [pid 925208:tid 925443] [client 223.185.13.213:6253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UAcRX7OrFkv0FyuIodAAAAGk"]
[Mon Jul 20 06:26:41.774930 2026] [security2:error] [pid 925208:tid 925263] [remote 5.161.225.162:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UAcRX7OrFkv0FyuIoegAAFzY"]
[Mon Jul 20 06:26:41.838315 2026] [security2:error] [pid 925208:tid 925381] [client 74.208.214.194:42670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UAcRX7OrFkv0FyuIogAAAACs"]
[Mon Jul 20 06:26:42.017335 2026] [security2:error] [pid 925208:tid 925288] [remote 5.161.225.162:48542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIokAAAfE8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:42.064273 2026] [security2:error] [pid 925208:tid 925282] [remote 81.173.115.7:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIokQAAMEk"]
[Mon Jul 20 06:26:42.235407 2026] [security2:error] [pid 925208:tid 925393] [client 34.73.38.214:58072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UAsRX7OrFkv0FyuIooQAAADc"]
[Mon Jul 20 06:26:42.278262 2026] [security2:error] [pid 925208:tid 925363] [client 57.141.18.102:28548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T_cRX7OrFkv0FyuInKAAAGSU"]
[Mon Jul 20 06:26:42.281189 2026] [security2:error] [pid 925208:tid 925332] [remote 81.173.115.7:54256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIopgAATHs"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:26:42.462702 2026] [security2:error] [pid 925208:tid 925289] [remote 202.51.202.242:39272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UAsRX7OrFkv0FyuIougAAAFA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:42.463842 2026] [security2:error] [pid 925208:tid 925426] [client 158.173.241.141:24495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIongAAWCI"]
[Mon Jul 20 06:26:42.600339 2026] [security2:error] [pid 925208:tid 925413] [client 106.219.188.178:27752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UAsRX7OrFkv0FyuIowAAAAEs"]
[Mon Jul 20 06:26:42.600453 2026] [security2:error] [pid 925208:tid 925413] [client 106.219.188.178:27752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UAsRX7OrFkv0FyuIowAAAAEs"]
[Mon Jul 20 06:26:42.604739 2026] [security2:error] [pid 925208:tid 925419] [client 114.119.134.231:61991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "vfcthomasville.org"] [uri "/sermons/the-domino-effect-part-2-vision-and-voices-jamie-nunnally/"] [unique_id "al4UAsRX7OrFkv0FyuIowQAAAFE"], referer: https://www.vfcthomasville.org/
[Mon Jul 20 06:26:43.010263 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo4wAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.010388 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo4wAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.148411 2026] [security2:error] [pid 925208:tid 925408] [client 50.116.65.227:29658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4UA8RX7OrFkv0FyuIo7wAAAEY"]
[Mon Jul 20 06:26:43.161539 2026] [security2:error] [pid 925208:tid 925381] [client 50.116.65.227:27564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4UA8RX7OrFkv0FyuIo8QAAACk"]
[Mon Jul 20 06:26:43.199158 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo-AAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.199269 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UA8RX7OrFkv0FyuIo-AAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:43.304253 2026] [security2:error] [pid 925208:tid 925367] [client 14.225.17.146:55452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIovwAAAB0"], referer: http://idigress.studio/WP
[Mon Jul 20 06:26:43.618803 2026] [security2:error] [pid 925208:tid 925373] [client 57.141.18.42:59198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4T_sRX7OrFkv0FyuInkwAAIxw"]
[Mon Jul 20 06:26:44.222298 2026] [security2:error] [pid 925208:tid 925349] [client 34.73.38.214:56060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UBMRX7OrFkv0FyuIpPwAAAAs"]
[Mon Jul 20 06:26:44.367932 2026] [security2:error] [pid 925208:tid 925339] [client 117.212.246.249:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.246.212.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpTQAAAAE"]
[Mon Jul 20 06:26:44.368079 2026] [security2:error] [pid 925208:tid 925339] [client 117.212.246.249:51782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "arunavabanerjee.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpTQAAAAE"]
[Mon Jul 20 06:26:44.960388 2026] [security2:error] [pid 925208:tid 925368] [client 112.208.70.94:45425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpigAAAB4"]
[Mon Jul 20 06:26:44.960504 2026] [security2:error] [pid 925208:tid 925368] [client 112.208.70.94:45425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UBMRX7OrFkv0FyuIpigAAAB4"]
[Mon Jul 20 06:26:44.971009 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UBMRX7OrFkv0FyuIpgAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.175070 2026] [security2:error] [pid 925208:tid 925420] [client 171.60.139.123:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UBcRX7OrFkv0FyuIpnQAAAFI"]
[Mon Jul 20 06:26:45.175238 2026] [security2:error] [pid 925208:tid 925420] [client 171.60.139.123:58964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UBcRX7OrFkv0FyuIpnQAAAFI"]
[Mon Jul 20 06:26:45.181290 2026] [security2:error] [pid 925208:tid 925352] [client 77.110.127.138:62678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 440 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UBcRX7OrFkv0FyuIpnwAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.250524 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.85:48838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAMRX7OrFkv0FyuIn7QAAaAI"]
[Mon Jul 20 06:26:45.337041 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UBcRX7OrFkv0FyuIprAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.337153 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UBcRX7OrFkv0FyuIprAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:45.753564 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UBcRX7OrFkv0FyuIptwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:46.021594 2026] [security2:error] [pid 925208:tid 925321] [remote 81.173.115.7:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UBsRX7OrFkv0FyuIp6AAAEXA"]
[Mon Jul 20 06:26:46.099178 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.4:26538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAMRX7OrFkv0FyuIoOgAATS0"]
[Mon Jul 20 06:26:46.285727 2026] [security2:error] [pid 925208:tid 925295] [remote 128.1.121.56:52954] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "abilityplus.org"] [uri "/"] [unique_id "al4UBsRX7OrFkv0FyuIqAwAAPFY"]
[Mon Jul 20 06:26:46.285851 2026] [security2:error] [pid 925208:tid 925261] [remote 81.173.115.7:56394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UBsRX7OrFkv0FyuIqBAAAEjQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:46.836637 2026] [security2:error] [pid 925208:tid 925459] [client 39.48.81.23:50635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLAAAAHk"]
[Mon Jul 20 06:26:46.836772 2026] [security2:error] [pid 925208:tid 925459] [client 39.48.81.23:50635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLAAAAHk"]
[Mon Jul 20 06:26:46.866489 2026] [security2:error] [pid 925208:tid 925371] [client 103.141.108.143:50521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLwAAACE"]
[Mon Jul 20 06:26:46.866625 2026] [security2:error] [pid 925208:tid 925371] [client 103.141.108.143:50521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqLwAAACE"]
[Mon Jul 20 06:26:46.999692 2026] [security2:error] [pid 925208:tid 925420] [client 45.116.69.230:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqOQAAAFI"]
[Mon Jul 20 06:26:46.999852 2026] [security2:error] [pid 925208:tid 925420] [client 45.116.69.230:51256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UBsRX7OrFkv0FyuIqOQAAAFI"]
[Mon Jul 20 06:26:47.064667 2026] [security2:error] [pid 925208:tid 925215] [remote 68.178.160.25:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqQgAABQY"]
[Mon Jul 20 06:26:47.281971 2026] [security2:error] [pid 925208:tid 925241] [remote 45.90.123.233:34316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqWQAAKyA"]
[Mon Jul 20 06:26:47.457638 2026] [security2:error] [pid 925208:tid 925384] [client 57.141.18.14:52024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIonAAALmA"]
[Mon Jul 20 06:26:47.507362 2026] [security2:error] [pid 925208:tid 925312] [remote 45.90.123.233:34316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqaQAAI2c"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:26:47.568918 2026] [security2:error] [pid 925208:tid 925296] [remote 68.178.160.25:34044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UB8RX7OrFkv0FyuIqbAAAe1c"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:26:47.662274 2026] [security2:error] [pid 925208:tid 925346] [client 14.225.17.146:63949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4UBsRX7OrFkv0FyuIp8AAAAAg"], referer: http://bnb-engineering.com/WP
[Mon Jul 20 06:26:47.690630 2026] [security2:error] [pid 925208:tid 925378] [client 57.141.18.115:32152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIotQAAKGI"]
[Mon Jul 20 06:26:47.980095 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UB8RX7OrFkv0FyuIqigAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:47.980209 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UB8RX7OrFkv0FyuIqigAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.006671 2026] [security2:error] [pid 925208:tid 925375] [client 57.141.18.92:47848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UAsRX7OrFkv0FyuIoxgAAJV0"]
[Mon Jul 20 06:26:48.137158 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqmgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.137320 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqmgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.303284 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqpwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.303395 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:62684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqpwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.514919 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqtQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.515021 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqtQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.681565 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqvwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.681673 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIqvwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.709971 2026] [security2:error] [pid 925208:tid 925357] [client 66.249.72.165:44778] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "box5020.bluehost.com"] [uri "/robots.txt"] [unique_id "al4UCMRX7OrFkv0FyuIqwAAAABM"]
[Mon Jul 20 06:26:48.835310 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq0QAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.835400 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:62688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq0QAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.952809 2026] [security2:error] [pid 925208:tid 925434] [client 46.55.204.251:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4UBsRX7OrFkv0FyuIp8gAAAGA"]
[Mon Jul 20 06:26:48.987121 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq4gAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:48.987214 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCMRX7OrFkv0FyuIq4gAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.168569 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq5gAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.168675 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq5gAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.327049 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq-gAAAEA"]
[Mon Jul 20 06:26:49.327170 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:62692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIq-gAAAEA"]
[Mon Jul 20 06:26:49.464809 2026] [security2:error] [pid 925208:tid 925431] [client 57.141.18.11:53720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBMRX7OrFkv0FyuIpRwAAXUA"]
[Mon Jul 20 06:26:49.480138 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrCQAAAAw"]
[Mon Jul 20 06:26:49.480213 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:62693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrCQAAAAw"]
[Mon Jul 20 06:26:49.617827 2026] [proxy:error] [pid 925208:tid 925406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.617918 2026] [proxy_http:error] [pid 925208:tid 925406] [client 185.147.157.29:58298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.618647 2026] [proxy:error] [pid 925208:tid 925406] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.618681 2026] [proxy_http:error] [pid 925208:tid 925406] [client 185.147.157.29:58298] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.634881 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrEwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.635014 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:62694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrEwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.638497 2026] [proxy:error] [pid 925208:tid 925371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.638528 2026] [proxy_http:error] [pid 925208:tid 925371] [client 185.147.157.29:32720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.639000 2026] [proxy:error] [pid 925208:tid 925371] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.639022 2026] [proxy_http:error] [pid 925208:tid 925371] [client 185.147.157.29:32720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.681005 2026] [security2:error] [pid 925208:tid 925272] [remote 192.241.143.148:45464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UCcRX7OrFkv0FyuIrHAAARj8"]
[Mon Jul 20 06:26:49.681178 2026] [security2:error] [pid 925208:tid 925408] [client 192.241.143.148:45464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UCcRX7OrFkv0FyuIrHAAARj8"]
[Mon Jul 20 06:26:49.778381 2026] [security2:error] [pid 925208:tid 925421] [client 57.141.18.25:51248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBMRX7OrFkv0FyuIpYgAAUw4"]
[Mon Jul 20 06:26:49.791876 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrKwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.792029 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:62695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrKwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.835881 2026] [proxy:error] [pid 925208:tid 925393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.835961 2026] [proxy_http:error] [pid 925208:tid 925393] [client 185.147.157.29:32730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.836444 2026] [proxy:error] [pid 925208:tid 925382] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.836543 2026] [proxy_http:error] [pid 925208:tid 925382] [client 185.147.157.29:32736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.836631 2026] [proxy:error] [pid 925208:tid 925393] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.836663 2026] [proxy_http:error] [pid 925208:tid 925393] [client 185.147.157.29:32730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.837433 2026] [proxy:error] [pid 925208:tid 925382] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:49.837487 2026] [proxy_http:error] [pid 925208:tid 925382] [client 185.147.157.29:32736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:49.945419 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrNAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:49.945521 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCcRX7OrFkv0FyuIrNAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.102173 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrSQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.102267 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrSQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.189151 2026] [security2:error] [pid 925208:tid 925395] [client 50.116.65.227:24650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/wp-cron.php"] [unique_id "al4UCsRX7OrFkv0FyuIrUQAAADk"]
[Mon Jul 20 06:26:50.217790 2026] [security2:error] [pid 925208:tid 925423] [client 14.225.17.146:61871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrTAAAAFU"], referer: http://grndl.com/WP
[Mon Jul 20 06:26:50.239416 2026] [security2:error] [pid 925208:tid 925359] [client 57.141.18.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrRwAAABU"]
[Mon Jul 20 06:26:50.258835 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrVgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.258952 2026] [security2:error] [pid 925208:tid 925366] [client 77.110.127.138:62698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrVgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.292213 2026] [security2:error] [pid 925208:tid 925392] [client 14.225.17.146:50406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrPAAAADY"], referer: http://healthylifegourmet.org/WP
[Mon Jul 20 06:26:50.412002 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrYQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.412095 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrYQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.453513 2026] [security2:error] [pid 925208:tid 925386] [client 104.234.53.94:33545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UCsRX7OrFkv0FyuIrZgAAADA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:50.479558 2026] [security2:error] [pid 925208:tid 925369] [client 50.116.65.227:16692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UCsRX7OrFkv0FyuIraQAAAB8"]
[Mon Jul 20 06:26:50.490645 2026] [security2:error] [pid 925208:tid 925370] [client 50.116.65.227:16698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UCsRX7OrFkv0FyuIrbAAAACA"]
[Mon Jul 20 06:26:50.571582 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrcwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.571673 2026] [security2:error] [pid 925208:tid 925462] [client 77.110.127.138:62700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrcwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.750138 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrgwAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.750269 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrgwAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.849263 2026] [security2:error] [pid 925208:tid 925360] [client 57.141.18.95:55830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBcRX7OrFkv0FyuIpuwAAFhs"]
[Mon Jul 20 06:26:50.908688 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrkAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.908791 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UCsRX7OrFkv0FyuIrkAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:50.969039 2026] [security2:error] [pid 925208:tid 925348] [client 57.141.18.113:22636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBcRX7OrFkv0FyuIpwQAAClk"]
[Mon Jul 20 06:26:51.062628 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrlwAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.062765 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrlwAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.178301 2026] [security2:error] [pid 925208:tid 925278] [remote 160.187.68.132:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIrngAAUEU"]
[Mon Jul 20 06:26:51.216073 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIroAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.216185 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:62704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIroAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.237121 2026] [security2:error] [pid 925208:tid 925308] [remote 160.187.68.132:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIroQAAG2M"]
[Mon Jul 20 06:26:51.371464 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIruQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.371542 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:62705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIruQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.526182 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:62706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrxgAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.526297 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:62706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrxgAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.580022 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrzQAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.580135 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIrzQAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.651605 2026] [security2:error] [pid 925208:tid 925251] [remote 160.187.68.132:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIr1AAAQyo"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 06:26:51.736227 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr2QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.736340 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:62707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr2QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.749136 2026] [security2:error] [pid 925208:tid 925331] [remote 160.187.68.132:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UC8RX7OrFkv0FyuIr3QAAIHo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:26:51.892202 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr6AAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:51.892289 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UC8RX7OrFkv0FyuIr6AAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.045621 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr9QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.045718 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr9QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.096864 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr_QAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.096959 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIr_QAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.132590 2026] [security2:error] [pid 925208:tid 925427] [client 57.141.18.96:57648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UBsRX7OrFkv0FyuIqMwAAWSQ"]
[Mon Jul 20 06:26:52.249170 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.249295 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.251372 2026] [security2:error] [pid 925208:tid 925390] [client 13.201.64.214:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBgAAADQ"]
[Mon Jul 20 06:26:52.251465 2026] [security2:error] [pid 925208:tid 925390] [client 13.201.64.214:64758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsBgAAADQ"]
[Mon Jul 20 06:26:52.277370 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:19949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsCQAAAC0"]
[Mon Jul 20 06:26:52.277515 2026] [security2:error] [pid 925208:tid 925383] [client 223.185.13.213:19949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsCQAAAC0"]
[Mon Jul 20 06:26:52.402948 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsEQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.403044 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:62711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsEQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.569475 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsHgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.569582 2026] [security2:error] [pid 925208:tid 925371] [client 77.110.127.138:62712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsHgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.621368 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsIgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.621488 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsIgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.781763 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:62713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.781877 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:62713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.846635 2026] [security2:error] [pid 925208:tid 925388] [client 106.219.188.178:27748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKgAAADI"]
[Mon Jul 20 06:26:52.853236 2026] [security2:error] [pid 925208:tid 925388] [client 106.219.188.178:27748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UDMRX7OrFkv0FyuIsKgAAADI"]
[Mon Jul 20 06:26:52.871505 2026] [security2:error] [pid 925208:tid 925391] [client 57.141.18.108:33030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UB8RX7OrFkv0FyuIqeQAANXE"]
[Mon Jul 20 06:26:52.874644 2026] [security2:error] [pid 925208:tid 925354] [client 45.157.112.60:48217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UDMRX7OrFkv0FyuIsLQAAABA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:26:52.934683 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsNAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:52.934777 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDMRX7OrFkv0FyuIsNAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.049830 2026] [security2:error] [pid 925208:tid 925461] [client 171.61.165.146:15076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPAAAAHs"]
[Mon Jul 20 06:26:53.049947 2026] [security2:error] [pid 925208:tid 925461] [client 171.61.165.146:15076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPAAAAHs"]
[Mon Jul 20 06:26:53.093242 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.093377 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:62715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsPwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.194254 2026] [security2:error] [pid 925208:tid 925459] [client 57.141.18.50:46372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCMRX7OrFkv0FyuIqlgAAeXM"]
[Mon Jul 20 06:26:53.198779 2026] [security2:error] [pid 925208:tid 925338] [client 104.234.53.85:55153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UDcRX7OrFkv0FyuIsRAAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:53.248480 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsSgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.248596 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:62716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsSgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.405619 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:62717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsXAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.405714 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:62717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsXAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.728684 2026] [security2:error] [pid 925208:tid 925276] [remote 41.76.213.235:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.213.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UDcRX7OrFkv0FyuIsdAAAb0M"]
[Mon Jul 20 06:26:53.841809 2026] [security2:error] [pid 925208:tid 925349] [client 57.141.18.66:30034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCMRX7OrFkv0FyuIqvQAAC38"]
[Mon Jul 20 06:26:53.903551 2026] [security2:error] [pid 925208:tid 925448] [client 77.110.127.138:62718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsgAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.903686 2026] [security2:error] [pid 925208:tid 925448] [client 77.110.127.138:62718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDcRX7OrFkv0FyuIsgAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:53.967960 2026] [security2:error] [pid 925208:tid 925429] [client 104.234.53.61:58351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UDcRX7OrFkv0FyuIsfgAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:54.056572 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsiwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.056675 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:62720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsiwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.057557 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:62719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 164 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UDsRX7OrFkv0FyuIsigAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.149433 2026] [security2:error] [pid 925208:tid 925419] [client 57.141.18.66:30036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCcRX7OrFkv0FyuIq5AAAUTM"]
[Mon Jul 20 06:26:54.228381 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsowAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.228519 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsowAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.264020 2026] [security2:error] [pid 925208:tid 925237] [remote 41.76.213.235:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.213.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UDsRX7OrFkv0FyuIsrgAAPxw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:26:54.381348 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsuwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.381469 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:62723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIsuwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.460804 2026] [security2:error] [pid 925208:tid 925369] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UDsRX7OrFkv0FyuIsrQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.539203 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIswwAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.539305 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:62724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIswwAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.621702 2026] [security2:error] [pid 925208:tid 925465] [client 77.110.127.138:62725] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 972 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UDsRX7OrFkv0FyuIs0QAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.693127 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs1wAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.693227 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:62726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs1wAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.847456 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs7AAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.847548 2026] [security2:error] [pid 925208:tid 925447] [client 77.110.127.138:62728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UDsRX7OrFkv0FyuIs7AAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:54.977497 2026] [security2:error] [pid 925208:tid 925344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UDsRX7OrFkv0FyuIs5gAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.154386 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:62729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 562 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UD8RX7OrFkv0FyuIs_QAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.160862 2026] [security2:error] [pid 925208:tid 925281] [remote 5.182.209.54:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UD8RX7OrFkv0FyuIs_AAAAUg"]
[Mon Jul 20 06:26:55.215164 2026] [security2:error] [pid 925208:tid 925455] [client 46.110.96.34:25294] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4UD8RX7OrFkv0FyuItAAAAAHU"]
[Mon Jul 20 06:26:55.216093 2026] [security2:error] [pid 925208:tid 925342] [client 46.110.96.34:22683] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4UD8RX7OrFkv0FyuItAQAAAAQ"]
[Mon Jul 20 06:26:55.300125 2026] [ssl:error] [pid 925208:tid 925406] [client 107.173.210.100:38812] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname kpb.qlr.mybluehost.me provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:26:55.317763 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UD8RX7OrFkv0FyuItDQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.318360 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:62730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UD8RX7OrFkv0FyuItDQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:55.337797 2026] [security2:error] [pid 925208:tid 925335] [remote 5.182.209.54:49282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UD8RX7OrFkv0FyuItDgAAC34"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:26:55.447196 2026] [proxy:error] [pid 925208:tid 925348] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:55.447272 2026] [proxy_http:error] [pid 925208:tid 925348] [client 34.73.38.214:63909] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:55.447865 2026] [proxy:error] [pid 925208:tid 925348] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:55.447890 2026] [proxy_http:error] [pid 925208:tid 925348] [client 34.73.38.214:63909] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:55.667905 2026] [security2:error] [pid 925208:tid 925440] [client 104.234.53.61:58351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UD8RX7OrFkv0FyuItKAAAAGY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:55.711412 2026] [security2:error] [pid 925208:tid 925437] [client 171.60.139.123:59483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UD8RX7OrFkv0FyuItLAAAAGM"]
[Mon Jul 20 06:26:55.711558 2026] [security2:error] [pid 925208:tid 925437] [client 171.60.139.123:59483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UD8RX7OrFkv0FyuItLAAAAGM"]
[Mon Jul 20 06:26:55.871716 2026] [security2:error] [pid 925208:tid 925340] [client 57.141.18.19:58644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UCsRX7OrFkv0FyuIrZQAAAis"]
[Mon Jul 20 06:26:56.177164 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItWAAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:56.177255 2026] [security2:error] [pid 925208:tid 925338] [client 77.110.127.138:62733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItWAAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:56.350375 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItZAAAADA"]
[Mon Jul 20 06:26:56.350471 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:62734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEMRX7OrFkv0FyuItZAAAADA"]
[Mon Jul 20 06:26:56.481754 2026] [security2:error] [pid 925208:tid 925347] [client 104.234.53.78:53111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UEMRX7OrFkv0FyuItZgAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:26:56.728271 2026] [fcgid:warn] [pid 925208:tid 925401] (70014)End of file found: [client 66.132.186.171:16164] mod_fcgid: can't get data from http client
[Mon Jul 20 06:26:57.015461 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UEMRX7OrFkv0FyuItiQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.022158 2026] [proxy:error] [pid 925208:tid 925345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:57.022231 2026] [proxy_http:error] [pid 925208:tid 925345] [client 34.73.38.214:62512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:57.022920 2026] [proxy:error] [pid 925208:tid 925345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:57.022953 2026] [proxy_http:error] [pid 925208:tid 925345] [client 34.73.38.214:62512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:57.064630 2026] [security2:error] [pid 925208:tid 925408] [client 57.141.18.124:20350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UC8RX7OrFkv0FyuIrwwAARkw"]
[Mon Jul 20 06:26:57.169864 2026] [security2:error] [pid 925208:tid 925376] [client 77.110.127.138:62736] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 970 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UEcRX7OrFkv0FyuItnwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.235578 2026] [security2:error] [pid 925208:tid 925433] [client 14.225.17.146:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UD8RX7OrFkv0FyuItKgAAAF8"], referer: http://nurturemarple.co.uk/WP
[Mon Jul 20 06:26:57.355463 2026] [security2:error] [pid 925208:tid 925435] [client 77.110.127.138:62737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItrgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.355546 2026] [security2:error] [pid 925208:tid 925435] [client 77.110.127.138:62737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItrgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:57.400466 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItsAAAABI"]
[Mon Jul 20 06:26:57.400590 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UEcRX7OrFkv0FyuItsAAAABI"]
[Mon Jul 20 06:26:57.489171 2026] [security2:error] [pid 925208:tid 925360] [client 103.141.108.143:50992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItvAAAABY"]
[Mon Jul 20 06:26:57.489293 2026] [security2:error] [pid 925208:tid 925360] [client 103.141.108.143:50992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItvAAAABY"]
[Mon Jul 20 06:26:57.534076 2026] [security2:error] [pid 925208:tid 925261] [remote 57.141.18.2:48034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4UEcRX7OrFkv0FyuItvgAABzQ"]
[Mon Jul 20 06:26:57.567221 2026] [security2:error] [pid 925208:tid 925212] [remote 156.67.31.167:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4UEcRX7OrFkv0FyuItwAAAXAM"]
[Mon Jul 20 06:26:57.624091 2026] [security2:error] [pid 925208:tid 925438] [client 39.48.81.23:51083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwQAAAGQ"]
[Mon Jul 20 06:26:57.624227 2026] [security2:error] [pid 925208:tid 925438] [client 39.48.81.23:51083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwQAAAGQ"]
[Mon Jul 20 06:26:57.650709 2026] [security2:error] [pid 925208:tid 925344] [client 45.116.69.230:51790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwwAAAAY"]
[Mon Jul 20 06:26:57.650841 2026] [security2:error] [pid 925208:tid 925344] [client 45.116.69.230:51790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UEcRX7OrFkv0FyuItwwAAAAY"]
[Mon Jul 20 06:26:57.719029 2026] [security2:error] [pid 925208:tid 925452] [client 50.116.65.227:16730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UEcRX7OrFkv0FyuItrwAAAHI"]
[Mon Jul 20 06:26:57.750081 2026] [security2:error] [pid 925208:tid 925224] [remote 156.67.31.167:33046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4UEcRX7OrFkv0FyuIt0gAANw8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:26:57.920132 2026] [security2:error] [pid 925208:tid 925420] [client 50.116.65.227:16738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UEcRX7OrFkv0FyuItygAAAFI"]
[Mon Jul 20 06:26:58.108894 2026] [security2:error] [pid 925208:tid 925402] [client 112.208.70.94:45881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIt9wAAAEA"]
[Mon Jul 20 06:26:58.108989 2026] [security2:error] [pid 925208:tid 925402] [client 112.208.70.94:45881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIt9wAAAEA"]
[Mon Jul 20 06:26:58.202091 2026] [security2:error] [pid 925208:tid 925403] [client 14.225.17.146:51397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UEsRX7OrFkv0FyuIt8gAAAEE"], referer: https://nurturemarple.co.uk/WP
[Mon Jul 20 06:26:58.369271 2026] [proxy:error] [pid 925208:tid 925449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:58.369358 2026] [proxy_http:error] [pid 925208:tid 925449] [client 34.73.38.214:52771] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:58.369886 2026] [proxy:error] [pid 925208:tid 925449] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:26:58.369915 2026] [proxy_http:error] [pid 925208:tid 925449] [client 34.73.38.214:52771] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:26:58.483710 2026] [security2:error] [pid 925208:tid 925416] [client 14.225.17.146:56595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4UEsRX7OrFkv0FyuIuBgAAAE4"], referer: http://adirondackengineering.com/WP
[Mon Jul 20 06:26:58.767387 2026] [security2:error] [pid 925208:tid 925368] [client 171.61.165.146:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIuJgAAAB4"]
[Mon Jul 20 06:26:58.767490 2026] [security2:error] [pid 925208:tid 925368] [client 171.61.165.146:29155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UEsRX7OrFkv0FyuIuJgAAAB4"]
[Mon Jul 20 06:26:58.916593 2026] [core:error] [pid 925208:tid 925415] [client 185.247.137.219:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:26:58.916611 2026] [core:error] [pid 925208:tid 925415] [client 185.247.137.219:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:26:59.203580 2026] [security2:error] [pid 925208:tid 925424] [client 57.141.18.98:26888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UDcRX7OrFkv0FyuIsUAAAVnU"]
[Mon Jul 20 06:26:59.477766 2026] [security2:error] [pid 925208:tid 925448] [client 50.116.65.227:13982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UE8RX7OrFkv0FyuIucwAAAG4"]
[Mon Jul 20 06:26:59.485971 2026] [security2:error] [pid 925208:tid 925378] [client 50.116.65.227:13984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UE8RX7OrFkv0FyuIudgAAACg"]
[Mon Jul 20 06:26:59.662306 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIucgAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:59.895022 2026] [security2:error] [pid 925208:tid 925230] [remote 117.0.21.154:40244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIuigAAPxU"]
[Mon Jul 20 06:26:59.895234 2026] [security2:error] [pid 925208:tid 925401] [client 117.0.21.154:40244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIuigAAPxU"]
[Mon Jul 20 06:26:59.918410 2026] [security2:error] [pid 925208:tid 925460] [client 77.110.127.138:62746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 106 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UE8RX7OrFkv0FyuIujQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:26:59.981178 2026] [security2:error] [pid 925208:tid 925324] [remote 8.217.108.67:2422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIukwAAcnM"]
[Mon Jul 20 06:26:59.981378 2026] [security2:error] [pid 925208:tid 925452] [client 8.217.108.67:2422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIukwAAcnM"]
[Mon Jul 20 06:26:59.985523 2026] [security2:error] [pid 925208:tid 925353] [client 43.205.139.3:30560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIulQAAAA8"]
[Mon Jul 20 06:26:59.985610 2026] [security2:error] [pid 925208:tid 925353] [client 43.205.139.3:30560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UE8RX7OrFkv0FyuIulQAAAA8"]
[Mon Jul 20 06:27:00.117541 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:62747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIungAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.117886 2026] [security2:error] [pid 925208:tid 925408] [client 77.110.127.138:62747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIungAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.231353 2026] [security2:error] [pid 925208:tid 925432] [client 14.225.17.146:50777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UFMRX7OrFkv0FyuIumAAAAF4"], referer: http://mezzacraft.com/WP
[Mon Jul 20 06:27:00.295393 2026] [security2:error] [pid 925208:tid 925464] [client 57.141.18.6:56662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UDsRX7OrFkv0FyuIsxwAAfgo"]
[Mon Jul 20 06:27:00.303873 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIurgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.303999 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIurgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.457632 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIuuAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.457722 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UFMRX7OrFkv0FyuIuuAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:00.548980 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:00.549033 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:59292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:00.549895 2026] [proxy:error] [pid 925208:tid 925357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:00.549930 2026] [proxy_http:error] [pid 925208:tid 925357] [client 34.73.38.214:59292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:00.632882 2026] [security2:error] [pid 925208:tid 925435] [client 14.225.17.146:64537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIuYQAAAGE"], referer: http://betterbonddogtraining.com/WP
[Mon Jul 20 06:27:00.893265 2026] [security2:error] [pid 925208:tid 925424] [client 50.116.65.227:13996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4UFMRX7OrFkv0FyuIu7gAAAFY"]
[Mon Jul 20 06:27:00.896861 2026] [security2:error] [pid 925208:tid 925352] [client 14.225.17.146:51238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIuZQAAAA4"], referer: http://recruitinginsight.us/WP
[Mon Jul 20 06:27:01.114927 2026] [security2:error] [pid 925208:tid 925370] [client 52.183.195.200:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4UFcRX7OrFkv0FyuIu_wAAACA"]
[Mon Jul 20 06:27:01.143286 2026] [security2:error] [pid 925208:tid 925376] [client 52.183.195.200:12164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4UFcRX7OrFkv0FyuIvAwAAACY"]
[Mon Jul 20 06:27:01.179639 2026] [security2:error] [pid 925208:tid 925394] [client 57.141.18.54:39846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UD8RX7OrFkv0FyuItGAAAOFU"]
[Mon Jul 20 06:27:01.222017 2026] [security2:error] [pid 925208:tid 925450] [client 52.183.195.200:26120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4UFcRX7OrFkv0FyuIvBwAAAHA"]
[Mon Jul 20 06:27:01.251906 2026] [security2:error] [pid 925208:tid 925413] [client 52.183.195.200:26120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4UFcRX7OrFkv0FyuIvCAAAAEs"]
[Mon Jul 20 06:27:01.267249 2026] [security2:error] [pid 925208:tid 925264] [remote 20.173.88.122:42650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UFcRX7OrFkv0FyuIvCQAATjc"]
[Mon Jul 20 06:27:01.521215 2026] [security2:error] [pid 925208:tid 925425] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UFcRX7OrFkv0FyuIvEQAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:01.731100 2026] [security2:error] [pid 925208:tid 925231] [remote 20.173.88.122:42650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UFcRX7OrFkv0FyuIvMgAAXxY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:27:01.778232 2026] [security2:error] [pid 925208:tid 925403] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "metodoshanti.com"] [uri "/.well-known/about.php"] [unique_id "al4UFcRX7OrFkv0FyuIvNwAAAEE"]
[Mon Jul 20 06:27:01.778329 2026] [security2:error] [pid 925208:tid 925403] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "metodoshanti.com"] [uri "/.well-known/about.php"] [unique_id "al4UFcRX7OrFkv0FyuIvNwAAAEE"]
[Mon Jul 20 06:27:01.962239 2026] [security2:error] [pid 925208:tid 925442] [client 57.141.18.1:61984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEMRX7OrFkv0FyuItaAAAaA0"]
[Mon Jul 20 06:27:01.993353 2026] [security2:error] [pid 925208:tid 925384] [client 34.73.38.214:61637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UFcRX7OrFkv0FyuIvTwAAAC4"]
[Mon Jul 20 06:27:02.102271 2026] [security2:error] [pid 925208:tid 925445] [client 158.173.166.181:61375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UFsRX7OrFkv0FyuIvVwAAAGs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:02.324140 2026] [security2:error] [pid 925208:tid 925364] [client 57.141.18.42:40466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEMRX7OrFkv0FyuItkAAAGj4"]
[Mon Jul 20 06:27:02.835684 2026] [security2:error] [pid 925208:tid 925284] [remote 57.141.18.32:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4636225"] [unique_id "al4UFsRX7OrFkv0FyuIvkAAABks"]
[Mon Jul 20 06:27:02.906247 2026] [security2:error] [pid 925208:tid 925339] [client 57.141.18.5:65376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEcRX7OrFkv0FyuItzgAAATI"]
[Mon Jul 20 06:27:02.949640 2026] [security2:error] [pid 925208:tid 925439] [client 34.73.38.214:54162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UFsRX7OrFkv0FyuIvpQAAAGU"]
[Mon Jul 20 06:27:03.111220 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:15402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIvtQAAAB8"]
[Mon Jul 20 06:27:03.111347 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:15402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIvtQAAAB8"]
[Mon Jul 20 06:27:03.420800 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UF8RX7OrFkv0FyuIvtgAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:03.590901 2026] [security2:error] [pid 925208:tid 925402] [client 57.141.18.82:62116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UEsRX7OrFkv0FyuIuGQAAQCc"]
[Mon Jul 20 06:27:03.786685 2026] [security2:error] [pid 925208:tid 925366] [client 106.219.188.178:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIv4AAAABw"]
[Mon Jul 20 06:27:03.786820 2026] [security2:error] [pid 925208:tid 925366] [client 106.219.188.178:47744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UF8RX7OrFkv0FyuIv4AAAABw"]
[Mon Jul 20 06:27:03.991395 2026] [security2:error] [pid 925208:tid 925385] [client 14.225.17.146:56305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4UFsRX7OrFkv0FyuIvjQAAAC8"], referer: http://momheadquarters.com/WP
[Mon Jul 20 06:27:04.080075 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:62769] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:page_id"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UGMRX7OrFkv0FyuIv_AAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.196900 2026] [security2:error] [pid 925208:tid 925345] [client 104.234.53.74:57203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UGMRX7OrFkv0FyuIwCAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:04.233242 2026] [security2:error] [pid 925208:tid 925379] [client 34.73.38.214:61402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UGMRX7OrFkv0FyuIwCwAAACk"]
[Mon Jul 20 06:27:04.238248 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwDAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.238383 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:62772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwDAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.394982 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwFQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.395091 2026] [security2:error] [pid 925208:tid 925387] [client 77.110.127.138:62774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwFQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.549996 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwKQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.550107 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:62777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwKQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.560098 2026] [security2:error] [pid 925208:tid 925373] [client 57.141.18.11:55212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIueQAAI2w"]
[Mon Jul 20 06:27:04.596864 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGMRX7OrFkv0FyuIwFgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.753239 2026] [security2:error] [pid 925208:tid 925298] [remote 124.55.178.99:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UGMRX7OrFkv0FyuIwPQAABlk"]
[Mon Jul 20 06:27:04.875617 2026] [security2:error] [pid 925208:tid 925343] [client 57.141.18.77:56346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UE8RX7OrFkv0FyuIuhQAABRE"]
[Mon Jul 20 06:27:04.916481 2026] [security2:error] [pid 925208:tid 925391] [client 14.225.17.146:56121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4UF8RX7OrFkv0FyuIvwgAAADU"], referer: http://ironcitywellness.com/WP
[Mon Jul 20 06:27:04.986827 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwTAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:04.986936 2026] [security2:error] [pid 925208:tid 925449] [client 77.110.127.138:62782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGMRX7OrFkv0FyuIwTAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.201306 2026] [security2:error] [pid 925208:tid 925244] [remote 124.55.178.99:37938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UGcRX7OrFkv0FyuIwZAAAdyM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:27:05.254707 2026] [security2:error] [pid 925208:tid 925445] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwUQAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.560307 2026] [security2:error] [pid 925208:tid 925446] [client 178.128.183.250:54020] ModSecurity: Warning. Pattern match "^\\\\/$" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1450"] [id "9011111"] [msg "SQUID data collection"] [hostname "www.processorstudio.com"] [uri "/"] [unique_id "al4UGcRX7OrFkv0FyuIwfwAAAGw"]
[Mon Jul 20 06:27:05.686288 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwdgAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.699513 2026] [security2:error] [pid 925208:tid 925364] [client 18.184.179.151:19182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UGcRX7OrFkv0FyuIwiwAAABo"]
[Mon Jul 20 06:27:05.728679 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwkgAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.728800 2026] [security2:error] [pid 925208:tid 925356] [client 77.110.127.138:62787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwkgAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.860181 2026] [security2:error] [pid 925208:tid 925249] [remote 185.115.217.185:56092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.217.115.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UGcRX7OrFkv0FyuIwmwAAdSg"]
[Mon Jul 20 06:27:05.860484 2026] [security2:error] [pid 925208:tid 925455] [client 185.115.217.185:56092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UGcRX7OrFkv0FyuIwmwAAdSg"]
[Mon Jul 20 06:27:05.906862 2026] [core:error] [pid 925208:tid 925411] [client 103.153.183.69:51164] AH10244: invalid URI path (http://autodiscover.koaconsultants.com/%%32e%%32e/.env?_=9we78yum&v=g056v), referer: https://www.facebook.com/
[Mon Jul 20 06:27:05.961913 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwpAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:05.962008 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:62789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGcRX7OrFkv0FyuIwpAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.053800 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwngAAABY"]
[Mon Jul 20 06:27:06.206174 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwuQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.206286 2026] [security2:error] [pid 925208:tid 925406] [client 77.110.127.138:62790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwuQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.321151 2026] [security2:error] [pid 925208:tid 925452] [client 14.225.17.146:61922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4UGMRX7OrFkv0FyuIwMgAAAHI"], referer: http://tacticaltreeoperations.com/WP
[Mon Jul 20 06:27:06.381010 2026] [security2:error] [pid 925208:tid 925338] [client 198.98.54.225:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.54.98.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4UGsRX7OrFkv0FyuIwyAAAAAA"]
[Mon Jul 20 06:27:06.396152 2026] [security2:error] [pid 925208:tid 925376] [client 3.75.183.99:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UGsRX7OrFkv0FyuIwyQAAACY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:27:06.425087 2026] [security2:error] [pid 925208:tid 925408] [client 34.73.38.214:50234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UGsRX7OrFkv0FyuIwzAAAAEY"]
[Mon Jul 20 06:27:06.431161 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIwvQAAAHk"]
[Mon Jul 20 06:27:06.434255 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwzgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.434334 2026] [security2:error] [pid 925208:tid 925355] [client 77.110.127.138:62754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIwzgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.447919 2026] [security2:error] [pid 925208:tid 925434] [client 114.119.130.136:37233] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.qualitycoatingsinspection.com"] [uri "/contact"] [unique_id "al4UGsRX7OrFkv0FyuIw0gAAAGA"], referer: https://www.qualitycoatingsinspection.com/about
[Mon Jul 20 06:27:06.485820 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:62759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw1gAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.485970 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:62759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw1gAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.526924 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIwxgAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.606990 2026] [security2:error] [pid 925208:tid 925364] [client 171.60.139.123:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UGsRX7OrFkv0FyuIw5AAAABo"]
[Mon Jul 20 06:27:06.607166 2026] [security2:error] [pid 925208:tid 925364] [client 171.60.139.123:60004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UGsRX7OrFkv0FyuIw5AAAABo"]
[Mon Jul 20 06:27:06.715303 2026] [security2:error] [pid 925208:tid 925415] [client 57.141.18.7:35420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UFcRX7OrFkv0FyuIvMAAATWI"]
[Mon Jul 20 06:27:06.755401 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:page_id"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UGsRX7OrFkv0FyuIw7QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.943395 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw_QAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:06.943540 2026] [security2:error] [pid 925208:tid 925382] [client 77.110.127.138:62799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UGsRX7OrFkv0FyuIw_QAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:07.063403 2026] [security2:error] [pid 925208:tid 925405] [client 104.234.53.72:60583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UG8RX7OrFkv0FyuIxBwAAAEM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:07.103326 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UG8RX7OrFkv0FyuIxDwAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:07.103418 2026] [security2:error] [pid 925208:tid 925437] [client 77.110.127.138:62800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UG8RX7OrFkv0FyuIxDwAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:07.139649 2026] [security2:error] [pid 925208:tid 925340] [client 14.225.17.146:62094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIw0QAAAAI"]
[Mon Jul 20 06:27:07.209499 2026] [security2:error] [pid 925208:tid 925370] [client 57.141.18.117:56870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UFsRX7OrFkv0FyuIvWgAAIEc"]
[Mon Jul 20 06:27:07.249022 2026] [security2:error] [pid 925208:tid 925392] [client 14.225.17.146:62597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwZQAAADY"], referer: http://savilerowtravel.com/WP
[Mon Jul 20 06:27:07.572451 2026] [security2:error] [pid 925208:tid 925403] [client 66.249.73.130:63481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIw9wAAAEE"]
[Mon Jul 20 06:27:07.738369 2026] [security2:error] [pid 925208:tid 925376] [client 34.73.38.214:63378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UG8RX7OrFkv0FyuIxVwAAACY"]
[Mon Jul 20 06:27:07.974578 2026] [proxy:error] [pid 925208:tid 925430] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:07.974659 2026] [proxy_http:error] [pid 925208:tid 925430] [client 185.247.137.187:46959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:07.975347 2026] [proxy:error] [pid 925208:tid 925430] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:07.975377 2026] [proxy_http:error] [pid 925208:tid 925430] [client 185.247.137.187:46959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:08.089034 2026] [security2:error] [pid 925208:tid 925212] [remote 57.141.18.79:31858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4UHMRX7OrFkv0FyuIxegAAIAM"]
[Mon Jul 20 06:27:08.140696 2026] [security2:error] [pid 925208:tid 925338] [client 103.141.108.143:51458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxfgAAAAA"]
[Mon Jul 20 06:27:08.140858 2026] [security2:error] [pid 925208:tid 925338] [client 103.141.108.143:51458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxfgAAAAA"]
[Mon Jul 20 06:27:08.172898 2026] [security2:error] [pid 925208:tid 925381] [client 57.141.18.10:36128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UF8RX7OrFkv0FyuIvvQAAK1g"]
[Mon Jul 20 06:27:08.287197 2026] [security2:error] [pid 925208:tid 925375] [client 14.225.17.146:56124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4UHMRX7OrFkv0FyuIxewAAACU"], referer: https://savilerowtravel.com/WP
[Mon Jul 20 06:27:08.352627 2026] [security2:error] [pid 925208:tid 925343] [client 45.116.69.230:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxjAAAAAU"]
[Mon Jul 20 06:27:08.352727 2026] [security2:error] [pid 925208:tid 925343] [client 45.116.69.230:52296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UHMRX7OrFkv0FyuIxjAAAAAU"]
[Mon Jul 20 06:27:08.413710 2026] [security2:error] [pid 925208:tid 925421] [client 14.225.17.146:62924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4UG8RX7OrFkv0FyuIxaQAAAFM"], referer: http://uritems.net/WP
[Mon Jul 20 06:27:08.575137 2026] [security2:error] [pid 925208:tid 925370] [client 50.116.65.227:14066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UHMRX7OrFkv0FyuIxpAAAACA"]
[Mon Jul 20 06:27:08.588026 2026] [security2:error] [pid 925208:tid 925369] [client 50.116.65.227:14072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UHMRX7OrFkv0FyuIxqAAAAB8"]
[Mon Jul 20 06:27:08.943804 2026] [security2:error] [pid 925208:tid 925403] [client 77.110.127.138:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHMRX7OrFkv0FyuIxwQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:08.943914 2026] [security2:error] [pid 925208:tid 925403] [client 77.110.127.138:62814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHMRX7OrFkv0FyuIxwQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.003733 2026] [security2:error] [pid 925208:tid 925415] [client 14.225.17.146:62944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4UG8RX7OrFkv0FyuIxMgAAAE0"], referer: http://vinovinhowine.com/WP
[Mon Jul 20 06:27:09.004429 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIxyAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.004535 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:62781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIxyAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.061135 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIx0AAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.061286 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHcRX7OrFkv0FyuIx0AAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:09.169777 2026] [security2:error] [pid 925208:tid 925341] [client 34.73.38.214:58656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UHcRX7OrFkv0FyuIx1wAAAAM"]
[Mon Jul 20 06:27:09.335808 2026] [security2:error] [pid 925208:tid 925413] [client 77.110.127.138:62822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:page_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4UHcRX7OrFkv0FyuIx5wAAAEs"]
[Mon Jul 20 06:27:09.360980 2026] [security2:error] [pid 925208:tid 925250] [remote 217.61.143.92:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4UHcRX7OrFkv0FyuIx7AAAbSk"]
[Mon Jul 20 06:27:09.414175 2026] [security2:error] [pid 925208:tid 925461] [client 57.141.18.113:52504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGMRX7OrFkv0FyuIwNgAAe0E"]
[Mon Jul 20 06:27:09.604484 2026] [security2:error] [pid 925208:tid 925267] [remote 217.61.143.92:45348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4UHcRX7OrFkv0FyuIyBgAABDo"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:27:09.695033 2026] [security2:error] [pid 925208:tid 925378] [client 171.61.165.146:10965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UHcRX7OrFkv0FyuIyEQAAACg"]
[Mon Jul 20 06:27:09.695142 2026] [security2:error] [pid 925208:tid 925378] [client 171.61.165.146:10965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UHcRX7OrFkv0FyuIyEQAAACg"]
[Mon Jul 20 06:27:09.718866 2026] [security2:error] [pid 925208:tid 925385] [client 104.234.53.79:42937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIyBQAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:09.739927 2026] [security2:error] [pid 925208:tid 925387] [client 14.225.17.146:62681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIx3AAAADE"], referer: http://waterproofgoods.com/WP
[Mon Jul 20 06:27:09.900279 2026] [security2:error] [pid 925208:tid 925246] [remote 57.141.18.91:34172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2766231"] [unique_id "al4UHcRX7OrFkv0FyuIyJAAAEyU"]
[Mon Jul 20 06:27:10.161437 2026] [security2:error] [pid 925208:tid 925407] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIyKgAAAEU"]
[Mon Jul 20 06:27:10.261583 2026] [security2:error] [pid 925208:tid 925395] [client 57.141.18.17:23980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwbAAAOTU"]
[Mon Jul 20 06:27:10.393162 2026] [security2:error] [pid 925208:tid 925383] [client 57.141.18.105:61942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGcRX7OrFkv0FyuIwggAALV8"]
[Mon Jul 20 06:27:10.521884 2026] [security2:error] [pid 925208:tid 925367] [client 34.73.38.214:49984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UHsRX7OrFkv0FyuIyWAAAAB0"]
[Mon Jul 20 06:27:10.595849 2026] [security2:error] [pid 925208:tid 925347] [client 104.234.53.79:42937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UHsRX7OrFkv0FyuIyXwAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:10.655884 2026] [security2:error] [pid 925208:tid 925361] [client 14.225.17.146:62771] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyNQAAABc"], referer: http://laceycaraccident.com/WP
[Mon Jul 20 06:27:10.756092 2026] [security2:error] [pid 925208:tid 925345] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyUAAAAAc"]
[Mon Jul 20 06:27:10.927980 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIyeQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:10.928086 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:62849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIyeQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:10.979520 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIygAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:10.979682 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UHsRX7OrFkv0FyuIygAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.052652 2026] [core:error] [pid 925208:tid 925462] [client 14.225.17.146:62209] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WP
[Mon Jul 20 06:27:11.052981 2026] [core:error] [pid 925208:tid 925462] [client 14.225.17.146:62209] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/WP
[Mon Jul 20 06:27:11.061486 2026] [security2:error] [pid 925208:tid 925339] [client 57.141.18.11:55228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UGsRX7OrFkv0FyuIwwAAAAXA"]
[Mon Jul 20 06:27:11.134603 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:62854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UH8RX7OrFkv0FyuIylQAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.134704 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:62854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UH8RX7OrFkv0FyuIylQAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.193232 2026] [security2:error] [pid 925208:tid 925368] [client 172.104.20.239:61434] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UH8RX7OrFkv0FyuIylgAAAB4"]
[Mon Jul 20 06:27:11.322456 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyiwAAABY"]
[Mon Jul 20 06:27:11.464527 2026] [security2:error] [pid 925208:tid 925425] [client 34.73.38.214:49629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UH8RX7OrFkv0FyuIysAAAAFc"]
[Mon Jul 20 06:27:11.507104 2026] [security2:error] [pid 925208:tid 925457] [client 112.208.70.94:42303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UH8RX7OrFkv0FyuIyuAAAAHc"]
[Mon Jul 20 06:27:11.507228 2026] [security2:error] [pid 925208:tid 925457] [client 112.208.70.94:42303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UH8RX7OrFkv0FyuIyuAAAAHc"]
[Mon Jul 20 06:27:11.693170 2026] [security2:error] [pid 925208:tid 925451] [client 104.234.53.93:46125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UH8RX7OrFkv0FyuIy0QAAAHE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:11.710169 2026] [security2:error] [pid 925208:tid 925426] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyqAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:11.885117 2026] [security2:error] [pid 925208:tid 925409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyzgAAAEc"]
[Mon Jul 20 06:27:12.300960 2026] [security2:error] [pid 925208:tid 925366] [client 57.141.18.104:55836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UG8RX7OrFkv0FyuIxUAAAHG8"]
[Mon Jul 20 06:27:12.434156 2026] [security2:error] [pid 925208:tid 925432] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIy_AAAAF4"]
[Mon Jul 20 06:27:12.535704 2026] [security2:error] [pid 925208:tid 925353] [client 54.169.146.187:15714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UIMRX7OrFkv0FyuIzFAAAAA8"]
[Mon Jul 20 06:27:12.535883 2026] [security2:error] [pid 925208:tid 925353] [client 54.169.146.187:15714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UIMRX7OrFkv0FyuIzFAAAAA8"]
[Mon Jul 20 06:27:12.627168 2026] [security2:error] [pid 925208:tid 925354] [client 34.73.38.214:53999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UIMRX7OrFkv0FyuIzGAAAABA"]
[Mon Jul 20 06:27:12.977679 2026] [security2:error] [pid 925208:tid 925409] [client 14.225.17.146:49423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzGQAAAEc"], referer: http://mcg.homes/WP
[Mon Jul 20 06:27:13.268105 2026] [security2:error] [pid 925208:tid 925398] [client 14.225.17.146:63000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIywgAAADw"], referer: http://grecruit.online/WP
[Mon Jul 20 06:27:13.288082 2026] [security2:error] [pid 925208:tid 925346] [client 104.210.140.142:5062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyegAACGY"]
[Mon Jul 20 06:27:13.323719 2026] [security2:error] [pid 925208:tid 925414] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzPAAAAEw"]
[Mon Jul 20 06:27:13.375341 2026] [security2:error] [pid 925208:tid 925396] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzMAAAADo"]
[Mon Jul 20 06:27:13.605619 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzagAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.605761 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzagAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.665233 2026] [security2:error] [pid 925208:tid 925426] [client 104.210.140.142:5062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzVwAAWGE"]
[Mon Jul 20 06:27:13.732142 2026] [security2:error] [pid 925208:tid 925445] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzXgAAAGs"]
[Mon Jul 20 06:27:13.758585 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzeQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.758689 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:62909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzeQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.819367 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzfwAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:13.819540 2026] [security2:error] [pid 925208:tid 925394] [client 77.110.127.138:62836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UIcRX7OrFkv0FyuIzfwAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:14.026810 2026] [security2:error] [pid 925208:tid 925419] [client 57.141.18.14:53216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIx3QAAUSw"]
[Mon Jul 20 06:27:14.027297 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzfQAAABk"]
[Mon Jul 20 06:27:14.032253 2026] [security2:error] [pid 925208:tid 925440] [client 106.219.188.178:10272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzngAAAGY"]
[Mon Jul 20 06:27:14.034417 2026] [security2:error] [pid 925208:tid 925440] [client 106.219.188.178:10272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzngAAAGY"]
[Mon Jul 20 06:27:14.077284 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzhQAAABo"]
[Mon Jul 20 06:27:14.159633 2026] [security2:error] [pid 925208:tid 925457] [client 104.234.53.86:27447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UIsRX7OrFkv0FyuIzqwAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:14.211278 2026] [core:error] [pid 925208:tid 925342] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:14.211299 2026] [core:error] [pid 925208:tid 925342] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:14.225357 2026] [security2:error] [pid 925208:tid 925435] [client 223.185.13.213:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzsAAAAGE"]
[Mon Jul 20 06:27:14.225527 2026] [security2:error] [pid 925208:tid 925435] [client 223.185.13.213:9615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UIsRX7OrFkv0FyuIzsAAAAGE"]
[Mon Jul 20 06:27:14.317819 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIzoQAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:14.428206 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIzrwAAAFw"]
[Mon Jul 20 06:27:14.543709 2026] [security2:error] [pid 925208:tid 925411] [client 57.141.18.81:60712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UHcRX7OrFkv0FyuIyGQAASRU"]
[Mon Jul 20 06:27:14.549971 2026] [security2:error] [pid 925208:tid 925422] [client 14.225.17.146:62151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzSwAAAFQ"], referer: http://mazzucelli.com/WP
[Mon Jul 20 06:27:14.558687 2026] [security2:error] [pid 925208:tid 925391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIztwAAADU"]
[Mon Jul 20 06:27:14.615705 2026] [security2:error] [pid 925208:tid 925369] [client 14.225.17.146:62091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzSQAAAB8"], referer: http://ghivs.com/WP
[Mon Jul 20 06:27:14.643221 2026] [http2:info] [pid 929851:tid 929851] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:27:14.811081 2026] [security2:error] [pid 929851:tid 929990] [client 34.73.38.214:53813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UImV3ou772CelrLhpIQAAAIo"]
[Mon Jul 20 06:27:14.884553 2026] [security2:error] [pid 925208:tid 925381] [client 57.141.18.42:22896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UHsRX7OrFkv0FyuIyQgAAK1Q"]
[Mon Jul 20 06:27:14.965588 2026] [security2:error] [pid 925208:tid 925348] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIz3gAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:14.991549 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIz5wAAAGo"]
[Mon Jul 20 06:27:15.023013 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UImV3ou772CelrLhpHwAAAIc"]
[Mon Jul 20 06:27:15.325193 2026] [security2:error] [pid 929851:tid 930018] [client 172.104.20.239:9894] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UI2V3ou772CelrLhpMQAAAKY"]
[Mon Jul 20 06:27:15.399050 2026] [security2:error] [pid 925208:tid 925379] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0HwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:15.427398 2026] [security2:error] [pid 925208:tid 925438] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0IAAAAGQ"]
[Mon Jul 20 06:27:15.462046 2026] [security2:error] [pid 925208:tid 925421] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0IQAAAFM"]
[Mon Jul 20 06:27:15.823968 2026] [security2:error] [pid 925208:tid 925392] [client 104.234.53.55:34425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UI8RX7OrFkv0FyuI0VwAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:15.945833 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpPQAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:15.981692 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpQAAAAL4"]
[Mon Jul 20 06:27:16.014911 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpRgAAAMY"]
[Mon Jul 20 06:27:16.117170 2026] [security2:error] [pid 925208:tid 925357] [client 57.141.18.77:45270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UH8RX7OrFkv0FyuIyzAAAEwk"]
[Mon Jul 20 06:27:16.129063 2026] [security2:error] [pid 929851:tid 930073] [client 34.73.38.214:50426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UJGV3ou772CelrLhpUgAAAN0"]
[Mon Jul 20 06:27:16.244531 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJGV3ou772CelrLhpWQAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.244661 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:62933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJGV3ou772CelrLhpWQAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.296916 2026] [security2:error] [pid 925208:tid 925438] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJMRX7OrFkv0FyuI0bQAAAGQ"]
[Mon Jul 20 06:27:16.329300 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0gwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.329426 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:62910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0gwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.489803 2026] [security2:error] [pid 925208:tid 925383] [client 57.141.18.105:61508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIy9QAALRI"]
[Mon Jul 20 06:27:16.490821 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0lAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.490905 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:62938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJMRX7OrFkv0FyuI0lAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:16.537445 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJGV3ou772CelrLhpXAAAAOs"]
[Mon Jul 20 06:27:16.623770 2026] [security2:error] [pid 929851:tid 930095] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJGV3ou772CelrLhpXgAAAPM"]
[Mon Jul 20 06:27:16.790074 2026] [security2:error] [pid 929851:tid 930112] [client 34.74.185.202:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UJGV3ou772CelrLhpbQAAAQQ"]
[Mon Jul 20 06:27:16.840626 2026] [security2:error] [pid 925208:tid 925464] [client 39.48.81.23:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UJMRX7OrFkv0FyuI0qgAAAH4"]
[Mon Jul 20 06:27:16.840767 2026] [security2:error] [pid 925208:tid 925464] [client 39.48.81.23:51533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UJMRX7OrFkv0FyuI0qgAAAH4"]
[Mon Jul 20 06:27:16.864561 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJGV3ou772CelrLhpZAAAAIg"]
[Mon Jul 20 06:27:16.921325 2026] [security2:error] [pid 925208:tid 925406] [client 14.225.17.146:51188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0PAAAAEQ"], referer: http://bbwipartnerconference.com/WP
[Mon Jul 20 06:27:17.032775 2026] [security2:error] [pid 925208:tid 925342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJMRX7OrFkv0FyuI0pwAAAAQ"]
[Mon Jul 20 06:27:17.062787 2026] [security2:error] [pid 925208:tid 925386] [client 57.141.18.23:46164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIMRX7OrFkv0FyuIzGgAAMA0"]
[Mon Jul 20 06:27:17.181388 2026] [security2:error] [pid 925208:tid 925343] [client 34.74.185.202:54597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UJcRX7OrFkv0FyuI0vQAAAAU"]
[Mon Jul 20 06:27:17.337186 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJWV3ou772CelrLhpeQAAALY"]
[Mon Jul 20 06:27:17.357662 2026] [security2:error] [pid 925208:tid 925376] [client 14.225.17.146:59663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI0wAAAACY"], referer: http://omrobuildingcenter.com/WP
[Mon Jul 20 06:27:17.362934 2026] [security2:error] [pid 925208:tid 925438] [client 171.60.139.123:60527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UJcRX7OrFkv0FyuI0zQAAAGQ"]
[Mon Jul 20 06:27:17.363049 2026] [security2:error] [pid 925208:tid 925438] [client 171.60.139.123:60527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UJcRX7OrFkv0FyuI0zQAAAGQ"]
[Mon Jul 20 06:27:17.459914 2026] [security2:error] [pid 929851:tid 930046] [client 14.225.17.146:59790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpTAAAAMI"], referer: http://thechancersband.com/WP
[Mon Jul 20 06:27:17.537987 2026] [security2:error] [pid 925208:tid 925409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI0wQAAAEc"]
[Mon Jul 20 06:27:17.560146 2026] [security2:error] [pid 929851:tid 930019] [client 34.73.38.214:52574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UJWV3ou772CelrLhphQAAAKc"]
[Mon Jul 20 06:27:17.707310 2026] [security2:error] [pid 925208:tid 925397] [client 74.208.214.194:49986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UJcRX7OrFkv0FyuI04QAAADs"]
[Mon Jul 20 06:27:17.921131 2026] [security2:error] [pid 929851:tid 930083] [client 34.74.185.202:58509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UJWV3ou772CelrLhplwAAAOc"]
[Mon Jul 20 06:27:18.068669 2026] [security2:error] [pid 929851:tid 929987] [client 50.116.65.227:59866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UJmV3ou772CelrLhpnwAAAIc"]
[Mon Jul 20 06:27:18.079438 2026] [security2:error] [pid 929851:tid 930005] [client 50.116.65.227:59870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UJmV3ou772CelrLhpoQAAAJk"]
[Mon Jul 20 06:27:18.111831 2026] [security2:error] [pid 925208:tid 925363] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI06wAAABk"]
[Mon Jul 20 06:27:18.131636 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJsRX7OrFkv0FyuI09wAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.131722 2026] [security2:error] [pid 925208:tid 925444] [client 77.110.127.138:62948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJsRX7OrFkv0FyuI09wAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.171315 2026] [security2:error] [pid 925208:tid 925433] [client 57.141.18.17:32314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzegAAXyY"]
[Mon Jul 20 06:27:18.307623 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhpsAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.307726 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:62951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhpsAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.321135 2026] [security2:error] [pid 929851:tid 929874] [remote 173.236.254.75:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.254.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4UJmV3ou772CelrLhpqwAAoRI"], referer: https://greenvillemovingco.com/wp-login.php
[Mon Jul 20 06:27:18.385998 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJmV3ou772CelrLhppgAAAKw"]
[Mon Jul 20 06:27:18.395007 2026] [security2:error] [pid 925208:tid 925334] [remote 217.61.143.92:54336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1CgAAI30"]
[Mon Jul 20 06:27:18.395154 2026] [security2:error] [pid 925208:tid 925373] [client 217.61.143.92:54336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1CgAAI30"]
[Mon Jul 20 06:27:18.416082 2026] [security2:error] [pid 925208:tid 925357] [client 34.74.185.202:54537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UJsRX7OrFkv0FyuI1DQAAABM"]
[Mon Jul 20 06:27:18.418496 2026] [security2:error] [pid 925208:tid 925408] [client 57.141.18.89:41540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIcRX7OrFkv0FyuIzlQAARnM"]
[Mon Jul 20 06:27:18.511846 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhptgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.511963 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:62957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UJmV3ou772CelrLhptgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:18.542032 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJmV3ou772CelrLhptAAAAL4"]
[Mon Jul 20 06:27:18.728694 2026] [security2:error] [pid 929851:tid 929878] [remote 173.212.252.15:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4UJmV3ou772CelrLhpvwAA_hY"]
[Mon Jul 20 06:27:18.744404 2026] [security2:error] [pid 929851:tid 929879] [remote 173.236.254.75:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.254.236.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4UJmV3ou772CelrLhpwQAAyRc"], referer: https://greenvillemovingco.com/wp-login.php
[Mon Jul 20 06:27:18.760400 2026] [security2:error] [pid 925208:tid 925390] [client 57.141.18.62:37544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIzuQAANC0"]
[Mon Jul 20 06:27:18.829066 2026] [security2:error] [pid 925208:tid 925312] [remote 15.206.251.117:39084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UJsRX7OrFkv0FyuI1KQAAZWc"]
[Mon Jul 20 06:27:18.833408 2026] [security2:error] [pid 925208:tid 925443] [client 103.141.108.143:51935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1KwAAAGk"]
[Mon Jul 20 06:27:18.833493 2026] [security2:error] [pid 925208:tid 925443] [client 103.141.108.143:51935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UJsRX7OrFkv0FyuI1KwAAAGk"]
[Mon Jul 20 06:27:18.844847 2026] [security2:error] [pid 929851:tid 929996] [client 106.212.14.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4UJmV3ou772CelrLhpwgAAAJA"]
[Mon Jul 20 06:27:18.863986 2026] [security2:error] [pid 929851:tid 930088] [client 34.74.185.202:62748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UJmV3ou772CelrLhpxQAAAOw"]
[Mon Jul 20 06:27:18.882459 2026] [security2:error] [pid 929851:tid 930096] [client 113.160.97.242:50257] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4UJmV3ou772CelrLhpxwAAAPQ"]
[Mon Jul 20 06:27:18.942249 2026] [security2:error] [pid 925208:tid 925456] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1HgAAAHY"]
[Mon Jul 20 06:27:18.999742 2026] [security2:error] [pid 925208:tid 925463] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flowmeterfactory.com"] [uri "/.well-known/about.php"] [unique_id "al4UJsRX7OrFkv0FyuI1MQAAAH0"]
[Mon Jul 20 06:27:18.999865 2026] [security2:error] [pid 925208:tid 925463] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "flowmeterfactory.com"] [uri "/.well-known/about.php"] [unique_id "al4UJsRX7OrFkv0FyuI1MQAAAH0"]
[Mon Jul 20 06:27:19.016224 2026] [security2:error] [pid 925208:tid 925398] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1JgAAADw"]
[Mon Jul 20 06:27:19.049175 2026] [security2:error] [pid 925208:tid 925371] [client 57.141.18.61:48522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UIsRX7OrFkv0FyuIz4QAAIRM"]
[Mon Jul 20 06:27:19.099494 2026] [security2:error] [pid 925208:tid 925407] [client 45.116.69.230:52808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1OQAAAEU"]
[Mon Jul 20 06:27:19.099611 2026] [security2:error] [pid 925208:tid 925407] [client 45.116.69.230:52808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1OQAAAEU"]
[Mon Jul 20 06:27:19.194600 2026] [security2:error] [pid 929851:tid 930108] [client 34.74.185.202:65329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UJ2V3ou772CelrLhp1gAAAQA"]
[Mon Jul 20 06:27:19.224685 2026] [security2:error] [pid 929851:tid 929881] [remote 173.212.252.15:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4UJ2V3ou772CelrLhp2AAAjRk"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:27:19.240444 2026] [security2:error] [pid 925208:tid 925309] [remote 15.206.251.117:39084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1RwAAaGQ"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:27:19.252591 2026] [security2:error] [pid 925208:tid 925457] [client 104.234.53.63:50955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1SAAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:19.272369 2026] [security2:error] [pid 925208:tid 925423] [client 14.225.17.146:59595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI02QAAAFU"], referer: http://bigwormfishing.com/WP
[Mon Jul 20 06:27:19.332229 2026] [security2:error] [pid 929851:tid 930005] [client 172.104.20.239:9898] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UJ2V3ou772CelrLhp3wAAAJk"]
[Mon Jul 20 06:27:19.389012 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhpzwAAAPg"]
[Mon Jul 20 06:27:19.398482 2026] [security2:error] [pid 925208:tid 925414] [client 14.225.17.146:63761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1DwAAAEw"], referer: http://partnerselectricalllc.com/WP
[Mon Jul 20 06:27:19.452429 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhp2QAAALs"]
[Mon Jul 20 06:27:19.534388 2026] [security2:error] [pid 929851:tid 930023] [client 158.173.89.95:48881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UJ2V3ou772CelrLhp5AAAAKs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:19.762287 2026] [security2:error] [pid 925208:tid 925398] [client 106.212.14.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4UJ8RX7OrFkv0FyuI1ZQAAADw"]
[Mon Jul 20 06:27:19.816610 2026] [security2:error] [pid 929851:tid 930028] [client 34.74.185.202:54064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UJ2V3ou772CelrLhp8AAAALA"]
[Mon Jul 20 06:27:19.987004 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhp5wAAAKw"]
[Mon Jul 20 06:27:20.043717 2026] [security2:error] [pid 925208:tid 925389] [client 57.141.18.43:33402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UI8RX7OrFkv0FyuI0QwAAMxc"]
[Mon Jul 20 06:27:20.154942 2026] [security2:error] [pid 929851:tid 930027] [client 34.74.185.202:50525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UKGV3ou772CelrLhp_wAAAK8"]
[Mon Jul 20 06:27:20.167356 2026] [security2:error] [pid 929851:tid 930105] [client 103.153.183.69:20128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../root/.bash_history"] [unique_id "al4UKGV3ou772CelrLhqAAAAAP0"], referer: https://duckduckgo.com/?q=k8rw9
[Mon Jul 20 06:27:20.192718 2026] [security2:error] [pid 925208:tid 925325] [remote 130.185.118.215:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thestudioatfruitland.com"] [uri "/wp-login.php"] [unique_id "al4UKMRX7OrFkv0FyuI1fwAAJXQ"]
[Mon Jul 20 06:27:20.255438 2026] [security2:error] [pid 929851:tid 930048] [client 57.141.18.0:64496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UI2V3ou772CelrLhpRQAAxAE"]
[Mon Jul 20 06:27:20.256968 2026] [security2:error] [pid 929851:tid 930019] [client 14.225.17.146:51061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhp_QAAAKc"], referer: https://bigwormfishing.com/WP
[Mon Jul 20 06:27:20.373960 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:51146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqAgAAAO4"], referer: http://koaconsultants.com/WP
[Mon Jul 20 06:27:20.377620 2026] [security2:error] [pid 925208:tid 925242] [remote 130.185.118.215:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thestudioatfruitland.com"] [uri "/wp-login.php"] [unique_id "al4UKMRX7OrFkv0FyuI1iAAANCE"], referer: https://thestudioatfruitland.com/wp-login.php
[Mon Jul 20 06:27:20.509223 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqDQAAAQI"]
[Mon Jul 20 06:27:20.618478 2026] [security2:error] [pid 925208:tid 925368] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "querenciapartners.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI1IAAAAB4"]
[Mon Jul 20 06:27:20.648324 2026] [security2:error] [pid 929851:tid 930101] [client 77.110.127.138:62943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqGQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.648468 2026] [security2:error] [pid 929851:tid 930101] [client 77.110.127.138:62943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqGQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.689983 2026] [security2:error] [pid 929851:tid 930074] [client 171.61.165.146:3569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UKGV3ou772CelrLhqHwAAAN4"]
[Mon Jul 20 06:27:20.691062 2026] [security2:error] [pid 929851:tid 930074] [client 171.61.165.146:3569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UKGV3ou772CelrLhqHwAAAN4"]
[Mon Jul 20 06:27:20.800835 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/charity/feed/0kuu8amwj3su.php"] [unique_id "al4UKGV3ou772CelrLhqJwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.838533 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKMRX7OrFkv0FyuI1rAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.838690 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:62815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKMRX7OrFkv0FyuI1rAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.849210 2026] [security2:error] [pid 925208:tid 925461] [client 34.74.185.202:51368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UKMRX7OrFkv0FyuI1rgAAAHs"]
[Mon Jul 20 06:27:20.930010 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:62947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqHAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.961951 2026] [core:error] [pid 929851:tid 930091] [client 185.247.137.75:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:20.961981 2026] [core:error] [pid 929851:tid 930091] [client 185.247.137.75:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:27:20.990423 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqOAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:20.990590 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKGV3ou772CelrLhqOAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.130217 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqJgAAALo"]
[Mon Jul 20 06:27:21.142644 2026] [security2:error] [pid 925208:tid 925435] [client 57.141.18.113:63436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJMRX7OrFkv0FyuI0ogAAYSQ"]
[Mon Jul 20 06:27:21.178988 2026] [security2:error] [pid 925208:tid 925407] [client 39.48.81.23:51994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UKcRX7OrFkv0FyuI1xQAAAEU"]
[Mon Jul 20 06:27:21.179145 2026] [security2:error] [pid 925208:tid 925407] [client 39.48.81.23:51994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UKcRX7OrFkv0FyuI1xQAAAEU"]
[Mon Jul 20 06:27:21.208287 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqKgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.233022 2026] [security2:error] [pid 929851:tid 930079] [client 104.234.53.88:34171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UKWV3ou772CelrLhqPgAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:21.277134 2026] [security2:error] [pid 929851:tid 930084] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKGV3ou772CelrLhqLwAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.525187 2026] [security2:error] [pid 929851:tid 930001] [client 34.74.185.202:61691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UKWV3ou772CelrLhqVQAAAJU"]
[Mon Jul 20 06:27:21.542645 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/cowl/feed/14dsr01kc27o.php"] [unique_id "al4UKcRX7OrFkv0FyuI14QAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:21.592320 2026] [security2:error] [pid 925208:tid 925440] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI10AAAAGY"]
[Mon Jul 20 06:27:21.642676 2026] [security2:error] [pid 925208:tid 925410] [client 14.225.17.146:58286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI1ugAAAEg"], referer: http://bruceledewitz.com/WP
[Mon Jul 20 06:27:21.927276 2026] [security2:error] [pid 929851:tid 930021] [client 34.74.185.202:61327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UKWV3ou772CelrLhqdAAAAKk"]
[Mon Jul 20 06:27:21.988529 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.112:32012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJcRX7OrFkv0FyuI04wAAV2k"]
[Mon Jul 20 06:27:22.175484 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKWV3ou772CelrLhqTAAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.221069 2026] [security2:error] [pid 925208:tid 925357] [client 77.110.127.138:62942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI11QAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.222895 2026] [security2:error] [pid 925208:tid 925461] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKcRX7OrFkv0FyuI12wAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.250023 2026] [security2:error] [pid 925208:tid 925370] [client 34.74.185.202:49658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UKsRX7OrFkv0FyuI2BgAAACA"]
[Mon Jul 20 06:27:22.329110 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:63019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/course-terms-conditions/y5ni4apxsu5b.php"] [unique_id "al4UKmV3ou772CelrLhqigAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.429131 2026] [security2:error] [pid 925208:tid 925341] [client 57.141.18.53:50738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJsRX7OrFkv0FyuI0-AAAA3k"]
[Mon Jul 20 06:27:22.715557 2026] [security2:error] [pid 925208:tid 925383] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKsRX7OrFkv0FyuI2AAAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.848975 2026] [security2:error] [pid 925208:tid 925333] [remote 47.86.33.52:3808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UKsRX7OrFkv0FyuI2IQAAYHw"]
[Mon Jul 20 06:27:22.888348 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:62929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKmV3ou772CelrLhqpwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.888455 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:62929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UKmV3ou772CelrLhqpwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:22.958000 2026] [security2:error] [pid 925208:tid 925347] [client 104.234.53.78:44891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UKsRX7OrFkv0FyuI2KQAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:23.020763 2026] [security2:error] [pid 929851:tid 930006] [client 34.74.185.202:54166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ial.nce.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UK2V3ou772CelrLhqtQAAAJo"]
[Mon Jul 20 06:27:23.109225 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/501/feed/rl7wjedeqyzl.php"] [unique_id "al4UK2V3ou772CelrLhqwAAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.169143 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:62993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqhgAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.171111 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKsRX7OrFkv0FyuI2CwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.327447 2026] [security2:error] [pid 929851:tid 930025] [client 172.104.20.239:19258] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UK2V3ou772CelrLhqygAAAK0"]
[Mon Jul 20 06:27:23.327664 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhqyQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.327820 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhqyQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.372170 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqpgAAAOI"], referer: https://mezzacraft.com/about-mezzacraft-crochet/img_4196-2/
[Mon Jul 20 06:27:23.480137 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:63013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/chart/hl4o1aaurcbs.php"] [unique_id "al4UK8RX7OrFkv0FyuI2WAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.552650 2026] [security2:error] [pid 929851:tid 930034] [client 14.225.17.146:54890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhq1AAAALY"], referer: http://hammadownenterprises.com/WP
[Mon Jul 20 06:27:23.753347 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:62934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhq7QAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.753487 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:62934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UK2V3ou772CelrLhq7QAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:23.814860 2026] [security2:error] [pid 929851:tid 930111] [client 14.225.17.146:58395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqqAAAAQM"], referer: http://walkingandtalking.net/WP
[Mon Jul 20 06:27:23.918355 2026] [security2:error] [pid 929851:tid 930056] [client 57.141.18.18:23928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UJ2V3ou772CelrLhp8QAAzBw"]
[Mon Jul 20 06:27:23.995302 2026] [security2:error] [pid 925208:tid 925385] [client 57.141.18.34:26798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKMRX7OrFkv0FyuI1dQAAL2E"]
[Mon Jul 20 06:27:24.139327 2026] [security2:error] [pid 929851:tid 930022] [client 112.208.70.94:42717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhq_AAAAKo"]
[Mon Jul 20 06:27:24.139492 2026] [security2:error] [pid 929851:tid 930022] [client 112.208.70.94:42717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhq_AAAAKo"]
[Mon Jul 20 06:27:24.152575 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:62958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhqxAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.184047 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhqxgAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.186888 2026] [security2:error] [pid 925208:tid 925370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK8RX7OrFkv0FyuI2RgAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.435490 2026] [fcgid:warn] [pid 929851:tid 929996] (70014)End of file found: [client 199.45.154.146:33176] mod_fcgid: can't get data from http client
[Mon Jul 20 06:27:24.451456 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhq2QAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.469711 2026] [security2:error] [pid 929851:tid 929931] [remote 57.141.18.92:48200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5475098"] [unique_id "al4ULGV3ou772CelrLhrEAAAv0s"]
[Mon Jul 20 06:27:24.516149 2026] [security2:error] [pid 925208:tid 925345] [client 14.225.17.146:58346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4UKsRX7OrFkv0FyuI1_gAAAAc"], referer: http://adastra.love/WP
[Mon Jul 20 06:27:24.534397 2026] [security2:error] [pid 925208:tid 925361] [client 77.110.127.138:62884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK8RX7OrFkv0FyuI2XgAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.537304 2026] [security2:error] [pid 925208:tid 925427] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UK8RX7OrFkv0FyuI2agAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:24.709614 2026] [security2:error] [pid 929851:tid 930038] [client 14.225.17.146:54902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4ULGV3ou772CelrLhrGgAAALo"], referer: https://walkingandtalking.net/WP
[Mon Jul 20 06:27:24.722599 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:8325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ULMRX7OrFkv0FyuI2kgAAADg"]
[Mon Jul 20 06:27:24.722732 2026] [security2:error] [pid 925208:tid 925394] [client 223.185.13.213:8325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ULMRX7OrFkv0FyuI2kgAAADg"]
[Mon Jul 20 06:27:24.759801 2026] [security2:error] [pid 929851:tid 930068] [client 106.219.188.178:47757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhrHAAAANg"]
[Mon Jul 20 06:27:24.761138 2026] [security2:error] [pid 929851:tid 930068] [client 106.219.188.178:47757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ULGV3ou772CelrLhrHAAAANg"]
[Mon Jul 20 06:27:25.123416 2026] [security2:error] [pid 929851:tid 930095] [client 52.109.52.84:19149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ULWV3ou772CelrLhrJgAAAPM"]
[Mon Jul 20 06:27:25.178100 2026] [security2:error] [pid 925208:tid 925442] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ULMRX7OrFkv0FyuI2gQAAAGg"], referer: 1'"3000
[Mon Jul 20 06:27:25.243082 2026] [security2:error] [pid 929851:tid 929994] [client 52.109.52.84:19149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ULWV3ou772CelrLhrLAAAAI4"]
[Mon Jul 20 06:27:25.553523 2026] [security2:error] [pid 929851:tid 930053] [client 57.141.18.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ULWV3ou772CelrLhrMwAAAMk"]
[Mon Jul 20 06:27:25.708709 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:25.708766 2026] [proxy_http:error] [pid 929851:tid 930026] [client 34.73.38.214:64849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:25.709629 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:25.709658 2026] [proxy_http:error] [pid 929851:tid 930026] [client 34.73.38.214:64849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:25.718120 2026] [security2:error] [pid 929851:tid 930047] [client 57.141.18.118:21438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKWV3ou772CelrLhqRwAAwyY"]
[Mon Jul 20 06:27:25.871138 2026] [security2:error] [pid 929851:tid 930056] [client 51.143.183.75:29505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ULWV3ou772CelrLhrVAAAAMw"]
[Mon Jul 20 06:27:25.883213 2026] [security2:error] [pid 929851:tid 929942] [remote 192.241.143.148:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ULWV3ou772CelrLhrVgAAxVY"]
[Mon Jul 20 06:27:25.944850 2026] [security2:error] [pid 929851:tid 930055] [client 57.141.18.58:22026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKWV3ou772CelrLhqXgAAyyk"]
[Mon Jul 20 06:27:26.004361 2026] [security2:error] [pid 929851:tid 930045] [client 51.143.183.75:29505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ULmV3ou772CelrLhrWwAAAME"]
[Mon Jul 20 06:27:26.073623 2026] [security2:error] [pid 925208:tid 925217] [remote 57.141.18.28:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4ULsRX7OrFkv0FyuI2vgAAEQg"]
[Mon Jul 20 06:27:26.237472 2026] [security2:error] [pid 929851:tid 930100] [client 14.225.17.146:58116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrYAAAAPg"], referer: http://sarahsnyder.net/WP
[Mon Jul 20 06:27:26.249205 2026] [security2:error] [pid 929851:tid 929947] [remote 192.241.143.148:47748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ULmV3ou772CelrLhrawAA51s"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:27:26.577064 2026] [security2:error] [pid 925208:tid 925339] [client 14.225.17.146:51177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4ULMRX7OrFkv0FyuI2hgAAAAE"], referer: http://securingmemories.com/WP
[Mon Jul 20 06:27:26.750476 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:26.750555 2026] [proxy_http:error] [pid 929851:tid 930079] [client 34.73.38.214:53186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:26.751113 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:26.751145 2026] [proxy_http:error] [pid 929851:tid 930079] [client 34.73.38.214:53186] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:26.818990 2026] [security2:error] [pid 925208:tid 925347] [client 35.90.38.209:45470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4ULsRX7OrFkv0FyuI24wAAAAk"]
[Mon Jul 20 06:27:27.038586 2026] [security2:error] [pid 929851:tid 930050] [client 57.141.18.38:60588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqlgAAxjU"]
[Mon Jul 20 06:27:27.050814 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.125:57934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UKmV3ou772CelrLhqkwAAojQ"]
[Mon Jul 20 06:27:27.238085 2026] [security2:error] [pid 925208:tid 925452] [client 14.225.17.146:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4UL8RX7OrFkv0FyuI29AAAAHI"], referer: https://sarahsnyder.net/WP
[Mon Jul 20 06:27:27.255868 2026] [security2:error] [pid 929851:tid 930056] [client 98.159.234.160:48795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UL2V3ou772CelrLhriwAAAMw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:27.353977 2026] [security2:error] [pid 929851:tid 929998] [client 172.104.20.239:19272] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4UL2V3ou772CelrLhrjwAAAJI"]
[Mon Jul 20 06:27:27.761159 2026] [proxy:error] [pid 929851:tid 930028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:27.761238 2026] [proxy_http:error] [pid 929851:tid 930028] [client 34.73.38.214:58104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:27.761892 2026] [proxy:error] [pid 929851:tid 930028] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:27.761932 2026] [proxy_http:error] [pid 929851:tid 930028] [client 34.73.38.214:58104] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:27.897516 2026] [security2:error] [pid 929851:tid 930081] [client 57.141.18.48:30298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UK2V3ou772CelrLhq0AAA5T4"]
[Mon Jul 20 06:27:28.041919 2026] [security2:error] [pid 925208:tid 925374] [client 171.60.139.123:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UMMRX7OrFkv0FyuI3FQAAACQ"]
[Mon Jul 20 06:27:28.042043 2026] [security2:error] [pid 925208:tid 925374] [client 171.60.139.123:61050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UMMRX7OrFkv0FyuI3FQAAACQ"]
[Mon Jul 20 06:27:28.230557 2026] [security2:error] [pid 929851:tid 930101] [client 47.128.46.251:17586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "floorsourcestock.com"] [uri "/robots.txt"] [unique_id "al4UMGV3ou772CelrLhrqgAAAPk"]
[Mon Jul 20 06:27:28.235795 2026] [security2:error] [pid 925208:tid 925391] [client 50.116.65.227:52156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UMMRX7OrFkv0FyuI3HQAAADU"]
[Mon Jul 20 06:27:28.244924 2026] [security2:error] [pid 925208:tid 925412] [client 50.116.65.227:52164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UMMRX7OrFkv0FyuI3HgAAAEo"]
[Mon Jul 20 06:27:28.432416 2026] [security2:error] [pid 929851:tid 929963] [remote 4.205.168.44:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4UMGV3ou772CelrLhruQAAjGs"]
[Mon Jul 20 06:27:28.487084 2026] [security2:error] [pid 929851:tid 930029] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-4c7fda08.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrZAAAALE"]
[Mon Jul 20 06:27:28.611263 2026] [security2:error] [pid 929851:tid 929965] [remote 4.205.168.44:38608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4UMGV3ou772CelrLhrwQAA8W0"], referer: https://faadenergy.com/wp-login.php
[Mon Jul 20 06:27:28.828690 2026] [security2:error] [pid 925208:tid 925308] [remote 45.90.123.233:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UMMRX7OrFkv0FyuI3OwAAOGM"]
[Mon Jul 20 06:27:28.856578 2026] [proxy:error] [pid 925208:tid 925419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:28.856629 2026] [proxy_http:error] [pid 925208:tid 925419] [client 34.73.38.214:55420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:28.857332 2026] [proxy:error] [pid 925208:tid 925419] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:28.857365 2026] [proxy_http:error] [pid 925208:tid 925419] [client 34.73.38.214:55420] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:28.941954 2026] [security2:error] [pid 929851:tid 929967] [remote 91.142.222.105:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4UMGV3ou772CelrLhrzQAAyW8"]
[Mon Jul 20 06:27:28.985960 2026] [security2:error] [pid 925208:tid 925410] [client 14.225.17.146:64346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4UMMRX7OrFkv0FyuI3QAAAAEg"], referer: http://intelligentengineeringsolutions.com/WP
[Mon Jul 20 06:27:29.213031 2026] [security2:error] [pid 925208:tid 925360] [client 57.141.18.59:54630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ULMRX7OrFkv0FyuI2lQAAFhs"]
[Mon Jul 20 06:27:29.297509 2026] [security2:error] [pid 929851:tid 929973] [remote 91.142.222.105:48304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4UMWV3ou772CelrLhr3gAA4nU"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 06:27:29.665106 2026] [security2:error] [pid 929851:tid 930076] [client 103.141.108.143:52409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr9gAAAOA"]
[Mon Jul 20 06:27:29.665775 2026] [security2:error] [pid 929851:tid 930076] [client 103.141.108.143:52409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr9gAAAOA"]
[Mon Jul 20 06:27:29.673959 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr4gAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:29.706918 2026] [security2:error] [pid 929851:tid 930018] [client 45.116.69.230:53326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr-gAAAKY"]
[Mon Jul 20 06:27:29.707030 2026] [security2:error] [pid 929851:tid 930018] [client 45.116.69.230:53326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UMWV3ou772CelrLhr-gAAAKY"]
[Mon Jul 20 06:27:29.707714 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr4wAAALE"], referer: 1'"3000
[Mon Jul 20 06:27:29.790969 2026] [ssl:error] [pid 929851:tid 930021] [client 98.88.137.2:48949] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname cpanel.nzj.ghe.mybluehost.me provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:27:29.812248 2026] [security2:error] [pid 929851:tid 930059] [client 14.225.17.146:50962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4UMGV3ou772CelrLhrugAAAM8"], referer: http://scott-assist.com/WP
[Mon Jul 20 06:27:29.919160 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMcRX7OrFkv0FyuI3awAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:29.919309 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:63075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMcRX7OrFkv0FyuI3awAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:29.971021 2026] [security2:error] [pid 925208:tid 925325] [remote 45.90.123.233:60290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UMcRX7OrFkv0FyuI3bwAAAHQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:27:29.990211 2026] [security2:error] [pid 925208:tid 925367] [client 34.73.38.214:55425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UMcRX7OrFkv0FyuI3cAAAAB0"]
[Mon Jul 20 06:27:30.102211 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3eQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.102331 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3eQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.113663 2026] [security2:error] [pid 925208:tid 925397] [client 39.48.81.23:52480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UMsRX7OrFkv0FyuI3fAAAADs"]
[Mon Jul 20 06:27:30.113824 2026] [security2:error] [pid 925208:tid 925397] [client 39.48.81.23:52480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UMsRX7OrFkv0FyuI3fAAAADs"]
[Mon Jul 20 06:27:30.183589 2026] [security2:error] [pid 925208:tid 925328] [remote 199.189.225.40:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UMsRX7OrFkv0FyuI3hAAAcXc"]
[Mon Jul 20 06:27:30.197536 2026] [security2:error] [pid 929851:tid 930088] [client 14.225.17.146:64490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4UMGV3ou772CelrLhrzAAAAOw"], referer: http://wathenbartlett.co.uk/WP
[Mon Jul 20 06:27:30.229828 2026] [security2:error] [pid 925208:tid 925404] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UMsRX7OrFkv0FyuI3cQAAAEI"], referer: 1'"3000
[Mon Jul 20 06:27:30.254014 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.254149 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.333112 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.333278 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMmV3ou772CelrLhsCQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.366885 2026] [security2:error] [pid 925208:tid 925230] [remote 199.189.225.40:27571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UMsRX7OrFkv0FyuI3iwAAAhU"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:27:30.477430 2026] [security2:error] [pid 929851:tid 929856] [remote 47.86.33.52:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UMmV3ou772CelrLhsDwAAhgA"]
[Mon Jul 20 06:27:30.477615 2026] [security2:error] [pid 929851:tid 929986] [client 47.86.33.52:47670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UMmV3ou772CelrLhsDwAAhgA"]
[Mon Jul 20 06:27:30.551048 2026] [security2:error] [pid 929851:tid 930006] [client 57.141.18.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UMmV3ou772CelrLhsCwAAAJo"]
[Mon Jul 20 06:27:30.598812 2026] [security2:error] [pid 929851:tid 929859] [remote 57.141.18.67:25840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2608670"] [unique_id "al4UMmV3ou772CelrLhsEgAAlwM"]
[Mon Jul 20 06:27:30.616257 2026] [security2:error] [pid 925208:tid 925245] [remote 57.141.18.79:20898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5107369"] [unique_id "al4UMsRX7OrFkv0FyuI3lwAANiQ"]
[Mon Jul 20 06:27:30.650169 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:63100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3mQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.650272 2026] [security2:error] [pid 925208:tid 925386] [client 77.110.127.138:63100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UMsRX7OrFkv0FyuI3mQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:30.840329 2026] [security2:error] [pid 929851:tid 930079] [client 4.154.193.167:60790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4UMmV3ou772CelrLhsGQAA4wY"]
[Mon Jul 20 06:27:30.916538 2026] [security2:error] [pid 925208:tid 925459] [client 34.73.38.214:49584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UMsRX7OrFkv0FyuI3pQAAAHk"]
[Mon Jul 20 06:27:30.990957 2026] [security2:error] [pid 929851:tid 929865] [remote 20.153.140.50:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4UMmV3ou772CelrLhsIQAA1Ak"]
[Mon Jul 20 06:27:31.002593 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3qAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.002731 2026] [security2:error] [pid 925208:tid 925416] [client 77.110.127.138:63104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3qAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.140208 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:59269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4UM8RX7OrFkv0FyuI3rAAAAAA"], referer: https://wathenbartlett.co.uk/WP
[Mon Jul 20 06:27:31.207916 2026] [security2:error] [pid 925208:tid 925398] [client 14.225.17.146:59158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4UMcRX7OrFkv0FyuI3YQAAADw"], referer: http://blaizeaccountingservices.com/WP
[Mon Jul 20 06:27:31.297485 2026] [security2:error] [pid 929851:tid 930091] [client 74.7.227.179:46460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4UM2V3ou772CelrLhsLgAA7xA"], referer: https://tejasenvironmental.com/p=1477799
[Mon Jul 20 06:27:31.297850 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsOQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.297967 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsOQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.376037 2026] [security2:error] [pid 929851:tid 930009] [client 14.225.17.146:58765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr7QAAAJ0"], referer: http://ccsdifference.com/WP
[Mon Jul 20 06:27:31.399875 2026] [security2:error] [pid 929851:tid 929878] [remote 20.153.140.50:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4UM2V3ou772CelrLhsPAAAmhY"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:27:31.502158 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:1561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UM2V3ou772CelrLhsPwAAALw"]
[Mon Jul 20 06:27:31.502885 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:1561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UM2V3ou772CelrLhsPwAAALw"]
[Mon Jul 20 06:27:31.523429 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3wQAAACg"]
[Mon Jul 20 06:27:31.523548 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3wQAAACg"]
[Mon Jul 20 06:27:31.574138 2026] [security2:error] [pid 929851:tid 930063] [client 57.141.18.43:32020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrewAA018"]
[Mon Jul 20 06:27:31.652834 2026] [security2:error] [pid 929851:tid 930004] [client 57.141.18.59:24320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ULmV3ou772CelrLhrfgAAmGA"]
[Mon Jul 20 06:27:31.721101 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.721193 2026] [proxy_http:error] [pid 929851:tid 930079] [client 198.235.24.141:61808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.721879 2026] [proxy:error] [pid 929851:tid 930079] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.721909 2026] [proxy_http:error] [pid 929851:tid 930079] [client 198.235.24.141:61808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.731904 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.731988 2026] [proxy_http:error] [pid 929851:tid 930026] [client 198.235.24.141:61816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.732687 2026] [proxy:error] [pid 929851:tid 930026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:27:31.732723 2026] [proxy_http:error] [pid 929851:tid 930026] [client 198.235.24.141:61816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:27:31.789695 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:63111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3yQAAAGk"]
[Mon Jul 20 06:27:31.789833 2026] [security2:error] [pid 925208:tid 925443] [client 77.110.127.138:63111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM8RX7OrFkv0FyuI3yQAAAGk"]
[Mon Jul 20 06:27:31.808197 2026] [security2:error] [pid 929851:tid 930023] [client 13.201.64.214:32228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UM2V3ou772CelrLhsUAAAAKs"]
[Mon Jul 20 06:27:31.999488 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsWQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:31.999580 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UM2V3ou772CelrLhsWQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.225614 2026] [security2:error] [pid 925208:tid 925386] [client 34.73.38.214:59865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UNMRX7OrFkv0FyuI32QAAADA"]
[Mon Jul 20 06:27:32.276148 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNGV3ou772CelrLhsYAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.328611 2026] [security2:error] [pid 929851:tid 929885] [remote 38.242.157.30:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4UNGV3ou772CelrLhsbwABAx0"]
[Mon Jul 20 06:27:32.377218 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:65315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UNGV3ou772CelrLhsawAAAKQ"], referer: https://ccsdifference.com/WP
[Mon Jul 20 06:27:32.528278 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:63120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNMRX7OrFkv0FyuI35QAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.528382 2026] [security2:error] [pid 925208:tid 925457] [client 77.110.127.138:63120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNMRX7OrFkv0FyuI35QAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.614304 2026] [security2:error] [pid 929851:tid 929888] [remote 124.55.178.99:47312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UNGV3ou772CelrLhsegAA5SA"]
[Mon Jul 20 06:27:32.614450 2026] [security2:error] [pid 929851:tid 930081] [client 124.55.178.99:47312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UNGV3ou772CelrLhsegAA5SA"]
[Mon Jul 20 06:27:32.663969 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNMRX7OrFkv0FyuI34QAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:32.737345 2026] [security2:error] [pid 929851:tid 929860] [remote 38.242.157.30:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4UNGV3ou772CelrLhsgQAAqgQ"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 06:27:32.887628 2026] [security2:error] [pid 925208:tid 925410] [client 65.1.132.125:12554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UNMRX7OrFkv0FyuI39wAAAEg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:27:33.043774 2026] [security2:error] [pid 929851:tid 930070] [client 34.73.38.214:64093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UNWV3ou772CelrLhslQAAANo"]
[Mon Jul 20 06:27:33.199227 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNGV3ou772CelrLhskQAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:33.440143 2026] [security2:error] [pid 929851:tid 930062] [client 46.110.96.34:65304] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4UNWV3ou772CelrLhsqgAAANI"]
[Mon Jul 20 06:27:33.440143 2026] [security2:error] [pid 925208:tid 925369] [client 46.110.96.34:46529] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4UNcRX7OrFkv0FyuI4DQAAAB8"]
[Mon Jul 20 06:27:33.756439 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNcRX7OrFkv0FyuI4EgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:33.948812 2026] [security2:error] [pid 929851:tid 930056] [client 104.234.53.51:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UNWV3ou772CelrLhs6QAAAMw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:33.964670 2026] [security2:error] [pid 929851:tid 930021] [client 91.162.53.208:65098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UNWV3ou772CelrLhs6gAAAKk"]
[Mon Jul 20 06:27:33.980275 2026] [security2:error] [pid 929851:tid 930106] [client 70.52.223.115:38260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4UNWV3ou772CelrLhs7QAAAP4"]
[Mon Jul 20 06:27:33.998195 2026] [security2:error] [pid 925208:tid 925463] [client 88.174.200.112:28238] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4UNcRX7OrFkv0FyuI4JwAAAH0"]
[Mon Jul 20 06:27:34.011236 2026] [security2:error] [pid 929851:tid 930099] [client 82.66.24.165:47066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4UNmV3ou772CelrLhs8gAAAPc"]
[Mon Jul 20 06:27:34.024822 2026] [security2:error] [pid 929851:tid 930086] [client 90.248.175.80:60210] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4UNmV3ou772CelrLhs-wAAAOo"]
[Mon Jul 20 06:27:34.090986 2026] [security2:error] [pid 925208:tid 925452] [client 90.113.29.14:48826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UNsRX7OrFkv0FyuI4LwAAAHI"]
[Mon Jul 20 06:27:34.104803 2026] [security2:error] [pid 929851:tid 930018] [client 99.246.181.85:51790] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4UNmV3ou772CelrLhtAgAAAKY"]
[Mon Jul 20 06:27:34.113193 2026] [security2:error] [pid 925208:tid 925274] [remote 57.141.18.61:38270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4UNsRX7OrFkv0FyuI4MAAAMUE"]
[Mon Jul 20 06:27:34.123443 2026] [security2:error] [pid 929851:tid 930109] [client 57.141.18.111:47600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr5AABAXY"]
[Mon Jul 20 06:27:34.137090 2026] [security2:error] [pid 925208:tid 925366] [client 88.98.127.76:13488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4UNsRX7OrFkv0FyuI4MwAAABw"]
[Mon Jul 20 06:27:34.153848 2026] [security2:error] [pid 929851:tid 929954] [remote 47.86.33.52:44240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UNmV3ou772CelrLhtBQAA72I"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:27:34.178579 2026] [security2:error] [pid 929851:tid 929993] [client 57.141.18.58:59634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UMWV3ou772CelrLhr6gAAjXg"]
[Mon Jul 20 06:27:34.237228 2026] [security2:error] [pid 929851:tid 930100] [client 2.213.247.11:49898] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UNmV3ou772CelrLhtBgAAAPg"]
[Mon Jul 20 06:27:34.238631 2026] [security2:error] [pid 929851:tid 930048] [client 85.145.110.236:54110] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4UNmV3ou772CelrLhtBwAAAMQ"]
[Mon Jul 20 06:27:34.260318 2026] [security2:error] [pid 929851:tid 930101] [client 38.62.90.158:36694] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4UNmV3ou772CelrLhtCAAAAPk"]
[Mon Jul 20 06:27:34.278772 2026] [security2:error] [pid 929851:tid 930024] [client 92.208.64.126:13696] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4UNmV3ou772CelrLhtCQAAAKw"]
[Mon Jul 20 06:27:34.296922 2026] [security2:error] [pid 929851:tid 929986] [client 81.105.86.231:54320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.ttf"] [unique_id "al4UNmV3ou772CelrLhtDAAAAIY"]
[Mon Jul 20 06:27:34.337171 2026] [security2:error] [pid 925208:tid 925385] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNsRX7OrFkv0FyuI4MgAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.364654 2026] [security2:error] [pid 929851:tid 930068] [client 99.233.147.186:58888] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4UNmV3ou772CelrLhtFAAAANg"]
[Mon Jul 20 06:27:34.399354 2026] [security2:error] [pid 925208:tid 925462] [client 34.73.38.214:54547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UNsRX7OrFkv0FyuI4OwAAAHw"]
[Mon Jul 20 06:27:34.481229 2026] [security2:error] [pid 929851:tid 930066] [client 103.73.107.17:37346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4UNmV3ou772CelrLhtFwAAANY"]
[Mon Jul 20 06:27:34.499679 2026] [security2:error] [pid 925208:tid 925408] [client 94.73.43.173:7708] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4UNsRX7OrFkv0FyuI4PgAAAEY"]
[Mon Jul 20 06:27:34.502543 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtGQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.502642 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtGQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.657196 2026] [security2:error] [pid 929851:tid 930040] [client 90.69.100.135:47298] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4UNmV3ou772CelrLhtJAAAALw"]
[Mon Jul 20 06:27:34.664516 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtJQAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.664603 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UNmV3ou772CelrLhtJQAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.710045 2026] [security2:error] [pid 929851:tid 930023] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNmV3ou772CelrLhtGgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:34.844738 2026] [security2:error] [pid 925208:tid 925361] [client 95.26.107.190:7931] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UNsRX7OrFkv0FyuI4UgAAABc"]
[Mon Jul 20 06:27:35.019978 2026] [security2:error] [pid 929851:tid 930075] [client 34.73.38.214:52072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UN2V3ou772CelrLhtLwAAAN8"]
[Mon Jul 20 06:27:35.074644 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UNsRX7OrFkv0FyuI4UAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.289707 2026] [security2:error] [pid 929851:tid 929997] [client 106.219.188.178:16476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UN2V3ou772CelrLhtPQAAAJE"]
[Mon Jul 20 06:27:35.290153 2026] [security2:error] [pid 929851:tid 929997] [client 106.219.188.178:16476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UN2V3ou772CelrLhtPQAAAJE"]
[Mon Jul 20 06:27:35.397087 2026] [security2:error] [pid 929851:tid 930031] [client 199.45.154.146:38672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.154.45.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aula.cimahmo.pro"] [uri "/theme/image.php/boost/theme/1713903875/favicon"] [unique_id "al4UN2V3ou772CelrLhtQQAAALM"]
[Mon Jul 20 06:27:35.434300 2026] [security2:error] [pid 925208:tid 925451] [client 223.185.13.213:11435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UN8RX7OrFkv0FyuI4awAAAHE"]
[Mon Jul 20 06:27:35.434395 2026] [security2:error] [pid 925208:tid 925451] [client 223.185.13.213:11435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UN8RX7OrFkv0FyuI4awAAAHE"]
[Mon Jul 20 06:27:35.536139 2026] [security2:error] [pid 925208:tid 925434] [client 181.172.193.121:33642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UN8RX7OrFkv0FyuI4bgAAAGA"]
[Mon Jul 20 06:27:35.553687 2026] [security2:error] [pid 925208:tid 925460] [client 74.208.214.194:59938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UN8RX7OrFkv0FyuI4bwAAAHo"]
[Mon Jul 20 06:27:35.680421 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UN2V3ou772CelrLhtTwAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.789764 2026] [security2:error] [pid 929851:tid 930081] [client 34.73.38.214:58037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UN2V3ou772CelrLhtZAAAAOU"]
[Mon Jul 20 06:27:35.811488 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:63102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UN8RX7OrFkv0FyuI4fAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.811618 2026] [security2:error] [pid 925208:tid 925360] [client 77.110.127.138:63102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UN8RX7OrFkv0FyuI4fAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:35.898558 2026] [security2:error] [pid 929851:tid 930082] [client 57.141.18.85:52780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UM2V3ou772CelrLhsMwAA5hQ"]
[Mon Jul 20 06:27:35.984999 2026] [security2:error] [pid 929851:tid 929990] [client 104.234.53.49:55235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UN2V3ou772CelrLhtbAAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:36.014832 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.87:33726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UM2V3ou772CelrLhsNgAAwRM"]
[Mon Jul 20 06:27:36.327915 2026] [security2:error] [pid 929851:tid 930107] [client 37.120.158.248:49149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UOGV3ou772CelrLhtfwAAAP8"]
[Mon Jul 20 06:27:36.724926 2026] [security2:error] [pid 929851:tid 929872] [remote 188.166.241.141:46782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4UOGV3ou772CelrLhtlgAA7hA"]
[Mon Jul 20 06:27:36.962837 2026] [security2:error] [pid 929851:tid 930043] [client 34.73.38.214:54667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UOGV3ou772CelrLhtoAAAAL8"]
[Mon Jul 20 06:27:37.099447 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UOGV3ou772CelrLhtnQAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:37.110014 2026] [security2:error] [pid 929851:tid 929867] [remote 188.166.241.141:46782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4UOWV3ou772CelrLhtpQAA1gs"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:27:37.325445 2026] [security2:error] [pid 929851:tid 930091] [client 50.116.65.227:22912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UOWV3ou772CelrLhtsAAAAO8"]
[Mon Jul 20 06:27:37.334313 2026] [security2:error] [pid 929851:tid 930044] [client 50.116.65.227:22922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UOWV3ou772CelrLhtsgAAAMA"]
[Mon Jul 20 06:27:37.648980 2026] [security2:error] [pid 929851:tid 929885] [remote 81.173.115.7:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UOWV3ou772CelrLhtwwABAB0"]
[Mon Jul 20 06:27:37.731397 2026] [security2:error] [pid 929851:tid 930010] [client 112.208.70.94:43171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UOWV3ou772CelrLhtyAAAAJ4"]
[Mon Jul 20 06:27:37.731524 2026] [security2:error] [pid 929851:tid 930010] [client 112.208.70.94:43171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UOWV3ou772CelrLhtyAAAAJ4"]
[Mon Jul 20 06:27:37.886973 2026] [security2:error] [pid 929851:tid 929888] [remote 81.173.115.7:51678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UOWV3ou772CelrLhtywAAmyA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:37.909220 2026] [security2:error] [pid 929851:tid 930065] [client 50.116.65.227:22952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UOWV3ou772CelrLhtxAAAANU"]
[Mon Jul 20 06:27:38.098104 2026] [security2:error] [pid 929851:tid 930058] [client 50.116.65.227:22968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UOWV3ou772CelrLhtzgAAAM4"]
[Mon Jul 20 06:27:38.165922 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOmV3ou772CelrLht3gAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.166046 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOmV3ou772CelrLht3gAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.278011 2026] [security2:error] [pid 925208:tid 925422] [client 57.141.18.84:56580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UNcRX7OrFkv0FyuI4IgAAVGQ"]
[Mon Jul 20 06:27:38.323326 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOsRX7OrFkv0FyuI45gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.323426 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UOsRX7OrFkv0FyuI45gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:38.760871 2026] [security2:error] [pid 929851:tid 930048] [client 34.73.38.214:61055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UOmV3ou772CelrLht7QAAAMQ"]
[Mon Jul 20 06:27:38.826042 2026] [security2:error] [pid 925208:tid 925417] [client 43.205.139.3:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UOsRX7OrFkv0FyuI4-gAAAE8"]
[Mon Jul 20 06:27:38.827702 2026] [security2:error] [pid 925208:tid 925349] [client 171.60.139.123:61572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UOsRX7OrFkv0FyuI4-wAAAAs"]
[Mon Jul 20 06:27:38.827807 2026] [security2:error] [pid 925208:tid 925349] [client 171.60.139.123:61572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UOsRX7OrFkv0FyuI4-wAAAAs"]
[Mon Jul 20 06:27:38.972615 2026] [security2:error] [pid 925208:tid 925390] [client 57.141.18.67:37768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UNsRX7OrFkv0FyuI4RQAANDI"]
[Mon Jul 20 06:27:38.976306 2026] [fcgid:warn] [pid 929851:tid 930018] (70014)End of file found: [client 66.132.172.200:40680] mod_fcgid: can't get data from http client
[Mon Jul 20 06:27:39.177600 2026] [security2:error] [pid 929851:tid 929864] [remote 57.141.18.18:43714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4UO2V3ou772CelrLht_gAAuAg"]
[Mon Jul 20 06:27:39.524288 2026] [security2:error] [pid 929851:tid 930090] [client 34.73.38.214:65045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UO2V3ou772CelrLhuFAAAAO4"]
[Mon Jul 20 06:27:39.744577 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5IQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.744690 2026] [security2:error] [pid 925208:tid 925353] [client 77.110.127.138:63177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5IQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.841240 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO2V3ou772CelrLhuHQAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.841334 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO2V3ou772CelrLhuHQAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.851236 2026] [security2:error] [pid 925208:tid 925446] [client 43.205.139.3:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UO8RX7OrFkv0FyuI5JAAAAGw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:27:39.919024 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:63180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5JwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:39.919121 2026] [security2:error] [pid 925208:tid 925384] [client 77.110.127.138:63180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UO8RX7OrFkv0FyuI5JwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:40.194563 2026] [security2:error] [pid 929851:tid 930094] [client 66.249.74.37:48860] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.ililac.com"] [uri "/robots.txt"] [unique_id "al4UPGV3ou772CelrLhuMwAAAPI"]
[Mon Jul 20 06:27:40.314612 2026] [security2:error] [pid 929851:tid 930059] [client 103.141.108.143:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuOQAAAM8"]
[Mon Jul 20 06:27:40.314825 2026] [security2:error] [pid 929851:tid 930059] [client 103.141.108.143:52888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuOQAAAM8"]
[Mon Jul 20 06:27:40.383657 2026] [security2:error] [pid 925208:tid 925273] [remote 167.233.114.32:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UPMRX7OrFkv0FyuI5NQAAGUA"]
[Mon Jul 20 06:27:40.385590 2026] [security2:error] [pid 929851:tid 930084] [client 45.116.69.230:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuQQAAAOg"]
[Mon Jul 20 06:27:40.385723 2026] [security2:error] [pid 929851:tid 930084] [client 45.116.69.230:53861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuQQAAAOg"]
[Mon Jul 20 06:27:40.424690 2026] [security2:error] [pid 929851:tid 929913] [remote 57.141.18.112:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4UPGV3ou772CelrLhuQgAA6zk"]
[Mon Jul 20 06:27:40.512452 2026] [security2:error] [pid 925208:tid 925358] [client 57.141.18.20:24660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UOMRX7OrFkv0FyuI4jwAAFDM"]
[Mon Jul 20 06:27:40.525115 2026] [security2:error] [pid 929851:tid 930105] [client 34.73.38.214:65012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.dienerranch.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UPGV3ou772CelrLhuSgAAAP0"]
[Mon Jul 20 06:27:40.597764 2026] [security2:error] [pid 925208:tid 925211] [remote 167.233.114.32:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UPMRX7OrFkv0FyuI5PQAAZgI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:27:40.726640 2026] [security2:error] [pid 929851:tid 930021] [client 39.48.81.23:52948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuVQAAAKk"]
[Mon Jul 20 06:27:40.726837 2026] [security2:error] [pid 929851:tid 930021] [client 39.48.81.23:52948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UPGV3ou772CelrLhuVQAAAKk"]
[Mon Jul 20 06:27:40.805675 2026] [security2:error] [pid 925208:tid 925221] [remote 15.206.251.117:36170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UPMRX7OrFkv0FyuI5RAAAUQw"]
[Mon Jul 20 06:27:40.890788 2026] [security2:error] [pid 929851:tid 930054] [client 172.232.181.107:48584] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4UPGV3ou772CelrLhuWwAAAMo"]
[Mon Jul 20 06:27:40.912828 2026] [security2:error] [pid 929851:tid 930112] [client 57.141.18.58:45392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UOGV3ou772CelrLhtnwABBF0"]
[Mon Jul 20 06:27:40.994974 2026] [security2:error] [pid 929851:tid 929905] [remote 3.7.185.37:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UPGV3ou772CelrLhuZAAA4zE"]
[Mon Jul 20 06:27:41.065204 2026] [security2:error] [pid 929851:tid 929884] [remote 57.141.18.22:24092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4UPWV3ou772CelrLhuagAA6Bw"]
[Mon Jul 20 06:27:41.237980 2026] [security2:error] [pid 925208:tid 925310] [remote 15.206.251.117:36170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UPcRX7OrFkv0FyuI5TwAAH2U"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:27:41.270255 2026] [security2:error] [pid 929851:tid 929930] [remote 57.141.18.112:22338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4UPWV3ou772CelrLhucwABAko"]
[Mon Jul 20 06:27:41.272666 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhudAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.272776 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhudAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.325526 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhueAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.325631 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhueAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.379263 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4UPWV3ou772CelrLhuewAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.395609 2026] [security2:error] [pid 929851:tid 929932] [remote 3.7.185.37:52596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UPWV3ou772CelrLhufAAAvUw"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:27:41.434898 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhufQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.434982 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhufQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.490427 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuggAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.490551 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuggAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.529127 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuhQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.529252 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPWV3ou772CelrLhuhQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.634070 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPWV3ou772CelrLhueQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.909145 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPcRX7OrFkv0FyuI5YgAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:41.909274 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPcRX7OrFkv0FyuI5YgAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.128595 2026] [security2:error] [pid 925208:tid 925413] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPcRX7OrFkv0FyuI5aAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.282424 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuoQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.282518 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuoQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.345994 2026] [security2:error] [pid 925208:tid 925434] [client 171.61.165.146:29719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UPsRX7OrFkv0FyuI5eAAAAGA"]
[Mon Jul 20 06:27:42.346126 2026] [security2:error] [pid 925208:tid 925434] [client 171.61.165.146:29719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UPsRX7OrFkv0FyuI5eAAAAGA"]
[Mon Jul 20 06:27:42.362460 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhupQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.362593 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhupQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.386861 2026] [security2:error] [pid 925208:tid 925257] [remote 3.7.185.37:52606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4UPsRX7OrFkv0FyuI5egAAATA"]
[Mon Jul 20 06:27:42.519403 2026] [security2:error] [pid 929851:tid 930111] [client 57.141.18.91:27618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UOmV3ou772CelrLht5wABAx4"]
[Mon Jul 20 06:27:42.533884 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5gQAAAFU"]
[Mon Jul 20 06:27:42.533989 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5gQAAAFU"]
[Mon Jul 20 06:27:42.591218 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPmV3ou772CelrLhuqgAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.775487 2026] [security2:error] [pid 925208:tid 925344] [client 77.110.127.138:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5kwAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.775568 2026] [security2:error] [pid 925208:tid 925344] [client 77.110.127.138:63209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPsRX7OrFkv0FyuI5kwAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:42.851804 2026] [security2:error] [pid 925208:tid 925318] [remote 3.7.185.37:52606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.185.7.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4UPsRX7OrFkv0FyuI5mgAAG20"], referer: https://allandbeckson.com/wp-login.php
[Mon Jul 20 06:27:42.966009 2026] [security2:error] [pid 929851:tid 929934] [remote 15.206.251.117:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UPmV3ou772CelrLhuwgAAoE4"]
[Mon Jul 20 06:27:42.976554 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:63213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuwwAAAP4"]
[Mon Jul 20 06:27:42.976672 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:63213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UPmV3ou772CelrLhuwwAAAP4"]
[Mon Jul 20 06:27:43.188240 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UPmV3ou772CelrLhuvQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:43.401340 2026] [security2:error] [pid 929851:tid 929920] [remote 15.206.251.117:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UP2V3ou772CelrLhu2gAAxEA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:43.682793 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.31:63674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UO2V3ou772CelrLhuHAAA3yo"]
[Mon Jul 20 06:27:43.738640 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4UP2V3ou772CelrLhu8AAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:43.791341 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UP2V3ou772CelrLhu8QAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:43.791444 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UP2V3ou772CelrLhu8QAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.079493 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UP2V3ou772CelrLhu9gAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.440336 2026] [security2:error] [pid 929851:tid 929921] [remote 57.141.18.80:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3079353"] [unique_id "al4UQGV3ou772CelrLhvEgAAyUE"]
[Mon Jul 20 06:27:44.582099 2026] [security2:error] [pid 925208:tid 925342] [client 114.119.136.111:38169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sesamegreenbeans.com"] [uri "/singapore-to-seoul-without-flying-21-to-30-dec-2024/"] [unique_id "al4UQMRX7OrFkv0FyuI52AAAAAQ"], referer: http://sesamegreenbeans.com/rugby-world-cup-2019-match-experiences-in-kyushu/
[Mon Jul 20 06:27:44.613249 2026] [security2:error] [pid 929851:tid 930101] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UQGV3ou772CelrLhvEwAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.715184 2026] [security2:error] [pid 929851:tid 930042] [client 45.157.112.60:34189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UQGV3ou772CelrLhvIAAAAL4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:44.831740 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQGV3ou772CelrLhvKgAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.831886 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQGV3ou772CelrLhvKgAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:44.897079 2026] [security2:error] [pid 929851:tid 930079] [client 172.232.181.107:39908] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4UQGV3ou772CelrLhvKwAAAOM"]
[Mon Jul 20 06:27:45.253994 2026] [security2:error] [pid 929851:tid 930093] [client 57.141.18.15:65438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPWV3ou772CelrLhuiAAA8UU"]
[Mon Jul 20 06:27:45.294200 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQWV3ou772CelrLhvOQAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:45.294313 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQWV3ou772CelrLhvOQAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:45.444509 2026] [security2:error] [pid 925208:tid 925368] [client 57.141.18.67:32054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPcRX7OrFkv0FyuI5YAAAHh8"]
[Mon Jul 20 06:27:45.455173 2026] [authz_core:error] [pid 925208:tid 925349] [client 209.85.238.228:48688] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:27:45.690183 2026] [security2:error] [pid 929851:tid 930088] [client 106.219.188.178:16474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UQWV3ou772CelrLhvSwAAAOw"]
[Mon Jul 20 06:27:45.694457 2026] [security2:error] [pid 929851:tid 930088] [client 106.219.188.178:16474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UQWV3ou772CelrLhvSwAAAOw"]
[Mon Jul 20 06:27:45.807470 2026] [security2:error] [pid 925208:tid 925463] [client 57.141.18.64:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPsRX7OrFkv0FyuI5cgAAfQc"]
[Mon Jul 20 06:27:45.809628 2026] [security2:error] [pid 929851:tid 930084] [client 14.225.17.146:53263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4UQWV3ou772CelrLhvOgAAAOg"], referer: http://gearwaterproof.com/old
[Mon Jul 20 06:27:45.967444 2026] [security2:error] [pid 925208:tid 925221] [remote 91.142.222.105:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UQcRX7OrFkv0FyuI6FQAARAw"]
[Mon Jul 20 06:27:45.970312 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UQWV3ou772CelrLhvUAAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.112140 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:63200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4UQsRX7OrFkv0FyuI6GwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.240966 2026] [security2:error] [pid 925208:tid 925217] [remote 91.142.222.105:35662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UQsRX7OrFkv0FyuI6HwAAZQg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:27:46.306997 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQmV3ou772CelrLhvbQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.307151 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQmV3ou772CelrLhvbQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:46.386030 2026] [security2:error] [pid 925208:tid 925443] [client 57.141.18.94:22336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UPsRX7OrFkv0FyuI5mAAAaXw"]
[Mon Jul 20 06:27:46.390958 2026] [security2:error] [pid 929851:tid 930028] [client 14.225.17.146:57372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvZgAAALA"], referer: https://north-woods-engineering.com/old
[Mon Jul 20 06:27:46.889588 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvgQAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.066456 2026] [security2:error] [pid 925208:tid 925385] [client 77.110.127.138:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6PwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.066564 2026] [security2:error] [pid 925208:tid 925385] [client 77.110.127.138:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6PwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.420312 2026] [security2:error] [pid 929851:tid 930101] [client 68.235.52.68:34130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.235.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpAAAAPk"]
[Mon Jul 20 06:27:47.420448 2026] [security2:error] [pid 929851:tid 930101] [client 68.235.52.68:34130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpAAAAPk"]
[Mon Jul 20 06:27:47.428357 2026] [security2:error] [pid 929851:tid 930069] [client 223.185.13.213:31944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpQAAANk"]
[Mon Jul 20 06:27:47.428485 2026] [security2:error] [pid 929851:tid 930069] [client 223.185.13.213:31944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UQ2V3ou772CelrLhvpQAAANk"]
[Mon Jul 20 06:27:47.474521 2026] [security2:error] [pid 929851:tid 929924] [remote 159.65.81.207:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4UQ2V3ou772CelrLhvpwAAskQ"]
[Mon Jul 20 06:27:47.678920 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.67:32056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQGV3ou772CelrLhvAQAA2yM"]
[Mon Jul 20 06:27:47.694662 2026] [security2:error] [pid 929851:tid 930080] [client 57.141.18.70:49840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQGV3ou772CelrLhvAgAA5EM"]
[Mon Jul 20 06:27:47.873812 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6fgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.873897 2026] [security2:error] [pid 925208:tid 925359] [client 77.110.127.138:63249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ8RX7OrFkv0FyuI6fgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.897258 2026] [security2:error] [pid 929851:tid 929928] [remote 159.65.81.207:40748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4UQ2V3ou772CelrLhvvgAAnEg"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:27:47.928012 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ2V3ou772CelrLhvwQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.928137 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UQ2V3ou772CelrLhvwQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:47.971945 2026] [security2:error] [pid 929851:tid 929962] [remote 147.50.252.213:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UQ2V3ou772CelrLhvwgAAxGo"]
[Mon Jul 20 06:27:48.150245 2026] [security2:error] [pid 925208:tid 925399] [client 57.141.18.65:22046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQMRX7OrFkv0FyuI5zAAAPX8"]
[Mon Jul 20 06:27:48.344659 2026] [security2:error] [pid 925208:tid 925431] [client 77.110.127.138:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URMRX7OrFkv0FyuI6lAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:48.344763 2026] [security2:error] [pid 925208:tid 925431] [client 77.110.127.138:63251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URMRX7OrFkv0FyuI6lAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:48.372623 2026] [security2:error] [pid 929851:tid 930111] [client 14.225.17.146:57729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvjAAAAQM"], referer: http://colinkeyphotography.com/old
[Mon Jul 20 06:27:48.427308 2026] [security2:error] [pid 929851:tid 929969] [remote 147.50.252.213:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4URGV3ou772CelrLhv2gAAk3E"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:48.839002 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:63253] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501*if(now()=sysdate(),sleep(15),0)/amp/"] [unique_id "al4URMRX7OrFkv0FyuI6qQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:48.895961 2026] [security2:error] [pid 929851:tid 930089] [client 172.232.181.107:39908] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4URGV3ou772CelrLhv6QAAAO0"]
[Mon Jul 20 06:27:49.164802 2026] [security2:error] [pid 929851:tid 929997] [client 158.173.166.181:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4URWV3ou772CelrLhv-wAAAJE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:27:49.257568 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:63226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URcRX7OrFkv0FyuI6uQAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.257665 2026] [security2:error] [pid 925208:tid 925410] [client 77.110.127.138:63226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URcRX7OrFkv0FyuI6uQAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.279349 2026] [security2:error] [pid 929851:tid 930031] [client 14.225.17.146:57359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4URWV3ou772CelrLhv_QAAALM"], referer: http://katsklar.com/old
[Mon Jul 20 06:27:49.383703 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:63257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwCQAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.383815 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:63257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwCQAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.600774 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwFwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.600890 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URWV3ou772CelrLhwFwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:49.748657 2026] [security2:error] [pid 929851:tid 930042] [client 171.60.139.123:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4URWV3ou772CelrLhwHgAAAL4"]
[Mon Jul 20 06:27:49.748855 2026] [security2:error] [pid 929851:tid 930042] [client 171.60.139.123:62090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4URWV3ou772CelrLhwHgAAAL4"]
[Mon Jul 20 06:27:49.788467 2026] [security2:error] [pid 929851:tid 930109] [client 57.141.18.22:27774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQWV3ou772CelrLhvWAABAXY"]
[Mon Jul 20 06:27:50.166556 2026] [security2:error] [pid 929851:tid 930035] [client 57.141.18.99:24070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQmV3ou772CelrLhvdAAAt1c"]
[Mon Jul 20 06:27:50.504899 2026] [security2:error] [pid 925208:tid 925379] [client 57.141.18.97:21704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQsRX7OrFkv0FyuI6MAAAKUo"]
[Mon Jul 20 06:27:50.737804 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:63234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI67QAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:50.737921 2026] [security2:error] [pid 925208:tid 925412] [client 77.110.127.138:63234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI67QAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:50.801990 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:63264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI68gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:50.802095 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:63264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4URsRX7OrFkv0FyuI68gAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.018732 2026] [security2:error] [pid 929851:tid 930073] [client 103.141.108.143:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwWQAAAN0"]
[Mon Jul 20 06:27:51.018919 2026] [security2:error] [pid 929851:tid 930073] [client 103.141.108.143:53360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwWQAAAN0"]
[Mon Jul 20 06:27:51.063799 2026] [security2:error] [pid 929851:tid 929989] [client 57.141.18.54:42594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UQ2V3ou772CelrLhvnAAAiWM"]
[Mon Jul 20 06:27:51.095568 2026] [security2:error] [pid 925208:tid 925388] [client 45.116.69.230:54430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UR8RX7OrFkv0FyuI6_gAAADI"]
[Mon Jul 20 06:27:51.095669 2026] [security2:error] [pid 925208:tid 925388] [client 45.116.69.230:54430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UR8RX7OrFkv0FyuI6_gAAADI"]
[Mon Jul 20 06:27:51.145301 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.145391 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.152044 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.152119 2026] [security2:error] [pid 929851:tid 930027] [client 77.110.127.138:63266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwXwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.172398 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwVgAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.210021 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwYgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.210128 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwYgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.407406 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwbgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.407551 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwbgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.540491 2026] [security2:error] [pid 925208:tid 925450] [client 77.110.127.138:63208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7CgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.540634 2026] [security2:error] [pid 925208:tid 925450] [client 77.110.127.138:63208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7CgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.566367 2026] [security2:error] [pid 929851:tid 930076] [client 39.48.81.23:53417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwdwAAAOA"]
[Mon Jul 20 06:27:51.566525 2026] [security2:error] [pid 929851:tid 930076] [client 39.48.81.23:53417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UR2V3ou772CelrLhwdwAAAOA"]
[Mon Jul 20 06:27:51.634269 2026] [security2:error] [pid 929851:tid 930056] [client 93.152.221.118:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UR2V3ou772CelrLhweQAAAMw"], referer: https://wordpress.org/
[Mon Jul 20 06:27:51.653577 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:63273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7EAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.653669 2026] [security2:error] [pid 925208:tid 925397] [client 77.110.127.138:63273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR8RX7OrFkv0FyuI7EAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.707526 2026] [security2:error] [pid 929851:tid 930040] [client 14.225.17.146:55898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4UR2V3ou772CelrLhwewAAALw"], referer: http://dasmarque.com/old
[Mon Jul 20 06:27:51.795523 2026] [security2:error] [pid 925208:tid 925279] [remote 192.241.143.148:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UR8RX7OrFkv0FyuI7EwAAEUY"]
[Mon Jul 20 06:27:51.853065 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwhQAAAMg"]
[Mon Jul 20 06:27:51.853211 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UR2V3ou772CelrLhwhQAAAMg"]
[Mon Jul 20 06:27:51.884859 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63275] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/5010'XOR(501*if(now()=sysdate(),sleep(15),0))XOR'Z/amp/"] [unique_id "al4UR2V3ou772CelrLhwhwAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:51.909049 2026] [security2:error] [pid 929851:tid 930033] [client 93.152.221.118:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UR2V3ou772CelrLhwiwAAALU"]
[Mon Jul 20 06:27:51.930145 2026] [security2:error] [pid 929851:tid 930096] [client 116.76.196.216:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwTQAAAPQ"]
[Mon Jul 20 06:27:51.950555 2026] [security2:error] [pid 929851:tid 930070] [client 57.141.18.81:25120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URGV3ou772CelrLhvyQAA2m4"]
[Mon Jul 20 06:27:51.985467 2026] [security2:error] [pid 925208:tid 925309] [remote 192.241.143.148:36364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UR8RX7OrFkv0FyuI7GAAAE2Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:27:52.002938 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7GQAAABQ"]
[Mon Jul 20 06:27:52.003059 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7GQAAABQ"]
[Mon Jul 20 06:27:52.472375 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.115:28060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URGV3ou772CelrLhv6wAAlnw"]
[Mon Jul 20 06:27:52.478740 2026] [security2:error] [pid 925208:tid 925407] [client 77.110.127.138:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7MgAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:52.478849 2026] [security2:error] [pid 925208:tid 925407] [client 77.110.127.138:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USMRX7OrFkv0FyuI7MgAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:52.893175 2026] [security2:error] [pid 929851:tid 930111] [client 172.232.181.107:39908] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4USGV3ou772CelrLhwrgAAAQM"]
[Mon Jul 20 06:27:53.164671 2026] [security2:error] [pid 925208:tid 925369] [client 171.61.165.146:31211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7UAAAAB8"]
[Mon Jul 20 06:27:53.165724 2026] [security2:error] [pid 925208:tid 925369] [client 171.61.165.146:31211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7UAAAAB8"]
[Mon Jul 20 06:27:53.227112 2026] [security2:error] [pid 925208:tid 925457] [client 93.152.221.118:54027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.221.152.93.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UScRX7OrFkv0FyuI7UgAAAHc"]
[Mon Jul 20 06:27:53.233502 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63221] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4USWV3ou772CelrLhwxgAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.551848 2026] [security2:error] [pid 929851:tid 930059] [client 14.225.17.146:55889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwzQAAAM8"], referer: http://reosportsboats.com/old
[Mon Jul 20 06:27:53.634539 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwzgAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.773589 2026] [security2:error] [pid 925208:tid 925397] [client 112.208.70.94:43569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7YgAAADs"]
[Mon Jul 20 06:27:53.773703 2026] [security2:error] [pid 925208:tid 925397] [client 112.208.70.94:43569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UScRX7OrFkv0FyuI7YgAAADs"]
[Mon Jul 20 06:27:53.794164 2026] [security2:error] [pid 929851:tid 929981] [remote 154.66.198.148:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4USWV3ou772CelrLhw6AAAxn0"]
[Mon Jul 20 06:27:53.841019 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USWV3ou772CelrLhw6wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.841146 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USWV3ou772CelrLhw6wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:53.934310 2026] [security2:error] [pid 929851:tid 930012] [client 57.141.18.55:47266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwPwAAoBg"]
[Mon Jul 20 06:27:53.992096 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:63287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/5010\\"XOR(501*if(now()=sysdate(),sleep(15),0))XOR\\"Z/amp/"] [unique_id "al4USWV3ou772CelrLhw9QAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:54.042663 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USmV3ou772CelrLhw-AAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:54.042790 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4USmV3ou772CelrLhw-AAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:54.073539 2026] [security2:error] [pid 929851:tid 929998] [client 57.141.18.26:33408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwRgAAkgY"]
[Mon Jul 20 06:27:54.332356 2026] [security2:error] [pid 929851:tid 929903] [remote 154.66.198.148:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4USmV3ou772CelrLhxCAAA6S8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:54.430132 2026] [security2:error] [pid 929851:tid 930041] [client 57.141.18.103:42072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4URmV3ou772CelrLhwWAAAvQ4"]
[Mon Jul 20 06:27:54.526393 2026] [security2:error] [pid 929851:tid 930063] [client 14.225.17.146:60743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4USmV3ou772CelrLhxDgAAANM"], referer: https://reosportsboats.com/old
[Mon Jul 20 06:27:54.622595 2026] [security2:error] [pid 929851:tid 930100] [client 57.141.18.0:55026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UR2V3ou772CelrLhwZQAA-BY"]
[Mon Jul 20 06:27:54.826858 2026] [security2:error] [pid 929851:tid 930105] [client 104.234.53.57:21505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4USmV3ou772CelrLhxIgAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:55.089499 2026] [security2:error] [pid 929851:tid 930109] [client 57.141.18.100:37108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UR2V3ou772CelrLhwfQABAQ8"]
[Mon Jul 20 06:27:55.250013 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4US8RX7OrFkv0FyuI7qAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:55.250118 2026] [security2:error] [pid 925208:tid 925358] [client 77.110.127.138:63294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4US8RX7OrFkv0FyuI7qAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:55.275108 2026] [security2:error] [pid 929851:tid 929914] [remote 8.217.108.67:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4US2V3ou772CelrLhxLgAAjzo"]
[Mon Jul 20 06:27:55.426963 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63297] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4US2V3ou772CelrLhxOgAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:55.522845 2026] [security2:error] [pid 925208:tid 925310] [remote 100.42.189.89:48238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4US8RX7OrFkv0FyuI7tQAAfmU"]
[Mon Jul 20 06:27:55.730127 2026] [security2:error] [pid 925208:tid 925238] [remote 100.42.189.89:48238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4US8RX7OrFkv0FyuI7wQAAKh0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:55.736389 2026] [security2:error] [pid 925208:tid 925381] [client 103.153.183.69:60932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/apache2/apache2.conf"] [unique_id "al4US8RX7OrFkv0FyuI7wgAAACs"], referer: https://www.google.com/
[Mon Jul 20 06:27:55.775422 2026] [security2:error] [pid 929851:tid 930047] [client 14.225.17.146:60544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4US2V3ou772CelrLhxTgAAAMM"], referer: http://processorstudio.com/old
[Mon Jul 20 06:27:55.781739 2026] [security2:error] [pid 929851:tid 929926] [remote 8.217.108.67:3396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4US2V3ou772CelrLhxUgAAqUY"], referer: https://roguedragonstudio.com/wp-login.php
[Mon Jul 20 06:27:55.813820 2026] [security2:error] [pid 925208:tid 925372] [client 57.141.18.63:59106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USMRX7OrFkv0FyuI7KAAAInU"]
[Mon Jul 20 06:27:55.870033 2026] [security2:error] [pid 929851:tid 929860] [remote 154.66.198.148:24610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4US2V3ou772CelrLhxVAAAswQ"]
[Mon Jul 20 06:27:56.347371 2026] [security2:error] [pid 929851:tid 930074] [client 106.219.188.178:51782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UTGV3ou772CelrLhxYgAAAN4"]
[Mon Jul 20 06:27:56.347499 2026] [security2:error] [pid 929851:tid 930074] [client 106.219.188.178:51782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UTGV3ou772CelrLhxYgAAAN4"]
[Mon Jul 20 06:27:56.367772 2026] [security2:error] [pid 925208:tid 925460] [client 104.234.53.53:29097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UTMRX7OrFkv0FyuI72wAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:56.443732 2026] [security2:error] [pid 929851:tid 929940] [remote 154.66.198.148:24610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UTGV3ou772CelrLhxZQAAn1Q"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:27:56.528424 2026] [security2:error] [pid 929851:tid 930058] [client 57.141.18.79:36322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USGV3ou772CelrLhwtgAAzmQ"]
[Mon Jul 20 06:27:56.653770 2026] [security2:error] [pid 925208:tid 925387] [client 104.234.53.53:29097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UTMRX7OrFkv0FyuI76AAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:27:56.714822 2026] [security2:error] [pid 929851:tid 930089] [client 57.141.18.44:44756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwwAAA7Qg"]
[Mon Jul 20 06:27:56.808969 2026] [security2:error] [pid 929851:tid 930028] [client 14.225.17.146:53198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxeQAAALA"], referer: https://processorstudio.com/old
[Mon Jul 20 06:27:56.844361 2026] [security2:error] [pid 929851:tid 930007] [client 57.141.18.113:64624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhwyAAAmys"]
[Mon Jul 20 06:27:57.091505 2026] [security2:error] [pid 929851:tid 930103] [client 50.116.65.227:18708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UTWV3ou772CelrLhxjAAAAPs"]
[Mon Jul 20 06:27:57.104086 2026] [security2:error] [pid 929851:tid 930002] [client 50.116.65.227:18710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UTWV3ou772CelrLhxjQAAAJY"]
[Mon Jul 20 06:27:57.137515 2026] [security2:error] [pid 929851:tid 930071] [client 18.192.166.72:49040] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxiAAAANs"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:27:57.168219 2026] [security2:error] [pid 925208:tid 925381] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UTMRX7OrFkv0FyuI78gAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.240690 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.57:43388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USWV3ou772CelrLhw2gAA_iw"]
[Mon Jul 20 06:27:57.263085 2026] [security2:error] [pid 929851:tid 929986] [client 223.185.13.213:25435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UTWV3ou772CelrLhxkQAAAIY"]
[Mon Jul 20 06:27:57.263221 2026] [security2:error] [pid 929851:tid 929986] [client 223.185.13.213:25435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UTWV3ou772CelrLhxkQAAAIY"]
[Mon Jul 20 06:27:57.371105 2026] [security2:error] [pid 929851:tid 930063] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxewAA01Y"], referer: http://ardhalwafaa.com/old
[Mon Jul 20 06:27:57.377540 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:63304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTcRX7OrFkv0FyuI8AAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.377621 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:63304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTcRX7OrFkv0FyuI8AAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.773967 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxowAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.774077 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxowAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.924723 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxqQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:57.924818 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTWV3ou772CelrLhxqQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.027342 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.103:42082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USmV3ou772CelrLhxEQAA1zM"]
[Mon Jul 20 06:27:58.050826 2026] [security2:error] [pid 925208:tid 925269] [remote 84.247.172.23:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4UTsRX7OrFkv0FyuI8FwAATDw"]
[Mon Jul 20 06:27:58.072880 2026] [cgid:error] [pid 929851:tid 930061] [client 66.132.186.196:58328] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: http://www.website-fa490990.threethirds.co:80/cgi-bin
[Mon Jul 20 06:27:58.175930 2026] [security2:error] [pid 925208:tid 925393] [client 57.141.18.22:46752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4USsRX7OrFkv0FyuI7hwAANwU"]
[Mon Jul 20 06:27:58.300991 2026] [security2:error] [pid 925208:tid 925309] [remote 84.247.172.23:32804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4UTsRX7OrFkv0FyuI8JQAARmQ"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 06:27:58.308152 2026] [security2:error] [pid 929851:tid 930039] [client 45.3.44.200:50425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/xmlrpc.php"] [unique_id "al4UTmV3ou772CelrLhxvgAAALs"], referer: https://t.co/
[Mon Jul 20 06:27:58.625046 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTmV3ou772CelrLhxzAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.625183 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UTmV3ou772CelrLhxzAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.707801 2026] [security2:error] [pid 925208:tid 925396] [client 57.141.18.56:32690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4US8RX7OrFkv0FyuI7nwAAOg0"]
[Mon Jul 20 06:27:58.762217 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:63313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UTmV3ou772CelrLhx1wAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:58.971393 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:60686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4UTmV3ou772CelrLhxyAAAAKQ"], referer: http://overloadcomedy.com/old
[Mon Jul 20 06:27:59.063923 2026] [security2:error] [pid 925208:tid 925359] [client 50.116.65.227:54726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/08/IMG_8766.jpeg"] [unique_id "al4UT8RX7OrFkv0FyuI8RgAAAGU"]
[Mon Jul 20 06:27:59.261787 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.91:63684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4US2V3ou772CelrLhxUQAA-kc"]
[Mon Jul 20 06:27:59.525918 2026] [security2:error] [pid 925208:tid 925274] [remote 49.12.216.176:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4UT8RX7OrFkv0FyuI8XAAAa0E"]
[Mon Jul 20 06:27:59.542084 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.4:22070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxVwAA2E8"]
[Mon Jul 20 06:27:59.609342 2026] [security2:error] [pid 929851:tid 930107] [client 14.225.17.146:63770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4UT2V3ou772CelrLhx9wAAAP8"], referer: http://taskidsvirginia.com/old
[Mon Jul 20 06:27:59.696381 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UT8RX7OrFkv0FyuI8WgAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:59.728058 2026] [security2:error] [pid 925208:tid 925306] [remote 49.12.216.176:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4UT8RX7OrFkv0FyuI8XwAAEmE"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:27:59.734202 2026] [security2:error] [pid 925208:tid 925452] [client 47.128.30.83:25910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zonemist.com"] [uri "/robots.txt"] [unique_id "al4UT8RX7OrFkv0FyuI8YAAAAHI"]
[Mon Jul 20 06:27:59.859710 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UT2V3ou772CelrLhyCAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:59.859837 2026] [security2:error] [pid 929851:tid 930000] [client 77.110.127.138:63320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UT2V3ou772CelrLhyCAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:27:59.996948 2026] [security2:error] [pid 929851:tid 930060] [client 14.225.17.146:60467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4UT2V3ou772CelrLhyBwAAANA"], referer: http://cephasnext.com/old
[Mon Jul 20 06:28:00.017033 2026] [security2:error] [pid 925208:tid 925351] [client 14.225.17.146:60576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4UTsRX7OrFkv0FyuI8KQAAAA0"], referer: http://ksands.co.uk/old
[Mon Jul 20 06:28:00.055777 2026] [security2:error] [pid 929851:tid 929960] [remote 160.187.68.132:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyFAAAhWg"]
[Mon Jul 20 06:28:00.060642 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.34:42824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTGV3ou772CelrLhxbwAAuU4"]
[Mon Jul 20 06:28:00.228544 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UUGV3ou772CelrLhyEwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:00.282231 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUMRX7OrFkv0FyuI8cwAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:00.282326 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:63200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUMRX7OrFkv0FyuI8cwAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:00.293102 2026] [security2:error] [pid 929851:tid 930029] [client 14.225.17.146:60721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4UUGV3ou772CelrLhyGAAAALE"], referer: http://samdothan.org/old
[Mon Jul 20 06:28:00.437610 2026] [security2:error] [pid 925208:tid 925405] [client 171.60.139.123:62620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UUMRX7OrFkv0FyuI8eQAAAEM"]
[Mon Jul 20 06:28:00.437731 2026] [security2:error] [pid 925208:tid 925405] [client 171.60.139.123:62620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UUMRX7OrFkv0FyuI8eQAAAEM"]
[Mon Jul 20 06:28:00.573934 2026] [security2:error] [pid 929851:tid 929967] [remote 160.187.68.132:36038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyKQAAzm8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:00.658588 2026] [security2:error] [pid 929851:tid 929973] [remote 162.19.86.63:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyMAAApnU"]
[Mon Jul 20 06:28:00.747773 2026] [fcgid:warn] [pid 925208:tid 925378] (70014)End of file found: [client 199.45.154.146:44016] mod_fcgid: can't get data from http client
[Mon Jul 20 06:28:00.869063 2026] [security2:error] [pid 929851:tid 929963] [remote 162.19.86.63:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4UUGV3ou772CelrLhyOgAArWs"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:28:00.933610 2026] [security2:error] [pid 929851:tid 930024] [client 57.141.18.31:54210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTWV3ou772CelrLhxlgAArBE"]
[Mon Jul 20 06:28:00.976279 2026] [security2:error] [pid 925208:tid 925459] [client 14.225.17.146:50363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4UT8RX7OrFkv0FyuI8YQAAAHk"], referer: http://sarahholyfield.com/old
[Mon Jul 20 06:28:01.001966 2026] [security2:error] [pid 925208:tid 925357] [client 57.141.18.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UUMRX7OrFkv0FyuI8iAAAABM"]
[Mon Jul 20 06:28:01.173407 2026] [security2:error] [pid 925208:tid 925374] [client 77.110.127.138:63325] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UUcRX7OrFkv0FyuI8kgAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:01.316716 2026] [security2:error] [pid 929851:tid 930083] [client 57.141.18.63:32078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTWV3ou772CelrLhxqAAA50s"]
[Mon Jul 20 06:28:01.677913 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUWV3ou772CelrLhyXQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:01.678021 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:63267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUWV3ou772CelrLhyXQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:01.699050 2026] [security2:error] [pid 925208:tid 925352] [client 103.141.108.143:53837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8qwAAAA4"]
[Mon Jul 20 06:28:01.699199 2026] [security2:error] [pid 925208:tid 925352] [client 103.141.108.143:53837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8qwAAAA4"]
[Mon Jul 20 06:28:01.699524 2026] [security2:error] [pid 929851:tid 930094] [client 50.116.65.227:42652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4UUWV3ou772CelrLhyXwAAAPI"]
[Mon Jul 20 06:28:01.711445 2026] [security2:error] [pid 929851:tid 929988] [client 50.116.65.227:54758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4UUWV3ou772CelrLhyYwAAAOE"]
[Mon Jul 20 06:28:01.789808 2026] [security2:error] [pid 929851:tid 930015] [client 181.121.225.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4UT2V3ou772CelrLhx6QAAAKM"]
[Mon Jul 20 06:28:01.828191 2026] [security2:error] [pid 925208:tid 925434] [client 45.116.69.230:54959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8swAAAGA"]
[Mon Jul 20 06:28:01.828432 2026] [security2:error] [pid 925208:tid 925434] [client 45.116.69.230:54959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UUcRX7OrFkv0FyuI8swAAAGA"]
[Mon Jul 20 06:28:02.039462 2026] [security2:error] [pid 929851:tid 930010] [client 39.48.81.23:53889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UUmV3ou772CelrLhycwAAAJ4"]
[Mon Jul 20 06:28:02.040283 2026] [security2:error] [pid 929851:tid 930010] [client 39.48.81.23:53889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UUmV3ou772CelrLhycwAAAJ4"]
[Mon Jul 20 06:28:02.075958 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UUcRX7OrFkv0FyuI8sQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.079797 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:63337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8vwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.079922 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:63337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8vwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.106116 2026] [security2:error] [pid 929851:tid 930035] [client 57.141.18.51:62386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTmV3ou772CelrLhxzQAAt1A"]
[Mon Jul 20 06:28:02.135173 2026] [security2:error] [pid 929851:tid 929856] [remote 109.234.164.108:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.164.234.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhydwAA0AA"]
[Mon Jul 20 06:28:02.179906 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUmV3ou772CelrLhyewAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.180018 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:63303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUmV3ou772CelrLhyewAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.228027 2026] [security2:error] [pid 925208:tid 925410] [client 57.141.18.1:45118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UTsRX7OrFkv0FyuI8OgAASFM"]
[Mon Jul 20 06:28:02.296599 2026] [security2:error] [pid 929851:tid 929879] [remote 217.61.143.92:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyfwAAqRc"]
[Mon Jul 20 06:28:02.329932 2026] [security2:error] [pid 929851:tid 929982] [remote 109.234.164.108:52656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.164.234.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyggAA934"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 06:28:02.333963 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:63343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xAAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.334110 2026] [security2:error] [pid 925208:tid 925451] [client 77.110.127.138:63343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xAAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.419572 2026] [security2:error] [pid 929851:tid 929866] [remote 100.42.189.89:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyhgAAoQo"]
[Mon Jul 20 06:28:02.476965 2026] [security2:error] [pid 925208:tid 925349] [client 194.187.171.135:55479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xQAACyI"]
[Mon Jul 20 06:28:02.504192 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8zAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.504324 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI8zAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.622337 2026] [security2:error] [pid 929851:tid 929955] [remote 100.42.189.89:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyjAAAkWM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:28:02.658077 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI81QAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.658220 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UUsRX7OrFkv0FyuI81QAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:02.660458 2026] [security2:error] [pid 929851:tid 929872] [remote 217.61.143.92:54074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UUmV3ou772CelrLhyjgAArRA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:28:03.078170 2026] [security2:error] [pid 929851:tid 930031] [client 104.234.53.56:30625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UUmV3ou772CelrLhyngAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:03.181923 2026] [security2:error] [pid 929851:tid 929994] [client 14.225.17.146:60507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4UUmV3ou772CelrLhyhwAAAI4"], referer: http://oldracelimited.com/old
[Mon Jul 20 06:28:03.248496 2026] [security2:error] [pid 925208:tid 925212] [remote 57.141.18.65:43140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4415964"] [unique_id "al4UU8RX7OrFkv0FyuI85gAATgM"]
[Mon Jul 20 06:28:03.520562 2026] [security2:error] [pid 925208:tid 925418] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UU8RX7OrFkv0FyuI86wAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:03.710535 2026] [proxy:error] [pid 925208:tid 925354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:03.710604 2026] [proxy_http:error] [pid 925208:tid 925354] [client 34.73.38.214:51054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:03.711798 2026] [proxy:error] [pid 925208:tid 925354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:03.711830 2026] [proxy_http:error] [pid 925208:tid 925354] [client 34.73.38.214:51054] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:03.714286 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:63354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UU8RX7OrFkv0FyuI89wAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:03.714369 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:63354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UU8RX7OrFkv0FyuI89wAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:03.837011 2026] [security2:error] [pid 929851:tid 929888] [remote 130.51.180.8:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UU2V3ou772CelrLhyyAAAhiA"]
[Mon Jul 20 06:28:03.881412 2026] [security2:error] [pid 925208:tid 925370] [client 57.141.18.89:44520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUMRX7OrFkv0FyuI8fAAAIHo"]
[Mon Jul 20 06:28:03.921982 2026] [security2:error] [pid 929851:tid 930093] [client 57.141.18.96:35472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUGV3ou772CelrLhyKAAA8Wo"]
[Mon Jul 20 06:28:03.964659 2026] [security2:error] [pid 929851:tid 930075] [client 104.234.53.56:30625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UU2V3ou772CelrLhyywAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:04.180369 2026] [security2:error] [pid 929851:tid 930052] [client 171.61.165.146:4808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UVGV3ou772CelrLhyzgAAAMg"]
[Mon Jul 20 06:28:04.180477 2026] [security2:error] [pid 929851:tid 930052] [client 171.61.165.146:4808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UVGV3ou772CelrLhyzgAAAMg"]
[Mon Jul 20 06:28:04.196597 2026] [security2:error] [pid 929851:tid 929857] [remote 130.51.180.8:59582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UVGV3ou772CelrLhy0wAA6QE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:28:04.345251 2026] [security2:error] [pid 925208:tid 925423] [client 50.116.65.227:54788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4UU8RX7OrFkv0FyuI8-AAAAFU"]
[Mon Jul 20 06:28:04.347472 2026] [security2:error] [pid 929851:tid 930067] [client 146.120.227.216:55318] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4UVGV3ou772CelrLhy2AAAANc"]
[Mon Jul 20 06:28:04.391168 2026] [security2:error] [pid 929851:tid 930050] [client 186.189.111.130:49320] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4UVGV3ou772CelrLhy2wAAAMY"]
[Mon Jul 20 06:28:04.410376 2026] [security2:error] [pid 929851:tid 930081] [client 64.233.172.3:38682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UVGV3ou772CelrLhy1AAAAOU"]
[Mon Jul 20 06:28:04.539608 2026] [security2:error] [pid 929851:tid 930105] [client 57.141.18.8:23532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUWV3ou772CelrLhyQwAA_Vo"]
[Mon Jul 20 06:28:04.623858 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.62:36782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUcRX7OrFkv0FyuI8kwAAVyw"]
[Mon Jul 20 06:28:04.787547 2026] [security2:error] [pid 929851:tid 930102] [client 71.249.119.72:39914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UVGV3ou772CelrLhy7AAAAPo"]
[Mon Jul 20 06:28:04.787807 2026] [proxy:error] [pid 929851:tid 930108] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:04.787885 2026] [proxy_http:error] [pid 929851:tid 930108] [client 34.73.38.214:50777] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:04.788557 2026] [proxy:error] [pid 929851:tid 930108] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:04.788601 2026] [proxy_http:error] [pid 929851:tid 930108] [client 34.73.38.214:50777] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:04.928827 2026] [security2:error] [pid 929851:tid 929995] [client 50.116.65.227:54806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4UVGV3ou772CelrLhy2QAAAI8"]
[Mon Jul 20 06:28:05.059651 2026] [security2:error] [pid 929851:tid 929988] [client 75.158.224.112:35566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4UVWV3ou772CelrLhy9AAAAIg"]
[Mon Jul 20 06:28:05.063101 2026] [security2:error] [pid 925208:tid 925413] [client 57.141.18.71:45694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUcRX7OrFkv0FyuI8sgAASxU"]
[Mon Jul 20 06:28:05.064514 2026] [security2:error] [pid 929851:tid 930039] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UVGV3ou772CelrLhy8AAAALs"]
[Mon Jul 20 06:28:05.187810 2026] [security2:error] [pid 929851:tid 930074] [client 139.28.49.104:54664] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4UVWV3ou772CelrLhy-QAAAN4"]
[Mon Jul 20 06:28:05.212306 2026] [security2:error] [pid 929851:tid 930099] [client 41.90.172.147:9795] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UVWV3ou772CelrLhy_gAAAPc"]
[Mon Jul 20 06:28:05.492976 2026] [security2:error] [pid 925208:tid 925458] [client 78.160.164.3:33198] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4UVcRX7OrFkv0FyuI9OwAAAHg"]
[Mon Jul 20 06:28:05.540541 2026] [security2:error] [pid 929851:tid 930097] [client 131.196.114.35:54798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4UVWV3ou772CelrLhzCgAAAPU"]
[Mon Jul 20 06:28:05.603946 2026] [security2:error] [pid 929851:tid 930019] [client 196.187.145.251:41505] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UVWV3ou772CelrLhzEAAAAKc"]
[Mon Jul 20 06:28:05.740170 2026] [security2:error] [pid 929851:tid 930066] [client 58.186.167.209:63691] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4UVWV3ou772CelrLhzHQAAANY"]
[Mon Jul 20 06:28:05.832043 2026] [security2:error] [pid 929851:tid 930088] [client 65.1.132.125:10326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UVWV3ou772CelrLhzJAAAAOw"]
[Mon Jul 20 06:28:05.836514 2026] [proxy:error] [pid 929851:tid 930093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:05.836574 2026] [proxy_http:error] [pid 929851:tid 930093] [client 34.73.38.214:58201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:05.837278 2026] [proxy:error] [pid 929851:tid 930093] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:05.837306 2026] [proxy_http:error] [pid 929851:tid 930093] [client 34.73.38.214:58201] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:05.850443 2026] [security2:error] [pid 929851:tid 929981] [remote 97.74.87.194:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UVWV3ou772CelrLhzJgAA230"]
[Mon Jul 20 06:28:05.867257 2026] [security2:error] [pid 925208:tid 925445] [client 57.141.18.118:61464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUsRX7OrFkv0FyuI8xgAAaz8"]
[Mon Jul 20 06:28:05.881893 2026] [security2:error] [pid 929851:tid 930040] [client 14.225.17.146:60318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzGwAAALw"], referer: http://dadanetnet.net/old
[Mon Jul 20 06:28:05.957728 2026] [security2:error] [pid 929851:tid 930036] [client 57.141.18.48:36874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUmV3ou772CelrLhyiAAAuHc"]
[Mon Jul 20 06:28:05.966001 2026] [security2:error] [pid 925208:tid 925402] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UVcRX7OrFkv0FyuI9SAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:06.011251 2026] [security2:error] [pid 925208:tid 925342] [client 59.103.220.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4UVcRX7OrFkv0FyuI9RQAAAAQ"]
[Mon Jul 20 06:28:06.019431 2026] [security2:error] [pid 925208:tid 925380] [client 57.141.18.65:28762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UUsRX7OrFkv0FyuI80AAAKgc"]
[Mon Jul 20 06:28:06.138307 2026] [security2:error] [pid 929851:tid 930108] [client 14.225.17.146:53820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzMAAAAQA"], referer: http://ivetstrategies.com/old
[Mon Jul 20 06:28:06.246699 2026] [security2:error] [pid 929851:tid 930031] [client 14.225.17.146:53825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UVmV3ou772CelrLhzMgAAALM"], referer: http://mezzacraft.com/old
[Mon Jul 20 06:28:06.414513 2026] [security2:error] [pid 929851:tid 930064] [client 45.225.44.179:57149] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UVmV3ou772CelrLhzSgAAANQ"]
[Mon Jul 20 06:28:06.497509 2026] [security2:error] [pid 925208:tid 925389] [client 213.139.53.205:52486] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4UVsRX7OrFkv0FyuI9aAAAADM"]
[Mon Jul 20 06:28:06.608725 2026] [security2:error] [pid 929851:tid 929861] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4UVmV3ou772CelrLhzUAAA4gU"]
[Mon Jul 20 06:28:06.634720 2026] [security2:error] [pid 929851:tid 930006] [client 50.116.65.227:54850] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UVmV3ou772CelrLhzVQAAAJo"]
[Mon Jul 20 06:28:06.645231 2026] [security2:error] [pid 925208:tid 925417] [client 50.116.65.227:54866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UVsRX7OrFkv0FyuI9bwAAAE8"]
[Mon Jul 20 06:28:06.697670 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UVmV3ou772CelrLhzWwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:06.697772 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UVmV3ou772CelrLhzWwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:06.706389 2026] [security2:error] [pid 925208:tid 925421] [client 104.234.53.89:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UVsRX7OrFkv0FyuI9cwAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:06.710965 2026] [proxy:error] [pid 929851:tid 930087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:06.711007 2026] [proxy_http:error] [pid 929851:tid 930087] [client 34.73.38.214:57839] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:06.711694 2026] [proxy:error] [pid 929851:tid 930087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:06.711717 2026] [proxy_http:error] [pid 929851:tid 930087] [client 34.73.38.214:57839] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:06.803237 2026] [security2:error] [pid 929851:tid 930106] [client 106.219.188.178:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UVmV3ou772CelrLhzYwAAAP4"]
[Mon Jul 20 06:28:06.810869 2026] [security2:error] [pid 929851:tid 930106] [client 106.219.188.178:40974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UVmV3ou772CelrLhzYwAAAP4"]
[Mon Jul 20 06:28:06.822823 2026] [security2:error] [pid 929851:tid 930021] [client 49.147.198.12:49119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4UVmV3ou772CelrLhzZwAAAKk"]
[Mon Jul 20 06:28:06.886863 2026] [security2:error] [pid 929851:tid 929999] [client 37.114.177.7:4896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4UVmV3ou772CelrLhzbAAAAJM"]
[Mon Jul 20 06:28:06.892834 2026] [security2:error] [pid 929851:tid 930083] [client 43.205.139.3:21350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UVmV3ou772CelrLhzbQAAAOc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:28:06.908712 2026] [security2:error] [pid 929851:tid 929906] [remote 97.74.87.194:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UVmV3ou772CelrLhzbgAAvjI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:28:07.057549 2026] [security2:error] [pid 925208:tid 925464] [client 115.69.212.210:59518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UV8RX7OrFkv0FyuI9iAAAAH4"]
[Mon Jul 20 06:28:07.176782 2026] [security2:error] [pid 925208:tid 925460] [client 185.187.77.183:18818] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UV8RX7OrFkv0FyuI9jAAAAHo"]
[Mon Jul 20 06:28:07.266138 2026] [security2:error] [pid 929851:tid 930031] [client 112.208.70.94:43987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UV2V3ou772CelrLhzdwAAALM"]
[Mon Jul 20 06:28:07.266302 2026] [security2:error] [pid 929851:tid 930031] [client 112.208.70.94:43987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UV2V3ou772CelrLhzdwAAALM"]
[Mon Jul 20 06:28:07.273174 2026] [security2:error] [pid 925208:tid 925401] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UV8RX7OrFkv0FyuI9hwAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:07.290704 2026] [security2:error] [pid 929851:tid 930099] [client 152.59.19.173:47592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4UV2V3ou772CelrLhzeAAAAPc"]
[Mon Jul 20 06:28:07.431757 2026] [security2:error] [pid 929851:tid 929884] [remote 202.51.202.242:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4UV2V3ou772CelrLhzhAABAhw"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:28:07.433553 2026] [security2:error] [pid 929851:tid 930086] [client 144.48.151.179:49176] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4UV2V3ou772CelrLhzhQAAAOo"]
[Mon Jul 20 06:28:07.719812 2026] [security2:error] [pid 925208:tid 925420] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UV8RX7OrFkv0FyuI9ogAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:07.914824 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UV8RX7OrFkv0FyuI9sAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:07.914944 2026] [security2:error] [pid 925208:tid 925417] [client 77.110.127.138:63379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UV8RX7OrFkv0FyuI9sAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.067573 2026] [security2:error] [pid 929851:tid 930100] [client 14.225.17.146:54194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4UV2V3ou772CelrLhzigAAAPg"], referer: http://nwcarvingacademy.com/old
[Mon Jul 20 06:28:08.074585 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWGV3ou772CelrLhzpAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.074693 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWGV3ou772CelrLhzpAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.135304 2026] [security2:error] [pid 925208:tid 925340] [client 57.141.18.20:27898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVMRX7OrFkv0FyuI9HQAAAjk"]
[Mon Jul 20 06:28:08.144047 2026] [security2:error] [pid 925208:tid 925238] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "omenana.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4UWMRX7OrFkv0FyuI9vAAAOh0"]
[Mon Jul 20 06:28:08.147875 2026] [security2:error] [pid 929851:tid 930066] [client 116.204.228.180:33220] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4UWGV3ou772CelrLhzpwAAANY"]
[Mon Jul 20 06:28:08.248521 2026] [security2:error] [pid 929851:tid 930077] [client 104.234.53.91:37443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UWGV3ou772CelrLhztwAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:08.408496 2026] [security2:error] [pid 929851:tid 929997] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzqAAAAJE"]
[Mon Jul 20 06:28:08.423538 2026] [security2:error] [pid 929851:tid 929930] [remote 160.187.68.132:34022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UWGV3ou772CelrLhzwwAA50o"]
[Mon Jul 20 06:28:08.459800 2026] [security2:error] [pid 925208:tid 925384] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9yAAAAC4"]
[Mon Jul 20 06:28:08.473291 2026] [security2:error] [pid 929851:tid 930054] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzsAAAAMo"]
[Mon Jul 20 06:28:08.476006 2026] [security2:error] [pid 929851:tid 929998] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzrgAAAJI"]
[Mon Jul 20 06:28:08.480161 2026] [security2:error] [pid 929851:tid 930040] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzrQAAALw"]
[Mon Jul 20 06:28:08.487271 2026] [security2:error] [pid 929851:tid 930053] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzrwAAAMk"]
[Mon Jul 20 06:28:08.488033 2026] [security2:error] [pid 925208:tid 925385] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9yQAAAC8"]
[Mon Jul 20 06:28:08.531816 2026] [security2:error] [pid 925208:tid 925297] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "omenana.com"] [uri "/.env"] [unique_id "al4UWMRX7OrFkv0FyuI93AAAV1g"]
[Mon Jul 20 06:28:08.554695 2026] [security2:error] [pid 929851:tid 930101] [client 34.73.38.214:63240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UWGV3ou772CelrLhzyQAAAPk"]
[Mon Jul 20 06:28:08.575621 2026] [security2:error] [pid 925208:tid 925364] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9zwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:08.725362 2026] [security2:error] [pid 929851:tid 930027] [client 57.141.18.25:29206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzAwAAr3s"]
[Mon Jul 20 06:28:08.738386 2026] [security2:error] [pid 925208:tid 925323] [remote 130.51.180.8:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UWMRX7OrFkv0FyuI95gAAJnI"]
[Mon Jul 20 06:28:08.747120 2026] [security2:error] [pid 929851:tid 930004] [client 14.225.17.146:64124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhz0AAAAJg"], referer: http://nextlvlmarketingco.com/old
[Mon Jul 20 06:28:08.838420 2026] [security2:error] [pid 925208:tid 925452] [client 57.141.18.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI9vwAAAHI"]
[Mon Jul 20 06:28:08.865009 2026] [security2:error] [pid 925208:tid 925281] [remote 20.173.88.122:35016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UWMRX7OrFkv0FyuI97AAAP0g"]
[Mon Jul 20 06:28:08.865162 2026] [security2:error] [pid 925208:tid 925401] [client 20.173.88.122:35016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UWMRX7OrFkv0FyuI97AAAP0g"]
[Mon Jul 20 06:28:08.906458 2026] [fcgid:warn] [pid 929851:tid 930007] (70014)End of file found: [client 91.230.168.151:48411] mod_fcgid: can't get data from http client
[Mon Jul 20 06:28:08.910681 2026] [security2:error] [pid 929851:tid 929940] [remote 160.187.68.132:34022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UWGV3ou772CelrLhz3QAAx1Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:08.940712 2026] [security2:error] [pid 925208:tid 925231] [remote 130.51.180.8:53490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UWMRX7OrFkv0FyuI98gAAShY"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:08.944024 2026] [security2:error] [pid 929851:tid 930084] [client 57.141.18.55:39694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzEwAA6Gw"]
[Mon Jul 20 06:28:09.143285 2026] [security2:error] [pid 929851:tid 930109] [client 14.225.17.146:57104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhz3wAAAQE"], referer: https://nwcarvingacademy.com/old
[Mon Jul 20 06:28:09.182733 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.33:53560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UVWV3ou772CelrLhzIgAAzyc"]
[Mon Jul 20 06:28:09.207129 2026] [security2:error] [pid 929851:tid 930026] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzyAAAAK4"]
[Mon Jul 20 06:28:09.296179 2026] [security2:error] [pid 929851:tid 930038] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzywAAALo"]
[Mon Jul 20 06:28:09.303974 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:23069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UWcRX7OrFkv0FyuI-BAAAAB8"]
[Mon Jul 20 06:28:09.304088 2026] [security2:error] [pid 925208:tid 925369] [client 223.185.13.213:23069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UWcRX7OrFkv0FyuI-BAAAAB8"]
[Mon Jul 20 06:28:09.313208 2026] [security2:error] [pid 929851:tid 929985] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWGV3ou772CelrLhzzgAAAIU"]
[Mon Jul 20 06:28:09.330208 2026] [security2:error] [pid 929851:tid 930053] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWWV3ou772CelrLhz6wAAAMk"]
[Mon Jul 20 06:28:09.345843 2026] [security2:error] [pid 925208:tid 925438] [client 34.73.38.214:62618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UWcRX7OrFkv0FyuI-CAAAAGQ"]
[Mon Jul 20 06:28:09.456019 2026] [security2:error] [pid 925208:tid 925368] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI93QAAAB4"]
[Mon Jul 20 06:28:09.508288 2026] [security2:error] [pid 925208:tid 925365] [client 158.173.89.95:54427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UWcRX7OrFkv0FyuI-EQAAABs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:09.662683 2026] [security2:error] [pid 929851:tid 929899] [remote 45.150.79.142:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UWWV3ou772CelrLh0CAAA5is"]
[Mon Jul 20 06:28:09.823302 2026] [security2:error] [pid 929851:tid 929898] [remote 45.150.79.142:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UWWV3ou772CelrLh0EgAAlCo"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:28:09.860025 2026] [security2:error] [pid 925208:tid 925417] [client 14.164.183.65:47910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4UWcRX7OrFkv0FyuI-FQAAAE8"]
[Mon Jul 20 06:28:09.950867 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWWV3ou772CelrLh0CwAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:10.007185 2026] [security2:error] [pid 925208:tid 925274] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "omenana.com"] [uri "/.env.local"] [unique_id "al4UWsRX7OrFkv0FyuI-HgAALUE"]
[Mon Jul 20 06:28:10.063288 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWmV3ou772CelrLh0GAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:10.063394 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UWmV3ou772CelrLh0GAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:10.157409 2026] [security2:error] [pid 925208:tid 925432] [client 14.225.17.146:64039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4UWMRX7OrFkv0FyuI94wAAAF4"], referer: http://tntcatholic.com/old
[Mon Jul 20 06:28:10.373264 2026] [security2:error] [pid 929851:tid 930026] [client 198.13.214.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4UWmV3ou772CelrLh0GwAArlg"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91singularity-studio-escala-1-4-malenia/
[Mon Jul 20 06:28:10.520714 2026] [security2:error] [pid 929851:tid 930010] [client 51.158.58.168:57890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4UWmV3ou772CelrLh0NwAAAJ4"]
[Mon Jul 20 06:28:10.659916 2026] [security2:error] [pid 925208:tid 925461] [client 34.74.185.202:62873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UWsRX7OrFkv0FyuI-PwAAAHs"]
[Mon Jul 20 06:28:10.675663 2026] [security2:error] [pid 929851:tid 930112] [client 57.141.18.121:37380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UV2V3ou772CelrLhzdgABBA8"]
[Mon Jul 20 06:28:10.689033 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWmV3ou772CelrLh0MgAAAIY"]
[Mon Jul 20 06:28:10.698259 2026] [security2:error] [pid 925208:tid 925259] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.env.old"] [unique_id "al4UWsRX7OrFkv0FyuI-QQAAaTI"]
[Mon Jul 20 06:28:10.698265 2026] [security2:error] [pid 925208:tid 925245] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.env.backup"] [unique_id "al4UWsRX7OrFkv0FyuI-QgAAaSQ"]
[Mon Jul 20 06:28:10.698272 2026] [security2:error] [pid 925208:tid 925215] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.env.bak"] [unique_id "al4UWsRX7OrFkv0FyuI-QwAAaQY"]
[Mon Jul 20 06:28:10.700326 2026] [security2:error] [pid 925208:tid 925236] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/backend/.env"] [unique_id "al4UWsRX7OrFkv0FyuI-RQAAaRs"]
[Mon Jul 20 06:28:10.700450 2026] [security2:error] [pid 925208:tid 925270] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/api/.env"] [unique_id "al4UWsRX7OrFkv0FyuI-RgAAaT0"]
[Mon Jul 20 06:28:10.975771 2026] [security2:error] [pid 929851:tid 930078] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UWmV3ou772CelrLh0PQAAAOI"]
[Mon Jul 20 06:28:11.062776 2026] [security2:error] [pid 925208:tid 925413] [client 57.141.18.109:54274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UV8RX7OrFkv0FyuI9pAAASzM"]
[Mon Jul 20 06:28:11.113183 2026] [security2:error] [pid 929851:tid 930024] [client 171.60.139.123:63148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UW2V3ou772CelrLh0SgAAAKw"]
[Mon Jul 20 06:28:11.113376 2026] [security2:error] [pid 929851:tid 930024] [client 171.60.139.123:63148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UW2V3ou772CelrLh0SgAAAKw"]
[Mon Jul 20 06:28:11.127347 2026] [security2:error] [pid 925208:tid 925373] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UWsRX7OrFkv0FyuI-VgAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:11.276671 2026] [security2:error] [pid 929851:tid 930022] [client 34.73.38.214:62951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UW2V3ou772CelrLh0UAAAAKo"]
[Mon Jul 20 06:28:11.281999 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UW8RX7OrFkv0FyuI-YwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:11.282092 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UW8RX7OrFkv0FyuI-YwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:11.287579 2026] [security2:error] [pid 925208:tid 925251] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/config/.env"] [unique_id "al4UW8RX7OrFkv0FyuI-ZQAADio"]
[Mon Jul 20 06:28:11.547197 2026] [security2:error] [pid 925208:tid 925447] [client 34.74.185.202:60180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UW8RX7OrFkv0FyuI-cgAAAG0"]
[Mon Jul 20 06:28:11.589209 2026] [security2:error] [pid 925208:tid 925377] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UW8RX7OrFkv0FyuI-aAAAACc"]
[Mon Jul 20 06:28:12.097293 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXGV3ou772CelrLh0eAAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.097402 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXGV3ou772CelrLh0eAAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.154348 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:63375] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 218 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UXGV3ou772CelrLh0fgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.308369 2026] [security2:error] [pid 925208:tid 925419] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXMRX7OrFkv0FyuI-hAAAAFE"]
[Mon Jul 20 06:28:12.308968 2026] [security2:error] [pid 929851:tid 929973] [remote 72.167.132.114:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4UXGV3ou772CelrLh0jgAAyHU"]
[Mon Jul 20 06:28:12.329451 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:63433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXMRX7OrFkv0FyuI-kgAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.329585 2026] [security2:error] [pid 925208:tid 925389] [client 77.110.127.138:63433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXMRX7OrFkv0FyuI-kgAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:12.442266 2026] [security2:error] [pid 925208:tid 925413] [client 103.141.108.143:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UXMRX7OrFkv0FyuI-mQAAAEs"]
[Mon Jul 20 06:28:12.442961 2026] [security2:error] [pid 925208:tid 925413] [client 103.141.108.143:54323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UXMRX7OrFkv0FyuI-mQAAAEs"]
[Mon Jul 20 06:28:12.466197 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:55485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UXGV3ou772CelrLh0lQAAAMU"]
[Mon Jul 20 06:28:12.466306 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:55485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UXGV3ou772CelrLh0lQAAAMU"]
[Mon Jul 20 06:28:12.514243 2026] [security2:error] [pid 929851:tid 929971] [remote 72.167.132.114:42732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4UXGV3ou772CelrLh0lgAA2nM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:28:12.694106 2026] [security2:error] [pid 929851:tid 930093] [client 104.234.53.73:34635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UXGV3ou772CelrLh0oAAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:13.014728 2026] [security2:error] [pid 929851:tid 930100] [client 39.48.81.23:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UXWV3ou772CelrLh0rQAAAPg"]
[Mon Jul 20 06:28:13.014891 2026] [security2:error] [pid 929851:tid 930100] [client 39.48.81.23:54374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UXWV3ou772CelrLh0rQAAAPg"]
[Mon Jul 20 06:28:13.256905 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-uQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:13.283290 2026] [security2:error] [pid 929851:tid 930089] [client 34.73.38.214:52187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UXWV3ou772CelrLh0ugAAAO0"]
[Mon Jul 20 06:28:13.308234 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXWV3ou772CelrLh0uwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:13.308340 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXWV3ou772CelrLh0uwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:13.328887 2026] [security2:error] [pid 929851:tid 930108] [client 14.225.17.146:54427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4UXWV3ou772CelrLh0tAAAAQA"], referer: http://myspineworld.com/old
[Mon Jul 20 06:28:13.348392 2026] [security2:error] [pid 929851:tid 930000] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXWV3ou772CelrLh0sgAAAJQ"]
[Mon Jul 20 06:28:13.349257 2026] [security2:error] [pid 925208:tid 925412] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-wwAAAEo"]
[Mon Jul 20 06:28:13.705529 2026] [security2:error] [pid 925208:tid 925340] [client 34.74.185.202:62176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UXcRX7OrFkv0FyuI-5gAAAAI"]
[Mon Jul 20 06:28:13.831801 2026] [security2:error] [pid 925208:tid 925358] [client 119.157.66.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4UXMRX7OrFkv0FyuI-mgAAABQ"]
[Mon Jul 20 06:28:13.843233 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:13.843270 2026] [proxy_http:error] [pid 925208:tid 925405] [client 205.210.31.23:62750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:13.843920 2026] [proxy:error] [pid 925208:tid 925405] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:13.843950 2026] [proxy_http:error] [pid 925208:tid 925405] [client 205.210.31.23:62750] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:13.910986 2026] [security2:error] [pid 925208:tid 925434] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northplating.com"] [uri "/.well-known/about.php"] [unique_id "al4UXcRX7OrFkv0FyuI-9AAAAGA"]
[Mon Jul 20 06:28:13.911071 2026] [security2:error] [pid 925208:tid 925434] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "northplating.com"] [uri "/.well-known/about.php"] [unique_id "al4UXcRX7OrFkv0FyuI-9AAAAGA"]
[Mon Jul 20 06:28:13.958429 2026] [security2:error] [pid 925208:tid 925351] [client 34.73.38.214:53385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UXcRX7OrFkv0FyuI-9gAAAA0"]
[Mon Jul 20 06:28:13.994456 2026] [security2:error] [pid 929851:tid 930061] [client 77.110.127.138:63397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 833 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UXWV3ou772CelrLh0xwAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.163224 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXmV3ou772CelrLh01AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.163311 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:63443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXmV3ou772CelrLh01AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.213381 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:63407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXsRX7OrFkv0FyuI-_AAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.213488 2026] [security2:error] [pid 925208:tid 925433] [client 77.110.127.138:63407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UXsRX7OrFkv0FyuI-_AAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:14.259902 2026] [security2:error] [pid 925208:tid 925252] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/.ssh/id_ed25519"] [unique_id "al4UXsRX7OrFkv0FyuI_BQAAECs"]
[Mon Jul 20 06:28:14.261455 2026] [security2:error] [pid 925208:tid 925228] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.ssh/id_rsa"] [unique_id "al4UXsRX7OrFkv0FyuI_AgAAEBM"]
[Mon Jul 20 06:28:14.285733 2026] [authz_core:error] [pid 929851:tid 929993] [client 34.24.141.69:0] AH01630: client denied by server configuration: /home1/omenanac/public_html/.htpasswd
[Mon Jul 20 06:28:14.291492 2026] [security2:error] [pid 925208:tid 925342] [client 57.141.18.5:43360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UWsRX7OrFkv0FyuI-WQAABCE"]
[Mon Jul 20 06:28:14.310528 2026] [security2:error] [pid 929851:tid 930093] [client 65.1.132.125:53292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UXmV3ou772CelrLh08QAAAPE"]
[Mon Jul 20 06:28:14.366310 2026] [security2:error] [pid 929851:tid 930010] [client 34.74.185.202:59857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UXmV3ou772CelrLh08wAAAJ4"]
[Mon Jul 20 06:28:14.394361 2026] [security2:error] [pid 925208:tid 925430] [client 14.225.17.146:49402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4UXsRX7OrFkv0FyuI-_QAAAFw"], referer: https://myspineworld.com/old
[Mon Jul 20 06:28:14.523487 2026] [security2:error] [pid 929851:tid 930104] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh06AAAAPw"]
[Mon Jul 20 06:28:14.523519 2026] [security2:error] [pid 929851:tid 930042] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh06QAAAL4"]
[Mon Jul 20 06:28:14.566924 2026] [security2:error] [pid 929851:tid 929985] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh06wAAAIU"]
[Mon Jul 20 06:28:14.593551 2026] [security2:error] [pid 929851:tid 930067] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh07AAAANc"]
[Mon Jul 20 06:28:14.630296 2026] [security2:error] [pid 929851:tid 930062] [client 104.234.53.81:42443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UXmV3ou772CelrLh0-AAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:14.886897 2026] [security2:error] [pid 929851:tid 930105] [client 14.225.17.146:65529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh03QAAAP0"]
[Mon Jul 20 06:28:15.075309 2026] [security2:error] [pid 929851:tid 930041] [client 171.61.165.146:15048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UX2V3ou772CelrLh1DgAAAL0"]
[Mon Jul 20 06:28:15.078006 2026] [security2:error] [pid 925208:tid 925336] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/id_dsa"] [unique_id "al4UX8RX7OrFkv0FyuI_LgAAH38"]
[Mon Jul 20 06:28:15.081657 2026] [security2:error] [pid 929851:tid 930041] [client 171.61.165.146:15048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UX2V3ou772CelrLh1DgAAAL0"]
[Mon Jul 20 06:28:15.171529 2026] [security2:error] [pid 929851:tid 930110] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UXmV3ou772CelrLh1CwAAAQI"]
[Mon Jul 20 06:28:15.200127 2026] [security2:error] [pid 925208:tid 925305] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/.ssh/known_hosts"] [unique_id "al4UX8RX7OrFkv0FyuI_NQAAFmA"]
[Mon Jul 20 06:28:15.201825 2026] [security2:error] [pid 925208:tid 925286] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/id_rsa"] [unique_id "al4UX8RX7OrFkv0FyuI_NwAAFk0"]
[Mon Jul 20 06:28:15.201825 2026] [security2:error] [pid 925208:tid 925260] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.ssh/id_dsa"] [unique_id "al4UX8RX7OrFkv0FyuI_NgAAFjM"]
[Mon Jul 20 06:28:15.278780 2026] [security2:error] [pid 929851:tid 930093] [client 13.201.64.214:27596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UX2V3ou772CelrLh1GwAAAPE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:28:15.439892 2026] [security2:error] [pid 929851:tid 930042] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1FgAAAL4"]
[Mon Jul 20 06:28:15.458256 2026] [security2:error] [pid 929851:tid 930104] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1FwAAAPw"]
[Mon Jul 20 06:28:15.460280 2026] [security2:error] [pid 929851:tid 930107] [client 34.73.38.214:64666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UX2V3ou772CelrLh1KwAAAP8"]
[Mon Jul 20 06:28:15.462194 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:15.462262 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:51425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:15.462706 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:15.462755 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:51425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:15.542711 2026] [security2:error] [pid 925208:tid 925392] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UX8RX7OrFkv0FyuI_QAAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:15.595185 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:63427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UX8RX7OrFkv0FyuI_SAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:15.595298 2026] [security2:error] [pid 925208:tid 925390] [client 77.110.127.138:63427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UX8RX7OrFkv0FyuI_SAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:15.652250 2026] [security2:error] [pid 925208:tid 925452] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UX8RX7OrFkv0FyuI_RQAAAHI"]
[Mon Jul 20 06:28:15.671293 2026] [security2:error] [pid 929851:tid 930111] [client 34.74.185.202:60307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UX2V3ou772CelrLh1QAAAAQM"]
[Mon Jul 20 06:28:15.740672 2026] [security2:error] [pid 929851:tid 930060] [client 57.141.18.49:38542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXGV3ou772CelrLh0iwAA0G8"]
[Mon Jul 20 06:28:15.781895 2026] [security2:error] [pid 925208:tid 925351] [client 14.225.17.146:49852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4UX8RX7OrFkv0FyuI_PAAAAA0"]
[Mon Jul 20 06:28:15.865197 2026] [security2:error] [pid 929851:tid 930015] [client 14.225.17.146:65356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1RgAAAKM"], referer: http://lutheranphilosopher.com/old
[Mon Jul 20 06:28:16.022847 2026] [security2:error] [pid 925208:tid 925371] [client 57.141.18.124:39056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXMRX7OrFkv0FyuI-nAAAIXE"]
[Mon Jul 20 06:28:16.201996 2026] [security2:error] [pid 929851:tid 930104] [client 34.74.185.202:57955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UYGV3ou772CelrLh1WAAAAPw"]
[Mon Jul 20 06:28:16.220214 2026] [security2:error] [pid 925208:tid 925377] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_ZQAAACc"]
[Mon Jul 20 06:28:16.232554 2026] [security2:error] [pid 925208:tid 925415] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_ZAAAAE0"]
[Mon Jul 20 06:28:16.295285 2026] [security2:error] [pid 929851:tid 929985] [client 77.110.127.138:63375] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 511 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UYGV3ou772CelrLh1XQAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.386044 2026] [security2:error] [pid 929851:tid 930102] [client 37.140.192.175:45154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4UX2V3ou772CelrLh1TwAAAPo"]
[Mon Jul 20 06:28:16.647258 2026] [security2:error] [pid 929851:tid 929975] [remote 173.249.4.11:33965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4UYGV3ou772CelrLh1awAAjHc"]
[Mon Jul 20 06:28:16.696061 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:63455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYGV3ou772CelrLh1bwAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.696180 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:63455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYGV3ou772CelrLh1bwAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.740272 2026] [security2:error] [pid 925208:tid 925411] [client 57.141.18.59:45746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-zgAASTw"]
[Mon Jul 20 06:28:16.745801 2026] [security2:error] [pid 925208:tid 925363] [client 47.128.96.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_eAAAABk"]
[Mon Jul 20 06:28:16.767220 2026] [security2:error] [pid 929851:tid 930002] [client 98.159.234.160:20351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UYGV3ou772CelrLh1cAAAAJY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:16.926572 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYMRX7OrFkv0FyuI_jwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:16.926697 2026] [security2:error] [pid 925208:tid 925380] [client 77.110.127.138:63457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYMRX7OrFkv0FyuI_jwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:17.055444 2026] [security2:error] [pid 925208:tid 925425] [client 57.141.18.34:45874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UXcRX7OrFkv0FyuI-2gAAV0Y"]
[Mon Jul 20 06:28:17.186005 2026] [security2:error] [pid 925208:tid 925360] [client 14.225.17.146:65378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4UYcRX7OrFkv0FyuI_kgAAABY"], referer: http://ccsdifference.com/old
[Mon Jul 20 06:28:17.213136 2026] [security2:error] [pid 925208:tid 925313] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/privatekey.key"] [unique_id "al4UYcRX7OrFkv0FyuI_nwAAIWg"]
[Mon Jul 20 06:28:17.213136 2026] [security2:error] [pid 925208:tid 925307] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/key.pem"] [unique_id "al4UYcRX7OrFkv0FyuI_oAAAIWI"]
[Mon Jul 20 06:28:17.229544 2026] [security2:error] [pid 929851:tid 929862] [remote 173.249.4.11:33965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4UYWV3ou772CelrLh1hgAA5QY"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 06:28:17.341184 2026] [security2:error] [pid 929851:tid 929878] [remote 217.61.143.92:41500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1kwAA_xY"]
[Mon Jul 20 06:28:17.341339 2026] [security2:error] [pid 929851:tid 930107] [client 217.61.143.92:41500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1kwAA_xY"]
[Mon Jul 20 06:28:17.350827 2026] [security2:error] [pid 929851:tid 929989] [client 106.219.188.178:25948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1lQAAAIk"]
[Mon Jul 20 06:28:17.351002 2026] [security2:error] [pid 929851:tid 929989] [client 106.219.188.178:25948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UYWV3ou772CelrLh1lQAAAIk"]
[Mon Jul 20 06:28:17.367588 2026] [security2:error] [pid 925208:tid 925422] [client 65.111.24.142:30929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UYcRX7OrFkv0FyuI_pwAAAFQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:17.448234 2026] [security2:error] [pid 925208:tid 925352] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYcRX7OrFkv0FyuI_ngAAAA4"]
[Mon Jul 20 06:28:17.462550 2026] [security2:error] [pid 929851:tid 930089] [client 34.74.185.202:57378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UYWV3ou772CelrLh1nAAAAO0"]
[Mon Jul 20 06:28:17.472308 2026] [security2:error] [pid 929851:tid 930082] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/public../.env"] [unique_id "al4UYWV3ou772CelrLh1nQAAAOY"], referer: https://duckduckgo.com/?q=05mxa
[Mon Jul 20 06:28:17.501637 2026] [security2:error] [pid 929851:tid 929997] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1igAAAJE"]
[Mon Jul 20 06:28:17.529498 2026] [security2:error] [pid 929851:tid 930105] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1iwAAAP0"]
[Mon Jul 20 06:28:17.547746 2026] [security2:error] [pid 929851:tid 930004] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1jAAAAJg"]
[Mon Jul 20 06:28:17.563019 2026] [security2:error] [pid 929851:tid 930054] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UYWV3ou772CelrLh1jQAAAMo"]
[Mon Jul 20 06:28:17.653437 2026] [security2:error] [pid 929851:tid 929885] [remote 103.161.172.221:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UYWV3ou772CelrLh1oQAAsR0"]
[Mon Jul 20 06:28:17.767124 2026] [security2:error] [pid 929851:tid 930101] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/resources../.env"] [unique_id "al4UYWV3ou772CelrLh1rAAAAPk"], referer: https://www.facebook.com/
[Mon Jul 20 06:28:17.985807 2026] [security2:error] [pid 929851:tid 930090] [client 34.73.38.214:54381] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UYWV3ou772CelrLh1ugAAAO4"]
[Mon Jul 20 06:28:18.021084 2026] [security2:error] [pid 929851:tid 929988] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4UYmV3ou772CelrLh1wAAAAIg"], referer: https://www.google.com/
[Mon Jul 20 06:28:18.027045 2026] [security2:error] [pid 929851:tid 930087] [client 45.3.52.99:51483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UYmV3ou772CelrLh1vQAAAOs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:18.049344 2026] [security2:error] [pid 929851:tid 929926] [remote 103.161.172.221:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UYmV3ou772CelrLh1xAAAkUY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:28:18.128276 2026] [security2:error] [pid 929851:tid 930031] [client 216.73.216.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.slutilities.com"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh1vwAAALM"], referer: http://www.slutilities.com/sitemap.xml
[Mon Jul 20 06:28:18.135953 2026] [proxy:error] [pid 929851:tid 930084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.136024 2026] [proxy_http:error] [pid 929851:tid 930084] [client 34.73.38.214:59959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:18.136595 2026] [proxy:error] [pid 929851:tid 930084] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.136621 2026] [proxy_http:error] [pid 929851:tid 930084] [client 34.73.38.214:59959] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:18.235699 2026] [security2:error] [pid 929851:tid 930042] [client 14.225.17.146:49266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh1wwAAAL4"], referer: https://ccsdifference.com/old
[Mon Jul 20 06:28:18.292440 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYmV3ou772CelrLh10QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:18.292553 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UYmV3ou772CelrLh10QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:18.848743 2026] [security2:error] [pid 929851:tid 929996] [client 34.73.38.214:65352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UYmV3ou772CelrLh17gAAAJA"]
[Mon Jul 20 06:28:18.851298 2026] [proxy:error] [pid 929851:tid 930054] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.851381 2026] [proxy_http:error] [pid 929851:tid 930054] [client 34.73.38.214:52217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:18.852153 2026] [proxy:error] [pid 929851:tid 930054] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:18.852187 2026] [proxy_http:error] [pid 929851:tid 930054] [client 34.73.38.214:52217] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:19.230927 2026] [security2:error] [pid 925208:tid 925272] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.openclaw/.env"] [unique_id "al4UY8RX7OrFkv0FyuI_5AAAUz8"]
[Mon Jul 20 06:28:19.432190 2026] [security2:error] [pid 925208:tid 925334] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "omenana.com"] [uri "/.hermes/.env"] [unique_id "al4UY8RX7OrFkv0FyuI_7gAAUX0"]
[Mon Jul 20 06:28:19.444686 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:63478] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:noamp"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UY2V3ou772CelrLh2IAAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.607338 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:63480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2JgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.607453 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:63480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2JgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.660010 2026] [security2:error] [pid 929851:tid 930068] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2EwAAANg"]
[Mon Jul 20 06:28:19.674206 2026] [security2:error] [pid 929851:tid 930076] [client 14.225.17.146:60074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2KAAAAOA"], referer: http://grndl.com/old
[Mon Jul 20 06:28:19.714451 2026] [security2:error] [pid 929851:tid 930058] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2IQAAAM4"]
[Mon Jul 20 06:28:19.714772 2026] [security2:error] [pid 929851:tid 930029] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2IgAAALE"]
[Mon Jul 20 06:28:19.735007 2026] [security2:error] [pid 929851:tid 930089] [client 50.116.65.227:44172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4UY2V3ou772CelrLh2LwAAAO0"]
[Mon Jul 20 06:28:19.738436 2026] [security2:error] [pid 929851:tid 930009] [client 14.225.17.146:50164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh11AAAAJ0"]
[Mon Jul 20 06:28:19.795032 2026] [security2:error] [pid 929851:tid 930090] [client 34.73.38.214:54940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UY2V3ou772CelrLh2MgAAAO4"]
[Mon Jul 20 06:28:19.813586 2026] [security2:error] [pid 929851:tid 929998] [client 223.185.13.213:18992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UY2V3ou772CelrLh2NAAAAJI"]
[Mon Jul 20 06:28:19.813689 2026] [security2:error] [pid 929851:tid 929998] [client 223.185.13.213:18992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UY2V3ou772CelrLh2NAAAAJI"]
[Mon Jul 20 06:28:19.820471 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2NQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.820556 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UY2V3ou772CelrLh2NQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:19.891584 2026] [security2:error] [pid 925208:tid 925369] [client 57.141.18.8:48450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYMRX7OrFkv0FyuI_bwAAHyc"]
[Mon Jul 20 06:28:19.930457 2026] [security2:error] [pid 925208:tid 925259] [remote 47.86.33.52:22500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4UY8RX7OrFkv0FyuI_9wAAETI"]
[Mon Jul 20 06:28:20.019417 2026] [security2:error] [pid 929851:tid 930061] [client 112.208.70.94:44366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UZGV3ou772CelrLh2RwAAANE"]
[Mon Jul 20 06:28:20.019605 2026] [security2:error] [pid 929851:tid 930061] [client 112.208.70.94:44366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UZGV3ou772CelrLh2RwAAANE"]
[Mon Jul 20 06:28:20.133764 2026] [security2:error] [pid 925208:tid 925389] [client 34.74.185.202:56801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UZMRX7OrFkv0FyuI__AAAADM"]
[Mon Jul 20 06:28:20.171783 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:20.171849 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:64254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:20.173187 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:20.173237 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:64254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:20.196733 2026] [security2:error] [pid 929851:tid 930064] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2QgAAANQ"]
[Mon Jul 20 06:28:20.198806 2026] [security2:error] [pid 929851:tid 930052] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2RQAAAMg"]
[Mon Jul 20 06:28:20.323171 2026] [security2:error] [pid 929851:tid 929948] [remote 220.181.108.178:12247] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UZGV3ou772CelrLh2WQAAjFw"]
[Mon Jul 20 06:28:20.328734 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZMRX7OrFkv0FyuJACQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:20.329030 2026] [security2:error] [pid 925208:tid 925339] [client 77.110.127.138:63485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZMRX7OrFkv0FyuJACQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:20.454681 2026] [security2:error] [pid 929851:tid 930106] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UZGV3ou772CelrLh2UQAAAP4"]
[Mon Jul 20 06:28:20.527820 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.2:22030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYGV3ou772CelrLh1eQAAuSE"]
[Mon Jul 20 06:28:20.724793 2026] [security2:error] [pid 929851:tid 929896] [remote 78.46.157.202:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4UZGV3ou772CelrLh2dwAAnyg"]
[Mon Jul 20 06:28:20.755527 2026] [security2:error] [pid 929851:tid 930060] [client 216.73.216.123:5836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techexecutive.me"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2KQAA0A8"]
[Mon Jul 20 06:28:20.761603 2026] [security2:error] [pid 929851:tid 929983] [remote 47.86.33.52:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4UZGV3ou772CelrLh2eQAA238"]
[Mon Jul 20 06:28:20.807719 2026] [security2:error] [pid 925208:tid 925372] [client 57.141.18.26:47848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYcRX7OrFkv0FyuI_owAAImk"]
[Mon Jul 20 06:28:20.862883 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UZGV3ou772CelrLh2bgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:20.941933 2026] [security2:error] [pid 929851:tid 929945] [remote 78.46.157.202:44808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4UZGV3ou772CelrLh2fwAA1lk"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 06:28:21.107274 2026] [security2:error] [pid 925208:tid 925241] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omenana.com"] [uri "/graphql"] [unique_id "al4UZcRX7OrFkv0FyuJAKwAAeyA"]
[Mon Jul 20 06:28:21.159737 2026] [security2:error] [pid 925208:tid 925394] [client 34.74.185.202:56603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UZcRX7OrFkv0FyuJALgAAADg"]
[Mon Jul 20 06:28:21.160177 2026] [core:error] [pid 929851:tid 930110] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:21.160207 2026] [core:error] [pid 929851:tid 930110] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:21.265536 2026] [security2:error] [pid 929851:tid 930010] [client 34.73.38.214:57066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UZWV3ou772CelrLh2nwAAAJ4"]
[Mon Jul 20 06:28:21.388275 2026] [security2:error] [pid 929851:tid 929856] [remote 47.86.33.52:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4UZWV3ou772CelrLh2ogAAxgA"], referer: https://schuttfarms.com/wp-login.php
[Mon Jul 20 06:28:21.531170 2026] [security2:error] [pid 925208:tid 925335] [remote 81.173.115.7:43620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4UZcRX7OrFkv0FyuJAQAAARH4"]
[Mon Jul 20 06:28:21.726823 2026] [security2:error] [pid 925208:tid 925295] [remote 81.173.115.7:43620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4UZcRX7OrFkv0FyuJARAAAFVY"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:28:21.731373 2026] [security2:error] [pid 925208:tid 925381] [client 171.60.139.123:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UZcRX7OrFkv0FyuJARQAAACs"]
[Mon Jul 20 06:28:21.731489 2026] [security2:error] [pid 925208:tid 925381] [client 171.60.139.123:63660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UZcRX7OrFkv0FyuJARQAAACs"]
[Mon Jul 20 06:28:21.819274 2026] [security2:error] [pid 929851:tid 930008] [client 14.188.210.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4UZWV3ou772CelrLh2uAAAAJw"]
[Mon Jul 20 06:28:21.973782 2026] [security2:error] [pid 929851:tid 930095] [client 14.225.17.146:60084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2DwAAAPM"]
[Mon Jul 20 06:28:22.007192 2026] [security2:error] [pid 925208:tid 925422] [client 34.73.38.214:61452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UZsRX7OrFkv0FyuJASgAAAFQ"]
[Mon Jul 20 06:28:22.039939 2026] [security2:error] [pid 925208:tid 925420] [client 34.74.185.202:59056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UZsRX7OrFkv0FyuJATQAAAFI"]
[Mon Jul 20 06:28:22.241340 2026] [security2:error] [pid 925208:tid 925399] [client 77.110.127.138:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZsRX7OrFkv0FyuJAVgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:22.241474 2026] [security2:error] [pid 925208:tid 925399] [client 77.110.127.138:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZsRX7OrFkv0FyuJAVgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:22.250282 2026] [security2:error] [pid 929851:tid 930087] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env"] [unique_id "al4UZmV3ou772CelrLh20wAAAOs"], referer: https://www.facebook.com/
[Mon Jul 20 06:28:22.266240 2026] [security2:error] [pid 929851:tid 930096] [client 14.225.17.146:50164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4UZWV3ou772CelrLh2wgAAAPQ"], referer: http://www.justinagrayman.com/old
[Mon Jul 20 06:28:22.498562 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.118:33142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UYmV3ou772CelrLh18QAAlmw"]
[Mon Jul 20 06:28:22.776241 2026] [security2:error] [pid 925208:tid 925266] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omenana.com"] [uri "/api/graphql"] [unique_id "al4UZsRX7OrFkv0FyuJAZwAAbDk"]
[Mon Jul 20 06:28:22.818100 2026] [security2:error] [pid 929851:tid 929981] [remote 111.225.214.197:63434] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UZmV3ou772CelrLh29AABAH0"]
[Mon Jul 20 06:28:23.032583 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:49326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4UZmV3ou772CelrLh28wAAAO4"], referer: http://falconarrowshop.com/old
[Mon Jul 20 06:28:23.050481 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4UZ2V3ou772CelrLh3BQAAAIs"]
[Mon Jul 20 06:28:23.105006 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3CwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.105128 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3CwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.137906 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:56011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3DQAAAPk"]
[Mon Jul 20 06:28:23.137988 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:56011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3DQAAAPk"]
[Mon Jul 20 06:28:23.152945 2026] [security2:error] [pid 929851:tid 930046] [client 57.141.18.8:57416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UY2V3ou772CelrLh2JAAAwlg"]
[Mon Jul 20 06:28:23.167014 2026] [security2:error] [pid 929851:tid 930040] [client 103.141.108.143:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3EAAAALw"]
[Mon Jul 20 06:28:23.167643 2026] [security2:error] [pid 929851:tid 930040] [client 103.141.108.143:54806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3EAAAALw"]
[Mon Jul 20 06:28:23.267252 2026] [security2:error] [pid 929851:tid 929867] [remote 217.61.143.92:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UZ2V3ou772CelrLh3GAAA9Qs"]
[Mon Jul 20 06:28:23.411662 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3HQAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.411758 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UZ2V3ou772CelrLh3HQAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.512391 2026] [security2:error] [pid 929851:tid 929901] [remote 217.61.143.92:41514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4UZ2V3ou772CelrLh3JAAAii0"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:28:23.558152 2026] [security2:error] [pid 929851:tid 929996] [client 40.77.167.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nyradigitalsolutions.com"] [uri "/index.php"] [unique_id "al4UZmV3ou772CelrLh23QAAkGo"]
[Mon Jul 20 06:28:23.572258 2026] [security2:error] [pid 925208:tid 925339] [client 103.153.183.69:59348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../etc/ssh/sshd_config"] [unique_id "al4UZ8RX7OrFkv0FyuJAhAAAAAE"], referer: https://www.reddit.com/
[Mon Jul 20 06:28:23.573647 2026] [security2:error] [pid 925208:tid 925349] [client 34.24.141.69:39210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UZ8RX7OrFkv0FyuJAeQAAC2I"]
[Mon Jul 20 06:28:23.749507 2026] [security2:error] [pid 929851:tid 930101] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4UZ2V3ou772CelrLh3OQAAAPk"], referer: https://twitter.com/
[Mon Jul 20 06:28:23.756335 2026] [security2:error] [pid 929851:tid 930031] [client 216.73.217.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3NQAAALM"]
[Mon Jul 20 06:28:23.775015 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3LgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:23.775443 2026] [security2:error] [pid 929851:tid 929997] [client 14.225.17.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3NgAAAJE"], referer: http://daseighty.net/old
[Mon Jul 20 06:28:23.800471 2026] [security2:error] [pid 929851:tid 930060] [client 39.48.81.23:54852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3PQAAANA"]
[Mon Jul 20 06:28:23.800568 2026] [security2:error] [pid 929851:tid 930060] [client 39.48.81.23:54852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UZ2V3ou772CelrLh3PQAAANA"]
[Mon Jul 20 06:28:24.120000 2026] [security2:error] [pid 925208:tid 925407] [client 34.74.185.202:55124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UaMRX7OrFkv0FyuJAlwAAAEU"]
[Mon Jul 20 06:28:24.120148 2026] [security2:error] [pid 929851:tid 930085] [client 57.141.18.9:40202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZGV3ou772CelrLh2XgAA6U8"]
[Mon Jul 20 06:28:24.246158 2026] [security2:error] [pid 925208:tid 925294] [remote 173.249.4.11:14374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4UaMRX7OrFkv0FyuJAnAAAcVU"]
[Mon Jul 20 06:28:24.246326 2026] [security2:error] [pid 925208:tid 925451] [client 173.249.4.11:14374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4UaMRX7OrFkv0FyuJAnAAAcVU"]
[Mon Jul 20 06:28:24.255942 2026] [security2:error] [pid 929851:tid 930075] [client 34.73.38.214:49702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UaGV3ou772CelrLh3UgAAAN8"]
[Mon Jul 20 06:28:24.258294 2026] [security2:error] [pid 929851:tid 930026] [client 34.73.38.214:49775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UaGV3ou772CelrLh3VAAAAK4"]
[Mon Jul 20 06:28:24.324964 2026] [security2:error] [pid 925208:tid 925439] [client 57.141.18.52:57226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZMRX7OrFkv0FyuJAGgAAZSY"]
[Mon Jul 20 06:28:24.354756 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaGV3ou772CelrLh3WwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:24.354841 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:63515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaGV3ou772CelrLh3WwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:24.426988 2026] [security2:error] [pid 929851:tid 929937] [remote 111.225.214.164:49451] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UaGV3ou772CelrLh3YAAAsFE"]
[Mon Jul 20 06:28:24.550411 2026] [security2:error] [pid 925208:tid 925277] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omenana.com"] [uri "/v1/graphql"] [unique_id "al4UaMRX7OrFkv0FyuJApQAAVUQ"]
[Mon Jul 20 06:28:24.773076 2026] [security2:error] [pid 925208:tid 925378] [client 34.74.185.202:53630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UaMRX7OrFkv0FyuJAqAAAACg"]
[Mon Jul 20 06:28:25.036227 2026] [security2:error] [pid 929851:tid 930078] [client 34.73.38.214:50642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eliteeventsleaders.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UaWV3ou772CelrLh3hAAAAOI"]
[Mon Jul 20 06:28:25.046517 2026] [security2:error] [pid 929851:tid 930087] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/.env"] [unique_id "al4UaWV3ou772CelrLh3hgAAAOs"], referer: https://duckduckgo.com/?q=12m6t
[Mon Jul 20 06:28:25.070160 2026] [security2:error] [pid 929851:tid 930048] [client 34.73.38.214:61593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UaWV3ou772CelrLh3iQAAAMQ"]
[Mon Jul 20 06:28:25.119808 2026] [security2:error] [pid 929851:tid 930010] [client 103.153.183.69:1718] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4UaWV3ou772CelrLh3jQAAAJ4"], referer: https://t.co/2r7sg09vqt
[Mon Jul 20 06:28:25.337848 2026] [security2:error] [pid 929851:tid 930101] [client 34.74.185.202:59055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jennylouraya.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UaWV3ou772CelrLh3lwAAAPk"]
[Mon Jul 20 06:28:25.367595 2026] [security2:error] [pid 929851:tid 929998] [client 50.116.65.227:30680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UaWV3ou772CelrLh3mwAAAJI"]
[Mon Jul 20 06:28:25.378623 2026] [security2:error] [pid 925208:tid 925342] [client 50.116.65.227:30690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UacRX7OrFkv0FyuJAuwAAAAQ"]
[Mon Jul 20 06:28:25.543975 2026] [security2:error] [pid 925208:tid 925408] [client 14.225.17.146:53705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4UacRX7OrFkv0FyuJAtgAAAEY"], referer: http://adastra.love/old
[Mon Jul 20 06:28:25.671575 2026] [security2:error] [pid 925208:tid 925324] [remote 45.90.123.233:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4UacRX7OrFkv0FyuJAvgAAMXM"]
[Mon Jul 20 06:28:25.691713 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaWV3ou772CelrLh3qAAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:25.691839 2026] [security2:error] [pid 929851:tid 930081] [client 77.110.127.138:63493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UaWV3ou772CelrLh3qAAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:26.107130 2026] [security2:error] [pid 929851:tid 930096] [client 171.61.165.146:26594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh3wAAAAPQ"]
[Mon Jul 20 06:28:26.107237 2026] [security2:error] [pid 929851:tid 930096] [client 171.61.165.146:26594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh3wAAAAPQ"]
[Mon Jul 20 06:28:26.306966 2026] [security2:error] [pid 929851:tid 930008] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.llr.lqn.mybluehost.me"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3vgAAAJw"]
[Mon Jul 20 06:28:26.319385 2026] [security2:error] [pid 929851:tid 930058] [client 34.73.38.214:57601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UamV3ou772CelrLh3zwAAAM4"]
[Mon Jul 20 06:28:26.343715 2026] [security2:error] [pid 929851:tid 930110] [client 57.141.18.59:62908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZmV3ou772CelrLh27gABAl8"]
[Mon Jul 20 06:28:26.368891 2026] [security2:error] [pid 929851:tid 929971] [remote 60.205.8.163:33486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.8.205.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh30wAA7XM"]
[Mon Jul 20 06:28:26.369146 2026] [security2:error] [pid 929851:tid 930089] [client 60.205.8.163:33486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UamV3ou772CelrLh30wAA7XM"]
[Mon Jul 20 06:28:26.384794 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:63526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UasRX7OrFkv0FyuJAzQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:26.384909 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:63526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UasRX7OrFkv0FyuJAzQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:26.704249 2026] [security2:error] [pid 925208:tid 925252] [remote 45.90.123.233:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4UasRX7OrFkv0FyuJA1QAAOSs"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:28:26.765618 2026] [security2:error] [pid 929851:tid 929915] [remote 173.249.4.11:21034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UamV3ou772CelrLh37QAAmjs"]
[Mon Jul 20 06:28:26.785527 2026] [security2:error] [pid 929851:tid 930061] [client 34.73.38.214:62472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UamV3ou772CelrLh38QAAANE"]
[Mon Jul 20 06:28:27.207860 2026] [security2:error] [pid 929851:tid 930007] [client 14.225.17.146:53553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4UaWV3ou772CelrLh3pwAAAJs"], referer: http://careysheatingandcooling.com/old
[Mon Jul 20 06:28:27.251888 2026] [security2:error] [pid 929851:tid 929986] [client 14.225.17.146:58790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3xAAAAIY"], referer: http://ncsynchro.com/old
[Mon Jul 20 06:28:27.309610 2026] [security2:error] [pid 929851:tid 930064] [client 57.141.18.24:42580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UZ2V3ou772CelrLh3OAAA1Dw"]
[Mon Jul 20 06:28:27.425947 2026] [security2:error] [pid 929851:tid 929893] [remote 173.249.4.11:21034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Ua2V3ou772CelrLh4IQAA0SU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:27.683567 2026] [security2:error] [pid 929851:tid 930056] [client 34.73.38.214:59868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Ua2V3ou772CelrLh4LwAAAMw"]
[Mon Jul 20 06:28:27.746400 2026] [security2:error] [pid 929851:tid 930051] [client 65.111.23.116:33011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Ua2V3ou772CelrLh4MgAAAMc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:27.866219 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.30:30900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UaGV3ou772CelrLh3WAAAzRg"]
[Mon Jul 20 06:28:27.934642 2026] [security2:error] [pid 929851:tid 930010] [client 104.234.53.64:36565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Ua2V3ou772CelrLh4PwAAAJ4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:28.046842 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.109:31254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UaGV3ou772CelrLh3YwAA2CQ"]
[Mon Jul 20 06:28:28.095782 2026] [security2:error] [pid 929851:tid 930024] [client 74.208.214.194:48908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UbGV3ou772CelrLh4RwAAAKw"]
[Mon Jul 20 06:28:28.190670 2026] [security2:error] [pid 929851:tid 930008] [client 14.225.17.146:60241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4QwAAAJw"], referer: http://backandneckpainrelieflaceychiropractor.com/old
[Mon Jul 20 06:28:28.198208 2026] [security2:error] [pid 929851:tid 930070] [client 57.141.18.91:54212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UaGV3ou772CelrLh3dgAA2j8"]
[Mon Jul 20 06:28:28.393273 2026] [security2:error] [pid 925208:tid 925363] [client 103.153.183.69:59348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../root/.ssh/id_rsa"] [unique_id "al4UbMRX7OrFkv0FyuJBBAAAABk"], referer: https://www.facebook.com/
[Mon Jul 20 06:28:28.501874 2026] [security2:error] [pid 929851:tid 930063] [client 34.73.38.214:59691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UbGV3ou772CelrLh4WwAAANM"]
[Mon Jul 20 06:28:28.515793 2026] [security2:error] [pid 929851:tid 930014] [client 106.219.188.178:25941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UbGV3ou772CelrLh4XQAAAKI"]
[Mon Jul 20 06:28:28.517376 2026] [security2:error] [pid 929851:tid 930014] [client 106.219.188.178:25941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UbGV3ou772CelrLh4XQAAAKI"]
[Mon Jul 20 06:28:28.518344 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4VQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:29.138781 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbWV3ou772CelrLh4egAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:29.138872 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:63551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbWV3ou772CelrLh4egAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:29.285741 2026] [security2:error] [pid 929851:tid 929994] [client 14.225.17.146:52931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4VgAAAI4"]
[Mon Jul 20 06:28:29.426538 2026] [ssl:error] [pid 925208:tid 925416] [client 104.48.69.105:37972] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:28:29.456852 2026] [security2:error] [pid 929851:tid 930013] [client 57.141.18.31:57758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3uwAAoUg"]
[Mon Jul 20 06:28:29.659293 2026] [security2:error] [pid 925208:tid 925397] [client 57.141.18.37:25902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UasRX7OrFkv0FyuJAygAAOwk"]
[Mon Jul 20 06:28:29.765060 2026] [security2:error] [pid 925208:tid 925390] [client 14.225.17.146:65120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4Ua8RX7OrFkv0FyuJA6gAAADQ"], referer: http://younutrition.gr/old
[Mon Jul 20 06:28:29.961385 2026] [proxy:error] [pid 929851:tid 930102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:29.961440 2026] [proxy_http:error] [pid 929851:tid 930102] [client 34.73.38.214:65458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:29.961994 2026] [proxy:error] [pid 929851:tid 930102] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:29.962020 2026] [proxy_http:error] [pid 929851:tid 930102] [client 34.73.38.214:65458] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.028652 2026] [proxy:error] [pid 925208:tid 925365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.028735 2026] [proxy_http:error] [pid 925208:tid 925365] [client 34.73.38.214:49195] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.029358 2026] [proxy:error] [pid 925208:tid 925365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.029389 2026] [proxy_http:error] [pid 925208:tid 925365] [client 34.73.38.214:49195] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.296695 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.55:32964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UamV3ou772CelrLh3-wAAzwA"]
[Mon Jul 20 06:28:30.450068 2026] [proxy:error] [pid 929851:tid 930050] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.450131 2026] [proxy_http:error] [pid 929851:tid 930050] [client 34.73.38.214:62881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.450572 2026] [proxy:error] [pid 929851:tid 930050] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:30.450601 2026] [proxy_http:error] [pid 929851:tid 930050] [client 34.73.38.214:62881] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:30.551298 2026] [security2:error] [pid 929851:tid 930013] [client 50.116.65.227:37266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4UbmV3ou772CelrLh4wAAAAKE"]
[Mon Jul 20 06:28:30.556406 2026] [security2:error] [pid 929851:tid 930087] [client 223.185.13.213:28863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UbmV3ou772CelrLh4wQAAAOs"]
[Mon Jul 20 06:28:30.556516 2026] [security2:error] [pid 929851:tid 930087] [client 223.185.13.213:28863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UbmV3ou772CelrLh4wQAAAOs"]
[Mon Jul 20 06:28:30.566658 2026] [security2:error] [pid 929851:tid 930081] [client 50.116.65.227:19982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4UbmV3ou772CelrLh4wgAAAOU"]
[Mon Jul 20 06:28:30.795804 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbmV3ou772CelrLh4ywAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:30.795949 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:63559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UbmV3ou772CelrLh4ywAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:30.958670 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:63560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UbsRX7OrFkv0FyuJBVgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.149182 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.80:28656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ua2V3ou772CelrLh4MQAAwXQ"]
[Mon Jul 20 06:28:31.210544 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:63563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh44gAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.210650 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:63563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh44gAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.406168 2026] [proxy:error] [pid 925208:tid 925411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.406229 2026] [proxy_http:error] [pid 925208:tid 925411] [client 34.73.38.214:59808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.406640 2026] [proxy:error] [pid 925208:tid 925411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.406664 2026] [proxy_http:error] [pid 925208:tid 925411] [client 34.73.38.214:59808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.484666 2026] [core:error] [pid 925208:tid 925367] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:31.484686 2026] [core:error] [pid 925208:tid 925367] [client 35.252.248.221:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:31.485681 2026] [security2:error] [pid 925208:tid 925280] [remote 47.86.33.52:39380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBawAAOUc"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:28:31.529162 2026] [proxy:error] [pid 929851:tid 930013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.529234 2026] [proxy_http:error] [pid 929851:tid 930013] [client 34.73.38.214:63897] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.529764 2026] [proxy:error] [pid 929851:tid 930013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:31.529789 2026] [proxy_http:error] [pid 929851:tid 930013] [client 34.73.38.214:63897] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:31.603048 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBdAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.603164 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBdAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.618701 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh48gAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.618819 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh48gAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.850087 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh5AgAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.850236 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ub2V3ou772CelrLh5AgAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:31.917840 2026] [security2:error] [pid 929851:tid 930084] [client 57.141.18.18:34242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbGV3ou772CelrLh4YAAA6C8"]
[Mon Jul 20 06:28:31.987341 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ub2V3ou772CelrLh4_AAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:32.007639 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5CgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:32.007735 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5CgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:32.012660 2026] [security2:error] [pid 929851:tid 930063] [client 104.234.53.68:22531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UcGV3ou772CelrLh5CQAAANM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:32.082935 2026] [security2:error] [pid 929851:tid 930067] [client 116.179.33.206:63990] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4UcGV3ou772CelrLh5DwAAANc"]
[Mon Jul 20 06:28:32.122709 2026] [security2:error] [pid 925208:tid 925392] [client 57.141.18.124:47200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbMRX7OrFkv0FyuJBEQAANkM"]
[Mon Jul 20 06:28:32.175958 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5GQAAAOM"]
[Mon Jul 20 06:28:32.176100 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5GQAAAOM"]
[Mon Jul 20 06:28:32.291692 2026] [security2:error] [pid 929851:tid 930071] [client 34.73.38.214:51691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UcGV3ou772CelrLh5IwAAANs"]
[Mon Jul 20 06:28:32.294559 2026] [security2:error] [pid 925208:tid 925359] [client 171.60.139.123:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UcMRX7OrFkv0FyuJBjgAAABU"]
[Mon Jul 20 06:28:32.294646 2026] [security2:error] [pid 925208:tid 925359] [client 171.60.139.123:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UcMRX7OrFkv0FyuJBjgAAABU"]
[Mon Jul 20 06:28:32.299995 2026] [proxy:error] [pid 929851:tid 930037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:32.300070 2026] [proxy_http:error] [pid 929851:tid 930037] [client 34.73.38.214:53121] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:32.300704 2026] [proxy:error] [pid 929851:tid 930037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:32.300739 2026] [proxy_http:error] [pid 929851:tid 930037] [client 34.73.38.214:53121] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:32.358888 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5KwAAAMs"]
[Mon Jul 20 06:28:32.359007 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcGV3ou772CelrLh5KwAAAMs"]
[Mon Jul 20 06:28:32.396948 2026] [security2:error] [pid 925208:tid 925346] [client 57.141.18.120:35180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbcRX7OrFkv0FyuJBGgAACB4"]
[Mon Jul 20 06:28:32.664207 2026] [security2:error] [pid 929851:tid 930104] [client 57.141.18.72:22122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbWV3ou772CelrLh4iwAA_Eo"]
[Mon Jul 20 06:28:32.815966 2026] [security2:error] [pid 925208:tid 925432] [client 57.141.18.114:33346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UbcRX7OrFkv0FyuJBMQAAXjM"]
[Mon Jul 20 06:28:33.119667 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:44752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5XgAAAM8"]
[Mon Jul 20 06:28:33.119780 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:44752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5XgAAAM8"]
[Mon Jul 20 06:28:33.177869 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UccRX7OrFkv0FyuJBqQAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.177960 2026] [security2:error] [pid 925208:tid 925395] [client 77.110.127.138:63585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UccRX7OrFkv0FyuJBqQAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.271110 2026] [proxy:error] [pid 925208:tid 925438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.271151 2026] [security2:error] [pid 929851:tid 930078] [client 34.73.38.214:63092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UcWV3ou772CelrLh5ZgAAAOI"]
[Mon Jul 20 06:28:33.271185 2026] [proxy_http:error] [pid 925208:tid 925438] [client 34.73.38.214:62941] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.271724 2026] [proxy:error] [pid 925208:tid 925438] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.271768 2026] [proxy_http:error] [pid 925208:tid 925438] [client 34.73.38.214:62941] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.274614 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.274664 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:63191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.275094 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.275119 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:63191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.334578 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5bgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.334660 2026] [security2:error] [pid 929851:tid 930034] [client 77.110.127.138:63588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5bgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.484597 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5gAAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.484694 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5gAAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.542077 2026] [proxy:error] [pid 925208:tid 925422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.542139 2026] [proxy_http:error] [pid 925208:tid 925422] [client 34.73.38.214:61182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.542779 2026] [proxy:error] [pid 925208:tid 925422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:33.542822 2026] [proxy_http:error] [pid 925208:tid 925422] [client 34.73.38.214:61182] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:33.672704 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5kAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.672813 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5kAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.819713 2026] [security2:error] [pid 929851:tid 930108] [client 45.116.69.230:56546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5nAAAAQA"]
[Mon Jul 20 06:28:33.819846 2026] [security2:error] [pid 929851:tid 930108] [client 45.116.69.230:56546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5nAAAAQA"]
[Mon Jul 20 06:28:33.871298 2026] [security2:error] [pid 929851:tid 930020] [client 14.225.17.146:65126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5kQAAAKg"], referer: http://nurturemarple.co.uk/old
[Mon Jul 20 06:28:33.874027 2026] [security2:error] [pid 929851:tid 930007] [client 34.73.38.214:63337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UcWV3ou772CelrLh5owAAAJs"]
[Mon Jul 20 06:28:33.884635 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5pQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.884729 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcWV3ou772CelrLh5pQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:33.896627 2026] [security2:error] [pid 929851:tid 930022] [client 103.141.108.143:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5pwAAAKo"]
[Mon Jul 20 06:28:33.896726 2026] [security2:error] [pid 929851:tid 930022] [client 103.141.108.143:55279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UcWV3ou772CelrLh5pwAAAKo"]
[Mon Jul 20 06:28:34.035513 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5sQAAAOo"]
[Mon Jul 20 06:28:34.035608 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:63594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5sQAAAOo"]
[Mon Jul 20 06:28:34.065841 2026] [security2:error] [pid 929851:tid 930052] [client 114.119.135.251:24313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aosta.nz"] [uri "/quality_auto/36a582_27c4844a2e464a7daa0e8da9b2905fa1~mv2.png"] [unique_id "al4UcmV3ou772CelrLh5tAAAAMg"], referer: https://www.aosta.nz/quality_auto/36a582_27c4844a2e464a7daa0e8da9b2905fa1~mv2.png
[Mon Jul 20 06:28:34.149853 2026] [security2:error] [pid 925208:tid 925355] [client 75.155.66.71:41056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UccRX7OrFkv0FyuJBxwAAABE"]
[Mon Jul 20 06:28:34.194116 2026] [security2:error] [pid 929851:tid 930015] [client 114.119.152.108:58353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/layering-lockets-with-the-chain-extender/locketsandcharms.origamiowl.com"] [unique_id "al4UcmV3ou772CelrLh5vAAAAKM"], referer: https://locketsandcharms.com/layering-lockets-with-the-chain-extender/
[Mon Jul 20 06:28:34.214396 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5vwAAAL8"]
[Mon Jul 20 06:28:34.214522 2026] [security2:error] [pid 929851:tid 930043] [client 77.110.127.138:63598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh5vwAAAL8"]
[Mon Jul 20 06:28:34.220970 2026] [security2:error] [pid 929851:tid 930065] [client 50.116.65.227:20004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5rAAAANU"]
[Mon Jul 20 06:28:34.257888 2026] [security2:error] [pid 929851:tid 929999] [client 14.225.17.146:61106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4UcmV3ou772CelrLh5uAAAAJM"], referer: http://collectingrealestate.com/old
[Mon Jul 20 06:28:34.294530 2026] [security2:error] [pid 925208:tid 925423] [client 57.141.18.104:24414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ub8RX7OrFkv0FyuJBYQAAVXc"]
[Mon Jul 20 06:28:34.308816 2026] [proxy:error] [pid 925208:tid 925372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.308900 2026] [proxy_http:error] [pid 925208:tid 925372] [client 34.73.38.214:61320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.309735 2026] [proxy:error] [pid 925208:tid 925372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.309787 2026] [proxy_http:error] [pid 925208:tid 925372] [client 34.73.38.214:61320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.315677 2026] [proxy:error] [pid 929851:tid 930010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.315771 2026] [proxy_http:error] [pid 929851:tid 930010] [client 34.73.38.214:61407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.316652 2026] [proxy:error] [pid 929851:tid 930010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.316703 2026] [proxy_http:error] [pid 929851:tid 930010] [client 34.73.38.214:61407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.461972 2026] [security2:error] [pid 929851:tid 930096] [client 50.116.65.227:20024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4UcmV3ou772CelrLh5wAAAAPQ"]
[Mon Jul 20 06:28:34.633282 2026] [security2:error] [pid 929851:tid 929986] [client 14.224.227.113:58457] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4UcmV3ou772CelrLh52QAAAIY"]
[Mon Jul 20 06:28:34.679862 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:63603] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UcmV3ou772CelrLh53gAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:34.699963 2026] [security2:error] [pid 925208:tid 925388] [client 114.119.133.245:34899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asliceofleadership.com"] [uri "/upsurgecommunications/"] [unique_id "al4UcsRX7OrFkv0FyuJB4QAAADI"], referer: https://asliceofleadership.com/
[Mon Jul 20 06:28:34.731432 2026] [proxy:error] [pid 929851:tid 930041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.731506 2026] [proxy_http:error] [pid 929851:tid 930041] [client 34.73.38.214:53582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.732318 2026] [proxy:error] [pid 929851:tid 930041] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:34.732351 2026] [proxy_http:error] [pid 929851:tid 930041] [client 34.73.38.214:53582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:34.833227 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:63604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh55AAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:34.833338 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:63604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UcmV3ou772CelrLh55AAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:34.837181 2026] [security2:error] [pid 929851:tid 930074] [client 57.141.18.102:25792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ub2V3ou772CelrLh5BgAA3kc"]
[Mon Jul 20 06:28:34.905117 2026] [security2:error] [pid 929851:tid 930089] [client 39.48.81.23:55357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UcmV3ou772CelrLh56wAAAO0"]
[Mon Jul 20 06:28:34.905225 2026] [security2:error] [pid 929851:tid 930089] [client 39.48.81.23:55357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UcmV3ou772CelrLh56wAAAO0"]
[Mon Jul 20 06:28:35.097956 2026] [core:error] [pid 925208:tid 925434] [client 198.235.24.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:35.097994 2026] [core:error] [pid 925208:tid 925434] [client 198.235.24.8:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:28:35.241926 2026] [security2:error] [pid 929851:tid 930070] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh58gAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.262376 2026] [security2:error] [pid 929851:tid 930025] [client 34.73.38.214:54872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6BQAAAK0"]
[Mon Jul 20 06:28:35.263194 2026] [security2:error] [pid 925208:tid 925441] [client 34.73.38.214:61560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc8RX7OrFkv0FyuJB8QAAAGc"]
[Mon Jul 20 06:28:35.271630 2026] [security2:error] [pid 929851:tid 930018] [client 34.73.38.214:55026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6BgAAAKY"]
[Mon Jul 20 06:28:35.346468 2026] [security2:error] [pid 929851:tid 930046] [client 74.7.227.179:59682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6AAAAwh4"], referer: https://tejasenvironmental.com/p=3228
[Mon Jul 20 06:28:35.370115 2026] [security2:error] [pid 925208:tid 925415] [client 45.157.112.60:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Uc8RX7OrFkv0FyuJB9AAAAE0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:35.395142 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uc2V3ou772CelrLh6DgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.395238 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uc2V3ou772CelrLh6DgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.599327 2026] [security2:error] [pid 929851:tid 930001] [client 14.225.17.146:61234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6FwAAAJU"], referer: https://nurturemarple.co.uk/old
[Mon Jul 20 06:28:35.700264 2026] [security2:error] [pid 925208:tid 925435] [client 104.234.53.48:49079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Uc8RX7OrFkv0FyuJCAgAAAGE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:35.701477 2026] [security2:error] [pid 929851:tid 930097] [client 57.141.18.32:23210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcGV3ou772CelrLh5UAAA9Ts"]
[Mon Jul 20 06:28:35.716591 2026] [security2:error] [pid 925208:tid 925221] [remote 47.86.33.52:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4Uc8RX7OrFkv0FyuJCAwAAFgw"]
[Mon Jul 20 06:28:35.807091 2026] [security2:error] [pid 925208:tid 925347] [client 34.73.38.214:56739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc8RX7OrFkv0FyuJCCAAAAAk"]
[Mon Jul 20 06:28:35.808099 2026] [security2:error] [pid 929851:tid 930034] [client 34.73.38.214:65184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6NQAAALY"]
[Mon Jul 20 06:28:35.815290 2026] [security2:error] [pid 929851:tid 930096] [client 34.73.38.214:59759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.eql.eda.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Uc2V3ou772CelrLh6NgAAAPQ"]
[Mon Jul 20 06:28:35.852274 2026] [security2:error] [pid 929851:tid 930092] [client 8.215.94.139:49519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6OAAAAPA"]
[Mon Jul 20 06:28:35.907607 2026] [security2:error] [pid 925208:tid 925400] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uc8RX7OrFkv0FyuJCAQAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:35.969492 2026] [security2:error] [pid 929851:tid 930050] [client 57.141.18.119:49480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5XAAAxnA"]
[Mon Jul 20 06:28:36.258000 2026] [security2:error] [pid 929851:tid 930097] [client 34.73.38.214:60074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6VwAAAPU"]
[Mon Jul 20 06:28:36.280013 2026] [security2:error] [pid 929851:tid 930087] [client 8.215.94.139:49527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6WAAAAOs"]
[Mon Jul 20 06:28:36.304027 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6TQAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.480310 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdGV3ou772CelrLh6YgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.480403 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdGV3ou772CelrLh6YgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.519873 2026] [security2:error] [pid 929851:tid 929868] [remote 192.241.143.148:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UdGV3ou772CelrLh6aAAAzgw"]
[Mon Jul 20 06:28:36.567740 2026] [security2:error] [pid 929851:tid 930112] [client 14.225.17.146:64948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6YAAAAQQ"], referer: http://detroitcsc.com/old
[Mon Jul 20 06:28:36.574827 2026] [security2:error] [pid 929851:tid 930025] [client 34.73.38.214:59730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6bAAAAK0"]
[Mon Jul 20 06:28:36.574880 2026] [security2:error] [pid 929851:tid 930069] [client 34.73.38.214:63183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6bQAAANk"]
[Mon Jul 20 06:28:36.629508 2026] [security2:error] [pid 929851:tid 930072] [client 57.141.18.124:47242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcWV3ou772CelrLh5jAAA3CQ"]
[Mon Jul 20 06:28:36.683076 2026] [security2:error] [pid 925208:tid 925344] [client 8.215.94.139:49537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdMRX7OrFkv0FyuJCIwAAAAY"]
[Mon Jul 20 06:28:36.689133 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6ZgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:36.703423 2026] [security2:error] [pid 929851:tid 929953] [remote 192.241.143.148:43880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UdGV3ou772CelrLh6dAAA-GE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:36.741743 2026] [security2:error] [pid 929851:tid 930057] [client 34.73.38.214:64406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UdGV3ou772CelrLh6dgAAAM0"]
[Mon Jul 20 06:28:36.990807 2026] [ssl:error] [pid 925208:tid 925370] [client 104.48.69.105:37974] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:28:37.014909 2026] [security2:error] [pid 925208:tid 925422] [client 34.73.38.214:59667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UdcRX7OrFkv0FyuJCLgAAAFQ"]
[Mon Jul 20 06:28:37.031728 2026] [security2:error] [pid 929851:tid 930102] [client 34.73.38.214:59389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UdWV3ou772CelrLh6kgAAAPo"]
[Mon Jul 20 06:28:37.046906 2026] [security2:error] [pid 925208:tid 925357] [client 171.61.165.146:18663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UdcRX7OrFkv0FyuJCLwAAABM"]
[Mon Jul 20 06:28:37.047034 2026] [security2:error] [pid 925208:tid 925357] [client 171.61.165.146:18663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UdcRX7OrFkv0FyuJCLwAAABM"]
[Mon Jul 20 06:28:37.050968 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6hgAAAI8"]
[Mon Jul 20 06:28:37.100040 2026] [security2:error] [pid 925208:tid 925448] [client 8.215.94.139:49546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdcRX7OrFkv0FyuJCMwAAAG4"]
[Mon Jul 20 06:28:37.154581 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:63624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UdWV3ou772CelrLh6nAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.253983 2026] [security2:error] [pid 929851:tid 929986] [client 14.225.17.146:52494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6WQAAAIY"], referer: http://retzkolonglogistics.com/old
[Mon Jul 20 06:28:37.323992 2026] [security2:error] [pid 929851:tid 930016] [client 77.110.127.138:63627] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UdWV3ou772CelrLh6rQAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.343143 2026] [security2:error] [pid 925208:tid 925242] [remote 47.86.33.52:33506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4UdcRX7OrFkv0FyuJCOQAATSE"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:28:37.346764 2026] [security2:error] [pid 925208:tid 925429] [client 158.173.166.181:25489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UdcRX7OrFkv0FyuJCOgAAAFs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:37.351566 2026] [security2:error] [pid 929851:tid 930054] [client 57.141.18.122:29144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UcmV3ou772CelrLh5xwAAyg4"]
[Mon Jul 20 06:28:37.474909 2026] [security2:error] [pid 929851:tid 930006] [client 14.225.17.146:51868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh6qgAAAJo"], referer: http://koaconsultants.com/old
[Mon Jul 20 06:28:37.480729 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6uQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.480883 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6uQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.485288 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh6pwAAAKA"]
[Mon Jul 20 06:28:37.515315 2026] [security2:error] [pid 929851:tid 930065] [client 8.215.94.139:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh6uwAAANU"]
[Mon Jul 20 06:28:37.601627 2026] [security2:error] [pid 929851:tid 930110] [client 34.73.38.214:50274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UdWV3ou772CelrLh6wAAAAQI"]
[Mon Jul 20 06:28:37.630534 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xAAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.630626 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xAAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.634189 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.634289 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6xQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.685019 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6ywAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.685164 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:63601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh6ywAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.757666 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:63606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60AAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.757776 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:63606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60AAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.789984 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60gAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.790097 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh60gAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.894403 2026] [security2:error] [pid 925208:tid 925355] [client 34.73.38.214:64512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UdcRX7OrFkv0FyuJCRgAAABE"]
[Mon Jul 20 06:28:37.896304 2026] [security2:error] [pid 925208:tid 925457] [client 34.73.38.214:52034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UdcRX7OrFkv0FyuJCRwAAAHc"]
[Mon Jul 20 06:28:37.908871 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh63QAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.908966 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh63QAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.922450 2026] [security2:error] [pid 929851:tid 930005] [client 8.215.94.139:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.94.215.8.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4UdWV3ou772CelrLh63wAAAJk"]
[Mon Jul 20 06:28:37.941286 2026] [security2:error] [pid 925208:tid 925419] [client 77.110.127.138:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdcRX7OrFkv0FyuJCSQAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.941364 2026] [security2:error] [pid 925208:tid 925419] [client 77.110.127.138:63636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdcRX7OrFkv0FyuJCSQAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:37.946105 2026] [security2:error] [pid 925208:tid 925446] [client 34.74.185.202:50023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UdcRX7OrFkv0FyuJCSgAAAGw"]
[Mon Jul 20 06:28:37.994420 2026] [security2:error] [pid 929851:tid 930062] [client 77.110.127.138:63609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh64QAAANI"]
[Mon Jul 20 06:28:37.994542 2026] [security2:error] [pid 929851:tid 930062] [client 77.110.127.138:63609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdWV3ou772CelrLh64QAAANI"]
[Mon Jul 20 06:28:38.027948 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh65AAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.028096 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:63583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh65AAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.046527 2026] [ssl:error] [pid 929851:tid 930016] [client 104.48.69.105:54886] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:28:38.047892 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66AAAAKA"]
[Mon Jul 20 06:28:38.048007 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:63615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66AAAAKA"]
[Mon Jul 20 06:28:38.112407 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66wAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.112515 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:63637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh66wAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.134574 2026] [security2:error] [pid 929851:tid 930010] [client 57.141.18.22:40374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh59QAAnk0"]
[Mon Jul 20 06:28:38.187696 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:63640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCTgAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.187801 2026] [security2:error] [pid 925208:tid 925368] [client 77.110.127.138:63640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCTgAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.198156 2026] [security2:error] [pid 929851:tid 930095] [client 34.74.185.202:58908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh69AAAAPM"]
[Mon Jul 20 06:28:38.228430 2026] [security2:error] [pid 925208:tid 925408] [client 57.141.18.95:29684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uc8RX7OrFkv0FyuJB7gAARmY"]
[Mon Jul 20 06:28:38.366962 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6-wAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.367096 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6-wAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.426833 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCXQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.427006 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:63586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdsRX7OrFkv0FyuJCXQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.447565 2026] [security2:error] [pid 929851:tid 930097] [client 34.73.38.214:51242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh6_gAAAPU"]
[Mon Jul 20 06:28:38.482819 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6_wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.482942 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:63620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh6_wAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.533173 2026] [security2:error] [pid 929851:tid 930031] [client 57.141.18.42:39154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uc2V3ou772CelrLh6GQAAsyM"]
[Mon Jul 20 06:28:38.620814 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7BgAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.620920 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:63642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7BgAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.640187 2026] [security2:error] [pid 929851:tid 930075] [client 62.164.177.222:35778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4UdmV3ou772CelrLh7BwAAAN8"]
[Mon Jul 20 06:28:38.640291 2026] [security2:error] [pid 929851:tid 930075] [client 62.164.177.222:35778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4UdmV3ou772CelrLh7BwAAAN8"]
[Mon Jul 20 06:28:38.678118 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7CwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.678212 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:63643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7CwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.737931 2026] [security2:error] [pid 925208:tid 925459] [client 34.73.38.214:52227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UdsRX7OrFkv0FyuJCYQAAAHk"]
[Mon Jul 20 06:28:38.770234 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:63591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7EwAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.770335 2026] [security2:error] [pid 929851:tid 929990] [client 77.110.127.138:63591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UdmV3ou772CelrLh7EwAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:38.903056 2026] [security2:error] [pid 929851:tid 930068] [client 34.74.185.202:52096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh7HgAAANg"]
[Mon Jul 20 06:28:38.941266 2026] [security2:error] [pid 929851:tid 930089] [client 34.73.38.214:58299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh7JgAAAO0"]
[Mon Jul 20 06:28:38.941283 2026] [security2:error] [pid 929851:tid 930063] [client 34.73.38.214:56172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UdmV3ou772CelrLh7JQAAANM"]
[Mon Jul 20 06:28:39.101788 2026] [security2:error] [pid 925208:tid 925438] [client 62.164.177.222:38982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCaAAAAGQ"]
[Mon Jul 20 06:28:39.101863 2026] [security2:error] [pid 925208:tid 925438] [client 62.164.177.222:38982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCaAAAAGQ"]
[Mon Jul 20 06:28:39.142724 2026] [security2:error] [pid 929851:tid 930059] [client 106.219.188.178:47757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ud2V3ou772CelrLh7MgAAAM8"]
[Mon Jul 20 06:28:39.151279 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCbQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.151385 2026] [security2:error] [pid 925208:tid 925343] [client 77.110.127.138:63648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCbQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.151717 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63647] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ud2V3ou772CelrLh7MwAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.165918 2026] [security2:error] [pid 929851:tid 930059] [client 106.219.188.178:47757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ud2V3ou772CelrLh7MgAAAM8"]
[Mon Jul 20 06:28:39.183576 2026] [security2:error] [pid 929851:tid 930013] [client 66.249.73.172:60287] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "jmq.beb.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4Ud2V3ou772CelrLh7NgAAAKE"]
[Mon Jul 20 06:28:39.227480 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:63625] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ud2V3ou772CelrLh7OwAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.256708 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud2V3ou772CelrLh7PAAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.256927 2026] [security2:error] [pid 929851:tid 930100] [client 77.110.127.138:63597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ud2V3ou772CelrLh7PAAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:39.273044 2026] [security2:error] [pid 925208:tid 925338] [client 14.225.17.146:61717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Ud8RX7OrFkv0FyuJCaQAAAAA"], referer: http://secretkeynumerology.com/old
[Mon Jul 20 06:28:39.345138 2026] [security2:error] [pid 929851:tid 930091] [client 34.73.38.214:54028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7QAAAAO8"]
[Mon Jul 20 06:28:39.421234 2026] [security2:error] [pid 929851:tid 930024] [client 34.73.38.214:50506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7RwAAAKw"]
[Mon Jul 20 06:28:39.487401 2026] [security2:error] [pid 929851:tid 930008] [client 34.73.38.214:61479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7TwAAAJw"]
[Mon Jul 20 06:28:39.531688 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.52:47972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6XgAA11o"]
[Mon Jul 20 06:28:39.762533 2026] [security2:error] [pid 925208:tid 925420] [client 34.74.185.202:54026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud8RX7OrFkv0FyuJCfQAAAFI"]
[Mon Jul 20 06:28:39.814004 2026] [security2:error] [pid 929851:tid 929993] [client 54.244.177.189:54446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ud2V3ou772CelrLh7aAAAAI0"], referer: https://curlsnpearlsss.com/wp-cron.php?doing_wp_cron=1784550519.5384230613708496093750
[Mon Jul 20 06:28:39.862296 2026] [security2:error] [pid 929851:tid 930041] [client 14.225.17.146:61729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4UdmV3ou772CelrLh7FgAAAL0"], referer: http://adultdaycarereno.com/old
[Mon Jul 20 06:28:39.862611 2026] [security2:error] [pid 929851:tid 930109] [client 34.73.38.214:65525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Ud2V3ou772CelrLh7bAAAAQE"]
[Mon Jul 20 06:28:40.044635 2026] [security2:error] [pid 925208:tid 925395] [client 104.234.53.65:46883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UeMRX7OrFkv0FyuJCjAAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:40.047068 2026] [security2:error] [pid 925208:tid 925437] [client 57.141.18.100:22538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdMRX7OrFkv0FyuJCKAAAYwM"]
[Mon Jul 20 06:28:40.064672 2026] [security2:error] [pid 929851:tid 930101] [client 34.73.38.214:64771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UeGV3ou772CelrLh7eAAAAPk"]
[Mon Jul 20 06:28:40.187780 2026] [security2:error] [pid 929851:tid 930085] [client 57.141.18.55:45270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdGV3ou772CelrLh6kAAA6Sg"]
[Mon Jul 20 06:28:40.403498 2026] [security2:error] [pid 929851:tid 930086] [client 34.73.38.214:56426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UeGV3ou772CelrLh7kAAAAOo"]
[Mon Jul 20 06:28:40.413157 2026] [security2:error] [pid 925208:tid 925397] [client 14.225.17.146:61435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4UeMRX7OrFkv0FyuJCkAAAADs"], referer: https://secretkeynumerology.com/old
[Mon Jul 20 06:28:40.911181 2026] [security2:error] [pid 929851:tid 930109] [client 14.225.17.146:60942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4UeGV3ou772CelrLh7qAAAAQE"], referer: https://adultdaycarereno.com/old
[Mon Jul 20 06:28:40.936936 2026] [security2:error] [pid 929851:tid 930103] [client 176.9.19.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4UeGV3ou772CelrLh7oQAAAPs"]
[Mon Jul 20 06:28:41.011108 2026] [security2:error] [pid 929851:tid 929883] [remote 147.50.252.213:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7tQAAiBs"]
[Mon Jul 20 06:28:41.044105 2026] [security2:error] [pid 925208:tid 925462] [client 14.225.17.146:61121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4UeMRX7OrFkv0FyuJClwAAAHw"], referer: http://waterproofgoods.com/old
[Mon Jul 20 06:28:41.049368 2026] [security2:error] [pid 929851:tid 930069] [client 14.225.17.146:55177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4Ud2V3ou772CelrLh7RQAAANk"], referer: http://maplerespiteservices.com/old
[Mon Jul 20 06:28:41.145475 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UeWV3ou772CelrLh7vAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:41.145593 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:63659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UeWV3ou772CelrLh7vAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:41.184344 2026] [security2:error] [pid 929851:tid 930033] [client 34.74.185.202:61978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UeWV3ou772CelrLh7vgAAALU"]
[Mon Jul 20 06:28:41.188132 2026] [security2:error] [pid 929851:tid 930026] [client 223.185.13.213:17107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UeWV3ou772CelrLh7vwAAAK4"]
[Mon Jul 20 06:28:41.188223 2026] [security2:error] [pid 929851:tid 930026] [client 223.185.13.213:17107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UeWV3ou772CelrLh7vwAAAK4"]
[Mon Jul 20 06:28:41.193814 2026] [security2:error] [pid 929851:tid 930098] [client 34.73.38.214:65055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UeWV3ou772CelrLh7wQAAAPY"]
[Mon Jul 20 06:28:41.238202 2026] [security2:error] [pid 929851:tid 929935] [remote 159.65.81.207:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7wwAA908"]
[Mon Jul 20 06:28:41.303784 2026] [security2:error] [pid 925208:tid 925246] [remote 20.153.140.50:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UecRX7OrFkv0FyuJCqQAABiU"]
[Mon Jul 20 06:28:41.327380 2026] [security2:error] [pid 929851:tid 929886] [remote 160.187.68.132:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7yQAAwh4"]
[Mon Jul 20 06:28:41.404229 2026] [security2:error] [pid 929851:tid 929974] [remote 159.65.81.207:42696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh7zwAAx3Y"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:28:41.409505 2026] [security2:error] [pid 925208:tid 925366] [client 57.141.18.13:53032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UdsRX7OrFkv0FyuJCUwAAHGc"]
[Mon Jul 20 06:28:41.478491 2026] [security2:error] [pid 929851:tid 929856] [remote 147.50.252.213:40908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh70gAAjgA"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:28:41.481732 2026] [security2:error] [pid 929851:tid 930095] [client 104.234.53.64:62339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UeWV3ou772CelrLh70wAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:41.602040 2026] [security2:error] [pid 929851:tid 930036] [client 144.76.19.72:39816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4UeWV3ou772CelrLh70QAAALg"]
[Mon Jul 20 06:28:41.694563 2026] [security2:error] [pid 925208:tid 925332] [remote 103.191.209.69:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.209.191.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCsAAAXns"]
[Mon Jul 20 06:28:41.694725 2026] [security2:error] [pid 925208:tid 925432] [client 103.191.209.69:38980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCsAAAXns"]
[Mon Jul 20 06:28:41.716046 2026] [security2:error] [pid 925208:tid 925232] [remote 20.153.140.50:35988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UecRX7OrFkv0FyuJCswAAAhc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:41.716997 2026] [security2:error] [pid 929851:tid 929860] [remote 152.228.213.32:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh74AAA8QQ"]
[Mon Jul 20 06:28:41.786975 2026] [security2:error] [pid 925208:tid 925359] [client 34.73.38.214:61463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UecRX7OrFkv0FyuJCtQAAABU"]
[Mon Jul 20 06:28:41.809287 2026] [security2:error] [pid 929851:tid 929937] [remote 160.187.68.132:57976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh75gAA2FE"], referer: https://fbvrealtors.com/wp-login.php
[Mon Jul 20 06:28:41.886741 2026] [security2:error] [pid 925208:tid 925410] [client 34.73.38.214:56087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UecRX7OrFkv0FyuJCvwAAAEg"]
[Mon Jul 20 06:28:41.923315 2026] [security2:error] [pid 929851:tid 929980] [remote 152.228.213.32:51126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4UeWV3ou772CelrLh78AAA9nw"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:28:41.934209 2026] [security2:error] [pid 925208:tid 925455] [client 62.164.177.222:57746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/ar/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCwQAAAHU"]
[Mon Jul 20 06:28:41.934289 2026] [security2:error] [pid 925208:tid 925455] [client 62.164.177.222:57746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/ar/xmlrpc.php"] [unique_id "al4UecRX7OrFkv0FyuJCwQAAAHU"]
[Mon Jul 20 06:28:42.020658 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UemV3ou772CelrLh79QAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.020771 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:63663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UemV3ou772CelrLh79QAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.069485 2026] [security2:error] [pid 929851:tid 929987] [client 34.74.185.202:58566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UemV3ou772CelrLh7-QAAAIc"]
[Mon Jul 20 06:28:42.082073 2026] [security2:error] [pid 929851:tid 929990] [client 45.61.188.240:60337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.aandarealtygroup.com"] [uri "/"] [unique_id "al4UemV3ou772CelrLh7-gAAAIo"]
[Mon Jul 20 06:28:42.242264 2026] [security2:error] [pid 925208:tid 925408] [client 34.73.38.214:62606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UesRX7OrFkv0FyuJCxQAAAEY"]
[Mon Jul 20 06:28:42.348279 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.110:30538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ud2V3ou772CelrLh7UwAAohg"]
[Mon Jul 20 06:28:42.358494 2026] [security2:error] [pid 925208:tid 925403] [client 45.61.188.240:60392] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.aandarealtygroup.com"] [uri "/"] [unique_id "al4UesRX7OrFkv0FyuJCygAAAEE"]
[Mon Jul 20 06:28:42.420125 2026] [security2:error] [pid 929851:tid 930066] [client 62.164.177.222:32820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp/xmlrpc.php"] [unique_id "al4UemV3ou772CelrLh8EAAAANY"]
[Mon Jul 20 06:28:42.420233 2026] [security2:error] [pid 929851:tid 930066] [client 62.164.177.222:32820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/wp/xmlrpc.php"] [unique_id "al4UemV3ou772CelrLh8EAAAANY"]
[Mon Jul 20 06:28:42.449115 2026] [security2:error] [pid 929851:tid 930061] [client 170.23.24.119:8508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4UemV3ou772CelrLh8CAAA0Uk"]
[Mon Jul 20 06:28:42.481808 2026] [security2:error] [pid 929851:tid 930095] [client 14.225.17.146:63165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4UemV3ou772CelrLh8DgAAAPM"], referer: http://intelligentengineeringsolutions.com/old
[Mon Jul 20 06:28:42.549515 2026] [security2:error] [pid 925208:tid 925350] [client 77.110.127.138:63667] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UesRX7OrFkv0FyuJC0AAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.595130 2026] [security2:error] [pid 929851:tid 930015] [client 57.141.18.69:64400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ud2V3ou772CelrLh7awAAoyo"]
[Mon Jul 20 06:28:42.663612 2026] [core:error] [pid 925208:tid 925349] [client 159.89.133.65:50020] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Mon Jul 20 06:28:42.714611 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:63670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UesRX7OrFkv0FyuJC2wAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.714723 2026] [security2:error] [pid 925208:tid 925459] [client 77.110.127.138:63670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UesRX7OrFkv0FyuJC2wAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:42.913843 2026] [security2:error] [pid 925208:tid 925373] [client 62.164.177.222:36354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/site/xmlrpc.php"] [unique_id "al4UesRX7OrFkv0FyuJC4AAAACM"]
[Mon Jul 20 06:28:42.913968 2026] [security2:error] [pid 925208:tid 925373] [client 62.164.177.222:36354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/site/xmlrpc.php"] [unique_id "al4UesRX7OrFkv0FyuJC4AAAACM"]
[Mon Jul 20 06:28:42.927081 2026] [security2:error] [pid 929851:tid 930110] [client 34.74.185.202:52539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UemV3ou772CelrLh8LgAAAQI"]
[Mon Jul 20 06:28:42.933391 2026] [security2:error] [pid 929851:tid 930024] [client 57.141.18.96:45748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UeGV3ou772CelrLh7fQAArBY"]
[Mon Jul 20 06:28:42.941783 2026] [security2:error] [pid 929851:tid 930020] [client 45.61.188.240:60509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.civitansuncitiesaz.org"] [uri "/"] [unique_id "al4UemV3ou772CelrLh8LwAAAKg"]
[Mon Jul 20 06:28:43.056294 2026] [security2:error] [pid 929851:tid 930101] [client 34.73.38.214:56159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8MQAAAPk"]
[Mon Jul 20 06:28:43.169089 2026] [security2:error] [pid 929851:tid 930078] [client 171.60.139.123:64724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8PAAAAOI"]
[Mon Jul 20 06:28:43.169204 2026] [security2:error] [pid 929851:tid 930078] [client 171.60.139.123:64724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8PAAAAOI"]
[Mon Jul 20 06:28:43.198930 2026] [security2:error] [pid 925208:tid 925430] [client 50.116.65.227:10876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Ue8RX7OrFkv0FyuJC6QAAAFw"]
[Mon Jul 20 06:28:43.215568 2026] [security2:error] [pid 929851:tid 930056] [client 50.116.65.227:52596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4Ue2V3ou772CelrLh8RAAAAPw"]
[Mon Jul 20 06:28:43.215617 2026] [security2:error] [pid 929851:tid 930054] [client 45.61.188.240:60557] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.civitansuncitiesaz.org"] [uri "/"] [unique_id "al4Ue2V3ou772CelrLh8RQAAAMo"]
[Mon Jul 20 06:28:43.259163 2026] [security2:error] [pid 929851:tid 929998] [client 34.73.38.214:60896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8RwAAAJI"]
[Mon Jul 20 06:28:43.378993 2026] [security2:error] [pid 929851:tid 930095] [client 62.164.177.222:39420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/news/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8TgAAAPM"]
[Mon Jul 20 06:28:43.379081 2026] [security2:error] [pid 929851:tid 930095] [client 62.164.177.222:39420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/news/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8TgAAAPM"]
[Mon Jul 20 06:28:43.533695 2026] [security2:error] [pid 925208:tid 925348] [client 34.74.185.202:61817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue8RX7OrFkv0FyuJC8gAAAAo"]
[Mon Jul 20 06:28:43.750861 2026] [security2:error] [pid 929851:tid 930036] [client 34.73.38.214:55976] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8ZgAAALg"]
[Mon Jul 20 06:28:43.788071 2026] [security2:error] [pid 929851:tid 930027] [client 57.141.18.22:40092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UeWV3ou772CelrLh7wAAArxw"]
[Mon Jul 20 06:28:43.834371 2026] [security2:error] [pid 929851:tid 930077] [client 57.141.18.72:62600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UeWV3ou772CelrLh7vQAA4Vc"]
[Mon Jul 20 06:28:43.868106 2026] [security2:error] [pid 929851:tid 930078] [client 34.73.38.214:63668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiasconscientes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ue2V3ou772CelrLh8cgAAAOI"]
[Mon Jul 20 06:28:43.870089 2026] [security2:error] [pid 929851:tid 929994] [client 62.164.177.222:42606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/web/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8cwAAAI4"]
[Mon Jul 20 06:28:43.870211 2026] [security2:error] [pid 929851:tid 929994] [client 62.164.177.222:42606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/web/xmlrpc.php"] [unique_id "al4Ue2V3ou772CelrLh8cwAAAI4"]
[Mon Jul 20 06:28:43.934547 2026] [security2:error] [pid 929851:tid 929933] [remote 57.141.18.87:26290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5138828"] [unique_id "al4Ue2V3ou772CelrLh8fQAA_E0"]
[Mon Jul 20 06:28:44.116120 2026] [security2:error] [pid 925208:tid 925361] [client 34.73.38.214:57288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.fansarogroup.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UfMRX7OrFkv0FyuJC_wAAABc"]
[Mon Jul 20 06:28:44.119247 2026] [security2:error] [pid 925208:tid 925437] [client 50.116.65.227:52600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UfMRX7OrFkv0FyuJDAAAAAGM"]
[Mon Jul 20 06:28:44.133014 2026] [security2:error] [pid 925208:tid 925440] [client 50.116.65.227:52604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UfMRX7OrFkv0FyuJDAwAAAGY"]
[Mon Jul 20 06:28:44.304155 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8jAAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.304264 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8jAAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.320937 2026] [security2:error] [pid 925208:tid 925464] [client 62.164.177.222:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/main/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDCwAAAH4"]
[Mon Jul 20 06:28:44.321047 2026] [security2:error] [pid 925208:tid 925464] [client 62.164.177.222:45598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/main/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDCwAAAH4"]
[Mon Jul 20 06:28:44.439614 2026] [security2:error] [pid 925208:tid 925391] [client 57.141.18.104:45940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UecRX7OrFkv0FyuJCtwAANSo"]
[Mon Jul 20 06:28:44.546622 2026] [security2:error] [pid 925208:tid 925439] [client 45.116.69.230:57085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDFAAAAGU"]
[Mon Jul 20 06:28:44.546757 2026] [security2:error] [pid 925208:tid 925439] [client 45.116.69.230:57085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDFAAAAGU"]
[Mon Jul 20 06:28:44.606833 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8nAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.606940 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8nAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.649784 2026] [security2:error] [pid 929851:tid 930027] [client 34.74.185.202:64184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UfGV3ou772CelrLh8ngAAAK8"]
[Mon Jul 20 06:28:44.678796 2026] [security2:error] [pid 925208:tid 925426] [client 103.141.108.143:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGAAAAFg"]
[Mon Jul 20 06:28:44.678913 2026] [security2:error] [pid 925208:tid 925426] [client 103.141.108.143:55766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGAAAAFg"]
[Mon Jul 20 06:28:44.766083 2026] [security2:error] [pid 929851:tid 930001] [client 77.110.127.138:63683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8ogAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.766428 2026] [security2:error] [pid 929851:tid 930001] [client 77.110.127.138:63683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfGV3ou772CelrLh8ogAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:44.796644 2026] [security2:error] [pid 925208:tid 925378] [client 62.164.177.222:49088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/cms/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGQAAACg"]
[Mon Jul 20 06:28:44.796762 2026] [security2:error] [pid 925208:tid 925378] [client 62.164.177.222:49088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/cms/xmlrpc.php"] [unique_id "al4UfMRX7OrFkv0FyuJDGQAAACg"]
[Mon Jul 20 06:28:44.880488 2026] [security2:error] [pid 929851:tid 930011] [client 74.208.214.194:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4UfGV3ou772CelrLh8qgAAAJ8"]
[Mon Jul 20 06:28:44.912780 2026] [security2:error] [pid 929851:tid 929991] [client 14.225.17.146:54790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4UfGV3ou772CelrLh8mwAAAIs"], referer: http://transparentservices.online/old
[Mon Jul 20 06:28:45.043352 2026] [security2:error] [pid 925208:tid 925448] [client 34.74.185.202:52402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UfcRX7OrFkv0FyuJDIQAAAG4"]
[Mon Jul 20 06:28:45.065866 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.82:59124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UemV3ou772CelrLh8EwAA-jA"]
[Mon Jul 20 06:28:45.066464 2026] [security2:error] [pid 929851:tid 930079] [client 34.73.38.214:63722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.familiaconsciente.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UfWV3ou772CelrLh8tAAAAOM"]
[Mon Jul 20 06:28:45.075019 2026] [security2:error] [pid 925208:tid 925316] [remote 154.61.75.100:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UfcRX7OrFkv0FyuJDIwAATms"]
[Mon Jul 20 06:28:45.078689 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8tgAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.078792 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8tgAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.123517 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8uAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.123610 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:63685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8uAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.272081 2026] [security2:error] [pid 929851:tid 930085] [client 62.164.177.222:52428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh8wgAAAOk"]
[Mon Jul 20 06:28:45.272169 2026] [security2:error] [pid 929851:tid 930085] [client 62.164.177.222:52428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh8wgAAAOk"]
[Mon Jul 20 06:28:45.302299 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8xQAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.302419 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:63687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh8xQAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.457202 2026] [security2:error] [pid 929851:tid 930057] [client 77.110.127.138:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh81AAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.457283 2026] [security2:error] [pid 929851:tid 930057] [client 77.110.127.138:63690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh81AAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.509545 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:63660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfcRX7OrFkv0FyuJDLwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.509645 2026] [security2:error] [pid 925208:tid 925347] [client 77.110.127.138:63660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfcRX7OrFkv0FyuJDLwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.551204 2026] [security2:error] [pid 925208:tid 925287] [remote 154.61.75.100:52618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UfcRX7OrFkv0FyuJDMwAAEU4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:45.567484 2026] [security2:error] [pid 925208:tid 925446] [client 77.110.127.138:63692] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UfcRX7OrFkv0FyuJDOAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.616957 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh85QAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.617089 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UfWV3ou772CelrLh85QAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:45.637403 2026] [security2:error] [pid 925208:tid 925389] [client 39.48.81.23:55872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UfcRX7OrFkv0FyuJDPAAAADM"]
[Mon Jul 20 06:28:45.637512 2026] [security2:error] [pid 925208:tid 925389] [client 39.48.81.23:55872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UfcRX7OrFkv0FyuJDPAAAADM"]
[Mon Jul 20 06:28:45.757547 2026] [security2:error] [pid 929851:tid 930102] [client 62.164.177.222:55652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/old/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh86AAAAPo"]
[Mon Jul 20 06:28:45.757644 2026] [security2:error] [pid 929851:tid 930102] [client 62.164.177.222:55652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "youpositive.co"] [uri "/old/xmlrpc.php"] [unique_id "al4UfWV3ou772CelrLh86AAAAPo"]
[Mon Jul 20 06:28:45.814463 2026] [security2:error] [pid 925208:tid 925414] [client 13.215.47.127:15584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UfcRX7OrFkv0FyuJDQQAAAEw"]
[Mon Jul 20 06:28:45.995474 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh87AAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:46.039547 2026] [security2:error] [pid 925208:tid 925437] [client 112.208.70.94:45183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UfsRX7OrFkv0FyuJDUQAAAGM"]
[Mon Jul 20 06:28:46.039664 2026] [security2:error] [pid 925208:tid 925437] [client 112.208.70.94:45183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UfsRX7OrFkv0FyuJDUQAAAGM"]
[Mon Jul 20 06:28:46.091705 2026] [security2:error] [pid 929851:tid 930085] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh89wAAAOk"]
[Mon Jul 20 06:28:46.181178 2026] [security2:error] [pid 925208:tid 925456] [client 34.74.185.202:53027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UfsRX7OrFkv0FyuJDXAAAAHY"]
[Mon Jul 20 06:28:46.182636 2026] [security2:error] [pid 929851:tid 930107] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh89gAAAP8"]
[Mon Jul 20 06:28:46.202072 2026] [security2:error] [pid 929851:tid 929990] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfWV3ou772CelrLh89AAAAIo"]
[Mon Jul 20 06:28:46.287164 2026] [security2:error] [pid 929851:tid 930068] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9AwAAANg"]
[Mon Jul 20 06:28:46.330672 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.117:37492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ue2V3ou772CelrLh8awAAoiY"]
[Mon Jul 20 06:28:46.550796 2026] [security2:error] [pid 925208:tid 925450] [client 57.141.18.47:58302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfMRX7OrFkv0FyuJDBQAAcB0"]
[Mon Jul 20 06:28:46.661420 2026] [security2:error] [pid 929851:tid 930079] [client 65.111.23.40:30443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UfmV3ou772CelrLh9HwAAAOM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:28:46.695861 2026] [security2:error] [pid 929851:tid 930006] [client 54.169.146.187:20556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UfmV3ou772CelrLh9IgAAAJo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:28:46.942719 2026] [security2:error] [pid 925208:tid 925396] [client 57.141.18.71:48830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfMRX7OrFkv0FyuJDEwAAOnU"]
[Mon Jul 20 06:28:46.998891 2026] [security2:error] [pid 925208:tid 925353] [client 14.225.17.146:52112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4UfcRX7OrFkv0FyuJDKwAAAA8"], referer: http://superiorcopywriting.com/old
[Mon Jul 20 06:28:47.408003 2026] [security2:error] [pid 929851:tid 930092] [client 62.164.177.222:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Uf2V3ou772CelrLh9QAAAAPA"], referer: https://youpositive.co/wp-admin/
[Mon Jul 20 06:28:47.415046 2026] [security2:error] [pid 929851:tid 930018] [client 14.225.17.146:63929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9EAAAAKY"], referer: http://travelbyfire.com/old
[Mon Jul 20 06:28:47.588907 2026] [security2:error] [pid 925208:tid 925440] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Uf8RX7OrFkv0FyuJDfwAAAGY"]
[Mon Jul 20 06:28:47.769408 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uf2V3ou772CelrLh9UgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:47.769537 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uf2V3ou772CelrLh9UgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:47.782823 2026] [security2:error] [pid 925208:tid 925385] [client 57.141.18.49:34100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfcRX7OrFkv0FyuJDLgAAL08"]
[Mon Jul 20 06:28:47.856270 2026] [security2:error] [pid 929851:tid 930079] [client 62.164.177.222:41484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4Uf2V3ou772CelrLh9WgAAAOM"]
[Mon Jul 20 06:28:47.866162 2026] [security2:error] [pid 929851:tid 930066] [client 34.24.141.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Uf2V3ou772CelrLh9UwAAANY"]
[Mon Jul 20 06:28:47.877289 2026] [security2:error] [pid 929851:tid 930074] [client 104.234.53.75:25741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Uf2V3ou772CelrLh9WAAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:48.023650 2026] [security2:error] [pid 929851:tid 930033] [client 34.74.185.202:61536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UgGV3ou772CelrLh9ZgAAALU"]
[Mon Jul 20 06:28:48.099509 2026] [security2:error] [pid 929851:tid 930095] [client 43.205.139.3:46220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UgGV3ou772CelrLh9aQAAAPM"]
[Mon Jul 20 06:28:48.099593 2026] [security2:error] [pid 929851:tid 930095] [client 43.205.139.3:46220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UgGV3ou772CelrLh9aQAAAPM"]
[Mon Jul 20 06:28:48.359360 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:63206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9eAAAANU"], referer: https://travelbyfire.com/old
[Mon Jul 20 06:28:48.391004 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:63701] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 921 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UgGV3ou772CelrLh9fAAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.441985 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgMRX7OrFkv0FyuJDowAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.442100 2026] [security2:error] [pid 925208:tid 925362] [client 77.110.127.138:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgMRX7OrFkv0FyuJDowAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.521292 2026] [security2:error] [pid 929851:tid 930048] [client 57.141.18.67:59678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9FAAAxGo"]
[Mon Jul 20 06:28:48.847065 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:63674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgGV3ou772CelrLh9nAAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.847196 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:63674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgGV3ou772CelrLh9nAAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:48.911993 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.82:29156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UfmV3ou772CelrLh9MgAA_hs"]
[Mon Jul 20 06:28:49.232619 2026] [security2:error] [pid 925208:tid 925400] [client 57.141.18.75:33850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uf8RX7OrFkv0FyuJDdgAAPis"]
[Mon Jul 20 06:28:49.313807 2026] [security2:error] [pid 929851:tid 930112] [client 51.222.31.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Uf2V3ou772CelrLh9RwAAAQQ"]
[Mon Jul 20 06:28:49.417436 2026] [security2:error] [pid 929851:tid 930014] [client 171.61.165.146:9186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh9wAAAAKI"]
[Mon Jul 20 06:28:49.418427 2026] [security2:error] [pid 929851:tid 930014] [client 171.61.165.146:9186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh9wAAAAKI"]
[Mon Jul 20 06:28:49.634804 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgWV3ou772CelrLh9vgAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:49.732547 2026] [security2:error] [pid 925208:tid 925419] [client 34.74.185.202:54807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.jwo.ral.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UgcRX7OrFkv0FyuJD0AAAAFE"]
[Mon Jul 20 06:28:49.858988 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:10290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh93AAAAOY"]
[Mon Jul 20 06:28:49.859271 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:10290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UgWV3ou772CelrLh93AAAAOY"]
[Mon Jul 20 06:28:50.114691 2026] [security2:error] [pid 925208:tid 925413] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgcRX7OrFkv0FyuJD1AAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.339492 2026] [security2:error] [pid 925208:tid 925244] [remote 100.42.189.89:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD4AAAMCM"]
[Mon Jul 20 06:28:50.353210 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.124:21608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9ewAAliw"]
[Mon Jul 20 06:28:50.532230 2026] [security2:error] [pid 925208:tid 925262] [remote 100.42.189.89:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD6QAAOjU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:28:50.591778 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:63711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgsRX7OrFkv0FyuJD7QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.591876 2026] [security2:error] [pid 925208:tid 925428] [client 77.110.127.138:63711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgsRX7OrFkv0FyuJD7QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.604867 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgmV3ou772CelrLh9-wAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.714490 2026] [security2:error] [pid 929851:tid 930104] [client 57.141.18.34:31718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9ngAA_Aw"]
[Mon Jul 20 06:28:50.715508 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.112:61122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgGV3ou772CelrLh9nQAAzxg"]
[Mon Jul 20 06:28:50.745302 2026] [security2:error] [pid 929851:tid 929992] [client 77.110.127.138:63712] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 253 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UgmV3ou772CelrLh-EQAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.951260 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgmV3ou772CelrLh-HgAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.951351 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UgmV3ou772CelrLh-HgAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:50.985660 2026] [security2:error] [pid 925208:tid 925417] [client 14.225.17.146:51836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4UgsRX7OrFkv0FyuJD9wAAAE8"], referer: http://claysharecon.com/old
[Mon Jul 20 06:28:51.000698 2026] [security2:error] [pid 925208:tid 925235] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.141.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omenana.com"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD-wAAbRo"], referer: https://omenana.com/login
[Mon Jul 20 06:28:51.030454 2026] [security2:error] [pid 925208:tid 925280] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.141.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omenana.com"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD-gAAbUc"], referer: https://omenana.com/wp-admin/
[Mon Jul 20 06:28:51.035631 2026] [security2:error] [pid 925208:tid 925304] [remote 34.24.141.69:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.141.24.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "omenana.com"] [uri "/wp-login.php"] [unique_id "al4UgsRX7OrFkv0FyuJD-QAAbV8"], referer: https://omenana.com/wp-admin/
[Mon Jul 20 06:28:51.133916 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ug2V3ou772CelrLh-JwAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.134098 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:63716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ug2V3ou772CelrLh-JwAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.143691 2026] [security2:error] [pid 929851:tid 930065] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UgmV3ou772CelrLh-GwAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.274833 2026] [security2:error] [pid 925208:tid 925400] [client 34.31.203.120:13568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEAAAAPhk"]
[Mon Jul 20 06:28:51.311259 2026] [security2:error] [pid 925208:tid 925349] [client 54.196.52.99:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4UgsRX7OrFkv0FyuJD6gAAAAs"]
[Mon Jul 20 06:28:51.382724 2026] [security2:error] [pid 929851:tid 930039] [client 54.196.52.99:59470] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4UgmV3ou772CelrLh-AwAAALs"]
[Mon Jul 20 06:28:51.405641 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:51714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4UgWV3ou772CelrLh9zAAAAO4"], referer: http://windowtx.com/old
[Mon Jul 20 06:28:51.585975 2026] [security2:error] [pid 925208:tid 925350] [client 34.31.203.120:13568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEGQAADDg"]
[Mon Jul 20 06:28:51.615856 2026] [security2:error] [pid 925208:tid 925463] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEFwAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:51.803366 2026] [security2:error] [pid 929851:tid 930006] [client 57.141.18.21:23736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgmV3ou772CelrLh98AAAmnk"]
[Mon Jul 20 06:28:52.078405 2026] [security2:error] [pid 925208:tid 925338] [client 223.185.13.213:24486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UhMRX7OrFkv0FyuJEOQAAAAA"]
[Mon Jul 20 06:28:52.078570 2026] [security2:error] [pid 925208:tid 925338] [client 223.185.13.213:24486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UhMRX7OrFkv0FyuJEOQAAAAA"]
[Mon Jul 20 06:28:52.179604 2026] [security2:error] [pid 929851:tid 930098] [client 14.225.17.146:63704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-UAAAAPY"], referer: http://thefriendlyspreadsheet.com/old
[Mon Jul 20 06:28:52.200156 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ug2V3ou772CelrLh-RAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:52.207794 2026] [security2:error] [pid 925208:tid 925446] [client 34.31.203.120:13568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4UhMRX7OrFkv0FyuJENQAAbGM"]
[Mon Jul 20 06:28:52.271170 2026] [security2:error] [pid 925208:tid 925416] [client 57.141.18.43:26686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UgsRX7OrFkv0FyuJD6wAATiA"]
[Mon Jul 20 06:28:52.497951 2026] [security2:error] [pid 925208:tid 925231] [remote 81.173.115.7:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UhMRX7OrFkv0FyuJETAAAUhY"]
[Mon Jul 20 06:28:52.535780 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-WwAAAME"]
[Mon Jul 20 06:28:52.663299 2026] [security2:error] [pid 925208:tid 925367] [client 57.141.18.114:47062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJD_gAAHX4"]
[Mon Jul 20 06:28:52.713708 2026] [security2:error] [pid 925208:tid 925282] [remote 81.173.115.7:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UhMRX7OrFkv0FyuJEUQAAfEk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:52.913338 2026] [security2:error] [pid 925208:tid 925422] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UhMRX7OrFkv0FyuJETgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:52.945538 2026] [security2:error] [pid 925208:tid 925380] [client 57.141.18.60:20454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJECgAAKkM"]
[Mon Jul 20 06:28:53.031100 2026] [security2:error] [pid 925208:tid 925343] [client 57.141.18.69:59892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEEgAABXA"]
[Mon Jul 20 06:28:53.042515 2026] [security2:error] [pid 925208:tid 925392] [client 50.116.65.227:25350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UhcRX7OrFkv0FyuJEXgAAADY"]
[Mon Jul 20 06:28:53.053936 2026] [security2:error] [pid 925208:tid 925368] [client 50.116.65.227:25366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UhcRX7OrFkv0FyuJEXwAAAB4"]
[Mon Jul 20 06:28:53.112468 2026] [security2:error] [pid 929851:tid 930095] [client 14.225.17.146:61266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-egAAAPM"], referer: http://scott-assist.com/old
[Mon Jul 20 06:28:53.205534 2026] [security2:error] [pid 929851:tid 929934] [remote 173.212.252.15:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UhWV3ou772CelrLh-iAAA0U4"]
[Mon Jul 20 06:28:53.414370 2026] [security2:error] [pid 925208:tid 925353] [client 57.141.18.46:60184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ug8RX7OrFkv0FyuJEKQAADzM"]
[Mon Jul 20 06:28:53.472487 2026] [security2:error] [pid 929851:tid 930001] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UhWV3ou772CelrLh-iQAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.546435 2026] [security2:error] [pid 929851:tid 929862] [remote 173.212.252.15:39926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UhWV3ou772CelrLh-lwAAnAY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:28:53.569780 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-mAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.569893 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-mAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.754226 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63738] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 906 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UhWV3ou772CelrLh-qAAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.808014 2026] [proxy:error] [pid 925208:tid 925379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:53.808108 2026] [proxy_http:error] [pid 925208:tid 925379] [client 34.73.38.214:50648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:53.808714 2026] [proxy:error] [pid 925208:tid 925379] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:53.808742 2026] [proxy_http:error] [pid 925208:tid 925379] [client 34.73.38.214:50648] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:53.874564 2026] [security2:error] [pid 929851:tid 930111] [client 171.60.139.123:65269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UhWV3ou772CelrLh-swAAAQM"]
[Mon Jul 20 06:28:53.874676 2026] [security2:error] [pid 929851:tid 930111] [client 171.60.139.123:65269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UhWV3ou772CelrLh-swAAAQM"]
[Mon Jul 20 06:28:53.916587 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:63741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-uAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.916696 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:63741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-uAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.967708 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-vQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:53.967813 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:63708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UhWV3ou772CelrLh-vQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:54.360414 2026] [security2:error] [pid 925208:tid 925426] [client 121.229.156.62:46596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2010-commission/"] [unique_id "al4UhsRX7OrFkv0FyuJEiAAAAFg"]
[Mon Jul 20 06:28:54.360536 2026] [security2:error] [pid 925208:tid 925426] [client 121.229.156.62:46596] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/past-commissions/2010-commission/"] [unique_id "al4UhsRX7OrFkv0FyuJEiAAAAFg"]
[Mon Jul 20 06:28:54.530807 2026] [security2:error] [pid 929851:tid 930090] [client 146.75.222.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4UhGV3ou772CelrLh-aAAAAO4"]
[Mon Jul 20 06:28:54.748307 2026] [security2:error] [pid 925208:tid 925404] [client 104.234.53.53:32153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UhsRX7OrFkv0FyuJEkwAAAEI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:54.935387 2026] [security2:error] [pid 925208:tid 925450] [client 14.225.17.146:50961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4UhsRX7OrFkv0FyuJEkAAAAHA"], referer: http://healthylifegourmet.org/old
[Mon Jul 20 06:28:55.012168 2026] [security2:error] [pid 925208:tid 925455] [client 104.234.53.53:32153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEnAAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:55.279631 2026] [security2:error] [pid 925208:tid 925442] [client 45.116.69.230:57732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEqQAAAGg"]
[Mon Jul 20 06:28:55.280380 2026] [security2:error] [pid 925208:tid 925442] [client 45.116.69.230:57732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEqQAAAGg"]
[Mon Jul 20 06:28:55.300336 2026] [security2:error] [pid 929851:tid 930095] [client 103.141.108.143:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh2V3ou772CelrLh-_gAAAPM"]
[Mon Jul 20 06:28:55.301399 2026] [security2:error] [pid 929851:tid 930095] [client 103.141.108.143:56243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Uh2V3ou772CelrLh-_gAAAPM"]
[Mon Jul 20 06:28:55.363084 2026] [security2:error] [pid 925208:tid 925441] [client 14.225.17.146:63629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEqwAAAGc"], referer: http://friendlyspreadsheet.com/old
[Mon Jul 20 06:28:55.411469 2026] [security2:error] [pid 925208:tid 925388] [client 57.141.18.107:60046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhcRX7OrFkv0FyuJEdgAAMhQ"]
[Mon Jul 20 06:28:55.440375 2026] [security2:error] [pid 925208:tid 925446] [client 57.141.18.121:29686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhcRX7OrFkv0FyuJEdAAAbAw"]
[Mon Jul 20 06:28:55.446226 2026] [proxy:error] [pid 929851:tid 930025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.446312 2026] [proxy_http:error] [pid 929851:tid 930025] [client 34.73.38.214:57499] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:55.447017 2026] [proxy:error] [pid 929851:tid 930025] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.447047 2026] [proxy_http:error] [pid 929851:tid 930025] [client 34.73.38.214:57499] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:55.486121 2026] [security2:error] [pid 925208:tid 925329] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env"] [unique_id "al4Uh8RX7OrFkv0FyuJErQAAEHg"]
[Mon Jul 20 06:28:55.507001 2026] [security2:error] [pid 925208:tid 925289] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/rclone.conf"] [unique_id "al4Uh8RX7OrFkv0FyuJEsAAAZVA"]
[Mon Jul 20 06:28:55.507908 2026] [security2:error] [pid 925208:tid 925297] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.git/HEAD"] [unique_id "al4Uh8RX7OrFkv0FyuJEsgAAZVg"]
[Mon Jul 20 06:28:55.507908 2026] [security2:error] [pid 925208:tid 925272] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.git/config"] [unique_id "al4Uh8RX7OrFkv0FyuJEtAAAZT8"]
[Mon Jul 20 06:28:55.508104 2026] [security2:error] [pid 925208:tid 925288] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-json"] [unique_id "al4Uh8RX7OrFkv0FyuJEswAAZU8"]
[Mon Jul 20 06:28:55.508143 2026] [security2:error] [pid 925208:tid 925439] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.git/config"] [unique_id "al4Uh8RX7OrFkv0FyuJEtAAAZT8"]
[Mon Jul 20 06:28:55.508158 2026] [security2:error] [pid 925208:tid 925216] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.aws/credentials"] [unique_id "al4Uh8RX7OrFkv0FyuJEuQAAZQc"]
[Mon Jul 20 06:28:55.508277 2026] [security2:error] [pid 925208:tid 925439] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-json"] [unique_id "al4Uh8RX7OrFkv0FyuJEswAAZU8"]
[Mon Jul 20 06:28:55.719189 2026] [security2:error] [pid 929851:tid 930061] [client 14.225.17.146:51024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh_EAAAANE"], referer: http://bigwormfishing.com/old
[Mon Jul 20 06:28:55.814667 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.76:49238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhmV3ou772CelrLh-0gAAuR4"]
[Mon Jul 20 06:28:55.835241 2026] [security2:error] [pid 925208:tid 925434] [client 104.234.53.80:32141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Uh8RX7OrFkv0FyuJEwwAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:28:55.887134 2026] [security2:error] [pid 925208:tid 925245] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4Uh8RX7OrFkv0FyuJExgAAZSQ"]
[Mon Jul 20 06:28:55.887280 2026] [security2:error] [pid 925208:tid 925439] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4Uh8RX7OrFkv0FyuJExgAAZSQ"]
[Mon Jul 20 06:28:55.923925 2026] [security2:error] [pid 925208:tid 925302] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.old"] [unique_id "al4Uh8RX7OrFkv0FyuJEywAAZV0"]
[Mon Jul 20 06:28:55.924678 2026] [security2:error] [pid 925208:tid 925275] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.backup"] [unique_id "al4Uh8RX7OrFkv0FyuJEzQAAZUI"]
[Mon Jul 20 06:28:55.949721 2026] [security2:error] [pid 929851:tid 929994] [client 50.116.65.227:44506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4Uh2V3ou772CelrLh_IwAAAI4"]
[Mon Jul 20 06:28:55.963570 2026] [security2:error] [pid 929851:tid 930054] [client 50.116.65.227:25404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4Uh2V3ou772CelrLh_JQAAAIg"]
[Mon Jul 20 06:28:55.969165 2026] [proxy:error] [pid 929851:tid 930082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.969248 2026] [proxy_http:error] [pid 929851:tid 930082] [client 34.73.38.214:56028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:55.970088 2026] [proxy:error] [pid 929851:tid 930082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:55.970134 2026] [proxy_http:error] [pid 929851:tid 930082] [client 34.73.38.214:56028] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:56.009260 2026] [security2:error] [pid 929851:tid 930105] [client 14.225.17.146:50637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh_GgAAAP0"], referer: http://savilerowtravel.com/old
[Mon Jul 20 06:28:56.044969 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:63752] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4UiGV3ou772CelrLh_LAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.151631 2026] [security2:error] [pid 925208:tid 925285] [remote 72.167.132.114:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UiMRX7OrFkv0FyuJE1gAAJUw"]
[Mon Jul 20 06:28:56.195965 2026] [security2:error] [pid 929851:tid 930015] [client 57.141.18.33:33462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UhmV3ou772CelrLh-5wAAozs"]
[Mon Jul 20 06:28:56.209037 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_NQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.209162 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_NQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.298304 2026] [security2:error] [pid 925208:tid 925218] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.jeffjaeger.com"] [uri "/graphql"] [unique_id "al4UiMRX7OrFkv0FyuJE3AAAZQk"]
[Mon Jul 20 06:28:56.367408 2026] [security2:error] [pid 929851:tid 929931] [remote 57.141.18.5:32648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5956503"] [unique_id "al4UiGV3ou772CelrLh_PQAA0Es"]
[Mon Jul 20 06:28:56.368300 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:63762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_PgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.368420 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:63762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiGV3ou772CelrLh_PgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.384930 2026] [security2:error] [pid 925208:tid 925246] [remote 72.167.132.114:34620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4UiMRX7OrFkv0FyuJE4QAAWSU"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:28:56.398988 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:51594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_OgAAANU"], referer: https://friendlyspreadsheet.com/old
[Mon Jul 20 06:28:56.410352 2026] [security2:error] [pid 925208:tid 925227] [remote 216.73.216.55:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4UiMRX7OrFkv0FyuJE4wAAbhI"]
[Mon Jul 20 06:28:56.419460 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiMRX7OrFkv0FyuJE5AAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.419591 2026] [security2:error] [pid 925208:tid 925378] [client 77.110.127.138:63721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UiMRX7OrFkv0FyuJE5AAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.445810 2026] [security2:error] [pid 925208:tid 925303] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/api/.env"] [unique_id "al4UiMRX7OrFkv0FyuJE5wAAZV4"]
[Mon Jul 20 06:28:56.472008 2026] [security2:error] [pid 929851:tid 930077] [client 77.110.127.138:63720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UiGV3ou772CelrLh_RQAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:56.476738 2026] [security2:error] [pid 929851:tid 930018] [client 57.141.18.23:43138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh-9gAApmo"]
[Mon Jul 20 06:28:56.491702 2026] [security2:error] [pid 925208:tid 925334] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.jeffjaeger.com"] [uri "/api/graphql"] [unique_id "al4UiMRX7OrFkv0FyuJE6QAAZX0"]
[Mon Jul 20 06:28:56.504035 2026] [security2:error] [pid 929851:tid 930090] [client 39.48.81.23:56361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UiGV3ou772CelrLh_SAAAAO4"]
[Mon Jul 20 06:28:56.504166 2026] [security2:error] [pid 929851:tid 930090] [client 39.48.81.23:56361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UiGV3ou772CelrLh_SAAAAO4"]
[Mon Jul 20 06:28:56.510536 2026] [security2:error] [pid 929851:tid 930026] [client 57.141.18.116:45412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uh2V3ou772CelrLh-9QAArkM"]
[Mon Jul 20 06:28:56.631612 2026] [security2:error] [pid 925208:tid 925300] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/backend/.env"] [unique_id "al4UiMRX7OrFkv0FyuJE9QAAd1s"]
[Mon Jul 20 06:28:56.631737 2026] [security2:error] [pid 925208:tid 925325] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/config/.env"] [unique_id "al4UiMRX7OrFkv0FyuJE9gAAd3Q"]
[Mon Jul 20 06:28:56.778628 2026] [security2:error] [pid 929851:tid 930011] [client 14.225.17.146:50646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_UgAAAJ8"], referer: https://bigwormfishing.com/old
[Mon Jul 20 06:28:56.841226 2026] [security2:error] [pid 925208:tid 925291] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "dashboard.jeffjaeger.com"] [uri "/v1/graphql"] [unique_id "al4UiMRX7OrFkv0FyuJE_QAAVVI"]
[Mon Jul 20 06:28:57.098223 2026] [security2:error] [pid 929851:tid 930091] [client 14.225.17.146:51114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_XgAAAO8"], referer: https://savilerowtravel.com/old
[Mon Jul 20 06:28:57.162250 2026] [security2:error] [pid 925208:tid 925251] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.docker/config.json"] [unique_id "al4UicRX7OrFkv0FyuJFEAAAZyo"]
[Mon Jul 20 06:28:57.162518 2026] [security2:error] [pid 925208:tid 925441] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.docker/config.json"] [unique_id "al4UicRX7OrFkv0FyuJFEAAAZyo"]
[Mon Jul 20 06:28:57.184854 2026] [security2:error] [pid 929851:tid 930066] [client 157.52.92.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UhWV3ou772CelrLh-rwAAANY"]
[Mon Jul 20 06:28:57.184857 2026] [security2:error] [pid 929851:tid 930036] [client 157.52.92.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UhWV3ou772CelrLh-rgAAALg"]
[Mon Jul 20 06:28:57.295342 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:57.295387 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:58713] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:57.295810 2026] [proxy:error] [pid 929851:tid 930085] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:28:57.295832 2026] [proxy_http:error] [pid 929851:tid 930085] [client 34.73.38.214:58713] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:28:57.504328 2026] [security2:error] [pid 925208:tid 925258] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.npmrc"] [unique_id "al4UicRX7OrFkv0FyuJFIQAAcTE"]
[Mon Jul 20 06:28:57.506572 2026] [security2:error] [pid 925208:tid 925313] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/.vscode/launch.json"] [unique_id "al4UicRX7OrFkv0FyuJFIgAAcWg"]
[Mon Jul 20 06:28:57.608817 2026] [security2:error] [pid 925208:tid 925253] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.s3cfg"] [unique_id "al4UicRX7OrFkv0FyuJFLAAAdCw"]
[Mon Jul 20 06:28:57.609008 2026] [security2:error] [pid 925208:tid 925454] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/.s3cfg"] [unique_id "al4UicRX7OrFkv0FyuJFLAAAdCw"]
[Mon Jul 20 06:28:57.609325 2026] [authz_core:error] [pid 925208:tid 925276] [remote 34.66.252.77:54426] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 06:28:57.609703 2026] [security2:error] [pid 925208:tid 925335] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.ssh/id_rsa"] [unique_id "al4UicRX7OrFkv0FyuJFJwAAdH4"]
[Mon Jul 20 06:28:57.796790 2026] [security2:error] [pid 925208:tid 925247] [remote 103.75.185.95:47570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UicRX7OrFkv0FyuJFNwAAMyY"]
[Mon Jul 20 06:28:57.796996 2026] [security2:error] [pid 925208:tid 925389] [client 103.75.185.95:47570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UicRX7OrFkv0FyuJFNwAAMyY"]
[Mon Jul 20 06:28:57.864843 2026] [security2:error] [pid 925208:tid 925323] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.ssh/id_dsa"] [unique_id "al4UicRX7OrFkv0FyuJFRAAAWnI"]
[Mon Jul 20 06:28:57.868862 2026] [security2:error] [pid 925208:tid 925237] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/id_rsa"] [unique_id "al4UicRX7OrFkv0FyuJFRgAAIxw"]
[Mon Jul 20 06:28:57.877027 2026] [security2:error] [pid 925208:tid 925316] [remote 176.56.118.182:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UicRX7OrFkv0FyuJFRQAASms"]
[Mon Jul 20 06:28:57.972236 2026] [security2:error] [pid 925208:tid 925257] [remote 95.217.78.234:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UicRX7OrFkv0FyuJFSQAAVDA"]
[Mon Jul 20 06:28:57.994019 2026] [security2:error] [pid 925208:tid 925330] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.ssh/known_hosts"] [unique_id "al4UicRX7OrFkv0FyuJFTAAAAHk"]
[Mon Jul 20 06:28:57.995480 2026] [security2:error] [pid 925208:tid 925333] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4UicRX7OrFkv0FyuJFTwAAAHw"]
[Mon Jul 20 06:28:57.995568 2026] [security2:error] [pid 925208:tid 925338] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4UicRX7OrFkv0FyuJFTwAAAHw"]
[Mon Jul 20 06:28:58.074003 2026] [security2:error] [pid 929851:tid 929865] [remote 167.233.114.32:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UimV3ou772CelrLh_kgAAwwk"]
[Mon Jul 20 06:28:58.074256 2026] [security2:error] [pid 925208:tid 925418] [client 158.173.89.95:32855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UisRX7OrFkv0FyuJFUAAAAFA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:28:58.169567 2026] [security2:error] [pid 925208:tid 925240] [remote 176.56.118.182:34758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4UisRX7OrFkv0FyuJFUgAARh8"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 06:28:58.206794 2026] [security2:error] [pid 929851:tid 930089] [client 57.141.18.115:30070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UiWV3ou772CelrLh_aAAA7XI"]
[Mon Jul 20 06:28:58.215951 2026] [security2:error] [pid 925208:tid 925222] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/privatekey.key"] [unique_id "al4UisRX7OrFkv0FyuJFVwAAGQ0"]
[Mon Jul 20 06:28:58.216247 2026] [security2:error] [pid 925208:tid 925320] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/key.pem"] [unique_id "al4UisRX7OrFkv0FyuJFVgAAGW8"]
[Mon Jul 20 06:28:58.257787 2026] [security2:error] [pid 925208:tid 925242] [remote 95.217.78.234:41320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UisRX7OrFkv0FyuJFWQAAayE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:28:58.344684 2026] [security2:error] [pid 925208:tid 925216] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/localhost.key"] [unique_id "al4UisRX7OrFkv0FyuJFZwAAaAc"]
[Mon Jul 20 06:28:58.344878 2026] [security2:error] [pid 925208:tid 925442] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/localhost.key"] [unique_id "al4UisRX7OrFkv0FyuJFZwAAaAc"]
[Mon Jul 20 06:28:58.389191 2026] [security2:error] [pid 929851:tid 929966] [remote 167.233.114.32:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UimV3ou772CelrLh_qgAA024"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:28:58.546973 2026] [security2:error] [pid 925208:tid 925259] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.aider.conf.yml"] [unique_id "al4UisRX7OrFkv0FyuJFdAAADjI"]
[Mon Jul 20 06:28:58.609371 2026] [security2:error] [pid 925208:tid 925267] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.hermes/.env"] [unique_id "al4UisRX7OrFkv0FyuJFdwAAPjo"]
[Mon Jul 20 06:28:58.609459 2026] [security2:error] [pid 925208:tid 925302] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.openclaw/.env"] [unique_id "al4UisRX7OrFkv0FyuJFeAAAPl0"]
[Mon Jul 20 06:28:58.622209 2026] [security2:error] [pid 929851:tid 930041] [client 119.8.170.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4UiGV3ou772CelrLh_XQAAvVk"], referer: https://www.aleishapenny.ca/listing/page/1140?paged=1140&view=list
[Mon Jul 20 06:28:58.758013 2026] [security2:error] [pid 925208:tid 925393] [client 77.110.127.138:63784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UisRX7OrFkv0FyuJFggAAADc"]
[Mon Jul 20 06:28:58.864385 2026] [security2:error] [pid 925208:tid 925430] [client 77.110.127.138:63710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/amp0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4UisRX7OrFkv0FyuJFhgAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.012695 2026] [security2:error] [pid 929851:tid 930056] [client 171.61.165.146:13954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ui2V3ou772CelrLh_0gAAAMw"]
[Mon Jul 20 06:28:59.020894 2026] [security2:error] [pid 929851:tid 930056] [client 171.61.165.146:13954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Ui2V3ou772CelrLh_0gAAAMw"]
[Mon Jul 20 06:28:59.026586 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_0wAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.026701 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_0wAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.060850 2026] [security2:error] [pid 925208:tid 925332] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.bashrc"] [unique_id "al4Ui8RX7OrFkv0FyuJFkgAAdns"]
[Mon Jul 20 06:28:59.109758 2026] [security2:error] [pid 925208:tid 925262] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-config.php.old"] [unique_id "al4Ui8RX7OrFkv0FyuJFkwAAdjU"]
[Mon Jul 20 06:28:59.109868 2026] [security2:error] [pid 925208:tid 925236] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "dashboard.jeffjaeger.com"] [uri "/wp-config.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFlAAAdhs"]
[Mon Jul 20 06:28:59.110023 2026] [security2:error] [pid 925208:tid 925278] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.profile"] [unique_id "al4Ui8RX7OrFkv0FyuJFlQAAdkU"]
[Mon Jul 20 06:28:59.188825 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:63788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui8RX7OrFkv0FyuJFmgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.188938 2026] [security2:error] [pid 925208:tid 925367] [client 77.110.127.138:63788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui8RX7OrFkv0FyuJFmgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.340719 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:63789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_6QAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.340834 2026] [security2:error] [pid 929851:tid 930110] [client 77.110.127.138:63789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ui2V3ou772CelrLh_6QAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.382440 2026] [security2:error] [pid 925208:tid 925235] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/laravel/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFpQAAdho"]
[Mon Jul 20 06:28:59.382463 2026] [security2:error] [pid 925208:tid 925280] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFpgAAdkc"]
[Mon Jul 20 06:28:59.393809 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:63750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1 OR 468. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 468 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ui2V3ou772CelrLh_7wAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:28:59.422074 2026] [security2:error] [pid 925208:tid 925318] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/config/.env.php"] [unique_id "al4Ui8RX7OrFkv0FyuJFpwAAdm0"]
[Mon Jul 20 06:28:59.547745 2026] [security2:error] [pid 925208:tid 925239] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/configuration.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFrQAAdh4"]
[Mon Jul 20 06:28:59.561491 2026] [security2:error] [pid 925208:tid 925270] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.swp"] [unique_id "al4Ui8RX7OrFkv0FyuJFrgAAdj0"]
[Mon Jul 20 06:28:59.563164 2026] [security2:error] [pid 925208:tid 925234] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/core/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFrwAAdhk"]
[Mon Jul 20 06:28:59.566552 2026] [security2:error] [pid 925208:tid 925265] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/config.php.bak"] [unique_id "al4Ui8RX7OrFkv0FyuJFsQAAdjg"]
[Mon Jul 20 06:28:59.566898 2026] [security2:error] [pid 925208:tid 925292] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/web/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFsAAAdlM"]
[Mon Jul 20 06:28:59.589257 2026] [security2:error] [pid 925208:tid 925243] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/public/.env"] [unique_id "al4Ui8RX7OrFkv0FyuJFtAAAdiI"]
[Mon Jul 20 06:28:59.847659 2026] [security2:error] [pid 929851:tid 930074] [client 57.141.18.125:55326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UimV3ou772CelrLh_rwAA3iU"]
[Mon Jul 20 06:28:59.906162 2026] [security2:error] [pid 925208:tid 925279] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/bootstrap.properties"] [unique_id "al4Ui8RX7OrFkv0FyuJFwgAAdkY"]
[Mon Jul 20 06:28:59.906333 2026] [security2:error] [pid 925208:tid 925456] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/bootstrap.properties"] [unique_id "al4Ui8RX7OrFkv0FyuJFwgAAdkY"]
[Mon Jul 20 06:28:59.915783 2026] [security2:error] [pid 929851:tid 930080] [client 34.73.38.214:55021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Ui2V3ou772CelrLiADQAAAOQ"]
[Mon Jul 20 06:29:00.005439 2026] [security2:error] [pid 929851:tid 930045] [client 14.225.17.146:62448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLiADAAAAME"], referer: http://39ishlife.com/old
[Mon Jul 20 06:29:00.010616 2026] [security2:error] [pid 929851:tid 930044] [client 14.225.17.146:64753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4UimV3ou772CelrLh_wwAAAMA"], referer: http://northbrookcpa.ca/old
[Mon Jul 20 06:29:00.063187 2026] [security2:error] [pid 929851:tid 929905] [remote 195.26.244.42:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UjGV3ou772CelrLiAFgAA_zE"]
[Mon Jul 20 06:29:00.222815 2026] [security2:error] [pid 929851:tid 929891] [remote 57.141.18.3:20614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4UjGV3ou772CelrLiAHwABASM"]
[Mon Jul 20 06:29:00.274539 2026] [security2:error] [pid 929851:tid 930089] [client 112.208.70.94:45668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiAIQAAAO0"]
[Mon Jul 20 06:29:00.274692 2026] [security2:error] [pid 929851:tid 930089] [client 112.208.70.94:45668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiAIQAAAO0"]
[Mon Jul 20 06:29:00.319479 2026] [security2:error] [pid 929851:tid 929926] [remote 195.26.244.42:54530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UjGV3ou772CelrLiAJAAAhkY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:00.410088 2026] [security2:error] [pid 925208:tid 925323] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/web.config"] [unique_id "al4UjMRX7OrFkv0FyuJF4AAAdnI"]
[Mon Jul 20 06:29:00.480644 2026] [security2:error] [pid 925208:tid 925315] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/appsettings.Production.json"] [unique_id "al4UjMRX7OrFkv0FyuJF4gAAdmo"]
[Mon Jul 20 06:29:00.481713 2026] [security2:error] [pid 929851:tid 930060] [client 57.141.18.23:43140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLh_4AAA0Ac"]
[Mon Jul 20 06:29:00.616257 2026] [security2:error] [pid 929851:tid 930021] [client 106.219.188.178:20187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiANgAAAKk"]
[Mon Jul 20 06:29:00.618984 2026] [security2:error] [pid 929851:tid 930021] [client 106.219.188.178:20187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UjGV3ou772CelrLiANgAAAKk"]
[Mon Jul 20 06:29:00.647526 2026] [security2:error] [pid 925208:tid 925240] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/local.settings.json"] [unique_id "al4UjMRX7OrFkv0FyuJF7QAAdh8"]
[Mon Jul 20 06:29:00.684884 2026] [security2:error] [pid 929851:tid 930015] [client 34.73.38.214:50869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UjGV3ou772CelrLiAOwAAAKM"]
[Mon Jul 20 06:29:00.746982 2026] [security2:error] [pid 929851:tid 929990] [client 57.141.18.73:27772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLh_9gAAimw"]
[Mon Jul 20 06:29:00.777845 2026] [security2:error] [pid 929851:tid 930017] [client 77.110.127.138:63798] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/amp0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4UjGV3ou772CelrLiAQQAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.869613 2026] [security2:error] [pid 929851:tid 929997] [client 57.141.18.43:21516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ui2V3ou772CelrLh_-AAAkTM"]
[Mon Jul 20 06:29:00.891617 2026] [security2:error] [pid 929851:tid 930086] [client 104.234.53.52:36377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UjGV3ou772CelrLiARAAAAOo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:00.934061 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjMRX7OrFkv0FyuJF-AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.934175 2026] [security2:error] [pid 925208:tid 925372] [client 77.110.127.138:63799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjMRX7OrFkv0FyuJF-AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.984499 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjGV3ou772CelrLiASwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:00.984620 2026] [security2:error] [pid 929851:tid 930047] [client 77.110.127.138:63720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjGV3ou772CelrLiASwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:01.006461 2026] [security2:error] [pid 929851:tid 930010] [client 14.225.17.146:56612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4UjGV3ou772CelrLiARgAAAJ4"], referer: https://39ishlife.com/old
[Mon Jul 20 06:29:01.007864 2026] [fcgid:warn] [pid 925208:tid 925459] (70014)End of file found: [client 66.132.195.53:60508] mod_fcgid: can't get data from http client
[Mon Jul 20 06:29:01.276136 2026] [security2:error] [pid 925208:tid 925331] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/server/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGDQAAdno"]
[Mon Jul 20 06:29:01.276172 2026] [security2:error] [pid 925208:tid 925248] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/app/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGDAAAdic"]
[Mon Jul 20 06:29:01.276235 2026] [security2:error] [pid 925208:tid 925310] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/dev/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGCgAAdmU"]
[Mon Jul 20 06:29:01.276337 2026] [security2:error] [pid 925208:tid 925268] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/frontend/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGCwAAdjs"]
[Mon Jul 20 06:29:01.294299 2026] [security2:error] [pid 925208:tid 925261] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/src/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGEQAAdjQ"]
[Mon Jul 20 06:29:01.439868 2026] [security2:error] [pid 925208:tid 925296] [remote 216.73.216.55:48689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4UjcRX7OrFkv0FyuJGHgAAOFc"]
[Mon Jul 20 06:29:01.449884 2026] [security2:error] [pid 925208:tid 925252] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/production/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGIgAAdis"]
[Mon Jul 20 06:29:01.450132 2026] [security2:error] [pid 925208:tid 925309] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/staging/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGIwAAdmQ"]
[Mon Jul 20 06:29:01.450154 2026] [security2:error] [pid 925208:tid 925336] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.production.bak"] [unique_id "al4UjcRX7OrFkv0FyuJGHwAAdn8"]
[Mon Jul 20 06:29:01.450283 2026] [security2:error] [pid 925208:tid 925319] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/docker/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGIAAAdm4"]
[Mon Jul 20 06:29:01.450804 2026] [security2:error] [pid 925208:tid 925285] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/.env.prod.bak"] [unique_id "al4UjcRX7OrFkv0FyuJGIQAAdkw"]
[Mon Jul 20 06:29:01.569012 2026] [security2:error] [pid 925208:tid 925401] [client 14.225.17.146:62469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4UjMRX7OrFkv0FyuJF2QAAAD8"]
[Mon Jul 20 06:29:01.585961 2026] [security2:error] [pid 925208:tid 925306] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/@fs/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGKAAAdmE"]
[Mon Jul 20 06:29:01.598938 2026] [security2:error] [pid 929851:tid 929988] [client 104.210.140.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cathybuffini.com"] [uri "/index.php"] [unique_id "al4UjGV3ou772CelrLiAMgAAAIg"]
[Mon Jul 20 06:29:01.642436 2026] [security2:error] [pid 925208:tid 925332] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/keys/service-account.json"] [unique_id "al4UjcRX7OrFkv0FyuJGKwAAdns"]
[Mon Jul 20 06:29:01.642491 2026] [security2:error] [pid 925208:tid 925305] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/sa.json"] [unique_id "al4UjcRX7OrFkv0FyuJGLQAAdmA"]
[Mon Jul 20 06:29:01.642738 2026] [security2:error] [pid 925208:tid 925456] [client 34.66.252.77:54426] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/sa.json"] [unique_id "al4UjcRX7OrFkv0FyuJGLQAAdmA"]
[Mon Jul 20 06:29:01.644020 2026] [security2:error] [pid 925208:tid 925227] [remote 34.66.252.77:54426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/@fs/root/.env"] [unique_id "al4UjcRX7OrFkv0FyuJGLgAAdhI"]
[Mon Jul 20 06:29:01.644180 2026] [security2:error] [pid 925208:tid 925246] [remote 34.66.252.77:54426] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "dashboard.jeffjaeger.com"] [uri "/@fs/proc/self/environ"] [unique_id "al4UjcRX7OrFkv0FyuJGMAAAdiU"]
[Mon Jul 20 06:29:01.824785 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjWV3ou772CelrLiAdgAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:01.824869 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:63802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UjWV3ou772CelrLiAdgAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:01.882248 2026] [security2:error] [pid 929851:tid 929999] [client 77.110.127.138:63764] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1) OR 454. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 454 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UjWV3ou772CelrLiAeQAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:02.235436 2026] [security2:error] [pid 925208:tid 925352] [client 57.141.18.117:50494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjMRX7OrFkv0FyuJF9gAADlk"]
[Mon Jul 20 06:29:02.388401 2026] [security2:error] [pid 929851:tid 930020] [client 50.116.65.227:50064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UjmV3ou772CelrLiAoAAAAKg"]
[Mon Jul 20 06:29:02.399194 2026] [security2:error] [pid 929851:tid 930059] [client 50.116.65.227:50066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UjmV3ou772CelrLiAoQAAAM8"]
[Mon Jul 20 06:29:02.432999 2026] [security2:error] [pid 925208:tid 925347] [client 34.73.38.214:62388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UjsRX7OrFkv0FyuJGQgAAAAk"]
[Mon Jul 20 06:29:02.556853 2026] [security2:error] [pid 929851:tid 929864] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/config.json"] [unique_id "al4UjmV3ou772CelrLiAswAAwQg"]
[Mon Jul 20 06:29:02.807380 2026] [security2:error] [pid 929851:tid 929963] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/env.json"] [unique_id "al4UjmV3ou772CelrLiAzAAAwWs"]
[Mon Jul 20 06:29:02.886952 2026] [security2:error] [pid 929851:tid 930021] [client 223.109.252.223:54666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2014/02/mezza41-300x300.jpg"] [unique_id "al4UjmV3ou772CelrLiA1AAAAKk"]
[Mon Jul 20 06:29:02.887094 2026] [security2:error] [pid 929851:tid 930021] [client 223.109.252.223:54666] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2014/02/mezza41-300x300.jpg"] [unique_id "al4UjmV3ou772CelrLiA1AAAAKk"]
[Mon Jul 20 06:29:02.941404 2026] [security2:error] [pid 929851:tid 930079] [client 50.116.65.227:50090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiAxwAAAOM"]
[Mon Jul 20 06:29:03.122983 2026] [security2:error] [pid 929851:tid 930033] [client 50.116.65.227:50094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiA2QAAALU"]
[Mon Jul 20 06:29:03.128833 2026] [security2:error] [pid 929851:tid 930056] [client 104.248.167.239:43176] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "phillipbloch.com"] [uri "/"] [unique_id "al4Uj2V3ou772CelrLiA4QAAAMw"]
[Mon Jul 20 06:29:03.247276 2026] [security2:error] [pid 929851:tid 930095] [client 57.141.18.10:26480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjWV3ou772CelrLiAewAA8yQ"]
[Mon Jul 20 06:29:03.382714 2026] [security2:error] [pid 929851:tid 929940] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/openapi.json"] [unique_id "al4Uj2V3ou772CelrLiA-QAAwVQ"]
[Mon Jul 20 06:29:03.382926 2026] [security2:error] [pid 929851:tid 930045] [client 34.66.252.77:54436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/openapi.json"] [unique_id "al4Uj2V3ou772CelrLiA-QAAwVQ"]
[Mon Jul 20 06:29:03.560991 2026] [security2:error] [pid 929851:tid 930055] [client 57.141.18.21:31996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiAjgAAyzs"]
[Mon Jul 20 06:29:03.753893 2026] [security2:error] [pid 929851:tid 929896] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/app-config.json"] [unique_id "al4Uj2V3ou772CelrLiBGQAApCg"]
[Mon Jul 20 06:29:03.791876 2026] [security2:error] [pid 929851:tid 930087] [client 106.8.138.135:50369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiA3wAAAOs"], referer: http://bandsir.com/
[Mon Jul 20 06:29:03.841580 2026] [security2:error] [pid 929851:tid 929993] [client 114.119.137.237:36211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4Uj2V3ou772CelrLiBIgAAAI0"], referer: https://newstral.com/en/article/en/953742537/gonzales-middle-teacher-receives-ascension-fund-grant
[Mon Jul 20 06:29:03.870162 2026] [security2:error] [pid 929851:tid 929861] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/api/v1/env"] [unique_id "al4Uj2V3ou772CelrLiBJAAA4gU"]
[Mon Jul 20 06:29:03.921456 2026] [security2:error] [pid 925208:tid 925343] [client 34.73.38.214:61772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Uj8RX7OrFkv0FyuJGXgAAAAU"]
[Mon Jul 20 06:29:03.928702 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.107:38730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjmV3ou772CelrLiAxQAA20E"]
[Mon Jul 20 06:29:04.028421 2026] [security2:error] [pid 929851:tid 929885] [remote 209.121.27.247:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiBGwAA_R0"]
[Mon Jul 20 06:29:04.086742 2026] [security2:error] [pid 925208:tid 925386] [client 57.141.18.121:29576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UjsRX7OrFkv0FyuJGSgAAMBo"]
[Mon Jul 20 06:29:04.213966 2026] [security2:error] [pid 929851:tid 929907] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/ngsw.json"] [unique_id "al4UkGV3ou772CelrLiBRAAAkzM"]
[Mon Jul 20 06:29:04.214110 2026] [security2:error] [pid 929851:tid 929999] [client 34.66.252.77:54436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/ngsw.json"] [unique_id "al4UkGV3ou772CelrLiBRAAAkzM"]
[Mon Jul 20 06:29:04.215013 2026] [security2:error] [pid 929851:tid 929964] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/service-worker.js"] [unique_id "al4UkGV3ou772CelrLiBQQAAk2w"]
[Mon Jul 20 06:29:04.357361 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBUAAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.357504 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBUAAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.405233 2026] [security2:error] [pid 929851:tid 930000] [client 57.141.18.8:26030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiA8gAAlHk"]
[Mon Jul 20 06:29:04.514132 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBXgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.514237 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:63822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBXgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.572597 2026] [security2:error] [pid 929851:tid 929938] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/test.php"] [unique_id "al4UkGV3ou772CelrLiBZgAAklI"]
[Mon Jul 20 06:29:04.575252 2026] [security2:error] [pid 925208:tid 925458] [client 57.141.18.64:40058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uj8RX7OrFkv0FyuJGXAAAeD0"]
[Mon Jul 20 06:29:04.579310 2026] [security2:error] [pid 929851:tid 929920] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/phpinfo.php"] [unique_id "al4UkGV3ou772CelrLiBaAAAq0A"]
[Mon Jul 20 06:29:04.592971 2026] [security2:error] [pid 929851:tid 929912] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/pi.php"] [unique_id "al4UkGV3ou772CelrLiBaQAAjDg"]
[Mon Jul 20 06:29:04.603322 2026] [security2:error] [pid 929851:tid 929870] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/info.php"] [unique_id "al4UkGV3ou772CelrLiBdAAApg4"]
[Mon Jul 20 06:29:04.603527 2026] [security2:error] [pid 929851:tid 929953] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/i.php"] [unique_id "al4UkGV3ou772CelrLiBdwAApmE"]
[Mon Jul 20 06:29:04.676946 2026] [security2:error] [pid 925208:tid 925362] [client 171.60.139.123:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UkMRX7OrFkv0FyuJGegAAABg"]
[Mon Jul 20 06:29:04.677124 2026] [security2:error] [pid 925208:tid 925362] [client 171.60.139.123:49424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UkMRX7OrFkv0FyuJGegAAABg"]
[Mon Jul 20 06:29:04.682137 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:63824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBlgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.682225 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:63824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UkGV3ou772CelrLiBlgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.727635 2026] [security2:error] [pid 929851:tid 930001] [client 57.141.18.91:32220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uj2V3ou772CelrLiBEAAAlVA"]
[Mon Jul 20 06:29:04.832003 2026] [security2:error] [pid 929851:tid 930054] [client 77.110.127.138:63825] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1)) OR 372. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 372 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UkGV3ou772CelrLiBrAAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:04.850496 2026] [security2:error] [pid 929851:tid 929915] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/app_dev.php/_profiler"] [unique_id "al4UkGV3ou772CelrLiBrwAAkzs"]
[Mon Jul 20 06:29:04.851224 2026] [security2:error] [pid 929851:tid 929958] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.252.66.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dashboard.jeffjaeger.com"] [uri "/app_dev.php"] [unique_id "al4UkGV3ou772CelrLiBtQAAk2Y"]
[Mon Jul 20 06:29:04.852430 2026] [security2:error] [pid 929851:tid 929906] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "dashboard.jeffjaeger.com"] [uri "/trace.axd"] [unique_id "al4UkGV3ou772CelrLiBsgAAkzI"]
[Mon Jul 20 06:29:04.904643 2026] [access_compat:error] [pid 929851:tid 929857] [remote 34.66.252.77:54436] AH01797: client denied by server configuration: /var/www/html/server-status
[Mon Jul 20 06:29:04.979071 2026] [security2:error] [pid 929851:tid 929896] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "dashboard.jeffjaeger.com"] [uri "/server-info"] [unique_id "al4UkGV3ou772CelrLiBxgAA8ig"]
[Mon Jul 20 06:29:04.999035 2026] [security2:error] [pid 929851:tid 929894] [remote 34.66.252.77:54436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dashboard.jeffjaeger.com"] [uri "/nginx_status"] [unique_id "al4UkGV3ou772CelrLiByQAAlCY"]
[Mon Jul 20 06:29:04.999300 2026] [security2:error] [pid 929851:tid 930000] [client 34.66.252.77:54436] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "dashboard.jeffjaeger.com"] [uri "/nginx_status"] [unique_id "al4UkGV3ou772CelrLiByQAAlCY"]
[Mon Jul 20 06:29:05.059086 2026] [security2:error] [pid 929851:tid 930026] [client 98.159.234.160:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UkWV3ou772CelrLiBzQAAAK4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:05.157081 2026] [security2:error] [pid 929851:tid 929987] [client 223.185.13.213:31164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UkWV3ou772CelrLiB0AAAAIc"]
[Mon Jul 20 06:29:05.157181 2026] [security2:error] [pid 929851:tid 929987] [client 223.185.13.213:31164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UkWV3ou772CelrLiB0AAAAIc"]
[Mon Jul 20 06:29:05.288178 2026] [security2:error] [pid 925208:tid 925213] [remote 97.74.93.24:52980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UkcRX7OrFkv0FyuJGiQAAOQQ"]
[Mon Jul 20 06:29:05.412018 2026] [security2:error] [pid 925208:tid 925211] [remote 152.228.213.32:46332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UkcRX7OrFkv0FyuJGjwAALgI"]
[Mon Jul 20 06:29:05.566145 2026] [security2:error] [pid 929851:tid 930097] [client 104.207.61.204:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UkWV3ou772CelrLiB5QAAAPU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:05.598992 2026] [security2:error] [pid 925208:tid 925313] [remote 152.228.213.32:46332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4UkcRX7OrFkv0FyuJGmgAAA2g"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:29:05.703186 2026] [security2:error] [pid 929851:tid 930028] [client 57.141.18.71:33906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UkGV3ou772CelrLiBigAAsFU"]
[Mon Jul 20 06:29:05.752381 2026] [security2:error] [pid 929851:tid 929974] [remote 167.233.114.32:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UkWV3ou772CelrLiB_AAA-nY"]
[Mon Jul 20 06:29:05.930184 2026] [security2:error] [pid 929851:tid 930072] [client 14.225.17.146:56470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiB_gAAANw"], referer: http://ghivs.com/old
[Mon Jul 20 06:29:05.960643 2026] [security2:error] [pid 929851:tid 929979] [remote 167.233.114.32:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UkWV3ou772CelrLiCBwAA5Xs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:06.038337 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCEAAAAQQ"]
[Mon Jul 20 06:29:06.038469 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:56725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCEAAAAQQ"]
[Mon Jul 20 06:29:06.038744 2026] [security2:error] [pid 925208:tid 925294] [remote 97.74.93.24:52980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UksRX7OrFkv0FyuJGqQAAS1U"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:29:06.059793 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:58414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCFAAAAPk"]
[Mon Jul 20 06:29:06.059937 2026] [security2:error] [pid 929851:tid 930101] [client 45.116.69.230:58414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UkmV3ou772CelrLiCFAAAAPk"]
[Mon Jul 20 06:29:06.164212 2026] [security2:error] [pid 929851:tid 930083] [client 45.3.45.220:50101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UkmV3ou772CelrLiCGAAAAOc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:06.309070 2026] [security2:error] [pid 925208:tid 925382] [client 14.225.17.146:51422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4UksRX7OrFkv0FyuJGrwAAACw"], referer: http://whiteoutcb.com/old
[Mon Jul 20 06:29:06.465528 2026] [security2:error] [pid 925208:tid 925462] [client 34.73.38.214:58583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UksRX7OrFkv0FyuJGtAAAAHw"]
[Mon Jul 20 06:29:06.578341 2026] [security2:error] [pid 929851:tid 930058] [client 74.7.230.44:55552] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4UkmV3ou772CelrLiCLAAAzgQ"]
[Mon Jul 20 06:29:06.650811 2026] [security2:error] [pid 929851:tid 930036] [client 57.141.18.116:59598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiB3wAAuEc"]
[Mon Jul 20 06:29:06.656932 2026] [security2:error] [pid 929851:tid 929897] [remote 102.134.101.35:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4UkmV3ou772CelrLiCMgAAqyk"]
[Mon Jul 20 06:29:07.094773 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UkmV3ou772CelrLiCNgAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.142907 2026] [security2:error] [pid 929851:tid 929929] [remote 102.134.101.35:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Uk2V3ou772CelrLiCTgAAmUk"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:29:07.224558 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.224674 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.282125 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.282259 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCVwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.334665 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCWQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.334818 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCWQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.386967 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:63814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1G0cZ0do9' OR 47. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 47 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Uk2V3ou772CelrLiCXAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.423814 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCYgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.423947 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:63850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCYgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.459677 2026] [security2:error] [pid 929851:tid 930089] [client 213.152.162.79:35872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Uk2V3ou772CelrLiCZQAAAO0"]
[Mon Jul 20 06:29:07.459780 2026] [security2:error] [pid 929851:tid 930089] [client 213.152.162.79:35872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4Uk2V3ou772CelrLiCZQAAAO0"]
[Mon Jul 20 06:29:07.502299 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCawAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.502430 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:63851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCawAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.585733 2026] [security2:error] [pid 929851:tid 930029] [client 45.3.55.217:25653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Uk2V3ou772CelrLiCbgAAALE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:07.626842 2026] [security2:error] [pid 929851:tid 930075] [client 14.225.17.146:51406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiCAwAAAN8"], referer: http://according2plant.com/old
[Mon Jul 20 06:29:07.654310 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:63854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG2QAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.654465 2026] [security2:error] [pid 925208:tid 925411] [client 77.110.127.138:63854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG2QAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.672907 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:63855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCeAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.673011 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:63855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCeAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.760078 2026] [security2:error] [pid 925208:tid 925320] [remote 74.235.96.117:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG2gAAQW8"]
[Mon Jul 20 06:29:07.771425 2026] [security2:error] [pid 929851:tid 930079] [client 104.234.53.65:58319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Uk2V3ou772CelrLiCfgAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:07.783527 2026] [security2:error] [pid 929851:tid 930047] [client 14.225.17.146:56621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4UkWV3ou772CelrLiB9wAAAMM"], referer: http://mollycahill.com/old
[Mon Jul 20 06:29:07.821467 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCgAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.821583 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:63857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCgAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.852452 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiChAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.852614 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:63858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiChAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.939596 2026] [security2:error] [pid 925208:tid 925242] [remote 74.235.96.117:44904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Uk8RX7OrFkv0FyuJG3gAAGyE"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:29:07.968520 2026] [security2:error] [pid 925208:tid 925427] [client 57.141.18.100:31576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UksRX7OrFkv0FyuJGuAAAWUQ"]
[Mon Jul 20 06:29:07.981390 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCjQAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.981525 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:63859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uk2V3ou772CelrLiCjQAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:07.992731 2026] [core:error] [pid 929851:tid 929995] [client 103.153.183.69:41802] AH10244: invalid URI path (/%2e%2e/.env?_=3r1d02sa&v=21mjx), referer: https://twitter.com/
[Mon Jul 20 06:29:08.034504 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:63860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiClAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:08.034593 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:63860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiClAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:08.111635 2026] [security2:error] [pid 929851:tid 929971] [remote 160.187.68.132:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UlGV3ou772CelrLiCmAAA9HM"]
[Mon Jul 20 06:29:08.124492 2026] [security2:error] [pid 929851:tid 930073] [client 14.225.17.146:62388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4UkmV3ou772CelrLiCJgAAAN0"], referer: http://swafforddetailing.com/old
[Mon Jul 20 06:29:08.220949 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCrAAAAPE"]
[Mon Jul 20 06:29:08.221046 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:63861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCrAAAAPE"]
[Mon Jul 20 06:29:08.339037 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCswAAAIc"]
[Mon Jul 20 06:29:08.339150 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:63862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCswAAAIc"]
[Mon Jul 20 06:29:08.373667 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCtgAAAOc"]
[Mon Jul 20 06:29:08.373796 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:63863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlGV3ou772CelrLiCtgAAAOc"]
[Mon Jul 20 06:29:08.430801 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlMRX7OrFkv0FyuJG6QAAAFU"]
[Mon Jul 20 06:29:08.430947 2026] [security2:error] [pid 925208:tid 925423] [client 77.110.127.138:63833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlMRX7OrFkv0FyuJG6QAAAFU"]
[Mon Jul 20 06:29:08.613804 2026] [security2:error] [pid 929851:tid 930048] [client 39.48.81.23:56848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UlGV3ou772CelrLiCwgAAAMQ"]
[Mon Jul 20 06:29:08.613923 2026] [security2:error] [pid 929851:tid 930048] [client 39.48.81.23:56848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UlGV3ou772CelrLiCwgAAAMQ"]
[Mon Jul 20 06:29:08.619511 2026] [security2:error] [pid 929851:tid 929866] [remote 160.187.68.132:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UlGV3ou772CelrLiCwQAAqAo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:29:08.780712 2026] [security2:error] [pid 925208:tid 925358] [client 34.73.38.214:55326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UlMRX7OrFkv0FyuJG9QAAABQ"]
[Mon Jul 20 06:29:08.873491 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:62285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4Uk2V3ou772CelrLiCcAAAANU"], referer: http://elitetax-mi.com/old
[Mon Jul 20 06:29:09.094497 2026] [security2:error] [pid 925208:tid 925418] [client 14.225.17.146:56324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4UlMRX7OrFkv0FyuJG-wAAAFA"]
[Mon Jul 20 06:29:09.205810 2026] [security2:error] [pid 925208:tid 925354] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UlMRX7OrFkv0FyuJHBAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:09.494056 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlWV3ou772CelrLiC6QAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:09.494194 2026] [security2:error] [pid 929851:tid 930085] [client 77.110.127.138:63873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UlWV3ou772CelrLiC6QAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:09.703388 2026] [security2:error] [pid 929851:tid 930012] [client 57.141.18.59:62880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlGV3ou772CelrLiCrgAAoDo"]
[Mon Jul 20 06:29:09.775299 2026] [security2:error] [pid 929851:tid 930042] [client 57.141.18.16:60922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlGV3ou772CelrLiCtQAAvg8"]
[Mon Jul 20 06:29:09.834461 2026] [security2:error] [pid 925208:tid 925331] [remote 186.10.194.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4UlcRX7OrFkv0FyuJHFwAAMHo"], referer: https://tiokubito.cl/page/3/?s=%2B18&post_type=product
[Mon Jul 20 06:29:10.029607 2026] [security2:error] [pid 925208:tid 925421] [client 171.61.165.146:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UlsRX7OrFkv0FyuJHIwAAAFM"]
[Mon Jul 20 06:29:10.029703 2026] [security2:error] [pid 925208:tid 925421] [client 171.61.165.146:10185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UlsRX7OrFkv0FyuJHIwAAAFM"]
[Mon Jul 20 06:29:10.099000 2026] [security2:error] [pid 929851:tid 929899] [remote 130.185.118.215:44160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UlmV3ou772CelrLiDDgAA3Ss"]
[Mon Jul 20 06:29:10.297482 2026] [security2:error] [pid 929851:tid 929943] [remote 130.185.118.215:44160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4UlmV3ou772CelrLiDJAAA71c"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:29:10.630674 2026] [security2:error] [pid 929851:tid 930070] [client 77.110.127.138:63883] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1JOB0LpeT') OR 771. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 771 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UlmV3ou772CelrLiDRAAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.062578 2026] [security2:error] [pid 929851:tid 930056] [client 34.73.38.214:64960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ul2V3ou772CelrLiDcgAAAMw"]
[Mon Jul 20 06:29:11.158628 2026] [security2:error] [pid 929851:tid 930090] [client 57.141.18.80:33016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlWV3ou772CelrLiC9wAA7lk"]
[Mon Jul 20 06:29:11.291274 2026] [security2:error] [pid 929851:tid 930096] [client 106.219.188.178:27751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ul2V3ou772CelrLiDgQAAAPQ"]
[Mon Jul 20 06:29:11.291386 2026] [security2:error] [pid 929851:tid 930096] [client 106.219.188.178:27751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ul2V3ou772CelrLiDgQAAAPQ"]
[Mon Jul 20 06:29:11.366137 2026] [security2:error] [pid 929851:tid 930060] [client 103.153.183.69:33744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4Ul2V3ou772CelrLiDjAAAANA"], referer: https://duckduckgo.com/?q=5q9yk
[Mon Jul 20 06:29:11.459977 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDkgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.460135 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDkgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.472589 2026] [security2:error] [pid 929851:tid 930086] [client 74.208.214.194:43802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Ul2V3ou772CelrLiDlQAAAOo"]
[Mon Jul 20 06:29:11.612758 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDngAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.612849 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ul2V3ou772CelrLiDngAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:11.675471 2026] [security2:error] [pid 929851:tid 930010] [client 57.141.18.30:65110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UlmV3ou772CelrLiDKwAAniY"]
[Mon Jul 20 06:29:12.108005 2026] [security2:error] [pid 929851:tid 929959] [remote 95.217.78.234:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UmGV3ou772CelrLiDxAAA8Gc"]
[Mon Jul 20 06:29:12.385151 2026] [security2:error] [pid 929851:tid 929886] [remote 95.217.78.234:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UmGV3ou772CelrLiD4gABAB4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:29:12.425626 2026] [security2:error] [pid 929851:tid 929987] [client 34.73.38.214:64125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UmGV3ou772CelrLiD6AAAAIc"]
[Mon Jul 20 06:29:12.452818 2026] [security2:error] [pid 929851:tid 930028] [client 47.128.37.62:56884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "dollpassionista.com"] [uri "/robots.txt"] [unique_id "al4UmGV3ou772CelrLiD7wAAALA"]
[Mon Jul 20 06:29:12.741015 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiD9wAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:12.856166 2026] [security2:error] [pid 929851:tid 929889] [remote 91.142.222.105:48226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4UmGV3ou772CelrLiECgAAwCE"]
[Mon Jul 20 06:29:12.864543 2026] [security2:error] [pid 929851:tid 930006] [client 112.208.70.94:42090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UmGV3ou772CelrLiEDwAAAJo"]
[Mon Jul 20 06:29:12.864739 2026] [security2:error] [pid 929851:tid 930006] [client 112.208.70.94:42090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UmGV3ou772CelrLiEDwAAAJo"]
[Mon Jul 20 06:29:12.998160 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UmGV3ou772CelrLiEGwAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:12.998279 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:63895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UmGV3ou772CelrLiEGwAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:13.130523 2026] [security2:error] [pid 929851:tid 929970] [remote 91.142.222.105:48226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4UmWV3ou772CelrLiEIwABA3I"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:29:13.271546 2026] [security2:error] [pid 929851:tid 930005] [client 223.185.13.213:2277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiEMAAAAJk"]
[Mon Jul 20 06:29:13.271680 2026] [security2:error] [pid 929851:tid 930005] [client 223.185.13.213:2277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiEMAAAAJk"]
[Mon Jul 20 06:29:13.280816 2026] [security2:error] [pid 929851:tid 930109] [client 14.225.17.146:64970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4Ul2V3ou772CelrLiDowAAAQE"], referer: http://headachescarpaltunnelfibromyalgia.com/old
[Mon Jul 20 06:29:13.310213 2026] [security2:error] [pid 929851:tid 930009] [client 50.116.65.227:11176] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UmWV3ou772CelrLiEMQAAAJ0"]
[Mon Jul 20 06:29:13.321707 2026] [security2:error] [pid 929851:tid 930071] [client 50.116.65.227:11180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UmWV3ou772CelrLiEMwAAANs"]
[Mon Jul 20 06:29:13.338413 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.43:40600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiD3gAAwUs"]
[Mon Jul 20 06:29:13.389743 2026] [security2:error] [pid 929851:tid 930043] [client 165.165.114.112:6090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiDvwAAAL8"]
[Mon Jul 20 06:29:13.469562 2026] [security2:error] [pid 929851:tid 929940] [remote 91.142.222.105:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UmWV3ou772CelrLiESAAAhVQ"]
[Mon Jul 20 06:29:13.540061 2026] [security2:error] [pid 929851:tid 930104] [client 65.1.132.125:41130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiESwAAAPw"]
[Mon Jul 20 06:29:13.540165 2026] [security2:error] [pid 929851:tid 930104] [client 65.1.132.125:41130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UmWV3ou772CelrLiESwAAAPw"]
[Mon Jul 20 06:29:13.738259 2026] [security2:error] [pid 929851:tid 929925] [remote 91.142.222.105:50052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4UmWV3ou772CelrLiEXAAA6UU"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:29:13.945270 2026] [security2:error] [pid 929851:tid 930005] [client 216.73.217.138:59290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4UmWV3ou772CelrLiEXgAAmV4"]
[Mon Jul 20 06:29:13.952111 2026] [security2:error] [pid 929851:tid 930112] [client 34.73.38.214:53478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UmWV3ou772CelrLiEaQAAAQQ"]
[Mon Jul 20 06:29:13.975152 2026] [security2:error] [pid 929851:tid 930076] [client 103.153.183.69:33744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4UmWV3ou772CelrLiEawAAAOA"], referer: https://twitter.com/
[Mon Jul 20 06:29:13.994215 2026] [security2:error] [pid 929851:tid 930006] [client 14.225.17.146:62781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4UmWV3ou772CelrLiEYQAAAJo"]
[Mon Jul 20 06:29:14.144867 2026] [security2:error] [pid 929851:tid 930055] [client 14.225.17.146:62255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEbQAAAMs"], referer: http://christiancountytrumpet.com/old
[Mon Jul 20 06:29:14.152122 2026] [security2:error] [pid 929851:tid 930025] [client 57.141.18.98:34694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmGV3ou772CelrLiEFwAArRI"]
[Mon Jul 20 06:29:14.366165 2026] [security2:error] [pid 929851:tid 930059] [client 104.234.53.70:28603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UmmV3ou772CelrLiEgQAAAM8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:14.573288 2026] [security2:error] [pid 929851:tid 930024] [client 14.225.17.146:63176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEeQAAAKw"], referer: http://massagelacey.com/old
[Mon Jul 20 06:29:14.696709 2026] [security2:error] [pid 929851:tid 929985] [client 103.153.183.69:33744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4UmmV3ou772CelrLiEpgAAAIU"], referer: https://www.reddit.com/
[Mon Jul 20 06:29:14.865801 2026] [security2:error] [pid 929851:tid 930100] [client 213.152.162.79:49352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UmmV3ou772CelrLiEtQAAAPg"]
[Mon Jul 20 06:29:14.865960 2026] [security2:error] [pid 929851:tid 930100] [client 213.152.162.79:49352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UmmV3ou772CelrLiEtQAAAPg"]
[Mon Jul 20 06:29:15.000042 2026] [security2:error] [pid 929851:tid 929992] [client 104.234.53.80:22573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UmmV3ou772CelrLiEwgAAAIw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:15.225828 2026] [security2:error] [pid 929851:tid 930054] [client 57.141.18.65:59224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEbwAAyhg"]
[Mon Jul 20 06:29:15.247473 2026] [security2:error] [pid 929851:tid 930046] [client 34.73.38.214:52023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Um2V3ou772CelrLiE3wAAAMI"]
[Mon Jul 20 06:29:15.368127 2026] [security2:error] [pid 929851:tid 930019] [client 171.60.139.123:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Um2V3ou772CelrLiE4gAAAKc"]
[Mon Jul 20 06:29:15.368309 2026] [security2:error] [pid 929851:tid 930019] [client 171.60.139.123:49958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Um2V3ou772CelrLiE4gAAAKc"]
[Mon Jul 20 06:29:15.541172 2026] [security2:error] [pid 929851:tid 930008] [client 57.141.18.22:56068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UmmV3ou772CelrLiEfAAAnAE"]
[Mon Jul 20 06:29:15.558496 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:63909] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1bRTmkNaz')) OR 565. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 565 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Um2V3ou772CelrLiE7wAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:15.578927 2026] [security2:error] [pid 929851:tid 930106] [client 34.73.38.214:58539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Um2V3ou772CelrLiE8wAAAP4"]
[Mon Jul 20 06:29:15.987843 2026] [security2:error] [pid 929851:tid 929985] [client 57.141.18.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Um2V3ou772CelrLiFBAAAAIU"]
[Mon Jul 20 06:29:16.138807 2026] [security2:error] [pid 929851:tid 930070] [client 104.234.53.75:21059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UnGV3ou772CelrLiFHwAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:16.375642 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFLAAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.375765 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:63920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFLAAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.540238 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.540365 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:63921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.568175 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.568311 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:63922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFMwAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.576944 2026] [security2:error] [pid 929851:tid 930105] [client 57.141.18.57:42034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Um2V3ou772CelrLiE4QAA_XQ"]
[Mon Jul 20 06:29:16.656477 2026] [security2:error] [pid 929851:tid 930018] [client 103.141.108.143:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFPQAAAKY"]
[Mon Jul 20 06:29:16.656796 2026] [security2:error] [pid 929851:tid 930018] [client 103.141.108.143:57207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFPQAAAKY"]
[Mon Jul 20 06:29:16.710409 2026] [security2:error] [pid 929851:tid 930042] [client 14.225.17.146:62900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4Um2V3ou772CelrLiE2QAAAL4"], referer: http://709fx.com/old
[Mon Jul 20 06:29:16.764925 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:58971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFTgAAAMU"]
[Mon Jul 20 06:29:16.765085 2026] [security2:error] [pid 929851:tid 930049] [client 45.116.69.230:58971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UnGV3ou772CelrLiFTgAAAMU"]
[Mon Jul 20 06:29:16.874978 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFVAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:16.875076 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnGV3ou772CelrLiFVAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.149244 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFbAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.149344 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:63926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFbAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.188489 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFcgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.188602 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:63927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFcgAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.245096 2026] [security2:error] [pid 929851:tid 930027] [client 34.73.38.214:65267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.frontecinc.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UnWV3ou772CelrLiFdQAAAK8"]
[Mon Jul 20 06:29:17.312296 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFdwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.312395 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:63928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFdwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.342629 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFfgAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.342727 2026] [security2:error] [pid 929851:tid 930040] [client 77.110.127.138:63929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFfgAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.428602 2026] [security2:error] [pid 929851:tid 929917] [remote 38.242.157.30:44868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4UnWV3ou772CelrLiFigAAtD0"]
[Mon Jul 20 06:29:17.487820 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFjwAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.487908 2026] [security2:error] [pid 929851:tid 930006] [client 77.110.127.138:63931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnWV3ou772CelrLiFjwAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.687220 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:57327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UnWV3ou772CelrLiFngAAAI8"]
[Mon Jul 20 06:29:17.687472 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:57327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UnWV3ou772CelrLiFngAAAI8"]
[Mon Jul 20 06:29:17.696975 2026] [security2:error] [pid 929851:tid 929922] [remote 38.242.157.30:44868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4UnWV3ou772CelrLiFnwAAqEI"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:29:17.775913 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UnWV3ou772CelrLiFlwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:17.879986 2026] [security2:error] [pid 929851:tid 930011] [client 14.225.17.146:62992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4UnGV3ou772CelrLiFTQAAAJ8"], referer: http://mourgroup.com/old
[Mon Jul 20 06:29:17.987788 2026] [security2:error] [pid 929851:tid 930063] [client 57.141.18.57:42038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UnGV3ou772CelrLiFTAAA03U"]
[Mon Jul 20 06:29:18.037072 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiFuAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.037159 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:63935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiFuAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.142900 2026] [security2:error] [pid 929851:tid 929967] [remote 130.185.118.215:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4UnmV3ou772CelrLiFwgAAlm8"]
[Mon Jul 20 06:29:18.384113 2026] [security2:error] [pid 929851:tid 929934] [remote 130.185.118.215:40680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4UnmV3ou772CelrLiF2QAArE4"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 06:29:18.497238 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF5QAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.497390 2026] [security2:error] [pid 929851:tid 930063] [client 77.110.127.138:63936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF5QAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.771678 2026] [security2:error] [pid 929851:tid 930018] [client 14.225.17.146:59757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4UnmV3ou772CelrLiF5gAAAKY"], referer: http://securingmemories.com/old
[Mon Jul 20 06:29:18.892374 2026] [security2:error] [pid 929851:tid 930078] [client 14.225.17.146:63777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4UnmV3ou772CelrLiF1AAAAOI"], referer: http://laceycaraccident.com/old
[Mon Jul 20 06:29:18.915647 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF-wAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:18.915761 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:63899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UnmV3ou772CelrLiF-wAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.069025 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGBwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.069176 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGBwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.088247 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.49:25480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UnWV3ou772CelrLiFpQAAzXE"]
[Mon Jul 20 06:29:19.271127 2026] [security2:error] [pid 929851:tid 930111] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4Un2V3ou772CelrLiGBAABAwA"], referer: http://assasalnazaha.com/old
[Mon Jul 20 06:29:19.405821 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGJgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.406028 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:63910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Un2V3ou772CelrLiGJgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:19.883851 2026] [security2:error] [pid 929851:tid 929938] [remote 57.141.18.72:65362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3142824"] [unique_id "al4Un2V3ou772CelrLiGTgAAtVI"]
[Mon Jul 20 06:29:20.199473 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGcwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.199563 2026] [security2:error] [pid 929851:tid 930044] [client 77.110.127.138:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGcwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.313142 2026] [security2:error] [pid 929851:tid 930090] [client 14.225.17.146:62751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGZQAAAO4"]
[Mon Jul 20 06:29:20.635153 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.14:26664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Un2V3ou772CelrLiGMwAA2As"]
[Mon Jul 20 06:29:20.805491 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGngAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.805589 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:63964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UoGV3ou772CelrLiGngAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:20.991996 2026] [security2:error] [pid 929851:tid 930106] [client 171.61.165.146:21667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UoGV3ou772CelrLiGpgAAAP4"]
[Mon Jul 20 06:29:20.992159 2026] [security2:error] [pid 929851:tid 930106] [client 171.61.165.146:21667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UoGV3ou772CelrLiGpgAAAP4"]
[Mon Jul 20 06:29:21.472563 2026] [security2:error] [pid 929851:tid 929922] [remote 162.19.86.63:39700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiGxwAAwUI"]
[Mon Jul 20 06:29:21.472744 2026] [security2:error] [pid 929851:tid 930045] [client 162.19.86.63:39700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiGxwAAwUI"]
[Mon Jul 20 06:29:21.591279 2026] [security2:error] [pid 929851:tid 929997] [client 14.225.17.146:59595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGXwAAAJE"], referer: http://idigress.group/old
[Mon Jul 20 06:29:21.759437 2026] [security2:error] [pid 929851:tid 929991] [client 57.141.18.65:56424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGiAAAi1A"]
[Mon Jul 20 06:29:21.804445 2026] [security2:error] [pid 929851:tid 930094] [client 106.219.188.178:27768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiG7QAAAPI"]
[Mon Jul 20 06:29:21.804615 2026] [security2:error] [pid 929851:tid 930094] [client 106.219.188.178:27768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UoWV3ou772CelrLiG7QAAAPI"]
[Mon Jul 20 06:29:22.033624 2026] [security2:error] [pid 929851:tid 930035] [client 14.225.17.146:59811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGcgAAALc"], referer: http://longevityperformanceclinic.com/old
[Mon Jul 20 06:29:22.284929 2026] [security2:error] [pid 929851:tid 929913] [remote 103.187.169.251:39072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UomV3ou772CelrLiHFwAA9Tk"]
[Mon Jul 20 06:29:22.357188 2026] [security2:error] [pid 929851:tid 930072] [client 14.225.17.146:59888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGoQAAANw"], referer: http://solkeetw.com/old
[Mon Jul 20 06:29:22.358097 2026] [proxy:error] [pid 929851:tid 929996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.358170 2026] [proxy_http:error] [pid 929851:tid 929996] [client 34.73.38.214:58039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:22.358881 2026] [proxy:error] [pid 929851:tid 929996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.358932 2026] [proxy_http:error] [pid 929851:tid 929996] [client 34.73.38.214:58039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:22.417522 2026] [security2:error] [pid 929851:tid 930086] [client 14.225.17.146:59927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4UoGV3ou772CelrLiGpAAAAOo"], referer: http://guidehunting.com/old
[Mon Jul 20 06:29:22.703770 2026] [security2:error] [pid 929851:tid 929969] [remote 103.187.169.251:39072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UomV3ou772CelrLiHRQAAnXE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:29:22.840642 2026] [security2:error] [pid 929851:tid 929998] [client 57.141.18.56:62556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UoWV3ou772CelrLiG8gAAkk0"]
[Mon Jul 20 06:29:22.988092 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.988181 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:53790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:22.989484 2026] [proxy:error] [pid 929851:tid 930045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:22.989520 2026] [proxy_http:error] [pid 929851:tid 930045] [client 34.73.38.214:53790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.104906 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.104960 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:62460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.105404 2026] [proxy:error] [pid 929851:tid 930051] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.105426 2026] [proxy_http:error] [pid 929851:tid 930051] [client 34.73.38.214:62460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.345928 2026] [security2:error] [pid 929851:tid 930046] [client 57.141.18.107:57950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UomV3ou772CelrLiHKQAAwhM"]
[Mon Jul 20 06:29:23.417036 2026] [security2:error] [pid 929851:tid 929986] [client 158.173.166.181:51815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Uo2V3ou772CelrLiHdgAAAIY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:23.495253 2026] [proxy:error] [pid 929851:tid 930031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.495337 2026] [proxy_http:error] [pid 929851:tid 930031] [client 34.73.38.214:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.496104 2026] [proxy:error] [pid 929851:tid 930031] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.496139 2026] [proxy_http:error] [pid 929851:tid 930031] [client 34.73.38.214:54946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.581949 2026] [security2:error] [pid 929851:tid 930107] [client 14.225.17.146:59816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHbQAAAP8"], referer: https://guidehunting.com/old
[Mon Jul 20 06:29:23.816265 2026] [proxy:error] [pid 929851:tid 930023] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.816342 2026] [proxy_http:error] [pid 929851:tid 930023] [client 34.73.38.214:58785] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.816959 2026] [proxy:error] [pid 929851:tid 930023] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:23.816987 2026] [proxy_http:error] [pid 929851:tid 930023] [client 34.73.38.214:58785] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:23.895818 2026] [security2:error] [pid 929851:tid 930014] [client 45.157.112.60:41973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Uo2V3ou772CelrLiHpgAAAKI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:23.936198 2026] [security2:error] [pid 929851:tid 929999] [client 223.185.13.213:9012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uo2V3ou772CelrLiHqAAAAJM"]
[Mon Jul 20 06:29:23.936295 2026] [security2:error] [pid 929851:tid 929999] [client 223.185.13.213:9012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uo2V3ou772CelrLiHqAAAAJM"]
[Mon Jul 20 06:29:23.969897 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHkQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.103273 2026] [security2:error] [pid 929851:tid 930091] [client 50.116.65.227:58644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UpGV3ou772CelrLiHsQAAAO8"]
[Mon Jul 20 06:29:24.113492 2026] [security2:error] [pid 929851:tid 929987] [client 50.116.65.227:58654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UpGV3ou772CelrLiHtAAAAIc"]
[Mon Jul 20 06:29:24.152151 2026] [proxy:error] [pid 929851:tid 930020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.152229 2026] [proxy_http:error] [pid 929851:tid 930020] [client 34.73.38.214:59636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.152671 2026] [proxy:error] [pid 929851:tid 930020] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.152698 2026] [proxy_http:error] [pid 929851:tid 930020] [client 34.73.38.214:59636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.274420 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpGV3ou772CelrLiHywAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.274542 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:63990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpGV3ou772CelrLiHywAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.427152 2026] [security2:error] [pid 929851:tid 930104] [client 77.110.127.138:63992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UpGV3ou772CelrLiH1QAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:24.506543 2026] [proxy:error] [pid 929851:tid 930091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.506597 2026] [proxy_http:error] [pid 929851:tid 930091] [client 34.73.38.214:58423] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.507191 2026] [proxy:error] [pid 929851:tid 930091] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:24.507216 2026] [proxy_http:error] [pid 929851:tid 930091] [client 34.73.38.214:58423] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:24.675906 2026] [security2:error] [pid 929851:tid 930062] [client 57.141.18.37:47320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHbAAA0iY"]
[Mon Jul 20 06:29:24.952175 2026] [security2:error] [pid 929851:tid 929993] [client 57.141.18.0:23972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHfgAAjXo"]
[Mon Jul 20 06:29:25.031489 2026] [security2:error] [pid 929851:tid 930091] [client 34.73.38.214:61432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIEgAAAO8"]
[Mon Jul 20 06:29:25.110421 2026] [proxy:error] [pid 929851:tid 930056] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:25.110484 2026] [proxy_http:error] [pid 929851:tid 930056] [client 34.73.38.214:57923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:25.111309 2026] [proxy:error] [pid 929851:tid 930056] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:29:25.111338 2026] [proxy_http:error] [pid 929851:tid 930056] [client 34.73.38.214:57923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:29:25.214601 2026] [security2:error] [pid 929851:tid 930009] [client 14.225.17.146:51255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIDwAAAJ0"], referer: http://narv.co/old
[Mon Jul 20 06:29:25.257924 2026] [security2:error] [pid 929851:tid 930024] [client 213.152.162.79:48982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIJQAAAKw"]
[Mon Jul 20 06:29:25.258020 2026] [security2:error] [pid 929851:tid 930024] [client 213.152.162.79:48982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIJQAAAKw"]
[Mon Jul 20 06:29:25.277878 2026] [security2:error] [pid 929851:tid 929903] [remote 45.90.123.233:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UpWV3ou772CelrLiIKAAA7i8"]
[Mon Jul 20 06:29:25.291513 2026] [security2:error] [pid 929851:tid 930083] [client 57.141.18.64:55230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHqQAA5x4"]
[Mon Jul 20 06:29:25.298358 2026] [security2:error] [pid 929851:tid 930047] [client 34.73.38.214:54648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiILAAAAMM"]
[Mon Jul 20 06:29:25.341371 2026] [security2:error] [pid 929851:tid 930045] [client 14.225.17.146:58633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHpwAAAME"], referer: http://balticsteelmgmt.com/old
[Mon Jul 20 06:29:25.405666 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.10:58248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UpGV3ou772CelrLiHtwAAtSw"]
[Mon Jul 20 06:29:25.421996 2026] [security2:error] [pid 929851:tid 930012] [client 34.73.38.214:61947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIPQAAAKA"]
[Mon Jul 20 06:29:25.476857 2026] [security2:error] [pid 929851:tid 929921] [remote 45.90.123.233:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UpWV3ou772CelrLiIRAABAkE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:29:25.783630 2026] [security2:error] [pid 929851:tid 930014] [client 34.73.38.214:64881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIWAAAAKI"]
[Mon Jul 20 06:29:25.895245 2026] [security2:error] [pid 929851:tid 930064] [client 112.208.70.94:42621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIZAAAANQ"]
[Mon Jul 20 06:29:25.895349 2026] [security2:error] [pid 929851:tid 930064] [client 112.208.70.94:42621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UpWV3ou772CelrLiIZAAAANQ"]
[Mon Jul 20 06:29:25.938930 2026] [security2:error] [pid 929851:tid 930082] [client 34.73.38.214:51340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UpWV3ou772CelrLiIagAAAOY"]
[Mon Jul 20 06:29:26.084124 2026] [security2:error] [pid 929851:tid 930098] [client 171.60.139.123:50483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIcwAAAPY"]
[Mon Jul 20 06:29:26.084258 2026] [security2:error] [pid 929851:tid 930098] [client 171.60.139.123:50483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIcwAAAPY"]
[Mon Jul 20 06:29:26.241309 2026] [security2:error] [pid 929851:tid 930028] [client 50.116.65.227:58694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4UpmV3ou772CelrLiIfwAAALA"]
[Mon Jul 20 06:29:26.245509 2026] [security2:error] [pid 929851:tid 930043] [client 14.225.17.146:58194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIbQAAAL8"], referer: http://recruitinginsight.us/old
[Mon Jul 20 06:29:26.278037 2026] [security2:error] [pid 929851:tid 930004] [client 14.225.17.146:58574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4UpmV3ou772CelrLiIcgAAAJg"], referer: https://narv.co/old
[Mon Jul 20 06:29:26.303713 2026] [security2:error] [pid 929851:tid 930018] [client 104.207.59.142:19277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UpmV3ou772CelrLiIggAAAKY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:26.400822 2026] [security2:error] [pid 929851:tid 930021] [client 57.141.18.121:61216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIEwAAqUU"]
[Mon Jul 20 06:29:26.401170 2026] [security2:error] [pid 929851:tid 929880] [remote 78.46.157.202:44882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIiwAAvBg"]
[Mon Jul 20 06:29:26.401299 2026] [security2:error] [pid 929851:tid 930040] [client 78.46.157.202:44882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIiwAAvBg"]
[Mon Jul 20 06:29:26.420409 2026] [security2:error] [pid 929851:tid 930009] [client 34.74.185.202:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UpmV3ou772CelrLiIjgAAAJ0"]
[Mon Jul 20 06:29:26.439058 2026] [security2:error] [pid 929851:tid 930087] [client 34.73.38.214:60547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UpmV3ou772CelrLiIkwAAAOs"]
[Mon Jul 20 06:29:26.466241 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpmV3ou772CelrLiIlgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:26.466357 2026] [security2:error] [pid 929851:tid 930011] [client 77.110.127.138:63999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UpmV3ou772CelrLiIlgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:26.481929 2026] [security2:error] [pid 929851:tid 930105] [client 34.73.38.214:63118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UpmV3ou772CelrLiImQAAAP0"]
[Mon Jul 20 06:29:26.681629 2026] [security2:error] [pid 929851:tid 930046] [client 14.225.17.146:58157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4UpGV3ou772CelrLiH7AAAAMI"], referer: http://dollpassionista.com/old
[Mon Jul 20 06:29:26.683371 2026] [security2:error] [pid 929851:tid 930091] [client 212.47.78.27:43756] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4UpmV3ou772CelrLiIqQAAAO8"]
[Mon Jul 20 06:29:27.030450 2026] [security2:error] [pid 929851:tid 930096] [client 14.225.17.146:59658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4UpmV3ou772CelrLiIvQAAAPQ"], referer: http://hammadownenterprises.com/old
[Mon Jul 20 06:29:27.156675 2026] [security2:error] [pid 929851:tid 929991] [client 57.141.18.1:25928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UpWV3ou772CelrLiIXgAAizk"]
[Mon Jul 20 06:29:27.158338 2026] [security2:error] [pid 929851:tid 930039] [client 212.47.78.27:43762] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4Up2V3ou772CelrLiI0gAAALs"]
[Mon Jul 20 06:29:27.199603 2026] [security2:error] [pid 929851:tid 930074] [client 103.141.108.143:57686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiI1gAAAN4"]
[Mon Jul 20 06:29:27.199772 2026] [security2:error] [pid 929851:tid 930074] [client 103.141.108.143:57686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiI1gAAAN4"]
[Mon Jul 20 06:29:27.239034 2026] [security2:error] [pid 929851:tid 930028] [client 14.225.17.146:54918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4UpmV3ou772CelrLiIvgAAALA"], referer: http://mcg.homes/old
[Mon Jul 20 06:29:27.301693 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiI4gAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.301787 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:64007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiI4gAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.316417 2026] [security2:error] [pid 929851:tid 930088] [client 14.225.17.146:58563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4UpGV3ou772CelrLiIAgAAAOw"], referer: http://drewsasburyparkbeachhouse.com/old
[Mon Jul 20 06:29:27.560299 2026] [security2:error] [pid 929851:tid 930001] [client 45.116.69.230:59509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJAwAAAJU"]
[Mon Jul 20 06:29:27.560454 2026] [security2:error] [pid 929851:tid 930001] [client 45.116.69.230:59509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJAwAAAJU"]
[Mon Jul 20 06:29:27.582982 2026] [security2:error] [pid 929851:tid 930008] [client 34.74.185.202:49633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Up2V3ou772CelrLiJBQAAAJw"]
[Mon Jul 20 06:29:27.615669 2026] [security2:error] [pid 929851:tid 929987] [client 212.47.78.27:58424] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4Up2V3ou772CelrLiJBgAAAIc"]
[Mon Jul 20 06:29:27.709151 2026] [security2:error] [pid 929851:tid 930079] [client 34.73.38.214:51289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Up2V3ou772CelrLiJDQAAAOM"]
[Mon Jul 20 06:29:27.720693 2026] [security2:error] [pid 929851:tid 929948] [remote 97.74.87.194:39652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJCwAAq1w"]
[Mon Jul 20 06:29:27.720911 2026] [security2:error] [pid 929851:tid 930023] [client 97.74.87.194:39652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Up2V3ou772CelrLiJCwAAq1w"]
[Mon Jul 20 06:29:27.721130 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiI-wAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.765970 2026] [security2:error] [pid 929851:tid 930080] [client 14.225.17.146:64561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiJBAAAAOQ"], referer: https://dollpassionista.com/old
[Mon Jul 20 06:29:27.914982 2026] [security2:error] [pid 929851:tid 930039] [client 34.73.38.214:59754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Up2V3ou772CelrLiJJgAAALs"]
[Mon Jul 20 06:29:27.929020 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:64011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiJKwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:27.929142 2026] [security2:error] [pid 929851:tid 930031] [client 77.110.127.138:64011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Up2V3ou772CelrLiJKwAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:28.044396 2026] [security2:error] [pid 929851:tid 930010] [client 104.234.53.90:23239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UqGV3ou772CelrLiJOAAAAJ4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:28.081447 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:64014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UqGV3ou772CelrLiJOwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:28.175270 2026] [security2:error] [pid 929851:tid 929916] [remote 66.94.101.63:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UqGV3ou772CelrLiJQAAA2Tw"]
[Mon Jul 20 06:29:28.326883 2026] [security2:error] [pid 929851:tid 930006] [client 57.141.18.18:23666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiIzAAAmgY"]
[Mon Jul 20 06:29:28.341715 2026] [security2:error] [pid 929851:tid 930014] [client 57.141.18.7:45532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Up2V3ou772CelrLiIywAAoik"]
[Mon Jul 20 06:29:28.484835 2026] [security2:error] [pid 929851:tid 930104] [client 39.48.81.23:57802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UqGV3ou772CelrLiJWQAAAPw"]
[Mon Jul 20 06:29:28.484999 2026] [security2:error] [pid 929851:tid 930104] [client 39.48.81.23:57802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UqGV3ou772CelrLiJWQAAAPw"]
[Mon Jul 20 06:29:28.627349 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJSwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:28.804425 2026] [security2:error] [pid 929851:tid 930029] [client 34.74.185.202:53176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UqGV3ou772CelrLiJjwAAALE"]
[Mon Jul 20 06:29:28.918942 2026] [security2:error] [pid 929851:tid 930044] [client 74.7.241.163:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "poopatrol608.com"] [uri "/index.php"] [unique_id "al4Uo2V3ou772CelrLiHkgAAwFI"]
[Mon Jul 20 06:29:29.085732 2026] [security2:error] [pid 929851:tid 930077] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJoAAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.206822 2026] [security2:error] [pid 929851:tid 930045] [client 34.73.38.214:52528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UqWV3ou772CelrLiJywAAAME"]
[Mon Jul 20 06:29:29.444472 2026] [security2:error] [pid 929851:tid 930048] [client 34.73.38.214:52711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UqWV3ou772CelrLiJ2QAAAMQ"]
[Mon Jul 20 06:29:29.746499 2026] [security2:error] [pid 929851:tid 930002] [client 57.141.18.73:21514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJXQAAlno"]
[Mon Jul 20 06:29:29.810014 2026] [security2:error] [pid 929851:tid 930041] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqWV3ou772CelrLiJ8AAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.954060 2026] [security2:error] [pid 929851:tid 930058] [client 77.110.127.138:64036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqWV3ou772CelrLiKBAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.954155 2026] [security2:error] [pid 929851:tid 930058] [client 77.110.127.138:64036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqWV3ou772CelrLiKBAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:29.990154 2026] [security2:error] [pid 929851:tid 930111] [client 34.73.38.214:63714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UqWV3ou772CelrLiKCQAAAQM"]
[Mon Jul 20 06:29:30.069070 2026] [security2:error] [pid 929851:tid 929902] [remote 115.79.143.180:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UqmV3ou772CelrLiKEwAAqS4"]
[Mon Jul 20 06:29:30.094830 2026] [security2:error] [pid 929851:tid 930055] [client 34.74.185.202:54401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UqmV3ou772CelrLiKGgAAAMs"]
[Mon Jul 20 06:29:30.110352 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.86:40880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UqGV3ou772CelrLiJkgAA21c"]
[Mon Jul 20 06:29:30.305700 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqmV3ou772CelrLiKFwAAAMI"]
[Mon Jul 20 06:29:30.485304 2026] [security2:error] [pid 929851:tid 929976] [remote 115.79.143.180:47284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UqmV3ou772CelrLiKOQAA63g"], referer: https://vyx.sbv.mybluehost.me/wp-login.php
[Mon Jul 20 06:29:30.591094 2026] [security2:error] [pid 929851:tid 930034] [client 34.73.38.214:65306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UqmV3ou772CelrLiKRQAAALY"]
[Mon Jul 20 06:29:30.738913 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKWAAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.739045 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKWAAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.739577 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UqmV3ou772CelrLiKQAAAAKc"]
[Mon Jul 20 06:29:30.789370 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKXQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.789488 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UqmV3ou772CelrLiKXQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:30.802362 2026] [security2:error] [pid 929851:tid 930070] [client 34.73.38.214:65019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UqmV3ou772CelrLiKXgAAANo"]
[Mon Jul 20 06:29:30.974086 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:64050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UqmV3ou772CelrLiKawAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:31.024194 2026] [security2:error] [pid 929851:tid 930108] [client 34.73.38.214:60627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Uq2V3ou772CelrLiKbwAAAQA"]
[Mon Jul 20 06:29:31.131887 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.53:63836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UqWV3ou772CelrLiKAQAA-nQ"]
[Mon Jul 20 06:29:31.317223 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uq2V3ou772CelrLiKggAAAIs"], referer: 1'"3000
[Mon Jul 20 06:29:31.624936 2026] [security2:error] [pid 929851:tid 930031] [client 34.73.38.214:57304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Uq2V3ou772CelrLiKsAAAALM"]
[Mon Jul 20 06:29:31.734873 2026] [security2:error] [pid 929851:tid 930071] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uq2V3ou772CelrLiKqQAAANs"], referer: 1'"3000
[Mon Jul 20 06:29:31.885412 2026] [security2:error] [pid 929851:tid 929924] [remote 8.217.108.67:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Uq2V3ou772CelrLiKwQAAtUQ"]
[Mon Jul 20 06:29:31.918282 2026] [security2:error] [pid 929851:tid 930042] [client 171.61.165.146:9731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Uq2V3ou772CelrLiKxAAAAL4"]
[Mon Jul 20 06:29:31.918388 2026] [security2:error] [pid 929851:tid 930042] [client 171.61.165.146:9731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Uq2V3ou772CelrLiKxAAAAL4"]
[Mon Jul 20 06:29:31.993410 2026] [security2:error] [pid 929851:tid 930002] [client 34.74.185.202:64311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Uq2V3ou772CelrLiKyQAAAJY"]
[Mon Jul 20 06:29:32.108598 2026] [security2:error] [pid 929851:tid 930039] [client 34.73.38.214:55141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UrGV3ou772CelrLiKywAAALs"]
[Mon Jul 20 06:29:32.474585 2026] [security2:error] [pid 929851:tid 930081] [client 104.234.53.63:27693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UrGV3ou772CelrLiK6AAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:32.498407 2026] [security2:error] [pid 929851:tid 929899] [remote 66.94.101.63:35980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UrGV3ou772CelrLiK7QAAqys"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:32.561476 2026] [security2:error] [pid 929851:tid 930086] [client 106.219.188.178:20183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiK7wAAAOo"]
[Mon Jul 20 06:29:32.562066 2026] [security2:error] [pid 929851:tid 930086] [client 106.219.188.178:20183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiK7wAAAOo"]
[Mon Jul 20 06:29:32.619321 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UrGV3ou772CelrLiK5gAAAKc"], referer: 1'"3000
[Mon Jul 20 06:29:32.751945 2026] [security2:error] [pid 929851:tid 930082] [client 74.7.230.36:56440] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bokkunst.com"] [uri "/robots.txt"] [unique_id "al4UrGV3ou772CelrLiLCgAAAOY"]
[Mon Jul 20 06:29:32.905689 2026] [security2:error] [pid 929851:tid 930026] [client 197.186.66.42:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiLFgAAAK4"]
[Mon Jul 20 06:29:32.905945 2026] [security2:error] [pid 929851:tid 930026] [client 197.186.66.42:52142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UrGV3ou772CelrLiLFgAAAK4"]
[Mon Jul 20 06:29:33.019611 2026] [security2:error] [pid 929851:tid 930074] [client 34.74.185.202:62807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLHAAAAN4"]
[Mon Jul 20 06:29:33.153873 2026] [security2:error] [pid 929851:tid 929927] [remote 188.40.28.4:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLJwAAsUc"]
[Mon Jul 20 06:29:33.189294 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLLgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.189408 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLLgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.202644 2026] [security2:error] [pid 929851:tid 930097] [client 34.73.38.214:65083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLLwAAAPU"]
[Mon Jul 20 06:29:33.240997 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLNQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.241125 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:64030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLNQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.263070 2026] [security2:error] [pid 929851:tid 930039] [client 34.73.38.214:58818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.glx.ehd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLPAAAALs"]
[Mon Jul 20 06:29:33.353677 2026] [security2:error] [pid 929851:tid 929920] [remote 188.40.28.4:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLQwAApEA"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 06:29:33.416687 2026] [security2:error] [pid 929851:tid 930026] [client 50.116.65.227:39880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UrWV3ou772CelrLiLSQAAAK4"]
[Mon Jul 20 06:29:33.427012 2026] [security2:error] [pid 929851:tid 930065] [client 50.116.65.227:39882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UrWV3ou772CelrLiLTAAAANU"]
[Mon Jul 20 06:29:33.447012 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLUAAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.447114 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:64066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UrWV3ou772CelrLiLUAAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.537649 2026] [security2:error] [pid 929851:tid 930112] [client 57.141.18.37:42948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uq2V3ou772CelrLiKuQABBAU"]
[Mon Jul 20 06:29:33.592594 2026] [security2:error] [pid 929851:tid 929929] [remote 194.164.192.228:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLWAAAwEk"]
[Mon Jul 20 06:29:33.604577 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64067] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UrWV3ou772CelrLiLWwAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:33.774599 2026] [security2:error] [pid 929851:tid 929948] [remote 194.164.192.228:55816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4UrWV3ou772CelrLiLbQAA_1w"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:29:33.881266 2026] [security2:error] [pid 929851:tid 930032] [client 34.74.185.202:53013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UrWV3ou772CelrLiLeAAAALQ"]
[Mon Jul 20 06:29:33.988247 2026] [security2:error] [pid 929851:tid 930108] [client 14.225.17.146:64456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLcgAAAQA"], referer: http://lifeisbetterlakeside.com/old
[Mon Jul 20 06:29:34.115326 2026] [security2:error] [pid 929851:tid 929923] [remote 103.187.169.251:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UrmV3ou772CelrLiLhQAA80M"]
[Mon Jul 20 06:29:34.122811 2026] [security2:error] [pid 929851:tid 929995] [client 34.74.185.202:64218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UrmV3ou772CelrLiLhgAAAI8"]
[Mon Jul 20 06:29:34.531604 2026] [security2:error] [pid 929851:tid 929972] [remote 103.187.169.251:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UrmV3ou772CelrLiLpwAA3nQ"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:29:34.917300 2026] [security2:error] [pid 929851:tid 930051] [client 57.141.18.65:59176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLHgAAxzY"]
[Mon Jul 20 06:29:34.944094 2026] [security2:error] [pid 929851:tid 930085] [client 34.73.38.214:54326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UrmV3ou772CelrLiLyQAAAOk"]
[Mon Jul 20 06:29:35.000162 2026] [security2:error] [pid 929851:tid 930039] [client 34.74.185.202:64013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UrmV3ou772CelrLiL1AAAALs"]
[Mon Jul 20 06:29:35.183996 2026] [security2:error] [pid 929851:tid 930058] [client 223.185.13.213:9394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Ur2V3ou772CelrLiL3gAAAM4"]
[Mon Jul 20 06:29:35.184131 2026] [security2:error] [pid 929851:tid 930058] [client 223.185.13.213:9394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Ur2V3ou772CelrLiL3gAAAM4"]
[Mon Jul 20 06:29:35.196118 2026] [ssl:error] [pid 929851:tid 929987] [client 66.132.172.139:2760] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.bridgeamazon.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:29:35.270366 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.22:31034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLMAAA_no"]
[Mon Jul 20 06:29:35.394582 2026] [security2:error] [pid 929851:tid 930033] [client 74.208.214.194:46076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Ur2V3ou772CelrLiL9QAAALU"]
[Mon Jul 20 06:29:35.415843 2026] [security2:error] [pid 929851:tid 930080] [client 57.141.18.81:60590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrWV3ou772CelrLiLRQAA5Dg"]
[Mon Jul 20 06:29:35.417563 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:64078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL9wAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.417646 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:64078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL9wAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.462443 2026] [security2:error] [pid 929851:tid 930057] [client 34.74.185.202:60427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiL_AAAAM0"]
[Mon Jul 20 06:29:35.468159 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL_QAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.468268 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ur2V3ou772CelrLiL_QAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:35.741307 2026] [security2:error] [pid 929851:tid 929987] [client 34.74.185.202:57674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiMFQAAAIc"]
[Mon Jul 20 06:29:35.762414 2026] [security2:error] [pid 929851:tid 929935] [remote 47.86.33.52:6442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4Ur2V3ou772CelrLiMFgAA408"]
[Mon Jul 20 06:29:35.794412 2026] [security2:error] [pid 929851:tid 930024] [client 34.73.38.214:58376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiMGwAAAKw"]
[Mon Jul 20 06:29:35.876242 2026] [security2:error] [pid 929851:tid 929918] [remote 173.212.252.15:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Ur2V3ou772CelrLiMIwAAjT4"]
[Mon Jul 20 06:29:35.975265 2026] [security2:error] [pid 929851:tid 930026] [client 34.74.185.202:52965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.latiendadejorge.com.gt"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Ur2V3ou772CelrLiMKAAAAK4"]
[Mon Jul 20 06:29:36.086008 2026] [security2:error] [pid 929851:tid 929937] [remote 173.212.252.15:52012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMMQAA1lE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:29:36.121571 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMPgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.121675 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:64086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMPgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.178572 2026] [security2:error] [pid 929851:tid 930055] [client 65.111.27.42:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMQAAAAMs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:29:36.305017 2026] [security2:error] [pid 929851:tid 930000] [client 104.234.53.74:26423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UsGV3ou772CelrLiMUQAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:36.376149 2026] [security2:error] [pid 929851:tid 929883] [remote 47.86.33.52:6442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMVgAA5Bs"], referer: https://nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:29:36.399373 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMRwAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.624742 2026] [security2:error] [pid 929851:tid 930107] [client 14.225.17.146:57686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiL7AAAAP8"]
[Mon Jul 20 06:29:36.764033 2026] [security2:error] [pid 929851:tid 929994] [client 57.141.18.59:43966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UrmV3ou772CelrLiLqgAAjiQ"]
[Mon Jul 20 06:29:36.765875 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMbQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.765971 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsGV3ou772CelrLiMbQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:36.808425 2026] [security2:error] [pid 929851:tid 930109] [client 171.60.139.123:51136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UsGV3ou772CelrLiMdAAAAQE"]
[Mon Jul 20 06:29:36.808525 2026] [security2:error] [pid 929851:tid 930109] [client 171.60.139.123:51136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UsGV3ou772CelrLiMdAAAAQE"]
[Mon Jul 20 06:29:36.856805 2026] [security2:error] [pid 929851:tid 929889] [remote 8.217.108.67:23474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4UsGV3ou772CelrLiMfAAAoSE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:29:37.090094 2026] [security2:error] [pid 929851:tid 930049] [client 14.225.17.146:51311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMMAAAAMU"], referer: http://ancestralidadytrance.space/old
[Mon Jul 20 06:29:37.097094 2026] [security2:error] [pid 929851:tid 929868] [remote 57.141.18.63:54646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3396212"] [unique_id "al4UsWV3ou772CelrLiMlQAA7ww"]
[Mon Jul 20 06:29:37.134110 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMlwAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.134214 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:64094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMlwAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.178717 2026] [security2:error] [pid 929851:tid 929990] [client 104.234.53.57:41321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UsWV3ou772CelrLiMmgAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:37.430351 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMuwAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.430469 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMuwAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.581418 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMygAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.581534 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsWV3ou772CelrLiMygAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:37.715543 2026] [security2:error] [pid 929851:tid 930017] [client 157.52.92.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiMwgAAAKU"]
[Mon Jul 20 06:29:37.728327 2026] [security2:error] [pid 929851:tid 930095] [client 157.52.92.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiMwQAAAPM"]
[Mon Jul 20 06:29:37.730843 2026] [security2:error] [pid 929851:tid 929993] [client 14.225.17.146:64697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMZgAAAI0"], referer: http://ravmike.com/old
[Mon Jul 20 06:29:38.026843 2026] [security2:error] [pid 929851:tid 929986] [client 103.141.108.143:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM6wAAAIY"]
[Mon Jul 20 06:29:38.027513 2026] [security2:error] [pid 929851:tid 929986] [client 103.141.108.143:58296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM6wAAAIY"]
[Mon Jul 20 06:29:38.029504 2026] [security2:error] [pid 929851:tid 930044] [client 57.141.18.107:29848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiMDgAAwHs"]
[Mon Jul 20 06:29:38.191031 2026] [security2:error] [pid 929851:tid 930083] [client 45.116.69.230:60035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM9AAAAOc"]
[Mon Jul 20 06:29:38.191125 2026] [security2:error] [pid 929851:tid 930083] [client 45.116.69.230:60035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiM9AAAAOc"]
[Mon Jul 20 06:29:38.273837 2026] [security2:error] [pid 929851:tid 930086] [client 104.234.53.74:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UsmV3ou772CelrLiM-wAAAOo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:38.276462 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.23:52560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiMJAAAtQE"]
[Mon Jul 20 06:29:38.339068 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNAQAAANw"]
[Mon Jul 20 06:29:38.339168 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNAQAAANw"]
[Mon Jul 20 06:29:38.354076 2026] [security2:error] [pid 929851:tid 929919] [remote 188.166.241.141:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UsmV3ou772CelrLiNAgAAwj8"]
[Mon Jul 20 06:29:38.407254 2026] [security2:error] [pid 929851:tid 930037] [client 57.141.18.111:30394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ur2V3ou772CelrLiMKQAAuS0"]
[Mon Jul 20 06:29:38.487425 2026] [security2:error] [pid 929851:tid 930080] [client 47.128.20.144:41738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elespecialista.mx"] [uri "/robots.txt"] [unique_id "al4UsmV3ou772CelrLiNEQAAAOQ"]
[Mon Jul 20 06:29:38.687892 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNGwAAAI4"]
[Mon Jul 20 06:29:38.688068 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNGwAAAI4"]
[Mon Jul 20 06:29:38.695196 2026] [security2:error] [pid 929851:tid 929893] [remote 93.152.221.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiNFgAA8CU"]
[Mon Jul 20 06:29:38.727907 2026] [security2:error] [pid 929851:tid 929931] [remote 188.166.241.141:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UsmV3ou772CelrLiNHgAAp0s"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:38.818226 2026] [security2:error] [pid 929851:tid 930012] [client 112.208.70.94:43129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiNKwAAAKA"]
[Mon Jul 20 06:29:38.818361 2026] [security2:error] [pid 929851:tid 930012] [client 112.208.70.94:43129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UsmV3ou772CelrLiNKwAAAKA"]
[Mon Jul 20 06:29:38.858442 2026] [security2:error] [pid 929851:tid 930023] [client 14.225.17.146:58285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiNJQAAAKs"], referer: https://ravmike.com/old
[Mon Jul 20 06:29:38.859666 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNLgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:38.859826 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UsmV3ou772CelrLiNLgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.036094 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Us2V3ou772CelrLiNPAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.036227 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Us2V3ou772CelrLiNPAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.254297 2026] [security2:error] [pid 929851:tid 930010] [client 57.141.18.12:54416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMfQAAnig"]
[Mon Jul 20 06:29:39.337545 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:58291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Us2V3ou772CelrLiNZwAAAI8"]
[Mon Jul 20 06:29:39.337702 2026] [security2:error] [pid 929851:tid 929995] [client 39.48.81.23:58291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Us2V3ou772CelrLiNZwAAAI8"]
[Mon Jul 20 06:29:39.411564 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.33:40826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMjQAAzWU"]
[Mon Jul 20 06:29:39.444914 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNRQAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.709703 2026] [security2:error] [pid 929851:tid 930086] [client 14.225.17.146:64434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNSAAAAOo"], referer: http://bruceledewitz.com/old
[Mon Jul 20 06:29:39.773345 2026] [security2:error] [pid 929851:tid 930102] [client 57.141.18.18:21046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiMowAA-lg"]
[Mon Jul 20 06:29:39.847539 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNewAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:39.866155 2026] [security2:error] [pid 929851:tid 930014] [client 74.7.227.179:56872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNgQAAoiM"], referer: https://tejasenvironmental.com/p=919923
[Mon Jul 20 06:29:40.254763 2026] [security2:error] [pid 929851:tid 930031] [client 14.225.17.146:64663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4UsGV3ou772CelrLiMZAAAALM"], referer: http://areitoproducciones.com/old
[Mon Jul 20 06:29:40.428671 2026] [security2:error] [pid 929851:tid 930025] [client 77.110.127.138:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtGV3ou772CelrLiNvgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.428790 2026] [security2:error] [pid 929851:tid 930025] [client 77.110.127.138:64093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtGV3ou772CelrLiNvgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.508919 2026] [security2:error] [pid 929851:tid 930014] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiNtgAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.694228 2026] [security2:error] [pid 929851:tid 930046] [client 104.234.53.75:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UtGV3ou772CelrLiN1wAAAMI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:40.711924 2026] [security2:error] [pid 929851:tid 929866] [remote 93.152.221.21:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "origine.nz"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UtGV3ou772CelrLiN2QAArAo"]
[Mon Jul 20 06:29:40.729154 2026] [security2:error] [pid 929851:tid 930056] [client 14.225.17.146:65275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiN0QAAAMw"]
[Mon Jul 20 06:29:40.803170 2026] [security2:error] [pid 929851:tid 929999] [client 57.141.18.60:30084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsWV3ou772CelrLiM5wAAk10"]
[Mon Jul 20 06:29:40.906412 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiN1gAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:40.942310 2026] [security2:error] [pid 929851:tid 930020] [client 57.141.18.22:46482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiM7gAAqD0"]
[Mon Jul 20 06:29:41.232004 2026] [security2:error] [pid 929851:tid 930054] [client 57.141.18.32:38006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiNCwAAyko"]
[Mon Jul 20 06:29:41.488282 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOAwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.535347 2026] [security2:error] [pid 929851:tid 930104] [client 14.225.17.146:64781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNjAAAAPw"], referer: http://nomorewetsheets.net/old
[Mon Jul 20 06:29:41.667492 2026] [security2:error] [pid 929851:tid 929988] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOJAAAAIg"], referer: 1'"3000
[Mon Jul 20 06:29:41.700758 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOQQAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.700898 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOQQAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.775451 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOLgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.852453 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOTgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.852559 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtWV3ou772CelrLiOTgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:41.921250 2026] [security2:error] [pid 929851:tid 929969] [remote 91.142.222.105:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UtWV3ou772CelrLiOUwAAvHE"]
[Mon Jul 20 06:29:42.010456 2026] [security2:error] [pid 929851:tid 930042] [client 77.110.127.138:64133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 190 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UtmV3ou772CelrLiOWwAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.049059 2026] [security2:error] [pid 929851:tid 929988] [client 103.153.183.69:39066] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f../etc/passwd"] [unique_id "al4UtmV3ou772CelrLiOYwAAAIg"], referer: https://www.bing.com/search?q=i8cziq
[Mon Jul 20 06:29:42.066130 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOIgAAANg"]
[Mon Jul 20 06:29:42.069985 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.50:23494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UsmV3ou772CelrLiNOQAA1yw"]
[Mon Jul 20 06:29:42.162480 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64134] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UtmV3ou772CelrLiOcwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.171363 2026] [security2:error] [pid 929851:tid 929896] [remote 91.142.222.105:38526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOdAAArSg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:29:42.214544 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOWAAAAN4"], referer: 1'"3000
[Mon Jul 20 06:29:42.216525 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOWgAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.311882 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOhQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.312025 2026] [security2:error] [pid 929851:tid 930029] [client 77.110.127.138:64135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOhQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.454727 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOigAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.454847 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOigAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.504159 2026] [security2:error] [pid 929851:tid 930076] [client 82.102.18.116:56258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4UtmV3ou772CelrLiOkAAAAOA"]
[Mon Jul 20 06:29:42.513652 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOkwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.513737 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOkwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.536429 2026] [security2:error] [pid 929851:tid 929940] [remote 162.19.86.63:46132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOlgAAilQ"]
[Mon Jul 20 06:29:42.565711 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOlwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.565835 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOlwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.609349 2026] [security2:error] [pid 929851:tid 930009] [client 197.186.66.42:52645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOmwAAAJ0"]
[Mon Jul 20 06:29:42.609462 2026] [security2:error] [pid 929851:tid 930009] [client 197.186.66.42:52645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOmwAAAJ0"]
[Mon Jul 20 06:29:42.715936 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOowAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.716028 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:64139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOowAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.768921 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOrgAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.769057 2026] [security2:error] [pid 929851:tid 930053] [client 77.110.127.138:64115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOrgAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.772300 2026] [security2:error] [pid 929851:tid 929944] [remote 162.19.86.63:46132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOsAAAlFg"], referer: https://lutheranphilosopher.com/wp-login.php
[Mon Jul 20 06:29:42.803595 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:24953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOtAAAALw"]
[Mon Jul 20 06:29:42.803793 2026] [security2:error] [pid 929851:tid 930040] [client 171.61.165.146:24953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOtAAAALw"]
[Mon Jul 20 06:29:42.817565 2026] [security2:error] [pid 929851:tid 930007] [client 50.116.65.227:35036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UtmV3ou772CelrLiOtgAAAJs"]
[Mon Jul 20 06:29:42.827655 2026] [security2:error] [pid 929851:tid 930033] [client 50.116.65.227:35052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UtmV3ou772CelrLiOuQAAALU"]
[Mon Jul 20 06:29:42.830822 2026] [security2:error] [pid 929851:tid 929950] [remote 217.61.143.92:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOuAABA14"]
[Mon Jul 20 06:29:42.857856 2026] [security2:error] [pid 929851:tid 930080] [client 82.102.18.116:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sergnotes.com"] [uri "/xmlrpc.php"] [unique_id "al4UtmV3ou772CelrLiOuwAAAOQ"]
[Mon Jul 20 06:29:42.866822 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.82:44182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Us2V3ou772CelrLiNiwAAzVY"]
[Mon Jul 20 06:29:42.939780 2026] [security2:error] [pid 929851:tid 930018] [client 43.205.139.3:24144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOyAAAAKY"]
[Mon Jul 20 06:29:42.946323 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:64141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOygAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.946417 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:64141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UtmV3ou772CelrLiOygAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:42.986656 2026] [security2:error] [pid 929851:tid 930097] [client 104.234.53.66:52429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UtmV3ou772CelrLiOzwAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:43.053720 2026] [security2:error] [pid 929851:tid 929895] [remote 217.61.143.92:44110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Ut2V3ou772CelrLiO3QAA_yc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:29:43.082935 2026] [security2:error] [pid 929851:tid 930054] [client 66.249.79.131:55949] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "greenport-us.us"] [uri "/robots.txt"] [unique_id "al4Ut2V3ou772CelrLiO5AAAAMo"]
[Mon Jul 20 06:29:43.105082 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiO6gAAAJc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:29:43.105211 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiO6gAAAJc"], referer: https://mezzacraft.com/501/
[Mon Jul 20 06:29:43.124023 2026] [security2:error] [pid 929851:tid 930041] [client 57.141.18.73:31190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiNnAAAvQ0"]
[Mon Jul 20 06:29:43.185468 2026] [security2:error] [pid 929851:tid 930099] [client 82.102.18.116:56276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Ut2V3ou772CelrLiO-wAAAPc"]
[Mon Jul 20 06:29:43.263504 2026] [security2:error] [pid 929851:tid 930017] [client 77.110.127.138:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-blanket/w4ai4r3qk8nc.php"] [unique_id "al4Ut2V3ou772CelrLiPBwAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.280783 2026] [security2:error] [pid 929851:tid 930044] [client 106.219.188.178:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPCAAAAMA"]
[Mon Jul 20 06:29:43.281114 2026] [security2:error] [pid 929851:tid 930044] [client 106.219.188.178:59904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPCAAAAMA"]
[Mon Jul 20 06:29:43.388214 2026] [security2:error] [pid 929851:tid 930080] [client 65.1.132.125:27452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPFAAAAOQ"]
[Mon Jul 20 06:29:43.388312 2026] [security2:error] [pid 929851:tid 930080] [client 65.1.132.125:27452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Ut2V3ou772CelrLiPFAAAAOQ"]
[Mon Jul 20 06:29:43.502316 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:64038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPGAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.502415 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:64038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPGAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.503667 2026] [security2:error] [pid 929851:tid 930026] [client 82.102.18.116:56278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Ut2V3ou772CelrLiPGgAAAK4"]
[Mon Jul 20 06:29:43.590327 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:64068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPAgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.622585 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPBQAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.625699 2026] [security2:error] [pid 929851:tid 930008] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPEAAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.633780 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.41:39740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtGV3ou772CelrLiNwAAAnyY"]
[Mon Jul 20 06:29:43.669219 2026] [security2:error] [pid 929851:tid 930023] [client 77.110.127.138:64148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPIgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.669309 2026] [security2:error] [pid 929851:tid 930023] [client 77.110.127.138:64148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ut2V3ou772CelrLiPIgAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.727244 2026] [security2:error] [pid 929851:tid 930025] [client 79.215.172.42:64039] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4Ut2V3ou772CelrLiPKQAAAK0"]
[Mon Jul 20 06:29:43.820248 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:64149] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 778 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ut2V3ou772CelrLiPPwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.826072 2026] [security2:error] [pid 929851:tid 930092] [client 99.226.215.103:36240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4Ut2V3ou772CelrLiPQgAAAPA"]
[Mon Jul 20 06:29:43.844073 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/crochet-classes-in-surrey/sykbyjo6qckn.php"] [unique_id "al4Ut2V3ou772CelrLiPRgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:43.848235 2026] [security2:error] [pid 929851:tid 930042] [client 82.102.18.116:35275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Ut2V3ou772CelrLiPSQAAAL4"]
[Mon Jul 20 06:29:43.996715 2026] [security2:error] [pid 929851:tid 930087] [client 77.110.127.138:64154] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Ut2V3ou772CelrLiPXwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.050601 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64124] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/img_4196-2/"] [unique_id "al4UuGV3ou772CelrLiPYwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.130406 2026] [security2:error] [pid 929851:tid 930031] [client 13.201.64.214:42380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4UuGV3ou772CelrLiPZwAAALM"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:29:44.188001 2026] [security2:error] [pid 929851:tid 930095] [client 82.102.18.116:56298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4UuGV3ou772CelrLiPdAAAAPM"]
[Mon Jul 20 06:29:44.213404 2026] [security2:error] [pid 929851:tid 930012] [client 14.225.17.146:55277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4UtmV3ou772CelrLiOpwAAAKA"], referer: http://chestermonty.com/old
[Mon Jul 20 06:29:44.371020 2026] [security2:error] [pid 929851:tid 930054] [client 104.234.53.73:38265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4UuGV3ou772CelrLiPgQAAAMo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:44.427499 2026] [security2:error] [pid 929851:tid 930083] [client 14.225.17.146:55327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4UtmV3ou772CelrLiOugAAAOc"], referer: http://inspirespublishing.com/old
[Mon Jul 20 06:29:44.520433 2026] [security2:error] [pid 929851:tid 929996] [client 113.163.183.66:57203] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4UuGV3ou772CelrLiPigAAAJA"]
[Mon Jul 20 06:29:44.526494 2026] [security2:error] [pid 929851:tid 930082] [client 82.102.18.116:56304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UuGV3ou772CelrLiPiwAAAOY"]
[Mon Jul 20 06:29:44.683143 2026] [security2:error] [pid 929851:tid 930055] [client 77.193.8.9:47154] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4UuGV3ou772CelrLiPmgAAAMs"]
[Mon Jul 20 06:29:44.724586 2026] [security2:error] [pid 929851:tid 930091] [client 79.117.197.205:52268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UuGV3ou772CelrLiPoAAAAO8"]
[Mon Jul 20 06:29:44.754309 2026] [security2:error] [pid 929851:tid 929992] [client 99.252.129.110:37882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4UuGV3ou772CelrLiPpgAAAIw"]
[Mon Jul 20 06:29:44.785856 2026] [security2:error] [pid 929851:tid 930003] [client 62.216.211.191:55404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4UuGV3ou772CelrLiPrAAAAJc"]
[Mon Jul 20 06:29:44.791572 2026] [http2:info] [pid 935758:tid 935758] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:29:44.855870 2026] [security2:error] [pid 929851:tid 930056] [client 57.141.18.39:39921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOPAAAzFU"]
[Mon Jul 20 06:29:44.869991 2026] [security2:error] [pid 929851:tid 930019] [client 35.231.144.158:58532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.144.231.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bzm.ppv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4UuGV3ou772CelrLiPtAAAAKc"]
[Mon Jul 20 06:29:44.880527 2026] [security2:error] [pid 935758:tid 935893] [client 82.102.18.116:56320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4UuLcDxY_mIul-JSGGFAAAAQ0"]
[Mon Jul 20 06:29:44.884060 2026] [security2:error] [pid 929851:tid 930054] [client 34.74.185.202:52649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4UuGV3ou772CelrLiPuQAAAMo"]
[Mon Jul 20 06:29:44.942893 2026] [security2:error] [pid 929851:tid 930106] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPVQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.975469 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPTgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:44.976899 2026] [security2:error] [pid 929851:tid 930072] [client 105.103.92.88:47748] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4UuGV3ou772CelrLiPuwAAANw"]
[Mon Jul 20 06:29:44.985617 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.10:59690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtWV3ou772CelrLiOQgAAwSU"]
[Mon Jul 20 06:29:44.988297 2026] [security2:error] [pid 929851:tid 929985] [client 86.18.126.4:59556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4UuGV3ou772CelrLiPvAAAAIU"]
[Mon Jul 20 06:29:45.019034 2026] [security2:error] [pid 929851:tid 930053] [client 188.232.7.148:51870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4UuWV3ou772CelrLiPvQAAAMk"]
[Mon Jul 20 06:29:45.221907 2026] [security2:error] [pid 929851:tid 930082] [client 82.102.18.116:56330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiPxwAAAOY"]
[Mon Jul 20 06:29:45.233553 2026] [security2:error] [pid 929851:tid 930030] [client 77.110.127.138:64153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPWQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.239262 2026] [security2:error] [pid 929851:tid 930023] [client 223.185.13.213:5781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiPygAAAKs"]
[Mon Jul 20 06:29:45.239365 2026] [security2:error] [pid 929851:tid 930023] [client 223.185.13.213:5781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiPygAAAKs"]
[Mon Jul 20 06:29:45.305872 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP0AAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.306031 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP0AAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.329928 2026] [security2:error] [pid 929851:tid 930101] [client 35.231.144.158:62566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiP1AAAAPk"]
[Mon Jul 20 06:29:45.364122 2026] [security2:error] [pid 929851:tid 930068] [client 14.225.17.146:59108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiPzwAAANg"], referer: https://chestermonty.com/old
[Mon Jul 20 06:29:45.364210 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP3AAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.364298 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP3AAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.373518 2026] [security2:error] [pid 929851:tid 929996] [client 15.237.142.234:43668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiP2QAAAJA"]
[Mon Jul 20 06:29:45.373633 2026] [security2:error] [pid 929851:tid 929996] [client 15.237.142.234:43668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UuWV3ou772CelrLiP2QAAAJA"]
[Mon Jul 20 06:29:45.386328 2026] [security2:error] [pid 935758:tid 935900] [client 104.234.53.86:62859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4UubcDxY_mIul-JSGGGgAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:45.418213 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:64070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP4gAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.418534 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:64070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP4gAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.473946 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:64118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 478 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UuWV3ou772CelrLiP5QAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.550487 2026] [security2:error] [pid 935758:tid 935904] [client 34.74.185.202:55376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4UubcDxY_mIul-JSGGHwAAARg"]
[Mon Jul 20 06:29:45.564293 2026] [security2:error] [pid 935758:tid 935919] [client 82.102.18.116:56342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UubcDxY_mIul-JSGGIAAAASc"]
[Mon Jul 20 06:29:45.621061 2026] [security2:error] [pid 929851:tid 930104] [client 47.203.242.42:36939] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4UuWV3ou772CelrLiP9QAAAPw"]
[Mon Jul 20 06:29:45.627716 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UubcDxY_mIul-JSGGIwAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.645628 2026] [security2:error] [pid 935758:tid 935899] [client 5.147.122.105:62028] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UubcDxY_mIul-JSGGJQAAARM"]
[Mon Jul 20 06:29:45.679077 2026] [security2:error] [pid 929851:tid 930109] [client 77.110.127.138:64053] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/img_4196-2/"] [unique_id "al4UuWV3ou772CelrLiP-QAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.693112 2026] [security2:error] [pid 935758:tid 935901] [client 88.190.117.4:27386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UubcDxY_mIul-JSGGJgAAARU"]
[Mon Jul 20 06:29:45.702981 2026] [security2:error] [pid 929851:tid 929988] [client 57.141.18.44:28216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UtmV3ou772CelrLiOiAAAiCs"]
[Mon Jul 20 06:29:45.712038 2026] [security2:error] [pid 929851:tid 930013] [client 84.123.100.20:50986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4UuWV3ou772CelrLiP_AAAAKE"]
[Mon Jul 20 06:29:45.725843 2026] [security2:error] [pid 935758:tid 935932] [client 77.110.127.138:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/colour-work/sohim3j6lank.php"] [unique_id "al4UubcDxY_mIul-JSGGKAAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.732385 2026] [security2:error] [pid 929851:tid 930046] [client 35.231.144.158:59791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiP_QAAAMI"]
[Mon Jul 20 06:29:45.736819 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP_wAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.736932 2026] [security2:error] [pid 929851:tid 929987] [client 77.110.127.138:64121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiP_wAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.742420 2026] [security2:error] [pid 929851:tid 930087] [client 95.146.45.203:34714] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4UuWV3ou772CelrLiQAAAAAOs"]
[Mon Jul 20 06:29:45.792390 2026] [security2:error] [pid 929851:tid 930011] [client 70.80.217.121:40034] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.ttf"] [unique_id "al4UuWV3ou772CelrLiQCAAAAJ8"]
[Mon Jul 20 06:29:45.792611 2026] [security2:error] [pid 929851:tid 930105] [client 77.110.127.138:64116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:na"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UuWV3ou772CelrLiQBwAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.801529 2026] [security2:error] [pid 929851:tid 930043] [client 92.208.178.74:52000] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4UuWV3ou772CelrLiQCQAAAL8"]
[Mon Jul 20 06:29:45.892646 2026] [security2:error] [pid 929851:tid 930073] [client 77.110.127.138:64137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiP9AAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.907374 2026] [security2:error] [pid 935758:tid 935951] [client 82.102.18.116:56350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UubcDxY_mIul-JSGGMgAAAUc"]
[Mon Jul 20 06:29:45.944718 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiQEgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.944874 2026] [security2:error] [pid 929851:tid 930108] [client 77.110.127.138:64164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UuWV3ou772CelrLiQEgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:45.995624 2026] [security2:error] [pid 929851:tid 930106] [client 34.74.185.202:57211] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4UuWV3ou772CelrLiQEwAAAP4"]
[Mon Jul 20 06:29:46.005239 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQFAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.005337 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQFAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.056623 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQGAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.056770 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQGAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.074522 2026] [security2:error] [pid 929851:tid 930017] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiQBQAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.114411 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UubcDxY_mIul-JSGGLwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.126370 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UumV3ou772CelrLiQGwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.152807 2026] [security2:error] [pid 935758:tid 935922] [client 190.158.139.57:49232] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4UurcDxY_mIul-JSGGOwAAASo"]
[Mon Jul 20 06:29:46.217383 2026] [security2:error] [pid 929851:tid 930101] [client 82.102.18.116:56362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQHwAAAPk"]
[Mon Jul 20 06:29:46.226206 2026] [security2:error] [pid 935758:tid 935963] [client 35.231.144.158:64844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UurcDxY_mIul-JSGGPAAAAVM"]
[Mon Jul 20 06:29:46.299809 2026] [security2:error] [pid 929851:tid 930071] [client 34.21.41.254:52648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/xmlrpc.php"] [unique_id "al4UumV3ou772CelrLiQIgAAANs"]
[Mon Jul 20 06:29:46.299910 2026] [security2:error] [pid 929851:tid 930071] [client 34.21.41.254:52648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "studio.xp-design.co"] [uri "/xmlrpc.php"] [unique_id "al4UumV3ou772CelrLiQIgAAANs"]
[Mon Jul 20 06:29:46.341307 2026] [security2:error] [pid 935758:tid 935965] [client 34.74.185.202:51762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4UurcDxY_mIul-JSGGQwAAAVU"]
[Mon Jul 20 06:29:46.515306 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.10:59700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiO-AAA30c"]
[Mon Jul 20 06:29:46.527263 2026] [security2:error] [pid 929851:tid 930016] [client 82.102.18.116:56372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQLQAAAKQ"]
[Mon Jul 20 06:29:46.545088 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64153] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/about-mezzacraft-crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/img_4196-2/"] [unique_id "al4UumV3ou772CelrLiQLgAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.548376 2026] [security2:error] [pid 929851:tid 929996] [client 35.231.144.158:51461] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQLwAAAJA"]
[Mon Jul 20 06:29:46.666204 2026] [security2:error] [pid 929851:tid 930043] [client 34.74.185.202:50286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQMwAAAL8"]
[Mon Jul 20 06:29:46.816527 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UurcDxY_mIul-JSGGTQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.816632 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UurcDxY_mIul-JSGGTQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.826382 2026] [security2:error] [pid 935758:tid 936003] [client 77.110.127.138:64158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-border/68apksk051pg.php"] [unique_id "al4UurcDxY_mIul-JSGGTwAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.839309 2026] [security2:error] [pid 929851:tid 930069] [client 82.102.18.116:56384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UumV3ou772CelrLiQPAAAANk"]
[Mon Jul 20 06:29:46.879017 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQQQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.879125 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UumV3ou772CelrLiQQQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:46.895122 2026] [security2:error] [pid 929851:tid 930049] [client 14.225.17.146:59040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4UumV3ou772CelrLiQHgAAAMU"], referer: http://aljosour-alarabia.com/old
[Mon Jul 20 06:29:46.916535 2026] [security2:error] [pid 935758:tid 935999] [client 35.231.144.158:64867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4UurcDxY_mIul-JSGGVwAAAXc"]
[Mon Jul 20 06:29:47.031281 2026] [security2:error] [pid 929851:tid 930086] [client 57.141.18.49:34494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPHQAA6iA"]
[Mon Jul 20 06:29:47.034907 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQTQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.035043 2026] [security2:error] [pid 929851:tid 930072] [client 77.110.127.138:64175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQTQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.047263 2026] [security2:error] [pid 929851:tid 930065] [client 77.110.127.138:64080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UumV3ou772CelrLiQOgAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.081804 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UumV3ou772CelrLiQPwAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.087726 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:64162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGYAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.087887 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:64162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGYAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.181094 2026] [security2:error] [pid 935758:tid 935920] [client 82.102.18.116:56392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGZAAAASg"]
[Mon Jul 20 06:29:47.192314 2026] [security2:error] [pid 929851:tid 930009] [client 57.141.18.46:48194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ut2V3ou772CelrLiPOgAAnQ4"]
[Mon Jul 20 06:29:47.211642 2026] [security2:error] [pid 935758:tid 935894] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UurcDxY_mIul-JSGGVgAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.241453 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQWwAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.241542 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQWwAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.297522 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQXAAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.297641 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:64096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQXAAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.301137 2026] [security2:error] [pid 929851:tid 930066] [client 34.74.185.202:60667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu2V3ou772CelrLiQXgAAANY"]
[Mon Jul 20 06:29:47.353686 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQYAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.353816 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQYAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.434232 2026] [security2:error] [pid 929851:tid 930052] [client 171.60.139.123:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Uu2V3ou772CelrLiQZAAAAMg"]
[Mon Jul 20 06:29:47.434347 2026] [security2:error] [pid 929851:tid 930052] [client 171.60.139.123:51774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Uu2V3ou772CelrLiQZAAAAMg"]
[Mon Jul 20 06:29:47.440538 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.440717 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:47.497941 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcwAAATo"]
[Mon Jul 20 06:29:47.498132 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcwAAATo"]
[Mon Jul 20 06:29:47.527418 2026] [security2:error] [pid 935758:tid 935960] [client 82.102.18.116:56394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.sergnotes.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGdAAAAVA"]
[Mon Jul 20 06:29:47.551488 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:64142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQaQAAANQ"]
[Mon Jul 20 06:29:47.551572 2026] [security2:error] [pid 929851:tid 930064] [client 77.110.127.138:64142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uu2V3ou772CelrLiQaQAAANQ"]
[Mon Jul 20 06:29:47.573064 2026] [security2:error] [pid 935758:tid 935945] [client 35.231.144.158:62702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGdwAAAUE"]
[Mon Jul 20 06:29:47.657601 2026] [security2:error] [pid 935758:tid 935972] [client 103.153.183.69:26114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../etc/passwd"] [unique_id "al4Uu7cDxY_mIul-JSGGeQAAAVw"], referer: https://twitter.com/
[Mon Jul 20 06:29:47.865971 2026] [security2:error] [pid 929851:tid 930076] [client 34.74.185.202:50209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu2V3ou772CelrLiQcgAAAOA"]
[Mon Jul 20 06:29:47.931302 2026] [security2:error] [pid 935758:tid 935971] [client 35.231.144.158:62626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Uu7cDxY_mIul-JSGGhwAAAVs"]
[Mon Jul 20 06:29:47.969585 2026] [security2:error] [pid 929851:tid 930035] [client 57.141.18.96:47212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UuGV3ou772CelrLiPjAAAt2c"]
[Mon Jul 20 06:29:48.015116 2026] [security2:error] [pid 935758:tid 935917] [client 52.22.236.30:49834] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Uu7cDxY_mIul-JSGGigAAASU"], referer: https://windowtx.com
[Mon Jul 20 06:29:48.055115 2026] [security2:error] [pid 929851:tid 929990] [client 104.234.53.93:30047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4UvGV3ou772CelrLiQfAAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:48.201537 2026] [security2:error] [pid 929851:tid 930097] [client 34.74.185.202:57344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4UvGV3ou772CelrLiQfwAAAPU"]
[Mon Jul 20 06:29:48.379687 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGoAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.379834 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGoAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.389716 2026] [security2:error] [pid 935758:tid 935904] [client 35.231.144.158:55913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UvLcDxY_mIul-JSGGowAAARg"]
[Mon Jul 20 06:29:48.540910 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGqQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.541011 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvLcDxY_mIul-JSGGqQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.593834 2026] [security2:error] [pid 929851:tid 930112] [client 77.110.127.138:64172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvGV3ou772CelrLiQjAAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.593946 2026] [security2:error] [pid 929851:tid 930112] [client 77.110.127.138:64172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvGV3ou772CelrLiQjAAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:48.680120 2026] [security2:error] [pid 935758:tid 935940] [client 103.141.108.143:58881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGrgAAATw"]
[Mon Jul 20 06:29:48.680273 2026] [security2:error] [pid 935758:tid 935940] [client 103.141.108.143:58881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGrgAAATw"]
[Mon Jul 20 06:29:48.704866 2026] [security2:error] [pid 929851:tid 930096] [client 57.141.18.62:25576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UuWV3ou772CelrLiP0gAA9F8"]
[Mon Jul 20 06:29:48.730706 2026] [security2:error] [pid 929851:tid 930012] [client 77.110.127.138:64137] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UvGV3ou772CelrLiQkQAAAKA"]
[Mon Jul 20 06:29:48.749867 2026] [security2:error] [pid 935758:tid 935934] [client 34.74.185.202:50047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4UvLcDxY_mIul-JSGGtAAAATY"]
[Mon Jul 20 06:29:48.774488 2026] [security2:error] [pid 935758:tid 935953] [client 45.116.69.230:60571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGuQAAAUk"]
[Mon Jul 20 06:29:48.774575 2026] [security2:error] [pid 935758:tid 935953] [client 45.116.69.230:60571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4UvLcDxY_mIul-JSGGuQAAAUk"]
[Mon Jul 20 06:29:48.795250 2026] [security2:error] [pid 935758:tid 936011] [client 14.225.17.146:59276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Uu7cDxY_mIul-JSGGYgAAAYM"], referer: http://lelandumc.org/old
[Mon Jul 20 06:29:48.828992 2026] [security2:error] [pid 935758:tid 935967] [client 35.231.144.158:53654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4UvLcDxY_mIul-JSGGvwAAAVc"]
[Mon Jul 20 06:29:48.933727 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4UvGV3ou772CelrLiQlQAAANc"]
[Mon Jul 20 06:29:49.018074 2026] [security2:error] [pid 929851:tid 930007] [client 83.114.245.181:42788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4UvWV3ou772CelrLiQpAAAAJs"]
[Mon Jul 20 06:29:49.076460 2026] [security2:error] [pid 935758:tid 935923] [client 57.141.18.45:36318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UubcDxY_mIul-JSGGJAABKwI"]
[Mon Jul 20 06:29:49.157521 2026] [security2:error] [pid 929851:tid 930106] [client 158.173.89.95:28665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UvWV3ou772CelrLiQrAAAAP4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:49.227766 2026] [security2:error] [pid 929851:tid 930065] [client 35.231.144.158:55899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "bzm.ppv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UvWV3ou772CelrLiQtQAAANU"]
[Mon Jul 20 06:29:49.458022 2026] [security2:error] [pid 935758:tid 936015] [client 34.74.185.202:55924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4UvbcDxY_mIul-JSGG3AAAAYc"]
[Mon Jul 20 06:29:49.459844 2026] [security2:error] [pid 935758:tid 935929] [client 47.128.122.10:46604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG1QABMRk"]
[Mon Jul 20 06:29:49.669550 2026] [core:error] [pid 929851:tid 930012] [client 14.225.17.146:58698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:29:49.669576 2026] [core:error] [pid 929851:tid 930012] [client 14.225.17.146:58698] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:29:49.688946 2026] [security2:error] [pid 929851:tid 930086] [client 121.229.156.93:42212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bluedoorbar.co.nz"] [uri "/"] [unique_id "al4UvWV3ou772CelrLiQyQAAAOo"]
[Mon Jul 20 06:29:49.689044 2026] [security2:error] [pid 929851:tid 930086] [client 121.229.156.93:42212] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.bluedoorbar.co.nz"] [uri "/"] [unique_id "al4UvWV3ou772CelrLiQyQAAAOo"]
[Mon Jul 20 06:29:49.719602 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvWV3ou772CelrLiQzgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:49.719719 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvWV3ou772CelrLiQzgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:49.735131 2026] [security2:error] [pid 935758:tid 935902] [client 39.48.81.23:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UvbcDxY_mIul-JSGG4AAAARY"]
[Mon Jul 20 06:29:49.735227 2026] [security2:error] [pid 935758:tid 935902] [client 39.48.81.23:58774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UvbcDxY_mIul-JSGG4AAAARY"]
[Mon Jul 20 06:29:50.043670 2026] [security2:error] [pid 929851:tid 930055] [client 14.225.17.146:59018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4UvGV3ou772CelrLiQmwAAAMs"], referer: http://getgarrison.com/old
[Mon Jul 20 06:29:50.106621 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG5QAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.189775 2026] [security2:error] [pid 929851:tid 930083] [client 34.74.185.202:60660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4UvmV3ou772CelrLiQ6QAAAOc"]
[Mon Jul 20 06:29:50.284380 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:64193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiQ8AAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.284478 2026] [security2:error] [pid 929851:tid 929998] [client 77.110.127.138:64193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiQ8AAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.620142 2026] [security2:error] [pid 929851:tid 930012] [client 34.74.185.202:52622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.lgi.ful.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4UvmV3ou772CelrLiRBAAAAKA"]
[Mon Jul 20 06:29:50.632373 2026] [security2:error] [pid 929851:tid 930064] [client 104.234.53.53:41421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4UvmV3ou772CelrLiQ_QAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:50.678973 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG-QAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.679168 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG-QAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.730064 2026] [security2:error] [pid 935758:tid 935992] [client 77.110.127.138:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG_AAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.730179 2026] [security2:error] [pid 935758:tid 935992] [client 77.110.127.138:64179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGG_AAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.782277 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 263 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UvrcDxY_mIul-JSGHAQAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.843555 2026] [security2:error] [pid 935758:tid 936014] [client 77.110.127.138:64198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGHAgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.843674 2026] [security2:error] [pid 935758:tid 936014] [client 77.110.127.138:64198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvrcDxY_mIul-JSGHAgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.861274 2026] [security2:error] [pid 935758:tid 935950] [client 57.141.18.113:25232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uu7cDxY_mIul-JSGGcgABRgg"]
[Mon Jul 20 06:29:50.966354 2026] [security2:error] [pid 929851:tid 930071] [client 77.110.127.138:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiRDgAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.966467 2026] [security2:error] [pid 929851:tid 930071] [client 77.110.127.138:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UvmV3ou772CelrLiRDgAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:50.995871 2026] [security2:error] [pid 935758:tid 935967] [client 14.225.17.146:53466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4UvrcDxY_mIul-JSGG9AAAAVc"]
[Mon Jul 20 06:29:51.227317 2026] [security2:error] [pid 935758:tid 935926] [client 14.225.17.146:57586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG5AAAAS4"], referer: http://expertcultures.com/old
[Mon Jul 20 06:29:51.376331 2026] [security2:error] [pid 929851:tid 930069] [client 14.225.17.146:57254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4UvWV3ou772CelrLiQqwAAANk"], referer: http://mrbambooplus.com/old
[Mon Jul 20 06:29:51.648126 2026] [security2:error] [pid 929851:tid 930009] [client 57.141.18.113:25260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvGV3ou772CelrLiQhAAAnSo"]
[Mon Jul 20 06:29:51.653035 2026] [security2:error] [pid 929851:tid 929987] [client 50.116.65.227:19154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Uv2V3ou772CelrLiRGQAAAIc"]
[Mon Jul 20 06:29:51.784500 2026] [security2:error] [pid 929851:tid 930018] [client 14.225.17.146:53381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Uv2V3ou772CelrLiRIAAAAKY"]
[Mon Jul 20 06:29:51.903250 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv7cDxY_mIul-JSGHJQAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.903404 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv7cDxY_mIul-JSGHJQAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.955714 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRLwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.955840 2026] [security2:error] [pid 929851:tid 930092] [client 77.110.127.138:64080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRLwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.965775 2026] [security2:error] [pid 929851:tid 930032] [client 50.116.65.227:19168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Uv2V3ou772CelrLiRJwAAALQ"]
[Mon Jul 20 06:29:51.979247 2026] [security2:error] [pid 929851:tid 929929] [remote 173.212.252.15:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Uv2V3ou772CelrLiRMAAA10k"]
[Mon Jul 20 06:29:51.981238 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:64202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRMQAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:51.981343 2026] [security2:error] [pid 929851:tid 930024] [client 77.110.127.138:64202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uv2V3ou772CelrLiRMQAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.007300 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRNQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.007441 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:64137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRNQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.048644 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHKQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.049156 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHKQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.088757 2026] [security2:error] [pid 929851:tid 930048] [client 112.208.70.94:43661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UwGV3ou772CelrLiROgAAAMQ"]
[Mon Jul 20 06:29:52.088869 2026] [security2:error] [pid 929851:tid 930048] [client 112.208.70.94:43661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UwGV3ou772CelrLiROgAAAMQ"]
[Mon Jul 20 06:29:52.101334 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHLAAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.101503 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHLAAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.153990 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRPwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.154130 2026] [security2:error] [pid 929851:tid 930039] [client 77.110.127.138:64189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRPwAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.156837 2026] [security2:error] [pid 935758:tid 936005] [client 50.116.65.227:19180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4UwLcDxY_mIul-JSGHMQAAAX0"]
[Mon Jul 20 06:29:52.158465 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:64212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRQAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.158537 2026] [security2:error] [pid 929851:tid 930045] [client 77.110.127.138:64212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRQAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.167543 2026] [security2:error] [pid 935758:tid 936006] [client 50.116.65.227:19182] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4UwLcDxY_mIul-JSGHMwAAAX4"]
[Mon Jul 20 06:29:52.205224 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRSAAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.205329 2026] [security2:error] [pid 929851:tid 930097] [client 77.110.127.138:64169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRSAAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.225831 2026] [security2:error] [pid 929851:tid 929888] [remote 173.212.252.15:50898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4UwGV3ou772CelrLiRSQAA-SA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:29:52.313923 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHQAAAAXo"]
[Mon Jul 20 06:29:52.314024 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHQAAAAXo"]
[Mon Jul 20 06:29:52.498354 2026] [security2:error] [pid 929851:tid 929992] [client 104.234.53.53:41421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UwGV3ou772CelrLiRUwAAAIw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:29:52.525684 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHRQAAAYk"]
[Mon Jul 20 06:29:52.525776 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwLcDxY_mIul-JSGHRQAAAYk"]
[Mon Jul 20 06:29:52.688437 2026] [security2:error] [pid 935758:tid 936010] [client 57.141.18.6:28238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvbcDxY_mIul-JSGG2AABghs"]
[Mon Jul 20 06:29:52.718942 2026] [security2:error] [pid 929851:tid 930057] [client 57.141.18.106:34196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvWV3ou772CelrLiQugAAzRI"]
[Mon Jul 20 06:29:52.834227 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRZQAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:52.834426 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwGV3ou772CelrLiRZQAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.119679 2026] [security2:error] [pid 929851:tid 929956] [remote 95.217.78.234:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UwWV3ou772CelrLiRcwAAtGQ"]
[Mon Jul 20 06:29:53.176934 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHXwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.177072 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHXwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.332654 2026] [security2:error] [pid 935758:tid 936014] [client 77.110.127.138:64219] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 969 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UwbcDxY_mIul-JSGHZwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.339022 2026] [security2:error] [pid 935758:tid 935962] [client 57.141.18.105:42774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvrcDxY_mIul-JSGG6gABUiA"]
[Mon Jul 20 06:29:53.339846 2026] [security2:error] [pid 929851:tid 929902] [remote 95.217.78.234:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4UwWV3ou772CelrLiRfAAApC4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:29:53.359256 2026] [security2:error] [pid 935758:tid 935940] [client 14.225.17.146:57472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4UwbcDxY_mIul-JSGHWgAAATw"], referer: http://hilltopnurseryinc.com/old
[Mon Jul 20 06:29:53.386279 2026] [security2:error] [pid 929851:tid 930105] [client 85.87.87.122:57558] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4UwWV3ou772CelrLiRgAAAAP0"]
[Mon Jul 20 06:29:53.421122 2026] [security2:error] [pid 935758:tid 935968] [client 197.186.66.42:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHcgAAAVg"]
[Mon Jul 20 06:29:53.436364 2026] [security2:error] [pid 935758:tid 935968] [client 197.186.66.42:53354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHcgAAAVg"]
[Mon Jul 20 06:29:53.466996 2026] [security2:error] [pid 929851:tid 930094] [client 100.26.198.54:32358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.198.26.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UwWV3ou772CelrLiRiAAAAPI"]
[Mon Jul 20 06:29:53.467150 2026] [security2:error] [pid 929851:tid 930094] [client 100.26.198.54:32358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4UwWV3ou772CelrLiRiAAAAPI"]
[Mon Jul 20 06:29:53.494656 2026] [security2:error] [pid 929851:tid 930106] [client 98.159.234.160:56751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4UwWV3ou772CelrLiRiwAAAP4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:29:53.525520 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwWV3ou772CelrLiRjQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.525675 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwWV3ou772CelrLiRjQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.528520 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwbcDxY_mIul-JSGHYwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.650018 2026] [security2:error] [pid 935758:tid 935935] [client 57.141.18.94:35194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UvrcDxY_mIul-JSGG8AABNyE"]
[Mon Jul 20 06:29:53.714043 2026] [security2:error] [pid 935758:tid 936016] [client 77.110.127.138:64222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHgAAAAYg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.714177 2026] [security2:error] [pid 935758:tid 936016] [client 77.110.127.138:64222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHgAAAAYg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.867494 2026] [security2:error] [pid 935758:tid 935891] [client 171.61.165.146:14626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHiwAAAQs"]
[Mon Jul 20 06:29:53.868425 2026] [security2:error] [pid 935758:tid 935891] [client 171.61.165.146:14626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHiwAAAQs"]
[Mon Jul 20 06:29:53.872784 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHjAAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.872912 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UwbcDxY_mIul-JSGHjAAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:53.880160 2026] [security2:error] [pid 935758:tid 935966] [client 106.219.188.178:40187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHjQAAAVY"]
[Mon Jul 20 06:29:53.887500 2026] [security2:error] [pid 935758:tid 935966] [client 106.219.188.178:40187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UwbcDxY_mIul-JSGHjQAAAVY"]
[Mon Jul 20 06:29:54.229961 2026] [security2:error] [pid 935758:tid 935893] [client 66.249.93.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4UwLcDxY_mIul-JSGHPwAAAQ0"]
[Mon Jul 20 06:29:54.245593 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHnAAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.276334 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHoAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.664518 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHsQAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.835252 2026] [security2:error] [pid 935758:tid 935923] [client 77.110.127.138:64230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHsgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.871139 2026] [security2:error] [pid 929851:tid 930111] [client 77.110.127.138:64244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 401 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UwmV3ou772CelrLiR1gAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:54.879707 2026] [security2:error] [pid 935758:tid 935928] [client 14.225.17.146:57188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4UwLcDxY_mIul-JSGHVAAAATA"], referer: http://cheesewithjam.com/old
[Mon Jul 20 06:29:55.023322 2026] [security2:error] [pid 935758:tid 935939] [client 77.110.127.138:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHygAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.023424 2026] [security2:error] [pid 935758:tid 935939] [client 77.110.127.138:64246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHygAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.178479 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR5QAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.178570 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR5QAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.328282 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHzwAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.328414 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw7cDxY_mIul-JSGHzwAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.373872 2026] [security2:error] [pid 929851:tid 930091] [client 77.110.127.138:64203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiR4AAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.378413 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR9gAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.378512 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR9gAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.558262 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR_AAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.558384 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiR_AAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.738632 2026] [security2:error] [pid 935758:tid 935943] [client 14.225.17.146:53252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHqAAAAT8"], referer: http://amalia-capital.com/old
[Mon Jul 20 06:29:55.770230 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSBgAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.770347 2026] [security2:error] [pid 929851:tid 930026] [client 77.110.127.138:64217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSBgAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.798922 2026] [security2:error] [pid 935758:tid 936009] [client 82.102.27.163:60212] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Uw7cDxY_mIul-JSGH2wAAAYE"]
[Mon Jul 20 06:29:55.799012 2026] [security2:error] [pid 935758:tid 936009] [client 82.102.27.163:60212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4Uw7cDxY_mIul-JSGH2wAAAYE"]
[Mon Jul 20 06:29:55.874382 2026] [security2:error] [pid 929851:tid 930096] [client 223.185.13.213:27813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uw2V3ou772CelrLiSFAAAAPQ"]
[Mon Jul 20 06:29:55.874465 2026] [security2:error] [pid 929851:tid 930096] [client 223.185.13.213:27813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Uw2V3ou772CelrLiSFAAAAPQ"]
[Mon Jul 20 06:29:55.966831 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSGAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:55.966954 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uw2V3ou772CelrLiSGAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.036175 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH5wAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.036900 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH5wAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.075289 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.98:39572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UwLcDxY_mIul-JSGHVwABhTM"]
[Mon Jul 20 06:29:56.206100 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uw7cDxY_mIul-JSGH5AAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.260796 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH7AAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.260918 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGH7AAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.300629 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:53401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiSBAAAAKQ"], referer: http://eframiproperties.com/old
[Mon Jul 20 06:29:56.636200 2026] [security2:error] [pid 929851:tid 929995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UxGV3ou772CelrLiSKQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.839658 2026] [security2:error] [pid 929851:tid 930060] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4UxGV3ou772CelrLiSMQAA0Ek"], referer: http://aleishapenny.ca/old
[Mon Jul 20 06:29:56.904724 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UxLcDxY_mIul-JSGIFwAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.957984 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGIGQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.958120 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxLcDxY_mIul-JSGIGQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:56.983342 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:64263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UxLcDxY_mIul-JSGIDQAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:57.181894 2026] [security2:error] [pid 929851:tid 930041] [client 14.225.17.146:53464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiSAwAAAL0"], referer: http://bbwipartnerconference.com/old
[Mon Jul 20 06:29:57.367712 2026] [security2:error] [pid 935758:tid 936003] [client 57.141.18.11:52866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UwrcDxY_mIul-JSGHnwABe0w"]
[Mon Jul 20 06:29:57.677875 2026] [security2:error] [pid 929851:tid 930070] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4UxWV3ou772CelrLiSTAAA2lg"], referer: https://aleishapenny.ca/old
[Mon Jul 20 06:29:58.154994 2026] [security2:error] [pid 935758:tid 935979] [client 171.60.139.123:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UxrcDxY_mIul-JSGIUQAAAWM"]
[Mon Jul 20 06:29:58.155193 2026] [security2:error] [pid 935758:tid 935979] [client 171.60.139.123:52309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4UxrcDxY_mIul-JSGIUQAAAWM"]
[Mon Jul 20 06:29:58.406175 2026] [security2:error] [pid 929851:tid 930046] [client 57.141.18.55:65282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiR4wAAwhA"]
[Mon Jul 20 06:29:58.593126 2026] [security2:error] [pid 929851:tid 930045] [client 57.141.18.44:22124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiR7wAAwUE"]
[Mon Jul 20 06:29:58.609854 2026] [security2:error] [pid 935758:tid 935767] [remote 152.53.111.131:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UxrcDxY_mIul-JSGIZwABDAY"]
[Mon Jul 20 06:29:58.832281 2026] [security2:error] [pid 935758:tid 935773] [remote 152.53.111.131:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4UxrcDxY_mIul-JSGIeQABCww"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:29:58.958510 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxmV3ou772CelrLiSdQAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:58.958626 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UxmV3ou772CelrLiSdQAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:58.987849 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.7:62770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uw2V3ou772CelrLiSDQAA3yw"]
[Mon Jul 20 06:29:59.112287 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ux7cDxY_mIul-JSGIiAAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.112401 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Ux7cDxY_mIul-JSGIiAAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.404976 2026] [security2:error] [pid 935758:tid 935978] [client 103.141.108.143:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGImwAAAWI"]
[Mon Jul 20 06:29:59.405569 2026] [security2:error] [pid 935758:tid 935978] [client 103.141.108.143:59396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGImwAAAWI"]
[Mon Jul 20 06:29:59.526679 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ux2V3ou772CelrLiSegAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.561514 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:64273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ux7cDxY_mIul-JSGIkAAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.564594 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ux2V3ou772CelrLiSgAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:29:59.694041 2026] [security2:error] [pid 935758:tid 935892] [client 45.116.69.230:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGIpwAAAQw"]
[Mon Jul 20 06:29:59.694137 2026] [security2:error] [pid 935758:tid 935892] [client 45.116.69.230:61106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4Ux7cDxY_mIul-JSGIpwAAAQw"]
[Mon Jul 20 06:29:59.766618 2026] [security2:error] [pid 929851:tid 929924] [remote 160.187.68.132:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4Ux2V3ou772CelrLiSkgAAikQ"]
[Mon Jul 20 06:30:00.117830 2026] [security2:error] [pid 935758:tid 935966] [client 57.141.18.50:27512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UxLcDxY_mIul-JSGICAABVmg"]
[Mon Jul 20 06:30:00.168593 2026] [core:error] [pid 935758:tid 935918] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:00.168622 2026] [core:error] [pid 935758:tid 935918] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:00.294534 2026] [security2:error] [pid 929851:tid 929953] [remote 160.187.68.132:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4UyGV3ou772CelrLiSpwAArWE"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:30:00.351957 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyGV3ou772CelrLiSoAAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.393204 2026] [security2:error] [pid 935758:tid 935976] [client 63.179.149.246:36006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UyLcDxY_mIul-JSGIvgAAAWA"]
[Mon Jul 20 06:30:00.416226 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGIvwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.416337 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGIvwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.428058 2026] [security2:error] [pid 935758:tid 935960] [client 39.48.81.23:59254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UyLcDxY_mIul-JSGIwAAAAVA"]
[Mon Jul 20 06:30:00.428172 2026] [security2:error] [pid 935758:tid 935960] [client 39.48.81.23:59254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4UyLcDxY_mIul-JSGIwAAAAVA"]
[Mon Jul 20 06:30:00.462624 2026] [security2:error] [pid 929851:tid 930065] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyGV3ou772CelrLiSpQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.741217 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyGV3ou772CelrLiSvQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.741367 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyGV3ou772CelrLiSvQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.791284 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGI0QAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.791396 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyLcDxY_mIul-JSGI0QAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:00.958082 2026] [security2:error] [pid 935758:tid 935944] [client 3.75.183.99:29194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4UyLcDxY_mIul-JSGI2wAAAUA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:30:00.975206 2026] [security2:error] [pid 935758:tid 935961] [client 77.110.127.138:64280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGIzQAAAVE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.013059 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGIzwAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.043228 2026] [security2:error] [pid 935758:tid 935941] [client 57.141.18.6:22956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UxbcDxY_mIul-JSGILQABPXI"]
[Mon Jul 20 06:30:01.143961 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI5QAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.144108 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI5QAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.248251 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UybcDxY_mIul-JSGI4QAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.445772 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:64286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI-wAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.445877 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:64286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGI-wAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.783894 2026] [security2:error] [pid 929851:tid 930035] [client 77.110.127.138:64284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UyWV3ou772CelrLiS1wAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.824110 2026] [security2:error] [pid 935758:tid 936006] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UybcDxY_mIul-JSGI-QAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.825826 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UybcDxY_mIul-JSGJAAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.909787 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyWV3ou772CelrLiS7gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.909918 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UyWV3ou772CelrLiS7gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.918208 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGJFwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:01.918383 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UybcDxY_mIul-JSGJFwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:02.338489 2026] [security2:error] [pid 929851:tid 929890] [remote 50.28.1.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4UymV3ou772CelrLiTAAAAiSI"]
[Mon Jul 20 06:30:02.338709 2026] [security2:error] [pid 929851:tid 929989] [client 50.28.1.50:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4UymV3ou772CelrLiTAAAAiSI"]
[Mon Jul 20 06:30:02.580534 2026] [security2:error] [pid 935758:tid 935902] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-27c0eea6.iwv.oao.mybluehost.me"] [uri "/index.php"] [unique_id "al4UxrcDxY_mIul-JSGIcwAAARY"]
[Mon Jul 20 06:30:02.837950 2026] [security2:error] [pid 929851:tid 930072] [client 57.141.18.94:29264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UxmV3ou772CelrLiSaAAA3CE"]
[Mon Jul 20 06:30:03.959064 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uy7cDxY_mIul-JSGJYwAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.226405 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:64293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uy7cDxY_mIul-JSGJegAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.235175 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJgQAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.406994 2026] [security2:error] [pid 935758:tid 936010] [client 57.141.18.104:42536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGItgABghk"]
[Mon Jul 20 06:30:04.427571 2026] [security2:error] [pid 935758:tid 935978] [client 197.186.66.42:53822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJngAAAWI"]
[Mon Jul 20 06:30:04.427710 2026] [security2:error] [pid 935758:tid 935978] [client 197.186.66.42:53822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJngAAAWI"]
[Mon Jul 20 06:30:04.530958 2026] [security2:error] [pid 935758:tid 935986] [client 171.61.165.146:16808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJoAAAAWo"]
[Mon Jul 20 06:30:04.531107 2026] [security2:error] [pid 935758:tid 935986] [client 171.61.165.146:16808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4UzLcDxY_mIul-JSGJoAAAAWo"]
[Mon Jul 20 06:30:04.595270 2026] [security2:error] [pid 935758:tid 935835] [remote 72.167.132.114:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4UzLcDxY_mIul-JSGJpwABR0o"]
[Mon Jul 20 06:30:04.681917 2026] [security2:error] [pid 929851:tid 929991] [client 106.219.188.178:51798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UzGV3ou772CelrLiTXwAAAIs"]
[Mon Jul 20 06:30:04.682351 2026] [security2:error] [pid 929851:tid 929991] [client 106.219.188.178:51798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4UzGV3ou772CelrLiTXwAAAIs"]
[Mon Jul 20 06:30:04.781649 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJrwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.781766 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJrwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.791352 2026] [security2:error] [pid 935758:tid 935905] [client 57.141.18.108:61724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGIxQABGR4"]
[Mon Jul 20 06:30:04.824499 2026] [security2:error] [pid 935758:tid 935839] [remote 72.167.132.114:46070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4UzLcDxY_mIul-JSGJtAABaU4"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:30:04.882549 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJtwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.882716 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJtwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:04.934980 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:64305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJuQAAAR0"]
[Mon Jul 20 06:30:04.935101 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:64305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzLcDxY_mIul-JSGJuQAAAR0"]
[Mon Jul 20 06:30:05.060442 2026] [security2:error] [pid 935758:tid 935949] [client 24.216.165.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "poopatrol608.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJuAAAAUU"], referer: https://facebook.com/
[Mon Jul 20 06:30:05.147726 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJxAAAAYI"]
[Mon Jul 20 06:30:05.147853 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJxAAAAYI"]
[Mon Jul 20 06:30:05.174011 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.32:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyLcDxY_mIul-JSGI1AABYx0"]
[Mon Jul 20 06:30:05.372472 2026] [security2:error] [pid 935758:tid 935895] [client 77.110.127.138:64307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJvgAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.413949 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64311] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4UzWV3ou772CelrLiTegAAAKE"]
[Mon Jul 20 06:30:05.415133 2026] [security2:error] [pid 935758:tid 936003] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJvwAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.420441 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJwgAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.480019 2026] [security2:error] [pid 935758:tid 936004] [client 14.225.17.146:60518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJhwAAAXw"], referer: http://momheadquarters.com/old
[Mon Jul 20 06:30:05.535715 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzWV3ou772CelrLiTfQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.535853 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzWV3ou772CelrLiTfQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.541077 2026] [security2:error] [pid 935758:tid 935926] [client 104.234.53.61:57857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4UzbcDxY_mIul-JSGJ3gAAAS4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:05.754145 2026] [security2:error] [pid 935758:tid 935802] [remote 57.141.18.77:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4107923"] [unique_id "al4UzbcDxY_mIul-JSGJ6QABESk"]
[Mon Jul 20 06:30:05.900800 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJ6AAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.907365 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ9wAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.907474 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ9wAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.960558 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ-wAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:05.960657 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:64287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzbcDxY_mIul-JSGJ-wAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:06.015202 2026] [security2:error] [pid 935758:tid 935953] [client 112.208.70.94:44131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UzrcDxY_mIul-JSGJ_gAAAUk"]
[Mon Jul 20 06:30:06.015375 2026] [security2:error] [pid 935758:tid 935953] [client 112.208.70.94:44131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4UzrcDxY_mIul-JSGJ_gAAAUk"]
[Mon Jul 20 06:30:06.054679 2026] [security2:error] [pid 935758:tid 936012] [client 216.73.216.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.poopscoopmarketing.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJ9AAAAYQ"]
[Mon Jul 20 06:30:06.239706 2026] [security2:error] [pid 935758:tid 935920] [client 57.141.18.30:23182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UyrcDxY_mIul-JSGJHgABKC4"]
[Mon Jul 20 06:30:06.659726 2026] [security2:error] [pid 935758:tid 935968] [client 77.110.127.138:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzrcDxY_mIul-JSGKQQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:06.659839 2026] [security2:error] [pid 935758:tid 935968] [client 77.110.127.138:64319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4UzrcDxY_mIul-JSGKQQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:06.670788 2026] [security2:error] [pid 935758:tid 935961] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKFwAAAVE"]
[Mon Jul 20 06:30:06.702095 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKIwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.042634 2026] [security2:error] [pid 935758:tid 935951] [client 77.110.127.138:64323] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4Uz7cDxY_mIul-JSGKYgAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.046178 2026] [security2:error] [pid 929851:tid 930040] [client 72.154.155.130:33090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "webmail.seidemannlab.site"] [uri "/___proxy_subdomain_webmail/"] [unique_id "al4Uz2V3ou772CelrLiTtAAAALw"]
[Mon Jul 20 06:30:07.079925 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4UzmV3ou772CelrLiTsAAAAMQ"]
[Mon Jul 20 06:30:07.196559 2026] [security2:error] [pid 929851:tid 930068] [client 57.141.18.52:33176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UymV3ou772CelrLiTFwAA2C0"]
[Mon Jul 20 06:30:07.205774 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKbwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.205875 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:64325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKbwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.256890 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKdQAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.257054 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKdQAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.289869 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Uz7cDxY_mIul-JSGKYAAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.434940 2026] [core:error] [pid 929851:tid 930041] [client 14.225.17.146:64220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:07.434967 2026] [core:error] [pid 929851:tid 930041] [client 14.225.17.146:64220] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:07.572126 2026] [security2:error] [pid 929851:tid 930050] [client 57.141.18.111:57470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uy2V3ou772CelrLiTNgAAxhE"]
[Mon Jul 20 06:30:07.613038 2026] [security2:error] [pid 929851:tid 930016] [client 14.225.17.146:60317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Uz2V3ou772CelrLiTyQAAAKQ"]
[Mon Jul 20 06:30:07.626552 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiTzAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.626646 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiTzAAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.679621 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKhwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.679760 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:64308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKhwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.873008 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKkQAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.873147 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Uz7cDxY_mIul-JSGKkQAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:07.909766 2026] [security2:error] [pid 929851:tid 930104] [client 87.199.196.160:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.nurturemarple.co.uk"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiT2wAAAPw"], referer: https://www.nurturemarple.co.uk/download/pre-school-september-2023/
[Mon Jul 20 06:30:07.909875 2026] [security2:error] [pid 929851:tid 930104] [client 87.199.196.160:58065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.nurturemarple.co.uk"] [uri "/wp-comments-post.php"] [unique_id "al4Uz2V3ou772CelrLiT2wAAAPw"], referer: https://www.nurturemarple.co.uk/download/pre-school-september-2023/
[Mon Jul 20 06:30:07.941055 2026] [security2:error] [pid 935758:tid 936008] [client 14.225.17.146:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKAgAAAYA"], referer: http://tacticaltreeoperations.com/old
[Mon Jul 20 06:30:08.150261 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:64329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT5QAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.150398 2026] [security2:error] [pid 929851:tid 930067] [client 77.110.127.138:64329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT5QAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.219130 2026] [security2:error] [pid 935758:tid 935967] [client 57.141.18.61:39930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJfQABV0A"]
[Mon Jul 20 06:30:08.266442 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT6gAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.266559 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0GV3ou772CelrLiT6gAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.452769 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKuAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.452908 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKuAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.583622 2026] [security2:error] [pid 935758:tid 935897] [client 14.225.17.146:54225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4Uz7cDxY_mIul-JSGKeAAAARE"], referer: http://idigress.agency/old
[Mon Jul 20 06:30:08.645378 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKvwAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.645470 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0LcDxY_mIul-JSGKvwAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:08.746192 2026] [security2:error] [pid 935758:tid 935965] [client 114.119.153.172:31841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jndsupport.com"] [uri "/heres-whats-in-store-for-the-last-windows-moments-update/"] [unique_id "al4U0LcDxY_mIul-JSGKwgAAAVU"], referer: https://jndsupport.com/blog/
[Mon Jul 20 06:30:08.877335 2026] [security2:error] [pid 935758:tid 935946] [client 57.141.18.21:41378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJpQABQkk"]
[Mon Jul 20 06:30:08.892691 2026] [security2:error] [pid 935758:tid 935890] [client 57.141.18.25:57198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzLcDxY_mIul-JSGJqAABCiM"]
[Mon Jul 20 06:30:09.005597 2026] [security2:error] [pid 935758:tid 935870] [remote 152.228.213.32:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4U0LcDxY_mIul-JSGK0QABTW0"]
[Mon Jul 20 06:30:09.038546 2026] [security2:error] [pid 929851:tid 929989] [client 77.110.127.138:64337] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/cowl/feed/"] [unique_id "al4U0WV3ou772CelrLiUCQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.089054 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0bcDxY_mIul-JSGK1QAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.089240 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:64316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0bcDxY_mIul-JSGK1QAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.163790 2026] [security2:error] [pid 935758:tid 935899] [client 171.60.139.123:52836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U0bcDxY_mIul-JSGK1gAAARM"]
[Mon Jul 20 06:30:09.163914 2026] [security2:error] [pid 935758:tid 935899] [client 171.60.139.123:52836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U0bcDxY_mIul-JSGK1gAAARM"]
[Mon Jul 20 06:30:09.198318 2026] [security2:error] [pid 935758:tid 935772] [remote 152.228.213.32:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4U0bcDxY_mIul-JSGK2gABcQs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:30:09.201550 2026] [core:error] [pid 935758:tid 935920] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.201583 2026] [core:error] [pid 935758:tid 935920] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.253723 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4U0bcDxY_mIul-JSGK3wAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:09.598478 2026] [security2:error] [pid 935758:tid 935888] [remote 91.142.222.105:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4U0bcDxY_mIul-JSGK8QABDn8"]
[Mon Jul 20 06:30:09.621557 2026] [security2:error] [pid 929851:tid 930070] [client 223.185.13.213:23492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0WV3ou772CelrLiUIAAAANo"]
[Mon Jul 20 06:30:09.621692 2026] [security2:error] [pid 929851:tid 930070] [client 223.185.13.213:23492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0WV3ou772CelrLiUIAAAANo"]
[Mon Jul 20 06:30:09.656464 2026] [core:error] [pid 929851:tid 930059] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.656482 2026] [core:error] [pid 929851:tid 930072] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.656491 2026] [core:error] [pid 929851:tid 930059] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.656502 2026] [core:error] [pid 929851:tid 930072] [client 207.241.172.220:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:09.750696 2026] [security2:error] [pid 935758:tid 935903] [client 57.141.18.53:41958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzbcDxY_mIul-JSGJ3AABF1Q"]
[Mon Jul 20 06:30:09.894520 2026] [proxy:error] [pid 935758:tid 936015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:09.894573 2026] [proxy_http:error] [pid 935758:tid 936015] [client 34.73.38.214:56403] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:09.895564 2026] [proxy:error] [pid 935758:tid 936015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:09.895625 2026] [proxy_http:error] [pid 935758:tid 936015] [client 34.73.38.214:56403] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:09.928261 2026] [security2:error] [pid 935758:tid 935783] [remote 91.142.222.105:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4U0bcDxY_mIul-JSGLAgABIhY"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:30:10.000570 2026] [security2:error] [pid 929851:tid 930012] [client 14.225.17.146:60423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4U0WV3ou772CelrLiULAAAAKA"], referer: http://thechancersband.com/old
[Mon Jul 20 06:30:10.090610 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U0mV3ou772CelrLiUNAAAAQQ"]
[Mon Jul 20 06:30:10.090740 2026] [security2:error] [pid 929851:tid 930112] [client 103.141.108.143:59885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U0mV3ou772CelrLiUNAAAAQQ"]
[Mon Jul 20 06:30:10.224458 2026] [security2:error] [pid 935758:tid 935910] [client 14.225.17.146:64074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4U0LcDxY_mIul-JSGKtwAAAR4"], referer: http://fluidtemple.org/old
[Mon Jul 20 06:30:10.312722 2026] [security2:error] [pid 935758:tid 935981] [client 158.173.166.181:46685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U0rcDxY_mIul-JSGLGAAAAWU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:10.520476 2026] [security2:error] [pid 935758:tid 935911] [client 45.116.69.230:61651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLLAAAAR8"]
[Mon Jul 20 06:30:10.520645 2026] [security2:error] [pid 935758:tid 935911] [client 45.116.69.230:61651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLLAAAAR8"]
[Mon Jul 20 06:30:10.675160 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0mV3ou772CelrLiURwAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:10.675313 2026] [security2:error] [pid 929851:tid 930093] [client 77.110.127.138:64340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U0mV3ou772CelrLiURwAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:10.955954 2026] [security2:error] [pid 935758:tid 935918] [client 39.48.81.23:59745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLPAAAASY"]
[Mon Jul 20 06:30:10.956073 2026] [security2:error] [pid 935758:tid 935918] [client 39.48.81.23:59745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U0rcDxY_mIul-JSGLPAAAASY"]
[Mon Jul 20 06:30:10.967196 2026] [security2:error] [pid 935758:tid 936017] [client 57.141.18.102:51810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4UzrcDxY_mIul-JSGKNQABiTQ"]
[Mon Jul 20 06:30:11.049929 2026] [security2:error] [pid 935758:tid 935936] [client 50.116.65.227:45964] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U07cDxY_mIul-JSGLQwAAATg"]
[Mon Jul 20 06:30:11.062963 2026] [security2:error] [pid 935758:tid 935897] [client 50.116.65.227:45978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U07cDxY_mIul-JSGLRwAAARE"]
[Mon Jul 20 06:30:11.088915 2026] [security2:error] [pid 929851:tid 930074] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U0mV3ou772CelrLiUTAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.213736 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:11.213836 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57269] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:11.215168 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:11.215207 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57269] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:11.314918 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U07cDxY_mIul-JSGLVQAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.315096 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U07cDxY_mIul-JSGLVQAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.366804 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/cowl/feed/"] [unique_id "al4U07cDxY_mIul-JSGLWgAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:11.438854 2026] [security2:error] [pid 935758:tid 935800] [remote 192.241.143.148:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U07cDxY_mIul-JSGLXAABQCc"]
[Mon Jul 20 06:30:11.585187 2026] [security2:error] [pid 935758:tid 935990] [client 57.141.18.22:49872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uz7cDxY_mIul-JSGKcwABbmY"]
[Mon Jul 20 06:30:11.621684 2026] [security2:error] [pid 935758:tid 935809] [remote 192.241.143.148:41582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U07cDxY_mIul-JSGLaQABVzA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:11.862146 2026] [security2:error] [pid 929851:tid 930008] [client 57.141.18.3:41510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Uz2V3ou772CelrLiTzQAAnFI"]
[Mon Jul 20 06:30:12.008547 2026] [security2:error] [pid 935758:tid 935920] [client 14.225.17.146:57096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLHwAAASg"], referer: http://olearyplumbingllc.com/old
[Mon Jul 20 06:30:12.055210 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1LcDxY_mIul-JSGLfwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:12.055321 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1LcDxY_mIul-JSGLfwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:12.109108 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4U1LcDxY_mIul-JSGLgwAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:12.588332 2026] [proxy:error] [pid 929851:tid 930089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:12.588419 2026] [proxy_http:error] [pid 929851:tid 930089] [client 34.73.38.214:56754] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:12.589603 2026] [proxy:error] [pid 929851:tid 930089] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:12.589647 2026] [proxy_http:error] [pid 929851:tid 930089] [client 34.73.38.214:56754] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:12.590563 2026] [security2:error] [pid 935758:tid 935919] [client 14.225.17.146:54491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLPQAAASc"], referer: http://floorsourcestock.com/old
[Mon Jul 20 06:30:12.733070 2026] [security2:error] [pid 935758:tid 935957] [client 14.225.17.146:54465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLNwAAAU0"], referer: http://aandarealtygroup.com/old
[Mon Jul 20 06:30:13.334742 2026] [security2:error] [pid 929851:tid 930091] [client 34.221.76.50:29440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4U1WV3ou772CelrLiUoQAAAO8"]
[Mon Jul 20 06:30:13.812367 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.37:52096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U0WV3ou772CelrLiUHwAAn2w"]
[Mon Jul 20 06:30:14.011064 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL2AAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.011217 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL2AAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.254114 2026] [security2:error] [pid 935758:tid 935983] [client 57.141.18.33:20336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U0bcDxY_mIul-JSGLCwABZwI"]
[Mon Jul 20 06:30:14.330018 2026] [security2:error] [pid 935758:tid 935790] [remote 20.173.88.122:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U1rcDxY_mIul-JSGL6QABOB0"]
[Mon Jul 20 06:30:14.359415 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/cowl/feed/"] [unique_id "al4U1rcDxY_mIul-JSGL7AAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.510845 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1mV3ou772CelrLiUzwAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.510952 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1mV3ou772CelrLiUzwAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.541381 2026] [proxy:error] [pid 935758:tid 935922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:14.541455 2026] [proxy_http:error] [pid 935758:tid 935922] [client 34.73.38.214:60308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:14.542886 2026] [proxy:error] [pid 935758:tid 935922] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:14.542928 2026] [proxy_http:error] [pid 935758:tid 935922] [client 34.73.38.214:60308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:14.555366 2026] [security2:error] [pid 935758:tid 935986] [client 65.111.25.164:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U1rcDxY_mIul-JSGL8AAAAWo"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:14.573299 2026] [security2:error] [pid 935758:tid 935894] [client 14.225.17.146:54719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4U1bcDxY_mIul-JSGLugAAAQ4"], referer: http://betterbonddogtraining.com/old
[Mon Jul 20 06:30:14.634496 2026] [security2:error] [pid 935758:tid 935947] [client 57.141.18.30:45400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U0rcDxY_mIul-JSGLHAABQxw"]
[Mon Jul 20 06:30:14.663517 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL-QAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.663631 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U1rcDxY_mIul-JSGL-QAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.733012 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U1rcDxY_mIul-JSGL7wAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:14.908286 2026] [security2:error] [pid 935758:tid 935846] [remote 20.173.88.122:37552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U1rcDxY_mIul-JSGMBAABDFU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:14.999276 2026] [security2:error] [pid 929851:tid 930000] [client 14.225.17.146:64161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4U1mV3ou772CelrLiU4QAAAJQ"], referer: http://omrobuildingcenter.com/old
[Mon Jul 20 06:30:15.131304 2026] [security2:error] [pid 935758:tid 935976] [client 45.157.112.60:35583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U17cDxY_mIul-JSGMDAAAAWA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:15.264572 2026] [security2:error] [pid 935758:tid 935995] [client 197.186.66.42:54295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFAAAAXM"]
[Mon Jul 20 06:30:15.265024 2026] [security2:error] [pid 935758:tid 935995] [client 197.186.66.42:54295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFAAAAXM"]
[Mon Jul 20 06:30:15.328661 2026] [security2:error] [pid 935758:tid 935939] [client 171.61.165.146:17532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFwAAATs"]
[Mon Jul 20 06:30:15.329641 2026] [security2:error] [pid 935758:tid 935939] [client 171.61.165.146:17532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMFwAAATs"]
[Mon Jul 20 06:30:15.344345 2026] [security2:error] [pid 935758:tid 935919] [client 106.219.188.178:25950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMGQAAASc"]
[Mon Jul 20 06:30:15.344745 2026] [security2:error] [pid 935758:tid 935919] [client 106.219.188.178:25950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U17cDxY_mIul-JSGMGQAAASc"]
[Mon Jul 20 06:30:15.647940 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMHQAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:15.974864 2026] [security2:error] [pid 935758:tid 935957] [client 34.73.38.214:63400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4U17cDxY_mIul-JSGMNAAAAU0"]
[Mon Jul 20 06:30:16.050310 2026] [security2:error] [pid 935758:tid 935868] [remote 57.141.18.102:58620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4U2LcDxY_mIul-JSGMNgABS2s"]
[Mon Jul 20 06:30:16.117075 2026] [security2:error] [pid 929851:tid 930071] [client 57.141.18.2:22532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U02V3ou772CelrLiUcAAA2wY"]
[Mon Jul 20 06:30:16.153500 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U12V3ou772CelrLiVFQAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:16.163644 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2LcDxY_mIul-JSGMOQAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:16.163792 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2LcDxY_mIul-JSGMOQAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:16.174870 2026] [security2:error] [pid 935758:tid 936015] [client 57.141.18.9:46940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U07cDxY_mIul-JSGLdQABhxE"]
[Mon Jul 20 06:30:16.220490 2026] [autoindex:error] [pid 929851:tid 930110] [client 43.130.111.40:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.varmath.com
[Mon Jul 20 06:30:16.246902 2026] [security2:error] [pid 935758:tid 936003] [client 57.141.18.125:34028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U1LcDxY_mIul-JSGLgAABeyA"]
[Mon Jul 20 06:30:16.469205 2026] [security2:error] [pid 935758:tid 935879] [remote 194.164.192.228:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4U2LcDxY_mIul-JSGMQwABI3Y"]
[Mon Jul 20 06:30:16.689438 2026] [security2:error] [pid 935758:tid 935866] [remote 194.164.192.228:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4U2LcDxY_mIul-JSGMRgABCmk"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:30:16.736953 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2GV3ou772CelrLiVNQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.031183 2026] [security2:error] [pid 935758:tid 935899] [client 57.141.18.118:55038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U1LcDxY_mIul-JSGLrAABE0Q"]
[Mon Jul 20 06:30:17.074969 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2bcDxY_mIul-JSGMYQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.075142 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2bcDxY_mIul-JSGMYQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.127055 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2WV3ou772CelrLiVTgAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.127179 2026] [security2:error] [pid 929851:tid 930032] [client 77.110.127.138:64311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2WV3ou772CelrLiVTgAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.177822 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4U2bcDxY_mIul-JSGMZAAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.342697 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2bcDxY_mIul-JSGMYgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.447906 2026] [security2:error] [pid 929851:tid 930099] [client 13.201.64.214:46334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U2WV3ou772CelrLiVWQAAAPc"]
[Mon Jul 20 06:30:17.447981 2026] [security2:error] [pid 929851:tid 930099] [client 13.201.64.214:46334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U2WV3ou772CelrLiVWQAAAPc"]
[Mon Jul 20 06:30:17.519328 2026] [security2:error] [pid 929851:tid 930104] [client 34.73.38.214:53808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4U2WV3ou772CelrLiVXAAAAPw"]
[Mon Jul 20 06:30:17.561683 2026] [core:error] [pid 929851:tid 930072] [client 103.153.183.69:37106] AH10244: invalid URI path (/../../../../etc/passwd?_=3scrqhos&v=4hezl), referer: https://duckduckgo.com/?q=7kcgk
[Mon Jul 20 06:30:17.565056 2026] [security2:error] [pid 935758:tid 935927] [client 127.0.0.1:43090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4U2bcDxY_mIul-JSGMdQAAAS8"], referer: https://duckduckgo.com/?q=7kcgk
[Mon Jul 20 06:30:17.651650 2026] [security2:error] [pid 929851:tid 930019] [client 57.141.18.4:52670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U1WV3ou772CelrLiUpQAApy0"]
[Mon Jul 20 06:30:17.888190 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2WV3ou772CelrLiVaQAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.900720 2026] [security2:error] [pid 929851:tid 930043] [client 14.225.17.146:54041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4U2GV3ou772CelrLiVMQAAAL8"], referer: http://kromosenergy.com/old
[Mon Jul 20 06:30:17.977290 2026] [security2:error] [pid 929851:tid 930076] [client 77.110.127.138:64355] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U2WV3ou772CelrLiVfAAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:17.990067 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4U2GV3ou772CelrLiVLwAAANU"], referer: http://ironcitywellness.com/old
[Mon Jul 20 06:30:18.152106 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMgwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.152243 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMgwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.315194 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:64379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVhQAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.315296 2026] [security2:error] [pid 929851:tid 930089] [client 77.110.127.138:64379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVhQAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.406863 2026] [security2:error] [pid 935758:tid 935772] [remote 124.55.178.99:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4U2rcDxY_mIul-JSGMjgABfQs"]
[Mon Jul 20 06:30:18.522490 2026] [security2:error] [pid 935758:tid 935973] [client 112.208.70.94:44563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U2rcDxY_mIul-JSGMlwAAAV0"]
[Mon Jul 20 06:30:18.522678 2026] [security2:error] [pid 935758:tid 935973] [client 112.208.70.94:44563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U2rcDxY_mIul-JSGMlwAAAV0"]
[Mon Jul 20 06:30:18.530575 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:64380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMmQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.530685 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:64380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMmQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.593972 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:64361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVlwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.594078 2026] [security2:error] [pid 929851:tid 930068] [client 77.110.127.138:64361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVlwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.645910 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVmQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.646083 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVmQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.684673 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2mV3ou772CelrLiVgwAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:18.712866 2026] [security2:error] [pid 929851:tid 930009] [client 77.110.127.138:64362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVnQAAAJ0"]
[Mon Jul 20 06:30:18.712988 2026] [security2:error] [pid 929851:tid 930009] [client 77.110.127.138:64362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2mV3ou772CelrLiVnQAAAJ0"]
[Mon Jul 20 06:30:18.863203 2026] [security2:error] [pid 935758:tid 935974] [client 77.110.127.138:64382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMpgAAAV4"]
[Mon Jul 20 06:30:18.863287 2026] [security2:error] [pid 935758:tid 935974] [client 77.110.127.138:64382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U2rcDxY_mIul-JSGMpgAAAV4"]
[Mon Jul 20 06:30:18.863501 2026] [security2:error] [pid 935758:tid 935858] [remote 124.55.178.99:36350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4U2rcDxY_mIul-JSGMpwABSWE"], referer: https://travelbyfire.com/wp-login.php
[Mon Jul 20 06:30:19.171335 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2rcDxY_mIul-JSGMtAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.218848 2026] [security2:error] [pid 935758:tid 935911] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U2rcDxY_mIul-JSGMugAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.336136 2026] [security2:error] [pid 935758:tid 935952] [client 57.141.18.22:49910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMCgABSFg"]
[Mon Jul 20 06:30:19.436705 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:64386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U27cDxY_mIul-JSGMygAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.436802 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:64386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U27cDxY_mIul-JSGMygAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.487175 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U22V3ou772CelrLiVuAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.487320 2026] [security2:error] [pid 929851:tid 930102] [client 77.110.127.138:64366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U22V3ou772CelrLiVuAAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.537104 2026] [security2:error] [pid 935758:tid 935907] [client 77.110.127.138:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpHaZqWM3z'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4U27cDxY_mIul-JSGM0QAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:19.557436 2026] [security2:error] [pid 935758:tid 935912] [client 57.141.18.64:57930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMFgABIFo"]
[Mon Jul 20 06:30:19.681498 2026] [security2:error] [pid 929851:tid 929985] [client 34.73.38.214:53832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4U22V3ou772CelrLiVwAAAAIU"]
[Mon Jul 20 06:30:19.921217 2026] [security2:error] [pid 935758:tid 936004] [client 171.60.139.123:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U27cDxY_mIul-JSGM4QAAAXw"]
[Mon Jul 20 06:30:19.921373 2026] [security2:error] [pid 935758:tid 936004] [client 171.60.139.123:53392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U27cDxY_mIul-JSGM4QAAAXw"]
[Mon Jul 20 06:30:19.928763 2026] [security2:error] [pid 935758:tid 935926] [client 57.141.18.54:53468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U17cDxY_mIul-JSGMKgABLmQ"]
[Mon Jul 20 06:30:20.023521 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64371] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U3LcDxY_mIul-JSGM6gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:20.195742 2026] [security2:error] [pid 935758:tid 935900] [client 104.234.53.50:38245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U3LcDxY_mIul-JSGM8AAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:20.404739 2026] [lsapi:warn] [pid 929851:tid 930065] [client 14.225.17.146:55844] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/old
[Mon Jul 20 06:30:20.404788 2026] [lsapi:warn] [pid 929851:tid 930065] [client 14.225.17.146:55844] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/old
[Mon Jul 20 06:30:20.647253 2026] [security2:error] [pid 935758:tid 935799] [remote 217.61.143.92:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4U3LcDxY_mIul-JSGNDQABZCY"]
[Mon Jul 20 06:30:20.764373 2026] [security2:error] [pid 929851:tid 930032] [client 50.116.65.227:16980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U3GV3ou772CelrLiV6AAAALQ"]
[Mon Jul 20 06:30:20.775422 2026] [security2:error] [pid 935758:tid 936004] [client 50.116.65.227:16984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U3LcDxY_mIul-JSGNEQAAAXw"]
[Mon Jul 20 06:30:20.810084 2026] [security2:error] [pid 935758:tid 935960] [client 103.141.108.143:60369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U3LcDxY_mIul-JSGNEgAAAVA"]
[Mon Jul 20 06:30:20.810249 2026] [security2:error] [pid 935758:tid 935960] [client 103.141.108.143:60369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U3LcDxY_mIul-JSGNEgAAAVA"]
[Mon Jul 20 06:30:20.893416 2026] [security2:error] [pid 935758:tid 935803] [remote 217.61.143.92:32862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4U3LcDxY_mIul-JSGNGQABNCo"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:30:20.922477 2026] [lsapi:warn] [pid 935758:tid 935976] [client 50.116.65.227:17004] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:30:20.922507 2026] [lsapi:warn] [pid 935758:tid 935976] [client 50.116.65.227:17004] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:30:20.937856 2026] [security2:error] [pid 929851:tid 930065] [client 14.225.17.146:55844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4U22V3ou772CelrLiVyAAAANU"], referer: http://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.176043 2026] [security2:error] [pid 935758:tid 935918] [client 57.141.18.100:23950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2LcDxY_mIul-JSGMSwABJj8"]
[Mon Jul 20 06:30:21.230711 2026] [security2:error] [pid 935758:tid 935923] [client 45.116.69.230:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNIwAAASs"]
[Mon Jul 20 06:30:21.231291 2026] [security2:error] [pid 935758:tid 935923] [client 45.116.69.230:62189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNIwAAASs"]
[Mon Jul 20 06:30:21.334606 2026] [security2:error] [pid 935758:tid 935911] [client 50.116.65.227:17026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNIAAAAR8"]
[Mon Jul 20 06:30:21.346402 2026] [security2:error] [pid 935758:tid 935808] [remote 45.90.123.233:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U3bcDxY_mIul-JSGNJwABDS8"]
[Mon Jul 20 06:30:21.382029 2026] [security2:error] [pid 935758:tid 935925] [client 57.141.18.115:38992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2LcDxY_mIul-JSGMVwABLVk"]
[Mon Jul 20 06:30:21.461889 2026] [security2:error] [pid 935758:tid 935909] [client 34.90.235.227:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.uzq.jkk.mybluehost.me"] [uri "/"] [unique_id "al4U3bcDxY_mIul-JSGNMQAAAR0"]
[Mon Jul 20 06:30:21.461978 2026] [security2:error] [pid 935758:tid 935909] [client 34.90.235.227:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcalendars.uzq.jkk.mybluehost.me"] [uri "/"] [unique_id "al4U3bcDxY_mIul-JSGNMQAAAR0"]
[Mon Jul 20 06:30:21.515321 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:64399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3WV3ou772CelrLiWBgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:21.515421 2026] [security2:error] [pid 929851:tid 929991] [client 77.110.127.138:64399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3WV3ou772CelrLiWBgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:21.525934 2026] [security2:error] [pid 935758:tid 935906] [client 50.116.65.227:17034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNKQAAARo"]
[Mon Jul 20 06:30:21.568571 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64346] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/charity/feed/"] [unique_id "al4U3bcDxY_mIul-JSGNNAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:21.632142 2026] [security2:error] [pid 935758:tid 935974] [client 74.7.175.150:46312] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bokverk.com"] [uri "/robots.txt"] [unique_id "al4U3bcDxY_mIul-JSGNOQAAAV4"]
[Mon Jul 20 06:30:21.649391 2026] [security2:error] [pid 935758:tid 935776] [remote 173.249.4.11:13297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNOgABVQ8"]
[Mon Jul 20 06:30:21.649549 2026] [security2:error] [pid 935758:tid 935965] [client 173.249.4.11:13297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNOgABVQ8"]
[Mon Jul 20 06:30:21.773776 2026] [security2:error] [pid 935758:tid 935957] [client 57.141.18.25:34794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2bcDxY_mIul-JSGMaQABTXg"]
[Mon Jul 20 06:30:21.836034 2026] [lsapi:warn] [pid 929851:tid 930106] [client 14.225.17.146:65306] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.836057 2026] [lsapi:warn] [pid 929851:tid 930106] [client 14.225.17.146:65306] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.891042 2026] [security2:error] [pid 929851:tid 930106] [client 14.225.17.146:65306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4U3WV3ou772CelrLiWFQAAAP4"], referer: https://oswegooperatheater.com/old
[Mon Jul 20 06:30:21.920549 2026] [security2:error] [pid 935758:tid 935814] [remote 45.90.123.233:56600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U3bcDxY_mIul-JSGNRAABCjU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:30:21.926983 2026] [security2:error] [pid 935758:tid 935920] [client 39.48.81.23:60229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNRQAAASg"]
[Mon Jul 20 06:30:21.927100 2026] [security2:error] [pid 935758:tid 935920] [client 39.48.81.23:60229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U3bcDxY_mIul-JSGNRQAAASg"]
[Mon Jul 20 06:30:21.978976 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNPAAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.091426 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWIAAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.091547 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWIAAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.119768 2026] [security2:error] [pid 929851:tid 930070] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4U3WV3ou772CelrLiWHQAAANo"]
[Mon Jul 20 06:30:22.142917 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:64374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWJQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.143038 2026] [security2:error] [pid 929851:tid 930069] [client 77.110.127.138:64374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U3mV3ou772CelrLiWJQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.292318 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpOu5CMg3U'%20OR%20672=(SELECT%20672%20FROM%20PG_SLEEP(15))--"] [unique_id "al4U3rcDxY_mIul-JSGNTQAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.380180 2026] [security2:error] [pid 935758:tid 935940] [client 34.74.185.202:49462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4U3rcDxY_mIul-JSGNVAAAATw"]
[Mon Jul 20 06:30:22.483888 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:54036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4U3rcDxY_mIul-JSGNTwAAAWo"], referer: http://bnb-engineering.com/old
[Mon Jul 20 06:30:22.508588 2026] [security2:error] [pid 929851:tid 929988] [client 34.73.38.214:49477] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4U3mV3ou772CelrLiWNQAAAIg"]
[Mon Jul 20 06:30:22.778721 2026] [security2:error] [pid 935758:tid 935794] [remote 188.166.241.141:50002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3rcDxY_mIul-JSGNZgABaCE"]
[Mon Jul 20 06:30:22.778867 2026] [security2:error] [pid 935758:tid 935984] [client 188.166.241.141:50002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U3rcDxY_mIul-JSGNZgABaCE"]
[Mon Jul 20 06:30:22.829565 2026] [security2:error] [pid 929851:tid 929957] [remote 173.212.252.15:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4U3mV3ou772CelrLiWPAAAs2U"]
[Mon Jul 20 06:30:22.878739 2026] [security2:error] [pid 935758:tid 935951] [client 77.110.127.138:64408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U3rcDxY_mIul-JSGNagAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:22.960535 2026] [security2:error] [pid 935758:tid 935786] [remote 8.217.108.67:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4U3rcDxY_mIul-JSGNcgABbBk"]
[Mon Jul 20 06:30:22.963173 2026] [security2:error] [pid 935758:tid 935957] [client 34.74.185.202:56534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4U3rcDxY_mIul-JSGNcwAAAU0"]
[Mon Jul 20 06:30:23.428514 2026] [security2:error] [pid 935758:tid 936003] [client 57.141.18.81:65244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U2rcDxY_mIul-JSGMrQABewk"]
[Mon Jul 20 06:30:23.535679 2026] [security2:error] [pid 929851:tid 929901] [remote 173.212.252.15:35680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4U32V3ou772CelrLiWVgAA7S0"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:30:23.569456 2026] [security2:error] [pid 935758:tid 935966] [client 165.22.226.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.alaraycreative.com"] [uri "/index.php"] [unique_id "al4U37cDxY_mIul-JSGNiQAAAVY"], referer: https://www.alaraycreative.com/
[Mon Jul 20 06:30:23.704856 2026] [security2:error] [pid 929851:tid 930047] [client 34.74.185.202:57097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4U32V3ou772CelrLiWWwAAAMM"]
[Mon Jul 20 06:30:24.087707 2026] [security2:error] [pid 935758:tid 935908] [client 57.141.18.87:46854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U27cDxY_mIul-JSGM0AABHFs"]
[Mon Jul 20 06:30:24.126242 2026] [security2:error] [pid 935758:tid 935763] [remote 8.217.108.67:55600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gescontrols.com"] [uri "/wp-login.php"] [unique_id "al4U4LcDxY_mIul-JSGNowABWQI"], referer: https://gescontrols.com/wp-login.php
[Mon Jul 20 06:30:24.230930 2026] [security2:error] [pid 935758:tid 936002] [client 104.207.58.75:56823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4LcDxY_mIul-JSGNpAAAAXo"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:24.324089 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNpQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.324180 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNpQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.403741 2026] [security2:error] [pid 935758:tid 935987] [client 34.74.185.202:59350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4U4LcDxY_mIul-JSGNrAAAAWs"]
[Mon Jul 20 06:30:24.462712 2026] [security2:error] [pid 929851:tid 930029] [client 57.141.18.50:54054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U22V3ou772CelrLiVzAAAsR4"]
[Mon Jul 20 06:30:24.485259 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNswAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.485349 2026] [security2:error] [pid 935758:tid 935940] [client 77.110.127.138:64420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNswAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.485647 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:64419] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/charity/feed/"] [unique_id "al4U4LcDxY_mIul-JSGNsgAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.691116 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNuAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.691215 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNuAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.841807 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNvQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.841944 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4LcDxY_mIul-JSGNvQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.867076 2026] [security2:error] [pid 935758:tid 935946] [client 65.111.28.172:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4LcDxY_mIul-JSGNvgAAAUI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:24.880479 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U4LcDxY_mIul-JSGNtgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:24.886800 2026] [security2:error] [pid 929851:tid 930078] [client 57.141.18.124:39936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3GV3ou772CelrLiV1gAA4m4"]
[Mon Jul 20 06:30:24.959673 2026] [security2:error] [pid 935758:tid 935910] [client 34.73.38.214:49330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4U4LcDxY_mIul-JSGNxQAAAR4"]
[Mon Jul 20 06:30:24.989464 2026] [security2:error] [pid 935758:tid 935983] [client 34.74.185.202:63777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4U4LcDxY_mIul-JSGNyQAAAWc"]
[Mon Jul 20 06:30:25.011015 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWjQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.011104 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWjQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.085795 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.085901 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.162378 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzgAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.162476 2026] [security2:error] [pid 935758:tid 935899] [client 77.110.127.138:64432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4bcDxY_mIul-JSGNzgAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.179442 2026] [security2:error] [pid 935758:tid 935945] [client 57.141.18.10:20698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3LcDxY_mIul-JSGNBQABQXU"]
[Mon Jul 20 06:30:25.238781 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWlQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.238889 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWlQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.297722 2026] [security2:error] [pid 935758:tid 935848] [remote 47.86.33.52:10648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4U4bcDxY_mIul-JSGN1AABUVc"]
[Mon Jul 20 06:30:25.313077 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWnQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.313198 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U4WV3ou772CelrLiWnQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.391440 2026] [security2:error] [pid 935758:tid 935917] [client 77.110.127.138:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phptJc3bgt3')%20OR%20985=(SELECT%20985%20FROM%20PG_SLEEP(15))--"] [unique_id "al4U4bcDxY_mIul-JSGN2QAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:25.400347 2026] [security2:error] [pid 929851:tid 930055] [client 34.74.185.202:57433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4U4WV3ou772CelrLiWowAAAMs"]
[Mon Jul 20 06:30:25.410857 2026] [security2:error] [pid 935758:tid 936009] [client 50.255.62.89:41480] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4U4bcDxY_mIul-JSGN3AAAAYE"]
[Mon Jul 20 06:30:25.455891 2026] [security2:error] [pid 935758:tid 935932] [client 45.3.45.248:28713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4bcDxY_mIul-JSGN4AAAATQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:25.481798 2026] [security2:error] [pid 929851:tid 930042] [client 50.255.62.89:58734] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4U4WV3ou772CelrLiWqAAAAL4"]
[Mon Jul 20 06:30:25.716438 2026] [security2:error] [pid 935758:tid 935913] [client 14.225.17.146:52654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4U4bcDxY_mIul-JSGN4QAAASE"], referer: http://mobilesurvsolutions.com/old
[Mon Jul 20 06:30:25.946977 2026] [security2:error] [pid 929851:tid 929988] [client 34.74.185.202:52455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4U4WV3ou772CelrLiWtgAAAIg"]
[Mon Jul 20 06:30:26.017579 2026] [security2:error] [pid 929851:tid 930083] [client 77.110.127.138:64439] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U4mV3ou772CelrLiWtwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:26.069185 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWuQAAAOY"]
[Mon Jul 20 06:30:26.069341 2026] [security2:error] [pid 929851:tid 930082] [client 106.219.188.178:47744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWuQAAAOY"]
[Mon Jul 20 06:30:26.070406 2026] [security2:error] [pid 935758:tid 935967] [client 65.111.27.144:37731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4rcDxY_mIul-JSGN9gAAAVc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:26.077761 2026] [security2:error] [pid 929851:tid 930105] [client 197.186.66.42:54770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWugAAAP0"]
[Mon Jul 20 06:30:26.081715 2026] [security2:error] [pid 929851:tid 930105] [client 197.186.66.42:54770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWugAAAP0"]
[Mon Jul 20 06:30:26.082666 2026] [security2:error] [pid 935758:tid 935960] [client 104.234.53.75:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4U4rcDxY_mIul-JSGN9wAAAVA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:26.267462 2026] [security2:error] [pid 935758:tid 935952] [client 57.141.18.87:46870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3bcDxY_mIul-JSGNJgABSCU"]
[Mon Jul 20 06:30:26.278092 2026] [security2:error] [pid 929851:tid 930095] [client 171.61.165.146:12741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWwgAAAPM"]
[Mon Jul 20 06:30:26.279095 2026] [security2:error] [pid 929851:tid 930095] [client 171.61.165.146:12741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U4mV3ou772CelrLiWwgAAAPM"]
[Mon Jul 20 06:30:26.428911 2026] [security2:error] [pid 929851:tid 930028] [client 34.74.185.202:58010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4U4mV3ou772CelrLiWzAAAALA"]
[Mon Jul 20 06:30:26.584687 2026] [security2:error] [pid 929851:tid 930001] [client 14.225.17.146:53663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4U4WV3ou772CelrLiWtAAAAJU"], referer: http://idigress.studio/old
[Mon Jul 20 06:30:26.722354 2026] [security2:error] [pid 929851:tid 930043] [client 65.111.26.110:41987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U4mV3ou772CelrLiW1gAAAL8"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:26.724109 2026] [security2:error] [pid 929851:tid 930049] [client 66.249.74.35:36803] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "certasit.com"] [uri "/robots.txt"] [unique_id "al4U4mV3ou772CelrLiW1wAAAMU"]
[Mon Jul 20 06:30:26.741357 2026] [security2:error] [pid 929851:tid 930046] [client 34.73.38.214:55531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4U4mV3ou772CelrLiW2AAAAMI"]
[Mon Jul 20 06:30:26.834231 2026] [security2:error] [pid 935758:tid 935901] [client 14.225.17.146:52634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4U4bcDxY_mIul-JSGN0wAAARU"], referer: http://vinovinhowine.com/old
[Mon Jul 20 06:30:26.869029 2026] [security2:error] [pid 935758:tid 935897] [client 34.74.185.202:63758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4U4rcDxY_mIul-JSGOFgAAARE"]
[Mon Jul 20 06:30:26.882198 2026] [security2:error] [pid 929851:tid 929996] [client 123.202.189.111:2879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "blog.danwolfe.us"] [uri "/wp-content/uploads/2015/01/xBobbyJindal-Governor-louisiana-indian-american-politician-statement-reaction-300x183.jpg.pagespeed.ic.-30w9dTMBP.jpg"] [unique_id "al4U4mV3ou772CelrLiW4QAAAJA"]
[Mon Jul 20 06:30:27.096366 2026] [security2:error] [pid 929851:tid 929935] [remote 130.185.118.215:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4U42V3ou772CelrLiW6wABAU8"]
[Mon Jul 20 06:30:27.209557 2026] [security2:error] [pid 935758:tid 935946] [client 34.74.185.202:58311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4U47cDxY_mIul-JSGOIwAAAUI"]
[Mon Jul 20 06:30:27.244116 2026] [security2:error] [pid 929851:tid 930032] [client 57.141.18.55:22936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3mV3ou772CelrLiWKgAAtC4"]
[Mon Jul 20 06:30:27.246262 2026] [security2:error] [pid 935758:tid 935949] [client 57.141.18.33:42000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3rcDxY_mIul-JSGNSQABRTY"]
[Mon Jul 20 06:30:27.272385 2026] [security2:error] [pid 935758:tid 935974] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4U47cDxY_mIul-JSGOIQAAAV4"]
[Mon Jul 20 06:30:27.283919 2026] [security2:error] [pid 929851:tid 929922] [remote 130.185.118.215:35478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4U42V3ou772CelrLiW8gAAqEI"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:30:27.583642 2026] [security2:error] [pid 935758:tid 935918] [client 77.110.127.138:64446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/charity/feed/"] [unique_id "al4U47cDxY_mIul-JSGOOwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:27.716322 2026] [security2:error] [pid 935758:tid 936014] [client 14.225.17.146:52598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4U47cDxY_mIul-JSGOKQAAAYY"], referer: http://nextlevelpressurewashing.com/old
[Mon Jul 20 06:30:27.821803 2026] [security2:error] [pid 935758:tid 935905] [client 34.74.185.202:52574] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4U47cDxY_mIul-JSGOQQAAARk"]
[Mon Jul 20 06:30:27.851407 2026] [security2:error] [pid 935758:tid 935941] [client 57.141.18.37:46120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U3rcDxY_mIul-JSGNbwABPTg"]
[Mon Jul 20 06:30:28.063569 2026] [security2:error] [pid 929851:tid 930078] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U42V3ou772CelrLiXCQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.187678 2026] [security2:error] [pid 935758:tid 935928] [client 104.234.53.55:22827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4U5LcDxY_mIul-JSGOTgAAATA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:28.196633 2026] [security2:error] [pid 935758:tid 935883] [remote 47.86.33.52:10648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4U5LcDxY_mIul-JSGOTQABPno"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:30:28.268112 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOUQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.268196 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:64451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOUQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.313197 2026] [security2:error] [pid 929851:tid 930096] [client 34.74.185.202:49429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.makeupyourskin.online"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4U5GV3ou772CelrLiXGgAAAPQ"]
[Mon Jul 20 06:30:28.358524 2026] [security2:error] [pid 935758:tid 935894] [client 34.73.38.214:57595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4U5LcDxY_mIul-JSGOVQAAAQ4"]
[Mon Jul 20 06:30:28.419965 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOWQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.420065 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOWQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.739374 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOYQAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.739491 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:64453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U5LcDxY_mIul-JSGOYQAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:28.759877 2026] [security2:error] [pid 935758:tid 935991] [client 57.141.18.125:28578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U37cDxY_mIul-JSGNkAABbxM"]
[Mon Jul 20 06:30:28.879363 2026] [security2:error] [pid 929851:tid 930053] [client 223.185.13.213:7523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U5GV3ou772CelrLiXMgAAAMk"]
[Mon Jul 20 06:30:28.879515 2026] [security2:error] [pid 929851:tid 930053] [client 223.185.13.213:7523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U5GV3ou772CelrLiXMgAAAMk"]
[Mon Jul 20 06:30:28.970708 2026] [security2:error] [pid 929851:tid 930004] [client 77.110.127.138:64454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phprqqCqFbD'))%20OR%20468=(SELECT%20468%20FROM%20PG_SLEEP(15))--"] [unique_id "al4U5GV3ou772CelrLiXPQAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:29.105975 2026] [security2:error] [pid 935758:tid 935957] [client 104.234.53.61:57747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4U5LcDxY_mIul-JSGOagAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:29.116065 2026] [security2:error] [pid 935758:tid 935999] [client 57.141.18.41:59248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U37cDxY_mIul-JSGNnAABd04"]
[Mon Jul 20 06:30:29.470355 2026] [security2:error] [pid 935758:tid 935936] [client 104.234.53.61:57747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U5bcDxY_mIul-JSGOfgAAATg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:29.559599 2026] [security2:error] [pid 929851:tid 930024] [client 14.225.17.146:52625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXEAAAAKw"], referer: http://eduardsales.com/old
[Mon Jul 20 06:30:29.850291 2026] [security2:error] [pid 935758:tid 935907] [client 34.73.38.214:60872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4U5bcDxY_mIul-JSGOiwAAARs"]
[Mon Jul 20 06:30:30.567692 2026] [security2:error] [pid 935758:tid 935971] [client 57.141.18.108:38268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U4bcDxY_mIul-JSGNywABWyk"]
[Mon Jul 20 06:30:30.732458 2026] [security2:error] [pid 935758:tid 935898] [client 14.225.17.146:65210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4U5rcDxY_mIul-JSGOoQAAARI"]
[Mon Jul 20 06:30:31.028414 2026] [security2:error] [pid 929851:tid 930014] [client 171.60.139.123:53991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXjQAAAKI"]
[Mon Jul 20 06:30:31.028526 2026] [security2:error] [pid 929851:tid 930014] [client 171.60.139.123:53991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXjQAAAKI"]
[Mon Jul 20 06:30:31.119032 2026] [security2:error] [pid 929851:tid 929974] [remote 81.173.115.7:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXkgAAwXY"]
[Mon Jul 20 06:30:31.205570 2026] [security2:error] [pid 929851:tid 930051] [client 14.225.17.146:52613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4U5WV3ou772CelrLiXYAAAAMc"], referer: http://cloudspacesgroup.com/old
[Mon Jul 20 06:30:31.320065 2026] [security2:error] [pid 935758:tid 935963] [client 104.234.53.50:27971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4U57cDxY_mIul-JSGO0AAAAVM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:31.320126 2026] [security2:error] [pid 929851:tid 929982] [remote 81.173.115.7:37624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXnAAAzX4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:31.356607 2026] [security2:error] [pid 929851:tid 930039] [client 50.116.65.227:30108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U52V3ou772CelrLiXnwAAALs"]
[Mon Jul 20 06:30:31.366722 2026] [security2:error] [pid 929851:tid 930007] [client 50.116.65.227:30114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U52V3ou772CelrLiXoAAAAJs"]
[Mon Jul 20 06:30:31.450067 2026] [security2:error] [pid 929851:tid 929890] [remote 72.167.132.114:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXogAAniI"]
[Mon Jul 20 06:30:31.541450 2026] [security2:error] [pid 935758:tid 935928] [client 14.225.17.146:52587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4U57cDxY_mIul-JSGOxgAAATA"], referer: http://uritems.net/old
[Mon Jul 20 06:30:31.577671 2026] [security2:error] [pid 935758:tid 935933] [client 103.141.108.143:60858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U57cDxY_mIul-JSGO3wAAATU"]
[Mon Jul 20 06:30:31.577794 2026] [security2:error] [pid 935758:tid 935933] [client 103.141.108.143:60858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U57cDxY_mIul-JSGO3wAAATU"]
[Mon Jul 20 06:30:31.670424 2026] [security2:error] [pid 929851:tid 929887] [remote 72.167.132.114:48602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4U52V3ou772CelrLiXqgAAkx8"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:30:31.938492 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U57cDxY_mIul-JSGO4QAAAYk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:31.951448 2026] [security2:error] [pid 935758:tid 935935] [client 34.73.38.214:56745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4U57cDxY_mIul-JSGO7wAAATc"]
[Mon Jul 20 06:30:31.957282 2026] [security2:error] [pid 929851:tid 929996] [client 112.208.70.94:44961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvAAAAJA"]
[Mon Jul 20 06:30:31.957377 2026] [security2:error] [pid 929851:tid 929996] [client 112.208.70.94:44961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvAAAAJA"]
[Mon Jul 20 06:30:31.979172 2026] [security2:error] [pid 929851:tid 930085] [client 45.116.69.230:62722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvQAAAOk"]
[Mon Jul 20 06:30:31.979263 2026] [security2:error] [pid 929851:tid 930085] [client 45.116.69.230:62722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U52V3ou772CelrLiXvQAAAOk"]
[Mon Jul 20 06:30:32.147032 2026] [security2:error] [pid 929851:tid 930109] [client 77.110.127.138:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXyAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.147133 2026] [security2:error] [pid 929851:tid 930109] [client 77.110.127.138:64472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXyAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.164630 2026] [security2:error] [pid 935758:tid 935989] [client 39.48.81.23:60714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U6LcDxY_mIul-JSGO-QAAAW0"]
[Mon Jul 20 06:30:32.164828 2026] [security2:error] [pid 935758:tid 935989] [client 39.48.81.23:60714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U6LcDxY_mIul-JSGO-QAAAW0"]
[Mon Jul 20 06:30:32.324058 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXywAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.324184 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:64474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiXywAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.335120 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGO_gAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.335226 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:64473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGO_gAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.497384 2026] [security2:error] [pid 935758:tid 935993] [client 57.141.18.45:26554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U4rcDxY_mIul-JSGODwABcWU"]
[Mon Jul 20 06:30:32.497718 2026] [security2:error] [pid 935758:tid 935972] [client 77.110.127.138:64475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4U6LcDxY_mIul-JSGPCAAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.684646 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX1AAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.684743 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX1AAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.879764 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX3AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.879902 2026] [security2:error] [pid 929851:tid 930099] [client 77.110.127.138:64478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6GV3ou772CelrLiX3AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.947601 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGPIgAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:32.947742 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6LcDxY_mIul-JSGPIgAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.168285 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4U6bcDxY_mIul-JSGPKwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.169261 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6WV3ou772CelrLiX5AAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.169357 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6WV3ou772CelrLiX5AAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.224192 2026] [security2:error] [pid 935758:tid 935983] [client 34.73.38.214:56920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4U6bcDxY_mIul-JSGPMQAAAWc"]
[Mon Jul 20 06:30:33.442718 2026] [security2:error] [pid 935758:tid 935918] [client 77.110.127.138:64485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4U6bcDxY_mIul-JSGPQAAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.462447 2026] [security2:error] [pid 935758:tid 935960] [client 57.141.18.74:34160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U47cDxY_mIul-JSGOJwABUHA"]
[Mon Jul 20 06:30:33.487293 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPQQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.487445 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPQQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.586798 2026] [core:error] [pid 929851:tid 930011] [client 14.225.17.146:51893] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:33.586826 2026] [core:error] [pid 929851:tid 930011] [client 14.225.17.146:51893] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:30:33.649630 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPRgAAATo"]
[Mon Jul 20 06:30:33.649726 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:64490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPRgAAATo"]
[Mon Jul 20 06:30:33.765875 2026] [security2:error] [pid 929851:tid 929991] [client 104.234.53.61:33397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U6WV3ou772CelrLiX_wAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:33.808739 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U6bcDxY_mIul-JSGPRQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:33.920540 2026] [security2:error] [pid 929851:tid 930023] [client 47.128.41.206:45872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "marscafe.com"] [uri "/robots.txt"] [unique_id "al4U6WV3ou772CelrLiYBQAAAKs"]
[Mon Jul 20 06:30:33.923523 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPUwAAAWY"]
[Mon Jul 20 06:30:33.923629 2026] [security2:error] [pid 935758:tid 935982] [client 77.110.127.138:64492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U6bcDxY_mIul-JSGPUwAAAWY"]
[Mon Jul 20 06:30:34.248639 2026] [security2:error] [pid 929851:tid 930037] [client 14.225.17.146:52634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4U6GV3ou772CelrLiXvwAAALk"], referer: http://jvcmotorsports.com/old
[Mon Jul 20 06:30:34.312008 2026] [security2:error] [pid 929851:tid 930022] [client 77.110.127.138:64497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U6mV3ou772CelrLiYCgAAAKo"]
[Mon Jul 20 06:30:34.347254 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.91:57932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXFwAAtSw"]
[Mon Jul 20 06:30:34.443385 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:52239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4U6LcDxY_mIul-JSGPDgAAAVY"], referer: http://fineartsfactory.net/old
[Mon Jul 20 06:30:34.542150 2026] [security2:error] [pid 929851:tid 930091] [client 57.141.18.39:54653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXIgAA7wQ"]
[Mon Jul 20 06:30:34.687236 2026] [security2:error] [pid 929851:tid 930073] [client 34.73.38.214:50685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4U6mV3ou772CelrLiYJQAAAN0"]
[Mon Jul 20 06:30:34.831091 2026] [security2:error] [pid 935758:tid 935895] [client 77.110.127.138:64499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U6rcDxY_mIul-JSGPeAAAAQ8"]
[Mon Jul 20 06:30:34.957446 2026] [security2:error] [pid 929851:tid 930000] [client 57.141.18.120:58620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5GV3ou772CelrLiXPAAAlBc"]
[Mon Jul 20 06:30:35.035374 2026] [security2:error] [pid 935758:tid 936002] [client 57.141.18.22:40346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5bcDxY_mIul-JSGObQABegA"]
[Mon Jul 20 06:30:35.309236 2026] [security2:error] [pid 929851:tid 929996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U62V3ou772CelrLiYNgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:35.444841 2026] [security2:error] [pid 929851:tid 930045] [client 216.73.163.114:46873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "avatrip.co"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4U62V3ou772CelrLiYQgAAAME"]
[Mon Jul 20 06:30:35.683136 2026] [security2:error] [pid 935758:tid 935848] [remote 188.166.241.141:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4U67cDxY_mIul-JSGPngABV1c"]
[Mon Jul 20 06:30:35.751893 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U67cDxY_mIul-JSGPlgAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:35.961261 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U67cDxY_mIul-JSGPqQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:35.961352 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U67cDxY_mIul-JSGPqQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.112285 2026] [security2:error] [pid 935758:tid 935855] [remote 188.166.241.141:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4U7LcDxY_mIul-JSGPsAABXl4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:30:36.122885 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGPsQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.122978 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGPsQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.173864 2026] [security2:error] [pid 935758:tid 935968] [client 136.112.200.207:15908] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "buildwithbluestem.com"] [uri "/wp-json/batch/v1"] [unique_id "al4U7LcDxY_mIul-JSGPtQAAAVg"]
[Mon Jul 20 06:30:36.492415 2026] [security2:error] [pid 929851:tid 930058] [client 57.141.18.76:62966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U5mV3ou772CelrLiXdwAAzm0"]
[Mon Jul 20 06:30:36.512554 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7LcDxY_mIul-JSGPwAAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.531105 2026] [security2:error] [pid 935758:tid 935985] [client 106.219.188.178:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGPygAAAWk"]
[Mon Jul 20 06:30:36.531244 2026] [security2:error] [pid 935758:tid 935985] [client 106.219.188.178:51785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGPygAAAWk"]
[Mon Jul 20 06:30:36.720288 2026] [security2:error] [pid 935758:tid 935943] [client 197.186.66.42:55240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGP0AAAAT8"]
[Mon Jul 20 06:30:36.720554 2026] [security2:error] [pid 935758:tid 935943] [client 197.186.66.42:55240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U7LcDxY_mIul-JSGP0AAAAT8"]
[Mon Jul 20 06:30:36.771226 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:64518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 673 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U7GV3ou772CelrLiYfgAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.942192 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGP2wAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:36.942318 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7LcDxY_mIul-JSGP2wAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:37.019676 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7LcDxY_mIul-JSGP1AAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:37.147016 2026] [security2:error] [pid 935758:tid 935976] [client 34.73.38.214:57020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ial.nce.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4U7bcDxY_mIul-JSGP4gAAAWA"]
[Mon Jul 20 06:30:37.166359 2026] [security2:error] [pid 935758:tid 935955] [client 13.201.64.214:24694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U7bcDxY_mIul-JSGP4wAAAUs"]
[Mon Jul 20 06:30:37.166457 2026] [security2:error] [pid 935758:tid 935955] [client 13.201.64.214:24694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4U7bcDxY_mIul-JSGP4wAAAUs"]
[Mon Jul 20 06:30:37.242312 2026] [security2:error] [pid 929851:tid 929959] [remote 82.223.97.42:47510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4U7WV3ou772CelrLiYjwAAx2c"]
[Mon Jul 20 06:30:37.465889 2026] [security2:error] [pid 935758:tid 935924] [client 57.141.18.30:21276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U57cDxY_mIul-JSGOxwABLGw"]
[Mon Jul 20 06:30:37.474835 2026] [security2:error] [pid 929851:tid 929929] [remote 82.223.97.42:47510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4U7WV3ou772CelrLiYnAAA70k"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:30:37.487226 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7bcDxY_mIul-JSGP6QAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:37.537952 2026] [security2:error] [pid 929851:tid 930023] [client 171.61.165.146:8165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U7WV3ou772CelrLiYoAAAAKs"]
[Mon Jul 20 06:30:37.538069 2026] [security2:error] [pid 929851:tid 930023] [client 171.61.165.146:8165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U7WV3ou772CelrLiYoAAAAKs"]
[Mon Jul 20 06:30:38.070253 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7bcDxY_mIul-JSGQDQAAAVc"]
[Mon Jul 20 06:30:38.372726 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7rcDxY_mIul-JSGQHQAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:38.372905 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U7rcDxY_mIul-JSGQHQAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:38.390767 2026] [security2:error] [pid 929851:tid 929990] [client 163.172.182.64:55928] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4U7mV3ou772CelrLiYxAAAAIo"]
[Mon Jul 20 06:30:38.519565 2026] [security2:error] [pid 935758:tid 935866] [remote 182.77.62.24:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U7rcDxY_mIul-JSGQJAABL2k"]
[Mon Jul 20 06:30:38.519768 2026] [security2:error] [pid 935758:tid 935927] [client 182.77.62.24:59072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U7rcDxY_mIul-JSGQJAABL2k"]
[Mon Jul 20 06:30:38.568618 2026] [security2:error] [pid 929851:tid 930052] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7mV3ou772CelrLiYwwAAAMg"]
[Mon Jul 20 06:30:38.592218 2026] [security2:error] [pid 935758:tid 935983] [client 104.234.53.90:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4U7rcDxY_mIul-JSGQKQAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:38.789114 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U7rcDxY_mIul-JSGQKAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:38.789698 2026] [security2:error] [pid 935758:tid 935969] [client 14.225.17.146:65186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4U7bcDxY_mIul-JSGP5QAAAVk"], referer: http://xp-design.co/old
[Mon Jul 20 06:30:39.003166 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.003254 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.053620 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPwAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.053730 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQPwAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.101053 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.22:40364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U6LcDxY_mIul-JSGPFgABhRg"]
[Mon Jul 20 06:30:39.199953 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQRAAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.200054 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQRAAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.368389 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQTQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.368500 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQTQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.475897 2026] [core:error] [pid 929851:tid 930106] [client 14.225.17.146:64999] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/old
[Mon Jul 20 06:30:39.475925 2026] [core:error] [pid 929851:tid 930106] [client 14.225.17.146:64999] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/old
[Mon Jul 20 06:30:39.562886 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQUwAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.562983 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:64580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQUwAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.565844 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 534 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U77cDxY_mIul-JSGQVAAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.615351 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQVQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.615487 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQVQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.683587 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:64518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.683692 2026] [security2:error] [pid 929851:tid 930005] [client 77.110.127.138:64518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9AAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.719542 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9gAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.719664 2026] [security2:error] [pid 929851:tid 929986] [client 77.110.127.138:64592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY9gAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.798695 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.64:32886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U6bcDxY_mIul-JSGPOwABYwQ"]
[Mon Jul 20 06:30:39.850103 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQbgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.850234 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U77cDxY_mIul-JSGQbgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:39.989903 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY_wAAAOY"]
[Mon Jul 20 06:30:39.990032 2026] [security2:error] [pid 929851:tid 930082] [client 77.110.127.138:64519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U72V3ou772CelrLiY_wAAAOY"]
[Mon Jul 20 06:30:39.999116 2026] [security2:error] [pid 929851:tid 930098] [client 223.185.13.213:28392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U72V3ou772CelrLiZAAAAAPY"]
[Mon Jul 20 06:30:39.999215 2026] [security2:error] [pid 929851:tid 930098] [client 223.185.13.213:28392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U72V3ou772CelrLiZAAAAAPY"]
[Mon Jul 20 06:30:40.142995 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQfwAAAR4"]
[Mon Jul 20 06:30:40.143187 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQfwAAAR4"]
[Mon Jul 20 06:30:40.332999 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQiAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.333116 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQiAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.406928 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQjQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.407084 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQjQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.430706 2026] [security2:error] [pid 935758:tid 935774] [remote 20.153.140.50:35958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4U8LcDxY_mIul-JSGQkQABhQ0"]
[Mon Jul 20 06:30:40.447310 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8GV3ou772CelrLiZEQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.447444 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8GV3ou772CelrLiZEQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.665392 2026] [security2:error] [pid 935758:tid 936004] [client 158.173.89.95:22305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U8LcDxY_mIul-JSGQnQAAAXw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:40.785349 2026] [security2:error] [pid 935758:tid 935944] [client 77.110.127.138:64607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQpAAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.785460 2026] [security2:error] [pid 935758:tid 935944] [client 77.110.127.138:64607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQpAAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.808898 2026] [security2:error] [pid 935758:tid 935967] [client 74.208.214.194:45838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4U8LcDxY_mIul-JSGQpgAAAVc"]
[Mon Jul 20 06:30:40.832427 2026] [security2:error] [pid 929851:tid 930075] [client 57.141.18.22:40378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U6mV3ou772CelrLiYHwAA3zo"]
[Mon Jul 20 06:30:40.844612 2026] [security2:error] [pid 935758:tid 935865] [remote 20.153.140.50:35958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4U8LcDxY_mIul-JSGQqAABZmg"], referer: https://samueldcohen.com/wp-login.php
[Mon Jul 20 06:30:40.968513 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQtwAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:40.968630 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8LcDxY_mIul-JSGQtwAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.014471 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuQAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.014576 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuQAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.022035 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U8LcDxY_mIul-JSGQpQAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.090733 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.090881 2026] [security2:error] [pid 929851:tid 930094] [client 77.110.127.138:64566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.128507 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.128643 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZKgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.147467 2026] [security2:error] [pid 935758:tid 935930] [client 77.110.127.138:64588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.147610 2026] [security2:error] [pid 935758:tid 935930] [client 77.110.127.138:64588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQuwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.219919 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZLgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.220035 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8WV3ou772CelrLiZLgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.252178 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQwAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.252268 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:64618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQwAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.323413 2026] [security2:error] [pid 935758:tid 935987] [client 50.116.65.227:51414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U8bcDxY_mIul-JSGQzgAAAWs"]
[Mon Jul 20 06:30:41.334315 2026] [security2:error] [pid 935758:tid 935999] [client 50.116.65.227:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U8bcDxY_mIul-JSGQ0AAAAXc"]
[Mon Jul 20 06:30:41.336169 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQ0QAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.336269 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U8bcDxY_mIul-JSGQ0QAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.422889 2026] [security2:error] [pid 929851:tid 930009] [client 77.110.127.138:64622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 37 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U8WV3ou772CelrLiZOgAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:41.443915 2026] [security2:error] [pid 935758:tid 935969] [client 74.7.227.179:36170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4U8bcDxY_mIul-JSGQxQABWSY"], referer: https://tejasenvironmental.com/p=961764
[Mon Jul 20 06:30:41.903732 2026] [security2:error] [pid 929851:tid 930104] [client 57.141.18.54:20384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U62V3ou772CelrLiYSAAA_B4"]
[Mon Jul 20 06:30:41.906030 2026] [security2:error] [pid 929851:tid 930062] [client 104.234.53.54:37061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4U8WV3ou772CelrLiZTgAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:41.978523 2026] [security2:error] [pid 935758:tid 935982] [client 171.60.139.123:54544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U8bcDxY_mIul-JSGQ8gAAAWY"]
[Mon Jul 20 06:30:41.978722 2026] [security2:error] [pid 935758:tid 935982] [client 171.60.139.123:54544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U8bcDxY_mIul-JSGQ8gAAAWY"]
[Mon Jul 20 06:30:42.031355 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.46:64790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U67cDxY_mIul-JSGPnQABiHU"]
[Mon Jul 20 06:30:42.084697 2026] [security2:error] [pid 935758:tid 935805] [remote 57.141.18.22:48342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4U8rcDxY_mIul-JSGQ9QABNSw"]
[Mon Jul 20 06:30:42.318421 2026] [security2:error] [pid 935758:tid 935997] [client 14.225.17.146:52113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4U8LcDxY_mIul-JSGQuAAAAXU"], referer: http://wathenbartlett.co.uk/old
[Mon Jul 20 06:30:42.365471 2026] [security2:error] [pid 935758:tid 935922] [client 57.141.18.65:29984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U67cDxY_mIul-JSGPqgABKjs"]
[Mon Jul 20 06:30:42.407292 2026] [security2:error] [pid 935758:tid 935881] [remote 72.167.132.114:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4U8rcDxY_mIul-JSGRDAABCng"]
[Mon Jul 20 06:30:42.518725 2026] [security2:error] [pid 929851:tid 930034] [client 103.141.108.143:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZYwAAALY"]
[Mon Jul 20 06:30:42.519049 2026] [security2:error] [pid 929851:tid 930034] [client 103.141.108.143:61344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZYwAAALY"]
[Mon Jul 20 06:30:42.623394 2026] [security2:error] [pid 935758:tid 935879] [remote 72.167.132.114:53084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4U8rcDxY_mIul-JSGRFwABOXY"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:30:42.852316 2026] [security2:error] [pid 935758:tid 935822] [remote 124.55.178.99:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U8rcDxY_mIul-JSGRGwABNj0"]
[Mon Jul 20 06:30:42.853501 2026] [security2:error] [pid 929851:tid 930090] [client 45.116.69.230:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZbgAAAO4"]
[Mon Jul 20 06:30:42.853669 2026] [security2:error] [pid 929851:tid 930090] [client 45.116.69.230:63342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U8mV3ou772CelrLiZbgAAAO4"]
[Mon Jul 20 06:30:42.944340 2026] [security2:error] [pid 935758:tid 935945] [client 74.208.214.194:45852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4U8rcDxY_mIul-JSGRHgAAAUE"]
[Mon Jul 20 06:30:42.987691 2026] [security2:error] [pid 935758:tid 936010] [client 39.48.81.23:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U8rcDxY_mIul-JSGRIwAAAYI"]
[Mon Jul 20 06:30:42.988342 2026] [security2:error] [pid 935758:tid 936010] [client 39.48.81.23:61199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U8rcDxY_mIul-JSGRIwAAAYI"]
[Mon Jul 20 06:30:43.055172 2026] [security2:error] [pid 929851:tid 929994] [client 57.141.18.125:60372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U7GV3ou772CelrLiYgAAAjn4"]
[Mon Jul 20 06:30:43.076068 2026] [security2:error] [pid 935758:tid 936009] [client 14.225.17.146:61084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4U8rcDxY_mIul-JSGQ-wAAAYE"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/old
[Mon Jul 20 06:30:43.191383 2026] [security2:error] [pid 929851:tid 930053] [client 14.225.17.146:49756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4U82V3ou772CelrLiZfAAAAMk"], referer: https://wathenbartlett.co.uk/old
[Mon Jul 20 06:30:43.217294 2026] [security2:error] [pid 935758:tid 935894] [client 136.112.200.207:18722] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "buildwithbluestem.com"] [uri "/"] [unique_id "al4U87cDxY_mIul-JSGRLgAAAQ4"]
[Mon Jul 20 06:30:43.234548 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:64633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U82V3ou772CelrLiZgQAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:43.234657 2026] [security2:error] [pid 929851:tid 929997] [client 77.110.127.138:64633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U82V3ou772CelrLiZgQAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:43.387244 2026] [security2:error] [pid 935758:tid 935830] [remote 124.55.178.99:41434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U87cDxY_mIul-JSGRMgABhEU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:43.513008 2026] [security2:error] [pid 935758:tid 935993] [client 185.223.152.130:62379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.152.223.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sarahmusica.com"] [uri "/wp-login.php"] [unique_id "al4U87cDxY_mIul-JSGRNgAAAXE"]
[Mon Jul 20 06:30:43.555631 2026] [security2:error] [pid 935758:tid 935899] [client 124.120.192.126:57670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4U87cDxY_mIul-JSGRMwAAARM"]
[Mon Jul 20 06:30:43.760143 2026] [security2:error] [pid 929851:tid 930006] [client 14.225.17.146:60980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4U82V3ou772CelrLiZjwAAAJo"], referer: http://mtlegnews.gov/old
[Mon Jul 20 06:30:44.022467 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.39:64195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U7WV3ou772CelrLiYsgAAny4"]
[Mon Jul 20 06:30:44.378166 2026] [security2:error] [pid 935758:tid 935769] [remote 57.141.18.6:27688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3802589"] [unique_id "al4U9LcDxY_mIul-JSGRbgABIQg"]
[Mon Jul 20 06:30:44.530939 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U9LcDxY_mIul-JSGRawAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:44.743405 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9LcDxY_mIul-JSGRfwAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:44.743496 2026] [security2:error] [pid 935758:tid 935970] [client 77.110.127.138:64643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9LcDxY_mIul-JSGRfwAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:44.897266 2026] [security2:error] [pid 935758:tid 935914] [client 14.225.17.146:61421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4U9LcDxY_mIul-JSGRiAAAASI"], referer: http://nikkidesigns.net/old
[Mon Jul 20 06:30:45.010573 2026] [security2:error] [pid 929851:tid 930062] [client 104.234.53.80:23007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4U9WV3ou772CelrLiZygAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:45.022592 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRmAAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.022715 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRmAAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.024889 2026] [security2:error] [pid 935758:tid 935951] [client 57.141.18.44:38498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U7rcDxY_mIul-JSGQNwABRz4"]
[Mon Jul 20 06:30:45.230098 2026] [security2:error] [pid 935758:tid 935961] [client 57.141.18.89:47820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U77cDxY_mIul-JSGQQAABUXc"]
[Mon Jul 20 06:30:45.285056 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRoAAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.285142 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRoAAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.437039 2026] [security2:error] [pid 929851:tid 930051] [client 77.110.127.138:64652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U9WV3ou772CelrLiZ1AAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.610052 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRuwAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.610195 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9bcDxY_mIul-JSGRuwAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:45.630535 2026] [security2:error] [pid 929851:tid 930095] [client 45.3.44.22:17819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U9WV3ou772CelrLiZ3AAAAPM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:45.736974 2026] [security2:error] [pid 929851:tid 930083] [client 57.141.18.0:28528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U72V3ou772CelrLiY8AAA5ww"]
[Mon Jul 20 06:30:45.738051 2026] [security2:error] [pid 935758:tid 935965] [client 112.208.70.94:45399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U9bcDxY_mIul-JSGRxgAAAVU"]
[Mon Jul 20 06:30:45.738218 2026] [security2:error] [pid 935758:tid 935965] [client 112.208.70.94:45399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4U9bcDxY_mIul-JSGRxgAAAVU"]
[Mon Jul 20 06:30:45.871029 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.17:37700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U77cDxY_mIul-JSGQXgABEko"]
[Mon Jul 20 06:30:46.046900 2026] [security2:error] [pid 935758:tid 935942] [client 14.225.17.146:60878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4U9bcDxY_mIul-JSGRlwAAAT4"], referer: http://entuvy.com/old
[Mon Jul 20 06:30:46.238905 2026] [security2:error] [pid 935758:tid 935950] [client 104.207.58.240:23715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4U9rcDxY_mIul-JSGR2gAAAUY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:30:46.510773 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGR5wAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.510872 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGR5wAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.848873 2026] [security2:error] [pid 935758:tid 936003] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U9rcDxY_mIul-JSGR7wAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.964544 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGSAAAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:46.964656 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U9rcDxY_mIul-JSGSAAAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.056825 2026] [security2:error] [pid 935758:tid 935956] [client 77.110.127.138:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSBAAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.056960 2026] [security2:error] [pid 935758:tid 935956] [client 77.110.127.138:64665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSBAAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.126039 2026] [security2:error] [pid 929851:tid 930003] [client 106.219.188.178:20191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaEAAAAJc"]
[Mon Jul 20 06:30:47.133797 2026] [security2:error] [pid 929851:tid 930003] [client 106.219.188.178:20191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaEAAAAJc"]
[Mon Jul 20 06:30:47.211876 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:64669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSCgAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.212011 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:64669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSCgAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.285544 2026] [security2:error] [pid 935758:tid 935920] [client 13.201.64.214:56076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U97cDxY_mIul-JSGSDgAAASg"]
[Mon Jul 20 06:30:47.465190 2026] [security2:error] [pid 935758:tid 935953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSDQAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.615537 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSGwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.615644 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:64670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSGwAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.633855 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSHwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.633954 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:64641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U97cDxY_mIul-JSGSHwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.660551 2026] [security2:error] [pid 929851:tid 930103] [client 197.186.66.42:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaIgAAAPs"]
[Mon Jul 20 06:30:47.676926 2026] [security2:error] [pid 929851:tid 930017] [client 98.159.234.160:27593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4U92V3ou772CelrLiaJgAAAKU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:47.679734 2026] [security2:error] [pid 929851:tid 930103] [client 197.186.66.42:55718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4U92V3ou772CelrLiaIgAAAPs"]
[Mon Jul 20 06:30:47.796382 2026] [security2:error] [pid 929851:tid 930061] [client 57.141.18.20:49042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8WV3ou772CelrLiZRQAA0UY"]
[Mon Jul 20 06:30:47.869502 2026] [security2:error] [pid 935758:tid 935915] [client 34.74.185.202:50008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4U97cDxY_mIul-JSGSLgAAASM"]
[Mon Jul 20 06:30:47.991905 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U92V3ou772CelrLiaNgAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:47.992055 2026] [security2:error] [pid 929851:tid 930086] [client 77.110.127.138:64673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U92V3ou772CelrLiaNgAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.004974 2026] [security2:error] [pid 935758:tid 935959] [client 57.141.18.118:22578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8rcDxY_mIul-JSGQ8wABT28"]
[Mon Jul 20 06:30:48.106007 2026] [security2:error] [pid 935758:tid 935909] [client 171.61.165.146:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U-LcDxY_mIul-JSGSOgAAAR0"]
[Mon Jul 20 06:30:48.106201 2026] [security2:error] [pid 935758:tid 935909] [client 171.61.165.146:24894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4U-LcDxY_mIul-JSGSOgAAAR0"]
[Mon Jul 20 06:30:48.140515 2026] [security2:error] [pid 935758:tid 935939] [client 57.141.18.8:28696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8rcDxY_mIul-JSGQ-gABOzo"]
[Mon Jul 20 06:30:48.154587 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSPQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.154715 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSPQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.251413 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSQAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.251523 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:64676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-LcDxY_mIul-JSGSQAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.579816 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-LcDxY_mIul-JSGSSgAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:48.580418 2026] [security2:error] [pid 929851:tid 930028] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../.env"] [unique_id "al4U-GV3ou772CelrLiaTgAAALA"], referer: https://www.facebook.com/
[Mon Jul 20 06:30:48.690432 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:64679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4U-LcDxY_mIul-JSGSYAAAAU8"]
[Mon Jul 20 06:30:48.728482 2026] [security2:error] [pid 935758:tid 935909] [client 136.112.200.207:48628] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "buildwithbluestem.com"] [uri "/"] [unique_id "al4U-LcDxY_mIul-JSGSawAAAR0"]
[Mon Jul 20 06:30:48.797069 2026] [security2:error] [pid 935758:tid 935911] [client 65.1.132.125:16554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U-LcDxY_mIul-JSGSbwAAAR8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:30:48.797225 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:61690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSLAAAAVY"], referer: http://walkingandtalking.net/old
[Mon Jul 20 06:30:48.983496 2026] [security2:error] [pid 929851:tid 930051] [client 34.74.185.202:52822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4U-GV3ou772CelrLiaXwAAAMc"]
[Mon Jul 20 06:30:49.003148 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.122:47742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U8mV3ou772CelrLiZawAA_jg"]
[Mon Jul 20 06:30:49.013140 2026] [security2:error] [pid 929851:tid 930017] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../var/www/html/.env"] [unique_id "al4U-WV3ou772CelrLiaYwAAAKU"], referer: https://www.reddit.com/
[Mon Jul 20 06:30:49.067628 2026] [security2:error] [pid 929851:tid 929985] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../var/www/.env"] [unique_id "al4U-WV3ou772CelrLiaZwAAAIU"], referer: https://t.co/nwtvl8i78z
[Mon Jul 20 06:30:49.098552 2026] [security2:error] [pid 929851:tid 930101] [client 103.153.183.69:6588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//....//var/www/html/wp-config.php"] [unique_id "al4U-WV3ou772CelrLiaaAAAAPk"], referer: https://www.google.com/search?q=muy0uo
[Mon Jul 20 06:30:49.245483 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSgQAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.245639 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSgQAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.534401 2026] [security2:error] [pid 929851:tid 930067] [client 34.74.185.202:56717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4U-WV3ou772CelrLiafQAAANc"]
[Mon Jul 20 06:30:49.630399 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSnQAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.630539 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-bcDxY_mIul-JSGSnQAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.671989 2026] [security2:error] [pid 929851:tid 930033] [client 57.141.18.8:28712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U82V3ou772CelrLiZjQAAtQM"]
[Mon Jul 20 06:30:49.683411 2026] [security2:error] [pid 929851:tid 930013] [client 14.225.17.146:63346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4U-WV3ou772CelrLiadAAAAKE"], referer: http://grecruit.online/old
[Mon Jul 20 06:30:49.818264 2026] [security2:error] [pid 935758:tid 935845] [remote 188.166.241.141:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U-bcDxY_mIul-JSGSogABflQ"]
[Mon Jul 20 06:30:49.818543 2026] [security2:error] [pid 935758:tid 936006] [client 188.166.241.141:60256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4U-bcDxY_mIul-JSGSogABflQ"]
[Mon Jul 20 06:30:49.819072 2026] [security2:error] [pid 935758:tid 935931] [client 14.225.17.146:63182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSoAAAATM"], referer: https://walkingandtalking.net/old
[Mon Jul 20 06:30:49.939861 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSnAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:49.970146 2026] [security2:error] [pid 935758:tid 935950] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSnwAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.061239 2026] [security2:error] [pid 929851:tid 929989] [client 57.141.18.85:22090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9GV3ou772CelrLiZowAAiUI"]
[Mon Jul 20 06:30:50.110681 2026] [security2:error] [pid 935758:tid 936017] [client 57.141.18.17:37720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9LcDxY_mIul-JSGRYQABiVs"]
[Mon Jul 20 06:30:50.260683 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-rcDxY_mIul-JSGSwAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.260875 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-rcDxY_mIul-JSGSwAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.311942 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-mV3ou772CelrLiamwAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.312125 2026] [security2:error] [pid 929851:tid 930019] [client 77.110.127.138:64666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-mV3ou772CelrLiamwAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:50.425755 2026] [security2:error] [pid 935758:tid 935988] [client 104.234.53.51:40077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4U-rcDxY_mIul-JSGS1QAAAWw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:50.532162 2026] [security2:error] [pid 935758:tid 935975] [client 50.116.65.227:26776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4U-rcDxY_mIul-JSGS3QAAAV8"]
[Mon Jul 20 06:30:50.544593 2026] [security2:error] [pid 935758:tid 935921] [client 50.116.65.227:26788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4U-rcDxY_mIul-JSGS3gAAASk"]
[Mon Jul 20 06:30:50.671181 2026] [security2:error] [pid 935758:tid 935998] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-rcDxY_mIul-JSGS1gAAAXY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.002485 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTJgAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.002610 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTJgAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.053331 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTKAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.053446 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:64636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U-7cDxY_mIul-JSGTKAAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.240759 2026] [security2:error] [pid 935758:tid 935837] [remote 182.77.62.24:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U-7cDxY_mIul-JSGTLwABJkw"]
[Mon Jul 20 06:30:51.242654 2026] [security2:error] [pid 929851:tid 930020] [client 34.74.185.202:55245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4U-2V3ou772CelrLiawQAAAKg"]
[Mon Jul 20 06:30:51.511252 2026] [security2:error] [pid 935758:tid 935963] [client 14.225.17.146:61824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4U-bcDxY_mIul-JSGSsgAAAVM"], referer: http://slutilities.com/old
[Mon Jul 20 06:30:51.558500 2026] [security2:error] [pid 935758:tid 935962] [client 57.141.18.14:40528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9bcDxY_mIul-JSGRvQABUmA"]
[Mon Jul 20 06:30:51.559550 2026] [security2:error] [pid 929851:tid 930055] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-2V3ou772CelrLiaxAAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.598996 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-7cDxY_mIul-JSGTOQAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:51.680852 2026] [proxy:error] [pid 935758:tid 936017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:51.680945 2026] [proxy_http:error] [pid 935758:tid 936017] [client 34.73.38.214:52441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:51.681642 2026] [proxy:error] [pid 935758:tid 936017] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:51.681687 2026] [proxy_http:error] [pid 935758:tid 936017] [client 34.73.38.214:52441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:51.762253 2026] [security2:error] [pid 935758:tid 935947] [client 57.141.18.82:26194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9bcDxY_mIul-JSGRxwABQzM"]
[Mon Jul 20 06:30:51.784855 2026] [security2:error] [pid 929851:tid 930077] [client 34.74.185.202:59468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4U-2V3ou772CelrLia2QAAAOE"]
[Mon Jul 20 06:30:52.145153 2026] [proxy:error] [pid 935758:tid 936009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:52.145239 2026] [proxy_http:error] [pid 935758:tid 936009] [client 34.73.38.214:64637] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:52.146166 2026] [proxy:error] [pid 935758:tid 936009] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:52.146221 2026] [proxy_http:error] [pid 935758:tid 936009] [client 34.73.38.214:64637] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:52.184806 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U-7cDxY_mIul-JSGTXQAAASw"]
[Mon Jul 20 06:30:52.200428 2026] [security2:error] [pid 935758:tid 935829] [remote 182.77.62.24:46878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4U_LcDxY_mIul-JSGTbQABU0Q"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:30:52.484104 2026] [security2:error] [pid 935758:tid 935969] [client 34.74.185.202:50300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4U_LcDxY_mIul-JSGTgAAAAVk"]
[Mon Jul 20 06:30:52.513224 2026] [security2:error] [pid 935758:tid 935992] [client 104.234.53.66:28285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4U_LcDxY_mIul-JSGTgQAAAXA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:52.556186 2026] [security2:error] [pid 935758:tid 936005] [client 57.141.18.1:44016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U9rcDxY_mIul-JSGR6gABfQ4"]
[Mon Jul 20 06:30:52.569183 2026] [security2:error] [pid 929851:tid 930034] [client 43.205.139.3:18846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U_GV3ou772CelrLia6gAAALY"]
[Mon Jul 20 06:30:52.891781 2026] [security2:error] [pid 935758:tid 935947] [client 171.60.139.123:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U_LcDxY_mIul-JSGTjAAAAUM"]
[Mon Jul 20 06:30:52.891888 2026] [security2:error] [pid 935758:tid 935947] [client 171.60.139.123:55074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4U_LcDxY_mIul-JSGTjAAAAUM"]
[Mon Jul 20 06:30:52.904719 2026] [security2:error] [pid 929851:tid 930033] [client 14.225.17.146:54828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4U-2V3ou772CelrLiazwAAALU"], referer: http://iagdevelopments.com/old
[Mon Jul 20 06:30:52.947602 2026] [security2:error] [pid 929851:tid 929932] [remote 5.252.52.249:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4U_GV3ou772CelrLia_wAAoEw"]
[Mon Jul 20 06:30:53.019864 2026] [security2:error] [pid 935758:tid 935834] [remote 182.77.62.24:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4U_bcDxY_mIul-JSGTkwABF0k"]
[Mon Jul 20 06:30:53.030456 2026] [security2:error] [pid 929851:tid 930002] [client 34.74.185.202:60323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4U_WV3ou772CelrLibBAAAAJY"]
[Mon Jul 20 06:30:53.095775 2026] [security2:error] [pid 929851:tid 930090] [client 103.141.108.143:61838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibBQAAAO4"]
[Mon Jul 20 06:30:53.096902 2026] [security2:error] [pid 929851:tid 930090] [client 103.141.108.143:61838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibBQAAAO4"]
[Mon Jul 20 06:30:53.111896 2026] [security2:error] [pid 929851:tid 929871] [remote 5.252.52.249:49028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibBgAAjw8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:30:53.212176 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTogAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.212282 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:64705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTogAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.263328 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTowAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.263465 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:64655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_bcDxY_mIul-JSGTowAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.289618 2026] [security2:error] [pid 935758:tid 935980] [client 57.141.18.54:44650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSEAABZDY"]
[Mon Jul 20 06:30:53.316220 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.316361 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:64680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEAAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.376368 2026] [security2:error] [pid 935758:tid 936013] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_bcDxY_mIul-JSGTmQAAAYU"]
[Mon Jul 20 06:30:53.416843 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:64706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEwAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.416956 2026] [security2:error] [pid 929851:tid 930080] [client 77.110.127.138:64706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibEwAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.425334 2026] [security2:error] [pid 929851:tid 929963] [remote 192.241.143.148:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibFQAAqms"]
[Mon Jul 20 06:30:53.435828 2026] [security2:error] [pid 929851:tid 930079] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_WV3ou772CelrLibCQAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.524427 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.524563 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:64707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.563404 2026] [security2:error] [pid 935758:tid 935968] [client 57.141.18.82:26230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U97cDxY_mIul-JSGSKQABWEs"]
[Mon Jul 20 06:30:53.568481 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.568563 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHgAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.576233 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:64683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHwAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.576349 2026] [security2:error] [pid 929851:tid 930059] [client 77.110.127.138:64683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibHwAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.600305 2026] [security2:error] [pid 929851:tid 929997] [client 34.74.185.202:61043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4U_WV3ou772CelrLibIwAAAJE"]
[Mon Jul 20 06:30:53.619371 2026] [security2:error] [pid 929851:tid 929863] [remote 192.241.143.148:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibJQAA0Qc"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:30:53.639662 2026] [security2:error] [pid 929851:tid 930077] [client 45.116.69.230:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibJgAAAOE"]
[Mon Jul 20 06:30:53.639790 2026] [security2:error] [pid 929851:tid 930077] [client 45.116.69.230:63893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4U_WV3ou772CelrLibJgAAAOE"]
[Mon Jul 20 06:30:53.734499 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibKgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.734649 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:64711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibKgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.745538 2026] [proxy:error] [pid 935758:tid 935947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:53.745613 2026] [proxy_http:error] [pid 935758:tid 935947] [client 34.73.38.214:52487] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:53.746409 2026] [proxy:error] [pid 935758:tid 935947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:53.746446 2026] [proxy_http:error] [pid 935758:tid 935947] [client 34.73.38.214:52487] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:53.788849 2026] [security2:error] [pid 935758:tid 935875] [remote 182.77.62.24:53386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4U_bcDxY_mIul-JSGTuQABU3I"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:30:53.811354 2026] [security2:error] [pid 929851:tid 930073] [client 65.1.132.125:16562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4U_WV3ou772CelrLibLgAAAN0"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:30:53.883518 2026] [security2:error] [pid 935758:tid 935991] [client 39.48.81.23:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U_bcDxY_mIul-JSGTwgAAAW8"]
[Mon Jul 20 06:30:53.883687 2026] [security2:error] [pid 935758:tid 935991] [client 39.48.81.23:61691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4U_bcDxY_mIul-JSGTwgAAAW8"]
[Mon Jul 20 06:30:53.939687 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_WV3ou772CelrLibIgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:53.941566 2026] [security2:error] [pid 929851:tid 930068] [client 14.225.17.146:62056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4U_WV3ou772CelrLibLwAAANg"], referer: https://iagdevelopments.com/old
[Mon Jul 20 06:30:53.967006 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibNQAAAJ4"]
[Mon Jul 20 06:30:53.967114 2026] [security2:error] [pid 929851:tid 930010] [client 77.110.127.138:64712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_WV3ou772CelrLibNQAAAJ4"]
[Mon Jul 20 06:30:54.018873 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGTygAAAXc"]
[Mon Jul 20 06:30:54.018972 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGTygAAAXc"]
[Mon Jul 20 06:30:54.146381 2026] [security2:error] [pid 929851:tid 930105] [client 57.141.18.14:40530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U-GV3ou772CelrLiaRgAA_Ro"]
[Mon Jul 20 06:30:54.249398 2026] [security2:error] [pid 935758:tid 935974] [client 34.74.185.202:60410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4U_rcDxY_mIul-JSGT1QAAAV4"]
[Mon Jul 20 06:30:54.348815 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:63986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT0QAAAVY"], referer: http://margaretspeckogawa.com/old
[Mon Jul 20 06:30:54.551349 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT2gAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.689862 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT7wAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.689982 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT7wAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.745451 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT9QAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.745571 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:64698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_rcDxY_mIul-JSGT9QAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.752264 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT5wAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:54.783991 2026] [security2:error] [pid 935758:tid 935998] [client 34.74.185.202:55021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4U_rcDxY_mIul-JSGT-AAAAXY"]
[Mon Jul 20 06:30:54.864984 2026] [proxy:error] [pid 935758:tid 935928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:54.865033 2026] [proxy_http:error] [pid 935758:tid 935928] [client 34.73.38.214:60816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:54.865944 2026] [proxy:error] [pid 935758:tid 935928] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:30:54.865972 2026] [proxy_http:error] [pid 935758:tid 935928] [client 34.73.38.214:60816] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:30:54.876100 2026] [security2:error] [pid 935758:tid 935847] [remote 8.217.108.67:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U_rcDxY_mIul-JSGUAwABXFY"]
[Mon Jul 20 06:30:54.993110 2026] [security2:error] [pid 935758:tid 935945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT8wAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.018313 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_2V3ou772CelrLibXwAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.018461 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_2V3ou772CelrLibXwAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.039139 2026] [security2:error] [pid 935758:tid 935880] [remote 182.77.62.24:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4U_7cDxY_mIul-JSGUCgABfXc"]
[Mon Jul 20 06:30:55.116418 2026] [security2:error] [pid 935758:tid 935948] [client 14.225.17.146:64028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4U_LcDxY_mIul-JSGTiQAAAUQ"], referer: http://latiendadejorge.com.gt/old
[Mon Jul 20 06:30:55.262090 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGUCQAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.270453 2026] [security2:error] [pid 935758:tid 935960] [client 34.74.185.202:64900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4U_7cDxY_mIul-JSGUEgAAAVA"]
[Mon Jul 20 06:30:55.701969 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:64721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_7cDxY_mIul-JSGUIgAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.702067 2026] [security2:error] [pid 935758:tid 935906] [client 77.110.127.138:64721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4U_7cDxY_mIul-JSGUIgAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:55.732296 2026] [security2:error] [pid 935758:tid 935843] [remote 182.77.62.24:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4U_7cDxY_mIul-JSGUJgABbVI"], referer: https://giftofgiving-usa.org/wp-login.php
[Mon Jul 20 06:30:55.795858 2026] [security2:error] [pid 935758:tid 935848] [remote 8.217.108.67:8912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4U_7cDxY_mIul-JSGUKgABDlc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:30:55.800797 2026] [security2:error] [pid 935758:tid 936016] [client 103.153.183.69:64094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/%2e%2e%2f%2e%2e%2fetc%2fpasswd"] [unique_id "al4U_7cDxY_mIul-JSGULAAAAYg"], referer: https://www.reddit.com/
[Mon Jul 20 06:30:55.948816 2026] [security2:error] [pid 929851:tid 929970] [remote 72.167.132.114:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4U_2V3ou772CelrLibgwAA13I"]
[Mon Jul 20 06:30:55.964998 2026] [security2:error] [pid 929851:tid 930011] [client 57.141.18.26:61674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U-mV3ou772CelrLiaogAAn3g"]
[Mon Jul 20 06:30:56.013170 2026] [security2:error] [pid 935758:tid 935936] [client 104.234.53.48:41539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VALcDxY_mIul-JSGUOgAAATg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:56.112699 2026] [security2:error] [pid 929851:tid 930020] [client 34.74.185.202:59590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VAGV3ou772CelrLibjgAAAKg"]
[Mon Jul 20 06:30:56.146287 2026] [security2:error] [pid 929851:tid 929856] [remote 72.167.132.114:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VAGV3ou772CelrLibkAAA0AA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:30:56.340327 2026] [security2:error] [pid 929851:tid 930018] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAGV3ou772CelrLibiQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.428969 2026] [security2:error] [pid 929851:tid 930038] [client 57.141.18.32:30096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U-2V3ou772CelrLiauAAAumI"]
[Mon Jul 20 06:30:56.548480 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUSwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.548597 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUSwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.604922 2026] [security2:error] [pid 935758:tid 935952] [client 34.73.38.214:56349] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VALcDxY_mIul-JSGUTgAAAUg"]
[Mon Jul 20 06:30:56.819250 2026] [security2:error] [pid 929851:tid 930004] [client 34.74.185.202:62105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.membresiabeyou.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VAGV3ou772CelrLibswAAAJg"]
[Mon Jul 20 06:30:56.918257 2026] [security2:error] [pid 935758:tid 935995] [client 34.73.38.214:50705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VALcDxY_mIul-JSGUWgAAAXM"]
[Mon Jul 20 06:30:56.942154 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUWwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:56.942247 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VALcDxY_mIul-JSGUWwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.131611 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUZgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.135586 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUZgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.224800 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUbQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.224976 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:64684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUbQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.299444 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUcQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.299554 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:64731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUcQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.382617 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUgAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.382764 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUgAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.492152 2026] [security2:error] [pid 935758:tid 935948] [client 112.208.70.94:45859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUkwAAAUQ"]
[Mon Jul 20 06:30:57.492233 2026] [security2:error] [pid 935758:tid 935948] [client 112.208.70.94:45859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUkwAAAUQ"]
[Mon Jul 20 06:30:57.516573 2026] [security2:error] [pid 935758:tid 935986] [client 57.141.18.65:54110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_LcDxY_mIul-JSGTcAABakI"]
[Mon Jul 20 06:30:57.520185 2026] [security2:error] [pid 935758:tid 935898] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUeAAAARI"]
[Mon Jul 20 06:30:57.533327 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUmgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.533441 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUmgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.684717 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib0QAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.684840 2026] [security2:error] [pid 929851:tid 929993] [client 77.110.127.138:64739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib0QAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.736622 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUiwAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.766074 2026] [security2:error] [pid 935758:tid 935945] [client 106.219.188.178:40968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUqwAAAUE"]
[Mon Jul 20 06:30:57.766397 2026] [security2:error] [pid 935758:tid 935945] [client 106.219.188.178:40968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VAbcDxY_mIul-JSGUqwAAAUE"]
[Mon Jul 20 06:30:57.777801 2026] [security2:error] [pid 929851:tid 930048] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAWV3ou772CelrLibyQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.826658 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUlAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.835452 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib1gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.835589 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:64744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAWV3ou772CelrLib1gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.895263 2026] [security2:error] [pid 935758:tid 935969] [client 103.153.183.69:64094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/etc/passwd"] [unique_id "al4VAbcDxY_mIul-JSGUtQAAAVk"], referer: https://twitter.com/
[Mon Jul 20 06:30:57.909285 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUtwAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.909407 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:64719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUtwAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.947829 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUuAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:57.947989 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAbcDxY_mIul-JSGUuAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.070786 2026] [security2:error] [pid 935758:tid 935950] [client 57.141.18.3:64518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_LcDxY_mIul-JSGTigABRlA"]
[Mon Jul 20 06:30:58.110037 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:64747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUxQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.110150 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:64747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUxQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.142635 2026] [security2:error] [pid 935758:tid 936006] [client 34.73.38.214:59057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VArcDxY_mIul-JSGUxwAAAX4"]
[Mon Jul 20 06:30:58.263242 2026] [security2:error] [pid 935758:tid 935911] [client 77.110.127.138:64748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUzQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.263452 2026] [security2:error] [pid 935758:tid 935911] [client 77.110.127.138:64748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGUzQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.314879 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAmV3ou772CelrLib6AAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.315005 2026] [security2:error] [pid 929851:tid 930056] [client 77.110.127.138:64723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VAmV3ou772CelrLib6AAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.342754 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:64695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUtAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:58.448525 2026] [security2:error] [pid 929851:tid 929987] [client 104.234.53.82:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VAmV3ou772CelrLib7gAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:30:58.521398 2026] [security2:error] [pid 935758:tid 935926] [client 158.101.99.182:53026] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGU1AAAAS4"]
[Mon Jul 20 06:30:58.521509 2026] [security2:error] [pid 935758:tid 935926] [client 158.101.99.182:53026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VArcDxY_mIul-JSGU1AAAAS4"]
[Mon Jul 20 06:30:58.554698 2026] [security2:error] [pid 935758:tid 935891] [client 212.47.238.7:59156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail-box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4VArcDxY_mIul-JSGU4QAAAQs"]
[Mon Jul 20 06:30:58.625974 2026] [security2:error] [pid 929851:tid 930073] [client 197.186.66.42:56194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VAmV3ou772CelrLib9QAAAN0"]
[Mon Jul 20 06:30:58.664405 2026] [security2:error] [pid 929851:tid 930073] [client 197.186.66.42:56194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VAmV3ou772CelrLib9QAAAN0"]
[Mon Jul 20 06:30:58.684346 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.66:35190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_bcDxY_mIul-JSGTtAABY2Y"]
[Mon Jul 20 06:30:58.789256 2026] [security2:error] [pid 935758:tid 936013] [client 14.225.17.146:63340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4VArcDxY_mIul-JSGU5QAAAYU"], referer: http://alrowad-hub.net/old
[Mon Jul 20 06:30:58.915713 2026] [security2:error] [pid 935758:tid 935948] [client 103.153.183.69:64094] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/.env"] [unique_id "al4VArcDxY_mIul-JSGU8gAAAUQ"], referer: https://t.co/hxzrsygf44
[Mon Jul 20 06:30:58.989187 2026] [security2:error] [pid 935758:tid 935933] [client 171.61.165.146:6247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VArcDxY_mIul-JSGU9QAAATU"]
[Mon Jul 20 06:30:58.989301 2026] [security2:error] [pid 935758:tid 935933] [client 171.61.165.146:6247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VArcDxY_mIul-JSGU9QAAATU"]
[Mon Jul 20 06:30:59.021351 2026] [security2:error] [pid 935758:tid 935983] [client 158.101.99.182:53034] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGU9gAAAWc"]
[Mon Jul 20 06:30:59.021453 2026] [security2:error] [pid 935758:tid 935983] [client 158.101.99.182:53034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGU9gAAAWc"]
[Mon Jul 20 06:30:59.154902 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA2V3ou772CelrLicDQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.155018 2026] [security2:error] [pid 929851:tid 930020] [client 77.110.127.138:64751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA2V3ou772CelrLicDQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.306312 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cowl/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4VA2V3ou772CelrLicFwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.364347 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:64750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGU_AAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.463991 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVCQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.464115 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:64757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVCQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.503655 2026] [security2:error] [pid 935758:tid 935958] [client 57.141.18.95:64110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT5gABThI"]
[Mon Jul 20 06:30:59.521032 2026] [security2:error] [pid 935758:tid 935903] [client 158.101.99.182:53040] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVDgAAARc"]
[Mon Jul 20 06:30:59.521116 2026] [security2:error] [pid 935758:tid 935903] [client 158.101.99.182:53040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVDgAAARc"]
[Mon Jul 20 06:30:59.617934 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGAAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.618105 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGAAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.692088 2026] [security2:error] [pid 929851:tid 930038] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA2V3ou772CelrLicGwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.769686 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.769803 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:64763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVGwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.771421 2026] [security2:error] [pid 935758:tid 935891] [client 158.173.166.181:56423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VA7cDxY_mIul-JSGVHQAAAQs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:30:59.811146 2026] [security2:error] [pid 935758:tid 935967] [client 57.141.18.85:45284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_rcDxY_mIul-JSGT_wABV0g"]
[Mon Jul 20 06:30:59.843271 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVJQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.843372 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:64733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VA7cDxY_mIul-JSGVJQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.857193 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGVFgAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:30:59.905335 2026] [security2:error] [pid 935758:tid 935897] [client 77.110.127.138:64734] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cowl/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4VA7cDxY_mIul-JSGVKwAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.023736 2026] [security2:error] [pid 935758:tid 935981] [client 223.185.13.213:24949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VBLcDxY_mIul-JSGVNAAAAWU"]
[Mon Jul 20 06:31:00.023887 2026] [security2:error] [pid 935758:tid 935981] [client 223.185.13.213:24949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VBLcDxY_mIul-JSGVNAAAAWU"]
[Mon Jul 20 06:31:00.092584 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGVKgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.138810 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVPwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.141130 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:64765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVPwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.277505 2026] [security2:error] [pid 935758:tid 935968] [client 57.141.18.22:28090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4U_7cDxY_mIul-JSGUEAABWAM"]
[Mon Jul 20 06:31:00.293352 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVRAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.293433 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:64766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVRAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.322025 2026] [security2:error] [pid 929851:tid 929890] [remote 20.153.140.50:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4VBGV3ou772CelrLicPAAAvSI"]
[Mon Jul 20 06:31:00.399223 2026] [security2:error] [pid 935758:tid 935982] [client 34.73.38.214:61600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VBLcDxY_mIul-JSGVSAAAAWY"]
[Mon Jul 20 06:31:00.447239 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicQgAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.447393 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicQgAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.503112 2026] [security2:error] [pid 935758:tid 936003] [client 185.122.141.230:46572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVQwABewo"]
[Mon Jul 20 06:31:00.612828 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVVQAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.612953 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:64769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVVQAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.666398 2026] [security2:error] [pid 935758:tid 935963] [client 77.110.127.138:64743] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/cowl/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4VBLcDxY_mIul-JSGVXAAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.711562 2026] [security2:error] [pid 929851:tid 929955] [remote 20.153.140.50:45088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4VBGV3ou772CelrLicUgABA2M"], referer: https://crimargroup.com/wp-login.php
[Mon Jul 20 06:31:00.822912 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicWgAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.823023 2026] [security2:error] [pid 929851:tid 930088] [client 77.110.127.138:64770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBGV3ou772CelrLicWgAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.843469 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVVgAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.897669 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVXQAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.988452 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVbgAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:00.988539 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBLcDxY_mIul-JSGVbgAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.256195 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBbcDxY_mIul-JSGVcQAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.453815 2026] [security2:error] [pid 929851:tid 930068] [client 34.73.38.214:56029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VBWV3ou772CelrLiccAAAANg"]
[Mon Jul 20 06:31:01.525929 2026] [security2:error] [pid 929851:tid 930107] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLicYwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.555779 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiceQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.555883 2026] [security2:error] [pid 929851:tid 930028] [client 77.110.127.138:64753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiceQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.562252 2026] [security2:error] [pid 935758:tid 936003] [client 104.234.53.74:25141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VBbcDxY_mIul-JSGViwAAAXs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:01.608732 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLicewAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.608904 2026] [security2:error] [pid 929851:tid 930002] [client 77.110.127.138:64752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLicewAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.870806 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:64778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLiccwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.956664 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiciwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:01.956849 2026] [security2:error] [pid 929851:tid 930050] [client 77.110.127.138:64781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBWV3ou772CelrLiciwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.007843 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVpAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.007953 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVpAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.029701 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBbcDxY_mIul-JSGVmgAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.092115 2026] [security2:error] [pid 935758:tid 935984] [client 176.171.59.233:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4VA7cDxY_mIul-JSGVIQAAAWg"], referer: https://worbals.com
[Mon Jul 20 06:31:02.210324 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:64734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBrcDxY_mIul-JSGVoQAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.456484 2026] [security2:error] [pid 929851:tid 930058] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicoQAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.638802 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBmV3ou772CelrLicvAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.638920 2026] [security2:error] [pid 929851:tid 930013] [client 77.110.127.138:64785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBmV3ou772CelrLicvAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.689408 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVtAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.689523 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VBrcDxY_mIul-JSGVtAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.691903 2026] [security2:error] [pid 929851:tid 930021] [client 77.110.127.138:64784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicrQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.907796 2026] [security2:error] [pid 929851:tid 930033] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicwAAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:02.916617 2026] [core:error] [pid 935758:tid 935992] [client 103.153.183.69:64094] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=6bbhnmb0&v=8z9us), referer: https://t.co/b99irgjw85
[Mon Jul 20 06:31:02.919405 2026] [security2:error] [pid 935758:tid 935937] [client 127.0.0.1:18636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VBrcDxY_mIul-JSGVwQAAATk"], referer: https://t.co/b99irgjw85
[Mon Jul 20 06:31:03.150176 2026] [security2:error] [pid 935758:tid 935979] [client 34.73.38.214:63061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VB7cDxY_mIul-JSGVzgAAAWM"]
[Mon Jul 20 06:31:03.191247 2026] [security2:error] [pid 935758:tid 935972] [client 57.141.18.107:49454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VAbcDxY_mIul-JSGUoQABXCU"]
[Mon Jul 20 06:31:03.193849 2026] [security2:error] [pid 935758:tid 935987] [client 158.101.99.182:53046] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGVzwAAAWs"]
[Mon Jul 20 06:31:03.193950 2026] [security2:error] [pid 935758:tid 935987] [client 158.101.99.182:53046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGVzwAAAWs"]
[Mon Jul 20 06:31:03.255370 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:64679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VBrcDxY_mIul-JSGVxQAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.448712 2026] [security2:error] [pid 935758:tid 935803] [remote 162.19.86.63:44481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4VB7cDxY_mIul-JSGV3wABTyo"]
[Mon Jul 20 06:31:03.473918 2026] [security2:error] [pid 929851:tid 930036] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VB2V3ou772CelrLic0gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.615896 2026] [security2:error] [pid 929851:tid 930103] [client 66.249.65.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amagicbutton.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLickwAAAPs"]
[Mon Jul 20 06:31:03.656867 2026] [security2:error] [pid 935758:tid 935874] [remote 162.19.86.63:44481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4VB7cDxY_mIul-JSGV7QABSHE"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:31:03.691190 2026] [security2:error] [pid 935758:tid 935999] [client 57.141.18.30:34594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VArcDxY_mIul-JSGUyQABdwc"]
[Mon Jul 20 06:31:03.704185 2026] [security2:error] [pid 935758:tid 935985] [client 158.101.99.182:53056] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGV7gAAAWk"]
[Mon Jul 20 06:31:03.704266 2026] [security2:error] [pid 935758:tid 935985] [client 158.101.99.182:53056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGV7gAAAWk"]
[Mon Jul 20 06:31:03.711207 2026] [security2:error] [pid 935758:tid 935994] [client 171.60.139.123:55602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV7wAAAXI"]
[Mon Jul 20 06:31:03.711299 2026] [security2:error] [pid 935758:tid 935994] [client 171.60.139.123:55602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV7wAAAXI"]
[Mon Jul 20 06:31:03.731087 2026] [security2:error] [pid 935758:tid 935916] [client 103.141.108.143:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV8gAAASQ"]
[Mon Jul 20 06:31:03.731198 2026] [security2:error] [pid 935758:tid 935916] [client 103.141.108.143:62394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VB7cDxY_mIul-JSGV8gAAASQ"]
[Mon Jul 20 06:31:03.736807 2026] [security2:error] [pid 935758:tid 935937] [client 34.73.38.214:55321] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VB7cDxY_mIul-JSGV9AAAATk"]
[Mon Jul 20 06:31:03.747438 2026] [security2:error] [pid 935758:tid 936002] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VB7cDxY_mIul-JSGV5wAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.977780 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:64792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGWBQAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:03.977932 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:64792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VB7cDxY_mIul-JSGWBQAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.111900 2026] [security2:error] [pid 935758:tid 936008] [client 57.141.18.110:65174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VArcDxY_mIul-JSGU3wABgGw"]
[Mon Jul 20 06:31:04.132568 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWEAAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.132651 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWEAAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.191708 2026] [security2:error] [pid 935758:tid 935972] [client 104.234.53.88:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VCLcDxY_mIul-JSGWEQAAAVw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:04.282459 2026] [security2:error] [pid 935758:tid 935810] [remote 216.73.163.113:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nzfoodstory.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4VCLcDxY_mIul-JSGWGQABcjE"], referer: http://nzfoodstory.com/wp-includes/css/buttons.css
[Mon Jul 20 06:31:04.293467 2026] [security2:error] [pid 935758:tid 935932] [client 39.48.81.23:62172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWGwAAATQ"]
[Mon Jul 20 06:31:04.293555 2026] [security2:error] [pid 935758:tid 935932] [client 39.48.81.23:62172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWGwAAATQ"]
[Mon Jul 20 06:31:04.302035 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWHAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.302137 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWHAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.383060 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWJQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.383150 2026] [security2:error] [pid 935758:tid 935964] [client 77.110.127.138:64773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWJQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.447635 2026] [security2:error] [pid 935758:tid 936003] [client 45.116.69.230:64426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWJwAAAXs"]
[Mon Jul 20 06:31:04.447761 2026] [security2:error] [pid 935758:tid 936003] [client 45.116.69.230:64426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VCLcDxY_mIul-JSGWJwAAAXs"]
[Mon Jul 20 06:31:04.569424 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWLwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.569509 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWLwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.616059 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWMAAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.616159 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:64780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWMAAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.655215 2026] [security2:error] [pid 935758:tid 936007] [client 194.163.145.123:50932] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4VCLcDxY_mIul-JSGWNgAAAX8"]
[Mon Jul 20 06:31:04.671824 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:64778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9QAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.671967 2026] [security2:error] [pid 929851:tid 930066] [client 77.110.127.138:64778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9QAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.742519 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9wAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.742664 2026] [security2:error] [pid 929851:tid 930046] [client 77.110.127.138:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCGV3ou772CelrLic9wAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:04.743262 2026] [security2:error] [pid 929851:tid 930013] [client 34.73.38.214:60282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VCGV3ou772CelrLic-AAAAKE"]
[Mon Jul 20 06:31:04.814280 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWPQAAASk"]
[Mon Jul 20 06:31:04.814402 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:64715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWPQAAASk"]
[Mon Jul 20 06:31:04.989012 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWSQAAAXI"]
[Mon Jul 20 06:31:04.989125 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:64800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCLcDxY_mIul-JSGWSQAAAXI"]
[Mon Jul 20 06:31:05.127395 2026] [security2:error] [pid 935758:tid 935905] [client 194.163.145.123:50940] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4VCbcDxY_mIul-JSGWVgAAARk"]
[Mon Jul 20 06:31:05.243327 2026] [security2:error] [pid 935758:tid 935980] [client 158.101.99.182:53058] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCbcDxY_mIul-JSGWYAAAAWQ"]
[Mon Jul 20 06:31:05.243437 2026] [security2:error] [pid 935758:tid 935980] [client 158.101.99.182:53058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCbcDxY_mIul-JSGWYAAAAWQ"]
[Mon Jul 20 06:31:05.412432 2026] [security2:error] [pid 929851:tid 930106] [client 57.141.18.79:28912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VA2V3ou772CelrLicKAAA_ko"]
[Mon Jul 20 06:31:05.614997 2026] [security2:error] [pid 929851:tid 930037] [client 194.163.145.123:50946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4VCWV3ou772CelrLidHAAAALk"]
[Mon Jul 20 06:31:05.638842 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64782] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/charity/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4VCbcDxY_mIul-JSGWcAAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:05.650094 2026] [security2:error] [pid 935758:tid 935965] [client 34.73.38.214:54592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VCbcDxY_mIul-JSGWcgAAAVU"]
[Mon Jul 20 06:31:05.738332 2026] [security2:error] [pid 929851:tid 930082] [client 158.101.99.182:53068] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCWV3ou772CelrLidIgAAAOY"]
[Mon Jul 20 06:31:05.738438 2026] [security2:error] [pid 929851:tid 930082] [client 158.101.99.182:53068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCWV3ou772CelrLidIgAAAOY"]
[Mon Jul 20 06:31:05.796084 2026] [security2:error] [pid 935758:tid 935900] [client 14.225.17.146:50830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4VCLcDxY_mIul-JSGWJgAAARQ"], referer: http://alchemygroup.ca/old
[Mon Jul 20 06:31:05.929729 2026] [security2:error] [pid 935758:tid 935935] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWdAAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.140546 2026] [security2:error] [pid 929851:tid 930009] [client 40.77.167.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4VCWV3ou772CelrLidKwAAAJ0"]
[Mon Jul 20 06:31:06.152152 2026] [autoindex:error] [pid 929851:tid 930084] [client 44.201.152.248:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:31:06.283552 2026] [security2:error] [pid 929851:tid 930067] [client 57.141.18.70:25114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBGV3ou772CelrLicRAAA12c"]
[Mon Jul 20 06:31:06.327293 2026] [security2:error] [pid 935758:tid 935860] [remote 57.141.18.72:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4VCrcDxY_mIul-JSGWjAABG2M"]
[Mon Jul 20 06:31:06.444713 2026] [security2:error] [pid 929851:tid 930013] [client 158.101.99.182:53078] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidQQAAAKE"]
[Mon Jul 20 06:31:06.444822 2026] [security2:error] [pid 929851:tid 930013] [client 158.101.99.182:53078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidQQAAAKE"]
[Mon Jul 20 06:31:06.468969 2026] [security2:error] [pid 929851:tid 930073] [client 45.157.112.60:53269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VCmV3ou772CelrLidRAAAAN0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:06.780729 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.56:38650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBLcDxY_mIul-JSGVawABhX8"]
[Mon Jul 20 06:31:06.812191 2026] [security2:error] [pid 935758:tid 935984] [client 34.73.38.214:62635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VCrcDxY_mIul-JSGWqwAAAWg"]
[Mon Jul 20 06:31:06.875161 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWrAAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.875287 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:64807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWrAAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.911642 2026] [security2:error] [pid 935758:tid 935893] [client 14.225.17.146:56559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4VCrcDxY_mIul-JSGWqgAAAQ0"], referer: http://soloceos.com/old
[Mon Jul 20 06:31:06.929738 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidWwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.929892 2026] [security2:error] [pid 929851:tid 930049] [client 77.110.127.138:64784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCmV3ou772CelrLidWwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.981264 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWswAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:06.981432 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:64695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VCrcDxY_mIul-JSGWswAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:07.413200 2026] [security2:error] [pid 935758:tid 935937] [client 103.125.179.95:63645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VC7cDxY_mIul-JSGWxAAAATk"]
[Mon Jul 20 06:31:07.413377 2026] [security2:error] [pid 935758:tid 935937] [client 103.125.179.95:63645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VC7cDxY_mIul-JSGWxAAAATk"]
[Mon Jul 20 06:31:07.444139 2026] [security2:error] [pid 935758:tid 935907] [client 158.173.241.141:51511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGWvgABGws"]
[Mon Jul 20 06:31:07.499830 2026] [security2:error] [pid 929851:tid 930059] [client 57.141.18.76:45168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLicdgAAzwA"]
[Mon Jul 20 06:31:07.503410 2026] [security2:error] [pid 935758:tid 935915] [client 77.110.127.138:64679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VC7cDxY_mIul-JSGWzQAAASM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:07.503549 2026] [security2:error] [pid 935758:tid 935915] [client 77.110.127.138:64679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VC7cDxY_mIul-JSGWzQAAASM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:07.547916 2026] [security2:error] [pid 929851:tid 929992] [client 57.141.18.24:38368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBWV3ou772CelrLicgAAAjBM"]
[Mon Jul 20 06:31:07.581252 2026] [security2:error] [pid 935758:tid 935955] [client 34.73.38.214:65423] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jennylouraya.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VC7cDxY_mIul-JSGW1QAAAUs"]
[Mon Jul 20 06:31:07.587308 2026] [security2:error] [pid 929851:tid 930062] [client 14.225.17.146:56099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VC2V3ou772CelrLidagAAANI"], referer: http://fkconstructionfunding.com/old
[Mon Jul 20 06:31:07.609494 2026] [security2:error] [pid 935758:tid 936008] [client 14.225.17.146:56400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGWxwAAAYA"], referer: http://thesoloceos.com/old
[Mon Jul 20 06:31:07.703920 2026] [security2:error] [pid 929851:tid 930065] [client 74.125.215.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4VCmV3ou772CelrLidMwAAANU"]
[Mon Jul 20 06:31:07.728444 2026] [security2:error] [pid 935758:tid 935982] [client 14.225.17.146:51508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4VCrcDxY_mIul-JSGWiQAAAWY"], referer: http://alexsandbergmusic.com/old
[Mon Jul 20 06:31:07.892341 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:64818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGW2wAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:08.006430 2026] [security2:error] [pid 929851:tid 930096] [client 77.110.127.138:64754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/charity/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4VDGV3ou772CelrLidfwAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:08.024732 2026] [security2:error] [pid 935758:tid 935808] [remote 57.141.18.108:37270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600520"] [unique_id "al4VDLcDxY_mIul-JSGW6gABaS8"]
[Mon Jul 20 06:31:08.124930 2026] [security2:error] [pid 935758:tid 935950] [client 50.116.65.227:51358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4VDLcDxY_mIul-JSGW8wAAAUY"]
[Mon Jul 20 06:31:08.139516 2026] [security2:error] [pid 935758:tid 935951] [client 50.116.65.227:40616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4VDLcDxY_mIul-JSGW9QAAAUc"]
[Mon Jul 20 06:31:08.148186 2026] [security2:error] [pid 935758:tid 935999] [client 158.101.99.182:51892] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGW9gAAAXc"]
[Mon Jul 20 06:31:08.148321 2026] [security2:error] [pid 935758:tid 935999] [client 158.101.99.182:51892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGW9gAAAXc"]
[Mon Jul 20 06:31:08.455851 2026] [security2:error] [pid 929851:tid 930097] [client 103.153.183.69:8542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../app/.env"] [unique_id "al4VDGV3ou772CelrLidkAAAAPU"], referer: https://t.co/hzyflcs9ty
[Mon Jul 20 06:31:08.633125 2026] [security2:error] [pid 929851:tid 930035] [client 103.153.183.69:8542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../srv/.env"] [unique_id "al4VDGV3ou772CelrLidlwAAALc"], referer: https://www.reddit.com/
[Mon Jul 20 06:31:08.649515 2026] [security2:error] [pid 929851:tid 930087] [client 14.225.17.146:56517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4VDGV3ou772CelrLidkgAAAOs"], referer: https://thesoloceos.com/old
[Mon Jul 20 06:31:08.743535 2026] [security2:error] [pid 935758:tid 935973] [client 216.73.216.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4VDLcDxY_mIul-JSGXBwABXUw"]
[Mon Jul 20 06:31:08.754704 2026] [security2:error] [pid 929851:tid 930040] [client 57.141.18.99:23770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VBmV3ou772CelrLicygAAvHc"]
[Mon Jul 20 06:31:08.754781 2026] [security2:error] [pid 935758:tid 935910] [client 216.73.216.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "giftsurprizo.com"] [uri "/index.php"] [unique_id "al4VDLcDxY_mIul-JSGXBQAAAR4"], referer: https://giftsurprizo.com/wp-sitemap.xml
[Mon Jul 20 06:31:08.845930 2026] [security2:error] [pid 935758:tid 935966] [client 158.101.99.182:51906] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 182.99.101.158.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGXEgAAAVY"]
[Mon Jul 20 06:31:08.846019 2026] [security2:error] [pid 935758:tid 935966] [client 158.101.99.182:51906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "skiboutiques.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDLcDxY_mIul-JSGXEgAAAVY"]
[Mon Jul 20 06:31:08.860169 2026] [security2:error] [pid 929851:tid 929999] [client 14.225.17.146:56116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4VDGV3ou772CelrLidmQAAAJM"], referer: http://carolinapressurewashers.com/old
[Mon Jul 20 06:31:09.193201 2026] [security2:error] [pid 929851:tid 929862] [remote 152.228.213.32:60080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VDWV3ou772CelrLidqgAA7AY"]
[Mon Jul 20 06:31:09.220135 2026] [security2:error] [pid 929851:tid 930068] [client 197.186.66.42:56682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLidrAAAANg"]
[Mon Jul 20 06:31:09.224765 2026] [security2:error] [pid 929851:tid 930068] [client 197.186.66.42:56682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLidrAAAANg"]
[Mon Jul 20 06:31:09.260480 2026] [security2:error] [pid 935758:tid 936013] [client 113.186.25.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VDbcDxY_mIul-JSGXIAAAAYU"]
[Mon Jul 20 06:31:09.336922 2026] [security2:error] [pid 935758:tid 935932] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VDbcDxY_mIul-JSGXJAAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:09.513972 2026] [security2:error] [pid 929851:tid 930044] [client 103.153.183.69:8542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/.env"] [unique_id "al4VDWV3ou772CelrLidtwAAAMA"], referer: https://t.co/cs3knd3dtk
[Mon Jul 20 06:31:09.534266 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:42287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLiduAAAAM8"]
[Mon Jul 20 06:31:09.534398 2026] [security2:error] [pid 929851:tid 930059] [client 112.208.70.94:42287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VDWV3ou772CelrLiduAAAAM8"]
[Mon Jul 20 06:31:09.560055 2026] [security2:error] [pid 929851:tid 929921] [remote 152.228.213.32:60080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VDWV3ou772CelrLidugAAikE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:09.564885 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDbcDxY_mIul-JSGXPgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:09.564964 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:64823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDbcDxY_mIul-JSGXPgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:09.990145 2026] [security2:error] [pid 929851:tid 929953] [remote 192.241.143.148:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VDWV3ou772CelrLidywAA9mE"]
[Mon Jul 20 06:31:10.050273 2026] [security2:error] [pid 929851:tid 930051] [client 171.61.165.146:6584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VDmV3ou772CelrLidzAAAAMc"]
[Mon Jul 20 06:31:10.050390 2026] [security2:error] [pid 929851:tid 930051] [client 171.61.165.146:6584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VDmV3ou772CelrLidzAAAAMc"]
[Mon Jul 20 06:31:10.163473 2026] [security2:error] [pid 929851:tid 929915] [remote 192.241.143.148:39588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VDmV3ou772CelrLidzgAA5Ds"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:31:10.225713 2026] [fcgid:warn] [pid 929851:tid 930023] (70014)End of file found: [client 167.94.146.52:35242] mod_fcgid: can't get data from http client
[Mon Jul 20 06:31:10.384396 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXYAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.384529 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:64826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXYAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.502909 2026] [security2:error] [pid 935758:tid 935925] [client 57.141.18.62:31784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCLcDxY_mIul-JSGWNwABLXc"]
[Mon Jul 20 06:31:10.531929 2026] [proxy:error] [pid 929851:tid 930039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:10.531986 2026] [proxy_http:error] [pid 929851:tid 930039] [client 34.73.38.214:56123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:10.532434 2026] [proxy:error] [pid 929851:tid 930039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:10.532457 2026] [proxy_http:error] [pid 929851:tid 930039] [client 34.73.38.214:56123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:10.543089 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:64827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXbwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.543163 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:64827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXbwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.752711 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXdgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.752846 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:64829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VDrcDxY_mIul-JSGXdgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:10.887977 2026] [security2:error] [pid 929851:tid 930012] [client 50.116.65.227:48052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VDmV3ou772CelrLid7AAAAKA"]
[Mon Jul 20 06:31:10.898331 2026] [security2:error] [pid 929851:tid 930105] [client 50.116.65.227:48068] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VDmV3ou772CelrLid7QAAAP0"]
[Mon Jul 20 06:31:11.014966 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXfAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.015108 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:64830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXfAAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.078603 2026] [security2:error] [pid 935758:tid 935944] [client 57.141.18.22:61110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWWwABQHk"]
[Mon Jul 20 06:31:11.155443 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:64831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXigAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.155536 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:64831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXigAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.309551 2026] [security2:error] [pid 935758:tid 936004] [client 77.110.127.138:64832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/charity/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4VD7cDxY_mIul-JSGXjQAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.309833 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.309909 2026] [security2:error] [pid 929851:tid 930003] [client 77.110.127.138:64833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9gAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.344958 2026] [security2:error] [pid 929851:tid 930016] [client 77.110.127.138:64834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9wAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.345059 2026] [security2:error] [pid 929851:tid 930016] [client 77.110.127.138:64834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid9wAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.355084 2026] [security2:error] [pid 935758:tid 935930] [client 57.141.18.3:39612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWZQABMlI"]
[Mon Jul 20 06:31:11.500880 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid_AAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.501034 2026] [security2:error] [pid 929851:tid 929994] [client 77.110.127.138:64836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLid_AAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.646985 2026] [security2:error] [pid 935758:tid 935914] [client 57.141.18.71:41572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VCbcDxY_mIul-JSGWbQABIlc"]
[Mon Jul 20 06:31:11.655772 2026] [security2:error] [pid 935758:tid 935929] [client 77.110.127.138:64837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXpAAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.655897 2026] [security2:error] [pid 935758:tid 935929] [client 77.110.127.138:64837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXpAAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.694271 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:64835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VD7cDxY_mIul-JSGXlQAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.802721 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXqQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.802846 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:64838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD7cDxY_mIul-JSGXqQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:11.823635 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLieBQAAAPY"]
[Mon Jul 20 06:31:11.823784 2026] [security2:error] [pid 929851:tid 930098] [client 77.110.127.138:64839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VD2V3ou772CelrLieBQAAAPY"]
[Mon Jul 20 06:31:12.008153 2026] [security2:error] [pid 935758:tid 936008] [client 223.185.13.213:16035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VELcDxY_mIul-JSGXsQAAAYA"]
[Mon Jul 20 06:31:12.008271 2026] [security2:error] [pid 935758:tid 936008] [client 223.185.13.213:16035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VELcDxY_mIul-JSGXsQAAAYA"]
[Mon Jul 20 06:31:12.131267 2026] [security2:error] [pid 935758:tid 935941] [client 104.234.53.74:22843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VELcDxY_mIul-JSGXuQAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:12.173711 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXvgAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.173881 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXvgAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.216145 2026] [security2:error] [pid 929851:tid 929978] [remote 173.249.4.11:29882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4VEGV3ou772CelrLieDgAA5Ho"]
[Mon Jul 20 06:31:12.244725 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXxgAAAT4"]
[Mon Jul 20 06:31:12.244829 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:64843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VELcDxY_mIul-JSGXxgAAAT4"]
[Mon Jul 20 06:31:12.398661 2026] [security2:error] [pid 929851:tid 930054] [client 77.110.127.138:64844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieEQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.398837 2026] [security2:error] [pid 929851:tid 930054] [client 77.110.127.138:64844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieEQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.440407 2026] [proxy:error] [pid 929851:tid 930040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:12.440491 2026] [proxy_http:error] [pid 929851:tid 930040] [client 34.73.38.214:56260] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:12.441236 2026] [proxy:error] [pid 929851:tid 930040] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:12.441281 2026] [proxy_http:error] [pid 929851:tid 930040] [client 34.73.38.214:56260] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:12.612253 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieHAAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.612367 2026] [security2:error] [pid 929851:tid 930060] [client 77.110.127.138:64846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEGV3ou772CelrLieHAAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.793407 2026] [security2:error] [pid 929851:tid 930037] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VEGV3ou772CelrLieGQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:12.825508 2026] [security2:error] [pid 935758:tid 935932] [client 14.225.17.146:51612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4VDrcDxY_mIul-JSGXZAAAATQ"], referer: http://onewingpictures.com/old
[Mon Jul 20 06:31:13.006670 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEWV3ou772CelrLieKAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.006786 2026] [security2:error] [pid 929851:tid 930007] [client 77.110.127.138:64847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEWV3ou772CelrLieKAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.064240 2026] [security2:error] [pid 929851:tid 929885] [remote 173.249.4.11:29882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4VEWV3ou772CelrLieLQAArR0"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 06:31:13.293931 2026] [security2:error] [pid 935758:tid 935946] [client 54.224.22.173:64186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.224.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VEbcDxY_mIul-JSGYCgAAAUI"]
[Mon Jul 20 06:31:13.515371 2026] [security2:error] [pid 935758:tid 935907] [client 34.74.185.202:50683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VEbcDxY_mIul-JSGYFgAAARs"]
[Mon Jul 20 06:31:13.560249 2026] [security2:error] [pid 935758:tid 935911] [client 57.141.18.125:64890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VC7cDxY_mIul-JSGW2gABH1E"]
[Mon Jul 20 06:31:13.774593 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEbcDxY_mIul-JSGYLgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.774698 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:64852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VEbcDxY_mIul-JSGYLgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:13.805352 2026] [security2:error] [pid 935758:tid 935905] [client 34.207.130.29:32426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VEbcDxY_mIul-JSGYMAAAARk"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:31:13.842643 2026] [security2:error] [pid 935758:tid 935992] [client 34.74.185.202:54320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VEbcDxY_mIul-JSGYMwAAAXA"]
[Mon Jul 20 06:31:13.979058 2026] [security2:error] [pid 935758:tid 935772] [remote 122.154.60.154:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.60.154.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "beauacoustics.com"] [uri "/xmlrpc.php"] [unique_id "al4VEbcDxY_mIul-JSGYOgABbws"]
[Mon Jul 20 06:31:13.979239 2026] [security2:error] [pid 935758:tid 935991] [client 122.154.60.154:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "beauacoustics.com"] [uri "/xmlrpc.php"] [unique_id "al4VEbcDxY_mIul-JSGYOgABbws"]
[Mon Jul 20 06:31:14.152920 2026] [security2:error] [pid 929851:tid 930013] [client 57.141.18.116:57572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDGV3ou772CelrLidhQAAoVo"]
[Mon Jul 20 06:31:14.184706 2026] [security2:error] [pid 929851:tid 930035] [client 34.74.185.202:57958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VEmV3ou772CelrLieTAAAALc"]
[Mon Jul 20 06:31:14.401283 2026] [security2:error] [pid 935758:tid 935995] [client 57.141.18.78:37914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDLcDxY_mIul-JSGXAwABcxE"]
[Mon Jul 20 06:31:14.427073 2026] [security2:error] [pid 935758:tid 935993] [client 171.60.139.123:56133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYUwAAAXE"]
[Mon Jul 20 06:31:14.427234 2026] [security2:error] [pid 935758:tid 935993] [client 171.60.139.123:56133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYUwAAAXE"]
[Mon Jul 20 06:31:14.460020 2026] [core:error] [pid 929851:tid 930030] [client 14.225.17.146:62208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/old
[Mon Jul 20 06:31:14.460056 2026] [core:error] [pid 929851:tid 930030] [client 14.225.17.146:62208] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/old
[Mon Jul 20 06:31:14.477667 2026] [security2:error] [pid 929851:tid 930068] [client 34.74.185.202:53432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VEmV3ou772CelrLieUwAAANg"]
[Mon Jul 20 06:31:14.483408 2026] [proxy:error] [pid 929851:tid 929987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:14.483486 2026] [proxy_http:error] [pid 929851:tid 929987] [client 34.73.38.214:60053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:14.484361 2026] [proxy:error] [pid 929851:tid 929987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:14.484412 2026] [proxy_http:error] [pid 929851:tid 929987] [client 34.73.38.214:60053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:14.502190 2026] [security2:error] [pid 929851:tid 930082] [client 103.141.108.143:62877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieVQAAAOY"]
[Mon Jul 20 06:31:14.502623 2026] [security2:error] [pid 929851:tid 930082] [client 103.141.108.143:62877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieVQAAAOY"]
[Mon Jul 20 06:31:14.519439 2026] [security2:error] [pid 935758:tid 935912] [client 14.225.17.146:50627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4VEbcDxY_mIul-JSGYDwAAASA"], referer: http://mazzucelli.com/old
[Mon Jul 20 06:31:14.841890 2026] [security2:error] [pid 935758:tid 935982] [client 34.74.185.202:62786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VErcDxY_mIul-JSGYdgAAAWY"]
[Mon Jul 20 06:31:14.856207 2026] [security2:error] [pid 929851:tid 930088] [client 39.48.81.23:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieWAAAAOw"]
[Mon Jul 20 06:31:14.856372 2026] [security2:error] [pid 929851:tid 930088] [client 39.48.81.23:62662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VEmV3ou772CelrLieWAAAAOw"]
[Mon Jul 20 06:31:14.993091 2026] [security2:error] [pid 935758:tid 935905] [client 45.116.69.230:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYgwAAARk"]
[Mon Jul 20 06:31:14.993230 2026] [security2:error] [pid 935758:tid 935905] [client 45.116.69.230:64968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VErcDxY_mIul-JSGYgwAAARk"]
[Mon Jul 20 06:31:15.053823 2026] [security2:error] [pid 935758:tid 935954] [client 14.225.17.146:62704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4VEbcDxY_mIul-JSGX-QAAAUo"], referer: http://itdynamix.com/old
[Mon Jul 20 06:31:15.071441 2026] [security2:error] [pid 935758:tid 935893] [client 34.74.185.202:55508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGYigAAAQ0"]
[Mon Jul 20 06:31:15.084683 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGYjQAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.084806 2026] [security2:error] [pid 935758:tid 935913] [client 77.110.127.138:64859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGYjQAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.351771 2026] [security2:error] [pid 935758:tid 935942] [client 34.74.185.202:51388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGYowAAAT4"]
[Mon Jul 20 06:31:15.488551 2026] [security2:error] [pid 935758:tid 935995] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtQAAAXM"]
[Mon Jul 20 06:31:15.488551 2026] [security2:error] [pid 935758:tid 935896] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtAAAARA"]
[Mon Jul 20 06:31:15.490078 2026] [security2:error] [pid 935758:tid 935983] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYuAAAAWc"]
[Mon Jul 20 06:31:15.490977 2026] [security2:error] [pid 935758:tid 935917] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtgAAASU"]
[Mon Jul 20 06:31:15.491071 2026] [security2:error] [pid 935758:tid 935993] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYuQAAAXE"]
[Mon Jul 20 06:31:15.512588 2026] [security2:error] [pid 935758:tid 935905] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYtwAAARk"]
[Mon Jul 20 06:31:15.570019 2026] [security2:error] [pid 935758:tid 936017] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYxwABiXk"]
[Mon Jul 20 06:31:15.581231 2026] [security2:error] [pid 935758:tid 935890] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYzAAAAQo"]
[Mon Jul 20 06:31:15.584956 2026] [security2:error] [pid 935758:tid 935985] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYywAAAWk"]
[Mon Jul 20 06:31:15.604694 2026] [security2:error] [pid 935758:tid 935987] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYzwAAAWs"]
[Mon Jul 20 06:31:15.618911 2026] [security2:error] [pid 935758:tid 935986] [client 34.74.185.202:64068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGY2QAAAWo"]
[Mon Jul 20 06:31:15.623778 2026] [security2:error] [pid 935758:tid 935913] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYzgAAASE"]
[Mon Jul 20 06:31:15.665998 2026] [security2:error] [pid 929851:tid 929943] [remote 57.141.18.13:55710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDWV3ou772CelrLidxQAAlFc"]
[Mon Jul 20 06:31:15.785421 2026] [security2:error] [pid 935758:tid 935766] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env"] [unique_id "al4VE7cDxY_mIul-JSGY7AABdwU"]
[Mon Jul 20 06:31:15.788158 2026] [proxy:error] [pid 935758:tid 935969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:15.788200 2026] [proxy_http:error] [pid 935758:tid 935969] [client 34.73.38.214:49334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:15.788627 2026] [proxy:error] [pid 935758:tid 935969] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:15.788653 2026] [proxy_http:error] [pid 935758:tid 935969] [client 34.73.38.214:49334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:15.875019 2026] [security2:error] [pid 935758:tid 936009] [client 34.74.185.202:56479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VE7cDxY_mIul-JSGZBAAAAYE"]
[Mon Jul 20 06:31:15.896565 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGZCwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.896646 2026] [security2:error] [pid 935758:tid 935912] [client 77.110.127.138:64862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VE7cDxY_mIul-JSGZCwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:15.954835 2026] [security2:error] [pid 935758:tid 935763] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env.backup"] [unique_id "al4VE7cDxY_mIul-JSGZEAABXgI"]
[Mon Jul 20 06:31:15.956401 2026] [security2:error] [pid 935758:tid 935890] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZCgAAAQo"]
[Mon Jul 20 06:31:15.975640 2026] [security2:error] [pid 935758:tid 935939] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZBwAAATs"]
[Mon Jul 20 06:31:15.992504 2026] [security2:error] [pid 935758:tid 935786] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/.env.old"] [unique_id "al4VE7cDxY_mIul-JSGZFgABXhk"]
[Mon Jul 20 06:31:16.000636 2026] [security2:error] [pid 935758:tid 935770] [remote 84.247.172.23:59706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VE7cDxY_mIul-JSGZFQABGwk"]
[Mon Jul 20 06:31:16.000834 2026] [security2:error] [pid 935758:tid 935907] [client 84.247.172.23:59706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VE7cDxY_mIul-JSGZFQABGwk"]
[Mon Jul 20 06:31:16.010149 2026] [security2:error] [pid 935758:tid 935826] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tadlarsen.com"] [uri "/graphql"] [unique_id "al4VFLcDxY_mIul-JSGZHAABXkE"]
[Mon Jul 20 06:31:16.011105 2026] [security2:error] [pid 935758:tid 935828] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env.bak"] [unique_id "al4VFLcDxY_mIul-JSGZGwABXkM"]
[Mon Jul 20 06:31:16.029709 2026] [security2:error] [pid 935758:tid 935860] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/api/.env"] [unique_id "al4VFLcDxY_mIul-JSGZHgABXmM"]
[Mon Jul 20 06:31:16.029858 2026] [security2:error] [pid 935758:tid 935974] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/api/.env"] [unique_id "al4VFLcDxY_mIul-JSGZHgABXmM"]
[Mon Jul 20 06:31:16.055821 2026] [security2:error] [pid 935758:tid 935952] [client 14.225.17.146:62859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZCAAAAUg"], referer: https://itdynamix.com/old
[Mon Jul 20 06:31:16.069342 2026] [security2:error] [pid 935758:tid 935807] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/admin/.env"] [unique_id "al4VFLcDxY_mIul-JSGZJgABXi4"]
[Mon Jul 20 06:31:16.069486 2026] [security2:error] [pid 935758:tid 935974] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/admin/.env"] [unique_id "al4VFLcDxY_mIul-JSGZJgABXi4"]
[Mon Jul 20 06:31:16.090303 2026] [security2:error] [pid 935758:tid 935913] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGZFwAAASE"]
[Mon Jul 20 06:31:16.094379 2026] [security2:error] [pid 935758:tid 935761] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/backend/.env"] [unique_id "al4VFLcDxY_mIul-JSGZLgABRgA"]
[Mon Jul 20 06:31:16.158654 2026] [security2:error] [pid 935758:tid 935918] [client 34.74.185.202:50867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VFLcDxY_mIul-JSGZMgAAASY"]
[Mon Jul 20 06:31:16.194594 2026] [autoindex:error] [pid 935758:tid 935993] [client 14.225.17.146:62843] AH01276: Cannot serve directory /home2/blaizeac/public_html/old/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://blaizeaccountingservices.com/old
[Mon Jul 20 06:31:16.195986 2026] [security2:error] [pid 935758:tid 935888] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/config/.env"] [unique_id "al4VFLcDxY_mIul-JSGZNQABS38"]
[Mon Jul 20 06:31:16.196699 2026] [security2:error] [pid 929851:tid 929910] [remote 57.141.18.102:25450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDmV3ou772CelrLid1AAAlTY"]
[Mon Jul 20 06:31:16.278069 2026] [security2:error] [pid 935758:tid 935920] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZKAAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.284594 2026] [security2:error] [pid 935758:tid 935804] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tadlarsen.com"] [uri "/api/graphql"] [unique_id "al4VFLcDxY_mIul-JSGZQQABVCs"]
[Mon Jul 20 06:31:16.389997 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZSwABOHs"]
[Mon Jul 20 06:31:16.390806 2026] [security2:error] [pid 935758:tid 935792] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.s3cfg"] [unique_id "al4VFLcDxY_mIul-JSGZYwABOB8"]
[Mon Jul 20 06:31:16.390974 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.s3cfg"] [unique_id "al4VFLcDxY_mIul-JSGZYwABOB8"]
[Mon Jul 20 06:31:16.392398 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZSgABOCg"]
[Mon Jul 20 06:31:16.396681 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZRAABOF4"]
[Mon Jul 20 06:31:16.411341 2026] [security2:error] [pid 935758:tid 935998] [client 34.74.185.202:59823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VFLcDxY_mIul-JSGZawAAAXY"]
[Mon Jul 20 06:31:16.413157 2026] [security2:error] [pid 935758:tid 935930] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZTgAAATI"]
[Mon Jul 20 06:31:16.421362 2026] [authz_core:error] [pid 935758:tid 935897] [client 34.129.173.120:0] AH01630: client denied by server configuration: /home1/tadlarse/public_html/.htpasswd
[Mon Jul 20 06:31:16.431123 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZUgAAAXA"]
[Mon Jul 20 06:31:16.440234 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVAABOGQ"]
[Mon Jul 20 06:31:16.448616 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVwABOAw"]
[Mon Jul 20 06:31:16.449155 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVgABOBE"]
[Mon Jul 20 06:31:16.450215 2026] [security2:error] [pid 935758:tid 935936] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZVQABOGY"]
[Mon Jul 20 06:31:16.458069 2026] [security2:error] [pid 935758:tid 935851] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "tadlarsen.com"] [uri "/v1/graphql"] [unique_id "al4VFLcDxY_mIul-JSGZdAABOFo"]
[Mon Jul 20 06:31:16.490512 2026] [security2:error] [pid 935758:tid 935967] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZbwAAAVc"]
[Mon Jul 20 06:31:16.503830 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZdQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.503946 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:64864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZdQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.518768 2026] [security2:error] [pid 935758:tid 935960] [client 57.141.18.41:51110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VDrcDxY_mIul-JSGXcQABUA4"]
[Mon Jul 20 06:31:16.607991 2026] [security2:error] [pid 935758:tid 935764] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.ssh/id_rsa"] [unique_id "al4VFLcDxY_mIul-JSGZggABcgM"]
[Mon Jul 20 06:31:16.624268 2026] [security2:error] [pid 935758:tid 935942] [client 14.225.17.146:62122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZWwAAAT4"], referer: http://talknutritionwithlesley.com/old
[Mon Jul 20 06:31:16.632070 2026] [security2:error] [pid 935758:tid 935857] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.ssh/id_dsa"] [unique_id "al4VFLcDxY_mIul-JSGZjAABcmA"]
[Mon Jul 20 06:31:16.680205 2026] [security2:error] [pid 935758:tid 935994] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZfAABchg"]
[Mon Jul 20 06:31:16.685456 2026] [security2:error] [pid 935758:tid 935961] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZiAAAAVE"]
[Mon Jul 20 06:31:16.686568 2026] [security2:error] [pid 935758:tid 935962] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZiQAAAVI"]
[Mon Jul 20 06:31:16.696779 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZoQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.696878 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZoQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.705639 2026] [security2:error] [pid 935758:tid 936013] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZiwAAAYU"]
[Mon Jul 20 06:31:16.709176 2026] [security2:error] [pid 935758:tid 935952] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZjQAAAUg"]
[Mon Jul 20 06:31:16.734897 2026] [security2:error] [pid 935758:tid 935880] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/id_rsa"] [unique_id "al4VFLcDxY_mIul-JSGZpwABcnc"]
[Mon Jul 20 06:31:16.746553 2026] [security2:error] [pid 935758:tid 935900] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZnwAAARQ"]
[Mon Jul 20 06:31:16.748191 2026] [security2:error] [pid 935758:tid 935897] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZoAAAARE"]
[Mon Jul 20 06:31:16.749126 2026] [security2:error] [pid 935758:tid 935958] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZngAAAU4"]
[Mon Jul 20 06:31:16.766756 2026] [security2:error] [pid 935758:tid 935932] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZowAAATQ"]
[Mon Jul 20 06:31:16.862187 2026] [security2:error] [pid 929851:tid 929906] [remote 57.141.18.117:33008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VD2V3ou772CelrLid9QAAmDI"]
[Mon Jul 20 06:31:16.862913 2026] [security2:error] [pid 935758:tid 935831] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/id_dsa"] [unique_id "al4VFLcDxY_mIul-JSGZuwABVEY"]
[Mon Jul 20 06:31:16.900633 2026] [security2:error] [pid 935758:tid 935901] [client 34.74.185.202:63002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mochawavepublishing.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VFLcDxY_mIul-JSGZ6wAAARU"]
[Mon Jul 20 06:31:16.908973 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZ1gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.909074 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:64868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFLcDxY_mIul-JSGZ1gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:16.934680 2026] [security2:error] [pid 935758:tid 935782] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/key.pem"] [unique_id "al4VFLcDxY_mIul-JSGZ8QABeBU"]
[Mon Jul 20 06:31:16.959449 2026] [security2:error] [pid 935758:tid 935823] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/localhost.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9AABeD4"]
[Mon Jul 20 06:31:16.959638 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/localhost.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9AABeD4"]
[Mon Jul 20 06:31:16.960142 2026] [security2:error] [pid 935758:tid 935797] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/ssl/server.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9gABeCQ"]
[Mon Jul 20 06:31:16.960254 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/ssl/server.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9gABeCQ"]
[Mon Jul 20 06:31:16.961223 2026] [security2:error] [pid 935758:tid 935761] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/privatekey.key"] [unique_id "al4VFLcDxY_mIul-JSGZ9QABeAA"]
[Mon Jul 20 06:31:16.969300 2026] [security2:error] [pid 935758:tid 936007] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ7QAAAX8"]
[Mon Jul 20 06:31:16.974392 2026] [security2:error] [pid 935758:tid 935895] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ4wAAAQ8"]
[Mon Jul 20 06:31:17.024474 2026] [security2:error] [pid 935758:tid 935896] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ-AAAARA"]
[Mon Jul 20 06:31:17.048532 2026] [security2:error] [pid 935758:tid 935963] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ_QAAAVM"]
[Mon Jul 20 06:31:17.048793 2026] [security2:error] [pid 935758:tid 935894] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZ_gAAAQ4"]
[Mon Jul 20 06:31:17.065616 2026] [security2:error] [pid 935758:tid 935924] [client 57.141.18.84:43064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VD7cDxY_mIul-JSGXjAABLDY"]
[Mon Jul 20 06:31:17.069224 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:64869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaCAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.069321 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:64869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaCAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.128697 2026] [security2:error] [pid 935758:tid 935978] [client 74.208.214.194:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VFbcDxY_mIul-JSGaDgAAAWI"]
[Mon Jul 20 06:31:17.132674 2026] [security2:error] [pid 935758:tid 935884] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.openclaw/.env"] [unique_id "al4VFbcDxY_mIul-JSGaDwABeHs"]
[Mon Jul 20 06:31:17.165357 2026] [security2:error] [pid 935758:tid 935932] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaBwAAATQ"]
[Mon Jul 20 06:31:17.177063 2026] [security2:error] [pid 935758:tid 935949] [client 145.223.130.17:47576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.130.223.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-rahudsongallery-com/order-buy-geodon-online-clinic-uk/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaFwAAAUU"]
[Mon Jul 20 06:31:17.193703 2026] [security2:error] [pid 935758:tid 935778] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.hermes/.env"] [unique_id "al4VFbcDxY_mIul-JSGaHAABeBE"]
[Mon Jul 20 06:31:17.195543 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaEAABeB8"]
[Mon Jul 20 06:31:17.214672 2026] [security2:error] [pid 929851:tid 929979] [remote 57.141.18.115:33018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VD2V3ou772CelrLid-wAA-3s"]
[Mon Jul 20 06:31:17.257285 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaGgABeGQ"]
[Mon Jul 20 06:31:17.276649 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaGQABeDk"]
[Mon Jul 20 06:31:17.302904 2026] [security2:error] [pid 935758:tid 935908] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaKQAAARw"]
[Mon Jul 20 06:31:17.307481 2026] [security2:error] [pid 935758:tid 935915] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaLAAAASM"]
[Mon Jul 20 06:31:17.327133 2026] [security2:error] [pid 935758:tid 935795] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.claude.json"] [unique_id "al4VFbcDxY_mIul-JSGaOAABeCI"]
[Mon Jul 20 06:31:17.327267 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.claude.json"] [unique_id "al4VFbcDxY_mIul-JSGaOAABeCI"]
[Mon Jul 20 06:31:17.332221 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaPQAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.332311 2026] [security2:error] [pid 935758:tid 935967] [client 77.110.127.138:64870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaPQAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.340213 2026] [security2:error] [pid 935758:tid 935906] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaNAAAARo"]
[Mon Jul 20 06:31:17.354828 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaQAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.354904 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaQAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.365245 2026] [security2:error] [pid 935758:tid 935865] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.hermes/auth.json"] [unique_id "al4VFbcDxY_mIul-JSGaQQABeGg"]
[Mon Jul 20 06:31:17.365435 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.hermes/auth.json"] [unique_id "al4VFbcDxY_mIul-JSGaQQABeGg"]
[Mon Jul 20 06:31:17.365777 2026] [security2:error] [pid 935758:tid 935812] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al4VFbcDxY_mIul-JSGaQgABeDM"]
[Mon Jul 20 06:31:17.365873 2026] [security2:error] [pid 935758:tid 936000] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/.config/anthropic/credentials/default.json"] [unique_id "al4VFbcDxY_mIul-JSGaQgABeDM"]
[Mon Jul 20 06:31:17.526265 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaWQAAAYc"]
[Mon Jul 20 06:31:17.527131 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaYwAAAYk"]
[Mon Jul 20 06:31:17.527241 2026] [security2:error] [pid 935758:tid 936017] [client 77.110.127.138:64875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaYwAAAYk"]
[Mon Jul 20 06:31:17.530942 2026] [security2:error] [pid 935758:tid 935943] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaUgABP08"]
[Mon Jul 20 06:31:17.533248 2026] [security2:error] [pid 935758:tid 935938] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaWgAAATo"]
[Mon Jul 20 06:31:17.550969 2026] [security2:error] [pid 935758:tid 935943] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaWwABP0Q"]
[Mon Jul 20 06:31:17.561315 2026] [security2:error] [pid 935758:tid 935882] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tadlarsen.com"] [uri "/wp-config.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGaaQABY3k"]
[Mon Jul 20 06:31:17.563461 2026] [security2:error] [pid 935758:tid 935798] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "tadlarsen.com"] [uri "/wp-config.php.old"] [unique_id "al4VFbcDxY_mIul-JSGaagABgCU"]
[Mon Jul 20 06:31:17.564928 2026] [security2:error] [pid 935758:tid 935856] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/laravel/.env"] [unique_id "al4VFbcDxY_mIul-JSGabAABgF8"]
[Mon Jul 20 06:31:17.575255 2026] [security2:error] [pid 935758:tid 935831] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/config/.env.php"] [unique_id "al4VFbcDxY_mIul-JSGabgABgEY"]
[Mon Jul 20 06:31:17.631437 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaggAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.631525 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:64876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaggAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.655100 2026] [security2:error] [pid 935758:tid 936008] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaawABgDA"]
[Mon Jul 20 06:31:17.682492 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:64877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGahwAAAV0"]
[Mon Jul 20 06:31:17.682648 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:64877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGahwAAAV0"]
[Mon Jul 20 06:31:17.685980 2026] [security2:error] [pid 935758:tid 936004] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGafQAAAXw"]
[Mon Jul 20 06:31:17.687539 2026] [security2:error] [pid 935758:tid 935996] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaewAAAXQ"]
[Mon Jul 20 06:31:17.694952 2026] [security2:error] [pid 935758:tid 935791] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/.env.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGaiAABWB4"]
[Mon Jul 20 06:31:17.743473 2026] [security2:error] [pid 935758:tid 935784] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/configuration.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGakQABhxc"]
[Mon Jul 20 06:31:17.744681 2026] [security2:error] [pid 935758:tid 935875] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/.env.swp"] [unique_id "al4VFbcDxY_mIul-JSGakgABh3I"]
[Mon Jul 20 06:31:17.746693 2026] [security2:error] [pid 935758:tid 935816] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/auth.json"] [unique_id "al4VFbcDxY_mIul-JSGalQABhzc"]
[Mon Jul 20 06:31:17.747138 2026] [security2:error] [pid 935758:tid 935763] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/config.php.bak"] [unique_id "al4VFbcDxY_mIul-JSGalgABhwI"]
[Mon Jul 20 06:31:17.747334 2026] [security2:error] [pid 935758:tid 935794] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/core/.env"] [unique_id "al4VFbcDxY_mIul-JSGalAABhyE"]
[Mon Jul 20 06:31:17.789002 2026] [security2:error] [pid 935758:tid 935871] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/web/.env"] [unique_id "al4VFbcDxY_mIul-JSGanAABh24"]
[Mon Jul 20 06:31:17.799239 2026] [security2:error] [pid 935758:tid 935839] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/public/.env"] [unique_id "al4VFbcDxY_mIul-JSGanwABh04"]
[Mon Jul 20 06:31:17.814191 2026] [security2:error] [pid 935758:tid 935966] [client 103.125.179.95:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VFbcDxY_mIul-JSGaowAAAVY"]
[Mon Jul 20 06:31:17.817303 2026] [security2:error] [pid 935758:tid 935966] [client 103.125.179.95:64137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VFbcDxY_mIul-JSGaowAAAVY"]
[Mon Jul 20 06:31:17.858727 2026] [security2:error] [pid 935758:tid 935906] [client 34.73.38.214:56320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VFbcDxY_mIul-JSGasAAAARo"]
[Mon Jul 20 06:31:17.876576 2026] [security2:error] [pid 929851:tid 929965] [remote 57.141.18.27:46906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VEGV3ou772CelrLieCQABAm0"]
[Mon Jul 20 06:31:17.880890 2026] [security2:error] [pid 935758:tid 935948] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGamwAAAUQ"]
[Mon Jul 20 06:31:17.914592 2026] [security2:error] [pid 935758:tid 935967] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGarAAAAVc"]
[Mon Jul 20 06:31:17.951106 2026] [security2:error] [pid 935758:tid 935761] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/api/config"] [unique_id "al4VFbcDxY_mIul-JSGawQABhwA"]
[Mon Jul 20 06:31:17.959616 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaxgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.959760 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:64880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFbcDxY_mIul-JSGaxgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:17.968555 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGatgABhwQ"]
[Mon Jul 20 06:31:17.971022 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGatwABhzw"]
[Mon Jul 20 06:31:17.992262 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGauAABh30"]
[Mon Jul 20 06:31:18.020472 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGawgABhw8"]
[Mon Jul 20 06:31:18.025825 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGawAABhyQ"]
[Mon Jul 20 06:31:18.044432 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGayQAAARc"]
[Mon Jul 20 06:31:18.044923 2026] [security2:error] [pid 935758:tid 935891] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGayAAAAQs"]
[Mon Jul 20 06:31:18.156515 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa0AABhzY"]
[Mon Jul 20 06:31:18.156662 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGazwABh1M"]
[Mon Jul 20 06:31:18.178914 2026] [security2:error] [pid 935758:tid 935813] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/runtime-config.js"] [unique_id "al4VFrcDxY_mIul-JSGa5QABhzQ"]
[Mon Jul 20 06:31:18.179069 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/runtime-config.js"] [unique_id "al4VFrcDxY_mIul-JSGa5QABhzQ"]
[Mon Jul 20 06:31:18.188682 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGawwAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.202426 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa2wABhzs"]
[Mon Jul 20 06:31:18.244709 2026] [security2:error] [pid 935758:tid 935982] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa5gAAAWY"]
[Mon Jul 20 06:31:18.245981 2026] [security2:error] [pid 935758:tid 936016] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa5wAAAYg"]
[Mon Jul 20 06:31:18.269110 2026] [security2:error] [pid 935758:tid 935948] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa4wAAAUQ"]
[Mon Jul 20 06:31:18.274098 2026] [security2:error] [pid 935758:tid 935962] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa6QAAAVI"]
[Mon Jul 20 06:31:18.284525 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa6gABh1Q"]
[Mon Jul 20 06:31:18.305559 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa6wABh0M"]
[Mon Jul 20 06:31:18.307415 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa7AABhys"]
[Mon Jul 20 06:31:18.418776 2026] [security2:error] [pid 935758:tid 935899] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa9gAAARM"]
[Mon Jul 20 06:31:18.429819 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbBwAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.429935 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:64883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbBwAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.447210 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGa-AABhyg"]
[Mon Jul 20 06:31:18.466026 2026] [security2:error] [pid 935758:tid 935971] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbBAAAAVs"]
[Mon Jul 20 06:31:18.469195 2026] [security2:error] [pid 935758:tid 935954] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbAQAAAUo"]
[Mon Jul 20 06:31:18.480594 2026] [security2:error] [pid 935758:tid 935818] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tadlarsen.com"] [uri "/service-worker.js"] [unique_id "al4VFrcDxY_mIul-JSGbDgABhzk"]
[Mon Jul 20 06:31:18.492714 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbBgABhx8"]
[Mon Jul 20 06:31:18.529188 2026] [core:error] [pid 935758:tid 935973] [client 14.225.17.146:49663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/old
[Mon Jul 20 06:31:18.529210 2026] [core:error] [pid 935758:tid 935973] [client 14.225.17.146:49663] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/old
[Mon Jul 20 06:31:18.536603 2026] [security2:error] [pid 935758:tid 935961] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbDQAAAVE"]
[Mon Jul 20 06:31:18.546184 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbDwABh1s"]
[Mon Jul 20 06:31:18.559459 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbDAABh1o"]
[Mon Jul 20 06:31:18.569294 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbEQABhww"]
[Mon Jul 20 06:31:18.596906 2026] [security2:error] [pid 935758:tid 935953] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbGAAAAUk"]
[Mon Jul 20 06:31:18.627184 2026] [security2:error] [pid 935758:tid 936008] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbHQAAAYA"]
[Mon Jul 20 06:31:18.679711 2026] [security2:error] [pid 935758:tid 935779] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/actuator/mappings"] [unique_id "al4VFrcDxY_mIul-JSGbLwABhxI"]
[Mon Jul 20 06:31:18.699648 2026] [security2:error] [pid 935758:tid 935800] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/phpinfo.php"] [unique_id "al4VFrcDxY_mIul-JSGbNQABhyc"]
[Mon Jul 20 06:31:18.718475 2026] [security2:error] [pid 935758:tid 935933] [client 57.141.18.30:46046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VELcDxY_mIul-JSGX7gABNSw"]
[Mon Jul 20 06:31:18.745621 2026] [security2:error] [pid 935758:tid 935771] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/test.php"] [unique_id "al4VFrcDxY_mIul-JSGbPQABhwo"]
[Mon Jul 20 06:31:18.745827 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/test.php"] [unique_id "al4VFrcDxY_mIul-JSGbPQABhwo"]
[Mon Jul 20 06:31:18.745985 2026] [security2:error] [pid 935758:tid 935858] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/pi.php"] [unique_id "al4VFrcDxY_mIul-JSGbPgABh2E"]
[Mon Jul 20 06:31:18.746069 2026] [security2:error] [pid 935758:tid 935841] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/info.php"] [unique_id "al4VFrcDxY_mIul-JSGbPwABh1A"]
[Mon Jul 20 06:31:18.771701 2026] [security2:error] [pid 935758:tid 935981] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbNwAAAWU"]
[Mon Jul 20 06:31:18.772206 2026] [security2:error] [pid 935758:tid 935905] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbMwAAARk"]
[Mon Jul 20 06:31:18.775301 2026] [security2:error] [pid 935758:tid 935943] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbOQAAAT8"]
[Mon Jul 20 06:31:18.777792 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbRQAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.777895 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:64884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbRQAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.780387 2026] [security2:error] [pid 935758:tid 935793] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/i.php"] [unique_id "al4VFrcDxY_mIul-JSGbRwABhyA"]
[Mon Jul 20 06:31:18.814427 2026] [security2:error] [pid 935758:tid 935976] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbQAAAAWA"]
[Mon Jul 20 06:31:18.840511 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbVwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.840610 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:64885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VFrcDxY_mIul-JSGbVwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:18.877888 2026] [security2:error] [pid 935758:tid 935876] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/app_dev.php"] [unique_id "al4VFrcDxY_mIul-JSGbXQABh3M"]
[Mon Jul 20 06:31:18.897584 2026] [security2:error] [pid 935758:tid 935787] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/app_dev.php/_profiler"] [unique_id "al4VFrcDxY_mIul-JSGbYQABhxo"]
[Mon Jul 20 06:31:18.958854 2026] [security2:error] [pid 935758:tid 935768] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tadlarsen.com"] [uri "/_ignition/health-check"] [unique_id "al4VFrcDxY_mIul-JSGbdwABhwc"]
[Mon Jul 20 06:31:18.959069 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tadlarsen.com"] [uri "/_ignition/health-check"] [unique_id "al4VFrcDxY_mIul-JSGbdwABhwc"]
[Mon Jul 20 06:31:19.010355 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkQAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.010442 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:64888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkQAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.020714 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:64889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkgAAAU8"]
[Mon Jul 20 06:31:19.020841 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:64889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbkgAAAU8"]
[Mon Jul 20 06:31:19.029171 2026] [access_compat:error] [pid 935758:tid 935860] [remote 34.129.173.120:52974] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Mon Jul 20 06:31:19.029641 2026] [security2:error] [pid 935758:tid 935886] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "tadlarsen.com"] [uri "/server-info"] [unique_id "al4VF7cDxY_mIul-JSGbkwABh30"]
[Mon Jul 20 06:31:19.135811 2026] [security2:error] [pid 935758:tid 935942] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbVgAAAT4"]
[Mon Jul 20 06:31:19.169007 2026] [security2:error] [pid 935758:tid 936008] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbXgAAAYA"]
[Mon Jul 20 06:31:19.189866 2026] [security2:error] [pid 935758:tid 936011] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbfAAAAYM"]
[Mon Jul 20 06:31:19.197215 2026] [security2:error] [pid 935758:tid 935983] [client 34.73.38.214:64012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VF7cDxY_mIul-JSGbtwAAAWc"]
[Mon Jul 20 06:31:19.199849 2026] [security2:error] [pid 935758:tid 935950] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbrgAAAUY"]
[Mon Jul 20 06:31:19.201331 2026] [security2:error] [pid 935758:tid 935897] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbggAAARE"]
[Mon Jul 20 06:31:19.204199 2026] [security2:error] [pid 935758:tid 935920] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbgAAAASg"]
[Mon Jul 20 06:31:19.204309 2026] [security2:error] [pid 935758:tid 935944] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbfwAAAUA"]
[Mon Jul 20 06:31:19.205899 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbqAABhzs"]
[Mon Jul 20 06:31:19.206680 2026] [security2:error] [pid 935758:tid 935931] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbgQAAATM"]
[Mon Jul 20 06:31:19.251715 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbugAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.251832 2026] [security2:error] [pid 935758:tid 935999] [client 77.110.127.138:64890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbugAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.252790 2026] [security2:error] [pid 935758:tid 935901] [client 77.110.127.138:64891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbuwAAARU"]
[Mon Jul 20 06:31:19.252896 2026] [security2:error] [pid 935758:tid 935901] [client 77.110.127.138:64891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGbuwAAARU"]
[Mon Jul 20 06:31:19.286501 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbtgABh1Q"]
[Mon Jul 20 06:31:19.287247 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbuAABh0M"]
[Mon Jul 20 06:31:19.334629 2026] [security2:error] [pid 935758:tid 936015] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbvgABh3s"]
[Mon Jul 20 06:31:19.407293 2026] [security2:error] [pid 935758:tid 935964] [client 14.225.17.146:62902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbvQAAAVQ"], referer: http://alaraycreative.com/old
[Mon Jul 20 06:31:19.442512 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbygABcEw"]
[Mon Jul 20 06:31:19.448693 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbyQABcAs"]
[Mon Jul 20 06:31:19.459717 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb1wAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.459901 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:64892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb1wAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.465306 2026] [security2:error] [pid 935758:tid 935992] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbzgABcDk"]
[Mon Jul 20 06:31:19.568966 2026] [security2:error] [pid 935758:tid 935911] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb3gABHw4"]
[Mon Jul 20 06:31:19.591211 2026] [security2:error] [pid 935758:tid 935911] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb2gABH1o"]
[Mon Jul 20 06:31:19.595152 2026] [security2:error] [pid 935758:tid 935911] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb3wABHww"]
[Mon Jul 20 06:31:19.626435 2026] [security2:error] [pid 935758:tid 935985] [client 77.110.127.138:64893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb7QAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.626591 2026] [security2:error] [pid 935758:tid 935985] [client 77.110.127.138:64893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGb7QAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.693520 2026] [security2:error] [pid 935758:tid 935849] [remote 194.164.192.228:43700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VF7cDxY_mIul-JSGb9QABg1g"]
[Mon Jul 20 06:31:19.711735 2026] [security2:error] [pid 935758:tid 936006] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb8AABfhI"]
[Mon Jul 20 06:31:19.728425 2026] [security2:error] [pid 935758:tid 936006] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb8wABfmo"]
[Mon Jul 20 06:31:19.730433 2026] [security2:error] [pid 935758:tid 936006] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb7wABflE"]
[Mon Jul 20 06:31:19.788866 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcAAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.788998 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:64895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcAAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.809727 2026] [security2:error] [pid 935758:tid 935923] [client 77.110.127.138:64896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcBgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.809867 2026] [security2:error] [pid 935758:tid 935923] [client 77.110.127.138:64896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VF7cDxY_mIul-JSGcBgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:19.901039 2026] [http2:info] [pid 940476:tid 940476] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:31:19.902359 2026] [security2:error] [pid 935758:tid 935887] [remote 194.164.192.228:43700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VF7cDxY_mIul-JSGcDAABeH4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:19.937011 2026] [security2:error] [pid 935758:tid 935999] [client 197.186.66.42:57169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VF7cDxY_mIul-JSGcEwAAAXc"]
[Mon Jul 20 06:31:19.950210 2026] [security2:error] [pid 935758:tid 935999] [client 197.186.66.42:57169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VF7cDxY_mIul-JSGcEwAAAXc"]
[Mon Jul 20 06:31:20.072216 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGLcDxY_mIul-JSGcHQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.072351 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGLcDxY_mIul-JSGcHQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.126513 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb_QABF2E"]
[Mon Jul 20 06:31:20.141850 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGcAQABF0k"]
[Mon Jul 20 06:31:20.147831 2026] [security2:error] [pid 935758:tid 935903] [client 34.129.173.120:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGcAgABF2g"]
[Mon Jul 20 06:31:20.153273 2026] [fcgid:warn] [pid 935758:tid 935940] (70014)End of file found: [client 66.132.172.223:34248] mod_fcgid: can't get data from http client
[Mon Jul 20 06:31:20.155520 2026] [security2:error] [pid 935758:tid 935919] [client 57.141.18.89:35622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VErcDxY_mIul-JSGYRAABJy8"]
[Mon Jul 20 06:31:20.202489 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGcFwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.361373 2026] [security2:error] [pid 935758:tid 935909] [client 157.52.92.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amazonservices.xp-design.co"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbcQAAAR0"]
[Mon Jul 20 06:31:20.361858 2026] [security2:error] [pid 935758:tid 935913] [client 157.52.92.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.amazonservices.xp-design.co"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbXAAAASE"]
[Mon Jul 20 06:31:20.473350 2026] [security2:error] [pid 940476:tid 940631] [client 114.119.155.81:31733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hilltopnurseryinc.com"] [uri "/robots.txt"] [unique_id "al4VGBjVYcQxwGpYwZmZ3gAAABk"], referer: https://hilltopnurseryinc.com/robots.txt
[Mon Jul 20 06:31:20.495258 2026] [security2:error] [pid 935758:tid 936002] [client 57.141.18.52:56834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VErcDxY_mIul-JSGYXwABemI"]
[Mon Jul 20 06:31:20.731737 2026] [security2:error] [pid 940476:tid 940679] [client 34.73.38.214:64845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VGBjVYcQxwGpYwZmZ8wAAAEk"]
[Mon Jul 20 06:31:20.790227 2026] [security2:error] [pid 935758:tid 936015] [client 52.187.75.220:19457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4VGLcDxY_mIul-JSGcUQAAAYc"]
[Mon Jul 20 06:31:20.825720 2026] [security2:error] [pid 935758:tid 935974] [client 14.225.17.146:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb0gAAAV4"], referer: http://dereckcastellon.com/old
[Mon Jul 20 06:31:20.967019 2026] [security2:error] [pid 940476:tid 940677] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGBjVYcQxwGpYwZmZ8QAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:20.979636 2026] [security2:error] [pid 935758:tid 935952] [client 14.225.17.146:62952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb4gAAAUg"], referer: http://sarahsnyder.net/old
[Mon Jul 20 06:31:20.990233 2026] [security2:error] [pid 935758:tid 935913] [client 52.187.75.220:19457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4VGLcDxY_mIul-JSGcXwAAASE"]
[Mon Jul 20 06:31:20.997250 2026] [security2:error] [pid 935758:tid 935904] [client 57.141.18.38:36480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VE7cDxY_mIul-JSGYnAABGBA"]
[Mon Jul 20 06:31:21.003772 2026] [security2:error] [pid 935758:tid 935914] [client 34.73.38.214:50118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VGbcDxY_mIul-JSGcYQAAASI"]
[Mon Jul 20 06:31:21.167337 2026] [security2:error] [pid 940476:tid 940660] [client 171.61.165.146:16214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VGRjVYcQxwGpYwZmaBgAAADY"]
[Mon Jul 20 06:31:21.168391 2026] [security2:error] [pid 940476:tid 940660] [client 171.61.165.146:16214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VGRjVYcQxwGpYwZmaBgAAADY"]
[Mon Jul 20 06:31:21.188964 2026] [security2:error] [pid 940476:tid 940712] [client 50.116.65.227:12742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VGRjVYcQxwGpYwZmaCAAAAGo"]
[Mon Jul 20 06:31:21.203200 2026] [security2:error] [pid 940476:tid 940715] [client 50.116.65.227:12752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VGRjVYcQxwGpYwZmaCQAAAG0"]
[Mon Jul 20 06:31:21.206304 2026] [security2:error] [pid 935758:tid 935906] [client 14.225.17.146:62200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGb-wAAARo"], referer: http://phillipbloch.com/old
[Mon Jul 20 06:31:21.240954 2026] [security2:error] [pid 935758:tid 935957] [client 104.234.53.50:63799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VGbcDxY_mIul-JSGccAAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:21.267106 2026] [security2:error] [pid 940476:tid 940686] [client 14.225.17.146:49663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4VGRjVYcQxwGpYwZmZ_wAAAFA"], referer: http://adirondackengineering.com/old
[Mon Jul 20 06:31:21.467014 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGRjVYcQxwGpYwZmaDgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:21.821626 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGbcDxY_mIul-JSGcjQAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:21.937187 2026] [security2:error] [pid 940476:tid 940629] [client 14.225.17.146:62811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4VGRjVYcQxwGpYwZmaHgAAABc"], referer: https://sarahsnyder.net/old
[Mon Jul 20 06:31:21.968933 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGbcDxY_mIul-JSGcnQAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:22.080942 2026] [security2:error] [pid 935758:tid 935932] [client 104.234.53.73:44683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VGrcDxY_mIul-JSGcsAAAATQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:22.154165 2026] [security2:error] [pid 935758:tid 935913] [client 223.185.13.213:13020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VGrcDxY_mIul-JSGcswAAASE"]
[Mon Jul 20 06:31:22.154343 2026] [security2:error] [pid 935758:tid 935913] [client 223.185.13.213:13020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VGrcDxY_mIul-JSGcswAAASE"]
[Mon Jul 20 06:31:22.181094 2026] [proxy:error] [pid 935758:tid 935958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:22.181169 2026] [proxy_http:error] [pid 935758:tid 935958] [client 165.154.182.53:37834] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:22.181798 2026] [proxy:error] [pid 935758:tid 935958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:22.181862 2026] [proxy_http:error] [pid 935758:tid 935958] [client 165.154.182.53:37834] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:22.194348 2026] [security2:error] [pid 935758:tid 935907] [client 57.141.18.46:63580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZUAABGwE"]
[Mon Jul 20 06:31:22.397857 2026] [security2:error] [pid 935758:tid 935936] [client 34.73.38.214:65134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VGrcDxY_mIul-JSGcxQAAATg"]
[Mon Jul 20 06:31:22.425930 2026] [security2:error] [pid 940476:tid 940667] [client 114.119.143.104:55713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.itdynamix.com"] [uri "/why-is-customer-relationship-management-so-important"] [unique_id "al4VGhjVYcQxwGpYwZmaMwAAAD0"], referer: https://www.itdynamix.com/why-is-customer-relationship-management-so-important
[Mon Jul 20 06:31:22.434738 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGrcDxY_mIul-JSGcvAAAASo"]
[Mon Jul 20 06:31:22.604657 2026] [security2:error] [pid 935758:tid 935984] [client 57.141.18.123:28974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFLcDxY_mIul-JSGZqwABaA0"]
[Mon Jul 20 06:31:22.836405 2026] [security2:error] [pid 940476:tid 940712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGhjVYcQxwGpYwZmaPAAAAGo"]
[Mon Jul 20 06:31:22.899944 2026] [security2:error] [pid 940476:tid 940683] [client 112.208.70.94:42768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VGhjVYcQxwGpYwZmaQwAAAE0"]
[Mon Jul 20 06:31:22.900091 2026] [security2:error] [pid 940476:tid 940683] [client 112.208.70.94:42768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VGhjVYcQxwGpYwZmaQwAAAE0"]
[Mon Jul 20 06:31:22.933773 2026] [security2:error] [pid 935758:tid 935858] [remote 91.142.222.105:60826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4VGrcDxY_mIul-JSGc4wABaWE"]
[Mon Jul 20 06:31:22.941109 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGhjVYcQxwGpYwZmaRAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:22.941210 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:64927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGhjVYcQxwGpYwZmaRAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.253972 2026] [security2:error] [pid 940476:tid 940609] [client 45.3.42.229:65169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VGxjVYcQxwGpYwZmaVgAAAAM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:23.303461 2026] [security2:error] [pid 935758:tid 935794] [remote 91.142.222.105:60826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4VG7cDxY_mIul-JSGc-wABLSE"], referer: https://omrobuildingcenter.com/wp-login.php
[Mon Jul 20 06:31:23.309250 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.61:42782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGaSwABEhg"]
[Mon Jul 20 06:31:23.442150 2026] [security2:error] [pid 940476:tid 940642] [client 34.73.38.214:63189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VGxjVYcQxwGpYwZmaXQAAACQ"]
[Mon Jul 20 06:31:23.468683 2026] [security2:error] [pid 935758:tid 935915] [client 57.141.18.106:20100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFbcDxY_mIul-JSGadQABIyM"]
[Mon Jul 20 06:31:23.541352 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VG7cDxY_mIul-JSGc_AAAARA"], referer: 1'"3000
[Mon Jul 20 06:31:23.648032 2026] [security2:error] [pid 940476:tid 940666] [client 14.225.17.146:49523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VGhjVYcQxwGpYwZmaMAAAADw"], referer: http://effingweirdmuseums.com/old
[Mon Jul 20 06:31:23.691123 2026] [security2:error] [pid 940476:tid 940661] [client 34.74.185.202:51493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VGxjVYcQxwGpYwZmaZgAAADc"]
[Mon Jul 20 06:31:23.735771 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VG7cDxY_mIul-JSGdGAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.735917 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:64938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VG7cDxY_mIul-JSGdGAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.747297 2026] [security2:error] [pid 940476:tid 940688] [client 165.154.182.53:38064] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/favicon.ico"] [unique_id "al4VGxjVYcQxwGpYwZmaaAAAAFI"]
[Mon Jul 20 06:31:23.823341 2026] [security2:error] [pid 935758:tid 935874] [remote 152.228.213.32:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4VG7cDxY_mIul-JSGdHgABVnE"]
[Mon Jul 20 06:31:23.842350 2026] [security2:error] [pid 940476:tid 940677] [client 165.154.182.53:38068] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/sitemap.xml"] [unique_id "al4VGxjVYcQxwGpYwZmaawAAAEc"]
[Mon Jul 20 06:31:23.842350 2026] [security2:error] [pid 935758:tid 935998] [client 165.154.182.53:38070] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/robots.txt"] [unique_id "al4VG7cDxY_mIul-JSGdIQAAAXY"]
[Mon Jul 20 06:31:23.851204 2026] [security2:error] [pid 935758:tid 935972] [client 104.207.52.225:20583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VG7cDxY_mIul-JSGdHwAAAVw"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:23.893164 2026] [security2:error] [pid 940476:tid 940669] [client 77.110.127.138:64940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGxjVYcQxwGpYwZmacAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.893282 2026] [security2:error] [pid 940476:tid 940669] [client 77.110.127.138:64940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VGxjVYcQxwGpYwZmacAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:23.967720 2026] [security2:error] [pid 940476:tid 940507] [remote 47.86.33.52:25874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VGxjVYcQxwGpYwZmacQAAFh4"]
[Mon Jul 20 06:31:24.039983 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VGxjVYcQxwGpYwZmaaQAAADs"], referer: 1'"3000
[Mon Jul 20 06:31:24.162695 2026] [security2:error] [pid 940476:tid 940710] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaeQAAAGg"]
[Mon Jul 20 06:31:24.179237 2026] [security2:error] [pid 940476:tid 940729] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmahQAAAHs"]
[Mon Jul 20 06:31:24.181122 2026] [security2:error] [pid 940476:tid 940720] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaggAAAHI"]
[Mon Jul 20 06:31:24.183122 2026] [security2:error] [pid 940476:tid 940683] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmagwAAAE0"]
[Mon Jul 20 06:31:24.184920 2026] [security2:error] [pid 935758:tid 935980] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHLcDxY_mIul-JSGdNwAAAWQ"]
[Mon Jul 20 06:31:24.194219 2026] [security2:error] [pid 935758:tid 935943] [client 34.73.38.214:55867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VHLcDxY_mIul-JSGdPAAAAT8"]
[Mon Jul 20 06:31:24.200072 2026] [security2:error] [pid 940476:tid 940730] [client 34.129.173.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tadlarsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmahgAAAHw"]
[Mon Jul 20 06:31:24.207415 2026] [security2:error] [pid 935758:tid 935824] [remote 152.228.213.32:50624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdPQABGj8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:31:24.387346 2026] [security2:error] [pid 935758:tid 935997] [client 57.141.18.65:57438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbGQABdSI"]
[Mon Jul 20 06:31:24.443370 2026] [security2:error] [pid 935758:tid 935840] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdRwABO08"], referer: https://tadlarsen.com/login
[Mon Jul 20 06:31:24.465586 2026] [security2:error] [pid 935758:tid 935915] [client 104.207.62.94:48223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdSwAAASM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:24.506139 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.23:59312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VFrcDxY_mIul-JSGbJgABiAM"]
[Mon Jul 20 06:31:24.580803 2026] [security2:error] [pid 940476:tid 940610] [client 14.225.17.146:59648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmajgAAAAQ"], referer: https://effingweirdmuseums.com/old
[Mon Jul 20 06:31:24.622993 2026] [security2:error] [pid 940476:tid 940620] [client 34.74.185.202:57827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VHBjVYcQxwGpYwZmalAAAAA4"]
[Mon Jul 20 06:31:24.746331 2026] [security2:error] [pid 940476:tid 940652] [client 104.234.53.73:55981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VHBjVYcQxwGpYwZmanQAAAC4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:24.865122 2026] [security2:error] [pid 935758:tid 935828] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdZQABC0M"], referer: https://tadlarsen.com/wp-admin/
[Mon Jul 20 06:31:24.865874 2026] [security2:error] [pid 935758:tid 935884] [remote 34.129.173.120:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.173.129.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4VHLcDxY_mIul-JSGdZgABC3s"], referer: https://tadlarsen.com/wp-admin/
[Mon Jul 20 06:31:24.897811 2026] [security2:error] [pid 935758:tid 935989] [client 57.141.18.24:25774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VF7cDxY_mIul-JSGbrQABbXQ"]
[Mon Jul 20 06:31:24.922272 2026] [security2:error] [pid 935758:tid 935898] [client 34.73.38.214:56089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VHLcDxY_mIul-JSGdbQAAARI"]
[Mon Jul 20 06:31:25.079613 2026] [security2:error] [pid 935758:tid 935976] [client 171.60.139.123:56668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdewAAAWA"]
[Mon Jul 20 06:31:25.079704 2026] [security2:error] [pid 935758:tid 935976] [client 171.60.139.123:56668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdewAAAWA"]
[Mon Jul 20 06:31:25.087721 2026] [security2:error] [pid 935758:tid 936008] [client 65.111.20.90:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VHbcDxY_mIul-JSGdegAAAYA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:31:25.207247 2026] [security2:error] [pid 935758:tid 935990] [client 34.74.185.202:63333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VHbcDxY_mIul-JSGdhQAAAW4"]
[Mon Jul 20 06:31:25.217395 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VHRjVYcQxwGpYwZmaqgAAAFo"]
[Mon Jul 20 06:31:25.217842 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:63362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VHRjVYcQxwGpYwZmaqgAAAFo"]
[Mon Jul 20 06:31:25.436447 2026] [security2:error] [pid 940476:tid 940712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VHRjVYcQxwGpYwZmarAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:25.691458 2026] [security2:error] [pid 935758:tid 935938] [client 45.116.69.230:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdnQAAATo"]
[Mon Jul 20 06:31:25.691620 2026] [security2:error] [pid 935758:tid 935938] [client 45.116.69.230:65525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VHbcDxY_mIul-JSGdnQAAATo"]
[Mon Jul 20 06:31:25.772490 2026] [security2:error] [pid 940476:tid 940630] [client 34.73.38.214:57245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VHRjVYcQxwGpYwZmawgAAABg"]
[Mon Jul 20 06:31:25.903227 2026] [security2:error] [pid 940476:tid 940657] [client 34.74.185.202:59392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VHRjVYcQxwGpYwZmaxwAAADM"]
[Mon Jul 20 06:31:26.134028 2026] [security2:error] [pid 940476:tid 940695] [client 39.48.81.23:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VHhjVYcQxwGpYwZma1wAAAFk"]
[Mon Jul 20 06:31:26.134207 2026] [security2:error] [pid 940476:tid 940695] [client 39.48.81.23:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VHhjVYcQxwGpYwZma1wAAAFk"]
[Mon Jul 20 06:31:26.514628 2026] [security2:error] [pid 940476:tid 940706] [client 34.73.38.214:63747] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VHhjVYcQxwGpYwZma5wAAAGQ"]
[Mon Jul 20 06:31:26.528410 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:64952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma6AAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.528503 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:64952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma6AAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.529437 2026] [security2:error] [pid 940476:tid 940535] [remote 162.19.86.63:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4VHhjVYcQxwGpYwZma6QAAZjo"]
[Mon Jul 20 06:31:26.579076 2026] [security2:error] [pid 940476:tid 940718] [client 34.74.185.202:50602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VHhjVYcQxwGpYwZma7AAAAHA"]
[Mon Jul 20 06:31:26.581682 2026] [security2:error] [pid 940476:tid 940616] [client 104.234.53.55:45875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VHhjVYcQxwGpYwZma7QAAAAo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:26.642719 2026] [security2:error] [pid 940476:tid 940717] [client 66.249.70.4:57839] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.gitec.org"] [uri "/robots.txt"] [unique_id "al4VHhjVYcQxwGpYwZma9AAAAG8"]
[Mon Jul 20 06:31:26.714787 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma-QAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.714884 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:64954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZma-QAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.752827 2026] [security2:error] [pid 940476:tid 940541] [remote 162.19.86.63:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4VHhjVYcQxwGpYwZma-wAAXUA"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:31:26.887158 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:64955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZmbAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.887276 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:64955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHhjVYcQxwGpYwZmbAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:26.948146 2026] [security2:error] [pid 935758:tid 935944] [client 14.225.17.146:59506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4VHLcDxY_mIul-JSGdcQAAAUA"], referer: http://webgardensbypaula.com/old
[Mon Jul 20 06:31:27.048562 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:64956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbDAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.048710 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:64956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbDAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.214622 2026] [security2:error] [pid 940476:tid 940608] [client 34.74.185.202:63017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VHxjVYcQxwGpYwZmbFgAAAAI"]
[Mon Jul 20 06:31:27.269377 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbGgAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.269489 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:64958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbGgAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.315011 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VH7cDxY_mIul-JSGdwgAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.315147 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:64959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VH7cDxY_mIul-JSGdwgAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.473117 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:64961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbIQAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.473205 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:64961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbIQAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.502009 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.39:62343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VGbcDxY_mIul-JSGcjwABYxE"]
[Mon Jul 20 06:31:27.551723 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbJwAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.551854 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:64962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbJwAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.565854 2026] [security2:error] [pid 935758:tid 935923] [client 34.73.38.214:60956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VH7cDxY_mIul-JSGdxwAAASs"]
[Mon Jul 20 06:31:27.758707 2026] [security2:error] [pid 940476:tid 940687] [client 78.188.32.111:60312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.32.188.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bandsir.com"] [uri "/xmlrpc.php"] [unique_id "al4VHxjVYcQxwGpYwZmbLAAAAFE"]
[Mon Jul 20 06:31:27.758861 2026] [security2:error] [pid 940476:tid 940687] [client 78.188.32.111:60312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bandsir.com"] [uri "/xmlrpc.php"] [unique_id "al4VHxjVYcQxwGpYwZmbLAAAAFE"]
[Mon Jul 20 06:31:27.894056 2026] [security2:error] [pid 940476:tid 940649] [client 77.110.127.138:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbMAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:27.894174 2026] [security2:error] [pid 940476:tid 940649] [client 77.110.127.138:64964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VHxjVYcQxwGpYwZmbMAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:28.413198 2026] [security2:error] [pid 940476:tid 940618] [client 34.73.38.214:50828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.jwo.ral.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VIBjVYcQxwGpYwZmbSAAAAAw"]
[Mon Jul 20 06:31:28.489565 2026] [security2:error] [pid 940476:tid 940678] [client 104.234.53.93:28241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VIBjVYcQxwGpYwZmbSwAAAEg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:28.737305 2026] [security2:error] [pid 940476:tid 940717] [client 34.74.185.202:65123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VIBjVYcQxwGpYwZmbYgAAAG8"]
[Mon Jul 20 06:31:28.797905 2026] [security2:error] [pid 935758:tid 936011] [client 103.125.179.95:64765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VILcDxY_mIul-JSGd8QAAAYM"]
[Mon Jul 20 06:31:28.798054 2026] [security2:error] [pid 935758:tid 936011] [client 103.125.179.95:64765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VILcDxY_mIul-JSGd8QAAAYM"]
[Mon Jul 20 06:31:28.867914 2026] [security2:error] [pid 940476:tid 940705] [client 57.141.18.23:58248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VGhjVYcQxwGpYwZmaQAAAYxc"]
[Mon Jul 20 06:31:28.946627 2026] [security2:error] [pid 940476:tid 940580] [remote 47.86.33.52:25874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VIBjVYcQxwGpYwZmbbAAAXmc"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:31:29.022343 2026] [security2:error] [pid 940476:tid 940716] [client 14.225.17.146:58627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4VIBjVYcQxwGpYwZmbagAAAG4"], referer: http://dnsplumbing.com/old
[Mon Jul 20 06:31:29.251729 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VIRjVYcQxwGpYwZmbcgAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:29.589797 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:62727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4VIbcDxY_mIul-JSGd9wAAAWo"], referer: http://partnerselectricalllc.com/old
[Mon Jul 20 06:31:30.474337 2026] [security2:error] [pid 940476:tid 940704] [client 57.141.18.113:64016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaiQAAYiM"]
[Mon Jul 20 06:31:30.493173 2026] [security2:error] [pid 935758:tid 935964] [client 34.74.185.202:57403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VIrcDxY_mIul-JSGeGwAAAVQ"]
[Mon Jul 20 06:31:30.571246 2026] [security2:error] [pid 940476:tid 940609] [client 57.141.18.100:59772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VHBjVYcQxwGpYwZmaiwAAAyU"]
[Mon Jul 20 06:31:30.651418 2026] [security2:error] [pid 935758:tid 935924] [client 63.177.52.239:54086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VIrcDxY_mIul-JSGeHQAAASw"]
[Mon Jul 20 06:31:30.651551 2026] [security2:error] [pid 935758:tid 935924] [client 63.177.52.239:54086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VIrcDxY_mIul-JSGeHQAAASw"]
[Mon Jul 20 06:31:30.886487 2026] [security2:error] [pid 935758:tid 936010] [client 104.234.53.70:61167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VIrcDxY_mIul-JSGeJQAAAYI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:30.933487 2026] [security2:error] [pid 940476:tid 940698] [client 197.186.66.42:57671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VIhjVYcQxwGpYwZmbwwAAAFw"]
[Mon Jul 20 06:31:30.949544 2026] [security2:error] [pid 940476:tid 940698] [client 197.186.66.42:57671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VIhjVYcQxwGpYwZmbwwAAAFw"]
[Mon Jul 20 06:31:30.983316 2026] [security2:error] [pid 940476:tid 940493] [remote 100.42.189.89:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4VIhjVYcQxwGpYwZmbxgAAexA"]
[Mon Jul 20 06:31:30.994138 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIrcDxY_mIul-JSGeLQAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:30.994232 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:64981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIrcDxY_mIul-JSGeLQAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.151975 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:64982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIxjVYcQxwGpYwZmb1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.152082 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:64982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VIxjVYcQxwGpYwZmb1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.266955 2026] [security2:error] [pid 940476:tid 940628] [client 50.116.65.227:54866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VIxjVYcQxwGpYwZmb2wAAABY"]
[Mon Jul 20 06:31:31.279008 2026] [security2:error] [pid 935758:tid 935907] [client 50.116.65.227:54872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VI7cDxY_mIul-JSGePgAAARs"]
[Mon Jul 20 06:31:31.421076 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VI7cDxY_mIul-JSGePwAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.421172 2026] [security2:error] [pid 935758:tid 935937] [client 77.110.127.138:64983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VI7cDxY_mIul-JSGePwAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:31.706144 2026] [security2:error] [pid 940476:tid 940645] [client 34.74.185.202:58281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VIxjVYcQxwGpYwZmb8AAAACc"]
[Mon Jul 20 06:31:31.717900 2026] [security2:error] [pid 940476:tid 940508] [remote 100.42.189.89:50856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4VIxjVYcQxwGpYwZmb8QAAdR8"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:31:31.817141 2026] [security2:error] [pid 935758:tid 935894] [client 50.116.65.227:54898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VI7cDxY_mIul-JSGeSQAAAQ4"]
[Mon Jul 20 06:31:31.833647 2026] [security2:error] [pid 935758:tid 935885] [remote 173.249.4.11:12637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4VI7cDxY_mIul-JSGeUwABPXw"]
[Mon Jul 20 06:31:32.021381 2026] [security2:error] [pid 935758:tid 936006] [client 50.116.65.227:54912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VI7cDxY_mIul-JSGeVAAAAX4"]
[Mon Jul 20 06:31:32.145544 2026] [security2:error] [pid 940476:tid 940524] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4VJBjVYcQxwGpYwZmcCwAAey8"]
[Mon Jul 20 06:31:32.145871 2026] [security2:error] [pid 940476:tid 940729] [client 47.86.33.52:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4VJBjVYcQxwGpYwZmcCwAAey8"]
[Mon Jul 20 06:31:32.272716 2026] [security2:error] [pid 935758:tid 936008] [client 171.61.165.146:7872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VJLcDxY_mIul-JSGeYwAAAYA"]
[Mon Jul 20 06:31:32.272835 2026] [security2:error] [pid 935758:tid 936008] [client 171.61.165.146:7872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VJLcDxY_mIul-JSGeYwAAAYA"]
[Mon Jul 20 06:31:32.395222 2026] [security2:error] [pid 940476:tid 940681] [client 98.159.234.160:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VJBjVYcQxwGpYwZmcHAAAAEs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:32.415334 2026] [security2:error] [pid 940476:tid 940697] [client 57.141.18.4:33228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VHhjVYcQxwGpYwZma1AAAWzI"]
[Mon Jul 20 06:31:32.679301 2026] [security2:error] [pid 935758:tid 935918] [client 5.189.184.113:50732] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "cpanel-box5020.bluehost.com"] [uri "/"] [unique_id "al4VJLcDxY_mIul-JSGeagAAASY"]
[Mon Jul 20 06:31:32.694127 2026] [security2:error] [pid 940476:tid 940640] [client 158.173.89.95:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VJBjVYcQxwGpYwZmcMwAAACI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:32.718059 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJBjVYcQxwGpYwZmcJAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:32.778501 2026] [security2:error] [pid 935758:tid 935955] [client 34.74.185.202:59483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VJLcDxY_mIul-JSGecAAAAUs"]
[Mon Jul 20 06:31:33.228568 2026] [security2:error] [pid 940476:tid 940649] [client 50.116.65.227:45470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4VJRjVYcQxwGpYwZmcQwAAACs"]
[Mon Jul 20 06:31:33.351327 2026] [security2:error] [pid 935758:tid 935923] [client 223.185.13.213:3031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VJbcDxY_mIul-JSGeiAAAASs"]
[Mon Jul 20 06:31:33.352950 2026] [security2:error] [pid 935758:tid 935923] [client 223.185.13.213:3031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VJbcDxY_mIul-JSGeiAAAASs"]
[Mon Jul 20 06:31:33.776927 2026] [security2:error] [pid 935758:tid 935899] [client 34.74.185.202:63263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VJbcDxY_mIul-JSGengAAARM"]
[Mon Jul 20 06:31:33.808328 2026] [security2:error] [pid 935758:tid 935969] [client 57.141.18.53:28216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VH7cDxY_mIul-JSGdzAABWUk"]
[Mon Jul 20 06:31:34.414633 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:65001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJhjVYcQxwGpYwZmcdwAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.441873 2026] [security2:error] [pid 940476:tid 940617] [client 34.74.185.202:65128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.mpp.jej.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VJhjVYcQxwGpYwZmcgAAAAAs"]
[Mon Jul 20 06:31:34.456926 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:65003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmcggAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.457010 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:65003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmcggAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.615352 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmciAAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.616943 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:65004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmciAAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.767952 2026] [security2:error] [pid 940476:tid 940639] [client 77.110.127.138:65006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmckAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.768056 2026] [security2:error] [pid 940476:tid 940639] [client 77.110.127.138:65006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VJhjVYcQxwGpYwZmckAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:34.969797 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:65005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJhjVYcQxwGpYwZmcjwAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:35.085606 2026] [core:error] [pid 940476:tid 940670] [client 198.235.24.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:35.085632 2026] [core:error] [pid 940476:tid 940670] [client 198.235.24.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:35.151848 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJhjVYcQxwGpYwZmcmwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:35.400635 2026] [security2:error] [pid 940476:tid 940642] [client 77.110.127.138:65012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJxjVYcQxwGpYwZmcswAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:35.563508 2026] [security2:error] [pid 935758:tid 935779] [remote 162.19.86.63:38461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VJ7cDxY_mIul-JSGexQABKxI"]
[Mon Jul 20 06:31:35.563659 2026] [security2:error] [pid 935758:tid 935923] [client 162.19.86.63:38461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VJ7cDxY_mIul-JSGexQABKxI"]
[Mon Jul 20 06:31:35.654924 2026] [security2:error] [pid 940476:tid 940733] [client 74.208.214.194:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VJxjVYcQxwGpYwZmczQAAAH8"]
[Mon Jul 20 06:31:35.718684 2026] [security2:error] [pid 940476:tid 940616] [client 171.60.139.123:57194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VJxjVYcQxwGpYwZmc0AAAAAo"]
[Mon Jul 20 06:31:35.718843 2026] [security2:error] [pid 940476:tid 940616] [client 171.60.139.123:57194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VJxjVYcQxwGpYwZmc0AAAAAo"]
[Mon Jul 20 06:31:35.720905 2026] [security2:error] [pid 935758:tid 935944] [client 82.135.202.97:46432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.202.135.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/forecast/covers.php"] [unique_id "al4VJ7cDxY_mIul-JSGe0AAAAUA"]
[Mon Jul 20 06:31:35.761235 2026] [security2:error] [pid 940476:tid 940654] [client 57.141.18.68:57488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VIRjVYcQxwGpYwZmbdQAAMGs"]
[Mon Jul 20 06:31:35.958796 2026] [security2:error] [pid 935758:tid 935987] [client 77.110.127.138:65017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VJ7cDxY_mIul-JSGezQAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.016084 2026] [security2:error] [pid 940476:tid 940697] [client 103.141.108.143:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc2QAAAFs"]
[Mon Jul 20 06:31:36.016188 2026] [security2:error] [pid 940476:tid 940697] [client 103.141.108.143:63846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc2QAAAFs"]
[Mon Jul 20 06:31:36.105583 2026] [security2:error] [pid 935758:tid 935948] [client 39.48.81.23:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe2QAAAUQ"]
[Mon Jul 20 06:31:36.105679 2026] [security2:error] [pid 935758:tid 935948] [client 39.48.81.23:63641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe2QAAAUQ"]
[Mon Jul 20 06:31:36.156779 2026] [security2:error] [pid 940476:tid 940597] [remote 20.173.88.122:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VKBjVYcQxwGpYwZmc4QAARng"]
[Mon Jul 20 06:31:36.297296 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKBjVYcQxwGpYwZmc3wAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.404114 2026] [security2:error] [pid 935758:tid 935805] [remote 47.86.33.52:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4VKLcDxY_mIul-JSGe4wABKCw"]
[Mon Jul 20 06:31:36.426420 2026] [security2:error] [pid 935758:tid 935995] [client 45.116.69.230:49692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe5AAAAXM"]
[Mon Jul 20 06:31:36.426566 2026] [security2:error] [pid 935758:tid 935995] [client 45.116.69.230:49692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VKLcDxY_mIul-JSGe5AAAAXM"]
[Mon Jul 20 06:31:36.455635 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:65026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKBjVYcQxwGpYwZmc6gAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.506350 2026] [security2:error] [pid 940476:tid 940604] [remote 20.173.88.122:54948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VKBjVYcQxwGpYwZmc9QAAdH8"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:36.533762 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:65029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-AAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.533864 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:65029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-AAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.556433 2026] [proxy:error] [pid 935758:tid 935912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.556512 2026] [proxy_http:error] [pid 935758:tid 935912] [client 165.232.42.95:53624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:36.557217 2026] [proxy:error] [pid 935758:tid 935912] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.557247 2026] [proxy_http:error] [pid 935758:tid 935912] [client 165.232.42.95:53624] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:36.589267 2026] [security2:error] [pid 940476:tid 940648] [client 112.208.70.94:43232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-gAAACo"]
[Mon Jul 20 06:31:36.589436 2026] [security2:error] [pid 940476:tid 940648] [client 112.208.70.94:43232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VKBjVYcQxwGpYwZmc-gAAACo"]
[Mon Jul 20 06:31:36.723050 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdBQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.723156 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdBQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.773560 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:64990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdCAAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.773679 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:64990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKBjVYcQxwGpYwZmdCAAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:36.820203 2026] [security2:error] [pid 940476:tid 940677] [client 104.234.53.80:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VKBjVYcQxwGpYwZmdCwAAAEc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:36.835992 2026] [proxy:error] [pid 940476:tid 940658] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.836030 2026] [proxy_http:error] [pid 940476:tid 940658] [client 165.232.42.95:53640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.msandreaadams.net/
[Mon Jul 20 06:31:36.836470 2026] [proxy:error] [pid 940476:tid 940658] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:36.836491 2026] [proxy_http:error] [pid 940476:tid 940658] [client 165.232.42.95:53640] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.msandreaadams.net/
[Mon Jul 20 06:31:36.893165 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:64989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKBjVYcQxwGpYwZmdAgAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:37.078997 2026] [security2:error] [pid 935758:tid 935870] [remote 47.86.33.52:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4VKbcDxY_mIul-JSGe9gABb20"], referer: https://claysharecon.com/wp-login.php
[Mon Jul 20 06:31:37.148633 2026] [proxy:error] [pid 935758:tid 935896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:37.148675 2026] [proxy_http:error] [pid 935758:tid 935896] [client 107.175.132.21:40000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:37.149297 2026] [proxy:error] [pid 935758:tid 935896] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:37.149321 2026] [proxy_http:error] [pid 935758:tid 935896] [client 107.175.132.21:40000] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:37.171165 2026] [security2:error] [pid 935758:tid 935957] [client 57.141.18.52:63472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VIrcDxY_mIul-JSGeFQABTRs"]
[Mon Jul 20 06:31:37.348539 2026] [security2:error] [pid 940476:tid 940690] [client 77.110.127.138:65040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdGQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:37.434121 2026] [core:error] [pid 940476:tid 940680] [client 165.232.42.95:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:37.434140 2026] [core:error] [pid 940476:tid 940680] [client 165.232.42.95:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:31:37.468578 2026] [security2:error] [pid 935758:tid 935937] [client 114.119.152.130:64121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bluedoorbar.co.nz"] [uri "/pagine/460428-HIDRKYBFAH.html"] [unique_id "al4VKbcDxY_mIul-JSGfAwAAATk"], referer: http://bluedoorbar.co.nz/pagine/460428-HIDRKYBFAH.html
[Mon Jul 20 06:31:37.616507 2026] [security2:error] [pid 940476:tid 940689] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdLAAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:37.836654 2026] [security2:error] [pid 935758:tid 935871] [remote 81.173.115.7:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4VKbcDxY_mIul-JSGfDQABfm4"]
[Mon Jul 20 06:31:37.891947 2026] [security2:error] [pid 935758:tid 936010] [client 77.110.127.138:65047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKbcDxY_mIul-JSGfBwAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.058163 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdPgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.101956 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKRjVYcQxwGpYwZmdRQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.200471 2026] [security2:error] [pid 935758:tid 935785] [remote 81.173.115.7:46258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4VKrcDxY_mIul-JSGfGgABGxg"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:31:38.246471 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKhjVYcQxwGpYwZmdTwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.246602 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:65056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VKhjVYcQxwGpYwZmdTwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:38.261216 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.84:65128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VI7cDxY_mIul-JSGeQQABEj8"]
[Mon Jul 20 06:31:38.351182 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:65055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKhjVYcQxwGpYwZmdTQAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.039391 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKrcDxY_mIul-JSGfMgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.114981 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:65060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKhjVYcQxwGpYwZmdbAAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.314885 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:65065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfOwAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.314986 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:65065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfOwAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.459598 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VK7cDxY_mIul-JSGfOQAAAVI"]
[Mon Jul 20 06:31:39.512144 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:65070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfQgAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.512264 2026] [security2:error] [pid 935758:tid 935903] [client 77.110.127.138:65070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VK7cDxY_mIul-JSGfQgAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.567880 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:65066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VK7cDxY_mIul-JSGfPgAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.746290 2026] [security2:error] [pid 940476:tid 940706] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKxjVYcQxwGpYwZmdhwAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:39.747232 2026] [security2:error] [pid 940476:tid 940720] [client 103.125.179.95:65240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VKxjVYcQxwGpYwZmdjAAAAHI"]
[Mon Jul 20 06:31:39.747368 2026] [security2:error] [pid 940476:tid 940720] [client 103.125.179.95:65240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VKxjVYcQxwGpYwZmdjAAAAHI"]
[Mon Jul 20 06:31:39.779847 2026] [security2:error] [pid 940476:tid 940694] [client 50.116.65.227:38918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4VKxjVYcQxwGpYwZmdjwAAAFg"]
[Mon Jul 20 06:31:39.791015 2026] [security2:error] [pid 940476:tid 940622] [client 50.116.65.227:21308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4VKxjVYcQxwGpYwZmdkAAAADk"]
[Mon Jul 20 06:31:39.935334 2026] [security2:error] [pid 940476:tid 940698] [client 74.249.245.134:52774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VKxjVYcQxwGpYwZmdngAAAFw"]
[Mon Jul 20 06:31:39.935451 2026] [security2:error] [pid 940476:tid 940698] [client 74.249.245.134:52774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VKxjVYcQxwGpYwZmdngAAAFw"]
[Mon Jul 20 06:31:40.016599 2026] [security2:error] [pid 940476:tid 940682] [client 77.110.127.138:65073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKxjVYcQxwGpYwZmdkwAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:40.075598 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VKxjVYcQxwGpYwZmdmAAAAEM"]
[Mon Jul 20 06:31:40.218855 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLLcDxY_mIul-JSGfTgAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:40.283570 2026] [security2:error] [pid 940476:tid 940703] [client 77.110.127.138:65042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLBjVYcQxwGpYwZmdqgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:40.313140 2026] [security2:error] [pid 940476:tid 940730] [client 57.141.18.18:24174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VJRjVYcQxwGpYwZmcTAAAfEQ"]
[Mon Jul 20 06:31:41.167151 2026] [security2:error] [pid 940476:tid 940632] [client 104.234.53.64:41203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VLRjVYcQxwGpYwZmd2wAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:41.570530 2026] [security2:error] [pid 935758:tid 935947] [client 57.141.18.41:37594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VJrcDxY_mIul-JSGerQABQ0g"]
[Mon Jul 20 06:31:41.732960 2026] [security2:error] [pid 935758:tid 935910] [client 195.2.67.184:61192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-content/plugins/si-captcha-for-wordpress/captcha/securimage_show.php"] [unique_id "al4VLbcDxY_mIul-JSGfgQAAAR4"], referer: https://suretybonds-california.com/new-wage-liability-for-general-contractors/
[Mon Jul 20 06:31:41.842626 2026] [security2:error] [pid 940476:tid 940671] [client 197.186.66.42:58168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VLRjVYcQxwGpYwZmeAAAAAEE"]
[Mon Jul 20 06:31:41.854090 2026] [security2:error] [pid 940476:tid 940671] [client 197.186.66.42:58168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VLRjVYcQxwGpYwZmeAAAAAEE"]
[Mon Jul 20 06:31:41.891263 2026] [security2:error] [pid 935758:tid 935966] [client 104.234.53.82:23557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VLbcDxY_mIul-JSGfhQAAAVY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:42.088804 2026] [security2:error] [pid 940476:tid 940733] [client 74.249.245.134:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4VLhjVYcQxwGpYwZmeCwAAAH8"]
[Mon Jul 20 06:31:42.088900 2026] [security2:error] [pid 940476:tid 940733] [client 74.249.245.134:52770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4VLhjVYcQxwGpYwZmeCwAAAH8"]
[Mon Jul 20 06:31:42.230739 2026] [security2:error] [pid 940476:tid 940624] [client 20.245.75.247:38560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4VLhjVYcQxwGpYwZmeDwAAABI"]
[Mon Jul 20 06:31:42.236344 2026] [security2:error] [pid 940476:tid 940614] [client 77.110.127.138:65091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeEgAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.236439 2026] [security2:error] [pid 940476:tid 940614] [client 77.110.127.138:65091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeEgAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.250566 2026] [security2:error] [pid 940476:tid 940700] [client 20.245.75.247:38560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4VLhjVYcQxwGpYwZmeFwAAAF4"]
[Mon Jul 20 06:31:42.373316 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:65043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLhjVYcQxwGpYwZmeDQAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.457255 2026] [security2:error] [pid 940476:tid 940713] [client 57.141.18.57:60126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VJxjVYcQxwGpYwZmcxAAAa2o"]
[Mon Jul 20 06:31:42.489192 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLrcDxY_mIul-JSGfkwAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.698745 2026] [security2:error] [pid 940476:tid 940676] [client 195.2.67.184:61329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.67.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeLgAAAEY"], referer: https://suretybonds-california.com/new-wage-liability-for-general-contractors/
[Mon Jul 20 06:31:42.698853 2026] [security2:error] [pid 940476:tid 940676] [client 195.2.67.184:61329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmeLgAAAEY"], referer: https://suretybonds-california.com/new-wage-liability-for-general-contractors/
[Mon Jul 20 06:31:42.746960 2026] [security2:error] [pid 940476:tid 940621] [client 47.128.21.147:14616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "itekphonerepair.com"] [uri "/robots.txt"] [unique_id "al4VLhjVYcQxwGpYwZmeNQAAAA8"]
[Mon Jul 20 06:31:42.804974 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:65095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLhjVYcQxwGpYwZmeKAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.840688 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLrcDxY_mIul-JSGfpAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.840786 2026] [security2:error] [pid 935758:tid 935914] [client 77.110.127.138:65097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLrcDxY_mIul-JSGfpAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.847822 2026] [security2:error] [pid 940476:tid 940634] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VLhjVYcQxwGpYwZmeLQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.991171 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:65099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmePwAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:42.991279 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:65099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VLhjVYcQxwGpYwZmePwAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:43.002551 2026] [security2:error] [pid 940476:tid 940606] [client 171.61.165.146:17750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeQAAAAAA"]
[Mon Jul 20 06:31:43.002709 2026] [security2:error] [pid 940476:tid 940606] [client 171.61.165.146:17750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeQAAAAAA"]
[Mon Jul 20 06:31:43.159476 2026] [security2:error] [pid 940476:tid 940716] [client 106.219.188.178:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeSAAAAG4"]
[Mon Jul 20 06:31:43.159679 2026] [security2:error] [pid 940476:tid 940716] [client 106.219.188.178:58750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VLxjVYcQxwGpYwZmeSAAAAG4"]
[Mon Jul 20 06:31:43.287423 2026] [security2:error] [pid 935758:tid 935932] [client 77.110.127.138:65017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VL7cDxY_mIul-JSGfpwAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:43.942329 2026] [proxy:error] [pid 935758:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:43.942430 2026] [proxy_http:error] [pid 935758:tid 935995] [client 34.73.38.214:57441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:43.943503 2026] [proxy:error] [pid 935758:tid 935995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:43.943552 2026] [proxy_http:error] [pid 935758:tid 935995] [client 34.73.38.214:57441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:44.216206 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMLcDxY_mIul-JSGfzAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.368681 2026] [security2:error] [pid 935758:tid 935978] [client 223.185.13.213:23766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VMLcDxY_mIul-JSGf2AAAAWI"]
[Mon Jul 20 06:31:44.368809 2026] [security2:error] [pid 935758:tid 935978] [client 223.185.13.213:23766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VMLcDxY_mIul-JSGf2AAAAWI"]
[Mon Jul 20 06:31:44.537521 2026] [security2:error] [pid 940476:tid 940652] [client 216.73.216.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.waterproofgoods.com"] [uri "/index.php"] [unique_id "al4VMBjVYcQxwGpYwZmedQAAAC4"]
[Mon Jul 20 06:31:44.642982 2026] [security2:error] [pid 940476:tid 940675] [client 77.110.127.138:65107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMBjVYcQxwGpYwZmegwAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.805020 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:65108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMLcDxY_mIul-JSGf6AAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.805154 2026] [security2:error] [pid 935758:tid 935958] [client 77.110.127.138:65108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMLcDxY_mIul-JSGf6AAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:44.840743 2026] [proxy:error] [pid 935758:tid 935974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:44.840847 2026] [proxy_http:error] [pid 935758:tid 935974] [client 34.73.38.214:54308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:44.841324 2026] [proxy:error] [pid 935758:tid 935974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:44.841348 2026] [proxy_http:error] [pid 935758:tid 935974] [client 34.73.38.214:54308] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:45.074290 2026] [security2:error] [pid 935758:tid 935924] [client 176.57.150.156:53280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4VMbcDxY_mIul-JSGf9AAAASw"]
[Mon Jul 20 06:31:45.193876 2026] [security2:error] [pid 940476:tid 940688] [client 104.234.53.92:36231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VMRjVYcQxwGpYwZmemgAAAFI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:45.288802 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMRjVYcQxwGpYwZmelwAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:45.419534 2026] [security2:error] [pid 940476:tid 940677] [client 34.24.137.199:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.137.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "casabella.aasgroup.online"] [uri "/xmlrpc.php"] [unique_id "al4VMRjVYcQxwGpYwZmeqQAAAEc"]
[Mon Jul 20 06:31:45.426934 2026] [security2:error] [pid 940476:tid 940733] [client 74.7.227.179:43334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VMRjVYcQxwGpYwZmeogAAfxE"], referer: https://tejasenvironmental.com/p=955081
[Mon Jul 20 06:31:45.478458 2026] [security2:error] [pid 940476:tid 940714] [client 158.173.166.181:35153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VMRjVYcQxwGpYwZmesAAAAGw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:45.517400 2026] [security2:error] [pid 935758:tid 935903] [client 176.57.150.156:53290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4VMbcDxY_mIul-JSGgCQAAARc"]
[Mon Jul 20 06:31:45.607590 2026] [security2:error] [pid 940476:tid 940671] [client 14.225.17.146:64773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4VMRjVYcQxwGpYwZmesgAAAEE"], referer: http://nikkidesigns.net/Old
[Mon Jul 20 06:31:45.659089 2026] [security2:error] [pid 935758:tid 935949] [client 74.249.245.134:10945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/wp.php"] [unique_id "al4VMbcDxY_mIul-JSGgEAAAAUU"]
[Mon Jul 20 06:31:45.659228 2026] [security2:error] [pid 935758:tid 935949] [client 74.249.245.134:10945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/wp.php"] [unique_id "al4VMbcDxY_mIul-JSGgEAAAAUU"]
[Mon Jul 20 06:31:45.772740 2026] [security2:error] [pid 935758:tid 935897] [client 57.141.18.125:27450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VKrcDxY_mIul-JSGfJAABEVI"]
[Mon Jul 20 06:31:45.948538 2026] [security2:error] [pid 940476:tid 940709] [client 176.57.150.156:53300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4VMRjVYcQxwGpYwZmevAAAAGc"]
[Mon Jul 20 06:31:45.959906 2026] [proxy:error] [pid 935758:tid 935901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:45.959984 2026] [proxy_http:error] [pid 935758:tid 935901] [client 34.73.38.214:54283] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:45.960705 2026] [proxy:error] [pid 935758:tid 935901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:45.960739 2026] [proxy_http:error] [pid 935758:tid 935901] [client 34.73.38.214:54283] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:46.078726 2026] [security2:error] [pid 940476:tid 940630] [client 34.24.137.199:52092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VMhjVYcQxwGpYwZmevgAAABg"]
[Mon Jul 20 06:31:46.134606 2026] [security2:error] [pid 935758:tid 935954] [client 77.110.127.138:65114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMbcDxY_mIul-JSGgCAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.168306 2026] [security2:error] [pid 935758:tid 935976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMbcDxY_mIul-JSGgGgAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.271051 2026] [security2:error] [pid 935758:tid 935978] [client 171.60.139.123:57723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VMrcDxY_mIul-JSGgNgAAAWI"]
[Mon Jul 20 06:31:46.271158 2026] [security2:error] [pid 935758:tid 935978] [client 171.60.139.123:57723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VMrcDxY_mIul-JSGgNgAAAWI"]
[Mon Jul 20 06:31:46.452582 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme3gAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.452686 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme3gAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.459112 2026] [security2:error] [pid 940476:tid 940732] [client 164.52.11.194:39498] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme2QAAAH4"]
[Mon Jul 20 06:31:46.459243 2026] [security2:error] [pid 940476:tid 940732] [client 164.52.11.194:39498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme2QAAAH4"]
[Mon Jul 20 06:31:46.459275 2026] [security2:error] [pid 940476:tid 940732] [client 164.52.11.194:39498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme2QAAAH4"]
[Mon Jul 20 06:31:46.613794 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme5QAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.613932 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMhjVYcQxwGpYwZme5QAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:46.641495 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VMhjVYcQxwGpYwZme5gAAAFo"]
[Mon Jul 20 06:31:46.641888 2026] [security2:error] [pid 940476:tid 940696] [client 103.141.108.143:64328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VMhjVYcQxwGpYwZme5gAAAFo"]
[Mon Jul 20 06:31:46.713936 2026] [security2:error] [pid 940476:tid 940627] [client 34.24.137.199:51693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VMhjVYcQxwGpYwZme7AAAABU"]
[Mon Jul 20 06:31:46.748959 2026] [security2:error] [pid 940476:tid 940682] [client 14.225.17.146:51285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZme4AAAAEw"], referer: http://nomorewetsheets.net/Old
[Mon Jul 20 06:31:46.787230 2026] [security2:error] [pid 935758:tid 935988] [client 74.249.245.134:52757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/new.php"] [unique_id "al4VMrcDxY_mIul-JSGgRgAAAWw"]
[Mon Jul 20 06:31:46.787322 2026] [security2:error] [pid 935758:tid 935988] [client 74.249.245.134:52757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/new.php"] [unique_id "al4VMrcDxY_mIul-JSGgRgAAAWw"]
[Mon Jul 20 06:31:46.857873 2026] [security2:error] [pid 940476:tid 940697] [client 14.225.17.146:51430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZme6QAAAFs"], referer: http://xp-design.co/Old
[Mon Jul 20 06:31:46.984821 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:65120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZme7wAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.014027 2026] [security2:error] [pid 935758:tid 935978] [client 39.48.81.23:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgUQAAAWI"]
[Mon Jul 20 06:31:47.014187 2026] [security2:error] [pid 935758:tid 935978] [client 39.48.81.23:64143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgUQAAAWI"]
[Mon Jul 20 06:31:47.198560 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:65123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMxjVYcQxwGpYwZmfCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.198696 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:65123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VMxjVYcQxwGpYwZmfCQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.213651 2026] [security2:error] [pid 935758:tid 935859] [remote 103.28.36.106:47574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VM7cDxY_mIul-JSGgVwABWWI"]
[Mon Jul 20 06:31:47.251821 2026] [security2:error] [pid 935758:tid 936005] [client 57.141.18.19:49134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLLcDxY_mIul-JSGfVAABfQA"]
[Mon Jul 20 06:31:47.257280 2026] [security2:error] [pid 935758:tid 935907] [client 45.116.69.230:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgWgAAARs"]
[Mon Jul 20 06:31:47.257398 2026] [security2:error] [pid 935758:tid 935907] [client 45.116.69.230:50238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VM7cDxY_mIul-JSGgWgAAARs"]
[Mon Jul 20 06:31:47.286697 2026] [proxy:error] [pid 940476:tid 940628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:47.286774 2026] [proxy_http:error] [pid 940476:tid 940628] [client 34.73.38.214:55274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:47.287459 2026] [proxy:error] [pid 940476:tid 940628] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:47.287493 2026] [proxy_http:error] [pid 940476:tid 940628] [client 34.73.38.214:55274] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:47.361534 2026] [security2:error] [pid 940476:tid 940624] [client 34.24.137.199:52028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VMxjVYcQxwGpYwZmfFQAAABI"]
[Mon Jul 20 06:31:47.380866 2026] [security2:error] [pid 935758:tid 935919] [client 77.110.127.138:65121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgVgAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:47.456080 2026] [security2:error] [pid 940476:tid 940694] [client 57.141.18.96:21426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLBjVYcQxwGpYwZmdvAAAWEk"]
[Mon Jul 20 06:31:47.633558 2026] [security2:error] [pid 935758:tid 935766] [remote 103.28.36.106:47574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VM7cDxY_mIul-JSGgbgABTgU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:31:47.729152 2026] [security2:error] [pid 940476:tid 940709] [client 46.110.96.34:59854] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4VMxjVYcQxwGpYwZmfKAAAAGc"]
[Mon Jul 20 06:31:47.734089 2026] [security2:error] [pid 940476:tid 940530] [remote 72.167.132.114:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4VMxjVYcQxwGpYwZmfJwAASTU"]
[Mon Jul 20 06:31:47.877167 2026] [security2:error] [pid 935758:tid 935962] [client 34.73.38.214:58316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VM7cDxY_mIul-JSGgewAAAVI"]
[Mon Jul 20 06:31:47.880284 2026] [security2:error] [pid 935758:tid 935952] [client 14.225.17.146:56779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgcgAAAUg"], referer: http://taskidsvirginia.com/Old
[Mon Jul 20 06:31:47.887449 2026] [security2:error] [pid 935758:tid 935947] [client 34.24.137.199:59297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VM7cDxY_mIul-JSGgfQAAAUM"]
[Mon Jul 20 06:31:47.921363 2026] [security2:error] [pid 940476:tid 940642] [client 74.7.175.158:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rentorangegrove.com"] [uri "/index.php"] [unique_id "al4VMhjVYcQxwGpYwZmeyAAAACQ"]
[Mon Jul 20 06:31:47.927824 2026] [security2:error] [pid 940476:tid 940612] [client 74.7.175.158:36718] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "rentorangegrove.com"] [uri "/robots.txt"] [unique_id "al4VMhjVYcQxwGpYwZmewgAABik"]
[Mon Jul 20 06:31:47.947785 2026] [security2:error] [pid 940476:tid 940526] [remote 72.167.132.114:58152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4VMxjVYcQxwGpYwZmfMQAADzE"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:31:48.014969 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:65126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgeAAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:48.285740 2026] [security2:error] [pid 935758:tid 935960] [client 14.225.17.146:57934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGggAAAAVA"], referer: http://tacticaltreeoperations.com/Old
[Mon Jul 20 06:31:48.294441 2026] [security2:error] [pid 940476:tid 940699] [client 34.73.38.214:58714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VNBjVYcQxwGpYwZmfQAAAAF0"]
[Mon Jul 20 06:31:48.332977 2026] [security2:error] [pid 935758:tid 935931] [client 164.52.11.194:39942] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VNLcDxY_mIul-JSGgkAAAATM"]
[Mon Jul 20 06:31:48.333190 2026] [security2:error] [pid 935758:tid 935931] [client 164.52.11.194:39942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VNLcDxY_mIul-JSGgkAAAATM"]
[Mon Jul 20 06:31:48.333245 2026] [security2:error] [pid 935758:tid 935931] [client 164.52.11.194:39942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VNLcDxY_mIul-JSGgkAAAATM"]
[Mon Jul 20 06:31:48.473531 2026] [security2:error] [pid 935758:tid 935911] [client 34.24.137.199:60186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VNLcDxY_mIul-JSGgmQAAAR8"]
[Mon Jul 20 06:31:48.571785 2026] [security2:error] [pid 940476:tid 940675] [client 14.251.3.155:58424] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4VNBjVYcQxwGpYwZmfTgAAAEU"]
[Mon Jul 20 06:31:48.659458 2026] [security2:error] [pid 940476:tid 940536] [remote 160.187.68.132:37342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VNBjVYcQxwGpYwZmfUQAAbDs"]
[Mon Jul 20 06:31:48.689112 2026] [security2:error] [pid 940476:tid 940689] [client 74.249.245.134:10996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/wpls.php"] [unique_id "al4VNBjVYcQxwGpYwZmfVAAAAFM"]
[Mon Jul 20 06:31:48.689212 2026] [security2:error] [pid 940476:tid 940689] [client 74.249.245.134:10996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/wpls.php"] [unique_id "al4VNBjVYcQxwGpYwZmfVAAAAFM"]
[Mon Jul 20 06:31:48.866983 2026] [security2:error] [pid 935758:tid 935969] [client 77.110.127.138:65129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNLcDxY_mIul-JSGgnAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:48.890300 2026] [security2:error] [pid 940476:tid 940678] [client 57.141.18.22:32520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLRjVYcQxwGpYwZmd-AAASGE"]
[Mon Jul 20 06:31:48.970483 2026] [security2:error] [pid 940476:tid 940717] [client 34.24.137.199:50730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VNBjVYcQxwGpYwZmfYwAAAG8"]
[Mon Jul 20 06:31:49.004298 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:65131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNBjVYcQxwGpYwZmfVgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.060712 2026] [security2:error] [pid 940476:tid 940718] [client 57.141.18.60:27394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLRjVYcQxwGpYwZmeAQAAcGI"]
[Mon Jul 20 06:31:49.089281 2026] [security2:error] [pid 940476:tid 940730] [client 77.110.127.138:65135] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/contact-me/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4VNRjVYcQxwGpYwZmfaAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.129608 2026] [security2:error] [pid 935758:tid 936017] [client 14.225.17.146:55545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4VM7cDxY_mIul-JSGgZgAAAYk"], referer: http://swafforddetailing.com/Old
[Mon Jul 20 06:31:49.138313 2026] [security2:error] [pid 940476:tid 940537] [remote 160.187.68.132:37342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VNRjVYcQxwGpYwZmfagAAIjw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:31:49.220999 2026] [security2:error] [pid 935758:tid 935891] [client 34.73.38.214:55660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VNbcDxY_mIul-JSGgrQAAAQs"]
[Mon Jul 20 06:31:49.240834 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:65141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNbcDxY_mIul-JSGgrwAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.240939 2026] [security2:error] [pid 935758:tid 935904] [client 77.110.127.138:65141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNbcDxY_mIul-JSGgrwAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.264986 2026] [security2:error] [pid 940476:tid 940731] [client 114.119.134.231:47123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.danwolfe.us"] [uri "/on-the-closure-of-valley-forge-military-academy/"] [unique_id "al4VNRjVYcQxwGpYwZmfbQAAAH0"], referer: https://blog.danwolfe.us/
[Mon Jul 20 06:31:49.391931 2026] [security2:error] [pid 940476:tid 940728] [client 34.24.137.199:54867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VNRjVYcQxwGpYwZmfdgAAAHo"]
[Mon Jul 20 06:31:49.453784 2026] [security2:error] [pid 940476:tid 940668] [client 77.110.127.138:65144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNRjVYcQxwGpYwZmfeAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.453949 2026] [security2:error] [pid 940476:tid 940668] [client 77.110.127.138:65144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNRjVYcQxwGpYwZmfeAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.563450 2026] [security2:error] [pid 940476:tid 940619] [client 77.110.127.138:65143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNRjVYcQxwGpYwZmfdQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:49.749857 2026] [security2:error] [pid 940476:tid 940700] [client 50.116.65.227:24456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VNRjVYcQxwGpYwZmfiAAAAF4"]
[Mon Jul 20 06:31:49.760546 2026] [security2:error] [pid 940476:tid 940643] [client 50.116.65.227:24462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VNRjVYcQxwGpYwZmfiQAAACU"]
[Mon Jul 20 06:31:49.848653 2026] [security2:error] [pid 940476:tid 940651] [client 34.24.137.199:54658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VNRjVYcQxwGpYwZmfjQAAAC0"]
[Mon Jul 20 06:31:49.891557 2026] [security2:error] [pid 940476:tid 940623] [client 14.225.17.146:56861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4VMxjVYcQxwGpYwZmfKgAAABE"], referer: http://dollpassionista.com/Old
[Mon Jul 20 06:31:50.005897 2026] [security2:error] [pid 940476:tid 940615] [client 34.73.38.214:53398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VNhjVYcQxwGpYwZmflAAAAAk"]
[Mon Jul 20 06:31:50.227134 2026] [security2:error] [pid 940476:tid 940646] [client 34.24.137.199:52183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VNhjVYcQxwGpYwZmfnwAAACg"]
[Mon Jul 20 06:31:50.295276 2026] [security2:error] [pid 940476:tid 940663] [client 74.249.245.134:52772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/mjq.php"] [unique_id "al4VNhjVYcQxwGpYwZmfpAAAADk"]
[Mon Jul 20 06:31:50.295387 2026] [security2:error] [pid 940476:tid 940663] [client 74.249.245.134:52772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/mjq.php"] [unique_id "al4VNhjVYcQxwGpYwZmfpAAAADk"]
[Mon Jul 20 06:31:50.328233 2026] [security2:error] [pid 935758:tid 935896] [client 14.225.17.146:55577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VNrcDxY_mIul-JSGgyAAAARA"], referer: http://sesamegreenbeans.com/Old
[Mon Jul 20 06:31:50.371001 2026] [security2:error] [pid 940476:tid 940680] [client 78.176.96.33:62814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VLxjVYcQxwGpYwZmeagAASgU"], referer: https://toddnielsen.com
[Mon Jul 20 06:31:50.447854 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:65147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNhjVYcQxwGpYwZmfowAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.564413 2026] [security2:error] [pid 940476:tid 940699] [client 103.125.179.95:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VNhjVYcQxwGpYwZmfrAAAAF0"]
[Mon Jul 20 06:31:50.564685 2026] [security2:error] [pid 940476:tid 940699] [client 103.125.179.95:49305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VNhjVYcQxwGpYwZmfrAAAAF0"]
[Mon Jul 20 06:31:50.608094 2026] [security2:error] [pid 935758:tid 935957] [client 34.24.137.199:56965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VNrcDxY_mIul-JSGg3AAAAU0"]
[Mon Jul 20 06:31:50.652305 2026] [proxy:error] [pid 935758:tid 936004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:50.652397 2026] [proxy_http:error] [pid 935758:tid 936004] [client 34.73.38.214:63969] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:50.653382 2026] [proxy:error] [pid 935758:tid 936004] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:50.653431 2026] [proxy_http:error] [pid 935758:tid 936004] [client 34.73.38.214:63969] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:50.678063 2026] [security2:error] [pid 940476:tid 940724] [client 57.141.18.60:27418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VMBjVYcQxwGpYwZmedAAAdhI"]
[Mon Jul 20 06:31:50.693604 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:65150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNhjVYcQxwGpYwZmfqAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.906298 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:65154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VNrcDxY_mIul-JSGg3wAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.922889 2026] [security2:error] [pid 940476:tid 940621] [client 14.225.17.146:59289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4VNhjVYcQxwGpYwZmfswAAAA8"], referer: https://dollpassionista.com/Old
[Mon Jul 20 06:31:50.926389 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNhjVYcQxwGpYwZmfuQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:50.926466 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VNhjVYcQxwGpYwZmfuQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:51.102888 2026] [security2:error] [pid 940476:tid 940549] [remote 167.71.218.184:48614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VNxjVYcQxwGpYwZmfwQAAHEg"]
[Mon Jul 20 06:31:51.203379 2026] [security2:error] [pid 935758:tid 936006] [client 104.234.53.53:51697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VN7cDxY_mIul-JSGg7wAAAX4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:51.375156 2026] [security2:error] [pid 940476:tid 940722] [client 34.24.137.199:52157] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VNxjVYcQxwGpYwZmfzQAAAHQ"]
[Mon Jul 20 06:31:51.377416 2026] [security2:error] [pid 940476:tid 940612] [client 14.225.17.146:59308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmfxQAAAAY"], referer: https://sesamegreenbeans.com/Old
[Mon Jul 20 06:31:51.497164 2026] [security2:error] [pid 940476:tid 940552] [remote 167.71.218.184:48614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VNxjVYcQxwGpYwZmf0AAAR0s"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:31:51.763502 2026] [security2:error] [pid 940476:tid 940673] [client 104.234.53.75:55023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VNxjVYcQxwGpYwZmf3gAAAEM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:51.831390 2026] [security2:error] [pid 940476:tid 940701] [client 14.225.17.146:53241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmf1QAAAF8"], referer: http://709fx.com/Old
[Mon Jul 20 06:31:51.850793 2026] [security2:error] [pid 940476:tid 940624] [client 14.225.17.146:59348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmf3AAAABI"], referer: http://alaraycreative.com/Old
[Mon Jul 20 06:31:51.912429 2026] [proxy:error] [pid 940476:tid 940711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:51.912512 2026] [proxy_http:error] [pid 940476:tid 940711] [client 34.73.38.214:61948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:51.913072 2026] [proxy:error] [pid 940476:tid 940711] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:51.913103 2026] [proxy_http:error] [pid 940476:tid 940711] [client 34.73.38.214:61948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:51.961114 2026] [security2:error] [pid 935758:tid 935958] [client 74.249.245.134:10955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/class-t.api.php"] [unique_id "al4VN7cDxY_mIul-JSGhDAAAAU4"]
[Mon Jul 20 06:31:51.961221 2026] [security2:error] [pid 935758:tid 935958] [client 74.249.245.134:10955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/class-t.api.php"] [unique_id "al4VN7cDxY_mIul-JSGhDAAAAU4"]
[Mon Jul 20 06:31:52.064800 2026] [security2:error] [pid 935758:tid 935925] [client 34.73.38.214:61873] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VOLcDxY_mIul-JSGhFQAAAS0"]
[Mon Jul 20 06:31:52.167475 2026] [security2:error] [pid 940476:tid 940690] [client 34.24.137.199:52161] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "casabella.aasgroup.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VOBjVYcQxwGpYwZmf9QAAAFQ"]
[Mon Jul 20 06:31:52.243699 2026] [security2:error] [pid 935758:tid 935956] [client 57.141.18.108:38436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VMbcDxY_mIul-JSGgJgABTHc"]
[Mon Jul 20 06:31:52.299862 2026] [security2:error] [pid 935758:tid 936008] [client 77.110.127.138:65161] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/contact-me/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4VOLcDxY_mIul-JSGhIgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.451264 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgBgAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.451373 2026] [security2:error] [pid 940476:tid 940704] [client 77.110.127.138:65166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgBgAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.606446 2026] [security2:error] [pid 940476:tid 940618] [client 77.110.127.138:65168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgCgAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.606583 2026] [security2:error] [pid 940476:tid 940618] [client 77.110.127.138:65168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOBjVYcQxwGpYwZmgCgAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:52.611320 2026] [proxy:error] [pid 935758:tid 935919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:52.611377 2026] [proxy_http:error] [pid 935758:tid 935919] [client 34.73.38.214:64406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:52.611936 2026] [proxy:error] [pid 935758:tid 935919] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:52.611962 2026] [proxy_http:error] [pid 935758:tid 935919] [client 34.73.38.214:64406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:52.622302 2026] [security2:error] [pid 935758:tid 935911] [client 197.186.66.42:58656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhLwAAAR8"]
[Mon Jul 20 06:31:52.622403 2026] [security2:error] [pid 935758:tid 935911] [client 197.186.66.42:58656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhLwAAAR8"]
[Mon Jul 20 06:31:52.827342 2026] [security2:error] [pid 940476:tid 940623] [client 14.225.17.146:57454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4VOBjVYcQxwGpYwZmgEgAAABE"], referer: http://betterbonddogtraining.com/Old
[Mon Jul 20 06:31:52.836697 2026] [security2:error] [pid 935758:tid 935898] [client 104.234.53.50:48667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VOLcDxY_mIul-JSGhNwAAARI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:52.934091 2026] [security2:error] [pid 935758:tid 935963] [client 15.237.142.234:23356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhOQAAAVM"]
[Mon Jul 20 06:31:52.934189 2026] [security2:error] [pid 935758:tid 935963] [client 15.237.142.234:23356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4VOLcDxY_mIul-JSGhOQAAAVM"]
[Mon Jul 20 06:31:52.987418 2026] [security2:error] [pid 940476:tid 940675] [client 112.208.70.94:43694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VOBjVYcQxwGpYwZmgIQAAAEU"]
[Mon Jul 20 06:31:52.987547 2026] [security2:error] [pid 940476:tid 940675] [client 112.208.70.94:43694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VOBjVYcQxwGpYwZmgIQAAAEU"]
[Mon Jul 20 06:31:53.152171 2026] [security2:error] [pid 935758:tid 935942] [client 14.225.17.146:58999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4VOLcDxY_mIul-JSGhPAAAAT4"], referer: http://bbwipartnerconference.com/Old
[Mon Jul 20 06:31:53.177349 2026] [proxy:error] [pid 935758:tid 935984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:53.177397 2026] [proxy_http:error] [pid 935758:tid 935984] [client 34.73.38.214:58867] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:53.177961 2026] [proxy:error] [pid 935758:tid 935984] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:31:53.177994 2026] [proxy_http:error] [pid 935758:tid 935984] [client 34.73.38.214:58867] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:31:53.316743 2026] [security2:error] [pid 940476:tid 940658] [client 106.219.188.178:10276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgKQAAADQ"]
[Mon Jul 20 06:31:53.316909 2026] [security2:error] [pid 940476:tid 940658] [client 106.219.188.178:10276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgKQAAADQ"]
[Mon Jul 20 06:31:53.353366 2026] [security2:error] [pid 935758:tid 936000] [client 34.73.38.214:63071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VObcDxY_mIul-JSGhTgAAAXg"]
[Mon Jul 20 06:31:53.359415 2026] [security2:error] [pid 940476:tid 940651] [client 14.225.17.146:57972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4VORjVYcQxwGpYwZmgJwAAAC0"], referer: http://alexsandbergmusic.com/Old
[Mon Jul 20 06:31:53.436885 2026] [security2:error] [pid 935758:tid 935932] [client 45.157.112.60:36679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VObcDxY_mIul-JSGhUQAAATQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:31:53.701346 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VORjVYcQxwGpYwZmgNAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:53.702107 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:65173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VORjVYcQxwGpYwZmgNAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:53.837884 2026] [security2:error] [pid 940476:tid 940721] [client 171.61.165.146:23232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgOgAAAHM"]
[Mon Jul 20 06:31:53.838023 2026] [security2:error] [pid 940476:tid 940721] [client 171.61.165.146:23232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VORjVYcQxwGpYwZmgOgAAAHM"]
[Mon Jul 20 06:31:53.884512 2026] [security2:error] [pid 935758:tid 935954] [client 34.73.38.214:56604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VObcDxY_mIul-JSGhagAAAUo"]
[Mon Jul 20 06:31:53.978408 2026] [security2:error] [pid 935758:tid 935938] [client 14.225.17.146:57408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4VObcDxY_mIul-JSGhaAAAATo"]
[Mon Jul 20 06:31:53.982798 2026] [security2:error] [pid 940476:tid 940713] [client 34.73.38.214:56403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VORjVYcQxwGpYwZmgQgAAAGs"]
[Mon Jul 20 06:31:54.356443 2026] [security2:error] [pid 940476:tid 940708] [client 82.102.27.163:35234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVQAAAGY"]
[Mon Jul 20 06:31:54.356561 2026] [security2:error] [pid 940476:tid 940708] [client 82.102.27.163:35234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVQAAAGY"]
[Mon Jul 20 06:31:54.374758 2026] [security2:error] [pid 940476:tid 940644] [client 223.185.13.213:20529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVgAAACY"]
[Mon Jul 20 06:31:54.374845 2026] [security2:error] [pid 940476:tid 940644] [client 223.185.13.213:20529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VOhjVYcQxwGpYwZmgVgAAACY"]
[Mon Jul 20 06:31:54.617960 2026] [security2:error] [pid 940476:tid 940667] [client 34.73.38.214:50875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VOhjVYcQxwGpYwZmgXQAAAD0"]
[Mon Jul 20 06:31:54.714174 2026] [security2:error] [pid 940476:tid 940588] [remote 47.86.33.52:17168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4VOhjVYcQxwGpYwZmgbAAAPG8"]
[Mon Jul 20 06:31:54.985328 2026] [security2:error] [pid 940476:tid 940625] [client 34.73.38.214:50348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VOhjVYcQxwGpYwZmgfgAAABM"]
[Mon Jul 20 06:31:55.110053 2026] [security2:error] [pid 935758:tid 935968] [client 164.52.11.194:41806] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhjwAAAVg"]
[Mon Jul 20 06:31:55.110729 2026] [security2:error] [pid 935758:tid 935968] [client 164.52.11.194:41806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhjwAAAVg"]
[Mon Jul 20 06:31:55.110775 2026] [security2:error] [pid 935758:tid 935968] [client 164.52.11.194:41806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhjwAAAVg"]
[Mon Jul 20 06:31:55.123437 2026] [security2:error] [pid 940476:tid 940659] [client 57.141.18.42:54494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNBjVYcQxwGpYwZmfXQAANTo"]
[Mon Jul 20 06:31:55.435814 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:65184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/contact-me/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4VOxjVYcQxwGpYwZmglAAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.450269 2026] [security2:error] [pid 940476:tid 940676] [client 114.119.131.253:34583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elevator-data.com"] [uri "/robots.txt"] [unique_id "al4VOxjVYcQxwGpYwZmglQAAAEY"], referer: http://elevator-data.com/robots.txt
[Mon Jul 20 06:31:55.515648 2026] [security2:error] [pid 940476:tid 940643] [client 34.73.38.214:56632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VOxjVYcQxwGpYwZmgmAAAACU"]
[Mon Jul 20 06:31:55.540783 2026] [security2:error] [pid 940476:tid 940715] [client 104.234.53.75:22739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VOxjVYcQxwGpYwZmgmgAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:31:55.546417 2026] [security2:error] [pid 940476:tid 940621] [client 74.249.245.134:10965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/plugins.php"] [unique_id "al4VOxjVYcQxwGpYwZmgmwAAAA8"]
[Mon Jul 20 06:31:55.546501 2026] [security2:error] [pid 940476:tid 940621] [client 74.249.245.134:10965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/plugins.php"] [unique_id "al4VOxjVYcQxwGpYwZmgmwAAAA8"]
[Mon Jul 20 06:31:55.587963 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:65186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhoQAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.588065 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:65186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VO7cDxY_mIul-JSGhoQAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.738367 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:65187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOxjVYcQxwGpYwZmgogAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.738469 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:65187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VOxjVYcQxwGpYwZmgogAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:55.791081 2026] [security2:error] [pid 935758:tid 935895] [client 57.141.18.75:60946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNbcDxY_mIul-JSGgvwABD0k"]
[Mon Jul 20 06:31:55.865946 2026] [security2:error] [pid 940476:tid 940733] [client 34.73.38.214:50347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VOxjVYcQxwGpYwZmgqAAAAH8"]
[Mon Jul 20 06:31:55.911445 2026] [security2:error] [pid 940476:tid 940481] [remote 5.161.225.162:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VOxjVYcQxwGpYwZmgrQAAawQ"]
[Mon Jul 20 06:31:56.224166 2026] [security2:error] [pid 940476:tid 940601] [remote 5.161.225.162:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VPBjVYcQxwGpYwZmgvAAAOnw"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:31:56.239308 2026] [security2:error] [pid 940476:tid 940514] [remote 47.86.33.52:17168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4VPBjVYcQxwGpYwZmgvQAASSU"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:31:56.313182 2026] [security2:error] [pid 940476:tid 940614] [client 34.73.38.214:54764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VPBjVYcQxwGpYwZmgwQAAAAg"]
[Mon Jul 20 06:31:56.560552 2026] [security2:error] [pid 935758:tid 935762] [remote 152.228.213.32:46466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VPLcDxY_mIul-JSGhzQABQwE"]
[Mon Jul 20 06:31:56.560710 2026] [security2:error] [pid 935758:tid 935947] [client 152.228.213.32:46466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VPLcDxY_mIul-JSGhzQABQwE"]
[Mon Jul 20 06:31:56.670255 2026] [security2:error] [pid 935758:tid 935965] [client 57.141.18.122:30870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNrcDxY_mIul-JSGg4gABVSc"]
[Mon Jul 20 06:31:56.872795 2026] [security2:error] [pid 940476:tid 940655] [client 34.73.38.214:53769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VPBjVYcQxwGpYwZmg2AAAADE"]
[Mon Jul 20 06:31:56.882797 2026] [security2:error] [pid 940476:tid 940678] [client 172.232.181.107:16162] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VPBjVYcQxwGpYwZmg2QAAAEg"]
[Mon Jul 20 06:31:56.998274 2026] [security2:error] [pid 940476:tid 940702] [client 171.60.139.123:58239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VPBjVYcQxwGpYwZmg5AAAAGA"]
[Mon Jul 20 06:31:56.998401 2026] [security2:error] [pid 940476:tid 940702] [client 171.60.139.123:58239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VPBjVYcQxwGpYwZmg5AAAAGA"]
[Mon Jul 20 06:31:57.010512 2026] [security2:error] [pid 940476:tid 940489] [remote 20.153.140.50:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4VPBjVYcQxwGpYwZmg4wAAMww"]
[Mon Jul 20 06:31:57.015883 2026] [security2:error] [pid 940476:tid 940710] [client 57.141.18.22:48268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmfxAAAaEI"]
[Mon Jul 20 06:31:57.097858 2026] [security2:error] [pid 940476:tid 940728] [client 114.119.133.35:60713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "windowtx.com"] [uri "/news/"] [unique_id "al4VPRjVYcQxwGpYwZmg5wAAAHo"], referer: https://www.1stoncology.com/blog/category/uncategorized/page/10703/
[Mon Jul 20 06:31:57.201429 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:65202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmg9wAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.201523 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:65202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmg9wAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.254854 2026] [security2:error] [pid 940476:tid 940716] [client 103.141.108.143:64806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.108.141.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmg-wAAAG4"]
[Mon Jul 20 06:31:57.255374 2026] [security2:error] [pid 940476:tid 940716] [client 103.141.108.143:64806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmg-wAAAG4"]
[Mon Jul 20 06:31:57.280835 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:65161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPbcDxY_mIul-JSGh5gAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.280969 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:65161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPbcDxY_mIul-JSGh5gAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.424161 2026] [security2:error] [pid 940476:tid 940700] [client 39.48.81.23:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAgAAAF4"]
[Mon Jul 20 06:31:57.424279 2026] [security2:error] [pid 940476:tid 940700] [client 39.48.81.23:64641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAgAAAF4"]
[Mon Jul 20 06:31:57.424593 2026] [security2:error] [pid 940476:tid 940486] [remote 20.153.140.50:39616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAQAAKwk"], referer: https://fansarogroup.com/wp-login.php
[Mon Jul 20 06:31:57.456262 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.456383 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhAwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.580409 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VPRjVYcQxwGpYwZmg_QAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.635871 2026] [security2:error] [pid 940476:tid 940640] [client 57.141.18.0:36808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VNxjVYcQxwGpYwZmf6QAAIkw"]
[Mon Jul 20 06:31:57.669909 2026] [security2:error] [pid 935758:tid 935857] [remote 154.66.198.148:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VPbcDxY_mIul-JSGh9wABYGA"]
[Mon Jul 20 06:31:57.765535 2026] [security2:error] [pid 935758:tid 935963] [client 45.116.69.230:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VPbcDxY_mIul-JSGh-wAAAVM"]
[Mon Jul 20 06:31:57.765671 2026] [security2:error] [pid 935758:tid 935963] [client 45.116.69.230:50778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VPbcDxY_mIul-JSGh-wAAAVM"]
[Mon Jul 20 06:31:57.855167 2026] [security2:error] [pid 940476:tid 940694] [client 34.73.38.214:62123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VPRjVYcQxwGpYwZmhGAAAAFg"]
[Mon Jul 20 06:31:57.956857 2026] [security2:error] [pid 940476:tid 940615] [client 77.110.127.138:65208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhHAAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:57.956955 2026] [security2:error] [pid 940476:tid 940615] [client 77.110.127.138:65208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPRjVYcQxwGpYwZmhHAAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.199287 2026] [security2:error] [pid 935758:tid 935880] [remote 154.66.198.148:28246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VPrcDxY_mIul-JSGiCwABf3c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:31:58.234891 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:65181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhKwAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.235047 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:65181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhKwAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.259195 2026] [security2:error] [pid 940476:tid 940706] [client 14.225.17.146:59375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4VPRjVYcQxwGpYwZmg-gAAAGQ"], referer: http://ancestralidadytrance.space/Old
[Mon Jul 20 06:31:58.375940 2026] [security2:error] [pid 935758:tid 935926] [client 57.141.18.5:56096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOLcDxY_mIul-JSGhKwABLgI"]
[Mon Jul 20 06:31:58.390136 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOgAAABo"]
[Mon Jul 20 06:31:58.390232 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOgAAABo"]
[Mon Jul 20 06:31:58.392130 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:65214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.392275 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:65214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhOwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.576718 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:65217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhRAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.576844 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:65217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPhjVYcQxwGpYwZmhRAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:58.626214 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPrcDxY_mIul-JSGiFwAAAUU"]
[Mon Jul 20 06:31:58.626308 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPrcDxY_mIul-JSGiFwAAAUU"]
[Mon Jul 20 06:31:58.691585 2026] [security2:error] [pid 940476:tid 940708] [client 34.73.38.214:56649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VPhjVYcQxwGpYwZmhSwAAAGY"]
[Mon Jul 20 06:31:58.754803 2026] [security2:error] [pid 940476:tid 940609] [client 57.141.18.43:59310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOBjVYcQxwGpYwZmgGwAAA1w"]
[Mon Jul 20 06:31:58.811539 2026] [security2:error] [pid 940476:tid 940641] [client 34.73.38.214:54453] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.latiendadejorge.com.gt"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VPhjVYcQxwGpYwZmhUAAAACM"]
[Mon Jul 20 06:31:58.849100 2026] [security2:error] [pid 940476:tid 940519] [remote 154.61.75.100:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4VPhjVYcQxwGpYwZmhUQAAcyo"]
[Mon Jul 20 06:31:59.008870 2026] [security2:error] [pid 935758:tid 936006] [client 74.249.245.134:10969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/jp.php"] [unique_id "al4VP7cDxY_mIul-JSGiLwAAAX4"]
[Mon Jul 20 06:31:59.008994 2026] [security2:error] [pid 935758:tid 936006] [client 74.249.245.134:10969] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/jp.php"] [unique_id "al4VP7cDxY_mIul-JSGiLwAAAX4"]
[Mon Jul 20 06:31:59.042241 2026] [security2:error] [pid 940476:tid 940633] [client 34.73.38.214:57151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VPxjVYcQxwGpYwZmhWgAAABs"]
[Mon Jul 20 06:31:59.265349 2026] [security2:error] [pid 940476:tid 940692] [client 50.116.65.227:43982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VPxjVYcQxwGpYwZmhYgAAAFY"]
[Mon Jul 20 06:31:59.275210 2026] [security2:error] [pid 940476:tid 940632] [client 50.116.65.227:43988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VPxjVYcQxwGpYwZmhYwAAABo"]
[Mon Jul 20 06:31:59.333141 2026] [security2:error] [pid 940476:tid 940522] [remote 154.61.75.100:37314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4VPxjVYcQxwGpYwZmhZAAAYi0"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:31:59.389720 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:65220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VPxjVYcQxwGpYwZmhXgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:59.605973 2026] [security2:error] [pid 940476:tid 940638] [client 57.141.18.101:21894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VORjVYcQxwGpYwZmgMQAAIFo"]
[Mon Jul 20 06:31:59.803119 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VPxjVYcQxwGpYwZmhcwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:59.949165 2026] [security2:error] [pid 940476:tid 940697] [client 34.73.38.214:61973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VPxjVYcQxwGpYwZmhfAAAAFs"]
[Mon Jul 20 06:31:59.978633 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPxjVYcQxwGpYwZmhfQAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:31:59.978763 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:65223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VPxjVYcQxwGpYwZmhfQAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.120311 2026] [security2:error] [pid 935758:tid 936009] [client 57.141.18.13:51876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOrcDxY_mIul-JSGhegABgUg"]
[Mon Jul 20 06:32:00.432951 2026] [security2:error] [pid 940476:tid 940610] [client 34.74.185.202:59599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VQBjVYcQxwGpYwZmhlAAAAAQ"]
[Mon Jul 20 06:32:00.441397 2026] [security2:error] [pid 940476:tid 940676] [client 45.131.194.10:42881] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "generationloveproject.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4VQBjVYcQxwGpYwZmhlgAAAEY"]
[Mon Jul 20 06:32:00.537943 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:65206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhmgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.538121 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:65206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhmgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.646785 2026] [security2:error] [pid 935758:tid 935930] [client 14.225.17.146:55886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4VP7cDxY_mIul-JSGiQQAAATI"], referer: http://intelligentengineeringsolutions.com/Old
[Mon Jul 20 06:32:00.759378 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQLcDxY_mIul-JSGiagAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.759469 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:65229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQLcDxY_mIul-JSGiagAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:00.898537 2026] [security2:error] [pid 940476:tid 940650] [client 82.102.27.163:57490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrgAAACw"]
[Mon Jul 20 06:32:00.898632 2026] [security2:error] [pid 940476:tid 940650] [client 82.102.27.163:57490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrgAAACw"]
[Mon Jul 20 06:32:00.918527 2026] [security2:error] [pid 940476:tid 940629] [client 164.52.11.194:43530] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrwAAABc"]
[Mon Jul 20 06:32:00.918684 2026] [security2:error] [pid 940476:tid 940629] [client 164.52.11.194:43530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrwAAABc"]
[Mon Jul 20 06:32:00.918732 2026] [security2:error] [pid 940476:tid 940629] [client 164.52.11.194:43530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VQBjVYcQxwGpYwZmhrwAAABc"]
[Mon Jul 20 06:32:00.985143 2026] [security2:error] [pid 940476:tid 940674] [client 172.232.181.107:20174] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VQBjVYcQxwGpYwZmhtQAAAEQ"]
[Mon Jul 20 06:32:01.186990 2026] [security2:error] [pid 940476:tid 940618] [client 103.125.179.95:49764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmhxAAAAAw"]
[Mon Jul 20 06:32:01.187604 2026] [security2:error] [pid 940476:tid 940618] [client 103.125.179.95:49764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmhxAAAAAw"]
[Mon Jul 20 06:32:01.338528 2026] [security2:error] [pid 935758:tid 935968] [client 14.225.17.146:58830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4VQbcDxY_mIul-JSGicAAAAVg"], referer: http://hilltopnurseryinc.com/Old
[Mon Jul 20 06:32:01.389311 2026] [security2:error] [pid 940476:tid 940678] [client 34.74.185.202:52805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VQRjVYcQxwGpYwZmhzAAAAEg"]
[Mon Jul 20 06:32:01.468389 2026] [security2:error] [pid 940476:tid 940717] [client 104.234.53.58:38491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VQRjVYcQxwGpYwZmhzQAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:01.585143 2026] [security2:error] [pid 935758:tid 935971] [client 34.73.38.214:63401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VQbcDxY_mIul-JSGihAAAAVs"]
[Mon Jul 20 06:32:01.697974 2026] [security2:error] [pid 935758:tid 935837] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VQbcDxY_mIul-JSGiiAABJkw"]
[Mon Jul 20 06:32:01.713630 2026] [security2:error] [pid 940476:tid 940656] [client 57.141.18.69:26668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VOxjVYcQxwGpYwZmgqQAAMiM"]
[Mon Jul 20 06:32:01.847103 2026] [security2:error] [pid 940476:tid 940714] [client 106.219.188.178:47756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmh1wAAAGw"]
[Mon Jul 20 06:32:01.848585 2026] [security2:error] [pid 940476:tid 940714] [client 106.219.188.178:47756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VQRjVYcQxwGpYwZmh1wAAAGw"]
[Mon Jul 20 06:32:02.155626 2026] [security2:error] [pid 935758:tid 935959] [client 34.74.185.202:50852] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VQrcDxY_mIul-JSGinQAAAU8"]
[Mon Jul 20 06:32:02.202214 2026] [security2:error] [pid 935758:tid 935987] [client 104.207.58.248:41203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VQrcDxY_mIul-JSGinwAAAWs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:02.599019 2026] [security2:error] [pid 940476:tid 940687] [client 74.249.245.134:10953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/pu9.php"] [unique_id "al4VQhjVYcQxwGpYwZmh8AAAAFE"]
[Mon Jul 20 06:32:02.599118 2026] [security2:error] [pid 940476:tid 940687] [client 74.249.245.134:10953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/pu9.php"] [unique_id "al4VQhjVYcQxwGpYwZmh8AAAAFE"]
[Mon Jul 20 06:32:02.794400 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VQrcDxY_mIul-JSGirwAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:02.800571 2026] [security2:error] [pid 940476:tid 940729] [client 34.73.38.214:54028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VQhjVYcQxwGpYwZmh-wAAAHs"]
[Mon Jul 20 06:32:02.839916 2026] [security2:error] [pid 940476:tid 940647] [client 104.28.156.112:13519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.156.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmh_QAAACk"]
[Mon Jul 20 06:32:02.850378 2026] [security2:error] [pid 940476:tid 940651] [client 65.111.26.68:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmh_wAAAC0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:02.861904 2026] [security2:error] [pid 940476:tid 940541] [remote 202.51.202.242:44632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmiAAAAC0A"]
[Mon Jul 20 06:32:02.869050 2026] [security2:error] [pid 940476:tid 940646] [client 104.28.156.112:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.156.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kgsnsteel.com"] [uri "/wp-login.php"] [unique_id "al4VQhjVYcQxwGpYwZmiBAAAACg"]
[Mon Jul 20 06:32:02.924352 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:56094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4VQrcDxY_mIul-JSGiqgAAAWo"]
[Mon Jul 20 06:32:02.984540 2026] [security2:error] [pid 940476:tid 940690] [client 34.74.185.202:59064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VQhjVYcQxwGpYwZmiCwAAAFQ"]
[Mon Jul 20 06:32:03.033054 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiDQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.033168 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiDQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.247391 2026] [security2:error] [pid 935758:tid 935783] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VQ7cDxY_mIul-JSGixAABeBY"]
[Mon Jul 20 06:32:03.357102 2026] [security2:error] [pid 940476:tid 940702] [client 177.215.119.206:59192] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4VQxjVYcQxwGpYwZmiHQAAAGA"]
[Mon Jul 20 06:32:03.383700 2026] [security2:error] [pid 935758:tid 935897] [client 14.225.17.146:58881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4VQbcDxY_mIul-JSGilwAAARE"], referer: http://balticsteelmgmt.com/Old
[Mon Jul 20 06:32:03.446530 2026] [security2:error] [pid 940476:tid 940640] [client 34.73.38.214:64062] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VQxjVYcQxwGpYwZmiIwAAACI"]
[Mon Jul 20 06:32:03.450058 2026] [security2:error] [pid 935758:tid 935793] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VQ7cDxY_mIul-JSGi0gABJCA"]
[Mon Jul 20 06:32:03.481771 2026] [security2:error] [pid 935758:tid 935946] [client 45.3.45.198:9715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VQ7cDxY_mIul-JSGi0AAAAUI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:03.501845 2026] [security2:error] [pid 940476:tid 940682] [client 57.141.18.48:51428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VPRjVYcQxwGpYwZmhCAAATA4"]
[Mon Jul 20 06:32:03.621300 2026] [security2:error] [pid 935758:tid 935944] [client 197.186.66.42:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VQ7cDxY_mIul-JSGi2AAAAUA"]
[Mon Jul 20 06:32:03.621415 2026] [security2:error] [pid 935758:tid 935944] [client 197.186.66.42:59147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VQ7cDxY_mIul-JSGi2AAAAUA"]
[Mon Jul 20 06:32:03.670072 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiLwAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.670183 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQxjVYcQxwGpYwZmiLwAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.858311 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:65256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi4QAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.858435 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:65256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi4QAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.910360 2026] [security2:error] [pid 935758:tid 935972] [client 77.110.127.138:65194] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VQ7cDxY_mIul-JSGi5QAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.971534 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi5wAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.971685 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:65257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VQ7cDxY_mIul-JSGi5wAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:03.989797 2026] [security2:error] [pid 940476:tid 940552] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VQxjVYcQxwGpYwZmiOgAAH0s"]
[Mon Jul 20 06:32:04.009288 2026] [security2:error] [pid 940476:tid 940613] [client 103.87.64.56:36200] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4VRBjVYcQxwGpYwZmiOwAAAAc"]
[Mon Jul 20 06:32:04.044788 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiPAAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.044903 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiPAAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.060132 2026] [security2:error] [pid 940476:tid 940719] [client 91.51.137.234:51168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VPhjVYcQxwGpYwZmhQwAAcSY"], referer: https://toddnielsen.com
[Mon Jul 20 06:32:04.065909 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi7AAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.066011 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi7AAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.218453 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQAAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.218554 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQAAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.219148 2026] [security2:error] [pid 935758:tid 936008] [client 34.74.185.202:55854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VRLcDxY_mIul-JSGi8QAAAYA"]
[Mon Jul 20 06:32:04.288837 2026] [security2:error] [pid 940476:tid 940660] [client 77.110.127.138:65264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQgAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.288961 2026] [security2:error] [pid 940476:tid 940660] [client 77.110.127.138:65264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiQgAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.341070 2026] [security2:error] [pid 935758:tid 935778] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRLcDxY_mIul-JSGi-QABXhE"]
[Mon Jul 20 06:32:04.424513 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi_AAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.424602 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:65224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRLcDxY_mIul-JSGi_AAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.444896 2026] [security2:error] [pid 935758:tid 935950] [client 69.160.102.45:36410] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4VRLcDxY_mIul-JSGi_QAAAUY"]
[Mon Jul 20 06:32:04.474830 2026] [security2:error] [pid 940476:tid 940712] [client 54.166.194.245:48160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.194.166.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VRBjVYcQxwGpYwZmiSQAAAGo"]
[Mon Jul 20 06:32:04.584353 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:65266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiVgAAAH0"]
[Mon Jul 20 06:32:04.584449 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:65266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiVgAAAH0"]
[Mon Jul 20 06:32:04.621204 2026] [security2:error] [pid 940476:tid 940611] [client 34.73.38.214:56951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VRBjVYcQxwGpYwZmiWAAAAAU"]
[Mon Jul 20 06:32:04.639167 2026] [security2:error] [pid 940476:tid 940650] [client 74.249.245.134:10977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/error.php"] [unique_id "al4VRBjVYcQxwGpYwZmiWgAAACw"]
[Mon Jul 20 06:32:04.639264 2026] [security2:error] [pid 940476:tid 940650] [client 74.249.245.134:10977] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/error.php"] [unique_id "al4VRBjVYcQxwGpYwZmiWgAAACw"]
[Mon Jul 20 06:32:04.650385 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:65268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiXAAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.650503 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:65268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiXAAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.656236 2026] [security2:error] [pid 940476:tid 940547] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRBjVYcQxwGpYwZmiXQAAKEY"]
[Mon Jul 20 06:32:04.677967 2026] [security2:error] [pid 940476:tid 940693] [client 136.158.62.28:26840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4VRBjVYcQxwGpYwZmiXgAAAFc"]
[Mon Jul 20 06:32:04.696153 2026] [security2:error] [pid 940476:tid 940609] [client 34.74.185.202:59358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VRBjVYcQxwGpYwZmiYQAAAAM"]
[Mon Jul 20 06:32:04.704608 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:65236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiZAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.704738 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:65236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiZAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.708037 2026] [security2:error] [pid 935758:tid 935894] [client 78.182.129.136:2726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4VRLcDxY_mIul-JSGjCgAAAQ4"]
[Mon Jul 20 06:32:04.748209 2026] [security2:error] [pid 935758:tid 935912] [client 223.185.13.213:4240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VRLcDxY_mIul-JSGjCwAAASA"]
[Mon Jul 20 06:32:04.748383 2026] [security2:error] [pid 935758:tid 935912] [client 223.185.13.213:4240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VRLcDxY_mIul-JSGjCwAAASA"]
[Mon Jul 20 06:32:04.749071 2026] [security2:error] [pid 940476:tid 940616] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VRBjVYcQxwGpYwZmiVQAAAAo"]
[Mon Jul 20 06:32:04.757290 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiawAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.757401 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:65238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmiawAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.798504 2026] [security2:error] [pid 940476:tid 940711] [client 57.141.18.77:40994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VPxjVYcQxwGpYwZmhXwAAaSs"]
[Mon Jul 20 06:32:04.798875 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmibwAAACo"]
[Mon Jul 20 06:32:04.798974 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmibwAAACo"]
[Mon Jul 20 06:32:04.799139 2026] [security2:error] [pid 940476:tid 940637] [client 52.207.32.99:26306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VRBjVYcQxwGpYwZmibAAAAB8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:04.808490 2026] [security2:error] [pid 935758:tid 935900] [client 199.27.99.213:43328] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.eot"] [unique_id "al4VRLcDxY_mIul-JSGjDgAAARQ"]
[Mon Jul 20 06:32:04.811683 2026] [security2:error] [pid 935758:tid 935978] [client 200.112.80.245:36856] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4VRLcDxY_mIul-JSGjDwAAAWI"]
[Mon Jul 20 06:32:04.822009 2026] [security2:error] [pid 940476:tid 940715] [client 171.61.165.146:25453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VRBjVYcQxwGpYwZmicAAAAG0"]
[Mon Jul 20 06:32:04.822134 2026] [security2:error] [pid 940476:tid 940715] [client 171.61.165.146:25453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VRBjVYcQxwGpYwZmicAAAAG0"]
[Mon Jul 20 06:32:04.879514 2026] [security2:error] [pid 935758:tid 935969] [client 45.165.207.57:42742] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4VRLcDxY_mIul-JSGjEQAAAVk"]
[Mon Jul 20 06:32:04.882514 2026] [security2:error] [pid 935758:tid 935913] [client 172.232.181.107:20180] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VRLcDxY_mIul-JSGjEwAAASE"]
[Mon Jul 20 06:32:04.909980 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmicgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.910092 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRBjVYcQxwGpYwZmicgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:04.972652 2026] [security2:error] [pid 935758:tid 935933] [client 181.163.102.84:39316] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4VRLcDxY_mIul-JSGjGQAAATU"]
[Mon Jul 20 06:32:04.988418 2026] [security2:error] [pid 935758:tid 935930] [client 121.121.56.114:3664] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4VRLcDxY_mIul-JSGjGgAAATI"]
[Mon Jul 20 06:32:05.102573 2026] [security2:error] [pid 940476:tid 940664] [client 203.211.104.148:8840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4VRRjVYcQxwGpYwZmieAAAADo"]
[Mon Jul 20 06:32:05.211930 2026] [security2:error] [pid 940476:tid 940713] [client 70.29.144.67:36424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4VRRjVYcQxwGpYwZmigAAAAGs"]
[Mon Jul 20 06:32:05.327604 2026] [security2:error] [pid 935758:tid 936003] [client 37.202.72.176:62457] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjJgAAAXs"]
[Mon Jul 20 06:32:05.328292 2026] [security2:error] [pid 940476:tid 940685] [client 14.225.17.146:52996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4VRRjVYcQxwGpYwZmifAAAAE8"], referer: http://kromosenergy.com/Old
[Mon Jul 20 06:32:05.336308 2026] [security2:error] [pid 940476:tid 940661] [client 141.126.4.26:48030] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf"] [unique_id "al4VRRjVYcQxwGpYwZmihgAAADc"]
[Mon Jul 20 06:32:05.362466 2026] [security2:error] [pid 940476:tid 940622] [client 92.63.112.224:35026] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmihwAAABA"]
[Mon Jul 20 06:32:05.362914 2026] [security2:error] [pid 940476:tid 940499] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRRjVYcQxwGpYwZmiiAAAKBY"]
[Mon Jul 20 06:32:05.393183 2026] [security2:error] [pid 935758:tid 935957] [client 144.91.117.173:57258] ModSecurity: Warning. Matched phrase "Firefox/7.0" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "box5033.bluehost.com"] [uri "/"] [unique_id "al4VRbcDxY_mIul-JSGjKAAAAU0"]
[Mon Jul 20 06:32:05.395531 2026] [security2:error] [pid 940476:tid 940642] [client 177.53.145.13:25569] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmiigAAACQ"]
[Mon Jul 20 06:32:05.398514 2026] [security2:error] [pid 935758:tid 936004] [client 112.203.171.97:62158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4VRbcDxY_mIul-JSGjKQAAAXw"]
[Mon Jul 20 06:32:05.404801 2026] [security2:error] [pid 940476:tid 940641] [client 14.225.17.146:54249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4VRRjVYcQxwGpYwZmifgAAACM"]
[Mon Jul 20 06:32:05.418663 2026] [security2:error] [pid 940476:tid 940690] [client 88.181.188.87:34546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmiiwAAAFQ"]
[Mon Jul 20 06:32:05.441059 2026] [security2:error] [pid 940476:tid 940659] [client 109.243.71.120:14520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4VRRjVYcQxwGpYwZmijAAAADU"]
[Mon Jul 20 06:32:05.485871 2026] [security2:error] [pid 940476:tid 940669] [client 49.151.135.136:11691] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.eot"] [unique_id "al4VRRjVYcQxwGpYwZmikgAAAD8"]
[Mon Jul 20 06:32:05.505871 2026] [security2:error] [pid 940476:tid 940677] [client 51.36.227.236:1710] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmilAAAAEc"]
[Mon Jul 20 06:32:05.507472 2026] [security2:error] [pid 940476:tid 940663] [client 189.110.175.226:38078] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4VRRjVYcQxwGpYwZmilQAAADk"]
[Mon Jul 20 06:32:05.508550 2026] [security2:error] [pid 940476:tid 940676] [client 186.189.89.122:31700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4VRRjVYcQxwGpYwZmilgAAAEY"]
[Mon Jul 20 06:32:05.553802 2026] [security2:error] [pid 940476:tid 940665] [client 45.169.175.159:41933] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmimAAAADs"]
[Mon Jul 20 06:32:05.573548 2026] [security2:error] [pid 940476:tid 940653] [client 80.30.118.242:51864] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4VRRjVYcQxwGpYwZmimQAAAC8"]
[Mon Jul 20 06:32:05.598214 2026] [security2:error] [pid 935758:tid 935903] [client 186.194.20.193:2160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4VRbcDxY_mIul-JSGjMQAAARc"]
[Mon Jul 20 06:32:05.635112 2026] [security2:error] [pid 940476:tid 940683] [client 84.238.252.86:35272] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4VRRjVYcQxwGpYwZmimgAAAE0"]
[Mon Jul 20 06:32:05.655547 2026] [security2:error] [pid 940476:tid 940639] [client 23.17.128.7:49092] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4VRRjVYcQxwGpYwZminQAAACE"]
[Mon Jul 20 06:32:05.679680 2026] [security2:error] [pid 940476:tid 940546] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRRjVYcQxwGpYwZmioAAAYUU"]
[Mon Jul 20 06:32:05.686480 2026] [security2:error] [pid 940476:tid 940607] [client 131.0.198.61:55624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4VRRjVYcQxwGpYwZmioQAAAAE"]
[Mon Jul 20 06:32:05.723757 2026] [security2:error] [pid 935758:tid 935939] [client 125.99.232.55:41132] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjNQAAATs"]
[Mon Jul 20 06:32:05.747210 2026] [security2:error] [pid 940476:tid 940729] [client 188.3.178.90:15422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff"] [unique_id "al4VRRjVYcQxwGpYwZmipgAAAHs"]
[Mon Jul 20 06:32:05.772058 2026] [security2:error] [pid 935758:tid 935924] [client 103.148.213.80:37368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjNwAAASw"]
[Mon Jul 20 06:32:05.845539 2026] [security2:error] [pid 935758:tid 936009] [client 45.124.5.137:35296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4VRbcDxY_mIul-JSGjOwAAAYE"]
[Mon Jul 20 06:32:05.845539 2026] [security2:error] [pid 940476:tid 940706] [client 80.94.250.34:51476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4VRRjVYcQxwGpYwZmiswAAAGQ"]
[Mon Jul 20 06:32:05.877506 2026] [security2:error] [pid 935758:tid 936002] [client 171.229.249.99:56234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4VRbcDxY_mIul-JSGjPQAAAXo"]
[Mon Jul 20 06:32:05.896779 2026] [security2:error] [pid 940476:tid 940570] [remote 160.187.68.132:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VRRjVYcQxwGpYwZmitAAAb10"]
[Mon Jul 20 06:32:05.990990 2026] [security2:error] [pid 935758:tid 935943] [client 103.190.40.137:14046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4VRbcDxY_mIul-JSGjRQAAAT8"]
[Mon Jul 20 06:32:05.991323 2026] [security2:error] [pid 935758:tid 935959] [client 177.21.78.46:8260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.woff"] [unique_id "al4VRbcDxY_mIul-JSGjRAAAAU8"]
[Mon Jul 20 06:32:06.009293 2026] [security2:error] [pid 935758:tid 935886] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VRrcDxY_mIul-JSGjRwABXn0"]
[Mon Jul 20 06:32:06.015954 2026] [security2:error] [pid 935758:tid 935932] [client 186.189.90.48:23784] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff"] [unique_id "al4VRrcDxY_mIul-JSGjSAAAATQ"]
[Mon Jul 20 06:32:06.024799 2026] [security2:error] [pid 940476:tid 940658] [client 77.239.165.93:65128] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4VRhjVYcQxwGpYwZmiwwAAADQ"]
[Mon Jul 20 06:32:06.040107 2026] [security2:error] [pid 940476:tid 940579] [remote 202.51.202.242:44632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmixAAATmY"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:32:06.048571 2026] [security2:error] [pid 935758:tid 935937] [client 34.74.185.202:52380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VRrcDxY_mIul-JSGjSgAAATk"]
[Mon Jul 20 06:32:06.066946 2026] [security2:error] [pid 935758:tid 935935] [client 181.123.89.110:55266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4VRrcDxY_mIul-JSGjSwAAATc"]
[Mon Jul 20 06:32:06.100280 2026] [security2:error] [pid 940476:tid 940577] [remote 113.160.142.119:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmixgAAd2Q"]
[Mon Jul 20 06:32:06.115908 2026] [security2:error] [pid 940476:tid 940719] [client 49.156.84.178:45652] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4VRhjVYcQxwGpYwZmiyQAAAHE"]
[Mon Jul 20 06:32:06.117054 2026] [security2:error] [pid 940476:tid 940647] [client 119.30.119.166:10478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4VRhjVYcQxwGpYwZmiygAAACk"]
[Mon Jul 20 06:32:06.142550 2026] [security2:error] [pid 940476:tid 940666] [client 112.208.70.94:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VRhjVYcQxwGpYwZmizQAAADw"]
[Mon Jul 20 06:32:06.142667 2026] [security2:error] [pid 940476:tid 940666] [client 112.208.70.94:44159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VRhjVYcQxwGpYwZmizQAAADw"]
[Mon Jul 20 06:32:06.142826 2026] [security2:error] [pid 940476:tid 940708] [client 90.238.19.133:24763] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmizAAAAGY"]
[Mon Jul 20 06:32:06.185580 2026] [security2:error] [pid 940476:tid 940611] [client 113.199.244.176:43468] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmizwAAAAU"]
[Mon Jul 20 06:32:06.206541 2026] [security2:error] [pid 940476:tid 940655] [client 190.80.34.72:39476] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi0gAAADE"]
[Mon Jul 20 06:32:06.206640 2026] [security2:error] [pid 935758:tid 935987] [client 1.52.89.105:52966] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4VRrcDxY_mIul-JSGjWQAAAWs"]
[Mon Jul 20 06:32:06.230945 2026] [security2:error] [pid 940476:tid 940695] [client 79.106.125.131:54780] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi0wAAAFk"]
[Mon Jul 20 06:32:06.244123 2026] [security2:error] [pid 935758:tid 935925] [client 153.67.107.135:17086] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4VRrcDxY_mIul-JSGjWgAAAS0"]
[Mon Jul 20 06:32:06.293210 2026] [security2:error] [pid 940476:tid 940606] [client 45.41.165.152:6672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmixQAAAGg"]
[Mon Jul 20 06:32:06.329543 2026] [security2:error] [pid 940476:tid 940711] [client 192.223.105.252:57732] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi1gAAAGk"]
[Mon Jul 20 06:32:06.363948 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjUgAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.386299 2026] [security2:error] [pid 935758:tid 936005] [client 91.73.227.1:36832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4VRrcDxY_mIul-JSGjXgAAAX0"]
[Mon Jul 20 06:32:06.395707 2026] [security2:error] [pid 935758:tid 936007] [client 49.147.194.213:5397] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.ttf"] [unique_id "al4VRrcDxY_mIul-JSGjXwAAAX8"]
[Mon Jul 20 06:32:06.400870 2026] [security2:error] [pid 940476:tid 940673] [client 114.119.130.251:61197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.maxenengineering.com"] [uri "/wp-content/uploads/2016/07/20160120_110949.jpg"] [unique_id "al4VRhjVYcQxwGpYwZmi2gAAAEM"], referer: https://www.maxenengineering.com/gallery/page/2
[Mon Jul 20 06:32:06.402429 2026] [security2:error] [pid 940476:tid 940500] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4VRhjVYcQxwGpYwZmi2QAAVhc"]
[Mon Jul 20 06:32:06.402785 2026] [security2:error] [pid 940476:tid 940580] [remote 160.187.68.132:59780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmi2AAAbmc"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:32:06.415643 2026] [security2:error] [pid 935758:tid 935953] [client 212.47.149.30:2649] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4VRrcDxY_mIul-JSGjYAAAAUk"]
[Mon Jul 20 06:32:06.423573 2026] [security2:error] [pid 935758:tid 935973] [client 34.73.38.214:64281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.lgi.ful.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VRrcDxY_mIul-JSGjYgAAAV0"]
[Mon Jul 20 06:32:06.431143 2026] [security2:error] [pid 935758:tid 935909] [client 103.159.167.42:37806] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4VRrcDxY_mIul-JSGjYwAAAR0"]
[Mon Jul 20 06:32:06.434872 2026] [security2:error] [pid 935758:tid 935980] [client 14.225.17.146:53343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4VRbcDxY_mIul-JSGjIQAAAWQ"], referer: http://getgarrison.com/Old
[Mon Jul 20 06:32:06.482036 2026] [security2:error] [pid 940476:tid 940616] [client 176.236.157.150:57284] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi2wAAAAo"]
[Mon Jul 20 06:32:06.568148 2026] [security2:error] [pid 940476:tid 940641] [client 2.89.151.80:49822] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi3gAAACM"]
[Mon Jul 20 06:32:06.620988 2026] [security2:error] [pid 940476:tid 940668] [client 78.161.242.177:58626] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4VRhjVYcQxwGpYwZmi5QAAAD4"]
[Mon Jul 20 06:32:06.681868 2026] [security2:error] [pid 940476:tid 940649] [client 89.246.100.230:20425] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi5gAAACs"]
[Mon Jul 20 06:32:06.686918 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRrcDxY_mIul-JSGjcwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.687037 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:65286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRrcDxY_mIul-JSGjcwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.701516 2026] [security2:error] [pid 940476:tid 940702] [client 164.52.11.194:44796] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VRhjVYcQxwGpYwZmi6AAAAGA"]
[Mon Jul 20 06:32:06.701971 2026] [security2:error] [pid 940476:tid 940702] [client 164.52.11.194:44796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VRhjVYcQxwGpYwZmi6AAAAGA"]
[Mon Jul 20 06:32:06.702018 2026] [security2:error] [pid 940476:tid 940702] [client 164.52.11.194:44796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VRhjVYcQxwGpYwZmi6AAAAGA"]
[Mon Jul 20 06:32:06.734928 2026] [security2:error] [pid 940476:tid 940728] [client 14.225.17.146:50370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi3wAAAHo"], referer: http://dnsplumbing.com/Old
[Mon Jul 20 06:32:06.760101 2026] [security2:error] [pid 935758:tid 935950] [client 45.165.207.66:1766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_grid/vc_grid_v1.ttf"] [unique_id "al4VRrcDxY_mIul-JSGjeQAAAUY"]
[Mon Jul 20 06:32:06.801776 2026] [security2:error] [pid 940476:tid 940679] [client 14.225.17.146:50369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi4gAAAEk"], referer: http://windowtx.com/Old
[Mon Jul 20 06:32:06.816602 2026] [security2:error] [pid 940476:tid 940583] [remote 113.160.142.119:36310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VRhjVYcQxwGpYwZmi7gAATmo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:06.843595 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:65287] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VRrcDxY_mIul-JSGjfQAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:06.852095 2026] [security2:error] [pid 940476:tid 940614] [client 88.227.93.193:34920] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4VRhjVYcQxwGpYwZmi7wAAAAg"]
[Mon Jul 20 06:32:06.857310 2026] [security2:error] [pid 935758:tid 935839] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VRrcDxY_mIul-JSGjfgABDE4"]
[Mon Jul 20 06:32:06.860142 2026] [security2:error] [pid 940476:tid 940637] [client 187.109.135.18:1623] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4VRhjVYcQxwGpYwZmi8AAAAB8"]
[Mon Jul 20 06:32:06.862244 2026] [security2:error] [pid 935758:tid 935995] [client 52.190.138.124:44676] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "scarlettshirt.com"] [uri "/"] [unique_id "al4VRrcDxY_mIul-JSGjgAAAAXM"]
[Mon Jul 20 06:32:06.917723 2026] [security2:error] [pid 935758:tid 935964] [client 213.152.162.79:54508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VRrcDxY_mIul-JSGjgwAAAVQ"]
[Mon Jul 20 06:32:06.917859 2026] [security2:error] [pid 935758:tid 935964] [client 213.152.162.79:54508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VRrcDxY_mIul-JSGjgwAAAVQ"]
[Mon Jul 20 06:32:06.939556 2026] [security2:error] [pid 935758:tid 935924] [client 66.249.73.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjewAAASw"]
[Mon Jul 20 06:32:06.994036 2026] [security2:error] [pid 940476:tid 940648] [client 187.62.186.117:21380] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4VRhjVYcQxwGpYwZmi9QAAACo"]
[Mon Jul 20 06:32:07.018140 2026] [security2:error] [pid 940476:tid 940633] [client 103.134.219.130:16405] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmi-AAAABs"]
[Mon Jul 20 06:32:07.234783 2026] [security2:error] [pid 935758:tid 935933] [client 34.74.185.202:59056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VR7cDxY_mIul-JSGjmQAAATU"]
[Mon Jul 20 06:32:07.401536 2026] [security2:error] [pid 940476:tid 940638] [client 172.59.215.204:28477] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjAwAAACA"]
[Mon Jul 20 06:32:07.408498 2026] [security2:error] [pid 935758:tid 935789] [remote 157.85.212.221:51721] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "concat(,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mtlegnews.gov"] [uri "/wp-json/batch/v1"] [unique_id "al4VR7cDxY_mIul-JSGjpwABcBw"]
[Mon Jul 20 06:32:07.415175 2026] [security2:error] [pid 940476:tid 940721] [client 125.162.26.230:48182] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjBAAAAHM"]
[Mon Jul 20 06:32:07.486186 2026] [security2:error] [pid 935758:tid 935939] [client 178.27.54.222:56872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufc5qw54a.woff2"] [unique_id "al4VR7cDxY_mIul-JSGjwAAAATs"]
[Mon Jul 20 06:32:07.534832 2026] [security2:error] [pid 940476:tid 940708] [client 46.248.208.100:37466] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjCgAAAGY"]
[Mon Jul 20 06:32:07.537429 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:65194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VR7cDxY_mIul-JSGj0AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.537514 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:65194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VR7cDxY_mIul-JSGj0AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.588371 2026] [security2:error] [pid 935758:tid 935955] [client 102.66.149.122:48990] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4VR7cDxY_mIul-JSGj2wAAAUs"]
[Mon Jul 20 06:32:07.687362 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:65297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRxjVYcQxwGpYwZmjEQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.687457 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:65297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VRxjVYcQxwGpYwZmjEQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:07.689413 2026] [security2:error] [pid 935758:tid 935915] [client 171.60.139.123:58761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VR7cDxY_mIul-JSGj4QAAASM"]
[Mon Jul 20 06:32:07.689565 2026] [security2:error] [pid 935758:tid 935915] [client 171.60.139.123:58761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VR7cDxY_mIul-JSGj4QAAASM"]
[Mon Jul 20 06:32:07.690307 2026] [security2:error] [pid 935758:tid 935871] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VR7cDxY_mIul-JSGj4AABe24"]
[Mon Jul 20 06:32:07.888637 2026] [security2:error] [pid 940476:tid 940611] [client 139.135.241.3:34100] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4VRxjVYcQxwGpYwZmjGwAAAAU"]
[Mon Jul 20 06:32:07.912138 2026] [security2:error] [pid 940476:tid 940616] [client 14.225.17.146:60859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4VRxjVYcQxwGpYwZmjGQAAAAo"], referer: http://backandneckpainrelieflaceychiropractor.com/Old
[Mon Jul 20 06:32:08.128759 2026] [security2:error] [pid 940476:tid 940694] [client 14.225.17.146:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4VSBjVYcQxwGpYwZmjIQAAAFg"], referer: http://mazzucelli.com/Old
[Mon Jul 20 06:32:08.231316 2026] [security2:error] [pid 940476:tid 940700] [client 180.191.208.151:35296] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4VSBjVYcQxwGpYwZmjMQAAAF4"]
[Mon Jul 20 06:32:08.315306 2026] [security2:error] [pid 935758:tid 936011] [client 50.116.65.227:44090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VSLcDxY_mIul-JSGj_QAAAYM"]
[Mon Jul 20 06:32:08.325925 2026] [security2:error] [pid 935758:tid 935942] [client 50.116.65.227:44100] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VSLcDxY_mIul-JSGj_gAAAT4"]
[Mon Jul 20 06:32:08.327682 2026] [security2:error] [pid 935758:tid 935794] [remote 157.85.212.221:30679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:alter|drop)\\\\b [a-z0-9]+ \\\\b(?:column|database|procedure|table)\\\\b|delete[[:space:]] .{1,100}+ update [a-z0-9]+ set .{1,100}+=|union all select |\\\\bunion\\\\b.{1,100}?\\\\bselect\\\\b.{0,200}[a-z0-9]+ from |select (?:load_file|char ?\\\\()|(?:insert|r ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "314"] [id "340144"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL injection protection 2"] [data "761"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mtlegnews.gov"] [uri "/wp-json/batch/v1"] [unique_id "al4VSLcDxY_mIul-JSGj_wABhSE"]
[Mon Jul 20 06:32:08.341499 2026] [security2:error] [pid 935758:tid 935916] [client 177.44.177.215:28950] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4VSLcDxY_mIul-JSGkAQAAASQ"]
[Mon Jul 20 06:32:08.385354 2026] [security2:error] [pid 935758:tid 935951] [client 45.116.69.230:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VSLcDxY_mIul-JSGkAwAAAUc"]
[Mon Jul 20 06:32:08.385456 2026] [security2:error] [pid 935758:tid 935951] [client 45.116.69.230:51308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VSLcDxY_mIul-JSGkAwAAAUc"]
[Mon Jul 20 06:32:08.386220 2026] [security2:error] [pid 940476:tid 940674] [client 14.225.17.146:50410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmiwAAAAEQ"], referer: http://adastra.love/Old
[Mon Jul 20 06:32:08.489932 2026] [security2:error] [pid 935758:tid 935969] [client 102.100.89.214:60796] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/js_composer/assets/fonts/vc_icons/fonts/vcpb-plugin-icons.woff"] [unique_id "al4VSLcDxY_mIul-JSGkCQAAAVk"]
[Mon Jul 20 06:32:08.498587 2026] [security2:error] [pid 935758:tid 935921] [client 104.234.53.62:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VSLcDxY_mIul-JSGkCgAAASk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:08.516354 2026] [security2:error] [pid 940476:tid 940598] [remote 5.182.209.54:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VSBjVYcQxwGpYwZmjPQAAQ3k"]
[Mon Jul 20 06:32:08.529514 2026] [security2:error] [pid 940476:tid 940699] [client 57.141.18.12:39052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VQxjVYcQxwGpYwZmiDAAAXXE"]
[Mon Jul 20 06:32:08.531150 2026] [security2:error] [pid 940476:tid 940613] [client 14.225.17.146:64273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4VSBjVYcQxwGpYwZmjNwAAAAc"], referer: http://mourgroup.com/Old
[Mon Jul 20 06:32:08.532954 2026] [security2:error] [pid 940476:tid 940538] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VSBjVYcQxwGpYwZmjPwAAWz0"]
[Mon Jul 20 06:32:08.570009 2026] [security2:error] [pid 940476:tid 940621] [client 34.74.185.202:59698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VSBjVYcQxwGpYwZmjQAAAAA8"]
[Mon Jul 20 06:32:08.689577 2026] [security2:error] [pid 940476:tid 940481] [remote 5.182.209.54:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VSBjVYcQxwGpYwZmjRgAAfAQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:08.766037 2026] [security2:error] [pid 940476:tid 940722] [client 57.141.18.71:50048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VQxjVYcQxwGpYwZmiFgAAdEQ"]
[Mon Jul 20 06:32:08.869327 2026] [security2:error] [pid 940476:tid 940693] [client 39.48.81.23:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VSBjVYcQxwGpYwZmjTQAAAFc"]
[Mon Jul 20 06:32:08.869435 2026] [security2:error] [pid 940476:tid 940693] [client 39.48.81.23:65137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VSBjVYcQxwGpYwZmjTQAAAFc"]
[Mon Jul 20 06:32:08.882833 2026] [security2:error] [pid 940476:tid 940694] [client 172.232.181.107:20184] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VSBjVYcQxwGpYwZmjTgAAAFg"]
[Mon Jul 20 06:32:09.295609 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:65311] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VSRjVYcQxwGpYwZmjVgAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:09.402458 2026] [security2:error] [pid 940476:tid 940688] [client 74.249.245.134:52769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.245.249.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.tablas.me"] [uri "/bdshell.php"] [unique_id "al4VSRjVYcQxwGpYwZmjWQAAAFI"]
[Mon Jul 20 06:32:09.402586 2026] [security2:error] [pid 940476:tid 940688] [client 74.249.245.134:52769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.tablas.me"] [uri "/bdshell.php"] [unique_id "al4VSRjVYcQxwGpYwZmjWQAAAFI"]
[Mon Jul 20 06:32:09.437371 2026] [security2:error] [pid 935758:tid 935840] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VSbcDxY_mIul-JSGkMgABSk8"]
[Mon Jul 20 06:32:09.482532 2026] [security2:error] [pid 940476:tid 940642] [client 95.177.87.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VRxjVYcQxwGpYwZmjHQAAACQ"]
[Mon Jul 20 06:32:09.532625 2026] [security2:error] [pid 935758:tid 935999] [client 95.177.87.42:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VR7cDxY_mIul-JSGj6gABdz8"]
[Mon Jul 20 06:32:09.539034 2026] [security2:error] [pid 935758:tid 935999] [client 95.177.87.42:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VR7cDxY_mIul-JSGj6wABdzA"]
[Mon Jul 20 06:32:09.763168 2026] [security2:error] [pid 940476:tid 940712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VSRjVYcQxwGpYwZmjYQAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:09.811540 2026] [security2:error] [pid 940476:tid 940682] [client 57.141.18.13:50748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRBjVYcQxwGpYwZmiUQAATE8"]
[Mon Jul 20 06:32:09.857734 2026] [security2:error] [pid 935758:tid 935907] [client 112.204.205.62:41160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4VSbcDxY_mIul-JSGkSwAAARs"]
[Mon Jul 20 06:32:09.928886 2026] [security2:error] [pid 940476:tid 940704] [client 52.190.138.124:56576] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scarlettshirt.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi8gAAAGI"]
[Mon Jul 20 06:32:09.929160 2026] [security2:error] [pid 935758:tid 935952] [client 52.190.138.124:56586] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scarlettshirt.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjhQAAAUg"]
[Mon Jul 20 06:32:09.989169 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:65316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSbcDxY_mIul-JSGkUQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:09.989295 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:65316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSbcDxY_mIul-JSGkUQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.049067 2026] [security2:error] [pid 940476:tid 940663] [client 52.190.138.124:56608] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "scarlettshirt.com"] [uri "/cgi-sys/404.html"] [unique_id "al4VShjVYcQxwGpYwZmjewAAADk"]
[Mon Jul 20 06:32:10.102353 2026] [security2:error] [pid 940476:tid 940720] [client 34.74.185.202:53353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VShjVYcQxwGpYwZmjfQAAAHI"]
[Mon Jul 20 06:32:10.139876 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:65317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkXAAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.139983 2026] [security2:error] [pid 935758:tid 935896] [client 77.110.127.138:65317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkXAAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.277687 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:65320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjigAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.277862 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:65320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjigAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.294275 2026] [security2:error] [pid 940476:tid 940486] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VShjVYcQxwGpYwZmjiwAAKgk"]
[Mon Jul 20 06:32:10.314337 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjjgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.314512 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:65322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjjgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.536197 2026] [security2:error] [pid 940476:tid 940695] [client 34.74.185.202:52106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VShjVYcQxwGpYwZmjmgAAAFk"]
[Mon Jul 20 06:32:10.696684 2026] [security2:error] [pid 940476:tid 940686] [client 52.190.138.124:56608] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "scarlettshirt.com"] [uri "/wp-login.php"] [unique_id "al4VShjVYcQxwGpYwZmjggAAAFA"]
[Mon Jul 20 06:32:10.720241 2026] [security2:error] [pid 940476:tid 940652] [client 57.141.18.114:49616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRRjVYcQxwGpYwZmingAALl8"]
[Mon Jul 20 06:32:10.727970 2026] [security2:error] [pid 940476:tid 940728] [client 52.190.138.124:56608] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "scarlettshirt.com"] [uri "/ads.txt"] [unique_id "al4VShjVYcQxwGpYwZmjoAAAAHo"]
[Mon Jul 20 06:32:10.757817 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:65327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjowAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.757910 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:65327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjowAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.764883 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:65326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjpAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.764950 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:65326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VShjVYcQxwGpYwZmjpAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.766285 2026] [security2:error] [pid 935758:tid 935996] [client 63.177.52.239:13804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VSrcDxY_mIul-JSGkdgAAAXQ"]
[Mon Jul 20 06:32:10.955251 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkfgAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:10.955335 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSrcDxY_mIul-JSGkfgAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.103111 2026] [security2:error] [pid 935758:tid 935825] [remote 43.249.38.40:0] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4VS7cDxY_mIul-JSGkgwABSUA"]
[Mon Jul 20 06:32:11.141001 2026] [security2:error] [pid 935758:tid 935894] [client 34.74.185.202:54411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.nikkidesigns.net"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VS7cDxY_mIul-JSGkhQAAAQ4"]
[Mon Jul 20 06:32:11.193072 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.193191 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:65333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.200484 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.200608 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VSxjVYcQxwGpYwZmjsgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:11.341772 2026] [security2:error] [pid 935758:tid 935972] [client 63.177.52.239:13814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VS7cDxY_mIul-JSGkjwAAAVw"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:11.877600 2026] [security2:error] [pid 940476:tid 940646] [client 57.141.18.37:65402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRhjVYcQxwGpYwZmi5AAAKGk"]
[Mon Jul 20 06:32:11.878320 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.45:36536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjcgABiGs"]
[Mon Jul 20 06:32:11.993511 2026] [security2:error] [pid 935758:tid 935917] [client 57.141.18.34:58562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VRrcDxY_mIul-JSGjdwABJSk"]
[Mon Jul 20 06:32:12.031051 2026] [security2:error] [pid 935758:tid 936008] [client 103.125.179.95:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VTLcDxY_mIul-JSGktAAAAYA"]
[Mon Jul 20 06:32:12.031529 2026] [security2:error] [pid 935758:tid 936008] [client 103.125.179.95:50227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VTLcDxY_mIul-JSGktAAAAYA"]
[Mon Jul 20 06:32:12.105379 2026] [security2:error] [pid 935758:tid 935973] [client 14.225.17.146:54794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4VS7cDxY_mIul-JSGkhAAAAV0"]
[Mon Jul 20 06:32:12.274108 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:65338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkvQAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.274216 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:65338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkvQAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.304143 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkwQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.304285 2026] [security2:error] [pid 935758:tid 935933] [client 77.110.127.138:65339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTLcDxY_mIul-JSGkwQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.488835 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:65340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VTBjVYcQxwGpYwZmj_gAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.777050 2026] [ssl:error] [pid 940476:tid 940613] [client 54.86.115.253:25406] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname webmail.ambarmdesign.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:32:12.796500 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VTBjVYcQxwGpYwZmkAwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:12.883408 2026] [security2:error] [pid 940476:tid 940637] [client 172.232.181.107:61016] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5024.bluehost.com"] [uri "/"] [unique_id "al4VTBjVYcQxwGpYwZmkDgAAAB8"]
[Mon Jul 20 06:32:12.970448 2026] [security2:error] [pid 940476:tid 940699] [client 14.225.17.146:60440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4VSxjVYcQxwGpYwZmj1QAAAF0"], referer: http://daseighty.net/Old
[Mon Jul 20 06:32:12.978337 2026] [security2:error] [pid 935758:tid 935991] [client 57.141.18.60:61532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VR7cDxY_mIul-JSGj5wABbxg"]
[Mon Jul 20 06:32:13.005275 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk4wAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.005434 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:65343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk4wAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.007944 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:65344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk5AAAAWw"]
[Mon Jul 20 06:32:13.008037 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:65344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGk5AAAAWw"]
[Mon Jul 20 06:32:13.010605 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkGAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.010678 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:65345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkGAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.427881 2026] [security2:error] [pid 940476:tid 940512] [remote 81.173.115.7:52380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTRjVYcQxwGpYwZmkJAAAGiM"]
[Mon Jul 20 06:32:13.428015 2026] [security2:error] [pid 940476:tid 940632] [client 81.173.115.7:52380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTRjVYcQxwGpYwZmkJAAAGiM"]
[Mon Jul 20 06:32:13.695237 2026] [security2:error] [pid 935758:tid 935907] [client 77.110.127.138:65357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGlBAAAARs"]
[Mon Jul 20 06:32:13.695380 2026] [security2:error] [pid 935758:tid 935907] [client 77.110.127.138:65357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTbcDxY_mIul-JSGlBAAAARs"]
[Mon Jul 20 06:32:13.699502 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:65358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkKQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.699611 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:65358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkKQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:13.976822 2026] [security2:error] [pid 940476:tid 940672] [client 164.52.11.194:46376] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkNQAAAEI"]
[Mon Jul 20 06:32:13.977001 2026] [security2:error] [pid 940476:tid 940672] [client 164.52.11.194:46376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkNQAAAEI"]
[Mon Jul 20 06:32:13.977057 2026] [security2:error] [pid 940476:tid 940672] [client 164.52.11.194:46376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTRjVYcQxwGpYwZmkNQAAAEI"]
[Mon Jul 20 06:32:14.132056 2026] [security2:error] [pid 940476:tid 940593] [remote 57.141.18.23:33588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4VThjVYcQxwGpYwZmkPQAACHQ"]
[Mon Jul 20 06:32:14.135859 2026] [security2:error] [pid 940476:tid 940624] [client 82.102.27.163:56782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VThjVYcQxwGpYwZmkPgAAABI"]
[Mon Jul 20 06:32:14.135948 2026] [security2:error] [pid 940476:tid 940624] [client 82.102.27.163:56782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4VThjVYcQxwGpYwZmkPgAAABI"]
[Mon Jul 20 06:32:14.173606 2026] [security2:error] [pid 935758:tid 935981] [client 151.123.177.234:58357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VTrcDxY_mIul-JSGlIwAAAWU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:14.192981 2026] [security2:error] [pid 935758:tid 935997] [client 216.73.216.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rywventures.com"] [uri "/index.php"] [unique_id "al4VTrcDxY_mIul-JSGlHQAAAXU"]
[Mon Jul 20 06:32:14.465981 2026] [security2:error] [pid 935758:tid 936009] [client 197.186.66.42:59643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlNgAAAYE"]
[Mon Jul 20 06:32:14.473927 2026] [security2:error] [pid 935758:tid 936009] [client 197.186.66.42:59643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlNgAAAYE"]
[Mon Jul 20 06:32:14.498405 2026] [security2:error] [pid 935758:tid 935811] [remote 162.19.86.63:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlOQABJzI"]
[Mon Jul 20 06:32:14.498584 2026] [security2:error] [pid 935758:tid 935919] [client 162.19.86.63:59383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VTrcDxY_mIul-JSGlOQABJzI"]
[Mon Jul 20 06:32:14.599251 2026] [security2:error] [pid 935758:tid 935960] [client 57.141.18.9:53612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VSbcDxY_mIul-JSGkQAABUCI"]
[Mon Jul 20 06:32:14.704467 2026] [security2:error] [pid 935758:tid 935931] [client 14.225.17.146:56027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4VTrcDxY_mIul-JSGlPAAAATM"], referer: http://lifeisbetterlakeside.com/Old
[Mon Jul 20 06:32:14.737554 2026] [security2:error] [pid 935758:tid 935996] [client 164.52.11.194:46832] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTrcDxY_mIul-JSGlRgAAAXQ"]
[Mon Jul 20 06:32:14.737735 2026] [security2:error] [pid 935758:tid 935996] [client 164.52.11.194:46832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTrcDxY_mIul-JSGlRgAAAXQ"]
[Mon Jul 20 06:32:14.737785 2026] [security2:error] [pid 935758:tid 935996] [client 164.52.11.194:46832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-comments-post.php"] [unique_id "al4VTrcDxY_mIul-JSGlRgAAAXQ"]
[Mon Jul 20 06:32:14.890903 2026] [security2:error] [pid 935758:tid 936000] [client 5.161.187.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4VTbcDxY_mIul-JSGk_gAAAXg"]
[Mon Jul 20 06:32:15.150984 2026] [security2:error] [pid 940476:tid 940491] [remote 100.42.189.89:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VTxjVYcQxwGpYwZmkWAAAXw4"]
[Mon Jul 20 06:32:15.159873 2026] [security2:error] [pid 935758:tid 935999] [client 5.161.76.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4VTrcDxY_mIul-JSGlMAAAAXc"]
[Mon Jul 20 06:32:15.378516 2026] [security2:error] [pid 940476:tid 940540] [remote 100.42.189.89:51382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VTxjVYcQxwGpYwZmkZQAAcj8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:15.440846 2026] [security2:error] [pid 935758:tid 935963] [client 57.141.18.2:41642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VSrcDxY_mIul-JSGkaAABUxw"]
[Mon Jul 20 06:32:16.011298 2026] [security2:error] [pid 940476:tid 940714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VTxjVYcQxwGpYwZmkbQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:16.026115 2026] [security2:error] [pid 940476:tid 940666] [client 171.61.165.146:9507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkeQAAADw"]
[Mon Jul 20 06:32:16.026223 2026] [security2:error] [pid 940476:tid 940666] [client 171.61.165.146:9507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkeQAAADw"]
[Mon Jul 20 06:32:16.045450 2026] [security2:error] [pid 935758:tid 935827] [remote 81.173.115.7:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VULcDxY_mIul-JSGlfQABbUI"]
[Mon Jul 20 06:32:16.291113 2026] [security2:error] [pid 940476:tid 940722] [client 114.119.150.49:39913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtlegnews.gov"] [uri "/robots.txt"] [unique_id "al4VUBjVYcQxwGpYwZmkhAAAAHQ"], referer: https://mtlegnews.gov/robots.txt
[Mon Jul 20 06:32:16.302334 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:65373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:16.302455 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:65373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:16.333295 2026] [security2:error] [pid 940476:tid 940673] [client 223.185.13.213:21534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhwAAAEM"]
[Mon Jul 20 06:32:16.333449 2026] [security2:error] [pid 940476:tid 940673] [client 223.185.13.213:21534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUBjVYcQxwGpYwZmkhwAAAEM"]
[Mon Jul 20 06:32:16.354606 2026] [security2:error] [pid 940476:tid 940547] [remote 57.141.18.77:42816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2535740"] [unique_id "al4VUBjVYcQxwGpYwZmkigAAUUY"]
[Mon Jul 20 06:32:16.780112 2026] [security2:error] [pid 935758:tid 935892] [client 50.116.65.227:16304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4VULcDxY_mIul-JSGlnQAAAQw"]
[Mon Jul 20 06:32:16.794555 2026] [security2:error] [pid 940476:tid 940638] [client 50.116.65.227:58284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4VUBjVYcQxwGpYwZmkowAAACA"]
[Mon Jul 20 06:32:17.113884 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:65383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUbcDxY_mIul-JSGlqAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.113985 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:65383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUbcDxY_mIul-JSGlqAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.278758 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VURjVYcQxwGpYwZmktgAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.278854 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:65385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VURjVYcQxwGpYwZmktgAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.524585 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmkuQAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.646407 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:65387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmkwwAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:17.752103 2026] [security2:error] [pid 935758:tid 935987] [client 50.116.65.227:58310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VUbcDxY_mIul-JSGlwQAAAWs"]
[Mon Jul 20 06:32:17.756784 2026] [security2:error] [pid 935758:tid 935993] [client 98.159.234.160:43047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VUbcDxY_mIul-JSGlwgAAAXE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:32:17.763759 2026] [security2:error] [pid 940476:tid 940714] [client 50.116.65.227:58316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VURjVYcQxwGpYwZmkzwAAAGw"]
[Mon Jul 20 06:32:18.233784 2026] [security2:error] [pid 940476:tid 940650] [client 104.234.53.79:25633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VUhjVYcQxwGpYwZmk3QAAACw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:18.460521 2026] [security2:error] [pid 940476:tid 940643] [client 171.60.139.123:59281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk6wAAACU"]
[Mon Jul 20 06:32:18.460649 2026] [security2:error] [pid 940476:tid 940643] [client 171.60.139.123:59281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk6wAAACU"]
[Mon Jul 20 06:32:18.597124 2026] [security2:error] [pid 940476:tid 940613] [client 39.48.81.23:49370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk8wAAAAc"]
[Mon Jul 20 06:32:18.597266 2026] [security2:error] [pid 940476:tid 940613] [client 39.48.81.23:49370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmk8wAAAAc"]
[Mon Jul 20 06:32:18.621365 2026] [security2:error] [pid 935758:tid 935927] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VUrcDxY_mIul-JSGl3gAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:18.958372 2026] [security2:error] [pid 940476:tid 940706] [client 14.225.17.146:54445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmkzgAAAGQ"], referer: http://lutheranphilosopher.com/Old
[Mon Jul 20 06:32:18.985187 2026] [security2:error] [pid 940476:tid 940615] [client 45.116.69.230:51864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmlCgAAAAk"]
[Mon Jul 20 06:32:18.985353 2026] [security2:error] [pid 940476:tid 940615] [client 45.116.69.230:51864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VUhjVYcQxwGpYwZmlCgAAAAk"]
[Mon Jul 20 06:32:19.099664 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VUhjVYcQxwGpYwZmlBgAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.195167 2026] [security2:error] [pid 940476:tid 940674] [client 14.225.17.146:49282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmk2gAAAEQ"], referer: http://momheadquarters.com/Old
[Mon Jul 20 06:32:19.277256 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:19.277322 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:19.277836 2026] [proxy:error] [pid 935758:tid 935911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:19.277860 2026] [proxy_http:error] [pid 935758:tid 935911] [client 34.73.38.214:57178] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:19.361347 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUxjVYcQxwGpYwZmlGAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.361439 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VUxjVYcQxwGpYwZmlGAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.440007 2026] [security2:error] [pid 935758:tid 935782] [remote 81.173.115.7:50168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VU7cDxY_mIul-JSGmAwABFxU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:32:19.517651 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:65400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmCAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.517777 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:65400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmCAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.705652 2026] [security2:error] [pid 935758:tid 935988] [client 13.201.64.214:16936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VU7cDxY_mIul-JSGmEwAAAWw"]
[Mon Jul 20 06:32:19.744573 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:65403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmFAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.744711 2026] [security2:error] [pid 935758:tid 935921] [client 77.110.127.138:65403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VU7cDxY_mIul-JSGmFAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:19.854068 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VU7cDxY_mIul-JSGmDgAAAW4"]
[Mon Jul 20 06:32:19.858272 2026] [security2:error] [pid 940476:tid 940703] [client 57.141.18.83:28978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VTxjVYcQxwGpYwZmkVgAAYRo"]
[Mon Jul 20 06:32:20.057334 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:65404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlMwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.057456 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:65404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlMwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.143162 2026] [security2:error] [pid 935758:tid 935969] [client 14.225.17.146:54773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4VVLcDxY_mIul-JSGmIQAAAVk"], referer: http://ksands.co.uk/Old
[Mon Jul 20 06:32:20.222618 2026] [security2:error] [pid 940476:tid 940632] [client 104.234.53.79:25633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlRAAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:20.229297 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:65368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlSAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.229473 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:65368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlSAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.358726 2026] [security2:error] [pid 935758:tid 935971] [client 112.208.70.94:44597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VVLcDxY_mIul-JSGmKQAAAVs"]
[Mon Jul 20 06:32:20.358899 2026] [security2:error] [pid 935758:tid 935971] [client 112.208.70.94:44597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VVLcDxY_mIul-JSGmKQAAAVs"]
[Mon Jul 20 06:32:20.362561 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:65406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlTAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.362648 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:65406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVBjVYcQxwGpYwZmlTAAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.406796 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVBjVYcQxwGpYwZmlOwAAABU"]
[Mon Jul 20 06:32:20.440796 2026] [security2:error] [pid 935758:tid 935999] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-5ab144f7.uritems.net"] [uri "/index.php"] [unique_id "al4VUrcDxY_mIul-JSGl1gAAAXc"]
[Mon Jul 20 06:32:20.645539 2026] [security2:error] [pid 940476:tid 940596] [remote 217.61.143.92:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlXAAABXc"]
[Mon Jul 20 06:32:20.758163 2026] [security2:error] [pid 940476:tid 940591] [remote 167.233.114.32:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlXQAAAHI"]
[Mon Jul 20 06:32:20.760561 2026] [security2:error] [pid 940476:tid 940730] [client 77.110.127.138:65407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVBjVYcQxwGpYwZmlWAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:20.801779 2026] [security2:error] [pid 940476:tid 940684] [client 103.174.5.160:42862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VUBjVYcQxwGpYwZmkjQAATis"], referer: https://toddnielsen.com
[Mon Jul 20 06:32:20.879255 2026] [security2:error] [pid 940476:tid 940542] [remote 217.61.143.92:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlYQAARkE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:32:20.944731 2026] [security2:error] [pid 940476:tid 940602] [remote 167.233.114.32:54868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4VVBjVYcQxwGpYwZmlZwAAVn0"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 06:32:21.077182 2026] [security2:error] [pid 940476:tid 940631] [client 57.141.18.12:59660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VUBjVYcQxwGpYwZmklQAAGVM"]
[Mon Jul 20 06:32:21.189934 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmlbgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.190026 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:65411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmlbgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.222573 2026] [security2:error] [pid 940476:tid 940720] [client 14.225.17.146:63901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4VVRjVYcQxwGpYwZmlawAAAHI"], referer: http://ironcitywellness.com/Old
[Mon Jul 20 06:32:21.307475 2026] [proxy:error] [pid 940476:tid 940647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:21.307540 2026] [proxy_http:error] [pid 940476:tid 940647] [client 34.73.38.214:54488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:21.308165 2026] [proxy:error] [pid 940476:tid 940647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:21.308199 2026] [proxy_http:error] [pid 940476:tid 940647] [client 34.73.38.214:54488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:21.519534 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmligAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.519673 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:65413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmligAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.748923 2026] [security2:error] [pid 940476:tid 940481] [remote 100.42.189.89:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4VVRjVYcQxwGpYwZmljAAAWAQ"]
[Mon Jul 20 06:32:21.763008 2026] [security2:error] [pid 940476:tid 940690] [client 77.110.127.138:65414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmljQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:21.763134 2026] [security2:error] [pid 940476:tid 940690] [client 77.110.127.138:65414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVRjVYcQxwGpYwZmljQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.014619 2026] [security2:error] [pid 940476:tid 940514] [remote 100.42.189.89:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4VVhjVYcQxwGpYwZmlmQAAPyU"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:32:22.026419 2026] [security2:error] [pid 935758:tid 935890] [client 87.199.196.160:60669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.musichaven.info"] [uri "/wp-comments-post.php"] [unique_id "al4VVbcDxY_mIul-JSGmYQAAAQo"], referer: https://www.musichaven.info/how-songwriting-improves-mental-health/
[Mon Jul 20 06:32:22.026569 2026] [security2:error] [pid 935758:tid 935890] [client 87.199.196.160:60669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.musichaven.info"] [uri "/wp-comments-post.php"] [unique_id "al4VVbcDxY_mIul-JSGmYQAAAQo"], referer: https://www.musichaven.info/how-songwriting-improves-mental-health/
[Mon Jul 20 06:32:22.174685 2026] [security2:error] [pid 940476:tid 940703] [client 158.173.89.95:20717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VVhjVYcQxwGpYwZmlogAAAGE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:32:22.191760 2026] [security2:error] [pid 940476:tid 940665] [client 14.225.17.146:49494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VVhjVYcQxwGpYwZmlngAAADs"], referer: http://effingweirdmuseums.com/Old
[Mon Jul 20 06:32:22.195317 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:65391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVrcDxY_mIul-JSGmaQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.195438 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:65391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VVrcDxY_mIul-JSGmaQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.246504 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVhjVYcQxwGpYwZmlmwAAAEA"], referer: 1'"3000
[Mon Jul 20 06:32:22.392303 2026] [security2:error] [pid 940476:tid 940624] [client 57.141.18.94:57972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VURjVYcQxwGpYwZmk2QAAElg"]
[Mon Jul 20 06:32:22.400480 2026] [security2:error] [pid 935758:tid 935950] [client 77.110.127.138:65416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampJEqIeGln' OR 664. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 664 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VVrcDxY_mIul-JSGmcgAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:22.597788 2026] [security2:error] [pid 940476:tid 940625] [client 57.141.18.75:21894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VUhjVYcQxwGpYwZmk4QAAE2M"]
[Mon Jul 20 06:32:22.791300 2026] [security2:error] [pid 940476:tid 940728] [client 103.125.179.95:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmluwAAAHo"]
[Mon Jul 20 06:32:22.791426 2026] [security2:error] [pid 940476:tid 940728] [client 103.125.179.95:50697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmluwAAAHo"]
[Mon Jul 20 06:32:22.816491 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:22.816556 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:52508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:22.817125 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:22.817164 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:52508] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:22.916232 2026] [security2:error] [pid 935758:tid 935976] [client 57.141.18.109:62544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmjQABYAY"]
[Mon Jul 20 06:32:22.988300 2026] [security2:error] [pid 940476:tid 940722] [client 106.219.188.178:40165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmlxAAAAHQ"]
[Mon Jul 20 06:32:22.998629 2026] [security2:error] [pid 940476:tid 940722] [client 106.219.188.178:40165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VVhjVYcQxwGpYwZmlxAAAAHQ"]
[Mon Jul 20 06:32:23.072205 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmjAAAATY"], referer: 1'"3000
[Mon Jul 20 06:32:23.126062 2026] [security2:error] [pid 940476:tid 940730] [client 14.225.17.146:64141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4VVxjVYcQxwGpYwZmlxgAAAHw"], referer: https://effingweirdmuseums.com/Old
[Mon Jul 20 06:32:23.361129 2026] [security2:error] [pid 940476:tid 940724] [client 114.119.130.57:49085] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/why-is-screen-printing-so-expensive/"] [unique_id "al4VVxjVYcQxwGpYwZmlzQAAAHY"], referer: https://sustaintheart.com/how-long-does-it-take-to-do-a-screen-print/
[Mon Jul 20 06:32:23.487012 2026] [security2:error] [pid 935758:tid 935994] [client 104.234.53.54:38955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VV7cDxY_mIul-JSGmrwAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:23.767508 2026] [security2:error] [pid 940476:tid 940659] [client 187.108.85.186:63848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVxjVYcQxwGpYwZml3wAAADU"]
[Mon Jul 20 06:32:23.767758 2026] [security2:error] [pid 940476:tid 940659] [client 187.108.85.186:63848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VVxjVYcQxwGpYwZml3wAAADU"]
[Mon Jul 20 06:32:23.851517 2026] [security2:error] [pid 940476:tid 940617] [client 65.111.26.25:65377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VVxjVYcQxwGpYwZml5QAAAAs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:23.906725 2026] [security2:error] [pid 940476:tid 940647] [client 43.205.139.3:63722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VVxjVYcQxwGpYwZml7QAAACk"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:23.966595 2026] [proxy:error] [pid 940476:tid 940690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:23.966643 2026] [proxy_http:error] [pid 940476:tid 940690] [client 34.73.38.214:64295] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:23.967287 2026] [proxy:error] [pid 940476:tid 940690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:23.967312 2026] [proxy_http:error] [pid 940476:tid 940690] [client 34.73.38.214:64295] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:24.009120 2026] [security2:error] [pid 940476:tid 940631] [client 14.225.17.146:52440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4VVxjVYcQxwGpYwZml3gAAABk"], referer: http://mcg.homes/Old
[Mon Jul 20 06:32:24.261110 2026] [security2:error] [pid 935758:tid 936012] [client 57.141.18.76:53226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VU7cDxY_mIul-JSGmFwABhAg"]
[Mon Jul 20 06:32:24.330244 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWBjVYcQxwGpYwZml_AAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:24.330352 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:65429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWBjVYcQxwGpYwZml_AAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:24.502933 2026] [security2:error] [pid 935758:tid 935923] [client 65.111.26.132:14365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VWLcDxY_mIul-JSGmzAAAASs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:24.998221 2026] [security2:error] [pid 935758:tid 935803] [remote 85.204.69.248:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4VWLcDxY_mIul-JSGm4gABcyo"]
[Mon Jul 20 06:32:25.037877 2026] [security2:error] [pid 935758:tid 935947] [client 17.241.75.183:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.willowbranchequines.org"] [uri "/index.php"] [unique_id "al4VV7cDxY_mIul-JSGmrQAAAUM"]
[Mon Jul 20 06:32:25.256840 2026] [security2:error] [pid 935758:tid 935795] [remote 85.204.69.248:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4VWbcDxY_mIul-JSGm7QABaiI"], referer: https://website-e4de5cd0.epu.kzx.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:32:25.493657 2026] [security2:error] [pid 935758:tid 935929] [client 197.186.66.42:60143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VWbcDxY_mIul-JSGm8wAAATE"]
[Mon Jul 20 06:32:25.493774 2026] [security2:error] [pid 935758:tid 935929] [client 197.186.66.42:60143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VWbcDxY_mIul-JSGm8wAAATE"]
[Mon Jul 20 06:32:25.505772 2026] [security2:error] [pid 935758:tid 935964] [client 34.73.38.214:54035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VWbcDxY_mIul-JSGm9QAAAVQ"]
[Mon Jul 20 06:32:25.577871 2026] [security2:error] [pid 940476:tid 940723] [client 57.141.18.112:52458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVRjVYcQxwGpYwZmlaQAAdWs"]
[Mon Jul 20 06:32:25.610395 2026] [security2:error] [pid 935758:tid 935993] [client 104.234.53.59:20727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VWbcDxY_mIul-JSGm-QAAAXE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:25.673353 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWRjVYcQxwGpYwZmmKgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:25.673450 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWRjVYcQxwGpYwZmmKgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.067603 2026] [security2:error] [pid 940476:tid 940639] [client 223.185.13.213:22868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VWhjVYcQxwGpYwZmmOAAAACE"]
[Mon Jul 20 06:32:26.067719 2026] [security2:error] [pid 940476:tid 940639] [client 223.185.13.213:22868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VWhjVYcQxwGpYwZmmOAAAACE"]
[Mon Jul 20 06:32:26.220396 2026] [security2:error] [pid 940476:tid 940509] [remote 152.228.213.32:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4VWhjVYcQxwGpYwZmmQgAAdyA"]
[Mon Jul 20 06:32:26.294223 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:65438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampLR0ntXZF') OR 198. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VWhjVYcQxwGpYwZmmRgAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.430251 2026] [security2:error] [pid 940476:tid 940508] [remote 152.228.213.32:57974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4VWhjVYcQxwGpYwZmmTAAAMB8"], referer: https://daseighty.net/wp-login.php
[Mon Jul 20 06:32:26.460588 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWrcDxY_mIul-JSGnHAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.464452 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:65441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWrcDxY_mIul-JSGnHAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:26.469046 2026] [security2:error] [pid 935758:tid 935891] [client 57.141.18.67:56926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVbcDxY_mIul-JSGmXAABCy0"]
[Mon Jul 20 06:32:26.663682 2026] [security2:error] [pid 935758:tid 936005] [client 171.61.165.146:33195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VWrcDxY_mIul-JSGnKQAAAX0"]
[Mon Jul 20 06:32:26.721342 2026] [security2:error] [pid 935758:tid 936005] [client 171.61.165.146:33195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VWrcDxY_mIul-JSGnKQAAAX0"]
[Mon Jul 20 06:32:26.836348 2026] [security2:error] [pid 940476:tid 940684] [client 104.234.53.69:25281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VWhjVYcQxwGpYwZmmXQAAAE4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:27.224847 2026] [security2:error] [pid 940476:tid 940689] [client 34.73.38.214:64805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VWxjVYcQxwGpYwZmmbAAAAFM"]
[Mon Jul 20 06:32:27.255034 2026] [security2:error] [pid 935758:tid 935898] [client 50.116.65.227:54796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VW7cDxY_mIul-JSGnQwAAARI"]
[Mon Jul 20 06:32:27.265732 2026] [security2:error] [pid 940476:tid 940613] [client 50.116.65.227:54810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VWxjVYcQxwGpYwZmmbwAAAAc"]
[Mon Jul 20 06:32:27.662109 2026] [security2:error] [pid 935758:tid 935957] [client 57.141.18.31:64732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmiwABTVA"]
[Mon Jul 20 06:32:27.761841 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWxjVYcQxwGpYwZmmjAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:27.761927 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:65446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VWxjVYcQxwGpYwZmmjAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:27.821146 2026] [security2:error] [pid 935758:tid 935972] [client 57.141.18.112:52468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VVrcDxY_mIul-JSGmlAABXGU"]
[Mon Jul 20 06:32:28.108136 2026] [security2:error] [pid 940476:tid 940626] [client 34.73.38.214:64187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VXBjVYcQxwGpYwZmmlAAAABQ"]
[Mon Jul 20 06:32:28.428871 2026] [security2:error] [pid 940476:tid 940642] [client 20.15.133.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4VXBjVYcQxwGpYwZmmnwAAACQ"]
[Mon Jul 20 06:32:28.433719 2026] [security2:error] [pid 935758:tid 935995] [client 57.141.18.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VXLcDxY_mIul-JSGnawAAAXM"]
[Mon Jul 20 06:32:28.905922 2026] [security2:error] [pid 940476:tid 940714] [client 171.60.139.123:59788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VXBjVYcQxwGpYwZmmugAAAGw"]
[Mon Jul 20 06:32:28.906044 2026] [security2:error] [pid 940476:tid 940714] [client 171.60.139.123:59788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VXBjVYcQxwGpYwZmmugAAAGw"]
[Mon Jul 20 06:32:28.949667 2026] [security2:error] [pid 940476:tid 940675] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VXBjVYcQxwGpYwZmmtwAAAEU"], referer: 1'"3000
[Mon Jul 20 06:32:29.020373 2026] [security2:error] [pid 940476:tid 940661] [client 77.110.127.138:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmmyAAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.020468 2026] [security2:error] [pid 940476:tid 940661] [client 77.110.127.138:65452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmmyAAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.141975 2026] [security2:error] [pid 940476:tid 940689] [client 34.73.38.214:59646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VXRjVYcQxwGpYwZmmygAAAFM"]
[Mon Jul 20 06:32:29.243977 2026] [security2:error] [pid 940476:tid 940687] [client 77.110.127.138:65453] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:amp9aGghcWq')) OR 199. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 199 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/501/"] [unique_id "al4VXRjVYcQxwGpYwZmmzwAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.393600 2026] [security2:error] [pid 940476:tid 940708] [client 43.129.235.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4VWxjVYcQxwGpYwZmmhwAAZnQ"], referer: https://www.aleishapenny.ca/listing/page/193?view=map&paged=193
[Mon Jul 20 06:32:29.395035 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmm0wAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.395153 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:65454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VXRjVYcQxwGpYwZmm0wAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:29.563827 2026] [security2:error] [pid 940476:tid 940679] [client 104.234.53.85:20133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VXRjVYcQxwGpYwZmm3gAAAEk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:29.620381 2026] [security2:error] [pid 940476:tid 940494] [remote 100.42.189.89:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4VXRjVYcQxwGpYwZmm4AAADRE"]
[Mon Jul 20 06:32:29.638526 2026] [security2:error] [pid 940476:tid 940625] [client 45.116.69.230:52394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VXRjVYcQxwGpYwZmm4QAAABM"]
[Mon Jul 20 06:32:29.638639 2026] [security2:error] [pid 940476:tid 940625] [client 45.116.69.230:52394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VXRjVYcQxwGpYwZmm4QAAABM"]
[Mon Jul 20 06:32:29.680863 2026] [security2:error] [pid 940476:tid 940630] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VXRjVYcQxwGpYwZmm3AAAABg"], referer: 1'"3000
[Mon Jul 20 06:32:29.828856 2026] [security2:error] [pid 940476:tid 940561] [remote 100.42.189.89:51500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4VXRjVYcQxwGpYwZmm6QAAOVQ"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:32:29.989297 2026] [security2:error] [pid 940476:tid 940717] [client 173.239.224.236:22593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "marketingrift.com"] [uri "/wp-login.php"] [unique_id "al4VXRjVYcQxwGpYwZmm7QAAAG8"]
[Mon Jul 20 06:32:30.020980 2026] [security2:error] [pid 940476:tid 940720] [client 14.225.17.146:53987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4VXBjVYcQxwGpYwZmmpwAAAHI"], referer: http://nwcarvingacademy.com/Old
[Mon Jul 20 06:32:30.031097 2026] [security2:error] [pid 940476:tid 940694] [client 34.73.38.214:60775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VXhjVYcQxwGpYwZmm7gAAAFg"]
[Mon Jul 20 06:32:30.033211 2026] [security2:error] [pid 940476:tid 940623] [client 142.93.64.197:44190] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.35"] [uri "/"] [unique_id "al4VXhjVYcQxwGpYwZmm7wAAABE"]
[Mon Jul 20 06:32:30.078935 2026] [security2:error] [pid 935758:tid 935906] [client 173.239.224.35:63631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narulatrucking.com"] [uri "/wp-login.php"] [unique_id "al4VXrcDxY_mIul-JSGnpAAAARo"]
[Mon Jul 20 06:32:30.288071 2026] [security2:error] [pid 940476:tid 940684] [client 39.48.81.23:50042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VXhjVYcQxwGpYwZmnAwAAAE4"]
[Mon Jul 20 06:32:30.288244 2026] [security2:error] [pid 940476:tid 940684] [client 39.48.81.23:50042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VXhjVYcQxwGpYwZmnAwAAAE4"]
[Mon Jul 20 06:32:30.743501 2026] [security2:error] [pid 940476:tid 940642] [client 158.173.166.181:29195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VXhjVYcQxwGpYwZmnGAAAACQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:32:30.846618 2026] [security2:error] [pid 940476:tid 940666] [client 34.73.38.214:58988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VXhjVYcQxwGpYwZmnIAAAADw"]
[Mon Jul 20 06:32:31.004558 2026] [security2:error] [pid 940476:tid 940694] [client 50.116.65.227:25402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Feature-Image.jpg"] [unique_id "al4VXxjVYcQxwGpYwZmnKAAAAFg"]
[Mon Jul 20 06:32:31.016675 2026] [security2:error] [pid 940476:tid 940702] [client 50.116.65.227:31054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Feature-Image.jpg"] [unique_id "al4VXxjVYcQxwGpYwZmnKQAAABA"]
[Mon Jul 20 06:32:31.108783 2026] [security2:error] [pid 940476:tid 940654] [client 14.225.17.146:52813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4VXhjVYcQxwGpYwZmnJAAAADA"], referer: https://nwcarvingacademy.com/Old
[Mon Jul 20 06:32:31.315224 2026] [security2:error] [pid 940476:tid 940689] [client 66.249.74.102:40838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techexecutive.me"] [uri "/index.php"] [unique_id "al4VXhjVYcQxwGpYwZmm_QAAAFM"]
[Mon Jul 20 06:32:31.435746 2026] [security2:error] [pid 935758:tid 935939] [client 77.110.127.138:65464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VX7cDxY_mIul-JSGn3wAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:31.435855 2026] [security2:error] [pid 935758:tid 935939] [client 77.110.127.138:65464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VX7cDxY_mIul-JSGn3wAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:31.724185 2026] [security2:error] [pid 935758:tid 935918] [client 14.225.17.146:57098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4VX7cDxY_mIul-JSGn2gAAASY"], referer: http://uritems.net/Old
[Mon Jul 20 06:32:31.783280 2026] [security2:error] [pid 940476:tid 940500] [remote 47.86.33.52:4360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4VXxjVYcQxwGpYwZmnQwAAEhc"]
[Mon Jul 20 06:32:31.783478 2026] [security2:error] [pid 940476:tid 940624] [client 47.86.33.52:4360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4VXxjVYcQxwGpYwZmnQwAAEhc"]
[Mon Jul 20 06:32:31.828202 2026] [security2:error] [pid 935758:tid 935915] [client 104.234.53.57:50173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VX7cDxY_mIul-JSGn7QAAASM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:31.870005 2026] [security2:error] [pid 935758:tid 935962] [client 47.129.160.40:33694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-newdartshow-com/index.php"] [unique_id "al4VX7cDxY_mIul-JSGn7AAAAVI"]
[Mon Jul 20 06:32:32.079366 2026] [security2:error] [pid 935758:tid 935993] [client 34.73.38.214:57830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VYLcDxY_mIul-JSGn9QAAAXE"]
[Mon Jul 20 06:32:32.127564 2026] [security2:error] [pid 940476:tid 940503] [remote 57.141.18.22:45414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/5490371"] [unique_id "al4VYBjVYcQxwGpYwZmnWgAAMxo"]
[Mon Jul 20 06:32:32.467185 2026] [security2:error] [pid 940476:tid 940648] [client 112.208.70.94:44998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VYBjVYcQxwGpYwZmnaAAAACo"]
[Mon Jul 20 06:32:32.467337 2026] [security2:error] [pid 940476:tid 940648] [client 112.208.70.94:44998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VYBjVYcQxwGpYwZmnaAAAACo"]
[Mon Jul 20 06:32:32.566991 2026] [security2:error] [pid 940476:tid 940725] [client 77.110.127.138:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/beaded-flower-garlands-crochet-course/zkxkko29k9t7.php"] [unique_id "al4VYBjVYcQxwGpYwZmnbwAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:32.817631 2026] [security2:error] [pid 940476:tid 940722] [client 74.208.214.194:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VYBjVYcQxwGpYwZmngQAAAHQ"]
[Mon Jul 20 06:32:32.902565 2026] [security2:error] [pid 940476:tid 940603] [remote 47.86.33.52:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4VYBjVYcQxwGpYwZmnjAAAH34"]
[Mon Jul 20 06:32:32.913923 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:65480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYLcDxY_mIul-JSGoFgAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:32.971497 2026] [security2:error] [pid 940476:tid 940586] [remote 100.42.189.89:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4VYBjVYcQxwGpYwZmnjwAALG0"]
[Mon Jul 20 06:32:33.009598 2026] [security2:error] [pid 940476:tid 940694] [client 57.141.18.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VYBjVYcQxwGpYwZmnhwAAAFg"]
[Mon Jul 20 06:32:33.172844 2026] [security2:error] [pid 940476:tid 940589] [remote 100.42.189.89:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4VYRjVYcQxwGpYwZmnkwAAOXA"], referer: https://file.learnthissecret.com/wp-login.php
[Mon Jul 20 06:32:33.292763 2026] [security2:error] [pid 940476:tid 940684] [client 34.73.38.214:57265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VYRjVYcQxwGpYwZmnlwAAAE4"]
[Mon Jul 20 06:32:33.337911 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYBjVYcQxwGpYwZmndwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:33.340461 2026] [security2:error] [pid 935758:tid 935873] [remote 45.90.123.233:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4VYbcDxY_mIul-JSGoLgABXnA"]
[Mon Jul 20 06:32:33.371585 2026] [security2:error] [pid 940476:tid 940614] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYBjVYcQxwGpYwZmneAAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:33.581089 2026] [security2:error] [pid 940476:tid 940714] [client 103.125.179.95:51167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VYRjVYcQxwGpYwZmnogAAAGw"]
[Mon Jul 20 06:32:33.581199 2026] [security2:error] [pid 940476:tid 940714] [client 103.125.179.95:51167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VYRjVYcQxwGpYwZmnogAAAGw"]
[Mon Jul 20 06:32:33.655809 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:65485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VYRjVYcQxwGpYwZmnowAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:33.655954 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:65485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VYRjVYcQxwGpYwZmnowAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:33.706344 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VYRjVYcQxwGpYwZmnpQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:33.706505 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:65461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VYRjVYcQxwGpYwZmnpQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:33.850385 2026] [security2:error] [pid 940476:tid 940686] [client 57.141.18.65:24668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VXBjVYcQxwGpYwZmmqwAAUAY"]
[Mon Jul 20 06:32:34.260155 2026] [security2:error] [pid 935758:tid 935977] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYbcDxY_mIul-JSGoRAAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:34.292857 2026] [security2:error] [pid 940476:tid 940705] [client 77.110.127.138:65490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/beaded-flower-garlands-crochet-course/embed/p56ult1z4ge7.php"] [unique_id "al4VYhjVYcQxwGpYwZmnvQAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:34.294233 2026] [security2:error] [pid 940476:tid 940626] [client 187.108.85.186:64378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VYhjVYcQxwGpYwZmnvwAAABQ"]
[Mon Jul 20 06:32:34.294324 2026] [security2:error] [pid 940476:tid 940626] [client 187.108.85.186:64378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VYhjVYcQxwGpYwZmnvwAAABQ"]
[Mon Jul 20 06:32:34.370962 2026] [security2:error] [pid 940476:tid 940664] [client 77.110.127.138:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VYhjVYcQxwGpYwZmnzAAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:34.371072 2026] [security2:error] [pid 940476:tid 940664] [client 77.110.127.138:65498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VYhjVYcQxwGpYwZmnzAAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:34.515568 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:65492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYhjVYcQxwGpYwZmnwAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:34.668507 2026] [security2:error] [pid 935758:tid 935944] [client 106.219.188.178:58746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VYrcDxY_mIul-JSGoYQAAAUA"]
[Mon Jul 20 06:32:34.674975 2026] [security2:error] [pid 935758:tid 935944] [client 106.219.188.178:58746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VYrcDxY_mIul-JSGoYQAAAUA"]
[Mon Jul 20 06:32:34.743358 2026] [security2:error] [pid 940476:tid 940673] [client 51.68.236.90:35515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elementalkneads.com"] [uri "/robots.txt"] [unique_id "al4VYhjVYcQxwGpYwZmn3AAAAEM"]
[Mon Jul 20 06:32:34.743505 2026] [security2:error] [pid 940476:tid 940673] [client 51.68.236.90:35515] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elementalkneads.com"] [uri "/robots.txt"] [unique_id "al4VYhjVYcQxwGpYwZmn3AAAAEM"]
[Mon Jul 20 06:32:34.978180 2026] [security2:error] [pid 940476:tid 940719] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYhjVYcQxwGpYwZmnxwAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.042281 2026] [security2:error] [pid 935758:tid 935894] [client 77.110.127.138:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/rywcv3jxpe9j.php"] [unique_id "al4VY7cDxY_mIul-JSGocAAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.081699 2026] [autoindex:error] [pid 935758:tid 935908] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:32:35.085035 2026] [autoindex:error] [pid 935758:tid 935909] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.124413 2026] [security2:error] [pid 935758:tid 935914] [client 34.73.38.214:57209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.makeupyourskin.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VY7cDxY_mIul-JSGofQAAASI"]
[Mon Jul 20 06:32:35.170168 2026] [security2:error] [pid 935758:tid 935968] [client 47.129.160.40:33694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-saraljart-com/index.php"] [unique_id "al4VY7cDxY_mIul-JSGogAAAAVg"]
[Mon Jul 20 06:32:35.296353 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:65481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYxjVYcQxwGpYwZmn-gAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.306437 2026] [security2:error] [pid 940476:tid 940606] [client 57.141.18.54:30582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VXhjVYcQxwGpYwZmm8QAAAE0"]
[Mon Jul 20 06:32:35.392567 2026] [security2:error] [pid 940476:tid 940635] [client 57.141.18.33:49496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VXhjVYcQxwGpYwZmnAQAAHRY"]
[Mon Jul 20 06:32:35.457390 2026] [security2:error] [pid 940476:tid 940653] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYxjVYcQxwGpYwZmn_wAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.748057 2026] [security2:error] [pid 935758:tid 935799] [remote 45.90.123.233:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4VY7cDxY_mIul-JSGokgABSiY"], referer: https://guidehunting.com/wp-login.php
[Mon Jul 20 06:32:35.768627 2026] [security2:error] [pid 940476:tid 940569] [remote 47.128.99.60:35848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/brs-bet-2024-01-20-id-11373.pdf"] [unique_id "al4VYxjVYcQxwGpYwZmoJwAAbVw"]
[Mon Jul 20 06:32:35.782299 2026] [security2:error] [pid 940476:tid 940667] [client 57.141.18.108:62870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VXhjVYcQxwGpYwZmnFgAAPUU"]
[Mon Jul 20 06:32:35.857960 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VY7cDxY_mIul-JSGolQAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.858092 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:65501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VY7cDxY_mIul-JSGolQAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:35.858519 2026] [security2:error] [pid 940476:tid 940672] [client 77.110.127.138:65467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/_inc/x14y8qycmh0d.php"] [unique_id "al4VYxjVYcQxwGpYwZmoKAAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:36.092169 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:65487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VYxjVYcQxwGpYwZmoKQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:36.593850 2026] [security2:error] [pid 940476:tid 940612] [client 14.225.17.146:52542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4VYhjVYcQxwGpYwZmn7AAAAAY"], referer: http://superiorcopywriting.com/Old
[Mon Jul 20 06:32:36.599105 2026] [security2:error] [pid 940476:tid 940575] [remote 47.86.33.52:4348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4VZBjVYcQxwGpYwZmoVAAASGI"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:32:36.683076 2026] [security2:error] [pid 940476:tid 940643] [client 197.186.66.42:60641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VZBjVYcQxwGpYwZmoWQAAACU"]
[Mon Jul 20 06:32:36.683178 2026] [security2:error] [pid 940476:tid 940643] [client 197.186.66.42:60641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VZBjVYcQxwGpYwZmoWQAAACU"]
[Mon Jul 20 06:32:36.752921 2026] [security2:error] [pid 935758:tid 935955] [client 57.141.18.69:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VX7cDxY_mIul-JSGn4gABS1M"]
[Mon Jul 20 06:32:36.885013 2026] [autoindex:error] [pid 940476:tid 940655] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:32:36.886233 2026] [security2:error] [pid 935758:tid 935903] [client 223.185.13.213:26496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VZLcDxY_mIul-JSGovwAAARc"]
[Mon Jul 20 06:32:36.886386 2026] [security2:error] [pid 935758:tid 935903] [client 223.185.13.213:26496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VZLcDxY_mIul-JSGovwAAARc"]
[Mon Jul 20 06:32:36.888966 2026] [autoindex:error] [pid 940476:tid 940700] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:32:36.897209 2026] [security2:error] [pid 935758:tid 935963] [client 77.110.127.138:65508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZLcDxY_mIul-JSGowAAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:36.897320 2026] [security2:error] [pid 935758:tid 935963] [client 77.110.127.138:65508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZLcDxY_mIul-JSGowAAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:36.949559 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZBjVYcQxwGpYwZmoewAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:36.949716 2026] [security2:error] [pid 940476:tid 940692] [client 77.110.127.138:65473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZBjVYcQxwGpYwZmoewAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.046242 2026] [security2:error] [pid 940476:tid 940726] [client 50.116.65.227:31126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VZRjVYcQxwGpYwZmofQAAAHg"]
[Mon Jul 20 06:32:37.059324 2026] [security2:error] [pid 940476:tid 940668] [client 50.116.65.227:31134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VZRjVYcQxwGpYwZmofgAAAD4"]
[Mon Jul 20 06:32:37.117398 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:65510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZRjVYcQxwGpYwZmokwAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.117485 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:65510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZRjVYcQxwGpYwZmokwAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.140093 2026] [security2:error] [pid 940476:tid 940666] [client 50.116.65.227:31110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4VZBjVYcQxwGpYwZmodwAAADw"]
[Mon Jul 20 06:32:37.165294 2026] [security2:error] [pid 940476:tid 940695] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZBjVYcQxwGpYwZmoagAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.236742 2026] [proxy:error] [pid 940476:tid 940694] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:37.236827 2026] [proxy_http:error] [pid 940476:tid 940694] [client 34.73.38.214:50467] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:37.237486 2026] [proxy:error] [pid 940476:tid 940694] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:37.237522 2026] [proxy_http:error] [pid 940476:tid 940694] [client 34.73.38.214:50467] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:37.281234 2026] [security2:error] [pid 935758:tid 935959] [client 77.110.127.138:65478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/_inc/build/13184epu2b8y.php"] [unique_id "al4VZbcDxY_mIul-JSGo0QAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.324326 2026] [autoindex:error] [pid 940476:tid 940715] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/build/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:32:37.326612 2026] [autoindex:error] [pid 940476:tid 940733] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/build/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.353482 2026] [security2:error] [pid 940476:tid 940651] [client 50.116.65.227:31146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4VZRjVYcQxwGpYwZmowwAAAC0"]
[Mon Jul 20 06:32:37.507432 2026] [security2:error] [pid 940476:tid 940696] [client 77.110.127.138:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZRjVYcQxwGpYwZmo5QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.507528 2026] [security2:error] [pid 940476:tid 940696] [client 77.110.127.138:65512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZRjVYcQxwGpYwZmo5QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.511592 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:65499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZRjVYcQxwGpYwZmozQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.540215 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZRjVYcQxwGpYwZmo1AAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.551093 2026] [security2:error] [pid 940476:tid 940676] [client 104.234.53.93:28857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VZRjVYcQxwGpYwZmo6gAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:37.605512 2026] [security2:error] [pid 940476:tid 940635] [client 77.110.127.138:65487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/_inc/build/related-posts/6xxkdrviuo8z.php"] [unique_id "al4VZRjVYcQxwGpYwZmo7QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.744416 2026] [autoindex:error] [pid 940476:tid 940652] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/build/related-posts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:32:37.753332 2026] [autoindex:error] [pid 940476:tid 940720] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/build/related-posts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.831006 2026] [security2:error] [pid 940476:tid 940659] [client 77.110.127.138:65505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZRjVYcQxwGpYwZmo8AAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:37.862129 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZRjVYcQxwGpYwZmo9gAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.001845 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZrcDxY_mIul-JSGo7gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.001975 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZrcDxY_mIul-JSGo7gAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.183012 2026] [security2:error] [pid 940476:tid 940630] [client 77.110.127.138:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZhjVYcQxwGpYwZmpRQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.183135 2026] [security2:error] [pid 940476:tid 940630] [client 77.110.127.138:65504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZhjVYcQxwGpYwZmpRQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.339424 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:65520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZhjVYcQxwGpYwZmpUQAAAH0"]
[Mon Jul 20 06:32:38.339514 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:65520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZhjVYcQxwGpYwZmpUQAAAH0"]
[Mon Jul 20 06:32:38.415608 2026] [security2:error] [pid 940476:tid 940729] [client 14.225.17.146:53709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4VZRjVYcQxwGpYwZmoxgAAAHs"], referer: http://sarahholyfield.com/Old
[Mon Jul 20 06:32:38.447421 2026] [security2:error] [pid 940476:tid 940711] [client 77.110.127.138:65499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/competition/8ny75h7akept.php"] [unique_id "al4VZhjVYcQxwGpYwZmpawAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.499411 2026] [proxy:error] [pid 935758:tid 935938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:38.499487 2026] [proxy_http:error] [pid 935758:tid 935938] [client 34.73.38.214:64267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:38.500425 2026] [proxy:error] [pid 935758:tid 935938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:38.500462 2026] [proxy_http:error] [pid 935758:tid 935938] [client 34.73.38.214:64267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:38.672190 2026] [security2:error] [pid 935758:tid 935973] [client 14.225.17.146:52365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4VZbcDxY_mIul-JSGozgAAAV0"], referer: http://chestermonty.com/Old
[Mon Jul 20 06:32:38.772286 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZrcDxY_mIul-JSGpEwAAAUI"]
[Mon Jul 20 06:32:38.772424 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:65488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZrcDxY_mIul-JSGpEwAAAUI"]
[Mon Jul 20 06:32:38.825168 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZrcDxY_mIul-JSGpFQAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:38.825320 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:65469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZrcDxY_mIul-JSGpFQAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:39.055332 2026] [proxy:error] [pid 940476:tid 940627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:39.055412 2026] [proxy_http:error] [pid 940476:tid 940627] [client 34.73.38.214:55103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:39.056331 2026] [proxy:error] [pid 940476:tid 940627] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:39.056385 2026] [proxy_http:error] [pid 940476:tid 940627] [client 34.73.38.214:55103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:39.374312 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZhjVYcQxwGpYwZmpdQAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:39.407095 2026] [security2:error] [pid 935758:tid 935918] [client 77.110.127.138:65523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZrcDxY_mIul-JSGpDQAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:39.411092 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZhjVYcQxwGpYwZmpeQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:39.424727 2026] [security2:error] [pid 940476:tid 940700] [client 14.225.17.146:65055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4VZhjVYcQxwGpYwZmpfwAAAF4"]
[Mon Jul 20 06:32:39.553410 2026] [security2:error] [pid 940476:tid 940667] [client 14.225.17.146:61201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4VZhjVYcQxwGpYwZmpRAAAAD0"], referer: http://blaizeaccountingservices.com/Old
[Mon Jul 20 06:32:39.572026 2026] [security2:error] [pid 935758:tid 935966] [client 14.225.17.146:52205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4VZ7cDxY_mIul-JSGpMQAAAVY"], referer: https://chestermonty.com/Old
[Mon Jul 20 06:32:39.616503 2026] [security2:error] [pid 940476:tid 940678] [client 54.184.226.94:16652] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/"] [unique_id "al4VZxjVYcQxwGpYwZmpnwAAAEg"]
[Mon Jul 20 06:32:39.620674 2026] [security2:error] [pid 940476:tid 940726] [client 77.110.127.138:65500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZxjVYcQxwGpYwZmpoAAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:39.620799 2026] [security2:error] [pid 940476:tid 940726] [client 77.110.127.138:65500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VZxjVYcQxwGpYwZmpoAAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:39.772933 2026] [security2:error] [pid 940476:tid 940681] [client 171.60.139.123:60315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VZxjVYcQxwGpYwZmpsgAAAEs"]
[Mon Jul 20 06:32:39.773091 2026] [security2:error] [pid 940476:tid 940681] [client 171.60.139.123:60315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VZxjVYcQxwGpYwZmpsgAAAEs"]
[Mon Jul 20 06:32:39.856949 2026] [security2:error] [pid 940476:tid 940608] [client 103.131.71.86:34609] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.californiaperfumecompany.com"] [uri "/robots.txt"] [unique_id "al4VZxjVYcQxwGpYwZmpvQAAAAI"]
[Mon Jul 20 06:32:39.998903 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/hk2x01b1yxor.php"] [unique_id "al4VZxjVYcQxwGpYwZmpzgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:40.267900 2026] [security2:error] [pid 940476:tid 940677] [client 77.110.127.138:65474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZxjVYcQxwGpYwZmpwAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:40.268720 2026] [security2:error] [pid 940476:tid 940715] [client 45.116.69.230:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VaBjVYcQxwGpYwZmp4QAAAG0"]
[Mon Jul 20 06:32:40.268822 2026] [security2:error] [pid 940476:tid 940715] [client 45.116.69.230:52928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VaBjVYcQxwGpYwZmp4QAAAG0"]
[Mon Jul 20 06:32:40.321522 2026] [security2:error] [pid 935758:tid 935924] [client 14.225.17.146:65030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4VZrcDxY_mIul-JSGpFAAAASw"], referer: http://expertcultures.com/Old
[Mon Jul 20 06:32:40.370443 2026] [security2:error] [pid 940476:tid 940725] [client 54.184.226.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4VZxjVYcQxwGpYwZmpuQAAAHc"], referer: http://koaconsultants.com/?rnd=1784550759506
[Mon Jul 20 06:32:40.372065 2026] [security2:error] [pid 940476:tid 940668] [client 54.184.226.94:65366] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koaconsultants.com"] [uri "/"] [unique_id "al4VZxjVYcQxwGpYwZmptAAAAD4"], referer: http://koaconsultants.com/?rnd=1784550759506
[Mon Jul 20 06:32:40.419320 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZ7cDxY_mIul-JSGpSQAAAS4"], referer: 1'"3000
[Mon Jul 20 06:32:40.544668 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VZxjVYcQxwGpYwZmpywAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:40.572864 2026] [security2:error] [pid 940476:tid 940718] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VaBjVYcQxwGpYwZmp0QAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:40.627800 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:40.627841 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:58808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:40.628286 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:40.628307 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:58808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:40.898725 2026] [security2:error] [pid 940476:tid 940648] [client 45.157.112.60:26733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VaBjVYcQxwGpYwZmp9wAAACo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:32:40.943926 2026] [security2:error] [pid 940476:tid 940581] [remote 152.228.213.32:60230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4VaBjVYcQxwGpYwZmp-gAAUWg"]
[Mon Jul 20 06:32:41.129725 2026] [lsapi:warn] [pid 935758:tid 935843] [remote 13.219.67.125:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:32:41.130795 2026] [security2:error] [pid 940476:tid 940568] [remote 152.228.213.32:60230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4VaRjVYcQxwGpYwZmqBAAAQFs"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 06:32:41.215076 2026] [security2:error] [pid 935758:tid 935794] [remote 91.142.222.105:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4VabcDxY_mIul-JSGpbAABDSE"]
[Mon Jul 20 06:32:41.302910 2026] [security2:error] [pid 940476:tid 940705] [client 57.141.18.73:28242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VZBjVYcQxwGpYwZmoMgAAY0k"]
[Mon Jul 20 06:32:41.340687 2026] [security2:error] [pid 940476:tid 940635] [client 194.163.186.52:51386] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4VaRjVYcQxwGpYwZmqFQAAAB0"]
[Mon Jul 20 06:32:41.466816 2026] [security2:error] [pid 940476:tid 940718] [client 34.73.38.214:53607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VaRjVYcQxwGpYwZmqIAAAAHA"]
[Mon Jul 20 06:32:41.495363 2026] [security2:error] [pid 940476:tid 940626] [client 57.141.18.49:46682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VZBjVYcQxwGpYwZmoNgAAFAM"]
[Mon Jul 20 06:32:41.629103 2026] [security2:error] [pid 935758:tid 935776] [remote 91.142.222.105:52364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4VabcDxY_mIul-JSGpfQABgQ8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:32:41.784654 2026] [security2:error] [pid 935758:tid 935901] [client 194.163.186.52:51394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4VabcDxY_mIul-JSGphgAAARU"]
[Mon Jul 20 06:32:41.909132 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VaRjVYcQxwGpYwZmqJgAAADE"], referer: 1'"3000
[Mon Jul 20 06:32:42.169503 2026] [security2:error] [pid 935758:tid 935907] [client 57.141.18.109:64272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VZbcDxY_mIul-JSGoxwABGzQ"]
[Mon Jul 20 06:32:42.244800 2026] [security2:error] [pid 935758:tid 936010] [client 194.163.186.52:51404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4VarcDxY_mIul-JSGpnwAAAYI"]
[Mon Jul 20 06:32:42.314319 2026] [security2:error] [pid 935758:tid 936017] [client 103.131.71.86:16721] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.californiaperfumecompany.com"] [uri "/robots.txt"] [unique_id "al4VarcDxY_mIul-JSGppQAAAYk"]
[Mon Jul 20 06:32:42.734991 2026] [security2:error] [pid 940476:tid 940602] [remote 167.233.114.32:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VahjVYcQxwGpYwZmqVAAAIn0"]
[Mon Jul 20 06:32:42.735174 2026] [security2:error] [pid 940476:tid 940640] [client 167.233.114.32:38280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VahjVYcQxwGpYwZmqVAAAIn0"]
[Mon Jul 20 06:32:43.039132 2026] [security2:error] [pid 935758:tid 935972] [client 77.110.127.138:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Va7cDxY_mIul-JSGpuQAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:43.039281 2026] [security2:error] [pid 935758:tid 935972] [client 77.110.127.138:65457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Va7cDxY_mIul-JSGpuQAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:43.090820 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VaxjVYcQxwGpYwZmqagAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:43.090949 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:65511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VaxjVYcQxwGpYwZmqagAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:43.093566 2026] [security2:error] [pid 935758:tid 935803] [remote 124.55.178.99:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Va7cDxY_mIul-JSGpugABEio"]
[Mon Jul 20 06:32:43.116411 2026] [security2:error] [pid 940476:tid 940660] [client 14.225.17.146:52098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4VahjVYcQxwGpYwZmqYwAAADY"], referer: http://thesoloceos.com/Old
[Mon Jul 20 06:32:43.248860 2026] [security2:error] [pid 935758:tid 935899] [client 104.207.62.105:37121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Va7cDxY_mIul-JSGpwwAAARM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:43.306880 2026] [security2:error] [pid 940476:tid 940628] [client 34.73.38.214:52994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VaxjVYcQxwGpYwZmqcgAAABY"]
[Mon Jul 20 06:32:43.416206 2026] [security2:error] [pid 940476:tid 940657] [client 57.141.18.81:20558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VZhjVYcQxwGpYwZmpdgAAMwk"]
[Mon Jul 20 06:32:43.536103 2026] [security2:error] [pid 935758:tid 935834] [remote 124.55.178.99:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Va7cDxY_mIul-JSGp1AABLEk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:32:43.666082 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:49179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VaxjVYcQxwGpYwZmqhAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:43.666180 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:49179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VaxjVYcQxwGpYwZmqhAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:43.797703 2026] [security2:error] [pid 940476:tid 940675] [client 44.245.170.32:36378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4VaxjVYcQxwGpYwZmqjwAAAEU"]
[Mon Jul 20 06:32:43.875234 2026] [security2:error] [pid 935758:tid 935957] [client 65.111.27.5:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Va7cDxY_mIul-JSGp3AAAAU0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:43.889091 2026] [security2:error] [pid 940476:tid 940677] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VaxjVYcQxwGpYwZmqhQAAAEc"]
[Mon Jul 20 06:32:44.023210 2026] [security2:error] [pid 940476:tid 940728] [client 57.141.18.104:29322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VZxjVYcQxwGpYwZmpmAAAelE"]
[Mon Jul 20 06:32:44.107206 2026] [security2:error] [pid 940476:tid 940667] [client 14.225.17.146:52149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4VaxjVYcQxwGpYwZmqlgAAAD0"], referer: https://thesoloceos.com/Old
[Mon Jul 20 06:32:44.178684 2026] [security2:error] [pid 935758:tid 935917] [client 14.225.17.146:65143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4VarcDxY_mIul-JSGpmgAAASU"], referer: http://maplerespiteservices.com/Old
[Mon Jul 20 06:32:44.322799 2026] [security2:error] [pid 940476:tid 940670] [client 103.131.71.155:44207] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "304"] [hostname "www.californiaperfumecompany.com"] [uri "/products/cal_atomizer_sets_1.html"] [unique_id "al4VbBjVYcQxwGpYwZmqqgAAAEA"]
[Mon Jul 20 06:32:44.353361 2026] [security2:error] [pid 940476:tid 940635] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VbBjVYcQxwGpYwZmqogAAAB0"]
[Mon Jul 20 06:32:44.479680 2026] [security2:error] [pid 940476:tid 940681] [client 103.125.179.95:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VbBjVYcQxwGpYwZmqtgAAAEs"]
[Mon Jul 20 06:32:44.479804 2026] [security2:error] [pid 940476:tid 940681] [client 103.125.179.95:51635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VbBjVYcQxwGpYwZmqtgAAAEs"]
[Mon Jul 20 06:32:44.738814 2026] [security2:error] [pid 935758:tid 935943] [client 216.73.217.138:39229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VbLcDxY_mIul-JSGp-gABP1s"]
[Mon Jul 20 06:32:44.809167 2026] [security2:error] [pid 940476:tid 940690] [client 104.234.53.56:26601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VbBjVYcQxwGpYwZmqyAAAAFQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:44.879426 2026] [security2:error] [pid 940476:tid 940678] [client 57.141.18.22:24500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VaBjVYcQxwGpYwZmp3wAASCc"]
[Mon Jul 20 06:32:44.945210 2026] [security2:error] [pid 940476:tid 940618] [client 57.141.18.64:36198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VaBjVYcQxwGpYwZmp4AAADC4"]
[Mon Jul 20 06:32:45.103431 2026] [security2:error] [pid 940476:tid 940635] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VbBjVYcQxwGpYwZmq1wAAAB0"]
[Mon Jul 20 06:32:45.169971 2026] [security2:error] [pid 940476:tid 940617] [client 34.73.38.214:55292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VbRjVYcQxwGpYwZmq5gAAAAs"]
[Mon Jul 20 06:32:45.266796 2026] [security2:error] [pid 935758:tid 935905] [client 187.108.85.186:65092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VbbcDxY_mIul-JSGqDwAAARk"]
[Mon Jul 20 06:32:45.266897 2026] [security2:error] [pid 935758:tid 935905] [client 187.108.85.186:65092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VbbcDxY_mIul-JSGqDwAAARk"]
[Mon Jul 20 06:32:45.474325 2026] [security2:error] [pid 935758:tid 936009] [client 112.208.70.94:45402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VbbcDxY_mIul-JSGqHgAAAYE"]
[Mon Jul 20 06:32:45.474454 2026] [security2:error] [pid 935758:tid 936009] [client 112.208.70.94:45402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VbbcDxY_mIul-JSGqHgAAAYE"]
[Mon Jul 20 06:32:45.557530 2026] [security2:error] [pid 935758:tid 935993] [client 57.141.18.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VbbcDxY_mIul-JSGqFgAAAXE"]
[Mon Jul 20 06:32:45.597444 2026] [security2:error] [pid 935758:tid 935901] [client 65.111.31.218:17569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VbbcDxY_mIul-JSGqJwAAARU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:45.653724 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbRjVYcQxwGpYwZmq-AAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:45.653846 2026] [security2:error] [pid 940476:tid 940652] [client 77.110.127.138:65519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbRjVYcQxwGpYwZmq-AAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:45.693672 2026] [security2:error] [pid 935758:tid 935762] [remote 152.228.213.32:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VbbcDxY_mIul-JSGqKwABfQE"]
[Mon Jul 20 06:32:45.732241 2026] [security2:error] [pid 940476:tid 940609] [client 57.141.18.69:51806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VaRjVYcQxwGpYwZmqAwAAA3g"]
[Mon Jul 20 06:32:45.764190 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:49156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbRjVYcQxwGpYwZmq_AAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:45.764329 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:49156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbRjVYcQxwGpYwZmq_AAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:45.837819 2026] [security2:error] [pid 940476:tid 940628] [client 104.234.53.56:26601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VbRjVYcQxwGpYwZmrAAAAABY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:45.897838 2026] [security2:error] [pid 935758:tid 935802] [remote 152.228.213.32:51944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VbbcDxY_mIul-JSGqMQABYSk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:45.928811 2026] [security2:error] [pid 940476:tid 940569] [remote 95.217.78.234:57594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VbRjVYcQxwGpYwZmrBAAAb1w"]
[Mon Jul 20 06:32:46.033010 2026] [security2:error] [pid 940476:tid 940674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VbRjVYcQxwGpYwZmq_wAAAEQ"]
[Mon Jul 20 06:32:46.077541 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:49194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrCwAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.077638 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:49194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrCwAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.127977 2026] [security2:error] [pid 940476:tid 940624] [client 57.141.18.125:55256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VaRjVYcQxwGpYwZmqEwAAEjE"]
[Mon Jul 20 06:32:46.249528 2026] [security2:error] [pid 935758:tid 935960] [client 65.111.26.121:64495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VbrcDxY_mIul-JSGqQAAAAVA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:32:46.256529 2026] [security2:error] [pid 940476:tid 940681] [client 74.7.227.179:54894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VbhjVYcQxwGpYwZmrDgAAS2s"], referer: https://tejasenvironmental.com/p=575215
[Mon Jul 20 06:32:46.297491 2026] [security2:error] [pid 935758:tid 935986] [client 34.73.38.214:56449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VbrcDxY_mIul-JSGqRQAAAWo"]
[Mon Jul 20 06:32:46.396277 2026] [security2:error] [pid 940476:tid 940477] [remote 95.217.78.234:57594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VbhjVYcQxwGpYwZmrFQAAVgA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:46.435062 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:49195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqSQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.435163 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:49195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqSQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.491420 2026] [security2:error] [pid 935758:tid 935967] [client 50.116.65.227:34116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VbrcDxY_mIul-JSGqTgAAAVc"]
[Mon Jul 20 06:32:46.502149 2026] [security2:error] [pid 935758:tid 935974] [client 50.116.65.227:34130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VbrcDxY_mIul-JSGqTwAAAV4"]
[Mon Jul 20 06:32:46.608101 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:65524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqVQAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.608240 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:65524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqVQAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.652656 2026] [security2:error] [pid 940476:tid 940533] [remote 47.128.117.170:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zanjan-fromer.com"] [uri "/robots.txt"] [unique_id "al4VbhjVYcQxwGpYwZmrJwAAJjg"]
[Mon Jul 20 06:32:46.653645 2026] [security2:error] [pid 940476:tid 940622] [client 57.141.18.54:42780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VaRjVYcQxwGpYwZmqNQAAEHA"]
[Mon Jul 20 06:32:46.672141 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqVwAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.672294 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:65527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqVwAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.749886 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrKwAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.750006 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:49178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrKwAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.827096 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:49181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqYAAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.827228 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:49181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqYAAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.850475 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqYwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.850575 2026] [security2:error] [pid 935758:tid 935924] [client 77.110.127.138:49199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbrcDxY_mIul-JSGqYwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:46.880605 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:49185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrLAAAADE"]
[Mon Jul 20 06:32:46.880777 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:49185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrLAAAADE"]
[Mon Jul 20 06:32:46.927198 2026] [security2:error] [pid 940476:tid 940636] [client 39.48.81.23:50630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VbhjVYcQxwGpYwZmrLQAAAB4"]
[Mon Jul 20 06:32:46.927316 2026] [security2:error] [pid 940476:tid 940636] [client 39.48.81.23:50630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VbhjVYcQxwGpYwZmrLQAAAB4"]
[Mon Jul 20 06:32:46.938160 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:65513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrLwAAAAM"]
[Mon Jul 20 06:32:46.938264 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:65513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VbhjVYcQxwGpYwZmrLwAAAAM"]
[Mon Jul 20 06:32:47.065530 2026] [security2:error] [pid 935758:tid 935954] [client 57.141.18.117:48452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VarcDxY_mIul-JSGpqAABSiM"]
[Mon Jul 20 06:32:47.069787 2026] [security2:error] [pid 940476:tid 940680] [client 14.225.17.146:49783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4VbhjVYcQxwGpYwZmrCgAAAEo"], referer: http://claysharecon.com/Old
[Mon Jul 20 06:32:47.092450 2026] [security2:error] [pid 940476:tid 940659] [client 14.224.227.113:54478] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4VbxjVYcQxwGpYwZmrNgAAADU"]
[Mon Jul 20 06:32:47.269844 2026] [security2:error] [pid 940476:tid 940634] [client 74.208.214.194:43666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VbxjVYcQxwGpYwZmrPAAAABw"]
[Mon Jul 20 06:32:47.536176 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VbxjVYcQxwGpYwZmrPwAAAHU"]
[Mon Jul 20 06:32:47.598364 2026] [security2:error] [pid 935758:tid 935947] [client 197.186.66.42:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Vb7cDxY_mIul-JSGqiQAAAUM"]
[Mon Jul 20 06:32:47.604074 2026] [security2:error] [pid 940476:tid 940650] [client 14.225.17.146:55208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4VbxjVYcQxwGpYwZmrRQAAACw"], referer: http://dereckcastellon.com/Old
[Mon Jul 20 06:32:47.604827 2026] [security2:error] [pid 935758:tid 935947] [client 197.186.66.42:61143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Vb7cDxY_mIul-JSGqiQAAAUM"]
[Mon Jul 20 06:32:47.742224 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:49206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vb7cDxY_mIul-JSGqkgAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:47.742326 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:49206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vb7cDxY_mIul-JSGqkgAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:47.818629 2026] [security2:error] [pid 940476:tid 940631] [client 34.73.38.214:57669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VbxjVYcQxwGpYwZmrUAAAABk"]
[Mon Jul 20 06:32:48.023291 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:49209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VcLcDxY_mIul-JSGqmwAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:48.023381 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:49209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VcLcDxY_mIul-JSGqmwAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:48.165716 2026] [security2:error] [pid 940476:tid 940646] [client 57.141.18.79:23826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VaxjVYcQxwGpYwZmqfQAAKFM"]
[Mon Jul 20 06:32:48.169354 2026] [security2:error] [pid 940476:tid 940684] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VbxjVYcQxwGpYwZmrWgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:48.439191 2026] [security2:error] [pid 935758:tid 935922] [client 14.225.17.146:55190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4VcLcDxY_mIul-JSGqpAAAASo"], referer: http://longevityperformanceclinic.com/Old
[Mon Jul 20 06:32:48.694820 2026] [security2:error] [pid 940476:tid 940549] [remote 192.241.143.148:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4VcBjVYcQxwGpYwZmreQAAHEg"]
[Mon Jul 20 06:32:48.855226 2026] [security2:error] [pid 940476:tid 940512] [remote 192.241.143.148:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4VcBjVYcQxwGpYwZmrfgAAWiM"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:32:48.900154 2026] [security2:error] [pid 935758:tid 935897] [client 77.110.127.138:49191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VcLcDxY_mIul-JSGqvQAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:48.900244 2026] [security2:error] [pid 935758:tid 935897] [client 77.110.127.138:49191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VcLcDxY_mIul-JSGqvQAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:48.925925 2026] [lsapi:warn] [pid 940476:tid 940594] [remote 20.215.220.179:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:32:49.040062 2026] [security2:error] [pid 935758:tid 935812] [remote 91.142.222.105:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4VcbcDxY_mIul-JSGqwwABXzM"]
[Mon Jul 20 06:32:49.090638 2026] [security2:error] [pid 940476:tid 940698] [client 171.61.165.146:23782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VcRjVYcQxwGpYwZmrhQAAAFw"]
[Mon Jul 20 06:32:49.090828 2026] [security2:error] [pid 940476:tid 940698] [client 171.61.165.146:23782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VcRjVYcQxwGpYwZmrhQAAAFw"]
[Mon Jul 20 06:32:49.188937 2026] [security2:error] [pid 940476:tid 940654] [client 57.141.18.112:32184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VbBjVYcQxwGpYwZmqwAAAMBg"]
[Mon Jul 20 06:32:49.280822 2026] [security2:error] [pid 940476:tid 940658] [client 34.73.38.214:57519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VcRjVYcQxwGpYwZmriwAAADQ"]
[Mon Jul 20 06:32:49.292850 2026] [security2:error] [pid 940476:tid 940669] [client 223.185.13.213:28609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VcRjVYcQxwGpYwZmrjAAAAD8"]
[Mon Jul 20 06:32:49.292949 2026] [security2:error] [pid 940476:tid 940669] [client 223.185.13.213:28609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VcRjVYcQxwGpYwZmrjAAAAD8"]
[Mon Jul 20 06:32:49.490594 2026] [security2:error] [pid 935758:tid 935811] [remote 91.142.222.105:43980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4VcbcDxY_mIul-JSGq0wABFDI"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:32:50.095522 2026] [security2:error] [pid 935758:tid 936003] [client 104.234.53.88:64905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VcrcDxY_mIul-JSGq6AAAAXs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:50.174471 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:49197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VcrcDxY_mIul-JSGq7wAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:50.174588 2026] [security2:error] [pid 935758:tid 936005] [client 77.110.127.138:49197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VcrcDxY_mIul-JSGq7wAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:50.233002 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VcrcDxY_mIul-JSGq5wAAAR4"]
[Mon Jul 20 06:32:50.375668 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:49228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VchjVYcQxwGpYwZmrwwAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:50.375776 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:49228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VchjVYcQxwGpYwZmrwwAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:50.380359 2026] [security2:error] [pid 940476:tid 940662] [client 171.60.139.123:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VchjVYcQxwGpYwZmrwgAAADg"]
[Mon Jul 20 06:32:50.380601 2026] [security2:error] [pid 940476:tid 940662] [client 171.60.139.123:60841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VchjVYcQxwGpYwZmrwgAAADg"]
[Mon Jul 20 06:32:50.384793 2026] [security2:error] [pid 940476:tid 940582] [remote 130.185.118.215:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VchjVYcQxwGpYwZmrxAAASGk"]
[Mon Jul 20 06:32:50.404699 2026] [security2:error] [pid 935758:tid 935925] [client 39.48.81.23:51127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VcrcDxY_mIul-JSGq-QAAAS0"]
[Mon Jul 20 06:32:50.404861 2026] [security2:error] [pid 935758:tid 935925] [client 39.48.81.23:51127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VcrcDxY_mIul-JSGq-QAAAS0"]
[Mon Jul 20 06:32:50.558526 2026] [security2:error] [pid 940476:tid 940635] [client 50.116.65.227:55634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4VchjVYcQxwGpYwZmrywAAAB0"]
[Mon Jul 20 06:32:50.561831 2026] [security2:error] [pid 935758:tid 935893] [client 14.225.17.146:61700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4VcLcDxY_mIul-JSGqwQAAAQ0"], referer: http://recruitinginsight.us/Old
[Mon Jul 20 06:32:50.583501 2026] [security2:error] [pid 940476:tid 940705] [client 14.225.17.146:60976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4VchjVYcQxwGpYwZmrtwAAAGM"], referer: http://guidehunting.com/Old
[Mon Jul 20 06:32:50.584096 2026] [security2:error] [pid 940476:tid 940513] [remote 130.185.118.215:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VchjVYcQxwGpYwZmrzgAADSQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:32:50.606023 2026] [security2:error] [pid 940476:tid 940668] [client 57.141.18.10:50468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VbhjVYcQxwGpYwZmrDAAAPlo"]
[Mon Jul 20 06:32:50.785976 2026] [security2:error] [pid 940476:tid 940598] [remote 84.247.172.23:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VchjVYcQxwGpYwZmr1AAAYHk"]
[Mon Jul 20 06:32:50.908567 2026] [security2:error] [pid 940476:tid 940719] [client 45.116.69.230:53468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VchjVYcQxwGpYwZmr2gAAAHE"]
[Mon Jul 20 06:32:50.908730 2026] [security2:error] [pid 940476:tid 940719] [client 45.116.69.230:53468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VchjVYcQxwGpYwZmr2gAAAHE"]
[Mon Jul 20 06:32:50.964167 2026] [security2:error] [pid 940476:tid 940621] [client 34.73.38.214:53245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VchjVYcQxwGpYwZmr4gAAAA8"]
[Mon Jul 20 06:32:51.281149 2026] [ssl:error] [pid 935758:tid 936014] [client 109.53.71.144:64902] AH02032: Hostname www.peycosoluciones.com provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:32:51.412360 2026] [security2:error] [pid 935758:tid 935899] [client 34.74.185.202:51229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Vc7cDxY_mIul-JSGrJAAAARM"]
[Mon Jul 20 06:32:51.648630 2026] [security2:error] [pid 935758:tid 935909] [client 14.225.17.146:62028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Vc7cDxY_mIul-JSGrIwAAAR0"], referer: https://guidehunting.com/Old
[Mon Jul 20 06:32:51.831548 2026] [security2:error] [pid 940476:tid 940706] [client 34.74.185.202:60716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VcxjVYcQxwGpYwZmsEwAAAGQ"]
[Mon Jul 20 06:32:51.919598 2026] [security2:error] [pid 940476:tid 940625] [client 57.141.18.81:25962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VbxjVYcQxwGpYwZmrSwAAEyA"]
[Mon Jul 20 06:32:52.053439 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdBjVYcQxwGpYwZmsHQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:52.053527 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:49236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdBjVYcQxwGpYwZmsHQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:52.079175 2026] [security2:error] [pid 940476:tid 940586] [remote 84.247.172.23:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VdBjVYcQxwGpYwZmsHgAAdm0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:32:52.146593 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:49237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdBjVYcQxwGpYwZmsHwAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:52.146689 2026] [security2:error] [pid 940476:tid 940699] [client 77.110.127.138:49237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdBjVYcQxwGpYwZmsHwAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:52.442572 2026] [security2:error] [pid 940476:tid 940712] [client 14.225.17.146:61961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4VdBjVYcQxwGpYwZmsKAAAAGo"], referer: http://carolinapressurewashers.com/Old
[Mon Jul 20 06:32:52.470839 2026] [security2:error] [pid 940476:tid 940606] [client 34.74.185.202:62924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VdBjVYcQxwGpYwZmsOgAAAAA"]
[Mon Jul 20 06:32:52.575575 2026] [security2:error] [pid 935758:tid 935948] [client 34.73.38.214:65076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VdLcDxY_mIul-JSGrTQAAAUQ"]
[Mon Jul 20 06:32:52.810658 2026] [security2:error] [pid 940476:tid 940666] [client 57.141.18.19:40102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VcBjVYcQxwGpYwZmrbQAAPG8"]
[Mon Jul 20 06:32:52.867149 2026] [security2:error] [pid 940476:tid 940633] [client 57.141.18.31:59706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VcBjVYcQxwGpYwZmrbgAAGzc"]
[Mon Jul 20 06:32:53.128155 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsWQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.128265 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:49208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsWQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.149967 2026] [security2:error] [pid 940476:tid 940642] [client 34.74.185.202:61568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VdRjVYcQxwGpYwZmsWwAAACQ"]
[Mon Jul 20 06:32:53.230199 2026] [security2:error] [pid 940476:tid 940669] [client 77.110.127.138:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsXgAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.230376 2026] [security2:error] [pid 940476:tid 940669] [client 77.110.127.138:49210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsXgAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.287217 2026] [security2:error] [pid 940476:tid 940656] [client 77.110.127.138:49212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsXwAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.287390 2026] [security2:error] [pid 940476:tid 940656] [client 77.110.127.138:49212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsXwAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.381784 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VdRjVYcQxwGpYwZmsUAAAAFI"]
[Mon Jul 20 06:32:53.420106 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VdRjVYcQxwGpYwZmsXAAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.545276 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:49247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsbAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.545367 2026] [security2:error] [pid 940476:tid 940681] [client 77.110.127.138:49247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsbAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.693781 2026] [security2:error] [pid 940476:tid 940627] [client 34.74.185.202:49510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VdRjVYcQxwGpYwZmsdgAAABU"]
[Mon Jul 20 06:32:53.744272 2026] [security2:error] [pid 940476:tid 940714] [client 77.110.127.138:49250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsfAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.744414 2026] [security2:error] [pid 940476:tid 940714] [client 77.110.127.138:49250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VdRjVYcQxwGpYwZmsfAAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:53.779680 2026] [security2:error] [pid 940476:tid 940696] [client 14.225.17.146:55761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4VdRjVYcQxwGpYwZmsXQAAAFo"], referer: http://laceycaraccident.com/Old
[Mon Jul 20 06:32:53.996677 2026] [proxy:error] [pid 940476:tid 940722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:53.996780 2026] [proxy_http:error] [pid 940476:tid 940722] [client 34.73.38.214:52603] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:53.998302 2026] [proxy:error] [pid 940476:tid 940722] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:53.998357 2026] [proxy_http:error] [pid 940476:tid 940722] [client 34.73.38.214:52603] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:54.064366 2026] [security2:error] [pid 940476:tid 940683] [client 34.74.185.202:61699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VdhjVYcQxwGpYwZmskAAAAE0"]
[Mon Jul 20 06:32:54.100481 2026] [security2:error] [pid 940476:tid 940653] [client 54.81.157.232:59286] ModSecurity: Access denied with code 406 (phase 1). String match "User-Agent: " at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "380"] [id "900242"] [msg "Fake UA :: User-Agent at start of UA"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4VdhjVYcQxwGpYwZmskwAAAC8"]
[Mon Jul 20 06:32:54.269245 2026] [security2:error] [pid 940476:tid 940490] [remote 100.42.189.89:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VdhjVYcQxwGpYwZmsmAAAOw0"]
[Mon Jul 20 06:32:54.269374 2026] [security2:error] [pid 940476:tid 940665] [client 100.42.189.89:51804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VdhjVYcQxwGpYwZmsmAAAOw0"]
[Mon Jul 20 06:32:54.341459 2026] [security2:error] [pid 940476:tid 940673] [client 34.74.185.202:55857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VdhjVYcQxwGpYwZmsmQAAAEM"]
[Mon Jul 20 06:32:54.430012 2026] [security2:error] [pid 935758:tid 935958] [client 34.73.38.214:55527] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VdrcDxY_mIul-JSGrkwAAAU4"]
[Mon Jul 20 06:32:54.537542 2026] [security2:error] [pid 935758:tid 935820] [remote 95.217.78.234:47908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VdrcDxY_mIul-JSGrnAABQzs"]
[Mon Jul 20 06:32:54.537663 2026] [security2:error] [pid 935758:tid 935947] [client 95.217.78.234:47908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VdrcDxY_mIul-JSGrnAABQzs"]
[Mon Jul 20 06:32:54.576140 2026] [core:error] [pid 935758:tid 935916] [client 152.32.170.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:32:54.576165 2026] [core:error] [pid 935758:tid 935916] [client 152.32.170.230:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:32:54.653338 2026] [security2:error] [pid 935758:tid 935900] [client 114.119.136.139:62841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "youpositive.co"] [uri "/ar/img_7463185437"] [unique_id "al4VdrcDxY_mIul-JSGrpgAAARQ"], referer: https://youpositive.co/en/img_7463185437
[Mon Jul 20 06:32:54.851668 2026] [security2:error] [pid 940476:tid 940626] [client 66.249.68.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4VdRjVYcQxwGpYwZmsVAAAABQ"]
[Mon Jul 20 06:32:55.239528 2026] [security2:error] [pid 940476:tid 940651] [client 103.125.179.95:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VdxjVYcQxwGpYwZmstwAAAC0"]
[Mon Jul 20 06:32:55.239637 2026] [security2:error] [pid 940476:tid 940651] [client 103.125.179.95:52109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VdxjVYcQxwGpYwZmstwAAAC0"]
[Mon Jul 20 06:32:55.325978 2026] [security2:error] [pid 940476:tid 940615] [client 34.74.185.202:50238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VdxjVYcQxwGpYwZmsugAAAAk"]
[Mon Jul 20 06:32:55.500970 2026] [proxy:error] [pid 940476:tid 940629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:55.501052 2026] [proxy_http:error] [pid 940476:tid 940629] [client 34.73.38.214:51430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:55.501683 2026] [proxy:error] [pid 940476:tid 940629] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:55.501719 2026] [proxy_http:error] [pid 940476:tid 940629] [client 34.73.38.214:51430] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:55.544606 2026] [security2:error] [pid 935758:tid 935994] [client 14.225.17.146:51733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4VdrcDxY_mIul-JSGrowAAAXI"], referer: http://retzkolonglogistics.com/Old
[Mon Jul 20 06:32:55.690534 2026] [security2:error] [pid 935758:tid 935985] [client 57.141.18.49:45084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vc7cDxY_mIul-JSGrFgABaUQ"]
[Mon Jul 20 06:32:55.851985 2026] [security2:error] [pid 940476:tid 940628] [client 34.73.38.214:52457] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.membresiabeyou.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VdxjVYcQxwGpYwZmszAAAABY"]
[Mon Jul 20 06:32:55.935139 2026] [security2:error] [pid 940476:tid 940648] [client 14.225.17.146:55670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4VdhjVYcQxwGpYwZmsowAAACo"], referer: http://ncsynchro.com/Old
[Mon Jul 20 06:32:55.944307 2026] [security2:error] [pid 940476:tid 940725] [client 187.108.85.186:49237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VdxjVYcQxwGpYwZmszgAAAHc"]
[Mon Jul 20 06:32:55.944427 2026] [security2:error] [pid 940476:tid 940725] [client 187.108.85.186:49237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VdxjVYcQxwGpYwZmszgAAAHc"]
[Mon Jul 20 06:32:56.169439 2026] [security2:error] [pid 940476:tid 940656] [client 106.219.188.178:53917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VeBjVYcQxwGpYwZms2gAAADI"]
[Mon Jul 20 06:32:56.169549 2026] [security2:error] [pid 940476:tid 940656] [client 106.219.188.178:53917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VeBjVYcQxwGpYwZms2gAAADI"]
[Mon Jul 20 06:32:56.364718 2026] [security2:error] [pid 940476:tid 940699] [client 34.74.185.202:64707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VeBjVYcQxwGpYwZms4wAAAF0"]
[Mon Jul 20 06:32:56.416835 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeBjVYcQxwGpYwZms5QAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.416969 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeBjVYcQxwGpYwZms5QAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.422626 2026] [security2:error] [pid 940476:tid 940691] [client 77.110.127.138:49263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeBjVYcQxwGpYwZms6AAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.422719 2026] [security2:error] [pid 940476:tid 940691] [client 77.110.127.138:49263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeBjVYcQxwGpYwZms6AAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.450558 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:56.450649 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:63523] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:56.451363 2026] [proxy:error] [pid 940476:tid 940615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:56.451419 2026] [proxy_http:error] [pid 940476:tid 940615] [client 34.73.38.214:63523] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:56.576938 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VeBjVYcQxwGpYwZms4gAAAHQ"]
[Mon Jul 20 06:32:56.727634 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:49267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeLcDxY_mIul-JSGr8QAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.727744 2026] [security2:error] [pid 935758:tid 936001] [client 77.110.127.138:49267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeLcDxY_mIul-JSGr8QAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.869582 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeBjVYcQxwGpYwZms-gAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:56.869742 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:49268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VeBjVYcQxwGpYwZms-gAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:57.028867 2026] [proxy:error] [pid 935758:tid 935932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:57.028916 2026] [proxy_http:error] [pid 935758:tid 935932] [client 34.73.38.214:56962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:57.029342 2026] [proxy:error] [pid 935758:tid 935932] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:32:57.029365 2026] [proxy_http:error] [pid 935758:tid 935932] [client 34.73.38.214:56962] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:32:57.034397 2026] [security2:error] [pid 935758:tid 935966] [client 34.74.185.202:61022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VebcDxY_mIul-JSGr_QAAAVY"]
[Mon Jul 20 06:32:57.066758 2026] [security2:error] [pid 935758:tid 935906] [client 14.225.17.146:54531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4VeLcDxY_mIul-JSGr9AAAARo"], referer: http://nurturemarple.co.uk/Old
[Mon Jul 20 06:32:57.071206 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VeLcDxY_mIul-JSGr4AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:57.118884 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VeBjVYcQxwGpYwZmtAAAAAA4"]
[Mon Jul 20 06:32:57.412577 2026] [security2:error] [pid 935758:tid 935923] [client 15.237.142.234:24564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VebcDxY_mIul-JSGsEgAAASs"]
[Mon Jul 20 06:32:57.520706 2026] [security2:error] [pid 935758:tid 935926] [client 34.74.185.202:54189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VebcDxY_mIul-JSGsFQAAAS4"]
[Mon Jul 20 06:32:57.547160 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VebcDxY_mIul-JSGsDQAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:32:57.669450 2026] [security2:error] [pid 940476:tid 940623] [client 57.141.18.8:23004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VdRjVYcQxwGpYwZmsZQAAESU"]
[Mon Jul 20 06:32:57.882563 2026] [security2:error] [pid 935758:tid 935991] [client 15.237.142.234:24566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VebcDxY_mIul-JSGsIQAAAW8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:32:57.961672 2026] [security2:error] [pid 940476:tid 940683] [client 14.225.17.146:51786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4VeRjVYcQxwGpYwZmtLgAAAE0"], referer: http://jvcmotorsports.com/Old
[Mon Jul 20 06:32:58.031228 2026] [security2:error] [pid 935758:tid 935969] [client 14.225.17.146:63564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4VebcDxY_mIul-JSGsIgAAAVk"], referer: https://nurturemarple.co.uk/Old
[Mon Jul 20 06:32:58.038338 2026] [security2:error] [pid 940476:tid 940728] [client 34.74.185.202:59181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VehjVYcQxwGpYwZmtPQAAAHo"]
[Mon Jul 20 06:32:58.039691 2026] [security2:error] [pid 935758:tid 935977] [client 104.234.53.89:46113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VercDxY_mIul-JSGsJAAAAWE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:32:58.121028 2026] [security2:error] [pid 940476:tid 940631] [client 57.141.18.88:36884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VdRjVYcQxwGpYwZmsfQAAGRY"]
[Mon Jul 20 06:32:58.142451 2026] [security2:error] [pid 935758:tid 936005] [client 34.73.38.214:58798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VercDxY_mIul-JSGsKwAAAX0"]
[Mon Jul 20 06:32:58.264543 2026] [security2:error] [pid 935758:tid 935946] [client 197.186.66.42:61632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VercDxY_mIul-JSGsMgAAAUI"]
[Mon Jul 20 06:32:58.264641 2026] [security2:error] [pid 935758:tid 935946] [client 197.186.66.42:61632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VercDxY_mIul-JSGsMgAAAUI"]
[Mon Jul 20 06:32:58.467765 2026] [security2:error] [pid 940476:tid 940654] [client 50.116.65.227:55814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VehjVYcQxwGpYwZmtUwAAADA"]
[Mon Jul 20 06:32:58.480369 2026] [security2:error] [pid 940476:tid 940651] [client 50.116.65.227:55830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VehjVYcQxwGpYwZmtVQAAAC0"]
[Mon Jul 20 06:32:58.594352 2026] [security2:error] [pid 940476:tid 940678] [client 34.74.185.202:60369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.oqw.bur.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VehjVYcQxwGpYwZmtXQAAAEg"]
[Mon Jul 20 06:32:58.655826 2026] [security2:error] [pid 935758:tid 935981] [client 57.141.18.100:40586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VdrcDxY_mIul-JSGrjAABZQM"]
[Mon Jul 20 06:32:58.687709 2026] [security2:error] [pid 940476:tid 940692] [client 152.32.170.230:43490] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/favicon.ico"] [unique_id "al4VehjVYcQxwGpYwZmtZAAAAFY"]
[Mon Jul 20 06:32:58.735922 2026] [security2:error] [pid 935758:tid 936007] [client 57.141.18.115:45828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VdrcDxY_mIul-JSGrlwABf3Q"]
[Mon Jul 20 06:32:58.762945 2026] [security2:error] [pid 940476:tid 940685] [client 112.208.70.94:45885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VehjVYcQxwGpYwZmtZwAAAE8"]
[Mon Jul 20 06:32:58.763089 2026] [security2:error] [pid 940476:tid 940685] [client 112.208.70.94:45885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VehjVYcQxwGpYwZmtZwAAAE8"]
[Mon Jul 20 06:32:58.792372 2026] [security2:error] [pid 940476:tid 940665] [client 14.225.17.146:50783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4VehjVYcQxwGpYwZmtWAAAADs"], referer: http://massagelacey.com/Old
[Mon Jul 20 06:32:59.003284 2026] [security2:error] [pid 940476:tid 940613] [client 50.116.65.227:55860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VehjVYcQxwGpYwZmtagAAAAc"]
[Mon Jul 20 06:32:59.003551 2026] [security2:error] [pid 935758:tid 935978] [client 34.74.185.202:61045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Ve7cDxY_mIul-JSGsRgAAAWI"]
[Mon Jul 20 06:32:59.212879 2026] [security2:error] [pid 940476:tid 940728] [client 50.116.65.227:53660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VexjVYcQxwGpYwZmtdQAAAHo"]
[Mon Jul 20 06:32:59.224545 2026] [security2:error] [pid 940476:tid 940717] [client 34.73.38.214:64609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VexjVYcQxwGpYwZmtgwAAAG8"]
[Mon Jul 20 06:32:59.428008 2026] [security2:error] [pid 940476:tid 940711] [client 152.32.170.230:43608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/robots.txt"] [unique_id "al4VexjVYcQxwGpYwZmtkAAAAGk"]
[Mon Jul 20 06:32:59.428692 2026] [security2:error] [pid 940476:tid 940620] [client 152.32.170.230:43606] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "cpcalendars.transamericagrid.com"] [uri "/sitemap.xml"] [unique_id "al4VexjVYcQxwGpYwZmtkQAAAA4"]
[Mon Jul 20 06:32:59.598843 2026] [security2:error] [pid 940476:tid 940555] [remote 91.212.174.124:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.174.212.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VexjVYcQxwGpYwZmtnAAABU4"]
[Mon Jul 20 06:32:59.666496 2026] [security2:error] [pid 935758:tid 936012] [client 57.141.18.41:26310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vd7cDxY_mIul-JSGrtQABhEk"]
[Mon Jul 20 06:32:59.821408 2026] [security2:error] [pid 940476:tid 940524] [remote 57.141.18.112:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3480050"] [unique_id "al4VexjVYcQxwGpYwZmtsAAAAy8"]
[Mon Jul 20 06:33:00.042086 2026] [security2:error] [pid 935758:tid 935944] [client 223.185.13.213:1698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VfLcDxY_mIul-JSGsWAAAAUA"]
[Mon Jul 20 06:33:00.042307 2026] [security2:error] [pid 935758:tid 935944] [client 223.185.13.213:1698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VfLcDxY_mIul-JSGsWAAAAUA"]
[Mon Jul 20 06:33:00.234508 2026] [security2:error] [pid 940476:tid 940733] [client 34.74.185.202:59045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VfBjVYcQxwGpYwZmtwAAAAH8"]
[Mon Jul 20 06:33:00.570738 2026] [security2:error] [pid 940476:tid 940603] [remote 91.212.174.124:38350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.174.212.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VfBjVYcQxwGpYwZmt1AAAEX4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:33:00.607429 2026] [security2:error] [pid 935758:tid 935994] [client 34.73.38.214:60766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VfLcDxY_mIul-JSGsZQAAAXI"]
[Mon Jul 20 06:33:00.952096 2026] [security2:error] [pid 935758:tid 935931] [client 34.74.185.202:58875] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VfLcDxY_mIul-JSGsbgAAATM"]
[Mon Jul 20 06:33:01.141603 2026] [security2:error] [pid 940476:tid 940710] [client 171.60.139.123:61368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmt8wAAAGg"]
[Mon Jul 20 06:33:01.141720 2026] [security2:error] [pid 940476:tid 940710] [client 171.60.139.123:61368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmt8wAAAGg"]
[Mon Jul 20 06:33:01.172164 2026] [security2:error] [pid 940476:tid 940638] [client 39.48.81.23:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmt9AAAACA"]
[Mon Jul 20 06:33:01.172244 2026] [security2:error] [pid 940476:tid 940638] [client 39.48.81.23:51620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmt9AAAACA"]
[Mon Jul 20 06:33:01.264558 2026] [security2:error] [pid 940476:tid 940699] [client 171.61.165.146:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmt-AAAAF0"]
[Mon Jul 20 06:33:01.264686 2026] [security2:error] [pid 940476:tid 940699] [client 171.61.165.146:10574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmt-AAAAF0"]
[Mon Jul 20 06:33:01.443783 2026] [security2:error] [pid 935758:tid 935983] [client 20.197.192.193:44830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VfbcDxY_mIul-JSGsdgAAAWc"]
[Mon Jul 20 06:33:01.443892 2026] [security2:error] [pid 935758:tid 935983] [client 20.197.192.193:44830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VfbcDxY_mIul-JSGsdgAAAWc"]
[Mon Jul 20 06:33:01.575533 2026] [security2:error] [pid 940476:tid 940667] [client 45.116.69.230:54030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmuFwAAAD0"]
[Mon Jul 20 06:33:01.575661 2026] [security2:error] [pid 940476:tid 940667] [client 45.116.69.230:54030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VfRjVYcQxwGpYwZmuFwAAAD0"]
[Mon Jul 20 06:33:01.660360 2026] [security2:error] [pid 940476:tid 940647] [client 57.141.18.110:23862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VeBjVYcQxwGpYwZms_AAAKTE"]
[Mon Jul 20 06:33:01.725132 2026] [security2:error] [pid 940476:tid 940608] [client 34.74.185.202:61042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VfRjVYcQxwGpYwZmuGwAAAAI"]
[Mon Jul 20 06:33:01.817151 2026] [security2:error] [pid 940476:tid 940628] [client 34.73.38.214:64877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VfRjVYcQxwGpYwZmuJAAAABY"]
[Mon Jul 20 06:33:01.846105 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:49274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfbcDxY_mIul-JSGsfQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:01.846222 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:49274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfbcDxY_mIul-JSGsfQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:01.894333 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfRjVYcQxwGpYwZmuJgAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:01.894438 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfRjVYcQxwGpYwZmuJgAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:01.896796 2026] [security2:error] [pid 940476:tid 940658] [client 77.110.127.138:49286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfRjVYcQxwGpYwZmuKAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:01.896883 2026] [security2:error] [pid 940476:tid 940658] [client 77.110.127.138:49286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfRjVYcQxwGpYwZmuKAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:02.132764 2026] [proxy:error] [pid 940476:tid 940720] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:02.132837 2026] [proxy_http:error] [pid 940476:tid 940720] [client 34.73.38.214:65460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:02.133810 2026] [proxy:error] [pid 940476:tid 940720] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:02.133841 2026] [proxy_http:error] [pid 940476:tid 940720] [client 34.73.38.214:65460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:02.144402 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfhjVYcQxwGpYwZmuOQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:02.144532 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfhjVYcQxwGpYwZmuOQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:02.195743 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VfRjVYcQxwGpYwZmuLgAAAA8"]
[Mon Jul 20 06:33:02.228592 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VfRjVYcQxwGpYwZmuLwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:02.481269 2026] [security2:error] [pid 940476:tid 940723] [client 57.141.18.64:55848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VeRjVYcQxwGpYwZmtGwAAdR4"]
[Mon Jul 20 06:33:02.491115 2026] [security2:error] [pid 935758:tid 935924] [client 34.74.185.202:65503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VfrcDxY_mIul-JSGsjQAAASw"]
[Mon Jul 20 06:33:02.619598 2026] [security2:error] [pid 935758:tid 935993] [client 14.225.17.146:63977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4VfrcDxY_mIul-JSGsiwAAAXE"], referer: http://myspineworld.com/Old
[Mon Jul 20 06:33:02.673787 2026] [security2:error] [pid 935758:tid 935895] [client 49.13.130.29:55386] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4VfrcDxY_mIul-JSGsjwAAAQ8"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:33:02.900854 2026] [security2:error] [pid 940476:tid 940660] [client 104.234.53.66:49735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VfhjVYcQxwGpYwZmuYAAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:02.976463 2026] [security2:error] [pid 935758:tid 935815] [remote 57.141.18.114:47988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4927482"] [unique_id "al4VfrcDxY_mIul-JSGsnAABEDY"]
[Mon Jul 20 06:33:03.003040 2026] [security2:error] [pid 940476:tid 940730] [client 57.141.18.24:57070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VeRjVYcQxwGpYwZmtOAAAfDM"]
[Mon Jul 20 06:33:03.078413 2026] [security2:error] [pid 940476:tid 940712] [client 57.141.18.102:56438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VeRjVYcQxwGpYwZmtOQAAah8"]
[Mon Jul 20 06:33:03.207631 2026] [security2:error] [pid 940476:tid 940662] [client 34.74.185.202:60160] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VfxjVYcQxwGpYwZmubwAAADg"]
[Mon Jul 20 06:33:03.591305 2026] [security2:error] [pid 935758:tid 935941] [client 14.225.17.146:61559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Vf7cDxY_mIul-JSGsqgAAAT0"], referer: https://myspineworld.com/Old
[Mon Jul 20 06:33:03.645434 2026] [security2:error] [pid 935758:tid 935844] [remote 130.51.180.8:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Vf7cDxY_mIul-JSGsrAABVFM"]
[Mon Jul 20 06:33:03.740914 2026] [security2:error] [pid 940476:tid 940633] [client 14.225.17.146:50668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4VfxjVYcQxwGpYwZmuhQAAABs"], referer: http://koaconsultants.com/Old
[Mon Jul 20 06:33:03.819279 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:49301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfxjVYcQxwGpYwZmukQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:03.819384 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:49301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfxjVYcQxwGpYwZmukQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:03.830526 2026] [security2:error] [pid 935758:tid 935803] [remote 130.51.180.8:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Vf7cDxY_mIul-JSGstQABFio"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:33:03.847589 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:49305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfxjVYcQxwGpYwZmumQAAACY"]
[Mon Jul 20 06:33:03.847716 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:49305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VfxjVYcQxwGpYwZmumQAAACY"]
[Mon Jul 20 06:33:03.848521 2026] [security2:error] [pid 940476:tid 940663] [client 34.73.38.214:58722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VfxjVYcQxwGpYwZmumgAAADk"]
[Mon Jul 20 06:33:04.075310 2026] [security2:error] [pid 940476:tid 940625] [client 34.74.185.202:51606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VgBjVYcQxwGpYwZmuswAAABM"]
[Mon Jul 20 06:33:04.155258 2026] [security2:error] [pid 940476:tid 940617] [client 57.141.18.69:61128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VexjVYcQxwGpYwZmthwAAC1o"]
[Mon Jul 20 06:33:04.192044 2026] [proxy:error] [pid 940476:tid 940650] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:04.192141 2026] [proxy_http:error] [pid 940476:tid 940650] [client 34.73.38.214:51035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:04.193132 2026] [proxy:error] [pid 940476:tid 940650] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:04.193175 2026] [proxy_http:error] [pid 940476:tid 940650] [client 34.73.38.214:51035] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:04.377188 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VfxjVYcQxwGpYwZmumAAAAAo"]
[Mon Jul 20 06:33:04.559773 2026] [security2:error] [pid 940476:tid 940719] [client 77.110.127.138:49306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VgBjVYcQxwGpYwZmu1AAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:04.559907 2026] [security2:error] [pid 940476:tid 940719] [client 77.110.127.138:49306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VgBjVYcQxwGpYwZmu1AAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:04.559905 2026] [security2:error] [pid 940476:tid 940700] [client 14.225.17.146:50675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4VfhjVYcQxwGpYwZmuPgAAAF4"], referer: http://younutrition.gr/Old
[Mon Jul 20 06:33:04.587383 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VfxjVYcQxwGpYwZmumwAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:04.758619 2026] [security2:error] [pid 940476:tid 940626] [client 34.73.38.214:63141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VgBjVYcQxwGpYwZmu3gAAABQ"]
[Mon Jul 20 06:33:04.766138 2026] [security2:error] [pid 940476:tid 940610] [client 34.74.185.202:55304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VgBjVYcQxwGpYwZmu3wAAAAQ"]
[Mon Jul 20 06:33:04.894204 2026] [security2:error] [pid 940476:tid 940698] [client 57.141.18.91:51122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VexjVYcQxwGpYwZmtuAAAXGg"]
[Mon Jul 20 06:33:04.989936 2026] [proxy:error] [pid 940476:tid 940616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:04.990010 2026] [proxy_http:error] [pid 940476:tid 940616] [client 34.73.38.214:51974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:04.990480 2026] [proxy:error] [pid 940476:tid 940616] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:04.990512 2026] [proxy_http:error] [pid 940476:tid 940616] [client 34.73.38.214:51974] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:05.096530 2026] [security2:error] [pid 940476:tid 940710] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VgBjVYcQxwGpYwZmu5QAAAGg"]
[Mon Jul 20 06:33:05.107842 2026] [security2:error] [pid 940476:tid 940652] [client 104.234.53.56:52841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VgRjVYcQxwGpYwZmu9gAAAC4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:05.146961 2026] [security2:error] [pid 940476:tid 940542] [remote 8.217.108.67:50192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VgRjVYcQxwGpYwZmvAQAAeEE"]
[Mon Jul 20 06:33:05.147222 2026] [security2:error] [pid 940476:tid 940726] [client 8.217.108.67:50192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VgRjVYcQxwGpYwZmvAQAAeEE"]
[Mon Jul 20 06:33:05.215612 2026] [security2:error] [pid 940476:tid 940715] [client 77.110.127.138:49312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VgRjVYcQxwGpYwZmvBAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:05.215763 2026] [security2:error] [pid 940476:tid 940715] [client 77.110.127.138:49312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VgRjVYcQxwGpYwZmvBAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:05.271099 2026] [security2:error] [pid 935758:tid 935995] [client 34.74.185.202:54155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VgbcDxY_mIul-JSGs3AAAAXM"]
[Mon Jul 20 06:33:05.287821 2026] [security2:error] [pid 935758:tid 935998] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VgbcDxY_mIul-JSGs2AAAAXY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:05.336785 2026] [security2:error] [pid 940476:tid 940670] [client 98.159.234.160:54341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VgRjVYcQxwGpYwZmvBgAAAEA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:33:05.475002 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:49313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VgbcDxY_mIul-JSGs4wAAATM"]
[Mon Jul 20 06:33:05.475152 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:49313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VgbcDxY_mIul-JSGs4wAAATM"]
[Mon Jul 20 06:33:05.489861 2026] [security2:error] [pid 935758:tid 935928] [client 34.73.38.214:55380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VgbcDxY_mIul-JSGs5AAAATA"]
[Mon Jul 20 06:33:05.926147 2026] [security2:error] [pid 935758:tid 935807] [remote 57.141.18.8:54696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3652821"] [unique_id "al4VgbcDxY_mIul-JSGs8wABUy4"]
[Mon Jul 20 06:33:05.968017 2026] [security2:error] [pid 935758:tid 935926] [client 34.74.185.202:55814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VgbcDxY_mIul-JSGs9gAAAS4"]
[Mon Jul 20 06:33:05.985116 2026] [security2:error] [pid 940476:tid 940709] [client 216.73.217.138:29574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VgRjVYcQxwGpYwZmvHQAAZwo"]
[Mon Jul 20 06:33:05.986235 2026] [security2:error] [pid 935758:tid 936004] [client 103.125.179.95:52588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VgbcDxY_mIul-JSGs-QAAAXw"]
[Mon Jul 20 06:33:05.986346 2026] [security2:error] [pid 935758:tid 936004] [client 103.125.179.95:52588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VgbcDxY_mIul-JSGs-QAAAXw"]
[Mon Jul 20 06:33:06.333174 2026] [security2:error] [pid 935758:tid 935979] [client 216.73.217.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theprocess.oldcartsconsulting.com"] [uri "/index.php"] [unique_id "al4Vf7cDxY_mIul-JSGspgAAAWM"]
[Mon Jul 20 06:33:06.338314 2026] [security2:error] [pid 940476:tid 940688] [client 104.234.53.56:52841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VghjVYcQxwGpYwZmvPAAAAFI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:06.430014 2026] [security2:error] [pid 940476:tid 940539] [remote 91.142.222.105:58298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4VghjVYcQxwGpYwZmvPwAASD4"]
[Mon Jul 20 06:33:06.494137 2026] [security2:error] [pid 940476:tid 940652] [client 187.108.85.186:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VghjVYcQxwGpYwZmvRQAAAC4"]
[Mon Jul 20 06:33:06.494273 2026] [security2:error] [pid 940476:tid 940652] [client 187.108.85.186:49744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VghjVYcQxwGpYwZmvRQAAAC4"]
[Mon Jul 20 06:33:06.591827 2026] [security2:error] [pid 940476:tid 940659] [client 106.219.188.178:42203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VghjVYcQxwGpYwZmvSgAAADU"]
[Mon Jul 20 06:33:06.592357 2026] [security2:error] [pid 940476:tid 940659] [client 106.219.188.178:42203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VghjVYcQxwGpYwZmvSgAAADU"]
[Mon Jul 20 06:33:06.723379 2026] [security2:error] [pid 940476:tid 940588] [remote 91.142.222.105:58298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4VghjVYcQxwGpYwZmvUgAACW8"], referer: https://north-woods-engineering.com/wp-login.php
[Mon Jul 20 06:33:06.766346 2026] [security2:error] [pid 940476:tid 940732] [client 34.73.38.214:65528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VghjVYcQxwGpYwZmvVQAAAH4"]
[Mon Jul 20 06:33:06.911810 2026] [security2:error] [pid 935758:tid 935917] [client 34.74.185.202:61084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.ouw.egd.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VgrcDxY_mIul-JSGtDAAAASU"]
[Mon Jul 20 06:33:06.914374 2026] [security2:error] [pid 940476:tid 940677] [client 57.141.18.106:55512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VfRjVYcQxwGpYwZmuMQAARww"]
[Mon Jul 20 06:33:07.030494 2026] [security2:error] [pid 940476:tid 940665] [client 34.73.38.214:59011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VgxjVYcQxwGpYwZmvZQAAADs"]
[Mon Jul 20 06:33:07.046489 2026] [security2:error] [pid 940476:tid 940690] [client 14.225.17.146:50942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4VgRjVYcQxwGpYwZmvHAAAAFQ"], referer: http://collectingrealestate.com/Old
[Mon Jul 20 06:33:07.066307 2026] [security2:error] [pid 940476:tid 940671] [client 114.119.155.94:25361] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.appelmanimages.com"] [uri "/naperville-documentary-portraits-kids-home-marker-incident/"] [unique_id "al4VgxjVYcQxwGpYwZmvaQAAAEE"], referer: https://www.appelmanimages.com/category/individual/page/3/
[Mon Jul 20 06:33:07.529427 2026] [security2:error] [pid 935758:tid 935992] [client 20.197.192.193:44828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4Vg7cDxY_mIul-JSGtFwAAAXA"]
[Mon Jul 20 06:33:07.529549 2026] [security2:error] [pid 935758:tid 935992] [client 20.197.192.193:44828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4Vg7cDxY_mIul-JSGtFwAAAXA"]
[Mon Jul 20 06:33:07.564064 2026] [security2:error] [pid 940476:tid 940658] [client 57.141.18.103:35840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VfhjVYcQxwGpYwZmuVQAANHY"]
[Mon Jul 20 06:33:07.616255 2026] [security2:error] [pid 940476:tid 940657] [client 104.234.53.49:43253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VgxjVYcQxwGpYwZmvgwAAADM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:07.923235 2026] [security2:error] [pid 940476:tid 940665] [client 82.102.27.163:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VgxjVYcQxwGpYwZmvkgAAADs"]
[Mon Jul 20 06:33:07.923346 2026] [security2:error] [pid 940476:tid 940665] [client 82.102.27.163:58286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VgxjVYcQxwGpYwZmvkgAAADs"]
[Mon Jul 20 06:33:08.178883 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhBjVYcQxwGpYwZmvpAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:08.178973 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhBjVYcQxwGpYwZmvpAAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:08.582784 2026] [security2:error] [pid 935758:tid 935775] [remote 5.161.225.162:32962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VhLcDxY_mIul-JSGtJQABEA4"]
[Mon Jul 20 06:33:08.582951 2026] [security2:error] [pid 935758:tid 935896] [client 5.161.225.162:32962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VhLcDxY_mIul-JSGtJQABEA4"]
[Mon Jul 20 06:33:08.681693 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VhBjVYcQxwGpYwZmvqwAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:08.716365 2026] [security2:error] [pid 940476:tid 940647] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VhBjVYcQxwGpYwZmvrQAAACk"]
[Mon Jul 20 06:33:08.850061 2026] [security2:error] [pid 935758:tid 935958] [client 223.185.13.213:11606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VhLcDxY_mIul-JSGtKQAAAU4"]
[Mon Jul 20 06:33:08.850190 2026] [security2:error] [pid 935758:tid 935958] [client 223.185.13.213:11606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VhLcDxY_mIul-JSGtKQAAAU4"]
[Mon Jul 20 06:33:08.963712 2026] [security2:error] [pid 940476:tid 940655] [client 57.141.18.108:45160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VfxjVYcQxwGpYwZmupwAAMSI"]
[Mon Jul 20 06:33:08.994350 2026] [security2:error] [pid 940476:tid 940663] [client 34.73.38.214:63443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VhBjVYcQxwGpYwZmv5QAAADk"]
[Mon Jul 20 06:33:09.004097 2026] [security2:error] [pid 940476:tid 940719] [client 77.110.127.138:49327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhRjVYcQxwGpYwZmv5wAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:09.004172 2026] [security2:error] [pid 940476:tid 940719] [client 77.110.127.138:49327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhRjVYcQxwGpYwZmv5wAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:09.092439 2026] [security2:error] [pid 940476:tid 940646] [client 197.186.66.42:62131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VhRjVYcQxwGpYwZmv6wAAACg"]
[Mon Jul 20 06:33:09.093232 2026] [security2:error] [pid 940476:tid 940646] [client 197.186.66.42:62131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VhRjVYcQxwGpYwZmv6wAAACg"]
[Mon Jul 20 06:33:09.228082 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhRjVYcQxwGpYwZmv9gAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:09.228210 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhRjVYcQxwGpYwZmv9gAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:09.384943 2026] [security2:error] [pid 940476:tid 940630] [client 77.110.127.138:49331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhRjVYcQxwGpYwZmwAAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:09.385086 2026] [security2:error] [pid 940476:tid 940630] [client 77.110.127.138:49331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VhRjVYcQxwGpYwZmwAAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:09.545358 2026] [security2:error] [pid 940476:tid 940693] [client 14.225.17.146:62096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4VhRjVYcQxwGpYwZmv_wAAAFc"], referer: http://www.justinagrayman.com/Old
[Mon Jul 20 06:33:09.805067 2026] [security2:error] [pid 940476:tid 940725] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VhRjVYcQxwGpYwZmwCQAAAHc"]
[Mon Jul 20 06:33:09.863313 2026] [security2:error] [pid 940476:tid 940521] [remote 103.161.172.221:33096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VhRjVYcQxwGpYwZmwGgAAXiw"]
[Mon Jul 20 06:33:09.863506 2026] [security2:error] [pid 940476:tid 940700] [client 103.161.172.221:33096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VhRjVYcQxwGpYwZmwGgAAXiw"]
[Mon Jul 20 06:33:09.922161 2026] [security2:error] [pid 940476:tid 940513] [remote 124.55.178.99:41564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VhRjVYcQxwGpYwZmwHAAAMCQ"]
[Mon Jul 20 06:33:09.954668 2026] [security2:error] [pid 940476:tid 940619] [client 34.73.38.214:54828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VhRjVYcQxwGpYwZmwHwAAAA0"]
[Mon Jul 20 06:33:09.959301 2026] [security2:error] [pid 940476:tid 940671] [client 34.73.38.214:58275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VhRjVYcQxwGpYwZmwIAAAAEE"]
[Mon Jul 20 06:33:09.976908 2026] [security2:error] [pid 935758:tid 935956] [client 57.141.18.35:36212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VgLcDxY_mIul-JSGs0wABTAs"]
[Mon Jul 20 06:33:10.148803 2026] [security2:error] [pid 935758:tid 935899] [client 171.61.165.146:8888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VhrcDxY_mIul-JSGtUgAAARM"]
[Mon Jul 20 06:33:10.148970 2026] [security2:error] [pid 935758:tid 935899] [client 171.61.165.146:8888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VhrcDxY_mIul-JSGtUgAAARM"]
[Mon Jul 20 06:33:10.215347 2026] [security2:error] [pid 935758:tid 936013] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VhbcDxY_mIul-JSGtSgAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:10.295599 2026] [security2:error] [pid 935758:tid 935962] [client 14.225.17.146:51456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4VhrcDxY_mIul-JSGtUQAAAVI"], referer: http://amalia-capital.com/Old
[Mon Jul 20 06:33:10.433642 2026] [security2:error] [pid 940476:tid 940580] [remote 124.55.178.99:41564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VhhjVYcQxwGpYwZmwOQAAYmc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:33:10.562685 2026] [security2:error] [pid 935758:tid 935802] [remote 98.156.100.191:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4VhrcDxY_mIul-JSGtWwABIyk"]
[Mon Jul 20 06:33:10.604044 2026] [security2:error] [pid 940476:tid 940503] [remote 8.217.108.67:50196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4VhhjVYcQxwGpYwZmwQQAATRo"]
[Mon Jul 20 06:33:11.034252 2026] [security2:error] [pid 940476:tid 940707] [client 57.141.18.106:55522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VgRjVYcQxwGpYwZmvGQAAZX4"]
[Mon Jul 20 06:33:11.174474 2026] [security2:error] [pid 940476:tid 940670] [client 34.73.38.214:55472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mochawavepublishing.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VhxjVYcQxwGpYwZmwZQAAAEA"]
[Mon Jul 20 06:33:11.214289 2026] [security2:error] [pid 940476:tid 940717] [client 62.169.31.200:35622] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4VhxjVYcQxwGpYwZmwZwAAAG8"]
[Mon Jul 20 06:33:11.239755 2026] [security2:error] [pid 940476:tid 940725] [client 158.173.89.95:38625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VhxjVYcQxwGpYwZmwaQAAAHc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:33:11.282368 2026] [security2:error] [pid 940476:tid 940666] [client 34.73.38.214:61653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VhxjVYcQxwGpYwZmwbgAAADw"]
[Mon Jul 20 06:33:11.431552 2026] [security2:error] [pid 940476:tid 940687] [client 57.141.18.60:36236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VghjVYcQxwGpYwZmvKwAAUQY"]
[Mon Jul 20 06:33:11.489534 2026] [security2:error] [pid 940476:tid 940648] [client 14.225.17.146:63990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4VhhjVYcQxwGpYwZmwVwAAACo"], referer: http://gearwaterproof.com/Old
[Mon Jul 20 06:33:11.648490 2026] [security2:error] [pid 935758:tid 935890] [client 62.169.31.200:35624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4Vh7cDxY_mIul-JSGtbQAAAQo"]
[Mon Jul 20 06:33:11.760543 2026] [security2:error] [pid 940476:tid 940731] [client 171.60.139.123:61884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VhxjVYcQxwGpYwZmwgwAAAH0"]
[Mon Jul 20 06:33:11.760707 2026] [security2:error] [pid 940476:tid 940731] [client 171.60.139.123:61884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VhxjVYcQxwGpYwZmwgwAAAH0"]
[Mon Jul 20 06:33:11.801137 2026] [security2:error] [pid 940476:tid 940656] [client 39.48.81.23:52114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VhxjVYcQxwGpYwZmwhwAAADI"]
[Mon Jul 20 06:33:11.801257 2026] [security2:error] [pid 940476:tid 940656] [client 39.48.81.23:52114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VhxjVYcQxwGpYwZmwhwAAADI"]
[Mon Jul 20 06:33:11.803052 2026] [core:error] [pid 935758:tid 935960] [client 14.225.17.146:51453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:33:11.803080 2026] [core:error] [pid 935758:tid 935960] [client 14.225.17.146:51453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:33:11.990712 2026] [security2:error] [pid 940476:tid 940661] [client 14.225.17.146:51413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4VhhjVYcQxwGpYwZmwPAAAADc"], referer: http://slutilities.com/Old
[Mon Jul 20 06:33:12.014390 2026] [security2:error] [pid 940476:tid 940706] [client 57.141.18.28:52260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VghjVYcQxwGpYwZmvUQAAZHo"]
[Mon Jul 20 06:33:12.074817 2026] [security2:error] [pid 935758:tid 935764] [remote 98.156.100.191:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ViLcDxY_mIul-JSGteQABSgM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:33:12.087881 2026] [security2:error] [pid 940476:tid 940712] [client 62.169.31.200:35628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4ViBjVYcQxwGpYwZmwlgAAAGo"]
[Mon Jul 20 06:33:12.098131 2026] [security2:error] [pid 940476:tid 940664] [client 77.110.127.138:49342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViBjVYcQxwGpYwZmwmQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.098232 2026] [security2:error] [pid 940476:tid 940664] [client 77.110.127.138:49342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViBjVYcQxwGpYwZmwmQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.252648 2026] [security2:error] [pid 940476:tid 940720] [client 34.73.38.214:49789] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ViBjVYcQxwGpYwZmwqwAAAHI"]
[Mon Jul 20 06:33:12.258970 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:49345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViBjVYcQxwGpYwZmwrQAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.259106 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:49345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViBjVYcQxwGpYwZmwrQAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.412239 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:49346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViLcDxY_mIul-JSGtfwAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.412328 2026] [security2:error] [pid 935758:tid 935978] [client 77.110.127.138:49346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViLcDxY_mIul-JSGtfwAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.442230 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ViBjVYcQxwGpYwZmwnwAAAAM"]
[Mon Jul 20 06:33:12.500911 2026] [security2:error] [pid 940476:tid 940681] [client 45.116.69.230:54567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ViBjVYcQxwGpYwZmwtAAAAEs"]
[Mon Jul 20 06:33:12.501045 2026] [security2:error] [pid 940476:tid 940681] [client 45.116.69.230:54567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4ViBjVYcQxwGpYwZmwtAAAAEs"]
[Mon Jul 20 06:33:12.593982 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViBjVYcQxwGpYwZmwuwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.594085 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViBjVYcQxwGpYwZmwuwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:12.744549 2026] [security2:error] [pid 940476:tid 940612] [client 57.141.18.6:42568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VgxjVYcQxwGpYwZmvdwAABng"]
[Mon Jul 20 06:33:12.887132 2026] [security2:error] [pid 940476:tid 940595] [remote 159.65.81.207:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ViBjVYcQxwGpYwZmwzAAATHY"]
[Mon Jul 20 06:33:13.105828 2026] [security2:error] [pid 940476:tid 940645] [client 112.208.70.94:42323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ViRjVYcQxwGpYwZmw1QAAACc"]
[Mon Jul 20 06:33:13.106013 2026] [security2:error] [pid 940476:tid 940645] [client 112.208.70.94:42323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ViRjVYcQxwGpYwZmw1QAAACc"]
[Mon Jul 20 06:33:13.208127 2026] [security2:error] [pid 935758:tid 935987] [client 57.141.18.92:40486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vg7cDxY_mIul-JSGtGwABa2Y"]
[Mon Jul 20 06:33:13.334921 2026] [security2:error] [pid 940476:tid 940533] [remote 159.65.81.207:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ViRjVYcQxwGpYwZmw4wAAMzg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:33:13.504960 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:49353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViRjVYcQxwGpYwZmw6AAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:13.505075 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:49353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ViRjVYcQxwGpYwZmw6AAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:13.550682 2026] [security2:error] [pid 940476:tid 940641] [client 57.141.18.53:24404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VhBjVYcQxwGpYwZmvogAAIzA"]
[Mon Jul 20 06:33:13.616858 2026] [security2:error] [pid 940476:tid 940685] [client 57.141.18.46:49766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VhBjVYcQxwGpYwZmvrgAATwE"]
[Mon Jul 20 06:33:13.657725 2026] [security2:error] [pid 935758:tid 935925] [client 178.156.238.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4VibcDxY_mIul-JSGtlwAAAS0"]
[Mon Jul 20 06:33:13.750639 2026] [security2:error] [pid 940476:tid 940626] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ViRjVYcQxwGpYwZmw6wAAABQ"]
[Mon Jul 20 06:33:13.906994 2026] [security2:error] [pid 935758:tid 936004] [client 34.73.38.214:59984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VibcDxY_mIul-JSGtogAAAXw"]
[Mon Jul 20 06:33:14.147346 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:49354] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/chart/"] [unique_id "al4VihjVYcQxwGpYwZmxCgAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:14.220337 2026] [security2:error] [pid 940476:tid 940620] [client 57.141.18.111:24542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VhBjVYcQxwGpYwZmvxwAADiM"]
[Mon Jul 20 06:33:14.487292 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:49356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VihjVYcQxwGpYwZmxIwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:14.487396 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:49356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VihjVYcQxwGpYwZmxIwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:14.668490 2026] [security2:error] [pid 940476:tid 940700] [client 45.61.187.148:56161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.187.61.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ancestralidadytrance.space"] [uri "/wp-login.php"] [unique_id "al4VihjVYcQxwGpYwZmxMAAAAF4"]
[Mon Jul 20 06:33:15.232296 2026] [security2:error] [pid 940476:tid 940640] [client 77.110.127.138:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VixjVYcQxwGpYwZmxSwAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:15.232390 2026] [security2:error] [pid 940476:tid 940640] [client 77.110.127.138:49362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VixjVYcQxwGpYwZmxSwAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:15.404878 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VixjVYcQxwGpYwZmxVwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:15.404978 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VixjVYcQxwGpYwZmxVwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:15.478228 2026] [security2:error] [pid 940476:tid 940708] [client 34.73.38.214:52616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VixjVYcQxwGpYwZmxWwAAAGY"]
[Mon Jul 20 06:33:15.555167 2026] [security2:error] [pid 940476:tid 940691] [client 57.141.18.87:28804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VhRjVYcQxwGpYwZmwFQAAVVQ"]
[Mon Jul 20 06:33:15.781311 2026] [security2:error] [pid 940476:tid 940531] [remote 72.167.132.114:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VixjVYcQxwGpYwZmxbAAASjY"]
[Mon Jul 20 06:33:16.035350 2026] [security2:error] [pid 940476:tid 940483] [remote 72.167.132.114:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VjBjVYcQxwGpYwZmxjAAAUQY"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:33:16.115605 2026] [security2:error] [pid 940476:tid 940714] [client 109.123.255.91:41756] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4VjBjVYcQxwGpYwZmxkQAAAGw"]
[Mon Jul 20 06:33:16.309417 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:49368] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/chart/"] [unique_id "al4VjBjVYcQxwGpYwZmxmwAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:16.315135 2026] [security2:error] [pid 935758:tid 935948] [client 104.234.53.83:29341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VjLcDxY_mIul-JSGt2wAAAUQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:16.318424 2026] [security2:error] [pid 940476:tid 940617] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VjBjVYcQxwGpYwZmxkAAAAAs"]
[Mon Jul 20 06:33:16.596527 2026] [security2:error] [pid 940476:tid 940656] [client 77.110.127.138:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjBjVYcQxwGpYwZmxrgAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:16.596644 2026] [security2:error] [pid 940476:tid 940656] [client 77.110.127.138:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjBjVYcQxwGpYwZmxrgAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:16.623959 2026] [security2:error] [pid 940476:tid 940648] [client 109.123.255.91:41758] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4VjBjVYcQxwGpYwZmxsAAAACo"]
[Mon Jul 20 06:33:16.670402 2026] [security2:error] [pid 940476:tid 940678] [client 103.125.179.95:53065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VjBjVYcQxwGpYwZmxtgAAAEg"]
[Mon Jul 20 06:33:16.670979 2026] [security2:error] [pid 940476:tid 940678] [client 103.125.179.95:53065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VjBjVYcQxwGpYwZmxtgAAAEg"]
[Mon Jul 20 06:33:16.795230 2026] [security2:error] [pid 940476:tid 940700] [client 77.110.127.138:49371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjBjVYcQxwGpYwZmxvQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:16.795341 2026] [security2:error] [pid 940476:tid 940700] [client 77.110.127.138:49371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjBjVYcQxwGpYwZmxvQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:16.889953 2026] [security2:error] [pid 935758:tid 935964] [client 50.116.65.227:50824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VjLcDxY_mIul-JSGt5gAAAVQ"]
[Mon Jul 20 06:33:16.900065 2026] [security2:error] [pid 940476:tid 940673] [client 50.116.65.227:50828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VjBjVYcQxwGpYwZmxwQAAAEM"]
[Mon Jul 20 06:33:16.913274 2026] [security2:error] [pid 940476:tid 940608] [client 158.173.166.181:21259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VjBjVYcQxwGpYwZmxwwAAAAI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:33:16.968891 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VjLcDxY_mIul-JSGt4gAAARw"]
[Mon Jul 20 06:33:17.104359 2026] [security2:error] [pid 935758:tid 935943] [client 104.234.53.53:32349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VjbcDxY_mIul-JSGt7AAAAT8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:17.156294 2026] [security2:error] [pid 940476:tid 940611] [client 14.225.17.146:62172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4VjBjVYcQxwGpYwZmxvwAAAAU"]
[Mon Jul 20 06:33:17.160633 2026] [security2:error] [pid 940476:tid 940633] [client 187.108.85.186:50243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VjRjVYcQxwGpYwZmx4QAAABs"]
[Mon Jul 20 06:33:17.160774 2026] [security2:error] [pid 940476:tid 940633] [client 187.108.85.186:50243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VjRjVYcQxwGpYwZmx4QAAABs"]
[Mon Jul 20 06:33:17.218445 2026] [security2:error] [pid 940476:tid 940635] [client 109.123.255.91:41760] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4VjRjVYcQxwGpYwZmx5AAAAB0"]
[Mon Jul 20 06:33:17.347065 2026] [security2:error] [pid 940476:tid 940660] [client 34.73.38.214:60942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VjRjVYcQxwGpYwZmx7gAAADY"]
[Mon Jul 20 06:33:17.362940 2026] [security2:error] [pid 935758:tid 935890] [client 14.225.17.146:62170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4VjbcDxY_mIul-JSGt8AAAAQo"], referer: http://idigress.group/Old
[Mon Jul 20 06:33:17.559061 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjRjVYcQxwGpYwZmyAwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:17.559271 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:49350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjRjVYcQxwGpYwZmyAwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:17.588347 2026] [security2:error] [pid 935758:tid 935892] [client 20.197.192.193:58849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/asd67.php"] [unique_id "al4VjbcDxY_mIul-JSGt-wAAAQw"]
[Mon Jul 20 06:33:17.588432 2026] [security2:error] [pid 935758:tid 935892] [client 20.197.192.193:58849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/asd67.php"] [unique_id "al4VjbcDxY_mIul-JSGt-wAAAQw"]
[Mon Jul 20 06:33:17.639552 2026] [security2:error] [pid 940476:tid 940616] [client 57.141.18.59:37652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VhxjVYcQxwGpYwZmwiQAACh0"]
[Mon Jul 20 06:33:17.710730 2026] [security2:error] [pid 940476:tid 940647] [client 57.141.18.67:63132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VhxjVYcQxwGpYwZmwiwAAKQI"]
[Mon Jul 20 06:33:17.712072 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:49376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjRjVYcQxwGpYwZmyDQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:17.712154 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:49376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjRjVYcQxwGpYwZmyDQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:17.736450 2026] [security2:error] [pid 940476:tid 940609] [client 14.225.17.146:62362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4VjBjVYcQxwGpYwZmxrQAAAAM"], referer: http://ravmike.com/Old
[Mon Jul 20 06:33:18.038831 2026] [security2:error] [pid 940476:tid 940666] [client 77.110.127.138:49378] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/chart/"] [unique_id "al4VjhjVYcQxwGpYwZmyJAAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:18.051655 2026] [core:error] [pid 940476:tid 940716] [client 14.225.17.146:62202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Old
[Mon Jul 20 06:33:18.051680 2026] [core:error] [pid 940476:tid 940716] [client 14.225.17.146:62202] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Old
[Mon Jul 20 06:33:18.071210 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VjRjVYcQxwGpYwZmyFwAAAHI"]
[Mon Jul 20 06:33:18.210780 2026] [security2:error] [pid 935758:tid 935781] [remote 192.241.143.148:42538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VjrcDxY_mIul-JSGuBgABRxQ"]
[Mon Jul 20 06:33:18.229882 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjhjVYcQxwGpYwZmyNwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:18.229975 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjhjVYcQxwGpYwZmyNwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:18.238020 2026] [security2:error] [pid 940476:tid 940619] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "canqungarments.com"] [uri "/index.php"] [unique_id "al4VjRjVYcQxwGpYwZmx9gAAAA0"]
[Mon Jul 20 06:33:18.388407 2026] [security2:error] [pid 935758:tid 935818] [remote 192.241.143.148:42538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4VjrcDxY_mIul-JSGuDQABJzk"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:33:18.674844 2026] [security2:error] [pid 940476:tid 940726] [client 14.225.17.146:62230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4VjhjVYcQxwGpYwZmyTQAAAHg"], referer: https://ravmike.com/Old
[Mon Jul 20 06:33:18.729847 2026] [security2:error] [pid 935758:tid 935985] [client 77.110.127.138:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjrcDxY_mIul-JSGuEgAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:18.729963 2026] [security2:error] [pid 935758:tid 935985] [client 77.110.127.138:49385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjrcDxY_mIul-JSGuEgAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:18.771142 2026] [security2:error] [pid 935758:tid 935938] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VjrcDxY_mIul-JSGuDgAAATo"]
[Mon Jul 20 06:33:18.794722 2026] [security2:error] [pid 940476:tid 940681] [client 14.225.17.146:63129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4VjRjVYcQxwGpYwZmx5wAAAEs"]
[Mon Jul 20 06:33:19.191290 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:49365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjxjVYcQxwGpYwZmycQAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:19.191434 2026] [security2:error] [pid 940476:tid 940620] [client 77.110.127.138:49365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VjxjVYcQxwGpYwZmycQAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:19.454659 2026] [security2:error] [pid 940476:tid 940596] [remote 57.141.18.20:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600005"] [unique_id "al4VjxjVYcQxwGpYwZmyhwAAanc"]
[Mon Jul 20 06:33:19.531853 2026] [security2:error] [pid 940476:tid 940663] [client 57.141.18.39:61967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ViRjVYcQxwGpYwZmw_wAAOUg"]
[Mon Jul 20 06:33:19.692245 2026] [security2:error] [pid 940476:tid 940622] [client 14.225.17.146:62237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4VjhjVYcQxwGpYwZmyJwAAABA"], referer: http://olearyplumbingllc.com/Old
[Mon Jul 20 06:33:19.717305 2026] [security2:error] [pid 935758:tid 935926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vj7cDxY_mIul-JSGuHQAAAS4"]
[Mon Jul 20 06:33:19.744541 2026] [security2:error] [pid 935758:tid 935976] [client 34.73.38.214:60940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Vj7cDxY_mIul-JSGuJQAAAWA"]
[Mon Jul 20 06:33:19.801948 2026] [security2:error] [pid 935758:tid 935880] [remote 103.82.22.235:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Vj7cDxY_mIul-JSGuKAABanc"]
[Mon Jul 20 06:33:19.842001 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:49391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vj7cDxY_mIul-JSGuKwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:19.842110 2026] [security2:error] [pid 935758:tid 935905] [client 77.110.127.138:49391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vj7cDxY_mIul-JSGuKwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:19.886807 2026] [security2:error] [pid 940476:tid 940664] [client 223.185.13.213:8751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VjxjVYcQxwGpYwZmypQAAADo"]
[Mon Jul 20 06:33:19.886904 2026] [security2:error] [pid 940476:tid 940664] [client 223.185.13.213:8751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VjxjVYcQxwGpYwZmypQAAADo"]
[Mon Jul 20 06:33:20.139279 2026] [security2:error] [pid 940476:tid 940727] [client 197.186.66.42:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VkBjVYcQxwGpYwZmyswAAAHk"]
[Mon Jul 20 06:33:20.139446 2026] [security2:error] [pid 940476:tid 940727] [client 197.186.66.42:62618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VkBjVYcQxwGpYwZmyswAAAHk"]
[Mon Jul 20 06:33:20.209191 2026] [security2:error] [pid 935758:tid 936017] [client 14.225.17.146:56431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4VjrcDxY_mIul-JSGuFQAAAYk"], referer: http://cloudspacesgroup.com/Old
[Mon Jul 20 06:33:20.244214 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkBjVYcQxwGpYwZmyuwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:20.244369 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:49393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkBjVYcQxwGpYwZmyuwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:20.273285 2026] [security2:error] [pid 935758:tid 935800] [remote 103.82.22.235:58228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VkLcDxY_mIul-JSGuNQABGyc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:33:20.337538 2026] [security2:error] [pid 940476:tid 940729] [client 14.225.17.146:62248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4VjxjVYcQxwGpYwZmyoAAAAHs"], referer: http://idigress.agency/Old
[Mon Jul 20 06:33:20.388331 2026] [security2:error] [pid 940476:tid 940673] [client 14.225.17.146:49560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4VjxjVYcQxwGpYwZmyewAAAEM"], referer: http://travelbyfire.com/Old
[Mon Jul 20 06:33:20.586700 2026] [security2:error] [pid 935758:tid 935895] [client 171.61.165.146:1390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VkLcDxY_mIul-JSGuPAAAAQ8"]
[Mon Jul 20 06:33:20.586857 2026] [security2:error] [pid 935758:tid 935895] [client 171.61.165.146:1390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VkLcDxY_mIul-JSGuPAAAAQ8"]
[Mon Jul 20 06:33:20.718181 2026] [security2:error] [pid 940476:tid 940695] [client 57.141.18.76:20592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VihjVYcQxwGpYwZmxPQAAWQs"]
[Mon Jul 20 06:33:20.898351 2026] [security2:error] [pid 935758:tid 935909] [client 34.73.38.214:52824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VkLcDxY_mIul-JSGuRwAAAR0"]
[Mon Jul 20 06:33:20.952206 2026] [security2:error] [pid 935758:tid 936013] [client 57.141.18.112:28756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vi7cDxY_mIul-JSGtvQABhUg"]
[Mon Jul 20 06:33:20.997734 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:49396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkLcDxY_mIul-JSGuSgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:20.998871 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:49396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkLcDxY_mIul-JSGuSgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:21.074991 2026] [security2:error] [pid 940476:tid 940705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VkBjVYcQxwGpYwZmy4QAAAGM"]
[Mon Jul 20 06:33:21.133425 2026] [security2:error] [pid 940476:tid 940662] [client 57.141.18.30:22794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VixjVYcQxwGpYwZmxVAAAOCw"]
[Mon Jul 20 06:33:21.273316 2026] [security2:error] [pid 940476:tid 940724] [client 14.225.17.146:63223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4VkRjVYcQxwGpYwZmy8QAAAHY"], referer: https://travelbyfire.com/Old
[Mon Jul 20 06:33:21.861645 2026] [security2:error] [pid 940476:tid 940620] [client 104.234.53.58:29409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VkRjVYcQxwGpYwZmzEAAAAA4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:21.951874 2026] [security2:error] [pid 935758:tid 935999] [client 74.208.214.194:48728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VkbcDxY_mIul-JSGuZAAAAXc"]
[Mon Jul 20 06:33:21.952341 2026] [security2:error] [pid 935758:tid 935896] [client 57.141.18.0:39116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VjLcDxY_mIul-JSGt2AABEAI"]
[Mon Jul 20 06:33:22.013240 2026] [security2:error] [pid 935758:tid 935960] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VkbcDxY_mIul-JSGuXQAAAVA"]
[Mon Jul 20 06:33:22.153414 2026] [security2:error] [pid 940476:tid 940710] [client 77.110.127.138:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkhjVYcQxwGpYwZmzIgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:22.153501 2026] [security2:error] [pid 940476:tid 940710] [client 77.110.127.138:49408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkhjVYcQxwGpYwZmzIgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:22.438415 2026] [security2:error] [pid 940476:tid 940696] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VkhjVYcQxwGpYwZmzKwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:22.468705 2026] [security2:error] [pid 935758:tid 935926] [client 39.48.81.23:52612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VkrcDxY_mIul-JSGudgAAAS4"]
[Mon Jul 20 06:33:22.468810 2026] [security2:error] [pid 935758:tid 935926] [client 39.48.81.23:52612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VkrcDxY_mIul-JSGudgAAAS4"]
[Mon Jul 20 06:33:22.540441 2026] [security2:error] [pid 935758:tid 935941] [client 171.60.139.123:62407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VkrcDxY_mIul-JSGudwAAAT0"]
[Mon Jul 20 06:33:22.540552 2026] [security2:error] [pid 935758:tid 935941] [client 171.60.139.123:62407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VkrcDxY_mIul-JSGudwAAAT0"]
[Mon Jul 20 06:33:22.649162 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:49415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkhjVYcQxwGpYwZmzRAAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:22.649288 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:49415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VkhjVYcQxwGpYwZmzRAAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:22.717885 2026] [security2:error] [pid 940476:tid 940683] [client 34.73.38.214:58497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VkhjVYcQxwGpYwZmzSgAAAE0"]
[Mon Jul 20 06:33:22.966535 2026] [security2:error] [pid 935758:tid 935977] [client 57.141.18.41:50888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VjbcDxY_mIul-JSGt7wABYXo"]
[Mon Jul 20 06:33:22.981773 2026] [security2:error] [pid 940476:tid 940644] [client 84.67.150.97:33260] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4VkhjVYcQxwGpYwZmzYQAAACY"]
[Mon Jul 20 06:33:23.019893 2026] [security2:error] [pid 940476:tid 940642] [client 45.116.69.230:55103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VkxjVYcQxwGpYwZmzYwAAACQ"]
[Mon Jul 20 06:33:23.019997 2026] [security2:error] [pid 940476:tid 940642] [client 45.116.69.230:55103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VkxjVYcQxwGpYwZmzYwAAACQ"]
[Mon Jul 20 06:33:23.111854 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VkhjVYcQxwGpYwZmzXAAAAAQ"]
[Mon Jul 20 06:33:23.289909 2026] [security2:error] [pid 935758:tid 935909] [client 45.3.44.8:48149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Vk7cDxY_mIul-JSGuhAAAAR0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:33:23.825968 2026] [security2:error] [pid 940476:tid 940687] [client 104.234.53.58:29409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VkxjVYcQxwGpYwZmzkwAAAFE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:23.991857 2026] [security2:error] [pid 940476:tid 940695] [client 20.197.192.193:44842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/csa.php"] [unique_id "al4VkxjVYcQxwGpYwZmzmAAAAFk"]
[Mon Jul 20 06:33:23.991959 2026] [security2:error] [pid 940476:tid 940695] [client 20.197.192.193:44842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/csa.php"] [unique_id "al4VkxjVYcQxwGpYwZmzmAAAAFk"]
[Mon Jul 20 06:33:24.165720 2026] [security2:error] [pid 940476:tid 940634] [client 14.182.195.220:52230] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4VlBjVYcQxwGpYwZmzpwAAABw"]
[Mon Jul 20 06:33:24.271970 2026] [security2:error] [pid 940476:tid 940513] [remote 162.19.86.63:43567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4VlBjVYcQxwGpYwZmzrQAAKSQ"]
[Mon Jul 20 06:33:24.272442 2026] [security2:error] [pid 935758:tid 935986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlLcDxY_mIul-JSGumAAAAWo"]
[Mon Jul 20 06:33:24.277650 2026] [security2:error] [pid 940476:tid 940730] [client 77.110.127.138:49424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlBjVYcQxwGpYwZmzsAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:24.277719 2026] [security2:error] [pid 940476:tid 940730] [client 77.110.127.138:49424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlBjVYcQxwGpYwZmzsAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:24.496497 2026] [security2:error] [pid 940476:tid 940596] [remote 162.19.86.63:43567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4VlBjVYcQxwGpYwZmzvwAAY3c"], referer: https://mail.innspace.ca/wp-login.php
[Mon Jul 20 06:33:24.556881 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlBjVYcQxwGpYwZmzwQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:24.557010 2026] [security2:error] [pid 940476:tid 940622] [client 77.110.127.138:49426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlBjVYcQxwGpYwZmzwQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:24.657162 2026] [security2:error] [pid 940476:tid 940612] [client 57.141.18.89:33504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VjxjVYcQxwGpYwZmybAAABmg"]
[Mon Jul 20 06:33:24.889196 2026] [security2:error] [pid 940476:tid 940720] [client 20.197.192.193:58863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/2.php"] [unique_id "al4VlBjVYcQxwGpYwZmz1AAAAHI"]
[Mon Jul 20 06:33:24.889296 2026] [security2:error] [pid 940476:tid 940720] [client 20.197.192.193:58863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/2.php"] [unique_id "al4VlBjVYcQxwGpYwZmz1AAAAHI"]
[Mon Jul 20 06:33:24.890804 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:49429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlBjVYcQxwGpYwZmz1QAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:24.890893 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:49429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlBjVYcQxwGpYwZmz1QAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:24.980843 2026] [security2:error] [pid 940476:tid 940652] [client 57.141.18.0:39122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VjxjVYcQxwGpYwZmyfgAALmU"]
[Mon Jul 20 06:33:25.050865 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlBjVYcQxwGpYwZmz0AAAAEE"]
[Mon Jul 20 06:33:25.078962 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:49433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlbcDxY_mIul-JSGuswAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:25.079078 2026] [security2:error] [pid 935758:tid 935990] [client 77.110.127.138:49433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlbcDxY_mIul-JSGuswAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:25.259267 2026] [security2:error] [pid 940476:tid 940616] [client 34.73.38.214:58498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VlRjVYcQxwGpYwZmz8gAAAAo"]
[Mon Jul 20 06:33:25.330413 2026] [security2:error] [pid 935758:tid 935941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlbcDxY_mIul-JSGutQAAAT0"]
[Mon Jul 20 06:33:25.373604 2026] [security2:error] [pid 935758:tid 935968] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlbcDxY_mIul-JSGutgAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:25.408537 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlRjVYcQxwGpYwZmz6gAAAG4"]
[Mon Jul 20 06:33:25.788240 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlbcDxY_mIul-JSGuyQAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:25.788332 2026] [security2:error] [pid 935758:tid 935952] [client 77.110.127.138:49436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlbcDxY_mIul-JSGuyQAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:25.840127 2026] [security2:error] [pid 940476:tid 940488] [remote 152.228.213.32:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4VlRjVYcQxwGpYwZm0DgAAdgs"]
[Mon Jul 20 06:33:25.931253 2026] [security2:error] [pid 940476:tid 940706] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlRjVYcQxwGpYwZm0BwAAAGQ"]
[Mon Jul 20 06:33:26.030684 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:49403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0GwAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:26.030811 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:49403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0GwAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:26.061778 2026] [security2:error] [pid 940476:tid 940583] [remote 152.228.213.32:46232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4VlhjVYcQxwGpYwZm0HwAAV2o"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:33:26.184401 2026] [security2:error] [pid 940476:tid 940685] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlRjVYcQxwGpYwZm0GQAAAE8"]
[Mon Jul 20 06:33:26.281253 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:49441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0KQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:26.281341 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:49441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0KQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:26.379318 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:49414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0NAAAABk"]
[Mon Jul 20 06:33:26.379423 2026] [security2:error] [pid 940476:tid 940631] [client 77.110.127.138:49414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0NAAAABk"]
[Mon Jul 20 06:33:26.400157 2026] [security2:error] [pid 940476:tid 940661] [client 138.84.92.211:1331] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4VlhjVYcQxwGpYwZm0NgAAADc"]
[Mon Jul 20 06:33:26.449350 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0OwAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:26.449520 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlhjVYcQxwGpYwZm0OwAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:26.466708 2026] [security2:error] [pid 940476:tid 940690] [client 88.176.29.82:41668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0PQAAAFQ"]
[Mon Jul 20 06:33:26.480734 2026] [security2:error] [pid 940476:tid 940650] [client 90.63.205.82:44976] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0QQAAACw"]
[Mon Jul 20 06:33:26.503116 2026] [security2:error] [pid 940476:tid 940637] [client 124.217.48.252:40510] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf"] [unique_id "al4VlhjVYcQxwGpYwZm0RgAAAB8"]
[Mon Jul 20 06:33:26.503606 2026] [security2:error] [pid 940476:tid 940680] [client 180.75.244.168:47387] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0RwAAAEo"]
[Mon Jul 20 06:33:26.506661 2026] [security2:error] [pid 935758:tid 935894] [client 88.188.7.28:15709] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4VlrcDxY_mIul-JSGu3QAAAQ4"]
[Mon Jul 20 06:33:26.508959 2026] [security2:error] [pid 935758:tid 935940] [client 89.93.89.89:57445] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4VlrcDxY_mIul-JSGu3gAAATw"]
[Mon Jul 20 06:33:26.528568 2026] [security2:error] [pid 940476:tid 940677] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlhjVYcQxwGpYwZm0LgAAAEc"]
[Mon Jul 20 06:33:26.545916 2026] [security2:error] [pid 940476:tid 940620] [client 112.208.70.94:42832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VlhjVYcQxwGpYwZm0SQAAAA4"]
[Mon Jul 20 06:33:26.546066 2026] [security2:error] [pid 940476:tid 940620] [client 112.208.70.94:42832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VlhjVYcQxwGpYwZm0SQAAAA4"]
[Mon Jul 20 06:33:26.556329 2026] [security2:error] [pid 940476:tid 940626] [client 89.92.70.101:25658] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4VlhjVYcQxwGpYwZm0SgAAABQ"]
[Mon Jul 20 06:33:26.565160 2026] [security2:error] [pid 940476:tid 940687] [client 86.90.116.143:57178] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4VlhjVYcQxwGpYwZm0SwAAAFE"]
[Mon Jul 20 06:33:26.569418 2026] [security2:error] [pid 935758:tid 936006] [client 77.110.127.138:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlrcDxY_mIul-JSGu4wAAAX4"]
[Mon Jul 20 06:33:26.569528 2026] [security2:error] [pid 935758:tid 936006] [client 77.110.127.138:49444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlrcDxY_mIul-JSGu4wAAAX4"]
[Mon Jul 20 06:33:26.592764 2026] [security2:error] [pid 940476:tid 940702] [client 62.57.192.225:45690] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0TQAAAGA"]
[Mon Jul 20 06:33:26.594023 2026] [security2:error] [pid 935758:tid 935975] [client 65.95.194.109:41482] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4VlrcDxY_mIul-JSGu5QAAAV8"]
[Mon Jul 20 06:33:26.594080 2026] [security2:error] [pid 940476:tid 940705] [client 50.116.65.227:51330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VlhjVYcQxwGpYwZm0TgAAAGM"]
[Mon Jul 20 06:33:26.606341 2026] [security2:error] [pid 940476:tid 940695] [client 88.190.72.77:59418] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0TwAAAFk"]
[Mon Jul 20 06:33:26.606775 2026] [security2:error] [pid 940476:tid 940653] [client 50.116.65.227:51336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VlhjVYcQxwGpYwZm0UAAAAC8"]
[Mon Jul 20 06:33:26.611874 2026] [security2:error] [pid 935758:tid 935948] [client 70.24.121.198:47510] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4VlrcDxY_mIul-JSGu5gAAAUQ"]
[Mon Jul 20 06:33:26.615814 2026] [security2:error] [pid 940476:tid 940629] [client 92.16.226.45:53158] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbnka.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0UQAAABc"]
[Mon Jul 20 06:33:26.620890 2026] [security2:error] [pid 935758:tid 935987] [client 79.108.230.152:39655] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4VlrcDxY_mIul-JSGu5wAAAWs"]
[Mon Jul 20 06:33:26.633308 2026] [security2:error] [pid 940476:tid 940638] [client 46.6.48.54:24180] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff"] [unique_id "al4VlhjVYcQxwGpYwZm0UgAAACA"]
[Mon Jul 20 06:33:26.636660 2026] [security2:error] [pid 940476:tid 940708] [client 79.116.174.239:45650] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4VlhjVYcQxwGpYwZm0UwAAAGY"]
[Mon Jul 20 06:33:26.646310 2026] [security2:error] [pid 940476:tid 940608] [client 86.26.209.117:39798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4VlhjVYcQxwGpYwZm0VAAAAAI"]
[Mon Jul 20 06:33:26.647063 2026] [security2:error] [pid 940476:tid 940673] [client 90.113.193.172:48422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff"] [unique_id "al4VlhjVYcQxwGpYwZm0VQAAAEM"]
[Mon Jul 20 06:33:26.655885 2026] [security2:error] [pid 935758:tid 935964] [client 90.243.11.18:58818] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4VlrcDxY_mIul-JSGu6QAAAVQ"]
[Mon Jul 20 06:33:26.671303 2026] [security2:error] [pid 940476:tid 940639] [client 51.190.91.246:1532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4VlhjVYcQxwGpYwZm0VwAAACE"]
[Mon Jul 20 06:33:26.672726 2026] [security2:error] [pid 940476:tid 940640] [client 84.157.211.42:36984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0WAAAACI"]
[Mon Jul 20 06:33:26.685078 2026] [security2:error] [pid 940476:tid 940716] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlhjVYcQxwGpYwZm0OQAAAG4"]
[Mon Jul 20 06:33:26.689464 2026] [security2:error] [pid 940476:tid 940674] [client 113.172.15.38:45243] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0WwAAAEQ"]
[Mon Jul 20 06:33:26.703235 2026] [security2:error] [pid 940476:tid 940711] [client 84.120.71.94:35136] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4VlhjVYcQxwGpYwZm0XAAAAGk"]
[Mon Jul 20 06:33:26.705234 2026] [security2:error] [pid 940476:tid 940719] [client 92.209.206.148:1638] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4VlhjVYcQxwGpYwZm0XQAAAHE"]
[Mon Jul 20 06:33:26.749335 2026] [security2:error] [pid 940476:tid 940607] [client 88.176.94.244:19814] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0YgAAAAE"]
[Mon Jul 20 06:33:26.749335 2026] [security2:error] [pid 940476:tid 940616] [client 87.122.16.4:30502] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4VlhjVYcQxwGpYwZm0YwAAAAo"]
[Mon Jul 20 06:33:26.765666 2026] [security2:error] [pid 940476:tid 940669] [client 90.195.235.248:34790] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0ZwAAAD8"]
[Mon Jul 20 06:33:26.766718 2026] [security2:error] [pid 940476:tid 940683] [client 97.81.201.165:44566] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4VlhjVYcQxwGpYwZm0aAAAAE0"]
[Mon Jul 20 06:33:26.767525 2026] [security2:error] [pid 940476:tid 940676] [client 86.193.228.17:44114] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4VlhjVYcQxwGpYwZm0aQAAAEY"]
[Mon Jul 20 06:33:26.795666 2026] [security2:error] [pid 940476:tid 940659] [client 82.5.29.110:50152] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0bgAAADU"]
[Mon Jul 20 06:33:26.825571 2026] [security2:error] [pid 940476:tid 940678] [client 88.6.47.174:44736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0bwAAAEg"]
[Mon Jul 20 06:33:26.830379 2026] [security2:error] [pid 940476:tid 940733] [client 45.93.58.73:2970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0cQAAAH8"]
[Mon Jul 20 06:33:26.839308 2026] [security2:error] [pid 940476:tid 940646] [client 88.14.114.91:42388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4VlhjVYcQxwGpYwZm0cgAAACg"]
[Mon Jul 20 06:33:26.878320 2026] [security2:error] [pid 940476:tid 940709] [client 143.105.127.118:55642] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4VlhjVYcQxwGpYwZm0dAAAAGc"]
[Mon Jul 20 06:33:26.884328 2026] [security2:error] [pid 935758:tid 936004] [client 62.175.99.145:43956] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4VlrcDxY_mIul-JSGu8gAAAXw"]
[Mon Jul 20 06:33:26.906027 2026] [security2:error] [pid 940476:tid 940645] [client 92.208.65.53:62723] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3yuba.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0dQAAACc"]
[Mon Jul 20 06:33:26.907504 2026] [security2:error] [pid 940476:tid 940688] [client 94.236.209.170:40266] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4VlhjVYcQxwGpYwZm0dgAAAFI"]
[Mon Jul 20 06:33:26.916422 2026] [security2:error] [pid 940476:tid 940720] [client 24.36.97.247:54654] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0eAAAAHI"]
[Mon Jul 20 06:33:26.922689 2026] [security2:error] [pid 940476:tid 940627] [client 82.169.152.148:36062] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0eQAAABU"]
[Mon Jul 20 06:33:26.934213 2026] [security2:error] [pid 940476:tid 940643] [client 89.181.135.141:38620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4VlhjVYcQxwGpYwZm0ewAAACU"]
[Mon Jul 20 06:33:26.939231 2026] [security2:error] [pid 940476:tid 940673] [client 34.73.38.214:50832] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.mpp.jej.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VlhjVYcQxwGpYwZm0fQAAAEM"]
[Mon Jul 20 06:33:27.010518 2026] [security2:error] [pid 940476:tid 940724] [client 86.25.22.84:50808] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4VlxjVYcQxwGpYwZm0gQAAAHY"]
[Mon Jul 20 06:33:27.061362 2026] [security2:error] [pid 935758:tid 935954] [client 190.90.37.117:56102] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4Vl7cDxY_mIul-JSGu9wAAAUo"]
[Mon Jul 20 06:33:27.088164 2026] [security2:error] [pid 935758:tid 935983] [client 103.16.31.150:9678] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4Vl7cDxY_mIul-JSGu-QAAAWc"]
[Mon Jul 20 06:33:27.234086 2026] [security2:error] [pid 940476:tid 940658] [client 14.225.17.146:63718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4VlhjVYcQxwGpYwZm0dwAAADQ"], referer: http://webgardensbypaula.com/Old
[Mon Jul 20 06:33:27.254720 2026] [security2:error] [pid 940476:tid 940706] [client 150.228.61.240:23102] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4VlxjVYcQxwGpYwZm0kQAAAGQ"]
[Mon Jul 20 06:33:27.283462 2026] [security2:error] [pid 935758:tid 935974] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vl7cDxY_mIul-JSGu-AAAAV4"]
[Mon Jul 20 06:33:27.401083 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:49447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlxjVYcQxwGpYwZm0ngAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:27.401185 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:49447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VlxjVYcQxwGpYwZm0ngAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:27.411045 2026] [security2:error] [pid 940476:tid 940729] [client 14.225.17.146:59668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4VlRjVYcQxwGpYwZm0AAAAAHs"], referer: http://fineartsfactory.net/Old
[Mon Jul 20 06:33:27.416702 2026] [security2:error] [pid 940476:tid 940643] [client 85.208.98.23:30734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marscafe.com"] [uri "/robots.txt"] [unique_id "al4VlxjVYcQxwGpYwZm0owAAACU"]
[Mon Jul 20 06:33:27.416852 2026] [security2:error] [pid 940476:tid 940643] [client 85.208.98.23:30734] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.marscafe.com"] [uri "/robots.txt"] [unique_id "al4VlxjVYcQxwGpYwZm0owAAACU"]
[Mon Jul 20 06:33:27.507224 2026] [security2:error] [pid 940476:tid 940718] [client 94.3.228.194:50484] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2"] [unique_id "al4VlxjVYcQxwGpYwZm0qQAAAHA"]
[Mon Jul 20 06:33:27.509865 2026] [security2:error] [pid 940476:tid 940655] [client 103.125.179.95:53546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VlxjVYcQxwGpYwZm0qgAAADE"]
[Mon Jul 20 06:33:27.510055 2026] [security2:error] [pid 940476:tid 940655] [client 103.125.179.95:53546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VlxjVYcQxwGpYwZm0qgAAADE"]
[Mon Jul 20 06:33:27.539708 2026] [security2:error] [pid 935758:tid 936014] [client 57.141.18.57:37706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VkbcDxY_mIul-JSGuZQABhj0"]
[Mon Jul 20 06:33:27.631367 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlxjVYcQxwGpYwZm0nwAAAHI"]
[Mon Jul 20 06:33:27.747649 2026] [security2:error] [pid 940476:tid 940672] [client 177.37.42.187:8346] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufc5qw54a.woff2"] [unique_id "al4VlxjVYcQxwGpYwZm0ugAAAEI"]
[Mon Jul 20 06:33:27.779566 2026] [security2:error] [pid 940476:tid 940701] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VlxjVYcQxwGpYwZm0rwAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:27.811411 2026] [security2:error] [pid 935758:tid 935992] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vl7cDxY_mIul-JSGvBgAAAXA"]
[Mon Jul 20 06:33:27.914832 2026] [security2:error] [pid 940476:tid 940703] [client 187.108.85.186:50761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VlxjVYcQxwGpYwZm0wQAAAGE"]
[Mon Jul 20 06:33:27.914935 2026] [security2:error] [pid 940476:tid 940703] [client 187.108.85.186:50761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VlxjVYcQxwGpYwZm0wQAAAGE"]
[Mon Jul 20 06:33:27.927795 2026] [security2:error] [pid 940476:tid 940620] [client 106.219.188.178:35108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VlxjVYcQxwGpYwZm0wgAAAA4"]
[Mon Jul 20 06:33:27.929353 2026] [security2:error] [pid 940476:tid 940620] [client 106.219.188.178:35108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VlxjVYcQxwGpYwZm0wgAAAA4"]
[Mon Jul 20 06:33:27.942050 2026] [security2:error] [pid 940476:tid 940575] [remote 5.161.225.162:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4VlxjVYcQxwGpYwZm0xAAAdWI"]
[Mon Jul 20 06:33:28.253873 2026] [security2:error] [pid 940476:tid 940707] [client 57.141.18.45:29348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VkhjVYcQxwGpYwZmzSwAAZQI"]
[Mon Jul 20 06:33:28.278533 2026] [security2:error] [pid 940476:tid 940632] [client 102.208.123.68:29727] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamawcubgee.woff2"] [unique_id "al4VmBjVYcQxwGpYwZm01AAAABo"]
[Mon Jul 20 06:33:28.314577 2026] [security2:error] [pid 940476:tid 940628] [client 57.141.18.76:34588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VkhjVYcQxwGpYwZmzUQAAFkU"]
[Mon Jul 20 06:33:28.453647 2026] [security2:error] [pid 935758:tid 935920] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmLcDxY_mIul-JSGvGgAAASg"]
[Mon Jul 20 06:33:28.647889 2026] [security2:error] [pid 940476:tid 940699] [client 57.141.18.96:48188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VkxjVYcQxwGpYwZmzbwAAXUA"]
[Mon Jul 20 06:33:28.648219 2026] [security2:error] [pid 940476:tid 940495] [remote 57.141.18.85:44554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4899371"] [unique_id "al4VmBjVYcQxwGpYwZm07gAAaRI"]
[Mon Jul 20 06:33:28.724189 2026] [security2:error] [pid 940476:tid 940601] [remote 5.161.225.162:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4VmBjVYcQxwGpYwZm0-AAAUXw"], referer: https://schuttfarms.com/wp-login.php
[Mon Jul 20 06:33:28.873556 2026] [security2:error] [pid 940476:tid 940733] [client 104.234.53.62:42175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VmBjVYcQxwGpYwZm1CAAAAH8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:28.883656 2026] [security2:error] [pid 940476:tid 940728] [client 150.109.46.88:36008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4VmBjVYcQxwGpYwZm08QAAAHo"]
[Mon Jul 20 06:33:28.941289 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:49455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VmBjVYcQxwGpYwZm1DQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:28.941429 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:49455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VmBjVYcQxwGpYwZm1DQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:29.082243 2026] [security2:error] [pid 935758:tid 935957] [client 66.183.146.125:34636] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4VmbcDxY_mIul-JSGvLwAAAU0"]
[Mon Jul 20 06:33:29.140612 2026] [security2:error] [pid 935758:tid 935891] [client 52.187.246.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4Vl7cDxY_mIul-JSGvAwAAAQs"]
[Mon Jul 20 06:33:29.492521 2026] [security2:error] [pid 940476:tid 940611] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmRjVYcQxwGpYwZm1JQAAAAU"]
[Mon Jul 20 06:33:29.509865 2026] [security2:error] [pid 940476:tid 940519] [remote 81.173.115.7:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4VmRjVYcQxwGpYwZm1OAAATio"]
[Mon Jul 20 06:33:29.701984 2026] [security2:error] [pid 935758:tid 935999] [client 57.141.18.0:51818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VlLcDxY_mIul-JSGumwABdy8"]
[Mon Jul 20 06:33:29.756664 2026] [security2:error] [pid 935758:tid 936017] [client 223.123.5.211:3799] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4VmbcDxY_mIul-JSGvRAAAAYk"]
[Mon Jul 20 06:33:29.831426 2026] [security2:error] [pid 940476:tid 940634] [client 14.225.17.146:59912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4VmRjVYcQxwGpYwZm1RAAAABw"], referer: http://grndl.com/Old
[Mon Jul 20 06:33:29.848301 2026] [ssl:error] [pid 935758:tid 936015] [client 104.48.69.105:47252] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:33:29.880335 2026] [security2:error] [pid 940476:tid 940637] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmRjVYcQxwGpYwZm1PgAAAB8"]
[Mon Jul 20 06:33:29.918139 2026] [security2:error] [pid 940476:tid 940664] [client 91.161.242.103:10130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4VmRjVYcQxwGpYwZm1TAAAADo"]
[Mon Jul 20 06:33:30.055205 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:49439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VmhjVYcQxwGpYwZm1VwAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:30.055308 2026] [security2:error] [pid 940476:tid 940723] [client 77.110.127.138:49439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VmhjVYcQxwGpYwZm1VwAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:30.059161 2026] [security2:error] [pid 940476:tid 940644] [client 216.73.217.138:4077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VmRjVYcQxwGpYwZm1TgAAJi8"]
[Mon Jul 20 06:33:30.108206 2026] [security2:error] [pid 940476:tid 940549] [remote 81.173.115.7:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4VmhjVYcQxwGpYwZm1XQAAf0g"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:33:30.287934 2026] [security2:error] [pid 940476:tid 940665] [client 20.197.192.193:44839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/667.php"] [unique_id "al4VmhjVYcQxwGpYwZm1bwAAADs"]
[Mon Jul 20 06:33:30.288054 2026] [security2:error] [pid 940476:tid 940665] [client 20.197.192.193:44839] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/667.php"] [unique_id "al4VmhjVYcQxwGpYwZm1bwAAADs"]
[Mon Jul 20 06:33:30.342680 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmhjVYcQxwGpYwZm1WQAAAEk"]
[Mon Jul 20 06:33:30.382663 2026] [security2:error] [pid 940476:tid 940629] [client 186.41.8.15:11686] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4VmhjVYcQxwGpYwZm1cQAAABc"]
[Mon Jul 20 06:33:30.619461 2026] [security2:error] [pid 935758:tid 935897] [client 14.225.17.146:62516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4VmLcDxY_mIul-JSGvLQAAARE"], referer: http://bigwormfishing.com/Old
[Mon Jul 20 06:33:30.748137 2026] [security2:error] [pid 935758:tid 935830] [remote 173.249.4.11:62319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VmrcDxY_mIul-JSGvYQABFkU"]
[Mon Jul 20 06:33:30.748386 2026] [security2:error] [pid 935758:tid 935902] [client 173.249.4.11:62319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VmrcDxY_mIul-JSGvYQABFkU"]
[Mon Jul 20 06:33:30.808610 2026] [security2:error] [pid 940476:tid 940640] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmhjVYcQxwGpYwZm1gAAAACI"], referer: 1'"3000
[Mon Jul 20 06:33:30.977846 2026] [security2:error] [pid 940476:tid 940733] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmhjVYcQxwGpYwZm1jAAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:31.002937 2026] [security2:error] [pid 940476:tid 940564] [remote 42.200.84.61:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VmhjVYcQxwGpYwZm1mgAALlc"]
[Mon Jul 20 06:33:31.069791 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmhjVYcQxwGpYwZm1kgAAAAc"]
[Mon Jul 20 06:33:31.286007 2026] [security2:error] [pid 940476:tid 940662] [client 45.157.112.60:33159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VmxjVYcQxwGpYwZm1pgAAADg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:33:31.395018 2026] [security2:error] [pid 940476:tid 940502] [remote 42.200.84.61:39898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VmxjVYcQxwGpYwZm1rwAARhk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:33:31.436252 2026] [autoindex:error] [pid 940476:tid 940704] [client 62.171.158.190:0] AH01276: Cannot serve directory /home1/aphvlbmy/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:33:31.511063 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:49418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vm7cDxY_mIul-JSGvegAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:31.511235 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:49418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vm7cDxY_mIul-JSGvegAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:31.518954 2026] [security2:error] [pid 940476:tid 940679] [client 171.61.165.146:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VmxjVYcQxwGpYwZm1uAAAAEk"]
[Mon Jul 20 06:33:31.519107 2026] [security2:error] [pid 940476:tid 940679] [client 171.61.165.146:15160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VmxjVYcQxwGpYwZm1uAAAAEk"]
[Mon Jul 20 06:33:31.590019 2026] [security2:error] [pid 940476:tid 940660] [client 14.225.17.146:60029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4VmxjVYcQxwGpYwZm1tQAAADY"], referer: https://bigwormfishing.com/Old
[Mon Jul 20 06:33:31.600585 2026] [security2:error] [pid 935758:tid 936007] [client 57.141.18.70:56524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VlbcDxY_mIul-JSGuzAABf2I"]
[Mon Jul 20 06:33:31.811568 2026] [security2:error] [pid 940476:tid 940608] [client 223.185.13.213:31715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VmxjVYcQxwGpYwZm1zAAAAAI"]
[Mon Jul 20 06:33:31.811707 2026] [security2:error] [pid 940476:tid 940608] [client 223.185.13.213:31715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VmxjVYcQxwGpYwZm1zAAAAAI"]
[Mon Jul 20 06:33:31.845725 2026] [security2:error] [pid 940476:tid 940588] [remote 173.249.4.11:2925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4VmxjVYcQxwGpYwZm10AAADG8"]
[Mon Jul 20 06:33:31.845883 2026] [security2:error] [pid 940476:tid 940618] [client 173.249.4.11:2925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4VmxjVYcQxwGpYwZm10AAADG8"]
[Mon Jul 20 06:33:32.098202 2026] [security2:error] [pid 940476:tid 940733] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VmxjVYcQxwGpYwZm10wAAAH8"]
[Mon Jul 20 06:33:32.288716 2026] [security2:error] [pid 940476:tid 940714] [client 57.141.18.43:34162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VlhjVYcQxwGpYwZm0RAAAbCY"]
[Mon Jul 20 06:33:32.426901 2026] [security2:error] [pid 940476:tid 940729] [client 14.225.17.146:58298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4VmhjVYcQxwGpYwZm1lAAAAHs"], referer: http://colinkeyphotography.com/Old
[Mon Jul 20 06:33:32.694828 2026] [security2:error] [pid 935758:tid 935955] [client 104.234.53.56:25861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VnLcDxY_mIul-JSGvogAAAUs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:32.738661 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:49500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnBjVYcQxwGpYwZm2CgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.738770 2026] [security2:error] [pid 940476:tid 940646] [client 77.110.127.138:49500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnBjVYcQxwGpYwZm2CgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.794646 2026] [security2:error] [pid 935758:tid 935893] [client 77.110.127.138:49451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnLcDxY_mIul-JSGvqQAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.794778 2026] [security2:error] [pid 935758:tid 935893] [client 77.110.127.138:49451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnLcDxY_mIul-JSGvqQAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.844600 2026] [security2:error] [pid 940476:tid 940696] [client 77.110.127.138:49504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnBjVYcQxwGpYwZm2FgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.844706 2026] [security2:error] [pid 940476:tid 940696] [client 77.110.127.138:49504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnBjVYcQxwGpYwZm2FgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.863121 2026] [security2:error] [pid 935758:tid 935927] [client 197.186.66.42:63150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VnLcDxY_mIul-JSGvrwAAAS8"]
[Mon Jul 20 06:33:32.863217 2026] [security2:error] [pid 935758:tid 935927] [client 197.186.66.42:63150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VnLcDxY_mIul-JSGvrwAAAS8"]
[Mon Jul 20 06:33:32.932732 2026] [security2:error] [pid 940476:tid 940632] [client 45.3.45.231:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VnBjVYcQxwGpYwZm2GwAAABo"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:33:32.953892 2026] [security2:error] [pid 940476:tid 940635] [client 77.110.127.138:49506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnBjVYcQxwGpYwZm2HgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:32.953982 2026] [security2:error] [pid 940476:tid 940635] [client 77.110.127.138:49506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnBjVYcQxwGpYwZm2HgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:33.046084 2026] [security2:error] [pid 940476:tid 940643] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VnBjVYcQxwGpYwZm2EQAAACU"]
[Mon Jul 20 06:33:33.071657 2026] [security2:error] [pid 940476:tid 940733] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VnBjVYcQxwGpYwZm2GAAAAH8"], referer: 1'"3000
[Mon Jul 20 06:33:33.160601 2026] [security2:error] [pid 940476:tid 940683] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sah.swq.mybluehost.me"] [uri "/index.php"] [unique_id "al4VmxjVYcQxwGpYwZm1qAAAAE0"]
[Mon Jul 20 06:33:33.213265 2026] [security2:error] [pid 940476:tid 940616] [client 171.60.139.123:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VnRjVYcQxwGpYwZm2LAAAAAo"]
[Mon Jul 20 06:33:33.213364 2026] [security2:error] [pid 940476:tid 940616] [client 171.60.139.123:62933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VnRjVYcQxwGpYwZm2LAAAAAo"]
[Mon Jul 20 06:33:33.216611 2026] [security2:error] [pid 935758:tid 935926] [client 104.234.53.56:25861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VnbcDxY_mIul-JSGvugAAAS4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:33.288534 2026] [security2:error] [pid 940476:tid 940477] [remote 100.42.189.89:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4VnRjVYcQxwGpYwZm2MwAAagA"]
[Mon Jul 20 06:33:33.306424 2026] [security2:error] [pid 940476:tid 940657] [client 14.225.17.146:59673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4VnBjVYcQxwGpYwZm16AAAADM"], referer: http://entuvy.com/Old
[Mon Jul 20 06:33:33.503396 2026] [security2:error] [pid 935758:tid 935768] [remote 8.217.108.67:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4VnbcDxY_mIul-JSGvyQABfQc"]
[Mon Jul 20 06:33:33.507007 2026] [security2:error] [pid 940476:tid 940479] [remote 100.42.189.89:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4VnRjVYcQxwGpYwZm2QQAAKAI"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:33:33.560634 2026] [security2:error] [pid 940476:tid 940628] [client 39.48.81.23:53107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VnRjVYcQxwGpYwZm2QwAAABY"]
[Mon Jul 20 06:33:33.560828 2026] [security2:error] [pid 940476:tid 940628] [client 39.48.81.23:53107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VnRjVYcQxwGpYwZm2QwAAABY"]
[Mon Jul 20 06:33:33.641544 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnRjVYcQxwGpYwZm2SgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:33.641664 2026] [security2:error] [pid 940476:tid 940632] [client 77.110.127.138:49458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnRjVYcQxwGpYwZm2SgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:33.731640 2026] [security2:error] [pid 935758:tid 935898] [client 45.116.69.230:55629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.69.116.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VnbcDxY_mIul-JSGv0gAAARI"]
[Mon Jul 20 06:33:33.731769 2026] [security2:error] [pid 935758:tid 935898] [client 45.116.69.230:55629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xmlrpc.php"] [unique_id "al4VnbcDxY_mIul-JSGv0gAAARI"]
[Mon Jul 20 06:33:33.763707 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VnbcDxY_mIul-JSGvygAAAXg"]
[Mon Jul 20 06:33:33.873610 2026] [security2:error] [pid 940476:tid 940664] [client 168.232.163.251:29668] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4VnRjVYcQxwGpYwZm2VwAAADo"]
[Mon Jul 20 06:33:33.907233 2026] [security2:error] [pid 940476:tid 940704] [client 14.225.17.146:58260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4VnRjVYcQxwGpYwZm2NQAAAGI"], referer: http://drewsasburyparkbeachhouse.com/Old
[Mon Jul 20 06:33:33.992474 2026] [security2:error] [pid 940476:tid 940499] [remote 160.187.68.132:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VnRjVYcQxwGpYwZm2XgAAXhY"]
[Mon Jul 20 06:33:34.137249 2026] [security2:error] [pid 940476:tid 940612] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VnhjVYcQxwGpYwZm2ZQAAAAY"]
[Mon Jul 20 06:33:34.137369 2026] [security2:error] [pid 940476:tid 940612] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VnhjVYcQxwGpYwZm2ZQAAAAY"]
[Mon Jul 20 06:33:34.189505 2026] [security2:error] [pid 940476:tid 940668] [client 104.234.53.93:46111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VnhjVYcQxwGpYwZm2aAAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:34.190087 2026] [security2:error] [pid 935758:tid 935963] [client 57.141.18.117:57706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VmLcDxY_mIul-JSGvIgABU00"]
[Mon Jul 20 06:33:34.300783 2026] [security2:error] [pid 935758:tid 936002] [client 57.141.18.86:48742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VmLcDxY_mIul-JSGvJAABenY"]
[Mon Jul 20 06:33:34.314895 2026] [security2:error] [pid 935758:tid 935870] [remote 8.217.108.67:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4VnrcDxY_mIul-JSGv5AABJW0"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:33:34.457111 2026] [security2:error] [pid 940476:tid 940594] [remote 160.187.68.132:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VnhjVYcQxwGpYwZm2cAAAZXU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:33:34.691928 2026] [security2:error] [pid 940476:tid 940505] [remote 8.217.108.67:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VnhjVYcQxwGpYwZm2gAAAeBw"]
[Mon Jul 20 06:33:34.772113 2026] [proxy:error] [pid 940476:tid 940634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:34.772177 2026] [proxy_http:error] [pid 940476:tid 940634] [client 34.73.38.214:51437] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:34.772874 2026] [proxy:error] [pid 940476:tid 940634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:34.772911 2026] [proxy_http:error] [pid 940476:tid 940634] [client 34.73.38.214:51437] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:34.956629 2026] [security2:error] [pid 940476:tid 940628] [client 14.225.17.146:62242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4VnhjVYcQxwGpYwZm2iAAAABY"], referer: http://alrowad-hub.net/Old
[Mon Jul 20 06:33:35.000561 2026] [security2:error] [pid 940476:tid 940616] [client 103.153.183.69:59914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/ubuntu/.ssh/id_rsa"] [unique_id "al4VnhjVYcQxwGpYwZm2nAAAAAo"], referer: https://duckduckgo.com/?q=vww9s
[Mon Jul 20 06:33:35.047093 2026] [security2:error] [pid 940476:tid 940679] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4VnxjVYcQxwGpYwZm2oAAAAEk"]
[Mon Jul 20 06:33:35.047204 2026] [security2:error] [pid 940476:tid 940679] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4VnxjVYcQxwGpYwZm2oAAAAEk"]
[Mon Jul 20 06:33:35.081049 2026] [security2:error] [pid 940476:tid 940600] [remote 8.217.108.67:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VnxjVYcQxwGpYwZm2owAAJ3s"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:33:35.132148 2026] [security2:error] [pid 940476:tid 940649] [client 57.141.18.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4VnBjVYcQxwGpYwZm2FwAAACs"]
[Mon Jul 20 06:33:35.175008 2026] [security2:error] [pid 935758:tid 935907] [client 14.225.17.146:62351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4VnbcDxY_mIul-JSGv0QAAARs"], referer: http://detroitcsc.com/Old
[Mon Jul 20 06:33:35.287982 2026] [security2:error] [pid 940476:tid 940650] [client 57.141.18.75:37930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VmRjVYcQxwGpYwZm1OwAALDY"]
[Mon Jul 20 06:33:35.287982 2026] [security2:error] [pid 935758:tid 935974] [client 57.141.18.12:34726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VmbcDxY_mIul-JSGvPQABXjk"]
[Mon Jul 20 06:33:35.456007 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vn7cDxY_mIul-JSGwBQAAAT4"]
[Mon Jul 20 06:33:35.456124 2026] [security2:error] [pid 935758:tid 935942] [client 77.110.127.138:49512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vn7cDxY_mIul-JSGwBQAAAT4"]
[Mon Jul 20 06:33:35.469789 2026] [security2:error] [pid 940476:tid 940637] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/media.php"] [unique_id "al4VnxjVYcQxwGpYwZm2xAAAAB8"]
[Mon Jul 20 06:33:35.469909 2026] [security2:error] [pid 940476:tid 940637] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/media.php"] [unique_id "al4VnxjVYcQxwGpYwZm2xAAAAB8"]
[Mon Jul 20 06:33:35.509873 2026] [security2:error] [pid 940476:tid 940647] [client 104.234.53.78:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4VnxjVYcQxwGpYwZm2yQAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:35.547914 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:49402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnxjVYcQxwGpYwZm2ywAAAFI"]
[Mon Jul 20 06:33:35.548105 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:49402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VnxjVYcQxwGpYwZm2ywAAAFI"]
[Mon Jul 20 06:33:35.652544 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VnxjVYcQxwGpYwZm2vAAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:35.783783 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VnxjVYcQxwGpYwZm2xgAAACc"]
[Mon Jul 20 06:33:35.986759 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/images.php"] [unique_id "al4VnxjVYcQxwGpYwZm22wAAAHg"]
[Mon Jul 20 06:33:35.986883 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/images.php"] [unique_id "al4VnxjVYcQxwGpYwZm22wAAAHg"]
[Mon Jul 20 06:33:36.182850 2026] [security2:error] [pid 935758:tid 935946] [client 57.141.18.15:61374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VmrcDxY_mIul-JSGvWgABQlg"]
[Mon Jul 20 06:33:36.354923 2026] [security2:error] [pid 940476:tid 940648] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/gecko.php"] [unique_id "al4VoBjVYcQxwGpYwZm29AAAACo"]
[Mon Jul 20 06:33:36.355114 2026] [security2:error] [pid 940476:tid 940648] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/gecko.php"] [unique_id "al4VoBjVYcQxwGpYwZm29AAAACo"]
[Mon Jul 20 06:33:36.360090 2026] [ssl:error] [pid 935758:tid 935983] [client 104.48.69.105:47256] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:33:36.467908 2026] [security2:error] [pid 940476:tid 940510] [remote 78.46.99.182:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VoBjVYcQxwGpYwZm2-gAAaCE"]
[Mon Jul 20 06:33:36.598979 2026] [security2:error] [pid 940476:tid 940625] [client 163.172.144.16:48524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5016.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4VoBjVYcQxwGpYwZm3AQAAABM"]
[Mon Jul 20 06:33:36.667048 2026] [security2:error] [pid 940476:tid 940645] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/82.php"] [unique_id "al4VoBjVYcQxwGpYwZm3CAAAACc"]
[Mon Jul 20 06:33:36.667153 2026] [security2:error] [pid 940476:tid 940645] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/82.php"] [unique_id "al4VoBjVYcQxwGpYwZm3CAAAACc"]
[Mon Jul 20 06:33:36.669885 2026] [security2:error] [pid 940476:tid 940539] [remote 78.46.99.182:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VoBjVYcQxwGpYwZm3CQAAWj4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:33:36.833056 2026] [security2:error] [pid 940476:tid 940646] [client 74.208.214.194:40556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4VoBjVYcQxwGpYwZm3FQAAACg"]
[Mon Jul 20 06:33:36.862776 2026] [security2:error] [pid 940476:tid 940653] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VoBjVYcQxwGpYwZm3GQAAAC8"]
[Mon Jul 20 06:33:36.862870 2026] [security2:error] [pid 940476:tid 940653] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VoBjVYcQxwGpYwZm3GQAAAC8"]
[Mon Jul 20 06:33:36.988387 2026] [proxy:error] [pid 940476:tid 940703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:36.988461 2026] [proxy_http:error] [pid 940476:tid 940703] [client 34.73.38.214:52474] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:36.989683 2026] [proxy:error] [pid 940476:tid 940703] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:36.989715 2026] [proxy_http:error] [pid 940476:tid 940703] [client 34.73.38.214:52474] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:37.027863 2026] [security2:error] [pid 940476:tid 940647] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/adminner.php"] [unique_id "al4VoRjVYcQxwGpYwZm3IAAAACk"]
[Mon Jul 20 06:33:37.027976 2026] [security2:error] [pid 940476:tid 940647] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/adminner.php"] [unique_id "al4VoRjVYcQxwGpYwZm3IAAAACk"]
[Mon Jul 20 06:33:37.224934 2026] [security2:error] [pid 940476:tid 940699] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VoRjVYcQxwGpYwZm3LwAAAF0"]
[Mon Jul 20 06:33:37.225022 2026] [security2:error] [pid 940476:tid 940699] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VoRjVYcQxwGpYwZm3LwAAAF0"]
[Mon Jul 20 06:33:37.257681 2026] [security2:error] [pid 940476:tid 940730] [client 14.225.17.146:59692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4VnxjVYcQxwGpYwZm22AAAAHw"], referer: http://iagdevelopments.com/Old
[Mon Jul 20 06:33:37.362951 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VoRjVYcQxwGpYwZm3NwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:37.363061 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:49522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VoRjVYcQxwGpYwZm3NwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:37.406163 2026] [security2:error] [pid 940476:tid 940704] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/k.php"] [unique_id "al4VoRjVYcQxwGpYwZm3OwAAAGI"]
[Mon Jul 20 06:33:37.406255 2026] [security2:error] [pid 940476:tid 940704] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/k.php"] [unique_id "al4VoRjVYcQxwGpYwZm3OwAAAGI"]
[Mon Jul 20 06:33:37.486723 2026] [security2:error] [pid 935758:tid 935952] [client 57.141.18.102:21218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VnLcDxY_mIul-JSGvjgABSF8"]
[Mon Jul 20 06:33:37.495833 2026] [ssl:error] [pid 935758:tid 935975] [client 104.48.69.105:47266] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:33:37.538527 2026] [security2:error] [pid 940476:tid 940617] [client 77.110.127.138:49524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VoRjVYcQxwGpYwZm3RgAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:37.538626 2026] [security2:error] [pid 940476:tid 940617] [client 77.110.127.138:49524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VoRjVYcQxwGpYwZm3RgAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:37.687764 2026] [security2:error] [pid 940476:tid 940556] [remote 8.217.108.67:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VoRjVYcQxwGpYwZm3TgAAME8"]
[Mon Jul 20 06:33:37.750462 2026] [security2:error] [pid 940476:tid 940484] [remote 152.228.213.32:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VoRjVYcQxwGpYwZm3UAAAbwc"]
[Mon Jul 20 06:33:37.750658 2026] [security2:error] [pid 940476:tid 940717] [client 152.228.213.32:59930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VoRjVYcQxwGpYwZm3UAAAbwc"]
[Mon Jul 20 06:33:37.885347 2026] [security2:error] [pid 940476:tid 940618] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/blurbs.php"] [unique_id "al4VoRjVYcQxwGpYwZm3WQAAAAw"]
[Mon Jul 20 06:33:37.885489 2026] [security2:error] [pid 940476:tid 940618] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/blurbs.php"] [unique_id "al4VoRjVYcQxwGpYwZm3WQAAAAw"]
[Mon Jul 20 06:33:37.980959 2026] [core:error] [pid 935758:tid 935955] [client 14.225.17.146:63012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:33:37.980978 2026] [core:error] [pid 935758:tid 935955] [client 14.225.17.146:63012] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:33:38.183093 2026] [security2:error] [pid 940476:tid 940647] [client 14.225.17.146:58383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4VohjVYcQxwGpYwZm3ZAAAACk"], referer: https://iagdevelopments.com/Old
[Mon Jul 20 06:33:38.292366 2026] [security2:error] [pid 940476:tid 940694] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/bajah.php"] [unique_id "al4VohjVYcQxwGpYwZm3fwAAAFg"]
[Mon Jul 20 06:33:38.292468 2026] [security2:error] [pid 940476:tid 940694] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/bajah.php"] [unique_id "al4VohjVYcQxwGpYwZm3fwAAAFg"]
[Mon Jul 20 06:33:38.296390 2026] [security2:error] [pid 940476:tid 940703] [client 103.125.179.95:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VohjVYcQxwGpYwZm3fQAAAGE"]
[Mon Jul 20 06:33:38.296524 2026] [security2:error] [pid 940476:tid 940703] [client 103.125.179.95:54024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VohjVYcQxwGpYwZm3fQAAAGE"]
[Mon Jul 20 06:33:38.315062 2026] [security2:error] [pid 940476:tid 940668] [client 14.225.17.146:59837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4VohjVYcQxwGpYwZm3ewAAAD4"], referer: http://thefriendlyspreadsheet.com/Old
[Mon Jul 20 06:33:38.424727 2026] [security2:error] [pid 940476:tid 940625] [client 187.108.85.186:51266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VohjVYcQxwGpYwZm3iQAAABM"]
[Mon Jul 20 06:33:38.424850 2026] [security2:error] [pid 940476:tid 940625] [client 187.108.85.186:51266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VohjVYcQxwGpYwZm3iQAAABM"]
[Mon Jul 20 06:33:38.446945 2026] [security2:error] [pid 935758:tid 935976] [client 46.110.96.34:49436] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4VorcDxY_mIul-JSGwWAAAAWA"]
[Mon Jul 20 06:33:38.663589 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VohjVYcQxwGpYwZm3jAAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:38.879864 2026] [security2:error] [pid 940476:tid 940715] [client 14.225.17.146:62975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4VohjVYcQxwGpYwZm3vwAAAG0"], referer: http://dasmarque.com/Old
[Mon Jul 20 06:33:38.930339 2026] [security2:error] [pid 935758:tid 935894] [client 57.141.18.104:56164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VnbcDxY_mIul-JSGvwwABDkM"]
[Mon Jul 20 06:33:39.036203 2026] [security2:error] [pid 940476:tid 940698] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VohjVYcQxwGpYwZm3vgAAAFw"], referer: 1'"3000
[Mon Jul 20 06:33:39.258953 2026] [security2:error] [pid 940476:tid 940688] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/a.php"] [unique_id "al4VoxjVYcQxwGpYwZm34QAAAFI"]
[Mon Jul 20 06:33:39.259080 2026] [security2:error] [pid 940476:tid 940688] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/a.php"] [unique_id "al4VoxjVYcQxwGpYwZm34QAAAFI"]
[Mon Jul 20 06:33:39.274286 2026] [security2:error] [pid 935758:tid 935959] [client 14.225.17.146:63164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4Vo7cDxY_mIul-JSGwagAAAU8"], referer: http://nextlevelpressurewashing.com/Old
[Mon Jul 20 06:33:39.379305 2026] [security2:error] [pid 940476:tid 940624] [client 113.160.97.242:57720] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4VoxjVYcQxwGpYwZm36gAAABI"]
[Mon Jul 20 06:33:39.577308 2026] [security2:error] [pid 940476:tid 940608] [client 77.110.127.138:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/chevrons-ripples-crochet-course-walton-on-thames/71nzslu7g05h.php"] [unique_id "al4VoxjVYcQxwGpYwZm3-wAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:39.611417 2026] [security2:error] [pid 935758:tid 936005] [client 14.225.17.146:63129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4Vo7cDxY_mIul-JSGwaQAAAX0"], referer: http://waterproofgoods.com/Old
[Mon Jul 20 06:33:39.701940 2026] [security2:error] [pid 940476:tid 940659] [client 57.141.18.104:56174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VnhjVYcQxwGpYwZm2YgAANT8"]
[Mon Jul 20 06:33:39.749589 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm39gAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:39.753491 2026] [proxy:error] [pid 940476:tid 940644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:39.753573 2026] [proxy_http:error] [pid 940476:tid 940644] [client 34.73.38.214:57088] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:39.754423 2026] [proxy:error] [pid 940476:tid 940644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:33:39.754464 2026] [proxy_http:error] [pid 940476:tid 940644] [client 34.73.38.214:57088] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:33:39.796428 2026] [security2:error] [pid 935758:tid 935869] [remote 45.157.112.81:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.112.157.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/xmlrpc.php"] [unique_id "al4Vo7cDxY_mIul-JSGwiQABQ2w"], referer: http://benbayly.co.nz/xmlrpc.php
[Mon Jul 20 06:33:39.895267 2026] [security2:error] [pid 940476:tid 940643] [client 82.102.27.163:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VoxjVYcQxwGpYwZm4OQAAACU"]
[Mon Jul 20 06:33:39.895376 2026] [security2:error] [pid 940476:tid 940643] [client 82.102.27.163:54056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4VoxjVYcQxwGpYwZm4OQAAACU"]
[Mon Jul 20 06:33:39.954293 2026] [security2:error] [pid 940476:tid 940617] [client 77.110.127.138:49541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm3_QAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.024153 2026] [security2:error] [pid 940476:tid 940680] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/edit.php"] [unique_id "al4VpBjVYcQxwGpYwZm4RAAAAEo"]
[Mon Jul 20 06:33:40.024316 2026] [security2:error] [pid 940476:tid 940680] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/edit.php"] [unique_id "al4VpBjVYcQxwGpYwZm4RAAAAEo"]
[Mon Jul 20 06:33:40.062431 2026] [security2:error] [pid 940476:tid 940705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm4AgAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.120665 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:49543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpLcDxY_mIul-JSGwmAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.120791 2026] [security2:error] [pid 935758:tid 935962] [client 77.110.127.138:49543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpLcDxY_mIul-JSGwmAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.129356 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vo7cDxY_mIul-JSGwjAAAAUQ"], referer: 1'"3000
[Mon Jul 20 06:33:40.188650 2026] [security2:error] [pid 940476:tid 940729] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm4OgAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.277278 2026] [autoindex:error] [pid 940476:tid 940646] [client 157.230.13.33:0] AH01276: Cannot serve directory /home1/itdynami/public_html/wp-content/plugins/essential-addons-for-elementor-lite/assets/front-end/img/image-masking/svg-shapes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:33:40.476829 2026] [security2:error] [pid 940476:tid 940707] [client 14.225.17.146:63123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4VoRjVYcQxwGpYwZm3VQAAAGU"], referer: http://bruceledewitz.com/Old
[Mon Jul 20 06:33:40.614301 2026] [security2:error] [pid 940476:tid 940534] [remote 8.217.108.67:3088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4VpBjVYcQxwGpYwZm4dQAAFTk"]
[Mon Jul 20 06:33:40.646428 2026] [security2:error] [pid 940476:tid 940692] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/hosty.php"] [unique_id "al4VpBjVYcQxwGpYwZm4fAAAAFY"]
[Mon Jul 20 06:33:40.646556 2026] [security2:error] [pid 940476:tid 940692] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/hosty.php"] [unique_id "al4VpBjVYcQxwGpYwZm4fAAAAFY"]
[Mon Jul 20 06:33:40.661782 2026] [security2:error] [pid 935758:tid 935901] [client 77.110.127.138:49523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpLcDxY_mIul-JSGwsgAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.661920 2026] [security2:error] [pid 935758:tid 935901] [client 77.110.127.138:49523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpLcDxY_mIul-JSGwsgAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.719740 2026] [security2:error] [pid 935758:tid 935930] [client 77.110.127.138:49526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpLcDxY_mIul-JSGwtQAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.719898 2026] [security2:error] [pid 935758:tid 935930] [client 77.110.127.138:49526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpLcDxY_mIul-JSGwtQAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:40.747102 2026] [security2:error] [pid 935758:tid 936008] [client 112.208.70.94:43288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VpLcDxY_mIul-JSGwuAAAAYA"]
[Mon Jul 20 06:33:40.747271 2026] [security2:error] [pid 935758:tid 936008] [client 112.208.70.94:43288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VpLcDxY_mIul-JSGwuAAAAYA"]
[Mon Jul 20 06:33:41.003129 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:49550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpRjVYcQxwGpYwZm4oAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.003239 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:49550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpRjVYcQxwGpYwZm4oAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.004154 2026] [security2:error] [pid 940476:tid 940642] [client 34.73.38.214:59688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/xmlrpc.php"] [unique_id "al4VpRjVYcQxwGpYwZm4oQAAACQ"]
[Mon Jul 20 06:33:41.008257 2026] [security2:error] [pid 935758:tid 935832] [remote 5.252.52.249:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VpLcDxY_mIul-JSGwxAABIEc"]
[Mon Jul 20 06:33:41.024695 2026] [security2:error] [pid 940476:tid 940630] [client 50.116.65.227:22900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/08/IMG_8766.jpeg"] [unique_id "al4VpRjVYcQxwGpYwZm4pAAAABg"]
[Mon Jul 20 06:33:41.230606 2026] [security2:error] [pid 935758:tid 935931] [client 77.110.127.138:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/chevrons-ripples-crochet-course-walton-on-thames/embed/c1glp30nn14c.php"] [unique_id "al4VpbcDxY_mIul-JSGw1AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.255195 2026] [security2:error] [pid 935758:tid 935798] [remote 5.252.52.249:55654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VpbcDxY_mIul-JSGw2gABcyU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:33:41.346951 2026] [security2:error] [pid 940476:tid 940657] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VpRjVYcQxwGpYwZm4qwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.371557 2026] [security2:error] [pid 940476:tid 940640] [client 14.225.17.146:59812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm37QAAACI"], referer: http://ccsdifference.com/Old
[Mon Jul 20 06:33:41.429306 2026] [security2:error] [pid 940476:tid 940721] [client 178.20.47.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4VpRjVYcQxwGpYwZm4tQAAAHM"], referer: https://blog.danwolfe.us/2021/02/18/we-have-landed/#comment-41471
[Mon Jul 20 06:33:41.442925 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:49477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpRjVYcQxwGpYwZm44AAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.443239 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:49477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpRjVYcQxwGpYwZm44AAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.548084 2026] [security2:error] [pid 940476:tid 940723] [client 57.141.18.111:64156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VnxjVYcQxwGpYwZm20gAAdUs"]
[Mon Jul 20 06:33:41.615529 2026] [security2:error] [pid 935758:tid 935967] [client 57.141.18.26:37942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vn7cDxY_mIul-JSGwDwABV3E"]
[Mon Jul 20 06:33:41.671996 2026] [security2:error] [pid 940476:tid 940733] [client 223.185.13.213:29946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VpRjVYcQxwGpYwZm4_gAAAH8"]
[Mon Jul 20 06:33:41.672173 2026] [security2:error] [pid 940476:tid 940733] [client 223.185.13.213:29946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VpRjVYcQxwGpYwZm4_gAAAH8"]
[Mon Jul 20 06:33:41.723129 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:49556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VpRjVYcQxwGpYwZm4vgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.725675 2026] [security2:error] [pid 940476:tid 940693] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VpRjVYcQxwGpYwZm4ygAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.735573 2026] [security2:error] [pid 935758:tid 936016] [client 57.141.18.34:47850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vn7cDxY_mIul-JSGwEwABiCE"]
[Mon Jul 20 06:33:41.765607 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VpRjVYcQxwGpYwZm4yQAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:41.827363 2026] [security2:error] [pid 935758:tid 935945] [client 47.128.119.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4VpbcDxY_mIul-JSGw1QAAAUE"]
[Mon Jul 20 06:33:42.058483 2026] [security2:error] [pid 940476:tid 940733] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/k.php"] [unique_id "al4VphjVYcQxwGpYwZm5JwAAAH8"]
[Mon Jul 20 06:33:42.058594 2026] [security2:error] [pid 940476:tid 940733] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/k.php"] [unique_id "al4VphjVYcQxwGpYwZm5JwAAAH8"]
[Mon Jul 20 06:33:42.192444 2026] [security2:error] [pid 935758:tid 936009] [client 104.234.53.68:57933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VprcDxY_mIul-JSGxCgAAAYE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:42.269343 2026] [security2:error] [pid 935758:tid 936006] [client 66.249.79.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.undefeatedthe.com"] [uri "/index.php"] [unique_id "al4VoLcDxY_mIul-JSGwLQAAAX4"]
[Mon Jul 20 06:33:42.463325 2026] [security2:error] [pid 940476:tid 940660] [client 14.225.17.146:60138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4VpRjVYcQxwGpYwZm4uAAAADY"], referer: http://northbrookcpa.ca/Old
[Mon Jul 20 06:33:42.473369 2026] [security2:error] [pid 935758:tid 935986] [client 14.225.17.146:49610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4VprcDxY_mIul-JSGxCwAAAWo"], referer: https://ccsdifference.com/Old
[Mon Jul 20 06:33:42.746356 2026] [security2:error] [pid 940476:tid 940665] [client 20.197.192.193:58822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/09.php"] [unique_id "al4VphjVYcQxwGpYwZm5dgAAADs"]
[Mon Jul 20 06:33:42.746437 2026] [security2:error] [pid 940476:tid 940665] [client 20.197.192.193:58822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/09.php"] [unique_id "al4VphjVYcQxwGpYwZm5dgAAADs"]
[Mon Jul 20 06:33:42.762277 2026] [security2:error] [pid 940476:tid 940729] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/aaa.php"] [unique_id "al4VphjVYcQxwGpYwZm5dwAAAHs"]
[Mon Jul 20 06:33:42.762380 2026] [security2:error] [pid 940476:tid 940729] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/aaa.php"] [unique_id "al4VphjVYcQxwGpYwZm5dwAAAHs"]
[Mon Jul 20 06:33:42.989756 2026] [security2:error] [pid 940476:tid 940669] [client 57.141.18.12:56072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VoRjVYcQxwGpYwZm3MQAAPww"]
[Mon Jul 20 06:33:42.996157 2026] [security2:error] [pid 940476:tid 940521] [remote 162.19.86.63:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4VphjVYcQxwGpYwZm5kQAAHiw"]
[Mon Jul 20 06:33:43.043523 2026] [security2:error] [pid 935758:tid 935868] [remote 47.86.33.52:23580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Vp7cDxY_mIul-JSGxKgABRWs"]
[Mon Jul 20 06:33:43.046139 2026] [security2:error] [pid 935758:tid 935974] [client 57.141.18.87:34666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VobcDxY_mIul-JSGwOwABXlM"]
[Mon Jul 20 06:33:43.180268 2026] [security2:error] [pid 935758:tid 935945] [client 34.73.38.214:56781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Vp7cDxY_mIul-JSGxLgAAAUE"]
[Mon Jul 20 06:33:43.193173 2026] [security2:error] [pid 940476:tid 940727] [client 57.141.18.84:23694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VoRjVYcQxwGpYwZm3QQAAeVY"]
[Mon Jul 20 06:33:43.210116 2026] [security2:error] [pid 940476:tid 940507] [remote 162.19.86.63:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4VpxjVYcQxwGpYwZm5mgAATB4"], referer: https://mail.factsandminds.com/wp-login.php
[Mon Jul 20 06:33:43.239179 2026] [security2:error] [pid 940476:tid 940699] [client 14.225.17.146:49966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4VpxjVYcQxwGpYwZm5lQAAAF0"], referer: http://aljosour-alarabia.com/Old
[Mon Jul 20 06:33:43.242102 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:49544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vp7cDxY_mIul-JSGxMgAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.242250 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:49544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vp7cDxY_mIul-JSGxMgAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.303435 2026] [autoindex:error] [pid 935758:tid 935906] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/genesis/lib/js/menu/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/themes/genesis/lib/js/menu/
[Mon Jul 20 06:33:43.346433 2026] [security2:error] [pid 940476:tid 940705] [client 77.110.127.138:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpxjVYcQxwGpYwZm5pAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.346580 2026] [security2:error] [pid 940476:tid 940705] [client 77.110.127.138:49563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpxjVYcQxwGpYwZm5pAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.422634 2026] [security2:error] [pid 935758:tid 935930] [client 13.201.64.214:47166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Vp7cDxY_mIul-JSGxPAAAATI"]
[Mon Jul 20 06:33:43.422852 2026] [security2:error] [pid 935758:tid 935930] [client 13.201.64.214:47166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Vp7cDxY_mIul-JSGxPAAAATI"]
[Mon Jul 20 06:33:43.542126 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VpxjVYcQxwGpYwZm5oAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.616322 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpxjVYcQxwGpYwZm5ugAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.616420 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:49566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VpxjVYcQxwGpYwZm5ugAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:43.719719 2026] [security2:error] [pid 935758:tid 935767] [remote 47.86.33.52:23580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Vp7cDxY_mIul-JSGxRQABbgY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:33:43.750340 2026] [security2:error] [pid 935758:tid 935910] [client 82.224.86.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4VpbcDxY_mIul-JSGxAQAAAR4"], referer: https://areitoproducciones.com/
[Mon Jul 20 06:33:43.818337 2026] [security2:error] [pid 940476:tid 940678] [client 197.186.66.42:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VpxjVYcQxwGpYwZm5wQAAAEg"]
[Mon Jul 20 06:33:43.818438 2026] [security2:error] [pid 940476:tid 940678] [client 197.186.66.42:63642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VpxjVYcQxwGpYwZm5wQAAAEg"]
[Mon Jul 20 06:33:43.837387 2026] [security2:error] [pid 940476:tid 940695] [client 171.60.139.123:63447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VpxjVYcQxwGpYwZm5xAAAAFk"]
[Mon Jul 20 06:33:43.837521 2026] [security2:error] [pid 940476:tid 940695] [client 171.60.139.123:63447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VpxjVYcQxwGpYwZm5xAAAAFk"]
[Mon Jul 20 06:33:43.838402 2026] [security2:error] [pid 940476:tid 940665] [client 39.48.81.23:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VpxjVYcQxwGpYwZm5xQAAADs"]
[Mon Jul 20 06:33:43.838761 2026] [security2:error] [pid 940476:tid 940665] [client 39.48.81.23:53605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VpxjVYcQxwGpYwZm5xQAAADs"]
[Mon Jul 20 06:33:43.984129 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VpxjVYcQxwGpYwZm5vgAAAA8"]
[Mon Jul 20 06:33:44.234660 2026] [security2:error] [pid 935758:tid 935876] [remote 195.26.253.119:43774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VqLcDxY_mIul-JSGxVgABMXM"]
[Mon Jul 20 06:33:44.261497 2026] [security2:error] [pid 940476:tid 940695] [client 34.73.38.214:51695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VqBjVYcQxwGpYwZm54QAAAFk"]
[Mon Jul 20 06:33:44.262762 2026] [fcgid:warn] [pid 935758:tid 936012] (70014)End of file found: [client 217.181.95.230:53032] mod_fcgid: can't get data from http client
[Mon Jul 20 06:33:44.337907 2026] [security2:error] [pid 940476:tid 940622] [client 57.141.18.61:25452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VohjVYcQxwGpYwZm3twAAEFo"]
[Mon Jul 20 06:33:44.372804 2026] [security2:error] [pid 940476:tid 940534] [remote 167.233.114.32:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VqBjVYcQxwGpYwZm55QAAHjk"]
[Mon Jul 20 06:33:44.389706 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VqBjVYcQxwGpYwZm55gAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:44.389826 2026] [security2:error] [pid 940476:tid 940731] [client 77.110.127.138:49570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VqBjVYcQxwGpYwZm55gAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:44.406540 2026] [security2:error] [pid 935758:tid 935818] [remote 195.26.253.119:43774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VqLcDxY_mIul-JSGxXAABTzk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:33:44.624457 2026] [security2:error] [pid 940476:tid 940490] [remote 167.233.114.32:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VqBjVYcQxwGpYwZm59gAAKg0"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:33:44.660721 2026] [security2:error] [pid 935758:tid 936011] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/file5.php"] [unique_id "al4VqLcDxY_mIul-JSGxZAAAAYM"]
[Mon Jul 20 06:33:44.660881 2026] [security2:error] [pid 935758:tid 936011] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/file5.php"] [unique_id "al4VqLcDxY_mIul-JSGxZAAAAYM"]
[Mon Jul 20 06:33:44.662027 2026] [security2:error] [pid 935758:tid 935981] [client 57.141.18.51:23610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vo7cDxY_mIul-JSGwaAABZSs"]
[Mon Jul 20 06:33:44.714507 2026] [security2:error] [pid 940476:tid 940613] [client 57.141.18.74:25118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm31gAAB10"]
[Mon Jul 20 06:33:44.726983 2026] [security2:error] [pid 940476:tid 940615] [client 57.141.18.14:29890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VoxjVYcQxwGpYwZm31wAACSg"]
[Mon Jul 20 06:33:44.745994 2026] [security2:error] [pid 940476:tid 940661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqBjVYcQxwGpYwZm57gAAADc"]
[Mon Jul 20 06:33:44.921264 2026] [security2:error] [pid 940476:tid 940717] [client 77.110.127.138:49539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/corner-to-corner/ys1dszz2rphl.php"] [unique_id "al4VqBjVYcQxwGpYwZm6DAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:44.973132 2026] [security2:error] [pid 935758:tid 935898] [client 77.110.127.138:49553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VqLcDxY_mIul-JSGxbQAAARI"], referer: https://mezzacraft.com/tag/crochet-classes/
[Mon Jul 20 06:33:45.090074 2026] [security2:error] [pid 940476:tid 940520] [remote 130.51.180.8:48192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4VqRjVYcQxwGpYwZm6HAAAfys"]
[Mon Jul 20 06:33:45.282984 2026] [security2:error] [pid 940476:tid 940519] [remote 130.51.180.8:48192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4VqRjVYcQxwGpYwZm6LwAAYSo"], referer: https://dlu.cjf.mybluehost.me/blog/wp-login.php
[Mon Jul 20 06:33:45.434683 2026] [security2:error] [pid 935758:tid 935910] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqLcDxY_mIul-JSGxcAAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:45.492693 2026] [security2:error] [pid 935758:tid 935999] [client 217.181.95.230:20420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4VqbcDxY_mIul-JSGxgAAAAXc"]
[Mon Jul 20 06:33:45.493948 2026] [security2:error] [pid 935758:tid 935866] [remote 103.255.134.61:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VqbcDxY_mIul-JSGxggABQGk"]
[Mon Jul 20 06:33:45.693300 2026] [security2:error] [pid 935758:tid 935983] [client 77.110.127.138:49577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqbcDxY_mIul-JSGxeAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:45.724207 2026] [security2:error] [pid 935758:tid 935913] [client 57.141.18.112:38296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VpLcDxY_mIul-JSGwoQABITE"]
[Mon Jul 20 06:33:45.776552 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqRjVYcQxwGpYwZm6KwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:45.907929 2026] [security2:error] [pid 940476:tid 940712] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/222.php"] [unique_id "al4VqRjVYcQxwGpYwZm6WwAAAGo"]
[Mon Jul 20 06:33:45.908031 2026] [security2:error] [pid 940476:tid 940712] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/222.php"] [unique_id "al4VqRjVYcQxwGpYwZm6WwAAAGo"]
[Mon Jul 20 06:33:45.957429 2026] [security2:error] [pid 940476:tid 940696] [client 77.110.127.138:49585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/crochet-tips-tutorials/9uyxiou38irb.php"] [unique_id "al4VqRjVYcQxwGpYwZm6YQAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:45.980227 2026] [security2:error] [pid 940476:tid 940698] [client 14.225.17.146:58604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4VqBjVYcQxwGpYwZm51AAAAFw"]
[Mon Jul 20 06:33:46.053620 2026] [security2:error] [pid 935758:tid 935849] [remote 103.255.134.61:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VqrcDxY_mIul-JSGxkQABTFg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:33:46.062269 2026] [security2:error] [pid 940476:tid 940540] [remote 72.167.132.114:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VqhjVYcQxwGpYwZm6cAAAPT8"]
[Mon Jul 20 06:33:46.185597 2026] [security2:error] [pid 940476:tid 940714] [client 50.116.65.227:23034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VqhjVYcQxwGpYwZm6eQAAAGw"]
[Mon Jul 20 06:33:46.199196 2026] [security2:error] [pid 940476:tid 940694] [client 50.116.65.227:23048] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VqhjVYcQxwGpYwZm6egAAAFg"]
[Mon Jul 20 06:33:46.201182 2026] [security2:error] [pid 935758:tid 935909] [client 77.110.127.138:49571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqbcDxY_mIul-JSGxigAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:46.203856 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqRjVYcQxwGpYwZm6WAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:46.239636 2026] [security2:error] [pid 940476:tid 940660] [client 14.225.17.146:64539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4VqhjVYcQxwGpYwZm6dQAAADY"], referer: http://christiancountytrumpet.com/Old
[Mon Jul 20 06:33:46.379522 2026] [security2:error] [pid 940476:tid 940591] [remote 72.167.132.114:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VqhjVYcQxwGpYwZm6ggAAcnI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:33:46.426347 2026] [security2:error] [pid 940476:tid 940657] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqRjVYcQxwGpYwZm6aQAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:46.489206 2026] [security2:error] [pid 940476:tid 940711] [client 103.153.183.69:41156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/deploy/.ssh/id_rsa"] [unique_id "al4VqhjVYcQxwGpYwZm6igAAAGk"], referer: https://duckduckgo.com/?q=iyxl0
[Mon Jul 20 06:33:46.734778 2026] [security2:error] [pid 940476:tid 940665] [client 34.73.38.214:51788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VqhjVYcQxwGpYwZm6ngAAADs"]
[Mon Jul 20 06:33:46.735320 2026] [security2:error] [pid 935758:tid 935841] [remote 8.217.108.67:9824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VqrcDxY_mIul-JSGxqQABP1A"], referer: https://maa.hws.mybluehost.me/wp-login.php
[Mon Jul 20 06:33:46.814145 2026] [security2:error] [pid 940476:tid 940712] [client 5.155.11.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4VqhjVYcQxwGpYwZm6jAAAam4"]
[Mon Jul 20 06:33:46.913042 2026] [security2:error] [pid 940476:tid 940695] [client 77.110.127.138:49590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VqhjVYcQxwGpYwZm6qQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:46.913167 2026] [security2:error] [pid 940476:tid 940695] [client 77.110.127.138:49590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VqhjVYcQxwGpYwZm6qQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.067858 2026] [security2:error] [pid 940476:tid 940662] [client 57.141.18.1:26970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VphjVYcQxwGpYwZm5PAAAOFI"]
[Mon Jul 20 06:33:47.226103 2026] [security2:error] [pid 940476:tid 940636] [client 77.110.127.138:49552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-pattern/we8o9k9v9l63.php"] [unique_id "al4VqxjVYcQxwGpYwZm6uwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.440233 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:49517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqxjVYcQxwGpYwZm6vQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.472113 2026] [security2:error] [pid 935758:tid 935900] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vq7cDxY_mIul-JSGxvwAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.473298 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqxjVYcQxwGpYwZm6wgAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.598298 2026] [security2:error] [pid 940476:tid 940689] [client 14.225.17.146:64729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4VqxjVYcQxwGpYwZm61wAAAFM"], referer: http://ivetstrategies.com/Old
[Mon Jul 20 06:33:47.608361 2026] [security2:error] [pid 935758:tid 935969] [client 66.249.70.128:65418] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.umatha.art"] [uri "/robots.txt"] [unique_id "al4Vq7cDxY_mIul-JSGxyAAAAVk"]
[Mon Jul 20 06:33:47.628487 2026] [security2:error] [pid 940476:tid 940528] [remote 193.70.112.205:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VqxjVYcQxwGpYwZm65gAALzM"]
[Mon Jul 20 06:33:47.662224 2026] [security2:error] [pid 935758:tid 936011] [client 77.110.127.138:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/free-crochet-patterns/cnd9i01tn9fg.php"] [unique_id "al4Vq7cDxY_mIul-JSGxzQAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.710905 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:49569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VqxjVYcQxwGpYwZm69wAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.711049 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:49569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VqxjVYcQxwGpYwZm69wAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:47.861402 2026] [security2:error] [pid 940476:tid 940571] [remote 193.70.112.205:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VqxjVYcQxwGpYwZm7CgAAcV4"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:33:48.025593 2026] [security2:error] [pid 940476:tid 940630] [client 57.141.18.84:52676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VpxjVYcQxwGpYwZm5mwAAGHM"]
[Mon Jul 20 06:33:48.113882 2026] [security2:error] [pid 935758:tid 936000] [client 34.74.185.202:62358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VrLcDxY_mIul-JSGx5AAAAXg"]
[Mon Jul 20 06:33:48.242829 2026] [security2:error] [pid 935758:tid 935960] [client 77.110.127.138:49596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vq7cDxY_mIul-JSGx2gAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:48.453252 2026] [security2:error] [pid 940476:tid 940654] [client 40.77.179.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4VrBjVYcQxwGpYwZm7JwAAADA"]
[Mon Jul 20 06:33:48.456000 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vq7cDxY_mIul-JSGx4AAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:48.457867 2026] [security2:error] [pid 940476:tid 940637] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VqxjVYcQxwGpYwZm7BwAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:48.651466 2026] [security2:error] [pid 940476:tid 940730] [client 57.141.18.11:63778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VpxjVYcQxwGpYwZm5wgAAfB8"]
[Mon Jul 20 06:33:48.662920 2026] [security2:error] [pid 935758:tid 935949] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/test.php"] [unique_id "al4VrLcDxY_mIul-JSGx-AAAAUU"]
[Mon Jul 20 06:33:48.663053 2026] [security2:error] [pid 935758:tid 935949] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/test.php"] [unique_id "al4VrLcDxY_mIul-JSGx-AAAAUU"]
[Mon Jul 20 06:33:48.730700 2026] [security2:error] [pid 935758:tid 935908] [client 14.225.17.146:55463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VrLcDxY_mIul-JSGx8QAAARw"], referer: http://mezzacraft.com/Old
[Mon Jul 20 06:33:48.833175 2026] [security2:error] [pid 935758:tid 936002] [client 74.7.227.179:59694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VrLcDxY_mIul-JSGx-gABeiI"], referer: https://tejasenvironmental.com/p=1949990
[Mon Jul 20 06:33:48.911878 2026] [security2:error] [pid 935758:tid 935808] [remote 8.217.108.67:1274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4VrLcDxY_mIul-JSGyEQABGC8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:33:49.089445 2026] [security2:error] [pid 935758:tid 935931] [client 34.74.185.202:65144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VrbcDxY_mIul-JSGyFwAAATM"]
[Mon Jul 20 06:33:49.206216 2026] [security2:error] [pid 940476:tid 940658] [client 187.108.85.186:51801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VrRjVYcQxwGpYwZm7XQAAADQ"]
[Mon Jul 20 06:33:49.206375 2026] [security2:error] [pid 940476:tid 940658] [client 187.108.85.186:51801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VrRjVYcQxwGpYwZm7XQAAADQ"]
[Mon Jul 20 06:33:49.221085 2026] [security2:error] [pid 940476:tid 940707] [client 103.125.179.95:54509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VrRjVYcQxwGpYwZm7XgAAAGU"]
[Mon Jul 20 06:33:49.221270 2026] [security2:error] [pid 940476:tid 940707] [client 103.125.179.95:54509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VrRjVYcQxwGpYwZm7XgAAAGU"]
[Mon Jul 20 06:33:49.328838 2026] [security2:error] [pid 935758:tid 936013] [client 106.219.188.178:10299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VrbcDxY_mIul-JSGyIQAAAYU"]
[Mon Jul 20 06:33:49.329015 2026] [security2:error] [pid 935758:tid 936013] [client 106.219.188.178:10299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4VrbcDxY_mIul-JSGyIQAAAYU"]
[Mon Jul 20 06:33:49.530984 2026] [security2:error] [pid 940476:tid 940706] [client 57.141.18.76:64146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VqBjVYcQxwGpYwZm58gAAZBI"]
[Mon Jul 20 06:33:49.536006 2026] [security2:error] [pid 940476:tid 940668] [client 47.128.22.85:35660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jvcmotorsports.com"] [uri "/robots.txt"] [unique_id "al4VrRjVYcQxwGpYwZm7dgAAAD4"]
[Mon Jul 20 06:33:49.544007 2026] [autoindex:error] [pid 940476:tid 940729] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/genesis/lib/js/menu/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:33:49.595533 2026] [security2:error] [pid 935758:tid 935897] [client 34.73.38.214:55849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VrbcDxY_mIul-JSGyKQAAARE"]
[Mon Jul 20 06:33:49.693705 2026] [security2:error] [pid 940476:tid 940660] [client 77.110.127.138:49517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VrRjVYcQxwGpYwZm7hQAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:49.693854 2026] [security2:error] [pid 940476:tid 940660] [client 77.110.127.138:49517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VrRjVYcQxwGpYwZm7hQAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:49.715501 2026] [security2:error] [pid 935758:tid 935957] [client 82.224.86.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4Vq7cDxY_mIul-JSGx4wAAAU0"], referer: https://areitoproducciones.com/instrumentos-virtuales/
[Mon Jul 20 06:33:49.726837 2026] [security2:error] [pid 940476:tid 940722] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/aaa.php"] [unique_id "al4VrRjVYcQxwGpYwZm7hwAAAHQ"]
[Mon Jul 20 06:33:49.726947 2026] [security2:error] [pid 940476:tid 940722] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/aaa.php"] [unique_id "al4VrRjVYcQxwGpYwZm7hwAAAHQ"]
[Mon Jul 20 06:33:49.785382 2026] [security2:error] [pid 940476:tid 940524] [remote 209.42.18.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4VrRjVYcQxwGpYwZm7iwAAKS8"]
[Mon Jul 20 06:33:49.867832 2026] [security2:error] [pid 940476:tid 940681] [client 13.233.207.33:33958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4VrRjVYcQxwGpYwZm7VgAAAEs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:33:49.994120 2026] [security2:error] [pid 940476:tid 940510] [remote 209.42.18.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4VrRjVYcQxwGpYwZm7lgAALyE"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 06:33:50.292416 2026] [security2:error] [pid 940476:tid 940625] [client 14.225.17.146:58972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4VrBjVYcQxwGpYwZm7LgAAABM"], referer: http://scott-assist.com/Old
[Mon Jul 20 06:33:50.375994 2026] [security2:error] [pid 940476:tid 940659] [client 34.74.185.202:63046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VrhjVYcQxwGpYwZm7uAAAADU"]
[Mon Jul 20 06:33:50.413739 2026] [security2:error] [pid 935758:tid 935989] [client 195.2.79.165:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.79.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VrrcDxY_mIul-JSGyPQAAAW0"], referer: https://swafforddetailing.com/
[Mon Jul 20 06:33:50.443680 2026] [security2:error] [pid 940476:tid 940677] [client 14.225.17.146:58917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4VrRjVYcQxwGpYwZm7eAAAAEc"], referer: http://processorstudio.com/Old
[Mon Jul 20 06:33:50.469461 2026] [security2:error] [pid 940476:tid 940658] [client 77.110.127.138:49609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VrhjVYcQxwGpYwZm7vAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:50.469571 2026] [security2:error] [pid 940476:tid 940658] [client 77.110.127.138:49609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VrhjVYcQxwGpYwZm7vAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:50.526568 2026] [security2:error] [pid 940476:tid 940617] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/11.php"] [unique_id "al4VrhjVYcQxwGpYwZm7vwAAAAs"]
[Mon Jul 20 06:33:50.526670 2026] [security2:error] [pid 940476:tid 940617] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/11.php"] [unique_id "al4VrhjVYcQxwGpYwZm7vwAAAAs"]
[Mon Jul 20 06:33:50.726742 2026] [security2:error] [pid 940476:tid 940692] [client 14.225.17.146:58940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4VrRjVYcQxwGpYwZm7awAAAFY"], referer: http://39ishlife.com/Old
[Mon Jul 20 06:33:50.857669 2026] [security2:error] [pid 940476:tid 940668] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/mac.php"] [unique_id "al4VrhjVYcQxwGpYwZm72AAAAD4"]
[Mon Jul 20 06:33:50.857788 2026] [security2:error] [pid 940476:tid 940668] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/mac.php"] [unique_id "al4VrhjVYcQxwGpYwZm72AAAAD4"]
[Mon Jul 20 06:33:50.887384 2026] [security2:error] [pid 940476:tid 940664] [client 57.141.18.117:52228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VqRjVYcQxwGpYwZm6WgAAOkc"]
[Mon Jul 20 06:33:50.938564 2026] [security2:error] [pid 940476:tid 940702] [client 57.141.18.16:58554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VqRjVYcQxwGpYwZm6XwAAYFA"]
[Mon Jul 20 06:33:51.083760 2026] [security2:error] [pid 940476:tid 940610] [client 34.73.38.214:50738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VrxjVYcQxwGpYwZm78AAAAAQ"]
[Mon Jul 20 06:33:51.240141 2026] [security2:error] [pid 940476:tid 940640] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VrxjVYcQxwGpYwZm75AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:51.287486 2026] [security2:error] [pid 940476:tid 940667] [client 14.225.17.146:64674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4VrxjVYcQxwGpYwZm7-wAAAD0"], referer: https://processorstudio.com/Old
[Mon Jul 20 06:33:51.434208 2026] [security2:error] [pid 940476:tid 940706] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/chosen.php"] [unique_id "al4VrxjVYcQxwGpYwZm8DQAAAGQ"]
[Mon Jul 20 06:33:51.434313 2026] [security2:error] [pid 940476:tid 940706] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/chosen.php"] [unique_id "al4VrxjVYcQxwGpYwZm8DQAAAGQ"]
[Mon Jul 20 06:33:51.503108 2026] [security2:error] [pid 935758:tid 935928] [client 77.110.127.138:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Vr7cDxY_mIul-JSGyVgAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:51.523716 2026] [security2:error] [pid 940476:tid 940489] [remote 4.205.168.44:49960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VrxjVYcQxwGpYwZm8EAAARAw"]
[Mon Jul 20 06:33:51.523868 2026] [security2:error] [pid 940476:tid 940674] [client 4.205.168.44:49960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VrxjVYcQxwGpYwZm8EAAARAw"]
[Mon Jul 20 06:33:51.640831 2026] [security2:error] [pid 940476:tid 940730] [client 14.225.17.146:58944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4VrxjVYcQxwGpYwZm8EgAAAHw"], referer: https://39ishlife.com/Old
[Mon Jul 20 06:33:51.702450 2026] [security2:error] [pid 935758:tid 935893] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/cream1.php"] [unique_id "al4Vr7cDxY_mIul-JSGyZQAAAQ0"]
[Mon Jul 20 06:33:51.702550 2026] [security2:error] [pid 935758:tid 935893] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/cream1.php"] [unique_id "al4Vr7cDxY_mIul-JSGyZQAAAQ0"]
[Mon Jul 20 06:33:51.914312 2026] [security2:error] [pid 940476:tid 940603] [remote 72.167.132.114:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VrxjVYcQxwGpYwZm8JQAAAX4"]
[Mon Jul 20 06:33:52.029833 2026] [security2:error] [pid 935758:tid 935955] [client 14.225.17.146:59008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4Vr7cDxY_mIul-JSGybQAAAUs"], referer: http://eduardsales.com/Old
[Mon Jul 20 06:33:52.066642 2026] [security2:error] [pid 940476:tid 940651] [client 34.74.185.202:57159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VsBjVYcQxwGpYwZm8LQAAAC0"]
[Mon Jul 20 06:33:52.077464 2026] [security2:error] [pid 940476:tid 940611] [client 223.185.13.213:32276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VsBjVYcQxwGpYwZm8LAAAAAU"]
[Mon Jul 20 06:33:52.077706 2026] [security2:error] [pid 940476:tid 940611] [client 223.185.13.213:32276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VsBjVYcQxwGpYwZm8LAAAAAU"]
[Mon Jul 20 06:33:52.137662 2026] [security2:error] [pid 940476:tid 940528] [remote 72.167.132.114:58450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VsBjVYcQxwGpYwZm8NgAAETM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:33:52.224193 2026] [security2:error] [pid 935758:tid 935956] [client 34.73.38.214:52668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VsLcDxY_mIul-JSGygQAAAUw"]
[Mon Jul 20 06:33:52.263795 2026] [security2:error] [pid 935758:tid 935933] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-content/uploads/"] [unique_id "al4VsLcDxY_mIul-JSGyhQAAATU"]
[Mon Jul 20 06:33:52.267184 2026] [security2:error] [pid 940476:tid 940617] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-content/uploads/"] [unique_id "al4VsBjVYcQxwGpYwZm8PwAAAAs"]
[Mon Jul 20 06:33:52.556699 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsBjVYcQxwGpYwZm8WQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:52.556823 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsBjVYcQxwGpYwZm8WQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:52.748470 2026] [security2:error] [pid 940476:tid 940696] [client 34.74.185.202:63973] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VsBjVYcQxwGpYwZm8aAAAAFo"]
[Mon Jul 20 06:33:52.843548 2026] [security2:error] [pid 940476:tid 940490] [remote 97.74.93.24:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4VsBjVYcQxwGpYwZm8bwAANA0"]
[Mon Jul 20 06:33:52.986175 2026] [security2:error] [pid 935758:tid 935772] [remote 192.241.143.148:41832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VsLcDxY_mIul-JSGymQABVgs"]
[Mon Jul 20 06:33:53.001616 2026] [security2:error] [pid 940476:tid 940606] [client 57.141.18.76:64158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrBjVYcQxwGpYwZm7GQAAAAg"]
[Mon Jul 20 06:33:53.140384 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsRjVYcQxwGpYwZm8fAAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:53.140493 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:49574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsRjVYcQxwGpYwZm8fAAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:53.178620 2026] [security2:error] [pid 935758:tid 935794] [remote 192.241.143.148:41832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VsbcDxY_mIul-JSGynAABESE"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:33:53.227840 2026] [security2:error] [pid 940476:tid 940541] [remote 97.74.93.24:59036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4VsRjVYcQxwGpYwZm8hAAAEUA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:33:53.228568 2026] [security2:error] [pid 940476:tid 940713] [client 14.225.17.146:64511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4VrxjVYcQxwGpYwZm79QAAAGs"], referer: http://savilerowtravel.com/Old
[Mon Jul 20 06:33:53.239190 2026] [autoindex:error] [pid 940476:tid 940733] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:33:53.239887 2026] [security2:error] [pid 940476:tid 940733] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VsRjVYcQxwGpYwZm8gwAAAH8"]
[Mon Jul 20 06:33:53.249247 2026] [security2:error] [pid 940476:tid 940659] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-content/uploads/"] [unique_id "al4VsRjVYcQxwGpYwZm8fwAAADU"]
[Mon Jul 20 06:33:53.371590 2026] [security2:error] [pid 940476:tid 940637] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/Text/"] [unique_id "al4VsRjVYcQxwGpYwZm8lQAAAB8"]
[Mon Jul 20 06:33:53.374001 2026] [security2:error] [pid 940476:tid 940669] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/Text/"] [unique_id "al4VsRjVYcQxwGpYwZm8kQAAAD8"]
[Mon Jul 20 06:33:53.395276 2026] [security2:error] [pid 935758:tid 935923] [client 34.74.185.202:64534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VsbcDxY_mIul-JSGypQAAASs"]
[Mon Jul 20 06:33:53.428628 2026] [security2:error] [pid 940476:tid 940706] [client 34.73.38.214:56284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VsRjVYcQxwGpYwZm8mAAAAGQ"]
[Mon Jul 20 06:33:53.440805 2026] [security2:error] [pid 940476:tid 940720] [client 14.225.17.146:59114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4VrxjVYcQxwGpYwZm8FAAAAHI"], referer: http://areitoproducciones.com/Old
[Mon Jul 20 06:33:53.461679 2026] [autoindex:error] [pid 940476:tid 940662] [client 170.106.140.110:0] AH01276: Cannot serve directory /home2/genspagr/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.genspagroup.com
[Mon Jul 20 06:33:53.477626 2026] [autoindex:error] [pid 935758:tid 935955] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:33:53.478217 2026] [security2:error] [pid 935758:tid 935955] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VsbcDxY_mIul-JSGyqgAAAUs"]
[Mon Jul 20 06:33:53.481274 2026] [security2:error] [pid 940476:tid 940617] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/Text/"] [unique_id "al4VsRjVYcQxwGpYwZm8mwAAAAs"]
[Mon Jul 20 06:33:53.487631 2026] [security2:error] [pid 935758:tid 935986] [client 57.141.18.56:47370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrLcDxY_mIul-JSGx9AABalk"]
[Mon Jul 20 06:33:53.522838 2026] [security2:error] [pid 935758:tid 936015] [client 98.159.234.160:46913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VsbcDxY_mIul-JSGyrAAAAYc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:33:53.543957 2026] [security2:error] [pid 940476:tid 940695] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/dr.php"] [unique_id "al4VsRjVYcQxwGpYwZm8qQAAAFk"]
[Mon Jul 20 06:33:53.544062 2026] [security2:error] [pid 940476:tid 940695] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/dr.php"] [unique_id "al4VsRjVYcQxwGpYwZm8qQAAAFk"]
[Mon Jul 20 06:33:53.548550 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VsbcDxY_mIul-JSGyrQAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:53.589494 2026] [security2:error] [pid 940476:tid 940703] [client 57.141.18.0:39704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrBjVYcQxwGpYwZm7OAAAYSs"]
[Mon Jul 20 06:33:53.776013 2026] [security2:error] [pid 940476:tid 940657] [client 34.73.38.214:52200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VsRjVYcQxwGpYwZm8vAAAADM"]
[Mon Jul 20 06:33:53.780276 2026] [security2:error] [pid 940476:tid 940688] [client 34.74.185.202:64509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VsRjVYcQxwGpYwZm8vQAAAFI"]
[Mon Jul 20 06:33:53.790440 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VsRjVYcQxwGpYwZm8pQAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:53.827526 2026] [security2:error] [pid 940476:tid 940683] [client 77.110.127.138:49564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VsRjVYcQxwGpYwZm8qwAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:53.847011 2026] [security2:error] [pid 940476:tid 940719] [client 112.208.70.94:43804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VsRjVYcQxwGpYwZm8xAAAAHE"]
[Mon Jul 20 06:33:53.847169 2026] [security2:error] [pid 940476:tid 940719] [client 112.208.70.94:43804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VsRjVYcQxwGpYwZm8xAAAAHE"]
[Mon Jul 20 06:33:54.084284 2026] [security2:error] [pid 940476:tid 940702] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/x.php"] [unique_id "al4VshjVYcQxwGpYwZm8zwAAAGA"]
[Mon Jul 20 06:33:54.084414 2026] [security2:error] [pid 940476:tid 940702] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/x.php"] [unique_id "al4VshjVYcQxwGpYwZm8zwAAAGA"]
[Mon Jul 20 06:33:54.152136 2026] [security2:error] [pid 940476:tid 940626] [client 77.110.127.138:49611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VsRjVYcQxwGpYwZm8xgAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:54.239660 2026] [security2:error] [pid 940476:tid 940718] [client 57.141.18.22:59362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrRjVYcQxwGpYwZm7YgAAcDY"]
[Mon Jul 20 06:33:54.242457 2026] [security2:error] [pid 940476:tid 940733] [client 14.225.17.146:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4VshjVYcQxwGpYwZm8zgAAAH8"], referer: https://savilerowtravel.com/Old
[Mon Jul 20 06:33:54.339082 2026] [security2:error] [pid 940476:tid 940711] [client 197.186.66.42:64144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VshjVYcQxwGpYwZm84wAAAGk"]
[Mon Jul 20 06:33:54.351803 2026] [security2:error] [pid 940476:tid 940711] [client 197.186.66.42:64144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VshjVYcQxwGpYwZm84wAAAGk"]
[Mon Jul 20 06:33:54.419462 2026] [security2:error] [pid 935758:tid 935965] [client 57.141.18.31:50874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrbcDxY_mIul-JSGyKAABVVI"]
[Mon Jul 20 06:33:54.477661 2026] [security2:error] [pid 940476:tid 940696] [client 39.48.81.23:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VshjVYcQxwGpYwZm87QAAAFo"]
[Mon Jul 20 06:33:54.477847 2026] [security2:error] [pid 940476:tid 940696] [client 39.48.81.23:54101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VshjVYcQxwGpYwZm87QAAAFo"]
[Mon Jul 20 06:33:54.546882 2026] [security2:error] [pid 940476:tid 940644] [client 114.119.139.19:31019] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "phillipbloch.com"] [uri "/contact"] [unique_id "al4VshjVYcQxwGpYwZm88gAAACY"], referer: http://phillipbloch.com/news/P195
[Mon Jul 20 06:33:54.617189 2026] [security2:error] [pid 940476:tid 940676] [client 34.74.185.202:62983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VshjVYcQxwGpYwZm89QAAAEY"]
[Mon Jul 20 06:33:54.620936 2026] [security2:error] [pid 940476:tid 940726] [client 57.141.18.82:55408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrRjVYcQxwGpYwZm7gwAAeHw"]
[Mon Jul 20 06:33:54.650100 2026] [security2:error] [pid 935758:tid 935950] [client 171.60.139.123:63980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VsrcDxY_mIul-JSGyyQAAAUY"]
[Mon Jul 20 06:33:54.650218 2026] [security2:error] [pid 935758:tid 935950] [client 171.60.139.123:63980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VsrcDxY_mIul-JSGyyQAAAUY"]
[Mon Jul 20 06:33:54.837935 2026] [security2:error] [pid 940476:tid 940551] [remote 95.217.78.234:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4VshjVYcQxwGpYwZm9CAAAXko"]
[Mon Jul 20 06:33:54.876759 2026] [security2:error] [pid 940476:tid 940625] [client 103.153.183.69:27532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.jjw.pvq.mybluehost.me"] [uri "/"] [unique_id "al4VshjVYcQxwGpYwZm9CwAAABM"], referer: https://www.reddit.com/
[Mon Jul 20 06:33:54.952429 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:49631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VshjVYcQxwGpYwZm9EgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:54.952550 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:49631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VshjVYcQxwGpYwZm9EgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.004317 2026] [security2:error] [pid 935758:tid 935966] [client 77.110.127.138:49532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4Vs7cDxY_mIul-JSGyzwAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.065595 2026] [security2:error] [pid 940476:tid 940578] [remote 95.217.78.234:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4VsxjVYcQxwGpYwZm9HQAADWU"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 06:33:55.089284 2026] [security2:error] [pid 935758:tid 935924] [client 104.234.53.51:28709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Vs7cDxY_mIul-JSGy0wAAASw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:55.128478 2026] [security2:error] [pid 940476:tid 940634] [client 77.110.127.138:49633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9IwAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.128622 2026] [security2:error] [pid 940476:tid 940634] [client 77.110.127.138:49633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9IwAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.139323 2026] [security2:error] [pid 940476:tid 940717] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VshjVYcQxwGpYwZm9DAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.160309 2026] [security2:error] [pid 940476:tid 940526] [remote 47.86.33.52:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4VsxjVYcQxwGpYwZm9JQAAAjE"]
[Mon Jul 20 06:33:55.165491 2026] [security2:error] [pid 940476:tid 940708] [client 77.110.127.138:49630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VshjVYcQxwGpYwZm9DQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.222026 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:49617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9KQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.222170 2026] [security2:error] [pid 940476:tid 940621] [client 77.110.127.138:49617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9KQAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.234631 2026] [security2:error] [pid 940476:tid 940627] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/155.php"] [unique_id "al4VsxjVYcQxwGpYwZm9KgAAABU"]
[Mon Jul 20 06:33:55.234764 2026] [security2:error] [pid 940476:tid 940627] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/155.php"] [unique_id "al4VsxjVYcQxwGpYwZm9KgAAABU"]
[Mon Jul 20 06:33:55.272777 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9LAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.272899 2026] [security2:error] [pid 940476:tid 940665] [client 77.110.127.138:49619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9LAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.339634 2026] [security2:error] [pid 940476:tid 940700] [client 77.110.127.138:49607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9MgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.339759 2026] [security2:error] [pid 940476:tid 940700] [client 77.110.127.138:49607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VsxjVYcQxwGpYwZm9MgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.388215 2026] [security2:error] [pid 935758:tid 936004] [client 50.116.65.227:21742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Vs7cDxY_mIul-JSGy2wAAAXw"]
[Mon Jul 20 06:33:55.390710 2026] [security2:error] [pid 935758:tid 935844] [remote 5.161.225.162:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4Vs7cDxY_mIul-JSGy3AABX1M"]
[Mon Jul 20 06:33:55.398803 2026] [security2:error] [pid 935758:tid 935945] [client 50.116.65.227:21750] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Vs7cDxY_mIul-JSGy3QAAAUE"]
[Mon Jul 20 06:33:55.460028 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:49636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vs7cDxY_mIul-JSGy3gAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.460136 2026] [security2:error] [pid 935758:tid 935997] [client 77.110.127.138:49636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vs7cDxY_mIul-JSGy3gAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.463698 2026] [security2:error] [pid 935758:tid 936000] [client 34.73.38.214:62482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Vs7cDxY_mIul-JSGy4QAAAXg"]
[Mon Jul 20 06:33:55.490074 2026] [security2:error] [pid 935758:tid 936015] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ops.php"] [unique_id "al4Vs7cDxY_mIul-JSGy4wAAAYc"]
[Mon Jul 20 06:33:55.490213 2026] [security2:error] [pid 935758:tid 936015] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ops.php"] [unique_id "al4Vs7cDxY_mIul-JSGy4wAAAYc"]
[Mon Jul 20 06:33:55.515705 2026] [security2:error] [pid 935758:tid 935923] [client 34.74.185.202:55684] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Vs7cDxY_mIul-JSGy5QAAASs"]
[Mon Jul 20 06:33:55.536217 2026] [security2:error] [pid 935758:tid 935897] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vs7cDxY_mIul-JSGy1wAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.604571 2026] [security2:error] [pid 940476:tid 940557] [remote 47.86.33.52:53884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4VsxjVYcQxwGpYwZm9QQAAPlA"], referer: https://uninursity.com/wp-login.php
[Mon Jul 20 06:33:55.699002 2026] [security2:error] [pid 935758:tid 935951] [client 77.110.127.138:49635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vs7cDxY_mIul-JSGy2gAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:55.711051 2026] [security2:error] [pid 935758:tid 935786] [remote 5.161.225.162:39948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4Vs7cDxY_mIul-JSGy7AABTBk"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:33:55.736356 2026] [security2:error] [pid 940476:tid 940642] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/file31.php"] [unique_id "al4VsxjVYcQxwGpYwZm9SwAAACQ"]
[Mon Jul 20 06:33:55.736443 2026] [security2:error] [pid 940476:tid 940642] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/file31.php"] [unique_id "al4VsxjVYcQxwGpYwZm9SwAAACQ"]
[Mon Jul 20 06:33:55.765211 2026] [security2:error] [pid 935758:tid 936013] [client 74.7.244.61:59618] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.rvprintfactory.com"] [uri "/index.php"] [unique_id "al4Vs7cDxY_mIul-JSGy6wABhXY"]
[Mon Jul 20 06:33:55.770733 2026] [core:error] [pid 940476:tid 940667] [client 14.225.17.146:57543] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:33:55.770767 2026] [core:error] [pid 940476:tid 940667] [client 14.225.17.146:57543] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:33:55.784480 2026] [security2:error] [pid 940476:tid 940719] [client 34.73.38.214:61656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VsxjVYcQxwGpYwZm9VQAAAHE"]
[Mon Jul 20 06:33:55.807494 2026] [security2:error] [pid 935758:tid 935921] [client 34.74.185.202:51738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Vs7cDxY_mIul-JSGy7gAAASk"]
[Mon Jul 20 06:33:56.003437 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:49608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9YAAAAAQ"]
[Mon Jul 20 06:33:56.003551 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:49608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9YAAAAAQ"]
[Mon Jul 20 06:33:56.054117 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:49611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9ZQAAACw"]
[Mon Jul 20 06:33:56.054235 2026] [security2:error] [pid 940476:tid 940650] [client 77.110.127.138:49611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9ZQAAACw"]
[Mon Jul 20 06:33:56.125615 2026] [security2:error] [pid 940476:tid 940636] [client 20.197.192.193:44845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/fz.php"] [unique_id "al4VtBjVYcQxwGpYwZm9bAAAAB4"]
[Mon Jul 20 06:33:56.125735 2026] [security2:error] [pid 940476:tid 940636] [client 20.197.192.193:44845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/fz.php"] [unique_id "al4VtBjVYcQxwGpYwZm9bAAAAB4"]
[Mon Jul 20 06:33:56.224918 2026] [security2:error] [pid 940476:tid 940728] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/file6.php"] [unique_id "al4VtBjVYcQxwGpYwZm9dgAAAHo"]
[Mon Jul 20 06:33:56.225027 2026] [security2:error] [pid 940476:tid 940728] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/file6.php"] [unique_id "al4VtBjVYcQxwGpYwZm9dgAAAHo"]
[Mon Jul 20 06:33:56.380661 2026] [security2:error] [pid 940476:tid 940733] [client 77.110.127.138:49565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtBjVYcQxwGpYwZm9bwAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.397083 2026] [security2:error] [pid 940476:tid 940670] [client 57.141.18.118:56968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VrxjVYcQxwGpYwZm8BAAAQCw"]
[Mon Jul 20 06:33:56.425650 2026] [security2:error] [pid 940476:tid 940528] [remote 173.249.4.11:40147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4VtBjVYcQxwGpYwZm9igAAEDM"]
[Mon Jul 20 06:33:56.495185 2026] [security2:error] [pid 935758:tid 935900] [client 14.225.17.146:57610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4VtLcDxY_mIul-JSGy-wAAARQ"]
[Mon Jul 20 06:33:56.650210 2026] [security2:error] [pid 940476:tid 940702] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/assets/"] [unique_id "al4VtBjVYcQxwGpYwZm9mwAAAGA"]
[Mon Jul 20 06:33:56.654264 2026] [security2:error] [pid 940476:tid 940680] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/assets/"] [unique_id "al4VtBjVYcQxwGpYwZm9lgAAAEo"]
[Mon Jul 20 06:33:56.659714 2026] [security2:error] [pid 940476:tid 940515] [remote 173.249.4.11:40147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4VtBjVYcQxwGpYwZm9nQAAVCY"], referer: https://alaraycreative.com/wp-login.php
[Mon Jul 20 06:33:56.680293 2026] [security2:error] [pid 940476:tid 940642] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtBjVYcQxwGpYwZm9gAAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.680815 2026] [security2:error] [pid 935758:tid 935818] [remote 192.241.143.148:41848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4VtLcDxY_mIul-JSGzBAABRTk"]
[Mon Jul 20 06:33:56.748290 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49582] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VtBjVYcQxwGpYwZm9pAAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.769626 2026] [security2:error] [pid 935758:tid 935959] [client 104.234.53.63:45463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VtLcDxY_mIul-JSGzAwAAAU8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:56.811685 2026] [autoindex:error] [pid 935758:tid 935960] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:33:56.812359 2026] [security2:error] [pid 935758:tid 935960] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VtLcDxY_mIul-JSGzBgAAAVA"]
[Mon Jul 20 06:33:56.815053 2026] [security2:error] [pid 940476:tid 940664] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/assets/"] [unique_id "al4VtBjVYcQxwGpYwZm9owAAADo"]
[Mon Jul 20 06:33:56.897253 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9tQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.897338 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9tQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.899380 2026] [security2:error] [pid 940476:tid 940720] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/adminfuns.php"] [unique_id "al4VtBjVYcQxwGpYwZm9tgAAAHI"]
[Mon Jul 20 06:33:56.899538 2026] [security2:error] [pid 940476:tid 940720] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/adminfuns.php"] [unique_id "al4VtBjVYcQxwGpYwZm9tgAAAHI"]
[Mon Jul 20 06:33:56.945675 2026] [security2:error] [pid 940476:tid 940649] [client 77.110.127.138:49644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtBjVYcQxwGpYwZm9ngAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.948794 2026] [security2:error] [pid 940476:tid 940707] [client 34.73.38.214:64967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.nikkidesigns.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VtBjVYcQxwGpYwZm9vAAAAGU"]
[Mon Jul 20 06:33:56.948828 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:49630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9vQAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.948998 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:49630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtBjVYcQxwGpYwZm9vQAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:56.952277 2026] [security2:error] [pid 940476:tid 940655] [client 34.74.185.202:55126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VtBjVYcQxwGpYwZm9vgAAADE"]
[Mon Jul 20 06:33:56.972743 2026] [security2:error] [pid 935758:tid 935804] [remote 192.241.143.148:41848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4VtLcDxY_mIul-JSGzCgABPCs"], referer: https://pscmedicalbilling.com/wp-login.php
[Mon Jul 20 06:33:57.021307 2026] [security2:error] [pid 935758:tid 935985] [client 57.141.18.0:34454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsLcDxY_mIul-JSGycgABaVs"]
[Mon Jul 20 06:33:57.085189 2026] [security2:error] [pid 940476:tid 940658] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/goods.php"] [unique_id "al4VtRjVYcQxwGpYwZm9-wAAADQ"]
[Mon Jul 20 06:33:57.085284 2026] [security2:error] [pid 940476:tid 940658] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/goods.php"] [unique_id "al4VtRjVYcQxwGpYwZm9-wAAADQ"]
[Mon Jul 20 06:33:57.172051 2026] [security2:error] [pid 940476:tid 940620] [client 57.141.18.85:59296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsBjVYcQxwGpYwZm8MgAADg4"]
[Mon Jul 20 06:33:57.228237 2026] [security2:error] [pid 935758:tid 935893] [client 34.74.185.202:51703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VtbcDxY_mIul-JSGzEQAAAQ0"]
[Mon Jul 20 06:33:57.247558 2026] [security2:error] [pid 940476:tid 940726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtBjVYcQxwGpYwZm9uwAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:57.314555 2026] [security2:error] [pid 935758:tid 935998] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/100.php"] [unique_id "al4VtbcDxY_mIul-JSGzEwAAAXY"]
[Mon Jul 20 06:33:57.314664 2026] [security2:error] [pid 935758:tid 935998] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/100.php"] [unique_id "al4VtbcDxY_mIul-JSGzEwAAAXY"]
[Mon Jul 20 06:33:57.490400 2026] [security2:error] [pid 935758:tid 936000] [client 104.234.53.63:45463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VtbcDxY_mIul-JSGzFgAAAXg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:33:57.528313 2026] [security2:error] [pid 940476:tid 940708] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/about.php"] [unique_id "al4VtRjVYcQxwGpYwZm-HgAAAGY"]
[Mon Jul 20 06:33:57.528416 2026] [security2:error] [pid 940476:tid 940708] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/about.php"] [unique_id "al4VtRjVYcQxwGpYwZm-HgAAAGY"]
[Mon Jul 20 06:33:57.539668 2026] [security2:error] [pid 940476:tid 940683] [client 14.225.17.146:59384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4VtBjVYcQxwGpYwZm9YwAAAE0"], referer: http://solkeetw.com/Old
[Mon Jul 20 06:33:57.560428 2026] [security2:error] [pid 940476:tid 940706] [client 171.61.165.146:17754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VtRjVYcQxwGpYwZm-JgAAAGQ"]
[Mon Jul 20 06:33:57.560581 2026] [security2:error] [pid 940476:tid 940706] [client 171.61.165.146:17754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VtRjVYcQxwGpYwZm-JgAAAGQ"]
[Mon Jul 20 06:33:57.640664 2026] [security2:error] [pid 940476:tid 940622] [client 34.74.185.202:56763] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.poopatrol608.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VtRjVYcQxwGpYwZm-LAAAABA"]
[Mon Jul 20 06:33:57.655911 2026] [core:error] [pid 940476:tid 940719] [client 14.225.17.146:57530] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Old
[Mon Jul 20 06:33:57.655933 2026] [core:error] [pid 940476:tid 940719] [client 14.225.17.146:57530] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Old
[Mon Jul 20 06:33:57.670507 2026] [security2:error] [pid 940476:tid 940624] [client 57.141.18.99:27378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsBjVYcQxwGpYwZm8UQAAEjo"]
[Mon Jul 20 06:33:58.007419 2026] [security2:error] [pid 940476:tid 940700] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtRjVYcQxwGpYwZm-OgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.033790 2026] [security2:error] [pid 940476:tid 940701] [client 77.110.127.138:49657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtRjVYcQxwGpYwZm-PgAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.104624 2026] [security2:error] [pid 935758:tid 936012] [client 20.197.192.193:58877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/taff.php"] [unique_id "al4VtrcDxY_mIul-JSGzJwAAAYQ"]
[Mon Jul 20 06:33:58.104714 2026] [security2:error] [pid 935758:tid 936012] [client 20.197.192.193:58877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/taff.php"] [unique_id "al4VtrcDxY_mIul-JSGzJwAAAYQ"]
[Mon Jul 20 06:33:58.324236 2026] [security2:error] [pid 940476:tid 940627] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/about.php"] [unique_id "al4VthjVYcQxwGpYwZm-ZwAAABU"]
[Mon Jul 20 06:33:58.324354 2026] [security2:error] [pid 940476:tid 940627] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/about.php"] [unique_id "al4VthjVYcQxwGpYwZm-ZwAAABU"]
[Mon Jul 20 06:33:58.466043 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VthjVYcQxwGpYwZm-VwAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.492277 2026] [security2:error] [pid 940476:tid 940623] [client 77.110.127.138:49634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VthjVYcQxwGpYwZm-WQAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.582588 2026] [security2:error] [pid 935758:tid 935894] [client 57.141.18.22:59366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsbcDxY_mIul-JSGynQABDkA"]
[Mon Jul 20 06:33:58.585800 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:49564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VthjVYcQxwGpYwZm-eQAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.719148 2026] [security2:error] [pid 940476:tid 940694] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VthjVYcQxwGpYwZm-iwAAAFg"]
[Mon Jul 20 06:33:58.719285 2026] [security2:error] [pid 940476:tid 940694] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VthjVYcQxwGpYwZm-iwAAAFg"]
[Mon Jul 20 06:33:58.884905 2026] [security2:error] [pid 940476:tid 940641] [client 57.141.18.105:26322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsRjVYcQxwGpYwZm8oAAAI2o"]
[Mon Jul 20 06:33:58.943432 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtrcDxY_mIul-JSGzPAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.943554 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:49637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtrcDxY_mIul-JSGzPAAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:58.977516 2026] [security2:error] [pid 940476:tid 940696] [client 74.7.175.155:47836] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "join.learnthissecret.com"] [uri "/index.php"] [unique_id "al4VsxjVYcQxwGpYwZm9RAAAWmc"]
[Mon Jul 20 06:33:59.000447 2026] [security2:error] [pid 940476:tid 940664] [client 14.225.17.146:59344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4VtRjVYcQxwGpYwZm-HwAAADo"], referer: http://inspirespublishing.com/Old
[Mon Jul 20 06:33:59.103449 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-oQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.103555 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:49678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-oQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.119446 2026] [security2:error] [pid 940476:tid 940710] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VtxjVYcQxwGpYwZm-owAAAGg"]
[Mon Jul 20 06:33:59.119602 2026] [security2:error] [pid 940476:tid 940710] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/admin.php"] [unique_id "al4VtxjVYcQxwGpYwZm-owAAAGg"]
[Mon Jul 20 06:33:59.183505 2026] [security2:error] [pid 940476:tid 940682] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VthjVYcQxwGpYwZm-mAAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.419185 2026] [security2:error] [pid 940476:tid 940703] [client 77.110.127.138:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-tQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.419286 2026] [security2:error] [pid 940476:tid 940703] [client 77.110.127.138:49640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-tQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.470584 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-twAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.470758 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:49641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-twAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.522564 2026] [security2:error] [pid 935758:tid 936009] [client 77.110.127.138:49679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vt7cDxY_mIul-JSGzRAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.576880 2026] [core:error] [pid 940476:tid 940645] [client 103.153.183.69:27532] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e%u002e/.env?_=oocnqkvo&v=0jx71), referer: https://twitter.com/
[Mon Jul 20 06:33:59.600623 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/themes.php"] [unique_id "al4VtxjVYcQxwGpYwZm-vQAAAHg"]
[Mon Jul 20 06:33:59.600708 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/themes.php"] [unique_id "al4VtxjVYcQxwGpYwZm-vQAAAHg"]
[Mon Jul 20 06:33:59.625608 2026] [security2:error] [pid 940476:tid 940624] [client 77.110.127.138:49681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-wQAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.625699 2026] [security2:error] [pid 940476:tid 940624] [client 77.110.127.138:49681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-wQAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.652923 2026] [security2:error] [pid 935758:tid 936001] [client 187.108.85.186:52309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Vt7cDxY_mIul-JSGzSgAAAXk"]
[Mon Jul 20 06:33:59.653050 2026] [security2:error] [pid 935758:tid 936001] [client 187.108.85.186:52309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Vt7cDxY_mIul-JSGzSgAAAXk"]
[Mon Jul 20 06:33:59.763213 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:49643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-xAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.763341 2026] [security2:error] [pid 940476:tid 940654] [client 77.110.127.138:49643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-xAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.816550 2026] [security2:error] [pid 940476:tid 940718] [client 77.110.127.138:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-xgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.816660 2026] [security2:error] [pid 940476:tid 940718] [client 77.110.127.138:49629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VtxjVYcQxwGpYwZm-xgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.924967 2026] [security2:error] [pid 940476:tid 940614] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4VtxjVYcQxwGpYwZm-zgAAAAg"]
[Mon Jul 20 06:33:59.926427 2026] [security2:error] [pid 935758:tid 935998] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4Vt7cDxY_mIul-JSGzVgAAAXY"]
[Mon Jul 20 06:33:59.990317 2026] [security2:error] [pid 935758:tid 935917] [client 77.110.127.138:49693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vt7cDxY_mIul-JSGzWQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.990412 2026] [security2:error] [pid 935758:tid 935917] [client 77.110.127.138:49693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Vt7cDxY_mIul-JSGzWQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:33:59.996178 2026] [security2:error] [pid 940476:tid 940622] [client 103.125.179.95:54991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VtxjVYcQxwGpYwZm-0gAAABA"]
[Mon Jul 20 06:33:59.996315 2026] [security2:error] [pid 940476:tid 940622] [client 103.125.179.95:54991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VtxjVYcQxwGpYwZm-0gAAABA"]
[Mon Jul 20 06:34:00.085894 2026] [lsapi:warn] [pid 940476:tid 940677] [client 14.225.17.146:53286] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Old
[Mon Jul 20 06:34:00.085922 2026] [lsapi:warn] [pid 940476:tid 940677] [client 14.225.17.146:53286] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Old
[Mon Jul 20 06:34:00.101362 2026] [security2:error] [pid 940476:tid 940666] [client 57.141.18.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VtxjVYcQxwGpYwZm-0AAAADw"]
[Mon Jul 20 06:34:00.145552 2026] [security2:error] [pid 940476:tid 940607] [client 77.110.127.138:49690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VtxjVYcQxwGpYwZm-zwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:00.327193 2026] [security2:error] [pid 935758:tid 935938] [client 185.61.216.143:20117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4Vt7cDxY_mIul-JSGzRgABOkQ"]
[Mon Jul 20 06:34:00.384613 2026] [security2:error] [pid 935758:tid 935979] [client 77.110.127.138:49621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VuLcDxY_mIul-JSGzZAAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:00.487699 2026] [security2:error] [pid 935758:tid 935856] [remote 8.217.108.67:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4VuLcDxY_mIul-JSGzZgABLF8"]
[Mon Jul 20 06:34:00.506059 2026] [autoindex:error] [pid 940476:tid 940683] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:00.506600 2026] [security2:error] [pid 940476:tid 940683] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VuBjVYcQxwGpYwZm-8wAAAE0"]
[Mon Jul 20 06:34:00.510003 2026] [security2:error] [pid 940476:tid 940702] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4VuBjVYcQxwGpYwZm-8QAAAGA"]
[Mon Jul 20 06:34:00.527475 2026] [security2:error] [pid 940476:tid 940641] [client 77.110.127.138:49655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VuBjVYcQxwGpYwZm-4QAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:00.546631 2026] [security2:error] [pid 940476:tid 940687] [client 20.197.192.193:44804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/ty.php"] [unique_id "al4VuBjVYcQxwGpYwZm--AAAAFE"]
[Mon Jul 20 06:34:00.546721 2026] [security2:error] [pid 940476:tid 940687] [client 20.197.192.193:44804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/ty.php"] [unique_id "al4VuBjVYcQxwGpYwZm--AAAAFE"]
[Mon Jul 20 06:34:00.599775 2026] [lsapi:warn] [pid 940476:tid 940639] [client 50.116.65.227:38486] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:34:00.599794 2026] [lsapi:warn] [pid 940476:tid 940639] [client 50.116.65.227:38486] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:34:00.600847 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VuBjVYcQxwGpYwZm_AQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:00.600930 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:49694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VuBjVYcQxwGpYwZm_AQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:00.601153 2026] [security2:error] [pid 940476:tid 940711] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/audi/"] [unique_id "al4VuBjVYcQxwGpYwZm_AAAAAGk"]
[Mon Jul 20 06:34:00.603481 2026] [security2:error] [pid 935758:tid 935906] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/audi/"] [unique_id "al4VuLcDxY_mIul-JSGzZwAAARo"]
[Mon Jul 20 06:34:00.615397 2026] [security2:error] [pid 940476:tid 940677] [client 14.225.17.146:53286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4VtxjVYcQxwGpYwZm-ugAAAEc"], referer: http://oswegooperatheater.com/Old
[Mon Jul 20 06:34:00.659698 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:49657] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/crochet-blanket/"] [unique_id "al4VuBjVYcQxwGpYwZm_CAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:00.784014 2026] [security2:error] [pid 940476:tid 940674] [client 57.141.18.22:59380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsxjVYcQxwGpYwZm9JAAARG4"]
[Mon Jul 20 06:34:00.792348 2026] [security2:error] [pid 940476:tid 940616] [client 20.104.96.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4VuBjVYcQxwGpYwZm_DgAAAAo"]
[Mon Jul 20 06:34:00.792371 2026] [security2:error] [pid 940476:tid 940616] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4VuBjVYcQxwGpYwZm_DgAAAAo"]
[Mon Jul 20 06:34:00.794852 2026] [security2:error] [pid 940476:tid 940660] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/audi/"] [unique_id "al4VuBjVYcQxwGpYwZm_CQAAADY"]
[Mon Jul 20 06:34:00.858422 2026] [security2:error] [pid 940476:tid 940712] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/ec2-user/.ssh/id_rsa"] [unique_id "al4VuBjVYcQxwGpYwZm_IAAAAGo"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:34:01.014412 2026] [security2:error] [pid 940476:tid 940698] [client 151.123.178.213:31387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VuBjVYcQxwGpYwZm_IwAAAFw"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:01.069451 2026] [security2:error] [pid 940476:tid 940687] [client 45.61.188.240:49581] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "itdynamix.com"] [uri "/"] [unique_id "al4VuRjVYcQxwGpYwZm_KwAAAFE"]
[Mon Jul 20 06:34:01.083877 2026] [security2:error] [pid 940476:tid 940501] [remote 160.187.68.132:49964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VuRjVYcQxwGpYwZm_LAAAWhg"]
[Mon Jul 20 06:34:01.161597 2026] [security2:error] [pid 935758:tid 935939] [client 104.234.53.62:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VubcDxY_mIul-JSGzcQAAATs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:01.229245 2026] [security2:error] [pid 940476:tid 940627] [client 77.110.127.138:49698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VuRjVYcQxwGpYwZm_JQAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:01.236232 2026] [security2:error] [pid 940476:tid 940721] [client 57.141.18.63:36980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VsxjVYcQxwGpYwZm9QgAAc38"]
[Mon Jul 20 06:34:01.338362 2026] [security2:error] [pid 935758:tid 935899] [client 45.61.188.240:49624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "itdynamix.com"] [uri "/"] [unique_id "al4VubcDxY_mIul-JSGzewAAARM"]
[Mon Jul 20 06:34:01.445740 2026] [lsapi:warn] [pid 940476:tid 940711] [client 14.225.17.146:59191] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Old
[Mon Jul 20 06:34:01.445791 2026] [lsapi:warn] [pid 940476:tid 940711] [client 14.225.17.146:59191] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Old
[Mon Jul 20 06:34:01.499854 2026] [security2:error] [pid 940476:tid 940711] [client 14.225.17.146:59191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4VuRjVYcQxwGpYwZm_PgAAAGk"], referer: https://oswegooperatheater.com/Old
[Mon Jul 20 06:34:01.618411 2026] [security2:error] [pid 935758:tid 935904] [client 45.3.45.80:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VubcDxY_mIul-JSGzgwAAARg"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:01.654127 2026] [security2:error] [pid 940476:tid 940576] [remote 160.187.68.132:49964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VuRjVYcQxwGpYwZm_QwAAHGM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:34:01.785152 2026] [security2:error] [pid 940476:tid 940629] [client 57.141.18.49:47302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VtBjVYcQxwGpYwZm9dAAAFwc"]
[Mon Jul 20 06:34:01.814541 2026] [security2:error] [pid 940476:tid 940705] [client 50.116.65.227:21920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4VuRjVYcQxwGpYwZm_SwAAAGM"]
[Mon Jul 20 06:34:01.832787 2026] [security2:error] [pid 935758:tid 935961] [client 50.116.65.227:38502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4VubcDxY_mIul-JSGzjwAAAVE"]
[Mon Jul 20 06:34:01.882457 2026] [security2:error] [pid 940476:tid 940680] [client 158.173.89.95:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VuRjVYcQxwGpYwZm_UgAAAEo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:34:02.157927 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:49677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VuhjVYcQxwGpYwZm_XQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:02.158104 2026] [security2:error] [pid 940476:tid 940670] [client 77.110.127.138:49677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VuhjVYcQxwGpYwZm_XQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:02.187542 2026] [core:error] [pid 940476:tid 940608] [client 103.153.183.69:3760] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e%u002e/etc/passwd?_=fumbagmy&v=r7d9b), referer: https://www.google.com/
[Mon Jul 20 06:34:02.190891 2026] [security2:error] [pid 940476:tid 940694] [client 127.0.0.1:12512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VuhjVYcQxwGpYwZm_ZAAAAFg"], referer: https://www.google.com/
[Mon Jul 20 06:34:02.257072 2026] [security2:error] [pid 940476:tid 940709] [client 65.111.23.204:25533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VuhjVYcQxwGpYwZm_aAAAAGc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:02.328208 2026] [security2:error] [pid 940476:tid 940695] [client 77.110.127.138:49709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VuhjVYcQxwGpYwZm_cQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:02.328311 2026] [security2:error] [pid 940476:tid 940695] [client 77.110.127.138:49709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VuhjVYcQxwGpYwZm_cQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:02.355418 2026] [security2:error] [pid 940476:tid 940559] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4VuhjVYcQxwGpYwZm_cgAAEFI"]
[Mon Jul 20 06:34:02.355618 2026] [security2:error] [pid 940476:tid 940622] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4VuhjVYcQxwGpYwZm_cgAAEFI"]
[Mon Jul 20 06:34:02.486428 2026] [security2:error] [pid 940476:tid 940673] [client 77.110.127.138:49710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/crochet-blanket/"] [unique_id "al4VuhjVYcQxwGpYwZm_ewAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:02.500838 2026] [security2:error] [pid 940476:tid 940721] [client 14.225.17.146:58834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4VuhjVYcQxwGpYwZm_dAAAAHM"], referer: http://alchemygroup.ca/Old
[Mon Jul 20 06:34:02.529459 2026] [security2:error] [pid 940476:tid 940610] [client 223.185.13.213:29622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VuhjVYcQxwGpYwZm_gAAAAAQ"]
[Mon Jul 20 06:34:02.529796 2026] [security2:error] [pid 940476:tid 940610] [client 223.185.13.213:29622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VuhjVYcQxwGpYwZm_gAAAAAQ"]
[Mon Jul 20 06:34:02.701640 2026] [security2:error] [pid 935758:tid 935973] [client 158.173.166.181:25347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VurcDxY_mIul-JSGznwAAAV0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:34:02.720027 2026] [security2:error] [pid 940476:tid 940656] [client 20.104.96.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4VuhjVYcQxwGpYwZm_iQAAADI"]
[Mon Jul 20 06:34:02.720063 2026] [security2:error] [pid 940476:tid 940656] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4VuhjVYcQxwGpYwZm_iQAAADI"]
[Mon Jul 20 06:34:02.721577 2026] [security2:error] [pid 940476:tid 940698] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/wp-includes/blocks/audi/"] [unique_id "al4VuhjVYcQxwGpYwZm_hgAAAFw"]
[Mon Jul 20 06:34:02.880818 2026] [security2:error] [pid 935758:tid 935895] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/.well-known/about.php"] [unique_id "al4VurcDxY_mIul-JSGzrwAAAQ8"]
[Mon Jul 20 06:34:02.880929 2026] [security2:error] [pid 935758:tid 935895] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/.well-known/about.php"] [unique_id "al4VurcDxY_mIul-JSGzrwAAAQ8"]
[Mon Jul 20 06:34:02.882576 2026] [security2:error] [pid 935758:tid 935901] [client 104.207.52.155:14467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VurcDxY_mIul-JSGzpwAAARU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:02.949323 2026] [access_compat:error] [pid 940476:tid 940618] [client 66.198.240.43:0] AH01797: client denied by server configuration: /home1/deltattw/public_html/wp-cron.php
[Mon Jul 20 06:34:03.271700 2026] [security2:error] [pid 940476:tid 940719] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/www-data/.ssh/id_rsa"] [unique_id "al4VuxjVYcQxwGpYwZm_sgAAAHE"], referer: https://twitter.com/
[Mon Jul 20 06:34:03.278125 2026] [security2:error] [pid 940476:tid 940732] [client 20.197.192.193:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/v2.php"] [unique_id "al4VuxjVYcQxwGpYwZm_tAAAAH4"]
[Mon Jul 20 06:34:03.278210 2026] [security2:error] [pid 940476:tid 940732] [client 20.197.192.193:58837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/v2.php"] [unique_id "al4VuxjVYcQxwGpYwZm_tAAAAH4"]
[Mon Jul 20 06:34:03.297596 2026] [security2:error] [pid 935758:tid 935878] [remote 8.217.108.67:6140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4Vu7cDxY_mIul-JSGzugABeXU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:34:03.314706 2026] [security2:error] [pid 940476:tid 940640] [client 57.141.18.10:32768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VtRjVYcQxwGpYwZm-EgAAImU"]
[Mon Jul 20 06:34:03.370412 2026] [security2:error] [pid 940476:tid 940488] [remote 160.187.68.132:39376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VuxjVYcQxwGpYwZm_vQAAbgs"]
[Mon Jul 20 06:34:03.469540 2026] [security2:error] [pid 940476:tid 940610] [client 45.3.44.98:33409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VuxjVYcQxwGpYwZm_xAAAAAQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:03.506898 2026] [security2:error] [pid 940476:tid 940647] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/git/.ssh/id_rsa"] [unique_id "al4VuxjVYcQxwGpYwZm_xgAAACk"], referer: https://www.facebook.com/
[Mon Jul 20 06:34:03.578046 2026] [security2:error] [pid 935758:tid 935968] [client 104.234.53.82:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Vu7cDxY_mIul-JSGzxAAAAVg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:03.813960 2026] [security2:error] [pid 940476:tid 940609] [client 14.225.17.146:60813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4VuhjVYcQxwGpYwZm_bAAAAAM"], referer: http://tntcatholic.com/Old
[Mon Jul 20 06:34:03.824213 2026] [security2:error] [pid 940476:tid 940681] [client 50.116.65.227:38568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VuxjVYcQxwGpYwZm_1gAAAEs"]
[Mon Jul 20 06:34:03.835487 2026] [security2:error] [pid 940476:tid 940645] [client 50.116.65.227:38576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VuxjVYcQxwGpYwZm_1wAAACc"]
[Mon Jul 20 06:34:03.894773 2026] [security2:error] [pid 940476:tid 940574] [remote 160.187.68.132:39376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4VuxjVYcQxwGpYwZm_2gAAc2E"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:34:03.944000 2026] [security2:error] [pid 940476:tid 940719] [client 77.110.127.138:49720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4VuxjVYcQxwGpYwZm_4QAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:03.944338 2026] [security2:error] [pid 940476:tid 940633] [client 57.141.18.10:32770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VthjVYcQxwGpYwZm-WwAAGzM"]
[Mon Jul 20 06:34:03.999309 2026] [security2:error] [pid 940476:tid 940664] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4VuxjVYcQxwGpYwZm_6QAAADo"]
[Mon Jul 20 06:34:03.999399 2026] [security2:error] [pid 940476:tid 940664] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4VuxjVYcQxwGpYwZm_6QAAADo"]
[Mon Jul 20 06:34:04.218264 2026] [security2:error] [pid 935758:tid 936008] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wefile.php"] [unique_id "al4VvLcDxY_mIul-JSGz2QAAAYA"]
[Mon Jul 20 06:34:04.218354 2026] [security2:error] [pid 935758:tid 936008] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wefile.php"] [unique_id "al4VvLcDxY_mIul-JSGz2QAAAYA"]
[Mon Jul 20 06:34:04.480919 2026] [security2:error] [pid 940476:tid 940689] [client 57.141.18.97:60422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VthjVYcQxwGpYwZm-kQAAUx8"]
[Mon Jul 20 06:34:04.732222 2026] [security2:error] [pid 935758:tid 935949] [client 57.141.18.103:64810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vt7cDxY_mIul-JSGzQAABRVg"]
[Mon Jul 20 06:34:04.793567 2026] [security2:error] [pid 935758:tid 935910] [client 57.141.18.53:50766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vt7cDxY_mIul-JSGzQQABHnw"]
[Mon Jul 20 06:34:04.806615 2026] [security2:error] [pid 940476:tid 940731] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../home/admin/.ssh/id_rsa"] [unique_id "al4VvBjVYcQxwGpYwZnAGAAAAH0"], referer: https://www.facebook.com/
[Mon Jul 20 06:34:04.858879 2026] [core:error] [pid 940476:tid 940730] [client 103.153.183.69:3776] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e%u002e/%u002e%u002e/.env?_=tkpxpqdm&v=fdwdr), referer: https://t.co/91ib88qm47
[Mon Jul 20 06:34:04.894088 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:49728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvLcDxY_mIul-JSGz6wAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:04.894195 2026] [security2:error] [pid 935758:tid 935981] [client 77.110.127.138:49728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvLcDxY_mIul-JSGz6wAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:05.103010 2026] [security2:error] [pid 940476:tid 940687] [client 197.186.66.42:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VvRjVYcQxwGpYwZnALQAAAFE"]
[Mon Jul 20 06:34:05.103139 2026] [security2:error] [pid 940476:tid 940687] [client 197.186.66.42:64644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VvRjVYcQxwGpYwZnALQAAAFE"]
[Mon Jul 20 06:34:05.118841 2026] [security2:error] [pid 940476:tid 940689] [client 50.116.65.227:38594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VvRjVYcQxwGpYwZnALgAAAFM"]
[Mon Jul 20 06:34:05.128786 2026] [security2:error] [pid 940476:tid 940733] [client 50.116.65.227:38598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4VvRjVYcQxwGpYwZnALwAAAH8"]
[Mon Jul 20 06:34:05.143357 2026] [security2:error] [pid 935758:tid 935951] [client 39.48.81.23:54584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VvbcDxY_mIul-JSGz8QAAAUc"]
[Mon Jul 20 06:34:05.143481 2026] [security2:error] [pid 935758:tid 935951] [client 39.48.81.23:54584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4VvbcDxY_mIul-JSGz8QAAAUc"]
[Mon Jul 20 06:34:05.143773 2026] [security2:error] [pid 940476:tid 940680] [client 77.110.127.138:49729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvRjVYcQxwGpYwZnAMAAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:05.143888 2026] [security2:error] [pid 940476:tid 940680] [client 77.110.127.138:49729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvRjVYcQxwGpYwZnAMAAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:05.301127 2026] [security2:error] [pid 940476:tid 940725] [client 111.225.149.73:62126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.adultdaycarereno.com"] [uri "/robots.txt"] [unique_id "al4VvRjVYcQxwGpYwZnAOgAAAHc"]
[Mon Jul 20 06:34:05.320708 2026] [security2:error] [pid 940476:tid 940714] [client 171.60.139.123:64509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VvRjVYcQxwGpYwZnAOwAAAGw"]
[Mon Jul 20 06:34:05.320867 2026] [security2:error] [pid 940476:tid 940714] [client 171.60.139.123:64509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VvRjVYcQxwGpYwZnAOwAAAGw"]
[Mon Jul 20 06:34:05.343252 2026] [security2:error] [pid 935758:tid 935988] [client 77.110.127.138:49730] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/crochet-blanket/"] [unique_id "al4VvbcDxY_mIul-JSGz9QAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:05.364995 2026] [security2:error] [pid 935758:tid 935963] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4VvbcDxY_mIul-JSGz9wAAAVM"]
[Mon Jul 20 06:34:05.366360 2026] [security2:error] [pid 935758:tid 935904] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4VvbcDxY_mIul-JSGz9gAAARg"]
[Mon Jul 20 06:34:05.389355 2026] [security2:error] [pid 940476:tid 940707] [client 57.141.18.29:39060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VuBjVYcQxwGpYwZm-1AAAZQU"]
[Mon Jul 20 06:34:05.444888 2026] [security2:error] [pid 940476:tid 940650] [client 35.245.239.138:53944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/xmlrpc.php"] [unique_id "al4VvRjVYcQxwGpYwZnARQAAACw"]
[Mon Jul 20 06:34:05.524896 2026] [autoindex:error] [pid 940476:tid 940731] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:05.525399 2026] [security2:error] [pid 940476:tid 940731] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VvRjVYcQxwGpYwZnATAAAAH0"]
[Mon Jul 20 06:34:05.531711 2026] [security2:error] [pid 940476:tid 940659] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4VvRjVYcQxwGpYwZnARwAAADU"]
[Mon Jul 20 06:34:05.589451 2026] [security2:error] [pid 935758:tid 935931] [client 57.141.18.71:46146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VuLcDxY_mIul-JSGzXwABMwg"]
[Mon Jul 20 06:34:05.600587 2026] [core:error] [pid 940476:tid 940648] [client 103.153.183.69:3784] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e%u002e%u002f%u002e%u002e%u002f.env?_=ooen4k80&v=nn2yv), referer: https://twitter.com/
[Mon Jul 20 06:34:05.628356 2026] [security2:error] [pid 935758:tid 935925] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-admin/js/"] [unique_id "al4VvbcDxY_mIul-JSG0AAAAAS0"]
[Mon Jul 20 06:34:05.699444 2026] [security2:error] [pid 940476:tid 940669] [client 35.245.239.138:53463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VvRjVYcQxwGpYwZnAXgAAAD8"]
[Mon Jul 20 06:34:05.748912 2026] [autoindex:error] [pid 940476:tid 940687] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:05.749520 2026] [security2:error] [pid 940476:tid 940687] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-admin/js/"] [unique_id "al4VvRjVYcQxwGpYwZnAYAAAAFE"]
[Mon Jul 20 06:34:05.823045 2026] [security2:error] [pid 935758:tid 935961] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al4VvbcDxY_mIul-JSG0BgAAAVE"]
[Mon Jul 20 06:34:05.823172 2026] [security2:error] [pid 935758:tid 935961] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al4VvbcDxY_mIul-JSG0BgAAAVE"]
[Mon Jul 20 06:34:05.863353 2026] [security2:error] [pid 940476:tid 940642] [client 77.110.127.138:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4VvRjVYcQxwGpYwZnAaQAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:05.997218 2026] [security2:error] [pid 940476:tid 940657] [client 35.245.239.138:50043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VvRjVYcQxwGpYwZnAcQAAADM"]
[Mon Jul 20 06:34:06.282438 2026] [core:error] [pid 935758:tid 935905] [client 103.153.183.69:3790] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e%u002e%u002f%u002e%u002e%u002fetc%u002fpasswd?_=pev54ggt&v=224uc), referer: https://twitter.com/
[Mon Jul 20 06:34:06.286017 2026] [security2:error] [pid 940476:tid 940717] [client 127.0.0.1:12554] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VvhjVYcQxwGpYwZnAgQAAAG8"], referer: https://twitter.com/
[Mon Jul 20 06:34:06.335611 2026] [security2:error] [pid 940476:tid 940658] [client 35.245.239.138:51440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VvhjVYcQxwGpYwZnAhAAAADQ"]
[Mon Jul 20 06:34:06.353783 2026] [security2:error] [pid 935758:tid 935894] [client 34.74.185.202:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4VvrcDxY_mIul-JSG0HQAAAQ4"]
[Mon Jul 20 06:34:06.403364 2026] [security2:error] [pid 935758:tid 935949] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/8.php"] [unique_id "al4VvrcDxY_mIul-JSG0HwAAAUU"]
[Mon Jul 20 06:34:06.403484 2026] [security2:error] [pid 935758:tid 935949] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/8.php"] [unique_id "al4VvrcDxY_mIul-JSG0HwAAAUU"]
[Mon Jul 20 06:34:06.658678 2026] [security2:error] [pid 940476:tid 940615] [client 35.245.239.138:61937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VvhjVYcQxwGpYwZnAmgAAAAk"]
[Mon Jul 20 06:34:06.675930 2026] [security2:error] [pid 935758:tid 935782] [remote 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4VvrcDxY_mIul-JSG0JgABWRU"]
[Mon Jul 20 06:34:06.772102 2026] [core:error] [pid 940476:tid 940698] [client 103.153.183.69:3798] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e%u002e/%u002e%u002e/%u002e%u002e/etc/passwd?_=gl1sfyfl&v=0mb8s), referer: https://twitter.com/
[Mon Jul 20 06:34:06.775615 2026] [security2:error] [pid 940476:tid 940630] [client 127.0.0.1:12556] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VvhjVYcQxwGpYwZnAoAAAABg"], referer: https://twitter.com/
[Mon Jul 20 06:34:06.876101 2026] [security2:error] [pid 935758:tid 935957] [client 112.208.70.94:44256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VvrcDxY_mIul-JSG0KAAAAU0"]
[Mon Jul 20 06:34:06.876246 2026] [security2:error] [pid 935758:tid 935957] [client 112.208.70.94:44256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VvrcDxY_mIul-JSG0KAAAAU0"]
[Mon Jul 20 06:34:06.956933 2026] [security2:error] [pid 935758:tid 935984] [client 57.141.18.120:47302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VubcDxY_mIul-JSGzhAABaDs"]
[Mon Jul 20 06:34:06.969774 2026] [security2:error] [pid 940476:tid 940627] [client 35.245.239.138:61397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VvhjVYcQxwGpYwZnArAAAABU"]
[Mon Jul 20 06:34:06.969953 2026] [security2:error] [pid 935758:tid 935802] [remote 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4VvrcDxY_mIul-JSG0KgABRik"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:34:06.972485 2026] [security2:error] [pid 935758:tid 936009] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-content/admin.php"] [unique_id "al4VvrcDxY_mIul-JSG0KwAAAYE"]
[Mon Jul 20 06:34:06.972560 2026] [security2:error] [pid 935758:tid 936009] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-content/admin.php"] [unique_id "al4VvrcDxY_mIul-JSG0KwAAAYE"]
[Mon Jul 20 06:34:07.158611 2026] [security2:error] [pid 935758:tid 935899] [client 14.225.17.146:60723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4VvrcDxY_mIul-JSG0KQAAARM"], referer: http://mobilesurvsolutions.com/Old
[Mon Jul 20 06:34:07.159200 2026] [proxy:error] [pid 940476:tid 940668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:07.159267 2026] [proxy_http:error] [pid 940476:tid 940668] [client 34.73.38.214:65105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:07.160022 2026] [proxy:error] [pid 940476:tid 940668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:07.160059 2026] [proxy_http:error] [pid 940476:tid 940668] [client 34.73.38.214:65105] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:07.290041 2026] [security2:error] [pid 940476:tid 940491] [remote 124.55.178.99:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VvxjVYcQxwGpYwZnAvwAAYQ4"]
[Mon Jul 20 06:34:07.334758 2026] [security2:error] [pid 935758:tid 935985] [client 57.141.18.107:43690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VubcDxY_mIul-JSGzlAABaWg"]
[Mon Jul 20 06:34:07.360380 2026] [security2:error] [pid 940476:tid 940687] [client 77.110.127.138:49745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvxjVYcQxwGpYwZnAxQAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:07.360483 2026] [security2:error] [pid 940476:tid 940687] [client 77.110.127.138:49745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvxjVYcQxwGpYwZnAxQAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:07.400182 2026] [security2:error] [pid 940476:tid 940662] [client 35.245.239.138:63549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VvxjVYcQxwGpYwZnAygAAADg"]
[Mon Jul 20 06:34:07.412178 2026] [security2:error] [pid 940476:tid 940718] [client 77.110.127.138:49710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvxjVYcQxwGpYwZnAzAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:07.412297 2026] [security2:error] [pid 940476:tid 940718] [client 77.110.127.138:49710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VvxjVYcQxwGpYwZnAzAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:07.508683 2026] [security2:error] [pid 940476:tid 940623] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/f6.php"] [unique_id "al4VvxjVYcQxwGpYwZnA1AAAABE"]
[Mon Jul 20 06:34:07.508786 2026] [security2:error] [pid 940476:tid 940623] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/f6.php"] [unique_id "al4VvxjVYcQxwGpYwZnA1AAAABE"]
[Mon Jul 20 06:34:07.541630 2026] [autoindex:error] [pid 935758:tid 935903] [client 49.51.33.159:0] AH01276: Cannot serve directory /home1/peycosol/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:07.543043 2026] [security2:error] [pid 940476:tid 940651] [client 77.110.127.138:49715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 639 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VvxjVYcQxwGpYwZnA1gAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:07.606903 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:49711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4VvxjVYcQxwGpYwZnA2wAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:07.624461 2026] [security2:error] [pid 940476:tid 940609] [client 34.74.185.202:54398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VvxjVYcQxwGpYwZnA3AAAAAM"]
[Mon Jul 20 06:34:07.695962 2026] [security2:error] [pid 940476:tid 940559] [remote 124.55.178.99:46028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4VvxjVYcQxwGpYwZnA4AAAWFI"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:34:07.738549 2026] [security2:error] [pid 940476:tid 940697] [client 35.245.239.138:63898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VvxjVYcQxwGpYwZnA5QAAAFs"]
[Mon Jul 20 06:34:07.788993 2026] [security2:error] [pid 940476:tid 940704] [client 217.142.18.172:12787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4VvxjVYcQxwGpYwZnA5AAAAGI"]
[Mon Jul 20 06:34:07.789239 2026] [security2:error] [pid 940476:tid 940704] [client 217.142.18.172:12787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4VvxjVYcQxwGpYwZnA5AAAAGI"]
[Mon Jul 20 06:34:07.943786 2026] [security2:error] [pid 935758:tid 936002] [client 14.225.17.146:60463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4VvrcDxY_mIul-JSG0JAAAAXo"], referer: http://sarahsnyder.net/Old
[Mon Jul 20 06:34:07.964603 2026] [proxy:error] [pid 940476:tid 940621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:07.964691 2026] [proxy_http:error] [pid 940476:tid 940621] [client 34.73.38.214:55978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:07.966200 2026] [proxy:error] [pid 940476:tid 940621] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:07.966259 2026] [proxy_http:error] [pid 940476:tid 940621] [client 34.73.38.214:55978] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:07.972513 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VvxjVYcQxwGpYwZnA5wAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:08.026344 2026] [security2:error] [pid 940476:tid 940651] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/inputs.php"] [unique_id "al4VwBjVYcQxwGpYwZnA_gAAAC0"]
[Mon Jul 20 06:34:08.026459 2026] [security2:error] [pid 940476:tid 940651] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/inputs.php"] [unique_id "al4VwBjVYcQxwGpYwZnA_gAAAC0"]
[Mon Jul 20 06:34:08.129654 2026] [security2:error] [pid 940476:tid 940681] [client 35.245.239.138:50757] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VwBjVYcQxwGpYwZnBAgAAAEs"]
[Mon Jul 20 06:34:08.209615 2026] [security2:error] [pid 940476:tid 940610] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../etc/passwd"] [unique_id "al4VwBjVYcQxwGpYwZnBCQAAAAQ"], referer: https://www.reddit.com/
[Mon Jul 20 06:34:08.266434 2026] [security2:error] [pid 935758:tid 936010] [client 34.74.185.202:58584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VwLcDxY_mIul-JSG0TgAAAYI"]
[Mon Jul 20 06:34:08.277903 2026] [security2:error] [pid 940476:tid 940710] [client 171.61.165.146:6241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VwBjVYcQxwGpYwZnBDgAAAGg"]
[Mon Jul 20 06:34:08.278859 2026] [security2:error] [pid 940476:tid 940710] [client 171.61.165.146:6241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VwBjVYcQxwGpYwZnBDgAAAGg"]
[Mon Jul 20 06:34:08.283711 2026] [security2:error] [pid 940476:tid 940713] [client 57.141.18.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4VvxjVYcQxwGpYwZnA_AAAAGs"]
[Mon Jul 20 06:34:08.403909 2026] [security2:error] [pid 940476:tid 940657] [client 35.245.239.138:63774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VwBjVYcQxwGpYwZnBEwAAADM"]
[Mon Jul 20 06:34:08.516832 2026] [security2:error] [pid 940476:tid 940716] [client 14.225.17.146:60746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4VvhjVYcQxwGpYwZnArQAAAG4"], referer: http://reosportsboats.com/Old
[Mon Jul 20 06:34:08.691149 2026] [security2:error] [pid 940476:tid 940722] [client 35.245.239.138:65195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "vfcthomasville-net.vfcthomasville.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VwBjVYcQxwGpYwZnBJwAAAHQ"]
[Mon Jul 20 06:34:08.719247 2026] [security2:error] [pid 940476:tid 940718] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwBjVYcQxwGpYwZnBGAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:08.847580 2026] [security2:error] [pid 935758:tid 935912] [client 57.141.18.96:55792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Vu7cDxY_mIul-JSGzwAABIEU"]
[Mon Jul 20 06:34:08.886321 2026] [security2:error] [pid 940476:tid 940703] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/inputs.php"] [unique_id "al4VwBjVYcQxwGpYwZnBMAAAAGE"]
[Mon Jul 20 06:34:08.886421 2026] [security2:error] [pid 940476:tid 940703] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/inputs.php"] [unique_id "al4VwBjVYcQxwGpYwZnBMAAAAGE"]
[Mon Jul 20 06:34:08.925803 2026] [security2:error] [pid 940476:tid 940680] [client 14.225.17.146:51225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4VwBjVYcQxwGpYwZnBKQAAAEo"], referer: https://sarahsnyder.net/Old
[Mon Jul 20 06:34:09.041628 2026] [security2:error] [pid 935758:tid 935964] [client 57.141.18.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VwLcDxY_mIul-JSG0ZAAAAVQ"]
[Mon Jul 20 06:34:09.061088 2026] [security2:error] [pid 940476:tid 940515] [remote 115.79.143.180:55468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VwRjVYcQxwGpYwZnBNgAAKyY"]
[Mon Jul 20 06:34:09.117316 2026] [security2:error] [pid 935758:tid 935960] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwLcDxY_mIul-JSG0ZQAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:09.154886 2026] [security2:error] [pid 940476:tid 940694] [client 34.74.185.202:60399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VwRjVYcQxwGpYwZnBRQAAAFg"]
[Mon Jul 20 06:34:09.398961 2026] [security2:error] [pid 940476:tid 940622] [client 47.129.160.40:50928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "sustaintheart.com"] [uri "/index.php"] [unique_id "al4VwRjVYcQxwGpYwZnBSwAAABA"]
[Mon Jul 20 06:34:09.469468 2026] [security2:error] [pid 940476:tid 940686] [client 14.225.17.146:64048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4VwRjVYcQxwGpYwZnBSgAAAFA"], referer: https://reosportsboats.com/Old
[Mon Jul 20 06:34:09.496443 2026] [security2:error] [pid 940476:tid 940678] [client 57.141.18.90:39058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VvBjVYcQxwGpYwZm_6wAASGo"]
[Mon Jul 20 06:34:09.539003 2026] [security2:error] [pid 940476:tid 940494] [remote 115.79.143.180:55468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4VwRjVYcQxwGpYwZnBVQAAERE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:34:09.566987 2026] [security2:error] [pid 940476:tid 940647] [client 57.141.18.14:38546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VvBjVYcQxwGpYwZm_7wAAKS4"]
[Mon Jul 20 06:34:09.571254 2026] [security2:error] [pid 940476:tid 940513] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4VwRjVYcQxwGpYwZnBWgAAIyQ"]
[Mon Jul 20 06:34:09.571387 2026] [security2:error] [pid 940476:tid 940641] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4VwRjVYcQxwGpYwZnBWgAAIyQ"]
[Mon Jul 20 06:34:09.590689 2026] [security2:error] [pid 940476:tid 940613] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/classwithtostring.php"] [unique_id "al4VwRjVYcQxwGpYwZnBWwAAAAc"]
[Mon Jul 20 06:34:09.590849 2026] [security2:error] [pid 940476:tid 940613] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/classwithtostring.php"] [unique_id "al4VwRjVYcQxwGpYwZnBWwAAAAc"]
[Mon Jul 20 06:34:09.610929 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:49730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VwbcDxY_mIul-JSG0dgAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:09.611054 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:49730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VwbcDxY_mIul-JSG0dgAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:09.668458 2026] [security2:error] [pid 935758:tid 935930] [client 104.234.53.88:56861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4VwbcDxY_mIul-JSG0dwAAATI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:09.741469 2026] [proxy:error] [pid 940476:tid 940610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:09.741547 2026] [proxy_http:error] [pid 940476:tid 940610] [client 34.73.38.214:53572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:09.742111 2026] [proxy:error] [pid 940476:tid 940610] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:09.742145 2026] [proxy_http:error] [pid 940476:tid 940610] [client 34.73.38.214:53572] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:09.742363 2026] [proxy:error] [pid 940476:tid 940624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:09.742439 2026] [proxy_http:error] [pid 940476:tid 940624] [client 34.73.38.214:60005] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:09.743711 2026] [proxy:error] [pid 940476:tid 940624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:09.743754 2026] [proxy_http:error] [pid 940476:tid 940624] [client 34.73.38.214:60005] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:09.766267 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:49780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VwRjVYcQxwGpYwZnBbAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:09.766390 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:49780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VwRjVYcQxwGpYwZnBbAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:09.805107 2026] [security2:error] [pid 940476:tid 940508] [remote 162.19.86.63:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VwRjVYcQxwGpYwZnBbQAAZh8"]
[Mon Jul 20 06:34:09.915148 2026] [security2:error] [pid 940476:tid 940710] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4VwRjVYcQxwGpYwZnBdgAAAGg"]
[Mon Jul 20 06:34:09.915266 2026] [security2:error] [pid 940476:tid 940710] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4VwRjVYcQxwGpYwZnBdgAAAGg"]
[Mon Jul 20 06:34:09.917223 2026] [security2:error] [pid 935758:tid 935920] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwbcDxY_mIul-JSG0eQAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:09.923416 2026] [security2:error] [pid 940476:tid 940657] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../etc/shadow"] [unique_id "al4VwRjVYcQxwGpYwZnBeAAAADM"], referer: https://t.co/ukndmyqu68
[Mon Jul 20 06:34:09.995874 2026] [security2:error] [pid 940476:tid 940511] [remote 162.19.86.63:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VwRjVYcQxwGpYwZnBfAAALCI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:34:10.041490 2026] [security2:error] [pid 935758:tid 935983] [client 20.197.192.193:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dollpassionista.dollpassionista.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VwrcDxY_mIul-JSG0gQAAAWc"]
[Mon Jul 20 06:34:10.041599 2026] [security2:error] [pid 935758:tid 935983] [client 20.197.192.193:58834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "dollpassionista.dollpassionista.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4VwrcDxY_mIul-JSG0gQAAAWc"]
[Mon Jul 20 06:34:10.114532 2026] [security2:error] [pid 940476:tid 940726] [client 57.141.18.110:24982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VvBjVYcQxwGpYwZnAFAAAeBw"]
[Mon Jul 20 06:34:10.156145 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwbcDxY_mIul-JSG0fAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:10.179514 2026] [security2:error] [pid 940476:tid 940661] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-blog.php"] [unique_id "al4VwhjVYcQxwGpYwZnBgwAAADc"]
[Mon Jul 20 06:34:10.179654 2026] [security2:error] [pid 940476:tid 940661] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-blog.php"] [unique_id "al4VwhjVYcQxwGpYwZnBgwAAADc"]
[Mon Jul 20 06:34:10.237767 2026] [security2:error] [pid 940476:tid 940655] [client 20.197.192.193:58844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.massagelacey.com"] [uri "/fm-cdjs.php"] [unique_id "al4VwhjVYcQxwGpYwZnBiQAAADE"]
[Mon Jul 20 06:34:10.237875 2026] [security2:error] [pid 940476:tid 940655] [client 20.197.192.193:58844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.massagelacey.com"] [uri "/fm-cdjs.php"] [unique_id "al4VwhjVYcQxwGpYwZnBiQAAADE"]
[Mon Jul 20 06:34:10.259799 2026] [core:error] [pid 940476:tid 940612] [client 103.153.183.69:19426] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%u002e./%u002e./.env?_=mzq0557u&v=v42m2), referer: https://news.ycombinator.com/
[Mon Jul 20 06:34:10.360364 2026] [security2:error] [pid 940476:tid 940478] [remote 216.73.216.55:36502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4VwhjVYcQxwGpYwZnBjQAAIgE"]
[Mon Jul 20 06:34:10.369737 2026] [security2:error] [pid 935758:tid 935902] [client 77.110.127.138:49784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 326 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VwrcDxY_mIul-JSG0jQAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:10.388966 2026] [security2:error] [pid 935758:tid 935890] [client 34.74.185.202:63175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VwrcDxY_mIul-JSG0kAAAAQo"]
[Mon Jul 20 06:34:10.408400 2026] [security2:error] [pid 940476:tid 940646] [client 187.108.85.186:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VwhjVYcQxwGpYwZnBjgAAACg"]
[Mon Jul 20 06:34:10.408574 2026] [security2:error] [pid 940476:tid 940646] [client 187.108.85.186:52843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VwhjVYcQxwGpYwZnBjgAAACg"]
[Mon Jul 20 06:34:10.414844 2026] [security2:error] [pid 940476:tid 940609] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwhjVYcQxwGpYwZnBiAAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:10.443449 2026] [security2:error] [pid 940476:tid 940691] [client 103.153.183.69:11602] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../etc/hosts"] [unique_id "al4VwhjVYcQxwGpYwZnBkQAAAFU"], referer: https://www.google.com/
[Mon Jul 20 06:34:10.676226 2026] [security2:error] [pid 940476:tid 940639] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4VwhjVYcQxwGpYwZnBmgAAACE"]
[Mon Jul 20 06:34:10.682173 2026] [security2:error] [pid 940476:tid 940717] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4VwhjVYcQxwGpYwZnBlQAAAG8"]
[Mon Jul 20 06:34:10.755251 2026] [security2:error] [pid 935758:tid 935969] [client 34.74.185.202:63679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VwrcDxY_mIul-JSG0pwAAAVk"]
[Mon Jul 20 06:34:10.832599 2026] [security2:error] [pid 940476:tid 940623] [client 103.125.179.95:55474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VwhjVYcQxwGpYwZnBpAAAABE"]
[Mon Jul 20 06:34:10.832728 2026] [security2:error] [pid 940476:tid 940623] [client 103.125.179.95:55474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VwhjVYcQxwGpYwZnBpAAAABE"]
[Mon Jul 20 06:34:10.879385 2026] [security2:error] [pid 940476:tid 940669] [client 103.153.183.69:11602] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//....//....//proc/self/environ"] [unique_id "al4VwhjVYcQxwGpYwZnBqQAAAD8"], referer: https://duckduckgo.com/?q=85weh
[Mon Jul 20 06:34:10.959365 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwhjVYcQxwGpYwZnBoAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:11.039511 2026] [security2:error] [pid 940476:tid 940678] [client 34.73.38.214:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VwxjVYcQxwGpYwZnBtQAAAEg"]
[Mon Jul 20 06:34:11.061600 2026] [autoindex:error] [pid 935758:tid 935921] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:11.062171 2026] [security2:error] [pid 935758:tid 935921] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4Vw7cDxY_mIul-JSG0qwAAASk"]
[Mon Jul 20 06:34:11.071150 2026] [security2:error] [pid 940476:tid 940617] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4VwhjVYcQxwGpYwZnBsAAAAAs"]
[Mon Jul 20 06:34:11.091668 2026] [proxy:error] [pid 940476:tid 940715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:11.091741 2026] [proxy_http:error] [pid 940476:tid 940715] [client 34.73.38.214:60007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:11.092720 2026] [proxy:error] [pid 940476:tid 940715] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:11.092790 2026] [proxy_http:error] [pid 940476:tid 940715] [client 34.73.38.214:60007] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:11.197381 2026] [security2:error] [pid 940476:tid 940630] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-content/admin.php"] [unique_id "al4VwxjVYcQxwGpYwZnBvwAAABg"]
[Mon Jul 20 06:34:11.197536 2026] [security2:error] [pid 940476:tid 940630] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-content/admin.php"] [unique_id "al4VwxjVYcQxwGpYwZnBvwAAABg"]
[Mon Jul 20 06:34:11.305477 2026] [security2:error] [pid 940476:tid 940584] [remote 45.90.123.233:40162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VwxjVYcQxwGpYwZnBxgAAPms"]
[Mon Jul 20 06:34:11.471933 2026] [security2:error] [pid 940476:tid 940674] [client 85.208.98.16:49848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.marscafe.com"] [uri "/php/simple-dl/simple-dl.php"] [unique_id "al4VwxjVYcQxwGpYwZnB0QAAAEQ"]
[Mon Jul 20 06:34:11.472044 2026] [security2:error] [pid 940476:tid 940674] [client 85.208.98.16:49848] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.marscafe.com"] [uri "/php/simple-dl/simple-dl.php"] [unique_id "al4VwxjVYcQxwGpYwZnB0QAAAEQ"]
[Mon Jul 20 06:34:11.498590 2026] [security2:error] [pid 940476:tid 940596] [remote 45.90.123.233:40162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VwxjVYcQxwGpYwZnB0gAAEXc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:34:11.722829 2026] [security2:error] [pid 940476:tid 940698] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ms-edit.php"] [unique_id "al4VwxjVYcQxwGpYwZnB2wAAAFw"]
[Mon Jul 20 06:34:11.722951 2026] [security2:error] [pid 940476:tid 940698] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ms-edit.php"] [unique_id "al4VwxjVYcQxwGpYwZnB2wAAAFw"]
[Mon Jul 20 06:34:11.762978 2026] [security2:error] [pid 940476:tid 940667] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwxjVYcQxwGpYwZnB1wAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:11.775101 2026] [security2:error] [pid 940476:tid 940531] [remote 57.141.18.120:42634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6157927"] [unique_id "al4VwxjVYcQxwGpYwZnB3gAAFDY"]
[Mon Jul 20 06:34:11.873127 2026] [security2:error] [pid 940476:tid 940633] [client 18.142.226.106:51650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/index.php"] [unique_id "al4VwxjVYcQxwGpYwZnB4wAAABs"]
[Mon Jul 20 06:34:11.889423 2026] [proxy:error] [pid 940476:tid 940634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:11.889455 2026] [proxy_http:error] [pid 940476:tid 940634] [client 198.235.24.139:62540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:11.889863 2026] [proxy:error] [pid 940476:tid 940634] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:11.889892 2026] [proxy_http:error] [pid 940476:tid 940634] [client 198.235.24.139:62540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:11.941382 2026] [security2:error] [pid 940476:tid 940690] [client 103.153.183.69:3012] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//....//....//proc/self/environ"] [unique_id "al4VwxjVYcQxwGpYwZnB8QAAAFQ"], referer: https://duckduckgo.com/?q=85weh
[Mon Jul 20 06:34:11.980115 2026] [security2:error] [pid 940476:tid 940621] [client 34.74.185.202:55276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VwxjVYcQxwGpYwZnB8wAAAA8"]
[Mon Jul 20 06:34:12.033166 2026] [security2:error] [pid 940476:tid 940647] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VwxjVYcQxwGpYwZnB5QAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:12.329410 2026] [security2:error] [pid 935758:tid 935981] [client 195.96.139.151:55115] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4VxLcDxY_mIul-JSG0zAAAAWU"]
[Mon Jul 20 06:34:12.367722 2026] [security2:error] [pid 940476:tid 940733] [client 50.116.65.227:47942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4VxBjVYcQxwGpYwZnCCgAAAH8"]
[Mon Jul 20 06:34:12.372827 2026] [security2:error] [pid 940476:tid 940606] [client 66.102.9.101:63800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.locketsandcharms.com"] [uri "/index.php"] [unique_id "al4VxBjVYcQxwGpYwZnCAwAAAAA"]
[Mon Jul 20 06:34:12.379677 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:49717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxLcDxY_mIul-JSG0zwAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:12.379796 2026] [security2:error] [pid 935758:tid 935989] [client 77.110.127.138:49717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxLcDxY_mIul-JSG0zwAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:12.510023 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VxLcDxY_mIul-JSG0zgAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:12.512580 2026] [security2:error] [pid 935758:tid 935916] [client 34.74.185.202:52141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VxLcDxY_mIul-JSG01gAAASQ"]
[Mon Jul 20 06:34:12.553772 2026] [security2:error] [pid 940476:tid 940708] [client 77.110.127.138:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxBjVYcQxwGpYwZnCOgAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:12.553878 2026] [security2:error] [pid 940476:tid 940708] [client 77.110.127.138:49806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxBjVYcQxwGpYwZnCOgAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:12.595906 2026] [security2:error] [pid 940476:tid 940707] [client 14.225.17.146:64547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4VwhjVYcQxwGpYwZnBpwAAAGU"], referer: http://grecruit.online/Old
[Mon Jul 20 06:34:12.734913 2026] [security2:error] [pid 940476:tid 940634] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/cgi-bin/index.php"] [unique_id "al4VxBjVYcQxwGpYwZnCRAAAABw"]
[Mon Jul 20 06:34:12.735003 2026] [security2:error] [pid 940476:tid 940634] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/cgi-bin/index.php"] [unique_id "al4VxBjVYcQxwGpYwZnCRAAAABw"]
[Mon Jul 20 06:34:12.827216 2026] [security2:error] [pid 940476:tid 940731] [client 57.141.18.50:50434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VvxjVYcQxwGpYwZnAxwAAfRU"]
[Mon Jul 20 06:34:12.885475 2026] [security2:error] [pid 935758:tid 935953] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4VxLcDxY_mIul-JSG01wAAAUk"]
[Mon Jul 20 06:34:12.929384 2026] [security2:error] [pid 935758:tid 935948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VxLcDxY_mIul-JSG02AAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:13.039493 2026] [security2:error] [pid 935758:tid 935995] [client 77.110.127.138:49616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 344 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VxbcDxY_mIul-JSG05AAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:13.088881 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4VxRjVYcQxwGpYwZnCYgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:13.113347 2026] [security2:error] [pid 940476:tid 940692] [client 45.3.44.124:19955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VxRjVYcQxwGpYwZnCYwAAAFY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:13.163568 2026] [security2:error] [pid 935758:tid 935973] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VxLcDxY_mIul-JSG04wAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:13.283734 2026] [security2:error] [pid 935758:tid 935971] [client 34.73.38.214:49291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VxbcDxY_mIul-JSG06QAAAVs"]
[Mon Jul 20 06:34:13.285729 2026] [security2:error] [pid 940476:tid 940696] [client 57.141.18.19:55036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VvxjVYcQxwGpYwZnA6wAAWgo"]
[Mon Jul 20 06:34:13.327079 2026] [proxy:error] [pid 940476:tid 940732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:13.327174 2026] [proxy_http:error] [pid 940476:tid 940732] [client 34.73.38.214:60017] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:13.327710 2026] [proxy:error] [pid 940476:tid 940732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:13.327740 2026] [proxy_http:error] [pid 940476:tid 940732] [client 34.73.38.214:60017] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:13.470744 2026] [security2:error] [pid 940476:tid 940617] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4VxRjVYcQxwGpYwZnCewAAAAs"]
[Mon Jul 20 06:34:13.472491 2026] [security2:error] [pid 940476:tid 940647] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4VxRjVYcQxwGpYwZnCeQAAACk"]
[Mon Jul 20 06:34:13.514643 2026] [security2:error] [pid 935758:tid 935955] [client 34.74.185.202:62931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VxbcDxY_mIul-JSG09AAAAUs"]
[Mon Jul 20 06:34:13.569790 2026] [security2:error] [pid 935758:tid 935968] [client 14.225.17.146:60431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4VxbcDxY_mIul-JSG05wAAAVg"]
[Mon Jul 20 06:34:13.596925 2026] [autoindex:error] [pid 940476:tid 940662] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:13.597608 2026] [security2:error] [pid 940476:tid 940662] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VxRjVYcQxwGpYwZnCigAAADg"]
[Mon Jul 20 06:34:13.600360 2026] [security2:error] [pid 940476:tid 940674] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4VxRjVYcQxwGpYwZnCgwAAAEQ"]
[Mon Jul 20 06:34:13.660685 2026] [security2:error] [pid 940476:tid 940638] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/BDKR28WP.php"] [unique_id "al4VxRjVYcQxwGpYwZnCkQAAACA"]
[Mon Jul 20 06:34:13.660820 2026] [security2:error] [pid 940476:tid 940638] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/BDKR28WP.php"] [unique_id "al4VxRjVYcQxwGpYwZnCkQAAACA"]
[Mon Jul 20 06:34:13.856898 2026] [security2:error] [pid 935758:tid 935924] [client 57.141.18.39:39663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VwLcDxY_mIul-JSG0UQABLDg"]
[Mon Jul 20 06:34:14.154743 2026] [security2:error] [pid 940476:tid 940625] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/l10n/"] [unique_id "al4VxhjVYcQxwGpYwZnCrAAAABM"]
[Mon Jul 20 06:34:14.169810 2026] [security2:error] [pid 935758:tid 935984] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/l10n/"] [unique_id "al4VxrcDxY_mIul-JSG1DwAAAWg"]
[Mon Jul 20 06:34:14.246060 2026] [security2:error] [pid 940476:tid 940647] [client 34.73.38.214:50710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4VxhjVYcQxwGpYwZnCsgAAACk"]
[Mon Jul 20 06:34:14.306762 2026] [security2:error] [pid 935758:tid 935916] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VxrcDxY_mIul-JSG1DQAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:14.415421 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxhjVYcQxwGpYwZnCvgAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:14.415513 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxhjVYcQxwGpYwZnCvgAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:14.440306 2026] [autoindex:error] [pid 935758:tid 935977] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:14.441066 2026] [security2:error] [pid 935758:tid 935977] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VxrcDxY_mIul-JSG1FgAAAWE"]
[Mon Jul 20 06:34:14.444803 2026] [security2:error] [pid 940476:tid 940664] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/l10n/"] [unique_id "al4VxhjVYcQxwGpYwZnCvAAAADo"]
[Mon Jul 20 06:34:14.470242 2026] [security2:error] [pid 935758:tid 936013] [client 77.110.127.138:49784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxrcDxY_mIul-JSG1FwAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:14.470374 2026] [security2:error] [pid 935758:tid 936013] [client 77.110.127.138:49784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VxrcDxY_mIul-JSG1FwAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:14.547226 2026] [security2:error] [pid 935758:tid 935951] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-content/uploads/"] [unique_id "al4VxrcDxY_mIul-JSG1GQAAAUc"]
[Mon Jul 20 06:34:14.642201 2026] [security2:error] [pid 935758:tid 935915] [client 77.110.127.138:49783] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VxrcDxY_mIul-JSG1HQAAASM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:14.642831 2026] [security2:error] [pid 940476:tid 940719] [client 34.74.185.202:64799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VxhjVYcQxwGpYwZnCzQAAAHE"]
[Mon Jul 20 06:34:14.679583 2026] [autoindex:error] [pid 935758:tid 936007] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:14.680286 2026] [security2:error] [pid 935758:tid 936007] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VxrcDxY_mIul-JSG1HwAAAX8"]
[Mon Jul 20 06:34:14.689284 2026] [security2:error] [pid 940476:tid 940681] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-content/uploads/"] [unique_id "al4VxhjVYcQxwGpYwZnCywAAAEs"]
[Mon Jul 20 06:34:14.742293 2026] [security2:error] [pid 940476:tid 940631] [client 82.102.18.182:37036] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4VxhjVYcQxwGpYwZnCzwAAABk"]
[Mon Jul 20 06:34:14.771950 2026] [security2:error] [pid 935758:tid 935945] [client 216.73.217.138:35499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4VxrcDxY_mIul-JSG1HgABQRM"]
[Mon Jul 20 06:34:14.871244 2026] [security2:error] [pid 935758:tid 935904] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/abcd.php"] [unique_id "al4VxrcDxY_mIul-JSG1IwAAARg"]
[Mon Jul 20 06:34:14.871359 2026] [security2:error] [pid 935758:tid 935904] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/abcd.php"] [unique_id "al4VxrcDxY_mIul-JSG1IwAAARg"]
[Mon Jul 20 06:34:14.946041 2026] [security2:error] [pid 940476:tid 940720] [client 34.73.38.214:62718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VxhjVYcQxwGpYwZnC5gAAAHI"]
[Mon Jul 20 06:34:15.162499 2026] [security2:error] [pid 935758:tid 935985] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/file15.php"] [unique_id "al4Vx7cDxY_mIul-JSG1KQAAAWk"]
[Mon Jul 20 06:34:15.162596 2026] [security2:error] [pid 935758:tid 935985] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/file15.php"] [unique_id "al4Vx7cDxY_mIul-JSG1KQAAAWk"]
[Mon Jul 20 06:34:15.184927 2026] [security2:error] [pid 940476:tid 940613] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VxhjVYcQxwGpYwZnC6gAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:15.381308 2026] [security2:error] [pid 940476:tid 940695] [client 82.102.18.182:37050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VxxjVYcQxwGpYwZnDDQAAAFk"]
[Mon Jul 20 06:34:15.411381 2026] [security2:error] [pid 935758:tid 935936] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Vx7cDxY_mIul-JSG1KgAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:15.435602 2026] [security2:error] [pid 940476:tid 940615] [client 34.74.185.202:49252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VxxjVYcQxwGpYwZnDGAAAAAk"]
[Mon Jul 20 06:34:15.449426 2026] [security2:error] [pid 940476:tid 940714] [client 50.116.65.227:28794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4VxxjVYcQxwGpYwZnDGgAAAGw"]
[Mon Jul 20 06:34:15.453253 2026] [security2:error] [pid 935758:tid 935946] [client 34.73.38.214:50751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Vx7cDxY_mIul-JSG1LQAAAUI"]
[Mon Jul 20 06:34:15.460678 2026] [security2:error] [pid 935758:tid 935954] [client 50.116.65.227:28810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Vx7cDxY_mIul-JSG1LgAAAUo"]
[Mon Jul 20 06:34:15.473089 2026] [security2:error] [pid 935758:tid 936012] [client 77.110.127.138:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpE3yqn1qo'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4Vx7cDxY_mIul-JSG1LwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:15.480241 2026] [security2:error] [pid 940476:tid 940542] [remote 74.235.96.117:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VxxjVYcQxwGpYwZnDGwAAX0E"]
[Mon Jul 20 06:34:15.514713 2026] [security2:error] [pid 940476:tid 940663] [client 52.109.56.130:29189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4VxxjVYcQxwGpYwZnDIAAAADk"]
[Mon Jul 20 06:34:15.555499 2026] [security2:error] [pid 940476:tid 940716] [client 57.141.18.73:22520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VwhjVYcQxwGpYwZnBfgAAbig"]
[Mon Jul 20 06:34:15.649570 2026] [security2:error] [pid 940476:tid 940636] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4VxxjVYcQxwGpYwZnDIgAAAB4"]
[Mon Jul 20 06:34:15.650104 2026] [security2:error] [pid 935758:tid 935896] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/jp.php"] [unique_id "al4Vx7cDxY_mIul-JSG1PgAAARA"]
[Mon Jul 20 06:34:15.650180 2026] [security2:error] [pid 935758:tid 935896] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/jp.php"] [unique_id "al4Vx7cDxY_mIul-JSG1PgAAARA"]
[Mon Jul 20 06:34:15.660522 2026] [security2:error] [pid 940476:tid 940518] [remote 74.235.96.117:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4VxxjVYcQxwGpYwZnDJwAAfSk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:34:15.672565 2026] [security2:error] [pid 935758:tid 936006] [client 39.48.81.23:55084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Vx7cDxY_mIul-JSG1PwAAAX4"]
[Mon Jul 20 06:34:15.672704 2026] [security2:error] [pid 935758:tid 936006] [client 39.48.81.23:55084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Vx7cDxY_mIul-JSG1PwAAAX4"]
[Mon Jul 20 06:34:15.723494 2026] [security2:error] [pid 935758:tid 935914] [client 82.102.18.182:37056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Vx7cDxY_mIul-JSG1QAAAASI"]
[Mon Jul 20 06:34:15.742704 2026] [security2:error] [pid 940476:tid 940652] [client 52.109.56.130:29189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4VxxjVYcQxwGpYwZnDKQAAAC4"]
[Mon Jul 20 06:34:15.855676 2026] [security2:error] [pid 940476:tid 940657] [client 197.186.66.42:65147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VxxjVYcQxwGpYwZnDNwAAADM"]
[Mon Jul 20 06:34:15.855808 2026] [security2:error] [pid 940476:tid 940657] [client 197.186.66.42:65147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4VxxjVYcQxwGpYwZnDNwAAADM"]
[Mon Jul 20 06:34:15.923942 2026] [security2:error] [pid 940476:tid 940658] [client 171.60.139.123:65050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VxxjVYcQxwGpYwZnDQQAAADQ"]
[Mon Jul 20 06:34:15.924080 2026] [security2:error] [pid 940476:tid 940658] [client 171.60.139.123:65050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4VxxjVYcQxwGpYwZnDQQAAADQ"]
[Mon Jul 20 06:34:16.001775 2026] [security2:error] [pid 935758:tid 935909] [client 57.141.18.66:29456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VwrcDxY_mIul-JSG0owABHXs"]
[Mon Jul 20 06:34:16.038564 2026] [security2:error] [pid 935758:tid 935982] [client 82.102.18.182:37066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VyLcDxY_mIul-JSG1SAAAAWY"]
[Mon Jul 20 06:34:16.289020 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:49846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyLcDxY_mIul-JSG1VgAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:16.289119 2026] [security2:error] [pid 935758:tid 935994] [client 77.110.127.138:49846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyLcDxY_mIul-JSG1VgAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:16.346271 2026] [security2:error] [pid 935758:tid 935911] [client 114.119.140.50:63793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karimnawfal.com"] [uri "/dr-karim-nawfal/index.php"] [unique_id "al4VyLcDxY_mIul-JSG1WwAAAR8"], referer: http://karimnawfal.com/dr-karim-nawfal/Laparoscopic-Surgery.php
[Mon Jul 20 06:34:16.349435 2026] [security2:error] [pid 940476:tid 940682] [client 77.110.127.138:49808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyBjVYcQxwGpYwZnDTgAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:16.349572 2026] [security2:error] [pid 940476:tid 940682] [client 77.110.127.138:49808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyBjVYcQxwGpYwZnDTgAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:16.382867 2026] [security2:error] [pid 935758:tid 935901] [client 82.102.18.182:37072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4VyLcDxY_mIul-JSG1XgAAARU"]
[Mon Jul 20 06:34:16.443758 2026] [security2:error] [pid 940476:tid 940708] [client 14.225.17.146:60619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4VxhjVYcQxwGpYwZnC3QAAAGY"], referer: http://headachescarpaltunnelfibromyalgia.com/Old
[Mon Jul 20 06:34:16.471418 2026] [security2:error] [pid 940476:tid 940661] [client 57.141.18.11:41752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VwxjVYcQxwGpYwZnBuwAAN0s"]
[Mon Jul 20 06:34:16.510685 2026] [security2:error] [pid 935758:tid 935916] [client 34.73.38.214:50037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4VyLcDxY_mIul-JSG1YgAAASQ"]
[Mon Jul 20 06:34:16.561814 2026] [security2:error] [pid 935758:tid 935922] [client 34.74.185.202:53253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VyLcDxY_mIul-JSG1YwAAASo"]
[Mon Jul 20 06:34:16.661151 2026] [security2:error] [pid 935758:tid 935969] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/f35.php"] [unique_id "al4VyLcDxY_mIul-JSG1ZgAAAVk"]
[Mon Jul 20 06:34:16.661298 2026] [security2:error] [pid 935758:tid 935969] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/f35.php"] [unique_id "al4VyLcDxY_mIul-JSG1ZgAAAVk"]
[Mon Jul 20 06:34:16.688114 2026] [security2:error] [pid 935758:tid 935953] [client 34.73.38.214:59854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VyLcDxY_mIul-JSG1aAAAAUk"]
[Mon Jul 20 06:34:16.733022 2026] [security2:error] [pid 935758:tid 935915] [client 82.102.18.182:29113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VyLcDxY_mIul-JSG1agAAASM"]
[Mon Jul 20 06:34:17.026829 2026] [security2:error] [pid 935758:tid 935985] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-load.php"] [unique_id "al4VybcDxY_mIul-JSG1cQAAAWk"]
[Mon Jul 20 06:34:17.026971 2026] [security2:error] [pid 935758:tid 935985] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-load.php"] [unique_id "al4VybcDxY_mIul-JSG1cQAAAWk"]
[Mon Jul 20 06:34:17.037472 2026] [security2:error] [pid 935758:tid 935945] [client 34.74.185.202:59308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.puk.jiv.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VybcDxY_mIul-JSG1cgAAAUE"]
[Mon Jul 20 06:34:17.044857 2026] [security2:error] [pid 940476:tid 940620] [client 82.102.18.182:37234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4VyRjVYcQxwGpYwZnDagAAAA4"]
[Mon Jul 20 06:34:17.122423 2026] [security2:error] [pid 940476:tid 940710] [client 54.184.226.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4VxhjVYcQxwGpYwZnC2AAAAGg"]
[Mon Jul 20 06:34:17.126969 2026] [security2:error] [pid 940476:tid 940692] [client 14.225.17.146:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4VxxjVYcQxwGpYwZnDMwAAAFY"], referer: http://keywayconstructionclt.com/Old
[Mon Jul 20 06:34:17.127077 2026] [security2:error] [pid 940476:tid 940649] [client 54.184.226.94:4717] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4VxhjVYcQxwGpYwZnC1QAAACs"]
[Mon Jul 20 06:34:17.299262 2026] [security2:error] [pid 940476:tid 940624] [client 57.141.18.27:42780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VxBjVYcQxwGpYwZnB-QAAEn8"]
[Mon Jul 20 06:34:17.308042 2026] [security2:error] [pid 940476:tid 940648] [client 57.141.18.87:60148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VxBjVYcQxwGpYwZnB-wAAKiM"]
[Mon Jul 20 06:34:17.342446 2026] [security2:error] [pid 935758:tid 935919] [client 104.234.53.58:22813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4VybcDxY_mIul-JSG1eQAAASc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:17.366052 2026] [security2:error] [pid 940476:tid 940647] [client 34.73.38.214:63471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4VyRjVYcQxwGpYwZnDgQAAACk"]
[Mon Jul 20 06:34:17.384848 2026] [security2:error] [pid 940476:tid 940652] [client 82.102.18.182:37236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VyRjVYcQxwGpYwZnDiQAAAC4"]
[Mon Jul 20 06:34:17.505562 2026] [security2:error] [pid 940476:tid 940729] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/xyn.php"] [unique_id "al4VyRjVYcQxwGpYwZnDkAAAAHs"]
[Mon Jul 20 06:34:17.505656 2026] [security2:error] [pid 940476:tid 940729] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/xyn.php"] [unique_id "al4VyRjVYcQxwGpYwZnDkAAAAHs"]
[Mon Jul 20 06:34:17.630106 2026] [security2:error] [pid 940476:tid 940721] [client 34.73.38.214:49744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4VyRjVYcQxwGpYwZnDmAAAAHM"]
[Mon Jul 20 06:34:17.729887 2026] [security2:error] [pid 935758:tid 935924] [client 82.102.18.182:37246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VybcDxY_mIul-JSG1gwAAASw"]
[Mon Jul 20 06:34:17.772578 2026] [security2:error] [pid 940476:tid 940726] [client 77.110.127.138:49852] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4VyRjVYcQxwGpYwZnDowAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:17.884906 2026] [security2:error] [pid 935758:tid 935976] [client 104.234.53.58:22813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4VybcDxY_mIul-JSG1hAAAAWA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:18.046242 2026] [security2:error] [pid 935758:tid 935910] [client 82.102.18.182:37262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VyrcDxY_mIul-JSG1iQAAAR4"]
[Mon Jul 20 06:34:18.070978 2026] [security2:error] [pid 940476:tid 940688] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-includes/assets/"] [unique_id "al4VyhjVYcQxwGpYwZnDuQAAAFI"]
[Mon Jul 20 06:34:18.075346 2026] [security2:error] [pid 940476:tid 940681] [client 34.73.38.214:50071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VyhjVYcQxwGpYwZnDuwAAAEs"]
[Mon Jul 20 06:34:18.082905 2026] [security2:error] [pid 940476:tid 940672] [client 14.225.17.146:54583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4VyhjVYcQxwGpYwZnDtwAAAEI"], referer: https://keywayconstructionclt.com/Old
[Mon Jul 20 06:34:18.146632 2026] [security2:error] [pid 940476:tid 940653] [client 200.120.157.86:58058] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.ttf"] [unique_id "al4VyhjVYcQxwGpYwZnDwQAAAC8"]
[Mon Jul 20 06:34:18.172444 2026] [autoindex:error] [pid 940476:tid 940612] [client 194.233.91.21:59606] AH01276: Cannot serve directory /home4/ksandsco/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:34:18.180796 2026] [security2:error] [pid 940476:tid 940678] [client 34.73.38.214:56791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4VyhjVYcQxwGpYwZnDxAAAAEg"]
[Mon Jul 20 06:34:18.224366 2026] [security2:error] [pid 935758:tid 935892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VybcDxY_mIul-JSG1hwAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:18.305130 2026] [security2:error] [pid 940476:tid 940625] [client 217.142.18.172:14123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4VyhjVYcQxwGpYwZnDzAAAABM"]
[Mon Jul 20 06:34:18.312021 2026] [security2:error] [pid 940476:tid 940625] [client 217.142.18.172:14123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4VyhjVYcQxwGpYwZnDzAAAABM"]
[Mon Jul 20 06:34:18.330271 2026] [autoindex:error] [pid 940476:tid 940662] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:18.331022 2026] [security2:error] [pid 940476:tid 940662] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4VyhjVYcQxwGpYwZnDzgAAADg"]
[Mon Jul 20 06:34:18.332217 2026] [security2:error] [pid 935758:tid 935918] [client 77.110.127.138:49706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phppH5Q3bjb'%20OR%20620=(SELECT%20620%20FROM%20PG_SLEEP(15))--"] [unique_id "al4VyrcDxY_mIul-JSG1kQAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:18.333857 2026] [security2:error] [pid 940476:tid 940727] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-includes/assets/"] [unique_id "al4VyhjVYcQxwGpYwZnDygAAAHk"]
[Mon Jul 20 06:34:18.363347 2026] [security2:error] [pid 935758:tid 936014] [client 82.102.18.182:37266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VyrcDxY_mIul-JSG1kgAAAYY"]
[Mon Jul 20 06:34:18.379208 2026] [security2:error] [pid 940476:tid 940638] [client 77.110.127.138:49829] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4VyhjVYcQxwGpYwZnD0wAAACA"]
[Mon Jul 20 06:34:18.394722 2026] [security2:error] [pid 935758:tid 935932] [client 57.141.18.111:54926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VxbcDxY_mIul-JSG07AABNDA"]
[Mon Jul 20 06:34:18.630946 2026] [security2:error] [pid 940476:tid 940674] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al4VyhjVYcQxwGpYwZnD4QAAAEQ"]
[Mon Jul 20 06:34:18.697731 2026] [security2:error] [pid 940476:tid 940730] [client 82.102.18.182:37272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4VyhjVYcQxwGpYwZnD6AAAAHw"]
[Mon Jul 20 06:34:18.816929 2026] [security2:error] [pid 940476:tid 940664] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VyhjVYcQxwGpYwZnD3AAAADo"], referer: 1'"3000
[Mon Jul 20 06:34:18.913842 2026] [security2:error] [pid 940476:tid 940634] [client 34.73.38.214:57037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VyhjVYcQxwGpYwZnD7QAAABw"]
[Mon Jul 20 06:34:18.986246 2026] [security2:error] [pid 935758:tid 935953] [client 34.73.38.214:54001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4VyrcDxY_mIul-JSG1oAAAAUk"]
[Mon Jul 20 06:34:18.992840 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyrcDxY_mIul-JSG1oQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:18.992936 2026] [security2:error] [pid 935758:tid 935996] [client 77.110.127.138:49794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyrcDxY_mIul-JSG1oQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:19.012830 2026] [security2:error] [pid 940476:tid 940719] [client 82.102.18.182:37276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4VyxjVYcQxwGpYwZnD9AAAAHE"]
[Mon Jul 20 06:34:19.043155 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:49795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyxjVYcQxwGpYwZnD9QAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:19.043283 2026] [security2:error] [pid 940476:tid 940662] [client 77.110.127.138:49795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VyxjVYcQxwGpYwZnD9QAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:19.143505 2026] [security2:error] [pid 940476:tid 940645] [client 171.61.165.146:16855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VyxjVYcQxwGpYwZnD-QAAACc"]
[Mon Jul 20 06:34:19.143624 2026] [security2:error] [pid 940476:tid 940645] [client 171.61.165.146:16855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4VyxjVYcQxwGpYwZnD-QAAACc"]
[Mon Jul 20 06:34:19.162231 2026] [security2:error] [pid 935758:tid 935935] [client 182.8.97.45:5327] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-solid-900.woff2"] [unique_id "al4Vy7cDxY_mIul-JSG1pgAAATc"]
[Mon Jul 20 06:34:19.242828 2026] [security2:error] [pid 940476:tid 940711] [client 178.120.53.25:3077] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-brands-400.woff2"] [unique_id "al4VyxjVYcQxwGpYwZnEAgAAAGk"]
[Mon Jul 20 06:34:19.257559 2026] [proxy:error] [pid 940476:tid 940721] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:19.257637 2026] [proxy_http:error] [pid 940476:tid 940721] [client 158.173.77.209:64833] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:19.258326 2026] [proxy:error] [pid 940476:tid 940721] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:19.258359 2026] [proxy_http:error] [pid 940476:tid 940721] [client 158.173.77.209:64833] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:19.323855 2026] [security2:error] [pid 940476:tid 940606] [client 82.102.18.182:37280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4VyxjVYcQxwGpYwZnEDAAAAAA"]
[Mon Jul 20 06:34:19.333705 2026] [autoindex:error] [pid 940476:tid 940638] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:19.334283 2026] [security2:error] [pid 940476:tid 940638] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "thescarystory.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al4VyxjVYcQxwGpYwZnEBAAAACA"]
[Mon Jul 20 06:34:19.335186 2026] [security2:error] [pid 940476:tid 940727] [client 45.145.137.233:15768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnD-AAAeRs"]
[Mon Jul 20 06:34:19.355347 2026] [security2:error] [pid 935758:tid 935933] [client 197.38.129.159:62028] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-regular-400.woff2"] [unique_id "al4Vy7cDxY_mIul-JSG1qgAAATU"]
[Mon Jul 20 06:34:19.416716 2026] [security2:error] [pid 940476:tid 940696] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ccc.php"] [unique_id "al4VyxjVYcQxwGpYwZnEFAAAAFo"]
[Mon Jul 20 06:34:19.416835 2026] [security2:error] [pid 940476:tid 940696] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ccc.php"] [unique_id "al4VyxjVYcQxwGpYwZnEFAAAAFo"]
[Mon Jul 20 06:34:19.519577 2026] [security2:error] [pid 940476:tid 940707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnECQAAAGU"], referer: 1'"3000
[Mon Jul 20 06:34:19.537459 2026] [security2:error] [pid 940476:tid 940699] [client 138.199.21.247:50887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnEDgAAAF0"], referer: http://fkconstructionfunding.com
[Mon Jul 20 06:34:19.551374 2026] [security2:error] [pid 940476:tid 940693] [client 14.225.17.146:54041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnEEwAAAFc"], referer: http://hammadownenterprises.com/Old
[Mon Jul 20 06:34:19.660306 2026] [security2:error] [pid 940476:tid 940678] [client 82.102.18.182:37290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4VyxjVYcQxwGpYwZnEIQAAAEg"]
[Mon Jul 20 06:34:19.677113 2026] [security2:error] [pid 940476:tid 940609] [client 144.124.192.126:55048] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.eot"] [unique_id "al4VyxjVYcQxwGpYwZnEJAAAAAM"]
[Mon Jul 20 06:34:19.896541 2026] [security2:error] [pid 940476:tid 940683] [client 50.116.65.227:56564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnEJgAAAE0"]
[Mon Jul 20 06:34:19.905424 2026] [security2:error] [pid 940476:tid 940622] [client 154.208.58.31:38066] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff"] [unique_id "al4VyxjVYcQxwGpYwZnEOQAAABA"]
[Mon Jul 20 06:34:19.983558 2026] [security2:error] [pid 940476:tid 940672] [client 82.102.18.182:37296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.nhe.tfw.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4VyxjVYcQxwGpYwZnEQwAAAEI"]
[Mon Jul 20 06:34:20.008798 2026] [security2:error] [pid 940476:tid 940615] [client 112.208.70.94:44722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VzBjVYcQxwGpYwZnERAAAAAk"]
[Mon Jul 20 06:34:20.008939 2026] [security2:error] [pid 940476:tid 940615] [client 112.208.70.94:44722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4VzBjVYcQxwGpYwZnERAAAAAk"]
[Mon Jul 20 06:34:20.018053 2026] [security2:error] [pid 935758:tid 935950] [client 170.246.82.73:12446] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/the-post-grid/assets/vendor/flaticon/flaticon_the_post_grid.woff2"] [unique_id "al4VzLcDxY_mIul-JSG1vQAAAUY"]
[Mon Jul 20 06:34:20.025167 2026] [security2:error] [pid 940476:tid 940541] [remote 100.42.189.89:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4VzBjVYcQxwGpYwZnERQAAUEA"]
[Mon Jul 20 06:34:20.121796 2026] [security2:error] [pid 940476:tid 940562] [remote 173.212.252.15:43402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4VzBjVYcQxwGpYwZnESAAAcVU"]
[Mon Jul 20 06:34:20.169568 2026] [security2:error] [pid 940476:tid 940680] [client 82.224.86.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4VyhjVYcQxwGpYwZnD1gAAAEo"], referer: https://areitoproducciones.com/instrumentos-virtuales/latin-percussion-vol-1/
[Mon Jul 20 06:34:20.189543 2026] [security2:error] [pid 940476:tid 940704] [client 50.116.65.227:56580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnEOgAAAGI"]
[Mon Jul 20 06:34:20.198573 2026] [security2:error] [pid 940476:tid 940693] [client 114.119.133.213:32059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bitesofwealth.com"] [uri "/robots.txt"] [unique_id "al4VzBjVYcQxwGpYwZnETgAAAFc"], referer: http://bitesofwealth.com/robots.txt
[Mon Jul 20 06:34:20.358533 2026] [security2:error] [pid 935758:tid 935976] [client 45.157.112.60:29827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4VzLcDxY_mIul-JSG1zwAAAWA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:34:20.363794 2026] [security2:error] [pid 940476:tid 940702] [client 57.141.18.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnELgAAAGA"]
[Mon Jul 20 06:34:20.410104 2026] [security2:error] [pid 940476:tid 940648] [client 161.118.195.148:62484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4VzBjVYcQxwGpYwZnEWgAAACo"]
[Mon Jul 20 06:34:20.422702 2026] [security2:error] [pid 940476:tid 940527] [remote 100.42.189.89:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4VzBjVYcQxwGpYwZnEWwAAbjI"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:34:20.462175 2026] [security2:error] [pid 940476:tid 940668] [client 57.141.18.106:23166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VxxjVYcQxwGpYwZnDJgAAPnI"]
[Mon Jul 20 06:34:20.542949 2026] [security2:error] [pid 940476:tid 940611] [client 57.141.18.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4VzBjVYcQxwGpYwZnEWQAAAAU"]
[Mon Jul 20 06:34:20.574357 2026] [security2:error] [pid 940476:tid 940517] [remote 173.212.252.15:43402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4VzBjVYcQxwGpYwZnEYgAAaSg"], referer: https://michiganhomecaregroup.com/wp-login.php
[Mon Jul 20 06:34:20.607210 2026] [security2:error] [pid 935758:tid 935941] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/w.php"] [unique_id "al4VzLcDxY_mIul-JSG12QAAAT0"]
[Mon Jul 20 06:34:20.607296 2026] [security2:error] [pid 935758:tid 935941] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/w.php"] [unique_id "al4VzLcDxY_mIul-JSG12QAAAT0"]
[Mon Jul 20 06:34:20.640673 2026] [security2:error] [pid 935758:tid 936012] [client 104.234.53.93:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4VzLcDxY_mIul-JSG12gAAAYQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:20.728523 2026] [security2:error] [pid 935758:tid 935796] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4VzLcDxY_mIul-JSG13QABEiM"]
[Mon Jul 20 06:34:20.728658 2026] [security2:error] [pid 935758:tid 935898] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4VzLcDxY_mIul-JSG13QABEiM"]
[Mon Jul 20 06:34:20.835222 2026] [security2:error] [pid 940476:tid 940703] [client 42.104.235.14:35960] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/plugins/post-slider-and-carousel/assets/webfonts/fa-v4compatibility.woff2"] [unique_id "al4VzBjVYcQxwGpYwZnEbwAAAGE"]
[Mon Jul 20 06:34:20.857146 2026] [security2:error] [pid 940476:tid 940697] [client 57.141.18.77:28010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VyBjVYcQxwGpYwZnDRwAAWwY"]
[Mon Jul 20 06:34:20.861767 2026] [security2:error] [pid 940476:tid 940689] [client 34.73.38.214:58804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4VzBjVYcQxwGpYwZnEcAAAAFM"]
[Mon Jul 20 06:34:20.887156 2026] [security2:error] [pid 935758:tid 935823] [remote 8.217.108.67:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VzLcDxY_mIul-JSG15QABKD4"]
[Mon Jul 20 06:34:20.956203 2026] [security2:error] [pid 940476:tid 940632] [client 14.225.17.146:54772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4VzBjVYcQxwGpYwZnEdAAAABo"], referer: http://katsklar.com/Old
[Mon Jul 20 06:34:21.028647 2026] [security2:error] [pid 935758:tid 935973] [client 187.108.85.186:53360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VzbcDxY_mIul-JSG16gAAAV0"]
[Mon Jul 20 06:34:21.028760 2026] [security2:error] [pid 935758:tid 935973] [client 187.108.85.186:53360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VzbcDxY_mIul-JSG16gAAAV0"]
[Mon Jul 20 06:34:21.087415 2026] [security2:error] [pid 940476:tid 940710] [client 201.239.150.235:49730] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.woff"] [unique_id "al4VzRjVYcQxwGpYwZnEhgAAAGg"]
[Mon Jul 20 06:34:21.140505 2026] [security2:error] [pid 940476:tid 940667] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VzBjVYcQxwGpYwZnEdwAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.250731 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:49842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpjMFhyJEt')%20OR%20339=(SELECT%20339%20FROM%20PG_SLEEP(15))--"] [unique_id "al4VzbcDxY_mIul-JSG17gAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.269810 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.110:47794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VyLcDxY_mIul-JSG1YAABY1o"]
[Mon Jul 20 06:34:21.293314 2026] [fcgid:warn] [pid 940476:tid 940645] (70014)End of file found: [client 103.168.67.159:39996] mod_fcgid: can't get data from http client
[Mon Jul 20 06:34:21.310972 2026] [security2:error] [pid 935758:tid 935908] [client 190.20.69.106:38972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.ttf"] [unique_id "al4VzbcDxY_mIul-JSG17wAAARw"]
[Mon Jul 20 06:34:21.368311 2026] [core:error] [pid 935758:tid 935958] [client 103.153.183.69:31192] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%uff0e%uff0e/.env?_=4zx0fv86&v=x6t5f), referer: https://t.co/kldyyuq3pu
[Mon Jul 20 06:34:21.371526 2026] [security2:error] [pid 935758:tid 935914] [client 127.0.0.1:24876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (%uFFFD)" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "100"] [id "390621"] [rev "5"] [msg "Atomicorp.com WAF Rules: Unicode Width Attack Attempt"] [data "%uff0e"] [severity "WARNING"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VzbcDxY_mIul-JSG18QAAASI"], referer: https://t.co/kldyyuq3pu
[Mon Jul 20 06:34:21.379474 2026] [proxy:error] [pid 935758:tid 935982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:21.379527 2026] [proxy_http:error] [pid 935758:tid 935982] [client 185.247.137.163:40211] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:21.380195 2026] [proxy:error] [pid 935758:tid 935982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:21.380224 2026] [proxy_http:error] [pid 935758:tid 935982] [client 185.247.137.163:40211] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:21.415624 2026] [security2:error] [pid 940476:tid 940666] [client 77.110.127.138:49873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnElgAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.415760 2026] [security2:error] [pid 940476:tid 940666] [client 77.110.127.138:49873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnElgAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.433525 2026] [security2:error] [pid 940476:tid 940652] [client 118.103.253.205:46659] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4VzRjVYcQxwGpYwZnEmQAAAC4"]
[Mon Jul 20 06:34:21.475405 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:49778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnEnAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.475499 2026] [security2:error] [pid 940476:tid 940663] [client 77.110.127.138:49778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnEnAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.533103 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:49850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzbcDxY_mIul-JSG1_AAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.533208 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:49850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzbcDxY_mIul-JSG1_AAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.559670 2026] [security2:error] [pid 940476:tid 940677] [client 103.125.179.95:55962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VzRjVYcQxwGpYwZnEogAAAEc"]
[Mon Jul 20 06:34:21.559828 2026] [security2:error] [pid 940476:tid 940677] [client 103.125.179.95:55962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4VzRjVYcQxwGpYwZnEogAAAEc"]
[Mon Jul 20 06:34:21.574476 2026] [security2:error] [pid 935758:tid 935825] [remote 8.217.108.67:53996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4VzbcDxY_mIul-JSG1_wABNEA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:34:21.584632 2026] [security2:error] [pid 935758:tid 935900] [client 161.118.195.148:62806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4VzbcDxY_mIul-JSG2AAAAARQ"]
[Mon Jul 20 06:34:21.585788 2026] [security2:error] [pid 940476:tid 940715] [client 77.110.127.138:49875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnEpAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.585879 2026] [security2:error] [pid 940476:tid 940715] [client 77.110.127.138:49875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnEpAAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.666932 2026] [security2:error] [pid 940476:tid 940563] [remote 57.141.18.103:28184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4085058"] [unique_id "al4VzRjVYcQxwGpYwZnErAAAC1Y"]
[Mon Jul 20 06:34:21.686730 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:49877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnErgAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.686834 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:49877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnErgAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.974812 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:49880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnEwQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:21.974917 2026] [security2:error] [pid 940476:tid 940628] [client 77.110.127.138:49880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzRjVYcQxwGpYwZnEwQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:22.025495 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:49783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzrcDxY_mIul-JSG2DQAAAWg"]
[Mon Jul 20 06:34:22.025604 2026] [security2:error] [pid 935758:tid 935984] [client 77.110.127.138:49783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzrcDxY_mIul-JSG2DQAAAWg"]
[Mon Jul 20 06:34:22.132440 2026] [security2:error] [pid 940476:tid 940643] [client 121.91.61.102:43254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "liquidationteam.com"] [uri "/wp-content/themes/kleo/assets/font/fontello.eot"] [unique_id "al4VzhjVYcQxwGpYwZnEzQAAACU"]
[Mon Jul 20 06:34:22.165291 2026] [security2:error] [pid 940476:tid 940635] [client 34.73.38.214:49498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4VzhjVYcQxwGpYwZnE0gAAAB0"]
[Mon Jul 20 06:34:22.182621 2026] [security2:error] [pid 940476:tid 940699] [client 34.73.38.214:55427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4VzhjVYcQxwGpYwZnE1QAAAF0"]
[Mon Jul 20 06:34:22.192778 2026] [security2:error] [pid 940476:tid 940619] [client 77.110.127.138:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzhjVYcQxwGpYwZnE1gAAAA0"]
[Mon Jul 20 06:34:22.192901 2026] [security2:error] [pid 940476:tid 940619] [client 77.110.127.138:49855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4VzhjVYcQxwGpYwZnE1gAAAA0"]
[Mon Jul 20 06:34:22.238199 2026] [security2:error] [pid 940476:tid 940657] [client 14.225.17.146:54480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnEOAAAADM"], referer: http://talknutritionwithlesley.com/Old
[Mon Jul 20 06:34:22.374244 2026] [security2:error] [pid 935758:tid 935955] [client 57.141.18.84:55408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VybcDxY_mIul-JSG1egABS3o"]
[Mon Jul 20 06:34:22.442683 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4VzhjVYcQxwGpYwZnE5QAAAHg"]
[Mon Jul 20 06:34:22.442793 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4VzhjVYcQxwGpYwZnE5QAAAHg"]
[Mon Jul 20 06:34:22.656672 2026] [security2:error] [pid 940476:tid 940655] [client 161.118.195.148:63428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4VzhjVYcQxwGpYwZnE7gAAADE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:22.775216 2026] [security2:error] [pid 935758:tid 935989] [client 45.3.52.95:13085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4VzrcDxY_mIul-JSG2GgAAAW0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:22.964838 2026] [core:error] [pid 940476:tid 940695] [client 103.153.183.69:31200] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%uff0e%uff0e/etc/passwd?_=7g04ozk6&v=c167l), referer: https://www.google.com/
[Mon Jul 20 06:34:22.967358 2026] [security2:error] [pid 940476:tid 940619] [client 127.0.0.1:24900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (%uFFFD)" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "100"] [id "390621"] [rev "5"] [msg "Atomicorp.com WAF Rules: Unicode Width Attack Attempt"] [data "%uff0e"] [severity "WARNING"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4VzhjVYcQxwGpYwZnFAwAAAA0"], referer: https://www.google.com/
[Mon Jul 20 06:34:23.242989 2026] [security2:error] [pid 940476:tid 940730] [client 161.118.195.148:64062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4VzxjVYcQxwGpYwZnFEAAAAHw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:23.603766 2026] [security2:error] [pid 940476:tid 940574] [remote 188.210.222.21:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.222.210.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4VzxjVYcQxwGpYwZnFGwAAXGE"]
[Mon Jul 20 06:34:23.768914 2026] [security2:error] [pid 940476:tid 940716] [client 34.73.38.214:59523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4VzxjVYcQxwGpYwZnFLAAAAG4"]
[Mon Jul 20 06:34:23.787600 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4VzxjVYcQxwGpYwZnFHgAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:23.801308 2026] [security2:error] [pid 940476:tid 940675] [client 34.73.38.214:55139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4VzxjVYcQxwGpYwZnFLgAAAEU"]
[Mon Jul 20 06:34:23.814215 2026] [security2:error] [pid 940476:tid 940523] [remote 188.210.222.21:53440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.222.210.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4VzxjVYcQxwGpYwZnFLwAACS4"], referer: https://musichaven.info/wp-login.php
[Mon Jul 20 06:34:23.814675 2026] [security2:error] [pid 940476:tid 940676] [client 161.118.195.148:64411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4VzxjVYcQxwGpYwZnFMAAAAEY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:23.816420 2026] [security2:error] [pid 935758:tid 935900] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/FWAZ.php"] [unique_id "al4Vz7cDxY_mIul-JSG2OgAAARQ"]
[Mon Jul 20 06:34:23.816556 2026] [security2:error] [pid 935758:tid 935900] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/FWAZ.php"] [unique_id "al4Vz7cDxY_mIul-JSG2OgAAARQ"]
[Mon Jul 20 06:34:23.988342 2026] [security2:error] [pid 940476:tid 940666] [client 14.225.17.146:52437] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4VzhjVYcQxwGpYwZnE3wAAADw"], referer: http://lelandumc.org/Old
[Mon Jul 20 06:34:23.991454 2026] [security2:error] [pid 940476:tid 940709] [client 77.110.127.138:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phplP7cp03o'))%20OR%20791=(SELECT%20791%20FROM%20PG_SLEEP(15))--"] [unique_id "al4VzxjVYcQxwGpYwZnFPQAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.150929 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:49893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2SQAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.151049 2026] [security2:error] [pid 935758:tid 935934] [client 77.110.127.138:49893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2SQAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.237380 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:49833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2TAAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.238093 2026] [security2:error] [pid 935758:tid 935957] [client 77.110.127.138:49833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2TAAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.254496 2026] [security2:error] [pid 940476:tid 940610] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V0BjVYcQxwGpYwZnFRAAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.374653 2026] [security2:error] [pid 940476:tid 940618] [client 223.185.13.213:19156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V0BjVYcQxwGpYwZnFUQAAAAw"]
[Mon Jul 20 06:34:24.374845 2026] [security2:error] [pid 940476:tid 940618] [client 223.185.13.213:19156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V0BjVYcQxwGpYwZnFUQAAAAw"]
[Mon Jul 20 06:34:24.388973 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:49895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0BjVYcQxwGpYwZnFUwAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.389079 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:49895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0BjVYcQxwGpYwZnFUwAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.394615 2026] [security2:error] [pid 935758:tid 935960] [client 161.118.195.148:64735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V0LcDxY_mIul-JSG2TQAAAVA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:24.658989 2026] [security2:error] [pid 940476:tid 940692] [client 14.225.17.146:49447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4V0BjVYcQxwGpYwZnFXQAAAFY"], referer: http://aandarealtygroup.com/Old
[Mon Jul 20 06:34:24.694872 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V0BjVYcQxwGpYwZnFXgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.722212 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:49899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2XAAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.722341 2026] [security2:error] [pid 935758:tid 935943] [client 77.110.127.138:49899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2XAAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.733730 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:49900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2XQAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.733846 2026] [security2:error] [pid 935758:tid 936000] [client 77.110.127.138:49900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0LcDxY_mIul-JSG2XQAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.743073 2026] [security2:error] [pid 940476:tid 940612] [client 57.141.18.0:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VyxjVYcQxwGpYwZnEJwAABn0"]
[Mon Jul 20 06:34:24.790271 2026] [security2:error] [pid 940476:tid 940670] [client 2.78.60.10:39538] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 10.60.78.2.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0BjVYcQxwGpYwZnFcwAAAEA"]
[Mon Jul 20 06:34:24.790486 2026] [security2:error] [pid 940476:tid 940670] [client 2.78.60.10:39538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "giftsurprizo.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0BjVYcQxwGpYwZnFcwAAAEA"]
[Mon Jul 20 06:34:24.812522 2026] [security2:error] [pid 940476:tid 940524] [remote 130.185.118.215:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V0BjVYcQxwGpYwZnFdAAAES8"]
[Mon Jul 20 06:34:24.861301 2026] [security2:error] [pid 940476:tid 940685] [client 104.234.53.56:45455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4V0BjVYcQxwGpYwZnFdwAAAE8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:24.967485 2026] [security2:error] [pid 940476:tid 940690] [client 161.118.195.148:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V0BjVYcQxwGpYwZnFhAAAAFQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:24.980900 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:49906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0BjVYcQxwGpYwZnFhQAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:24.981050 2026] [security2:error] [pid 940476:tid 940702] [client 77.110.127.138:49906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0BjVYcQxwGpYwZnFhQAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:25.000216 2026] [security2:error] [pid 935758:tid 935954] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/miru1.php"] [unique_id "al4V0LcDxY_mIul-JSG2YQAAAUo"]
[Mon Jul 20 06:34:25.000347 2026] [security2:error] [pid 935758:tid 935954] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/miru1.php"] [unique_id "al4V0LcDxY_mIul-JSG2YQAAAUo"]
[Mon Jul 20 06:34:25.011048 2026] [security2:error] [pid 940476:tid 940540] [remote 130.185.118.215:51348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V0RjVYcQxwGpYwZnFigAAUT8"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:34:25.033393 2026] [security2:error] [pid 940476:tid 940615] [client 14.225.17.146:49424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4V0BjVYcQxwGpYwZnFcgAAAAk"], referer: http://maxenengineering.com/Old
[Mon Jul 20 06:34:25.101984 2026] [security2:error] [pid 940476:tid 940625] [client 34.73.38.214:62637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4V0RjVYcQxwGpYwZnFjwAAABM"]
[Mon Jul 20 06:34:25.106515 2026] [security2:error] [pid 940476:tid 940693] [client 34.73.38.214:62811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.oqw.bur.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4V0RjVYcQxwGpYwZnFkAAAAFc"]
[Mon Jul 20 06:34:25.137403 2026] [security2:error] [pid 940476:tid 940659] [client 77.110.127.138:49912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0RjVYcQxwGpYwZnFlAAAADU"]
[Mon Jul 20 06:34:25.137570 2026] [security2:error] [pid 940476:tid 940659] [client 77.110.127.138:49912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0RjVYcQxwGpYwZnFlAAAADU"]
[Mon Jul 20 06:34:25.137922 2026] [security2:error] [pid 940476:tid 940717] [client 216.73.217.138:24287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4V0RjVYcQxwGpYwZnFiQAAbxI"]
[Mon Jul 20 06:34:25.297975 2026] [security2:error] [pid 935758:tid 935931] [client 141.94.194.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4V0LcDxY_mIul-JSG2YAAAATM"]
[Mon Jul 20 06:34:25.313048 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:49917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0bcDxY_mIul-JSG2agAAARw"]
[Mon Jul 20 06:34:25.313189 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:49917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0bcDxY_mIul-JSG2agAAARw"]
[Mon Jul 20 06:34:25.343393 2026] [security2:error] [pid 935758:tid 935894] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V0bcDxY_mIul-JSG2YgAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:25.456897 2026] [security2:error] [pid 940476:tid 940664] [client 223.237.130.40:52357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4V0BjVYcQxwGpYwZnFeAAAADo"]
[Mon Jul 20 06:34:25.533804 2026] [security2:error] [pid 940476:tid 940678] [client 57.141.18.106:47790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VzBjVYcQxwGpYwZnEUQAASA0"]
[Mon Jul 20 06:34:25.541184 2026] [security2:error] [pid 935758:tid 935914] [client 161.118.195.148:65385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V0bcDxY_mIul-JSG2bQAAASI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:25.646710 2026] [security2:error] [pid 940476:tid 940713] [client 14.225.17.146:56090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4V0RjVYcQxwGpYwZnFiwAAAGs"], referer: http://partnerselectricalllc.com/Old
[Mon Jul 20 06:34:25.719387 2026] [security2:error] [pid 940476:tid 940687] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V0RjVYcQxwGpYwZnFrQAAAFE"]
[Mon Jul 20 06:34:25.935239 2026] [security2:error] [pid 935758:tid 935933] [client 14.225.17.146:49522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4Vz7cDxY_mIul-JSG2MgAAATU"], referer: http://mrbambooplus.com/Old
[Mon Jul 20 06:34:25.945985 2026] [security2:error] [pid 935758:tid 935991] [client 14.225.17.146:52439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Vz7cDxY_mIul-JSG2PAAAAW8"], referer: http://floorsourcestock.com/Old
[Mon Jul 20 06:34:26.079848 2026] [security2:error] [pid 940476:tid 940606] [client 14.225.17.146:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4V0RjVYcQxwGpYwZnFyQAAAAA"], referer: https://maxenengineering.com/Old
[Mon Jul 20 06:34:26.117969 2026] [security2:error] [pid 940476:tid 940729] [client 161.118.195.148:49350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V0hjVYcQxwGpYwZnF1wAAAHs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:26.169041 2026] [security2:error] [pid 940476:tid 940658] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V0RjVYcQxwGpYwZnF0QAAADQ"]
[Mon Jul 20 06:34:26.440859 2026] [security2:error] [pid 935758:tid 935999] [client 14.225.17.146:49408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4V0rcDxY_mIul-JSG2gwAAAXc"], referer: http://fkconstructionfunding.com/Old
[Mon Jul 20 06:34:26.499560 2026] [core:error] [pid 940476:tid 940669] [client 103.153.183.69:31220] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%uff0e%uff0e/%uff0e%uff0e/.env?_=uk5dm7lh&v=hqtb2), referer: https://t.co/vdtogr5syw
[Mon Jul 20 06:34:26.502626 2026] [security2:error] [pid 940476:tid 940637] [client 127.0.0.1:24914] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (%uFFFD)" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "100"] [id "390621"] [rev "5"] [msg "Atomicorp.com WAF Rules: Unicode Width Attack Attempt"] [data "%uff0e"] [severity "WARNING"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4V0hjVYcQxwGpYwZnF7wAAAB8"], referer: https://t.co/vdtogr5syw
[Mon Jul 20 06:34:26.542418 2026] [security2:error] [pid 940476:tid 940610] [client 171.60.139.123:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V0hjVYcQxwGpYwZnF8QAAAAQ"]
[Mon Jul 20 06:34:26.542551 2026] [security2:error] [pid 940476:tid 940610] [client 171.60.139.123:49216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V0hjVYcQxwGpYwZnF8QAAAAQ"]
[Mon Jul 20 06:34:26.570082 2026] [security2:error] [pid 940476:tid 940642] [client 57.141.18.91:35484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VzRjVYcQxwGpYwZnEkAAAJEc"]
[Mon Jul 20 06:34:26.692093 2026] [security2:error] [pid 940476:tid 940719] [client 161.118.195.148:49680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V0hjVYcQxwGpYwZnF_gAAAHE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:26.832838 2026] [security2:error] [pid 935758:tid 935921] [client 14.225.17.146:64197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4V0rcDxY_mIul-JSG2iQAAASk"], referer: http://itdynamix.com/Old
[Mon Jul 20 06:34:26.882366 2026] [security2:error] [pid 940476:tid 940622] [client 197.186.66.42:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V0hjVYcQxwGpYwZnGCAAAABA"]
[Mon Jul 20 06:34:26.882852 2026] [security2:error] [pid 940476:tid 940622] [client 197.186.66.42:49268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V0hjVYcQxwGpYwZnGCAAAABA"]
[Mon Jul 20 06:34:26.908323 2026] [security2:error] [pid 940476:tid 940645] [client 77.110.127.138:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4V0hjVYcQxwGpYwZnGCQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:26.992209 2026] [security2:error] [pid 935758:tid 935976] [client 57.141.18.96:59974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VzbcDxY_mIul-JSG2AQABYGk"]
[Mon Jul 20 06:34:27.028085 2026] [security2:error] [pid 940476:tid 940705] [client 34.73.38.214:52378] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4V0xjVYcQxwGpYwZnGEAAAAGM"]
[Mon Jul 20 06:34:27.062489 2026] [security2:error] [pid 940476:tid 940619] [client 77.110.127.138:49935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGEQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.062576 2026] [security2:error] [pid 940476:tid 940619] [client 77.110.127.138:49935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGEQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.084193 2026] [security2:error] [pid 940476:tid 940721] [client 77.110.127.138:49936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V0xjVYcQxwGpYwZnGEwAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.222293 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:49939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V07cDxY_mIul-JSG2mgAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.222387 2026] [security2:error] [pid 935758:tid 935908] [client 77.110.127.138:49939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V07cDxY_mIul-JSG2mgAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.236314 2026] [security2:error] [pid 935758:tid 935946] [client 77.110.127.138:49940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php'\\""] [unique_id "al4V07cDxY_mIul-JSG2nAAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.267875 2026] [security2:error] [pid 935758:tid 935979] [client 161.118.195.148:50017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V07cDxY_mIul-JSG2ngAAAWM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:27.273115 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:49831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGIAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.273294 2026] [security2:error] [pid 940476:tid 940676] [client 77.110.127.138:49831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGIAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.281813 2026] [security2:error] [pid 940476:tid 940656] [client 57.141.18.103:44438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VzRjVYcQxwGpYwZnEwgAAMj4"]
[Mon Jul 20 06:34:27.423943 2026] [security2:error] [pid 935758:tid 935890] [client 77.110.127.138:49942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V07cDxY_mIul-JSG2pQAAAQo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.424029 2026] [security2:error] [pid 935758:tid 935890] [client 77.110.127.138:49942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V07cDxY_mIul-JSG2pQAAAQo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.475264 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:49943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4V0xjVYcQxwGpYwZnGLwAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.576298 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:49944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGNwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.576385 2026] [security2:error] [pid 940476:tid 940678] [client 77.110.127.138:49944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGNwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.698197 2026] [security2:error] [pid 935758:tid 935990] [client 39.48.81.23:55607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V07cDxY_mIul-JSG2qAAAAW4"]
[Mon Jul 20 06:34:27.698307 2026] [security2:error] [pid 935758:tid 935990] [client 39.48.81.23:55607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V07cDxY_mIul-JSG2qAAAAW4"]
[Mon Jul 20 06:34:27.727229 2026] [security2:error] [pid 940476:tid 940659] [client 77.110.127.138:49946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGSAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.727345 2026] [security2:error] [pid 940476:tid 940659] [client 77.110.127.138:49946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGSAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.769660 2026] [security2:error] [pid 935758:tid 935900] [client 52.167.144.142:34069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daseighty.net"] [uri "/gallery/main.php"] [unique_id "al4V07cDxY_mIul-JSG2qwAAARQ"]
[Mon Jul 20 06:34:27.812477 2026] [security2:error] [pid 940476:tid 940714] [client 77.110.127.138:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGTgAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.812570 2026] [security2:error] [pid 940476:tid 940714] [client 77.110.127.138:49947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V0xjVYcQxwGpYwZnGTgAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.816944 2026] [security2:error] [pid 935758:tid 935914] [client 14.225.17.146:65488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4V07cDxY_mIul-JSG2pwAAASI"], referer: https://itdynamix.com/Old
[Mon Jul 20 06:34:27.844700 2026] [security2:error] [pid 940476:tid 940674] [client 161.118.195.148:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V0xjVYcQxwGpYwZnGUAAAAEQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:27.853078 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:49945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V0xjVYcQxwGpYwZnGPgAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:27.927065 2026] [security2:error] [pid 940476:tid 940698] [client 14.225.17.146:53930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4V0xjVYcQxwGpYwZnGTAAAAFw"]
[Mon Jul 20 06:34:27.929797 2026] [security2:error] [pid 940476:tid 940547] [remote 192.241.143.148:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4V0xjVYcQxwGpYwZnGVwAAOUY"]
[Mon Jul 20 06:34:28.080438 2026] [security2:error] [pid 935758:tid 935930] [client 104.234.53.94:58977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4V1LcDxY_mIul-JSG2tQAAATI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:28.138329 2026] [security2:error] [pid 940476:tid 940494] [remote 192.241.143.148:45892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4V1BjVYcQxwGpYwZnGcwAACRE"], referer: https://colinkeyphotography.com/wp-login.php
[Mon Jul 20 06:34:28.217299 2026] [security2:error] [pid 940476:tid 940644] [client 77.110.127.138:49908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V1BjVYcQxwGpYwZnGYQAAACY"]
[Mon Jul 20 06:34:28.254455 2026] [security2:error] [pid 940476:tid 940606] [client 77.110.127.138:49948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1BjVYcQxwGpYwZnGfwAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:28.254536 2026] [security2:error] [pid 940476:tid 940606] [client 77.110.127.138:49948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1BjVYcQxwGpYwZnGfwAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:28.293676 2026] [security2:error] [pid 940476:tid 940686] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/aa.php"] [unique_id "al4V1BjVYcQxwGpYwZnGgwAAAFA"]
[Mon Jul 20 06:34:28.293798 2026] [security2:error] [pid 940476:tid 940686] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/aa.php"] [unique_id "al4V1BjVYcQxwGpYwZnGgwAAAFA"]
[Mon Jul 20 06:34:28.412491 2026] [security2:error] [pid 940476:tid 940643] [client 14.225.17.146:50343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4V1BjVYcQxwGpYwZnGhQAAACU"], referer: http://thechancersband.com/Old
[Mon Jul 20 06:34:28.418080 2026] [security2:error] [pid 940476:tid 940664] [client 161.118.195.148:50691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V1BjVYcQxwGpYwZnGjQAAADo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:28.532604 2026] [security2:error] [pid 940476:tid 940725] [client 77.110.127.138:49928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V1BjVYcQxwGpYwZnGgAAAAHc"]
[Mon Jul 20 06:34:28.559213 2026] [security2:error] [pid 940476:tid 940697] [client 57.141.18.40:23372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4VzxjVYcQxwGpYwZnFEQAAWxU"]
[Mon Jul 20 06:34:28.561359 2026] [security2:error] [pid 940476:tid 940733] [client 14.225.17.146:52371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4V1BjVYcQxwGpYwZnGjAAAAH8"], referer: http://mtlegnews.gov/Old
[Mon Jul 20 06:34:28.782285 2026] [security2:error] [pid 935758:tid 936012] [client 104.234.53.55:63085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4V1LcDxY_mIul-JSG2xAAAAYQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:28.836161 2026] [security2:error] [pid 940476:tid 940723] [client 217.142.18.172:13047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V1BjVYcQxwGpYwZnGpQAAAHU"]
[Mon Jul 20 06:34:28.836320 2026] [security2:error] [pid 940476:tid 940723] [client 217.142.18.172:13047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V1BjVYcQxwGpYwZnGpQAAAHU"]
[Mon Jul 20 06:34:29.004873 2026] [security2:error] [pid 940476:tid 940709] [client 161.118.195.148:51018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V1RjVYcQxwGpYwZnGtwAAAGc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:29.576480 2026] [security2:error] [pid 940476:tid 940674] [client 161.118.195.148:51299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V1RjVYcQxwGpYwZnG_QAAAEQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:29.691555 2026] [security2:error] [pid 940476:tid 940720] [client 34.73.38.214:55200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4V1RjVYcQxwGpYwZnHBAAAAHI"]
[Mon Jul 20 06:34:29.852477 2026] [security2:error] [pid 935758:tid 936009] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4V1LcDxY_mIul-JSG2swAAAYE"]
[Mon Jul 20 06:34:29.903675 2026] [security2:error] [pid 940476:tid 940704] [client 14.225.17.146:60348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4V1RjVYcQxwGpYwZnGwgAAAGI"], referer: http://idigress.studio/Old
[Mon Jul 20 06:34:29.903733 2026] [security2:error] [pid 940476:tid 940724] [client 104.234.53.86:49875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4V1RjVYcQxwGpYwZnHFAAAAHY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:29.925511 2026] [security2:error] [pid 935758:tid 936016] [client 14.225.17.146:52879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4V1bcDxY_mIul-JSG26AAAAYg"], referer: http://vinovinhowine.com/Old
[Mon Jul 20 06:34:30.051474 2026] [security2:error] [pid 940476:tid 940706] [client 14.225.17.146:53774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4V1RjVYcQxwGpYwZnHEQAAAGQ"]
[Mon Jul 20 06:34:30.083027 2026] [security2:error] [pid 940476:tid 940650] [client 57.141.18.53:43906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0BjVYcQxwGpYwZnFewAALHE"]
[Mon Jul 20 06:34:30.117563 2026] [security2:error] [pid 940476:tid 940679] [client 14.225.17.146:54069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4V1BjVYcQxwGpYwZnGpAAAAEk"], referer: http://wathenbartlett.co.uk/Old
[Mon Jul 20 06:34:30.148947 2026] [security2:error] [pid 940476:tid 940642] [client 161.118.195.148:51596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V1hjVYcQxwGpYwZnHJgAAACQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:30.255723 2026] [security2:error] [pid 940476:tid 940733] [client 77.110.127.138:49969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHKQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.255873 2026] [security2:error] [pid 940476:tid 940733] [client 77.110.127.138:49969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHKQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.308690 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHLQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.308861 2026] [security2:error] [pid 940476:tid 940616] [client 77.110.127.138:49938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHLQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.314439 2026] [security2:error] [pid 940476:tid 940585] [remote 47.86.33.52:12966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4V1hjVYcQxwGpYwZnHLAAAemw"]
[Mon Jul 20 06:34:30.321462 2026] [security2:error] [pid 940476:tid 940718] [client 57.141.18.101:43490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0RjVYcQxwGpYwZnFkgAAcHs"]
[Mon Jul 20 06:34:30.519688 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:49974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1rcDxY_mIul-JSG3BgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.519822 2026] [security2:error] [pid 935758:tid 935891] [client 77.110.127.138:49974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1rcDxY_mIul-JSG3BgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.552367 2026] [security2:error] [pid 940476:tid 940604] [remote 103.255.134.61:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHNgAAWn8"]
[Mon Jul 20 06:34:30.552535 2026] [security2:error] [pid 940476:tid 940696] [client 103.255.134.61:56108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHNgAAWn8"]
[Mon Jul 20 06:34:30.628115 2026] [security2:error] [pid 935758:tid 935892] [client 57.141.18.86:43336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0bcDxY_mIul-JSG2bAABDFc"]
[Mon Jul 20 06:34:30.661336 2026] [security2:error] [pid 940476:tid 940629] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/122.php"] [unique_id "al4V1hjVYcQxwGpYwZnHOgAAABc"]
[Mon Jul 20 06:34:30.661434 2026] [security2:error] [pid 940476:tid 940629] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/122.php"] [unique_id "al4V1hjVYcQxwGpYwZnHOgAAABc"]
[Mon Jul 20 06:34:30.681828 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:49976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1rcDxY_mIul-JSG3CgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.681907 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:49976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1rcDxY_mIul-JSG3CgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.698999 2026] [security2:error] [pid 940476:tid 940564] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHOwAAaVc"]
[Mon Jul 20 06:34:30.699218 2026] [security2:error] [pid 940476:tid 940711] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHOwAAaVc"]
[Mon Jul 20 06:34:30.724312 2026] [security2:error] [pid 935758:tid 935907] [client 161.118.195.148:51929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V1rcDxY_mIul-JSG3DAAAARs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:30.732534 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:49908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHPAAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.732633 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:49908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHPAAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.794212 2026] [security2:error] [pid 940476:tid 940729] [client 106.219.188.178:47744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHQgAAAHs"]
[Mon Jul 20 06:34:30.794322 2026] [security2:error] [pid 940476:tid 940729] [client 106.219.188.178:47744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHQgAAAHs"]
[Mon Jul 20 06:34:30.891299 2026] [security2:error] [pid 940476:tid 940615] [client 77.110.127.138:49978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHSAAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.891392 2026] [security2:error] [pid 940476:tid 940615] [client 77.110.127.138:49978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHSAAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.965844 2026] [security2:error] [pid 940476:tid 940686] [client 77.110.127.138:49878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHUAAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.965935 2026] [security2:error] [pid 940476:tid 940686] [client 77.110.127.138:49878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHUAAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.972231 2026] [security2:error] [pid 940476:tid 940624] [client 77.110.127.138:49951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHUQAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.972370 2026] [security2:error] [pid 940476:tid 940624] [client 77.110.127.138:49951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V1hjVYcQxwGpYwZnHUQAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:30.992823 2026] [security2:error] [pid 940476:tid 940655] [client 171.61.165.146:26455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHVAAAADE"]
[Mon Jul 20 06:34:30.992959 2026] [security2:error] [pid 940476:tid 940655] [client 171.61.165.146:26455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V1hjVYcQxwGpYwZnHVAAAADE"]
[Mon Jul 20 06:34:31.016486 2026] [security2:error] [pid 935758:tid 935975] [client 77.110.127.138:49956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V17cDxY_mIul-JSG3FAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:31.110597 2026] [security2:error] [pid 940476:tid 940620] [client 14.225.17.146:54329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4V1xjVYcQxwGpYwZnHVgAAAA4"], referer: https://wathenbartlett.co.uk/Old
[Mon Jul 20 06:34:31.296913 2026] [security2:error] [pid 940476:tid 940625] [client 161.118.195.148:52289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V1xjVYcQxwGpYwZnHZAAAABM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:31.299933 2026] [security2:error] [pid 940476:tid 940606] [client 104.234.53.64:58957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4V1xjVYcQxwGpYwZnHZQAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:31.406356 2026] [security2:error] [pid 940476:tid 940723] [client 14.225.17.146:52860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4V1RjVYcQxwGpYwZnHAQAAAHU"], referer: http://secretkeynumerology.com/Old
[Mon Jul 20 06:34:31.438645 2026] [security2:error] [pid 940476:tid 940682] [client 34.73.38.214:62908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ouw.egd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4V1xjVYcQxwGpYwZnHaQAAAEw"]
[Mon Jul 20 06:34:31.537909 2026] [security2:error] [pid 940476:tid 940608] [client 57.141.18.83:65524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0hjVYcQxwGpYwZnF8AAAAik"]
[Mon Jul 20 06:34:31.709520 2026] [security2:error] [pid 940476:tid 940719] [client 187.108.85.186:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V1xjVYcQxwGpYwZnHfgAAAHE"]
[Mon Jul 20 06:34:31.709673 2026] [security2:error] [pid 940476:tid 940719] [client 187.108.85.186:53894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V1xjVYcQxwGpYwZnHfgAAAHE"]
[Mon Jul 20 06:34:31.873804 2026] [security2:error] [pid 935758:tid 935955] [client 161.118.195.148:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V17cDxY_mIul-JSG3KAAAAUs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:31.925659 2026] [security2:error] [pid 940476:tid 940690] [client 14.225.17.146:53799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4V1xjVYcQxwGpYwZnHgAAAAFQ"], referer: http://transparentservices.online/Old
[Mon Jul 20 06:34:31.967526 2026] [security2:error] [pid 940476:tid 940628] [client 14.225.17.146:53573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4V1xjVYcQxwGpYwZnHhwAAABY"], referer: http://friendlyspreadsheet.com/Old
[Mon Jul 20 06:34:32.083827 2026] [security2:error] [pid 940476:tid 940583] [remote 47.86.33.52:12966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4V2BjVYcQxwGpYwZnHlAAAOmo"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:34:32.130303 2026] [security2:error] [pid 940476:tid 940653] [client 57.141.18.1:41750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0xjVYcQxwGpYwZnGGAAAL3U"]
[Mon Jul 20 06:34:32.180818 2026] [security2:error] [pid 940476:tid 940688] [client 103.125.179.95:56444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V2BjVYcQxwGpYwZnHnQAAAFI"]
[Mon Jul 20 06:34:32.180908 2026] [security2:error] [pid 940476:tid 940688] [client 103.125.179.95:56444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V2BjVYcQxwGpYwZnHnQAAAFI"]
[Mon Jul 20 06:34:32.376258 2026] [security2:error] [pid 940476:tid 940608] [client 77.110.127.138:49988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V2BjVYcQxwGpYwZnHpwAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:32.376373 2026] [security2:error] [pid 940476:tid 940608] [client 77.110.127.138:49988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V2BjVYcQxwGpYwZnHpwAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:32.411718 2026] [security2:error] [pid 940476:tid 940717] [client 14.225.17.146:52831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnHoQAAAG8"], referer: https://secretkeynumerology.com/Old
[Mon Jul 20 06:34:32.446661 2026] [security2:error] [pid 940476:tid 940723] [client 161.118.195.148:52936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnHrwAAAHU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:32.505778 2026] [security2:error] [pid 940476:tid 940731] [client 57.141.18.74:22178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0xjVYcQxwGpYwZnGNQAAfTw"]
[Mon Jul 20 06:34:32.533526 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:49989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V2BjVYcQxwGpYwZnHtQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:32.533619 2026] [security2:error] [pid 940476:tid 940727] [client 77.110.127.138:49989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V2BjVYcQxwGpYwZnHtQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:32.653664 2026] [security2:error] [pid 940476:tid 940694] [client 57.141.18.93:48384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V0xjVYcQxwGpYwZnGPwAAWHk"]
[Mon Jul 20 06:34:32.712858 2026] [security2:error] [pid 940476:tid 940618] [client 104.234.53.59:42493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4V2BjVYcQxwGpYwZnHxAAAAAw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:32.713001 2026] [security2:error] [pid 940476:tid 940724] [client 57.141.18.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnHugAAAHY"]
[Mon Jul 20 06:34:32.789635 2026] [security2:error] [pid 940476:tid 940688] [client 185.117.225.199:52046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.sergnotes.com"] [uri "/robots.txt"] [unique_id "al4V2BjVYcQxwGpYwZnHzwAAAFI"]
[Mon Jul 20 06:34:32.890806 2026] [security2:error] [pid 940476:tid 940622] [client 14.225.17.146:53089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnH0AAAABA"], referer: https://friendlyspreadsheet.com/Old
[Mon Jul 20 06:34:33.009661 2026] [security2:error] [pid 940476:tid 940629] [client 77.110.127.138:49971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2RjVYcQxwGpYwZnH5gAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:33.029938 2026] [security2:error] [pid 940476:tid 940647] [client 161.118.195.148:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V2RjVYcQxwGpYwZnH5wAAACk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:33.166546 2026] [security2:error] [pid 940476:tid 940697] [client 77.110.127.138:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2RjVYcQxwGpYwZnH7wAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:33.217915 2026] [security2:error] [pid 940476:tid 940627] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4V2RjVYcQxwGpYwZnH6gAAFWY"], referer: http://aleishapenny.ca/Old
[Mon Jul 20 06:34:33.257129 2026] [security2:error] [pid 940476:tid 940706] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/get.php"] [unique_id "al4V2RjVYcQxwGpYwZnH9gAAAGQ"]
[Mon Jul 20 06:34:33.257272 2026] [security2:error] [pid 940476:tid 940706] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/get.php"] [unique_id "al4V2RjVYcQxwGpYwZnH9gAAAGQ"]
[Mon Jul 20 06:34:33.316671 2026] [security2:error] [pid 940476:tid 940632] [client 112.208.70.94:45169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V2RjVYcQxwGpYwZnH-AAAABo"]
[Mon Jul 20 06:34:33.316828 2026] [security2:error] [pid 940476:tid 940632] [client 112.208.70.94:45169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V2RjVYcQxwGpYwZnH-AAAABo"]
[Mon Jul 20 06:34:33.330991 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:49997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2RjVYcQxwGpYwZnH-wAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:33.350520 2026] [security2:error] [pid 940476:tid 940717] [client 82.224.86.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnH3wAAAG8"], referer: https://areitoproducciones.com/instrumentos-virtuales/
[Mon Jul 20 06:34:33.567122 2026] [security2:error] [pid 940476:tid 940657] [client 51.158.58.168:37600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel-box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4V2RjVYcQxwGpYwZnIDQAAADM"]
[Mon Jul 20 06:34:33.604573 2026] [security2:error] [pid 940476:tid 940688] [client 161.118.195.148:53551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V2RjVYcQxwGpYwZnIEgAAAFI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:33.636989 2026] [security2:error] [pid 940476:tid 940707] [client 74.208.214.194:39458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4V2RjVYcQxwGpYwZnIFAAAAGU"]
[Mon Jul 20 06:34:33.854615 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:49999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2RjVYcQxwGpYwZnIHwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:33.907329 2026] [security2:error] [pid 935758:tid 935904] [client 57.141.18.78:36148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V1bcDxY_mIul-JSG20QABGBo"]
[Mon Jul 20 06:34:34.018127 2026] [security2:error] [pid 940476:tid 940607] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4V2RjVYcQxwGpYwZnIJgAAAXA"], referer: https://aleishapenny.ca/Old
[Mon Jul 20 06:34:34.047925 2026] [security2:error] [pid 935758:tid 935955] [client 145.239.10.137:36266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/eetu.php"] [unique_id "al4V2rcDxY_mIul-JSG3WgAAAUs"], referer: http://alchemygroup.ca/eetu.php
[Mon Jul 20 06:34:34.072433 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.46:45330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V1bcDxY_mIul-JSG20gABY3E"]
[Mon Jul 20 06:34:34.125267 2026] [security2:error] [pid 940476:tid 940685] [client 223.185.13.213:27053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V2hjVYcQxwGpYwZnIOAAAAE8"]
[Mon Jul 20 06:34:34.126785 2026] [security2:error] [pid 940476:tid 940685] [client 223.185.13.213:27053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V2hjVYcQxwGpYwZnIOAAAAE8"]
[Mon Jul 20 06:34:34.183736 2026] [security2:error] [pid 935758:tid 936009] [client 161.118.195.148:53880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V2rcDxY_mIul-JSG3YQAAAYE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:34.312114 2026] [security2:error] [pid 940476:tid 940657] [client 77.110.127.138:50004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2hjVYcQxwGpYwZnIRQAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:34.341105 2026] [security2:error] [pid 940476:tid 940711] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/as.php"] [unique_id "al4V2hjVYcQxwGpYwZnISQAAAGk"]
[Mon Jul 20 06:34:34.341185 2026] [security2:error] [pid 940476:tid 940711] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/as.php"] [unique_id "al4V2hjVYcQxwGpYwZnISQAAAGk"]
[Mon Jul 20 06:34:34.378126 2026] [security2:error] [pid 940476:tid 940684] [client 104.234.53.73:43259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4V2hjVYcQxwGpYwZnITAAAAE4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:34.434629 2026] [security2:error] [pid 940476:tid 940618] [client 77.110.127.138:49977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2hjVYcQxwGpYwZnIUAAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:34.562125 2026] [security2:error] [pid 940476:tid 940669] [client 14.225.17.146:49848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnHkwAAAD8"], referer: http://healthylifegourmet.org/Old
[Mon Jul 20 06:34:34.595528 2026] [security2:error] [pid 940476:tid 940649] [client 77.110.127.138:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V2hjVYcQxwGpYwZnIZQAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:34.628012 2026] [security2:error] [pid 935758:tid 935805] [remote 57.141.18.125:46750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3632122"] [unique_id "al4V2rcDxY_mIul-JSG3bwABDCw"]
[Mon Jul 20 06:34:34.636097 2026] [security2:error] [pid 935758:tid 935978] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4V2rcDxY_mIul-JSG3bAAAAWI"]
[Mon Jul 20 06:34:34.756195 2026] [security2:error] [pid 940476:tid 940657] [client 161.118.195.148:54208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V2hjVYcQxwGpYwZnIawAAADM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:34.838105 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V2hjVYcQxwGpYwZnIcQAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:34.838253 2026] [security2:error] [pid 940476:tid 940612] [client 77.110.127.138:49980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V2hjVYcQxwGpYwZnIcQAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:34.847784 2026] [security2:error] [pid 940476:tid 940648] [client 52.59.238.198:30870] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4V2hjVYcQxwGpYwZnIcgAAACo"]
[Mon Jul 20 06:34:34.927426 2026] [security2:error] [pid 940476:tid 940526] [remote 124.55.178.99:59202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4V2hjVYcQxwGpYwZnIeAAAfTE"]
[Mon Jul 20 06:34:34.950874 2026] [security2:error] [pid 935758:tid 935906] [client 57.141.18.22:28180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V1rcDxY_mIul-JSG28AABGnI"]
[Mon Jul 20 06:34:34.961490 2026] [security2:error] [pid 940476:tid 940682] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4V2hjVYcQxwGpYwZnIUwAATEw"], referer: http://ardhalwafaa.com/Old
[Mon Jul 20 06:34:34.980925 2026] [security2:error] [pid 935758:tid 936010] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ccou.php"] [unique_id "al4V2rcDxY_mIul-JSG3eAAAAYI"]
[Mon Jul 20 06:34:34.981092 2026] [security2:error] [pid 935758:tid 936010] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ccou.php"] [unique_id "al4V2rcDxY_mIul-JSG3eAAAAYI"]
[Mon Jul 20 06:34:35.005966 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V27cDxY_mIul-JSG3egAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:35.006080 2026] [security2:error] [pid 935758:tid 935947] [client 77.110.127.138:50010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V27cDxY_mIul-JSG3egAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:35.011585 2026] [security2:error] [pid 935758:tid 935941] [client 57.141.18.22:28184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V1rcDxY_mIul-JSG29gABPTU"]
[Mon Jul 20 06:34:35.327258 2026] [security2:error] [pid 940476:tid 940624] [client 161.118.195.148:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V2xjVYcQxwGpYwZnIkwAAABI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:35.376386 2026] [security2:error] [pid 940476:tid 940599] [remote 124.55.178.99:59202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4V2xjVYcQxwGpYwZnImAAAWHo"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:34:35.785756 2026] [security2:error] [pid 940476:tid 940656] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/w3lls.php"] [unique_id "al4V2xjVYcQxwGpYwZnIrwAAADI"]
[Mon Jul 20 06:34:35.785917 2026] [security2:error] [pid 940476:tid 940656] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/w3lls.php"] [unique_id "al4V2xjVYcQxwGpYwZnIrwAAADI"]
[Mon Jul 20 06:34:35.874682 2026] [security2:error] [pid 940476:tid 940643] [client 57.141.18.84:50282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V1xjVYcQxwGpYwZnHWgAAJTo"]
[Mon Jul 20 06:34:35.875503 2026] [security2:error] [pid 940476:tid 940663] [client 52.59.238.198:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4V2xjVYcQxwGpYwZnImgAAADk"]
[Mon Jul 20 06:34:35.879086 2026] [security2:error] [pid 940476:tid 940677] [client 52.59.238.198:59218] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4V2xjVYcQxwGpYwZnIlQAAAEc"]
[Mon Jul 20 06:34:35.898877 2026] [security2:error] [pid 940476:tid 940670] [client 161.118.195.148:54865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V2xjVYcQxwGpYwZnItAAAAEA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:36.177654 2026] [security2:error] [pid 940476:tid 940594] [remote 47.82.124.113:39176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2021/03/Hillside-Beach-Club-Turkey-Sailing-1200w.jpg"] [unique_id "al4V3BjVYcQxwGpYwZnIwQAARXU"]
[Mon Jul 20 06:34:36.458749 2026] [security2:error] [pid 940476:tid 940612] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/test1.php"] [unique_id "al4V3BjVYcQxwGpYwZnI1wAAAAY"]
[Mon Jul 20 06:34:36.458867 2026] [security2:error] [pid 940476:tid 940612] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/test1.php"] [unique_id "al4V3BjVYcQxwGpYwZnI1wAAAAY"]
[Mon Jul 20 06:34:36.472482 2026] [security2:error] [pid 940476:tid 940662] [client 161.118.195.148:55164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V3BjVYcQxwGpYwZnI2QAAADg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:36.640192 2026] [security2:error] [pid 940476:tid 940672] [client 57.141.18.113:48280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V1xjVYcQxwGpYwZnHgwAAQjg"]
[Mon Jul 20 06:34:36.829617 2026] [security2:error] [pid 935758:tid 935925] [client 57.141.18.91:62126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V17cDxY_mIul-JSG3KQABLW4"]
[Mon Jul 20 06:34:36.867928 2026] [security2:error] [pid 940476:tid 940711] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/database.php"] [unique_id "al4V3BjVYcQxwGpYwZnI8AAAAGk"]
[Mon Jul 20 06:34:36.868018 2026] [security2:error] [pid 940476:tid 940711] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/database.php"] [unique_id "al4V3BjVYcQxwGpYwZnI8AAAAGk"]
[Mon Jul 20 06:34:37.054077 2026] [security2:error] [pid 940476:tid 940680] [client 161.118.195.148:55491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V3RjVYcQxwGpYwZnI-gAAAEo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:37.097914 2026] [security2:error] [pid 940476:tid 940714] [client 14.225.17.146:52723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4V3BjVYcQxwGpYwZnI8gAAAGw"], referer: http://soloceos.com/Old
[Mon Jul 20 06:34:37.114114 2026] [security2:error] [pid 940476:tid 940720] [client 77.110.127.138:49994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V3RjVYcQxwGpYwZnI_gAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:37.120846 2026] [security2:error] [pid 935758:tid 936010] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/file.php"] [unique_id "al4V3bcDxY_mIul-JSG3rAAAAYI"]
[Mon Jul 20 06:34:37.120960 2026] [security2:error] [pid 935758:tid 936010] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/file.php"] [unique_id "al4V3bcDxY_mIul-JSG3rAAAAYI"]
[Mon Jul 20 06:34:37.127444 2026] [security2:error] [pid 935758:tid 935891] [client 63.177.52.239:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4V3LcDxY_mIul-JSG3lwAAAQs"]
[Mon Jul 20 06:34:37.191368 2026] [security2:error] [pid 940476:tid 940652] [client 63.177.52.239:13182] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4V3BjVYcQxwGpYwZnI0AAAAC4"]
[Mon Jul 20 06:34:37.322161 2026] [security2:error] [pid 935758:tid 935969] [client 171.60.139.123:49746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V3bcDxY_mIul-JSG3tQAAAVk"]
[Mon Jul 20 06:34:37.322255 2026] [security2:error] [pid 935758:tid 935969] [client 171.60.139.123:49746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V3bcDxY_mIul-JSG3tQAAAVk"]
[Mon Jul 20 06:34:37.367063 2026] [security2:error] [pid 940476:tid 940623] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/file.php"] [unique_id "al4V3RjVYcQxwGpYwZnJCwAAABE"]
[Mon Jul 20 06:34:37.367158 2026] [security2:error] [pid 940476:tid 940623] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/file.php"] [unique_id "al4V3RjVYcQxwGpYwZnJCwAAABE"]
[Mon Jul 20 06:34:37.371660 2026] [security2:error] [pid 940476:tid 940696] [client 57.141.18.10:30518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnHrQAAWgI"]
[Mon Jul 20 06:34:37.435912 2026] [security2:error] [pid 940476:tid 940485] [remote 47.82.124.113:39176] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2021/03/Hillside-Beach-Club-Turkey-Sailing-1200w.jpg"] [unique_id "al4V3RjVYcQxwGpYwZnJDgAAYwg"]
[Mon Jul 20 06:34:37.625671 2026] [security2:error] [pid 940476:tid 940620] [client 57.141.18.118:48944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2BjVYcQxwGpYwZnHzQAADn0"]
[Mon Jul 20 06:34:37.629546 2026] [security2:error] [pid 940476:tid 940669] [client 161.118.195.148:55853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V3RjVYcQxwGpYwZnJHQAAAD8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:37.647962 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:49998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V3RjVYcQxwGpYwZnJHgAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:37.648120 2026] [security2:error] [pid 940476:tid 940679] [client 77.110.127.138:49998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V3RjVYcQxwGpYwZnJHgAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:37.664336 2026] [security2:error] [pid 940476:tid 940641] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/777.php"] [unique_id "al4V3RjVYcQxwGpYwZnJHwAAACM"]
[Mon Jul 20 06:34:37.664442 2026] [security2:error] [pid 940476:tid 940641] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/777.php"] [unique_id "al4V3RjVYcQxwGpYwZnJHwAAACM"]
[Mon Jul 20 06:34:37.701061 2026] [security2:error] [pid 935758:tid 935912] [client 14.225.17.146:53674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4V3LcDxY_mIul-JSG3nQAAASA"], referer: http://careysheatingandcooling.com/Old
[Mon Jul 20 06:34:37.807961 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V3RjVYcQxwGpYwZnJJwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:37.808085 2026] [security2:error] [pid 940476:tid 940655] [client 77.110.127.138:50033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V3RjVYcQxwGpYwZnJJwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:38.016114 2026] [security2:error] [pid 940476:tid 940727] [client 39.48.81.23:56122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V3hjVYcQxwGpYwZnJOQAAAHk"]
[Mon Jul 20 06:34:38.016617 2026] [security2:error] [pid 940476:tid 940727] [client 39.48.81.23:56122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V3hjVYcQxwGpYwZnJOQAAAHk"]
[Mon Jul 20 06:34:38.041557 2026] [security2:error] [pid 940476:tid 940658] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ssixta.php"] [unique_id "al4V3hjVYcQxwGpYwZnJOgAAADQ"]
[Mon Jul 20 06:34:38.041765 2026] [security2:error] [pid 940476:tid 940658] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ssixta.php"] [unique_id "al4V3hjVYcQxwGpYwZnJOgAAADQ"]
[Mon Jul 20 06:34:38.110629 2026] [security2:error] [pid 935758:tid 936000] [client 103.153.183.69:52880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../.env"] [unique_id "al4V3rcDxY_mIul-JSG3zgAAAXg"], referer: https://www.google.com/
[Mon Jul 20 06:34:38.203761 2026] [security2:error] [pid 935758:tid 935972] [client 161.118.195.148:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V3rcDxY_mIul-JSG3zwAAAVw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:38.266185 2026] [security2:error] [pid 935758:tid 935784] [remote 194.164.192.228:36502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V3rcDxY_mIul-JSG30AABWhc"]
[Mon Jul 20 06:34:38.293742 2026] [security2:error] [pid 935758:tid 935940] [client 57.141.18.18:63136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2bcDxY_mIul-JSG3SwABPEA"]
[Mon Jul 20 06:34:38.321318 2026] [security2:error] [pid 940476:tid 940706] [client 197.186.66.42:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V3hjVYcQxwGpYwZnJRQAAAGQ"]
[Mon Jul 20 06:34:38.326889 2026] [security2:error] [pid 940476:tid 940706] [client 197.186.66.42:49806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V3hjVYcQxwGpYwZnJRQAAAGQ"]
[Mon Jul 20 06:34:38.386117 2026] [security2:error] [pid 935758:tid 935869] [remote 47.82.124.67:4675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2021/03/Hillside-Beach-Club-Turkey-Sailing-1200w.jpg"] [unique_id "al4V3rcDxY_mIul-JSG31AABhmw"]
[Mon Jul 20 06:34:38.463485 2026] [security2:error] [pid 940476:tid 940663] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/1c.php"] [unique_id "al4V3hjVYcQxwGpYwZnJUgAAADk"]
[Mon Jul 20 06:34:38.463562 2026] [security2:error] [pid 940476:tid 940663] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/1c.php"] [unique_id "al4V3hjVYcQxwGpYwZnJUgAAADk"]
[Mon Jul 20 06:34:38.465004 2026] [security2:error] [pid 935758:tid 935897] [client 14.225.17.146:52796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4V3bcDxY_mIul-JSG3rgAAARE"], referer: http://elitetax-mi.com/Old
[Mon Jul 20 06:34:38.488997 2026] [security2:error] [pid 935758:tid 935878] [remote 194.164.192.228:36502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V3rcDxY_mIul-JSG32AABYHU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:34:38.592943 2026] [security2:error] [pid 935758:tid 935933] [client 57.141.18.73:49446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2bcDxY_mIul-JSG3UgABNSQ"]
[Mon Jul 20 06:34:38.627485 2026] [security2:error] [pid 940476:tid 940501] [remote 160.187.68.132:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4V3hjVYcQxwGpYwZnJVwAABhg"]
[Mon Jul 20 06:34:38.660013 2026] [security2:error] [pid 940476:tid 940559] [remote 216.73.217.138:20001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4V3hjVYcQxwGpYwZnJWAAAHFI"]
[Mon Jul 20 06:34:38.741524 2026] [security2:error] [pid 935758:tid 935947] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/test2.php"] [unique_id "al4V3rcDxY_mIul-JSG35QAAAUM"]
[Mon Jul 20 06:34:38.741623 2026] [security2:error] [pid 935758:tid 935947] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/test2.php"] [unique_id "al4V3rcDxY_mIul-JSG35QAAAUM"]
[Mon Jul 20 06:34:38.774804 2026] [security2:error] [pid 935758:tid 935926] [client 161.118.195.148:56531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V3rcDxY_mIul-JSG35gAAAS4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:38.911541 2026] [security2:error] [pid 940476:tid 940642] [client 57.141.18.11:34520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2RjVYcQxwGpYwZnIKwAAJFA"]
[Mon Jul 20 06:34:39.065555 2026] [security2:error] [pid 940476:tid 940700] [client 216.73.217.138:20001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4V3hjVYcQxwGpYwZnJZwAAXlQ"]
[Mon Jul 20 06:34:39.111359 2026] [security2:error] [pid 940476:tid 940516] [remote 160.187.68.132:45986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4V3xjVYcQxwGpYwZnJcQAAbic"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:34:39.171909 2026] [security2:error] [pid 935758:tid 935890] [client 14.225.17.146:52792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4V3bcDxY_mIul-JSG3qQAAAQo"], referer: http://securingmemories.com/Old
[Mon Jul 20 06:34:39.206699 2026] [security2:error] [pid 940476:tid 940729] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/buy.php"] [unique_id "al4V3xjVYcQxwGpYwZnJdgAAAHs"]
[Mon Jul 20 06:34:39.206826 2026] [security2:error] [pid 940476:tid 940729] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/buy.php"] [unique_id "al4V3xjVYcQxwGpYwZnJdgAAAHs"]
[Mon Jul 20 06:34:39.269389 2026] [security2:error] [pid 935758:tid 935982] [client 82.224.86.139:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4V3bcDxY_mIul-JSG3vwAAAWY"], referer: https://areitoproducciones.com/instrumentos-virtuales/latin-percussion-vol-2/
[Mon Jul 20 06:34:39.349857 2026] [security2:error] [pid 940476:tid 940728] [client 161.118.195.148:56842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V3xjVYcQxwGpYwZnJfQAAAHo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:39.378661 2026] [security2:error] [pid 935758:tid 935934] [client 217.142.18.172:51098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V37cDxY_mIul-JSG39gAAATY"]
[Mon Jul 20 06:34:39.378820 2026] [security2:error] [pid 935758:tid 935934] [client 217.142.18.172:51098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V37cDxY_mIul-JSG39gAAATY"]
[Mon Jul 20 06:34:39.490727 2026] [security2:error] [pid 940476:tid 940669] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ssend.php"] [unique_id "al4V3xjVYcQxwGpYwZnJiwAAAD8"]
[Mon Jul 20 06:34:39.490814 2026] [security2:error] [pid 940476:tid 940669] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ssend.php"] [unique_id "al4V3xjVYcQxwGpYwZnJiwAAAD8"]
[Mon Jul 20 06:34:39.685347 2026] [security2:error] [pid 940476:tid 940675] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/item.php"] [unique_id "al4V3xjVYcQxwGpYwZnJnwAAAEU"]
[Mon Jul 20 06:34:39.685454 2026] [security2:error] [pid 940476:tid 940675] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/item.php"] [unique_id "al4V3xjVYcQxwGpYwZnJnwAAAEU"]
[Mon Jul 20 06:34:39.738065 2026] [security2:error] [pid 940476:tid 940637] [client 57.141.18.21:42414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2hjVYcQxwGpYwZnIdgAAHxA"]
[Mon Jul 20 06:34:39.779069 2026] [security2:error] [pid 935758:tid 935929] [client 65.49.1.38:26796] ModSecurity: Access denied with code 406 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "61"] [id "390616"] [rev "2"] [msg "Atomicorp.com WAF Rules: POST request must have a Content-Length header"] [severity "WARNING"] [hostname "96.125.175.127"] [uri "/"] [unique_id "al4V37cDxY_mIul-JSG4AwAAATE"]
[Mon Jul 20 06:34:39.813906 2026] [security2:error] [pid 940476:tid 940687] [client 57.141.18.22:28192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2hjVYcQxwGpYwZnIfQAAUSM"]
[Mon Jul 20 06:34:39.816356 2026] [security2:error] [pid 940476:tid 940671] [client 77.110.127.138:50041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V3xjVYcQxwGpYwZnJpwAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:39.915457 2026] [security2:error] [pid 940476:tid 940679] [client 14.225.17.146:61254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4V3xjVYcQxwGpYwZnJpgAAAEk"], referer: http://omrobuildingcenter.com/Old
[Mon Jul 20 06:34:39.926756 2026] [security2:error] [pid 940476:tid 940616] [client 161.118.195.148:57136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V3xjVYcQxwGpYwZnJsQAAAAo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:39.929273 2026] [security2:error] [pid 940476:tid 940649] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ss.php"] [unique_id "al4V3xjVYcQxwGpYwZnJswAAACs"]
[Mon Jul 20 06:34:39.929372 2026] [security2:error] [pid 940476:tid 940649] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ss.php"] [unique_id "al4V3xjVYcQxwGpYwZnJswAAACs"]
[Mon Jul 20 06:34:40.160090 2026] [security2:error] [pid 940476:tid 940700] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/hypo.php"] [unique_id "al4V4BjVYcQxwGpYwZnJyQAAAF4"]
[Mon Jul 20 06:34:40.160176 2026] [security2:error] [pid 940476:tid 940700] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/hypo.php"] [unique_id "al4V4BjVYcQxwGpYwZnJyQAAAF4"]
[Mon Jul 20 06:34:40.165127 2026] [security2:error] [pid 940476:tid 940666] [client 57.141.18.115:57222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2xjVYcQxwGpYwZnIlAAAPCY"]
[Mon Jul 20 06:34:40.171266 2026] [security2:error] [pid 940476:tid 940645] [client 18.142.226.106:15330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4V4BjVYcQxwGpYwZnJygAAACc"]
[Mon Jul 20 06:34:40.171342 2026] [security2:error] [pid 940476:tid 940645] [client 18.142.226.106:15330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4V4BjVYcQxwGpYwZnJygAAACc"]
[Mon Jul 20 06:34:40.312315 2026] [security2:error] [pid 940476:tid 940644] [client 57.141.18.62:44864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V2xjVYcQxwGpYwZnIowAAJik"]
[Mon Jul 20 06:34:40.354976 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:50022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ0gAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:40.355082 2026] [security2:error] [pid 940476:tid 940732] [client 77.110.127.138:50022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ0gAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:40.427881 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:49937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ2QAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:40.427977 2026] [security2:error] [pid 940476:tid 940688] [client 77.110.127.138:49937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ2QAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:40.500059 2026] [security2:error] [pid 940476:tid 940647] [client 161.118.195.148:57504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ3wAAACk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:40.662388 2026] [security2:error] [pid 940476:tid 940620] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/users.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ5gAAAA4"]
[Mon Jul 20 06:34:40.662492 2026] [security2:error] [pid 940476:tid 940620] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/users.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ5gAAAA4"]
[Mon Jul 20 06:34:40.769294 2026] [security2:error] [pid 940476:tid 940685] [client 171.61.165.146:26126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ7AAAAE8"]
[Mon Jul 20 06:34:40.769426 2026] [security2:error] [pid 940476:tid 940685] [client 171.61.165.146:26126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ7AAAAE8"]
[Mon Jul 20 06:34:40.846977 2026] [security2:error] [pid 935758:tid 935971] [client 57.141.18.82:55332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3LcDxY_mIul-JSG3kQABWzg"]
[Mon Jul 20 06:34:40.859044 2026] [security2:error] [pid 935758:tid 935938] [client 57.141.18.104:21528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3LcDxY_mIul-JSG3lQABOiY"]
[Mon Jul 20 06:34:40.879227 2026] [security2:error] [pid 940476:tid 940681] [client 98.159.234.160:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ8AAAAEs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:34:40.943574 2026] [security2:error] [pid 935758:tid 936011] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/177.php"] [unique_id "al4V4LcDxY_mIul-JSG4HgAAAYM"]
[Mon Jul 20 06:34:40.943697 2026] [security2:error] [pid 935758:tid 936011] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/177.php"] [unique_id "al4V4LcDxY_mIul-JSG4HgAAAYM"]
[Mon Jul 20 06:34:40.980080 2026] [security2:error] [pid 940476:tid 940689] [client 144.172.114.51:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.thescarystory.com"] [uri "/.env.old"] [unique_id "al4V4BjVYcQxwGpYwZnJ9QAAAFM"]
[Mon Jul 20 06:34:41.059497 2026] [security2:error] [pid 935758:tid 935844] [remote 47.82.124.67:4675] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2021/03/Hillside-Beach-Club-Turkey-Sailing-1200w.jpg"] [unique_id "al4V4bcDxY_mIul-JSG4KgABD1M"]
[Mon Jul 20 06:34:41.073075 2026] [security2:error] [pid 940476:tid 940697] [client 161.118.195.148:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V4RjVYcQxwGpYwZnKEgAAAFs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:41.179079 2026] [security2:error] [pid 935758:tid 936009] [client 104.234.53.70:49465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4V4bcDxY_mIul-JSG4MQAAAYE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:41.228460 2026] [security2:error] [pid 940476:tid 940626] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/config.php"] [unique_id "al4V4RjVYcQxwGpYwZnKIgAAABQ"]
[Mon Jul 20 06:34:41.228552 2026] [security2:error] [pid 940476:tid 940626] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/config.php"] [unique_id "al4V4RjVYcQxwGpYwZnKIgAAABQ"]
[Mon Jul 20 06:34:41.229926 2026] [security2:error] [pid 935758:tid 935952] [client 106.219.188.178:15812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V4bcDxY_mIul-JSG4MgAAAUg"]
[Mon Jul 20 06:34:41.230023 2026] [security2:error] [pid 935758:tid 935952] [client 106.219.188.178:15812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V4bcDxY_mIul-JSG4MgAAAUg"]
[Mon Jul 20 06:34:41.362446 2026] [security2:error] [pid 940476:tid 940587] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V4RjVYcQxwGpYwZnKJwAAEG4"]
[Mon Jul 20 06:34:41.362583 2026] [security2:error] [pid 940476:tid 940622] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V4RjVYcQxwGpYwZnKJwAAEG4"]
[Mon Jul 20 06:34:41.377131 2026] [security2:error] [pid 940476:tid 940610] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/gettest.php"] [unique_id "al4V4RjVYcQxwGpYwZnKKgAAAAQ"]
[Mon Jul 20 06:34:41.377232 2026] [security2:error] [pid 940476:tid 940610] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/gettest.php"] [unique_id "al4V4RjVYcQxwGpYwZnKKgAAAAQ"]
[Mon Jul 20 06:34:41.405130 2026] [security2:error] [pid 935758:tid 935917] [client 14.225.17.146:52434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4V4LcDxY_mIul-JSG4DgAAASU"], referer: http://whiteoutcb.com/Old
[Mon Jul 20 06:34:41.526922 2026] [security2:error] [pid 940476:tid 940627] [client 74.7.228.47:52102] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mrbambooplus.com"] [uri "/robots.txt"] [unique_id "al4V4RjVYcQxwGpYwZnKRQAAABU"]
[Mon Jul 20 06:34:41.554205 2026] [security2:error] [pid 935758:tid 935891] [client 14.225.17.146:65243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4V4LcDxY_mIul-JSG4GAAAAQs"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/Old
[Mon Jul 20 06:34:41.611437 2026] [security2:error] [pid 940476:tid 940654] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/min.php"] [unique_id "al4V4RjVYcQxwGpYwZnKUgAAADA"]
[Mon Jul 20 06:34:41.611538 2026] [security2:error] [pid 940476:tid 940654] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/min.php"] [unique_id "al4V4RjVYcQxwGpYwZnKUgAAADA"]
[Mon Jul 20 06:34:41.646669 2026] [security2:error] [pid 940476:tid 940703] [client 161.118.195.148:58139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V4RjVYcQxwGpYwZnKVAAAAGE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:41.713227 2026] [security2:error] [pid 940476:tid 940694] [client 57.141.18.81:47984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3RjVYcQxwGpYwZnJAAAAWAQ"]
[Mon Jul 20 06:34:41.883239 2026] [security2:error] [pid 940476:tid 940642] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "al4V4RjVYcQxwGpYwZnKZwAAACQ"]
[Mon Jul 20 06:34:41.883324 2026] [security2:error] [pid 940476:tid 940642] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/3PJcpMFsD8B.php"] [unique_id "al4V4RjVYcQxwGpYwZnKZwAAACQ"]
[Mon Jul 20 06:34:41.925271 2026] [security2:error] [pid 940476:tid 940677] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mrbambooplus.com"] [uri "/index.php"] [unique_id "al4V4RjVYcQxwGpYwZnKWAAAAEc"], referer: http://www.mrbambooplus.com/robots.txt
[Mon Jul 20 06:34:41.925299 2026] [security2:error] [pid 940476:tid 940677] [client 74.7.228.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mrbambooplus.com"] [uri "/index.php"] [unique_id "al4V4RjVYcQxwGpYwZnKWAAAAEc"], referer: http://www.mrbambooplus.com/robots.txt
[Mon Jul 20 06:34:41.936494 2026] [security2:error] [pid 940476:tid 940629] [client 74.7.228.47:38870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mrbambooplus.com"] [uri "/robots.txt"] [unique_id "al4V4RjVYcQxwGpYwZnKVQAAF1I"], referer: http://www.mrbambooplus.com/robots.txt
[Mon Jul 20 06:34:41.988261 2026] [security2:error] [pid 940476:tid 940618] [client 74.208.214.194:33314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4V4RjVYcQxwGpYwZnKcAAAAAw"]
[Mon Jul 20 06:34:42.051337 2026] [proxy:error] [pid 940476:tid 940702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:42.051390 2026] [proxy_http:error] [pid 940476:tid 940702] [client 195.96.139.183:36901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:42.051975 2026] [proxy:error] [pid 940476:tid 940702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:42.052004 2026] [proxy_http:error] [pid 940476:tid 940702] [client 195.96.139.183:36901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:42.071797 2026] [security2:error] [pid 940476:tid 940649] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/dvjul.php"] [unique_id "al4V4hjVYcQxwGpYwZnKfgAAACs"]
[Mon Jul 20 06:34:42.071907 2026] [security2:error] [pid 940476:tid 940649] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/dvjul.php"] [unique_id "al4V4hjVYcQxwGpYwZnKfgAAACs"]
[Mon Jul 20 06:34:42.080573 2026] [security2:error] [pid 935758:tid 935900] [client 57.141.18.102:55608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3bcDxY_mIul-JSG3vAABFBM"]
[Mon Jul 20 06:34:42.220053 2026] [security2:error] [pid 940476:tid 940628] [client 161.118.195.148:58442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V4hjVYcQxwGpYwZnKiQAAABY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:42.288936 2026] [security2:error] [pid 940476:tid 940719] [client 74.7.228.47:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4V4hjVYcQxwGpYwZnKggAAAHE"], referer: https://www.mrbambooplus.com/robots.txt
[Mon Jul 20 06:34:42.317949 2026] [security2:error] [pid 940476:tid 940704] [client 74.7.228.47:38876] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mrbambooplus.com"] [uri "/robots.txt"] [unique_id "al4V4hjVYcQxwGpYwZnKewAAYhs"], referer: https://www.mrbambooplus.com/robots.txt
[Mon Jul 20 06:34:42.325873 2026] [security2:error] [pid 935758:tid 935933] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/biufile.php"] [unique_id "al4V4rcDxY_mIul-JSG4WgAAATU"]
[Mon Jul 20 06:34:42.326018 2026] [security2:error] [pid 935758:tid 935933] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/biufile.php"] [unique_id "al4V4rcDxY_mIul-JSG4WgAAATU"]
[Mon Jul 20 06:34:42.335023 2026] [security2:error] [pid 940476:tid 940650] [client 187.108.85.186:54419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V4hjVYcQxwGpYwZnKlAAAACw"]
[Mon Jul 20 06:34:42.335139 2026] [security2:error] [pid 940476:tid 940650] [client 187.108.85.186:54419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V4hjVYcQxwGpYwZnKlAAAACw"]
[Mon Jul 20 06:34:42.421029 2026] [security2:error] [pid 935758:tid 935909] [client 57.141.18.114:44844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3bcDxY_mIul-JSG3xwABHU4"]
[Mon Jul 20 06:34:42.468506 2026] [security2:error] [pid 935758:tid 935964] [client 57.141.18.10:30530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3bcDxY_mIul-JSG3ywABVH8"]
[Mon Jul 20 06:34:42.516561 2026] [security2:error] [pid 940476:tid 940652] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/av.php"] [unique_id "al4V4hjVYcQxwGpYwZnKnQAAAC4"]
[Mon Jul 20 06:34:42.516698 2026] [security2:error] [pid 940476:tid 940652] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/av.php"] [unique_id "al4V4hjVYcQxwGpYwZnKnQAAAC4"]
[Mon Jul 20 06:34:42.651437 2026] [security2:error] [pid 940476:tid 940698] [client 57.141.18.76:45892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3hjVYcQxwGpYwZnJPAAAXC0"]
[Mon Jul 20 06:34:42.666911 2026] [security2:error] [pid 935758:tid 935990] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/coffexium.php"] [unique_id "al4V4rcDxY_mIul-JSG4aAAAAW4"]
[Mon Jul 20 06:34:42.666999 2026] [security2:error] [pid 935758:tid 935990] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/coffexium.php"] [unique_id "al4V4rcDxY_mIul-JSG4aAAAAW4"]
[Mon Jul 20 06:34:42.792471 2026] [security2:error] [pid 940476:tid 940712] [client 161.118.195.148:58778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V4hjVYcQxwGpYwZnKsAAAAGo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:42.799324 2026] [security2:error] [pid 940476:tid 940638] [client 14.225.17.146:61250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4V4RjVYcQxwGpYwZnKTgAAACA"]
[Mon Jul 20 06:34:42.802443 2026] [security2:error] [pid 940476:tid 940681] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/app.php"] [unique_id "al4V4hjVYcQxwGpYwZnKsgAAAEs"]
[Mon Jul 20 06:34:42.802553 2026] [security2:error] [pid 940476:tid 940681] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/app.php"] [unique_id "al4V4hjVYcQxwGpYwZnKsgAAAEs"]
[Mon Jul 20 06:34:42.960385 2026] [security2:error] [pid 935758:tid 935904] [client 103.125.179.95:56929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V4rcDxY_mIul-JSG4bQAAARg"]
[Mon Jul 20 06:34:42.962191 2026] [security2:error] [pid 935758:tid 935904] [client 103.125.179.95:56929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V4rcDxY_mIul-JSG4bQAAARg"]
[Mon Jul 20 06:34:42.963716 2026] [security2:error] [pid 940476:tid 940680] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/core.php"] [unique_id "al4V4hjVYcQxwGpYwZnKugAAAEo"]
[Mon Jul 20 06:34:42.963819 2026] [security2:error] [pid 940476:tid 940680] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/core.php"] [unique_id "al4V4hjVYcQxwGpYwZnKugAAAEo"]
[Mon Jul 20 06:34:43.075734 2026] [security2:error] [pid 935758:tid 935993] [client 103.153.183.69:52880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../var/www/html/.env"] [unique_id "al4V47cDxY_mIul-JSG4dwAAAXE"], referer: https://www.reddit.com/
[Mon Jul 20 06:34:43.091168 2026] [security2:error] [pid 940476:tid 940682] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4V4hjVYcQxwGpYwZnKtAAATEo"], referer: http://assasalnazaha.com/Old
[Mon Jul 20 06:34:43.211666 2026] [security2:error] [pid 940476:tid 940618] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/header.php"] [unique_id "al4V4xjVYcQxwGpYwZnKwwAAAAw"]
[Mon Jul 20 06:34:43.211803 2026] [security2:error] [pid 940476:tid 940618] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/header.php"] [unique_id "al4V4xjVYcQxwGpYwZnKwwAAAAw"]
[Mon Jul 20 06:34:43.305434 2026] [security2:error] [pid 940476:tid 940647] [client 14.225.17.146:61294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4V4xjVYcQxwGpYwZnKvwAAACk"], referer: http://adirondackengineering.com/Old
[Mon Jul 20 06:34:43.335074 2026] [security2:error] [pid 940476:tid 940656] [client 144.172.104.62:34142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4V4hjVYcQxwGpYwZnKqQAAADI"]
[Mon Jul 20 06:34:43.384491 2026] [security2:error] [pid 940476:tid 940700] [client 161.118.195.148:59133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V4xjVYcQxwGpYwZnKzQAAAF4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:43.397044 2026] [security2:error] [pid 935758:tid 935917] [client 77.110.127.138:50065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V47cDxY_mIul-JSG4hQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:43.427727 2026] [security2:error] [pid 940476:tid 940636] [client 144.172.104.62:34134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4V4hjVYcQxwGpYwZnKtgAAAB4"]
[Mon Jul 20 06:34:43.537756 2026] [security2:error] [pid 935758:tid 935951] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/als.php"] [unique_id "al4V47cDxY_mIul-JSG4jAAAAUc"]
[Mon Jul 20 06:34:43.537878 2026] [security2:error] [pid 935758:tid 935951] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/als.php"] [unique_id "al4V47cDxY_mIul-JSG4jAAAAUc"]
[Mon Jul 20 06:34:43.613736 2026] [security2:error] [pid 940476:tid 940614] [client 57.141.18.6:43538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V3xjVYcQxwGpYwZnJggAACAM"]
[Mon Jul 20 06:34:43.802942 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/simple.php"] [unique_id "al4V4xjVYcQxwGpYwZnK7AAAAHg"]
[Mon Jul 20 06:34:43.803058 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/simple.php"] [unique_id "al4V4xjVYcQxwGpYwZnK7AAAAHg"]
[Mon Jul 20 06:34:43.803134 2026] [security2:error] [pid 940476:tid 940581] [remote 57.141.18.22:62200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4V4xjVYcQxwGpYwZnK7QAADWg"]
[Mon Jul 20 06:34:43.809423 2026] [security2:error] [pid 935758:tid 935925] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V47cDxY_mIul-JSG4jwAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:43.964164 2026] [security2:error] [pid 940476:tid 940714] [client 161.118.195.148:59464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V4xjVYcQxwGpYwZnK8wAAAGw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:43.975510 2026] [security2:error] [pid 940476:tid 940725] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/init.php"] [unique_id "al4V4xjVYcQxwGpYwZnK9AAAAHc"]
[Mon Jul 20 06:34:43.975583 2026] [security2:error] [pid 940476:tid 940725] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/init.php"] [unique_id "al4V4xjVYcQxwGpYwZnK9AAAAHc"]
[Mon Jul 20 06:34:44.037488 2026] [security2:error] [pid 935758:tid 935954] [client 147.182.149.91:51422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.karmaminds.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4V47cDxY_mIul-JSG4kwAAAUo"]
[Mon Jul 20 06:34:44.162639 2026] [security2:error] [pid 935758:tid 935840] [remote 152.228.213.32:38582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4V5LcDxY_mIul-JSG4mAABOE8"]
[Mon Jul 20 06:34:44.171255 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:50068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V5BjVYcQxwGpYwZnK_wAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:44.171336 2026] [security2:error] [pid 940476:tid 940722] [client 77.110.127.138:50068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V5BjVYcQxwGpYwZnK_wAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:44.256640 2026] [security2:error] [pid 935758:tid 935941] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/fpwch.php"] [unique_id "al4V5LcDxY_mIul-JSG4mgAAAT0"]
[Mon Jul 20 06:34:44.256735 2026] [security2:error] [pid 935758:tid 935941] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/fpwch.php"] [unique_id "al4V5LcDxY_mIul-JSG4mgAAAT0"]
[Mon Jul 20 06:34:44.323224 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:50072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V5BjVYcQxwGpYwZnLCAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:44.323348 2026] [security2:error] [pid 940476:tid 940728] [client 77.110.127.138:50072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V5BjVYcQxwGpYwZnLCAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:44.347881 2026] [security2:error] [pid 935758:tid 935864] [remote 152.228.213.32:38582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4V5LcDxY_mIul-JSG4nQABMmc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:34:44.441064 2026] [security2:error] [pid 940476:tid 940681] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/domvf.php"] [unique_id "al4V5BjVYcQxwGpYwZnLDgAAAEs"]
[Mon Jul 20 06:34:44.441173 2026] [security2:error] [pid 940476:tid 940681] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/domvf.php"] [unique_id "al4V5BjVYcQxwGpYwZnLDgAAAEs"]
[Mon Jul 20 06:34:44.529815 2026] [security2:error] [pid 935758:tid 935965] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V5LcDxY_mIul-JSG4ngAAAVU"]
[Mon Jul 20 06:34:44.540344 2026] [security2:error] [pid 940476:tid 940655] [client 161.118.195.148:59778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V5BjVYcQxwGpYwZnLFwAAADE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:44.653005 2026] [security2:error] [pid 940476:tid 940729] [client 57.141.18.0:53344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V4BjVYcQxwGpYwZnJzgAAewk"]
[Mon Jul 20 06:34:44.653009 2026] [security2:error] [pid 940476:tid 940705] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp.php"] [unique_id "al4V5BjVYcQxwGpYwZnLGwAAAGM"]
[Mon Jul 20 06:34:44.653170 2026] [security2:error] [pid 940476:tid 940705] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp.php"] [unique_id "al4V5BjVYcQxwGpYwZnLGwAAAGM"]
[Mon Jul 20 06:34:44.788291 2026] [security2:error] [pid 940476:tid 940616] [client 57.141.18.22:43192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V4BjVYcQxwGpYwZnJ4gAAChE"]
[Mon Jul 20 06:34:44.846075 2026] [security2:error] [pid 935758:tid 935963] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/class.php"] [unique_id "al4V5LcDxY_mIul-JSG4rgAAAVM"]
[Mon Jul 20 06:34:44.846193 2026] [security2:error] [pid 935758:tid 935963] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/class.php"] [unique_id "al4V5LcDxY_mIul-JSG4rgAAAVM"]
[Mon Jul 20 06:34:44.861688 2026] [security2:error] [pid 940476:tid 940575] [remote 188.166.241.141:50178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4V5BjVYcQxwGpYwZnLKgAAVWI"]
[Mon Jul 20 06:34:44.892880 2026] [security2:error] [pid 940476:tid 940625] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4V5BjVYcQxwGpYwZnLIQAAABM"]
[Mon Jul 20 06:34:44.955782 2026] [security2:error] [pid 940476:tid 940613] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/echkm.php"] [unique_id "al4V5BjVYcQxwGpYwZnLMAAAAAc"]
[Mon Jul 20 06:34:44.955900 2026] [security2:error] [pid 940476:tid 940613] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/echkm.php"] [unique_id "al4V5BjVYcQxwGpYwZnLMAAAAAc"]
[Mon Jul 20 06:34:44.986793 2026] [security2:error] [pid 935758:tid 935995] [client 103.153.183.69:52880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../var/www/.env"] [unique_id "al4V5LcDxY_mIul-JSG4sQAAAXM"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:34:45.113368 2026] [security2:error] [pid 935758:tid 936009] [client 161.118.195.148:60140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V5bcDxY_mIul-JSG4swAAAYE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:45.231608 2026] [security2:error] [pid 940476:tid 940485] [remote 217.61.143.92:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V5RjVYcQxwGpYwZnLQAAAPAg"]
[Mon Jul 20 06:34:45.253507 2026] [security2:error] [pid 940476:tid 940495] [remote 188.166.241.141:50178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4V5RjVYcQxwGpYwZnLQgAAWRI"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 06:34:45.332631 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/lib.php"] [unique_id "al4V5RjVYcQxwGpYwZnLRAAAAHg"]
[Mon Jul 20 06:34:45.332761 2026] [security2:error] [pid 940476:tid 940726] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/lib.php"] [unique_id "al4V5RjVYcQxwGpYwZnLRAAAAHg"]
[Mon Jul 20 06:34:45.445382 2026] [security2:error] [pid 935758:tid 935940] [client 223.185.13.213:21361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V5bcDxY_mIul-JSG4xAAAATw"]
[Mon Jul 20 06:34:45.445473 2026] [security2:error] [pid 935758:tid 935940] [client 223.185.13.213:21361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V5bcDxY_mIul-JSG4xAAAATw"]
[Mon Jul 20 06:34:45.477926 2026] [security2:error] [pid 940476:tid 940602] [remote 217.61.143.92:39956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V5RjVYcQxwGpYwZnLTQAAAn0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:34:45.522394 2026] [security2:error] [pid 940476:tid 940647] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/login.php"] [unique_id "al4V5RjVYcQxwGpYwZnLWQAAACk"]
[Mon Jul 20 06:34:45.522484 2026] [security2:error] [pid 940476:tid 940647] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/login.php"] [unique_id "al4V5RjVYcQxwGpYwZnLWQAAACk"]
[Mon Jul 20 06:34:45.686859 2026] [security2:error] [pid 940476:tid 940717] [client 161.118.195.148:60480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V5RjVYcQxwGpYwZnLXwAAAG8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:45.687543 2026] [security2:error] [pid 940476:tid 940633] [client 57.141.18.25:54620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V4RjVYcQxwGpYwZnKOAAAG3g"]
[Mon Jul 20 06:34:45.689132 2026] [security2:error] [pid 935758:tid 935968] [client 103.153.183.69:52880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//....//....//var/www/html/wp-config.php"] [unique_id "al4V5bcDxY_mIul-JSG4zgAAAVg"], referer: https://www.facebook.com/
[Mon Jul 20 06:34:45.817339 2026] [security2:error] [pid 940476:tid 940628] [client 50.116.65.227:59150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4V5RjVYcQxwGpYwZnLagAAABY"]
[Mon Jul 20 06:34:45.826322 2026] [security2:error] [pid 940476:tid 940678] [client 50.116.65.227:59166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4V5RjVYcQxwGpYwZnLawAAAEg"]
[Mon Jul 20 06:34:45.988134 2026] [security2:error] [pid 935758:tid 935967] [client 112.208.70.94:45606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V5bcDxY_mIul-JSG41AAAAVc"]
[Mon Jul 20 06:34:45.988264 2026] [security2:error] [pid 935758:tid 935967] [client 112.208.70.94:45606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V5bcDxY_mIul-JSG41AAAAVc"]
[Mon Jul 20 06:34:46.115938 2026] [security2:error] [pid 940476:tid 940706] [client 57.141.18.32:49062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V4RjVYcQxwGpYwZnKbQAAZEg"]
[Mon Jul 20 06:34:46.134068 2026] [security2:error] [pid 940476:tid 940709] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/sites.php"] [unique_id "al4V5hjVYcQxwGpYwZnLfgAAAGc"]
[Mon Jul 20 06:34:46.134180 2026] [security2:error] [pid 940476:tid 940709] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/sites.php"] [unique_id "al4V5hjVYcQxwGpYwZnLfgAAAGc"]
[Mon Jul 20 06:34:46.262832 2026] [security2:error] [pid 935758:tid 935918] [client 161.118.195.148:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V5rcDxY_mIul-JSG43gAAASY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:46.306360 2026] [security2:error] [pid 935758:tid 935890] [client 44.240.37.43:54338] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thecreole.com"] [uri "/index.cgi"] [unique_id "al4V5rcDxY_mIul-JSG43AAAAQo"]
[Mon Jul 20 06:34:46.592003 2026] [security2:error] [pid 940476:tid 940633] [client 44.240.37.43:54356] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4V5hjVYcQxwGpYwZnLkAAAABs"], referer: http://www.google.com/images/url
[Mon Jul 20 06:34:46.668093 2026] [security2:error] [pid 940476:tid 940668] [client 77.110.127.138:50091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V5hjVYcQxwGpYwZnLmwAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:46.693223 2026] [security2:error] [pid 940476:tid 940665] [client 44.240.37.43:54364] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "TRACE" at REQUEST_METHOD. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "52"] [id "340002"] [rev "3"] [msg "Atomicorp.com WAF Rules: TRACE/TRACK method denied"] [severity "CRITICAL"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4V5hjVYcQxwGpYwZnLngAAADs"]
[Mon Jul 20 06:34:46.823816 2026] [security2:error] [pid 940476:tid 940624] [client 77.110.127.138:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V5hjVYcQxwGpYwZnLogAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:46.823916 2026] [security2:error] [pid 940476:tid 940624] [client 77.110.127.138:50092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V5hjVYcQxwGpYwZnLogAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:46.835744 2026] [security2:error] [pid 940476:tid 940709] [client 161.118.195.148:61140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V5hjVYcQxwGpYwZnLpAAAAGc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:47.083439 2026] [security2:error] [pid 935758:tid 935919] [client 57.141.18.94:20596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V4rcDxY_mIul-JSG4bwABJ2A"]
[Mon Jul 20 06:34:47.182943 2026] [security2:error] [pid 935758:tid 935940] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/a2.php"] [unique_id "al4V57cDxY_mIul-JSG48gAAATw"]
[Mon Jul 20 06:34:47.183051 2026] [security2:error] [pid 935758:tid 935940] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/a2.php"] [unique_id "al4V57cDxY_mIul-JSG48gAAATw"]
[Mon Jul 20 06:34:47.256405 2026] [security2:error] [pid 940476:tid 940645] [client 14.225.17.146:52391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4V5RjVYcQxwGpYwZnLXQAAACc"], referer: http://margaretspeckogawa.com/Old
[Mon Jul 20 06:34:47.331592 2026] [security2:error] [pid 935758:tid 935926] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/d61.php"] [unique_id "al4V57cDxY_mIul-JSG4-QAAAS4"]
[Mon Jul 20 06:34:47.331671 2026] [security2:error] [pid 935758:tid 935926] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/d61.php"] [unique_id "al4V57cDxY_mIul-JSG4-QAAAS4"]
[Mon Jul 20 06:34:47.424274 2026] [security2:error] [pid 935758:tid 935902] [client 161.118.195.148:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V57cDxY_mIul-JSG4-wAAARY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:47.756898 2026] [security2:error] [pid 940476:tid 940682] [client 104.234.53.58:63623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4V5xjVYcQxwGpYwZnL0QAAAEw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:47.790002 2026] [security2:error] [pid 935758:tid 935973] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/info.php"] [unique_id "al4V57cDxY_mIul-JSG5AwAAAV0"]
[Mon Jul 20 06:34:47.790083 2026] [security2:error] [pid 935758:tid 935973] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/info.php"] [unique_id "al4V57cDxY_mIul-JSG5AwAAAV0"]
[Mon Jul 20 06:34:47.999985 2026] [security2:error] [pid 940476:tid 940683] [client 161.118.195.148:61882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V5xjVYcQxwGpYwZnL5AAAAE0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:48.011083 2026] [security2:error] [pid 940476:tid 940625] [client 104.234.53.58:63623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4V6BjVYcQxwGpYwZnL5QAAABM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:48.046112 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:50097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V6BjVYcQxwGpYwZnL6QAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:48.046191 2026] [security2:error] [pid 940476:tid 940648] [client 77.110.127.138:50097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V6BjVYcQxwGpYwZnL6QAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:48.047601 2026] [security2:error] [pid 940476:tid 940607] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/11.php"] [unique_id "al4V6BjVYcQxwGpYwZnL6gAAAAE"]
[Mon Jul 20 06:34:48.047670 2026] [security2:error] [pid 940476:tid 940607] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/11.php"] [unique_id "al4V6BjVYcQxwGpYwZnL6gAAAAE"]
[Mon Jul 20 06:34:48.124746 2026] [security2:error] [pid 935758:tid 935961] [client 171.60.139.123:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V6LcDxY_mIul-JSG5CgAAAVE"]
[Mon Jul 20 06:34:48.124874 2026] [security2:error] [pid 935758:tid 935961] [client 171.60.139.123:50286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V6LcDxY_mIul-JSG5CgAAAVE"]
[Mon Jul 20 06:34:48.403315 2026] [security2:error] [pid 940476:tid 940634] [client 223.237.130.40:53022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4V6BjVYcQxwGpYwZnL8wAAABw"]
[Mon Jul 20 06:34:48.407332 2026] [security2:error] [pid 940476:tid 940666] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/v2.php"] [unique_id "al4V6BjVYcQxwGpYwZnMAQAAADw"]
[Mon Jul 20 06:34:48.407409 2026] [security2:error] [pid 940476:tid 940666] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/v2.php"] [unique_id "al4V6BjVYcQxwGpYwZnMAQAAADw"]
[Mon Jul 20 06:34:48.419762 2026] [security2:error] [pid 940476:tid 940652] [client 197.186.66.42:50288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V6BjVYcQxwGpYwZnMAwAAAC4"]
[Mon Jul 20 06:34:48.438559 2026] [security2:error] [pid 940476:tid 940652] [client 197.186.66.42:50288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V6BjVYcQxwGpYwZnMAwAAAC4"]
[Mon Jul 20 06:34:48.502345 2026] [security2:error] [pid 935758:tid 935905] [client 57.141.18.76:36948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V5LcDxY_mIul-JSG4nwABGSo"]
[Mon Jul 20 06:34:48.573045 2026] [security2:error] [pid 940476:tid 940706] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4V6BjVYcQxwGpYwZnL6wAAZCM"], referer: http://ali-alghanim.net/Old
[Mon Jul 20 06:34:48.577232 2026] [security2:error] [pid 940476:tid 940641] [client 161.118.195.148:62256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V6BjVYcQxwGpYwZnMDAAAACM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:48.674902 2026] [security2:error] [pid 940476:tid 940618] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/panel.php"] [unique_id "al4V6BjVYcQxwGpYwZnMFgAAAAw"]
[Mon Jul 20 06:34:48.674978 2026] [security2:error] [pid 940476:tid 940618] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/panel.php"] [unique_id "al4V6BjVYcQxwGpYwZnMFgAAAAw"]
[Mon Jul 20 06:34:48.771469 2026] [security2:error] [pid 940476:tid 940672] [client 13.229.83.156:35138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4V6BjVYcQxwGpYwZnMIAAAAEI"]
[Mon Jul 20 06:34:48.771595 2026] [security2:error] [pid 940476:tid 940672] [client 13.229.83.156:35138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4V6BjVYcQxwGpYwZnMIAAAAEI"]
[Mon Jul 20 06:34:48.869994 2026] [security2:error] [pid 940476:tid 940727] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/dex.php"] [unique_id "al4V6BjVYcQxwGpYwZnMKQAAAHk"]
[Mon Jul 20 06:34:48.870120 2026] [security2:error] [pid 940476:tid 940727] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/dex.php"] [unique_id "al4V6BjVYcQxwGpYwZnMKQAAAHk"]
[Mon Jul 20 06:34:48.931531 2026] [security2:error] [pid 935758:tid 935941] [client 39.48.81.23:56629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V6LcDxY_mIul-JSG5EwAAAT0"]
[Mon Jul 20 06:34:48.932671 2026] [security2:error] [pid 935758:tid 935941] [client 39.48.81.23:56629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V6LcDxY_mIul-JSG5EwAAAT0"]
[Mon Jul 20 06:34:49.062211 2026] [security2:error] [pid 935758:tid 935901] [client 20.104.96.117:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "thescarystory.com"] [uri "/1.php"] [unique_id "al4V6bcDxY_mIul-JSG5GQAAARU"]
[Mon Jul 20 06:34:49.062310 2026] [security2:error] [pid 935758:tid 935901] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/1.php"] [unique_id "al4V6bcDxY_mIul-JSG5GQAAARU"]
[Mon Jul 20 06:34:49.062386 2026] [security2:error] [pid 935758:tid 935901] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/1.php"] [unique_id "al4V6bcDxY_mIul-JSG5GQAAARU"]
[Mon Jul 20 06:34:49.147420 2026] [security2:error] [pid 940476:tid 940678] [client 158.173.166.181:60907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4V6RjVYcQxwGpYwZnMMwAAAEg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:34:49.151341 2026] [security2:error] [pid 935758:tid 935890] [client 161.118.195.148:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V6bcDxY_mIul-JSG5HQAAAQo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:49.331148 2026] [security2:error] [pid 935758:tid 936017] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/ms.php"] [unique_id "al4V6bcDxY_mIul-JSG5LAAAAYk"]
[Mon Jul 20 06:34:49.331260 2026] [security2:error] [pid 935758:tid 936017] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/ms.php"] [unique_id "al4V6bcDxY_mIul-JSG5LAAAAYk"]
[Mon Jul 20 06:34:49.353039 2026] [security2:error] [pid 935758:tid 935778] [remote 72.167.132.114:41322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V6bcDxY_mIul-JSG5LgABUBE"]
[Mon Jul 20 06:34:49.392731 2026] [security2:error] [pid 935758:tid 935916] [client 57.141.18.116:58610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V5bcDxY_mIul-JSG4wwABJGo"]
[Mon Jul 20 06:34:49.435944 2026] [security2:error] [pid 935758:tid 935830] [remote 124.55.178.99:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4V6bcDxY_mIul-JSG5NgABSUU"]
[Mon Jul 20 06:34:49.636641 2026] [security2:error] [pid 935758:tid 935879] [remote 72.167.132.114:41322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V6bcDxY_mIul-JSG5UwABeXY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:34:49.646398 2026] [security2:error] [pid 935758:tid 935918] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4V6bcDxY_mIul-JSG5WQAAASY"]
[Mon Jul 20 06:34:49.714575 2026] [security2:error] [pid 940476:tid 940540] [remote 57.141.18.13:49894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V5RjVYcQxwGpYwZnLXgAAGT8"]
[Mon Jul 20 06:34:49.723716 2026] [security2:error] [pid 935758:tid 935973] [client 161.118.195.148:62978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V6bcDxY_mIul-JSG5XwAAAV0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:49.768207 2026] [security2:error] [pid 935758:tid 935767] [remote 194.164.192.228:34366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4V6bcDxY_mIul-JSG5YQABGAY"]
[Mon Jul 20 06:34:49.824869 2026] [security2:error] [pid 935758:tid 935922] [client 217.142.18.172:24248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V6bcDxY_mIul-JSG5ZQAAASo"]
[Mon Jul 20 06:34:49.836016 2026] [security2:error] [pid 935758:tid 935922] [client 217.142.18.172:24248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V6bcDxY_mIul-JSG5ZQAAASo"]
[Mon Jul 20 06:34:49.860219 2026] [autoindex:error] [pid 935758:tid 936016] [client 20.104.96.117:0] AH01276: Cannot serve directory /home4/guitaram/public_html/thescarystory/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:34:49.860685 2026] [security2:error] [pid 935758:tid 936016] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "thescarystory.com"] [uri "/cgi-sys/403.html"] [unique_id "al4V6bcDxY_mIul-JSG5YwAAAYg"]
[Mon Jul 20 06:34:49.866682 2026] [security2:error] [pid 935758:tid 935860] [remote 124.55.178.99:58602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4V6bcDxY_mIul-JSG5ZwABFGM"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:34:49.931511 2026] [security2:error] [pid 935758:tid 935916] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/memberfuns.php"] [unique_id "al4V6bcDxY_mIul-JSG5cAAAASQ"]
[Mon Jul 20 06:34:49.931596 2026] [security2:error] [pid 935758:tid 935916] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/memberfuns.php"] [unique_id "al4V6bcDxY_mIul-JSG5cAAAASQ"]
[Mon Jul 20 06:34:50.054390 2026] [security2:error] [pid 935758:tid 935834] [remote 194.164.192.228:34366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5fAABVUk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:34:50.137505 2026] [security2:error] [pid 935758:tid 935931] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/0.php"] [unique_id "al4V6rcDxY_mIul-JSG5hQAAATM"]
[Mon Jul 20 06:34:50.137607 2026] [security2:error] [pid 935758:tid 935931] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/0.php"] [unique_id "al4V6rcDxY_mIul-JSG5hQAAATM"]
[Mon Jul 20 06:34:50.171338 2026] [security2:error] [pid 935758:tid 935902] [client 157.66.56.117:55360] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5iQAAARY"]
[Mon Jul 20 06:34:50.171420 2026] [security2:error] [pid 935758:tid 935902] [client 157.66.56.117:55360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5iQAAARY"]
[Mon Jul 20 06:34:50.205676 2026] [security2:error] [pid 935758:tid 935955] [client 104.234.53.71:51877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4V6rcDxY_mIul-JSG5jQAAAUs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:50.266987 2026] [security2:error] [pid 935758:tid 935779] [remote 124.55.178.99:42276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5kgABNBI"]
[Mon Jul 20 06:34:50.296330 2026] [security2:error] [pid 935758:tid 935988] [client 161.118.195.148:63319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5lAAAAWw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:50.490679 2026] [security2:error] [pid 935758:tid 936006] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/BDKR28.php"] [unique_id "al4V6rcDxY_mIul-JSG5ogAAAX4"]
[Mon Jul 20 06:34:50.490786 2026] [security2:error] [pid 935758:tid 936006] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/BDKR28.php"] [unique_id "al4V6rcDxY_mIul-JSG5ogAAAX4"]
[Mon Jul 20 06:34:50.494979 2026] [security2:error] [pid 935758:tid 935970] [client 57.141.18.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5mAAAAVo"]
[Mon Jul 20 06:34:50.685840 2026] [security2:error] [pid 935758:tid 935842] [remote 124.55.178.99:42276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5sAABUFE"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:34:50.704594 2026] [security2:error] [pid 935758:tid 935928] [client 77.110.127.138:50112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5rAAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:50.859628 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:50114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V6rcDxY_mIul-JSG5vAAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:50.859768 2026] [security2:error] [pid 935758:tid 935993] [client 77.110.127.138:50114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V6rcDxY_mIul-JSG5vAAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:50.868198 2026] [security2:error] [pid 935758:tid 936000] [client 161.118.195.148:63647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5vgAAAXg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:50.869545 2026] [security2:error] [pid 935758:tid 935931] [client 104.207.63.190:42841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4V6rcDxY_mIul-JSG5uQAAATM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:51.068450 2026] [security2:error] [pid 935758:tid 936007] [client 57.141.18.91:36996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V5rcDxY_mIul-JSG47AABf1w"]
[Mon Jul 20 06:34:51.201929 2026] [security2:error] [pid 935758:tid 935927] [client 14.225.17.146:55318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5kwAAAS8"], referer: http://walkingandtalking.net/Old
[Mon Jul 20 06:34:51.281976 2026] [security2:error] [pid 935758:tid 935978] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/green1.php"] [unique_id "al4V67cDxY_mIul-JSG54wAAAWI"]
[Mon Jul 20 06:34:51.282087 2026] [security2:error] [pid 935758:tid 935978] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/green1.php"] [unique_id "al4V67cDxY_mIul-JSG54wAAAWI"]
[Mon Jul 20 06:34:51.444264 2026] [security2:error] [pid 935758:tid 935930] [client 161.118.195.148:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V67cDxY_mIul-JSG58AAAATI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:51.467284 2026] [security2:error] [pid 935758:tid 935949] [client 45.3.45.232:64403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4V67cDxY_mIul-JSG57wAAAUU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:34:51.487638 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:50121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V67cDxY_mIul-JSG59AAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:51.487737 2026] [security2:error] [pid 935758:tid 935980] [client 77.110.127.138:50121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V67cDxY_mIul-JSG59AAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:51.564068 2026] [security2:error] [pid 935758:tid 935890] [client 14.225.17.146:61795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5gAAAAQo"], referer: http://samdothan.org/Old
[Mon Jul 20 06:34:51.578740 2026] [security2:error] [pid 935758:tid 935903] [client 14.225.17.146:55246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5ewAAARc"]
[Mon Jul 20 06:34:51.768260 2026] [security2:error] [pid 935758:tid 935919] [client 171.61.165.146:27673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V67cDxY_mIul-JSG6EQAAASc"]
[Mon Jul 20 06:34:51.768371 2026] [security2:error] [pid 935758:tid 935919] [client 171.61.165.146:27673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V67cDxY_mIul-JSG6EQAAASc"]
[Mon Jul 20 06:34:51.821043 2026] [security2:error] [pid 940476:tid 940504] [remote 57.141.18.27:40116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V5xjVYcQxwGpYwZnLxAAAdBs"]
[Mon Jul 20 06:34:51.904883 2026] [security2:error] [pid 935758:tid 935880] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V67cDxY_mIul-JSG6GgABUnc"]
[Mon Jul 20 06:34:51.905120 2026] [security2:error] [pid 935758:tid 935962] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V67cDxY_mIul-JSG6GgABUnc"]
[Mon Jul 20 06:34:51.939408 2026] [security2:error] [pid 935758:tid 935789] [remote 47.82.124.27:60873] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2021/03/Hillside-Beach-Club-Turkey-Sailing-1200w.jpg"] [unique_id "al4V67cDxY_mIul-JSG6HgABNxw"]
[Mon Jul 20 06:34:52.020494 2026] [security2:error] [pid 935758:tid 935928] [client 161.118.195.148:64372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V7LcDxY_mIul-JSG6LAAAATA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:52.040262 2026] [security2:error] [pid 935758:tid 935938] [client 14.225.17.146:61660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4V67cDxY_mIul-JSG6KgAAATo"], referer: https://walkingandtalking.net/Old
[Mon Jul 20 06:34:52.235383 2026] [security2:error] [pid 935758:tid 935968] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/nc4.php"] [unique_id "al4V7LcDxY_mIul-JSG6TwAAAVg"]
[Mon Jul 20 06:34:52.235467 2026] [security2:error] [pid 935758:tid 935968] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/nc4.php"] [unique_id "al4V7LcDxY_mIul-JSG6TwAAAVg"]
[Mon Jul 20 06:34:52.478717 2026] [security2:error] [pid 940476:tid 940573] [remote 57.141.18.17:31862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V6BjVYcQxwGpYwZnL7QAABGA"]
[Mon Jul 20 06:34:52.594620 2026] [security2:error] [pid 935758:tid 935940] [client 161.118.195.148:64737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V7LcDxY_mIul-JSG6XQAAATw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:52.633059 2026] [security2:error] [pid 935758:tid 935957] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/a1.php"] [unique_id "al4V7LcDxY_mIul-JSG6ZQAAAU0"]
[Mon Jul 20 06:34:52.633224 2026] [security2:error] [pid 935758:tid 935957] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/a1.php"] [unique_id "al4V7LcDxY_mIul-JSG6ZQAAAU0"]
[Mon Jul 20 06:34:52.828101 2026] [security2:error] [pid 935758:tid 935899] [client 158.173.89.95:44413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4V7LcDxY_mIul-JSG6bgAAARM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:34:52.829317 2026] [security2:error] [pid 935758:tid 935945] [client 74.7.227.179:53926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4V7LcDxY_mIul-JSG6agABQTs"], referer: https://tejasenvironmental.com/p=2661
[Mon Jul 20 06:34:52.854688 2026] [security2:error] [pid 935758:tid 935909] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/eee.php"] [unique_id "al4V7LcDxY_mIul-JSG6cAAAAR0"]
[Mon Jul 20 06:34:52.854841 2026] [security2:error] [pid 935758:tid 935909] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/eee.php"] [unique_id "al4V7LcDxY_mIul-JSG6cAAAAR0"]
[Mon Jul 20 06:34:52.968082 2026] [security2:error] [pid 935758:tid 935928] [client 187.108.85.186:54935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V7LcDxY_mIul-JSG6dgAAATA"]
[Mon Jul 20 06:34:52.968188 2026] [security2:error] [pid 935758:tid 935928] [client 187.108.85.186:54935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V7LcDxY_mIul-JSG6dgAAATA"]
[Mon Jul 20 06:34:53.003590 2026] [security2:error] [pid 935758:tid 935892] [client 106.219.188.178:27746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V7bcDxY_mIul-JSG6eQAAAQw"]
[Mon Jul 20 06:34:53.005401 2026] [security2:error] [pid 935758:tid 935892] [client 106.219.188.178:27746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V7bcDxY_mIul-JSG6eQAAAQw"]
[Mon Jul 20 06:34:53.059678 2026] [security2:error] [pid 935758:tid 935862] [remote 154.61.75.100:43028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V7bcDxY_mIul-JSG6fgABaGU"]
[Mon Jul 20 06:34:53.086400 2026] [security2:error] [pid 935758:tid 935991] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-aothait.php"] [unique_id "al4V7bcDxY_mIul-JSG6hAAAAW8"]
[Mon Jul 20 06:34:53.086493 2026] [security2:error] [pid 935758:tid 935991] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/wp-aothait.php"] [unique_id "al4V7bcDxY_mIul-JSG6hAAAAW8"]
[Mon Jul 20 06:34:53.172477 2026] [security2:error] [pid 935758:tid 935931] [client 161.118.195.148:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V7bcDxY_mIul-JSG6kwAAATM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:53.272266 2026] [security2:error] [pid 935758:tid 935767] [remote 5.161.225.162:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4V7bcDxY_mIul-JSG6owABKAY"]
[Mon Jul 20 06:34:53.333613 2026] [security2:error] [pid 935758:tid 936003] [client 52.15.147.27:58914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4V7bcDxY_mIul-JSG6qQAAAXs"], referer: https://windowtx.com
[Mon Jul 20 06:34:53.368274 2026] [security2:error] [pid 935758:tid 935960] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/config.json.php"] [unique_id "al4V7bcDxY_mIul-JSG6qwAAAVA"]
[Mon Jul 20 06:34:53.368416 2026] [security2:error] [pid 935758:tid 935960] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/config.json.php"] [unique_id "al4V7bcDxY_mIul-JSG6qwAAAVA"]
[Mon Jul 20 06:34:53.496563 2026] [security2:error] [pid 935758:tid 935818] [remote 5.161.225.162:43582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4V7bcDxY_mIul-JSG6sQABZDk"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:34:53.542821 2026] [security2:error] [pid 935758:tid 935785] [remote 154.61.75.100:43028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V7bcDxY_mIul-JSG6tgABGhg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:53.646935 2026] [security2:error] [pid 935758:tid 936009] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al4V7bcDxY_mIul-JSG6yQAAAYE"]
[Mon Jul 20 06:34:53.647044 2026] [security2:error] [pid 935758:tid 936009] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/2PJcpMFsD8B.php"] [unique_id "al4V7bcDxY_mIul-JSG6yQAAAYE"]
[Mon Jul 20 06:34:53.677640 2026] [security2:error] [pid 935758:tid 935988] [client 35.90.38.209:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4V7bcDxY_mIul-JSG6zAAAAWw"]
[Mon Jul 20 06:34:53.677800 2026] [security2:error] [pid 935758:tid 935954] [client 44.245.170.32:10528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4V7bcDxY_mIul-JSG6ywAAAUo"]
[Mon Jul 20 06:34:53.681640 2026] [security2:error] [pid 935758:tid 935920] [client 54.244.177.189:20224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4V7bcDxY_mIul-JSG6zgAAASg"]
[Mon Jul 20 06:34:53.682441 2026] [security2:error] [pid 935758:tid 935943] [client 35.90.38.209:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4V7bcDxY_mIul-JSG6zwAAAT8"]
[Mon Jul 20 06:34:53.713126 2026] [security2:error] [pid 935758:tid 936017] [client 103.125.179.95:57409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V7bcDxY_mIul-JSG60gAAAYk"]
[Mon Jul 20 06:34:53.713239 2026] [security2:error] [pid 935758:tid 936017] [client 103.125.179.95:57409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V7bcDxY_mIul-JSG60gAAAYk"]
[Mon Jul 20 06:34:53.721403 2026] [security2:error] [pid 935758:tid 935944] [client 54.244.177.189:20228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4V7bcDxY_mIul-JSG64QAAAUA"]
[Mon Jul 20 06:34:53.747467 2026] [security2:error] [pid 935758:tid 935963] [client 161.118.195.148:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V7bcDxY_mIul-JSG64gAAAVM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:53.785209 2026] [security2:error] [pid 935758:tid 935771] [remote 167.172.73.193:48660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.73.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4V7bcDxY_mIul-JSG64wABaAo"]
[Mon Jul 20 06:34:53.867102 2026] [security2:error] [pid 935758:tid 936009] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/k2.php"] [unique_id "al4V7bcDxY_mIul-JSG69gAAAYE"]
[Mon Jul 20 06:34:53.867202 2026] [security2:error] [pid 935758:tid 936009] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/k2.php"] [unique_id "al4V7bcDxY_mIul-JSG69gAAAYE"]
[Mon Jul 20 06:34:53.913875 2026] [security2:error] [pid 935758:tid 935925] [client 14.225.17.146:61700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4V7bcDxY_mIul-JSG65AAAAS0"], referer: http://cephasnext.com/Old
[Mon Jul 20 06:34:54.026611 2026] [security2:error] [pid 935758:tid 935974] [client 46.110.96.34:12781] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4V7rcDxY_mIul-JSG6_wAAAV4"]
[Mon Jul 20 06:34:54.110293 2026] [security2:error] [pid 935758:tid 935993] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/uiuvs58l.php"] [unique_id "al4V7rcDxY_mIul-JSG7BwAAAXE"]
[Mon Jul 20 06:34:54.110360 2026] [security2:error] [pid 935758:tid 936007] [client 77.110.127.138:50139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V7rcDxY_mIul-JSG7CAAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:54.110401 2026] [security2:error] [pid 935758:tid 935993] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/uiuvs58l.php"] [unique_id "al4V7rcDxY_mIul-JSG7BwAAAXE"]
[Mon Jul 20 06:34:54.154967 2026] [security2:error] [pid 935758:tid 935866] [remote 167.172.73.193:48660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.73.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4V7rcDxY_mIul-JSG7DwABaGk"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:34:54.259657 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V7rcDxY_mIul-JSG7GwAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:54.259770 2026] [security2:error] [pid 935758:tid 935991] [client 77.110.127.138:50140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V7rcDxY_mIul-JSG7GwAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:54.326940 2026] [security2:error] [pid 935758:tid 935905] [client 161.118.195.148:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V7rcDxY_mIul-JSG7IwAAARk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:54.337797 2026] [security2:error] [pid 935758:tid 935931] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/40p9ixjd.php"] [unique_id "al4V7rcDxY_mIul-JSG7JAAAATM"]
[Mon Jul 20 06:34:54.337868 2026] [security2:error] [pid 935758:tid 935931] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/40p9ixjd.php"] [unique_id "al4V7rcDxY_mIul-JSG7JAAAATM"]
[Mon Jul 20 06:34:54.529581 2026] [security2:error] [pid 935758:tid 935912] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/uiuvs58l.update.php"] [unique_id "al4V7rcDxY_mIul-JSG7LwAAASA"]
[Mon Jul 20 06:34:54.529683 2026] [security2:error] [pid 935758:tid 935912] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "thescarystory.com"] [uri "/uiuvs58l.update.php"] [unique_id "al4V7rcDxY_mIul-JSG7LwAAASA"]
[Mon Jul 20 06:34:54.595671 2026] [security2:error] [pid 935758:tid 935898] [client 57.141.18.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ferrellroofing.com"] [uri "/index.php"] [unique_id "al4V7rcDxY_mIul-JSG7KAAAARI"]
[Mon Jul 20 06:34:54.667798 2026] [security2:error] [pid 935758:tid 935966] [client 57.141.18.0:42516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V6bcDxY_mIul-JSG5ZgABVnQ"]
[Mon Jul 20 06:34:54.734567 2026] [security2:error] [pid 935758:tid 935973] [client 14.225.17.146:60949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4V7LcDxY_mIul-JSG6dAAAAV0"], referer: http://according2plant.com/Old
[Mon Jul 20 06:34:54.753060 2026] [security2:error] [pid 935758:tid 935963] [client 54.244.177.189:20238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4V7rcDxY_mIul-JSG7TwAAAVM"]
[Mon Jul 20 06:34:54.870290 2026] [proxy:error] [pid 935758:tid 936003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:54.870368 2026] [proxy_http:error] [pid 935758:tid 936003] [client 34.73.38.214:55574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:54.871107 2026] [proxy:error] [pid 935758:tid 936003] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:54.871140 2026] [proxy_http:error] [pid 935758:tid 936003] [client 34.73.38.214:55574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:54.881676 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:50143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V7rcDxY_mIul-JSG7XgAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:54.881773 2026] [security2:error] [pid 935758:tid 935922] [client 77.110.127.138:50143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V7rcDxY_mIul-JSG7XgAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:54.899322 2026] [security2:error] [pid 935758:tid 935946] [client 161.118.195.148:49845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V7rcDxY_mIul-JSG7YAAAAUI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:54.982865 2026] [security2:error] [pid 935758:tid 935979] [client 57.141.18.30:32464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5kQABYws"]
[Mon Jul 20 06:34:55.372265 2026] [security2:error] [pid 935758:tid 935980] [client 34.74.185.202:56330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4V77cDxY_mIul-JSG7kwAAAWQ"]
[Mon Jul 20 06:34:55.423855 2026] [security2:error] [pid 935758:tid 935902] [client 14.251.3.155:55776] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4V77cDxY_mIul-JSG7mAAAARY"]
[Mon Jul 20 06:34:55.473899 2026] [security2:error] [pid 935758:tid 935983] [client 57.141.18.34:40624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V6rcDxY_mIul-JSG5zAABZ08"]
[Mon Jul 20 06:34:55.478686 2026] [security2:error] [pid 935758:tid 935929] [client 161.118.195.148:50224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V77cDxY_mIul-JSG7nQAAATE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:55.706401 2026] [security2:error] [pid 935758:tid 935770] [remote 47.82.124.184:4334] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2021/03/Hillside-Beach-Club-Turkey-Sailing-1200w.jpg"] [unique_id "al4V77cDxY_mIul-JSG7tgABgQk"]
[Mon Jul 20 06:34:55.735046 2026] [security2:error] [pid 935758:tid 935974] [client 34.74.185.202:53442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4V77cDxY_mIul-JSG7uQAAAV4"]
[Mon Jul 20 06:34:55.848907 2026] [security2:error] [pid 935758:tid 936000] [client 94.154.43.179:21178] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "dev.cira.org"] [uri "/.env"] [unique_id "al4V77cDxY_mIul-JSG7wQAAAXg"]
[Mon Jul 20 06:34:56.050392 2026] [security2:error] [pid 935758:tid 935971] [client 34.74.185.202:59182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4V8LcDxY_mIul-JSG7zwAAAVs"]
[Mon Jul 20 06:34:56.056255 2026] [security2:error] [pid 935758:tid 935943] [client 161.118.195.148:50542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V8LcDxY_mIul-JSG70AAAAT8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:56.402920 2026] [security2:error] [pid 935758:tid 935948] [client 57.141.18.120:23866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V67cDxY_mIul-JSG6JQABREE"]
[Mon Jul 20 06:34:56.426265 2026] [security2:error] [pid 935758:tid 935965] [client 34.74.185.202:52681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4V8LcDxY_mIul-JSG78gAAAVU"]
[Mon Jul 20 06:34:56.532788 2026] [security2:error] [pid 935758:tid 936014] [client 216.73.216.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4V7rcDxY_mIul-JSG7WAAAAYY"]
[Mon Jul 20 06:34:56.630197 2026] [security2:error] [pid 935758:tid 935913] [client 161.118.195.148:50838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V8LcDxY_mIul-JSG7_gAAASE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:56.984115 2026] [security2:error] [pid 935758:tid 935974] [client 34.74.185.202:53998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4V8LcDxY_mIul-JSG8HQAAAV4"]
[Mon Jul 20 06:34:57.064699 2026] [security2:error] [pid 935758:tid 935977] [client 223.237.130.40:53652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4V8LcDxY_mIul-JSG8GAAAAWE"]
[Mon Jul 20 06:34:57.123788 2026] [security2:error] [pid 935758:tid 935906] [client 50.116.65.227:41072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4V8bcDxY_mIul-JSG8KQAAARo"]
[Mon Jul 20 06:34:57.133412 2026] [security2:error] [pid 935758:tid 935981] [client 50.116.65.227:41084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4V8bcDxY_mIul-JSG8KwAAAWU"]
[Mon Jul 20 06:34:57.181010 2026] [security2:error] [pid 935758:tid 935976] [client 216.73.217.93:48335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4V8LcDxY_mIul-JSG8FwABYDU"]
[Mon Jul 20 06:34:57.205234 2026] [security2:error] [pid 935758:tid 935929] [client 161.118.195.148:51170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V8bcDxY_mIul-JSG8MgAAATE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:57.210183 2026] [proxy:error] [pid 935758:tid 935942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:57.210269 2026] [proxy_http:error] [pid 935758:tid 935942] [client 34.73.38.214:62688] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:57.210794 2026] [proxy:error] [pid 935758:tid 935942] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:57.210822 2026] [proxy_http:error] [pid 935758:tid 935942] [client 34.73.38.214:62688] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:57.241164 2026] [security2:error] [pid 935758:tid 936009] [client 223.185.13.213:14500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V8bcDxY_mIul-JSG8OAAAAYE"]
[Mon Jul 20 06:34:57.241304 2026] [security2:error] [pid 935758:tid 936009] [client 223.185.13.213:14500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V8bcDxY_mIul-JSG8OAAAAYE"]
[Mon Jul 20 06:34:57.390195 2026] [security2:error] [pid 935758:tid 935949] [client 77.110.127.138:50156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V8bcDxY_mIul-JSG8TAAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:57.550285 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:50158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V8bcDxY_mIul-JSG8UgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:57.550396 2026] [security2:error] [pid 935758:tid 935971] [client 77.110.127.138:50158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V8bcDxY_mIul-JSG8UgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:57.558863 2026] [security2:error] [pid 935758:tid 936016] [client 34.74.185.202:65149] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4V8bcDxY_mIul-JSG8UwAAAYg"]
[Mon Jul 20 06:34:57.606715 2026] [security2:error] [pid 935758:tid 935995] [client 57.141.18.97:63806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V7bcDxY_mIul-JSG6iwABc1c"]
[Mon Jul 20 06:34:57.778815 2026] [security2:error] [pid 935758:tid 935933] [client 161.118.195.148:51498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V8bcDxY_mIul-JSG8XwAAATU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:58.033029 2026] [security2:error] [pid 935758:tid 935953] [client 14.225.17.146:55098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4V8bcDxY_mIul-JSG8XQAAAUk"]
[Mon Jul 20 06:34:58.081298 2026] [security2:error] [pid 935758:tid 935932] [client 34.74.185.202:61687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4V8rcDxY_mIul-JSG8cwAAATQ"]
[Mon Jul 20 06:34:58.162745 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:50161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V8rcDxY_mIul-JSG8eAAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:58.162855 2026] [security2:error] [pid 935758:tid 935955] [client 77.110.127.138:50161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V8rcDxY_mIul-JSG8eAAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:34:58.360191 2026] [security2:error] [pid 935758:tid 935943] [client 161.118.195.148:51855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V8rcDxY_mIul-JSG8kAAAAT8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:58.422949 2026] [security2:error] [pid 935758:tid 935963] [client 34.74.185.202:50413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4V8rcDxY_mIul-JSG8mAAAAVM"]
[Mon Jul 20 06:34:58.783621 2026] [security2:error] [pid 935758:tid 936000] [client 112.208.70.94:42017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V8rcDxY_mIul-JSG8nwAAAXg"]
[Mon Jul 20 06:34:58.783702 2026] [security2:error] [pid 935758:tid 936000] [client 112.208.70.94:42017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V8rcDxY_mIul-JSG8nwAAAXg"]
[Mon Jul 20 06:34:58.874563 2026] [security2:error] [pid 935758:tid 935954] [client 171.60.139.123:50876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V8rcDxY_mIul-JSG8oAAAAUo"]
[Mon Jul 20 06:34:58.874767 2026] [security2:error] [pid 935758:tid 935954] [client 171.60.139.123:50876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V8rcDxY_mIul-JSG8oAAAAUo"]
[Mon Jul 20 06:34:59.117653 2026] [http2:info] [pid 953991:tid 953991] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:34:59.132643 2026] [security2:error] [pid 953991:tid 954127] [client 114.119.158.234:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "scoophouse.com"] [uri "/robots.txt"] [unique_id "al4V86_X-kAXGDrIFaekwwAAAIs"], referer: http://scoophouse.com/robots.txt
[Mon Jul 20 06:34:59.139292 2026] [proxy:error] [pid 953991:tid 954121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:59.139417 2026] [proxy_http:error] [pid 953991:tid 954121] [client 34.73.38.214:53594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:59.139920 2026] [proxy:error] [pid 953991:tid 954121] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:34:59.139945 2026] [proxy_http:error] [pid 953991:tid 954121] [client 34.73.38.214:53594] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:34:59.159374 2026] [security2:error] [pid 935758:tid 935980] [client 14.225.17.146:52112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4V8bcDxY_mIul-JSG8JAAAAWQ"], referer: http://dadanetnet.net/Old
[Mon Jul 20 06:34:59.159542 2026] [security2:error] [pid 935758:tid 935968] [client 14.225.17.146:61244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4V8LcDxY_mIul-JSG7-QAAAVg"], referer: http://narv.co/Old
[Mon Jul 20 06:34:59.210518 2026] [security2:error] [pid 935758:tid 935964] [client 39.48.81.23:57146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V87cDxY_mIul-JSG8oQAAAVQ"]
[Mon Jul 20 06:34:59.210650 2026] [security2:error] [pid 935758:tid 935964] [client 39.48.81.23:57146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V87cDxY_mIul-JSG8oQAAAVQ"]
[Mon Jul 20 06:34:59.242579 2026] [security2:error] [pid 953991:tid 954142] [client 34.74.185.202:63562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4V86_X-kAXGDrIFaek-QAAAJo"]
[Mon Jul 20 06:34:59.327566 2026] [security2:error] [pid 953991:tid 954141] [client 161.118.195.148:52235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V86_X-kAXGDrIFaelBAAAAJk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:59.525583 2026] [security2:error] [pid 953991:tid 954143] [client 197.186.66.42:50799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V86_X-kAXGDrIFaelHgAAAJs"]
[Mon Jul 20 06:34:59.525691 2026] [security2:error] [pid 953991:tid 954143] [client 197.186.66.42:50799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V86_X-kAXGDrIFaelHgAAAJs"]
[Mon Jul 20 06:34:59.638446 2026] [security2:error] [pid 953991:tid 954134] [client 14.225.17.146:55635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelEAAAAJI"], referer: http://falconarrowshop.com/Old
[Mon Jul 20 06:34:59.646614 2026] [security2:error] [pid 953991:tid 954161] [client 104.234.53.67:42281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4V86_X-kAXGDrIFaelMQAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:34:59.708273 2026] [security2:error] [pid 953991:tid 954033] [remote 100.42.189.89:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4V86_X-kAXGDrIFaelOAAAuyk"]
[Mon Jul 20 06:34:59.782385 2026] [security2:error] [pid 935758:tid 935802] [remote 57.141.18.102:58830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V77cDxY_mIul-JSG7jwABIik"]
[Mon Jul 20 06:34:59.905027 2026] [security2:error] [pid 953991:tid 954214] [client 34.74.185.202:51889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4V86_X-kAXGDrIFaelWgAAAOI"]
[Mon Jul 20 06:34:59.913635 2026] [security2:error] [pid 953991:tid 954185] [client 161.118.195.148:52767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V86_X-kAXGDrIFaelWwAAAMU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:34:59.932665 2026] [security2:error] [pid 953991:tid 954057] [remote 100.42.189.89:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4V86_X-kAXGDrIFaelXQAAjUE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:34:59.976979 2026] [security2:error] [pid 953991:tid 954141] [client 114.119.130.218:47979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.californiaperfumecompany.com"] [uri "/collector/cal_cpc_sale_terms_and_conditions.html"] [unique_id "al4V86_X-kAXGDrIFaelbgAAAJk"], referer: https://www.californiaperfumecompany.com/collector/cal_cpc_for_sale.html
[Mon Jul 20 06:35:00.037283 2026] [security2:error] [pid 953991:tid 954137] [client 14.225.17.146:55454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelDgAAAJU"], referer: http://oldracelimited.com/Old
[Mon Jul 20 06:35:00.227229 2026] [security2:error] [pid 953991:tid 954224] [client 14.225.17.146:52060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4V9K_X-kAXGDrIFaeldQAAAOw"], referer: https://narv.co/Old
[Mon Jul 20 06:35:00.337786 2026] [security2:error] [pid 953991:tid 954183] [client 34.74.185.202:50895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4V9K_X-kAXGDrIFaelpQAAAMM"]
[Mon Jul 20 06:35:00.366250 2026] [security2:error] [pid 953991:tid 954156] [client 217.142.18.172:20813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V9K_X-kAXGDrIFaelsgAAAKg"]
[Mon Jul 20 06:35:00.374391 2026] [security2:error] [pid 953991:tid 954156] [client 217.142.18.172:20813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V9K_X-kAXGDrIFaelsgAAAKg"]
[Mon Jul 20 06:35:00.489821 2026] [security2:error] [pid 953991:tid 954136] [client 161.118.195.148:53154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V9K_X-kAXGDrIFaelwgAAAJQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:00.651124 2026] [core:error] [pid 953991:tid 954135] [client 14.225.17.146:51814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Old
[Mon Jul 20 06:35:00.651149 2026] [core:error] [pid 953991:tid 954135] [client 14.225.17.146:51814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/Old
[Mon Jul 20 06:35:00.833819 2026] [security2:error] [pid 953991:tid 954165] [client 34.73.38.214:49405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4V9K_X-kAXGDrIFael6QAAALE"]
[Mon Jul 20 06:35:00.891474 2026] [security2:error] [pid 953991:tid 954133] [client 14.225.17.146:55636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelDwAAAJE"], referer: http://eframiproperties.com/Old
[Mon Jul 20 06:35:01.053641 2026] [security2:error] [pid 953991:tid 954123] [client 145.239.81.31:38404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelBQAAAIc"]
[Mon Jul 20 06:35:01.054255 2026] [security2:error] [pid 953991:tid 954240] [client 51.75.23.120:34752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4V9K_X-kAXGDrIFaeldAAAAPw"]
[Mon Jul 20 06:35:01.061535 2026] [security2:error] [pid 953991:tid 954186] [client 161.118.195.148:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V9a_X-kAXGDrIFael_QAAAMY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:01.178802 2026] [security2:error] [pid 953991:tid 954209] [client 34.74.185.202:53829] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4V9a_X-kAXGDrIFaemCgAAAN0"]
[Mon Jul 20 06:35:01.280629 2026] [security2:error] [pid 953991:tid 954185] [client 14.225.17.146:52171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4V9a_X-kAXGDrIFaemAwAAAMU"], referer: https://north-woods-engineering.com/Old
[Mon Jul 20 06:35:01.536086 2026] [security2:error] [pid 953991:tid 954227] [client 45.3.45.230:45037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4V9a_X-kAXGDrIFaemGwAAAO8"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:35:01.634313 2026] [security2:error] [pid 953991:tid 954200] [client 161.118.195.148:53825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V9a_X-kAXGDrIFaemJwAAANQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:01.978231 2026] [security2:error] [pid 953991:tid 954177] [client 34.74.185.202:51316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.reosportsboats.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4V9a_X-kAXGDrIFaemSQAAAL0"]
[Mon Jul 20 06:35:02.110727 2026] [security2:error] [pid 953991:tid 954237] [client 77.110.127.138:50181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V9q_X-kAXGDrIFaemdgAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:02.155703 2026] [security2:error] [pid 953991:tid 954245] [client 104.207.59.180:46379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4V9q_X-kAXGDrIFaemeQAAAQE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:35:02.171867 2026] [security2:error] [pid 953991:tid 954220] [client 14.225.17.146:52058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelbQAAAOg"], referer: http://latiendadejorge.com.gt/Old
[Mon Jul 20 06:35:02.206852 2026] [security2:error] [pid 953991:tid 954173] [client 149.118.58.82:53209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V9q_X-kAXGDrIFaemfwAAALk"]
[Mon Jul 20 06:35:02.208434 2026] [security2:error] [pid 953991:tid 954157] [client 161.118.195.148:54186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V9q_X-kAXGDrIFaemhQAAAKk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:02.212244 2026] [security2:error] [pid 953991:tid 954229] [client 13.201.64.214:35666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4V9q_X-kAXGDrIFaemgwAAAPE"]
[Mon Jul 20 06:35:02.229807 2026] [security2:error] [pid 953991:tid 954217] [client 104.234.53.93:48547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4V9q_X-kAXGDrIFaemiQAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:02.307853 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V9q_X-kAXGDrIFaemjQAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:02.307992 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V9q_X-kAXGDrIFaemjQAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:02.375656 2026] [security2:error] [pid 953991:tid 954196] [client 106.219.188.178:8591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V9q_X-kAXGDrIFaemmAAAANA"]
[Mon Jul 20 06:35:02.375959 2026] [security2:error] [pid 953991:tid 954196] [client 106.219.188.178:8591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4V9q_X-kAXGDrIFaemmAAAANA"]
[Mon Jul 20 06:35:02.427430 2026] [security2:error] [pid 953991:tid 954111] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V9q_X-kAXGDrIFaemnQAAznc"]
[Mon Jul 20 06:35:02.427670 2026] [security2:error] [pid 953991:tid 954194] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4V9q_X-kAXGDrIFaemnQAAznc"]
[Mon Jul 20 06:35:02.432856 2026] [security2:error] [pid 935758:tid 935858] [remote 57.141.18.23:51254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V8bcDxY_mIul-JSG8aQABTGE"]
[Mon Jul 20 06:35:02.530237 2026] [security2:error] [pid 953991:tid 954183] [client 171.61.165.146:12645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V9q_X-kAXGDrIFaemqwAAAMM"]
[Mon Jul 20 06:35:02.530394 2026] [security2:error] [pid 953991:tid 954183] [client 171.61.165.146:12645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4V9q_X-kAXGDrIFaemqwAAAMM"]
[Mon Jul 20 06:35:02.729929 2026] [security2:error] [pid 953991:tid 954234] [client 14.225.17.146:63623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4V9a_X-kAXGDrIFaemMQAAAPY"]
[Mon Jul 20 06:35:02.780741 2026] [security2:error] [pid 953991:tid 954166] [client 161.118.195.148:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V9q_X-kAXGDrIFaemxAAAALI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:02.802771 2026] [security2:error] [pid 953991:tid 954148] [client 114.119.155.111:31521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sanifidensolutions.com"] [uri "/"] [unique_id "al4V9q_X-kAXGDrIFaemxwAAAKA"], referer: https://sidhulawyers.com.au/sitemap_quality_91.xml
[Mon Jul 20 06:35:02.900824 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V9q_X-kAXGDrIFaem0AAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:02.900911 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V9q_X-kAXGDrIFaem0AAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:03.241425 2026] [security2:error] [pid 953991:tid 954130] [client 13.229.83.156:30832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4V96_X-kAXGDrIFaem8wAAAI4"]
[Mon Jul 20 06:35:03.241537 2026] [security2:error] [pid 953991:tid 954130] [client 13.229.83.156:30832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4V96_X-kAXGDrIFaem8wAAAI4"]
[Mon Jul 20 06:35:03.255659 2026] [security2:error] [pid 953991:tid 954188] [client 14.225.17.146:50498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4V96_X-kAXGDrIFaem4gAAAMg"], referer: http://phillipbloch.com/Old
[Mon Jul 20 06:35:03.286248 2026] [security2:error] [pid 953991:tid 954179] [client 43.205.139.3:10862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4V96_X-kAXGDrIFaem-AAAAL8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:35:03.354222 2026] [security2:error] [pid 953991:tid 954153] [client 161.118.195.148:54927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V96_X-kAXGDrIFaenAAAAAKU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:03.629602 2026] [security2:error] [pid 953991:tid 954048] [remote 152.228.213.32:46450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4V96_X-kAXGDrIFaenFAAAnzg"]
[Mon Jul 20 06:35:03.629827 2026] [security2:error] [pid 953991:tid 954147] [client 152.228.213.32:46450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4V96_X-kAXGDrIFaenFAAAnzg"]
[Mon Jul 20 06:35:03.642290 2026] [security2:error] [pid 953991:tid 954180] [client 50.116.65.227:30636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4V96_X-kAXGDrIFaenGwAAAMA"]
[Mon Jul 20 06:35:03.651901 2026] [security2:error] [pid 953991:tid 954197] [client 50.116.65.227:30638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4V96_X-kAXGDrIFaenHAAAANE"]
[Mon Jul 20 06:35:03.706720 2026] [security2:error] [pid 953991:tid 954243] [client 187.108.85.186:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V96_X-kAXGDrIFaenIwAAAP8"]
[Mon Jul 20 06:35:03.706863 2026] [security2:error] [pid 953991:tid 954243] [client 187.108.85.186:55473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V96_X-kAXGDrIFaenIwAAAP8"]
[Mon Jul 20 06:35:03.817302 2026] [security2:error] [pid 953991:tid 954234] [client 77.110.127.138:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V96_X-kAXGDrIFaenNwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:03.817406 2026] [security2:error] [pid 953991:tid 954234] [client 77.110.127.138:50198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V96_X-kAXGDrIFaenNwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:03.902727 2026] [security2:error] [pid 953991:tid 954149] [client 103.153.183.69:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/....//....//....//....//....//var/www/html/configuration.php"] [unique_id "al4V96_X-kAXGDrIFaenPAAAAKE"], referer: https://t.co/txx12w8efj
[Mon Jul 20 06:35:03.929369 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:55278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V96_X-kAXGDrIFaenPwAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:03.943338 2026] [security2:error] [pid 953991:tid 954203] [client 57.141.18.19:43964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelAAAA1xM"]
[Mon Jul 20 06:35:03.957413 2026] [security2:error] [pid 953991:tid 954063] [remote 188.166.241.141:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4V96_X-kAXGDrIFaenQAAAwkc"]
[Mon Jul 20 06:35:04.038402 2026] [security2:error] [pid 953991:tid 954223] [client 149.118.58.82:54197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4V96_X-kAXGDrIFaenQwAAAOs"]
[Mon Jul 20 06:35:04.048811 2026] [security2:error] [pid 953991:tid 954057] [remote 154.66.198.148:36388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaenRwAA3kE"]
[Mon Jul 20 06:35:04.065808 2026] [security2:error] [pid 953991:tid 954231] [client 57.141.18.99:60732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V86_X-kAXGDrIFaelBwAA8xU"]
[Mon Jul 20 06:35:04.333981 2026] [core:error] [pid 953991:tid 954168] [client 103.153.183.69:35068] AH10244: invalid URI path (http://autodiscover.jjw.pvq.mybluehost.me/%%32e%%32e/%%32e%%32e/etc/passwd?_=x8rjsjke&v=dyisn), referer: https://www.reddit.com/
[Mon Jul 20 06:35:04.336559 2026] [security2:error] [pid 953991:tid 954229] [client 127.0.0.1:33064] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4V-K_X-kAXGDrIFaenbQAAAPE"], referer: https://www.reddit.com/
[Mon Jul 20 06:35:04.344565 2026] [security2:error] [pid 953991:tid 954075] [remote 188.166.241.141:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaenbgAAoVM"], referer: https://adultdaycarereno.com/wp-login.php
[Mon Jul 20 06:35:04.379477 2026] [security2:error] [pid 953991:tid 954136] [client 77.110.127.138:50204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-K_X-kAXGDrIFaendAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:04.379554 2026] [security2:error] [pid 953991:tid 954136] [client 77.110.127.138:50204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-K_X-kAXGDrIFaendAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:04.386540 2026] [security2:error] [pid 953991:tid 954128] [client 14.225.17.146:51927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4V96_X-kAXGDrIFaenQQAAAIw"], referer: http://mollycahill.com/Old
[Mon Jul 20 06:35:04.426997 2026] [security2:error] [pid 953991:tid 954178] [client 103.125.179.95:57881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V-K_X-kAXGDrIFaeneQAAAL4"]
[Mon Jul 20 06:35:04.427180 2026] [security2:error] [pid 953991:tid 954094] [remote 20.153.140.50:33224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaeneAAAimY"]
[Mon Jul 20 06:35:04.429102 2026] [security2:error] [pid 953991:tid 954178] [client 103.125.179.95:57881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4V-K_X-kAXGDrIFaeneQAAAL4"]
[Mon Jul 20 06:35:04.491742 2026] [security2:error] [pid 953991:tid 954205] [client 34.73.38.214:60956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4V-K_X-kAXGDrIFaenfAAAANk"]
[Mon Jul 20 06:35:04.507995 2026] [security2:error] [pid 953991:tid 954230] [client 161.118.195.148:55624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaenfQAAAPI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:04.618499 2026] [security2:error] [pid 953991:tid 954186] [client 77.110.127.138:50207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-K_X-kAXGDrIFaengQAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:04.618602 2026] [security2:error] [pid 953991:tid 954186] [client 77.110.127.138:50207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-K_X-kAXGDrIFaengQAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:04.624911 2026] [security2:error] [pid 953991:tid 954223] [client 149.118.58.82:54526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4V-K_X-kAXGDrIFaenggAAAOs"]
[Mon Jul 20 06:35:04.731955 2026] [security2:error] [pid 953991:tid 954135] [client 57.129.139.88:60698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4V-K_X-kAXGDrIFaengAAAAJM"]
[Mon Jul 20 06:35:04.750605 2026] [security2:error] [pid 953991:tid 954088] [remote 154.66.198.148:36388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaenigAAsWA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:35:04.789140 2026] [security2:error] [pid 953991:tid 954198] [client 77.110.127.138:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaenkQAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:04.842688 2026] [security2:error] [pid 953991:tid 954103] [remote 20.153.140.50:33224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V-K_X-kAXGDrIFaenmAAA128"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:35:04.975795 2026] [security2:error] [pid 953991:tid 954146] [client 34.73.38.214:52545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4V-K_X-kAXGDrIFaenqAAAAJ4"]
[Mon Jul 20 06:35:05.036952 2026] [security2:error] [pid 953991:tid 954231] [client 77.110.127.138:50210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-a_X-kAXGDrIFaenrAAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:05.037065 2026] [security2:error] [pid 953991:tid 954231] [client 77.110.127.138:50210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-a_X-kAXGDrIFaenrAAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:05.082765 2026] [security2:error] [pid 953991:tid 954133] [client 161.118.195.148:55963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V-a_X-kAXGDrIFaensgAAAJE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:05.141318 2026] [security2:error] [pid 953991:tid 954228] [client 14.225.17.146:50546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4V-K_X-kAXGDrIFaenUgAAAPA"], referer: http://adultdaycarereno.com/Old
[Mon Jul 20 06:35:05.194979 2026] [security2:error] [pid 953991:tid 954244] [client 149.118.58.82:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-admin/load-styles.php"] [unique_id "al4V-a_X-kAXGDrIFaenuQAAAQA"]
[Mon Jul 20 06:35:05.212375 2026] [security2:error] [pid 953991:tid 954233] [client 57.141.18.20:20580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V9K_X-kAXGDrIFaelygAA9Qs"]
[Mon Jul 20 06:35:05.484564 2026] [security2:error] [pid 953991:tid 954175] [client 14.225.17.146:51067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4V-K_X-kAXGDrIFaenTAAAALs"], referer: http://ghivs.com/Old
[Mon Jul 20 06:35:05.518666 2026] [security2:error] [pid 953991:tid 954180] [client 77.110.127.138:50217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-a_X-kAXGDrIFaen2gAAAMA"]
[Mon Jul 20 06:35:05.518789 2026] [security2:error] [pid 953991:tid 954180] [client 77.110.127.138:50217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-a_X-kAXGDrIFaen2gAAAMA"]
[Mon Jul 20 06:35:05.643175 2026] [security2:error] [pid 953991:tid 954156] [client 57.141.18.15:22634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V9K_X-kAXGDrIFael6wAAqCQ"]
[Mon Jul 20 06:35:05.656366 2026] [security2:error] [pid 953991:tid 954186] [client 161.118.195.148:56354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V-a_X-kAXGDrIFaen3gAAAMY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:05.876911 2026] [security2:error] [pid 953991:tid 954159] [client 74.7.228.47:47746] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.mrbambooplus.com"] [uri "/robots.txt"] [unique_id "al4V-a_X-kAXGDrIFaen-wAAqwU"]
[Mon Jul 20 06:35:06.020214 2026] [security2:error] [pid 953991:tid 954130] [client 74.7.228.47:47752] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mrbambooplus.com"] [uri "/robots.txt"] [unique_id "al4V-q_X-kAXGDrIFaeoDQAAjh8"], referer: https://www.mrbambooplus.com/robots.txt
[Mon Jul 20 06:35:06.022663 2026] [security2:error] [pid 953991:tid 954160] [client 57.141.18.99:60744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V9a_X-kAXGDrIFaemEQAArCg"]
[Mon Jul 20 06:35:06.024822 2026] [security2:error] [pid 953991:tid 954233] [client 77.110.127.138:50218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-q_X-kAXGDrIFaeoEQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:06.024928 2026] [security2:error] [pid 953991:tid 954233] [client 77.110.127.138:50218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-q_X-kAXGDrIFaeoEQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:06.033458 2026] [security2:error] [pid 953991:tid 954143] [client 14.225.17.146:62730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4V-a_X-kAXGDrIFaeoBwAAAJs"], referer: https://adultdaycarereno.com/Old
[Mon Jul 20 06:35:06.197195 2026] [security2:error] [pid 953991:tid 954024] [remote 97.74.93.24:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4V-q_X-kAXGDrIFaeoIQAA3yA"]
[Mon Jul 20 06:35:06.230946 2026] [security2:error] [pid 953991:tid 954145] [client 161.118.195.148:56711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V-q_X-kAXGDrIFaeoIwAAAJ0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:06.357497 2026] [security2:error] [pid 953991:tid 954204] [client 57.141.18.88:36274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V9a_X-kAXGDrIFaemMwAA2Dk"]
[Mon Jul 20 06:35:06.436839 2026] [security2:error] [pid 953991:tid 954233] [client 77.110.127.138:50185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-q_X-kAXGDrIFaeoVQAAAPU"]
[Mon Jul 20 06:35:06.436956 2026] [security2:error] [pid 953991:tid 954233] [client 77.110.127.138:50185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V-q_X-kAXGDrIFaeoVQAAAPU"]
[Mon Jul 20 06:35:06.540447 2026] [security2:error] [pid 953991:tid 954167] [client 103.153.183.69:35402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../app/.env"] [unique_id "al4V-q_X-kAXGDrIFaeoagAAALM"], referer: https://www.facebook.com/
[Mon Jul 20 06:35:06.615264 2026] [security2:error] [pid 953991:tid 954094] [remote 97.74.93.24:48220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4V-q_X-kAXGDrIFaeobwABBGY"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:35:06.621676 2026] [security2:error] [pid 953991:tid 954125] [client 14.182.195.220:52245] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4V-q_X-kAXGDrIFaeocAAAAIk"]
[Mon Jul 20 06:35:06.638157 2026] [security2:error] [pid 953991:tid 954196] [client 14.182.195.220:52247] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4V-q_X-kAXGDrIFaeocgAAANA"]
[Mon Jul 20 06:35:06.648534 2026] [security2:error] [pid 953991:tid 954201] [client 14.182.195.220:52246] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4V-q_X-kAXGDrIFaeodQAAANU"]
[Mon Jul 20 06:35:06.706833 2026] [security2:error] [pid 953991:tid 954151] [client 103.153.183.69:35402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../srv/.env"] [unique_id "al4V-q_X-kAXGDrIFaeoegAAAKM"], referer: https://www.google.com/
[Mon Jul 20 06:35:06.803864 2026] [security2:error] [pid 953991:tid 954224] [client 161.118.195.148:57044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V-q_X-kAXGDrIFaeoiAAAAOw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:07.159611 2026] [security2:error] [pid 953991:tid 954211] [client 34.73.38.214:60135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4V-6_X-kAXGDrIFaeorQAAAN8"]
[Mon Jul 20 06:35:07.233392 2026] [security2:error] [pid 953991:tid 954135] [client 104.234.53.70:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4V-6_X-kAXGDrIFaeosAAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:07.383177 2026] [security2:error] [pid 953991:tid 954151] [client 161.118.195.148:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V-6_X-kAXGDrIFaeowAAAAKM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:07.388956 2026] [security2:error] [pid 953991:tid 954209] [client 223.185.13.213:21558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V-6_X-kAXGDrIFaeovwAAAN0"]
[Mon Jul 20 06:35:07.389118 2026] [security2:error] [pid 953991:tid 954209] [client 223.185.13.213:21558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V-6_X-kAXGDrIFaeovwAAAN0"]
[Mon Jul 20 06:35:07.594565 2026] [security2:error] [pid 953991:tid 954229] [client 4.218.23.144:26881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4V-6_X-kAXGDrIFaeo0gAAAPE"]
[Mon Jul 20 06:35:07.681810 2026] [security2:error] [pid 953991:tid 954218] [client 77.110.127.138:50194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V-6_X-kAXGDrIFaeo2AAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:07.734578 2026] [security2:error] [pid 953991:tid 954165] [client 4.218.23.144:26881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4V-6_X-kAXGDrIFaeo2wAAALE"]
[Mon Jul 20 06:35:07.799769 2026] [security2:error] [pid 953991:tid 954139] [client 14.225.17.146:62740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4V-q_X-kAXGDrIFaeoEAAAAJc"], referer: http://cheesewithjam.com/Old
[Mon Jul 20 06:35:07.844665 2026] [security2:error] [pid 953991:tid 954181] [client 77.110.127.138:50240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V-6_X-kAXGDrIFaeo6gAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:07.873509 2026] [security2:error] [pid 953991:tid 954240] [client 213.152.162.79:44958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4V-6_X-kAXGDrIFaeo6wAAAPw"]
[Mon Jul 20 06:35:07.873639 2026] [security2:error] [pid 953991:tid 954240] [client 213.152.162.79:44958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4V-6_X-kAXGDrIFaeo6wAAAPw"]
[Mon Jul 20 06:35:07.924013 2026] [security2:error] [pid 953991:tid 954115] [remote 51.158.61.221:48358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4V-6_X-kAXGDrIFaeo8QAA63s"]
[Mon Jul 20 06:35:07.958121 2026] [security2:error] [pid 953991:tid 954239] [client 161.118.195.148:57871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V-6_X-kAXGDrIFaeo8gAAAPs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:08.168900 2026] [security2:error] [pid 953991:tid 953998] [remote 51.158.61.221:48358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4V_K_X-kAXGDrIFaepBQAAzwY"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:35:08.181060 2026] [security2:error] [pid 953991:tid 954136] [client 34.73.38.214:63824] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4V_K_X-kAXGDrIFaepBwAAAJQ"]
[Mon Jul 20 06:35:08.220301 2026] [security2:error] [pid 953991:tid 954168] [client 149.118.58.82:56470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-includes/version.php"] [unique_id "al4V_K_X-kAXGDrIFaepDAAAALQ"]
[Mon Jul 20 06:35:08.249715 2026] [security2:error] [pid 953991:tid 954140] [client 57.141.18.1:47684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V96_X-kAXGDrIFaenCQAAmCU"]
[Mon Jul 20 06:35:08.282678 2026] [security2:error] [pid 953991:tid 954247] [client 14.225.17.146:51924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4V-q_X-kAXGDrIFaeoZwAAAQM"], referer: http://fluidtemple.org/Old
[Mon Jul 20 06:35:08.401933 2026] [security2:error] [pid 953991:tid 954189] [client 77.110.127.138:50247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V_K_X-kAXGDrIFaepJQAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:08.402025 2026] [security2:error] [pid 953991:tid 954189] [client 77.110.127.138:50247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V_K_X-kAXGDrIFaepJQAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:08.530833 2026] [security2:error] [pid 953991:tid 954222] [client 161.118.195.148:58248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V_K_X-kAXGDrIFaepLwAAAOo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:08.536742 2026] [security2:error] [pid 953991:tid 954200] [client 223.237.130.40:54249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4V_K_X-kAXGDrIFaepHAAAANQ"]
[Mon Jul 20 06:35:08.566561 2026] [security2:error] [pid 953991:tid 954221] [client 77.110.127.138:50249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V_K_X-kAXGDrIFaepMgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:08.566650 2026] [security2:error] [pid 953991:tid 954221] [client 77.110.127.138:50249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V_K_X-kAXGDrIFaepMgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:08.614818 2026] [security2:error] [pid 953991:tid 953993] [remote 172.232.108.36:55406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "108.179.214.134"] [uri "/"] [unique_id "al4V_K_X-kAXGDrIFaepNQAA0gE"]
[Mon Jul 20 06:35:08.801933 2026] [security2:error] [pid 953991:tid 954140] [client 34.74.185.202:51211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4V_K_X-kAXGDrIFaepQgAAAJg"]
[Mon Jul 20 06:35:08.802614 2026] [security2:error] [pid 953991:tid 954195] [client 149.118.58.82:56796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-includes/functions.php"] [unique_id "al4V_K_X-kAXGDrIFaepRQAAAM8"]
[Mon Jul 20 06:35:08.871311 2026] [security2:error] [pid 953991:tid 954161] [client 57.141.18.68:30706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V-K_X-kAXGDrIFaenagAArVc"]
[Mon Jul 20 06:35:08.960403 2026] [security2:error] [pid 953991:tid 954091] [remote 176.56.118.182:39500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4V_K_X-kAXGDrIFaepUwAA7WM"]
[Mon Jul 20 06:35:09.108952 2026] [security2:error] [pid 953991:tid 954139] [client 161.118.195.148:58597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V_a_X-kAXGDrIFaepYAAAAJc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:09.131602 2026] [security2:error] [pid 953991:tid 954021] [remote 100.42.189.89:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V_a_X-kAXGDrIFaepYwAA8B0"]
[Mon Jul 20 06:35:09.132109 2026] [security2:error] [pid 953991:tid 954181] [client 77.110.127.138:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V_a_X-kAXGDrIFaepYgAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:09.189738 2026] [security2:error] [pid 953991:tid 954045] [remote 176.56.118.182:39500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4V_a_X-kAXGDrIFaepZgAA4jU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:35:09.364907 2026] [security2:error] [pid 953991:tid 954119] [remote 100.42.189.89:53262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4V_a_X-kAXGDrIFaepfQAAjn8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:35:09.380452 2026] [security2:error] [pid 953991:tid 954200] [client 149.118.58.82:57074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-includes/class-wp.php"] [unique_id "al4V_a_X-kAXGDrIFaepfwAAANQ"]
[Mon Jul 20 06:35:09.524139 2026] [security2:error] [pid 953991:tid 954196] [client 45.157.112.60:46243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4V_a_X-kAXGDrIFaepiAAAANA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:35:09.561521 2026] [security2:error] [pid 953991:tid 954167] [client 171.60.139.123:51526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V_a_X-kAXGDrIFaepiwAAALM"]
[Mon Jul 20 06:35:09.561633 2026] [security2:error] [pid 953991:tid 954167] [client 171.60.139.123:51526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4V_a_X-kAXGDrIFaepiwAAALM"]
[Mon Jul 20 06:35:09.585917 2026] [security2:error] [pid 953991:tid 954205] [client 34.74.185.202:54620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4V_a_X-kAXGDrIFaepjAAAANk"]
[Mon Jul 20 06:35:09.688662 2026] [security2:error] [pid 953991:tid 954239] [client 161.118.195.148:58935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V_a_X-kAXGDrIFaepkAAAAPs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:09.863790 2026] [security2:error] [pid 953991:tid 954158] [client 14.225.17.146:51547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4V_a_X-kAXGDrIFaepgwAAAKo"], referer: http://overloadcomedy.com/Old
[Mon Jul 20 06:35:09.891071 2026] [security2:error] [pid 953991:tid 954245] [client 197.186.66.42:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V_a_X-kAXGDrIFaepqgAAAQE"]
[Mon Jul 20 06:35:09.896112 2026] [security2:error] [pid 953991:tid 954245] [client 197.186.66.42:51301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4V_a_X-kAXGDrIFaepqgAAAQE"]
[Mon Jul 20 06:35:09.926621 2026] [security2:error] [pid 953991:tid 954213] [client 77.110.127.138:50253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V_a_X-kAXGDrIFaepsAAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:09.953454 2026] [security2:error] [pid 953991:tid 954231] [client 149.118.58.82:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-includes/option.php"] [unique_id "al4V_a_X-kAXGDrIFaepsgAAAPM"]
[Mon Jul 20 06:35:09.997284 2026] [security2:error] [pid 953991:tid 954174] [client 34.73.38.214:64944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4V_a_X-kAXGDrIFaepswAAALo"]
[Mon Jul 20 06:35:10.262323 2026] [security2:error] [pid 953991:tid 954122] [client 161.118.195.148:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V_q_X-kAXGDrIFaepwwAAAIY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:10.424466 2026] [security2:error] [pid 953991:tid 954186] [client 77.110.127.138:50262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V_q_X-kAXGDrIFaep1AAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:10.450961 2026] [security2:error] [pid 953991:tid 954121] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4V_a_X-kAXGDrIFaepjQAAAIU"]
[Mon Jul 20 06:35:10.520368 2026] [security2:error] [pid 953991:tid 954236] [client 39.48.81.23:57653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V_q_X-kAXGDrIFaep2wAAAPg"]
[Mon Jul 20 06:35:10.520477 2026] [security2:error] [pid 953991:tid 954236] [client 39.48.81.23:57653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4V_q_X-kAXGDrIFaep2wAAAPg"]
[Mon Jul 20 06:35:10.527235 2026] [security2:error] [pid 953991:tid 954177] [client 149.118.58.82:57717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-includes/post.php"] [unique_id "al4V_q_X-kAXGDrIFaep3QAAAL0"]
[Mon Jul 20 06:35:10.567562 2026] [security2:error] [pid 953991:tid 954135] [client 103.153.183.69:35402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../home/.env"] [unique_id "al4V_q_X-kAXGDrIFaep4gAAAJM"], referer: https://duckduckgo.com/?q=dx0hk
[Mon Jul 20 06:35:10.766425 2026] [security2:error] [pid 953991:tid 954204] [client 34.74.185.202:60996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4V_q_X-kAXGDrIFaep6gAAANg"]
[Mon Jul 20 06:35:10.809882 2026] [security2:error] [pid 953991:tid 954148] [client 77.110.127.138:50263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V_q_X-kAXGDrIFaep8AAAAKA"]
[Mon Jul 20 06:35:10.837179 2026] [security2:error] [pid 953991:tid 954142] [client 161.118.195.148:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V_q_X-kAXGDrIFaep8wAAAJo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:10.852495 2026] [security2:error] [pid 953991:tid 954164] [client 114.119.159.145:35637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.crmpfilms.com"] [uri "/blog/2016/08/27/files/stacks-image-d248a46-200x200.png"] [unique_id "al4V_q_X-kAXGDrIFaep9AAAALA"], referer: https://www.crmpfilms.com/blog/2016/08/27/files/stacks-image-d248a46-200x200.png
[Mon Jul 20 06:35:10.972689 2026] [security2:error] [pid 953991:tid 954144] [client 217.142.18.172:62566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V_q_X-kAXGDrIFaep_AAAAJw"]
[Mon Jul 20 06:35:10.973703 2026] [security2:error] [pid 953991:tid 954144] [client 217.142.18.172:62566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4V_q_X-kAXGDrIFaep_AAAAJw"]
[Mon Jul 20 06:35:10.976218 2026] [security2:error] [pid 953991:tid 954208] [client 77.110.127.138:50265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4V_q_X-kAXGDrIFaep_gAAANw"]
[Mon Jul 20 06:35:11.098021 2026] [security2:error] [pid 953991:tid 954229] [client 149.118.58.82:58084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-includes/user.php"] [unique_id "al4V_6_X-kAXGDrIFaeqCwAAAPE"]
[Mon Jul 20 06:35:11.165415 2026] [security2:error] [pid 953991:tid 954103] [remote 208.109.9.173:38212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4V_6_X-kAXGDrIFaeqFQAA528"]
[Mon Jul 20 06:35:11.231967 2026] [security2:error] [pid 953991:tid 954127] [client 14.225.17.146:56574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4V_6_X-kAXGDrIFaeqDAAAAIs"], referer: http://nextlvlmarketingco.com/Old
[Mon Jul 20 06:35:11.352779 2026] [security2:error] [pid 953991:tid 954248] [client 112.208.70.94:42515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V_6_X-kAXGDrIFaeqIQAAAQQ"]
[Mon Jul 20 06:35:11.352914 2026] [security2:error] [pid 953991:tid 954248] [client 112.208.70.94:42515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4V_6_X-kAXGDrIFaeqIQAAAQQ"]
[Mon Jul 20 06:35:11.404251 2026] [security2:error] [pid 953991:tid 954154] [client 14.225.17.146:50552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4V_K_X-kAXGDrIFaepWAAAAKY"], referer: http://onewingpictures.com/Old
[Mon Jul 20 06:35:11.411518 2026] [security2:error] [pid 953991:tid 954221] [client 161.118.195.148:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4V_6_X-kAXGDrIFaeqJAAAAOk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:11.417490 2026] [security2:error] [pid 953991:tid 954200] [client 77.110.127.138:50269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V_6_X-kAXGDrIFaeqJwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:11.417589 2026] [security2:error] [pid 953991:tid 954200] [client 77.110.127.138:50269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4V_6_X-kAXGDrIFaeqJwAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:11.502250 2026] [security2:error] [pid 953991:tid 954163] [client 34.74.185.202:50047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4V_6_X-kAXGDrIFaeqLQAAAK8"]
[Mon Jul 20 06:35:11.563177 2026] [security2:error] [pid 953991:tid 954099] [remote 208.109.9.173:38212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.9.109.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4V_6_X-kAXGDrIFaeqMAAAyWs"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:35:11.608455 2026] [security2:error] [pid 953991:tid 954210] [client 57.141.18.64:23144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V-q_X-kAXGDrIFaeojQAA3l4"]
[Mon Jul 20 06:35:11.720256 2026] [security2:error] [pid 953991:tid 954195] [client 34.73.38.214:64137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4V_6_X-kAXGDrIFaeqPQAAAM8"]
[Mon Jul 20 06:35:11.936620 2026] [security2:error] [pid 953991:tid 954223] [client 74.125.213.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onpoint-evsolutions.com"] [uri "/index.php"] [unique_id "al4V_6_X-kAXGDrIFaeqLwAA63E"]
[Mon Jul 20 06:35:11.988472 2026] [security2:error] [pid 953991:tid 954127] [client 161.118.195.148:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4V_6_X-kAXGDrIFaeqUwAAAIs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:12.098180 2026] [security2:error] [pid 953991:tid 954154] [client 34.74.185.202:61603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WAK_X-kAXGDrIFaeqXwAAAKY"]
[Mon Jul 20 06:35:12.160145 2026] [security2:error] [pid 953991:tid 954125] [client 77.110.127.138:50276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAK_X-kAXGDrIFaeqZwAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:12.160268 2026] [security2:error] [pid 953991:tid 954125] [client 77.110.127.138:50276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAK_X-kAXGDrIFaeqZwAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:12.178942 2026] [security2:error] [pid 953991:tid 954214] [client 152.39.182.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4V_a_X-kAXGDrIFaepmAAAAOI"]
[Mon Jul 20 06:35:12.325598 2026] [security2:error] [pid 953991:tid 954133] [client 77.110.127.138:50279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAK_X-kAXGDrIFaeqeQAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:12.325704 2026] [security2:error] [pid 953991:tid 954133] [client 77.110.127.138:50279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAK_X-kAXGDrIFaeqeQAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:12.531488 2026] [security2:error] [pid 953991:tid 954225] [client 34.74.185.202:62793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WAK_X-kAXGDrIFaeqigAAAO0"]
[Mon Jul 20 06:35:12.567426 2026] [security2:error] [pid 953991:tid 954169] [client 161.118.195.148:60850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WAK_X-kAXGDrIFaeqkAAAALU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:12.604675 2026] [security2:error] [pid 953991:tid 954238] [client 77.110.127.138:50281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAK_X-kAXGDrIFaeqkwAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:12.604781 2026] [security2:error] [pid 953991:tid 954238] [client 77.110.127.138:50281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAK_X-kAXGDrIFaeqkwAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:12.880482 2026] [security2:error] [pid 953991:tid 954037] [remote 72.167.132.114:36420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4WAK_X-kAXGDrIFaequwAApi0"]
[Mon Jul 20 06:35:12.993317 2026] [security2:error] [pid 953991:tid 954185] [client 34.73.38.214:50661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WAK_X-kAXGDrIFaeq2AAAAMU"]
[Mon Jul 20 06:35:12.994512 2026] [security2:error] [pid 953991:tid 954040] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WAK_X-kAXGDrIFaeq2QAAhzA"]
[Mon Jul 20 06:35:12.994631 2026] [security2:error] [pid 953991:tid 954123] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WAK_X-kAXGDrIFaeq2QAAhzA"]
[Mon Jul 20 06:35:13.005543 2026] [security2:error] [pid 953991:tid 954170] [client 77.110.127.138:50286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAa_X-kAXGDrIFaeq3AAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.005663 2026] [security2:error] [pid 953991:tid 954170] [client 77.110.127.138:50286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAa_X-kAXGDrIFaeq3AAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.137596 2026] [security2:error] [pid 953991:tid 954125] [client 161.118.195.148:61237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WAa_X-kAXGDrIFaeq6gAAAIk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:13.159903 2026] [security2:error] [pid 953991:tid 954200] [client 106.219.188.178:47761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WAa_X-kAXGDrIFaeq7gAAANQ"]
[Mon Jul 20 06:35:13.159997 2026] [security2:error] [pid 953991:tid 954200] [client 106.219.188.178:47761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WAa_X-kAXGDrIFaeq7gAAANQ"]
[Mon Jul 20 06:35:13.251267 2026] [security2:error] [pid 953991:tid 954216] [client 77.110.127.138:50292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAa_X-kAXGDrIFaeq9QAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.251354 2026] [security2:error] [pid 953991:tid 954216] [client 77.110.127.138:50292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAa_X-kAXGDrIFaeq9QAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.365523 2026] [security2:error] [pid 953991:tid 954171] [client 171.61.165.146:12704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WAa_X-kAXGDrIFaerBAAAALc"]
[Mon Jul 20 06:35:13.365622 2026] [security2:error] [pid 953991:tid 954171] [client 171.61.165.146:12704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WAa_X-kAXGDrIFaerBAAAALc"]
[Mon Jul 20 06:35:13.435767 2026] [security2:error] [pid 953991:tid 954088] [remote 72.167.132.114:36420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4WAa_X-kAXGDrIFaerCQAAomA"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:35:13.489958 2026] [security2:error] [pid 953991:tid 954180] [client 77.110.127.138:50296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WAa_X-kAXGDrIFaerEAAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.717912 2026] [security2:error] [pid 953991:tid 954163] [client 161.118.195.148:61605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WAa_X-kAXGDrIFaerLQAAAK8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:13.768889 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAa_X-kAXGDrIFaerLgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.769022 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAa_X-kAXGDrIFaerLgAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:13.812142 2026] [security2:error] [pid 953991:tid 954222] [client 223.237.130.40:54686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WAa_X-kAXGDrIFaerKAAAAOo"]
[Mon Jul 20 06:35:13.897664 2026] [security2:error] [pid 953991:tid 954209] [client 34.74.185.202:51278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WAa_X-kAXGDrIFaerPgAAAN0"]
[Mon Jul 20 06:35:14.015925 2026] [security2:error] [pid 953991:tid 954152] [client 77.110.127.138:50301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAq_X-kAXGDrIFaerRQAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:14.016038 2026] [security2:error] [pid 953991:tid 954152] [client 77.110.127.138:50301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAq_X-kAXGDrIFaerRQAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:14.250402 2026] [security2:error] [pid 953991:tid 954158] [client 187.108.85.186:55991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WAq_X-kAXGDrIFaerWAAAAKo"]
[Mon Jul 20 06:35:14.250550 2026] [security2:error] [pid 953991:tid 954158] [client 187.108.85.186:55991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WAq_X-kAXGDrIFaerWAAAAKo"]
[Mon Jul 20 06:35:14.293960 2026] [security2:error] [pid 953991:tid 954241] [client 161.118.195.148:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WAq_X-kAXGDrIFaerXQAAAP0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:14.460768 2026] [security2:error] [pid 953991:tid 954219] [client 34.74.185.202:58839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WAq_X-kAXGDrIFaerbwAAAOc"]
[Mon Jul 20 06:35:14.481379 2026] [security2:error] [pid 953991:tid 954160] [client 157.66.56.117:55717] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4WAq_X-kAXGDrIFaercAAAAKw"]
[Mon Jul 20 06:35:14.500151 2026] [security2:error] [pid 953991:tid 954160] [client 157.66.56.117:55717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4WAq_X-kAXGDrIFaercAAAAKw"]
[Mon Jul 20 06:35:14.669255 2026] [security2:error] [pid 953991:tid 954005] [remote 31.207.36.13:42202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4WAq_X-kAXGDrIFaergQAAkA0"]
[Mon Jul 20 06:35:14.706432 2026] [security2:error] [pid 953991:tid 954139] [client 77.110.127.138:50271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAq_X-kAXGDrIFaerhwAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:14.706554 2026] [security2:error] [pid 953991:tid 954139] [client 77.110.127.138:50271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WAq_X-kAXGDrIFaerhwAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:14.866737 2026] [security2:error] [pid 953991:tid 954125] [client 161.118.195.148:62384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WAq_X-kAXGDrIFaerlwAAAIk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:14.872239 2026] [security2:error] [pid 953991:tid 953999] [remote 31.207.36.13:42202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4WAq_X-kAXGDrIFaermAAA9wc"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:35:14.972374 2026] [security2:error] [pid 953991:tid 954239] [client 34.74.185.202:59031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WAq_X-kAXGDrIFaermwAAAPs"]
[Mon Jul 20 06:35:15.062837 2026] [security2:error] [pid 953991:tid 954242] [client 14.182.195.220:52249] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WA6_X-kAXGDrIFaerogAAAP4"]
[Mon Jul 20 06:35:15.067054 2026] [security2:error] [pid 953991:tid 954220] [client 14.182.195.220:52250] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WA6_X-kAXGDrIFaerowAAAOg"]
[Mon Jul 20 06:35:15.100949 2026] [security2:error] [pid 953991:tid 954176] [client 14.182.195.220:52251] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WA6_X-kAXGDrIFaerpQAAALw"]
[Mon Jul 20 06:35:15.115214 2026] [security2:error] [pid 953991:tid 954214] [client 34.73.38.214:49803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WA6_X-kAXGDrIFaerpgAAAOI"]
[Mon Jul 20 06:35:15.212007 2026] [security2:error] [pid 953991:tid 954178] [client 103.125.179.95:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WA6_X-kAXGDrIFaerrQAAAL4"]
[Mon Jul 20 06:35:15.212176 2026] [security2:error] [pid 953991:tid 954178] [client 103.125.179.95:58364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WA6_X-kAXGDrIFaerrQAAAL4"]
[Mon Jul 20 06:35:15.443098 2026] [security2:error] [pid 953991:tid 954188] [client 161.118.195.148:62747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WA6_X-kAXGDrIFaerwgAAAMg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:15.535074 2026] [security2:error] [pid 953991:tid 954197] [client 85.208.98.199:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/index.php"] [unique_id "al4WA6_X-kAXGDrIFaerngAAANE"]
[Mon Jul 20 06:35:15.535097 2026] [security2:error] [pid 953991:tid 954197] [client 85.208.98.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/index.php"] [unique_id "al4WA6_X-kAXGDrIFaerngAAANE"]
[Mon Jul 20 06:35:15.537802 2026] [security2:error] [pid 953991:tid 954203] [client 85.208.98.199:8450] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/robots.txt"] [unique_id "al4WA6_X-kAXGDrIFaernAAAANc"]
[Mon Jul 20 06:35:15.540838 2026] [security2:error] [pid 953991:tid 954216] [client 34.74.185.202:52753] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WA6_X-kAXGDrIFaerxgAAAOQ"]
[Mon Jul 20 06:35:15.750912 2026] [security2:error] [pid 953991:tid 954247] [client 85.208.98.199:23564] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aosta.nz"] [uri "/robots.txt"] [unique_id "al4WA6_X-kAXGDrIFaer1gAAAQM"]
[Mon Jul 20 06:35:15.815390 2026] [security2:error] [pid 953991:tid 954213] [client 34.74.185.202:51909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WA6_X-kAXGDrIFaer5wAAAOE"]
[Mon Jul 20 06:35:16.017362 2026] [security2:error] [pid 953991:tid 954228] [client 161.118.195.148:63102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WBK_X-kAXGDrIFaesAQAAAPA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:16.215645 2026] [security2:error] [pid 953991:tid 954188] [client 104.234.53.94:53277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WBK_X-kAXGDrIFaesDgAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:16.352063 2026] [security2:error] [pid 953991:tid 954215] [client 77.110.127.138:50325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBK_X-kAXGDrIFaesJgAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.372657 2026] [security2:error] [pid 953991:tid 954147] [client 57.141.18.25:59736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4V_6_X-kAXGDrIFaeqIgAAn3A"]
[Mon Jul 20 06:35:16.432938 2026] [security2:error] [pid 953991:tid 954036] [remote 162.19.86.63:40240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WBK_X-kAXGDrIFaesTAAAriw"]
[Mon Jul 20 06:35:16.433129 2026] [security2:error] [pid 953991:tid 954162] [client 162.19.86.63:40240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WBK_X-kAXGDrIFaesTAAAriw"]
[Mon Jul 20 06:35:16.532529 2026] [security2:error] [pid 953991:tid 954224] [client 34.74.185.202:55423] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WBK_X-kAXGDrIFaesVQAAAOw"]
[Mon Jul 20 06:35:16.567927 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBK_X-kAXGDrIFaesWwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.591724 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WBK_X-kAXGDrIFaesYAAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:16.762501 2026] [security2:error] [pid 953991:tid 954158] [client 77.110.127.138:50328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBK_X-kAXGDrIFaesbgAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.834281 2026] [security2:error] [pid 953991:tid 954198] [client 77.110.127.138:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBK_X-kAXGDrIFaesgQAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.834390 2026] [security2:error] [pid 953991:tid 954198] [client 77.110.127.138:50329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBK_X-kAXGDrIFaesgQAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.885901 2026] [security2:error] [pid 953991:tid 954185] [client 77.110.127.138:50293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBK_X-kAXGDrIFaeskAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.885997 2026] [security2:error] [pid 953991:tid 954185] [client 77.110.127.138:50293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBK_X-kAXGDrIFaeskAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:16.886627 2026] [security2:error] [pid 953991:tid 954162] [client 34.73.38.214:61589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WBK_X-kAXGDrIFaeskQAAAK4"]
[Mon Jul 20 06:35:16.933662 2026] [security2:error] [pid 953991:tid 954200] [client 37.66.192.75:59098] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/jetpack/jetpack_vendor/automattic/jetpack-forms/dist/contact-form/css/jetpack-forms-layout.css"] [unique_id "al4WBK_X-kAXGDrIFaeslgAAANQ"]
[Mon Jul 20 06:35:17.132175 2026] [security2:error] [pid 953991:tid 954210] [client 77.110.127.138:50331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBa_X-kAXGDrIFaesuQAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.164541 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:63834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WBa_X-kAXGDrIFaesxQAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:17.190065 2026] [security2:error] [pid 953991:tid 954215] [client 77.110.127.138:50297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBa_X-kAXGDrIFaesxgAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.190170 2026] [security2:error] [pid 953991:tid 954215] [client 77.110.127.138:50297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBa_X-kAXGDrIFaesxgAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.261739 2026] [security2:error] [pid 953991:tid 954171] [client 34.74.185.202:59300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WBa_X-kAXGDrIFaes0gAAALc"]
[Mon Jul 20 06:35:17.344218 2026] [security2:error] [pid 953991:tid 954209] [client 77.110.127.138:50334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBa_X-kAXGDrIFaes2wAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.344319 2026] [security2:error] [pid 953991:tid 954209] [client 77.110.127.138:50334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBa_X-kAXGDrIFaes2wAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.399503 2026] [security2:error] [pid 953991:tid 954155] [client 223.185.13.213:5641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WBa_X-kAXGDrIFaes3gAAAKc"]
[Mon Jul 20 06:35:17.399640 2026] [security2:error] [pid 953991:tid 954155] [client 223.185.13.213:5641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WBa_X-kAXGDrIFaes3gAAAKc"]
[Mon Jul 20 06:35:17.442236 2026] [security2:error] [pid 953991:tid 954172] [client 34.74.185.202:59998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WBa_X-kAXGDrIFaes5AAAALg"]
[Mon Jul 20 06:35:17.605992 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBa_X-kAXGDrIFaes6gAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.742833 2026] [security2:error] [pid 953991:tid 954125] [client 161.118.195.148:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WBa_X-kAXGDrIFaes9AAAAIk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:17.829905 2026] [security2:error] [pid 953991:tid 954193] [client 85.208.98.199:8450] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/"] [unique_id "al4WBa_X-kAXGDrIFaes-QAAAM0"]
[Mon Jul 20 06:35:17.934084 2026] [security2:error] [pid 953991:tid 954175] [client 77.110.127.138:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBa_X-kAXGDrIFaetBgAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.934193 2026] [security2:error] [pid 953991:tid 954175] [client 77.110.127.138:50341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBa_X-kAXGDrIFaetBgAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:17.962260 2026] [security2:error] [pid 953991:tid 954238] [client 77.110.127.138:50303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBa_X-kAXGDrIFaetCgAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:18.135455 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WBq_X-kAXGDrIFaetEwAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:18.215817 2026] [security2:error] [pid 953991:tid 954195] [client 34.74.185.202:55047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.robertpierson.org"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WBq_X-kAXGDrIFaetIQAAAM8"]
[Mon Jul 20 06:35:18.216092 2026] [security2:error] [pid 953991:tid 954146] [client 34.74.185.202:57091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WBq_X-kAXGDrIFaetIgAAAJ4"]
[Mon Jul 20 06:35:18.230372 2026] [security2:error] [pid 953991:tid 954072] [remote 160.187.68.132:55630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4WBq_X-kAXGDrIFaetIAAA8lA"]
[Mon Jul 20 06:35:18.313066 2026] [security2:error] [pid 953991:tid 954206] [client 77.110.127.138:50311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBq_X-kAXGDrIFaetKgAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:18.313170 2026] [security2:error] [pid 953991:tid 954206] [client 77.110.127.138:50311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBq_X-kAXGDrIFaetKgAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:18.313941 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:64539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WBq_X-kAXGDrIFaetKwAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:18.364934 2026] [security2:error] [pid 953991:tid 954178] [client 77.110.127.138:50313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBq_X-kAXGDrIFaetMgAAAL4"]
[Mon Jul 20 06:35:18.365207 2026] [security2:error] [pid 953991:tid 954178] [client 77.110.127.138:50313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBq_X-kAXGDrIFaetMgAAAL4"]
[Mon Jul 20 06:35:18.415770 2026] [security2:error] [pid 953991:tid 954156] [client 77.110.127.138:50317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBq_X-kAXGDrIFaetNAAAAKg"]
[Mon Jul 20 06:35:18.415906 2026] [security2:error] [pid 953991:tid 954156] [client 77.110.127.138:50317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WBq_X-kAXGDrIFaetNAAAAKg"]
[Mon Jul 20 06:35:18.554283 2026] [security2:error] [pid 953991:tid 954215] [client 34.73.38.214:59688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WBq_X-kAXGDrIFaetQAAAAOM"]
[Mon Jul 20 06:35:18.649409 2026] [security2:error] [pid 953991:tid 954121] [client 34.74.185.202:52893] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WBq_X-kAXGDrIFaetRwAAAIU"]
[Mon Jul 20 06:35:18.714477 2026] [security2:error] [pid 953991:tid 954116] [remote 160.187.68.132:55630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4WBq_X-kAXGDrIFaetSwAAmXw"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:35:18.888144 2026] [security2:error] [pid 953991:tid 954155] [client 161.118.195.148:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WBq_X-kAXGDrIFaetVAAAAKc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:18.909067 2026] [security2:error] [pid 953991:tid 954219] [client 27.71.121.77:63919] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.ttf"] [unique_id "al4WBq_X-kAXGDrIFaetWAAAAOc"]
[Mon Jul 20 06:35:18.943836 2026] [security2:error] [pid 953991:tid 954161] [client 84.181.0.190:42422] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufj5qw54a.woff2"] [unique_id "al4WBq_X-kAXGDrIFaetXAAAAK0"]
[Mon Jul 20 06:35:18.953226 2026] [security2:error] [pid 953991:tid 954127] [client 2.124.108.221:52742] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.ttf"] [unique_id "al4WBq_X-kAXGDrIFaetXQAAAIs"]
[Mon Jul 20 06:35:18.973371 2026] [security2:error] [pid 953991:tid 954230] [client 96.55.196.95:35592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff2"] [unique_id "al4WBq_X-kAXGDrIFaetXwAAAPI"]
[Mon Jul 20 06:35:18.989980 2026] [security2:error] [pid 953991:tid 954228] [client 14.170.85.161:46907] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufo5qw54a.woff2"] [unique_id "al4WBq_X-kAXGDrIFaetZQAAAPA"]
[Mon Jul 20 06:35:19.020777 2026] [security2:error] [pid 953991:tid 954180] [client 90.109.122.109:55400] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetaQAAAMA"]
[Mon Jul 20 06:35:19.020788 2026] [security2:error] [pid 953991:tid 954188] [client 64.118.254.110:44696] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4WB6_X-kAXGDrIFaetagAAAMg"]
[Mon Jul 20 06:35:19.030441 2026] [security2:error] [pid 953991:tid 954136] [client 64.72.246.13:46048] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkankawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetbQAAAJQ"]
[Mon Jul 20 06:35:19.033052 2026] [security2:error] [pid 953991:tid 954122] [client 109.153.89.35:35876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.woff"] [unique_id "al4WB6_X-kAXGDrIFaetbwAAAIY"]
[Mon Jul 20 06:35:19.066813 2026] [security2:error] [pid 953991:tid 954186] [client 79.117.239.225:54406] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetdAAAAMY"]
[Mon Jul 20 06:35:19.088414 2026] [security2:error] [pid 953991:tid 954237] [client 2.34.85.166:33592] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkenkawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetdwAAAPk"]
[Mon Jul 20 06:35:19.102897 2026] [security2:error] [pid 953991:tid 954135] [client 83.202.235.96:44840] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbxkawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaeteAAAAJM"]
[Mon Jul 20 06:35:19.107209 2026] [security2:error] [pid 953991:tid 954150] [client 90.247.137.148:43254] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4WB6_X-kAXGDrIFaetegAAAKI"]
[Mon Jul 20 06:35:19.108827 2026] [security2:error] [pid 953991:tid 954192] [client 95.233.7.238:37950] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.woff"] [unique_id "al4WB6_X-kAXGDrIFaeteQAAAMw"]
[Mon Jul 20 06:35:19.114774 2026] [security2:error] [pid 953991:tid 954242] [client 85.245.104.94:43268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.woff"] [unique_id "al4WB6_X-kAXGDrIFaetfAAAAP4"]
[Mon Jul 20 06:35:19.114821 2026] [security2:error] [pid 953991:tid 954158] [client 46.6.127.25:61980] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.eot"] [unique_id "al4WB6_X-kAXGDrIFaetewAAAKo"]
[Mon Jul 20 06:35:19.141903 2026] [security2:error] [pid 953991:tid 954217] [client 81.220.82.125:5798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3oubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetfwAAAOU"]
[Mon Jul 20 06:35:19.148587 2026] [security2:error] [pid 953991:tid 954225] [client 90.243.64.35:60268] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3cubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetgwAAAO0"]
[Mon Jul 20 06:35:19.156924 2026] [security2:error] [pid 953991:tid 954235] [client 79.192.17.233:50412] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4WB6_X-kAXGDrIFaethQAAAPc"]
[Mon Jul 20 06:35:19.160022 2026] [security2:error] [pid 953991:tid 954238] [client 34.74.185.202:59998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WB6_X-kAXGDrIFaethwAAAPo"]
[Mon Jul 20 06:35:19.162674 2026] [security2:error] [pid 953991:tid 954206] [client 14.191.83.24:19057] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.woff"] [unique_id "al4WB6_X-kAXGDrIFaetiAAAANo"]
[Mon Jul 20 06:35:19.185024 2026] [security2:error] [pid 953991:tid 954181] [client 110.54.204.217:56860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4WB6_X-kAXGDrIFaetjwAAAME"]
[Mon Jul 20 06:35:19.219123 2026] [security2:error] [pid 953991:tid 954183] [client 50.98.50.203:51484] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkahkawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetkwAAAMM"]
[Mon Jul 20 06:35:19.238136 2026] [security2:error] [pid 953991:tid 954212] [client 194.99.85.79:11434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcnkawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetlgAAAOA"]
[Mon Jul 20 06:35:19.247503 2026] [security2:error] [pid 953991:tid 954146] [client 78.85.4.59:5141] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3iubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetmAAAAJ4"]
[Mon Jul 20 06:35:19.270463 2026] [security2:error] [pid 953991:tid 954193] [client 31.189.89.255:48924] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4WB6_X-kAXGDrIFaetmQAAAM0"]
[Mon Jul 20 06:35:19.280924 2026] [security2:error] [pid 953991:tid 954144] [client 46.6.120.121:55708] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamaxkubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetmgAAAJw"]
[Mon Jul 20 06:35:19.311107 2026] [security2:error] [pid 953991:tid 954246] [client 98.254.35.77:37859] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.eot"] [unique_id "al4WB6_X-kAXGDrIFaetmwAAAQI"]
[Mon Jul 20 06:35:19.321141 2026] [security2:error] [pid 953991:tid 954178] [client 85.85.48.16:59146] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff"] [unique_id "al4WB6_X-kAXGDrIFaetnQAAAL4"]
[Mon Jul 20 06:35:19.324468 2026] [security2:error] [pid 953991:tid 954172] [client 119.93.99.225:6639] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkcxkawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetngAAALg"]
[Mon Jul 20 06:35:19.325978 2026] [security2:error] [pid 953991:tid 954177] [client 86.210.61.137:38870] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufb5qw54a.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetoAAAAL0"]
[Mon Jul 20 06:35:19.347808 2026] [security2:error] [pid 953991:tid 954125] [client 95.236.219.98:40408] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4WB6_X-kAXGDrIFaetowAAAIk"]
[Mon Jul 20 06:35:19.351517 2026] [security2:error] [pid 953991:tid 954175] [client 50.99.29.164:33174] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3gubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetpAAAALs"]
[Mon Jul 20 06:35:19.354257 2026] [security2:error] [pid 953991:tid 954153] [client 87.17.64.166:49242] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3kubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetpgAAAKU"]
[Mon Jul 20 06:35:19.381970 2026] [security2:error] [pid 953991:tid 954151] [client 2.82.241.137:58524] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluamawcubgee.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetqgAAAKM"]
[Mon Jul 20 06:35:19.382089 2026] [security2:error] [pid 953991:tid 954199] [client 125.166.75.107:34674] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufd5qw54a.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetqQAAANM"]
[Mon Jul 20 06:35:19.423875 2026] [security2:error] [pid 953991:tid 954143] [client 91.237.55.160:38596] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufn5qu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetrgAAAJs"]
[Mon Jul 20 06:35:19.423875 2026] [security2:error] [pid 953991:tid 954245] [client 37.61.120.35:8726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkchkawzu.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetrwAAAQE"]
[Mon Jul 20 06:35:19.456616 2026] [security2:error] [pid 953991:tid 954237] [client 34.74.185.202:61294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WB6_X-kAXGDrIFaetswAAAPk"]
[Mon Jul 20 06:35:19.466933 2026] [security2:error] [pid 953991:tid 954224] [client 161.118.195.148:65243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WB6_X-kAXGDrIFaettAAAAOw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:19.468666 2026] [security2:error] [pid 953991:tid 954168] [client 31.47.8.119:48462] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-solid-900.eot"] [unique_id "al4WB6_X-kAXGDrIFaettQAAALQ"]
[Mon Jul 20 06:35:19.568335 2026] [security2:error] [pid 953991:tid 954191] [client 178.217.197.24:37504] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufa5qw54a.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetuwAAAMs"]
[Mon Jul 20 06:35:19.607541 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WB6_X-kAXGDrIFaetvAAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:19.607672 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WB6_X-kAXGDrIFaetvAAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:19.613104 2026] [security2:error] [pid 953991:tid 954140] [client 189.138.117.28:51954] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.woff2"] [unique_id "al4WB6_X-kAXGDrIFaetvgAAAJg"]
[Mon Jul 20 06:35:19.655050 2026] [security2:error] [pid 953991:tid 954023] [remote 217.182.128.41:36810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WB6_X-kAXGDrIFaetwQAAwR8"]
[Mon Jul 20 06:35:19.725997 2026] [security2:error] [pid 953991:tid 954171] [client 152.58.191.29:53227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WBq_X-kAXGDrIFaetOwAAALc"]
[Mon Jul 20 06:35:19.731955 2026] [security2:error] [pid 953991:tid 954156] [client 196.84.26.136:2709] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.ttf"] [unique_id "al4WB6_X-kAXGDrIFaetxwAAAKg"]
[Mon Jul 20 06:35:19.759568 2026] [security2:error] [pid 953991:tid 954242] [client 13.42.250.172:37990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4WB6_X-kAXGDrIFaetyAAAAP4"]
[Mon Jul 20 06:35:19.759680 2026] [security2:error] [pid 953991:tid 954242] [client 13.42.250.172:37990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4WB6_X-kAXGDrIFaetyAAAAP4"]
[Mon Jul 20 06:35:19.883259 2026] [security2:error] [pid 953991:tid 954096] [remote 217.182.128.41:36810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WB6_X-kAXGDrIFaet0gAArmg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:35:19.908510 2026] [security2:error] [pid 953991:tid 954128] [client 88.7.139.153:56276] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.eot"] [unique_id "al4WB6_X-kAXGDrIFaet1gAAAIw"]
[Mon Jul 20 06:35:20.002273 2026] [security2:error] [pid 953991:tid 954143] [client 34.74.185.202:56607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WCK_X-kAXGDrIFaet3AAAAJs"]
[Mon Jul 20 06:35:20.041539 2026] [security2:error] [pid 953991:tid 954238] [client 161.118.195.148:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WCK_X-kAXGDrIFaet4AAAAPo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:20.140515 2026] [security2:error] [pid 953991:tid 954170] [client 45.224.205.239:20442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-brands-400.eot"] [unique_id "al4WCK_X-kAXGDrIFaet6AAAALY"]
[Mon Jul 20 06:35:20.145956 2026] [security2:error] [pid 953991:tid 954149] [client 171.60.139.123:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WCK_X-kAXGDrIFaet5wAAAKE"]
[Mon Jul 20 06:35:20.146093 2026] [security2:error] [pid 953991:tid 954149] [client 171.60.139.123:52093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WCK_X-kAXGDrIFaet5wAAAKE"]
[Mon Jul 20 06:35:20.151469 2026] [security2:error] [pid 953991:tid 954131] [client 37.100.185.135:60352] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/WooCommerce.ttf"] [unique_id "al4WCK_X-kAXGDrIFaet6QAAAI8"]
[Mon Jul 20 06:35:20.165055 2026] [security2:error] [pid 953991:tid 954121] [client 34.73.38.214:61144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.puk.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WCK_X-kAXGDrIFaet6wAAAIU"]
[Mon Jul 20 06:35:20.178692 2026] [security2:error] [pid 953991:tid 954194] [client 154.125.134.143:47778] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/font-awesome/webfonts/fa-regular-400.ttf"] [unique_id "al4WCK_X-kAXGDrIFaet7AAAAM4"]
[Mon Jul 20 06:35:20.189125 2026] [security2:error] [pid 953991:tid 954154] [client 57.141.18.53:63130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WA6_X-kAXGDrIFaerzAAApiI"]
[Mon Jul 20 06:35:20.191909 2026] [security2:error] [pid 953991:tid 954164] [client 74.208.214.194:58272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WCK_X-kAXGDrIFaet8gAAALA"]
[Mon Jul 20 06:35:20.339867 2026] [security2:error] [pid 953991:tid 954179] [client 57.141.18.47:47206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WA6_X-kAXGDrIFaer8wAAvy8"]
[Mon Jul 20 06:35:20.363904 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WCK_X-kAXGDrIFaeuBQAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:20.413780 2026] [security2:error] [pid 953991:tid 954129] [client 77.110.127.138:50330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCK_X-kAXGDrIFaeuDQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:20.413877 2026] [security2:error] [pid 953991:tid 954129] [client 77.110.127.138:50330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCK_X-kAXGDrIFaeuDQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:20.428762 2026] [security2:error] [pid 953991:tid 954214] [client 197.186.66.42:51806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WCK_X-kAXGDrIFaeuEwAAAOI"]
[Mon Jul 20 06:35:20.429482 2026] [security2:error] [pid 953991:tid 954214] [client 197.186.66.42:51806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WCK_X-kAXGDrIFaeuEwAAAOI"]
[Mon Jul 20 06:35:20.509399 2026] [security2:error] [pid 953991:tid 954190] [client 94.180.35.74:48738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo7cnqeu92fr1me7ksn66agldtyluama3-ubgee.woff2"] [unique_id "al4WCK_X-kAXGDrIFaeuGQAAAMo"]
[Mon Jul 20 06:35:20.529672 2026] [security2:error] [pid 953991:tid 954205] [client 85.172.90.55:5454] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/robotoslab-bngmuxzytxpivibgjjsb6ufc5qw54a.woff2"] [unique_id "al4WCK_X-kAXGDrIFaeuHgAAANk"]
[Mon Jul 20 06:35:20.615277 2026] [security2:error] [pid 953991:tid 954143] [client 161.118.195.148:49605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WCK_X-kAXGDrIFaeuJQAAAJs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:20.701279 2026] [security2:error] [pid 953991:tid 954204] [client 34.74.185.202:50340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WCK_X-kAXGDrIFaeuLwAAANg"]
[Mon Jul 20 06:35:20.866097 2026] [security2:error] [pid 953991:tid 954198] [client 149.118.58.82:64165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.ggb.jiv.mybluehost.me"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4WCK_X-kAXGDrIFaeuRQAAANI"]
[Mon Jul 20 06:35:21.035808 2026] [security2:error] [pid 953991:tid 954125] [client 181.42.176.238:7318] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/assets/lib/eicons/fonts/eicons.eot"] [unique_id "al4WCa_X-kAXGDrIFaeuUgAAAIk"]
[Mon Jul 20 06:35:21.101505 2026] [security2:error] [pid 953991:tid 954209] [client 34.74.185.202:54633] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WCa_X-kAXGDrIFaeuWwAAAN0"]
[Mon Jul 20 06:35:21.116189 2026] [security2:error] [pid 953991:tid 954192] [client 39.48.81.23:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeuXAAAAMw"]
[Mon Jul 20 06:35:21.116294 2026] [security2:error] [pid 953991:tid 954192] [client 39.48.81.23:58166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeuXAAAAMw"]
[Mon Jul 20 06:35:21.138491 2026] [security2:error] [pid 953991:tid 954075] [remote 72.167.132.114:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeuXwAAiFM"]
[Mon Jul 20 06:35:21.138642 2026] [security2:error] [pid 953991:tid 954124] [client 72.167.132.114:52940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeuXwAAiFM"]
[Mon Jul 20 06:35:21.197252 2026] [security2:error] [pid 953991:tid 954194] [client 161.118.195.148:49971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WCa_X-kAXGDrIFaeuZQAAAM4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:21.327549 2026] [security2:error] [pid 953991:tid 954198] [client 13.42.250.172:36569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeubQAAANI"]
[Mon Jul 20 06:35:21.327649 2026] [security2:error] [pid 953991:tid 954198] [client 13.42.250.172:36569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeubQAAANI"]
[Mon Jul 20 06:35:21.490501 2026] [security2:error] [pid 953991:tid 954185] [client 77.110.127.138:50338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCa_X-kAXGDrIFaeufgAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:21.490609 2026] [security2:error] [pid 953991:tid 954185] [client 77.110.127.138:50338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCa_X-kAXGDrIFaeufgAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:21.519358 2026] [security2:error] [pid 953991:tid 954172] [client 217.142.18.172:39286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeufwAAALg"]
[Mon Jul 20 06:35:21.519467 2026] [security2:error] [pid 953991:tid 954172] [client 217.142.18.172:39286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WCa_X-kAXGDrIFaeufwAAALg"]
[Mon Jul 20 06:35:21.559305 2026] [security2:error] [pid 953991:tid 954193] [client 34.74.185.202:54515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WCa_X-kAXGDrIFaeuhAAAAM0"]
[Mon Jul 20 06:35:21.777145 2026] [security2:error] [pid 953991:tid 954143] [client 161.118.195.148:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WCa_X-kAXGDrIFaeulAAAAJs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:21.981117 2026] [security2:error] [pid 953991:tid 954224] [client 34.74.185.202:65529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.roguedragonstudio.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WCa_X-kAXGDrIFaeunAAAAOw"]
[Mon Jul 20 06:35:21.994521 2026] [security2:error] [pid 953991:tid 954202] [client 114.119.129.33:60209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/category/fantasy/page/2"] [unique_id "al4WCa_X-kAXGDrIFaeunQAAANY"], referer: https://omenana.com/category/fantasy?amp
[Mon Jul 20 06:35:22.358251 2026] [security2:error] [pid 953991:tid 954193] [client 161.118.195.148:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WCq_X-kAXGDrIFaeuxQAAAM0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:22.409183 2026] [security2:error] [pid 953991:tid 954176] [client 77.110.127.138:50377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WCq_X-kAXGDrIFaeuywAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.613703 2026] [security2:error] [pid 953991:tid 954223] [client 77.110.127.138:50379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCq_X-kAXGDrIFaeu6AAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.613803 2026] [security2:error] [pid 953991:tid 954223] [client 77.110.127.138:50379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCq_X-kAXGDrIFaeu6AAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.621384 2026] [security2:error] [pid 953991:tid 954152] [client 89.82.122.56:38074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/woocommerce/assets/fonts/star.ttf"] [unique_id "al4WCq_X-kAXGDrIFaeu6QAAAKQ"]
[Mon Jul 20 06:35:22.756963 2026] [security2:error] [pid 953991:tid 954203] [client 77.110.127.138:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCq_X-kAXGDrIFaeu9wAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.757169 2026] [security2:error] [pid 953991:tid 954203] [client 77.110.127.138:50353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCq_X-kAXGDrIFaeu9wAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.908544 2026] [security2:error] [pid 953991:tid 954234] [client 77.110.127.138:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCq_X-kAXGDrIFaevAwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.908620 2026] [security2:error] [pid 953991:tid 954234] [client 77.110.127.138:50382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WCq_X-kAXGDrIFaevAwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:22.913353 2026] [security2:error] [pid 953991:tid 954160] [client 138.68.143.180:64799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4WCq_X-kAXGDrIFaevAAAAAKw"]
[Mon Jul 20 06:35:22.935719 2026] [security2:error] [pid 953991:tid 954194] [client 161.118.195.148:51094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WCq_X-kAXGDrIFaevBQAAAM4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:23.059898 2026] [security2:error] [pid 953991:tid 954202] [client 77.110.127.138:50383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevDwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.060000 2026] [security2:error] [pid 953991:tid 954202] [client 77.110.127.138:50383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevDwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.158140 2026] [security2:error] [pid 953991:tid 954132] [client 50.116.65.227:11262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4WCq_X-kAXGDrIFaeu-QAAAJA"]
[Mon Jul 20 06:35:23.169181 2026] [security2:error] [pid 953991:tid 954205] [client 223.237.130.40:55181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WC6_X-kAXGDrIFaevDAAAANk"]
[Mon Jul 20 06:35:23.195686 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevHQAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.195793 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:50384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevHQAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.248393 2026] [security2:error] [pid 953991:tid 954147] [client 220.181.108.105:35689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4WC6_X-kAXGDrIFaevHAAAnxI"]
[Mon Jul 20 06:35:23.354831 2026] [security2:error] [pid 953991:tid 954220] [client 57.141.18.22:29682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WBq_X-kAXGDrIFaetVgAA6HE"]
[Mon Jul 20 06:35:23.370266 2026] [security2:error] [pid 953991:tid 954225] [client 50.116.65.227:11278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4WC6_X-kAXGDrIFaevGgAAAO0"]
[Mon Jul 20 06:35:23.482846 2026] [security2:error] [pid 953991:tid 954192] [client 138.68.143.180:64845] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4WC6_X-kAXGDrIFaevNQAAAMw"]
[Mon Jul 20 06:35:23.521874 2026] [security2:error] [pid 953991:tid 954242] [client 161.118.195.148:51467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WC6_X-kAXGDrIFaevOAAAAP4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:23.614094 2026] [security2:error] [pid 953991:tid 954117] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WC6_X-kAXGDrIFaevOQAAt30"]
[Mon Jul 20 06:35:23.614257 2026] [security2:error] [pid 953991:tid 954171] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WC6_X-kAXGDrIFaevOQAAt30"]
[Mon Jul 20 06:35:23.723294 2026] [security2:error] [pid 953991:tid 954232] [client 106.219.188.178:3285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WC6_X-kAXGDrIFaevXgAAAPQ"]
[Mon Jul 20 06:35:23.723387 2026] [security2:error] [pid 953991:tid 954232] [client 106.219.188.178:3285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WC6_X-kAXGDrIFaevXgAAAPQ"]
[Mon Jul 20 06:35:23.739956 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevYAAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.740038 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:50389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevYAAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.914300 2026] [security2:error] [pid 953991:tid 954217] [client 77.110.127.138:50391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevfQAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:23.914412 2026] [security2:error] [pid 953991:tid 954217] [client 77.110.127.138:50391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WC6_X-kAXGDrIFaevfQAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:24.108689 2026] [security2:error] [pid 953991:tid 954220] [client 161.118.195.148:51784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WDK_X-kAXGDrIFaevjQAAAOg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:24.176622 2026] [security2:error] [pid 953991:tid 954180] [client 24.212.51.235:43896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkbnka.woff2"] [unique_id "al4WDK_X-kAXGDrIFaevmAAAAMA"]
[Mon Jul 20 06:35:24.203867 2026] [security2:error] [pid 953991:tid 954152] [client 77.110.127.138:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WDK_X-kAXGDrIFaevmgAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:24.203970 2026] [security2:error] [pid 953991:tid 954152] [client 77.110.127.138:50392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WDK_X-kAXGDrIFaevmgAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:24.681914 2026] [security2:error] [pid 953991:tid 954230] [client 161.118.195.148:52189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WDK_X-kAXGDrIFaevwAAAAPI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:24.755471 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WDK_X-kAXGDrIFaevxwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:24.920506 2026] [security2:error] [pid 953991:tid 954136] [client 43.157.98.187:46470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.98.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4WDK_X-kAXGDrIFaev1wAAAJQ"]
[Mon Jul 20 06:35:25.034719 2026] [security2:error] [pid 953991:tid 954216] [client 187.108.85.186:56521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WDa_X-kAXGDrIFaev3QAAAOQ"]
[Mon Jul 20 06:35:25.034847 2026] [security2:error] [pid 953991:tid 954216] [client 187.108.85.186:56521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WDa_X-kAXGDrIFaev3QAAAOQ"]
[Mon Jul 20 06:35:25.097017 2026] [security2:error] [pid 953991:tid 954170] [client 112.208.70.94:42980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WDa_X-kAXGDrIFaev4gAAALY"]
[Mon Jul 20 06:35:25.097134 2026] [security2:error] [pid 953991:tid 954170] [client 112.208.70.94:42980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WDa_X-kAXGDrIFaev4gAAALY"]
[Mon Jul 20 06:35:25.256780 2026] [security2:error] [pid 953991:tid 954225] [client 161.118.195.148:52565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WDa_X-kAXGDrIFaev7wAAAO0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:25.338336 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WDa_X-kAXGDrIFaev9AAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:25.338435 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WDa_X-kAXGDrIFaev9AAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:25.471350 2026] [security2:error] [pid 953991:tid 954228] [client 114.119.147.6:56965] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.safe-systems.net"] [uri "/nextbit.mx/portafolio/photo/full-3-info.html"] [unique_id "al4WDa_X-kAXGDrIFaewAAAAAPA"], referer: https://www.safe-systems.net/nextbit.mx/portafolio/photo/full-4-info.html
[Mon Jul 20 06:35:25.831006 2026] [security2:error] [pid 953991:tid 954141] [client 161.118.195.148:52938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WDa_X-kAXGDrIFaewHQAAAJk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:25.924028 2026] [security2:error] [pid 953991:tid 954208] [client 103.125.179.95:58828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WDa_X-kAXGDrIFaewKQAAANw"]
[Mon Jul 20 06:35:25.925017 2026] [security2:error] [pid 953991:tid 954208] [client 103.125.179.95:58828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WDa_X-kAXGDrIFaewKQAAANw"]
[Mon Jul 20 06:35:26.161405 2026] [security2:error] [pid 953991:tid 954184] [client 77.110.127.138:50402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WDq_X-kAXGDrIFaewNwAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:26.161499 2026] [security2:error] [pid 953991:tid 954184] [client 77.110.127.138:50402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WDq_X-kAXGDrIFaewNwAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:26.298774 2026] [security2:error] [pid 953991:tid 954164] [client 57.141.18.115:49892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WCa_X-kAXGDrIFaeukgAAsEk"]
[Mon Jul 20 06:35:26.406394 2026] [security2:error] [pid 953991:tid 954141] [client 161.118.195.148:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WDq_X-kAXGDrIFaewWgAAAJk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:26.837370 2026] [security2:error] [pid 953991:tid 954051] [remote 173.212.252.15:57150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4WDq_X-kAXGDrIFaewegAA2Ts"]
[Mon Jul 20 06:35:26.922843 2026] [security2:error] [pid 953991:tid 954227] [client 77.110.127.138:50408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WDq_X-kAXGDrIFaewiAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:26.982349 2026] [security2:error] [pid 953991:tid 954190] [client 161.118.195.148:53691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WDq_X-kAXGDrIFaewlAAAAMo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:27.049410 2026] [security2:error] [pid 953991:tid 954066] [remote 173.212.252.15:57150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4WD6_X-kAXGDrIFaewmwAAxko"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:35:27.149724 2026] [security2:error] [pid 953991:tid 954130] [client 13.42.250.172:21428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4WD6_X-kAXGDrIFaewoAAAAI4"]
[Mon Jul 20 06:35:27.149855 2026] [security2:error] [pid 953991:tid 954130] [client 13.42.250.172:21428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4WD6_X-kAXGDrIFaewoAAAAI4"]
[Mon Jul 20 06:35:27.531181 2026] [security2:error] [pid 953991:tid 954223] [client 13.42.250.172:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4WD6_X-kAXGDrIFaewxgAAAOs"]
[Mon Jul 20 06:35:27.531268 2026] [security2:error] [pid 953991:tid 954223] [client 13.42.250.172:62395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4WD6_X-kAXGDrIFaewxgAAAOs"]
[Mon Jul 20 06:35:27.560227 2026] [security2:error] [pid 953991:tid 954154] [client 161.118.195.148:54112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WD6_X-kAXGDrIFaewywAAAKY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:27.668210 2026] [security2:error] [pid 953991:tid 954140] [client 34.74.185.202:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WD6_X-kAXGDrIFaew0QAAAJg"]
[Mon Jul 20 06:35:27.691613 2026] [security2:error] [pid 953991:tid 954130] [client 77.110.127.138:50390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WD6_X-kAXGDrIFaew0wAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:27.691721 2026] [security2:error] [pid 953991:tid 954130] [client 77.110.127.138:50390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WD6_X-kAXGDrIFaew0wAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:27.819160 2026] [security2:error] [pid 953991:tid 954089] [remote 47.128.58.208:30016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gertoger.org"] [uri "/tour/mongolia-nomad-homestay-live-like-a-local-nomad-mongolia/"] [unique_id "al4WD6_X-kAXGDrIFaew2wAA9GE"]
[Mon Jul 20 06:35:27.896487 2026] [security2:error] [pid 953991:tid 954152] [client 34.74.185.202:63680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WD6_X-kAXGDrIFaew6AAAAKQ"]
[Mon Jul 20 06:35:27.936450 2026] [proxy:error] [pid 953991:tid 954188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:27.936502 2026] [proxy_http:error] [pid 953991:tid 954188] [client 34.73.38.214:60402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:27.936996 2026] [proxy:error] [pid 953991:tid 954188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:27.937019 2026] [proxy_http:error] [pid 953991:tid 954188] [client 34.73.38.214:60402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:28.130668 2026] [proxy:error] [pid 953991:tid 954153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:28.130736 2026] [proxy_http:error] [pid 953991:tid 954153] [client 34.73.38.214:50876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:28.131373 2026] [proxy:error] [pid 953991:tid 954153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:28.131398 2026] [proxy_http:error] [pid 953991:tid 954153] [client 34.73.38.214:50876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:28.134691 2026] [security2:error] [pid 953991:tid 954130] [client 161.118.195.148:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WEK_X-kAXGDrIFaexAAAAAI4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:28.231860 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WEK_X-kAXGDrIFaexAwAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:28.231957 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WEK_X-kAXGDrIFaexAwAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:28.278480 2026] [security2:error] [pid 953991:tid 954165] [client 34.74.185.202:50248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WEK_X-kAXGDrIFaexBQAAALE"]
[Mon Jul 20 06:35:28.340645 2026] [security2:error] [pid 953991:tid 954212] [client 152.58.191.29:53748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WEK_X-kAXGDrIFaexBAAAAOA"]
[Mon Jul 20 06:35:28.381236 2026] [security2:error] [pid 953991:tid 954247] [client 223.185.13.213:14374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WEK_X-kAXGDrIFaexFAAAAQM"]
[Mon Jul 20 06:35:28.381364 2026] [security2:error] [pid 953991:tid 954247] [client 223.185.13.213:14374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WEK_X-kAXGDrIFaexFAAAAQM"]
[Mon Jul 20 06:35:28.711271 2026] [security2:error] [pid 953991:tid 954141] [client 161.118.195.148:54965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WEK_X-kAXGDrIFaexLwAAAJk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:28.730510 2026] [security2:error] [pid 953991:tid 954214] [client 77.110.127.138:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WEK_X-kAXGDrIFaexMwAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:28.906113 2026] [security2:error] [pid 953991:tid 954216] [client 34.74.185.202:51281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WEK_X-kAXGDrIFaexQAAAAOQ"]
[Mon Jul 20 06:35:28.967297 2026] [proxy:error] [pid 953991:tid 954194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:28.967377 2026] [proxy_http:error] [pid 953991:tid 954194] [client 34.73.38.214:59021] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:28.968105 2026] [proxy:error] [pid 953991:tid 954194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:28.968155 2026] [proxy_http:error] [pid 953991:tid 954194] [client 34.73.38.214:59021] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:28.979462 2026] [autoindex:error] [pid 953991:tid 954204] [client 3.151.194.164:58229] AH01276: Cannot serve directory /home1/ikrsycmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ikr.syc.mybluehost.me/
[Mon Jul 20 06:35:29.074214 2026] [security2:error] [pid 953991:tid 954147] [client 98.159.234.160:57037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WEa_X-kAXGDrIFaexVAAAAJ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:35:29.232075 2026] [security2:error] [pid 953991:tid 954228] [client 34.74.185.202:64984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WEa_X-kAXGDrIFaexXQAAAPA"]
[Mon Jul 20 06:35:29.283505 2026] [security2:error] [pid 953991:tid 954164] [client 161.118.195.148:55332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WEa_X-kAXGDrIFaexYAAAALA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:29.463222 2026] [security2:error] [pid 953991:tid 954002] [remote 8.217.108.67:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4WEa_X-kAXGDrIFaexawAArgo"]
[Mon Jul 20 06:35:29.550655 2026] [security2:error] [pid 953991:tid 954183] [client 34.74.185.202:60834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WEa_X-kAXGDrIFaexcgAAAMM"]
[Mon Jul 20 06:35:29.592881 2026] [proxy:error] [pid 953991:tid 954148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:29.592956 2026] [proxy_http:error] [pid 953991:tid 954148] [client 34.73.38.214:53039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:29.593513 2026] [proxy:error] [pid 953991:tid 954148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:29.593539 2026] [proxy_http:error] [pid 953991:tid 954148] [client 34.73.38.214:53039] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:29.841455 2026] [security2:error] [pid 953991:tid 954224] [client 13.42.250.172:41589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4WEa_X-kAXGDrIFaexhQAAAOw"]
[Mon Jul 20 06:35:29.841555 2026] [security2:error] [pid 953991:tid 954224] [client 13.42.250.172:41589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4WEa_X-kAXGDrIFaexhQAAAOw"]
[Mon Jul 20 06:35:29.854151 2026] [security2:error] [pid 953991:tid 954222] [client 34.74.185.202:62091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WEa_X-kAXGDrIFaexiAAAAOo"]
[Mon Jul 20 06:35:29.858788 2026] [security2:error] [pid 953991:tid 954230] [client 161.118.195.148:55681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WEa_X-kAXGDrIFaexigAAAPI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:29.977158 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WEa_X-kAXGDrIFaexmAAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:29.977306 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WEa_X-kAXGDrIFaexmAAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:30.029168 2026] [security2:error] [pid 953991:tid 954237] [client 77.110.127.138:50376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WEq_X-kAXGDrIFaexoQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:30.029253 2026] [security2:error] [pid 953991:tid 954237] [client 77.110.127.138:50376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WEq_X-kAXGDrIFaexoQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:30.045848 2026] [security2:error] [pid 953991:tid 954219] [client 45.3.55.168:27859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WEq_X-kAXGDrIFaexoAAAAOc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:35:30.068712 2026] [security2:error] [pid 953991:tid 954162] [client 216.73.217.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.sacredpathway.net"] [uri "/index.php"] [unique_id "al4WEa_X-kAXGDrIFaexmQAAAK4"]
[Mon Jul 20 06:35:30.076205 2026] [security2:error] [pid 953991:tid 954154] [client 34.74.185.202:53802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WEq_X-kAXGDrIFaexqAAAAKY"]
[Mon Jul 20 06:35:30.095767 2026] [security2:error] [pid 953991:tid 954185] [client 14.225.17.146:56432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4WEa_X-kAXGDrIFaexdAAAAMU"], referer: http://drewsasburyparkbeachhouse.com/OLD
[Mon Jul 20 06:35:30.206634 2026] [proxy:error] [pid 953991:tid 954123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:30.206707 2026] [proxy_http:error] [pid 953991:tid 954123] [client 34.73.38.214:64548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:30.207401 2026] [proxy:error] [pid 953991:tid 954123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:30.207436 2026] [proxy_http:error] [pid 953991:tid 954123] [client 34.73.38.214:64548] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:30.370358 2026] [security2:error] [pid 953991:tid 954217] [client 34.74.185.202:53435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WEq_X-kAXGDrIFaexvwAAAOU"]
[Mon Jul 20 06:35:30.406784 2026] [security2:error] [pid 953991:tid 954079] [remote 217.61.143.92:33838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4WEq_X-kAXGDrIFaexxgAAlVc"]
[Mon Jul 20 06:35:30.443385 2026] [security2:error] [pid 953991:tid 954239] [client 161.118.195.148:56072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WEq_X-kAXGDrIFaexywAAAPs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:30.638706 2026] [security2:error] [pid 953991:tid 954169] [client 45.3.45.19:40581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WEq_X-kAXGDrIFaex2gAAALU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:35:30.643249 2026] [security2:error] [pid 953991:tid 954033] [remote 217.61.143.92:33838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4WEq_X-kAXGDrIFaex3AAAwCk"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:35:30.687782 2026] [security2:error] [pid 953991:tid 954148] [client 34.74.185.202:50327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WEq_X-kAXGDrIFaex4QAAAKA"]
[Mon Jul 20 06:35:30.725563 2026] [security2:error] [pid 953991:tid 954188] [client 82.102.27.163:60748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WEq_X-kAXGDrIFaex4wAAAMg"]
[Mon Jul 20 06:35:30.725651 2026] [security2:error] [pid 953991:tid 954188] [client 82.102.27.163:60748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WEq_X-kAXGDrIFaex4wAAAMg"]
[Mon Jul 20 06:35:30.748311 2026] [security2:error] [pid 953991:tid 954159] [client 216.73.216.229:9163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4WEq_X-kAXGDrIFaex3QAAqyo"]
[Mon Jul 20 06:35:30.800226 2026] [proxy:error] [pid 953991:tid 954130] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:30.800302 2026] [proxy_http:error] [pid 953991:tid 954130] [client 34.73.38.214:56086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:30.800772 2026] [proxy:error] [pid 953991:tid 954130] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:30.800803 2026] [proxy_http:error] [pid 953991:tid 954130] [client 34.73.38.214:56086] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:30.855139 2026] [security2:error] [pid 953991:tid 954228] [client 171.60.139.123:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WEq_X-kAXGDrIFaex8QAAAPA"]
[Mon Jul 20 06:35:30.855292 2026] [security2:error] [pid 953991:tid 954228] [client 171.60.139.123:52622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WEq_X-kAXGDrIFaex8QAAAPA"]
[Mon Jul 20 06:35:30.899197 2026] [security2:error] [pid 953991:tid 954230] [client 216.73.216.229:9163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4WEq_X-kAXGDrIFaex6AAA8nQ"], referer: https://www.iagdevelopments.com/sitemap.xml
[Mon Jul 20 06:35:30.970729 2026] [security2:error] [pid 953991:tid 954149] [client 34.74.185.202:51537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WEq_X-kAXGDrIFaex-wAAAKE"]
[Mon Jul 20 06:35:31.016584 2026] [security2:error] [pid 953991:tid 954198] [client 161.118.195.148:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WE6_X-kAXGDrIFaex_QAAANI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:31.139018 2026] [security2:error] [pid 953991:tid 954234] [client 197.186.66.42:52511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WE6_X-kAXGDrIFaeyCAAAAPY"]
[Mon Jul 20 06:35:31.158783 2026] [security2:error] [pid 953991:tid 954234] [client 197.186.66.42:52511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WE6_X-kAXGDrIFaeyCAAAAPY"]
[Mon Jul 20 06:35:31.239658 2026] [security2:error] [pid 953991:tid 954121] [client 104.207.58.202:29883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WE6_X-kAXGDrIFaeyFAAAAIU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:35:31.243286 2026] [security2:error] [pid 953991:tid 954213] [client 34.74.185.202:54932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.rzj.zfx.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WE6_X-kAXGDrIFaeyFwAAAOE"]
[Mon Jul 20 06:35:31.247319 2026] [security2:error] [pid 953991:tid 954011] [remote 8.217.108.67:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4WE6_X-kAXGDrIFaeyFgAAyBM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:35:31.279724 2026] [security2:error] [pid 953991:tid 954160] [client 34.73.38.214:64882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.reosportsboats.com"] [uri "/xmlrpc.php"] [unique_id "al4WE6_X-kAXGDrIFaeyGwAAAKw"]
[Mon Jul 20 06:35:31.304912 2026] [security2:error] [pid 953991:tid 954238] [client 14.225.17.146:49210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4WE6_X-kAXGDrIFaeyEgAAAPo"]
[Mon Jul 20 06:35:31.409153 2026] [security2:error] [pid 953991:tid 954243] [client 40.77.167.149:24510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4WE6_X-kAXGDrIFaeyIwAA_ww"]
[Mon Jul 20 06:35:31.548177 2026] [security2:error] [pid 953991:tid 954140] [client 77.110.127.138:50403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WE6_X-kAXGDrIFaeyLwAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:31.590006 2026] [security2:error] [pid 953991:tid 954207] [client 161.118.195.148:56812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WE6_X-kAXGDrIFaeyMgAAANs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:31.624898 2026] [security2:error] [pid 953991:tid 954200] [client 57.141.18.68:57968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WD6_X-kAXGDrIFaewngAA1Dg"]
[Mon Jul 20 06:35:31.724886 2026] [security2:error] [pid 953991:tid 954193] [client 196.191.223.175:26775] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/elementor/google-fonts/fonts/roboto-kfo5cnqeu92fr1mu53zec9_vu3r1gihoszmkc3kawzu.woff2"] [unique_id "al4WE6_X-kAXGDrIFaeyOwAAAM0"]
[Mon Jul 20 06:35:31.867771 2026] [security2:error] [pid 953991:tid 954192] [client 14.225.17.146:56300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4WE6_X-kAXGDrIFaeyOQAAAMw"], referer: http://scott-assist.com/OLD
[Mon Jul 20 06:35:31.994856 2026] [security2:error] [pid 953991:tid 954182] [client 217.142.18.172:28088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WE6_X-kAXGDrIFaeySAAAAMI"]
[Mon Jul 20 06:35:31.999740 2026] [security2:error] [pid 953991:tid 954182] [client 217.142.18.172:28088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WE6_X-kAXGDrIFaeySAAAAMI"]
[Mon Jul 20 06:35:32.129232 2026] [security2:error] [pid 953991:tid 954209] [client 34.73.38.214:58377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.representgrace.com"] [uri "/xmlrpc.php"] [unique_id "al4WFK_X-kAXGDrIFaeyVQAAAN0"]
[Mon Jul 20 06:35:32.182993 2026] [security2:error] [pid 953991:tid 954181] [client 161.118.195.148:57213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WFK_X-kAXGDrIFaeyWwAAAME"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:32.224989 2026] [security2:error] [pid 953991:tid 954232] [client 13.42.250.172:42442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4WFK_X-kAXGDrIFaeyYgAAAPQ"]
[Mon Jul 20 06:35:32.225073 2026] [security2:error] [pid 953991:tid 954232] [client 13.42.250.172:42442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4WFK_X-kAXGDrIFaeyYgAAAPQ"]
[Mon Jul 20 06:35:32.231043 2026] [security2:error] [pid 953991:tid 954211] [client 66.249.74.167:56658] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.whispersofevidence.com"] [uri "/robots.txt"] [unique_id "al4WFK_X-kAXGDrIFaeyZAAAAN8"]
[Mon Jul 20 06:35:32.458283 2026] [security2:error] [pid 953991:tid 954072] [remote 75.119.132.40:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.132.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4WFK_X-kAXGDrIFaeycgAA1FA"]
[Mon Jul 20 06:35:32.651538 2026] [security2:error] [pid 953991:tid 954109] [remote 75.119.132.40:35376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.132.119.75.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4WFK_X-kAXGDrIFaeyewAAkXU"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:35:32.706010 2026] [security2:error] [pid 953991:tid 954172] [client 77.110.127.138:50429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WFK_X-kAXGDrIFaeygQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:32.706134 2026] [security2:error] [pid 953991:tid 954172] [client 77.110.127.138:50429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WFK_X-kAXGDrIFaeygQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:32.758019 2026] [security2:error] [pid 953991:tid 954189] [client 161.118.195.148:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WFK_X-kAXGDrIFaeyhQAAAMk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:32.857797 2026] [security2:error] [pid 953991:tid 954232] [client 77.110.127.138:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WFK_X-kAXGDrIFaeykAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:32.857884 2026] [security2:error] [pid 953991:tid 954232] [client 77.110.127.138:50430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WFK_X-kAXGDrIFaeykAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:33.094017 2026] [security2:error] [pid 953991:tid 954195] [client 34.73.38.214:55389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WFa_X-kAXGDrIFaeypAAAAM8"]
[Mon Jul 20 06:35:33.237786 2026] [security2:error] [pid 953991:tid 954160] [client 223.237.130.40:55545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WFa_X-kAXGDrIFaeymQAAAKw"]
[Mon Jul 20 06:35:33.335717 2026] [security2:error] [pid 953991:tid 954228] [client 161.118.195.148:58030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WFa_X-kAXGDrIFaeywgAAAPA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:33.340630 2026] [security2:error] [pid 953991:tid 954161] [client 13.42.250.172:29614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/site/xmlrpc.php"] [unique_id "al4WFa_X-kAXGDrIFaeywwAAAK0"]
[Mon Jul 20 06:35:33.340725 2026] [security2:error] [pid 953991:tid 954161] [client 13.42.250.172:29614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/site/xmlrpc.php"] [unique_id "al4WFa_X-kAXGDrIFaeywwAAAK0"]
[Mon Jul 20 06:35:33.451710 2026] [security2:error] [pid 953991:tid 954183] [client 104.234.53.87:64583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WFa_X-kAXGDrIFaeyzwAAAMM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:33.898462 2026] [security2:error] [pid 953991:tid 954122] [client 14.225.17.146:63529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4WFK_X-kAXGDrIFaeycAAAAIY"], referer: http://guidehunting.com/OLD
[Mon Jul 20 06:35:33.903121 2026] [security2:error] [pid 953991:tid 954080] [remote 20.153.140.50:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4WFa_X-kAXGDrIFaey6QAAmVg"]
[Mon Jul 20 06:35:33.903292 2026] [security2:error] [pid 953991:tid 954141] [client 20.153.140.50:44148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4WFa_X-kAXGDrIFaey6QAAmVg"]
[Mon Jul 20 06:35:33.907459 2026] [security2:error] [pid 953991:tid 954238] [client 161.118.195.148:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WFa_X-kAXGDrIFaey7QAAAPo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:34.191279 2026] [security2:error] [pid 953991:tid 954168] [client 34.73.38.214:62406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WFq_X-kAXGDrIFaey_gAAALQ"]
[Mon Jul 20 06:35:34.191799 2026] [security2:error] [pid 953991:tid 954142] [client 34.73.38.214:62417] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WFq_X-kAXGDrIFaey_wAAAJo"]
[Mon Jul 20 06:35:34.254914 2026] [security2:error] [pid 953991:tid 954096] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WFq_X-kAXGDrIFaezBAAAq2g"]
[Mon Jul 20 06:35:34.255071 2026] [security2:error] [pid 953991:tid 954159] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WFq_X-kAXGDrIFaezBAAAq2g"]
[Mon Jul 20 06:35:34.473865 2026] [security2:error] [pid 953991:tid 954213] [client 106.219.188.178:10186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WFq_X-kAXGDrIFaezGAAAAOE"]
[Mon Jul 20 06:35:34.473988 2026] [security2:error] [pid 953991:tid 954213] [client 106.219.188.178:10186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WFq_X-kAXGDrIFaezGAAAAOE"]
[Mon Jul 20 06:35:34.480862 2026] [security2:error] [pid 953991:tid 954200] [client 161.118.195.148:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WFq_X-kAXGDrIFaezGgAAANQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:34.709933 2026] [security2:error] [pid 953991:tid 954212] [client 34.73.38.214:56317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WFq_X-kAXGDrIFaezNQAAAOA"]
[Mon Jul 20 06:35:34.842458 2026] [security2:error] [pid 953991:tid 954160] [client 50.116.65.227:45214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WFq_X-kAXGDrIFaezPgAAAKw"]
[Mon Jul 20 06:35:34.851126 2026] [security2:error] [pid 953991:tid 954192] [client 50.116.65.227:45220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WFq_X-kAXGDrIFaezQwAAAMw"]
[Mon Jul 20 06:35:34.969914 2026] [security2:error] [pid 953991:tid 954126] [client 39.48.81.23:58684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WFq_X-kAXGDrIFaezTwAAAIo"]
[Mon Jul 20 06:35:34.970011 2026] [security2:error] [pid 953991:tid 954126] [client 39.48.81.23:58684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WFq_X-kAXGDrIFaezTwAAAIo"]
[Mon Jul 20 06:35:34.993569 2026] [security2:error] [pid 953991:tid 954122] [client 14.225.17.146:62464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WFq_X-kAXGDrIFaezNwAAAIY"], referer: https://guidehunting.com/OLD
[Mon Jul 20 06:35:35.060392 2026] [security2:error] [pid 953991:tid 954200] [client 161.118.195.148:59146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WF6_X-kAXGDrIFaezVQAAANQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:35.192454 2026] [security2:error] [pid 953991:tid 954147] [client 158.173.166.181:61997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WF6_X-kAXGDrIFaezXQAAAJ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:35:35.201760 2026] [security2:error] [pid 953991:tid 954245] [client 34.73.38.214:54955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WF6_X-kAXGDrIFaezXwAAAQE"]
[Mon Jul 20 06:35:35.204685 2026] [security2:error] [pid 953991:tid 954104] [remote 152.228.213.32:40548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WF6_X-kAXGDrIFaezXgAAmXA"]
[Mon Jul 20 06:35:35.291673 2026] [security2:error] [pid 953991:tid 954140] [client 171.61.165.146:24406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WF6_X-kAXGDrIFaezZwAAAJg"]
[Mon Jul 20 06:35:35.291797 2026] [security2:error] [pid 953991:tid 954140] [client 171.61.165.146:24406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WF6_X-kAXGDrIFaezZwAAAJg"]
[Mon Jul 20 06:35:35.321703 2026] [security2:error] [pid 953991:tid 954169] [client 77.110.127.138:50447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WF6_X-kAXGDrIFaezbAAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:35.422370 2026] [security2:error] [pid 953991:tid 954135] [client 13.42.250.172:16050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/news/xmlrpc.php"] [unique_id "al4WF6_X-kAXGDrIFaezeAAAAJM"]
[Mon Jul 20 06:35:35.422461 2026] [security2:error] [pid 953991:tid 954135] [client 13.42.250.172:16050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/news/xmlrpc.php"] [unique_id "al4WF6_X-kAXGDrIFaezeAAAAJM"]
[Mon Jul 20 06:35:35.483840 2026] [security2:error] [pid 953991:tid 954172] [client 14.225.17.146:56282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4WF6_X-kAXGDrIFaezaQAAALg"], referer: http://narv.co/OLD
[Mon Jul 20 06:35:35.495798 2026] [security2:error] [pid 953991:tid 954069] [remote 152.228.213.32:40548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WF6_X-kAXGDrIFaezgQABAk0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:35:35.496097 2026] [security2:error] [pid 953991:tid 954134] [client 34.73.38.214:60850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WF6_X-kAXGDrIFaezhAAAAJI"]
[Mon Jul 20 06:35:35.615969 2026] [security2:error] [pid 953991:tid 954212] [client 34.73.38.214:65022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WF6_X-kAXGDrIFaeziwAAAOA"]
[Mon Jul 20 06:35:35.633549 2026] [security2:error] [pid 953991:tid 954225] [client 161.118.195.148:59506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WF6_X-kAXGDrIFaezjQAAAO0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:35.658858 2026] [security2:error] [pid 953991:tid 954199] [client 14.225.17.146:58328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4WF6_X-kAXGDrIFaezbwAAANM"], referer: http://adastra.love/OLD
[Mon Jul 20 06:35:35.693287 2026] [security2:error] [pid 953991:tid 954155] [client 187.108.85.186:57048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WF6_X-kAXGDrIFaezjwAAAKc"]
[Mon Jul 20 06:35:35.693439 2026] [security2:error] [pid 953991:tid 954155] [client 187.108.85.186:57048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WF6_X-kAXGDrIFaezjwAAAKc"]
[Mon Jul 20 06:35:35.806213 2026] [security2:error] [pid 953991:tid 954230] [client 57.141.18.92:26504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WE6_X-kAXGDrIFaeyKQAA8i4"]
[Mon Jul 20 06:35:35.806941 2026] [security2:error] [pid 953991:tid 954133] [client 121.229.156.89:57728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/about-us/"] [unique_id "al4WF6_X-kAXGDrIFaeznAAAAJE"]
[Mon Jul 20 06:35:35.807039 2026] [security2:error] [pid 953991:tid 954133] [client 121.229.156.89:57728] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/about-us/"] [unique_id "al4WF6_X-kAXGDrIFaeznAAAAJE"]
[Mon Jul 20 06:35:36.005063 2026] [security2:error] [pid 953991:tid 954224] [client 74.208.214.194:36094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WGK_X-kAXGDrIFaezrgAAAOw"]
[Mon Jul 20 06:35:36.049958 2026] [security2:error] [pid 953991:tid 954232] [client 77.110.127.138:50449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WGK_X-kAXGDrIFaezsAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:36.050057 2026] [security2:error] [pid 953991:tid 954232] [client 77.110.127.138:50449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WGK_X-kAXGDrIFaezsAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:36.205784 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WGK_X-kAXGDrIFaeztgAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:36.205879 2026] [security2:error] [pid 953991:tid 954121] [client 77.110.127.138:50452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WGK_X-kAXGDrIFaeztgAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:36.211844 2026] [security2:error] [pid 953991:tid 954138] [client 161.118.195.148:59883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WGK_X-kAXGDrIFaeztwAAAJY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:36.318324 2026] [security2:error] [pid 953991:tid 954188] [client 14.225.17.146:63568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4WGK_X-kAXGDrIFaeztQAAAMg"], referer: http://39ishlife.com/OLD
[Mon Jul 20 06:35:36.407455 2026] [autoindex:error] [pid 953991:tid 954207] [client 14.225.17.146:63556] AH01276: Cannot serve directory /home3/alpchxmy/public_html/OLD/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://noisepacks.com/OLD
[Mon Jul 20 06:35:36.507804 2026] [security2:error] [pid 953991:tid 954151] [client 14.225.17.146:58385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4WGK_X-kAXGDrIFaezzAAAAKM"], referer: https://narv.co/OLD
[Mon Jul 20 06:35:36.516314 2026] [security2:error] [pid 953991:tid 954148] [client 14.225.17.146:50665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4WGK_X-kAXGDrIFaez5AAAAKA"], referer: http://dasmarque.com/OLD
[Mon Jul 20 06:35:36.587737 2026] [security2:error] [pid 953991:tid 954071] [remote 91.142.222.105:57292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WGK_X-kAXGDrIFaez6wABAU8"]
[Mon Jul 20 06:35:36.628865 2026] [security2:error] [pid 953991:tid 954135] [client 13.42.250.172:16838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/web/xmlrpc.php"] [unique_id "al4WGK_X-kAXGDrIFaez7AAAAJM"]
[Mon Jul 20 06:35:36.628951 2026] [security2:error] [pid 953991:tid 954135] [client 13.42.250.172:16838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/web/xmlrpc.php"] [unique_id "al4WGK_X-kAXGDrIFaez7AAAAJM"]
[Mon Jul 20 06:35:36.753576 2026] [security2:error] [pid 953991:tid 954159] [client 34.73.38.214:57314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WGK_X-kAXGDrIFaez9QAAAKs"]
[Mon Jul 20 06:35:36.782792 2026] [security2:error] [pid 953991:tid 954239] [client 161.118.195.148:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WGK_X-kAXGDrIFaez-wAAAPs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:36.805596 2026] [security2:error] [pid 953991:tid 954123] [client 103.125.179.95:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WGK_X-kAXGDrIFaez_QAAAIc"]
[Mon Jul 20 06:35:36.807227 2026] [security2:error] [pid 953991:tid 954123] [client 103.125.179.95:59311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WGK_X-kAXGDrIFaez_QAAAIc"]
[Mon Jul 20 06:35:36.901637 2026] [security2:error] [pid 953991:tid 953992] [remote 91.142.222.105:57292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WGK_X-kAXGDrIFae0BgAA1wA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:35:36.928214 2026] [security2:error] [pid 953991:tid 954122] [client 34.73.38.214:63761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WGK_X-kAXGDrIFae0DAAAAIY"]
[Mon Jul 20 06:35:37.284163 2026] [security2:error] [pid 953991:tid 954178] [client 14.225.17.146:58561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4WGa_X-kAXGDrIFae0GgAAAL4"], referer: https://39ishlife.com/OLD
[Mon Jul 20 06:35:37.317484 2026] [security2:error] [pid 953991:tid 954180] [client 14.225.17.146:58570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4WGa_X-kAXGDrIFae0GwAAAMA"], referer: http://wathenbartlett.co.uk/OLD
[Mon Jul 20 06:35:37.357768 2026] [security2:error] [pid 953991:tid 954156] [client 161.118.195.148:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WGa_X-kAXGDrIFae0IAAAAKg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:37.429202 2026] [security2:error] [pid 953991:tid 954181] [client 112.208.70.94:43401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WGa_X-kAXGDrIFae0JwAAAME"]
[Mon Jul 20 06:35:37.429295 2026] [security2:error] [pid 953991:tid 954181] [client 112.208.70.94:43401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WGa_X-kAXGDrIFae0JwAAAME"]
[Mon Jul 20 06:35:37.570143 2026] [security2:error] [pid 953991:tid 954186] [client 34.73.38.214:65051] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WGa_X-kAXGDrIFae0NgAAAMY"]
[Mon Jul 20 06:35:37.766546 2026] [security2:error] [pid 953991:tid 954229] [client 14.225.17.146:62209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4WGK_X-kAXGDrIFaez6QAAAPE"], referer: http://collectingrealestate.com/OLD
[Mon Jul 20 06:35:37.936114 2026] [security2:error] [pid 953991:tid 954227] [client 161.118.195.148:61029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WGa_X-kAXGDrIFae0UwAAAO8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:38.095388 2026] [security2:error] [pid 953991:tid 954224] [client 82.102.27.163:37086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4WGq_X-kAXGDrIFae0ZgAAAOw"]
[Mon Jul 20 06:35:38.095484 2026] [security2:error] [pid 953991:tid 954224] [client 82.102.27.163:37086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4WGq_X-kAXGDrIFae0ZgAAAOw"]
[Mon Jul 20 06:35:38.188632 2026] [security2:error] [pid 953991:tid 954032] [remote 91.142.222.105:32954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4WGq_X-kAXGDrIFae0agAA7Sg"]
[Mon Jul 20 06:35:38.194780 2026] [security2:error] [pid 953991:tid 954127] [client 34.73.38.214:57323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WGq_X-kAXGDrIFae0bAAAAIs"]
[Mon Jul 20 06:35:38.214051 2026] [security2:error] [pid 953991:tid 954219] [client 14.225.17.146:58265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4WGq_X-kAXGDrIFae0aAAAAOc"], referer: https://wathenbartlett.co.uk/OLD
[Mon Jul 20 06:35:38.294702 2026] [security2:error] [pid 953991:tid 954202] [client 57.141.18.34:27834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WFq_X-kAXGDrIFaey_AAA1ho"]
[Mon Jul 20 06:35:38.315572 2026] [security2:error] [pid 953991:tid 954190] [client 104.234.53.66:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WGq_X-kAXGDrIFae0cwAAAMo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:38.334796 2026] [security2:error] [pid 953991:tid 954151] [client 13.42.250.172:16026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/main/xmlrpc.php"] [unique_id "al4WGq_X-kAXGDrIFae0dwAAAKM"]
[Mon Jul 20 06:35:38.334873 2026] [security2:error] [pid 953991:tid 954151] [client 13.42.250.172:16026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/main/xmlrpc.php"] [unique_id "al4WGq_X-kAXGDrIFae0dwAAAKM"]
[Mon Jul 20 06:35:38.508721 2026] [security2:error] [pid 953991:tid 954146] [client 161.118.195.148:61463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WGq_X-kAXGDrIFae0iwAAAJ4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:38.753678 2026] [security2:error] [pid 953991:tid 954131] [client 77.110.127.138:50468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WGq_X-kAXGDrIFae0mQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:38.829550 2026] [security2:error] [pid 953991:tid 954016] [remote 91.142.222.105:32954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4WGq_X-kAXGDrIFae0nwAAqhg"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 06:35:38.847319 2026] [security2:error] [pid 953991:tid 954217] [client 34.73.38.214:53102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WGq_X-kAXGDrIFae0oQAAAOU"]
[Mon Jul 20 06:35:38.909237 2026] [proxy:error] [pid 953991:tid 954167] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:38.909297 2026] [proxy_http:error] [pid 953991:tid 954167] [client 34.73.38.214:62964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:38.909722 2026] [proxy:error] [pid 953991:tid 954167] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:38.909743 2026] [proxy_http:error] [pid 953991:tid 954167] [client 34.73.38.214:62964] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:39.087648 2026] [security2:error] [pid 953991:tid 954135] [client 161.118.195.148:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WG6_X-kAXGDrIFae0vAAAAJM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:39.183664 2026] [security2:error] [pid 953991:tid 954239] [client 152.58.191.29:54110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WG6_X-kAXGDrIFae0uwAAAPs"]
[Mon Jul 20 06:35:39.459096 2026] [security2:error] [pid 953991:tid 954131] [client 77.110.127.138:50470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WG6_X-kAXGDrIFae01AAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:39.459172 2026] [security2:error] [pid 953991:tid 954131] [client 77.110.127.138:50470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WG6_X-kAXGDrIFae01AAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:39.630078 2026] [security2:error] [pid 953991:tid 954146] [client 77.110.127.138:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WG6_X-kAXGDrIFae05wAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:39.630171 2026] [security2:error] [pid 953991:tid 954146] [client 77.110.127.138:50472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WG6_X-kAXGDrIFae05wAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:39.661660 2026] [security2:error] [pid 953991:tid 954136] [client 161.118.195.148:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WG6_X-kAXGDrIFae06wAAAJQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:39.698909 2026] [security2:error] [pid 953991:tid 954165] [client 216.73.217.138:30358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WG6_X-kAXGDrIFae04AAAsRM"]
[Mon Jul 20 06:35:39.758073 2026] [security2:error] [pid 953991:tid 954186] [client 223.185.13.213:20535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WG6_X-kAXGDrIFae0-QAAAMY"]
[Mon Jul 20 06:35:39.758204 2026] [security2:error] [pid 953991:tid 954186] [client 223.185.13.213:20535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WG6_X-kAXGDrIFae0-QAAAMY"]
[Mon Jul 20 06:35:39.806580 2026] [security2:error] [pid 953991:tid 954247] [client 77.110.127.138:50473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WG6_X-kAXGDrIFae0-wAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:39.806674 2026] [security2:error] [pid 953991:tid 954247] [client 77.110.127.138:50473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WG6_X-kAXGDrIFae0-wAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:39.916899 2026] [security2:error] [pid 953991:tid 954244] [client 216.73.217.138:30358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WG6_X-kAXGDrIFae0_AABAFQ"]
[Mon Jul 20 06:35:39.934078 2026] [proxy:error] [pid 953991:tid 954177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:39.934136 2026] [proxy_http:error] [pid 953991:tid 954177] [client 34.73.38.214:58168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:39.934658 2026] [proxy:error] [pid 953991:tid 954177] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:39.934688 2026] [proxy_http:error] [pid 953991:tid 954177] [client 34.73.38.214:58168] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:39.963344 2026] [security2:error] [pid 953991:tid 954210] [client 34.73.38.214:58197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WG6_X-kAXGDrIFae1DwAAAN4"]
[Mon Jul 20 06:35:40.021438 2026] [security2:error] [pid 953991:tid 954231] [client 13.42.250.172:17933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4WHK_X-kAXGDrIFae1FAAAAPM"]
[Mon Jul 20 06:35:40.021548 2026] [security2:error] [pid 953991:tid 954231] [client 13.42.250.172:17933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4WHK_X-kAXGDrIFae1FAAAAPM"]
[Mon Jul 20 06:35:40.171308 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:50478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1IAAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:40.171415 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:50478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1IAAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:40.234520 2026] [security2:error] [pid 953991:tid 954218] [client 161.118.195.148:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WHK_X-kAXGDrIFae1IQAAAOY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:40.439715 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:50480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1LwAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:40.439854 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:50480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1LwAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:40.520943 2026] [security2:error] [pid 953991:tid 954225] [client 37.140.223.240:50267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WHK_X-kAXGDrIFae1PQAAAO0"]
[Mon Jul 20 06:35:40.709633 2026] [security2:error] [pid 953991:tid 954193] [client 77.110.127.138:50482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1TwAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:40.709724 2026] [security2:error] [pid 953991:tid 954193] [client 77.110.127.138:50482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1TwAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:40.729775 2026] [security2:error] [pid 953991:tid 954133] [client 13.42.250.172:5244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4WHK_X-kAXGDrIFae1UQAAAJE"]
[Mon Jul 20 06:35:40.729897 2026] [security2:error] [pid 953991:tid 954133] [client 13.42.250.172:5244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4WHK_X-kAXGDrIFae1UQAAAJE"]
[Mon Jul 20 06:35:40.752290 2026] [security2:error] [pid 953991:tid 954143] [client 14.225.17.146:63916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4WHK_X-kAXGDrIFae1RQAAAJs"], referer: http://soloceos.com/OLD
[Mon Jul 20 06:35:40.808397 2026] [security2:error] [pid 953991:tid 954122] [client 161.118.195.148:62944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WHK_X-kAXGDrIFae1VAAAAIY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:40.879904 2026] [security2:error] [pid 953991:tid 954126] [client 57.141.18.123:60140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WGK_X-kAXGDrIFae0CAAAimI"]
[Mon Jul 20 06:35:40.962893 2026] [security2:error] [pid 953991:tid 954154] [client 77.110.127.138:50485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1YQAAAKY"]
[Mon Jul 20 06:35:40.962998 2026] [security2:error] [pid 953991:tid 954154] [client 77.110.127.138:50485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHK_X-kAXGDrIFae1YQAAAKY"]
[Mon Jul 20 06:35:41.213004 2026] [security2:error] [pid 953991:tid 954221] [client 34.73.38.214:57712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WHa_X-kAXGDrIFae1cQAAAOk"]
[Mon Jul 20 06:35:41.308318 2026] [security2:error] [pid 953991:tid 954150] [client 34.74.185.202:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1dAAAAKI"]
[Mon Jul 20 06:35:41.318657 2026] [security2:error] [pid 953991:tid 954204] [client 77.110.127.138:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHa_X-kAXGDrIFae1dQAAANg"]
[Mon Jul 20 06:35:41.318805 2026] [security2:error] [pid 953991:tid 954204] [client 77.110.127.138:50486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WHa_X-kAXGDrIFae1dQAAANg"]
[Mon Jul 20 06:35:41.327137 2026] [security2:error] [pid 953991:tid 954195] [client 34.74.185.202:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1dwAAAM8"]
[Mon Jul 20 06:35:41.380089 2026] [security2:error] [pid 953991:tid 954146] [client 161.118.195.148:63289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WHa_X-kAXGDrIFae1fwAAAJ4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:41.425687 2026] [security2:error] [pid 953991:tid 954208] [client 13.42.250.172:27548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1iAAAANw"]
[Mon Jul 20 06:35:41.425818 2026] [security2:error] [pid 953991:tid 954208] [client 13.42.250.172:27548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1iAAAANw"]
[Mon Jul 20 06:35:41.437779 2026] [security2:error] [pid 953991:tid 954175] [client 14.225.17.146:63269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WHa_X-kAXGDrIFae1cgAAALs"], referer: http://mezzacraft.com/OLD
[Mon Jul 20 06:35:41.485788 2026] [security2:error] [pid 953991:tid 954165] [client 171.60.139.123:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1kAAAALE"]
[Mon Jul 20 06:35:41.485879 2026] [security2:error] [pid 953991:tid 954165] [client 171.60.139.123:53162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1kAAAALE"]
[Mon Jul 20 06:35:41.516146 2026] [security2:error] [pid 953991:tid 954178] [client 14.225.17.146:59927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4WHa_X-kAXGDrIFae1eQAAAL4"], referer: http://nurturemarple.co.uk/OLD
[Mon Jul 20 06:35:41.566613 2026] [security2:error] [pid 953991:tid 954244] [client 34.73.38.214:61098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WHa_X-kAXGDrIFae1mQAAAQA"]
[Mon Jul 20 06:35:41.781429 2026] [security2:error] [pid 953991:tid 954126] [client 197.186.66.42:53200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1qAAAAIo"]
[Mon Jul 20 06:35:41.781528 2026] [security2:error] [pid 953991:tid 954126] [client 197.186.66.42:53200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WHa_X-kAXGDrIFae1qAAAAIo"]
[Mon Jul 20 06:35:41.915161 2026] [security2:error] [pid 953991:tid 954236] [client 34.74.185.202:64496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WHa_X-kAXGDrIFae1uAAAAPg"]
[Mon Jul 20 06:35:41.952313 2026] [security2:error] [pid 953991:tid 954160] [client 161.118.195.148:63642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WHa_X-kAXGDrIFae1uwAAAKw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:41.962968 2026] [security2:error] [pid 953991:tid 954216] [client 34.74.185.202:53475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WHa_X-kAXGDrIFae1vgAAAOQ"]
[Mon Jul 20 06:35:42.151731 2026] [proxy:error] [pid 953991:tid 954131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:42.151813 2026] [proxy_http:error] [pid 953991:tid 954131] [client 34.73.38.214:54888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:42.152395 2026] [proxy:error] [pid 953991:tid 954131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:42.152422 2026] [proxy_http:error] [pid 953991:tid 954131] [client 34.73.38.214:54888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:42.168490 2026] [security2:error] [pid 953991:tid 954028] [remote 20.153.140.50:59778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4WHq_X-kAXGDrIFae1zAAA0SQ"]
[Mon Jul 20 06:35:42.422481 2026] [proxy:error] [pid 953991:tid 954224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:42.422550 2026] [proxy_http:error] [pid 953991:tid 954224] [client 34.73.38.214:58374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:42.423254 2026] [proxy:error] [pid 953991:tid 954224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:42.423277 2026] [proxy_http:error] [pid 953991:tid 954224] [client 34.73.38.214:58374] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:42.427011 2026] [security2:error] [pid 953991:tid 954164] [client 13.42.250.172:57443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/old/xmlrpc.php"] [unique_id "al4WHq_X-kAXGDrIFae15AAAALA"]
[Mon Jul 20 06:35:42.427107 2026] [security2:error] [pid 953991:tid 954164] [client 13.42.250.172:57443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/old/xmlrpc.php"] [unique_id "al4WHq_X-kAXGDrIFae15AAAALA"]
[Mon Jul 20 06:35:42.477144 2026] [security2:error] [pid 953991:tid 954201] [client 14.225.17.146:49701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4WHq_X-kAXGDrIFae13AAAANU"], referer: https://nurturemarple.co.uk/OLD
[Mon Jul 20 06:35:42.524960 2026] [security2:error] [pid 953991:tid 954167] [client 217.142.18.172:43713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WHq_X-kAXGDrIFae18AAAALM"]
[Mon Jul 20 06:35:42.525743 2026] [security2:error] [pid 953991:tid 954167] [client 217.142.18.172:43713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WHq_X-kAXGDrIFae18AAAALM"]
[Mon Jul 20 06:35:42.526132 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WHq_X-kAXGDrIFae18QAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:42.548087 2026] [security2:error] [pid 953991:tid 954191] [client 34.73.38.214:51342] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WHq_X-kAXGDrIFae19AAAAMs"]
[Mon Jul 20 06:35:42.588679 2026] [security2:error] [pid 953991:tid 954149] [client 57.141.18.93:27502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WGq_X-kAXGDrIFae0hwAAoQI"]
[Mon Jul 20 06:35:42.591403 2026] [security2:error] [pid 953991:tid 954163] [client 34.74.185.202:61353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WHq_X-kAXGDrIFae1-QAAAK8"]
[Mon Jul 20 06:35:42.610456 2026] [security2:error] [pid 953991:tid 954244] [client 77.110.127.138:50491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WHq_X-kAXGDrIFae1-wAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:42.647005 2026] [security2:error] [pid 953991:tid 954148] [client 34.74.185.202:61368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WHq_X-kAXGDrIFae1_QAAAKA"]
[Mon Jul 20 06:35:42.828897 2026] [security2:error] [pid 953991:tid 954135] [client 34.73.38.214:52964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WHq_X-kAXGDrIFae2BgAAAJM"]
[Mon Jul 20 06:35:42.870365 2026] [security2:error] [pid 953991:tid 954110] [remote 20.153.140.50:59778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4WHq_X-kAXGDrIFae2CQAAuXY"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:35:42.978486 2026] [security2:error] [pid 953991:tid 954191] [client 192.178.4.96:50351] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "jeffreyjaeger.com"] [uri "/robots.txt"] [unique_id "al4WHq_X-kAXGDrIFae2FQAAAMs"]
[Mon Jul 20 06:35:43.017535 2026] [security2:error] [pid 953991:tid 954140] [client 34.74.185.202:55163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WH6_X-kAXGDrIFae2HQAAAJg"]
[Mon Jul 20 06:35:43.098399 2026] [security2:error] [pid 953991:tid 954246] [client 161.118.195.148:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WH6_X-kAXGDrIFae2JQAAAQI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:43.128909 2026] [security2:error] [pid 953991:tid 954226] [client 13.42.250.172:27779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/new/xmlrpc.php"] [unique_id "al4WH6_X-kAXGDrIFae2JgAAAO4"]
[Mon Jul 20 06:35:43.129004 2026] [security2:error] [pid 953991:tid 954226] [client 13.42.250.172:27779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/new/xmlrpc.php"] [unique_id "al4WH6_X-kAXGDrIFae2JgAAAO4"]
[Mon Jul 20 06:35:43.192844 2026] [security2:error] [pid 953991:tid 954234] [client 158.173.89.95:40875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WH6_X-kAXGDrIFae2KgAAAPY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:35:43.292684 2026] [security2:error] [pid 953991:tid 954236] [client 34.74.185.202:61651] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WH6_X-kAXGDrIFae2LQAAAPg"]
[Mon Jul 20 06:35:43.366429 2026] [proxy:error] [pid 953991:tid 954192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:43.366507 2026] [proxy_http:error] [pid 953991:tid 954192] [client 34.73.38.214:50367] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:43.366969 2026] [proxy:error] [pid 953991:tid 954192] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:43.366995 2026] [proxy_http:error] [pid 953991:tid 954192] [client 34.73.38.214:50367] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:43.513617 2026] [security2:error] [pid 953991:tid 954245] [client 43.135.148.92:56450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.148.135.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/foodcost/foodcost2_results_prev.php"] [unique_id "al4WH6_X-kAXGDrIFae2NgAAAQE"]
[Mon Jul 20 06:35:43.518734 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:50497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WH6_X-kAXGDrIFae2PQAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:43.518826 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:50497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WH6_X-kAXGDrIFae2PQAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:43.670715 2026] [security2:error] [pid 953991:tid 954133] [client 161.118.195.148:64740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WH6_X-kAXGDrIFae2WwAAAJE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:43.827469 2026] [core:error] [pid 953991:tid 954131] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:43.827488 2026] [core:error] [pid 953991:tid 954131] [client 65.49.1.38:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:43.830354 2026] [security2:error] [pid 953991:tid 954145] [client 34.74.185.202:58002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WH6_X-kAXGDrIFae2ZQAAAJ0"]
[Mon Jul 20 06:35:43.831347 2026] [security2:error] [pid 953991:tid 954139] [client 34.74.185.202:59024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WH6_X-kAXGDrIFae2ZgAAAJc"]
[Mon Jul 20 06:35:44.027185 2026] [proxy:error] [pid 953991:tid 954194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:44.027256 2026] [proxy_http:error] [pid 953991:tid 954194] [client 34.73.38.214:58361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:44.027881 2026] [proxy:error] [pid 953991:tid 954194] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:44.027909 2026] [proxy_http:error] [pid 953991:tid 954194] [client 34.73.38.214:58361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:44.072539 2026] [security2:error] [pid 953991:tid 954125] [client 34.74.185.202:49217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2cwAAAIk"]
[Mon Jul 20 06:35:44.107853 2026] [security2:error] [pid 953991:tid 954170] [client 38.76.188.117:58562] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "portkeytravelplanning.com"] [uri "/wp-comments-post.php"] [unique_id "al4WIK_X-kAXGDrIFae2cAAAALY"]
[Mon Jul 20 06:35:44.113468 2026] [security2:error] [pid 953991:tid 954213] [client 14.225.17.146:49796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4WH6_X-kAXGDrIFae2UwAAAOE"], referer: http://partnerselectricalllc.com/OLD
[Mon Jul 20 06:35:44.141162 2026] [security2:error] [pid 953991:tid 954163] [client 34.74.185.202:61473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2gQAAAK8"]
[Mon Jul 20 06:35:44.174475 2026] [security2:error] [pid 953991:tid 954170] [client 38.76.188.117:58562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "portkeytravelplanning.com"] [uri "/wp-comments-post.php"] [unique_id "al4WIK_X-kAXGDrIFae2cAAAALY"]
[Mon Jul 20 06:35:44.255489 2026] [security2:error] [pid 953991:tid 954180] [client 161.118.195.148:65095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WIK_X-kAXGDrIFae2kAAAAMA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:44.260439 2026] [security2:error] [pid 953991:tid 954185] [client 57.141.18.101:41780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WG6_X-kAXGDrIFae1BAAAxT0"]
[Mon Jul 20 06:35:44.323185 2026] [security2:error] [pid 953991:tid 954188] [client 104.234.53.56:46923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WIK_X-kAXGDrIFae2igAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:44.375327 2026] [security2:error] [pid 953991:tid 954165] [client 223.237.130.40:55947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WIK_X-kAXGDrIFae2iwAAALE"]
[Mon Jul 20 06:35:44.397688 2026] [security2:error] [pid 953991:tid 954193] [client 63.179.149.246:62010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WIK_X-kAXGDrIFae2lgAAAM0"]
[Mon Jul 20 06:35:44.406896 2026] [security2:error] [pid 953991:tid 954225] [client 34.73.38.214:51728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2lwAAAO0"]
[Mon Jul 20 06:35:44.491012 2026] [security2:error] [pid 953991:tid 954221] [client 34.74.185.202:58101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2owAAAOk"]
[Mon Jul 20 06:35:44.491109 2026] [security2:error] [pid 953991:tid 954197] [client 34.74.185.202:61087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2ogAAANE"]
[Mon Jul 20 06:35:44.830195 2026] [security2:error] [pid 953991:tid 954210] [client 161.118.195.148:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WIK_X-kAXGDrIFae2vQAAAN4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:44.884250 2026] [security2:error] [pid 953991:tid 954198] [client 34.74.185.202:61971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2xwAAANI"]
[Mon Jul 20 06:35:44.954512 2026] [security2:error] [pid 953991:tid 954140] [client 34.74.185.202:58997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WIK_X-kAXGDrIFae2zQAAAJg"]
[Mon Jul 20 06:35:44.992114 2026] [security2:error] [pid 953991:tid 954204] [client 3.75.183.99:44854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WIK_X-kAXGDrIFae20QAAANg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:35:44.999697 2026] [security2:error] [pid 953991:tid 954094] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WIK_X-kAXGDrIFae22gAA4mY"]
[Mon Jul 20 06:35:44.999948 2026] [security2:error] [pid 953991:tid 954214] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WIK_X-kAXGDrIFae22gAA4mY"]
[Mon Jul 20 06:35:45.007456 2026] [security2:error] [pid 953991:tid 954203] [client 104.234.53.56:46923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WIa_X-kAXGDrIFae23AAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:45.175310 2026] [security2:error] [pid 953991:tid 954158] [client 34.74.185.202:61924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae29wAAAKo"]
[Mon Jul 20 06:35:45.222682 2026] [security2:error] [pid 953991:tid 954140] [client 50.116.65.227:10898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WIa_X-kAXGDrIFae2_AAAAJg"]
[Mon Jul 20 06:35:45.236551 2026] [security2:error] [pid 953991:tid 954241] [client 50.116.65.227:10914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WIa_X-kAXGDrIFae2_QAAAP0"]
[Mon Jul 20 06:35:45.239144 2026] [security2:error] [pid 953991:tid 954146] [client 34.73.38.214:65519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae2_gAAAJ4"]
[Mon Jul 20 06:35:45.258470 2026] [security2:error] [pid 953991:tid 954202] [client 34.73.38.214:64175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WIa_X-kAXGDrIFae2_wAAANY"]
[Mon Jul 20 06:35:45.315381 2026] [security2:error] [pid 953991:tid 954180] [client 34.74.185.202:59564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae3CAAAAMA"]
[Mon Jul 20 06:35:45.330113 2026] [security2:error] [pid 953991:tid 954174] [client 14.225.17.146:60346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4WIK_X-kAXGDrIFae22QAAALo"]
[Mon Jul 20 06:35:45.407306 2026] [security2:error] [pid 953991:tid 954153] [client 161.118.195.148:49462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WIa_X-kAXGDrIFae3CwAAAKU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:45.475717 2026] [security2:error] [pid 953991:tid 953992] [remote 47.86.33.52:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WIa_X-kAXGDrIFae3DQAA3AA"]
[Mon Jul 20 06:35:45.582620 2026] [security2:error] [pid 953991:tid 954189] [client 34.73.38.214:54067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.robertpierson.org"] [uri "/xmlrpc.php"] [unique_id "al4WIa_X-kAXGDrIFae3HwAAAMk"]
[Mon Jul 20 06:35:45.597170 2026] [security2:error] [pid 953991:tid 954156] [client 34.74.185.202:49276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae3IgAAAKg"]
[Mon Jul 20 06:35:45.613028 2026] [security2:error] [pid 953991:tid 954205] [client 34.74.185.202:59610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae3JQAAANk"]
[Mon Jul 20 06:35:45.646465 2026] [security2:error] [pid 953991:tid 954214] [client 34.73.38.214:51002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.reosportsboats.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae3KgAAAOI"]
[Mon Jul 20 06:35:45.776417 2026] [security2:error] [pid 953991:tid 954182] [client 38.76.188.117:52288] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "portkeytravelplanning.com"] [uri "/wp-comments-post.php"] [unique_id "al4WIa_X-kAXGDrIFae3NwAAAMI"]
[Mon Jul 20 06:35:45.804088 2026] [security2:error] [pid 953991:tid 954234] [client 50.116.65.227:10946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WIa_X-kAXGDrIFae3JgAAAPY"]
[Mon Jul 20 06:35:45.841671 2026] [security2:error] [pid 953991:tid 954182] [client 38.76.188.117:52288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "portkeytravelplanning.com"] [uri "/wp-comments-post.php"] [unique_id "al4WIa_X-kAXGDrIFae3NwAAAMI"]
[Mon Jul 20 06:35:45.852903 2026] [security2:error] [pid 953991:tid 954177] [client 34.73.38.214:57422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae3QAAAAL0"]
[Mon Jul 20 06:35:45.915291 2026] [security2:error] [pid 953991:tid 953996] [remote 47.86.33.52:11834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WIa_X-kAXGDrIFae3QgAArAQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:35:45.977929 2026] [security2:error] [pid 953991:tid 954141] [client 161.118.195.148:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WIa_X-kAXGDrIFae3TQAAAJk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:45.999381 2026] [security2:error] [pid 953991:tid 954122] [client 34.74.185.202:52685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WIa_X-kAXGDrIFae3UQAAAIY"]
[Mon Jul 20 06:35:46.001452 2026] [security2:error] [pid 953991:tid 954218] [client 34.74.185.202:55113] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3UgAAAOY"]
[Mon Jul 20 06:35:46.015823 2026] [security2:error] [pid 953991:tid 954232] [client 50.116.65.227:10956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WIa_X-kAXGDrIFae3OwAAAPQ"]
[Mon Jul 20 06:35:46.095180 2026] [security2:error] [pid 953991:tid 954227] [client 39.48.81.23:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3WgAAAO8"]
[Mon Jul 20 06:35:46.095294 2026] [security2:error] [pid 953991:tid 954227] [client 39.48.81.23:59188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3WgAAAO8"]
[Mon Jul 20 06:35:46.112561 2026] [security2:error] [pid 953991:tid 954248] [client 77.110.127.138:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WIq_X-kAXGDrIFae3XAAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:46.147952 2026] [security2:error] [pid 953991:tid 954196] [client 57.141.18.17:28694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WHa_X-kAXGDrIFae1pQAA0Fk"]
[Mon Jul 20 06:35:46.181423 2026] [security2:error] [pid 953991:tid 954162] [client 106.219.188.178:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3YQAAAK4"]
[Mon Jul 20 06:35:46.181593 2026] [security2:error] [pid 953991:tid 954162] [client 106.219.188.178:42194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3YQAAAK4"]
[Mon Jul 20 06:35:46.206576 2026] [security2:error] [pid 953991:tid 954208] [client 34.73.38.214:64620] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3YwAAANw"]
[Mon Jul 20 06:35:46.207529 2026] [security2:error] [pid 953991:tid 954216] [client 34.73.38.214:64609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3ZAAAAOQ"]
[Mon Jul 20 06:35:46.264573 2026] [security2:error] [pid 953991:tid 954224] [client 77.110.127.138:50520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WIq_X-kAXGDrIFae3agAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:46.302583 2026] [security2:error] [pid 953991:tid 954239] [client 34.74.185.202:51444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sardimacmillan.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3bQAAAPs"]
[Mon Jul 20 06:35:46.331408 2026] [security2:error] [pid 953991:tid 954142] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4WIK_X-kAXGDrIFae2pgAAAJo"]
[Mon Jul 20 06:35:46.337213 2026] [security2:error] [pid 953991:tid 954197] [client 171.61.165.146:4300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3cAAAANE"]
[Mon Jul 20 06:35:46.343925 2026] [security2:error] [pid 953991:tid 954197] [client 171.61.165.146:4300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3cAAAANE"]
[Mon Jul 20 06:35:46.425690 2026] [security2:error] [pid 953991:tid 954186] [client 187.108.85.186:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3eQAAAMY"]
[Mon Jul 20 06:35:46.425706 2026] [security2:error] [pid 953991:tid 954243] [client 34.74.185.202:55122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3eAAAAP8"]
[Mon Jul 20 06:35:46.425796 2026] [security2:error] [pid 953991:tid 954186] [client 187.108.85.186:57574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WIq_X-kAXGDrIFae3eQAAAMY"]
[Mon Jul 20 06:35:46.469317 2026] [security2:error] [pid 953991:tid 954241] [client 77.110.127.138:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WIq_X-kAXGDrIFae3ewAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:46.552921 2026] [security2:error] [pid 953991:tid 954214] [client 161.118.195.148:50205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WIq_X-kAXGDrIFae3gQAAAOI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:46.660082 2026] [security2:error] [pid 953991:tid 954190] [client 34.73.38.214:58180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3iAAAAMo"]
[Mon Jul 20 06:35:46.821287 2026] [security2:error] [pid 953991:tid 954182] [client 34.74.185.202:55470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.sarahmusica.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3lgAAAMI"]
[Mon Jul 20 06:35:46.844659 2026] [security2:error] [pid 953991:tid 954139] [client 34.73.38.214:63550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WIq_X-kAXGDrIFae3mAAAAJc"]
[Mon Jul 20 06:35:46.948865 2026] [security2:error] [pid 953991:tid 954175] [client 77.110.127.138:50526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WIq_X-kAXGDrIFae3ogAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:47.042706 2026] [security2:error] [pid 953991:tid 954121] [client 13.42.250.172:7347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4WI6_X-kAXGDrIFae3qgAAAIU"], referer: https://ghivs.com/wp-admin/
[Mon Jul 20 06:35:47.130904 2026] [security2:error] [pid 953991:tid 954186] [client 161.118.195.148:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WI6_X-kAXGDrIFae3swAAAMY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:47.235734 2026] [security2:error] [pid 953991:tid 954184] [client 77.110.127.138:50528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WI6_X-kAXGDrIFae3uQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:47.395261 2026] [security2:error] [pid 953991:tid 954158] [client 77.110.127.138:50531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WI6_X-kAXGDrIFae3wAAAAKo"]
[Mon Jul 20 06:35:47.462335 2026] [security2:error] [pid 953991:tid 954129] [client 34.73.38.214:59119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WI6_X-kAXGDrIFae3yAAAAI0"]
[Mon Jul 20 06:35:47.475021 2026] [security2:error] [pid 953991:tid 954239] [client 103.125.179.95:59787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WI6_X-kAXGDrIFae3ygAAAPs"]
[Mon Jul 20 06:35:47.480272 2026] [security2:error] [pid 953991:tid 954239] [client 103.125.179.95:59787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WI6_X-kAXGDrIFae3ygAAAPs"]
[Mon Jul 20 06:35:47.533260 2026] [security2:error] [pid 953991:tid 954202] [client 13.42.250.172:15005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.250.42.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4WI6_X-kAXGDrIFae31wAAANY"]
[Mon Jul 20 06:35:47.569650 2026] [security2:error] [pid 953991:tid 954122] [client 77.110.127.138:50533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WI6_X-kAXGDrIFae32AAAAIY"]
[Mon Jul 20 06:35:47.653992 2026] [security2:error] [pid 953991:tid 954219] [client 77.110.127.138:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WI6_X-kAXGDrIFae33AAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:47.654097 2026] [security2:error] [pid 953991:tid 954219] [client 77.110.127.138:50534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WI6_X-kAXGDrIFae33AAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:47.689410 2026] [security2:error] [pid 953991:tid 954221] [client 34.73.38.214:54591] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WI6_X-kAXGDrIFae34AAAAOk"]
[Mon Jul 20 06:35:47.703132 2026] [security2:error] [pid 953991:tid 954170] [client 161.118.195.148:50893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WI6_X-kAXGDrIFae34gAAALY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:47.819413 2026] [security2:error] [pid 953991:tid 954229] [client 14.225.17.146:50072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4WI6_X-kAXGDrIFae32gAAAPE"], referer: http://taskidsvirginia.com/OLD
[Mon Jul 20 06:35:47.940120 2026] [security2:error] [pid 953991:tid 954158] [client 34.73.38.214:60749] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WI6_X-kAXGDrIFae3-AAAAKo"]
[Mon Jul 20 06:35:47.944488 2026] [security2:error] [pid 953991:tid 954133] [client 34.73.38.214:60759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.representgrace.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WI6_X-kAXGDrIFae3-QAAAJE"]
[Mon Jul 20 06:35:48.002828 2026] [security2:error] [pid 953991:tid 954154] [client 57.141.18.88:52238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WH6_X-kAXGDrIFae2TwAApjY"]
[Mon Jul 20 06:35:48.045849 2026] [security2:error] [pid 953991:tid 954107] [remote 72.167.132.114:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WJK_X-kAXGDrIFae4BQAAnXM"]
[Mon Jul 20 06:35:48.275972 2026] [security2:error] [pid 953991:tid 954201] [client 161.118.195.148:51241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WJK_X-kAXGDrIFae4GgAAANU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:48.311912 2026] [security2:error] [pid 953991:tid 954048] [remote 72.167.132.114:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WJK_X-kAXGDrIFae4HwAAzDg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:35:48.683302 2026] [security2:error] [pid 953991:tid 954143] [client 34.73.38.214:59014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WJK_X-kAXGDrIFae4NgAAAJs"]
[Mon Jul 20 06:35:48.711728 2026] [security2:error] [pid 953991:tid 954226] [client 14.225.17.146:62959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4WJK_X-kAXGDrIFae4KwAAAO4"], referer: http://ivetstrategies.com/OLD
[Mon Jul 20 06:35:48.848213 2026] [security2:error] [pid 953991:tid 954124] [client 104.234.53.82:41071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WJK_X-kAXGDrIFae4RAAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:48.849815 2026] [security2:error] [pid 953991:tid 954138] [client 161.118.195.148:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WJK_X-kAXGDrIFae4RQAAAJY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:48.852569 2026] [security2:error] [pid 953991:tid 954090] [remote 95.217.78.234:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4WJK_X-kAXGDrIFae4QgAA2WI"]
[Mon Jul 20 06:35:49.001442 2026] [security2:error] [pid 953991:tid 954195] [client 34.73.38.214:49355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WJa_X-kAXGDrIFae4VwAAAM8"]
[Mon Jul 20 06:35:49.081340 2026] [security2:error] [pid 953991:tid 954098] [remote 95.217.78.234:33822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4WJa_X-kAXGDrIFae4XQAA4Go"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 06:35:49.176132 2026] [security2:error] [pid 953991:tid 954185] [client 47.128.43.154:34010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "holistichealthmassagenz.com"] [uri "/robots.txt"] [unique_id "al4WJa_X-kAXGDrIFae4ZAAAAMU"]
[Mon Jul 20 06:35:49.196125 2026] [security2:error] [pid 953991:tid 954057] [remote 47.128.110.245:58236] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "talknutritionwithlesley.com"] [uri "/managing-your-nutrition-is-self-care/"] [unique_id "al4WJa_X-kAXGDrIFae4ZQAAm0E"]
[Mon Jul 20 06:35:49.351666 2026] [security2:error] [pid 953991:tid 954238] [client 114.119.141.200:44277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "verdunestate.com"] [uri "/lebanon-beirut/propertyDetail.asp"] [unique_id "al4WJa_X-kAXGDrIFae4cQAAAPo"], referer: http://verdunestate.com/lebanon-beirut/property.asp?p=3&region&area&ListingtypeID&PropertytypeID
[Mon Jul 20 06:35:49.405786 2026] [security2:error] [pid 953991:tid 954230] [client 34.73.38.214:52881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WJa_X-kAXGDrIFae4dgAAAPI"]
[Mon Jul 20 06:35:49.528517 2026] [security2:error] [pid 953991:tid 954170] [client 161.118.195.148:51999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WJa_X-kAXGDrIFae4fwAAALY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:49.756306 2026] [security2:error] [pid 953991:tid 954131] [client 216.73.217.138:62329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WJa_X-kAXGDrIFae4iAAAj2U"]
[Mon Jul 20 06:35:49.793274 2026] [security2:error] [pid 953991:tid 954212] [client 34.73.38.214:49204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WJa_X-kAXGDrIFae4kAAAAOA"]
[Mon Jul 20 06:35:49.982095 2026] [security2:error] [pid 953991:tid 954122] [client 216.73.217.138:62329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WJa_X-kAXGDrIFae4nAAAhgY"]
[Mon Jul 20 06:35:50.023957 2026] [security2:error] [pid 953991:tid 954172] [client 152.58.191.29:16397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WJa_X-kAXGDrIFae4ngAAALg"]
[Mon Jul 20 06:35:50.144400 2026] [security2:error] [pid 953991:tid 954202] [client 161.118.195.148:52425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WJq_X-kAXGDrIFae4rwAAANY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:50.657241 2026] [security2:error] [pid 953991:tid 954193] [client 223.185.13.213:31996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WJq_X-kAXGDrIFae43wAAAM0"]
[Mon Jul 20 06:35:50.657325 2026] [security2:error] [pid 953991:tid 954193] [client 223.185.13.213:31996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WJq_X-kAXGDrIFae43wAAAM0"]
[Mon Jul 20 06:35:50.716812 2026] [security2:error] [pid 953991:tid 954247] [client 34.73.38.214:49534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WJq_X-kAXGDrIFae45AAAAQM"]
[Mon Jul 20 06:35:50.745522 2026] [security2:error] [pid 953991:tid 954225] [client 161.118.195.148:52842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WJq_X-kAXGDrIFae45QAAAO0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:50.781011 2026] [security2:error] [pid 953991:tid 954141] [client 34.73.38.214:64997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WJq_X-kAXGDrIFae46QAAAJk"]
[Mon Jul 20 06:35:51.143775 2026] [security2:error] [pid 953991:tid 954177] [client 39.48.81.23:59692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WJ6_X-kAXGDrIFae5CQAAAL0"]
[Mon Jul 20 06:35:51.143874 2026] [security2:error] [pid 953991:tid 954177] [client 39.48.81.23:59692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WJ6_X-kAXGDrIFae5CQAAAL0"]
[Mon Jul 20 06:35:51.353323 2026] [security2:error] [pid 953991:tid 954228] [client 161.118.195.148:53249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WJ6_X-kAXGDrIFae5FgAAAPA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:51.439244 2026] [security2:error] [pid 953991:tid 954224] [client 14.225.17.146:58768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4WJq_X-kAXGDrIFae4pAAAAOw"], referer: http://slutilities.com/OLD
[Mon Jul 20 06:35:51.647986 2026] [security2:error] [pid 953991:tid 954236] [client 77.110.127.138:50555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WJ6_X-kAXGDrIFae5LQAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:51.704436 2026] [security2:error] [pid 953991:tid 954222] [client 14.225.17.146:57526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4WJq_X-kAXGDrIFae4tAAAAOo"], referer: http://alexsandbergmusic.com/OLD
[Mon Jul 20 06:35:51.802860 2026] [security2:error] [pid 953991:tid 954138] [client 77.110.127.138:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WJ6_X-kAXGDrIFae5OgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:51.802950 2026] [security2:error] [pid 953991:tid 954138] [client 77.110.127.138:50556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WJ6_X-kAXGDrIFae5OgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:51.951264 2026] [security2:error] [pid 953991:tid 954127] [client 34.73.38.214:49536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WJ6_X-kAXGDrIFae5RQAAAIs"]
[Mon Jul 20 06:35:51.969866 2026] [security2:error] [pid 953991:tid 954210] [client 161.118.195.148:53691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WJ6_X-kAXGDrIFae5TAAAAN4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:52.003956 2026] [proxy:error] [pid 953991:tid 954243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:52.004058 2026] [proxy_http:error] [pid 953991:tid 954243] [client 34.73.38.214:63530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:52.004948 2026] [proxy:error] [pid 953991:tid 954243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:52.004986 2026] [proxy_http:error] [pid 953991:tid 954243] [client 34.73.38.214:63530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:52.026928 2026] [security2:error] [pid 953991:tid 954163] [client 34.73.38.214:59352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WKK_X-kAXGDrIFae5VAAAAK8"]
[Mon Jul 20 06:35:52.036490 2026] [security2:error] [pid 953991:tid 954223] [client 69.171.234.30:55976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4WJa_X-kAXGDrIFae4jQAA6wo"]
[Mon Jul 20 06:35:52.186132 2026] [security2:error] [pid 953991:tid 954229] [client 171.60.139.123:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WKK_X-kAXGDrIFae5XwAAAPE"]
[Mon Jul 20 06:35:52.186235 2026] [security2:error] [pid 953991:tid 954229] [client 171.60.139.123:53715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WKK_X-kAXGDrIFae5XwAAAPE"]
[Mon Jul 20 06:35:52.516155 2026] [security2:error] [pid 953991:tid 954197] [client 197.186.66.42:53743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WKK_X-kAXGDrIFae5dQAAANE"]
[Mon Jul 20 06:35:52.516356 2026] [security2:error] [pid 953991:tid 954197] [client 197.186.66.42:53743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WKK_X-kAXGDrIFae5dQAAANE"]
[Mon Jul 20 06:35:52.576508 2026] [security2:error] [pid 953991:tid 954210] [client 161.118.195.148:54134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WKK_X-kAXGDrIFae5fgAAAN4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:52.582777 2026] [security2:error] [pid 953991:tid 954237] [client 57.141.18.39:51199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WJK_X-kAXGDrIFae4CQAA-Uo"]
[Mon Jul 20 06:35:52.808404 2026] [security2:error] [pid 953991:tid 954127] [client 112.208.70.94:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WKK_X-kAXGDrIFae5jgAAAIs"]
[Mon Jul 20 06:35:52.808503 2026] [security2:error] [pid 953991:tid 954127] [client 112.208.70.94:43841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WKK_X-kAXGDrIFae5jgAAAIs"]
[Mon Jul 20 06:35:53.090142 2026] [security2:error] [pid 953991:tid 954183] [client 217.142.18.172:32147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WKa_X-kAXGDrIFae5pQAAAMM"]
[Mon Jul 20 06:35:53.090280 2026] [security2:error] [pid 953991:tid 954183] [client 217.142.18.172:32147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WKa_X-kAXGDrIFae5pQAAAMM"]
[Mon Jul 20 06:35:53.100425 2026] [core:error] [pid 953991:tid 954199] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.100455 2026] [core:error] [pid 953991:tid 954199] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.129687 2026] [proxy:error] [pid 953991:tid 954195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:53.129763 2026] [proxy_http:error] [pid 953991:tid 954195] [client 34.73.38.214:57720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:53.130251 2026] [proxy:error] [pid 953991:tid 954195] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:53.130280 2026] [proxy_http:error] [pid 953991:tid 954195] [client 34.73.38.214:57720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:53.154236 2026] [core:error] [pid 953991:tid 954196] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.154255 2026] [core:error] [pid 953991:tid 954196] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.171859 2026] [security2:error] [pid 953991:tid 954177] [client 161.118.195.148:54511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WKa_X-kAXGDrIFae5twAAAL0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:53.175301 2026] [core:error] [pid 953991:tid 954148] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.175323 2026] [core:error] [pid 953991:tid 954148] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.208739 2026] [core:error] [pid 953991:tid 954229] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.208768 2026] [core:error] [pid 953991:tid 954229] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.259164 2026] [core:error] [pid 953991:tid 954142] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.259197 2026] [core:error] [pid 953991:tid 954142] [client 52.230.100.152:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.423275 2026] [security2:error] [pid 953991:tid 954178] [client 34.73.38.214:52761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WKa_X-kAXGDrIFae51gAAAL4"]
[Mon Jul 20 06:35:53.428274 2026] [security2:error] [pid 953991:tid 954241] [client 69.171.230.16:59466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4WKK_X-kAXGDrIFae5iAAA_To"]
[Mon Jul 20 06:35:53.533721 2026] [security2:error] [pid 953991:tid 954143] [client 14.225.17.146:65023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4WJ6_X-kAXGDrIFae5NgAAAJs"], referer: http://superiorcopywriting.com/OLD
[Mon Jul 20 06:35:53.821689 2026] [security2:error] [pid 953991:tid 954191] [client 161.118.195.148:54956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WKa_X-kAXGDrIFae5-gAAAMs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:53.863412 2026] [core:error] [pid 953991:tid 954207] [client 14.225.17.146:64554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.863434 2026] [core:error] [pid 953991:tid 954207] [client 14.225.17.146:64554] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:35:53.918002 2026] [fcgid:warn] [pid 953991:tid 954162] (70014)End of file found: [client 199.45.155.70:36216] mod_fcgid: can't get data from http client
[Mon Jul 20 06:35:54.187211 2026] [proxy:error] [pid 953991:tid 954204] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:54.187286 2026] [proxy_http:error] [pid 953991:tid 954204] [client 34.73.38.214:57372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:54.187923 2026] [proxy:error] [pid 953991:tid 954204] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:35:54.187950 2026] [proxy_http:error] [pid 953991:tid 954204] [client 34.73.38.214:57372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:35:54.259986 2026] [security2:error] [pid 953991:tid 953995] [remote 47.86.33.52:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4WKq_X-kAXGDrIFae6KQAAowM"]
[Mon Jul 20 06:35:54.270653 2026] [security2:error] [pid 953991:tid 954115] [remote 147.50.252.213:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4WKq_X-kAXGDrIFae6LQAAxHs"]
[Mon Jul 20 06:35:54.400436 2026] [security2:error] [pid 953991:tid 954154] [client 223.237.130.40:56341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WKq_X-kAXGDrIFae6KAAAAKY"]
[Mon Jul 20 06:35:54.406135 2026] [security2:error] [pid 953991:tid 954208] [client 34.73.38.214:51181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WKq_X-kAXGDrIFae6NwAAANw"]
[Mon Jul 20 06:35:54.427052 2026] [security2:error] [pid 953991:tid 954163] [client 161.118.195.148:55372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WKq_X-kAXGDrIFae6OQAAAK8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:54.607096 2026] [security2:error] [pid 953991:tid 954171] [client 34.73.38.214:53671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WKq_X-kAXGDrIFae6SAAAALc"]
[Mon Jul 20 06:35:54.727138 2026] [security2:error] [pid 953991:tid 954061] [remote 147.50.252.213:60912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4WKq_X-kAXGDrIFae6TAAAx0U"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:35:54.787658 2026] [security2:error] [pid 953991:tid 954130] [client 34.73.38.214:54960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WKq_X-kAXGDrIFae6UgAAAI4"]
[Mon Jul 20 06:35:54.797467 2026] [security2:error] [pid 953991:tid 954101] [remote 47.86.33.52:11840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4WKq_X-kAXGDrIFae6UQAA2W0"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:35:55.047262 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:55823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WK6_X-kAXGDrIFae6bAAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:55.049360 2026] [security2:error] [pid 953991:tid 954145] [client 113.160.97.242:50373] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WK6_X-kAXGDrIFae6bgAAAJ0"]
[Mon Jul 20 06:35:55.072882 2026] [security2:error] [pid 953991:tid 954216] [client 104.234.53.48:51567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4WK6_X-kAXGDrIFae6cAAAAOQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:35:55.101495 2026] [security2:error] [pid 953991:tid 954171] [client 50.116.65.227:33440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WK6_X-kAXGDrIFae6dQAAALc"]
[Mon Jul 20 06:35:55.112339 2026] [security2:error] [pid 953991:tid 954234] [client 50.116.65.227:33450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WK6_X-kAXGDrIFae6dwAAAPY"]
[Mon Jul 20 06:35:55.520057 2026] [security2:error] [pid 953991:tid 954162] [client 34.73.38.214:61503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WK6_X-kAXGDrIFae6lAAAAK4"]
[Mon Jul 20 06:35:55.552088 2026] [security2:error] [pid 953991:tid 954144] [client 34.73.38.214:63506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WK6_X-kAXGDrIFae6lwAAAJw"]
[Mon Jul 20 06:35:55.650029 2026] [security2:error] [pid 953991:tid 954155] [client 77.110.127.138:50580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WK6_X-kAXGDrIFae6pAAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:55.661526 2026] [security2:error] [pid 953991:tid 954215] [client 161.118.195.148:56271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WK6_X-kAXGDrIFae6qQAAAOM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:55.672552 2026] [security2:error] [pid 953991:tid 954034] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WK6_X-kAXGDrIFae6qwAAvio"]
[Mon Jul 20 06:35:55.672740 2026] [security2:error] [pid 953991:tid 954178] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WK6_X-kAXGDrIFae6qwAAvio"]
[Mon Jul 20 06:35:55.678132 2026] [security2:error] [pid 953991:tid 954245] [client 147.182.149.91:61076] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.kidsklubz.org"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4WK6_X-kAXGDrIFae6mQAAAQE"]
[Mon Jul 20 06:35:55.705061 2026] [security2:error] [pid 953991:tid 954218] [client 106.219.188.178:10199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WK6_X-kAXGDrIFae6rgAAAOY"]
[Mon Jul 20 06:35:55.705707 2026] [security2:error] [pid 953991:tid 954218] [client 106.219.188.178:10199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WK6_X-kAXGDrIFae6rgAAAOY"]
[Mon Jul 20 06:35:55.849763 2026] [security2:error] [pid 953991:tid 954151] [client 77.110.127.138:50583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WK6_X-kAXGDrIFae6vwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.078173 2026] [security2:error] [pid 953991:tid 954146] [client 34.73.38.214:56512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WLK_X-kAXGDrIFae6zwAAAJ4"]
[Mon Jul 20 06:35:56.188074 2026] [security2:error] [pid 953991:tid 954198] [client 77.110.127.138:50586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WLK_X-kAXGDrIFae62QAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.211872 2026] [security2:error] [pid 953991:tid 954200] [client 34.73.38.214:63352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WLK_X-kAXGDrIFae62gAAANQ"]
[Mon Jul 20 06:35:56.271878 2026] [security2:error] [pid 953991:tid 954248] [client 161.118.195.148:56699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WLK_X-kAXGDrIFae64gAAAQQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:56.285819 2026] [security2:error] [pid 953991:tid 954236] [client 57.141.18.43:20888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WKK_X-kAXGDrIFae5YAAA-FQ"]
[Mon Jul 20 06:35:56.313941 2026] [security2:error] [pid 953991:tid 954201] [client 34.73.38.214:54131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WLK_X-kAXGDrIFae66AAAANU"]
[Mon Jul 20 06:35:56.402843 2026] [security2:error] [pid 953991:tid 954230] [client 77.110.127.138:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLK_X-kAXGDrIFae66wAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.402947 2026] [security2:error] [pid 953991:tid 954230] [client 77.110.127.138:50587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLK_X-kAXGDrIFae66wAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.452761 2026] [security2:error] [pid 953991:tid 954209] [client 77.110.127.138:50588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WLK_X-kAXGDrIFae68AAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.606893 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:50591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLK_X-kAXGDrIFae6_wAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.607021 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:50591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLK_X-kAXGDrIFae6_wAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.639589 2026] [security2:error] [pid 953991:tid 954181] [client 34.73.38.214:51032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.robertpierson.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WLK_X-kAXGDrIFae7AAAAAME"]
[Mon Jul 20 06:35:56.795373 2026] [security2:error] [pid 953991:tid 954175] [client 34.73.38.214:65494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WLK_X-kAXGDrIFae7DQAAALs"]
[Mon Jul 20 06:35:56.856370 2026] [security2:error] [pid 953991:tid 954164] [client 77.110.127.138:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WLK_X-kAXGDrIFae7EAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:56.892271 2026] [security2:error] [pid 953991:tid 954244] [client 161.118.195.148:57096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WLK_X-kAXGDrIFae7EgAAAQA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:56.972717 2026] [security2:error] [pid 953991:tid 954190] [client 14.225.17.146:59225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4WKq_X-kAXGDrIFae6XwAAAMo"], referer: http://webgardensbypaula.com/OLD
[Mon Jul 20 06:35:57.032115 2026] [security2:error] [pid 953991:tid 954216] [client 77.110.127.138:50595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7IgAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.032217 2026] [security2:error] [pid 953991:tid 954216] [client 77.110.127.138:50595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7IgAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.057896 2026] [security2:error] [pid 953991:tid 954200] [client 187.108.85.186:58087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WLa_X-kAXGDrIFae7KQAAANQ"]
[Mon Jul 20 06:35:57.057999 2026] [security2:error] [pid 953991:tid 954200] [client 187.108.85.186:58087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WLa_X-kAXGDrIFae7KQAAANQ"]
[Mon Jul 20 06:35:57.063444 2026] [security2:error] [pid 953991:tid 954147] [client 91.203.63.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4WLK_X-kAXGDrIFae7DwAAn2k"], referer: https://www.aleishapenny.ca
[Mon Jul 20 06:35:57.064014 2026] [security2:error] [pid 953991:tid 954222] [client 74.7.227.179:40288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WLK_X-kAXGDrIFae7FwAA6lA"], referer: https://tejasenvironmental.com/p=298513
[Mon Jul 20 06:35:57.079619 2026] [security2:error] [pid 953991:tid 954168] [client 77.110.127.138:50571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WLa_X-kAXGDrIFae7LwAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.086007 2026] [security2:error] [pid 953991:tid 954192] [client 62.197.45.208:58447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.45.197.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WLa_X-kAXGDrIFae7LQAAAMw"], referer: https://entuvy.com/
[Mon Jul 20 06:35:57.173528 2026] [security2:error] [pid 953991:tid 954135] [client 34.73.38.214:61968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.roguedragonstudio.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WLa_X-kAXGDrIFae7OgAAAJM"]
[Mon Jul 20 06:35:57.205388 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:50576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7PwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.205511 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:50576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7PwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.232312 2026] [security2:error] [pid 953991:tid 954238] [client 77.110.127.138:50600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WLa_X-kAXGDrIFae7QwAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.232320 2026] [security2:error] [pid 953991:tid 954164] [client 34.73.38.214:62724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WLa_X-kAXGDrIFae7QgAAALA"]
[Mon Jul 20 06:35:57.256618 2026] [security2:error] [pid 953991:tid 954173] [client 77.110.127.138:50575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7RQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.256726 2026] [security2:error] [pid 953991:tid 954173] [client 77.110.127.138:50575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7RQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:57.407166 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7VAAAAIc"]
[Mon Jul 20 06:35:57.407245 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7VAAAAIc"]
[Mon Jul 20 06:35:57.444104 2026] [security2:error] [pid 953991:tid 954231] [client 171.61.165.146:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WLa_X-kAXGDrIFae7WQAAAPM"]
[Mon Jul 20 06:35:57.444189 2026] [security2:error] [pid 953991:tid 954231] [client 171.61.165.146:24773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WLa_X-kAXGDrIFae7WQAAAPM"]
[Mon Jul 20 06:35:57.501145 2026] [security2:error] [pid 953991:tid 954191] [client 161.118.195.148:57599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WLa_X-kAXGDrIFae7YwAAAMs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:57.730695 2026] [security2:error] [pid 953991:tid 954214] [client 77.110.127.138:50609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7eAAAAOI"]
[Mon Jul 20 06:35:57.730819 2026] [security2:error] [pid 953991:tid 954214] [client 77.110.127.138:50609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WLa_X-kAXGDrIFae7eAAAAOI"]
[Mon Jul 20 06:35:57.739701 2026] [security2:error] [pid 953991:tid 954169] [client 172.98.33.10:36805] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bridgeamazon.com"] [uri "/"] [unique_id "al4WLa_X-kAXGDrIFae7ewAAALU"]
[Mon Jul 20 06:35:57.855536 2026] [security2:error] [pid 953991:tid 954180] [client 45.132.115.253:56501] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bridgeamazon.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4WLa_X-kAXGDrIFae7gQAAAMA"]
[Mon Jul 20 06:35:57.974642 2026] [security2:error] [pid 953991:tid 954231] [client 172.98.33.14:30845] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "bridgeamazon.com"] [uri "/media/system/js/core.js"] [unique_id "al4WLa_X-kAXGDrIFae7iAAAAPM"]
[Mon Jul 20 06:35:58.085588 2026] [security2:error] [pid 953991:tid 954136] [client 34.73.38.214:58299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WLq_X-kAXGDrIFae7jwAAAJQ"]
[Mon Jul 20 06:35:58.115774 2026] [security2:error] [pid 953991:tid 954127] [client 161.118.195.148:58004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WLq_X-kAXGDrIFae7kAAAAIs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:58.209922 2026] [security2:error] [pid 953991:tid 954165] [client 57.141.18.51:42384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WKq_X-kAXGDrIFae6IwAAsT4"]
[Mon Jul 20 06:35:58.494691 2026] [security2:error] [pid 953991:tid 954163] [client 103.125.179.95:60268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WLq_X-kAXGDrIFae7sgAAAK8"]
[Mon Jul 20 06:35:58.494804 2026] [security2:error] [pid 953991:tid 954163] [client 103.125.179.95:60268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WLq_X-kAXGDrIFae7sgAAAK8"]
[Mon Jul 20 06:35:58.496038 2026] [security2:error] [pid 953991:tid 954142] [client 14.225.17.146:56860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4WLa_X-kAXGDrIFae7LgAAAJo"], referer: http://blaizeaccountingservices.com/OLD
[Mon Jul 20 06:35:58.506262 2026] [security2:error] [pid 953991:tid 954137] [client 45.157.112.60:46779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WLq_X-kAXGDrIFae7swAAAJU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:35:58.708469 2026] [security2:error] [pid 953991:tid 954131] [client 161.118.195.148:58464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WLq_X-kAXGDrIFae7xgAAAI8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:58.743168 2026] [security2:error] [pid 953991:tid 954224] [client 34.73.38.214:63563] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WLq_X-kAXGDrIFae7xwAAAOw"]
[Mon Jul 20 06:35:59.062758 2026] [security2:error] [pid 953991:tid 954192] [client 45.3.45.117:12599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WL6_X-kAXGDrIFae74gAAAMw"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:35:59.147247 2026] [security2:error] [pid 953991:tid 954183] [client 65.1.132.125:21240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WL6_X-kAXGDrIFae78QAAAMM"]
[Mon Jul 20 06:35:59.147364 2026] [security2:error] [pid 953991:tid 954183] [client 65.1.132.125:21240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WL6_X-kAXGDrIFae78QAAAMM"]
[Mon Jul 20 06:35:59.289601 2026] [security2:error] [pid 953991:tid 954122] [client 161.118.195.148:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WL6_X-kAXGDrIFae8BwAAAIY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:59.298365 2026] [security2:error] [pid 953991:tid 954148] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4WL6_X-kAXGDrIFae8CQAAAKA"]
[Mon Jul 20 06:35:59.300715 2026] [security2:error] [pid 953991:tid 954144] [client 34.73.38.214:63993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WL6_X-kAXGDrIFae8CwAAAJw"]
[Mon Jul 20 06:35:59.407933 2026] [security2:error] [pid 953991:tid 954189] [client 50.116.65.227:13766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_43ccd705/wp-cron.php"] [unique_id "al4WL6_X-kAXGDrIFae8EgAAAMk"]
[Mon Jul 20 06:35:59.722999 2026] [security2:error] [pid 953991:tid 954175] [client 34.73.38.214:64615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WL6_X-kAXGDrIFae8KAAAALs"]
[Mon Jul 20 06:35:59.738906 2026] [security2:error] [pid 953991:tid 954150] [client 103.153.183.69:64274] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.bash_history"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../root/.bash_history"] [unique_id "al4WL6_X-kAXGDrIFae8KgAAAKI"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:35:59.785612 2026] [security2:error] [pid 953991:tid 954140] [client 77.110.127.138:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WL6_X-kAXGDrIFae8LAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:59.868643 2026] [security2:error] [pid 953991:tid 954124] [client 161.118.195.148:59311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WL6_X-kAXGDrIFae8NQAAAIg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:35:59.873308 2026] [security2:error] [pid 953991:tid 954236] [client 66.249.70.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lelandmc.org"] [uri "/index.php"] [unique_id "al4WL6_X-kAXGDrIFae8KQAA-FY"]
[Mon Jul 20 06:35:59.877595 2026] [security2:error] [pid 953991:tid 954002] [remote 124.55.178.99:39558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WL6_X-kAXGDrIFae8NAABAQo"]
[Mon Jul 20 06:35:59.916903 2026] [security2:error] [pid 953991:tid 954225] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WL6_X-kAXGDrIFae8PgAAAO0"]
[Mon Jul 20 06:35:59.954469 2026] [security2:error] [pid 953991:tid 954151] [client 77.110.127.138:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WL6_X-kAXGDrIFae8PwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:59.954589 2026] [security2:error] [pid 953991:tid 954151] [client 77.110.127.138:50623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WL6_X-kAXGDrIFae8PwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:35:59.962949 2026] [security2:error] [pid 953991:tid 954122] [client 114.119.140.50:32589] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villa-m-medjugorje.com"] [uri "/shop-2/"] [unique_id "al4WL6_X-kAXGDrIFae8QAAAAIY"], referer: https://villa-m-medjugorje.com/booking-confirmation/booking-canceled/
[Mon Jul 20 06:36:00.191037 2026] [security2:error] [pid 953991:tid 954148] [client 14.225.17.146:57750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4WMK_X-kAXGDrIFae8SQAAAKA"], referer: http://whiteoutcb.com/OLD
[Mon Jul 20 06:36:00.221055 2026] [security2:error] [pid 953991:tid 954215] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WMK_X-kAXGDrIFae8TwAAAOM"]
[Mon Jul 20 06:36:00.313575 2026] [security2:error] [pid 953991:tid 954147] [client 14.225.17.146:57677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4WMK_X-kAXGDrIFae8UQAAAJ8"], referer: http://processorstudio.com/OLD
[Mon Jul 20 06:36:00.317600 2026] [security2:error] [pid 953991:tid 954107] [remote 124.55.178.99:39558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WMK_X-kAXGDrIFae8VAAAz3M"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:36:00.468947 2026] [security2:error] [pid 953991:tid 954187] [client 161.118.195.148:59733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WMK_X-kAXGDrIFae8YwAAAMc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:00.523825 2026] [security2:error] [pid 953991:tid 954236] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WMK_X-kAXGDrIFae8ZwAAAPg"]
[Mon Jul 20 06:36:00.526957 2026] [security2:error] [pid 953991:tid 954182] [client 34.73.38.214:53200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WMK_X-kAXGDrIFae8aAAAAMI"]
[Mon Jul 20 06:36:00.630210 2026] [security2:error] [pid 953991:tid 954186] [client 57.141.18.65:24546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WLK_X-kAXGDrIFae60QAAxiA"]
[Mon Jul 20 06:36:00.659897 2026] [security2:error] [pid 953991:tid 954222] [client 14.225.17.146:53528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4WL6_X-kAXGDrIFae8AgAAAOo"], referer: http://detroitcsc.com/OLD
[Mon Jul 20 06:36:00.802512 2026] [security2:error] [pid 953991:tid 954240] [client 152.58.191.29:19319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WMK_X-kAXGDrIFae8fAAAAPw"]
[Mon Jul 20 06:36:00.825193 2026] [security2:error] [pid 953991:tid 954229] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4WMK_X-kAXGDrIFae8hAAAAPE"]
[Mon Jul 20 06:36:00.994320 2026] [security2:error] [pid 953991:tid 954236] [client 34.73.38.214:51977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WMK_X-kAXGDrIFae8lwAAAPg"]
[Mon Jul 20 06:36:01.055892 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:60151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WMa_X-kAXGDrIFae8oAAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:01.141488 2026] [security2:error] [pid 953991:tid 954231] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WMa_X-kAXGDrIFae8qAAAAPM"]
[Mon Jul 20 06:36:01.184191 2026] [security2:error] [pid 953991:tid 954172] [client 14.225.17.146:57887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4WMa_X-kAXGDrIFae8qQAAALg"], referer: https://processorstudio.com/OLD
[Mon Jul 20 06:36:01.212974 2026] [security2:error] [pid 953991:tid 954244] [client 223.185.13.213:27986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WMa_X-kAXGDrIFae8rQAAAQA"]
[Mon Jul 20 06:36:01.213074 2026] [security2:error] [pid 953991:tid 954244] [client 223.185.13.213:27986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WMa_X-kAXGDrIFae8rQAAAQA"]
[Mon Jul 20 06:36:01.447685 2026] [security2:error] [pid 953991:tid 954160] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4WMa_X-kAXGDrIFae8xQAAAKw"]
[Mon Jul 20 06:36:01.494053 2026] [security2:error] [pid 953991:tid 954187] [client 34.73.38.214:58916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WMa_X-kAXGDrIFae8yAAAAMc"]
[Mon Jul 20 06:36:01.635682 2026] [security2:error] [pid 953991:tid 954164] [client 161.118.195.148:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WMa_X-kAXGDrIFae83gAAALA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:01.663168 2026] [security2:error] [pid 953991:tid 954153] [client 57.141.18.22:20550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WLa_X-kAXGDrIFae7MgAApTU"]
[Mon Jul 20 06:36:01.663460 2026] [security2:error] [pid 953991:tid 954247] [client 13.229.223.11:19676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WMa_X-kAXGDrIFae84gAAAQM"]
[Mon Jul 20 06:36:01.754401 2026] [security2:error] [pid 953991:tid 954220] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WMa_X-kAXGDrIFae85gAAAOg"]
[Mon Jul 20 06:36:01.953471 2026] [security2:error] [pid 953991:tid 954146] [client 34.73.38.214:63421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WMa_X-kAXGDrIFae8-AAAAJ4"]
[Mon Jul 20 06:36:02.005487 2026] [security2:error] [pid 953991:tid 954195] [client 77.110.127.138:50642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WMa_X-kAXGDrIFae8-QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:02.053609 2026] [security2:error] [pid 953991:tid 954242] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WMq_X-kAXGDrIFae8_gAAAP4"]
[Mon Jul 20 06:36:02.222789 2026] [security2:error] [pid 953991:tid 954140] [client 161.118.195.148:60955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WMq_X-kAXGDrIFae9DwAAAJg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:02.328124 2026] [security2:error] [pid 953991:tid 954238] [client 34.73.38.214:54998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.rzj.zfx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WMq_X-kAXGDrIFae9FQAAAPo"]
[Mon Jul 20 06:36:02.357003 2026] [security2:error] [pid 953991:tid 954227] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WMq_X-kAXGDrIFae9FgAAAO8"]
[Mon Jul 20 06:36:02.455090 2026] [security2:error] [pid 953991:tid 954218] [client 77.110.127.138:50654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WMq_X-kAXGDrIFae9GgAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:02.455194 2026] [security2:error] [pid 953991:tid 954218] [client 77.110.127.138:50654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WMq_X-kAXGDrIFae9GgAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:02.511318 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WMq_X-kAXGDrIFae9IgAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:02.511460 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WMq_X-kAXGDrIFae9IgAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:02.656689 2026] [security2:error] [pid 953991:tid 954122] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WMq_X-kAXGDrIFae9OgAAAIY"]
[Mon Jul 20 06:36:02.800310 2026] [security2:error] [pid 953991:tid 954161] [client 161.118.195.148:61305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WMq_X-kAXGDrIFae9PwAAAK0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:02.959806 2026] [security2:error] [pid 953991:tid 954152] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WMq_X-kAXGDrIFae9SQAAAKQ"]
[Mon Jul 20 06:36:02.993894 2026] [security2:error] [pid 953991:tid 954131] [client 171.60.139.123:54288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WMq_X-kAXGDrIFae9TQAAAI8"]
[Mon Jul 20 06:36:02.993998 2026] [security2:error] [pid 953991:tid 954131] [client 171.60.139.123:54288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WMq_X-kAXGDrIFae9TQAAAI8"]
[Mon Jul 20 06:36:03.062618 2026] [security2:error] [pid 953991:tid 954061] [remote 216.73.216.55:6393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4WM6_X-kAXGDrIFae9WAAAp0U"]
[Mon Jul 20 06:36:03.112790 2026] [security2:error] [pid 953991:tid 954104] [remote 91.142.222.105:37638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WM6_X-kAXGDrIFae9WwAAlnA"]
[Mon Jul 20 06:36:03.152290 2026] [security2:error] [pid 953991:tid 954222] [client 197.186.66.42:54264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WM6_X-kAXGDrIFae9YgAAAOo"]
[Mon Jul 20 06:36:03.152533 2026] [security2:error] [pid 953991:tid 954222] [client 197.186.66.42:54264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WM6_X-kAXGDrIFae9YgAAAOo"]
[Mon Jul 20 06:36:03.266187 2026] [security2:error] [pid 953991:tid 954207] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4WM6_X-kAXGDrIFae9cgAAANs"]
[Mon Jul 20 06:36:03.368870 2026] [proxy:error] [pid 953991:tid 954223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:03.368938 2026] [proxy_http:error] [pid 953991:tid 954223] [client 34.73.38.214:54973] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:03.369223 2026] [security2:error] [pid 953991:tid 954140] [client 77.110.127.138:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WM6_X-kAXGDrIFae9ewAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:03.369313 2026] [security2:error] [pid 953991:tid 954140] [client 77.110.127.138:50666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WM6_X-kAXGDrIFae9ewAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:03.369515 2026] [proxy:error] [pid 953991:tid 954223] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:03.369541 2026] [proxy_http:error] [pid 953991:tid 954223] [client 34.73.38.214:54973] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:03.378225 2026] [security2:error] [pid 953991:tid 954190] [client 161.118.195.148:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WM6_X-kAXGDrIFae9fgAAAMo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:03.466123 2026] [proxy:error] [pid 953991:tid 954201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:03.466200 2026] [proxy_http:error] [pid 953991:tid 954201] [client 34.73.38.214:63529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:03.466909 2026] [proxy:error] [pid 953991:tid 954201] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:03.466940 2026] [proxy_http:error] [pid 953991:tid 954201] [client 34.73.38.214:63529] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:03.504727 2026] [security2:error] [pid 953991:tid 954214] [client 114.119.144.84:41929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.myspineworld.com"] [uri "/robots.txt"] [unique_id "al4WM6_X-kAXGDrIFae9iwAAAOI"], referer: https://www.myspineworld.com/robots.txt
[Mon Jul 20 06:36:03.547016 2026] [security2:error] [pid 953991:tid 954108] [remote 91.142.222.105:37638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WM6_X-kAXGDrIFae9jAAAk3Q"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:36:03.560530 2026] [security2:error] [pid 953991:tid 954187] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WM6_X-kAXGDrIFae9jgAAAMc"]
[Mon Jul 20 06:36:03.577610 2026] [security2:error] [pid 953991:tid 954245] [client 217.142.18.172:61552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WM6_X-kAXGDrIFae9kwAAAQE"]
[Mon Jul 20 06:36:03.589419 2026] [security2:error] [pid 953991:tid 954245] [client 217.142.18.172:61552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WM6_X-kAXGDrIFae9kwAAAQE"]
[Mon Jul 20 06:36:03.705610 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WM6_X-kAXGDrIFae9ngAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:03.705741 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:50628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WM6_X-kAXGDrIFae9ngAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:03.806114 2026] [security2:error] [pid 953991:tid 954228] [client 14.225.17.146:57287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4WM6_X-kAXGDrIFae9mgAAAPA"], referer: http://alrowad-hub.net/OLD
[Mon Jul 20 06:36:03.858283 2026] [security2:error] [pid 953991:tid 954248] [client 77.110.127.138:50671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WM6_X-kAXGDrIFae9rgAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:03.858380 2026] [security2:error] [pid 953991:tid 954248] [client 77.110.127.138:50671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WM6_X-kAXGDrIFae9rgAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:03.867989 2026] [security2:error] [pid 953991:tid 954238] [client 51.255.160.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lakelopezonline.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4WM6_X-kAXGDrIFae9rwAAAPo"]
[Mon Jul 20 06:36:03.980806 2026] [security2:error] [pid 953991:tid 954231] [client 161.118.195.148:62032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WM6_X-kAXGDrIFae9sgAAAPM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:04.065744 2026] [proxy:error] [pid 953991:tid 954215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.065843 2026] [proxy_http:error] [pid 953991:tid 954215] [client 34.73.38.214:52267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.066571 2026] [proxy:error] [pid 953991:tid 954215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.066619 2026] [proxy_http:error] [pid 953991:tid 954215] [client 34.73.38.214:52267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.193210 2026] [proxy:error] [pid 953991:tid 954186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.193270 2026] [proxy_http:error] [pid 953991:tid 954186] [client 34.73.38.214:56366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.193698 2026] [proxy:error] [pid 953991:tid 954186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.193726 2026] [proxy_http:error] [pid 953991:tid 954186] [client 34.73.38.214:56366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.224568 2026] [core:error] [pid 953991:tid 954190] [client 14.225.17.146:56086] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/OLD
[Mon Jul 20 06:36:04.224598 2026] [core:error] [pid 953991:tid 954190] [client 14.225.17.146:56086] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/OLD
[Mon Jul 20 06:36:04.330379 2026] [security2:error] [pid 953991:tid 954203] [client 77.110.127.138:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WNK_X-kAXGDrIFae93QAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:04.330467 2026] [security2:error] [pid 953991:tid 954203] [client 77.110.127.138:50596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WNK_X-kAXGDrIFae93QAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:04.380887 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WNK_X-kAXGDrIFae94AAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:04.380986 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WNK_X-kAXGDrIFae94AAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:04.516998 2026] [security2:error] [pid 953991:tid 954121] [client 13.229.223.11:19098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WNK_X-kAXGDrIFae95gAAAIU"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:36:04.560002 2026] [security2:error] [pid 953991:tid 954185] [client 161.118.195.148:62436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WNK_X-kAXGDrIFae96wAAAMU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:04.749139 2026] [proxy:error] [pid 953991:tid 954241] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.749217 2026] [proxy_http:error] [pid 953991:tid 954241] [client 34.73.38.214:55017] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.749903 2026] [proxy:error] [pid 953991:tid 954241] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.749942 2026] [proxy_http:error] [pid 953991:tid 954241] [client 34.73.38.214:55017] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.790320 2026] [security2:error] [pid 953991:tid 954209] [client 50.116.65.227:24872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WNK_X-kAXGDrIFae-CAAAAN0"]
[Mon Jul 20 06:36:04.801316 2026] [security2:error] [pid 953991:tid 954137] [client 50.116.65.227:24880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WNK_X-kAXGDrIFae-CgAAAJU"]
[Mon Jul 20 06:36:04.863494 2026] [proxy:error] [pid 953991:tid 954148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.863582 2026] [proxy_http:error] [pid 953991:tid 954148] [client 34.73.38.214:49518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:04.864391 2026] [proxy:error] [pid 953991:tid 954148] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:04.864440 2026] [proxy_http:error] [pid 953991:tid 954148] [client 34.73.38.214:49518] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:05.150304 2026] [security2:error] [pid 953991:tid 954202] [client 161.118.195.148:62799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WNa_X-kAXGDrIFae-HQAAANY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:05.231944 2026] [security2:error] [pid 953991:tid 954215] [client 223.237.130.40:56752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WNa_X-kAXGDrIFae-FwAAAOM"]
[Mon Jul 20 06:36:05.270896 2026] [security2:error] [pid 953991:tid 954248] [client 77.110.127.138:50678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WNa_X-kAXGDrIFae-KwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:05.366959 2026] [security2:error] [pid 953991:tid 954057] [remote 117.0.21.154:54900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4WNa_X-kAXGDrIFae-NwAA0EE"]
[Mon Jul 20 06:36:05.378985 2026] [security2:error] [pid 953991:tid 954134] [client 112.208.70.94:44258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WNa_X-kAXGDrIFae-PAAAAJI"]
[Mon Jul 20 06:36:05.379081 2026] [security2:error] [pid 953991:tid 954134] [client 112.208.70.94:44258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WNa_X-kAXGDrIFae-PAAAAJI"]
[Mon Jul 20 06:36:05.668697 2026] [security2:error] [pid 953991:tid 954153] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4WNa_X-kAXGDrIFae-RgAAAKU"]
[Mon Jul 20 06:36:05.687104 2026] [security2:error] [pid 953991:tid 954233] [client 34.73.38.214:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/xmlrpc.php"] [unique_id "al4WNa_X-kAXGDrIFae-UAAAAPU"]
[Mon Jul 20 06:36:05.718766 2026] [security2:error] [pid 953991:tid 954145] [client 34.73.38.214:61750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.sarahmusica.com"] [uri "/xmlrpc.php"] [unique_id "al4WNa_X-kAXGDrIFae-UwAAAJ0"]
[Mon Jul 20 06:36:05.723880 2026] [security2:error] [pid 953991:tid 953999] [remote 130.185.118.215:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4WNa_X-kAXGDrIFae-UgAA9gc"]
[Mon Jul 20 06:36:05.735321 2026] [security2:error] [pid 953991:tid 954191] [client 161.118.195.148:63230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WNa_X-kAXGDrIFae-WAAAAMs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:05.950098 2026] [security2:error] [pid 953991:tid 954085] [remote 130.185.118.215:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4WNa_X-kAXGDrIFae-bQAAqV0"], referer: https://mail.grndl.com/wp-login.php
[Mon Jul 20 06:36:06.022760 2026] [security2:error] [pid 953991:tid 953998] [remote 117.0.21.154:54900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4WNq_X-kAXGDrIFae-cgAA_gY"], referer: https://solkeetw.com/wp-login.php
[Mon Jul 20 06:36:06.112959 2026] [security2:error] [pid 953991:tid 954183] [client 34.73.38.214:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WNq_X-kAXGDrIFae-dwAAAMM"]
[Mon Jul 20 06:36:06.213305 2026] [security2:error] [pid 953991:tid 954114] [remote 154.61.75.100:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WNq_X-kAXGDrIFae-hQAAuXo"]
[Mon Jul 20 06:36:06.245085 2026] [security2:error] [pid 953991:tid 954181] [client 57.141.18.49:60020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WMa_X-kAXGDrIFae85QAAwQA"]
[Mon Jul 20 06:36:06.308134 2026] [security2:error] [pid 953991:tid 954180] [client 14.225.17.146:53359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4WNq_X-kAXGDrIFae-gAAAAMA"], referer: http://ghivs.com/OLD
[Mon Jul 20 06:36:06.314615 2026] [security2:error] [pid 953991:tid 954194] [client 161.118.195.148:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WNq_X-kAXGDrIFae-kAAAAM4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:06.361688 2026] [security2:error] [pid 953991:tid 954136] [client 34.73.38.214:55186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WNq_X-kAXGDrIFae-mAAAAJQ"]
[Mon Jul 20 06:36:06.434367 2026] [security2:error] [pid 953991:tid 954003] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WNq_X-kAXGDrIFae-nwAA8Qs"]
[Mon Jul 20 06:36:06.434509 2026] [security2:error] [pid 953991:tid 954229] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WNq_X-kAXGDrIFae-nwAA8Qs"]
[Mon Jul 20 06:36:06.536823 2026] [security2:error] [pid 953991:tid 954226] [client 14.182.195.220:52260] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WNq_X-kAXGDrIFae-ogAAAO4"]
[Mon Jul 20 06:36:06.625052 2026] [security2:error] [pid 953991:tid 954073] [remote 72.167.132.114:35060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WNq_X-kAXGDrIFae-qQAA0FE"]
[Mon Jul 20 06:36:06.644010 2026] [security2:error] [pid 953991:tid 954143] [client 77.110.127.138:50662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WNq_X-kAXGDrIFae-qwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:06.644144 2026] [security2:error] [pid 953991:tid 954143] [client 77.110.127.138:50662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WNq_X-kAXGDrIFae-qwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:06.695219 2026] [security2:error] [pid 953991:tid 954216] [client 14.225.17.146:55998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4WNq_X-kAXGDrIFae-pAAAAOQ"]
[Mon Jul 20 06:36:06.711526 2026] [security2:error] [pid 953991:tid 954061] [remote 154.61.75.100:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WNq_X-kAXGDrIFae-sAAA8EU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:36:06.860544 2026] [security2:error] [pid 953991:tid 954099] [remote 72.167.132.114:35060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WNq_X-kAXGDrIFae-vAAAuGs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:36:06.913882 2026] [security2:error] [pid 953991:tid 954204] [client 161.118.195.148:64020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WNq_X-kAXGDrIFae-wgAAANg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:06.957027 2026] [security2:error] [pid 953991:tid 954218] [client 34.73.38.214:60993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WNq_X-kAXGDrIFae-xAAAAOY"]
[Mon Jul 20 06:36:07.332481 2026] [security2:error] [pid 953991:tid 954210] [client 106.219.188.178:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WN6_X-kAXGDrIFae-3wAAAN4"]
[Mon Jul 20 06:36:07.334201 2026] [security2:error] [pid 953991:tid 954210] [client 106.219.188.178:15809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WN6_X-kAXGDrIFae-3wAAAN4"]
[Mon Jul 20 06:36:07.382089 2026] [security2:error] [pid 953991:tid 954184] [client 77.110.127.138:50690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WN6_X-kAXGDrIFae-5QAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:07.406774 2026] [security2:error] [pid 953991:tid 954233] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4WN6_X-kAXGDrIFae-1wAAAPU"]
[Mon Jul 20 06:36:07.423089 2026] [security2:error] [pid 953991:tid 954239] [client 34.73.38.214:55917] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WN6_X-kAXGDrIFae-6AAAAPs"]
[Mon Jul 20 06:36:07.494248 2026] [security2:error] [pid 953991:tid 954162] [client 161.118.195.148:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WN6_X-kAXGDrIFae-6gAAAK4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:07.495245 2026] [security2:error] [pid 953991:tid 954044] [remote 162.19.86.63:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WN6_X-kAXGDrIFae-6wAAljQ"]
[Mon Jul 20 06:36:07.696779 2026] [security2:error] [pid 953991:tid 954037] [remote 162.19.86.63:46590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WN6_X-kAXGDrIFae--gAA_i0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:07.721155 2026] [security2:error] [pid 953991:tid 954157] [client 187.108.85.186:58616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WN6_X-kAXGDrIFae-_QAAAKk"]
[Mon Jul 20 06:36:07.721365 2026] [security2:error] [pid 953991:tid 954157] [client 187.108.85.186:58616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WN6_X-kAXGDrIFae-_QAAAKk"]
[Mon Jul 20 06:36:07.865827 2026] [security2:error] [pid 953991:tid 954025] [remote 130.185.118.215:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WN6_X-kAXGDrIFae_EAAA5iE"]
[Mon Jul 20 06:36:08.041080 2026] [security2:error] [pid 953991:tid 954201] [client 216.73.217.138:41435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WN6_X-kAXGDrIFae_FgAA1RA"]
[Mon Jul 20 06:36:08.060592 2026] [security2:error] [pid 953991:tid 954012] [remote 130.185.118.215:38686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WOK_X-kAXGDrIFae_IwAA2BQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:08.066070 2026] [security2:error] [pid 953991:tid 954228] [client 161.118.195.148:64795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WOK_X-kAXGDrIFae_JQAAAPA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:08.130166 2026] [security2:error] [pid 953991:tid 954172] [client 14.225.17.146:50076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4WOK_X-kAXGDrIFae_IgAAALg"]
[Mon Jul 20 06:36:08.354050 2026] [security2:error] [pid 953991:tid 954217] [client 216.73.217.138:41435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WOK_X-kAXGDrIFae_NQAA5WE"]
[Mon Jul 20 06:36:08.638664 2026] [security2:error] [pid 953991:tid 954245] [client 14.225.17.146:53401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "waterproofgoods.com"] [uri "/index.php"] [unique_id "al4WNq_X-kAXGDrIFae-jgAAAQE"], referer: http://waterproofgoods.com/OLD
[Mon Jul 20 06:36:08.642059 2026] [security2:error] [pid 953991:tid 954153] [client 161.118.195.148:65183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WOK_X-kAXGDrIFae_WAAAAKU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:08.671771 2026] [security2:error] [pid 953991:tid 954195] [client 34.73.38.214:52325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WOK_X-kAXGDrIFae_WQAAAM8"]
[Mon Jul 20 06:36:08.846872 2026] [security2:error] [pid 953991:tid 954134] [client 34.73.38.214:57548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WOK_X-kAXGDrIFae_ZwAAAJI"]
[Mon Jul 20 06:36:08.854122 2026] [security2:error] [pid 953991:tid 954157] [client 216.73.217.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4WOK_X-kAXGDrIFae_XQAAqUc"]
[Mon Jul 20 06:36:09.222745 2026] [security2:error] [pid 953991:tid 954161] [client 161.118.195.148:49180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WOa_X-kAXGDrIFae_iQAAAK0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:09.257587 2026] [security2:error] [pid 953991:tid 954126] [client 63.176.132.15:27082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WOa_X-kAXGDrIFae_jQAAAIo"]
[Mon Jul 20 06:36:09.283649 2026] [security2:error] [pid 953991:tid 954153] [client 77.110.127.138:50706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WOa_X-kAXGDrIFae_kwAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:09.283758 2026] [security2:error] [pid 953991:tid 954153] [client 77.110.127.138:50706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WOa_X-kAXGDrIFae_kwAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:09.385256 2026] [security2:error] [pid 953991:tid 954158] [client 103.125.179.95:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WOa_X-kAXGDrIFae_mwAAAKo"]
[Mon Jul 20 06:36:09.385394 2026] [security2:error] [pid 953991:tid 954158] [client 103.125.179.95:60758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WOa_X-kAXGDrIFae_mwAAAKo"]
[Mon Jul 20 06:36:09.581410 2026] [security2:error] [pid 953991:tid 954086] [remote 100.42.189.89:53992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4WOa_X-kAXGDrIFae_qAAA3l4"]
[Mon Jul 20 06:36:09.681665 2026] [security2:error] [pid 953991:tid 954213] [client 14.225.17.146:60788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4WOa_X-kAXGDrIFae_qQAAAOE"], referer: http://ravmike.com/OLD
[Mon Jul 20 06:36:09.795028 2026] [security2:error] [pid 953991:tid 954103] [remote 100.42.189.89:53992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4WOa_X-kAXGDrIFae_vgAAyW8"], referer: https://709fx.com/wp-login.php
[Mon Jul 20 06:36:09.796991 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WOa_X-kAXGDrIFae_vwAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:09.822679 2026] [security2:error] [pid 953991:tid 954248] [client 34.73.38.214:62645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WOa_X-kAXGDrIFae_xAAAAQQ"]
[Mon Jul 20 06:36:09.844147 2026] [security2:error] [pid 953991:tid 954149] [client 104.207.58.101:12871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WOa_X-kAXGDrIFae_vQAAAKE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:09.928142 2026] [security2:error] [pid 953991:tid 954125] [client 167.99.161.130:59595] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.techtradeinc.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4WOa_X-kAXGDrIFae_yQAAAIk"]
[Mon Jul 20 06:36:10.039896 2026] [security2:error] [pid 953991:tid 954133] [client 104.234.53.86:37033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WOq_X-kAXGDrIFae_3AAAAJE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:10.065570 2026] [security2:error] [pid 953991:tid 953996] [remote 152.228.213.32:41980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WOq_X-kAXGDrIFae_3QAAiAQ"]
[Mon Jul 20 06:36:10.150013 2026] [security2:error] [pid 953991:tid 954228] [client 63.176.132.15:27086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WOq_X-kAXGDrIFae_5wAAAPA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:36:10.185564 2026] [security2:error] [pid 953991:tid 954208] [client 34.73.38.214:52831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WOq_X-kAXGDrIFae_6QAAANw"]
[Mon Jul 20 06:36:10.340144 2026] [security2:error] [pid 953991:tid 954093] [remote 152.228.213.32:41980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WOq_X-kAXGDrIFae_8AAAtmU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:10.378953 2026] [security2:error] [pid 953991:tid 954158] [client 161.118.195.148:50031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WOq_X-kAXGDrIFae_9gAAAKo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:10.564530 2026] [security2:error] [pid 953991:tid 954199] [client 223.185.13.213:22267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WOq_X-kAXGDrIFafADgAAANM"]
[Mon Jul 20 06:36:10.564642 2026] [security2:error] [pid 953991:tid 954199] [client 223.185.13.213:22267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WOq_X-kAXGDrIFafADgAAANM"]
[Mon Jul 20 06:36:10.588206 2026] [security2:error] [pid 953991:tid 954224] [client 14.225.17.146:64180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4WOq_X-kAXGDrIFafABwAAAOw"], referer: https://ravmike.com/OLD
[Mon Jul 20 06:36:10.591433 2026] [security2:error] [pid 953991:tid 954178] [client 77.110.127.138:50715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WOq_X-kAXGDrIFafAEAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:10.953852 2026] [security2:error] [pid 953991:tid 954134] [client 161.118.195.148:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WOq_X-kAXGDrIFafAJgAAAJI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:11.156718 2026] [security2:error] [pid 953991:tid 954121] [client 34.73.38.214:57300] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WO6_X-kAXGDrIFafAMAAAAIU"]
[Mon Jul 20 06:36:11.303857 2026] [security2:error] [pid 953991:tid 954222] [client 14.225.17.146:60567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4WOa_X-kAXGDrIFae_vAAAAOo"], referer: http://olearyplumbingllc.com/OLD
[Mon Jul 20 06:36:11.304163 2026] [security2:error] [pid 953991:tid 954213] [client 34.73.38.214:49182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WO6_X-kAXGDrIFafAPAAAAOE"]
[Mon Jul 20 06:36:11.527282 2026] [security2:error] [pid 953991:tid 954160] [client 161.118.195.148:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WO6_X-kAXGDrIFafAUwAAAKw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:11.612163 2026] [security2:error] [pid 953991:tid 954229] [client 171.61.165.146:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WO6_X-kAXGDrIFafAYwAAAPE"]
[Mon Jul 20 06:36:11.612307 2026] [security2:error] [pid 953991:tid 954229] [client 171.61.165.146:4042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WO6_X-kAXGDrIFafAYwAAAPE"]
[Mon Jul 20 06:36:11.630438 2026] [security2:error] [pid 953991:tid 954175] [client 14.225.17.146:51344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4WO6_X-kAXGDrIFafATAAAALs"], referer: http://vinovinhowine.com/OLD
[Mon Jul 20 06:36:11.633622 2026] [security2:error] [pid 953991:tid 954147] [client 104.234.53.63:61747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WO6_X-kAXGDrIFafAUQAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:11.947835 2026] [security2:error] [pid 953991:tid 954180] [client 57.141.18.65:58758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WNq_X-kAXGDrIFae-vwAAwA4"]
[Mon Jul 20 06:36:11.952390 2026] [security2:error] [pid 953991:tid 954012] [remote 5.161.225.162:60858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WO6_X-kAXGDrIFafAfQAAqxQ"]
[Mon Jul 20 06:36:11.970506 2026] [security2:error] [pid 953991:tid 954200] [client 152.58.191.29:55315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WO6_X-kAXGDrIFafAcQAAANQ"]
[Mon Jul 20 06:36:12.057550 2026] [security2:error] [pid 953991:tid 954231] [client 43.205.139.3:17194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WPK_X-kAXGDrIFafAhgAAAPM"]
[Mon Jul 20 06:36:12.102830 2026] [security2:error] [pid 953991:tid 954222] [client 161.118.195.148:51161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WPK_X-kAXGDrIFafAjAAAAOo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:12.217845 2026] [security2:error] [pid 953991:tid 954130] [client 14.225.17.146:64109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4WOq_X-kAXGDrIFafADAAAAI4"], referer: http://swafforddetailing.com/OLD
[Mon Jul 20 06:36:12.293549 2026] [security2:error] [pid 953991:tid 954125] [client 104.234.53.63:61747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WPK_X-kAXGDrIFafAlwAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:12.306098 2026] [security2:error] [pid 953991:tid 954176] [client 77.110.127.138:50743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WPK_X-kAXGDrIFafAmAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:12.306240 2026] [security2:error] [pid 953991:tid 954176] [client 77.110.127.138:50743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WPK_X-kAXGDrIFafAmAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:12.329611 2026] [security2:error] [pid 953991:tid 954121] [client 34.73.38.214:55308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WPK_X-kAXGDrIFafAmwAAAIU"]
[Mon Jul 20 06:36:12.680146 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:51576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WPK_X-kAXGDrIFafAvQAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:12.711802 2026] [security2:error] [pid 953991:tid 954194] [client 34.73.38.214:65196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WPK_X-kAXGDrIFafAwwAAAM4"]
[Mon Jul 20 06:36:12.935021 2026] [security2:error] [pid 953991:tid 954135] [client 34.73.38.214:62141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WPK_X-kAXGDrIFafA0wAAAJM"]
[Mon Jul 20 06:36:12.962239 2026] [security2:error] [pid 953991:tid 954109] [remote 5.161.225.162:60858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WPK_X-kAXGDrIFafA1gAA5nU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:36:13.041024 2026] [security2:error] [pid 953991:tid 954147] [client 65.1.132.125:45854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WPa_X-kAXGDrIFafA4wAAAJ8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:36:13.257479 2026] [security2:error] [pid 953991:tid 954148] [client 161.118.195.148:51985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WPa_X-kAXGDrIFafA-gAAAKA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:13.379899 2026] [security2:error] [pid 953991:tid 954248] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WPK_X-kAXGDrIFafAxgAAAQQ"]
[Mon Jul 20 06:36:13.456196 2026] [security2:error] [pid 953991:tid 954217] [client 34.73.38.214:53778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WPa_X-kAXGDrIFafBCgAAAOU"]
[Mon Jul 20 06:36:13.516602 2026] [security2:error] [pid 953991:tid 954126] [client 77.110.127.138:50753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WPa_X-kAXGDrIFafBFQAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:13.595648 2026] [security2:error] [pid 953991:tid 954186] [client 171.60.139.123:54823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WPa_X-kAXGDrIFafBGwAAAMY"]
[Mon Jul 20 06:36:13.595796 2026] [security2:error] [pid 953991:tid 954186] [client 171.60.139.123:54823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WPa_X-kAXGDrIFafBGwAAAMY"]
[Mon Jul 20 06:36:13.608218 2026] [security2:error] [pid 953991:tid 954106] [remote 202.51.202.242:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WPa_X-kAXGDrIFafBGAAA0XI"]
[Mon Jul 20 06:36:13.673575 2026] [security2:error] [pid 953991:tid 954153] [client 34.73.38.214:65031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WPa_X-kAXGDrIFafBJAAAAKU"]
[Mon Jul 20 06:36:13.705226 2026] [security2:error] [pid 953991:tid 954154] [client 104.234.53.64:38509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WPa_X-kAXGDrIFafBKQAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:13.741233 2026] [security2:error] [pid 953991:tid 954246] [client 34.73.38.214:56169] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WPa_X-kAXGDrIFafBLQAAAQI"]
[Mon Jul 20 06:36:13.785619 2026] [security2:error] [pid 953991:tid 954199] [client 197.186.66.42:54772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WPa_X-kAXGDrIFafBLgAAANM"]
[Mon Jul 20 06:36:13.785716 2026] [security2:error] [pid 953991:tid 954199] [client 197.186.66.42:54772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WPa_X-kAXGDrIFafBLgAAANM"]
[Mon Jul 20 06:36:13.833663 2026] [security2:error] [pid 953991:tid 954187] [client 161.118.195.148:52424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WPa_X-kAXGDrIFafBMwAAAMc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:13.874241 2026] [security2:error] [pid 953991:tid 954158] [client 14.225.17.146:54408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4WPK_X-kAXGDrIFafAnAAAAKo"], referer: http://laceycaraccident.com/OLD
[Mon Jul 20 06:36:13.913411 2026] [security2:error] [pid 953991:tid 954247] [client 57.141.18.109:55210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WOK_X-kAXGDrIFae_ZAABA0Q"]
[Mon Jul 20 06:36:14.058473 2026] [security2:error] [pid 953991:tid 954230] [client 217.142.18.172:24724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WPq_X-kAXGDrIFafBSQAAAPI"]
[Mon Jul 20 06:36:14.061950 2026] [security2:error] [pid 953991:tid 954230] [client 217.142.18.172:24724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WPq_X-kAXGDrIFafBSQAAAPI"]
[Mon Jul 20 06:36:14.417448 2026] [security2:error] [pid 953991:tid 954215] [client 34.73.38.214:64865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WPq_X-kAXGDrIFafBaQAAAOM"]
[Mon Jul 20 06:36:14.417473 2026] [security2:error] [pid 953991:tid 954224] [client 161.118.195.148:52872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WPq_X-kAXGDrIFafBagAAAOw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:14.450179 2026] [security2:error] [pid 953991:tid 954148] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4WPq_X-kAXGDrIFafBWQAAoGU"], referer: http://assasalnazaha.com/OLD
[Mon Jul 20 06:36:14.509993 2026] [security2:error] [pid 953991:tid 954140] [client 57.141.18.122:27612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WOa_X-kAXGDrIFae_oAAAmEI"]
[Mon Jul 20 06:36:14.582385 2026] [security2:error] [pid 953991:tid 954144] [client 77.110.127.138:50727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WPq_X-kAXGDrIFafBdgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:14.582542 2026] [security2:error] [pid 953991:tid 954144] [client 77.110.127.138:50727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WPq_X-kAXGDrIFafBdgAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:14.679523 2026] [security2:error] [pid 953991:tid 954079] [remote 78.46.99.182:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WPq_X-kAXGDrIFafBfAAA61c"]
[Mon Jul 20 06:36:14.684302 2026] [security2:error] [pid 953991:tid 954157] [client 34.73.38.214:51322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WPq_X-kAXGDrIFafBfgAAAKk"]
[Mon Jul 20 06:36:14.797768 2026] [security2:error] [pid 953991:tid 954067] [remote 193.70.112.205:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WPq_X-kAXGDrIFafBjQAArUs"]
[Mon Jul 20 06:36:14.813884 2026] [security2:error] [pid 953991:tid 954022] [remote 202.51.202.242:34796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WPq_X-kAXGDrIFafBjgAA8R4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:14.863764 2026] [security2:error] [pid 953991:tid 954027] [remote 78.46.99.182:52316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WPq_X-kAXGDrIFafBkQAAliM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:14.996223 2026] [security2:error] [pid 953991:tid 954091] [remote 193.70.112.205:43974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WPq_X-kAXGDrIFafBlQAAkWM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:15.001978 2026] [security2:error] [pid 953991:tid 954129] [client 161.118.195.148:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WP6_X-kAXGDrIFafBmAAAAI0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:15.270521 2026] [security2:error] [pid 953991:tid 954214] [client 34.73.38.214:58881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WP6_X-kAXGDrIFafBtgAAAOI"]
[Mon Jul 20 06:36:15.273337 2026] [security2:error] [pid 953991:tid 954226] [client 50.116.65.227:35472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WP6_X-kAXGDrIFafBtwAAAO4"]
[Mon Jul 20 06:36:15.283253 2026] [security2:error] [pid 953991:tid 954242] [client 50.116.65.227:35480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WP6_X-kAXGDrIFafBuQAAAP4"]
[Mon Jul 20 06:36:15.339380 2026] [security2:error] [pid 953991:tid 954201] [client 34.73.38.214:62366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WP6_X-kAXGDrIFafBvAAAANU"]
[Mon Jul 20 06:36:15.442113 2026] [security2:error] [pid 953991:tid 954186] [client 14.225.17.146:64429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4WPq_X-kAXGDrIFafBYAAAAMY"], referer: http://mourgroup.com/OLD
[Mon Jul 20 06:36:15.579669 2026] [security2:error] [pid 953991:tid 954158] [client 161.118.195.148:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WP6_X-kAXGDrIFafBxQAAAKo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:15.687739 2026] [security2:error] [pid 953991:tid 954153] [client 77.110.127.138:50769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WP6_X-kAXGDrIFafBzgAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:15.689366 2026] [security2:error] [pid 953991:tid 954148] [client 223.237.130.40:57157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WP6_X-kAXGDrIFafBwwAAAKA"]
[Mon Jul 20 06:36:15.716570 2026] [security2:error] [pid 953991:tid 954181] [client 57.141.18.70:36616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WOq_X-kAXGDrIFae_9wAAwVE"]
[Mon Jul 20 06:36:15.833663 2026] [security2:error] [pid 953991:tid 954209] [client 14.225.17.146:57066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4WP6_X-kAXGDrIFafB0wAAAN0"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/OLD
[Mon Jul 20 06:36:15.969721 2026] [security2:error] [pid 953991:tid 954125] [client 77.110.127.138:50746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WP6_X-kAXGDrIFafB5wAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:15.969878 2026] [security2:error] [pid 953991:tid 954125] [client 77.110.127.138:50746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WP6_X-kAXGDrIFafB5wAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:16.110525 2026] [security2:error] [pid 953991:tid 954197] [client 34.73.38.214:61295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sarahmusica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WQK_X-kAXGDrIFafB-AAAANE"]
[Mon Jul 20 06:36:16.153243 2026] [security2:error] [pid 953991:tid 954193] [client 161.118.195.148:54095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WQK_X-kAXGDrIFafB_wAAAM0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:16.223202 2026] [security2:error] [pid 953991:tid 954223] [client 98.159.234.160:21851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WQK_X-kAXGDrIFafCDAAAAOs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:36:16.625626 2026] [security2:error] [pid 953991:tid 954179] [client 50.116.65.227:46932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4WQK_X-kAXGDrIFafCKwAAAL8"]
[Mon Jul 20 06:36:16.637098 2026] [security2:error] [pid 953991:tid 954189] [client 50.116.65.227:35508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4WQK_X-kAXGDrIFafCLAAAAJA"]
[Mon Jul 20 06:36:16.637638 2026] [security2:error] [pid 953991:tid 954156] [client 14.225.17.146:60434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4WP6_X-kAXGDrIFafBwAAAAKg"], referer: http://sesamegreenbeans.com/OLD
[Mon Jul 20 06:36:16.639636 2026] [security2:error] [pid 953991:tid 954183] [client 57.141.18.122:27628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WO6_X-kAXGDrIFafARwAAw1g"]
[Mon Jul 20 06:36:16.730237 2026] [security2:error] [pid 953991:tid 954175] [client 161.118.195.148:54433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WQK_X-kAXGDrIFafCNQAAALs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:16.753806 2026] [security2:error] [pid 953991:tid 954234] [client 34.73.38.214:50249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WQK_X-kAXGDrIFafCOAAAAPY"]
[Mon Jul 20 06:36:16.903178 2026] [security2:error] [pid 953991:tid 954248] [client 14.225.17.146:59049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4WQK_X-kAXGDrIFafCNwAAAQQ"], referer: http://elitetax-mi.com/OLD
[Mon Jul 20 06:36:16.938624 2026] [security2:error] [pid 953991:tid 954170] [client 14.225.17.146:59044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4WQK_X-kAXGDrIFafCMwAAALY"], referer: http://jvcmotorsports.com/OLD
[Mon Jul 20 06:36:17.066083 2026] [security2:error] [pid 953991:tid 954197] [client 103.178.190.6:13399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.190.178.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/xmlrpc.php"] [unique_id "al4WQa_X-kAXGDrIFafCWAAAANE"]
[Mon Jul 20 06:36:17.066301 2026] [security2:error] [pid 953991:tid 954197] [client 103.178.190.6:13399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "besttestedrecipes.com"] [uri "/xmlrpc.php"] [unique_id "al4WQa_X-kAXGDrIFafCWAAAANE"]
[Mon Jul 20 06:36:17.071475 2026] [core:error] [pid 953991:tid 954172] [client 14.225.17.146:59486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/OLD
[Mon Jul 20 06:36:17.071495 2026] [core:error] [pid 953991:tid 954172] [client 14.225.17.146:59486] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/OLD
[Mon Jul 20 06:36:17.113807 2026] [security2:error] [pid 953991:tid 954161] [client 77.110.127.138:50754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WQa_X-kAXGDrIFafCYwAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:17.250704 2026] [security2:error] [pid 953991:tid 954247] [client 57.141.0.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WQa_X-kAXGDrIFafCZAAAAQM"]
[Mon Jul 20 06:36:17.272846 2026] [security2:error] [pid 953991:tid 954221] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WQa_X-kAXGDrIFafCZQAAAOk"]
[Mon Jul 20 06:36:17.324107 2026] [security2:error] [pid 953991:tid 954234] [client 161.118.195.148:54840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WQa_X-kAXGDrIFafCdQAAAPY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:17.344716 2026] [security2:error] [pid 953991:tid 954086] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WQa_X-kAXGDrIFafCeAAAyF4"]
[Mon Jul 20 06:36:17.344877 2026] [security2:error] [pid 953991:tid 954188] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WQa_X-kAXGDrIFafCeAAAyF4"]
[Mon Jul 20 06:36:17.469592 2026] [security2:error] [pid 953991:tid 954151] [client 104.234.53.70:55855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WQa_X-kAXGDrIFafCfgAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:17.494153 2026] [security2:error] [pid 953991:tid 954112] [remote 66.94.101.63:49950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.101.94.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WQa_X-kAXGDrIFafCfwAA6Hg"]
[Mon Jul 20 06:36:17.494315 2026] [security2:error] [pid 953991:tid 954220] [client 66.94.101.63:49950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WQa_X-kAXGDrIFafCfwAA6Hg"]
[Mon Jul 20 06:36:17.674596 2026] [security2:error] [pid 953991:tid 954229] [client 14.225.17.146:54568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4WQa_X-kAXGDrIFafCgAAAAPE"], referer: https://sesamegreenbeans.com/OLD
[Mon Jul 20 06:36:17.677554 2026] [security2:error] [pid 953991:tid 954212] [client 57.141.18.9:63980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WPK_X-kAXGDrIFafAuwAA4Eo"]
[Mon Jul 20 06:36:17.700567 2026] [security2:error] [pid 953991:tid 954136] [client 113.160.97.242:50396] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WQa_X-kAXGDrIFafCjgAAAJQ"]
[Mon Jul 20 06:36:17.797882 2026] [security2:error] [pid 953991:tid 954243] [client 77.110.127.138:50758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WQa_X-kAXGDrIFafClwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:17.797997 2026] [security2:error] [pid 953991:tid 954243] [client 77.110.127.138:50758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WQa_X-kAXGDrIFafClwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:17.822789 2026] [security2:error] [pid 953991:tid 954162] [client 34.73.38.214:51994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sardimacmillan.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WQa_X-kAXGDrIFafCnAAAAK4"]
[Mon Jul 20 06:36:17.898719 2026] [security2:error] [pid 953991:tid 954181] [client 161.118.195.148:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WQa_X-kAXGDrIFafCpQAAAME"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:18.198573 2026] [security2:error] [pid 953991:tid 954216] [client 106.219.188.178:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCsAAAAOQ"]
[Mon Jul 20 06:36:18.198726 2026] [security2:error] [pid 953991:tid 954216] [client 106.219.188.178:27757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCsAAAAOQ"]
[Mon Jul 20 06:36:18.309671 2026] [security2:error] [pid 953991:tid 954185] [client 57.141.18.65:58764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WPa_X-kAXGDrIFafA-QAAxWY"]
[Mon Jul 20 06:36:18.343985 2026] [security2:error] [pid 953991:tid 954246] [client 213.152.162.79:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCwAAAAQI"]
[Mon Jul 20 06:36:18.344081 2026] [security2:error] [pid 953991:tid 954246] [client 213.152.162.79:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCwAAAAQI"]
[Mon Jul 20 06:36:18.390470 2026] [security2:error] [pid 953991:tid 954166] [client 112.208.70.94:44663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCxQAAALI"]
[Mon Jul 20 06:36:18.390583 2026] [security2:error] [pid 953991:tid 954166] [client 112.208.70.94:44663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCxQAAALI"]
[Mon Jul 20 06:36:18.403972 2026] [security2:error] [pid 953991:tid 954082] [remote 20.153.140.50:44376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WQq_X-kAXGDrIFafCxgAAiFo"]
[Mon Jul 20 06:36:18.465437 2026] [security2:error] [pid 953991:tid 954213] [client 187.108.85.186:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCzwAAAOE"]
[Mon Jul 20 06:36:18.465562 2026] [security2:error] [pid 953991:tid 954213] [client 187.108.85.186:59150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafCzwAAAOE"]
[Mon Jul 20 06:36:18.483281 2026] [security2:error] [pid 953991:tid 954144] [client 161.118.195.148:55634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WQq_X-kAXGDrIFafC0AAAAJw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:18.527432 2026] [security2:error] [pid 953991:tid 954023] [remote 57.141.18.101:43688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5570424"] [unique_id "al4WQq_X-kAXGDrIFafC0gAAoB8"]
[Mon Jul 20 06:36:18.622924 2026] [security2:error] [pid 953991:tid 954093] [remote 72.167.132.114:40224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafC2QAAvmU"]
[Mon Jul 20 06:36:18.623102 2026] [security2:error] [pid 953991:tid 954178] [client 72.167.132.114:40224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WQq_X-kAXGDrIFafC2QAAvmU"]
[Mon Jul 20 06:36:18.840825 2026] [security2:error] [pid 953991:tid 954099] [remote 20.153.140.50:44376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WQq_X-kAXGDrIFafC8QAA-Ws"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:36:19.073202 2026] [security2:error] [pid 953991:tid 954240] [client 216.73.216.78:8413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/index.php"] [unique_id "al4WQa_X-kAXGDrIFafChwAA_G8"]
[Mon Jul 20 06:36:19.083574 2026] [security2:error] [pid 953991:tid 954136] [client 161.118.195.148:56047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WQ6_X-kAXGDrIFafC_wAAAJQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:19.455187 2026] [security2:error] [pid 953991:tid 954228] [client 82.102.27.163:33240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WQ6_X-kAXGDrIFafDIQAAAPA"]
[Mon Jul 20 06:36:19.455258 2026] [security2:error] [pid 953991:tid 954228] [client 82.102.27.163:33240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WQ6_X-kAXGDrIFafDIQAAAPA"]
[Mon Jul 20 06:36:19.567507 2026] [security2:error] [pid 953991:tid 954153] [client 45.3.44.150:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WQ6_X-kAXGDrIFafDKAAAAKU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:19.659315 2026] [security2:error] [pid 953991:tid 954159] [client 161.118.195.148:56517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WQ6_X-kAXGDrIFafDLAAAAKs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:19.936980 2026] [security2:error] [pid 953991:tid 954223] [client 77.110.127.138:50794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WQ6_X-kAXGDrIFafDSQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:20.243367 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:56927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WRK_X-kAXGDrIFafDZQAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:20.254970 2026] [security2:error] [pid 953991:tid 954230] [client 171.61.165.146:2253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WRK_X-kAXGDrIFafDZgAAAPI"]
[Mon Jul 20 06:36:20.255080 2026] [security2:error] [pid 953991:tid 954230] [client 171.61.165.146:2253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WRK_X-kAXGDrIFafDZgAAAPI"]
[Mon Jul 20 06:36:20.315127 2026] [security2:error] [pid 953991:tid 954172] [client 103.153.183.69:50202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../etc/apache2/apache2.conf"] [unique_id "al4WRK_X-kAXGDrIFafDaQAAALg"], referer: https://www.bing.com/search?q=2j8i57
[Mon Jul 20 06:36:20.500006 2026] [security2:error] [pid 953991:tid 954089] [remote 20.153.140.50:44392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WRK_X-kAXGDrIFafDdwAAiGE"]
[Mon Jul 20 06:36:20.500235 2026] [security2:error] [pid 953991:tid 954124] [client 20.153.140.50:44392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WRK_X-kAXGDrIFafDdwAAiGE"]
[Mon Jul 20 06:36:20.601761 2026] [security2:error] [pid 953991:tid 954134] [client 158.173.166.181:48687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WRK_X-kAXGDrIFafDewAAAJI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:36:20.738336 2026] [security2:error] [pid 953991:tid 954202] [client 146.103.96.37:52662] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4WRK_X-kAXGDrIFafDgAAAANY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 06:36:20.815282 2026] [security2:error] [pid 953991:tid 954220] [client 161.118.195.148:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WRK_X-kAXGDrIFafDiwAAAOg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:20.936545 2026] [security2:error] [pid 953991:tid 954204] [client 103.125.179.95:61245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WRK_X-kAXGDrIFafDmQAAANg"]
[Mon Jul 20 06:36:20.950186 2026] [security2:error] [pid 953991:tid 954204] [client 103.125.179.95:61245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WRK_X-kAXGDrIFafDmQAAANg"]
[Mon Jul 20 06:36:21.084284 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WRa_X-kAXGDrIFafDqAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:21.084379 2026] [security2:error] [pid 953991:tid 954123] [client 77.110.127.138:50799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WRa_X-kAXGDrIFafDqAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:21.393452 2026] [security2:error] [pid 953991:tid 954236] [client 161.118.195.148:57758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WRa_X-kAXGDrIFafDxwAAAPg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:21.506253 2026] [security2:error] [pid 953991:tid 954241] [client 223.185.13.213:25881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WRa_X-kAXGDrIFafD1gAAAP0"]
[Mon Jul 20 06:36:21.506357 2026] [security2:error] [pid 953991:tid 954241] [client 223.185.13.213:25881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WRa_X-kAXGDrIFafD1gAAAP0"]
[Mon Jul 20 06:36:21.599879 2026] [security2:error] [pid 953991:tid 954220] [client 104.234.53.57:22865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4WRa_X-kAXGDrIFafD4gAAAOg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:21.764279 2026] [security2:error] [pid 953991:tid 954147] [client 57.141.18.22:30434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WQK_X-kAXGDrIFafCPQAAn3U"]
[Mon Jul 20 06:36:21.932800 2026] [security2:error] [pid 953991:tid 954202] [client 146.103.96.37:52662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4WRK_X-kAXGDrIFafDgAAAANY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 06:36:21.932848 2026] [security2:error] [pid 953991:tid 954202] [client 146.103.96.37:52662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4WRK_X-kAXGDrIFafDgAAAANY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 06:36:21.974940 2026] [security2:error] [pid 953991:tid 954176] [client 161.118.195.148:58115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WRa_X-kAXGDrIFafD-QAAALw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:22.320896 2026] [security2:error] [pid 953991:tid 954194] [client 14.225.17.146:57885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4WRa_X-kAXGDrIFafD_gAAAM4"]
[Mon Jul 20 06:36:22.485009 2026] [security2:error] [pid 953991:tid 954118] [remote 57.141.18.59:38424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5629755"] [unique_id "al4WRq_X-kAXGDrIFafEJQAA_X4"]
[Mon Jul 20 06:36:22.555313 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:58494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WRq_X-kAXGDrIFafEKQAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:22.711385 2026] [security2:error] [pid 953991:tid 954144] [client 77.110.127.138:50816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WRq_X-kAXGDrIFafEOAAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:22.817706 2026] [security2:error] [pid 953991:tid 954242] [client 50.116.65.227:14160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4WRq_X-kAXGDrIFafEQAAAAP4"]
[Mon Jul 20 06:36:22.828494 2026] [security2:error] [pid 953991:tid 954180] [client 50.116.65.227:43916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4WRq_X-kAXGDrIFafEQQAAANE"]
[Mon Jul 20 06:36:22.867690 2026] [security2:error] [pid 953991:tid 954248] [client 14.225.17.146:54325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4WRq_X-kAXGDrIFafEDgAAAQQ"], referer: http://overloadcomedy.com/OLD
[Mon Jul 20 06:36:23.014474 2026] [security2:error] [pid 953991:tid 954223] [client 77.110.127.138:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WR6_X-kAXGDrIFafEVAAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:23.149275 2026] [security2:error] [pid 953991:tid 954213] [client 161.118.195.148:58865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WR6_X-kAXGDrIFafEagAAAOE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:23.175346 2026] [security2:error] [pid 953991:tid 954190] [client 14.225.17.146:57121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4WR6_X-kAXGDrIFafEWQAAAMo"], referer: http://xp-design.co/OLD
[Mon Jul 20 06:36:23.200853 2026] [security2:error] [pid 953991:tid 954200] [client 14.225.17.146:54780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4WRa_X-kAXGDrIFafD0QAAANQ"], referer: http://nwcarvingacademy.com/OLD
[Mon Jul 20 06:36:23.269314 2026] [security2:error] [pid 953991:tid 954230] [client 77.110.127.138:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WR6_X-kAXGDrIFafEdgAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:23.543888 2026] [security2:error] [pid 953991:tid 954247] [client 77.110.127.138:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WR6_X-kAXGDrIFafEhQAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:23.705008 2026] [security2:error] [pid 953991:tid 954168] [client 14.225.17.146:60727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4WRq_X-kAXGDrIFafEGQAAALQ"], referer: http://expertcultures.com/OLD
[Mon Jul 20 06:36:23.731412 2026] [security2:error] [pid 953991:tid 954221] [client 161.118.195.148:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WR6_X-kAXGDrIFafEmgAAAOk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:23.804691 2026] [security2:error] [pid 953991:tid 954242] [client 77.110.127.138:50827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WR6_X-kAXGDrIFafEoQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:24.126983 2026] [security2:error] [pid 953991:tid 954223] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WSK_X-kAXGDrIFafEsQAAAOs"]
[Mon Jul 20 06:36:24.128228 2026] [security2:error] [pid 953991:tid 954244] [client 77.110.127.138:50829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WSK_X-kAXGDrIFafEugAAAQA"]
[Mon Jul 20 06:36:24.256684 2026] [security2:error] [pid 953991:tid 954179] [client 197.186.66.42:55275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafExwAAAL8"]
[Mon Jul 20 06:36:24.257123 2026] [security2:error] [pid 953991:tid 954179] [client 197.186.66.42:55275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafExwAAAL8"]
[Mon Jul 20 06:36:24.259860 2026] [security2:error] [pid 953991:tid 954199] [client 171.60.139.123:55351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafEyQAAANM"]
[Mon Jul 20 06:36:24.259984 2026] [security2:error] [pid 953991:tid 954199] [client 171.60.139.123:55351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafEyQAAANM"]
[Mon Jul 20 06:36:24.311422 2026] [security2:error] [pid 953991:tid 954125] [client 161.118.195.148:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WSK_X-kAXGDrIFafEzQAAAIk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:24.353837 2026] [security2:error] [pid 953991:tid 954194] [client 77.110.127.138:50832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WSK_X-kAXGDrIFafEzwAAAM4"]
[Mon Jul 20 06:36:24.412049 2026] [security2:error] [pid 953991:tid 954127] [client 152.58.191.29:55749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafEywAAAIs"]
[Mon Jul 20 06:36:24.458011 2026] [security2:error] [pid 953991:tid 954175] [client 14.225.17.146:54242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4WSK_X-kAXGDrIFafEwwAAALs"], referer: https://nwcarvingacademy.com/OLD
[Mon Jul 20 06:36:24.633626 2026] [security2:error] [pid 953991:tid 954242] [client 217.142.18.172:12708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafE7QAAAP4"]
[Mon Jul 20 06:36:24.637261 2026] [security2:error] [pid 953991:tid 954242] [client 217.142.18.172:12708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WSK_X-kAXGDrIFafE7QAAAP4"]
[Mon Jul 20 06:36:24.885702 2026] [security2:error] [pid 953991:tid 954191] [client 161.118.195.148:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WSK_X-kAXGDrIFafFBQAAAMs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:24.957697 2026] [security2:error] [pid 953991:tid 954014] [remote 57.141.18.28:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4604305"] [unique_id "al4WSK_X-kAXGDrIFafFBwAAvhY"]
[Mon Jul 20 06:36:25.025298 2026] [security2:error] [pid 953991:tid 954097] [remote 5.161.225.162:47434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WSa_X-kAXGDrIFafFCgAAqWk"]
[Mon Jul 20 06:36:25.025438 2026] [security2:error] [pid 953991:tid 954157] [client 5.161.225.162:47434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WSa_X-kAXGDrIFafFCgAAqWk"]
[Mon Jul 20 06:36:25.169877 2026] [security2:error] [pid 953991:tid 954230] [client 104.234.53.66:29247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WSa_X-kAXGDrIFafFDwAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:25.193783 2026] [security2:error] [pid 953991:tid 954198] [client 14.225.17.146:54227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4WSK_X-kAXGDrIFafEwgAAANI"], referer: http://retzkolonglogistics.com/OLD
[Mon Jul 20 06:36:25.335698 2026] [security2:error] [pid 953991:tid 954205] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4WSa_X-kAXGDrIFafFFgAAANk"]
[Mon Jul 20 06:36:25.460737 2026] [security2:error] [pid 953991:tid 954182] [client 161.118.195.148:60379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WSa_X-kAXGDrIFafFNgAAAMI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:25.543691 2026] [security2:error] [pid 953991:tid 954216] [client 77.110.127.138:50841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WSa_X-kAXGDrIFafFOgAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:25.543790 2026] [security2:error] [pid 953991:tid 954216] [client 77.110.127.138:50841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WSa_X-kAXGDrIFafFOgAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:25.980014 2026] [security2:error] [pid 953991:tid 954193] [client 14.225.17.146:55997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4WSa_X-kAXGDrIFafFVQAAAM0"], referer: http://cephasnext.com/OLD
[Mon Jul 20 06:36:26.038716 2026] [security2:error] [pid 953991:tid 954175] [client 161.118.195.148:60830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WSq_X-kAXGDrIFafFXwAAALs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:26.517474 2026] [security2:error] [pid 953991:tid 954001] [remote 5.161.225.162:47450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4WSq_X-kAXGDrIFafFfQAAkAk"]
[Mon Jul 20 06:36:26.609704 2026] [security2:error] [pid 953991:tid 954189] [client 161.118.195.148:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WSq_X-kAXGDrIFafFggAAAMk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:26.975317 2026] [security2:error] [pid 953991:tid 954023] [remote 5.161.225.162:47450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4WSq_X-kAXGDrIFafFnQAA6B8"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:36:27.043169 2026] [security2:error] [pid 953991:tid 954191] [client 39.48.81.23:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafFogAAAMs"]
[Mon Jul 20 06:36:27.043384 2026] [security2:error] [pid 953991:tid 954191] [client 39.48.81.23:61291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafFogAAAMs"]
[Mon Jul 20 06:36:27.186018 2026] [security2:error] [pid 953991:tid 954151] [client 161.118.195.148:61587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WS6_X-kAXGDrIFafFrgAAAKM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:27.489985 2026] [security2:error] [pid 953991:tid 954154] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WS6_X-kAXGDrIFafFygAAAKY"]
[Mon Jul 20 06:36:27.657177 2026] [security2:error] [pid 953991:tid 954148] [client 223.237.130.40:57589] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafF1wAAAKA"]
[Mon Jul 20 06:36:27.657319 2026] [security2:error] [pid 953991:tid 954148] [client 223.237.130.40:57589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafF1wAAAKA"]
[Mon Jul 20 06:36:27.664346 2026] [security2:error] [pid 953991:tid 954202] [client 106.219.188.178:14537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafF2AAAANY"]
[Mon Jul 20 06:36:27.724098 2026] [security2:error] [pid 953991:tid 954202] [client 106.219.188.178:14537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafF2AAAANY"]
[Mon Jul 20 06:36:27.759685 2026] [security2:error] [pid 953991:tid 954183] [client 161.118.195.148:61977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WS6_X-kAXGDrIFafF4gAAAMM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:27.888404 2026] [security2:error] [pid 953991:tid 954243] [client 57.141.18.33:54240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WRq_X-kAXGDrIFafEPQAA_0U"]
[Mon Jul 20 06:36:27.908781 2026] [security2:error] [pid 953991:tid 954161] [client 66.249.64.67:65370] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "kvnuk.co.uk"] [uri "/robots.txt"] [unique_id "al4WS6_X-kAXGDrIFafF7wAAAK0"]
[Mon Jul 20 06:36:27.936959 2026] [security2:error] [pid 953991:tid 954096] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafF8AAAvGg"]
[Mon Jul 20 06:36:27.937656 2026] [security2:error] [pid 953991:tid 954176] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WS6_X-kAXGDrIFafF8AAAvGg"]
[Mon Jul 20 06:36:28.008766 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WTK_X-kAXGDrIFafF9QAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:28.353174 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:62375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WTK_X-kAXGDrIFafGFgAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:28.385703 2026] [security2:error] [pid 953991:tid 954236] [client 14.225.17.146:55957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4WTK_X-kAXGDrIFafGEAAAAPg"], referer: http://betterbonddogtraining.com/OLD
[Mon Jul 20 06:36:28.495211 2026] [security2:error] [pid 953991:tid 954008] [remote 57.141.18.99:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2774927"] [unique_id "al4WTK_X-kAXGDrIFafGHAAA_xA"]
[Mon Jul 20 06:36:28.735377 2026] [security2:error] [pid 953991:tid 954188] [client 104.234.53.53:41417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WTK_X-kAXGDrIFafGMAAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:28.826160 2026] [security2:error] [pid 953991:tid 954039] [remote 173.249.4.11:41206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4WTK_X-kAXGDrIFafGOgAApi8"]
[Mon Jul 20 06:36:28.927205 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:62782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WTK_X-kAXGDrIFafGSAAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:28.944891 2026] [security2:error] [pid 953991:tid 954193] [client 187.108.85.186:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WTK_X-kAXGDrIFafGSQAAAM0"]
[Mon Jul 20 06:36:28.945044 2026] [security2:error] [pid 953991:tid 954193] [client 187.108.85.186:59667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WTK_X-kAXGDrIFafGSQAAAM0"]
[Mon Jul 20 06:36:28.964354 2026] [security2:error] [pid 953991:tid 954149] [client 57.141.18.15:63820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WR6_X-kAXGDrIFafEpgAAoXE"]
[Mon Jul 20 06:36:29.058405 2026] [security2:error] [pid 953991:tid 954217] [client 14.225.17.146:52612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4WTK_X-kAXGDrIFafGPQAAAOU"], referer: http://samdothan.org/OLD
[Mon Jul 20 06:36:29.105457 2026] [security2:error] [pid 953991:tid 954062] [remote 173.249.4.11:41206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4WTa_X-kAXGDrIFafGUQAA80Y"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:36:29.118411 2026] [security2:error] [pid 953991:tid 954152] [client 14.225.17.146:49412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4WTK_X-kAXGDrIFafF_QAAAKQ"], referer: http://nikkidesigns.net/OLD
[Mon Jul 20 06:36:29.291514 2026] [security2:error] [pid 953991:tid 954246] [client 14.225.17.146:64284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4WTa_X-kAXGDrIFafGUgAAAQI"], referer: http://margaretspeckogawa.com/OLD
[Mon Jul 20 06:36:29.338504 2026] [security2:error] [pid 953991:tid 954047] [remote 162.19.246.208:34238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4WTa_X-kAXGDrIFafGYwAAtTc"]
[Mon Jul 20 06:36:29.512245 2026] [security2:error] [pid 953991:tid 954224] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4WTK_X-kAXGDrIFafGRwAA7Gk"], referer: http://ali-alghanim.net/OLD
[Mon Jul 20 06:36:29.522188 2026] [security2:error] [pid 953991:tid 954212] [client 161.118.195.148:63144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WTa_X-kAXGDrIFafGfAAAAOA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:29.523710 2026] [security2:error] [pid 953991:tid 954159] [client 65.111.28.127:60457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WTa_X-kAXGDrIFafGewAAAKs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:29.565067 2026] [security2:error] [pid 953991:tid 954112] [remote 162.19.246.208:34238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4WTa_X-kAXGDrIFafGfgAAuHg"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:36:29.751502 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WTa_X-kAXGDrIFafGgQAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:29.751609 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:50859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WTa_X-kAXGDrIFafGgQAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:30.104794 2026] [security2:error] [pid 953991:tid 954225] [client 161.118.195.148:63476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WTq_X-kAXGDrIFafGpAAAAO0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:30.128452 2026] [security2:error] [pid 953991:tid 954126] [client 14.225.17.146:64240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4WTK_X-kAXGDrIFafGLgAAAIo"]
[Mon Jul 20 06:36:30.639406 2026] [security2:error] [pid 953991:tid 954145] [client 14.225.17.146:53993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4WTq_X-kAXGDrIFafGqwAAAJ0"], referer: http://idigress.agency/OLD
[Mon Jul 20 06:36:30.683923 2026] [security2:error] [pid 953991:tid 954154] [client 161.118.195.148:63864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WTq_X-kAXGDrIFafG1QAAAKY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:30.687472 2026] [security2:error] [pid 953991:tid 954131] [client 52.109.68.130:26594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4WTq_X-kAXGDrIFafG1AAAAI8"]
[Mon Jul 20 06:36:30.706439 2026] [security2:error] [pid 953991:tid 954133] [client 171.61.165.146:28496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WTq_X-kAXGDrIFafG1wAAAJE"]
[Mon Jul 20 06:36:30.706560 2026] [security2:error] [pid 953991:tid 954133] [client 171.61.165.146:28496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WTq_X-kAXGDrIFafG1wAAAJE"]
[Mon Jul 20 06:36:30.750132 2026] [security2:error] [pid 953991:tid 954152] [client 172.200.24.58:24772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4WTq_X-kAXGDrIFafG2wAAAKQ"]
[Mon Jul 20 06:36:30.810710 2026] [security2:error] [pid 953991:tid 954230] [client 172.200.24.58:24772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4WTq_X-kAXGDrIFafG5wAAAPI"]
[Mon Jul 20 06:36:30.843382 2026] [security2:error] [pid 953991:tid 954203] [client 52.109.68.130:26594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4WTq_X-kAXGDrIFafG7gAAANc"]
[Mon Jul 20 06:36:31.021946 2026] [security2:error] [pid 953991:tid 954123] [client 104.207.52.164:43977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WTq_X-kAXGDrIFafG_QAAAIc"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:31.264969 2026] [security2:error] [pid 953991:tid 954207] [client 161.118.195.148:64257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WT6_X-kAXGDrIFafHCAAAANs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:31.406338 2026] [security2:error] [pid 953991:tid 954169] [client 213.152.162.79:55464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4WT6_X-kAXGDrIFafHFgAAALU"]
[Mon Jul 20 06:36:31.406429 2026] [security2:error] [pid 953991:tid 954169] [client 213.152.162.79:55464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4WT6_X-kAXGDrIFafHFgAAALU"]
[Mon Jul 20 06:36:31.450540 2026] [security2:error] [pid 953991:tid 954222] [client 112.208.70.94:45078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WT6_X-kAXGDrIFafHHAAAAOo"]
[Mon Jul 20 06:36:31.450643 2026] [security2:error] [pid 953991:tid 954222] [client 112.208.70.94:45078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WT6_X-kAXGDrIFafHHAAAAOo"]
[Mon Jul 20 06:36:31.699108 2026] [security2:error] [pid 953991:tid 954132] [client 45.3.44.108:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WT6_X-kAXGDrIFafHMgAAAJA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:31.848050 2026] [security2:error] [pid 953991:tid 954229] [client 161.118.195.148:64677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WT6_X-kAXGDrIFafHQAAAAPE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:31.923930 2026] [security2:error] [pid 953991:tid 954213] [client 77.110.127.138:50870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WT6_X-kAXGDrIFafHRwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:31.930265 2026] [security2:error] [pid 953991:tid 954182] [client 57.141.18.87:26278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WSq_X-kAXGDrIFafFhAAAwno"]
[Mon Jul 20 06:36:32.065445 2026] [security2:error] [pid 953991:tid 954121] [client 103.125.179.95:61729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHTwAAAIU"]
[Mon Jul 20 06:36:32.066515 2026] [security2:error] [pid 953991:tid 954121] [client 103.125.179.95:61729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHTwAAAIU"]
[Mon Jul 20 06:36:32.367179 2026] [security2:error] [pid 953991:tid 954119] [remote 103.152.165.165:3800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.165.152.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WUK_X-kAXGDrIFafHZwAAwX8"]
[Mon Jul 20 06:36:32.400307 2026] [security2:error] [pid 953991:tid 954000] [remote 100.42.189.89:54240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHbAABBAg"]
[Mon Jul 20 06:36:32.400446 2026] [security2:error] [pid 953991:tid 954248] [client 100.42.189.89:54240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHbAABBAg"]
[Mon Jul 20 06:36:32.420384 2026] [security2:error] [pid 953991:tid 954226] [client 161.118.195.148:65085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WUK_X-kAXGDrIFafHbwAAAO4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:32.535173 2026] [security2:error] [pid 953991:tid 954139] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WUK_X-kAXGDrIFafHcAAAAJc"]
[Mon Jul 20 06:36:32.661920 2026] [security2:error] [pid 953991:tid 954194] [client 57.141.18.25:63184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WS6_X-kAXGDrIFafFpQAAziU"]
[Mon Jul 20 06:36:32.729679 2026] [security2:error] [pid 953991:tid 954141] [client 77.110.127.138:50879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WUK_X-kAXGDrIFafHgQAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:32.793833 2026] [security2:error] [pid 953991:tid 954051] [remote 103.152.165.165:3800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.165.152.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WUK_X-kAXGDrIFafHhgAA_js"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:36:32.852428 2026] [security2:error] [pid 953991:tid 954167] [client 103.238.106.162:60697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHiQAAALM"]
[Mon Jul 20 06:36:32.852571 2026] [security2:error] [pid 953991:tid 954167] [client 103.238.106.162:60697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHiQAAALM"]
[Mon Jul 20 06:36:32.955642 2026] [security2:error] [pid 953991:tid 954236] [client 223.185.13.213:18383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHlgAAAPg"]
[Mon Jul 20 06:36:32.955794 2026] [security2:error] [pid 953991:tid 954236] [client 223.185.13.213:18383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WUK_X-kAXGDrIFafHlgAAAPg"]
[Mon Jul 20 06:36:32.995427 2026] [security2:error] [pid 953991:tid 954189] [client 161.118.195.148:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WUK_X-kAXGDrIFafHmAAAAMk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:33.520397 2026] [security2:error] [pid 953991:tid 954146] [client 152.58.191.29:56063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WUa_X-kAXGDrIFafHqwAAAJ4"]
[Mon Jul 20 06:36:33.578945 2026] [security2:error] [pid 953991:tid 954229] [client 161.118.195.148:49477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WUa_X-kAXGDrIFafHxwAAAPE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:33.665802 2026] [security2:error] [pid 953991:tid 954183] [client 14.225.17.146:57176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4WUa_X-kAXGDrIFafHwAAAAMM"], referer: http://dnsplumbing.com/OLD
[Mon Jul 20 06:36:33.732849 2026] [security2:error] [pid 953991:tid 954209] [client 77.110.127.138:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WUa_X-kAXGDrIFafH0QAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:33.732946 2026] [security2:error] [pid 953991:tid 954209] [client 77.110.127.138:50886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WUa_X-kAXGDrIFafH0QAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:33.794862 2026] [security2:error] [pid 953991:tid 954201] [client 77.110.127.138:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WUa_X-kAXGDrIFafH1gAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:33.895776 2026] [security2:error] [pid 953991:tid 954205] [client 77.110.127.138:50889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WUa_X-kAXGDrIFafH4wAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:33.895867 2026] [security2:error] [pid 953991:tid 954205] [client 77.110.127.138:50889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WUa_X-kAXGDrIFafH4wAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:33.995390 2026] [security2:error] [pid 953991:tid 954211] [client 104.234.53.92:21305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WUa_X-kAXGDrIFafH7wAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:34.161157 2026] [security2:error] [pid 953991:tid 954146] [client 161.118.195.148:49940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WUq_X-kAXGDrIFafH-wAAAJ4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:34.186627 2026] [security2:error] [pid 953991:tid 954145] [client 158.173.89.95:49431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WUq_X-kAXGDrIFafH_wAAAJ0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:36:34.511160 2026] [security2:error] [pid 953991:tid 954081] [remote 216.73.217.138:64294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WUq_X-kAXGDrIFafIEwAAy1k"]
[Mon Jul 20 06:36:34.714311 2026] [security2:error] [pid 953991:tid 954204] [client 216.73.217.138:64294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WUq_X-kAXGDrIFafIJAAA2Ac"]
[Mon Jul 20 06:36:34.734413 2026] [security2:error] [pid 953991:tid 954146] [client 161.118.195.148:50394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WUq_X-kAXGDrIFafIKwAAAJ4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:34.812580 2026] [security2:error] [pid 953991:tid 954248] [client 171.60.139.123:55856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WUq_X-kAXGDrIFafILgAAAQQ"]
[Mon Jul 20 06:36:34.812710 2026] [security2:error] [pid 953991:tid 954248] [client 171.60.139.123:55856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WUq_X-kAXGDrIFafILgAAAQQ"]
[Mon Jul 20 06:36:34.915146 2026] [security2:error] [pid 953991:tid 954193] [client 57.141.18.35:57434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WTa_X-kAXGDrIFafGcQAAzWo"]
[Mon Jul 20 06:36:34.929286 2026] [security2:error] [pid 953991:tid 954202] [client 197.186.66.42:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WUq_X-kAXGDrIFafINwAAANY"]
[Mon Jul 20 06:36:34.929401 2026] [security2:error] [pid 953991:tid 954202] [client 197.186.66.42:55779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WUq_X-kAXGDrIFafINwAAANY"]
[Mon Jul 20 06:36:35.063131 2026] [security2:error] [pid 953991:tid 954170] [client 104.234.53.58:48505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4WUq_X-kAXGDrIFafINgAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:35.232915 2026] [security2:error] [pid 953991:tid 954229] [client 217.142.18.172:4870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WU6_X-kAXGDrIFafIXgAAAPE"]
[Mon Jul 20 06:36:35.233072 2026] [security2:error] [pid 953991:tid 954229] [client 217.142.18.172:4870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WU6_X-kAXGDrIFafIXgAAAPE"]
[Mon Jul 20 06:36:35.309706 2026] [security2:error] [pid 953991:tid 954149] [client 161.118.195.148:50807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WU6_X-kAXGDrIFafIYQAAAKE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:35.331822 2026] [security2:error] [pid 953991:tid 954168] [client 14.225.17.146:61120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIUwAAALQ"]
[Mon Jul 20 06:36:35.446882 2026] [security2:error] [pid 953991:tid 954122] [client 77.110.127.138:50907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WU6_X-kAXGDrIFafIbQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:35.500392 2026] [security2:error] [pid 953991:tid 954199] [client 77.110.127.138:50910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WU6_X-kAXGDrIFafIdAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:35.500504 2026] [security2:error] [pid 953991:tid 954199] [client 77.110.127.138:50910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WU6_X-kAXGDrIFafIdAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:35.746891 2026] [security2:error] [pid 953991:tid 954166] [client 77.110.127.138:50912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WU6_X-kAXGDrIFafIggAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:35.865411 2026] [security2:error] [pid 953991:tid 954161] [client 77.110.127.138:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WU6_X-kAXGDrIFafIkgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:35.865520 2026] [security2:error] [pid 953991:tid 954161] [client 77.110.127.138:50914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WU6_X-kAXGDrIFafIkgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:35.884576 2026] [security2:error] [pid 953991:tid 954211] [client 161.118.195.148:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIlAAAAN8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:36.034404 2026] [security2:error] [pid 953991:tid 954215] [client 77.110.127.138:50916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WVK_X-kAXGDrIFafImwAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:36.055850 2026] [security2:error] [pid 953991:tid 954156] [client 14.225.17.146:56992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIlgAAAKg"], referer: http://reosportsboats.com/OLD
[Mon Jul 20 06:36:36.400618 2026] [security2:error] [pid 953991:tid 954122] [client 14.225.17.146:57158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4WVK_X-kAXGDrIFafIrwAAAIY"], referer: http://falconarrowshop.com/OLD
[Mon Jul 20 06:36:36.475572 2026] [security2:error] [pid 953991:tid 954157] [client 161.118.195.148:51667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WVK_X-kAXGDrIFafIxQAAAKk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:36.802191 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WVK_X-kAXGDrIFafI1wAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:36.843704 2026] [security2:error] [pid 953991:tid 954127] [client 104.234.53.58:48505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WVK_X-kAXGDrIFafI2QAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:36.995104 2026] [security2:error] [pid 953991:tid 954177] [client 14.225.17.146:52955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4WVK_X-kAXGDrIFafI4wAAAL0"], referer: https://reosportsboats.com/OLD
[Mon Jul 20 06:36:37.009857 2026] [security2:error] [pid 953991:tid 954039] [remote 188.40.28.4:36060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4WVa_X-kAXGDrIFafI6wAAwC8"]
[Mon Jul 20 06:36:37.065689 2026] [security2:error] [pid 953991:tid 954162] [client 161.118.195.148:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WVa_X-kAXGDrIFafI8AAAAK4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:37.115821 2026] [security2:error] [pid 953991:tid 954144] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WVK_X-kAXGDrIFafI6gAAAJw"]
[Mon Jul 20 06:36:37.191958 2026] [security2:error] [pid 953991:tid 954126] [client 57.141.18.103:29896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WT6_X-kAXGDrIFafHMAAAiiQ"]
[Mon Jul 20 06:36:37.216904 2026] [security2:error] [pid 953991:tid 954080] [remote 188.40.28.4:36060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4WVa_X-kAXGDrIFafJAQAAyFg"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:36:37.261170 2026] [security2:error] [pid 953991:tid 954214] [client 84.37.228.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIkwAAAOI"]
[Mon Jul 20 06:36:37.448305 2026] [security2:error] [pid 953991:tid 954213] [client 77.110.127.138:50925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WVa_X-kAXGDrIFafJGgAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:37.448415 2026] [security2:error] [pid 953991:tid 954213] [client 77.110.127.138:50925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WVa_X-kAXGDrIFafJGgAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:37.553195 2026] [security2:error] [pid 953991:tid 954142] [client 160.187.117.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4WVK_X-kAXGDrIFafIsAAAAJo"]
[Mon Jul 20 06:36:37.579133 2026] [security2:error] [pid 953991:tid 954209] [client 14.225.17.146:65268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4WVa_X-kAXGDrIFafJEAAAAN0"], referer: http://securingmemories.com/OLD
[Mon Jul 20 06:36:37.603118 2026] [security2:error] [pid 953991:tid 954224] [client 14.225.17.146:57253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIegAAAOw"], referer: http://ksands.co.uk/OLD
[Mon Jul 20 06:36:37.640821 2026] [security2:error] [pid 953991:tid 954218] [client 161.118.195.148:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WVa_X-kAXGDrIFafJJgAAAOY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:37.760403 2026] [core:error] [pid 953991:tid 954200] [client 14.225.17.146:52897] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/OLD
[Mon Jul 20 06:36:37.760422 2026] [core:error] [pid 953991:tid 954200] [client 14.225.17.146:52897] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/OLD
[Mon Jul 20 06:36:37.772377 2026] [security2:error] [pid 953991:tid 954128] [client 77.110.127.138:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WVa_X-kAXGDrIFafJMAAAAIw"]
[Mon Jul 20 06:36:37.772456 2026] [security2:error] [pid 953991:tid 954128] [client 77.110.127.138:50932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WVa_X-kAXGDrIFafJMAAAAIw"]
[Mon Jul 20 06:36:37.881872 2026] [core:error] [pid 953991:tid 954213] [client 14.225.17.146:53038] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:36:37.881894 2026] [core:error] [pid 953991:tid 954213] [client 14.225.17.146:53038] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:36:37.937787 2026] [security2:error] [pid 953991:tid 954201] [client 77.110.127.138:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WVa_X-kAXGDrIFafJPgAAANU"]
[Mon Jul 20 06:36:37.937877 2026] [security2:error] [pid 953991:tid 954201] [client 77.110.127.138:50881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WVa_X-kAXGDrIFafJPgAAANU"]
[Mon Jul 20 06:36:38.131819 2026] [security2:error] [pid 953991:tid 954152] [client 57.141.18.114:22210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WUK_X-kAXGDrIFafHhQAApHE"]
[Mon Jul 20 06:36:38.230070 2026] [security2:error] [pid 953991:tid 954151] [client 161.118.195.148:53091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WVq_X-kAXGDrIFafJWgAAAKM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:38.457796 2026] [security2:error] [pid 953991:tid 954154] [client 106.219.188.178:25930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WVq_X-kAXGDrIFafJaAAAAKY"]
[Mon Jul 20 06:36:38.472283 2026] [security2:error] [pid 953991:tid 954154] [client 106.219.188.178:25930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WVq_X-kAXGDrIFafJaAAAAKY"]
[Mon Jul 20 06:36:38.594094 2026] [security2:error] [pid 953991:tid 954057] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WVq_X-kAXGDrIFafJcwAAz0E"]
[Mon Jul 20 06:36:38.594310 2026] [security2:error] [pid 953991:tid 954195] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WVq_X-kAXGDrIFafJcwAAz0E"]
[Mon Jul 20 06:36:38.654374 2026] [security2:error] [pid 953991:tid 954224] [client 170.64.227.98:53040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sustaintheart.com"] [uri "/wp-login.php"] [unique_id "al4WVq_X-kAXGDrIFafJcQAAAOw"]
[Mon Jul 20 06:36:38.806628 2026] [security2:error] [pid 953991:tid 954150] [client 161.118.195.148:53559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WVq_X-kAXGDrIFafJhQAAAKI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:38.926457 2026] [security2:error] [pid 953991:tid 954226] [client 223.237.130.40:58009] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WVq_X-kAXGDrIFafJkwAAAO4"]
[Mon Jul 20 06:36:38.926616 2026] [security2:error] [pid 953991:tid 954226] [client 223.237.130.40:58009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WVq_X-kAXGDrIFafJkwAAAO4"]
[Mon Jul 20 06:36:39.274057 2026] [security2:error] [pid 953991:tid 954157] [client 170.64.227.98:53074] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "sustaintheart.com"] [uri "/wp-login.php"] [unique_id "al4WV6_X-kAXGDrIFafJrwAAAKk"]
[Mon Jul 20 06:36:39.382485 2026] [security2:error] [pid 953991:tid 954152] [client 161.118.195.148:53998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WV6_X-kAXGDrIFafJuwAAAKQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:39.562657 2026] [security2:error] [pid 953991:tid 954212] [client 187.108.85.186:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WV6_X-kAXGDrIFafJxAAAAOA"]
[Mon Jul 20 06:36:39.562775 2026] [security2:error] [pid 953991:tid 954212] [client 187.108.85.186:60190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WV6_X-kAXGDrIFafJxAAAAOA"]
[Mon Jul 20 06:36:39.638632 2026] [security2:error] [pid 953991:tid 954238] [client 45.185.163.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4WV6_X-kAXGDrIFafJwgAAAPo"]
[Mon Jul 20 06:36:39.647212 2026] [security2:error] [pid 953991:tid 954233] [client 45.185.163.53:55018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/25352.php"] [unique_id "al4WV6_X-kAXGDrIFafJvgAA9UI"]
[Mon Jul 20 06:36:39.763092 2026] [security2:error] [pid 953991:tid 954143] [client 39.48.81.23:61853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WV6_X-kAXGDrIFafJ0AAAAJs"]
[Mon Jul 20 06:36:39.763220 2026] [security2:error] [pid 953991:tid 954143] [client 39.48.81.23:61853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WV6_X-kAXGDrIFafJ0AAAAJs"]
[Mon Jul 20 06:36:39.910274 2026] [security2:error] [pid 953991:tid 954216] [client 18.184.179.151:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WV6_X-kAXGDrIFafJ3wAAAOQ"]
[Mon Jul 20 06:36:39.957937 2026] [security2:error] [pid 953991:tid 954157] [client 161.118.195.148:54464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WV6_X-kAXGDrIFafJ6gAAAKk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:40.222916 2026] [proxy:error] [pid 953991:tid 954144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:40.222992 2026] [proxy_http:error] [pid 953991:tid 954144] [client 34.73.38.214:62448] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:40.223428 2026] [proxy:error] [pid 953991:tid 954144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:40.223462 2026] [proxy_http:error] [pid 953991:tid 954144] [client 34.73.38.214:62448] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:40.223830 2026] [proxy:error] [pid 953991:tid 954182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:40.223905 2026] [proxy_http:error] [pid 953991:tid 954182] [client 34.73.38.214:62444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:40.224502 2026] [proxy:error] [pid 953991:tid 954182] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:40.224535 2026] [proxy_http:error] [pid 953991:tid 954182] [client 34.73.38.214:62444] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:40.333123 2026] [security2:error] [pid 953991:tid 954197] [client 57.141.18.20:41238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIPAAA0Uw"]
[Mon Jul 20 06:36:40.393283 2026] [security2:error] [pid 953991:tid 954150] [client 74.208.214.194:48202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WWK_X-kAXGDrIFafKDwAAAKI"]
[Mon Jul 20 06:36:40.507406 2026] [security2:error] [pid 953991:tid 954130] [client 52.59.238.198:58092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WWK_X-kAXGDrIFafKFQAAAI4"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:36:40.547006 2026] [security2:error] [pid 953991:tid 954153] [client 161.118.195.148:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WWK_X-kAXGDrIFafKGgAAAKU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:40.830360 2026] [security2:error] [pid 953991:tid 954165] [client 104.234.53.85:24017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WWK_X-kAXGDrIFafKMQAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:40.887502 2026] [security2:error] [pid 953991:tid 954201] [client 45.3.48.137:58765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/xmlrpc.php"] [unique_id "al4WWK_X-kAXGDrIFafKNQAAANU"]
[Mon Jul 20 06:36:40.915182 2026] [security2:error] [pid 953991:tid 954170] [client 77.110.127.138:50966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WWK_X-kAXGDrIFafKPQAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:41.012372 2026] [security2:error] [pid 953991:tid 954137] [client 57.141.18.117:28130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WU6_X-kAXGDrIFafIfgAAlUU"]
[Mon Jul 20 06:36:41.018565 2026] [security2:error] [pid 953991:tid 954180] [client 74.208.214.194:48204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WWa_X-kAXGDrIFafKQwAAAMA"]
[Mon Jul 20 06:36:41.133250 2026] [security2:error] [pid 953991:tid 954126] [client 161.118.195.148:55364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WWa_X-kAXGDrIFafKVgAAAIo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:41.344398 2026] [security2:error] [pid 953991:tid 954241] [client 171.61.165.146:18563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WWa_X-kAXGDrIFafKXwAAAP0"]
[Mon Jul 20 06:36:41.364756 2026] [security2:error] [pid 953991:tid 954241] [client 171.61.165.146:18563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WWa_X-kAXGDrIFafKXwAAAP0"]
[Mon Jul 20 06:36:41.491198 2026] [security2:error] [pid 953991:tid 954187] [client 77.110.127.138:50975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WWa_X-kAXGDrIFafKcAAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:41.491280 2026] [security2:error] [pid 953991:tid 954187] [client 77.110.127.138:50975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WWa_X-kAXGDrIFafKcAAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:41.498348 2026] [security2:error] [pid 953991:tid 954246] [client 65.111.26.102:40023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WWa_X-kAXGDrIFafKbQAAAQI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:41.659040 2026] [proxy:error] [pid 953991:tid 954169] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:41.659116 2026] [proxy_http:error] [pid 953991:tid 954169] [client 34.73.38.214:63418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:41.659827 2026] [proxy:error] [pid 953991:tid 954169] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:41.659869 2026] [proxy_http:error] [pid 953991:tid 954169] [client 34.73.38.214:63418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:41.671509 2026] [proxy:error] [pid 953991:tid 954230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:41.671594 2026] [proxy_http:error] [pid 953991:tid 954230] [client 34.73.38.214:63323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:41.672183 2026] [proxy:error] [pid 953991:tid 954230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:41.672223 2026] [proxy_http:error] [pid 953991:tid 954230] [client 34.73.38.214:63323] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:41.708767 2026] [security2:error] [pid 953991:tid 954124] [client 161.118.195.148:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WWa_X-kAXGDrIFafKgwAAAIg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:41.996897 2026] [security2:error] [pid 953991:tid 954064] [remote 192.241.143.148:58686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WWa_X-kAXGDrIFafKnQAA_Ug"]
[Mon Jul 20 06:36:42.081297 2026] [security2:error] [pid 953991:tid 954215] [client 57.141.18.83:63254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WVK_X-kAXGDrIFafIzgAA4z0"]
[Mon Jul 20 06:36:42.186232 2026] [security2:error] [pid 953991:tid 954036] [remote 192.241.143.148:58686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WWq_X-kAXGDrIFafKqQAAiCw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:36:42.282200 2026] [security2:error] [pid 953991:tid 954198] [client 161.118.195.148:56360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WWq_X-kAXGDrIFafKsQAAANI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:42.386607 2026] [security2:error] [pid 953991:tid 954214] [client 105.172.34.103:46924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4WWq_X-kAXGDrIFafKsgAAAOI"]
[Mon Jul 20 06:36:42.573977 2026] [security2:error] [pid 953991:tid 954207] [client 57.141.18.44:34470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WVa_X-kAXGDrIFafI_QAA21U"]
[Mon Jul 20 06:36:42.617827 2026] [proxy:error] [pid 953991:tid 954181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:42.617880 2026] [proxy_http:error] [pid 953991:tid 954181] [client 34.73.38.214:55013] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:42.618687 2026] [proxy:error] [pid 953991:tid 954181] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:42.618731 2026] [proxy_http:error] [pid 953991:tid 954181] [client 34.73.38.214:55013] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:42.623030 2026] [proxy:error] [pid 953991:tid 954188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:42.623085 2026] [proxy_http:error] [pid 953991:tid 954188] [client 34.73.38.214:55036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:42.623489 2026] [proxy:error] [pid 953991:tid 954188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:36:42.623521 2026] [proxy_http:error] [pid 953991:tid 954188] [client 34.73.38.214:55036] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:36:42.710700 2026] [security2:error] [pid 953991:tid 954192] [client 37.59.21.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4WWq_X-kAXGDrIFafK3wAAAMw"]
[Mon Jul 20 06:36:42.782049 2026] [security2:error] [pid 953991:tid 954166] [client 103.125.179.95:62216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WWq_X-kAXGDrIFafK8AAAALI"]
[Mon Jul 20 06:36:42.782213 2026] [security2:error] [pid 953991:tid 954166] [client 103.125.179.95:62216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WWq_X-kAXGDrIFafK8AAAALI"]
[Mon Jul 20 06:36:42.864139 2026] [security2:error] [pid 953991:tid 954239] [client 161.118.195.148:56854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WWq_X-kAXGDrIFafK-QAAAPs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:42.903112 2026] [security2:error] [pid 953991:tid 954189] [client 223.185.13.213:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WWq_X-kAXGDrIFafLAQAAAMk"]
[Mon Jul 20 06:36:42.903213 2026] [security2:error] [pid 953991:tid 954189] [client 223.185.13.213:7592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WWq_X-kAXGDrIFafLAQAAAMk"]
[Mon Jul 20 06:36:42.933641 2026] [security2:error] [pid 953991:tid 954138] [client 34.74.185.202:58711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WWq_X-kAXGDrIFafLAgAAAJY"]
[Mon Jul 20 06:36:42.962575 2026] [security2:error] [pid 953991:tid 954191] [client 45.224.123.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4WWq_X-kAXGDrIFafK9QAAAMs"]
[Mon Jul 20 06:36:43.025279 2026] [security2:error] [pid 953991:tid 954142] [client 14.225.17.146:53021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4WWa_X-kAXGDrIFafKhgAAAJo"], referer: http://cloudspacesgroup.com/OLD
[Mon Jul 20 06:36:43.130180 2026] [security2:error] [pid 953991:tid 954153] [client 216.73.217.138:57201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WW6_X-kAXGDrIFafLEQAApWU"]
[Mon Jul 20 06:36:43.135397 2026] [security2:error] [pid 953991:tid 954153] [client 216.73.217.138:57201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WW6_X-kAXGDrIFafLEgAApTk"]
[Mon Jul 20 06:36:43.216392 2026] [autoindex:error] [pid 953991:tid 954217] [client 173.249.34.197:57575] AH01276: Cannot serve directory /home4/chestfa2/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:36:43.262102 2026] [security2:error] [pid 953991:tid 954176] [remote 45.224.123.32:21983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/25352.php"] [unique_id "al4WWq_X-kAXGDrIFafK7QAAkjI"]
[Mon Jul 20 06:36:43.288435 2026] [security2:error] [pid 953991:tid 954248] [client 103.238.106.162:60939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLKQAAAQQ"]
[Mon Jul 20 06:36:43.288548 2026] [security2:error] [pid 953991:tid 954248] [client 103.238.106.162:60939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLKQAAAQQ"]
[Mon Jul 20 06:36:43.457137 2026] [security2:error] [pid 953991:tid 954159] [client 161.118.195.148:57367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WW6_X-kAXGDrIFafLPQAAAKs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:43.470934 2026] [security2:error] [pid 953991:tid 954192] [client 35.245.239.138:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "victoryfinancialcoaching-net.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLPgAAAMw"]
[Mon Jul 20 06:36:43.471091 2026] [security2:error] [pid 953991:tid 954192] [client 35.245.239.138:57014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "victoryfinancialcoaching-net.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLPgAAAMw"]
[Mon Jul 20 06:36:43.495857 2026] [security2:error] [pid 953991:tid 954187] [client 34.74.185.202:57229] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WW6_X-kAXGDrIFafLQgAAAMc"]
[Mon Jul 20 06:36:43.565935 2026] [security2:error] [pid 953991:tid 954224] [client 34.74.185.202:56890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLSgAAAOw"]
[Mon Jul 20 06:36:43.764948 2026] [security2:error] [pid 953991:tid 954194] [client 34.73.38.214:62151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLUQAAAM4"]
[Mon Jul 20 06:36:43.853782 2026] [security2:error] [pid 953991:tid 954188] [client 34.73.38.214:56141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/xmlrpc.php"] [unique_id "al4WW6_X-kAXGDrIFafLXQAAAMg"]
[Mon Jul 20 06:36:43.907843 2026] [security2:error] [pid 953991:tid 954227] [client 14.225.17.146:52695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4WW6_X-kAXGDrIFafLOQAAAO8"], referer: http://onewingpictures.com/OLD
[Mon Jul 20 06:36:43.981912 2026] [security2:error] [pid 953991:tid 954133] [client 57.141.18.101:37850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WVq_X-kAXGDrIFafJdAAAkXc"]
[Mon Jul 20 06:36:43.989173 2026] [security2:error] [pid 953991:tid 954218] [client 34.74.185.202:56511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WW6_X-kAXGDrIFafLbAAAAOY"]
[Mon Jul 20 06:36:43.993845 2026] [security2:error] [pid 953991:tid 954143] [client 34.74.185.202:60263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WW6_X-kAXGDrIFafLbQAAAJs"]
[Mon Jul 20 06:36:44.050612 2026] [security2:error] [pid 953991:tid 954212] [client 161.118.195.148:57851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WXK_X-kAXGDrIFafLcQAAAOA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:44.215557 2026] [security2:error] [pid 953991:tid 954197] [client 152.58.191.29:56432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WXK_X-kAXGDrIFafLdgAAANE"]
[Mon Jul 20 06:36:44.478810 2026] [security2:error] [pid 953991:tid 954128] [client 34.74.185.202:53588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WXK_X-kAXGDrIFafLjQAAAIw"]
[Mon Jul 20 06:36:44.501930 2026] [security2:error] [pid 953991:tid 954214] [client 34.74.185.202:65370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WXK_X-kAXGDrIFafLkQAAAOI"]
[Mon Jul 20 06:36:44.601368 2026] [security2:error] [pid 953991:tid 954013] [remote 20.153.140.50:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4WXK_X-kAXGDrIFafLmwAAlRU"]
[Mon Jul 20 06:36:44.625120 2026] [security2:error] [pid 953991:tid 954196] [client 161.118.195.148:58329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WXK_X-kAXGDrIFafLoQAAANA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:44.860083 2026] [security2:error] [pid 953991:tid 954160] [client 34.74.185.202:63705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WXK_X-kAXGDrIFafLugAAAKw"]
[Mon Jul 20 06:36:44.920094 2026] [security2:error] [pid 953991:tid 954194] [client 112.208.70.94:45507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WXK_X-kAXGDrIFafLvwAAAM4"]
[Mon Jul 20 06:36:44.920221 2026] [security2:error] [pid 953991:tid 954194] [client 112.208.70.94:45507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WXK_X-kAXGDrIFafLvwAAAM4"]
[Mon Jul 20 06:36:44.944343 2026] [security2:error] [pid 953991:tid 954186] [client 34.74.185.202:58774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WXK_X-kAXGDrIFafLwQAAAMY"]
[Mon Jul 20 06:36:45.032682 2026] [security2:error] [pid 953991:tid 954080] [remote 20.153.140.50:58830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4WXa_X-kAXGDrIFafLxgAA8Vg"], referer: https://mrbambooplus.com/wp-login.php
[Mon Jul 20 06:36:45.088091 2026] [security2:error] [pid 953991:tid 954171] [client 34.73.38.214:59024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WXa_X-kAXGDrIFafL0AAAALc"]
[Mon Jul 20 06:36:45.196635 2026] [security2:error] [pid 953991:tid 954145] [client 161.118.195.148:58743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WXa_X-kAXGDrIFafL1gAAAJ0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:45.257173 2026] [security2:error] [pid 953991:tid 954200] [client 77.110.127.138:51005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WXa_X-kAXGDrIFafL3wAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:45.293734 2026] [security2:error] [pid 953991:tid 954038] [remote 217.113.60.80:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WXa_X-kAXGDrIFafL5AAA2y4"]
[Mon Jul 20 06:36:45.385121 2026] [security2:error] [pid 953991:tid 954167] [client 34.74.185.202:64925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WXa_X-kAXGDrIFafL7QAAALM"]
[Mon Jul 20 06:36:45.462147 2026] [security2:error] [pid 953991:tid 954226] [client 34.73.38.214:62386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WXa_X-kAXGDrIFafL9AAAAO4"]
[Mon Jul 20 06:36:45.524632 2026] [security2:error] [pid 953991:tid 954195] [client 171.60.139.123:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMAAAAAM8"]
[Mon Jul 20 06:36:45.524743 2026] [security2:error] [pid 953991:tid 954195] [client 171.60.139.123:56380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMAAAAAM8"]
[Mon Jul 20 06:36:45.543003 2026] [security2:error] [pid 953991:tid 954248] [client 14.225.17.146:52413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4WXa_X-kAXGDrIFafL6QAAAQQ"], referer: http://according2plant.com/OLD
[Mon Jul 20 06:36:45.562562 2026] [security2:error] [pid 953991:tid 954137] [client 15.237.142.234:39446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMAQAAAJU"]
[Mon Jul 20 06:36:45.562703 2026] [security2:error] [pid 953991:tid 954137] [client 15.237.142.234:39446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMAQAAAJU"]
[Mon Jul 20 06:36:45.565121 2026] [security2:error] [pid 953991:tid 954070] [remote 217.113.60.80:35572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WXa_X-kAXGDrIFafMAgAA0k4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:36:45.596694 2026] [security2:error] [pid 953991:tid 954210] [client 34.73.38.214:65010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WXa_X-kAXGDrIFafMCQAAAN4"]
[Mon Jul 20 06:36:45.603604 2026] [security2:error] [pid 953991:tid 954193] [client 197.186.66.42:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMDAAAAM0"]
[Mon Jul 20 06:36:45.614500 2026] [security2:error] [pid 953991:tid 954193] [client 197.186.66.42:56284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMDAAAAM0"]
[Mon Jul 20 06:36:45.658675 2026] [security2:error] [pid 953991:tid 954165] [client 34.74.185.202:52329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WXa_X-kAXGDrIFafMEwAAALE"]
[Mon Jul 20 06:36:45.677422 2026] [security2:error] [pid 953991:tid 954129] [client 217.142.18.172:16952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMFgAAAI0"]
[Mon Jul 20 06:36:45.684818 2026] [security2:error] [pid 953991:tid 954129] [client 217.142.18.172:16952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WXa_X-kAXGDrIFafMFgAAAI0"]
[Mon Jul 20 06:36:45.773847 2026] [security2:error] [pid 953991:tid 954123] [client 161.118.195.148:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WXa_X-kAXGDrIFafMHgAAAIc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:45.805740 2026] [security2:error] [pid 953991:tid 954204] [client 57.141.18.2:39750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WV6_X-kAXGDrIFafJ7gAA2B0"]
[Mon Jul 20 06:36:45.854429 2026] [security2:error] [pid 953991:tid 954071] [remote 68.178.160.25:58898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4WXa_X-kAXGDrIFafMIwAAy08"]
[Mon Jul 20 06:36:45.864509 2026] [security2:error] [pid 953991:tid 954209] [client 104.234.53.76:32067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WXa_X-kAXGDrIFafMKAAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:45.871698 2026] [security2:error] [pid 953991:tid 954174] [client 77.110.127.138:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXa_X-kAXGDrIFafMKQAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:45.871818 2026] [security2:error] [pid 953991:tid 954174] [client 77.110.127.138:51008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXa_X-kAXGDrIFafMKQAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:45.900191 2026] [security2:error] [pid 953991:tid 954170] [client 34.74.185.202:64827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WXa_X-kAXGDrIFafMLAAAALY"]
[Mon Jul 20 06:36:46.034200 2026] [security2:error] [pid 953991:tid 954219] [client 77.110.127.138:51012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMNQAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.034300 2026] [security2:error] [pid 953991:tid 954219] [client 77.110.127.138:51012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMNQAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.198303 2026] [security2:error] [pid 953991:tid 954223] [client 34.73.38.214:53140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMPgAAAOs"]
[Mon Jul 20 06:36:46.198776 2026] [security2:error] [pid 953991:tid 954208] [client 34.73.38.214:52168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMPwAAANw"]
[Mon Jul 20 06:36:46.248105 2026] [security2:error] [pid 953991:tid 954234] [client 34.74.185.202:51218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMSAAAAPY"]
[Mon Jul 20 06:36:46.256218 2026] [security2:error] [pid 953991:tid 954097] [remote 68.178.160.25:58898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4WXq_X-kAXGDrIFafMRQAA7Gk"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 06:36:46.265873 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMTAAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.265980 2026] [security2:error] [pid 953991:tid 954160] [client 77.110.127.138:51014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMTAAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.280912 2026] [security2:error] [pid 953991:tid 954146] [client 57.141.18.72:23080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WWK_X-kAXGDrIFafJ9gAAnhg"]
[Mon Jul 20 06:36:46.349216 2026] [security2:error] [pid 953991:tid 954184] [client 161.118.195.148:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WXq_X-kAXGDrIFafMUwAAAMQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:46.466181 2026] [security2:error] [pid 953991:tid 954193] [client 34.74.185.202:55762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMXQAAAM0"]
[Mon Jul 20 06:36:46.520698 2026] [security2:error] [pid 953991:tid 954216] [client 39.48.81.23:62361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WXq_X-kAXGDrIFafMYwAAAOQ"]
[Mon Jul 20 06:36:46.521053 2026] [security2:error] [pid 953991:tid 954216] [client 39.48.81.23:62361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WXq_X-kAXGDrIFafMYwAAAOQ"]
[Mon Jul 20 06:36:46.526043 2026] [security2:error] [pid 953991:tid 954001] [remote 182.77.62.24:34094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4WXq_X-kAXGDrIFafMYgAAnwk"]
[Mon Jul 20 06:36:46.687994 2026] [security2:error] [pid 953991:tid 954176] [client 77.110.127.138:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMeQAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.688140 2026] [security2:error] [pid 953991:tid 954176] [client 77.110.127.138:51017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMeQAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.703857 2026] [security2:error] [pid 953991:tid 954207] [client 14.225.17.146:51995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4WXq_X-kAXGDrIFafMcAAAANs"], referer: http://daseighty.net/OLD
[Mon Jul 20 06:36:46.716548 2026] [security2:error] [pid 953991:tid 954214] [client 34.73.38.214:61465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMfgAAAOI"]
[Mon Jul 20 06:36:46.717053 2026] [security2:error] [pid 953991:tid 954227] [client 34.73.38.214:61468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMgAAAAO8"]
[Mon Jul 20 06:36:46.757674 2026] [security2:error] [pid 953991:tid 954154] [client 34.74.185.202:61073] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WXq_X-kAXGDrIFafMhgAAAKY"]
[Mon Jul 20 06:36:46.942483 2026] [security2:error] [pid 953991:tid 954182] [client 161.118.195.148:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WXq_X-kAXGDrIFafMjwAAAMI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:46.948468 2026] [security2:error] [pid 953991:tid 954202] [client 77.110.127.138:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMkAAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:46.948604 2026] [security2:error] [pid 953991:tid 954202] [client 77.110.127.138:51019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WXq_X-kAXGDrIFafMkAAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:47.017222 2026] [security2:error] [pid 953991:tid 954201] [client 34.74.185.202:51826] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WX6_X-kAXGDrIFafMlQAAANU"]
[Mon Jul 20 06:36:47.194265 2026] [security2:error] [pid 953991:tid 954217] [client 77.110.127.138:51021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WX6_X-kAXGDrIFafMrgAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:47.194391 2026] [security2:error] [pid 953991:tid 954217] [client 77.110.127.138:51021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WX6_X-kAXGDrIFafMrgAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:47.205679 2026] [security2:error] [pid 953991:tid 954199] [client 34.73.38.214:61584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WX6_X-kAXGDrIFafMsAAAANM"]
[Mon Jul 20 06:36:47.207568 2026] [security2:error] [pid 953991:tid 954193] [client 34.73.38.214:61588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WX6_X-kAXGDrIFafMsQAAAM0"]
[Mon Jul 20 06:36:47.255302 2026] [security2:error] [pid 953991:tid 954202] [client 114.119.129.14:27859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/resource/sustainable-development-impacts-namas-report-unep-ris%C3%B8-centre"] [unique_id "al4WX6_X-kAXGDrIFafMuQAAANY"], referer: http://www.lowemissionsasia.org/resources?qt-resources=1
[Mon Jul 20 06:36:47.320776 2026] [security2:error] [pid 953991:tid 954187] [client 34.74.185.202:58186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WX6_X-kAXGDrIFafMvQAAAMc"]
[Mon Jul 20 06:36:47.350628 2026] [security2:error] [pid 953991:tid 954133] [client 14.225.17.146:52550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4WXa_X-kAXGDrIFafMDgAAAJE"], referer: http://maxenengineering.com/OLD
[Mon Jul 20 06:36:47.373741 2026] [security2:error] [pid 953991:tid 954116] [remote 182.77.62.24:34094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4WX6_X-kAXGDrIFafMwQAAmnw"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 06:36:47.515405 2026] [security2:error] [pid 953991:tid 954220] [client 161.118.195.148:60371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WX6_X-kAXGDrIFafMzgAAAOg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:47.653663 2026] [security2:error] [pid 953991:tid 954196] [client 34.74.185.202:54570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WX6_X-kAXGDrIFafM2QAAANA"]
[Mon Jul 20 06:36:47.712608 2026] [security2:error] [pid 953991:tid 954246] [client 15.237.142.234:11948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WX6_X-kAXGDrIFafM4AAAAQI"]
[Mon Jul 20 06:36:47.712690 2026] [security2:error] [pid 953991:tid 954246] [client 15.237.142.234:11948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WX6_X-kAXGDrIFafM4AAAAQI"]
[Mon Jul 20 06:36:47.783183 2026] [security2:error] [pid 953991:tid 954131] [client 57.141.18.30:39806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WWa_X-kAXGDrIFafKegAAjwU"]
[Mon Jul 20 06:36:47.807796 2026] [security2:error] [pid 953991:tid 954145] [client 77.110.127.138:51025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WX6_X-kAXGDrIFafM6gAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:47.807896 2026] [security2:error] [pid 953991:tid 954145] [client 77.110.127.138:51025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WX6_X-kAXGDrIFafM6gAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:48.027316 2026] [security2:error] [pid 953991:tid 954219] [client 34.73.38.214:51607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WYK_X-kAXGDrIFafNCgAAAOc"]
[Mon Jul 20 06:36:48.032117 2026] [security2:error] [pid 953991:tid 954150] [client 34.73.38.214:53635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WYK_X-kAXGDrIFafNCwAAAKI"]
[Mon Jul 20 06:36:48.090056 2026] [security2:error] [pid 953991:tid 954220] [client 161.118.195.148:60738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WYK_X-kAXGDrIFafNEAAAAOg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:48.133290 2026] [security2:error] [pid 953991:tid 954237] [client 34.74.185.202:57788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WYK_X-kAXGDrIFafNEwAAAPk"]
[Mon Jul 20 06:36:48.153016 2026] [security2:error] [pid 953991:tid 954239] [client 57.141.18.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4WX6_X-kAXGDrIFafM8AAAAPs"]
[Mon Jul 20 06:36:48.364593 2026] [security2:error] [pid 953991:tid 954205] [client 14.225.17.146:65257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4WYK_X-kAXGDrIFafNGAAAANk"], referer: https://maxenengineering.com/OLD
[Mon Jul 20 06:36:48.364718 2026] [security2:error] [pid 953991:tid 954197] [client 34.74.185.202:58791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WYK_X-kAXGDrIFafNKwAAANE"]
[Mon Jul 20 06:36:48.547743 2026] [security2:error] [pid 953991:tid 954175] [client 14.225.17.146:52519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4WX6_X-kAXGDrIFafMzQAAALs"]
[Mon Jul 20 06:36:48.596075 2026] [security2:error] [pid 953991:tid 954125] [client 45.157.112.60:28331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WYK_X-kAXGDrIFafNPAAAAIk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:36:48.666186 2026] [security2:error] [pid 953991:tid 954190] [client 161.118.195.148:61101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WYK_X-kAXGDrIFafNQAAAAMo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:48.677426 2026] [security2:error] [pid 953991:tid 954140] [client 57.141.18.42:62168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WWq_X-kAXGDrIFafKzQAAmG4"]
[Mon Jul 20 06:36:48.782659 2026] [security2:error] [pid 953991:tid 954229] [client 106.219.188.178:10185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WYK_X-kAXGDrIFafNRwAAAPE"]
[Mon Jul 20 06:36:48.782840 2026] [security2:error] [pid 953991:tid 954229] [client 106.219.188.178:10185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WYK_X-kAXGDrIFafNRwAAAPE"]
[Mon Jul 20 06:36:49.018192 2026] [security2:error] [pid 953991:tid 954193] [client 34.74.185.202:57930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundhealingsouthflorida.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WYa_X-kAXGDrIFafNagAAAM0"]
[Mon Jul 20 06:36:49.097561 2026] [security2:error] [pid 953991:tid 954126] [client 34.74.185.202:49263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WYa_X-kAXGDrIFafNcgAAAIo"]
[Mon Jul 20 06:36:49.238695 2026] [security2:error] [pid 953991:tid 954129] [client 14.225.17.146:65425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4WYa_X-kAXGDrIFafNdwAAAI0"], referer: http://walkingandtalking.net/OLD
[Mon Jul 20 06:36:49.249913 2026] [security2:error] [pid 953991:tid 954141] [client 161.118.195.148:61481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WYa_X-kAXGDrIFafNfQAAAJk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:49.254372 2026] [http2:info] [pid 966386:tid 966386] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:36:49.261902 2026] [security2:error] [pid 953991:tid 954036] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WYa_X-kAXGDrIFafNfwAA3Sw"]
[Mon Jul 20 06:36:49.262077 2026] [security2:error] [pid 953991:tid 954209] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WYa_X-kAXGDrIFafNfwAA3Sw"]
[Mon Jul 20 06:36:49.508646 2026] [security2:error] [pid 966386:tid 966570] [client 50.116.65.227:44616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Mong-Kok-Feature-Image.jpg"] [unique_id "al4WYTrLBqY1mBmWu_byOgAAAAg"]
[Mon Jul 20 06:36:49.523030 2026] [security2:error] [pid 966386:tid 966563] [client 34.74.185.202:65428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WYTrLBqY1mBmWu_byPgAAAAI"]
[Mon Jul 20 06:36:49.524244 2026] [security2:error] [pid 966386:tid 966576] [client 50.116.65.227:11488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Mong-Kok-Feature-Image.jpg"] [unique_id "al4WYTrLBqY1mBmWu_byPQAAAAw"]
[Mon Jul 20 06:36:49.630276 2026] [security2:error] [pid 953991:tid 954057] [remote 188.166.241.141:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4WYa_X-kAXGDrIFafNnQAAukE"]
[Mon Jul 20 06:36:49.648455 2026] [security2:error] [pid 953991:tid 954075] [remote 103.187.169.251:40058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4WYa_X-kAXGDrIFafNngAA9VM"]
[Mon Jul 20 06:36:49.732829 2026] [core:error] [pid 966386:tid 966593] [client 198.235.24.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:36:49.732851 2026] [core:error] [pid 966386:tid 966593] [client 198.235.24.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:36:49.780563 2026] [security2:error] [pid 953991:tid 954133] [client 34.73.38.214:63478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WYa_X-kAXGDrIFafNpQAAAJE"]
[Mon Jul 20 06:36:49.855816 2026] [security2:error] [pid 966386:tid 966587] [client 161.118.195.148:61898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WYTrLBqY1mBmWu_bySQAAABk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:49.921664 2026] [security2:error] [pid 966386:tid 966602] [client 77.110.127.138:51044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WYTrLBqY1mBmWu_byTQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:49.994053 2026] [security2:error] [pid 953991:tid 954166] [client 223.237.130.40:58426] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WYa_X-kAXGDrIFafNsQAAALI"]
[Mon Jul 20 06:36:49.994171 2026] [security2:error] [pid 953991:tid 954166] [client 223.237.130.40:58426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WYa_X-kAXGDrIFafNsQAAALI"]
[Mon Jul 20 06:36:50.015226 2026] [security2:error] [pid 953991:tid 954059] [remote 188.166.241.141:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4WYq_X-kAXGDrIFafNtQAAi0M"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:36:50.072665 2026] [security2:error] [pid 953991:tid 954049] [remote 103.187.169.251:40058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4WYq_X-kAXGDrIFafNuQAAwzk"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:36:50.112930 2026] [security2:error] [pid 966386:tid 966598] [client 14.225.17.146:52408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4WYjrLBqY1mBmWu_byUQAAACQ"], referer: https://walkingandtalking.net/OLD
[Mon Jul 20 06:36:50.222820 2026] [security2:error] [pid 966386:tid 966600] [client 187.108.85.186:60710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WYjrLBqY1mBmWu_byVgAAACY"]
[Mon Jul 20 06:36:50.223097 2026] [security2:error] [pid 966386:tid 966600] [client 187.108.85.186:60710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WYjrLBqY1mBmWu_byVgAAACY"]
[Mon Jul 20 06:36:50.264581 2026] [security2:error] [pid 953991:tid 954201] [client 14.225.17.146:55297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4WYa_X-kAXGDrIFafNkgAAANU"], referer: http://solkeetw.com/OLD
[Mon Jul 20 06:36:50.285848 2026] [security2:error] [pid 953991:tid 954129] [client 34.73.38.214:63650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WYq_X-kAXGDrIFafNwwAAAI0"]
[Mon Jul 20 06:36:50.351250 2026] [security2:error] [pid 953991:tid 954213] [client 57.141.18.64:22734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WXK_X-kAXGDrIFafLdAAA4Rc"]
[Mon Jul 20 06:36:50.432486 2026] [security2:error] [pid 953991:tid 954174] [client 161.118.195.148:62374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WYq_X-kAXGDrIFafN3AAAALo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:50.587001 2026] [security2:error] [pid 953991:tid 954231] [client 34.74.185.202:60402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WYq_X-kAXGDrIFafN4wAAAPM"]
[Mon Jul 20 06:36:50.627679 2026] [security2:error] [pid 953991:tid 954139] [client 34.73.38.214:59881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WYq_X-kAXGDrIFafN5QAAAJc"]
[Mon Jul 20 06:36:50.710720 2026] [security2:error] [pid 953991:tid 954150] [client 14.225.17.146:63428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4WYq_X-kAXGDrIFafN5AAAAKI"], referer: https://north-woods-engineering.com/OLD
[Mon Jul 20 06:36:50.869076 2026] [security2:error] [pid 966386:tid 966607] [client 104.234.53.55:39195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WYjrLBqY1mBmWu_byaAAAAC0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:50.925673 2026] [security2:error] [pid 953991:tid 954121] [client 57.141.18.88:29452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WXK_X-kAXGDrIFafLsAAAhSA"]
[Mon Jul 20 06:36:50.946440 2026] [security2:error] [pid 966386:tid 966659] [client 34.73.38.214:50389] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WYjrLBqY1mBmWu_byawAAAGA"]
[Mon Jul 20 06:36:51.022640 2026] [security2:error] [pid 953991:tid 954131] [client 161.118.195.148:62857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WY6_X-kAXGDrIFafN-gAAAI8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:51.113596 2026] [security2:error] [pid 953991:tid 954232] [client 57.141.18.44:34484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WXa_X-kAXGDrIFafL0gAA9Ds"]
[Mon Jul 20 06:36:51.143128 2026] [security2:error] [pid 966386:tid 966668] [client 34.74.185.202:65316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.soundbathmiami.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WYzrLBqY1mBmWu_bybgAAAGg"]
[Mon Jul 20 06:36:51.281562 2026] [security2:error] [pid 953991:tid 954166] [client 45.3.45.143:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WY6_X-kAXGDrIFafOAAAAALI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:51.331489 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:51051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WY6_X-kAXGDrIFafOBQAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:51.331586 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:51051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WY6_X-kAXGDrIFafOBQAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:51.601064 2026] [security2:error] [pid 953991:tid 954147] [client 161.118.195.148:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WY6_X-kAXGDrIFafOHQAAAJ8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:51.732131 2026] [security2:error] [pid 953991:tid 954197] [client 34.73.38.214:60736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WY6_X-kAXGDrIFafOJgAAANE"]
[Mon Jul 20 06:36:51.928348 2026] [security2:error] [pid 953991:tid 954168] [client 104.207.57.230:16483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WY6_X-kAXGDrIFafOMgAAALQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:36:52.053187 2026] [security2:error] [pid 953991:tid 954136] [client 57.141.18.47:61238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WXa_X-kAXGDrIFafMLQAAlD8"]
[Mon Jul 20 06:36:52.179683 2026] [security2:error] [pid 966386:tid 966571] [client 161.118.195.148:63720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WZDrLBqY1mBmWu_bygQAAAAk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:52.309205 2026] [security2:error] [pid 966386:tid 966588] [client 34.73.38.214:63855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WZDrLBqY1mBmWu_byggAAABo"]
[Mon Jul 20 06:36:52.317872 2026] [autoindex:error] [pid 953991:tid 954166] [client 147.93.171.184:61214] AH01276: Cannot serve directory /home2/fiqjjcmy/public_html/headachescarpaltunnelfibromyalgia/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:36:52.433698 2026] [security2:error] [pid 953991:tid 954169] [client 57.141.18.114:61842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WXq_X-kAXGDrIFafMTQAAtWA"]
[Mon Jul 20 06:36:52.697550 2026] [security2:error] [pid 953991:tid 954050] [remote 103.82.22.235:38324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WZK_X-kAXGDrIFafOXQAA9To"]
[Mon Jul 20 06:36:52.697723 2026] [security2:error] [pid 953991:tid 954233] [client 103.82.22.235:38324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WZK_X-kAXGDrIFafOXQAA9To"]
[Mon Jul 20 06:36:52.748415 2026] [security2:error] [pid 966386:tid 966442] [remote 57.141.18.17:31738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3656248"] [unique_id "al4WZDrLBqY1mBmWu_bylwAAQA8"]
[Mon Jul 20 06:36:52.763544 2026] [security2:error] [pid 966386:tid 966615] [client 161.118.195.148:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WZDrLBqY1mBmWu_bymQAAADU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:52.817820 2026] [security2:error] [pid 966386:tid 966645] [client 184.154.36.173:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "maa.hws.mybluehost.me"] [uri "/cgi-sys/404.html"] [unique_id "al4WZDrLBqY1mBmWu_byngAAAFM"]
[Mon Jul 20 06:36:52.820521 2026] [security2:error] [pid 966386:tid 966612] [client 184.154.36.173:54748] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "maa.hws.mybluehost.me"] [uri "/th1s_1s_a_4o4.html"] [unique_id "al4WZDrLBqY1mBmWu_bymAAAADI"]
[Mon Jul 20 06:36:53.288427 2026] [security2:error] [pid 953991:tid 954144] [client 34.73.38.214:60736] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WZa_X-kAXGDrIFafOgQAAAJw"]
[Mon Jul 20 06:36:53.346441 2026] [security2:error] [pid 966386:tid 966679] [client 161.118.195.148:64587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WZTrLBqY1mBmWu_byrQAAAHI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:53.386828 2026] [security2:error] [pid 966386:tid 966686] [client 50.116.65.227:11582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4WZTrLBqY1mBmWu_byrwAAAHk"]
[Mon Jul 20 06:36:53.539029 2026] [security2:error] [pid 953991:tid 954127] [client 65.1.132.125:58466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WZa_X-kAXGDrIFafOjgAAAIs"]
[Mon Jul 20 06:36:53.544732 2026] [security2:error] [pid 966386:tid 966661] [client 103.125.179.95:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WZTrLBqY1mBmWu_bytwAAAGI"]
[Mon Jul 20 06:36:53.544845 2026] [security2:error] [pid 966386:tid 966661] [client 103.125.179.95:62705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WZTrLBqY1mBmWu_bytwAAAGI"]
[Mon Jul 20 06:36:53.658741 2026] [security2:error] [pid 966386:tid 966683] [client 14.225.17.146:63433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4WYzrLBqY1mBmWu_bycwAAAHY"], referer: http://lifeisbetterlakeside.com/OLD
[Mon Jul 20 06:36:53.669713 2026] [security2:error] [pid 953991:tid 954242] [client 14.225.17.146:61102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4WZK_X-kAXGDrIFafOQAAAAP4"], referer: http://amalia-capital.com/OLD
[Mon Jul 20 06:36:53.859051 2026] [security2:error] [pid 966386:tid 966595] [client 77.110.127.138:51066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WZTrLBqY1mBmWu_byvgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:53.919081 2026] [security2:error] [pid 953991:tid 954160] [client 103.238.106.162:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WZa_X-kAXGDrIFafOoQAAAKw"]
[Mon Jul 20 06:36:53.919874 2026] [security2:error] [pid 953991:tid 954160] [client 103.238.106.162:60640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WZa_X-kAXGDrIFafOoQAAAKw"]
[Mon Jul 20 06:36:53.921398 2026] [security2:error] [pid 953991:tid 954196] [client 161.118.195.148:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WZa_X-kAXGDrIFafOogAAANA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:53.987324 2026] [security2:error] [pid 966386:tid 966692] [client 14.225.17.146:55954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4WZTrLBqY1mBmWu_byvQAAAH8"], referer: http://lelandumc.org/OLD
[Mon Jul 20 06:36:54.050280 2026] [security2:error] [pid 966386:tid 966579] [client 223.185.13.213:16393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WZjrLBqY1mBmWu_byxAAAABE"]
[Mon Jul 20 06:36:54.050417 2026] [security2:error] [pid 966386:tid 966579] [client 223.185.13.213:16393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WZjrLBqY1mBmWu_byxAAAABE"]
[Mon Jul 20 06:36:54.253927 2026] [security2:error] [pid 966386:tid 966641] [client 34.73.38.214:52493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WZjrLBqY1mBmWu_byzQAAAE8"]
[Mon Jul 20 06:36:54.333605 2026] [security2:error] [pid 953991:tid 953999] [remote 154.66.198.148:38950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WZq_X-kAXGDrIFafOtQAA3Qc"]
[Mon Jul 20 06:36:54.452733 2026] [security2:error] [pid 953991:tid 954242] [client 104.234.53.50:29269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WZq_X-kAXGDrIFafOvgAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:54.453068 2026] [security2:error] [pid 966386:tid 966597] [client 14.225.17.146:61134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4WZjrLBqY1mBmWu_byxgAAACM"], referer: http://mrbambooplus.com/OLD
[Mon Jul 20 06:36:54.467931 2026] [security2:error] [pid 966386:tid 966662] [client 52.109.89.119:6147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4WZjrLBqY1mBmWu_by2wAAAGM"]
[Mon Jul 20 06:36:54.495070 2026] [security2:error] [pid 966386:tid 966613] [client 14.225.17.146:61190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4WZjrLBqY1mBmWu_by0AAAADM"], referer: http://fluidtemple.org/OLD
[Mon Jul 20 06:36:54.497652 2026] [security2:error] [pid 966386:tid 966635] [client 161.118.195.148:65364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WZjrLBqY1mBmWu_by3gAAAEk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:54.603569 2026] [security2:error] [pid 966386:tid 966630] [client 43.205.139.3:20632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WZjrLBqY1mBmWu_by4wAAAEQ"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:36:54.615374 2026] [security2:error] [pid 966386:tid 966576] [client 52.109.89.119:6147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4WZjrLBqY1mBmWu_by5gAAAA4"]
[Mon Jul 20 06:36:54.619785 2026] [security2:error] [pid 966386:tid 966570] [client 52.109.52.84:32581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4WZjrLBqY1mBmWu_by5AAAAAg"]
[Mon Jul 20 06:36:54.666522 2026] [security2:error] [pid 953991:tid 954129] [client 34.73.38.214:51609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WZq_X-kAXGDrIFafOzQAAAI0"]
[Mon Jul 20 06:36:54.709130 2026] [security2:error] [pid 953991:tid 954136] [client 184.154.36.173:55920] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-includes/js/jquery/jquery-migrate.min.js"] [unique_id "al4WZq_X-kAXGDrIFafO0AAAAJQ"]
[Mon Jul 20 06:36:54.732129 2026] [security2:error] [pid 966386:tid 966593] [client 52.109.52.84:32581] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4WZjrLBqY1mBmWu_by7gAAAB8"]
[Mon Jul 20 06:36:54.876837 2026] [security2:error] [pid 966386:tid 966636] [client 34.73.38.214:62916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundhealingsouthflorida.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WZjrLBqY1mBmWu_by8wAAAEo"]
[Mon Jul 20 06:36:54.876875 2026] [security2:error] [pid 966386:tid 966618] [client 34.73.38.214:61117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WZjrLBqY1mBmWu_by8gAAADg"]
[Mon Jul 20 06:36:54.918828 2026] [security2:error] [pid 953991:tid 954091] [remote 154.66.198.148:38950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WZq_X-kAXGDrIFafO1gAA82M"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:36:55.077444 2026] [security2:error] [pid 966386:tid 966587] [client 161.118.195.148:49372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WZzrLBqY1mBmWu_bzCAAAABk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:55.384714 2026] [security2:error] [pid 966386:tid 966599] [client 184.154.36.173:56046] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WZjrLBqY1mBmWu_by-AAAACU"]
[Mon Jul 20 06:36:55.397067 2026] [security2:error] [pid 966386:tid 966610] [client 77.110.127.138:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WZzrLBqY1mBmWu_bzGAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:55.397180 2026] [security2:error] [pid 966386:tid 966610] [client 77.110.127.138:51076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WZzrLBqY1mBmWu_bzGAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:55.594229 2026] [security2:error] [pid 953991:tid 954150] [client 50.116.65.227:11608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WZ6_X-kAXGDrIFafO8QAAAKI"]
[Mon Jul 20 06:36:55.607903 2026] [security2:error] [pid 966386:tid 966585] [client 50.116.65.227:11620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WZzrLBqY1mBmWu_bzIgAAABc"]
[Mon Jul 20 06:36:55.661343 2026] [security2:error] [pid 966386:tid 966561] [client 161.118.195.148:49771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WZzrLBqY1mBmWu_bzJAAAAAE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:55.740065 2026] [security2:error] [pid 966386:tid 966692] [client 171.61.165.146:25397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WZzrLBqY1mBmWu_bzJgAAAH8"]
[Mon Jul 20 06:36:55.740295 2026] [security2:error] [pid 966386:tid 966692] [client 171.61.165.146:25397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WZzrLBqY1mBmWu_bzJgAAAH8"]
[Mon Jul 20 06:36:55.861496 2026] [security2:error] [pid 966386:tid 966649] [client 34.73.38.214:61787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.soundbathmiami.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WZzrLBqY1mBmWu_bzKQAAAFc"]
[Mon Jul 20 06:36:55.940510 2026] [security2:error] [pid 953991:tid 954209] [client 39.48.81.23:62882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WZ6_X-kAXGDrIFafPAgAAAN0"]
[Mon Jul 20 06:36:55.943059 2026] [security2:error] [pid 953991:tid 954209] [client 39.48.81.23:62882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WZ6_X-kAXGDrIFafPAgAAAN0"]
[Mon Jul 20 06:36:56.103936 2026] [security2:error] [pid 966386:tid 966651] [client 104.234.53.88:22411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4WaDrLBqY1mBmWu_bzMwAAAFk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:56.129201 2026] [security2:error] [pid 966386:tid 966616] [client 171.60.139.123:56904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WaDrLBqY1mBmWu_bzNQAAADY"]
[Mon Jul 20 06:36:56.129362 2026] [security2:error] [pid 966386:tid 966616] [client 171.60.139.123:56904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WaDrLBqY1mBmWu_bzNQAAADY"]
[Mon Jul 20 06:36:56.175131 2026] [security2:error] [pid 966386:tid 966667] [client 50.116.65.227:11642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WZzrLBqY1mBmWu_bzLwAAAGc"]
[Mon Jul 20 06:36:56.201557 2026] [security2:error] [pid 953991:tid 954177] [client 213.152.162.79:43110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4WaK_X-kAXGDrIFafPDAAAAL0"]
[Mon Jul 20 06:36:56.201664 2026] [security2:error] [pid 953991:tid 954177] [client 213.152.162.79:43110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4WaK_X-kAXGDrIFafPDAAAAL0"]
[Mon Jul 20 06:36:56.202849 2026] [security2:error] [pid 953991:tid 954123] [client 217.142.18.172:43163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WaK_X-kAXGDrIFafPDQAAAIc"]
[Mon Jul 20 06:36:56.210260 2026] [security2:error] [pid 953991:tid 954123] [client 217.142.18.172:43163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WaK_X-kAXGDrIFafPDQAAAIc"]
[Mon Jul 20 06:36:56.251027 2026] [security2:error] [pid 966386:tid 966581] [client 161.118.195.148:50157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WaDrLBqY1mBmWu_bzQQAAABM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:56.349684 2026] [security2:error] [pid 966386:tid 966659] [client 197.186.66.42:56806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WaDrLBqY1mBmWu_bzRQAAAGA"]
[Mon Jul 20 06:36:56.350222 2026] [security2:error] [pid 966386:tid 966659] [client 197.186.66.42:56806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WaDrLBqY1mBmWu_bzRQAAAGA"]
[Mon Jul 20 06:36:56.396137 2026] [security2:error] [pid 953991:tid 954230] [client 14.225.17.146:62104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4WZ6_X-kAXGDrIFafO_AAAAPI"], referer: http://bruceledewitz.com/OLD
[Mon Jul 20 06:36:56.409708 2026] [security2:error] [pid 966386:tid 966597] [client 50.116.65.227:11658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WaDrLBqY1mBmWu_bzOwAAACM"]
[Mon Jul 20 06:36:56.751475 2026] [security2:error] [pid 953991:tid 954199] [client 14.225.17.146:55098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4WZ6_X-kAXGDrIFafO7AAAANM"], referer: http://mcg.homes/OLD
[Mon Jul 20 06:36:56.825959 2026] [security2:error] [pid 966386:tid 966663] [client 161.118.195.148:50523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WaDrLBqY1mBmWu_bzYAAAAGQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:56.945428 2026] [security2:error] [pid 966386:tid 966607] [client 172.236.247.64:42170] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WaDrLBqY1mBmWu_bzZgAAAC0"]
[Mon Jul 20 06:36:56.945551 2026] [security2:error] [pid 966386:tid 966607] [client 172.236.247.64:42170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WaDrLBqY1mBmWu_bzZgAAAC0"]
[Mon Jul 20 06:36:57.037887 2026] [security2:error] [pid 953991:tid 954226] [client 104.234.53.81:60659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Waa_X-kAXGDrIFafPLQAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:36:57.183551 2026] [security2:error] [pid 953991:tid 954189] [client 57.141.18.70:48418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WY6_X-kAXGDrIFafOEAAAyUs"]
[Mon Jul 20 06:36:57.196469 2026] [security2:error] [pid 966386:tid 966561] [client 103.153.183.69:40812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..../..../..../..../..../root/.ssh/id_rsa"] [unique_id "al4WaTrLBqY1mBmWu_bzeQAAAAE"], referer: https://t.co/p6ysg8r7si
[Mon Jul 20 06:36:57.399429 2026] [security2:error] [pid 953991:tid 954122] [client 161.118.195.148:50907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Waa_X-kAXGDrIFafPPwAAAIY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:57.457803 2026] [security2:error] [pid 966386:tid 966598] [client 196.247.225.93:50303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.225.247.196.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4WaTrLBqY1mBmWu_bzhgAAACQ"], referer: https://recruitinginsight.us/2022/05/02/agent-and-manager-behaviors-survey-results/
[Mon Jul 20 06:36:57.457948 2026] [security2:error] [pid 966386:tid 966598] [client 196.247.225.93:50303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4WaTrLBqY1mBmWu_bzhgAAACQ"], referer: https://recruitinginsight.us/2022/05/02/agent-and-manager-behaviors-survey-results/
[Mon Jul 20 06:36:57.547190 2026] [security2:error] [pid 966386:tid 966630] [client 172.236.247.64:42184] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WaTrLBqY1mBmWu_bzkgAAAEQ"]
[Mon Jul 20 06:36:57.547273 2026] [security2:error] [pid 966386:tid 966630] [client 172.236.247.64:42184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WaTrLBqY1mBmWu_bzkgAAAEQ"]
[Mon Jul 20 06:36:57.972625 2026] [security2:error] [pid 953991:tid 954128] [client 161.118.195.148:51284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Waa_X-kAXGDrIFafPTQAAAIw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:58.012002 2026] [security2:error] [pid 966386:tid 966604] [client 77.110.127.138:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WajrLBqY1mBmWu_bzsAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:58.177473 2026] [security2:error] [pid 966386:tid 966629] [client 172.236.247.64:42186] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WajrLBqY1mBmWu_bzugAAAEM"]
[Mon Jul 20 06:36:58.177558 2026] [security2:error] [pid 966386:tid 966629] [client 172.236.247.64:42186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WajrLBqY1mBmWu_bzugAAAEM"]
[Mon Jul 20 06:36:58.211299 2026] [security2:error] [pid 966386:tid 966615] [client 184.154.36.173:57954] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-includes/js/wp-util.min.js"] [unique_id "al4WajrLBqY1mBmWu_bzuwAAADU"]
[Mon Jul 20 06:36:58.271303 2026] [security2:error] [pid 966386:tid 966624] [client 112.208.70.94:45996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WajrLBqY1mBmWu_bzvgAAAD4"]
[Mon Jul 20 06:36:58.271428 2026] [security2:error] [pid 966386:tid 966624] [client 112.208.70.94:45996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WajrLBqY1mBmWu_bzvgAAAD4"]
[Mon Jul 20 06:36:58.363537 2026] [security2:error] [pid 966386:tid 966679] [client 74.7.227.179:42452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WajrLBqY1mBmWu_bzvQAAcjo"], referer: https://tejasenvironmental.com/p=451621
[Mon Jul 20 06:36:58.412150 2026] [security2:error] [pid 966386:tid 966566] [client 184.154.36.173:58060] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-includes/js/dist/i18n.min.js"] [unique_id "al4WajrLBqY1mBmWu_bzxQAAAAQ"]
[Mon Jul 20 06:36:58.545092 2026] [security2:error] [pid 966386:tid 966564] [client 161.118.195.148:51712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WajrLBqY1mBmWu_bzyAAAAAM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:58.552777 2026] [security2:error] [pid 953991:tid 954188] [client 57.141.18.124:61502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WZK_X-kAXGDrIFafOYQAAyDw"]
[Mon Jul 20 06:36:58.619994 2026] [security2:error] [pid 966386:tid 966627] [client 184.154.36.173:58204] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-includes/js/clipboard.min.js"] [unique_id "al4WajrLBqY1mBmWu_bzzAAAAEE"]
[Mon Jul 20 06:36:58.725809 2026] [security2:error] [pid 966386:tid 966617] [client 77.110.127.138:51111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WajrLBqY1mBmWu_bz1wAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:58.725939 2026] [security2:error] [pid 966386:tid 966617] [client 77.110.127.138:51111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WajrLBqY1mBmWu_bz1wAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:36:58.797994 2026] [security2:error] [pid 966386:tid 966642] [client 172.236.247.64:42200] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WajrLBqY1mBmWu_bz3wAAAFA"]
[Mon Jul 20 06:36:58.798142 2026] [security2:error] [pid 966386:tid 966642] [client 172.236.247.64:42200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WajrLBqY1mBmWu_bz3wAAAFA"]
[Mon Jul 20 06:36:58.814881 2026] [security2:error] [pid 953991:tid 954162] [client 14.225.17.146:61436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4Waq_X-kAXGDrIFafPdgAAAK4"], referer: http://grndl.com/OLD
[Mon Jul 20 06:36:58.823404 2026] [security2:error] [pid 966386:tid 966583] [client 184.154.36.173:58296] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-admin/css/forms.min.css"] [unique_id "al4WajrLBqY1mBmWu_bz4QAAABU"]
[Mon Jul 20 06:36:58.915407 2026] [security2:error] [pid 966386:tid 966618] [client 63.179.149.246:18728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WajrLBqY1mBmWu_bz6wAAADg"]
[Mon Jul 20 06:36:58.915566 2026] [security2:error] [pid 966386:tid 966618] [client 63.179.149.246:18728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WajrLBqY1mBmWu_bz6wAAADg"]
[Mon Jul 20 06:36:59.120181 2026] [security2:error] [pid 966386:tid 966692] [client 161.118.195.148:52088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WazrLBqY1mBmWu_bz9AAAAH8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:59.290007 2026] [security2:error] [pid 953991:tid 954222] [client 184.154.36.173:58538] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-admin/js/user-profile.min.js"] [unique_id "al4Wa6_X-kAXGDrIFafPiwAAAOo"]
[Mon Jul 20 06:36:59.386660 2026] [security2:error] [pid 966386:tid 966612] [client 14.225.17.146:52072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4WazrLBqY1mBmWu_bz9wAAADI"], referer: http://entuvy.com/OLD
[Mon Jul 20 06:36:59.395151 2026] [security2:error] [pid 966386:tid 966594] [client 172.236.247.64:42210] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WazrLBqY1mBmWu_bz-AAAACA"]
[Mon Jul 20 06:36:59.395242 2026] [security2:error] [pid 966386:tid 966594] [client 172.236.247.64:42210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WazrLBqY1mBmWu_bz-AAAACA"]
[Mon Jul 20 06:36:59.429317 2026] [security2:error] [pid 966386:tid 966570] [client 106.219.188.178:15831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WazrLBqY1mBmWu_bz-gAAAAg"]
[Mon Jul 20 06:36:59.429417 2026] [security2:error] [pid 966386:tid 966570] [client 106.219.188.178:15831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WazrLBqY1mBmWu_bz-gAAAAg"]
[Mon Jul 20 06:36:59.505088 2026] [security2:error] [pid 953991:tid 954187] [client 196.247.225.93:41602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4Wa6_X-kAXGDrIFafPlgAAAMc"], referer: https://recruitinginsight.us/2022/05/02/agent-and-manager-behaviors-survey-results/
[Mon Jul 20 06:36:59.505125 2026] [security2:error] [pid 953991:tid 954187] [client 196.247.225.93:41602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4Wa6_X-kAXGDrIFafPlgAAAMc"], referer: https://recruitinginsight.us/2022/05/02/agent-and-manager-behaviors-survey-results/
[Mon Jul 20 06:36:59.690854 2026] [security2:error] [pid 953991:tid 954170] [client 45.61.188.240:63128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "petpawo.com"] [uri "/"] [unique_id "al4Wa6_X-kAXGDrIFafPpAAAALY"]
[Mon Jul 20 06:36:59.695406 2026] [security2:error] [pid 966386:tid 966609] [client 161.118.195.148:52445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WazrLBqY1mBmWu_b0DAAAAC8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:36:59.745642 2026] [security2:error] [pid 953991:tid 954165] [client 184.154.36.173:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/readme.html"] [unique_id "al4Wa6_X-kAXGDrIFafPqQAAALE"]
[Mon Jul 20 06:36:59.748319 2026] [security2:error] [pid 953991:tid 954135] [client 184.154.36.173:58910] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/readme.html"] [unique_id "al4Wa6_X-kAXGDrIFafPpgAAAJM"]
[Mon Jul 20 06:36:59.956902 2026] [security2:error] [pid 953991:tid 954162] [client 45.61.188.240:63185] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "petpawo.com"] [uri "/"] [unique_id "al4Wa6_X-kAXGDrIFafPswAAAK4"]
[Mon Jul 20 06:36:59.971866 2026] [security2:error] [pid 966386:tid 966583] [client 184.154.36.173:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-content/plugins/creative-mail-by-constant-contact/readme.txt"] [unique_id "al4WazrLBqY1mBmWu_b0FAAAABU"]
[Mon Jul 20 06:36:59.973799 2026] [security2:error] [pid 966386:tid 966502] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WazrLBqY1mBmWu_b0FgAAFkg"]
[Mon Jul 20 06:36:59.973977 2026] [security2:error] [pid 966386:tid 966584] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WazrLBqY1mBmWu_b0FgAAFkg"]
[Mon Jul 20 06:36:59.975966 2026] [security2:error] [pid 966386:tid 966568] [client 184.154.36.173:59038] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-content/plugins/creative-mail-by-constant-contact/readme.txt"] [unique_id "al4WazrLBqY1mBmWu_b0EgAAAAY"]
[Mon Jul 20 06:37:00.002309 2026] [security2:error] [pid 966386:tid 966563] [client 172.236.247.64:42214] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbDrLBqY1mBmWu_b0GAAAAAI"]
[Mon Jul 20 06:37:00.002419 2026] [security2:error] [pid 966386:tid 966563] [client 172.236.247.64:42214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbDrLBqY1mBmWu_b0GAAAAAI"]
[Mon Jul 20 06:37:00.218807 2026] [security2:error] [pid 953991:tid 954008] [remote 91.142.222.105:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WbK_X-kAXGDrIFafPvAAAyBA"]
[Mon Jul 20 06:37:00.258009 2026] [security2:error] [pid 966386:tid 966619] [client 57.141.18.96:20712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WZjrLBqY1mBmWu_by2AAAORc"]
[Mon Jul 20 06:37:00.270688 2026] [security2:error] [pid 966386:tid 966687] [client 161.118.195.148:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WbDrLBqY1mBmWu_b0JwAAAHo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:00.605911 2026] [security2:error] [pid 953991:tid 954129] [client 172.236.247.64:42224] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbK_X-kAXGDrIFafPywAAAI0"]
[Mon Jul 20 06:37:00.606007 2026] [security2:error] [pid 953991:tid 954129] [client 172.236.247.64:42224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbK_X-kAXGDrIFafPywAAAI0"]
[Mon Jul 20 06:37:00.649332 2026] [security2:error] [pid 953991:tid 954239] [client 77.110.127.138:51125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WbK_X-kAXGDrIFafPzAAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:00.851299 2026] [security2:error] [pid 953991:tid 954147] [client 223.237.130.40:58852] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WbK_X-kAXGDrIFafP1gAAAJ8"]
[Mon Jul 20 06:37:00.851422 2026] [security2:error] [pid 953991:tid 954147] [client 223.237.130.40:58852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WbK_X-kAXGDrIFafP1gAAAJ8"]
[Mon Jul 20 06:37:00.858455 2026] [security2:error] [pid 953991:tid 954191] [client 161.118.195.148:53323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WbK_X-kAXGDrIFafP1wAAAMs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:00.863994 2026] [security2:error] [pid 966386:tid 966588] [client 187.108.85.186:61239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WbDrLBqY1mBmWu_b0PAAAABo"]
[Mon Jul 20 06:37:00.864608 2026] [security2:error] [pid 966386:tid 966588] [client 187.108.85.186:61239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WbDrLBqY1mBmWu_b0PAAAABo"]
[Mon Jul 20 06:37:01.012425 2026] [security2:error] [pid 966386:tid 966614] [client 14.225.17.146:52134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4WazrLBqY1mBmWu_b0AwAAADQ"], referer: http://709fx.com/OLD
[Mon Jul 20 06:37:01.230602 2026] [security2:error] [pid 966386:tid 966606] [client 172.236.247.64:42234] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbTrLBqY1mBmWu_b0TAAAACw"]
[Mon Jul 20 06:37:01.230712 2026] [security2:error] [pid 966386:tid 966606] [client 172.236.247.64:42234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbTrLBqY1mBmWu_b0TAAAACw"]
[Mon Jul 20 06:37:01.361007 2026] [security2:error] [pid 966386:tid 966512] [remote 142.93.10.93:52738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4WbTrLBqY1mBmWu_b0VAAAJFI"]
[Mon Jul 20 06:37:01.361227 2026] [security2:error] [pid 966386:tid 966598] [client 142.93.10.93:52738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4WbTrLBqY1mBmWu_b0VAAAJFI"]
[Mon Jul 20 06:37:01.438728 2026] [security2:error] [pid 966386:tid 966625] [client 161.118.195.148:53716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WbTrLBqY1mBmWu_b0WAAAAD8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:01.442434 2026] [security2:error] [pid 953991:tid 954046] [remote 91.142.222.105:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Wba_X-kAXGDrIFafP6wAAijY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:37:01.546372 2026] [security2:error] [pid 966386:tid 966633] [client 14.225.17.146:63367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4WbDrLBqY1mBmWu_b0IAAAAEc"], referer: http://carolinapressurewashers.com/OLD
[Mon Jul 20 06:37:01.859452 2026] [security2:error] [pid 966386:tid 966572] [client 172.236.247.64:48518] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 64.247.236.172.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbTrLBqY1mBmWu_b0bwAAAAo"]
[Mon Jul 20 06:37:01.859536 2026] [security2:error] [pid 966386:tid 966572] [client 172.236.247.64:48518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "jndsupport.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbTrLBqY1mBmWu_b0bwAAAAo"]
[Mon Jul 20 06:37:01.940191 2026] [security2:error] [pid 966386:tid 966584] [client 77.110.127.138:51096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbTrLBqY1mBmWu_b0cgAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:01.940319 2026] [security2:error] [pid 966386:tid 966584] [client 77.110.127.138:51096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WbTrLBqY1mBmWu_b0cgAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:02.016446 2026] [security2:error] [pid 966386:tid 966664] [client 161.118.195.148:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WbjrLBqY1mBmWu_b0dwAAAGU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:02.028163 2026] [security2:error] [pid 966386:tid 966626] [client 14.225.17.146:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WbTrLBqY1mBmWu_b0bgAAAEA"], referer: http://fkconstructionfunding.com/OLD
[Mon Jul 20 06:37:02.036366 2026] [security2:error] [pid 966386:tid 966628] [client 104.234.53.55:56507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WbjrLBqY1mBmWu_b0eAAAAEI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:02.055991 2026] [security2:error] [pid 953991:tid 954121] [client 157.66.56.117:57247] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4Wbq_X-kAXGDrIFafP_wAAAIU"]
[Mon Jul 20 06:37:02.056137 2026] [security2:error] [pid 953991:tid 954121] [client 157.66.56.117:57247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4Wbq_X-kAXGDrIFafP_wAAAIU"]
[Mon Jul 20 06:37:02.175792 2026] [security2:error] [pid 966386:tid 966636] [client 14.225.17.146:62189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4WbTrLBqY1mBmWu_b0dAAAAEo"], referer: http://windowtx.com/OLD
[Mon Jul 20 06:37:02.333907 2026] [security2:error] [pid 966386:tid 966681] [client 57.141.18.115:61680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WaDrLBqY1mBmWu_bzPgAAdCU"]
[Mon Jul 20 06:37:02.491144 2026] [security2:error] [pid 966386:tid 966684] [client 77.110.127.138:51101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WbjrLBqY1mBmWu_b0kAAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:02.587378 2026] [security2:error] [pid 966386:tid 966653] [client 65.111.28.52:25161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WbjrLBqY1mBmWu_b0lgAAAFs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:37:02.590221 2026] [security2:error] [pid 966386:tid 966650] [client 161.118.195.148:54469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WbjrLBqY1mBmWu_b0mQAAAFg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:02.641741 2026] [security2:error] [pid 966386:tid 966522] [remote 192.241.143.148:44304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WbjrLBqY1mBmWu_b0mwAARlw"]
[Mon Jul 20 06:37:02.822894 2026] [security2:error] [pid 966386:tid 966523] [remote 192.241.143.148:44304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WbjrLBqY1mBmWu_b0ngAAYl0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:37:03.077420 2026] [proxy:error] [pid 966386:tid 966593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:03.077529 2026] [proxy_http:error] [pid 966386:tid 966593] [client 34.73.38.214:55746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:03.078288 2026] [proxy:error] [pid 966386:tid 966593] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:03.078316 2026] [proxy_http:error] [pid 966386:tid 966593] [client 34.73.38.214:55746] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:03.094397 2026] [security2:error] [pid 966386:tid 966656] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4WbjrLBqY1mBmWu_b0nwAAAF4"]
[Mon Jul 20 06:37:03.164472 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:54825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wb6_X-kAXGDrIFafQLAAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:03.712929 2026] [security2:error] [pid 966386:tid 966674] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.phillipbloch.com"] [uri "/index.php"] [unique_id "al4WbzrLBqY1mBmWu_b0xQAAAG0"]
[Mon Jul 20 06:37:03.740790 2026] [security2:error] [pid 966386:tid 966629] [client 161.118.195.148:55223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WbzrLBqY1mBmWu_b01AAAAEM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:03.978267 2026] [security2:error] [pid 953991:tid 954052] [remote 154.66.198.148:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4Wb6_X-kAXGDrIFafQUgAAujw"]
[Mon Jul 20 06:37:04.047461 2026] [security2:error] [pid 966386:tid 966534] [remote 152.228.213.32:45422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WcDrLBqY1mBmWu_b05AAAOGg"]
[Mon Jul 20 06:37:04.239012 2026] [security2:error] [pid 966386:tid 966537] [remote 152.228.213.32:45422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WcDrLBqY1mBmWu_b07wAAJWs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:37:04.321898 2026] [security2:error] [pid 966386:tid 966685] [client 161.118.195.148:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WcDrLBqY1mBmWu_b08gAAAHg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:04.326757 2026] [security2:error] [pid 966386:tid 966686] [client 103.125.179.95:63202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WcDrLBqY1mBmWu_b08wAAAHk"]
[Mon Jul 20 06:37:04.327617 2026] [security2:error] [pid 966386:tid 966686] [client 103.125.179.95:63202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WcDrLBqY1mBmWu_b08wAAAHk"]
[Mon Jul 20 06:37:04.333627 2026] [proxy:error] [pid 953991:tid 954186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:04.333699 2026] [proxy_http:error] [pid 953991:tid 954186] [client 34.73.38.214:64332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:04.334344 2026] [proxy:error] [pid 953991:tid 954186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:04.334370 2026] [proxy_http:error] [pid 953991:tid 954186] [client 34.73.38.214:64332] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:04.453635 2026] [security2:error] [pid 953991:tid 954241] [client 103.238.106.162:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WcK_X-kAXGDrIFafQagAAAP0"]
[Mon Jul 20 06:37:04.453743 2026] [security2:error] [pid 953991:tid 954241] [client 103.238.106.162:60959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WcK_X-kAXGDrIFafQagAAAP0"]
[Mon Jul 20 06:37:04.527951 2026] [security2:error] [pid 953991:tid 954072] [remote 154.66.198.148:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4WcK_X-kAXGDrIFafQbQAAvlA"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:37:04.603883 2026] [security2:error] [pid 953991:tid 954042] [remote 188.166.241.141:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WcK_X-kAXGDrIFafQcQAA0TI"]
[Mon Jul 20 06:37:04.619868 2026] [security2:error] [pid 966386:tid 966561] [client 57.141.18.123:30246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WajrLBqY1mBmWu_bz4wAAAUA"]
[Mon Jul 20 06:37:04.895529 2026] [security2:error] [pid 966386:tid 966580] [client 161.118.195.148:56034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WcDrLBqY1mBmWu_b1DwAAABI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:04.902368 2026] [security2:error] [pid 966386:tid 966586] [client 77.110.127.138:51124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WcDrLBqY1mBmWu_b1EQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:04.902452 2026] [security2:error] [pid 966386:tid 966586] [client 77.110.127.138:51124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WcDrLBqY1mBmWu_b1EQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:04.989496 2026] [security2:error] [pid 953991:tid 954070] [remote 188.166.241.141:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WcK_X-kAXGDrIFafQgAAA704"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:37:05.140911 2026] [security2:error] [pid 966386:tid 966685] [client 77.110.127.138:51129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WcTrLBqY1mBmWu_b1GgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:05.482022 2026] [security2:error] [pid 953991:tid 954230] [client 161.118.195.148:56416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wca_X-kAXGDrIFafQlAAAAPI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:05.559965 2026] [proxy:error] [pid 953991:tid 954141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:05.560043 2026] [proxy_http:error] [pid 953991:tid 954141] [client 34.73.38.214:59049] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:05.560687 2026] [proxy:error] [pid 953991:tid 954141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:05.560716 2026] [proxy_http:error] [pid 953991:tid 954141] [client 34.73.38.214:59049] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:05.602660 2026] [security2:error] [pid 966386:tid 966630] [client 223.185.13.213:25530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WcTrLBqY1mBmWu_b1LwAAAEQ"]
[Mon Jul 20 06:37:05.602761 2026] [security2:error] [pid 966386:tid 966630] [client 223.185.13.213:25530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WcTrLBqY1mBmWu_b1LwAAAEQ"]
[Mon Jul 20 06:37:05.623976 2026] [security2:error] [pid 966386:tid 966683] [client 14.225.17.146:50984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4WcTrLBqY1mBmWu_b1KQAAAHY"], referer: http://eframiproperties.com/OLD
[Mon Jul 20 06:37:05.637709 2026] [security2:error] [pid 966386:tid 966650] [client 216.73.217.138:8149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WcTrLBqY1mBmWu_b1LAAAWHU"]
[Mon Jul 20 06:37:05.743960 2026] [security2:error] [pid 966386:tid 966636] [client 216.73.217.138:8149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WcTrLBqY1mBmWu_b1MQAASnY"]
[Mon Jul 20 06:37:06.059266 2026] [security2:error] [pid 966386:tid 966662] [client 161.118.195.148:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WcjrLBqY1mBmWu_b1RQAAAGM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:06.151063 2026] [security2:error] [pid 953991:tid 954147] [client 39.48.81.23:63410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wcq_X-kAXGDrIFafQuAAAAJ8"]
[Mon Jul 20 06:37:06.151170 2026] [security2:error] [pid 953991:tid 954147] [client 39.48.81.23:63410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wcq_X-kAXGDrIFafQuAAAAJ8"]
[Mon Jul 20 06:37:06.152867 2026] [security2:error] [pid 953991:tid 954204] [client 14.225.17.146:51070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4WcK_X-kAXGDrIFafQZwAAANg"]
[Mon Jul 20 06:37:06.261685 2026] [security2:error] [pid 953991:tid 954128] [client 57.141.18.29:39646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WbK_X-kAXGDrIFafPxAAAjBk"]
[Mon Jul 20 06:37:06.372269 2026] [security2:error] [pid 966386:tid 966642] [client 14.225.17.146:51899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4WcjrLBqY1mBmWu_b1UAAAAFA"], referer: http://headachescarpaltunnelfibromyalgia.com/OLD
[Mon Jul 20 06:37:06.444464 2026] [security2:error] [pid 953991:tid 954138] [client 50.116.65.227:18782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Wcq_X-kAXGDrIFafQwgAAAJY"]
[Mon Jul 20 06:37:06.453310 2026] [security2:error] [pid 953991:tid 954167] [client 50.116.65.227:18784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Wcq_X-kAXGDrIFafQxAAAALM"]
[Mon Jul 20 06:37:06.594202 2026] [security2:error] [pid 966386:tid 966600] [client 14.225.17.146:51685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4WcTrLBqY1mBmWu_b1HQAAACY"], referer: http://sarahsnyder.net/OLD
[Mon Jul 20 06:37:06.634598 2026] [security2:error] [pid 966386:tid 966661] [client 161.118.195.148:57130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WcjrLBqY1mBmWu_b1YQAAAGI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:06.692645 2026] [security2:error] [pid 966386:tid 966620] [client 217.142.18.172:43560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1YwAAADo"]
[Mon Jul 20 06:37:06.696981 2026] [security2:error] [pid 966386:tid 966620] [client 217.142.18.172:43560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1YwAAADo"]
[Mon Jul 20 06:37:06.716495 2026] [security2:error] [pid 966386:tid 966623] [client 98.159.234.160:29037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WcjrLBqY1mBmWu_b1ZAAAAD0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:37:06.893993 2026] [security2:error] [pid 966386:tid 966619] [client 57.141.18.68:50586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WbTrLBqY1mBmWu_b0UQAAOVE"]
[Mon Jul 20 06:37:06.924280 2026] [security2:error] [pid 966386:tid 966656] [client 34.73.38.214:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.supportinghands22.org"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1cQAAAF4"]
[Mon Jul 20 06:37:06.946381 2026] [security2:error] [pid 966386:tid 966560] [client 171.60.139.123:57434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1cgAAAAA"]
[Mon Jul 20 06:37:06.946510 2026] [security2:error] [pid 966386:tid 966560] [client 171.60.139.123:57434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1cgAAAAA"]
[Mon Jul 20 06:37:06.965199 2026] [security2:error] [pid 966386:tid 966683] [client 197.186.66.42:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1cwAAAHY"]
[Mon Jul 20 06:37:06.965325 2026] [security2:error] [pid 966386:tid 966683] [client 197.186.66.42:57324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WcjrLBqY1mBmWu_b1cwAAAHY"]
[Mon Jul 20 06:37:07.142351 2026] [security2:error] [pid 953991:tid 954196] [client 158.173.166.181:60001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Wc6_X-kAXGDrIFafQ4wAAANA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:37:07.216957 2026] [security2:error] [pid 966386:tid 966671] [client 161.118.195.148:57478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WczrLBqY1mBmWu_b1fQAAAGo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:07.237429 2026] [security2:error] [pid 966386:tid 966635] [client 14.225.17.146:50695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4WcjrLBqY1mBmWu_b1aAAAAEk"], referer: http://mollycahill.com/OLD
[Mon Jul 20 06:37:07.573004 2026] [security2:error] [pid 966386:tid 966435] [remote 78.46.157.202:60400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WczrLBqY1mBmWu_b1kwAAVAg"]
[Mon Jul 20 06:37:07.573208 2026] [security2:error] [pid 966386:tid 966646] [client 78.46.157.202:60400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WczrLBqY1mBmWu_b1kwAAVAg"]
[Mon Jul 20 06:37:07.581483 2026] [security2:error] [pid 966386:tid 966573] [client 14.225.17.146:50610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4WczrLBqY1mBmWu_b1jAAAAAs"], referer: https://sarahsnyder.net/OLD
[Mon Jul 20 06:37:07.601578 2026] [security2:error] [pid 953991:tid 954213] [client 77.110.127.138:51149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wc6_X-kAXGDrIFafQ8wAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:07.601679 2026] [security2:error] [pid 953991:tid 954213] [client 77.110.127.138:51149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wc6_X-kAXGDrIFafQ8wAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:07.699440 2026] [security2:error] [pid 953991:tid 954211] [client 103.78.254.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thelastgamestandingexp.com"] [uri "/index.php"] [unique_id "al4Wcq_X-kAXGDrIFafQuwAAAN8"]
[Mon Jul 20 06:37:07.796146 2026] [security2:error] [pid 966386:tid 966641] [client 161.118.195.148:57856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WczrLBqY1mBmWu_b1pAAAAE8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:07.941711 2026] [security2:error] [pid 966386:tid 966692] [client 77.110.127.138:51155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WczrLBqY1mBmWu_b1sQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:08.249642 2026] [security2:error] [pid 966386:tid 966617] [client 57.141.18.47:59540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WbjrLBqY1mBmWu_b0mAAAN1o"]
[Mon Jul 20 06:37:08.384568 2026] [security2:error] [pid 966386:tid 966573] [client 161.118.195.148:58250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WdDrLBqY1mBmWu_b1zQAAAAs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:08.475436 2026] [security2:error] [pid 966386:tid 966577] [client 104.234.53.57:44665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WdDrLBqY1mBmWu_b10AAAAA8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:08.509693 2026] [security2:error] [pid 953991:tid 954130] [client 57.141.18.105:36624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wbq_X-kAXGDrIFafQHwAAjk8"]
[Mon Jul 20 06:37:08.845514 2026] [security2:error] [pid 953991:tid 954241] [client 34.73.38.214:55274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WdK_X-kAXGDrIFafRHgAAAP0"]
[Mon Jul 20 06:37:08.956299 2026] [security2:error] [pid 966386:tid 966671] [client 161.118.195.148:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WdDrLBqY1mBmWu_b12QAAAGo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:09.054437 2026] [ssl:error] [pid 966386:tid 966635] [client 109.53.56.127:60841] AH02032: Hostname www.pfl.ail.mybluehost.me provided via SNI and hostname www.forbes.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:37:09.240773 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WdTrLBqY1mBmWu_b13gAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:09.240929 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:51158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WdTrLBqY1mBmWu_b13gAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:09.445096 2026] [security2:error] [pid 966386:tid 966682] [client 57.141.18.15:47674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WcDrLBqY1mBmWu_b04wAAdWc"]
[Mon Jul 20 06:37:09.450285 2026] [security2:error] [pid 966386:tid 966655] [client 34.73.38.214:62039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WdTrLBqY1mBmWu_b15gAAAF0"]
[Mon Jul 20 06:37:09.533319 2026] [security2:error] [pid 953991:tid 954245] [client 161.118.195.148:58964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wda_X-kAXGDrIFafRQwAAAQE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:09.699357 2026] [security2:error] [pid 966386:tid 966604] [client 54.94.85.83:63145] ModSecurity: Warning. Matched phrase "Collector" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "suretybonds-california.com"] [uri "/wp-content/uploads/top-10-reasons-contractors-succeed_slides.pdf"] [unique_id "al4WdDrLBqY1mBmWu_b11QAAACo"]
[Mon Jul 20 06:37:09.924321 2026] [security2:error] [pid 953991:tid 954210] [client 105.168.67.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4Wda_X-kAXGDrIFafRSAAAAN4"]
[Mon Jul 20 06:37:09.967709 2026] [security2:error] [pid 966386:tid 966561] [client 106.219.188.178:10183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WdTrLBqY1mBmWu_b2AgAAAAE"]
[Mon Jul 20 06:37:09.968022 2026] [security2:error] [pid 966386:tid 966561] [client 106.219.188.178:10183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WdTrLBqY1mBmWu_b2AgAAAAE"]
[Mon Jul 20 06:37:10.010885 2026] [security2:error] [pid 966386:tid 966619] [client 13.201.64.214:44034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WdjrLBqY1mBmWu_b2BwAAADk"]
[Mon Jul 20 06:37:10.047113 2026] [security2:error] [pid 966386:tid 966589] [client 54.244.177.189:22840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4WdjrLBqY1mBmWu_b2CQAAABs"]
[Mon Jul 20 06:37:10.120285 2026] [security2:error] [pid 966386:tid 966686] [client 161.118.195.148:59333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WdjrLBqY1mBmWu_b2DQAAAHk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:10.159549 2026] [security2:error] [pid 966386:tid 966638] [client 77.110.127.138:51190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WdjrLBqY1mBmWu_b2EAAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:10.340628 2026] [security2:error] [pid 966386:tid 966587] [client 34.73.38.214:54076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WdjrLBqY1mBmWu_b2HwAAABk"]
[Mon Jul 20 06:37:10.360513 2026] [security2:error] [pid 953991:tid 954171] [client 77.110.127.138:51196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Wdq_X-kAXGDrIFafRaQAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:10.399351 2026] [security2:error] [pid 966386:tid 966621] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/admin/phpinfo.php"] [unique_id "al4WdjrLBqY1mBmWu_b2IAAAADs"]
[Mon Jul 20 06:37:10.466299 2026] [security2:error] [pid 953991:tid 954237] [client 77.110.127.138:51139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Wdq_X-kAXGDrIFafRbAAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:10.557564 2026] [security2:error] [pid 966386:tid 966598] [client 14.225.17.146:51636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4WdjrLBqY1mBmWu_b2IQAAACQ"], referer: http://idigress.group/OLD
[Mon Jul 20 06:37:10.572370 2026] [security2:error] [pid 953991:tid 954165] [client 45.3.54.43:63741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Wdq_X-kAXGDrIFafRbwAAALE"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:10.631067 2026] [security2:error] [pid 966386:tid 966575] [client 77.110.127.138:51201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WdjrLBqY1mBmWu_b2NQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:10.696029 2026] [security2:error] [pid 966386:tid 966639] [client 161.118.195.148:59694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WdjrLBqY1mBmWu_b2OgAAAE0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:10.702481 2026] [security2:error] [pid 966386:tid 966647] [client 57.141.18.104:25090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WcTrLBqY1mBmWu_b1JgAAVXQ"]
[Mon Jul 20 06:37:10.760999 2026] [security2:error] [pid 953991:tid 954115] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Wdq_X-kAXGDrIFafRdgAAkHs"]
[Mon Jul 20 06:37:10.761219 2026] [security2:error] [pid 953991:tid 954132] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Wdq_X-kAXGDrIFafRdgAAkHs"]
[Mon Jul 20 06:37:11.216696 2026] [security2:error] [pid 953991:tid 954234] [client 77.110.127.138:51173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Wd6_X-kAXGDrIFafRhgAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:11.267254 2026] [security2:error] [pid 966386:tid 966688] [client 77.110.127.138:51085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WdzrLBqY1mBmWu_b2VAAAAHs"]
[Mon Jul 20 06:37:11.269831 2026] [security2:error] [pid 953991:tid 954209] [client 112.208.70.94:42402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Wd6_X-kAXGDrIFafRjAAAAN0"]
[Mon Jul 20 06:37:11.269928 2026] [security2:error] [pid 953991:tid 954209] [client 112.208.70.94:42402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Wd6_X-kAXGDrIFafRjAAAAN0"]
[Mon Jul 20 06:37:11.276324 2026] [security2:error] [pid 966386:tid 966652] [client 161.118.195.148:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WdzrLBqY1mBmWu_b2VQAAAFo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:11.311150 2026] [security2:error] [pid 953991:tid 954208] [client 14.225.17.146:62831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4Wdq_X-kAXGDrIFafRaAAAANw"], referer: http://ancestralidadytrance.space/OLD
[Mon Jul 20 06:37:11.422575 2026] [security2:error] [pid 966386:tid 966566] [client 77.110.127.138:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4WdzrLBqY1mBmWu_b2WQAAAAQ"]
[Mon Jul 20 06:37:11.476247 2026] [security2:error] [pid 953991:tid 954201] [client 57.141.18.59:40072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wcq_X-kAXGDrIFafQvQAA1WE"]
[Mon Jul 20 06:37:11.544286 2026] [security2:error] [pid 966386:tid 966576] [client 14.225.17.146:62645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4WdjrLBqY1mBmWu_b2QQAAAA4"], referer: http://oldracelimited.com/OLD
[Mon Jul 20 06:37:11.580402 2026] [security2:error] [pid 966386:tid 966601] [client 187.108.85.186:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WdzrLBqY1mBmWu_b2YgAAACc"]
[Mon Jul 20 06:37:11.580507 2026] [security2:error] [pid 966386:tid 966601] [client 187.108.85.186:61763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WdzrLBqY1mBmWu_b2YgAAACc"]
[Mon Jul 20 06:37:11.605647 2026] [security2:error] [pid 966386:tid 966464] [remote 57.141.18.56:61326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4529487"] [unique_id "al4WdzrLBqY1mBmWu_b2ZAAAEyQ"]
[Mon Jul 20 06:37:11.683892 2026] [security2:error] [pid 966386:tid 966674] [client 223.237.130.40:59276] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WdzrLBqY1mBmWu_b2bwAAAG0"]
[Mon Jul 20 06:37:11.684008 2026] [security2:error] [pid 966386:tid 966674] [client 223.237.130.40:59276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WdzrLBqY1mBmWu_b2bwAAAG0"]
[Mon Jul 20 06:37:11.700119 2026] [security2:error] [pid 953991:tid 954220] [client 14.225.17.146:52010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4Wda_X-kAXGDrIFafRXwAAAOg"], referer: http://nomorewetsheets.net/OLD
[Mon Jul 20 06:37:11.731736 2026] [security2:error] [pid 966386:tid 966560] [client 34.73.38.214:49632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WdzrLBqY1mBmWu_b2dQAAAAA"]
[Mon Jul 20 06:37:11.851440 2026] [security2:error] [pid 966386:tid 966616] [client 161.118.195.148:60397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WdzrLBqY1mBmWu_b2fAAAADY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:11.895662 2026] [security2:error] [pid 966386:tid 966561] [client 14.225.17.146:62742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4WdjrLBqY1mBmWu_b2PwAAAAE"], referer: http://intelligentengineeringsolutions.com/OLD
[Mon Jul 20 06:37:11.941954 2026] [security2:error] [pid 953991:tid 954148] [client 13.233.207.33:11594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Wd6_X-kAXGDrIFafRgwAAAKA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:37:12.170681 2026] [security2:error] [pid 966386:tid 966677] [client 14.225.17.146:51116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4WdTrLBqY1mBmWu_b19AAAAHA"], referer: http://talknutritionwithlesley.com/OLD
[Mon Jul 20 06:37:12.435242 2026] [security2:error] [pid 966386:tid 966625] [client 161.118.195.148:60762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WeDrLBqY1mBmWu_b2lgAAAD8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:12.471780 2026] [security2:error] [pid 966386:tid 966640] [client 77.110.127.138:51162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WeDrLBqY1mBmWu_b2mQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:12.471985 2026] [security2:error] [pid 966386:tid 966640] [client 77.110.127.138:51162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WeDrLBqY1mBmWu_b2mQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:12.747831 2026] [security2:error] [pid 966386:tid 966566] [client 50.116.65.227:59786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4WeDrLBqY1mBmWu_b2ggAAAAQ"]
[Mon Jul 20 06:37:12.795489 2026] [security2:error] [pid 966386:tid 966561] [client 34.73.38.214:65401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WeDrLBqY1mBmWu_b2oQAAAAE"]
[Mon Jul 20 06:37:12.942741 2026] [security2:error] [pid 966386:tid 966600] [client 14.225.17.146:56660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4WdzrLBqY1mBmWu_b2ewAAACY"], referer: http://getgarrison.com/OLD
[Mon Jul 20 06:37:13.023399 2026] [security2:error] [pid 953991:tid 954138] [client 161.118.195.148:61103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wea_X-kAXGDrIFafR1gAAAJY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:13.378351 2026] [security2:error] [pid 966386:tid 966567] [client 57.141.18.56:47652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WdDrLBqY1mBmWu_b1yQAABRE"]
[Mon Jul 20 06:37:13.415168 2026] [security2:error] [pid 966386:tid 966617] [client 50.116.65.227:59796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4WeDrLBqY1mBmWu_b2oAAAADc"]
[Mon Jul 20 06:37:13.596285 2026] [security2:error] [pid 966386:tid 966633] [client 161.118.195.148:61454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WeTrLBqY1mBmWu_b2zwAAAEc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:13.636908 2026] [security2:error] [pid 966386:tid 966476] [remote 81.173.115.7:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WeTrLBqY1mBmWu_b20QAANC8"]
[Mon Jul 20 06:37:13.743842 2026] [security2:error] [pid 966386:tid 966609] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WeTrLBqY1mBmWu_b2zQAAAC8"], referer: 1'"3000
[Mon Jul 20 06:37:13.832792 2026] [security2:error] [pid 966386:tid 966483] [remote 81.173.115.7:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WeTrLBqY1mBmWu_b21wAAJjU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:37:13.977200 2026] [security2:error] [pid 966386:tid 966481] [remote 182.77.62.24:40912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WeTrLBqY1mBmWu_b23QAARTM"]
[Mon Jul 20 06:37:13.977390 2026] [security2:error] [pid 966386:tid 966631] [client 182.77.62.24:40912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WeTrLBqY1mBmWu_b23QAARTM"]
[Mon Jul 20 06:37:14.173280 2026] [security2:error] [pid 953991:tid 954158] [client 161.118.195.148:61770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Weq_X-kAXGDrIFafSBQAAAKo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:14.267196 2026] [security2:error] [pid 953991:tid 954227] [client 135.181.246.99:59596] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "taskidsvirginia.com"] [uri "/"] [unique_id "al4Weq_X-kAXGDrIFafSCQAAAO8"]
[Mon Jul 20 06:37:14.329017 2026] [security2:error] [pid 966386:tid 966686] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/test/phpinfo.php"] [unique_id "al4WejrLBqY1mBmWu_b26QAAAHk"]
[Mon Jul 20 06:37:14.674522 2026] [security2:error] [pid 953991:tid 954044] [remote 5.252.52.249:44032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4Weq_X-kAXGDrIFafSHQAAwDQ"]
[Mon Jul 20 06:37:14.748825 2026] [security2:error] [pid 966386:tid 966627] [client 161.118.195.148:62129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WejrLBqY1mBmWu_b3AAAAAEE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:14.748828 2026] [security2:error] [pid 953991:tid 954026] [remote 188.166.241.141:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4Weq_X-kAXGDrIFafSIAAAySI"]
[Mon Jul 20 06:37:14.836388 2026] [security2:error] [pid 966386:tid 966635] [client 223.185.13.213:18217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WejrLBqY1mBmWu_b3BAAAAEk"]
[Mon Jul 20 06:37:14.836494 2026] [security2:error] [pid 966386:tid 966635] [client 223.185.13.213:18217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WejrLBqY1mBmWu_b3BAAAAEk"]
[Mon Jul 20 06:37:14.907433 2026] [security2:error] [pid 953991:tid 954083] [remote 5.252.52.249:44032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4Weq_X-kAXGDrIFafSKwAA2Fs"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 06:37:14.964321 2026] [security2:error] [pid 953991:tid 954183] [client 103.238.106.162:61006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Weq_X-kAXGDrIFafSMQAAAMM"]
[Mon Jul 20 06:37:14.965056 2026] [security2:error] [pid 953991:tid 954183] [client 103.238.106.162:61006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Weq_X-kAXGDrIFafSMQAAAMM"]
[Mon Jul 20 06:37:14.989295 2026] [security2:error] [pid 966386:tid 966595] [client 34.73.38.214:60568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WejrLBqY1mBmWu_b3CQAAACE"]
[Mon Jul 20 06:37:15.143759 2026] [security2:error] [pid 953991:tid 954169] [client 14.225.17.146:56596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Wea_X-kAXGDrIFafR4wAAALU"], referer: http://secretkeynumerology.com/OLD
[Mon Jul 20 06:37:15.164377 2026] [security2:error] [pid 953991:tid 954094] [remote 188.166.241.141:56234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4We6_X-kAXGDrIFafSOAAAt2Y"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:37:15.215665 2026] [security2:error] [pid 966386:tid 966495] [remote 192.241.143.148:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4WezrLBqY1mBmWu_b3EgAAf0E"]
[Mon Jul 20 06:37:15.324906 2026] [security2:error] [pid 966386:tid 966596] [client 161.118.195.148:62450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WezrLBqY1mBmWu_b3EwAAACI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:15.542779 2026] [proxy:error] [pid 966386:tid 966647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:15.542851 2026] [proxy_http:error] [pid 966386:tid 966647] [client 34.73.38.214:60172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:15.543396 2026] [proxy:error] [pid 966386:tid 966647] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:15.543421 2026] [proxy_http:error] [pid 966386:tid 966647] [client 34.73.38.214:60172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:15.726176 2026] [security2:error] [pid 953991:tid 954149] [client 103.125.179.95:63850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4We6_X-kAXGDrIFafSSAAAAKE"]
[Mon Jul 20 06:37:15.726412 2026] [security2:error] [pid 953991:tid 954149] [client 103.125.179.95:63850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4We6_X-kAXGDrIFafSSAAAAKE"]
[Mon Jul 20 06:37:15.864190 2026] [security2:error] [pid 966386:tid 966502] [remote 192.241.143.148:58306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4WezrLBqY1mBmWu_b3LgAADkg"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:37:15.866484 2026] [security2:error] [pid 966386:tid 966571] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WezrLBqY1mBmWu_b3JwAAAAk"], referer: 1'"3000
[Mon Jul 20 06:37:15.901559 2026] [security2:error] [pid 953991:tid 954247] [client 161.118.195.148:62816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4We6_X-kAXGDrIFafSTgAAAQM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:16.068523 2026] [security2:error] [pid 966386:tid 966680] [client 171.61.165.146:13597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WfDrLBqY1mBmWu_b3OQAAAHM"]
[Mon Jul 20 06:37:16.068623 2026] [security2:error] [pid 966386:tid 966680] [client 171.61.165.146:13597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WfDrLBqY1mBmWu_b3OQAAAHM"]
[Mon Jul 20 06:37:16.162437 2026] [security2:error] [pid 953991:tid 954122] [client 14.225.17.146:56705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4We6_X-kAXGDrIFafSVgAAAIY"], referer: https://secretkeynumerology.com/OLD
[Mon Jul 20 06:37:16.283530 2026] [security2:error] [pid 966386:tid 966568] [client 14.225.17.146:56754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4WezrLBqY1mBmWu_b3DgAAAAY"]
[Mon Jul 20 06:37:16.303850 2026] [security2:error] [pid 966386:tid 966660] [client 77.110.127.138:51207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfDrLBqY1mBmWu_b3SAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:16.303986 2026] [security2:error] [pid 966386:tid 966660] [client 77.110.127.138:51207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfDrLBqY1mBmWu_b3SAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:16.350931 2026] [security2:error] [pid 966386:tid 966608] [client 50.116.65.227:59834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WfDrLBqY1mBmWu_b3TAAAAC4"]
[Mon Jul 20 06:37:16.360246 2026] [security2:error] [pid 966386:tid 966654] [client 50.116.65.227:59838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WfDrLBqY1mBmWu_b3TwAAAFw"]
[Mon Jul 20 06:37:16.426724 2026] [security2:error] [pid 953991:tid 954156] [client 66.249.74.2:62047] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "greenbee-emea.com"] [uri "/robots.txt"] [unique_id "al4WfK_X-kAXGDrIFafSYgAAAKg"]
[Mon Jul 20 06:37:16.476317 2026] [security2:error] [pid 966386:tid 966649] [client 161.118.195.148:63126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WfDrLBqY1mBmWu_b3VQAAAFc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:16.544504 2026] [security2:error] [pid 953991:tid 954215] [client 37.140.223.43:46351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.223.140.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "balticsteelmgmt.com"] [uri "/wp-login.php"] [unique_id "al4WfK_X-kAXGDrIFafSaAAAAOM"]
[Mon Jul 20 06:37:16.685724 2026] [core:error] [pid 953991:tid 954190] [client 157.245.2.225:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:37:16.685744 2026] [core:error] [pid 953991:tid 954190] [client 157.245.2.225:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:37:16.743924 2026] [security2:error] [pid 953991:tid 954160] [client 39.48.81.23:63934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WfK_X-kAXGDrIFafSdwAAAKw"]
[Mon Jul 20 06:37:16.744049 2026] [security2:error] [pid 953991:tid 954160] [client 39.48.81.23:63934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WfK_X-kAXGDrIFafSdwAAAKw"]
[Mon Jul 20 06:37:16.833913 2026] [security2:error] [pid 966386:tid 966609] [client 104.234.53.87:22203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WfDrLBqY1mBmWu_b3XgAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:16.865136 2026] [security2:error] [pid 966386:tid 966615] [client 14.225.17.146:56590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4WezrLBqY1mBmWu_b3LQAAADU"], referer: http://adultdaycarereno.com/OLD
[Mon Jul 20 06:37:16.865138 2026] [security2:error] [pid 966386:tid 966651] [client 14.225.17.146:56774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4WfDrLBqY1mBmWu_b3SQAAAFk"], referer: http://nextlevelpressurewashing.com/OLD
[Mon Jul 20 06:37:16.996800 2026] [security2:error] [pid 966386:tid 966459] [remote 167.233.114.32:55090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4WfDrLBqY1mBmWu_b3cQAAMCA"]
[Mon Jul 20 06:37:17.056564 2026] [security2:error] [pid 966386:tid 966625] [client 161.118.195.148:63414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WfTrLBqY1mBmWu_b3cwAAAD8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:17.096361 2026] [security2:error] [pid 966386:tid 966663] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WfDrLBqY1mBmWu_b3YwAAAGQ"]
[Mon Jul 20 06:37:17.201496 2026] [proxy:error] [pid 966386:tid 966667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:17.201567 2026] [proxy_http:error] [pid 966386:tid 966667] [client 34.73.38.214:63162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:17.202056 2026] [proxy:error] [pid 966386:tid 966667] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:17.202082 2026] [proxy_http:error] [pid 966386:tid 966667] [client 34.73.38.214:63162] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:17.202900 2026] [security2:error] [pid 966386:tid 966586] [client 34.73.38.214:55891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WfTrLBqY1mBmWu_b3egAAABg"]
[Mon Jul 20 06:37:17.210687 2026] [security2:error] [pid 966386:tid 966508] [remote 167.233.114.32:55090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4WfTrLBqY1mBmWu_b3fAAAdE4"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:37:17.218157 2026] [security2:error] [pid 966386:tid 966584] [client 57.141.18.98:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WeDrLBqY1mBmWu_b2gQAAFiI"]
[Mon Jul 20 06:37:17.309428 2026] [security2:error] [pid 966386:tid 966583] [client 217.142.18.172:10361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WfTrLBqY1mBmWu_b3fwAAABU"]
[Mon Jul 20 06:37:17.316813 2026] [security2:error] [pid 966386:tid 966583] [client 217.142.18.172:10361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WfTrLBqY1mBmWu_b3fwAAABU"]
[Mon Jul 20 06:37:17.333150 2026] [security2:error] [pid 966386:tid 966620] [client 114.119.154.39:38003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/category/tablescapes/occasions/back-to-school/"] [unique_id "al4WfTrLBqY1mBmWu_b3gAAAADo"], referer: https://lifeisbetterlakeside.com/lemurs-up-close-and-personal-at-the-alabama-gulf-coast-zoo-part-2/
[Mon Jul 20 06:37:17.413475 2026] [security2:error] [pid 966386:tid 966512] [remote 103.82.22.235:35966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4WfTrLBqY1mBmWu_b3ggAATFI"]
[Mon Jul 20 06:37:17.631135 2026] [security2:error] [pid 953991:tid 954131] [client 161.118.195.148:63775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wfa_X-kAXGDrIFafSoQAAAI8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:17.663146 2026] [security2:error] [pid 966386:tid 966654] [client 171.60.139.123:57953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WfTrLBqY1mBmWu_b3jwAAAFw"]
[Mon Jul 20 06:37:17.663249 2026] [security2:error] [pid 966386:tid 966654] [client 171.60.139.123:57953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WfTrLBqY1mBmWu_b3jwAAAFw"]
[Mon Jul 20 06:37:17.663311 2026] [security2:error] [pid 953991:tid 954187] [client 197.186.66.42:57848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Wfa_X-kAXGDrIFafSogAAAMc"]
[Mon Jul 20 06:37:17.663933 2026] [security2:error] [pid 953991:tid 954187] [client 197.186.66.42:57848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Wfa_X-kAXGDrIFafSogAAAMc"]
[Mon Jul 20 06:37:17.767941 2026] [security2:error] [pid 966386:tid 966640] [client 14.225.17.146:56706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4WfTrLBqY1mBmWu_b3kgAAAE4"], referer: https://adultdaycarereno.com/OLD
[Mon Jul 20 06:37:17.898031 2026] [security2:error] [pid 966386:tid 966514] [remote 103.82.22.235:35966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4WfTrLBqY1mBmWu_b3lQAAAVQ"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 06:37:17.957054 2026] [security2:error] [pid 953991:tid 954232] [client 47.128.44.43:9102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsafety.ca"] [uri "/robots.txt"] [unique_id "al4Wfa_X-kAXGDrIFafSrAAAAPQ"]
[Mon Jul 20 06:37:17.968098 2026] [proxy:error] [pid 966386:tid 966601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:17.968164 2026] [proxy_http:error] [pid 966386:tid 966601] [client 34.73.38.214:61870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:17.968612 2026] [proxy:error] [pid 966386:tid 966601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:17.968647 2026] [proxy_http:error] [pid 966386:tid 966601] [client 34.73.38.214:61870] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:18.015966 2026] [security2:error] [pid 966386:tid 966656] [client 34.74.185.202:64422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WfjrLBqY1mBmWu_b3mwAAAF4"]
[Mon Jul 20 06:37:18.184561 2026] [security2:error] [pid 966386:tid 966659] [client 104.234.53.87:22203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WfjrLBqY1mBmWu_b3owAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:18.212346 2026] [security2:error] [pid 953991:tid 954190] [client 161.118.195.148:64104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wfq_X-kAXGDrIFafSwwAAAMo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:18.454019 2026] [security2:error] [pid 966386:tid 966599] [client 34.73.38.214:63815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WfjrLBqY1mBmWu_b3rgAAACU"]
[Mon Jul 20 06:37:18.530221 2026] [security2:error] [pid 966386:tid 966679] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/backup/config.php"] [unique_id "al4WfjrLBqY1mBmWu_b3swAAAHI"]
[Mon Jul 20 06:37:18.784464 2026] [security2:error] [pid 966386:tid 966646] [client 161.118.195.148:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WfjrLBqY1mBmWu_b3ugAAAFQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:18.810912 2026] [security2:error] [pid 953991:tid 954122] [client 77.110.127.138:51253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wfq_X-kAXGDrIFafS2gAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:18.811007 2026] [security2:error] [pid 953991:tid 954122] [client 77.110.127.138:51253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wfq_X-kAXGDrIFafS2gAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:18.890099 2026] [security2:error] [pid 966386:tid 966608] [client 13.233.207.33:62072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WfjrLBqY1mBmWu_b3pQAAAC4"]
[Mon Jul 20 06:37:18.952264 2026] [security2:error] [pid 966386:tid 966640] [client 34.74.185.202:63524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WfjrLBqY1mBmWu_b3wgAAAE4"]
[Mon Jul 20 06:37:18.964835 2026] [security2:error] [pid 966386:tid 966598] [client 77.110.127.138:51255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfjrLBqY1mBmWu_b3xAAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:18.964924 2026] [security2:error] [pid 966386:tid 966598] [client 77.110.127.138:51255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfjrLBqY1mBmWu_b3xAAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.072237 2026] [security2:error] [pid 966386:tid 966647] [client 34.73.38.214:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WfzrLBqY1mBmWu_b3xwAAAFU"]
[Mon Jul 20 06:37:19.207947 2026] [security2:error] [pid 966386:tid 966596] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WfjrLBqY1mBmWu_b3vgAAACI"]
[Mon Jul 20 06:37:19.310359 2026] [security2:error] [pid 966386:tid 966465] [remote 20.173.88.122:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4WfzrLBqY1mBmWu_b3zwAAUCU"]
[Mon Jul 20 06:37:19.333285 2026] [security2:error] [pid 953991:tid 954180] [client 104.234.53.85:47657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Wf6_X-kAXGDrIFafS8QAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:19.333521 2026] [security2:error] [pid 966386:tid 966583] [client 113.160.97.242:50400] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4WfzrLBqY1mBmWu_b31QAAABU"]
[Mon Jul 20 06:37:19.356849 2026] [security2:error] [pid 966386:tid 966624] [client 161.118.195.148:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WfzrLBqY1mBmWu_b32QAAAD4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:19.367838 2026] [security2:error] [pid 953991:tid 954173] [client 77.110.127.138:51257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wf6_X-kAXGDrIFafS8gAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.367935 2026] [security2:error] [pid 953991:tid 954173] [client 77.110.127.138:51257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wf6_X-kAXGDrIFafS8gAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.474199 2026] [security2:error] [pid 966386:tid 966692] [client 14.225.17.146:56580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4WfjrLBqY1mBmWu_b3ogAAAH8"], referer: http://dereckcastellon.com/OLD
[Mon Jul 20 06:37:19.479388 2026] [security2:error] [pid 966386:tid 966523] [remote 173.212.252.15:53146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WfzrLBqY1mBmWu_b33wAALV0"]
[Mon Jul 20 06:37:19.479636 2026] [security2:error] [pid 966386:tid 966607] [client 173.212.252.15:53146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WfzrLBqY1mBmWu_b33wAALV0"]
[Mon Jul 20 06:37:19.571692 2026] [security2:error] [pid 966386:tid 966521] [remote 81.173.115.7:48372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WfzrLBqY1mBmWu_b34gAAX1s"]
[Mon Jul 20 06:37:19.598606 2026] [security2:error] [pid 966386:tid 966571] [client 77.110.127.138:51260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfzrLBqY1mBmWu_b35AAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.598729 2026] [security2:error] [pid 966386:tid 966571] [client 77.110.127.138:51260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfzrLBqY1mBmWu_b35AAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.658845 2026] [security2:error] [pid 966386:tid 966616] [client 82.102.27.163:41844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WfzrLBqY1mBmWu_b35gAAADY"]
[Mon Jul 20 06:37:19.658934 2026] [security2:error] [pid 966386:tid 966616] [client 82.102.27.163:41844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4WfzrLBqY1mBmWu_b35gAAADY"]
[Mon Jul 20 06:37:19.695098 2026] [security2:error] [pid 966386:tid 966528] [remote 20.173.88.122:43192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4WfzrLBqY1mBmWu_b36gAAY2I"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:37:19.727677 2026] [security2:error] [pid 953991:tid 954129] [client 34.74.185.202:53993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Wf6_X-kAXGDrIFafS_wAAAI0"]
[Mon Jul 20 06:37:19.764154 2026] [security2:error] [pid 953991:tid 954241] [client 77.110.127.138:51262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wf6_X-kAXGDrIFafTAQAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.764233 2026] [security2:error] [pid 953991:tid 954241] [client 77.110.127.138:51262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wf6_X-kAXGDrIFafTAQAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:19.817141 2026] [security2:error] [pid 966386:tid 966479] [remote 81.173.115.7:48372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WfzrLBqY1mBmWu_b38QAAADE"], referer: https://rcq.nst.mybluehost.me/wp-login.php
[Mon Jul 20 06:37:19.933273 2026] [security2:error] [pid 966386:tid 966569] [client 161.118.195.148:65193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WfzrLBqY1mBmWu_b39wAAAAc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:19.933631 2026] [security2:error] [pid 966386:tid 966568] [client 77.110.127.138:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfzrLBqY1mBmWu_b3-AAAAAY"]
[Mon Jul 20 06:37:19.933700 2026] [security2:error] [pid 966386:tid 966568] [client 77.110.127.138:51264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WfzrLBqY1mBmWu_b3-AAAAAY"]
[Mon Jul 20 06:37:19.980775 2026] [security2:error] [pid 966386:tid 966646] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WfzrLBqY1mBmWu_b37QAAAFQ"]
[Mon Jul 20 06:37:20.006254 2026] [security2:error] [pid 953991:tid 954240] [client 14.225.17.146:56789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4Wfa_X-kAXGDrIFafSqgAAAPw"], referer: http://younutrition.gr/OLD
[Mon Jul 20 06:37:20.047851 2026] [security2:error] [pid 966386:tid 966649] [client 77.110.127.138:51179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WgDrLBqY1mBmWu_b3_gAAAFc"]
[Mon Jul 20 06:37:20.047945 2026] [security2:error] [pid 966386:tid 966649] [client 77.110.127.138:51179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WgDrLBqY1mBmWu_b3_gAAAFc"]
[Mon Jul 20 06:37:20.099272 2026] [security2:error] [pid 953991:tid 954073] [remote 162.19.86.63:32809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WgK_X-kAXGDrIFafTDQAAqlE"]
[Mon Jul 20 06:37:20.201077 2026] [security2:error] [pid 966386:tid 966668] [client 34.73.38.214:58908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WgDrLBqY1mBmWu_b4CwAAAGg"]
[Mon Jul 20 06:37:20.212538 2026] [security2:error] [pid 966386:tid 966629] [client 34.74.185.202:58500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WgDrLBqY1mBmWu_b4DAAAAEM"]
[Mon Jul 20 06:37:20.338718 2026] [security2:error] [pid 953991:tid 954083] [remote 162.19.86.63:32809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WgK_X-kAXGDrIFafTFAAA4Fs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:37:20.512126 2026] [security2:error] [pid 966386:tid 966676] [client 161.118.195.148:49160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WgDrLBqY1mBmWu_b4HAAAAG8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:20.518678 2026] [security2:error] [pid 953991:tid 954198] [client 106.219.188.178:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WgK_X-kAXGDrIFafTHQAAANI"]
[Mon Jul 20 06:37:20.519287 2026] [security2:error] [pid 953991:tid 954198] [client 106.219.188.178:51799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WgK_X-kAXGDrIFafTHQAAANI"]
[Mon Jul 20 06:37:20.626595 2026] [security2:error] [pid 966386:tid 966612] [client 14.225.17.146:57044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4WgDrLBqY1mBmWu_b4HQAAADI"], referer: http://thechancersband.com/OLD
[Mon Jul 20 06:37:20.774532 2026] [security2:error] [pid 966386:tid 966598] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WgDrLBqY1mBmWu_b4GwAAACQ"]
[Mon Jul 20 06:37:20.783719 2026] [security2:error] [pid 953991:tid 954176] [client 104.207.42.139:41613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WgK_X-kAXGDrIFafTJAAAALw"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:20.795782 2026] [security2:error] [pid 953991:tid 954227] [client 34.74.185.202:60509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WgK_X-kAXGDrIFafTJgAAAO8"]
[Mon Jul 20 06:37:21.062786 2026] [security2:error] [pid 966386:tid 966604] [client 34.73.38.214:63904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WgTrLBqY1mBmWu_b4MQAAACo"]
[Mon Jul 20 06:37:21.065079 2026] [security2:error] [pid 966386:tid 966614] [client 34.73.38.214:52284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WgTrLBqY1mBmWu_b4MgAAADQ"]
[Mon Jul 20 06:37:21.100350 2026] [security2:error] [pid 966386:tid 966643] [client 161.118.195.148:49558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WgTrLBqY1mBmWu_b4MwAAAFE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:21.255236 2026] [security2:error] [pid 953991:tid 954184] [client 104.234.53.70:63647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wga_X-kAXGDrIFafTNAAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:21.276732 2026] [security2:error] [pid 966386:tid 966616] [client 34.139.11.221:49751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/xmlrpc.php"] [unique_id "al4WgTrLBqY1mBmWu_b4PgAAADY"]
[Mon Jul 20 06:37:21.310226 2026] [security2:error] [pid 966386:tid 966637] [client 57.141.18.21:54014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WfDrLBqY1mBmWu_b3RQAAS0o"]
[Mon Jul 20 06:37:21.531570 2026] [security2:error] [pid 953991:tid 954243] [client 34.139.11.221:50452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Wga_X-kAXGDrIFafTQgAAAP8"]
[Mon Jul 20 06:37:21.547357 2026] [security2:error] [pid 966386:tid 966572] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WgTrLBqY1mBmWu_b4QAAAAAo"]
[Mon Jul 20 06:37:21.594150 2026] [security2:error] [pid 966386:tid 966540] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WgTrLBqY1mBmWu_b4TAAAVW4"]
[Mon Jul 20 06:37:21.594284 2026] [security2:error] [pid 966386:tid 966647] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WgTrLBqY1mBmWu_b4TAAAVW4"]
[Mon Jul 20 06:37:21.622173 2026] [core:error] [pid 966386:tid 966560] [client 14.225.17.146:57661] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:37:21.622186 2026] [core:error] [pid 966386:tid 966560] [client 14.225.17.146:57661] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:37:21.644323 2026] [security2:error] [pid 966386:tid 966655] [client 57.141.18.104:21508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WfDrLBqY1mBmWu_b3XwAAXU0"]
[Mon Jul 20 06:37:21.676633 2026] [security2:error] [pid 966386:tid 966627] [client 161.118.195.148:49903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WgTrLBqY1mBmWu_b4TwAAAEE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:21.682148 2026] [security2:error] [pid 953991:tid 954240] [client 34.139.11.221:55939] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Wga_X-kAXGDrIFafTSAAAAPw"]
[Mon Jul 20 06:37:21.835132 2026] [security2:error] [pid 953991:tid 954195] [client 34.74.185.202:61134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Wga_X-kAXGDrIFafTTgAAAM8"]
[Mon Jul 20 06:37:21.888175 2026] [security2:error] [pid 966386:tid 966577] [client 34.139.11.221:55915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WgTrLBqY1mBmWu_b4VAAAAA8"]
[Mon Jul 20 06:37:22.030328 2026] [security2:error] [pid 953991:tid 954231] [client 13.201.64.214:46568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.64.201.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Wgq_X-kAXGDrIFafTUwAAAPM"]
[Mon Jul 20 06:37:22.030423 2026] [security2:error] [pid 953991:tid 954231] [client 13.201.64.214:46568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Wgq_X-kAXGDrIFafTUwAAAPM"]
[Mon Jul 20 06:37:22.094487 2026] [security2:error] [pid 966386:tid 966657] [client 34.139.11.221:56123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4ZAAAAF8"]
[Mon Jul 20 06:37:22.157171 2026] [security2:error] [pid 966386:tid 966690] [client 187.108.85.186:62289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WgjrLBqY1mBmWu_b4ZwAAAH0"]
[Mon Jul 20 06:37:22.157332 2026] [security2:error] [pid 966386:tid 966690] [client 187.108.85.186:62289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WgjrLBqY1mBmWu_b4ZwAAAH0"]
[Mon Jul 20 06:37:22.240503 2026] [security2:error] [pid 966386:tid 966594] [client 34.73.38.214:63951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.supportinghands22.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4bQAAACA"]
[Mon Jul 20 06:37:22.247886 2026] [security2:error] [pid 966386:tid 966614] [client 161.118.195.148:50233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WgjrLBqY1mBmWu_b4bgAAADQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:22.255475 2026] [security2:error] [pid 966386:tid 966600] [client 34.139.11.221:60722] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4bwAAACY"]
[Mon Jul 20 06:37:22.331589 2026] [security2:error] [pid 966386:tid 966578] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WgjrLBqY1mBmWu_b4XgAAABA"]
[Mon Jul 20 06:37:22.331762 2026] [security2:error] [pid 966386:tid 966590] [client 34.73.38.214:62598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4dAAAABw"]
[Mon Jul 20 06:37:22.455948 2026] [autoindex:error] [pid 966386:tid 966676] [client 3.151.194.164:42303] AH01276: Cannot serve directory /home1/ikrsycmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:37:22.485077 2026] [security2:error] [pid 966386:tid 966580] [client 34.139.11.221:65254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4fAAAABI"]
[Mon Jul 20 06:37:22.532349 2026] [security2:error] [pid 966386:tid 966665] [client 14.225.17.146:57430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4WgTrLBqY1mBmWu_b4RQAAAGY"], referer: http://koaconsultants.com/OLD
[Mon Jul 20 06:37:22.702867 2026] [security2:error] [pid 966386:tid 966644] [client 34.139.11.221:58904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4iQAAAFI"]
[Mon Jul 20 06:37:22.782887 2026] [security2:error] [pid 966386:tid 966622] [client 104.234.53.94:64085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WgjrLBqY1mBmWu_b4jgAAADw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:22.825520 2026] [security2:error] [pid 953991:tid 954216] [client 161.118.195.148:50553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wgq_X-kAXGDrIFafTYAAAAOQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:22.902596 2026] [security2:error] [pid 966386:tid 966661] [client 212.106.90.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4WgjrLBqY1mBmWu_b4gAAAYnE"]
[Mon Jul 20 06:37:22.905878 2026] [security2:error] [pid 966386:tid 966597] [client 34.139.11.221:61209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WgjrLBqY1mBmWu_b4mwAAACM"]
[Mon Jul 20 06:37:23.059886 2026] [security2:error] [pid 966386:tid 966642] [client 34.74.185.202:55358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WgzrLBqY1mBmWu_b4pQAAAFA"]
[Mon Jul 20 06:37:23.088080 2026] [security2:error] [pid 966386:tid 966590] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/private/config.php"] [unique_id "al4WgzrLBqY1mBmWu_b4pwAAABw"]
[Mon Jul 20 06:37:23.096170 2026] [security2:error] [pid 966386:tid 966664] [client 103.163.98.191:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WgjrLBqY1mBmWu_b4kgAAAGU"]
[Mon Jul 20 06:37:23.113256 2026] [security2:error] [pid 953991:tid 954143] [client 74.208.214.194:41984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Wg6_X-kAXGDrIFafTZgAAAJs"]
[Mon Jul 20 06:37:23.144345 2026] [security2:error] [pid 966386:tid 966576] [client 34.139.11.221:49171] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WgzrLBqY1mBmWu_b4qwAAAA4"]
[Mon Jul 20 06:37:23.329190 2026] [security2:error] [pid 953991:tid 954178] [client 37.27.59.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "test.koaconsultants.com"] [uri "/index.php"] [unique_id "al4Wg6_X-kAXGDrIFafTZQAAAL4"]
[Mon Jul 20 06:37:23.355678 2026] [security2:error] [pid 966386:tid 966650] [client 34.139.11.221:57870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WgzrLBqY1mBmWu_b4twAAAFg"]
[Mon Jul 20 06:37:23.405793 2026] [security2:error] [pid 966386:tid 966580] [client 161.118.195.148:50899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WgzrLBqY1mBmWu_b4uQAAABI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:23.450171 2026] [security2:error] [pid 966386:tid 966685] [client 34.73.38.214:62011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WgzrLBqY1mBmWu_b4ugAAAHg"]
[Mon Jul 20 06:37:23.696073 2026] [security2:error] [pid 966386:tid 966622] [client 34.139.11.221:50452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.aljosour-alarabia.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WgzrLBqY1mBmWu_b4xgAAADw"]
[Mon Jul 20 06:37:23.856289 2026] [security2:error] [pid 953991:tid 954150] [client 158.173.89.95:37959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Wg6_X-kAXGDrIFafTdAAAAKI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:37:23.899371 2026] [proxy:error] [pid 953991:tid 954214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:23.899449 2026] [proxy_http:error] [pid 953991:tid 954214] [client 34.73.38.214:51432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:23.900270 2026] [proxy:error] [pid 953991:tid 954214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:23.900308 2026] [proxy_http:error] [pid 953991:tid 954214] [client 34.73.38.214:51432] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:23.936863 2026] [security2:error] [pid 953991:tid 954232] [client 57.141.18.34:64428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wf6_X-kAXGDrIFafS7AAA9HE"]
[Mon Jul 20 06:37:23.985875 2026] [security2:error] [pid 953991:tid 954153] [client 34.73.38.214:64295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Wg6_X-kAXGDrIFafTeQAAAKU"]
[Mon Jul 20 06:37:23.994253 2026] [security2:error] [pid 966386:tid 966663] [client 161.118.195.148:51246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WgzrLBqY1mBmWu_b41gAAAGQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:24.100134 2026] [security2:error] [pid 966386:tid 966602] [client 77.110.127.138:51283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WhDrLBqY1mBmWu_b44AAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:24.100225 2026] [security2:error] [pid 966386:tid 966602] [client 77.110.127.138:51283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WhDrLBqY1mBmWu_b44AAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:24.255046 2026] [security2:error] [pid 966386:tid 966589] [client 14.225.17.146:58233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4WgzrLBqY1mBmWu_b4qgAAABs"], referer: http://sarahholyfield.com/OLD
[Mon Jul 20 06:37:24.320438 2026] [security2:error] [pid 966386:tid 966662] [client 34.74.185.202:53205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WhDrLBqY1mBmWu_b47wAAAGM"]
[Mon Jul 20 06:37:24.400138 2026] [security2:error] [pid 953991:tid 954166] [client 112.208.70.94:42831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WhK_X-kAXGDrIFafTiQAAALI"]
[Mon Jul 20 06:37:24.400233 2026] [security2:error] [pid 953991:tid 954166] [client 112.208.70.94:42831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WhK_X-kAXGDrIFafTiQAAALI"]
[Mon Jul 20 06:37:24.569506 2026] [security2:error] [pid 966386:tid 966629] [client 161.118.195.148:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WhDrLBqY1mBmWu_b5AgAAAEM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:24.585105 2026] [security2:error] [pid 953991:tid 954151] [client 47.128.19.87:41766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4WhK_X-kAXGDrIFafTjQAAAKM"]
[Mon Jul 20 06:37:24.793016 2026] [security2:error] [pid 966386:tid 966573] [client 34.73.38.214:63974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WhDrLBqY1mBmWu_b5BwAAAAs"]
[Mon Jul 20 06:37:24.930997 2026] [security2:error] [pid 966386:tid 966677] [client 14.225.17.146:58422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4WgzrLBqY1mBmWu_b4vQAAAHA"], referer: http://balticsteelmgmt.com/OLD
[Mon Jul 20 06:37:24.966838 2026] [proxy:error] [pid 953991:tid 954170] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:24.966933 2026] [proxy_http:error] [pid 953991:tid 954170] [client 34.73.38.214:50292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:24.967698 2026] [proxy:error] [pid 953991:tid 954170] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:24.967742 2026] [proxy_http:error] [pid 953991:tid 954170] [client 34.73.38.214:50292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:25.030998 2026] [security2:error] [pid 953991:tid 954216] [client 34.74.185.202:53218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Wha_X-kAXGDrIFafTmAAAAOQ"]
[Mon Jul 20 06:37:25.143778 2026] [security2:error] [pid 966386:tid 966618] [client 161.118.195.148:51956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WhTrLBqY1mBmWu_b5JAAAADg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:25.147062 2026] [security2:error] [pid 966386:tid 966591] [client 14.225.17.146:59049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4WhDrLBqY1mBmWu_b5HgAAAB0"], referer: http://ncsynchro.com/OLD
[Mon Jul 20 06:37:25.267306 2026] [security2:error] [pid 966386:tid 966578] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/settings.php"] [unique_id "al4WhTrLBqY1mBmWu_b5KAAAABA"]
[Mon Jul 20 06:37:25.311534 2026] [security2:error] [pid 953991:tid 954213] [client 223.185.13.213:9402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wha_X-kAXGDrIFafTngAAAOE"]
[Mon Jul 20 06:37:25.311652 2026] [security2:error] [pid 953991:tid 954213] [client 223.185.13.213:9402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wha_X-kAXGDrIFafTngAAAOE"]
[Mon Jul 20 06:37:25.502763 2026] [security2:error] [pid 953991:tid 954196] [client 103.238.106.162:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Wha_X-kAXGDrIFafTpQAAANA"]
[Mon Jul 20 06:37:25.503464 2026] [security2:error] [pid 953991:tid 954196] [client 103.238.106.162:60557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Wha_X-kAXGDrIFafTpQAAANA"]
[Mon Jul 20 06:37:25.648206 2026] [security2:error] [pid 953991:tid 954221] [client 34.73.38.214:58553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Wha_X-kAXGDrIFafTrAAAAOk"]
[Mon Jul 20 06:37:25.722377 2026] [security2:error] [pid 953991:tid 954238] [client 216.73.217.138:37036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wha_X-kAXGDrIFafTqQAA-gU"]
[Mon Jul 20 06:37:25.726951 2026] [security2:error] [pid 953991:tid 954136] [client 161.118.195.148:52317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wha_X-kAXGDrIFafTrwAAAJQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:25.842379 2026] [security2:error] [pid 966386:tid 966688] [client 14.225.17.146:58730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4WhDrLBqY1mBmWu_b49wAAAHs"], referer: http://inspirespublishing.com/OLD
[Mon Jul 20 06:37:25.854721 2026] [security2:error] [pid 953991:tid 954177] [client 216.73.217.138:37036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wha_X-kAXGDrIFafTsAAAvRE"]
[Mon Jul 20 06:37:25.903874 2026] [security2:error] [pid 966386:tid 966684] [client 50.116.65.227:16696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4WhTrLBqY1mBmWu_b5UAAAAHc"]
[Mon Jul 20 06:37:25.907396 2026] [security2:error] [pid 966386:tid 966605] [client 14.225.17.146:58967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4WhDrLBqY1mBmWu_b4_AAAACs"]
[Mon Jul 20 06:37:25.982237 2026] [proxy:error] [pid 966386:tid 966682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:25.982306 2026] [proxy_http:error] [pid 966386:tid 966682] [client 34.73.38.214:58253] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:25.982761 2026] [proxy:error] [pid 966386:tid 966682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:25.982791 2026] [proxy_http:error] [pid 966386:tid 966682] [client 34.73.38.214:58253] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:25.998198 2026] [security2:error] [pid 966386:tid 966641] [client 104.234.53.62:28337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WhTrLBqY1mBmWu_b5WAAAAE8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:26.039575 2026] [security2:error] [pid 953991:tid 954148] [client 34.74.185.202:59892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Whq_X-kAXGDrIFafTuAAAAKA"]
[Mon Jul 20 06:37:26.077912 2026] [security2:error] [pid 966386:tid 966665] [client 14.225.17.146:59418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4WhTrLBqY1mBmWu_b5VQAAAGY"], referer: http://phillipbloch.com/OLD
[Mon Jul 20 06:37:26.133434 2026] [security2:error] [pid 953991:tid 954241] [client 223.109.252.171:45788] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "liquidationteam.com"] [uri "/exclusive-deals/"] [unique_id "al4Whq_X-kAXGDrIFafTuQAAAP0"]
[Mon Jul 20 06:37:26.133538 2026] [security2:error] [pid 953991:tid 954241] [client 223.109.252.171:45788] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "liquidationteam.com"] [uri "/exclusive-deals/"] [unique_id "al4Whq_X-kAXGDrIFafTuQAAAP0"]
[Mon Jul 20 06:37:26.309454 2026] [security2:error] [pid 966386:tid 966578] [client 161.118.195.148:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WhjrLBqY1mBmWu_b5ZQAAABA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:26.482662 2026] [security2:error] [pid 953991:tid 954081] [remote 78.46.157.202:59974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4Whq_X-kAXGDrIFafTwgAAqlk"]
[Mon Jul 20 06:37:26.712369 2026] [security2:error] [pid 953991:tid 954068] [remote 78.46.157.202:59974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4Whq_X-kAXGDrIFafTxQAAj0w"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:37:26.716088 2026] [security2:error] [pid 966386:tid 966644] [client 171.61.165.146:13131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WhjrLBqY1mBmWu_b5fgAAAFI"]
[Mon Jul 20 06:37:26.716174 2026] [security2:error] [pid 966386:tid 966644] [client 171.61.165.146:13131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WhjrLBqY1mBmWu_b5fgAAAFI"]
[Mon Jul 20 06:37:26.727631 2026] [security2:error] [pid 966386:tid 966570] [client 34.74.185.202:60391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WhjrLBqY1mBmWu_b5fwAAAAg"]
[Mon Jul 20 06:37:26.865153 2026] [security2:error] [pid 966386:tid 966682] [client 34.73.38.214:52663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WhjrLBqY1mBmWu_b5igAAAHU"]
[Mon Jul 20 06:37:26.891366 2026] [security2:error] [pid 966386:tid 966684] [client 161.118.195.148:52993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WhjrLBqY1mBmWu_b5jgAAAHc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:27.201614 2026] [security2:error] [pid 966386:tid 966631] [client 34.73.38.214:61139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WhzrLBqY1mBmWu_b5pwAAAEU"]
[Mon Jul 20 06:37:27.368537 2026] [security2:error] [pid 966386:tid 966569] [client 34.74.185.202:62907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WhzrLBqY1mBmWu_b5qwAAAAc"]
[Mon Jul 20 06:37:27.473154 2026] [security2:error] [pid 953991:tid 954207] [client 161.118.195.148:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wh6_X-kAXGDrIFafT2wAAANs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:27.696213 2026] [security2:error] [pid 953991:tid 954210] [client 14.225.17.146:50866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Whq_X-kAXGDrIFafTwAAAAN4"], referer: http://alaraycreative.com/OLD
[Mon Jul 20 06:37:27.809363 2026] [security2:error] [pid 966386:tid 966623] [client 14.225.17.146:51306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4WhzrLBqY1mBmWu_b5vAAAAD0"], referer: http://aljosour-alarabia.com/OLD
[Mon Jul 20 06:37:27.874576 2026] [security2:error] [pid 966386:tid 966599] [client 34.73.38.214:57831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WhzrLBqY1mBmWu_b5zAAAACU"]
[Mon Jul 20 06:37:27.917334 2026] [security2:error] [pid 966386:tid 966681] [client 217.142.18.172:4226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WhzrLBqY1mBmWu_b50QAAAHQ"]
[Mon Jul 20 06:37:27.929077 2026] [security2:error] [pid 966386:tid 966681] [client 217.142.18.172:4226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WhzrLBqY1mBmWu_b50QAAAHQ"]
[Mon Jul 20 06:37:28.054078 2026] [security2:error] [pid 966386:tid 966657] [client 161.118.195.148:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WiDrLBqY1mBmWu_b52gAAAF8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:28.070314 2026] [security2:error] [pid 966386:tid 966672] [client 14.225.17.146:50827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4WhjrLBqY1mBmWu_b5ZwAAAGs"], referer: http://transparentservices.online/OLD
[Mon Jul 20 06:37:28.233404 2026] [security2:error] [pid 966386:tid 966678] [client 39.48.81.23:64458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b55wAAAHE"]
[Mon Jul 20 06:37:28.233503 2026] [security2:error] [pid 966386:tid 966678] [client 39.48.81.23:64458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b55wAAAHE"]
[Mon Jul 20 06:37:28.238397 2026] [security2:error] [pid 966386:tid 966683] [client 197.186.66.42:58365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b56gAAAHY"]
[Mon Jul 20 06:37:28.249415 2026] [security2:error] [pid 966386:tid 966683] [client 197.186.66.42:58365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b56gAAAHY"]
[Mon Jul 20 06:37:28.650091 2026] [security2:error] [pid 953991:tid 954212] [client 161.118.195.148:54081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WiK_X-kAXGDrIFafT_QAAAOA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:28.668723 2026] [security2:error] [pid 966386:tid 966628] [client 171.60.139.123:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b5_gAAAEI"]
[Mon Jul 20 06:37:28.668925 2026] [security2:error] [pid 966386:tid 966628] [client 171.60.139.123:58496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b5_gAAAEI"]
[Mon Jul 20 06:37:28.757991 2026] [security2:error] [pid 966386:tid 966676] [client 34.73.38.214:61186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WiDrLBqY1mBmWu_b6AQAAAG8"]
[Mon Jul 20 06:37:28.847361 2026] [security2:error] [pid 966386:tid 966596] [client 34.74.185.202:60885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.supportinghands22.org"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WiDrLBqY1mBmWu_b6BAAAACI"]
[Mon Jul 20 06:37:28.868049 2026] [security2:error] [pid 966386:tid 966586] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omrobuildingcenter.com"] [uri "/index.php"] [unique_id "al4WiDrLBqY1mBmWu_b5_AAAABg"]
[Mon Jul 20 06:37:28.958728 2026] [security2:error] [pid 966386:tid 966633] [client 103.125.179.95:64543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b6EQAAAEc"]
[Mon Jul 20 06:37:28.958846 2026] [security2:error] [pid 966386:tid 966633] [client 103.125.179.95:64543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WiDrLBqY1mBmWu_b6EQAAAEc"]
[Mon Jul 20 06:37:29.187795 2026] [security2:error] [pid 953991:tid 954204] [client 77.110.127.138:51319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wia_X-kAXGDrIFafUAwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:29.187893 2026] [security2:error] [pid 953991:tid 954204] [client 77.110.127.138:51319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wia_X-kAXGDrIFafUAwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:29.231800 2026] [security2:error] [pid 966386:tid 966603] [client 161.118.195.148:54483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WiTrLBqY1mBmWu_b6JAAAACk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:29.276440 2026] [security2:error] [pid 966386:tid 966589] [client 34.73.38.214:65374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WiTrLBqY1mBmWu_b6JwAAABs"]
[Mon Jul 20 06:37:29.340966 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:51321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WiTrLBqY1mBmWu_b6LwAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:29.341078 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:51321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WiTrLBqY1mBmWu_b6LwAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:29.512634 2026] [security2:error] [pid 966386:tid 966606] [client 14.225.17.146:63213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4WiTrLBqY1mBmWu_b6LQAAACw"], referer: http://adirondackengineering.com/OLD
[Mon Jul 20 06:37:29.552908 2026] [security2:error] [pid 966386:tid 966651] [client 77.110.127.138:51323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WiTrLBqY1mBmWu_b6QQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:29.553016 2026] [security2:error] [pid 966386:tid 966651] [client 77.110.127.138:51323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WiTrLBqY1mBmWu_b6QQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:29.737457 2026] [security2:error] [pid 953991:tid 954129] [client 104.234.53.58:46893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Wia_X-kAXGDrIFafUDQAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:29.807094 2026] [security2:error] [pid 966386:tid 966655] [client 161.118.195.148:54877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WiTrLBqY1mBmWu_b6TgAAAF0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:30.050279 2026] [security2:error] [pid 953991:tid 954127] [client 104.234.53.58:46893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Wiq_X-kAXGDrIFafUGwAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:30.054483 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:51324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WijrLBqY1mBmWu_b6WQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.054582 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:51324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WijrLBqY1mBmWu_b6WQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.095902 2026] [security2:error] [pid 966386:tid 966442] [remote 202.51.202.242:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WijrLBqY1mBmWu_b6WwAAVw8"]
[Mon Jul 20 06:37:30.129834 2026] [security2:error] [pid 966386:tid 966569] [client 34.73.38.214:57650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WijrLBqY1mBmWu_b6YQAAAAc"]
[Mon Jul 20 06:37:30.235518 2026] [security2:error] [pid 953991:tid 954214] [client 77.110.127.138:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wiq_X-kAXGDrIFafUJwAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.235637 2026] [security2:error] [pid 953991:tid 954214] [client 77.110.127.138:51301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wiq_X-kAXGDrIFafUJwAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.293009 2026] [security2:error] [pid 966386:tid 966673] [client 77.110.127.138:51303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WijrLBqY1mBmWu_b6bwAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.293178 2026] [security2:error] [pid 966386:tid 966673] [client 77.110.127.138:51303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WijrLBqY1mBmWu_b6bwAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.332240 2026] [security2:error] [pid 966386:tid 966676] [client 216.73.217.138:46867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WijrLBqY1mBmWu_b6awAAb2c"]
[Mon Jul 20 06:37:30.335828 2026] [security2:error] [pid 966386:tid 966676] [client 216.73.217.138:46867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WijrLBqY1mBmWu_b6bAAAb2k"]
[Mon Jul 20 06:37:30.343876 2026] [security2:error] [pid 966386:tid 966685] [client 77.110.127.138:51302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WijrLBqY1mBmWu_b6cgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.343997 2026] [security2:error] [pid 966386:tid 966685] [client 77.110.127.138:51302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WijrLBqY1mBmWu_b6cgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:30.402105 2026] [security2:error] [pid 966386:tid 966620] [client 161.118.195.148:55284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WijrLBqY1mBmWu_b6dwAAADo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:30.942884 2026] [security2:error] [pid 966386:tid 966600] [client 34.73.38.214:51092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WijrLBqY1mBmWu_b6igAAACY"]
[Mon Jul 20 06:37:30.943702 2026] [security2:error] [pid 953991:tid 954189] [client 152.58.191.29:57115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Wiq_X-kAXGDrIFafUMgAAAMk"]
[Mon Jul 20 06:37:30.976239 2026] [security2:error] [pid 966386:tid 966598] [client 14.225.17.146:63716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4WiTrLBqY1mBmWu_b6RAAAACQ"], referer: http://colinkeyphotography.com/OLD
[Mon Jul 20 06:37:31.001403 2026] [security2:error] [pid 953991:tid 954244] [client 161.118.195.148:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wi6_X-kAXGDrIFafUOQAAAQA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:31.002743 2026] [security2:error] [pid 966386:tid 966625] [client 106.219.188.178:47754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WizrLBqY1mBmWu_b6jQAAAD8"]
[Mon Jul 20 06:37:31.004241 2026] [security2:error] [pid 966386:tid 966625] [client 106.219.188.178:47754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WizrLBqY1mBmWu_b6jQAAAD8"]
[Mon Jul 20 06:37:31.024531 2026] [security2:error] [pid 966386:tid 966585] [client 14.225.17.146:63928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4WiTrLBqY1mBmWu_b6EwAAABc"], referer: http://www.justinagrayman.com/OLD
[Mon Jul 20 06:37:31.161248 2026] [security2:error] [pid 966386:tid 966668] [client 57.141.18.121:51750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WhjrLBqY1mBmWu_b5XwAAaD8"]
[Mon Jul 20 06:37:31.183974 2026] [security2:error] [pid 966386:tid 966575] [client 74.208.214.194:50660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WizrLBqY1mBmWu_b6mQAAAA0"]
[Mon Jul 20 06:37:31.241853 2026] [security2:error] [pid 966386:tid 966676] [client 34.73.38.214:51723] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tco.chi.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WizrLBqY1mBmWu_b6nQAAAG8"]
[Mon Jul 20 06:37:31.428613 2026] [security2:error] [pid 966386:tid 966651] [client 13.38.91.115:20052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.91.38.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WizrLBqY1mBmWu_b6pgAAAFk"]
[Mon Jul 20 06:37:31.428719 2026] [security2:error] [pid 966386:tid 966651] [client 13.38.91.115:20052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WizrLBqY1mBmWu_b6pgAAAFk"]
[Mon Jul 20 06:37:31.575421 2026] [security2:error] [pid 966386:tid 966588] [client 161.118.195.148:56132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WizrLBqY1mBmWu_b6tAAAABo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:31.586926 2026] [security2:error] [pid 966386:tid 966598] [client 77.110.127.138:51312] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WizrLBqY1mBmWu_b6tQAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:31.614272 2026] [security2:error] [pid 953991:tid 954204] [client 104.207.63.68:52893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Wi6_X-kAXGDrIFafUSAAAANg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:31.649403 2026] [security2:error] [pid 966386:tid 966623] [client 114.119.148.163:28241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/how-long-does-a-bottle-of-thieves-foaming-hand-soap-last/"] [unique_id "al4WizrLBqY1mBmWu_b6twAAAD0"], referer: https://www.thewelloiledlife.com/why-thieves-spray-is-a-must-have-for-the-hotel-room/
[Mon Jul 20 06:37:31.814446 2026] [security2:error] [pid 966386:tid 966622] [client 34.73.38.214:64288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WizrLBqY1mBmWu_b6yAAAADw"]
[Mon Jul 20 06:37:31.875979 2026] [security2:error] [pid 966386:tid 966481] [remote 202.51.202.242:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WizrLBqY1mBmWu_b6zAAAYjM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:37:31.883914 2026] [security2:error] [pid 966386:tid 966618] [client 57.141.18.22:27186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WhjrLBqY1mBmWu_b5fAAAOEI"]
[Mon Jul 20 06:37:32.151615 2026] [security2:error] [pid 953991:tid 954215] [client 161.118.195.148:56501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WjK_X-kAXGDrIFafUVgAAAOM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:32.228590 2026] [lsapi:warn] [pid 966386:tid 966577] [client 14.225.17.146:63516] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/OLD
[Mon Jul 20 06:37:32.228617 2026] [lsapi:warn] [pid 966386:tid 966577] [client 14.225.17.146:63516] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/OLD
[Mon Jul 20 06:37:32.369729 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:51313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WjK_X-kAXGDrIFafUXAAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:32.369830 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:51313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WjK_X-kAXGDrIFafUXAAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:32.536888 2026] [security2:error] [pid 953991:tid 954200] [client 65.111.20.218:11293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WjK_X-kAXGDrIFafUYgAAANQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:32.713641 2026] [lsapi:warn] [pid 953991:tid 954158] [client 50.116.65.227:35318] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:37:32.713669 2026] [lsapi:warn] [pid 953991:tid 954158] [client 50.116.65.227:35318] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:37:32.725370 2026] [security2:error] [pid 953991:tid 954220] [client 161.118.195.148:56905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WjK_X-kAXGDrIFafUawAAAOg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:32.727601 2026] [security2:error] [pid 966386:tid 966577] [client 14.225.17.146:63516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4WizrLBqY1mBmWu_b6vQAAAA8"], referer: http://oswegooperatheater.com/OLD
[Mon Jul 20 06:37:32.808984 2026] [security2:error] [pid 953991:tid 954230] [client 187.108.85.186:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WjK_X-kAXGDrIFafUbQAAAPI"]
[Mon Jul 20 06:37:32.809107 2026] [security2:error] [pid 953991:tid 954230] [client 187.108.85.186:62807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WjK_X-kAXGDrIFafUbQAAAPI"]
[Mon Jul 20 06:37:32.897851 2026] [security2:error] [pid 966386:tid 966659] [client 34.73.38.214:62235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WjDrLBqY1mBmWu_b7BQAAAGA"]
[Mon Jul 20 06:37:32.928785 2026] [security2:error] [pid 966386:tid 966572] [client 192.236.168.43:50518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "ancestralidadytrance.space"] [uri "/"] [unique_id "al4WjDrLBqY1mBmWu_b7CAAAAAo"]
[Mon Jul 20 06:37:32.980276 2026] [security2:error] [pid 966386:tid 966445] [remote 217.61.143.92:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4WjDrLBqY1mBmWu_b7CwAAeRI"]
[Mon Jul 20 06:37:33.047969 2026] [security2:error] [pid 953991:tid 954113] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Wja_X-kAXGDrIFafUdgAA33k"]
[Mon Jul 20 06:37:33.048096 2026] [security2:error] [pid 953991:tid 954211] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Wja_X-kAXGDrIFafUdgAA33k"]
[Mon Jul 20 06:37:33.204110 2026] [security2:error] [pid 966386:tid 966513] [remote 217.61.143.92:43146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4WjTrLBqY1mBmWu_b7EwAAJlM"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:37:33.326076 2026] [security2:error] [pid 966386:tid 966663] [client 161.118.195.148:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WjTrLBqY1mBmWu_b7HwAAAGQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:33.344090 2026] [security2:error] [pid 953991:tid 954133] [client 57.141.18.40:48778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WiK_X-kAXGDrIFafT6QAAkQM"]
[Mon Jul 20 06:37:33.354335 2026] [security2:error] [pid 966386:tid 966614] [client 104.207.32.236:28009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WjTrLBqY1mBmWu_b7IQAAADQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:33.637729 2026] [security2:error] [pid 966386:tid 966653] [client 46.110.96.34:61737] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4WjTrLBqY1mBmWu_b7MQAAAFs"]
[Mon Jul 20 06:37:33.637732 2026] [security2:error] [pid 966386:tid 966662] [client 46.110.96.34:38206] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4WjTrLBqY1mBmWu_b7MgAAAGM"]
[Mon Jul 20 06:37:33.647402 2026] [security2:error] [pid 953991:tid 954227] [client 34.73.38.214:53294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Wja_X-kAXGDrIFafUfgAAAO8"]
[Mon Jul 20 06:37:33.774823 2026] [lsapi:warn] [pid 966386:tid 966681] [client 14.225.17.146:56463] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/OLD
[Mon Jul 20 06:37:33.774845 2026] [lsapi:warn] [pid 966386:tid 966681] [client 14.225.17.146:56463] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/OLD
[Mon Jul 20 06:37:33.834929 2026] [security2:error] [pid 966386:tid 966681] [client 14.225.17.146:56463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4WjTrLBqY1mBmWu_b7OwAAAHQ"], referer: https://oswegooperatheater.com/OLD
[Mon Jul 20 06:37:33.905498 2026] [security2:error] [pid 966386:tid 966685] [client 161.118.195.148:57663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WjTrLBqY1mBmWu_b7RgAAAHg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:34.036194 2026] [proxy:error] [pid 966386:tid 966670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:34.036266 2026] [proxy_http:error] [pid 966386:tid 966670] [client 34.73.38.214:57387] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:34.036688 2026] [proxy:error] [pid 966386:tid 966670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:34.036713 2026] [proxy_http:error] [pid 966386:tid 966670] [client 34.73.38.214:57387] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:34.201549 2026] [security2:error] [pid 966386:tid 966581] [client 14.225.17.146:56419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4WjDrLBqY1mBmWu_b7DQAAABM"], referer: http://christiancountytrumpet.com/OLD
[Mon Jul 20 06:37:34.291342 2026] [security2:error] [pid 953991:tid 954079] [remote 167.233.114.32:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Wjq_X-kAXGDrIFafUlwAAplc"]
[Mon Jul 20 06:37:34.436453 2026] [security2:error] [pid 966386:tid 966566] [client 104.234.53.63:59849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WjjrLBqY1mBmWu_b7XgAAAAQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:34.447612 2026] [security2:error] [pid 966386:tid 966677] [client 14.225.17.146:56659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4WjTrLBqY1mBmWu_b7QgAAAHA"]
[Mon Jul 20 06:37:34.479300 2026] [security2:error] [pid 966386:tid 966601] [client 161.118.195.148:58028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WjjrLBqY1mBmWu_b7ZgAAACc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:34.492006 2026] [security2:error] [pid 966386:tid 966540] [remote 81.173.115.7:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WjjrLBqY1mBmWu_b7aQAAAG4"]
[Mon Jul 20 06:37:34.512155 2026] [security2:error] [pid 953991:tid 954003] [remote 167.233.114.32:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Wjq_X-kAXGDrIFafUoQAA8As"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:37:34.582233 2026] [security2:error] [pid 966386:tid 966567] [client 216.73.217.138:21461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WjjrLBqY1mBmWu_b7aAAABWs"]
[Mon Jul 20 06:37:34.704922 2026] [security2:error] [pid 966386:tid 966449] [remote 81.173.115.7:54596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WjjrLBqY1mBmWu_b7cwAAaRY"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:37:34.794229 2026] [security2:error] [pid 966386:tid 966646] [client 216.73.217.138:21461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WjjrLBqY1mBmWu_b7cgAAVGA"]
[Mon Jul 20 06:37:34.816068 2026] [security2:error] [pid 966386:tid 966583] [client 104.207.54.116:43703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WjjrLBqY1mBmWu_b7dQAAABU"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:34.996649 2026] [security2:error] [pid 966386:tid 966538] [remote 5.252.52.249:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4WjjrLBqY1mBmWu_b7gwAALmw"]
[Mon Jul 20 06:37:35.043764 2026] [security2:error] [pid 953991:tid 954140] [client 57.141.18.33:39096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wia_X-kAXGDrIFafUFQAAmFQ"]
[Mon Jul 20 06:37:35.052392 2026] [security2:error] [pid 966386:tid 966616] [client 161.118.195.148:58394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WjzrLBqY1mBmWu_b7hgAAADY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:35.179212 2026] [security2:error] [pid 966386:tid 966548] [remote 5.252.52.249:57350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4WjzrLBqY1mBmWu_b7kQAAdXY"], referer: https://mail.holistichealthmassagenz.com/wp-login.php
[Mon Jul 20 06:37:35.233471 2026] [security2:error] [pid 953991:tid 954143] [client 14.225.17.146:56589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Wja_X-kAXGDrIFafUjgAAAJs"], referer: http://iagdevelopments.com/OLD
[Mon Jul 20 06:37:35.275512 2026] [security2:error] [pid 966386:tid 966649] [client 50.116.65.227:35380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WjzrLBqY1mBmWu_b7mQAAAFc"]
[Mon Jul 20 06:37:35.285677 2026] [security2:error] [pid 966386:tid 966641] [client 50.116.65.227:35390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WjzrLBqY1mBmWu_b7mgAAAE8"]
[Mon Jul 20 06:37:35.355991 2026] [security2:error] [pid 966386:tid 966586] [client 14.225.17.146:56249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4WjzrLBqY1mBmWu_b7jQAAABg"], referer: http://recruitinginsight.us/OLD
[Mon Jul 20 06:37:35.367939 2026] [security2:error] [pid 953991:tid 954134] [client 34.73.38.214:59199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Wj6_X-kAXGDrIFafUwQAAAJI"]
[Mon Jul 20 06:37:35.462656 2026] [security2:error] [pid 966386:tid 966623] [client 50.116.65.227:35362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4WjjrLBqY1mBmWu_b7ggAAAD0"]
[Mon Jul 20 06:37:35.641262 2026] [security2:error] [pid 966386:tid 966635] [client 161.118.195.148:58777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WjzrLBqY1mBmWu_b7rwAAAEk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:35.753903 2026] [security2:error] [pid 966386:tid 966660] [client 45.3.46.180:19425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WjzrLBqY1mBmWu_b7tgAAAGE"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:35.787952 2026] [security2:error] [pid 966386:tid 966676] [client 77.110.127.138:51347] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WjzrLBqY1mBmWu_b7uQAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:35.946895 2026] [security2:error] [pid 966386:tid 966604] [client 50.116.65.227:35392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4WjzrLBqY1mBmWu_b7qgAAACo"]
[Mon Jul 20 06:37:36.009721 2026] [security2:error] [pid 953991:tid 954232] [client 103.238.106.162:60631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WkK_X-kAXGDrIFafU2QAAAPQ"]
[Mon Jul 20 06:37:36.009838 2026] [security2:error] [pid 953991:tid 954232] [client 103.238.106.162:60631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WkK_X-kAXGDrIFafU2QAAAPQ"]
[Mon Jul 20 06:37:36.215295 2026] [security2:error] [pid 966386:tid 966560] [client 161.118.195.148:59165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WkDrLBqY1mBmWu_b7zAAAAAA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:36.313469 2026] [security2:error] [pid 966386:tid 966638] [client 14.225.17.146:60119] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4WkDrLBqY1mBmWu_b7zgAAAEw"], referer: https://iagdevelopments.com/OLD
[Mon Jul 20 06:37:36.375911 2026] [proxy:error] [pid 966386:tid 966690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:36.376002 2026] [proxy_http:error] [pid 966386:tid 966690] [client 34.73.38.214:64540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:36.376624 2026] [proxy:error] [pid 966386:tid 966690] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:36.376654 2026] [proxy_http:error] [pid 966386:tid 966690] [client 34.73.38.214:64540] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:36.447607 2026] [access_compat:error] [pid 966386:tid 966605] [client 54.166.194.245:48308] AH01797: client denied by server configuration: /home4/curlsnp2/public_html/server-status
[Mon Jul 20 06:37:36.607694 2026] [security2:error] [pid 966386:tid 966612] [client 171.61.165.146:32234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WkDrLBqY1mBmWu_b77AAAADI"]
[Mon Jul 20 06:37:36.608568 2026] [security2:error] [pid 966386:tid 966612] [client 171.61.165.146:32234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WkDrLBqY1mBmWu_b77AAAADI"]
[Mon Jul 20 06:37:36.649827 2026] [security2:error] [pid 966386:tid 966608] [client 34.73.38.214:54376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WkDrLBqY1mBmWu_b77QAAAC4"]
[Mon Jul 20 06:37:36.707104 2026] [security2:error] [pid 966386:tid 966578] [client 57.141.18.32:46106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WizrLBqY1mBmWu_b6sAAAEAw"]
[Mon Jul 20 06:37:36.792240 2026] [security2:error] [pid 953991:tid 954140] [client 161.118.195.148:59551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WkK_X-kAXGDrIFafU6wAAAJg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:37.130908 2026] [security2:error] [pid 953991:tid 954169] [client 77.110.127.138:51357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wka_X-kAXGDrIFafU-QAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:37.131009 2026] [security2:error] [pid 953991:tid 954169] [client 77.110.127.138:51357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wka_X-kAXGDrIFafU-QAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:37.151577 2026] [proxy:error] [pid 966386:tid 966584] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:37.151656 2026] [proxy_http:error] [pid 966386:tid 966584] [client 34.73.38.214:60333] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:37.152892 2026] [proxy:error] [pid 966386:tid 966584] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:37.152924 2026] [proxy_http:error] [pid 966386:tid 966584] [client 34.73.38.214:60333] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:37.163293 2026] [security2:error] [pid 966386:tid 966660] [client 14.225.17.146:56328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4WkDrLBqY1mBmWu_b78gAAAGE"], referer: http://hilltopnurseryinc.com/OLD
[Mon Jul 20 06:37:37.377407 2026] [security2:error] [pid 953991:tid 954132] [client 161.118.195.148:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wka_X-kAXGDrIFafVAwAAAJA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:37.527329 2026] [security2:error] [pid 966386:tid 966572] [client 65.21.237.125:0] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "origine.nz"] [uri "/wp-content/uploads/2025/06/dinner-square-150x150.webp"] [unique_id "al4WkTrLBqY1mBmWu_b8FAAACmU"], referer: https://origine.nz/menu/
[Mon Jul 20 06:37:37.549705 2026] [security2:error] [pid 953991:tid 954136] [client 45.157.112.60:34225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Wka_X-kAXGDrIFafVCwAAAJQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:37:37.712733 2026] [security2:error] [pid 966386:tid 966684] [client 112.208.70.94:43264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WkTrLBqY1mBmWu_b8HgAAAHc"]
[Mon Jul 20 06:37:37.712858 2026] [security2:error] [pid 966386:tid 966684] [client 112.208.70.94:43264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WkTrLBqY1mBmWu_b8HgAAAHc"]
[Mon Jul 20 06:37:37.886969 2026] [security2:error] [pid 953991:tid 954128] [client 57.141.18.83:55212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WjK_X-kAXGDrIFafUZgAAjFM"]
[Mon Jul 20 06:37:37.959350 2026] [security2:error] [pid 953991:tid 954222] [client 161.118.195.148:60401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wka_X-kAXGDrIFafVGgAAAOo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:38.007170 2026] [security2:error] [pid 966386:tid 966624] [client 57.141.18.50:49568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WjDrLBqY1mBmWu_b7AAAAPkU"]
[Mon Jul 20 06:37:38.098934 2026] [security2:error] [pid 966386:tid 966649] [client 34.73.38.214:61100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WkjrLBqY1mBmWu_b8KgAAAFc"]
[Mon Jul 20 06:37:38.184821 2026] [security2:error] [pid 953991:tid 954157] [client 146.174.172.100:41714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wkq_X-kAXGDrIFafVIwAAAKk"]
[Mon Jul 20 06:37:38.191076 2026] [security2:error] [pid 966386:tid 966691] [client 57.141.18.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4WkTrLBqY1mBmWu_b8JQAAAH4"]
[Mon Jul 20 06:37:38.288226 2026] [security2:error] [pid 953991:tid 954194] [client 223.185.13.213:30890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVKQAAAM4"]
[Mon Jul 20 06:37:38.288384 2026] [security2:error] [pid 953991:tid 954194] [client 223.185.13.213:30890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVKQAAAM4"]
[Mon Jul 20 06:37:38.362771 2026] [security2:error] [pid 953991:tid 954177] [client 14.225.17.146:62451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4Wka_X-kAXGDrIFafU9QAAAL0"], referer: http://hammadownenterprises.com/OLD
[Mon Jul 20 06:37:38.432904 2026] [proxy:error] [pid 953991:tid 954170] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:38.433002 2026] [proxy_http:error] [pid 953991:tid 954170] [client 34.73.38.214:60523] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:38.433737 2026] [proxy:error] [pid 953991:tid 954170] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:38.433786 2026] [proxy_http:error] [pid 953991:tid 954170] [client 34.73.38.214:60523] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:38.458940 2026] [security2:error] [pid 953991:tid 954193] [client 39.48.81.23:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVLgAAAM0"]
[Mon Jul 20 06:37:38.459136 2026] [security2:error] [pid 953991:tid 954193] [client 39.48.81.23:64977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVLgAAAM0"]
[Mon Jul 20 06:37:38.525745 2026] [security2:error] [pid 953991:tid 954227] [client 217.142.18.172:32524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVNgAAAO8"]
[Mon Jul 20 06:37:38.529064 2026] [security2:error] [pid 953991:tid 954227] [client 217.142.18.172:32524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVNgAAAO8"]
[Mon Jul 20 06:37:38.540438 2026] [security2:error] [pid 953991:tid 954229] [client 161.118.195.148:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wkq_X-kAXGDrIFafVNwAAAPE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:38.568881 2026] [security2:error] [pid 966386:tid 966603] [client 57.141.18.68:39874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WjTrLBqY1mBmWu_b7EQAAKVI"]
[Mon Jul 20 06:37:38.731556 2026] [security2:error] [pid 953991:tid 954138] [client 173.252.70.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4Wkq_X-kAXGDrIFafVOQAAAJY"]
[Mon Jul 20 06:37:38.805233 2026] [security2:error] [pid 966386:tid 966637] [client 14.225.17.146:62302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4WkTrLBqY1mBmWu_b8EQAAAEs"], referer: http://mazzucelli.com/OLD
[Mon Jul 20 06:37:38.857115 2026] [security2:error] [pid 953991:tid 954172] [client 34.73.38.214:55808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.thepauze.com"] [uri "/xmlrpc.php"] [unique_id "al4Wkq_X-kAXGDrIFafVQQAAALg"]
[Mon Jul 20 06:37:39.018919 2026] [security2:error] [pid 966386:tid 966652] [client 197.186.66.42:58884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WkzrLBqY1mBmWu_b8VAAAAFo"]
[Mon Jul 20 06:37:39.019022 2026] [security2:error] [pid 966386:tid 966652] [client 197.186.66.42:58884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WkzrLBqY1mBmWu_b8VAAAAFo"]
[Mon Jul 20 06:37:39.115087 2026] [security2:error] [pid 953991:tid 954245] [client 161.118.195.148:61216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wk6_X-kAXGDrIFafVTQAAAQE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:39.306958 2026] [security2:error] [pid 966386:tid 966564] [client 171.60.139.123:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WkzrLBqY1mBmWu_b8ZwAAAAM"]
[Mon Jul 20 06:37:39.307096 2026] [security2:error] [pid 966386:tid 966564] [client 171.60.139.123:59012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WkzrLBqY1mBmWu_b8ZwAAAAM"]
[Mon Jul 20 06:37:39.485808 2026] [security2:error] [pid 953991:tid 954158] [client 14.225.17.146:62529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4Wka_X-kAXGDrIFafVFgAAAKo"], referer: http://aandarealtygroup.com/OLD
[Mon Jul 20 06:37:39.651730 2026] [security2:error] [pid 966386:tid 966691] [client 14.225.17.146:59963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4WkzrLBqY1mBmWu_b8dgAAAH4"], referer: http://mtlegnews.gov/OLD
[Mon Jul 20 06:37:39.661552 2026] [security2:error] [pid 966386:tid 966516] [remote 95.217.78.234:53768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WkzrLBqY1mBmWu_b8fgAAfVY"]
[Mon Jul 20 06:37:39.661731 2026] [security2:error] [pid 966386:tid 966690] [client 95.217.78.234:53768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WkzrLBqY1mBmWu_b8fgAAfVY"]
[Mon Jul 20 06:37:39.688315 2026] [security2:error] [pid 953991:tid 954196] [client 161.118.195.148:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wk6_X-kAXGDrIFafVYAAAANA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:39.894869 2026] [security2:error] [pid 966386:tid 966605] [client 14.225.17.146:62457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4WkTrLBqY1mBmWu_b8HQAAACs"], referer: http://latiendadejorge.com.gt/OLD
[Mon Jul 20 06:37:39.907802 2026] [security2:error] [pid 966386:tid 966574] [client 138.68.143.180:53788] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "staging.joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4WkzrLBqY1mBmWu_b8hwAAAAw"]
[Mon Jul 20 06:37:40.043133 2026] [security2:error] [pid 953991:tid 954165] [client 57.141.18.9:61468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wjq_X-kAXGDrIFafUoAAAsQE"]
[Mon Jul 20 06:37:40.151923 2026] [security2:error] [pid 966386:tid 966624] [client 77.110.127.138:51372] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WlDrLBqY1mBmWu_b8lAAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:40.259094 2026] [security2:error] [pid 966386:tid 966564] [client 34.73.38.214:55504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WlDrLBqY1mBmWu_b8lwAAAAM"]
[Mon Jul 20 06:37:40.268862 2026] [security2:error] [pid 966386:tid 966571] [client 161.118.195.148:62099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WlDrLBqY1mBmWu_b8mgAAAAk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:40.368579 2026] [security2:error] [pid 953991:tid 954127] [client 104.234.53.68:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WlK_X-kAXGDrIFafVbAAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:40.608622 2026] [proxy:error] [pid 953991:tid 954218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:40.608695 2026] [proxy_http:error] [pid 953991:tid 954218] [client 34.73.38.214:64375] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:40.609246 2026] [proxy:error] [pid 953991:tid 954218] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:40.609284 2026] [proxy_http:error] [pid 953991:tid 954218] [client 34.73.38.214:64375] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:40.697948 2026] [security2:error] [pid 953991:tid 954178] [client 14.225.17.146:62510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4Wk6_X-kAXGDrIFafVTAAAAL4"], referer: http://myspineworld.com/OLD
[Mon Jul 20 06:37:40.809555 2026] [security2:error] [pid 966386:tid 966596] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4WlDrLBqY1mBmWu_b8qAAAACI"]
[Mon Jul 20 06:37:40.852303 2026] [security2:error] [pid 966386:tid 966600] [client 161.118.195.148:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WlDrLBqY1mBmWu_b8vwAAACY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:40.886307 2026] [security2:error] [pid 966386:tid 966591] [client 34.73.38.214:49640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WlDrLBqY1mBmWu_b8wQAAAB0"]
[Mon Jul 20 06:37:41.388896 2026] [security2:error] [pid 966386:tid 966449] [remote 162.19.86.63:38488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WlTrLBqY1mBmWu_b81QAAAxY"]
[Mon Jul 20 06:37:41.389060 2026] [security2:error] [pid 966386:tid 966564] [client 162.19.86.63:38488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WlTrLBqY1mBmWu_b81QAAAxY"]
[Mon Jul 20 06:37:41.444296 2026] [security2:error] [pid 953991:tid 954219] [client 161.118.195.148:62969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wla_X-kAXGDrIFafVggAAAOc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:41.533065 2026] [security2:error] [pid 953991:tid 954241] [client 77.110.127.138:51381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wla_X-kAXGDrIFafVhAAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:41.533156 2026] [security2:error] [pid 953991:tid 954241] [client 77.110.127.138:51381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wla_X-kAXGDrIFafVhAAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:41.693219 2026] [security2:error] [pid 953991:tid 954142] [client 14.225.17.146:63222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Wla_X-kAXGDrIFafVhQAAAJo"], referer: https://myspineworld.com/OLD
[Mon Jul 20 06:37:42.026722 2026] [security2:error] [pid 966386:tid 966657] [client 161.118.195.148:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WljrLBqY1mBmWu_b8_QAAAF8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:42.135778 2026] [security2:error] [pid 953991:tid 954133] [client 57.141.18.22:27210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WkK_X-kAXGDrIFafU4wAAkWM"]
[Mon Jul 20 06:37:42.171681 2026] [security2:error] [pid 966386:tid 966628] [client 152.58.191.29:58147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WljrLBqY1mBmWu_b8_gAAAEI"]
[Mon Jul 20 06:37:42.276496 2026] [security2:error] [pid 953991:tid 954160] [client 192.236.168.43:52676] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.ancestralidadytrance.space"] [uri "/"] [unique_id "al4Wlq_X-kAXGDrIFafVmgAAAKw"]
[Mon Jul 20 06:37:42.493759 2026] [security2:error] [pid 953991:tid 954215] [client 57.141.18.22:24630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WkK_X-kAXGDrIFafU8QAA4yA"]
[Mon Jul 20 06:37:42.604017 2026] [security2:error] [pid 966386:tid 966643] [client 161.118.195.148:63771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WljrLBqY1mBmWu_b9GAAAAFE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:42.758547 2026] [security2:error] [pid 966386:tid 966631] [client 34.73.38.214:57935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WljrLBqY1mBmWu_b9HwAAAEU"]
[Mon Jul 20 06:37:42.938701 2026] [security2:error] [pid 966386:tid 966452] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WljrLBqY1mBmWu_b9KAAAERk"]
[Mon Jul 20 06:37:42.938827 2026] [security2:error] [pid 966386:tid 966579] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WljrLBqY1mBmWu_b9KAAAERk"]
[Mon Jul 20 06:37:43.016382 2026] [security2:error] [pid 966386:tid 966567] [client 14.225.17.146:62545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4WljrLBqY1mBmWu_b9IwAAAAU"], referer: http://mobilesurvsolutions.com/OLD
[Mon Jul 20 06:37:43.058084 2026] [proxy:error] [pid 953991:tid 954188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:43.058174 2026] [proxy_http:error] [pid 953991:tid 954188] [client 34.73.38.214:54880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:43.059440 2026] [proxy:error] [pid 953991:tid 954188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:37:43.059476 2026] [proxy_http:error] [pid 953991:tid 954188] [client 34.73.38.214:54880] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:37:43.172882 2026] [security2:error] [pid 953991:tid 954131] [client 57.141.18.77:25022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wka_X-kAXGDrIFafVCAAAj24"]
[Mon Jul 20 06:37:43.180539 2026] [security2:error] [pid 953991:tid 954195] [client 161.118.195.148:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wl6_X-kAXGDrIFafVuAAAAM8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:43.244459 2026] [security2:error] [pid 953991:tid 954220] [client 65.21.237.125:0] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "origine.nz"] [uri "/wp-content/uploads/2025/06/dinner-square-100x100.webp"] [unique_id "al4Wl6_X-kAXGDrIFafVvgAA6CI"], referer: https://origine.nz/menu/
[Mon Jul 20 06:37:43.374668 2026] [security2:error] [pid 966386:tid 966585] [client 34.73.38.214:61343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WlzrLBqY1mBmWu_b9NgAAABc"]
[Mon Jul 20 06:37:43.424193 2026] [security2:error] [pid 953991:tid 954157] [client 187.108.85.186:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Wl6_X-kAXGDrIFafVzQAAAKk"]
[Mon Jul 20 06:37:43.424286 2026] [security2:error] [pid 953991:tid 954157] [client 187.108.85.186:63342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Wl6_X-kAXGDrIFafVzQAAAKk"]
[Mon Jul 20 06:37:43.772711 2026] [security2:error] [pid 966386:tid 966638] [client 161.118.195.148:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WlzrLBqY1mBmWu_b9RgAAAEw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:44.120108 2026] [security2:error] [pid 966386:tid 966626] [client 57.141.18.114:37124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WkjrLBqY1mBmWu_b8RgAAQB8"]
[Mon Jul 20 06:37:44.184221 2026] [security2:error] [pid 966386:tid 966676] [client 77.110.127.138:51398] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WmDrLBqY1mBmWu_b9WwAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:44.355274 2026] [security2:error] [pid 966386:tid 966570] [client 161.118.195.148:65088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WmDrLBqY1mBmWu_b9ZAAAAAg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:44.660299 2026] [security2:error] [pid 953991:tid 954204] [client 106.219.188.178:16471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WmK_X-kAXGDrIFafV-AAAANg"]
[Mon Jul 20 06:37:44.660467 2026] [security2:error] [pid 953991:tid 954204] [client 106.219.188.178:16471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WmK_X-kAXGDrIFafV-AAAANg"]
[Mon Jul 20 06:37:44.874059 2026] [security2:error] [pid 966386:tid 966484] [remote 103.28.36.200:38194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WmDrLBqY1mBmWu_b9jgAAXDY"]
[Mon Jul 20 06:37:44.883620 2026] [security2:error] [pid 953991:tid 954101] [remote 162.19.86.63:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WmK_X-kAXGDrIFafV-wAA620"]
[Mon Jul 20 06:37:44.909794 2026] [security2:error] [pid 966386:tid 966578] [client 3.90.176.61:56696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.curlsnpearlsss.com"] [uri "/.env"] [unique_id "al4WmDrLBqY1mBmWu_b9kwAAABA"]
[Mon Jul 20 06:37:44.929723 2026] [security2:error] [pid 966386:tid 966640] [client 161.118.195.148:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WmDrLBqY1mBmWu_b9lQAAAE4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:45.038124 2026] [security2:error] [pid 966386:tid 966652] [client 50.116.65.227:50238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WmTrLBqY1mBmWu_b9oQAAAFo"]
[Mon Jul 20 06:37:45.051013 2026] [security2:error] [pid 953991:tid 954240] [client 50.116.65.227:50242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Wma_X-kAXGDrIFafWAQAAAPw"]
[Mon Jul 20 06:37:45.080968 2026] [security2:error] [pid 953991:tid 954104] [remote 162.19.86.63:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Wma_X-kAXGDrIFafWAwAA-3A"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:37:45.108642 2026] [security2:error] [pid 966386:tid 966665] [client 57.141.18.83:55222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WkzrLBqY1mBmWu_b8egAAZlU"]
[Mon Jul 20 06:37:45.223104 2026] [security2:error] [pid 966386:tid 966657] [client 57.141.18.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4WmTrLBqY1mBmWu_b9owAAAF8"]
[Mon Jul 20 06:37:45.285929 2026] [security2:error] [pid 966386:tid 966487] [remote 103.28.36.200:38194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WmTrLBqY1mBmWu_b9rwAAeDk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:37:45.298891 2026] [security2:error] [pid 966386:tid 966456] [remote 182.77.62.24:33210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4WmTrLBqY1mBmWu_b9sAAAFh0"]
[Mon Jul 20 06:37:45.426778 2026] [security2:error] [pid 966386:tid 966654] [client 34.73.38.214:57950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.tff.hws.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WmTrLBqY1mBmWu_b9uAAAAFw"]
[Mon Jul 20 06:37:45.504062 2026] [security2:error] [pid 966386:tid 966653] [client 161.118.195.148:49550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WmTrLBqY1mBmWu_b9vgAAAFs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:45.551068 2026] [security2:error] [pid 966386:tid 966624] [client 34.73.38.214:55763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/xmlrpc.php"] [unique_id "al4WmTrLBqY1mBmWu_b9vwAAAD4"]
[Mon Jul 20 06:37:45.634922 2026] [security2:error] [pid 966386:tid 966580] [client 77.110.127.138:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WmTrLBqY1mBmWu_b9zQAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:45.635029 2026] [security2:error] [pid 966386:tid 966580] [client 77.110.127.138:51407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WmTrLBqY1mBmWu_b9zQAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:45.641280 2026] [security2:error] [pid 953991:tid 954049] [remote 209.42.18.223:55818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Wma_X-kAXGDrIFafWEgAAxTk"]
[Mon Jul 20 06:37:45.654791 2026] [security2:error] [pid 966386:tid 966660] [client 14.225.17.146:63219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4WlzrLBqY1mBmWu_b9PwAAAGE"], referer: http://itdynamix.com/OLD
[Mon Jul 20 06:37:45.774686 2026] [security2:error] [pid 966386:tid 966629] [client 34.73.38.214:54710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WmTrLBqY1mBmWu_b92QAAAEM"]
[Mon Jul 20 06:37:45.888466 2026] [security2:error] [pid 966386:tid 966517] [remote 182.77.62.24:33210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4WmTrLBqY1mBmWu_b94QAAQVc"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:37:45.940289 2026] [security2:error] [pid 953991:tid 954006] [remote 209.42.18.223:55818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Wma_X-kAXGDrIFafWGAAAvg4"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:37:45.947178 2026] [security2:error] [pid 966386:tid 966619] [client 14.225.17.146:62189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4WmDrLBqY1mBmWu_b9YQAAADk"], referer: http://careysheatingandcooling.com/OLD
[Mon Jul 20 06:37:46.081355 2026] [security2:error] [pid 966386:tid 966583] [client 161.118.195.148:50029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WmjrLBqY1mBmWu_b97QAAABU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:46.202381 2026] [security2:error] [pid 966386:tid 966643] [client 14.225.17.146:58314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4WmjrLBqY1mBmWu_b98AAAAFE"], referer: http://friendlyspreadsheet.com/OLD
[Mon Jul 20 06:37:46.458802 2026] [security2:error] [pid 966386:tid 966575] [client 14.182.195.220:52269] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4WmjrLBqY1mBmWu_b-AAAAAA0"]
[Mon Jul 20 06:37:46.560529 2026] [security2:error] [pid 966386:tid 966647] [client 103.238.106.162:63878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WmjrLBqY1mBmWu_b-BAAAAFU"]
[Mon Jul 20 06:37:46.560640 2026] [security2:error] [pid 966386:tid 966647] [client 103.238.106.162:63878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WmjrLBqY1mBmWu_b-BAAAAFU"]
[Mon Jul 20 06:37:46.578811 2026] [security2:error] [pid 953991:tid 954229] [client 34.74.185.202:58295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4Wmq_X-kAXGDrIFafWJQAAAPE"]
[Mon Jul 20 06:37:46.657406 2026] [security2:error] [pid 966386:tid 966564] [client 161.118.195.148:50457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WmjrLBqY1mBmWu_b-CgAAAAM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:46.667140 2026] [security2:error] [pid 966386:tid 966580] [client 14.225.17.146:49915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4WmjrLBqY1mBmWu_b-AwAAABI"], referer: https://itdynamix.com/OLD
[Mon Jul 20 06:37:46.728320 2026] [security2:error] [pid 966386:tid 966573] [client 223.237.130.40:60588] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WmjrLBqY1mBmWu_b-EQAAAAs"]
[Mon Jul 20 06:37:46.728449 2026] [security2:error] [pid 966386:tid 966573] [client 223.237.130.40:60588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WmjrLBqY1mBmWu_b-EQAAAAs"]
[Mon Jul 20 06:37:46.909674 2026] [security2:error] [pid 953991:tid 954132] [client 34.74.185.202:63262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Wmq_X-kAXGDrIFafWLAAAAJA"]
[Mon Jul 20 06:37:46.942963 2026] [security2:error] [pid 953991:tid 954245] [client 57.141.18.21:56068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wla_X-kAXGDrIFafVfQABAU8"]
[Mon Jul 20 06:37:47.054545 2026] [security2:error] [pid 953991:tid 954115] [remote 84.247.172.23:48440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4Wm6_X-kAXGDrIFafWOwAA-ns"]
[Mon Jul 20 06:37:47.068031 2026] [security2:error] [pid 953991:tid 954208] [client 50.116.65.227:50314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Wm6_X-kAXGDrIFafWPAAAANw"]
[Mon Jul 20 06:37:47.080790 2026] [security2:error] [pid 953991:tid 954127] [client 50.116.65.227:50326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Wm6_X-kAXGDrIFafWPQAAAIs"]
[Mon Jul 20 06:37:47.107669 2026] [security2:error] [pid 966386:tid 966626] [client 14.225.17.146:49749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4WmzrLBqY1mBmWu_b-HwAAAEA"], referer: https://friendlyspreadsheet.com/OLD
[Mon Jul 20 06:37:47.232236 2026] [security2:error] [pid 966386:tid 966624] [client 161.118.195.148:50863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WmzrLBqY1mBmWu_b-JgAAAD4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:47.235278 2026] [security2:error] [pid 953991:tid 954105] [remote 84.247.172.23:48440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4Wm6_X-kAXGDrIFafWRQAAsnE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 06:37:47.494152 2026] [security2:error] [pid 966386:tid 966670] [client 34.74.185.202:59237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WmzrLBqY1mBmWu_b-NQAAAGk"]
[Mon Jul 20 06:37:47.537980 2026] [security2:error] [pid 953991:tid 954240] [client 171.61.165.146:7195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Wm6_X-kAXGDrIFafWTAAAAPw"]
[Mon Jul 20 06:37:47.538091 2026] [security2:error] [pid 953991:tid 954240] [client 171.61.165.146:7195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Wm6_X-kAXGDrIFafWTAAAAPw"]
[Mon Jul 20 06:37:47.562647 2026] [security2:error] [pid 953991:tid 954188] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Wm6_X-kAXGDrIFafWSgAAyDA"], referer: http://aleishapenny.ca/OLD
[Mon Jul 20 06:37:47.806441 2026] [security2:error] [pid 966386:tid 966672] [client 161.118.195.148:51245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WmzrLBqY1mBmWu_b-SQAAAGs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:47.844081 2026] [security2:error] [pid 966386:tid 966621] [client 34.73.38.214:57157] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WmzrLBqY1mBmWu_b-SgAAADs"]
[Mon Jul 20 06:37:48.153005 2026] [security2:error] [pid 966386:tid 966625] [client 57.141.18.74:61330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WljrLBqY1mBmWu_b9FQAAP3s"]
[Mon Jul 20 06:37:48.221495 2026] [security2:error] [pid 953991:tid 954155] [client 114.119.134.152:43891] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/product/must-have-shorts-m1058"] [unique_id "al4WnK_X-kAXGDrIFafWXwAAAKc"], referer: https://www.liquidationteam.com/product/must-have-shorts-m1058
[Mon Jul 20 06:37:48.330800 2026] [security2:error] [pid 966386:tid 966614] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4WnDrLBqY1mBmWu_b-WwAANHE"], referer: https://aleishapenny.ca/OLD
[Mon Jul 20 06:37:48.382623 2026] [security2:error] [pid 953991:tid 954229] [client 161.118.195.148:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WnK_X-kAXGDrIFafWZwAAAPE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:48.611385 2026] [security2:error] [pid 966386:tid 966441] [remote 100.42.189.89:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4WnDrLBqY1mBmWu_b-awAAHQ4"]
[Mon Jul 20 06:37:48.670947 2026] [security2:error] [pid 966386:tid 966561] [client 34.74.185.202:59627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WnDrLBqY1mBmWu_b-bwAAAAE"]
[Mon Jul 20 06:37:48.757144 2026] [security2:error] [pid 966386:tid 966596] [client 104.234.53.67:23325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WnDrLBqY1mBmWu_b-cwAAACI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:48.799704 2026] [security2:error] [pid 953991:tid 954207] [client 57.141.18.102:62640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wl6_X-kAXGDrIFafVtwAA21E"]
[Mon Jul 20 06:37:48.805397 2026] [security2:error] [pid 966386:tid 966556] [remote 100.42.189.89:55054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4WnDrLBqY1mBmWu_b-dgAAWn4"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:37:48.868104 2026] [security2:error] [pid 966386:tid 966613] [client 65.21.237.125:0] ModSecurity: Warning. Matched phrase "SEOkicks" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "origine.nz"] [uri "/wp-content/uploads/2025/06/drinks-square-150x150.webp"] [unique_id "al4WnDrLBqY1mBmWu_b-eAAAM2c"], referer: https://origine.nz/menu/
[Mon Jul 20 06:37:48.909711 2026] [security2:error] [pid 953991:tid 954230] [client 34.73.38.214:59209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WnK_X-kAXGDrIFafWcwAAAPI"]
[Mon Jul 20 06:37:48.952361 2026] [security2:error] [pid 966386:tid 966678] [client 223.185.13.213:29905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WnDrLBqY1mBmWu_b-fQAAAHE"]
[Mon Jul 20 06:37:48.952457 2026] [security2:error] [pid 966386:tid 966678] [client 223.185.13.213:29905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WnDrLBqY1mBmWu_b-fQAAAHE"]
[Mon Jul 20 06:37:48.957702 2026] [security2:error] [pid 966386:tid 966606] [client 161.118.195.148:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WnDrLBqY1mBmWu_b-fgAAACw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:48.975081 2026] [security2:error] [pid 953991:tid 954180] [client 57.141.18.72:30562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wl6_X-kAXGDrIFafVwgAAwCY"]
[Mon Jul 20 06:37:48.987108 2026] [security2:error] [pid 953991:tid 954148] [client 34.73.38.214:51473] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WnK_X-kAXGDrIFafWdAAAAKA"]
[Mon Jul 20 06:37:49.105497 2026] [security2:error] [pid 953991:tid 954236] [client 34.74.185.202:54760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Wna_X-kAXGDrIFafWdwAAAPg"]
[Mon Jul 20 06:37:49.153613 2026] [security2:error] [pid 966386:tid 966617] [client 217.142.18.172:18861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WnTrLBqY1mBmWu_b-hwAAADc"]
[Mon Jul 20 06:37:49.153724 2026] [security2:error] [pid 966386:tid 966617] [client 217.142.18.172:18861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WnTrLBqY1mBmWu_b-hwAAADc"]
[Mon Jul 20 06:37:49.367556 2026] [security2:error] [pid 966386:tid 966683] [client 34.74.185.202:56998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WnTrLBqY1mBmWu_b-kgAAAHY"]
[Mon Jul 20 06:37:49.539892 2026] [security2:error] [pid 953991:tid 954214] [client 161.118.195.148:52527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wna_X-kAXGDrIFafWhgAAAOI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:49.629280 2026] [security2:error] [pid 966386:tid 966574] [client 112.208.70.94:43680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WnTrLBqY1mBmWu_b-mgAAAAw"]
[Mon Jul 20 06:37:49.629412 2026] [security2:error] [pid 966386:tid 966574] [client 112.208.70.94:43680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WnTrLBqY1mBmWu_b-mgAAAAw"]
[Mon Jul 20 06:37:49.691465 2026] [security2:error] [pid 953991:tid 954172] [client 77.110.127.138:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wna_X-kAXGDrIFafWiQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:49.691551 2026] [security2:error] [pid 953991:tid 954172] [client 77.110.127.138:51422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wna_X-kAXGDrIFafWiQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:49.833362 2026] [security2:error] [pid 953991:tid 954155] [client 104.234.53.66:38755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Wna_X-kAXGDrIFafWlAAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:49.882015 2026] [security2:error] [pid 953991:tid 954227] [client 34.73.38.214:55299] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Wna_X-kAXGDrIFafWmAAAAO8"]
[Mon Jul 20 06:37:49.985885 2026] [security2:error] [pid 953991:tid 954116] [remote 20.153.140.50:35594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Wna_X-kAXGDrIFafWngAApnw"]
[Mon Jul 20 06:37:50.130353 2026] [security2:error] [pid 953991:tid 954130] [client 161.118.195.148:52975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wnq_X-kAXGDrIFafWowAAAI4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:50.262818 2026] [security2:error] [pid 953991:tid 954150] [client 171.60.139.123:59532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Wnq_X-kAXGDrIFafWqgAAAKI"]
[Mon Jul 20 06:37:50.262945 2026] [security2:error] [pid 953991:tid 954150] [client 171.60.139.123:59532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Wnq_X-kAXGDrIFafWqgAAAKI"]
[Mon Jul 20 06:37:50.276010 2026] [security2:error] [pid 953991:tid 954207] [client 34.74.185.202:51476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Wnq_X-kAXGDrIFafWqwAAANs"]
[Mon Jul 20 06:37:50.295348 2026] [security2:error] [pid 966386:tid 966608] [client 34.73.38.214:56217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WnjrLBqY1mBmWu_b-sgAAAC4"]
[Mon Jul 20 06:37:50.372955 2026] [security2:error] [pid 953991:tid 954004] [remote 20.153.140.50:35594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Wnq_X-kAXGDrIFafWrAAAqgw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:37:50.436448 2026] [security2:error] [pid 953991:tid 954133] [client 114.119.151.237:32739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/wholesalemedicinecompanycom-772a.pdf"] [unique_id "al4Wnq_X-kAXGDrIFafWsAAAAJE"]
[Mon Jul 20 06:37:50.472816 2026] [security2:error] [pid 953991:tid 954035] [remote 68.178.160.25:38390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Wnq_X-kAXGDrIFafWsQAAnys"]
[Mon Jul 20 06:37:50.472976 2026] [security2:error] [pid 953991:tid 954147] [client 68.178.160.25:38390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Wnq_X-kAXGDrIFafWsQAAnys"]
[Mon Jul 20 06:37:50.623609 2026] [security2:error] [pid 966386:tid 966616] [client 57.141.18.59:37760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WmDrLBqY1mBmWu_b9kAAANjU"]
[Mon Jul 20 06:37:50.634978 2026] [security2:error] [pid 966386:tid 966687] [client 57.141.18.39:46281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WmDrLBqY1mBmWu_b9igAAekU"]
[Mon Jul 20 06:37:50.712202 2026] [security2:error] [pid 953991:tid 954185] [client 161.118.195.148:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wnq_X-kAXGDrIFafWvwAAAMU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:50.810094 2026] [security2:error] [pid 966386:tid 966636] [client 104.234.53.68:28387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4WnjrLBqY1mBmWu_b-1QAAAEo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:50.813030 2026] [security2:error] [pid 966386:tid 966625] [client 197.186.66.42:59407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WnjrLBqY1mBmWu_b-1gAAAD8"]
[Mon Jul 20 06:37:50.836556 2026] [security2:error] [pid 966386:tid 966625] [client 197.186.66.42:59407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WnjrLBqY1mBmWu_b-1gAAAD8"]
[Mon Jul 20 06:37:50.988150 2026] [security2:error] [pid 966386:tid 966652] [client 34.74.185.202:62154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WnjrLBqY1mBmWu_b-5wAAAFo"]
[Mon Jul 20 06:37:51.294860 2026] [security2:error] [pid 966386:tid 966677] [client 161.118.195.148:53870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WnzrLBqY1mBmWu_b-9AAAAHA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:51.461671 2026] [security2:error] [pid 966386:tid 966505] [remote 124.55.178.99:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WnzrLBqY1mBmWu_b-_wAAaUs"]
[Mon Jul 20 06:37:51.700463 2026] [security2:error] [pid 966386:tid 966588] [client 104.234.53.71:47507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WnzrLBqY1mBmWu_b_CQAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:51.822286 2026] [security2:error] [pid 966386:tid 966690] [client 34.73.38.214:60713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WnzrLBqY1mBmWu_b_GQAAAH0"]
[Mon Jul 20 06:37:51.877782 2026] [security2:error] [pid 953991:tid 954157] [client 161.118.195.148:54295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wn6_X-kAXGDrIFafW2wAAAKk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:51.883140 2026] [security2:error] [pid 966386:tid 966528] [remote 124.55.178.99:36258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WnzrLBqY1mBmWu_b_HAAAa2I"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:37:51.918433 2026] [security2:error] [pid 966386:tid 966686] [client 23.122.144.59:51365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "carolinapressurewashers.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WnzrLBqY1mBmWu_b_AQAAeT0"], referer: https://carolinapressurewashers.com/wp-admin/edit.php
[Mon Jul 20 06:37:52.191914 2026] [security2:error] [pid 966386:tid 966571] [client 106.219.188.178:2899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WoDrLBqY1mBmWu_b_MQAAAAk"]
[Mon Jul 20 06:37:52.193519 2026] [security2:error] [pid 966386:tid 966571] [client 106.219.188.178:2899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WoDrLBqY1mBmWu_b_MQAAAAk"]
[Mon Jul 20 06:37:52.299265 2026] [security2:error] [pid 966386:tid 966655] [client 34.74.185.202:55266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WoDrLBqY1mBmWu_b_OAAAAF0"]
[Mon Jul 20 06:37:52.363375 2026] [security2:error] [pid 953991:tid 954241] [client 57.141.18.87:59886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wmq_X-kAXGDrIFafWJAAA_Wo"]
[Mon Jul 20 06:37:52.465213 2026] [security2:error] [pid 966386:tid 966670] [client 161.118.195.148:54702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WoDrLBqY1mBmWu_b_QQAAAGk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:52.615443 2026] [security2:error] [pid 966386:tid 966656] [client 34.73.38.214:56927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WoDrLBqY1mBmWu_b_SQAAAF4"]
[Mon Jul 20 06:37:52.682636 2026] [security2:error] [pid 966386:tid 966676] [client 14.225.17.146:59777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4WnzrLBqY1mBmWu_b-7wAAAG8"], referer: http://tntcatholic.com/OLD
[Mon Jul 20 06:37:52.860691 2026] [security2:error] [pid 953991:tid 954237] [client 57.141.18.115:24152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wm6_X-kAXGDrIFafWNwAA-QA"]
[Mon Jul 20 06:37:52.889133 2026] [security2:error] [pid 966386:tid 966659] [client 39.48.81.23:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WoDrLBqY1mBmWu_b_WQAAAGA"]
[Mon Jul 20 06:37:52.889313 2026] [security2:error] [pid 966386:tid 966659] [client 39.48.81.23:65511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WoDrLBqY1mBmWu_b_WQAAAGA"]
[Mon Jul 20 06:37:52.967580 2026] [security2:error] [pid 953991:tid 954144] [client 152.58.191.29:58829] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WoK_X-kAXGDrIFafW-gAAAJw"]
[Mon Jul 20 06:37:52.967704 2026] [security2:error] [pid 953991:tid 954144] [client 152.58.191.29:58829] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WoK_X-kAXGDrIFafW-gAAAJw"]
[Mon Jul 20 06:37:53.054902 2026] [security2:error] [pid 953991:tid 954168] [client 161.118.195.148:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Woa_X-kAXGDrIFafXBAAAALQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:53.241849 2026] [security2:error] [pid 966386:tid 966598] [client 188.40.21.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4WoTrLBqY1mBmWu_b_YQAAACQ"]
[Mon Jul 20 06:37:53.299744 2026] [security2:error] [pid 953991:tid 954127] [client 157.66.56.117:58024] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "232"] [id "900331"] [msg "Joomla Com_Content SQL Injection POST"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4Woa_X-kAXGDrIFafXCwAAAIs"]
[Mon Jul 20 06:37:53.299858 2026] [security2:error] [pid 953991:tid 954127] [client 157.66.56.117:58024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "406"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4Woa_X-kAXGDrIFafXCwAAAIs"]
[Mon Jul 20 06:37:53.335964 2026] [security2:error] [pid 966386:tid 966663] [client 34.74.185.202:59074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WoTrLBqY1mBmWu_b_bAAAAGQ"]
[Mon Jul 20 06:37:53.354514 2026] [security2:error] [pid 953991:tid 954229] [client 103.125.179.95:49195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Woa_X-kAXGDrIFafXEAAAAPE"]
[Mon Jul 20 06:37:53.354653 2026] [security2:error] [pid 953991:tid 954229] [client 103.125.179.95:49195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Woa_X-kAXGDrIFafXEAAAAPE"]
[Mon Jul 20 06:37:53.528484 2026] [security2:error] [pid 966386:tid 966447] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WoTrLBqY1mBmWu_b_cQAANBQ"]
[Mon Jul 20 06:37:53.528684 2026] [security2:error] [pid 966386:tid 966614] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WoTrLBqY1mBmWu_b_cQAANBQ"]
[Mon Jul 20 06:37:53.638563 2026] [security2:error] [pid 966386:tid 966662] [client 161.118.195.148:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WoTrLBqY1mBmWu_b_fQAAAGM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:53.708100 2026] [security2:error] [pid 953991:tid 954135] [client 34.73.38.214:51980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Woa_X-kAXGDrIFafXGwAAAJM"]
[Mon Jul 20 06:37:53.886243 2026] [security2:error] [pid 953991:tid 954163] [client 77.110.127.138:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Woa_X-kAXGDrIFafXJwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:53.886359 2026] [security2:error] [pid 953991:tid 954163] [client 77.110.127.138:51453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Woa_X-kAXGDrIFafXJwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:53.935885 2026] [security2:error] [pid 953991:tid 954141] [client 104.234.53.64:57195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Woa_X-kAXGDrIFafXKQAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:53.985564 2026] [security2:error] [pid 966386:tid 966596] [client 187.108.85.186:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WoTrLBqY1mBmWu_b_jgAAACI"]
[Mon Jul 20 06:37:53.985668 2026] [security2:error] [pid 966386:tid 966596] [client 187.108.85.186:63941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WoTrLBqY1mBmWu_b_jgAAACI"]
[Mon Jul 20 06:37:54.213233 2026] [security2:error] [pid 953991:tid 954195] [client 161.118.195.148:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Woq_X-kAXGDrIFafXMwAAAM8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:54.232859 2026] [security2:error] [pid 953991:tid 954153] [client 57.141.18.35:62822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WnK_X-kAXGDrIFafWZQAApRA"]
[Mon Jul 20 06:37:54.473362 2026] [security2:error] [pid 966386:tid 966692] [client 158.173.166.181:23171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WojrLBqY1mBmWu_b_pAAAAH8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:37:54.555733 2026] [security2:error] [pid 966386:tid 966557] [remote 68.178.160.25:48938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4WojrLBqY1mBmWu_b_pgAAH38"]
[Mon Jul 20 06:37:54.611583 2026] [security2:error] [pid 966386:tid 966556] [remote 103.82.22.235:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4WojrLBqY1mBmWu_b_qgAAJn4"]
[Mon Jul 20 06:37:54.611792 2026] [security2:error] [pid 966386:tid 966600] [client 103.82.22.235:49458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4WojrLBqY1mBmWu_b_qgAAJn4"]
[Mon Jul 20 06:37:54.689961 2026] [security2:error] [pid 953991:tid 954154] [client 14.225.17.146:51514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4Woa_X-kAXGDrIFafXFgAAAKY"], referer: http://massagelacey.com/OLD
[Mon Jul 20 06:37:54.750876 2026] [security2:error] [pid 966386:tid 966608] [client 34.73.38.214:54764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WojrLBqY1mBmWu_b_swAAAC4"]
[Mon Jul 20 06:37:54.785457 2026] [security2:error] [pid 966386:tid 966585] [client 34.74.185.202:53039] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WojrLBqY1mBmWu_b_twAAABc"]
[Mon Jul 20 06:37:54.790412 2026] [security2:error] [pid 966386:tid 966616] [client 50.116.65.227:14312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WojrLBqY1mBmWu_b_uQAAADY"]
[Mon Jul 20 06:37:54.800134 2026] [security2:error] [pid 953991:tid 954223] [client 161.118.195.148:56462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Woq_X-kAXGDrIFafXSwAAAOs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:54.803419 2026] [security2:error] [pid 953991:tid 954130] [client 50.116.65.227:14326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Woq_X-kAXGDrIFafXTAAAAI4"]
[Mon Jul 20 06:37:55.087460 2026] [security2:error] [pid 966386:tid 966433] [remote 68.178.160.25:48938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4WozrLBqY1mBmWu_b_wgAASQY"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 06:37:55.272464 2026] [security2:error] [pid 966386:tid 966673] [client 34.73.38.214:55377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WozrLBqY1mBmWu_b_1QAAAGw"]
[Mon Jul 20 06:37:55.299985 2026] [security2:error] [pid 953991:tid 954150] [client 104.207.60.167:44875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Wo6_X-kAXGDrIFafXVwAAAKI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:37:55.357989 2026] [security2:error] [pid 953991:tid 954189] [client 14.225.17.146:55193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4Wo6_X-kAXGDrIFafXVAAAAMk"], referer: http://eduardsales.com/OLD
[Mon Jul 20 06:37:55.399616 2026] [security2:error] [pid 966386:tid 966588] [client 161.118.195.148:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WozrLBqY1mBmWu_b_3QAAABo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:55.663515 2026] [security2:error] [pid 953991:tid 954224] [client 34.73.38.214:54270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Wo6_X-kAXGDrIFafXZwAAAOw"]
[Mon Jul 20 06:37:55.709982 2026] [security2:error] [pid 966386:tid 966584] [client 34.74.185.202:57255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WozrLBqY1mBmWu_b_7wAAABY"]
[Mon Jul 20 06:37:55.830292 2026] [security2:error] [pid 953991:tid 954248] [client 14.225.17.146:55219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4Woq_X-kAXGDrIFafXSQAAAQQ"], referer: http://northbrookcpa.ca/OLD
[Mon Jul 20 06:37:55.858889 2026] [security2:error] [pid 953991:tid 954146] [client 57.141.18.97:53620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wna_X-kAXGDrIFafWjgAAnlk"]
[Mon Jul 20 06:37:55.977010 2026] [security2:error] [pid 953991:tid 954153] [client 161.118.195.148:57397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wo6_X-kAXGDrIFafXbQAAAKU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:56.292786 2026] [security2:error] [pid 966386:tid 966563] [client 98.159.234.160:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4WpDrLBqY1mBmWu_YAAwAAAAI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:37:56.335515 2026] [security2:error] [pid 953991:tid 954215] [client 77.110.127.138:51470] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 272 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WpK_X-kAXGDrIFafXcgAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:56.388889 2026] [security2:error] [pid 953991:tid 954247] [client 14.225.17.146:58155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Woq_X-kAXGDrIFafXKwAAAQM"], referer: http://healthylifegourmet.org/OLD
[Mon Jul 20 06:37:56.391488 2026] [security2:error] [pid 966386:tid 966594] [client 5.188.87.40:43348] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mrbambooplus.com"] [uri "/"] [unique_id "al4WpDrLBqY1mBmWu_YACQAAACA"]
[Mon Jul 20 06:37:56.564303 2026] [security2:error] [pid 953991:tid 954122] [client 161.118.195.148:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WpK_X-kAXGDrIFafXegAAAIY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:56.765591 2026] [security2:error] [pid 966386:tid 966635] [client 34.73.38.214:54802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WpDrLBqY1mBmWu_YANwAAAEk"]
[Mon Jul 20 06:37:56.775586 2026] [security2:error] [pid 953991:tid 954127] [client 104.234.53.55:39869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WpK_X-kAXGDrIFafXggAAAIs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:56.865867 2026] [security2:error] [pid 953991:tid 954157] [client 5.188.87.40:43354] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mrbambooplus.com"] [uri "/"] [unique_id "al4WpK_X-kAXGDrIFafXgwAAAKk"]
[Mon Jul 20 06:37:57.016295 2026] [security2:error] [pid 966386:tid 966606] [client 34.74.185.202:54913] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.tff.hws.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WpTrLBqY1mBmWu_YARQAAACw"]
[Mon Jul 20 06:37:57.063691 2026] [security2:error] [pid 953991:tid 954148] [client 77.110.127.138:51473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wpa_X-kAXGDrIFafXigAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:57.063817 2026] [security2:error] [pid 953991:tid 954148] [client 77.110.127.138:51473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wpa_X-kAXGDrIFafXigAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:37:57.094354 2026] [security2:error] [pid 953991:tid 954201] [client 103.238.106.162:60547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Wpa_X-kAXGDrIFafXiwAAANU"]
[Mon Jul 20 06:37:57.094517 2026] [security2:error] [pid 953991:tid 954201] [client 103.238.106.162:60547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Wpa_X-kAXGDrIFafXiwAAANU"]
[Mon Jul 20 06:37:57.139044 2026] [security2:error] [pid 966386:tid 966602] [client 161.118.195.148:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WpTrLBqY1mBmWu_YASQAAACg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:57.330955 2026] [security2:error] [pid 966386:tid 966611] [client 223.185.13.213:23608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WpTrLBqY1mBmWu_YAUwAAADE"]
[Mon Jul 20 06:37:57.331118 2026] [security2:error] [pid 966386:tid 966611] [client 223.185.13.213:23608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WpTrLBqY1mBmWu_YAUwAAADE"]
[Mon Jul 20 06:37:57.433079 2026] [security2:error] [pid 966386:tid 966561] [client 57.141.18.116:43252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WnzrLBqY1mBmWu_b-_gAAAUc"]
[Mon Jul 20 06:37:57.729632 2026] [security2:error] [pid 966386:tid 966574] [client 34.73.38.214:49539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WpTrLBqY1mBmWu_YAaAAAAAw"]
[Mon Jul 20 06:37:57.734777 2026] [security2:error] [pid 966386:tid 966652] [client 161.118.195.148:58584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WpTrLBqY1mBmWu_YAaQAAAFo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:57.808580 2026] [security2:error] [pid 966386:tid 966560] [client 34.139.11.221:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.arrazoado.com"] [uri "/xmlrpc.php"] [unique_id "al4WpTrLBqY1mBmWu_YAbwAAAAA"]
[Mon Jul 20 06:37:57.844029 2026] [security2:error] [pid 953991:tid 954210] [client 104.234.53.70:42901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Wpa_X-kAXGDrIFafXnwAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:57.921726 2026] [security2:error] [pid 953991:tid 954186] [client 45.3.44.34:20261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Wpa_X-kAXGDrIFafXoQAAAMY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:37:57.982149 2026] [security2:error] [pid 966386:tid 966564] [client 34.139.11.221:54123] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WpTrLBqY1mBmWu_YAeAAAAAM"]
[Mon Jul 20 06:37:58.110357 2026] [security2:error] [pid 966386:tid 966585] [client 34.139.11.221:57570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WpjrLBqY1mBmWu_YAfwAAABc"]
[Mon Jul 20 06:37:58.167171 2026] [security2:error] [pid 966386:tid 966611] [client 34.73.38.214:64698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WpjrLBqY1mBmWu_YAgwAAADE"]
[Mon Jul 20 06:37:58.303776 2026] [security2:error] [pid 953991:tid 954212] [client 34.139.11.221:50978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Wpq_X-kAXGDrIFafXrwAAAOA"]
[Mon Jul 20 06:37:58.319814 2026] [security2:error] [pid 953991:tid 954154] [client 161.118.195.148:58948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wpq_X-kAXGDrIFafXsQAAAKY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:58.386972 2026] [security2:error] [pid 966386:tid 966668] [client 171.61.165.146:15554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WpjrLBqY1mBmWu_YAigAAAGg"]
[Mon Jul 20 06:37:58.387088 2026] [security2:error] [pid 966386:tid 966668] [client 171.61.165.146:15554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WpjrLBqY1mBmWu_YAigAAAGg"]
[Mon Jul 20 06:37:58.467705 2026] [security2:error] [pid 966386:tid 966578] [client 34.139.11.221:62606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WpjrLBqY1mBmWu_YAkAAAABA"]
[Mon Jul 20 06:37:58.560639 2026] [security2:error] [pid 966386:tid 966625] [client 57.141.18.117:25022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WoDrLBqY1mBmWu_b_QAAAP0o"]
[Mon Jul 20 06:37:58.661953 2026] [security2:error] [pid 953991:tid 954202] [client 34.139.11.221:55955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Wpq_X-kAXGDrIFafXugAAANY"]
[Mon Jul 20 06:37:58.901794 2026] [security2:error] [pid 953991:tid 954148] [client 161.118.195.148:59329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wpq_X-kAXGDrIFafXxQAAAKA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:58.916004 2026] [security2:error] [pid 953991:tid 954174] [client 104.234.53.73:28127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Wpq_X-kAXGDrIFafXxgAAALo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:58.935315 2026] [security2:error] [pid 966386:tid 966581] [client 34.139.11.221:62771] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WpjrLBqY1mBmWu_YApAAAABM"]
[Mon Jul 20 06:37:58.971070 2026] [security2:error] [pid 966386:tid 966522] [remote 57.141.18.99:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2766231"] [unique_id "al4WpjrLBqY1mBmWu_YApgAAElw"]
[Mon Jul 20 06:37:59.036982 2026] [security2:error] [pid 966386:tid 966606] [client 157.55.39.61:50841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4WpjrLBqY1mBmWu_YApQAALGI"]
[Mon Jul 20 06:37:59.040154 2026] [security2:error] [pid 966386:tid 966607] [client 212.47.238.7:37876] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4WpzrLBqY1mBmWu_YAqwAAAC0"]
[Mon Jul 20 06:37:59.046011 2026] [security2:error] [pid 966386:tid 966492] [remote 209.42.18.223:59232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WpzrLBqY1mBmWu_YAqgAAUD4"]
[Mon Jul 20 06:37:59.105143 2026] [security2:error] [pid 953991:tid 954141] [client 45.3.45.63:36169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Wp6_X-kAXGDrIFafXygAAAJk"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:37:59.125559 2026] [security2:error] [pid 953991:tid 954146] [client 34.139.11.221:63907] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Wp6_X-kAXGDrIFafXzQAAAJ4"]
[Mon Jul 20 06:37:59.217984 2026] [security2:error] [pid 966386:tid 966523] [remote 209.42.18.223:59232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WpzrLBqY1mBmWu_YAtAAAHV0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:37:59.227194 2026] [security2:error] [pid 953991:tid 954149] [client 14.225.17.146:64635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4Wpa_X-kAXGDrIFafXjgAAAKE"], referer: http://fineartsfactory.net/OLD
[Mon Jul 20 06:37:59.253692 2026] [security2:error] [pid 966386:tid 966665] [client 34.139.11.221:56650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WpzrLBqY1mBmWu_YAtgAAAGY"]
[Mon Jul 20 06:37:59.260932 2026] [security2:error] [pid 953991:tid 954129] [client 34.73.38.214:60592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Wp6_X-kAXGDrIFafX0AAAAI0"]
[Mon Jul 20 06:37:59.275762 2026] [security2:error] [pid 966386:tid 966575] [client 14.225.17.146:59298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4WpTrLBqY1mBmWu_YAXwAAAA0"], referer: http://maplerespiteservices.com/OLD
[Mon Jul 20 06:37:59.428533 2026] [security2:error] [pid 953991:tid 954198] [client 34.139.11.221:63106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Wp6_X-kAXGDrIFafX3AAAANI"]
[Mon Jul 20 06:37:59.447826 2026] [security2:error] [pid 953991:tid 954195] [client 14.225.17.146:58828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4Wpq_X-kAXGDrIFafXpAAAAM8"], referer: http://bbwipartnerconference.com/OLD
[Mon Jul 20 06:37:59.483188 2026] [security2:error] [pid 953991:tid 954121] [client 161.118.195.148:59699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wp6_X-kAXGDrIFafX4QAAAIU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:37:59.592746 2026] [security2:error] [pid 953991:tid 954074] [remote 74.7.227.179:36620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wp6_X-kAXGDrIFafX4AAA4FI"], referer: https://tejasenvironmental.com/p=199200
[Mon Jul 20 06:37:59.646699 2026] [security2:error] [pid 966386:tid 966537] [remote 162.19.86.63:56960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4WpzrLBqY1mBmWu_YA0QAAP2s"]
[Mon Jul 20 06:37:59.674761 2026] [security2:error] [pid 966386:tid 966668] [client 13.233.207.33:40310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WpzrLBqY1mBmWu_YAzgAAAGg"]
[Mon Jul 20 06:37:59.706694 2026] [security2:error] [pid 966386:tid 966612] [client 34.139.11.221:63959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WpzrLBqY1mBmWu_YA1gAAADI"]
[Mon Jul 20 06:37:59.733769 2026] [security2:error] [pid 966386:tid 966578] [client 217.142.18.172:8937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WpzrLBqY1mBmWu_YA2wAAABA"]
[Mon Jul 20 06:37:59.749306 2026] [security2:error] [pid 966386:tid 966578] [client 217.142.18.172:8937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WpzrLBqY1mBmWu_YA2wAAABA"]
[Mon Jul 20 06:37:59.761392 2026] [security2:error] [pid 966386:tid 966682] [client 45.3.45.153:52761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WpzrLBqY1mBmWu_YA1wAAAHU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:37:59.875072 2026] [security2:error] [pid 966386:tid 966449] [remote 162.19.86.63:56960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4WpzrLBqY1mBmWu_YA6QAARRY"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:37:59.890214 2026] [security2:error] [pid 966386:tid 966683] [client 104.234.53.83:42843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WpzrLBqY1mBmWu_YA6gAAAHY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:37:59.929237 2026] [security2:error] [pid 953991:tid 954150] [client 34.139.11.221:59925] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.arrazoado.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Wp6_X-kAXGDrIFafX8AAAAKI"]
[Mon Jul 20 06:37:59.947226 2026] [security2:error] [pid 953991:tid 954196] [client 34.73.38.214:49607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thepauze.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Wp6_X-kAXGDrIFafX8QAAANA"]
[Mon Jul 20 06:37:59.952473 2026] [security2:error] [pid 953991:tid 954131] [client 34.73.38.214:64756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Wp6_X-kAXGDrIFafX8gAAAI8"]
[Mon Jul 20 06:38:00.018369 2026] [security2:error] [pid 966386:tid 966605] [client 14.225.17.146:65041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4WpzrLBqY1mBmWu_YA4AAAACs"], referer: http://savilerowtravel.com/OLD
[Mon Jul 20 06:38:00.056861 2026] [security2:error] [pid 953991:tid 954201] [client 161.118.195.148:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WqK_X-kAXGDrIFafX-AAAANU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:00.141319 2026] [security2:error] [pid 966386:tid 966610] [client 157.55.39.61:50841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4WpzrLBqY1mBmWu_YA3QAAMEA"]
[Mon Jul 20 06:38:00.154262 2026] [security2:error] [pid 966386:tid 966657] [client 197.186.66.42:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YA8QAAAF8"]
[Mon Jul 20 06:38:00.154354 2026] [security2:error] [pid 966386:tid 966657] [client 197.186.66.42:59926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YA8QAAAF8"]
[Mon Jul 20 06:38:00.219627 2026] [security2:error] [pid 953991:tid 954119] [remote 117.0.21.154:42286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4WqK_X-kAXGDrIFafYAgAAyX8"]
[Mon Jul 20 06:38:00.261463 2026] [security2:error] [pid 966386:tid 966574] [client 103.125.179.95:49687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YA9wAAAAw"]
[Mon Jul 20 06:38:00.261553 2026] [security2:error] [pid 966386:tid 966574] [client 103.125.179.95:49687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YA9wAAAAw"]
[Mon Jul 20 06:38:00.322943 2026] [security2:error] [pid 953991:tid 954244] [client 57.141.18.32:57254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Woq_X-kAXGDrIFafXSAABAHU"]
[Mon Jul 20 06:38:00.379991 2026] [security2:error] [pid 953991:tid 954136] [client 39.48.81.23:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WqK_X-kAXGDrIFafYCQAAAJQ"]
[Mon Jul 20 06:38:00.380526 2026] [security2:error] [pid 953991:tid 954136] [client 39.48.81.23:49794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WqK_X-kAXGDrIFafYCQAAAJQ"]
[Mon Jul 20 06:38:00.567090 2026] [security2:error] [pid 953991:tid 954158] [client 171.60.139.123:60053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WqK_X-kAXGDrIFafYEwAAAKo"]
[Mon Jul 20 06:38:00.567234 2026] [security2:error] [pid 953991:tid 954158] [client 171.60.139.123:60053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WqK_X-kAXGDrIFafYEwAAAKo"]
[Mon Jul 20 06:38:00.630664 2026] [security2:error] [pid 966386:tid 966608] [client 161.118.195.148:60565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WqDrLBqY1mBmWu_YBCQAAAC4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:00.681349 2026] [security2:error] [pid 966386:tid 966548] [remote 182.77.62.24:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WqDrLBqY1mBmWu_YBDAAAYHY"]
[Mon Jul 20 06:38:00.732340 2026] [security2:error] [pid 953991:tid 954167] [client 13.233.207.33:40312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WqK_X-kAXGDrIFafYFwAAALM"]
[Mon Jul 20 06:38:00.736899 2026] [security2:error] [pid 966386:tid 966603] [client 112.208.70.94:44104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YBEQAAACk"]
[Mon Jul 20 06:38:00.736979 2026] [security2:error] [pid 966386:tid 966603] [client 112.208.70.94:44104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YBEQAAACk"]
[Mon Jul 20 06:38:00.782876 2026] [security2:error] [pid 953991:tid 954027] [remote 117.0.21.154:42286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4WqK_X-kAXGDrIFafYGgAA_CM"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 06:38:00.961847 2026] [security2:error] [pid 966386:tid 966582] [client 34.74.185.202:65527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WqDrLBqY1mBmWu_YBGgAAABQ"]
[Mon Jul 20 06:38:01.075822 2026] [security2:error] [pid 966386:tid 966568] [client 14.225.17.146:55066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4WqDrLBqY1mBmWu_YBGAAAAAY"], referer: https://savilerowtravel.com/OLD
[Mon Jul 20 06:38:01.116613 2026] [security2:error] [pid 966386:tid 966441] [remote 57.141.18.94:26960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4918599"] [unique_id "al4WqTrLBqY1mBmWu_YBIgAACA4"]
[Mon Jul 20 06:38:01.132993 2026] [security2:error] [pid 966386:tid 966636] [client 77.110.127.138:51487] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 997 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WqTrLBqY1mBmWu_YBIwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:01.192378 2026] [security2:error] [pid 966386:tid 966452] [remote 182.77.62.24:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WqTrLBqY1mBmWu_YBKwAAAhk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:38:01.216638 2026] [security2:error] [pid 966386:tid 966604] [client 161.118.195.148:60960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WqTrLBqY1mBmWu_YBMAAAACo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:01.270209 2026] [security2:error] [pid 966386:tid 966646] [client 34.73.38.214:51215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WqTrLBqY1mBmWu_YBNAAAAFQ"]
[Mon Jul 20 06:38:01.286295 2026] [security2:error] [pid 966386:tid 966584] [client 77.110.127.138:51489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WqTrLBqY1mBmWu_YBNwAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:01.286429 2026] [security2:error] [pid 966386:tid 966584] [client 77.110.127.138:51489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WqTrLBqY1mBmWu_YBNwAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:01.295512 2026] [security2:error] [pid 966386:tid 966470] [remote 5.252.52.249:35644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WqTrLBqY1mBmWu_YBOQAAQyo"]
[Mon Jul 20 06:38:01.438014 2026] [security2:error] [pid 966386:tid 966593] [client 104.234.53.62:57181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WqTrLBqY1mBmWu_YBQAAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:01.539105 2026] [security2:error] [pid 966386:tid 966466] [remote 5.252.52.249:35644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WqTrLBqY1mBmWu_YBRQAABSY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:38:01.679656 2026] [security2:error] [pid 966386:tid 966662] [client 34.74.185.202:62090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WqTrLBqY1mBmWu_YBTgAAAGM"]
[Mon Jul 20 06:38:01.797711 2026] [security2:error] [pid 966386:tid 966618] [client 161.118.195.148:61302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WqTrLBqY1mBmWu_YBUwAAADg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:01.863672 2026] [security2:error] [pid 966386:tid 966460] [remote 57.141.18.35:42132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4846509"] [unique_id "al4WqTrLBqY1mBmWu_YBWAAAeiE"]
[Mon Jul 20 06:38:02.117341 2026] [security2:error] [pid 953991:tid 954213] [client 14.225.17.146:59529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4WqK_X-kAXGDrIFafYEAAAAOE"], referer: http://bigwormfishing.com/OLD
[Mon Jul 20 06:38:02.133680 2026] [security2:error] [pid 966386:tid 966620] [client 14.225.17.146:59700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4WqDrLBqY1mBmWu_YBEgAAADo"], referer: http://effingweirdmuseums.com/OLD
[Mon Jul 20 06:38:02.214719 2026] [security2:error] [pid 953991:tid 954230] [client 34.74.185.202:56105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Wqq_X-kAXGDrIFafYRQAAAPI"]
[Mon Jul 20 06:38:02.253075 2026] [security2:error] [pid 953991:tid 954139] [client 57.141.18.26:27434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WpK_X-kAXGDrIFafXcQAAlxs"]
[Mon Jul 20 06:38:02.365193 2026] [security2:error] [pid 966386:tid 966673] [client 57.141.18.99:34620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WpDrLBqY1mBmWu_YABQAAbBE"]
[Mon Jul 20 06:38:02.395579 2026] [security2:error] [pid 966386:tid 966674] [client 161.118.195.148:61673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WqjrLBqY1mBmWu_YBeQAAAG0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:02.460176 2026] [security2:error] [pid 953991:tid 954090] [remote 216.73.217.138:60629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wqq_X-kAXGDrIFafYTAAA0mI"]
[Mon Jul 20 06:38:02.649924 2026] [security2:error] [pid 966386:tid 966637] [client 106.219.188.178:8587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WqjrLBqY1mBmWu_YBigAAAEs"]
[Mon Jul 20 06:38:02.655060 2026] [security2:error] [pid 966386:tid 966637] [client 106.219.188.178:8587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WqjrLBqY1mBmWu_YBigAAAEs"]
[Mon Jul 20 06:38:02.826578 2026] [security2:error] [pid 953991:tid 954229] [client 216.73.217.138:60629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wqq_X-kAXGDrIFafYVQAA8Ug"]
[Mon Jul 20 06:38:02.887676 2026] [security2:error] [pid 966386:tid 966594] [client 14.225.17.146:55286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4WqjrLBqY1mBmWu_YBmAAAACA"], referer: http://claysharecon.com/OLD
[Mon Jul 20 06:38:02.921739 2026] [security2:error] [pid 966386:tid 966607] [client 104.234.53.74:55039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WqjrLBqY1mBmWu_YBnwAAAC0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:02.937923 2026] [security2:error] [pid 966386:tid 966670] [client 34.73.38.214:52098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WqjrLBqY1mBmWu_YBoQAAAGk"]
[Mon Jul 20 06:38:02.972900 2026] [security2:error] [pid 966386:tid 966685] [client 161.118.195.148:62060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WqjrLBqY1mBmWu_YBpQAAAHg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:02.980093 2026] [security2:error] [pid 953991:tid 954098] [remote 47.86.33.52:44402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4Wqq_X-kAXGDrIFafYWQAA1Go"]
[Mon Jul 20 06:38:03.003190 2026] [security2:error] [pid 966386:tid 966597] [client 34.74.185.202:63433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WqzrLBqY1mBmWu_YBqQAAACM"]
[Mon Jul 20 06:38:03.188942 2026] [security2:error] [pid 966386:tid 966580] [client 14.225.17.146:56913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4WqzrLBqY1mBmWu_YBvgAAABI"], referer: https://effingweirdmuseums.com/OLD
[Mon Jul 20 06:38:03.189095 2026] [security2:error] [pid 966386:tid 966656] [client 14.225.17.146:56910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4WqzrLBqY1mBmWu_YBsQAAAF4"], referer: https://bigwormfishing.com/OLD
[Mon Jul 20 06:38:03.443316 2026] [security2:error] [pid 966386:tid 966657] [client 34.74.185.202:64183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WqzrLBqY1mBmWu_YBywAAAF8"]
[Mon Jul 20 06:38:03.467938 2026] [security2:error] [pid 953991:tid 954096] [remote 20.153.140.50:48978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Wq6_X-kAXGDrIFafYZgAA0Gg"]
[Mon Jul 20 06:38:03.547091 2026] [security2:error] [pid 966386:tid 966646] [client 161.118.195.148:62386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WqzrLBqY1mBmWu_YB0AAAAFQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:03.754522 2026] [security2:error] [pid 953991:tid 954077] [remote 47.86.33.52:44402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4Wq6_X-kAXGDrIFafYbAAArFU"], referer: https://technicalseohouse.com/wp-login.php
[Mon Jul 20 06:38:03.834203 2026] [security2:error] [pid 953991:tid 954191] [client 152.58.191.29:59355] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Wq6_X-kAXGDrIFafYbgAAAMs"]
[Mon Jul 20 06:38:03.834352 2026] [security2:error] [pid 953991:tid 954191] [client 152.58.191.29:59355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Wq6_X-kAXGDrIFafYbgAAAMs"]
[Mon Jul 20 06:38:03.868674 2026] [security2:error] [pid 953991:tid 954211] [client 57.141.18.26:27442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wpa_X-kAXGDrIFafXngAA3zc"]
[Mon Jul 20 06:38:03.875803 2026] [security2:error] [pid 953991:tid 954043] [remote 20.153.140.50:48978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Wq6_X-kAXGDrIFafYcAAAuDM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:38:04.032949 2026] [security2:error] [pid 966386:tid 966570] [client 34.74.185.202:55609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WrDrLBqY1mBmWu_YB7QAAAAg"]
[Mon Jul 20 06:38:04.127045 2026] [security2:error] [pid 966386:tid 966637] [client 161.118.195.148:62735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WrDrLBqY1mBmWu_YB8AAAAEs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:04.179083 2026] [security2:error] [pid 966386:tid 966620] [client 14.225.17.146:56933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4WqzrLBqY1mBmWu_YBvwAAADo"], referer: http://travelbyfire.com/OLD
[Mon Jul 20 06:38:04.223914 2026] [security2:error] [pid 966386:tid 966508] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WrDrLBqY1mBmWu_YB9gAAWk4"]
[Mon Jul 20 06:38:04.224094 2026] [security2:error] [pid 966386:tid 966652] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WrDrLBqY1mBmWu_YB9gAAWk4"]
[Mon Jul 20 06:38:04.547089 2026] [security2:error] [pid 953991:tid 954207] [client 34.74.185.202:64012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WrK_X-kAXGDrIFafYjQAAANs"]
[Mon Jul 20 06:38:04.704961 2026] [security2:error] [pid 953991:tid 954171] [client 161.118.195.148:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WrK_X-kAXGDrIFafYkAAAALc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:04.710379 2026] [security2:error] [pid 953991:tid 954246] [client 54.204.130.104:16990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.130.204.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WrK_X-kAXGDrIFafYjwAAAQI"]
[Mon Jul 20 06:38:04.710477 2026] [security2:error] [pid 953991:tid 954246] [client 54.204.130.104:16990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WrK_X-kAXGDrIFafYjwAAAQI"]
[Mon Jul 20 06:38:04.737284 2026] [security2:error] [pid 966386:tid 966622] [client 14.225.17.146:53582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4WqjrLBqY1mBmWu_YBowAAADw"], referer: http://tacticaltreeoperations.com/OLD
[Mon Jul 20 06:38:04.749954 2026] [security2:error] [pid 966386:tid 966682] [client 34.73.38.214:56377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WrDrLBqY1mBmWu_YCCgAAAHU"]
[Mon Jul 20 06:38:04.755457 2026] [security2:error] [pid 966386:tid 966571] [client 57.141.18.47:44926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WpjrLBqY1mBmWu_YAnwAACSM"]
[Mon Jul 20 06:38:04.935466 2026] [security2:error] [pid 953991:tid 954193] [client 187.108.85.186:64883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WrK_X-kAXGDrIFafYlwAAAM0"]
[Mon Jul 20 06:38:04.935607 2026] [security2:error] [pid 953991:tid 954193] [client 187.108.85.186:64883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WrK_X-kAXGDrIFafYlwAAAM0"]
[Mon Jul 20 06:38:05.012558 2026] [security2:error] [pid 953991:tid 954248] [client 34.74.185.202:59307] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Wra_X-kAXGDrIFafYmQAAAQQ"]
[Mon Jul 20 06:38:05.074199 2026] [security2:error] [pid 966386:tid 966519] [remote 45.90.123.233:53712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WrTrLBqY1mBmWu_YCJQAAFlk"]
[Mon Jul 20 06:38:05.074371 2026] [security2:error] [pid 966386:tid 966584] [client 45.90.123.233:53712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WrTrLBqY1mBmWu_YCJQAAFlk"]
[Mon Jul 20 06:38:05.083656 2026] [security2:error] [pid 966386:tid 966578] [client 14.225.17.146:57921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4WrTrLBqY1mBmWu_YCIQAAABA"], referer: https://travelbyfire.com/OLD
[Mon Jul 20 06:38:05.285074 2026] [security2:error] [pid 953991:tid 954208] [client 161.118.195.148:63477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wra_X-kAXGDrIFafYpAAAANw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:05.308634 2026] [security2:error] [pid 953991:tid 954183] [client 57.141.18.119:59726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wp6_X-kAXGDrIFafX4wAAw3Q"]
[Mon Jul 20 06:38:05.378582 2026] [security2:error] [pid 953991:tid 954149] [client 34.74.185.202:59297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Wra_X-kAXGDrIFafYpgAAAKE"]
[Mon Jul 20 06:38:05.539836 2026] [security2:error] [pid 953991:tid 954175] [client 77.110.127.138:51507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wra_X-kAXGDrIFafYqAAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:05.539946 2026] [security2:error] [pid 953991:tid 954175] [client 77.110.127.138:51507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wra_X-kAXGDrIFafYqAAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:05.689848 2026] [security2:error] [pid 966386:tid 966572] [client 77.110.127.138:51509] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 608 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WrTrLBqY1mBmWu_YCSAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:05.815442 2026] [security2:error] [pid 966386:tid 966664] [client 34.74.185.202:50026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WrTrLBqY1mBmWu_YCUgAAAGU"]
[Mon Jul 20 06:38:05.859221 2026] [security2:error] [pid 953991:tid 954221] [client 161.118.195.148:63892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wra_X-kAXGDrIFafYsAAAAOk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:06.025725 2026] [security2:error] [pid 953991:tid 954135] [client 34.73.38.214:54262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.thewelloiledlife.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Wrq_X-kAXGDrIFafYtQAAAJM"]
[Mon Jul 20 06:38:06.235662 2026] [security2:error] [pid 966386:tid 966685] [client 34.74.185.202:54412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WrjrLBqY1mBmWu_YCbAAAAHg"]
[Mon Jul 20 06:38:06.432698 2026] [security2:error] [pid 966386:tid 966652] [client 161.118.195.148:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WrjrLBqY1mBmWu_YCeAAAAFo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:06.509492 2026] [security2:error] [pid 966386:tid 966611] [client 14.225.17.146:53415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4WrjrLBqY1mBmWu_YCdwAAADE"], referer: http://thefriendlyspreadsheet.com/OLD
[Mon Jul 20 06:38:06.597264 2026] [security2:error] [pid 966386:tid 966651] [client 14.225.17.146:53425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4WrjrLBqY1mBmWu_YCeQAAAFk"], referer: http://grecruit.online/OLD
[Mon Jul 20 06:38:06.610261 2026] [security2:error] [pid 966386:tid 966691] [client 34.74.185.202:49607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thepauze.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WrjrLBqY1mBmWu_YCgAAAAH4"]
[Mon Jul 20 06:38:06.798339 2026] [security2:error] [pid 953991:tid 954216] [client 57.141.18.51:45252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WqK_X-kAXGDrIFafYHwAA5EU"]
[Mon Jul 20 06:38:06.829293 2026] [security2:error] [pid 966386:tid 966548] [remote 167.233.114.32:43762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WrjrLBqY1mBmWu_YCigAAEHY"]
[Mon Jul 20 06:38:06.829435 2026] [security2:error] [pid 966386:tid 966578] [client 167.233.114.32:43762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WrjrLBqY1mBmWu_YCigAAEHY"]
[Mon Jul 20 06:38:07.008306 2026] [security2:error] [pid 953991:tid 954231] [client 161.118.195.148:64638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wr6_X-kAXGDrIFafYwwAAAPM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:07.583470 2026] [security2:error] [pid 966386:tid 966653] [client 161.118.195.148:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WrzrLBqY1mBmWu_YCswAAAFs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:07.658917 2026] [security2:error] [pid 966386:tid 966600] [client 103.238.106.162:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WrzrLBqY1mBmWu_YCuAAAACY"]
[Mon Jul 20 06:38:07.659085 2026] [security2:error] [pid 966386:tid 966600] [client 103.238.106.162:60942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WrzrLBqY1mBmWu_YCuAAAACY"]
[Mon Jul 20 06:38:07.822728 2026] [security2:error] [pid 953991:tid 954140] [client 103.153.183.69:32406] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4Wr6_X-kAXGDrIFafY5wAAAJg"], referer: https://www.reddit.com/
[Mon Jul 20 06:38:08.058878 2026] [security2:error] [pid 953991:tid 954084] [remote 152.228.213.32:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WsK_X-kAXGDrIFafY7gAA4lw"]
[Mon Jul 20 06:38:08.059129 2026] [security2:error] [pid 953991:tid 954214] [client 152.228.213.32:53986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WsK_X-kAXGDrIFafY7gAA4lw"]
[Mon Jul 20 06:38:08.158803 2026] [security2:error] [pid 953991:tid 954128] [client 57.141.18.3:31482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wqq_X-kAXGDrIFafYRAAAjDY"]
[Mon Jul 20 06:38:08.161588 2026] [security2:error] [pid 966386:tid 966567] [client 161.118.195.148:65405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WsDrLBqY1mBmWu_YC1gAAAAU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:08.172430 2026] [security2:error] [pid 953991:tid 954153] [client 47.128.27.48:28980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "techtradeinc.com"] [uri "/robots.txt"] [unique_id "al4WsK_X-kAXGDrIFafY8QAAAKU"]
[Mon Jul 20 06:38:08.374681 2026] [security2:error] [pid 966386:tid 966575] [client 34.74.185.202:60331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4WsDrLBqY1mBmWu_YC5wAAAA0"]
[Mon Jul 20 06:38:08.486822 2026] [security2:error] [pid 966386:tid 966532] [remote 167.233.114.32:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4WsDrLBqY1mBmWu_YC7wAAZ2Y"]
[Mon Jul 20 06:38:08.691217 2026] [security2:error] [pid 966386:tid 966499] [remote 45.90.123.233:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WsDrLBqY1mBmWu_YC9gAAK0U"]
[Mon Jul 20 06:38:08.736485 2026] [security2:error] [pid 966386:tid 966688] [client 161.118.195.148:49347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WsDrLBqY1mBmWu_YC-AAAAHs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:08.737930 2026] [security2:error] [pid 966386:tid 966483] [remote 167.233.114.32:43778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4WsDrLBqY1mBmWu_YC-QAAaDU"], referer: https://detroitcsc.com/wp-login.php
[Mon Jul 20 06:38:08.774627 2026] [security2:error] [pid 953991:tid 954234] [client 34.74.185.202:65002] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WsK_X-kAXGDrIFafY_QAAAPY"]
[Mon Jul 20 06:38:09.061844 2026] [security2:error] [pid 953991:tid 954228] [client 77.110.127.138:51531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsa_X-kAXGDrIFafZCwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.061932 2026] [security2:error] [pid 953991:tid 954228] [client 77.110.127.138:51531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsa_X-kAXGDrIFafZCwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.078417 2026] [security2:error] [pid 966386:tid 966655] [client 34.74.185.202:63851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WsTrLBqY1mBmWu_YDDQAAAF0"]
[Mon Jul 20 06:38:09.100546 2026] [security2:error] [pid 966386:tid 966571] [client 223.185.13.213:18974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WsTrLBqY1mBmWu_YDEAAAAAk"]
[Mon Jul 20 06:38:09.100680 2026] [security2:error] [pid 966386:tid 966571] [client 223.185.13.213:18974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WsTrLBqY1mBmWu_YDEAAAAAk"]
[Mon Jul 20 06:38:09.214909 2026] [security2:error] [pid 966386:tid 966661] [client 77.110.127.138:51532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WsTrLBqY1mBmWu_YDFwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.226195 2026] [security2:error] [pid 966386:tid 966686] [client 77.110.127.138:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WsTrLBqY1mBmWu_YDGAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.226313 2026] [security2:error] [pid 966386:tid 966686] [client 77.110.127.138:51533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WsTrLBqY1mBmWu_YDGAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.257851 2026] [security2:error] [pid 953991:tid 954119] [remote 156.67.31.167:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Wsa_X-kAXGDrIFafZFQAAon8"]
[Mon Jul 20 06:38:09.309718 2026] [security2:error] [pid 966386:tid 966672] [client 161.118.195.148:49714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WsTrLBqY1mBmWu_YDHgAAAGs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:09.322331 2026] [security2:error] [pid 953991:tid 954186] [client 49.13.24.81:23394] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4Wsa_X-kAXGDrIFafZEwAAAMY"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:38:09.590918 2026] [security2:error] [pid 953991:tid 954116] [remote 156.67.31.167:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4Wsa_X-kAXGDrIFafZLQAA2Xw"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:38:09.606643 2026] [security2:error] [pid 953991:tid 954169] [client 65.111.28.254:43789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4Wsa_X-kAXGDrIFafZKQAAALU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:38:09.641701 2026] [security2:error] [pid 953991:tid 954159] [client 77.110.127.138:51536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsa_X-kAXGDrIFafZLwAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.641853 2026] [security2:error] [pid 953991:tid 954159] [client 77.110.127.138:51536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsa_X-kAXGDrIFafZLwAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:09.732653 2026] [security2:error] [pid 953991:tid 954197] [client 57.141.18.3:31488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wq6_X-kAXGDrIFafYagAA0Wc"]
[Mon Jul 20 06:38:09.771673 2026] [security2:error] [pid 966386:tid 966674] [client 34.74.185.202:50892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WsTrLBqY1mBmWu_YDNgAAAG0"]
[Mon Jul 20 06:38:09.825638 2026] [security2:error] [pid 966386:tid 966502] [remote 45.90.123.233:53702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4WsTrLBqY1mBmWu_YDOAAASkg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:38:09.830300 2026] [security2:error] [pid 966386:tid 966578] [client 14.225.17.146:56200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4WsDrLBqY1mBmWu_YDAAAAABA"], referer: http://kromosenergy.com/OLD
[Mon Jul 20 06:38:09.884104 2026] [security2:error] [pid 953991:tid 954126] [client 161.118.195.148:50085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wsa_X-kAXGDrIFafZPQAAAIo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:09.892148 2026] [security2:error] [pid 966386:tid 966505] [remote 45.150.79.142:33644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4WsTrLBqY1mBmWu_YDOgAAS0s"]
[Mon Jul 20 06:38:10.021360 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:51545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsq_X-kAXGDrIFafZQwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:10.021460 2026] [security2:error] [pid 953991:tid 954240] [client 77.110.127.138:51545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsq_X-kAXGDrIFafZQwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:10.055975 2026] [security2:error] [pid 966386:tid 966552] [remote 160.187.68.132:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WsjrLBqY1mBmWu_YDQwAAJ3o"]
[Mon Jul 20 06:38:10.056295 2026] [security2:error] [pid 966386:tid 966601] [client 160.187.68.132:44158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WsjrLBqY1mBmWu_YDQwAAJ3o"]
[Mon Jul 20 06:38:10.074520 2026] [security2:error] [pid 966386:tid 966508] [remote 45.150.79.142:33644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4WsjrLBqY1mBmWu_YDRAAAbk4"], referer: https://mail.cathybuffini.com/wp-login.php
[Mon Jul 20 06:38:10.316395 2026] [security2:error] [pid 966386:tid 966614] [client 34.74.185.202:61064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WsjrLBqY1mBmWu_YDTgAAADQ"]
[Mon Jul 20 06:38:10.342723 2026] [security2:error] [pid 966386:tid 966564] [client 217.142.18.172:37319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WsjrLBqY1mBmWu_YDVAAAAAM"]
[Mon Jul 20 06:38:10.345880 2026] [security2:error] [pid 966386:tid 966564] [client 217.142.18.172:37319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WsjrLBqY1mBmWu_YDVAAAAAM"]
[Mon Jul 20 06:38:10.400864 2026] [security2:error] [pid 966386:tid 966632] [client 77.110.127.138:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WsjrLBqY1mBmWu_YDXAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:10.400971 2026] [security2:error] [pid 966386:tid 966632] [client 77.110.127.138:51518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WsjrLBqY1mBmWu_YDXAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:10.461203 2026] [security2:error] [pid 966386:tid 966561] [client 161.118.195.148:50445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WsjrLBqY1mBmWu_YDYAAAAAE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:10.565130 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsq_X-kAXGDrIFafZWQAAAIs"]
[Mon Jul 20 06:38:10.565283 2026] [security2:error] [pid 953991:tid 954127] [client 77.110.127.138:51548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsq_X-kAXGDrIFafZWQAAAIs"]
[Mon Jul 20 06:38:10.661639 2026] [security2:error] [pid 966386:tid 966567] [client 14.225.17.146:50286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4WsTrLBqY1mBmWu_YDFAAAAAU"], referer: http://dadanetnet.net/OLD
[Mon Jul 20 06:38:10.787303 2026] [security2:error] [pid 966386:tid 966598] [client 34.74.185.202:58531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WsjrLBqY1mBmWu_YDdgAAACQ"]
[Mon Jul 20 06:38:10.947494 2026] [security2:error] [pid 966386:tid 966620] [client 57.141.18.95:59452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WrTrLBqY1mBmWu_YCJAAAOl0"]
[Mon Jul 20 06:38:10.953811 2026] [security2:error] [pid 966386:tid 966671] [client 197.186.66.42:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WsjrLBqY1mBmWu_YDhQAAAGo"]
[Mon Jul 20 06:38:10.961290 2026] [security2:error] [pid 966386:tid 966671] [client 197.186.66.42:60450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WsjrLBqY1mBmWu_YDhQAAAGo"]
[Mon Jul 20 06:38:10.991062 2026] [security2:error] [pid 953991:tid 954205] [client 77.110.127.138:51550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsq_X-kAXGDrIFafZaAAAANk"]
[Mon Jul 20 06:38:10.991219 2026] [security2:error] [pid 953991:tid 954205] [client 77.110.127.138:51550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wsq_X-kAXGDrIFafZaAAAANk"]
[Mon Jul 20 06:38:11.036406 2026] [security2:error] [pid 966386:tid 966688] [client 161.118.195.148:50852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WszrLBqY1mBmWu_YDjwAAAHs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:11.207744 2026] [security2:error] [pid 953991:tid 954122] [client 104.234.53.85:51977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Ws6_X-kAXGDrIFafZcwAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:11.259333 2026] [security2:error] [pid 966386:tid 966690] [client 171.60.139.123:60575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WszrLBqY1mBmWu_YDpAAAAH0"]
[Mon Jul 20 06:38:11.259435 2026] [security2:error] [pid 966386:tid 966690] [client 171.60.139.123:60575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WszrLBqY1mBmWu_YDpAAAAH0"]
[Mon Jul 20 06:38:11.447644 2026] [security2:error] [pid 966386:tid 966582] [client 34.74.185.202:59139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WszrLBqY1mBmWu_YDsAAAABQ"]
[Mon Jul 20 06:38:11.611207 2026] [security2:error] [pid 953991:tid 954213] [client 161.118.195.148:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Ws6_X-kAXGDrIFafZjAAAAOE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:11.781781 2026] [security2:error] [pid 953991:tid 954185] [client 14.225.17.146:62204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4Ws6_X-kAXGDrIFafZigAAAMU"], referer: http://dollpassionista.com/OLD
[Mon Jul 20 06:38:11.805062 2026] [security2:error] [pid 953991:tid 954143] [client 149.88.98.69:27607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.98.88.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "belavistatile.com"] [uri "/xmlrpc.php"] [unique_id "al4Ws6_X-kAXGDrIFafZlwAAAJs"]
[Mon Jul 20 06:38:11.805201 2026] [security2:error] [pid 953991:tid 954143] [client 149.88.98.69:27607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "belavistatile.com"] [uri "/xmlrpc.php"] [unique_id "al4Ws6_X-kAXGDrIFafZlwAAAJs"]
[Mon Jul 20 06:38:11.936198 2026] [security2:error] [pid 953991:tid 954127] [client 34.74.185.202:57909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Ws6_X-kAXGDrIFafZngAAAIs"]
[Mon Jul 20 06:38:11.948851 2026] [security2:error] [pid 966386:tid 966609] [client 103.125.179.95:50171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WszrLBqY1mBmWu_YD0QAAAC8"]
[Mon Jul 20 06:38:11.949008 2026] [security2:error] [pid 966386:tid 966609] [client 103.125.179.95:50171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WszrLBqY1mBmWu_YD0QAAAC8"]
[Mon Jul 20 06:38:12.082606 2026] [security2:error] [pid 966386:tid 966560] [client 57.141.18.23:27976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WrjrLBqY1mBmWu_YCXwAAAHA"]
[Mon Jul 20 06:38:12.182384 2026] [security2:error] [pid 966386:tid 966659] [client 161.118.195.148:51510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WtDrLBqY1mBmWu_YD2wAAAGA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:12.305624 2026] [security2:error] [pid 966386:tid 966611] [client 34.74.185.202:52387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WtDrLBqY1mBmWu_YD6AAAADE"]
[Mon Jul 20 06:38:12.536144 2026] [security2:error] [pid 953991:tid 954226] [client 77.110.127.138:51565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtK_X-kAXGDrIFafZsgAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:12.536268 2026] [security2:error] [pid 953991:tid 954226] [client 77.110.127.138:51565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtK_X-kAXGDrIFafZsgAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:12.605130 2026] [security2:error] [pid 966386:tid 966585] [client 34.74.185.202:61311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4WtDrLBqY1mBmWu_YEAQAAABc"]
[Mon Jul 20 06:38:12.701080 2026] [security2:error] [pid 966386:tid 966637] [client 20.151.10.161:4635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4WtDrLBqY1mBmWu_YEBAAAAEs"]
[Mon Jul 20 06:38:12.701271 2026] [security2:error] [pid 966386:tid 966637] [client 20.151.10.161:4635] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4WtDrLBqY1mBmWu_YEBAAAAEs"]
[Mon Jul 20 06:38:12.750690 2026] [security2:error] [pid 953991:tid 954207] [client 77.110.127.138:51544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/crochet-meetups/"] [unique_id "al4WtK_X-kAXGDrIFafZuQAAANs"]
[Mon Jul 20 06:38:12.763686 2026] [security2:error] [pid 966386:tid 966616] [client 161.118.195.148:51918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WtDrLBqY1mBmWu_YECwAAADY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:12.797995 2026] [security2:error] [pid 953991:tid 954220] [client 39.48.81.23:50419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WtK_X-kAXGDrIFafZvAAAAOg"]
[Mon Jul 20 06:38:12.798131 2026] [security2:error] [pid 953991:tid 954220] [client 39.48.81.23:50419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WtK_X-kAXGDrIFafZvAAAAOg"]
[Mon Jul 20 06:38:12.837160 2026] [security2:error] [pid 953991:tid 954131] [client 20.151.10.161:4653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4WtK_X-kAXGDrIFafZvQAAAI8"]
[Mon Jul 20 06:38:12.837274 2026] [security2:error] [pid 953991:tid 954131] [client 20.151.10.161:4653] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4WtK_X-kAXGDrIFafZvQAAAI8"]
[Mon Jul 20 06:38:12.866523 2026] [security2:error] [pid 953991:tid 954202] [client 34.74.185.202:65243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WtK_X-kAXGDrIFafZvgAAANY"]
[Mon Jul 20 06:38:12.884060 2026] [security2:error] [pid 966386:tid 966677] [client 14.225.17.146:53270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4WtDrLBqY1mBmWu_YECAAAAHA"], referer: https://dollpassionista.com/OLD
[Mon Jul 20 06:38:12.965436 2026] [security2:error] [pid 953991:tid 954134] [client 20.151.10.161:4623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/images.php"] [unique_id "al4WtK_X-kAXGDrIFafZwgAAAJI"]
[Mon Jul 20 06:38:12.965551 2026] [security2:error] [pid 953991:tid 954134] [client 20.151.10.161:4623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/images.php"] [unique_id "al4WtK_X-kAXGDrIFafZwgAAAJI"]
[Mon Jul 20 06:38:13.095637 2026] [security2:error] [pid 966386:tid 966626] [client 20.151.10.161:4648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/for.php"] [unique_id "al4WtTrLBqY1mBmWu_YEFgAAAEA"]
[Mon Jul 20 06:38:13.095742 2026] [security2:error] [pid 966386:tid 966626] [client 20.151.10.161:4648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/for.php"] [unique_id "al4WtTrLBqY1mBmWu_YEFgAAAEA"]
[Mon Jul 20 06:38:13.159849 2026] [security2:error] [pid 966386:tid 966572] [client 34.74.185.202:63508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.thewelloiledlife.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4WtTrLBqY1mBmWu_YEHQAAAAo"]
[Mon Jul 20 06:38:13.226731 2026] [security2:error] [pid 966386:tid 966617] [client 20.151.10.161:4640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/wap1.php"] [unique_id "al4WtTrLBqY1mBmWu_YEKAAAADc"]
[Mon Jul 20 06:38:13.226841 2026] [security2:error] [pid 966386:tid 966617] [client 20.151.10.161:4640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/wap1.php"] [unique_id "al4WtTrLBqY1mBmWu_YEKAAAADc"]
[Mon Jul 20 06:38:13.334527 2026] [security2:error] [pid 966386:tid 966671] [client 161.118.195.148:52304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WtTrLBqY1mBmWu_YELgAAAGo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:13.365168 2026] [security2:error] [pid 953991:tid 954158] [client 20.151.10.161:4293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/adminner.php"] [unique_id "al4Wta_X-kAXGDrIFafZywAAAKo"]
[Mon Jul 20 06:38:13.365271 2026] [security2:error] [pid 953991:tid 954158] [client 20.151.10.161:4293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/adminner.php"] [unique_id "al4Wta_X-kAXGDrIFafZywAAAKo"]
[Mon Jul 20 06:38:13.417204 2026] [security2:error] [pid 953991:tid 954007] [remote 216.73.217.138:3777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4Wta_X-kAXGDrIFafZzQAA1A8"]
[Mon Jul 20 06:38:13.491682 2026] [security2:error] [pid 966386:tid 966556] [remote 5.161.225.162:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4WtTrLBqY1mBmWu_YEOgAAM34"]
[Mon Jul 20 06:38:13.509333 2026] [security2:error] [pid 966386:tid 966588] [client 20.151.10.161:4295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/82.php"] [unique_id "al4WtTrLBqY1mBmWu_YEPAAAABo"]
[Mon Jul 20 06:38:13.509485 2026] [security2:error] [pid 966386:tid 966588] [client 20.151.10.161:4295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/82.php"] [unique_id "al4WtTrLBqY1mBmWu_YEPAAAABo"]
[Mon Jul 20 06:38:13.517645 2026] [security2:error] [pid 966386:tid 966595] [client 112.208.70.94:44393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WtTrLBqY1mBmWu_YEPQAAACE"]
[Mon Jul 20 06:38:13.517773 2026] [security2:error] [pid 966386:tid 966595] [client 112.208.70.94:44393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WtTrLBqY1mBmWu_YEPQAAACE"]
[Mon Jul 20 06:38:13.631195 2026] [security2:error] [pid 966386:tid 966599] [client 20.151.10.161:4302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "representgrace.representgrace.com"] [uri "/kir.php"] [unique_id "al4WtTrLBqY1mBmWu_YEQwAAACU"]
[Mon Jul 20 06:38:13.631303 2026] [security2:error] [pid 966386:tid 966599] [client 20.151.10.161:4302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "representgrace.representgrace.com"] [uri "/kir.php"] [unique_id "al4WtTrLBqY1mBmWu_YEQwAAACU"]
[Mon Jul 20 06:38:13.678989 2026] [security2:error] [pid 953991:tid 954174] [client 14.225.17.146:53328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4Ws6_X-kAXGDrIFafZnQAAALo"], referer: http://cheesewithjam.com/OLD
[Mon Jul 20 06:38:13.709901 2026] [security2:error] [pid 953991:tid 954061] [remote 216.73.217.138:3777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Wta_X-kAXGDrIFafZ0QAAjUU"]
[Mon Jul 20 06:38:13.874235 2026] [security2:error] [pid 953991:tid 954198] [client 14.225.17.146:50319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4Ws6_X-kAXGDrIFafZiwAAANI"]
[Mon Jul 20 06:38:13.958721 2026] [security2:error] [pid 966386:tid 966604] [client 14.225.17.146:53229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4WtTrLBqY1mBmWu_YEUAAAACo"], referer: http://keywayconstructionclt.com/OLD
[Mon Jul 20 06:38:13.995794 2026] [security2:error] [pid 966386:tid 966619] [client 57.141.18.22:32366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WsDrLBqY1mBmWu_YC0wAAORo"]
[Mon Jul 20 06:38:14.010138 2026] [security2:error] [pid 953991:tid 954137] [client 157.66.56.117:58255] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1054"] [id "900998"] [msg "Wordpress Brute Force 15 attempts in 3 Mins. 5 Min block"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4Wta_X-kAXGDrIFafZ3gAAAJU"]
[Mon Jul 20 06:38:14.141202 2026] [security2:error] [pid 953991:tid 954190] [client 158.173.89.95:39465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Wtq_X-kAXGDrIFafZ5gAAAMo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:38:14.303006 2026] [security2:error] [pid 953991:tid 954023] [remote 199.189.225.40:37621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Wtq_X-kAXGDrIFafZ7QABAB8"]
[Mon Jul 20 06:38:14.520315 2026] [security2:error] [pid 953991:tid 954000] [remote 199.189.225.40:37621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Wtq_X-kAXGDrIFafZ9QAArwg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:38:14.618922 2026] [security2:error] [pid 953991:tid 954153] [client 106.219.188.178:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Wtq_X-kAXGDrIFafZ-AAAAKU"]
[Mon Jul 20 06:38:14.619045 2026] [security2:error] [pid 953991:tid 954153] [client 106.219.188.178:42180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Wtq_X-kAXGDrIFafZ-AAAAKU"]
[Mon Jul 20 06:38:14.625779 2026] [security2:error] [pid 966386:tid 966515] [remote 5.161.225.162:57484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4WtjrLBqY1mBmWu_YEeAAANFU"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:38:14.747524 2026] [security2:error] [pid 966386:tid 966626] [client 152.42.250.144:56247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.250.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/index.php"] [unique_id "al4WtjrLBqY1mBmWu_YEgAAAAEA"]
[Mon Jul 20 06:38:14.820169 2026] [security2:error] [pid 953991:tid 954219] [client 14.225.17.146:64819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4Wtq_X-kAXGDrIFafZ6gAAAOc"], referer: http://gearwaterproof.com/OLD
[Mon Jul 20 06:38:14.884453 2026] [security2:error] [pid 966386:tid 966650] [client 152.58.191.29:59775] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WtjrLBqY1mBmWu_YEiwAAAFg"]
[Mon Jul 20 06:38:14.884596 2026] [security2:error] [pid 966386:tid 966650] [client 152.58.191.29:59775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WtjrLBqY1mBmWu_YEiwAAAFg"]
[Mon Jul 20 06:38:14.920257 2026] [security2:error] [pid 953991:tid 954204] [client 57.141.18.43:61670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wsa_X-kAXGDrIFafZFAAA2Ds"]
[Mon Jul 20 06:38:14.949112 2026] [security2:error] [pid 966386:tid 966606] [client 14.225.17.146:60786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4WtjrLBqY1mBmWu_YEjAAAACw"], referer: https://keywayconstructionclt.com/OLD
[Mon Jul 20 06:38:14.981502 2026] [security2:error] [pid 953991:tid 954199] [client 50.116.65.227:34632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Wtq_X-kAXGDrIFafaAgAAANM"]
[Mon Jul 20 06:38:14.992316 2026] [security2:error] [pid 966386:tid 966618] [client 50.116.65.227:34642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WtjrLBqY1mBmWu_YEmQAAADg"]
[Mon Jul 20 06:38:14.992916 2026] [security2:error] [pid 966386:tid 966488] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WtjrLBqY1mBmWu_YEmgAASzo"]
[Mon Jul 20 06:38:14.993101 2026] [security2:error] [pid 966386:tid 966637] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WtjrLBqY1mBmWu_YEmgAASzo"]
[Mon Jul 20 06:38:15.135260 2026] [security2:error] [pid 953991:tid 954138] [client 57.141.18.101:45288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wsa_X-kAXGDrIFafZMwAAlio"]
[Mon Jul 20 06:38:15.397312 2026] [security2:error] [pid 966386:tid 966677] [client 77.110.127.138:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtzrLBqY1mBmWu_YEtgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:15.397429 2026] [security2:error] [pid 966386:tid 966677] [client 77.110.127.138:51524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtzrLBqY1mBmWu_YEtgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:15.490519 2026] [security2:error] [pid 953991:tid 954041] [remote 45.90.123.233:53692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Wt6_X-kAXGDrIFafaDQAAnTE"]
[Mon Jul 20 06:38:15.593083 2026] [security2:error] [pid 966386:tid 966574] [client 50.116.65.227:34656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WtzrLBqY1mBmWu_YEsQAAAAw"]
[Mon Jul 20 06:38:15.593577 2026] [security2:error] [pid 966386:tid 966615] [client 77.110.127.138:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtzrLBqY1mBmWu_YExAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:15.593689 2026] [security2:error] [pid 966386:tid 966615] [client 77.110.127.138:51552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtzrLBqY1mBmWu_YExAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:15.767026 2026] [security2:error] [pid 966386:tid 966664] [client 77.110.127.138:51579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtzrLBqY1mBmWu_YE1AAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:15.767132 2026] [security2:error] [pid 966386:tid 966664] [client 77.110.127.138:51579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WtzrLBqY1mBmWu_YE1AAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:15.792168 2026] [security2:error] [pid 966386:tid 966609] [client 50.116.65.227:34674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4WtzrLBqY1mBmWu_YExgAAAC8"]
[Mon Jul 20 06:38:15.862997 2026] [security2:error] [pid 953991:tid 954117] [remote 45.90.123.233:53692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Wt6_X-kAXGDrIFafaGwAA0X0"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:38:15.941707 2026] [security2:error] [pid 953991:tid 954160] [client 187.108.85.186:65506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Wt6_X-kAXGDrIFafaHAAAAKw"]
[Mon Jul 20 06:38:15.941860 2026] [security2:error] [pid 953991:tid 954160] [client 187.108.85.186:65506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Wt6_X-kAXGDrIFafaHAAAAKw"]
[Mon Jul 20 06:38:16.173773 2026] [security2:error] [pid 953991:tid 954244] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wt6_X-kAXGDrIFafaHQAAAQA"], referer: 1'"3000
[Mon Jul 20 06:38:16.196004 2026] [security2:error] [pid 953991:tid 954133] [client 57.141.18.125:28760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wsq_X-kAXGDrIFafZXAAAkWo"]
[Mon Jul 20 06:38:16.543170 2026] [security2:error] [pid 953991:tid 954241] [client 57.141.18.22:32378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wsq_X-kAXGDrIFafZZwAA_QA"]
[Mon Jul 20 06:38:16.674379 2026] [security2:error] [pid 966386:tid 966643] [client 77.110.127.138:51556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WuDrLBqY1mBmWu_YE-wAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:16.674475 2026] [security2:error] [pid 966386:tid 966643] [client 77.110.127.138:51556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WuDrLBqY1mBmWu_YE-wAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:16.824266 2026] [security2:error] [pid 953991:tid 954177] [client 77.110.127.138:51584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WuK_X-kAXGDrIFafaOQAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:16.824391 2026] [security2:error] [pid 953991:tid 954177] [client 77.110.127.138:51584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WuK_X-kAXGDrIFafaOQAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:17.188249 2026] [security2:error] [pid 966386:tid 966587] [client 57.141.18.27:41122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WszrLBqY1mBmWu_YDtAAAGWA"]
[Mon Jul 20 06:38:17.226963 2026] [security2:error] [pid 953991:tid 954140] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WuK_X-kAXGDrIFafaQQAAAJg"], referer: 1'"3000
[Mon Jul 20 06:38:17.329897 2026] [security2:error] [pid 953991:tid 954149] [client 77.110.127.138:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wua_X-kAXGDrIFafaTAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:17.329976 2026] [security2:error] [pid 953991:tid 954149] [client 77.110.127.138:51587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wua_X-kAXGDrIFafaTAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:17.445221 2026] [security2:error] [pid 953991:tid 954218] [client 161.118.195.148:52699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wua_X-kAXGDrIFafaUwAAAOY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:17.648177 2026] [security2:error] [pid 953991:tid 954173] [client 14.225.17.146:64416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4Wua_X-kAXGDrIFafaVQAAALk"], referer: http://katsklar.com/OLD
[Mon Jul 20 06:38:17.854095 2026] [security2:error] [pid 966386:tid 966685] [client 104.234.53.63:32687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4WuTrLBqY1mBmWu_YFQAAAAHg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:18.026331 2026] [security2:error] [pid 953991:tid 954237] [client 161.118.195.148:55532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wuq_X-kAXGDrIFafaZAAAAPk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:18.064518 2026] [security2:error] [pid 966386:tid 966600] [client 77.110.127.138:51573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WujrLBqY1mBmWu_YFTwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:18.064616 2026] [security2:error] [pid 966386:tid 966600] [client 77.110.127.138:51573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WujrLBqY1mBmWu_YFTwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:18.200153 2026] [security2:error] [pid 966386:tid 966602] [client 103.238.106.162:63599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WujrLBqY1mBmWu_YFVAAAACg"]
[Mon Jul 20 06:38:18.200266 2026] [security2:error] [pid 966386:tid 966602] [client 103.238.106.162:63599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WujrLBqY1mBmWu_YFVAAAACg"]
[Mon Jul 20 06:38:18.478923 2026] [security2:error] [pid 966386:tid 966609] [client 14.225.17.146:60793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4WujrLBqY1mBmWu_YFTQAAAC8"], referer: http://uritems.net/OLD
[Mon Jul 20 06:38:18.605245 2026] [security2:error] [pid 953991:tid 954193] [client 161.118.195.148:55998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wuq_X-kAXGDrIFafafgAAAM0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:18.730154 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/integrations/jrv7zlx7n60y.php"] [unique_id "al4WujrLBqY1mBmWu_YFdQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:18.760765 2026] [autoindex:error] [pid 966386:tid 966626] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/integrations/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:38:18.763951 2026] [security2:error] [pid 953991:tid 954242] [client 62.150.67.110:19746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4Wuq_X-kAXGDrIFafaaAAAAP4"]
[Mon Jul 20 06:38:18.888685 2026] [autoindex:error] [pid 966386:tid 966629] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/integrations/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:38:18.902329 2026] [security2:error] [pid 953991:tid 954175] [client 14.225.17.146:50550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4Wuq_X-kAXGDrIFafagQAAALs"], referer: http://nextlvlmarketingco.com/OLD
[Mon Jul 20 06:38:19.009296 2026] [autoindex:error] [pid 953991:tid 954234] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/integrations/stripe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:38:19.010227 2026] [security2:error] [pid 966386:tid 966577] [client 77.110.127.138:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/integrations/stripe/eq9u5lrntoc5.php"] [unique_id "al4WuzrLBqY1mBmWu_YFmwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:19.113051 2026] [autoindex:error] [pid 966386:tid 966593] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/integrations/stripe/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:38:19.185853 2026] [security2:error] [pid 953991:tid 954161] [client 161.118.195.148:56450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wu6_X-kAXGDrIFafajAAAAK0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:19.227733 2026] [security2:error] [pid 966386:tid 966567] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WujrLBqY1mBmWu_YFfAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:19.285693 2026] [security2:error] [pid 966386:tid 966674] [client 77.110.127.138:51603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WujrLBqY1mBmWu_YFiwAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:19.307197 2026] [security2:error] [pid 966386:tid 966582] [client 104.234.53.63:32687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4WuzrLBqY1mBmWu_YFsAAAABQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:19.409427 2026] [security2:error] [pid 966386:tid 966595] [client 223.185.13.213:3696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WuzrLBqY1mBmWu_YFuwAAACE"]
[Mon Jul 20 06:38:19.409530 2026] [security2:error] [pid 966386:tid 966595] [client 223.185.13.213:3696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WuzrLBqY1mBmWu_YFuwAAACE"]
[Mon Jul 20 06:38:19.454304 2026] [security2:error] [pid 966386:tid 966596] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WuzrLBqY1mBmWu_YFogAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:19.491698 2026] [security2:error] [pid 966386:tid 966588] [client 77.110.127.138:51567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WuzrLBqY1mBmWu_YFngAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:19.732771 2026] [security2:error] [pid 966386:tid 966621] [client 65.1.132.125:52960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WuzrLBqY1mBmWu_YF1AAAADs"]
[Mon Jul 20 06:38:19.764630 2026] [security2:error] [pid 953991:tid 954176] [client 161.118.195.148:56889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wu6_X-kAXGDrIFafangAAALw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:19.797120 2026] [security2:error] [pid 966386:tid 966579] [client 34.139.11.221:57345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WuzrLBqY1mBmWu_YF2wAAABE"]
[Mon Jul 20 06:38:19.853146 2026] [security2:error] [pid 953991:tid 954222] [client 14.225.17.146:60977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Wua_X-kAXGDrIFafaWwAAAOo"], referer: http://floorsourcestock.com/OLD
[Mon Jul 20 06:38:19.961814 2026] [security2:error] [pid 966386:tid 966686] [client 34.139.11.221:62953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4WuzrLBqY1mBmWu_YF5QAAAHk"]
[Mon Jul 20 06:38:19.993412 2026] [security2:error] [pid 966386:tid 966594] [client 57.141.18.72:30504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WtjrLBqY1mBmWu_YEXAAAIBs"]
[Mon Jul 20 06:38:20.053360 2026] [security2:error] [pid 953991:tid 954151] [client 77.110.127.138:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WvK_X-kAXGDrIFafapQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:20.053468 2026] [security2:error] [pid 953991:tid 954151] [client 77.110.127.138:51614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WvK_X-kAXGDrIFafapQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:20.145802 2026] [security2:error] [pid 966386:tid 966688] [client 34.139.11.221:55695] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WvDrLBqY1mBmWu_YF9AAAAHs"]
[Mon Jul 20 06:38:20.289862 2026] [security2:error] [pid 953991:tid 954132] [client 34.139.11.221:63015] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WvK_X-kAXGDrIFafaqgAAAJA"]
[Mon Jul 20 06:38:20.327863 2026] [security2:error] [pid 966386:tid 966570] [client 171.61.165.146:12008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WvDrLBqY1mBmWu_YGBgAAAAg"]
[Mon Jul 20 06:38:20.327985 2026] [security2:error] [pid 966386:tid 966570] [client 171.61.165.146:12008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4WvDrLBqY1mBmWu_YGBgAAAAg"]
[Mon Jul 20 06:38:20.340375 2026] [security2:error] [pid 966386:tid 966670] [client 161.118.195.148:57332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WvDrLBqY1mBmWu_YGCQAAAGk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:20.436339 2026] [security2:error] [pid 966386:tid 966536] [remote 47.128.58.176:11076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gertoger.org"] [uri "/tour/mongolia-nomad-homestay-live-like-a-local-nomad-mongolia/"] [unique_id "al4WvDrLBqY1mBmWu_YGEgAAeWo"]
[Mon Jul 20 06:38:20.520916 2026] [security2:error] [pid 953991:tid 954147] [client 34.139.11.221:52176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4WvK_X-kAXGDrIFafasQAAAJ8"]
[Mon Jul 20 06:38:20.697674 2026] [security2:error] [pid 953991:tid 954155] [client 43.205.139.3:46024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WvK_X-kAXGDrIFafatQAAAKc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:38:20.717891 2026] [security2:error] [pid 953991:tid 954191] [client 34.139.11.221:50787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WvK_X-kAXGDrIFafatgAAAMs"]
[Mon Jul 20 06:38:20.877805 2026] [security2:error] [pid 953991:tid 954226] [client 217.142.18.172:50329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WvK_X-kAXGDrIFafauQAAAO4"]
[Mon Jul 20 06:38:20.888318 2026] [security2:error] [pid 953991:tid 954226] [client 217.142.18.172:50329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4WvK_X-kAXGDrIFafauQAAAO4"]
[Mon Jul 20 06:38:20.903034 2026] [security2:error] [pid 953991:tid 954142] [client 34.139.11.221:51937] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4WvK_X-kAXGDrIFafavAAAAJo"]
[Mon Jul 20 06:38:20.918706 2026] [security2:error] [pid 953991:tid 954213] [client 161.118.195.148:57767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WvK_X-kAXGDrIFafavQAAAOE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:21.051240 2026] [security2:error] [pid 966386:tid 966586] [client 57.141.18.31:25866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WtzrLBqY1mBmWu_YEoAAAGDw"]
[Mon Jul 20 06:38:21.094596 2026] [security2:error] [pid 966386:tid 966590] [client 34.139.11.221:65308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4WvTrLBqY1mBmWu_YGMgAAABw"]
[Mon Jul 20 06:38:21.169711 2026] [security2:error] [pid 953991:tid 954164] [client 77.110.127.138:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-tips/c1q02yqj9yxo.php"] [unique_id "al4Wva_X-kAXGDrIFafaxQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:21.225454 2026] [security2:error] [pid 953991:tid 954136] [client 104.234.53.59:31491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Wva_X-kAXGDrIFafayAAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:21.381596 2026] [security2:error] [pid 953991:tid 954165] [client 34.139.11.221:57894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Wva_X-kAXGDrIFafa1AAAALE"]
[Mon Jul 20 06:38:21.403993 2026] [security2:error] [pid 966386:tid 966661] [client 77.110.127.138:51578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGNwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:21.497556 2026] [security2:error] [pid 966386:tid 966688] [client 161.118.195.148:58214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGXgAAAHs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:21.544057 2026] [security2:error] [pid 966386:tid 966606] [client 197.186.66.42:60978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WvTrLBqY1mBmWu_YGYgAAACw"]
[Mon Jul 20 06:38:21.544198 2026] [security2:error] [pid 966386:tid 966606] [client 197.186.66.42:60978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WvTrLBqY1mBmWu_YGYgAAACw"]
[Mon Jul 20 06:38:21.552220 2026] [security2:error] [pid 966386:tid 966665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGQAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:21.593503 2026] [security2:error] [pid 966386:tid 966572] [client 34.139.11.221:62318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4WvTrLBqY1mBmWu_YGZQAAAAo"]
[Mon Jul 20 06:38:21.645098 2026] [security2:error] [pid 966386:tid 966607] [client 212.119.227.172:63310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "grndl.com"] [uri "/"] [unique_id "al4WvTrLBqY1mBmWu_YGZwAAAC0"]
[Mon Jul 20 06:38:21.814717 2026] [security2:error] [pid 966386:tid 966580] [client 216.73.217.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGbAAAEno"]
[Mon Jul 20 06:38:21.845230 2026] [security2:error] [pid 966386:tid 966692] [client 34.139.11.221:51911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4WvTrLBqY1mBmWu_YGcAAAAH8"]
[Mon Jul 20 06:38:21.943102 2026] [security2:error] [pid 953991:tid 954174] [client 171.60.139.123:61098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Wva_X-kAXGDrIFafa6gAAALo"]
[Mon Jul 20 06:38:21.943259 2026] [security2:error] [pid 953991:tid 954174] [client 171.60.139.123:61098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4Wva_X-kAXGDrIFafa6gAAALo"]
[Mon Jul 20 06:38:22.003696 2026] [security2:error] [pid 953991:tid 954132] [client 34.139.11.221:51598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.awj.kzx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Wvq_X-kAXGDrIFafa6wAAAJA"]
[Mon Jul 20 06:38:22.008679 2026] [security2:error] [pid 966386:tid 966677] [client 57.141.18.97:62064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WtzrLBqY1mBmWu_YE3AAAcBc"]
[Mon Jul 20 06:38:22.031709 2026] [security2:error] [pid 966386:tid 966473] [remote 124.55.178.99:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4WvjrLBqY1mBmWu_YGfQAAHy0"]
[Mon Jul 20 06:38:22.074522 2026] [security2:error] [pid 953991:tid 954198] [client 161.118.195.148:58579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wvq_X-kAXGDrIFafa7AAAANI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:22.139387 2026] [security2:error] [pid 966386:tid 966560] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGRAAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:22.261870 2026] [security2:error] [pid 966386:tid 966690] [client 77.110.127.138:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/hpslfk2n2bl9.php"] [unique_id "al4WvjrLBqY1mBmWu_YGjgAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:22.352116 2026] [security2:error] [pid 966386:tid 966543] [remote 216.73.217.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGdwAAGnE"], referer: https://lowelldrycleaners.com/sitemap.xml
[Mon Jul 20 06:38:22.353648 2026] [security2:error] [pid 966386:tid 966471] [remote 95.217.78.234:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WvjrLBqY1mBmWu_YGkQAALSs"]
[Mon Jul 20 06:38:22.369921 2026] [security2:error] [pid 966386:tid 966622] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGTgAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:22.472127 2026] [security2:error] [pid 966386:tid 966541] [remote 124.55.178.99:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4WvjrLBqY1mBmWu_YGmQAAYW8"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 06:38:22.517989 2026] [security2:error] [pid 966386:tid 966599] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGWwAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:22.562014 2026] [security2:error] [pid 966386:tid 966649] [client 77.110.127.138:51627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGYAAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:22.573695 2026] [security2:error] [pid 953991:tid 954172] [client 77.110.127.138:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page/nb3uz9a3xo7f.php"] [unique_id "al4Wvq_X-kAXGDrIFafa_gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:22.600862 2026] [security2:error] [pid 966386:tid 966540] [remote 95.217.78.234:54970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WvjrLBqY1mBmWu_YGpgAATm4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:38:22.622172 2026] [security2:error] [pid 966386:tid 966511] [remote 154.66.198.148:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4WvjrLBqY1mBmWu_YGqQAAQlE"]
[Mon Jul 20 06:38:22.658910 2026] [security2:error] [pid 966386:tid 966651] [client 161.118.195.148:58997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WvjrLBqY1mBmWu_YGsAAAAFk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:23.028219 2026] [security2:error] [pid 953991:tid 954230] [client 14.225.17.146:50567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4Wva_X-kAXGDrIFafa3gAAAPI"], referer: http://momheadquarters.com/OLD
[Mon Jul 20 06:38:23.176959 2026] [security2:error] [pid 966386:tid 966449] [remote 154.66.198.148:7436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4WvzrLBqY1mBmWu_YGygAAHRY"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:38:23.252835 2026] [security2:error] [pid 966386:tid 966622] [client 161.118.195.148:59452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WvzrLBqY1mBmWu_YGzwAAADw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:23.719091 2026] [security2:error] [pid 953991:tid 954179] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wvq_X-kAXGDrIFafa_QAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:23.751589 2026] [security2:error] [pid 966386:tid 966633] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvjrLBqY1mBmWu_YGqAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:23.802304 2026] [security2:error] [pid 953991:tid 954175] [client 77.110.127.138:51636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wvq_X-kAXGDrIFafbAAAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:23.838034 2026] [security2:error] [pid 953991:tid 954211] [client 51.68.107.137:19425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "maplerespiteservices.com"] [uri "/robots.txt"] [unique_id "al4Wv6_X-kAXGDrIFafbHAAAAN8"]
[Mon Jul 20 06:38:23.838154 2026] [security2:error] [pid 953991:tid 954211] [client 51.68.107.137:19425] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "maplerespiteservices.com"] [uri "/robots.txt"] [unique_id "al4Wv6_X-kAXGDrIFafbHAAAAN8"]
[Mon Jul 20 06:38:23.841652 2026] [security2:error] [pid 966386:tid 966602] [client 161.118.195.148:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WvzrLBqY1mBmWu_YHBAAAACg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:23.941005 2026] [security2:error] [pid 966386:tid 966599] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvzrLBqY1mBmWu_YG1gAAACU"]
[Mon Jul 20 06:38:23.983770 2026] [security2:error] [pid 966386:tid 966685] [client 106.219.188.178:8591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WvzrLBqY1mBmWu_YHDAAAAHg"]
[Mon Jul 20 06:38:23.984269 2026] [security2:error] [pid 966386:tid 966685] [client 106.219.188.178:8591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WvzrLBqY1mBmWu_YHDAAAAHg"]
[Mon Jul 20 06:38:24.016649 2026] [security2:error] [pid 966386:tid 966589] [client 77.110.127.138:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page/2/rls3y54q31d8.php"] [unique_id "al4WwDrLBqY1mBmWu_YHDgAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:24.130508 2026] [security2:error] [pid 966386:tid 966621] [client 39.48.81.23:50940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WwDrLBqY1mBmWu_YHFwAAADs"]
[Mon Jul 20 06:38:24.130658 2026] [security2:error] [pid 966386:tid 966621] [client 39.48.81.23:50940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WwDrLBqY1mBmWu_YHFwAAADs"]
[Mon Jul 20 06:38:24.191144 2026] [security2:error] [pid 953991:tid 954131] [client 65.1.132.125:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4WwK_X-kAXGDrIFafbKAAAAI8"]
[Mon Jul 20 06:38:24.209792 2026] [security2:error] [pid 966386:tid 966682] [client 112.208.70.94:44826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WwDrLBqY1mBmWu_YHHgAAAHU"]
[Mon Jul 20 06:38:24.209904 2026] [security2:error] [pid 966386:tid 966682] [client 112.208.70.94:44826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WwDrLBqY1mBmWu_YHHgAAAHU"]
[Mon Jul 20 06:38:24.424164 2026] [security2:error] [pid 953991:tid 954199] [client 161.118.195.148:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WwK_X-kAXGDrIFafbMAAAANM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:24.555271 2026] [proxy:error] [pid 966386:tid 966601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:24.555305 2026] [proxy_http:error] [pid 966386:tid 966601] [client 198.235.24.54:61534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:24.555855 2026] [proxy:error] [pid 966386:tid 966601] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:24.555879 2026] [proxy_http:error] [pid 966386:tid 966601] [client 198.235.24.54:61534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:24.640254 2026] [security2:error] [pid 966386:tid 966635] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvzrLBqY1mBmWu_YG0wAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:24.783816 2026] [security2:error] [pid 966386:tid 966643] [client 104.234.53.77:34261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4WwDrLBqY1mBmWu_YHSQAAAFE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:24.790729 2026] [security2:error] [pid 966386:tid 966598] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WvzrLBqY1mBmWu_YHBQAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:24.927893 2026] [security2:error] [pid 966386:tid 966440] [remote 47.86.33.52:55402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4WwDrLBqY1mBmWu_YHUgAAWA0"]
[Mon Jul 20 06:38:24.945440 2026] [security2:error] [pid 966386:tid 966628] [client 77.110.127.138:51644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwDrLBqY1mBmWu_YHEQAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:24.995722 2026] [security2:error] [pid 966386:tid 966651] [client 50.116.65.227:11050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/08/IMG_8766.jpeg"] [unique_id "al4WwDrLBqY1mBmWu_YHVwAAAHc"]
[Mon Jul 20 06:38:25.022999 2026] [security2:error] [pid 966386:tid 966681] [client 161.118.195.148:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WwTrLBqY1mBmWu_YHWwAAAHQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:25.365463 2026] [security2:error] [pid 966386:tid 966532] [remote 57.141.18.61:26674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4910317"] [unique_id "al4WwTrLBqY1mBmWu_YHbQAAcWY"]
[Mon Jul 20 06:38:25.387317 2026] [security2:error] [pid 966386:tid 966688] [client 65.1.132.125:52982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4WwTrLBqY1mBmWu_YHbwAAAHs"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:38:25.389963 2026] [security2:error] [pid 966386:tid 966625] [client 57.141.18.57:27800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WujrLBqY1mBmWu_YFZgAAP2w"]
[Mon Jul 20 06:38:25.429169 2026] [security2:error] [pid 966386:tid 966575] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwDrLBqY1mBmWu_YHJQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:25.604312 2026] [security2:error] [pid 966386:tid 966644] [client 161.118.195.148:61223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WwTrLBqY1mBmWu_YHfAAAAFI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:25.694283 2026] [security2:error] [pid 966386:tid 966629] [client 77.110.127.138:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-tutor/w4rtxkqqxnju.php"] [unique_id "al4WwTrLBqY1mBmWu_YHiAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:25.715847 2026] [security2:error] [pid 953991:tid 954133] [client 14.225.17.146:54650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4Wv6_X-kAXGDrIFafbEAAAAJE"], referer: http://areitoproducciones.com/OLD
[Mon Jul 20 06:38:25.716355 2026] [autoindex:error] [pid 966386:tid 966623] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:38:25.716917 2026] [security2:error] [pid 966386:tid 966484] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WwTrLBqY1mBmWu_YHjgAAajY"]
[Mon Jul 20 06:38:25.717058 2026] [security2:error] [pid 966386:tid 966671] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WwTrLBqY1mBmWu_YHjgAAajY"]
[Mon Jul 20 06:38:25.717604 2026] [security2:error] [pid 953991:tid 954229] [client 45.157.112.60:36297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Wwa_X-kAXGDrIFafbWAAAAPE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:38:25.730784 2026] [autoindex:error] [pid 953991:tid 954247] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.023334 2026] [security2:error] [pid 966386:tid 966617] [client 77.110.127.138:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2016/opfrsnmv1km0.php"] [unique_id "al4WwjrLBqY1mBmWu_YHqgAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.073054 2026] [security2:error] [pid 966386:tid 966626] [client 152.58.191.29:50947] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WwjrLBqY1mBmWu_YHrAAAAEA"]
[Mon Jul 20 06:38:26.074716 2026] [security2:error] [pid 966386:tid 966626] [client 152.58.191.29:50947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WwjrLBqY1mBmWu_YHrAAAAEA"]
[Mon Jul 20 06:38:26.101092 2026] [security2:error] [pid 953991:tid 954143] [client 77.110.127.138:51636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wwq_X-kAXGDrIFafbZgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.101162 2026] [security2:error] [pid 953991:tid 954143] [client 77.110.127.138:51636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Wwq_X-kAXGDrIFafbZgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.187080 2026] [security2:error] [pid 953991:tid 954140] [client 161.118.195.148:61661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wwq_X-kAXGDrIFafbbAAAAJg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:26.445357 2026] [security2:error] [pid 953991:tid 954194] [client 77.110.127.138:51607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wwa_X-kAXGDrIFafbTQAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.445799 2026] [security2:error] [pid 953991:tid 954138] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wwa_X-kAXGDrIFafbTgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.518244 2026] [security2:error] [pid 953991:tid 954125] [client 57.141.18.86:57134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wu6_X-kAXGDrIFafanQAAiS0"]
[Mon Jul 20 06:38:26.555721 2026] [security2:error] [pid 953991:tid 954213] [client 187.108.85.186:49677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Wwq_X-kAXGDrIFafbegAAAOE"]
[Mon Jul 20 06:38:26.555846 2026] [security2:error] [pid 953991:tid 954213] [client 187.108.85.186:49677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Wwq_X-kAXGDrIFafbegAAAOE"]
[Mon Jul 20 06:38:26.599220 2026] [security2:error] [pid 953991:tid 954211] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wwa_X-kAXGDrIFafbVwAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.686386 2026] [security2:error] [pid 966386:tid 966513] [remote 199.189.225.40:55943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4WwjrLBqY1mBmWu_YH0wAAD1M"]
[Mon Jul 20 06:38:26.764879 2026] [security2:error] [pid 966386:tid 966588] [client 161.118.195.148:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WwjrLBqY1mBmWu_YH2AAAABo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:26.890638 2026] [security2:error] [pid 966386:tid 966462] [remote 199.189.225.40:55943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4WwjrLBqY1mBmWu_YH3wAAFSI"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:38:26.891428 2026] [security2:error] [pid 966386:tid 966572] [client 77.110.127.138:51605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwjrLBqY1mBmWu_YHpgAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:26.918963 2026] [security2:error] [pid 953991:tid 954149] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wwq_X-kAXGDrIFafbYgAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.029639 2026] [security2:error] [pid 966386:tid 966672] [client 57.141.18.84:32776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WvDrLBqY1mBmWu_YF6gAAawE"]
[Mon Jul 20 06:38:27.045676 2026] [security2:error] [pid 966386:tid 966651] [client 77.110.127.138:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2016/11/9n2l147vbp1a.php"] [unique_id "al4WwzrLBqY1mBmWu_YH8AAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.065797 2026] [security2:error] [pid 966386:tid 966650] [client 50.116.65.227:11106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4WwzrLBqY1mBmWu_YH9QAAAFg"]
[Mon Jul 20 06:38:27.077502 2026] [security2:error] [pid 966386:tid 966568] [client 50.116.65.227:11110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4WwzrLBqY1mBmWu_YH9wAAAAY"]
[Mon Jul 20 06:38:27.091170 2026] [autoindex:error] [pid 966386:tid 966673] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.182571 2026] [autoindex:error] [pid 966386:tid 966649] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:38:27.294945 2026] [autoindex:error] [pid 966386:tid 966574] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/category/charity/
[Mon Jul 20 06:38:27.338805 2026] [security2:error] [pid 966386:tid 966611] [client 161.118.195.148:62570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIHgAAADE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:27.339937 2026] [security2:error] [pid 966386:tid 966589] [client 77.110.127.138:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/learn-to-crochet-faqs/rvxq9r0v6nwd.php"] [unique_id "al4WwzrLBqY1mBmWu_YIHwAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.358579 2026] [security2:error] [pid 966386:tid 966637] [client 57.141.18.115:37138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WvDrLBqY1mBmWu_YF_QAASyc"]
[Mon Jul 20 06:38:27.454516 2026] [security2:error] [pid 966386:tid 966511] [remote 47.86.33.52:55402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4WwzrLBqY1mBmWu_YINAAAIlE"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:38:27.474569 2026] [security2:error] [pid 966386:tid 966601] [client 77.110.127.138:51647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YH8QAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.518263 2026] [security2:error] [pid 966386:tid 966679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YH-QAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.660435 2026] [security2:error] [pid 966386:tid 966569] [client 77.110.127.138:51604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIIAAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.700480 2026] [security2:error] [pid 966386:tid 966678] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIIQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.703073 2026] [security2:error] [pid 966386:tid 966640] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIOQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.706120 2026] [security2:error] [pid 966386:tid 966609] [client 57.141.18.107:22618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WvDrLBqY1mBmWu_YGHgAAL1I"]
[Mon Jul 20 06:38:27.755551 2026] [security2:error] [pid 953991:tid 954132] [client 14.225.17.146:55964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4Wwq_X-kAXGDrIFafbbgAAAJA"], referer: http://chestermonty.com/OLD
[Mon Jul 20 06:38:27.899738 2026] [security2:error] [pid 966386:tid 966629] [client 77.110.127.138:51653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet/ws7je2d89jo0.php"] [unique_id "al4WwzrLBqY1mBmWu_YIXQAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:27.918295 2026] [security2:error] [pid 966386:tid 966638] [client 161.118.195.148:62999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WwzrLBqY1mBmWu_YIZAAAAEw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:28.163159 2026] [security2:error] [pid 966386:tid 966623] [client 14.225.17.146:52661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIPwAAAD0"]
[Mon Jul 20 06:38:28.191217 2026] [security2:error] [pid 966386:tid 966641] [client 57.141.18.14:36702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WvTrLBqY1mBmWu_YGMAAATzo"]
[Mon Jul 20 06:38:28.351288 2026] [http2:info] [pid 983757:tid 983757] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:38:28.396731 2026] [security2:error] [pid 966386:tid 966574] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIZQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:28.435667 2026] [security2:error] [pid 966386:tid 966432] [remote 45.252.249.226:45588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.249.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4WxDrLBqY1mBmWu_YIogAAGQU"]
[Mon Jul 20 06:38:28.466763 2026] [security2:error] [pid 966386:tid 966613] [client 18.141.57.241:42886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WxDrLBqY1mBmWu_YIpAAAADM"]
[Mon Jul 20 06:38:28.483426 2026] [security2:error] [pid 966386:tid 966595] [client 77.110.127.138:51652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIZgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:28.494537 2026] [security2:error] [pid 966386:tid 966626] [client 161.118.195.148:63436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WxDrLBqY1mBmWu_YIpwAAAEA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:28.536355 2026] [security2:error] [pid 966386:tid 966590] [client 167.71.6.96:52614] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4WxDrLBqY1mBmWu_YIqAAAABw"]
[Mon Jul 20 06:38:28.560726 2026] [security2:error] [pid 966386:tid 966600] [client 45.3.44.113:47933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WxDrLBqY1mBmWu_YIqgAAACY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:38:28.585056 2026] [security2:error] [pid 983757:tid 983893] [client 77.110.127.138:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-courses/1z3a2qwzgfnn.php"] [unique_id "al4WxHKwMdFW9UVnNBSKTAAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:28.714816 2026] [security2:error] [pid 966386:tid 966662] [client 103.238.106.162:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WxDrLBqY1mBmWu_YItAAAAGM"]
[Mon Jul 20 06:38:28.714912 2026] [security2:error] [pid 966386:tid 966662] [client 103.238.106.162:60626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4WxDrLBqY1mBmWu_YItAAAAGM"]
[Mon Jul 20 06:38:28.926972 2026] [security2:error] [pid 983757:tid 983894] [client 14.225.17.146:54428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4WxHKwMdFW9UVnNBSKVQAAAQ8"], referer: https://chestermonty.com/OLD
[Mon Jul 20 06:38:29.070678 2026] [security2:error] [pid 966386:tid 966670] [client 161.118.195.148:63887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WxTrLBqY1mBmWu_YIzgAAAGk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:29.117531 2026] [security2:error] [pid 966386:tid 966647] [client 14.225.17.146:65532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4WxDrLBqY1mBmWu_YInwAAAFU"], referer: http://idigress.studio/OLD
[Mon Jul 20 06:38:29.123374 2026] [security2:error] [pid 966386:tid 966439] [remote 45.252.249.226:45588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.249.252.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4WxTrLBqY1mBmWu_YI1AAAJgw"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:38:29.211966 2026] [security2:error] [pid 966386:tid 966649] [client 223.185.13.213:26439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WxTrLBqY1mBmWu_YI3AAAAFc"]
[Mon Jul 20 06:38:29.212104 2026] [security2:error] [pid 966386:tid 966649] [client 223.185.13.213:26439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4WxTrLBqY1mBmWu_YI3AAAAFc"]
[Mon Jul 20 06:38:29.301985 2026] [security2:error] [pid 966386:tid 966606] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YIagAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:29.474469 2026] [security2:error] [pid 983757:tid 983937] [client 18.140.64.130:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4WxXKwMdFW9UVnNBSKZwAAATo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:38:29.568299 2026] [security2:error] [pid 966386:tid 966615] [client 77.110.127.138:51612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxDrLBqY1mBmWu_YIrgAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:29.627498 2026] [security2:error] [pid 966386:tid 966603] [client 34.147.16.58:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.ebm.tmu.mybluehost.me"] [uri "/"] [unique_id "al4WxTrLBqY1mBmWu_YI7QAAACk"]
[Mon Jul 20 06:38:29.627587 2026] [security2:error] [pid 966386:tid 966603] [client 34.147.16.58:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ebm.tmu.mybluehost.me"] [uri "/"] [unique_id "al4WxTrLBqY1mBmWu_YI7QAAACk"]
[Mon Jul 20 06:38:29.638984 2026] [security2:error] [pid 983757:tid 983899] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxHKwMdFW9UVnNBSKTwAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:29.646227 2026] [security2:error] [pid 983757:tid 983946] [client 161.118.195.148:64344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WxXKwMdFW9UVnNBSKawAAAUM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:29.676266 2026] [security2:error] [pid 966386:tid 966663] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxDrLBqY1mBmWu_YIuQAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:29.705717 2026] [security2:error] [pid 983757:tid 983949] [client 3.67.192.83:54704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WxXKwMdFW9UVnNBSKbQAAAUY"]
[Mon Jul 20 06:38:29.705874 2026] [security2:error] [pid 983757:tid 983949] [client 3.67.192.83:54704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4WxXKwMdFW9UVnNBSKbQAAAUY"]
[Mon Jul 20 06:38:29.800261 2026] [security2:error] [pid 966386:tid 966593] [client 57.141.18.0:41928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WvjrLBqY1mBmWu_YGrQAAH2A"]
[Mon Jul 20 06:38:29.841967 2026] [security2:error] [pid 953991:tid 954006] [remote 57.141.18.115:37146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wvq_X-kAXGDrIFafbBgAA2w4"]
[Mon Jul 20 06:38:30.219006 2026] [security2:error] [pid 966386:tid 966606] [client 161.118.195.148:64781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WxjrLBqY1mBmWu_YJCAAAACw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:30.268606 2026] [ssl:error] [pid 966386:tid 966664] [client 104.48.69.105:59162] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:38:30.414891 2026] [security2:error] [pid 983757:tid 983963] [client 14.225.17.146:54403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4WxXKwMdFW9UVnNBSKcQAAAVQ"], referer: http://backandneckpainrelieflaceychiropractor.com/OLD
[Mon Jul 20 06:38:30.453627 2026] [security2:error] [pid 966386:tid 966682] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxjrLBqY1mBmWu_YJCQAAAHU"]
[Mon Jul 20 06:38:30.485199 2026] [security2:error] [pid 966386:tid 966691] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxjrLBqY1mBmWu_YJCwAAAH4"]
[Mon Jul 20 06:38:30.629233 2026] [security2:error] [pid 966386:tid 966617] [client 216.73.217.138:60363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WxjrLBqY1mBmWu_YJHAAAN3k"]
[Mon Jul 20 06:38:30.704288 2026] [security2:error] [pid 983757:tid 983989] [client 104.234.53.62:60979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4WxnKwMdFW9UVnNBSKiwAAAW4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:30.794471 2026] [security2:error] [pid 966386:tid 966589] [client 161.118.195.148:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WxjrLBqY1mBmWu_YJMQAAABs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:30.797678 2026] [security2:error] [pid 966386:tid 966509] [remote 173.212.252.15:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WxjrLBqY1mBmWu_YJMgAAek8"]
[Mon Jul 20 06:38:30.817230 2026] [security2:error] [pid 966386:tid 966649] [client 216.73.217.138:60363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4WxjrLBqY1mBmWu_YJKgAAVzk"]
[Mon Jul 20 06:38:30.836355 2026] [security2:error] [pid 966386:tid 966570] [client 77.110.127.138:51658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WxjrLBqY1mBmWu_YJNQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:30.836452 2026] [security2:error] [pid 966386:tid 966570] [client 77.110.127.138:51658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WxjrLBqY1mBmWu_YJNQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:30.865709 2026] [security2:error] [pid 983757:tid 984008] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxnKwMdFW9UVnNBSKhQAAAYE"]
[Mon Jul 20 06:38:31.008241 2026] [security2:error] [pid 966386:tid 966656] [client 14.225.17.146:54224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4WxjrLBqY1mBmWu_YJLwAAAF4"], referer: http://ccsdifference.com/OLD
[Mon Jul 20 06:38:31.036465 2026] [security2:error] [pid 966386:tid 966428] [remote 173.212.252.15:34986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4WxzrLBqY1mBmWu_YJPQAALQE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:38:31.073899 2026] [security2:error] [pid 983757:tid 983991] [client 171.61.165.146:19551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKmQAAAXA"]
[Mon Jul 20 06:38:31.074051 2026] [security2:error] [pid 983757:tid 983991] [client 171.61.165.146:19551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKmQAAAXA"]
[Mon Jul 20 06:38:31.231241 2026] [security2:error] [pid 983757:tid 983770] [remote 160.187.68.132:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKngABFgo"]
[Mon Jul 20 06:38:31.231425 2026] [security2:error] [pid 983757:tid 983901] [client 160.187.68.132:35538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKngABFgo"]
[Mon Jul 20 06:38:31.237962 2026] [proxy:error] [pid 983757:tid 983918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:31.238008 2026] [proxy_http:error] [pid 983757:tid 983918] [client 34.73.38.214:53172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:31.238918 2026] [proxy:error] [pid 983757:tid 983918] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:31.238951 2026] [proxy_http:error] [pid 983757:tid 983918] [client 34.73.38.214:53172] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:31.369541 2026] [security2:error] [pid 983757:tid 983919] [client 161.118.195.148:65525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKpgAAASg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:31.428321 2026] [security2:error] [pid 966386:tid 966672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxzrLBqY1mBmWu_YJSQAAAGs"]
[Mon Jul 20 06:38:31.439529 2026] [security2:error] [pid 983757:tid 983936] [client 217.142.18.172:4011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKqwAAATk"]
[Mon Jul 20 06:38:31.439604 2026] [security2:error] [pid 983757:tid 983936] [client 217.142.18.172:4011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKqwAAATk"]
[Mon Jul 20 06:38:31.590557 2026] [security2:error] [pid 966386:tid 966654] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxzrLBqY1mBmWu_YJUgAAAFw"]
[Mon Jul 20 06:38:31.639466 2026] [security2:error] [pid 966386:tid 966619] [client 57.141.18.60:56764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwDrLBqY1mBmWu_YHQAAAOSY"]
[Mon Jul 20 06:38:31.761881 2026] [security2:error] [pid 966386:tid 966633] [client 57.141.18.90:20364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwDrLBqY1mBmWu_YHRwAARyw"]
[Mon Jul 20 06:38:31.827118 2026] [security2:error] [pid 966386:tid 966660] [client 57.141.18.114:27730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwDrLBqY1mBmWu_YHUAAAYSE"]
[Mon Jul 20 06:38:31.895206 2026] [security2:error] [pid 983757:tid 983963] [client 40.77.177.3:63876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKtwABVA8"]
[Mon Jul 20 06:38:31.947050 2026] [security2:error] [pid 966386:tid 966651] [client 161.118.195.148:49491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WxzrLBqY1mBmWu_YJcgAAAFk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:31.964238 2026] [security2:error] [pid 983757:tid 983970] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKsQAAAVs"]
[Mon Jul 20 06:38:31.991611 2026] [security2:error] [pid 966386:tid 966516] [remote 57.141.18.105:46380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5680545"] [unique_id "al4WxzrLBqY1mBmWu_YJcQAAVVY"]
[Mon Jul 20 06:38:32.074577 2026] [security2:error] [pid 966386:tid 966602] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WxzrLBqY1mBmWu_YJaQAAACg"]
[Mon Jul 20 06:38:32.124607 2026] [security2:error] [pid 966386:tid 966646] [client 57.141.18.15:32110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwTrLBqY1mBmWu_YHbAAAVB8"]
[Mon Jul 20 06:38:32.185056 2026] [security2:error] [pid 966386:tid 966610] [client 14.225.17.146:60795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4WyDrLBqY1mBmWu_YJdwAAADA"], referer: https://ccsdifference.com/OLD
[Mon Jul 20 06:38:32.297251 2026] [security2:error] [pid 966386:tid 966683] [client 197.186.66.42:61501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WyDrLBqY1mBmWu_YJhQAAAHY"]
[Mon Jul 20 06:38:32.301082 2026] [security2:error] [pid 966386:tid 966683] [client 197.186.66.42:61501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4WyDrLBqY1mBmWu_YJhQAAAHY"]
[Mon Jul 20 06:38:32.346610 2026] [security2:error] [pid 983757:tid 983893] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyHKwMdFW9UVnNBSKwQAAAQ4"]
[Mon Jul 20 06:38:32.369780 2026] [security2:error] [pid 983757:tid 984003] [client 14.225.17.146:49590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4WyHKwMdFW9UVnNBSKxgAAAXw"], referer: http://longevityperformanceclinic.com/OLD
[Mon Jul 20 06:38:32.525942 2026] [security2:error] [pid 983757:tid 983991] [client 74.208.214.194:43772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WyHKwMdFW9UVnNBSK1QAAAXA"]
[Mon Jul 20 06:38:32.543469 2026] [security2:error] [pid 966386:tid 966688] [client 161.118.195.148:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WyDrLBqY1mBmWu_YJkgAAAHs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:32.546935 2026] [security2:error] [pid 983757:tid 983908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyHKwMdFW9UVnNBSKxwAAAR0"]
[Mon Jul 20 06:38:32.724840 2026] [security2:error] [pid 966386:tid 966643] [client 57.141.18.22:25300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwTrLBqY1mBmWu_YHngAAUR0"]
[Mon Jul 20 06:38:32.752191 2026] [security2:error] [pid 983757:tid 983966] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyHKwMdFW9UVnNBSK1AAAAVc"]
[Mon Jul 20 06:38:32.766853 2026] [security2:error] [pid 983757:tid 983914] [client 171.60.139.123:61624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WyHKwMdFW9UVnNBSK3AAAASM"]
[Mon Jul 20 06:38:32.767013 2026] [security2:error] [pid 983757:tid 983914] [client 171.60.139.123:61624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4WyHKwMdFW9UVnNBSK3AAAASM"]
[Mon Jul 20 06:38:32.855157 2026] [proxy:error] [pid 983757:tid 983957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:32.855218 2026] [proxy_http:error] [pid 983757:tid 983957] [client 34.73.38.214:54760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:32.855640 2026] [proxy:error] [pid 983757:tid 983957] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:32.855662 2026] [proxy_http:error] [pid 983757:tid 983957] [client 34.73.38.214:54760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:33.118600 2026] [security2:error] [pid 966386:tid 966588] [client 161.118.195.148:50199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WyTrLBqY1mBmWu_YJtwAAABo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:33.192584 2026] [security2:error] [pid 966386:tid 966681] [client 57.141.18.15:32124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwjrLBqY1mBmWu_YHtAAAdDc"]
[Mon Jul 20 06:38:33.351931 2026] [security2:error] [pid 983757:tid 983946] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyHKwMdFW9UVnNBSK4wAAAUM"]
[Mon Jul 20 06:38:33.380604 2026] [security2:error] [pid 983757:tid 983929] [client 103.125.179.95:51156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WyXKwMdFW9UVnNBSK9AAAATI"]
[Mon Jul 20 06:38:33.380783 2026] [security2:error] [pid 983757:tid 983929] [client 103.125.179.95:51156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WyXKwMdFW9UVnNBSK9AAAATI"]
[Mon Jul 20 06:38:33.392993 2026] [security2:error] [pid 983757:tid 983890] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyHKwMdFW9UVnNBSK4gAAAQs"]
[Mon Jul 20 06:38:33.579686 2026] [security2:error] [pid 983757:tid 983952] [client 223.237.130.40:62628] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WyXKwMdFW9UVnNBSK9gAAAUk"]
[Mon Jul 20 06:38:33.579812 2026] [security2:error] [pid 983757:tid 983952] [client 223.237.130.40:62628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4WyXKwMdFW9UVnNBSK9gAAAUk"]
[Mon Jul 20 06:38:33.693728 2026] [security2:error] [pid 966386:tid 966483] [remote 57.141.18.25:32950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4WyTrLBqY1mBmWu_YJ2AAALTU"]
[Mon Jul 20 06:38:33.696545 2026] [security2:error] [pid 966386:tid 966674] [client 161.118.195.148:50530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WyTrLBqY1mBmWu_YJ2gAAAG0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:33.805736 2026] [security2:error] [pid 983757:tid 983782] [remote 217.113.60.80:58310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WyXKwMdFW9UVnNBSLBAABIBY"]
[Mon Jul 20 06:38:33.877410 2026] [security2:error] [pid 966386:tid 966653] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyTrLBqY1mBmWu_YJ1QAAAFs"]
[Mon Jul 20 06:38:33.896346 2026] [security2:error] [pid 983757:tid 983994] [client 47.128.52.69:14452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/robots.txt"] [unique_id "al4WyXKwMdFW9UVnNBSLCQAAAXM"]
[Mon Jul 20 06:38:33.993684 2026] [security2:error] [pid 966386:tid 966665] [client 57.141.18.103:60084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WwzrLBqY1mBmWu_YH9AAAZko"]
[Mon Jul 20 06:38:34.012090 2026] [security2:error] [pid 966386:tid 966631] [client 45.3.45.195:39661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WyTrLBqY1mBmWu_YJ5QAAAEU"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:38:34.028113 2026] [security2:error] [pid 966386:tid 966587] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyTrLBqY1mBmWu_YJ1AAAABk"]
[Mon Jul 20 06:38:34.031067 2026] [security2:error] [pid 983757:tid 983783] [remote 217.113.60.80:58310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4WynKwMdFW9UVnNBSLDwABPRc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:38:34.037216 2026] [security2:error] [pid 983757:tid 983991] [client 77.110.127.138:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WynKwMdFW9UVnNBSLEAAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:34.037305 2026] [security2:error] [pid 983757:tid 983991] [client 77.110.127.138:51693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WynKwMdFW9UVnNBSLEAAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:34.233536 2026] [security2:error] [pid 983757:tid 983908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WynKwMdFW9UVnNBSLDgAAAR0"]
[Mon Jul 20 06:38:34.270990 2026] [security2:error] [pid 966386:tid 966569] [client 161.118.195.148:50914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WyjrLBqY1mBmWu_YJ9QAAAAc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:34.297574 2026] [security2:error] [pid 983757:tid 983971] [client 110.38.243.178:28362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4WyXKwMdFW9UVnNBSLCgAAAVw"]
[Mon Jul 20 06:38:34.364513 2026] [proxy:error] [pid 983757:tid 983967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:34.364584 2026] [proxy_http:error] [pid 983757:tid 983967] [client 34.73.38.214:53030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:34.365068 2026] [proxy:error] [pid 983757:tid 983967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:34.365103 2026] [proxy_http:error] [pid 983757:tid 983967] [client 34.73.38.214:53030] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:34.602853 2026] [security2:error] [pid 983757:tid 983934] [client 106.219.188.178:32933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WynKwMdFW9UVnNBSLKAAAATc"]
[Mon Jul 20 06:38:34.605347 2026] [security2:error] [pid 983757:tid 983934] [client 106.219.188.178:32933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4WynKwMdFW9UVnNBSLKAAAATc"]
[Mon Jul 20 06:38:34.651944 2026] [security2:error] [pid 966386:tid 966668] [client 57.141.18.93:62042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WxDrLBqY1mBmWu_YIdAAAaHc"]
[Mon Jul 20 06:38:34.686104 2026] [security2:error] [pid 966386:tid 966637] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyjrLBqY1mBmWu_YJ_gAAAEs"]
[Mon Jul 20 06:38:34.751453 2026] [security2:error] [pid 983757:tid 983957] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WynKwMdFW9UVnNBSLHAAAAU4"]
[Mon Jul 20 06:38:34.843174 2026] [security2:error] [pid 983757:tid 983993] [client 161.118.195.148:51263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WynKwMdFW9UVnNBSLNAAAAXI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:34.873366 2026] [security2:error] [pid 983757:tid 983952] [client 34.73.38.214:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4WynKwMdFW9UVnNBSLNwAAAUk"]
[Mon Jul 20 06:38:34.886688 2026] [security2:error] [pid 983757:tid 983943] [client 112.208.70.94:45246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WynKwMdFW9UVnNBSLOAAAAUA"]
[Mon Jul 20 06:38:34.886868 2026] [security2:error] [pid 983757:tid 983943] [client 112.208.70.94:45246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4WynKwMdFW9UVnNBSLOAAAAUA"]
[Mon Jul 20 06:38:35.185729 2026] [security2:error] [pid 966386:tid 966581] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyjrLBqY1mBmWu_YKGgAAABM"]
[Mon Jul 20 06:38:35.219212 2026] [security2:error] [pid 966386:tid 966679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyjrLBqY1mBmWu_YKGQAAAHI"]
[Mon Jul 20 06:38:35.251148 2026] [security2:error] [pid 983757:tid 983894] [client 14.251.3.155:58556] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Wy3KwMdFW9UVnNBSLRgAAAQ8"]
[Mon Jul 20 06:38:35.416260 2026] [security2:error] [pid 983757:tid 983947] [client 161.118.195.148:51615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4Wy3KwMdFW9UVnNBSLTQAAAUQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:35.569779 2026] [security2:error] [pid 966386:tid 966659] [client 65.111.24.141:51611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WyzrLBqY1mBmWu_YKQQAAAGA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:38:35.721888 2026] [security2:error] [pid 966386:tid 966637] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4WyzrLBqY1mBmWu_YKPAAAAEs"]
[Mon Jul 20 06:38:35.769806 2026] [security2:error] [pid 966386:tid 966686] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyzrLBqY1mBmWu_YKOQAAAHk"]
[Mon Jul 20 06:38:35.796481 2026] [security2:error] [pid 966386:tid 966522] [remote 47.86.33.52:19952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WyzrLBqY1mBmWu_YKUgAAc1w"]
[Mon Jul 20 06:38:35.851050 2026] [security2:error] [pid 966386:tid 966623] [client 57.141.18.34:46570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WxTrLBqY1mBmWu_YI6AAAPRE"]
[Mon Jul 20 06:38:35.917283 2026] [security2:error] [pid 983757:tid 983897] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Wy3KwMdFW9UVnNBSLUAAAARI"]
[Mon Jul 20 06:38:35.981672 2026] [security2:error] [pid 983757:tid 984010] [client 34.73.38.214:62700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Wy3KwMdFW9UVnNBSLYAAAAYM"]
[Mon Jul 20 06:38:35.990848 2026] [security2:error] [pid 966386:tid 966692] [client 161.118.195.148:51977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WyzrLBqY1mBmWu_YKXgAAAH8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:36.098797 2026] [security2:error] [pid 966386:tid 966683] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WyzrLBqY1mBmWu_YKVgAAAHY"]
[Mon Jul 20 06:38:36.355372 2026] [security2:error] [pid 966386:tid 966577] [client 104.28.246.116:45078] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "civitansuncitiesaz.org"] [uri "/ms-themes.php"] [unique_id "al4WzDrLBqY1mBmWu_YKZwAAAA8"]
[Mon Jul 20 06:38:36.423130 2026] [security2:error] [pid 966386:tid 966460] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WzDrLBqY1mBmWu_YKaQAAJCE"]
[Mon Jul 20 06:38:36.423272 2026] [security2:error] [pid 966386:tid 966598] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4WzDrLBqY1mBmWu_YKaQAAJCE"]
[Mon Jul 20 06:38:36.499358 2026] [security2:error] [pid 966386:tid 966659] [client 104.28.246.116:45082] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "civitansuncitiesaz.org"] [uri "/chosen.php"] [unique_id "al4WzDrLBqY1mBmWu_YKcwAAAGA"]
[Mon Jul 20 06:38:36.565418 2026] [security2:error] [pid 966386:tid 966582] [client 161.118.195.148:52305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WzDrLBqY1mBmWu_YKdwAAABQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:36.730791 2026] [security2:error] [pid 983757:tid 983965] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WzHKwMdFW9UVnNBSLcgAAAVY"], referer: 1'"3000
[Mon Jul 20 06:38:36.818593 2026] [ssl:error] [pid 966386:tid 966573] [client 104.48.69.105:59172] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:38:36.874207 2026] [security2:error] [pid 966386:tid 966480] [remote 47.86.33.52:19952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4WzDrLBqY1mBmWu_YKjAAAQDI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:38:36.876835 2026] [security2:error] [pid 983757:tid 983955] [client 74.208.214.194:39638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4WzHKwMdFW9UVnNBSLiwAAAUw"]
[Mon Jul 20 06:38:36.925397 2026] [security2:error] [pid 966386:tid 966614] [client 34.73.38.214:49544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4WzDrLBqY1mBmWu_YKkAAAADQ"]
[Mon Jul 20 06:38:36.965928 2026] [security2:error] [pid 983757:tid 983943] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4WzHKwMdFW9UVnNBSLbgABQCo"], referer: http://ardhalwafaa.com/OLD
[Mon Jul 20 06:38:37.017315 2026] [security2:error] [pid 966386:tid 966652] [client 104.234.53.92:41093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4WzTrLBqY1mBmWu_YKlwAAAFo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:37.069429 2026] [security2:error] [pid 983757:tid 983904] [client 57.141.18.40:45186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WxnKwMdFW9UVnNBSKkAABGQc"]
[Mon Jul 20 06:38:37.126489 2026] [security2:error] [pid 983757:tid 983910] [client 57.141.18.6:60254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WxnKwMdFW9UVnNBSKlgABHwg"]
[Mon Jul 20 06:38:37.137824 2026] [security2:error] [pid 966386:tid 966655] [client 161.118.195.148:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WzTrLBqY1mBmWu_YKmwAAAF0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:37.187510 2026] [security2:error] [pid 983757:tid 983909] [client 65.111.30.14:14117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4WzXKwMdFW9UVnNBSLkAAAAR4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:38:37.237169 2026] [security2:error] [pid 983757:tid 983897] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WzXKwMdFW9UVnNBSLjgAAARI"], referer: 1'"3000
[Mon Jul 20 06:38:37.318492 2026] [security2:error] [pid 983757:tid 983927] [client 152.58.191.29:60665] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WzXKwMdFW9UVnNBSLoAAAATA"]
[Mon Jul 20 06:38:37.318655 2026] [security2:error] [pid 983757:tid 983927] [client 152.58.191.29:60665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4WzXKwMdFW9UVnNBSLoAAAATA"]
[Mon Jul 20 06:38:37.331794 2026] [security2:error] [pid 983757:tid 983928] [client 77.110.127.138:51691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WzXKwMdFW9UVnNBSLogAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:37.331903 2026] [security2:error] [pid 983757:tid 983928] [client 77.110.127.138:51691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4WzXKwMdFW9UVnNBSLogAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:37.495198 2026] [security2:error] [pid 983757:tid 984013] [client 187.108.85.186:50226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WzXKwMdFW9UVnNBSLqAAAAYY"]
[Mon Jul 20 06:38:37.495353 2026] [security2:error] [pid 983757:tid 984013] [client 187.108.85.186:50226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4WzXKwMdFW9UVnNBSLqAAAAYY"]
[Mon Jul 20 06:38:37.543124 2026] [security2:error] [pid 983757:tid 983948] [client 57.141.18.74:47790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Wx3KwMdFW9UVnNBSKoAABRQs"]
[Mon Jul 20 06:38:37.710605 2026] [security2:error] [pid 983757:tid 983907] [client 161.118.195.148:52992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WzXKwMdFW9UVnNBSLrgAAARw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:37.833729 2026] [security2:error] [pid 983757:tid 983965] [client 47.82.11.98:57334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.11.82.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4WzXKwMdFW9UVnNBSLtgAAAVY"], referer: https://sustaintheart.com/wp-content/plugins/aawp/public/image.php?url=YUhSMGNITTZMeTl0TG0xbFpHbGhMV0Z0WVhwdmJpNWpiMjB2YVcxaFoyVnpMMGt2TlRGWGIxUndWamN5VlV3dVgxTk1NVFl3WHk1cWNHYz18MTc3MjE1Nzc1Nw=
[Mon Jul 20 06:38:37.846821 2026] [security2:error] [pid 983757:tid 983816] [remote 45.90.123.233:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4WzXKwMdFW9UVnNBSLugABDjg"]
[Mon Jul 20 06:38:37.877951 2026] [ssl:error] [pid 966386:tid 966674] [client 104.48.69.105:59188] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:38:37.992502 2026] [security2:error] [pid 966386:tid 966570] [client 57.141.18.107:29314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WxzrLBqY1mBmWu_YJaAAACF0"]
[Mon Jul 20 06:38:38.166210 2026] [security2:error] [pid 966386:tid 966673] [client 14.225.17.146:53158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4WzTrLBqY1mBmWu_YKtwAAAGw"]
[Mon Jul 20 06:38:38.179012 2026] [security2:error] [pid 983757:tid 983929] [client 34.73.38.214:55731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4WznKwMdFW9UVnNBSLxwAAATI"]
[Mon Jul 20 06:38:38.267450 2026] [security2:error] [pid 983757:tid 983819] [remote 45.90.123.233:33778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4WznKwMdFW9UVnNBSLyQABejs"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 06:38:38.283831 2026] [security2:error] [pid 983757:tid 983968] [client 161.118.195.148:53369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WznKwMdFW9UVnNBSLzAAAAVk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:38.370305 2026] [security2:error] [pid 983757:tid 983904] [client 65.111.28.97:62405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4WznKwMdFW9UVnNBSL0gAAARk"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:38:38.581486 2026] [security2:error] [pid 966386:tid 966621] [client 14.225.17.146:53673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4WzDrLBqY1mBmWu_YKkwAAADs"], referer: http://ironcitywellness.com/OLD
[Mon Jul 20 06:38:38.601908 2026] [security2:error] [pid 983757:tid 984013] [client 34.73.38.214:59813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4WznKwMdFW9UVnNBSL2QAAAYY"]
[Mon Jul 20 06:38:38.767225 2026] [security2:error] [pid 966386:tid 966600] [client 57.141.18.4:27516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WyDrLBqY1mBmWu_YJmQAAJnA"]
[Mon Jul 20 06:38:38.860872 2026] [security2:error] [pid 983757:tid 983956] [client 161.118.195.148:53739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4WznKwMdFW9UVnNBSL6AAAAU0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:38.871821 2026] [security2:error] [pid 983757:tid 983919] [client 216.73.217.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.indiraskitchenllc.com"] [uri "/index.php"] [unique_id "al4WznKwMdFW9UVnNBSL4AABKEE"]
[Mon Jul 20 06:38:38.882995 2026] [security2:error] [pid 966386:tid 966586] [client 14.225.17.146:54595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4WzTrLBqY1mBmWu_YKngAAABg"], referer: http://thesoloceos.com/OLD
[Mon Jul 20 06:38:39.241158 2026] [security2:error] [pid 983757:tid 983828] [remote 162.19.86.63:52346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Wz3KwMdFW9UVnNBSL8gABJkQ"]
[Mon Jul 20 06:38:39.318063 2026] [security2:error] [pid 983757:tid 983987] [client 158.173.166.181:35269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Wz3KwMdFW9UVnNBSL9AAAAWw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:38:39.322143 2026] [security2:error] [pid 966386:tid 966679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WzzrLBqY1mBmWu_YK-AAAAHI"], referer: 1'"3000
[Mon Jul 20 06:38:39.346725 2026] [security2:error] [pid 983757:tid 983984] [client 103.238.106.162:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Wz3KwMdFW9UVnNBSL9gAAAWk"]
[Mon Jul 20 06:38:39.346868 2026] [security2:error] [pid 983757:tid 983984] [client 103.238.106.162:60932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Wz3KwMdFW9UVnNBSL9gAAAWk"]
[Mon Jul 20 06:38:39.395076 2026] [security2:error] [pid 966386:tid 966591] [client 57.141.18.62:34238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WyTrLBqY1mBmWu_YJyAAAHQw"]
[Mon Jul 20 06:38:39.435487 2026] [security2:error] [pid 966386:tid 966592] [client 161.118.195.148:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4WzzrLBqY1mBmWu_YLDQAAAB4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:39.450833 2026] [security2:error] [pid 983757:tid 983829] [remote 162.19.86.63:52346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4Wz3KwMdFW9UVnNBSL-AABY0U"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:38:39.458945 2026] [security2:error] [pid 983757:tid 984010] [client 14.251.3.155:54539] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Wz3KwMdFW9UVnNBSL-QAAAYM"]
[Mon Jul 20 06:38:39.714894 2026] [security2:error] [pid 966386:tid 966611] [client 34.73.38.214:53487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4WzzrLBqY1mBmWu_YLFgAAADE"]
[Mon Jul 20 06:38:39.934712 2026] [security2:error] [pid 966386:tid 966568] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4WzzrLBqY1mBmWu_YLFwAAAAY"], referer: 1'"3000
[Mon Jul 20 06:38:39.935439 2026] [security2:error] [pid 966386:tid 966601] [client 14.225.17.146:53032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4WzzrLBqY1mBmWu_YLIAAAACc"], referer: https://thesoloceos.com/OLD
[Mon Jul 20 06:38:40.010221 2026] [security2:error] [pid 983757:tid 983898] [client 161.118.195.148:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W0HKwMdFW9UVnNBSMEQAAARM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:40.010725 2026] [security2:error] [pid 983757:tid 983834] [remote 192.241.143.148:39096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4W0HKwMdFW9UVnNBSMEAABeEo"]
[Mon Jul 20 06:38:40.181398 2026] [security2:error] [pid 966386:tid 966617] [client 77.110.127.138:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W0DrLBqY1mBmWu_YLKwAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:40.181515 2026] [security2:error] [pid 966386:tid 966617] [client 77.110.127.138:51668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W0DrLBqY1mBmWu_YLKwAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:40.194119 2026] [security2:error] [pid 983757:tid 983836] [remote 192.241.143.148:39096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4W0HKwMdFW9UVnNBSMFQABW0w"], referer: https://bigwormfishing.com/wp-login.php
[Mon Jul 20 06:38:40.199579 2026] [security2:error] [pid 983757:tid 983890] [client 14.225.17.146:54038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4WznKwMdFW9UVnNBSL5gAAAQs"], referer: http://alchemygroup.ca/OLD
[Mon Jul 20 06:38:40.242604 2026] [security2:error] [pid 983757:tid 983960] [client 34.73.38.214:63201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4W0HKwMdFW9UVnNBSMGQAAAVE"]
[Mon Jul 20 06:38:40.339829 2026] [security2:error] [pid 966386:tid 966618] [client 14.225.17.146:60325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4WzzrLBqY1mBmWu_YK_QAAADg"], referer: http://lutheranphilosopher.com/OLD
[Mon Jul 20 06:38:40.585634 2026] [security2:error] [pid 983757:tid 983976] [client 161.118.195.148:54969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W0HKwMdFW9UVnNBSMLQAAAWE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:40.664070 2026] [security2:error] [pid 966386:tid 966641] [client 57.141.18.69:25316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WyTrLBqY1mBmWu_YJ1gAATwM"]
[Mon Jul 20 06:38:40.730085 2026] [security2:error] [pid 983757:tid 984010] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W0HKwMdFW9UVnNBSMJwAAAYM"], referer: 1'"3000
[Mon Jul 20 06:38:40.784059 2026] [security2:error] [pid 983757:tid 983957] [client 223.185.13.213:24364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W0HKwMdFW9UVnNBSMNAAAAU4"]
[Mon Jul 20 06:38:40.784169 2026] [security2:error] [pid 983757:tid 983957] [client 223.185.13.213:24364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W0HKwMdFW9UVnNBSMNAAAAU4"]
[Mon Jul 20 06:38:41.164736 2026] [security2:error] [pid 983757:tid 983962] [client 161.118.195.148:55301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W0XKwMdFW9UVnNBSMRQAAAVM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:41.188721 2026] [security2:error] [pid 966386:tid 966649] [client 34.73.38.214:63740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4W0TrLBqY1mBmWu_YLWQAAAFc"]
[Mon Jul 20 06:38:41.278502 2026] [security2:error] [pid 983757:tid 983901] [client 104.234.53.76:41799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4W0XKwMdFW9UVnNBSMSgAAARY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:41.324285 2026] [security2:error] [pid 983757:tid 983955] [client 54.39.152.94:52546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "phillipbloch.com"] [uri "/"] [unique_id "al4W0XKwMdFW9UVnNBSMUAAAAUw"]
[Mon Jul 20 06:38:41.396086 2026] [security2:error] [pid 966386:tid 966605] [client 39.48.81.23:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W0TrLBqY1mBmWu_YLYQAAACs"]
[Mon Jul 20 06:38:41.396188 2026] [security2:error] [pid 966386:tid 966605] [client 39.48.81.23:51460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W0TrLBqY1mBmWu_YLYQAAACs"]
[Mon Jul 20 06:38:41.473190 2026] [security2:error] [pid 983757:tid 983844] [remote 49.13.1.223:52762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4W0XKwMdFW9UVnNBSMUwABWFQ"]
[Mon Jul 20 06:38:41.533682 2026] [security2:error] [pid 983757:tid 983950] [client 34.73.38.214:57764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4W0XKwMdFW9UVnNBSMVQAAAUc"]
[Mon Jul 20 06:38:41.658488 2026] [security2:error] [pid 983757:tid 983846] [remote 49.13.1.223:52762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4W0XKwMdFW9UVnNBSMWQABM1Y"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:38:41.741139 2026] [security2:error] [pid 966386:tid 966626] [client 161.118.195.148:55644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W0TrLBqY1mBmWu_YLbgAAAEA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:41.962408 2026] [security2:error] [pid 966386:tid 966560] [client 171.61.165.146:31161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W0TrLBqY1mBmWu_YLfQAAAAA"]
[Mon Jul 20 06:38:41.962543 2026] [security2:error] [pid 966386:tid 966560] [client 171.61.165.146:31161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W0TrLBqY1mBmWu_YLfQAAAAA"]
[Mon Jul 20 06:38:42.024869 2026] [security2:error] [pid 966386:tid 966690] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W0TrLBqY1mBmWu_YLawAAAH0"], referer: 1'"3000
[Mon Jul 20 06:38:42.047461 2026] [security2:error] [pid 983757:tid 983906] [client 217.142.18.172:22646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W0nKwMdFW9UVnNBSMbgAAARs"]
[Mon Jul 20 06:38:42.060656 2026] [security2:error] [pid 983757:tid 983906] [client 217.142.18.172:22646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W0nKwMdFW9UVnNBSMbgAAARs"]
[Mon Jul 20 06:38:42.158543 2026] [security2:error] [pid 983757:tid 983982] [client 57.141.18.112:20784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WzHKwMdFW9UVnNBSLawABZyk"]
[Mon Jul 20 06:38:42.318605 2026] [security2:error] [pid 983757:tid 983999] [client 161.118.195.148:55982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W0nKwMdFW9UVnNBSMegAAAXg"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:42.359876 2026] [security2:error] [pid 983757:tid 983853] [remote 95.217.78.234:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4W0nKwMdFW9UVnNBSMfQABO10"]
[Mon Jul 20 06:38:42.412804 2026] [security2:error] [pid 966386:tid 966636] [client 34.73.38.214:50124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4W0jrLBqY1mBmWu_YLkQAAAEo"]
[Mon Jul 20 06:38:42.532981 2026] [security2:error] [pid 983757:tid 983993] [client 104.234.53.63:61795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4W0nKwMdFW9UVnNBSMhAAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:42.570519 2026] [security2:error] [pid 983757:tid 983983] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W0nKwMdFW9UVnNBSMeAAAAWg"], referer: 1'"3000
[Mon Jul 20 06:38:42.596428 2026] [security2:error] [pid 983757:tid 983856] [remote 95.217.78.234:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4W0nKwMdFW9UVnNBSMjgABQWA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:38:42.836000 2026] [security2:error] [pid 983757:tid 983987] [client 197.186.66.42:62022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W0nKwMdFW9UVnNBSMmAAAAWw"]
[Mon Jul 20 06:38:42.836120 2026] [security2:error] [pid 983757:tid 983987] [client 197.186.66.42:62022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W0nKwMdFW9UVnNBSMmAAAAWw"]
[Mon Jul 20 06:38:42.896021 2026] [security2:error] [pid 983757:tid 983908] [client 161.118.195.148:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W0nKwMdFW9UVnNBSMnQAAAR0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:43.037996 2026] [security2:error] [pid 966386:tid 966590] [client 57.141.18.122:55226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WzTrLBqY1mBmWu_YKogAAHEA"]
[Mon Jul 20 06:38:43.203149 2026] [security2:error] [pid 966386:tid 966627] [client 98.159.234.160:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4W0zrLBqY1mBmWu_YLqwAAAEE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:38:43.374737 2026] [security2:error] [pid 966386:tid 966599] [client 34.73.38.214:63612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4W0zrLBqY1mBmWu_YLsgAAACU"]
[Mon Jul 20 06:38:43.423254 2026] [security2:error] [pid 966386:tid 966595] [client 77.110.127.138:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W0zrLBqY1mBmWu_YLtQAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:43.423358 2026] [security2:error] [pid 966386:tid 966595] [client 77.110.127.138:51740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W0zrLBqY1mBmWu_YLtQAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:43.470464 2026] [security2:error] [pid 983757:tid 983941] [client 161.118.195.148:56640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W03KwMdFW9UVnNBSMqgAAAT4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:43.810995 2026] [security2:error] [pid 983757:tid 983955] [client 171.60.139.123:62152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W03KwMdFW9UVnNBSMugAAAUw"]
[Mon Jul 20 06:38:43.811137 2026] [security2:error] [pid 983757:tid 983955] [client 171.60.139.123:62152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W03KwMdFW9UVnNBSMugAAAUw"]
[Mon Jul 20 06:38:44.042860 2026] [security2:error] [pid 983757:tid 983948] [client 161.118.195.148:57002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W1HKwMdFW9UVnNBSMyAAAAUU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:44.230561 2026] [security2:error] [pid 983757:tid 983866] [remote 95.217.78.234:40934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W1HKwMdFW9UVnNBSM0QABGWo"]
[Mon Jul 20 06:38:44.353089 2026] [security2:error] [pid 983757:tid 983896] [client 57.141.18.107:29322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4WznKwMdFW9UVnNBSL0wABET4"]
[Mon Jul 20 06:38:44.370963 2026] [security2:error] [pid 966386:tid 966677] [client 34.73.38.214:63619] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.vbb.yvf.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4W1DrLBqY1mBmWu_YL3gAAAHA"]
[Mon Jul 20 06:38:44.496900 2026] [security2:error] [pid 983757:tid 983868] [remote 95.217.78.234:40934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W1HKwMdFW9UVnNBSM1wABR2w"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:38:44.616412 2026] [security2:error] [pid 983757:tid 983956] [client 161.118.195.148:57343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSM4AAAAU0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:44.835506 2026] [security2:error] [pid 983757:tid 983897] [client 66.249.74.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSM5gAAARI"]
[Mon Jul 20 06:38:44.847899 2026] [security2:error] [pid 983757:tid 983985] [client 216.73.217.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSM6wAAAWo"], referer: https://intelligentengineeringsolutions.com/sitemap.xml
[Mon Jul 20 06:38:45.092299 2026] [security2:error] [pid 983757:tid 983898] [client 216.73.217.138:16919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSM9wABE3Y"]
[Mon Jul 20 06:38:45.198022 2026] [security2:error] [pid 983757:tid 983920] [client 161.118.195.148:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W1XKwMdFW9UVnNBSNAgAAASk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:45.265846 2026] [security2:error] [pid 983757:tid 983983] [client 106.219.188.178:27753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W1XKwMdFW9UVnNBSNBwAAAWg"]
[Mon Jul 20 06:38:45.266019 2026] [security2:error] [pid 983757:tid 983983] [client 106.219.188.178:27753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W1XKwMdFW9UVnNBSNBwAAAWg"]
[Mon Jul 20 06:38:45.309592 2026] [security2:error] [pid 983757:tid 983972] [client 216.73.217.138:16919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W1XKwMdFW9UVnNBSNBgABXXc"]
[Mon Jul 20 06:38:45.472559 2026] [security2:error] [pid 983757:tid 983908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W1XKwMdFW9UVnNBSNAwAAAR0"]
[Mon Jul 20 06:38:45.539918 2026] [security2:error] [pid 983757:tid 983992] [client 103.125.179.95:51645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W1XKwMdFW9UVnNBSNGAAAAXE"]
[Mon Jul 20 06:38:45.540068 2026] [security2:error] [pid 983757:tid 983992] [client 103.125.179.95:51645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W1XKwMdFW9UVnNBSNGAAAAXE"]
[Mon Jul 20 06:38:45.554324 2026] [security2:error] [pid 983757:tid 983971] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-4dafb119.villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSMygAAAVw"]
[Mon Jul 20 06:38:45.772122 2026] [security2:error] [pid 983757:tid 983998] [client 161.118.195.148:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W1XKwMdFW9UVnNBSNKgAAAXc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:46.037143 2026] [security2:error] [pid 983757:tid 983891] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W1XKwMdFW9UVnNBSNLAAAAQw"]
[Mon Jul 20 06:38:46.343845 2026] [security2:error] [pid 983757:tid 983993] [client 161.118.195.148:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W1nKwMdFW9UVnNBSNQgAAAXI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:46.375046 2026] [security2:error] [pid 966386:tid 966652] [client 57.141.18.92:52002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W0DrLBqY1mBmWu_YLQwAAWi0"]
[Mon Jul 20 06:38:46.379660 2026] [security2:error] [pid 966386:tid 966600] [client 2a03:2880:24ff:42:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4W1DrLBqY1mBmWu_YL4QAAJmY"]
[Mon Jul 20 06:38:46.394313 2026] [security2:error] [pid 983757:tid 983994] [client 112.208.70.94:45675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W1nKwMdFW9UVnNBSNRAAAAXM"]
[Mon Jul 20 06:38:46.394416 2026] [security2:error] [pid 983757:tid 983994] [client 112.208.70.94:45675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W1nKwMdFW9UVnNBSNRAAAAXM"]
[Mon Jul 20 06:38:46.436741 2026] [security2:error] [pid 966386:tid 966662] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4W1TrLBqY1mBmWu_YMFAAAAGM"]
[Mon Jul 20 06:38:46.482259 2026] [security2:error] [pid 966386:tid 966617] [client 2a03:2880:24ff:48:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4W1DrLBqY1mBmWu_YL2QAAN2w"]
[Mon Jul 20 06:38:46.724554 2026] [security2:error] [pid 983757:tid 983915] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W1nKwMdFW9UVnNBSNSwAAASQ"]
[Mon Jul 20 06:38:46.882334 2026] [security2:error] [pid 983757:tid 983964] [client 77.110.127.138:51756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W1nKwMdFW9UVnNBSNXAAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:46.882438 2026] [security2:error] [pid 983757:tid 983964] [client 77.110.127.138:51756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W1nKwMdFW9UVnNBSNXAAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:46.916194 2026] [security2:error] [pid 966386:tid 966673] [client 161.118.195.148:58716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W1jrLBqY1mBmWu_YMQQAAAGw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:47.150047 2026] [security2:error] [pid 983757:tid 983770] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W13KwMdFW9UVnNBSNawABcAo"]
[Mon Jul 20 06:38:47.150286 2026] [security2:error] [pid 983757:tid 983991] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W13KwMdFW9UVnNBSNawABcAo"]
[Mon Jul 20 06:38:47.239726 2026] [security2:error] [pid 966386:tid 966681] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W1zrLBqY1mBmWu_YMSAAAAHQ"]
[Mon Jul 20 06:38:47.408633 2026] [security2:error] [pid 983757:tid 983889] [client 57.141.18.87:48664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W0XKwMdFW9UVnNBSMXgABClc"]
[Mon Jul 20 06:38:47.491245 2026] [security2:error] [pid 983757:tid 983978] [client 161.118.195.148:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W13KwMdFW9UVnNBSNewAAAWM"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:47.798053 2026] [security2:error] [pid 983757:tid 983904] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W13KwMdFW9UVnNBSNgAAAARk"]
[Mon Jul 20 06:38:47.893665 2026] [security2:error] [pid 983757:tid 983777] [remote 45.90.123.233:57910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4W13KwMdFW9UVnNBSNiAABFxE"]
[Mon Jul 20 06:38:48.065760 2026] [security2:error] [pid 983757:tid 983905] [client 161.118.195.148:59406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W2HKwMdFW9UVnNBSNiwAAARo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:48.077812 2026] [security2:error] [pid 983757:tid 983893] [client 57.141.18.99:32442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W0nKwMdFW9UVnNBSMjwABDmE"]
[Mon Jul 20 06:38:48.232000 2026] [security2:error] [pid 983757:tid 983982] [client 187.108.85.186:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W2HKwMdFW9UVnNBSNkgAAAWc"]
[Mon Jul 20 06:38:48.232136 2026] [security2:error] [pid 983757:tid 983982] [client 187.108.85.186:50763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W2HKwMdFW9UVnNBSNkgAAAWc"]
[Mon Jul 20 06:38:48.420323 2026] [security2:error] [pid 983757:tid 983782] [remote 8.217.108.67:8996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4W2HKwMdFW9UVnNBSNmAABKBY"]
[Mon Jul 20 06:38:48.507142 2026] [security2:error] [pid 983757:tid 983953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W2HKwMdFW9UVnNBSNjwAAAUo"]
[Mon Jul 20 06:38:48.572573 2026] [security2:error] [pid 983757:tid 983901] [client 57.141.18.103:34646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W03KwMdFW9UVnNBSMpQABFmM"]
[Mon Jul 20 06:38:48.646377 2026] [security2:error] [pid 983757:tid 983979] [client 161.118.195.148:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W2HKwMdFW9UVnNBSNoQAAAWQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:48.830261 2026] [security2:error] [pid 983757:tid 983784] [remote 8.217.108.67:8996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4W2HKwMdFW9UVnNBSNqQABChg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:38:49.054789 2026] [security2:error] [pid 983757:tid 983949] [client 43.205.139.3:33600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4W2XKwMdFW9UVnNBSNsAAAAUY"]
[Mon Jul 20 06:38:49.054893 2026] [security2:error] [pid 983757:tid 983949] [client 43.205.139.3:33600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4W2XKwMdFW9UVnNBSNsAAAAUY"]
[Mon Jul 20 06:38:49.092289 2026] [security2:error] [pid 966386:tid 966578] [client 104.207.55.115:24635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4W2TrLBqY1mBmWu_YMqQAAABA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:38:49.099553 2026] [security2:error] [pid 983757:tid 984010] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W2HKwMdFW9UVnNBSNqwAAAYM"]
[Mon Jul 20 06:38:49.220046 2026] [security2:error] [pid 983757:tid 983957] [client 161.118.195.148:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W2XKwMdFW9UVnNBSNvAAAAU4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:49.233562 2026] [security2:error] [pid 983757:tid 983791] [remote 45.90.123.233:57910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4W2XKwMdFW9UVnNBSNvgABdx8"], referer: https://sbinframx.com/wp-login.php
[Mon Jul 20 06:38:49.557598 2026] [security2:error] [pid 966386:tid 966590] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W2TrLBqY1mBmWu_YM3AAAABw"]
[Mon Jul 20 06:38:49.570936 2026] [security2:error] [pid 983757:tid 984006] [client 3.77.67.4:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4W2XKwMdFW9UVnNBSNwgABfx4"], referer: https://origine.nz
[Mon Jul 20 06:38:49.691682 2026] [security2:error] [pid 966386:tid 966646] [client 104.234.53.82:42357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4W2TrLBqY1mBmWu_YM8wAAAFQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:49.705199 2026] [security2:error] [pid 983757:tid 983991] [client 104.207.63.245:52627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4W2XKwMdFW9UVnNBSNzQAAAXA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:38:49.798265 2026] [security2:error] [pid 966386:tid 966633] [client 161.118.195.148:60477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W2TrLBqY1mBmWu_YM-AAAAEc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:49.810598 2026] [security2:error] [pid 983757:tid 983988] [client 57.141.18.116:29782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSM2gABbW4"]
[Mon Jul 20 06:38:49.854455 2026] [security2:error] [pid 966386:tid 966660] [client 103.238.106.162:60733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W2TrLBqY1mBmWu_YM_QAAAGE"]
[Mon Jul 20 06:38:49.854545 2026] [security2:error] [pid 966386:tid 966660] [client 103.238.106.162:60733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W2TrLBqY1mBmWu_YM_QAAAGE"]
[Mon Jul 20 06:38:50.097491 2026] [security2:error] [pid 983757:tid 983937] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W2XKwMdFW9UVnNBSN1QAAATo"]
[Mon Jul 20 06:38:50.214089 2026] [security2:error] [pid 983757:tid 983946] [client 57.141.18.68:46082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W1HKwMdFW9UVnNBSM8wABQ3Q"]
[Mon Jul 20 06:38:50.278319 2026] [security2:error] [pid 983757:tid 983930] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/config/smtp.php"] [unique_id "al4W2nKwMdFW9UVnNBSN3gAAATM"]
[Mon Jul 20 06:38:50.290621 2026] [security2:error] [pid 983757:tid 983968] [client 104.234.53.64:56407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4W2nKwMdFW9UVnNBSN4QAAAVk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:50.329290 2026] [security2:error] [pid 966386:tid 966579] [client 217.181.92.40:32519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4W2jrLBqY1mBmWu_YNCwAAABE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:38:50.374844 2026] [security2:error] [pid 966386:tid 966585] [client 161.118.195.148:60857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W2jrLBqY1mBmWu_YNDgAAABc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:50.583525 2026] [security2:error] [pid 983757:tid 983974] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W2nKwMdFW9UVnNBSN6AAAAV8"]
[Mon Jul 20 06:38:50.618442 2026] [security2:error] [pid 966386:tid 966629] [client 35.187.45.1:47490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4W2jrLBqY1mBmWu_YNFgAAAEM"]
[Mon Jul 20 06:38:50.632558 2026] [security2:error] [pid 983757:tid 983961] [client 77.110.127.138:51776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W2nKwMdFW9UVnNBSOCwAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:50.632641 2026] [security2:error] [pid 983757:tid 983961] [client 77.110.127.138:51776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W2nKwMdFW9UVnNBSOCwAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:50.749077 2026] [security2:error] [pid 983757:tid 983931] [client 103.153.183.69:50376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/wp-config.php"] [unique_id "al4W2nKwMdFW9UVnNBSOHgAAATQ"], referer: https://duckduckgo.com/?q=q9308
[Mon Jul 20 06:38:50.958077 2026] [security2:error] [pid 983757:tid 983963] [client 161.118.195.148:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W2nKwMdFW9UVnNBSOMQAAAVQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:51.057845 2026] [security2:error] [pid 983757:tid 983894] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W2nKwMdFW9UVnNBSOKwAAAQ8"]
[Mon Jul 20 06:38:51.250436 2026] [security2:error] [pid 983757:tid 983978] [client 104.234.53.92:21675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4W23KwMdFW9UVnNBSOPwAAAWM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:51.531287 2026] [security2:error] [pid 983757:tid 983939] [client 161.118.195.148:61632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W23KwMdFW9UVnNBSOVAAAATw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:51.620499 2026] [security2:error] [pid 983757:tid 983898] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W23KwMdFW9UVnNBSORwAAARM"]
[Mon Jul 20 06:38:51.846795 2026] [security2:error] [pid 983757:tid 983902] [client 223.185.13.213:18507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W23KwMdFW9UVnNBSOaAAAARc"]
[Mon Jul 20 06:38:51.846943 2026] [security2:error] [pid 983757:tid 983902] [client 223.185.13.213:18507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W23KwMdFW9UVnNBSOaAAAARc"]
[Mon Jul 20 06:38:51.948264 2026] [security2:error] [pid 966386:tid 966585] [client 216.73.217.138:6467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W2zrLBqY1mBmWu_YNTAAAF0o"]
[Mon Jul 20 06:38:52.046241 2026] [security2:error] [pid 983757:tid 983932] [client 57.141.18.48:52134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W1nKwMdFW9UVnNBSNYAABNQY"]
[Mon Jul 20 06:38:52.102612 2026] [security2:error] [pid 983757:tid 983993] [client 161.118.195.148:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W3HKwMdFW9UVnNBSOcQAAAXI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:52.171063 2026] [security2:error] [pid 966386:tid 966636] [client 216.73.217.138:6467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W3DrLBqY1mBmWu_YNVgAASkU"]
[Mon Jul 20 06:38:52.210972 2026] [security2:error] [pid 983757:tid 983918] [client 170.64.227.98:65129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.karmaminds.com"] [uri "/wp-login.php"] [unique_id "al4W3HKwMdFW9UVnNBSOdAAAASc"]
[Mon Jul 20 06:38:52.443930 2026] [security2:error] [pid 983757:tid 983945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W3HKwMdFW9UVnNBSOdQAAAUI"]
[Mon Jul 20 06:38:52.602302 2026] [security2:error] [pid 983757:tid 984002] [client 217.142.18.172:50690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W3HKwMdFW9UVnNBSOiAAAAXs"]
[Mon Jul 20 06:38:52.613433 2026] [security2:error] [pid 983757:tid 984002] [client 217.142.18.172:50690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W3HKwMdFW9UVnNBSOiAAAAXs"]
[Mon Jul 20 06:38:52.677573 2026] [security2:error] [pid 983757:tid 983987] [client 161.118.195.148:62306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W3HKwMdFW9UVnNBSOjQAAAWw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:52.828633 2026] [security2:error] [pid 966386:tid 966574] [client 171.61.165.146:14325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W3DrLBqY1mBmWu_YNdQAAAAw"]
[Mon Jul 20 06:38:52.828764 2026] [security2:error] [pid 966386:tid 966574] [client 171.61.165.146:14325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W3DrLBqY1mBmWu_YNdQAAAAw"]
[Mon Jul 20 06:38:52.830022 2026] [security2:error] [pid 983757:tid 983940] [client 170.64.227.98:65157] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.karmaminds.com"] [uri "/wp-login.php"] [unique_id "al4W3HKwMdFW9UVnNBSOjwAAAT0"]
[Mon Jul 20 06:38:53.199791 2026] [security2:error] [pid 966386:tid 966619] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W3DrLBqY1mBmWu_YNfQAAADk"]
[Mon Jul 20 06:38:53.250199 2026] [security2:error] [pid 983757:tid 983963] [client 161.118.195.148:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W3XKwMdFW9UVnNBSOoAAAAVQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:53.446583 2026] [security2:error] [pid 983757:tid 983972] [client 57.141.18.81:22958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W2HKwMdFW9UVnNBSNlwABXRQ"]
[Mon Jul 20 06:38:53.472437 2026] [security2:error] [pid 983757:tid 983873] [remote 103.90.234.13:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4W3XKwMdFW9UVnNBSOqAABYnE"]
[Mon Jul 20 06:38:53.571847 2026] [security2:error] [pid 966386:tid 966660] [client 197.186.66.42:62546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W3TrLBqY1mBmWu_YNlAAAAGE"]
[Mon Jul 20 06:38:53.571941 2026] [security2:error] [pid 966386:tid 966660] [client 197.186.66.42:62546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W3TrLBqY1mBmWu_YNlAAAAGE"]
[Mon Jul 20 06:38:53.699196 2026] [security2:error] [pid 983757:tid 983982] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W3XKwMdFW9UVnNBSOpwAAAWc"]
[Mon Jul 20 06:38:53.754328 2026] [security2:error] [pid 983757:tid 983890] [client 66.249.88.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4W3XKwMdFW9UVnNBSOsAAAAQs"]
[Mon Jul 20 06:38:53.786607 2026] [security2:error] [pid 966386:tid 966598] [client 216.73.217.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.callourplace.com"] [uri "/index.php"] [unique_id "al4W2zrLBqY1mBmWu_YNSAAAACQ"]
[Mon Jul 20 06:38:53.825342 2026] [security2:error] [pid 966386:tid 966638] [client 161.118.195.148:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W3TrLBqY1mBmWu_YNoAAAAEw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:53.881600 2026] [security2:error] [pid 983757:tid 983880] [remote 103.90.234.13:53510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4W3XKwMdFW9UVnNBSOwQABhng"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:38:54.046562 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W3TrLBqY1mBmWu_YNowAAAF4"]
[Mon Jul 20 06:38:54.202895 2026] [security2:error] [pid 983757:tid 983905] [client 77.110.127.138:51793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W3nKwMdFW9UVnNBSO2wAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:54.203004 2026] [security2:error] [pid 983757:tid 983905] [client 77.110.127.138:51793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W3nKwMdFW9UVnNBSO2wAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:54.254625 2026] [security2:error] [pid 983757:tid 983980] [client 77.110.127.138:51748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W3nKwMdFW9UVnNBSO3wAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:54.254726 2026] [security2:error] [pid 983757:tid 983980] [client 77.110.127.138:51748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W3nKwMdFW9UVnNBSO3wAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:54.409265 2026] [security2:error] [pid 983757:tid 983960] [client 77.110.127.138:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W3nKwMdFW9UVnNBSO5AAAAVE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:54.409353 2026] [security2:error] [pid 983757:tid 983960] [client 77.110.127.138:51794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W3nKwMdFW9UVnNBSO5AAAAVE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:54.413497 2026] [security2:error] [pid 966386:tid 966627] [client 161.118.195.148:63397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W3jrLBqY1mBmWu_YNsAAAAEE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:54.414378 2026] [security2:error] [pid 983757:tid 983992] [client 171.60.139.123:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W3nKwMdFW9UVnNBSO5QAAAXE"]
[Mon Jul 20 06:38:54.414530 2026] [security2:error] [pid 983757:tid 983992] [client 171.60.139.123:62679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W3nKwMdFW9UVnNBSO5QAAAXE"]
[Mon Jul 20 06:38:54.568895 2026] [security2:error] [pid 983757:tid 983915] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W3nKwMdFW9UVnNBSO4wAAASQ"]
[Mon Jul 20 06:38:54.658279 2026] [proxy:error] [pid 966386:tid 966624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:54.658352 2026] [proxy_http:error] [pid 966386:tid 966624] [client 34.73.38.214:50110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:54.658855 2026] [proxy:error] [pid 966386:tid 966624] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:54.658880 2026] [proxy_http:error] [pid 966386:tid 966624] [client 34.73.38.214:50110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:54.922723 2026] [security2:error] [pid 966386:tid 966609] [client 14.251.3.155:54545] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4W3jrLBqY1mBmWu_YNygAAAC8"]
[Mon Jul 20 06:38:54.931826 2026] [security2:error] [pid 966386:tid 966588] [client 14.225.17.146:65464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4W3jrLBqY1mBmWu_YNxAAAABo"], referer: http://lutheranphilosopher.com/oldsite
[Mon Jul 20 06:38:54.979451 2026] [security2:error] [pid 966386:tid 966686] [client 14.225.17.146:65466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4W3jrLBqY1mBmWu_YNxQAAAHk"], referer: http://mtlegnews.gov/oldsite
[Mon Jul 20 06:38:54.986228 2026] [security2:error] [pid 966386:tid 966689] [client 161.118.195.148:63768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W3jrLBqY1mBmWu_YNzwAAAHw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:55.036234 2026] [security2:error] [pid 966386:tid 966623] [client 103.125.179.95:52139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W3zrLBqY1mBmWu_YN0gAAAD0"]
[Mon Jul 20 06:38:55.046793 2026] [security2:error] [pid 966386:tid 966623] [client 103.125.179.95:52139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W3zrLBqY1mBmWu_YN0gAAAD0"]
[Mon Jul 20 06:38:55.160567 2026] [security2:error] [pid 983757:tid 983902] [client 77.110.127.138:51799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W33KwMdFW9UVnNBSO-wAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:55.160638 2026] [security2:error] [pid 983757:tid 983902] [client 77.110.127.138:51799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W33KwMdFW9UVnNBSO-wAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:55.314712 2026] [security2:error] [pid 966386:tid 966672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W3zrLBqY1mBmWu_YN2AAAAGs"]
[Mon Jul 20 06:38:55.488005 2026] [security2:error] [pid 983757:tid 983937] [client 77.110.127.138:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W33KwMdFW9UVnNBSPEgAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:55.488132 2026] [security2:error] [pid 983757:tid 983937] [client 77.110.127.138:51737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W33KwMdFW9UVnNBSPEgAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:38:55.515593 2026] [security2:error] [pid 966386:tid 966683] [client 14.225.17.146:50126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4W3zrLBqY1mBmWu_YN3gAAAHY"], referer: http://lifeisbetterlakeside.com/oldsite
[Mon Jul 20 06:38:55.563140 2026] [security2:error] [pid 983757:tid 983957] [client 161.118.195.148:64131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W33KwMdFW9UVnNBSPFgAAAU4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:55.638729 2026] [security2:error] [pid 983757:tid 983977] [client 77.110.127.138:51802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W33KwMdFW9UVnNBSPIAAAAWI"]
[Mon Jul 20 06:38:55.638842 2026] [security2:error] [pid 983757:tid 983977] [client 77.110.127.138:51802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W33KwMdFW9UVnNBSPIAAAAWI"]
[Mon Jul 20 06:38:55.769839 2026] [security2:error] [pid 966386:tid 966586] [client 57.141.18.38:46042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W2jrLBqY1mBmWu_YNHQAAGDo"]
[Mon Jul 20 06:38:55.812522 2026] [security2:error] [pid 983757:tid 983960] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W33KwMdFW9UVnNBSPGgAAAVE"]
[Mon Jul 20 06:38:55.844381 2026] [security2:error] [pid 983757:tid 983962] [client 66.249.73.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.almaz-aura.net"] [uri "/index.php"] [unique_id "al4W33KwMdFW9UVnNBSPEwAAAVM"]
[Mon Jul 20 06:38:56.100701 2026] [security2:error] [pid 983757:tid 983941] [client 57.141.18.58:43774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W23KwMdFW9UVnNBSOQAABPik"]
[Mon Jul 20 06:38:56.141376 2026] [security2:error] [pid 983757:tid 983928] [client 161.118.195.148:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W4HKwMdFW9UVnNBSPOwAAATE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:56.197847 2026] [security2:error] [pid 983757:tid 984006] [client 57.141.18.32:32994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W23KwMdFW9UVnNBSOUQABf1w"]
[Mon Jul 20 06:38:56.323225 2026] [security2:error] [pid 966386:tid 966637] [client 106.219.188.178:8577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W4DrLBqY1mBmWu_YOCgAAAEs"]
[Mon Jul 20 06:38:56.323583 2026] [security2:error] [pid 966386:tid 966637] [client 106.219.188.178:8577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W4DrLBqY1mBmWu_YOCgAAAEs"]
[Mon Jul 20 06:38:56.465332 2026] [security2:error] [pid 983757:tid 984002] [client 77.110.127.138:51806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W4HKwMdFW9UVnNBSPSAAAAXs"]
[Mon Jul 20 06:38:56.465438 2026] [security2:error] [pid 983757:tid 984002] [client 77.110.127.138:51806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W4HKwMdFW9UVnNBSPSAAAAXs"]
[Mon Jul 20 06:38:56.501884 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W4DrLBqY1mBmWu_YOBQAAAHo"]
[Mon Jul 20 06:38:56.528357 2026] [proxy:error] [pid 983757:tid 983982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:56.528417 2026] [proxy_http:error] [pid 983757:tid 983982] [client 34.73.38.214:52778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:56.528832 2026] [proxy:error] [pid 983757:tid 983982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:56.528855 2026] [proxy_http:error] [pid 983757:tid 983982] [client 34.73.38.214:52778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:56.715837 2026] [security2:error] [pid 983757:tid 983974] [client 161.118.195.148:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W4HKwMdFW9UVnNBSPVAAAAV8"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:56.736025 2026] [security2:error] [pid 983757:tid 983919] [client 65.111.4.76:53655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.4.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4W4HKwMdFW9UVnNBSPUgAAASg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:38:57.007711 2026] [security2:error] [pid 983757:tid 983927] [client 14.225.17.146:53020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4W4HKwMdFW9UVnNBSPTwAAATA"], referer: http://mollycahill.com/oldsite
[Mon Jul 20 06:38:57.101699 2026] [security2:error] [pid 983757:tid 983935] [client 112.208.70.94:42074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W4XKwMdFW9UVnNBSPXgAAATg"]
[Mon Jul 20 06:38:57.101879 2026] [security2:error] [pid 983757:tid 983935] [client 112.208.70.94:42074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W4XKwMdFW9UVnNBSPXgAAATg"]
[Mon Jul 20 06:38:57.254731 2026] [security2:error] [pid 966386:tid 966607] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W4TrLBqY1mBmWu_YOMQAAAC0"]
[Mon Jul 20 06:38:57.296911 2026] [security2:error] [pid 966386:tid 966585] [client 161.118.195.148:65169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W4TrLBqY1mBmWu_YOPQAAABc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:57.392676 2026] [security2:error] [pid 983757:tid 983915] [client 14.225.17.146:52540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4W33KwMdFW9UVnNBSPMQAAASQ"], referer: http://reosportsboats.com/oldsite
[Mon Jul 20 06:38:57.648049 2026] [security2:error] [pid 983757:tid 983909] [client 57.141.18.50:47210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W3XKwMdFW9UVnNBSOnAABHms"]
[Mon Jul 20 06:38:57.712358 2026] [proxy:error] [pid 983757:tid 983992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:57.712440 2026] [proxy_http:error] [pid 983757:tid 983992] [client 34.73.38.214:58004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:57.713892 2026] [proxy:error] [pid 983757:tid 983992] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:38:57.713947 2026] [proxy_http:error] [pid 983757:tid 983992] [client 34.73.38.214:58004] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:38:57.726817 2026] [security2:error] [pid 983757:tid 983920] [client 14.225.17.146:49158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4W4XKwMdFW9UVnNBSPZgAAASk"], referer: http://nwcarvingacademy.com/oldsite
[Mon Jul 20 06:38:57.849655 2026] [security2:error] [pid 983757:tid 984011] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W4XKwMdFW9UVnNBSPaQAAAYQ"]
[Mon Jul 20 06:38:57.872233 2026] [security2:error] [pid 983757:tid 983896] [client 161.118.195.148:49154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W4XKwMdFW9UVnNBSPgAAAARE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:57.958745 2026] [security2:error] [pid 983757:tid 983781] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W4XKwMdFW9UVnNBSPgwABShU"]
[Mon Jul 20 06:38:57.958991 2026] [security2:error] [pid 983757:tid 983953] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W4XKwMdFW9UVnNBSPgwABShU"]
[Mon Jul 20 06:38:58.194124 2026] [security2:error] [pid 966386:tid 966622] [client 14.225.17.146:53027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4W4DrLBqY1mBmWu_YOIQAAADw"], referer: http://vinovinhowine.com/oldsite
[Mon Jul 20 06:38:58.453409 2026] [security2:error] [pid 983757:tid 983897] [client 161.118.195.148:49521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W4nKwMdFW9UVnNBSPnwAAARI"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:58.491979 2026] [security2:error] [pid 983757:tid 983911] [client 14.225.17.146:61538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4W4XKwMdFW9UVnNBSPYgAAASA"], referer: http://whiteoutcb.com/oldsite
[Mon Jul 20 06:38:58.501357 2026] [autoindex:error] [pid 966386:tid 966600] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:38:58.536047 2026] [security2:error] [pid 966386:tid 966612] [client 14.225.17.146:61108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4W4jrLBqY1mBmWu_YObAAAADI"], referer: https://reosportsboats.com/oldsite
[Mon Jul 20 06:38:58.557256 2026] [security2:error] [pid 983757:tid 983961] [client 14.225.17.146:61208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4W4XKwMdFW9UVnNBSPYQAAAVI"], referer: http://expertcultures.com/oldsite
[Mon Jul 20 06:38:58.753293 2026] [security2:error] [pid 966386:tid 966560] [client 216.73.217.138:55240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W4jrLBqY1mBmWu_YOegAAAEc"]
[Mon Jul 20 06:38:58.762632 2026] [security2:error] [pid 966386:tid 966500] [remote 216.73.217.138:55240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W4jrLBqY1mBmWu_YOeQAAAEY"]
[Mon Jul 20 06:38:58.838227 2026] [security2:error] [pid 966386:tid 966618] [client 34.73.38.214:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W4jrLBqY1mBmWu_YOiwAAADg"]
[Mon Jul 20 06:38:58.894755 2026] [security2:error] [pid 983757:tid 983992] [client 187.108.85.186:51304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W4nKwMdFW9UVnNBSPswAAAXE"]
[Mon Jul 20 06:38:58.894863 2026] [security2:error] [pid 983757:tid 983992] [client 187.108.85.186:51304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W4nKwMdFW9UVnNBSPswAAAXE"]
[Mon Jul 20 06:38:58.919930 2026] [security2:error] [pid 983757:tid 983902] [client 14.225.17.146:65135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4W4nKwMdFW9UVnNBSPqgAAARc"], referer: https://nwcarvingacademy.com/oldsite
[Mon Jul 20 06:38:59.028633 2026] [security2:error] [pid 983757:tid 983997] [client 161.118.195.148:49911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W43KwMdFW9UVnNBSPugAAAXY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:59.093140 2026] [security2:error] [pid 983757:tid 983995] [client 104.234.53.56:23801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4W43KwMdFW9UVnNBSPuwAAAXQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:38:59.231739 2026] [security2:error] [pid 966386:tid 966671] [client 14.225.17.146:53138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4W4DrLBqY1mBmWu_YOKgAAAGo"], referer: http://drewsasburyparkbeachhouse.com/oldsite
[Mon Jul 20 06:38:59.600585 2026] [security2:error] [pid 983757:tid 983891] [client 161.118.195.148:50246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W43KwMdFW9UVnNBSP0wAAAQw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:38:59.602300 2026] [security2:error] [pid 983757:tid 983942] [client 57.141.18.6:29552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W33KwMdFW9UVnNBSPDwABPwQ"]
[Mon Jul 20 06:38:59.769469 2026] [security2:error] [pid 966386:tid 966600] [client 34.73.38.214:64972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4W4zrLBqY1mBmWu_YOqwAAACY"]
[Mon Jul 20 06:38:59.787375 2026] [security2:error] [pid 983757:tid 983970] [client 14.225.17.146:62019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4W4nKwMdFW9UVnNBSPogAAAVs"], referer: http://cloudspacesgroup.com/oldsite
[Mon Jul 20 06:38:59.990117 2026] [security2:error] [pid 983757:tid 983802] [remote 5.182.209.54:36612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4W43KwMdFW9UVnNBSP5AABWio"]
[Mon Jul 20 06:39:00.042825 2026] [security2:error] [pid 983757:tid 983917] [client 57.141.18.4:34534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W33KwMdFW9UVnNBSPLgABJlc"]
[Mon Jul 20 06:39:00.166785 2026] [security2:error] [pid 966386:tid 966655] [client 14.225.17.146:61082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4W4jrLBqY1mBmWu_YOjQAAAF0"], referer: http://betterbonddogtraining.com/oldsite
[Mon Jul 20 06:39:00.173420 2026] [security2:error] [pid 983757:tid 983976] [client 161.118.195.148:50582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W5HKwMdFW9UVnNBSP7wAAAWE"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:00.206756 2026] [security2:error] [pid 983757:tid 983931] [client 74.7.227.179:50238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4W5HKwMdFW9UVnNBSP7QABNCI"], referer: https://tejasenvironmental.com/p=788502
[Mon Jul 20 06:39:00.233308 2026] [security2:error] [pid 983757:tid 983979] [client 77.110.127.138:51827] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4W5HKwMdFW9UVnNBSP8gAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:00.282371 2026] [security2:error] [pid 966386:tid 966691] [client 77.110.127.138:51800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5DrLBqY1mBmWu_YOvwAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:00.282482 2026] [security2:error] [pid 966386:tid 966691] [client 77.110.127.138:51800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5DrLBqY1mBmWu_YOvwAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:00.298665 2026] [security2:error] [pid 983757:tid 983941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W5HKwMdFW9UVnNBSP7AAAAT4"], referer: 1'"3000
[Mon Jul 20 06:39:00.414564 2026] [security2:error] [pid 983757:tid 983821] [remote 5.182.209.54:36612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4W5HKwMdFW9UVnNBSP-gABSD0"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 06:39:00.479624 2026] [security2:error] [pid 983757:tid 983971] [client 14.225.17.146:53859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4W43KwMdFW9UVnNBSPvQAAAVw"], referer: http://blaizeaccountingservices.com/oldsite
[Mon Jul 20 06:39:00.527432 2026] [security2:error] [pid 983757:tid 983948] [client 103.238.106.162:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W5HKwMdFW9UVnNBSP_QAAAUU"]
[Mon Jul 20 06:39:00.527560 2026] [security2:error] [pid 983757:tid 983948] [client 103.238.106.162:60876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W5HKwMdFW9UVnNBSP_QAAAUU"]
[Mon Jul 20 06:39:00.605682 2026] [security2:error] [pid 966386:tid 966609] [client 34.73.38.214:53635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4W5DrLBqY1mBmWu_YOxwAAAC8"]
[Mon Jul 20 06:39:00.690995 2026] [security2:error] [pid 983757:tid 983815] [remote 194.164.192.228:52414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4W5HKwMdFW9UVnNBSQBQABcDc"]
[Mon Jul 20 06:39:00.747390 2026] [security2:error] [pid 983757:tid 983954] [client 161.118.195.148:50941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W5HKwMdFW9UVnNBSQCAAAAUs"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:00.793982 2026] [security2:error] [pid 983757:tid 983996] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W5HKwMdFW9UVnNBSQAAAAAXU"], referer: 1'"3000
[Mon Jul 20 06:39:00.861652 2026] [security2:error] [pid 983757:tid 983814] [remote 124.55.178.99:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4W5HKwMdFW9UVnNBSQEQABETY"]
[Mon Jul 20 06:39:00.890836 2026] [security2:error] [pid 983757:tid 983811] [remote 194.164.192.228:52414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4W5HKwMdFW9UVnNBSQEwABbDM"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 06:39:01.291226 2026] [security2:error] [pid 966386:tid 966622] [client 114.119.128.154:41071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "greenvillemoving.com"] [uri "/robots.txt"] [unique_id "al4W5TrLBqY1mBmWu_YO3QAAADw"], referer: http://greenvillemoving.com/robots.txt
[Mon Jul 20 06:39:01.297148 2026] [security2:error] [pid 983757:tid 983818] [remote 124.55.178.99:33646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4W5XKwMdFW9UVnNBSQKwABPzo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:39:01.319760 2026] [security2:error] [pid 966386:tid 966598] [client 161.118.195.148:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W5TrLBqY1mBmWu_YO3gAAACQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:01.388972 2026] [security2:error] [pid 983757:tid 983899] [client 152.58.191.29:61689] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4W5XKwMdFW9UVnNBSQMwAAARQ"]
[Mon Jul 20 06:39:01.389123 2026] [security2:error] [pid 983757:tid 983899] [client 152.58.191.29:61689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4W5XKwMdFW9UVnNBSQMwAAARQ"]
[Mon Jul 20 06:39:01.558669 2026] [security2:error] [pid 966386:tid 966547] [remote 162.19.86.63:41888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/wp-login.php"] [unique_id "al4W5TrLBqY1mBmWu_YO7gAAdnU"]
[Mon Jul 20 06:39:01.677187 2026] [security2:error] [pid 983757:tid 983974] [client 34.73.38.214:65520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4W5XKwMdFW9UVnNBSQPAAAAV8"]
[Mon Jul 20 06:39:01.740185 2026] [security2:error] [pid 966386:tid 966447] [remote 162.19.86.63:41888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/wp-login.php"] [unique_id "al4W5TrLBqY1mBmWu_YO_AAAIBQ"], referer: https://elementconstruction.co.uk/wp-login.php
[Mon Jul 20 06:39:01.892221 2026] [security2:error] [pid 983757:tid 983966] [client 161.118.195.148:51614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W5XKwMdFW9UVnNBSQQgAAAVc"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:02.137848 2026] [security2:error] [pid 983757:tid 983963] [client 57.141.18.60:43066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W4nKwMdFW9UVnNBSPiQABVB0"]
[Mon Jul 20 06:39:02.303669 2026] [security2:error] [pid 983757:tid 983897] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4W5nKwMdFW9UVnNBSQUAAAARI"]
[Mon Jul 20 06:39:02.403278 2026] [security2:error] [pid 983757:tid 983996] [client 14.225.17.146:55330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4W5nKwMdFW9UVnNBSQTgAAAXU"], referer: http://itdynamix.com/oldsite
[Mon Jul 20 06:39:02.467973 2026] [security2:error] [pid 966386:tid 966663] [client 161.118.195.148:51936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W5jrLBqY1mBmWu_YPGwAAAGQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:02.827440 2026] [security2:error] [pid 983757:tid 984012] [client 34.73.38.214:65216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4W5nKwMdFW9UVnNBSQbQAAAYU"]
[Mon Jul 20 06:39:02.862693 2026] [security2:error] [pid 966386:tid 966685] [client 77.110.127.138:51819] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4W5jrLBqY1mBmWu_YPMAAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:02.877902 2026] [security2:error] [pid 966386:tid 966438] [remote 47.86.33.52:6800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W5jrLBqY1mBmWu_YPMQAACws"]
[Mon Jul 20 06:39:02.912273 2026] [security2:error] [pid 966386:tid 966627] [client 77.110.127.138:51820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5jrLBqY1mBmWu_YPNQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:02.912367 2026] [security2:error] [pid 966386:tid 966627] [client 77.110.127.138:51820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5jrLBqY1mBmWu_YPNQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:02.946219 2026] [security2:error] [pid 983757:tid 983899] [client 158.173.89.95:34471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4W5nKwMdFW9UVnNBSQcAAAARQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:39:03.041107 2026] [security2:error] [pid 983757:tid 983924] [client 161.118.195.148:52275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W53KwMdFW9UVnNBSQcwAAAS0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:03.090903 2026] [security2:error] [pid 966386:tid 966672] [client 217.142.18.172:45928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W5zrLBqY1mBmWu_YPQAAAAGs"]
[Mon Jul 20 06:39:03.091033 2026] [security2:error] [pid 966386:tid 966672] [client 217.142.18.172:45928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W5zrLBqY1mBmWu_YPQAAAAGs"]
[Mon Jul 20 06:39:03.093574 2026] [security2:error] [pid 983757:tid 984013] [client 223.185.13.213:18256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W53KwMdFW9UVnNBSQdAAAAYY"]
[Mon Jul 20 06:39:03.093642 2026] [security2:error] [pid 983757:tid 984013] [client 223.185.13.213:18256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W53KwMdFW9UVnNBSQdAAAAYY"]
[Mon Jul 20 06:39:03.255427 2026] [security2:error] [pid 983757:tid 983922] [client 77.110.127.138:51827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W53KwMdFW9UVnNBSQeAAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.255518 2026] [security2:error] [pid 983757:tid 983922] [client 77.110.127.138:51827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W53KwMdFW9UVnNBSQeAAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.387532 2026] [security2:error] [pid 966386:tid 966570] [client 14.225.17.146:61420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4W5zrLBqY1mBmWu_YPRgAAAAg"], referer: https://itdynamix.com/oldsite
[Mon Jul 20 06:39:03.408147 2026] [security2:error] [pid 966386:tid 966618] [client 77.110.127.138:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5zrLBqY1mBmWu_YPUAAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.408224 2026] [security2:error] [pid 966386:tid 966618] [client 77.110.127.138:51844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5zrLBqY1mBmWu_YPUAAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.611514 2026] [security2:error] [pid 966386:tid 966625] [client 34.73.38.214:56968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4W5zrLBqY1mBmWu_YPVwAAAD8"]
[Mon Jul 20 06:39:03.614397 2026] [security2:error] [pid 983757:tid 983997] [client 161.118.195.148:52607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W53KwMdFW9UVnNBSQjgAAAXY"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:03.687610 2026] [security2:error] [pid 983757:tid 983923] [client 171.61.165.146:19813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W53KwMdFW9UVnNBSQlgAAASw"]
[Mon Jul 20 06:39:03.688597 2026] [security2:error] [pid 983757:tid 983923] [client 171.61.165.146:19813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W53KwMdFW9UVnNBSQlgAAASw"]
[Mon Jul 20 06:39:03.716080 2026] [security2:error] [pid 966386:tid 966663] [client 77.110.127.138:51825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5zrLBqY1mBmWu_YPXAAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.716176 2026] [security2:error] [pid 966386:tid 966663] [client 77.110.127.138:51825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5zrLBqY1mBmWu_YPXAAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.751485 2026] [security2:error] [pid 966386:tid 966641] [client 34.73.38.214:60287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4W5zrLBqY1mBmWu_YPXwAAAE8"]
[Mon Jul 20 06:39:03.762285 2026] [proxy:error] [pid 983757:tid 983909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:03.762356 2026] [proxy_http:error] [pid 983757:tid 983909] [client 178.128.170.91:53878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:39:03.762877 2026] [proxy:error] [pid 983757:tid 983909] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:03.762905 2026] [proxy_http:error] [pid 983757:tid 983909] [client 178.128.170.91:53878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:39:03.909922 2026] [security2:error] [pid 966386:tid 966660] [client 77.110.127.138:51845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5zrLBqY1mBmWu_YPaQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:03.910025 2026] [security2:error] [pid 966386:tid 966660] [client 77.110.127.138:51845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W5zrLBqY1mBmWu_YPaQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:04.104340 2026] [security2:error] [pid 983757:tid 983894] [client 197.186.66.42:63065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W6HKwMdFW9UVnNBSQsgAAAQ8"]
[Mon Jul 20 06:39:04.113195 2026] [security2:error] [pid 983757:tid 983894] [client 197.186.66.42:63065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W6HKwMdFW9UVnNBSQsgAAAQ8"]
[Mon Jul 20 06:39:04.113670 2026] [security2:error] [pid 983757:tid 983914] [client 14.225.17.146:51701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4W53KwMdFW9UVnNBSQqwAAASM"], referer: http://mazzucelli.com/oldsite
[Mon Jul 20 06:39:04.118771 2026] [proxy:error] [pid 983757:tid 983961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:04.118844 2026] [proxy_http:error] [pid 983757:tid 983961] [client 178.128.170.91:53888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.travelbyfire.com/
[Mon Jul 20 06:39:04.119525 2026] [proxy:error] [pid 983757:tid 983961] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:04.119564 2026] [proxy_http:error] [pid 983757:tid 983961] [client 178.128.170.91:53888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.travelbyfire.com/
[Mon Jul 20 06:39:04.188025 2026] [security2:error] [pid 983757:tid 983936] [client 161.118.195.148:52979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W6HKwMdFW9UVnNBSQvAAAATk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:04.244309 2026] [security2:error] [pid 983757:tid 984014] [client 104.234.53.91:38639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4W6HKwMdFW9UVnNBSQvQAAAYc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:04.335274 2026] [security2:error] [pid 966386:tid 966653] [client 77.110.127.138:51803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W6DrLBqY1mBmWu_YPcwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:04.335413 2026] [security2:error] [pid 966386:tid 966653] [client 77.110.127.138:51803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W6DrLBqY1mBmWu_YPcwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:04.430428 2026] [security2:error] [pid 983757:tid 984008] [client 34.73.38.214:62726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4W6HKwMdFW9UVnNBSQwwAAAYE"]
[Mon Jul 20 06:39:04.494433 2026] [security2:error] [pid 983757:tid 983917] [client 77.110.127.138:51847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W6HKwMdFW9UVnNBSQxwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:04.494543 2026] [security2:error] [pid 983757:tid 983917] [client 77.110.127.138:51847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W6HKwMdFW9UVnNBSQxwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:04.686240 2026] [security2:error] [pid 983757:tid 983935] [client 74.7.241.185:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "seedsofchangefilm.com"] [uri "/index.php"] [unique_id "al4W53KwMdFW9UVnNBSQnAABOFE"]
[Mon Jul 20 06:39:04.706810 2026] [core:error] [pid 966386:tid 966691] [client 178.128.170.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:39:04.706834 2026] [core:error] [pid 966386:tid 966691] [client 178.128.170.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:39:04.724692 2026] [security2:error] [pid 983757:tid 983972] [client 14.225.17.146:52079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4W6HKwMdFW9UVnNBSQyQAAAV0"], referer: http://aljosour-alarabia.com/oldsite
[Mon Jul 20 06:39:04.762856 2026] [security2:error] [pid 966386:tid 966624] [client 161.118.195.148:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W6DrLBqY1mBmWu_YPjgAAAD4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:04.778336 2026] [security2:error] [pid 966386:tid 966681] [client 34.73.38.214:63750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4W6DrLBqY1mBmWu_YPjwAAAHQ"]
[Mon Jul 20 06:39:04.948444 2026] [security2:error] [pid 983757:tid 983998] [client 14.225.17.146:55766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4W6HKwMdFW9UVnNBSQuAAAAXc"], referer: http://mrbambooplus.com/oldsite
[Mon Jul 20 06:39:04.955100 2026] [security2:error] [pid 966386:tid 966615] [client 14.225.17.146:55783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4W6DrLBqY1mBmWu_YPjQAAADU"], referer: http://thesoloceos.com/oldsite
[Mon Jul 20 06:39:05.035098 2026] [security2:error] [pid 966386:tid 966608] [client 14.225.17.146:62159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4W6DrLBqY1mBmWu_YPlAAAAC4"], referer: http://superiorcopywriting.com/oldsite
[Mon Jul 20 06:39:05.056460 2026] [security2:error] [pid 983757:tid 983982] [client 171.60.139.123:63207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W6XKwMdFW9UVnNBSQ0wAAAWc"]
[Mon Jul 20 06:39:05.056599 2026] [security2:error] [pid 983757:tid 983982] [client 171.60.139.123:63207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W6XKwMdFW9UVnNBSQ0wAAAWc"]
[Mon Jul 20 06:39:05.101845 2026] [security2:error] [pid 983757:tid 983995] [client 57.141.18.23:25294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W5XKwMdFW9UVnNBSQRAABdEA"]
[Mon Jul 20 06:39:05.197652 2026] [security2:error] [pid 983757:tid 983933] [client 34.73.38.214:55131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4W6XKwMdFW9UVnNBSQ2AAAATY"]
[Mon Jul 20 06:39:05.340119 2026] [security2:error] [pid 966386:tid 966642] [client 39.48.81.23:53283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W6TrLBqY1mBmWu_YPrAAAAFA"]
[Mon Jul 20 06:39:05.340270 2026] [security2:error] [pid 966386:tid 966642] [client 39.48.81.23:53283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W6TrLBqY1mBmWu_YPrAAAAFA"]
[Mon Jul 20 06:39:05.340515 2026] [security2:error] [pid 983757:tid 983892] [client 161.118.195.148:53676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W6XKwMdFW9UVnNBSQ4gAAAQ0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:05.431582 2026] [security2:error] [pid 983757:tid 984003] [client 173.239.240.96:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W6XKwMdFW9UVnNBSQ5QAAAXw"]
[Mon Jul 20 06:39:05.548183 2026] [security2:error] [pid 966386:tid 966596] [client 57.141.18.96:41160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W5jrLBqY1mBmWu_YPDQAAImM"]
[Mon Jul 20 06:39:05.619319 2026] [security2:error] [pid 966386:tid 966594] [client 34.73.38.214:50491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4W6TrLBqY1mBmWu_YPugAAACA"]
[Mon Jul 20 06:39:05.747660 2026] [security2:error] [pid 966386:tid 966661] [client 103.125.179.95:52636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W6TrLBqY1mBmWu_YPvAAAAGI"]
[Mon Jul 20 06:39:05.747878 2026] [security2:error] [pid 966386:tid 966661] [client 103.125.179.95:52636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W6TrLBqY1mBmWu_YPvAAAAGI"]
[Mon Jul 20 06:39:05.789474 2026] [security2:error] [pid 983757:tid 983766] [remote 5.161.225.162:46082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W6XKwMdFW9UVnNBSQ9AABDgY"]
[Mon Jul 20 06:39:05.789635 2026] [security2:error] [pid 983757:tid 983893] [client 5.161.225.162:46082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W6XKwMdFW9UVnNBSQ9AABDgY"]
[Mon Jul 20 06:39:05.799245 2026] [security2:error] [pid 983757:tid 984006] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W6HKwMdFW9UVnNBSQygAAAX8"], referer: 1'"3000
[Mon Jul 20 06:39:05.914219 2026] [security2:error] [pid 966386:tid 966654] [client 161.118.195.148:54046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W6TrLBqY1mBmWu_YPwAAAAFw"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:05.930546 2026] [security2:error] [pid 966386:tid 966511] [remote 97.74.93.24:36404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4W6TrLBqY1mBmWu_YPwQAAJlE"]
[Mon Jul 20 06:39:05.956884 2026] [proxy:error] [pid 983757:tid 983993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:05.956919 2026] [proxy_http:error] [pid 983757:tid 983993] [client 94.154.43.177:27720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:39:05.957815 2026] [proxy:error] [pid 983757:tid 983993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:05.957850 2026] [proxy_http:error] [pid 983757:tid 983993] [client 94.154.43.177:27720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:39:06.011073 2026] [security2:error] [pid 966386:tid 966636] [client 14.225.17.146:51092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4W6TrLBqY1mBmWu_YPvwAAAEo"], referer: https://thesoloceos.com/oldsite
[Mon Jul 20 06:39:06.011183 2026] [proxy:error] [pid 983757:tid 983982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:06.011250 2026] [proxy_http:error] [pid 983757:tid 983982] [client 94.154.43.178:56422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:39:06.011878 2026] [proxy:error] [pid 983757:tid 983982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:39:06.011905 2026] [proxy_http:error] [pid 983757:tid 983982] [client 94.154.43.178:56422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:39:06.049252 2026] [autoindex:error] [pid 966386:tid 966686] [client 94.154.43.183:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:39:06.132916 2026] [security2:error] [pid 983757:tid 983952] [client 34.73.38.214:56634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4W6nKwMdFW9UVnNBSRDAAAAUk"]
[Mon Jul 20 06:39:06.326215 2026] [security2:error] [pid 966386:tid 966488] [remote 97.74.93.24:36404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4W6jrLBqY1mBmWu_YP1gAAejo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:39:06.349325 2026] [security2:error] [pid 966386:tid 966675] [client 57.141.18.83:39970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4W6TrLBqY1mBmWu_YPpgAAbnE"]
[Mon Jul 20 06:39:06.389357 2026] [security2:error] [pid 983757:tid 983914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W6XKwMdFW9UVnNBSRAgAAASM"], referer: 1'"3000
[Mon Jul 20 06:39:06.487295 2026] [security2:error] [pid 983757:tid 983925] [client 161.118.195.148:54411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W6nKwMdFW9UVnNBSRFwAAAS4"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:06.572726 2026] [security2:error] [pid 966386:tid 966650] [client 34.73.38.214:55535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.wcn.ktk.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4W6jrLBqY1mBmWu_YP4gAAAFg"]
[Mon Jul 20 06:39:06.607666 2026] [security2:error] [pid 966386:tid 966643] [client 77.110.127.138:51835] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4W6jrLBqY1mBmWu_YP5AAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:06.632730 2026] [security2:error] [pid 966386:tid 966682] [client 14.225.17.146:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4W6jrLBqY1mBmWu_YP2wAAAHU"], referer: http://aandarealtygroup.com/oldsite
[Mon Jul 20 06:39:06.784323 2026] [security2:error] [pid 983757:tid 983946] [client 106.219.188.178:15038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W6nKwMdFW9UVnNBSRKAAAAUM"]
[Mon Jul 20 06:39:06.785884 2026] [security2:error] [pid 983757:tid 983946] [client 106.219.188.178:15038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W6nKwMdFW9UVnNBSRKAAAAUM"]
[Mon Jul 20 06:39:06.813720 2026] [security2:error] [pid 966386:tid 966593] [client 65.111.2.208:29713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4W6jrLBqY1mBmWu_YP7QAAAB8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:07.061580 2026] [security2:error] [pid 983757:tid 983915] [client 161.118.195.148:54717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W63KwMdFW9UVnNBSRNwAAASQ"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:07.391977 2026] [security2:error] [pid 983757:tid 984013] [client 77.110.127.138:51867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W63KwMdFW9UVnNBSRQgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:07.392076 2026] [security2:error] [pid 983757:tid 984013] [client 77.110.127.138:51867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W63KwMdFW9UVnNBSRQgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:07.582246 2026] [security2:error] [pid 983757:tid 983935] [client 74.7.244.28:48118] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "meditacionmiami.com"] [uri "/cgi-sys/404.html"] [unique_id "al4W63KwMdFW9UVnNBSRTAAAATg"]
[Mon Jul 20 06:39:07.608728 2026] [security2:error] [pid 983757:tid 983963] [client 65.111.2.250:54565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4W63KwMdFW9UVnNBSRTQAAAVQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:07.636144 2026] [security2:error] [pid 983757:tid 983908] [client 161.118.195.148:55068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W63KwMdFW9UVnNBSRUQAAAR0"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:07.686708 2026] [security2:error] [pid 966386:tid 966632] [client 57.141.18.118:44116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W6DrLBqY1mBmWu_YPlQAARhE"]
[Mon Jul 20 06:39:07.719976 2026] [security2:error] [pid 966386:tid 966620] [client 112.208.70.94:42534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W6zrLBqY1mBmWu_YQFAAAADo"]
[Mon Jul 20 06:39:07.720098 2026] [security2:error] [pid 966386:tid 966620] [client 112.208.70.94:42534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W6zrLBqY1mBmWu_YQFAAAADo"]
[Mon Jul 20 06:39:07.822721 2026] [security2:error] [pid 966386:tid 966638] [client 57.141.18.91:44456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W6TrLBqY1mBmWu_YPogAATCU"]
[Mon Jul 20 06:39:07.858360 2026] [security2:error] [pid 983757:tid 983962] [client 14.225.17.146:51892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4W63KwMdFW9UVnNBSRVAAAAVM"], referer: http://inspirespublishing.com/oldsite
[Mon Jul 20 06:39:07.914628 2026] [security2:error] [pid 983757:tid 983917] [client 14.225.17.146:51938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4W63KwMdFW9UVnNBSRWgAAASY"], referer: http://ironcitywellness.com/oldsite
[Mon Jul 20 06:39:08.055609 2026] [core:error] [pid 983757:tid 983912] [client 178.128.170.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.travelbyfire.com/
[Mon Jul 20 06:39:08.055645 2026] [core:error] [pid 983757:tid 983912] [client 178.128.170.91:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpcalendars.travelbyfire.com/
[Mon Jul 20 06:39:08.142411 2026] [security2:error] [pid 983757:tid 983914] [client 77.110.127.138:51876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W7HKwMdFW9UVnNBSRfgAAASM"], referer: https://mezzacraft.com/baby-suri-tips-for-crochet/
[Mon Jul 20 06:39:08.142532 2026] [security2:error] [pid 983757:tid 983914] [client 77.110.127.138:51876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W7HKwMdFW9UVnNBSRfgAAASM"], referer: https://mezzacraft.com/baby-suri-tips-for-crochet/
[Mon Jul 20 06:39:08.195461 2026] [security2:error] [pid 983757:tid 983947] [client 173.239.240.92:20447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W7HKwMdFW9UVnNBSRggAAAUQ"]
[Mon Jul 20 06:39:08.208100 2026] [security2:error] [pid 983757:tid 983895] [client 161.118.195.148:55420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4W7HKwMdFW9UVnNBSRigAAARA"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:08.410379 2026] [security2:error] [pid 966386:tid 966661] [client 77.110.127.138:51881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet/page/ehy2zkftvcwj.php"] [unique_id "al4W7DrLBqY1mBmWu_YQOgAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:08.509258 2026] [security2:error] [pid 983757:tid 984001] [client 77.110.127.138:51882] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4W7HKwMdFW9UVnNBSRoAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:08.589391 2026] [security2:error] [pid 966386:tid 966510] [remote 160.187.68.132:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W7DrLBqY1mBmWu_YQPwAAT1A"]
[Mon Jul 20 06:39:08.776714 2026] [security2:error] [pid 983757:tid 984015] [client 57.141.18.3:27754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W6nKwMdFW9UVnNBSRCwABiD4"]
[Mon Jul 20 06:39:08.778774 2026] [security2:error] [pid 983757:tid 983916] [client 161.118.195.148:55770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.195.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-admin/index.php"] [unique_id "al4W7HKwMdFW9UVnNBSRswAAASU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:39:08.792860 2026] [security2:error] [pid 983757:tid 983986] [client 57.141.18.72:24754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W6nKwMdFW9UVnNBSRCQABa2o"]
[Mon Jul 20 06:39:08.825042 2026] [security2:error] [pid 983757:tid 983885] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W7HKwMdFW9UVnNBSRtgABQn0"]
[Mon Jul 20 06:39:08.825287 2026] [security2:error] [pid 983757:tid 983945] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W7HKwMdFW9UVnNBSRtgABQn0"]
[Mon Jul 20 06:39:09.051743 2026] [security2:error] [pid 983757:tid 984004] [client 50.116.65.227:51334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4W7XKwMdFW9UVnNBSRwgAAAX0"]
[Mon Jul 20 06:39:09.061739 2026] [security2:error] [pid 966386:tid 966609] [client 50.116.65.227:51340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4W7TrLBqY1mBmWu_YQSQAAAC8"]
[Mon Jul 20 06:39:09.083445 2026] [security2:error] [pid 966386:tid 966437] [remote 160.187.68.132:35650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W7TrLBqY1mBmWu_YQSgAAVwo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:39:09.211458 2026] [security2:error] [pid 983757:tid 983897] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7HKwMdFW9UVnNBSRlAAAARI"]
[Mon Jul 20 06:39:09.248499 2026] [security2:error] [pid 966386:tid 966616] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7DrLBqY1mBmWu_YQMAAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:09.278465 2026] [security2:error] [pid 983757:tid 984002] [client 77.110.127.138:51831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7HKwMdFW9UVnNBSRnAAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:09.311671 2026] [security2:error] [pid 983757:tid 983932] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7HKwMdFW9UVnNBSRnQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:09.343557 2026] [security2:error] [pid 983757:tid 983940] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7HKwMdFW9UVnNBSRnwAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:09.602112 2026] [security2:error] [pid 966386:tid 966663] [client 187.108.85.186:51841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W7TrLBqY1mBmWu_YQYwAAAGQ"]
[Mon Jul 20 06:39:09.602207 2026] [security2:error] [pid 966386:tid 966663] [client 187.108.85.186:51841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W7TrLBqY1mBmWu_YQYwAAAGQ"]
[Mon Jul 20 06:39:09.705626 2026] [security2:error] [pid 983757:tid 983929] [client 77.110.127.138:51891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet/page/2/xnw93gehyxry.php"] [unique_id "al4W7XKwMdFW9UVnNBSR5gAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:09.753502 2026] [security2:error] [pid 983757:tid 983891] [client 57.141.18.88:53488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W63KwMdFW9UVnNBSROgABDGw"]
[Mon Jul 20 06:39:09.788505 2026] [security2:error] [pid 983757:tid 983961] [client 152.58.191.29:62339] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4W7XKwMdFW9UVnNBSR4gAAAVI"]
[Mon Jul 20 06:39:09.788846 2026] [security2:error] [pid 983757:tid 983961] [client 152.58.191.29:62339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4W7XKwMdFW9UVnNBSR4gAAAVI"]
[Mon Jul 20 06:39:09.819410 2026] [security2:error] [pid 983757:tid 983897] [client 74.208.214.194:51532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4W7XKwMdFW9UVnNBSR9QAAARI"]
[Mon Jul 20 06:39:09.820273 2026] [security2:error] [pid 983757:tid 983930] [client 51.15.243.144:44016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5024.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4W7XKwMdFW9UVnNBSR9AAAATM"]
[Mon Jul 20 06:39:09.828998 2026] [security2:error] [pid 966386:tid 966682] [client 77.110.127.138:51839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7TrLBqY1mBmWu_YQZAAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:09.847203 2026] [security2:error] [pid 983757:tid 984016] [client 35.187.45.1:47504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4W7XKwMdFW9UVnNBSR8wAAAYk"]
[Mon Jul 20 06:39:10.037106 2026] [security2:error] [pid 983757:tid 983959] [client 136.144.35.250:39977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W7nKwMdFW9UVnNBSR-wAAAVA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:10.103872 2026] [security2:error] [pid 983757:tid 983893] [client 142.93.64.197:60970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.44"] [uri "/"] [unique_id "al4W7nKwMdFW9UVnNBSSAgAAAQ4"]
[Mon Jul 20 06:39:10.188131 2026] [security2:error] [pid 983757:tid 983985] [client 142.93.64.197:55498] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.44"] [uri "/"] [unique_id "al4W7nKwMdFW9UVnNBSSBQAAAWo"]
[Mon Jul 20 06:39:10.194134 2026] [security2:error] [pid 983757:tid 983977] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7XKwMdFW9UVnNBSR7AAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:10.293716 2026] [security2:error] [pid 983757:tid 983935] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7XKwMdFW9UVnNBSR7QAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:10.527741 2026] [security2:error] [pid 966386:tid 966589] [client 173.239.240.30:45719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W7jrLBqY1mBmWu_YQmgAAABs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:10.529480 2026] [security2:error] [pid 983757:tid 983962] [client 77.110.127.138:51882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/mezzacraft-crochet-newsletter/ghnt7w5z4roz.php"] [unique_id "al4W7nKwMdFW9UVnNBSSHgAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:10.788744 2026] [security2:error] [pid 983757:tid 984013] [client 54.244.177.189:33760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4W7nKwMdFW9UVnNBSSOQAAAYY"]
[Mon Jul 20 06:39:10.817937 2026] [security2:error] [pid 983757:tid 983778] [remote 154.66.198.148:50394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4W7nKwMdFW9UVnNBSSOwABQhI"]
[Mon Jul 20 06:39:10.872376 2026] [security2:error] [pid 966386:tid 966631] [client 77.110.127.138:51848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7jrLBqY1mBmWu_YQoQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:10.874557 2026] [security2:error] [pid 983757:tid 983930] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7nKwMdFW9UVnNBSSIwAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:10.932410 2026] [security2:error] [pid 983757:tid 983964] [client 57.141.18.104:56232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W7HKwMdFW9UVnNBSRngABVXs"]
[Mon Jul 20 06:39:11.009010 2026] [security2:error] [pid 983757:tid 983949] [client 173.239.240.91:53093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W7nKwMdFW9UVnNBSSQAAAAUY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:11.019565 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7jrLBqY1mBmWu_YQpAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:11.077919 2026] [security2:error] [pid 966386:tid 966671] [client 103.238.106.162:42671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W7zrLBqY1mBmWu_YQswAAAGo"]
[Mon Jul 20 06:39:11.078052 2026] [security2:error] [pid 966386:tid 966671] [client 103.238.106.162:42671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W7zrLBqY1mBmWu_YQswAAAGo"]
[Mon Jul 20 06:39:11.111484 2026] [security2:error] [pid 966386:tid 966593] [client 77.110.127.138:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W7zrLBqY1mBmWu_YQtAAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:11.111596 2026] [security2:error] [pid 966386:tid 966593] [client 77.110.127.138:51834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W7zrLBqY1mBmWu_YQtAAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:11.238162 2026] [security2:error] [pid 983757:tid 983878] [remote 134.209.147.209:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4W73KwMdFW9UVnNBSSRwABGXY"]
[Mon Jul 20 06:39:11.372204 2026] [security2:error] [pid 983757:tid 983859] [remote 154.66.198.148:50394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4W73KwMdFW9UVnNBSSVwABZmM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:39:11.475396 2026] [security2:error] [pid 983757:tid 983902] [client 173.239.240.93:29405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W73KwMdFW9UVnNBSSWAAAARc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:11.517746 2026] [security2:error] [pid 983757:tid 983968] [client 104.234.53.67:57027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSWgAAAVk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:11.649134 2026] [security2:error] [pid 983757:tid 983887] [remote 134.209.147.209:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4W73KwMdFW9UVnNBSSYQABDX8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:39:11.833481 2026] [security2:error] [pid 966386:tid 966579] [client 57.141.18.23:25310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W7TrLBqY1mBmWu_YQWwAAEUY"]
[Mon Jul 20 06:39:11.848094 2026] [security2:error] [pid 983757:tid 984011] [client 66.249.70.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSXQABhBk"]
[Mon Jul 20 06:39:11.861598 2026] [security2:error] [pid 983757:tid 983869] [remote 103.255.134.61:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4W73KwMdFW9UVnNBSScAABfG0"]
[Mon Jul 20 06:39:11.887949 2026] [security2:error] [pid 983757:tid 983912] [client 13.233.207.33:34224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4W73KwMdFW9UVnNBSSaAAAASE"]
[Mon Jul 20 06:39:11.962282 2026] [security2:error] [pid 983757:tid 983896] [client 136.144.35.249:41139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSfwAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:11.997520 2026] [security2:error] [pid 983757:tid 983975] [client 57.141.18.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSUwAAAWA"]
[Mon Jul 20 06:39:12.009257 2026] [security2:error] [pid 966386:tid 966632] [client 77.110.127.138:51902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/s96socrrd35u.php"] [unique_id "al4W8DrLBqY1mBmWu_YQ3AAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:12.078543 2026] [security2:error] [pid 966386:tid 966685] [client 35.187.45.1:47508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4W8DrLBqY1mBmWu_YQ3gAAAHg"]
[Mon Jul 20 06:39:12.223668 2026] [security2:error] [pid 983757:tid 983973] [client 77.110.127.138:51890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSeQAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:12.250020 2026] [security2:error] [pid 966386:tid 966574] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W7zrLBqY1mBmWu_YQ0gAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:12.275531 2026] [security2:error] [pid 983757:tid 983933] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSewAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:12.301583 2026] [security2:error] [pid 983757:tid 983900] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSfAAAARU"]
[Mon Jul 20 06:39:12.352839 2026] [security2:error] [pid 983757:tid 983798] [remote 103.75.185.95:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4W8HKwMdFW9UVnNBSSjwABfiY"]
[Mon Jul 20 06:39:12.386760 2026] [security2:error] [pid 983757:tid 983908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSShQAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:12.437985 2026] [security2:error] [pid 966386:tid 966615] [client 173.239.240.102:49223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W8DrLBqY1mBmWu_YQ7AAAADU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:12.463480 2026] [security2:error] [pid 983757:tid 983793] [remote 103.255.134.61:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4W8HKwMdFW9UVnNBSSkAABhiE"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:39:12.685463 2026] [security2:error] [pid 966386:tid 966633] [client 57.141.18.13:58924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W7jrLBqY1mBmWu_YQjgAARxk"]
[Mon Jul 20 06:39:12.688730 2026] [security2:error] [pid 983757:tid 983804] [remote 57.141.18.22:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5834995"] [unique_id "al4W8HKwMdFW9UVnNBSSnwABhCw"]
[Mon Jul 20 06:39:12.748376 2026] [security2:error] [pid 983757:tid 983947] [client 77.110.127.138:51893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/2/0yecuzysac9z.php"] [unique_id "al4W8HKwMdFW9UVnNBSSqAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:12.864658 2026] [security2:error] [pid 983757:tid 983802] [remote 103.75.185.95:45382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4W8HKwMdFW9UVnNBSSuQABFyo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:39:12.933233 2026] [security2:error] [pid 983757:tid 983975] [client 136.144.35.248:47667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W8HKwMdFW9UVnNBSSvgAAAWA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:12.987076 2026] [security2:error] [pid 983757:tid 983919] [client 144.76.32.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSSnQAAASg"]
[Mon Jul 20 06:39:13.028649 2026] [security2:error] [pid 983757:tid 983960] [client 43.205.139.3:46926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4W8XKwMdFW9UVnNBSSyAAAAVE"]
[Mon Jul 20 06:39:13.028732 2026] [security2:error] [pid 983757:tid 983960] [client 43.205.139.3:46926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4W8XKwMdFW9UVnNBSSyAAAAVE"]
[Mon Jul 20 06:39:13.155328 2026] [security2:error] [pid 983757:tid 983950] [client 77.110.127.138:51894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSSqgAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:13.324672 2026] [security2:error] [pid 983757:tid 983961] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSSswAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:13.326108 2026] [security2:error] [pid 983757:tid 983898] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSStQAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:13.405712 2026] [security2:error] [pid 966386:tid 966649] [client 136.144.35.252:48283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W8TrLBqY1mBmWu_YRBgAAAFc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:13.473440 2026] [security2:error] [pid 983757:tid 983917] [client 57.141.18.74:46550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W73KwMdFW9UVnNBSSQgABJhM"]
[Mon Jul 20 06:39:13.596061 2026] [security2:error] [pid 983757:tid 983947] [client 217.142.18.172:51478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W8XKwMdFW9UVnNBSS6gAAAUQ"]
[Mon Jul 20 06:39:13.602968 2026] [security2:error] [pid 983757:tid 983947] [client 217.142.18.172:51478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W8XKwMdFW9UVnNBSS6gAAAUQ"]
[Mon Jul 20 06:39:13.702690 2026] [security2:error] [pid 983757:tid 984001] [client 104.234.53.50:62727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4W8XKwMdFW9UVnNBSS7QAAAXo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:13.848612 2026] [security2:error] [pid 983757:tid 983943] [client 114.119.132.202:37559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/national-parks-journal/"] [unique_id "al4W8XKwMdFW9UVnNBSS-AAAAUA"], referer: https://jenfarley.com/childrens-drawing-workshops-events-with-jennifer-farley/
[Mon Jul 20 06:39:13.879616 2026] [security2:error] [pid 983757:tid 983895] [client 136.144.35.249:37503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W8XKwMdFW9UVnNBSS-gAAARA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:14.316310 2026] [security2:error] [pid 983757:tid 983909] [client 14.225.17.146:51184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4W8nKwMdFW9UVnNBSTDgAAAR4"], referer: http://keywayconstructionclt.com/oldsite
[Mon Jul 20 06:39:14.338666 2026] [security2:error] [pid 983757:tid 984003] [client 223.185.13.213:11416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W8nKwMdFW9UVnNBSTGQAAAXw"]
[Mon Jul 20 06:39:14.338788 2026] [security2:error] [pid 983757:tid 984003] [client 223.185.13.213:11416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W8nKwMdFW9UVnNBSTGQAAAXw"]
[Mon Jul 20 06:39:14.359508 2026] [security2:error] [pid 983757:tid 983896] [client 173.239.240.101:48371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W8nKwMdFW9UVnNBSTGgAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:14.438219 2026] [security2:error] [pid 983757:tid 984000] [client 171.61.165.146:9580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W8nKwMdFW9UVnNBSTIwAAAXk"]
[Mon Jul 20 06:39:14.438334 2026] [security2:error] [pid 983757:tid 984000] [client 171.61.165.146:9580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W8nKwMdFW9UVnNBSTIwAAAXk"]
[Mon Jul 20 06:39:14.555960 2026] [security2:error] [pid 983757:tid 983987] [client 57.141.18.107:49394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSSiAABbG4"]
[Mon Jul 20 06:39:14.623800 2026] [security2:error] [pid 983757:tid 983925] [client 57.141.18.80:65170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSSiQABLiU"]
[Mon Jul 20 06:39:14.811656 2026] [security2:error] [pid 983757:tid 983913] [client 136.144.35.248:23807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W8nKwMdFW9UVnNBSTMgAAASI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:14.933640 2026] [security2:error] [pid 983757:tid 983892] [client 197.186.66.42:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W8nKwMdFW9UVnNBSTOAAAAQ0"]
[Mon Jul 20 06:39:14.933992 2026] [security2:error] [pid 983757:tid 983892] [client 197.186.66.42:63594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W8nKwMdFW9UVnNBSTOAAAAQ0"]
[Mon Jul 20 06:39:14.944972 2026] [security2:error] [pid 983757:tid 983844] [remote 47.86.33.52:29210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W8nKwMdFW9UVnNBSTNwABZFQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:39:15.186179 2026] [security2:error] [pid 983757:tid 983914] [client 14.225.17.146:62671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4W83KwMdFW9UVnNBSTSQAAASM"], referer: https://keywayconstructionclt.com/oldsite
[Mon Jul 20 06:39:15.345773 2026] [security2:error] [pid 983757:tid 983896] [client 173.239.240.102:24555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W83KwMdFW9UVnNBSTUwAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:15.459395 2026] [security2:error] [pid 983757:tid 983955] [client 57.141.18.35:46874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W8HKwMdFW9UVnNBSSwQABTCc"]
[Mon Jul 20 06:39:15.471958 2026] [security2:error] [pid 983757:tid 983958] [client 14.225.17.146:51748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4W83KwMdFW9UVnNBSTRgAAAU8"]
[Mon Jul 20 06:39:15.607218 2026] [security2:error] [pid 983757:tid 983998] [client 171.60.139.123:63729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W83KwMdFW9UVnNBSTXwAAAXc"]
[Mon Jul 20 06:39:15.607372 2026] [security2:error] [pid 983757:tid 983998] [client 171.60.139.123:63729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W83KwMdFW9UVnNBSTXwAAAXc"]
[Mon Jul 20 06:39:15.833689 2026] [security2:error] [pid 983757:tid 983904] [client 173.239.240.102:41569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W83KwMdFW9UVnNBSTbgAAARk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:15.949447 2026] [security2:error] [pid 983757:tid 983932] [client 45.157.112.60:36851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4W83KwMdFW9UVnNBSTdwAAATU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:39:16.013734 2026] [security2:error] [pid 966386:tid 966610] [client 77.110.127.138:51811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W9DrLBqY1mBmWu_YRMwAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:16.013864 2026] [security2:error] [pid 966386:tid 966610] [client 77.110.127.138:51811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W9DrLBqY1mBmWu_YRMwAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:16.077174 2026] [security2:error] [pid 983757:tid 983872] [remote 8.217.108.67:36890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W9HKwMdFW9UVnNBSTgQABJ3A"]
[Mon Jul 20 06:39:16.077300 2026] [security2:error] [pid 983757:tid 983918] [client 8.217.108.67:36890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W9HKwMdFW9UVnNBSTgQABJ3A"]
[Mon Jul 20 06:39:16.147237 2026] [security2:error] [pid 983757:tid 983914] [client 163.172.144.16:58330] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5028.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4W9HKwMdFW9UVnNBSThAAAASM"]
[Mon Jul 20 06:39:16.222765 2026] [security2:error] [pid 983757:tid 983970] [client 104.234.53.89:22035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4W9HKwMdFW9UVnNBSThwAAAVs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:16.245670 2026] [security2:error] [pid 983757:tid 983871] [remote 95.217.78.234:47604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W9HKwMdFW9UVnNBSTjgABRG8"]
[Mon Jul 20 06:39:16.245877 2026] [security2:error] [pid 983757:tid 983947] [client 95.217.78.234:47604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4W9HKwMdFW9UVnNBSTjgABRG8"]
[Mon Jul 20 06:39:16.352905 2026] [security2:error] [pid 983757:tid 983923] [client 136.144.35.248:37345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W9HKwMdFW9UVnNBSTkgAAASw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:16.388293 2026] [security2:error] [pid 983757:tid 983959] [client 103.125.179.95:53136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W9HKwMdFW9UVnNBSTmQAAAVA"]
[Mon Jul 20 06:39:16.388661 2026] [security2:error] [pid 983757:tid 983959] [client 103.125.179.95:53136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W9HKwMdFW9UVnNBSTmQAAAVA"]
[Mon Jul 20 06:39:16.664227 2026] [security2:error] [pid 983757:tid 983986] [client 57.141.18.80:26398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W8nKwMdFW9UVnNBSTDQABa0o"]
[Mon Jul 20 06:39:16.688055 2026] [security2:error] [pid 966386:tid 966635] [client 39.48.81.23:54055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W9DrLBqY1mBmWu_YRRAAAAEk"]
[Mon Jul 20 06:39:16.688505 2026] [security2:error] [pid 966386:tid 966635] [client 39.48.81.23:54055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W9DrLBqY1mBmWu_YRRAAAAEk"]
[Mon Jul 20 06:39:16.783892 2026] [security2:error] [pid 983757:tid 983951] [client 105.246.21.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4W9HKwMdFW9UVnNBSTmwAAAUg"]
[Mon Jul 20 06:39:16.805556 2026] [security2:error] [pid 983757:tid 983909] [client 173.239.240.102:31825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W9HKwMdFW9UVnNBSTrgAAAR4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:16.860672 2026] [security2:error] [pid 983757:tid 983786] [remote 217.61.143.92:41372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4W9HKwMdFW9UVnNBSTsQABXho"]
[Mon Jul 20 06:39:17.279480 2026] [security2:error] [pid 983757:tid 983948] [client 57.141.18.83:48758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W8nKwMdFW9UVnNBSTNQABRU0"]
[Mon Jul 20 06:39:17.290111 2026] [security2:error] [pid 966386:tid 966653] [client 136.144.35.250:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W9TrLBqY1mBmWu_YRWAAAAFs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:17.407698 2026] [security2:error] [pid 983757:tid 983843] [remote 217.61.143.92:41380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBSTwgABH1M"]
[Mon Jul 20 06:39:17.459584 2026] [security2:error] [pid 983757:tid 983832] [remote 217.61.143.92:41372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBSTygABGUg"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 06:39:17.550898 2026] [security2:error] [pid 983757:tid 983777] [remote 192.241.143.148:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBSTzwABSxE"]
[Mon Jul 20 06:39:17.600891 2026] [security2:error] [pid 983757:tid 983905] [client 106.219.188.178:8607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W9XKwMdFW9UVnNBST0AAAARo"]
[Mon Jul 20 06:39:17.601050 2026] [security2:error] [pid 983757:tid 983905] [client 106.219.188.178:8607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4W9XKwMdFW9UVnNBST0AAAARo"]
[Mon Jul 20 06:39:17.655716 2026] [security2:error] [pid 983757:tid 983775] [remote 217.61.143.92:41380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBST1AABFw8"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:39:17.706068 2026] [security2:error] [pid 983757:tid 984008] [client 65.111.12.119:44827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBST1QAAAYE"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:17.723462 2026] [security2:error] [pid 983757:tid 983878] [remote 192.241.143.148:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBST3AABb3Y"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:39:17.799845 2026] [security2:error] [pid 983757:tid 983925] [client 173.239.240.97:24271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W9XKwMdFW9UVnNBST4QAAAS4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:18.031891 2026] [security2:error] [pid 983757:tid 983932] [client 14.225.17.146:51842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4W9XKwMdFW9UVnNBST6wAAATU"], referer: http://friendlyspreadsheet.com/oldsite
[Mon Jul 20 06:39:18.284784 2026] [security2:error] [pid 983757:tid 983969] [client 57.141.18.42:60670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W83KwMdFW9UVnNBSTdgABWmk"]
[Mon Jul 20 06:39:18.291172 2026] [security2:error] [pid 983757:tid 984011] [client 136.144.35.245:49257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W9nKwMdFW9UVnNBSUFwAAAYQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:18.307511 2026] [security2:error] [pid 983757:tid 983955] [client 104.234.53.91:47633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4W9nKwMdFW9UVnNBSUHQAAAUw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:18.356892 2026] [security2:error] [pid 966386:tid 966610] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4W9jrLBqY1mBmWu_YRawAAADA"]
[Mon Jul 20 06:39:18.362719 2026] [security2:error] [pid 983757:tid 984004] [client 112.208.70.94:42959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W9nKwMdFW9UVnNBSUIQAAAX0"]
[Mon Jul 20 06:39:18.362820 2026] [security2:error] [pid 983757:tid 984004] [client 112.208.70.94:42959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4W9nKwMdFW9UVnNBSUIQAAAX0"]
[Mon Jul 20 06:39:18.516554 2026] [security2:error] [pid 983757:tid 983917] [client 65.111.27.229:21403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4W9nKwMdFW9UVnNBSUJwAAASY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:39:18.553659 2026] [security2:error] [pid 966386:tid 966639] [client 45.3.37.250:28877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4W9jrLBqY1mBmWu_YReQAAAE0"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:18.796501 2026] [security2:error] [pid 983757:tid 983996] [client 173.239.240.98:22471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W9nKwMdFW9UVnNBSURAAAAXU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:18.812737 2026] [security2:error] [pid 983757:tid 983895] [client 50.116.65.227:51404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4W9nKwMdFW9UVnNBSURwAAARA"]
[Mon Jul 20 06:39:18.822148 2026] [security2:error] [pid 983757:tid 983916] [client 50.116.65.227:51418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4W9nKwMdFW9UVnNBSUSAAAASU"]
[Mon Jul 20 06:39:18.864845 2026] [security2:error] [pid 983757:tid 983957] [client 14.225.17.146:62125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4W9HKwMdFW9UVnNBSTrwAAAU4"], referer: http://jvcmotorsports.com/oldsite
[Mon Jul 20 06:39:18.961354 2026] [security2:error] [pid 983757:tid 983928] [client 14.225.17.146:51756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4W9nKwMdFW9UVnNBSUTgAAATE"], referer: https://friendlyspreadsheet.com/oldsite
[Mon Jul 20 06:39:19.184456 2026] [security2:error] [pid 983757:tid 983862] [remote 57.141.18.52:44108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4W93KwMdFW9UVnNBSUaAABJ2Y"]
[Mon Jul 20 06:39:19.240382 2026] [security2:error] [pid 966386:tid 966566] [client 163.172.166.82:55706] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5028.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4W9zrLBqY1mBmWu_YRhgAAAAQ"]
[Mon Jul 20 06:39:19.289425 2026] [security2:error] [pid 983757:tid 983919] [client 57.141.18.56:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W9XKwMdFW9UVnNBSTuwABKAA"]
[Mon Jul 20 06:39:19.290013 2026] [security2:error] [pid 966386:tid 966609] [client 173.239.240.101:35415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W9zrLBqY1mBmWu_YRhwAAAC8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:19.366551 2026] [security2:error] [pid 983757:tid 983936] [client 104.234.53.58:61685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4W93KwMdFW9UVnNBSUfAAAATk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:19.582317 2026] [security2:error] [pid 983757:tid 983875] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W93KwMdFW9UVnNBSUkAABH3M"]
[Mon Jul 20 06:39:19.582471 2026] [security2:error] [pid 983757:tid 983910] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4W93KwMdFW9UVnNBSUkAABH3M"]
[Mon Jul 20 06:39:19.697288 2026] [security2:error] [pid 966386:tid 966599] [client 57.141.18.69:48826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W9TrLBqY1mBmWu_YRZQAAJXg"]
[Mon Jul 20 06:39:19.806563 2026] [security2:error] [pid 966386:tid 966622] [client 173.239.240.90:24289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W9zrLBqY1mBmWu_YRkQAAADw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:19.923081 2026] [security2:error] [pid 983757:tid 983911] [client 34.74.185.202:59349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4W93KwMdFW9UVnNBSUqwAAASA"]
[Mon Jul 20 06:39:20.116283 2026] [security2:error] [pid 983757:tid 983765] [remote 162.19.86.63:47436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4W-HKwMdFW9UVnNBSUtgABHgU"]
[Mon Jul 20 06:39:20.116735 2026] [security2:error] [pid 983757:tid 983960] [client 114.119.146.230:42595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mollycahill.com"] [uri "/robots.txt"] [unique_id "al4W-HKwMdFW9UVnNBSUtwAAAVE"], referer: https://mollycahill.com/robots.txt
[Mon Jul 20 06:39:20.224676 2026] [security2:error] [pid 966386:tid 966691] [client 45.205.29.99:55738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mtlegnews.gov"] [uri "/"] [unique_id "al4W-DrLBqY1mBmWu_YRmQAAAH4"]
[Mon Jul 20 06:39:20.237345 2026] [security2:error] [pid 966386:tid 966680] [client 187.108.85.186:52378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W-DrLBqY1mBmWu_YRmwAAAHM"]
[Mon Jul 20 06:39:20.237481 2026] [security2:error] [pid 966386:tid 966680] [client 187.108.85.186:52378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W-DrLBqY1mBmWu_YRmwAAAHM"]
[Mon Jul 20 06:39:20.324855 2026] [security2:error] [pid 983757:tid 984012] [client 173.239.240.94:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W-HKwMdFW9UVnNBSUyQAAAYU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:20.340978 2026] [security2:error] [pid 983757:tid 983946] [client 14.225.17.146:51689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4W93KwMdFW9UVnNBSUcgAAAUM"], referer: http://grndl.com/oldsite
[Mon Jul 20 06:39:20.513735 2026] [security2:error] [pid 983757:tid 983973] [client 77.110.127.138:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W-HKwMdFW9UVnNBSU3gAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:20.513832 2026] [security2:error] [pid 983757:tid 983973] [client 77.110.127.138:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W-HKwMdFW9UVnNBSU3gAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:20.533261 2026] [security2:error] [pid 966386:tid 966657] [client 152.58.191.29:50617] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4W-DrLBqY1mBmWu_YRpgAAAF8"]
[Mon Jul 20 06:39:20.533403 2026] [security2:error] [pid 966386:tid 966657] [client 152.58.191.29:50617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4W-DrLBqY1mBmWu_YRpgAAAF8"]
[Mon Jul 20 06:39:20.630336 2026] [security2:error] [pid 983757:tid 984013] [client 104.234.53.59:21571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4W-HKwMdFW9UVnNBSU5QAAAYY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:20.669188 2026] [security2:error] [pid 983757:tid 983784] [remote 162.19.86.63:47436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4W-HKwMdFW9UVnNBSU5gABPBg"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:39:20.730090 2026] [security2:error] [pid 966386:tid 966589] [client 57.141.18.91:60816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W9jrLBqY1mBmWu_YRfwAAGw4"]
[Mon Jul 20 06:39:20.785266 2026] [core:error] [pid 966386:tid 966580] [client 66.249.73.164:63024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:39:20.785291 2026] [core:error] [pid 966386:tid 966580] [client 66.249.73.164:63024] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:39:20.793519 2026] [security2:error] [pid 983757:tid 983945] [client 173.239.240.101:31039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W-HKwMdFW9UVnNBSU8wAAAUI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:20.813398 2026] [security2:error] [pid 983757:tid 983970] [client 34.74.185.202:50644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4W-HKwMdFW9UVnNBSU-AAAAVs"]
[Mon Jul 20 06:39:20.985399 2026] [security2:error] [pid 983757:tid 983798] [remote 57.141.18.115:64650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4W-HKwMdFW9UVnNBSVAQABJCY"]
[Mon Jul 20 06:39:21.038344 2026] [security2:error] [pid 966386:tid 966688] [client 45.205.29.99:55799] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "mtredistricting.gov"] [uri "/"] [unique_id "al4W-TrLBqY1mBmWu_YRswAAAHs"]
[Mon Jul 20 06:39:21.057609 2026] [security2:error] [pid 983757:tid 983902] [client 57.141.18.31:37102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W9nKwMdFW9UVnNBSUTQABF1I"]
[Mon Jul 20 06:39:21.309622 2026] [security2:error] [pid 983757:tid 983985] [client 173.239.240.30:53485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W-XKwMdFW9UVnNBSVCgAAAWo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:21.475033 2026] [security2:error] [pid 983757:tid 983764] [remote 154.66.198.148:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4W-XKwMdFW9UVnNBSVGgABEgQ"]
[Mon Jul 20 06:39:21.651668 2026] [security2:error] [pid 983757:tid 984012] [client 34.74.185.202:64077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4W-XKwMdFW9UVnNBSVKQAAAYU"]
[Mon Jul 20 06:39:21.690781 2026] [security2:error] [pid 983757:tid 983785] [remote 57.141.18.76:45758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3874665"] [unique_id "al4W-XKwMdFW9UVnNBSVKgABMRk"]
[Mon Jul 20 06:39:21.722288 2026] [security2:error] [pid 983757:tid 983927] [client 45.61.187.148:50037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.187.61.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.coachpops.org"] [uri "/wp-login.php"] [unique_id "al4W-XKwMdFW9UVnNBSVLQAAATA"]
[Mon Jul 20 06:39:21.727065 2026] [security2:error] [pid 983757:tid 983909] [client 103.238.106.162:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W-XKwMdFW9UVnNBSVMgAAAR4"]
[Mon Jul 20 06:39:21.727502 2026] [security2:error] [pid 983757:tid 983909] [client 103.238.106.162:42868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4W-XKwMdFW9UVnNBSVMgAAAR4"]
[Mon Jul 20 06:39:21.770024 2026] [security2:error] [pid 983757:tid 983972] [client 136.144.35.247:36539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W-XKwMdFW9UVnNBSVNAAAAV0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:21.797007 2026] [security2:error] [pid 966386:tid 966663] [client 57.141.18.32:39888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W9zrLBqY1mBmWu_YRjAAAZDk"]
[Mon Jul 20 06:39:21.956758 2026] [security2:error] [pid 983757:tid 983890] [client 14.225.17.146:56835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4W-XKwMdFW9UVnNBSVEQAAAQs"], referer: http://oldracelimited.com/oldsite
[Mon Jul 20 06:39:22.112783 2026] [security2:error] [pid 983757:tid 983826] [remote 154.66.198.148:27526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4W-nKwMdFW9UVnNBSVUwABLkI"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:39:22.164708 2026] [security2:error] [pid 983757:tid 983957] [client 14.225.17.146:62088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4W-HKwMdFW9UVnNBSU4gAAAU4"], referer: http://nurturemarple.co.uk/oldsite
[Mon Jul 20 06:39:22.248400 2026] [security2:error] [pid 983757:tid 983945] [client 173.239.240.32:59769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W-nKwMdFW9UVnNBSVXAAAAUI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:22.282132 2026] [security2:error] [pid 983757:tid 984004] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4W-nKwMdFW9UVnNBSVVgAAAX0"]
[Mon Jul 20 06:39:22.321420 2026] [security2:error] [pid 983757:tid 983908] [client 57.141.18.106:61146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W93KwMdFW9UVnNBSUiQABHW8"]
[Mon Jul 20 06:39:22.321641 2026] [security2:error] [pid 983757:tid 983987] [client 57.141.18.62:34218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-HKwMdFW9UVnNBSUswABbAk"]
[Mon Jul 20 06:39:22.432379 2026] [security2:error] [pid 966386:tid 966605] [client 57.141.18.120:34884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-DrLBqY1mBmWu_YRlwAAK3w"]
[Mon Jul 20 06:39:22.566854 2026] [security2:error] [pid 983757:tid 983985] [client 34.74.185.202:60361] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4W-nKwMdFW9UVnNBSVbQAAAWo"]
[Mon Jul 20 06:39:22.667768 2026] [security2:error] [pid 983757:tid 984008] [client 50.116.65.227:44182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4W-nKwMdFW9UVnNBSVYgAAAYE"]
[Mon Jul 20 06:39:22.718938 2026] [security2:error] [pid 983757:tid 983978] [client 223.185.13.213:20389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W-nKwMdFW9UVnNBSVcwAAAWM"]
[Mon Jul 20 06:39:22.719065 2026] [security2:error] [pid 983757:tid 983978] [client 223.185.13.213:20389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W-nKwMdFW9UVnNBSVcwAAAWM"]
[Mon Jul 20 06:39:22.757771 2026] [security2:error] [pid 966386:tid 966648] [client 136.144.35.243:42399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W-jrLBqY1mBmWu_YR4QAAAFY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:22.868836 2026] [security2:error] [pid 966386:tid 966588] [client 50.116.65.227:44204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4W-jrLBqY1mBmWu_YR4AAAABo"]
[Mon Jul 20 06:39:22.971970 2026] [security2:error] [pid 983757:tid 983845] [remote 5.252.52.249:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4W-nKwMdFW9UVnNBSVfQABGlU"]
[Mon Jul 20 06:39:23.148818 2026] [security2:error] [pid 983757:tid 983892] [client 34.74.185.202:52772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4W-3KwMdFW9UVnNBSVigAAAQ0"]
[Mon Jul 20 06:39:23.151057 2026] [security2:error] [pid 983757:tid 983966] [client 14.225.17.146:56532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4W-3KwMdFW9UVnNBSVgwAAAVc"], referer: https://nurturemarple.co.uk/oldsite
[Mon Jul 20 06:39:23.179226 2026] [security2:error] [pid 983757:tid 983856] [remote 5.252.52.249:41816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4W-3KwMdFW9UVnNBSVjAABXWA"], referer: https://fineartsfactory.net/wp-login.php
[Mon Jul 20 06:39:23.233349 2026] [security2:error] [pid 983757:tid 984004] [client 173.239.240.98:43451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W-3KwMdFW9UVnNBSVjQAAAX0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:23.391692 2026] [security2:error] [pid 966386:tid 966655] [client 34.74.185.202:65476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4W-zrLBqY1mBmWu_YR-QAAAF0"]
[Mon Jul 20 06:39:23.560436 2026] [security2:error] [pid 966386:tid 966679] [client 34.74.185.202:52731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4W-zrLBqY1mBmWu_YSCQAAAHI"]
[Mon Jul 20 06:39:23.699867 2026] [security2:error] [pid 966386:tid 966643] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4W-zrLBqY1mBmWu_YSAgAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:23.727602 2026] [security2:error] [pid 983757:tid 983936] [client 136.144.35.246:28817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W-3KwMdFW9UVnNBSVoAAAATk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:23.901291 2026] [security2:error] [pid 966386:tid 966614] [client 158.173.166.181:48905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4W-zrLBqY1mBmWu_YSDwAAADQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:39:23.928020 2026] [security2:error] [pid 983757:tid 983981] [client 57.141.18.16:29400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-XKwMdFW9UVnNBSVKwABZmk"]
[Mon Jul 20 06:39:23.935763 2026] [security2:error] [pid 966386:tid 966677] [client 77.110.127.138:51943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W-zrLBqY1mBmWu_YSEAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:23.935900 2026] [security2:error] [pid 966386:tid 966677] [client 77.110.127.138:51943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4W-zrLBqY1mBmWu_YSEAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:24.126387 2026] [security2:error] [pid 983757:tid 984010] [client 34.74.185.202:50739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4W_HKwMdFW9UVnNBSVuwAAAYM"]
[Mon Jul 20 06:39:24.126449 2026] [security2:error] [pid 983757:tid 983993] [client 217.142.18.172:32236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W_HKwMdFW9UVnNBSVvAAAAXI"]
[Mon Jul 20 06:39:24.137433 2026] [security2:error] [pid 983757:tid 983993] [client 217.142.18.172:32236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4W_HKwMdFW9UVnNBSVvAAAAXI"]
[Mon Jul 20 06:39:24.181678 2026] [security2:error] [pid 983757:tid 983894] [client 57.141.18.22:56586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-XKwMdFW9UVnNBSVSAABDxM"]
[Mon Jul 20 06:39:24.197880 2026] [security2:error] [pid 983757:tid 983987] [client 34.74.185.202:49173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4W_HKwMdFW9UVnNBSVxAAAAWw"]
[Mon Jul 20 06:39:24.199522 2026] [security2:error] [pid 983757:tid 983924] [client 136.144.35.250:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W_HKwMdFW9UVnNBSVxQAAAS0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:24.490245 2026] [security2:error] [pid 983757:tid 983998] [client 104.234.53.84:31623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4W_HKwMdFW9UVnNBSV1gAAAXc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:24.572256 2026] [security2:error] [pid 983757:tid 983955] [client 34.74.185.202:56636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4W_HKwMdFW9UVnNBSV3QAAAUw"]
[Mon Jul 20 06:39:24.593783 2026] [security2:error] [pid 966386:tid 966686] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4W_DrLBqY1mBmWu_YSHAAAAHk"]
[Mon Jul 20 06:39:24.670403 2026] [security2:error] [pid 983757:tid 983973] [client 34.74.185.202:51681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4W_HKwMdFW9UVnNBSV8AAAAV4"]
[Mon Jul 20 06:39:24.677594 2026] [security2:error] [pid 983757:tid 983989] [client 173.239.240.101:64617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W_HKwMdFW9UVnNBSV8QAAAW4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:24.933720 2026] [security2:error] [pid 983757:tid 983917] [client 39.48.81.23:54651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W_HKwMdFW9UVnNBSWAAAAASY"]
[Mon Jul 20 06:39:24.933964 2026] [security2:error] [pid 983757:tid 983917] [client 39.48.81.23:54651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4W_HKwMdFW9UVnNBSWAAAAASY"]
[Mon Jul 20 06:39:25.038213 2026] [security2:error] [pid 966386:tid 966577] [client 34.74.185.202:64562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4W_TrLBqY1mBmWu_YSLgAAAA8"]
[Mon Jul 20 06:39:25.045540 2026] [security2:error] [pid 983757:tid 983959] [client 34.74.185.202:60210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4W_XKwMdFW9UVnNBSWBQAAAVA"]
[Mon Jul 20 06:39:25.174244 2026] [security2:error] [pid 966386:tid 966582] [client 136.144.35.244:44671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W_TrLBqY1mBmWu_YSMAAAABQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:25.196356 2026] [security2:error] [pid 966386:tid 966580] [client 171.61.165.146:10614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W_TrLBqY1mBmWu_YSMgAAABI"]
[Mon Jul 20 06:39:25.196484 2026] [security2:error] [pid 966386:tid 966580] [client 171.61.165.146:10614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4W_TrLBqY1mBmWu_YSMgAAABI"]
[Mon Jul 20 06:39:25.425331 2026] [security2:error] [pid 966386:tid 966653] [client 14.225.17.146:61963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4W-zrLBqY1mBmWu_YSDQAAAFs"], referer: http://swafforddetailing.com/oldsite
[Mon Jul 20 06:39:25.552247 2026] [security2:error] [pid 983757:tid 983970] [client 197.186.66.42:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W_XKwMdFW9UVnNBSWKwAAAVs"]
[Mon Jul 20 06:39:25.575773 2026] [security2:error] [pid 983757:tid 983970] [client 197.186.66.42:64115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4W_XKwMdFW9UVnNBSWKwAAAVs"]
[Mon Jul 20 06:39:25.633610 2026] [security2:error] [pid 983757:tid 983869] [remote 95.217.78.234:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4W_XKwMdFW9UVnNBSWMwABVW0"]
[Mon Jul 20 06:39:25.687008 2026] [security2:error] [pid 966386:tid 966599] [client 173.239.240.93:58047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W_TrLBqY1mBmWu_YSPQAAACU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:25.703935 2026] [security2:error] [pid 966386:tid 966575] [client 57.141.18.122:40614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-zrLBqY1mBmWu_YR_gAADT4"]
[Mon Jul 20 06:39:25.750882 2026] [security2:error] [pid 983757:tid 984015] [client 34.74.185.202:49442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4W_XKwMdFW9UVnNBSWPwAAAYg"]
[Mon Jul 20 06:39:25.840964 2026] [security2:error] [pid 983757:tid 983959] [client 34.74.185.202:59383] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4W_XKwMdFW9UVnNBSWSAAAAVA"]
[Mon Jul 20 06:39:25.866590 2026] [security2:error] [pid 983757:tid 983803] [remote 95.217.78.234:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4W_XKwMdFW9UVnNBSWSgABQys"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:39:25.927115 2026] [security2:error] [pid 983757:tid 984014] [client 173.252.82.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mochawavepublishing.com"] [uri "/index.php"] [unique_id "al4W-XKwMdFW9UVnNBSVGwAAAYc"]
[Mon Jul 20 06:39:26.010481 2026] [security2:error] [pid 983757:tid 983988] [client 57.141.18.58:23784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-3KwMdFW9UVnNBSVpwABbV8"]
[Mon Jul 20 06:39:26.017291 2026] [security2:error] [pid 983757:tid 983914] [client 57.141.18.48:51932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W-3KwMdFW9UVnNBSVpgABIzU"]
[Mon Jul 20 06:39:26.139388 2026] [security2:error] [pid 983757:tid 984004] [client 173.239.240.94:44511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W_nKwMdFW9UVnNBSWUgAAAX0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:26.275082 2026] [security2:error] [pid 983757:tid 983923] [client 34.74.185.202:49405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4W_nKwMdFW9UVnNBSWcgAAASw"]
[Mon Jul 20 06:39:26.344641 2026] [security2:error] [pid 983757:tid 984016] [client 34.74.185.202:55859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4W_nKwMdFW9UVnNBSWeQAAAYk"]
[Mon Jul 20 06:39:26.381148 2026] [security2:error] [pid 983757:tid 983925] [client 171.60.139.123:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.139.60.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W_nKwMdFW9UVnNBSWegAAAS4"]
[Mon Jul 20 06:39:26.381295 2026] [security2:error] [pid 983757:tid 983925] [client 171.60.139.123:64178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/xmlrpc.php"] [unique_id "al4W_nKwMdFW9UVnNBSWegAAAS4"]
[Mon Jul 20 06:39:26.475820 2026] [security2:error] [pid 983757:tid 983941] [client 57.141.18.43:23356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W_HKwMdFW9UVnNBSVwwABPg4"]
[Mon Jul 20 06:39:26.476178 2026] [security2:error] [pid 983757:tid 983932] [client 173.252.82.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mochawavepublishing.com"] [uri "/index.php"] [unique_id "al4W_nKwMdFW9UVnNBSWdgAAATU"]
[Mon Jul 20 06:39:26.585628 2026] [security2:error] [pid 983757:tid 983909] [client 34.74.185.202:49609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4W_nKwMdFW9UVnNBSWjQAAAR4"]
[Mon Jul 20 06:39:26.649744 2026] [security2:error] [pid 983757:tid 983978] [client 173.239.240.98:52045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W_nKwMdFW9UVnNBSWkAAAAWM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:26.831285 2026] [security2:error] [pid 983757:tid 983907] [client 34.74.185.202:51517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4W_nKwMdFW9UVnNBSWnwAAARw"]
[Mon Jul 20 06:39:26.903828 2026] [security2:error] [pid 966386:tid 966607] [client 34.74.185.202:60106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4W_jrLBqY1mBmWu_YSWQAAAC0"]
[Mon Jul 20 06:39:27.122385 2026] [security2:error] [pid 966386:tid 966647] [client 34.74.185.202:58595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4W_zrLBqY1mBmWu_YSYAAAAFU"]
[Mon Jul 20 06:39:27.128103 2026] [security2:error] [pid 966386:tid 966579] [client 173.239.240.101:43101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4W_zrLBqY1mBmWu_YSYQAAABE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:27.328179 2026] [security2:error] [pid 966386:tid 966683] [client 34.74.185.202:54066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vbb.yvf.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4W_zrLBqY1mBmWu_YSZQAAAHY"]
[Mon Jul 20 06:39:27.577083 2026] [security2:error] [pid 983757:tid 983936] [client 34.74.185.202:49403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4W_3KwMdFW9UVnNBSWygAAATk"]
[Mon Jul 20 06:39:27.613157 2026] [security2:error] [pid 983757:tid 983941] [client 136.144.35.244:25119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4W_3KwMdFW9UVnNBSWzAAAAT4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:27.651273 2026] [security2:error] [pid 966386:tid 966638] [client 103.125.179.95:53639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W_zrLBqY1mBmWu_YSbgAAAEw"]
[Mon Jul 20 06:39:27.651367 2026] [security2:error] [pid 966386:tid 966638] [client 103.125.179.95:53639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4W_zrLBqY1mBmWu_YSbgAAAEw"]
[Mon Jul 20 06:39:27.888205 2026] [security2:error] [pid 983757:tid 983991] [client 57.141.18.27:37616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4W_XKwMdFW9UVnNBSWJwABcB4"]
[Mon Jul 20 06:39:27.912753 2026] [security2:error] [pid 966386:tid 966530] [remote 152.228.213.32:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4W_zrLBqY1mBmWu_YScgAAdGQ"]
[Mon Jul 20 06:39:27.979420 2026] [security2:error] [pid 983757:tid 983908] [client 34.74.185.202:58222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4W_3KwMdFW9UVnNBSW3wAAAR0"]
[Mon Jul 20 06:39:28.098416 2026] [security2:error] [pid 983757:tid 983986] [client 173.239.240.100:28439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XAHKwMdFW9UVnNBSW5AAAAWs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:28.108123 2026] [security2:error] [pid 966386:tid 966515] [remote 152.228.213.32:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XADrLBqY1mBmWu_YSewAAHVU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:39:28.302864 2026] [security2:error] [pid 966386:tid 966667] [client 106.219.188.178:2897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XADrLBqY1mBmWu_YShAAAAGc"]
[Mon Jul 20 06:39:28.302988 2026] [security2:error] [pid 966386:tid 966667] [client 106.219.188.178:2897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XADrLBqY1mBmWu_YShAAAAGc"]
[Mon Jul 20 06:39:28.603199 2026] [security2:error] [pid 983757:tid 983952] [client 104.207.60.95:35309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XAHKwMdFW9UVnNBSW_QAAAUk"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:28.609099 2026] [security2:error] [pid 966386:tid 966671] [client 173.239.240.96:42597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XADrLBqY1mBmWu_YSiQAAAGo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:28.776632 2026] [security2:error] [pid 983757:tid 983860] [remote 216.73.216.55:14656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/contact-us/"] [unique_id "al4XAHKwMdFW9UVnNBSXDwABU2Q"]
[Mon Jul 20 06:39:28.785020 2026] [security2:error] [pid 983757:tid 983861] [remote 42.200.84.61:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XAHKwMdFW9UVnNBSXDgABcWU"]
[Mon Jul 20 06:39:28.864125 2026] [security2:error] [pid 983757:tid 983967] [client 14.225.17.146:58931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4W_3KwMdFW9UVnNBSWtQAAAVg"], referer: http://margaretspeckogawa.com/oldsite
[Mon Jul 20 06:39:28.980549 2026] [security2:error] [pid 983757:tid 983925] [client 34.74.185.202:64156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XAHKwMdFW9UVnNBSXGAAAAS4"]
[Mon Jul 20 06:39:29.076491 2026] [security2:error] [pid 983757:tid 983957] [client 173.239.240.101:62181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XAXKwMdFW9UVnNBSXGwAAAU4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:29.101729 2026] [security2:error] [pid 966386:tid 966586] [client 112.208.70.94:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XATrLBqY1mBmWu_YSkwAAABg"]
[Mon Jul 20 06:39:29.101846 2026] [security2:error] [pid 966386:tid 966586] [client 112.208.70.94:43377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XATrLBqY1mBmWu_YSkwAAABg"]
[Mon Jul 20 06:39:29.161103 2026] [security2:error] [pid 983757:tid 983864] [remote 42.200.84.61:34180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XAXKwMdFW9UVnNBSXIAABL2g"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:39:29.229206 2026] [security2:error] [pid 983757:tid 984001] [client 77.110.127.138:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XAXKwMdFW9UVnNBSXJgAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:29.229313 2026] [security2:error] [pid 983757:tid 984001] [client 77.110.127.138:51967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XAXKwMdFW9UVnNBSXJgAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:29.239638 2026] [security2:error] [pid 983757:tid 983947] [client 98.159.234.160:48903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XAXKwMdFW9UVnNBSXJwAAAUQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:39:29.545130 2026] [security2:error] [pid 983757:tid 983972] [client 136.144.35.248:52451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XAXKwMdFW9UVnNBSXNgAAAV0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:29.751717 2026] [security2:error] [pid 983757:tid 984014] [client 104.234.53.52:53321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XAXKwMdFW9UVnNBSXQgAAAYc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:30.059415 2026] [security2:error] [pid 983757:tid 983982] [client 173.239.240.95:39995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XAnKwMdFW9UVnNBSXUwAAAWc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:30.149445 2026] [security2:error] [pid 983757:tid 983919] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XAXKwMdFW9UVnNBSXTgAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:30.295116 2026] [security2:error] [pid 966386:tid 966451] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XAjrLBqY1mBmWu_YSuQAAGhg"]
[Mon Jul 20 06:39:30.295285 2026] [security2:error] [pid 966386:tid 966588] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XAjrLBqY1mBmWu_YSuQAAGhg"]
[Mon Jul 20 06:39:30.546121 2026] [security2:error] [pid 983757:tid 983941] [client 173.239.240.97:24135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XAnKwMdFW9UVnNBSXbgAAAT4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:30.736157 2026] [security2:error] [pid 966386:tid 966574] [client 14.225.17.146:63866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4XAjrLBqY1mBmWu_YSuwAAAAw"], referer: http://transparentservices.online/oldsite
[Mon Jul 20 06:39:31.005227 2026] [security2:error] [pid 966386:tid 966639] [client 173.239.240.91:49111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XAzrLBqY1mBmWu_YSzAAAAE0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:31.035432 2026] [security2:error] [pid 983757:tid 983965] [client 187.108.85.186:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XA3KwMdFW9UVnNBSXjQAAAVY"]
[Mon Jul 20 06:39:31.035562 2026] [security2:error] [pid 983757:tid 983965] [client 187.108.85.186:52918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XA3KwMdFW9UVnNBSXjQAAAVY"]
[Mon Jul 20 06:39:31.049936 2026] [security2:error] [pid 983757:tid 983983] [client 34.74.185.202:54991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.vergotek.com"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XA3KwMdFW9UVnNBSXkAAAAWg"]
[Mon Jul 20 06:39:31.070904 2026] [security2:error] [pid 966386:tid 966504] [remote 81.173.115.7:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4XAzrLBqY1mBmWu_YSzQAAIUo"]
[Mon Jul 20 06:39:31.102546 2026] [security2:error] [pid 983757:tid 983985] [client 57.141.18.2:57478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XAHKwMdFW9UVnNBSXBAABagA"]
[Mon Jul 20 06:39:31.274819 2026] [security2:error] [pid 966386:tid 966602] [client 50.116.65.227:54494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XAzrLBqY1mBmWu_YS0AAAACg"]
[Mon Jul 20 06:39:31.472721 2026] [security2:error] [pid 966386:tid 966571] [client 50.116.65.227:54510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XAzrLBqY1mBmWu_YS2QAAAAk"]
[Mon Jul 20 06:39:31.476881 2026] [security2:error] [pid 966386:tid 966599] [client 136.144.35.246:30107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XAzrLBqY1mBmWu_YS3gAAACU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:31.670549 2026] [security2:error] [pid 983757:tid 983907] [client 57.141.18.94:64090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XAXKwMdFW9UVnNBSXLAABHHU"]
[Mon Jul 20 06:39:31.732396 2026] [security2:error] [pid 983757:tid 983898] [client 103.153.183.69:13686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4XA3KwMdFW9UVnNBSXsQAAARM"], referer: https://duckduckgo.com/?q=145dw
[Mon Jul 20 06:39:31.786431 2026] [core:error] [pid 966386:tid 966641] [client 14.225.17.146:51043] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:39:31.786453 2026] [core:error] [pid 966386:tid 966641] [client 14.225.17.146:51043] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:39:31.847629 2026] [security2:error] [pid 983757:tid 984001] [client 14.225.17.146:64050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4XA3KwMdFW9UVnNBSXsAAAAXo"], referer: http://christiancountytrumpet.com/oldsite
[Mon Jul 20 06:39:31.916143 2026] [security2:error] [pid 983757:tid 984008] [client 103.153.183.69:13686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4XA3KwMdFW9UVnNBSXugAAAYE"], referer: https://t.co/przic7ak5b
[Mon Jul 20 06:39:31.959877 2026] [security2:error] [pid 966386:tid 966652] [client 173.239.240.101:64859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XAzrLBqY1mBmWu_YS7gAAAFo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:31.979214 2026] [security2:error] [pid 966386:tid 966475] [remote 217.61.143.92:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4XAzrLBqY1mBmWu_YS7wAABy4"]
[Mon Jul 20 06:39:32.088532 2026] [security2:error] [pid 983757:tid 983894] [client 57.141.18.75:63952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XAXKwMdFW9UVnNBSXSgABDwI"]
[Mon Jul 20 06:39:32.093343 2026] [security2:error] [pid 966386:tid 966536] [remote 81.173.115.7:56764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4XBDrLBqY1mBmWu_YS9wAAFWo"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:39:32.156716 2026] [security2:error] [pid 966386:tid 966686] [client 216.73.217.138:23497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XBDrLBqY1mBmWu_YS8QAAeQo"]
[Mon Jul 20 06:39:32.225332 2026] [security2:error] [pid 966386:tid 966486] [remote 217.61.143.92:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4XBDrLBqY1mBmWu_YS-wAAETg"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:39:32.230550 2026] [security2:error] [pid 983757:tid 983905] [client 103.238.106.162:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XBHKwMdFW9UVnNBSXzAAAARo"]
[Mon Jul 20 06:39:32.230662 2026] [security2:error] [pid 983757:tid 983905] [client 103.238.106.162:60628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XBHKwMdFW9UVnNBSXzAAAARo"]
[Mon Jul 20 06:39:32.263539 2026] [security2:error] [pid 983757:tid 984012] [client 77.110.127.138:51980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XBHKwMdFW9UVnNBSX0AAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:32.263623 2026] [security2:error] [pid 983757:tid 984012] [client 77.110.127.138:51980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XBHKwMdFW9UVnNBSX0AAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:32.341436 2026] [security2:error] [pid 966386:tid 966660] [client 14.225.17.146:51074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4XBDrLBqY1mBmWu_YS-gAAAGE"], referer: http://ncsynchro.com/oldsite
[Mon Jul 20 06:39:32.427846 2026] [security2:error] [pid 983757:tid 983993] [client 136.144.35.246:23595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XBHKwMdFW9UVnNBSX3gAAAXI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:32.427931 2026] [security2:error] [pid 966386:tid 966586] [client 216.73.217.138:23497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XBDrLBqY1mBmWu_YTAAAAGGs"]
[Mon Jul 20 06:39:32.536007 2026] [security2:error] [pid 966386:tid 966595] [client 74.208.214.194:37536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XBDrLBqY1mBmWu_YTBAAAACE"]
[Mon Jul 20 06:39:32.903332 2026] [security2:error] [pid 983757:tid 984011] [client 173.239.240.100:26575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XBHKwMdFW9UVnNBSX9AAAAYQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:33.089032 2026] [security2:error] [pid 966386:tid 966616] [client 57.141.18.11:32308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XAjrLBqY1mBmWu_YSxwAANns"]
[Mon Jul 20 06:39:33.373742 2026] [security2:error] [pid 983757:tid 983905] [client 173.239.240.98:28801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XBXKwMdFW9UVnNBSYDwAAARo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:33.443298 2026] [security2:error] [pid 983757:tid 983954] [client 77.110.127.138:51987] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 314 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XBXKwMdFW9UVnNBSYFgAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:33.607135 2026] [security2:error] [pid 983757:tid 984015] [client 223.185.13.213:25339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XBXKwMdFW9UVnNBSYJQAAAYg"]
[Mon Jul 20 06:39:33.607273 2026] [security2:error] [pid 983757:tid 984015] [client 223.185.13.213:25339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XBXKwMdFW9UVnNBSYJQAAAYg"]
[Mon Jul 20 06:39:33.613011 2026] [security2:error] [pid 983757:tid 983994] [client 14.225.17.146:63762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4XBXKwMdFW9UVnNBSYFQAAAXM"], referer: http://fineartsfactory.net/oldsite
[Mon Jul 20 06:39:33.843318 2026] [security2:error] [pid 966386:tid 966641] [client 173.239.240.92:38841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XBTrLBqY1mBmWu_YTGgAAAE8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:33.857782 2026] [security2:error] [pid 966386:tid 966640] [client 57.141.18.19:42276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XAzrLBqY1mBmWu_YS4QAATjA"]
[Mon Jul 20 06:39:34.110185 2026] [security2:error] [pid 966386:tid 966611] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XBTrLBqY1mBmWu_YTIwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:34.185184 2026] [security2:error] [pid 966386:tid 966563] [client 57.141.18.62:54522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBDrLBqY1mBmWu_YS-AAAAjQ"]
[Mon Jul 20 06:39:34.331172 2026] [security2:error] [pid 983757:tid 983981] [client 136.144.35.254:39927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XBnKwMdFW9UVnNBSYRQAAAWY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:34.336684 2026] [security2:error] [pid 966386:tid 966652] [client 14.225.17.146:63885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4XBjrLBqY1mBmWu_YTLAAAAFo"], referer: http://carolinapressurewashers.com/oldsite
[Mon Jul 20 06:39:34.499133 2026] [security2:error] [pid 983757:tid 983892] [client 57.141.18.6:22252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBHKwMdFW9UVnNBSX1wABDTM"]
[Mon Jul 20 06:39:34.536711 2026] [security2:error] [pid 983757:tid 983921] [client 34.139.11.221:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XBnKwMdFW9UVnNBSYUAAAASo"]
[Mon Jul 20 06:39:34.582682 2026] [security2:error] [pid 983757:tid 983993] [client 35.187.45.1:34506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XBnKwMdFW9UVnNBSYUQAAAXI"]
[Mon Jul 20 06:39:34.605426 2026] [security2:error] [pid 983757:tid 983980] [client 104.234.53.77:37435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XBnKwMdFW9UVnNBSYUwAAAWU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:34.650975 2026] [security2:error] [pid 983757:tid 983941] [client 217.142.18.172:4755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XBnKwMdFW9UVnNBSYVgAAAT4"]
[Mon Jul 20 06:39:34.654686 2026] [security2:error] [pid 983757:tid 983941] [client 217.142.18.172:4755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XBnKwMdFW9UVnNBSYVgAAAT4"]
[Mon Jul 20 06:39:34.718426 2026] [security2:error] [pid 983757:tid 983939] [client 34.139.11.221:63604] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XBnKwMdFW9UVnNBSYWAAAATw"]
[Mon Jul 20 06:39:34.810661 2026] [security2:error] [pid 966386:tid 966609] [client 136.144.35.254:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XBjrLBqY1mBmWu_YTPgAAAC8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:34.906606 2026] [security2:error] [pid 966386:tid 966678] [client 34.139.11.221:64045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XBjrLBqY1mBmWu_YTQwAAAHE"]
[Mon Jul 20 06:39:35.046817 2026] [security2:error] [pid 966386:tid 966632] [client 34.139.11.221:55444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XBzrLBqY1mBmWu_YTSQAAAEY"]
[Mon Jul 20 06:39:35.242134 2026] [security2:error] [pid 966386:tid 966596] [client 34.139.11.221:58895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XBzrLBqY1mBmWu_YTTwAAACI"]
[Mon Jul 20 06:39:35.285713 2026] [security2:error] [pid 983757:tid 983898] [client 136.144.35.254:36785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XB3KwMdFW9UVnNBSYbAAAARM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:35.329024 2026] [security2:error] [pid 983757:tid 984015] [client 39.48.81.23:55171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XB3KwMdFW9UVnNBSYcAAAAYg"]
[Mon Jul 20 06:39:35.329171 2026] [security2:error] [pid 983757:tid 984015] [client 39.48.81.23:55171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XB3KwMdFW9UVnNBSYcAAAAYg"]
[Mon Jul 20 06:39:35.454312 2026] [security2:error] [pid 983757:tid 984012] [client 57.141.18.123:36546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBXKwMdFW9UVnNBSYCwABhTs"]
[Mon Jul 20 06:39:35.463989 2026] [security2:error] [pid 983757:tid 983901] [client 34.139.11.221:53202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XB3KwMdFW9UVnNBSYeAAAARY"]
[Mon Jul 20 06:39:35.535672 2026] [security2:error] [pid 966386:tid 966671] [client 14.225.17.146:56567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4XBzrLBqY1mBmWu_YTUAAAAGo"], referer: http://cheesewithjam.com/oldsite
[Mon Jul 20 06:39:35.710510 2026] [security2:error] [pid 983757:tid 983991] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4XB3KwMdFW9UVnNBSYfAABcGY"], referer: http://assasalnazaha.com/oldsite
[Mon Jul 20 06:39:35.746607 2026] [security2:error] [pid 983757:tid 983965] [client 14.225.17.146:63641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4XB3KwMdFW9UVnNBSYfgAAAVY"], referer: http://latiendadejorge.com.gt/oldsite
[Mon Jul 20 06:39:35.750118 2026] [security2:error] [pid 983757:tid 983891] [client 173.239.240.102:22075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XB3KwMdFW9UVnNBSYiQAAAQw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:35.776875 2026] [security2:error] [pid 983757:tid 983890] [client 34.139.11.221:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XB3KwMdFW9UVnNBSYiwAAAQs"]
[Mon Jul 20 06:39:35.887395 2026] [security2:error] [pid 983757:tid 983822] [remote 72.167.132.114:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4XB3KwMdFW9UVnNBSYlwABMT4"]
[Mon Jul 20 06:39:35.927359 2026] [security2:error] [pid 983757:tid 984009] [client 34.139.11.221:56864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XB3KwMdFW9UVnNBSYogAAAYI"]
[Mon Jul 20 06:39:35.949220 2026] [security2:error] [pid 983757:tid 983763] [remote 160.187.68.132:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XB3KwMdFW9UVnNBSYpAABHwM"]
[Mon Jul 20 06:39:36.009560 2026] [security2:error] [pid 966386:tid 966600] [client 57.141.18.118:63260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBTrLBqY1mBmWu_YTIgAAJkA"]
[Mon Jul 20 06:39:36.141127 2026] [security2:error] [pid 983757:tid 983987] [client 34.139.11.221:63616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XCHKwMdFW9UVnNBSYsgAAAWw"]
[Mon Jul 20 06:39:36.163345 2026] [security2:error] [pid 966386:tid 966656] [client 197.186.66.42:64636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XCDrLBqY1mBmWu_YTYAAAAF4"]
[Mon Jul 20 06:39:36.164836 2026] [security2:error] [pid 966386:tid 966656] [client 197.186.66.42:64636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XCDrLBqY1mBmWu_YTYAAAAF4"]
[Mon Jul 20 06:39:36.208723 2026] [security2:error] [pid 966386:tid 966684] [client 171.61.165.146:26010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XCDrLBqY1mBmWu_YTYwAAAHc"]
[Mon Jul 20 06:39:36.208841 2026] [security2:error] [pid 966386:tid 966684] [client 171.61.165.146:26010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XCDrLBqY1mBmWu_YTYwAAAHc"]
[Mon Jul 20 06:39:36.219367 2026] [security2:error] [pid 983757:tid 983968] [client 14.225.17.146:56511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4XCHKwMdFW9UVnNBSYrwAAAVk"], referer: http://collectingrealestate.com/oldsite
[Mon Jul 20 06:39:36.224407 2026] [security2:error] [pid 966386:tid 966614] [client 136.144.35.245:59957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XCDrLBqY1mBmWu_YTZAAAADQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:36.238417 2026] [security2:error] [pid 983757:tid 983843] [remote 72.167.132.114:45946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4XCHKwMdFW9UVnNBSYtwABLVM"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:39:36.332098 2026] [security2:error] [pid 966386:tid 966680] [client 14.225.17.146:56657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4XCDrLBqY1mBmWu_YTYgAAAHM"], referer: http://thechancersband.com/oldsite
[Mon Jul 20 06:39:36.333779 2026] [security2:error] [pid 983757:tid 983998] [client 34.139.11.221:52988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XCHKwMdFW9UVnNBSYuwAAAXc"]
[Mon Jul 20 06:39:36.346239 2026] [security2:error] [pid 983757:tid 983948] [client 57.141.18.114:42824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBnKwMdFW9UVnNBSYRAABRSc"]
[Mon Jul 20 06:39:36.455211 2026] [security2:error] [pid 983757:tid 983831] [remote 160.187.68.132:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XCHKwMdFW9UVnNBSYxgABC0c"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:39:36.498834 2026] [security2:error] [pid 983757:tid 983889] [client 34.139.11.221:56705] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XCHKwMdFW9UVnNBSYyQAAAQo"]
[Mon Jul 20 06:39:36.651012 2026] [security2:error] [pid 983757:tid 983918] [client 34.139.11.221:59103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XCHKwMdFW9UVnNBSY1QAAASc"]
[Mon Jul 20 06:39:36.680782 2026] [security2:error] [pid 966386:tid 966653] [client 57.141.18.44:54940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBjrLBqY1mBmWu_YTPQAAWxo"]
[Mon Jul 20 06:39:36.713548 2026] [security2:error] [pid 983757:tid 983900] [client 173.239.240.94:51785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XCHKwMdFW9UVnNBSY2gAAARU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:36.804710 2026] [security2:error] [pid 983757:tid 983982] [client 34.139.11.221:52611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.bzm.ppv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XCHKwMdFW9UVnNBSY3wAAAWc"]
[Mon Jul 20 06:39:36.884563 2026] [security2:error] [pid 966386:tid 966646] [client 152.58.191.29:32763] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XCDrLBqY1mBmWu_YTawAAAFQ"]
[Mon Jul 20 06:39:36.884733 2026] [security2:error] [pid 966386:tid 966646] [client 152.58.191.29:32763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XCDrLBqY1mBmWu_YTawAAAFQ"]
[Mon Jul 20 06:39:37.053254 2026] [security2:error] [pid 983757:tid 983958] [client 14.225.17.146:63808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4XCHKwMdFW9UVnNBSY1AAAAU8"]
[Mon Jul 20 06:39:37.108485 2026] [security2:error] [pid 983757:tid 984004] [client 57.141.18.119:35592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XB3KwMdFW9UVnNBSYZgABfRM"]
[Mon Jul 20 06:39:37.138214 2026] [security2:error] [pid 983757:tid 983760] [remote 188.166.241.141:58234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4XCXKwMdFW9UVnNBSY8QABhQA"]
[Mon Jul 20 06:39:37.167006 2026] [security2:error] [pid 983757:tid 983985] [client 136.144.35.246:41723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XCXKwMdFW9UVnNBSY8wAAAWo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:37.503718 2026] [security2:error] [pid 983757:tid 983842] [remote 188.166.241.141:58234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4XCXKwMdFW9UVnNBSZCAABTFI"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:39:37.603073 2026] [security2:error] [pid 966386:tid 966619] [client 57.141.18.64:28934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XBzrLBqY1mBmWu_YTVQAAOUQ"]
[Mon Jul 20 06:39:37.648907 2026] [security2:error] [pid 983757:tid 983938] [client 173.239.240.93:28785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XCXKwMdFW9UVnNBSZEAAAATs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:38.085007 2026] [security2:error] [pid 966386:tid 966651] [client 40.77.167.247:37982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4XCDrLBqY1mBmWu_YTYQAAWSw"]
[Mon Jul 20 06:39:38.100723 2026] [security2:error] [pid 966386:tid 966577] [client 173.239.240.30:42631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XCjrLBqY1mBmWu_YThAAAAA8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:38.229835 2026] [security2:error] [pid 966386:tid 966609] [client 14.225.17.146:63580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4XCjrLBqY1mBmWu_YTgAAAAC8"], referer: http://careysheatingandcooling.com/oldsite
[Mon Jul 20 06:39:38.333160 2026] [security2:error] [pid 983757:tid 983876] [remote 20.153.140.50:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XCnKwMdFW9UVnNBSZNwABDXQ"]
[Mon Jul 20 06:39:38.565493 2026] [security2:error] [pid 983757:tid 983955] [client 173.239.240.90:33153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XCnKwMdFW9UVnNBSZRQAAAUw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:38.649991 2026] [security2:error] [pid 966386:tid 966665] [client 14.225.17.146:62392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4XCjrLBqY1mBmWu_YTkwAAAGY"], referer: http://hilltopnurseryinc.com/oldsite
[Mon Jul 20 06:39:38.672090 2026] [security2:error] [pid 966386:tid 966594] [client 104.234.53.47:41231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XCjrLBqY1mBmWu_YTmwAAACA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:38.747308 2026] [security2:error] [pid 983757:tid 983847] [remote 20.153.140.50:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XCnKwMdFW9UVnNBSZTgABD1c"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:39:38.754245 2026] [security2:error] [pid 983757:tid 983994] [client 14.225.17.146:63708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4XCHKwMdFW9UVnNBSY5AAAAXM"], referer: http://areitoproducciones.com/oldsite
[Mon Jul 20 06:39:38.811705 2026] [security2:error] [pid 983757:tid 983967] [client 77.110.127.138:52011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XCnKwMdFW9UVnNBSZUwAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:38.811827 2026] [security2:error] [pid 983757:tid 983967] [client 77.110.127.138:52011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XCnKwMdFW9UVnNBSZUwAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:38.881433 2026] [security2:error] [pid 983757:tid 983932] [client 57.141.18.40:52060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XCHKwMdFW9UVnNBSY5QABNRA"]
[Mon Jul 20 06:39:38.902814 2026] [security2:error] [pid 966386:tid 966585] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XCjrLBqY1mBmWu_YTkQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:38.954069 2026] [security2:error] [pid 966386:tid 966641] [client 106.219.188.178:32956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XCjrLBqY1mBmWu_YTogAAAE8"]
[Mon Jul 20 06:39:38.954605 2026] [security2:error] [pid 966386:tid 966641] [client 106.219.188.178:32956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XCjrLBqY1mBmWu_YTogAAAE8"]
[Mon Jul 20 06:39:39.033166 2026] [security2:error] [pid 966386:tid 966607] [client 136.144.35.254:23965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XCzrLBqY1mBmWu_YTpQAAAC0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:39.067873 2026] [security2:error] [pid 983757:tid 983941] [client 14.224.227.113:54553] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XC3KwMdFW9UVnNBSZYAAAAT4"]
[Mon Jul 20 06:39:39.316952 2026] [security2:error] [pid 966386:tid 966657] [client 216.73.217.138:39651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XCzrLBqY1mBmWu_YTsAAAXx0"]
[Mon Jul 20 06:39:39.390945 2026] [security2:error] [pid 966386:tid 966653] [client 40.77.167.247:37982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4XCzrLBqY1mBmWu_YTpwAAW18"]
[Mon Jul 20 06:39:39.439901 2026] [security2:error] [pid 966386:tid 966639] [client 216.73.217.138:39651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XCzrLBqY1mBmWu_YTtgAATX0"]
[Mon Jul 20 06:39:39.457037 2026] [security2:error] [pid 983757:tid 983977] [client 114.119.146.195:21773] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nandansonscharitablefoundation.com"] [uri "/2019/12/23/nandansons-supports-swaminarayan-akshardham-temple/"] [unique_id "al4XC3KwMdFW9UVnNBSZcwAAAWI"], referer: https://nandansonscharitablefoundation.com/blog/page/4/
[Mon Jul 20 06:39:39.477376 2026] [security2:error] [pid 983757:tid 983974] [client 45.81.144.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4XCnKwMdFW9UVnNBSZVwABXwk"], referer: https://packerjanitorial.com
[Mon Jul 20 06:39:39.498202 2026] [security2:error] [pid 983757:tid 983915] [client 14.225.17.146:62498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4XCnKwMdFW9UVnNBSZKAAAASQ"], referer: http://detroitcsc.com/oldsite
[Mon Jul 20 06:39:39.509256 2026] [security2:error] [pid 983757:tid 983936] [client 136.144.35.247:27315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XC3KwMdFW9UVnNBSZdwAAATk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:39.554387 2026] [security2:error] [pid 983757:tid 983952] [client 14.225.17.146:49380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4XC3KwMdFW9UVnNBSZbAAAAUk"], referer: http://mobilesurvsolutions.com/oldsite
[Mon Jul 20 06:39:39.576202 2026] [security2:error] [pid 983757:tid 983911] [client 104.234.53.47:25473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XC3KwMdFW9UVnNBSZewAAASA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:39.623833 2026] [security2:error] [pid 983757:tid 983899] [client 103.125.179.95:54163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XC3KwMdFW9UVnNBSZfQAAARQ"]
[Mon Jul 20 06:39:39.624023 2026] [security2:error] [pid 983757:tid 983899] [client 103.125.179.95:54163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XC3KwMdFW9UVnNBSZfQAAARQ"]
[Mon Jul 20 06:39:39.681125 2026] [security2:error] [pid 983757:tid 983943] [client 112.208.70.94:43792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XC3KwMdFW9UVnNBSZgwAAAUA"]
[Mon Jul 20 06:39:39.681252 2026] [security2:error] [pid 983757:tid 983943] [client 112.208.70.94:43792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XC3KwMdFW9UVnNBSZgwAAAUA"]
[Mon Jul 20 06:39:39.750149 2026] [security2:error] [pid 966386:tid 966689] [client 77.110.127.138:52025] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 344 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XCzrLBqY1mBmWu_YTwwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:39.981975 2026] [security2:error] [pid 983757:tid 984002] [client 173.239.240.102:52327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XC3KwMdFW9UVnNBSZlAAAAXs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:40.197112 2026] [security2:error] [pid 983757:tid 983982] [client 14.225.17.146:62495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4XDHKwMdFW9UVnNBSZlwAAAWc"], referer: http://709fx.com/oldsite
[Mon Jul 20 06:39:40.425147 2026] [security2:error] [pid 983757:tid 983811] [remote 77.90.2.3:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.2.90.77.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XDHKwMdFW9UVnNBSZrgABbTM"]
[Mon Jul 20 06:39:40.425378 2026] [security2:error] [pid 983757:tid 983988] [client 77.90.2.3:51624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XDHKwMdFW9UVnNBSZrgABbTM"]
[Mon Jul 20 06:39:40.456756 2026] [security2:error] [pid 983757:tid 983977] [client 173.239.240.102:38567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XDHKwMdFW9UVnNBSZsgAAAWI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:40.611312 2026] [access_compat:error] [pid 983757:tid 983967] [client 168.144.19.97:59324] AH01797: client denied by server configuration: /home1/asliceo1/public_html/toddnielsen/wp-admin/css/index.php, referer: binance.com
[Mon Jul 20 06:39:40.619987 2026] [access_compat:error] [pid 983757:tid 983967] [client 168.144.19.97:59324] AH01797: client denied by server configuration: /home1/asliceo1/public_html/toddnielsen/wp-admin/css/index.php5, referer: binance.com
[Mon Jul 20 06:39:40.667140 2026] [security2:error] [pid 966386:tid 966674] [client 152.58.191.29:32763] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XDDrLBqY1mBmWu_YT2wAAAG0"]
[Mon Jul 20 06:39:40.667278 2026] [security2:error] [pid 966386:tid 966674] [client 152.58.191.29:32763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XDDrLBqY1mBmWu_YT2wAAAG0"]
[Mon Jul 20 06:39:40.755991 2026] [security2:error] [pid 983757:tid 983841] [remote 45.150.79.142:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4XDHKwMdFW9UVnNBSZwwABUFE"]
[Mon Jul 20 06:39:40.921635 2026] [security2:error] [pid 983757:tid 984009] [client 136.144.35.247:20031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XDHKwMdFW9UVnNBSZzAAAAYI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:40.929409 2026] [security2:error] [pid 983757:tid 983850] [remote 45.150.79.142:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4XDHKwMdFW9UVnNBSZzQABf1o"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:39:41.029106 2026] [security2:error] [pid 966386:tid 966485] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XDTrLBqY1mBmWu_YT5wAAAjc"]
[Mon Jul 20 06:39:41.029310 2026] [security2:error] [pid 966386:tid 966563] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XDTrLBqY1mBmWu_YT5wAAAjc"]
[Mon Jul 20 06:39:41.084109 2026] [security2:error] [pid 966386:tid 966618] [client 57.141.18.105:42656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XCzrLBqY1mBmWu_YTrQAAOBk"]
[Mon Jul 20 06:39:41.406190 2026] [security2:error] [pid 966386:tid 966587] [client 173.239.240.31:61911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XDTrLBqY1mBmWu_YT8wAAABk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:41.462898 2026] [security2:error] [pid 983757:tid 983917] [client 57.141.18.60:36986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XC3KwMdFW9UVnNBSZdAABJiU"]
[Mon Jul 20 06:39:41.539475 2026] [security2:error] [pid 983757:tid 983907] [client 34.234.200.207:7156] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XDXKwMdFW9UVnNBSaAQAAARw"]
[Mon Jul 20 06:39:41.599493 2026] [security2:error] [pid 983757:tid 983886] [remote 81.173.115.7:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4XDXKwMdFW9UVnNBSaBwABbX4"]
[Mon Jul 20 06:39:41.669046 2026] [security2:error] [pid 983757:tid 984013] [client 77.110.127.138:52060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XDXKwMdFW9UVnNBSaEwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:41.669191 2026] [security2:error] [pid 983757:tid 984013] [client 77.110.127.138:52060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XDXKwMdFW9UVnNBSaEwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:41.839010 2026] [security2:error] [pid 983757:tid 983968] [client 187.108.85.186:53469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XDXKwMdFW9UVnNBSaIgAAAVk"]
[Mon Jul 20 06:39:41.839152 2026] [security2:error] [pid 983757:tid 983968] [client 187.108.85.186:53469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XDXKwMdFW9UVnNBSaIgAAAVk"]
[Mon Jul 20 06:39:41.862235 2026] [security2:error] [pid 983757:tid 983848] [remote 81.173.115.7:46216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4XDXKwMdFW9UVnNBSaIwABE1g"], referer: https://joulecommunications.com/wp-login.php
[Mon Jul 20 06:39:41.883562 2026] [security2:error] [pid 983757:tid 983895] [client 173.239.240.93:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XDXKwMdFW9UVnNBSaJwAAARA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:41.947296 2026] [security2:error] [pid 983757:tid 983784] [remote 57.141.18.44:29970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5484005"] [unique_id "al4XDXKwMdFW9UVnNBSaLAABcBg"]
[Mon Jul 20 06:39:42.138310 2026] [security2:error] [pid 983757:tid 983984] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XDXKwMdFW9UVnNBSaDwAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:42.361384 2026] [security2:error] [pid 983757:tid 983977] [client 136.144.35.254:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XDnKwMdFW9UVnNBSaQwAAAWI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:42.445124 2026] [security2:error] [pid 983757:tid 984003] [client 57.141.18.122:59280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XDHKwMdFW9UVnNBSZtAABfFQ"]
[Mon Jul 20 06:39:42.552498 2026] [security2:error] [pid 966386:tid 966643] [client 43.154.114.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4XDjrLBqY1mBmWu_YUCgAAUTw"]
[Mon Jul 20 06:39:42.720647 2026] [security2:error] [pid 966386:tid 966659] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XDjrLBqY1mBmWu_YUFQAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:42.728632 2026] [security2:error] [pid 983757:tid 983924] [client 77.110.127.138:52067] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 980 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XDnKwMdFW9UVnNBSaWQAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:42.777567 2026] [security2:error] [pid 983757:tid 983899] [client 103.238.106.162:42796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XDnKwMdFW9UVnNBSaXQAAARQ"]
[Mon Jul 20 06:39:42.777693 2026] [security2:error] [pid 983757:tid 983899] [client 103.238.106.162:42796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XDnKwMdFW9UVnNBSaXQAAARQ"]
[Mon Jul 20 06:39:42.824907 2026] [security2:error] [pid 983757:tid 984006] [client 136.144.35.245:29057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XDnKwMdFW9UVnNBSaYQAAAX8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:43.149144 2026] [security2:error] [pid 966386:tid 966644] [client 104.234.53.66:55845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XDzrLBqY1mBmWu_YUJgAAAFI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:43.208924 2026] [security2:error] [pid 983757:tid 983847] [remote 72.167.132.114:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XD3KwMdFW9UVnNBSacQABdVc"]
[Mon Jul 20 06:39:43.295317 2026] [security2:error] [pid 966386:tid 966670] [client 57.141.18.53:20210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XDTrLBqY1mBmWu_YT9QAAaWc"]
[Mon Jul 20 06:39:43.298034 2026] [security2:error] [pid 966386:tid 966652] [client 136.144.35.250:44339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XDzrLBqY1mBmWu_YULwAAAFo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:43.405127 2026] [security2:error] [pid 983757:tid 983921] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XDnKwMdFW9UVnNBSaaQAAASo"]
[Mon Jul 20 06:39:43.442615 2026] [security2:error] [pid 983757:tid 983787] [remote 147.50.252.213:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XD3KwMdFW9UVnNBSafgABdBs"]
[Mon Jul 20 06:39:43.456651 2026] [security2:error] [pid 983757:tid 983771] [remote 72.167.132.114:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XD3KwMdFW9UVnNBSagAABQgs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:39:43.747270 2026] [security2:error] [pid 983757:tid 983891] [client 173.239.240.100:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XD3KwMdFW9UVnNBSajAAAAQw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:43.782167 2026] [security2:error] [pid 983757:tid 983936] [client 57.141.18.21:55330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XDnKwMdFW9UVnNBSaNQABOVI"]
[Mon Jul 20 06:39:43.950602 2026] [security2:error] [pid 983757:tid 983769] [remote 147.50.252.213:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XD3KwMdFW9UVnNBSalgABbAk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:39:43.977606 2026] [security2:error] [pid 983757:tid 983938] [client 77.110.127.138:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XD3KwMdFW9UVnNBSamQAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:43.994424 2026] [security2:error] [pid 983757:tid 983938] [client 77.110.127.138:52075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XD3KwMdFW9UVnNBSamQAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:44.138228 2026] [security2:error] [pid 966386:tid 966592] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XDzrLBqY1mBmWu_YUPwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:44.153594 2026] [security2:error] [pid 966386:tid 966621] [client 57.141.18.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XEDrLBqY1mBmWu_YURAAAADs"]
[Mon Jul 20 06:39:44.195903 2026] [security2:error] [pid 966386:tid 966654] [client 98.83.10.183:24159] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XEDrLBqY1mBmWu_YUTAAAAFw"]
[Mon Jul 20 06:39:44.218610 2026] [security2:error] [pid 983757:tid 983970] [client 136.144.35.248:59203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XEHKwMdFW9UVnNBSanwAAAVs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:44.222109 2026] [security2:error] [pid 966386:tid 966578] [client 77.110.127.138:52078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XEDrLBqY1mBmWu_YUTQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:44.222183 2026] [security2:error] [pid 966386:tid 966578] [client 77.110.127.138:52078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XEDrLBqY1mBmWu_YUTQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:44.248520 2026] [security2:error] [pid 983757:tid 983789] [remote 5.39.1.234:47828] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.secretkeynumerology.com"] [uri "/robots.txt"] [unique_id "al4XEHKwMdFW9UVnNBSaogABPx0"]
[Mon Jul 20 06:39:44.248675 2026] [security2:error] [pid 983757:tid 983942] [client 5.39.1.234:47828] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.secretkeynumerology.com"] [uri "/robots.txt"] [unique_id "al4XEHKwMdFW9UVnNBSaogABPx0"]
[Mon Jul 20 06:39:44.685949 2026] [security2:error] [pid 966386:tid 966605] [client 173.239.240.98:32119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XEDrLBqY1mBmWu_YUegAAACs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:44.741243 2026] [security2:error] [pid 983757:tid 983923] [client 77.110.127.138:52084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 435 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XEHKwMdFW9UVnNBSa3AAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:44.903900 2026] [security2:error] [pid 983757:tid 983987] [client 14.225.17.146:63411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4XEHKwMdFW9UVnNBSa3gAAAWw"], referer: http://northbrookcpa.ca/oldsite
[Mon Jul 20 06:39:45.155957 2026] [security2:error] [pid 983757:tid 983947] [client 173.239.240.93:42423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSbAQAAAUQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:45.180555 2026] [security2:error] [pid 983757:tid 983968] [client 217.142.18.172:2960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XEXKwMdFW9UVnNBSbBAAAAVk"]
[Mon Jul 20 06:39:45.180691 2026] [security2:error] [pid 983757:tid 983968] [client 217.142.18.172:2960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XEXKwMdFW9UVnNBSbBAAAAVk"]
[Mon Jul 20 06:39:45.457847 2026] [security2:error] [pid 983757:tid 983958] [client 47.128.121.91:32648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSbCwABT2c"]
[Mon Jul 20 06:39:45.534433 2026] [security2:error] [pid 983757:tid 983770] [remote 217.61.143.92:44942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4XEXKwMdFW9UVnNBSbHQABaAo"]
[Mon Jul 20 06:39:45.622189 2026] [security2:error] [pid 983757:tid 983987] [client 173.239.240.90:55837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XEXKwMdFW9UVnNBSbKAAAAWw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:45.646229 2026] [security2:error] [pid 983757:tid 983952] [client 104.234.53.78:40423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XEXKwMdFW9UVnNBSbLQAAAUk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:45.655352 2026] [security2:error] [pid 983757:tid 983848] [remote 142.44.233.179:33730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "www.secretkeynumerology.com"] [uri "/0-and-2/"] [unique_id "al4XEXKwMdFW9UVnNBSbLgABLVg"]
[Mon Jul 20 06:39:45.655502 2026] [security2:error] [pid 983757:tid 983924] [client 142.44.233.179:33730] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.secretkeynumerology.com"] [uri "/0-and-2/"] [unique_id "al4XEXKwMdFW9UVnNBSbLgABLVg"]
[Mon Jul 20 06:39:45.808549 2026] [security2:error] [pid 983757:tid 983942] [client 35.187.45.1:50798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSbMwAAAT8"]
[Mon Jul 20 06:39:45.808723 2026] [security2:error] [pid 983757:tid 983929] [client 35.187.45.1:50786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSbNAAAATI"]
[Mon Jul 20 06:39:45.810553 2026] [security2:error] [pid 983757:tid 983936] [client 14.225.17.146:63433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSbHgAAATk"], referer: http://younutrition.gr/oldsite
[Mon Jul 20 06:39:45.855947 2026] [security2:error] [pid 983757:tid 983911] [client 14.225.17.146:56458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4XEHKwMdFW9UVnNBSa6QAAASA"], referer: http://retzkolonglogistics.com/oldsite
[Mon Jul 20 06:39:45.991081 2026] [security2:error] [pid 983757:tid 983823] [remote 217.61.143.92:44942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4XEXKwMdFW9UVnNBSbPQABIT8"], referer: https://hammadownenterprises.com/wp-login.php
[Mon Jul 20 06:39:46.025511 2026] [security2:error] [pid 983757:tid 983933] [client 39.48.81.23:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XEnKwMdFW9UVnNBSbQAAAATY"]
[Mon Jul 20 06:39:46.025645 2026] [security2:error] [pid 983757:tid 983933] [client 39.48.81.23:55686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XEnKwMdFW9UVnNBSbQAAAATY"]
[Mon Jul 20 06:39:46.103892 2026] [security2:error] [pid 966386:tid 966601] [client 173.239.240.94:35799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XEjrLBqY1mBmWu_YUlgAAACc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:46.177272 2026] [security2:error] [pid 966386:tid 966593] [client 51.158.124.4:40196] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5024.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4XEjrLBqY1mBmWu_YUmAAAAB8"]
[Mon Jul 20 06:39:46.275662 2026] [security2:error] [pid 983757:tid 983926] [client 77.110.127.138:52092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XEnKwMdFW9UVnNBSbUgAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:46.275779 2026] [security2:error] [pid 983757:tid 983926] [client 77.110.127.138:52092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XEnKwMdFW9UVnNBSbUgAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:46.383227 2026] [security2:error] [pid 983757:tid 983993] [client 45.3.45.153:30525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XEnKwMdFW9UVnNBSbWwAAAXI"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:39:46.603643 2026] [security2:error] [pid 983757:tid 984016] [client 136.144.35.253:39007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XEnKwMdFW9UVnNBSbaAAAAYk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:46.604691 2026] [security2:error] [pid 983757:tid 983945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XEnKwMdFW9UVnNBSbVwAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:46.719959 2026] [security2:error] [pid 983757:tid 983974] [client 57.141.18.57:44138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSa9AABXzg"]
[Mon Jul 20 06:39:46.868670 2026] [security2:error] [pid 983757:tid 983941] [client 57.141.18.63:65300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSa_gABPnE"]
[Mon Jul 20 06:39:46.999291 2026] [security2:error] [pid 983757:tid 983918] [client 35.187.45.1:50806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XEnKwMdFW9UVnNBSbewAAASc"]
[Mon Jul 20 06:39:47.076574 2026] [security2:error] [pid 983757:tid 983963] [client 136.144.35.254:34425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XE3KwMdFW9UVnNBSbgQAAAVQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:47.198174 2026] [security2:error] [pid 966386:tid 966621] [client 171.61.165.146:22394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XEzrLBqY1mBmWu_YUsQAAADs"]
[Mon Jul 20 06:39:47.198321 2026] [security2:error] [pid 966386:tid 966621] [client 171.61.165.146:22394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XEzrLBqY1mBmWu_YUsQAAADs"]
[Mon Jul 20 06:39:47.297372 2026] [security2:error] [pid 983757:tid 983939] [client 57.141.18.48:64116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XEXKwMdFW9UVnNBSbHwABPBM"]
[Mon Jul 20 06:39:47.322542 2026] [security2:error] [pid 983757:tid 983914] [client 45.3.44.8:22195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XE3KwMdFW9UVnNBSbjgAAASM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:39:47.561671 2026] [security2:error] [pid 983757:tid 983965] [client 136.144.35.244:25075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XE3KwMdFW9UVnNBSbnQAAAVY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:47.697437 2026] [security2:error] [pid 983757:tid 983998] [client 77.110.127.138:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XE3KwMdFW9UVnNBSbqwAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:47.697567 2026] [security2:error] [pid 983757:tid 983998] [client 77.110.127.138:52097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XE3KwMdFW9UVnNBSbqwAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:47.848631 2026] [security2:error] [pid 983757:tid 983989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XE3KwMdFW9UVnNBSbnwAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:47.897374 2026] [security2:error] [pid 983757:tid 983940] [client 14.225.17.146:59965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4XEnKwMdFW9UVnNBSbYgAAAT0"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/oldsite
[Mon Jul 20 06:39:47.902087 2026] [security2:error] [pid 983757:tid 983916] [client 65.111.21.88:13543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XE3KwMdFW9UVnNBSbsgAAASU"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:48.040705 2026] [security2:error] [pid 966386:tid 966639] [client 136.144.35.251:65521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XFDrLBqY1mBmWu_YUywAAAE0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:48.042150 2026] [security2:error] [pid 983757:tid 983953] [client 77.110.127.138:52099] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 502 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XFHKwMdFW9UVnNBSbtwAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:48.070961 2026] [security2:error] [pid 983757:tid 983996] [client 65.111.23.107:43317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XFHKwMdFW9UVnNBSbuAAAAXU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:39:48.199822 2026] [security2:error] [pid 983757:tid 983915] [client 14.225.17.146:49850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4XEnKwMdFW9UVnNBSbdQAAASQ"], referer: http://39ishlife.com/oldsite
[Mon Jul 20 06:39:48.256874 2026] [security2:error] [pid 983757:tid 983995] [client 52.54.249.218:23028] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XFHKwMdFW9UVnNBSbxQAAAXQ"]
[Mon Jul 20 06:39:48.530162 2026] [security2:error] [pid 983757:tid 983963] [client 173.239.240.102:36347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XFHKwMdFW9UVnNBSb3AAAAVQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:48.681826 2026] [security2:error] [pid 983757:tid 984013] [client 57.141.18.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4XFHKwMdFW9UVnNBSbuQAAAYY"]
[Mon Jul 20 06:39:48.724756 2026] [security2:error] [pid 966386:tid 966576] [client 65.111.6.84:21389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XFDrLBqY1mBmWu_YU3QAAAA4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:48.736583 2026] [security2:error] [pid 966386:tid 966601] [client 197.186.66.42:65182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XFDrLBqY1mBmWu_YU4AAAACc"]
[Mon Jul 20 06:39:48.736708 2026] [security2:error] [pid 966386:tid 966601] [client 197.186.66.42:65182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XFDrLBqY1mBmWu_YU4AAAACc"]
[Mon Jul 20 06:39:48.937621 2026] [security2:error] [pid 983757:tid 983951] [client 57.141.18.107:39560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XE3KwMdFW9UVnNBSbkAABSHY"]
[Mon Jul 20 06:39:48.946010 2026] [security2:error] [pid 983757:tid 983891] [client 57.141.18.57:44148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XE3KwMdFW9UVnNBSbjwABDA4"]
[Mon Jul 20 06:39:48.978705 2026] [security2:error] [pid 983757:tid 983988] [client 136.144.35.246:23367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XFHKwMdFW9UVnNBSb7wAAAW0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:49.008314 2026] [security2:error] [pid 983757:tid 983991] [client 14.225.17.146:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4XE3KwMdFW9UVnNBSbjAAAAXA"], referer: http://fluidtemple.org/oldsite
[Mon Jul 20 06:39:49.138776 2026] [security2:error] [pid 966386:tid 966571] [client 14.225.17.146:60010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4XFTrLBqY1mBmWu_YU6QAAAAk"], referer: https://39ishlife.com/oldsite
[Mon Jul 20 06:39:49.197119 2026] [security2:error] [pid 966386:tid 966642] [client 173.252.70.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cimexenvironmental.com"] [uri "/index.php"] [unique_id "al4XEjrLBqY1mBmWu_YUpwAAUFs"]
[Mon Jul 20 06:39:49.322893 2026] [security2:error] [pid 983757:tid 983890] [client 57.141.18.24:25942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XE3KwMdFW9UVnNBSbrAABCws"]
[Mon Jul 20 06:39:49.450570 2026] [security2:error] [pid 966386:tid 966688] [client 136.144.35.250:21175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XFTrLBqY1mBmWu_YU8wAAAHs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:49.563932 2026] [security2:error] [pid 983757:tid 984003] [client 106.219.188.178:10291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XFXKwMdFW9UVnNBScDgAAAXw"]
[Mon Jul 20 06:39:49.570664 2026] [security2:error] [pid 983757:tid 984003] [client 106.219.188.178:10291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XFXKwMdFW9UVnNBScDgAAAXw"]
[Mon Jul 20 06:39:49.573189 2026] [security2:error] [pid 966386:tid 966614] [client 77.110.127.138:52105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XFTrLBqY1mBmWu_YU9wAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:49.573277 2026] [security2:error] [pid 966386:tid 966614] [client 77.110.127.138:52105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XFTrLBqY1mBmWu_YU9wAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:49.731361 2026] [security2:error] [pid 983757:tid 984000] [client 185.117.225.199:43854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bradpetersphotography.com"] [uri "/robots.txt"] [unique_id "al4XFXKwMdFW9UVnNBScHwAAAXk"]
[Mon Jul 20 06:39:49.738075 2026] [security2:error] [pid 983757:tid 983978] [client 77.110.127.138:52113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 954 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XFXKwMdFW9UVnNBScIAAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:49.889096 2026] [security2:error] [pid 983757:tid 983897] [client 77.110.127.138:52117] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/crochet-classes/page/2/"] [unique_id "al4XFXKwMdFW9UVnNBScJwAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:49.924797 2026] [security2:error] [pid 983757:tid 983940] [client 136.144.35.254:60821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XFXKwMdFW9UVnNBScKwAAAT0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:49.927201 2026] [security2:error] [pid 983757:tid 983908] [client 77.110.127.138:52119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XFXKwMdFW9UVnNBScLAAAAR0"]
[Mon Jul 20 06:39:49.927305 2026] [security2:error] [pid 983757:tid 983908] [client 77.110.127.138:52119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XFXKwMdFW9UVnNBScLAAAAR0"]
[Mon Jul 20 06:39:50.321298 2026] [security2:error] [pid 983757:tid 983904] [client 112.208.70.94:44217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XFnKwMdFW9UVnNBScSAAAARk"]
[Mon Jul 20 06:39:50.321457 2026] [security2:error] [pid 983757:tid 983904] [client 112.208.70.94:44217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XFnKwMdFW9UVnNBScSAAAARk"]
[Mon Jul 20 06:39:50.358084 2026] [security2:error] [pid 983757:tid 983984] [client 185.117.225.199:37478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "bradpetersphotography.com"] [uri "/robots.txt"] [unique_id "al4XFnKwMdFW9UVnNBScSwAAAWk"]
[Mon Jul 20 06:39:50.378409 2026] [security2:error] [pid 983757:tid 983974] [client 173.239.240.90:32871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XFnKwMdFW9UVnNBScTgAAAV8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:50.407441 2026] [security2:error] [pid 966386:tid 966678] [client 14.225.17.146:49891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4XFDrLBqY1mBmWu_YU4wAAAHE"], referer: http://alexsandbergmusic.com/oldsite
[Mon Jul 20 06:39:50.523996 2026] [security2:error] [pid 983757:tid 983979] [client 74.7.175.141:40050] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "genesismedicalbilling.com"] [uri "/cgi-sys/404.html"] [unique_id "al4XFnKwMdFW9UVnNBScWgAAAWQ"]
[Mon Jul 20 06:39:50.739689 2026] [security2:error] [pid 983757:tid 983851] [remote 217.61.143.92:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XFnKwMdFW9UVnNBScZQABYls"]
[Mon Jul 20 06:39:50.767358 2026] [security2:error] [pid 966386:tid 966676] [client 103.125.179.95:54678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XFjrLBqY1mBmWu_YVDwAAAG8"]
[Mon Jul 20 06:39:50.767466 2026] [security2:error] [pid 966386:tid 966676] [client 103.125.179.95:54678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XFjrLBqY1mBmWu_YVDwAAAG8"]
[Mon Jul 20 06:39:50.860813 2026] [security2:error] [pid 983757:tid 983983] [client 136.144.35.244:39285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XFnKwMdFW9UVnNBScawAAAWg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:50.946252 2026] [security2:error] [pid 983757:tid 983892] [client 14.225.17.146:62267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4XFXKwMdFW9UVnNBScGQAAAQ0"], referer: http://alaraycreative.com/oldsite
[Mon Jul 20 06:39:50.974501 2026] [security2:error] [pid 983757:tid 983866] [remote 217.61.143.92:44954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XFnKwMdFW9UVnNBScdQABX2o"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:39:51.241356 2026] [security2:error] [pid 966386:tid 966615] [client 13.229.223.11:58424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XFzrLBqY1mBmWu_YVHQAAADU"]
[Mon Jul 20 06:39:51.241464 2026] [security2:error] [pid 966386:tid 966615] [client 13.229.223.11:58424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XFzrLBqY1mBmWu_YVHQAAADU"]
[Mon Jul 20 06:39:51.332433 2026] [security2:error] [pid 983757:tid 983951] [client 173.239.240.32:30957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XF3KwMdFW9UVnNBSchgAAAUg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:51.381979 2026] [security2:error] [pid 966386:tid 966606] [client 57.141.18.102:58604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XFTrLBqY1mBmWu_YU_AAALBg"]
[Mon Jul 20 06:39:51.476855 2026] [security2:error] [pid 983757:tid 983907] [client 136.107.64.51:50726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "shw.opy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XF3KwMdFW9UVnNBSciwAAARw"]
[Mon Jul 20 06:39:51.476962 2026] [security2:error] [pid 983757:tid 983907] [client 136.107.64.51:50726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "shw.opy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XF3KwMdFW9UVnNBSciwAAARw"]
[Mon Jul 20 06:39:51.572851 2026] [security2:error] [pid 966386:tid 966536] [remote 162.19.86.63:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XFzrLBqY1mBmWu_YVJgAAKGo"]
[Mon Jul 20 06:39:51.644627 2026] [security2:error] [pid 966386:tid 966578] [client 50.116.65.227:44522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XFzrLBqY1mBmWu_YVJwAAABA"]
[Mon Jul 20 06:39:51.654330 2026] [security2:error] [pid 966386:tid 966564] [client 50.116.65.227:44528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XFzrLBqY1mBmWu_YVKgAAAAM"]
[Mon Jul 20 06:39:51.662790 2026] [security2:error] [pid 983757:tid 983984] [client 35.187.45.1:50806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XF3KwMdFW9UVnNBSclQAAAWk"]
[Mon Jul 20 06:39:51.787903 2026] [security2:error] [pid 966386:tid 966433] [remote 162.19.86.63:41918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XFzrLBqY1mBmWu_YVOAAAcwY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:39:51.847257 2026] [security2:error] [pid 966386:tid 966483] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XFzrLBqY1mBmWu_YVOwAAGjU"]
[Mon Jul 20 06:39:51.847440 2026] [security2:error] [pid 966386:tid 966588] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XFzrLBqY1mBmWu_YVOwAAGjU"]
[Mon Jul 20 06:39:51.871908 2026] [security2:error] [pid 966386:tid 966642] [client 136.144.35.243:28649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XFzrLBqY1mBmWu_YVOQAAAFA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:52.029159 2026] [security2:error] [pid 983757:tid 983924] [client 158.173.89.95:50987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XGHKwMdFW9UVnNBScogAAAS0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:39:52.157292 2026] [security2:error] [pid 983757:tid 983949] [client 152.58.191.29:51849] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XGHKwMdFW9UVnNBScrAAAAUY"]
[Mon Jul 20 06:39:52.158607 2026] [security2:error] [pid 983757:tid 983949] [client 152.58.191.29:51849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XGHKwMdFW9UVnNBScrAAAAUY"]
[Mon Jul 20 06:39:52.186602 2026] [security2:error] [pid 983757:tid 983985] [client 14.225.17.146:49979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4XFnKwMdFW9UVnNBScWAAAAWo"], referer: http://koaconsultants.com/oldsite
[Mon Jul 20 06:39:52.224472 2026] [security2:error] [pid 983757:tid 983988] [client 35.187.45.1:39572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XGHKwMdFW9UVnNBScswAAAW0"]
[Mon Jul 20 06:39:52.224525 2026] [security2:error] [pid 966386:tid 966587] [client 35.187.45.1:39560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XGDrLBqY1mBmWu_YVSwAAABk"]
[Mon Jul 20 06:39:52.267791 2026] [security2:error] [pid 983757:tid 983990] [client 104.234.53.59:55219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XGHKwMdFW9UVnNBScugAAAW8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:52.373259 2026] [security2:error] [pid 983757:tid 983950] [client 136.144.35.251:50579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XGHKwMdFW9UVnNBScxAAAAUc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:52.408606 2026] [security2:error] [pid 983757:tid 983986] [client 35.187.45.1:50806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XGHKwMdFW9UVnNBScwgAAAWs"]
[Mon Jul 20 06:39:52.541995 2026] [security2:error] [pid 983757:tid 983962] [client 77.110.127.138:52126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XGHKwMdFW9UVnNBSczgAAAVM"]
[Mon Jul 20 06:39:52.542294 2026] [security2:error] [pid 983757:tid 983962] [client 77.110.127.138:52126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XGHKwMdFW9UVnNBSczgAAAVM"]
[Mon Jul 20 06:39:52.586813 2026] [security2:error] [pid 966386:tid 966620] [client 187.108.85.186:54012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XGDrLBqY1mBmWu_YVUwAAADo"]
[Mon Jul 20 06:39:52.586940 2026] [security2:error] [pid 966386:tid 966620] [client 187.108.85.186:54012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XGDrLBqY1mBmWu_YVUwAAADo"]
[Mon Jul 20 06:39:52.679210 2026] [security2:error] [pid 966386:tid 966441] [remote 216.73.216.55:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4XGDrLBqY1mBmWu_YVVwAALA4"]
[Mon Jul 20 06:39:52.834834 2026] [security2:error] [pid 966386:tid 966580] [client 173.239.240.32:59229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XGDrLBqY1mBmWu_YVXAAAABI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:52.985028 2026] [security2:error] [pid 983757:tid 983940] [client 57.141.18.37:55026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XF3KwMdFW9UVnNBSceAABPSc"]
[Mon Jul 20 06:39:52.992247 2026] [security2:error] [pid 983757:tid 983925] [client 57.141.18.3:23552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XF3KwMdFW9UVnNBScegABLkg"]
[Mon Jul 20 06:39:53.285445 2026] [security2:error] [pid 983757:tid 983976] [client 136.144.35.248:39951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XGXKwMdFW9UVnNBSc7AAAAWE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:53.433595 2026] [security2:error] [pid 966386:tid 966653] [client 14.225.17.146:50115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4XGDrLBqY1mBmWu_YVYwAAAFs"], referer: http://bruceledewitz.com/oldsite
[Mon Jul 20 06:39:53.454052 2026] [security2:error] [pid 966386:tid 966560] [client 103.238.106.162:42674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XGTrLBqY1mBmWu_YVgQAAAAA"]
[Mon Jul 20 06:39:53.454159 2026] [security2:error] [pid 966386:tid 966560] [client 103.238.106.162:42674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XGTrLBqY1mBmWu_YVgQAAAAA"]
[Mon Jul 20 06:39:53.520066 2026] [security2:error] [pid 966386:tid 966552] [remote 95.217.78.234:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4XGTrLBqY1mBmWu_YVgwAAO3o"]
[Mon Jul 20 06:39:53.595659 2026] [security2:error] [pid 983757:tid 984006] [client 34.74.185.202:61185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4XGXKwMdFW9UVnNBSc9QAAAX8"]
[Mon Jul 20 06:39:53.747308 2026] [security2:error] [pid 966386:tid 966459] [remote 95.217.78.234:56698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4XGTrLBqY1mBmWu_YVjgAADyA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:39:53.755877 2026] [security2:error] [pid 966386:tid 966648] [client 173.239.240.90:43409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XGTrLBqY1mBmWu_YVkAAAAFY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:53.856304 2026] [security2:error] [pid 966386:tid 966644] [client 57.141.18.108:22788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XFzrLBqY1mBmWu_YVNwAAUjg"]
[Mon Jul 20 06:39:53.968642 2026] [security2:error] [pid 966386:tid 966672] [client 77.110.127.138:52131] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XGTrLBqY1mBmWu_YVqwAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:54.202120 2026] [security2:error] [pid 966386:tid 966614] [client 34.74.185.202:64647] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XGjrLBqY1mBmWu_YVsgAAADQ"]
[Mon Jul 20 06:39:54.263810 2026] [security2:error] [pid 983757:tid 983908] [client 173.239.240.92:48519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XGnKwMdFW9UVnNBSdBwAAAR0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:54.294102 2026] [security2:error] [pid 966386:tid 966636] [client 57.141.18.116:58164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XGDrLBqY1mBmWu_YVRQAAShU"]
[Mon Jul 20 06:39:54.406308 2026] [security2:error] [pid 983757:tid 983951] [client 57.141.18.60:35638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XGHKwMdFW9UVnNBSctgABSDw"]
[Mon Jul 20 06:39:54.409260 2026] [security2:error] [pid 966386:tid 966498] [remote 50.28.1.50:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4XGjrLBqY1mBmWu_YVuwAABEQ"]
[Mon Jul 20 06:39:54.409409 2026] [security2:error] [pid 966386:tid 966566] [client 50.28.1.50:48952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4XGjrLBqY1mBmWu_YVuwAABEQ"]
[Mon Jul 20 06:39:54.460501 2026] [security2:error] [pid 983757:tid 983988] [client 14.224.227.113:54555] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XGnKwMdFW9UVnNBSdEAAAAW0"]
[Mon Jul 20 06:39:54.648135 2026] [security2:error] [pid 983757:tid 983964] [client 114.119.159.233:59521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fkconstructionfunding.com"] [uri "/nearly-7-of-us-bridges-in-poor-condition/"] [unique_id "al4XGnKwMdFW9UVnNBSdFQAAAVU"], referer: https://fkconstructionfunding.com/latest-news/page/213/
[Mon Jul 20 06:39:54.727258 2026] [security2:error] [pid 983757:tid 983915] [client 223.185.13.213:30813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XGnKwMdFW9UVnNBSdGQAAASQ"]
[Mon Jul 20 06:39:54.727356 2026] [security2:error] [pid 983757:tid 983915] [client 223.185.13.213:30813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XGnKwMdFW9UVnNBSdGQAAASQ"]
[Mon Jul 20 06:39:54.755916 2026] [security2:error] [pid 966386:tid 966619] [client 136.144.35.247:55565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XGjrLBqY1mBmWu_YVwwAAADk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:54.766144 2026] [security2:error] [pid 983757:tid 983926] [client 77.110.127.138:52133] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/crochet-classes/page/2/"] [unique_id "al4XGnKwMdFW9UVnNBSdGgAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:54.828539 2026] [security2:error] [pid 966386:tid 966643] [client 34.74.185.202:51028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XGjrLBqY1mBmWu_YVxwAAAFE"]
[Mon Jul 20 06:39:55.225808 2026] [security2:error] [pid 966386:tid 966580] [client 173.239.240.30:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XGzrLBqY1mBmWu_YV0AAAABI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:55.260136 2026] [security2:error] [pid 983757:tid 983891] [client 34.74.185.202:57443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XG3KwMdFW9UVnNBSdLwAAAQw"]
[Mon Jul 20 06:39:55.311145 2026] [security2:error] [pid 983757:tid 983989] [client 57.141.18.89:34294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XGXKwMdFW9UVnNBSc5QABbis"]
[Mon Jul 20 06:39:55.367002 2026] [security2:error] [pid 983757:tid 983916] [client 57.141.18.104:23160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XGXKwMdFW9UVnNBSc5gABJV8"]
[Mon Jul 20 06:39:55.692509 2026] [security2:error] [pid 966386:tid 966588] [client 173.239.240.92:47745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XGzrLBqY1mBmWu_YV3AAAABo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:55.724128 2026] [security2:error] [pid 983757:tid 983919] [client 217.142.18.172:40774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XG3KwMdFW9UVnNBSdSgAAASg"]
[Mon Jul 20 06:39:55.724240 2026] [security2:error] [pid 983757:tid 983919] [client 217.142.18.172:40774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XG3KwMdFW9UVnNBSdSgAAASg"]
[Mon Jul 20 06:39:55.736588 2026] [security2:error] [pid 983757:tid 983914] [client 34.74.185.202:59587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XG3KwMdFW9UVnNBSdSwAAASM"]
[Mon Jul 20 06:39:55.838912 2026] [security2:error] [pid 983757:tid 983829] [remote 154.61.75.100:44492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4XG3KwMdFW9UVnNBSdTQABD0U"]
[Mon Jul 20 06:39:55.931019 2026] [security2:error] [pid 966386:tid 966543] [remote 5.252.52.249:40124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4XGzrLBqY1mBmWu_YV6QAAM3E"]
[Mon Jul 20 06:39:55.931157 2026] [security2:error] [pid 966386:tid 966613] [client 5.252.52.249:40124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4XGzrLBqY1mBmWu_YV6QAAM3E"]
[Mon Jul 20 06:39:55.985347 2026] [security2:error] [pid 966386:tid 966636] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XGzrLBqY1mBmWu_YV4gAAAEo"]
[Mon Jul 20 06:39:56.090193 2026] [security2:error] [pid 983757:tid 984011] [client 34.74.185.202:61004] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XHHKwMdFW9UVnNBSdWAAAAYQ"]
[Mon Jul 20 06:39:56.169267 2026] [security2:error] [pid 983757:tid 983924] [client 136.144.35.254:24749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XHHKwMdFW9UVnNBSdWwAAAS0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:56.329543 2026] [security2:error] [pid 983757:tid 983856] [remote 154.61.75.100:44492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4XHHKwMdFW9UVnNBSdZQABdWA"], referer: https://slutilities.com/wp-login.php
[Mon Jul 20 06:39:56.519558 2026] [security2:error] [pid 966386:tid 966633] [client 84.37.247.13:13296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4XHDrLBqY1mBmWu_YV9gAAR2E"]
[Mon Jul 20 06:39:56.525538 2026] [security2:error] [pid 966386:tid 966611] [client 57.141.18.93:57950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XGjrLBqY1mBmWu_YVtAAAMW8"]
[Mon Jul 20 06:39:56.526629 2026] [security2:error] [pid 966386:tid 966661] [client 104.234.53.89:48303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XHDrLBqY1mBmWu_YV-wAAAGI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:56.549570 2026] [security2:error] [pid 983757:tid 984008] [client 3.93.98.99:5758] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XHHKwMdFW9UVnNBSdeQAAAYE"]
[Mon Jul 20 06:39:56.556204 2026] [autoindex:error] [pid 983757:tid 983927] [client 198.235.24.155:63022] AH01276: Cannot serve directory /home1/wcnktkmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:39:56.621824 2026] [security2:error] [pid 983757:tid 983919] [client 77.110.127.138:52140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/crochet-classes/page/2/"] [unique_id "al4XHHKwMdFW9UVnNBSdfAAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:56.626641 2026] [security2:error] [pid 983757:tid 983980] [client 74.7.175.131:54578] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "genesismbs.com"] [uri "/robots.txt"] [unique_id "al4XHHKwMdFW9UVnNBSdfQAAAWU"]
[Mon Jul 20 06:39:56.640481 2026] [security2:error] [pid 966386:tid 966650] [client 173.239.240.30:42835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XHDrLBqY1mBmWu_YV_AAAAFg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:56.656765 2026] [security2:error] [pid 983757:tid 983824] [remote 98.156.100.191:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XHHKwMdFW9UVnNBSdfgABYkA"]
[Mon Jul 20 06:39:56.657013 2026] [security2:error] [pid 983757:tid 983952] [client 34.74.185.202:62328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XHHKwMdFW9UVnNBSdfwAAAUk"]
[Mon Jul 20 06:39:56.771106 2026] [security2:error] [pid 983757:tid 983960] [client 77.110.127.138:52141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XHHKwMdFW9UVnNBSdiAAAAVE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:56.771492 2026] [security2:error] [pid 983757:tid 983960] [client 77.110.127.138:52141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XHHKwMdFW9UVnNBSdiAAAAVE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:57.019260 2026] [security2:error] [pid 983757:tid 983898] [client 54.91.122.193:48381] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/outxpro-snake-repellent-772a.pdf"] [unique_id "al4XHXKwMdFW9UVnNBSdmwAAARM"]
[Mon Jul 20 06:39:57.089851 2026] [security2:error] [pid 966386:tid 966610] [client 136.144.35.254:53091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XHTrLBqY1mBmWu_YWBwAAADA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:57.258832 2026] [security2:error] [pid 966386:tid 966596] [client 34.74.185.202:50870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XHTrLBqY1mBmWu_YWCwAAACI"]
[Mon Jul 20 06:39:57.270220 2026] [security2:error] [pid 983757:tid 983984] [client 57.141.18.71:27542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XG3KwMdFW9UVnNBSdKwABaUQ"]
[Mon Jul 20 06:39:57.275996 2026] [security2:error] [pid 983757:tid 983965] [client 52.109.112.174:17410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XHXKwMdFW9UVnNBSdpwAAAVY"]
[Mon Jul 20 06:39:57.278680 2026] [security2:error] [pid 966386:tid 966578] [client 74.7.175.131:46516] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "genesismbs.com"] [uri "/index.php"] [unique_id "al4XHDrLBqY1mBmWu_YWAAAAEBQ"], referer: http://genesismbs.com/robots.txt
[Mon Jul 20 06:39:57.433539 2026] [security2:error] [pid 983757:tid 983941] [client 52.109.112.174:17410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XHXKwMdFW9UVnNBSdsQAAAT4"]
[Mon Jul 20 06:39:57.442918 2026] [security2:error] [pid 983757:tid 984006] [client 14.225.17.146:64755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4XHXKwMdFW9UVnNBSdqAAAAX8"], referer: http://idigress.group/oldsite
[Mon Jul 20 06:39:57.537722 2026] [security2:error] [pid 966386:tid 966479] [remote 47.86.33.52:4886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4XHTrLBqY1mBmWu_YWDgAANDE"]
[Mon Jul 20 06:39:57.542124 2026] [security2:error] [pid 983757:tid 983977] [client 34.74.185.202:59774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XHXKwMdFW9UVnNBSdugAAAWI"]
[Mon Jul 20 06:39:57.562037 2026] [security2:error] [pid 983757:tid 983958] [client 136.144.35.249:25151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XHXKwMdFW9UVnNBSdvQAAAU8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:57.832182 2026] [security2:error] [pid 966386:tid 966452] [remote 162.19.86.63:40086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4XHTrLBqY1mBmWu_YWHAAATRk"]
[Mon Jul 20 06:39:57.894462 2026] [security2:error] [pid 983757:tid 983897] [client 77.110.127.138:52150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XHXKwMdFW9UVnNBSd0QAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:58.029321 2026] [security2:error] [pid 966386:tid 966546] [remote 162.19.86.63:40086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4XHjrLBqY1mBmWu_YWIAAAeHQ"], referer: https://amalia-capital.com/wp-login.php
[Mon Jul 20 06:39:58.031070 2026] [security2:error] [pid 983757:tid 983895] [client 173.239.240.94:50107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XHnKwMdFW9UVnNBSd2wAAARA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:58.057507 2026] [security2:error] [pid 966386:tid 966587] [client 34.74.185.202:56317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XHjrLBqY1mBmWu_YWIQAAABk"]
[Mon Jul 20 06:39:58.185076 2026] [security2:error] [pid 983757:tid 983984] [client 104.234.53.53:33275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XHnKwMdFW9UVnNBSd5AAAAWk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:39:58.389970 2026] [security2:error] [pid 983757:tid 983889] [client 34.74.185.202:50219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XHnKwMdFW9UVnNBSd8QAAAQo"]
[Mon Jul 20 06:39:58.472201 2026] [security2:error] [pid 983757:tid 983852] [remote 152.228.213.32:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4XHnKwMdFW9UVnNBSd9QABf1w"]
[Mon Jul 20 06:39:58.498490 2026] [security2:error] [pid 966386:tid 966598] [client 173.239.240.98:51755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XHjrLBqY1mBmWu_YWLQAAACQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:58.658830 2026] [security2:error] [pid 983757:tid 983947] [client 5.32.247.70:40184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4XHnKwMdFW9UVnNBSd7QAAAUQ"]
[Mon Jul 20 06:39:58.704601 2026] [security2:error] [pid 983757:tid 983770] [remote 152.228.213.32:44056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4XHnKwMdFW9UVnNBSeAQABNAo"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:39:58.777424 2026] [security2:error] [pid 983757:tid 983942] [client 171.61.165.146:32815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XHnKwMdFW9UVnNBSeCQAAAT8"]
[Mon Jul 20 06:39:58.777587 2026] [security2:error] [pid 983757:tid 983942] [client 171.61.165.146:32815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XHnKwMdFW9UVnNBSeCQAAAT8"]
[Mon Jul 20 06:39:58.819014 2026] [security2:error] [pid 983757:tid 983760] [remote 20.153.140.50:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4XHnKwMdFW9UVnNBSeCwABNgA"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:39:58.828116 2026] [security2:error] [pid 966386:tid 966583] [client 34.74.185.202:57173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XHjrLBqY1mBmWu_YWNwAAABU"]
[Mon Jul 20 06:39:58.832343 2026] [security2:error] [pid 983757:tid 983975] [client 57.141.18.54:21758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XHHKwMdFW9UVnNBSdjAABYGk"]
[Mon Jul 20 06:39:58.946061 2026] [security2:error] [pid 983757:tid 983918] [client 136.144.35.246:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XHnKwMdFW9UVnNBSeGQAAASc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:59.012713 2026] [security2:error] [pid 983757:tid 983958] [client 5.161.61.238:44002] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4XHnKwMdFW9UVnNBSd9gAAAU8"], referer: https://windowtx.com
[Mon Jul 20 06:39:59.229578 2026] [security2:error] [pid 966386:tid 966574] [client 57.141.18.72:49078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XHTrLBqY1mBmWu_YWCgAADFU"]
[Mon Jul 20 06:39:59.250197 2026] [security2:error] [pid 983757:tid 983891] [client 34.74.185.202:56317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.wcn.ktk.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XH3KwMdFW9UVnNBSeJAAAAQw"]
[Mon Jul 20 06:39:59.271136 2026] [security2:error] [pid 966386:tid 966578] [client 190.92.174.183:51456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4XHzrLBqY1mBmWu_YWQAAAABA"]
[Mon Jul 20 06:39:59.271226 2026] [security2:error] [pid 966386:tid 966578] [client 190.92.174.183:51456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4XHzrLBqY1mBmWu_YWQAAAABA"]
[Mon Jul 20 06:39:59.413814 2026] [security2:error] [pid 983757:tid 983914] [client 173.239.240.93:57959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XH3KwMdFW9UVnNBSeLwAAASM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:59.489450 2026] [security2:error] [pid 983757:tid 983832] [remote 98.156.100.191:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XH3KwMdFW9UVnNBSeOQABG0g"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:39:59.622743 2026] [security2:error] [pid 983757:tid 983959] [client 77.110.127.138:52169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XH3KwMdFW9UVnNBSeSAAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:59.622889 2026] [security2:error] [pid 983757:tid 983959] [client 77.110.127.138:52169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XH3KwMdFW9UVnNBSeSAAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:39:59.638420 2026] [security2:error] [pid 983757:tid 983971] [client 57.141.18.83:27966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XHXKwMdFW9UVnNBSdxQABXFs"]
[Mon Jul 20 06:39:59.731098 2026] [security2:error] [pid 983757:tid 983978] [client 65.111.31.43:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XH3KwMdFW9UVnNBSeUQAAAWM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:39:59.738871 2026] [security2:error] [pid 983757:tid 983821] [remote 103.190.93.143:44694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.93.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4XH3KwMdFW9UVnNBSeUgABDz0"]
[Mon Jul 20 06:39:59.760486 2026] [security2:error] [pid 983757:tid 983901] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XH3KwMdFW9UVnNBSeTQAAARY"]
[Mon Jul 20 06:39:59.866376 2026] [security2:error] [pid 966386:tid 966639] [client 173.239.240.102:25121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XHzrLBqY1mBmWu_YWUAAAAE0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:39:59.962104 2026] [security2:error] [pid 983757:tid 983963] [client 57.141.18.87:51992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XHXKwMdFW9UVnNBSd2AABVBo"]
[Mon Jul 20 06:40:00.002864 2026] [security2:error] [pid 983757:tid 983914] [client 23.21.204.95:15625] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/pharmacy-order-entry-technician-job-description-772a.pdf"] [unique_id "al4XIHKwMdFW9UVnNBSeYwAAASM"]
[Mon Jul 20 06:40:00.099223 2026] [security2:error] [pid 966386:tid 966582] [client 77.110.127.138:52172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XHzrLBqY1mBmWu_YWUQAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:00.142447 2026] [security2:error] [pid 983757:tid 984011] [client 190.92.174.183:51462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4XIHKwMdFW9UVnNBSeawAAAYQ"]
[Mon Jul 20 06:40:00.142535 2026] [security2:error] [pid 983757:tid 984011] [client 190.92.174.183:51462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4XIHKwMdFW9UVnNBSeawAAAYQ"]
[Mon Jul 20 06:40:00.172381 2026] [security2:error] [pid 983757:tid 983813] [remote 103.190.93.143:44694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.93.190.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4XIHKwMdFW9UVnNBSebQABZzU"], referer: https://superiorcopywriting.com/wp-login.php
[Mon Jul 20 06:40:00.456384 2026] [security2:error] [pid 983757:tid 983940] [client 197.186.66.42:49307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XIHKwMdFW9UVnNBSeewAAAT0"]
[Mon Jul 20 06:40:00.462871 2026] [security2:error] [pid 983757:tid 983940] [client 197.186.66.42:49307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XIHKwMdFW9UVnNBSeewAAAT0"]
[Mon Jul 20 06:40:00.466018 2026] [security2:error] [pid 966386:tid 966594] [client 136.144.35.245:44317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XIDrLBqY1mBmWu_YWYQAAACA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:00.470802 2026] [security2:error] [pid 983757:tid 984009] [client 14.225.17.146:58252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4XIHKwMdFW9UVnNBSeZgAAAYI"], referer: http://uritems.net/oldsite
[Mon Jul 20 06:40:00.658683 2026] [security2:error] [pid 983757:tid 983941] [client 45.3.51.183:49763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.51.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XIHKwMdFW9UVnNBSehwAAAT4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:00.802319 2026] [security2:error] [pid 983757:tid 984008] [client 57.141.18.12:50542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XHnKwMdFW9UVnNBSeCAABgVg"]
[Mon Jul 20 06:40:00.953731 2026] [security2:error] [pid 983757:tid 983896] [client 173.239.240.101:36547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XIHKwMdFW9UVnNBSelQAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:01.056998 2026] [security2:error] [pid 966386:tid 966647] [client 112.208.70.94:44641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XITrLBqY1mBmWu_YWcwAAAFU"]
[Mon Jul 20 06:40:01.057100 2026] [security2:error] [pid 966386:tid 966647] [client 112.208.70.94:44641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XITrLBqY1mBmWu_YWcwAAAFU"]
[Mon Jul 20 06:40:01.125024 2026] [security2:error] [pid 983757:tid 983913] [client 106.219.188.178:10288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XIXKwMdFW9UVnNBSemgAAASI"]
[Mon Jul 20 06:40:01.125124 2026] [security2:error] [pid 983757:tid 983913] [client 106.219.188.178:10288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XIXKwMdFW9UVnNBSemgAAASI"]
[Mon Jul 20 06:40:01.434502 2026] [security2:error] [pid 983757:tid 983898] [client 173.239.240.99:27349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XIXKwMdFW9UVnNBSepgAAARM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:01.471204 2026] [security2:error] [pid 983757:tid 983931] [client 34.139.11.221:56823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XIXKwMdFW9UVnNBSeqwAAATQ"]
[Mon Jul 20 06:40:01.649682 2026] [security2:error] [pid 983757:tid 983978] [client 34.139.11.221:53923] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XIXKwMdFW9UVnNBSetwAAAWM"]
[Mon Jul 20 06:40:01.820736 2026] [security2:error] [pid 983757:tid 983915] [client 34.139.11.221:61572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XIXKwMdFW9UVnNBSevgAAASQ"]
[Mon Jul 20 06:40:01.889744 2026] [security2:error] [pid 966386:tid 966571] [client 103.125.179.95:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XITrLBqY1mBmWu_YWiQAAAAk"]
[Mon Jul 20 06:40:01.889898 2026] [security2:error] [pid 966386:tid 966571] [client 103.125.179.95:55184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XITrLBqY1mBmWu_YWiQAAAAk"]
[Mon Jul 20 06:40:01.944724 2026] [security2:error] [pid 983757:tid 984012] [client 136.144.35.253:36781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XIXKwMdFW9UVnNBSexwAAAYU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:01.998893 2026] [security2:error] [pid 966386:tid 966626] [client 34.139.11.221:62512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XITrLBqY1mBmWu_YWlgAAAEA"]
[Mon Jul 20 06:40:02.022267 2026] [security2:error] [pid 983757:tid 983989] [client 104.207.54.140:16225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XIXKwMdFW9UVnNBSeywAAAW4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:02.040980 2026] [security2:error] [pid 983757:tid 983856] [remote 8.217.108.67:18356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4XInKwMdFW9UVnNBSezgABDGA"]
[Mon Jul 20 06:40:02.111740 2026] [security2:error] [pid 983757:tid 983948] [client 216.73.217.138:10472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XIXKwMdFW9UVnNBSezAABRUk"]
[Mon Jul 20 06:40:02.123532 2026] [security2:error] [pid 983757:tid 984015] [client 34.139.11.221:51554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XInKwMdFW9UVnNBSe0QAAAYg"]
[Mon Jul 20 06:40:02.255061 2026] [security2:error] [pid 983757:tid 983938] [client 34.139.11.221:54685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XInKwMdFW9UVnNBSe2QAAATs"]
[Mon Jul 20 06:40:02.354912 2026] [security2:error] [pid 983757:tid 983850] [remote 98.156.100.191:36132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4XInKwMdFW9UVnNBSe4QABWVo"]
[Mon Jul 20 06:40:02.413001 2026] [security2:error] [pid 983757:tid 983982] [client 216.73.217.138:10472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XInKwMdFW9UVnNBSe3gABZ10"]
[Mon Jul 20 06:40:02.423898 2026] [security2:error] [pid 983757:tid 983936] [client 136.144.35.247:22451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XInKwMdFW9UVnNBSe6AAAATk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:02.426765 2026] [security2:error] [pid 983757:tid 983971] [client 34.139.11.221:54708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XInKwMdFW9UVnNBSe6QAAAVw"]
[Mon Jul 20 06:40:02.507831 2026] [security2:error] [pid 983757:tid 983794] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XInKwMdFW9UVnNBSe8AABKiI"]
[Mon Jul 20 06:40:02.507968 2026] [security2:error] [pid 983757:tid 983921] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XInKwMdFW9UVnNBSe8AABKiI"]
[Mon Jul 20 06:40:02.618085 2026] [security2:error] [pid 983757:tid 983915] [client 34.139.11.221:63257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XInKwMdFW9UVnNBSe_QAAASQ"]
[Mon Jul 20 06:40:02.755000 2026] [security2:error] [pid 983757:tid 983924] [client 152.58.191.29:52243] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XInKwMdFW9UVnNBSfBgAAAS0"]
[Mon Jul 20 06:40:02.755160 2026] [security2:error] [pid 983757:tid 983924] [client 152.58.191.29:52243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XInKwMdFW9UVnNBSfBgAAAS0"]
[Mon Jul 20 06:40:02.808616 2026] [security2:error] [pid 983757:tid 983985] [client 34.139.11.221:53376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XInKwMdFW9UVnNBSfCAAAAWo"]
[Mon Jul 20 06:40:02.882070 2026] [security2:error] [pid 983757:tid 983896] [client 136.144.35.246:41743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XInKwMdFW9UVnNBSfCwAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:02.897863 2026] [security2:error] [pid 983757:tid 984008] [client 104.207.37.5:13545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XInKwMdFW9UVnNBSfCgAAAYE"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:02.904900 2026] [security2:error] [pid 966386:tid 966569] [client 14.225.17.146:65128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4XITrLBqY1mBmWu_YWeAAAAAc"], referer: http://amalia-capital.com/oldsite
[Mon Jul 20 06:40:02.921982 2026] [security2:error] [pid 983757:tid 983984] [client 77.110.127.138:52180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XInKwMdFW9UVnNBSe8wAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:02.942454 2026] [security2:error] [pid 983757:tid 983861] [remote 20.153.140.50:42142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4XInKwMdFW9UVnNBSfDgABVGU"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:40:03.001367 2026] [security2:error] [pid 983757:tid 983819] [remote 8.217.108.67:18356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4XInKwMdFW9UVnNBSfEgABOTs"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:40:03.010539 2026] [security2:error] [pid 983757:tid 983954] [client 34.139.11.221:54854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XI3KwMdFW9UVnNBSfFAAAAUs"]
[Mon Jul 20 06:40:03.065478 2026] [security2:error] [pid 983757:tid 983945] [client 57.141.18.119:62156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XIHKwMdFW9UVnNBSejAABQiE"]
[Mon Jul 20 06:40:03.095155 2026] [access_compat:error] [pid 966386:tid 966690] [client 144.172.114.51:0] AH01797: client denied by server configuration: proxy:https://127.0.0.1:8443/server-status
[Mon Jul 20 06:40:03.153079 2026] [security2:error] [pid 983757:tid 983924] [client 34.139.11.221:52660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XI3KwMdFW9UVnNBSfIwAAAS0"]
[Mon Jul 20 06:40:03.319026 2026] [security2:error] [pid 983757:tid 983991] [client 74.7.227.179:48932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XI3KwMdFW9UVnNBSfKQABcEs"], referer: https://tejasenvironmental.com/p=944509
[Mon Jul 20 06:40:03.334400 2026] [security2:error] [pid 983757:tid 983958] [client 34.139.11.221:57154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XI3KwMdFW9UVnNBSfLwAAAU8"]
[Mon Jul 20 06:40:03.369202 2026] [security2:error] [pid 966386:tid 966654] [client 173.239.240.92:35477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XIzrLBqY1mBmWu_YWtAAAAFw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:03.439991 2026] [security2:error] [pid 983757:tid 983992] [client 14.225.17.146:64657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4XI3KwMdFW9UVnNBSfMAAAAXE"], referer: http://claysharecon.com/oldsite
[Mon Jul 20 06:40:03.454290 2026] [security2:error] [pid 983757:tid 983919] [client 187.108.85.186:54565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XI3KwMdFW9UVnNBSfNQAAASg"]
[Mon Jul 20 06:40:03.454387 2026] [security2:error] [pid 983757:tid 983919] [client 187.108.85.186:54565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XI3KwMdFW9UVnNBSfNQAAASg"]
[Mon Jul 20 06:40:03.602958 2026] [security2:error] [pid 983757:tid 983915] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XI3KwMdFW9UVnNBSfHgAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:03.634526 2026] [security2:error] [pid 983757:tid 983990] [client 77.110.127.138:52189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XI3KwMdFW9UVnNBSfLQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:03.690409 2026] [security2:error] [pid 966386:tid 966608] [client 65.111.20.147:13515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XIzrLBqY1mBmWu_YWxAAAAC4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:03.843742 2026] [security2:error] [pid 983757:tid 984012] [client 173.239.240.96:59043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XI3KwMdFW9UVnNBSfTAAAAYU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:03.873442 2026] [security2:error] [pid 983757:tid 984002] [client 57.141.18.101:49520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XIXKwMdFW9UVnNBSevwABe3Y"]
[Mon Jul 20 06:40:03.875212 2026] [security2:error] [pid 983757:tid 983894] [client 57.141.18.29:23080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XIXKwMdFW9UVnNBSeugABDyQ"]
[Mon Jul 20 06:40:03.995404 2026] [security2:error] [pid 966386:tid 966595] [client 57.141.18.8:63520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XITrLBqY1mBmWu_YWkAAAIUs"]
[Mon Jul 20 06:40:04.050773 2026] [security2:error] [pid 983757:tid 983954] [client 103.238.106.162:60832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XJHKwMdFW9UVnNBSfVAAAAUs"]
[Mon Jul 20 06:40:04.050897 2026] [security2:error] [pid 983757:tid 983954] [client 103.238.106.162:60832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XJHKwMdFW9UVnNBSfVAAAAUs"]
[Mon Jul 20 06:40:04.304319 2026] [security2:error] [pid 983757:tid 984001] [client 57.141.18.50:41996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XInKwMdFW9UVnNBSe1QABejA"]
[Mon Jul 20 06:40:04.324926 2026] [security2:error] [pid 983757:tid 983984] [client 136.144.35.254:44503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XJHKwMdFW9UVnNBSfZwAAAWk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:04.420233 2026] [security2:error] [pid 983757:tid 983963] [client 14.225.17.146:59558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4XJHKwMdFW9UVnNBSfWgAAAVQ"]
[Mon Jul 20 06:40:04.436936 2026] [security2:error] [pid 983757:tid 983868] [remote 113.160.142.119:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XJHKwMdFW9UVnNBSfbQABc2w"]
[Mon Jul 20 06:40:04.511956 2026] [security2:error] [pid 983757:tid 984016] [client 52.202.233.37:39995] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XJHKwMdFW9UVnNBSfdQAAAYk"]
[Mon Jul 20 06:40:04.761297 2026] [security2:error] [pid 966386:tid 966600] [client 39.48.81.23:56192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XJDrLBqY1mBmWu_YW4QAAACY"]
[Mon Jul 20 06:40:04.761740 2026] [security2:error] [pid 966386:tid 966600] [client 39.48.81.23:56192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XJDrLBqY1mBmWu_YW4QAAACY"]
[Mon Jul 20 06:40:04.771904 2026] [security2:error] [pid 983757:tid 983977] [client 14.225.17.146:64669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4XJHKwMdFW9UVnNBSfeQAAAWI"], referer: http://eduardsales.com/oldsite
[Mon Jul 20 06:40:04.796413 2026] [security2:error] [pid 983757:tid 983920] [client 136.144.35.254:40735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XJHKwMdFW9UVnNBSfiAAAASk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:04.909483 2026] [security2:error] [pid 966386:tid 966596] [client 57.141.18.113:65100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XIjrLBqY1mBmWu_YWrAAAIno"]
[Mon Jul 20 06:40:05.046200 2026] [security2:error] [pid 983757:tid 983784] [remote 47.86.33.52:17894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4XJXKwMdFW9UVnNBSfkQABKhg"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:40:05.052788 2026] [security2:error] [pid 983757:tid 983874] [remote 173.212.252.15:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XJXKwMdFW9UVnNBSfkAABWnI"]
[Mon Jul 20 06:40:05.159744 2026] [security2:error] [pid 966386:tid 966623] [client 57.141.18.16:52586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XIzrLBqY1mBmWu_YWswAAPSA"]
[Mon Jul 20 06:40:05.195273 2026] [security2:error] [pid 983757:tid 983875] [remote 113.160.142.119:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XJXKwMdFW9UVnNBSfmQABQHM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:40:05.277642 2026] [security2:error] [pid 966386:tid 966688] [client 136.144.35.250:54747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XJTrLBqY1mBmWu_YW8wAAAHs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:05.453933 2026] [security2:error] [pid 966386:tid 966637] [client 14.225.17.146:58111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4XJTrLBqY1mBmWu_YW8gAAAEs"], referer: http://falconarrowshop.com/oldsite
[Mon Jul 20 06:40:05.497612 2026] [security2:error] [pid 983757:tid 983821] [remote 173.212.252.15:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XJXKwMdFW9UVnNBSfqwABez0"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:40:05.583441 2026] [security2:error] [pid 966386:tid 966512] [remote 57.141.18.81:26696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4927482"] [unique_id "al4XJTrLBqY1mBmWu_YW_QAAMlI"]
[Mon Jul 20 06:40:05.758519 2026] [security2:error] [pid 983757:tid 983971] [client 136.144.35.246:33513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XJXKwMdFW9UVnNBSfuwAAAVw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:05.817828 2026] [security2:error] [pid 966386:tid 966691] [client 4.194.217.15:1362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/nine2code.php"] [unique_id "al4XJTrLBqY1mBmWu_YXBgAAAH4"]
[Mon Jul 20 06:40:06.222099 2026] [security2:error] [pid 966386:tid 966609] [client 136.144.35.245:44905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XJjrLBqY1mBmWu_YXEQAAAC8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:06.274660 2026] [security2:error] [pid 983757:tid 983981] [client 57.141.18.57:63906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XJHKwMdFW9UVnNBSfhAABZmc"]
[Mon Jul 20 06:40:06.334800 2026] [security2:error] [pid 983757:tid 983972] [client 104.234.53.52:63877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XJnKwMdFW9UVnNBSf4QAAAV0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:06.365883 2026] [security2:error] [pid 983757:tid 983949] [client 223.185.13.213:12242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XJnKwMdFW9UVnNBSf4gAAAUY"]
[Mon Jul 20 06:40:06.366154 2026] [security2:error] [pid 983757:tid 983949] [client 223.185.13.213:12242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XJnKwMdFW9UVnNBSf4gAAAUY"]
[Mon Jul 20 06:40:06.367172 2026] [security2:error] [pid 983757:tid 983930] [client 217.142.18.172:27246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XJnKwMdFW9UVnNBSf4wAAATM"]
[Mon Jul 20 06:40:06.367276 2026] [security2:error] [pid 983757:tid 983930] [client 217.142.18.172:27246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XJnKwMdFW9UVnNBSf4wAAATM"]
[Mon Jul 20 06:40:06.381670 2026] [security2:error] [pid 983757:tid 983979] [client 4.194.217.15:2003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/num.php"] [unique_id "al4XJnKwMdFW9UVnNBSf5AAAAWQ"]
[Mon Jul 20 06:40:06.604468 2026] [security2:error] [pid 983757:tid 984001] [client 40.77.167.77:49442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4XJXKwMdFW9UVnNBSflQABeic"]
[Mon Jul 20 06:40:06.754137 2026] [security2:error] [pid 983757:tid 983910] [client 173.239.240.95:49961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XJnKwMdFW9UVnNBSf9QAAAR8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:06.770374 2026] [security2:error] [pid 983757:tid 984002] [client 35.187.45.1:47822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XJnKwMdFW9UVnNBSf9gAAAXs"]
[Mon Jul 20 06:40:06.838728 2026] [security2:error] [pid 983757:tid 983995] [client 209.139.113.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4XI3KwMdFW9UVnNBSfRgABdAQ"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91pickstar-studio-naruto-shino-aburame/
[Mon Jul 20 06:40:06.923194 2026] [security2:error] [pid 983757:tid 983916] [client 4.194.217.15:1054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4XJnKwMdFW9UVnNBSgAAAAASU"]
[Mon Jul 20 06:40:06.940267 2026] [security2:error] [pid 983757:tid 983957] [client 45.157.112.60:22517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XJnKwMdFW9UVnNBSf_wAAAU4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:40:07.049621 2026] [security2:error] [pid 983757:tid 983904] [client 158.173.166.181:65079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XJ3KwMdFW9UVnNBSgBgAAARk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:40:07.079168 2026] [security2:error] [pid 966386:tid 966675] [client 14.225.17.146:59748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4XJDrLBqY1mBmWu_YW7gAAAG4"], referer: http://securingmemories.com/oldsite
[Mon Jul 20 06:40:07.152528 2026] [security2:error] [pid 983757:tid 983985] [client 77.110.127.138:52207] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XJ3KwMdFW9UVnNBSgEgAAAWo"]
[Mon Jul 20 06:40:07.225988 2026] [security2:error] [pid 966386:tid 966682] [client 173.239.240.102:49403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XJzrLBqY1mBmWu_YXMAAAAHU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:07.284448 2026] [security2:error] [pid 983757:tid 983984] [client 57.141.18.66:41724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XJXKwMdFW9UVnNBSfygABaTU"]
[Mon Jul 20 06:40:07.332819 2026] [security2:error] [pid 983757:tid 983915] [client 57.141.18.60:35714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XJXKwMdFW9UVnNBSfywABJDc"]
[Mon Jul 20 06:40:07.377589 2026] [security2:error] [pid 966386:tid 966595] [client 77.110.127.138:52202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XJzrLBqY1mBmWu_YXJwAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:07.491562 2026] [security2:error] [pid 966386:tid 966607] [client 45.3.44.248:40929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XJzrLBqY1mBmWu_YXOgAAAC0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:40:07.496357 2026] [security2:error] [pid 983757:tid 983973] [client 4.194.217.15:1049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/option.php"] [unique_id "al4XJ3KwMdFW9UVnNBSgKgAAAV4"]
[Mon Jul 20 06:40:07.699185 2026] [security2:error] [pid 966386:tid 966589] [client 173.239.240.101:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XJzrLBqY1mBmWu_YXQwAAABs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:07.857762 2026] [security2:error] [pid 983757:tid 984004] [client 14.225.17.146:57784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4XJXKwMdFW9UVnNBSfogAAAX0"], referer: http://healthylifegourmet.org/oldsite
[Mon Jul 20 06:40:07.982631 2026] [security2:error] [pid 983757:tid 983955] [client 190.92.174.183:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4XJ3KwMdFW9UVnNBSgRQAAAUw"]
[Mon Jul 20 06:40:07.982834 2026] [security2:error] [pid 983757:tid 983955] [client 190.92.174.183:37512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "areitoproducciones.com"] [uri "/xmlrpc.php"] [unique_id "al4XJ3KwMdFW9UVnNBSgRQAAAUw"]
[Mon Jul 20 06:40:08.063186 2026] [security2:error] [pid 983757:tid 983917] [client 4.194.217.15:1061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/p.php"] [unique_id "al4XKHKwMdFW9UVnNBSgSAAAASY"]
[Mon Jul 20 06:40:08.177243 2026] [security2:error] [pid 983757:tid 983928] [client 136.144.35.243:31767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XKHKwMdFW9UVnNBSgSgAAATE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:08.245166 2026] [security2:error] [pid 983757:tid 983922] [client 190.92.174.183:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4XKHKwMdFW9UVnNBSgTwAAASs"]
[Mon Jul 20 06:40:08.245255 2026] [security2:error] [pid 983757:tid 983922] [client 190.92.174.183:51468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4XKHKwMdFW9UVnNBSgTwAAASs"]
[Mon Jul 20 06:40:08.306792 2026] [security2:error] [pid 966386:tid 966672] [client 57.141.18.4:48564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XJzrLBqY1mBmWu_YXKwAAawI"]
[Mon Jul 20 06:40:08.565197 2026] [security2:error] [pid 983757:tid 983941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XKHKwMdFW9UVnNBSgWgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:08.566707 2026] [security2:error] [pid 983757:tid 983932] [client 57.141.18.74:62544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XJ3KwMdFW9UVnNBSgJQABNSg"]
[Mon Jul 20 06:40:08.614342 2026] [security2:error] [pid 966386:tid 966575] [client 4.194.217.15:1498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/past.php"] [unique_id "al4XKDrLBqY1mBmWu_YXVQAAAA0"]
[Mon Jul 20 06:40:08.648021 2026] [security2:error] [pid 966386:tid 966623] [client 136.144.35.250:47473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XKDrLBqY1mBmWu_YXVgAAAD0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:08.839242 2026] [security2:error] [pid 983757:tid 983920] [client 77.110.127.138:52222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XKHKwMdFW9UVnNBSgZwAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:08.898472 2026] [security2:error] [pid 983757:tid 983892] [client 171.61.165.146:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XKHKwMdFW9UVnNBSgdwAAAQ0"]
[Mon Jul 20 06:40:08.898573 2026] [security2:error] [pid 983757:tid 983892] [client 171.61.165.146:31947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XKHKwMdFW9UVnNBSgdwAAAQ0"]
[Mon Jul 20 06:40:08.984245 2026] [security2:error] [pid 983757:tid 983896] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XKHKwMdFW9UVnNBSgdgAAARE"]
[Mon Jul 20 06:40:09.012712 2026] [security2:error] [pid 983757:tid 984011] [client 190.92.174.183:37522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4XKXKwMdFW9UVnNBSgggAAAYQ"]
[Mon Jul 20 06:40:09.012854 2026] [security2:error] [pid 983757:tid 984011] [client 190.92.174.183:37522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4XKXKwMdFW9UVnNBSgggAAAYQ"]
[Mon Jul 20 06:40:09.080973 2026] [security2:error] [pid 983757:tid 984004] [client 14.225.17.146:53187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4XKHKwMdFW9UVnNBSgbQAAAX0"], referer: http://savilerowtravel.com/oldsite
[Mon Jul 20 06:40:09.129615 2026] [security2:error] [pid 983757:tid 983972] [client 136.144.35.250:62395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XKXKwMdFW9UVnNBSghwAAAV0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:09.160429 2026] [security2:error] [pid 983757:tid 984014] [client 14.251.3.155:54556] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XKXKwMdFW9UVnNBSgiQAAAYc"]
[Mon Jul 20 06:40:09.191874 2026] [security2:error] [pid 983757:tid 983910] [client 4.194.217.15:1036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/php.php"] [unique_id "al4XKXKwMdFW9UVnNBSgjQAAAR8"]
[Mon Jul 20 06:40:09.300028 2026] [security2:error] [pid 983757:tid 984009] [client 23.21.225.190:28636] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XKXKwMdFW9UVnNBSgkAAAAYI"]
[Mon Jul 20 06:40:09.338811 2026] [security2:error] [pid 983757:tid 983879] [remote 176.56.118.182:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XKXKwMdFW9UVnNBSgkwABNHc"]
[Mon Jul 20 06:40:09.568479 2026] [security2:error] [pid 983757:tid 983870] [remote 176.56.118.182:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XKXKwMdFW9UVnNBSgngABM24"], referer: https://thefriendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:09.608900 2026] [security2:error] [pid 966386:tid 966595] [client 136.144.35.247:59581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XKTrLBqY1mBmWu_YXdwAAACE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:09.757400 2026] [security2:error] [pid 983757:tid 983993] [client 190.92.174.183:37538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4XKXKwMdFW9UVnNBSgpAAAAXI"]
[Mon Jul 20 06:40:09.757499 2026] [security2:error] [pid 983757:tid 983993] [client 190.92.174.183:37538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4XKXKwMdFW9UVnNBSgpAAAAXI"]
[Mon Jul 20 06:40:09.787156 2026] [security2:error] [pid 983757:tid 983914] [client 4.194.217.15:1526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/php8.php"] [unique_id "al4XKXKwMdFW9UVnNBSgpQAAASM"]
[Mon Jul 20 06:40:10.073372 2026] [security2:error] [pid 983757:tid 983926] [client 173.239.240.91:31673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XKnKwMdFW9UVnNBSgvAAAAS8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:10.158950 2026] [security2:error] [pid 966386:tid 966587] [client 14.225.17.146:56280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4XKTrLBqY1mBmWu_YXfQAAABk"], referer: https://savilerowtravel.com/oldsite
[Mon Jul 20 06:40:10.168081 2026] [security2:error] [pid 983757:tid 983893] [client 77.110.127.138:52232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XKXKwMdFW9UVnNBSgtQAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:10.172629 2026] [security2:error] [pid 983757:tid 983891] [client 14.225.17.146:56103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4XKXKwMdFW9UVnNBSgtAAAAQw"], referer: http://floorsourcestock.com/oldsite
[Mon Jul 20 06:40:10.220289 2026] [security2:error] [pid 983757:tid 984012] [client 57.141.18.84:54216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XKHKwMdFW9UVnNBSgeAABhSU"]
[Mon Jul 20 06:40:10.375626 2026] [security2:error] [pid 983757:tid 983965] [client 4.194.217.15:1529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/phpinfo.php"] [unique_id "al4XKnKwMdFW9UVnNBSgzwAAAVY"]
[Mon Jul 20 06:40:10.533387 2026] [security2:error] [pid 983757:tid 983995] [client 190.92.174.183:37548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/site/xmlrpc.php"] [unique_id "al4XKnKwMdFW9UVnNBSg2QAAAXQ"]
[Mon Jul 20 06:40:10.533516 2026] [security2:error] [pid 983757:tid 983995] [client 190.92.174.183:37548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/site/xmlrpc.php"] [unique_id "al4XKnKwMdFW9UVnNBSg2QAAAXQ"]
[Mon Jul 20 06:40:10.583389 2026] [security2:error] [pid 983757:tid 983991] [client 136.144.35.252:25127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XKnKwMdFW9UVnNBSg3AAAAXA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:10.628813 2026] [security2:error] [pid 983757:tid 983979] [client 114.119.133.228:47561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/wp-content/uploads/2022/07/RJP8182-scaled.jpg"] [unique_id "al4XKnKwMdFW9UVnNBSg4AAAAWQ"], referer: https://mourgroup.com/portfolio/skyline-view-apartments-renovation/
[Mon Jul 20 06:40:10.639200 2026] [security2:error] [pid 966386:tid 966684] [client 106.219.188.178:25936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XKjrLBqY1mBmWu_YXkgAAAHc"]
[Mon Jul 20 06:40:10.654618 2026] [security2:error] [pid 966386:tid 966684] [client 106.219.188.178:25936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XKjrLBqY1mBmWu_YXkgAAAHc"]
[Mon Jul 20 06:40:10.757805 2026] [security2:error] [pid 983757:tid 983984] [client 77.110.127.138:52237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XKnKwMdFW9UVnNBSg2wAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:11.037815 2026] [security2:error] [pid 983757:tid 983923] [client 173.239.240.101:62069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XK3KwMdFW9UVnNBSg-wAAASw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:11.083819 2026] [security2:error] [pid 983757:tid 983900] [client 39.48.81.23:56699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XK3KwMdFW9UVnNBSg_wAAARU"]
[Mon Jul 20 06:40:11.083906 2026] [security2:error] [pid 983757:tid 983900] [client 39.48.81.23:56699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XK3KwMdFW9UVnNBSg_wAAARU"]
[Mon Jul 20 06:40:11.280224 2026] [security2:error] [pid 983757:tid 983986] [client 190.92.174.183:37560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/web/xmlrpc.php"] [unique_id "al4XK3KwMdFW9UVnNBShCgAAAWs"]
[Mon Jul 20 06:40:11.280293 2026] [security2:error] [pid 983757:tid 983986] [client 190.92.174.183:37560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/web/xmlrpc.php"] [unique_id "al4XK3KwMdFW9UVnNBShCgAAAWs"]
[Mon Jul 20 06:40:11.441353 2026] [security2:error] [pid 983757:tid 983927] [client 216.24.210.91:20171] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "asliceofleadership.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4XK3KwMdFW9UVnNBShFwAAATA"]
[Mon Jul 20 06:40:11.516815 2026] [security2:error] [pid 983757:tid 983955] [client 14.225.17.146:60686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4XK3KwMdFW9UVnNBShEAAAAUw"], referer: http://thefriendlyspreadsheet.com/oldsite
[Mon Jul 20 06:40:11.538646 2026] [security2:error] [pid 983757:tid 983979] [client 136.144.35.245:50467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XK3KwMdFW9UVnNBShHQAAAWQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:11.704691 2026] [security2:error] [pid 966386:tid 966675] [client 50.116.65.227:57724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XKzrLBqY1mBmWu_YXpgAAAG4"]
[Mon Jul 20 06:40:11.714522 2026] [security2:error] [pid 983757:tid 983898] [client 50.116.65.227:57740] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XK3KwMdFW9UVnNBShIAAAARM"]
[Mon Jul 20 06:40:11.743804 2026] [security2:error] [pid 983757:tid 983928] [client 77.110.127.138:52243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XK3KwMdFW9UVnNBShFQAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:11.745705 2026] [security2:error] [pid 983757:tid 983964] [client 112.208.70.94:45070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XK3KwMdFW9UVnNBShIgAAAVU"]
[Mon Jul 20 06:40:11.745826 2026] [security2:error] [pid 983757:tid 983964] [client 112.208.70.94:45070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XK3KwMdFW9UVnNBShIgAAAVU"]
[Mon Jul 20 06:40:11.768436 2026] [security2:error] [pid 983757:tid 983994] [client 57.141.18.56:37680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XKnKwMdFW9UVnNBSg0AABcwo"]
[Mon Jul 20 06:40:11.769939 2026] [security2:error] [pid 966386:tid 966572] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XKzrLBqY1mBmWu_YXnQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:12.007277 2026] [security2:error] [pid 983757:tid 983931] [client 136.144.35.250:52615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XLHKwMdFW9UVnNBShNAAAATQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:12.018625 2026] [security2:error] [pid 983757:tid 983953] [client 190.92.174.183:37568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/main/xmlrpc.php"] [unique_id "al4XLHKwMdFW9UVnNBShMwAAAUo"]
[Mon Jul 20 06:40:12.018775 2026] [security2:error] [pid 983757:tid 983953] [client 190.92.174.183:37568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/main/xmlrpc.php"] [unique_id "al4XLHKwMdFW9UVnNBShMwAAAUo"]
[Mon Jul 20 06:40:12.197890 2026] [security2:error] [pid 966386:tid 966644] [client 4.194.217.15:1349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4XKjrLBqY1mBmWu_YXlQAAAFI"]
[Mon Jul 20 06:40:12.351769 2026] [security2:error] [pid 983757:tid 983935] [client 77.110.127.138:52248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XLHKwMdFW9UVnNBShOgAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:12.378184 2026] [security2:error] [pid 966386:tid 966624] [client 4.194.217.15:1349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/post.php"] [unique_id "al4XLDrLBqY1mBmWu_YXuwAAAD4"]
[Mon Jul 20 06:40:12.469482 2026] [security2:error] [pid 983757:tid 983984] [client 3.211.105.134:14544] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XLHKwMdFW9UVnNBShTAAAAWk"]
[Mon Jul 20 06:40:12.476521 2026] [security2:error] [pid 983757:tid 983972] [client 173.239.240.90:27825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XLHKwMdFW9UVnNBShTQAAAV0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:12.590379 2026] [security2:error] [pid 983757:tid 983977] [client 57.141.18.105:26066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XK3KwMdFW9UVnNBShAAABYio"]
[Mon Jul 20 06:40:12.765225 2026] [security2:error] [pid 983757:tid 983964] [client 190.92.174.183:37584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4XLHKwMdFW9UVnNBShXwAAAVU"]
[Mon Jul 20 06:40:12.765332 2026] [security2:error] [pid 983757:tid 983964] [client 190.92.174.183:37584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4XLHKwMdFW9UVnNBShXwAAAVU"]
[Mon Jul 20 06:40:12.916233 2026] [security2:error] [pid 983757:tid 984010] [client 103.125.179.95:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XLHKwMdFW9UVnNBShaQAAAYM"]
[Mon Jul 20 06:40:12.916591 2026] [security2:error] [pid 983757:tid 984010] [client 103.125.179.95:55679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XLHKwMdFW9UVnNBShaQAAAYM"]
[Mon Jul 20 06:40:12.947937 2026] [security2:error] [pid 966386:tid 966561] [client 173.239.240.95:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XLDrLBqY1mBmWu_YXygAAAAE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:12.952978 2026] [security2:error] [pid 983757:tid 983948] [client 4.194.217.15:1376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4XLHKwMdFW9UVnNBShbQAAAUU"]
[Mon Jul 20 06:40:13.125237 2026] [security2:error] [pid 983757:tid 983791] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBSheAABDR8"]
[Mon Jul 20 06:40:13.125425 2026] [security2:error] [pid 983757:tid 983892] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBSheAABDR8"]
[Mon Jul 20 06:40:13.341188 2026] [security2:error] [pid 983757:tid 983913] [client 104.234.53.68:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XLXKwMdFW9UVnNBShggAAASI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:13.397126 2026] [security2:error] [pid 983757:tid 983983] [client 136.144.35.245:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XLXKwMdFW9UVnNBShhAAAAWg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:13.397565 2026] [security2:error] [pid 966386:tid 966659] [client 72.63.1.22:31348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "daseighty.net"] [uri "/gallery/main.php"] [unique_id "al4XLTrLBqY1mBmWu_YX2AAAAGA"]
[Mon Jul 20 06:40:13.408010 2026] [security2:error] [pid 983757:tid 983979] [client 197.186.66.42:49856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBShhwAAAWQ"]
[Mon Jul 20 06:40:13.421002 2026] [security2:error] [pid 983757:tid 983979] [client 197.186.66.42:49856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBShhwAAAWQ"]
[Mon Jul 20 06:40:13.436626 2026] [security2:error] [pid 966386:tid 966601] [client 14.225.17.146:53683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4XLTrLBqY1mBmWu_YX1wAAACc"], referer: http://chestermonty.com/oldsite
[Mon Jul 20 06:40:13.514556 2026] [security2:error] [pid 983757:tid 983988] [client 190.92.174.183:59418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBShiwAAAW0"]
[Mon Jul 20 06:40:13.514683 2026] [security2:error] [pid 983757:tid 983988] [client 190.92.174.183:59418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBShiwAAAW0"]
[Mon Jul 20 06:40:13.517568 2026] [security2:error] [pid 983757:tid 983893] [client 4.194.217.15:1065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/public/css.php"] [unique_id "al4XLXKwMdFW9UVnNBShjAAAAQ4"]
[Mon Jul 20 06:40:13.543292 2026] [security2:error] [pid 966386:tid 966602] [client 77.110.127.138:52254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XLTrLBqY1mBmWu_YX0wAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:13.623140 2026] [security2:error] [pid 983757:tid 983937] [client 152.58.191.29:40454] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBShkQAAATo"]
[Mon Jul 20 06:40:13.623257 2026] [security2:error] [pid 983757:tid 983937] [client 152.58.191.29:40454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XLXKwMdFW9UVnNBShkQAAATo"]
[Mon Jul 20 06:40:13.708553 2026] [security2:error] [pid 983757:tid 983899] [client 57.141.18.32:63184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLHKwMdFW9UVnNBShPgABFHQ"]
[Mon Jul 20 06:40:13.744050 2026] [security2:error] [pid 983757:tid 983955] [client 57.141.18.31:27108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLHKwMdFW9UVnNBShPwABTDw"]
[Mon Jul 20 06:40:13.752466 2026] [security2:error] [pid 983757:tid 983943] [client 65.111.15.122:12837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XLXKwMdFW9UVnNBShlgAAAUA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:13.850658 2026] [security2:error] [pid 983757:tid 983973] [client 173.239.240.100:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XLXKwMdFW9UVnNBShnQAAAV4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:13.860543 2026] [security2:error] [pid 966386:tid 966645] [client 14.225.17.146:60701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4XLTrLBqY1mBmWu_YX2wAAAFM"]
[Mon Jul 20 06:40:14.049057 2026] [security2:error] [pid 983757:tid 983889] [client 187.108.85.186:55115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XLnKwMdFW9UVnNBShqAAAAQo"]
[Mon Jul 20 06:40:14.049176 2026] [security2:error] [pid 983757:tid 983889] [client 187.108.85.186:55115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XLnKwMdFW9UVnNBShqAAAAQo"]
[Mon Jul 20 06:40:14.058036 2026] [security2:error] [pid 966386:tid 966683] [client 4.194.217.15:2045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/r.php"] [unique_id "al4XLjrLBqY1mBmWu_YX8wAAAHY"]
[Mon Jul 20 06:40:14.242484 2026] [security2:error] [pid 966386:tid 966652] [client 190.92.174.183:59432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/old/xmlrpc.php"] [unique_id "al4XLjrLBqY1mBmWu_YX9wAAAFo"]
[Mon Jul 20 06:40:14.242640 2026] [security2:error] [pid 966386:tid 966652] [client 190.92.174.183:59432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/old/xmlrpc.php"] [unique_id "al4XLjrLBqY1mBmWu_YX9wAAAFo"]
[Mon Jul 20 06:40:14.308028 2026] [security2:error] [pid 983757:tid 983983] [client 136.144.35.248:32683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XLnKwMdFW9UVnNBShtgAAAWg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:14.399583 2026] [security2:error] [pid 966386:tid 966665] [client 14.225.17.146:60594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4XLjrLBqY1mBmWu_YX-AAAAGY"], referer: https://chestermonty.com/oldsite
[Mon Jul 20 06:40:14.538282 2026] [security2:error] [pid 983757:tid 983979] [client 98.159.234.160:61311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XLnKwMdFW9UVnNBShxgAAAWQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:40:14.656401 2026] [security2:error] [pid 983757:tid 983937] [client 4.194.217.15:1354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/radio.php"] [unique_id "al4XLnKwMdFW9UVnNBShzQAAATo"]
[Mon Jul 20 06:40:14.683023 2026] [security2:error] [pid 983757:tid 983911] [client 104.234.53.47:26441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XLnKwMdFW9UVnNBShzwAAASA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:14.751379 2026] [security2:error] [pid 983757:tid 983906] [client 103.238.106.162:60607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XLnKwMdFW9UVnNBSh0QAAARs"]
[Mon Jul 20 06:40:14.751506 2026] [security2:error] [pid 983757:tid 983906] [client 103.238.106.162:60607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XLnKwMdFW9UVnNBSh0QAAARs"]
[Mon Jul 20 06:40:14.765142 2026] [security2:error] [pid 966386:tid 966629] [client 136.144.35.248:25307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XLjrLBqY1mBmWu_YYBgAAAEM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:14.793028 2026] [security2:error] [pid 966386:tid 966686] [client 57.141.18.108:60772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLTrLBqY1mBmWu_YX3AAAeRw"]
[Mon Jul 20 06:40:14.832801 2026] [security2:error] [pid 966386:tid 966568] [client 57.141.18.116:42554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLTrLBqY1mBmWu_YX5AAABig"]
[Mon Jul 20 06:40:14.995131 2026] [security2:error] [pid 966386:tid 966583] [client 190.92.174.183:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/new/xmlrpc.php"] [unique_id "al4XLjrLBqY1mBmWu_YYEAAAABU"]
[Mon Jul 20 06:40:14.995271 2026] [security2:error] [pid 966386:tid 966583] [client 190.92.174.183:59434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.areitoproducciones.com"] [uri "/new/xmlrpc.php"] [unique_id "al4XLjrLBqY1mBmWu_YYEAAAABU"]
[Mon Jul 20 06:40:15.025894 2026] [security2:error] [pid 983757:tid 983939] [client 14.225.17.146:60622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4XLnKwMdFW9UVnNBSh1wAAATw"], referer: http://intelligentengineeringsolutions.com/oldsite
[Mon Jul 20 06:40:15.114553 2026] [security2:error] [pid 983757:tid 983889] [client 35.187.45.1:47826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XL3KwMdFW9UVnNBSh4AAAAQo"]
[Mon Jul 20 06:40:15.117229 2026] [security2:error] [pid 966386:tid 966647] [client 35.187.45.1:47828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XLzrLBqY1mBmWu_YYFQAAAFU"]
[Mon Jul 20 06:40:15.202302 2026] [security2:error] [pid 983757:tid 984009] [client 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4XL3KwMdFW9UVnNBSh6QAAAYI"]
[Mon Jul 20 06:40:15.202445 2026] [security2:error] [pid 983757:tid 984009] [client 5.161.225.162:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4XL3KwMdFW9UVnNBSh6QAAAYI"]
[Mon Jul 20 06:40:15.207288 2026] [security2:error] [pid 966386:tid 966621] [client 4.194.217.15:1385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/randkeyword.php7"] [unique_id "al4XLzrLBqY1mBmWu_YYGwAAADs"]
[Mon Jul 20 06:40:15.214569 2026] [security2:error] [pid 983757:tid 983921] [client 136.144.35.247:64185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XL3KwMdFW9UVnNBSh7AAAASo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:15.313432 2026] [security2:error] [pid 983757:tid 983988] [client 189.104.197.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4XL3KwMdFW9UVnNBSh8AAAAW0"]
[Mon Jul 20 06:40:15.319082 2026] [security2:error] [pid 966386:tid 966573] [client 189.104.197.5:36616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/gallery/main.php"] [unique_id "al4XLzrLBqY1mBmWu_YYGAAAAAs"]
[Mon Jul 20 06:40:15.414885 2026] [security2:error] [pid 983757:tid 983910] [client 57.141.18.95:24348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLnKwMdFW9UVnNBShtwABH0k"]
[Mon Jul 20 06:40:15.481567 2026] [security2:error] [pid 983757:tid 983977] [client 77.110.127.138:52261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XL3KwMdFW9UVnNBSh8QAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:15.589724 2026] [security2:error] [pid 966386:tid 966653] [client 104.234.53.66:41531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XLzrLBqY1mBmWu_YYKwAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:15.639331 2026] [security2:error] [pid 983757:tid 983924] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XL3KwMdFW9UVnNBSh9wAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:15.723763 2026] [security2:error] [pid 983757:tid 983987] [client 136.144.35.252:34113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XL3KwMdFW9UVnNBSiEgAAAWw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:15.777650 2026] [security2:error] [pid 983757:tid 983997] [client 4.194.217.15:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/readme.php"] [unique_id "al4XL3KwMdFW9UVnNBSiFQAAAXY"]
[Mon Jul 20 06:40:15.867005 2026] [security2:error] [pid 966386:tid 966587] [client 57.141.18.84:38368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLjrLBqY1mBmWu_YX_wAAGWM"]
[Mon Jul 20 06:40:15.874136 2026] [security2:error] [pid 966386:tid 966640] [client 74.208.214.194:52398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XLzrLBqY1mBmWu_YYNQAAAE4"]
[Mon Jul 20 06:40:15.973867 2026] [security2:error] [pid 966386:tid 966631] [client 57.141.18.54:28670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XLjrLBqY1mBmWu_YYBQAARUs"]
[Mon Jul 20 06:40:15.987275 2026] [security2:error] [pid 966386:tid 966673] [client 216.73.217.138:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XLzrLBqY1mBmWu_YYNgAAbE4"]
[Mon Jul 20 06:40:15.996468 2026] [security2:error] [pid 966386:tid 966448] [remote 216.73.217.138:30947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XLzrLBqY1mBmWu_YYNwAAbBU"]
[Mon Jul 20 06:40:16.120510 2026] [security2:error] [pid 966386:tid 966585] [client 14.225.17.146:50252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4XLjrLBqY1mBmWu_YYAAAAABc"], referer: http://ghivs.com/oldsite
[Mon Jul 20 06:40:16.160351 2026] [security2:error] [pid 983757:tid 983965] [client 217.181.92.200:52213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XMHKwMdFW9UVnNBSiJQAAAVY"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:16.233704 2026] [security2:error] [pid 966386:tid 966634] [client 173.239.240.99:22989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XMDrLBqY1mBmWu_YYQgAAAEg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:16.244413 2026] [security2:error] [pid 983757:tid 983931] [client 14.225.17.146:60989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4XMHKwMdFW9UVnNBSiHQAAATQ"]
[Mon Jul 20 06:40:16.335079 2026] [security2:error] [pid 983757:tid 983979] [client 4.194.217.15:2038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/reze.php"] [unique_id "al4XMHKwMdFW9UVnNBSiMgAAAWQ"]
[Mon Jul 20 06:40:16.427755 2026] [security2:error] [pid 983757:tid 983907] [client 74.7.228.43:34328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4XMHKwMdFW9UVnNBSiOQABHFY"]
[Mon Jul 20 06:40:16.523495 2026] [security2:error] [pid 983757:tid 983954] [client 74.7.228.43:34328] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sustaintheart.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4XMHKwMdFW9UVnNBSiPQABS00"], referer: https://sustaintheart.com/robots.txt
[Mon Jul 20 06:40:16.606052 2026] [security2:error] [pid 983757:tid 983797] [remote 173.212.252.15:37040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4XMHKwMdFW9UVnNBSiSQABWCU"]
[Mon Jul 20 06:40:16.712926 2026] [security2:error] [pid 966386:tid 966687] [client 52.5.242.243:33303] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/wwwthemedicalgroupcouk-772a.pdf"] [unique_id "al4XMDrLBqY1mBmWu_YYVgAAAHo"]
[Mon Jul 20 06:40:16.731089 2026] [security2:error] [pid 966386:tid 966572] [client 136.144.35.243:45851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XMDrLBqY1mBmWu_YYVwAAAAo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:16.794850 2026] [security2:error] [pid 983757:tid 983953] [client 57.141.18.66:32804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XL3KwMdFW9UVnNBSiDwABSj4"]
[Mon Jul 20 06:40:16.850143 2026] [security2:error] [pid 983757:tid 983885] [remote 173.212.252.15:37040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4XMHKwMdFW9UVnNBSiUwABF30"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:40:16.877055 2026] [security2:error] [pid 983757:tid 983962] [client 4.194.217.15:1492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/rh.php"] [unique_id "al4XMHKwMdFW9UVnNBSiWAAAAVM"]
[Mon Jul 20 06:40:16.907989 2026] [security2:error] [pid 966386:tid 966563] [client 77.110.127.138:52278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XMDrLBqY1mBmWu_YYVQAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:16.934794 2026] [security2:error] [pid 983757:tid 983901] [client 217.142.18.172:26948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XMHKwMdFW9UVnNBSiWwAAARY"]
[Mon Jul 20 06:40:16.934940 2026] [security2:error] [pid 983757:tid 983901] [client 217.142.18.172:26948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XMHKwMdFW9UVnNBSiWwAAARY"]
[Mon Jul 20 06:40:17.062654 2026] [security2:error] [pid 983757:tid 983935] [client 45.3.48.20:60613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XMXKwMdFW9UVnNBSiXwAAATg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:17.155686 2026] [core:error] [pid 983757:tid 983970] [client 195.170.172.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:40:17.155714 2026] [core:error] [pid 983757:tid 983970] [client 195.170.172.102:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:40:17.209342 2026] [security2:error] [pid 983757:tid 983905] [client 173.239.240.95:30941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XMXKwMdFW9UVnNBSiaQAAARo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:17.218130 2026] [security2:error] [pid 983757:tid 983972] [client 223.185.13.213:10072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XMXKwMdFW9UVnNBSiagAAAV0"]
[Mon Jul 20 06:40:17.218253 2026] [security2:error] [pid 983757:tid 983972] [client 223.185.13.213:10072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XMXKwMdFW9UVnNBSiagAAAV0"]
[Mon Jul 20 06:40:17.299057 2026] [security2:error] [pid 966386:tid 966574] [client 57.141.18.31:27112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XMDrLBqY1mBmWu_YYOQAADEQ"]
[Mon Jul 20 06:40:17.490544 2026] [security2:error] [pid 983757:tid 983882] [remote 5.161.225.162:50672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XMXKwMdFW9UVnNBSidQABhno"]
[Mon Jul 20 06:40:17.513593 2026] [security2:error] [pid 983757:tid 983947] [client 4.194.217.15:1374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/rip.php"] [unique_id "al4XMXKwMdFW9UVnNBSidgAAAUQ"]
[Mon Jul 20 06:40:17.697177 2026] [security2:error] [pid 966386:tid 966683] [client 173.239.240.100:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XMTrLBqY1mBmWu_YYaQAAAHY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:17.702129 2026] [security2:error] [pid 983757:tid 983874] [remote 130.51.180.8:49754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XMXKwMdFW9UVnNBSiggABMXI"]
[Mon Jul 20 06:40:17.702337 2026] [security2:error] [pid 983757:tid 983928] [client 130.51.180.8:49754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XMXKwMdFW9UVnNBSiggABMXI"]
[Mon Jul 20 06:40:17.804780 2026] [security2:error] [pid 966386:tid 966588] [client 91.92.42.58:37432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.teresaharding.com"] [uri "/wp-login.php"] [unique_id "al4XMTrLBqY1mBmWu_YYagAAABo"], referer: https://duckduckgo.com/
[Mon Jul 20 06:40:18.069708 2026] [security2:error] [pid 983757:tid 983975] [client 4.194.217.15:1370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/root.php"] [unique_id "al4XMnKwMdFW9UVnNBSilQAAAWA"]
[Mon Jul 20 06:40:18.150916 2026] [security2:error] [pid 983757:tid 984015] [client 173.239.240.95:46759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XMnKwMdFW9UVnNBSimQAAAYg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:18.311666 2026] [security2:error] [pid 983757:tid 983969] [client 190.92.174.183:59448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/wp-login.php"] [unique_id "al4XMnKwMdFW9UVnNBSiqwAAAVo"], referer: https://www.areitoproducciones.com/wp-admin/
[Mon Jul 20 06:40:18.372220 2026] [security2:error] [pid 983757:tid 983897] [client 39.48.81.23:57235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XMnKwMdFW9UVnNBSisAAAARI"]
[Mon Jul 20 06:40:18.372341 2026] [security2:error] [pid 983757:tid 983897] [client 39.48.81.23:57235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XMnKwMdFW9UVnNBSisAAAARI"]
[Mon Jul 20 06:40:18.451999 2026] [security2:error] [pid 983757:tid 983971] [client 45.3.55.187:39675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XMnKwMdFW9UVnNBSitwAAAVw"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:18.452420 2026] [security2:error] [pid 983757:tid 983857] [remote 154.66.198.148:31948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XMnKwMdFW9UVnNBSiuAABVWE"]
[Mon Jul 20 06:40:18.541167 2026] [security2:error] [pid 983757:tid 984010] [client 104.234.53.81:28887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XMnKwMdFW9UVnNBSivgAAAYM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:18.564592 2026] [security2:error] [pid 966386:tid 966659] [client 190.92.174.183:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.174.92.190.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.areitoproducciones.com"] [uri "/wp-login.php"] [unique_id "al4XMjrLBqY1mBmWu_YYgwAAAGA"]
[Mon Jul 20 06:40:18.629401 2026] [security2:error] [pid 983757:tid 984002] [client 4.194.217.15:1067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/s.php"] [unique_id "al4XMnKwMdFW9UVnNBSixAAAAXs"]
[Mon Jul 20 06:40:18.635473 2026] [security2:error] [pid 983757:tid 983941] [client 136.144.35.250:28045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XMnKwMdFW9UVnNBSiwgAAAT4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:18.962282 2026] [security2:error] [pid 983757:tid 983889] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4XMnKwMdFW9UVnNBSitgABChM"], referer: http://ardhalwafaa.com/oldsite
[Mon Jul 20 06:40:19.022675 2026] [security2:error] [pid 983757:tid 983842] [remote 5.161.225.162:50672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XM3KwMdFW9UVnNBSi1QABPVI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:40:19.045082 2026] [security2:error] [pid 983757:tid 983825] [remote 154.66.198.148:31948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XM3KwMdFW9UVnNBSi1wABL0E"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:40:19.064048 2026] [security2:error] [pid 966386:tid 966613] [client 57.141.18.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4XMjrLBqY1mBmWu_YYggAAADM"]
[Mon Jul 20 06:40:19.070200 2026] [security2:error] [pid 983757:tid 983979] [client 14.225.17.146:62196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4XMXKwMdFW9UVnNBSicwAAAWQ"], referer: http://ksands.co.uk/oldsite
[Mon Jul 20 06:40:19.101850 2026] [security2:error] [pid 966386:tid 966578] [client 173.239.240.31:61787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XMzrLBqY1mBmWu_YYkwAAABA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:19.200159 2026] [security2:error] [pid 983757:tid 983991] [client 4.194.217.15:1377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sang.php"] [unique_id "al4XM3KwMdFW9UVnNBSi4wAAAXA"]
[Mon Jul 20 06:40:19.345862 2026] [security2:error] [pid 966386:tid 966429] [remote 188.166.241.141:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XMzrLBqY1mBmWu_YYnAAAKgI"]
[Mon Jul 20 06:40:19.368013 2026] [security2:error] [pid 966386:tid 966689] [client 65.111.11.231:60879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XMzrLBqY1mBmWu_YYmwAAAHw"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:19.593514 2026] [security2:error] [pid 983757:tid 983891] [client 173.239.240.31:24705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XM3KwMdFW9UVnNBSi8gAAAQw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:19.772166 2026] [security2:error] [pid 983757:tid 983922] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XM3KwMdFW9UVnNBSi7wAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:19.775095 2026] [proxy:error] [pid 983757:tid 983975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:19.775167 2026] [proxy_http:error] [pid 983757:tid 983975] [client 34.73.38.214:65400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:19.775619 2026] [proxy:error] [pid 983757:tid 983975] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:19.775646 2026] [proxy_http:error] [pid 983757:tid 983975] [client 34.73.38.214:65400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:19.780049 2026] [security2:error] [pid 966386:tid 966574] [client 4.194.217.15:1483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/scxy.php"] [unique_id "al4XMzrLBqY1mBmWu_YYqgAAAAw"]
[Mon Jul 20 06:40:19.783005 2026] [security2:error] [pid 966386:tid 966428] [remote 188.166.241.141:33944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XMzrLBqY1mBmWu_YYrAAAFAE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:40:20.068153 2026] [security2:error] [pid 966386:tid 966569] [client 173.239.240.98:50531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XNDrLBqY1mBmWu_YYtwAAAAc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:20.082594 2026] [security2:error] [pid 966386:tid 966686] [client 35.171.141.42:29671] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/nelumbo-nucifera-flower-extract-toxicity-772a.pdf"] [unique_id "al4XNDrLBqY1mBmWu_YYuAAAAHk"]
[Mon Jul 20 06:40:20.129349 2026] [security2:error] [pid 983757:tid 984002] [client 171.61.165.146:27756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XNHKwMdFW9UVnNBSjGAAAAXs"]
[Mon Jul 20 06:40:20.129436 2026] [security2:error] [pid 983757:tid 984002] [client 171.61.165.146:27756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XNHKwMdFW9UVnNBSjGAAAAXs"]
[Mon Jul 20 06:40:20.320867 2026] [security2:error] [pid 966386:tid 966649] [client 4.194.217.15:2005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sd.php"] [unique_id "al4XNDrLBqY1mBmWu_YYvAAAAFc"]
[Mon Jul 20 06:40:20.539127 2026] [security2:error] [pid 983757:tid 983910] [client 173.239.240.99:31293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XNHKwMdFW9UVnNBSjKgAAAR8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:20.548806 2026] [security2:error] [pid 966386:tid 966672] [client 104.234.53.52:46095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XNDrLBqY1mBmWu_YYwQAAAGs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:20.580904 2026] [security2:error] [pid 966386:tid 966556] [remote 124.55.178.99:48570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XNDrLBqY1mBmWu_YYwgAAPH4"]
[Mon Jul 20 06:40:20.655224 2026] [proxy:error] [pid 966386:tid 966572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:20.655306 2026] [proxy_http:error] [pid 966386:tid 966572] [client 34.73.38.214:54920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:20.656538 2026] [proxy:error] [pid 966386:tid 966572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:20.656585 2026] [proxy_http:error] [pid 966386:tid 966572] [client 34.73.38.214:54920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:20.728437 2026] [core:error] [pid 983757:tid 983963] [client 14.225.17.146:64457] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:40:20.728457 2026] [core:error] [pid 983757:tid 983963] [client 14.225.17.146:64457] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:40:20.878071 2026] [security2:error] [pid 983757:tid 983903] [client 4.194.217.15:1432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sf.php"] [unique_id "al4XNHKwMdFW9UVnNBSjOgAAARg"]
[Mon Jul 20 06:40:20.945350 2026] [security2:error] [pid 966386:tid 966604] [client 216.73.216.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4XNDrLBqY1mBmWu_YY0AAAACo"]
[Mon Jul 20 06:40:20.974658 2026] [security2:error] [pid 983757:tid 983924] [client 14.225.17.146:64499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4XNHKwMdFW9UVnNBSjHQAAAS0"], referer: http://idigress.studio/oldsite
[Mon Jul 20 06:40:20.987238 2026] [security2:error] [pid 983757:tid 984016] [client 14.225.17.146:60930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4XNHKwMdFW9UVnNBSjLAAAAYk"], referer: http://idigress.agency/oldsite
[Mon Jul 20 06:40:21.010115 2026] [security2:error] [pid 966386:tid 966639] [client 173.239.240.92:37155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XNTrLBqY1mBmWu_YY3QAAAE0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:21.098010 2026] [security2:error] [pid 966386:tid 966510] [remote 124.55.178.99:48570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XNTrLBqY1mBmWu_YY4QAAYlA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:40:21.119390 2026] [security2:error] [pid 983757:tid 983951] [client 77.110.127.138:52317] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4XNXKwMdFW9UVnNBSjRQAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:21.168708 2026] [security2:error] [pid 983757:tid 983952] [client 57.141.18.67:56710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XM3KwMdFW9UVnNBSi8AABSQk"]
[Mon Jul 20 06:40:21.223310 2026] [security2:error] [pid 966386:tid 966684] [client 14.225.17.146:54077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4XMjrLBqY1mBmWu_YYigAAAHc"], referer: http://overloadcomedy.com/oldsite
[Mon Jul 20 06:40:21.295136 2026] [security2:error] [pid 966386:tid 966688] [client 106.219.188.178:47756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XNTrLBqY1mBmWu_YY5AAAAHs"]
[Mon Jul 20 06:40:21.311757 2026] [security2:error] [pid 966386:tid 966688] [client 106.219.188.178:47756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XNTrLBqY1mBmWu_YY5AAAAHs"]
[Mon Jul 20 06:40:21.432531 2026] [security2:error] [pid 983757:tid 983932] [client 57.141.18.39:45169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XM3KwMdFW9UVnNBSjBAABNTU"]
[Mon Jul 20 06:40:21.436369 2026] [security2:error] [pid 966386:tid 966652] [client 4.194.217.15:1497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/shell.php"] [unique_id "al4XNTrLBqY1mBmWu_YY6gAAAFo"]
[Mon Jul 20 06:40:21.484987 2026] [security2:error] [pid 966386:tid 966673] [client 173.239.240.95:28145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XNTrLBqY1mBmWu_YY7QAAAGw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:21.500542 2026] [security2:error] [pid 966386:tid 966602] [client 14.225.17.146:64430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4XNDrLBqY1mBmWu_YY1QAAACg"], referer: http://gearwaterproof.com/oldsite
[Mon Jul 20 06:40:21.626107 2026] [security2:error] [pid 983757:tid 983819] [remote 81.173.115.7:38180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XNXKwMdFW9UVnNBSjXQABYzs"]
[Mon Jul 20 06:40:21.626320 2026] [security2:error] [pid 983757:tid 983978] [client 81.173.115.7:38180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XNXKwMdFW9UVnNBSjXQABYzs"]
[Mon Jul 20 06:40:21.803865 2026] [security2:error] [pid 966386:tid 966616] [client 52.109.76.144:33059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XNTrLBqY1mBmWu_YY9wAAADY"]
[Mon Jul 20 06:40:21.948064 2026] [security2:error] [pid 966386:tid 966665] [client 52.109.76.144:33059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XNTrLBqY1mBmWu_YY_QAAAGY"]
[Mon Jul 20 06:40:21.998063 2026] [security2:error] [pid 983757:tid 983935] [client 136.144.35.246:38397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XNXKwMdFW9UVnNBSjcgAAATg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:22.077065 2026] [security2:error] [pid 983757:tid 983914] [client 52.109.89.119:20675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XNnKwMdFW9UVnNBSjdAAAASM"]
[Mon Jul 20 06:40:22.093127 2026] [security2:error] [pid 966386:tid 966687] [client 4.194.217.15:1417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4XNjrLBqY1mBmWu_YY_wAAAHo"]
[Mon Jul 20 06:40:22.253989 2026] [security2:error] [pid 983757:tid 983951] [client 52.109.89.119:20675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XNnKwMdFW9UVnNBSjeQAAAUg"]
[Mon Jul 20 06:40:22.273336 2026] [security2:error] [pid 966386:tid 966632] [client 4.194.217.15:1417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sid3.php"] [unique_id "al4XNjrLBqY1mBmWu_YZBgAAAEY"]
[Mon Jul 20 06:40:22.375172 2026] [security2:error] [pid 966386:tid 966439] [remote 173.249.4.11:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4XNjrLBqY1mBmWu_YZCwAAbww"]
[Mon Jul 20 06:40:22.403355 2026] [security2:error] [pid 983757:tid 983936] [client 112.208.70.94:45488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XNnKwMdFW9UVnNBSjfAAAATk"]
[Mon Jul 20 06:40:22.403465 2026] [security2:error] [pid 983757:tid 983936] [client 112.208.70.94:45488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XNnKwMdFW9UVnNBSjfAAAATk"]
[Mon Jul 20 06:40:22.454456 2026] [security2:error] [pid 966386:tid 966674] [client 173.239.240.95:31165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XNjrLBqY1mBmWu_YZDwAAAG0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:22.595443 2026] [security2:error] [pid 966386:tid 966433] [remote 216.73.216.55:16085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/contact-us/"] [unique_id "al4XNjrLBqY1mBmWu_YZFgAAYgY"]
[Mon Jul 20 06:40:22.616334 2026] [proxy:error] [pid 966386:tid 966564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:22.616406 2026] [proxy_http:error] [pid 966386:tid 966564] [client 34.73.38.214:49229] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:22.617056 2026] [proxy:error] [pid 966386:tid 966564] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:22.617085 2026] [proxy_http:error] [pid 966386:tid 966564] [client 34.73.38.214:49229] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:22.814496 2026] [security2:error] [pid 966386:tid 966630] [client 4.194.217.15:1033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/simple.php"] [unique_id "al4XNjrLBqY1mBmWu_YZHwAAAEQ"]
[Mon Jul 20 06:40:22.914177 2026] [security2:error] [pid 966386:tid 966688] [client 173.239.240.91:40813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XNjrLBqY1mBmWu_YZIwAAAHs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:22.940341 2026] [security2:error] [pid 983757:tid 983915] [client 14.225.17.146:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4XNXKwMdFW9UVnNBSjWQAAASQ"], referer: http://dereckcastellon.com/oldsite
[Mon Jul 20 06:40:22.950133 2026] [security2:error] [pid 983757:tid 983941] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XNnKwMdFW9UVnNBSjiQAAAT4"]
[Mon Jul 20 06:40:23.180004 2026] [security2:error] [pid 966386:tid 966603] [client 57.141.18.65:32662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XNTrLBqY1mBmWu_YY7gAAKXA"]
[Mon Jul 20 06:40:23.213940 2026] [security2:error] [pid 983757:tid 983937] [client 14.225.17.146:57673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4XNXKwMdFW9UVnNBSjbgAAATo"], referer: http://windowtx.com/oldsite
[Mon Jul 20 06:40:23.319339 2026] [security2:error] [pid 966386:tid 966446] [remote 173.249.4.11:8310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4XNzrLBqY1mBmWu_YZOQAAQRM"], referer: https://thslogistics.net/wp-login.php
[Mon Jul 20 06:40:23.388704 2026] [security2:error] [pid 966386:tid 966635] [client 4.194.217.15:1387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sitemap.php"] [unique_id "al4XNzrLBqY1mBmWu_YZOwAAAEk"]
[Mon Jul 20 06:40:23.404467 2026] [security2:error] [pid 983757:tid 983967] [client 173.239.240.92:62365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XN3KwMdFW9UVnNBSjrAAAAVg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:23.490515 2026] [security2:error] [pid 966386:tid 966577] [client 50.116.65.227:26238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XNzrLBqY1mBmWu_YZPgAAAA8"]
[Mon Jul 20 06:40:23.500799 2026] [security2:error] [pid 983757:tid 984000] [client 50.116.65.227:26254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XN3KwMdFW9UVnNBSjswAAAXk"]
[Mon Jul 20 06:40:23.661616 2026] [security2:error] [pid 983757:tid 983927] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XN3KwMdFW9UVnNBSjrgAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:23.680222 2026] [security2:error] [pid 983757:tid 983898] [client 57.141.18.63:51770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XNXKwMdFW9UVnNBSjbwABExQ"]
[Mon Jul 20 06:40:23.781055 2026] [security2:error] [pid 983757:tid 983935] [client 103.125.179.95:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XN3KwMdFW9UVnNBSjxQAAATg"]
[Mon Jul 20 06:40:23.782897 2026] [security2:error] [pid 983757:tid 983935] [client 103.125.179.95:56189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XN3KwMdFW9UVnNBSjxQAAATg"]
[Mon Jul 20 06:40:23.838176 2026] [security2:error] [pid 983757:tid 983886] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XN3KwMdFW9UVnNBSjxgABL34"]
[Mon Jul 20 06:40:23.838331 2026] [security2:error] [pid 983757:tid 983926] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XN3KwMdFW9UVnNBSjxgABL34"]
[Mon Jul 20 06:40:23.865780 2026] [security2:error] [pid 983757:tid 983955] [client 136.144.35.253:59195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XN3KwMdFW9UVnNBSjyAAAAUw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:23.942641 2026] [security2:error] [pid 983757:tid 983940] [client 4.194.217.15:2019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/size.php"] [unique_id "al4XN3KwMdFW9UVnNBSjzAAAAT0"]
[Mon Jul 20 06:40:23.962898 2026] [security2:error] [pid 983757:tid 984011] [client 34.73.38.214:53163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/xmlrpc.php"] [unique_id "al4XN3KwMdFW9UVnNBSj0gAAAYQ"]
[Mon Jul 20 06:40:24.292732 2026] [security2:error] [pid 983757:tid 983902] [client 57.141.18.94:58988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XNnKwMdFW9UVnNBSjfgABFwU"]
[Mon Jul 20 06:40:24.329228 2026] [security2:error] [pid 966386:tid 966624] [client 173.239.240.96:30459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XODrLBqY1mBmWu_YZWwAAAD4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:24.353567 2026] [security2:error] [pid 966386:tid 966599] [client 216.73.217.138:61769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XODrLBqY1mBmWu_YZWgAAJXk"]
[Mon Jul 20 06:40:24.400170 2026] [security2:error] [pid 983757:tid 983975] [client 152.58.191.29:53055] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XOHKwMdFW9UVnNBSj4wAAAWA"]
[Mon Jul 20 06:40:24.400282 2026] [security2:error] [pid 983757:tid 983975] [client 152.58.191.29:53055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XOHKwMdFW9UVnNBSj4wAAAWA"]
[Mon Jul 20 06:40:24.477539 2026] [security2:error] [pid 983757:tid 983973] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XOHKwMdFW9UVnNBSj5QAAAV4"]
[Mon Jul 20 06:40:24.483234 2026] [security2:error] [pid 983757:tid 983941] [client 4.194.217.15:1355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sm.php"] [unique_id "al4XOHKwMdFW9UVnNBSj6wAAAT4"]
[Mon Jul 20 06:40:24.570565 2026] [security2:error] [pid 966386:tid 966650] [client 14.224.227.113:54561] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XODrLBqY1mBmWu_YZYgAAAFg"]
[Mon Jul 20 06:40:24.597582 2026] [security2:error] [pid 966386:tid 966561] [client 216.73.217.138:61769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XODrLBqY1mBmWu_YZYAAAAWw"]
[Mon Jul 20 06:40:24.644701 2026] [security2:error] [pid 983757:tid 983895] [client 44.195.145.102:7375] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/priligy-cost-in-singapore-772a.pdf"] [unique_id "al4XOHKwMdFW9UVnNBSj8wAAARA"]
[Mon Jul 20 06:40:24.647095 2026] [security2:error] [pid 983757:tid 983894] [client 57.141.18.55:52478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XNnKwMdFW9UVnNBSjkgABD0c"]
[Mon Jul 20 06:40:24.684378 2026] [security2:error] [pid 966386:tid 966634] [client 187.108.85.186:55657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XODrLBqY1mBmWu_YZawAAAEg"]
[Mon Jul 20 06:40:24.684488 2026] [security2:error] [pid 966386:tid 966634] [client 187.108.85.186:55657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XODrLBqY1mBmWu_YZawAAAEg"]
[Mon Jul 20 06:40:24.781366 2026] [security2:error] [pid 966386:tid 966611] [client 136.144.35.249:61255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XODrLBqY1mBmWu_YZbQAAADE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:24.834182 2026] [security2:error] [pid 983757:tid 983934] [client 104.234.53.92:23959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XOHKwMdFW9UVnNBSj_QAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:24.881472 2026] [security2:error] [pid 983757:tid 983899] [client 14.225.17.146:59146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4XOHKwMdFW9UVnNBSj_AAAARQ"], referer: http://wathenbartlett.co.uk/oldsite
[Mon Jul 20 06:40:24.993811 2026] [security2:error] [pid 983757:tid 983952] [client 77.110.127.138:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4XOHKwMdFW9UVnNBSkAAAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:25.033464 2026] [security2:error] [pid 983757:tid 983908] [client 4.194.217.15:2020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sql.php"] [unique_id "al4XOXKwMdFW9UVnNBSkAwAAAR0"]
[Mon Jul 20 06:40:25.054826 2026] [security2:error] [pid 983757:tid 983937] [client 34.73.38.214:56953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XOXKwMdFW9UVnNBSkBAAAATo"]
[Mon Jul 20 06:40:25.257330 2026] [security2:error] [pid 983757:tid 983967] [client 173.239.240.100:38931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XOXKwMdFW9UVnNBSkFAAAAVg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:25.350831 2026] [security2:error] [pid 983757:tid 984011] [client 103.238.106.162:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XOXKwMdFW9UVnNBSkFgAAAYQ"]
[Mon Jul 20 06:40:25.351009 2026] [security2:error] [pid 983757:tid 984011] [client 103.238.106.162:61034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XOXKwMdFW9UVnNBSkFgAAAYQ"]
[Mon Jul 20 06:40:25.492201 2026] [security2:error] [pid 966386:tid 966648] [client 14.225.17.146:54786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4XODrLBqY1mBmWu_YZcQAAAFY"], referer: http://onewingpictures.com/oldsite
[Mon Jul 20 06:40:25.597134 2026] [security2:error] [pid 983757:tid 983915] [client 4.194.217.15:1356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/ss.php"] [unique_id "al4XOXKwMdFW9UVnNBSkJAAAASQ"]
[Mon Jul 20 06:40:25.633162 2026] [security2:error] [pid 983757:tid 983898] [client 104.234.53.89:61683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XOXKwMdFW9UVnNBSkKAAAARM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:25.681623 2026] [security2:error] [pid 983757:tid 983892] [client 57.141.18.58:57286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XN3KwMdFW9UVnNBSjtAABDRI"]
[Mon Jul 20 06:40:25.721706 2026] [security2:error] [pid 983757:tid 983993] [client 136.144.35.248:31181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XOXKwMdFW9UVnNBSkKgAAAXI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:25.755501 2026] [security2:error] [pid 966386:tid 966670] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XOTrLBqY1mBmWu_YZgQAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:25.874278 2026] [security2:error] [pid 983757:tid 983975] [client 14.225.17.146:59514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4XOXKwMdFW9UVnNBSkMgAAAWA"], referer: https://wathenbartlett.co.uk/oldsite
[Mon Jul 20 06:40:26.138230 2026] [security2:error] [pid 983757:tid 983992] [client 4.194.217.15:1461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/stats.php"] [unique_id "al4XOnKwMdFW9UVnNBSkRwAAAXE"]
[Mon Jul 20 06:40:26.186870 2026] [security2:error] [pid 966386:tid 966624] [client 136.144.35.243:22871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XOjrLBqY1mBmWu_YZnQAAAD4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:26.294171 2026] [security2:error] [pid 966386:tid 966607] [client 57.141.18.119:31920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XODrLBqY1mBmWu_YZTgAALRc"]
[Mon Jul 20 06:40:26.309051 2026] [security2:error] [pid 966386:tid 966650] [client 104.234.53.87:41125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XOjrLBqY1mBmWu_YZoQAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:26.640433 2026] [security2:error] [pid 983757:tid 983911] [client 173.239.240.90:39965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XOnKwMdFW9UVnNBSkYwAAASA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:26.689623 2026] [security2:error] [pid 983757:tid 983929] [client 4.194.217.15:7426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/sump1.php"] [unique_id "al4XOnKwMdFW9UVnNBSkaAAAATI"]
[Mon Jul 20 06:40:26.743245 2026] [security2:error] [pid 966386:tid 966611] [client 197.186.66.42:50388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XOjrLBqY1mBmWu_YZqAAAADE"]
[Mon Jul 20 06:40:26.743825 2026] [security2:error] [pid 966386:tid 966611] [client 197.186.66.42:50388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XOjrLBqY1mBmWu_YZqAAAADE"]
[Mon Jul 20 06:40:26.815904 2026] [security2:error] [pid 983757:tid 983994] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XOnKwMdFW9UVnNBSkWgAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:26.987960 2026] [security2:error] [pid 983757:tid 983891] [client 57.141.18.53:20818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XOHKwMdFW9UVnNBSj-AABDHE"]
[Mon Jul 20 06:40:27.064419 2026] [security2:error] [pid 966386:tid 966627] [client 50.116.65.227:26294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4XOjrLBqY1mBmWu_YZpQAAAEE"]
[Mon Jul 20 06:40:27.084500 2026] [security2:error] [pid 966386:tid 966672] [client 223.185.13.213:26689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XOzrLBqY1mBmWu_YZswAAAGs"]
[Mon Jul 20 06:40:27.084630 2026] [security2:error] [pid 966386:tid 966672] [client 223.185.13.213:26689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XOzrLBqY1mBmWu_YZswAAAGs"]
[Mon Jul 20 06:40:27.087857 2026] [security2:error] [pid 966386:tid 966665] [client 34.73.38.214:57347] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XOzrLBqY1mBmWu_YZtAAAAGY"]
[Mon Jul 20 06:40:27.106335 2026] [security2:error] [pid 983757:tid 983844] [remote 81.173.115.7:46726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4XO3KwMdFW9UVnNBSkgAABXVQ"]
[Mon Jul 20 06:40:27.116449 2026] [security2:error] [pid 983757:tid 983977] [client 136.144.35.248:48447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XO3KwMdFW9UVnNBSkggAAAWI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:27.232927 2026] [security2:error] [pid 983757:tid 983976] [client 4.194.217.15:1380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/system.php"] [unique_id "al4XO3KwMdFW9UVnNBSkiwAAAWE"]
[Mon Jul 20 06:40:27.319727 2026] [security2:error] [pid 983757:tid 983762] [remote 81.173.115.7:46726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4XO3KwMdFW9UVnNBSkkAABTAI"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:40:27.363016 2026] [security2:error] [pid 983757:tid 983974] [client 110.249.201.16:60048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4XO3KwMdFW9UVnNBSklAAAAV8"]
[Mon Jul 20 06:40:27.429374 2026] [security2:error] [pid 983757:tid 983979] [client 217.142.18.172:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XO3KwMdFW9UVnNBSklQAAAWQ"]
[Mon Jul 20 06:40:27.429478 2026] [security2:error] [pid 983757:tid 983979] [client 217.142.18.172:62866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XO3KwMdFW9UVnNBSklQAAAWQ"]
[Mon Jul 20 06:40:27.447150 2026] [security2:error] [pid 983757:tid 983950] [client 57.141.18.96:53686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XOXKwMdFW9UVnNBSkDwABRzY"]
[Mon Jul 20 06:40:27.479067 2026] [security2:error] [pid 983757:tid 983980] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XO3KwMdFW9UVnNBSkgQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:27.586401 2026] [security2:error] [pid 983757:tid 983970] [client 173.239.240.101:22017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XO3KwMdFW9UVnNBSkmAAAAVs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:27.659649 2026] [security2:error] [pid 966386:tid 966613] [client 50.116.65.227:26302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4XOzrLBqY1mBmWu_YZsgAAADM"]
[Mon Jul 20 06:40:27.703591 2026] [security2:error] [pid 983757:tid 983776] [remote 57.141.18.34:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4XO3KwMdFW9UVnNBSkmwABSxA"]
[Mon Jul 20 06:40:27.831025 2026] [security2:error] [pid 983757:tid 983905] [client 4.194.217.15:1361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4XO3KwMdFW9UVnNBSkogAAARo"]
[Mon Jul 20 06:40:28.019495 2026] [security2:error] [pid 966386:tid 966649] [client 57.141.18.99:46020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XOTrLBqY1mBmWu_YZkgAAVyA"]
[Mon Jul 20 06:40:28.045640 2026] [security2:error] [pid 966386:tid 966632] [client 173.239.240.93:63759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XPDrLBqY1mBmWu_YZ0QAAAEY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:28.096690 2026] [security2:error] [pid 983757:tid 983944] [client 14.225.17.146:56207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4XPHKwMdFW9UVnNBSkqgAAAUE"], referer: http://iagdevelopments.com/oldsite
[Mon Jul 20 06:40:28.183994 2026] [security2:error] [pid 983757:tid 983915] [client 14.225.17.146:50155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4XOnKwMdFW9UVnNBSkawAAASQ"], referer: http://sarahsnyder.net/oldsite
[Mon Jul 20 06:40:28.226773 2026] [security2:error] [pid 983757:tid 983929] [client 34.73.38.214:57534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XPHKwMdFW9UVnNBSkvwAAATI"]
[Mon Jul 20 06:40:28.234209 2026] [security2:error] [pid 966386:tid 966585] [client 57.141.18.112:29506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XOjrLBqY1mBmWu_YZmgAAF2M"]
[Mon Jul 20 06:40:28.296802 2026] [security2:error] [pid 966386:tid 966644] [client 18.215.49.176:34699] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4XPDrLBqY1mBmWu_YZ2gAAAFI"]
[Mon Jul 20 06:40:28.400405 2026] [security2:error] [pid 983757:tid 983981] [client 4.194.217.15:1040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4XPHKwMdFW9UVnNBSkywAAAWY"]
[Mon Jul 20 06:40:28.421376 2026] [security2:error] [pid 983757:tid 983961] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XPHKwMdFW9UVnNBSkrwAAAVI"]
[Mon Jul 20 06:40:28.511353 2026] [security2:error] [pid 983757:tid 983909] [client 136.144.35.250:51703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XPHKwMdFW9UVnNBSk0QAAAR4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:28.761418 2026] [security2:error] [pid 983757:tid 983922] [client 77.110.127.138:52333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4XPHKwMdFW9UVnNBSk2gAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:28.963221 2026] [security2:error] [pid 966386:tid 966682] [client 4.194.217.15:1085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/system_log.php"] [unique_id "al4XPDrLBqY1mBmWu_YZ8QAAAHU"]
[Mon Jul 20 06:40:28.965301 2026] [security2:error] [pid 983757:tid 983992] [client 173.239.240.96:64641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XPHKwMdFW9UVnNBSk7gAAAXE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:29.005441 2026] [security2:error] [pid 983757:tid 983935] [client 104.234.53.48:65041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XPXKwMdFW9UVnNBSk8wAAATg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:29.019363 2026] [security2:error] [pid 983757:tid 983975] [client 39.48.81.23:57752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XPXKwMdFW9UVnNBSk9QAAAWA"]
[Mon Jul 20 06:40:29.020366 2026] [security2:error] [pid 983757:tid 983975] [client 39.48.81.23:57752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XPXKwMdFW9UVnNBSk9QAAAWA"]
[Mon Jul 20 06:40:29.023356 2026] [security2:error] [pid 966386:tid 966648] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XPDrLBqY1mBmWu_YZ6gAAAFY"]
[Mon Jul 20 06:40:29.025590 2026] [security2:error] [pid 966386:tid 966676] [client 14.225.17.146:52723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4XPDrLBqY1mBmWu_YZ8AAAAG8"], referer: https://iagdevelopments.com/oldsite
[Mon Jul 20 06:40:29.200792 2026] [security2:error] [pid 983757:tid 983936] [client 14.225.17.146:64307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4XPXKwMdFW9UVnNBSk-gAAATk"], referer: https://sarahsnyder.net/oldsite
[Mon Jul 20 06:40:29.259328 2026] [autoindex:error] [pid 983757:tid 983902] [client 205.210.31.34:0] AH01276: Cannot serve directory /home3/lnltfcmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://lnl.tfc.mybluehost.me/
[Mon Jul 20 06:40:29.434602 2026] [security2:error] [pid 966386:tid 966677] [client 173.239.240.32:64635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XPTrLBqY1mBmWu_YaCQAAAHA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:29.559330 2026] [security2:error] [pid 966386:tid 966643] [client 4.194.217.15:7425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/t.php"] [unique_id "al4XPTrLBqY1mBmWu_YaDQAAAFE"]
[Mon Jul 20 06:40:29.583137 2026] [security2:error] [pid 983757:tid 983914] [client 57.141.18.33:49282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XO3KwMdFW9UVnNBSklwABI3Q"]
[Mon Jul 20 06:40:29.877540 2026] [security2:error] [pid 966386:tid 966626] [client 34.73.38.214:62222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XPTrLBqY1mBmWu_YaHAAAAEA"]
[Mon Jul 20 06:40:29.906608 2026] [security2:error] [pid 983757:tid 983916] [client 136.144.35.252:59929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XPXKwMdFW9UVnNBSlHwAAASU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:29.974437 2026] [security2:error] [pid 983757:tid 983943] [client 120.53.224.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4XPXKwMdFW9UVnNBSlEgABQC0"]
[Mon Jul 20 06:40:30.019292 2026] [security2:error] [pid 966386:tid 966670] [client 13.74.155.112:7236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XPjrLBqY1mBmWu_YaIgAAAGk"]
[Mon Jul 20 06:40:30.092450 2026] [security2:error] [pid 966386:tid 966569] [client 57.141.18.50:60920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XPDrLBqY1mBmWu_YZ0gAAB0Q"]
[Mon Jul 20 06:40:30.107200 2026] [security2:error] [pid 983757:tid 983959] [client 4.194.217.15:1462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/term.php"] [unique_id "al4XPnKwMdFW9UVnNBSlIwAAAVA"]
[Mon Jul 20 06:40:30.154153 2026] [security2:error] [pid 966386:tid 966648] [client 13.74.155.112:7236] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XPjrLBqY1mBmWu_YaJwAAAFY"]
[Mon Jul 20 06:40:30.296768 2026] [security2:error] [pid 966386:tid 966587] [client 52.109.76.144:13428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XPjrLBqY1mBmWu_YaKwAAABk"]
[Mon Jul 20 06:40:30.353758 2026] [security2:error] [pid 983757:tid 983934] [client 66.249.90.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XPnKwMdFW9UVnNBSlJgAAATc"]
[Mon Jul 20 06:40:30.414111 2026] [security2:error] [pid 966386:tid 966621] [client 173.239.240.31:54023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XPjrLBqY1mBmWu_YaMgAAADs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:30.436643 2026] [security2:error] [pid 966386:tid 966566] [client 52.109.76.144:13428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XPjrLBqY1mBmWu_YaMwAAAAQ"]
[Mon Jul 20 06:40:30.681738 2026] [security2:error] [pid 966386:tid 966688] [client 4.194.217.15:1435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/test.php"] [unique_id "al4XPjrLBqY1mBmWu_YaOQAAAHs"]
[Mon Jul 20 06:40:30.792520 2026] [security2:error] [pid 966386:tid 966641] [client 14.225.17.146:52611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4XPjrLBqY1mBmWu_YaKgAAAE8"]
[Mon Jul 20 06:40:30.875322 2026] [security2:error] [pid 983757:tid 983964] [client 136.144.35.252:29939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XPnKwMdFW9UVnNBSlUgAAAVU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:30.995962 2026] [security2:error] [pid 983757:tid 983939] [client 171.61.165.146:14842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XPnKwMdFW9UVnNBSlVwAAATw"]
[Mon Jul 20 06:40:31.000708 2026] [security2:error] [pid 983757:tid 983939] [client 171.61.165.146:14842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XPnKwMdFW9UVnNBSlVwAAATw"]
[Mon Jul 20 06:40:31.243526 2026] [security2:error] [pid 966386:tid 966655] [client 4.194.217.15:9225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/test1.php"] [unique_id "al4XPzrLBqY1mBmWu_YaSwAAAF0"]
[Mon Jul 20 06:40:31.350630 2026] [security2:error] [pid 966386:tid 966683] [client 136.144.35.250:41573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XPzrLBqY1mBmWu_YaTQAAAHY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:31.651645 2026] [security2:error] [pid 983757:tid 983890] [client 106.219.188.178:25744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XP3KwMdFW9UVnNBSlbQAAAQs"]
[Mon Jul 20 06:40:31.654264 2026] [security2:error] [pid 983757:tid 983890] [client 106.219.188.178:25744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XP3KwMdFW9UVnNBSlbQAAAQs"]
[Mon Jul 20 06:40:31.663281 2026] [security2:error] [pid 983757:tid 984006] [client 104.234.53.69:32353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XP3KwMdFW9UVnNBSlaQAAAX8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:31.794207 2026] [security2:error] [pid 966386:tid 966645] [client 4.194.217.15:12598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/tfm.php"] [unique_id "al4XPzrLBqY1mBmWu_YaZQAAAFM"]
[Mon Jul 20 06:40:31.800050 2026] [security2:error] [pid 983757:tid 983958] [client 173.239.240.99:57157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XP3KwMdFW9UVnNBSldgAAAU8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:32.284450 2026] [security2:error] [pid 966386:tid 966668] [client 34.73.38.214:53044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XQDrLBqY1mBmWu_YadwAAAGg"]
[Mon Jul 20 06:40:32.287760 2026] [security2:error] [pid 983757:tid 983984] [client 173.239.240.92:58921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XQHKwMdFW9UVnNBSlkwAAAWk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:32.302639 2026] [security2:error] [pid 966386:tid 966475] [remote 95.217.78.234:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XQDrLBqY1mBmWu_YaeAAAAC4"]
[Mon Jul 20 06:40:32.352884 2026] [security2:error] [pid 966386:tid 966561] [client 4.194.217.15:12591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/thebe.php"] [unique_id "al4XQDrLBqY1mBmWu_YaegAAAAE"]
[Mon Jul 20 06:40:32.491547 2026] [security2:error] [pid 983757:tid 983972] [client 104.234.53.69:32353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XQHKwMdFW9UVnNBSlmgAAAV0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:32.545031 2026] [security2:error] [pid 966386:tid 966540] [remote 95.217.78.234:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XQDrLBqY1mBmWu_YafwAANG4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:40:32.647605 2026] [security2:error] [pid 983757:tid 983952] [client 77.110.127.138:52377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XQHKwMdFW9UVnNBSlqgAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:32.757626 2026] [security2:error] [pid 983757:tid 983986] [client 173.239.240.96:56115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XQHKwMdFW9UVnNBSltAAAAWs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:32.783696 2026] [security2:error] [pid 966386:tid 966608] [client 57.141.18.39:45383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XPjrLBqY1mBmWu_YaKQAALls"]
[Mon Jul 20 06:40:32.844755 2026] [security2:error] [pid 983757:tid 983996] [client 57.141.18.3:54906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XPnKwMdFW9UVnNBSlKQABdVY"]
[Mon Jul 20 06:40:32.890348 2026] [security2:error] [pid 983757:tid 983969] [client 104.210.140.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4XQHKwMdFW9UVnNBSlpQAAAVo"]
[Mon Jul 20 06:40:32.910930 2026] [security2:error] [pid 983757:tid 983810] [remote 8.217.108.67:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XQHKwMdFW9UVnNBSlvgABETI"]
[Mon Jul 20 06:40:32.923701 2026] [security2:error] [pid 966386:tid 966631] [client 4.194.217.15:1847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/themes.php"] [unique_id "al4XQDrLBqY1mBmWu_YahwAAAEU"]
[Mon Jul 20 06:40:32.935389 2026] [security2:error] [pid 983757:tid 983942] [client 14.225.17.146:52856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4XP3KwMdFW9UVnNBSlYgAAAT8"], referer: http://bigwormfishing.com/oldsite
[Mon Jul 20 06:40:33.101772 2026] [security2:error] [pid 983757:tid 983906] [client 112.208.70.94:45954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XQXKwMdFW9UVnNBSlyQAAARs"]
[Mon Jul 20 06:40:33.101890 2026] [security2:error] [pid 983757:tid 983906] [client 112.208.70.94:45954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XQXKwMdFW9UVnNBSlyQAAARs"]
[Mon Jul 20 06:40:33.245562 2026] [security2:error] [pid 983757:tid 983901] [client 173.239.240.98:33075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XQXKwMdFW9UVnNBSl0wAAARY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:33.388047 2026] [security2:error] [pid 966386:tid 966579] [client 34.73.38.214:55297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XQTrLBqY1mBmWu_YalgAAABE"]
[Mon Jul 20 06:40:33.464223 2026] [security2:error] [pid 983757:tid 983953] [client 4.194.217.15:12563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/tiny.php"] [unique_id "al4XQXKwMdFW9UVnNBSl6AAAAUo"]
[Mon Jul 20 06:40:33.544650 2026] [security2:error] [pid 983757:tid 983909] [client 104.234.53.89:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XQXKwMdFW9UVnNBSl6wAAAR4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:33.613799 2026] [security2:error] [pid 983757:tid 984009] [client 57.141.18.22:57168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XP3KwMdFW9UVnNBSlXgABghQ"]
[Mon Jul 20 06:40:33.619788 2026] [security2:error] [pid 983757:tid 983782] [remote 8.217.108.67:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XQXKwMdFW9UVnNBSl8gABWRY"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:40:33.696838 2026] [security2:error] [pid 966386:tid 966578] [client 50.116.65.227:40992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XQTrLBqY1mBmWu_YaoAAAABA"]
[Mon Jul 20 06:40:33.706187 2026] [security2:error] [pid 966386:tid 966566] [client 50.116.65.227:41004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XQTrLBqY1mBmWu_YaoQAAAAQ"]
[Mon Jul 20 06:40:33.739256 2026] [security2:error] [pid 983757:tid 983931] [client 173.239.240.31:29285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XQXKwMdFW9UVnNBSl_wAAATQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:33.774453 2026] [security2:error] [pid 983757:tid 983927] [client 57.141.18.105:46164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XP3KwMdFW9UVnNBSlZgABMH4"]
[Mon Jul 20 06:40:33.811428 2026] [security2:error] [pid 966386:tid 966626] [client 57.141.18.114:64538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XPzrLBqY1mBmWu_YaUAAAQEk"]
[Mon Jul 20 06:40:34.033378 2026] [security2:error] [pid 983757:tid 984014] [client 4.194.217.15:7475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/tmp/byp.php"] [unique_id "al4XQnKwMdFW9UVnNBSmFgAAAYc"]
[Mon Jul 20 06:40:34.040995 2026] [autoindex:error] [pid 983757:tid 983955] [client 199.45.155.87:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:40:34.045540 2026] [security2:error] [pid 983757:tid 983902] [client 14.225.17.146:54454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4XQXKwMdFW9UVnNBSmBwAAARc"], referer: https://bigwormfishing.com/oldsite
[Mon Jul 20 06:40:34.190697 2026] [security2:error] [pid 983757:tid 983898] [client 173.239.240.94:45309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XQnKwMdFW9UVnNBSmIQAAARM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:34.297901 2026] [security2:error] [pid 983757:tid 983932] [client 13.233.207.33:53504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XQnKwMdFW9UVnNBSmHgAAATU"]
[Mon Jul 20 06:40:34.559592 2026] [security2:error] [pid 966386:tid 966610] [client 57.141.18.121:44118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQDrLBqY1mBmWu_YadQAAMEE"]
[Mon Jul 20 06:40:34.577165 2026] [security2:error] [pid 983757:tid 983811] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XQnKwMdFW9UVnNBSmMgABWDM"]
[Mon Jul 20 06:40:34.577341 2026] [security2:error] [pid 983757:tid 983967] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XQnKwMdFW9UVnNBSmMgABWDM"]
[Mon Jul 20 06:40:34.672520 2026] [security2:error] [pid 983757:tid 983977] [client 136.144.35.243:36923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XQnKwMdFW9UVnNBSmOgAAAWI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:34.744018 2026] [security2:error] [pid 983757:tid 984008] [client 34.73.38.214:58958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XQnKwMdFW9UVnNBSmPgAAAYE"]
[Mon Jul 20 06:40:34.840466 2026] [security2:error] [pid 966386:tid 966656] [client 103.125.179.95:56699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XQjrLBqY1mBmWu_YauAAAAF4"]
[Mon Jul 20 06:40:34.840589 2026] [security2:error] [pid 966386:tid 966656] [client 103.125.179.95:56699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XQjrLBqY1mBmWu_YauAAAAF4"]
[Mon Jul 20 06:40:35.051925 2026] [security2:error] [pid 983757:tid 983931] [client 152.58.191.29:53457] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmTAAAATQ"]
[Mon Jul 20 06:40:35.052122 2026] [security2:error] [pid 983757:tid 983931] [client 152.58.191.29:53457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmTAAAATQ"]
[Mon Jul 20 06:40:35.071595 2026] [security2:error] [pid 966386:tid 966675] [client 57.141.18.7:51236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQDrLBqY1mBmWu_YahAAAbmo"]
[Mon Jul 20 06:40:35.078824 2026] [security2:error] [pid 983757:tid 983948] [client 57.141.18.103:45632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQHKwMdFW9UVnNBSluAABRRg"]
[Mon Jul 20 06:40:35.092627 2026] [security2:error] [pid 983757:tid 983854] [remote 45.90.123.233:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmTQABQ14"]
[Mon Jul 20 06:40:35.150598 2026] [security2:error] [pid 983757:tid 983953] [client 173.239.240.97:34503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmVQAAAUo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:35.163795 2026] [security2:error] [pid 966386:tid 966551] [remote 81.173.115.7:57476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4XQzrLBqY1mBmWu_YaxAAALnk"]
[Mon Jul 20 06:40:35.163959 2026] [security2:error] [pid 966386:tid 966608] [client 81.173.115.7:57476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4XQzrLBqY1mBmWu_YaxAAALnk"]
[Mon Jul 20 06:40:35.235623 2026] [security2:error] [pid 983757:tid 983826] [remote 51.195.39.149:25618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "website-4dafb119.villa-m-medjugorje.com"] [uri "/"] [unique_id "al4XQ3KwMdFW9UVnNBSmYAABg0I"]
[Mon Jul 20 06:40:35.298082 2026] [security2:error] [pid 983757:tid 983901] [client 14.225.17.146:50531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmVAAAARY"], referer: http://fkconstructionfunding.com/oldsite
[Mon Jul 20 06:40:35.317200 2026] [security2:error] [pid 983757:tid 983871] [remote 45.90.123.233:44764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmZQABUW8"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:40:35.338214 2026] [security2:error] [pid 983757:tid 983899] [client 187.108.85.186:56201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmZgAAARQ"]
[Mon Jul 20 06:40:35.338327 2026] [security2:error] [pid 983757:tid 983899] [client 187.108.85.186:56201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmZgAAARQ"]
[Mon Jul 20 06:40:35.532422 2026] [security2:error] [pid 983757:tid 983912] [client 14.225.17.146:60769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4XQnKwMdFW9UVnNBSmMAAAASE"], referer: http://headachescarpaltunnelfibromyalgia.com/oldsite
[Mon Jul 20 06:40:35.579509 2026] [security2:error] [pid 983757:tid 983934] [client 104.234.53.70:62971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmeAAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:35.636062 2026] [security2:error] [pid 966386:tid 966665] [client 136.144.35.251:39375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XQzrLBqY1mBmWu_Ya1QAAAGY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:35.715421 2026] [security2:error] [pid 983757:tid 983920] [client 43.205.139.3:45722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmfAAAASk"]
[Mon Jul 20 06:40:35.715524 2026] [security2:error] [pid 983757:tid 983920] [client 43.205.139.3:45722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmfAAAASk"]
[Mon Jul 20 06:40:35.812293 2026] [security2:error] [pid 983757:tid 984006] [client 57.141.18.53:20962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQXKwMdFW9UVnNBSl9AABf3E"]
[Mon Jul 20 06:40:35.819993 2026] [security2:error] [pid 983757:tid 983827] [remote 5.161.225.162:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmgwABKkM"]
[Mon Jul 20 06:40:35.873626 2026] [security2:error] [pid 983757:tid 983896] [client 34.73.38.214:58529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XQ3KwMdFW9UVnNBSmhwAAARE"]
[Mon Jul 20 06:40:36.002943 2026] [security2:error] [pid 983757:tid 983957] [client 103.238.106.162:42651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XRHKwMdFW9UVnNBSmjAAAAU4"]
[Mon Jul 20 06:40:36.003062 2026] [security2:error] [pid 983757:tid 983957] [client 103.238.106.162:42651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XRHKwMdFW9UVnNBSmjAAAAU4"]
[Mon Jul 20 06:40:36.070955 2026] [security2:error] [pid 983757:tid 983947] [client 14.225.17.146:50547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4XQnKwMdFW9UVnNBSmLgAAAUQ"], referer: https://north-woods-engineering.com/oldsite
[Mon Jul 20 06:40:36.086875 2026] [security2:error] [pid 983757:tid 984000] [client 173.239.240.98:62049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XRHKwMdFW9UVnNBSmkQAAAXk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:36.276460 2026] [security2:error] [pid 983757:tid 983970] [client 62.150.67.110:23147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmegAAAVs"]
[Mon Jul 20 06:40:36.426179 2026] [security2:error] [pid 983757:tid 983982] [client 57.141.18.3:54914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQnKwMdFW9UVnNBSmIwABZz8"]
[Mon Jul 20 06:40:36.458660 2026] [security2:error] [pid 983757:tid 983805] [remote 57.141.18.105:48210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5735655"] [unique_id "al4XRHKwMdFW9UVnNBSmqwABQS0"]
[Mon Jul 20 06:40:36.467291 2026] [security2:error] [pid 983757:tid 983905] [client 77.110.127.138:52402] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XRHKwMdFW9UVnNBSmrAAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:36.484535 2026] [security2:error] [pid 966386:tid 966607] [client 14.225.17.146:60455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XRDrLBqY1mBmWu_Ya6gAAAC0"], referer: https://fkconstructionfunding.com/oldsite
[Mon Jul 20 06:40:36.565850 2026] [security2:error] [pid 966386:tid 966604] [client 34.73.38.214:60803] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XRDrLBqY1mBmWu_Ya8wAAACo"]
[Mon Jul 20 06:40:36.583300 2026] [security2:error] [pid 966386:tid 966603] [client 173.239.240.31:20229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XRDrLBqY1mBmWu_Ya9AAAACk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:36.585997 2026] [security2:error] [pid 983757:tid 983904] [client 66.249.79.5:62477] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "archivetest.earle-brown.org"] [uri "/robots.txt"] [unique_id "al4XRHKwMdFW9UVnNBSmtgAAARk"]
[Mon Jul 20 06:40:36.929759 2026] [security2:error] [pid 983757:tid 983954] [client 77.110.127.138:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4XRHKwMdFW9UVnNBSmzQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:37.052799 2026] [security2:error] [pid 983757:tid 983891] [client 57.141.18.53:20972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQnKwMdFW9UVnNBSmQgABDBs"]
[Mon Jul 20 06:40:37.055383 2026] [security2:error] [pid 983757:tid 983977] [client 136.144.35.244:53709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XRXKwMdFW9UVnNBSm2QAAAWI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:37.136094 2026] [security2:error] [pid 966386:tid 966611] [client 213.5.192.51:62260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4XRTrLBqY1mBmWu_Ya_wAAADE"], referer: https://new-menus.com
[Mon Jul 20 06:40:37.156273 2026] [security2:error] [pid 966386:tid 966687] [client 57.141.18.71:45130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQzrLBqY1mBmWu_YawQAAei0"]
[Mon Jul 20 06:40:37.199919 2026] [security2:error] [pid 966386:tid 966554] [remote 188.40.28.4:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4XRTrLBqY1mBmWu_YbBgAAcXw"]
[Mon Jul 20 06:40:37.216061 2026] [security2:error] [pid 983757:tid 984009] [client 57.141.18.5:41870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XQ3KwMdFW9UVnNBSmUQABgkA"]
[Mon Jul 20 06:40:37.301426 2026] [security2:error] [pid 966386:tid 966657] [client 46.110.96.34:7759] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XRTrLBqY1mBmWu_YbDAAAAF8"]
[Mon Jul 20 06:40:37.389889 2026] [security2:error] [pid 966386:tid 966458] [remote 188.40.28.4:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4XRTrLBqY1mBmWu_YbDgAAEB8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:40:37.526158 2026] [security2:error] [pid 966386:tid 966591] [client 173.239.240.91:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XRTrLBqY1mBmWu_YbFwAAAB0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:37.550335 2026] [security2:error] [pid 966386:tid 966685] [client 34.73.38.214:64124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XRTrLBqY1mBmWu_YbGAAAAHg"]
[Mon Jul 20 06:40:37.822184 2026] [security2:error] [pid 966386:tid 966467] [remote 57.141.18.22:35974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5834995"] [unique_id "al4XRTrLBqY1mBmWu_YbIgAAJic"]
[Mon Jul 20 06:40:37.912762 2026] [security2:error] [pid 983757:tid 983994] [client 217.142.18.172:56400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XRXKwMdFW9UVnNBSm-wAAAXM"]
[Mon Jul 20 06:40:37.915857 2026] [security2:error] [pid 983757:tid 983994] [client 217.142.18.172:56400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XRXKwMdFW9UVnNBSm-wAAAXM"]
[Mon Jul 20 06:40:38.051385 2026] [security2:error] [pid 966386:tid 966635] [client 173.239.240.92:32057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XRjrLBqY1mBmWu_YbLgAAAEk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:38.481477 2026] [security2:error] [pid 966386:tid 966586] [client 197.186.66.42:50909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XRjrLBqY1mBmWu_YbOwAAABg"]
[Mon Jul 20 06:40:38.481590 2026] [security2:error] [pid 966386:tid 966586] [client 197.186.66.42:50909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XRjrLBqY1mBmWu_YbOwAAABg"]
[Mon Jul 20 06:40:38.543800 2026] [security2:error] [pid 983757:tid 983993] [client 136.144.35.253:59325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XRnKwMdFW9UVnNBSnHwAAAXI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:38.716804 2026] [security2:error] [pid 983757:tid 983938] [client 104.207.36.196:45617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.36.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XRnKwMdFW9UVnNBSnIwAAATs"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:38.811400 2026] [security2:error] [pid 983757:tid 983770] [remote 5.161.225.162:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4XRnKwMdFW9UVnNBSnKAABago"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 06:40:38.836619 2026] [security2:error] [pid 966386:tid 966627] [client 57.141.18.57:61102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XRDrLBqY1mBmWu_Ya-AAAQUg"]
[Mon Jul 20 06:40:38.975146 2026] [security2:error] [pid 966386:tid 966589] [client 34.73.38.214:63654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XRjrLBqY1mBmWu_YbVwAAABs"]
[Mon Jul 20 06:40:38.981290 2026] [security2:error] [pid 966386:tid 966651] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XRjrLBqY1mBmWu_YbQQAAAFk"]
[Mon Jul 20 06:40:38.999609 2026] [security2:error] [pid 983757:tid 983960] [client 173.239.240.95:37653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XRnKwMdFW9UVnNBSnOgAAAVE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:39.108204 2026] [security2:error] [pid 966386:tid 966429] [remote 8.217.108.67:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4XRzrLBqY1mBmWu_YbWwAAawI"]
[Mon Jul 20 06:40:39.287318 2026] [security2:error] [pid 983757:tid 983949] [client 14.224.227.113:54577] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XR3KwMdFW9UVnNBSnQQAAAUY"]
[Mon Jul 20 06:40:39.288011 2026] [security2:error] [pid 983757:tid 983917] [client 14.225.17.146:53878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4XRnKwMdFW9UVnNBSnLgAAASY"], referer: http://grecruit.online/oldsite
[Mon Jul 20 06:40:39.401048 2026] [security2:error] [pid 983757:tid 983778] [remote 147.50.252.213:46364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSnTQABIBI"]
[Mon Jul 20 06:40:39.451428 2026] [security2:error] [pid 966386:tid 966668] [client 14.225.17.146:50610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4XRzrLBqY1mBmWu_YbYwAAAGg"], referer: http://nextlvlmarketingco.com/oldsite
[Mon Jul 20 06:40:39.529716 2026] [security2:error] [pid 983757:tid 983904] [client 136.144.35.245:42995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSnWgAAARk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:39.537245 2026] [security2:error] [pid 983757:tid 983968] [client 104.234.53.54:29197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSnWQAAAVk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:39.543921 2026] [security2:error] [pid 983757:tid 983889] [client 223.185.13.213:28793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XR3KwMdFW9UVnNBSnXAAAAQo"]
[Mon Jul 20 06:40:39.544847 2026] [security2:error] [pid 983757:tid 983889] [client 223.185.13.213:28793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XR3KwMdFW9UVnNBSnXAAAAQo"]
[Mon Jul 20 06:40:39.597530 2026] [security2:error] [pid 983757:tid 983851] [remote 103.74.121.5:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.121.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSnXQABYVs"]
[Mon Jul 20 06:40:39.682688 2026] [security2:error] [pid 983757:tid 983862] [remote 103.161.172.221:47488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSnZgABe2Y"]
[Mon Jul 20 06:40:39.778115 2026] [security2:error] [pid 966386:tid 966690] [client 14.225.17.146:54077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4XRjrLBqY1mBmWu_YbNgAAAH0"], referer: http://bbwipartnerconference.com/oldsite
[Mon Jul 20 06:40:39.841915 2026] [security2:error] [pid 983757:tid 983836] [remote 194.164.192.228:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSncAABE0w"]
[Mon Jul 20 06:40:39.876911 2026] [security2:error] [pid 983757:tid 983842] [remote 147.50.252.213:46364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4XR3KwMdFW9UVnNBSncgABTFI"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:40:39.885910 2026] [security2:error] [pid 983757:tid 983918] [client 39.48.81.23:58290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XR3KwMdFW9UVnNBSndAAAASc"]
[Mon Jul 20 06:40:39.886065 2026] [security2:error] [pid 983757:tid 983918] [client 39.48.81.23:58290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XR3KwMdFW9UVnNBSndAAAASc"]
[Mon Jul 20 06:40:39.907628 2026] [security2:error] [pid 983757:tid 983972] [client 15.204.80.170:58994] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "genlius.com"] [uri "/"] [unique_id "al4XR3KwMdFW9UVnNBSndQAAAV0"]
[Mon Jul 20 06:40:39.977489 2026] [security2:error] [pid 983757:tid 983928] [client 173.239.240.92:36939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XR3KwMdFW9UVnNBSneQAAATE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:40.001096 2026] [security2:error] [pid 966386:tid 966607] [client 57.141.18.117:55692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XRTrLBqY1mBmWu_YbIwAALSA"]
[Mon Jul 20 06:40:40.005073 2026] [core:alert] [pid 983757:tid 983934] [client 43.133.14.237:54562] /home3/princfv3/public_html/.htaccess: php_value takes two arguments, PHP Value, referer: http://pathwaypuppetproductions.com
[Mon Jul 20 06:40:40.032744 2026] [security2:error] [pid 983757:tid 983795] [remote 194.164.192.228:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4XSHKwMdFW9UVnNBSnewABhiM"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 06:40:40.137982 2026] [security2:error] [pid 983757:tid 983814] [remote 103.74.121.5:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.121.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XSHKwMdFW9UVnNBSnigABVjY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:40:40.138854 2026] [security2:error] [pid 966386:tid 966684] [client 46.110.96.34:7759] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XSDrLBqY1mBmWu_YbdAAAAHc"]
[Mon Jul 20 06:40:40.174743 2026] [security2:error] [pid 983757:tid 983762] [remote 103.161.172.221:47488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4XSHKwMdFW9UVnNBSnjwABDQI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:40:40.246109 2026] [security2:error] [pid 966386:tid 966623] [client 57.141.18.10:64054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XRjrLBqY1mBmWu_YbMAAAPUw"]
[Mon Jul 20 06:40:40.329644 2026] [security2:error] [pid 966386:tid 966657] [client 46.110.96.34:42028] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XSDrLBqY1mBmWu_YbeQAAAF8"]
[Mon Jul 20 06:40:40.496388 2026] [security2:error] [pid 983757:tid 983899] [client 136.144.35.245:26261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XSHKwMdFW9UVnNBSnqwAAARQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:40.689361 2026] [security2:error] [pid 966386:tid 966566] [client 46.110.96.34:7759] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XSDrLBqY1mBmWu_YbgQAAAAQ"]
[Mon Jul 20 06:40:40.698131 2026] [security2:error] [pid 966386:tid 966588] [client 57.141.18.45:55050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XRjrLBqY1mBmWu_YbOQAAGh0"]
[Mon Jul 20 06:40:40.703859 2026] [security2:error] [pid 983757:tid 983997] [client 114.119.132.146:20629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "snctaxgroup.com"] [uri "/forms/"] [unique_id "al4XSHKwMdFW9UVnNBSnuAAAAXY"], referer: https://www.snctaxgroup.com/
[Mon Jul 20 06:40:40.757997 2026] [security2:error] [pid 983757:tid 984000] [client 46.110.96.34:5572] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XSHKwMdFW9UVnNBSnuQAAAXk"]
[Mon Jul 20 06:40:40.773856 2026] [security2:error] [pid 966386:tid 966442] [remote 8.217.108.67:42094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4XSDrLBqY1mBmWu_YbhQAAGQ8"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 06:40:40.873506 2026] [security2:error] [pid 983757:tid 983792] [remote 182.77.62.24:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XSHKwMdFW9UVnNBSnxQABeyA"]
[Mon Jul 20 06:40:40.873730 2026] [security2:error] [pid 983757:tid 984002] [client 182.77.62.24:45448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XSHKwMdFW9UVnNBSnxQABeyA"]
[Mon Jul 20 06:40:40.877457 2026] [security2:error] [pid 983757:tid 983983] [client 34.73.38.214:63573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.aljosour-alarabia.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XSHKwMdFW9UVnNBSnxwAAAWg"]
[Mon Jul 20 06:40:40.883355 2026] [security2:error] [pid 983757:tid 983994] [client 77.110.127.138:52429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XSHKwMdFW9UVnNBSnygAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:40.987070 2026] [security2:error] [pid 983757:tid 983953] [client 136.144.35.249:39343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XSHKwMdFW9UVnNBSn0wAAAUo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:41.097770 2026] [security2:error] [pid 983757:tid 983927] [client 120.28.167.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4XR3KwMdFW9UVnNBSnYwAAATA"]
[Mon Jul 20 06:40:41.114617 2026] [proxy:error] [pid 983757:tid 983974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:41.114675 2026] [proxy_http:error] [pid 983757:tid 983974] [client 34.73.38.214:57453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:41.115502 2026] [proxy:error] [pid 983757:tid 983974] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:41.115542 2026] [proxy_http:error] [pid 983757:tid 983974] [client 34.73.38.214:57453] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:41.156025 2026] [security2:error] [pid 966386:tid 966638] [client 57.141.18.69:49208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XRjrLBqY1mBmWu_YbUQAATBY"]
[Mon Jul 20 06:40:41.197791 2026] [security2:error] [pid 966386:tid 966685] [client 14.225.17.146:54114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4XSDrLBqY1mBmWu_YbiAAAAHg"], referer: http://guidehunting.com/oldsite
[Mon Jul 20 06:40:41.394952 2026] [security2:error] [pid 983757:tid 984013] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XSXKwMdFW9UVnNBSn3QAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:41.473650 2026] [security2:error] [pid 983757:tid 983889] [client 14.225.17.146:53940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4XSXKwMdFW9UVnNBSn2gAAAQo"], referer: http://massagelacey.com/oldsite
[Mon Jul 20 06:40:41.473948 2026] [security2:error] [pid 983757:tid 983936] [client 173.239.240.95:51737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XSXKwMdFW9UVnNBSn9wAAATk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:41.677034 2026] [security2:error] [pid 966386:tid 966637] [client 158.173.89.95:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XSTrLBqY1mBmWu_YbmQAAAEs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:40:41.721842 2026] [security2:error] [pid 983757:tid 983917] [client 171.61.165.146:13976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XSXKwMdFW9UVnNBSoAwAAASY"]
[Mon Jul 20 06:40:41.722965 2026] [security2:error] [pid 983757:tid 983917] [client 171.61.165.146:13976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XSXKwMdFW9UVnNBSoAwAAASY"]
[Mon Jul 20 06:40:41.772639 2026] [security2:error] [pid 983757:tid 983913] [client 77.110.127.138:52436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpUDQTMyhR'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4XSXKwMdFW9UVnNBSoCAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:41.983126 2026] [security2:error] [pid 983757:tid 983977] [client 57.141.18.49:45728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XR3KwMdFW9UVnNBSnbAABYhY"]
[Mon Jul 20 06:40:41.989293 2026] [security2:error] [pid 983757:tid 983997] [client 173.239.240.32:47395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XSXKwMdFW9UVnNBSoGAAAAXY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:41.990800 2026] [security2:error] [pid 983757:tid 983906] [client 57.141.18.7:24332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XR3KwMdFW9UVnNBSnbwABGys"]
[Mon Jul 20 06:40:42.350789 2026] [security2:error] [pid 983757:tid 983966] [client 106.219.188.178:8579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XSnKwMdFW9UVnNBSoJQAAAVc"]
[Mon Jul 20 06:40:42.350921 2026] [security2:error] [pid 983757:tid 983966] [client 106.219.188.178:8579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XSnKwMdFW9UVnNBSoJQAAAVc"]
[Mon Jul 20 06:40:42.368920 2026] [security2:error] [pid 983757:tid 983992] [client 14.225.17.146:54132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4XSHKwMdFW9UVnNBSnzAAAAXE"], referer: http://balticsteelmgmt.com/oldsite
[Mon Jul 20 06:40:42.383571 2026] [security2:error] [pid 966386:tid 966584] [client 14.225.17.146:54014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4XSjrLBqY1mBmWu_YbqgAAABY"], referer: https://guidehunting.com/oldsite
[Mon Jul 20 06:40:42.454157 2026] [security2:error] [pid 983757:tid 983982] [client 173.239.240.100:51941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XSnKwMdFW9UVnNBSoKQAAAWc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:42.675164 2026] [security2:error] [pid 966386:tid 966641] [client 14.225.17.146:53885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4XSTrLBqY1mBmWu_YbigAAAE8"], referer: http://lelandumc.org/oldsite
[Mon Jul 20 06:40:42.701363 2026] [security2:error] [pid 983757:tid 983808] [remote 152.228.213.32:33010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XSnKwMdFW9UVnNBSoMwABRzA"]
[Mon Jul 20 06:40:42.910997 2026] [security2:error] [pid 983757:tid 983951] [client 136.144.35.248:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XSnKwMdFW9UVnNBSoPgAAAUg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:42.923472 2026] [security2:error] [pid 983757:tid 983824] [remote 152.228.213.32:33010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XSnKwMdFW9UVnNBSoPwABVkA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:40:43.227054 2026] [security2:error] [pid 966386:tid 966672] [client 158.173.241.141:28005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4XSTrLBqY1mBmWu_YbkgAAAGs"], referer: http://sesamegreenbeans.com/tag/Japan/
[Mon Jul 20 06:40:43.329155 2026] [proxy:error] [pid 983757:tid 983926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:43.329228 2026] [proxy_http:error] [pid 983757:tid 983926] [client 34.73.38.214:51977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:43.329654 2026] [proxy:error] [pid 983757:tid 983926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:43.329682 2026] [proxy_http:error] [pid 983757:tid 983926] [client 34.73.38.214:51977] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:43.340783 2026] [security2:error] [pid 983757:tid 983929] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XS3KwMdFW9UVnNBSoVgAAATI"]
[Mon Jul 20 06:40:43.367437 2026] [security2:error] [pid 983757:tid 983976] [client 14.225.17.146:49590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4XS3KwMdFW9UVnNBSoTQAAAWE"]
[Mon Jul 20 06:40:43.401168 2026] [security2:error] [pid 983757:tid 983903] [client 136.144.35.246:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XS3KwMdFW9UVnNBSoYAAAARg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:43.530780 2026] [security2:error] [pid 966386:tid 966437] [remote 57.141.18.13:42214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5237967"] [unique_id "al4XSzrLBqY1mBmWu_YbywAAbAo"]
[Mon Jul 20 06:40:43.603731 2026] [security2:error] [pid 983757:tid 983890] [client 57.141.18.110:30174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XSXKwMdFW9UVnNBSn7gABCyE"]
[Mon Jul 20 06:40:43.708473 2026] [security2:error] [pid 983757:tid 983945] [client 112.208.70.94:42376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XS3KwMdFW9UVnNBSocQAAAUI"]
[Mon Jul 20 06:40:43.708576 2026] [security2:error] [pid 983757:tid 983945] [client 112.208.70.94:42376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XS3KwMdFW9UVnNBSocQAAAUI"]
[Mon Jul 20 06:40:43.806848 2026] [security2:error] [pid 966386:tid 966637] [client 50.116.65.227:52560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XSzrLBqY1mBmWu_Yb1AAAAEs"]
[Mon Jul 20 06:40:43.817235 2026] [security2:error] [pid 966386:tid 966576] [client 50.116.65.227:52570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XSzrLBqY1mBmWu_Yb1gAAAA4"]
[Mon Jul 20 06:40:43.864027 2026] [security2:error] [pid 983757:tid 983951] [client 136.144.35.250:64825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XS3KwMdFW9UVnNBSoeAAAAUg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:43.921724 2026] [security2:error] [pid 983757:tid 983936] [client 50.116.65.227:24458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4XS3KwMdFW9UVnNBSoegAAATk"]
[Mon Jul 20 06:40:43.934356 2026] [security2:error] [pid 983757:tid 984006] [client 50.116.65.227:52580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4XS3KwMdFW9UVnNBSoewAAAX8"]
[Mon Jul 20 06:40:43.941506 2026] [security2:error] [pid 966386:tid 966674] [client 104.234.53.93:38757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XSzrLBqY1mBmWu_Yb2AAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:44.081472 2026] [security2:error] [pid 966386:tid 966539] [remote 100.42.189.89:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XTDrLBqY1mBmWu_Yb3wAAZG0"]
[Mon Jul 20 06:40:44.300686 2026] [security2:error] [pid 966386:tid 966480] [remote 100.42.189.89:57122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4XTDrLBqY1mBmWu_Yb5QAAcDI"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:40:44.335605 2026] [security2:error] [pid 983757:tid 983980] [client 136.144.35.245:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XTHKwMdFW9UVnNBSokQAAAWU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:44.548491 2026] [security2:error] [pid 983757:tid 983892] [client 65.111.26.25:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XTHKwMdFW9UVnNBSolgAAAQ0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:40:44.813592 2026] [security2:error] [pid 983757:tid 983907] [client 136.144.35.243:57969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XTHKwMdFW9UVnNBSotAAAARw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:44.864248 2026] [security2:error] [pid 983757:tid 983913] [client 57.141.18.33:29614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XSnKwMdFW9UVnNBSoOAABIlk"]
[Mon Jul 20 06:40:45.041008 2026] [security2:error] [pid 966386:tid 966566] [client 57.141.18.22:21240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XSjrLBqY1mBmWu_YbvgAABGc"]
[Mon Jul 20 06:40:45.099658 2026] [security2:error] [pid 983757:tid 984008] [client 77.110.127.138:52463] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XTXKwMdFW9UVnNBSowAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:45.260991 2026] [security2:error] [pid 983757:tid 983974] [client 136.144.35.246:47249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XTXKwMdFW9UVnNBSozAAAAV8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:45.347889 2026] [security2:error] [pid 966386:tid 966531] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XTTrLBqY1mBmWu_Yb_gAAbGU"]
[Mon Jul 20 06:40:45.348092 2026] [security2:error] [pid 966386:tid 966673] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XTTrLBqY1mBmWu_Yb_gAAbGU"]
[Mon Jul 20 06:40:45.520874 2026] [proxy:error] [pid 983757:tid 983958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:45.520938 2026] [proxy_http:error] [pid 983757:tid 983958] [client 34.73.38.214:49813] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:45.521509 2026] [proxy:error] [pid 983757:tid 983958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:45.521538 2026] [proxy_http:error] [pid 983757:tid 983958] [client 34.73.38.214:49813] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:45.538466 2026] [security2:error] [pid 966386:tid 966601] [client 77.110.127.138:52466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpRNgPDthR'%20OR%20128=(SELECT%20128%20FROM%20PG_SLEEP(15))--"] [unique_id "al4XTTrLBqY1mBmWu_YcBQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:45.662407 2026] [security2:error] [pid 983757:tid 983923] [client 14.225.17.146:49608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4XS3KwMdFW9UVnNBSoXgAAASw"], referer: http://adastra.love/oldsite
[Mon Jul 20 06:40:45.718089 2026] [security2:error] [pid 983757:tid 984009] [client 136.144.35.253:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XTXKwMdFW9UVnNBSo5AAAAYI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:45.745710 2026] [security2:error] [pid 983757:tid 983934] [client 152.58.191.29:41345] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XTXKwMdFW9UVnNBSo6AAAATc"]
[Mon Jul 20 06:40:45.746133 2026] [security2:error] [pid 983757:tid 983934] [client 152.58.191.29:41345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XTXKwMdFW9UVnNBSo6AAAATc"]
[Mon Jul 20 06:40:45.818656 2026] [security2:error] [pid 983757:tid 983913] [client 104.234.53.52:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XTXKwMdFW9UVnNBSo7AAAASI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:45.825099 2026] [security2:error] [pid 983757:tid 983961] [client 57.141.18.7:24346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XS3KwMdFW9UVnNBSofAABUno"]
[Mon Jul 20 06:40:45.875094 2026] [security2:error] [pid 966386:tid 966653] [client 103.125.179.95:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XTTrLBqY1mBmWu_YcDQAAAFs"]
[Mon Jul 20 06:40:45.875257 2026] [security2:error] [pid 966386:tid 966653] [client 103.125.179.95:57208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XTTrLBqY1mBmWu_YcDQAAAFs"]
[Mon Jul 20 06:40:45.903687 2026] [security2:error] [pid 966386:tid 966486] [remote 160.187.68.132:44444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4XTTrLBqY1mBmWu_YcDgAAXjg"]
[Mon Jul 20 06:40:46.066360 2026] [security2:error] [pid 983757:tid 984016] [client 14.225.17.146:54238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4XTXKwMdFW9UVnNBSoxwAAAYk"], referer: http://processorstudio.com/oldsite
[Mon Jul 20 06:40:46.147850 2026] [security2:error] [pid 966386:tid 966611] [client 187.108.85.186:56746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XTjrLBqY1mBmWu_YcFgAAADE"]
[Mon Jul 20 06:40:46.147951 2026] [security2:error] [pid 966386:tid 966611] [client 187.108.85.186:56746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XTjrLBqY1mBmWu_YcFgAAADE"]
[Mon Jul 20 06:40:46.173686 2026] [security2:error] [pid 983757:tid 984002] [client 136.144.35.254:48237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XTnKwMdFW9UVnNBSo_wAAAXs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:46.204606 2026] [security2:error] [pid 983757:tid 984014] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XTXKwMdFW9UVnNBSo9AAAAYc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:46.328553 2026] [security2:error] [pid 966386:tid 966645] [client 34.73.38.214:59523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.arrazoado.com"] [uri "/xmlrpc.php"] [unique_id "al4XTjrLBqY1mBmWu_YcHQAAAFM"]
[Mon Jul 20 06:40:46.398502 2026] [security2:error] [pid 966386:tid 966514] [remote 160.187.68.132:44444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4XTjrLBqY1mBmWu_YcIgAAEFQ"], referer: https://stepupstepmom.com/wp-login.php
[Mon Jul 20 06:40:46.470619 2026] [security2:error] [pid 966386:tid 966609] [client 213.111.158.220:7834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.158.111.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muamoicosmetics.com"] [uri "/wp-login.php"] [unique_id "al4XTjrLBqY1mBmWu_YcJQAAAC8"]
[Mon Jul 20 06:40:46.595833 2026] [security2:error] [pid 983757:tid 983979] [client 14.225.17.146:54505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4XTnKwMdFW9UVnNBSpEQAAAWQ"], referer: http://adultdaycarereno.com/oldsite
[Mon Jul 20 06:40:46.635563 2026] [security2:error] [pid 966386:tid 966667] [client 136.144.35.252:59765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XTjrLBqY1mBmWu_YcMAAAAGc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:46.679100 2026] [security2:error] [pid 983757:tid 984011] [client 103.238.106.162:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XTnKwMdFW9UVnNBSpGAAAAYQ"]
[Mon Jul 20 06:40:46.679207 2026] [security2:error] [pid 983757:tid 984011] [client 103.238.106.162:42868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XTnKwMdFW9UVnNBSpGAAAAYQ"]
[Mon Jul 20 06:40:46.799605 2026] [security2:error] [pid 966386:tid 966672] [client 34.73.38.214:57203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XTjrLBqY1mBmWu_YcNQAAAGs"]
[Mon Jul 20 06:40:46.922413 2026] [security2:error] [pid 983757:tid 983895] [client 213.111.158.220:7848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.158.111.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muamoicosmetics.com"] [uri "/administrator/index.php"] [unique_id "al4XTnKwMdFW9UVnNBSpIgAAARA"]
[Mon Jul 20 06:40:46.992288 2026] [security2:error] [pid 983757:tid 983997] [client 14.225.17.146:49629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4XTnKwMdFW9UVnNBSpJAAAAXY"], referer: https://processorstudio.com/oldsite
[Mon Jul 20 06:40:47.044251 2026] [security2:error] [pid 966386:tid 966649] [client 14.225.17.146:54062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4XTTrLBqY1mBmWu_YcEQAAAFc"], referer: http://nikkidesigns.net/oldsite
[Mon Jul 20 06:40:47.086512 2026] [security2:error] [pid 983757:tid 984001] [client 136.144.35.252:53673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XT3KwMdFW9UVnNBSpKgAAAXo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:47.314674 2026] [security2:error] [pid 983757:tid 983975] [client 57.141.18.0:32490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XTXKwMdFW9UVnNBSozwABYFQ"]
[Mon Jul 20 06:40:47.376646 2026] [security2:error] [pid 983757:tid 983954] [client 213.111.158.220:7854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.158.111.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "muamoicosmetics.com"] [uri "/api/index.php/v1/config/application"] [unique_id "al4XT3KwMdFW9UVnNBSpOwAAAUs"]
[Mon Jul 20 06:40:47.453241 2026] [security2:error] [pid 966386:tid 966574] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XTzrLBqY1mBmWu_YcQQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:47.511061 2026] [security2:error] [pid 983757:tid 983766] [remote 115.74.105.156:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4XT3KwMdFW9UVnNBSpPgABWAY"]
[Mon Jul 20 06:40:47.552791 2026] [security2:error] [pid 983757:tid 983969] [client 57.141.18.84:60088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XTXKwMdFW9UVnNBSo4wABWn4"]
[Mon Jul 20 06:40:47.572414 2026] [security2:error] [pid 983757:tid 983932] [client 14.225.17.146:54342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4XT3KwMdFW9UVnNBSpQAAAATU"], referer: https://adultdaycarereno.com/oldsite
[Mon Jul 20 06:40:47.576319 2026] [security2:error] [pid 983757:tid 984008] [client 136.144.35.244:35497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XT3KwMdFW9UVnNBSpRQAAAYE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:47.600516 2026] [security2:error] [pid 983757:tid 983957] [client 34.73.38.214:57868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XT3KwMdFW9UVnNBSpSAAAAU4"]
[Mon Jul 20 06:40:47.685808 2026] [security2:error] [pid 983757:tid 983782] [remote 124.55.178.99:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4XT3KwMdFW9UVnNBSpUAABIBY"]
[Mon Jul 20 06:40:47.721997 2026] [security2:error] [pid 983757:tid 983803] [remote 124.55.178.99:49400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XT3KwMdFW9UVnNBSpUwABQCs"]
[Mon Jul 20 06:40:47.722263 2026] [security2:error] [pid 983757:tid 983943] [client 124.55.178.99:49400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XT3KwMdFW9UVnNBSpUwABQCs"]
[Mon Jul 20 06:40:47.760351 2026] [security2:error] [pid 983757:tid 983898] [client 14.225.17.146:54389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4XTnKwMdFW9UVnNBSpBQAAARM"], referer: http://tntcatholic.com/oldsite
[Mon Jul 20 06:40:47.961502 2026] [security2:error] [pid 966386:tid 966661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XTzrLBqY1mBmWu_YcTAAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:48.049145 2026] [security2:error] [pid 983757:tid 983988] [client 136.144.35.243:62977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XUHKwMdFW9UVnNBSpZwAAAW0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:48.106926 2026] [security2:error] [pid 983757:tid 983979] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XT3KwMdFW9UVnNBSpTgAAAWQ"]
[Mon Jul 20 06:40:48.224569 2026] [security2:error] [pid 983757:tid 983910] [client 114.119.134.231:58565] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vfcthomasville.org"] [uri "/robots.txt"] [unique_id "al4XUHKwMdFW9UVnNBSpbQAAAR8"], referer: https://www.vfcthomasville.org/robots.txt
[Mon Jul 20 06:40:48.238622 2026] [security2:error] [pid 983757:tid 983794] [remote 124.55.178.99:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4XUHKwMdFW9UVnNBSpbgABXiI"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:40:48.283198 2026] [security2:error] [pid 983757:tid 983914] [client 57.141.18.117:28114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XTnKwMdFW9UVnNBSpEAABI14"]
[Mon Jul 20 06:40:48.407515 2026] [security2:error] [pid 966386:tid 966578] [client 217.142.18.172:23057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XUDrLBqY1mBmWu_YcYAAAABA"]
[Mon Jul 20 06:40:48.407655 2026] [security2:error] [pid 966386:tid 966578] [client 217.142.18.172:23057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XUDrLBqY1mBmWu_YcYAAAABA"]
[Mon Jul 20 06:40:48.500872 2026] [security2:error] [pid 966386:tid 966564] [client 223.237.130.40:52883] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XUDrLBqY1mBmWu_YcYQAAAAM"]
[Mon Jul 20 06:40:48.501011 2026] [security2:error] [pid 966386:tid 966564] [client 223.237.130.40:52883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XUDrLBqY1mBmWu_YcYQAAAAM"]
[Mon Jul 20 06:40:48.535301 2026] [security2:error] [pid 983757:tid 983940] [client 136.144.35.247:33241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XUHKwMdFW9UVnNBSpgQAAAT0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:48.581075 2026] [security2:error] [pid 983757:tid 983824] [remote 20.173.88.122:51184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XUHKwMdFW9UVnNBSpgwABS0A"]
[Mon Jul 20 06:40:48.581254 2026] [security2:error] [pid 983757:tid 983954] [client 20.173.88.122:51184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XUHKwMdFW9UVnNBSpgwABS0A"]
[Mon Jul 20 06:40:48.660671 2026] [security2:error] [pid 983757:tid 983865] [remote 188.40.28.4:55348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XUHKwMdFW9UVnNBSpigABQGk"]
[Mon Jul 20 06:40:48.660847 2026] [security2:error] [pid 983757:tid 983943] [client 188.40.28.4:55348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XUHKwMdFW9UVnNBSpigABQGk"]
[Mon Jul 20 06:40:48.719453 2026] [security2:error] [pid 966386:tid 966642] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XUDrLBqY1mBmWu_YcZQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:48.744032 2026] [security2:error] [pid 983757:tid 983898] [client 104.207.61.19:9531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XUHKwMdFW9UVnNBSpjAAAARM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:48.870255 2026] [security2:error] [pid 983757:tid 983921] [client 34.73.38.214:65464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XUHKwMdFW9UVnNBSpkgAAASo"]
[Mon Jul 20 06:40:48.903091 2026] [security2:error] [pid 983757:tid 983897] [client 57.141.18.105:40202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XT3KwMdFW9UVnNBSpLgABEjI"]
[Mon Jul 20 06:40:49.009403 2026] [security2:error] [pid 983757:tid 983968] [client 173.239.240.91:47729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XUXKwMdFW9UVnNBSpnAAAAVk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:49.059683 2026] [security2:error] [pid 966386:tid 966589] [client 216.73.217.138:51342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XUDrLBqY1mBmWu_YccAAAG2I"]
[Mon Jul 20 06:40:49.086378 2026] [security2:error] [pid 966386:tid 966659] [client 14.225.17.146:54482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4XTzrLBqY1mBmWu_YcSgAAAGA"]
[Mon Jul 20 06:40:49.330404 2026] [security2:error] [pid 966386:tid 966598] [client 216.73.217.138:51342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XUTrLBqY1mBmWu_YceQAAJGY"]
[Mon Jul 20 06:40:49.434289 2026] [security2:error] [pid 966386:tid 966574] [client 34.139.11.221:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4XUTrLBqY1mBmWu_YchAAAAAw"]
[Mon Jul 20 06:40:49.485765 2026] [security2:error] [pid 983757:tid 983949] [client 136.144.35.253:60977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XUXKwMdFW9UVnNBSpsgAAAUY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:49.488959 2026] [security2:error] [pid 966386:tid 966660] [client 14.225.17.146:53901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4XUTrLBqY1mBmWu_YcggAAAGE"], referer: http://mcg.homes/oldsite
[Mon Jul 20 06:40:49.513980 2026] [security2:error] [pid 983757:tid 983878] [remote 115.74.105.156:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4XUXKwMdFW9UVnNBSptAABE3Y"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:40:49.607290 2026] [security2:error] [pid 983757:tid 984007] [client 34.139.11.221:59529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XUXKwMdFW9UVnNBSptwAAAYA"]
[Mon Jul 20 06:40:49.608299 2026] [security2:error] [pid 983757:tid 984014] [client 223.185.13.213:19030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XUXKwMdFW9UVnNBSpuAAAAYc"]
[Mon Jul 20 06:40:49.608398 2026] [security2:error] [pid 983757:tid 984014] [client 223.185.13.213:19030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XUXKwMdFW9UVnNBSpuAAAAYc"]
[Mon Jul 20 06:40:49.707237 2026] [security2:error] [pid 983757:tid 983900] [client 74.208.214.194:35730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XUXKwMdFW9UVnNBSpuwAAARU"]
[Mon Jul 20 06:40:49.729988 2026] [security2:error] [pid 983757:tid 983962] [client 34.139.11.221:58696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XUXKwMdFW9UVnNBSpvgAAAVM"]
[Mon Jul 20 06:40:49.856341 2026] [security2:error] [pid 983757:tid 983945] [client 34.73.38.214:53318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XUXKwMdFW9UVnNBSpygAAAUI"]
[Mon Jul 20 06:40:49.897227 2026] [security2:error] [pid 983757:tid 983910] [client 34.139.11.221:62603] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XUXKwMdFW9UVnNBSpzAAAAR8"]
[Mon Jul 20 06:40:49.909633 2026] [security2:error] [pid 983757:tid 983981] [client 57.141.18.100:55456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XUHKwMdFW9UVnNBSpeQABZh4"]
[Mon Jul 20 06:40:49.915486 2026] [security2:error] [pid 966386:tid 966674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XUTrLBqY1mBmWu_YcjwAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:49.934107 2026] [security2:error] [pid 983757:tid 983999] [client 14.225.17.146:53974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4XUXKwMdFW9UVnNBSptgAAAXg"], referer: http://nextlevelpressurewashing.com/oldsite
[Mon Jul 20 06:40:49.959265 2026] [security2:error] [pid 983757:tid 983927] [client 136.144.35.247:58305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XUXKwMdFW9UVnNBSp1AAAATA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:50.059142 2026] [security2:error] [pid 966386:tid 966617] [client 34.139.11.221:63090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XUjrLBqY1mBmWu_YcmgAAADc"]
[Mon Jul 20 06:40:50.071298 2026] [security2:error] [pid 983757:tid 983941] [client 104.207.57.51:25909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XUnKwMdFW9UVnNBSp2gAAAT4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:40:50.151737 2026] [security2:error] [pid 983757:tid 983988] [client 104.234.53.87:59687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XUnKwMdFW9UVnNBSp2QAAAW0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:50.193332 2026] [security2:error] [pid 983757:tid 983894] [client 34.139.11.221:62734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XUnKwMdFW9UVnNBSp4QAAAQ8"]
[Mon Jul 20 06:40:50.332784 2026] [security2:error] [pid 966386:tid 966602] [client 57.141.18.124:48074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XUDrLBqY1mBmWu_YcagAAKCY"]
[Mon Jul 20 06:40:50.342690 2026] [security2:error] [pid 983757:tid 983997] [client 34.139.11.221:49432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XUnKwMdFW9UVnNBSp6wAAAXY"]
[Mon Jul 20 06:40:50.437596 2026] [security2:error] [pid 983757:tid 983895] [client 173.239.240.102:42389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XUnKwMdFW9UVnNBSp8AAAARA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:50.466926 2026] [security2:error] [pid 983757:tid 983959] [client 77.110.127.138:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpNea2rN0i')%20OR%20910=(SELECT%20910%20FROM%20PG_SLEEP(15))--"] [unique_id "al4XUnKwMdFW9UVnNBSp9QAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:50.475419 2026] [security2:error] [pid 983757:tid 983935] [client 34.139.11.221:55143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XUnKwMdFW9UVnNBSp9wAAATg"]
[Mon Jul 20 06:40:50.494393 2026] [security2:error] [pid 983757:tid 983930] [client 57.141.18.41:45562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XUHKwMdFW9UVnNBSplgABMyg"]
[Mon Jul 20 06:40:50.569159 2026] [security2:error] [pid 983757:tid 983849] [remote 216.73.217.138:17742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XUnKwMdFW9UVnNBSp-AABR1k"]
[Mon Jul 20 06:40:50.578677 2026] [security2:error] [pid 983757:tid 983864] [remote 216.73.217.138:17742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XUnKwMdFW9UVnNBSp-QABR2g"]
[Mon Jul 20 06:40:50.640770 2026] [security2:error] [pid 966386:tid 966618] [client 34.139.11.221:53988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XUjrLBqY1mBmWu_YcowAAADg"]
[Mon Jul 20 06:40:50.696372 2026] [security2:error] [pid 983757:tid 983966] [client 39.48.81.23:58804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XUnKwMdFW9UVnNBSqCwAAAVc"]
[Mon Jul 20 06:40:50.696465 2026] [security2:error] [pid 983757:tid 983966] [client 39.48.81.23:58804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XUnKwMdFW9UVnNBSqCwAAAVc"]
[Mon Jul 20 06:40:50.750784 2026] [security2:error] [pid 983757:tid 983927] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XUnKwMdFW9UVnNBSqBQAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:50.819343 2026] [security2:error] [pid 983757:tid 983948] [client 34.139.11.221:59731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XUnKwMdFW9UVnNBSqFAAAAUU"]
[Mon Jul 20 06:40:50.844156 2026] [security2:error] [pid 966386:tid 966567] [client 57.141.18.64:43266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XUTrLBqY1mBmWu_YcfwAABWM"]
[Mon Jul 20 06:40:50.910784 2026] [security2:error] [pid 983757:tid 983972] [client 136.144.35.251:23931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XUnKwMdFW9UVnNBSqGQAAAV0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:50.967840 2026] [security2:error] [pid 983757:tid 983779] [remote 173.212.252.15:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XUnKwMdFW9UVnNBSqHQABNhM"]
[Mon Jul 20 06:40:50.973242 2026] [security2:error] [pid 983757:tid 983907] [client 34.139.11.221:50911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XUnKwMdFW9UVnNBSqHgAAARw"]
[Mon Jul 20 06:40:51.002100 2026] [security2:error] [pid 983757:tid 983995] [client 57.141.18.18:22762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XUnKwMdFW9UVnNBSqFwABdFs"]
[Mon Jul 20 06:40:51.106125 2026] [security2:error] [pid 983757:tid 983924] [client 104.234.53.87:59687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XU3KwMdFW9UVnNBSqKAAAAS0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:51.117291 2026] [security2:error] [pid 983757:tid 983930] [client 34.139.11.221:61947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XU3KwMdFW9UVnNBSqKQAAATM"]
[Mon Jul 20 06:40:51.187193 2026] [security2:error] [pid 983757:tid 983999] [client 34.73.38.214:54874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XU3KwMdFW9UVnNBSqLAAAAXg"]
[Mon Jul 20 06:40:51.212389 2026] [security2:error] [pid 966386:tid 966560] [client 197.186.66.42:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XUzrLBqY1mBmWu_YctwAAAAA"]
[Mon Jul 20 06:40:51.212513 2026] [security2:error] [pid 966386:tid 966560] [client 197.186.66.42:51448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XUzrLBqY1mBmWu_YctwAAAAA"]
[Mon Jul 20 06:40:51.273990 2026] [security2:error] [pid 983757:tid 983898] [client 217.60.2.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4XU3KwMdFW9UVnNBSqIwAAARM"], referer: http://blog.danwolfe.us/2021/02/we-have-landed/
[Mon Jul 20 06:40:51.327731 2026] [security2:error] [pid 983757:tid 984015] [client 14.225.17.146:54478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4XUnKwMdFW9UVnNBSp7AAAAYg"]
[Mon Jul 20 06:40:51.405694 2026] [security2:error] [pid 966386:tid 966651] [client 173.239.240.92:42761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XUzrLBqY1mBmWu_YcwgAAAFk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:51.432802 2026] [security2:error] [pid 983757:tid 983775] [remote 173.212.252.15:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XU3KwMdFW9UVnNBSqPgABSg8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:40:51.816162 2026] [security2:error] [pid 966386:tid 966650] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XUzrLBqY1mBmWu_YcxgAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:51.882794 2026] [security2:error] [pid 983757:tid 983896] [client 173.239.240.94:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XU3KwMdFW9UVnNBSqWgAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:51.884331 2026] [security2:error] [pid 966386:tid 966670] [client 127.0.0.1:55838] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4XUzrLBqY1mBmWu_YczgAAAGk"], referer: https://www.bing.com/search?q=hhb7sx
[Mon Jul 20 06:40:52.168249 2026] [security2:error] [pid 983757:tid 983941] [client 34.73.38.214:60605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XVHKwMdFW9UVnNBSqagAAAT4"]
[Mon Jul 20 06:40:52.211231 2026] [core:error] [pid 966386:tid 966600] [client 14.225.17.146:55200] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/oldsite
[Mon Jul 20 06:40:52.211260 2026] [core:error] [pid 966386:tid 966600] [client 14.225.17.146:55200] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/oldsite
[Mon Jul 20 06:40:52.331257 2026] [security2:error] [pid 983757:tid 983979] [client 136.144.35.247:58985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XVHKwMdFW9UVnNBSqgAAAAWQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:52.360310 2026] [security2:error] [pid 966386:tid 966617] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XVDrLBqY1mBmWu_Yc0gAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:52.467732 2026] [security2:error] [pid 983757:tid 983939] [client 171.61.165.146:2218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XVHKwMdFW9UVnNBSqiwAAATw"]
[Mon Jul 20 06:40:52.467858 2026] [security2:error] [pid 983757:tid 983939] [client 171.61.165.146:2218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XVHKwMdFW9UVnNBSqiwAAATw"]
[Mon Jul 20 06:40:52.489011 2026] [security2:error] [pid 966386:tid 966644] [client 57.141.18.44:55648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XUjrLBqY1mBmWu_YcpQAAUnI"]
[Mon Jul 20 06:40:52.503258 2026] [security2:error] [pid 983757:tid 983935] [client 13.74.155.112:19139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XVHKwMdFW9UVnNBSqkQAAATg"]
[Mon Jul 20 06:40:52.610253 2026] [lsapi:warn] [pid 966386:tid 966577] [client 14.225.17.146:55165] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/oldsite
[Mon Jul 20 06:40:52.610279 2026] [lsapi:warn] [pid 966386:tid 966577] [client 14.225.17.146:55165] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/oldsite
[Mon Jul 20 06:40:52.636868 2026] [security2:error] [pid 983757:tid 983953] [client 13.74.155.112:19139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XVHKwMdFW9UVnNBSqlwAAAUo"]
[Mon Jul 20 06:40:52.799302 2026] [security2:error] [pid 983757:tid 983894] [client 173.239.240.97:43369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XVHKwMdFW9UVnNBSqrAAAAQ8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:52.827795 2026] [security2:error] [pid 966386:tid 966680] [client 223.237.130.40:52883] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XVDrLBqY1mBmWu_Yc4QAAAHM"]
[Mon Jul 20 06:40:52.827944 2026] [security2:error] [pid 966386:tid 966680] [client 223.237.130.40:52883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XVDrLBqY1mBmWu_Yc4QAAAHM"]
[Mon Jul 20 06:40:52.861867 2026] [security2:error] [pid 983757:tid 983985] [client 158.173.166.181:39611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XVHKwMdFW9UVnNBSqrgAAAWo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:40:52.894347 2026] [security2:error] [pid 966386:tid 966523] [remote 100.42.189.89:57204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4XVDrLBqY1mBmWu_Yc5AAACF0"]
[Mon Jul 20 06:40:52.903562 2026] [security2:error] [pid 983757:tid 983904] [client 57.141.18.56:34250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XU3KwMdFW9UVnNBSqMQABGQM"]
[Mon Jul 20 06:40:53.062261 2026] [security2:error] [pid 983757:tid 983921] [client 78.47.165.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4XVHKwMdFW9UVnNBSqqQAAASo"]
[Mon Jul 20 06:40:53.083800 2026] [security2:error] [pid 983757:tid 984014] [client 106.219.188.178:8576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XVXKwMdFW9UVnNBSqxQAAAYc"]
[Mon Jul 20 06:40:53.084192 2026] [security2:error] [pid 983757:tid 984014] [client 106.219.188.178:8576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XVXKwMdFW9UVnNBSqxQAAAYc"]
[Mon Jul 20 06:40:53.098016 2026] [security2:error] [pid 966386:tid 966479] [remote 100.42.189.89:57204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4XVTrLBqY1mBmWu_Yc6AAAGzE"], referer: https://karimnawfal.com/wp-login.php
[Mon Jul 20 06:40:53.137348 2026] [lsapi:warn] [pid 983757:tid 983974] [client 50.116.65.227:49712] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:40:53.137365 2026] [lsapi:warn] [pid 983757:tid 983974] [client 50.116.65.227:49712] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:40:53.153301 2026] [security2:error] [pid 966386:tid 966577] [client 14.225.17.146:55165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4XVDrLBqY1mBmWu_Yc1QAAAA8"], referer: http://oswegooperatheater.com/oldsite
[Mon Jul 20 06:40:53.248435 2026] [security2:error] [pid 966386:tid 966614] [client 127.0.0.1:55840] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4XVTrLBqY1mBmWu_Yc6gAAADQ"], referer: https://www.facebook.com/
[Mon Jul 20 06:40:53.265252 2026] [security2:error] [pid 966386:tid 966659] [client 173.239.240.31:57743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XVTrLBqY1mBmWu_Yc6QAAAGA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:53.589276 2026] [security2:error] [pid 966386:tid 966645] [client 14.225.17.146:55732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4XVTrLBqY1mBmWu_Yc7gAAAFM"], referer: http://taskidsvirginia.com/oldsite
[Mon Jul 20 06:40:53.609980 2026] [security2:error] [pid 983757:tid 983954] [client 57.141.18.90:46054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XU3KwMdFW9UVnNBSqVwABSxA"]
[Mon Jul 20 06:40:53.737678 2026] [security2:error] [pid 983757:tid 983928] [client 173.239.240.100:61275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XVXKwMdFW9UVnNBSq7gAAATE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:53.831786 2026] [security2:error] [pid 966386:tid 966654] [client 34.73.38.214:53842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XVTrLBqY1mBmWu_Yc-gAAAFw"]
[Mon Jul 20 06:40:53.886411 2026] [security2:error] [pid 983757:tid 983918] [client 104.234.53.85:31173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XVXKwMdFW9UVnNBSq9gAAASc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:54.012757 2026] [lsapi:warn] [pid 966386:tid 966611] [client 14.225.17.146:56003] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/oldsite
[Mon Jul 20 06:40:54.012777 2026] [lsapi:warn] [pid 966386:tid 966611] [client 14.225.17.146:56003] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/oldsite
[Mon Jul 20 06:40:54.074395 2026] [security2:error] [pid 966386:tid 966611] [client 14.225.17.146:56003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4XVjrLBqY1mBmWu_YdAgAAADE"], referer: https://oswegooperatheater.com/oldsite
[Mon Jul 20 06:40:54.185979 2026] [security2:error] [pid 983757:tid 983945] [client 136.144.35.250:51625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XVnKwMdFW9UVnNBSq-wAAAUI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:54.256352 2026] [security2:error] [pid 983757:tid 983808] [remote 124.55.178.99:47270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4XVnKwMdFW9UVnNBSrAQABEjA"]
[Mon Jul 20 06:40:54.345176 2026] [security2:error] [pid 966386:tid 966593] [client 50.116.65.227:49748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XVjrLBqY1mBmWu_YdCwAAAB8"]
[Mon Jul 20 06:40:54.353009 2026] [security2:error] [pid 983757:tid 983999] [client 112.208.70.94:42806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XVnKwMdFW9UVnNBSrDQAAAXg"]
[Mon Jul 20 06:40:54.353144 2026] [security2:error] [pid 983757:tid 983999] [client 112.208.70.94:42806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XVnKwMdFW9UVnNBSrDQAAAXg"]
[Mon Jul 20 06:40:54.381537 2026] [security2:error] [pid 966386:tid 966595] [client 104.207.54.134:56643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XVjrLBqY1mBmWu_YdEgAAACE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:40:54.418767 2026] [security2:error] [pid 966386:tid 966677] [client 14.225.17.146:65199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4XVjrLBqY1mBmWu_YdEAAAAHA"], referer: http://dasmarque.com/oldsite
[Mon Jul 20 06:40:54.443270 2026] [security2:error] [pid 966386:tid 966630] [client 77.110.127.138:52516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpfrKE435R'))%20OR%20728=(SELECT%20728%20FROM%20PG_SLEEP(15))--"] [unique_id "al4XVjrLBqY1mBmWu_YdEwAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:54.458816 2026] [security2:error] [pid 983757:tid 983891] [client 14.225.17.146:55725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4XVXKwMdFW9UVnNBSq1QAAAQw"], referer: http://getgarrison.com/oldsite
[Mon Jul 20 06:40:54.559462 2026] [security2:error] [pid 966386:tid 966631] [client 50.116.65.227:49754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XVjrLBqY1mBmWu_YdEQAAAEU"]
[Mon Jul 20 06:40:54.652859 2026] [security2:error] [pid 983757:tid 983962] [client 136.144.35.252:59333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XVnKwMdFW9UVnNBSrHQAAAVM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:54.677528 2026] [security2:error] [pid 983757:tid 983845] [remote 124.55.178.99:47270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4XVnKwMdFW9UVnNBSrIQABbFU"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:40:54.680652 2026] [security2:error] [pid 983757:tid 983917] [client 146.75.222.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4XVHKwMdFW9UVnNBSqoAAAASY"]
[Mon Jul 20 06:40:54.726667 2026] [security2:error] [pid 983757:tid 983901] [client 14.251.3.155:54579] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XVnKwMdFW9UVnNBSrJgAAARY"]
[Mon Jul 20 06:40:55.118100 2026] [security2:error] [pid 983757:tid 983916] [client 173.239.240.100:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XV3KwMdFW9UVnNBSrRAAAASU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:55.557813 2026] [security2:error] [pid 983757:tid 983965] [client 14.225.17.146:61372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4XV3KwMdFW9UVnNBSrTgAAAVY"]
[Mon Jul 20 06:40:55.569104 2026] [security2:error] [pid 983757:tid 983910] [client 173.239.240.97:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XV3KwMdFW9UVnNBSrXgAAAR8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:55.606682 2026] [security2:error] [pid 983757:tid 983952] [client 14.225.17.146:61943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4XV3KwMdFW9UVnNBSrQwAAAUk"], referer: http://partnerselectricalllc.com/oldsite
[Mon Jul 20 06:40:55.670133 2026] [security2:error] [pid 966386:tid 966576] [client 34.73.38.214:50128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XVzrLBqY1mBmWu_YdKQAAAA4"]
[Mon Jul 20 06:40:55.853310 2026] [security2:error] [pid 983757:tid 983923] [client 46.110.96.34:4984] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XV3KwMdFW9UVnNBSraQAAASw"]
[Mon Jul 20 06:40:55.910587 2026] [security2:error] [pid 966386:tid 966650] [client 46.110.96.34:60606] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XVzrLBqY1mBmWu_YdOQAAAFg"]
[Mon Jul 20 06:40:56.005915 2026] [security2:error] [pid 983757:tid 983911] [client 57.141.18.120:31374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XVnKwMdFW9UVnNBSrDwABIGQ"]
[Mon Jul 20 06:40:56.037551 2026] [security2:error] [pid 983757:tid 984013] [client 136.144.35.246:30791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XWHKwMdFW9UVnNBSrcAAAAYY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:56.084190 2026] [security2:error] [pid 966386:tid 966617] [client 50.116.65.227:13992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4XWDrLBqY1mBmWu_YdPwAAADc"]
[Mon Jul 20 06:40:56.096194 2026] [security2:error] [pid 966386:tid 966612] [client 50.116.65.227:49784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4XWDrLBqY1mBmWu_YdQAAAAB8"]
[Mon Jul 20 06:40:56.125803 2026] [security2:error] [pid 966386:tid 966517] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdQQAAA1c"]
[Mon Jul 20 06:40:56.125965 2026] [security2:error] [pid 966386:tid 966564] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdQQAAA1c"]
[Mon Jul 20 06:40:56.136940 2026] [security2:error] [pid 983757:tid 984007] [client 57.141.18.39:30127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XVnKwMdFW9UVnNBSrEgABgAg"]
[Mon Jul 20 06:40:56.263276 2026] [security2:error] [pid 966386:tid 966609] [client 152.58.191.29:54292] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdSAAAAC8"]
[Mon Jul 20 06:40:56.267454 2026] [security2:error] [pid 966386:tid 966609] [client 152.58.191.29:54292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdSAAAAC8"]
[Mon Jul 20 06:40:56.276011 2026] [proxy:error] [pid 966386:tid 966644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:56.276075 2026] [proxy_http:error] [pid 966386:tid 966644] [client 34.73.38.214:58478] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:56.276716 2026] [proxy:error] [pid 966386:tid 966644] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:56.276756 2026] [proxy_http:error] [pid 966386:tid 966644] [client 34.73.38.214:58478] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:56.296560 2026] [security2:error] [pid 966386:tid 966483] [remote 162.19.86.63:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdSgAAdTU"]
[Mon Jul 20 06:40:56.296733 2026] [security2:error] [pid 966386:tid 966682] [client 162.19.86.63:50050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdSgAAdTU"]
[Mon Jul 20 06:40:56.465651 2026] [security2:error] [pid 966386:tid 966571] [client 50.116.65.227:14002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4XWDrLBqY1mBmWu_YdUQAAAAk"]
[Mon Jul 20 06:40:56.478569 2026] [security2:error] [pid 966386:tid 966589] [client 50.116.65.227:49786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4XWDrLBqY1mBmWu_YdUgAAABs"]
[Mon Jul 20 06:40:56.484414 2026] [security2:error] [pid 983757:tid 983953] [client 173.239.240.99:54229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XWHKwMdFW9UVnNBSrhwAAAUo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:56.519893 2026] [security2:error] [pid 966386:tid 966677] [client 40.77.167.26:11389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4XWDrLBqY1mBmWu_YdRgAAcC4"]
[Mon Jul 20 06:40:56.567235 2026] [security2:error] [pid 966386:tid 966647] [client 57.141.18.119:25372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XVjrLBqY1mBmWu_YdGwAAVWk"]
[Mon Jul 20 06:40:56.615646 2026] [security2:error] [pid 983757:tid 983924] [client 57.141.18.94:54202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XVnKwMdFW9UVnNBSrOQABLSE"]
[Mon Jul 20 06:40:56.651388 2026] [security2:error] [pid 983757:tid 983973] [client 187.108.85.186:57286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XWHKwMdFW9UVnNBSrjQAAAV4"]
[Mon Jul 20 06:40:56.651495 2026] [security2:error] [pid 983757:tid 983973] [client 187.108.85.186:57286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XWHKwMdFW9UVnNBSrjQAAAV4"]
[Mon Jul 20 06:40:56.671967 2026] [security2:error] [pid 983757:tid 983915] [client 57.141.18.35:42302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XV3KwMdFW9UVnNBSrPgABJBw"]
[Mon Jul 20 06:40:56.758496 2026] [security2:error] [pid 983757:tid 983982] [client 34.73.38.214:62639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XWHKwMdFW9UVnNBSrlAAAAWc"]
[Mon Jul 20 06:40:56.857995 2026] [security2:error] [pid 983757:tid 983935] [client 114.119.146.159:28499] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/cowl-knit-free-pattern/"] [unique_id "al4XWHKwMdFW9UVnNBSrmgAAATg"], referer: https://mezzacraft.com/feather-fan-crochet-blanket-pattern/
[Mon Jul 20 06:40:56.935665 2026] [security2:error] [pid 966386:tid 966618] [client 103.125.179.95:57714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdXwAAADg"]
[Mon Jul 20 06:40:56.935799 2026] [security2:error] [pid 966386:tid 966618] [client 103.125.179.95:57714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XWDrLBqY1mBmWu_YdXwAAADg"]
[Mon Jul 20 06:40:56.937037 2026] [security2:error] [pid 983757:tid 983992] [client 136.144.35.245:54447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XWHKwMdFW9UVnNBSrngAAAXE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:56.964658 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:52528] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/if(now()=sysdate(),sleep(15),0)/page/2/"] [unique_id "al4XWDrLBqY1mBmWu_YdYgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:57.349620 2026] [security2:error] [pid 983757:tid 984008] [client 104.234.53.83:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XWXKwMdFW9UVnNBSrsgAAAYE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:40:57.367891 2026] [security2:error] [pid 983757:tid 984015] [client 91.123.14.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4XWHKwMdFW9UVnNBSrnQAAAYg"]
[Mon Jul 20 06:40:57.406966 2026] [security2:error] [pid 966386:tid 966661] [client 173.239.240.94:38693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XWTrLBqY1mBmWu_YdbwAAAGI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:57.699178 2026] [security2:error] [pid 983757:tid 983978] [client 45.157.112.60:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XWXKwMdFW9UVnNBSryQAAAWM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:40:57.849598 2026] [proxy:error] [pid 966386:tid 966670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:57.849653 2026] [proxy_http:error] [pid 966386:tid 966670] [client 34.73.38.214:59218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:57.850157 2026] [proxy:error] [pid 966386:tid 966670] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:57.850184 2026] [proxy_http:error] [pid 966386:tid 966670] [client 34.73.38.214:59218] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:57.873817 2026] [security2:error] [pid 983757:tid 983963] [client 136.144.35.248:59223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XWXKwMdFW9UVnNBSr0AAAAVQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:57.907027 2026] [security2:error] [pid 983757:tid 983772] [remote 81.173.115.7:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4XWXKwMdFW9UVnNBSr0gABWQw"]
[Mon Jul 20 06:40:57.913179 2026] [security2:error] [pid 966386:tid 966624] [client 103.238.106.162:60623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XWTrLBqY1mBmWu_YdfQAAAD4"]
[Mon Jul 20 06:40:57.913308 2026] [security2:error] [pid 966386:tid 966624] [client 103.238.106.162:60623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XWTrLBqY1mBmWu_YdfQAAAD4"]
[Mon Jul 20 06:40:58.095525 2026] [security2:error] [pid 983757:tid 983811] [remote 81.173.115.7:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4XWnKwMdFW9UVnNBSr1wABazM"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:40:58.273101 2026] [security2:error] [pid 966386:tid 966593] [client 14.225.17.146:65258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4XWjrLBqY1mBmWu_YdgQAAAB8"], referer: http://sesamegreenbeans.com/oldsite
[Mon Jul 20 06:40:58.329994 2026] [security2:error] [pid 983757:tid 983958] [client 173.239.240.93:42249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XWnKwMdFW9UVnNBSr4AAAAU8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:58.416165 2026] [security2:error] [pid 966386:tid 966589] [client 34.73.38.214:52904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.arrazoado.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XWjrLBqY1mBmWu_YdjAAAABs"]
[Mon Jul 20 06:40:58.576608 2026] [security2:error] [pid 966386:tid 966588] [client 57.141.18.97:49352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XWTrLBqY1mBmWu_YdZQAAGhE"]
[Mon Jul 20 06:40:58.691187 2026] [security2:error] [pid 983757:tid 983933] [client 57.141.18.15:56118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XWXKwMdFW9UVnNBSrqwABNlc"]
[Mon Jul 20 06:40:58.778180 2026] [security2:error] [pid 983757:tid 983982] [client 136.144.35.244:35631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XWnKwMdFW9UVnNBSr8wAAAWc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:58.921146 2026] [security2:error] [pid 966386:tid 966563] [client 77.110.127.138:52544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4XWjrLBqY1mBmWu_YdogAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:58.956215 2026] [security2:error] [pid 983757:tid 983944] [client 217.142.18.172:6634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XWnKwMdFW9UVnNBSr_wAAAUE"]
[Mon Jul 20 06:40:58.960981 2026] [security2:error] [pid 983757:tid 983944] [client 217.142.18.172:6634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XWnKwMdFW9UVnNBSr_wAAAUE"]
[Mon Jul 20 06:40:59.180110 2026] [security2:error] [pid 983757:tid 983904] [client 77.110.127.138:52548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XW3KwMdFW9UVnNBSsEwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:59.180217 2026] [security2:error] [pid 983757:tid 983904] [client 77.110.127.138:52548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XW3KwMdFW9UVnNBSsEwAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:59.248605 2026] [security2:error] [pid 983757:tid 983894] [client 173.239.240.95:52557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XW3KwMdFW9UVnNBSsFwAAAQ8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:59.338401 2026] [security2:error] [pid 983757:tid 983911] [client 57.141.18.114:46420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XWXKwMdFW9UVnNBSrzwABIFI"]
[Mon Jul 20 06:40:59.371495 2026] [security2:error] [pid 983757:tid 983972] [client 14.225.17.146:52334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4XW3KwMdFW9UVnNBSsFAAAAV0"], referer: https://sesamegreenbeans.com/oldsite
[Mon Jul 20 06:40:59.471492 2026] [security2:error] [pid 983757:tid 983915] [client 77.110.127.138:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4XW3KwMdFW9UVnNBSsIQAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:59.501474 2026] [security2:error] [pid 966386:tid 966514] [remote 160.187.68.132:59614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XWzrLBqY1mBmWu_YdtgAAaFQ"]
[Mon Jul 20 06:40:59.620589 2026] [security2:error] [pid 966386:tid 966522] [remote 217.61.143.92:50096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XWzrLBqY1mBmWu_YdvwAAX1w"]
[Mon Jul 20 06:40:59.624893 2026] [security2:error] [pid 983757:tid 983903] [client 77.110.127.138:52555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4XW3KwMdFW9UVnNBSsJgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:40:59.721224 2026] [security2:error] [pid 983757:tid 983996] [client 136.144.35.252:27377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XW3KwMdFW9UVnNBSsKwAAAXU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:40:59.851829 2026] [security2:error] [pid 966386:tid 966516] [remote 217.61.143.92:50096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XWzrLBqY1mBmWu_YdwQAAIlY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:40:59.908761 2026] [proxy:error] [pid 966386:tid 966632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:59.908844 2026] [proxy_http:error] [pid 966386:tid 966632] [client 34.73.38.214:61288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:40:59.910589 2026] [proxy:error] [pid 966386:tid 966632] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:40:59.910636 2026] [proxy_http:error] [pid 966386:tid 966632] [client 34.73.38.214:61288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:00.122167 2026] [security2:error] [pid 983757:tid 983994] [client 77.110.127.138:52558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XW3KwMdFW9UVnNBSsLwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:00.176796 2026] [security2:error] [pid 983757:tid 984002] [client 136.144.35.253:45017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XXHKwMdFW9UVnNBSsSwAAAXs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:00.454757 2026] [security2:error] [pid 966386:tid 966450] [remote 160.187.68.132:59614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XXDrLBqY1mBmWu_YdzQAADRc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:41:00.459205 2026] [security2:error] [pid 966386:tid 966656] [client 77.110.127.138:52525] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/2/"] [unique_id "al4XXDrLBqY1mBmWu_YdzgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:00.480397 2026] [security2:error] [pid 983757:tid 983899] [client 104.234.53.83:27853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XXHKwMdFW9UVnNBSsXAAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:00.525568 2026] [security2:error] [pid 983757:tid 983897] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XXHKwMdFW9UVnNBSsWQAAARI"]
[Mon Jul 20 06:41:00.547555 2026] [security2:error] [pid 983757:tid 983934] [client 77.110.127.138:52560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XXHKwMdFW9UVnNBSsVQAAATc"]
[Mon Jul 20 06:41:00.630606 2026] [security2:error] [pid 966386:tid 966630] [client 14.225.17.146:65232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4XWzrLBqY1mBmWu_YdswAAAEQ"]
[Mon Jul 20 06:41:00.832024 2026] [security2:error] [pid 983757:tid 983946] [client 57.141.18.80:49832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XW3KwMdFW9UVnNBSsGwABQwY"]
[Mon Jul 20 06:41:00.862529 2026] [security2:error] [pid 966386:tid 966619] [client 136.144.35.246:56157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XXDrLBqY1mBmWu_Yd3QAAADk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:00.959971 2026] [security2:error] [pid 966386:tid 966638] [client 77.110.127.138:52528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XXDrLBqY1mBmWu_Yd1QAAAEw"]
[Mon Jul 20 06:41:01.042484 2026] [security2:error] [pid 983757:tid 983963] [client 65.111.28.141:37669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XXHKwMdFW9UVnNBSseQAAAVQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:01.076777 2026] [security2:error] [pid 983757:tid 983991] [client 223.185.13.213:5834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XXXKwMdFW9UVnNBSsfQAAAXA"]
[Mon Jul 20 06:41:01.076907 2026] [security2:error] [pid 983757:tid 983991] [client 223.185.13.213:5834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XXXKwMdFW9UVnNBSsfQAAAXA"]
[Mon Jul 20 06:41:01.206353 2026] [core:error] [pid 983757:tid 983985] [client 185.247.137.250:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:01.206371 2026] [core:error] [pid 983757:tid 983985] [client 185.247.137.250:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:01.209472 2026] [security2:error] [pid 966386:tid 966571] [client 34.73.38.214:60610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XXTrLBqY1mBmWu_Yd7wAAAAk"]
[Mon Jul 20 06:41:01.292224 2026] [security2:error] [pid 983757:tid 983988] [client 104.234.53.88:54025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XXXKwMdFW9UVnNBSsiwAAAW0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:01.318549 2026] [security2:error] [pid 983757:tid 983927] [client 39.48.81.23:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XXXKwMdFW9UVnNBSsjAAAATA"]
[Mon Jul 20 06:41:01.318709 2026] [security2:error] [pid 983757:tid 983927] [client 39.48.81.23:59318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XXXKwMdFW9UVnNBSsjAAAATA"]
[Mon Jul 20 06:41:01.347554 2026] [security2:error] [pid 966386:tid 966682] [client 173.239.240.101:61149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XXTrLBqY1mBmWu_Yd8AAAAHU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:01.402078 2026] [security2:error] [pid 966386:tid 966518] [remote 113.160.142.119:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4XXTrLBqY1mBmWu_Yd8gAAVVg"]
[Mon Jul 20 06:41:01.521831 2026] [security2:error] [pid 983757:tid 983960] [client 14.225.17.146:61339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4XXXKwMdFW9UVnNBSskQAAAVE"], referer: http://hammadownenterprises.com/oldsite
[Mon Jul 20 06:41:01.539601 2026] [security2:error] [pid 983757:tid 983944] [client 57.141.18.35:58086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XW3KwMdFW9UVnNBSsOAABQSs"]
[Mon Jul 20 06:41:01.825551 2026] [security2:error] [pid 983757:tid 983982] [client 136.144.35.251:26719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XXXKwMdFW9UVnNBSsqQAAAWc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:01.872921 2026] [security2:error] [pid 966386:tid 966610] [client 98.159.234.160:53231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XXTrLBqY1mBmWu_YeAAAAADA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:41:01.966270 2026] [security2:error] [pid 983757:tid 983993] [client 65.111.8.97:12603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XXXKwMdFW9UVnNBSssAAAAXI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:02.166442 2026] [security2:error] [pid 966386:tid 966625] [client 57.141.18.86:37864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XXDrLBqY1mBmWu_Yd0gAAPxU"]
[Mon Jul 20 06:41:02.279862 2026] [security2:error] [pid 983757:tid 983949] [client 136.144.35.249:49321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XXnKwMdFW9UVnNBSsvgAAAUY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:02.448574 2026] [security2:error] [pid 983757:tid 983979] [client 14.225.17.146:52965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4XXXKwMdFW9UVnNBSsiQAAAWQ"], referer: http://sarahholyfield.com/oldsite
[Mon Jul 20 06:41:02.459237 2026] [security2:error] [pid 983757:tid 983800] [remote 199.189.225.40:51205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4XXnKwMdFW9UVnNBSsxgABNig"]
[Mon Jul 20 06:41:02.644340 2026] [security2:error] [pid 983757:tid 983788] [remote 199.189.225.40:51205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4XXnKwMdFW9UVnNBSs0gABQRw"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:41:02.693017 2026] [security2:error] [pid 983757:tid 983899] [client 113.170.30.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4XXnKwMdFW9UVnNBSsvwAAARQ"]
[Mon Jul 20 06:41:02.714572 2026] [security2:error] [pid 983757:tid 983934] [client 104.207.61.19:28661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XXnKwMdFW9UVnNBSs2wAAATc"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:02.744809 2026] [security2:error] [pid 983757:tid 983907] [client 136.144.35.254:24999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XXnKwMdFW9UVnNBSs4AAAARw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:02.981181 2026] [security2:error] [pid 966386:tid 966667] [client 104.234.53.90:38415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XXjrLBqY1mBmWu_YeKgAAAGc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:03.000693 2026] [security2:error] [pid 983757:tid 983862] [remote 81.173.115.7:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XX3KwMdFW9UVnNBSs8wABRGY"]
[Mon Jul 20 06:41:03.113118 2026] [security2:error] [pid 983757:tid 984015] [client 34.73.38.214:52901] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XX3KwMdFW9UVnNBSs-wAAAYg"]
[Mon Jul 20 06:41:03.196221 2026] [security2:error] [pid 983757:tid 983859] [remote 81.173.115.7:59946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XX3KwMdFW9UVnNBSs_wABZWM"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:41:03.206169 2026] [security2:error] [pid 983757:tid 983990] [client 173.239.240.32:45663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XX3KwMdFW9UVnNBSs_gAAAW8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:03.302920 2026] [security2:error] [pid 966386:tid 966639] [client 57.141.18.9:28856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XXTrLBqY1mBmWu_Yd_gAATSw"]
[Mon Jul 20 06:41:03.314531 2026] [security2:error] [pid 983757:tid 984007] [client 171.61.165.146:19799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XX3KwMdFW9UVnNBStAgAAAYA"]
[Mon Jul 20 06:41:03.314638 2026] [security2:error] [pid 983757:tid 984007] [client 171.61.165.146:19799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XX3KwMdFW9UVnNBStAgAAAYA"]
[Mon Jul 20 06:41:03.328544 2026] [security2:error] [pid 966386:tid 966623] [client 122.183.32.225:24258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XXzrLBqY1mBmWu_YeMgAAAD0"]
[Mon Jul 20 06:41:03.328659 2026] [security2:error] [pid 966386:tid 966623] [client 122.183.32.225:24258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XXzrLBqY1mBmWu_YeMgAAAD0"]
[Mon Jul 20 06:41:03.408568 2026] [security2:error] [pid 966386:tid 966545] [remote 113.160.142.119:49794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4XXzrLBqY1mBmWu_YeNAAAR3M"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 06:41:03.551083 2026] [security2:error] [pid 983757:tid 983906] [client 57.141.18.15:56128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XXnKwMdFW9UVnNBSstQABG2Q"]
[Mon Jul 20 06:41:03.586939 2026] [security2:error] [pid 983757:tid 983998] [client 103.153.183.69:35560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.183.153.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env%00.php"] [unique_id "al4XX3KwMdFW9UVnNBStDQAAAXc"], referer: https://twitter.com/
[Mon Jul 20 06:41:03.701110 2026] [security2:error] [pid 983757:tid 984013] [client 136.144.35.253:43245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XX3KwMdFW9UVnNBStFAAAAYY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:03.885446 2026] [security2:error] [pid 966386:tid 966608] [client 34.73.38.214:51242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XXzrLBqY1mBmWu_YeQgAAAC4"]
[Mon Jul 20 06:41:03.997981 2026] [security2:error] [pid 966386:tid 966675] [client 77.110.127.138:52570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/2/"] [unique_id "al4XXzrLBqY1mBmWu_YeSAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:04.001465 2026] [security2:error] [pid 983757:tid 983919] [client 106.219.188.178:15036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XYHKwMdFW9UVnNBStJQAAASg"]
[Mon Jul 20 06:41:04.011228 2026] [security2:error] [pid 983757:tid 983919] [client 106.219.188.178:15036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XYHKwMdFW9UVnNBStJQAAASg"]
[Mon Jul 20 06:41:04.070728 2026] [security2:error] [pid 983757:tid 983932] [client 14.225.17.146:52397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4XX3KwMdFW9UVnNBStGQAAATU"], referer: http://ccsdifference.com/oldsite
[Mon Jul 20 06:41:04.119894 2026] [security2:error] [pid 983757:tid 983920] [client 168.227.23.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4XX3KwMdFW9UVnNBStDAAAASk"]
[Mon Jul 20 06:41:04.190541 2026] [security2:error] [pid 983757:tid 984006] [client 136.144.35.248:26881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XYHKwMdFW9UVnNBStMQAAAX8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:04.281437 2026] [security2:error] [pid 983757:tid 983890] [client 57.141.18.22:37356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XXnKwMdFW9UVnNBSs0AABCxI"]
[Mon Jul 20 06:41:04.644019 2026] [security2:error] [pid 983757:tid 983902] [client 136.144.35.249:34305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XYHKwMdFW9UVnNBStVgAAARc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:04.650835 2026] [core:error] [pid 983757:tid 983930] [client 14.225.17.146:62278] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/oldsite
[Mon Jul 20 06:41:04.650852 2026] [core:error] [pid 983757:tid 983930] [client 14.225.17.146:62278] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/oldsite
[Mon Jul 20 06:41:04.653989 2026] [security2:error] [pid 983757:tid 983922] [client 50.116.65.227:31088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XYHKwMdFW9UVnNBStWQAAASs"]
[Mon Jul 20 06:41:04.667307 2026] [security2:error] [pid 966386:tid 966629] [client 50.116.65.227:31094] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XYDrLBqY1mBmWu_YeWgAAAEM"]
[Mon Jul 20 06:41:04.715117 2026] [security2:error] [pid 966386:tid 966650] [client 197.186.66.42:51989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XYDrLBqY1mBmWu_YeXgAAAFg"]
[Mon Jul 20 06:41:04.715239 2026] [security2:error] [pid 966386:tid 966650] [client 197.186.66.42:51989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XYDrLBqY1mBmWu_YeXgAAAFg"]
[Mon Jul 20 06:41:04.715267 2026] [security2:error] [pid 966386:tid 966657] [client 77.110.127.138:52575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XYDrLBqY1mBmWu_YeXQAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:04.715344 2026] [security2:error] [pid 966386:tid 966657] [client 77.110.127.138:52575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XYDrLBqY1mBmWu_YeXQAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:04.912428 2026] [security2:error] [pid 983757:tid 983897] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XYHKwMdFW9UVnNBStYQAAARI"]
[Mon Jul 20 06:41:04.917140 2026] [security2:error] [pid 983757:tid 983842] [remote 45.150.79.142:42896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4XYHKwMdFW9UVnNBStaAABGlI"]
[Mon Jul 20 06:41:04.985513 2026] [security2:error] [pid 983757:tid 983909] [client 112.208.70.94:43229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XYHKwMdFW9UVnNBStagAAAR4"]
[Mon Jul 20 06:41:04.985622 2026] [security2:error] [pid 983757:tid 983909] [client 112.208.70.94:43229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XYHKwMdFW9UVnNBStagAAAR4"]
[Mon Jul 20 06:41:05.093497 2026] [security2:error] [pid 983757:tid 983975] [client 136.144.35.248:64079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XYXKwMdFW9UVnNBStcAAAAWA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:05.111069 2026] [security2:error] [pid 966386:tid 966598] [client 14.225.17.146:62400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4XYDrLBqY1mBmWu_YeZQAAACQ"], referer: https://ccsdifference.com/oldsite
[Mon Jul 20 06:41:05.169297 2026] [security2:error] [pid 983757:tid 983886] [remote 45.150.79.142:42896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4XYXKwMdFW9UVnNBSteQABRX4"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:41:05.288870 2026] [security2:error] [pid 966386:tid 966645] [client 34.73.38.214:49434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XYTrLBqY1mBmWu_YefAAAAFM"]
[Mon Jul 20 06:41:05.362007 2026] [security2:error] [pid 983757:tid 983990] [client 14.225.17.146:62226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4XYXKwMdFW9UVnNBStegAAAW8"], referer: http://alrowad-hub.net/oldsite
[Mon Jul 20 06:41:05.471913 2026] [security2:error] [pid 983757:tid 983997] [client 223.237.130.40:54105] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XYXKwMdFW9UVnNBSttwAAAXY"]
[Mon Jul 20 06:41:05.488174 2026] [security2:error] [pid 983757:tid 983997] [client 223.237.130.40:54105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XYXKwMdFW9UVnNBSttwAAAXY"]
[Mon Jul 20 06:41:05.543460 2026] [security2:error] [pid 983757:tid 983927] [client 74.7.227.179:38948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XYXKwMdFW9UVnNBStswABMB4"], referer: https://tejasenvironmental.com/p=3525271
[Mon Jul 20 06:41:05.561132 2026] [security2:error] [pid 983757:tid 983937] [client 136.144.35.252:55459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XYXKwMdFW9UVnNBSt6gAAATo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:05.764641 2026] [security2:error] [pid 983757:tid 983763] [remote 91.142.222.105:60160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4XYXKwMdFW9UVnNBSuCwABbQM"]
[Mon Jul 20 06:41:05.963829 2026] [security2:error] [pid 983757:tid 984002] [client 57.141.18.79:61322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XYHKwMdFW9UVnNBStWwABe04"]
[Mon Jul 20 06:41:06.027826 2026] [security2:error] [pid 983757:tid 983925] [client 136.144.35.249:20607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XYnKwMdFW9UVnNBSuNQAAAS4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:06.268728 2026] [security2:error] [pid 983757:tid 983791] [remote 91.142.222.105:60160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4XYnKwMdFW9UVnNBSuPQABfh8"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 06:41:06.361495 2026] [security2:error] [pid 966386:tid 966491] [remote 202.51.202.242:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XYjrLBqY1mBmWu_YexwAATj0"]
[Mon Jul 20 06:41:06.398949 2026] [security2:error] [pid 966386:tid 966623] [client 14.225.17.146:61210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4XYTrLBqY1mBmWu_YeeAAAAD0"], referer: http://travelbyfire.com/oldsite
[Mon Jul 20 06:41:06.473228 2026] [security2:error] [pid 983757:tid 983987] [client 34.73.38.214:49338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XYnKwMdFW9UVnNBSuRwAAAWw"]
[Mon Jul 20 06:41:06.476550 2026] [security2:error] [pid 983757:tid 983937] [client 173.239.240.92:25223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XYnKwMdFW9UVnNBSuSAAAATo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:06.558334 2026] [security2:error] [pid 983757:tid 984013] [client 57.141.18.83:58820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XYXKwMdFW9UVnNBStigABhks"]
[Mon Jul 20 06:41:06.668101 2026] [security2:error] [pid 983757:tid 983905] [client 14.225.17.146:61615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4XYnKwMdFW9UVnNBSuQwAAARo"], referer: http://talknutritionwithlesley.com/oldsite
[Mon Jul 20 06:41:06.679640 2026] [security2:error] [pid 983757:tid 983818] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XYnKwMdFW9UVnNBSuUgABSzo"]
[Mon Jul 20 06:41:06.679799 2026] [security2:error] [pid 983757:tid 983954] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XYnKwMdFW9UVnNBSuUgABSzo"]
[Mon Jul 20 06:41:06.921828 2026] [security2:error] [pid 966386:tid 966512] [remote 202.51.202.242:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XYjrLBqY1mBmWu_Ye5QAAOFI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:41:06.934953 2026] [security2:error] [pid 983757:tid 983988] [client 173.239.240.30:57697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XYnKwMdFW9UVnNBSuZgAAAW0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:07.009065 2026] [security2:error] [pid 983757:tid 983858] [remote 5.252.52.249:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XY3KwMdFW9UVnNBSubgABD2I"]
[Mon Jul 20 06:41:07.011460 2026] [security2:error] [pid 983757:tid 983964] [client 152.58.191.29:63461] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XY3KwMdFW9UVnNBSubwAAAVU"]
[Mon Jul 20 06:41:07.016147 2026] [security2:error] [pid 983757:tid 983964] [client 152.58.191.29:63461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XY3KwMdFW9UVnNBSubwAAAVU"]
[Mon Jul 20 06:41:07.207954 2026] [security2:error] [pid 983757:tid 983836] [remote 5.252.52.249:59026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XY3KwMdFW9UVnNBSudgABMkw"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 06:41:07.290060 2026] [security2:error] [pid 966386:tid 966644] [client 57.141.18.57:33254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XYTrLBqY1mBmWu_YeowAAUk8"]
[Mon Jul 20 06:41:07.290100 2026] [security2:error] [pid 983757:tid 983992] [client 187.108.85.186:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XY3KwMdFW9UVnNBSuewAAAXE"]
[Mon Jul 20 06:41:07.290216 2026] [security2:error] [pid 983757:tid 983992] [client 187.108.85.186:57832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XY3KwMdFW9UVnNBSuewAAAXE"]
[Mon Jul 20 06:41:07.296687 2026] [security2:error] [pid 983757:tid 983893] [client 14.225.17.146:61295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4XY3KwMdFW9UVnNBSueQAAAQ4"], referer: https://travelbyfire.com/oldsite
[Mon Jul 20 06:41:07.412406 2026] [security2:error] [pid 983757:tid 983991] [client 173.239.240.30:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XY3KwMdFW9UVnNBSuhAAAAXA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:07.473574 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:52592] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 286 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XYzrLBqY1mBmWu_YfDQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:07.823332 2026] [security2:error] [pid 983757:tid 983925] [client 34.73.38.214:51806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XY3KwMdFW9UVnNBSunwAAAS4"]
[Mon Jul 20 06:41:07.880586 2026] [security2:error] [pid 966386:tid 966627] [client 173.239.240.100:20593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XYzrLBqY1mBmWu_YfHQAAAEE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:08.065580 2026] [security2:error] [pid 983757:tid 983916] [client 103.125.179.95:58223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XZHKwMdFW9UVnNBSuwQAAASU"]
[Mon Jul 20 06:41:08.065741 2026] [security2:error] [pid 983757:tid 983916] [client 103.125.179.95:58223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XZHKwMdFW9UVnNBSuwQAAASU"]
[Mon Jul 20 06:41:08.354938 2026] [security2:error] [pid 983757:tid 983891] [client 173.239.240.101:31901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XZHKwMdFW9UVnNBSu0AAAAQw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:08.675324 2026] [security2:error] [pid 966386:tid 966635] [client 57.141.18.115:39226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XYzrLBqY1mBmWu_Ye_QAASXM"]
[Mon Jul 20 06:41:08.757903 2026] [security2:error] [pid 983757:tid 983941] [client 103.238.106.162:60576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XZHKwMdFW9UVnNBSu6wAAAT4"]
[Mon Jul 20 06:41:08.758005 2026] [security2:error] [pid 983757:tid 983941] [client 103.238.106.162:60576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XZHKwMdFW9UVnNBSu6wAAAT4"]
[Mon Jul 20 06:41:08.826580 2026] [security2:error] [pid 983757:tid 984004] [client 34.73.38.214:49486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XZHKwMdFW9UVnNBSu8wAAAX0"]
[Mon Jul 20 06:41:08.836969 2026] [security2:error] [pid 983757:tid 983960] [client 136.144.35.243:32075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XZHKwMdFW9UVnNBSu8gAAAVE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:08.849180 2026] [security2:error] [pid 983757:tid 983962] [client 77.110.127.138:52601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZHKwMdFW9UVnNBSu-AAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:08.849264 2026] [security2:error] [pid 983757:tid 983962] [client 77.110.127.138:52601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZHKwMdFW9UVnNBSu-AAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:09.017689 2026] [security2:error] [pid 983757:tid 983928] [client 77.110.127.138:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZXKwMdFW9UVnNBSvAwAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:09.017788 2026] [security2:error] [pid 983757:tid 983928] [client 77.110.127.138:52603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZXKwMdFW9UVnNBSvAwAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:09.307238 2026] [security2:error] [pid 983757:tid 983927] [client 173.239.240.94:31991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XZXKwMdFW9UVnNBSvCgAAATA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:09.332267 2026] [security2:error] [pid 966386:tid 966589] [client 14.251.3.155:54590] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XZTrLBqY1mBmWu_YfQQAAABs"]
[Mon Jul 20 06:41:09.332821 2026] [security2:error] [pid 983757:tid 983906] [client 104.234.53.52:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XZXKwMdFW9UVnNBSvDAAAARs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:09.335616 2026] [security2:error] [pid 983757:tid 983934] [client 77.110.127.138:52609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZXKwMdFW9UVnNBSvDgAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:09.335744 2026] [security2:error] [pid 983757:tid 983934] [client 77.110.127.138:52609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZXKwMdFW9UVnNBSvDgAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:09.371736 2026] [security2:error] [pid 983757:tid 983894] [client 57.141.18.20:36304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XY3KwMdFW9UVnNBSuqAABDyM"]
[Mon Jul 20 06:41:09.548858 2026] [security2:error] [pid 983757:tid 983978] [client 217.142.18.172:22990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XZXKwMdFW9UVnNBSvGgAAAWM"]
[Mon Jul 20 06:41:09.548958 2026] [security2:error] [pid 983757:tid 983978] [client 217.142.18.172:22990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XZXKwMdFW9UVnNBSvGgAAAWM"]
[Mon Jul 20 06:41:09.566183 2026] [security2:error] [pid 983757:tid 983903] [client 66.249.74.72:65361] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.sherthingplacements.com"] [uri "/robots.txt"] [unique_id "al4XZXKwMdFW9UVnNBSvGwAAARg"]
[Mon Jul 20 06:41:09.688936 2026] [security2:error] [pid 966386:tid 966647] [client 34.73.38.214:51690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XZTrLBqY1mBmWu_YfTQAAAFU"]
[Mon Jul 20 06:41:09.780490 2026] [security2:error] [pid 983757:tid 983902] [client 173.239.240.97:21915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XZXKwMdFW9UVnNBSvJgAAARc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:09.956673 2026] [security2:error] [pid 983757:tid 983950] [client 57.141.18.110:52460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZHKwMdFW9UVnNBSu4AABRxM"]
[Mon Jul 20 06:41:10.138071 2026] [security2:error] [pid 983757:tid 983911] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XZHKwMdFW9UVnNBSuvgAAASA"]
[Mon Jul 20 06:41:10.150061 2026] [security2:error] [pid 983757:tid 983886] [remote 176.56.118.182:35896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4XZnKwMdFW9UVnNBSvPQABMn4"]
[Mon Jul 20 06:41:10.257219 2026] [security2:error] [pid 983757:tid 983906] [client 136.144.35.243:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XZnKwMdFW9UVnNBSvQAAAARs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:10.288018 2026] [security2:error] [pid 966386:tid 966688] [client 57.141.18.114:55600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZDrLBqY1mBmWu_YfNAAAe3Q"]
[Mon Jul 20 06:41:10.332253 2026] [security2:error] [pid 983757:tid 984005] [client 77.110.127.138:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZnKwMdFW9UVnNBSvQwAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:10.332372 2026] [security2:error] [pid 983757:tid 984005] [client 77.110.127.138:52620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZnKwMdFW9UVnNBSvQwAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:10.352465 2026] [security2:error] [pid 966386:tid 966432] [remote 47.86.33.52:25324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4XZjrLBqY1mBmWu_YfWAAAKQU"]
[Mon Jul 20 06:41:10.390286 2026] [security2:error] [pid 983757:tid 983845] [remote 176.56.118.182:35896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4XZnKwMdFW9UVnNBSvRQABW1U"], referer: https://justinagrayman.com/wp-login.php
[Mon Jul 20 06:41:10.423228 2026] [security2:error] [pid 983757:tid 983994] [client 57.141.18.79:61352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZHKwMdFW9UVnNBSu_QABcyE"]
[Mon Jul 20 06:41:10.567350 2026] [security2:error] [pid 983757:tid 983951] [client 57.141.18.17:21062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZXKwMdFW9UVnNBSvCAABSF8"]
[Mon Jul 20 06:41:10.597200 2026] [security2:error] [pid 983757:tid 984006] [client 77.110.127.138:52624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZnKwMdFW9UVnNBSvWAAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:10.597307 2026] [security2:error] [pid 983757:tid 984006] [client 77.110.127.138:52624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZnKwMdFW9UVnNBSvWAAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:10.649338 2026] [authz_core:error] [pid 983757:tid 983993] [client 66.132.224.82:11414] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:41:10.738776 2026] [security2:error] [pid 983757:tid 983967] [client 173.239.240.90:54857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XZnKwMdFW9UVnNBSvYAAAAVg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:10.858778 2026] [security2:error] [pid 966386:tid 966660] [client 77.110.127.138:52626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZjrLBqY1mBmWu_YfZQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:10.858917 2026] [security2:error] [pid 966386:tid 966660] [client 77.110.127.138:52626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZjrLBqY1mBmWu_YfZQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:10.870074 2026] [security2:error] [pid 983757:tid 983977] [client 223.185.13.213:1718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XZnKwMdFW9UVnNBSvZQAAAWI"]
[Mon Jul 20 06:41:10.870170 2026] [security2:error] [pid 983757:tid 983977] [client 223.185.13.213:1718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XZnKwMdFW9UVnNBSvZQAAAWI"]
[Mon Jul 20 06:41:10.881900 2026] [security2:error] [pid 983757:tid 983923] [client 172.232.181.107:46330] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5020.bluehost.com"] [uri "/"] [unique_id "al4XZnKwMdFW9UVnNBSvZgAAASw"]
[Mon Jul 20 06:41:11.180929 2026] [security2:error] [pid 983757:tid 983924] [client 34.73.38.214:52836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XZ3KwMdFW9UVnNBSvfgAAAS0"]
[Mon Jul 20 06:41:11.209624 2026] [security2:error] [pid 983757:tid 983890] [client 173.239.240.90:33227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvfwAAAQs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:11.373425 2026] [security2:error] [pid 983757:tid 983928] [client 57.141.18.27:64926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZXKwMdFW9UVnNBSvLAABMRc"]
[Mon Jul 20 06:41:11.387978 2026] [security2:error] [pid 983757:tid 983921] [client 77.110.127.138:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvhwAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:11.388090 2026] [security2:error] [pid 983757:tid 983921] [client 77.110.127.138:52628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvhwAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:11.631764 2026] [security2:error] [pid 983757:tid 983934] [client 77.110.127.138:52630] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 329 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XZ3KwMdFW9UVnNBSvmQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:11.673946 2026] [security2:error] [pid 983757:tid 983991] [client 136.144.35.245:63463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvmgAAAXA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:11.765140 2026] [security2:error] [pid 966386:tid 966630] [client 34.73.38.214:53434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XZzrLBqY1mBmWu_YfdgAAAEQ"]
[Mon Jul 20 06:41:11.985308 2026] [security2:error] [pid 983757:tid 983974] [client 39.48.81.23:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvsQAAAV8"]
[Mon Jul 20 06:41:11.985523 2026] [security2:error] [pid 983757:tid 983974] [client 39.48.81.23:59842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvsQAAAV8"]
[Mon Jul 20 06:41:12.074244 2026] [security2:error] [pid 966386:tid 966567] [client 57.141.18.73:24386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZjrLBqY1mBmWu_YfZAAABUo"]
[Mon Jul 20 06:41:12.123072 2026] [security2:error] [pid 983757:tid 983951] [client 173.239.240.99:34087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XaHKwMdFW9UVnNBSvuAAAAUg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:12.361480 2026] [security2:error] [pid 966386:tid 966475] [remote 47.86.33.52:25324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4XaDrLBqY1mBmWu_YffwAAcS4"], referer: https://fluidtemple.org/wp-login.php
[Mon Jul 20 06:41:12.488301 2026] [security2:error] [pid 983757:tid 983891] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XaHKwMdFW9UVnNBSvwQAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:12.604452 2026] [security2:error] [pid 983757:tid 983940] [client 136.144.35.245:63767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XaHKwMdFW9UVnNBSv0gAAAT0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:12.670848 2026] [core:error] [pid 983757:tid 983964] [client 14.225.17.146:61793] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:12.670873 2026] [core:error] [pid 983757:tid 983964] [client 14.225.17.146:61793] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:12.769110 2026] [security2:error] [pid 966386:tid 966612] [client 34.73.38.214:50959] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XaDrLBqY1mBmWu_YfkAAAADI"]
[Mon Jul 20 06:41:12.997509 2026] [security2:error] [pid 983757:tid 984011] [client 57.141.18.101:55754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XZ3KwMdFW9UVnNBSvnAABhDA"]
[Mon Jul 20 06:41:13.005891 2026] [security2:error] [pid 966386:tid 966653] [client 104.234.53.86:25935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XaDrLBqY1mBmWu_YflgAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:13.071314 2026] [security2:error] [pid 983757:tid 983941] [client 136.144.35.247:31333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XaXKwMdFW9UVnNBSv5gAAAT4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:13.325530 2026] [security2:error] [pid 966386:tid 966570] [client 65.111.24.59:41315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XaTrLBqY1mBmWu_YfqAAAAAg"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:41:13.356801 2026] [security2:error] [pid 983757:tid 983975] [client 57.141.18.88:39232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XaHKwMdFW9UVnNBSvtwABYD8"]
[Mon Jul 20 06:41:13.415223 2026] [security2:error] [pid 966386:tid 966590] [client 65.111.29.63:9443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XaTrLBqY1mBmWu_YfqQAAABw"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:13.559962 2026] [security2:error] [pid 983757:tid 983958] [client 136.144.35.253:52613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XaXKwMdFW9UVnNBSv_QAAAU8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:13.910071 2026] [security2:error] [pid 966386:tid 966683] [client 57.141.18.67:20036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XaDrLBqY1mBmWu_YfhwAAdgo"]
[Mon Jul 20 06:41:14.006134 2026] [security2:error] [pid 983757:tid 983965] [client 57.141.18.68:45856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XaHKwMdFW9UVnNBSv1gABVhk"]
[Mon Jul 20 06:41:14.028983 2026] [security2:error] [pid 983757:tid 983916] [client 136.144.35.245:34511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XanKwMdFW9UVnNBSwFAAAASU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:14.161089 2026] [security2:error] [pid 983757:tid 983917] [client 171.61.165.146:15058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XanKwMdFW9UVnNBSwGAAAASY"]
[Mon Jul 20 06:41:14.161189 2026] [security2:error] [pid 983757:tid 983917] [client 171.61.165.146:15058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XanKwMdFW9UVnNBSwGAAAASY"]
[Mon Jul 20 06:41:14.259553 2026] [security2:error] [pid 983757:tid 984005] [client 106.219.188.178:8607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XanKwMdFW9UVnNBSwIAAAAX4"]
[Mon Jul 20 06:41:14.271244 2026] [security2:error] [pid 983757:tid 984005] [client 106.219.188.178:8607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XanKwMdFW9UVnNBSwIAAAAX4"]
[Mon Jul 20 06:41:14.409912 2026] [security2:error] [pid 966386:tid 966671] [client 34.73.38.214:63822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.awj.kzx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XajrLBqY1mBmWu_YfwwAAAGo"]
[Mon Jul 20 06:41:14.457304 2026] [security2:error] [pid 983757:tid 983922] [client 57.141.18.93:30874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XaXKwMdFW9UVnNBSv6QABK2Y"]
[Mon Jul 20 06:41:14.491746 2026] [security2:error] [pid 966386:tid 966596] [client 173.239.240.90:44779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XajrLBqY1mBmWu_YfxQAAACI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:14.812317 2026] [security2:error] [pid 983757:tid 983948] [client 57.141.18.78:34366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XaXKwMdFW9UVnNBSv8wABRXo"]
[Mon Jul 20 06:41:14.903889 2026] [security2:error] [pid 966386:tid 966665] [client 172.232.181.107:47262] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5020.bluehost.com"] [uri "/"] [unique_id "al4XajrLBqY1mBmWu_Yf2AAAAGY"]
[Mon Jul 20 06:41:14.947982 2026] [security2:error] [pid 983757:tid 983919] [client 173.239.240.102:36629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XanKwMdFW9UVnNBSwRgAAASg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:15.021203 2026] [fcgid:warn] [pid 966386:tid 966594] (70014)End of file found: [client 167.233.233.131:45546] mod_fcgid: can't get data from http client
[Mon Jul 20 06:41:15.068587 2026] [security2:error] [pid 983757:tid 984010] [client 57.141.18.7:47100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XaXKwMdFW9UVnNBSwDAABg0g"]
[Mon Jul 20 06:41:15.430882 2026] [security2:error] [pid 983757:tid 983892] [client 136.144.35.251:53471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwYwAAAQ0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:15.507059 2026] [security2:error] [pid 966386:tid 966648] [client 77.110.127.138:52673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XazrLBqY1mBmWu_Yf4QAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:15.507152 2026] [security2:error] [pid 966386:tid 966648] [client 77.110.127.138:52673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XazrLBqY1mBmWu_Yf4QAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:15.716186 2026] [security2:error] [pid 983757:tid 983921] [client 112.208.70.94:43657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Xa3KwMdFW9UVnNBSweQAAASo"]
[Mon Jul 20 06:41:15.716290 2026] [security2:error] [pid 983757:tid 983921] [client 112.208.70.94:43657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Xa3KwMdFW9UVnNBSweQAAASo"]
[Mon Jul 20 06:41:15.884835 2026] [security2:error] [pid 966386:tid 966595] [client 136.144.35.248:59025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XazrLBqY1mBmWu_Yf8QAAACE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:16.014884 2026] [security2:error] [pid 983757:tid 983979] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwZQAAAWQ"]
[Mon Jul 20 06:41:16.103079 2026] [security2:error] [pid 983757:tid 983917] [client 65.1.132.125:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XbHKwMdFW9UVnNBSwjQAAASY"]
[Mon Jul 20 06:41:16.103186 2026] [security2:error] [pid 983757:tid 983917] [client 65.1.132.125:58526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XbHKwMdFW9UVnNBSwjQAAASY"]
[Mon Jul 20 06:41:16.118145 2026] [security2:error] [pid 983757:tid 983876] [remote 57.141.18.10:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4927482"] [unique_id "al4XbHKwMdFW9UVnNBSwjAABEnQ"]
[Mon Jul 20 06:41:16.136884 2026] [security2:error] [pid 966386:tid 966637] [client 223.237.130.40:54523] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XbDrLBqY1mBmWu_Yf-AAAAEs"]
[Mon Jul 20 06:41:16.143160 2026] [security2:error] [pid 966386:tid 966637] [client 223.237.130.40:54523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XbDrLBqY1mBmWu_Yf-AAAAEs"]
[Mon Jul 20 06:41:16.259615 2026] [security2:error] [pid 983757:tid 983980] [client 57.141.18.49:32706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwUQABZXc"]
[Mon Jul 20 06:41:16.354473 2026] [security2:error] [pid 983757:tid 984013] [client 173.239.240.100:36443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XbHKwMdFW9UVnNBSwmQAAAYY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:16.415403 2026] [security2:error] [pid 983757:tid 983910] [client 77.110.127.138:52680] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 246 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XbHKwMdFW9UVnNBSwnwAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:16.608511 2026] [security2:error] [pid 983757:tid 983983] [client 57.141.18.39:52561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwYgABaBM"]
[Mon Jul 20 06:41:16.666184 2026] [security2:error] [pid 966386:tid 966664] [client 14.225.17.146:61739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4XbDrLBqY1mBmWu_YgBQAAAGU"], referer: http://katsklar.com/oldsite
[Mon Jul 20 06:41:16.805315 2026] [security2:error] [pid 983757:tid 983936] [client 136.144.35.246:54535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XbHKwMdFW9UVnNBSwtwAAATk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:16.895735 2026] [security2:error] [pid 966386:tid 966630] [client 104.234.53.61:54675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XbDrLBqY1mBmWu_YgCgAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:16.903595 2026] [security2:error] [pid 983757:tid 983971] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XbHKwMdFW9UVnNBSwrQAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:16.979963 2026] [security2:error] [pid 983757:tid 983928] [client 14.225.17.146:61819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwbAAAATE"], referer: http://colinkeyphotography.com/oldsite
[Mon Jul 20 06:41:17.064072 2026] [security2:error] [pid 983757:tid 983889] [client 57.141.18.6:48788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwhQABCjI"]
[Mon Jul 20 06:41:17.259597 2026] [security2:error] [pid 966386:tid 966653] [client 173.239.240.30:64689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XbTrLBqY1mBmWu_YgGQAAAFs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:17.403255 2026] [security2:error] [pid 966386:tid 966500] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XbTrLBqY1mBmWu_YgHQAAT0Y"]
[Mon Jul 20 06:41:17.403440 2026] [security2:error] [pid 966386:tid 966641] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XbTrLBqY1mBmWu_YgHQAAT0Y"]
[Mon Jul 20 06:41:17.488555 2026] [security2:error] [pid 966386:tid 966577] [client 104.234.53.61:54675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XbTrLBqY1mBmWu_YgIwAAAA8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:17.569660 2026] [security2:error] [pid 966386:tid 966609] [client 152.58.191.29:55183] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XbTrLBqY1mBmWu_YgKAAAAC8"]
[Mon Jul 20 06:41:17.584142 2026] [security2:error] [pid 966386:tid 966609] [client 152.58.191.29:55183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XbTrLBqY1mBmWu_YgKAAAAC8"]
[Mon Jul 20 06:41:17.713157 2026] [security2:error] [pid 983757:tid 983997] [client 136.144.35.252:24225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XbXKwMdFW9UVnNBSw4gAAAXY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:17.873082 2026] [security2:error] [pid 983757:tid 983996] [client 187.108.85.186:58376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XbXKwMdFW9UVnNBSw6wAAAXU"]
[Mon Jul 20 06:41:17.873245 2026] [security2:error] [pid 983757:tid 983996] [client 187.108.85.186:58376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XbXKwMdFW9UVnNBSw6wAAAXU"]
[Mon Jul 20 06:41:17.975295 2026] [security2:error] [pid 983757:tid 983949] [client 14.225.17.146:62941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4XbHKwMdFW9UVnNBSwmwAAAUY"], referer: http://myspineworld.com/oldsite
[Mon Jul 20 06:41:18.098613 2026] [security2:error] [pid 983757:tid 983899] [client 14.225.17.146:61928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4Xa3KwMdFW9UVnNBSwgwAAARQ"]
[Mon Jul 20 06:41:18.173460 2026] [security2:error] [pid 983757:tid 983911] [client 136.144.35.249:55143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XbnKwMdFW9UVnNBSxBAAAASA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:18.180457 2026] [core:error] [pid 966386:tid 966532] [remote 198.235.24.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:18.180481 2026] [core:error] [pid 966386:tid 966532] [remote 198.235.24.19:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:18.214421 2026] [security2:error] [pid 966386:tid 966583] [client 74.208.214.194:49830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XbjrLBqY1mBmWu_YgPAAAABU"]
[Mon Jul 20 06:41:18.470106 2026] [security2:error] [pid 966386:tid 966668] [client 104.234.53.91:49479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XbjrLBqY1mBmWu_YgTQAAAGg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:18.632132 2026] [security2:error] [pid 983757:tid 983903] [client 173.239.240.97:48265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XbnKwMdFW9UVnNBSxHAAAARg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:18.871551 2026] [security2:error] [pid 983757:tid 983906] [client 172.232.181.107:47270] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5020.bluehost.com"] [uri "/"] [unique_id "al4XbnKwMdFW9UVnNBSxLgAAARs"]
[Mon Jul 20 06:41:18.880895 2026] [security2:error] [pid 983757:tid 983869] [remote 20.153.140.50:46616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XbnKwMdFW9UVnNBSxLQABUG0"]
[Mon Jul 20 06:41:18.896029 2026] [security2:error] [pid 966386:tid 966582] [client 197.186.66.42:52796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XbjrLBqY1mBmWu_YgWgAAABQ"]
[Mon Jul 20 06:41:18.919973 2026] [security2:error] [pid 966386:tid 966582] [client 197.186.66.42:52796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XbjrLBqY1mBmWu_YgWgAAABQ"]
[Mon Jul 20 06:41:18.973841 2026] [security2:error] [pid 966386:tid 966681] [client 14.225.17.146:56987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4XbjrLBqY1mBmWu_YgVwAAAHQ"], referer: https://myspineworld.com/oldsite
[Mon Jul 20 06:41:18.980625 2026] [security2:error] [pid 966386:tid 966675] [client 103.125.179.95:58737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XbjrLBqY1mBmWu_YgYQAAAG4"]
[Mon Jul 20 06:41:18.980865 2026] [security2:error] [pid 983757:tid 983928] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XbnKwMdFW9UVnNBSxLAAAATE"]
[Mon Jul 20 06:41:18.980977 2026] [security2:error] [pid 966386:tid 966675] [client 103.125.179.95:58737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XbjrLBqY1mBmWu_YgYQAAAG4"]
[Mon Jul 20 06:41:19.123675 2026] [security2:error] [pid 983757:tid 983897] [client 173.239.240.97:54919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxQwAAARI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:19.293762 2026] [security2:error] [pid 983757:tid 983831] [remote 20.153.140.50:46616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxTwABVEc"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 06:41:19.339405 2026] [core:error] [pid 983757:tid 983935] [client 66.132.224.82:33460] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:19.339426 2026] [core:error] [pid 983757:tid 983935] [client 66.132.224.82:33460] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:19.380995 2026] [security2:error] [pid 983757:tid 983908] [client 103.238.106.162:60806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxUwAAAR0"]
[Mon Jul 20 06:41:19.381662 2026] [security2:error] [pid 983757:tid 983908] [client 103.238.106.162:60806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxUwAAAR0"]
[Mon Jul 20 06:41:19.522693 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:52694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XbzrLBqY1mBmWu_YgdQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:19.522802 2026] [security2:error] [pid 966386:tid 966687] [client 77.110.127.138:52694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XbzrLBqY1mBmWu_YgdQAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:19.590253 2026] [security2:error] [pid 983757:tid 983984] [client 173.239.240.90:28941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxWQAAAWk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:20.042304 2026] [security2:error] [pid 983757:tid 983944] [client 217.142.18.172:21146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XcHKwMdFW9UVnNBSxcwAAAUE"]
[Mon Jul 20 06:41:20.042413 2026] [security2:error] [pid 983757:tid 983944] [client 217.142.18.172:21146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XcHKwMdFW9UVnNBSxcwAAAUE"]
[Mon Jul 20 06:41:20.044374 2026] [security2:error] [pid 983757:tid 984005] [client 136.144.35.244:59973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XcHKwMdFW9UVnNBSxdgAAAX4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:20.174801 2026] [security2:error] [pid 966386:tid 966659] [client 57.141.18.24:40884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XbzrLBqY1mBmWu_YgYgAAYAI"]
[Mon Jul 20 06:41:20.228411 2026] [security2:error] [pid 983757:tid 983986] [client 136.64.212.75:20860] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "membresiabeyou.com"] [uri "/"] [unique_id "al4XcHKwMdFW9UVnNBSxgAAAAWs"]
[Mon Jul 20 06:41:20.291107 2026] [security2:error] [pid 983757:tid 983913] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxbQABIhQ"], referer: http://aleishapenny.ca/oldsite
[Mon Jul 20 06:41:20.404697 2026] [security2:error] [pid 983757:tid 983921] [client 57.141.18.68:32594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxTQABKhw"]
[Mon Jul 20 06:41:20.536928 2026] [security2:error] [pid 983757:tid 983936] [client 114.119.148.4:59277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "securingmemories.com"] [uri "/index.php/portfolio-item/50-questions-to-ask-your-kids-other-than-how-was-school"] [unique_id "al4XcHKwMdFW9UVnNBSxlwAAATk"], referer: https://securingmemories.com/index.php/portfolio-item/legacy-starter-kit
[Mon Jul 20 06:41:20.549510 2026] [security2:error] [pid 983757:tid 983984] [client 173.239.240.32:41005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxmQAAAWk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:20.870705 2026] [security2:error] [pid 983757:tid 983992] [client 57.141.18.69:50374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xb3KwMdFW9UVnNBSxYwABcVk"]
[Mon Jul 20 06:41:20.949030 2026] [security2:error] [pid 966386:tid 966608] [client 223.185.13.213:8069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XcDrLBqY1mBmWu_YgjQAAAC4"]
[Mon Jul 20 06:41:20.949189 2026] [security2:error] [pid 966386:tid 966608] [client 223.185.13.213:8069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XcDrLBqY1mBmWu_YgjQAAAC4"]
[Mon Jul 20 06:41:20.984380 2026] [security2:error] [pid 983757:tid 983939] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxqwAAATw"]
[Mon Jul 20 06:41:21.018618 2026] [security2:error] [pid 983757:tid 983935] [client 173.239.240.95:45241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XcXKwMdFW9UVnNBSxtQAAATg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:21.028490 2026] [security2:error] [pid 983757:tid 983933] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxrwABNlc"], referer: https://aleishapenny.ca/oldsite
[Mon Jul 20 06:41:21.071506 2026] [security2:error] [pid 983757:tid 983803] [remote 72.167.132.114:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4XcXKwMdFW9UVnNBSxtwABSSs"]
[Mon Jul 20 06:41:21.110850 2026] [security2:error] [pid 983757:tid 983977] [client 14.225.17.146:62786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxoQAAAWI"], referer: http://backandneckpainrelieflaceychiropractor.com/oldsite
[Mon Jul 20 06:41:21.282603 2026] [security2:error] [pid 983757:tid 983987] [client 57.141.18.114:24874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxhAABbGY"]
[Mon Jul 20 06:41:21.327049 2026] [security2:error] [pid 983757:tid 983816] [remote 72.167.132.114:50646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4XcXKwMdFW9UVnNBSxvwABhjg"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:41:21.389356 2026] [security2:error] [pid 983757:tid 983905] [client 57.141.18.20:53296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxhgABGlQ"]
[Mon Jul 20 06:41:21.414453 2026] [security2:error] [pid 983757:tid 983904] [client 35.187.45.1:55296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XcXKwMdFW9UVnNBSxwAAAARk"]
[Mon Jul 20 06:41:21.469900 2026] [security2:error] [pid 983757:tid 983980] [client 173.239.240.98:33197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XcXKwMdFW9UVnNBSxxAAAAWU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:21.559804 2026] [security2:error] [pid 983757:tid 983998] [client 35.187.45.1:40786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.45.187.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/install.php"] [unique_id "al4XcXKwMdFW9UVnNBSxygAAAXc"]
[Mon Jul 20 06:41:21.577249 2026] [security2:error] [pid 983757:tid 983934] [client 77.110.127.138:52704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 252 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XcXKwMdFW9UVnNBSxzwAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:21.929854 2026] [security2:error] [pid 983757:tid 983900] [client 136.144.35.244:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XcXKwMdFW9UVnNBSx5QAAARU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:21.948544 2026] [security2:error] [pid 983757:tid 983901] [client 14.225.17.146:62722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxegAAARY"], referer: http://narv.co/oldsite
[Mon Jul 20 06:41:21.955063 2026] [security2:error] [pid 983757:tid 984007] [client 35.187.45.1:55296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4XcXKwMdFW9UVnNBSx4AAAAYA"]
[Mon Jul 20 06:41:21.984023 2026] [security2:error] [pid 983757:tid 983928] [client 14.225.17.146:62791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4XcHKwMdFW9UVnNBSxpAAAATE"], referer: http://mourgroup.com/oldsite
[Mon Jul 20 06:41:22.096193 2026] [security2:error] [pid 966386:tid 966583] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XcTrLBqY1mBmWu_YgpAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:22.453056 2026] [security2:error] [pid 983757:tid 984008] [client 37.52.210.45:49171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XcnKwMdFW9UVnNBSyAAAAAYE"]
[Mon Jul 20 06:41:22.453455 2026] [security2:error] [pid 983757:tid 984008] [client 37.52.210.45:49171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XcnKwMdFW9UVnNBSyAAAAAYE"]
[Mon Jul 20 06:41:22.589375 2026] [security2:error] [pid 983757:tid 983914] [client 173.239.240.90:38475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XcnKwMdFW9UVnNBSyEwAAASM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:22.799849 2026] [security2:error] [pid 966386:tid 966601] [client 57.141.18.2:21520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcTrLBqY1mBmWu_YgnQAAJxY"]
[Mon Jul 20 06:41:22.880845 2026] [security2:error] [pid 983757:tid 984001] [client 172.232.181.107:59762] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5020.bluehost.com"] [uri "/"] [unique_id "al4XcnKwMdFW9UVnNBSyIQAAAXo"]
[Mon Jul 20 06:41:22.975103 2026] [security2:error] [pid 983757:tid 983994] [client 57.141.18.4:56750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcXKwMdFW9UVnNBSxzAABc1I"]
[Mon Jul 20 06:41:22.977210 2026] [security2:error] [pid 966386:tid 966629] [client 14.225.17.146:62789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4XcjrLBqY1mBmWu_YgvQAAAEM"], referer: https://narv.co/oldsite
[Mon Jul 20 06:41:23.054637 2026] [security2:error] [pid 966386:tid 966615] [client 65.111.28.75:55145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XczrLBqY1mBmWu_YgvwAAADU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:41:23.096007 2026] [security2:error] [pid 966386:tid 966510] [remote 95.217.78.234:38348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XczrLBqY1mBmWu_YgwgAAIFA"]
[Mon Jul 20 06:41:23.098292 2026] [security2:error] [pid 966386:tid 966672] [client 173.239.240.30:60481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XczrLBqY1mBmWu_YgwwAAAGs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:23.344969 2026] [security2:error] [pid 966386:tid 966439] [remote 95.217.78.234:38348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XczrLBqY1mBmWu_YgzAAADAw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:41:23.493151 2026] [security2:error] [pid 983757:tid 983889] [client 57.141.18.78:49732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcnKwMdFW9UVnNBSx8QABCmw"]
[Mon Jul 20 06:41:23.549098 2026] [security2:error] [pid 983757:tid 983914] [client 173.239.240.100:20365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xc3KwMdFW9UVnNBSyRwAAASM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:23.562350 2026] [security2:error] [pid 983757:tid 983992] [client 14.225.17.146:57429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Xc3KwMdFW9UVnNBSyPgAAAXE"]
[Mon Jul 20 06:41:23.731538 2026] [security2:error] [pid 983757:tid 983990] [client 104.207.33.191:60985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Xc3KwMdFW9UVnNBSyTQAAAW8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:23.846975 2026] [security2:error] [pid 983757:tid 983905] [client 57.141.18.2:21528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcnKwMdFW9UVnNBSx-QABGnk"]
[Mon Jul 20 06:41:23.949736 2026] [security2:error] [pid 983757:tid 983919] [client 57.141.18.34:39216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XcnKwMdFW9UVnNBSx-wABKC4"]
[Mon Jul 20 06:41:23.980973 2026] [security2:error] [pid 966386:tid 966489] [remote 20.153.140.50:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XczrLBqY1mBmWu_Yg0gAAKTs"]
[Mon Jul 20 06:41:24.076538 2026] [security2:error] [pid 983757:tid 983975] [client 173.239.240.30:20411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XdHKwMdFW9UVnNBSyXgAAAWA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:24.323739 2026] [core:error] [pid 966386:tid 966436] [remote 69.171.230.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:24.324317 2026] [core:error] [pid 966386:tid 966436] [remote 69.171.230.7:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:41:24.356955 2026] [security2:error] [pid 966386:tid 966581] [client 57.141.18.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XdDrLBqY1mBmWu_Yg3AAAABM"]
[Mon Jul 20 06:41:24.377775 2026] [security2:error] [pid 966386:tid 966483] [remote 20.153.140.50:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XdDrLBqY1mBmWu_Yg5QAASjU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:41:24.407133 2026] [security2:error] [pid 983757:tid 983962] [client 39.48.81.23:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XdHKwMdFW9UVnNBSycAAAAVM"]
[Mon Jul 20 06:41:24.407243 2026] [security2:error] [pid 983757:tid 983962] [client 39.48.81.23:60367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XdHKwMdFW9UVnNBSycAAAAVM"]
[Mon Jul 20 06:41:24.534785 2026] [security2:error] [pid 966386:tid 966586] [client 50.116.65.227:33664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XdDrLBqY1mBmWu_Yg6wAAABg"]
[Mon Jul 20 06:41:24.545565 2026] [security2:error] [pid 966386:tid 966651] [client 50.116.65.227:33676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XdDrLBqY1mBmWu_Yg7AAAAFk"]
[Mon Jul 20 06:41:24.552386 2026] [security2:error] [pid 983757:tid 983898] [client 173.239.240.92:27225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XdHKwMdFW9UVnNBSydwAAARM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:24.571405 2026] [security2:error] [pid 966386:tid 966572] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XdDrLBqY1mBmWu_Yg6QAAAAo"]
[Mon Jul 20 06:41:24.721139 2026] [security2:error] [pid 966386:tid 966613] [client 14.225.17.146:62901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4XczrLBqY1mBmWu_YgxQAAADM"], referer: http://slutilities.com/oldsite
[Mon Jul 20 06:41:24.731084 2026] [security2:error] [pid 983757:tid 983967] [client 77.110.127.138:52720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XdHKwMdFW9UVnNBSyfwAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:24.732031 2026] [security2:error] [pid 983757:tid 983967] [client 77.110.127.138:52720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XdHKwMdFW9UVnNBSyfwAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:24.764516 2026] [security2:error] [pid 983757:tid 983961] [client 14.251.3.155:54595] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XdHKwMdFW9UVnNBSyhAAAAVI"]
[Mon Jul 20 06:41:24.911138 2026] [security2:error] [pid 983757:tid 983981] [client 106.219.188.178:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XdHKwMdFW9UVnNBSyjgAAAWY"]
[Mon Jul 20 06:41:24.911367 2026] [security2:error] [pid 983757:tid 983981] [client 106.219.188.178:27757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XdHKwMdFW9UVnNBSyjgAAAWY"]
[Mon Jul 20 06:41:24.923228 2026] [security2:error] [pid 983757:tid 983912] [client 57.141.18.51:59454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xc3KwMdFW9UVnNBSyOwABIRc"]
[Mon Jul 20 06:41:25.069558 2026] [security2:error] [pid 983757:tid 983970] [client 173.239.240.102:36351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XdXKwMdFW9UVnNBSymgAAAVs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:25.084761 2026] [security2:error] [pid 983757:tid 983951] [client 57.141.18.59:20914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xc3KwMdFW9UVnNBSyQQABSDk"]
[Mon Jul 20 06:41:25.121729 2026] [security2:error] [pid 966386:tid 966643] [client 171.61.165.146:11063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XdTrLBqY1mBmWu_Yg_QAAAFE"]
[Mon Jul 20 06:41:25.121930 2026] [security2:error] [pid 966386:tid 966643] [client 171.61.165.146:11063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XdTrLBqY1mBmWu_Yg_QAAAFE"]
[Mon Jul 20 06:41:25.385818 2026] [security2:error] [pid 983757:tid 983978] [client 14.225.17.146:56799] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Xc3KwMdFW9UVnNBSyVQAAAWM"], referer: http://samdothan.org/oldsite
[Mon Jul 20 06:41:25.537445 2026] [security2:error] [pid 966386:tid 966645] [client 173.239.240.102:50363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XdTrLBqY1mBmWu_YhEgAAAFM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:25.554694 2026] [security2:error] [pid 983757:tid 983900] [client 52.109.124.141:21826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XdXKwMdFW9UVnNBSyrAAAARU"]
[Mon Jul 20 06:41:25.627888 2026] [security2:error] [pid 966386:tid 966582] [client 14.225.17.146:57531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4XdTrLBqY1mBmWu_YhEAAAABQ"], referer: http://longevityperformanceclinic.com/oldsite
[Mon Jul 20 06:41:25.739853 2026] [security2:error] [pid 983757:tid 983933] [client 52.109.124.141:21826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XdXKwMdFW9UVnNBSytQAAATY"]
[Mon Jul 20 06:41:25.820597 2026] [security2:error] [pid 983757:tid 983961] [client 50.116.65.227:33740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4XdXKwMdFW9UVnNBSyuwAAAVI"]
[Mon Jul 20 06:41:25.856941 2026] [security2:error] [pid 983757:tid 983973] [client 52.109.124.141:15392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XdXKwMdFW9UVnNBSyvgAAAV4"]
[Mon Jul 20 06:41:25.944406 2026] [security2:error] [pid 983757:tid 983905] [client 77.110.127.138:52732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 228 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XdXKwMdFW9UVnNBSyxwAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:26.006103 2026] [security2:error] [pid 983757:tid 984001] [client 173.239.240.101:21033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XdnKwMdFW9UVnNBSyywAAAXo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:26.034425 2026] [security2:error] [pid 983757:tid 983958] [client 52.109.124.141:15392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XdnKwMdFW9UVnNBSyzwAAAU8"]
[Mon Jul 20 06:41:26.418075 2026] [security2:error] [pid 983757:tid 983887] [remote 110.249.201.74:52900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/lutheran-philosopher-zoom-conversations/"] [unique_id "al4XdnKwMdFW9UVnNBSy6wABOn8"]
[Mon Jul 20 06:41:26.459597 2026] [security2:error] [pid 983757:tid 983957] [client 173.239.240.31:51095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XdnKwMdFW9UVnNBSy7gAAAU4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:26.698329 2026] [security2:error] [pid 983757:tid 983934] [client 104.234.53.87:64129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XdnKwMdFW9UVnNBSy_AAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:26.710848 2026] [security2:error] [pid 983757:tid 983972] [client 112.208.70.94:44097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XdnKwMdFW9UVnNBSzAgAAAV0"]
[Mon Jul 20 06:41:26.710959 2026] [security2:error] [pid 983757:tid 983972] [client 112.208.70.94:44097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XdnKwMdFW9UVnNBSzAgAAAV0"]
[Mon Jul 20 06:41:26.867542 2026] [security2:error] [pid 983757:tid 983923] [client 65.1.132.125:44164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XdnKwMdFW9UVnNBSzDQAAASw"]
[Mon Jul 20 06:41:26.867635 2026] [security2:error] [pid 983757:tid 983923] [client 65.1.132.125:44164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XdnKwMdFW9UVnNBSzDQAAASw"]
[Mon Jul 20 06:41:26.872778 2026] [security2:error] [pid 966386:tid 966621] [client 172.232.181.107:59766] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5020.bluehost.com"] [uri "/"] [unique_id "al4XdjrLBqY1mBmWu_YhNAAAADs"]
[Mon Jul 20 06:41:26.913016 2026] [security2:error] [pid 966386:tid 966591] [client 173.239.240.91:31953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XdjrLBqY1mBmWu_YhOAAAAB0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:27.010626 2026] [security2:error] [pid 983757:tid 983931] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XdnKwMdFW9UVnNBSzBwAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:27.041574 2026] [security2:error] [pid 966386:tid 966629] [client 57.141.18.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XdjrLBqY1mBmWu_YhNwAAAEM"]
[Mon Jul 20 06:41:27.127495 2026] [security2:error] [pid 966386:tid 966522] [remote 152.228.213.32:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4XdzrLBqY1mBmWu_YhOQAAFlw"]
[Mon Jul 20 06:41:27.135814 2026] [security2:error] [pid 983757:tid 983908] [client 223.237.130.40:54973] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4Xd3KwMdFW9UVnNBSzHQAAAR0"]
[Mon Jul 20 06:41:27.135927 2026] [security2:error] [pid 983757:tid 983908] [client 223.237.130.40:54973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4Xd3KwMdFW9UVnNBSzHQAAAR0"]
[Mon Jul 20 06:41:27.353366 2026] [security2:error] [pid 966386:tid 966524] [remote 152.228.213.32:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4XdzrLBqY1mBmWu_YhQQAAb14"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:41:27.354979 2026] [security2:error] [pid 983757:tid 983952] [client 57.141.18.42:51544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XdXKwMdFW9UVnNBSyuQABST8"]
[Mon Jul 20 06:41:27.405074 2026] [security2:error] [pid 966386:tid 966657] [client 136.144.35.250:55689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XdzrLBqY1mBmWu_YhRAAAAF8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:27.916810 2026] [security2:error] [pid 966386:tid 966605] [client 173.239.240.94:51079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XdzrLBqY1mBmWu_YhVAAAACs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:27.978288 2026] [security2:error] [pid 966386:tid 966680] [client 14.225.17.146:57237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4XdjrLBqY1mBmWu_YhJQAAAHM"], referer: http://nomorewetsheets.net/oldsite
[Mon Jul 20 06:41:27.986580 2026] [security2:error] [pid 983757:tid 983892] [client 216.73.217.138:5396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Xd3KwMdFW9UVnNBSzRwABDQA"]
[Mon Jul 20 06:41:28.015308 2026] [security2:error] [pid 966386:tid 966505] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XeDrLBqY1mBmWu_YhWgAAH0s"]
[Mon Jul 20 06:41:28.015461 2026] [security2:error] [pid 966386:tid 966593] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XeDrLBqY1mBmWu_YhWgAAH0s"]
[Mon Jul 20 06:41:28.086284 2026] [security2:error] [pid 983757:tid 983876] [remote 162.19.86.63:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XeHKwMdFW9UVnNBSzWwABF3Q"]
[Mon Jul 20 06:41:28.111389 2026] [security2:error] [pid 983757:tid 983974] [client 57.141.18.89:31402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XdnKwMdFW9UVnNBSy5gABX1E"]
[Mon Jul 20 06:41:28.218380 2026] [security2:error] [pid 983757:tid 984004] [client 152.58.191.29:42330] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XeHKwMdFW9UVnNBSzZAAAAX0"]
[Mon Jul 20 06:41:28.218485 2026] [security2:error] [pid 983757:tid 984004] [client 152.58.191.29:42330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XeHKwMdFW9UVnNBSzZAAAAX0"]
[Mon Jul 20 06:41:28.277538 2026] [security2:error] [pid 983757:tid 983779] [remote 162.19.86.63:33228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XeHKwMdFW9UVnNBSzZwABXhM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:41:28.403519 2026] [security2:error] [pid 983757:tid 983896] [client 173.239.240.90:33989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XeHKwMdFW9UVnNBSzbgAAARE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:28.552960 2026] [security2:error] [pid 966386:tid 966595] [client 187.108.85.186:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XeDrLBqY1mBmWu_YhYQAAACE"]
[Mon Jul 20 06:41:28.553081 2026] [security2:error] [pid 966386:tid 966595] [client 187.108.85.186:58926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XeDrLBqY1mBmWu_YhYQAAACE"]
[Mon Jul 20 06:41:28.691737 2026] [security2:error] [pid 983757:tid 983980] [client 14.225.17.146:57693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4Xd3KwMdFW9UVnNBSzJwAAAWU"], referer: http://alchemygroup.ca/oldsite
[Mon Jul 20 06:41:28.874566 2026] [security2:error] [pid 966386:tid 966660] [client 173.239.240.90:35987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XeDrLBqY1mBmWu_YhagAAAGE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:29.333025 2026] [security2:error] [pid 983757:tid 983969] [client 104.234.53.87:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XeXKwMdFW9UVnNBSzpQAAAVo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:29.335993 2026] [security2:error] [pid 966386:tid 966591] [client 173.239.240.98:57341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XeTrLBqY1mBmWu_YhdgAAAB0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:29.475696 2026] [security2:error] [pid 983757:tid 983953] [client 38.154.224.14:58699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4Xd3KwMdFW9UVnNBSzSAAAAUo"]
[Mon Jul 20 06:41:29.491767 2026] [security2:error] [pid 966386:tid 966584] [client 34.139.11.221:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.dienerranch.com"] [uri "/xmlrpc.php"] [unique_id "al4XeTrLBqY1mBmWu_YhfAAAABY"]
[Mon Jul 20 06:41:29.552629 2026] [security2:error] [pid 983757:tid 983932] [client 14.251.3.155:61331] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XeXKwMdFW9UVnNBSzsQAAATU"]
[Mon Jul 20 06:41:29.631991 2026] [security2:error] [pid 966386:tid 966655] [client 34.139.11.221:53862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XeTrLBqY1mBmWu_YhfQAAAF0"]
[Mon Jul 20 06:41:29.674709 2026] [security2:error] [pid 966386:tid 966633] [client 77.110.127.138:52760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XeTrLBqY1mBmWu_YhgAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:29.674807 2026] [security2:error] [pid 966386:tid 966633] [client 77.110.127.138:52760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XeTrLBqY1mBmWu_YhgAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:29.798620 2026] [security2:error] [pid 966386:tid 966574] [client 34.139.11.221:61025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XeTrLBqY1mBmWu_YhhQAAAAw"]
[Mon Jul 20 06:41:29.801370 2026] [security2:error] [pid 966386:tid 966676] [client 173.239.240.94:42601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XeTrLBqY1mBmWu_YhhgAAAG8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:29.939090 2026] [security2:error] [pid 966386:tid 966614] [client 34.139.11.221:51811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XeTrLBqY1mBmWu_YhjgAAADQ"]
[Mon Jul 20 06:41:30.008361 2026] [security2:error] [pid 983757:tid 983993] [client 103.238.106.162:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XenKwMdFW9UVnNBSzwQAAAXI"]
[Mon Jul 20 06:41:30.008951 2026] [security2:error] [pid 983757:tid 983993] [client 103.238.106.162:60906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XenKwMdFW9UVnNBSzwQAAAXI"]
[Mon Jul 20 06:41:30.110478 2026] [security2:error] [pid 983757:tid 983971] [client 34.139.11.221:61598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XenKwMdFW9UVnNBSzzwAAAVw"]
[Mon Jul 20 06:41:30.138135 2026] [security2:error] [pid 983757:tid 983990] [client 122.183.32.225:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XenKwMdFW9UVnNBSz0gAAAW8"]
[Mon Jul 20 06:41:30.138268 2026] [security2:error] [pid 983757:tid 983990] [client 122.183.32.225:1062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XenKwMdFW9UVnNBSz0gAAAW8"]
[Mon Jul 20 06:41:30.153686 2026] [security2:error] [pid 983757:tid 983924] [client 50.116.65.227:51728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4XenKwMdFW9UVnNBSz1AAAAS0"]
[Mon Jul 20 06:41:30.163964 2026] [security2:error] [pid 966386:tid 966583] [client 50.116.65.227:45534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4XejrLBqY1mBmWu_YhlAAAAHY"]
[Mon Jul 20 06:41:30.230452 2026] [security2:error] [pid 966386:tid 966671] [client 34.139.11.221:58301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XejrLBqY1mBmWu_YhlQAAAGo"]
[Mon Jul 20 06:41:30.248359 2026] [security2:error] [pid 983757:tid 983981] [client 173.239.240.96:46069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XenKwMdFW9UVnNBSz3wAAAWY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:30.394289 2026] [security2:error] [pid 983757:tid 983904] [client 77.110.127.138:52767] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 678 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XenKwMdFW9UVnNBSz6AAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:30.418304 2026] [security2:error] [pid 983757:tid 983940] [client 34.139.11.221:55605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XenKwMdFW9UVnNBSz7QAAAT0"]
[Mon Jul 20 06:41:30.493820 2026] [security2:error] [pid 966386:tid 966637] [client 38.154.224.14:45935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4XejrLBqY1mBmWu_YhmgAAAEs"]
[Mon Jul 20 06:41:30.555927 2026] [security2:error] [pid 983757:tid 983894] [client 217.142.18.172:45523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XenKwMdFW9UVnNBSz-AAAAQ8"]
[Mon Jul 20 06:41:30.556058 2026] [security2:error] [pid 983757:tid 983894] [client 217.142.18.172:45523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XenKwMdFW9UVnNBSz-AAAAQ8"]
[Mon Jul 20 06:41:30.582613 2026] [security2:error] [pid 966386:tid 966502] [remote 14.225.211.68:48764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.211.225.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4XejrLBqY1mBmWu_YhnQAARUg"]
[Mon Jul 20 06:41:30.587133 2026] [security2:error] [pid 983757:tid 983917] [client 34.139.11.221:52529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XenKwMdFW9UVnNBSz-wAAASY"]
[Mon Jul 20 06:41:30.639757 2026] [security2:error] [pid 983757:tid 983945] [client 74.208.214.194:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XenKwMdFW9UVnNBSz_QAAAUI"]
[Mon Jul 20 06:41:30.720802 2026] [security2:error] [pid 983757:tid 983892] [client 173.239.240.97:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XenKwMdFW9UVnNBS0AAAAAQ0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:30.730557 2026] [security2:error] [pid 966386:tid 966627] [client 34.139.11.221:57764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XejrLBqY1mBmWu_YhoAAAAEE"]
[Mon Jul 20 06:41:30.817785 2026] [security2:error] [pid 966386:tid 966622] [client 57.141.18.47:45428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XeDrLBqY1mBmWu_YhZgAAPDk"]
[Mon Jul 20 06:41:30.855073 2026] [security2:error] [pid 966386:tid 966660] [client 34.139.11.221:65128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dienerranch.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XejrLBqY1mBmWu_YhoQAAAGE"]
[Mon Jul 20 06:41:30.883358 2026] [security2:error] [pid 966386:tid 966567] [client 103.125.179.95:59239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XejrLBqY1mBmWu_YhogAAAAU"]
[Mon Jul 20 06:41:30.883495 2026] [security2:error] [pid 966386:tid 966567] [client 103.125.179.95:59239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XejrLBqY1mBmWu_YhogAAAAU"]
[Mon Jul 20 06:41:30.993035 2026] [security2:error] [pid 966386:tid 966596] [client 54.244.177.189:53518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4XejrLBqY1mBmWu_YhqAAAACI"]
[Mon Jul 20 06:41:30.998985 2026] [security2:error] [pid 966386:tid 966636] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4XejrLBqY1mBmWu_YhmwAASjo"], referer: http://ali-alghanim.net/oldsite
[Mon Jul 20 06:41:31.081540 2026] [security2:error] [pid 966386:tid 966597] [client 14.225.17.146:50940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4XeTrLBqY1mBmWu_YhbwAAACM"], referer: http://webgardensbypaula.com/oldsite
[Mon Jul 20 06:41:31.134708 2026] [security2:error] [pid 966386:tid 966529] [remote 14.225.211.68:48764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.211.225.14.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4XezrLBqY1mBmWu_YhsAAAT2M"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 06:41:31.173530 2026] [security2:error] [pid 966386:tid 966611] [client 173.239.240.32:54211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XezrLBqY1mBmWu_YhswAAADE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:31.344353 2026] [security2:error] [pid 966386:tid 966560] [client 57.141.18.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sgmachinehouston.com"] [uri "/index.php"] [unique_id "al4XeTrLBqY1mBmWu_YhgQAAAAA"]
[Mon Jul 20 06:41:31.475881 2026] [security2:error] [pid 983757:tid 983994] [client 197.186.66.42:53467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Xe3KwMdFW9UVnNBS0KgAAAXM"]
[Mon Jul 20 06:41:31.485622 2026] [security2:error] [pid 983757:tid 983994] [client 197.186.66.42:53467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Xe3KwMdFW9UVnNBS0KgAAAXM"]
[Mon Jul 20 06:41:31.569151 2026] [security2:error] [pid 983757:tid 984001] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Xe3KwMdFW9UVnNBS0GAAAAXo"]
[Mon Jul 20 06:41:31.571981 2026] [security2:error] [pid 966386:tid 966686] [client 70.115.45.82:49778] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/2025/07/31/gecko-girl-hussani-abdulrahim/"] [unique_id "al4XezrLBqY1mBmWu_YhsQAAAHk"]
[Mon Jul 20 06:41:31.633036 2026] [security2:error] [pid 966386:tid 966568] [client 158.173.89.95:31633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XezrLBqY1mBmWu_YhvwAAAAY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:41:31.642639 2026] [security2:error] [pid 983757:tid 983913] [client 173.239.240.32:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xe3KwMdFW9UVnNBS0PAAAASI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:32.026291 2026] [security2:error] [pid 983757:tid 984008] [client 223.185.13.213:8987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XfHKwMdFW9UVnNBS0TQAAAYE"]
[Mon Jul 20 06:41:32.026464 2026] [security2:error] [pid 983757:tid 984008] [client 223.185.13.213:8987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XfHKwMdFW9UVnNBS0TQAAAYE"]
[Mon Jul 20 06:41:32.055226 2026] [security2:error] [pid 966386:tid 966667] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XezrLBqY1mBmWu_YhxgAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:32.103378 2026] [security2:error] [pid 983757:tid 984009] [client 136.144.35.243:54201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XfHKwMdFW9UVnNBS0UwAAAYI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:32.435684 2026] [security2:error] [pid 983757:tid 983867] [remote 100.42.189.89:57646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XfHKwMdFW9UVnNBS0bAABems"]
[Mon Jul 20 06:41:32.435918 2026] [security2:error] [pid 983757:tid 984001] [client 100.42.189.89:57646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XfHKwMdFW9UVnNBS0bAABems"]
[Mon Jul 20 06:41:32.449411 2026] [security2:error] [pid 983757:tid 983897] [client 37.52.210.45:53368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XfHKwMdFW9UVnNBS0bgAAARI"]
[Mon Jul 20 06:41:32.449544 2026] [security2:error] [pid 983757:tid 983897] [client 37.52.210.45:53368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XfHKwMdFW9UVnNBS0bgAAARI"]
[Mon Jul 20 06:41:32.538505 2026] [security2:error] [pid 966386:tid 966428] [remote 72.167.132.114:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XfDrLBqY1mBmWu_Yh2QAAcAE"]
[Mon Jul 20 06:41:32.540079 2026] [security2:error] [pid 983757:tid 983908] [client 14.225.17.146:59448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4XfHKwMdFW9UVnNBS0ZAAAAR0"], referer: http://soloceos.com/oldsite
[Mon Jul 20 06:41:32.562339 2026] [security2:error] [pid 966386:tid 966567] [client 173.239.240.90:63447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XfDrLBqY1mBmWu_Yh2gAAAAU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:32.807302 2026] [security2:error] [pid 966386:tid 966599] [client 45.3.47.234:51537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XfDrLBqY1mBmWu_Yh4wAAACU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:41:32.821034 2026] [security2:error] [pid 966386:tid 966506] [remote 72.167.132.114:60676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XfDrLBqY1mBmWu_Yh5AAAD0w"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:41:33.012863 2026] [security2:error] [pid 966386:tid 966643] [client 173.239.240.90:60821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XfTrLBqY1mBmWu_Yh6wAAAFE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:33.018687 2026] [security2:error] [pid 983757:tid 983997] [client 57.141.18.7:28014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XenKwMdFW9UVnNBS0DQABdhE"]
[Mon Jul 20 06:41:33.060918 2026] [security2:error] [pid 966386:tid 966580] [client 104.234.53.73:36143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XfTrLBqY1mBmWu_Yh8gAAABI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:33.094730 2026] [security2:error] [pid 966386:tid 966690] [client 14.225.17.146:63957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4XezrLBqY1mBmWu_YhuQAAAH0"], referer: http://xp-design.co/oldsite
[Mon Jul 20 06:41:33.404928 2026] [security2:error] [pid 983757:tid 983996] [client 45.3.44.133:24213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XfXKwMdFW9UVnNBS0jgAAAXU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:41:33.466337 2026] [security2:error] [pid 966386:tid 966682] [client 136.144.35.253:58681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XfTrLBqY1mBmWu_YiDwAAAHU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:33.469652 2026] [security2:error] [pid 983757:tid 983917] [client 14.225.17.146:58457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4Xe3KwMdFW9UVnNBS0QAAAASY"], referer: http://tacticaltreeoperations.com/oldsite
[Mon Jul 20 06:41:33.499794 2026] [security2:error] [pid 983757:tid 983961] [client 43.205.139.3:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4XfXKwMdFW9UVnNBS0kwAAAVI"]
[Mon Jul 20 06:41:33.642296 2026] [security2:error] [pid 983757:tid 984015] [client 104.234.53.83:57641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XfXKwMdFW9UVnNBS0nQAAAYg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:33.798257 2026] [security2:error] [pid 983757:tid 983972] [client 45.3.52.25:34017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XfXKwMdFW9UVnNBS0owAAAV0"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:33.893779 2026] [security2:error] [pid 966386:tid 966692] [client 39.48.81.23:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XfTrLBqY1mBmWu_YiGwAAAH8"]
[Mon Jul 20 06:41:33.893918 2026] [security2:error] [pid 966386:tid 966692] [client 39.48.81.23:60881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XfTrLBqY1mBmWu_YiGwAAAH8"]
[Mon Jul 20 06:41:33.941453 2026] [security2:error] [pid 983757:tid 983954] [client 173.239.240.31:30743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XfXKwMdFW9UVnNBS0rgAAAUs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:34.191952 2026] [security2:error] [pid 983757:tid 983926] [client 50.116.65.227:45644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XfnKwMdFW9UVnNBS0vAAAAS8"]
[Mon Jul 20 06:41:34.204520 2026] [security2:error] [pid 983757:tid 983961] [client 50.116.65.227:45656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XfnKwMdFW9UVnNBS0vQAAAVI"]
[Mon Jul 20 06:41:34.419420 2026] [security2:error] [pid 983757:tid 983991] [client 136.144.35.246:37243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XfnKwMdFW9UVnNBS0yAAAAXA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:34.484069 2026] [security2:error] [pid 983757:tid 983901] [client 57.141.18.57:59718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfHKwMdFW9UVnNBS0ZQABFg8"]
[Mon Jul 20 06:41:34.534015 2026] [security2:error] [pid 983757:tid 983973] [client 13.233.207.33:22986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4XfnKwMdFW9UVnNBS0zAAAAV4"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:41:34.542791 2026] [security2:error] [pid 983757:tid 983981] [client 57.141.18.69:51850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfHKwMdFW9UVnNBS0ZwABZns"]
[Mon Jul 20 06:41:34.823328 2026] [security2:error] [pid 966386:tid 966667] [client 14.225.17.146:64035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4XfTrLBqY1mBmWu_YiEQAAAGc"], referer: http://effingweirdmuseums.com/oldsite
[Mon Jul 20 06:41:34.870589 2026] [security2:error] [pid 966386:tid 966649] [client 173.239.240.97:45373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XfjrLBqY1mBmWu_YiRwAAAFc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:34.896924 2026] [security2:error] [pid 966386:tid 966650] [client 50.116.65.227:51734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4XfjrLBqY1mBmWu_YiSQAAAFg"]
[Mon Jul 20 06:41:34.899941 2026] [security2:error] [pid 966386:tid 966620] [client 14.225.17.146:51231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4XfTrLBqY1mBmWu_YiEAAAADo"]
[Mon Jul 20 06:41:35.013180 2026] [security2:error] [pid 983757:tid 983910] [client 57.141.18.108:45130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfHKwMdFW9UVnNBS0fAABH3o"]
[Mon Jul 20 06:41:35.049796 2026] [security2:error] [pid 966386:tid 966621] [client 57.141.18.108:45132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfDrLBqY1mBmWu_Yh4gAAO28"]
[Mon Jul 20 06:41:35.119714 2026] [security2:error] [pid 983757:tid 983954] [client 77.110.127.138:52799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Xf3KwMdFW9UVnNBS04gAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:35.119952 2026] [security2:error] [pid 983757:tid 983954] [client 77.110.127.138:52799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Xf3KwMdFW9UVnNBS04gAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:35.154450 2026] [security2:error] [pid 983757:tid 983920] [client 104.207.63.55:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Xf3KwMdFW9UVnNBS05QAAASk"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:35.233381 2026] [security2:error] [pid 966386:tid 966632] [client 104.234.53.90:42155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XfzrLBqY1mBmWu_YiWQAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:35.341624 2026] [security2:error] [pid 983757:tid 983950] [client 173.239.240.101:48223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1CgAAAUc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:35.363457 2026] [security2:error] [pid 983757:tid 984013] [client 106.219.188.178:25946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1CwAAAYY"]
[Mon Jul 20 06:41:35.364867 2026] [security2:error] [pid 983757:tid 984013] [client 106.219.188.178:25946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1CwAAAYY"]
[Mon Jul 20 06:41:35.393241 2026] [security2:error] [pid 983757:tid 983944] [client 122.183.32.225:9091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1DgAAAUE"]
[Mon Jul 20 06:41:35.393444 2026] [security2:error] [pid 983757:tid 983944] [client 122.183.32.225:9091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1DgAAAUE"]
[Mon Jul 20 06:41:35.435802 2026] [security2:error] [pid 966386:tid 966659] [client 52.140.101.203:25475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XfzrLBqY1mBmWu_YiaQAAAGA"]
[Mon Jul 20 06:41:35.672613 2026] [security2:error] [pid 966386:tid 966577] [client 52.140.101.203:25475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XfzrLBqY1mBmWu_YiegAAAA8"]
[Mon Jul 20 06:41:35.793574 2026] [security2:error] [pid 983757:tid 984011] [client 14.225.17.146:51211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1JQAAAYQ"], referer: https://effingweirdmuseums.com/oldsite
[Mon Jul 20 06:41:35.801539 2026] [security2:error] [pid 983757:tid 983918] [client 57.141.18.118:38364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfXKwMdFW9UVnNBS0mQABJx0"]
[Mon Jul 20 06:41:35.833597 2026] [security2:error] [pid 983757:tid 983920] [client 173.239.240.31:62263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1KQAAASk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:35.864473 2026] [security2:error] [pid 966386:tid 966500] [remote 57.141.18.52:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4XfzrLBqY1mBmWu_YiiwAAeUY"]
[Mon Jul 20 06:41:35.913578 2026] [security2:error] [pid 966386:tid 966597] [client 104.234.53.84:23809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XfzrLBqY1mBmWu_YijQAAACM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:35.921553 2026] [security2:error] [pid 983757:tid 983973] [client 171.61.165.146:33231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1MAAAAV4"]
[Mon Jul 20 06:41:35.921672 2026] [security2:error] [pid 983757:tid 983973] [client 171.61.165.146:33231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Xf3KwMdFW9UVnNBS1MAAAAV4"]
[Mon Jul 20 06:41:36.021401 2026] [security2:error] [pid 966386:tid 966603] [client 77.110.127.138:52811] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XgDrLBqY1mBmWu_YikgAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:36.174062 2026] [security2:error] [pid 966386:tid 966638] [client 57.141.18.109:53434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfjrLBqY1mBmWu_YiHwAATDw"]
[Mon Jul 20 06:41:36.297183 2026] [security2:error] [pid 983757:tid 983912] [client 52.109.4.7:28291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XgHKwMdFW9UVnNBS1OgAAASE"]
[Mon Jul 20 06:41:36.301676 2026] [security2:error] [pid 966386:tid 966642] [client 173.239.240.32:29015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XgDrLBqY1mBmWu_YioAAAAFA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:36.359697 2026] [security2:error] [pid 983757:tid 983935] [client 52.109.4.7:28291] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XgHKwMdFW9UVnNBS1PAAAATg"]
[Mon Jul 20 06:41:36.455829 2026] [security2:error] [pid 966386:tid 966635] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XgDrLBqY1mBmWu_YimwAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:36.493531 2026] [security2:error] [pid 966386:tid 966671] [client 14.225.17.146:64197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4XgDrLBqY1mBmWu_YingAAAGo"], referer: http://recruitinginsight.us/oldsite
[Mon Jul 20 06:41:36.587731 2026] [security2:error] [pid 983757:tid 983943] [client 57.141.18.112:37148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfnKwMdFW9UVnNBS0yQABQH4"]
[Mon Jul 20 06:41:36.695338 2026] [security2:error] [pid 983757:tid 983950] [client 57.141.18.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XgHKwMdFW9UVnNBS1RwAAAUc"]
[Mon Jul 20 06:41:36.699913 2026] [security2:error] [pid 983757:tid 983924] [client 43.205.139.3:41194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XgHKwMdFW9UVnNBS1VwAAAS0"]
[Mon Jul 20 06:41:36.700025 2026] [security2:error] [pid 983757:tid 983924] [client 43.205.139.3:41194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XgHKwMdFW9UVnNBS1VwAAAS0"]
[Mon Jul 20 06:41:36.861700 2026] [security2:error] [pid 983757:tid 983995] [client 136.144.35.251:51171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XgHKwMdFW9UVnNBS1YwAAAXQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:36.896511 2026] [security2:error] [pid 983757:tid 983977] [client 57.141.18.34:45390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfnKwMdFW9UVnNBS00gABYn0"]
[Mon Jul 20 06:41:37.329149 2026] [security2:error] [pid 983757:tid 983932] [client 112.208.70.94:44535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XgXKwMdFW9UVnNBS1cwAAATU"]
[Mon Jul 20 06:41:37.329290 2026] [security2:error] [pid 983757:tid 983932] [client 112.208.70.94:44535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XgXKwMdFW9UVnNBS1cwAAATU"]
[Mon Jul 20 06:41:37.356158 2026] [security2:error] [pid 966386:tid 966602] [client 136.144.35.245:57705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XgTrLBqY1mBmWu_Yi0gAAACg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:37.369589 2026] [security2:error] [pid 966386:tid 966663] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XgTrLBqY1mBmWu_YiyQAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:37.610431 2026] [security2:error] [pid 966386:tid 966662] [client 57.141.18.86:31166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XfzrLBqY1mBmWu_YibgAAY38"]
[Mon Jul 20 06:41:37.748617 2026] [security2:error] [pid 983757:tid 983924] [client 14.225.17.146:63578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1fAAAAS0"], referer: http://dollpassionista.com/oldsite
[Mon Jul 20 06:41:37.827811 2026] [security2:error] [pid 983757:tid 983974] [client 173.239.240.93:35921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1kQAAAV8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:37.844395 2026] [security2:error] [pid 966386:tid 966610] [client 170.0.66.10:10686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marscafe.com"] [uri "/index.php"] [unique_id "al4XgTrLBqY1mBmWu_Yi3gAAADA"]
[Mon Jul 20 06:41:37.950723 2026] [security2:error] [pid 983757:tid 983958] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1iAAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:38.020050 2026] [security2:error] [pid 983757:tid 983986] [client 14.224.227.113:61335] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XgnKwMdFW9UVnNBS1owAAAWs"]
[Mon Jul 20 06:41:38.097121 2026] [security2:error] [pid 966386:tid 966645] [client 14.225.17.146:63475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4XgDrLBqY1mBmWu_YiqwAAAFM"], referer: http://solkeetw.com/oldsite
[Mon Jul 20 06:41:38.098696 2026] [security2:error] [pid 983757:tid 983964] [client 216.73.217.138:55537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1nAABVXg"]
[Mon Jul 20 06:41:38.279823 2026] [security2:error] [pid 983757:tid 983913] [client 173.239.240.100:22201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XgnKwMdFW9UVnNBS1sQAAASI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:38.388745 2026] [security2:error] [pid 966386:tid 966691] [client 57.141.18.111:49502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgDrLBqY1mBmWu_YinwAAfjc"]
[Mon Jul 20 06:41:38.447062 2026] [security2:error] [pid 966386:tid 966443] [remote 95.217.78.234:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4XgjrLBqY1mBmWu_YjBwAAAxA"]
[Mon Jul 20 06:41:38.459439 2026] [security2:error] [pid 966386:tid 966615] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XgjrLBqY1mBmWu_Yi9AAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:38.686164 2026] [security2:error] [pid 966386:tid 966499] [remote 95.217.78.234:45172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4XgjrLBqY1mBmWu_YjDQAAC0U"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:41:38.713031 2026] [security2:error] [pid 966386:tid 966470] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XgjrLBqY1mBmWu_YjDwAAJio"]
[Mon Jul 20 06:41:38.713205 2026] [security2:error] [pid 966386:tid 966600] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XgjrLBqY1mBmWu_YjDwAAJio"]
[Mon Jul 20 06:41:38.746577 2026] [security2:error] [pid 983757:tid 983899] [client 213.152.162.79:49480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4XgnKwMdFW9UVnNBS1wwAAARQ"]
[Mon Jul 20 06:41:38.746672 2026] [security2:error] [pid 983757:tid 983899] [client 213.152.162.79:49480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4XgnKwMdFW9UVnNBS1wwAAARQ"]
[Mon Jul 20 06:41:38.758196 2026] [security2:error] [pid 983757:tid 983957] [client 57.141.18.46:64344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgHKwMdFW9UVnNBS1UQABTlU"]
[Mon Jul 20 06:41:38.772980 2026] [security2:error] [pid 983757:tid 983981] [client 136.144.35.247:22325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XgnKwMdFW9UVnNBS1xAAAAWY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:38.924375 2026] [security2:error] [pid 966386:tid 966585] [client 152.58.191.29:55985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XgjrLBqY1mBmWu_YjHAAAABc"]
[Mon Jul 20 06:41:38.924553 2026] [security2:error] [pid 966386:tid 966585] [client 152.58.191.29:55985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XgjrLBqY1mBmWu_YjHAAAABc"]
[Mon Jul 20 06:41:38.956382 2026] [security2:error] [pid 966386:tid 966517] [remote 72.167.132.114:57360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XgjrLBqY1mBmWu_YjIAAAMVc"]
[Mon Jul 20 06:41:38.956605 2026] [security2:error] [pid 966386:tid 966611] [client 72.167.132.114:57360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XgjrLBqY1mBmWu_YjIAAAMVc"]
[Mon Jul 20 06:41:38.990209 2026] [security2:error] [pid 983757:tid 983892] [client 5.36.160.36:40114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4XgnKwMdFW9UVnNBS1vAAAAQ0"]
[Mon Jul 20 06:41:39.016374 2026] [security2:error] [pid 983757:tid 983900] [client 104.234.53.80:45627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Xg3KwMdFW9UVnNBS1zgAAARU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:39.058860 2026] [security2:error] [pid 983757:tid 983997] [client 14.225.17.146:51547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4XgnKwMdFW9UVnNBS1yAAAAXY"], referer: https://dollpassionista.com/oldsite
[Mon Jul 20 06:41:39.097640 2026] [security2:error] [pid 966386:tid 966653] [client 77.110.127.138:52833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XgzrLBqY1mBmWu_YjKAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:39.097737 2026] [security2:error] [pid 966386:tid 966653] [client 77.110.127.138:52833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XgzrLBqY1mBmWu_YjKAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:39.177602 2026] [security2:error] [pid 966386:tid 966644] [client 187.108.85.186:59476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XgzrLBqY1mBmWu_YjLQAAAFI"]
[Mon Jul 20 06:41:39.177766 2026] [security2:error] [pid 966386:tid 966644] [client 187.108.85.186:59476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XgzrLBqY1mBmWu_YjLQAAAFI"]
[Mon Jul 20 06:41:39.251679 2026] [security2:error] [pid 966386:tid 966678] [client 77.110.127.138:52840] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XgzrLBqY1mBmWu_YjMAAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:39.262863 2026] [security2:error] [pid 966386:tid 966635] [client 173.239.240.92:63381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XgzrLBqY1mBmWu_YjLwAAAEk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:39.277238 2026] [core:error] [pid 983757:tid 983951] [client 14.225.17.146:63543] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/oldsite
[Mon Jul 20 06:41:39.277263 2026] [core:error] [pid 983757:tid 983951] [client 14.225.17.146:63543] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/oldsite
[Mon Jul 20 06:41:39.397909 2026] [security2:error] [pid 983757:tid 984005] [client 14.224.227.113:54600] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Xg3KwMdFW9UVnNBS13AAAAX4"]
[Mon Jul 20 06:41:39.399671 2026] [security2:error] [pid 983757:tid 983986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Xg3KwMdFW9UVnNBS10gAAAWs"]
[Mon Jul 20 06:41:39.416130 2026] [security2:error] [pid 983757:tid 983928] [client 57.141.18.74:40596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1eAABMW4"]
[Mon Jul 20 06:41:39.450952 2026] [security2:error] [pid 983757:tid 983839] [remote 57.141.18.79:34756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3096972"] [unique_id "al4Xg3KwMdFW9UVnNBS13QABQ08"]
[Mon Jul 20 06:41:39.498851 2026] [security2:error] [pid 983757:tid 983921] [client 14.225.17.146:63558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1ewAAASo"], referer: http://according2plant.com/oldsite
[Mon Jul 20 06:41:39.541855 2026] [security2:error] [pid 966386:tid 966631] [client 158.173.166.181:24927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XgzrLBqY1mBmWu_YjSAAAAEU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:41:39.665483 2026] [security2:error] [pid 983757:tid 983899] [client 104.234.53.62:53975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Xg3KwMdFW9UVnNBS15gAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:39.757000 2026] [security2:error] [pid 966386:tid 966600] [client 173.239.240.93:38251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XgzrLBqY1mBmWu_YjUgAAACY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:39.893635 2026] [security2:error] [pid 983757:tid 983994] [client 14.225.17.146:63605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Xg3KwMdFW9UVnNBS16gAAAXM"], referer: http://laceycaraccident.com/oldsite
[Mon Jul 20 06:41:39.906057 2026] [security2:error] [pid 983757:tid 983932] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Xg3KwMdFW9UVnNBS16QAAATU"]
[Mon Jul 20 06:41:40.062707 2026] [security2:error] [pid 983757:tid 983898] [client 57.141.18.84:51870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgXKwMdFW9UVnNBS1nQABEws"]
[Mon Jul 20 06:41:40.090189 2026] [lsapi:warn] [pid 983757:tid 983881] [remote 185.21.13.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: http://ALI-ALGHANIM.COM
[Mon Jul 20 06:41:40.234154 2026] [security2:error] [pid 966386:tid 966568] [client 14.225.17.146:51113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4XgjrLBqY1mBmWu_YjFgAAAAY"], referer: http://momheadquarters.com/oldsite
[Mon Jul 20 06:41:40.256106 2026] [security2:error] [pid 983757:tid 983983] [client 173.239.240.93:58395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XhHKwMdFW9UVnNBS1_wAAAWg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:40.268997 2026] [security2:error] [pid 966386:tid 966567] [client 46.110.96.34:37153] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XhDrLBqY1mBmWu_YjYgAAAAU"]
[Mon Jul 20 06:41:40.412123 2026] [security2:error] [pid 966386:tid 966561] [client 57.141.18.107:43508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgjrLBqY1mBmWu_Yi8gAAASk"]
[Mon Jul 20 06:41:40.559550 2026] [security2:error] [pid 966386:tid 966683] [client 103.238.106.162:60602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XhDrLBqY1mBmWu_YjdAAAAHY"]
[Mon Jul 20 06:41:40.559735 2026] [security2:error] [pid 966386:tid 966683] [client 103.238.106.162:60602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XhDrLBqY1mBmWu_YjdAAAAHY"]
[Mon Jul 20 06:41:40.593038 2026] [security2:error] [pid 983757:tid 983982] [client 57.141.18.66:63726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgnKwMdFW9UVnNBS1swABZ0M"]
[Mon Jul 20 06:41:40.710006 2026] [security2:error] [pid 983757:tid 983922] [client 173.239.240.98:46899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XhHKwMdFW9UVnNBS2EAAAASs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:40.834488 2026] [security2:error] [pid 983757:tid 983944] [client 14.225.17.146:51626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4XgnKwMdFW9UVnNBS1ywAAAUE"], referer: http://dnsplumbing.com/oldsite
[Mon Jul 20 06:41:40.843594 2026] [security2:error] [pid 983757:tid 983904] [client 46.110.96.34:17992] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XhHKwMdFW9UVnNBS2FgAAARk"]
[Mon Jul 20 06:41:40.905209 2026] [security2:error] [pid 966386:tid 966687] [client 57.141.18.70:40130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgjrLBqY1mBmWu_YjCwAAeiQ"]
[Mon Jul 20 06:41:40.945031 2026] [security2:error] [pid 966386:tid 966560] [client 104.234.53.56:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XhDrLBqY1mBmWu_YjigAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:41.093068 2026] [security2:error] [pid 983757:tid 983958] [client 217.142.18.172:38401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XhXKwMdFW9UVnNBS2IwAAAU8"]
[Mon Jul 20 06:41:41.094764 2026] [security2:error] [pid 983757:tid 983958] [client 217.142.18.172:38401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XhXKwMdFW9UVnNBS2IwAAAU8"]
[Mon Jul 20 06:41:41.116017 2026] [security2:error] [pid 966386:tid 966617] [client 114.119.155.230:59317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "floorsourcestock.com"] [uri "/product/moonstruck-ardor/"] [unique_id "al4XhTrLBqY1mBmWu_YjkgAAADc"], referer: https://floorsourcestock.com/product-category/tile
[Mon Jul 20 06:41:41.227712 2026] [security2:error] [pid 983757:tid 983889] [client 136.144.35.254:34309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XhXKwMdFW9UVnNBS2KwAAAQo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:41.530620 2026] [security2:error] [pid 966386:tid 966573] [client 47.128.30.0:42954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "latiendadejorge.com.gt"] [uri "/robots.txt"] [unique_id "al4XhTrLBqY1mBmWu_YjpQAAAAs"]
[Mon Jul 20 06:41:41.678278 2026] [security2:error] [pid 983757:tid 983965] [client 173.239.240.96:54893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XhXKwMdFW9UVnNBS2QwAAAVY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:41.723597 2026] [security2:error] [pid 966386:tid 966591] [client 104.234.53.89:52945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XhTrLBqY1mBmWu_YjrwAAAB0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:41.780245 2026] [autoindex:error] [pid 983757:tid 983935] [client 147.93.171.185:65117] AH01276: Cannot serve directory /home3/ancestx0/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:41:41.807135 2026] [security2:error] [pid 966386:tid 966689] [client 57.141.18.92:35382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XgzrLBqY1mBmWu_YjRQAAfBE"]
[Mon Jul 20 06:41:41.904213 2026] [security2:error] [pid 966386:tid 966484] [remote 173.212.252.15:57148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4XhTrLBqY1mBmWu_YjtgAAQzY"]
[Mon Jul 20 06:41:42.103097 2026] [security2:error] [pid 983757:tid 984013] [client 77.110.127.138:52822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XhnKwMdFW9UVnNBS2WQAAAYY"]
[Mon Jul 20 06:41:42.114738 2026] [security2:error] [pid 966386:tid 966534] [remote 173.212.252.15:57148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4XhjrLBqY1mBmWu_YjwQAAXWg"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:41:42.122779 2026] [security2:error] [pid 983757:tid 983859] [remote 152.228.213.32:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XhnKwMdFW9UVnNBS2WgABdmM"]
[Mon Jul 20 06:41:42.166010 2026] [security2:error] [pid 966386:tid 966608] [client 14.225.17.146:63607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4XhDrLBqY1mBmWu_YjdgAAAC4"], referer: http://eframiproperties.com/oldsite
[Mon Jul 20 06:41:42.219080 2026] [security2:error] [pid 966386:tid 966605] [client 173.239.240.100:58593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XhjrLBqY1mBmWu_YjygAAACs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:42.334730 2026] [security2:error] [pid 983757:tid 983796] [remote 152.228.213.32:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XhnKwMdFW9UVnNBS2ZAABbCQ"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:41:42.458597 2026] [security2:error] [pid 966386:tid 966631] [client 223.185.13.213:18552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XhjrLBqY1mBmWu_Yj0wAAAEU"]
[Mon Jul 20 06:41:42.458765 2026] [security2:error] [pid 966386:tid 966631] [client 223.185.13.213:18552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XhjrLBqY1mBmWu_Yj0wAAAEU"]
[Mon Jul 20 06:41:42.477384 2026] [security2:error] [pid 983757:tid 983911] [client 77.110.127.138:52849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XhnKwMdFW9UVnNBS2aAAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:42.477488 2026] [security2:error] [pid 983757:tid 983911] [client 77.110.127.138:52849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XhnKwMdFW9UVnNBS2aAAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:42.537428 2026] [security2:error] [pid 966386:tid 966684] [client 57.141.18.5:29158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XhDrLBqY1mBmWu_YjZAAAd1w"]
[Mon Jul 20 06:41:42.614559 2026] [security2:error] [pid 966386:tid 966662] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XhjrLBqY1mBmWu_Yj1AAAAGM"]
[Mon Jul 20 06:41:42.728519 2026] [security2:error] [pid 983757:tid 983984] [client 173.239.240.99:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XhnKwMdFW9UVnNBS2eQAAAWk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:42.807129 2026] [security2:error] [pid 983757:tid 983878] [remote 160.187.68.132:40662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XhnKwMdFW9UVnNBS2fAABGXY"]
[Mon Jul 20 06:41:42.876836 2026] [security2:error] [pid 966386:tid 966649] [client 103.125.179.95:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XhjrLBqY1mBmWu_Yj4wAAAFc"]
[Mon Jul 20 06:41:42.877031 2026] [security2:error] [pid 966386:tid 966649] [client 103.125.179.95:59758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XhjrLBqY1mBmWu_Yj4wAAAFc"]
[Mon Jul 20 06:41:42.933817 2026] [security2:error] [pid 966386:tid 966616] [client 216.73.217.138:10906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XhjrLBqY1mBmWu_Yj4QAANnI"]
[Mon Jul 20 06:41:42.964240 2026] [security2:error] [pid 983757:tid 983899] [client 57.141.18.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XhnKwMdFW9UVnNBS2fgAAARQ"]
[Mon Jul 20 06:41:43.000942 2026] [security2:error] [pid 983757:tid 983977] [client 114.119.135.223:40669] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "samdothan.org"] [uri "/robots.txt"] [unique_id "al4Xh3KwMdFW9UVnNBS2hQAAAWI"], referer: https://samdothan.org/robots.txt
[Mon Jul 20 06:41:43.079654 2026] [security2:error] [pid 983757:tid 983893] [client 37.52.210.45:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Xh3KwMdFW9UVnNBS2iQAAAQ4"]
[Mon Jul 20 06:41:43.079790 2026] [security2:error] [pid 983757:tid 983893] [client 37.52.210.45:63435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Xh3KwMdFW9UVnNBS2iQAAAQ4"]
[Mon Jul 20 06:41:43.115797 2026] [security2:error] [pid 983757:tid 984007] [client 103.49.203.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4XhHKwMdFW9UVnNBS2CwAAAYA"]
[Mon Jul 20 06:41:43.135627 2026] [security2:error] [pid 966386:tid 966572] [client 46.110.96.34:37153] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XhzrLBqY1mBmWu_Yj8AAAAAo"]
[Mon Jul 20 06:41:43.193414 2026] [security2:error] [pid 966386:tid 966691] [client 136.144.35.252:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XhzrLBqY1mBmWu_Yj-QAAAH4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:43.203510 2026] [security2:error] [pid 983757:tid 983914] [client 46.110.96.34:58959] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4Xh3KwMdFW9UVnNBS2jwAAASM"]
[Mon Jul 20 06:41:43.412515 2026] [security2:error] [pid 983757:tid 983767] [remote 160.187.68.132:40662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Xh3KwMdFW9UVnNBS2kQABRwc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:41:43.517409 2026] [security2:error] [pid 983757:tid 983951] [client 57.141.18.85:61768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XhXKwMdFW9UVnNBS2MQABSEs"]
[Mon Jul 20 06:41:43.647016 2026] [security2:error] [pid 983757:tid 983890] [client 173.239.240.96:53749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xh3KwMdFW9UVnNBS2mgAAAQs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:43.744703 2026] [security2:error] [pid 983757:tid 984005] [client 57.141.18.0:57028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XhXKwMdFW9UVnNBS2PQABfgo"]
[Mon Jul 20 06:41:44.138837 2026] [security2:error] [pid 983757:tid 983895] [client 173.239.240.98:60417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XiHKwMdFW9UVnNBS2ugAAARA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:44.169011 2026] [security2:error] [pid 983757:tid 983924] [client 57.141.18.17:56670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XhnKwMdFW9UVnNBS2UwABLTk"]
[Mon Jul 20 06:41:44.182964 2026] [security2:error] [pid 983757:tid 983894] [client 39.48.81.23:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XiHKwMdFW9UVnNBS2vQAAAQ8"]
[Mon Jul 20 06:41:44.183130 2026] [security2:error] [pid 983757:tid 983894] [client 39.48.81.23:61403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XiHKwMdFW9UVnNBS2vQAAAQ8"]
[Mon Jul 20 06:41:44.262617 2026] [security2:error] [pid 966386:tid 966601] [client 50.116.65.227:15928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XiDrLBqY1mBmWu_YkIQAAACc"]
[Mon Jul 20 06:41:44.275762 2026] [security2:error] [pid 983757:tid 983922] [client 50.116.65.227:15936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XiHKwMdFW9UVnNBS2xQAAASs"]
[Mon Jul 20 06:41:44.465038 2026] [security2:error] [pid 983757:tid 983978] [client 197.186.66.42:53999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XiHKwMdFW9UVnNBS2ywAAAWM"]
[Mon Jul 20 06:41:44.468053 2026] [security2:error] [pid 983757:tid 983978] [client 197.186.66.42:53999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XiHKwMdFW9UVnNBS2ywAAAWM"]
[Mon Jul 20 06:41:44.600017 2026] [security2:error] [pid 983757:tid 983943] [client 136.144.35.254:24843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XiHKwMdFW9UVnNBS22QAAAUA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:44.606802 2026] [security2:error] [pid 966386:tid 966593] [client 104.234.53.50:27423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XiDrLBqY1mBmWu_YkMgAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:44.975165 2026] [security2:error] [pid 966386:tid 966662] [client 45.205.1.223:44052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4XiDrLBqY1mBmWu_YkRgAAAGM"]
[Mon Jul 20 06:41:45.051957 2026] [security2:error] [pid 983757:tid 983930] [client 136.144.35.243:64251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XiXKwMdFW9UVnNBS26wAAATM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:45.405792 2026] [security2:error] [pid 966386:tid 966631] [client 14.225.17.146:62675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4XhzrLBqY1mBmWu_YkEQAAAEU"], referer: http://olearyplumbingllc.com/oldsite
[Mon Jul 20 06:41:45.523739 2026] [security2:error] [pid 983757:tid 984001] [client 136.144.35.252:44357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XiXKwMdFW9UVnNBS3AQAAAXo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:45.539205 2026] [security2:error] [pid 966386:tid 966672] [client 45.205.1.223:44058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4XiTrLBqY1mBmWu_YkXgAAAGs"]
[Mon Jul 20 06:41:45.558000 2026] [security2:error] [pid 983757:tid 983946] [client 57.141.18.27:39284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xh3KwMdFW9UVnNBS2kwABQ20"]
[Mon Jul 20 06:41:45.792155 2026] [security2:error] [pid 966386:tid 966664] [client 192.140.149.97:46226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XiTrLBqY1mBmWu_YkdQAAAGU"]
[Mon Jul 20 06:41:45.792249 2026] [security2:error] [pid 966386:tid 966664] [client 192.140.149.97:46226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XiTrLBqY1mBmWu_YkdQAAAGU"]
[Mon Jul 20 06:41:45.792290 2026] [security2:error] [pid 966386:tid 966676] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4XiTrLBqY1mBmWu_YkcAAAAG8"]
[Mon Jul 20 06:41:45.812985 2026] [security2:error] [pid 966386:tid 966570] [client 122.183.32.225:17475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XiTrLBqY1mBmWu_YkeQAAAAg"]
[Mon Jul 20 06:41:45.813111 2026] [security2:error] [pid 966386:tid 966570] [client 122.183.32.225:17475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XiTrLBqY1mBmWu_YkeQAAAAg"]
[Mon Jul 20 06:41:45.840375 2026] [security2:error] [pid 983757:tid 983873] [remote 45.90.123.233:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4XiXKwMdFW9UVnNBS3FgABeXE"]
[Mon Jul 20 06:41:45.993548 2026] [security2:error] [pid 983757:tid 983998] [client 136.144.35.245:36825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XiXKwMdFW9UVnNBS3HQAAAXc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:46.001729 2026] [security2:error] [pid 966386:tid 966636] [client 106.219.188.178:25748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XijrLBqY1mBmWu_YkgQAAAEo"]
[Mon Jul 20 06:41:46.001920 2026] [security2:error] [pid 966386:tid 966636] [client 106.219.188.178:25748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XijrLBqY1mBmWu_YkgQAAAEo"]
[Mon Jul 20 06:41:46.102984 2026] [security2:error] [pid 983757:tid 983988] [client 104.207.55.99:41161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XinKwMdFW9UVnNBS3IAAAAW0"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:46.165398 2026] [security2:error] [pid 966386:tid 966615] [client 14.225.17.146:62510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4XiDrLBqY1mBmWu_YkNwAAADU"], referer: http://elitetax-mi.com/oldsite
[Mon Jul 20 06:41:46.192999 2026] [security2:error] [pid 983757:tid 983783] [remote 45.90.123.233:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4XinKwMdFW9UVnNBS3JwABRBc"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 06:41:46.297400 2026] [security2:error] [pid 983757:tid 983950] [client 57.141.18.94:40454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XiHKwMdFW9UVnNBS2uwABRw0"]
[Mon Jul 20 06:41:46.360413 2026] [security2:error] [pid 983757:tid 983911] [client 57.141.18.70:48040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XiHKwMdFW9UVnNBS2wAABIGA"]
[Mon Jul 20 06:41:46.445347 2026] [security2:error] [pid 983757:tid 983981] [client 136.144.35.253:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XinKwMdFW9UVnNBS3NgAAAWY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:46.546301 2026] [security2:error] [pid 983757:tid 983955] [client 57.141.18.78:47488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XiHKwMdFW9UVnNBS2yQABTHw"]
[Mon Jul 20 06:41:46.678162 2026] [security2:error] [pid 983757:tid 983899] [client 45.157.112.60:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XinKwMdFW9UVnNBS3RAAAARQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:41:46.722237 2026] [security2:error] [pid 966386:tid 966586] [client 77.110.127.138:52868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XijrLBqY1mBmWu_YkogAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:46.722366 2026] [security2:error] [pid 966386:tid 966586] [client 77.110.127.138:52868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XijrLBqY1mBmWu_YkogAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:46.740532 2026] [security2:error] [pid 983757:tid 984009] [client 104.234.53.59:42813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XinKwMdFW9UVnNBS3QQAAAYI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:46.766264 2026] [security2:error] [pid 966386:tid 966651] [client 171.61.165.146:10607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XijrLBqY1mBmWu_YkpwAAAFk"]
[Mon Jul 20 06:41:46.766495 2026] [security2:error] [pid 966386:tid 966651] [client 171.61.165.146:10607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XijrLBqY1mBmWu_YkpwAAAFk"]
[Mon Jul 20 06:41:46.897999 2026] [security2:error] [pid 966386:tid 966592] [client 136.144.35.247:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XijrLBqY1mBmWu_YkrAAAAB4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:46.997554 2026] [security2:error] [pid 983757:tid 983919] [client 104.234.53.59:42813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XinKwMdFW9UVnNBS3UQAAASg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:47.062682 2026] [security2:error] [pid 983757:tid 983892] [client 104.207.32.236:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Xi3KwMdFW9UVnNBS3VQAAAQ0"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:47.189545 2026] [security2:error] [pid 983757:tid 983904] [client 57.141.18.49:27286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XiXKwMdFW9UVnNBS29AABGRQ"]
[Mon Jul 20 06:41:47.202114 2026] [security2:error] [pid 983757:tid 983923] [client 216.73.217.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.robiem.com"] [uri "/index.php"] [unique_id "al4XiXKwMdFW9UVnNBS3GAAAASw"]
[Mon Jul 20 06:41:47.369495 2026] [security2:error] [pid 983757:tid 983958] [client 136.144.35.246:47685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xi3KwMdFW9UVnNBS3aQAAAU8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:47.520955 2026] [security2:error] [pid 966386:tid 966525] [remote 192.241.143.148:41490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XizrLBqY1mBmWu_YkwQAAdV8"]
[Mon Jul 20 06:41:47.550710 2026] [security2:error] [pid 966386:tid 966617] [client 57.141.18.43:55168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XiTrLBqY1mBmWu_YkagAANzM"]
[Mon Jul 20 06:41:47.606907 2026] [security2:error] [pid 966386:tid 966584] [client 14.225.17.146:63449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4XijrLBqY1mBmWu_YklQAAABY"], referer: http://ancestralidadytrance.space/oldsite
[Mon Jul 20 06:41:47.700109 2026] [security2:error] [pid 983757:tid 983803] [remote 57.141.18.4:50210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4636225"] [unique_id "al4Xi3KwMdFW9UVnNBS3cgABWSs"]
[Mon Jul 20 06:41:47.753891 2026] [security2:error] [pid 966386:tid 966522] [remote 192.241.143.148:41490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4XizrLBqY1mBmWu_YkzgAAblw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:41:47.841208 2026] [security2:error] [pid 966386:tid 966645] [client 173.239.240.95:25345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XizrLBqY1mBmWu_Yk1QAAAFM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:47.877589 2026] [security2:error] [pid 966386:tid 966614] [client 46.110.96.34:37158] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XizrLBqY1mBmWu_Yk2wAAADQ"]
[Mon Jul 20 06:41:47.882595 2026] [security2:error] [pid 983757:tid 983954] [client 35.245.239.138:52698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/xmlrpc.php"] [unique_id "al4Xi3KwMdFW9UVnNBS3dQAAAUs"]
[Mon Jul 20 06:41:47.882725 2026] [security2:error] [pid 983757:tid 983954] [client 35.245.239.138:52698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vinovinhowine.com"] [uri "/xmlrpc.php"] [unique_id "al4Xi3KwMdFW9UVnNBS3dQAAAUs"]
[Mon Jul 20 06:41:47.893559 2026] [security2:error] [pid 966386:tid 966679] [client 104.207.33.55:25807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XizrLBqY1mBmWu_Yk2QAAAHI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:47.948781 2026] [security2:error] [pid 983757:tid 983918] [client 112.208.70.94:44983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Xi3KwMdFW9UVnNBS3ewAAASc"]
[Mon Jul 20 06:41:47.948880 2026] [security2:error] [pid 983757:tid 983918] [client 112.208.70.94:44983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Xi3KwMdFW9UVnNBS3ewAAASc"]
[Mon Jul 20 06:41:47.990941 2026] [security2:error] [pid 983757:tid 983908] [client 57.141.18.113:28210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XinKwMdFW9UVnNBS3IwABHU0"]
[Mon Jul 20 06:41:47.994555 2026] [security2:error] [pid 966386:tid 966429] [remote 5.252.52.249:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XizrLBqY1mBmWu_Yk4gAAHwI"]
[Mon Jul 20 06:41:48.215128 2026] [security2:error] [pid 983757:tid 983986] [client 57.141.18.43:55184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XinKwMdFW9UVnNBS3NAABa10"]
[Mon Jul 20 06:41:48.219821 2026] [security2:error] [pid 966386:tid 966549] [remote 5.252.52.249:51424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XjDrLBqY1mBmWu_Yk6wAAXXc"], referer: https://zoa.jji.mybluehost.me/wp-login.php
[Mon Jul 20 06:41:48.233259 2026] [security2:error] [pid 983757:tid 983910] [client 14.225.17.146:49525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4XinKwMdFW9UVnNBS3HwAAAR8"], referer: http://www.justinagrayman.com/oldsite
[Mon Jul 20 06:41:48.307228 2026] [security2:error] [pid 966386:tid 966591] [client 98.159.234.160:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XjDrLBqY1mBmWu_Yk8QAAAB0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:41:48.309854 2026] [security2:error] [pid 983757:tid 983935] [client 136.144.35.247:54739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XjHKwMdFW9UVnNBS3hwAAATg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:48.326327 2026] [security2:error] [pid 983757:tid 983898] [client 104.234.53.77:48503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XjHKwMdFW9UVnNBS3hgAAARM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:48.463487 2026] [security2:error] [pid 983757:tid 983955] [client 170.64.227.98:55250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4XjHKwMdFW9UVnNBS3iQAAAUw"]
[Mon Jul 20 06:41:48.475637 2026] [security2:error] [pid 966386:tid 966642] [client 57.141.18.15:53422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XijrLBqY1mBmWu_YknQAAUCc"]
[Mon Jul 20 06:41:48.661741 2026] [security2:error] [pid 983757:tid 983913] [client 104.207.61.19:60621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XjHKwMdFW9UVnNBS3oAAAASI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:48.693082 2026] [security2:error] [pid 966386:tid 966563] [client 57.141.18.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XjDrLBqY1mBmWu_Yk9gAAAAI"]
[Mon Jul 20 06:41:48.748086 2026] [security2:error] [pid 983757:tid 983964] [client 57.141.18.7:60352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XinKwMdFW9UVnNBS3SwABVSc"]
[Mon Jul 20 06:41:48.760913 2026] [security2:error] [pid 966386:tid 966547] [remote 72.167.132.114:36960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XjDrLBqY1mBmWu_Yk_gAAQnU"]
[Mon Jul 20 06:41:48.763966 2026] [security2:error] [pid 983757:tid 983938] [client 136.144.35.248:35319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XjHKwMdFW9UVnNBS3qQAAATs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:48.999589 2026] [security2:error] [pid 966386:tid 966507] [remote 72.167.132.114:36960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XjDrLBqY1mBmWu_YlCAAACU0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:41:49.083708 2026] [security2:error] [pid 983757:tid 983966] [client 170.64.227.98:55291] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4XjXKwMdFW9UVnNBS3wgAAAVc"]
[Mon Jul 20 06:41:49.162193 2026] [security2:error] [pid 966386:tid 966572] [client 14.251.3.155:58480] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XjTrLBqY1mBmWu_YlEgAAAAo"]
[Mon Jul 20 06:41:49.233651 2026] [security2:error] [pid 983757:tid 983967] [client 136.144.35.248:40581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XjXKwMdFW9UVnNBS3yQAAAVg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:49.401374 2026] [security2:error] [pid 966386:tid 966540] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XjTrLBqY1mBmWu_YlGQAAMG4"]
[Mon Jul 20 06:41:49.401507 2026] [security2:error] [pid 966386:tid 966610] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XjTrLBqY1mBmWu_YlGQAAMG4"]
[Mon Jul 20 06:41:49.442160 2026] [security2:error] [pid 966386:tid 966652] [client 104.207.60.254:27209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XjTrLBqY1mBmWu_YlGgAAAFo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:49.706092 2026] [security2:error] [pid 983757:tid 983995] [client 136.144.35.244:38569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XjXKwMdFW9UVnNBS35AAAAXQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:49.711673 2026] [security2:error] [pid 983757:tid 983972] [client 187.108.85.186:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XjXKwMdFW9UVnNBS35QAAAV0"]
[Mon Jul 20 06:41:49.711822 2026] [security2:error] [pid 983757:tid 983972] [client 187.108.85.186:60017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XjXKwMdFW9UVnNBS35QAAAV0"]
[Mon Jul 20 06:41:49.726556 2026] [security2:error] [pid 983757:tid 983982] [client 152.58.191.29:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XjXKwMdFW9UVnNBS35wAAAWc"]
[Mon Jul 20 06:41:49.726646 2026] [security2:error] [pid 983757:tid 983982] [client 152.58.191.29:56397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XjXKwMdFW9UVnNBS35wAAAWc"]
[Mon Jul 20 06:41:50.000036 2026] [security2:error] [pid 966386:tid 966629] [client 14.225.17.146:60320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4XjTrLBqY1mBmWu_YlLQAAAEM"], referer: http://kromosenergy.com/oldsite
[Mon Jul 20 06:41:50.164084 2026] [security2:error] [pid 983757:tid 983980] [client 136.144.35.245:47447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XjnKwMdFW9UVnNBS39gAAAWU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:50.169239 2026] [security2:error] [pid 966386:tid 966605] [client 14.225.17.146:59893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XjTrLBqY1mBmWu_YlOAAAACs"], referer: http://mezzacraft.com/oldsite
[Mon Jul 20 06:41:50.187830 2026] [security2:error] [pid 983757:tid 983976] [client 103.153.183.69:35794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4XjnKwMdFW9UVnNBS39wAAAWE"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:41:50.235907 2026] [security2:error] [pid 983757:tid 983967] [client 77.110.127.138:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XjnKwMdFW9UVnNBS3_gAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:50.235981 2026] [security2:error] [pid 983757:tid 983967] [client 77.110.127.138:52890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XjnKwMdFW9UVnNBS3_gAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:50.407418 2026] [security2:error] [pid 983757:tid 983922] [client 52.233.165.60:10626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XjnKwMdFW9UVnNBS4BgAAASs"]
[Mon Jul 20 06:41:50.459831 2026] [security2:error] [pid 966386:tid 966564] [client 57.141.18.95:31066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XjTrLBqY1mBmWu_YlDwAAAww"]
[Mon Jul 20 06:41:50.552548 2026] [security2:error] [pid 983757:tid 983930] [client 52.233.165.60:10626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XjnKwMdFW9UVnNBS4FQAAATM"]
[Mon Jul 20 06:41:50.634492 2026] [security2:error] [pid 983757:tid 983936] [client 173.239.240.93:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XjnKwMdFW9UVnNBS4GwAAATk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:50.795636 2026] [security2:error] [pid 983757:tid 984005] [client 104.234.53.66:39195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XjnKwMdFW9UVnNBS4IwAAAX4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:50.815922 2026] [security2:error] [pid 983757:tid 983950] [client 217.181.92.145:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XjnKwMdFW9UVnNBS4IgAAAUc"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:50.856221 2026] [proxy:error] [pid 983757:tid 983980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:41:50.856292 2026] [proxy_http:error] [pid 983757:tid 983980] [client 34.73.38.214:64877] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:50.856844 2026] [proxy:error] [pid 983757:tid 983980] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:41:50.856873 2026] [proxy_http:error] [pid 983757:tid 983980] [client 34.73.38.214:64877] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:50.908815 2026] [security2:error] [pid 983757:tid 983891] [client 14.225.17.146:63323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4XjXKwMdFW9UVnNBS36wAAAQw"], referer: http://ravmike.com/oldsite
[Mon Jul 20 06:41:50.921188 2026] [security2:error] [pid 983757:tid 983924] [client 103.153.183.69:35794] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4XjnKwMdFW9UVnNBS4JgAAAS0"], referer: https://twitter.com/
[Mon Jul 20 06:41:51.011954 2026] [security2:error] [pid 966386:tid 966582] [client 103.238.106.162:60762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XjzrLBqY1mBmWu_YlWQAAABQ"]
[Mon Jul 20 06:41:51.012104 2026] [security2:error] [pid 966386:tid 966582] [client 103.238.106.162:60762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XjzrLBqY1mBmWu_YlWQAAABQ"]
[Mon Jul 20 06:41:51.049960 2026] [security2:error] [pid 983757:tid 983983] [client 192.178.15.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4XjXKwMdFW9UVnNBS3wAAAAWg"]
[Mon Jul 20 06:41:51.116122 2026] [security2:error] [pid 983757:tid 983940] [client 136.144.35.245:38057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4KwAAAT0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:51.302310 2026] [security2:error] [pid 983757:tid 983864] [remote 111.225.148.232:55600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/"] [unique_id "al4Xj3KwMdFW9UVnNBS4NgABOGg"]
[Mon Jul 20 06:41:51.340660 2026] [security2:error] [pid 983757:tid 983760] [remote 154.66.198.148:27936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4NwABfQA"]
[Mon Jul 20 06:41:51.550123 2026] [security2:error] [pid 983757:tid 983969] [client 114.119.139.207:59681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4Xj3KwMdFW9UVnNBS4QgAAAVo"], referer: https://newstral.com/en/article/en/1133465107/ribbon-cutting-takes-place-at-my-buddy-s-pet-resort
[Mon Jul 20 06:41:51.565445 2026] [security2:error] [pid 966386:tid 966608] [client 136.144.35.253:22593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XjzrLBqY1mBmWu_YlbAAAAC4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:51.641608 2026] [security2:error] [pid 983757:tid 983918] [client 217.142.18.172:63576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4TQAAASc"]
[Mon Jul 20 06:41:51.645150 2026] [security2:error] [pid 983757:tid 983918] [client 217.142.18.172:63576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4TQAAASc"]
[Mon Jul 20 06:41:51.665196 2026] [security2:error] [pid 983757:tid 983998] [client 104.207.48.156:60409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4TgAAAXc"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:51.726183 2026] [security2:error] [pid 983757:tid 983972] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4PwAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:51.796502 2026] [security2:error] [pid 983757:tid 983813] [remote 152.228.213.32:36116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4VwABNTU"]
[Mon Jul 20 06:41:51.796733 2026] [security2:error] [pid 983757:tid 983932] [client 152.228.213.32:36116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4VwABNTU"]
[Mon Jul 20 06:41:51.840816 2026] [security2:error] [pid 983757:tid 983894] [client 57.141.18.68:27908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XjnKwMdFW9UVnNBS4CwABD1Q"]
[Mon Jul 20 06:41:51.863742 2026] [security2:error] [pid 983757:tid 983893] [client 14.225.17.146:63254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4WAAAAQ4"], referer: https://ravmike.com/oldsite
[Mon Jul 20 06:41:51.871243 2026] [security2:error] [pid 983757:tid 983854] [remote 154.66.198.148:27936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4XAABWV4"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:41:51.910862 2026] [authz_core:error] [pid 983757:tid 984012] [client 66.132.224.82:5672] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini
[Mon Jul 20 06:41:51.966886 2026] [security2:error] [pid 966386:tid 966627] [client 57.141.18.0:21042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XjjrLBqY1mBmWu_YlRwAAQXk"]
[Mon Jul 20 06:41:52.045998 2026] [security2:error] [pid 983757:tid 984014] [client 173.239.240.98:48273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XkHKwMdFW9UVnNBS4ZwAAAYc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:52.112584 2026] [security2:error] [pid 966386:tid 966687] [client 103.181.212.250:64499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.212.181.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XkDrLBqY1mBmWu_YlegAAAHo"]
[Mon Jul 20 06:41:52.112708 2026] [security2:error] [pid 966386:tid 966687] [client 103.181.212.250:64499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XkDrLBqY1mBmWu_YlegAAAHo"]
[Mon Jul 20 06:41:52.232980 2026] [security2:error] [pid 983757:tid 983952] [client 14.225.17.146:50907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4Xj3KwMdFW9UVnNBS4MgAAAUk"], referer: http://entuvy.com/oldsite
[Mon Jul 20 06:41:52.337256 2026] [security2:error] [pid 966386:tid 966490] [remote 154.61.75.100:38156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XkDrLBqY1mBmWu_YliwAAXzw"]
[Mon Jul 20 06:41:52.337561 2026] [security2:error] [pid 966386:tid 966657] [client 154.61.75.100:38156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XkDrLBqY1mBmWu_YliwAAXzw"]
[Mon Jul 20 06:41:52.360485 2026] [security2:error] [pid 966386:tid 966599] [client 57.141.18.32:52090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XjzrLBqY1mBmWu_YlXwAAJWc"]
[Mon Jul 20 06:41:52.385462 2026] [security2:error] [pid 966386:tid 966492] [remote 188.166.241.141:43734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XkDrLBqY1mBmWu_YljwAAdj4"]
[Mon Jul 20 06:41:52.398188 2026] [security2:error] [pid 966386:tid 966583] [client 14.225.17.146:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4XjjrLBqY1mBmWu_YlVQAAABU"], referer: http://cephasnext.com/oldsite
[Mon Jul 20 06:41:52.430251 2026] [security2:error] [pid 966386:tid 966640] [client 45.3.46.109:42115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XkDrLBqY1mBmWu_YlkwAAAE4"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:41:52.555800 2026] [security2:error] [pid 966386:tid 966642] [client 136.144.35.244:26861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XkDrLBqY1mBmWu_YlmgAAAFA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:52.757187 2026] [security2:error] [pid 966386:tid 966525] [remote 188.166.241.141:43734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XkDrLBqY1mBmWu_YlpgAACl8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:41:53.034625 2026] [security2:error] [pid 966386:tid 966670] [client 173.239.240.99:42339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XkTrLBqY1mBmWu_YlrwAAAGk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:53.056624 2026] [proxy:error] [pid 966386:tid 966630] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:41:53.056724 2026] [proxy_http:error] [pid 966386:tid 966630] [client 34.73.38.214:64892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:53.057959 2026] [proxy:error] [pid 966386:tid 966630] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:41:53.058031 2026] [proxy_http:error] [pid 966386:tid 966630] [client 34.73.38.214:64892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:53.069174 2026] [security2:error] [pid 983757:tid 983955] [client 217.181.92.12:27799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XkXKwMdFW9UVnNBS4gQAAAUw"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:41:53.497319 2026] [security2:error] [pid 966386:tid 966610] [client 103.125.179.95:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XkTrLBqY1mBmWu_YlxgAAADA"]
[Mon Jul 20 06:41:53.497422 2026] [security2:error] [pid 966386:tid 966610] [client 103.125.179.95:60264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XkTrLBqY1mBmWu_YlxgAAADA"]
[Mon Jul 20 06:41:53.543150 2026] [security2:error] [pid 983757:tid 984004] [client 136.144.35.246:27879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XkXKwMdFW9UVnNBS4lwAAAX0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:53.566237 2026] [security2:error] [pid 983757:tid 983999] [client 77.110.127.138:52904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XkXKwMdFW9UVnNBS4mAAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:53.566322 2026] [security2:error] [pid 983757:tid 983999] [client 77.110.127.138:52904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XkXKwMdFW9UVnNBS4mAAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:53.598355 2026] [security2:error] [pid 983757:tid 983845] [remote 192.241.143.148:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XkXKwMdFW9UVnNBS4mQABL1U"]
[Mon Jul 20 06:41:53.694672 2026] [security2:error] [pid 983757:tid 983911] [client 37.52.210.45:57497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XkXKwMdFW9UVnNBS4oAAAASA"]
[Mon Jul 20 06:41:53.694859 2026] [security2:error] [pid 983757:tid 983911] [client 37.52.210.45:57497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XkXKwMdFW9UVnNBS4oAAAASA"]
[Mon Jul 20 06:41:53.705061 2026] [security2:error] [pid 983757:tid 983896] [client 223.185.13.213:31693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XkXKwMdFW9UVnNBS4ogAAARE"]
[Mon Jul 20 06:41:53.705175 2026] [security2:error] [pid 983757:tid 983896] [client 223.185.13.213:31693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XkXKwMdFW9UVnNBS4ogAAARE"]
[Mon Jul 20 06:41:53.791253 2026] [security2:error] [pid 983757:tid 983865] [remote 192.241.143.148:36342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XkXKwMdFW9UVnNBS4qQABC2k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:41:53.914365 2026] [security2:error] [pid 983757:tid 983805] [remote 154.66.198.148:27938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XkXKwMdFW9UVnNBS4rQABhi0"]
[Mon Jul 20 06:41:53.914593 2026] [security2:error] [pid 983757:tid 984013] [client 154.66.198.148:27938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XkXKwMdFW9UVnNBS4rQABhi0"]
[Mon Jul 20 06:41:53.963686 2026] [security2:error] [pid 983757:tid 983951] [client 216.73.217.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theprocess.oldcartsconsulting.com"] [uri "/index.php"] [unique_id "al4XkXKwMdFW9UVnNBS4lgAAAUg"]
[Mon Jul 20 06:41:53.975631 2026] [security2:error] [pid 983757:tid 983998] [client 57.141.18.22:35098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XkHKwMdFW9UVnNBS4dQABd2w"]
[Mon Jul 20 06:41:54.016326 2026] [security2:error] [pid 966386:tid 966563] [client 173.239.240.32:29175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XkjrLBqY1mBmWu_Yl4AAAAAI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:54.061648 2026] [security2:error] [pid 983757:tid 983891] [client 66.249.74.129:53647] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.candlelitchapters.com"] [uri "/robots.txt"] [unique_id "al4XknKwMdFW9UVnNBS4sgAAAQw"]
[Mon Jul 20 06:41:54.305237 2026] [security2:error] [pid 966386:tid 966597] [client 50.116.65.227:41830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XkjrLBqY1mBmWu_Yl8gAAACM"]
[Mon Jul 20 06:41:54.315651 2026] [security2:error] [pid 966386:tid 966684] [client 50.116.65.227:41840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XkjrLBqY1mBmWu_Yl8wAAAHc"]
[Mon Jul 20 06:41:54.490476 2026] [security2:error] [pid 966386:tid 966618] [client 136.144.35.244:27741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XkjrLBqY1mBmWu_Yl9gAAADg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:54.800394 2026] [security2:error] [pid 983757:tid 983924] [client 14.224.227.113:54612] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XknKwMdFW9UVnNBS40AAAAS0"]
[Mon Jul 20 06:41:54.968147 2026] [security2:error] [pid 983757:tid 983927] [client 39.48.81.23:61966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XknKwMdFW9UVnNBS40wAAATA"]
[Mon Jul 20 06:41:54.969334 2026] [security2:error] [pid 983757:tid 983927] [client 39.48.81.23:61966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XknKwMdFW9UVnNBS40wAAATA"]
[Mon Jul 20 06:41:54.972992 2026] [security2:error] [pid 966386:tid 966591] [client 136.144.35.253:47173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XkjrLBqY1mBmWu_YmEAAAAB0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:55.105460 2026] [security2:error] [pid 966386:tid 966634] [client 89.124.113.107:59430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-comments-post.php"] [unique_id "al4XkzrLBqY1mBmWu_YmEwAAAEg"], referer: https://schuttfarms.com/product/dollhouse-bitty-bunny-knit-pattern/
[Mon Jul 20 06:41:55.105640 2026] [security2:error] [pid 966386:tid 966634] [client 89.124.113.107:59430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "schuttfarms.com"] [uri "/wp-comments-post.php"] [unique_id "al4XkzrLBqY1mBmWu_YmEwAAAEg"], referer: https://schuttfarms.com/product/dollhouse-bitty-bunny-knit-pattern/
[Mon Jul 20 06:41:55.383564 2026] [security2:error] [pid 966386:tid 966642] [client 57.141.18.97:36956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XkTrLBqY1mBmWu_Yl3QAAUHU"]
[Mon Jul 20 06:41:55.456617 2026] [security2:error] [pid 983757:tid 983774] [remote 45.90.123.233:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Xk3KwMdFW9UVnNBS45QABRQ4"]
[Mon Jul 20 06:41:55.466322 2026] [security2:error] [pid 966386:tid 966601] [client 173.239.240.98:22409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XkzrLBqY1mBmWu_YmJAAAACc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:55.659041 2026] [security2:error] [pid 983757:tid 983807] [remote 45.90.123.233:39896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Xk3KwMdFW9UVnNBS48QABeC8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:41:55.746494 2026] [proxy:error] [pid 966386:tid 966659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:41:55.746570 2026] [proxy_http:error] [pid 966386:tid 966659] [client 34.73.38.214:53689] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:55.748121 2026] [proxy:error] [pid 966386:tid 966659] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:41:55.748164 2026] [proxy_http:error] [pid 966386:tid 966659] [client 34.73.38.214:53689] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:41:55.969066 2026] [security2:error] [pid 983757:tid 983983] [client 14.225.17.146:58409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4XknKwMdFW9UVnNBS4vgAAAWg"], referer: http://maplerespiteservices.com/oldsite
[Mon Jul 20 06:41:55.972022 2026] [security2:error] [pid 983757:tid 983809] [remote 57.141.18.22:44296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6131311"] [unique_id "al4Xk3KwMdFW9UVnNBS5AQABhjE"]
[Mon Jul 20 06:41:55.977406 2026] [security2:error] [pid 966386:tid 966639] [client 173.239.240.91:31661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XkzrLBqY1mBmWu_YmSwAAAE0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:56.297417 2026] [security2:error] [pid 983757:tid 983796] [remote 81.173.115.7:50502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XlHKwMdFW9UVnNBS5DQABZiQ"]
[Mon Jul 20 06:41:56.297587 2026] [security2:error] [pid 983757:tid 983981] [client 81.173.115.7:50502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XlHKwMdFW9UVnNBS5DQABZiQ"]
[Mon Jul 20 06:41:56.462717 2026] [security2:error] [pid 966386:tid 966578] [client 136.144.35.250:45513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XlDrLBqY1mBmWu_YmZAAAABA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:56.557616 2026] [security2:error] [pid 966386:tid 966613] [client 106.219.188.178:3286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XlDrLBqY1mBmWu_YmaQAAADM"]
[Mon Jul 20 06:41:56.557798 2026] [security2:error] [pid 966386:tid 966613] [client 106.219.188.178:3286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XlDrLBqY1mBmWu_YmaQAAADM"]
[Mon Jul 20 06:41:56.609666 2026] [security2:error] [pid 983757:tid 983945] [client 78.188.10.239:22733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.10.188.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besoundful.com"] [uri "/xmlrpc.php"] [unique_id "al4XlHKwMdFW9UVnNBS5GAAAAUI"]
[Mon Jul 20 06:41:56.609781 2026] [security2:error] [pid 983757:tid 983945] [client 78.188.10.239:22733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "besoundful.com"] [uri "/xmlrpc.php"] [unique_id "al4XlHKwMdFW9UVnNBS5GAAAAUI"]
[Mon Jul 20 06:41:56.640459 2026] [security2:error] [pid 966386:tid 966606] [client 14.225.17.146:63146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4XlDrLBqY1mBmWu_YmdAAAACw"], referer: http://daseighty.net/oldsite
[Mon Jul 20 06:41:56.791606 2026] [security2:error] [pid 983757:tid 983941] [client 57.141.18.34:26716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xk3KwMdFW9UVnNBS43gABPiw"]
[Mon Jul 20 06:41:56.815145 2026] [security2:error] [pid 983757:tid 983892] [client 14.225.17.146:59795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4Xk3KwMdFW9UVnNBS46gAAAQ0"]
[Mon Jul 20 06:41:56.861367 2026] [security2:error] [pid 983757:tid 983989] [client 15.237.142.234:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XlHKwMdFW9UVnNBS5KwAAAW4"]
[Mon Jul 20 06:41:56.861501 2026] [security2:error] [pid 983757:tid 983989] [client 15.237.142.234:55038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XlHKwMdFW9UVnNBS5KwAAAW4"]
[Mon Jul 20 06:41:56.936819 2026] [security2:error] [pid 983757:tid 983900] [client 173.239.240.100:63567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XlHKwMdFW9UVnNBS5MwAAARU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:56.954536 2026] [security2:error] [pid 983757:tid 983767] [remote 8.217.108.67:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4XlHKwMdFW9UVnNBS5NAABcwc"]
[Mon Jul 20 06:41:57.111174 2026] [security2:error] [pid 983757:tid 983998] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XlHKwMdFW9UVnNBS5LAAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:57.222918 2026] [security2:error] [pid 966386:tid 966681] [client 122.183.32.225:29313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XlTrLBqY1mBmWu_YmmwAAAHQ"]
[Mon Jul 20 06:41:57.223033 2026] [security2:error] [pid 966386:tid 966681] [client 122.183.32.225:29313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XlTrLBqY1mBmWu_YmmwAAAHQ"]
[Mon Jul 20 06:41:57.230161 2026] [security2:error] [pid 983757:tid 983971] [client 14.225.17.146:64872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4XlHKwMdFW9UVnNBS5DgAAAVw"], referer: http://walkingandtalking.net/oldsite
[Mon Jul 20 06:41:57.407670 2026] [security2:error] [pid 966386:tid 966630] [client 173.239.240.31:50277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XlTrLBqY1mBmWu_YmqgAAAEQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:57.491207 2026] [security2:error] [pid 966386:tid 966601] [client 171.61.165.146:16323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XlTrLBqY1mBmWu_YmsAAAACc"]
[Mon Jul 20 06:41:57.491313 2026] [security2:error] [pid 966386:tid 966601] [client 171.61.165.146:16323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XlTrLBqY1mBmWu_YmsAAAACc"]
[Mon Jul 20 06:41:57.615708 2026] [security2:error] [pid 966386:tid 966633] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XlTrLBqY1mBmWu_YmqAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:57.695825 2026] [security2:error] [pid 966386:tid 966610] [client 57.141.18.41:56700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XlDrLBqY1mBmWu_YmXwAAMBI"]
[Mon Jul 20 06:41:57.769772 2026] [security2:error] [pid 966386:tid 966570] [client 114.119.136.68:53975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "recruitinginsight.us"] [uri "/page/21"] [unique_id "al4XlTrLBqY1mBmWu_YmwQAAAAg"], referer: https://recruitinginsight.us/page/22?et_blog
[Mon Jul 20 06:41:57.829206 2026] [security2:error] [pid 966386:tid 966639] [client 197.186.66.42:54547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XlTrLBqY1mBmWu_YmxAAAAE0"]
[Mon Jul 20 06:41:57.836147 2026] [security2:error] [pid 966386:tid 966639] [client 197.186.66.42:54547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XlTrLBqY1mBmWu_YmxAAAAE0"]
[Mon Jul 20 06:41:57.880341 2026] [security2:error] [pid 966386:tid 966671] [client 57.141.18.60:20470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XlDrLBqY1mBmWu_YmaAAAamc"]
[Mon Jul 20 06:41:57.882732 2026] [security2:error] [pid 983757:tid 983941] [client 173.239.240.98:33529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XlXKwMdFW9UVnNBS5UQAAAT4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:58.193811 2026] [security2:error] [pid 983757:tid 983970] [client 52.44.174.136:8278] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/wp-content/uploads/2025/09/pasta-making-252x300.jpg"] [unique_id "al4XlnKwMdFW9UVnNBS5VwAAAVs"]
[Mon Jul 20 06:41:58.237286 2026] [security2:error] [pid 983757:tid 983968] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XlnKwMdFW9UVnNBS5VQAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:58.287341 2026] [security2:error] [pid 983757:tid 983966] [client 46.110.96.34:43483] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XlnKwMdFW9UVnNBS5XgAAAVc"]
[Mon Jul 20 06:41:58.329378 2026] [security2:error] [pid 983757:tid 983953] [client 14.225.17.146:50043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4XlnKwMdFW9UVnNBS5XwAAAUo"], referer: https://walkingandtalking.net/oldsite
[Mon Jul 20 06:41:58.338800 2026] [security2:error] [pid 983757:tid 983981] [client 173.239.240.90:34393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XlnKwMdFW9UVnNBS5YgAAAWY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:58.348911 2026] [security2:error] [pid 983757:tid 984004] [client 46.110.96.34:63527] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4XlnKwMdFW9UVnNBS5ZAAAAX0"]
[Mon Jul 20 06:41:58.355744 2026] [security2:error] [pid 983757:tid 983995] [client 57.141.18.24:64544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XlXKwMdFW9UVnNBS5OAABdEs"]
[Mon Jul 20 06:41:58.391643 2026] [security2:error] [pid 966386:tid 966433] [remote 81.173.115.7:50508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XljrLBqY1mBmWu_Ym3gAAZAY"]
[Mon Jul 20 06:41:58.391830 2026] [security2:error] [pid 966386:tid 966663] [client 81.173.115.7:50508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XljrLBqY1mBmWu_Ym3gAAZAY"]
[Mon Jul 20 06:41:58.468797 2026] [security2:error] [pid 983757:tid 983945] [client 77.110.127.138:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XlnKwMdFW9UVnNBS5bgAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:58.468884 2026] [security2:error] [pid 983757:tid 983945] [client 77.110.127.138:52934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XlnKwMdFW9UVnNBS5bgAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:58.485144 2026] [security2:error] [pid 983757:tid 983921] [client 34.73.38.214:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XlnKwMdFW9UVnNBS5bwAAASo"]
[Mon Jul 20 06:41:58.567651 2026] [security2:error] [pid 983757:tid 983988] [client 104.234.53.58:28379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XlnKwMdFW9UVnNBS5agAAAW0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:58.621093 2026] [security2:error] [pid 966386:tid 966626] [client 112.208.70.94:45416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XljrLBqY1mBmWu_Ym5gAAAEA"]
[Mon Jul 20 06:41:58.621210 2026] [security2:error] [pid 966386:tid 966626] [client 112.208.70.94:45416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XljrLBqY1mBmWu_Ym5gAAAEA"]
[Mon Jul 20 06:41:58.709804 2026] [security2:error] [pid 983757:tid 983950] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XlnKwMdFW9UVnNBS5cgAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:58.729315 2026] [security2:error] [pid 966386:tid 966539] [remote 216.73.216.55:28384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4XljrLBqY1mBmWu_Ym6wAAJ20"]
[Mon Jul 20 06:41:58.755404 2026] [security2:error] [pid 966386:tid 966593] [client 54.169.146.187:35840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XljrLBqY1mBmWu_Ym7gAAAB8"]
[Mon Jul 20 06:41:58.755484 2026] [security2:error] [pid 966386:tid 966593] [client 54.169.146.187:35840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XljrLBqY1mBmWu_Ym7gAAAB8"]
[Mon Jul 20 06:41:58.800448 2026] [security2:error] [pid 966386:tid 966657] [client 173.239.240.94:65079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XljrLBqY1mBmWu_Ym8AAAAF8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:59.242629 2026] [security2:error] [pid 983757:tid 983976] [client 104.234.53.58:28379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5lQAAAWE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:41:59.261934 2026] [security2:error] [pid 983757:tid 983935] [client 173.239.240.92:56141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5lwAAATg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:59.282341 2026] [security2:error] [pid 966386:tid 966564] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XlzrLBqY1mBmWu_Ym_AAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:41:59.347704 2026] [security2:error] [pid 966386:tid 966591] [client 57.141.18.32:46530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XlTrLBqY1mBmWu_YmyAAAHWE"]
[Mon Jul 20 06:41:59.728319 2026] [security2:error] [pid 983757:tid 983967] [client 14.225.17.146:59411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5pwAAAVg"], referer: http://adirondackengineering.com/oldsite
[Mon Jul 20 06:41:59.729580 2026] [security2:error] [pid 966386:tid 966620] [client 173.239.240.92:50087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XlzrLBqY1mBmWu_YnFwAAADo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:41:59.758190 2026] [security2:error] [pid 983757:tid 983971] [client 14.225.17.146:59404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5ogAAAVw"], referer: http://secretkeynumerology.com/oldsite
[Mon Jul 20 06:41:59.759798 2026] [security2:error] [pid 983757:tid 983975] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5pgAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:00.110854 2026] [security2:error] [pid 983757:tid 983821] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XmHKwMdFW9UVnNBS5vQABIj0"]
[Mon Jul 20 06:42:00.111031 2026] [security2:error] [pid 983757:tid 983913] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XmHKwMdFW9UVnNBS5vQABIj0"]
[Mon Jul 20 06:42:00.180701 2026] [security2:error] [pid 966386:tid 966689] [client 136.144.35.253:30791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XmDrLBqY1mBmWu_YnKgAAAHw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:00.349447 2026] [security2:error] [pid 966386:tid 966621] [client 152.58.191.29:57683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XmDrLBqY1mBmWu_YnMwAAADs"]
[Mon Jul 20 06:42:00.349556 2026] [security2:error] [pid 966386:tid 966621] [client 152.58.191.29:57683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XmDrLBqY1mBmWu_YnMwAAADs"]
[Mon Jul 20 06:42:00.351049 2026] [security2:error] [pid 966386:tid 966560] [client 187.108.85.186:60557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XmDrLBqY1mBmWu_YnNAAAAAA"]
[Mon Jul 20 06:42:00.351119 2026] [security2:error] [pid 966386:tid 966560] [client 187.108.85.186:60557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XmDrLBqY1mBmWu_YnNAAAAAA"]
[Mon Jul 20 06:42:00.422324 2026] [security2:error] [pid 983757:tid 984006] [client 14.225.17.146:58672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5iwAAAX8"], referer: http://dadanetnet.net/oldsite
[Mon Jul 20 06:42:00.458278 2026] [security2:error] [pid 983757:tid 983873] [remote 188.166.241.141:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XmHKwMdFW9UVnNBS5yQABR3E"]
[Mon Jul 20 06:42:00.522980 2026] [security2:error] [pid 983757:tid 983961] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XmHKwMdFW9UVnNBS5wQAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:00.550932 2026] [security2:error] [pid 966386:tid 966664] [client 158.173.241.141:34125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4XmDrLBqY1mBmWu_YnMAAAZXo"]
[Mon Jul 20 06:42:00.725744 2026] [security2:error] [pid 983757:tid 983921] [client 173.239.240.94:55421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XmHKwMdFW9UVnNBS51AAAASo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:00.774989 2026] [security2:error] [pid 983757:tid 983956] [client 34.73.38.214:52749] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XmHKwMdFW9UVnNBS51wAAAU0"]
[Mon Jul 20 06:42:00.867032 2026] [security2:error] [pid 983757:tid 983887] [remote 188.166.241.141:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XmHKwMdFW9UVnNBS53gABMH8"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:00.914589 2026] [security2:error] [pid 983757:tid 983773] [remote 72.167.132.114:48106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4XmHKwMdFW9UVnNBS54gABEA0"]
[Mon Jul 20 06:42:00.921465 2026] [security2:error] [pid 983757:tid 983893] [client 14.225.17.146:58579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4XmHKwMdFW9UVnNBS51gAAAQ4"], referer: https://secretkeynumerology.com/oldsite
[Mon Jul 20 06:42:00.993813 2026] [security2:error] [pid 983757:tid 983959] [client 57.141.18.118:35534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5mQABUAE"]
[Mon Jul 20 06:42:01.036272 2026] [security2:error] [pid 983757:tid 983894] [client 14.225.17.146:58533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4Xl3KwMdFW9UVnNBS5qQAAAQ8"], referer: http://scott-assist.com/oldsite
[Mon Jul 20 06:42:01.080024 2026] [core:error] [pid 983757:tid 983978] [client 167.71.83.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:01.080065 2026] [core:error] [pid 983757:tid 983978] [client 167.71.83.202:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:01.091010 2026] [security2:error] [pid 983757:tid 983867] [remote 188.166.241.141:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XmXKwMdFW9UVnNBS58gABL2s"]
[Mon Jul 20 06:42:01.166516 2026] [security2:error] [pid 983757:tid 983798] [remote 72.167.132.114:48106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4XmXKwMdFW9UVnNBS5-QABVyY"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:42:01.175765 2026] [security2:error] [pid 966386:tid 966686] [client 173.239.240.32:47641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XmTrLBqY1mBmWu_YnVwAAAHk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:01.229989 2026] [security2:error] [pid 966386:tid 966577] [client 50.116.65.227:59780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4XmTrLBqY1mBmWu_YnWwAAAA8"]
[Mon Jul 20 06:42:01.236839 2026] [security2:error] [pid 983757:tid 983901] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XmXKwMdFW9UVnNBS56QAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:01.244284 2026] [security2:error] [pid 966386:tid 966599] [client 50.116.65.227:23214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4XmTrLBqY1mBmWu_YnXQAAAFE"]
[Mon Jul 20 06:42:01.323696 2026] [security2:error] [pid 966386:tid 966614] [client 57.141.18.39:64489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XlzrLBqY1mBmWu_YnFQAANCg"]
[Mon Jul 20 06:42:01.471535 2026] [security2:error] [pid 983757:tid 983846] [remote 188.166.241.141:38980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XmXKwMdFW9UVnNBS6DQABYlY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:01.609201 2026] [security2:error] [pid 983757:tid 983989] [client 103.238.106.162:42906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XmXKwMdFW9UVnNBS6DwAAAW4"]
[Mon Jul 20 06:42:01.609317 2026] [security2:error] [pid 983757:tid 983989] [client 103.238.106.162:42906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XmXKwMdFW9UVnNBS6DwAAAW4"]
[Mon Jul 20 06:42:01.644029 2026] [security2:error] [pid 966386:tid 966677] [client 136.144.35.244:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XmTrLBqY1mBmWu_YnaQAAAHA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:01.648435 2026] [security2:error] [pid 983757:tid 983823] [remote 162.19.86.63:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4XmXKwMdFW9UVnNBS6EQABTT8"]
[Mon Jul 20 06:42:02.025640 2026] [security2:error] [pid 983757:tid 983853] [remote 162.19.86.63:41886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4XmnKwMdFW9UVnNBS6KgABM10"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:42:02.057411 2026] [security2:error] [pid 983757:tid 983984] [client 45.3.44.22:19551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XmnKwMdFW9UVnNBS6LQAAAWk"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:02.102685 2026] [security2:error] [pid 966386:tid 966616] [client 173.239.240.32:40967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XmjrLBqY1mBmWu_YneQAAADY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:02.206991 2026] [security2:error] [pid 983757:tid 983935] [client 217.142.18.172:37763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XmnKwMdFW9UVnNBS6MwAAATg"]
[Mon Jul 20 06:42:02.214516 2026] [security2:error] [pid 983757:tid 983935] [client 217.142.18.172:37763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XmnKwMdFW9UVnNBS6MwAAATg"]
[Mon Jul 20 06:42:02.299023 2026] [security2:error] [pid 983757:tid 983969] [client 34.73.38.214:63225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XmnKwMdFW9UVnNBS6OQAAAVo"]
[Mon Jul 20 06:42:02.549303 2026] [security2:error] [pid 966386:tid 966603] [client 173.239.240.97:40879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XmjrLBqY1mBmWu_YniwAAACk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:02.594598 2026] [security2:error] [pid 983757:tid 984002] [client 34.73.38.214:55855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XmnKwMdFW9UVnNBS6QQAAAXs"]
[Mon Jul 20 06:42:02.663730 2026] [security2:error] [pid 966386:tid 966685] [client 57.141.18.98:36114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XmTrLBqY1mBmWu_YnTwAAeGM"]
[Mon Jul 20 06:42:02.800994 2026] [security2:error] [pid 983757:tid 983781] [remote 114.119.141.232:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aleishapenny.ca"] [uri "/robots.txt"] [unique_id "al4XmnKwMdFW9UVnNBS6TQABTRU"], referer: https://aleishapenny.ca/robots.txt
[Mon Jul 20 06:42:02.806537 2026] [security2:error] [pid 983757:tid 983977] [client 14.225.17.146:58568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4XmnKwMdFW9UVnNBS6QwAAAWI"], referer: http://ivetstrategies.com/oldsite
[Mon Jul 20 06:42:03.012962 2026] [security2:error] [pid 966386:tid 966681] [client 173.239.240.91:58533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XmzrLBqY1mBmWu_YnogAAAHQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:03.031225 2026] [security2:error] [pid 983757:tid 983973] [client 50.116.65.227:59782] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Mong-Kok-Feature-Image.jpg"] [unique_id "al4Xm3KwMdFW9UVnNBS6UQAAAV4"]
[Mon Jul 20 06:42:03.041642 2026] [security2:error] [pid 983757:tid 983925] [client 50.116.65.227:23242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Mong-Kok-Feature-Image.jpg"] [unique_id "al4Xm3KwMdFW9UVnNBS6UwAAAUQ"]
[Mon Jul 20 06:42:03.090669 2026] [security2:error] [pid 966386:tid 966609] [client 77.110.127.138:52956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XmzrLBqY1mBmWu_YnpwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:03.090797 2026] [security2:error] [pid 966386:tid 966609] [client 77.110.127.138:52956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XmzrLBqY1mBmWu_YnpwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:03.414804 2026] [security2:error] [pid 983757:tid 983995] [client 45.3.32.194:36423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Xm3KwMdFW9UVnNBS6cAAAAXQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:42:03.466858 2026] [security2:error] [pid 966386:tid 966601] [client 136.144.35.253:50107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XmzrLBqY1mBmWu_YnvgAAACc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:03.599518 2026] [security2:error] [pid 983757:tid 983889] [client 57.141.18.115:50602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XmXKwMdFW9UVnNBS6JwABCmQ"]
[Mon Jul 20 06:42:03.777868 2026] [security2:error] [pid 983757:tid 984003] [client 223.185.13.213:22847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Xm3KwMdFW9UVnNBS6cwAAAXw"]
[Mon Jul 20 06:42:03.777988 2026] [security2:error] [pid 983757:tid 984003] [client 223.185.13.213:22847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Xm3KwMdFW9UVnNBS6cwAAAXw"]
[Mon Jul 20 06:42:03.917309 2026] [security2:error] [pid 966386:tid 966634] [client 136.144.35.252:37285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XmzrLBqY1mBmWu_Yn1wAAAEg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:03.921035 2026] [security2:error] [pid 983757:tid 983797] [remote 97.74.93.24:34306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4Xm3KwMdFW9UVnNBS6dwABayU"]
[Mon Jul 20 06:42:04.185410 2026] [security2:error] [pid 983757:tid 983899] [client 34.73.38.214:54971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XnHKwMdFW9UVnNBS6iQAAARQ"]
[Mon Jul 20 06:42:04.285419 2026] [security2:error] [pid 966386:tid 966612] [client 37.52.210.45:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XnDrLBqY1mBmWu_Yn6QAAADI"]
[Mon Jul 20 06:42:04.285515 2026] [security2:error] [pid 966386:tid 966612] [client 37.52.210.45:59697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XnDrLBqY1mBmWu_Yn6QAAADI"]
[Mon Jul 20 06:42:04.358790 2026] [security2:error] [pid 983757:tid 983876] [remote 97.74.93.24:34306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4XnHKwMdFW9UVnNBS6jAABNnQ"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:42:04.403400 2026] [security2:error] [pid 983757:tid 983990] [client 136.144.35.246:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XnHKwMdFW9UVnNBS6jQAAAW8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:04.483316 2026] [security2:error] [pid 966386:tid 966627] [client 57.141.18.74:64848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XmzrLBqY1mBmWu_YnowAAQSw"]
[Mon Jul 20 06:42:04.549914 2026] [security2:error] [pid 983757:tid 983987] [client 103.125.179.95:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XnHKwMdFW9UVnNBS6kQAAAWw"]
[Mon Jul 20 06:42:04.550027 2026] [security2:error] [pid 983757:tid 983987] [client 103.125.179.95:60780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XnHKwMdFW9UVnNBS6kQAAAWw"]
[Mon Jul 20 06:42:04.614155 2026] [security2:error] [pid 983757:tid 983910] [client 223.237.130.40:56301] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XnHKwMdFW9UVnNBS6kAAAAR8"]
[Mon Jul 20 06:42:04.614298 2026] [security2:error] [pid 983757:tid 983910] [client 223.237.130.40:56301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XnHKwMdFW9UVnNBS6kAAAAR8"]
[Mon Jul 20 06:42:04.856660 2026] [security2:error] [pid 983757:tid 984012] [client 77.110.127.138:52965] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/if(now()=sysdate(),sleep(15),0)/2/"] [unique_id "al4XnHKwMdFW9UVnNBS6ywAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:04.874057 2026] [security2:error] [pid 983757:tid 983807] [remote 173.249.4.11:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4XnHKwMdFW9UVnNBS6zQABIy8"]
[Mon Jul 20 06:42:04.881406 2026] [security2:error] [pid 983757:tid 983905] [client 173.239.240.92:24095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XnHKwMdFW9UVnNBS6zgAAARo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:05.319054 2026] [security2:error] [pid 983757:tid 983878] [remote 173.249.4.11:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4XnXKwMdFW9UVnNBS66wABNnY"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:42:05.356194 2026] [security2:error] [pid 983757:tid 983962] [client 173.239.240.95:53351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XnXKwMdFW9UVnNBS67gAAAVM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:05.411645 2026] [security2:error] [pid 966386:tid 966636] [client 34.73.38.214:55918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XnTrLBqY1mBmWu_YoEAAAAEo"]
[Mon Jul 20 06:42:05.821370 2026] [security2:error] [pid 966386:tid 966594] [client 173.239.240.95:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XnTrLBqY1mBmWu_YoLQAAACA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:05.894983 2026] [security2:error] [pid 983757:tid 983972] [client 57.141.18.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4XnXKwMdFW9UVnNBS6_AAAAV0"]
[Mon Jul 20 06:42:05.936512 2026] [security2:error] [pid 983757:tid 983829] [remote 103.255.134.61:60466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XnXKwMdFW9UVnNBS6_QABf0U"]
[Mon Jul 20 06:42:06.054872 2026] [security2:error] [pid 966386:tid 966688] [client 34.73.38.214:64602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XnjrLBqY1mBmWu_YoQwAAAHs"]
[Mon Jul 20 06:42:06.169224 2026] [proxy:error] [pid 966386:tid 966640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:06.169319 2026] [proxy_http:error] [pid 966386:tid 966640] [client 195.96.139.231:39535] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:06.169993 2026] [proxy:error] [pid 966386:tid 966640] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:06.170039 2026] [proxy_http:error] [pid 966386:tid 966640] [client 195.96.139.231:39535] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:06.187546 2026] [security2:error] [pid 966386:tid 966611] [client 74.7.227.179:45424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XnjrLBqY1mBmWu_YoQgAAMTk"], referer: https://tejasenvironmental.com/p=491235
[Mon Jul 20 06:42:06.200478 2026] [security2:error] [pid 966386:tid 966568] [client 50.116.65.227:23292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XnjrLBqY1mBmWu_YoTwAAAAY"]
[Mon Jul 20 06:42:06.211065 2026] [security2:error] [pid 966386:tid 966637] [client 50.116.65.227:23300] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XnjrLBqY1mBmWu_YoUAAAAEs"]
[Mon Jul 20 06:42:06.307437 2026] [security2:error] [pid 966386:tid 966616] [client 173.239.240.92:29081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XnjrLBqY1mBmWu_YoWAAAADY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:06.329845 2026] [security2:error] [pid 966386:tid 966570] [client 57.141.18.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oohlovely.com"] [uri "/index.php"] [unique_id "al4XnTrLBqY1mBmWu_YoFQAAAAg"]
[Mon Jul 20 06:42:06.589596 2026] [security2:error] [pid 983757:tid 983993] [client 104.234.53.55:42795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XnnKwMdFW9UVnNBS6_wAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:06.755128 2026] [security2:error] [pid 966386:tid 966656] [client 50.116.65.227:23322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XnjrLBqY1mBmWu_YoagAAAF4"]
[Mon Jul 20 06:42:06.801704 2026] [security2:error] [pid 966386:tid 966597] [client 173.239.240.102:49335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XnjrLBqY1mBmWu_YofQAAACM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:06.948130 2026] [security2:error] [pid 966386:tid 966640] [client 50.116.65.227:23324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4XnjrLBqY1mBmWu_YoeAAAAE4"]
[Mon Jul 20 06:42:06.952907 2026] [security2:error] [pid 966386:tid 966607] [client 77.110.127.138:52978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XnjrLBqY1mBmWu_YohgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:06.953035 2026] [security2:error] [pid 966386:tid 966607] [client 77.110.127.138:52978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XnjrLBqY1mBmWu_YohgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:07.019580 2026] [security2:error] [pid 966386:tid 966641] [client 57.141.18.8:25458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XnTrLBqY1mBmWu_YoFgAATxg"]
[Mon Jul 20 06:42:07.040098 2026] [security2:error] [pid 966386:tid 966690] [client 34.73.38.214:63935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XnzrLBqY1mBmWu_YomwAAAH0"]
[Mon Jul 20 06:42:07.080912 2026] [security2:error] [pid 966386:tid 966580] [client 106.219.188.178:27753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XnzrLBqY1mBmWu_YonwAAABI"]
[Mon Jul 20 06:42:07.081060 2026] [security2:error] [pid 966386:tid 966580] [client 106.219.188.178:27753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XnzrLBqY1mBmWu_YonwAAABI"]
[Mon Jul 20 06:42:07.112037 2026] [security2:error] [pid 966386:tid 966586] [client 77.110.127.138:52980] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XnzrLBqY1mBmWu_YoogAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:07.236474 2026] [security2:error] [pid 966386:tid 966606] [client 104.234.53.77:22691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XnzrLBqY1mBmWu_YoqgAAACw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:07.254273 2026] [security2:error] [pid 966386:tid 966603] [client 173.239.240.95:25505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XnzrLBqY1mBmWu_YorQAAACk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:07.422806 2026] [security2:error] [pid 966386:tid 966673] [client 57.141.18.25:27382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XnTrLBqY1mBmWu_YoKAAAbHo"]
[Mon Jul 20 06:42:07.572567 2026] [security2:error] [pid 966386:tid 966479] [remote 117.0.21.154:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4XnzrLBqY1mBmWu_YoywAAADE"]
[Mon Jul 20 06:42:07.615254 2026] [security2:error] [pid 966386:tid 966591] [client 192.140.149.97:44479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XnzrLBqY1mBmWu_YozgAAAB0"]
[Mon Jul 20 06:42:07.615381 2026] [security2:error] [pid 966386:tid 966591] [client 192.140.149.97:44479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XnzrLBqY1mBmWu_YozgAAAB0"]
[Mon Jul 20 06:42:07.706500 2026] [security2:error] [pid 966386:tid 966664] [client 136.144.35.252:59647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XnzrLBqY1mBmWu_Yo0QAAAGU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:07.716712 2026] [security2:error] [pid 966386:tid 966540] [remote 160.187.68.132:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XnzrLBqY1mBmWu_Yo0AAADm4"]
[Mon Jul 20 06:42:07.881598 2026] [security2:error] [pid 966386:tid 966655] [client 138.197.12.98:49311] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4XnzrLBqY1mBmWu_Yo2gAAAF0"]
[Mon Jul 20 06:42:07.889458 2026] [security2:error] [pid 966386:tid 966596] [client 77.110.127.138:52986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/2/"] [unique_id "al4XnzrLBqY1mBmWu_Yo3wAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:07.896292 2026] [security2:error] [pid 966386:tid 966537] [remote 103.255.134.61:60632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XnzrLBqY1mBmWu_Yo4AAARms"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:08.140055 2026] [security2:error] [pid 966386:tid 966467] [remote 117.0.21.154:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4XoDrLBqY1mBmWu_Yo9QAALSc"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:42:08.173082 2026] [security2:error] [pid 966386:tid 966483] [remote 160.187.68.132:52284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XoDrLBqY1mBmWu_Yo9wAAUDU"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:42:08.182825 2026] [security2:error] [pid 966386:tid 966572] [client 173.239.240.96:31801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XoDrLBqY1mBmWu_Yo-QAAAAo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:08.205815 2026] [security2:error] [pid 966386:tid 966684] [client 34.73.38.214:60388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XoDrLBqY1mBmWu_Yo_AAAAHc"]
[Mon Jul 20 06:42:08.396960 2026] [security2:error] [pid 966386:tid 966610] [client 171.61.165.146:22165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XoDrLBqY1mBmWu_YpCgAAADA"]
[Mon Jul 20 06:42:08.397120 2026] [security2:error] [pid 966386:tid 966610] [client 171.61.165.146:22165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XoDrLBqY1mBmWu_YpCgAAADA"]
[Mon Jul 20 06:42:08.669714 2026] [security2:error] [pid 966386:tid 966615] [client 173.239.240.96:59625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XoDrLBqY1mBmWu_YpHgAAADU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:08.731933 2026] [security2:error] [pid 966386:tid 966588] [client 34.73.38.214:59081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XoDrLBqY1mBmWu_YpIQAAABo"]
[Mon Jul 20 06:42:08.762249 2026] [security2:error] [pid 966386:tid 966571] [client 57.141.18.79:55340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XnzrLBqY1mBmWu_YoswAACQc"]
[Mon Jul 20 06:42:08.832977 2026] [security2:error] [pid 966386:tid 966597] [client 57.141.18.49:58428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XnzrLBqY1mBmWu_YouwAAIws"]
[Mon Jul 20 06:42:09.135793 2026] [security2:error] [pid 966386:tid 966586] [client 57.141.18.89:48472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XnzrLBqY1mBmWu_Yo3QAAGD8"]
[Mon Jul 20 06:42:09.156502 2026] [security2:error] [pid 966386:tid 966631] [client 173.239.240.100:25059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XoTrLBqY1mBmWu_YpQgAAAEU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:09.161169 2026] [security2:error] [pid 966386:tid 966584] [client 195.239.51.73:44984] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "grndl.com"] [uri "/"] [unique_id "al4XoTrLBqY1mBmWu_YpQwAAABY"]
[Mon Jul 20 06:42:09.195956 2026] [security2:error] [pid 966386:tid 966607] [client 112.208.70.94:45866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XoTrLBqY1mBmWu_YpRwAAAC0"]
[Mon Jul 20 06:42:09.196054 2026] [security2:error] [pid 966386:tid 966607] [client 112.208.70.94:45866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XoTrLBqY1mBmWu_YpRwAAAC0"]
[Mon Jul 20 06:42:09.414407 2026] [security2:error] [pid 966386:tid 966521] [remote 57.141.18.25:27396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XoDrLBqY1mBmWu_Yo9gAAMls"]
[Mon Jul 20 06:42:09.508850 2026] [security2:error] [pid 966386:tid 966603] [client 114.119.128.244:48445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4XoTrLBqY1mBmWu_YpYAAAACk"], referer: https://www.new-menus.com/index.php?topic=84.0
[Mon Jul 20 06:42:09.573125 2026] [http2:info] [pid 1011111:tid 1011111] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:42:09.605511 2026] [security2:error] [pid 1011111:tid 1011242] [client 14.224.227.113:54626] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XoRXES7Mv0Zfga-nx1QAAAIU"]
[Mon Jul 20 06:42:09.688384 2026] [security2:error] [pid 966386:tid 966657] [client 39.48.81.23:62479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XoTrLBqY1mBmWu_YpYQAAAF8"]
[Mon Jul 20 06:42:09.688457 2026] [security2:error] [pid 966386:tid 966657] [client 39.48.81.23:62479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XoTrLBqY1mBmWu_YpYQAAAF8"]
[Mon Jul 20 06:42:09.735921 2026] [security2:error] [pid 1011111:tid 1011252] [client 173.239.240.92:32159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XoRXES7Mv0Zfga-nx7AAAAI8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:09.803697 2026] [security2:error] [pid 966386:tid 966668] [client 122.183.32.225:20931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XoTrLBqY1mBmWu_YpYgAAAGg"]
[Mon Jul 20 06:42:09.803958 2026] [security2:error] [pid 966386:tid 966668] [client 122.183.32.225:20931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XoTrLBqY1mBmWu_YpYgAAAGg"]
[Mon Jul 20 06:42:09.903530 2026] [proxy:error] [pid 1011111:tid 1011304] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:09.903576 2026] [proxy_http:error] [pid 1011111:tid 1011304] [client 34.73.38.214:54096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:09.904058 2026] [proxy:error] [pid 1011111:tid 1011304] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:09.904081 2026] [proxy_http:error] [pid 1011111:tid 1011304] [client 34.73.38.214:54096] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:09.966974 2026] [security2:error] [pid 1011111:tid 1011243] [client 104.234.53.92:57969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XoRXES7Mv0Zfga-nyAAAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:10.082088 2026] [security2:error] [pid 1011111:tid 1011133] [remote 188.95.113.76:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nyBwAAuhQ"]
[Mon Jul 20 06:42:10.082239 2026] [security2:error] [pid 1011111:tid 1011295] [client 188.95.113.76:34290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nyBwAAuhQ"]
[Mon Jul 20 06:42:10.189731 2026] [security2:error] [pid 1011111:tid 1011333] [client 136.144.35.245:45211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XohXES7Mv0Zfga-nyDQAAAOA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:10.220911 2026] [security2:error] [pid 966386:tid 966527] [remote 57.141.18.31:59626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XoDrLBqY1mBmWu_YpDwAAPWE"]
[Mon Jul 20 06:42:10.254636 2026] [security2:error] [pid 1011111:tid 1011353] [client 34.73.38.214:59081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XohXES7Mv0Zfga-nyEgAAAPQ"]
[Mon Jul 20 06:42:10.358852 2026] [security2:error] [pid 966386:tid 966475] [remote 57.141.18.74:34034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XoDrLBqY1mBmWu_YpMAAAAC4"]
[Mon Jul 20 06:42:10.661602 2026] [security2:error] [pid 1011111:tid 1011276] [client 136.144.35.248:58263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XohXES7Mv0Zfga-nyOAAAAKc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:10.861386 2026] [security2:error] [pid 1011111:tid 1011158] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nyRgAAzS0"]
[Mon Jul 20 06:42:10.861568 2026] [security2:error] [pid 1011111:tid 1011314] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nyRgAAzS0"]
[Mon Jul 20 06:42:10.926611 2026] [security2:error] [pid 1011111:tid 1011271] [client 187.108.85.186:61109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nySgAAAKI"]
[Mon Jul 20 06:42:10.926970 2026] [security2:error] [pid 1011111:tid 1011271] [client 187.108.85.186:61109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nySgAAAKI"]
[Mon Jul 20 06:42:10.981325 2026] [security2:error] [pid 1011111:tid 1011366] [client 152.58.191.29:57212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nyTgAAAQE"]
[Mon Jul 20 06:42:10.986072 2026] [security2:error] [pid 1011111:tid 1011366] [client 152.58.191.29:57212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XohXES7Mv0Zfga-nyTgAAAQE"]
[Mon Jul 20 06:42:11.027397 2026] [security2:error] [pid 1011111:tid 1011303] [client 197.186.66.42:55089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XoxXES7Mv0Zfga-nyTwAAAMI"]
[Mon Jul 20 06:42:11.027512 2026] [security2:error] [pid 1011111:tid 1011303] [client 197.186.66.42:55089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XoxXES7Mv0Zfga-nyTwAAAMI"]
[Mon Jul 20 06:42:11.084096 2026] [security2:error] [pid 1011111:tid 1011166] [remote 57.141.18.106:35740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4899371"] [unique_id "al4XoxXES7Mv0Zfga-nyUwAA-TU"]
[Mon Jul 20 06:42:11.112974 2026] [security2:error] [pid 1011111:tid 1011349] [client 173.239.240.98:57759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XoxXES7Mv0Zfga-nyXAAAAPA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:11.157148 2026] [security2:error] [pid 1011111:tid 1011258] [client 223.237.130.40:57052] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XoxXES7Mv0Zfga-nyYQAAAJU"]
[Mon Jul 20 06:42:11.157252 2026] [security2:error] [pid 1011111:tid 1011258] [client 223.237.130.40:57052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XoxXES7Mv0Zfga-nyYQAAAJU"]
[Mon Jul 20 06:42:11.579881 2026] [security2:error] [pid 1011111:tid 1011307] [client 136.144.35.251:42113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XoxXES7Mv0Zfga-nydgAAAMY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:11.821626 2026] [security2:error] [pid 1011111:tid 1011188] [remote 57.141.18.71:21354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4XoxXES7Mv0Zfga-nyigAA7Es"]
[Mon Jul 20 06:42:11.843809 2026] [security2:error] [pid 1011111:tid 1011320] [client 34.73.38.214:52188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.bzm.ppv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XoxXES7Mv0Zfga-nykQAAANM"]
[Mon Jul 20 06:42:12.054517 2026] [security2:error] [pid 1011111:tid 1011364] [client 136.144.35.246:33285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XpBXES7Mv0Zfga-nyoQAAAP8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:12.117103 2026] [security2:error] [pid 1011111:tid 1011310] [client 103.238.106.162:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XpBXES7Mv0Zfga-nyowAAAMk"]
[Mon Jul 20 06:42:12.117202 2026] [security2:error] [pid 1011111:tid 1011310] [client 103.238.106.162:60944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XpBXES7Mv0Zfga-nyowAAAMk"]
[Mon Jul 20 06:42:12.492818 2026] [proxy:error] [pid 1011111:tid 1011275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:12.492883 2026] [proxy_http:error] [pid 1011111:tid 1011275] [client 34.73.38.214:62191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:12.493355 2026] [proxy:error] [pid 1011111:tid 1011275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:12.493395 2026] [proxy_http:error] [pid 1011111:tid 1011275] [client 34.73.38.214:62191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:12.505932 2026] [security2:error] [pid 1011111:tid 1011302] [client 173.239.240.91:20461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XpBXES7Mv0Zfga-nyxQAAAME"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:12.620692 2026] [security2:error] [pid 1011111:tid 1011336] [client 57.141.18.97:48202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XohXES7Mv0Zfga-nySwAA4y8"]
[Mon Jul 20 06:42:12.729259 2026] [security2:error] [pid 1011111:tid 1011348] [client 57.141.18.61:52680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XohXES7Mv0Zfga-nyTQAA7zE"]
[Mon Jul 20 06:42:12.743665 2026] [security2:error] [pid 1011111:tid 1011329] [client 217.142.18.172:28443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XpBXES7Mv0Zfga-ny0AAAANw"]
[Mon Jul 20 06:42:12.751242 2026] [security2:error] [pid 1011111:tid 1011329] [client 217.142.18.172:28443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XpBXES7Mv0Zfga-ny0AAAANw"]
[Mon Jul 20 06:42:12.773590 2026] [security2:error] [pid 1011111:tid 1011356] [client 57.141.18.100:35250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XoxXES7Mv0Zfga-nyUgAA9zQ"]
[Mon Jul 20 06:42:12.972987 2026] [security2:error] [pid 1011111:tid 1011364] [client 136.144.35.250:51931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XpBXES7Mv0Zfga-ny3gAAAP8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:13.447152 2026] [security2:error] [pid 1011111:tid 1011313] [client 136.144.35.252:48135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XpRXES7Mv0Zfga-ny_wAAAMw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:13.624292 2026] [security2:error] [pid 1011111:tid 1011360] [client 57.141.18.92:33734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XoxXES7Mv0Zfga-nykwAA-08"]
[Mon Jul 20 06:42:13.640507 2026] [proxy:error] [pid 1011111:tid 1011353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:13.640553 2026] [proxy_http:error] [pid 1011111:tid 1011353] [client 34.73.38.214:54095] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:13.641022 2026] [proxy:error] [pid 1011111:tid 1011353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:13.641051 2026] [proxy_http:error] [pid 1011111:tid 1011353] [client 34.73.38.214:54095] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:13.756810 2026] [proxy:error] [pid 1011111:tid 1011324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:13.756861 2026] [proxy_http:error] [pid 1011111:tid 1011324] [client 54.78.13.43:33926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:13.757264 2026] [proxy:error] [pid 1011111:tid 1011324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:13.757292 2026] [proxy_http:error] [pid 1011111:tid 1011324] [client 54.78.13.43:33926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:13.783585 2026] [security2:error] [pid 1011111:tid 1011243] [client 34.73.38.214:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XpRXES7Mv0Zfga-nzFwAAAIY"]
[Mon Jul 20 06:42:13.913389 2026] [security2:error] [pid 1011111:tid 1011292] [client 173.239.240.98:23391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XpRXES7Mv0Zfga-nzKAAAALc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:13.940983 2026] [security2:error] [pid 1011111:tid 1011261] [client 57.141.18.100:35256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XpBXES7Mv0Zfga-nyqgAAmFg"]
[Mon Jul 20 06:42:14.012233 2026] [security2:error] [pid 1011111:tid 1011303] [client 66.249.70.1:37348] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "travelmigration.com"] [uri "/robots.txt"] [unique_id "al4XphXES7Mv0Zfga-nzLwAAAMI"]
[Mon Jul 20 06:42:14.173781 2026] [security2:error] [pid 1011111:tid 1011131] [remote 152.228.213.32:44470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XphXES7Mv0Zfga-nzQQAAthI"]
[Mon Jul 20 06:42:14.334787 2026] [security2:error] [pid 1011111:tid 1011134] [remote 82.221.129.39:33258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.129.221.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4XphXES7Mv0Zfga-nzSwAAmRU"]
[Mon Jul 20 06:42:14.367710 2026] [security2:error] [pid 1011111:tid 1011284] [client 173.239.240.92:37389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XphXES7Mv0Zfga-nzVwAAAK8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:14.428154 2026] [security2:error] [pid 1011111:tid 1011143] [remote 152.228.213.32:44470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XphXES7Mv0Zfga-nzXQAAhh4"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:14.520667 2026] [security2:error] [pid 1011111:tid 1011350] [client 34.21.41.254:63185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suq.iks.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XphXES7Mv0Zfga-nzYQAAAPE"]
[Mon Jul 20 06:42:14.556090 2026] [security2:error] [pid 1011111:tid 1011142] [remote 82.221.129.39:33258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.129.221.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4XphXES7Mv0Zfga-nzZwAA-B0"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 06:42:14.660421 2026] [security2:error] [pid 1011111:tid 1011311] [client 34.73.38.214:64557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XphXES7Mv0Zfga-nzdgAAAMo"]
[Mon Jul 20 06:42:14.792156 2026] [security2:error] [pid 1011111:tid 1011309] [client 34.21.41.254:61487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XphXES7Mv0Zfga-nzfQAAAMg"]
[Mon Jul 20 06:42:14.822647 2026] [security2:error] [pid 1011111:tid 1011291] [client 173.239.240.98:33519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XphXES7Mv0Zfga-nzgAAAALY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:14.976182 2026] [security2:error] [pid 1011111:tid 1011331] [client 37.52.210.45:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XphXES7Mv0Zfga-nziAAAAN4"]
[Mon Jul 20 06:42:14.976281 2026] [security2:error] [pid 1011111:tid 1011331] [client 37.52.210.45:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XphXES7Mv0Zfga-nziAAAAN4"]
[Mon Jul 20 06:42:15.143148 2026] [security2:error] [pid 1011111:tid 1011345] [client 223.185.13.213:21020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XpxXES7Mv0Zfga-nzmAAAAOw"]
[Mon Jul 20 06:42:15.143241 2026] [security2:error] [pid 1011111:tid 1011345] [client 223.185.13.213:21020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XpxXES7Mv0Zfga-nzmAAAAOw"]
[Mon Jul 20 06:42:15.216863 2026] [security2:error] [pid 1011111:tid 1011168] [remote 152.228.213.32:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XpxXES7Mv0Zfga-nzmgAArDc"]
[Mon Jul 20 06:42:15.224668 2026] [security2:error] [pid 1011111:tid 1011257] [client 34.21.41.254:51780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XpxXES7Mv0Zfga-nzmwAAAJQ"]
[Mon Jul 20 06:42:15.293738 2026] [security2:error] [pid 1011111:tid 1011256] [client 136.144.35.246:61247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XpxXES7Mv0Zfga-nzngAAAJM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:15.363701 2026] [security2:error] [pid 1011111:tid 1011253] [client 103.125.179.95:61298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XpxXES7Mv0Zfga-nzpQAAAJA"]
[Mon Jul 20 06:42:15.363832 2026] [security2:error] [pid 1011111:tid 1011253] [client 103.125.179.95:61298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XpxXES7Mv0Zfga-nzpQAAAJA"]
[Mon Jul 20 06:42:15.368023 2026] [security2:error] [pid 1011111:tid 1011272] [client 14.225.17.146:56285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4XpxXES7Mv0Zfga-nznAAAAKM"], referer: http://mobilesurvsolutions.com/new
[Mon Jul 20 06:42:15.392637 2026] [security2:error] [pid 1011111:tid 1011308] [client 34.73.38.214:60341] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XpxXES7Mv0Zfga-nzrQAAAMc"]
[Mon Jul 20 06:42:15.444485 2026] [security2:error] [pid 1011111:tid 1011176] [remote 152.228.213.32:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4XpxXES7Mv0Zfga-nzswAA6T8"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:42:15.461866 2026] [security2:error] [pid 1011111:tid 1011328] [client 14.225.17.146:57742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4XpxXES7Mv0Zfga-nzogAAANs"], referer: http://koaconsultants.com/new
[Mon Jul 20 06:42:15.531783 2026] [security2:error] [pid 1011111:tid 1011265] [client 34.21.41.254:53921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XpxXES7Mv0Zfga-nzvAAAAJw"]
[Mon Jul 20 06:42:15.686668 2026] [core:error] [pid 1011111:tid 1011275] [client 74.7.244.8:32962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:15.686694 2026] [core:error] [pid 1011111:tid 1011275] [client 74.7.244.8:32962] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:15.686819 2026] [security2:error] [pid 1011111:tid 1011275] [client 74.7.244.8:32962] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "genesisventureglobal.com"] [uri "/index.php"] [unique_id "al4XpxXES7Mv0Zfga-nz0AAAAKY"]
[Mon Jul 20 06:42:15.687849 2026] [security2:error] [pid 1011111:tid 1011191] [remote 110.249.202.43:52494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/author/profgschulz/"] [unique_id "al4XpxXES7Mv0Zfga-nz0QAAsE4"]
[Mon Jul 20 06:42:15.750493 2026] [security2:error] [pid 1011111:tid 1011356] [client 173.239.240.100:30611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XpxXES7Mv0Zfga-nz1gAAAPc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:15.800633 2026] [security2:error] [pid 1011111:tid 1011194] [remote 173.212.252.15:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4XpxXES7Mv0Zfga-nz2QAA7lE"]
[Mon Jul 20 06:42:15.815719 2026] [security2:error] [pid 1011111:tid 1011197] [remote 8.217.108.67:22240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4XpxXES7Mv0Zfga-nz2gAApFQ"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:42:15.842726 2026] [security2:error] [pid 1011111:tid 1011294] [client 34.21.41.254:50781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XpxXES7Mv0Zfga-nz3QAAALk"]
[Mon Jul 20 06:42:16.028088 2026] [security2:error] [pid 1011111:tid 1011204] [remote 173.212.252.15:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4XqBXES7Mv0Zfga-nz6QAAyVs"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:42:16.123907 2026] [security2:error] [pid 1011111:tid 1011349] [client 34.21.41.254:55527] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XqBXES7Mv0Zfga-nz-QAAAPA"]
[Mon Jul 20 06:42:16.233896 2026] [security2:error] [pid 1011111:tid 1011292] [client 173.239.240.31:44635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XqBXES7Mv0Zfga-n0AAAAALc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:16.401023 2026] [security2:error] [pid 1011111:tid 1011347] [client 34.73.38.214:55119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XqBXES7Mv0Zfga-n0DQAAAO4"]
[Mon Jul 20 06:42:16.460021 2026] [security2:error] [pid 1011111:tid 1011297] [client 57.141.18.10:23096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XphXES7Mv0Zfga-nzhQAAvCo"]
[Mon Jul 20 06:42:16.487032 2026] [security2:error] [pid 1011111:tid 1011248] [client 34.21.41.254:52311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XqBXES7Mv0Zfga-n0EwAAAIs"]
[Mon Jul 20 06:42:16.599281 2026] [security2:error] [pid 1011111:tid 1011254] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XqBXES7Mv0Zfga-n0HQAAAJE"]
[Mon Jul 20 06:42:16.762232 2026] [security2:error] [pid 1011111:tid 1011296] [client 34.21.41.254:61637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XqBXES7Mv0Zfga-n0LAAAALs"]
[Mon Jul 20 06:42:16.779795 2026] [security2:error] [pid 1011111:tid 1011309] [client 173.239.240.100:53945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XqBXES7Mv0Zfga-n0KwAAAMg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:17.086146 2026] [security2:error] [pid 1011111:tid 1011277] [client 34.21.41.254:51071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XqRXES7Mv0Zfga-n0SAAAAKg"]
[Mon Jul 20 06:42:17.156663 2026] [security2:error] [pid 1011111:tid 1011361] [client 114.119.137.141:49047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.omrobuildingcenter.com"] [uri "/robots.txt"] [unique_id "al4XqRXES7Mv0Zfga-n0TgAAAPw"], referer: http://www.omrobuildingcenter.com/robots.txt
[Mon Jul 20 06:42:17.169211 2026] [security2:error] [pid 1011111:tid 1011364] [client 39.48.81.23:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0UQAAAP8"]
[Mon Jul 20 06:42:17.169394 2026] [security2:error] [pid 1011111:tid 1011364] [client 39.48.81.23:62994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0UQAAAP8"]
[Mon Jul 20 06:42:17.230928 2026] [security2:error] [pid 1011111:tid 1011248] [client 173.239.240.91:61085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XqRXES7Mv0Zfga-n0WQAAAIs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:17.363058 2026] [security2:error] [pid 1011111:tid 1011315] [client 34.21.41.254:63927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XqRXES7Mv0Zfga-n0ZQAAAM4"]
[Mon Jul 20 06:42:17.402464 2026] [security2:error] [pid 1011111:tid 1011341] [client 77.110.127.138:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XqRXES7Mv0Zfga-n0aAAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:17.402579 2026] [security2:error] [pid 1011111:tid 1011341] [client 77.110.127.138:53006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XqRXES7Mv0Zfga-n0aAAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:17.457950 2026] [security2:error] [pid 1011111:tid 1011267] [client 34.73.38.214:57041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XqRXES7Mv0Zfga-n0bgAAAJ4"]
[Mon Jul 20 06:42:17.523596 2026] [security2:error] [pid 1011111:tid 1011120] [remote 217.182.128.41:51390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4XqRXES7Mv0Zfga-n0dgAAzQc"], referer: https://gvillemoving.com/wp-login.php
[Mon Jul 20 06:42:17.525495 2026] [security2:error] [pid 1011111:tid 1011280] [client 57.141.18.11:61222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XpxXES7Mv0Zfga-nz4wAAq1U"]
[Mon Jul 20 06:42:17.562089 2026] [security2:error] [pid 1011111:tid 1011290] [client 77.110.127.138:53009] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XqRXES7Mv0Zfga-n0eAAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:17.624356 2026] [security2:error] [pid 1011111:tid 1011357] [client 34.21.41.254:52760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XqRXES7Mv0Zfga-n0ewAAAPg"]
[Mon Jul 20 06:42:17.710389 2026] [security2:error] [pid 1011111:tid 1011297] [client 173.239.240.96:28193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XqRXES7Mv0Zfga-n0hQAAALw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:17.757338 2026] [security2:error] [pid 1011111:tid 1011257] [client 192.140.149.97:44953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0jgAAAJQ"]
[Mon Jul 20 06:42:17.757422 2026] [security2:error] [pid 1011111:tid 1011257] [client 192.140.149.97:44953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0jgAAAJQ"]
[Mon Jul 20 06:42:17.800735 2026] [security2:error] [pid 1011111:tid 1011352] [client 106.219.188.178:25936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0jwAAAPM"]
[Mon Jul 20 06:42:17.802474 2026] [security2:error] [pid 1011111:tid 1011352] [client 106.219.188.178:25936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0jwAAAPM"]
[Mon Jul 20 06:42:17.883665 2026] [security2:error] [pid 1011111:tid 1011274] [client 34.21.41.254:64865] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "suq.iks.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XqRXES7Mv0Zfga-n0lAAAAKU"]
[Mon Jul 20 06:42:17.900849 2026] [security2:error] [pid 1011111:tid 1011240] [remote 217.182.128.41:51390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-login.php"] [unique_id "al4XqRXES7Mv0Zfga-n0lgAA7X8"], referer: https://gvillemoving.com/wp-login.php
[Mon Jul 20 06:42:18.043922 2026] [security2:error] [pid 1011111:tid 1011316] [client 183.82.98.154:50971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0ngAAAM8"]
[Mon Jul 20 06:42:18.044057 2026] [security2:error] [pid 1011111:tid 1011316] [client 183.82.98.154:50971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XqRXES7Mv0Zfga-n0ngAAAM8"]
[Mon Jul 20 06:42:18.196682 2026] [security2:error] [pid 1011111:tid 1011288] [client 136.144.35.243:54871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XqhXES7Mv0Zfga-n0pwAAALM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:18.407539 2026] [security2:error] [pid 1011111:tid 1011140] [remote 152.228.213.32:56664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XqhXES7Mv0Zfga-n0vQAAnxs"]
[Mon Jul 20 06:42:18.412114 2026] [security2:error] [pid 1011111:tid 1011255] [client 77.110.127.138:53015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/2/"] [unique_id "al4XqhXES7Mv0Zfga-n0vwAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:18.522765 2026] [security2:error] [pid 1011111:tid 1011300] [client 57.141.18.25:28424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XqRXES7Mv0Zfga-n0QwAAv3A"]
[Mon Jul 20 06:42:18.669598 2026] [security2:error] [pid 1011111:tid 1011265] [client 136.144.35.248:39121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XqhXES7Mv0Zfga-n01QAAAJw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:18.707559 2026] [security2:error] [pid 1011111:tid 1011151] [remote 57.141.18.62:39036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5891448"] [unique_id "al4XqhXES7Mv0Zfga-n02AAA-yY"]
[Mon Jul 20 06:42:18.821250 2026] [security2:error] [pid 1011111:tid 1011152] [remote 152.228.213.32:56664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XqhXES7Mv0Zfga-n04QAAxCc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:19.030936 2026] [security2:error] [pid 1011111:tid 1011256] [client 57.141.18.124:59958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XqRXES7Mv0Zfga-n0awAAk34"]
[Mon Jul 20 06:42:19.139231 2026] [security2:error] [pid 1011111:tid 1011354] [client 173.239.240.98:34551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XqxXES7Mv0Zfga-n0_AAAAPU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:19.233354 2026] [security2:error] [pid 1011111:tid 1011174] [remote 91.142.222.105:60468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4XqxXES7Mv0Zfga-n1AgAAhz0"]
[Mon Jul 20 06:42:19.275834 2026] [security2:error] [pid 1011111:tid 1011293] [client 171.61.165.146:24189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XqxXES7Mv0Zfga-n1BQAAALg"]
[Mon Jul 20 06:42:19.276529 2026] [security2:error] [pid 1011111:tid 1011293] [client 171.61.165.146:24189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XqxXES7Mv0Zfga-n1BQAAALg"]
[Mon Jul 20 06:42:19.346160 2026] [security2:error] [pid 1011111:tid 1011291] [client 14.225.17.146:58266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4XqxXES7Mv0Zfga-n0-wAAALY"], referer: http://www.justinagrayman.com/new
[Mon Jul 20 06:42:19.413684 2026] [security2:error] [pid 1011111:tid 1011179] [remote 162.19.86.63:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XqxXES7Mv0Zfga-n1DAAAhkI"]
[Mon Jul 20 06:42:19.469026 2026] [security2:error] [pid 1011111:tid 1011331] [client 14.225.17.146:53231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4XqhXES7Mv0Zfga-n0qwAAAN4"], referer: http://whiteoutcb.com/new
[Mon Jul 20 06:42:19.570844 2026] [security2:error] [pid 1011111:tid 1011256] [client 34.73.38.214:64694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XqxXES7Mv0Zfga-n1HQAAAJM"]
[Mon Jul 20 06:42:19.590320 2026] [security2:error] [pid 1011111:tid 1011286] [client 173.239.240.91:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XqxXES7Mv0Zfga-n1IwAAALE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:19.628652 2026] [security2:error] [pid 1011111:tid 1011195] [remote 162.19.86.63:60112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XqxXES7Mv0Zfga-n1KAAAlVI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:19.676587 2026] [security2:error] [pid 1011111:tid 1011288] [client 34.139.11.221:61534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/xmlrpc.php"] [unique_id "al4XqxXES7Mv0Zfga-n1LQAAALM"]
[Mon Jul 20 06:42:19.803733 2026] [security2:error] [pid 1011111:tid 1011335] [client 14.225.17.146:50466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4XqxXES7Mv0Zfga-n1HAAAAOI"], referer: http://savilerowtravel.com/new
[Mon Jul 20 06:42:19.812843 2026] [security2:error] [pid 1011111:tid 1011337] [client 14.225.17.146:60604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4XqhXES7Mv0Zfga-n0ugAAAOQ"], referer: http://expertcultures.com/new
[Mon Jul 20 06:42:19.813340 2026] [security2:error] [pid 1011111:tid 1011363] [client 34.139.11.221:64986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XqxXES7Mv0Zfga-n1QAAAAP4"]
[Mon Jul 20 06:42:19.816295 2026] [security2:error] [pid 1011111:tid 1011278] [client 112.208.70.94:42285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XqxXES7Mv0Zfga-n1QgAAAKk"]
[Mon Jul 20 06:42:19.816379 2026] [security2:error] [pid 1011111:tid 1011278] [client 112.208.70.94:42285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XqxXES7Mv0Zfga-n1QgAAAKk"]
[Mon Jul 20 06:42:19.826240 2026] [security2:error] [pid 1011111:tid 1011186] [remote 91.142.222.105:60468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4XqxXES7Mv0Zfga-n1QQAAr0k"], referer: https://according2plant.com/wp-login.php
[Mon Jul 20 06:42:20.015142 2026] [security2:error] [pid 1011111:tid 1011256] [client 34.139.11.221:52517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1UQAAAJM"]
[Mon Jul 20 06:42:20.061489 2026] [security2:error] [pid 1011111:tid 1011280] [client 136.144.35.250:30959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1UwAAAKs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:20.146145 2026] [security2:error] [pid 1011111:tid 1011357] [client 34.139.11.221:50234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1XQAAAPg"]
[Mon Jul 20 06:42:20.260603 2026] [security2:error] [pid 1011111:tid 1011307] [client 34.139.11.221:62867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1agAAAMY"]
[Mon Jul 20 06:42:20.338062 2026] [security2:error] [pid 1011111:tid 1011155] [remote 95.217.78.234:36190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1bgAAoyo"]
[Mon Jul 20 06:42:20.401177 2026] [security2:error] [pid 1011111:tid 1011331] [client 34.139.11.221:53510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1egAAAN4"]
[Mon Jul 20 06:42:20.534285 2026] [security2:error] [pid 1011111:tid 1011284] [client 173.239.240.90:21743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XrBXES7Mv0Zfga-n1gwAAAK8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:20.536174 2026] [security2:error] [pid 1011111:tid 1011324] [client 34.139.11.221:63804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1hQAAANc"]
[Mon Jul 20 06:42:20.563907 2026] [security2:error] [pid 1011111:tid 1011165] [remote 95.217.78.234:36190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1hgAAvDQ"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:42:20.594427 2026] [security2:error] [pid 1011111:tid 1011224] [remote 103.75.185.95:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1hwAA028"]
[Mon Jul 20 06:42:20.754691 2026] [security2:error] [pid 1011111:tid 1011322] [client 34.139.11.221:51391] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1lgAAANU"]
[Mon Jul 20 06:42:20.759960 2026] [security2:error] [pid 1011111:tid 1011282] [client 104.207.51.52:45871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1lAAAAK0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:20.800986 2026] [security2:error] [pid 1011111:tid 1011345] [client 77.110.127.138:53029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XrBXES7Mv0Zfga-n1ngAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:20.801104 2026] [security2:error] [pid 1011111:tid 1011345] [client 77.110.127.138:53029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XrBXES7Mv0Zfga-n1ngAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:20.824388 2026] [security2:error] [pid 1011111:tid 1011292] [client 122.183.32.225:32972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XrBXES7Mv0Zfga-n1ogAAALc"]
[Mon Jul 20 06:42:20.824514 2026] [security2:error] [pid 1011111:tid 1011292] [client 122.183.32.225:32972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XrBXES7Mv0Zfga-n1ogAAALc"]
[Mon Jul 20 06:42:20.839361 2026] [security2:error] [pid 1011111:tid 1011330] [client 14.225.17.146:59712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4XrBXES7Mv0Zfga-n1kAAAAN0"], referer: http://adirondackengineering.com/new
[Mon Jul 20 06:42:20.890218 2026] [security2:error] [pid 1011111:tid 1011284] [client 34.139.11.221:63065] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XrBXES7Mv0Zfga-n1rwAAAK8"]
[Mon Jul 20 06:42:20.990731 2026] [security2:error] [pid 1011111:tid 1011281] [client 173.239.240.93:43527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1tAAAAKw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:20.992672 2026] [security2:error] [pid 1011111:tid 1011236] [remote 95.217.78.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4XrBXES7Mv0Zfga-n1tgAA0ns"]
[Mon Jul 20 06:42:21.046423 2026] [security2:error] [pid 1011111:tid 1011266] [client 34.139.11.221:49176] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XrRXES7Mv0Zfga-n1uwAAAJ0"]
[Mon Jul 20 06:42:21.090250 2026] [security2:error] [pid 1011111:tid 1011235] [remote 103.75.185.95:60696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4XrRXES7Mv0Zfga-n1vgAA4Xo"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 06:42:21.194668 2026] [security2:error] [pid 1011111:tid 1011362] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4XrBXES7Mv0Zfga-n1sgAA_V8"], referer: http://assasalnazaha.com/new
[Mon Jul 20 06:42:21.219685 2026] [security2:error] [pid 1011111:tid 1011309] [client 14.225.17.146:61035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4XrRXES7Mv0Zfga-n1uAAAAMg"], referer: http://longevityperformanceclinic.com/new
[Mon Jul 20 06:42:21.283817 2026] [security2:error] [pid 1011111:tid 1011317] [client 34.139.11.221:63164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XrRXES7Mv0Zfga-n1zAAAANA"]
[Mon Jul 20 06:42:21.344159 2026] [security2:error] [pid 1011111:tid 1011242] [client 14.225.17.146:50398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4XqxXES7Mv0Zfga-n1SgAAAIU"], referer: http://eduardsales.com/new
[Mon Jul 20 06:42:21.368310 2026] [security2:error] [pid 1011111:tid 1011342] [client 151.123.176.248:59557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XrRXES7Mv0Zfga-n10QAAAOk"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:21.434866 2026] [security2:error] [pid 1011111:tid 1011263] [client 34.139.11.221:53905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XrRXES7Mv0Zfga-n13AAAAJo"]
[Mon Jul 20 06:42:21.451516 2026] [security2:error] [pid 1011111:tid 1011345] [client 136.144.35.250:45015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XrRXES7Mv0Zfga-n13gAAAOw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:21.529472 2026] [security2:error] [pid 1011111:tid 1011201] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XrRXES7Mv0Zfga-n15AAA-Fg"]
[Mon Jul 20 06:42:21.529672 2026] [security2:error] [pid 1011111:tid 1011357] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XrRXES7Mv0Zfga-n15AAA-Fg"]
[Mon Jul 20 06:42:21.554502 2026] [security2:error] [pid 1011111:tid 1011124] [remote 95.217.78.234:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4XrRXES7Mv0Zfga-n15gAAzAs"], referer: https://benbayly.co.nz/wp-login.php
[Mon Jul 20 06:42:21.582078 2026] [security2:error] [pid 1011111:tid 1011256] [client 187.108.85.186:61663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XrRXES7Mv0Zfga-n16AAAAJM"]
[Mon Jul 20 06:42:21.582174 2026] [security2:error] [pid 1011111:tid 1011256] [client 187.108.85.186:61663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XrRXES7Mv0Zfga-n16AAAAJM"]
[Mon Jul 20 06:42:21.629164 2026] [security2:error] [pid 1011111:tid 1011352] [client 158.173.89.95:53725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XrRXES7Mv0Zfga-n17wAAAPM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:42:21.641890 2026] [security2:error] [pid 1011111:tid 1011288] [client 34.139.11.221:49422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eliteeventsleaders.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XrRXES7Mv0Zfga-n18AAAALM"]
[Mon Jul 20 06:42:21.768491 2026] [security2:error] [pid 1011111:tid 1011347] [client 152.58.191.29:57643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XrRXES7Mv0Zfga-n1-AAAAO4"]
[Mon Jul 20 06:42:21.768622 2026] [security2:error] [pid 1011111:tid 1011347] [client 152.58.191.29:57643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XrRXES7Mv0Zfga-n1-AAAAO4"]
[Mon Jul 20 06:42:21.925217 2026] [security2:error] [pid 1011111:tid 1011282] [client 173.239.240.92:53535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XrRXES7Mv0Zfga-n2CQAAAK0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:21.973218 2026] [security2:error] [pid 1011111:tid 1011307] [client 104.207.50.15:25415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XrRXES7Mv0Zfga-n2CwAAAMY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:22.130036 2026] [security2:error] [pid 1011111:tid 1011143] [remote 45.90.123.233:49962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2GQAAlB4"]
[Mon Jul 20 06:42:22.130181 2026] [security2:error] [pid 1011111:tid 1011135] [remote 152.228.213.32:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4XrhXES7Mv0Zfga-n2GAAAiRY"]
[Mon Jul 20 06:42:22.130205 2026] [security2:error] [pid 1011111:tid 1011257] [client 45.90.123.233:49962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2GQAAlB4"]
[Mon Jul 20 06:42:22.231096 2026] [security2:error] [pid 1011111:tid 1011336] [client 57.141.18.68:48876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XrBXES7Mv0Zfga-n1sQAA43g"]
[Mon Jul 20 06:42:22.317244 2026] [security2:error] [pid 1011111:tid 1011364] [client 223.237.130.40:57512] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2LQAAAP8"]
[Mon Jul 20 06:42:22.317477 2026] [security2:error] [pid 1011111:tid 1011364] [client 223.237.130.40:57512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2LQAAAP8"]
[Mon Jul 20 06:42:22.347192 2026] [security2:error] [pid 1011111:tid 1011147] [remote 152.228.213.32:56672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4XrhXES7Mv0Zfga-n2NAABACI"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 06:42:22.384969 2026] [security2:error] [pid 1011111:tid 1011333] [client 173.239.240.95:40065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XrhXES7Mv0Zfga-n2NwAAAOA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:22.447067 2026] [security2:error] [pid 1011111:tid 1011323] [client 213.152.162.79:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2PQAAANY"]
[Mon Jul 20 06:42:22.447170 2026] [security2:error] [pid 1011111:tid 1011323] [client 213.152.162.79:50556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2PQAAANY"]
[Mon Jul 20 06:42:22.467178 2026] [security2:error] [pid 1011111:tid 1011341] [client 34.73.38.214:56782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XrhXES7Mv0Zfga-n2PwAAAOg"]
[Mon Jul 20 06:42:22.592247 2026] [security2:error] [pid 1011111:tid 1011359] [client 57.141.18.74:34854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XrRXES7Mv0Zfga-n1yAAA-gA"]
[Mon Jul 20 06:42:22.608264 2026] [security2:error] [pid 1011111:tid 1011318] [client 65.111.28.191:28803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XrhXES7Mv0Zfga-n2RAAAANE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:22.661921 2026] [security2:error] [pid 1011111:tid 1011354] [client 103.238.106.162:60870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2TgAAAPU"]
[Mon Jul 20 06:42:22.662109 2026] [security2:error] [pid 1011111:tid 1011354] [client 103.238.106.162:60870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XrhXES7Mv0Zfga-n2TgAAAPU"]
[Mon Jul 20 06:42:22.780818 2026] [security2:error] [pid 1011111:tid 1011303] [client 65.111.4.182:47291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.4.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XrhXES7Mv0Zfga-n2UgAAAMI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:42:22.858472 2026] [security2:error] [pid 1011111:tid 1011336] [client 173.239.240.97:36639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XrhXES7Mv0Zfga-n2ZgAAAOM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:23.241277 2026] [security2:error] [pid 1011111:tid 1011295] [client 14.225.17.146:50346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4XrxXES7Mv0Zfga-n2dwAAALo"], referer: http://getgarrison.com/new
[Mon Jul 20 06:42:23.243969 2026] [security2:error] [pid 1011111:tid 1011293] [client 65.111.26.68:63771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XrxXES7Mv0Zfga-n2fQAAALg"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:23.247412 2026] [security2:error] [pid 1011111:tid 1011254] [client 217.142.18.172:41929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XrxXES7Mv0Zfga-n2gAAAAJE"]
[Mon Jul 20 06:42:23.254659 2026] [security2:error] [pid 1011111:tid 1011254] [client 217.142.18.172:41929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XrxXES7Mv0Zfga-n2gAAAAJE"]
[Mon Jul 20 06:42:23.330603 2026] [security2:error] [pid 1011111:tid 1011363] [client 136.144.35.246:59239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XrxXES7Mv0Zfga-n2igAAAP4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:23.366074 2026] [security2:error] [pid 1011111:tid 1011346] [client 153.185.251.67:57391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.251.185.153.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/xmlrpc.php"] [unique_id "al4XrxXES7Mv0Zfga-n2jQAAAO0"]
[Mon Jul 20 06:42:23.366210 2026] [security2:error] [pid 1011111:tid 1011346] [client 153.185.251.67:57391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bigwormfishing.com"] [uri "/xmlrpc.php"] [unique_id "al4XrxXES7Mv0Zfga-n2jQAAAO0"]
[Mon Jul 20 06:42:23.532208 2026] [security2:error] [pid 1011111:tid 1011344] [client 197.186.66.42:55640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XrxXES7Mv0Zfga-n2mQAAAOs"]
[Mon Jul 20 06:42:23.532303 2026] [security2:error] [pid 1011111:tid 1011344] [client 197.186.66.42:55640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XrxXES7Mv0Zfga-n2mQAAAOs"]
[Mon Jul 20 06:42:23.709661 2026] [security2:error] [pid 1011111:tid 1011347] [client 14.225.17.146:61044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4XrxXES7Mv0Zfga-n2nQAAAO4"], referer: http://ghivs.com/new
[Mon Jul 20 06:42:23.714679 2026] [security2:error] [pid 1011111:tid 1011296] [client 104.234.53.80:34581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XrxXES7Mv0Zfga-n2pgAAALs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:23.832218 2026] [security2:error] [pid 1011111:tid 1011302] [client 173.239.240.90:24515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XrxXES7Mv0Zfga-n2rAAAAME"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:23.852522 2026] [security2:error] [pid 1011111:tid 1011314] [client 34.73.38.214:61529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XrxXES7Mv0Zfga-n2sQAAAM0"]
[Mon Jul 20 06:42:23.915862 2026] [security2:error] [pid 1011111:tid 1011259] [client 104.207.57.230:26537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XrxXES7Mv0Zfga-n2tQAAAJY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:24.246869 2026] [security2:error] [pid 1011111:tid 1011327] [client 144.172.114.51:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thescarystory.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XsBXES7Mv0Zfga-n2ygAAANo"]
[Mon Jul 20 06:42:24.307270 2026] [security2:error] [pid 1011111:tid 1011297] [client 136.144.35.246:38355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XsBXES7Mv0Zfga-n2ywAAALw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:24.340384 2026] [security2:error] [pid 1011111:tid 1011321] [client 57.141.18.104:55270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XrhXES7Mv0Zfga-n2VQAA1Cc"]
[Mon Jul 20 06:42:24.533863 2026] [security2:error] [pid 1011111:tid 1011349] [client 65.111.20.54:30475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XsBXES7Mv0Zfga-n23gAAAPA"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:24.758598 2026] [security2:error] [pid 1011111:tid 1011274] [client 136.144.35.245:40681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XsBXES7Mv0Zfga-n28AAAAKU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:24.856181 2026] [security2:error] [pid 1011111:tid 1011344] [client 14.225.17.146:61112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4XsBXES7Mv0Zfga-n26wAAAOs"], referer: http://hammadownenterprises.com/new
[Mon Jul 20 06:42:24.953954 2026] [security2:error] [pid 1011111:tid 1011272] [client 158.173.166.181:30697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XsBXES7Mv0Zfga-n3CwAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:42:25.003245 2026] [security2:error] [pid 1011111:tid 1011359] [client 14.251.3.155:54640] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XsRXES7Mv0Zfga-n3DgAAAPo"]
[Mon Jul 20 06:42:25.016268 2026] [security2:error] [pid 1011111:tid 1011298] [client 57.141.18.71:52434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XrxXES7Mv0Zfga-n2owAAvVI"]
[Mon Jul 20 06:42:25.053268 2026] [security2:error] [pid 1011111:tid 1011304] [client 14.225.17.146:51407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4XsBXES7Mv0Zfga-n3DAAAAMM"], referer: http://entuvy.com/new
[Mon Jul 20 06:42:25.208094 2026] [security2:error] [pid 1011111:tid 1011311] [client 136.144.35.251:36073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XsRXES7Mv0Zfga-n3HAAAAMo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:25.242562 2026] [security2:error] [pid 1011111:tid 1011307] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4XsRXES7Mv0Zfga-n3FQAAxm4"], referer: http://aleishapenny.ca/new
[Mon Jul 20 06:42:25.356856 2026] [security2:error] [pid 1011111:tid 1011275] [client 223.185.13.213:5803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XsRXES7Mv0Zfga-n3JQAAAKY"]
[Mon Jul 20 06:42:25.356944 2026] [security2:error] [pid 1011111:tid 1011275] [client 223.185.13.213:5803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XsRXES7Mv0Zfga-n3JQAAAKY"]
[Mon Jul 20 06:42:25.432268 2026] [security2:error] [pid 1011111:tid 1011244] [client 34.73.38.214:63508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XsRXES7Mv0Zfga-n3KgAAAIc"]
[Mon Jul 20 06:42:25.563850 2026] [security2:error] [pid 1011111:tid 1011246] [client 57.141.18.11:26172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XsBXES7Mv0Zfga-n2yAAAiVk"]
[Mon Jul 20 06:42:25.659954 2026] [security2:error] [pid 1011111:tid 1011297] [client 136.144.35.243:51871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XsRXES7Mv0Zfga-n3QAAAALw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:25.665881 2026] [security2:error] [pid 1011111:tid 1011289] [client 37.52.210.45:62687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XsRXES7Mv0Zfga-n3QgAAALQ"]
[Mon Jul 20 06:42:25.665964 2026] [security2:error] [pid 1011111:tid 1011289] [client 37.52.210.45:62687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XsRXES7Mv0Zfga-n3QgAAALQ"]
[Mon Jul 20 06:42:26.017693 2026] [security2:error] [pid 1011111:tid 1011254] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4XsRXES7Mv0Zfga-n3TAAAkQM"], referer: https://aleishapenny.ca/new
[Mon Jul 20 06:42:26.073994 2026] [security2:error] [pid 1011111:tid 1011121] [remote 195.26.253.119:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3XgAA_wg"]
[Mon Jul 20 06:42:26.204362 2026] [security2:error] [pid 1011111:tid 1011362] [client 136.144.35.250:42971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3ZgAAAP0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:26.252597 2026] [security2:error] [pid 1011111:tid 1011296] [client 103.125.179.95:61804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XshXES7Mv0Zfga-n3agAAALs"]
[Mon Jul 20 06:42:26.252707 2026] [security2:error] [pid 1011111:tid 1011296] [client 103.125.179.95:61804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XshXES7Mv0Zfga-n3agAAALs"]
[Mon Jul 20 06:42:26.258259 2026] [security2:error] [pid 1011111:tid 1011131] [remote 195.26.253.119:39602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3bAAAxhI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:26.380820 2026] [security2:error] [pid 1011111:tid 1011125] [remote 8.217.108.67:27244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4XshXES7Mv0Zfga-n3cgAAsAw"]
[Mon Jul 20 06:42:26.381012 2026] [security2:error] [pid 1011111:tid 1011285] [client 8.217.108.67:27244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4XshXES7Mv0Zfga-n3cgAAsAw"]
[Mon Jul 20 06:42:26.394731 2026] [security2:error] [pid 1011111:tid 1011332] [client 217.61.143.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3cwAAAN8"]
[Mon Jul 20 06:42:26.520501 2026] [security2:error] [pid 1011111:tid 1011249] [client 14.225.17.146:57729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4XsBXES7Mv0Zfga-n3CgAAAIw"], referer: http://nurturemarple.co.uk/new
[Mon Jul 20 06:42:26.530217 2026] [security2:error] [pid 1011111:tid 1011335] [client 34.73.38.214:53596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XshXES7Mv0Zfga-n3hgAAAOI"]
[Mon Jul 20 06:42:26.591781 2026] [security2:error] [pid 1011111:tid 1011337] [client 57.141.18.95:35448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XsRXES7Mv0Zfga-n3HQAA5HQ"]
[Mon Jul 20 06:42:26.637643 2026] [security2:error] [pid 1011111:tid 1011343] [client 104.28.219.192:44071] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "greenvillemoving.com"] [uri "/.env"] [unique_id "al4XshXES7Mv0Zfga-n3kQAAAOo"]
[Mon Jul 20 06:42:26.705129 2026] [security2:error] [pid 1011111:tid 1011336] [client 217.61.143.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3lQAAAOM"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:42:26.780823 2026] [security2:error] [pid 1011111:tid 1011294] [client 136.144.35.249:32607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3mwAAALk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:26.783057 2026] [security2:error] [pid 1011111:tid 1011366] [client 173.239.224.29:53759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4XshXES7Mv0Zfga-n3mgAAAQE"]
[Mon Jul 20 06:42:26.939652 2026] [security2:error] [pid 1011111:tid 1011364] [client 50.116.65.227:30138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XshXES7Mv0Zfga-n3qAAAAP8"]
[Mon Jul 20 06:42:26.949191 2026] [security2:error] [pid 1011111:tid 1011280] [client 50.116.65.227:30146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XshXES7Mv0Zfga-n3rwAAAKs"]
[Mon Jul 20 06:42:26.968348 2026] [security2:error] [pid 1011111:tid 1011362] [client 50.116.65.227:30130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4XshXES7Mv0Zfga-n3jwAAAP0"]
[Mon Jul 20 06:42:27.072346 2026] [security2:error] [pid 1011111:tid 1011315] [client 39.48.81.23:63501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XsxXES7Mv0Zfga-n3vQAAAM4"]
[Mon Jul 20 06:42:27.072611 2026] [security2:error] [pid 1011111:tid 1011315] [client 39.48.81.23:63501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XsxXES7Mv0Zfga-n3vQAAAM4"]
[Mon Jul 20 06:42:27.171567 2026] [security2:error] [pid 1011111:tid 1011308] [client 57.141.18.114:44344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XsRXES7Mv0Zfga-n3SQAAx1U"]
[Mon Jul 20 06:42:27.173284 2026] [security2:error] [pid 1011111:tid 1011253] [client 50.116.65.227:30154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4XshXES7Mv0Zfga-n3swAAAJA"]
[Mon Jul 20 06:42:27.199676 2026] [security2:error] [pid 1011111:tid 1011261] [client 77.110.127.138:53071] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4XsxXES7Mv0Zfga-n3zQAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:27.231402 2026] [security2:error] [pid 1011111:tid 1011290] [client 173.239.240.91:42585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n30QAAALU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:27.256130 2026] [security2:error] [pid 1011111:tid 1011303] [client 104.28.219.192:44073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XshXES7Mv0Zfga-n3tAAAANo"]
[Mon Jul 20 06:42:27.431988 2026] [security2:error] [pid 1011111:tid 1011258] [client 104.28.219.192:44071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n3zgAAAIo"]
[Mon Jul 20 06:42:27.456586 2026] [security2:error] [pid 1011111:tid 1011310] [client 14.225.17.146:59101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n31QAAAMk"], referer: https://nurturemarple.co.uk/new
[Mon Jul 20 06:42:27.489397 2026] [security2:error] [pid 1011111:tid 1011283] [client 104.28.219.192:43382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n3zwAAALM"]
[Mon Jul 20 06:42:27.510483 2026] [security2:error] [pid 1011111:tid 1011362] [client 104.28.219.192:43380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n30gAAAPs"]
[Mon Jul 20 06:42:27.705400 2026] [security2:error] [pid 1011111:tid 1011243] [client 173.239.240.92:21445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XsxXES7Mv0Zfga-n39QAAAIY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:27.708223 2026] [security2:error] [pid 1011111:tid 1011248] [client 104.28.219.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n35wAAAIs"]
[Mon Jul 20 06:42:27.907424 2026] [security2:error] [pid 1011111:tid 1011261] [client 104.28.219.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n3-wAAAJg"]
[Mon Jul 20 06:42:28.011253 2026] [security2:error] [pid 1011111:tid 1011356] [client 104.28.219.192:43382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n4AQAAAME"]
[Mon Jul 20 06:42:28.202303 2026] [security2:error] [pid 1011111:tid 1011249] [client 173.239.240.92:49039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XtBXES7Mv0Zfga-n4JwAAAIw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:28.239381 2026] [security2:error] [pid 1011111:tid 1011332] [client 104.28.219.192:19407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "greenvillemoving.com"] [uri "/wp-config.php~"] [unique_id "al4XtBXES7Mv0Zfga-n4KwAAAN8"]
[Mon Jul 20 06:42:28.277246 2026] [security2:error] [pid 1011111:tid 1011245] [client 104.28.219.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XtBXES7Mv0Zfga-n4GQAAAIg"]
[Mon Jul 20 06:42:28.288176 2026] [security2:error] [pid 1011111:tid 1011367] [client 104.28.219.192:44076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "greenvillemoving.com"] [uri "/wp-config.php.old"] [unique_id "al4XtBXES7Mv0Zfga-n4LgAAAQI"]
[Mon Jul 20 06:42:28.295148 2026] [security2:error] [pid 1011111:tid 1011196] [remote 91.142.222.105:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XtBXES7Mv0Zfga-n4LQAAjlM"]
[Mon Jul 20 06:42:28.310485 2026] [security2:error] [pid 1011111:tid 1011305] [client 34.73.38.214:62316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XtBXES7Mv0Zfga-n4LwAAAMQ"]
[Mon Jul 20 06:42:28.510175 2026] [security2:error] [pid 1011111:tid 1011353] [client 106.219.188.178:8576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XtBXES7Mv0Zfga-n4RAAAAPQ"]
[Mon Jul 20 06:42:28.510279 2026] [security2:error] [pid 1011111:tid 1011353] [client 106.219.188.178:8576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XtBXES7Mv0Zfga-n4RAAAAPQ"]
[Mon Jul 20 06:42:28.567502 2026] [security2:error] [pid 1011111:tid 1011281] [client 183.82.98.154:51700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XtBXES7Mv0Zfga-n4RgAAAKw"]
[Mon Jul 20 06:42:28.567632 2026] [security2:error] [pid 1011111:tid 1011281] [client 183.82.98.154:51700] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XtBXES7Mv0Zfga-n4RgAAAKw"]
[Mon Jul 20 06:42:28.671416 2026] [security2:error] [pid 1011111:tid 1011328] [client 136.144.35.244:50849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XtBXES7Mv0Zfga-n4SwAAANs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:28.856233 2026] [security2:error] [pid 1011111:tid 1011248] [client 104.28.219.192:43382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XtBXES7Mv0Zfga-n4TgAAAIs"]
[Mon Jul 20 06:42:28.899742 2026] [security2:error] [pid 1011111:tid 1011343] [client 57.141.18.28:58918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n3wwAA6ig"]
[Mon Jul 20 06:42:29.122231 2026] [security2:error] [pid 1011111:tid 1011319] [client 136.144.35.252:21733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4eQAAANI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:29.141339 2026] [security2:error] [pid 1011111:tid 1011306] [client 104.28.219.192:37874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "greenvillemoving.com"] [uri "/wp-config.php.bak"] [unique_id "al4XtRXES7Mv0Zfga-n4ewAAAMU"]
[Mon Jul 20 06:42:29.156616 2026] [security2:error] [pid 1011111:tid 1011315] [client 104.28.219.192:47797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.219.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "greenvillemoving.com"] [uri "/wp-config.php"] [unique_id "al4XtRXES7Mv0Zfga-n4fAAAAM4"]
[Mon Jul 20 06:42:29.209542 2026] [security2:error] [pid 1011111:tid 1011362] [client 104.28.219.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4dAAAAP0"]
[Mon Jul 20 06:42:29.210380 2026] [security2:error] [pid 1011111:tid 1011278] [client 104.28.219.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4cQAAAKk"]
[Mon Jul 20 06:42:29.258868 2026] [security2:error] [pid 1011111:tid 1011259] [client 74.7.175.152:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thelastgamestandingexp.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n3xwAAAJY"]
[Mon Jul 20 06:42:29.261258 2026] [security2:error] [pid 1011111:tid 1011255] [client 74.7.175.152:45382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "thelastgamestandingexp.com"] [uri "/robots.txt"] [unique_id "al4XsxXES7Mv0Zfga-n3wQAAkiw"]
[Mon Jul 20 06:42:29.299994 2026] [security2:error] [pid 1011111:tid 1011331] [client 104.28.219.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4egAAAN4"]
[Mon Jul 20 06:42:29.343389 2026] [security2:error] [pid 1011111:tid 1011256] [client 57.141.18.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n3_QAAAJM"]
[Mon Jul 20 06:42:29.396689 2026] [security2:error] [pid 1011111:tid 1011236] [remote 130.51.180.8:47084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4XtRXES7Mv0Zfga-n4lAAAnns"]
[Mon Jul 20 06:42:29.402395 2026] [security2:error] [pid 1011111:tid 1011329] [client 14.225.17.146:64597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4gAAAANw"], referer: http://olearyplumbingllc.com/new
[Mon Jul 20 06:42:29.487077 2026] [security2:error] [pid 1011111:tid 1011278] [client 34.73.38.214:53355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XtRXES7Mv0Zfga-n4mgAAAKk"]
[Mon Jul 20 06:42:29.560850 2026] [security2:error] [pid 1011111:tid 1011190] [remote 130.51.180.8:47084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4XtRXES7Mv0Zfga-n4ogAApE0"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:42:29.574730 2026] [security2:error] [pid 1011111:tid 1011341] [client 136.144.35.244:57013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XtRXES7Mv0Zfga-n4owAAAOg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:29.650884 2026] [security2:error] [pid 1011111:tid 1011268] [client 57.141.18.40:24634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n4AgAAnxk"]
[Mon Jul 20 06:42:29.792535 2026] [security2:error] [pid 1011111:tid 1011322] [client 57.141.18.41:48126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XsxXES7Mv0Zfga-n4BwAA1Us"]
[Mon Jul 20 06:42:29.795000 2026] [security2:error] [pid 1011111:tid 1011250] [client 104.28.219.192:44071] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "greenvillemoving.com"] [uri "/.env.old"] [unique_id "al4XtRXES7Mv0Zfga-n4sgAAAI0"]
[Mon Jul 20 06:42:29.895231 2026] [security2:error] [pid 1011111:tid 1011123] [remote 91.142.222.105:43782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XtRXES7Mv0Zfga-n4vgAAzAo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:30.046554 2026] [security2:error] [pid 1011111:tid 1011339] [client 136.144.35.251:30581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XthXES7Mv0Zfga-n4yQAAAOY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:30.152815 2026] [security2:error] [pid 1011111:tid 1011303] [client 34.73.38.214:62403] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XthXES7Mv0Zfga-n4zQAAAMI"]
[Mon Jul 20 06:42:30.164805 2026] [security2:error] [pid 1011111:tid 1011259] [client 171.61.165.146:9105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XthXES7Mv0Zfga-n4zgAAAJY"]
[Mon Jul 20 06:42:30.164998 2026] [security2:error] [pid 1011111:tid 1011259] [client 171.61.165.146:9105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XthXES7Mv0Zfga-n4zgAAAJY"]
[Mon Jul 20 06:42:30.296071 2026] [security2:error] [pid 1011111:tid 1011300] [client 14.225.17.146:64677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4hQAAAL8"], referer: http://intelligentengineeringsolutions.com/new
[Mon Jul 20 06:42:30.307042 2026] [security2:error] [pid 1011111:tid 1011244] [client 52.109.76.144:13124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XthXES7Mv0Zfga-n43AAAAIc"]
[Mon Jul 20 06:42:30.320786 2026] [security2:error] [pid 1011111:tid 1011317] [client 13.74.155.112:18370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XthXES7Mv0Zfga-n43QAAANA"]
[Mon Jul 20 06:42:30.369441 2026] [security2:error] [pid 1011111:tid 1011296] [client 112.208.70.94:42708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XthXES7Mv0Zfga-n44gAAALs"]
[Mon Jul 20 06:42:30.369537 2026] [security2:error] [pid 1011111:tid 1011296] [client 112.208.70.94:42708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XthXES7Mv0Zfga-n44gAAALs"]
[Mon Jul 20 06:42:30.417224 2026] [security2:error] [pid 1011111:tid 1011249] [client 216.73.217.138:13763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4XthXES7Mv0Zfga-n41gAAjBI"]
[Mon Jul 20 06:42:30.448184 2026] [security2:error] [pid 1011111:tid 1011302] [client 52.109.76.144:13124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XthXES7Mv0Zfga-n46gAAAME"]
[Mon Jul 20 06:42:30.452794 2026] [security2:error] [pid 1011111:tid 1011306] [client 13.74.155.112:18370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XthXES7Mv0Zfga-n46wAAAMU"]
[Mon Jul 20 06:42:30.711498 2026] [security2:error] [pid 1011111:tid 1011132] [remote 45.90.123.233:49976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XthXES7Mv0Zfga-n4-gABAxM"]
[Mon Jul 20 06:42:30.723904 2026] [security2:error] [pid 1011111:tid 1011359] [client 136.144.35.253:45705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XthXES7Mv0Zfga-n4-QAAAPo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:30.804306 2026] [security2:error] [pid 1011111:tid 1011283] [client 57.141.18.37:23434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XtRXES7Mv0Zfga-n4cAAArm0"]
[Mon Jul 20 06:42:30.821342 2026] [core:error] [pid 1011111:tid 1011357] [client 23.180.120.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:30.821373 2026] [core:error] [pid 1011111:tid 1011357] [client 23.180.120.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:30.931156 2026] [security2:error] [pid 1011111:tid 1011259] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XthXES7Mv0Zfga-n4_wAAAJY"]
[Mon Jul 20 06:42:31.108097 2026] [security2:error] [pid 1011111:tid 1011148] [remote 45.90.123.233:49976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XtxXES7Mv0Zfga-n5FAAA9CM"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:31.145593 2026] [security2:error] [pid 1011111:tid 1011239] [remote 95.217.78.234:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XtxXES7Mv0Zfga-n5FwAAiX4"]
[Mon Jul 20 06:42:31.180257 2026] [security2:error] [pid 1011111:tid 1011270] [client 173.239.240.90:36389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XtxXES7Mv0Zfga-n5HAAAAKE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:31.332149 2026] [security2:error] [pid 1011111:tid 1011352] [client 14.225.17.146:59137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4XthXES7Mv0Zfga-n4-wAAAPM"], referer: http://talknutritionwithlesley.com/new
[Mon Jul 20 06:42:31.389787 2026] [security2:error] [pid 1011111:tid 1011164] [remote 95.217.78.234:47354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XtxXES7Mv0Zfga-n5OAAApzM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:31.394962 2026] [security2:error] [pid 1011111:tid 1011354] [client 98.85.250.161:21982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.250.85.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XtxXES7Mv0Zfga-n5NQAAAPU"]
[Mon Jul 20 06:42:31.395067 2026] [security2:error] [pid 1011111:tid 1011354] [client 98.85.250.161:21982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XtxXES7Mv0Zfga-n5NQAAAPU"]
[Mon Jul 20 06:42:31.544262 2026] [security2:error] [pid 1011111:tid 1011288] [client 34.139.11.221:61704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XtxXES7Mv0Zfga-n5QAAAALM"]
[Mon Jul 20 06:42:31.569591 2026] [security2:error] [pid 1011111:tid 1011115] [remote 160.187.68.132:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4XtxXES7Mv0Zfga-n5QQAAzQI"]
[Mon Jul 20 06:42:31.635409 2026] [security2:error] [pid 1011111:tid 1011251] [client 173.239.240.95:54587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XtxXES7Mv0Zfga-n5SgAAAI4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:31.666855 2026] [security2:error] [pid 1011111:tid 1011344] [client 122.183.32.225:17371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XtxXES7Mv0Zfga-n5TwAAAOs"]
[Mon Jul 20 06:42:31.676521 2026] [security2:error] [pid 1011111:tid 1011344] [client 122.183.32.225:17371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XtxXES7Mv0Zfga-n5TwAAAOs"]
[Mon Jul 20 06:42:31.737487 2026] [security2:error] [pid 1011111:tid 1011352] [client 34.139.11.221:58681] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XtxXES7Mv0Zfga-n5VAAAAPM"]
[Mon Jul 20 06:42:31.848282 2026] [security2:error] [pid 1011111:tid 1011281] [client 167.71.6.96:51142] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.sk-financial.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4XtxXES7Mv0Zfga-n5XgAAAKw"]
[Mon Jul 20 06:42:31.996985 2026] [security2:error] [pid 1011111:tid 1011292] [client 34.139.11.221:49359] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XtxXES7Mv0Zfga-n5cwAAALc"]
[Mon Jul 20 06:42:32.023395 2026] [security2:error] [pid 1011111:tid 1011152] [remote 160.187.68.132:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4XuBXES7Mv0Zfga-n5dwAAoic"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:42:32.056248 2026] [security2:error] [pid 1011111:tid 1011293] [client 104.234.53.54:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XuBXES7Mv0Zfga-n5egAAALg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:32.109026 2026] [security2:error] [pid 1011111:tid 1011359] [client 173.239.240.95:34517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XuBXES7Mv0Zfga-n5fAAAAPo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:32.169307 2026] [security2:error] [pid 1011111:tid 1011298] [client 34.139.11.221:56078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XuBXES7Mv0Zfga-n5gQAAAL0"]
[Mon Jul 20 06:42:32.196420 2026] [security2:error] [pid 1011111:tid 1011354] [client 187.108.85.186:62211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XuBXES7Mv0Zfga-n5hAAAAPU"]
[Mon Jul 20 06:42:32.196579 2026] [security2:error] [pid 1011111:tid 1011354] [client 187.108.85.186:62211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XuBXES7Mv0Zfga-n5hAAAAPU"]
[Mon Jul 20 06:42:32.223813 2026] [security2:error] [pid 1011111:tid 1011332] [client 57.141.18.80:58398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XthXES7Mv0Zfga-n40gAA31g"]
[Mon Jul 20 06:42:32.310057 2026] [security2:error] [pid 1011111:tid 1011339] [client 34.139.11.221:53595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XuBXES7Mv0Zfga-n5hwAAAOY"]
[Mon Jul 20 06:42:32.367324 2026] [security2:error] [pid 1011111:tid 1011322] [client 14.224.227.113:61349] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XuBXES7Mv0Zfga-n5iQAAANU"]
[Mon Jul 20 06:42:32.411920 2026] [security2:error] [pid 1011111:tid 1011283] [client 152.58.191.29:58105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XuBXES7Mv0Zfga-n5jQAAAK4"]
[Mon Jul 20 06:42:32.427662 2026] [security2:error] [pid 1011111:tid 1011283] [client 152.58.191.29:58105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XuBXES7Mv0Zfga-n5jQAAAK4"]
[Mon Jul 20 06:42:32.468382 2026] [security2:error] [pid 1011111:tid 1011310] [client 34.139.11.221:53454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XuBXES7Mv0Zfga-n5kwAAAMk"]
[Mon Jul 20 06:42:32.567963 2026] [security2:error] [pid 1011111:tid 1011259] [client 136.144.35.243:44549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XuBXES7Mv0Zfga-n5lgAAAJY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:32.866124 2026] [security2:error] [pid 1011111:tid 1011212] [remote 182.77.62.24:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XuBXES7Mv0Zfga-n5pAAAmGM"]
[Mon Jul 20 06:42:32.921715 2026] [security2:error] [pid 1011111:tid 1011336] [client 65.111.5.230:56923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.5.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XuBXES7Mv0Zfga-n5pgAAAOM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:42:33.025690 2026] [security2:error] [pid 1011111:tid 1011348] [client 57.141.18.32:30440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XtxXES7Mv0Zfga-n5EwAA7x8"]
[Mon Jul 20 06:42:33.044930 2026] [security2:error] [pid 1011111:tid 1011269] [client 173.239.240.99:50137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XuRXES7Mv0Zfga-n5tgAAAKA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:33.045055 2026] [security2:error] [pid 1011111:tid 1011158] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n5uAAAkS0"]
[Mon Jul 20 06:42:33.045181 2026] [security2:error] [pid 1011111:tid 1011254] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n5uAAAkS0"]
[Mon Jul 20 06:42:33.098411 2026] [security2:error] [pid 1011111:tid 1011284] [client 34.139.11.221:49401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XuRXES7Mv0Zfga-n5vQAAAK8"]
[Mon Jul 20 06:42:33.221644 2026] [security2:error] [pid 1011111:tid 1011293] [client 14.225.17.146:56019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4XuBXES7Mv0Zfga-n5rAAAALg"], referer: http://tntcatholic.com/new
[Mon Jul 20 06:42:33.245865 2026] [security2:error] [pid 1011111:tid 1011308] [client 34.139.11.221:55923] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XuRXES7Mv0Zfga-n5ygAAAMc"]
[Mon Jul 20 06:42:33.250510 2026] [security2:error] [pid 1011111:tid 1011362] [client 223.237.130.40:57940] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n5zAAAAP0"]
[Mon Jul 20 06:42:33.250700 2026] [security2:error] [pid 1011111:tid 1011362] [client 223.237.130.40:57940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n5zAAAAP0"]
[Mon Jul 20 06:42:33.386456 2026] [security2:error] [pid 1011111:tid 1011236] [remote 182.77.62.24:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XuRXES7Mv0Zfga-n51QAA-Xs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:33.387564 2026] [security2:error] [pid 1011111:tid 1011328] [client 34.139.11.221:53089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XuRXES7Mv0Zfga-n51wAAANs"]
[Mon Jul 20 06:42:33.497852 2026] [security2:error] [pid 1011111:tid 1011296] [client 103.238.106.162:60620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n55QAAALs"]
[Mon Jul 20 06:42:33.497959 2026] [security2:error] [pid 1011111:tid 1011296] [client 103.238.106.162:60620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n55QAAALs"]
[Mon Jul 20 06:42:33.516381 2026] [security2:error] [pid 1011111:tid 1011249] [client 136.144.35.249:61599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XuRXES7Mv0Zfga-n55gAAAIw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:33.520582 2026] [security2:error] [pid 1011111:tid 1011190] [remote 45.90.123.233:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XuRXES7Mv0Zfga-n55wAAwU0"]
[Mon Jul 20 06:42:33.554171 2026] [security2:error] [pid 1011111:tid 1011274] [client 34.139.11.221:64133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XuRXES7Mv0Zfga-n57gAAAKU"]
[Mon Jul 20 06:42:33.716233 2026] [security2:error] [pid 1011111:tid 1011368] [client 34.139.11.221:55361] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XuRXES7Mv0Zfga-n5-AAAAQM"]
[Mon Jul 20 06:42:33.761577 2026] [security2:error] [pid 1011111:tid 1011268] [client 65.111.0.87:28589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.0.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XuRXES7Mv0Zfga-n59wAAAJ8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:42:33.773643 2026] [security2:error] [pid 1011111:tid 1011117] [remote 45.90.123.233:55618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4XuRXES7Mv0Zfga-n5_AAAygQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:33.784110 2026] [security2:error] [pid 1011111:tid 1011359] [client 217.142.18.172:60228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n5_QAAAPo"]
[Mon Jul 20 06:42:33.788666 2026] [security2:error] [pid 1011111:tid 1011359] [client 217.142.18.172:60228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XuRXES7Mv0Zfga-n5_QAAAPo"]
[Mon Jul 20 06:42:33.859966 2026] [security2:error] [pid 1011111:tid 1011188] [remote 47.86.33.52:32322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4XuRXES7Mv0Zfga-n6AQAAkEs"]
[Mon Jul 20 06:42:33.905571 2026] [security2:error] [pid 1011111:tid 1011336] [client 34.139.11.221:55362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XuRXES7Mv0Zfga-n6CwAAAOM"]
[Mon Jul 20 06:42:33.966781 2026] [security2:error] [pid 1011111:tid 1011338] [client 173.239.240.102:55325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XuRXES7Mv0Zfga-n6EgAAAOU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:34.064470 2026] [security2:error] [pid 1011111:tid 1011365] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4XuRXES7Mv0Zfga-n57AABAFA"], referer: http://ardhalwafaa.com/new
[Mon Jul 20 06:42:34.140939 2026] [security2:error] [pid 1011111:tid 1011314] [client 34.139.11.221:64585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.eql.eda.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XuhXES7Mv0Zfga-n6HQAAAM0"]
[Mon Jul 20 06:42:34.145516 2026] [security2:error] [pid 1011111:tid 1011357] [client 45.3.45.123:55637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XuhXES7Mv0Zfga-n6HAAAAPg"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:34.357369 2026] [security2:error] [pid 1011111:tid 1011125] [remote 20.153.140.50:51332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XuhXES7Mv0Zfga-n6JgAAhgw"]
[Mon Jul 20 06:42:34.357529 2026] [security2:error] [pid 1011111:tid 1011243] [client 20.153.140.50:51332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XuhXES7Mv0Zfga-n6JgAAhgw"]
[Mon Jul 20 06:42:34.419881 2026] [security2:error] [pid 1011111:tid 1011327] [client 136.144.35.244:54741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XuhXES7Mv0Zfga-n6LwAAANo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:34.439020 2026] [security2:error] [pid 1011111:tid 1011278] [client 104.234.53.85:34953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4XuhXES7Mv0Zfga-n6KAAAAKk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:34.791289 2026] [security2:error] [pid 1011111:tid 1011336] [client 45.3.52.132:21191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XuhXES7Mv0Zfga-n6QgAAAOM"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:34.893017 2026] [security2:error] [pid 1011111:tid 1011355] [client 136.144.35.253:28093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XuhXES7Mv0Zfga-n6UgAAAPY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:34.979677 2026] [security2:error] [pid 1011111:tid 1011262] [client 57.141.18.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XuhXES7Mv0Zfga-n6SwAAAJk"]
[Mon Jul 20 06:42:35.123844 2026] [security2:error] [pid 1011111:tid 1011273] [client 114.119.133.213:62739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "archivetest.earle-brown.org"] [uri "/robots.txt"] [unique_id "al4XuxXES7Mv0Zfga-n6aQAAAKQ"], referer: https://archivetest.earle-brown.org/robots.txt
[Mon Jul 20 06:42:35.208638 2026] [security2:error] [pid 1011111:tid 1011283] [client 57.141.18.62:52718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XuRXES7Mv0Zfga-n5xAAArjE"]
[Mon Jul 20 06:42:35.329562 2026] [security2:error] [pid 1011111:tid 1011297] [client 104.234.53.85:34953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XuxXES7Mv0Zfga-n6bwAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:35.333644 2026] [security2:error] [pid 1011111:tid 1011149] [remote 47.86.33.52:32322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4XuxXES7Mv0Zfga-n6cwAA5CQ"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:42:35.344438 2026] [security2:error] [pid 1011111:tid 1011354] [client 136.144.35.243:29587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XuxXES7Mv0Zfga-n6dwAAAPU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:35.394241 2026] [security2:error] [pid 1011111:tid 1011323] [client 104.207.60.167:32359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XuxXES7Mv0Zfga-n6ewAAANY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:35.423698 2026] [security2:error] [pid 1011111:tid 1011247] [client 51.143.183.75:28160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XuxXES7Mv0Zfga-n6gAAAAIo"]
[Mon Jul 20 06:42:35.477527 2026] [security2:error] [pid 1011111:tid 1011281] [client 144.172.114.51:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.thescarystory.com"] [uri "/wp-config.php.old"] [unique_id "al4XuxXES7Mv0Zfga-n6iAAAAKw"]
[Mon Jul 20 06:42:35.557414 2026] [security2:error] [pid 1011111:tid 1011340] [client 51.143.183.75:28160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XuxXES7Mv0Zfga-n6jgAAAOc"]
[Mon Jul 20 06:42:35.566057 2026] [security2:error] [pid 1011111:tid 1011368] [client 52.109.89.119:4610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XuxXES7Mv0Zfga-n6jQAAAQM"]
[Mon Jul 20 06:42:35.713377 2026] [security2:error] [pid 1011111:tid 1011341] [client 52.109.89.119:4610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XuxXES7Mv0Zfga-n6kwAAAOg"]
[Mon Jul 20 06:42:35.762431 2026] [security2:error] [pid 1011111:tid 1011364] [client 223.185.13.213:10988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XuxXES7Mv0Zfga-n6mQAAAP8"]
[Mon Jul 20 06:42:35.762571 2026] [security2:error] [pid 1011111:tid 1011364] [client 223.185.13.213:10988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XuxXES7Mv0Zfga-n6mQAAAP8"]
[Mon Jul 20 06:42:35.792344 2026] [security2:error] [pid 1011111:tid 1011362] [client 136.144.35.250:51309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XuxXES7Mv0Zfga-n6nQAAAP0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:35.793011 2026] [security2:error] [pid 1011111:tid 1011336] [client 197.186.66.42:56196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XuxXES7Mv0Zfga-n6ngAAAOM"]
[Mon Jul 20 06:42:35.797203 2026] [security2:error] [pid 1011111:tid 1011336] [client 197.186.66.42:56196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XuxXES7Mv0Zfga-n6ngAAAOM"]
[Mon Jul 20 06:42:35.910730 2026] [security2:error] [pid 1011111:tid 1011263] [client 57.141.18.56:22322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XuRXES7Mv0Zfga-n6CQAAmgo"]
[Mon Jul 20 06:42:36.003907 2026] [security2:error] [pid 1011111:tid 1011248] [client 45.3.41.219:23711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XuxXES7Mv0Zfga-n6rQAAAIs"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:36.088980 2026] [security2:error] [pid 1011111:tid 1011196] [remote 217.61.143.92:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XvBXES7Mv0Zfga-n6tAAAwFM"]
[Mon Jul 20 06:42:36.242132 2026] [security2:error] [pid 1011111:tid 1011278] [client 173.239.240.31:34715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XvBXES7Mv0Zfga-n6wQAAAKk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:36.329015 2026] [security2:error] [pid 1011111:tid 1011267] [client 57.141.18.105:64186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XuhXES7Mv0Zfga-n6HwAAnlw"]
[Mon Jul 20 06:42:36.335960 2026] [security2:error] [pid 1011111:tid 1011177] [remote 217.61.143.92:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XvBXES7Mv0Zfga-n6ywAAl0A"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:36.360258 2026] [security2:error] [pid 1011111:tid 1011326] [client 37.52.210.45:64607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XvBXES7Mv0Zfga-n6zgAAANk"]
[Mon Jul 20 06:42:36.360370 2026] [security2:error] [pid 1011111:tid 1011326] [client 37.52.210.45:64607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XvBXES7Mv0Zfga-n6zgAAANk"]
[Mon Jul 20 06:42:36.365402 2026] [security2:error] [pid 1011111:tid 1011306] [client 57.141.18.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4XuxXES7Mv0Zfga-n6mgAAAMU"]
[Mon Jul 20 06:42:36.630704 2026] [security2:error] [pid 1011111:tid 1011300] [client 14.225.17.146:52721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4XvBXES7Mv0Zfga-n6sQAAAL8"], referer: http://oldracelimited.com/new
[Mon Jul 20 06:42:36.631725 2026] [security2:error] [pid 1011111:tid 1011310] [client 65.111.27.90:52689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XvBXES7Mv0Zfga-n67AAAAMk"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:36.707544 2026] [security2:error] [pid 1011111:tid 1011303] [client 173.239.240.94:52471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XvBXES7Mv0Zfga-n6-AAAAMI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:36.968189 2026] [security2:error] [pid 1011111:tid 1011338] [client 14.225.17.146:60838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4XuxXES7Mv0Zfga-n6iwAAAOU"], referer: http://inspirespublishing.com/new
[Mon Jul 20 06:42:37.156450 2026] [security2:error] [pid 1011111:tid 1011307] [client 136.144.35.249:54519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XvRXES7Mv0Zfga-n7FQAAAMY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:37.295071 2026] [security2:error] [pid 1011111:tid 1011318] [client 98.159.234.160:54631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XvRXES7Mv0Zfga-n7IQAAANE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:42:37.345955 2026] [security2:error] [pid 1011111:tid 1011324] [client 103.125.179.95:62310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XvRXES7Mv0Zfga-n7IwAAANc"]
[Mon Jul 20 06:42:37.346134 2026] [security2:error] [pid 1011111:tid 1011324] [client 103.125.179.95:62310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XvRXES7Mv0Zfga-n7IwAAANc"]
[Mon Jul 20 06:42:37.541133 2026] [security2:error] [pid 1011111:tid 1011217] [remote 152.228.213.32:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.think-islam.com"] [uri "/wp-login.php"] [unique_id "al4XvRXES7Mv0Zfga-n7NAAA2Gg"]
[Mon Jul 20 06:42:37.622154 2026] [security2:error] [pid 1011111:tid 1011334] [client 173.239.240.101:35153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XvRXES7Mv0Zfga-n7OwAAAOE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:37.761578 2026] [security2:error] [pid 1011111:tid 1011307] [client 77.110.127.138:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvRXES7Mv0Zfga-n7QwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:37.761669 2026] [security2:error] [pid 1011111:tid 1011307] [client 77.110.127.138:53098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvRXES7Mv0Zfga-n7QwAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:37.768369 2026] [security2:error] [pid 1011111:tid 1011303] [client 50.116.65.227:38772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4XvRXES7Mv0Zfga-n7GgAAAMI"]
[Mon Jul 20 06:42:37.893483 2026] [security2:error] [pid 1011111:tid 1011227] [remote 152.228.213.32:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.think-islam.com"] [uri "/wp-login.php"] [unique_id "al4XvRXES7Mv0Zfga-n7TwABAHI"], referer: https://mail.think-islam.com/wp-login.php
[Mon Jul 20 06:42:37.907981 2026] [security2:error] [pid 1011111:tid 1011281] [client 104.234.53.69:42211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XvRXES7Mv0Zfga-n7TgAAAKw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:37.913315 2026] [security2:error] [pid 1011111:tid 1011290] [client 45.157.112.60:23321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XvRXES7Mv0Zfga-n7UAAAALU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:42:38.075661 2026] [security2:error] [pid 1011111:tid 1011364] [client 173.239.240.91:26539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XvhXES7Mv0Zfga-n7YQAAAP8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:38.127090 2026] [security2:error] [pid 1011111:tid 1011313] [client 57.141.18.103:33114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XvBXES7Mv0Zfga-n65AAAzGQ"]
[Mon Jul 20 06:42:38.181247 2026] [security2:error] [pid 1011111:tid 1011304] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XvRXES7Mv0Zfga-n7VgAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:38.235499 2026] [security2:error] [pid 1011111:tid 1011362] [client 77.110.127.138:53106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvhXES7Mv0Zfga-n7bAAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:38.235576 2026] [security2:error] [pid 1011111:tid 1011362] [client 77.110.127.138:53106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvhXES7Mv0Zfga-n7bAAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:38.329541 2026] [security2:error] [pid 1011111:tid 1011121] [remote 216.73.216.55:21368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/contact-us/"] [unique_id "al4XvhXES7Mv0Zfga-n7dQAA7wg"]
[Mon Jul 20 06:42:38.368587 2026] [security2:error] [pid 1011111:tid 1011332] [client 50.116.65.227:38776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4XvRXES7Mv0Zfga-n7RwAAAN8"]
[Mon Jul 20 06:42:38.467109 2026] [security2:error] [pid 1011111:tid 1011343] [client 51.15.143.46:44640] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5028.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4XvhXES7Mv0Zfga-n7gQAAAOo"]
[Mon Jul 20 06:42:38.544988 2026] [security2:error] [pid 1011111:tid 1011308] [client 173.239.240.32:48287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XvhXES7Mv0Zfga-n7gwAAAMc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:38.704361 2026] [autoindex:error] [pid 1011111:tid 1011265] [client 14.225.17.146:60777] AH01276: Cannot serve directory /home3/scottass/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://scott-assist.com/new
[Mon Jul 20 06:42:38.932737 2026] [security2:error] [pid 1011111:tid 1011332] [client 77.110.127.138:53113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvhXES7Mv0Zfga-n7rAAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:38.932874 2026] [security2:error] [pid 1011111:tid 1011332] [client 77.110.127.138:53113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvhXES7Mv0Zfga-n7rAAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:38.974552 2026] [security2:error] [pid 1011111:tid 1011277] [client 14.225.17.146:60837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4XvRXES7Mv0Zfga-n7HwAAAKg"], referer: http://bigwormfishing.com/new
[Mon Jul 20 06:42:39.020617 2026] [security2:error] [pid 1011111:tid 1011340] [client 57.141.18.67:62796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XvRXES7Mv0Zfga-n7LAAA53s"]
[Mon Jul 20 06:42:39.030850 2026] [security2:error] [pid 1011111:tid 1011306] [client 173.239.240.97:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XvxXES7Mv0Zfga-n7rwAAAMU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:39.156608 2026] [security2:error] [pid 1011111:tid 1011360] [client 46.110.96.34:64358] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XvxXES7Mv0Zfga-n7ugAAAPs"]
[Mon Jul 20 06:42:39.156610 2026] [security2:error] [pid 1011111:tid 1011313] [client 46.110.96.34:60747] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XvxXES7Mv0Zfga-n7uQAAAMw"]
[Mon Jul 20 06:42:39.199569 2026] [security2:error] [pid 1011111:tid 1011244] [client 46.110.96.34:51738] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XvxXES7Mv0Zfga-n7wQAAAIc"]
[Mon Jul 20 06:42:39.409073 2026] [security2:error] [pid 1011111:tid 1011338] [client 106.219.188.178:25945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XvxXES7Mv0Zfga-n70QAAAOU"]
[Mon Jul 20 06:42:39.410602 2026] [security2:error] [pid 1011111:tid 1011338] [client 106.219.188.178:25945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XvxXES7Mv0Zfga-n70QAAAOU"]
[Mon Jul 20 06:42:39.445132 2026] [security2:error] [pid 1011111:tid 1011300] [client 183.82.98.154:52338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XvxXES7Mv0Zfga-n71wAAAL8"]
[Mon Jul 20 06:42:39.445225 2026] [security2:error] [pid 1011111:tid 1011300] [client 183.82.98.154:52338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XvxXES7Mv0Zfga-n71wAAAL8"]
[Mon Jul 20 06:42:39.481680 2026] [security2:error] [pid 1011111:tid 1011323] [client 173.239.240.100:64879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XvxXES7Mv0Zfga-n72wAAANY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:39.612594 2026] [security2:error] [pid 1011111:tid 1011349] [client 14.224.227.113:54644] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XvxXES7Mv0Zfga-n75QAAAPA"]
[Mon Jul 20 06:42:39.728007 2026] [security2:error] [pid 1011111:tid 1011264] [client 77.110.127.138:53125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvxXES7Mv0Zfga-n77gAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:39.728118 2026] [security2:error] [pid 1011111:tid 1011264] [client 77.110.127.138:53125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XvxXES7Mv0Zfga-n77gAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:39.943422 2026] [security2:error] [pid 1011111:tid 1011274] [client 169.159.128.176:37816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kingsafety.ca"] [uri "/index.php"] [unique_id "al4XvxXES7Mv0Zfga-n7twAAAKU"]
[Mon Jul 20 06:42:39.956000 2026] [security2:error] [pid 1011111:tid 1011347] [client 136.144.35.247:20209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XvxXES7Mv0Zfga-n8BAAAAO4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:39.986671 2026] [proxy:error] [pid 1011111:tid 1011323] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:39.986737 2026] [proxy_http:error] [pid 1011111:tid 1011323] [client 134.199.229.178:42070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:39.987296 2026] [proxy:error] [pid 1011111:tid 1011323] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:39.987323 2026] [proxy_http:error] [pid 1011111:tid 1011323] [client 134.199.229.178:42070] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:40.075153 2026] [proxy:error] [pid 1011111:tid 1011343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:40.075233 2026] [proxy_http:error] [pid 1011111:tid 1011343] [client 134.199.229.178:42076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.viennarotaryfoundation.com/
[Mon Jul 20 06:42:40.075907 2026] [proxy:error] [pid 1011111:tid 1011343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:40.075975 2026] [proxy_http:error] [pid 1011111:tid 1011343] [client 134.199.229.178:42076] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.viennarotaryfoundation.com/
[Mon Jul 20 06:42:40.108689 2026] [security2:error] [pid 1011111:tid 1011306] [client 74.208.214.194:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XwBXES7Mv0Zfga-n8EwAAAMU"]
[Mon Jul 20 06:42:40.171633 2026] [proxy:error] [pid 1011111:tid 1011290] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:40.171668 2026] [proxy_http:error] [pid 1011111:tid 1011290] [client 134.199.229.178:43756] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:40.172261 2026] [proxy:error] [pid 1011111:tid 1011290] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:40.172304 2026] [proxy_http:error] [pid 1011111:tid 1011290] [client 134.199.229.178:43756] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:40.185817 2026] [security2:error] [pid 1011111:tid 1011269] [client 39.48.81.23:64069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XwBXES7Mv0Zfga-n8GwAAAKA"]
[Mon Jul 20 06:42:40.186702 2026] [security2:error] [pid 1011111:tid 1011269] [client 39.48.81.23:64069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XwBXES7Mv0Zfga-n8GwAAAKA"]
[Mon Jul 20 06:42:40.347996 2026] [security2:error] [pid 1011111:tid 1011275] [client 122.183.32.225:22537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XwBXES7Mv0Zfga-n8LwAAAKY"]
[Mon Jul 20 06:42:40.348161 2026] [security2:error] [pid 1011111:tid 1011275] [client 122.183.32.225:22537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XwBXES7Mv0Zfga-n8LwAAAKY"]
[Mon Jul 20 06:42:40.418836 2026] [security2:error] [pid 1011111:tid 1011297] [client 136.144.35.247:36801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XwBXES7Mv0Zfga-n8NwAAALw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:40.459502 2026] [security2:error] [pid 1011111:tid 1011272] [client 14.225.17.146:64303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4XwBXES7Mv0Zfga-n8HwAAAKM"], referer: http://ccsdifference.com/new
[Mon Jul 20 06:42:40.525912 2026] [security2:error] [pid 1011111:tid 1011353] [client 57.141.18.101:58606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XvhXES7Mv0Zfga-n7nwAA9BA"]
[Mon Jul 20 06:42:40.800440 2026] [security2:error] [pid 1011111:tid 1011142] [remote 110.249.202.40:38936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/the-narrow-way-not-barabara-pana/"] [unique_id "al4XwBXES7Mv0Zfga-n8TQAAwx0"]
[Mon Jul 20 06:42:40.888449 2026] [security2:error] [pid 1011111:tid 1011245] [client 112.208.70.94:43143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XwBXES7Mv0Zfga-n8VwAAAIg"]
[Mon Jul 20 06:42:40.888563 2026] [security2:error] [pid 1011111:tid 1011245] [client 112.208.70.94:43143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XwBXES7Mv0Zfga-n8VwAAAIg"]
[Mon Jul 20 06:42:40.905997 2026] [security2:error] [pid 1011111:tid 1011275] [client 173.239.240.101:34061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XwBXES7Mv0Zfga-n8WAAAAKY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:41.082204 2026] [security2:error] [pid 1011111:tid 1011242] [client 171.61.165.146:16291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XwRXES7Mv0Zfga-n8ZQAAAIU"]
[Mon Jul 20 06:42:41.082335 2026] [security2:error] [pid 1011111:tid 1011242] [client 171.61.165.146:16291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XwRXES7Mv0Zfga-n8ZQAAAIU"]
[Mon Jul 20 06:42:41.124908 2026] [proxy:error] [pid 1011111:tid 1011347] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:41.124983 2026] [proxy_http:error] [pid 1011111:tid 1011347] [client 134.199.229.178:43882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.viennarotaryfoundation.com/
[Mon Jul 20 06:42:41.125446 2026] [proxy:error] [pid 1011111:tid 1011347] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:41.125477 2026] [proxy_http:error] [pid 1011111:tid 1011347] [client 134.199.229.178:43882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcontacts.viennarotaryfoundation.com/
[Mon Jul 20 06:42:41.160172 2026] [security2:error] [pid 1011111:tid 1011291] [client 104.234.53.77:33865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4XwRXES7Mv0Zfga-n8agAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:41.354912 2026] [security2:error] [pid 1011111:tid 1011279] [client 173.239.240.96:58983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XwRXES7Mv0Zfga-n8gAAAAKo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:41.385625 2026] [security2:error] [pid 1011111:tid 1011332] [client 57.141.18.25:37808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XvxXES7Mv0Zfga-n74AAA3zE"]
[Mon Jul 20 06:42:41.805466 2026] [security2:error] [pid 1011111:tid 1011365] [client 57.141.18.87:63130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XwBXES7Mv0Zfga-n8BwABAAE"]
[Mon Jul 20 06:42:41.840240 2026] [security2:error] [pid 1011111:tid 1011242] [client 173.239.240.90:31865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XwRXES7Mv0Zfga-n8nwAAAIU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:42.297696 2026] [security2:error] [pid 1011111:tid 1011320] [client 173.239.240.101:31013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XwhXES7Mv0Zfga-n8vgAAANM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:42.371591 2026] [security2:error] [pid 1011111:tid 1011231] [remote 173.212.252.15:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XwhXES7Mv0Zfga-n8ygAAuHY"]
[Mon Jul 20 06:42:42.565448 2026] [proxy:error] [pid 1011111:tid 1011268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:42.565520 2026] [proxy_http:error] [pid 1011111:tid 1011268] [client 34.73.38.214:62208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:42.566112 2026] [proxy:error] [pid 1011111:tid 1011268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:42.566138 2026] [proxy_http:error] [pid 1011111:tid 1011268] [client 34.73.38.214:62208] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:42.593343 2026] [security2:error] [pid 1011111:tid 1011228] [remote 173.212.252.15:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4XwhXES7Mv0Zfga-n81QABAnM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:42:42.656937 2026] [security2:error] [pid 1011111:tid 1011363] [client 187.108.85.186:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XwhXES7Mv0Zfga-n82gAAAP4"]
[Mon Jul 20 06:42:42.657015 2026] [security2:error] [pid 1011111:tid 1011363] [client 187.108.85.186:62757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XwhXES7Mv0Zfga-n82gAAAP4"]
[Mon Jul 20 06:42:42.689558 2026] [security2:error] [pid 1011111:tid 1011317] [client 52.187.75.220:2817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XwhXES7Mv0Zfga-n82wAAANA"]
[Mon Jul 20 06:42:42.788222 2026] [security2:error] [pid 1011111:tid 1011254] [client 136.144.35.254:49807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XwhXES7Mv0Zfga-n84wAAAJE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:42.830981 2026] [security2:error] [pid 1011111:tid 1011353] [client 57.141.18.38:54934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XwRXES7Mv0Zfga-n8ZgAA9Ek"]
[Mon Jul 20 06:42:42.870639 2026] [security2:error] [pid 1011111:tid 1011339] [client 52.187.75.220:2817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XwhXES7Mv0Zfga-n85wAAAOY"]
[Mon Jul 20 06:42:42.892810 2026] [security2:error] [pid 1011111:tid 1011287] [client 14.225.17.146:64288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4XwRXES7Mv0Zfga-n8aQAAALI"], referer: http://windowtx.com/new
[Mon Jul 20 06:42:42.908200 2026] [security2:error] [pid 1011111:tid 1011193] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XwhXES7Mv0Zfga-n88QAAvFA"]
[Mon Jul 20 06:42:42.908345 2026] [security2:error] [pid 1011111:tid 1011297] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XwhXES7Mv0Zfga-n88QAAvFA"]
[Mon Jul 20 06:42:43.127150 2026] [security2:error] [pid 1011111:tid 1011310] [client 152.58.191.29:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XwxXES7Mv0Zfga-n9AAAAAMk"]
[Mon Jul 20 06:42:43.128073 2026] [security2:error] [pid 1011111:tid 1011310] [client 152.58.191.29:58580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XwxXES7Mv0Zfga-n9AAAAAMk"]
[Mon Jul 20 06:42:43.132739 2026] [security2:error] [pid 1011111:tid 1011306] [client 77.110.127.138:53135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XwxXES7Mv0Zfga-n9AwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:43.132868 2026] [security2:error] [pid 1011111:tid 1011306] [client 77.110.127.138:53135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XwxXES7Mv0Zfga-n9AwAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:43.269104 2026] [security2:error] [pid 1011111:tid 1011345] [client 136.144.35.253:28667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XwxXES7Mv0Zfga-n9DAAAAOw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:43.342589 2026] [security2:error] [pid 1011111:tid 1011313] [client 77.110.127.138:53138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XwxXES7Mv0Zfga-n9EgAAAMw"]
[Mon Jul 20 06:42:43.342700 2026] [security2:error] [pid 1011111:tid 1011313] [client 77.110.127.138:53138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XwxXES7Mv0Zfga-n9EgAAAMw"]
[Mon Jul 20 06:42:43.467479 2026] [proxy:error] [pid 1011111:tid 1011278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:43.467537 2026] [proxy_http:error] [pid 1011111:tid 1011278] [client 34.73.38.214:54680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:43.468148 2026] [proxy:error] [pid 1011111:tid 1011278] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:43.468174 2026] [proxy_http:error] [pid 1011111:tid 1011278] [client 34.73.38.214:54680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:43.517886 2026] [security2:error] [pid 1011111:tid 1011272] [client 57.141.18.89:59226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XwRXES7Mv0Zfga-n8oQAAo2w"]
[Mon Jul 20 06:42:43.724649 2026] [security2:error] [pid 1011111:tid 1011337] [client 173.239.240.100:40761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XwxXES7Mv0Zfga-n9NgAAAOQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:43.797063 2026] [security2:error] [pid 1011111:tid 1011357] [client 104.234.53.94:24623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4XwxXES7Mv0Zfga-n9OwAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:43.871587 2026] [security2:error] [pid 1011111:tid 1011345] [client 14.225.17.146:53781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4XwxXES7Mv0Zfga-n9PgAAAOw"]
[Mon Jul 20 06:42:43.967498 2026] [security2:error] [pid 1011111:tid 1011320] [client 103.238.106.162:60967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XwxXES7Mv0Zfga-n9SgAAANM"]
[Mon Jul 20 06:42:43.968194 2026] [security2:error] [pid 1011111:tid 1011320] [client 103.238.106.162:60967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XwxXES7Mv0Zfga-n9SgAAANM"]
[Mon Jul 20 06:42:44.049516 2026] [security2:error] [pid 1011111:tid 1011279] [client 65.111.6.58:58361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XxBXES7Mv0Zfga-n9UQAAAKo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:42:44.054778 2026] [security2:error] [pid 1011111:tid 1011272] [client 74.208.214.194:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4XxBXES7Mv0Zfga-n9VQAAAKM"]
[Mon Jul 20 06:42:44.192583 2026] [security2:error] [pid 1011111:tid 1011258] [client 173.239.240.92:61899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XxBXES7Mv0Zfga-n9ZQAAAJU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:44.255800 2026] [security2:error] [pid 1011111:tid 1011294] [client 57.141.18.27:20200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XwhXES7Mv0Zfga-n80QAAuV8"]
[Mon Jul 20 06:42:44.319569 2026] [security2:error] [pid 1011111:tid 1011325] [client 217.142.18.172:36029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XxBXES7Mv0Zfga-n9awAAANg"]
[Mon Jul 20 06:42:44.319733 2026] [security2:error] [pid 1011111:tid 1011325] [client 217.142.18.172:36029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XxBXES7Mv0Zfga-n9awAAANg"]
[Mon Jul 20 06:42:44.416701 2026] [security2:error] [pid 1011111:tid 1011288] [client 14.225.17.146:60779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4XxBXES7Mv0Zfga-n9cAAAALM"], referer: http://travelbyfire.com/new
[Mon Jul 20 06:42:44.662076 2026] [security2:error] [pid 1011111:tid 1011290] [client 173.239.240.31:23015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XxBXES7Mv0Zfga-n9gQAAALU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:44.740436 2026] [security2:error] [pid 1011111:tid 1011313] [client 104.234.53.59:36395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4XxBXES7Mv0Zfga-n9ggAAAMw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:44.747545 2026] [security2:error] [pid 1011111:tid 1011287] [client 77.110.127.138:53145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XxBXES7Mv0Zfga-n9hQAAALI"]
[Mon Jul 20 06:42:44.747658 2026] [security2:error] [pid 1011111:tid 1011287] [client 77.110.127.138:53145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XxBXES7Mv0Zfga-n9hQAAALI"]
[Mon Jul 20 06:42:44.787873 2026] [proxy:error] [pid 1011111:tid 1011245] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:44.787946 2026] [proxy_http:error] [pid 1011111:tid 1011245] [client 34.73.38.214:53495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:44.788767 2026] [proxy:error] [pid 1011111:tid 1011245] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:42:44.788797 2026] [proxy_http:error] [pid 1011111:tid 1011245] [client 34.73.38.214:53495] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:42:44.847766 2026] [security2:error] [pid 1011111:tid 1011345] [client 14.225.17.146:49732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4XxBXES7Mv0Zfga-n9gwAAAOw"], referer: http://carolinapressurewashers.com/new
[Mon Jul 20 06:42:44.851996 2026] [security2:error] [pid 1011111:tid 1011302] [client 223.237.130.40:58355] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XxBXES7Mv0Zfga-n9kgAAAME"]
[Mon Jul 20 06:42:44.861591 2026] [security2:error] [pid 1011111:tid 1011302] [client 223.237.130.40:58355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4XxBXES7Mv0Zfga-n9kgAAAME"]
[Mon Jul 20 06:42:45.028656 2026] [security2:error] [pid 1011111:tid 1011355] [client 52.109.108.111:22112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XxRXES7Mv0Zfga-n9ogAAAPY"]
[Mon Jul 20 06:42:45.055064 2026] [security2:error] [pid 1011111:tid 1011342] [client 140.245.46.64:62260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-login.php"] [unique_id "al4XxRXES7Mv0Zfga-n9pAAAAOk"]
[Mon Jul 20 06:42:45.131556 2026] [security2:error] [pid 1011111:tid 1011357] [client 173.239.240.94:62043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XxRXES7Mv0Zfga-n9rAAAAPg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:45.142337 2026] [security2:error] [pid 1011111:tid 1011358] [client 57.141.18.10:64796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XwxXES7Mv0Zfga-n9MAAA-Rg"]
[Mon Jul 20 06:42:45.188435 2026] [security2:error] [pid 1011111:tid 1011247] [client 52.109.108.111:22112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XxRXES7Mv0Zfga-n9sgAAAIo"]
[Mon Jul 20 06:42:45.304352 2026] [security2:error] [pid 1011111:tid 1011341] [client 14.225.17.146:53844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4XxRXES7Mv0Zfga-n9uAAAAOg"], referer: https://travelbyfire.com/new
[Mon Jul 20 06:42:45.335827 2026] [security2:error] [pid 1011111:tid 1011277] [client 14.225.17.146:60649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4XxBXES7Mv0Zfga-n9UAAAAKg"], referer: http://iagdevelopments.com/new
[Mon Jul 20 06:42:45.427827 2026] [security2:error] [pid 1011111:tid 1011300] [client 14.225.17.146:53163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4XxRXES7Mv0Zfga-n9tgAAAL8"]
[Mon Jul 20 06:42:45.580772 2026] [security2:error] [pid 1011111:tid 1011295] [client 173.239.240.96:60843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XxRXES7Mv0Zfga-n92wAAALo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:45.581408 2026] [security2:error] [pid 1011111:tid 1011253] [client 14.225.17.146:53833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4XxRXES7Mv0Zfga-n9wgAAAJA"], referer: http://bbwipartnerconference.com/new
[Mon Jul 20 06:42:45.613457 2026] [security2:error] [pid 1011111:tid 1011267] [client 57.141.18.15:55800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XxBXES7Mv0Zfga-n9WgAAniY"]
[Mon Jul 20 06:42:45.659364 2026] [security2:error] [pid 1011111:tid 1011299] [client 57.141.18.50:51744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XxBXES7Mv0Zfga-n9YwAAvis"]
[Mon Jul 20 06:42:46.027449 2026] [security2:error] [pid 1011111:tid 1011264] [client 173.239.240.97:29771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XxhXES7Mv0Zfga-n9_wAAAJs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:46.157601 2026] [security2:error] [pid 1011111:tid 1011322] [client 104.234.53.59:36395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4XxhXES7Mv0Zfga-n-CgAAANU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:46.211250 2026] [security2:error] [pid 1011111:tid 1011157] [remote 72.167.132.114:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4XxhXES7Mv0Zfga-n-DgAA9Cw"]
[Mon Jul 20 06:42:46.484009 2026] [security2:error] [pid 1011111:tid 1011282] [client 104.207.49.87:50253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XxhXES7Mv0Zfga-n-JQAAAK0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:46.489704 2026] [security2:error] [pid 1011111:tid 1011288] [client 173.239.240.102:38497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XxhXES7Mv0Zfga-n-KAAAALM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:46.511375 2026] [security2:error] [pid 1011111:tid 1011188] [remote 72.167.132.114:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4XxhXES7Mv0Zfga-n-KQAA-ks"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:42:46.679600 2026] [security2:error] [pid 1011111:tid 1011276] [client 223.185.13.213:16424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XxhXES7Mv0Zfga-n-NgAAAKc"]
[Mon Jul 20 06:42:46.679732 2026] [security2:error] [pid 1011111:tid 1011276] [client 223.185.13.213:16424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4XxhXES7Mv0Zfga-n-NgAAAKc"]
[Mon Jul 20 06:42:46.856212 2026] [security2:error] [pid 1011111:tid 1011291] [client 140.245.46.64:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4XxhXES7Mv0Zfga-n-PwAAALY"]
[Mon Jul 20 06:42:46.917192 2026] [security2:error] [pid 1011111:tid 1011298] [client 34.73.38.214:64399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4XxhXES7Mv0Zfga-n-SQAAAL0"]
[Mon Jul 20 06:42:46.955663 2026] [security2:error] [pid 1011111:tid 1011336] [client 136.144.35.250:58317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XxhXES7Mv0Zfga-n-TwAAAOM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:46.961738 2026] [security2:error] [pid 1011111:tid 1011356] [client 37.52.210.45:2007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XxhXES7Mv0Zfga-n-UAAAAPc"]
[Mon Jul 20 06:42:46.961980 2026] [security2:error] [pid 1011111:tid 1011356] [client 37.52.210.45:2007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XxhXES7Mv0Zfga-n-UAAAAPc"]
[Mon Jul 20 06:42:47.084221 2026] [security2:error] [pid 1011111:tid 1011267] [client 195.63.31.160:28891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XxxXES7Mv0Zfga-n-VQAAAJ4"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:47.294344 2026] [security2:error] [pid 1011111:tid 1011131] [remote 68.178.160.25:33122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XxxXES7Mv0Zfga-n-YwAAhxI"]
[Mon Jul 20 06:42:47.310106 2026] [security2:error] [pid 1011111:tid 1011250] [client 46.110.96.34:7079] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XxxXES7Mv0Zfga-n-aAAAAI0"]
[Mon Jul 20 06:42:47.310106 2026] [security2:error] [pid 1011111:tid 1011279] [client 46.110.96.34:29534] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XxxXES7Mv0Zfga-n-ZwAAAKo"]
[Mon Jul 20 06:42:47.337272 2026] [security2:error] [pid 1011111:tid 1011339] [client 50.116.65.227:16860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4XxxXES7Mv0Zfga-n-agAAAOY"]
[Mon Jul 20 06:42:47.339632 2026] [security2:error] [pid 1011111:tid 1011263] [client 46.110.96.34:49159] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XxxXES7Mv0Zfga-n-awAAAJo"]
[Mon Jul 20 06:42:47.347509 2026] [security2:error] [pid 1011111:tid 1011358] [client 50.116.65.227:16870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4XxxXES7Mv0Zfga-n-bAAAAPk"]
[Mon Jul 20 06:42:47.375236 2026] [security2:error] [pid 1011111:tid 1011211] [remote 173.249.4.11:49919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4XxxXES7Mv0Zfga-n-cAAA52I"]
[Mon Jul 20 06:42:47.414224 2026] [security2:error] [pid 1011111:tid 1011335] [client 173.239.240.93:40001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XxxXES7Mv0Zfga-n-cgAAAOI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:47.427244 2026] [security2:error] [pid 1011111:tid 1011272] [client 140.245.46.64:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4XxxXES7Mv0Zfga-n-cwAAAKM"]
[Mon Jul 20 06:42:47.532142 2026] [security2:error] [pid 1011111:tid 1011345] [client 57.141.18.53:31568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XxRXES7Mv0Zfga-n98AAA7B8"]
[Mon Jul 20 06:42:47.716708 2026] [security2:error] [pid 1011111:tid 1011154] [remote 68.178.160.25:33122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XxxXES7Mv0Zfga-n-kQAA-ik"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:47.718779 2026] [security2:error] [pid 1011111:tid 1011302] [client 45.3.44.87:40981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4XxxXES7Mv0Zfga-n-jgAAAME"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:42:47.766197 2026] [security2:error] [pid 1011111:tid 1011334] [client 57.141.18.7:57130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XxRXES7Mv0Zfga-n9_QAA4UM"]
[Mon Jul 20 06:42:47.876147 2026] [security2:error] [pid 1011111:tid 1011269] [client 173.239.240.92:48281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XxxXES7Mv0Zfga-n-ngAAAKA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:47.998412 2026] [security2:error] [pid 1011111:tid 1011305] [client 140.245.46.64:63678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4XxxXES7Mv0Zfga-n-qwAAAMQ"]
[Mon Jul 20 06:42:47.999844 2026] [security2:error] [pid 1011111:tid 1011252] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XxxXES7Mv0Zfga-n-kAAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:48.172715 2026] [security2:error] [pid 1011111:tid 1011303] [client 103.125.179.95:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XyBXES7Mv0Zfga-n-uAAAAMI"]
[Mon Jul 20 06:42:48.173378 2026] [security2:error] [pid 1011111:tid 1011303] [client 103.125.179.95:62807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XyBXES7Mv0Zfga-n-uAAAAMI"]
[Mon Jul 20 06:42:48.368260 2026] [security2:error] [pid 1011111:tid 1011365] [client 136.144.35.250:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XyBXES7Mv0Zfga-n-yAAAAQA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:48.376516 2026] [security2:error] [pid 1011111:tid 1011179] [remote 5.161.225.162:55086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XyBXES7Mv0Zfga-n-yQAAxkI"]
[Mon Jul 20 06:42:48.376671 2026] [security2:error] [pid 1011111:tid 1011307] [client 5.161.225.162:55086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XyBXES7Mv0Zfga-n-yQAAxkI"]
[Mon Jul 20 06:42:48.470233 2026] [security2:error] [pid 1011111:tid 1011300] [client 197.186.66.42:56773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XyBXES7Mv0Zfga-n-0AAAAL8"]
[Mon Jul 20 06:42:48.474633 2026] [security2:error] [pid 1011111:tid 1011293] [client 114.119.142.232:58235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thewritinglair.com"] [uri "/robots.txt"] [unique_id "al4XyBXES7Mv0Zfga-n-0gAAALg"], referer: https://thewritinglair.com/robots.txt
[Mon Jul 20 06:42:48.481355 2026] [security2:error] [pid 1011111:tid 1011300] [client 197.186.66.42:56773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4XyBXES7Mv0Zfga-n-0AAAAL8"]
[Mon Jul 20 06:42:48.556706 2026] [core:error] [pid 1011111:tid 1011295] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:48.556724 2026] [core:error] [pid 1011111:tid 1011295] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:48.819809 2026] [security2:error] [pid 1011111:tid 1011289] [client 136.144.35.243:38389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XyBXES7Mv0Zfga-n-9wAAALQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:48.867293 2026] [core:error] [pid 1011111:tid 1011362] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:48.867320 2026] [core:error] [pid 1011111:tid 1011362] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:48.879779 2026] [core:error] [pid 1011111:tid 1011300] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:48.879814 2026] [core:error] [pid 1011111:tid 1011300] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:42:49.083551 2026] [security2:error] [pid 1011111:tid 1011253] [client 14.225.17.146:54793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4XyBXES7Mv0Zfga-n_CQAAAJA"], referer: http://cephasnext.com/new
[Mon Jul 20 06:42:49.270181 2026] [security2:error] [pid 1011111:tid 1011297] [client 173.239.240.97:59431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XyRXES7Mv0Zfga-n_IwAAALw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:49.299017 2026] [security2:error] [pid 1011111:tid 1011277] [client 34.73.38.214:54425] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XyRXES7Mv0Zfga-n_JgAAAKg"]
[Mon Jul 20 06:42:49.366863 2026] [security2:error] [pid 1011111:tid 1011301] [client 65.1.132.125:37692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_LAAAAMA"]
[Mon Jul 20 06:42:49.366982 2026] [security2:error] [pid 1011111:tid 1011301] [client 65.1.132.125:37692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_LAAAAMA"]
[Mon Jul 20 06:42:49.370304 2026] [security2:error] [pid 1011111:tid 1011254] [client 14.225.17.146:54800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4XyBXES7Mv0Zfga-n_CgAAAJE"], referer: http://grecruit.online/new
[Mon Jul 20 06:42:49.491446 2026] [security2:error] [pid 1011111:tid 1011310] [client 14.225.17.146:53865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4XyRXES7Mv0Zfga-n_KgAAAMk"], referer: http://phillipbloch.com/new
[Mon Jul 20 06:42:49.689728 2026] [security2:error] [pid 1011111:tid 1011288] [client 106.219.188.178:51791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_RQAAALM"]
[Mon Jul 20 06:42:49.690109 2026] [security2:error] [pid 1011111:tid 1011288] [client 106.219.188.178:51791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_RQAAALM"]
[Mon Jul 20 06:42:49.749619 2026] [security2:error] [pid 1011111:tid 1011267] [client 57.141.18.40:44556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XxxXES7Mv0Zfga-n-lAAAnh4"]
[Mon Jul 20 06:42:49.753007 2026] [security2:error] [pid 1011111:tid 1011316] [client 173.239.240.99:50737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XyRXES7Mv0Zfga-n_TQAAAM8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:49.780802 2026] [security2:error] [pid 1011111:tid 1011264] [client 192.140.149.97:45506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_TgAAAJs"]
[Mon Jul 20 06:42:49.780936 2026] [security2:error] [pid 1011111:tid 1011264] [client 192.140.149.97:45506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_TgAAAJs"]
[Mon Jul 20 06:42:49.836884 2026] [security2:error] [pid 1011111:tid 1011362] [client 34.73.38.214:63509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XyRXES7Mv0Zfga-n_WwAAAP0"]
[Mon Jul 20 06:42:49.921271 2026] [security2:error] [pid 1011111:tid 1011369] [client 14.225.17.146:49685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4XyRXES7Mv0Zfga-n_KwAAAQQ"]
[Mon Jul 20 06:42:49.968382 2026] [security2:error] [pid 1011111:tid 1011176] [remote 192.241.143.148:44592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_ZwAAvj8"]
[Mon Jul 20 06:42:49.968488 2026] [security2:error] [pid 1011111:tid 1011299] [client 192.241.143.148:44592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4XyRXES7Mv0Zfga-n_ZwAAvj8"]
[Mon Jul 20 06:42:50.086778 2026] [security2:error] [pid 1011111:tid 1011252] [client 77.110.127.138:53181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XyhXES7Mv0Zfga-n_aQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:50.086898 2026] [security2:error] [pid 1011111:tid 1011252] [client 77.110.127.138:53181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XyhXES7Mv0Zfga-n_aQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:50.121698 2026] [security2:error] [pid 1011111:tid 1011280] [client 183.82.98.154:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XyhXES7Mv0Zfga-n_bAAAAKs"]
[Mon Jul 20 06:42:50.121844 2026] [security2:error] [pid 1011111:tid 1011280] [client 183.82.98.154:52917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4XyhXES7Mv0Zfga-n_bAAAAKs"]
[Mon Jul 20 06:42:50.213769 2026] [security2:error] [pid 1011111:tid 1011335] [client 136.144.35.254:47615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XyhXES7Mv0Zfga-n_dQAAAOI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:50.222687 2026] [security2:error] [pid 1011111:tid 1011338] [client 14.225.17.146:53263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4XyRXES7Mv0Zfga-n_VQAAAOU"], referer: http://uritems.net/new
[Mon Jul 20 06:42:50.555280 2026] [security2:error] [pid 1011111:tid 1011331] [client 14.225.17.146:55167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_dwAAAN4"], referer: http://nextlevelpressurewashing.com/new
[Mon Jul 20 06:42:50.696574 2026] [security2:error] [pid 1011111:tid 1011245] [client 136.144.35.248:24823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_sQAAAIg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:50.824176 2026] [security2:error] [pid 1011111:tid 1011260] [client 14.225.17.146:54528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_cgAAAJc"], referer: http://balticsteelmgmt.com/new
[Mon Jul 20 06:42:50.888366 2026] [security2:error] [pid 1011111:tid 1011347] [client 57.141.18.45:30850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XyBXES7Mv0Zfga-n_BwAA7jA"]
[Mon Jul 20 06:42:50.893811 2026] [security2:error] [pid 1011111:tid 1011265] [client 14.225.17.146:54879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_rAAAAJw"], referer: http://recruitinginsight.us/new
[Mon Jul 20 06:42:50.967634 2026] [security2:error] [pid 1011111:tid 1011321] [client 34.139.11.221:59777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.familiaconsciente.com"] [uri "/xmlrpc.php"] [unique_id "al4XyhXES7Mv0Zfga-n_yQAAANQ"]
[Mon Jul 20 06:42:51.005600 2026] [security2:error] [pid 1011111:tid 1011340] [client 140.245.46.64:65235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-includes/version.php"] [unique_id "al4XyxXES7Mv0Zfga-n_ywAAAOc"]
[Mon Jul 20 06:42:51.044644 2026] [security2:error] [pid 1011111:tid 1011352] [client 122.183.32.225:17244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-n_zgAAAPM"]
[Mon Jul 20 06:42:51.054257 2026] [security2:error] [pid 1011111:tid 1011352] [client 122.183.32.225:17244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-n_zgAAAPM"]
[Mon Jul 20 06:42:51.112099 2026] [security2:error] [pid 1011111:tid 1011319] [client 54.198.0.135:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_fwAAANI"]
[Mon Jul 20 06:42:51.132562 2026] [security2:error] [pid 1011111:tid 1011287] [client 54.198.0.135:55650] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-beans-habichuelas-guisadas/"] [unique_id "al4XyhXES7Mv0Zfga-n_eQAAALI"]
[Mon Jul 20 06:42:51.137253 2026] [security2:error] [pid 1011111:tid 1011339] [client 34.139.11.221:56712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-n_1QAAAOY"]
[Mon Jul 20 06:42:51.148960 2026] [security2:error] [pid 1011111:tid 1011324] [client 50.116.65.227:21648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4XyxXES7Mv0Zfga-n_2AAAAOU"]
[Mon Jul 20 06:42:51.193963 2026] [security2:error] [pid 1011111:tid 1011308] [client 136.144.35.248:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XyxXES7Mv0Zfga-n_3QAAAMc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:51.213235 2026] [security2:error] [pid 1011111:tid 1011264] [client 40.77.167.61:7731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_oAAAm3I"]
[Mon Jul 20 06:42:51.257858 2026] [security2:error] [pid 1011111:tid 1011313] [client 46.110.96.34:1434] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XyxXES7Mv0Zfga-n_5QAAAMw"]
[Mon Jul 20 06:42:51.259000 2026] [security2:error] [pid 1011111:tid 1011334] [client 46.110.96.34:31656] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XyxXES7Mv0Zfga-n_5gAAAOE"]
[Mon Jul 20 06:42:51.314887 2026] [security2:error] [pid 1011111:tid 1011252] [client 34.139.11.221:62059] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-n_7wAAAI8"]
[Mon Jul 20 06:42:51.321518 2026] [security2:error] [pid 1011111:tid 1011249] [client 46.110.96.34:18811] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4XyxXES7Mv0Zfga-n_8AAAAIw"]
[Mon Jul 20 06:42:51.369329 2026] [security2:error] [pid 1011111:tid 1011211] [remote 173.249.4.11:49919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4XyxXES7Mv0Zfga-n_9AAAn2I"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 06:42:51.488524 2026] [security2:error] [pid 1011111:tid 1011309] [client 112.208.70.94:43568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-kAAgAAAMg"]
[Mon Jul 20 06:42:51.488707 2026] [security2:error] [pid 1011111:tid 1011309] [client 112.208.70.94:43568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-kAAgAAAMg"]
[Mon Jul 20 06:42:51.491198 2026] [security2:error] [pid 1011111:tid 1011310] [client 34.139.11.221:49486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-kABAAAAMk"]
[Mon Jul 20 06:42:51.558816 2026] [security2:error] [pid 1011111:tid 1011356] [client 14.225.17.146:49628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4XyxXES7Mv0Zfga-n_4gAAAPc"], referer: http://hilltopnurseryinc.com/new
[Mon Jul 20 06:42:51.576289 2026] [security2:error] [pid 1011111:tid 1011323] [client 140.245.46.64:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-includes/functions.php"] [unique_id "al4XyxXES7Mv0Zfga-kACQAAANY"]
[Mon Jul 20 06:42:51.627657 2026] [security2:error] [pid 1011111:tid 1011354] [client 34.139.11.221:58217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.fansarogroup.com"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-kAEAAAAPU"]
[Mon Jul 20 06:42:51.646884 2026] [security2:error] [pid 1011111:tid 1011245] [client 173.239.240.100:28593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XyxXES7Mv0Zfga-kAEQAAAIg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:51.698810 2026] [security2:error] [pid 1011111:tid 1011262] [client 57.141.18.101:53286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XyRXES7Mv0Zfga-n_QwAAmSs"]
[Mon Jul 20 06:42:51.765613 2026] [security2:error] [pid 1011111:tid 1011331] [client 34.139.11.221:55555] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-kAFgAAAN4"]
[Mon Jul 20 06:42:51.831634 2026] [security2:error] [pid 1011111:tid 1011341] [client 34.139.11.221:60446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-kAGAAAAOg"]
[Mon Jul 20 06:42:51.921230 2026] [security2:error] [pid 1011111:tid 1011291] [client 34.139.11.221:59392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-kAJQAAALY"]
[Mon Jul 20 06:42:51.954287 2026] [security2:error] [pid 1011111:tid 1011352] [client 171.61.165.146:12834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-kAKgAAAPM"]
[Mon Jul 20 06:42:51.954393 2026] [security2:error] [pid 1011111:tid 1011352] [client 171.61.165.146:12834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-kAKgAAAPM"]
[Mon Jul 20 06:42:51.983228 2026] [security2:error] [pid 1011111:tid 1011285] [client 34.139.11.221:52975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XyxXES7Mv0Zfga-kAKwAAALA"]
[Mon Jul 20 06:42:51.985558 2026] [security2:error] [pid 1011111:tid 1011287] [client 34.139.11.221:63110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.familiasconscientes.com"] [uri "/xmlrpc.php"] [unique_id "al4XyxXES7Mv0Zfga-kALAAAALI"]
[Mon Jul 20 06:42:52.016332 2026] [security2:error] [pid 1011111:tid 1011277] [client 34.73.38.214:64863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kALwAAAKg"]
[Mon Jul 20 06:42:52.090125 2026] [security2:error] [pid 1011111:tid 1011248] [client 14.225.17.146:53790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4XyxXES7Mv0Zfga-n_zAAAAIs"], referer: http://ncsynchro.com/new
[Mon Jul 20 06:42:52.090294 2026] [security2:error] [pid 1011111:tid 1011281] [client 34.139.11.221:64311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kANwAAAKw"]
[Mon Jul 20 06:42:52.094886 2026] [security2:error] [pid 1011111:tid 1011323] [client 34.139.11.221:64889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAOQAAANY"]
[Mon Jul 20 06:42:52.111951 2026] [security2:error] [pid 1011111:tid 1011346] [client 136.144.35.254:23965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XzBXES7Mv0Zfga-kAOgAAAO0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:52.147440 2026] [security2:error] [pid 1011111:tid 1011367] [client 140.245.46.64:49437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4XzBXES7Mv0Zfga-kAOwAAAQI"]
[Mon Jul 20 06:42:52.161577 2026] [security2:error] [pid 1011111:tid 1011245] [client 34.139.11.221:59918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAPAAAAIg"]
[Mon Jul 20 06:42:52.236885 2026] [security2:error] [pid 1011111:tid 1011348] [client 34.139.11.221:50172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kARAAAAO8"]
[Mon Jul 20 06:42:52.286519 2026] [security2:error] [pid 1011111:tid 1011314] [client 34.139.11.221:49223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kARwAAAM0"]
[Mon Jul 20 06:42:52.316142 2026] [security2:error] [pid 1011111:tid 1011315] [client 34.139.11.221:50579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kASgAAAM4"]
[Mon Jul 20 06:42:52.350245 2026] [security2:error] [pid 1011111:tid 1011250] [client 57.141.18.72:27286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XyhXES7Mv0Zfga-n_kwAAjXY"]
[Mon Jul 20 06:42:52.374160 2026] [security2:error] [pid 1011111:tid 1011355] [client 34.139.11.221:55689] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAUAAAAPY"]
[Mon Jul 20 06:42:52.437526 2026] [security2:error] [pid 1011111:tid 1011267] [client 34.139.11.221:58671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAVgAAAJ4"]
[Mon Jul 20 06:42:52.502926 2026] [security2:error] [pid 1011111:tid 1011251] [client 52.233.165.60:11713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XzBXES7Mv0Zfga-kAYAAAAI4"]
[Mon Jul 20 06:42:52.536842 2026] [security2:error] [pid 1011111:tid 1011346] [client 34.139.11.221:53021] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAYwAAAO0"]
[Mon Jul 20 06:42:52.564789 2026] [security2:error] [pid 1011111:tid 1011365] [client 136.144.35.251:24041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XzBXES7Mv0Zfga-kAZgAAAQA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:52.585282 2026] [security2:error] [pid 1011111:tid 1011354] [client 34.139.11.221:57077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAaAAAAPU"]
[Mon Jul 20 06:42:52.585845 2026] [security2:error] [pid 1011111:tid 1011271] [client 14.225.17.146:55254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4XzBXES7Mv0Zfga-kAXwAAAKI"], referer: http://ravmike.com/new
[Mon Jul 20 06:42:52.597217 2026] [security2:error] [pid 1011111:tid 1011317] [client 34.139.11.221:56855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAagAAANA"]
[Mon Jul 20 06:42:52.651743 2026] [security2:error] [pid 1011111:tid 1011263] [client 52.233.165.60:11713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XzBXES7Mv0Zfga-kAbQAAAJo"]
[Mon Jul 20 06:42:52.683637 2026] [security2:error] [pid 1011111:tid 1011353] [client 20.199.97.14:1152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4XzBXES7Mv0Zfga-kAcAAAAPQ"]
[Mon Jul 20 06:42:52.703093 2026] [security2:error] [pid 1011111:tid 1011362] [client 34.139.11.221:55361] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAcgAAAP0"]
[Mon Jul 20 06:42:52.716958 2026] [security2:error] [pid 1011111:tid 1011248] [client 140.245.46.64:49769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-includes/option.php"] [unique_id "al4XzBXES7Mv0Zfga-kAdAAAAIs"]
[Mon Jul 20 06:42:52.800147 2026] [security2:error] [pid 1011111:tid 1011250] [client 34.139.11.221:50672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiaconsciente.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAeQAAAI0"]
[Mon Jul 20 06:42:52.812610 2026] [security2:error] [pid 1011111:tid 1011291] [client 34.139.11.221:49845] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAegAAALY"]
[Mon Jul 20 06:42:52.841671 2026] [security2:error] [pid 1011111:tid 1011360] [client 20.199.97.14:1152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4XzBXES7Mv0Zfga-kAewAAAPs"]
[Mon Jul 20 06:42:52.863105 2026] [security2:error] [pid 1011111:tid 1011368] [client 14.225.17.146:54032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4XzBXES7Mv0Zfga-kAeAAAAQM"], referer: http://daseighty.net/new
[Mon Jul 20 06:42:52.896010 2026] [security2:error] [pid 1011111:tid 1011287] [client 34.139.11.221:63133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAgAAAALI"]
[Mon Jul 20 06:42:52.914651 2026] [security2:error] [pid 1011111:tid 1011268] [client 34.73.38.214:49411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAhAAAAJ8"]
[Mon Jul 20 06:42:52.978421 2026] [security2:error] [pid 1011111:tid 1011251] [client 34.139.11.221:53702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4XzBXES7Mv0Zfga-kAhwAAAI4"]
[Mon Jul 20 06:42:53.034673 2026] [security2:error] [pid 1011111:tid 1011357] [client 173.239.240.98:32095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XzRXES7Mv0Zfga-kAjwAAAPg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:53.048636 2026] [security2:error] [pid 1011111:tid 1011282] [client 34.139.11.221:53411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kAkAAAAK0"]
[Mon Jul 20 06:42:53.077899 2026] [security2:error] [pid 1011111:tid 1011139] [remote 173.249.4.11:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XzRXES7Mv0Zfga-kAkwAAtBo"]
[Mon Jul 20 06:42:53.185552 2026] [security2:error] [pid 1011111:tid 1011249] [client 34.139.11.221:53635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kAnQAAAIw"]
[Mon Jul 20 06:42:53.188525 2026] [security2:error] [pid 1011111:tid 1011256] [client 34.139.11.221:61529] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kAngAAAJM"]
[Mon Jul 20 06:42:53.251153 2026] [security2:error] [pid 1011111:tid 1011242] [client 34.73.38.214:61370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kApgAAAIU"]
[Mon Jul 20 06:42:53.285502 2026] [security2:error] [pid 1011111:tid 1011353] [client 140.245.46.64:50087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-includes/post.php"] [unique_id "al4XzRXES7Mv0Zfga-kArAAAAPQ"]
[Mon Jul 20 06:42:53.332504 2026] [security2:error] [pid 1011111:tid 1011284] [client 34.139.11.221:65265] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kArwAAAK8"]
[Mon Jul 20 06:42:53.345038 2026] [security2:error] [pid 1011111:tid 1011285] [client 34.139.11.221:57335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fansarogroup.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kAsAAAALA"]
[Mon Jul 20 06:42:53.346827 2026] [security2:error] [pid 1011111:tid 1011308] [client 57.141.18.53:23902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XyxXES7Mv0Zfga-kADAAAx3s"]
[Mon Jul 20 06:42:53.380891 2026] [security2:error] [pid 1011111:tid 1011354] [client 187.108.85.186:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XzRXES7Mv0Zfga-kAtQAAAPU"]
[Mon Jul 20 06:42:53.381061 2026] [security2:error] [pid 1011111:tid 1011354] [client 187.108.85.186:63307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4XzRXES7Mv0Zfga-kAtQAAAPU"]
[Mon Jul 20 06:42:53.462027 2026] [security2:error] [pid 1011111:tid 1011333] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4XzRXES7Mv0Zfga-kAnwAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:53.510652 2026] [security2:error] [pid 1011111:tid 1011247] [client 136.144.35.250:30263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XzRXES7Mv0Zfga-kAwAAAAIo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:53.517610 2026] [security2:error] [pid 1011111:tid 1011196] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XzRXES7Mv0Zfga-kAvwABA1M"]
[Mon Jul 20 06:42:53.517858 2026] [security2:error] [pid 1011111:tid 1011368] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4XzRXES7Mv0Zfga-kAvwABA1M"]
[Mon Jul 20 06:42:53.539095 2026] [security2:error] [pid 1011111:tid 1011346] [client 34.139.11.221:57363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kAxQAAAO0"]
[Mon Jul 20 06:42:53.662324 2026] [security2:error] [pid 1011111:tid 1011293] [client 57.141.18.72:27292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4XyxXES7Mv0Zfga-kAKQAAuH4"]
[Mon Jul 20 06:42:53.740319 2026] [security2:error] [pid 1011111:tid 1011358] [client 34.139.11.221:62642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.familiasconscientes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4XzRXES7Mv0Zfga-kAzgAAAPk"]
[Mon Jul 20 06:42:53.771678 2026] [security2:error] [pid 1011111:tid 1011197] [remote 173.249.4.11:60649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4XzRXES7Mv0Zfga-kA0AAAx1Q"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:42:53.855616 2026] [security2:error] [pid 1011111:tid 1011249] [client 140.245.46.64:50382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-includes/user.php"] [unique_id "al4XzRXES7Mv0Zfga-kA2QAAAIw"]
[Mon Jul 20 06:42:53.913251 2026] [core:error] [pid 1011111:tid 1011266] [client 157.230.141.197:42578] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Mon Jul 20 06:42:53.962861 2026] [security2:error] [pid 1011111:tid 1011354] [client 136.144.35.248:47003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XzRXES7Mv0Zfga-kA5QAAAPU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:53.979103 2026] [security2:error] [pid 1011111:tid 1011295] [client 152.58.191.29:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XzRXES7Mv0Zfga-kA5wAAALo"]
[Mon Jul 20 06:42:53.979271 2026] [security2:error] [pid 1011111:tid 1011295] [client 152.58.191.29:59012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4XzRXES7Mv0Zfga-kA5wAAALo"]
[Mon Jul 20 06:42:54.036216 2026] [security2:error] [pid 1011111:tid 1011276] [client 165.0.44.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4XzRXES7Mv0Zfga-kAuAAAAKc"]
[Mon Jul 20 06:42:54.066488 2026] [security2:error] [pid 1011111:tid 1011306] [client 144.172.114.51:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.thescarystory.com"] [uri "/wp-config.php.txt"] [unique_id "al4XzhXES7Mv0Zfga-kA7gAAAMU"]
[Mon Jul 20 06:42:54.129340 2026] [security2:error] [pid 1011111:tid 1011310] [client 45.3.38.36:51291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4XzhXES7Mv0Zfga-kA8QAAAMk"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:42:54.433835 2026] [security2:error] [pid 1011111:tid 1011358] [client 173.239.240.96:29789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XzhXES7Mv0Zfga-kBCwAAAPk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:54.450502 2026] [security2:error] [pid 1011111:tid 1011280] [client 34.73.38.214:51610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4XzhXES7Mv0Zfga-kBDAAAAKs"]
[Mon Jul 20 06:42:54.524495 2026] [security2:error] [pid 1011111:tid 1011337] [client 103.238.106.162:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XzhXES7Mv0Zfga-kBFwAAAOQ"]
[Mon Jul 20 06:42:54.524683 2026] [security2:error] [pid 1011111:tid 1011337] [client 103.238.106.162:42656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4XzhXES7Mv0Zfga-kBFwAAAOQ"]
[Mon Jul 20 06:42:54.624858 2026] [security2:error] [pid 1011111:tid 1011311] [client 14.225.17.146:54725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4XzRXES7Mv0Zfga-kAkgAAAMo"], referer: http://blaizeaccountingservices.com/new
[Mon Jul 20 06:42:54.883961 2026] [security2:error] [pid 1011111:tid 1011366] [client 136.144.35.243:51899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XzhXES7Mv0Zfga-kBNgAAAQE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:54.916371 2026] [security2:error] [pid 1011111:tid 1011349] [client 217.142.18.172:26917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XzhXES7Mv0Zfga-kBOAAAAPA"]
[Mon Jul 20 06:42:54.916464 2026] [security2:error] [pid 1011111:tid 1011349] [client 217.142.18.172:26917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4XzhXES7Mv0Zfga-kBOAAAAPA"]
[Mon Jul 20 06:42:54.925997 2026] [security2:error] [pid 1011111:tid 1011369] [client 77.110.127.138:53220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzhXES7Mv0Zfga-kBOQAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:54.926101 2026] [security2:error] [pid 1011111:tid 1011369] [client 77.110.127.138:53220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzhXES7Mv0Zfga-kBOQAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.006916 2026] [security2:error] [pid 1011111:tid 1011304] [client 14.251.3.155:54647] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4XzxXES7Mv0Zfga-kBQAAAAMM"]
[Mon Jul 20 06:42:55.151161 2026] [security2:error] [pid 1011111:tid 1011334] [client 77.110.127.138:53223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzxXES7Mv0Zfga-kBUwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.151271 2026] [security2:error] [pid 1011111:tid 1011334] [client 77.110.127.138:53223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzxXES7Mv0Zfga-kBUwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.236424 2026] [security2:error] [pid 1011111:tid 1011321] [client 57.141.18.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4XzxXES7Mv0Zfga-kBTQAAANQ"]
[Mon Jul 20 06:42:55.356264 2026] [security2:error] [pid 1011111:tid 1011289] [client 173.239.240.92:46509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4XzxXES7Mv0Zfga-kBXgAAALQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:55.560278 2026] [security2:error] [pid 1011111:tid 1011329] [client 77.110.127.138:53225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzxXES7Mv0Zfga-kBbgAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.560355 2026] [security2:error] [pid 1011111:tid 1011329] [client 77.110.127.138:53225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzxXES7Mv0Zfga-kBbgAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.635408 2026] [security2:error] [pid 1011111:tid 1011181] [remote 57.141.18.6:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3927072"] [unique_id "al4XzxXES7Mv0Zfga-kBdAAAzkQ"]
[Mon Jul 20 06:42:55.815205 2026] [security2:error] [pid 1011111:tid 1011358] [client 77.110.127.138:53232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzxXES7Mv0Zfga-kBhQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.815322 2026] [security2:error] [pid 1011111:tid 1011358] [client 77.110.127.138:53232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4XzxXES7Mv0Zfga-kBhQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:55.816433 2026] [security2:error] [pid 1011111:tid 1011364] [client 136.144.35.246:33237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4XzxXES7Mv0Zfga-kBhwAAAP8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:56.085489 2026] [security2:error] [pid 1011111:tid 1011250] [client 77.110.127.138:53235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X0BXES7Mv0Zfga-kBoQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:56.085647 2026] [security2:error] [pid 1011111:tid 1011250] [client 77.110.127.138:53235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X0BXES7Mv0Zfga-kBoQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:42:56.287185 2026] [security2:error] [pid 1011111:tid 1011315] [client 173.239.240.91:23783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X0BXES7Mv0Zfga-kBrQAAAM4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:56.419325 2026] [security2:error] [pid 1011111:tid 1011351] [client 14.225.17.146:54308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4XzxXES7Mv0Zfga-kBWQAAAPI"], referer: http://collectingrealestate.com/new
[Mon Jul 20 06:42:56.554353 2026] [security2:error] [pid 1011111:tid 1011271] [client 46.110.96.34:56369] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X0BXES7Mv0Zfga-kBzQAAAKI"]
[Mon Jul 20 06:42:56.554355 2026] [security2:error] [pid 1011111:tid 1011306] [client 46.110.96.34:22878] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X0BXES7Mv0Zfga-kBzwAAAMU"]
[Mon Jul 20 06:42:56.579327 2026] [security2:error] [pid 1011111:tid 1011339] [client 46.110.96.34:5657] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X0BXES7Mv0Zfga-kB0gAAAOY"]
[Mon Jul 20 06:42:56.759193 2026] [security2:error] [pid 1011111:tid 1011273] [client 173.239.240.100:20495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X0BXES7Mv0Zfga-kB5gAAAKQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:56.760529 2026] [security2:error] [pid 1011111:tid 1011336] [client 34.73.38.214:52717] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4X0BXES7Mv0Zfga-kB5wAAAOM"]
[Mon Jul 20 06:42:57.010040 2026] [security2:error] [pid 1011111:tid 1011118] [remote 20.153.140.50:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4X0RXES7Mv0Zfga-kB-wAA2AU"]
[Mon Jul 20 06:42:57.131564 2026] [autoindex:error] [pid 1011111:tid 1011347] [client 13.229.83.156:34912] AH01276: Cannot serve directory /home4/curlsnp2/public_html/new/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://curlsnpearlsss.com/new
[Mon Jul 20 06:42:57.213917 2026] [security2:error] [pid 1011111:tid 1011329] [client 136.144.35.247:32601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X0RXES7Mv0Zfga-kCCQAAANw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:57.252537 2026] [security2:error] [pid 1011111:tid 1011346] [client 14.225.17.146:55636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4X0RXES7Mv0Zfga-kCBAAAAO0"], referer: http://walkingandtalking.net/new
[Mon Jul 20 06:42:57.306135 2026] [security2:error] [pid 1011111:tid 1011258] [client 50.116.65.227:21772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4X0RXES7Mv0Zfga-kCEAAAAJU"]
[Mon Jul 20 06:42:57.318252 2026] [security2:error] [pid 1011111:tid 1011369] [client 50.116.65.227:21778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4X0RXES7Mv0Zfga-kCEQAAAQQ"]
[Mon Jul 20 06:42:57.406000 2026] [security2:error] [pid 1011111:tid 1011166] [remote 20.153.140.50:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4X0RXES7Mv0Zfga-kCGQAAoTU"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 06:42:57.606182 2026] [security2:error] [pid 1011111:tid 1011157] [remote 182.77.62.24:35676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4X0RXES7Mv0Zfga-kCYAAApSw"]
[Mon Jul 20 06:42:57.622970 2026] [security2:error] [pid 1011111:tid 1011319] [client 14.225.17.146:54676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X0RXES7Mv0Zfga-kCHgAAANI"], referer: http://mezzacraft.com/new
[Mon Jul 20 06:42:57.655261 2026] [security2:error] [pid 1011111:tid 1011340] [client 37.52.210.45:3175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X0RXES7Mv0Zfga-kChgAAAOc"]
[Mon Jul 20 06:42:57.655381 2026] [security2:error] [pid 1011111:tid 1011340] [client 37.52.210.45:3175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X0RXES7Mv0Zfga-kChgAAAOc"]
[Mon Jul 20 06:42:57.672852 2026] [security2:error] [pid 1011111:tid 1011280] [client 173.239.240.92:44921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X0RXES7Mv0Zfga-kCiQAAAKs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:57.999700 2026] [security2:error] [pid 1011111:tid 1011301] [client 34.73.38.214:49729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4X0RXES7Mv0Zfga-kCpwAAAMA"]
[Mon Jul 20 06:42:58.127553 2026] [security2:error] [pid 1011111:tid 1011267] [client 173.239.240.97:22553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X0hXES7Mv0Zfga-kCswAAAJ4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:58.183318 2026] [security2:error] [pid 1011111:tid 1011336] [client 14.225.17.146:49223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4X0hXES7Mv0Zfga-kCtgAAAOM"], referer: https://walkingandtalking.net/new
[Mon Jul 20 06:42:58.217088 2026] [security2:error] [pid 1011111:tid 1011141] [remote 182.77.62.24:35676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4X0hXES7Mv0Zfga-kCuQAAlhw"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:42:58.473876 2026] [security2:error] [pid 1011111:tid 1011351] [client 46.110.96.34:27090] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4X0hXES7Mv0Zfga-kC0gAAAPI"]
[Mon Jul 20 06:42:58.539695 2026] [security2:error] [pid 1011111:tid 1011287] [client 46.110.96.34:45088] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4X0hXES7Mv0Zfga-kC1QAAALI"]
[Mon Jul 20 06:42:58.544041 2026] [security2:error] [pid 1011111:tid 1011302] [client 57.141.18.90:40366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X0BXES7Mv0Zfga-kBvQAAwR8"]
[Mon Jul 20 06:42:58.576410 2026] [security2:error] [pid 1011111:tid 1011328] [client 173.239.240.98:42175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X0hXES7Mv0Zfga-kC2AAAANs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:58.887665 2026] [security2:error] [pid 1011111:tid 1011359] [client 216.73.217.138:19841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4X0hXES7Mv0Zfga-kC5QAA-ns"]
[Mon Jul 20 06:42:58.947504 2026] [security2:error] [pid 1011111:tid 1011298] [client 103.125.179.95:63294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X0hXES7Mv0Zfga-kC9QAAAL0"]
[Mon Jul 20 06:42:58.947655 2026] [security2:error] [pid 1011111:tid 1011298] [client 103.125.179.95:63294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X0hXES7Mv0Zfga-kC9QAAAL0"]
[Mon Jul 20 06:42:59.025096 2026] [security2:error] [pid 1011111:tid 1011366] [client 136.144.35.251:44901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kC_gAAAQE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:59.028126 2026] [security2:error] [pid 1011111:tid 1011274] [client 14.225.17.146:52452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4X0hXES7Mv0Zfga-kC7AAAAKU"], referer: http://maplerespiteservices.com/new
[Mon Jul 20 06:42:59.059435 2026] [security2:error] [pid 1011111:tid 1011119] [remote 51.158.61.221:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kDAwAA8AY"]
[Mon Jul 20 06:42:59.143632 2026] [security2:error] [pid 1011111:tid 1011341] [client 14.225.17.146:54490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4X0xXES7Mv0Zfga-kC_wAAAOg"], referer: http://nextlvlmarketingco.com/new
[Mon Jul 20 06:42:59.262066 2026] [security2:error] [pid 1011111:tid 1011173] [remote 51.158.61.221:56970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kDEQAAnjw"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 06:42:59.309111 2026] [security2:error] [pid 1011111:tid 1011253] [client 223.185.13.213:31429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X0xXES7Mv0Zfga-kDFgAAAJA"]
[Mon Jul 20 06:42:59.309227 2026] [security2:error] [pid 1011111:tid 1011253] [client 223.185.13.213:31429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X0xXES7Mv0Zfga-kDFgAAAJA"]
[Mon Jul 20 06:42:59.319528 2026] [security2:error] [pid 1011111:tid 1011335] [client 104.234.53.52:21603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kDFQAAAOI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:42:59.349998 2026] [security2:error] [pid 1011111:tid 1011284] [client 14.225.17.146:65484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4X0xXES7Mv0Zfga-kDCwAAAK8"], referer: http://dadanetnet.net/new
[Mon Jul 20 06:42:59.409912 2026] [security2:error] [pid 1011111:tid 1011277] [client 46.110.96.34:52190] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X0xXES7Mv0Zfga-kDJwAAAKg"]
[Mon Jul 20 06:42:59.410784 2026] [security2:error] [pid 1011111:tid 1011298] [client 46.110.96.34:50607] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X0xXES7Mv0Zfga-kDKAAAAL0"]
[Mon Jul 20 06:42:59.433356 2026] [security2:error] [pid 1011111:tid 1011332] [client 34.73.38.214:51367] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4X0xXES7Mv0Zfga-kDKgAAAN8"]
[Mon Jul 20 06:42:59.471517 2026] [security2:error] [pid 1011111:tid 1011258] [client 46.110.96.34:4570] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X0xXES7Mv0Zfga-kDLAAAAJU"]
[Mon Jul 20 06:42:59.503973 2026] [security2:error] [pid 1011111:tid 1011299] [client 136.144.35.251:47215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X0xXES7Mv0Zfga-kDLgAAAL4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:42:59.569084 2026] [security2:error] [pid 1011111:tid 1011354] [client 14.225.17.146:52554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4X0xXES7Mv0Zfga-kDKwAAAPU"], referer: http://dnsplumbing.com/new
[Mon Jul 20 06:42:59.599559 2026] [security2:error] [pid 1011111:tid 1011135] [remote 91.142.222.105:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kDNgAAkRY"]
[Mon Jul 20 06:42:59.639901 2026] [security2:error] [pid 1011111:tid 1011276] [client 57.141.18.122:41276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X0RXES7Mv0Zfga-kCGAAAp1U"]
[Mon Jul 20 06:42:59.939581 2026] [security2:error] [pid 1011111:tid 1011335] [client 43.205.139.3:35950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kDVgAAAOI"]
[Mon Jul 20 06:42:59.959029 2026] [security2:error] [pid 1011111:tid 1011277] [client 136.144.35.253:45825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X0xXES7Mv0Zfga-kDWwAAAKg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:00.196884 2026] [security2:error] [pid 1011111:tid 1011343] [client 57.141.18.8:63698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X0RXES7Mv0Zfga-kCmwAA6iE"]
[Mon Jul 20 06:43:00.250062 2026] [security2:error] [pid 1011111:tid 1011164] [remote 91.142.222.105:56046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4X1BXES7Mv0Zfga-kDaAAA3DM"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 06:43:00.436341 2026] [security2:error] [pid 1011111:tid 1011251] [client 173.239.240.100:38187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X1BXES7Mv0Zfga-kDewAAAI4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:00.708496 2026] [security2:error] [pid 1011111:tid 1011249] [client 183.82.98.154:53492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X1BXES7Mv0Zfga-kDkgAAAIw"]
[Mon Jul 20 06:43:00.708606 2026] [security2:error] [pid 1011111:tid 1011249] [client 183.82.98.154:53492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X1BXES7Mv0Zfga-kDkgAAAIw"]
[Mon Jul 20 06:43:00.789833 2026] [security2:error] [pid 1011111:tid 1011247] [client 34.73.38.214:65449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4X1BXES7Mv0Zfga-kDlAAAAIo"]
[Mon Jul 20 06:43:00.930958 2026] [security2:error] [pid 1011111:tid 1011315] [client 173.239.240.99:21813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X1BXES7Mv0Zfga-kDowAAAM4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:00.999934 2026] [security2:error] [pid 1011111:tid 1011334] [client 13.233.207.33:22462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4X1BXES7Mv0Zfga-kDqwAAAOE"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:43:01.208877 2026] [autoindex:error] [pid 1011111:tid 1011355] [client 79.127.254.120:0] AH01276: Cannot serve directory /home3/lnltfcmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:43:01.351108 2026] [security2:error] [pid 1011111:tid 1011346] [client 57.141.18.35:61816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X0hXES7Mv0Zfga-kC8QAA7Qo"]
[Mon Jul 20 06:43:01.416996 2026] [security2:error] [pid 1011111:tid 1011264] [client 136.144.35.254:46223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X1RXES7Mv0Zfga-kD0wAAAJs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:01.517424 2026] [security2:error] [pid 1011111:tid 1011249] [client 197.186.66.42:57398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X1RXES7Mv0Zfga-kD2AAAAIw"]
[Mon Jul 20 06:43:01.526186 2026] [security2:error] [pid 1011111:tid 1011249] [client 197.186.66.42:57398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X1RXES7Mv0Zfga-kD2AAAAIw"]
[Mon Jul 20 06:43:01.541958 2026] [security2:error] [pid 1011111:tid 1011368] [client 57.141.18.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4X1RXES7Mv0Zfga-kDzwAAAQM"]
[Mon Jul 20 06:43:01.809603 2026] [security2:error] [pid 1011111:tid 1011337] [client 122.183.32.225:3922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X1RXES7Mv0Zfga-kD7gAAAOQ"]
[Mon Jul 20 06:43:01.809707 2026] [security2:error] [pid 1011111:tid 1011337] [client 122.183.32.225:3922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X1RXES7Mv0Zfga-kD7gAAAOQ"]
[Mon Jul 20 06:43:01.876138 2026] [core:error] [pid 1011111:tid 1011293] [client 14.225.17.146:56031] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:43:01.876159 2026] [core:error] [pid 1011111:tid 1011293] [client 14.225.17.146:56031] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:43:01.900960 2026] [security2:error] [pid 1011111:tid 1011265] [client 173.239.240.101:44627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X1RXES7Mv0Zfga-kD-wAAAJw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:01.943841 2026] [security2:error] [pid 1011111:tid 1011263] [client 77.110.127.138:53237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X1RXES7Mv0Zfga-kD_gAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:01.943936 2026] [security2:error] [pid 1011111:tid 1011263] [client 77.110.127.138:53237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X1RXES7Mv0Zfga-kD_gAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:02.085550 2026] [security2:error] [pid 1011111:tid 1011363] [client 112.208.70.94:43993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X1hXES7Mv0Zfga-kEBQAAAP4"]
[Mon Jul 20 06:43:02.085641 2026] [security2:error] [pid 1011111:tid 1011363] [client 112.208.70.94:43993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X1hXES7Mv0Zfga-kEBQAAAP4"]
[Mon Jul 20 06:43:02.373948 2026] [security2:error] [pid 1011111:tid 1011304] [client 136.144.35.253:58229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X1hXES7Mv0Zfga-kEGgAAAMM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:02.612942 2026] [security2:error] [pid 1011111:tid 1011251] [client 34.73.38.214:51578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4X1hXES7Mv0Zfga-kENwAAAI4"]
[Mon Jul 20 06:43:02.847461 2026] [security2:error] [pid 1011111:tid 1011243] [client 173.239.240.91:53367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X1hXES7Mv0Zfga-kESQAAAIY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:02.861877 2026] [security2:error] [pid 1011111:tid 1011332] [client 66.249.93.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4X1hXES7Mv0Zfga-kEJgAAAN8"]
[Mon Jul 20 06:43:03.000069 2026] [security2:error] [pid 1011111:tid 1011280] [client 34.73.38.214:51250] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4X1hXES7Mv0Zfga-kEWgAAAKs"]
[Mon Jul 20 06:43:03.112697 2026] [security2:error] [pid 1011111:tid 1011292] [client 46.110.96.34:5708] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X1xXES7Mv0Zfga-kEYQAAALc"]
[Mon Jul 20 06:43:03.118323 2026] [security2:error] [pid 1011111:tid 1011368] [client 14.225.17.146:53053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4X1hXES7Mv0Zfga-kETgAAAQM"], referer: http://according2plant.com/new
[Mon Jul 20 06:43:03.221508 2026] [security2:error] [pid 1011111:tid 1011281] [client 46.110.96.34:32144] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X1xXES7Mv0Zfga-kEbgAAAKw"]
[Mon Jul 20 06:43:03.248123 2026] [security2:error] [pid 1011111:tid 1011327] [client 104.234.53.62:22065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4X1xXES7Mv0Zfga-kEdQAAANo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:03.322388 2026] [security2:error] [pid 1011111:tid 1011295] [client 173.239.240.32:23347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X1xXES7Mv0Zfga-kEewAAALo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:03.334224 2026] [security2:error] [pid 1011111:tid 1011243] [client 77.110.127.138:53255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X1xXES7Mv0Zfga-kEfQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:03.334343 2026] [security2:error] [pid 1011111:tid 1011243] [client 77.110.127.138:53255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X1xXES7Mv0Zfga-kEfQAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:03.598570 2026] [security2:error] [pid 1011111:tid 1011365] [client 140.245.46.64:55411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismbs.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4X1xXES7Mv0Zfga-kElgAAAQA"]
[Mon Jul 20 06:43:03.691623 2026] [core:error] [pid 1011111:tid 1011306] [client 14.225.17.146:55915] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:43:03.691641 2026] [core:error] [pid 1011111:tid 1011306] [client 14.225.17.146:55915] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:43:03.793206 2026] [security2:error] [pid 1011111:tid 1011364] [client 173.239.240.32:63793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X1xXES7Mv0Zfga-kEqAAAAP8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:03.819074 2026] [security2:error] [pid 1011111:tid 1011242] [client 57.141.18.80:45896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X1RXES7Mv0Zfga-kDsQAAhRk"]
[Mon Jul 20 06:43:03.857104 2026] [security2:error] [pid 1011111:tid 1011310] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X1xXES7Mv0Zfga-kEdwAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:03.981107 2026] [security2:error] [pid 1011111:tid 1011261] [client 57.141.18.106:41006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X1RXES7Mv0Zfga-kDwQAAmBI"]
[Mon Jul 20 06:43:04.013786 2026] [security2:error] [pid 1011111:tid 1011368] [client 187.108.85.186:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X2BXES7Mv0Zfga-kEvgAAAQM"]
[Mon Jul 20 06:43:04.014362 2026] [security2:error] [pid 1011111:tid 1011368] [client 187.108.85.186:63905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X2BXES7Mv0Zfga-kEvgAAAQM"]
[Mon Jul 20 06:43:04.244793 2026] [security2:error] [pid 1011111:tid 1011190] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X2BXES7Mv0Zfga-kE1QAA8E0"]
[Mon Jul 20 06:43:04.244905 2026] [security2:error] [pid 1011111:tid 1011349] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X2BXES7Mv0Zfga-kE1QAA8E0"]
[Mon Jul 20 06:43:04.265941 2026] [security2:error] [pid 1011111:tid 1011342] [client 173.239.240.98:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X2BXES7Mv0Zfga-kE1gAAAOk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:04.270554 2026] [security2:error] [pid 1011111:tid 1011213] [remote 72.167.132.114:53988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4X2BXES7Mv0Zfga-kE1wAAsGQ"]
[Mon Jul 20 06:43:04.349072 2026] [security2:error] [pid 1011111:tid 1011332] [client 82.102.27.163:41676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4X2BXES7Mv0Zfga-kE3wAAAN8"]
[Mon Jul 20 06:43:04.349188 2026] [security2:error] [pid 1011111:tid 1011332] [client 82.102.27.163:41676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4X2BXES7Mv0Zfga-kE3wAAAN8"]
[Mon Jul 20 06:43:04.538830 2026] [security2:error] [pid 1011111:tid 1011240] [remote 72.167.132.114:53988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4X2BXES7Mv0Zfga-kE9QAA4n8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:43:04.671993 2026] [security2:error] [pid 1011111:tid 1011294] [client 104.234.53.58:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4X2BXES7Mv0Zfga-kFAAAAALk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:04.693878 2026] [security2:error] [pid 1011111:tid 1011271] [client 46.110.96.34:21447] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X2BXES7Mv0Zfga-kFCgAAAKI"]
[Mon Jul 20 06:43:04.695458 2026] [security2:error] [pid 1011111:tid 1011342] [client 46.110.96.34:51072] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X2BXES7Mv0Zfga-kFCwAAAOk"]
[Mon Jul 20 06:43:04.722334 2026] [security2:error] [pid 1011111:tid 1011312] [client 46.110.96.34:50952] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X2BXES7Mv0Zfga-kFDQAAAMs"]
[Mon Jul 20 06:43:04.729837 2026] [security2:error] [pid 1011111:tid 1011345] [client 136.144.35.247:21503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X2BXES7Mv0Zfga-kFDgAAAOw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:04.848443 2026] [security2:error] [pid 1011111:tid 1011156] [remote 110.249.202.210:17936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/lc-ms-administration-shills-for-more-african-missionaries-to-be-called-or-terminated-funded-or-defunded-at-the-will-of-the-lc-ms-administration/"] [unique_id "al4X2BXES7Mv0Zfga-kFJAAAhis"]
[Mon Jul 20 06:43:05.081639 2026] [security2:error] [pid 1011111:tid 1011251] [client 103.238.106.162:63635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFNwAAAI4"]
[Mon Jul 20 06:43:05.082205 2026] [security2:error] [pid 1011111:tid 1011251] [client 103.238.106.162:63635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFNwAAAI4"]
[Mon Jul 20 06:43:05.194643 2026] [security2:error] [pid 1011111:tid 1011343] [client 173.239.240.101:30787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X2RXES7Mv0Zfga-kFRwAAAOo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:05.351499 2026] [security2:error] [pid 1011111:tid 1011355] [client 57.141.18.102:57322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X1hXES7Mv0Zfga-kEPwAA9gI"]
[Mon Jul 20 06:43:05.417542 2026] [security2:error] [pid 1011111:tid 1011306] [client 152.58.191.29:59424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFYQAAAMU"]
[Mon Jul 20 06:43:05.418150 2026] [security2:error] [pid 1011111:tid 1011306] [client 152.58.191.29:59424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFYQAAAMU"]
[Mon Jul 20 06:43:05.447790 2026] [security2:error] [pid 1011111:tid 1011342] [client 217.142.18.172:10409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFYgAAAOk"]
[Mon Jul 20 06:43:05.451365 2026] [security2:error] [pid 1011111:tid 1011342] [client 217.142.18.172:10409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFYgAAAOk"]
[Mon Jul 20 06:43:05.554275 2026] [security2:error] [pid 1011111:tid 1011357] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4X2BXES7Mv0Zfga-kFLAAAAPg"]
[Mon Jul 20 06:43:05.669821 2026] [security2:error] [pid 1011111:tid 1011318] [client 173.239.240.32:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X2RXES7Mv0Zfga-kFfgAAANE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:05.912449 2026] [security2:error] [pid 1011111:tid 1011179] [remote 192.241.143.148:54066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFkQAAiUI"]
[Mon Jul 20 06:43:05.912649 2026] [security2:error] [pid 1011111:tid 1011246] [client 192.241.143.148:54066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X2RXES7Mv0Zfga-kFkQAAiUI"]
[Mon Jul 20 06:43:05.954983 2026] [security2:error] [pid 1011111:tid 1011328] [client 104.234.53.76:41741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4X2RXES7Mv0Zfga-kFiAAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:05.965103 2026] [security2:error] [pid 1011111:tid 1011321] [client 46.110.96.34:16603] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X2RXES7Mv0Zfga-kFmQAAANQ"]
[Mon Jul 20 06:43:05.966387 2026] [security2:error] [pid 1011111:tid 1011270] [client 46.110.96.34:63808] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X2RXES7Mv0Zfga-kFmgAAAKE"]
[Mon Jul 20 06:43:06.011732 2026] [security2:error] [pid 1011111:tid 1011315] [client 46.110.96.34:25438] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X2hXES7Mv0Zfga-kFoAAAAM4"]
[Mon Jul 20 06:43:06.130688 2026] [security2:error] [pid 1011111:tid 1011329] [client 173.239.240.102:40321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X2hXES7Mv0Zfga-kFrAAAANw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:06.221990 2026] [security2:error] [pid 1011111:tid 1011351] [client 104.234.53.76:41741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X2hXES7Mv0Zfga-kFtAAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:06.364219 2026] [security2:error] [pid 1011111:tid 1011311] [client 77.110.127.138:53279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X2hXES7Mv0Zfga-kFwQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:06.364331 2026] [security2:error] [pid 1011111:tid 1011311] [client 77.110.127.138:53279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X2hXES7Mv0Zfga-kFwQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:06.582315 2026] [security2:error] [pid 1011111:tid 1011286] [client 136.144.35.246:51509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X2hXES7Mv0Zfga-kF1QAAALE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:06.825651 2026] [security2:error] [pid 1011111:tid 1011292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X2hXES7Mv0Zfga-kF3gAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:07.033419 2026] [security2:error] [pid 1011111:tid 1011355] [client 173.239.240.32:54983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X2xXES7Mv0Zfga-kF-QAAAPY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:07.155988 2026] [security2:error] [pid 1011111:tid 1011328] [client 74.7.227.179:37504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kF_AAA20s"], referer: https://tejasenvironmental.com/p=462237
[Mon Jul 20 06:43:07.329228 2026] [security2:error] [pid 1011111:tid 1011276] [client 14.225.17.146:55240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kF_wAAAKc"], referer: http://samdothan.org/new
[Mon Jul 20 06:43:07.333493 2026] [security2:error] [pid 1011111:tid 1011272] [client 14.225.17.146:61324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4X2RXES7Mv0Zfga-kFeAAAAKM"], referer: http://nwcarvingacademy.com/new
[Mon Jul 20 06:43:07.398006 2026] [security2:error] [pid 1011111:tid 1011358] [client 104.234.53.52:20421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4X2xXES7Mv0Zfga-kGKAAAAPk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:07.507089 2026] [security2:error] [pid 1011111:tid 1011363] [client 173.239.240.32:60463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kGMwAAAP4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:07.643060 2026] [security2:error] [pid 1011111:tid 1011321] [client 180.153.197.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kGJQAA1AM"], referer: https://www.aleishapenny.ca/listing/page/198?view=list&paged=1&posts_per_page=24
[Mon Jul 20 06:43:07.787851 2026] [security2:error] [pid 1011111:tid 1011266] [client 223.185.13.213:13656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X2xXES7Mv0Zfga-kGTQAAAJ0"]
[Mon Jul 20 06:43:07.787991 2026] [security2:error] [pid 1011111:tid 1011266] [client 223.185.13.213:13656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X2xXES7Mv0Zfga-kGTQAAAJ0"]
[Mon Jul 20 06:43:07.974087 2026] [security2:error] [pid 1011111:tid 1011269] [client 173.239.240.93:26733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X2xXES7Mv0Zfga-kGZQAAAKA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:07.979039 2026] [security2:error] [pid 1011111:tid 1011267] [client 14.225.17.146:62394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kGUQAAAJ4"], referer: http://alchemygroup.ca/new
[Mon Jul 20 06:43:08.122574 2026] [security2:error] [pid 1011111:tid 1011346] [client 14.225.17.146:62525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kGZgAAAO0"], referer: http://transparentservices.online/new
[Mon Jul 20 06:43:08.241926 2026] [security2:error] [pid 1011111:tid 1011284] [client 57.141.18.119:37692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X2RXES7Mv0Zfga-kFkgAArxo"]
[Mon Jul 20 06:43:08.334170 2026] [security2:error] [pid 1011111:tid 1011332] [client 37.52.210.45:50936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X3BXES7Mv0Zfga-kGegAAAN8"]
[Mon Jul 20 06:43:08.334265 2026] [security2:error] [pid 1011111:tid 1011332] [client 37.52.210.45:50936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X3BXES7Mv0Zfga-kGegAAAN8"]
[Mon Jul 20 06:43:08.393937 2026] [security2:error] [pid 1011111:tid 1011334] [client 14.225.17.146:52503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4X3BXES7Mv0Zfga-kGbQAAAOE"], referer: https://nwcarvingacademy.com/new
[Mon Jul 20 06:43:08.424147 2026] [security2:error] [pid 1011111:tid 1011272] [client 136.144.35.253:51329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X3BXES7Mv0Zfga-kGfwAAAKM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:08.501442 2026] [security2:error] [pid 1011111:tid 1011326] [client 77.110.127.138:53292] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 76 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X3BXES7Mv0Zfga-kGjgAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:08.724510 2026] [security2:error] [pid 1011111:tid 1011309] [client 213.152.162.79:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4X3BXES7Mv0Zfga-kGqAAAAMg"]
[Mon Jul 20 06:43:08.724633 2026] [security2:error] [pid 1011111:tid 1011309] [client 213.152.162.79:42206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4X3BXES7Mv0Zfga-kGqAAAAMg"]
[Mon Jul 20 06:43:08.793288 2026] [security2:error] [pid 1011111:tid 1011242] [client 18.141.57.241:40190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4X3BXES7Mv0Zfga-kGrAAAAIU"]
[Mon Jul 20 06:43:08.793387 2026] [security2:error] [pid 1011111:tid 1011242] [client 18.141.57.241:40190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4X3BXES7Mv0Zfga-kGrAAAAIU"]
[Mon Jul 20 06:43:08.888480 2026] [security2:error] [pid 1011111:tid 1011255] [client 173.239.240.94:50915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X3BXES7Mv0Zfga-kGsgAAAJI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:09.317623 2026] [security2:error] [pid 1011111:tid 1011260] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4X3RXES7Mv0Zfga-kG0AAAAJc"]
[Mon Jul 20 06:43:09.359287 2026] [security2:error] [pid 1011111:tid 1011337] [client 136.144.35.253:36001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X3RXES7Mv0Zfga-kG3wAAAOQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:09.581481 2026] [security2:error] [pid 1011111:tid 1011259] [client 14.225.17.146:52490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4X3BXES7Mv0Zfga-kGagAAAJY"], referer: http://headachescarpaltunnelfibromyalgia.com/new
[Mon Jul 20 06:43:09.591681 2026] [security2:error] [pid 1011111:tid 1011335] [client 57.141.18.73:26476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kF_gAA4jI"]
[Mon Jul 20 06:43:09.642642 2026] [security2:error] [pid 1011111:tid 1011315] [client 14.251.3.155:54653] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4X3RXES7Mv0Zfga-kG_AAAAM4"]
[Mon Jul 20 06:43:09.808478 2026] [security2:error] [pid 1011111:tid 1011330] [client 14.225.17.146:62267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4X3RXES7Mv0Zfga-kG6gAAAN0"], referer: http://webgardensbypaula.com/new
[Mon Jul 20 06:43:09.827615 2026] [security2:error] [pid 1011111:tid 1011266] [client 173.239.240.101:25261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X3RXES7Mv0Zfga-kHEAAAAJ0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:10.051633 2026] [security2:error] [pid 1011111:tid 1011268] [client 57.141.18.25:63558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kGNgAAn3c"]
[Mon Jul 20 06:43:10.296602 2026] [security2:error] [pid 1011111:tid 1011340] [client 136.144.35.246:46857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X3hXES7Mv0Zfga-kHOQAAAOc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:10.303421 2026] [security2:error] [pid 1011111:tid 1011369] [client 103.125.179.95:63955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X3hXES7Mv0Zfga-kHOgAAAQQ"]
[Mon Jul 20 06:43:10.303564 2026] [security2:error] [pid 1011111:tid 1011369] [client 103.125.179.95:63955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X3hXES7Mv0Zfga-kHOgAAAQQ"]
[Mon Jul 20 06:43:10.323847 2026] [security2:error] [pid 1011111:tid 1011318] [client 77.110.127.138:53310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X3hXES7Mv0Zfga-kHPgAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:10.323968 2026] [security2:error] [pid 1011111:tid 1011318] [client 77.110.127.138:53310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X3hXES7Mv0Zfga-kHPgAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:10.479403 2026] [security2:error] [pid 1011111:tid 1011358] [client 57.141.18.5:33148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X2xXES7Mv0Zfga-kGYAAA-XA"]
[Mon Jul 20 06:43:10.532439 2026] [security2:error] [pid 1011111:tid 1011303] [client 14.225.17.146:61306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4X3RXES7Mv0Zfga-kG9gAAAMI"], referer: http://retzkolonglogistics.com/new
[Mon Jul 20 06:43:10.647304 2026] [security2:error] [pid 1011111:tid 1011276] [client 14.225.17.146:61576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4X3hXES7Mv0Zfga-kHQAAAAKc"]
[Mon Jul 20 06:43:10.706832 2026] [security2:error] [pid 1011111:tid 1011355] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X3hXES7Mv0Zfga-kHSAAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:10.753811 2026] [security2:error] [pid 1011111:tid 1011281] [client 173.239.240.30:35613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X3hXES7Mv0Zfga-kHVgAAAKw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:10.895169 2026] [security2:error] [pid 1011111:tid 1011260] [client 140.245.46.64:58864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4X3hXES7Mv0Zfga-kHaQAAAJc"]
[Mon Jul 20 06:43:11.028856 2026] [security2:error] [pid 1011111:tid 1011363] [client 57.141.18.84:22492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X3BXES7Mv0Zfga-kGmgAA_gU"]
[Mon Jul 20 06:43:11.034624 2026] [security2:error] [pid 1011111:tid 1011352] [client 57.141.18.74:57936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X3BXES7Mv0Zfga-kGpQAA81M"]
[Mon Jul 20 06:43:11.045364 2026] [proxy:error] [pid 1011111:tid 1011316] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:11.045445 2026] [proxy_http:error] [pid 1011111:tid 1011316] [client 34.73.38.214:63164] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:11.046058 2026] [proxy:error] [pid 1011111:tid 1011316] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:11.046086 2026] [proxy_http:error] [pid 1011111:tid 1011316] [client 34.73.38.214:63164] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:11.118828 2026] [security2:error] [pid 1011111:tid 1011343] [client 14.225.17.146:61497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4X3hXES7Mv0Zfga-kHcAAAAOo"], referer: http://fkconstructionfunding.com/new
[Mon Jul 20 06:43:11.197005 2026] [security2:error] [pid 1011111:tid 1011309] [client 158.173.89.95:27577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4X3xXES7Mv0Zfga-kHgQAAAMg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:43:11.263553 2026] [security2:error] [pid 1011111:tid 1011259] [client 46.110.96.34:32748] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X3xXES7Mv0Zfga-kHhQAAAJY"]
[Mon Jul 20 06:43:11.264892 2026] [security2:error] [pid 1011111:tid 1011263] [client 14.225.17.146:62207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4X3xXES7Mv0Zfga-kHdgAAAJo"], referer: http://latiendadejorge.com.gt/new
[Mon Jul 20 06:43:11.305510 2026] [security2:error] [pid 1011111:tid 1011340] [client 136.144.35.244:31145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X3xXES7Mv0Zfga-kHigAAAOc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:11.381917 2026] [security2:error] [pid 1011111:tid 1011256] [client 46.110.96.34:9479] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X3xXES7Mv0Zfga-kHlAAAAJM"]
[Mon Jul 20 06:43:11.469125 2026] [security2:error] [pid 1011111:tid 1011336] [client 192.140.149.97:46249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4X3xXES7Mv0Zfga-kHoAAAAOM"]
[Mon Jul 20 06:43:11.469216 2026] [security2:error] [pid 1011111:tid 1011336] [client 192.140.149.97:46249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4X3xXES7Mv0Zfga-kHoAAAAOM"]
[Mon Jul 20 06:43:11.560210 2026] [security2:error] [pid 1011111:tid 1011319] [client 106.219.188.178:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X3xXES7Mv0Zfga-kHpwAAANI"]
[Mon Jul 20 06:43:11.560325 2026] [security2:error] [pid 1011111:tid 1011319] [client 106.219.188.178:51804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X3xXES7Mv0Zfga-kHpwAAANI"]
[Mon Jul 20 06:43:11.655180 2026] [security2:error] [pid 1011111:tid 1011289] [client 104.234.53.80:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X3xXES7Mv0Zfga-kHrgAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:11.716611 2026] [security2:error] [pid 1011111:tid 1011306] [client 183.82.98.154:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X3xXES7Mv0Zfga-kHsQAAAMU"]
[Mon Jul 20 06:43:11.716704 2026] [security2:error] [pid 1011111:tid 1011306] [client 183.82.98.154:54064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X3xXES7Mv0Zfga-kHsQAAAMU"]
[Mon Jul 20 06:43:11.765225 2026] [security2:error] [pid 1011111:tid 1011369] [client 136.144.35.252:34971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X3xXES7Mv0Zfga-kHsgAAAQQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:11.783302 2026] [security2:error] [pid 1011111:tid 1011290] [client 14.225.17.146:61647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4X3RXES7Mv0Zfga-kG4QAAALU"], referer: http://drewsasburyparkbeachhouse.com/new
[Mon Jul 20 06:43:12.162039 2026] [security2:error] [pid 1011111:tid 1011316] [client 77.110.127.138:53321] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 802 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X4BXES7Mv0Zfga-kHzgAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:12.216106 2026] [security2:error] [pid 1011111:tid 1011245] [client 136.144.35.250:28679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X4BXES7Mv0Zfga-kH1QAAAIg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:12.286319 2026] [security2:error] [pid 1011111:tid 1011366] [client 66.249.70.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4X4BXES7Mv0Zfga-kHyQABAQI"]
[Mon Jul 20 06:43:12.324388 2026] [security2:error] [pid 1011111:tid 1011219] [remote 68.178.160.25:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4X4BXES7Mv0Zfga-kH4gAA1mo"]
[Mon Jul 20 06:43:12.334691 2026] [security2:error] [pid 1011111:tid 1011251] [client 104.234.53.88:57687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4X4BXES7Mv0Zfga-kH5gAAAI4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:12.506056 2026] [security2:error] [pid 1011111:tid 1011301] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X4BXES7Mv0Zfga-kH3wAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:12.524601 2026] [proxy:error] [pid 1011111:tid 1011333] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:12.524666 2026] [proxy_http:error] [pid 1011111:tid 1011333] [client 34.73.38.214:60630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:12.525224 2026] [proxy:error] [pid 1011111:tid 1011333] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:12.525247 2026] [proxy_http:error] [pid 1011111:tid 1011333] [client 34.73.38.214:60630] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:12.583130 2026] [security2:error] [pid 1011111:tid 1011327] [client 112.208.70.94:44424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X4BXES7Mv0Zfga-kH-gAAANo"]
[Mon Jul 20 06:43:12.583247 2026] [security2:error] [pid 1011111:tid 1011327] [client 112.208.70.94:44424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X4BXES7Mv0Zfga-kH-gAAANo"]
[Mon Jul 20 06:43:12.626292 2026] [security2:error] [pid 1011111:tid 1011319] [client 158.173.166.181:24609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4X4BXES7Mv0Zfga-kH_QAAANI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:43:12.681920 2026] [security2:error] [pid 1011111:tid 1011304] [client 57.141.18.85:21018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X3hXES7Mv0Zfga-kHIAAAwwk"]
[Mon Jul 20 06:43:12.685693 2026] [security2:error] [pid 1011111:tid 1011273] [client 140.245.46.64:59763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4X4BXES7Mv0Zfga-kIAgAAAKQ"]
[Mon Jul 20 06:43:12.698214 2026] [security2:error] [pid 1011111:tid 1011256] [client 136.144.35.248:54387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X4BXES7Mv0Zfga-kIBAAAAJM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:12.744938 2026] [security2:error] [pid 1011111:tid 1011159] [remote 68.178.160.25:51372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4X4BXES7Mv0Zfga-kIDQAA8i4"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:43:13.050877 2026] [security2:error] [pid 1011111:tid 1011325] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X4BXES7Mv0Zfga-kIFAAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:13.180924 2026] [security2:error] [pid 1011111:tid 1011366] [client 136.144.35.252:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X4RXES7Mv0Zfga-kIMgAAAQE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:13.261307 2026] [security2:error] [pid 1011111:tid 1011326] [client 140.245.46.64:60076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4X4RXES7Mv0Zfga-kIOwAAANk"]
[Mon Jul 20 06:43:13.487962 2026] [security2:error] [pid 1011111:tid 1011333] [client 104.207.37.5:39625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X4RXES7Mv0Zfga-kITgAAAOA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:13.533855 2026] [proxy:error] [pid 1011111:tid 1011325] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:13.533942 2026] [proxy_http:error] [pid 1011111:tid 1011325] [client 34.73.38.214:64126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:13.534393 2026] [proxy:error] [pid 1011111:tid 1011325] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:13.534423 2026] [proxy_http:error] [pid 1011111:tid 1011325] [client 34.73.38.214:64126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:13.599704 2026] [security2:error] [pid 1011111:tid 1011204] [remote 47.86.33.52:44624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4X4RXES7Mv0Zfga-kIVwAAh1s"]
[Mon Jul 20 06:43:13.635874 2026] [security2:error] [pid 1011111:tid 1011292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X4RXES7Mv0Zfga-kITAAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:13.641496 2026] [security2:error] [pid 1011111:tid 1011250] [client 173.239.240.95:49959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X4RXES7Mv0Zfga-kIWgAAAI0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:13.705472 2026] [security2:error] [pid 1011111:tid 1011334] [client 171.61.165.146:25987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4X4RXES7Mv0Zfga-kIYgAAAOE"]
[Mon Jul 20 06:43:13.706504 2026] [security2:error] [pid 1011111:tid 1011334] [client 171.61.165.146:25987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4X4RXES7Mv0Zfga-kIYgAAAOE"]
[Mon Jul 20 06:43:13.830209 2026] [security2:error] [pid 1011111:tid 1011281] [client 140.245.46.64:60349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4X4RXES7Mv0Zfga-kIbgAAAKw"]
[Mon Jul 20 06:43:14.140304 2026] [security2:error] [pid 1011111:tid 1011325] [client 136.144.35.243:38603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X4hXES7Mv0Zfga-kIiwAAANg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:14.164781 2026] [security2:error] [pid 1011111:tid 1011293] [client 46.110.96.34:10074] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X4hXES7Mv0Zfga-kIkQAAALg"]
[Mon Jul 20 06:43:14.166645 2026] [security2:error] [pid 1011111:tid 1011279] [client 46.110.96.34:18549] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X4hXES7Mv0Zfga-kIkgAAAKo"]
[Mon Jul 20 06:43:14.178411 2026] [security2:error] [pid 1011111:tid 1011269] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X4RXES7Mv0Zfga-kIgAAAAKA"]
[Mon Jul 20 06:43:14.204136 2026] [security2:error] [pid 1011111:tid 1011320] [client 46.110.96.34:36516] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X4hXES7Mv0Zfga-kIlgAAANM"]
[Mon Jul 20 06:43:14.540815 2026] [security2:error] [pid 1011111:tid 1011306] [client 110.249.202.136:28090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.keywayconstructionclt.com"] [uri "/robots.txt"] [unique_id "al4X4hXES7Mv0Zfga-kIsAAAAMU"]
[Mon Jul 20 06:43:14.569742 2026] [security2:error] [pid 1011111:tid 1011333] [client 77.110.127.138:53332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X4hXES7Mv0Zfga-kIsQAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:14.569852 2026] [security2:error] [pid 1011111:tid 1011333] [client 77.110.127.138:53332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X4hXES7Mv0Zfga-kIsQAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:14.608311 2026] [security2:error] [pid 1011111:tid 1011304] [client 173.239.240.92:28671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X4hXES7Mv0Zfga-kItQAAAMM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:14.764217 2026] [security2:error] [pid 1011111:tid 1011353] [client 197.186.66.42:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X4hXES7Mv0Zfga-kIvAAAAPQ"]
[Mon Jul 20 06:43:14.765159 2026] [security2:error] [pid 1011111:tid 1011353] [client 197.186.66.42:57962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X4hXES7Mv0Zfga-kIvAAAAPQ"]
[Mon Jul 20 06:43:14.852010 2026] [security2:error] [pid 1011111:tid 1011317] [client 187.108.85.186:64733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X4hXES7Mv0Zfga-kIvwAAANA"]
[Mon Jul 20 06:43:14.852147 2026] [security2:error] [pid 1011111:tid 1011317] [client 187.108.85.186:64733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X4hXES7Mv0Zfga-kIvwAAANA"]
[Mon Jul 20 06:43:14.875274 2026] [security2:error] [pid 1011111:tid 1011290] [client 14.225.17.146:52392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4X4RXES7Mv0Zfga-kIcgAAALU"], referer: http://claysharecon.com/new
[Mon Jul 20 06:43:14.918458 2026] [security2:error] [pid 1011111:tid 1011202] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X4hXES7Mv0Zfga-kIxQAAslk"]
[Mon Jul 20 06:43:14.918608 2026] [security2:error] [pid 1011111:tid 1011287] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X4hXES7Mv0Zfga-kIxQAAslk"]
[Mon Jul 20 06:43:15.061532 2026] [security2:error] [pid 1011111:tid 1011118] [remote 47.86.33.52:44624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4X4xXES7Mv0Zfga-kI1wAA2wU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:43:15.062212 2026] [security2:error] [pid 1011111:tid 1011334] [client 136.144.35.247:39571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X4xXES7Mv0Zfga-kI2gAAAOE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:15.255887 2026] [security2:error] [pid 1011111:tid 1011186] [remote 113.160.142.119:49800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kI7QAAn0k"]
[Mon Jul 20 06:43:15.256030 2026] [security2:error] [pid 1011111:tid 1011268] [client 113.160.142.119:49800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kI7QAAn0k"]
[Mon Jul 20 06:43:15.324115 2026] [security2:error] [pid 1011111:tid 1011306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X4xXES7Mv0Zfga-kI4AAAAMU"]
[Mon Jul 20 06:43:15.336565 2026] [security2:error] [pid 1011111:tid 1011309] [client 14.225.17.146:55552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4X4xXES7Mv0Zfga-kI5QAAAMg"], referer: http://ivetstrategies.com/new
[Mon Jul 20 06:43:15.410567 2026] [security2:error] [pid 1011111:tid 1011287] [client 77.110.127.138:53341] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 611 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X4xXES7Mv0Zfga-kI9gAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:15.417587 2026] [security2:error] [pid 1011111:tid 1011227] [remote 216.73.216.55:21368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4X4xXES7Mv0Zfga-kI9wAA2nI"]
[Mon Jul 20 06:43:15.478699 2026] [security2:error] [pid 1011111:tid 1011319] [client 34.73.38.214:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.dienerranch.com"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kI_AAAANI"]
[Mon Jul 20 06:43:15.514145 2026] [security2:error] [pid 1011111:tid 1011281] [client 173.239.240.98:36395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X4xXES7Mv0Zfga-kJBAAAAKw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:15.598743 2026] [security2:error] [pid 1011111:tid 1011360] [client 103.238.106.162:60879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kJBwAAAPs"]
[Mon Jul 20 06:43:15.598864 2026] [security2:error] [pid 1011111:tid 1011360] [client 103.238.106.162:60879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kJBwAAAPs"]
[Mon Jul 20 06:43:15.669958 2026] [security2:error] [pid 1011111:tid 1011208] [remote 57.141.18.97:56568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4X4xXES7Mv0Zfga-kJDAAAk18"]
[Mon Jul 20 06:43:15.699266 2026] [security2:error] [pid 1011111:tid 1011301] [client 104.234.53.57:60309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4X4xXES7Mv0Zfga-kJCQAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:15.805744 2026] [security2:error] [pid 1011111:tid 1011340] [client 14.225.17.146:52326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4X4RXES7Mv0Zfga-kIZAAAAOc"], referer: http://jvcmotorsports.com/new
[Mon Jul 20 06:43:15.828711 2026] [security2:error] [pid 1011111:tid 1011333] [client 18.142.226.106:60468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kJGwAAAOA"]
[Mon Jul 20 06:43:15.828833 2026] [security2:error] [pid 1011111:tid 1011333] [client 18.142.226.106:60468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4X4xXES7Mv0Zfga-kJGwAAAOA"]
[Mon Jul 20 06:43:15.963660 2026] [security2:error] [pid 1011111:tid 1011354] [client 136.144.35.249:45087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X4xXES7Mv0Zfga-kJJwAAAPU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:15.995293 2026] [security2:error] [pid 1011111:tid 1011281] [client 34.73.38.214:57600] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4X4xXES7Mv0Zfga-kJKwAAAKw"]
[Mon Jul 20 06:43:16.016641 2026] [security2:error] [pid 1011111:tid 1011292] [client 217.142.18.172:58518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X5BXES7Mv0Zfga-kJLQAAALc"]
[Mon Jul 20 06:43:16.020775 2026] [security2:error] [pid 1011111:tid 1011292] [client 217.142.18.172:58518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X5BXES7Mv0Zfga-kJLQAAALc"]
[Mon Jul 20 06:43:16.106394 2026] [security2:error] [pid 1011111:tid 1011290] [client 14.225.17.146:55389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4X5BXES7Mv0Zfga-kJLwAAALU"], referer: http://ancestralidadytrance.space/new
[Mon Jul 20 06:43:16.451998 2026] [security2:error] [pid 1011111:tid 1011262] [client 136.144.35.254:44553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X5BXES7Mv0Zfga-kJSAAAAJk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:16.807935 2026] [security2:error] [pid 1011111:tid 1011362] [client 104.234.53.57:60309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X5BXES7Mv0Zfga-kJYAAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:16.841190 2026] [security2:error] [pid 1011111:tid 1011357] [client 52.28.162.93:28996] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4X4xXES7Mv0Zfga-kI8wAAAPg"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:43:16.846790 2026] [security2:error] [pid 1011111:tid 1011360] [client 140.245.46.64:61937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-includes/version.php"] [unique_id "al4X5BXES7Mv0Zfga-kJZgAAAPs"]
[Mon Jul 20 06:43:16.917696 2026] [security2:error] [pid 1011111:tid 1011244] [client 136.144.35.249:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X5BXES7Mv0Zfga-kJaAAAAIc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:17.076263 2026] [security2:error] [pid 1011111:tid 1011197] [remote 162.19.86.63:42943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4X5RXES7Mv0Zfga-kJcwAA4VQ"]
[Mon Jul 20 06:43:17.320836 2026] [security2:error] [pid 1011111:tid 1011229] [remote 162.19.86.63:42943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4X5RXES7Mv0Zfga-kJhwAAnHQ"], referer: https://website-5ab144f7.uritems.net/wp-login.php
[Mon Jul 20 06:43:17.377467 2026] [security2:error] [pid 1011111:tid 1011284] [client 173.239.240.32:52197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X5RXES7Mv0Zfga-kJiwAAAK8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:17.394540 2026] [security2:error] [pid 1011111:tid 1011326] [client 57.141.18.19:60114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X4hXES7Mv0Zfga-kIwQAA2Sw"]
[Mon Jul 20 06:43:17.433408 2026] [security2:error] [pid 1011111:tid 1011251] [client 140.245.46.64:62285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-includes/functions.php"] [unique_id "al4X5RXES7Mv0Zfga-kJkgAAAI4"]
[Mon Jul 20 06:43:17.442765 2026] [security2:error] [pid 1011111:tid 1011268] [client 34.73.38.214:63244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4X5RXES7Mv0Zfga-kJlAAAAJ8"]
[Mon Jul 20 06:43:17.774828 2026] [security2:error] [pid 1011111:tid 1011322] [client 50.116.65.227:12430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4X5RXES7Mv0Zfga-kJogAAANU"]
[Mon Jul 20 06:43:17.884088 2026] [security2:error] [pid 1011111:tid 1011291] [client 136.144.35.245:32487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X5RXES7Mv0Zfga-kJswAAALY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:17.953924 2026] [security2:error] [pid 1011111:tid 1011315] [client 50.116.65.227:12436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4X5RXES7Mv0Zfga-kJrQAAAM4"]
[Mon Jul 20 06:43:18.003548 2026] [security2:error] [pid 1011111:tid 1011338] [client 140.245.46.64:62551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4X5hXES7Mv0Zfga-kJvQAAAOU"]
[Mon Jul 20 06:43:18.069726 2026] [security2:error] [pid 1011111:tid 1011242] [client 34.73.38.214:59895] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4X5hXES7Mv0Zfga-kJxAAAAIU"]
[Mon Jul 20 06:43:18.167592 2026] [security2:error] [pid 1011111:tid 1011279] [client 74.208.214.194:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4X5hXES7Mv0Zfga-kJzgAAAKo"]
[Mon Jul 20 06:43:18.279735 2026] [security2:error] [pid 1011111:tid 1011277] [client 223.185.13.213:21993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ0QAAAKg"]
[Mon Jul 20 06:43:18.279859 2026] [security2:error] [pid 1011111:tid 1011277] [client 223.185.13.213:21993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ0QAAAKg"]
[Mon Jul 20 06:43:18.403218 2026] [security2:error] [pid 1011111:tid 1011366] [client 173.239.240.30:54437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ3QAAAQE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:18.545142 2026] [security2:error] [pid 1011111:tid 1011297] [client 14.225.17.146:55713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ2gAAALw"], referer: http://elitetax-mi.com/new
[Mon Jul 20 06:43:18.550222 2026] [security2:error] [pid 1011111:tid 1011309] [client 14.225.17.146:51617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ1gAAAMg"], referer: http://lifeisbetterlakeside.com/new
[Mon Jul 20 06:43:18.574775 2026] [security2:error] [pid 1011111:tid 1011312] [client 140.245.46.64:62869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-includes/option.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ6wAAAMs"]
[Mon Jul 20 06:43:18.592515 2026] [security2:error] [pid 1011111:tid 1011337] [client 14.225.17.146:52215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ5AAAAOQ"]
[Mon Jul 20 06:43:18.744423 2026] [security2:error] [pid 1011111:tid 1011347] [client 57.141.18.54:35232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X5BXES7Mv0Zfga-kJPgAA7mo"]
[Mon Jul 20 06:43:18.792275 2026] [security2:error] [pid 1011111:tid 1011281] [client 77.110.127.138:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ_QAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:18.792389 2026] [security2:error] [pid 1011111:tid 1011281] [client 77.110.127.138:53359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X5hXES7Mv0Zfga-kJ_QAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:18.794829 2026] [security2:error] [pid 1011111:tid 1011334] [client 34.73.38.214:49494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4X5hXES7Mv0Zfga-kJ_gAAAOE"]
[Mon Jul 20 06:43:18.881688 2026] [security2:error] [pid 1011111:tid 1011289] [client 136.144.35.246:32549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X5hXES7Mv0Zfga-kKBgAAALQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:19.063720 2026] [security2:error] [pid 1011111:tid 1011280] [client 37.52.210.45:7694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X5xXES7Mv0Zfga-kKEwAAAKs"]
[Mon Jul 20 06:43:19.063839 2026] [security2:error] [pid 1011111:tid 1011280] [client 37.52.210.45:7694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X5xXES7Mv0Zfga-kKEwAAAKs"]
[Mon Jul 20 06:43:19.160055 2026] [security2:error] [pid 1011111:tid 1011329] [client 140.245.46.64:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-includes/post.php"] [unique_id "al4X5xXES7Mv0Zfga-kKHAAAANw"]
[Mon Jul 20 06:43:19.218006 2026] [security2:error] [pid 1011111:tid 1011120] [remote 98.156.100.191:42364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X5xXES7Mv0Zfga-kKIAAAyQc"]
[Mon Jul 20 06:43:19.364309 2026] [security2:error] [pid 1011111:tid 1011367] [client 173.239.240.99:28025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X5xXES7Mv0Zfga-kKLwAAAQI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:19.503564 2026] [security2:error] [pid 1011111:tid 1011259] [client 152.58.191.29:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X5xXES7Mv0Zfga-kKOAAAAJY"]
[Mon Jul 20 06:43:19.506160 2026] [security2:error] [pid 1011111:tid 1011259] [client 152.58.191.29:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X5xXES7Mv0Zfga-kKOAAAAJY"]
[Mon Jul 20 06:43:19.508233 2026] [security2:error] [pid 1011111:tid 1011343] [client 57.141.18.9:27836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X5BXES7Mv0Zfga-kJbQAA6hA"]
[Mon Jul 20 06:43:19.567195 2026] [security2:error] [pid 1011111:tid 1011309] [client 77.110.127.138:53361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 295 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X5xXES7Mv0Zfga-kKOwAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:19.639127 2026] [security2:error] [pid 1011111:tid 1011161] [remote 154.66.198.148:5934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X5xXES7Mv0Zfga-kKQwAAnTA"]
[Mon Jul 20 06:43:19.698305 2026] [security2:error] [pid 1011111:tid 1011311] [client 34.73.38.214:62185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4X5xXES7Mv0Zfga-kKRwAAAMo"]
[Mon Jul 20 06:43:19.719546 2026] [security2:error] [pid 1011111:tid 1011327] [client 114.119.149.218:58615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.brainwashed.marshallmcluhan.earle-brown.org"] [uri "/robots.txt"] [unique_id "al4X5xXES7Mv0Zfga-kKSwAAANo"], referer: http://www.brainwashed.marshallmcluhan.earle-brown.org/robots.txt
[Mon Jul 20 06:43:19.735240 2026] [security2:error] [pid 1011111:tid 1011275] [client 140.245.46.64:63525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-includes/user.php"] [unique_id "al4X5xXES7Mv0Zfga-kKTgAAAKY"]
[Mon Jul 20 06:43:19.818368 2026] [security2:error] [pid 1011111:tid 1011339] [client 173.239.240.30:57617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X5xXES7Mv0Zfga-kKUwAAAOY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:19.822535 2026] [security2:error] [pid 1011111:tid 1011304] [client 14.225.17.146:61946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4X5xXES7Mv0Zfga-kKTAAAAMM"], referer: http://momheadquarters.com/new
[Mon Jul 20 06:43:19.835946 2026] [security2:error] [pid 1011111:tid 1011305] [client 57.141.18.46:45606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X5RXES7Mv0Zfga-kJggAAxDQ"]
[Mon Jul 20 06:43:19.920508 2026] [security2:error] [pid 1011111:tid 1011288] [client 14.225.17.146:61900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4X5xXES7Mv0Zfga-kKPwAAALM"], referer: http://adastra.love/new
[Mon Jul 20 06:43:19.949345 2026] [security2:error] [pid 1011111:tid 1011123] [remote 98.156.100.191:42364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X5xXES7Mv0Zfga-kKXQABAgo"], referer: https://str.cly.mybluehost.me/wp-login.php
[Mon Jul 20 06:43:20.176932 2026] [security2:error] [pid 1011111:tid 1011139] [remote 154.66.198.148:5934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X6BXES7Mv0Zfga-kKbQAAuBo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:43:20.266297 2026] [security2:error] [pid 1011111:tid 1011315] [client 136.144.35.247:58203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X6BXES7Mv0Zfga-kKcQAAAM4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:20.347268 2026] [security2:error] [pid 1011111:tid 1011256] [client 34.73.38.214:61672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4X6BXES7Mv0Zfga-kKdgAAAJM"]
[Mon Jul 20 06:43:20.455490 2026] [security2:error] [pid 1011111:tid 1011353] [client 57.141.18.100:23234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X5RXES7Mv0Zfga-kJrAAA9Gw"]
[Mon Jul 20 06:43:20.498055 2026] [security2:error] [pid 1011111:tid 1011351] [client 14.225.17.146:51443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4X6BXES7Mv0Zfga-kKZQAAAPI"], referer: http://partnerselectricalllc.com/new
[Mon Jul 20 06:43:20.715917 2026] [security2:error] [pid 1011111:tid 1011302] [client 173.239.240.30:26197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X6BXES7Mv0Zfga-kKmQAAAME"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:21.049101 2026] [security2:error] [pid 1011111:tid 1011305] [client 66.249.82.230:63370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "juniper3medical.com"] [uri "/index.php"] [unique_id "al4X6BXES7Mv0Zfga-kKigAAAMQ"]
[Mon Jul 20 06:43:21.068530 2026] [security2:error] [pid 1011111:tid 1011178] [remote 202.51.202.242:41248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4X6RXES7Mv0Zfga-kKvwAAzUE"]
[Mon Jul 20 06:43:21.103666 2026] [security2:error] [pid 1011111:tid 1011359] [client 103.125.179.95:64635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X6RXES7Mv0Zfga-kKwgAAAPo"]
[Mon Jul 20 06:43:21.104429 2026] [security2:error] [pid 1011111:tid 1011359] [client 103.125.179.95:64635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X6RXES7Mv0Zfga-kKwgAAAPo"]
[Mon Jul 20 06:43:21.164506 2026] [security2:error] [pid 1011111:tid 1011259] [client 173.239.240.32:43475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X6RXES7Mv0Zfga-kKxgAAAJY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:21.359432 2026] [security2:error] [pid 1011111:tid 1011261] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4X6RXES7Mv0Zfga-kKwAAAAJg"]
[Mon Jul 20 06:43:21.444508 2026] [security2:error] [pid 1011111:tid 1011255] [client 14.225.17.146:51848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "solkeetw.com"] [uri "/index.php"] [unique_id "al4X6RXES7Mv0Zfga-kK2QAAAJI"], referer: http://solkeetw.com/new
[Mon Jul 20 06:43:21.480613 2026] [security2:error] [pid 1011111:tid 1011363] [client 104.234.53.69:62109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4X6RXES7Mv0Zfga-kK4QAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:21.617568 2026] [security2:error] [pid 1011111:tid 1011298] [client 173.239.240.95:60027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X6RXES7Mv0Zfga-kK8wAAAL0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:21.720384 2026] [security2:error] [pid 1011111:tid 1011353] [client 127.0.0.1:24894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4X6RXES7Mv0Zfga-kLAQAAAPQ"], referer: https://www.reddit.com/
[Mon Jul 20 06:43:21.753355 2026] [security2:error] [pid 1011111:tid 1011312] [client 34.73.38.214:57831] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4X6RXES7Mv0Zfga-kLBgAAAMs"]
[Mon Jul 20 06:43:21.860753 2026] [security2:error] [pid 1011111:tid 1011276] [client 157.34.84.63:63064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.84.34.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/xmlrpc.php"] [unique_id "al4X6RXES7Mv0Zfga-kLDQAAAKc"]
[Mon Jul 20 06:43:21.860854 2026] [security2:error] [pid 1011111:tid 1011276] [client 157.34.84.63:63064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "bbwipartnerconference.com"] [uri "/xmlrpc.php"] [unique_id "al4X6RXES7Mv0Zfga-kLDQAAAKc"]
[Mon Jul 20 06:43:22.067171 2026] [security2:error] [pid 1011111:tid 1011254] [client 136.144.35.245:30275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLHwAAAJE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:22.529135 2026] [security2:error] [pid 1011111:tid 1011276] [client 136.144.35.250:42243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X6hXES7Mv0Zfga-kLTgAAAKc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:22.530930 2026] [security2:error] [pid 1011111:tid 1011263] [client 14.225.17.146:61912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4X6BXES7Mv0Zfga-kKiQAAAJo"], referer: http://itdynamix.com/new
[Mon Jul 20 06:43:22.561592 2026] [security2:error] [pid 1011111:tid 1011203] [remote 81.173.115.7:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4X6hXES7Mv0Zfga-kLUAAAl1o"]
[Mon Jul 20 06:43:22.647105 2026] [security2:error] [pid 1011111:tid 1011287] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLTQAAALI"]
[Mon Jul 20 06:43:22.715547 2026] [security2:error] [pid 1011111:tid 1011323] [client 77.110.127.138:53381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X6hXES7Mv0Zfga-kLWwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:22.715647 2026] [security2:error] [pid 1011111:tid 1011323] [client 77.110.127.138:53381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X6hXES7Mv0Zfga-kLWwAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:22.753555 2026] [security2:error] [pid 1011111:tid 1011328] [client 183.82.98.154:54641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X6hXES7Mv0Zfga-kLZQAAANs"]
[Mon Jul 20 06:43:22.753572 2026] [security2:error] [pid 1011111:tid 1011224] [remote 81.173.115.7:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4X6hXES7Mv0Zfga-kLZAAAtm8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:43:22.753650 2026] [security2:error] [pid 1011111:tid 1011328] [client 183.82.98.154:54641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X6hXES7Mv0Zfga-kLZQAAANs"]
[Mon Jul 20 06:43:22.842794 2026] [security2:error] [pid 1011111:tid 1011297] [client 154.27.104.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLWgAAALw"]
[Mon Jul 20 06:43:22.849471 2026] [security2:error] [pid 1011111:tid 1011206] [remote 202.51.202.242:41248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4X6hXES7Mv0Zfga-kLbAAArF0"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 06:43:22.878688 2026] [security2:error] [pid 1011111:tid 1011129] [remote 152.42.137.70:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4X6hXES7Mv0Zfga-kLbgAA6hA"]
[Mon Jul 20 06:43:23.000041 2026] [security2:error] [pid 1011111:tid 1011356] [client 173.239.240.97:57811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLewAAAPc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:23.046884 2026] [security2:error] [pid 1011111:tid 1011161] [remote 152.42.137.70:55868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.137.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/wp-login.php"] [unique_id "al4X6xXES7Mv0Zfga-kLfwAAtzA"], referer: https://muafaces.org/wp-login.php
[Mon Jul 20 06:43:23.191059 2026] [security2:error] [pid 1011111:tid 1011275] [client 112.208.70.94:44869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X6xXES7Mv0Zfga-kLjQAAAKY"]
[Mon Jul 20 06:43:23.191167 2026] [security2:error] [pid 1011111:tid 1011275] [client 112.208.70.94:44869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X6xXES7Mv0Zfga-kLjQAAAKY"]
[Mon Jul 20 06:43:23.341605 2026] [security2:error] [pid 1011111:tid 1011290] [client 77.110.127.138:53384] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 553 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X6xXES7Mv0Zfga-kLnQAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:23.446701 2026] [security2:error] [pid 1011111:tid 1011358] [client 104.234.53.69:62109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X6xXES7Mv0Zfga-kLqAAAAPk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:23.493568 2026] [security2:error] [pid 1011111:tid 1011307] [client 173.239.240.92:31827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X6xXES7Mv0Zfga-kLrAAAAMY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:23.502237 2026] [security2:error] [pid 1011111:tid 1011355] [client 14.225.17.146:52026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4X6xXES7Mv0Zfga-kLoAAAAPY"], referer: https://itdynamix.com/new
[Mon Jul 20 06:43:23.704777 2026] [security2:error] [pid 1011111:tid 1011291] [client 45.3.41.7:10147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X6xXES7Mv0Zfga-kLuwAAALY"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:23.765295 2026] [security2:error] [pid 1011111:tid 1011310] [client 122.183.32.225:32870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X6xXES7Mv0Zfga-kLxwAAAMk"]
[Mon Jul 20 06:43:23.765449 2026] [security2:error] [pid 1011111:tid 1011310] [client 122.183.32.225:32870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X6xXES7Mv0Zfga-kLxwAAAMk"]
[Mon Jul 20 06:43:23.919026 2026] [security2:error] [pid 1011111:tid 1011357] [client 57.141.18.2:30934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X6BXES7Mv0Zfga-kKlQAA-CM"]
[Mon Jul 20 06:43:23.950577 2026] [security2:error] [pid 1011111:tid 1011269] [client 136.144.35.243:51951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X6xXES7Mv0Zfga-kL5AAAAKA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:24.126003 2026] [security2:error] [pid 1011111:tid 1011337] [client 14.225.17.146:51816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4X6xXES7Mv0Zfga-kL5QAAAOQ"], referer: http://xp-design.co/new
[Mon Jul 20 06:43:24.146573 2026] [security2:error] [pid 1011111:tid 1011326] [client 50.116.65.227:55786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4X6xXES7Mv0Zfga-kLugAAANk"]
[Mon Jul 20 06:43:24.270811 2026] [security2:error] [pid 1011111:tid 1011276] [client 157.55.39.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4X6xXES7Mv0Zfga-kL3gAAAKc"]
[Mon Jul 20 06:43:24.442120 2026] [security2:error] [pid 1011111:tid 1011266] [client 136.144.35.247:54939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X7BXES7Mv0Zfga-kMEgAAAJ0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:24.444918 2026] [security2:error] [pid 1011111:tid 1011356] [client 104.234.53.82:54139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4X7BXES7Mv0Zfga-kMFAAAAPc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:24.550229 2026] [security2:error] [pid 1011111:tid 1011300] [client 45.3.44.249:46201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4X7BXES7Mv0Zfga-kMGgAAAL8"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:43:24.604122 2026] [security2:error] [pid 1011111:tid 1011325] [client 171.61.165.146:22474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4X7BXES7Mv0Zfga-kMHgAAANg"]
[Mon Jul 20 06:43:24.604254 2026] [security2:error] [pid 1011111:tid 1011325] [client 171.61.165.146:22474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4X7BXES7Mv0Zfga-kMHgAAANg"]
[Mon Jul 20 06:43:24.628588 2026] [security2:error] [pid 1011111:tid 1011360] [client 14.225.17.146:51758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4X6xXES7Mv0Zfga-kLlQAAAPs"], referer: http://cloudspacesgroup.com/new
[Mon Jul 20 06:43:24.647722 2026] [security2:error] [pid 1011111:tid 1011268] [client 50.116.65.227:55818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4X7BXES7Mv0Zfga-kL9AAAAJ8"]
[Mon Jul 20 06:43:24.650094 2026] [security2:error] [pid 1011111:tid 1011297] [client 34.73.38.214:57058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4X7BXES7Mv0Zfga-kMJgAAALw"]
[Mon Jul 20 06:43:24.650180 2026] [security2:error] [pid 1011111:tid 1011267] [client 14.225.17.146:64201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLdwAAAJ4"], referer: http://margaretspeckogawa.com/new
[Mon Jul 20 06:43:24.895799 2026] [security2:error] [pid 1011111:tid 1011189] [remote 188.166.241.141:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4X7BXES7Mv0Zfga-kMNQABAkw"]
[Mon Jul 20 06:43:24.901336 2026] [security2:error] [pid 1011111:tid 1011281] [client 136.144.35.249:33019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X7BXES7Mv0Zfga-kMNwAAAKw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:24.923220 2026] [security2:error] [pid 1011111:tid 1011310] [client 34.139.11.221:50930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.frontecinc.com"] [uri "/xmlrpc.php"] [unique_id "al4X7BXES7Mv0Zfga-kMOgAAAMk"]
[Mon Jul 20 06:43:25.043564 2026] [security2:error] [pid 1011111:tid 1011339] [client 34.139.11.221:60238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMRwAAAOY"]
[Mon Jul 20 06:43:25.044862 2026] [security2:error] [pid 1011111:tid 1011292] [client 14.182.195.220:52312] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4X7RXES7Mv0Zfga-kMSAAAALc"]
[Mon Jul 20 06:43:25.062936 2026] [security2:error] [pid 1011111:tid 1011273] [client 14.224.227.113:54655] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4X7RXES7Mv0Zfga-kMSQAAAKQ"]
[Mon Jul 20 06:43:25.145776 2026] [security2:error] [pid 1011111:tid 1011337] [client 45.3.45.9:25929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4X7RXES7Mv0Zfga-kMUgAAAOQ"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:43:25.171075 2026] [security2:error] [pid 1011111:tid 1011305] [client 57.141.18.90:47534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLIgAAxDY"]
[Mon Jul 20 06:43:25.203140 2026] [security2:error] [pid 1011111:tid 1011368] [client 34.139.11.221:57657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMXwAAAQM"]
[Mon Jul 20 06:43:25.286281 2026] [security2:error] [pid 1011111:tid 1011245] [client 34.73.38.214:50475] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMZAAAAIg"]
[Mon Jul 20 06:43:25.297694 2026] [security2:error] [pid 1011111:tid 1011212] [remote 188.166.241.141:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4X7RXES7Mv0Zfga-kMZwAA7mM"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:43:25.341328 2026] [security2:error] [pid 1011111:tid 1011340] [client 34.139.11.221:51484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMbwAAAOc"]
[Mon Jul 20 06:43:25.370344 2026] [security2:error] [pid 1011111:tid 1011343] [client 173.239.240.100:49181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X7RXES7Mv0Zfga-kMcwAAAOo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:25.372756 2026] [security2:error] [pid 1011111:tid 1011354] [client 187.108.85.186:65363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X7RXES7Mv0Zfga-kMdQAAAPU"]
[Mon Jul 20 06:43:25.372887 2026] [security2:error] [pid 1011111:tid 1011354] [client 187.108.85.186:65363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X7RXES7Mv0Zfga-kMdQAAAPU"]
[Mon Jul 20 06:43:25.524329 2026] [security2:error] [pid 1011111:tid 1011236] [remote 57.141.18.52:46720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4070696"] [unique_id "al4X7RXES7Mv0Zfga-kMhAAA1ns"]
[Mon Jul 20 06:43:25.530283 2026] [security2:error] [pid 1011111:tid 1011307] [client 34.139.11.221:61996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMhQAAAMY"]
[Mon Jul 20 06:43:25.647883 2026] [security2:error] [pid 1011111:tid 1011274] [client 98.159.234.160:25371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4X7RXES7Mv0Zfga-kMjQAAAKU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:43:25.658134 2026] [security2:error] [pid 1011111:tid 1011134] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X7RXES7Mv0Zfga-kMjgAA1BU"]
[Mon Jul 20 06:43:25.658261 2026] [security2:error] [pid 1011111:tid 1011321] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X7RXES7Mv0Zfga-kMjgAA1BU"]
[Mon Jul 20 06:43:25.664337 2026] [security2:error] [pid 1011111:tid 1011244] [client 34.139.11.221:64810] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMkAAAAIc"]
[Mon Jul 20 06:43:25.741483 2026] [security2:error] [pid 1011111:tid 1011338] [client 45.3.45.126:33335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4X7RXES7Mv0Zfga-kMkwAAAOU"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:43:25.768040 2026] [security2:error] [pid 1011111:tid 1011268] [client 14.225.17.146:51650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4X7RXES7Mv0Zfga-kMjwAAAJ8"], referer: http://mourgroup.com/new
[Mon Jul 20 06:43:25.807190 2026] [security2:error] [pid 1011111:tid 1011297] [client 34.139.11.221:60850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMmAAAALw"]
[Mon Jul 20 06:43:25.809436 2026] [security2:error] [pid 1011111:tid 1011345] [client 57.141.18.20:20964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X6hXES7Mv0Zfga-kLUQAA7AQ"]
[Mon Jul 20 06:43:25.824981 2026] [security2:error] [pid 1011111:tid 1011276] [client 173.239.240.101:42365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X7RXES7Mv0Zfga-kMmwAAAKc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:25.986659 2026] [security2:error] [pid 1011111:tid 1011307] [client 34.139.11.221:54178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4X7RXES7Mv0Zfga-kMqQAAAMY"]
[Mon Jul 20 06:43:26.029262 2026] [security2:error] [pid 1011111:tid 1011366] [client 152.58.191.29:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMsgAAAQE"]
[Mon Jul 20 06:43:26.029867 2026] [security2:error] [pid 1011111:tid 1011366] [client 152.58.191.29:60259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMsgAAAQE"]
[Mon Jul 20 06:43:26.096250 2026] [security2:error] [pid 1011111:tid 1011315] [client 103.238.106.162:42791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMtgAAAM4"]
[Mon Jul 20 06:43:26.096383 2026] [security2:error] [pid 1011111:tid 1011315] [client 103.238.106.162:42791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMtgAAAM4"]
[Mon Jul 20 06:43:26.097392 2026] [security2:error] [pid 1011111:tid 1011250] [client 223.237.130.40:59569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.130.237.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMtQAAAI0"]
[Mon Jul 20 06:43:26.097458 2026] [security2:error] [pid 1011111:tid 1011250] [client 223.237.130.40:59569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMtQAAAI0"]
[Mon Jul 20 06:43:26.187474 2026] [security2:error] [pid 1011111:tid 1011244] [client 34.139.11.221:64308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4X7hXES7Mv0Zfga-kMugAAAIc"]
[Mon Jul 20 06:43:26.322892 2026] [security2:error] [pid 1011111:tid 1011268] [client 34.139.11.221:49175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4X7hXES7Mv0Zfga-kMwgAAAJ8"]
[Mon Jul 20 06:43:26.328674 2026] [security2:error] [pid 1011111:tid 1011247] [client 106.219.188.178:25750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMwwAAAIo"]
[Mon Jul 20 06:43:26.338174 2026] [security2:error] [pid 1011111:tid 1011247] [client 106.219.188.178:25750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kMwwAAAIo"]
[Mon Jul 20 06:43:26.428554 2026] [security2:error] [pid 1011111:tid 1011286] [client 34.73.38.214:65289] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4X7hXES7Mv0Zfga-kM0QAAALE"]
[Mon Jul 20 06:43:26.435176 2026] [security2:error] [pid 1011111:tid 1011331] [client 104.234.53.74:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X7hXES7Mv0Zfga-kM0AAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:26.484533 2026] [security2:error] [pid 1011111:tid 1011281] [client 34.139.11.221:59575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4X7hXES7Mv0Zfga-kM2gAAAKw"]
[Mon Jul 20 06:43:26.541672 2026] [security2:error] [pid 1011111:tid 1011284] [client 217.142.18.172:55942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kM4QAAAK8"]
[Mon Jul 20 06:43:26.541802 2026] [security2:error] [pid 1011111:tid 1011284] [client 217.142.18.172:55942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X7hXES7Mv0Zfga-kM4QAAAK8"]
[Mon Jul 20 06:43:26.612459 2026] [security2:error] [pid 1011111:tid 1011298] [client 34.139.11.221:53840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.frontecinc.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4X7hXES7Mv0Zfga-kM5QAAAL0"]
[Mon Jul 20 06:43:26.659882 2026] [security2:error] [pid 1011111:tid 1011242] [client 77.110.127.138:53400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X7hXES7Mv0Zfga-kM6AAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:26.659956 2026] [security2:error] [pid 1011111:tid 1011242] [client 77.110.127.138:53400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X7hXES7Mv0Zfga-kM6AAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:27.048492 2026] [security2:error] [pid 1011111:tid 1011323] [client 213.152.162.79:32880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.162.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4X7xXES7Mv0Zfga-kNDAAAANY"]
[Mon Jul 20 06:43:27.048590 2026] [security2:error] [pid 1011111:tid 1011323] [client 213.152.162.79:32880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4X7xXES7Mv0Zfga-kNDAAAANY"]
[Mon Jul 20 06:43:27.153176 2026] [security2:error] [pid 1011111:tid 1011320] [client 45.157.112.60:56523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4X7xXES7Mv0Zfga-kNFQAAANM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:43:27.302330 2026] [security2:error] [pid 1011111:tid 1011280] [client 50.116.65.227:55854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4X7xXES7Mv0Zfga-kNIAAAAKs"]
[Mon Jul 20 06:43:27.311876 2026] [security2:error] [pid 1011111:tid 1011286] [client 50.116.65.227:55868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4X7xXES7Mv0Zfga-kNIQAAALE"]
[Mon Jul 20 06:43:27.333042 2026] [security2:error] [pid 1011111:tid 1011353] [client 57.141.18.11:38692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X7BXES7Mv0Zfga-kL6wAA9Aw"]
[Mon Jul 20 06:43:27.592566 2026] [security2:error] [pid 1011111:tid 1011242] [client 77.110.127.138:53404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 750 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X7xXES7Mv0Zfga-kNRgAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:27.737836 2026] [security2:error] [pid 1011111:tid 1011310] [client 197.186.66.42:58516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X7xXES7Mv0Zfga-kNTwAAAMk"]
[Mon Jul 20 06:43:27.737942 2026] [security2:error] [pid 1011111:tid 1011310] [client 197.186.66.42:58516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X7xXES7Mv0Zfga-kNTwAAAMk"]
[Mon Jul 20 06:43:27.786536 2026] [security2:error] [pid 1011111:tid 1011281] [client 34.73.38.214:50941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4X7xXES7Mv0Zfga-kNWAAAAKw"]
[Mon Jul 20 06:43:27.999381 2026] [security2:error] [pid 1011111:tid 1011342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X7xXES7Mv0Zfga-kNVQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:28.247280 2026] [security2:error] [pid 1011111:tid 1011336] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4X8BXES7Mv0Zfga-kNdQAAAOM"]
[Mon Jul 20 06:43:28.696007 2026] [security2:error] [pid 1011111:tid 1011343] [client 34.73.38.214:64768] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.dienerranch.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4X8BXES7Mv0Zfga-kNuwAAAOo"]
[Mon Jul 20 06:43:28.977592 2026] [security2:error] [pid 1011111:tid 1011280] [client 14.225.17.146:62030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4X8BXES7Mv0Zfga-kNwAAAAKs"], referer: http://narv.co/new
[Mon Jul 20 06:43:29.071011 2026] [security2:error] [pid 1011111:tid 1011224] [remote 4.205.168.44:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4X8RXES7Mv0Zfga-kN3wAA128"]
[Mon Jul 20 06:43:29.175017 2026] [security2:error] [pid 1011111:tid 1011120] [remote 111.225.148.111:48242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/the-king-of-kings-is-speaking-so-be-good-prov-25-psalm-2/"] [unique_id "al4X8RXES7Mv0Zfga-kN7AABAwc"]
[Mon Jul 20 06:43:29.258642 2026] [security2:error] [pid 1011111:tid 1011270] [client 57.141.18.87:22772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X7RXES7Mv0Zfga-kMiQAAoSU"]
[Mon Jul 20 06:43:29.260146 2026] [security2:error] [pid 1011111:tid 1011228] [remote 4.205.168.44:33790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4X8RXES7Mv0Zfga-kN-wAA-nM"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 06:43:29.305693 2026] [security2:error] [pid 1011111:tid 1011330] [client 39.48.81.23:50294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X8RXES7Mv0Zfga-kOAgAAAN0"]
[Mon Jul 20 06:43:29.305843 2026] [security2:error] [pid 1011111:tid 1011330] [client 39.48.81.23:50294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X8RXES7Mv0Zfga-kOAgAAAN0"]
[Mon Jul 20 06:43:29.416640 2026] [security2:error] [pid 1011111:tid 1011230] [remote 152.228.213.32:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4X8RXES7Mv0Zfga-kODgAA_3U"]
[Mon Jul 20 06:43:29.478353 2026] [security2:error] [pid 1011111:tid 1011246] [client 140.245.46.64:51863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.genesismedicalbilling.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4X8RXES7Mv0Zfga-kOFAAAAIk"]
[Mon Jul 20 06:43:29.621834 2026] [ssl:error] [pid 1011111:tid 1011255] [client 104.48.69.105:38082] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:43:29.625762 2026] [security2:error] [pid 1011111:tid 1011133] [remote 152.228.213.32:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4X8RXES7Mv0Zfga-kOHgAA5BQ"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:43:29.718718 2026] [security2:error] [pid 1011111:tid 1011367] [client 14.225.17.146:62084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4X7xXES7Mv0Zfga-kNHQAAAQI"], referer: http://gearwaterproof.com/new
[Mon Jul 20 06:43:29.722164 2026] [security2:error] [pid 1011111:tid 1011298] [client 37.52.210.45:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X8RXES7Mv0Zfga-kOMQAAAL0"]
[Mon Jul 20 06:43:29.722271 2026] [security2:error] [pid 1011111:tid 1011298] [client 37.52.210.45:9615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X8RXES7Mv0Zfga-kOMQAAAL0"]
[Mon Jul 20 06:43:29.808354 2026] [security2:error] [pid 1011111:tid 1011115] [remote 173.249.4.11:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4X8RXES7Mv0Zfga-kOOgAAwAI"]
[Mon Jul 20 06:43:29.904373 2026] [security2:error] [pid 1011111:tid 1011347] [client 223.185.13.213:16057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X8RXES7Mv0Zfga-kOPgAAAO4"]
[Mon Jul 20 06:43:29.904501 2026] [security2:error] [pid 1011111:tid 1011347] [client 223.185.13.213:16057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X8RXES7Mv0Zfga-kOPgAAAO4"]
[Mon Jul 20 06:43:29.912416 2026] [security2:error] [pid 1011111:tid 1011328] [client 173.239.240.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "giftsurprizo.com"] [uri "/index.php"] [unique_id "al4X8RXES7Mv0Zfga-kOMgAAANs"]
[Mon Jul 20 06:43:29.968012 2026] [security2:error] [pid 1011111:tid 1011242] [client 14.225.17.146:52036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4X8RXES7Mv0Zfga-kOOQAAAIU"], referer: https://narv.co/new
[Mon Jul 20 06:43:30.472364 2026] [security2:error] [pid 1011111:tid 1011346] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4X8hXES7Mv0Zfga-kOZAAAAO0"]
[Mon Jul 20 06:43:30.642356 2026] [security2:error] [pid 1011111:tid 1011335] [client 104.234.53.93:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4X8hXES7Mv0Zfga-kOhwAAAOI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:30.727165 2026] [security2:error] [pid 1011111:tid 1011265] [client 52.187.75.220:7873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4X8hXES7Mv0Zfga-kOlgAAAJw"]
[Mon Jul 20 06:43:30.839218 2026] [security2:error] [pid 1011111:tid 1011209] [remote 173.249.4.11:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4X8hXES7Mv0Zfga-kOqQAA9WA"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 06:43:30.893648 2026] [security2:error] [pid 1011111:tid 1011212] [remote 81.173.115.7:56066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X8hXES7Mv0Zfga-kOrAAAwGM"]
[Mon Jul 20 06:43:30.893830 2026] [security2:error] [pid 1011111:tid 1011301] [client 81.173.115.7:56066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X8hXES7Mv0Zfga-kOrAAAwGM"]
[Mon Jul 20 06:43:30.915838 2026] [security2:error] [pid 1011111:tid 1011260] [client 52.187.75.220:7873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4X8hXES7Mv0Zfga-kOrgAAAJc"]
[Mon Jul 20 06:43:30.937013 2026] [security2:error] [pid 1011111:tid 1011237] [remote 188.40.28.4:45516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4X8hXES7Mv0Zfga-kOsQAA9Hw"]
[Mon Jul 20 06:43:30.946381 2026] [core:error] [pid 1011111:tid 1011257] [client 14.225.17.146:57359] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/new
[Mon Jul 20 06:43:30.946397 2026] [core:error] [pid 1011111:tid 1011257] [client 14.225.17.146:57359] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/new
[Mon Jul 20 06:43:31.109040 2026] [lsapi:warn] [pid 1011111:tid 1011316] [client 14.225.17.146:51019] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/new
[Mon Jul 20 06:43:31.109066 2026] [lsapi:warn] [pid 1011111:tid 1011316] [client 14.225.17.146:51019] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/new
[Mon Jul 20 06:43:31.125260 2026] [security2:error] [pid 1011111:tid 1011205] [remote 188.40.28.4:45516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kOwAAAoVw"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 06:43:31.209107 2026] [security2:error] [pid 1011111:tid 1011276] [client 57.141.18.88:33468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X7xXES7Mv0Zfga-kNJwAApys"]
[Mon Jul 20 06:43:31.284730 2026] [security2:error] [pid 1011111:tid 1011200] [remote 100.42.189.89:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kO1AAA21c"]
[Mon Jul 20 06:43:31.297372 2026] [security2:error] [pid 1011111:tid 1011353] [client 77.110.127.138:53419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X8xXES7Mv0Zfga-kO1gAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:31.297492 2026] [security2:error] [pid 1011111:tid 1011353] [client 77.110.127.138:53419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X8xXES7Mv0Zfga-kO1gAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:31.367328 2026] [security2:error] [pid 1011111:tid 1011302] [client 223.237.130.40:60060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.130.237.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4X8xXES7Mv0Zfga-kO2QAAAME"]
[Mon Jul 20 06:43:31.367434 2026] [security2:error] [pid 1011111:tid 1011302] [client 223.237.130.40:60060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4X8xXES7Mv0Zfga-kO2QAAAME"]
[Mon Jul 20 06:43:31.409873 2026] [security2:error] [pid 1011111:tid 1011343] [client 138.68.157.105:51736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.techtradeinc.com"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kO3AAAAOo"]
[Mon Jul 20 06:43:31.537506 2026] [security2:error] [pid 1011111:tid 1011250] [client 14.225.17.146:57432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4X8xXES7Mv0Zfga-kO2gAAAI0"], referer: http://thesoloceos.com/new
[Mon Jul 20 06:43:31.579052 2026] [security2:error] [pid 1011111:tid 1011146] [remote 80.82.65.226:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X8xXES7Mv0Zfga-kO6gAAhiE"]
[Mon Jul 20 06:43:31.590817 2026] [lsapi:warn] [pid 1011111:tid 1011297] [client 50.116.65.227:41322] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:43:31.590841 2026] [lsapi:warn] [pid 1011111:tid 1011297] [client 50.116.65.227:41322] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:43:31.604261 2026] [security2:error] [pid 1011111:tid 1011316] [client 14.225.17.146:51019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4X8hXES7Mv0Zfga-kOhAAAAM8"], referer: http://oswegooperatheater.com/new
[Mon Jul 20 06:43:31.710143 2026] [security2:error] [pid 1011111:tid 1011188] [remote 117.0.21.154:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kO-gAAh0s"]
[Mon Jul 20 06:43:31.789264 2026] [security2:error] [pid 1011111:tid 1011247] [client 103.125.179.95:65147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X8xXES7Mv0Zfga-kPCgAAAIo"]
[Mon Jul 20 06:43:31.789371 2026] [security2:error] [pid 1011111:tid 1011247] [client 103.125.179.95:65147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X8xXES7Mv0Zfga-kPCgAAAIo"]
[Mon Jul 20 06:43:31.862009 2026] [security2:error] [pid 1011111:tid 1011302] [client 74.208.214.194:54140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4X8xXES7Mv0Zfga-kPDwAAAME"]
[Mon Jul 20 06:43:31.883697 2026] [security2:error] [pid 1011111:tid 1011126] [remote 128.199.71.102:51132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.71.199.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kPDgAA-A0"]
[Mon Jul 20 06:43:31.901820 2026] [security2:error] [pid 1011111:tid 1011272] [client 77.110.127.138:53422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X8xXES7Mv0Zfga-kPEgAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:31.931498 2026] [security2:error] [pid 1011111:tid 1011161] [remote 100.42.189.89:59070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kPFgAAiDA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:43:31.965918 2026] [security2:error] [pid 1011111:tid 1011310] [client 57.141.18.59:49356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X8BXES7Mv0Zfga-kNeAAAyVU"]
[Mon Jul 20 06:43:31.983947 2026] [security2:error] [pid 1011111:tid 1011323] [client 138.68.157.105:51854] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.techtradeinc.com"] [uri "/wp-login.php"] [unique_id "al4X8xXES7Mv0Zfga-kPHgAAANY"]
[Mon Jul 20 06:43:32.201162 2026] [security2:error] [pid 1011111:tid 1011295] [client 52.109.16.52:10498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4X9BXES7Mv0Zfga-kPNwAAALo"]
[Mon Jul 20 06:43:32.214294 2026] [security2:error] [pid 1011111:tid 1011339] [client 173.239.240.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "giftsurprizo.com"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPJwAAAOY"]
[Mon Jul 20 06:43:32.252810 2026] [security2:error] [pid 1011111:tid 1011159] [remote 80.82.65.226:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPQwAAiS4"]
[Mon Jul 20 06:43:32.254097 2026] [security2:error] [pid 1011111:tid 1011301] [client 52.109.16.52:10498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4X9BXES7Mv0Zfga-kPQgAAAMA"]
[Mon Jul 20 06:43:32.286152 2026] [security2:error] [pid 1011111:tid 1011133] [remote 128.199.71.102:51132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.71.199.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4X9BXES7Mv0Zfga-kPRgAAkRQ"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 06:43:32.303118 2026] [security2:error] [pid 1011111:tid 1011232] [remote 117.0.21.154:33034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4X9BXES7Mv0Zfga-kPRwAAhXc"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 06:43:32.307326 2026] [security2:error] [pid 1011111:tid 1011306] [client 14.225.17.146:57604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPMgAAAMU"], referer: http://soloceos.com/new
[Mon Jul 20 06:43:32.368424 2026] [security2:error] [pid 1011111:tid 1011358] [client 57.141.18.92:27540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X8BXES7Mv0Zfga-kNiwAA-Qk"]
[Mon Jul 20 06:43:32.406825 2026] [security2:error] [pid 1011111:tid 1011233] [remote 80.82.65.226:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPVgAAwng"]
[Mon Jul 20 06:43:32.430520 2026] [lsapi:warn] [pid 1011111:tid 1011336] [client 14.225.17.146:57171] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/new
[Mon Jul 20 06:43:32.430542 2026] [lsapi:warn] [pid 1011111:tid 1011336] [client 14.225.17.146:57171] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/new
[Mon Jul 20 06:43:32.471233 2026] [security2:error] [pid 1011111:tid 1011319] [client 14.225.17.146:58095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPSwAAANI"], referer: http://alrowad-hub.net/new
[Mon Jul 20 06:43:32.500343 2026] [security2:error] [pid 1011111:tid 1011366] [client 14.225.17.146:56748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPTwAAAQE"], referer: http://dereckcastellon.com/new
[Mon Jul 20 06:43:32.562608 2026] [security2:error] [pid 1011111:tid 1011353] [client 14.225.17.146:62136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPUgAAAPQ"], referer: https://thesoloceos.com/new
[Mon Jul 20 06:43:32.674263 2026] [security2:error] [pid 1011111:tid 1011300] [client 57.141.18.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPYgAAAL8"]
[Mon Jul 20 06:43:32.709084 2026] [security2:error] [pid 1011111:tid 1011355] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPXwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:32.721588 2026] [security2:error] [pid 1011111:tid 1011290] [client 106.219.188.178:15835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X9BXES7Mv0Zfga-kPcQAAALU"]
[Mon Jul 20 06:43:32.728309 2026] [security2:error] [pid 1011111:tid 1011290] [client 106.219.188.178:15835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X9BXES7Mv0Zfga-kPcQAAALU"]
[Mon Jul 20 06:43:32.767284 2026] [security2:error] [pid 1011111:tid 1011281] [client 14.225.17.146:62135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4X8hXES7Mv0Zfga-kOrwAAAKw"], referer: http://fluidtemple.org/new
[Mon Jul 20 06:43:32.863442 2026] [security2:error] [pid 1011111:tid 1011286] [client 14.225.17.146:57139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4X8xXES7Mv0Zfga-kO3QAAALE"], referer: http://detroitcsc.com/new
[Mon Jul 20 06:43:32.978483 2026] [security2:error] [pid 1011111:tid 1011265] [client 14.225.17.146:57329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4X8xXES7Mv0Zfga-kO8QAAAJw"], referer: http://betterbonddogtraining.com/new
[Mon Jul 20 06:43:33.219318 2026] [security2:error] [pid 1011111:tid 1011220] [remote 80.82.65.226:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kPrgAA22s"]
[Mon Jul 20 06:43:33.279926 2026] [security2:error] [pid 1011111:tid 1011296] [client 14.225.17.146:51091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4X8xXES7Mv0Zfga-kO_wAAALs"]
[Mon Jul 20 06:43:33.283420 2026] [security2:error] [pid 1011111:tid 1011172] [remote 80.82.65.226:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kPtQAA9js"]
[Mon Jul 20 06:43:33.324611 2026] [security2:error] [pid 1011111:tid 1011351] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kPpAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:33.416085 2026] [security2:error] [pid 1011111:tid 1011271] [client 104.234.53.91:48049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4X9RXES7Mv0Zfga-kPwwAAAKI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:33.544103 2026] [security2:error] [pid 1011111:tid 1011274] [client 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4X9RXES7Mv0Zfga-kP0wAAAKU"]
[Mon Jul 20 06:43:33.637831 2026] [security2:error] [pid 1011111:tid 1011368] [client 183.82.98.154:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X9RXES7Mv0Zfga-kP2gAAAQM"]
[Mon Jul 20 06:43:33.638023 2026] [security2:error] [pid 1011111:tid 1011368] [client 183.82.98.154:55217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4X9RXES7Mv0Zfga-kP2gAAAQM"]
[Mon Jul 20 06:43:33.682093 2026] [security2:error] [pid 1011111:tid 1011225] [remote 80.82.65.226:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kP3wABAnA"]
[Mon Jul 20 06:43:33.788734 2026] [security2:error] [pid 1011111:tid 1011348] [client 112.208.70.94:45296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X9RXES7Mv0Zfga-kP7AAAAO8"]
[Mon Jul 20 06:43:33.788830 2026] [security2:error] [pid 1011111:tid 1011348] [client 112.208.70.94:45296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X9RXES7Mv0Zfga-kP7AAAAO8"]
[Mon Jul 20 06:43:33.816156 2026] [security2:error] [pid 1011111:tid 1011234] [remote 80.82.65.226:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kP7wAAiXk"]
[Mon Jul 20 06:43:33.817022 2026] [security2:error] [pid 1011111:tid 1011254] [client 65.111.13.151:25745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X9RXES7Mv0Zfga-kP6gAAAJE"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:33.903211 2026] [security2:error] [pid 1011111:tid 1011359] [client 14.225.17.146:58890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kP5wAAAPo"], referer: https://north-woods-engineering.com/new
[Mon Jul 20 06:43:33.915845 2026] [security2:error] [pid 1011111:tid 1011346] [client 163.172.135.240:42582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "cpanel-box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4X9RXES7Mv0Zfga-kP_QAAAO0"]
[Mon Jul 20 06:43:34.061266 2026] [security2:error] [pid 1011111:tid 1011304] [client 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQCgAAAMM"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:43:34.116726 2026] [security2:error] [pid 1011111:tid 1011160] [remote 80.82.65.226:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4X9hXES7Mv0Zfga-kQDwAAiC8"]
[Mon Jul 20 06:43:34.218423 2026] [security2:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4X9hXES7Mv0Zfga-kQFAAAkU0"]
[Mon Jul 20 06:43:34.244630 2026] [security2:error] [pid 1011111:tid 1011265] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4X9hXES7Mv0Zfga-kQEAAAAJw"]
[Mon Jul 20 06:43:34.249479 2026] [security2:error] [pid 1011111:tid 1011322] [client 157.20.215.123:49334] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4X9hXES7Mv0Zfga-kQGAAAANU"]
[Mon Jul 20 06:43:34.366083 2026] [security2:error] [pid 1011111:tid 1011222] [remote 91.142.222.105:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQJAAAt20"]
[Mon Jul 20 06:43:34.561179 2026] [security2:error] [pid 1011111:tid 1011337] [client 45.3.41.145:55545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQPQAAAOQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:34.580007 2026] [security2:error] [pid 1011111:tid 1011245] [client 173.239.240.102:48861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQQgAAAIg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:34.604657 2026] [security2:error] [pid 1011111:tid 1011333] [client 57.141.18.63:46330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X8hXES7Mv0Zfga-kOYwAA4Dc"]
[Mon Jul 20 06:43:34.637584 2026] [security2:error] [pid 1011111:tid 1011286] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X9hXES7Mv0Zfga-kQLQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:34.729914 2026] [security2:error] [pid 1011111:tid 1011161] [remote 217.61.143.92:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQTQAAjTA"]
[Mon Jul 20 06:43:34.803571 2026] [security2:error] [pid 1011111:tid 1011203] [remote 80.82.65.226:35196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4X9hXES7Mv0Zfga-kQVQAAkFo"]
[Mon Jul 20 06:43:34.915374 2026] [security2:error] [pid 1011111:tid 1011196] [remote 91.142.222.105:59280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQYwAA9FM"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 06:43:34.962581 2026] [security2:error] [pid 1011111:tid 1011177] [remote 217.61.143.92:51610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X9hXES7Mv0Zfga-kQawAA1UA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:43:35.027534 2026] [security2:error] [pid 1011111:tid 1011348] [client 136.144.35.252:55423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X9xXES7Mv0Zfga-kQbwAAAO8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:35.051489 2026] [security2:error] [pid 1011111:tid 1011321] [client 157.20.215.123:45508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4X9xXES7Mv0Zfga-kQcAAAANQ"]
[Mon Jul 20 06:43:35.076440 2026] [security2:error] [pid 1011111:tid 1011213] [remote 80.82.65.226:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQcQAA7mQ"]
[Mon Jul 20 06:43:35.380304 2026] [proxy:error] [pid 1011111:tid 1011238] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:35.380353 2026] [proxy_http:error] [pid 1011111:tid 1011238] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:35.380758 2026] [proxy:error] [pid 1011111:tid 1011238] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:35.380781 2026] [proxy_http:error] [pid 1011111:tid 1011238] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:35.394669 2026] [security2:error] [pid 1011111:tid 1011359] [client 45.3.35.221:54787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X9xXES7Mv0Zfga-kQjAAAAPo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:35.401664 2026] [security2:error] [pid 1011111:tid 1011315] [client 57.141.18.34:58424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X8xXES7Mv0Zfga-kOvQAAzhs"]
[Mon Jul 20 06:43:35.439584 2026] [security2:error] [pid 1011111:tid 1011271] [client 34.221.76.50:65300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4X9xXES7Mv0Zfga-kQkwAAAKI"]
[Mon Jul 20 06:43:35.444511 2026] [security2:error] [pid 1011111:tid 1011268] [client 39.48.81.23:51226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X9xXES7Mv0Zfga-kQlAAAAJ8"]
[Mon Jul 20 06:43:35.444587 2026] [security2:error] [pid 1011111:tid 1011268] [client 39.48.81.23:51226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X9xXES7Mv0Zfga-kQlAAAAJ8"]
[Mon Jul 20 06:43:35.457591 2026] [security2:error] [pid 1011111:tid 1011343] [client 171.61.165.146:10044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4X9xXES7Mv0Zfga-kQlQAAAOo"]
[Mon Jul 20 06:43:35.457680 2026] [security2:error] [pid 1011111:tid 1011343] [client 171.61.165.146:10044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4X9xXES7Mv0Zfga-kQlQAAAOo"]
[Mon Jul 20 06:43:35.507843 2026] [security2:error] [pid 1011111:tid 1011270] [client 173.239.240.100:58691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQnAAAAKE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:35.528110 2026] [security2:error] [pid 1011111:tid 1011136] [remote 80.82.65.226:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQnQAAzRc"]
[Mon Jul 20 06:43:35.985692 2026] [security2:error] [pid 1011111:tid 1011297] [client 173.239.240.96:45241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X9xXES7Mv0Zfga-kQxAAAALw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:36.025435 2026] [security2:error] [pid 1011111:tid 1011244] [client 187.108.85.186:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kQyAAAAIc"]
[Mon Jul 20 06:43:36.025544 2026] [security2:error] [pid 1011111:tid 1011244] [client 187.108.85.186:49533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kQyAAAAIc"]
[Mon Jul 20 06:43:36.091432 2026] [proxy:error] [pid 1011111:tid 1011153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:36.091485 2026] [proxy_http:error] [pid 1011111:tid 1011153] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:36.091946 2026] [proxy:error] [pid 1011111:tid 1011153] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:36.091973 2026] [proxy_http:error] [pid 1011111:tid 1011153] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:36.191882 2026] [security2:error] [pid 1011111:tid 1011209] [remote 80.82.65.226:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kQ2QAA6WA"]
[Mon Jul 20 06:43:36.195367 2026] [security2:error] [pid 1011111:tid 1011137] [remote 80.82.65.226:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kQ2wAAkRg"]
[Mon Jul 20 06:43:36.291131 2026] [security2:error] [pid 1011111:tid 1011214] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kQ6wAA5GU"]
[Mon Jul 20 06:43:36.291253 2026] [security2:error] [pid 1011111:tid 1011337] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kQ6wAA5GU"]
[Mon Jul 20 06:43:36.366734 2026] [security2:error] [pid 1011111:tid 1011259] [client 14.225.17.146:56786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQdQAAAJY"], referer: http://lutheranphilosopher.com/new
[Mon Jul 20 06:43:36.460731 2026] [security2:error] [pid 1011111:tid 1011322] [client 173.239.240.95:36239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kRAAAAANU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:36.549968 2026] [security2:error] [pid 1011111:tid 1011306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kQ8AAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:36.585887 2026] [security2:error] [pid 1011111:tid 1011280] [client 103.238.106.162:61014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kRCgAAAKs"]
[Mon Jul 20 06:43:36.586003 2026] [security2:error] [pid 1011111:tid 1011280] [client 103.238.106.162:61014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kRCgAAAKs"]
[Mon Jul 20 06:43:36.666728 2026] [http2:info] [pid 1014214:tid 1014214] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:43:36.675357 2026] [security2:error] [pid 1011111:tid 1011320] [client 152.58.191.29:60675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kRDwAAANM"]
[Mon Jul 20 06:43:36.675457 2026] [security2:error] [pid 1011111:tid 1011320] [client 152.58.191.29:60675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4X-BXES7Mv0Zfga-kRDwAAANM"]
[Mon Jul 20 06:43:36.680726 2026] [security2:error] [pid 1011111:tid 1011260] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQvAAAl3Y"]
[Mon Jul 20 06:43:36.683279 2026] [security2:error] [pid 1011111:tid 1011134] [remote 5.161.225.162:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X-BXES7Mv0Zfga-kREQAA4BU"]
[Mon Jul 20 06:43:36.747177 2026] [security2:error] [pid 1011111:tid 1011297] [client 104.207.58.25:24231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X-BXES7Mv0Zfga-kREgAAALw"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:36.779744 2026] [security2:error] [pid 1011111:tid 1011200] [remote 80.82.65.226:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kRGAAAhlc"]
[Mon Jul 20 06:43:36.782901 2026] [proxy:error] [pid 1011111:tid 1011190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:36.782965 2026] [proxy_http:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:36.783376 2026] [proxy:error] [pid 1011111:tid 1011190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:36.783404 2026] [proxy_http:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:36.876233 2026] [security2:error] [pid 1011111:tid 1011222] [remote 80.82.65.226:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kRIQAA220"]
[Mon Jul 20 06:43:36.908015 2026] [security2:error] [pid 1011111:tid 1011356] [client 173.239.240.92:53721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X-BXES7Mv0Zfga-kRJAAAAPc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:36.936919 2026] [security2:error] [pid 1011111:tid 1011130] [remote 5.161.225.162:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X-BXES7Mv0Zfga-kRKAAAphE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:43:37.065163 2026] [security2:error] [pid 1011111:tid 1011307] [client 57.141.18.19:34096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X9BXES7Mv0Zfga-kPfAAAxiI"]
[Mon Jul 20 06:43:37.073143 2026] [security2:error] [pid 1011111:tid 1011168] [remote 80.82.65.226:42936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRLgAAqTc"]
[Mon Jul 20 06:43:37.084189 2026] [security2:error] [pid 1011111:tid 1011162] [remote 80.82.65.226:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRLwAAwTE"]
[Mon Jul 20 06:43:37.096559 2026] [security2:error] [pid 1014214:tid 1014345] [client 217.142.18.172:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X-QuRBFTcQNywdCL4DgAAAZA"]
[Mon Jul 20 06:43:37.096676 2026] [security2:error] [pid 1014214:tid 1014345] [client 217.142.18.172:62481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4X-QuRBFTcQNywdCL4DgAAAZA"]
[Mon Jul 20 06:43:37.127591 2026] [security2:error] [pid 1011111:tid 1011276] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kRJQAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:37.163071 2026] [security2:error] [pid 1011111:tid 1011265] [client 14.225.17.146:51270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kRJwAAAJw"], referer: http://tacticaltreeoperations.com/new
[Mon Jul 20 06:43:37.193423 2026] [security2:error] [pid 1011111:tid 1011175] [remote 80.82.65.226:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRMwAA-T4"]
[Mon Jul 20 06:43:37.209865 2026] [proxy:error] [pid 1011111:tid 1011235] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:37.209932 2026] [proxy_http:error] [pid 1011111:tid 1011235] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:37.210475 2026] [proxy:error] [pid 1011111:tid 1011235] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:37.210502 2026] [proxy_http:error] [pid 1011111:tid 1011235] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:37.245902 2026] [ssl:error] [pid 1011111:tid 1011362] [client 104.48.69.105:38094] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:43:37.303984 2026] [security2:error] [pid 1014214:tid 1014360] [client 14.225.17.146:62239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4X-QuRBFTcQNywdCL4EAAAAZ8"], referer: http://effingweirdmuseums.com/new
[Mon Jul 20 06:43:37.335843 2026] [security2:error] [pid 1011111:tid 1011126] [remote 5.252.52.249:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4X-RXES7Mv0Zfga-kRPgAAlw0"]
[Mon Jul 20 06:43:37.372276 2026] [security2:error] [pid 1011111:tid 1011298] [client 173.239.240.91:58719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRQwAAAL0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:37.397674 2026] [security2:error] [pid 1011111:tid 1011263] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRQQAAmm4"]
[Mon Jul 20 06:43:37.401839 2026] [security2:error] [pid 1011111:tid 1011186] [remote 80.82.65.226:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRRQAA2Ek"]
[Mon Jul 20 06:43:37.504338 2026] [security2:error] [pid 1011111:tid 1011129] [remote 5.252.52.249:39174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4X-RXES7Mv0Zfga-kRTAAArBA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:43:37.577386 2026] [security2:error] [pid 1011111:tid 1011356] [client 77.110.127.138:53455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X-RXES7Mv0Zfga-kRUgAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:37.577477 2026] [security2:error] [pid 1011111:tid 1011356] [client 77.110.127.138:53455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X-RXES7Mv0Zfga-kRUgAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:37.621148 2026] [security2:error] [pid 1014214:tid 1014380] [client 65.111.10.103:27269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4X-QuRBFTcQNywdCL4IQAAAbM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:37.625590 2026] [security2:error] [pid 1011111:tid 1011206] [remote 80.82.65.226:42936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRVAAA4l0"]
[Mon Jul 20 06:43:37.639798 2026] [security2:error] [pid 1011111:tid 1011213] [remote 80.82.65.226:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRVQAAtGQ"]
[Mon Jul 20 06:43:37.687880 2026] [security2:error] [pid 1011111:tid 1011277] [client 57.141.18.125:37430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X9RXES7Mv0Zfga-kPygAAqHQ"]
[Mon Jul 20 06:43:37.691134 2026] [security2:error] [pid 1011111:tid 1011122] [remote 80.82.65.226:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRWAAAzwk"]
[Mon Jul 20 06:43:37.701521 2026] [security2:error] [pid 1011111:tid 1011232] [remote 80.82.65.226:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRWgAA9nc"]
[Mon Jul 20 06:43:37.728257 2026] [security2:error] [pid 1011111:tid 1011340] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRTgAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:37.745083 2026] [security2:error] [pid 1011111:tid 1011121] [remote 80.82.65.226:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRXgABAQg"]
[Mon Jul 20 06:43:37.750040 2026] [proxy:error] [pid 1011111:tid 1011233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:37.750146 2026] [proxy_http:error] [pid 1011111:tid 1011233] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:37.751446 2026] [proxy:error] [pid 1011111:tid 1011233] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:37.751512 2026] [proxy_http:error] [pid 1011111:tid 1011233] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:37.850473 2026] [security2:error] [pid 1011111:tid 1011276] [client 173.239.240.102:40731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X-RXES7Mv0Zfga-kRZgAAAKc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:37.977435 2026] [security2:error] [pid 1014214:tid 1014385] [client 104.234.53.67:37963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4X-QuRBFTcQNywdCL4LQAAAbg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:38.030274 2026] [security2:error] [pid 1011111:tid 1011330] [client 207.46.13.153:48270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4X-BXES7Mv0Zfga-kQyQAA3Uc"]
[Mon Jul 20 06:43:38.093277 2026] [security2:error] [pid 1011111:tid 1011201] [remote 80.82.65.226:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRfgAAw1g"]
[Mon Jul 20 06:43:38.143036 2026] [security2:error] [pid 1011111:tid 1011351] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRgAAA8mI"]
[Mon Jul 20 06:43:38.172263 2026] [security2:error] [pid 1011111:tid 1011322] [client 14.225.17.146:64215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRfwAAANU"], referer: https://effingweirdmuseums.com/new
[Mon Jul 20 06:43:38.183817 2026] [security2:error] [pid 1014214:tid 1014439] [client 77.110.127.138:53460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X-guRBFTcQNywdCL4OQAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:38.241663 2026] [security2:error] [pid 1011111:tid 1011345] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRdwAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:38.241998 2026] [ssl:error] [pid 1014214:tid 1014437] [client 104.48.69.105:41186] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:43:38.256504 2026] [security2:error] [pid 1011111:tid 1011226] [remote 80.82.65.226:42936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRhgAA3nE"]
[Mon Jul 20 06:43:38.276093 2026] [security2:error] [pid 1011111:tid 1011142] [remote 80.82.65.226:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRhwAAoR0"]
[Mon Jul 20 06:43:38.316633 2026] [security2:error] [pid 1014214:tid 1014447] [client 173.239.240.32:47143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X-guRBFTcQNywdCL4PAAAAfY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:38.407348 2026] [security2:error] [pid 1011111:tid 1011154] [remote 162.19.86.63:46639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4X-hXES7Mv0Zfga-kRiwAAqCk"]
[Mon Jul 20 06:43:38.437477 2026] [proxy:error] [pid 1011111:tid 1011191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:38.437554 2026] [proxy_http:error] [pid 1011111:tid 1011191] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:38.438081 2026] [proxy:error] [pid 1011111:tid 1011191] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:38.438109 2026] [proxy_http:error] [pid 1011111:tid 1011191] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:38.440193 2026] [security2:error] [pid 1011111:tid 1011165] [remote 80.82.65.226:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRkQAArzQ"]
[Mon Jul 20 06:43:38.485181 2026] [security2:error] [pid 1011111:tid 1011173] [remote 80.82.65.226:42936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRlgAAnzw"]
[Mon Jul 20 06:43:38.583467 2026] [security2:error] [pid 1011111:tid 1011325] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRnwAA2FQ"]
[Mon Jul 20 06:43:38.638308 2026] [security2:error] [pid 1011111:tid 1011189] [remote 162.19.86.63:46639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4X-hXES7Mv0Zfga-kRowABA0w"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 06:43:38.655368 2026] [security2:error] [pid 1011111:tid 1011178] [remote 80.82.65.226:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRpAAAjkE"]
[Mon Jul 20 06:43:38.713170 2026] [security2:error] [pid 1014214:tid 1014463] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4X-guRBFTcQNywdCL4QQAAAgY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:38.786251 2026] [security2:error] [pid 1011111:tid 1011272] [client 173.239.240.94:25207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X-hXES7Mv0Zfga-kRrAAAAKM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:38.861222 2026] [security2:error] [pid 1011111:tid 1011225] [remote 80.82.65.226:42926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/site/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRrgAA7nA"]
[Mon Jul 20 06:43:38.874200 2026] [security2:error] [pid 1011111:tid 1011199] [remote 80.82.65.226:42936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRsAAAolY"]
[Mon Jul 20 06:43:39.000770 2026] [security2:error] [pid 1011111:tid 1011307] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRsgAAxnk"]
[Mon Jul 20 06:43:39.034974 2026] [security2:error] [pid 1011111:tid 1011181] [remote 98.156.100.191:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4X-xXES7Mv0Zfga-kRtwAAnUQ"]
[Mon Jul 20 06:43:39.098710 2026] [security2:error] [pid 1011111:tid 1011216] [remote 80.82.65.226:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kRuQAAvWc"]
[Mon Jul 20 06:43:39.169847 2026] [security2:error] [pid 1011111:tid 1011164] [remote 80.82.65.226:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kRwAAA0TM"]
[Mon Jul 20 06:43:39.171559 2026] [security2:error] [pid 1011111:tid 1011131] [remote 80.82.65.226:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kRwQAA-BI"]
[Mon Jul 20 06:43:39.240093 2026] [security2:error] [pid 1011111:tid 1011363] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kRwgAA_go"]
[Mon Jul 20 06:43:39.242584 2026] [security2:error] [pid 1011111:tid 1011156] [remote 173.249.4.11:52773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X-xXES7Mv0Zfga-kRxwABBCs"]
[Mon Jul 20 06:43:39.242706 2026] [security2:error] [pid 1011111:tid 1011369] [client 173.249.4.11:52773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X-xXES7Mv0Zfga-kRxwABBCs"]
[Mon Jul 20 06:43:39.251329 2026] [security2:error] [pid 1011111:tid 1011367] [client 57.141.18.58:59672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X9hXES7Mv0Zfga-kQOQABAiA"]
[Mon Jul 20 06:43:39.279221 2026] [security2:error] [pid 1011111:tid 1011151] [remote 80.82.65.226:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kRyAAAqSY"]
[Mon Jul 20 06:43:39.300888 2026] [security2:error] [pid 1014214:tid 1014398] [client 173.239.240.92:29699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X-wuRBFTcQNywdCL4ZQAAAcU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:39.404953 2026] [security2:error] [pid 1014214:tid 1014419] [client 187.194.59.147:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4X-QuRBFTcQNywdCL4KwAAAdo"]
[Mon Jul 20 06:43:39.524918 2026] [security2:error] [pid 1014214:tid 1014439] [client 46.110.96.34:23096] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4dAAAAe4"]
[Mon Jul 20 06:43:39.525505 2026] [security2:error] [pid 1014214:tid 1014450] [client 46.110.96.34:50230] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4dQAAAfk"]
[Mon Jul 20 06:43:39.526199 2026] [security2:error] [pid 1011111:tid 1011342] [client 46.110.96.34:32459] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR1gAAAOk"]
[Mon Jul 20 06:43:39.541169 2026] [security2:error] [pid 1011111:tid 1011274] [client 57.141.18.27:46222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQcwAApVA"]
[Mon Jul 20 06:43:39.559279 2026] [security2:error] [pid 1011111:tid 1011187] [remote 80.82.65.226:42936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kR2AAAw0o"]
[Mon Jul 20 06:43:39.593029 2026] [security2:error] [pid 1014214:tid 1014447] [client 46.110.96.34:22874] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4eAAAAfY"]
[Mon Jul 20 06:43:39.595634 2026] [security2:error] [pid 1011111:tid 1011289] [client 46.110.96.34:17942] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR2wAAALQ"]
[Mon Jul 20 06:43:39.597085 2026] [security2:error] [pid 1011111:tid 1011322] [client 46.110.96.34:50504] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR3AAAANU"]
[Mon Jul 20 06:43:39.597087 2026] [security2:error] [pid 1014214:tid 1014452] [client 46.110.96.34:48589] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4eQAAAfs"]
[Mon Jul 20 06:43:39.600596 2026] [security2:error] [pid 1011111:tid 1011293] [client 46.110.96.34:1671] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR3QAAALg"]
[Mon Jul 20 06:43:39.605829 2026] [security2:error] [pid 1011111:tid 1011316] [client 46.110.96.34:25631] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR3gAAAM8"]
[Mon Jul 20 06:43:39.605830 2026] [security2:error] [pid 1011111:tid 1011355] [client 46.110.96.34:7079] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR3wAAAPY"]
[Mon Jul 20 06:43:39.606393 2026] [security2:error] [pid 1011111:tid 1011345] [client 46.110.96.34:5725] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR4AAAAOw"]
[Mon Jul 20 06:43:39.607997 2026] [security2:error] [pid 1014214:tid 1014448] [client 46.110.96.34:55997] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4egAAAfc"]
[Mon Jul 20 06:43:39.610736 2026] [security2:error] [pid 1011111:tid 1011307] [client 46.110.96.34:9220] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR4QAAAMY"]
[Mon Jul 20 06:43:39.611574 2026] [security2:error] [pid 1014214:tid 1014453] [client 46.110.96.34:45051] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4ewAAAfw"]
[Mon Jul 20 06:43:39.737671 2026] [security2:error] [pid 1011111:tid 1011268] [client 14.251.3.155:54661] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4X-xXES7Mv0Zfga-kR6wAAAJ8"]
[Mon Jul 20 06:43:39.751929 2026] [security2:error] [pid 1014214:tid 1014425] [client 173.239.240.96:31341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X-wuRBFTcQNywdCL4fgAAAeA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:39.777903 2026] [security2:error] [pid 1011111:tid 1011247] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kR6gAAiks"]
[Mon Jul 20 06:43:39.844383 2026] [security2:error] [pid 1014214:tid 1014466] [client 113.160.97.242:57791] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4X-wuRBFTcQNywdCL4gwAAAgk"]
[Mon Jul 20 06:43:39.849245 2026] [security2:error] [pid 1011111:tid 1011168] [remote 80.82.65.226:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kR9QAAmTc"]
[Mon Jul 20 06:43:40.034508 2026] [security2:error] [pid 1011111:tid 1011126] [remote 80.82.65.226:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSAAAAng0"]
[Mon Jul 20 06:43:40.083796 2026] [security2:error] [pid 1011111:tid 1011305] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSAQAAxDA"]
[Mon Jul 20 06:43:40.089462 2026] [security2:error] [pid 1011111:tid 1011186] [remote 154.0.166.254:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X_BXES7Mv0Zfga-kSBQAA4kk"]
[Mon Jul 20 06:43:40.103831 2026] [security2:error] [pid 1011111:tid 1011150] [remote 80.82.65.226:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSBgAAyyU"]
[Mon Jul 20 06:43:40.123146 2026] [security2:error] [pid 1011111:tid 1011169] [remote 80.82.65.226:34540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSBwAAwDg"]
[Mon Jul 20 06:43:40.222149 2026] [security2:error] [pid 1014214:tid 1014348] [client 173.239.240.102:49389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X_AuRBFTcQNywdCL4kgAAAZM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:40.238606 2026] [security2:error] [pid 1011111:tid 1011348] [client 57.141.18.119:37994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X9xXES7Mv0Zfga-kQuQAA7zs"]
[Mon Jul 20 06:43:40.294270 2026] [security2:error] [pid 1011111:tid 1011321] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSDgAA1EM"]
[Mon Jul 20 06:43:40.338770 2026] [security2:error] [pid 1011111:tid 1011293] [client 46.110.96.34:34767] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X_BXES7Mv0Zfga-kSFAAAALg"]
[Mon Jul 20 06:43:40.392412 2026] [security2:error] [pid 1011111:tid 1011362] [client 37.52.210.45:11583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X_BXES7Mv0Zfga-kSGAAAAP0"]
[Mon Jul 20 06:43:40.392571 2026] [security2:error] [pid 1011111:tid 1011362] [client 37.52.210.45:11583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X_BXES7Mv0Zfga-kSGAAAAP0"]
[Mon Jul 20 06:43:40.542738 2026] [security2:error] [pid 1011111:tid 1011233] [remote 98.156.100.191:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4X_BXES7Mv0Zfga-kSIQAA3Hg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:43:40.574720 2026] [security2:error] [pid 1011111:tid 1011127] [remote 154.0.166.254:57738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4X_BXES7Mv0Zfga-kSIgAAnw4"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:43:40.602174 2026] [security2:error] [pid 1011111:tid 1011170] [remote 80.82.65.226:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSJQAAkDk"]
[Mon Jul 20 06:43:40.652547 2026] [security2:error] [pid 1011111:tid 1011182] [remote 80.82.65.226:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSKQABBEU"]
[Mon Jul 20 06:43:40.664867 2026] [security2:error] [pid 1014214:tid 1014355] [client 14.225.17.146:64027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4X_AuRBFTcQNywdCL4lAAAAZo"], referer: http://backandneckpainrelieflaceychiropractor.com/new
[Mon Jul 20 06:43:40.697615 2026] [security2:error] [pid 1011111:tid 1011302] [client 136.144.35.254:58325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X_BXES7Mv0Zfga-kSLgAAAME"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:40.725680 2026] [security2:error] [pid 1011111:tid 1011115] [remote 80.82.65.226:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSMQAA_gI"]
[Mon Jul 20 06:43:40.734326 2026] [security2:error] [pid 1011111:tid 1011132] [remote 80.82.65.226:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSMgAApBM"]
[Mon Jul 20 06:43:40.816290 2026] [security2:error] [pid 1011111:tid 1011306] [client 197.186.66.42:59060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X_BXES7Mv0Zfga-kSOQAAAMU"]
[Mon Jul 20 06:43:40.827441 2026] [security2:error] [pid 1011111:tid 1011306] [client 197.186.66.42:59060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4X_BXES7Mv0Zfga-kSOQAAAMU"]
[Mon Jul 20 06:43:40.901598 2026] [security2:error] [pid 1014214:tid 1014248] [remote 103.187.23.21:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4X_AuRBFTcQNywdCL4pQABwCE"]
[Mon Jul 20 06:43:40.943298 2026] [security2:error] [pid 1011111:tid 1011258] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSQgAAlSM"]
[Mon Jul 20 06:43:41.170222 2026] [security2:error] [pid 1011111:tid 1011315] [client 14.225.17.146:51560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kR9AAAAM4"], referer: http://alaraycreative.com/new
[Mon Jul 20 06:43:41.192003 2026] [security2:error] [pid 1014214:tid 1014431] [client 173.239.240.95:40449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X_QuRBFTcQNywdCL4qwAAAeY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:41.202650 2026] [security2:error] [pid 1011111:tid 1011197] [remote 80.82.65.226:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/wp/index.php"] [unique_id "al4X_RXES7Mv0Zfga-kSWwAAxlQ"]
[Mon Jul 20 06:43:41.206324 2026] [security2:error] [pid 1014214:tid 1014396] [client 46.110.96.34:17039] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X_QuRBFTcQNywdCL4rAAAAcM"]
[Mon Jul 20 06:43:41.221130 2026] [security2:error] [pid 1011111:tid 1011192] [remote 80.82.65.226:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4X_RXES7Mv0Zfga-kSXAAAoE8"]
[Mon Jul 20 06:43:41.242999 2026] [security2:error] [pid 1011111:tid 1011266] [client 46.110.96.34:3848] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4X_RXES7Mv0Zfga-kSYAAAAJ0"]
[Mon Jul 20 06:43:41.349875 2026] [security2:error] [pid 1014214:tid 1014251] [remote 103.187.23.21:37786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4X_QuRBFTcQNywdCL4uAACCSQ"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:43:41.418024 2026] [security2:error] [pid 1014214:tid 1014347] [client 77.110.127.138:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X_QuRBFTcQNywdCL4vQAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:41.418140 2026] [security2:error] [pid 1014214:tid 1014347] [client 77.110.127.138:53478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X_QuRBFTcQNywdCL4vQAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:41.472508 2026] [security2:error] [pid 1011111:tid 1011273] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_RXES7Mv0Zfga-kSawAApCg"]
[Mon Jul 20 06:43:41.514345 2026] [security2:error] [pid 1011111:tid 1011214] [remote 182.77.62.24:40140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X_RXES7Mv0Zfga-kSbwAA1mU"]
[Mon Jul 20 06:43:41.558603 2026] [security2:error] [pid 1014214:tid 1014349] [client 114.119.136.199:21671] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ferrellroofing.com"] [uri "/author/dean"] [unique_id "al4X_QuRBFTcQNywdCL4wwAAAZQ"], referer: http://www.ferrellroofing.com/metalworks/
[Mon Jul 20 06:43:41.623992 2026] [security2:error] [pid 1011111:tid 1011181] [remote 193.70.112.205:41280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4X_RXES7Mv0Zfga-kSdwAA-UQ"]
[Mon Jul 20 06:43:41.640863 2026] [security2:error] [pid 1014214:tid 1014369] [client 57.141.18.110:37098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-QuRBFTcQNywdCL4EQABqAI"]
[Mon Jul 20 06:43:41.657149 2026] [security2:error] [pid 1014214:tid 1014400] [client 173.239.240.31:20781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X_QuRBFTcQNywdCL4xgAAAcc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:41.705078 2026] [security2:error] [pid 1014214:tid 1014395] [client 104.234.53.68:38329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4X_QuRBFTcQNywdCL4xQAAAcI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:41.706390 2026] [security2:error] [pid 1011111:tid 1011351] [client 46.110.96.34:41198] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4X_RXES7Mv0Zfga-kSfQAAAPI"]
[Mon Jul 20 06:43:41.740724 2026] [security2:error] [pid 1011111:tid 1011145] [remote 80.82.65.226:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4X_RXES7Mv0Zfga-kSgAAAqCA"]
[Mon Jul 20 06:43:41.742566 2026] [security2:error] [pid 1011111:tid 1011244] [client 14.225.17.146:63776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4X-xXES7Mv0Zfga-kR6AAAAIc"], referer: http://idigress.agency/new
[Mon Jul 20 06:43:41.818187 2026] [security2:error] [pid 1011111:tid 1011156] [remote 80.82.65.226:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/wordpress/index.php"] [unique_id "al4X_RXES7Mv0Zfga-kSigAA1Ss"]
[Mon Jul 20 06:43:41.844409 2026] [security2:error] [pid 1011111:tid 1011289] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_RXES7Mv0Zfga-kSiAAAtBU"]
[Mon Jul 20 06:43:41.966598 2026] [security2:error] [pid 1011111:tid 1011367] [client 223.185.13.213:25074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X_RXES7Mv0Zfga-kSmAAAAQI"]
[Mon Jul 20 06:43:41.967468 2026] [security2:error] [pid 1011111:tid 1011367] [client 223.185.13.213:25074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4X_RXES7Mv0Zfga-kSmAAAAQI"]
[Mon Jul 20 06:43:41.987966 2026] [security2:error] [pid 1014214:tid 1014426] [client 104.234.53.68:38329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4X_QuRBFTcQNywdCL44AAAAeE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:41.990316 2026] [security2:error] [pid 1011111:tid 1011135] [remote 193.70.112.205:41280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4X_RXES7Mv0Zfga-kSmgAA1xY"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 06:43:42.099622 2026] [security2:error] [pid 1011111:tid 1011187] [remote 182.77.62.24:40140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4X_hXES7Mv0Zfga-kSngABBEo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:43:42.104008 2026] [security2:error] [pid 1011111:tid 1011290] [client 173.239.240.31:35701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X_hXES7Mv0Zfga-kSnwAAALU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:42.134451 2026] [security2:error] [pid 1011111:tid 1011207] [remote 80.82.65.226:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/blog/index.php"] [unique_id "al4X_hXES7Mv0Zfga-kSogAAp14"]
[Mon Jul 20 06:43:42.237883 2026] [security2:error] [pid 1014214:tid 1014344] [client 223.237.130.40:60537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.130.237.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4X_guRBFTcQNywdCL47QAAAY8"]
[Mon Jul 20 06:43:42.248943 2026] [security2:error] [pid 1014214:tid 1014344] [client 223.237.130.40:60537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4X_guRBFTcQNywdCL47QAAAY8"]
[Mon Jul 20 06:43:42.348319 2026] [security2:error] [pid 1014214:tid 1014260] [remote 162.19.86.63:33626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gearwaterproof.com"] [uri "/wp-login.php"] [unique_id "al4X_guRBFTcQNywdCL48gAB3C0"]
[Mon Jul 20 06:43:42.366591 2026] [security2:error] [pid 1014214:tid 1014446] [client 74.7.228.22:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shw.opy.mybluehost.me"] [uri "/index.php"] [unique_id "al4X_QuRBFTcQNywdCL4uQAAAfU"]
[Mon Jul 20 06:43:42.374995 2026] [security2:error] [pid 1011111:tid 1011253] [client 74.7.228.22:35414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "shw.opy.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4X_RXES7Mv0Zfga-kSZgAAkBg"]
[Mon Jul 20 06:43:42.383196 2026] [security2:error] [pid 1011111:tid 1011120] [remote 80.82.65.226:34546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4X_hXES7Mv0Zfga-kSuwAAwwc"]
[Mon Jul 20 06:43:42.459660 2026] [security2:error] [pid 1011111:tid 1011158] [remote 80.82.65.226:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_hXES7Mv0Zfga-kSvwAA5C0"]
[Mon Jul 20 06:43:42.549338 2026] [security2:error] [pid 1011111:tid 1011254] [client 57.141.18.93:33208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-RXES7Mv0Zfga-kRbgAAkRs"]
[Mon Jul 20 06:43:42.578955 2026] [security2:error] [pid 1014214:tid 1014459] [client 173.239.240.92:46365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X_guRBFTcQNywdCL4_QAAAgI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:42.594744 2026] [security2:error] [pid 1014214:tid 1014395] [client 185.19.32.111:59692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marscafe.com"] [uri "/php/forecast/covers.php3"] [unique_id "al4X_guRBFTcQNywdCL4-QAAAcI"]
[Mon Jul 20 06:43:42.597672 2026] [security2:error] [pid 1014214:tid 1014263] [remote 162.19.86.63:33626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gearwaterproof.com"] [uri "/wp-login.php"] [unique_id "al4X_guRBFTcQNywdCL4_wAByTA"], referer: https://gearwaterproof.com/wp-login.php
[Mon Jul 20 06:43:42.623171 2026] [security2:error] [pid 1014214:tid 1014411] [client 77.110.127.138:53484] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page/2*if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4X_guRBFTcQNywdCL5AAAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:42.688574 2026] [security2:error] [pid 1014214:tid 1014376] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_guRBFTcQNywdCL5AQABrzE"]
[Mon Jul 20 06:43:42.797373 2026] [proxy:error] [pid 1011111:tid 1011159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:42.797430 2026] [proxy_http:error] [pid 1011111:tid 1011159] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:42.797874 2026] [proxy:error] [pid 1011111:tid 1011159] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:42.797902 2026] [proxy_http:error] [pid 1011111:tid 1011159] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:42.859845 2026] [security2:error] [pid 1011111:tid 1011196] [remote 80.82.65.226:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/index.php"] [unique_id "al4X_hXES7Mv0Zfga-kS1AAA9lM"]
[Mon Jul 20 06:43:42.864922 2026] [security2:error] [pid 1011111:tid 1011229] [remote 80.82.65.226:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/cms/index.php"] [unique_id "al4X_hXES7Mv0Zfga-kS1QAA0HQ"]
[Mon Jul 20 06:43:42.894863 2026] [security2:error] [pid 1011111:tid 1011261] [client 103.125.179.95:49266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X_hXES7Mv0Zfga-kS2AAAAJg"]
[Mon Jul 20 06:43:42.894973 2026] [security2:error] [pid 1011111:tid 1011261] [client 103.125.179.95:49266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4X_hXES7Mv0Zfga-kS2AAAAJg"]
[Mon Jul 20 06:43:42.895144 2026] [security2:error] [pid 1014214:tid 1014443] [client 57.141.18.74:20738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-guRBFTcQNywdCL4OgAB8go"]
[Mon Jul 20 06:43:42.969349 2026] [security2:error] [pid 1014214:tid 1014461] [client 192.140.149.97:44976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4X_guRBFTcQNywdCL5DAAAAgQ"]
[Mon Jul 20 06:43:42.970588 2026] [security2:error] [pid 1014214:tid 1014461] [client 192.140.149.97:44976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4X_guRBFTcQNywdCL5DAAAAgQ"]
[Mon Jul 20 06:43:43.054982 2026] [security2:error] [pid 1014214:tid 1014426] [client 173.239.240.31:29101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4X_wuRBFTcQNywdCL5EAAAAeE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:43.205058 2026] [security2:error] [pid 1011111:tid 1011182] [remote 80.82.65.226:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4X_xXES7Mv0Zfga-kS6QAA9UU"]
[Mon Jul 20 06:43:43.214086 2026] [security2:error] [pid 1011111:tid 1011139] [remote 80.82.65.226:34558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/site/index.php"] [unique_id "al4X_xXES7Mv0Zfga-kS6gAAnRo"]
[Mon Jul 20 06:43:43.233124 2026] [security2:error] [pid 1011111:tid 1011184] [remote 80.82.65.226:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4X_xXES7Mv0Zfga-kS7gAArEc"]
[Mon Jul 20 06:43:43.281742 2026] [security2:error] [pid 1014214:tid 1014390] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_wuRBFTcQNywdCL5EwABvTU"]
[Mon Jul 20 06:43:43.373981 2026] [proxy:error] [pid 1011111:tid 1011119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:43.374068 2026] [proxy_http:error] [pid 1011111:tid 1011119] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:43.374923 2026] [proxy:error] [pid 1011111:tid 1011119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:43.374958 2026] [proxy_http:error] [pid 1011111:tid 1011119] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:43.413736 2026] [security2:error] [pid 1011111:tid 1011331] [client 106.219.188.178:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X_xXES7Mv0Zfga-kS_QAAAN4"]
[Mon Jul 20 06:43:43.413851 2026] [security2:error] [pid 1011111:tid 1011331] [client 106.219.188.178:59909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4X_xXES7Mv0Zfga-kS_QAAAN4"]
[Mon Jul 20 06:43:43.521453 2026] [security2:error] [pid 1011111:tid 1011208] [remote 47.86.33.52:51168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X_xXES7Mv0Zfga-kTAgAA-l8"]
[Mon Jul 20 06:43:43.521619 2026] [security2:error] [pid 1011111:tid 1011359] [client 47.86.33.52:51168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4X_xXES7Mv0Zfga-kTAgAA-l8"]
[Mon Jul 20 06:43:43.530171 2026] [security2:error] [pid 1014214:tid 1014453] [client 14.225.17.146:49332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4X_wuRBFTcQNywdCL5HwAAAfw"], referer: http://aljosour-alarabia.com/new
[Mon Jul 20 06:43:43.533766 2026] [security2:error] [pid 1014214:tid 1014352] [client 173.239.240.102:26283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4X_wuRBFTcQNywdCL5JgAAAZc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:43.554192 2026] [security2:error] [pid 1011111:tid 1011211] [remote 80.82.65.226:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4X_xXES7Mv0Zfga-kTBQAA3GI"]
[Mon Jul 20 06:43:43.621478 2026] [security2:error] [pid 1014214:tid 1014371] [client 13.71.159.57:12936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4X_wuRBFTcQNywdCL5LAAAAao"]
[Mon Jul 20 06:43:43.629362 2026] [security2:error] [pid 1011111:tid 1011220] [remote 80.82.65.226:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4X_xXES7Mv0Zfga-kTCgAAiGs"]
[Mon Jul 20 06:43:43.662502 2026] [security2:error] [pid 1014214:tid 1014407] [client 122.183.32.225:30414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X_wuRBFTcQNywdCL5LgAAAc4"]
[Mon Jul 20 06:43:43.662603 2026] [security2:error] [pid 1014214:tid 1014407] [client 122.183.32.225:30414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4X_wuRBFTcQNywdCL5LgAAAc4"]
[Mon Jul 20 06:43:43.719930 2026] [proxy:error] [pid 1011111:tid 1011197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:43.720012 2026] [proxy_http:error] [pid 1011111:tid 1011197] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:43.720596 2026] [proxy:error] [pid 1011111:tid 1011197] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:43.720625 2026] [proxy_http:error] [pid 1011111:tid 1011197] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:43.724286 2026] [security2:error] [pid 1014214:tid 1014350] [client 57.141.18.24:58974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-guRBFTcQNywdCL4SAABlQw"]
[Mon Jul 20 06:43:43.732842 2026] [security2:error] [pid 1014214:tid 1014381] [client 13.71.159.57:12936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4X_wuRBFTcQNywdCL5NQAAAbQ"]
[Mon Jul 20 06:43:43.843980 2026] [security2:error] [pid 1014214:tid 1014394] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4X_wuRBFTcQNywdCL5OQABwTs"]
[Mon Jul 20 06:43:43.854515 2026] [security2:error] [pid 1011111:tid 1011237] [remote 80.82.65.226:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4X_xXES7Mv0Zfga-kTHQAA-3w"]
[Mon Jul 20 06:43:43.939893 2026] [security2:error] [pid 1014214:tid 1014416] [client 77.110.127.138:53494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X_wuRBFTcQNywdCL5OwAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:43.939973 2026] [security2:error] [pid 1014214:tid 1014416] [client 77.110.127.138:53494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4X_wuRBFTcQNywdCL5OwAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:43.984188 2026] [security2:error] [pid 1014214:tid 1014461] [client 77.110.127.138:53495] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4X_wuRBFTcQNywdCL5PgAAAgQ"]
[Mon Jul 20 06:43:44.009239 2026] [security2:error] [pid 1011111:tid 1011249] [client 173.239.240.96:45261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YABXES7Mv0Zfga-kTIgAAAIw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:44.180251 2026] [security2:error] [pid 1011111:tid 1011116] [remote 80.82.65.226:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTKQAAhwM"]
[Mon Jul 20 06:43:44.207491 2026] [security2:error] [pid 1011111:tid 1011181] [remote 80.82.65.226:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTLAAA1UQ"]
[Mon Jul 20 06:43:44.245234 2026] [security2:error] [pid 1014214:tid 1014414] [client 57.141.18.125:37442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-wuRBFTcQNywdCL4YwAB1RI"]
[Mon Jul 20 06:43:44.320896 2026] [proxy:error] [pid 1011111:tid 1011166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:44.320977 2026] [proxy_http:error] [pid 1011111:tid 1011166] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:44.321512 2026] [proxy:error] [pid 1011111:tid 1011166] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:44.321538 2026] [proxy_http:error] [pid 1011111:tid 1011166] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:44.357331 2026] [security2:error] [pid 1014214:tid 1014421] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAAuRBFTcQNywdCL5SAAB3D4"]
[Mon Jul 20 06:43:44.390994 2026] [security2:error] [pid 1014214:tid 1014417] [client 183.82.98.154:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YAAuRBFTcQNywdCL5TQAAAdg"]
[Mon Jul 20 06:43:44.391115 2026] [security2:error] [pid 1014214:tid 1014417] [client 183.82.98.154:55790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YAAuRBFTcQNywdCL5TQAAAdg"]
[Mon Jul 20 06:43:44.445633 2026] [security2:error] [pid 1014214:tid 1014457] [client 112.208.70.94:45733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YAAuRBFTcQNywdCL5UAAAAgA"]
[Mon Jul 20 06:43:44.445782 2026] [security2:error] [pid 1014214:tid 1014457] [client 112.208.70.94:45733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YAAuRBFTcQNywdCL5UAAAAgA"]
[Mon Jul 20 06:43:44.479708 2026] [security2:error] [pid 1011111:tid 1011286] [client 136.144.35.249:58299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTQgAAALE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:44.485278 2026] [security2:error] [pid 1014214:tid 1014466] [client 45.3.53.220:32649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YAAuRBFTcQNywdCL5UQAAAgk"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:43:44.504604 2026] [security2:error] [pid 1011111:tid 1011343] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTQQAA6go"]
[Mon Jul 20 06:43:44.527437 2026] [security2:error] [pid 1011111:tid 1011324] [client 74.249.226.166:44739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YABXES7Mv0Zfga-kTQwAAANc"]
[Mon Jul 20 06:43:44.579798 2026] [security2:error] [pid 1011111:tid 1011245] [client 74.249.226.166:44739] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YABXES7Mv0Zfga-kTRQAAAIg"]
[Mon Jul 20 06:43:44.598909 2026] [security2:error] [pid 1011111:tid 1011269] [client 77.110.127.138:53499] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page/20'XOR(2*if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4YABXES7Mv0Zfga-kTRwAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:44.694055 2026] [security2:error] [pid 1011111:tid 1011151] [remote 80.82.65.226:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTSQAAkyY"]
[Mon Jul 20 06:43:44.705043 2026] [security2:error] [pid 1014214:tid 1014455] [client 57.141.18.52:52172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-wuRBFTcQNywdCL4fAAB_hU"]
[Mon Jul 20 06:43:44.748963 2026] [proxy:error] [pid 1011111:tid 1011155] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:44.749035 2026] [proxy_http:error] [pid 1011111:tid 1011155] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:44.749701 2026] [proxy:error] [pid 1011111:tid 1011155] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:44.749734 2026] [proxy_http:error] [pid 1011111:tid 1011155] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:44.808610 2026] [security2:error] [pid 1011111:tid 1011160] [remote 80.82.65.226:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTUAAA_S8"]
[Mon Jul 20 06:43:44.870651 2026] [security2:error] [pid 1011111:tid 1011202] [remote 80.82.65.226:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTUgAAy1k"]
[Mon Jul 20 06:43:44.925209 2026] [security2:error] [pid 1011111:tid 1011369] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTVAABBAQ"]
[Mon Jul 20 06:43:44.926372 2026] [security2:error] [pid 1014214:tid 1014402] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAAuRBFTcQNywdCL5YwAByUQ"]
[Mon Jul 20 06:43:44.947938 2026] [security2:error] [pid 1014214:tid 1014397] [client 173.239.240.92:59977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YAAuRBFTcQNywdCL5bAAAAcQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:44.955319 2026] [security2:error] [pid 1011111:tid 1011219] [remote 80.82.65.226:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTVwAA5mo"]
[Mon Jul 20 06:43:45.006908 2026] [security2:error] [pid 1011111:tid 1011114] [remote 162.19.86.63:37558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YARXES7Mv0Zfga-kTWQAAogE"]
[Mon Jul 20 06:43:45.082586 2026] [security2:error] [pid 1014214:tid 1014394] [client 45.3.45.133:53461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YAQuRBFTcQNywdCL5cwAAAcE"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:43:45.191172 2026] [security2:error] [pid 1014214:tid 1014467] [client 57.141.18.39:47939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X-wuRBFTcQNywdCL4iQACChk"]
[Mon Jul 20 06:43:45.231233 2026] [security2:error] [pid 1011111:tid 1011120] [remote 162.19.86.63:37558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YARXES7Mv0Zfga-kTaQAAyAc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:43:45.273978 2026] [security2:error] [pid 1011111:tid 1011235] [remote 80.82.65.226:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTbAAAino"]
[Mon Jul 20 06:43:45.305414 2026] [security2:error] [pid 1011111:tid 1011158] [remote 80.82.65.226:42952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTbgAAhy0"]
[Mon Jul 20 06:43:45.318619 2026] [proxy:error] [pid 1011111:tid 1011140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:45.318689 2026] [proxy_http:error] [pid 1011111:tid 1011140] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:45.319189 2026] [proxy:error] [pid 1011111:tid 1011140] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:45.319217 2026] [proxy_http:error] [pid 1011111:tid 1011140] [remote 80.82.65.226:34546] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:45.342225 2026] [security2:error] [pid 1011111:tid 1011253] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTcAAAkD4"]
[Mon Jul 20 06:43:45.362420 2026] [security2:error] [pid 1014214:tid 1014470] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAQuRBFTcQNywdCL5gQACDU8"]
[Mon Jul 20 06:43:45.421349 2026] [security2:error] [pid 1014214:tid 1014359] [client 173.239.240.32:33029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YAQuRBFTcQNywdCL5hAAAAZ4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:45.476135 2026] [security2:error] [pid 1014214:tid 1014296] [remote 57.141.18.73:34850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4YAQuRBFTcQNywdCL5hgABoVE"]
[Mon Jul 20 06:43:45.523466 2026] [security2:error] [pid 1011111:tid 1011203] [remote 80.82.65.226:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTfAAA3lo"]
[Mon Jul 20 06:43:45.636473 2026] [security2:error] [pid 1011111:tid 1011144] [remote 80.82.65.226:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTgAAA-h8"]
[Mon Jul 20 06:43:45.793853 2026] [security2:error] [pid 1011111:tid 1011292] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTiAAAtww"]
[Mon Jul 20 06:43:45.847766 2026] [security2:error] [pid 1011111:tid 1011183] [remote 84.247.172.23:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4YARXES7Mv0Zfga-kTiwAA70Y"]
[Mon Jul 20 06:43:45.874592 2026] [security2:error] [pid 1014214:tid 1014386] [client 173.239.240.102:60043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YAQuRBFTcQNywdCL5mAAAAbk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:45.881293 2026] [security2:error] [pid 1011111:tid 1011206] [remote 80.82.65.226:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YARXES7Mv0Zfga-kTjgAAvl0"]
[Mon Jul 20 06:43:45.920867 2026] [security2:error] [pid 1011111:tid 1011251] [client 57.141.18.54:23032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X_BXES7Mv0Zfga-kSOgAAjmw"]
[Mon Jul 20 06:43:46.078250 2026] [security2:error] [pid 1014214:tid 1014304] [remote 80.82.65.226:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAguRBFTcQNywdCL5ogABzlk"]
[Mon Jul 20 06:43:46.098839 2026] [security2:error] [pid 1011111:tid 1011246] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTlgAAiQg"]
[Mon Jul 20 06:43:46.100249 2026] [security2:error] [pid 1011111:tid 1011138] [remote 80.82.65.226:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/wp/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTmgAA4Rk"]
[Mon Jul 20 06:43:46.135696 2026] [security2:error] [pid 1011111:tid 1011349] [client 80.82.65.226:34558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTmwAA8HI"]
[Mon Jul 20 06:43:46.169819 2026] [security2:error] [pid 1011111:tid 1011184] [remote 80.82.65.226:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTnwAA90c"]
[Mon Jul 20 06:43:46.170941 2026] [security2:error] [pid 1011111:tid 1011141] [remote 84.247.172.23:36118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4YAhXES7Mv0Zfga-kToAAA5hw"], referer: https://grndl.com/wp-login.php
[Mon Jul 20 06:43:46.295283 2026] [security2:error] [pid 1014214:tid 1014435] [client 57.141.18.25:39522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X_QuRBFTcQNywdCL4sQAB6iM"]
[Mon Jul 20 06:43:46.329588 2026] [security2:error] [pid 1014214:tid 1014424] [client 136.144.35.251:32877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YAguRBFTcQNywdCL5rwAAAd8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:46.339306 2026] [security2:error] [pid 1011111:tid 1011136] [remote 80.82.65.226:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/wordpress/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTqgAArBc"]
[Mon Jul 20 06:43:46.347390 2026] [security2:error] [pid 1011111:tid 1011201] [remote 80.82.65.226:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTqwAAmlg"]
[Mon Jul 20 06:43:46.452808 2026] [security2:error] [pid 1011111:tid 1011210] [remote 80.82.65.226:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTrgAAj2E"]
[Mon Jul 20 06:43:46.505087 2026] [autoindex:error] [pid 1014214:tid 1014458] [client 167.86.82.167:61913] AH01276: Cannot serve directory /home1/momheadq/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:43:46.579536 2026] [security2:error] [pid 1011111:tid 1011243] [client 187.108.85.186:50085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YAhXES7Mv0Zfga-kTtAAAAIY"]
[Mon Jul 20 06:43:46.579632 2026] [security2:error] [pid 1011111:tid 1011243] [client 187.108.85.186:50085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YAhXES7Mv0Zfga-kTtAAAAIY"]
[Mon Jul 20 06:43:46.602234 2026] [security2:error] [pid 1011111:tid 1011313] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTswAAzFI"]
[Mon Jul 20 06:43:46.613970 2026] [security2:error] [pid 1011111:tid 1011220] [remote 80.82.65.226:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/blog/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTtQAA7Ws"]
[Mon Jul 20 06:43:46.643148 2026] [security2:error] [pid 1011111:tid 1011191] [remote 80.82.65.226:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTtgAA2U4"]
[Mon Jul 20 06:43:46.649020 2026] [security2:error] [pid 1011111:tid 1011262] [client 14.225.17.146:49476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTrwAAAJk"], referer: http://myspineworld.com/new
[Mon Jul 20 06:43:46.687454 2026] [security2:error] [pid 1014214:tid 1014409] [client 171.61.165.146:7321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YAguRBFTcQNywdCL5vwAAAdA"]
[Mon Jul 20 06:43:46.687578 2026] [security2:error] [pid 1014214:tid 1014409] [client 171.61.165.146:7321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YAguRBFTcQNywdCL5vwAAAdA"]
[Mon Jul 20 06:43:46.804670 2026] [security2:error] [pid 1014214:tid 1014312] [remote 80.82.65.226:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YAguRBFTcQNywdCL5xAABn2E"]
[Mon Jul 20 06:43:46.869527 2026] [security2:error] [pid 1011111:tid 1011328] [client 136.144.35.249:31543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YAhXES7Mv0Zfga-kTwAAAANs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:46.917980 2026] [security2:error] [pid 1011111:tid 1011167] [remote 80.82.65.226:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTwQAAnDY"]
[Mon Jul 20 06:43:46.919543 2026] [security2:error] [pid 1014214:tid 1014355] [client 57.141.18.24:58990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4X_QuRBFTcQNywdCL42wABmik"]
[Mon Jul 20 06:43:46.972788 2026] [core:error] [pid 1014214:tid 1014352] [client 14.225.17.146:49412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/new
[Mon Jul 20 06:43:46.972808 2026] [core:error] [pid 1014214:tid 1014352] [client 14.225.17.146:49412] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/new
[Mon Jul 20 06:43:46.985158 2026] [security2:error] [pid 1014214:tid 1014317] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YAguRBFTcQNywdCL50QAB6GY"]
[Mon Jul 20 06:43:46.985409 2026] [security2:error] [pid 1014214:tid 1014433] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YAguRBFTcQNywdCL50QAB6GY"]
[Mon Jul 20 06:43:47.015322 2026] [security2:error] [pid 1011111:tid 1011189] [remote 80.82.65.226:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kTxQAAxkw"]
[Mon Jul 20 06:43:47.093043 2026] [proxy:error] [pid 1011111:tid 1011178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:47.093132 2026] [proxy_http:error] [pid 1011111:tid 1011178] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:47.093713 2026] [proxy:error] [pid 1011111:tid 1011178] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:47.093743 2026] [proxy_http:error] [pid 1011111:tid 1011178] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:47.099635 2026] [security2:error] [pid 1011111:tid 1011239] [remote 80.82.65.226:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/cms/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kTzAAA9n4"]
[Mon Jul 20 06:43:47.127310 2026] [security2:error] [pid 1014214:tid 1014430] [client 103.238.106.162:60971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YAwuRBFTcQNywdCL52gAAAeU"]
[Mon Jul 20 06:43:47.127418 2026] [security2:error] [pid 1014214:tid 1014430] [client 103.238.106.162:60971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YAwuRBFTcQNywdCL52gAAAeU"]
[Mon Jul 20 06:43:47.148857 2026] [security2:error] [pid 1011111:tid 1011287] [client 39.48.81.23:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kTzgAAALI"]
[Mon Jul 20 06:43:47.152477 2026] [security2:error] [pid 1011111:tid 1011287] [client 39.48.81.23:51991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kTzgAAALI"]
[Mon Jul 20 06:43:47.307237 2026] [security2:error] [pid 1011111:tid 1011314] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT2AAAzQM"]
[Mon Jul 20 06:43:47.311605 2026] [security2:error] [pid 1011111:tid 1011339] [client 77.110.127.138:53526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YAxXES7Mv0Zfga-kT2wAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:47.311707 2026] [security2:error] [pid 1011111:tid 1011339] [client 77.110.127.138:53526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YAxXES7Mv0Zfga-kT2wAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:47.329038 2026] [security2:error] [pid 1011111:tid 1011228] [remote 80.82.65.226:52458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT3gAAnnM"]
[Mon Jul 20 06:43:47.336860 2026] [security2:error] [pid 1011111:tid 1011181] [remote 80.82.65.226:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT3wABBEQ"]
[Mon Jul 20 06:43:47.343687 2026] [security2:error] [pid 1011111:tid 1011330] [client 136.144.35.249:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT4AAAAN0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:47.420616 2026] [security2:error] [pid 1014214:tid 1014462] [client 14.225.17.146:56680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4YAguRBFTcQNywdCL5swAAAgU"]
[Mon Jul 20 06:43:47.461683 2026] [security2:error] [pid 1014214:tid 1014391] [client 14.225.17.146:63585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4YAguRBFTcQNywdCL5xwAAAb4"]
[Mon Jul 20 06:43:47.485576 2026] [security2:error] [pid 1014214:tid 1014326] [remote 80.82.65.226:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YAwuRBFTcQNywdCL55gABtm8"]
[Mon Jul 20 06:43:47.523555 2026] [security2:error] [pid 1011111:tid 1011359] [client 152.58.191.29:61215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kT6QAAAPo"]
[Mon Jul 20 06:43:47.525158 2026] [security2:error] [pid 1011111:tid 1011359] [client 152.58.191.29:61215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kT6QAAAPo"]
[Mon Jul 20 06:43:47.539337 2026] [security2:error] [pid 1011111:tid 1011258] [client 74.7.241.144:58308] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "genesisventuregrp.com"] [uri "/robots.txt"] [unique_id "al4YAxXES7Mv0Zfga-kT6gAAAJU"]
[Mon Jul 20 06:43:47.541104 2026] [security2:error] [pid 1011111:tid 1011297] [client 117.247.108.24:59175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kT6AAAALw"]
[Mon Jul 20 06:43:47.541329 2026] [security2:error] [pid 1011111:tid 1011297] [client 117.247.108.24:59175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kT6AAAALw"]
[Mon Jul 20 06:43:47.547349 2026] [security2:error] [pid 1011111:tid 1011198] [remote 80.82.65.226:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT6wAAoVU"]
[Mon Jul 20 06:43:47.619974 2026] [security2:error] [pid 1011111:tid 1011290] [client 14.225.17.146:49492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT5AAAALU"], referer: https://myspineworld.com/new
[Mon Jul 20 06:43:47.620710 2026] [proxy:error] [pid 1011111:tid 1011163] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:47.620803 2026] [proxy_http:error] [pid 1011111:tid 1011163] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:47.622167 2026] [proxy:error] [pid 1011111:tid 1011163] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:47.622204 2026] [proxy_http:error] [pid 1011111:tid 1011163] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:47.650669 2026] [security2:error] [pid 1011111:tid 1011260] [client 217.142.18.172:27772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kT8gAAAJc"]
[Mon Jul 20 06:43:47.650803 2026] [security2:error] [pid 1011111:tid 1011260] [client 217.142.18.172:27772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YAxXES7Mv0Zfga-kT8gAAAJc"]
[Mon Jul 20 06:43:47.666974 2026] [core:error] [pid 1011111:tid 1011123] [remote 74.7.241.144:38382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/robots.txt
[Mon Jul 20 06:43:47.666991 2026] [core:error] [pid 1011111:tid 1011123] [remote 74.7.241.144:38382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/robots.txt
[Mon Jul 20 06:43:47.667188 2026] [security2:error] [pid 1011111:tid 1011244] [client 74.7.241.144:38382] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "500"] [hostname "genesisventuregrp.com"] [uri "/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kT8wAAhwo"], referer: http://genesisventuregrp.com/robots.txt
[Mon Jul 20 06:43:47.677583 2026] [security2:error] [pid 1014214:tid 1014387] [client 46.110.96.34:60192] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL57AAAAbo"]
[Mon Jul 20 06:43:47.680321 2026] [security2:error] [pid 1011111:tid 1011346] [client 46.110.96.34:45019] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAxXES7Mv0Zfga-kT9gAAAO0"]
[Mon Jul 20 06:43:47.680323 2026] [security2:error] [pid 1011111:tid 1011313] [client 46.110.96.34:14044] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAxXES7Mv0Zfga-kT9QAAAMw"]
[Mon Jul 20 06:43:47.752003 2026] [security2:error] [pid 1014214:tid 1014369] [client 46.110.96.34:2073] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL57gAAAag"]
[Mon Jul 20 06:43:47.765225 2026] [security2:error] [pid 1011111:tid 1011331] [client 46.110.96.34:28461] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAxXES7Mv0Zfga-kT_QAAAN4"]
[Mon Jul 20 06:43:47.765290 2026] [security2:error] [pid 1014214:tid 1014418] [client 46.110.96.34:50417] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL58QAAAdk"]
[Mon Jul 20 06:43:47.765292 2026] [security2:error] [pid 1014214:tid 1014377] [client 46.110.96.34:9712] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL57wAAAbA"]
[Mon Jul 20 06:43:47.765395 2026] [security2:error] [pid 1014214:tid 1014365] [client 46.110.96.34:52720] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL58gAAAaQ"]
[Mon Jul 20 06:43:47.765413 2026] [security2:error] [pid 1014214:tid 1014350] [client 46.110.96.34:21579] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL58AAAAZU"]
[Mon Jul 20 06:43:47.765573 2026] [security2:error] [pid 1011111:tid 1011305] [client 46.110.96.34:1838] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAxXES7Mv0Zfga-kT_gAAAMQ"]
[Mon Jul 20 06:43:47.766266 2026] [security2:error] [pid 1014214:tid 1014371] [client 46.110.96.34:56496] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL58wAAAao"]
[Mon Jul 20 06:43:47.766742 2026] [security2:error] [pid 1014214:tid 1014399] [client 46.110.96.34:4756] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL59AAAAcY"]
[Mon Jul 20 06:43:47.768549 2026] [security2:error] [pid 1014214:tid 1014367] [client 46.110.96.34:56304] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL59gAAAaY"]
[Mon Jul 20 06:43:47.773867 2026] [security2:error] [pid 1014214:tid 1014456] [client 46.110.96.34:41733] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YAwuRBFTcQNywdCL5-AAAAf8"]
[Mon Jul 20 06:43:47.799206 2026] [security2:error] [pid 1011111:tid 1011332] [client 173.239.240.95:21331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YAxXES7Mv0Zfga-kUAAAAAN8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:47.868128 2026] [security2:error] [pid 1014214:tid 1014332] [remote 80.82.65.226:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YAwuRBFTcQNywdCL5_gABs3U"]
[Mon Jul 20 06:43:47.887930 2026] [security2:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:52470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/site/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kUBQABAE0"]
[Mon Jul 20 06:43:47.911821 2026] [security2:error] [pid 1011111:tid 1011318] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kUBAAA0R4"]
[Mon Jul 20 06:43:47.945677 2026] [security2:error] [pid 1014214:tid 1014333] [remote 80.82.65.226:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YAwuRBFTcQNywdCL6AAAB83Y"]
[Mon Jul 20 06:43:48.002412 2026] [security2:error] [pid 1011111:tid 1011207] [remote 80.82.65.226:42956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUCwAAu14"]
[Mon Jul 20 06:43:48.040504 2026] [security2:error] [pid 1011111:tid 1011222] [remote 80.82.65.226:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUDQAA720"]
[Mon Jul 20 06:43:48.134300 2026] [security2:error] [pid 1014214:tid 1014401] [client 158.173.241.141:60195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4YAwuRBFTcQNywdCL5_wAAAcg"], referer: http://sesamegreenbeans.com/nine-days-south-africa-v/
[Mon Jul 20 06:43:48.217635 2026] [proxy:error] [pid 1011111:tid 1011124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:48.217707 2026] [proxy_http:error] [pid 1011111:tid 1011124] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:48.218322 2026] [proxy:error] [pid 1011111:tid 1011124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:48.218356 2026] [proxy_http:error] [pid 1011111:tid 1011124] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:48.267259 2026] [security2:error] [pid 1014214:tid 1014373] [client 173.239.240.100:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YBAuRBFTcQNywdCL6EgAAAaw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:48.337263 2026] [security2:error] [pid 1011111:tid 1011274] [client 57.141.18.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUFQAAAKU"]
[Mon Jul 20 06:43:48.401612 2026] [security2:error] [pid 1014214:tid 1014339] [remote 80.82.65.226:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YBAuRBFTcQNywdCL6GAAB33w"]
[Mon Jul 20 06:43:48.406013 2026] [security2:error] [pid 1014214:tid 1014368] [client 50.116.65.227:56440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4YBAuRBFTcQNywdCL6GQAAAac"]
[Mon Jul 20 06:43:48.415602 2026] [security2:error] [pid 1011111:tid 1011317] [client 80.82.65.226:45558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUJAAA0Ac"]
[Mon Jul 20 06:43:48.419626 2026] [security2:error] [pid 1011111:tid 1011364] [client 50.116.65.227:54484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4YBBXES7Mv0Zfga-kUJgAAAIk"]
[Mon Jul 20 06:43:48.486916 2026] [security2:error] [pid 1014214:tid 1014341] [remote 80.82.65.226:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YBAuRBFTcQNywdCL6GwAB-34"]
[Mon Jul 20 06:43:48.488599 2026] [security2:error] [pid 1011111:tid 1011168] [remote 80.82.65.226:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUKwAAtTc"]
[Mon Jul 20 06:43:48.502445 2026] [security2:error] [pid 1014214:tid 1014468] [client 77.110.127.138:53539] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-classes/page/20\\"XOR(2*if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4YBAuRBFTcQNywdCL6HAAAAgs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:48.503017 2026] [security2:error] [pid 1011111:tid 1011247] [client 46.110.96.34:26915] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YBBXES7Mv0Zfga-kULAAAAIo"]
[Mon Jul 20 06:43:48.634972 2026] [security2:error] [pid 1011111:tid 1011366] [client 74.7.241.170:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "theessencecatering.com"] [uri "/index.php"] [unique_id "al4X-hXES7Mv0Zfga-kRigABASQ"]
[Mon Jul 20 06:43:48.669827 2026] [security2:error] [pid 1014214:tid 1014216] [remote 80.82.65.226:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YBAuRBFTcQNywdCL6HgACCQE"]
[Mon Jul 20 06:43:48.698738 2026] [security2:error] [pid 1011111:tid 1011261] [client 14.225.17.146:49555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4YAxXES7Mv0Zfga-kUAgAAAJg"], referer: http://processorstudio.com/new
[Mon Jul 20 06:43:48.718855 2026] [security2:error] [pid 1011111:tid 1011313] [client 136.144.35.253:32067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUPwAAAMw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:48.779693 2026] [security2:error] [pid 1014214:tid 1014392] [client 14.225.17.146:49399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4YAguRBFTcQNywdCL50gAAAb8"], referer: http://aandarealtygroup.com/new
[Mon Jul 20 06:43:48.812617 2026] [security2:error] [pid 1011111:tid 1011348] [client 50.116.65.227:56446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4YBBXES7Mv0Zfga-kURwAAAO8"]
[Mon Jul 20 06:43:48.825695 2026] [security2:error] [pid 1011111:tid 1011298] [client 50.116.65.227:54506] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4YBBXES7Mv0Zfga-kUSQAAAL0"]
[Mon Jul 20 06:43:48.893545 2026] [security2:error] [pid 1014214:tid 1014387] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YBAuRBFTcQNywdCL6KwABugQ"]
[Mon Jul 20 06:43:48.932110 2026] [security2:error] [pid 1011111:tid 1011324] [client 54.238.43.39:40312] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "vfcthomasville.org"] [uri "/wp-json/batch/v1"] [unique_id "al4YBBXES7Mv0Zfga-kUSwAAANc"]
[Mon Jul 20 06:43:48.953269 2026] [proxy:error] [pid 1011111:tid 1011125] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:48.953369 2026] [proxy_http:error] [pid 1011111:tid 1011125] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:48.954000 2026] [proxy:error] [pid 1011111:tid 1011125] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:48.954032 2026] [proxy_http:error] [pid 1011111:tid 1011125] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:48.980687 2026] [security2:error] [pid 1011111:tid 1011300] [client 57.141.18.78:56042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YABXES7Mv0Zfga-kTJgAAv3U"]
[Mon Jul 20 06:43:49.016424 2026] [security2:error] [pid 1014214:tid 1014222] [remote 80.82.65.226:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6LwABxgc"]
[Mon Jul 20 06:43:49.045830 2026] [security2:error] [pid 1011111:tid 1011333] [client 104.234.53.49:26667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "getgarrison.com"] [uri "/wp-login.php"] [unique_id "al4YBRXES7Mv0Zfga-kUUgAAAOA"], referer: https://www.google.com/
[Mon Jul 20 06:43:49.076037 2026] [security2:error] [pid 1011111:tid 1011322] [client 14.225.17.146:63903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4YAhXES7Mv0Zfga-kTugAAANU"], referer: http://mrbambooplus.com/new
[Mon Jul 20 06:43:49.092479 2026] [security2:error] [pid 1014214:tid 1014417] [client 13.233.207.33:26946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YBQuRBFTcQNywdCL6MAAAAdg"]
[Mon Jul 20 06:43:49.169069 2026] [security2:error] [pid 1014214:tid 1014367] [client 173.239.240.100:28393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YBQuRBFTcQNywdCL6OQAAAaY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:49.199402 2026] [security2:error] [pid 1011111:tid 1011133] [remote 80.82.65.226:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YBRXES7Mv0Zfga-kUWwAAjRQ"]
[Mon Jul 20 06:43:49.206507 2026] [proxy:error] [pid 1014214:tid 1014411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:49.206551 2026] [proxy_http:error] [pid 1014214:tid 1014411] [client 34.73.38.214:63807] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:49.207539 2026] [proxy:error] [pid 1014214:tid 1014411] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:49.207577 2026] [proxy_http:error] [pid 1014214:tid 1014411] [client 34.73.38.214:63807] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:49.356651 2026] [proxy:error] [pid 1011111:tid 1011213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:49.356738 2026] [proxy_http:error] [pid 1011111:tid 1011213] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:49.357545 2026] [proxy:error] [pid 1011111:tid 1011213] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:49.357577 2026] [proxy_http:error] [pid 1011111:tid 1011213] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:49.362280 2026] [security2:error] [pid 1014214:tid 1014453] [client 46.110.96.34:13145] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YBQuRBFTcQNywdCL6SAAAAfw"]
[Mon Jul 20 06:43:49.401609 2026] [security2:error] [pid 1014214:tid 1014446] [client 46.110.96.34:44827] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YBQuRBFTcQNywdCL6TAAAAfU"]
[Mon Jul 20 06:43:49.437568 2026] [security2:error] [pid 1014214:tid 1014471] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6SgACDgk"]
[Mon Jul 20 06:43:49.542762 2026] [security2:error] [pid 1014214:tid 1014234] [remote 80.82.65.226:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6UwABzxM"]
[Mon Jul 20 06:43:49.543588 2026] [security2:error] [pid 1014214:tid 1014393] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6SwAAAcA"]
[Mon Jul 20 06:43:49.554202 2026] [security2:error] [pid 1011111:tid 1011247] [client 54.238.43.39:40326] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "vfcthomasville.org"] [uri "/"] [unique_id "al4YBRXES7Mv0Zfga-kUbQAAAIo"]
[Mon Jul 20 06:43:49.560439 2026] [security2:error] [pid 1014214:tid 1014361] [client 14.225.17.146:62706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4YBAuRBFTcQNywdCL6BwAAAaA"], referer: http://alexsandbergmusic.com/new
[Mon Jul 20 06:43:49.565473 2026] [security2:error] [pid 1014214:tid 1014397] [client 14.225.17.146:62564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6UgAAAcQ"], referer: https://processorstudio.com/new
[Mon Jul 20 06:43:49.622726 2026] [security2:error] [pid 1014214:tid 1014462] [client 173.239.240.30:24269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6WQAAAgU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:49.710647 2026] [proxy:error] [pid 1011111:tid 1011210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:49.710738 2026] [proxy_http:error] [pid 1011111:tid 1011210] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:49.711714 2026] [proxy:error] [pid 1011111:tid 1011210] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:49.711792 2026] [proxy_http:error] [pid 1011111:tid 1011210] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:49.730015 2026] [security2:error] [pid 1011111:tid 1011211] [remote 8.217.108.67:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YBRXES7Mv0Zfga-kUeAAAx2I"]
[Mon Jul 20 06:43:49.794287 2026] [security2:error] [pid 1014214:tid 1014231] [remote 80.82.65.226:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6ZAAB_xA"]
[Mon Jul 20 06:43:49.877647 2026] [security2:error] [pid 1014214:tid 1014353] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6ZgABmBw"]
[Mon Jul 20 06:43:50.067560 2026] [security2:error] [pid 1014214:tid 1014245] [remote 80.82.65.226:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YBguRBFTcQNywdCL6bAAB5h4"]
[Mon Jul 20 06:43:50.068584 2026] [security2:error] [pid 1014214:tid 1014442] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YBguRBFTcQNywdCL6awAB8Ro"]
[Mon Jul 20 06:43:50.074594 2026] [security2:error] [pid 1011111:tid 1011280] [client 173.239.240.32:63249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YBhXES7Mv0Zfga-kUhwAAAKs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:50.208794 2026] [security2:error] [pid 1014214:tid 1014409] [client 14.225.17.146:63772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6aQAAAdA"], referer: http://dollpassionista.com/new
[Mon Jul 20 06:43:50.209249 2026] [security2:error] [pid 1011111:tid 1011324] [client 43.205.139.3:62888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YBhXES7Mv0Zfga-kUjgAAANc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:43:50.325133 2026] [security2:error] [pid 1014214:tid 1014242] [remote 80.82.65.226:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YBguRBFTcQNywdCL6dAABmxs"]
[Mon Jul 20 06:43:50.362045 2026] [security2:error] [pid 1011111:tid 1011178] [remote 80.82.65.226:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/index.php"] [unique_id "al4YBhXES7Mv0Zfga-kUlgAAiEE"]
[Mon Jul 20 06:43:50.526724 2026] [security2:error] [pid 1014214:tid 1014344] [client 136.144.35.253:58159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YBguRBFTcQNywdCL6fwAAAY8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:50.532441 2026] [security2:error] [pid 1011111:tid 1011214] [remote 80.82.65.226:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBhXES7Mv0Zfga-kUoAAAvGU"]
[Mon Jul 20 06:43:50.564889 2026] [security2:error] [pid 1014214:tid 1014463] [client 13.233.207.33:26960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YBguRBFTcQNywdCL6gAAAAgY"]
[Mon Jul 20 06:43:50.688934 2026] [security2:error] [pid 1014214:tid 1014249] [remote 80.82.65.226:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YBguRBFTcQNywdCL6igAB6iI"]
[Mon Jul 20 06:43:50.692736 2026] [security2:error] [pid 1011111:tid 1011273] [client 223.185.13.213:16631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YBhXES7Mv0Zfga-kUqQAAAKQ"]
[Mon Jul 20 06:43:50.692903 2026] [security2:error] [pid 1011111:tid 1011273] [client 223.185.13.213:16631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YBhXES7Mv0Zfga-kUqQAAAKQ"]
[Mon Jul 20 06:43:50.739845 2026] [security2:error] [pid 1014214:tid 1014392] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBguRBFTcQNywdCL6iwABvyQ"]
[Mon Jul 20 06:43:50.760421 2026] [security2:error] [pid 1011111:tid 1011176] [remote 8.217.108.67:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YBhXES7Mv0Zfga-kUrgAA7T8"], referer: https://mail.ait.afz.mybluehost.me/wp-login.php
[Mon Jul 20 06:43:50.767811 2026] [proxy:error] [pid 1014214:tid 1014217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:50.767863 2026] [proxy_http:error] [pid 1014214:tid 1014217] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:50.769085 2026] [proxy:error] [pid 1014214:tid 1014217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:50.769127 2026] [proxy_http:error] [pid 1014214:tid 1014217] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:50.916040 2026] [security2:error] [pid 1011111:tid 1011205] [remote 80.82.65.226:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YBhXES7Mv0Zfga-kUuAAAmFw"]
[Mon Jul 20 06:43:50.918266 2026] [security2:error] [pid 1014214:tid 1014253] [remote 80.82.65.226:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/index.php"] [unique_id "al4YBguRBFTcQNywdCL6jwACByY"]
[Mon Jul 20 06:43:50.987269 2026] [security2:error] [pid 1014214:tid 1014255] [remote 80.82.65.226:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YBguRBFTcQNywdCL6lAABnCg"]
[Mon Jul 20 06:43:50.988527 2026] [security2:error] [pid 1014214:tid 1014408] [client 37.52.210.45:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YBguRBFTcQNywdCL6kgAAAc8"]
[Mon Jul 20 06:43:50.988641 2026] [security2:error] [pid 1014214:tid 1014408] [client 37.52.210.45:52884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YBguRBFTcQNywdCL6kgAAAc8"]
[Mon Jul 20 06:43:50.994163 2026] [security2:error] [pid 1014214:tid 1014422] [client 136.144.35.249:58537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YBguRBFTcQNywdCL6lQAAAd0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:51.026017 2026] [security2:error] [pid 1014214:tid 1014362] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YBguRBFTcQNywdCL6kwABoSc"]
[Mon Jul 20 06:43:51.049432 2026] [security2:error] [pid 1014214:tid 1014417] [client 77.110.127.138:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YBwuRBFTcQNywdCL6lwAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:51.049540 2026] [security2:error] [pid 1014214:tid 1014417] [client 77.110.127.138:53584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YBwuRBFTcQNywdCL6lwAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:51.080853 2026] [security2:error] [pid 1014214:tid 1014368] [client 14.225.17.146:62749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6YAAAAac"], referer: http://chestermonty.com/new
[Mon Jul 20 06:43:51.173132 2026] [proxy:error] [pid 1014214:tid 1014221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:51.173223 2026] [proxy_http:error] [pid 1014214:tid 1014221] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:51.174100 2026] [proxy:error] [pid 1014214:tid 1014221] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:51.174140 2026] [proxy_http:error] [pid 1014214:tid 1014221] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:51.206142 2026] [security2:error] [pid 1011111:tid 1011255] [client 14.225.17.146:60212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kUwAAAAJI"], referer: https://dollpassionista.com/new
[Mon Jul 20 06:43:51.212344 2026] [security2:error] [pid 1011111:tid 1011307] [client 14.225.17.146:56447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4YBhXES7Mv0Zfga-kUjAAAAMY"], referer: http://adultdaycarereno.com/new
[Mon Jul 20 06:43:51.214543 2026] [security2:error] [pid 1011111:tid 1011135] [remote 80.82.65.226:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kUyAAA2BY"]
[Mon Jul 20 06:43:51.260385 2026] [security2:error] [pid 1014214:tid 1014425] [client 104.234.53.76:56547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "getgarrison.com"] [uri "/wp-login.php"] [unique_id "al4YBwuRBFTcQNywdCL6ogAAAeA"], referer: https://t.co/
[Mon Jul 20 06:43:51.266008 2026] [security2:error] [pid 1011111:tid 1011202] [remote 80.82.65.226:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kUzQAA3Fk"]
[Mon Jul 20 06:43:51.335583 2026] [proxy:error] [pid 1014214:tid 1014450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:51.335657 2026] [proxy_http:error] [pid 1014214:tid 1014450] [client 34.73.38.214:57156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:51.336109 2026] [proxy:error] [pid 1014214:tid 1014450] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:51.336137 2026] [proxy_http:error] [pid 1014214:tid 1014450] [client 34.73.38.214:57156] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:51.355900 2026] [security2:error] [pid 1014214:tid 1014445] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6pwAB9Co"]
[Mon Jul 20 06:43:51.446344 2026] [autoindex:error] [pid 1011111:tid 1011366] [client 147.93.171.185:57777] AH01276: Cannot serve directory /home3/alaraycr/public_html/allisonsatterfield/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:43:51.454695 2026] [security2:error] [pid 1011111:tid 1011300] [client 114.119.148.165:44143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.oswegooperatheater.com"] [uri "/about-us/"] [unique_id "al4YBxXES7Mv0Zfga-kU1QAAAL8"], referer: https://www.oswegooperatheater.com/news/11th-annual-golf-tournament
[Mon Jul 20 06:43:51.457410 2026] [security2:error] [pid 1014214:tid 1014263] [remote 80.82.65.226:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6qQABljA"]
[Mon Jul 20 06:43:51.461656 2026] [security2:error] [pid 1011111:tid 1011321] [client 136.144.35.244:51271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kU1gAAANQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:51.492609 2026] [security2:error] [pid 1014214:tid 1014355] [client 65.1.132.125:19432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YBwuRBFTcQNywdCL6rAAAAZo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:43:51.503939 2026] [security2:error] [pid 1014214:tid 1014225] [remote 80.82.65.226:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6sQABvAo"]
[Mon Jul 20 06:43:51.573156 2026] [security2:error] [pid 1014214:tid 1014349] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6swABlDM"]
[Mon Jul 20 06:43:51.591522 2026] [security2:error] [pid 1011111:tid 1011236] [remote 80.82.65.226:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kU3QAA4Hs"]
[Mon Jul 20 06:43:51.679575 2026] [proxy:error] [pid 1014214:tid 1014268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:51.679637 2026] [proxy_http:error] [pid 1014214:tid 1014268] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:51.680104 2026] [proxy:error] [pid 1014214:tid 1014268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:51.680133 2026] [proxy_http:error] [pid 1014214:tid 1014268] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:51.738110 2026] [security2:error] [pid 1011111:tid 1011137] [remote 80.82.65.226:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kU4AAA1Rg"]
[Mon Jul 20 06:43:51.846904 2026] [security2:error] [pid 1014214:tid 1014386] [client 57.141.18.37:51174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YAwuRBFTcQNywdCL51AABuWc"]
[Mon Jul 20 06:43:51.883133 2026] [security2:error] [pid 1014214:tid 1014269] [remote 80.82.65.226:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6yAABqjY"]
[Mon Jul 20 06:43:51.914226 2026] [security2:error] [pid 1011111:tid 1011323] [client 173.239.240.100:55785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YBxXES7Mv0Zfga-kU6AAAANY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:51.951740 2026] [security2:error] [pid 1014214:tid 1014456] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6ygAB_zc"]
[Mon Jul 20 06:43:51.966568 2026] [security2:error] [pid 1014214:tid 1014272] [remote 80.82.65.226:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6zgABzzk"]
[Mon Jul 20 06:43:51.977010 2026] [security2:error] [pid 1011111:tid 1011161] [remote 80.82.65.226:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YBxXES7Mv0Zfga-kU7QAAijA"]
[Mon Jul 20 06:43:51.983314 2026] [security2:error] [pid 1014214:tid 1014392] [client 14.225.17.146:49841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6yQAAAb8"], referer: https://chestermonty.com/new
[Mon Jul 20 06:43:52.097379 2026] [security2:error] [pid 1011111:tid 1011140] [remote 80.82.65.226:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YCBXES7Mv0Zfga-kU8gAA9Bs"]
[Mon Jul 20 06:43:52.120206 2026] [security2:error] [pid 1011111:tid 1011297] [client 14.225.17.146:63601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4YCBXES7Mv0Zfga-kU8QAAALw"], referer: https://adultdaycarereno.com/new
[Mon Jul 20 06:43:52.201886 2026] [security2:error] [pid 1014214:tid 1014271] [remote 80.82.65.226:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YCAuRBFTcQNywdCL62QAB8zg"]
[Mon Jul 20 06:43:52.208062 2026] [proxy:error] [pid 1011111:tid 1011261] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.208125 2026] [proxy_http:error] [pid 1011111:tid 1011261] [client 34.73.38.214:64424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.208621 2026] [proxy:error] [pid 1011111:tid 1011261] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.208643 2026] [proxy_http:error] [pid 1011111:tid 1011261] [client 34.73.38.214:64424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.271880 2026] [security2:error] [pid 1014214:tid 1014356] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YCAuRBFTcQNywdCL63gABmxI"]
[Mon Jul 20 06:43:52.365533 2026] [security2:error] [pid 1014214:tid 1014416] [client 173.239.240.96:50305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YCAuRBFTcQNywdCL65gAAAdc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:52.376986 2026] [proxy:error] [pid 1014214:tid 1014277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.377035 2026] [proxy_http:error] [pid 1014214:tid 1014277] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.377432 2026] [proxy:error] [pid 1014214:tid 1014277] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.377453 2026] [proxy_http:error] [pid 1014214:tid 1014277] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.428178 2026] [security2:error] [pid 1014214:tid 1014278] [remote 80.82.65.226:45578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YCAuRBFTcQNywdCL66QAB7T8"]
[Mon Jul 20 06:43:52.471235 2026] [security2:error] [pid 1011111:tid 1011175] [remote 80.82.65.226:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YCBXES7Mv0Zfga-kVAQAA9j4"]
[Mon Jul 20 06:43:52.519246 2026] [security2:error] [pid 1011111:tid 1011304] [client 104.234.53.50:54827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "getgarrison.com"] [uri "/wp-login.php"] [unique_id "al4YCBXES7Mv0Zfga-kVAwAAAMM"]
[Mon Jul 20 06:43:52.545727 2026] [security2:error] [pid 1014214:tid 1014428] [client 80.82.65.226:45564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YCAuRBFTcQNywdCL68wAB40I"]
[Mon Jul 20 06:43:52.598874 2026] [proxy:error] [pid 1011111:tid 1011150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.598947 2026] [proxy_http:error] [pid 1011111:tid 1011150] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.599388 2026] [proxy:error] [pid 1011111:tid 1011150] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.599415 2026] [proxy_http:error] [pid 1011111:tid 1011150] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.608583 2026] [security2:error] [pid 1011111:tid 1011183] [remote 80.82.65.226:52486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YCBXES7Mv0Zfga-kVCwAAyUY"]
[Mon Jul 20 06:43:52.800292 2026] [security2:error] [pid 1014214:tid 1014285] [remote 80.82.65.226:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YCAuRBFTcQNywdCL6_QAB4kY"]
[Mon Jul 20 06:43:52.846798 2026] [security2:error] [pid 1011111:tid 1011280] [client 136.144.35.251:62699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YCBXES7Mv0Zfga-kVGAAAAKs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:52.850348 2026] [proxy:error] [pid 1014214:tid 1014240] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.850426 2026] [proxy_http:error] [pid 1014214:tid 1014240] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.851102 2026] [proxy:error] [pid 1014214:tid 1014240] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:52.851130 2026] [proxy_http:error] [pid 1014214:tid 1014240] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:52.909573 2026] [security2:error] [pid 1011111:tid 1011334] [client 57.141.18.87:57872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YBBXES7Mv0Zfga-kUHQAA4UI"]
[Mon Jul 20 06:43:52.934724 2026] [security2:error] [pid 1014214:tid 1014284] [remote 80.82.65.226:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YCAuRBFTcQNywdCL6_wAB80U"]
[Mon Jul 20 06:43:53.064457 2026] [security2:error] [pid 1011111:tid 1011138] [remote 80.82.65.226:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YCRXES7Mv0Zfga-kVIQAAvRk"]
[Mon Jul 20 06:43:53.147871 2026] [proxy:error] [pid 1011111:tid 1011115] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.147952 2026] [proxy_http:error] [pid 1011111:tid 1011115] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.148563 2026] [proxy:error] [pid 1011111:tid 1011115] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.148595 2026] [proxy_http:error] [pid 1011111:tid 1011115] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.310660 2026] [security2:error] [pid 1011111:tid 1011342] [client 136.144.35.245:58697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YCRXES7Mv0Zfga-kVNQAAAOk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:53.363150 2026] [security2:error] [pid 1011111:tid 1011316] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YCRXES7Mv0Zfga-kVNgAAz2I"]
[Mon Jul 20 06:43:53.374865 2026] [security2:error] [pid 1014214:tid 1014295] [remote 80.82.65.226:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YCQuRBFTcQNywdCL7DAABtlA"]
[Mon Jul 20 06:43:53.428728 2026] [proxy:error] [pid 1014214:tid 1014291] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.428815 2026] [proxy_http:error] [pid 1014214:tid 1014291] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.429391 2026] [proxy:error] [pid 1014214:tid 1014291] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.429434 2026] [proxy_http:error] [pid 1014214:tid 1014291] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.434391 2026] [security2:error] [pid 1014214:tid 1014421] [client 34.73.38.214:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/xmlrpc.php"] [unique_id "al4YCQuRBFTcQNywdCL7EgAAAdw"]
[Mon Jul 20 06:43:53.438912 2026] [proxy:error] [pid 1011111:tid 1011208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.438974 2026] [proxy_http:error] [pid 1011111:tid 1011208] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.439589 2026] [proxy:error] [pid 1011111:tid 1011208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.439619 2026] [proxy_http:error] [pid 1011111:tid 1011208] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.441381 2026] [security2:error] [pid 1011111:tid 1011349] [client 197.186.66.42:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YCRXES7Mv0Zfga-kVPQAAAPA"]
[Mon Jul 20 06:43:53.451177 2026] [security2:error] [pid 1011111:tid 1011349] [client 197.186.66.42:59634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YCRXES7Mv0Zfga-kVPQAAAPA"]
[Mon Jul 20 06:43:53.548265 2026] [security2:error] [pid 1014214:tid 1014296] [remote 80.82.65.226:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/wp/index.php"] [unique_id "al4YCQuRBFTcQNywdCL7FAAB71E"]
[Mon Jul 20 06:43:53.591916 2026] [proxy:error] [pid 1011111:tid 1011118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.592017 2026] [proxy_http:error] [pid 1011111:tid 1011118] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.592431 2026] [proxy:error] [pid 1011111:tid 1011118] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:53.592459 2026] [proxy_http:error] [pid 1011111:tid 1011118] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:53.712506 2026] [security2:error] [pid 1011111:tid 1011209] [remote 110.249.202.229:63568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/anatomy-of-an-implosion-christ-the-center-academic-work-we-do/"] [unique_id "al4YCRXES7Mv0Zfga-kVSwAA92A"]
[Mon Jul 20 06:43:53.715465 2026] [security2:error] [pid 1011111:tid 1011354] [client 103.125.179.95:49763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YCRXES7Mv0Zfga-kVTAAAAPU"]
[Mon Jul 20 06:43:53.716316 2026] [security2:error] [pid 1011111:tid 1011354] [client 103.125.179.95:49763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YCRXES7Mv0Zfga-kVTAAAAPU"]
[Mon Jul 20 06:43:53.717983 2026] [security2:error] [pid 1011111:tid 1011265] [client 50.116.65.227:20996] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4YCRXES7Mv0Zfga-kVTQAAAJw"]
[Mon Jul 20 06:43:53.727678 2026] [security2:error] [pid 1014214:tid 1014396] [client 50.116.65.227:39778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4YCQuRBFTcQNywdCL7GAAAAgE"]
[Mon Jul 20 06:43:53.737690 2026] [security2:error] [pid 1011111:tid 1011243] [client 192.140.149.97:44408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YCRXES7Mv0Zfga-kVTwAAAIY"]
[Mon Jul 20 06:43:53.737780 2026] [security2:error] [pid 1011111:tid 1011243] [client 192.140.149.97:44408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YCRXES7Mv0Zfga-kVTwAAAIY"]
[Mon Jul 20 06:43:53.802262 2026] [security2:error] [pid 1014214:tid 1014438] [client 136.144.35.245:54127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YCQuRBFTcQNywdCL7HAAAAe0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:53.840898 2026] [security2:error] [pid 1014214:tid 1014299] [remote 80.82.65.226:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YCQuRBFTcQNywdCL7IQABwFQ"]
[Mon Jul 20 06:43:53.883140 2026] [security2:error] [pid 1011111:tid 1011268] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YCRXES7Mv0Zfga-kVWAAAn38"]
[Mon Jul 20 06:43:53.969500 2026] [security2:error] [pid 1014214:tid 1014371] [client 39.48.81.23:52550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YCQuRBFTcQNywdCL7KQAAAao"]
[Mon Jul 20 06:43:53.969620 2026] [security2:error] [pid 1014214:tid 1014371] [client 39.48.81.23:52550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YCQuRBFTcQNywdCL7KQAAAao"]
[Mon Jul 20 06:43:53.993149 2026] [security2:error] [pid 1011111:tid 1011273] [client 34.73.38.214:57935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YCRXES7Mv0Zfga-kVYwAAAKQ"]
[Mon Jul 20 06:43:54.000768 2026] [proxy:error] [pid 1011111:tid 1011214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.000838 2026] [proxy_http:error] [pid 1011111:tid 1011214] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.001450 2026] [proxy:error] [pid 1011111:tid 1011214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.001487 2026] [proxy_http:error] [pid 1011111:tid 1011214] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.077967 2026] [security2:error] [pid 1014214:tid 1014344] [client 14.225.17.146:63281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4YCQuRBFTcQNywdCL7FgAAAY8"], referer: http://mollycahill.com/new
[Mon Jul 20 06:43:54.201529 2026] [security2:error] [pid 1011111:tid 1011318] [client 106.219.188.178:32950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YChXES7Mv0Zfga-kVbQAAANE"]
[Mon Jul 20 06:43:54.201968 2026] [security2:error] [pid 1011111:tid 1011318] [client 106.219.188.178:32950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YChXES7Mv0Zfga-kVbQAAANE"]
[Mon Jul 20 06:43:54.220338 2026] [security2:error] [pid 1011111:tid 1011330] [client 14.225.17.146:50921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4YChXES7Mv0Zfga-kVaQAAAN0"], referer: http://friendlyspreadsheet.com/new
[Mon Jul 20 06:43:54.274005 2026] [proxy:error] [pid 1011111:tid 1011116] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.274070 2026] [proxy_http:error] [pid 1011111:tid 1011116] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.274853 2026] [proxy:error] [pid 1011111:tid 1011116] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.274892 2026] [proxy_http:error] [pid 1011111:tid 1011116] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.277635 2026] [security2:error] [pid 1014214:tid 1014305] [remote 80.82.65.226:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/wordpress/index.php"] [unique_id "al4YCguRBFTcQNywdCL7MAAB8lo"]
[Mon Jul 20 06:43:54.311276 2026] [security2:error] [pid 1014214:tid 1014444] [client 136.144.35.252:60679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YCguRBFTcQNywdCL7MgAAAfM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:54.323662 2026] [security2:error] [pid 1014214:tid 1014359] [client 57.141.18.17:37932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YBQuRBFTcQNywdCL6XQABnhg"]
[Mon Jul 20 06:43:54.332587 2026] [lsapi:warn] [pid 1011111:tid 1011255] [client 15.204.114.164:12982] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: http://oldracelimited.com/
[Mon Jul 20 06:43:54.337874 2026] [lsapi:warn] [pid 1011111:tid 1011255] [client 15.204.114.164:12982] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: http://oldracelimited.com/
[Mon Jul 20 06:43:54.470131 2026] [security2:error] [pid 1014214:tid 1014309] [remote 80.82.65.226:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YCguRBFTcQNywdCL7OgABmF4"]
[Mon Jul 20 06:43:54.534854 2026] [security2:error] [pid 1011111:tid 1011336] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YChXES7Mv0Zfga-kViAAA41s"]
[Mon Jul 20 06:43:54.565162 2026] [security2:error] [pid 1014214:tid 1014349] [client 15.204.114.164:2884] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "oldracelimited.com"] [uri "/"] [unique_id "al4YCguRBFTcQNywdCL7PgAAAZQ"]
[Mon Jul 20 06:43:54.620400 2026] [proxy:error] [pid 1011111:tid 1011131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.620474 2026] [proxy_http:error] [pid 1011111:tid 1011131] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.621289 2026] [proxy:error] [pid 1011111:tid 1011131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.621338 2026] [proxy_http:error] [pid 1011111:tid 1011131] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.716366 2026] [security2:error] [pid 1014214:tid 1014467] [client 43.157.82.252:45594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.82.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/themes/daisy-theme/rslib/minify/load.php"] [unique_id "al4YCguRBFTcQNywdCL7RgAAAgo"]
[Mon Jul 20 06:43:54.737688 2026] [proxy:error] [pid 1011111:tid 1011190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.737787 2026] [proxy_http:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.738367 2026] [proxy:error] [pid 1011111:tid 1011190] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:54.738401 2026] [proxy_http:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:54.741500 2026] [security2:error] [pid 1014214:tid 1014312] [remote 80.82.65.226:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/blog/index.php"] [unique_id "al4YCguRBFTcQNywdCL7RwAB-GE"]
[Mon Jul 20 06:43:54.759636 2026] [security2:error] [pid 1014214:tid 1014387] [client 173.239.240.98:20195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YCguRBFTcQNywdCL7SAAAAbo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:54.863831 2026] [security2:error] [pid 1014214:tid 1014314] [remote 80.82.65.226:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YCguRBFTcQNywdCL7TwAB_WM"]
[Mon Jul 20 06:43:55.086274 2026] [security2:error] [pid 1014214:tid 1014471] [client 112.208.70.94:42157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YCwuRBFTcQNywdCL7WgAAAg4"]
[Mon Jul 20 06:43:55.086466 2026] [security2:error] [pid 1014214:tid 1014471] [client 112.208.70.94:42157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YCwuRBFTcQNywdCL7WgAAAg4"]
[Mon Jul 20 06:43:55.098999 2026] [security2:error] [pid 1014214:tid 1014433] [client 34.73.38.214:59844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YCwuRBFTcQNywdCL7WwAAAeg"]
[Mon Jul 20 06:43:55.205425 2026] [security2:error] [pid 1014214:tid 1014452] [client 14.225.17.146:65107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4YCwuRBFTcQNywdCL7WQAAAfs"]
[Mon Jul 20 06:43:55.230924 2026] [proxy:error] [pid 1011111:tid 1011117] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:55.230992 2026] [proxy_http:error] [pid 1011111:tid 1011117] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:55.231612 2026] [proxy:error] [pid 1011111:tid 1011117] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:55.231644 2026] [proxy_http:error] [pid 1011111:tid 1011117] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:55.234032 2026] [security2:error] [pid 1014214:tid 1014427] [client 136.144.35.251:39271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YCwuRBFTcQNywdCL7YgAAAeI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:55.246796 2026] [security2:error] [pid 1014214:tid 1014460] [client 183.82.98.154:56368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YCwuRBFTcQNywdCL7ZAAAAgM"]
[Mon Jul 20 06:43:55.246887 2026] [security2:error] [pid 1014214:tid 1014460] [client 183.82.98.154:56368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YCwuRBFTcQNywdCL7ZAAAAgM"]
[Mon Jul 20 06:43:55.253280 2026] [security2:error] [pid 1014214:tid 1014344] [client 77.110.127.138:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YCwuRBFTcQNywdCL7ZQAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:55.253373 2026] [security2:error] [pid 1014214:tid 1014344] [client 77.110.127.138:53605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YCwuRBFTcQNywdCL7ZQAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:55.288019 2026] [security2:error] [pid 1014214:tid 1014313] [remote 80.82.65.226:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YCwuRBFTcQNywdCL7aAAB9GI"]
[Mon Jul 20 06:43:55.332314 2026] [security2:error] [pid 1014214:tid 1014323] [remote 80.82.65.226:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/cms/index.php"] [unique_id "al4YCwuRBFTcQNywdCL7bgABsGw"]
[Mon Jul 20 06:43:55.332822 2026] [proxy:error] [pid 1011111:tid 1011217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:55.332900 2026] [proxy_http:error] [pid 1011111:tid 1011217] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:55.333687 2026] [proxy:error] [pid 1011111:tid 1011217] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:55.333731 2026] [proxy_http:error] [pid 1011111:tid 1011217] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:55.353996 2026] [security2:error] [pid 1011111:tid 1011316] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YCxXES7Mv0Zfga-kVsAAAz1A"]
[Mon Jul 20 06:43:55.418147 2026] [security2:error] [pid 1011111:tid 1011290] [client 14.224.227.113:54662] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YCxXES7Mv0Zfga-kVuQAAALU"]
[Mon Jul 20 06:43:55.662911 2026] [security2:error] [pid 1014214:tid 1014329] [remote 80.82.65.226:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YCwuRBFTcQNywdCL7hwABt3I"]
[Mon Jul 20 06:43:55.699568 2026] [security2:error] [pid 1014214:tid 1014396] [client 173.239.240.99:31889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YCwuRBFTcQNywdCL7iAAAAcM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:56.097785 2026] [security2:error] [pid 1014214:tid 1014414] [client 57.141.18.120:44024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6qgAB1S8"]
[Mon Jul 20 06:43:56.106834 2026] [security2:error] [pid 1011111:tid 1011293] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kV3wAAuC8"]
[Mon Jul 20 06:43:56.131898 2026] [security2:error] [pid 1014214:tid 1014334] [remote 80.82.65.226:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/site/index.php"] [unique_id "al4YDAuRBFTcQNywdCL7lwABpnc"]
[Mon Jul 20 06:43:56.137023 2026] [proxy:error] [pid 1011111:tid 1011232] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.137099 2026] [proxy_http:error] [pid 1011111:tid 1011232] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.137781 2026] [proxy:error] [pid 1011111:tid 1011232] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.137807 2026] [proxy_http:error] [pid 1011111:tid 1011232] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.154475 2026] [security2:error] [pid 1011111:tid 1011271] [client 173.239.240.92:24187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kV5AAAAKI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:56.159334 2026] [security2:error] [pid 1011111:tid 1011221] [remote 80.82.65.226:41376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kV5QAAiWw"]
[Mon Jul 20 06:43:56.227394 2026] [security2:error] [pid 1014214:tid 1014424] [client 57.141.18.55:22066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YBwuRBFTcQNywdCL6rwAB3zE"]
[Mon Jul 20 06:43:56.302095 2026] [security2:error] [pid 1014214:tid 1014336] [remote 8.217.108.67:30482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YDAuRBFTcQNywdCL7mwABrXk"]
[Mon Jul 20 06:43:56.302423 2026] [proxy:error] [pid 1011111:tid 1011309] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.302467 2026] [proxy_http:error] [pid 1011111:tid 1011309] [client 34.73.38.214:54414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.302952 2026] [proxy:error] [pid 1011111:tid 1011309] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.302980 2026] [proxy_http:error] [pid 1011111:tid 1011309] [client 34.73.38.214:54414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.370710 2026] [security2:error] [pid 1014214:tid 1014337] [remote 80.82.65.226:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YDAuRBFTcQNywdCL7ngAB3no"]
[Mon Jul 20 06:43:56.570028 2026] [security2:error] [pid 1011111:tid 1011300] [client 14.225.17.146:49875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kWBwAAAL8"], referer: http://thefriendlyspreadsheet.com/new
[Mon Jul 20 06:43:56.604389 2026] [security2:error] [pid 1011111:tid 1011299] [client 173.239.240.96:23823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YDBXES7Mv0Zfga-kWCwAAAL4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:56.631963 2026] [security2:error] [pid 1014214:tid 1014339] [remote 80.82.65.226:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YDAuRBFTcQNywdCL7pQAB3Hw"]
[Mon Jul 20 06:43:56.652986 2026] [security2:error] [pid 1011111:tid 1011296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kV_gAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:56.678913 2026] [proxy:error] [pid 1011111:tid 1011208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.679000 2026] [proxy_http:error] [pid 1011111:tid 1011208] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.679794 2026] [proxy:error] [pid 1011111:tid 1011208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.679838 2026] [proxy_http:error] [pid 1011111:tid 1011208] [remote 80.82.65.226:45582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.780064 2026] [proxy:error] [pid 1014214:tid 1014340] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.780131 2026] [proxy_http:error] [pid 1014214:tid 1014340] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.780700 2026] [proxy:error] [pid 1014214:tid 1014340] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:56.780726 2026] [proxy_http:error] [pid 1014214:tid 1014340] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:56.809898 2026] [security2:error] [pid 1014214:tid 1014353] [client 34.73.38.214:52561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YDAuRBFTcQNywdCL7rgAAAZg"]
[Mon Jul 20 06:43:56.814316 2026] [security2:error] [pid 1011111:tid 1011165] [remote 80.82.65.226:41376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kWEQABAzQ"]
[Mon Jul 20 06:43:56.910284 2026] [security2:error] [pid 1014214:tid 1014425] [client 57.141.18.75:64082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YCAuRBFTcQNywdCL63AAB4Do"]
[Mon Jul 20 06:43:56.937646 2026] [security2:error] [pid 1011111:tid 1011173] [remote 80.82.65.226:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kWFgAAiDw"]
[Mon Jul 20 06:43:57.011386 2026] [security2:error] [pid 1011111:tid 1011346] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kWGQAA7Sk"]
[Mon Jul 20 06:43:57.044556 2026] [access_compat:error] [pid 1014214:tid 1014341] [remote 82.40.71.187:44970] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:43:57.076223 2026] [security2:error] [pid 1014214:tid 1014396] [client 173.239.240.96:47777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YDQuRBFTcQNywdCL7vwAAAcM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:57.102761 2026] [security2:error] [pid 1014214:tid 1014385] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YDQuRBFTcQNywdCL7wAABuAU"]
[Mon Jul 20 06:43:57.179340 2026] [security2:error] [pid 1011111:tid 1011289] [client 65.111.3.236:56485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YDRXES7Mv0Zfga-kWJAAAALQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:57.201340 2026] [security2:error] [pid 1014214:tid 1014223] [remote 80.82.65.226:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YDQuRBFTcQNywdCL7wwACDQg"]
[Mon Jul 20 06:43:57.337605 2026] [security2:error] [pid 1011111:tid 1011228] [remote 80.82.65.226:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YDRXES7Mv0Zfga-kWLgAA33M"]
[Mon Jul 20 06:43:57.390560 2026] [proxy:error] [pid 1014214:tid 1014230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:57.390619 2026] [proxy_http:error] [pid 1014214:tid 1014230] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:57.391142 2026] [proxy:error] [pid 1014214:tid 1014230] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:57.391168 2026] [proxy_http:error] [pid 1014214:tid 1014230] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:57.445310 2026] [security2:error] [pid 1014214:tid 1014454] [client 187.108.85.186:50641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YDQuRBFTcQNywdCL71AAAAf0"]
[Mon Jul 20 06:43:57.445428 2026] [security2:error] [pid 1014214:tid 1014454] [client 187.108.85.186:50641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YDQuRBFTcQNywdCL71AAAAf0"]
[Mon Jul 20 06:43:57.469209 2026] [security2:error] [pid 1014214:tid 1014447] [client 171.61.165.146:14212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YDQuRBFTcQNywdCL71wAAAfY"]
[Mon Jul 20 06:43:57.470187 2026] [security2:error] [pid 1014214:tid 1014447] [client 171.61.165.146:14212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YDQuRBFTcQNywdCL71wAAAfY"]
[Mon Jul 20 06:43:57.532953 2026] [security2:error] [pid 1011111:tid 1011301] [client 173.239.240.100:35855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YDRXES7Mv0Zfga-kWOAAAAMA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:57.547708 2026] [security2:error] [pid 1014214:tid 1014282] [remote 80.82.65.226:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YDQuRBFTcQNywdCL73QAB3EM"]
[Mon Jul 20 06:43:57.549796 2026] [security2:error] [pid 1011111:tid 1011216] [remote 80.82.65.226:41376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YDRXES7Mv0Zfga-kWOQAA92c"]
[Mon Jul 20 06:43:57.678698 2026] [security2:error] [pid 1014214:tid 1014362] [client 103.238.106.162:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YDQuRBFTcQNywdCL75gAAAaE"]
[Mon Jul 20 06:43:57.678831 2026] [security2:error] [pid 1014214:tid 1014362] [client 103.238.106.162:60949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YDQuRBFTcQNywdCL75gAAAaE"]
[Mon Jul 20 06:43:57.683501 2026] [security2:error] [pid 1011111:tid 1011166] [remote 80.82.65.226:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YDRXES7Mv0Zfga-kWPQAAlDU"]
[Mon Jul 20 06:43:57.697391 2026] [security2:error] [pid 1011111:tid 1011200] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YDRXES7Mv0Zfga-kWPgAAx1c"]
[Mon Jul 20 06:43:57.697544 2026] [security2:error] [pid 1011111:tid 1011308] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YDRXES7Mv0Zfga-kWPgAAx1c"]
[Mon Jul 20 06:43:57.717025 2026] [security2:error] [pid 1014214:tid 1014359] [client 114.119.152.8:30645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "taskidsvirginia.com"] [uri "/robots.txt"] [unique_id "al4YDQuRBFTcQNywdCL76QAAAZ4"], referer: https://taskidsvirginia.com/robots.txt
[Mon Jul 20 06:43:57.880346 2026] [security2:error] [pid 1014214:tid 1014345] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YDQuRBFTcQNywdCL78AABkEo"]
[Mon Jul 20 06:43:57.906619 2026] [security2:error] [pid 1011111:tid 1011190] [remote 80.82.65.226:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YDRXES7Mv0Zfga-kWRgAA200"]
[Mon Jul 20 06:43:57.935526 2026] [proxy:error] [pid 1014214:tid 1014398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:57.935604 2026] [proxy_http:error] [pid 1014214:tid 1014398] [client 34.73.38.214:50817] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:57.936498 2026] [proxy:error] [pid 1014214:tid 1014398] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:57.936531 2026] [proxy_http:error] [pid 1014214:tid 1014398] [client 34.73.38.214:50817] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:57.984330 2026] [security2:error] [pid 1014214:tid 1014466] [client 136.144.35.245:23565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YDQuRBFTcQNywdCL79QAAAgk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:58.000337 2026] [security2:error] [pid 1011111:tid 1011268] [client 104.234.53.54:26203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YDRXES7Mv0Zfga-kWSQAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:43:58.058151 2026] [security2:error] [pid 1011111:tid 1011292] [client 57.141.18.109:52340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YCRXES7Mv0Zfga-kVQAAAt1I"]
[Mon Jul 20 06:43:58.126102 2026] [security2:error] [pid 1011111:tid 1011355] [client 57.141.18.98:22348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YCRXES7Mv0Zfga-kVQgAA9k4"]
[Mon Jul 20 06:43:58.157279 2026] [proxy:error] [pid 1014214:tid 1014243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:58.157347 2026] [proxy_http:error] [pid 1014214:tid 1014243] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:58.157806 2026] [proxy:error] [pid 1014214:tid 1014243] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:58.157830 2026] [proxy_http:error] [pid 1014214:tid 1014243] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:58.196502 2026] [security2:error] [pid 1011111:tid 1011134] [remote 80.82.65.226:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWTgAA4BU"]
[Mon Jul 20 06:43:58.200302 2026] [security2:error] [pid 1014214:tid 1014464] [client 217.142.18.172:14430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YDguRBFTcQNywdCL8AgAAAgc"]
[Mon Jul 20 06:43:58.206776 2026] [security2:error] [pid 1014214:tid 1014464] [client 217.142.18.172:14430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YDguRBFTcQNywdCL8AgAAAgc"]
[Mon Jul 20 06:43:58.264008 2026] [security2:error] [pid 1014214:tid 1014413] [client 152.58.191.29:62064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YDguRBFTcQNywdCL8CQAAAdQ"]
[Mon Jul 20 06:43:58.275667 2026] [security2:error] [pid 1014214:tid 1014413] [client 152.58.191.29:62064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YDguRBFTcQNywdCL8CQAAAdQ"]
[Mon Jul 20 06:43:58.283866 2026] [security2:error] [pid 1011111:tid 1011299] [client 117.247.108.24:21235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YDhXES7Mv0Zfga-kWUAAAAL4"]
[Mon Jul 20 06:43:58.283987 2026] [security2:error] [pid 1011111:tid 1011299] [client 117.247.108.24:21235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YDhXES7Mv0Zfga-kWUAAAAL4"]
[Mon Jul 20 06:43:58.365204 2026] [security2:error] [pid 1011111:tid 1011114] [remote 80.82.65.226:41376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWWQAAvQE"]
[Mon Jul 20 06:43:58.391598 2026] [security2:error] [pid 1014214:tid 1014251] [remote 80.82.65.226:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YDguRBFTcQNywdCL8FAABsyQ"]
[Mon Jul 20 06:43:58.432545 2026] [security2:error] [pid 1014214:tid 1014447] [client 173.239.240.32:35827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YDguRBFTcQNywdCL8GAAAAfY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:58.441272 2026] [security2:error] [pid 1014214:tid 1014450] [client 34.139.11.221:53934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YDguRBFTcQNywdCL8GQAAAfk"]
[Mon Jul 20 06:43:58.542690 2026] [security2:error] [pid 1014214:tid 1014401] [client 104.207.54.87:38825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YDguRBFTcQNywdCL8HwAAAcg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:43:58.543411 2026] [security2:error] [pid 1011111:tid 1011236] [remote 80.82.65.226:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWYAAA8ns"]
[Mon Jul 20 06:43:58.549214 2026] [security2:error] [pid 1014214:tid 1014417] [client 14.225.17.146:63405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4YDQuRBFTcQNywdCL7wQAAAdg"], referer: http://709fx.com/new
[Mon Jul 20 06:43:58.580872 2026] [security2:error] [pid 1014214:tid 1014365] [client 34.139.11.221:59488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YDguRBFTcQNywdCL8JQAAAaQ"]
[Mon Jul 20 06:43:58.654145 2026] [security2:error] [pid 1014214:tid 1014470] [client 50.116.65.227:39824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YDguRBFTcQNywdCL8LgAAAg0"]
[Mon Jul 20 06:43:58.655186 2026] [security2:error] [pid 1011111:tid 1011235] [remote 80.82.65.226:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWaQAAnXo"]
[Mon Jul 20 06:43:58.666883 2026] [security2:error] [pid 1014214:tid 1014438] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YDguRBFTcQNywdCL8LQAB7Sg"]
[Mon Jul 20 06:43:58.668280 2026] [security2:error] [pid 1014214:tid 1014399] [client 50.116.65.227:39826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YDguRBFTcQNywdCL8MAAAAcY"]
[Mon Jul 20 06:43:58.717280 2026] [security2:error] [pid 1014214:tid 1014452] [client 34.73.38.214:52662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YDguRBFTcQNywdCL8MQAAAfs"]
[Mon Jul 20 06:43:58.764695 2026] [security2:error] [pid 1014214:tid 1014405] [client 34.139.11.221:63205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YDguRBFTcQNywdCL8NAAAAcw"]
[Mon Jul 20 06:43:58.818097 2026] [security2:error] [pid 1014214:tid 1014436] [client 34.139.11.221:51287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YDguRBFTcQNywdCL8NwAAAes"]
[Mon Jul 20 06:43:58.876823 2026] [security2:error] [pid 1011111:tid 1011168] [remote 80.82.65.226:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWcAAArzc"]
[Mon Jul 20 06:43:58.876835 2026] [security2:error] [pid 1011111:tid 1011234] [remote 80.82.65.226:41376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWcQAA1Xk"]
[Mon Jul 20 06:43:58.889620 2026] [security2:error] [pid 1011111:tid 1011338] [client 173.239.240.100:49847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YDhXES7Mv0Zfga-kWcwAAAOU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:58.925370 2026] [security2:error] [pid 1014214:tid 1014221] [remote 80.82.65.226:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YDguRBFTcQNywdCL8PQABoQY"]
[Mon Jul 20 06:43:58.949478 2026] [security2:error] [pid 1011111:tid 1011354] [client 34.139.11.221:62479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YDhXES7Mv0Zfga-kWdgAAAPU"]
[Mon Jul 20 06:43:59.006155 2026] [security2:error] [pid 1014214:tid 1014353] [client 34.139.11.221:53327] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YDwuRBFTcQNywdCL8QwAAAZg"]
[Mon Jul 20 06:43:59.026135 2026] [security2:error] [pid 1014214:tid 1014461] [client 20.199.97.14:11521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YDwuRBFTcQNywdCL8RAAAAgQ"]
[Mon Jul 20 06:43:59.039968 2026] [security2:error] [pid 1011111:tid 1011149] [remote 80.82.65.226:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWeQAArCQ"]
[Mon Jul 20 06:43:59.095694 2026] [security2:error] [pid 1014214:tid 1014462] [client 34.139.11.221:55697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YDwuRBFTcQNywdCL8TQAAAgU"]
[Mon Jul 20 06:43:59.117235 2026] [security2:error] [pid 1014214:tid 1014396] [client 34.139.11.221:56621] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YDwuRBFTcQNywdCL8UQAAAcM"]
[Mon Jul 20 06:43:59.153273 2026] [security2:error] [pid 1014214:tid 1014387] [client 95.60.47.93:58246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4YDwuRBFTcQNywdCL8SAAAAbo"]
[Mon Jul 20 06:43:59.177893 2026] [security2:error] [pid 1014214:tid 1014366] [client 20.199.97.14:11521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YDwuRBFTcQNywdCL8VwAAAaU"]
[Mon Jul 20 06:43:59.189598 2026] [security2:error] [pid 1011111:tid 1011164] [remote 80.82.65.226:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWgQAAlDM"]
[Mon Jul 20 06:43:59.253678 2026] [security2:error] [pid 1014214:tid 1014388] [client 34.139.11.221:55249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YDwuRBFTcQNywdCL8WgAAAbs"]
[Mon Jul 20 06:43:59.328980 2026] [security2:error] [pid 1011111:tid 1011328] [client 34.139.11.221:56630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YDxXES7Mv0Zfga-kWhgAAANs"]
[Mon Jul 20 06:43:59.349233 2026] [proxy:error] [pid 1014214:tid 1014268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:59.349309 2026] [proxy_http:error] [pid 1014214:tid 1014268] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:59.349844 2026] [proxy:error] [pid 1014214:tid 1014268] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:43:59.349870 2026] [proxy_http:error] [pid 1014214:tid 1014268] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:43:59.364766 2026] [security2:error] [pid 1014214:tid 1014381] [client 136.144.35.250:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YDwuRBFTcQNywdCL8XgAAAbQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:59.374207 2026] [security2:error] [pid 1014214:tid 1014369] [client 57.141.18.97:60354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YCguRBFTcQNywdCL7SQABqGQ"]
[Mon Jul 20 06:43:59.379377 2026] [security2:error] [pid 1011111:tid 1011264] [client 77.110.127.138:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YDxXES7Mv0Zfga-kWhwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:59.379451 2026] [security2:error] [pid 1011111:tid 1011264] [client 77.110.127.138:53643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YDxXES7Mv0Zfga-kWhwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:43:59.423506 2026] [security2:error] [pid 1011111:tid 1011144] [remote 80.82.65.226:41376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWiwAAyR8"]
[Mon Jul 20 06:43:59.423506 2026] [security2:error] [pid 1011111:tid 1011159] [remote 80.82.65.226:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWjAAAty4"]
[Mon Jul 20 06:43:59.450734 2026] [security2:error] [pid 1011111:tid 1011244] [client 34.139.11.221:55697] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YDxXES7Mv0Zfga-kWjgAAAIc"]
[Mon Jul 20 06:43:59.452259 2026] [security2:error] [pid 1011111:tid 1011150] [remote 80.82.65.226:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWjwAAyyU"]
[Mon Jul 20 06:43:59.477865 2026] [security2:error] [pid 1011111:tid 1011366] [client 34.139.11.221:56193] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YDxXES7Mv0Zfga-kWkAAAAQE"]
[Mon Jul 20 06:43:59.517708 2026] [security2:error] [pid 1014214:tid 1014464] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YDwuRBFTcQNywdCL8ZgACBzY"]
[Mon Jul 20 06:43:59.592688 2026] [security2:error] [pid 1011111:tid 1011299] [client 34.139.11.221:62900] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YDxXES7Mv0Zfga-kWlQAAAL4"]
[Mon Jul 20 06:43:59.599400 2026] [security2:error] [pid 1014214:tid 1014270] [remote 80.82.65.226:41384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YDwuRBFTcQNywdCL8aAABzDc"]
[Mon Jul 20 06:43:59.607738 2026] [security2:error] [pid 1011111:tid 1011335] [client 34.139.11.221:51869] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YDxXES7Mv0Zfga-kWmQAAAOI"]
[Mon Jul 20 06:43:59.646124 2026] [security2:error] [pid 1011111:tid 1011252] [client 57.141.18.14:31432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YCxXES7Mv0Zfga-kVpwAAjyI"]
[Mon Jul 20 06:43:59.742703 2026] [security2:error] [pid 1011111:tid 1011122] [remote 80.82.65.226:33496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWoAAAkwk"]
[Mon Jul 20 06:43:59.798225 2026] [security2:error] [pid 1014214:tid 1014378] [client 34.139.11.221:61073] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YDwuRBFTcQNywdCL8cQAAAbE"]
[Mon Jul 20 06:43:59.816284 2026] [security2:error] [pid 1014214:tid 1014376] [client 34.139.11.221:52858] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YDwuRBFTcQNywdCL8cwAAAa8"]
[Mon Jul 20 06:43:59.835367 2026] [security2:error] [pid 1011111:tid 1011277] [client 136.144.35.246:45327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YDxXES7Mv0Zfga-kWowAAAKg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:43:59.999759 2026] [security2:error] [pid 1011111:tid 1011278] [client 77.110.127.138:53646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YDxXES7Mv0Zfga-kWrwAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:00.029380 2026] [security2:error] [pid 1011111:tid 1011182] [remote 80.82.65.226:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YEBXES7Mv0Zfga-kWsAAAsEU"]
[Mon Jul 20 06:44:00.035340 2026] [security2:error] [pid 1011111:tid 1011250] [client 34.139.11.221:56790] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YEBXES7Mv0Zfga-kWsQAAAI0"]
[Mon Jul 20 06:44:00.039999 2026] [security2:error] [pid 1011111:tid 1011322] [client 34.139.11.221:62530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YEBXES7Mv0Zfga-kWsgAAANU"]
[Mon Jul 20 06:44:00.082567 2026] [proxy:error] [pid 1014214:tid 1014283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.082667 2026] [proxy_http:error] [pid 1014214:tid 1014283] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.083828 2026] [proxy:error] [pid 1014214:tid 1014283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.083896 2026] [proxy_http:error] [pid 1014214:tid 1014283] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.087902 2026] [security2:error] [pid 1011111:tid 1011184] [remote 80.82.65.226:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YEBXES7Mv0Zfga-kWtQAAp0c"]
[Mon Jul 20 06:44:00.103249 2026] [proxy:error] [pid 1011111:tid 1011139] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.103320 2026] [proxy_http:error] [pid 1011111:tid 1011139] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.103733 2026] [proxy:error] [pid 1011111:tid 1011139] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.103767 2026] [proxy_http:error] [pid 1011111:tid 1011139] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.120958 2026] [proxy:error] [pid 1014214:tid 1014420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.121027 2026] [proxy_http:error] [pid 1014214:tid 1014420] [client 34.73.38.214:51393] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.121595 2026] [proxy:error] [pid 1014214:tid 1014420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.121623 2026] [proxy_http:error] [pid 1014214:tid 1014420] [client 34.73.38.214:51393] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.161392 2026] [security2:error] [pid 1011111:tid 1011179] [remote 57.141.18.41:63238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4899371"] [unique_id "al4YEBXES7Mv0Zfga-kWvQAAl0I"]
[Mon Jul 20 06:44:00.161883 2026] [security2:error] [pid 1011111:tid 1011315] [client 57.141.18.61:29760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YCxXES7Mv0Zfga-kVzgAAziE"]
[Mon Jul 20 06:44:00.168251 2026] [security2:error] [pid 1014214:tid 1014425] [client 34.139.11.221:49314] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YEAuRBFTcQNywdCL8hwAAAeA"]
[Mon Jul 20 06:44:00.174206 2026] [security2:error] [pid 1014214:tid 1014417] [client 34.139.11.221:63257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YEAuRBFTcQNywdCL8iAAAAdg"]
[Mon Jul 20 06:44:00.338731 2026] [security2:error] [pid 1014214:tid 1014467] [client 158.173.166.181:38315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YEAuRBFTcQNywdCL8kQAAAgo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:00.349627 2026] [security2:error] [pid 1014214:tid 1014397] [client 34.139.11.221:62989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YEAuRBFTcQNywdCL8kwAAAcQ"]
[Mon Jul 20 06:44:00.364705 2026] [security2:error] [pid 1014214:tid 1014403] [client 80.82.65.226:41352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YEAuRBFTcQNywdCL8kgAByhk"]
[Mon Jul 20 06:44:00.383534 2026] [security2:error] [pid 1011111:tid 1011243] [client 34.139.11.221:65117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YEBXES7Mv0Zfga-kWxAAAAIY"]
[Mon Jul 20 06:44:00.392481 2026] [security2:error] [pid 1014214:tid 1014431] [client 52.109.124.141:23937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YEAuRBFTcQNywdCL8lAAAAeY"]
[Mon Jul 20 06:44:00.409472 2026] [security2:error] [pid 1014214:tid 1014400] [client 173.239.240.99:43711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YEAuRBFTcQNywdCL8lgAAAcc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:00.457213 2026] [proxy:error] [pid 1011111:tid 1011220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.457266 2026] [proxy_http:error] [pid 1011111:tid 1011220] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.457708 2026] [proxy:error] [pid 1011111:tid 1011220] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:00.457733 2026] [proxy_http:error] [pid 1011111:tid 1011220] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:00.551421 2026] [security2:error] [pid 1014214:tid 1014404] [client 34.139.11.221:52979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YEAuRBFTcQNywdCL8ngAAAcs"]
[Mon Jul 20 06:44:00.569951 2026] [security2:error] [pid 1011111:tid 1011328] [client 104.234.53.66:22211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YEBXES7Mv0Zfga-kWzAAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:00.576716 2026] [security2:error] [pid 1014214:tid 1014443] [client 52.109.124.141:23937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YEAuRBFTcQNywdCL8oQAAAfI"]
[Mon Jul 20 06:44:00.717476 2026] [security2:error] [pid 1014214:tid 1014422] [client 34.139.11.221:55782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YEAuRBFTcQNywdCL8qwAAAd0"]
[Mon Jul 20 06:44:00.761133 2026] [security2:error] [pid 1014214:tid 1014382] [client 14.225.17.146:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4YDwuRBFTcQNywdCL8UgAAAbU"], referer: http://lelandumc.org/new
[Mon Jul 20 06:44:00.804322 2026] [security2:error] [pid 1011111:tid 1011128] [remote 182.77.62.24:52590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YEBXES7Mv0Zfga-kW2AAA0g8"]
[Mon Jul 20 06:44:00.860817 2026] [security2:error] [pid 1011111:tid 1011154] [remote 80.82.65.226:33514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/index.php"] [unique_id "al4YEBXES7Mv0Zfga-kW2wAApCk"]
[Mon Jul 20 06:44:00.888954 2026] [security2:error] [pid 1011111:tid 1011320] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YEBXES7Mv0Zfga-kW0gAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:00.912683 2026] [security2:error] [pid 1014214:tid 1014409] [client 50.116.65.227:36916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4YEAuRBFTcQNywdCL8tgAAAdA"]
[Mon Jul 20 06:44:00.970221 2026] [security2:error] [pid 1014214:tid 1014393] [client 173.239.240.90:35497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YEAuRBFTcQNywdCL8ugAAAcA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:00.980105 2026] [security2:error] [pid 1011111:tid 1011258] [client 158.173.89.95:54543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YEBXES7Mv0Zfga-kW4QAAAJU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:01.090855 2026] [security2:error] [pid 1014214:tid 1014396] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YEQuRBFTcQNywdCL8vwABw1Y"]
[Mon Jul 20 06:44:01.117878 2026] [security2:error] [pid 1011111:tid 1011178] [remote 80.82.65.226:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YERXES7Mv0Zfga-kW5gAA4EE"]
[Mon Jul 20 06:44:01.206888 2026] [security2:error] [pid 1011111:tid 1011291] [client 57.141.18.45:30648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDBXES7Mv0Zfga-kWCAAAtmI"]
[Mon Jul 20 06:44:01.256599 2026] [security2:error] [pid 1014214:tid 1014345] [client 104.234.53.67:34255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YEQuRBFTcQNywdCL80AAAAZA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:01.300938 2026] [security2:error] [pid 1011111:tid 1011153] [remote 80.82.65.226:33514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YERXES7Mv0Zfga-kW7wAAkig"]
[Mon Jul 20 06:44:01.301660 2026] [proxy:error] [pid 1011111:tid 1011237] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:01.301731 2026] [proxy_http:error] [pid 1011111:tid 1011237] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:01.303847 2026] [proxy:error] [pid 1011111:tid 1011237] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:01.303899 2026] [proxy_http:error] [pid 1011111:tid 1011237] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:01.310471 2026] [security2:error] [pid 1011111:tid 1011157] [remote 182.77.62.24:52590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YERXES7Mv0Zfga-kW7QAAkCw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:44:01.359796 2026] [security2:error] [pid 1011111:tid 1011247] [client 34.73.38.214:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YERXES7Mv0Zfga-kW9gAAAIo"]
[Mon Jul 20 06:44:01.360373 2026] [security2:error] [pid 1014214:tid 1014404] [client 34.73.38.214:49462] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YEQuRBFTcQNywdCL82gAAAcs"]
[Mon Jul 20 06:44:01.458149 2026] [security2:error] [pid 1011111:tid 1011334] [client 136.144.35.245:28381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YERXES7Mv0Zfga-kW-QAAAOE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:01.516219 2026] [security2:error] [pid 1011111:tid 1011113] [remote 80.82.65.226:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YERXES7Mv0Zfga-kW_AAAxAA"]
[Mon Jul 20 06:44:01.517044 2026] [proxy:error] [pid 1014214:tid 1014306] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:01.517136 2026] [proxy_http:error] [pid 1014214:tid 1014306] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:01.517800 2026] [proxy:error] [pid 1014214:tid 1014306] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:01.517841 2026] [proxy_http:error] [pid 1014214:tid 1014306] [remote 80.82.65.226:41364] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:01.561394 2026] [security2:error] [pid 1011111:tid 1011200] [remote 217.61.143.92:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4YERXES7Mv0Zfga-kXAAAAnFc"]
[Mon Jul 20 06:44:01.600732 2026] [security2:error] [pid 1014214:tid 1014407] [client 37.52.210.45:17169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YEQuRBFTcQNywdCL85wAAAc4"]
[Mon Jul 20 06:44:01.600851 2026] [security2:error] [pid 1014214:tid 1014407] [client 37.52.210.45:17169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YEQuRBFTcQNywdCL85wAAAc4"]
[Mon Jul 20 06:44:01.666059 2026] [proxy:error] [pid 1011111:tid 1011131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:01.666113 2026] [proxy_http:error] [pid 1011111:tid 1011131] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:01.666681 2026] [proxy:error] [pid 1011111:tid 1011131] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:01.666710 2026] [proxy_http:error] [pid 1011111:tid 1011131] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:01.690500 2026] [security2:error] [pid 1014214:tid 1014403] [client 223.185.13.213:11938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YEQuRBFTcQNywdCL87gAAAco"]
[Mon Jul 20 06:44:01.690620 2026] [security2:error] [pid 1014214:tid 1014403] [client 223.185.13.213:11938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YEQuRBFTcQNywdCL87gAAAco"]
[Mon Jul 20 06:44:01.732362 2026] [security2:error] [pid 1014214:tid 1014317] [remote 72.167.132.114:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YEQuRBFTcQNywdCL88QAB8WY"]
[Mon Jul 20 06:44:01.736465 2026] [security2:error] [pid 1014214:tid 1014460] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YEQuRBFTcQNywdCL87QACA2M"]
[Mon Jul 20 06:44:01.796304 2026] [security2:error] [pid 1011111:tid 1011187] [remote 217.61.143.92:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4YERXES7Mv0Zfga-kXCwAAxko"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 06:44:01.806525 2026] [security2:error] [pid 1011111:tid 1011195] [remote 80.82.65.226:33508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YERXES7Mv0Zfga-kXDQAAn1I"]
[Mon Jul 20 06:44:01.806623 2026] [security2:error] [pid 1011111:tid 1011219] [remote 80.82.65.226:33514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YERXES7Mv0Zfga-kXDgABA2o"]
[Mon Jul 20 06:44:01.807503 2026] [security2:error] [pid 1014214:tid 1014471] [client 57.141.18.25:51104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDQuRBFTcQNywdCL7xQACDg4"]
[Mon Jul 20 06:44:01.811238 2026] [security2:error] [pid 1014214:tid 1014441] [client 34.73.38.214:54532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YEQuRBFTcQNywdCL89gAAAfA"]
[Mon Jul 20 06:44:01.875658 2026] [security2:error] [pid 1011111:tid 1011242] [client 57.141.18.35:43272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDRXES7Mv0Zfga-kWJgAAhX4"]
[Mon Jul 20 06:44:01.894369 2026] [security2:error] [pid 1014214:tid 1014428] [client 34.73.38.214:57395] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YEQuRBFTcQNywdCL8-wAAAeM"]
[Mon Jul 20 06:44:01.907535 2026] [security2:error] [pid 1014214:tid 1014396] [client 173.239.240.98:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YEQuRBFTcQNywdCL8_AAAAcM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:02.007577 2026] [security2:error] [pid 1014214:tid 1014323] [remote 72.167.132.114:42284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YEQuRBFTcQNywdCL9BAAB-2w"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:44:02.199803 2026] [proxy:error] [pid 1011111:tid 1011224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:02.199889 2026] [proxy_http:error] [pid 1011111:tid 1011224] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:02.200526 2026] [proxy:error] [pid 1011111:tid 1011224] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:02.200554 2026] [proxy_http:error] [pid 1011111:tid 1011224] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:02.219128 2026] [security2:error] [pid 1011111:tid 1011117] [remote 80.82.65.226:33514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YEhXES7Mv0Zfga-kXIQAAxQQ"]
[Mon Jul 20 06:44:02.295246 2026] [security2:error] [pid 1014214:tid 1014346] [client 57.141.18.9:44352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDQuRBFTcQNywdCL75QABkRc"]
[Mon Jul 20 06:44:02.358572 2026] [security2:error] [pid 1014214:tid 1014348] [client 54.162.148.64:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.148.162.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YEguRBFTcQNywdCL9GgAAAZM"]
[Mon Jul 20 06:44:02.358654 2026] [security2:error] [pid 1014214:tid 1014334] [remote 80.82.65.226:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YEguRBFTcQNywdCL9HQACA3c"]
[Mon Jul 20 06:44:02.426473 2026] [security2:error] [pid 1011111:tid 1011333] [client 136.144.35.244:45803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YEhXES7Mv0Zfga-kXMQAAAOA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:02.440588 2026] [security2:error] [pid 1014214:tid 1014433] [client 34.73.38.214:54918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YEguRBFTcQNywdCL9JwAAAeg"]
[Mon Jul 20 06:44:02.500436 2026] [security2:error] [pid 1014214:tid 1014385] [client 207.46.13.155:62759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4YEguRBFTcQNywdCL9IwABuDE"]
[Mon Jul 20 06:44:02.532583 2026] [security2:error] [pid 1014214:tid 1014374] [client 34.73.38.214:55808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YEguRBFTcQNywdCL9KwAAAa0"]
[Mon Jul 20 06:44:02.795870 2026] [security2:error] [pid 1011111:tid 1011164] [remote 80.82.65.226:33514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YEhXES7Mv0Zfga-kXQQAAqjM"]
[Mon Jul 20 06:44:02.805524 2026] [security2:error] [pid 1014214:tid 1014219] [remote 80.82.65.226:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YEguRBFTcQNywdCL9NgAB7AQ"]
[Mon Jul 20 06:44:02.805848 2026] [security2:error] [pid 1014214:tid 1014469] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YEguRBFTcQNywdCL9NAACDDo"]
[Mon Jul 20 06:44:02.877681 2026] [security2:error] [pid 1011111:tid 1011288] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YEhXES7Mv0Zfga-kXRgAAszg"]
[Mon Jul 20 06:44:02.915374 2026] [security2:error] [pid 1014214:tid 1014377] [client 57.141.18.72:23084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDguRBFTcQNywdCL8DwABsB0"]
[Mon Jul 20 06:44:02.918448 2026] [security2:error] [pid 1011111:tid 1011294] [client 173.239.240.32:22197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YEhXES7Mv0Zfga-kXSQAAALk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:02.932237 2026] [proxy:error] [pid 1011111:tid 1011144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:02.932314 2026] [proxy_http:error] [pid 1011111:tid 1011144] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:02.933371 2026] [proxy:error] [pid 1011111:tid 1011144] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:02.933414 2026] [proxy_http:error] [pid 1011111:tid 1011144] [remote 80.82.65.226:41376] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:03.241644 2026] [security2:error] [pid 1014214:tid 1014426] [client 52.207.32.99:12076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YEwuRBFTcQNywdCL9RwAAAeE"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:44:03.284202 2026] [security2:error] [pid 1014214:tid 1014224] [remote 80.82.65.226:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zonemist.com"] [uri "/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9SgAB2Ak"]
[Mon Jul 20 06:44:03.348186 2026] [security2:error] [pid 1014214:tid 1014235] [remote 8.217.108.67:18062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YEwuRBFTcQNywdCL9SwABqBQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:44:03.385349 2026] [security2:error] [pid 1011111:tid 1011318] [client 34.73.38.214:53238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YExXES7Mv0Zfga-kXZAAAANE"]
[Mon Jul 20 06:44:03.411952 2026] [security2:error] [pid 1011111:tid 1011242] [client 173.239.240.99:44591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YExXES7Mv0Zfga-kXZgAAAIU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:03.449718 2026] [security2:error] [pid 1014214:tid 1014289] [remote 80.82.65.226:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9UAABoko"]
[Mon Jul 20 06:44:03.464925 2026] [security2:error] [pid 1011111:tid 1011297] [client 34.73.38.214:56105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eliteeventsleaders.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YExXES7Mv0Zfga-kXbQAAALw"]
[Mon Jul 20 06:44:03.514033 2026] [security2:error] [pid 1014214:tid 1014371] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9UQABqhE"]
[Mon Jul 20 06:44:03.532373 2026] [security2:error] [pid 1011111:tid 1011177] [remote 80.82.65.226:33514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YExXES7Mv0Zfga-kXbwAA8UA"]
[Mon Jul 20 06:44:03.637307 2026] [security2:error] [pid 1011111:tid 1011333] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YExXES7Mv0Zfga-kXdAAA4Bw"]
[Mon Jul 20 06:44:03.673590 2026] [security2:error] [pid 1014214:tid 1014358] [client 207.46.13.155:62759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9RgABnQs"]
[Mon Jul 20 06:44:03.735625 2026] [security2:error] [pid 1014214:tid 1014398] [client 14.225.17.146:63186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4YEQuRBFTcQNywdCL9AwAAAcU"], referer: http://swafforddetailing.com/new
[Mon Jul 20 06:44:03.762994 2026] [security2:error] [pid 1011111:tid 1011139] [remote 182.77.62.24:39434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4YExXES7Mv0Zfga-kXeQAAiRo"]
[Mon Jul 20 06:44:03.770233 2026] [security2:error] [pid 1014214:tid 1014246] [remote 80.82.65.226:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9YAABxh8"]
[Mon Jul 20 06:44:03.791957 2026] [security2:error] [pid 1014214:tid 1014389] [client 45.3.47.234:65059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YEwuRBFTcQNywdCL9YgAAAbw"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:44:03.824992 2026] [security2:error] [pid 1014214:tid 1014292] [remote 80.82.65.226:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zonemist.com"] [uri "/wp/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9ZgACDE0"]
[Mon Jul 20 06:44:03.876577 2026] [security2:error] [pid 1014214:tid 1014457] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9XgAAAgA"]
[Mon Jul 20 06:44:03.882346 2026] [security2:error] [pid 1014214:tid 1014388] [client 173.239.240.94:42493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9bAAAAbs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:03.956626 2026] [security2:error] [pid 1014214:tid 1014451] [client 39.48.81.23:53078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YEwuRBFTcQNywdCL9cQAAAfo"]
[Mon Jul 20 06:44:03.956727 2026] [security2:error] [pid 1014214:tid 1014451] [client 39.48.81.23:53078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YEwuRBFTcQNywdCL9cQAAAfo"]
[Mon Jul 20 06:44:04.041982 2026] [security2:error] [pid 1011111:tid 1011308] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFBXES7Mv0Zfga-kXiAAAxwY"]
[Mon Jul 20 06:44:04.105788 2026] [security2:error] [pid 1014214:tid 1014255] [remote 80.82.65.226:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9dQABySg"]
[Mon Jul 20 06:44:04.132273 2026] [security2:error] [pid 1014214:tid 1014425] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9cgAB4CA"]
[Mon Jul 20 06:44:04.236254 2026] [security2:error] [pid 1014214:tid 1014254] [remote 80.82.65.226:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9egABoic"]
[Mon Jul 20 06:44:04.287187 2026] [security2:error] [pid 1014214:tid 1014263] [remote 80.82.65.226:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zonemist.com"] [uri "/wordpress/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9gAABxzA"]
[Mon Jul 20 06:44:04.309825 2026] [security2:error] [pid 1011111:tid 1011142] [remote 182.77.62.24:39434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4YFBXES7Mv0Zfga-kXlAAAlR0"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:44:04.366272 2026] [security2:error] [pid 1014214:tid 1014348] [client 77.110.127.138:53671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YFAuRBFTcQNywdCL9ggAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:04.366389 2026] [security2:error] [pid 1014214:tid 1014348] [client 77.110.127.138:53671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YFAuRBFTcQNywdCL9ggAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:04.387417 2026] [security2:error] [pid 1014214:tid 1014403] [client 173.239.240.101:24657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YFAuRBFTcQNywdCL9hgAAAco"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:04.479004 2026] [security2:error] [pid 1014214:tid 1014432] [client 192.140.149.97:45115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YFAuRBFTcQNywdCL9igAAAec"]
[Mon Jul 20 06:44:04.479139 2026] [security2:error] [pid 1014214:tid 1014432] [client 192.140.149.97:45115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YFAuRBFTcQNywdCL9igAAAec"]
[Mon Jul 20 06:44:04.494243 2026] [security2:error] [pid 1011111:tid 1011334] [client 14.225.17.146:58532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4YExXES7Mv0Zfga-kXUQAAAOE"], referer: http://sarahsnyder.net/new
[Mon Jul 20 06:44:04.552147 2026] [security2:error] [pid 1014214:tid 1014265] [remote 80.82.65.226:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9jwABtTI"]
[Mon Jul 20 06:44:04.560330 2026] [security2:error] [pid 1014214:tid 1014461] [client 103.125.179.95:50273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YFAuRBFTcQNywdCL9kAAAAgQ"]
[Mon Jul 20 06:44:04.560465 2026] [security2:error] [pid 1014214:tid 1014461] [client 103.125.179.95:50273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YFAuRBFTcQNywdCL9kAAAAgQ"]
[Mon Jul 20 06:44:04.588699 2026] [security2:error] [pid 1011111:tid 1011263] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFBXES7Mv0Zfga-kXoQAAmlQ"]
[Mon Jul 20 06:44:04.605820 2026] [security2:error] [pid 1014214:tid 1014315] [remote 80.82.65.226:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9kQACDmQ"]
[Mon Jul 20 06:44:04.651093 2026] [security2:error] [pid 1014214:tid 1014372] [client 57.141.18.30:20504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDwuRBFTcQNywdCL8cgABqzs"]
[Mon Jul 20 06:44:04.666226 2026] [security2:error] [pid 1014214:tid 1014436] [client 57.141.18.125:50010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YDwuRBFTcQNywdCL8bgAB6zg"]
[Mon Jul 20 06:44:04.687468 2026] [security2:error] [pid 1011111:tid 1011361] [client 106.219.188.178:42203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YFBXES7Mv0Zfga-kXqQAAAPw"]
[Mon Jul 20 06:44:04.687806 2026] [security2:error] [pid 1011111:tid 1011361] [client 106.219.188.178:42203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YFBXES7Mv0Zfga-kXqQAAAPw"]
[Mon Jul 20 06:44:04.860109 2026] [security2:error] [pid 1014214:tid 1014227] [remote 80.82.65.226:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zonemist.com"] [uri "/blog/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9ogABwAw"]
[Mon Jul 20 06:44:04.871217 2026] [security2:error] [pid 1011111:tid 1011262] [client 173.239.240.97:23157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YFBXES7Mv0Zfga-kXswAAAJk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:04.875338 2026] [security2:error] [pid 1014214:tid 1014395] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9oAABwhI"]
[Mon Jul 20 06:44:04.960783 2026] [security2:error] [pid 1011111:tid 1011213] [remote 80.82.65.226:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFBXES7Mv0Zfga-kXugAA82Q"]
[Mon Jul 20 06:44:04.972649 2026] [security2:error] [pid 1014214:tid 1014355] [client 77.110.127.138:53675] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YFAuRBFTcQNywdCL9rQAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:04.999745 2026] [security2:error] [pid 1014214:tid 1014281] [remote 80.82.65.226:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9rgABx0I"]
[Mon Jul 20 06:44:05.100325 2026] [security2:error] [pid 1014214:tid 1014283] [remote 80.82.65.226:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9uAABzUQ"]
[Mon Jul 20 06:44:05.108430 2026] [security2:error] [pid 1014214:tid 1014278] [remote 80.82.65.226:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9uQABxT8"]
[Mon Jul 20 06:44:05.120079 2026] [security2:error] [pid 1011111:tid 1011163] [remote 188.166.241.141:45242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YFRXES7Mv0Zfga-kXwAAAjDI"]
[Mon Jul 20 06:44:05.184034 2026] [security2:error] [pid 1011111:tid 1011176] [remote 80.82.65.226:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YFRXES7Mv0Zfga-kXwgAA5z8"]
[Mon Jul 20 06:44:05.261283 2026] [security2:error] [pid 1014214:tid 1014284] [remote 80.82.65.226:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9wwAB-0U"]
[Mon Jul 20 06:44:05.319789 2026] [security2:error] [pid 1014214:tid 1014236] [remote 80.82.65.226:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/wp/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9yAABlhU"]
[Mon Jul 20 06:44:05.322940 2026] [security2:error] [pid 1014214:tid 1014389] [client 136.144.35.245:37853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YFQuRBFTcQNywdCL9yQAAAbw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:05.335807 2026] [security2:error] [pid 1014214:tid 1014381] [client 197.186.66.42:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YFQuRBFTcQNywdCL9ywAAAbQ"]
[Mon Jul 20 06:44:05.340706 2026] [security2:error] [pid 1014214:tid 1014381] [client 197.186.66.42:60184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YFQuRBFTcQNywdCL9ywAAAbQ"]
[Mon Jul 20 06:44:05.343242 2026] [security2:error] [pid 1011111:tid 1011276] [client 80.82.65.226:41388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFRXES7Mv0Zfga-kXxQAApyo"]
[Mon Jul 20 06:44:05.376061 2026] [security2:error] [pid 1011111:tid 1011251] [client 34.73.38.214:63335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YFRXES7Mv0Zfga-kXywAAAI4"]
[Mon Jul 20 06:44:05.389119 2026] [security2:error] [pid 1014214:tid 1014342] [remote 80.82.65.226:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zonemist.com"] [uri "/cms/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9zwABvn8"]
[Mon Jul 20 06:44:05.424332 2026] [security2:error] [pid 1014214:tid 1014286] [remote 80.82.65.226:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL90gAB10c"]
[Mon Jul 20 06:44:05.486111 2026] [security2:error] [pid 1014214:tid 1014379] [client 14.225.17.146:58335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9zAAAAbI"], referer: https://sarahsnyder.net/new
[Mon Jul 20 06:44:05.490359 2026] [security2:error] [pid 1014214:tid 1014438] [client 57.141.18.100:59896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEAuRBFTcQNywdCL8mAAB7Us"]
[Mon Jul 20 06:44:05.559400 2026] [security2:error] [pid 1014214:tid 1014294] [remote 80.82.65.226:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/wp/index.php"] [unique_id "al4YFQuRBFTcQNywdCL92gABoU8"]
[Mon Jul 20 06:44:05.606942 2026] [security2:error] [pid 1014214:tid 1014300] [remote 5.161.225.162:43176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4YFQuRBFTcQNywdCL93wABnVU"]
[Mon Jul 20 06:44:05.630337 2026] [security2:error] [pid 1011111:tid 1011191] [remote 188.166.241.141:45242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YFRXES7Mv0Zfga-kX1QAA5U4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:44:05.630356 2026] [security2:error] [pid 1011111:tid 1011354] [client 112.208.70.94:42625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YFRXES7Mv0Zfga-kX0wAAAPU"]
[Mon Jul 20 06:44:05.630508 2026] [security2:error] [pid 1011111:tid 1011354] [client 112.208.70.94:42625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YFRXES7Mv0Zfga-kX0wAAAPU"]
[Mon Jul 20 06:44:05.631329 2026] [security2:error] [pid 1014214:tid 1014298] [remote 80.82.65.226:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YFQuRBFTcQNywdCL94AAB3VM"]
[Mon Jul 20 06:44:05.642131 2026] [security2:error] [pid 1014214:tid 1014454] [client 57.141.18.77:25256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEAuRBFTcQNywdCL8owAB_T0"]
[Mon Jul 20 06:44:05.658169 2026] [security2:error] [pid 1014214:tid 1014304] [remote 80.82.65.226:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/wp/index.php"] [unique_id "al4YFQuRBFTcQNywdCL94gACAlk"]
[Mon Jul 20 06:44:05.695707 2026] [security2:error] [pid 1014214:tid 1014297] [remote 80.82.65.226:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YFQuRBFTcQNywdCL95QABw1I"]
[Mon Jul 20 06:44:05.735474 2026] [security2:error] [pid 1014214:tid 1014301] [remote 80.82.65.226:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/wordpress/index.php"] [unique_id "al4YFQuRBFTcQNywdCL96AAB9FY"]
[Mon Jul 20 06:44:05.801323 2026] [security2:error] [pid 1011111:tid 1011204] [remote 80.82.65.226:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YFRXES7Mv0Zfga-kX3QAAwFs"]
[Mon Jul 20 06:44:05.848895 2026] [security2:error] [pid 1014214:tid 1014450] [client 57.141.18.121:34812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEAuRBFTcQNywdCL8rQAB-VE"]
[Mon Jul 20 06:44:05.892378 2026] [security2:error] [pid 1011111:tid 1011288] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YFRXES7Mv0Zfga-kX2QAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:05.904385 2026] [security2:error] [pid 1014214:tid 1014420] [client 173.239.240.93:46013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YFQuRBFTcQNywdCL99QAAAds"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:05.926875 2026] [security2:error] [pid 1014214:tid 1014310] [remote 80.82.65.226:33518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.zonemist.com"] [uri "/site/index.php"] [unique_id "al4YFQuRBFTcQNywdCL99wACCl8"]
[Mon Jul 20 06:44:06.088218 2026] [security2:error] [pid 1014214:tid 1014425] [client 183.82.98.154:56939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YFguRBFTcQNywdCL9_wAAAeA"]
[Mon Jul 20 06:44:06.088331 2026] [security2:error] [pid 1014214:tid 1014425] [client 183.82.98.154:56939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YFguRBFTcQNywdCL9_wAAAeA"]
[Mon Jul 20 06:44:06.092733 2026] [security2:error] [pid 1014214:tid 1014306] [remote 80.82.65.226:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFguRBFTcQNywdCL-AAAByVs"]
[Mon Jul 20 06:44:06.188381 2026] [security2:error] [pid 1014214:tid 1014311] [remote 5.161.225.162:43176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4YFguRBFTcQNywdCL-BQAB2GA"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:44:06.207638 2026] [security2:error] [pid 1014214:tid 1014359] [client 34.73.38.214:51097] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YFguRBFTcQNywdCL-BgAAAZ4"]
[Mon Jul 20 06:44:06.210057 2026] [security2:error] [pid 1014214:tid 1014303] [remote 80.82.65.226:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YFguRBFTcQNywdCL-CAAB8Vg"]
[Mon Jul 20 06:44:06.260894 2026] [security2:error] [pid 1014214:tid 1014256] [remote 80.82.65.226:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/blog/index.php"] [unique_id "al4YFguRBFTcQNywdCL-CgABmik"]
[Mon Jul 20 06:44:06.275916 2026] [security2:error] [pid 1011111:tid 1011193] [remote 80.82.65.226:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YFhXES7Mv0Zfga-kX9QAApFA"]
[Mon Jul 20 06:44:06.347493 2026] [security2:error] [pid 1014214:tid 1014375] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFguRBFTcQNywdCL-CwABrmY"]
[Mon Jul 20 06:44:06.374036 2026] [security2:error] [pid 1011111:tid 1011318] [client 136.144.35.254:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YFhXES7Mv0Zfga-kX-wAAANE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:06.377085 2026] [security2:error] [pid 1014214:tid 1014363] [client 14.225.17.146:63057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9vgAAAaI"], referer: http://idigress.studio/new
[Mon Jul 20 06:44:06.399486 2026] [security2:error] [pid 1014214:tid 1014259] [remote 80.82.65.226:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YFguRBFTcQNywdCL-EAABqiw"]
[Mon Jul 20 06:44:06.413765 2026] [security2:error] [pid 1014214:tid 1014367] [client 104.234.53.68:29905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YFguRBFTcQNywdCL-DAAAAaY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:06.487226 2026] [security2:error] [pid 1011111:tid 1011274] [client 65.1.132.125:13340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YFhXES7Mv0Zfga-kYAwAAAKU"]
[Mon Jul 20 06:44:06.533630 2026] [security2:error] [pid 1014214:tid 1014322] [remote 80.82.65.226:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/wordpress/index.php"] [unique_id "al4YFguRBFTcQNywdCL-GgABxGs"]
[Mon Jul 20 06:44:06.569863 2026] [security2:error] [pid 1014214:tid 1014399] [client 104.234.53.68:29905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YFguRBFTcQNywdCL-HQAAAcY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:06.574208 2026] [security2:error] [pid 1014214:tid 1014323] [remote 80.82.65.226:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/wordpress/index.php"] [unique_id "al4YFguRBFTcQNywdCL-HgABkmw"]
[Mon Jul 20 06:44:06.643624 2026] [security2:error] [pid 1014214:tid 1014329] [remote 80.82.65.226:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YFguRBFTcQNywdCL-IwACDHI"]
[Mon Jul 20 06:44:06.646020 2026] [security2:error] [pid 1011111:tid 1011159] [remote 80.82.65.226:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFhXES7Mv0Zfga-kYCgAA3y4"]
[Mon Jul 20 06:44:06.658680 2026] [security2:error] [pid 1014214:tid 1014238] [remote 80.82.65.226:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YFguRBFTcQNywdCL-JAACChc"]
[Mon Jul 20 06:44:06.699125 2026] [security2:error] [pid 1014214:tid 1014327] [remote 80.82.65.226:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/cms/index.php"] [unique_id "al4YFguRBFTcQNywdCL-JgABuHA"]
[Mon Jul 20 06:44:06.811208 2026] [security2:error] [pid 1014214:tid 1014336] [remote 80.82.65.226:33528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YFguRBFTcQNywdCL-MgABsnk"]
[Mon Jul 20 06:44:06.830951 2026] [security2:error] [pid 1014214:tid 1014335] [remote 80.82.65.226:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YFguRBFTcQNywdCL-MwAB2Xg"]
[Mon Jul 20 06:44:06.850938 2026] [security2:error] [pid 1014214:tid 1014391] [client 173.239.240.94:25687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YFguRBFTcQNywdCL-NAAAAb4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:06.924364 2026] [security2:error] [pid 1011111:tid 1011144] [remote 80.82.65.226:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YFhXES7Mv0Zfga-kYFQABAh8"]
[Mon Jul 20 06:44:06.969799 2026] [security2:error] [pid 1014214:tid 1014331] [remote 80.82.65.226:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YFguRBFTcQNywdCL-NgAByHQ"]
[Mon Jul 20 06:44:06.970856 2026] [security2:error] [pid 1014214:tid 1014340] [remote 80.82.65.226:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/blog/index.php"] [unique_id "al4YFguRBFTcQNywdCL-NwABuX0"]
[Mon Jul 20 06:44:07.071819 2026] [security2:error] [pid 1014214:tid 1014219] [remote 80.82.65.226:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/site/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-PwAB3AQ"]
[Mon Jul 20 06:44:07.074076 2026] [security2:error] [pid 1014214:tid 1014383] [client 57.141.18.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4YFguRBFTcQNywdCL-MAAAAbY"]
[Mon Jul 20 06:44:07.087043 2026] [security2:error] [pid 1011111:tid 1011122] [remote 80.82.65.226:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YFxXES7Mv0Zfga-kYIgAAxAk"]
[Mon Jul 20 06:44:07.118957 2026] [security2:error] [pid 1011111:tid 1011270] [client 14.225.17.146:58404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4YFhXES7Mv0Zfga-kYHQAAAKE"]
[Mon Jul 20 06:44:07.165826 2026] [security2:error] [pid 1014214:tid 1014453] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-RAAB_B0"]
[Mon Jul 20 06:44:07.242177 2026] [security2:error] [pid 1014214:tid 1014443] [client 57.141.18.61:57968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEQuRBFTcQNywdCL9BgAB8m8"]
[Mon Jul 20 06:44:07.275632 2026] [security2:error] [pid 1014214:tid 1014230] [remote 80.82.65.226:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/blog/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-TQABxA8"]
[Mon Jul 20 06:44:07.306306 2026] [security2:error] [pid 1014214:tid 1014420] [client 34.73.38.214:51175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YFwuRBFTcQNywdCL-UQAAAds"]
[Mon Jul 20 06:44:07.314631 2026] [security2:error] [pid 1011111:tid 1011287] [client 173.239.240.92:29837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YFxXES7Mv0Zfga-kYLAAAALI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:07.418596 2026] [security2:error] [pid 1011111:tid 1011121] [remote 80.82.65.226:55038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YFxXES7Mv0Zfga-kYLwAAzgg"]
[Mon Jul 20 06:44:07.445519 2026] [security2:error] [pid 1014214:tid 1014237] [remote 80.82.65.226:55022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-XwAB6hY"]
[Mon Jul 20 06:44:07.497537 2026] [security2:error] [pid 1014214:tid 1014223] [remote 80.82.65.226:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/cms/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-YgACCwg"]
[Mon Jul 20 06:44:07.501560 2026] [security2:error] [pid 1014214:tid 1014231] [remote 80.82.65.226:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-YwAB4BA"]
[Mon Jul 20 06:44:07.565904 2026] [security2:error] [pid 1014214:tid 1014232] [remote 8.217.108.67:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4YFwuRBFTcQNywdCL-agAB2hE"]
[Mon Jul 20 06:44:07.568672 2026] [security2:error] [pid 1014214:tid 1014349] [client 14.225.17.146:58335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-WQAAAZQ"], referer: http://taskidsvirginia.com/new
[Mon Jul 20 06:44:07.620630 2026] [security2:error] [pid 1014214:tid 1014364] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-awABows"]
[Mon Jul 20 06:44:07.694262 2026] [security2:error] [pid 1011111:tid 1011138] [remote 80.82.65.226:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YFxXES7Mv0Zfga-kYOgAAmRk"]
[Mon Jul 20 06:44:07.786423 2026] [security2:error] [pid 1014214:tid 1014362] [client 136.144.35.250:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-dQAAAaE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:07.822489 2026] [security2:error] [pid 1014214:tid 1014465] [client 57.141.18.71:28600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEguRBFTcQNywdCL9LAACCHo"]
[Mon Jul 20 06:44:07.831154 2026] [security2:error] [pid 1014214:tid 1014454] [client 34.73.38.214:62175] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YFwuRBFTcQNywdCL-dwAAAf0"]
[Mon Jul 20 06:44:07.847844 2026] [security2:error] [pid 1014214:tid 1014292] [remote 80.82.65.226:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/cms/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-fAACBE0"]
[Mon Jul 20 06:44:07.869220 2026] [security2:error] [pid 1014214:tid 1014457] [client 187.108.85.186:51180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YFwuRBFTcQNywdCL-fwAAAgA"]
[Mon Jul 20 06:44:07.869381 2026] [security2:error] [pid 1014214:tid 1014457] [client 187.108.85.186:51180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YFwuRBFTcQNywdCL-fwAAAgA"]
[Mon Jul 20 06:44:07.871219 2026] [security2:error] [pid 1011111:tid 1011337] [client 57.141.18.26:53146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEhXES7Mv0Zfga-kXOAAA5Eg"]
[Mon Jul 20 06:44:07.999083 2026] [security2:error] [pid 1011111:tid 1011293] [client 104.234.53.47:43971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YFxXES7Mv0Zfga-kYQwAAALg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:08.019439 2026] [security2:error] [pid 1014214:tid 1014456] [client 171.61.165.146:22578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YGAuRBFTcQNywdCL-hgAAAf8"]
[Mon Jul 20 06:44:08.019539 2026] [security2:error] [pid 1014214:tid 1014456] [client 171.61.165.146:22578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YGAuRBFTcQNywdCL-hgAAAf8"]
[Mon Jul 20 06:44:08.051110 2026] [security2:error] [pid 1014214:tid 1014242] [remote 80.82.65.226:42428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/site/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-iAAB5xs"]
[Mon Jul 20 06:44:08.143880 2026] [security2:error] [pid 1011111:tid 1011238] [remote 80.82.65.226:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YGBXES7Mv0Zfga-kYUAAAjn0"]
[Mon Jul 20 06:44:08.178742 2026] [security2:error] [pid 1014214:tid 1014389] [client 14.225.17.146:59412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4YFguRBFTcQNywdCL-BwAAAbw"], referer: http://guidehunting.com/new
[Mon Jul 20 06:44:08.191268 2026] [security2:error] [pid 1014214:tid 1014417] [client 103.238.106.162:60905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YGAuRBFTcQNywdCL-jgAAAdg"]
[Mon Jul 20 06:44:08.191399 2026] [security2:error] [pid 1014214:tid 1014417] [client 103.238.106.162:60905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YGAuRBFTcQNywdCL-jgAAAdg"]
[Mon Jul 20 06:44:08.208843 2026] [security2:error] [pid 1014214:tid 1014380] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-jQABsyA"]
[Mon Jul 20 06:44:08.235535 2026] [security2:error] [pid 1014214:tid 1014350] [client 173.239.240.32:48671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YGAuRBFTcQNywdCL-lwAAAZU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:08.237823 2026] [security2:error] [pid 1014214:tid 1014254] [remote 80.82.65.226:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-mAABvic"]
[Mon Jul 20 06:44:08.335293 2026] [security2:error] [pid 1011111:tid 1011209] [remote 80.82.65.226:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/index.php"] [unique_id "al4YGBXES7Mv0Zfga-kYXQAAymA"]
[Mon Jul 20 06:44:08.356538 2026] [security2:error] [pid 1014214:tid 1014410] [client 57.141.18.75:53254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YEwuRBFTcQNywdCL9QQAB0QU"]
[Mon Jul 20 06:44:08.364638 2026] [security2:error] [pid 1014214:tid 1014470] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-mwACDSo"]
[Mon Jul 20 06:44:08.401986 2026] [security2:error] [pid 1011111:tid 1011118] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YGBXES7Mv0Zfga-kYYAAAqQU"]
[Mon Jul 20 06:44:08.402169 2026] [security2:error] [pid 1011111:tid 1011278] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YGBXES7Mv0Zfga-kYYAAAqQU"]
[Mon Jul 20 06:44:08.462216 2026] [security2:error] [pid 1014214:tid 1014260] [remote 80.82.65.226:42438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/site/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-nwAB0C0"]
[Mon Jul 20 06:44:08.629529 2026] [security2:error] [pid 1014214:tid 1014465] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-pwACCDs"]
[Mon Jul 20 06:44:08.650553 2026] [security2:error] [pid 1011111:tid 1011240] [remote 80.82.65.226:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YGBXES7Mv0Zfga-kYbQAAoH8"]
[Mon Jul 20 06:44:08.655555 2026] [security2:error] [pid 1014214:tid 1014271] [remote 8.217.108.67:30490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4YGAuRBFTcQNywdCL-rAAB_Tg"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:44:08.662060 2026] [security2:error] [pid 1011111:tid 1011215] [remote 80.82.65.226:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/wp/index.php"] [unique_id "al4YGBXES7Mv0Zfga-kYbwAA5mY"]
[Mon Jul 20 06:44:08.687876 2026] [security2:error] [pid 1014214:tid 1014362] [client 173.239.240.94:42373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-sAAAAaE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:08.704632 2026] [security2:error] [pid 1014214:tid 1014373] [client 134.209.23.115:57686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4YGAuRBFTcQNywdCL-rwAAAaw"]
[Mon Jul 20 06:44:08.720367 2026] [security2:error] [pid 1014214:tid 1014406] [client 122.183.32.225:31504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YGAuRBFTcQNywdCL-swAAAc0"]
[Mon Jul 20 06:44:08.720472 2026] [security2:error] [pid 1014214:tid 1014406] [client 122.183.32.225:31504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YGAuRBFTcQNywdCL-swAAAc0"]
[Mon Jul 20 06:44:08.760807 2026] [security2:error] [pid 1011111:tid 1011338] [client 217.142.18.172:23632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YGBXES7Mv0Zfga-kYcgAAAOU"]
[Mon Jul 20 06:44:08.760918 2026] [security2:error] [pid 1011111:tid 1011338] [client 217.142.18.172:23632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YGBXES7Mv0Zfga-kYcgAAAOU"]
[Mon Jul 20 06:44:08.778905 2026] [security2:error] [pid 1014214:tid 1014367] [client 77.110.127.138:53691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGAuRBFTcQNywdCL-vgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:08.779015 2026] [security2:error] [pid 1014214:tid 1014367] [client 77.110.127.138:53691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGAuRBFTcQNywdCL-vgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:08.788355 2026] [security2:error] [pid 1014214:tid 1014233] [remote 80.82.65.226:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-wAAB5xI"]
[Mon Jul 20 06:44:08.898542 2026] [security2:error] [pid 1011111:tid 1011260] [client 152.58.191.29:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YGBXES7Mv0Zfga-kYegAAAJc"]
[Mon Jul 20 06:44:08.898685 2026] [security2:error] [pid 1011111:tid 1011260] [client 152.58.191.29:55169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YGBXES7Mv0Zfga-kYegAAAJc"]
[Mon Jul 20 06:44:08.901662 2026] [security2:error] [pid 1014214:tid 1014277] [remote 80.82.65.226:55046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-wgABtj4"]
[Mon Jul 20 06:44:08.909267 2026] [security2:error] [pid 1014214:tid 1014381] [client 74.7.227.179:46280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-uAABtDQ"], referer: https://tejasenvironmental.com/p=5287
[Mon Jul 20 06:44:09.082251 2026] [security2:error] [pid 1011111:tid 1011295] [client 43.205.139.3:17510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YGRXES7Mv0Zfga-kYjQAAALo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:44:09.085824 2026] [security2:error] [pid 1014214:tid 1014392] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YGQuRBFTcQNywdCL-1AABvz8"]
[Mon Jul 20 06:44:09.106214 2026] [security2:error] [pid 1014214:tid 1014437] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YGQuRBFTcQNywdCL-0wAB7EQ"]
[Mon Jul 20 06:44:09.123433 2026] [security2:error] [pid 1011111:tid 1011200] [remote 80.82.65.226:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/wordpress/index.php"] [unique_id "al4YGRXES7Mv0Zfga-kYkAAAzFc"]
[Mon Jul 20 06:44:09.134131 2026] [security2:error] [pid 1014214:tid 1014379] [client 117.247.108.24:59427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YGQuRBFTcQNywdCL-3wAAAbI"]
[Mon Jul 20 06:44:09.134323 2026] [security2:error] [pid 1014214:tid 1014379] [client 117.247.108.24:59427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YGQuRBFTcQNywdCL-3wAAAbI"]
[Mon Jul 20 06:44:09.172045 2026] [security2:error] [pid 1011111:tid 1011274] [client 173.239.240.31:47055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YGRXES7Mv0Zfga-kYkQAAAKU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:09.192454 2026] [security2:error] [pid 1011111:tid 1011163] [remote 80.82.65.226:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YGRXES7Mv0Zfga-kYkwAA3jI"]
[Mon Jul 20 06:44:09.222577 2026] [security2:error] [pid 1011111:tid 1011317] [client 34.73.38.214:52811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YGRXES7Mv0Zfga-kYlQAAANA"]
[Mon Jul 20 06:44:09.276780 2026] [security2:error] [pid 1014214:tid 1014357] [client 134.209.23.115:58061] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "mail.sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4YGQuRBFTcQNywdCL-5AAAAZw"]
[Mon Jul 20 06:44:09.377862 2026] [security2:error] [pid 1011111:tid 1011272] [client 34.73.38.214:54156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YGRXES7Mv0Zfga-kYowAAAKM"]
[Mon Jul 20 06:44:09.407717 2026] [security2:error] [pid 1014214:tid 1014439] [client 14.225.17.146:59801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4YGQuRBFTcQNywdCL-1gAAAe4"], referer: https://guidehunting.com/new
[Mon Jul 20 06:44:09.414156 2026] [security2:error] [pid 1011111:tid 1011304] [client 77.110.127.138:53695] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YGRXES7Mv0Zfga-kYpwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:09.436717 2026] [security2:error] [pid 1014214:tid 1014240] [remote 80.82.65.226:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/wp/index.php"] [unique_id "al4YGQuRBFTcQNywdCL-7QACBRk"]
[Mon Jul 20 06:44:09.586940 2026] [security2:error] [pid 1011111:tid 1011239] [remote 80.82.65.226:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/blog/index.php"] [unique_id "al4YGRXES7Mv0Zfga-kYrQAAoH4"]
[Mon Jul 20 06:44:09.621132 2026] [security2:error] [pid 1014214:tid 1014348] [client 173.239.240.30:48635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YGQuRBFTcQNywdCL--QAAAZM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:09.637230 2026] [security2:error] [pid 1014214:tid 1014369] [client 57.141.18.34:38772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YFAuRBFTcQNywdCL9fAABqCU"]
[Mon Jul 20 06:44:09.688147 2026] [security2:error] [pid 1011111:tid 1011358] [client 14.224.227.113:54665] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YGRXES7Mv0Zfga-kYsAAAAPk"]
[Mon Jul 20 06:44:09.727814 2026] [security2:error] [pid 1014214:tid 1014275] [remote 80.82.65.226:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YGQuRBFTcQNywdCL-_AAB1Dw"]
[Mon Jul 20 06:44:09.728740 2026] [security2:error] [pid 1014214:tid 1014436] [client 77.110.127.138:53705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGQuRBFTcQNywdCL-_QAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:09.728847 2026] [security2:error] [pid 1014214:tid 1014436] [client 77.110.127.138:53705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGQuRBFTcQNywdCL-_QAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:09.962282 2026] [security2:error] [pid 1014214:tid 1014372] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YGQuRBFTcQNywdCL_DwABq1Q"]
[Mon Jul 20 06:44:09.992549 2026] [security2:error] [pid 1014214:tid 1014276] [remote 80.82.65.226:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/wordpress/index.php"] [unique_id "al4YGQuRBFTcQNywdCL_EAABoT0"]
[Mon Jul 20 06:44:10.032693 2026] [security2:error] [pid 1011111:tid 1011367] [client 14.225.17.146:58849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4YGBXES7Mv0Zfga-kYYQAAAQI"], referer: http://reosportsboats.com/new
[Mon Jul 20 06:44:10.055065 2026] [security2:error] [pid 1011111:tid 1011266] [client 34.73.38.214:62565] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.eql.eda.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YGhXES7Mv0Zfga-kYxgAAAJ0"]
[Mon Jul 20 06:44:10.102183 2026] [security2:error] [pid 1011111:tid 1011349] [client 173.239.240.98:32743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YGhXES7Mv0Zfga-kYyAAAAPA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:10.130546 2026] [security2:error] [pid 1011111:tid 1011162] [remote 80.82.65.226:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/cms/index.php"] [unique_id "al4YGhXES7Mv0Zfga-kYzAAAujE"]
[Mon Jul 20 06:44:10.160837 2026] [security2:error] [pid 1011111:tid 1011300] [client 136.108.37.179:56811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aljosour-alarabia.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4YGhXES7Mv0Zfga-kYzgAAAL8"]
[Mon Jul 20 06:44:10.160940 2026] [security2:error] [pid 1011111:tid 1011300] [client 136.108.37.179:56811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aljosour-alarabia.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4YGhXES7Mv0Zfga-kYzgAAAL8"]
[Mon Jul 20 06:44:10.206931 2026] [security2:error] [pid 1014214:tid 1014304] [remote 80.82.65.226:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/wp/index.php"] [unique_id "al4YGguRBFTcQNywdCL_HAABplk"]
[Mon Jul 20 06:44:10.242368 2026] [security2:error] [pid 1011111:tid 1011247] [client 136.108.37.179:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aljosour-alarabia.com"] [uri "/xmlrpc.php"] [unique_id "al4YGhXES7Mv0Zfga-kY0gAAAIo"]
[Mon Jul 20 06:44:10.242452 2026] [security2:error] [pid 1011111:tid 1011247] [client 136.108.37.179:56872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aljosour-alarabia.com"] [uri "/xmlrpc.php"] [unique_id "al4YGhXES7Mv0Zfga-kY0gAAAIo"]
[Mon Jul 20 06:44:10.285341 2026] [security2:error] [pid 1014214:tid 1014415] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YGguRBFTcQNywdCL_FwAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:10.344566 2026] [security2:error] [pid 1014214:tid 1014374] [client 103.66.148.71:38172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL9tgABrUg"], referer: https://toddnielsen.com
[Mon Jul 20 06:44:10.415278 2026] [security2:error] [pid 1014214:tid 1014417] [client 162.219.176.3:44986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4YGguRBFTcQNywdCL_KQAAAdg"]
[Mon Jul 20 06:44:10.415387 2026] [security2:error] [pid 1014214:tid 1014417] [client 162.219.176.3:44986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4YGguRBFTcQNywdCL_KQAAAdg"]
[Mon Jul 20 06:44:10.454067 2026] [security2:error] [pid 1014214:tid 1014371] [client 3.75.183.99:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YGguRBFTcQNywdCL_KwAAAao"]
[Mon Jul 20 06:44:10.502677 2026] [security2:error] [pid 1014214:tid 1014308] [remote 80.82.65.226:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/blog/index.php"] [unique_id "al4YGguRBFTcQNywdCL_LgABwV0"]
[Mon Jul 20 06:44:10.513415 2026] [security2:error] [pid 1011111:tid 1011253] [client 77.110.127.138:53716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGhXES7Mv0Zfga-kY4gAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:10.513501 2026] [security2:error] [pid 1011111:tid 1011253] [client 77.110.127.138:53716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGhXES7Mv0Zfga-kY4gAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:10.521456 2026] [security2:error] [pid 1011111:tid 1011357] [client 14.225.17.146:58767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4YFxXES7Mv0Zfga-kYQAAAAPg"], referer: http://bruceledewitz.com/new
[Mon Jul 20 06:44:10.537964 2026] [security2:error] [pid 1014214:tid 1014440] [client 57.141.18.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YGguRBFTcQNywdCL_KAAAAe8"]
[Mon Jul 20 06:44:10.573062 2026] [security2:error] [pid 1011111:tid 1011278] [client 173.239.240.91:34349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YGhXES7Mv0Zfga-kY5QAAAKk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:10.748442 2026] [security2:error] [pid 1014214:tid 1014364] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YGguRBFTcQNywdCL_OQABo1g"]
[Mon Jul 20 06:44:10.917932 2026] [security2:error] [pid 1011111:tid 1011194] [remote 80.82.65.226:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/site/index.php"] [unique_id "al4YGhXES7Mv0Zfga-kY-wAAxlE"]
[Mon Jul 20 06:44:10.924922 2026] [security2:error] [pid 1014214:tid 1014407] [client 57.141.18.47:62522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL92wABzg0"]
[Mon Jul 20 06:44:10.948035 2026] [security2:error] [pid 1014214:tid 1014317] [remote 80.82.65.226:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/cms/index.php"] [unique_id "al4YGguRBFTcQNywdCL_PgABn2Y"]
[Mon Jul 20 06:44:11.021571 2026] [security2:error] [pid 1014214:tid 1014405] [client 136.144.35.252:45723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YGwuRBFTcQNywdCL_QQAAAcw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:11.028799 2026] [security2:error] [pid 1011111:tid 1011244] [client 63.176.132.15:48330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YGxXES7Mv0Zfga-kZBQAAAIc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:44:11.030688 2026] [security2:error] [pid 1014214:tid 1014314] [remote 80.82.65.226:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/wordpress/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_QgABrGM"]
[Mon Jul 20 06:44:11.079840 2026] [security2:error] [pid 1014214:tid 1014433] [client 57.141.18.8:57106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YFQuRBFTcQNywdCL95wAB6CM"]
[Mon Jul 20 06:44:11.242167 2026] [security2:error] [pid 1014214:tid 1014451] [client 80.82.65.226:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108-179-214-134.unifiedlayer.com"] [uri "/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_SQAB-mU"]
[Mon Jul 20 06:44:11.424578 2026] [security2:error] [pid 1014214:tid 1014413] [client 77.110.127.138:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGwuRBFTcQNywdCL_VgAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:11.424662 2026] [security2:error] [pid 1014214:tid 1014413] [client 77.110.127.138:53724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGwuRBFTcQNywdCL_VgAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:11.480459 2026] [security2:error] [pid 1014214:tid 1014374] [client 173.239.240.101:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_WgAAAa0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:11.549325 2026] [security2:error] [pid 1014214:tid 1014333] [remote 80.82.65.226:42450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "108-179-215-73.unifiedlayer.com"] [uri "/site/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_YQAB8nY"]
[Mon Jul 20 06:44:11.716070 2026] [security2:error] [pid 1014214:tid 1014335] [remote 80.82.65.226:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/blog/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_awAB8Hg"]
[Mon Jul 20 06:44:11.755526 2026] [security2:error] [pid 1014214:tid 1014313] [remote 173.212.252.15:37072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4YGwuRBFTcQNywdCL_bgAB-GI"]
[Mon Jul 20 06:44:11.838527 2026] [security2:error] [pid 1014214:tid 1014425] [client 14.225.17.146:50288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_ZwAAAeA"], referer: http://ksands.co.uk/new
[Mon Jul 20 06:44:11.850690 2026] [security2:error] [pid 1014214:tid 1014366] [client 104.234.53.84:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YGwuRBFTcQNywdCL_bwAAAaU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:11.878719 2026] [security2:error] [pid 1014214:tid 1014418] [client 77.110.127.138:53681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGwuRBFTcQNywdCL_dAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:11.878838 2026] [security2:error] [pid 1014214:tid 1014418] [client 77.110.127.138:53681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YGwuRBFTcQNywdCL_dAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:11.947020 2026] [security2:error] [pid 1014214:tid 1014384] [client 57.141.18.42:60188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YFguRBFTcQNywdCL-KAABt3c"]
[Mon Jul 20 06:44:11.950392 2026] [security2:error] [pid 1014214:tid 1014465] [client 136.144.35.247:31033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YGwuRBFTcQNywdCL_dgAAAgg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:11.996773 2026] [security2:error] [pid 1014214:tid 1014325] [remote 173.212.252.15:37072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4YGwuRBFTcQNywdCL_fQABvm4"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:44:12.058265 2026] [security2:error] [pid 1014214:tid 1014444] [client 98.159.234.160:51507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YHAuRBFTcQNywdCL_fwAAAfM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:12.278727 2026] [security2:error] [pid 1014214:tid 1014454] [client 37.52.210.45:53851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YHAuRBFTcQNywdCL_igAAAf0"]
[Mon Jul 20 06:44:12.278877 2026] [security2:error] [pid 1014214:tid 1014454] [client 37.52.210.45:53851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YHAuRBFTcQNywdCL_igAAAf0"]
[Mon Jul 20 06:44:12.369476 2026] [security2:error] [pid 1014214:tid 1014216] [remote 80.82.65.226:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/cms/index.php"] [unique_id "al4YHAuRBFTcQNywdCL_kAACDQE"]
[Mon Jul 20 06:44:12.385962 2026] [security2:error] [pid 1014214:tid 1014424] [client 14.225.17.146:51120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4YHAuRBFTcQNywdCL_hwAAAd8"], referer: http://secretkeynumerology.com/new
[Mon Jul 20 06:44:12.402255 2026] [security2:error] [pid 1014214:tid 1014383] [client 173.239.240.31:31137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YHAuRBFTcQNywdCL_kgAAAbY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:12.459894 2026] [security2:error] [pid 1014214:tid 1014349] [client 77.110.127.138:53732] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YHAuRBFTcQNywdCL_lgAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:12.605549 2026] [security2:error] [pid 1014214:tid 1014460] [client 14.225.17.146:51280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4YHAuRBFTcQNywdCL_mwAAAgM"], referer: http://grndl.com/new
[Mon Jul 20 06:44:12.645589 2026] [security2:error] [pid 1011111:tid 1011359] [client 77.110.127.138:53735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YHBXES7Mv0Zfga-kZQgAAAPo"]
[Mon Jul 20 06:44:12.645680 2026] [security2:error] [pid 1011111:tid 1011359] [client 77.110.127.138:53735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YHBXES7Mv0Zfga-kZQgAAAPo"]
[Mon Jul 20 06:44:12.648294 2026] [security2:error] [pid 1014214:tid 1014385] [client 57.141.18.120:40226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YFwuRBFTcQNywdCL-XQABuBQ"]
[Mon Jul 20 06:44:12.856947 2026] [security2:error] [pid 1014214:tid 1014461] [client 173.239.240.32:31967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YHAuRBFTcQNywdCL_qAAAAgQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:12.974935 2026] [security2:error] [pid 1014214:tid 1014223] [remote 80.82.65.226:55078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.boracayhaven.com.ph"] [uri "/site/index.php"] [unique_id "al4YHAuRBFTcQNywdCL_rAABoQg"]
[Mon Jul 20 06:44:13.026180 2026] [proxy:error] [pid 1011111:tid 1011286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:13.026270 2026] [proxy_http:error] [pid 1011111:tid 1011286] [client 34.73.38.214:54616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:13.026896 2026] [proxy:error] [pid 1011111:tid 1011286] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:13.026926 2026] [proxy_http:error] [pid 1011111:tid 1011286] [client 34.73.38.214:54616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:13.206132 2026] [security2:error] [pid 1011111:tid 1011290] [client 77.110.127.138:53694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YHRXES7Mv0Zfga-kZYgAAALU"]
[Mon Jul 20 06:44:13.206225 2026] [security2:error] [pid 1011111:tid 1011290] [client 77.110.127.138:53694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YHRXES7Mv0Zfga-kZYgAAALU"]
[Mon Jul 20 06:44:13.249998 2026] [security2:error] [pid 1011111:tid 1011302] [client 50.116.65.227:32960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4YHRXES7Mv0Zfga-kZZwAAAME"]
[Mon Jul 20 06:44:13.267180 2026] [security2:error] [pid 1011111:tid 1011344] [client 50.116.65.227:43532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4YHRXES7Mv0Zfga-kZaAAAAOs"]
[Mon Jul 20 06:44:13.327715 2026] [security2:error] [pid 1011111:tid 1011308] [client 136.144.35.247:56319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YHRXES7Mv0Zfga-kZbQAAAMc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:13.382906 2026] [security2:error] [pid 1011111:tid 1011288] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YHRXES7Mv0Zfga-kZYAAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:13.393998 2026] [security2:error] [pid 1014214:tid 1014410] [client 14.225.17.146:51563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4YHQuRBFTcQNywdCL_swAAAdE"], referer: https://secretkeynumerology.com/new
[Mon Jul 20 06:44:13.780697 2026] [security2:error] [pid 1011111:tid 1011250] [client 173.239.240.32:36425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YHRXES7Mv0Zfga-kZfAAAAI0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:14.024240 2026] [security2:error] [pid 1014214:tid 1014363] [client 57.141.18.84:49976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YGAuRBFTcQNywdCL-tQABojY"]
[Mon Jul 20 06:44:14.037106 2026] [proxy:error] [pid 1014214:tid 1014461] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:14.037158 2026] [proxy_http:error] [pid 1014214:tid 1014461] [client 34.73.38.214:59923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:14.037692 2026] [proxy:error] [pid 1014214:tid 1014461] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:14.037717 2026] [proxy_http:error] [pid 1014214:tid 1014461] [client 34.73.38.214:59923] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:14.234656 2026] [security2:error] [pid 1011111:tid 1011365] [client 136.144.35.252:46697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YHhXES7Mv0Zfga-kZiwAAAQA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:14.294657 2026] [access_compat:error] [pid 1011111:tid 1011200] [remote 52.52.227.69:36526] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:44:14.375248 2026] [proxy:error] [pid 1014214:tid 1014435] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:14.375325 2026] [proxy_http:error] [pid 1014214:tid 1014435] [client 34.73.38.214:64263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:14.376037 2026] [proxy:error] [pid 1014214:tid 1014435] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:14.376095 2026] [proxy_http:error] [pid 1014214:tid 1014435] [client 34.73.38.214:64263] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:14.454046 2026] [security2:error] [pid 1014214:tid 1014447] [client 149.130.209.122:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4YHguRBFTcQNywdCL_6wAB9js"]
[Mon Jul 20 06:44:14.482205 2026] [proxy:error] [pid 1011111:tid 1011302] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:14.482298 2026] [proxy_http:error] [pid 1011111:tid 1011302] [client 34.73.38.214:54712] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:14.483320 2026] [proxy:error] [pid 1011111:tid 1011302] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:14.483378 2026] [proxy_http:error] [pid 1011111:tid 1011302] [client 34.73.38.214:54712] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:14.724704 2026] [security2:error] [pid 1011111:tid 1011303] [client 173.239.240.101:55911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YHhXES7Mv0Zfga-kZogAAAMI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:14.811997 2026] [security2:error] [pid 1014214:tid 1014349] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YHguRBFTcQNywdCIAAgABlDc"]
[Mon Jul 20 06:44:14.931958 2026] [security2:error] [pid 1011111:tid 1011291] [client 39.48.81.23:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YHhXES7Mv0Zfga-kZqwAAALY"]
[Mon Jul 20 06:44:14.932043 2026] [security2:error] [pid 1011111:tid 1011291] [client 39.48.81.23:53596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YHhXES7Mv0Zfga-kZqwAAALY"]
[Mon Jul 20 06:44:15.041609 2026] [security2:error] [pid 1011111:tid 1011261] [client 50.116.65.227:32972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4YHxXES7Mv0Zfga-kZsAAAAJg"]
[Mon Jul 20 06:44:15.044926 2026] [security2:error] [pid 1011111:tid 1011361] [client 14.225.17.146:51729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4YHRXES7Mv0Zfga-kZeAAAAPw"]
[Mon Jul 20 06:44:15.102259 2026] [security2:error] [pid 1011111:tid 1011273] [client 199.45.155.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4YHhXES7Mv0Zfga-kZrwAAAKQ"]
[Mon Jul 20 06:44:15.215611 2026] [security2:error] [pid 1011111:tid 1011337] [client 173.239.240.30:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YHxXES7Mv0Zfga-kZuAAAAOQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:15.399265 2026] [security2:error] [pid 1014214:tid 1014388] [client 106.219.188.178:25743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YHwuRBFTcQNywdCIAJQAAAbs"]
[Mon Jul 20 06:44:15.399680 2026] [security2:error] [pid 1014214:tid 1014388] [client 106.219.188.178:25743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YHwuRBFTcQNywdCIAJQAAAbs"]
[Mon Jul 20 06:44:15.483456 2026] [security2:error] [pid 1014214:tid 1014466] [client 103.125.179.95:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YHwuRBFTcQNywdCIAKwAAAgk"]
[Mon Jul 20 06:44:15.483595 2026] [security2:error] [pid 1014214:tid 1014466] [client 103.125.179.95:50764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YHwuRBFTcQNywdCIAKwAAAgk"]
[Mon Jul 20 06:44:15.494164 2026] [proxy:error] [pid 1014214:tid 1014400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:15.494222 2026] [proxy_http:error] [pid 1014214:tid 1014400] [client 34.73.38.214:58144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:15.494864 2026] [proxy:error] [pid 1014214:tid 1014400] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:15.494889 2026] [proxy_http:error] [pid 1014214:tid 1014400] [client 34.73.38.214:58144] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:15.536992 2026] [security2:error] [pid 1014214:tid 1014295] [remote 100.42.189.89:59636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4YHwuRBFTcQNywdCIALwAB3VA"]
[Mon Jul 20 06:44:15.540279 2026] [security2:error] [pid 1014214:tid 1014442] [client 14.225.17.146:59813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4YHwuRBFTcQNywdCIAGgAAAfE"], referer: http://massagelacey.com/new
[Mon Jul 20 06:44:15.562666 2026] [security2:error] [pid 1014214:tid 1014365] [client 77.110.127.138:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YHwuRBFTcQNywdCIAMAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:15.562759 2026] [security2:error] [pid 1014214:tid 1014365] [client 77.110.127.138:53758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YHwuRBFTcQNywdCIAMAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:15.595160 2026] [security2:error] [pid 1014214:tid 1014410] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YHwuRBFTcQNywdCIAMQAB0U4"]
[Mon Jul 20 06:44:15.687449 2026] [security2:error] [pid 1014214:tid 1014445] [client 173.239.240.102:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YHwuRBFTcQNywdCIAPgAAAfQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:15.775002 2026] [security2:error] [pid 1014214:tid 1014304] [remote 100.42.189.89:59636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4YHwuRBFTcQNywdCIAQwABwFk"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:44:16.044681 2026] [proxy:error] [pid 1014214:tid 1014416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:16.044737 2026] [proxy_http:error] [pid 1014214:tid 1014416] [client 34.73.38.214:64932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:16.045472 2026] [proxy:error] [pid 1014214:tid 1014416] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:16.045500 2026] [proxy_http:error] [pid 1014214:tid 1014416] [client 34.73.38.214:64932] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:16.112158 2026] [proxy:error] [pid 1014214:tid 1014368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:16.112222 2026] [proxy_http:error] [pid 1014214:tid 1014368] [client 34.73.38.214:62275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:16.112875 2026] [proxy:error] [pid 1014214:tid 1014368] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:16.112912 2026] [proxy_http:error] [pid 1014214:tid 1014368] [client 34.73.38.214:62275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:16.133225 2026] [security2:error] [pid 1011111:tid 1011354] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YHxXES7Mv0Zfga-kZ1AAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:16.181542 2026] [security2:error] [pid 1011111:tid 1011297] [client 14.225.17.146:59768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4YHhXES7Mv0Zfga-kZnAAAALw"], referer: http://vinovinhowine.com/new
[Mon Jul 20 06:44:16.195912 2026] [security2:error] [pid 1014214:tid 1014448] [client 173.239.240.98:57521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YIAuRBFTcQNywdCIAVAAAAfc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:16.221157 2026] [security2:error] [pid 1014214:tid 1014387] [client 112.208.70.94:43071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YIAuRBFTcQNywdCIAVQAAAbo"]
[Mon Jul 20 06:44:16.221270 2026] [security2:error] [pid 1014214:tid 1014387] [client 112.208.70.94:43071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YIAuRBFTcQNywdCIAVQAAAbo"]
[Mon Jul 20 06:44:16.272711 2026] [security2:error] [pid 1011111:tid 1011116] [remote 216.38.28.47:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4YIBXES7Mv0Zfga-kZ4wAA9AM"]
[Mon Jul 20 06:44:16.317349 2026] [security2:error] [pid 1014214:tid 1014452] [client 45.157.112.60:36353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YIAuRBFTcQNywdCIAVwAAAfs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:16.437302 2026] [security2:error] [pid 1011111:tid 1011313] [client 57.141.18.118:65528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YGxXES7Mv0Zfga-kZEQAAzBA"]
[Mon Jul 20 06:44:16.440987 2026] [security2:error] [pid 1011111:tid 1011181] [remote 216.38.28.47:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.28.38.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4YIBXES7Mv0Zfga-kZ5wAA-UQ"], referer: https://iagdevelopments.com/wp-login.php
[Mon Jul 20 06:44:16.451503 2026] [security2:error] [pid 1014214:tid 1014435] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YIAuRBFTcQNywdCIAXQAB6lY"]
[Mon Jul 20 06:44:16.647917 2026] [security2:error] [pid 1014214:tid 1014442] [client 173.239.240.31:27721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YIAuRBFTcQNywdCIAaQAAAfE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:16.838864 2026] [security2:error] [pid 1014214:tid 1014314] [remote 68.178.160.25:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YIAuRBFTcQNywdCIAdAABoWM"]
[Mon Jul 20 06:44:16.903223 2026] [security2:error] [pid 1014214:tid 1014378] [client 57.141.18.61:20002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YGwuRBFTcQNywdCL_ZgABsWk"]
[Mon Jul 20 06:44:16.903867 2026] [security2:error] [pid 1014214:tid 1014259] [remote 80.82.65.226:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/index.php"] [unique_id "al4YIAuRBFTcQNywdCIAeQAB2iw"]
[Mon Jul 20 06:44:16.962389 2026] [security2:error] [pid 1011111:tid 1011244] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4YIBXES7Mv0Zfga-kZ6QAAAIc"]
[Mon Jul 20 06:44:17.022910 2026] [security2:error] [pid 1011111:tid 1011263] [client 122.183.32.225:5275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YIRXES7Mv0Zfga-kaAAAAAJo"]
[Mon Jul 20 06:44:17.032913 2026] [security2:error] [pid 1011111:tid 1011263] [client 122.183.32.225:5275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YIRXES7Mv0Zfga-kaAAAAAJo"]
[Mon Jul 20 06:44:17.080005 2026] [security2:error] [pid 1011111:tid 1011315] [client 183.82.98.154:57527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YIRXES7Mv0Zfga-kaAwAAAM4"]
[Mon Jul 20 06:44:17.080146 2026] [security2:error] [pid 1011111:tid 1011315] [client 183.82.98.154:57527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YIRXES7Mv0Zfga-kaAwAAAM4"]
[Mon Jul 20 06:44:17.109879 2026] [security2:error] [pid 1011111:tid 1011355] [client 57.141.18.55:20276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YGxXES7Mv0Zfga-kZKwAA9gI"]
[Mon Jul 20 06:44:17.138599 2026] [security2:error] [pid 1014214:tid 1014403] [client 136.144.35.243:30143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YIQuRBFTcQNywdCIAiAAAAco"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:17.144395 2026] [security2:error] [pid 1014214:tid 1014357] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YIQuRBFTcQNywdCIAhwABnHE"]
[Mon Jul 20 06:44:17.310910 2026] [security2:error] [pid 1014214:tid 1014368] [client 34.73.38.214:60509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/xmlrpc.php"] [unique_id "al4YIQuRBFTcQNywdCIAkwAAAac"]
[Mon Jul 20 06:44:17.361994 2026] [security2:error] [pid 1014214:tid 1014238] [remote 68.178.160.25:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YIQuRBFTcQNywdCIAlAAB9xc"], referer: https://zbj.ahr.mybluehost.me/wp-login.php
[Mon Jul 20 06:44:17.424108 2026] [security2:error] [pid 1014214:tid 1014398] [client 57.141.18.62:64308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YHAuRBFTcQNywdCL_gwABxXM"]
[Mon Jul 20 06:44:17.596064 2026] [security2:error] [pid 1014214:tid 1014358] [client 34.181.240.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ipl.ysa.mybluehost.me"] [uri "/index.php"] [unique_id "al4YIQuRBFTcQNywdCIApgAAAZ0"]
[Mon Jul 20 06:44:17.607905 2026] [security2:error] [pid 1014214:tid 1014404] [client 136.144.35.250:32451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YIQuRBFTcQNywdCIAqgAAAcs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:17.663983 2026] [security2:error] [pid 1014214:tid 1014436] [client 34.181.240.240:50258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.240.181.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ipl.ysa.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YIQuRBFTcQNywdCIArgAAAes"]
[Mon Jul 20 06:44:17.678213 2026] [security2:error] [pid 1014214:tid 1014244] [remote 80.82.65.226:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/wp/index.php"] [unique_id "al4YIQuRBFTcQNywdCIArwAB8B0"]
[Mon Jul 20 06:44:17.806699 2026] [security2:error] [pid 1011111:tid 1011309] [client 14.225.17.146:57916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4YIBXES7Mv0Zfga-kZ9QAAAMg"], referer: http://sarahholyfield.com/new
[Mon Jul 20 06:44:17.813328 2026] [security2:error] [pid 1014214:tid 1014373] [client 80.82.65.226:55078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.boracayhaven.com.ph"] [uri "/index.php"] [unique_id "al4YIQuRBFTcQNywdCIAtwABrG8"]
[Mon Jul 20 06:44:17.836201 2026] [proxy:error] [pid 1014214:tid 1014353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:17.836277 2026] [proxy_http:error] [pid 1014214:tid 1014353] [client 34.73.38.214:62278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:17.837115 2026] [proxy:error] [pid 1014214:tid 1014353] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:17.837147 2026] [proxy_http:error] [pid 1014214:tid 1014353] [client 34.73.38.214:62278] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:17.862542 2026] [proxy:error] [pid 1011111:tid 1011347] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:17.862592 2026] [proxy_http:error] [pid 1011111:tid 1011347] [client 34.73.38.214:52713] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:17.863146 2026] [proxy:error] [pid 1011111:tid 1011347] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:17.863172 2026] [proxy_http:error] [pid 1011111:tid 1011347] [client 34.73.38.214:52713] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:17.948860 2026] [security2:error] [pid 1014214:tid 1014409] [client 34.181.240.240:50414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YIQuRBFTcQNywdCIAxwAAAdA"]
[Mon Jul 20 06:44:18.090900 2026] [security2:error] [pid 1014214:tid 1014432] [client 173.239.240.93:44159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YIguRBFTcQNywdCIA1QAAAec"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:18.094581 2026] [security2:error] [pid 1014214:tid 1014405] [client 193.37.252.163:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4YIguRBFTcQNywdCIA0wAAAcw"]
[Mon Jul 20 06:44:18.094656 2026] [security2:error] [pid 1014214:tid 1014405] [client 193.37.252.163:35296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4YIguRBFTcQNywdCIA0wAAAcw"]
[Mon Jul 20 06:44:18.137365 2026] [security2:error] [pid 1014214:tid 1014442] [client 34.73.38.214:53394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YIguRBFTcQNywdCIA3AAAAfE"]
[Mon Jul 20 06:44:18.253741 2026] [security2:error] [pid 1014214:tid 1014386] [client 34.181.240.240:63440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YIguRBFTcQNywdCIA4AAAAbk"]
[Mon Jul 20 06:44:18.488695 2026] [security2:error] [pid 1014214:tid 1014242] [remote 80.82.65.226:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/wordpress/index.php"] [unique_id "al4YIguRBFTcQNywdCIA8AABtBs"]
[Mon Jul 20 06:44:18.530820 2026] [security2:error] [pid 1011111:tid 1011368] [client 34.181.240.240:58173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YIhXES7Mv0Zfga-kaNgAAAQM"]
[Mon Jul 20 06:44:18.559864 2026] [security2:error] [pid 1014214:tid 1014470] [client 130.12.17.83:47799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4YIguRBFTcQNywdCIA6wACDSg"]
[Mon Jul 20 06:44:18.569192 2026] [security2:error] [pid 1014214:tid 1014444] [client 173.239.240.32:27531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YIguRBFTcQNywdCIA9QAAAfM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:18.575187 2026] [security2:error] [pid 1014214:tid 1014401] [client 187.108.85.186:51733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YIguRBFTcQNywdCIA9gAAAcg"]
[Mon Jul 20 06:44:18.575273 2026] [security2:error] [pid 1014214:tid 1014401] [client 187.108.85.186:51733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YIguRBFTcQNywdCIA9gAAAcg"]
[Mon Jul 20 06:44:18.601014 2026] [security2:error] [pid 1011111:tid 1011274] [client 50.116.65.227:43564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YIhXES7Mv0Zfga-kaOQAAAKU"]
[Mon Jul 20 06:44:18.606645 2026] [security2:error] [pid 1014214:tid 1014346] [client 104.234.53.72:26015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YIguRBFTcQNywdCIA9wAAAZE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:18.609454 2026] [security2:error] [pid 1011111:tid 1011304] [client 57.141.18.24:41138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YHRXES7Mv0Zfga-kZWgAAw1Q"]
[Mon Jul 20 06:44:18.611393 2026] [security2:error] [pid 1014214:tid 1014363] [client 50.116.65.227:43572] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YIguRBFTcQNywdCIA-AAAAaI"]
[Mon Jul 20 06:44:18.620954 2026] [security2:error] [pid 1014214:tid 1014227] [remote 110.249.202.174:53008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/the-700-year-old-reason-for-the-disciples-astonishment-isaiah-29/"] [unique_id "al4YIguRBFTcQNywdCIA-QABkgw"]
[Mon Jul 20 06:44:18.660580 2026] [security2:error] [pid 1011111:tid 1011230] [remote 80.82.65.226:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/index.php"] [unique_id "al4YIhXES7Mv0Zfga-kaOwAA63U"]
[Mon Jul 20 06:44:18.697929 2026] [security2:error] [pid 1011111:tid 1011346] [client 103.238.106.162:63931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YIhXES7Mv0Zfga-kaPgAAAO0"]
[Mon Jul 20 06:44:18.698719 2026] [security2:error] [pid 1011111:tid 1011346] [client 103.238.106.162:63931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YIhXES7Mv0Zfga-kaPgAAAO0"]
[Mon Jul 20 06:44:18.702531 2026] [security2:error] [pid 1011111:tid 1011362] [client 34.73.38.214:64914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.fansarogroup.com"] [uri "/xmlrpc.php"] [unique_id "al4YIhXES7Mv0Zfga-kaPwAAAP0"]
[Mon Jul 20 06:44:18.841873 2026] [security2:error] [pid 1014214:tid 1014463] [client 34.181.240.240:64834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YIguRBFTcQNywdCIBBAAAAgY"]
[Mon Jul 20 06:44:18.871674 2026] [security2:error] [pid 1011111:tid 1011356] [client 171.61.165.146:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YIhXES7Mv0Zfga-kaQwAAAPc"]
[Mon Jul 20 06:44:18.871786 2026] [security2:error] [pid 1011111:tid 1011356] [client 171.61.165.146:32971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YIhXES7Mv0Zfga-kaQwAAAPc"]
[Mon Jul 20 06:44:18.896857 2026] [security2:error] [pid 1014214:tid 1014386] [client 34.73.38.214:60298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/xmlrpc.php"] [unique_id "al4YIguRBFTcQNywdCIBDAAAAbk"]
[Mon Jul 20 06:44:18.898513 2026] [security2:error] [pid 1014214:tid 1014407] [client 14.225.17.146:53657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4YIguRBFTcQNywdCIA_AAAAc4"], referer: http://sesamegreenbeans.com/new
[Mon Jul 20 06:44:19.079657 2026] [security2:error] [pid 1014214:tid 1014427] [client 173.239.240.98:57555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YIwuRBFTcQNywdCIBEQAAAeI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:19.111789 2026] [security2:error] [pid 1014214:tid 1014349] [client 34.181.240.240:62597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YIwuRBFTcQNywdCIBFAAAAZQ"]
[Mon Jul 20 06:44:19.155572 2026] [security2:error] [pid 1011111:tid 1011138] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YIxXES7Mv0Zfga-kaSQAAwhk"]
[Mon Jul 20 06:44:19.155696 2026] [security2:error] [pid 1011111:tid 1011303] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YIxXES7Mv0Zfga-kaSQAAwhk"]
[Mon Jul 20 06:44:19.239775 2026] [security2:error] [pid 1011111:tid 1011320] [client 47.128.124.75:11526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ancestralidadytrance.space"] [uri "/robots.txt"] [unique_id "al4YIxXES7Mv0Zfga-kaTAAAANM"]
[Mon Jul 20 06:44:19.288871 2026] [security2:error] [pid 1014214:tid 1014435] [client 217.142.18.172:24805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBIAAAAeo"]
[Mon Jul 20 06:44:19.288970 2026] [security2:error] [pid 1014214:tid 1014435] [client 217.142.18.172:24805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBIAAAAeo"]
[Mon Jul 20 06:44:19.305155 2026] [security2:error] [pid 1014214:tid 1014441] [client 197.186.66.42:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBIQAAAfA"]
[Mon Jul 20 06:44:19.305862 2026] [security2:error] [pid 1014214:tid 1014441] [client 197.186.66.42:60776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBIQAAAfA"]
[Mon Jul 20 06:44:19.323834 2026] [core:error] [pid 1011111:tid 1011273] [client 65.110.40.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:19.323864 2026] [core:error] [pid 1011111:tid 1011273] [client 65.110.40.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:19.330566 2026] [security2:error] [pid 1011111:tid 1011361] [client 77.110.127.138:53794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YIxXES7Mv0Zfga-kaVAAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:19.330649 2026] [security2:error] [pid 1011111:tid 1011361] [client 77.110.127.138:53794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YIxXES7Mv0Zfga-kaVAAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:19.393311 2026] [security2:error] [pid 1011111:tid 1011353] [client 34.181.240.240:57726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YIxXES7Mv0Zfga-kaVwAAAPQ"]
[Mon Jul 20 06:44:19.414343 2026] [security2:error] [pid 1014214:tid 1014462] [client 34.73.38.214:65030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YIwuRBFTcQNywdCIBJwAAAgU"]
[Mon Jul 20 06:44:19.482647 2026] [security2:error] [pid 1014214:tid 1014416] [client 152.58.191.29:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBLQAAAdc"]
[Mon Jul 20 06:44:19.486451 2026] [core:error] [pid 1014214:tid 1014430] [client 65.110.40.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:19.486469 2026] [core:error] [pid 1014214:tid 1014430] [client 65.110.40.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:19.490187 2026] [security2:error] [pid 1014214:tid 1014416] [client 152.58.191.29:48150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBLQAAAdc"]
[Mon Jul 20 06:44:19.493562 2026] [core:error] [pid 1014214:tid 1014360] [client 65.110.40.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:19.493578 2026] [core:error] [pid 1014214:tid 1014360] [client 65.110.40.182:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:19.530082 2026] [security2:error] [pid 1014214:tid 1014418] [client 136.144.35.251:42661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBMwAAAdk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:19.608289 2026] [security2:error] [pid 1011111:tid 1011177] [remote 80.82.65.226:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/wp/index.php"] [unique_id "al4YIxXES7Mv0Zfga-kaWwAArEA"]
[Mon Jul 20 06:44:19.613987 2026] [security2:error] [pid 1014214:tid 1014280] [remote 80.82.65.226:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/blog/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBNgABpUE"]
[Mon Jul 20 06:44:19.646981 2026] [security2:error] [pid 1011111:tid 1011317] [client 77.110.127.138:53800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YIxXES7Mv0Zfga-kaXQAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:19.648582 2026] [security2:error] [pid 1011111:tid 1011317] [client 77.110.127.138:53800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YIxXES7Mv0Zfga-kaXQAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:19.667732 2026] [security2:error] [pid 1014214:tid 1014431] [client 34.181.240.240:64838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YIwuRBFTcQNywdCIBPQAAAeY"]
[Mon Jul 20 06:44:19.754510 2026] [security2:error] [pid 1014214:tid 1014435] [client 34.73.38.214:60414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YIwuRBFTcQNywdCIBSAAAAeo"]
[Mon Jul 20 06:44:19.864515 2026] [security2:error] [pid 1011111:tid 1011203] [remote 216.73.216.55:28298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4YIxXES7Mv0Zfga-kaaQAApVo"]
[Mon Jul 20 06:44:19.880956 2026] [security2:error] [pid 1014214:tid 1014379] [client 14.225.17.146:57976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBQgAAAbI"], referer: https://sesamegreenbeans.com/new
[Mon Jul 20 06:44:19.954246 2026] [security2:error] [pid 1014214:tid 1014453] [client 117.247.108.24:53006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBTwAAAfw"]
[Mon Jul 20 06:44:19.954362 2026] [security2:error] [pid 1014214:tid 1014453] [client 117.247.108.24:53006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YIwuRBFTcQNywdCIBTwAAAfw"]
[Mon Jul 20 06:44:19.965216 2026] [security2:error] [pid 1011111:tid 1011315] [client 34.181.240.240:51482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YIxXES7Mv0Zfga-kaawAAAM4"]
[Mon Jul 20 06:44:20.003826 2026] [security2:error] [pid 1011111:tid 1011351] [client 173.239.240.97:47219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YJBXES7Mv0Zfga-kabAAAAPI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:20.105128 2026] [security2:error] [pid 1014214:tid 1014376] [client 34.73.38.214:55985] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YJAuRBFTcQNywdCIBWAAAAa8"]
[Mon Jul 20 06:44:20.195551 2026] [security2:error] [pid 1014214:tid 1014430] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBUgAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:20.215581 2026] [security2:error] [pid 1014214:tid 1014451] [client 34.181.240.240:61488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YJAuRBFTcQNywdCIBYgAAAfo"]
[Mon Jul 20 06:44:20.458321 2026] [security2:error] [pid 1014214:tid 1014352] [client 173.239.240.95:43349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YJAuRBFTcQNywdCIBawAAAZc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:20.480510 2026] [security2:error] [pid 1014214:tid 1014440] [client 34.181.240.240:65206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YJAuRBFTcQNywdCIBbgAAAe8"]
[Mon Jul 20 06:44:20.512088 2026] [security2:error] [pid 1014214:tid 1014377] [client 77.110.127.138:53825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJAuRBFTcQNywdCIBbwAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:20.512161 2026] [security2:error] [pid 1014214:tid 1014377] [client 77.110.127.138:53825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJAuRBFTcQNywdCIBbwAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:20.515661 2026] [security2:error] [pid 1011111:tid 1011225] [remote 80.82.65.226:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/wordpress/index.php"] [unique_id "al4YJBXES7Mv0Zfga-kadgAA9XA"]
[Mon Jul 20 06:44:20.542106 2026] [security2:error] [pid 1014214:tid 1014359] [client 57.141.18.102:38976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YHwuRBFTcQNywdCIAFgABnkk"]
[Mon Jul 20 06:44:20.619238 2026] [security2:error] [pid 1014214:tid 1014300] [remote 80.82.65.226:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/cms/index.php"] [unique_id "al4YJAuRBFTcQNywdCIBdQABslU"]
[Mon Jul 20 06:44:20.724487 2026] [access_compat:error] [pid 1014214:tid 1014285] [remote 87.123.244.162:1370] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:44:20.761539 2026] [security2:error] [pid 1011111:tid 1011243] [client 34.181.240.240:64205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YJBXES7Mv0Zfga-kagAAAAIY"]
[Mon Jul 20 06:44:20.763193 2026] [security2:error] [pid 1011111:tid 1011259] [client 77.110.127.138:53830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJBXES7Mv0Zfga-kagQAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:20.763281 2026] [security2:error] [pid 1011111:tid 1011259] [client 77.110.127.138:53830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJBXES7Mv0Zfga-kagQAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:20.791531 2026] [security2:error] [pid 1014214:tid 1014452] [client 34.73.38.214:56551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YJAuRBFTcQNywdCIBfAAAAfs"]
[Mon Jul 20 06:44:20.860508 2026] [security2:error] [pid 1011111:tid 1011266] [client 57.141.18.105:57958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YHxXES7Mv0Zfga-kZugAAnU4"]
[Mon Jul 20 06:44:20.905197 2026] [security2:error] [pid 1014214:tid 1014348] [client 104.234.53.48:27891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YJAuRBFTcQNywdCIBgwAAAZM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:20.929622 2026] [security2:error] [pid 1014214:tid 1014454] [client 173.239.240.100:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YJAuRBFTcQNywdCIBhAAAAf0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:20.992398 2026] [security2:error] [pid 1014214:tid 1014462] [client 34.181.240.240:49734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ipl.ysa.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YJAuRBFTcQNywdCIBigAAAgU"]
[Mon Jul 20 06:44:21.018966 2026] [security2:error] [pid 1014214:tid 1014448] [client 34.73.38.214:57082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YJQuRBFTcQNywdCIBiwAAAfc"]
[Mon Jul 20 06:44:21.175405 2026] [security2:error] [pid 1014214:tid 1014458] [client 77.110.127.138:53836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJQuRBFTcQNywdCIBkQAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:21.175509 2026] [security2:error] [pid 1014214:tid 1014458] [client 77.110.127.138:53836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJQuRBFTcQNywdCIBkQAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:21.198623 2026] [security2:error] [pid 1014214:tid 1014398] [client 13.74.155.112:2240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YJQuRBFTcQNywdCIBkgAAAcU"]
[Mon Jul 20 06:44:21.263245 2026] [security2:error] [pid 1014214:tid 1014446] [client 52.237.147.83:23747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YJQuRBFTcQNywdCIBlgAAAfU"]
[Mon Jul 20 06:44:21.328998 2026] [security2:error] [pid 1014214:tid 1014357] [client 52.237.147.83:23747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YJQuRBFTcQNywdCIBmQAAAZw"]
[Mon Jul 20 06:44:21.333493 2026] [security2:error] [pid 1014214:tid 1014465] [client 13.74.155.112:2240] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YJQuRBFTcQNywdCIBmgAAAgg"]
[Mon Jul 20 06:44:21.381027 2026] [security2:error] [pid 1014214:tid 1014449] [client 77.110.127.138:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJQuRBFTcQNywdCIBnAAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:21.381157 2026] [security2:error] [pid 1014214:tid 1014449] [client 77.110.127.138:53838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJQuRBFTcQNywdCIBnAAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:21.411982 2026] [security2:error] [pid 1014214:tid 1014373] [client 173.239.240.100:44247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YJQuRBFTcQNywdCIBngAAAaw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:21.425580 2026] [security2:error] [pid 1014214:tid 1014347] [client 122.152.48.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBJAAAAZI"]
[Mon Jul 20 06:44:21.547889 2026] [security2:error] [pid 1014214:tid 1014344] [client 77.110.127.138:53843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJQuRBFTcQNywdCIBogAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:21.548010 2026] [security2:error] [pid 1014214:tid 1014344] [client 77.110.127.138:53843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YJQuRBFTcQNywdCIBogAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:21.667340 2026] [security2:error] [pid 1011111:tid 1011308] [client 57.141.18.60:40510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIBXES7Mv0Zfga-kZ2gAAx0s"]
[Mon Jul 20 06:44:21.699002 2026] [core:error] [pid 1011111:tid 1011254] [client 87.236.176.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:21.699022 2026] [core:error] [pid 1011111:tid 1011254] [client 87.236.176.59:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:21.714301 2026] [security2:error] [pid 1011111:tid 1011154] [remote 80.82.65.226:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/blog/index.php"] [unique_id "al4YJRXES7Mv0Zfga-kalgAAkik"]
[Mon Jul 20 06:44:21.722740 2026] [security2:error] [pid 1011111:tid 1011335] [client 57.141.18.55:20288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIBXES7Mv0Zfga-kZ3wAA4no"]
[Mon Jul 20 06:44:21.736577 2026] [security2:error] [pid 1014214:tid 1014411] [client 34.73.38.214:63627] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YJQuRBFTcQNywdCIBrAAAAdI"]
[Mon Jul 20 06:44:21.767641 2026] [security2:error] [pid 1014214:tid 1014310] [remote 80.82.65.226:42456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluehost.com"] [uri "/site/index.php"] [unique_id "al4YJQuRBFTcQNywdCIBsQAB8F8"]
[Mon Jul 20 06:44:21.837043 2026] [security2:error] [pid 1014214:tid 1014466] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4YJQuRBFTcQNywdCIBqwAAAgk"]
[Mon Jul 20 06:44:21.873789 2026] [security2:error] [pid 1011111:tid 1011351] [client 34.73.38.214:59091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YJRXES7Mv0Zfga-kaoAAAAPI"]
[Mon Jul 20 06:44:21.884583 2026] [security2:error] [pid 1014214:tid 1014360] [client 34.73.38.214:60261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YJQuRBFTcQNywdCIBtQAAAZ8"]
[Mon Jul 20 06:44:21.886081 2026] [security2:error] [pid 1011111:tid 1011260] [client 136.144.35.252:25857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YJRXES7Mv0Zfga-kapAAAAJc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:22.209082 2026] [security2:error] [pid 1014214:tid 1014423] [client 223.185.13.213:12770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YJguRBFTcQNywdCIBxwAAAd4"]
[Mon Jul 20 06:44:22.209186 2026] [security2:error] [pid 1014214:tid 1014423] [client 223.185.13.213:12770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YJguRBFTcQNywdCIBxwAAAd4"]
[Mon Jul 20 06:44:22.241105 2026] [security2:error] [pid 1011111:tid 1011292] [client 34.73.38.214:60263] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YJhXES7Mv0Zfga-karAAAALc"]
[Mon Jul 20 06:44:22.261622 2026] [security2:error] [pid 1014214:tid 1014306] [remote 162.19.86.63:52534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4YJguRBFTcQNywdCIBygABxVs"]
[Mon Jul 20 06:44:22.375556 2026] [security2:error] [pid 1014214:tid 1014381] [client 136.144.35.253:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YJguRBFTcQNywdCIBzgAAAbQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:22.463879 2026] [security2:error] [pid 1014214:tid 1014312] [remote 162.19.86.63:52534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4YJguRBFTcQNywdCIB2QABk2E"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 06:44:22.538124 2026] [security2:error] [pid 1014214:tid 1014405] [client 34.73.38.214:64449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YJguRBFTcQNywdCIB3gAAAcw"]
[Mon Jul 20 06:44:22.569091 2026] [security2:error] [pid 1011111:tid 1011113] [remote 80.82.65.226:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/cms/index.php"] [unique_id "al4YJhXES7Mv0Zfga-kaswAAyQA"]
[Mon Jul 20 06:44:22.799348 2026] [security2:error] [pid 1014214:tid 1014398] [client 34.73.38.214:55412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YJguRBFTcQNywdCIB8QAAAcU"]
[Mon Jul 20 06:44:22.852154 2026] [security2:error] [pid 1014214:tid 1014362] [client 14.225.17.146:50504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4YJQuRBFTcQNywdCIBoQAAAaE"], referer: http://colinkeyphotography.com/new
[Mon Jul 20 06:44:22.852988 2026] [security2:error] [pid 1011111:tid 1011320] [client 173.239.240.92:38021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YJhXES7Mv0Zfga-katgAAANM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:22.938700 2026] [security2:error] [pid 1011111:tid 1011243] [client 37.52.210.45:20771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YJhXES7Mv0Zfga-kauAAAAIY"]
[Mon Jul 20 06:44:22.938842 2026] [security2:error] [pid 1011111:tid 1011243] [client 37.52.210.45:20771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YJhXES7Mv0Zfga-kauAAAAIY"]
[Mon Jul 20 06:44:23.072085 2026] [security2:error] [pid 1014214:tid 1014454] [client 34.73.38.214:55163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YJwuRBFTcQNywdCICCAAAAf0"]
[Mon Jul 20 06:44:23.074888 2026] [security2:error] [pid 1011111:tid 1011333] [client 57.141.18.17:56302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIRXES7Mv0Zfga-kaEQAA4EM"]
[Mon Jul 20 06:44:23.110102 2026] [security2:error] [pid 1014214:tid 1014353] [client 104.210.140.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.phillipbloch.com"] [uri "/index.php"] [unique_id "al4YJguRBFTcQNywdCICBAAAAZg"]
[Mon Jul 20 06:44:23.306882 2026] [security2:error] [pid 1014214:tid 1014369] [client 34.73.38.214:62431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YJwuRBFTcQNywdCICHQAAAag"]
[Mon Jul 20 06:44:23.307139 2026] [security2:error] [pid 1014214:tid 1014366] [client 136.144.35.253:57277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YJwuRBFTcQNywdCICHgAAAaU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:23.503639 2026] [security2:error] [pid 1014214:tid 1014455] [client 112.203.164.244:23089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIguRBFTcQNywdCIA2gAB_h8"], referer: https://toddnielsen.com
[Mon Jul 20 06:44:23.543447 2026] [security2:error] [pid 1014214:tid 1014422] [client 57.141.18.40:29952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIguRBFTcQNywdCIA1AAB3QA"]
[Mon Jul 20 06:44:23.780820 2026] [security2:error] [pid 1014214:tid 1014465] [client 173.239.240.96:48107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YJwuRBFTcQNywdCICSwAAAgg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:23.786065 2026] [security2:error] [pid 1011111:tid 1011171] [remote 80.82.65.226:57928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.65.82.80.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.xavierprax.com"] [uri "/site/index.php"] [unique_id "al4YJxXES7Mv0Zfga-kaywAAkjo"]
[Mon Jul 20 06:44:23.898588 2026] [security2:error] [pid 1014214:tid 1014362] [client 14.225.17.146:61332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4YJwuRBFTcQNywdCICTAAAAaE"], referer: http://keywayconstructionclt.com/new
[Mon Jul 20 06:44:23.978683 2026] [security2:error] [pid 1014214:tid 1014449] [client 34.73.38.214:54231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YJwuRBFTcQNywdCICdQAAAfg"]
[Mon Jul 20 06:44:24.233620 2026] [security2:error] [pid 1014214:tid 1014432] [client 57.141.18.47:41022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIguRBFTcQNywdCIBBQAB5yc"]
[Mon Jul 20 06:44:24.255273 2026] [security2:error] [pid 1014214:tid 1014419] [client 173.239.240.100:27539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YKAuRBFTcQNywdCIChAAAAdo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:24.555496 2026] [security2:error] [pid 1011111:tid 1011261] [client 34.73.38.214:50255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YKBXES7Mv0Zfga-ka9AAAAJg"]
[Mon Jul 20 06:44:24.666646 2026] [security2:error] [pid 1011111:tid 1011353] [client 34.73.38.214:58558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YKBXES7Mv0Zfga-ka-QAAAPQ"]
[Mon Jul 20 06:44:24.738200 2026] [security2:error] [pid 1011111:tid 1011243] [client 173.239.240.97:62821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YKBXES7Mv0Zfga-ka-gAAAIY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:24.854241 2026] [security2:error] [pid 1011111:tid 1011170] [remote 5.161.225.162:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4YKBXES7Mv0Zfga-ka_QAA6jk"]
[Mon Jul 20 06:44:24.999661 2026] [security2:error] [pid 1014214:tid 1014359] [client 14.225.17.146:61303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4YJwuRBFTcQNywdCICGgAAAZ4"], referer: http://nomorewetsheets.net/new
[Mon Jul 20 06:44:25.053361 2026] [security2:error] [pid 1014214:tid 1014358] [client 57.141.18.113:30990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBNAABnS4"]
[Mon Jul 20 06:44:25.055447 2026] [security2:error] [pid 1014214:tid 1014459] [client 14.225.17.146:64853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4YJwuRBFTcQNywdCICJwAAAgI"], referer: http://ironcitywellness.com/new
[Mon Jul 20 06:44:25.064166 2026] [security2:error] [pid 1011111:tid 1011315] [client 39.48.81.23:54119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YKRXES7Mv0Zfga-kbBgAAAM4"]
[Mon Jul 20 06:44:25.066288 2026] [security2:error] [pid 1011111:tid 1011315] [client 39.48.81.23:54119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YKRXES7Mv0Zfga-kbBgAAAM4"]
[Mon Jul 20 06:44:25.072588 2026] [security2:error] [pid 1011111:tid 1011255] [client 14.224.227.113:54667] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YKRXES7Mv0Zfga-kbCAAAAJI"]
[Mon Jul 20 06:44:25.204951 2026] [security2:error] [pid 1014214:tid 1014412] [client 173.239.240.91:30169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YKQuRBFTcQNywdCICuwAAAdM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:25.209471 2026] [security2:error] [pid 1014214:tid 1014462] [client 14.225.17.146:61264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4YJwuRBFTcQNywdCICSQAAAgU"], referer: http://eframiproperties.com/new
[Mon Jul 20 06:44:25.227394 2026] [security2:error] [pid 1014214:tid 1014333] [remote 5.252.52.249:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4YKQuRBFTcQNywdCICvQABpXY"]
[Mon Jul 20 06:44:25.272481 2026] [security2:error] [pid 1014214:tid 1014438] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YKQuRBFTcQNywdCICtAAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:25.369188 2026] [security2:error] [pid 1014214:tid 1014384] [client 57.141.18.54:65246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YIwuRBFTcQNywdCIBUwABtxU"]
[Mon Jul 20 06:44:25.388146 2026] [security2:error] [pid 1011111:tid 1011277] [client 34.73.38.214:62624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YKRXES7Mv0Zfga-kbDwAAAKg"]
[Mon Jul 20 06:44:25.434650 2026] [security2:error] [pid 1014214:tid 1014340] [remote 5.252.52.249:59200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4YKQuRBFTcQNywdCIC0gAB_30"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:44:25.489830 2026] [security2:error] [pid 1014214:tid 1014360] [client 77.110.127.138:53899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YKQuRBFTcQNywdCIC1wAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:25.489925 2026] [security2:error] [pid 1014214:tid 1014360] [client 77.110.127.138:53899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YKQuRBFTcQNywdCIC1wAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:25.552723 2026] [security2:error] [pid 1011111:tid 1011161] [remote 5.161.225.162:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4YKRXES7Mv0Zfga-kbGgAAxjA"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:44:25.660125 2026] [security2:error] [pid 1014214:tid 1014416] [client 14.225.17.146:61331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4YJwuRBFTcQNywdCICdgAAAdc"], referer: http://superiorcopywriting.com/new
[Mon Jul 20 06:44:25.671711 2026] [security2:error] [pid 1014214:tid 1014377] [client 136.144.35.252:36465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YKQuRBFTcQNywdCIC4AAAAbA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:25.789993 2026] [security2:error] [pid 1014214:tid 1014371] [client 192.140.149.97:45030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YKQuRBFTcQNywdCIC6QAAAao"]
[Mon Jul 20 06:44:25.790108 2026] [security2:error] [pid 1014214:tid 1014371] [client 192.140.149.97:45030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YKQuRBFTcQNywdCIC6QAAAao"]
[Mon Jul 20 06:44:26.128161 2026] [security2:error] [pid 1014214:tid 1014464] [client 34.73.38.214:58526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YKguRBFTcQNywdCIC-QAAAgc"]
[Mon Jul 20 06:44:26.141678 2026] [security2:error] [pid 1011111:tid 1011261] [client 173.239.240.32:58563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YKhXES7Mv0Zfga-kbJgAAAJg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:26.176104 2026] [security2:error] [pid 1014214:tid 1014436] [client 106.219.188.178:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YKguRBFTcQNywdCIC-wAAAes"]
[Mon Jul 20 06:44:26.176195 2026] [security2:error] [pid 1014214:tid 1014436] [client 106.219.188.178:42194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YKguRBFTcQNywdCIC-wAAAes"]
[Mon Jul 20 06:44:26.437816 2026] [security2:error] [pid 1014214:tid 1014398] [client 34.73.38.214:57580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YKguRBFTcQNywdCIDCgAAAcU"]
[Mon Jul 20 06:44:26.439484 2026] [security2:error] [pid 1011111:tid 1011333] [client 34.73.38.214:57716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YKhXES7Mv0Zfga-kbMgAAAOA"]
[Mon Jul 20 06:44:26.533374 2026] [security2:error] [pid 1014214:tid 1014455] [client 103.125.179.95:51258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YKguRBFTcQNywdCIDDwAAAf4"]
[Mon Jul 20 06:44:26.533495 2026] [security2:error] [pid 1014214:tid 1014455] [client 103.125.179.95:51258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YKguRBFTcQNywdCIDDwAAAf4"]
[Mon Jul 20 06:44:26.591615 2026] [security2:error] [pid 1014214:tid 1014459] [client 57.141.18.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4YKguRBFTcQNywdCIDCQAAAgI"]
[Mon Jul 20 06:44:26.596918 2026] [security2:error] [pid 1011111:tid 1011309] [client 136.144.35.247:29275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YKhXES7Mv0Zfga-kbNQAAAMg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:26.882803 2026] [security2:error] [pid 1014214:tid 1014371] [client 112.208.70.94:43498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YKguRBFTcQNywdCIDJAAAAao"]
[Mon Jul 20 06:44:26.882927 2026] [security2:error] [pid 1014214:tid 1014371] [client 112.208.70.94:43498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YKguRBFTcQNywdCIDJAAAAao"]
[Mon Jul 20 06:44:26.930874 2026] [security2:error] [pid 1014214:tid 1014360] [client 34.73.38.214:54480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YKguRBFTcQNywdCIDJgAAAZ8"]
[Mon Jul 20 06:44:27.072345 2026] [security2:error] [pid 1011111:tid 1011262] [client 173.239.240.98:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YKxXES7Mv0Zfga-kbRAAAAJk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:27.157458 2026] [security2:error] [pid 1014214:tid 1014383] [client 14.225.17.146:64931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4YKQuRBFTcQNywdCIC5QAAAbY"], referer: http://thechancersband.com/new
[Mon Jul 20 06:44:27.210382 2026] [security2:error] [pid 1014214:tid 1014451] [client 40.77.167.143:4732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4YKwuRBFTcQNywdCIDMAAB-gI"]
[Mon Jul 20 06:44:27.441658 2026] [security2:error] [pid 1011111:tid 1011296] [client 34.73.38.214:51132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YKxXES7Mv0Zfga-kbVAAAALs"]
[Mon Jul 20 06:44:27.441808 2026] [security2:error] [pid 1011111:tid 1011269] [client 34.73.38.214:51141] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YKxXES7Mv0Zfga-kbVQAAAKA"]
[Mon Jul 20 06:44:27.545174 2026] [security2:error] [pid 1011111:tid 1011355] [client 173.239.240.92:38145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YKxXES7Mv0Zfga-kbWQAAAPY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:27.617497 2026] [security2:error] [pid 1014214:tid 1014470] [client 183.82.98.154:58105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YKwuRBFTcQNywdCIDVAAAAg0"]
[Mon Jul 20 06:44:27.617604 2026] [security2:error] [pid 1014214:tid 1014470] [client 183.82.98.154:58105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YKwuRBFTcQNywdCIDVAAAAg0"]
[Mon Jul 20 06:44:27.829485 2026] [security2:error] [pid 1014214:tid 1014364] [client 57.141.18.38:64202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YJguRBFTcQNywdCIB0gABoyk"]
[Mon Jul 20 06:44:28.007975 2026] [security2:error] [pid 1014214:tid 1014401] [client 173.239.240.30:37683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YLAuRBFTcQNywdCIDaAAAAcg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:28.170325 2026] [security2:error] [pid 1014214:tid 1014393] [client 14.225.17.146:53344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4YLAuRBFTcQNywdCIDawAAAcA"], referer: http://slutilities.com/new
[Mon Jul 20 06:44:28.474423 2026] [security2:error] [pid 1014214:tid 1014423] [client 173.239.240.99:43947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YLAuRBFTcQNywdCIDlgAAAd4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:28.483909 2026] [security2:error] [pid 1014214:tid 1014379] [client 34.73.38.214:56224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YLAuRBFTcQNywdCIDlwAAAbI"]
[Mon Jul 20 06:44:28.611548 2026] [security2:error] [pid 1011111:tid 1011132] [remote 47.86.33.52:21778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4YLBXES7Mv0Zfga-kbcQAAhxM"]
[Mon Jul 20 06:44:28.905724 2026] [security2:error] [pid 1011111:tid 1011256] [client 50.116.65.227:55280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YLBXES7Mv0Zfga-kbegAAAJM"]
[Mon Jul 20 06:44:28.915549 2026] [security2:error] [pid 1014214:tid 1014456] [client 50.116.65.227:55292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YLAuRBFTcQNywdCIDtQAAAf8"]
[Mon Jul 20 06:44:28.925851 2026] [security2:error] [pid 1014214:tid 1014456] [client 52.109.112.174:32128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YLAuRBFTcQNywdCIDtwAAAf8"]
[Mon Jul 20 06:44:28.957853 2026] [security2:error] [pid 1014214:tid 1014396] [client 34.73.38.214:54735] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YLAuRBFTcQNywdCIDugAAAcM"]
[Mon Jul 20 06:44:28.969909 2026] [security2:error] [pid 1014214:tid 1014374] [client 34.73.38.214:57593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YLAuRBFTcQNywdCIDuwAAAa0"]
[Mon Jul 20 06:44:28.975924 2026] [security2:error] [pid 1014214:tid 1014349] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YLAuRBFTcQNywdCIDqgAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:29.010277 2026] [security2:error] [pid 1011111:tid 1011272] [client 104.234.53.47:45583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YLRXES7Mv0Zfga-kbfAAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:29.021928 2026] [security2:error] [pid 1014214:tid 1014461] [client 173.239.240.96:48807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YLQuRBFTcQNywdCIDwQAAAgQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:29.053192 2026] [security2:error] [pid 1014214:tid 1014429] [client 14.225.17.146:64514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4YLAuRBFTcQNywdCIDvwAAAeQ"], referer: http://katsklar.com/new
[Mon Jul 20 06:44:29.083018 2026] [security2:error] [pid 1014214:tid 1014362] [client 52.109.112.174:32128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YLQuRBFTcQNywdCIDxAAAAaE"]
[Mon Jul 20 06:44:29.088865 2026] [security2:error] [pid 1014214:tid 1014372] [client 187.108.85.186:52268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCIDxQAAAas"]
[Mon Jul 20 06:44:29.088954 2026] [security2:error] [pid 1014214:tid 1014372] [client 187.108.85.186:52268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCIDxQAAAas"]
[Mon Jul 20 06:44:29.192943 2026] [security2:error] [pid 1014214:tid 1014379] [client 77.110.127.138:53959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YLQuRBFTcQNywdCID0AAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:29.193041 2026] [security2:error] [pid 1014214:tid 1014379] [client 77.110.127.138:53959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YLQuRBFTcQNywdCID0AAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:29.213433 2026] [security2:error] [pid 1014214:tid 1014452] [client 103.238.106.162:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCID0wAAAfs"]
[Mon Jul 20 06:44:29.213518 2026] [security2:error] [pid 1014214:tid 1014452] [client 103.238.106.162:60596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCID0wAAAfs"]
[Mon Jul 20 06:44:29.315755 2026] [security2:error] [pid 1014214:tid 1014385] [client 57.141.18.2:31126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YJwuRBFTcQNywdCICSAABuCQ"]
[Mon Jul 20 06:44:29.466354 2026] [security2:error] [pid 1011111:tid 1011277] [client 50.116.65.227:55318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4YLRXES7Mv0Zfga-kbiAAAAKg"]
[Mon Jul 20 06:44:29.538175 2026] [security2:error] [pid 1014214:tid 1014348] [client 136.144.35.248:30389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YLQuRBFTcQNywdCID4gAAAZM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:29.593120 2026] [security2:error] [pid 1014214:tid 1014355] [client 171.61.165.146:29996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCID6wAAAZo"]
[Mon Jul 20 06:44:29.593245 2026] [security2:error] [pid 1014214:tid 1014355] [client 171.61.165.146:29996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCID6wAAAZo"]
[Mon Jul 20 06:44:29.658379 2026] [security2:error] [pid 1014214:tid 1014349] [client 52.109.4.7:13762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YLQuRBFTcQNywdCID7gAAAZQ"]
[Mon Jul 20 06:44:29.662795 2026] [security2:error] [pid 1011111:tid 1011344] [client 57.141.18.62:35668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YKBXES7Mv0Zfga-ka2QAA6xY"]
[Mon Jul 20 06:44:29.678969 2026] [security2:error] [pid 1014214:tid 1014415] [client 50.116.65.227:55324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4YLQuRBFTcQNywdCID3AAAAdY"]
[Mon Jul 20 06:44:29.718667 2026] [security2:error] [pid 1014214:tid 1014362] [client 52.109.4.7:13762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YLQuRBFTcQNywdCID9QAAAaE"]
[Mon Jul 20 06:44:29.740560 2026] [security2:error] [pid 1014214:tid 1014366] [client 82.22.98.130:14220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4YLQuRBFTcQNywdCID1wAAAaU"]
[Mon Jul 20 06:44:29.796817 2026] [security2:error] [pid 1014214:tid 1014393] [client 217.142.18.172:15406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCID_wAAAcA"]
[Mon Jul 20 06:44:29.804467 2026] [security2:error] [pid 1014214:tid 1014393] [client 217.142.18.172:15406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCID_wAAAcA"]
[Mon Jul 20 06:44:29.861410 2026] [security2:error] [pid 1014214:tid 1014340] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCIEBQAByH0"]
[Mon Jul 20 06:44:29.861560 2026] [security2:error] [pid 1014214:tid 1014401] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YLQuRBFTcQNywdCIEBQAByH0"]
[Mon Jul 20 06:44:30.004580 2026] [security2:error] [pid 1014214:tid 1014452] [client 136.144.35.247:34123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YLguRBFTcQNywdCIECgAAAfs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:30.220645 2026] [security2:error] [pid 1014214:tid 1014456] [client 34.73.38.214:62562] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YLguRBFTcQNywdCIEFQAAAf8"]
[Mon Jul 20 06:44:30.225931 2026] [security2:error] [pid 1014214:tid 1014422] [client 34.73.38.214:62850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YLguRBFTcQNywdCIEFgAAAd0"]
[Mon Jul 20 06:44:30.287538 2026] [security2:error] [pid 1014214:tid 1014374] [client 152.58.191.29:56011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YLguRBFTcQNywdCIEGQAAAa0"]
[Mon Jul 20 06:44:30.290164 2026] [security2:error] [pid 1014214:tid 1014374] [client 152.58.191.29:56011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YLguRBFTcQNywdCIEGQAAAa0"]
[Mon Jul 20 06:44:30.507561 2026] [security2:error] [pid 1014214:tid 1014419] [client 34.73.38.214:64607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YLguRBFTcQNywdCIEJQAAAdo"]
[Mon Jul 20 06:44:30.625896 2026] [security2:error] [pid 1014214:tid 1014459] [client 173.239.240.31:52499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YLguRBFTcQNywdCIEKwAAAgI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:30.627122 2026] [security2:error] [pid 1014214:tid 1014425] [client 34.73.38.214:51373] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YLguRBFTcQNywdCIELAAAAeA"]
[Mon Jul 20 06:44:30.683763 2026] [security2:error] [pid 1014214:tid 1014446] [client 57.141.18.50:35180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YKQuRBFTcQNywdCICtwAB9Ws"]
[Mon Jul 20 06:44:30.746792 2026] [security2:error] [pid 1011111:tid 1011178] [remote 47.86.33.52:21778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4YLhXES7Mv0Zfga-kbrAAA6UE"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:44:30.820704 2026] [security2:error] [pid 1014214:tid 1014437] [client 117.247.108.24:29060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YLguRBFTcQNywdCIENgAAAew"]
[Mon Jul 20 06:44:30.820794 2026] [security2:error] [pid 1014214:tid 1014437] [client 117.247.108.24:29060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YLguRBFTcQNywdCIENgAAAew"]
[Mon Jul 20 06:44:30.821244 2026] [security2:error] [pid 1014214:tid 1014365] [client 57.141.18.16:32622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YKQuRBFTcQNywdCICwAABpHE"]
[Mon Jul 20 06:44:30.921669 2026] [security2:error] [pid 1014214:tid 1014369] [client 34.73.38.214:55583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiaconsciente.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YLguRBFTcQNywdCIEPQAAAag"]
[Mon Jul 20 06:44:31.082840 2026] [security2:error] [pid 1014214:tid 1014417] [client 136.144.35.247:39571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YLwuRBFTcQNywdCIESQAAAdg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:31.168360 2026] [security2:error] [pid 1014214:tid 1014420] [client 14.225.17.146:64774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4YLguRBFTcQNywdCIEPwAAAds"], referer: http://floorsourcestock.com/new
[Mon Jul 20 06:44:31.317321 2026] [security2:error] [pid 1011111:tid 1011358] [client 34.73.38.214:51177] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.fansarogroup.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YLxXES7Mv0Zfga-kbtQAAAPk"]
[Mon Jul 20 06:44:31.325645 2026] [security2:error] [pid 1014214:tid 1014366] [client 77.110.127.138:53986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 193 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YLwuRBFTcQNywdCIEUwAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:31.571597 2026] [security2:error] [pid 1014214:tid 1014446] [client 173.239.240.90:64495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YLwuRBFTcQNywdCIEZwAAAfU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:31.575884 2026] [security2:error] [pid 1014214:tid 1014379] [client 57.141.18.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YLwuRBFTcQNywdCIEXwAAAbI"]
[Mon Jul 20 06:44:31.599942 2026] [security2:error] [pid 1011111:tid 1011255] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4YLxXES7Mv0Zfga-kbtgAAAJI"]
[Mon Jul 20 06:44:31.628073 2026] [security2:error] [pid 1014214:tid 1014332] [remote 192.241.143.148:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YLwuRBFTcQNywdCIEbgAByHU"]
[Mon Jul 20 06:44:31.652132 2026] [security2:error] [pid 1014214:tid 1014418] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YLguRBFTcQNywdCIEEwAAAdk"]
[Mon Jul 20 06:44:31.751618 2026] [security2:error] [pid 1014214:tid 1014253] [remote 162.19.86.63:32909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4YLwuRBFTcQNywdCIEdgAB7CY"]
[Mon Jul 20 06:44:31.780927 2026] [security2:error] [pid 1014214:tid 1014374] [client 34.73.38.214:63752] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YLwuRBFTcQNywdCIEeAAAAa0"]
[Mon Jul 20 06:44:31.803137 2026] [security2:error] [pid 1014214:tid 1014292] [remote 192.241.143.148:52296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YLwuRBFTcQNywdCIEegACAU0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:44:31.851262 2026] [security2:error] [pid 1014214:tid 1014354] [client 57.141.18.66:39130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YKguRBFTcQNywdCIDDgABmR4"]
[Mon Jul 20 06:44:31.890811 2026] [security2:error] [pid 1014214:tid 1014364] [client 14.225.17.146:50230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4YLguRBFTcQNywdCIELwAAAaM"], referer: http://mazzucelli.com/new
[Mon Jul 20 06:44:31.960072 2026] [security2:error] [pid 1014214:tid 1014271] [remote 162.19.86.63:32909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4YLwuRBFTcQNywdCIEgAAB3jg"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:44:31.966432 2026] [security2:error] [pid 1014214:tid 1014417] [client 65.111.27.158:25355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YLwuRBFTcQNywdCIEfwAAAdg"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:44:31.990771 2026] [security2:error] [pid 1011111:tid 1011294] [client 57.141.18.57:53414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YKhXES7Mv0Zfga-kbOAAAuT4"]
[Mon Jul 20 06:44:32.089797 2026] [security2:error] [pid 1014214:tid 1014470] [client 173.239.240.93:32359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YMAuRBFTcQNywdCIEigAAAg0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:32.525968 2026] [security2:error] [pid 1014214:tid 1014415] [client 14.225.17.146:64495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4YMAuRBFTcQNywdCIElgAAAdY"], referer: http://laceycaraccident.com/new
[Mon Jul 20 06:44:32.528570 2026] [security2:error] [pid 1014214:tid 1014395] [client 197.186.66.42:61329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YMAuRBFTcQNywdCIEoQAAAcI"]
[Mon Jul 20 06:44:32.528711 2026] [security2:error] [pid 1014214:tid 1014395] [client 197.186.66.42:61329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YMAuRBFTcQNywdCIEoQAAAcI"]
[Mon Jul 20 06:44:32.529698 2026] [access_compat:error] [pid 1014214:tid 1014249] [remote 103.23.227.69:42681] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:44:32.569554 2026] [security2:error] [pid 1014214:tid 1014426] [client 136.144.35.248:23307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YMAuRBFTcQNywdCIEowAAAeE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:32.600234 2026] [security2:error] [pid 1014214:tid 1014403] [client 45.3.46.131:29081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YMAuRBFTcQNywdCIEpAAAAco"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:44:32.640074 2026] [security2:error] [pid 1014214:tid 1014389] [client 34.73.38.214:65298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.familiasconscientes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YMAuRBFTcQNywdCIEpwAAAbw"]
[Mon Jul 20 06:44:32.873581 2026] [security2:error] [pid 1014214:tid 1014452] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YMAuRBFTcQNywdCIEqwAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:32.902896 2026] [security2:error] [pid 1014214:tid 1014356] [client 13.233.207.33:50464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YMAuRBFTcQNywdCIEuwAAAZs"]
[Mon Jul 20 06:44:32.902992 2026] [security2:error] [pid 1014214:tid 1014356] [client 13.233.207.33:50464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YMAuRBFTcQNywdCIEuwAAAZs"]
[Mon Jul 20 06:44:32.946190 2026] [security2:error] [pid 1011111:tid 1011322] [client 66.249.90.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YMBXES7Mv0Zfga-kb1QAAANU"]
[Mon Jul 20 06:44:32.973519 2026] [security2:error] [pid 1011111:tid 1011261] [client 57.141.18.105:42306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YKxXES7Mv0Zfga-kbXwAAmFM"]
[Mon Jul 20 06:44:33.080600 2026] [security2:error] [pid 1014214:tid 1014407] [client 77.110.127.138:54008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YMQuRBFTcQNywdCIExwAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:33.080700 2026] [security2:error] [pid 1014214:tid 1014407] [client 77.110.127.138:54008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YMQuRBFTcQNywdCIExwAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:33.087343 2026] [security2:error] [pid 1011111:tid 1011216] [remote 162.19.86.63:38154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4YMRXES7Mv0Zfga-kb3gAArWc"]
[Mon Jul 20 06:44:33.088136 2026] [security2:error] [pid 1011111:tid 1011275] [client 136.144.35.250:56709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YMRXES7Mv0Zfga-kb3wAAAKY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:33.278784 2026] [security2:error] [pid 1011111:tid 1011202] [remote 162.19.86.63:38154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4YMRXES7Mv0Zfga-kb5wAA6lk"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 06:44:33.549995 2026] [security2:error] [pid 1011111:tid 1011288] [client 37.52.210.45:54826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YMRXES7Mv0Zfga-kb7wAAALM"]
[Mon Jul 20 06:44:33.550266 2026] [security2:error] [pid 1011111:tid 1011288] [client 37.52.210.45:54826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YMRXES7Mv0Zfga-kb7wAAALM"]
[Mon Jul 20 06:44:33.602493 2026] [security2:error] [pid 1014214:tid 1014456] [client 136.144.35.254:58951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YMQuRBFTcQNywdCIE2QAAAf8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:33.765305 2026] [security2:error] [pid 1011111:tid 1011360] [client 223.185.13.213:6341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YMRXES7Mv0Zfga-kb_AAAAPs"]
[Mon Jul 20 06:44:33.765403 2026] [security2:error] [pid 1011111:tid 1011360] [client 223.185.13.213:6341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YMRXES7Mv0Zfga-kb_AAAAPs"]
[Mon Jul 20 06:44:33.795019 2026] [security2:error] [pid 1014214:tid 1014406] [client 14.225.17.146:59199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4YMAuRBFTcQNywdCIEgwAAAc0"], referer: http://fineartsfactory.net/new
[Mon Jul 20 06:44:33.909783 2026] [security2:error] [pid 1011111:tid 1011309] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4YMRXES7Mv0Zfga-kb7AAAyC8"], referer: http://ali-alghanim.net/new
[Mon Jul 20 06:44:34.016725 2026] [security2:error] [pid 1014214:tid 1014397] [client 74.208.214.194:33966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4YMguRBFTcQNywdCIE7AAAAcQ"]
[Mon Jul 20 06:44:34.199572 2026] [security2:error] [pid 1014214:tid 1014441] [client 136.144.35.252:52263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YMguRBFTcQNywdCIE8wAAAfA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:34.355102 2026] [security2:error] [pid 1011111:tid 1011260] [client 104.234.53.91:38623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YMhXES7Mv0Zfga-kcCQAAAJc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:34.587651 2026] [security2:error] [pid 1011111:tid 1011353] [client 50.116.65.227:55396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YMhXES7Mv0Zfga-kcEgAAAPQ"]
[Mon Jul 20 06:44:34.598303 2026] [security2:error] [pid 1011111:tid 1011282] [client 50.116.65.227:55412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YMhXES7Mv0Zfga-kcEwAAAK0"]
[Mon Jul 20 06:44:34.680554 2026] [security2:error] [pid 1014214:tid 1014414] [client 136.144.35.253:40385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YMguRBFTcQNywdCIFEQAAAdU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:34.686133 2026] [security2:error] [pid 1014214:tid 1014443] [client 57.141.18.118:46746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLQuRBFTcQNywdCID2AAB8g4"]
[Mon Jul 20 06:44:34.771821 2026] [security2:error] [pid 1014214:tid 1014453] [client 57.141.18.70:24350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLQuRBFTcQNywdCID1gAB_GM"]
[Mon Jul 20 06:44:34.786729 2026] [security2:error] [pid 1014214:tid 1014409] [client 57.141.18.62:40644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLQuRBFTcQNywdCID2gAB0DQ"]
[Mon Jul 20 06:44:34.848269 2026] [security2:error] [pid 1014214:tid 1014365] [client 14.225.17.146:59207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4YMguRBFTcQNywdCIFGwAAAaQ"], referer: http://dasmarque.com/new
[Mon Jul 20 06:44:35.099072 2026] [security2:error] [pid 1011111:tid 1011242] [client 104.234.53.91:38623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YMxXES7Mv0Zfga-kcGwAAAIU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:35.203910 2026] [security2:error] [pid 1014214:tid 1014440] [client 173.239.240.93:35307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YMwuRBFTcQNywdCIFMQAAAe8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:35.324361 2026] [security2:error] [pid 1011111:tid 1011358] [client 74.7.175.131:53270] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "genesismbs.com"] [uri "/index.php"] [unique_id "al4YMxXES7Mv0Zfga-kcIQAA-Xk"]
[Mon Jul 20 06:44:35.428368 2026] [security2:error] [pid 1014214:tid 1014361] [client 14.225.17.146:60996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4YMwuRBFTcQNywdCIFOgAAAaA"], referer: http://mcg.homes/new
[Mon Jul 20 06:44:35.460353 2026] [security2:error] [pid 1011111:tid 1011310] [client 77.110.127.138:54027] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 932 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YMxXES7Mv0Zfga-kcKAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:35.499300 2026] [security2:error] [pid 1014214:tid 1014378] [client 122.183.32.225:14928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YMwuRBFTcQNywdCIFQQAAAbE"]
[Mon Jul 20 06:44:35.499396 2026] [security2:error] [pid 1014214:tid 1014378] [client 122.183.32.225:14928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YMwuRBFTcQNywdCIFQQAAAbE"]
[Mon Jul 20 06:44:35.659110 2026] [proxy:error] [pid 1014214:tid 1014422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:35.659185 2026] [proxy_http:error] [pid 1014214:tid 1014422] [client 34.73.38.214:59320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:35.659656 2026] [proxy:error] [pid 1014214:tid 1014422] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:35.659685 2026] [proxy_http:error] [pid 1014214:tid 1014422] [client 34.73.38.214:59320] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:35.712612 2026] [security2:error] [pid 1014214:tid 1014461] [client 136.144.35.246:43549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YMwuRBFTcQNywdCIFUwAAAgQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:35.931943 2026] [security2:error] [pid 1011111:tid 1011309] [client 104.234.53.94:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YMxXES7Mv0Zfga-kcPAAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:36.163660 2026] [proxy:error] [pid 1011111:tid 1011354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:36.163735 2026] [proxy_http:error] [pid 1011111:tid 1011354] [client 34.73.38.214:50672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:36.164256 2026] [proxy:error] [pid 1011111:tid 1011354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:36.164300 2026] [proxy_http:error] [pid 1011111:tid 1011354] [client 34.73.38.214:50672] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:36.172783 2026] [security2:error] [pid 1014214:tid 1014389] [client 136.144.35.246:44501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YNAuRBFTcQNywdCIFbAAAAbw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:36.250091 2026] [security2:error] [pid 1014214:tid 1014431] [client 57.141.18.50:64308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLguRBFTcQNywdCIELQAB5hQ"]
[Mon Jul 20 06:44:36.334864 2026] [security2:error] [pid 1011111:tid 1011269] [client 192.140.149.97:46063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YNBXES7Mv0Zfga-kcTAAAAKA"]
[Mon Jul 20 06:44:36.334984 2026] [security2:error] [pid 1011111:tid 1011269] [client 192.140.149.97:46063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YNBXES7Mv0Zfga-kcTAAAAKA"]
[Mon Jul 20 06:44:36.555669 2026] [security2:error] [pid 1014214:tid 1014398] [client 57.141.18.2:48282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLguRBFTcQNywdCIEPAABxQM"]
[Mon Jul 20 06:44:36.649380 2026] [security2:error] [pid 1014214:tid 1014352] [client 136.144.35.252:37973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YNAuRBFTcQNywdCIFgQAAAZc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:36.652681 2026] [security2:error] [pid 1014214:tid 1014469] [client 57.141.18.69:20206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLguRBFTcQNywdCIEQAACDGw"]
[Mon Jul 20 06:44:36.714513 2026] [security2:error] [pid 1014214:tid 1014387] [client 57.141.18.34:29696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLwuRBFTcQNywdCIERwABuhg"]
[Mon Jul 20 06:44:36.716621 2026] [security2:error] [pid 1011111:tid 1011357] [client 66.249.88.97:64202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4YNBXES7Mv0Zfga-kcUAAAAPg"]
[Mon Jul 20 06:44:36.796277 2026] [security2:error] [pid 1011111:tid 1011328] [client 45.3.32.89:34167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YNBXES7Mv0Zfga-kcWQAAANs"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:44:37.010968 2026] [security2:error] [pid 1011111:tid 1011260] [client 106.219.188.178:2905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YNRXES7Mv0Zfga-kcZAAAAJc"]
[Mon Jul 20 06:44:37.011095 2026] [security2:error] [pid 1011111:tid 1011260] [client 106.219.188.178:2905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YNRXES7Mv0Zfga-kcZAAAAJc"]
[Mon Jul 20 06:44:37.133130 2026] [security2:error] [pid 1014214:tid 1014437] [client 39.48.81.23:54633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YNQuRBFTcQNywdCIFnwAAAew"]
[Mon Jul 20 06:44:37.133349 2026] [security2:error] [pid 1014214:tid 1014437] [client 39.48.81.23:54633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YNQuRBFTcQNywdCIFnwAAAew"]
[Mon Jul 20 06:44:37.181310 2026] [security2:error] [pid 1011111:tid 1011358] [client 173.239.240.30:46751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YNRXES7Mv0Zfga-kcawAAAPk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:37.447034 2026] [security2:error] [pid 1014214:tid 1014436] [client 112.208.70.94:43933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YNQuRBFTcQNywdCIFpwAAAes"]
[Mon Jul 20 06:44:37.447172 2026] [security2:error] [pid 1014214:tid 1014436] [client 112.208.70.94:43933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YNQuRBFTcQNywdCIFpwAAAes"]
[Mon Jul 20 06:44:37.560169 2026] [security2:error] [pid 1014214:tid 1014410] [client 57.141.18.7:61974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLwuRBFTcQNywdCIEdQAB0W0"]
[Mon Jul 20 06:44:37.584276 2026] [security2:error] [pid 1011111:tid 1011331] [client 104.234.53.55:35463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YNRXES7Mv0Zfga-kccQAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:37.640242 2026] [proxy:error] [pid 1014214:tid 1014434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:37.640361 2026] [proxy_http:error] [pid 1014214:tid 1014434] [client 34.73.38.214:64730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:37.640960 2026] [proxy:error] [pid 1014214:tid 1014434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:37.641003 2026] [proxy_http:error] [pid 1014214:tid 1014434] [client 34.73.38.214:64730] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:37.673306 2026] [security2:error] [pid 1014214:tid 1014278] [remote 91.142.222.105:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4YNQuRBFTcQNywdCIFvgACCj8"]
[Mon Jul 20 06:44:37.732224 2026] [security2:error] [pid 1011111:tid 1011336] [client 103.125.179.95:51756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YNRXES7Mv0Zfga-kcdQAAAOM"]
[Mon Jul 20 06:44:37.732329 2026] [security2:error] [pid 1011111:tid 1011336] [client 103.125.179.95:51756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YNRXES7Mv0Zfga-kcdQAAAOM"]
[Mon Jul 20 06:44:37.758688 2026] [security2:error] [pid 1014214:tid 1014380] [client 57.141.18.39:37261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YLwuRBFTcQNywdCIEfAABsxM"]
[Mon Jul 20 06:44:37.768692 2026] [security2:error] [pid 1014214:tid 1014387] [client 136.144.35.253:30611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YNQuRBFTcQNywdCIFxQAAAbo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:37.785338 2026] [security2:error] [pid 1014214:tid 1014397] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YNQuRBFTcQNywdCIFsgAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:37.855658 2026] [security2:error] [pid 1011111:tid 1011345] [client 47.128.21.67:52272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "goyalsatyam.com"] [uri "/robots.txt"] [unique_id "al4YNRXES7Mv0Zfga-kcdwAAAOw"]
[Mon Jul 20 06:44:38.005892 2026] [security2:error] [pid 1014214:tid 1014435] [client 77.110.127.138:54056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YNguRBFTcQNywdCIF0gAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:38.005984 2026] [security2:error] [pid 1014214:tid 1014435] [client 77.110.127.138:54056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YNguRBFTcQNywdCIF0gAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:38.188945 2026] [security2:error] [pid 1014214:tid 1014428] [client 14.225.17.146:59585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4YNQuRBFTcQNywdCIFxgAAAeM"], referer: http://overloadcomedy.com/new
[Mon Jul 20 06:44:38.240935 2026] [security2:error] [pid 1014214:tid 1014297] [remote 91.142.222.105:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crimargroup.com"] [uri "/wp-login.php"] [unique_id "al4YNguRBFTcQNywdCIF5AABwFI"], referer: https://crimargroup.com/wp-login.php
[Mon Jul 20 06:44:38.255064 2026] [security2:error] [pid 1014214:tid 1014450] [client 173.239.240.97:40767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YNguRBFTcQNywdCIF5wAAAfk"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:38.267688 2026] [security2:error] [pid 1014214:tid 1014396] [client 57.141.18.120:56772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YMAuRBFTcQNywdCIEngABw0E"]
[Mon Jul 20 06:44:38.301454 2026] [security2:error] [pid 1014214:tid 1014380] [client 20.199.97.14:26050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YNguRBFTcQNywdCIF6AAAAbM"]
[Mon Jul 20 06:44:38.345934 2026] [security2:error] [pid 1014214:tid 1014369] [client 183.82.98.154:58673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YNguRBFTcQNywdCIF6wAAAag"]
[Mon Jul 20 06:44:38.346040 2026] [security2:error] [pid 1014214:tid 1014369] [client 183.82.98.154:58673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YNguRBFTcQNywdCIF6wAAAag"]
[Mon Jul 20 06:44:38.454205 2026] [security2:error] [pid 1014214:tid 1014456] [client 20.199.97.14:26050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YNguRBFTcQNywdCIF9AAAAf8"]
[Mon Jul 20 06:44:38.513917 2026] [security2:error] [pid 1014214:tid 1014405] [client 50.116.65.227:55474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YNguRBFTcQNywdCIF9gAAAcw"]
[Mon Jul 20 06:44:38.526083 2026] [security2:error] [pid 1014214:tid 1014365] [client 50.116.65.227:55480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YNguRBFTcQNywdCIF-QAAAaQ"]
[Mon Jul 20 06:44:38.719888 2026] [security2:error] [pid 1014214:tid 1014379] [client 173.239.240.32:35165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YNguRBFTcQNywdCIGAwAAAbI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:38.748651 2026] [security2:error] [pid 1014214:tid 1014410] [client 74.249.226.166:32001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YNguRBFTcQNywdCIGBQAAAdE"]
[Mon Jul 20 06:44:38.801160 2026] [security2:error] [pid 1014214:tid 1014445] [client 74.249.226.166:32001] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YNguRBFTcQNywdCIGCwAAAfQ"]
[Mon Jul 20 06:44:38.849411 2026] [security2:error] [pid 1014214:tid 1014451] [client 57.141.18.115:56572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YMAuRBFTcQNywdCIEvwAB-mc"]
[Mon Jul 20 06:44:38.932571 2026] [security2:error] [pid 1014214:tid 1014455] [client 223.237.130.40:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.130.237.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4YNguRBFTcQNywdCIGEQAAAf4"]
[Mon Jul 20 06:44:38.937491 2026] [security2:error] [pid 1014214:tid 1014455] [client 223.237.130.40:63136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4YNguRBFTcQNywdCIGEQAAAf4"]
[Mon Jul 20 06:44:39.164645 2026] [security2:error] [pid 1011111:tid 1011272] [client 77.110.127.138:54070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 938 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YNxXES7Mv0Zfga-kcogAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:39.190420 2026] [security2:error] [pid 1014214:tid 1014391] [client 14.225.17.146:51441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4YNQuRBFTcQNywdCIFnAAAAb4"], referer: http://younutrition.gr/new
[Mon Jul 20 06:44:39.202284 2026] [security2:error] [pid 1014214:tid 1014387] [client 173.239.240.95:30447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YNwuRBFTcQNywdCIGGgAAAbo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:39.228488 2026] [security2:error] [pid 1014214:tid 1014351] [client 14.225.17.146:56268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4YNguRBFTcQNywdCIF0wAAAZY"], referer: http://northbrookcpa.ca/new
[Mon Jul 20 06:44:39.294639 2026] [security2:error] [pid 1014214:tid 1014365] [client 34.73.38.214:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.frontecinc.com"] [uri "/xmlrpc.php"] [unique_id "al4YNwuRBFTcQNywdCIGIgAAAaQ"]
[Mon Jul 20 06:44:39.389546 2026] [security2:error] [pid 1014214:tid 1014301] [remote 100.42.189.89:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4YNwuRBFTcQNywdCIGKAAB_1Y"]
[Mon Jul 20 06:44:39.435506 2026] [security2:error] [pid 1014214:tid 1014426] [client 104.234.53.73:43029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YNwuRBFTcQNywdCIGKgAAAeE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:39.596238 2026] [security2:error] [pid 1014214:tid 1014276] [remote 100.42.189.89:59934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4YNwuRBFTcQNywdCIGNQACCj0"], referer: https://omrobuildingcenter.com/wp-login.php
[Mon Jul 20 06:44:39.680071 2026] [security2:error] [pid 1014214:tid 1014440] [client 173.239.240.99:47923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YNwuRBFTcQNywdCIGPAAAAe8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:39.713309 2026] [security2:error] [pid 1014214:tid 1014465] [client 57.141.18.50:64316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YMQuRBFTcQNywdCIE4QACCFw"]
[Mon Jul 20 06:44:39.769358 2026] [security2:error] [pid 1014214:tid 1014373] [client 57.141.18.41:31748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YMQuRBFTcQNywdCIE5wABrEY"]
[Mon Jul 20 06:44:39.771705 2026] [security2:error] [pid 1014214:tid 1014418] [client 103.238.106.162:60845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YNwuRBFTcQNywdCIGRQAAAdk"]
[Mon Jul 20 06:44:39.771812 2026] [security2:error] [pid 1014214:tid 1014418] [client 103.238.106.162:60845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YNwuRBFTcQNywdCIGRQAAAdk"]
[Mon Jul 20 06:44:39.785335 2026] [security2:error] [pid 1014214:tid 1014367] [client 34.73.38.214:61744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YNwuRBFTcQNywdCIGRwAAAaY"]
[Mon Jul 20 06:44:39.800164 2026] [security2:error] [pid 1011111:tid 1011346] [client 187.108.85.186:52813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YNxXES7Mv0Zfga-kcswAAAO0"]
[Mon Jul 20 06:44:39.800261 2026] [security2:error] [pid 1011111:tid 1011346] [client 187.108.85.186:52813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YNxXES7Mv0Zfga-kcswAAAO0"]
[Mon Jul 20 06:44:39.817720 2026] [security2:error] [pid 1014214:tid 1014417] [client 14.251.3.155:54671] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YNwuRBFTcQNywdCIGSgAAAdg"]
[Mon Jul 20 06:44:40.150293 2026] [security2:error] [pid 1011111:tid 1011356] [client 173.239.240.98:21591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YOBXES7Mv0Zfga-kcuwAAAPc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:40.329389 2026] [security2:error] [pid 1014214:tid 1014365] [client 217.142.18.172:27472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YOAuRBFTcQNywdCIGYQAAAaQ"]
[Mon Jul 20 06:44:40.335884 2026] [security2:error] [pid 1014214:tid 1014365] [client 217.142.18.172:27472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YOAuRBFTcQNywdCIGYQAAAaQ"]
[Mon Jul 20 06:44:40.514144 2026] [security2:error] [pid 1014214:tid 1014446] [client 171.61.165.146:11030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YOAuRBFTcQNywdCIGZQAAAfU"]
[Mon Jul 20 06:44:40.514290 2026] [security2:error] [pid 1014214:tid 1014446] [client 171.61.165.146:11030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YOAuRBFTcQNywdCIGZQAAAfU"]
[Mon Jul 20 06:44:40.566240 2026] [security2:error] [pid 1014214:tid 1014293] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YOAuRBFTcQNywdCIGaAAB804"]
[Mon Jul 20 06:44:40.566397 2026] [security2:error] [pid 1014214:tid 1014444] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YOAuRBFTcQNywdCIGaAAB804"]
[Mon Jul 20 06:44:40.596992 2026] [security2:error] [pid 1014214:tid 1014432] [client 173.239.240.99:30187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YOAuRBFTcQNywdCIGaQAAAec"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:40.646398 2026] [security2:error] [pid 1011111:tid 1011315] [client 34.73.38.214:52017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YOBXES7Mv0Zfga-kczAAAAM4"]
[Mon Jul 20 06:44:40.660633 2026] [security2:error] [pid 1014214:tid 1014454] [client 104.234.53.80:57693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YOAuRBFTcQNywdCIGawAAAf0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:41.013502 2026] [security2:error] [pid 1014214:tid 1014440] [client 152.58.191.29:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YOQuRBFTcQNywdCIGegAAAe8"]
[Mon Jul 20 06:44:41.028099 2026] [security2:error] [pid 1014214:tid 1014440] [client 152.58.191.29:56445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YOQuRBFTcQNywdCIGegAAAe8"]
[Mon Jul 20 06:44:41.051333 2026] [security2:error] [pid 1014214:tid 1014408] [client 173.239.240.95:58105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YOQuRBFTcQNywdCIGewAAAc8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:41.277321 2026] [security2:error] [pid 1014214:tid 1014433] [client 57.141.18.22:49096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YMwuRBFTcQNywdCIFQAAB6Gg"]
[Mon Jul 20 06:44:41.405444 2026] [security2:error] [pid 1014214:tid 1014447] [client 57.141.18.66:34930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YMwuRBFTcQNywdCIFRwAB9gA"]
[Mon Jul 20 06:44:41.412177 2026] [security2:error] [pid 1011111:tid 1011298] [client 57.141.18.69:58668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4YORXES7Mv0Zfga-kc2wAAvSk"]
[Mon Jul 20 06:44:41.516857 2026] [security2:error] [pid 1014214:tid 1014446] [client 173.239.240.99:35265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YOQuRBFTcQNywdCIGoAAAAfU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:41.561743 2026] [security2:error] [pid 1011111:tid 1011304] [client 117.247.108.24:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YORXES7Mv0Zfga-kc6AAAAMM"]
[Mon Jul 20 06:44:41.561855 2026] [security2:error] [pid 1011111:tid 1011304] [client 117.247.108.24:61150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YORXES7Mv0Zfga-kc6AAAAMM"]
[Mon Jul 20 06:44:41.790145 2026] [security2:error] [pid 1011111:tid 1011344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YORXES7Mv0Zfga-kc6gAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:41.886350 2026] [security2:error] [pid 1014214:tid 1014425] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4YOQuRBFTcQNywdCIGigAAAeA"]
[Mon Jul 20 06:44:41.977715 2026] [security2:error] [pid 1014214:tid 1014453] [client 34.73.38.214:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YOQuRBFTcQNywdCIGtAAAAfw"]
[Mon Jul 20 06:44:42.000010 2026] [security2:error] [pid 1014214:tid 1014406] [client 136.144.35.253:61259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YOQuRBFTcQNywdCIGuAAAAc0"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:42.023206 2026] [security2:error] [pid 1014214:tid 1014424] [client 57.141.18.69:20728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNAuRBFTcQNywdCIFbQAB314"]
[Mon Jul 20 06:44:42.038662 2026] [security2:error] [pid 1011111:tid 1011348] [client 57.141.18.72:62364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNBXES7Mv0Zfga-kcRAAA72g"]
[Mon Jul 20 06:44:42.046814 2026] [core:error] [pid 1011111:tid 1011282] [client 14.225.17.146:50622] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:42.046834 2026] [core:error] [pid 1011111:tid 1011282] [client 14.225.17.146:50622] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:44:42.063303 2026] [security2:error] [pid 1014214:tid 1014433] [client 77.110.127.138:54117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YOguRBFTcQNywdCIGugAAAeg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:42.063433 2026] [security2:error] [pid 1014214:tid 1014433] [client 77.110.127.138:54117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YOguRBFTcQNywdCIGugAAAeg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:42.281564 2026] [security2:error] [pid 1011111:tid 1011266] [client 14.225.17.146:59124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4YNxXES7Mv0Zfga-kctgAAAJ0"], referer: http://onewingpictures.com/new
[Mon Jul 20 06:44:42.282767 2026] [security2:error] [pid 1014214:tid 1014431] [client 65.111.28.41:25711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YOguRBFTcQNywdCIGxwAAAeY"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:44:42.451102 2026] [security2:error] [pid 1014214:tid 1014410] [client 173.239.240.92:20681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YOguRBFTcQNywdCIG2QAAAdE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:42.495406 2026] [security2:error] [pid 1011111:tid 1011315] [client 45.61.187.148:57489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.187.61.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4YOhXES7Mv0Zfga-kdBAAAAM4"]
[Mon Jul 20 06:44:42.523807 2026] [security2:error] [pid 1011111:tid 1011359] [client 23.251.146.115:39104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YOhXES7Mv0Zfga-kdAwAA-nQ"]
[Mon Jul 20 06:44:42.524889 2026] [security2:error] [pid 1014214:tid 1014448] [client 23.251.146.115:16192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YOguRBFTcQNywdCIG0wAB90A"]
[Mon Jul 20 06:44:42.620836 2026] [security2:error] [pid 1014214:tid 1014362] [client 180.75.246.63:16433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNQuRBFTcQNywdCIFlwABoU0"], referer: https://toddnielsen.com
[Mon Jul 20 06:44:42.640901 2026] [security2:error] [pid 1011111:tid 1011296] [client 23.251.146.115:39104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YOhXES7Mv0Zfga-kdBgAAu3w"]
[Mon Jul 20 06:44:42.640946 2026] [security2:error] [pid 1014214:tid 1014420] [client 23.251.146.115:16192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YOguRBFTcQNywdCIG3QAB210"]
[Mon Jul 20 06:44:42.660481 2026] [security2:error] [pid 1014214:tid 1014454] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YOguRBFTcQNywdCIG1AAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:42.869860 2026] [security2:error] [pid 1011111:tid 1011274] [client 57.141.18.40:64586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNRXES7Mv0Zfga-kcZwAApSI"]
[Mon Jul 20 06:44:42.923118 2026] [security2:error] [pid 1014214:tid 1014405] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YOguRBFTcQNywdCIG7wAAAcw"]
[Mon Jul 20 06:44:42.930182 2026] [security2:error] [pid 1011111:tid 1011311] [client 136.144.35.252:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YOhXES7Mv0Zfga-kdGwAAAMo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:42.932832 2026] [security2:error] [pid 1014214:tid 1014413] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YOguRBFTcQNywdCIG8AAAAdQ"]
[Mon Jul 20 06:44:42.932889 2026] [security2:error] [pid 1014214:tid 1014429] [client 14.225.17.146:52834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4YOQuRBFTcQNywdCIGtwAAAeQ"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/new
[Mon Jul 20 06:44:43.072793 2026] [security2:error] [pid 1014214:tid 1014354] [client 45.89.105.125:37714] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "uritems.net"] [uri "/wp-comments-post.php"] [unique_id "al4YOwuRBFTcQNywdCIG9gAAAZk"], referer: https://uritems.net/2023/05/08/hello-world/
[Mon Jul 20 06:44:43.106193 2026] [security2:error] [pid 1014214:tid 1014375] [client 104.234.53.52:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YOwuRBFTcQNywdCIG-wAAAa4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:43.190573 2026] [security2:error] [pid 1014214:tid 1014347] [client 34.73.38.214:51258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YOwuRBFTcQNywdCIHBAAAAZI"]
[Mon Jul 20 06:44:43.193346 2026] [security2:error] [pid 1014214:tid 1014234] [remote 173.212.252.15:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4YOwuRBFTcQNywdCIHBgAB2RM"]
[Mon Jul 20 06:44:43.245294 2026] [security2:error] [pid 1011111:tid 1011307] [client 77.110.127.138:54130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 988 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YOxXES7Mv0Zfga-kdKAAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:43.294265 2026] [security2:error] [pid 1011111:tid 1011176] [remote 110.249.202.25:50414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/live-not-by-lies/"] [unique_id "al4YOxXES7Mv0Zfga-kdKgAAuj8"]
[Mon Jul 20 06:44:43.319473 2026] [security2:error] [pid 1014214:tid 1014377] [client 57.141.18.107:38588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNQuRBFTcQNywdCIFvAABsEI"]
[Mon Jul 20 06:44:43.381302 2026] [security2:error] [pid 1014214:tid 1014423] [client 173.239.240.31:37927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YOwuRBFTcQNywdCIHEwAAAd4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:43.393936 2026] [security2:error] [pid 1014214:tid 1014222] [remote 173.212.252.15:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4YOwuRBFTcQNywdCIHFAABpwc"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:44:43.540939 2026] [security2:error] [pid 1011111:tid 1011344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YOxXES7Mv0Zfga-kdLAAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:43.563386 2026] [security2:error] [pid 1014214:tid 1014422] [client 57.141.18.104:42294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNQuRBFTcQNywdCIFzAAB3Sc"]
[Mon Jul 20 06:44:43.584961 2026] [security2:error] [pid 1014214:tid 1014354] [client 45.89.105.125:37714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "uritems.net"] [uri "/wp-comments-post.php"] [unique_id "al4YOwuRBFTcQNywdCIG9gAAAZk"], referer: https://uritems.net/2023/05/08/hello-world/
[Mon Jul 20 06:44:43.585015 2026] [security2:error] [pid 1014214:tid 1014354] [client 45.89.105.125:37714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "uritems.net"] [uri "/wp-comments-post.php"] [unique_id "al4YOwuRBFTcQNywdCIG9gAAAZk"], referer: https://uritems.net/2023/05/08/hello-world/
[Mon Jul 20 06:44:43.811862 2026] [security2:error] [pid 1011111:tid 1011355] [client 34.73.38.214:54140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YOxXES7Mv0Zfga-kdOAAAAPY"]
[Mon Jul 20 06:44:43.835033 2026] [security2:error] [pid 1014214:tid 1014433] [client 173.239.240.32:25397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YOwuRBFTcQNywdCIHKgAAAeg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:43.932641 2026] [security2:error] [pid 1014214:tid 1014454] [client 223.185.13.213:21607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YOwuRBFTcQNywdCIHLAAAAf0"]
[Mon Jul 20 06:44:43.932733 2026] [security2:error] [pid 1014214:tid 1014454] [client 223.185.13.213:21607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YOwuRBFTcQNywdCIHLAAAAf0"]
[Mon Jul 20 06:44:44.032055 2026] [security2:error] [pid 1014214:tid 1014356] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YOwuRBFTcQNywdCIHKAAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:44.243422 2026] [security2:error] [pid 1014214:tid 1014386] [client 34.73.38.214:56329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YPAuRBFTcQNywdCIHOgAAAbk"]
[Mon Jul 20 06:44:44.258385 2026] [security2:error] [pid 1014214:tid 1014471] [client 57.141.18.123:37174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNguRBFTcQNywdCIF9QACDks"]
[Mon Jul 20 06:44:44.311411 2026] [security2:error] [pid 1014214:tid 1014437] [client 37.52.210.45:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YPAuRBFTcQNywdCIHQwAAAew"]
[Mon Jul 20 06:44:44.311511 2026] [security2:error] [pid 1014214:tid 1014437] [client 37.52.210.45:55310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YPAuRBFTcQNywdCIHQwAAAew"]
[Mon Jul 20 06:44:44.332371 2026] [security2:error] [pid 1011111:tid 1011249] [client 173.239.240.95:60517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YPBXES7Mv0Zfga-kdQgAAAIw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:44.430725 2026] [security2:error] [pid 1014214:tid 1014318] [remote 188.40.28.4:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4YPAuRBFTcQNywdCIHRgABsmc"]
[Mon Jul 20 06:44:44.609847 2026] [security2:error] [pid 1014214:tid 1014414] [client 57.141.18.30:29196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNguRBFTcQNywdCIGDgAB1Uc"]
[Mon Jul 20 06:44:44.610219 2026] [security2:error] [pid 1011111:tid 1011301] [client 34.73.38.214:56398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YPBXES7Mv0Zfga-kdSgAAAMA"]
[Mon Jul 20 06:44:44.623119 2026] [security2:error] [pid 1014214:tid 1014277] [remote 188.40.28.4:56300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4YPAuRBFTcQNywdCIHTwABjz4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:44:44.673325 2026] [security2:error] [pid 1011111:tid 1011250] [client 167.99.92.166:54489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4YPBXES7Mv0Zfga-kdSQAAAI0"]
[Mon Jul 20 06:44:44.689000 2026] [security2:error] [pid 1011111:tid 1011331] [client 167.99.92.166:54493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "terrapro-marketing.zanjan-fromer.com"] [uri "/wp-login.php"] [unique_id "al4YPBXES7Mv0Zfga-kdSwAAAN4"]
[Mon Jul 20 06:44:44.782088 2026] [security2:error] [pid 1014214:tid 1014436] [client 173.239.240.99:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YPAuRBFTcQNywdCIHWgAAAes"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:44.982393 2026] [security2:error] [pid 1014214:tid 1014452] [client 57.141.18.38:39410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNwuRBFTcQNywdCIGHQAB-28"]
[Mon Jul 20 06:44:45.042836 2026] [security2:error] [pid 1014214:tid 1014403] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YPAuRBFTcQNywdCIHYAAAAco"]
[Mon Jul 20 06:44:45.145364 2026] [security2:error] [pid 1014214:tid 1014461] [client 34.73.38.214:50210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YPQuRBFTcQNywdCIHcwAAAgQ"]
[Mon Jul 20 06:44:45.180647 2026] [security2:error] [pid 1011111:tid 1011261] [client 104.234.53.70:33635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YPRXES7Mv0Zfga-kdVwAAAJg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:45.221036 2026] [security2:error] [pid 1014214:tid 1014440] [client 57.141.18.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YPQuRBFTcQNywdCIHbgAAAe8"]
[Mon Jul 20 06:44:45.248729 2026] [security2:error] [pid 1014214:tid 1014359] [client 167.99.92.166:54540] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4YPQuRBFTcQNywdCIHdgAAAZ4"]
[Mon Jul 20 06:44:45.266903 2026] [security2:error] [pid 1014214:tid 1014448] [client 167.99.92.166:54546] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "terrapro-marketing.zanjan-fromer.com"] [uri "/wp-login.php"] [unique_id "al4YPQuRBFTcQNywdCIHeAAAAfc"]
[Mon Jul 20 06:44:45.267003 2026] [security2:error] [pid 1014214:tid 1014445] [client 136.144.35.243:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YPQuRBFTcQNywdCIHeQAAAfQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:45.337848 2026] [security2:error] [pid 1011111:tid 1011269] [client 114.119.141.217:29187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ghivs.com"] [uri "/robots.txt"] [unique_id "al4YPRXES7Mv0Zfga-kdXQAAAKA"], referer: http://ghivs.com/robots.txt
[Mon Jul 20 06:44:45.416604 2026] [security2:error] [pid 1011111:tid 1011311] [client 197.186.66.42:61869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YPRXES7Mv0Zfga-kdYwAAAMo"]
[Mon Jul 20 06:44:45.416721 2026] [security2:error] [pid 1011111:tid 1011311] [client 197.186.66.42:61869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YPRXES7Mv0Zfga-kdYwAAAMo"]
[Mon Jul 20 06:44:45.572934 2026] [security2:error] [pid 1014214:tid 1014392] [client 85.208.96.197:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/robots.txt"] [unique_id "al4YPQuRBFTcQNywdCIHlAAAAb8"]
[Mon Jul 20 06:44:45.573016 2026] [security2:error] [pid 1014214:tid 1014392] [client 85.208.96.197:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lakelopezonline.com"] [uri "/robots.txt"] [unique_id "al4YPQuRBFTcQNywdCIHlAAAAb8"]
[Mon Jul 20 06:44:45.578364 2026] [security2:error] [pid 1014214:tid 1014469] [client 57.141.18.93:44910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YNwuRBFTcQNywdCIGSwACDGM"]
[Mon Jul 20 06:44:45.632420 2026] [security2:error] [pid 1011111:tid 1011285] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YPRXES7Mv0Zfga-kdWgAAALA"]
[Mon Jul 20 06:44:45.633014 2026] [access_compat:error] [pid 1014214:tid 1014228] [remote 104.207.44.143:17813] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:44:45.660873 2026] [security2:error] [pid 1014214:tid 1014437] [client 34.73.38.214:49520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YPQuRBFTcQNywdCIHmwAAAew"]
[Mon Jul 20 06:44:45.731789 2026] [security2:error] [pid 1014214:tid 1014456] [client 77.110.127.138:54163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YPQuRBFTcQNywdCIHoAAAAf8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:45.731917 2026] [security2:error] [pid 1014214:tid 1014456] [client 77.110.127.138:54163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YPQuRBFTcQNywdCIHoAAAAf8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:45.740539 2026] [security2:error] [pid 1011111:tid 1011356] [client 136.144.35.245:36387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YPRXES7Mv0Zfga-kdbgAAAPc"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:45.852577 2026] [security2:error] [pid 1014214:tid 1014426] [client 85.208.96.198:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/songs/language/wp-_ogin.html"] [unique_id "al4YPQuRBFTcQNywdCIHqQAAAeE"]
[Mon Jul 20 06:44:45.852676 2026] [security2:error] [pid 1014214:tid 1014426] [client 85.208.96.198:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lakelopezonline.com"] [uri "/songs/language/wp-_ogin.html"] [unique_id "al4YPQuRBFTcQNywdCIHqQAAAeE"]
[Mon Jul 20 06:44:45.902252 2026] [security2:error] [pid 1014214:tid 1014368] [client 34.73.38.214:61496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.frontecinc.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YPQuRBFTcQNywdCIHrAAAAac"]
[Mon Jul 20 06:44:46.192720 2026] [security2:error] [pid 1014214:tid 1014443] [client 173.239.240.92:57987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YPguRBFTcQNywdCIHvgAAAfI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:46.426482 2026] [security2:error] [pid 1011111:tid 1011349] [client 57.141.18.18:28626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YOBXES7Mv0Zfga-kcygAA8AU"]
[Mon Jul 20 06:44:46.552401 2026] [security2:error] [pid 1011111:tid 1011252] [client 104.234.53.66:47301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YPhXES7Mv0Zfga-kdhAAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:46.554294 2026] [security2:error] [pid 1014214:tid 1014380] [client 57.141.18.84:63884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YOAuRBFTcQNywdCIGcgABs3Q"]
[Mon Jul 20 06:44:46.663694 2026] [security2:error] [pid 1014214:tid 1014426] [client 173.239.240.100:61495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YPguRBFTcQNywdCIH3QAAAeE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:46.840809 2026] [security2:error] [pid 1014214:tid 1014431] [client 200.159.141.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4YPQuRBFTcQNywdCIHiAAAAeY"]
[Mon Jul 20 06:44:46.842570 2026] [security2:error] [pid 1014214:tid 1014411] [client 200.159.141.57:10170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/9547.php"] [unique_id "al4YPQuRBFTcQNywdCIHgQAB0nI"]
[Mon Jul 20 06:44:46.844192 2026] [security2:error] [pid 1014214:tid 1014446] [client 14.225.17.146:60644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4YPguRBFTcQNywdCIH2AAAAfU"], referer: http://securingmemories.com/new
[Mon Jul 20 06:44:47.083507 2026] [security2:error] [pid 1014214:tid 1014352] [client 52.109.124.141:32640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YPwuRBFTcQNywdCIH8wAAAZc"]
[Mon Jul 20 06:44:47.086785 2026] [security2:error] [pid 1011111:tid 1011318] [client 104.234.53.66:47301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YPxXES7Mv0Zfga-kdlgAAANE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:47.118185 2026] [security2:error] [pid 1014214:tid 1014457] [client 136.144.35.253:50999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YPwuRBFTcQNywdCIH9wAAAgA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:47.137435 2026] [security2:error] [pid 1011111:tid 1011354] [client 39.48.81.23:55159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YPxXES7Mv0Zfga-kdmwAAAPU"]
[Mon Jul 20 06:44:47.137562 2026] [security2:error] [pid 1011111:tid 1011354] [client 39.48.81.23:55159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YPxXES7Mv0Zfga-kdmwAAAPU"]
[Mon Jul 20 06:44:47.265646 2026] [security2:error] [pid 1011111:tid 1011257] [client 14.225.17.146:50185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4YPxXES7Mv0Zfga-kdmgAAAJQ"], referer: http://christiancountytrumpet.com/new
[Mon Jul 20 06:44:47.265884 2026] [security2:error] [pid 1014214:tid 1014359] [client 52.109.124.141:32640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YPwuRBFTcQNywdCIIAAAAAZ4"]
[Mon Jul 20 06:44:47.292943 2026] [security2:error] [pid 1014214:tid 1014422] [client 77.110.127.138:54179] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 924 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YPwuRBFTcQNywdCIIAQAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:47.423236 2026] [security2:error] [pid 1014214:tid 1014460] [client 57.141.18.97:58464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YOQuRBFTcQNywdCIGngACA1c"]
[Mon Jul 20 06:44:47.460690 2026] [security2:error] [pid 1014214:tid 1014361] [client 106.219.188.178:10272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YPwuRBFTcQNywdCIICgAAAaA"]
[Mon Jul 20 06:44:47.461259 2026] [security2:error] [pid 1014214:tid 1014361] [client 106.219.188.178:10272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YPwuRBFTcQNywdCIICgAAAaA"]
[Mon Jul 20 06:44:47.616519 2026] [security2:error] [pid 1014214:tid 1014345] [client 217.181.91.159:58589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YPwuRBFTcQNywdCIIEgAAAZA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:44:47.620231 2026] [security2:error] [pid 1014214:tid 1014415] [client 136.144.35.248:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YPwuRBFTcQNywdCIIFgAAAdY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:47.661421 2026] [security2:error] [pid 1014214:tid 1014409] [client 158.173.166.181:47451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YPwuRBFTcQNywdCIIGwAAAdA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:47.787194 2026] [security2:error] [pid 1014214:tid 1014425] [client 54.244.177.189:26418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4YPwuRBFTcQNywdCIIJQAAAeA"]
[Mon Jul 20 06:44:47.834078 2026] [security2:error] [pid 1011111:tid 1011337] [client 23.95.244.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vtv.zzt.mybluehost.me"] [uri "/index.php"] [unique_id "al4YPRXES7Mv0Zfga-kdcwAAAOQ"]
[Mon Jul 20 06:44:47.990086 2026] [security2:error] [pid 1014214:tid 1014355] [client 57.141.18.60:28802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YOguRBFTcQNywdCIGvgABmjY"]
[Mon Jul 20 06:44:48.040867 2026] [security2:error] [pid 1011111:tid 1011344] [client 112.208.70.94:44372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YQBXES7Mv0Zfga-kdtQAAAOs"]
[Mon Jul 20 06:44:48.041033 2026] [security2:error] [pid 1011111:tid 1011344] [client 112.208.70.94:44372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YQBXES7Mv0Zfga-kdtQAAAOs"]
[Mon Jul 20 06:44:48.076758 2026] [security2:error] [pid 1014214:tid 1014359] [client 173.239.240.99:29873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YQAuRBFTcQNywdCIINwAAAZ4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:48.093378 2026] [security2:error] [pid 1014214:tid 1014450] [client 74.249.226.166:35522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YQAuRBFTcQNywdCIIOQAAAfk"]
[Mon Jul 20 06:44:48.152086 2026] [security2:error] [pid 1014214:tid 1014455] [client 74.249.226.166:35522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YQAuRBFTcQNywdCIIPgAAAf4"]
[Mon Jul 20 06:44:48.482589 2026] [security2:error] [pid 1011111:tid 1011331] [client 14.225.17.146:50660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4YPxXES7Mv0Zfga-kdlQAAAN4"], referer: http://kromosenergy.com/new
[Mon Jul 20 06:44:48.543426 2026] [security2:error] [pid 1014214:tid 1014377] [client 136.144.35.243:40377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YQAuRBFTcQNywdCIIVgAAAbA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:48.560437 2026] [security2:error] [pid 1014214:tid 1014374] [client 103.125.179.95:52253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YQAuRBFTcQNywdCIIWAAAAa0"]
[Mon Jul 20 06:44:48.560569 2026] [security2:error] [pid 1014214:tid 1014374] [client 103.125.179.95:52253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YQAuRBFTcQNywdCIIWAAAAa0"]
[Mon Jul 20 06:44:48.560830 2026] [security2:error] [pid 1014214:tid 1014440] [client 122.183.32.225:19278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YQAuRBFTcQNywdCIIVwAAAe8"]
[Mon Jul 20 06:44:48.560952 2026] [security2:error] [pid 1014214:tid 1014440] [client 122.183.32.225:19278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YQAuRBFTcQNywdCIIVwAAAe8"]
[Mon Jul 20 06:44:48.561263 2026] [security2:error] [pid 1014214:tid 1014423] [client 77.110.127.138:54198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YQAuRBFTcQNywdCIIWwAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:48.561335 2026] [security2:error] [pid 1014214:tid 1014423] [client 77.110.127.138:54198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YQAuRBFTcQNywdCIIWwAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:48.920824 2026] [security2:error] [pid 1011111:tid 1011245] [client 57.141.18.61:38078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YOxXES7Mv0Zfga-kdHwAAiE8"]
[Mon Jul 20 06:44:48.924269 2026] [security2:error] [pid 1014214:tid 1014222] [remote 103.75.185.95:36864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4YQAuRBFTcQNywdCIIcwAB_wc"]
[Mon Jul 20 06:44:48.970155 2026] [security2:error] [pid 1011111:tid 1011286] [client 57.141.18.108:52272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YOxXES7Mv0Zfga-kdJAAAsSo"]
[Mon Jul 20 06:44:48.996612 2026] [security2:error] [pid 1011111:tid 1011301] [client 173.239.240.99:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YQBXES7Mv0Zfga-kdywAAAMA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:49.027291 2026] [security2:error] [pid 1014214:tid 1014426] [client 14.225.17.146:54315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4YQAuRBFTcQNywdCIIdAAAAeE"], referer: http://cheesewithjam.com/new
[Mon Jul 20 06:44:49.078685 2026] [security2:error] [pid 1014214:tid 1014378] [client 183.82.98.154:59249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YQQuRBFTcQNywdCIIfQAAAbE"]
[Mon Jul 20 06:44:49.078802 2026] [security2:error] [pid 1014214:tid 1014378] [client 183.82.98.154:59249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YQQuRBFTcQNywdCIIfQAAAbE"]
[Mon Jul 20 06:44:49.091962 2026] [security2:error] [pid 1014214:tid 1014458] [client 217.181.92.145:13859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YQQuRBFTcQNywdCIIfwAAAgE"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:44:49.424576 2026] [security2:error] [pid 1011111:tid 1011322] [client 50.116.65.227:40454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YQRXES7Mv0Zfga-kd0AAAANU"]
[Mon Jul 20 06:44:49.434986 2026] [security2:error] [pid 1014214:tid 1014380] [client 50.116.65.227:40460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YQQuRBFTcQNywdCIInQAAAbM"]
[Mon Jul 20 06:44:49.440157 2026] [security2:error] [pid 1014214:tid 1014330] [remote 103.75.185.95:36864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4YQQuRBFTcQNywdCIImwAB_nM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:44:49.466176 2026] [security2:error] [pid 1014214:tid 1014457] [client 171.225.200.194:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4YQQuRBFTcQNywdCIIjQAAAgA"]
[Mon Jul 20 06:44:49.469940 2026] [security2:error] [pid 1014214:tid 1014412] [client 136.144.35.251:47425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YQQuRBFTcQNywdCIIngAAAdM"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:49.470666 2026] [security2:error] [pid 1014214:tid 1014448] [client 171.225.200.194:19026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/9547.php"] [unique_id "al4YQQuRBFTcQNywdCIIhwAB9yU"]
[Mon Jul 20 06:44:49.944235 2026] [security2:error] [pid 1014214:tid 1014445] [client 173.239.240.93:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YQQuRBFTcQNywdCIItgAAAfQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:50.193938 2026] [security2:error] [pid 1014214:tid 1014366] [client 57.141.18.110:29026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPAuRBFTcQNywdCIHPwABpUw"]
[Mon Jul 20 06:44:50.273723 2026] [security2:error] [pid 1014214:tid 1014413] [client 103.238.106.162:42781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YQguRBFTcQNywdCIIzQAAAdQ"]
[Mon Jul 20 06:44:50.273820 2026] [security2:error] [pid 1014214:tid 1014413] [client 103.238.106.162:42781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YQguRBFTcQNywdCIIzQAAAdQ"]
[Mon Jul 20 06:44:50.275170 2026] [security2:error] [pid 1014214:tid 1014461] [client 187.108.85.186:53339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YQguRBFTcQNywdCIIywAAAgQ"]
[Mon Jul 20 06:44:50.275257 2026] [security2:error] [pid 1014214:tid 1014461] [client 187.108.85.186:53339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YQguRBFTcQNywdCIIywAAAgQ"]
[Mon Jul 20 06:44:50.349086 2026] [security2:error] [pid 1014214:tid 1014248] [remote 47.128.29.220:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.origine.nz"] [uri "/robots.txt"] [unique_id "al4YQguRBFTcQNywdCII0gABpCE"]
[Mon Jul 20 06:44:50.433735 2026] [security2:error] [pid 1014214:tid 1014452] [client 173.239.240.102:64319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YQguRBFTcQNywdCII2QAAAfs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:50.439063 2026] [security2:error] [pid 1014214:tid 1014460] [client 74.208.214.194:49788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4YQguRBFTcQNywdCII2gAAAgM"]
[Mon Jul 20 06:44:50.741945 2026] [security2:error] [pid 1014214:tid 1014454] [client 158.173.89.95:46913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YQguRBFTcQNywdCII6AAAAf0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:50.855171 2026] [security2:error] [pid 1014214:tid 1014409] [client 50.255.62.89:39010] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.27"] [uri "/"] [unique_id "al4YQguRBFTcQNywdCII8wAAAdA"]
[Mon Jul 20 06:44:50.855600 2026] [security2:error] [pid 1014214:tid 1014445] [client 217.142.18.172:46647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YQguRBFTcQNywdCII9AAAAfQ"]
[Mon Jul 20 06:44:50.859162 2026] [security2:error] [pid 1014214:tid 1014445] [client 217.142.18.172:46647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YQguRBFTcQNywdCII9AAAAfQ"]
[Mon Jul 20 06:44:50.898540 2026] [security2:error] [pid 1011111:tid 1011260] [client 50.255.62.89:43116] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.27"] [uri "/"] [unique_id "al4YQhXES7Mv0Zfga-kd8QAAAJc"]
[Mon Jul 20 06:44:50.906811 2026] [security2:error] [pid 1014214:tid 1014443] [client 173.239.240.93:36165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YQguRBFTcQNywdCII-gAAAfI"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:51.219336 2026] [security2:error] [pid 1011111:tid 1011188] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YQxXES7Mv0Zfga-kd9gAAu0s"]
[Mon Jul 20 06:44:51.219541 2026] [security2:error] [pid 1011111:tid 1011296] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YQxXES7Mv0Zfga-kd9gAAu0s"]
[Mon Jul 20 06:44:51.288939 2026] [security2:error] [pid 1011111:tid 1011290] [client 57.141.18.107:47468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPRXES7Mv0Zfga-kdYgAAtR0"]
[Mon Jul 20 06:44:51.365671 2026] [security2:error] [pid 1011111:tid 1011331] [client 136.144.35.250:35873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YQxXES7Mv0Zfga-kd_gAAAN4"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:51.376489 2026] [security2:error] [pid 1014214:tid 1014396] [client 171.61.165.146:32355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YQwuRBFTcQNywdCIJFwAAAcM"]
[Mon Jul 20 06:44:51.376575 2026] [security2:error] [pid 1014214:tid 1014396] [client 171.61.165.146:32355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YQwuRBFTcQNywdCIJFwAAAcM"]
[Mon Jul 20 06:44:51.458309 2026] [security2:error] [pid 1014214:tid 1014387] [client 14.225.17.146:60643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4YQguRBFTcQNywdCIIxwAAAbo"], referer: http://wathenbartlett.co.uk/new
[Mon Jul 20 06:44:51.523276 2026] [security2:error] [pid 1011111:tid 1011274] [client 77.110.127.138:54238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 496 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YQxXES7Mv0Zfga-keBgAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:51.586913 2026] [security2:error] [pid 1014214:tid 1014362] [client 57.141.18.125:61782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPQuRBFTcQNywdCIHngABoRc"]
[Mon Jul 20 06:44:51.645106 2026] [security2:error] [pid 1014214:tid 1014395] [client 14.225.17.146:49582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4YQguRBFTcQNywdCII1gAAAcI"], referer: http://39ishlife.com/new
[Mon Jul 20 06:44:51.653147 2026] [security2:error] [pid 1014214:tid 1014378] [client 152.58.191.29:56875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YQwuRBFTcQNywdCIJHwAAAbE"]
[Mon Jul 20 06:44:51.653276 2026] [security2:error] [pid 1014214:tid 1014378] [client 152.58.191.29:56875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YQwuRBFTcQNywdCIJHwAAAbE"]
[Mon Jul 20 06:44:51.730605 2026] [security2:error] [pid 1014214:tid 1014470] [client 14.225.17.146:60549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4YQguRBFTcQNywdCII6gAAAg0"], referer: http://healthylifegourmet.org/new
[Mon Jul 20 06:44:51.775790 2026] [security2:error] [pid 1014214:tid 1014458] [client 104.234.53.77:48539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YQwuRBFTcQNywdCIJKQAAAgE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:51.822082 2026] [security2:error] [pid 1011111:tid 1011354] [client 136.144.35.252:29367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YQxXES7Mv0Zfga-keEAAAAPU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:51.847343 2026] [security2:error] [pid 1014214:tid 1014400] [client 57.141.18.14:45196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPQuRBFTcQNywdCIHpgABx1s"]
[Mon Jul 20 06:44:52.292314 2026] [security2:error] [pid 1014214:tid 1014350] [client 136.144.35.253:37927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YRAuRBFTcQNywdCIJQwAAAZU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:52.327316 2026] [security2:error] [pid 1014214:tid 1014426] [client 117.247.108.24:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YRAuRBFTcQNywdCIJSgAAAeE"]
[Mon Jul 20 06:44:52.327424 2026] [security2:error] [pid 1014214:tid 1014426] [client 117.247.108.24:61983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YRAuRBFTcQNywdCIJSgAAAeE"]
[Mon Jul 20 06:44:52.390941 2026] [security2:error] [pid 1014214:tid 1014404] [client 14.225.17.146:49624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4YRAuRBFTcQNywdCIJSQAAAcs"], referer: https://wathenbartlett.co.uk/new
[Mon Jul 20 06:44:52.572528 2026] [security2:error] [pid 1011111:tid 1011346] [client 14.225.17.146:54526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4YRBXES7Mv0Zfga-keGQAAAO0"], referer: https://39ishlife.com/new
[Mon Jul 20 06:44:52.763219 2026] [security2:error] [pid 1011111:tid 1011279] [client 136.144.35.243:58381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YRBXES7Mv0Zfga-keIQAAAKo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:52.827129 2026] [security2:error] [pid 1014214:tid 1014441] [client 77.110.127.138:54262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YRAuRBFTcQNywdCIJYQAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:52.827235 2026] [security2:error] [pid 1014214:tid 1014441] [client 77.110.127.138:54262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YRAuRBFTcQNywdCIJYQAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:52.919410 2026] [security2:error] [pid 1011111:tid 1011248] [client 57.141.18.112:30918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPxXES7Mv0Zfga-kdlwAAix8"]
[Mon Jul 20 06:44:52.999178 2026] [security2:error] [pid 1014214:tid 1014352] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.cel.bdi.mybluehost.me"] [uri "/index.php"] [unique_id "al4YQguRBFTcQNywdCII3gAAAZc"]
[Mon Jul 20 06:44:53.173853 2026] [security2:error] [pid 1014214:tid 1014384] [client 57.141.18.42:63798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPwuRBFTcQNywdCIIBwABtx0"]
[Mon Jul 20 06:44:53.221823 2026] [security2:error] [pid 1014214:tid 1014425] [client 173.239.240.32:40011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YRQuRBFTcQNywdCIJcAAAAeA"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:53.235494 2026] [security2:error] [pid 1014214:tid 1014363] [client 57.141.18.99:34968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPwuRBFTcQNywdCIIBgABogo"]
[Mon Jul 20 06:44:53.407410 2026] [security2:error] [pid 1011111:tid 1011292] [client 57.141.18.44:29872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YPxXES7Mv0Zfga-kdpgAAt3U"]
[Mon Jul 20 06:44:53.494498 2026] [security2:error] [pid 1011111:tid 1011252] [client 52.109.28.48:14912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YRRXES7Mv0Zfga-keOgAAAI8"]
[Mon Jul 20 06:44:53.594858 2026] [security2:error] [pid 1014214:tid 1014397] [client 14.225.17.146:54731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4YRQuRBFTcQNywdCIJdgAAAcQ"], referer: http://careysheatingandcooling.com/new
[Mon Jul 20 06:44:53.633804 2026] [security2:error] [pid 1011111:tid 1011265] [client 52.109.28.48:14912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YRRXES7Mv0Zfga-kePwAAAJw"]
[Mon Jul 20 06:44:53.645993 2026] [core:error] [pid 1014214:tid 1014404] [client 14.225.17.146:54944] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/new
[Mon Jul 20 06:44:53.646011 2026] [core:error] [pid 1014214:tid 1014404] [client 14.225.17.146:54944] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/new
[Mon Jul 20 06:44:53.692251 2026] [security2:error] [pid 1014214:tid 1014456] [client 173.239.240.92:39433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.240.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YRQuRBFTcQNywdCIJhQAAAf8"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:53.818230 2026] [security2:error] [pid 1014214:tid 1014422] [client 14.225.17.146:60498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4YRQuRBFTcQNywdCIJcgAAAd0"], referer: http://idigress.group/new
[Mon Jul 20 06:44:54.145192 2026] [security2:error] [pid 1011111:tid 1011338] [client 173.239.240.91:35145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YRhXES7Mv0Zfga-keTQAAAOU"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:54.229730 2026] [security2:error] [pid 1014214:tid 1014327] [remote 152.228.213.32:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4YRguRBFTcQNywdCIJogABvnA"]
[Mon Jul 20 06:44:54.402596 2026] [security2:error] [pid 1014214:tid 1014374] [client 57.141.18.124:60840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YQAuRBFTcQNywdCIIXwABrW0"]
[Mon Jul 20 06:44:54.411792 2026] [security2:error] [pid 1014214:tid 1014418] [client 57.141.18.107:47482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YQAuRBFTcQNywdCIIXgAB2QU"]
[Mon Jul 20 06:44:54.421266 2026] [security2:error] [pid 1014214:tid 1014355] [client 57.141.18.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YRguRBFTcQNywdCIJpwAAAZo"]
[Mon Jul 20 06:44:54.423861 2026] [security2:error] [pid 1014214:tid 1014274] [remote 152.228.213.32:58496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4YRguRBFTcQNywdCIJrwACDTs"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:44:54.499382 2026] [security2:error] [pid 1011111:tid 1011263] [client 172.200.24.58:4227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YRRXES7Mv0Zfga-keOwAAAJo"]
[Mon Jul 20 06:44:54.559852 2026] [security2:error] [pid 1011111:tid 1011353] [client 172.200.24.58:4227] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YRhXES7Mv0Zfga-keZAAAAPQ"]
[Mon Jul 20 06:44:54.597287 2026] [security2:error] [pid 1011111:tid 1011344] [client 136.144.35.252:48289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YRhXES7Mv0Zfga-keZwAAAOs"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:54.911729 2026] [security2:error] [pid 1014214:tid 1014471] [client 57.141.18.113:39568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YQQuRBFTcQNywdCIIfAACDic"]
[Mon Jul 20 06:44:54.950852 2026] [security2:error] [pid 1014214:tid 1014349] [client 37.52.210.45:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YRguRBFTcQNywdCIJzAAAAZQ"]
[Mon Jul 20 06:44:54.951011 2026] [security2:error] [pid 1014214:tid 1014349] [client 37.52.210.45:55798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YRguRBFTcQNywdCIJzAAAAZQ"]
[Mon Jul 20 06:44:55.036151 2026] [security2:error] [pid 1011111:tid 1011332] [client 104.234.53.61:41561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YRhXES7Mv0Zfga-kecwAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:55.070643 2026] [security2:error] [pid 1011111:tid 1011270] [client 136.144.35.248:57543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YRxXES7Mv0Zfga-keeAAAAKE"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:55.091076 2026] [security2:error] [pid 1014214:tid 1014377] [client 14.225.17.146:54107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4YRguRBFTcQNywdCIJxgAAAbA"]
[Mon Jul 20 06:44:55.259894 2026] [security2:error] [pid 1011111:tid 1011247] [client 14.251.3.155:54674] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YRxXES7Mv0Zfga-kefAAAAIo"]
[Mon Jul 20 06:44:55.383933 2026] [security2:error] [pid 1011111:tid 1011256] [client 104.234.53.61:41561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YRxXES7Mv0Zfga-keiAAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:44:55.446201 2026] [security2:error] [pid 1011111:tid 1011335] [client 57.141.18.72:33438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YQRXES7Mv0Zfga-kd1AAA4hQ"]
[Mon Jul 20 06:44:55.540087 2026] [security2:error] [pid 1011111:tid 1011313] [client 136.144.35.251:42281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.35.144.136.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YRxXES7Mv0Zfga-kejwAAAMw"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:55.765869 2026] [security2:error] [pid 1014214:tid 1014447] [client 77.110.127.138:54305] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:attachment_id"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YRwuRBFTcQNywdCIJ-AAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:55.776164 2026] [security2:error] [pid 1011111:tid 1011281] [client 223.185.13.213:27193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YRxXES7Mv0Zfga-kelAAAAKw"]
[Mon Jul 20 06:44:55.776274 2026] [security2:error] [pid 1011111:tid 1011281] [client 223.185.13.213:27193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YRxXES7Mv0Zfga-kelAAAAKw"]
[Mon Jul 20 06:44:55.916477 2026] [security2:error] [pid 1014214:tid 1014362] [client 14.251.3.155:55809] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YRwuRBFTcQNywdCIKAQAAAaE"]
[Mon Jul 20 06:44:55.992129 2026] [security2:error] [pid 1014214:tid 1014349] [client 136.144.35.253:36745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.35.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YRwuRBFTcQNywdCIKBwAAAZQ"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:56.013154 2026] [proxy:error] [pid 1014214:tid 1014427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:56.013237 2026] [proxy_http:error] [pid 1014214:tid 1014427] [client 34.73.38.214:56583] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:56.014100 2026] [proxy:error] [pid 1014214:tid 1014427] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:56.014137 2026] [proxy_http:error] [pid 1014214:tid 1014427] [client 34.73.38.214:56583] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:56.161067 2026] [security2:error] [pid 1014214:tid 1014423] [client 14.225.17.146:49691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4YRwuRBFTcQNywdCIJ_wAAAd4"], referer: http://falconarrowshop.com/new
[Mon Jul 20 06:44:56.408897 2026] [security2:error] [pid 1014214:tid 1014466] [client 14.225.17.146:54717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4YSAuRBFTcQNywdCIKFgAAAgk"], referer: http://mtlegnews.gov/new
[Mon Jul 20 06:44:56.472925 2026] [security2:error] [pid 1014214:tid 1014433] [client 173.239.240.102:29387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.240.239.173.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-admin/index.php"] [unique_id "al4YSAuRBFTcQNywdCIKGwAAAeg"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:44:56.730619 2026] [security2:error] [pid 1014214:tid 1014446] [client 57.141.18.62:31010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YQguRBFTcQNywdCII8gAB9S4"]
[Mon Jul 20 06:44:57.036116 2026] [security2:error] [pid 1014214:tid 1014391] [client 31.58.30.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tgs.lfg.mybluehost.me"] [uri "/index.php"] [unique_id "al4YRwuRBFTcQNywdCIJ0QAAAb4"]
[Mon Jul 20 06:44:57.125716 2026] [security2:error] [pid 1014214:tid 1014401] [client 77.110.127.138:54324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YSQuRBFTcQNywdCIKWAAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:57.125825 2026] [security2:error] [pid 1014214:tid 1014401] [client 77.110.127.138:54324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YSQuRBFTcQNywdCIKWAAAAcg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:57.179599 2026] [security2:error] [pid 1011111:tid 1011141] [remote 47.86.33.52:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YSRXES7Mv0Zfga-kevwAAkhw"]
[Mon Jul 20 06:44:57.187428 2026] [proxy:error] [pid 1011111:tid 1011361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:57.187500 2026] [proxy_http:error] [pid 1011111:tid 1011361] [client 34.73.38.214:60585] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:57.188056 2026] [proxy:error] [pid 1011111:tid 1011361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:57.188081 2026] [proxy_http:error] [pid 1011111:tid 1011361] [client 34.73.38.214:60585] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:57.309940 2026] [security2:error] [pid 1014214:tid 1014442] [client 39.48.81.23:55684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YSQuRBFTcQNywdCIKZgAAAfE"]
[Mon Jul 20 06:44:57.310253 2026] [security2:error] [pid 1014214:tid 1014442] [client 39.48.81.23:55684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YSQuRBFTcQNywdCIKZgAAAfE"]
[Mon Jul 20 06:44:57.578114 2026] [security2:error] [pid 1014214:tid 1014459] [client 57.141.18.88:37930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YQwuRBFTcQNywdCIJLQACAjo"]
[Mon Jul 20 06:44:57.608451 2026] [security2:error] [pid 1014214:tid 1014437] [client 98.159.234.160:39379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YSQuRBFTcQNywdCIKdgAAAew"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:44:57.626950 2026] [security2:error] [pid 1011111:tid 1011273] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YSRXES7Mv0Zfga-keygAAAKQ"], referer: 1'"3000
[Mon Jul 20 06:44:57.687721 2026] [security2:error] [pid 1014214:tid 1014350] [client 192.140.149.97:44942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YSQuRBFTcQNywdCIKfQAAAZU"]
[Mon Jul 20 06:44:57.687870 2026] [security2:error] [pid 1014214:tid 1014350] [client 192.140.149.97:44942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YSQuRBFTcQNywdCIKfQAAAZU"]
[Mon Jul 20 06:44:57.695794 2026] [security2:error] [pid 1011111:tid 1011146] [remote 47.86.33.52:43992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YSRXES7Mv0Zfga-ke0wAA-iE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:44:57.720321 2026] [security2:error] [pid 1014214:tid 1014417] [client 57.141.18.99:34978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRAuRBFTcQNywdCIJNgAB2H4"]
[Mon Jul 20 06:44:57.825826 2026] [proxy:error] [pid 1011111:tid 1011282] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:57.825926 2026] [proxy_http:error] [pid 1011111:tid 1011282] [client 34.73.38.214:61441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:57.827283 2026] [proxy:error] [pid 1011111:tid 1011282] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:57.827355 2026] [proxy_http:error] [pid 1011111:tid 1011282] [client 34.73.38.214:61441] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:57.959632 2026] [proxy:error] [pid 1014214:tid 1014392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:57.959720 2026] [proxy_http:error] [pid 1014214:tid 1014392] [client 34.73.38.214:53109] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:57.960364 2026] [proxy:error] [pid 1014214:tid 1014392] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:57.960394 2026] [proxy_http:error] [pid 1014214:tid 1014392] [client 34.73.38.214:53109] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:58.128491 2026] [security2:error] [pid 1014214:tid 1014403] [client 122.183.32.225:10075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YSguRBFTcQNywdCIKnwAAAco"]
[Mon Jul 20 06:44:58.128592 2026] [security2:error] [pid 1014214:tid 1014403] [client 122.183.32.225:10075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YSguRBFTcQNywdCIKnwAAAco"]
[Mon Jul 20 06:44:58.163738 2026] [security2:error] [pid 1014214:tid 1014368] [client 106.219.188.178:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YSguRBFTcQNywdCIKogAAAac"]
[Mon Jul 20 06:44:58.163906 2026] [security2:error] [pid 1014214:tid 1014368] [client 106.219.188.178:53912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YSguRBFTcQNywdCIKogAAAac"]
[Mon Jul 20 06:44:58.349192 2026] [security2:error] [pid 1014214:tid 1014438] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YSguRBFTcQNywdCIKnQAAAe0"], referer: 1'"3000
[Mon Jul 20 06:44:58.591025 2026] [security2:error] [pid 1011111:tid 1011249] [client 57.141.18.101:36168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRBXES7Mv0Zfga-keKAAAjD4"]
[Mon Jul 20 06:44:58.647640 2026] [security2:error] [pid 1011111:tid 1011270] [client 112.208.70.94:44812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YShXES7Mv0Zfga-ke9gAAAKE"]
[Mon Jul 20 06:44:58.647732 2026] [security2:error] [pid 1011111:tid 1011270] [client 112.208.70.94:44812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YShXES7Mv0Zfga-ke9gAAAKE"]
[Mon Jul 20 06:44:58.681567 2026] [security2:error] [pid 1014214:tid 1014244] [remote 49.13.1.223:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4YSguRBFTcQNywdCIKwQACBR0"]
[Mon Jul 20 06:44:58.788966 2026] [security2:error] [pid 1014214:tid 1014367] [client 197.186.66.42:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YSguRBFTcQNywdCIKzAAAAaY"]
[Mon Jul 20 06:44:58.789078 2026] [security2:error] [pid 1014214:tid 1014367] [client 197.186.66.42:62438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YSguRBFTcQNywdCIKzAAAAaY"]
[Mon Jul 20 06:44:58.815645 2026] [security2:error] [pid 1011111:tid 1011274] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YShXES7Mv0Zfga-ke9wAAAKU"], referer: 1'"3000
[Mon Jul 20 06:44:58.863578 2026] [security2:error] [pid 1014214:tid 1014225] [remote 49.13.1.223:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.1.13.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4YSguRBFTcQNywdCIK1AACBwo"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:44:58.865519 2026] [security2:error] [pid 1011111:tid 1011367] [client 57.141.18.98:30312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRRXES7Mv0Zfga-keMQABAlM"]
[Mon Jul 20 06:44:59.138676 2026] [security2:error] [pid 1011111:tid 1011358] [client 14.225.17.146:55819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4YShXES7Mv0Zfga-ke_AAAAPk"]
[Mon Jul 20 06:44:59.229645 2026] [proxy:error] [pid 1014214:tid 1014360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:59.229725 2026] [proxy_http:error] [pid 1014214:tid 1014360] [client 34.73.38.214:51809] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:59.230425 2026] [proxy:error] [pid 1014214:tid 1014360] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:44:59.230457 2026] [proxy_http:error] [pid 1014214:tid 1014360] [client 34.73.38.214:51809] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:44:59.249476 2026] [security2:error] [pid 1014214:tid 1014468] [client 50.116.65.227:19550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YSwuRBFTcQNywdCIK6QAAAgs"]
[Mon Jul 20 06:44:59.258930 2026] [security2:error] [pid 1014214:tid 1014401] [client 50.116.65.227:19564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YSwuRBFTcQNywdCIK6gAAAcg"]
[Mon Jul 20 06:44:59.291158 2026] [security2:error] [pid 1014214:tid 1014456] [client 103.125.179.95:52754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCIK8AAAAf8"]
[Mon Jul 20 06:44:59.291249 2026] [security2:error] [pid 1014214:tid 1014456] [client 103.125.179.95:52754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCIK8AAAAf8"]
[Mon Jul 20 06:44:59.414508 2026] [security2:error] [pid 1014214:tid 1014386] [client 104.207.61.78:36263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YSwuRBFTcQNywdCIK8wAAAbk"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:44:59.450374 2026] [security2:error] [pid 1014214:tid 1014279] [remote 47.86.33.52:43998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCIK9AAB4EA"]
[Mon Jul 20 06:44:59.450539 2026] [security2:error] [pid 1014214:tid 1014425] [client 47.86.33.52:43998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCIK9AAB4EA"]
[Mon Jul 20 06:44:59.535725 2026] [security2:error] [pid 1014214:tid 1014469] [client 34.73.38.214:61635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCIK-QAAAgw"]
[Mon Jul 20 06:44:59.562903 2026] [security2:error] [pid 1011111:tid 1011299] [client 77.110.127.138:54347] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:attachment_id"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YSxXES7Mv0Zfga-kfCgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:44:59.763417 2026] [security2:error] [pid 1014214:tid 1014389] [client 183.82.98.154:59824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCILDQAAAbw"]
[Mon Jul 20 06:44:59.763528 2026] [security2:error] [pid 1014214:tid 1014389] [client 183.82.98.154:59824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YSwuRBFTcQNywdCILDQAAAbw"]
[Mon Jul 20 06:44:59.798032 2026] [security2:error] [pid 1014214:tid 1014465] [client 34.73.38.214:61802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YSwuRBFTcQNywdCILEwAAAgg"]
[Mon Jul 20 06:44:59.913651 2026] [security2:error] [pid 1011111:tid 1011346] [client 57.141.18.26:22088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRhXES7Mv0Zfga-keWgAA7RU"]
[Mon Jul 20 06:45:00.016414 2026] [security2:error] [pid 1011111:tid 1011154] [remote 20.173.88.122:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YTBXES7Mv0Zfga-kfGAAA8Ck"]
[Mon Jul 20 06:45:00.127433 2026] [proxy:error] [pid 1014214:tid 1014395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:00.127500 2026] [proxy_http:error] [pid 1014214:tid 1014395] [client 34.73.38.214:52922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:00.128107 2026] [proxy:error] [pid 1014214:tid 1014395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:00.128140 2026] [proxy_http:error] [pid 1014214:tid 1014395] [client 34.73.38.214:52922] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:00.139128 2026] [security2:error] [pid 1014214:tid 1014254] [remote 72.167.132.114:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YTAuRBFTcQNywdCILJQABuyc"]
[Mon Jul 20 06:45:00.198707 2026] [security2:error] [pid 1011111:tid 1011327] [client 104.207.59.252:14517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YTBXES7Mv0Zfga-kfHAAAANo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:00.270578 2026] [security2:error] [pid 1011111:tid 1011333] [client 57.141.18.0:31066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRhXES7Mv0Zfga-kebAAA4FU"]
[Mon Jul 20 06:45:00.286120 2026] [security2:error] [pid 1011111:tid 1011142] [remote 216.73.216.55:8271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4YTBXES7Mv0Zfga-kfHwAA9h0"]
[Mon Jul 20 06:45:00.357529 2026] [security2:error] [pid 1014214:tid 1014278] [remote 72.167.132.114:56346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YTAuRBFTcQNywdCILLwABpz8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:45:00.372282 2026] [security2:error] [pid 1011111:tid 1011214] [remote 20.173.88.122:58064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YTBXES7Mv0Zfga-kfIQAA82U"], referer: https://mail.yok.mqz.mybluehost.me/wp-login.php
[Mon Jul 20 06:45:00.404347 2026] [security2:error] [pid 1014214:tid 1014420] [client 14.225.17.146:56249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4YSwuRBFTcQNywdCILGgAAAds"]
[Mon Jul 20 06:45:00.427174 2026] [security2:error] [pid 1014214:tid 1014428] [client 24.80.98.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4YTAuRBFTcQNywdCILIwAB4wc"]
[Mon Jul 20 06:45:00.588120 2026] [security2:error] [pid 1014214:tid 1014357] [client 57.141.18.38:34754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRwuRBFTcQNywdCIJ2QABnHk"]
[Mon Jul 20 06:45:00.724700 2026] [security2:error] [pid 1014214:tid 1014426] [client 34.73.38.214:56862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YTAuRBFTcQNywdCILSwAAAeE"]
[Mon Jul 20 06:45:00.753539 2026] [security2:error] [pid 1011111:tid 1011276] [client 57.141.18.4:21814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YRxXES7Mv0Zfga-keiwAApxA"]
[Mon Jul 20 06:45:00.765036 2026] [security2:error] [pid 1014214:tid 1014352] [client 103.238.106.162:42657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YTAuRBFTcQNywdCILTwAAAZc"]
[Mon Jul 20 06:45:00.765151 2026] [security2:error] [pid 1014214:tid 1014352] [client 103.238.106.162:42657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YTAuRBFTcQNywdCILTwAAAZc"]
[Mon Jul 20 06:45:00.869600 2026] [security2:error] [pid 1014214:tid 1014417] [client 13.229.223.11:50778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YTAuRBFTcQNywdCILVwAAAdg"]
[Mon Jul 20 06:45:01.068795 2026] [security2:error] [pid 1014214:tid 1014434] [client 187.108.85.186:53905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILYwAAAek"]
[Mon Jul 20 06:45:01.068903 2026] [security2:error] [pid 1014214:tid 1014434] [client 187.108.85.186:53905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILYwAAAek"]
[Mon Jul 20 06:45:01.359518 2026] [security2:error] [pid 1014214:tid 1014348] [client 217.142.18.172:57102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILdwAAAZM"]
[Mon Jul 20 06:45:01.359627 2026] [security2:error] [pid 1014214:tid 1014348] [client 217.142.18.172:57102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILdwAAAZM"]
[Mon Jul 20 06:45:01.360124 2026] [security2:error] [pid 1014214:tid 1014445] [client 34.73.38.214:54079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILeAAAAfQ"]
[Mon Jul 20 06:45:01.479871 2026] [security2:error] [pid 1011111:tid 1011268] [client 77.110.127.138:54382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTRXES7Mv0Zfga-kfMgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:01.480277 2026] [security2:error] [pid 1011111:tid 1011303] [client 57.141.18.105:37322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YSBXES7Mv0Zfga-kenQAAwg4"]
[Mon Jul 20 06:45:01.500455 2026] [security2:error] [pid 1011111:tid 1011268] [client 77.110.127.138:54382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTRXES7Mv0Zfga-kfMgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:01.531076 2026] [security2:error] [pid 1011111:tid 1011285] [client 34.73.38.214:60775] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YTRXES7Mv0Zfga-kfNAAAALA"]
[Mon Jul 20 06:45:01.796902 2026] [security2:error] [pid 1014214:tid 1014464] [client 13.229.83.156:42898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YTQuRBFTcQNywdCILlQAAAgc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:45:01.804347 2026] [security2:error] [pid 1011111:tid 1011339] [client 57.141.18.32:53676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YSBXES7Mv0Zfga-kesgAA5gs"]
[Mon Jul 20 06:45:01.815432 2026] [security2:error] [pid 1011111:tid 1011358] [client 34.73.38.214:57142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YTRXES7Mv0Zfga-kfOwAAAPk"]
[Mon Jul 20 06:45:01.863304 2026] [security2:error] [pid 1014214:tid 1014295] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILmwACCFA"]
[Mon Jul 20 06:45:01.863452 2026] [security2:error] [pid 1014214:tid 1014465] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YTQuRBFTcQNywdCILmwACCFA"]
[Mon Jul 20 06:45:01.889107 2026] [security2:error] [pid 1011111:tid 1011334] [client 77.110.127.138:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTRXES7Mv0Zfga-kfPwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:01.889216 2026] [security2:error] [pid 1011111:tid 1011334] [client 77.110.127.138:54389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTRXES7Mv0Zfga-kfPwAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.073023 2026] [security2:error] [pid 1014214:tid 1014462] [client 77.110.127.138:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTguRBFTcQNywdCILogAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.073158 2026] [security2:error] [pid 1014214:tid 1014462] [client 77.110.127.138:54392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTguRBFTcQNywdCILogAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.195728 2026] [security2:error] [pid 1014214:tid 1014460] [client 171.61.17.42:10096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bbwipartnerconference.com"] [uri "/xmlrpc.php"] [unique_id "al4YTAuRBFTcQNywdCILHgAAAgM"]
[Mon Jul 20 06:45:02.229510 2026] [security2:error] [pid 1011111:tid 1011306] [client 77.110.127.138:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YThXES7Mv0Zfga-kfSQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.229613 2026] [security2:error] [pid 1011111:tid 1011306] [client 77.110.127.138:54395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YThXES7Mv0Zfga-kfSQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.291660 2026] [security2:error] [pid 1014214:tid 1014440] [client 34.73.38.214:64709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YTguRBFTcQNywdCILsQAAAe8"]
[Mon Jul 20 06:45:02.297426 2026] [security2:error] [pid 1014214:tid 1014408] [client 171.61.165.146:13863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YTguRBFTcQNywdCILsgAAAc8"]
[Mon Jul 20 06:45:02.297540 2026] [security2:error] [pid 1014214:tid 1014408] [client 171.61.165.146:13863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YTguRBFTcQNywdCILsgAAAc8"]
[Mon Jul 20 06:45:02.322327 2026] [security2:error] [pid 1014214:tid 1014359] [client 145.223.130.248:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4YTguRBFTcQNywdCILpQABnm4"]
[Mon Jul 20 06:45:02.386932 2026] [security2:error] [pid 1011111:tid 1011292] [client 77.110.127.138:54398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YThXES7Mv0Zfga-kfVAAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.387021 2026] [security2:error] [pid 1011111:tid 1011292] [client 77.110.127.138:54398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YThXES7Mv0Zfga-kfVAAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:02.388311 2026] [security2:error] [pid 1014214:tid 1014347] [client 152.58.191.29:16400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YTguRBFTcQNywdCILuAAAAZI"]
[Mon Jul 20 06:45:02.395994 2026] [security2:error] [pid 1014214:tid 1014347] [client 152.58.191.29:16400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YTguRBFTcQNywdCILuAAAAZI"]
[Mon Jul 20 06:45:02.513192 2026] [security2:error] [pid 1011111:tid 1011333] [client 77.110.127.138:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YThXES7Mv0Zfga-kfWAAAAOA"]
[Mon Jul 20 06:45:02.513284 2026] [security2:error] [pid 1011111:tid 1011333] [client 77.110.127.138:54334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YThXES7Mv0Zfga-kfWAAAAOA"]
[Mon Jul 20 06:45:02.631015 2026] [security2:error] [pid 1014214:tid 1014371] [client 34.73.38.214:57143] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YTguRBFTcQNywdCILxAAAAao"]
[Mon Jul 20 06:45:02.737717 2026] [security2:error] [pid 1014214:tid 1014465] [client 77.110.127.138:54401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTguRBFTcQNywdCILywAAAgg"]
[Mon Jul 20 06:45:02.737823 2026] [security2:error] [pid 1014214:tid 1014465] [client 77.110.127.138:54401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YTguRBFTcQNywdCILywAAAgg"]
[Mon Jul 20 06:45:03.024207 2026] [security2:error] [pid 1014214:tid 1014416] [client 77.110.127.138:54343] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:attachment_id. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/"] [unique_id "al4YTwuRBFTcQNywdCIL2gAAAdc"]
[Mon Jul 20 06:45:03.212136 2026] [security2:error] [pid 1014214:tid 1014373] [client 57.141.18.6:58274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YSguRBFTcQNywdCIKlQABrHI"]
[Mon Jul 20 06:45:03.232368 2026] [security2:error] [pid 1014214:tid 1014413] [client 196.190.60.133:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4YTguRBFTcQNywdCILxgAB1H0"], referer: https://packerjanitorial.com
[Mon Jul 20 06:45:03.294696 2026] [security2:error] [pid 1014214:tid 1014390] [client 117.247.108.24:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YTwuRBFTcQNywdCIL6AAAAb0"]
[Mon Jul 20 06:45:03.294808 2026] [security2:error] [pid 1014214:tid 1014390] [client 117.247.108.24:62542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YTwuRBFTcQNywdCIL6AAAAb0"]
[Mon Jul 20 06:45:03.464611 2026] [security2:error] [pid 1014214:tid 1014393] [client 34.73.38.214:58606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YTwuRBFTcQNywdCIL8AAAAcA"]
[Mon Jul 20 06:45:03.561240 2026] [security2:error] [pid 1014214:tid 1014434] [client 34.73.38.214:62335] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YTwuRBFTcQNywdCIL-AAAAek"]
[Mon Jul 20 06:45:03.610571 2026] [security2:error] [pid 1011111:tid 1011301] [client 57.141.18.78:38276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YShXES7Mv0Zfga-ke7gAAwBc"]
[Mon Jul 20 06:45:03.775577 2026] [security2:error] [pid 1014214:tid 1014452] [client 57.141.18.71:40168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YSguRBFTcQNywdCIKtgAB-14"]
[Mon Jul 20 06:45:03.819427 2026] [security2:error] [pid 1014214:tid 1014219] [remote 162.19.86.63:44137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YTwuRBFTcQNywdCIMBwABygQ"]
[Mon Jul 20 06:45:04.027205 2026] [security2:error] [pid 1014214:tid 1014232] [remote 162.19.86.63:44137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YUAuRBFTcQNywdCIMFgABsRE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:45:04.202848 2026] [security2:error] [pid 1011111:tid 1011353] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4YTxXES7Mv0Zfga-kffgAAAPQ"]
[Mon Jul 20 06:45:04.288710 2026] [security2:error] [pid 1011111:tid 1011261] [client 14.225.17.146:52668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4YTxXES7Mv0Zfga-kfZwAAAJg"]
[Mon Jul 20 06:45:04.399151 2026] [security2:error] [pid 1011111:tid 1011347] [client 104.234.53.65:23043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YUBXES7Mv0Zfga-kfigAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:04.515829 2026] [security2:error] [pid 1014214:tid 1014391] [client 34.73.38.214:55180] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YUAuRBFTcQNywdCIMNQAAAb4"]
[Mon Jul 20 06:45:04.599372 2026] [security2:error] [pid 1014214:tid 1014349] [client 45.157.112.60:25763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YUAuRBFTcQNywdCIMOwAAAZQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:45:04.610278 2026] [security2:error] [pid 1014214:tid 1014387] [client 57.141.18.84:61126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YSwuRBFTcQNywdCILBgABugU"]
[Mon Jul 20 06:45:04.769034 2026] [security2:error] [pid 1014214:tid 1014348] [client 216.73.217.138:27857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4YUAuRBFTcQNywdCIMPAABkxo"]
[Mon Jul 20 06:45:04.876077 2026] [security2:error] [pid 1014214:tid 1014464] [client 5.161.177.47:39044] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4YUAuRBFTcQNywdCIMKgAAAgc"], referer: https://windowtx.com
[Mon Jul 20 06:45:04.961455 2026] [security2:error] [pid 1011111:tid 1011355] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YUBXES7Mv0Zfga-kfkwAAAPY"], referer: 1'"3000
[Mon Jul 20 06:45:04.969205 2026] [security2:error] [pid 1014214:tid 1014453] [client 34.73.38.214:62379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YUAuRBFTcQNywdCIMWQAAAfw"]
[Mon Jul 20 06:45:05.131577 2026] [security2:error] [pid 1014214:tid 1014305] [remote 20.87.239.85:9101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4YUQuRBFTcQNywdCIMYQAB9lo"]
[Mon Jul 20 06:45:05.358858 2026] [security2:error] [pid 1014214:tid 1014376] [client 34.73.38.214:59841] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YUQuRBFTcQNywdCIMcwAAAa8"]
[Mon Jul 20 06:45:05.576385 2026] [security2:error] [pid 1011111:tid 1011251] [client 130.12.17.122:49083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4YURXES7Mv0Zfga-kfpgAAjiQ"]
[Mon Jul 20 06:45:05.653101 2026] [security2:error] [pid 1014214:tid 1014467] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YUQuRBFTcQNywdCIMbQAAAgo"], referer: 1'"3000
[Mon Jul 20 06:45:05.654760 2026] [security2:error] [pid 1014214:tid 1014454] [client 34.73.38.214:49411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YUQuRBFTcQNywdCIMgwAAAf0"]
[Mon Jul 20 06:45:05.670916 2026] [security2:error] [pid 1011111:tid 1011330] [client 37.52.210.45:30178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YURXES7Mv0Zfga-kfrAAAAN0"]
[Mon Jul 20 06:45:05.671032 2026] [security2:error] [pid 1011111:tid 1011330] [client 37.52.210.45:30178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YURXES7Mv0Zfga-kfrAAAAN0"]
[Mon Jul 20 06:45:05.767085 2026] [security2:error] [pid 1014214:tid 1014468] [client 57.141.18.19:46378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YTAuRBFTcQNywdCILRgACCyU"]
[Mon Jul 20 06:45:06.085256 2026] [security2:error] [pid 1014214:tid 1014411] [client 34.73.38.214:56534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YUguRBFTcQNywdCIMoQAAAdI"]
[Mon Jul 20 06:45:06.109138 2026] [access_compat:error] [pid 1014214:tid 1014275] [remote 20.163.34.92:36006] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:45:06.274327 2026] [security2:error] [pid 1014214:tid 1014448] [client 77.110.127.138:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YUguRBFTcQNywdCIMrQAAAfc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:06.274425 2026] [security2:error] [pid 1014214:tid 1014448] [client 77.110.127.138:54435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YUguRBFTcQNywdCIMrQAAAfc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:06.435650 2026] [security2:error] [pid 1014214:tid 1014418] [client 34.73.38.214:51121] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YUguRBFTcQNywdCIMvQAAAdk"]
[Mon Jul 20 06:45:06.460830 2026] [security2:error] [pid 1014214:tid 1014276] [remote 5.252.52.249:55430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YUguRBFTcQNywdCIMwAABkT0"]
[Mon Jul 20 06:45:06.571111 2026] [security2:error] [pid 1011111:tid 1011125] [remote 47.86.33.52:53236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4YUhXES7Mv0Zfga-kfvAAA1gw"]
[Mon Jul 20 06:45:06.729007 2026] [security2:error] [pid 1014214:tid 1014326] [remote 5.252.52.249:55430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YUguRBFTcQNywdCIMzwABpm8"], referer: https://friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:07.105672 2026] [security2:error] [pid 1014214:tid 1014454] [client 34.139.11.221:58408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YUwuRBFTcQNywdCIM8gAAAf0"]
[Mon Jul 20 06:45:07.223405 2026] [security2:error] [pid 1014214:tid 1014373] [client 34.139.11.221:61322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YUwuRBFTcQNywdCIM-gAAAaw"]
[Mon Jul 20 06:45:07.265972 2026] [security2:error] [pid 1014214:tid 1014433] [client 223.185.13.213:15971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YUwuRBFTcQNywdCIM-wAAAeg"]
[Mon Jul 20 06:45:07.266074 2026] [security2:error] [pid 1014214:tid 1014433] [client 223.185.13.213:15971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YUwuRBFTcQNywdCIM-wAAAeg"]
[Mon Jul 20 06:45:07.432415 2026] [security2:error] [pid 1011111:tid 1011290] [client 34.139.11.221:52778] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YUxXES7Mv0Zfga-kfyQAAALU"]
[Mon Jul 20 06:45:07.593783 2026] [security2:error] [pid 1014214:tid 1014376] [client 34.139.11.221:63150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YUwuRBFTcQNywdCINDQAAAa8"]
[Mon Jul 20 06:45:07.665483 2026] [security2:error] [pid 1014214:tid 1014397] [client 57.141.18.22:30888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YTguRBFTcQNywdCILvAABxCs"]
[Mon Jul 20 06:45:07.685502 2026] [security2:error] [pid 1014214:tid 1014407] [client 34.73.38.214:61431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YUwuRBFTcQNywdCINGgAAAc4"]
[Mon Jul 20 06:45:07.695719 2026] [security2:error] [pid 1014214:tid 1014238] [remote 192.241.143.148:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4YUwuRBFTcQNywdCINHQACCBc"]
[Mon Jul 20 06:45:07.752679 2026] [security2:error] [pid 1011111:tid 1011185] [remote 47.86.33.52:53236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4YUxXES7Mv0Zfga-kf2AABBEg"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:45:07.760846 2026] [security2:error] [pid 1014214:tid 1014463] [client 34.139.11.221:58615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YUwuRBFTcQNywdCINJgAAAgY"]
[Mon Jul 20 06:45:07.805843 2026] [security2:error] [pid 1014214:tid 1014389] [client 122.183.32.225:14127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YUwuRBFTcQNywdCINJwAAAbw"]
[Mon Jul 20 06:45:07.805985 2026] [security2:error] [pid 1014214:tid 1014389] [client 122.183.32.225:14127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YUwuRBFTcQNywdCINJwAAAbw"]
[Mon Jul 20 06:45:07.851425 2026] [security2:error] [pid 1014214:tid 1014442] [client 34.73.38.214:65469] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YUwuRBFTcQNywdCINLgAAAfE"]
[Mon Jul 20 06:45:07.853320 2026] [security2:error] [pid 1014214:tid 1014427] [client 57.141.18.122:22606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YTguRBFTcQNywdCILwgAB4nc"]
[Mon Jul 20 06:45:07.878358 2026] [security2:error] [pid 1014214:tid 1014293] [remote 192.241.143.148:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4YUwuRBFTcQNywdCINLwAB9U4"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:45:08.008115 2026] [security2:error] [pid 1014214:tid 1014341] [remote 20.87.239.85:9101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4YUwuRBFTcQNywdCINNgAB034"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 06:45:08.021409 2026] [security2:error] [pid 1011111:tid 1011252] [client 34.139.11.221:51726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YVBXES7Mv0Zfga-kf3gAAAI8"]
[Mon Jul 20 06:45:08.092945 2026] [security2:error] [pid 1014214:tid 1014350] [client 57.141.18.54:55186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YTguRBFTcQNywdCIL0gABlXg"]
[Mon Jul 20 06:45:08.183926 2026] [security2:error] [pid 1011111:tid 1011357] [client 34.139.11.221:58554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YVBXES7Mv0Zfga-kf6gAAAPg"]
[Mon Jul 20 06:45:08.210678 2026] [security2:error] [pid 1011111:tid 1011213] [remote 110.249.201.130:21398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/wp-content/uploads/2023/07/CUR-VERBUM-VERBA-the-essay.pdf"] [unique_id "al4YVBXES7Mv0Zfga-kf7AAA-WQ"]
[Mon Jul 20 06:45:08.320298 2026] [security2:error] [pid 1014214:tid 1014466] [client 14.225.17.146:54341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4YUwuRBFTcQNywdCIM_AAAAgk"], referer: http://nikkidesigns.net/new
[Mon Jul 20 06:45:08.326404 2026] [security2:error] [pid 1011111:tid 1011283] [client 34.139.11.221:61024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YVBXES7Mv0Zfga-kf8wAAAK4"]
[Mon Jul 20 06:45:08.361919 2026] [security2:error] [pid 1014214:tid 1014411] [client 39.48.81.23:56207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YVAuRBFTcQNywdCINQAAAAdI"]
[Mon Jul 20 06:45:08.362073 2026] [security2:error] [pid 1014214:tid 1014411] [client 39.48.81.23:56207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YVAuRBFTcQNywdCINQAAAAdI"]
[Mon Jul 20 06:45:08.393198 2026] [security2:error] [pid 1014214:tid 1014403] [client 171.61.17.42:24885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bbwipartnerconference.com"] [uri "/xmlrpc.php"] [unique_id "al4YUwuRBFTcQNywdCINNQAAAco"]
[Mon Jul 20 06:45:08.469581 2026] [security2:error] [pid 1014214:tid 1014454] [client 34.73.38.214:60369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YVAuRBFTcQNywdCINTgAAAf0"]
[Mon Jul 20 06:45:08.521102 2026] [security2:error] [pid 1014214:tid 1014372] [client 34.139.11.221:62843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YVAuRBFTcQNywdCINUQAAAas"]
[Mon Jul 20 06:45:08.589058 2026] [security2:error] [pid 1014214:tid 1014450] [client 106.219.188.178:25743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YVAuRBFTcQNywdCINVAAAAfk"]
[Mon Jul 20 06:45:08.589673 2026] [security2:error] [pid 1014214:tid 1014450] [client 106.219.188.178:25743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YVAuRBFTcQNywdCINVAAAAfk"]
[Mon Jul 20 06:45:08.715345 2026] [security2:error] [pid 1014214:tid 1014412] [client 34.139.11.221:61376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ial.nce.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YVAuRBFTcQNywdCINXAAAAdM"]
[Mon Jul 20 06:45:08.831842 2026] [security2:error] [pid 1014214:tid 1014423] [client 34.73.38.214:53630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YVAuRBFTcQNywdCINaQAAAd4"]
[Mon Jul 20 06:45:08.844211 2026] [security2:error] [pid 1014214:tid 1014361] [client 57.141.18.116:28148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YTwuRBFTcQNywdCIMAgABoAE"]
[Mon Jul 20 06:45:08.975070 2026] [security2:error] [pid 1011111:tid 1011233] [remote 47.86.33.52:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4YVBXES7Mv0Zfga-kf_AAAxXg"]
[Mon Jul 20 06:45:09.062842 2026] [security2:error] [pid 1014214:tid 1014463] [client 34.73.38.214:50950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.glx.ehd.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YVQuRBFTcQNywdCINbwAAAgY"]
[Mon Jul 20 06:45:09.122254 2026] [security2:error] [pid 1014214:tid 1014438] [client 57.141.18.15:20256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YTwuRBFTcQNywdCIMDwAB7Vc"]
[Mon Jul 20 06:45:09.264852 2026] [security2:error] [pid 1014214:tid 1014397] [client 112.208.70.94:45240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YVQuRBFTcQNywdCINdgAAAcQ"]
[Mon Jul 20 06:45:09.264980 2026] [security2:error] [pid 1014214:tid 1014397] [client 112.208.70.94:45240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YVQuRBFTcQNywdCINdgAAAcQ"]
[Mon Jul 20 06:45:09.360452 2026] [security2:error] [pid 1014214:tid 1014447] [client 34.73.38.214:50208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YVQuRBFTcQNywdCINgAAAAfY"]
[Mon Jul 20 06:45:09.691881 2026] [security2:error] [pid 1014214:tid 1014383] [client 77.110.127.138:54472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVQuRBFTcQNywdCINlAAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:09.691988 2026] [security2:error] [pid 1014214:tid 1014383] [client 77.110.127.138:54472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVQuRBFTcQNywdCINlAAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:09.772005 2026] [security2:error] [pid 1014214:tid 1014381] [client 14.224.227.113:54680] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YVQuRBFTcQNywdCINnAAAAbQ"]
[Mon Jul 20 06:45:09.795790 2026] [security2:error] [pid 1014214:tid 1014416] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4YVQuRBFTcQNywdCINkwAAAdc"]
[Mon Jul 20 06:45:09.893379 2026] [security2:error] [pid 1014214:tid 1014429] [client 50.116.65.227:33910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YVQuRBFTcQNywdCINoQAAAeQ"]
[Mon Jul 20 06:45:09.904446 2026] [security2:error] [pid 1014214:tid 1014355] [client 50.116.65.227:33924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YVQuRBFTcQNywdCINogAAAZo"]
[Mon Jul 20 06:45:10.047261 2026] [security2:error] [pid 1011111:tid 1011272] [client 77.110.127.138:54430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVhXES7Mv0Zfga-kgGQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.047380 2026] [security2:error] [pid 1011111:tid 1011272] [client 77.110.127.138:54430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVhXES7Mv0Zfga-kgGQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.114463 2026] [security2:error] [pid 1014214:tid 1014396] [client 57.141.18.78:38288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YUAuRBFTcQNywdCIMVwABw20"]
[Mon Jul 20 06:45:10.194666 2026] [security2:error] [pid 1011111:tid 1011260] [client 103.125.179.95:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YVhXES7Mv0Zfga-kgHwAAAJc"]
[Mon Jul 20 06:45:10.194856 2026] [security2:error] [pid 1011111:tid 1011260] [client 103.125.179.95:53265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YVhXES7Mv0Zfga-kgHwAAAJc"]
[Mon Jul 20 06:45:10.205808 2026] [security2:error] [pid 1014214:tid 1014436] [client 77.110.127.138:54496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVguRBFTcQNywdCINtgAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.205898 2026] [security2:error] [pid 1014214:tid 1014436] [client 77.110.127.138:54496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVguRBFTcQNywdCINtgAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.226353 2026] [security2:error] [pid 1011111:tid 1011322] [client 223.237.130.40:64904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.130.237.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4YVhXES7Mv0Zfga-kgIQAAANU"]
[Mon Jul 20 06:45:10.227134 2026] [security2:error] [pid 1011111:tid 1011322] [client 223.237.130.40:64904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4YVhXES7Mv0Zfga-kgIQAAANU"]
[Mon Jul 20 06:45:10.243628 2026] [security2:error] [pid 1014214:tid 1014368] [client 65.111.27.133:49913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YVguRBFTcQNywdCINtwAAAac"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:45:10.315180 2026] [security2:error] [pid 1011111:tid 1011336] [client 34.73.38.214:61379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YVhXES7Mv0Zfga-kgJgAAAOM"]
[Mon Jul 20 06:45:10.480222 2026] [security2:error] [pid 1011111:tid 1011313] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YVhXES7Mv0Zfga-kgJAAAAMw"], referer: 1'"3000
[Mon Jul 20 06:45:10.548088 2026] [security2:error] [pid 1014214:tid 1014434] [client 57.141.18.82:28424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YUQuRBFTcQNywdCIMdgAB6QM"]
[Mon Jul 20 06:45:10.830990 2026] [security2:error] [pid 1014214:tid 1014443] [client 57.141.18.49:61986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YUQuRBFTcQNywdCIMhAAB8iI"]
[Mon Jul 20 06:45:10.862262 2026] [security2:error] [pid 1011111:tid 1011307] [client 77.110.127.138:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVhXES7Mv0Zfga-kgNgAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.862391 2026] [security2:error] [pid 1011111:tid 1011307] [client 77.110.127.138:54394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVhXES7Mv0Zfga-kgNgAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.913791 2026] [security2:error] [pid 1014214:tid 1014415] [client 77.110.127.138:54445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVguRBFTcQNywdCIN2wAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.913916 2026] [security2:error] [pid 1014214:tid 1014415] [client 77.110.127.138:54445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVguRBFTcQNywdCIN2wAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:10.930292 2026] [security2:error] [pid 1014214:tid 1014427] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YVguRBFTcQNywdCIN0QAAAeI"], referer: 1'"3000
[Mon Jul 20 06:45:11.062859 2026] [security2:error] [pid 1014214:tid 1014460] [client 77.110.127.138:54516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVwuRBFTcQNywdCIN5gAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:11.062961 2026] [security2:error] [pid 1014214:tid 1014460] [client 77.110.127.138:54516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVwuRBFTcQNywdCIN5gAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:11.151271 2026] [security2:error] [pid 1014214:tid 1014366] [client 183.82.98.154:60426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIN7wAAAaU"]
[Mon Jul 20 06:45:11.151374 2026] [security2:error] [pid 1014214:tid 1014366] [client 183.82.98.154:60426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIN7wAAAaU"]
[Mon Jul 20 06:45:11.166999 2026] [security2:error] [pid 1011111:tid 1011218] [remote 47.86.33.52:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4YVxXES7Mv0Zfga-kgPgAA8mk"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 06:45:11.228883 2026] [security2:error] [pid 1014214:tid 1014438] [client 197.186.66.42:62985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIN9wAAAe0"]
[Mon Jul 20 06:45:11.229934 2026] [security2:error] [pid 1014214:tid 1014438] [client 197.186.66.42:62985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIN9wAAAe0"]
[Mon Jul 20 06:45:11.325964 2026] [security2:error] [pid 1014214:tid 1014361] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YVwuRBFTcQNywdCIN7QAAAaA"], referer: 1'"3000
[Mon Jul 20 06:45:11.357366 2026] [security2:error] [pid 1014214:tid 1014408] [client 103.238.106.162:42728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIOAgAAAc8"]
[Mon Jul 20 06:45:11.357503 2026] [security2:error] [pid 1014214:tid 1014408] [client 103.238.106.162:42728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIOAgAAAc8"]
[Mon Jul 20 06:45:11.512939 2026] [security2:error] [pid 1014214:tid 1014399] [client 77.110.127.138:54359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVwuRBFTcQNywdCIOCwAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:11.513036 2026] [security2:error] [pid 1014214:tid 1014399] [client 77.110.127.138:54359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YVwuRBFTcQNywdCIOCwAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:11.579326 2026] [security2:error] [pid 1011111:tid 1011266] [client 65.111.23.133:14741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vfcthomasville.org"] [uri "/wp-login.php"] [unique_id "al4YVxXES7Mv0Zfga-kgSAAAAJ0"], referer: https://vfcthomasville.org/wp-login.php
[Mon Jul 20 06:45:11.767824 2026] [security2:error] [pid 1014214:tid 1014465] [client 187.108.85.186:54459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIOFAAAAgg"]
[Mon Jul 20 06:45:11.767955 2026] [security2:error] [pid 1014214:tid 1014465] [client 187.108.85.186:54459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YVwuRBFTcQNywdCIOFAAAAgg"]
[Mon Jul 20 06:45:12.024987 2026] [security2:error] [pid 1011111:tid 1011292] [client 217.142.18.172:52059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YWBXES7Mv0Zfga-kgWAAAALc"]
[Mon Jul 20 06:45:12.028889 2026] [security2:error] [pid 1011111:tid 1011292] [client 217.142.18.172:52059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YWBXES7Mv0Zfga-kgWAAAALc"]
[Mon Jul 20 06:45:12.059867 2026] [security2:error] [pid 1014214:tid 1014409] [client 57.141.18.121:24358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YUguRBFTcQNywdCIM0QAB0GY"]
[Mon Jul 20 06:45:12.305741 2026] [access_compat:error] [pid 1014214:tid 1014261] [remote 192.132.138.218:33897] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:45:12.628442 2026] [security2:error] [pid 1011111:tid 1011120] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YWBXES7Mv0Zfga-kgZwAAlgc"]
[Mon Jul 20 06:45:12.628578 2026] [security2:error] [pid 1011111:tid 1011259] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YWBXES7Mv0Zfga-kgZwAAlgc"]
[Mon Jul 20 06:45:12.631774 2026] [security2:error] [pid 1014214:tid 1014465] [client 77.110.127.138:54537] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YWAuRBFTcQNywdCIOQwAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:12.636433 2026] [security2:error] [pid 1014214:tid 1014387] [client 57.141.18.123:57690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YUwuRBFTcQNywdCIM9gABug0"]
[Mon Jul 20 06:45:13.117671 2026] [security2:error] [pid 1011111:tid 1011336] [client 152.58.191.29:57813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YWRXES7Mv0Zfga-kgdgAAAOM"]
[Mon Jul 20 06:45:13.117777 2026] [security2:error] [pid 1011111:tid 1011336] [client 152.58.191.29:57813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YWRXES7Mv0Zfga-kgdgAAAOM"]
[Mon Jul 20 06:45:13.137963 2026] [security2:error] [pid 1014214:tid 1014420] [client 57.141.18.3:21862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YUwuRBFTcQNywdCINCgAB22E"]
[Mon Jul 20 06:45:13.151921 2026] [security2:error] [pid 1014214:tid 1014364] [client 104.234.53.59:60075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YWQuRBFTcQNywdCIOVwAAAaM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:13.219950 2026] [security2:error] [pid 1014214:tid 1014467] [client 171.61.165.146:3978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YWQuRBFTcQNywdCIOWQAAAgo"]
[Mon Jul 20 06:45:13.220069 2026] [security2:error] [pid 1014214:tid 1014467] [client 171.61.165.146:3978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YWQuRBFTcQNywdCIOWQAAAgo"]
[Mon Jul 20 06:45:13.462956 2026] [security2:error] [pid 1014214:tid 1014390] [client 94.154.43.187:59666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-11f1b15e.ctd.ann.mybluehost.me"] [uri "/.env"] [unique_id "al4YWQuRBFTcQNywdCIObQAAAb0"]
[Mon Jul 20 06:45:13.994563 2026] [security2:error] [pid 1014214:tid 1014446] [client 77.110.127.138:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YWQuRBFTcQNywdCIOigAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:13.994658 2026] [security2:error] [pid 1014214:tid 1014446] [client 77.110.127.138:54552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YWQuRBFTcQNywdCIOigAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:45:14.004623 2026] [security2:error] [pid 1014214:tid 1014329] [remote 160.187.68.132:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4YWQuRBFTcQNywdCIOiAAB63I"]
[Mon Jul 20 06:45:14.059469 2026] [security2:error] [pid 1014214:tid 1014267] [remote 57.141.18.22:26702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3696104"] [unique_id "al4YWguRBFTcQNywdCIOjgABvDQ"]
[Mon Jul 20 06:45:14.103792 2026] [security2:error] [pid 1014214:tid 1014465] [client 117.247.108.24:23140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YWguRBFTcQNywdCIOkAAAAgg"]
[Mon Jul 20 06:45:14.103897 2026] [security2:error] [pid 1014214:tid 1014465] [client 117.247.108.24:23140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YWguRBFTcQNywdCIOkAAAAgg"]
[Mon Jul 20 06:45:14.144735 2026] [security2:error] [pid 1014214:tid 1014356] [client 57.141.18.28:51764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVAuRBFTcQNywdCINWAABmwQ"]
[Mon Jul 20 06:45:14.406218 2026] [autoindex:error] [pid 1014214:tid 1014469] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/pro/css/fields/phone/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:14.509807 2026] [security2:error] [pid 1014214:tid 1014215] [remote 160.187.68.132:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4YWguRBFTcQNywdCIOswAB1wA"], referer: https://supportinghands22.org/wp-login.php
[Mon Jul 20 06:45:14.546689 2026] [security2:error] [pid 1014214:tid 1014424] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YWguRBFTcQNywdCIOqQAAAd8"]
[Mon Jul 20 06:45:14.659276 2026] [security2:error] [pid 1014214:tid 1014466] [client 74.7.227.179:38336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4YWguRBFTcQNywdCIOtQACCXQ"], referer: https://tejasenvironmental.com/p=9474
[Mon Jul 20 06:45:14.731384 2026] [security2:error] [pid 1014214:tid 1014413] [client 57.141.18.8:51942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVQuRBFTcQNywdCINcQAB1Bg"]
[Mon Jul 20 06:45:15.190526 2026] [security2:error] [pid 1014214:tid 1014349] [client 57.141.18.62:28882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVQuRBFTcQNywdCINggABlDY"]
[Mon Jul 20 06:45:15.340790 2026] [security2:error] [pid 1014214:tid 1014463] [client 14.225.17.146:55447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4YWQuRBFTcQNywdCIOdgAAAgY"], referer: http://amalia-capital.com/new
[Mon Jul 20 06:45:15.482368 2026] [security2:error] [pid 1011111:tid 1011246] [client 57.141.18.24:42146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVRXES7Mv0Zfga-kgDwAAiQY"]
[Mon Jul 20 06:45:16.010398 2026] [security2:error] [pid 1014214:tid 1014397] [client 14.225.17.146:62646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4YWAuRBFTcQNywdCIOLQAAAcQ"], referer: http://areitoproducciones.com/new
[Mon Jul 20 06:45:16.299887 2026] [security2:error] [pid 1011111:tid 1011269] [client 37.52.210.45:32154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YXBXES7Mv0Zfga-kgtAAAAKA"]
[Mon Jul 20 06:45:16.300023 2026] [security2:error] [pid 1011111:tid 1011269] [client 37.52.210.45:32154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YXBXES7Mv0Zfga-kgtAAAAKA"]
[Mon Jul 20 06:45:16.366480 2026] [security2:error] [pid 1014214:tid 1014371] [client 57.141.18.51:37914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVguRBFTcQNywdCINwAABqik"]
[Mon Jul 20 06:45:16.649656 2026] [security2:error] [pid 1014214:tid 1014467] [client 114.119.133.251:52817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mollycahill.com"] [uri "/wp-content/uploads/2022/05/community-building-on-Instagram-blog-images-1024x1024.jpg"] [unique_id "al4YXAuRBFTcQNywdCIPJgAAAgo"], referer: https://mollycahill.com/instagram-marketing-roadmap/
[Mon Jul 20 06:45:17.229238 2026] [security2:error] [pid 1011111:tid 1011294] [client 57.141.18.8:51952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVxXES7Mv0Zfga-kgQgAAuUs"]
[Mon Jul 20 06:45:17.586088 2026] [security2:error] [pid 1014214:tid 1014337] [remote 152.228.213.32:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4YXQuRBFTcQNywdCIPWgABxno"]
[Mon Jul 20 06:45:17.639075 2026] [security2:error] [pid 1011111:tid 1011290] [client 57.141.18.20:49150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YVxXES7Mv0Zfga-kgTgAAtVg"]
[Mon Jul 20 06:45:17.697802 2026] [security2:error] [pid 1014214:tid 1014372] [client 37.27.59.176:24432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.59.27.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/how-to-obtain-bonds/howto.php"] [unique_id "al4YXQuRBFTcQNywdCIPYgAAAas"]
[Mon Jul 20 06:45:17.789707 2026] [security2:error] [pid 1014214:tid 1014296] [remote 152.228.213.32:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4YXQuRBFTcQNywdCIPZQAB51E"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:45:18.260261 2026] [security2:error] [pid 1011111:tid 1011260] [client 223.185.13.213:21028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YXhXES7Mv0Zfga-kg4wAAAJc"]
[Mon Jul 20 06:45:18.260377 2026] [security2:error] [pid 1011111:tid 1011260] [client 223.185.13.213:21028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YXhXES7Mv0Zfga-kg4wAAAJc"]
[Mon Jul 20 06:45:18.444571 2026] [security2:error] [pid 1014214:tid 1014424] [client 39.48.81.23:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YXguRBFTcQNywdCIPhgAAAd8"]
[Mon Jul 20 06:45:18.444755 2026] [security2:error] [pid 1014214:tid 1014424] [client 39.48.81.23:56725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YXguRBFTcQNywdCIPhgAAAd8"]
[Mon Jul 20 06:45:18.973758 2026] [security2:error] [pid 1014214:tid 1014408] [client 192.140.149.97:45087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YXguRBFTcQNywdCIPpQAAAc8"]
[Mon Jul 20 06:45:18.973912 2026] [security2:error] [pid 1014214:tid 1014408] [client 192.140.149.97:45087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YXguRBFTcQNywdCIPpQAAAc8"]
[Mon Jul 20 06:45:19.155048 2026] [security2:error] [pid 1011111:tid 1011293] [client 106.219.188.178:40961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YXxXES7Mv0Zfga-khBgAAALg"]
[Mon Jul 20 06:45:19.155156 2026] [security2:error] [pid 1011111:tid 1011293] [client 106.219.188.178:40961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YXxXES7Mv0Zfga-khBgAAALg"]
[Mon Jul 20 06:45:19.164166 2026] [security2:error] [pid 1014214:tid 1014448] [client 220.181.108.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4YXwuRBFTcQNywdCIPqQAAAfc"]
[Mon Jul 20 06:45:19.314412 2026] [security2:error] [pid 1011111:tid 1011362] [client 104.234.53.47:27303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YXxXES7Mv0Zfga-khCAAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:19.374178 2026] [security2:error] [pid 1014214:tid 1014225] [remote 68.178.160.25:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YXwuRBFTcQNywdCIPtwABvgo"]
[Mon Jul 20 06:45:19.514537 2026] [security2:error] [pid 1014214:tid 1014349] [client 74.208.214.194:38582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4YXwuRBFTcQNywdCIPwgAAAZQ"]
[Mon Jul 20 06:45:19.770392 2026] [security2:error] [pid 1014214:tid 1014304] [remote 68.178.160.25:45424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YXwuRBFTcQNywdCIP0gABrVk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:45:19.855046 2026] [security2:error] [pid 1014214:tid 1014444] [client 112.208.70.94:45670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YXwuRBFTcQNywdCIP2AAAAfM"]
[Mon Jul 20 06:45:19.855198 2026] [security2:error] [pid 1014214:tid 1014444] [client 112.208.70.94:45670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YXwuRBFTcQNywdCIP2AAAAfM"]
[Mon Jul 20 06:45:19.885903 2026] [security2:error] [pid 1014214:tid 1014239] [remote 97.74.93.24:37076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YXwuRBFTcQNywdCIP3QAB4hg"]
[Mon Jul 20 06:45:20.043793 2026] [security2:error] [pid 1011111:tid 1011285] [client 1.55.194.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4YXxXES7Mv0Zfga-khDAAAsCo"], referer: https://packerjanitorial.com
[Mon Jul 20 06:45:20.194731 2026] [security2:error] [pid 1011111:tid 1011329] [client 57.141.18.103:59438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YWhXES7Mv0Zfga-kgmAAA3D8"]
[Mon Jul 20 06:45:20.249210 2026] [access_compat:error] [pid 1014214:tid 1014221] [remote 64.51.4.197:34911] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:45:20.261016 2026] [security2:error] [pid 1014214:tid 1014231] [remote 97.74.93.24:37076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YYAuRBFTcQNywdCIP-QACABA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:45:20.295357 2026] [security2:error] [pid 1011111:tid 1011274] [client 104.207.63.156:34155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YYBXES7Mv0Zfga-khFQAAAKU"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:20.739101 2026] [security2:error] [pid 1014214:tid 1014430] [client 57.141.18.1:28154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YWguRBFTcQNywdCIOxAAB5R0"]
[Mon Jul 20 06:45:20.931524 2026] [security2:error] [pid 1014214:tid 1014377] [client 103.180.163.59:42926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4YYAuRBFTcQNywdCIQFQABsDc"]
[Mon Jul 20 06:45:21.025042 2026] [security2:error] [pid 1011111:tid 1011354] [client 74.249.226.166:33538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YYRXES7Mv0Zfga-khIwAAAPU"]
[Mon Jul 20 06:45:21.034953 2026] [security2:error] [pid 1014214:tid 1014387] [client 103.125.179.95:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YYQuRBFTcQNywdCIQHQAAAbo"]
[Mon Jul 20 06:45:21.035066 2026] [security2:error] [pid 1014214:tid 1014387] [client 103.125.179.95:53773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YYQuRBFTcQNywdCIQHQAAAbo"]
[Mon Jul 20 06:45:21.076666 2026] [security2:error] [pid 1011111:tid 1011360] [client 74.249.226.166:33538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YYRXES7Mv0Zfga-khJgAAAPs"]
[Mon Jul 20 06:45:21.158530 2026] [security2:error] [pid 1011111:tid 1011336] [client 45.3.32.51:48033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YYRXES7Mv0Zfga-khKAAAAOM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:21.215418 2026] [security2:error] [pid 1014214:tid 1014394] [client 57.141.18.53:33018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YWwuRBFTcQNywdCIO4QABwRE"]
[Mon Jul 20 06:45:21.791330 2026] [security2:error] [pid 1014214:tid 1014375] [client 13.233.207.33:30642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YYQuRBFTcQNywdCIQPQAAAa4"]
[Mon Jul 20 06:45:21.869899 2026] [security2:error] [pid 1014214:tid 1014362] [client 103.238.106.162:42951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YYQuRBFTcQNywdCIQQAAAAaE"]
[Mon Jul 20 06:45:21.869987 2026] [security2:error] [pid 1014214:tid 1014362] [client 103.238.106.162:42951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YYQuRBFTcQNywdCIQQAAAAaE"]
[Mon Jul 20 06:45:21.939119 2026] [security2:error] [pid 1014214:tid 1014455] [client 183.82.98.154:61000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YYQuRBFTcQNywdCIQSwAAAf4"]
[Mon Jul 20 06:45:21.939261 2026] [security2:error] [pid 1014214:tid 1014455] [client 183.82.98.154:61000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YYQuRBFTcQNywdCIQSwAAAf4"]
[Mon Jul 20 06:45:21.979516 2026] [security2:error] [pid 1011111:tid 1011275] [client 104.207.32.147:20931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YYRXES7Mv0Zfga-khOwAAAKY"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:22.038302 2026] [security2:error] [pid 1014214:tid 1014280] [remote 216.73.217.138:3000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4YYguRBFTcQNywdCIQVAABzUE"]
[Mon Jul 20 06:45:22.185084 2026] [security2:error] [pid 1014214:tid 1014346] [client 52.109.76.144:37509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YYguRBFTcQNywdCIQXgAAAZE"]
[Mon Jul 20 06:45:22.306330 2026] [security2:error] [pid 1014214:tid 1014400] [client 187.108.85.186:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YYguRBFTcQNywdCIQYwAAAcc"]
[Mon Jul 20 06:45:22.306429 2026] [security2:error] [pid 1014214:tid 1014400] [client 187.108.85.186:54992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YYguRBFTcQNywdCIQYwAAAcc"]
[Mon Jul 20 06:45:22.326004 2026] [security2:error] [pid 1014214:tid 1014411] [client 52.109.76.144:37509] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YYguRBFTcQNywdCIQZgAAAdI"]
[Mon Jul 20 06:45:22.633496 2026] [security2:error] [pid 1011111:tid 1011295] [client 217.142.18.172:53311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YYhXES7Mv0Zfga-khRQAAALo"]
[Mon Jul 20 06:45:22.633614 2026] [security2:error] [pid 1011111:tid 1011295] [client 217.142.18.172:53311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YYhXES7Mv0Zfga-khRQAAALo"]
[Mon Jul 20 06:45:22.826115 2026] [security2:error] [pid 1014214:tid 1014378] [client 43.205.139.3:50346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YYguRBFTcQNywdCIQeQAAAbE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:45:22.989327 2026] [security2:error] [pid 1014214:tid 1014455] [client 65.1.132.125:28824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YYguRBFTcQNywdCIQhgAAAf4"]
[Mon Jul 20 06:45:23.026715 2026] [security2:error] [pid 1014214:tid 1014412] [client 57.141.18.37:20862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YXQuRBFTcQNywdCIPXAAB00w"]
[Mon Jul 20 06:45:23.147269 2026] [security2:error] [pid 1011111:tid 1011264] [client 57.141.18.7:61968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YXRXES7Mv0Zfga-kg1AAAmwk"]
[Mon Jul 20 06:45:23.375247 2026] [security2:error] [pid 1014214:tid 1014318] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YYwuRBFTcQNywdCIQmAACAGc"]
[Mon Jul 20 06:45:23.375454 2026] [security2:error] [pid 1014214:tid 1014457] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YYwuRBFTcQNywdCIQmAACAGc"]
[Mon Jul 20 06:45:23.551284 2026] [security2:error] [pid 1014214:tid 1014360] [client 57.141.18.124:31134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YXguRBFTcQNywdCIPcwABn08"]
[Mon Jul 20 06:45:23.724155 2026] [security2:error] [pid 1014214:tid 1014325] [remote 5.252.52.249:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YYwuRBFTcQNywdCIQqwAB0G4"]
[Mon Jul 20 06:45:23.854581 2026] [security2:error] [pid 1011111:tid 1011278] [client 3.67.192.83:32192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YYxXES7Mv0Zfga-khXwAAAKk"]
[Mon Jul 20 06:45:23.988339 2026] [security2:error] [pid 1011111:tid 1011243] [client 65.1.132.125:28830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YYxXES7Mv0Zfga-khbAAAAIY"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:45:23.993502 2026] [security2:error] [pid 1014214:tid 1014438] [client 152.58.191.29:58305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YYwuRBFTcQNywdCIQvwAAAe0"]
[Mon Jul 20 06:45:23.993616 2026] [security2:error] [pid 1014214:tid 1014438] [client 152.58.191.29:58305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YYwuRBFTcQNywdCIQvwAAAe0"]
[Mon Jul 20 06:45:23.998049 2026] [security2:error] [pid 1014214:tid 1014333] [remote 5.252.52.249:53596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4YYwuRBFTcQNywdCIQwQACAHY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 06:45:24.040452 2026] [security2:error] [pid 1014214:tid 1014407] [client 104.243.196.57:39920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4YYwuRBFTcQNywdCIQswABziM"]
[Mon Jul 20 06:45:24.192978 2026] [security2:error] [pid 1014214:tid 1014446] [client 54.169.146.187:34744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cryptomeaning.com"] [uri "/cryptocurrency/"] [unique_id "al4YZAuRBFTcQNywdCIQygAAAfU"], referer: https://cryptomeaning.com/category/bitcoin/
[Mon Jul 20 06:45:24.311195 2026] [security2:error] [pid 1011111:tid 1011326] [client 171.61.165.146:31325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YZBXES7Mv0Zfga-khcQAAANk"]
[Mon Jul 20 06:45:24.311304 2026] [security2:error] [pid 1011111:tid 1011326] [client 171.61.165.146:31325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YZBXES7Mv0Zfga-khcQAAANk"]
[Mon Jul 20 06:45:24.313400 2026] [security2:error] [pid 1014214:tid 1014236] [remote 81.173.115.7:50354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQzgABjxU"]
[Mon Jul 20 06:45:24.313571 2026] [security2:error] [pid 1014214:tid 1014344] [client 81.173.115.7:50354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQzgABjxU"]
[Mon Jul 20 06:45:24.512384 2026] [security2:error] [pid 1014214:tid 1014383] [client 3.67.192.83:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YZAuRBFTcQNywdCIQ2gAAAbY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:45:24.571745 2026] [security2:error] [pid 1011111:tid 1011367] [client 57.141.18.47:53802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YXxXES7Mv0Zfga-khBQABAkM"]
[Mon Jul 20 06:45:24.580180 2026] [security2:error] [pid 1014214:tid 1014462] [client 197.186.66.42:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQ4AAAAgU"]
[Mon Jul 20 06:45:24.580284 2026] [security2:error] [pid 1014214:tid 1014462] [client 197.186.66.42:63548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQ4AAAAgU"]
[Mon Jul 20 06:45:24.607520 2026] [security2:error] [pid 1014214:tid 1014467] [client 193.37.252.163:57230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQ4QAAAgo"]
[Mon Jul 20 06:45:24.607649 2026] [security2:error] [pid 1014214:tid 1014467] [client 193.37.252.163:57230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQ4QAAAgo"]
[Mon Jul 20 06:45:24.908269 2026] [security2:error] [pid 1014214:tid 1014373] [client 117.247.108.24:64224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQ7QAAAaw"]
[Mon Jul 20 06:45:24.908376 2026] [security2:error] [pid 1014214:tid 1014373] [client 117.247.108.24:64224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YZAuRBFTcQNywdCIQ7QAAAaw"]
[Mon Jul 20 06:45:24.963267 2026] [security2:error] [pid 1014214:tid 1014322] [remote 57.141.18.59:39608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5178086"] [unique_id "al4YZAuRBFTcQNywdCIQ8AABp2s"]
[Mon Jul 20 06:45:25.168041 2026] [security2:error] [pid 1011111:tid 1011264] [client 14.224.227.113:54682] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YZRXES7Mv0Zfga-khpgAAAJs"]
[Mon Jul 20 06:45:25.335857 2026] [security2:error] [pid 1014214:tid 1014406] [client 136.108.37.179:62353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4YZQuRBFTcQNywdCIQ_QAAAc0"]
[Mon Jul 20 06:45:25.405446 2026] [security2:error] [pid 1014214:tid 1014435] [client 136.108.37.179:62353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/xmlrpc.php"] [unique_id "al4YZQuRBFTcQNywdCIRAQAAAeo"]
[Mon Jul 20 06:45:25.530868 2026] [security2:error] [pid 1014214:tid 1014237] [remote 97.74.93.24:41730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YZQuRBFTcQNywdCIRDQAB2xY"]
[Mon Jul 20 06:45:25.579190 2026] [security2:error] [pid 1014214:tid 1014352] [client 143.47.54.170:50974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4YZQuRBFTcQNywdCIRBQABlw8"]
[Mon Jul 20 06:45:25.635827 2026] [security2:error] [pid 1014214:tid 1014351] [client 57.141.18.22:59968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYAuRBFTcQNywdCIP_QABllc"]
[Mon Jul 20 06:45:25.642620 2026] [security2:error] [pid 1014214:tid 1014429] [client 136.108.37.179:50215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YZQuRBFTcQNywdCIRGwAAAeQ"]
[Mon Jul 20 06:45:25.914277 2026] [security2:error] [pid 1014214:tid 1014244] [remote 78.46.157.202:54576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YZQuRBFTcQNywdCIRLAABvh0"]
[Mon Jul 20 06:45:25.914412 2026] [security2:error] [pid 1014214:tid 1014391] [client 78.46.157.202:54576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YZQuRBFTcQNywdCIRLAABvh0"]
[Mon Jul 20 06:45:25.954216 2026] [security2:error] [pid 1014214:tid 1014338] [remote 97.74.93.24:41730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YZQuRBFTcQNywdCIRMAABtns"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:45:25.968496 2026] [security2:error] [pid 1014214:tid 1014405] [client 136.108.37.179:58482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YZQuRBFTcQNywdCIRMQAAAcw"]
[Mon Jul 20 06:45:26.105339 2026] [security2:error] [pid 1011111:tid 1011270] [client 134.209.23.115:51677] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.techtradeinc.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4YZhXES7Mv0Zfga-khyQAAAKE"]
[Mon Jul 20 06:45:26.327412 2026] [security2:error] [pid 1014214:tid 1014461] [client 136.108.37.179:64719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YZguRBFTcQNywdCIRPwAAAgQ"]
[Mon Jul 20 06:45:26.416131 2026] [security2:error] [pid 1014214:tid 1014253] [remote 100.42.189.89:60334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4YZguRBFTcQNywdCIRQwAB8iY"]
[Mon Jul 20 06:45:26.563910 2026] [security2:error] [pid 1011111:tid 1011269] [client 57.141.18.42:39770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYRXES7Mv0Zfga-khJwAAoCc"]
[Mon Jul 20 06:45:26.613607 2026] [security2:error] [pid 1014214:tid 1014395] [client 136.108.37.179:62133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YZguRBFTcQNywdCIRTQAAAcI"]
[Mon Jul 20 06:45:26.618203 2026] [security2:error] [pid 1014214:tid 1014247] [remote 100.42.189.89:60334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4YZguRBFTcQNywdCIRTgAB2iA"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:45:26.914646 2026] [security2:error] [pid 1014214:tid 1014455] [client 37.52.210.45:57264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YZguRBFTcQNywdCIRZgAAAf4"]
[Mon Jul 20 06:45:26.914823 2026] [security2:error] [pid 1014214:tid 1014455] [client 37.52.210.45:57264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YZguRBFTcQNywdCIRZgAAAf4"]
[Mon Jul 20 06:45:26.939161 2026] [security2:error] [pid 1014214:tid 1014397] [client 136.108.37.179:51545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YZguRBFTcQNywdCIRagAAAcQ"]
[Mon Jul 20 06:45:27.056280 2026] [security2:error] [pid 1014214:tid 1014451] [client 57.141.18.43:38138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYQuRBFTcQNywdCIQPAAB-io"]
[Mon Jul 20 06:45:27.219472 2026] [security2:error] [pid 1014214:tid 1014373] [client 136.108.37.179:57334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YZwuRBFTcQNywdCIRewAAAaw"]
[Mon Jul 20 06:45:27.494097 2026] [security2:error] [pid 1014214:tid 1014379] [client 136.108.37.179:52137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YZwuRBFTcQNywdCIRigAAAbI"]
[Mon Jul 20 06:45:27.704360 2026] [security2:error] [pid 1014214:tid 1014416] [client 57.141.18.20:65298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYguRBFTcQNywdCIQawAB1z0"]
[Mon Jul 20 06:45:27.844982 2026] [security2:error] [pid 1014214:tid 1014397] [client 136.108.37.179:57194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YZwuRBFTcQNywdCIRmQAAAcQ"]
[Mon Jul 20 06:45:27.849621 2026] [security2:error] [pid 1014214:tid 1014399] [client 223.185.13.213:22272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YZwuRBFTcQNywdCIRmgAAAcY"]
[Mon Jul 20 06:45:27.849733 2026] [security2:error] [pid 1014214:tid 1014399] [client 223.185.13.213:22272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YZwuRBFTcQNywdCIRmgAAAcY"]
[Mon Jul 20 06:45:27.993450 2026] [security2:error] [pid 1014214:tid 1014463] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YZwuRBFTcQNywdCIRmwAAAgY"]
[Mon Jul 20 06:45:28.050141 2026] [security2:error] [pid 1011111:tid 1011252] [client 144.48.163.45:49838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.marscafe.com"] [uri "/php/food-safety-dl/download.php"] [unique_id "al4YZxXES7Mv0Zfga-kh6wAAAI8"]
[Mon Jul 20 06:45:28.153158 2026] [security2:error] [pid 1011111:tid 1011334] [client 136.108.37.179:64541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "allergyantidotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YaBXES7Mv0Zfga-kh_AAAAOE"]
[Mon Jul 20 06:45:28.436826 2026] [security2:error] [pid 1011111:tid 1011320] [client 57.141.18.24:42564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYxXES7Mv0Zfga-khUQAA01E"]
[Mon Jul 20 06:45:28.610553 2026] [security2:error] [pid 1014214:tid 1014277] [remote 57.141.18.33:63932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2747253"] [unique_id "al4YaAuRBFTcQNywdCIRvwAB2T4"]
[Mon Jul 20 06:45:28.763302 2026] [security2:error] [pid 1014214:tid 1014423] [client 57.141.18.46:39640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYwuRBFTcQNywdCIQmgAB3iE"]
[Mon Jul 20 06:45:28.889280 2026] [security2:error] [pid 1014214:tid 1014410] [client 18.141.57.241:49312] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "cryptomeaning.com"] [uri "/wp-comments-post.php"] [unique_id "al4YaAuRBFTcQNywdCIRzQAAAdE"]
[Mon Jul 20 06:45:29.058736 2026] [security2:error] [pid 1014214:tid 1014285] [remote 57.141.18.12:31980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6120407"] [unique_id "al4YaQuRBFTcQNywdCIR1gABlkY"]
[Mon Jul 20 06:45:29.126135 2026] [security2:error] [pid 1011111:tid 1011244] [client 57.141.18.125:51298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YYxXES7Mv0Zfga-khWQAAh3M"]
[Mon Jul 20 06:45:29.170260 2026] [security2:error] [pid 1014214:tid 1014375] [client 39.48.81.23:57252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YaQuRBFTcQNywdCIR2wAAAa4"]
[Mon Jul 20 06:45:29.174610 2026] [security2:error] [pid 1014214:tid 1014375] [client 39.48.81.23:57252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YaQuRBFTcQNywdCIR2wAAAa4"]
[Mon Jul 20 06:45:29.282679 2026] [security2:error] [pid 1014214:tid 1014238] [remote 84.247.172.23:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YaQuRBFTcQNywdCIR4AABpxc"]
[Mon Jul 20 06:45:29.561575 2026] [security2:error] [pid 1014214:tid 1014236] [remote 84.247.172.23:57510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YaQuRBFTcQNywdCIR6gABuRU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:45:29.585622 2026] [security2:error] [pid 1014214:tid 1014419] [client 106.219.188.178:8604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YaQuRBFTcQNywdCIR7AAAAdo"]
[Mon Jul 20 06:45:29.594126 2026] [security2:error] [pid 1014214:tid 1014419] [client 106.219.188.178:8604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YaQuRBFTcQNywdCIR7AAAAdo"]
[Mon Jul 20 06:45:29.703489 2026] [security2:error] [pid 1014214:tid 1014405] [client 192.140.149.97:44472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YaQuRBFTcQNywdCIR8AAAAcw"]
[Mon Jul 20 06:45:29.703639 2026] [security2:error] [pid 1014214:tid 1014405] [client 192.140.149.97:44472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YaQuRBFTcQNywdCIR8AAAAcw"]
[Mon Jul 20 06:45:29.805930 2026] [security2:error] [pid 1011111:tid 1011263] [client 57.141.18.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YaRXES7Mv0Zfga-kiKwAAAJo"]
[Mon Jul 20 06:45:30.067150 2026] [security2:error] [pid 1011111:tid 1011340] [client 57.141.18.99:51822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZBXES7Mv0Zfga-khewAA52c"]
[Mon Jul 20 06:45:30.099571 2026] [security2:error] [pid 1014214:tid 1014341] [remote 152.228.213.32:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YaguRBFTcQNywdCISAQABqX4"]
[Mon Jul 20 06:45:30.158789 2026] [security2:error] [pid 1011111:tid 1011275] [client 114.119.139.19:46139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "phillipbloch.com"] [uri "/robots.txt"] [unique_id "al4YahXES7Mv0Zfga-kiOAAAAKY"], referer: https://phillipbloch.com/robots.txt
[Mon Jul 20 06:45:30.294693 2026] [security2:error] [pid 1014214:tid 1014331] [remote 152.228.213.32:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YaguRBFTcQNywdCISCQACCnQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:45:30.350105 2026] [security2:error] [pid 1011111:tid 1011313] [client 112.208.70.94:42053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YahXES7Mv0Zfga-kiQAAAAMw"]
[Mon Jul 20 06:45:30.350220 2026] [security2:error] [pid 1011111:tid 1011313] [client 112.208.70.94:42053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YahXES7Mv0Zfga-kiQAAAAMw"]
[Mon Jul 20 06:45:30.351912 2026] [security2:error] [pid 1014214:tid 1014457] [client 57.141.18.29:31980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZAuRBFTcQNywdCIQ6AACAHc"]
[Mon Jul 20 06:45:30.381506 2026] [security2:error] [pid 1014214:tid 1014328] [remote 57.141.18.101:64220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2950356"] [unique_id "al4YaguRBFTcQNywdCISEwABkHE"]
[Mon Jul 20 06:45:30.522946 2026] [security2:error] [pid 1014214:tid 1014231] [remote 72.167.132.114:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4YaguRBFTcQNywdCISFwABrxA"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:45:30.704231 2026] [security2:error] [pid 1014214:tid 1014450] [client 50.116.65.227:51364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YaguRBFTcQNywdCISIQAAAfk"]
[Mon Jul 20 06:45:30.710332 2026] [access_compat:error] [pid 1014214:tid 1014230] [remote 3.82.46.75:57138] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 06:45:30.712866 2026] [security2:error] [pid 1014214:tid 1014428] [client 50.116.65.227:51380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YaguRBFTcQNywdCISIwAAAeM"]
[Mon Jul 20 06:45:30.745660 2026] [security2:error] [pid 1014214:tid 1014366] [client 57.141.18.92:31234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZQuRBFTcQNywdCIQ_gABpTo"]
[Mon Jul 20 06:45:31.089328 2026] [security2:error] [pid 1014214:tid 1014223] [remote 72.167.132.114:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4YawuRBFTcQNywdCISMQABjwg"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:45:31.198135 2026] [security2:error] [pid 1011111:tid 1011239] [remote 47.86.33.52:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YaxXES7Mv0Zfga-kiWAAAjH4"]
[Mon Jul 20 06:45:31.313545 2026] [security2:error] [pid 1014214:tid 1014414] [client 14.225.17.146:57066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4YawuRBFTcQNywdCISNQAAAdU"], referer: http://lutheranphilosopher.com/New
[Mon Jul 20 06:45:31.313866 2026] [security2:error] [pid 1014214:tid 1014279] [remote 82.112.255.5:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.255.112.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YawuRBFTcQNywdCISQQAB6EA"]
[Mon Jul 20 06:45:31.314030 2026] [security2:error] [pid 1014214:tid 1014433] [client 82.112.255.5:54706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YawuRBFTcQNywdCISQQAB6EA"]
[Mon Jul 20 06:45:31.464816 2026] [security2:error] [pid 1014214:tid 1014380] [client 122.183.32.225:1520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YawuRBFTcQNywdCISTwAAAbM"]
[Mon Jul 20 06:45:31.464936 2026] [security2:error] [pid 1014214:tid 1014380] [client 122.183.32.225:1520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YawuRBFTcQNywdCISTwAAAbM"]
[Mon Jul 20 06:45:31.564796 2026] [security2:error] [pid 1014214:tid 1014232] [remote 47.86.33.52:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4YawuRBFTcQNywdCISWQABuBE"]
[Mon Jul 20 06:45:31.633899 2026] [security2:error] [pid 1014214:tid 1014349] [client 57.141.18.104:30418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZguRBFTcQNywdCIRQAABlBo"]
[Mon Jul 20 06:45:31.853761 2026] [security2:error] [pid 1011111:tid 1011130] [remote 47.86.33.52:16354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YaxXES7Mv0Zfga-kiYAAA6RE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:45:31.989548 2026] [security2:error] [pid 1014214:tid 1014377] [client 57.141.18.80:49124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZguRBFTcQNywdCIRVgABsCU"]
[Mon Jul 20 06:45:32.013394 2026] [security2:error] [pid 1014214:tid 1014388] [client 103.125.179.95:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YbAuRBFTcQNywdCISbQAAAbs"]
[Mon Jul 20 06:45:32.013505 2026] [security2:error] [pid 1014214:tid 1014388] [client 103.125.179.95:54280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YbAuRBFTcQNywdCISbQAAAbs"]
[Mon Jul 20 06:45:32.032731 2026] [security2:error] [pid 1014214:tid 1014467] [client 104.207.59.221:18707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YawuRBFTcQNywdCISawAAAgo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:32.215955 2026] [security2:error] [pid 1014214:tid 1014278] [remote 130.51.180.8:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YbAuRBFTcQNywdCISdgAByz8"]
[Mon Jul 20 06:45:32.252502 2026] [security2:error] [pid 1014214:tid 1014257] [remote 57.141.18.39:59565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4YbAuRBFTcQNywdCISeAACASo"]
[Mon Jul 20 06:45:32.385007 2026] [security2:error] [pid 1014214:tid 1014263] [remote 130.51.180.8:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YbAuRBFTcQNywdCISfwAB2zA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:45:32.385140 2026] [security2:error] [pid 1014214:tid 1014410] [client 18.141.57.241:49312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "cryptomeaning.com"] [uri "/wp-comments-post.php"] [unique_id "al4YaAuRBFTcQNywdCIRzQAAAdE"]
[Mon Jul 20 06:45:32.385200 2026] [security2:error] [pid 1014214:tid 1014410] [client 18.141.57.241:49312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cryptomeaning.com"] [uri "/wp-comments-post.php"] [unique_id "al4YaAuRBFTcQNywdCIRzQAAAdE"]
[Mon Jul 20 06:45:32.401162 2026] [security2:error] [pid 1011111:tid 1011263] [client 103.238.106.162:42775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YbBXES7Mv0Zfga-kicQAAAJo"]
[Mon Jul 20 06:45:32.401316 2026] [security2:error] [pid 1011111:tid 1011263] [client 103.238.106.162:42775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YbBXES7Mv0Zfga-kicQAAAJo"]
[Mon Jul 20 06:45:32.403525 2026] [security2:error] [pid 1014214:tid 1014432] [client 57.141.18.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YbAuRBFTcQNywdCISegAAAec"]
[Mon Jul 20 06:45:32.484273 2026] [security2:error] [pid 1011111:tid 1011334] [client 104.234.53.80:23123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YbBXES7Mv0Zfga-kidAAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:32.505352 2026] [security2:error] [pid 1011111:tid 1011298] [client 57.141.18.113:36144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZxXES7Mv0Zfga-kh6QAAvWs"]
[Mon Jul 20 06:45:32.567712 2026] [security2:error] [pid 1014214:tid 1014443] [client 183.82.98.154:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YbAuRBFTcQNywdCISiQAAAfI"]
[Mon Jul 20 06:45:32.567830 2026] [security2:error] [pid 1014214:tid 1014443] [client 183.82.98.154:61582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YbAuRBFTcQNywdCISiQAAAfI"]
[Mon Jul 20 06:45:32.568302 2026] [security2:error] [pid 1014214:tid 1014222] [remote 47.86.33.52:7620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4YbAuRBFTcQNywdCIShgABxgc"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 06:45:32.587596 2026] [security2:error] [pid 1014214:tid 1014407] [client 57.141.18.109:24382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZwuRBFTcQNywdCIRfgABzkE"]
[Mon Jul 20 06:45:32.606745 2026] [security2:error] [pid 1014214:tid 1014383] [client 14.225.17.146:57451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4YawuRBFTcQNywdCISOwAAAbY"], referer: http://scott-assist.com/New
[Mon Jul 20 06:45:32.635273 2026] [access_compat:error] [pid 1014214:tid 1014275] [remote 151.145.91.139:40944] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:45:32.846467 2026] [security2:error] [pid 1014214:tid 1014452] [client 45.3.50.138:59217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.50.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YbAuRBFTcQNywdCISjgAAAfs"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:32.972029 2026] [security2:error] [pid 1011111:tid 1011181] [remote 110.249.202.243:41964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/"] [unique_id "al4YbBXES7Mv0Zfga-kiigAAoEQ"]
[Mon Jul 20 06:45:32.985139 2026] [security2:error] [pid 1014214:tid 1014371] [client 57.141.18.60:44830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YZwuRBFTcQNywdCIRnQABqno"]
[Mon Jul 20 06:45:33.072572 2026] [security2:error] [pid 1011111:tid 1011294] [client 217.142.18.172:52800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YbRXES7Mv0Zfga-kijwAAALk"]
[Mon Jul 20 06:45:33.078456 2026] [security2:error] [pid 1011111:tid 1011319] [client 187.108.85.186:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YbRXES7Mv0Zfga-kikAAAANI"]
[Mon Jul 20 06:45:33.078546 2026] [security2:error] [pid 1011111:tid 1011319] [client 187.108.85.186:55542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YbRXES7Mv0Zfga-kikAAAANI"]
[Mon Jul 20 06:45:33.080118 2026] [security2:error] [pid 1011111:tid 1011294] [client 217.142.18.172:52800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YbRXES7Mv0Zfga-kijwAAALk"]
[Mon Jul 20 06:45:33.235078 2026] [security2:error] [pid 1011111:tid 1011311] [client 192.132.136.39:17107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YbRXES7Mv0Zfga-kikwAAyjc"]
[Mon Jul 20 06:45:33.489884 2026] [security2:error] [pid 1011111:tid 1011258] [client 52.167.144.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.phillipbloch.com"] [uri "/index.php"] [unique_id "al4YbRXES7Mv0Zfga-kimQAAAJU"]
[Mon Jul 20 06:45:33.662277 2026] [security2:error] [pid 1011111:tid 1011264] [client 52.187.75.220:17409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YbRXES7Mv0Zfga-kiogAAAJs"]
[Mon Jul 20 06:45:33.844232 2026] [security2:error] [pid 1011111:tid 1011267] [client 52.187.75.220:17409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YbRXES7Mv0Zfga-kiqAAAAJ4"]
[Mon Jul 20 06:45:34.049583 2026] [security2:error] [pid 1014214:tid 1014248] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YbguRBFTcQNywdCIS3QACAyE"]
[Mon Jul 20 06:45:34.049771 2026] [security2:error] [pid 1014214:tid 1014460] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YbguRBFTcQNywdCIS3QACAyE"]
[Mon Jul 20 06:45:34.163818 2026] [security2:error] [pid 1011111:tid 1011281] [client 57.141.18.72:46088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YaRXES7Mv0Zfga-kiFwAArGg"]
[Mon Jul 20 06:45:34.862700 2026] [security2:error] [pid 1011111:tid 1011329] [client 152.58.191.29:58779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YbhXES7Mv0Zfga-kiwQAAANw"]
[Mon Jul 20 06:45:34.862846 2026] [security2:error] [pid 1011111:tid 1011329] [client 152.58.191.29:58779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YbhXES7Mv0Zfga-kiwQAAANw"]
[Mon Jul 20 06:45:35.198666 2026] [security2:error] [pid 1014214:tid 1014424] [client 171.61.165.146:7837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YbwuRBFTcQNywdCITEAAAAd8"]
[Mon Jul 20 06:45:35.198775 2026] [security2:error] [pid 1014214:tid 1014424] [client 171.61.165.146:7837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YbwuRBFTcQNywdCITEAAAAd8"]
[Mon Jul 20 06:45:35.449220 2026] [security2:error] [pid 1014214:tid 1014373] [client 158.173.166.181:20407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YbwuRBFTcQNywdCITFwAAAaw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:45:35.581045 2026] [security2:error] [pid 1014214:tid 1014465] [client 172.200.24.58:29378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YbwuRBFTcQNywdCITHwAAAgg"]
[Mon Jul 20 06:45:35.642595 2026] [security2:error] [pid 1014214:tid 1014376] [client 172.200.24.58:29378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YbwuRBFTcQNywdCITIQAAAa8"]
[Mon Jul 20 06:45:35.765948 2026] [security2:error] [pid 1014214:tid 1014441] [client 14.225.17.146:56801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4YbQuRBFTcQNywdCISzQAAAfA"], referer: http://webgardensbypaula.com/New
[Mon Jul 20 06:45:35.822204 2026] [security2:error] [pid 1011111:tid 1011342] [client 117.247.108.24:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YbxXES7Mv0Zfga-ki4wAAAOk"]
[Mon Jul 20 06:45:35.822628 2026] [security2:error] [pid 1011111:tid 1011342] [client 117.247.108.24:64243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YbxXES7Mv0Zfga-ki4wAAAOk"]
[Mon Jul 20 06:45:35.877389 2026] [security2:error] [pid 1014214:tid 1014471] [client 13.233.207.33:57034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YbwuRBFTcQNywdCITKwAAAg4"]
[Mon Jul 20 06:45:35.878853 2026] [security2:error] [pid 1014214:tid 1014351] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.stratabrandco.lnl.tfc.mybluehost.me"] [uri "/index.php"] [unique_id "al4YbguRBFTcQNywdCIS5AAAAZY"]
[Mon Jul 20 06:45:36.023558 2026] [security2:error] [pid 1014214:tid 1014354] [client 57.141.18.96:29508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YawuRBFTcQNywdCISRAABmXs"]
[Mon Jul 20 06:45:36.098926 2026] [security2:error] [pid 1014214:tid 1014447] [client 57.141.18.71:24628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YawuRBFTcQNywdCISTAAB9ko"]
[Mon Jul 20 06:45:36.418832 2026] [security2:error] [pid 1011111:tid 1011364] [client 14.225.17.146:58959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4YbxXES7Mv0Zfga-kizwAAAP8"], referer: http://ncsynchro.com/New
[Mon Jul 20 06:45:36.514671 2026] [security2:error] [pid 1014214:tid 1014302] [remote 81.173.115.7:36490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4YcAuRBFTcQNywdCITRQAB9Fc"]
[Mon Jul 20 06:45:36.692765 2026] [security2:error] [pid 1014214:tid 1014356] [client 51.158.123.193:51990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "webmail-box5033.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4YcAuRBFTcQNywdCITTQAAAZs"]
[Mon Jul 20 06:45:36.713845 2026] [security2:error] [pid 1014214:tid 1014224] [remote 81.173.115.7:36490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4YcAuRBFTcQNywdCITTwACDAk"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 06:45:36.893777 2026] [security2:error] [pid 1014214:tid 1014412] [client 13.233.207.33:57040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YcAuRBFTcQNywdCITXQAAAdM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:45:37.096068 2026] [proxy:error] [pid 1011111:tid 1011332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:37.096156 2026] [proxy_http:error] [pid 1011111:tid 1011332] [client 82.102.18.116:59680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:37.096960 2026] [proxy:error] [pid 1011111:tid 1011332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:37.096992 2026] [proxy_http:error] [pid 1011111:tid 1011332] [client 82.102.18.116:59680] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:37.102792 2026] [security2:error] [pid 1014214:tid 1014352] [client 14.225.17.146:62154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4YbwuRBFTcQNywdCITKQAAAZc"], referer: http://elitetax-mi.com/New
[Mon Jul 20 06:45:37.403033 2026] [security2:error] [pid 1014214:tid 1014424] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YcQuRBFTcQNywdCITagAAAd8"]
[Mon Jul 20 06:45:37.420647 2026] [proxy:error] [pid 1014214:tid 1014420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:37.420718 2026] [proxy_http:error] [pid 1014214:tid 1014420] [client 82.102.18.116:59692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:37.421429 2026] [proxy:error] [pid 1014214:tid 1014420] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:37.421459 2026] [proxy_http:error] [pid 1014214:tid 1014420] [client 82.102.18.116:59692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:37.469730 2026] [security2:error] [pid 1014214:tid 1014456] [client 14.225.17.146:62319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4YcQuRBFTcQNywdCITbwAAAf8"]
[Mon Jul 20 06:45:37.547120 2026] [security2:error] [pid 1011111:tid 1011248] [client 37.52.210.45:36430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YcRXES7Mv0Zfga-kjFwAAAIs"]
[Mon Jul 20 06:45:37.547247 2026] [security2:error] [pid 1011111:tid 1011248] [client 37.52.210.45:36430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YcRXES7Mv0Zfga-kjFwAAAIs"]
[Mon Jul 20 06:45:37.758485 2026] [security2:error] [pid 1014214:tid 1014423] [client 82.102.18.116:59696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4YcQuRBFTcQNywdCITkgAAAd4"]
[Mon Jul 20 06:45:37.921455 2026] [security2:error] [pid 1014214:tid 1014468] [client 104.234.53.93:34221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YcQuRBFTcQNywdCITmQAAAgs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:37.947192 2026] [security2:error] [pid 1011111:tid 1011212] [remote 103.187.169.251:52754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YcRXES7Mv0Zfga-kjIgABA2M"]
[Mon Jul 20 06:45:38.132104 2026] [security2:error] [pid 1014214:tid 1014344] [client 82.102.18.116:58970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.sergnotes.com"] [uri "/xmlrpc.php"] [unique_id "al4YcguRBFTcQNywdCITogAAAY8"]
[Mon Jul 20 06:45:38.165760 2026] [security2:error] [pid 1011111:tid 1011257] [client 57.141.18.52:62572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YbRXES7Mv0Zfga-kilQAAlFg"]
[Mon Jul 20 06:45:38.369851 2026] [security2:error] [pid 1011111:tid 1011194] [remote 103.187.169.251:52754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YchXES7Mv0Zfga-kjKAAA_1E"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:45:38.455069 2026] [proxy:error] [pid 1014214:tid 1014372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:38.455152 2026] [proxy_http:error] [pid 1014214:tid 1014372] [client 82.102.18.116:25353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:38.456257 2026] [proxy:error] [pid 1014214:tid 1014372] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:38.456288 2026] [proxy_http:error] [pid 1014214:tid 1014372] [client 82.102.18.116:25353] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:38.493722 2026] [security2:error] [pid 1014214:tid 1014466] [client 57.141.18.103:63424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YbQuRBFTcQNywdCIStQACCWY"]
[Mon Jul 20 06:45:38.511946 2026] [security2:error] [pid 1014214:tid 1014388] [client 197.186.66.42:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YcguRBFTcQNywdCITuAAAAbs"]
[Mon Jul 20 06:45:38.512022 2026] [security2:error] [pid 1014214:tid 1014388] [client 197.186.66.42:64119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YcguRBFTcQNywdCITuAAAAbs"]
[Mon Jul 20 06:45:38.803879 2026] [security2:error] [pid 1014214:tid 1014470] [client 82.102.18.116:64550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YcguRBFTcQNywdCITxAAAAg0"]
[Mon Jul 20 06:45:38.915441 2026] [security2:error] [pid 1014214:tid 1014240] [remote 194.163.135.93:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.135.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4YcguRBFTcQNywdCITyQACCxk"]
[Mon Jul 20 06:45:38.942915 2026] [security2:error] [pid 1014214:tid 1014419] [client 57.141.18.74:27970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YbQuRBFTcQNywdCIS1AAB2mc"]
[Mon Jul 20 06:45:39.058871 2026] [security2:error] [pid 1014214:tid 1014286] [remote 152.228.213.32:40880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YcwuRBFTcQNywdCIT0AAB70c"]
[Mon Jul 20 06:45:39.137002 2026] [security2:error] [pid 1014214:tid 1014276] [remote 194.163.135.93:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.135.163.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4YcwuRBFTcQNywdCIT0wAB_z0"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:45:39.145137 2026] [security2:error] [pid 1014214:tid 1014394] [client 82.102.18.116:58980] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YcwuRBFTcQNywdCIT1QAAAcE"]
[Mon Jul 20 06:45:39.249993 2026] [security2:error] [pid 1014214:tid 1014356] [client 74.208.214.194:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4YcwuRBFTcQNywdCIT2AAAAZs"]
[Mon Jul 20 06:45:39.453234 2026] [security2:error] [pid 1014214:tid 1014326] [remote 152.228.213.32:40880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YcwuRBFTcQNywdCIT4wABwm8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:45:39.460499 2026] [security2:error] [pid 1014214:tid 1014382] [client 82.102.18.116:58988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YcwuRBFTcQNywdCIT5AAAAbU"]
[Mon Jul 20 06:45:39.762698 2026] [security2:error] [pid 1014214:tid 1014415] [client 39.48.81.23:57765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YcwuRBFTcQNywdCIT9wAAAdY"]
[Mon Jul 20 06:45:39.762857 2026] [security2:error] [pid 1014214:tid 1014415] [client 39.48.81.23:57765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YcwuRBFTcQNywdCIT9wAAAdY"]
[Mon Jul 20 06:45:39.792209 2026] [security2:error] [pid 1014214:tid 1014465] [client 82.102.18.116:58996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4YcwuRBFTcQNywdCIT-QAAAgg"]
[Mon Jul 20 06:45:39.843461 2026] [security2:error] [pid 1011111:tid 1011246] [client 14.224.227.113:54686] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YcxXES7Mv0Zfga-kjVwAAAIk"]
[Mon Jul 20 06:45:40.039552 2026] [core:error] [pid 1014214:tid 1014435] [client 14.225.17.146:62213] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:45:40.039572 2026] [core:error] [pid 1014214:tid 1014435] [client 14.225.17.146:62213] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:45:40.069722 2026] [security2:error] [pid 1014214:tid 1014410] [client 57.141.18.117:48292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YbguRBFTcQNywdCITBAAB0U4"]
[Mon Jul 20 06:45:40.101643 2026] [security2:error] [pid 1014214:tid 1014378] [client 106.219.188.178:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YdAuRBFTcQNywdCIUAQAAAbE"]
[Mon Jul 20 06:45:40.101743 2026] [security2:error] [pid 1014214:tid 1014378] [client 106.219.188.178:51778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YdAuRBFTcQNywdCIUAQAAAbE"]
[Mon Jul 20 06:45:40.125565 2026] [security2:error] [pid 1014214:tid 1014429] [client 82.102.18.116:59006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YdAuRBFTcQNywdCIUBQAAAeQ"]
[Mon Jul 20 06:45:40.382813 2026] [security2:error] [pid 1014214:tid 1014433] [client 192.140.149.97:45991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YdAuRBFTcQNywdCIUEAAAAeg"]
[Mon Jul 20 06:45:40.382921 2026] [security2:error] [pid 1014214:tid 1014433] [client 192.140.149.97:45991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YdAuRBFTcQNywdCIUEAAAAeg"]
[Mon Jul 20 06:45:40.435002 2026] [security2:error] [pid 1011111:tid 1011364] [client 82.102.18.116:59012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4YdBXES7Mv0Zfga-kjaAAAAP8"]
[Mon Jul 20 06:45:40.654529 2026] [security2:error] [pid 1011111:tid 1011325] [client 57.141.18.43:47052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YbxXES7Mv0Zfga-ki0AAA2Hw"]
[Mon Jul 20 06:45:40.773222 2026] [security2:error] [pid 1014214:tid 1014458] [client 82.102.18.116:59014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YdAuRBFTcQNywdCIUIQAAAgE"]
[Mon Jul 20 06:45:40.894091 2026] [security2:error] [pid 1014214:tid 1014396] [client 158.173.89.95:38839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YdAuRBFTcQNywdCIUJgAAAcM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:45:41.076328 2026] [security2:error] [pid 1014214:tid 1014430] [client 112.208.70.94:42525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YdQuRBFTcQNywdCIUMwAAAeU"]
[Mon Jul 20 06:45:41.076419 2026] [security2:error] [pid 1014214:tid 1014430] [client 112.208.70.94:42525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YdQuRBFTcQNywdCIUMwAAAeU"]
[Mon Jul 20 06:45:41.112043 2026] [security2:error] [pid 1014214:tid 1014445] [client 82.102.18.116:59030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YdQuRBFTcQNywdCIUNAAAAfQ"]
[Mon Jul 20 06:45:41.213873 2026] [security2:error] [pid 1011111:tid 1011354] [client 14.225.17.146:57278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4YcxXES7Mv0Zfga-kjTwAAAPU"], referer: http://bigwormfishing.com/New
[Mon Jul 20 06:45:41.447463 2026] [security2:error] [pid 1014214:tid 1014352] [client 82.102.18.116:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YdQuRBFTcQNywdCIURQAAAZc"]
[Mon Jul 20 06:45:41.559779 2026] [security2:error] [pid 1011111:tid 1011326] [client 14.225.17.146:51558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4YdRXES7Mv0Zfga-kjgAAAANk"], referer: http://ironcitywellness.com/New
[Mon Jul 20 06:45:41.755522 2026] [security2:error] [pid 1014214:tid 1014262] [remote 72.167.132.114:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YdQuRBFTcQNywdCIUVQABli8"]
[Mon Jul 20 06:45:41.763789 2026] [security2:error] [pid 1014214:tid 1014357] [client 82.102.18.116:29659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YdQuRBFTcQNywdCIUVwAAAZw"]
[Mon Jul 20 06:45:41.824355 2026] [security2:error] [pid 1011111:tid 1011117] [remote 47.86.33.52:7634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YdRXES7Mv0Zfga-kjkQAAtAQ"]
[Mon Jul 20 06:45:41.999295 2026] [security2:error] [pid 1011111:tid 1011119] [remote 8.217.108.67:55700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4YdRXES7Mv0Zfga-kjlQAAuQY"]
[Mon Jul 20 06:45:42.091326 2026] [security2:error] [pid 1014214:tid 1014363] [client 82.102.18.116:59054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4YdguRBFTcQNywdCIUaAAAAaI"]
[Mon Jul 20 06:45:42.102244 2026] [security2:error] [pid 1014214:tid 1014378] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YdguRBFTcQNywdCIUYAAAAbE"]
[Mon Jul 20 06:45:42.118861 2026] [security2:error] [pid 1014214:tid 1014304] [remote 72.167.132.114:59766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YdguRBFTcQNywdCIUagACB1k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:45:42.179923 2026] [security2:error] [pid 1014214:tid 1014373] [client 127.0.0.1:45116] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4YdguRBFTcQNywdCIUcQAAAaw"], referer: https://t.co/3661zoymi9
[Mon Jul 20 06:45:42.403917 2026] [security2:error] [pid 1014214:tid 1014328] [remote 97.74.87.194:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4YdguRBFTcQNywdCIUfAACBnE"]
[Mon Jul 20 06:45:42.436603 2026] [security2:error] [pid 1014214:tid 1014432] [client 82.102.18.116:59064] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4YdguRBFTcQNywdCIUfgAAAec"]
[Mon Jul 20 06:45:42.629359 2026] [security2:error] [pid 1014214:tid 1014393] [client 14.225.17.146:56752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4YdguRBFTcQNywdCIUggAAAcA"], referer: http://thesoloceos.com/New
[Mon Jul 20 06:45:42.681454 2026] [security2:error] [pid 1014214:tid 1014386] [client 50.116.65.227:59364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YdguRBFTcQNywdCIUkgAAAbk"]
[Mon Jul 20 06:45:42.689325 2026] [security2:error] [pid 1014214:tid 1014405] [client 50.116.65.227:59366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YdguRBFTcQNywdCIUkwAAAcw"]
[Mon Jul 20 06:45:42.740361 2026] [proxy:error] [pid 1014214:tid 1014434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:42.740422 2026] [proxy_http:error] [pid 1014214:tid 1014434] [client 34.73.38.214:55245] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:42.740876 2026] [proxy:error] [pid 1014214:tid 1014434] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:42.740900 2026] [proxy_http:error] [pid 1014214:tid 1014434] [client 34.73.38.214:55245] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:42.760403 2026] [security2:error] [pid 1011111:tid 1011303] [client 82.102.18.116:27040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YdhXES7Mv0Zfga-kjqQAAAMI"]
[Mon Jul 20 06:45:42.798349 2026] [security2:error] [pid 1014214:tid 1014221] [remote 97.74.87.194:52212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4YdguRBFTcQNywdCIUmAABygY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:45:42.919212 2026] [security2:error] [pid 1014214:tid 1014423] [client 103.238.106.162:60616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YdguRBFTcQNywdCIUqQAAAd4"]
[Mon Jul 20 06:45:42.919354 2026] [security2:error] [pid 1014214:tid 1014423] [client 103.238.106.162:60616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YdguRBFTcQNywdCIUqQAAAd4"]
[Mon Jul 20 06:45:42.979985 2026] [security2:error] [pid 1014214:tid 1014467] [client 14.225.17.146:64033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4YdguRBFTcQNywdCIUmgAAAgo"], referer: http://nomorewetsheets.net/New
[Mon Jul 20 06:45:43.076131 2026] [security2:error] [pid 1011111:tid 1011270] [client 82.102.18.116:59070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YdxXES7Mv0Zfga-kjsQAAAKE"]
[Mon Jul 20 06:45:43.084026 2026] [security2:error] [pid 1011111:tid 1011181] [remote 47.86.33.52:7634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YdxXES7Mv0Zfga-kjsgAAmEQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:45:43.165286 2026] [security2:error] [pid 1014214:tid 1014463] [client 216.73.217.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4YdguRBFTcQNywdCIUqgAAAgY"]
[Mon Jul 20 06:45:43.209519 2026] [security2:error] [pid 1014214:tid 1014413] [client 50.116.65.227:59388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4YdwuRBFTcQNywdCIUtwAAAdQ"]
[Mon Jul 20 06:45:43.266226 2026] [security2:error] [pid 1014214:tid 1014365] [client 103.125.179.95:54782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YdwuRBFTcQNywdCIUwgAAAaQ"]
[Mon Jul 20 06:45:43.266844 2026] [security2:error] [pid 1014214:tid 1014365] [client 103.125.179.95:54782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YdwuRBFTcQNywdCIUwgAAAaQ"]
[Mon Jul 20 06:45:43.284391 2026] [security2:error] [pid 1014214:tid 1014420] [client 57.141.18.50:57768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YcguRBFTcQNywdCITpgAB2yo"]
[Mon Jul 20 06:45:43.390102 2026] [security2:error] [pid 1014214:tid 1014457] [client 50.116.65.227:59390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4YdwuRBFTcQNywdCIUvgAAAgA"]
[Mon Jul 20 06:45:43.393005 2026] [security2:error] [pid 1014214:tid 1014470] [client 82.102.18.116:59074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.sergnotes.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4YdwuRBFTcQNywdCIUxwAAAg0"]
[Mon Jul 20 06:45:43.394627 2026] [security2:error] [pid 1014214:tid 1014370] [client 183.82.98.154:62167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YdwuRBFTcQNywdCIUyAAAAak"]
[Mon Jul 20 06:45:43.394720 2026] [security2:error] [pid 1014214:tid 1014370] [client 183.82.98.154:62167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YdwuRBFTcQNywdCIUyAAAAak"]
[Mon Jul 20 06:45:43.526845 2026] [security2:error] [pid 1014214:tid 1014401] [client 14.225.17.146:64250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4YdQuRBFTcQNywdCIUXgAAAcg"], referer: http://maplerespiteservices.com/New
[Mon Jul 20 06:45:43.580720 2026] [security2:error] [pid 1011111:tid 1011272] [client 217.142.18.172:61228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YdxXES7Mv0Zfga-kjvAAAAKM"]
[Mon Jul 20 06:45:43.580816 2026] [security2:error] [pid 1011111:tid 1011272] [client 217.142.18.172:61228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YdxXES7Mv0Zfga-kjvAAAAKM"]
[Mon Jul 20 06:45:43.581950 2026] [security2:error] [pid 1014214:tid 1014393] [client 14.225.17.146:51158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4YdwuRBFTcQNywdCIUzAAAAcA"], referer: https://thesoloceos.com/New
[Mon Jul 20 06:45:43.680332 2026] [security2:error] [pid 1014214:tid 1014418] [client 187.108.85.186:56088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YdwuRBFTcQNywdCIU2wAAAdk"]
[Mon Jul 20 06:45:43.680902 2026] [security2:error] [pid 1014214:tid 1014418] [client 187.108.85.186:56088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YdwuRBFTcQNywdCIU2wAAAdk"]
[Mon Jul 20 06:45:43.748179 2026] [security2:error] [pid 1011111:tid 1011366] [client 40.77.167.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4YdxXES7Mv0Zfga-kjvQAAAQE"]
[Mon Jul 20 06:45:43.938067 2026] [security2:error] [pid 1011111:tid 1011248] [client 52.167.144.172:54615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.phillipbloch.com"] [uri "/bio.php"] [unique_id "al4YdxXES7Mv0Zfga-kjzQAAAIs"]
[Mon Jul 20 06:45:44.124879 2026] [security2:error] [pid 1011111:tid 1011361] [client 57.141.18.114:57014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YcxXES7Mv0Zfga-kjRQAA_A4"]
[Mon Jul 20 06:45:44.594130 2026] [security2:error] [pid 1011111:tid 1011301] [client 57.141.18.87:57804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YcxXES7Mv0Zfga-kjUgAAwCI"]
[Mon Jul 20 06:45:44.623991 2026] [proxy:error] [pid 1014214:tid 1014352] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:44.624074 2026] [proxy_http:error] [pid 1014214:tid 1014352] [client 34.73.38.214:55243] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:44.624542 2026] [proxy:error] [pid 1014214:tid 1014352] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:44.624569 2026] [proxy_http:error] [pid 1014214:tid 1014352] [client 34.73.38.214:55243] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:44.670239 2026] [security2:error] [pid 1011111:tid 1011315] [client 139.28.219.68:54992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "idigress.group"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4YeBXES7Mv0Zfga-kj6AAAAM4"]
[Mon Jul 20 06:45:44.695845 2026] [security2:error] [pid 1014214:tid 1014336] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YeAuRBFTcQNywdCIVAQACCnk"]
[Mon Jul 20 06:45:44.695950 2026] [security2:error] [pid 1014214:tid 1014467] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YeAuRBFTcQNywdCIVAQACCnk"]
[Mon Jul 20 06:45:44.823607 2026] [security2:error] [pid 1014214:tid 1014390] [client 57.141.18.111:25298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YcwuRBFTcQNywdCIT8QABvWU"]
[Mon Jul 20 06:45:45.003577 2026] [security2:error] [pid 1011111:tid 1011347] [client 57.141.18.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YeBXES7Mv0Zfga-kj8wAAAO4"]
[Mon Jul 20 06:45:45.189107 2026] [security2:error] [pid 1011111:tid 1011324] [client 14.225.17.146:64101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4YeBXES7Mv0Zfga-kj9wAAANc"], referer: http://lifeisbetterlakeside.com/New
[Mon Jul 20 06:45:45.270679 2026] [security2:error] [pid 1011111:tid 1011369] [client 139.28.219.68:55000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/xmlrpc.php"] [unique_id "al4YeRXES7Mv0Zfga-kkCQAAAQQ"]
[Mon Jul 20 06:45:45.524450 2026] [security2:error] [pid 1011111:tid 1011249] [client 152.58.191.29:59214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YeRXES7Mv0Zfga-kkFAAAAIw"]
[Mon Jul 20 06:45:45.527165 2026] [security2:error] [pid 1011111:tid 1011249] [client 152.58.191.29:59214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YeRXES7Mv0Zfga-kkFAAAAIw"]
[Mon Jul 20 06:45:45.756463 2026] [security2:error] [pid 1014214:tid 1014379] [client 57.141.18.87:57820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YdAuRBFTcQNywdCIUHAABsmQ"]
[Mon Jul 20 06:45:46.065174 2026] [security2:error] [pid 1011111:tid 1011367] [client 57.141.18.40:59222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YdBXES7Mv0Zfga-kjdwABAgg"]
[Mon Jul 20 06:45:46.144625 2026] [security2:error] [pid 1014214:tid 1014458] [client 14.225.17.146:63724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4YeguRBFTcQNywdCIVQgAAAgE"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/New
[Mon Jul 20 06:45:46.157383 2026] [security2:error] [pid 1014214:tid 1014407] [client 171.61.165.146:20560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YeguRBFTcQNywdCIVTwAAAc4"]
[Mon Jul 20 06:45:46.158527 2026] [security2:error] [pid 1014214:tid 1014407] [client 171.61.165.146:20560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YeguRBFTcQNywdCIVTwAAAc4"]
[Mon Jul 20 06:45:46.251189 2026] [security2:error] [pid 1014214:tid 1014285] [remote 51.158.61.221:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4YeguRBFTcQNywdCIVVAABmUY"]
[Mon Jul 20 06:45:46.252178 2026] [access_compat:error] [pid 1014214:tid 1014299] [remote 5.29.11.62:8467] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:45:46.336377 2026] [security2:error] [pid 1011111:tid 1011265] [client 115.84.114.187:3779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YehXES7Mv0Zfga-kkKAAAnDQ"]
[Mon Jul 20 06:45:46.428289 2026] [security2:error] [pid 1014214:tid 1014250] [remote 51.158.61.221:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4YeguRBFTcQNywdCIVZAABlyM"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:45:46.441850 2026] [proxy:error] [pid 1011111:tid 1011354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:46.441916 2026] [proxy_http:error] [pid 1011111:tid 1011354] [client 34.73.38.214:55527] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:46.442500 2026] [proxy:error] [pid 1011111:tid 1011354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:45:46.442523 2026] [proxy_http:error] [pid 1011111:tid 1011354] [client 34.73.38.214:55527] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:45:46.467792 2026] [security2:error] [pid 1014214:tid 1014361] [client 98.159.234.160:47573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YeguRBFTcQNywdCIVZgAAAaA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:45:46.527609 2026] [security2:error] [pid 1014214:tid 1014378] [client 14.225.17.146:63882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4YeguRBFTcQNywdCIVYAAAAbE"], referer: http://detroitcsc.com/New
[Mon Jul 20 06:45:46.670508 2026] [security2:error] [pid 1014214:tid 1014469] [client 117.247.108.24:63665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YeguRBFTcQNywdCIVhAAAAgw"]
[Mon Jul 20 06:45:46.670594 2026] [security2:error] [pid 1014214:tid 1014469] [client 117.247.108.24:63665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YeguRBFTcQNywdCIVhAAAAgw"]
[Mon Jul 20 06:45:46.751678 2026] [security2:error] [pid 1014214:tid 1014340] [remote 47.86.33.52:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YeguRBFTcQNywdCIVhwAB7X0"]
[Mon Jul 20 06:45:46.772363 2026] [security2:error] [pid 1014214:tid 1014399] [client 14.225.17.146:64108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4YeguRBFTcQNywdCIVgwAAAcY"]
[Mon Jul 20 06:45:47.155991 2026] [security2:error] [pid 1011111:tid 1011349] [client 14.225.17.146:64251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4YexXES7Mv0Zfga-kkOgAAAPA"], referer: http://thechancersband.com/New
[Mon Jul 20 06:45:47.418244 2026] [security2:error] [pid 1014214:tid 1014237] [remote 47.86.33.52:7586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YewuRBFTcQNywdCIVswABohY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:45:47.664488 2026] [security2:error] [pid 1011111:tid 1011199] [remote 8.217.108.67:63374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4YexXES7Mv0Zfga-kkUQAAmVY"]
[Mon Jul 20 06:45:47.664683 2026] [security2:error] [pid 1011111:tid 1011262] [client 8.217.108.67:63374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4YexXES7Mv0Zfga-kkUQAAmVY"]
[Mon Jul 20 06:45:48.096639 2026] [security2:error] [pid 1011111:tid 1011273] [client 14.225.17.146:58228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YehXES7Mv0Zfga-kkMgAAAKQ"], referer: http://samdothan.org/New
[Mon Jul 20 06:45:48.128038 2026] [security2:error] [pid 1014214:tid 1014260] [remote 217.61.143.92:53010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4YfAuRBFTcQNywdCIV3wABlC0"]
[Mon Jul 20 06:45:48.173677 2026] [security2:error] [pid 1014214:tid 1014462] [client 37.52.210.45:38606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YfAuRBFTcQNywdCIV4wAAAgU"]
[Mon Jul 20 06:45:48.173965 2026] [security2:error] [pid 1014214:tid 1014462] [client 37.52.210.45:38606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YfAuRBFTcQNywdCIV4wAAAgU"]
[Mon Jul 20 06:45:48.363284 2026] [security2:error] [pid 1014214:tid 1014253] [remote 217.61.143.92:53010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4YfAuRBFTcQNywdCIV6wAB9SY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:45:48.453260 2026] [security2:error] [pid 1014214:tid 1014444] [client 34.73.38.214:53080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YfAuRBFTcQNywdCIV8gAAAfM"]
[Mon Jul 20 06:45:48.484115 2026] [security2:error] [pid 1014214:tid 1014410] [client 14.225.17.146:58269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4YfAuRBFTcQNywdCIV5AAAAdE"], referer: http://processorstudio.com/New
[Mon Jul 20 06:45:48.584888 2026] [security2:error] [pid 1014214:tid 1014377] [client 57.141.18.29:21098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YdwuRBFTcQNywdCIU1wABsDg"]
[Mon Jul 20 06:45:49.020098 2026] [security2:error] [pid 1014214:tid 1014350] [client 194.124.219.145:63728] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "nwcarvingacademy.com"] [uri "/cgi-sys/404.html"] [unique_id "al4YfQuRBFTcQNywdCIWEAAAAZU"]
[Mon Jul 20 06:45:49.021412 2026] [security2:error] [pid 1011111:tid 1011330] [client 194.124.219.145:63742] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "nwcarvingacademy.com"] [uri "/cgi-sys/404.html"] [unique_id "al4YfRXES7Mv0Zfga-kkcAAAAN0"]
[Mon Jul 20 06:45:49.311478 2026] [security2:error] [pid 1014214:tid 1014336] [remote 91.212.174.124:35050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.174.212.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YfQuRBFTcQNywdCIWIAAB4Hk"]
[Mon Jul 20 06:45:49.331653 2026] [security2:error] [pid 1011111:tid 1011368] [client 57.141.18.14:30346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YeBXES7Mv0Zfga-kj3gABAzg"]
[Mon Jul 20 06:45:49.354476 2026] [security2:error] [pid 1014214:tid 1014381] [client 14.225.17.146:56587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4YfQuRBFTcQNywdCIWJQAAAbQ"], referer: https://processorstudio.com/New
[Mon Jul 20 06:45:49.370367 2026] [security2:error] [pid 1014214:tid 1014418] [client 14.225.17.146:63643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4YfQuRBFTcQNywdCIWHwAAAdk"], referer: http://daseighty.net/New
[Mon Jul 20 06:45:49.375930 2026] [security2:error] [pid 1011111:tid 1011180] [remote 45.150.79.142:42722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4YfRXES7Mv0Zfga-kkfwAA7EM"]
[Mon Jul 20 06:45:49.612655 2026] [security2:error] [pid 1011111:tid 1011239] [remote 45.150.79.142:42722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4YfRXES7Mv0Zfga-kkiQAAmX4"], referer: https://lmgorman.com/wp-login.php
[Mon Jul 20 06:45:49.634131 2026] [security2:error] [pid 1014214:tid 1014261] [remote 91.212.174.124:35050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.174.212.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YfQuRBFTcQNywdCIWOQAB9y4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:45:49.720850 2026] [security2:error] [pid 1014214:tid 1014446] [client 223.185.13.213:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YfQuRBFTcQNywdCIWPgAAAfU"]
[Mon Jul 20 06:45:49.720944 2026] [security2:error] [pid 1014214:tid 1014446] [client 223.185.13.213:14279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YfQuRBFTcQNywdCIWPgAAAfU"]
[Mon Jul 20 06:45:49.738348 2026] [security2:error] [pid 1011111:tid 1011160] [remote 57.141.18.91:41016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5138828"] [unique_id "al4YfRXES7Mv0Zfga-kkjgAA9C8"]
[Mon Jul 20 06:45:49.739925 2026] [security2:error] [pid 1014214:tid 1014358] [client 52.109.68.130:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YfQuRBFTcQNywdCIWPwAAAZ0"]
[Mon Jul 20 06:45:49.749690 2026] [security2:error] [pid 1011111:tid 1011318] [client 14.225.17.146:63544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4YfBXES7Mv0Zfga-kkXgAAANE"], referer: http://nwcarvingacademy.com/New
[Mon Jul 20 06:45:49.782150 2026] [security2:error] [pid 1014214:tid 1014356] [client 194.124.219.145:0] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4YfQuRBFTcQNywdCIWLwAAAZs"]
[Mon Jul 20 06:45:49.837048 2026] [security2:error] [pid 1014214:tid 1014407] [client 194.124.219.145:63748] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/"] [unique_id "al4YfQuRBFTcQNywdCIWLQAAAc4"]
[Mon Jul 20 06:45:49.897304 2026] [security2:error] [pid 1014214:tid 1014401] [client 52.109.68.130:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YfQuRBFTcQNywdCIWRgAAAcg"]
[Mon Jul 20 06:45:49.905782 2026] [security2:error] [pid 1014214:tid 1014394] [client 57.141.18.115:47408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YeQuRBFTcQNywdCIVFAABwUs"]
[Mon Jul 20 06:45:49.913486 2026] [security2:error] [pid 1014214:tid 1014405] [client 139.28.219.68:55012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/xmlrpc.php"] [unique_id "al4YfQuRBFTcQNywdCIWRwAAAcw"]
[Mon Jul 20 06:45:49.913560 2026] [security2:error] [pid 1014214:tid 1014405] [client 139.28.219.68:55012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "idigress.group"] [uri "/xmlrpc.php"] [unique_id "al4YfQuRBFTcQNywdCIWRwAAAcw"]
[Mon Jul 20 06:45:50.037454 2026] [access_compat:error] [pid 1014214:tid 1014301] [remote 54.234.254.74:49668] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:45:50.113552 2026] [security2:error] [pid 1014214:tid 1014361] [client 34.73.38.214:53191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YfguRBFTcQNywdCIWVwAAAaA"]
[Mon Jul 20 06:45:50.120014 2026] [security2:error] [pid 1014214:tid 1014460] [client 14.225.17.146:63663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4YfQuRBFTcQNywdCIWRQAAAgM"], referer: http://talknutritionwithlesley.com/New
[Mon Jul 20 06:45:50.122683 2026] [security2:error] [pid 1014214:tid 1014359] [client 57.141.18.15:24442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YeQuRBFTcQNywdCIVHQABnhI"]
[Mon Jul 20 06:45:50.149110 2026] [security2:error] [pid 1011111:tid 1011291] [client 121.229.156.76:50404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/crochet-cables-online-course/"] [unique_id "al4YfhXES7Mv0Zfga-kklAAAALY"]
[Mon Jul 20 06:45:50.149255 2026] [security2:error] [pid 1011111:tid 1011291] [client 121.229.156.76:50404] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mezzacraft.com"] [uri "/crochet-cables-online-course/"] [unique_id "al4YfhXES7Mv0Zfga-kklAAAALY"]
[Mon Jul 20 06:45:50.254569 2026] [security2:error] [pid 1014214:tid 1014284] [remote 160.187.68.132:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4YfguRBFTcQNywdCIWYgAB-UU"]
[Mon Jul 20 06:45:50.398808 2026] [security2:error] [pid 1014214:tid 1014404] [client 50.116.65.227:10060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4YfQuRBFTcQNywdCIWSgAAAcs"]
[Mon Jul 20 06:45:50.562597 2026] [security2:error] [pid 1014214:tid 1014365] [client 39.48.81.23:58292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YfguRBFTcQNywdCIWdQAAAaQ"]
[Mon Jul 20 06:45:50.562712 2026] [security2:error] [pid 1014214:tid 1014365] [client 39.48.81.23:58292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YfguRBFTcQNywdCIWdQAAAaQ"]
[Mon Jul 20 06:45:50.584724 2026] [security2:error] [pid 1014214:tid 1014283] [remote 5.161.225.162:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4YfguRBFTcQNywdCIWdgABsUQ"]
[Mon Jul 20 06:45:50.683626 2026] [security2:error] [pid 1014214:tid 1014353] [client 51.143.183.75:21504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YfguRBFTcQNywdCIWfwAAAZg"]
[Mon Jul 20 06:45:50.685198 2026] [security2:error] [pid 1014214:tid 1014438] [client 106.219.188.178:10202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YfguRBFTcQNywdCIWgAAAAe0"]
[Mon Jul 20 06:45:50.685572 2026] [security2:error] [pid 1014214:tid 1014438] [client 106.219.188.178:10202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YfguRBFTcQNywdCIWgAAAAe0"]
[Mon Jul 20 06:45:50.807301 2026] [security2:error] [pid 1014214:tid 1014427] [client 14.225.17.146:63883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4YfguRBFTcQNywdCIWeAAAAeI"], referer: https://nwcarvingacademy.com/New
[Mon Jul 20 06:45:50.816765 2026] [security2:error] [pid 1011111:tid 1011367] [client 50.116.65.227:10088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4YfhXES7Mv0Zfga-kkmwAAAQI"]
[Mon Jul 20 06:45:50.818142 2026] [security2:error] [pid 1014214:tid 1014333] [remote 5.161.225.162:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4YfguRBFTcQNywdCIWhgABxHY"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:45:50.823308 2026] [security2:error] [pid 1014214:tid 1014419] [client 51.143.183.75:21504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YfguRBFTcQNywdCIWhwAAAdo"]
[Mon Jul 20 06:45:50.971600 2026] [security2:error] [pid 1014214:tid 1014411] [client 57.141.18.60:54970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YeguRBFTcQNywdCIVXgAB0mE"]
[Mon Jul 20 06:45:50.987970 2026] [security2:error] [pid 1014214:tid 1014313] [remote 160.187.68.132:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4YfguRBFTcQNywdCIWkAABtWI"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 06:45:51.070294 2026] [security2:error] [pid 1014214:tid 1014364] [client 194.124.219.145:63748] ModSecurity: Warning. Matched phrase "Disco" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "nwcarvingacademy.com"] [uri "/meta.json"] [unique_id "al4YfwuRBFTcQNywdCIWlAAAAaM"]
[Mon Jul 20 06:45:51.071437 2026] [security2:error] [pid 1014214:tid 1014258] [remote 194.164.192.228:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4YfwuRBFTcQNywdCIWkwABjys"]
[Mon Jul 20 06:45:51.267062 2026] [security2:error] [pid 1014214:tid 1014331] [remote 194.164.192.228:55844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4YfwuRBFTcQNywdCIWnQAB_XQ"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:45:51.312025 2026] [security2:error] [pid 1011111:tid 1011366] [client 57.141.18.22:51252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YehXES7Mv0Zfga-kkNAABAUw"]
[Mon Jul 20 06:45:51.383050 2026] [security2:error] [pid 1014214:tid 1014464] [client 57.141.18.30:51484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YeguRBFTcQNywdCIVlQACB0M"]
[Mon Jul 20 06:45:51.679006 2026] [security2:error] [pid 1014214:tid 1014421] [client 112.208.70.94:42974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YfwuRBFTcQNywdCIWuAAAAdw"]
[Mon Jul 20 06:45:51.679127 2026] [security2:error] [pid 1014214:tid 1014421] [client 112.208.70.94:42974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YfwuRBFTcQNywdCIWuAAAAdw"]
[Mon Jul 20 06:45:51.837546 2026] [security2:error] [pid 1014214:tid 1014367] [client 34.73.38.214:59016] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YfwuRBFTcQNywdCIWvwAAAaY"]
[Mon Jul 20 06:45:51.892979 2026] [security2:error] [pid 1014214:tid 1014347] [client 14.225.17.146:62797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4YfguRBFTcQNywdCIWbQAAAZI"], referer: http://eduardsales.com/New
[Mon Jul 20 06:45:51.927965 2026] [security2:error] [pid 1014214:tid 1014432] [client 14.225.17.146:62784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4YfwuRBFTcQNywdCIWrwAAAec"], referer: http://mollycahill.com/New
[Mon Jul 20 06:45:52.340940 2026] [security2:error] [pid 1011111:tid 1011314] [client 197.186.66.42:64675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YgBXES7Mv0Zfga-kk3gAAAM0"]
[Mon Jul 20 06:45:52.341509 2026] [security2:error] [pid 1011111:tid 1011314] [client 197.186.66.42:64675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YgBXES7Mv0Zfga-kk3gAAAM0"]
[Mon Jul 20 06:45:52.382473 2026] [security2:error] [pid 1014214:tid 1014372] [client 45.3.37.234:21459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YgAuRBFTcQNywdCIW1AAAAas"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:45:52.491234 2026] [autoindex:error] [pid 1014214:tid 1014353] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:52.491662 2026] [security2:error] [pid 1014214:tid 1014353] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgAuRBFTcQNywdCIW3AAAAZg"]
[Mon Jul 20 06:45:52.496589 2026] [security2:error] [pid 1014214:tid 1014383] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/uploads/"] [unique_id "al4YgAuRBFTcQNywdCIW2gAAAbY"]
[Mon Jul 20 06:45:52.665150 2026] [autoindex:error] [pid 1014214:tid 1014458] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:52.665615 2026] [security2:error] [pid 1014214:tid 1014458] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgAuRBFTcQNywdCIW6AAAAgE"]
[Mon Jul 20 06:45:52.681726 2026] [security2:error] [pid 1014214:tid 1014419] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/"] [unique_id "al4YgAuRBFTcQNywdCIW5gAAAdo"]
[Mon Jul 20 06:45:52.853604 2026] [autoindex:error] [pid 1011111:tid 1011300] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:52.854097 2026] [security2:error] [pid 1011111:tid 1011300] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgBXES7Mv0Zfga-kk7QAAAL8"]
[Mon Jul 20 06:45:52.859539 2026] [security2:error] [pid 1014214:tid 1014373] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/css/"] [unique_id "al4YgAuRBFTcQNywdCIW9wAAAaw"]
[Mon Jul 20 06:45:53.027631 2026] [autoindex:error] [pid 1014214:tid 1014351] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:53.028114 2026] [security2:error] [pid 1014214:tid 1014351] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgQuRBFTcQNywdCIW_gAAAZY"]
[Mon Jul 20 06:45:53.030498 2026] [security2:error] [pid 1014214:tid 1014377] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/ID3/"] [unique_id "al4YgQuRBFTcQNywdCIW_AAAAbA"]
[Mon Jul 20 06:45:53.040599 2026] [security2:error] [pid 1014214:tid 1014434] [client 122.183.32.225:27067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YgQuRBFTcQNywdCIXAAAAAek"]
[Mon Jul 20 06:45:53.040693 2026] [security2:error] [pid 1014214:tid 1014434] [client 122.183.32.225:27067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YgQuRBFTcQNywdCIXAAAAAek"]
[Mon Jul 20 06:45:53.052035 2026] [security2:error] [pid 1011111:tid 1011275] [client 50.116.65.227:10116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YgRXES7Mv0Zfga-kk8wAAAKY"]
[Mon Jul 20 06:45:53.061189 2026] [security2:error] [pid 1014214:tid 1014372] [client 50.116.65.227:10118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YgQuRBFTcQNywdCIXAQAAAas"]
[Mon Jul 20 06:45:53.148240 2026] [security2:error] [pid 1014214:tid 1014398] [client 57.141.18.73:56420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YfAuRBFTcQNywdCIWAAABxVo"]
[Mon Jul 20 06:45:53.230313 2026] [autoindex:error] [pid 1014214:tid 1014359] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:53.231546 2026] [security2:error] [pid 1014214:tid 1014359] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgQuRBFTcQNywdCIXDAAAAZ4"]
[Mon Jul 20 06:45:53.247679 2026] [security2:error] [pid 1014214:tid 1014390] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/IXR/"] [unique_id "al4YgQuRBFTcQNywdCIXCQAAAb0"]
[Mon Jul 20 06:45:53.292511 2026] [security2:error] [pid 1014214:tid 1014450] [client 34.73.105.183:51308] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "stepupstepmom.com"] [uri "/wp-json/batch/v1"] [unique_id "al4YgQuRBFTcQNywdCIXFAAAAfk"]
[Mon Jul 20 06:45:53.383146 2026] [security2:error] [pid 1014214:tid 1014370] [client 176.118.193.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4YgQuRBFTcQNywdCIXEgAAAak"]
[Mon Jul 20 06:45:53.402451 2026] [security2:error] [pid 1014214:tid 1014437] [client 34.73.38.214:64748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YgQuRBFTcQNywdCIXGgAAAew"]
[Mon Jul 20 06:45:53.411310 2026] [autoindex:error] [pid 1011111:tid 1011254] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:53.411723 2026] [security2:error] [pid 1011111:tid 1011254] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgRXES7Mv0Zfga-klBQAAAJE"]
[Mon Jul 20 06:45:53.412894 2026] [security2:error] [pid 1014214:tid 1014344] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/Requests/"] [unique_id "al4YgQuRBFTcQNywdCIXGAAAAY8"]
[Mon Jul 20 06:45:53.430983 2026] [security2:error] [pid 1014214:tid 1014463] [client 103.238.106.162:60904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YgQuRBFTcQNywdCIXHAAAAgY"]
[Mon Jul 20 06:45:53.431082 2026] [security2:error] [pid 1014214:tid 1014463] [client 103.238.106.162:60904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YgQuRBFTcQNywdCIXHAAAAgY"]
[Mon Jul 20 06:45:53.593012 2026] [autoindex:error] [pid 1014214:tid 1014428] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:53.593717 2026] [security2:error] [pid 1014214:tid 1014428] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgQuRBFTcQNywdCIXKAAAAeM"]
[Mon Jul 20 06:45:53.595874 2026] [security2:error] [pid 1014214:tid 1014367] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/SimplePie/"] [unique_id "al4YgQuRBFTcQNywdCIXJAAAAaY"]
[Mon Jul 20 06:45:53.685539 2026] [security2:error] [pid 1011111:tid 1011369] [client 57.141.18.39:31263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YfRXES7Mv0Zfga-kkeAABBFc"]
[Mon Jul 20 06:45:53.764597 2026] [autoindex:error] [pid 1014214:tid 1014442] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:53.765077 2026] [security2:error] [pid 1014214:tid 1014442] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YgQuRBFTcQNywdCIXOQAAAfE"]
[Mon Jul 20 06:45:53.780452 2026] [security2:error] [pid 1014214:tid 1014414] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/Text/"] [unique_id "al4YgQuRBFTcQNywdCIXOAAAAdU"]
[Mon Jul 20 06:45:53.926537 2026] [security2:error] [pid 1014214:tid 1014355] [client 14.225.17.146:63821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4YgAuRBFTcQNywdCIW5AAAAZo"], referer: http://whiteoutcb.com/New
[Mon Jul 20 06:45:54.004471 2026] [security2:error] [pid 1011111:tid 1011277] [client 103.125.179.95:55272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YghXES7Mv0Zfga-klGQAAAKg"]
[Mon Jul 20 06:45:54.005356 2026] [security2:error] [pid 1011111:tid 1011277] [client 103.125.179.95:55272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YghXES7Mv0Zfga-klGQAAAKg"]
[Mon Jul 20 06:45:54.019274 2026] [security2:error] [pid 1014214:tid 1014256] [remote 20.153.140.50:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4YgguRBFTcQNywdCIXSwAB_Sk"]
[Mon Jul 20 06:45:54.107661 2026] [security2:error] [pid 1011111:tid 1011298] [client 44.245.170.32:43320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4YghXES7Mv0Zfga-klHQAAAL0"]
[Mon Jul 20 06:45:54.156246 2026] [security2:error] [pid 1014214:tid 1014353] [client 217.142.18.172:61574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YgguRBFTcQNywdCIXUgAAAZg"]
[Mon Jul 20 06:45:54.156449 2026] [security2:error] [pid 1014214:tid 1014353] [client 217.142.18.172:61574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YgguRBFTcQNywdCIXUgAAAZg"]
[Mon Jul 20 06:45:54.194950 2026] [security2:error] [pid 1014214:tid 1014300] [remote 194.164.192.228:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4YgguRBFTcQNywdCIXVQAB7FU"]
[Mon Jul 20 06:45:54.261144 2026] [security2:error] [pid 1011111:tid 1011299] [client 183.82.98.154:62751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YghXES7Mv0Zfga-klKAAAAL4"]
[Mon Jul 20 06:45:54.261264 2026] [security2:error] [pid 1011111:tid 1011299] [client 183.82.98.154:62751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YghXES7Mv0Zfga-klKAAAAL4"]
[Mon Jul 20 06:45:54.280403 2026] [security2:error] [pid 1014214:tid 1014419] [client 187.108.85.186:56635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YgguRBFTcQNywdCIXWgAAAdo"]
[Mon Jul 20 06:45:54.280513 2026] [security2:error] [pid 1014214:tid 1014419] [client 187.108.85.186:56635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YgguRBFTcQNywdCIXWgAAAdo"]
[Mon Jul 20 06:45:54.409151 2026] [security2:error] [pid 1014214:tid 1014252] [remote 20.153.140.50:55984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4YgguRBFTcQNywdCIXZAABtiU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:45:54.442885 2026] [security2:error] [pid 1014214:tid 1014271] [remote 194.164.192.228:52272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4YgguRBFTcQNywdCIXZQAB7Tg"], referer: https://spencersadventures.com/wp-login.php
[Mon Jul 20 06:45:54.515657 2026] [security2:error] [pid 1014214:tid 1014358] [client 45.157.112.60:27257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YgguRBFTcQNywdCIXZwAAAZ0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:45:54.526344 2026] [security2:error] [pid 1011111:tid 1011364] [client 162.12.226.9:37385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YghXES7Mv0Zfga-klMgAA_1U"]
[Mon Jul 20 06:45:54.624174 2026] [security2:error] [pid 1011111:tid 1011365] [client 34.73.38.214:56915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YghXES7Mv0Zfga-klOgAAAQA"]
[Mon Jul 20 06:45:54.781774 2026] [security2:error] [pid 1014214:tid 1014388] [client 34.139.11.221:53218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.jennylouraya.com"] [uri "/xmlrpc.php"] [unique_id "al4YgguRBFTcQNywdCIXcwAAAbs"]
[Mon Jul 20 06:45:54.908948 2026] [security2:error] [pid 1014214:tid 1014434] [client 34.139.11.221:59009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YgguRBFTcQNywdCIXeQAAAek"]
[Mon Jul 20 06:45:54.944499 2026] [security2:error] [pid 1011111:tid 1011334] [client 34.73.38.214:60167] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YghXES7Mv0Zfga-klRAAAAOE"]
[Mon Jul 20 06:45:55.085300 2026] [security2:error] [pid 1011111:tid 1011282] [client 34.139.11.221:50420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YgxXES7Mv0Zfga-klRwAAAK0"]
[Mon Jul 20 06:45:55.089717 2026] [security2:error] [pid 1011111:tid 1011261] [client 104.234.53.85:59197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YgxXES7Mv0Zfga-klRQAAAJg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:55.234233 2026] [security2:error] [pid 1014214:tid 1014410] [client 14.224.227.113:54688] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YgwuRBFTcQNywdCIXgQAAAdE"]
[Mon Jul 20 06:45:55.247561 2026] [security2:error] [pid 1011111:tid 1011279] [client 34.139.11.221:52957] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YgxXES7Mv0Zfga-klUwAAAKo"]
[Mon Jul 20 06:45:55.297488 2026] [security2:error] [pid 1011111:tid 1011122] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YgxXES7Mv0Zfga-klVAAAhgk"]
[Mon Jul 20 06:45:55.297678 2026] [security2:error] [pid 1011111:tid 1011243] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YgxXES7Mv0Zfga-klVAAAhgk"]
[Mon Jul 20 06:45:55.373599 2026] [security2:error] [pid 1014214:tid 1014425] [client 57.141.18.19:39938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YfguRBFTcQNywdCIWewAB4FQ"]
[Mon Jul 20 06:45:55.404610 2026] [security2:error] [pid 1011111:tid 1011300] [client 34.139.11.221:65206] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YgxXES7Mv0Zfga-klVgAAAL8"]
[Mon Jul 20 06:45:55.423946 2026] [security2:error] [pid 1014214:tid 1014469] [client 57.141.18.92:55910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YfguRBFTcQNywdCIWgwACDGM"]
[Mon Jul 20 06:45:55.538465 2026] [security2:error] [pid 1014214:tid 1014414] [client 34.139.11.221:54602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YgwuRBFTcQNywdCIXkgAAAdU"]
[Mon Jul 20 06:45:55.555560 2026] [security2:error] [pid 1014214:tid 1014422] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YgQuRBFTcQNywdCIXRAAAAd0"]
[Mon Jul 20 06:45:55.555592 2026] [security2:error] [pid 1014214:tid 1014422] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YgQuRBFTcQNywdCIXRAAAAd0"]
[Mon Jul 20 06:45:55.593519 2026] [security2:error] [pid 1014214:tid 1014448] [client 34.73.38.214:63607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YgwuRBFTcQNywdCIXmAAAAfc"]
[Mon Jul 20 06:45:55.630910 2026] [security2:error] [pid 1011111:tid 1011153] [remote 160.187.68.132:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YgxXES7Mv0Zfga-klXQAAoyg"]
[Mon Jul 20 06:45:55.634396 2026] [access_compat:error] [pid 1014214:tid 1014275] [remote 45.14.31.238:52940] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:45:55.681222 2026] [security2:error] [pid 1011111:tid 1011265] [client 34.139.11.221:61942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YgxXES7Mv0Zfga-klZQAAAJw"]
[Mon Jul 20 06:45:55.798932 2026] [security2:error] [pid 1014214:tid 1014408] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/mu-plugins-old/"] [unique_id "al4YgQuRBFTcQNywdCIXQgAAAgE"]
[Mon Jul 20 06:45:55.814617 2026] [security2:error] [pid 1014214:tid 1014286] [remote 57.141.18.99:20014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6219057"] [unique_id "al4YgwuRBFTcQNywdCIXowAB2Uc"]
[Mon Jul 20 06:45:55.833859 2026] [security2:error] [pid 1014214:tid 1014388] [client 34.139.11.221:64794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YgwuRBFTcQNywdCIXpwAAAbs"]
[Mon Jul 20 06:45:55.901014 2026] [security2:error] [pid 1014214:tid 1014342] [remote 8.217.108.67:40336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4YgwuRBFTcQNywdCIXqgAB738"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:45:56.015863 2026] [security2:error] [pid 1014214:tid 1014401] [client 34.139.11.221:49943] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YhAuRBFTcQNywdCIXtAAAAcg"]
[Mon Jul 20 06:45:56.048136 2026] [security2:error] [pid 1014214:tid 1014403] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIXswAAAco"]
[Mon Jul 20 06:45:56.051812 2026] [security2:error] [pid 1014214:tid 1014392] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIXtQAAAb8"]
[Mon Jul 20 06:45:56.053811 2026] [security2:error] [pid 1011111:tid 1011366] [client 114.119.149.222:53505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ksands.co.uk"] [uri "/news/human-resources/"] [unique_id "al4YhBXES7Mv0Zfga-klcQAAAQE"], referer: http://ksands.co.uk/
[Mon Jul 20 06:45:56.081843 2026] [security2:error] [pid 1014214:tid 1014378] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIXtwAAAbE"]
[Mon Jul 20 06:45:56.086251 2026] [security2:error] [pid 1014214:tid 1014439] [client 194.65.151.207:53770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YgwuRBFTcQNywdCIXsgAB7iI"]
[Mon Jul 20 06:45:56.118296 2026] [security2:error] [pid 1014214:tid 1014386] [client 152.58.191.29:59665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YhAuRBFTcQNywdCIXvQAAAbk"]
[Mon Jul 20 06:45:56.122013 2026] [security2:error] [pid 1014214:tid 1014386] [client 152.58.191.29:59665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YhAuRBFTcQNywdCIXvQAAAbk"]
[Mon Jul 20 06:45:56.166160 2026] [security2:error] [pid 1014214:tid 1014459] [client 34.139.11.221:64350] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YhAuRBFTcQNywdCIXwAAAAgI"]
[Mon Jul 20 06:45:56.298519 2026] [security2:error] [pid 1011111:tid 1011345] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhBXES7Mv0Zfga-kldgAAAOw"]
[Mon Jul 20 06:45:56.298552 2026] [security2:error] [pid 1011111:tid 1011345] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhBXES7Mv0Zfga-kldgAAAOw"]
[Mon Jul 20 06:45:56.308616 2026] [security2:error] [pid 1014214:tid 1014359] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/themes/classic/inc/"] [unique_id "al4YhAuRBFTcQNywdCIXuwAAAZ4"]
[Mon Jul 20 06:45:56.335827 2026] [security2:error] [pid 1014214:tid 1014371] [client 34.139.11.221:64749] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YhAuRBFTcQNywdCIXzwAAAao"]
[Mon Jul 20 06:45:56.338555 2026] [security2:error] [pid 1014214:tid 1014348] [client 34.73.38.214:53509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YhAuRBFTcQNywdCIX0AAAAZM"]
[Mon Jul 20 06:45:56.342337 2026] [security2:error] [pid 1014214:tid 1014373] [client 34.73.105.183:51308] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "stepupstepmom.com"] [uri "/"] [unique_id "al4YhAuRBFTcQNywdCIX0QAAAaw"]
[Mon Jul 20 06:45:56.474441 2026] [security2:error] [pid 1011111:tid 1011180] [remote 160.187.68.132:53158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YhBXES7Mv0Zfga-klggAA80M"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:45:56.511835 2026] [security2:error] [pid 1014214:tid 1014442] [client 34.139.11.221:50067] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jennylouraya.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YhAuRBFTcQNywdCIX3gAAAfE"]
[Mon Jul 20 06:45:56.610397 2026] [security2:error] [pid 1014214:tid 1014386] [client 89.58.73.111:38766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIX2wAAAbk"]
[Mon Jul 20 06:45:56.626743 2026] [security2:error] [pid 1011111:tid 1011336] [client 57.141.18.117:32952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YgBXES7Mv0Zfga-kk1QAA40g"]
[Mon Jul 20 06:45:56.727844 2026] [security2:error] [pid 1011111:tid 1011360] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhBXES7Mv0Zfga-klhgAAAPs"]
[Mon Jul 20 06:45:56.727870 2026] [security2:error] [pid 1011111:tid 1011360] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhBXES7Mv0Zfga-klhgAAAPs"]
[Mon Jul 20 06:45:56.745417 2026] [security2:error] [pid 1014214:tid 1014450] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "al4YhAuRBFTcQNywdCIX4QAAAfk"]
[Mon Jul 20 06:45:56.803377 2026] [security2:error] [pid 1011111:tid 1011301] [client 89.58.73.111:20304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhBXES7Mv0Zfga-kliwAAAMA"]
[Mon Jul 20 06:45:56.851069 2026] [security2:error] [pid 1011111:tid 1011206] [remote 130.51.180.8:46888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4YhBXES7Mv0Zfga-klkQAAxF0"]
[Mon Jul 20 06:45:56.900385 2026] [security2:error] [pid 1014214:tid 1014381] [client 57.141.18.76:46778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YgAuRBFTcQNywdCIW1wABtEo"]
[Mon Jul 20 06:45:56.905387 2026] [security2:error] [pid 1014214:tid 1014359] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIX8QAAAZ4"]
[Mon Jul 20 06:45:56.908670 2026] [security2:error] [pid 1014214:tid 1014413] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIX8wAAAdQ"]
[Mon Jul 20 06:45:56.913128 2026] [autoindex:error] [pid 1014214:tid 1014377] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:56.913551 2026] [security2:error] [pid 1014214:tid 1014377] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhAuRBFTcQNywdCIX-gAAAbA"]
[Mon Jul 20 06:45:56.915869 2026] [security2:error] [pid 1014214:tid 1014425] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/mu-plugins/"] [unique_id "al4YhAuRBFTcQNywdCIX9wAAAeA"]
[Mon Jul 20 06:45:56.924891 2026] [security2:error] [pid 1014214:tid 1014367] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIX9gAAAaY"]
[Mon Jul 20 06:45:57.030584 2026] [security2:error] [pid 1011111:tid 1011190] [remote 130.51.180.8:46888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4YhRXES7Mv0Zfga-kllgAAqU0"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:45:57.066383 2026] [security2:error] [pid 1011111:tid 1011195] [remote 111.225.149.43:29942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/lutheran-philosopher-resources-searchable-videos-and-other-study-tools/"] [unique_id "al4YhRXES7Mv0Zfga-klmAAAsVI"]
[Mon Jul 20 06:45:57.084264 2026] [autoindex:error] [pid 1011111:tid 1011355] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:57.084739 2026] [security2:error] [pid 1011111:tid 1011355] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhRXES7Mv0Zfga-klmQAAAPY"]
[Mon Jul 20 06:45:57.087081 2026] [security2:error] [pid 1014214:tid 1014464] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al4YhQuRBFTcQNywdCIYCAAAAgc"]
[Mon Jul 20 06:45:57.184739 2026] [security2:error] [pid 1011111:tid 1011315] [client 171.61.165.146:22449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YhRXES7Mv0Zfga-klnAAAAM4"]
[Mon Jul 20 06:45:57.184961 2026] [security2:error] [pid 1011111:tid 1011315] [client 171.61.165.146:22449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YhRXES7Mv0Zfga-klnAAAAM4"]
[Mon Jul 20 06:45:57.267219 2026] [security2:error] [pid 1011111:tid 1011329] [client 34.73.38.214:58046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YhRXES7Mv0Zfga-klpAAAANw"]
[Mon Jul 20 06:45:57.287597 2026] [security2:error] [pid 1011111:tid 1011366] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-includes/blocks/index.php"] [unique_id "al4YhRXES7Mv0Zfga-klowAAAQE"]
[Mon Jul 20 06:45:57.290536 2026] [security2:error] [pid 1014214:tid 1014381] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-includes/blocks/"] [unique_id "al4YhQuRBFTcQNywdCIYDQAAAbQ"]
[Mon Jul 20 06:45:57.371374 2026] [security2:error] [pid 1014214:tid 1014355] [client 89.58.73.111:56392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhQuRBFTcQNywdCIYEAAAAZo"]
[Mon Jul 20 06:45:57.382571 2026] [security2:error] [pid 1014214:tid 1014348] [client 117.247.108.24:23738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YhQuRBFTcQNywdCIYGQAAAZM"]
[Mon Jul 20 06:45:57.382683 2026] [security2:error] [pid 1014214:tid 1014348] [client 117.247.108.24:23738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YhQuRBFTcQNywdCIYGQAAAZM"]
[Mon Jul 20 06:45:57.395345 2026] [security2:error] [pid 1014214:tid 1014258] [remote 97.74.87.194:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YhQuRBFTcQNywdCIYGwAB2is"]
[Mon Jul 20 06:45:57.420532 2026] [security2:error] [pid 1011111:tid 1011274] [client 14.225.17.146:63362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4YhRXES7Mv0Zfga-klnQAAAKU"], referer: http://longevityperformanceclinic.com/New
[Mon Jul 20 06:45:57.454020 2026] [security2:error] [pid 1014214:tid 1014373] [client 86.110.51.41:33106] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "savilerowtravel.com"] [uri "/.env"] [unique_id "al4YhQuRBFTcQNywdCIYIwAAAaw"]
[Mon Jul 20 06:45:57.454212 2026] [autoindex:error] [pid 1014214:tid 1014382] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:57.454692 2026] [security2:error] [pid 1014214:tid 1014382] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhQuRBFTcQNywdCIYIgAAAbU"]
[Mon Jul 20 06:45:57.457139 2026] [security2:error] [pid 1014214:tid 1014444] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/certificates/"] [unique_id "al4YhQuRBFTcQNywdCIYIAAAAfM"]
[Mon Jul 20 06:45:57.518215 2026] [security2:error] [pid 1014214:tid 1014250] [remote 20.173.88.122:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YhQuRBFTcQNywdCIYJQAB9iM"]
[Mon Jul 20 06:45:57.530533 2026] [security2:error] [pid 1014214:tid 1014363] [client 89.58.73.111:38739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhQuRBFTcQNywdCIYHwAAAaI"]
[Mon Jul 20 06:45:57.627589 2026] [autoindex:error] [pid 1011111:tid 1011337] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:57.628066 2026] [security2:error] [pid 1011111:tid 1011337] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhRXES7Mv0Zfga-klrwAAAOQ"]
[Mon Jul 20 06:45:57.630305 2026] [security2:error] [pid 1014214:tid 1014458] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/customize/"] [unique_id "al4YhQuRBFTcQNywdCIYKgAAAgE"]
[Mon Jul 20 06:45:57.795935 2026] [autoindex:error] [pid 1014214:tid 1014403] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:57.796454 2026] [security2:error] [pid 1014214:tid 1014403] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhQuRBFTcQNywdCIYNgAAAco"]
[Mon Jul 20 06:45:57.797766 2026] [security2:error] [pid 1014214:tid 1014356] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/fonts/"] [unique_id "al4YhQuRBFTcQNywdCIYNAAAAZs"]
[Mon Jul 20 06:45:57.817455 2026] [security2:error] [pid 1011111:tid 1011254] [client 223.185.13.213:22804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YhRXES7Mv0Zfga-kltAAAAJE"]
[Mon Jul 20 06:45:57.817606 2026] [security2:error] [pid 1011111:tid 1011254] [client 223.185.13.213:22804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YhRXES7Mv0Zfga-kltAAAAJE"]
[Mon Jul 20 06:45:57.853849 2026] [security2:error] [pid 1014214:tid 1014352] [client 34.73.38.214:54014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YhQuRBFTcQNywdCIYPQAAAZc"]
[Mon Jul 20 06:45:57.859124 2026] [security2:error] [pid 1014214:tid 1014219] [remote 97.74.87.194:53700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YhQuRBFTcQNywdCIYPwABrAQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:45:57.865004 2026] [security2:error] [pid 1014214:tid 1014339] [remote 20.173.88.122:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YhQuRBFTcQNywdCIYQAAB13w"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:45:57.870589 2026] [security2:error] [pid 1011111:tid 1011358] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4YhRXES7Mv0Zfga-klrgAA-Xs"], referer: http://aleishapenny.ca/New
[Mon Jul 20 06:45:57.937762 2026] [security2:error] [pid 1014214:tid 1014386] [client 14.225.17.146:60401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4YhQuRBFTcQNywdCIYMQAAAbk"], referer: http://sesamegreenbeans.com/New
[Mon Jul 20 06:45:57.981226 2026] [autoindex:error] [pid 1014214:tid 1014420] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:57.981946 2026] [security2:error] [pid 1014214:tid 1014420] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhQuRBFTcQNywdCIYRwAAAds"]
[Mon Jul 20 06:45:57.984245 2026] [security2:error] [pid 1014214:tid 1014432] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/images/"] [unique_id "al4YhQuRBFTcQNywdCIYRQAAAec"]
[Mon Jul 20 06:45:58.015776 2026] [security2:error] [pid 1011111:tid 1011261] [client 14.225.17.146:63429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4YhRXES7Mv0Zfga-kltgAAAJg"], referer: http://colinkeyphotography.com/New
[Mon Jul 20 06:45:58.166524 2026] [autoindex:error] [pid 1014214:tid 1014357] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:58.169081 2026] [security2:error] [pid 1014214:tid 1014357] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhguRBFTcQNywdCIYUAAAAZw"]
[Mon Jul 20 06:45:58.173819 2026] [security2:error] [pid 1014214:tid 1014428] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/.well-known/"] [unique_id "al4YhguRBFTcQNywdCIYTQAAAeM"]
[Mon Jul 20 06:45:58.234317 2026] [security2:error] [pid 1014214:tid 1014423] [client 57.141.18.57:51710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YgQuRBFTcQNywdCIXMwAB3h0"]
[Mon Jul 20 06:45:58.315488 2026] [security2:error] [pid 1014214:tid 1014415] [client 14.225.17.146:60381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4YhAuRBFTcQNywdCIX3QAAAdY"], referer: http://according2plant.com/New
[Mon Jul 20 06:45:58.395876 2026] [security2:error] [pid 1014214:tid 1014389] [client 57.141.18.89:44612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YgQuRBFTcQNywdCIXPAABvAE"]
[Mon Jul 20 06:45:58.455890 2026] [security2:error] [pid 1011111:tid 1011307] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-klxgAAAMY"]
[Mon Jul 20 06:45:58.455913 2026] [security2:error] [pid 1011111:tid 1011307] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-klxgAAAMY"]
[Mon Jul 20 06:45:58.457435 2026] [security2:error] [pid 1011111:tid 1011249] [client 86.110.51.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-klwAAAAIw"]
[Mon Jul 20 06:45:58.462389 2026] [security2:error] [pid 1014214:tid 1014386] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/ALFA_DATA/"] [unique_id "al4YhguRBFTcQNywdCIYWwAAAbk"]
[Mon Jul 20 06:45:58.599258 2026] [security2:error] [pid 1014214:tid 1014446] [client 104.234.53.56:36107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YhguRBFTcQNywdCIYZQAAAfU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:45:58.651464 2026] [security2:error] [pid 1014214:tid 1014464] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4YhguRBFTcQNywdCIYYgACB3g"], referer: https://aleishapenny.ca/New
[Mon Jul 20 06:45:58.682178 2026] [security2:error] [pid 1011111:tid 1011246] [client 34.73.38.214:63741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ial.nce.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YhhXES7Mv0Zfga-kl5AAAAIk"]
[Mon Jul 20 06:45:58.743977 2026] [security2:error] [pid 1014214:tid 1014429] [client 37.52.210.45:58747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YhguRBFTcQNywdCIYaAAAAeQ"]
[Mon Jul 20 06:45:58.744087 2026] [security2:error] [pid 1014214:tid 1014429] [client 37.52.210.45:58747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YhguRBFTcQNywdCIYaAAAAeQ"]
[Mon Jul 20 06:45:58.747505 2026] [security2:error] [pid 1011111:tid 1011340] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-kl4gAAAOc"]
[Mon Jul 20 06:45:58.747526 2026] [security2:error] [pid 1011111:tid 1011340] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-kl4gAAAOc"]
[Mon Jul 20 06:45:58.771563 2026] [security2:error] [pid 1014214:tid 1014403] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/.well-knownold/"] [unique_id "al4YhguRBFTcQNywdCIYZgAAAco"]
[Mon Jul 20 06:45:58.798915 2026] [security2:error] [pid 1014214:tid 1014388] [client 3.67.192.83:11332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YhguRBFTcQNywdCIYaQAAAbs"]
[Mon Jul 20 06:45:58.799000 2026] [security2:error] [pid 1014214:tid 1014388] [client 3.67.192.83:11332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YhguRBFTcQNywdCIYaQAAAbs"]
[Mon Jul 20 06:45:58.845216 2026] [security2:error] [pid 1011111:tid 1011184] [remote 167.233.114.32:39064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YhhXES7Mv0Zfga-kl7wAA4kc"]
[Mon Jul 20 06:45:58.903477 2026] [security2:error] [pid 1011111:tid 1011341] [client 14.225.17.146:60374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-kl6wAAAOg"], referer: http://vinovinhowine.com/New
[Mon Jul 20 06:45:58.934610 2026] [security2:error] [pid 1011111:tid 1011247] [client 14.225.17.146:60397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-kl7QAAAIo"], referer: https://sesamegreenbeans.com/New
[Mon Jul 20 06:45:58.983414 2026] [autoindex:error] [pid 1011111:tid 1011251] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:45:58.983896 2026] [security2:error] [pid 1011111:tid 1011251] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhhXES7Mv0Zfga-kl9gAAAI4"]
[Mon Jul 20 06:45:59.000564 2026] [security2:error] [pid 1014214:tid 1014430] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/.well-known/acme-challenge/"] [unique_id "al4YhguRBFTcQNywdCIYcgAAAeU"]
[Mon Jul 20 06:45:59.176485 2026] [cgid:error] [pid 1014214:tid 1014458] [client 143.244.57.118:0] AH01265: stderr from /home1/whytuomy/public_html/website_55cf0d41/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 06:45:59.177289 2026] [security2:error] [pid 1014214:tid 1014458] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YhwuRBFTcQNywdCIYfwAAAgE"]
[Mon Jul 20 06:45:59.186720 2026] [security2:error] [pid 1014214:tid 1014396] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/cgi-bin/"] [unique_id "al4YhwuRBFTcQNywdCIYfAAAAcM"]
[Mon Jul 20 06:45:59.226135 2026] [security2:error] [pid 1011111:tid 1011146] [remote 57.141.18.19:42828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4321570"] [unique_id "al4YhxXES7Mv0Zfga-kl_QABASE"]
[Mon Jul 20 06:45:59.359870 2026] [security2:error] [pid 1011111:tid 1011138] [remote 167.233.114.32:39064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YhxXES7Mv0Zfga-kmAQAAixk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:45:59.415273 2026] [security2:error] [pid 1014214:tid 1014414] [client 86.110.51.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYdgAAAdU"]
[Mon Jul 20 06:45:59.471455 2026] [security2:error] [pid 1014214:tid 1014433] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYhQAAAeg"]
[Mon Jul 20 06:45:59.471480 2026] [security2:error] [pid 1014214:tid 1014433] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYhQAAAeg"]
[Mon Jul 20 06:45:59.518076 2026] [security2:error] [pid 1014214:tid 1014435] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index/"] [unique_id "al4YhwuRBFTcQNywdCIYgwAAAeo"]
[Mon Jul 20 06:45:59.551035 2026] [security2:error] [pid 1011111:tid 1011270] [client 57.141.18.39:49843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YgxXES7Mv0Zfga-klSgAAoWI"]
[Mon Jul 20 06:45:59.662339 2026] [security2:error] [pid 1014214:tid 1014370] [client 57.141.18.82:20872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YgwuRBFTcQNywdCIXhgABqQc"]
[Mon Jul 20 06:45:59.795585 2026] [security2:error] [pid 1014214:tid 1014356] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYqwAAAZs"]
[Mon Jul 20 06:45:59.795608 2026] [security2:error] [pid 1014214:tid 1014356] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYqwAAAZs"]
[Mon Jul 20 06:45:59.798189 2026] [security2:error] [pid 1014214:tid 1014358] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/id/"] [unique_id "al4YhwuRBFTcQNywdCIYpwAAAZ0"]
[Mon Jul 20 06:46:00.088480 2026] [security2:error] [pid 1014214:tid 1014437] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYwAAAAew"]
[Mon Jul 20 06:46:00.088504 2026] [security2:error] [pid 1014214:tid 1014437] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYwAAAAew"]
[Mon Jul 20 06:46:00.093971 2026] [security2:error] [pid 1014214:tid 1014396] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/www/"] [unique_id "al4YhwuRBFTcQNywdCIYvQAAAcM"]
[Mon Jul 20 06:46:00.147774 2026] [security2:error] [pid 1011111:tid 1011368] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhBXES7Mv0Zfga-klbgAAAQM"]
[Mon Jul 20 06:46:00.297456 2026] [security2:error] [pid 1011111:tid 1011247] [client 86.110.51.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YiBXES7Mv0Zfga-kmDwAAAIo"]
[Mon Jul 20 06:46:00.391058 2026] [security2:error] [pid 1011111:tid 1011366] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiBXES7Mv0Zfga-kmGgAAAQE"]
[Mon Jul 20 06:46:00.391081 2026] [security2:error] [pid 1011111:tid 1011366] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiBXES7Mv0Zfga-kmGgAAAQE"]
[Mon Jul 20 06:46:00.411679 2026] [security2:error] [pid 1014214:tid 1014356] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/web/"] [unique_id "al4YiAuRBFTcQNywdCIY1QAAAZs"]
[Mon Jul 20 06:46:00.533665 2026] [security2:error] [pid 1014214:tid 1014453] [client 34.74.185.202:64593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YiAuRBFTcQNywdCIY5wAAAfw"]
[Mon Jul 20 06:46:00.533808 2026] [security2:error] [pid 1014214:tid 1014453] [client 34.74.185.202:64593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YiAuRBFTcQNywdCIY5wAAAfw"]
[Mon Jul 20 06:46:00.584789 2026] [security2:error] [pid 1014214:tid 1014278] [remote 5.252.52.249:40154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YiAuRBFTcQNywdCIY6QABpj8"]
[Mon Jul 20 06:46:00.711421 2026] [security2:error] [pid 1011111:tid 1011352] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiBXES7Mv0Zfga-kmHwAAAPM"]
[Mon Jul 20 06:46:00.711448 2026] [security2:error] [pid 1011111:tid 1011352] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiBXES7Mv0Zfga-kmHwAAAPM"]
[Mon Jul 20 06:46:00.746246 2026] [security2:error] [pid 1014214:tid 1014350] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/uploads/"] [unique_id "al4YiAuRBFTcQNywdCIY6AAAAZU"]
[Mon Jul 20 06:46:00.777857 2026] [security2:error] [pid 1014214:tid 1014263] [remote 5.252.52.249:40154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YiAuRBFTcQNywdCIY8wABvzA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:46:00.907063 2026] [security2:error] [pid 1014214:tid 1014440] [client 77.110.127.138:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/pro/css/fields/phone/p3g67rjlb8dk.php"] [unique_id "al4YiAuRBFTcQNywdCIZAQAAAe8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:00.973866 2026] [autoindex:error] [pid 1014214:tid 1014383] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/pro/css/fields/phone/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 06:46:00.985519 2026] [security2:error] [pid 1014214:tid 1014432] [client 77.110.127.138:54919] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YiAuRBFTcQNywdCIZEwAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:01.053192 2026] [security2:error] [pid 1014214:tid 1014426] [client 54.169.146.187:39440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YiQuRBFTcQNywdCIZFwAAAeE"]
[Mon Jul 20 06:46:01.055145 2026] [security2:error] [pid 1014214:tid 1014351] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiAuRBFTcQNywdCIY_gAAAZY"]
[Mon Jul 20 06:46:01.055171 2026] [security2:error] [pid 1014214:tid 1014351] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiAuRBFTcQNywdCIY_gAAAZY"]
[Mon Jul 20 06:46:01.064210 2026] [security2:error] [pid 1014214:tid 1014373] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/upload/"] [unique_id "al4YiAuRBFTcQNywdCIY_QAAAaw"]
[Mon Jul 20 06:46:01.181377 2026] [security2:error] [pid 1014214:tid 1014394] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhQuRBFTcQNywdCIYBQAAAcE"]
[Mon Jul 20 06:46:01.238047 2026] [security2:error] [pid 1014214:tid 1014463] [client 86.110.51.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YiAuRBFTcQNywdCIY-AAAAgY"]
[Mon Jul 20 06:46:01.293803 2026] [security2:error] [pid 1014214:tid 1014469] [client 39.48.81.23:58813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YiQuRBFTcQNywdCIZLwAAAgw"]
[Mon Jul 20 06:46:01.293916 2026] [security2:error] [pid 1014214:tid 1014469] [client 39.48.81.23:58813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YiQuRBFTcQNywdCIZLwAAAgw"]
[Mon Jul 20 06:46:01.356173 2026] [security2:error] [pid 1014214:tid 1014345] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZJAAAAZA"]
[Mon Jul 20 06:46:01.356198 2026] [security2:error] [pid 1014214:tid 1014345] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZJAAAAZA"]
[Mon Jul 20 06:46:01.363978 2026] [security2:error] [pid 1014214:tid 1014350] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/admin/uploads/"] [unique_id "al4YiQuRBFTcQNywdCIZIAAAAZU"]
[Mon Jul 20 06:46:01.406962 2026] [security2:error] [pid 1011111:tid 1011252] [client 57.141.18.16:26332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhRXES7Mv0Zfga-kllwAAjzY"]
[Mon Jul 20 06:46:01.407610 2026] [security2:error] [pid 1014214:tid 1014337] [remote 217.61.143.92:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YiQuRBFTcQNywdCIZNwABnXo"]
[Mon Jul 20 06:46:01.459901 2026] [security2:error] [pid 1014214:tid 1014249] [remote 152.228.213.32:41826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YiQuRBFTcQNywdCIZOQAB7CI"]
[Mon Jul 20 06:46:01.460176 2026] [security2:error] [pid 1014214:tid 1014437] [client 152.228.213.32:41826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YiQuRBFTcQNywdCIZOQAB7CI"]
[Mon Jul 20 06:46:01.494710 2026] [security2:error] [pid 1014214:tid 1014360] [client 114.119.152.34:26487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whiteoutcb.com"] [uri "/careers/"] [unique_id "al4YiQuRBFTcQNywdCIZPgAAAZ8"], referer: http://whiteoutcb.com/
[Mon Jul 20 06:46:01.650144 2026] [security2:error] [pid 1014214:tid 1014302] [remote 217.61.143.92:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YiQuRBFTcQNywdCIZTQABzFc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:46:01.650848 2026] [security2:error] [pid 1014214:tid 1014416] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZRAAAAdc"]
[Mon Jul 20 06:46:01.650868 2026] [security2:error] [pid 1014214:tid 1014416] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZRAAAAdc"]
[Mon Jul 20 06:46:01.652783 2026] [security2:error] [pid 1014214:tid 1014400] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/Admin/uploads/"] [unique_id "al4YiQuRBFTcQNywdCIZPwAAAcc"]
[Mon Jul 20 06:46:01.797485 2026] [security2:error] [pid 1011111:tid 1011337] [client 86.110.51.41:33904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "savilerowtravel.com"] [uri "/blog/.env"] [unique_id "al4YiRXES7Mv0Zfga-kmSgAAAOQ"]
[Mon Jul 20 06:46:01.828771 2026] [security2:error] [pid 1014214:tid 1014427] [client 77.110.127.138:54782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiAuRBFTcQNywdCIZAAAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:01.905010 2026] [security2:error] [pid 1014214:tid 1014470] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZWAAAAg0"]
[Mon Jul 20 06:46:01.905038 2026] [security2:error] [pid 1014214:tid 1014470] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZWAAAAg0"]
[Mon Jul 20 06:46:01.907241 2026] [security2:error] [pid 1014214:tid 1014346] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/admin/"] [unique_id "al4YiQuRBFTcQNywdCIZVQAAAZE"]
[Mon Jul 20 06:46:02.058098 2026] [security2:error] [pid 1014214:tid 1014468] [client 57.141.18.107:27930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhQuRBFTcQNywdCIYLwACC0M"]
[Mon Jul 20 06:46:02.101309 2026] [security2:error] [pid 1011111:tid 1011344] [client 18.141.57.241:27056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YihXES7Mv0Zfga-kmUwAAAOs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:46:02.129438 2026] [security2:error] [pid 1014214:tid 1014402] [client 192.140.149.97:46035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YiguRBFTcQNywdCIZZAAAAck"]
[Mon Jul 20 06:46:02.129558 2026] [security2:error] [pid 1014214:tid 1014402] [client 192.140.149.97:46035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YiguRBFTcQNywdCIZZAAAAck"]
[Mon Jul 20 06:46:02.221919 2026] [security2:error] [pid 1014214:tid 1014447] [client 112.208.70.94:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YiguRBFTcQNywdCIZaAAAAfY"]
[Mon Jul 20 06:46:02.222015 2026] [security2:error] [pid 1014214:tid 1014447] [client 112.208.70.94:43400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YiguRBFTcQNywdCIZaAAAAfY"]
[Mon Jul 20 06:46:02.374393 2026] [security2:error] [pid 1011111:tid 1011359] [client 86.110.51.41:34218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "savilerowtravel.com"] [uri "/api/.env"] [unique_id "al4YihXES7Mv0Zfga-kmXQAAAPo"]
[Mon Jul 20 06:46:02.385098 2026] [security2:error] [pid 1014214:tid 1014385] [client 57.141.18.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YiguRBFTcQNywdCIZaQAAAbg"]
[Mon Jul 20 06:46:02.415742 2026] [security2:error] [pid 1014214:tid 1014396] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiAuRBFTcQNywdCIZDgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:02.425352 2026] [security2:error] [pid 1011111:tid 1011254] [client 87.199.196.160:64848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.justinagrayman.com"] [uri "/wp-comments-post.php"] [unique_id "al4YihXES7Mv0Zfga-kmXgAAAJE"], referer: https://www.justinagrayman.com/slide8/
[Mon Jul 20 06:46:02.425526 2026] [security2:error] [pid 1011111:tid 1011254] [client 87.199.196.160:64848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.justinagrayman.com"] [uri "/wp-comments-post.php"] [unique_id "al4YihXES7Mv0Zfga-kmXgAAAJE"], referer: https://www.justinagrayman.com/slide8/
[Mon Jul 20 06:46:02.609787 2026] [security2:error] [pid 1011111:tid 1011257] [client 104.234.53.85:64935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YihXES7Mv0Zfga-kmYQAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:02.816200 2026] [security2:error] [pid 1014214:tid 1014459] [client 143.244.57.118:52032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/index.php"] [unique_id "al4YiguRBFTcQNywdCIZegAAAgI"]
[Mon Jul 20 06:46:02.939090 2026] [security2:error] [pid 1011111:tid 1011276] [client 86.110.51.41:34456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "savilerowtravel.com"] [uri "/laravel/.env"] [unique_id "al4YihXES7Mv0Zfga-kmbQAAAKc"]
[Mon Jul 20 06:46:02.986524 2026] [security2:error] [pid 1014214:tid 1014389] [client 143.244.57.118:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YiguRBFTcQNywdCIZmwAAAbw"]
[Mon Jul 20 06:46:02.986640 2026] [security2:error] [pid 1014214:tid 1014389] [client 143.244.57.118:52032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YiguRBFTcQNywdCIZmwAAAbw"]
[Mon Jul 20 06:46:03.058159 2026] [security2:error] [pid 1014214:tid 1014445] [client 50.116.65.227:19646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YiwuRBFTcQNywdCIZnwAAAfQ"]
[Mon Jul 20 06:46:03.071793 2026] [security2:error] [pid 1014214:tid 1014368] [client 50.116.65.227:19658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YiwuRBFTcQNywdCIZoQAAAac"]
[Mon Jul 20 06:46:03.119401 2026] [security2:error] [pid 1014214:tid 1014378] [client 77.110.127.138:54978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/design/7zrwkemvs2qv.php"] [unique_id "al4YiwuRBFTcQNywdCIZqwAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:03.191313 2026] [security2:error] [pid 1014214:tid 1014388] [client 57.141.18.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplecleaningandhomecare.ca"] [uri "/index.php"] [unique_id "al4YiguRBFTcQNywdCIZlQAAAbs"]
[Mon Jul 20 06:46:03.206697 2026] [security2:error] [pid 1014214:tid 1014448] [client 104.207.52.134:41143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YiwuRBFTcQNywdCIZtgAAAfc"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:03.219401 2026] [security2:error] [pid 1014214:tid 1014387] [client 14.225.17.146:63207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4YiguRBFTcQNywdCIZiwAAAbo"]
[Mon Jul 20 06:46:03.234953 2026] [security2:error] [pid 1014214:tid 1014386] [client 14.225.17.146:49924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4YiguRBFTcQNywdCIZlwAAAbk"], referer: http://massagelacey.com/New
[Mon Jul 20 06:46:03.296300 2026] [security2:error] [pid 1011111:tid 1011243] [client 57.141.18.16:26340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhhXES7Mv0Zfga-kl6QAAhnY"]
[Mon Jul 20 06:46:03.325709 2026] [security2:error] [pid 1014214:tid 1014462] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZtAAAAgU"]
[Mon Jul 20 06:46:03.325758 2026] [security2:error] [pid 1014214:tid 1014462] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZtAAAAgU"]
[Mon Jul 20 06:46:03.327295 2026] [security2:error] [pid 1014214:tid 1014349] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/images/"] [unique_id "al4YiwuRBFTcQNywdCIZsAAAAZQ"]
[Mon Jul 20 06:46:03.380199 2026] [security2:error] [pid 1014214:tid 1014457] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZtQAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:03.412986 2026] [security2:error] [pid 1014214:tid 1014416] [client 77.110.127.138:54980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZsQAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:03.440616 2026] [security2:error] [pid 1011111:tid 1011281] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YixXES7Mv0Zfga-kmggAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:03.530933 2026] [security2:error] [pid 1014214:tid 1014444] [client 86.110.51.41:60902] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "savilerowtravel.com"] [uri "/docs/.env"] [unique_id "al4YiwuRBFTcQNywdCIZzQAAAfM"]
[Mon Jul 20 06:46:03.580663 2026] [security2:error] [pid 1014214:tid 1014308] [remote 57.141.18.28:37686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4YiwuRBFTcQNywdCIZ0wABw10"]
[Mon Jul 20 06:46:03.595897 2026] [core:error] [pid 1014214:tid 1014430] [client 14.225.17.146:63193] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/New
[Mon Jul 20 06:46:03.595915 2026] [core:error] [pid 1014214:tid 1014430] [client 14.225.17.146:63193] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/New
[Mon Jul 20 06:46:03.624080 2026] [security2:error] [pid 1014214:tid 1014440] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZywAAAe8"]
[Mon Jul 20 06:46:03.624106 2026] [security2:error] [pid 1014214:tid 1014440] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZywAAAe8"]
[Mon Jul 20 06:46:03.630826 2026] [security2:error] [pid 1014214:tid 1014425] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/assets/"] [unique_id "al4YiwuRBFTcQNywdCIZyQAAAeA"]
[Mon Jul 20 06:46:03.731631 2026] [security2:error] [pid 1014214:tid 1014348] [client 77.110.127.138:54919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-motif/4cvrax7nrkee.php"] [unique_id "al4YiwuRBFTcQNywdCIZ4AAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:03.763821 2026] [security2:error] [pid 1014214:tid 1014244] [remote 57.141.18.44:42704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4YiwuRBFTcQNywdCIZ4wAB_h0"]
[Mon Jul 20 06:46:03.914691 2026] [security2:error] [pid 1011111:tid 1011326] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YixXES7Mv0Zfga-kmkgAAANk"]
[Mon Jul 20 06:46:03.914718 2026] [security2:error] [pid 1011111:tid 1011326] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YixXES7Mv0Zfga-kmkgAAANk"]
[Mon Jul 20 06:46:03.921902 2026] [security2:error] [pid 1014214:tid 1014467] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "al4YiwuRBFTcQNywdCIZ5QAAAgo"]
[Mon Jul 20 06:46:03.976421 2026] [security2:error] [pid 1011111:tid 1011275] [client 103.238.106.162:42938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YixXES7Mv0Zfga-kmlwAAAKY"]
[Mon Jul 20 06:46:03.976502 2026] [security2:error] [pid 1011111:tid 1011275] [client 103.238.106.162:42938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YixXES7Mv0Zfga-kmlwAAAKY"]
[Mon Jul 20 06:46:04.053313 2026] [security2:error] [pid 1014214:tid 1014361] [client 77.110.127.138:54779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YjAuRBFTcQNywdCIZ_AAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:04.053432 2026] [security2:error] [pid 1014214:tid 1014361] [client 77.110.127.138:54779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YjAuRBFTcQNywdCIZ_AAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:04.097085 2026] [security2:error] [pid 1011111:tid 1011357] [client 45.3.34.17:21331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YjBXES7Mv0Zfga-kmmwAAAPg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:04.113664 2026] [security2:error] [pid 1011111:tid 1011161] [remote 154.61.75.100:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4YjBXES7Mv0Zfga-kmnQAA-zA"]
[Mon Jul 20 06:46:04.200323 2026] [security2:error] [pid 1014214:tid 1014421] [client 14.225.17.146:64916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIZ-wAAAdw"], referer: http://www.justinagrayman.com/New
[Mon Jul 20 06:46:04.224980 2026] [security2:error] [pid 1014214:tid 1014373] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaAgAAAaw"]
[Mon Jul 20 06:46:04.225017 2026] [security2:error] [pid 1014214:tid 1014373] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaAgAAAaw"]
[Mon Jul 20 06:46:04.240331 2026] [security2:error] [pid 1014214:tid 1014353] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/upload/image/"] [unique_id "al4YjAuRBFTcQNywdCIaAAAAAZg"]
[Mon Jul 20 06:46:04.305355 2026] [security2:error] [pid 1014214:tid 1014350] [client 77.110.127.138:54782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZ4gAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:04.330038 2026] [security2:error] [pid 1014214:tid 1014357] [client 57.141.18.63:49598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YhwuRBFTcQNywdCIYsAABnFs"]
[Mon Jul 20 06:46:04.338226 2026] [security2:error] [pid 1014214:tid 1014470] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZ5AAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:04.360137 2026] [security2:error] [pid 1014214:tid 1014432] [client 86.110.51.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaCQAAAec"]
[Mon Jul 20 06:46:04.457633 2026] [access_compat:error] [pid 1014214:tid 1014235] [remote 185.44.74.153:58126] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:04.480579 2026] [security2:error] [pid 1011111:tid 1011291] [client 104.234.53.85:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YjBXES7Mv0Zfga-kmpgAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:04.524229 2026] [security2:error] [pid 1014214:tid 1014405] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaGQAAAcw"]
[Mon Jul 20 06:46:04.524261 2026] [security2:error] [pid 1014214:tid 1014405] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaGQAAAcw"]
[Mon Jul 20 06:46:04.543788 2026] [security2:error] [pid 1014214:tid 1014387] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/assets/images/"] [unique_id "al4YjAuRBFTcQNywdCIaFwAAAbo"]
[Mon Jul 20 06:46:04.621869 2026] [security2:error] [pid 1011111:tid 1011263] [client 217.142.18.172:34184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YjBXES7Mv0Zfga-kmqwAAAJo"]
[Mon Jul 20 06:46:04.625695 2026] [security2:error] [pid 1011111:tid 1011263] [client 217.142.18.172:34184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YjBXES7Mv0Zfga-kmqwAAAJo"]
[Mon Jul 20 06:46:04.645738 2026] [security2:error] [pid 1014214:tid 1014359] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZ9QAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:04.740391 2026] [security2:error] [pid 1011111:tid 1011180] [remote 154.61.75.100:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4YjBXES7Mv0Zfga-kmsAAAo0M"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 06:46:04.821799 2026] [security2:error] [pid 1014214:tid 1014411] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaLQAAAdI"]
[Mon Jul 20 06:46:04.821822 2026] [security2:error] [pid 1014214:tid 1014411] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaLQAAAdI"]
[Mon Jul 20 06:46:04.834505 2026] [security2:error] [pid 1014214:tid 1014409] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/Public/"] [unique_id "al4YjAuRBFTcQNywdCIaKwAAAdA"]
[Mon Jul 20 06:46:04.869027 2026] [security2:error] [pid 1011111:tid 1011349] [client 77.110.127.138:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/easy/fszd0uggppf0.php"] [unique_id "al4YjBXES7Mv0Zfga-kmtgAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:04.910483 2026] [security2:error] [pid 1011111:tid 1011261] [client 45.3.33.184:55877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.33.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YjBXES7Mv0Zfga-kmtQAAAJg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:04.948879 2026] [security2:error] [pid 1014214:tid 1014410] [client 103.125.179.95:55786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YjAuRBFTcQNywdCIaPwAAAdE"]
[Mon Jul 20 06:46:04.949009 2026] [security2:error] [pid 1014214:tid 1014410] [client 103.125.179.95:55786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YjAuRBFTcQNywdCIaPwAAAdE"]
[Mon Jul 20 06:46:04.986115 2026] [security2:error] [pid 1014214:tid 1014433] [client 187.108.85.186:57182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YjAuRBFTcQNywdCIaQgAAAeg"]
[Mon Jul 20 06:46:04.986228 2026] [security2:error] [pid 1014214:tid 1014433] [client 187.108.85.186:57182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YjAuRBFTcQNywdCIaQgAAAeg"]
[Mon Jul 20 06:46:05.085491 2026] [security2:error] [pid 1014214:tid 1014397] [client 216.73.216.229:29108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaRAABxBI"]
[Mon Jul 20 06:46:05.120544 2026] [security2:error] [pid 1014214:tid 1014399] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaTgAAAcY"]
[Mon Jul 20 06:46:05.120577 2026] [security2:error] [pid 1014214:tid 1014399] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaTgAAAcY"]
[Mon Jul 20 06:46:05.123158 2026] [security2:error] [pid 1014214:tid 1014386] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/vendor/"] [unique_id "al4YjAuRBFTcQNywdCIaRgAAAbk"]
[Mon Jul 20 06:46:05.197967 2026] [security2:error] [pid 1011111:tid 1011246] [client 77.110.127.138:54981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjBXES7Mv0Zfga-kmtwAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:05.200589 2026] [security2:error] [pid 1014214:tid 1014389] [client 86.110.51.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaNQAAAbw"]
[Mon Jul 20 06:46:05.259407 2026] [security2:error] [pid 1014214:tid 1014363] [client 77.110.127.138:54976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YjQuRBFTcQNywdCIaZAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:05.273158 2026] [security2:error] [pid 1011111:tid 1011151] [remote 162.19.86.63:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YjRXES7Mv0Zfga-kmxAAAlyY"]
[Mon Jul 20 06:46:05.293065 2026] [security2:error] [pid 1014214:tid 1014423] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaPQAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:05.343916 2026] [security2:error] [pid 1014214:tid 1014453] [client 216.73.216.229:29108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaYgAB_Ds"], referer: https://www.iagdevelopments.com/sitemap.xml
[Mon Jul 20 06:46:05.344089 2026] [security2:error] [pid 1014214:tid 1014408] [client 57.141.18.70:43454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiAuRBFTcQNywdCIY-gABz2A"]
[Mon Jul 20 06:46:05.348098 2026] [security2:error] [pid 1014214:tid 1014373] [client 183.82.98.154:63331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YjQuRBFTcQNywdCIabwAAAaw"]
[Mon Jul 20 06:46:05.348258 2026] [security2:error] [pid 1014214:tid 1014373] [client 183.82.98.154:63331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YjQuRBFTcQNywdCIabwAAAaw"]
[Mon Jul 20 06:46:05.432084 2026] [security2:error] [pid 1014214:tid 1014444] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaawAAAfM"]
[Mon Jul 20 06:46:05.432110 2026] [security2:error] [pid 1014214:tid 1014444] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaawAAAfM"]
[Mon Jul 20 06:46:05.436071 2026] [security2:error] [pid 1014214:tid 1014447] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/local/"] [unique_id "al4YjQuRBFTcQNywdCIaZgAAAfY"]
[Mon Jul 20 06:46:05.476866 2026] [security2:error] [pid 1011111:tid 1011195] [remote 162.19.86.63:53018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YjRXES7Mv0Zfga-kmzQAA2VI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:46:05.508528 2026] [security2:error] [pid 1014214:tid 1014285] [remote 217.61.143.92:37570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YjQuRBFTcQNywdCIaewABzkY"]
[Mon Jul 20 06:46:05.545204 2026] [security2:error] [pid 1014214:tid 1014418] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaVAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:05.551809 2026] [security2:error] [pid 1011111:tid 1011298] [client 57.141.18.61:34356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiRXES7Mv0Zfga-kmNwAAvQ0"]
[Mon Jul 20 06:46:05.558007 2026] [security2:error] [pid 1014214:tid 1014366] [client 57.141.18.28:46610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZGAABpWM"]
[Mon Jul 20 06:46:05.734853 2026] [security2:error] [pid 1014214:tid 1014378] [client 197.186.66.42:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YjQuRBFTcQNywdCIamAAAAbE"]
[Mon Jul 20 06:46:05.735536 2026] [security2:error] [pid 1014214:tid 1014252] [remote 217.61.143.92:37570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YjQuRBFTcQNywdCIamQACCSU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:46:05.756273 2026] [security2:error] [pid 1014214:tid 1014378] [client 197.186.66.42:65221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YjQuRBFTcQNywdCIamAAAAbE"]
[Mon Jul 20 06:46:05.760838 2026] [security2:error] [pid 1011111:tid 1011310] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjRXES7Mv0Zfga-km0AAAAMk"]
[Mon Jul 20 06:46:05.760861 2026] [security2:error] [pid 1011111:tid 1011310] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjRXES7Mv0Zfga-km0AAAAMk"]
[Mon Jul 20 06:46:05.763892 2026] [security2:error] [pid 1014214:tid 1014406] [client 77.110.127.138:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-patterns/zdfzamevko5d.php"] [unique_id "al4YjQuRBFTcQNywdCIanQAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:05.765505 2026] [security2:error] [pid 1011111:tid 1011258] [client 57.141.18.20:42250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiRXES7Mv0Zfga-kmPgAAlQI"]
[Mon Jul 20 06:46:05.766941 2026] [security2:error] [pid 1014214:tid 1014381] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/modules/"] [unique_id "al4YjQuRBFTcQNywdCIaggAAAbQ"]
[Mon Jul 20 06:46:05.804553 2026] [security2:error] [pid 1014214:tid 1014374] [client 57.141.18.63:49608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiQuRBFTcQNywdCIZMQABrQo"]
[Mon Jul 20 06:46:05.881599 2026] [security2:error] [pid 1014214:tid 1014411] [client 14.225.17.146:63095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaiwAAAdI"], referer: http://lelandumc.org/New
[Mon Jul 20 06:46:05.968105 2026] [security2:error] [pid 1014214:tid 1014241] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YjQuRBFTcQNywdCIaqwABuRo"]
[Mon Jul 20 06:46:05.968221 2026] [security2:error] [pid 1014214:tid 1014386] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YjQuRBFTcQNywdCIaqwABuRo"]
[Mon Jul 20 06:46:06.064856 2026] [security2:error] [pid 1014214:tid 1014399] [client 14.225.17.146:59541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIafwAAAcY"]
[Mon Jul 20 06:46:06.066008 2026] [security2:error] [pid 1014214:tid 1014372] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaqAAAAas"]
[Mon Jul 20 06:46:06.066021 2026] [security2:error] [pid 1014214:tid 1014372] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIaqAAAAas"]
[Mon Jul 20 06:46:06.105554 2026] [security2:error] [pid 1014214:tid 1014366] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/Site/"] [unique_id "al4YjQuRBFTcQNywdCIapgAAAaU"]
[Mon Jul 20 06:46:06.200839 2026] [security2:error] [pid 1011111:tid 1011315] [client 77.110.127.138:54990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjRXES7Mv0Zfga-km1AAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:06.202028 2026] [security2:error] [pid 1014214:tid 1014367] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIakgAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:06.398866 2026] [security2:error] [pid 1014214:tid 1014420] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIawgAAAds"]
[Mon Jul 20 06:46:06.398891 2026] [security2:error] [pid 1014214:tid 1014420] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIawgAAAds"]
[Mon Jul 20 06:46:06.403975 2026] [security2:error] [pid 1014214:tid 1014376] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/system/"] [unique_id "al4YjguRBFTcQNywdCIawQAAAa8"]
[Mon Jul 20 06:46:06.545855 2026] [security2:error] [pid 1014214:tid 1014348] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIapAAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:06.686868 2026] [security2:error] [pid 1014214:tid 1014349] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIa0QAAAZQ"]
[Mon Jul 20 06:46:06.686910 2026] [security2:error] [pid 1014214:tid 1014349] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIa0QAAAZQ"]
[Mon Jul 20 06:46:06.729235 2026] [security2:error] [pid 1014214:tid 1014397] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/template/"] [unique_id "al4YjguRBFTcQNywdCIazgAAAcQ"]
[Mon Jul 20 06:46:06.790192 2026] [security2:error] [pid 1014214:tid 1014373] [client 152.58.191.29:60117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YjguRBFTcQNywdCIa4AAAAaw"]
[Mon Jul 20 06:46:06.790336 2026] [security2:error] [pid 1014214:tid 1014373] [client 152.58.191.29:60117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YjguRBFTcQNywdCIa4AAAAaw"]
[Mon Jul 20 06:46:07.005862 2026] [security2:error] [pid 1011111:tid 1011300] [client 77.110.127.138:54981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/21/wvzkhtoaukok.php"] [unique_id "al4YjxXES7Mv0Zfga-km-gAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:07.082464 2026] [security2:error] [pid 1014214:tid 1014364] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIa7wAAAaM"]
[Mon Jul 20 06:46:07.097435 2026] [security2:error] [pid 1014214:tid 1014425] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/shop/"] [unique_id "al4YjguRBFTcQNywdCIa6wAAAeA"]
[Mon Jul 20 06:46:07.156957 2026] [security2:error] [pid 1014214:tid 1014398] [client 57.141.18.32:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiguRBFTcQNywdCIZkQABxWk"]
[Mon Jul 20 06:46:07.375860 2026] [security2:error] [pid 1014214:tid 1014463] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjwuRBFTcQNywdCIbBAAAAgY"]
[Mon Jul 20 06:46:07.375882 2026] [security2:error] [pid 1014214:tid 1014463] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YjwuRBFTcQNywdCIbBAAAAgY"]
[Mon Jul 20 06:46:07.418760 2026] [security2:error] [pid 1014214:tid 1014426] [client 57.141.18.115:24220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZpwAB4XQ"]
[Mon Jul 20 06:46:07.422789 2026] [security2:error] [pid 1011111:tid 1011266] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjxXES7Mv0Zfga-km_AAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:07.432689 2026] [security2:error] [pid 1014214:tid 1014418] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/files/"] [unique_id "al4YjwuRBFTcQNywdCIbAQAAAdk"]
[Mon Jul 20 06:46:07.451346 2026] [autoindex:error] [pid 1011111:tid 1011332] [client 167.86.117.252:50997] AH01276: Cannot serve directory /home3/thedocz6/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:46:07.527014 2026] [security2:error] [pid 1014214:tid 1014450] [client 14.225.17.146:59621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIasgAAAfk"], referer: http://dnsplumbing.com/New
[Mon Jul 20 06:46:07.571775 2026] [security2:error] [pid 1014214:tid 1014381] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjwuRBFTcQNywdCIa_AAAAbQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:07.602694 2026] [security2:error] [pid 1011111:tid 1011347] [client 77.110.127.138:55049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YjxXES7Mv0Zfga-knAgAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:07.611349 2026] [security2:error] [pid 1014214:tid 1014400] [client 77.110.127.138:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YjwuRBFTcQNywdCIbEgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:07.611443 2026] [security2:error] [pid 1014214:tid 1014400] [client 77.110.127.138:55016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YjwuRBFTcQNywdCIbEgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:07.752897 2026] [security2:error] [pid 1014214:tid 1014445] [client 57.141.18.103:34052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YiwuRBFTcQNywdCIZ0gAB9AY"]
[Mon Jul 20 06:46:08.074634 2026] [security2:error] [pid 1014214:tid 1014428] [client 171.61.165.146:5677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YkAuRBFTcQNywdCIbLgAAAeM"]
[Mon Jul 20 06:46:08.074777 2026] [security2:error] [pid 1014214:tid 1014428] [client 171.61.165.146:5677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YkAuRBFTcQNywdCIbLgAAAeM"]
[Mon Jul 20 06:46:08.117955 2026] [security2:error] [pid 1014214:tid 1014412] [client 57.141.18.69:34264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIZ_gAB0xs"]
[Mon Jul 20 06:46:08.145426 2026] [security2:error] [pid 1014214:tid 1014420] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbKwAAAds"]
[Mon Jul 20 06:46:08.145457 2026] [security2:error] [pid 1014214:tid 1014420] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbKwAAAds"]
[Mon Jul 20 06:46:08.159662 2026] [security2:error] [pid 1014214:tid 1014406] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/admin/editor/"] [unique_id "al4YjwuRBFTcQNywdCIbKQAAAc0"]
[Mon Jul 20 06:46:08.178778 2026] [security2:error] [pid 1011111:tid 1011172] [remote 84.247.172.23:34416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4YkBXES7Mv0Zfga-knMwAArjs"]
[Mon Jul 20 06:46:08.182911 2026] [security2:error] [pid 1014214:tid 1014357] [client 117.247.108.24:24086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YkAuRBFTcQNywdCIbMgAAAZw"]
[Mon Jul 20 06:46:08.183014 2026] [security2:error] [pid 1014214:tid 1014357] [client 117.247.108.24:24086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YkAuRBFTcQNywdCIbMgAAAZw"]
[Mon Jul 20 06:46:08.255080 2026] [security2:error] [pid 1011111:tid 1011265] [client 40.77.179.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4YkBXES7Mv0Zfga-knMQAAAJw"]
[Mon Jul 20 06:46:08.269594 2026] [access_compat:error] [pid 1014214:tid 1014286] [remote 50.174.1.6:37556] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:08.402377 2026] [security2:error] [pid 1011111:tid 1011132] [remote 84.247.172.23:34416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4YkBXES7Mv0Zfga-knOAAAzxM"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:46:08.433828 2026] [security2:error] [pid 1014214:tid 1014432] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbOgAAAec"]
[Mon Jul 20 06:46:08.433847 2026] [security2:error] [pid 1014214:tid 1014432] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbOgAAAec"]
[Mon Jul 20 06:46:08.439520 2026] [security2:error] [pid 1014214:tid 1014433] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/include/"] [unique_id "al4YkAuRBFTcQNywdCIbNwAAAeg"]
[Mon Jul 20 06:46:08.607108 2026] [security2:error] [pid 1011111:tid 1011300] [client 14.225.17.146:60053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4YkBXES7Mv0Zfga-knOgAAAL8"], referer: http://jvcmotorsports.com/New
[Mon Jul 20 06:46:08.624299 2026] [security2:error] [pid 1014214:tid 1014427] [client 57.141.18.98:39282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaJwAB4mo"]
[Mon Jul 20 06:46:08.740379 2026] [security2:error] [pid 1014214:tid 1014391] [client 14.225.17.146:58709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbSgAAAb4"], referer: http://cheesewithjam.com/New
[Mon Jul 20 06:46:08.750971 2026] [security2:error] [pid 1014214:tid 1014413] [client 57.141.18.57:50794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjAuRBFTcQNywdCIaLwAB1C0"]
[Mon Jul 20 06:46:08.755929 2026] [security2:error] [pid 1014214:tid 1014404] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbTgAAAcs"]
[Mon Jul 20 06:46:08.755958 2026] [security2:error] [pid 1014214:tid 1014404] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbTgAAAcs"]
[Mon Jul 20 06:46:08.789608 2026] [security2:error] [pid 1014214:tid 1014396] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/Assets/"] [unique_id "al4YkAuRBFTcQNywdCIbSwAAAcM"]
[Mon Jul 20 06:46:08.797971 2026] [security2:error] [pid 1014214:tid 1014409] [client 77.110.127.138:54998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YkAuRBFTcQNywdCIbXAAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:08.960001 2026] [security2:error] [pid 1011111:tid 1011359] [client 66.249.73.102:50773] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "test.topspot.com.pk"] [uri "/robots.txt"] [unique_id "al4YkBXES7Mv0Zfga-knUQAAAPo"]
[Mon Jul 20 06:46:09.054826 2026] [security2:error] [pid 1011111:tid 1011249] [client 14.225.17.146:58629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4YkBXES7Mv0Zfga-knOQAAAIw"], referer: http://idigress.studio/New
[Mon Jul 20 06:46:09.073418 2026] [security2:error] [pid 1014214:tid 1014470] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbaQAAAg0"]
[Mon Jul 20 06:46:09.073444 2026] [security2:error] [pid 1014214:tid 1014470] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbaQAAAg0"]
[Mon Jul 20 06:46:09.080914 2026] [security2:error] [pid 1014214:tid 1014375] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/images/stories/"] [unique_id "al4YkAuRBFTcQNywdCIbZwAAAa4"]
[Mon Jul 20 06:46:09.318204 2026] [security2:error] [pid 1014214:tid 1014439] [client 103.194.174.80:49216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YkQuRBFTcQNywdCIbdAAB7nw"]
[Mon Jul 20 06:46:09.357014 2026] [security2:error] [pid 1011111:tid 1011255] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkRXES7Mv0Zfga-knWQAAAJI"]
[Mon Jul 20 06:46:09.357048 2026] [security2:error] [pid 1011111:tid 1011255] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkRXES7Mv0Zfga-knWQAAAJI"]
[Mon Jul 20 06:46:09.371068 2026] [security2:error] [pid 1014214:tid 1014451] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/plugins/"] [unique_id "al4YkQuRBFTcQNywdCIbdQAAAfo"]
[Mon Jul 20 06:46:09.453910 2026] [security2:error] [pid 1014214:tid 1014411] [client 37.52.210.45:43184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YkQuRBFTcQNywdCIbfAAAAdI"]
[Mon Jul 20 06:46:09.454040 2026] [security2:error] [pid 1014214:tid 1014411] [client 37.52.210.45:43184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YkQuRBFTcQNywdCIbfAAAAdI"]
[Mon Jul 20 06:46:09.532556 2026] [security2:error] [pid 1014214:tid 1014377] [client 57.141.18.105:56510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjQuRBFTcQNywdCIagQABsHU"]
[Mon Jul 20 06:46:09.536674 2026] [security2:error] [pid 1011111:tid 1011275] [client 57.141.18.58:22660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjRXES7Mv0Zfga-kmzgAApi0"]
[Mon Jul 20 06:46:09.613622 2026] [security2:error] [pid 1011111:tid 1011263] [client 223.185.13.213:13714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YkRXES7Mv0Zfga-knZAAAAJo"]
[Mon Jul 20 06:46:09.613740 2026] [security2:error] [pid 1011111:tid 1011263] [client 223.185.13.213:13714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YkRXES7Mv0Zfga-knZAAAAJo"]
[Mon Jul 20 06:46:09.661012 2026] [security2:error] [pid 1011111:tid 1011353] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkRXES7Mv0Zfga-knYQAAAPQ"]
[Mon Jul 20 06:46:09.661043 2026] [security2:error] [pid 1011111:tid 1011353] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkRXES7Mv0Zfga-knYQAAAPQ"]
[Mon Jul 20 06:46:09.680983 2026] [security2:error] [pid 1014214:tid 1014368] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/php/"] [unique_id "al4YkQuRBFTcQNywdCIbfgAAAac"]
[Mon Jul 20 06:46:09.883173 2026] [autoindex:error] [pid 1014214:tid 1014455] [client 143.244.57.118:54106] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:09.883732 2026] [security2:error] [pid 1014214:tid 1014455] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-admin/css/"] [unique_id "al4YkQuRBFTcQNywdCIbkgAAAf4"]
[Mon Jul 20 06:46:10.008862 2026] [security2:error] [pid 1011111:tid 1011361] [client 14.251.3.155:54690] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YkhXES7Mv0Zfga-knbwAAAPw"]
[Mon Jul 20 06:46:10.159622 2026] [security2:error] [pid 1011111:tid 1011268] [client 14.225.17.146:65251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4YkRXES7Mv0Zfga-knbgAAAJ8"], referer: http://kromosenergy.com/New
[Mon Jul 20 06:46:10.186217 2026] [security2:error] [pid 1014214:tid 1014466] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbngAAAgk"]
[Mon Jul 20 06:46:10.186241 2026] [security2:error] [pid 1014214:tid 1014466] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbngAAAgk"]
[Mon Jul 20 06:46:10.200299 2026] [security2:error] [pid 1014214:tid 1014437] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "al4YkguRBFTcQNywdCIbnAAAAew"]
[Mon Jul 20 06:46:10.499703 2026] [security2:error] [pid 1014214:tid 1014435] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbrQAAAeo"]
[Mon Jul 20 06:46:10.499759 2026] [security2:error] [pid 1014214:tid 1014435] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbrQAAAeo"]
[Mon Jul 20 06:46:10.505074 2026] [security2:error] [pid 1014214:tid 1014446] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/cache/"] [unique_id "al4YkguRBFTcQNywdCIbqwAAAfU"]
[Mon Jul 20 06:46:10.546431 2026] [security2:error] [pid 1014214:tid 1014438] [client 57.141.18.61:54924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjguRBFTcQNywdCIaygAB7XM"]
[Mon Jul 20 06:46:10.713102 2026] [autoindex:error] [pid 1014214:tid 1014425] [client 143.244.57.118:54106] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:10.713646 2026] [security2:error] [pid 1014214:tid 1014425] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-admin/maint/"] [unique_id "al4YkguRBFTcQNywdCIbxgAAAeA"]
[Mon Jul 20 06:46:10.847978 2026] [security2:error] [pid 1011111:tid 1011149] [remote 152.228.213.32:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4YkhXES7Mv0Zfga-knhgAAjSQ"]
[Mon Jul 20 06:46:10.872472 2026] [authz_core:error] [pid 1014214:tid 1014403] [client 143.244.57.118:0] AH01630: client denied by server configuration: /home1/whytuomy/public_html/website_55cf0d41/wp-content/plugins/akismet/
[Mon Jul 20 06:46:10.874206 2026] [security2:error] [pid 1014214:tid 1014403] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkguRBFTcQNywdCIb0wAAAco"]
[Mon Jul 20 06:46:10.887274 2026] [security2:error] [pid 1014214:tid 1014451] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/plugins/akismet/"] [unique_id "al4YkguRBFTcQNywdCIb0QAAAfo"]
[Mon Jul 20 06:46:10.940610 2026] [security2:error] [pid 1011111:tid 1011256] [client 216.73.217.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cira.org"] [uri "/index.php"] [unique_id "al4YkRXES7Mv0Zfga-knWAAAAJM"]
[Mon Jul 20 06:46:11.035994 2026] [security2:error] [pid 1011111:tid 1011219] [remote 152.228.213.32:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4YkxXES7Mv0Zfga-kniwAA8mo"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 06:46:11.062757 2026] [autoindex:error] [pid 1011111:tid 1011267] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:11.063217 2026] [security2:error] [pid 1011111:tid 1011267] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkxXES7Mv0Zfga-knjQAAAJ4"]
[Mon Jul 20 06:46:11.063917 2026] [security2:error] [pid 1014214:tid 1014226] [remote 188.166.241.141:52196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YkwuRBFTcQNywdCIb4AAB2Qs"]
[Mon Jul 20 06:46:11.064054 2026] [security2:error] [pid 1014214:tid 1014418] [client 188.166.241.141:52196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YkwuRBFTcQNywdCIb4AAB2Qs"]
[Mon Jul 20 06:46:11.065496 2026] [security2:error] [pid 1014214:tid 1014377] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/assets/"] [unique_id "al4YkwuRBFTcQNywdCIb3gAAAbA"]
[Mon Jul 20 06:46:11.093181 2026] [security2:error] [pid 1014214:tid 1014467] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/files../etc/passwd"] [unique_id "al4YkwuRBFTcQNywdCIb4QAAAgo"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:46:11.136100 2026] [security2:error] [pid 1014214:tid 1014378] [client 57.141.18.90:45060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjwuRBFTcQNywdCIa-gABsR4"]
[Mon Jul 20 06:46:11.176406 2026] [security2:error] [pid 1014214:tid 1014409] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/files../.env"] [unique_id "al4YkwuRBFTcQNywdCIb5AAAAdA"], referer: https://www.reddit.com/
[Mon Jul 20 06:46:11.230592 2026] [autoindex:error] [pid 1014214:tid 1014436] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:11.231040 2026] [security2:error] [pid 1014214:tid 1014436] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkwuRBFTcQNywdCIb6AAAAes"]
[Mon Jul 20 06:46:11.233246 2026] [security2:error] [pid 1014214:tid 1014421] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/block-patterns/"] [unique_id "al4YkwuRBFTcQNywdCIb5wAAAdw"]
[Mon Jul 20 06:46:11.318389 2026] [cgid:error] [pid 1011111:tid 1011305] [client 43.133.60.94:52310] AH01264: stderr from /home1/marscafe/public_html/cgi-bin/dbman/work_looking: script not found or unable to stat
[Mon Jul 20 06:46:11.364028 2026] [security2:error] [pid 1011111:tid 1011362] [client 77.110.127.138:55102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YkxXES7Mv0Zfga-knngAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:11.364143 2026] [security2:error] [pid 1011111:tid 1011362] [client 77.110.127.138:55102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YkxXES7Mv0Zfga-knngAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:11.409784 2026] [autoindex:error] [pid 1014214:tid 1014375] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:11.410395 2026] [security2:error] [pid 1014214:tid 1014375] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkwuRBFTcQNywdCIb7wAAAa4"]
[Mon Jul 20 06:46:11.412873 2026] [security2:error] [pid 1014214:tid 1014442] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/block-supports/"] [unique_id "al4YkwuRBFTcQNywdCIb7gAAAfE"]
[Mon Jul 20 06:46:11.482682 2026] [security2:error] [pid 1014214:tid 1014353] [client 66.249.74.132:41825] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "locketsandcharms.net"] [uri "/robots.txt"] [unique_id "al4YkwuRBFTcQNywdCIb9wAAAZg"]
[Mon Jul 20 06:46:11.606786 2026] [autoindex:error] [pid 1011111:tid 1011265] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:11.607496 2026] [security2:error] [pid 1011111:tid 1011265] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkxXES7Mv0Zfga-knpAAAAJw"]
[Mon Jul 20 06:46:11.609857 2026] [security2:error] [pid 1014214:tid 1014358] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/html-api/"] [unique_id "al4YkwuRBFTcQNywdCIb-QAAAZ0"]
[Mon Jul 20 06:46:11.775935 2026] [autoindex:error] [pid 1011111:tid 1011366] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:11.776426 2026] [security2:error] [pid 1011111:tid 1011366] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkxXES7Mv0Zfga-knsAAAAQE"]
[Mon Jul 20 06:46:11.778734 2026] [security2:error] [pid 1014214:tid 1014371] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/js/"] [unique_id "al4YkwuRBFTcQNywdCIcDwAAAao"]
[Mon Jul 20 06:46:11.792160 2026] [security2:error] [pid 1011111:tid 1011275] [client 104.234.53.63:32541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YkxXES7Mv0Zfga-knqAAAAKY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:11.858565 2026] [access_compat:error] [pid 1011111:tid 1011178] [remote 103.180.171.162:54082] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:11.886782 2026] [security2:error] [pid 1014214:tid 1014350] [client 216.73.217.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.robiem.com"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbyQAAAZU"]
[Mon Jul 20 06:46:11.902362 2026] [security2:error] [pid 1011111:tid 1011336] [client 57.141.18.59:34024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YjxXES7Mv0Zfga-knJQAA43c"]
[Mon Jul 20 06:46:11.946634 2026] [autoindex:error] [pid 1014214:tid 1014388] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:11.947136 2026] [security2:error] [pid 1014214:tid 1014388] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YkwuRBFTcQNywdCIcGwAAAbs"]
[Mon Jul 20 06:46:11.949731 2026] [security2:error] [pid 1014214:tid 1014462] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/php-compat/"] [unique_id "al4YkwuRBFTcQNywdCIcGAAAAgU"]
[Mon Jul 20 06:46:12.054439 2026] [security2:error] [pid 1014214:tid 1014422] [client 14.225.17.146:58603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbqAAAAd0"], referer: http://areitoproducciones.com/New
[Mon Jul 20 06:46:12.121380 2026] [autoindex:error] [pid 1014214:tid 1014453] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:12.121904 2026] [security2:error] [pid 1014214:tid 1014453] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlAuRBFTcQNywdCIcKQAAAfw"]
[Mon Jul 20 06:46:12.124178 2026] [security2:error] [pid 1014214:tid 1014466] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/PHPMailer/"] [unique_id "al4YlAuRBFTcQNywdCIcJwAAAgk"]
[Mon Jul 20 06:46:12.316686 2026] [autoindex:error] [pid 1014214:tid 1014452] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:12.317419 2026] [security2:error] [pid 1014214:tid 1014452] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlAuRBFTcQNywdCIcNAAAAfs"]
[Mon Jul 20 06:46:12.323513 2026] [security2:error] [pid 1014214:tid 1014359] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/pomo/"] [unique_id "al4YlAuRBFTcQNywdCIcMgAAAZ4"]
[Mon Jul 20 06:46:12.403690 2026] [security2:error] [pid 1014214:tid 1014429] [client 57.141.18.99:41270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbRQAB5FA"]
[Mon Jul 20 06:46:12.627599 2026] [security2:error] [pid 1014214:tid 1014406] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlAuRBFTcQNywdCIcPwAAAc0"]
[Mon Jul 20 06:46:12.627619 2026] [security2:error] [pid 1014214:tid 1014406] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlAuRBFTcQNywdCIcPwAAAc0"]
[Mon Jul 20 06:46:12.651361 2026] [security2:error] [pid 1014214:tid 1014438] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-includes/random_compat/"] [unique_id "al4YlAuRBFTcQNywdCIcOwAAAe0"]
[Mon Jul 20 06:46:12.721633 2026] [security2:error] [pid 1014214:tid 1014428] [client 57.141.18.34:29826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YkAuRBFTcQNywdCIbYwAB4wk"]
[Mon Jul 20 06:46:12.793829 2026] [security2:error] [pid 1014214:tid 1014361] [client 112.208.70.94:43827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YlAuRBFTcQNywdCIcWQAAAaA"]
[Mon Jul 20 06:46:12.793916 2026] [security2:error] [pid 1014214:tid 1014361] [client 112.208.70.94:43827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YlAuRBFTcQNywdCIcWQAAAaA"]
[Mon Jul 20 06:46:12.838301 2026] [autoindex:error] [pid 1014214:tid 1014390] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:12.838721 2026] [security2:error] [pid 1014214:tid 1014390] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlAuRBFTcQNywdCIcXAAAAb0"]
[Mon Jul 20 06:46:12.847572 2026] [security2:error] [pid 1014214:tid 1014393] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/rest-api/"] [unique_id "al4YlAuRBFTcQNywdCIcWgAAAcA"]
[Mon Jul 20 06:46:12.864769 2026] [security2:error] [pid 1014214:tid 1014349] [client 122.183.32.225:30854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YlAuRBFTcQNywdCIcYAAAAZQ"]
[Mon Jul 20 06:46:12.864866 2026] [security2:error] [pid 1014214:tid 1014349] [client 122.183.32.225:30854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YlAuRBFTcQNywdCIcYAAAAZQ"]
[Mon Jul 20 06:46:13.022887 2026] [autoindex:error] [pid 1014214:tid 1014448] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:13.023570 2026] [security2:error] [pid 1014214:tid 1014448] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlQuRBFTcQNywdCIcaAAAAfc"]
[Mon Jul 20 06:46:13.025863 2026] [security2:error] [pid 1014214:tid 1014418] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/sitemaps/"] [unique_id "al4YlAuRBFTcQNywdCIcZgAAAdk"]
[Mon Jul 20 06:46:13.121563 2026] [security2:error] [pid 1014214:tid 1014249] [remote 154.61.75.100:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YlQuRBFTcQNywdCIccAABwSI"]
[Mon Jul 20 06:46:13.192773 2026] [autoindex:error] [pid 1011111:tid 1011365] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:13.193285 2026] [security2:error] [pid 1011111:tid 1011365] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlRXES7Mv0Zfga-kn6AAAAQA"]
[Mon Jul 20 06:46:13.195647 2026] [security2:error] [pid 1014214:tid 1014401] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4YlQuRBFTcQNywdCIccwAAAcg"]
[Mon Jul 20 06:46:13.226995 2026] [security2:error] [pid 1011111:tid 1011237] [remote 152.228.213.32:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YlRXES7Mv0Zfga-kn6QAA5Hw"]
[Mon Jul 20 06:46:13.372548 2026] [autoindex:error] [pid 1011111:tid 1011281] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:13.372999 2026] [security2:error] [pid 1011111:tid 1011281] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlRXES7Mv0Zfga-kn7gAAAKw"]
[Mon Jul 20 06:46:13.375304 2026] [security2:error] [pid 1014214:tid 1014422] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/style-engine/"] [unique_id "al4YlQuRBFTcQNywdCIcgAAAAd0"]
[Mon Jul 20 06:46:13.416710 2026] [security2:error] [pid 1011111:tid 1011221] [remote 152.228.213.32:55400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YlRXES7Mv0Zfga-kn8AAAtmw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:46:13.421596 2026] [security2:error] [pid 1011111:tid 1011315] [client 104.234.53.63:32541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YlRXES7Mv0Zfga-kn8QAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:13.444499 2026] [security2:error] [pid 1014214:tid 1014465] [client 50.116.65.227:41352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YlQuRBFTcQNywdCIchwAAAgg"]
[Mon Jul 20 06:46:13.454647 2026] [security2:error] [pid 1014214:tid 1014439] [client 50.116.65.227:41360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YlQuRBFTcQNywdCIciAAAAe4"]
[Mon Jul 20 06:46:13.547433 2026] [autoindex:error] [pid 1011111:tid 1011284] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:13.547864 2026] [security2:error] [pid 1011111:tid 1011284] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlRXES7Mv0Zfga-kn9AAAAK8"]
[Mon Jul 20 06:46:13.550412 2026] [security2:error] [pid 1014214:tid 1014415] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/theme-compat/"] [unique_id "al4YlQuRBFTcQNywdCIcjAAAAdY"]
[Mon Jul 20 06:46:13.622694 2026] [security2:error] [pid 1014214:tid 1014303] [remote 154.61.75.100:60264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YlQuRBFTcQNywdCIckAABnVg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:46:13.666453 2026] [security2:error] [pid 1014214:tid 1014408] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/assets../etc/passwd"] [unique_id "al4YlQuRBFTcQNywdCIckgAAAc8"], referer: https://www.facebook.com/
[Mon Jul 20 06:46:13.700895 2026] [security2:error] [pid 1014214:tid 1014294] [remote 103.255.134.61:40396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YlQuRBFTcQNywdCIclQABoU8"]
[Mon Jul 20 06:46:13.720351 2026] [autoindex:error] [pid 1014214:tid 1014468] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:13.720812 2026] [security2:error] [pid 1014214:tid 1014468] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YlQuRBFTcQNywdCIclwAAAgs"]
[Mon Jul 20 06:46:13.723097 2026] [security2:error] [pid 1014214:tid 1014347] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-includes/widgets/"] [unique_id "al4YlQuRBFTcQNywdCIclgAAAZI"]
[Mon Jul 20 06:46:13.791738 2026] [security2:error] [pid 1014214:tid 1014459] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/assets../.env"] [unique_id "al4YlQuRBFTcQNywdCIcmQAAAgI"], referer: https://twitter.com/
[Mon Jul 20 06:46:13.921117 2026] [autoindex:error] [pid 1014214:tid 1014344] [client 143.244.57.118:54106] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:13.921574 2026] [security2:error] [pid 1014214:tid 1014344] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "al4YlQuRBFTcQNywdCIcmgAAAY8"]
[Mon Jul 20 06:46:13.934274 2026] [security2:error] [pid 1014214:tid 1014454] [client 57.141.18.116:45714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbogAB_Xg"]
[Mon Jul 20 06:46:13.961606 2026] [security2:error] [pid 1014214:tid 1014463] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/uploads../.env"] [unique_id "al4YlQuRBFTcQNywdCIcogAAAgY"], referer: https://duckduckgo.com/?q=8jd29
[Mon Jul 20 06:46:14.021934 2026] [security2:error] [pid 1011111:tid 1011269] [client 3.85.191.173:61188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.191.85.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YlhXES7Mv0Zfga-koCgAAAKA"]
[Mon Jul 20 06:46:14.125839 2026] [security2:error] [pid 1014214:tid 1014424] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YlQuRBFTcQNywdCIcpAAAAd8"]
[Mon Jul 20 06:46:14.140989 2026] [autoindex:error] [pid 1014214:tid 1014375] [client 143.244.57.118:54106] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:14.141488 2026] [security2:error] [pid 1014214:tid 1014375] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-admin/css/colors/"] [unique_id "al4YlguRBFTcQNywdCIcpwAAAa4"]
[Mon Jul 20 06:46:14.289032 2026] [security2:error] [pid 1014214:tid 1014305] [remote 103.255.134.61:40396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YlguRBFTcQNywdCIcswAB_Fo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:46:14.417622 2026] [security2:error] [pid 1014214:tid 1014451] [client 54.204.158.117:45750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.158.204.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YlguRBFTcQNywdCIctgAAAfo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:46:14.437000 2026] [security2:error] [pid 1011111:tid 1011268] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlhXES7Mv0Zfga-koGwAAAJ8"]
[Mon Jul 20 06:46:14.437025 2026] [security2:error] [pid 1011111:tid 1011268] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlhXES7Mv0Zfga-koGwAAAJ8"]
[Mon Jul 20 06:46:14.441518 2026] [security2:error] [pid 1014214:tid 1014431] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/admin/images/slider/"] [unique_id "al4YlguRBFTcQNywdCIcsgAAAeY"]
[Mon Jul 20 06:46:14.503013 2026] [security2:error] [pid 1014214:tid 1014462] [client 104.234.53.82:37843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YlguRBFTcQNywdCIcvAAAAgU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:14.527231 2026] [security2:error] [pid 1014214:tid 1014364] [client 103.238.106.162:60760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YlguRBFTcQNywdCIcvwAAAaM"]
[Mon Jul 20 06:46:14.527863 2026] [security2:error] [pid 1014214:tid 1014364] [client 103.238.106.162:60760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YlguRBFTcQNywdCIcvwAAAaM"]
[Mon Jul 20 06:46:14.603019 2026] [security2:error] [pid 1014214:tid 1014416] [client 57.141.18.124:56156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YkguRBFTcQNywdCIbzQAB1wc"]
[Mon Jul 20 06:46:14.748561 2026] [security2:error] [pid 1014214:tid 1014349] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlguRBFTcQNywdCIcxwAAAZQ"]
[Mon Jul 20 06:46:14.748581 2026] [security2:error] [pid 1014214:tid 1014349] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlguRBFTcQNywdCIcxwAAAZQ"]
[Mon Jul 20 06:46:14.753217 2026] [security2:error] [pid 1014214:tid 1014408] [client 143.244.57.118:54106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "al4YlguRBFTcQNywdCIcwgAAAc8"]
[Mon Jul 20 06:46:14.789513 2026] [security2:error] [pid 1014214:tid 1014447] [client 18.141.57.241:13876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YlguRBFTcQNywdCIc1wAAAfY"]
[Mon Jul 20 06:46:14.954944 2026] [security2:error] [pid 1011111:tid 1011341] [client 14.225.17.146:51366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4YlhXES7Mv0Zfga-koMAAAAOg"], referer: http://securingmemories.com/New
[Mon Jul 20 06:46:15.089866 2026] [security2:error] [pid 1014214:tid 1014361] [client 34.139.11.221:53793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIc5QAAAaA"]
[Mon Jul 20 06:46:15.137793 2026] [security2:error] [pid 1014214:tid 1014432] [client 217.142.18.172:44084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIc6QAAAec"]
[Mon Jul 20 06:46:15.137927 2026] [security2:error] [pid 1014214:tid 1014432] [client 217.142.18.172:44084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIc6QAAAec"]
[Mon Jul 20 06:46:15.186261 2026] [security2:error] [pid 1014214:tid 1014390] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIc4wAAAb0"]
[Mon Jul 20 06:46:15.186296 2026] [security2:error] [pid 1014214:tid 1014390] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIc4wAAAb0"]
[Mon Jul 20 06:46:15.216760 2026] [security2:error] [pid 1014214:tid 1014419] [client 34.139.11.221:54530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YlwuRBFTcQNywdCIc8QAAAdo"]
[Mon Jul 20 06:46:15.262904 2026] [security2:error] [pid 1011111:tid 1011310] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlxXES7Mv0Zfga-koQAAAAMk"]
[Mon Jul 20 06:46:15.269203 2026] [security2:error] [pid 1011111:tid 1011301] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlxXES7Mv0Zfga-koQgAAAMA"]
[Mon Jul 20 06:46:15.301737 2026] [security2:error] [pid 1014214:tid 1014389] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIc9QAAAbw"]
[Mon Jul 20 06:46:15.358471 2026] [security2:error] [pid 1014214:tid 1014349] [client 34.139.11.221:59951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YlwuRBFTcQNywdCIc-AAAAZQ"]
[Mon Jul 20 06:46:15.393182 2026] [security2:error] [pid 1014214:tid 1014266] [remote 103.75.185.95:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4YlwuRBFTcQNywdCIc-gAB5TM"]
[Mon Jul 20 06:46:15.448240 2026] [security2:error] [pid 1011111:tid 1011290] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/sites/default/files/"] [unique_id "al4YlxXES7Mv0Zfga-koNwAAAJk"]
[Mon Jul 20 06:46:15.469553 2026] [security2:error] [pid 1014214:tid 1014450] [client 187.108.85.186:57725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIc_AAAAfk"]
[Mon Jul 20 06:46:15.469655 2026] [security2:error] [pid 1014214:tid 1014450] [client 187.108.85.186:57725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIc_AAAAfk"]
[Mon Jul 20 06:46:15.492637 2026] [security2:error] [pid 1014214:tid 1014447] [client 34.139.11.221:63580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YlwuRBFTcQNywdCIc_gAAAfY"]
[Mon Jul 20 06:46:15.678329 2026] [security2:error] [pid 1011111:tid 1011368] [client 34.139.11.221:63246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YlxXES7Mv0Zfga-koUAAAAQM"]
[Mon Jul 20 06:46:15.719811 2026] [security2:error] [pid 1014214:tid 1014435] [client 195.63.31.120:21965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YlwuRBFTcQNywdCIdBgAAAeo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:15.754109 2026] [security2:error] [pid 1011111:tid 1011324] [client 57.141.18.34:21086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YkxXES7Mv0Zfga-knswAA1xA"]
[Mon Jul 20 06:46:15.754526 2026] [security2:error] [pid 1011111:tid 1011364] [client 89.58.73.111:56405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlxXES7Mv0Zfga-koSgAAAP8"]
[Mon Jul 20 06:46:15.761306 2026] [security2:error] [pid 1014214:tid 1014386] [client 57.141.18.3:48902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YkwuRBFTcQNywdCIcDQABuSc"]
[Mon Jul 20 06:46:15.806503 2026] [security2:error] [pid 1014214:tid 1014388] [client 207.175.80.208:52148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4YlguRBFTcQNywdCIc2QAAAbs"]
[Mon Jul 20 06:46:15.809216 2026] [security2:error] [pid 1014214:tid 1014376] [client 207.175.80.208:61893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice-ca.innspace.ca"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIc5AAAAa8"]
[Mon Jul 20 06:46:15.830203 2026] [security2:error] [pid 1014214:tid 1014404] [client 103.125.179.95:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIdDwAAAcs"]
[Mon Jul 20 06:46:15.831540 2026] [security2:error] [pid 1014214:tid 1014404] [client 103.125.179.95:56293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIdDwAAAcs"]
[Mon Jul 20 06:46:15.887254 2026] [security2:error] [pid 1014214:tid 1014381] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIdCwAAAbQ"]
[Mon Jul 20 06:46:15.887279 2026] [security2:error] [pid 1014214:tid 1014381] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIdCwAAAbQ"]
[Mon Jul 20 06:46:15.900465 2026] [security2:error] [pid 1014214:tid 1014220] [remote 103.75.185.95:57558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4YlwuRBFTcQNywdCIdFQAB3AU"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 06:46:15.913902 2026] [security2:error] [pid 1014214:tid 1014364] [client 34.139.11.221:55162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YlwuRBFTcQNywdCIdGAAAAaM"]
[Mon Jul 20 06:46:15.943078 2026] [security2:error] [pid 1011111:tid 1011343] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/admin/controller/extension/extension/"] [unique_id "al4YlxXES7Mv0Zfga-koVQAAAOo"]
[Mon Jul 20 06:46:16.002041 2026] [security2:error] [pid 1014214:tid 1014432] [client 89.58.73.111:38739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIdFgAAAec"]
[Mon Jul 20 06:46:16.016034 2026] [security2:error] [pid 1014214:tid 1014419] [client 207.175.80.208:61893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.80.175.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice-ca.innspace.ca"] [uri "/xmlrpc.php"] [unique_id "al4YlwuRBFTcQNywdCIdIAAAAdo"]
[Mon Jul 20 06:46:16.068689 2026] [security2:error] [pid 1014214:tid 1014454] [client 207.175.80.208:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.80.175.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YmAuRBFTcQNywdCIdKwAAAf0"]
[Mon Jul 20 06:46:16.071082 2026] [security2:error] [pid 1011111:tid 1011246] [client 14.225.17.146:58874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4YlhXES7Mv0Zfga-koFAAAAIk"], referer: http://partnerselectricalllc.com/New
[Mon Jul 20 06:46:16.107477 2026] [security2:error] [pid 1011111:tid 1011268] [client 34.139.11.221:54332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YmBXES7Mv0Zfga-koXQAAAJ8"]
[Mon Jul 20 06:46:16.131465 2026] [security2:error] [pid 1011111:tid 1011211] [remote 57.141.18.53:38642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600005"] [unique_id "al4YmBXES7Mv0Zfga-koXgAAkGI"]
[Mon Jul 20 06:46:16.286398 2026] [security2:error] [pid 1014214:tid 1014405] [client 77.110.127.138:55165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YmAuRBFTcQNywdCIdOQAAAcw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:16.286503 2026] [security2:error] [pid 1014214:tid 1014405] [client 77.110.127.138:55165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YmAuRBFTcQNywdCIdOQAAAcw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:16.317725 2026] [security2:error] [pid 1014214:tid 1014376] [client 34.139.11.221:65410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdPAAAAa8"]
[Mon Jul 20 06:46:16.330514 2026] [security2:error] [pid 1014214:tid 1014352] [client 183.82.98.154:63917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YmAuRBFTcQNywdCIdPQAAAZc"]
[Mon Jul 20 06:46:16.330647 2026] [security2:error] [pid 1014214:tid 1014352] [client 183.82.98.154:63917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YmAuRBFTcQNywdCIdPQAAAZc"]
[Mon Jul 20 06:46:16.334395 2026] [security2:error] [pid 1014214:tid 1014365] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdMgAAAaQ"]
[Mon Jul 20 06:46:16.334434 2026] [security2:error] [pid 1014214:tid 1014365] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdMgAAAaQ"]
[Mon Jul 20 06:46:16.345095 2026] [security2:error] [pid 1011111:tid 1011282] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "al4YmBXES7Mv0Zfga-koYgAAAK0"]
[Mon Jul 20 06:46:16.360055 2026] [security2:error] [pid 1014214:tid 1014431] [client 14.225.17.146:63039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdMAAAAeY"], referer: http://mtlegnews.gov/New
[Mon Jul 20 06:46:16.498185 2026] [security2:error] [pid 1014214:tid 1014446] [client 34.139.11.221:54099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdRwAAAfU"]
[Mon Jul 20 06:46:16.557107 2026] [security2:error] [pid 1014214:tid 1014457] [client 57.141.18.119:50358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlAuRBFTcQNywdCIcSAACAHA"]
[Mon Jul 20 06:46:16.634688 2026] [security2:error] [pid 1014214:tid 1014353] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/media../.env"] [unique_id "al4YmAuRBFTcQNywdCIdUAAAAZg"], referer: https://www.bing.com/search?q=wmt3mx
[Mon Jul 20 06:46:16.639959 2026] [security2:error] [pid 1011111:tid 1011139] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YmBXES7Mv0Zfga-kodwAAoho"]
[Mon Jul 20 06:46:16.640108 2026] [security2:error] [pid 1011111:tid 1011271] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YmBXES7Mv0Zfga-kodwAAoho"]
[Mon Jul 20 06:46:16.644526 2026] [security2:error] [pid 1011111:tid 1011307] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmBXES7Mv0Zfga-kodQAAAMY"]
[Mon Jul 20 06:46:16.644543 2026] [security2:error] [pid 1011111:tid 1011307] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmBXES7Mv0Zfga-kodQAAAMY"]
[Mon Jul 20 06:46:16.659989 2026] [security2:error] [pid 1014214:tid 1014424] [client 34.139.11.221:55420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdUgAAAd8"]
[Mon Jul 20 06:46:16.662224 2026] [security2:error] [pid 1011111:tid 1011245] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/components/"] [unique_id "al4YmBXES7Mv0Zfga-kocwAAAIg"]
[Mon Jul 20 06:46:16.683247 2026] [security2:error] [pid 1014214:tid 1014387] [client 207.175.80.208:58724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdVQAAAbo"]
[Mon Jul 20 06:46:16.684085 2026] [security2:error] [pid 1014214:tid 1014418] [client 207.175.80.208:60677] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdVgAAAdk"]
[Mon Jul 20 06:46:16.703305 2026] [security2:error] [pid 1014214:tid 1014401] [client 74.208.214.194:56446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4YmAuRBFTcQNywdCIdVwAAAcg"]
[Mon Jul 20 06:46:16.711013 2026] [security2:error] [pid 1011111:tid 1011359] [client 13.229.83.156:39650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.83.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4YmBXES7Mv0Zfga-koegAAAPo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:46:16.805024 2026] [security2:error] [pid 1014214:tid 1014427] [client 34.139.11.221:61184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdYQAAAeI"]
[Mon Jul 20 06:46:16.937539 2026] [security2:error] [pid 1014214:tid 1014421] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdYwAAAdw"]
[Mon Jul 20 06:46:16.937569 2026] [security2:error] [pid 1014214:tid 1014421] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdYwAAAdw"]
[Mon Jul 20 06:46:16.942700 2026] [security2:error] [pid 1014214:tid 1014448] [client 34.139.11.221:61946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.jwo.ral.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YmAuRBFTcQNywdCIdcAAAAfc"]
[Mon Jul 20 06:46:16.966472 2026] [security2:error] [pid 1011111:tid 1011298] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/admin/uploads/images/"] [unique_id "al4YmBXES7Mv0Zfga-kofQAAAL0"]
[Mon Jul 20 06:46:17.190201 2026] [security2:error] [pid 1011111:tid 1011264] [client 14.225.17.146:50351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4YmBXES7Mv0Zfga-kofgAAAJs"], referer: http://nextlevelpressurewashing.com/New
[Mon Jul 20 06:46:17.237323 2026] [security2:error] [pid 1014214:tid 1014413] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/cdn../.env"] [unique_id "al4YmQuRBFTcQNywdCIdjQAAAdQ"], referer: https://www.bing.com/search?q=veuow8
[Mon Jul 20 06:46:17.267156 2026] [security2:error] [pid 1014214:tid 1014435] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdhAAAAeo"]
[Mon Jul 20 06:46:17.267188 2026] [security2:error] [pid 1014214:tid 1014435] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdhAAAAeo"]
[Mon Jul 20 06:46:17.270489 2026] [security2:error] [pid 1011111:tid 1011362] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "al4YmRXES7Mv0Zfga-koggAAAP0"]
[Mon Jul 20 06:46:17.271581 2026] [security2:error] [pid 1014214:tid 1014385] [client 92.209.217.208:5988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YmQuRBFTcQNywdCIdhQABuEY"]
[Mon Jul 20 06:46:17.305449 2026] [security2:error] [pid 1011111:tid 1011336] [client 57.141.18.89:51202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlRXES7Mv0Zfga-kn7AAA4zU"]
[Mon Jul 20 06:46:17.307178 2026] [security2:error] [pid 1011111:tid 1011272] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmRXES7Mv0Zfga-koiQAAAKM"]
[Mon Jul 20 06:46:17.313482 2026] [security2:error] [pid 1011111:tid 1011316] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmRXES7Mv0Zfga-koigAAAM8"]
[Mon Jul 20 06:46:17.344806 2026] [security2:error] [pid 1014214:tid 1014465] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdkAAAAgg"]
[Mon Jul 20 06:46:17.388400 2026] [security2:error] [pid 1014214:tid 1014362] [client 207.175.80.208:60410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YmQuRBFTcQNywdCIdkwAAAaE"]
[Mon Jul 20 06:46:17.420582 2026] [security2:error] [pid 1014214:tid 1014464] [client 207.175.80.208:59902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YmQuRBFTcQNywdCIdlQAAAgc"]
[Mon Jul 20 06:46:17.548864 2026] [security2:error] [pid 1014214:tid 1014463] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/public../.env"] [unique_id "al4YmQuRBFTcQNywdCIdowAAAgY"], referer: https://duckduckgo.com/?q=t3844
[Mon Jul 20 06:46:17.558559 2026] [security2:error] [pid 1014214:tid 1014377] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdmAAAAbA"]
[Mon Jul 20 06:46:17.558593 2026] [security2:error] [pid 1014214:tid 1014377] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdmAAAAbA"]
[Mon Jul 20 06:46:17.564906 2026] [security2:error] [pid 1011111:tid 1011246] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/fonts/"] [unique_id "al4YmRXES7Mv0Zfga-kojwAAAIk"]
[Mon Jul 20 06:46:17.578037 2026] [security2:error] [pid 1014214:tid 1014448] [client 145.239.10.137:46984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/class.php"] [unique_id "al4YmQuRBFTcQNywdCIdpQAAAfc"], referer: http://superiorcopywriting.com/class.php
[Mon Jul 20 06:46:17.586560 2026] [security2:error] [pid 1014214:tid 1014354] [client 51.143.183.75:4480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YmQuRBFTcQNywdCIdpgAAAZk"]
[Mon Jul 20 06:46:17.719259 2026] [security2:error] [pid 1014214:tid 1014435] [client 51.143.183.75:4480] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YmQuRBFTcQNywdCIdswAAAeo"]
[Mon Jul 20 06:46:17.782527 2026] [security2:error] [pid 1014214:tid 1014434] [client 89.58.73.111:56430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdrAAAAek"]
[Mon Jul 20 06:46:17.820073 2026] [security2:error] [pid 1011111:tid 1011331] [client 13.71.159.57:31616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YmRXES7Mv0Zfga-komQAAAN4"]
[Mon Jul 20 06:46:17.847822 2026] [security2:error] [pid 1011111:tid 1011330] [client 57.141.18.95:43720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlhXES7Mv0Zfga-koEAAA3To"]
[Mon Jul 20 06:46:17.855740 2026] [security2:error] [pid 1014214:tid 1014388] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdtgAAAbs"]
[Mon Jul 20 06:46:17.855785 2026] [security2:error] [pid 1014214:tid 1014388] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdtgAAAbs"]
[Mon Jul 20 06:46:17.863876 2026] [security2:error] [pid 1011111:tid 1011258] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "al4YmRXES7Mv0Zfga-kolQAAAJU"]
[Mon Jul 20 06:46:17.931617 2026] [security2:error] [pid 1011111:tid 1011291] [client 13.71.159.57:31616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YmRXES7Mv0Zfga-konQAAALY"]
[Mon Jul 20 06:46:17.946566 2026] [security2:error] [pid 1011111:tid 1011270] [client 89.58.73.111:56385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmRXES7Mv0Zfga-komwAAAKE"]
[Mon Jul 20 06:46:17.948556 2026] [security2:error] [pid 1014214:tid 1014398] [client 43.205.139.3:33664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YmQuRBFTcQNywdCIdvwAAAcU"]
[Mon Jul 20 06:46:17.948650 2026] [security2:error] [pid 1014214:tid 1014398] [client 43.205.139.3:33664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YmQuRBFTcQNywdCIdvwAAAcU"]
[Mon Jul 20 06:46:17.961976 2026] [security2:error] [pid 1014214:tid 1014470] [client 14.225.17.146:51869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdeAAAAg0"]
[Mon Jul 20 06:46:17.967866 2026] [security2:error] [pid 1014214:tid 1014387] [client 207.175.80.208:58724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YmQuRBFTcQNywdCIdwQAAAbo"]
[Mon Jul 20 06:46:18.034666 2026] [security2:error] [pid 1014214:tid 1014411] [client 152.58.191.29:62498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YmguRBFTcQNywdCIdxwAAAdI"]
[Mon Jul 20 06:46:18.034802 2026] [security2:error] [pid 1014214:tid 1014411] [client 152.58.191.29:62498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YmguRBFTcQNywdCIdxwAAAdI"]
[Mon Jul 20 06:46:18.064487 2026] [autoindex:error] [pid 1011111:tid 1011367] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/plugins/contact-form-7/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:18.064945 2026] [security2:error] [pid 1011111:tid 1011367] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YmhXES7Mv0Zfga-koqAAAAQI"]
[Mon Jul 20 06:46:18.068177 2026] [security2:error] [pid 1011111:tid 1011321] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "al4YmhXES7Mv0Zfga-kopQAAANQ"]
[Mon Jul 20 06:46:18.102692 2026] [security2:error] [pid 1014214:tid 1014356] [client 207.175.80.208:52996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YmguRBFTcQNywdCIdygAAAZs"]
[Mon Jul 20 06:46:18.116555 2026] [security2:error] [pid 1014214:tid 1014349] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/resources../.env"] [unique_id "al4YmguRBFTcQNywdCIdzQAAAZQ"], referer: https://www.reddit.com/
[Mon Jul 20 06:46:18.196376 2026] [security2:error] [pid 1014214:tid 1014423] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4YmguRBFTcQNywdCId0gAAAd4"], referer: https://www.reddit.com/
[Mon Jul 20 06:46:18.221746 2026] [security2:error] [pid 1011111:tid 1011278] [client 57.141.18.74:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlhXES7Mv0Zfga-koJQAAqS4"]
[Mon Jul 20 06:46:18.237881 2026] [security2:error] [pid 1014214:tid 1014424] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4YmguRBFTcQNywdCId2AAAAd8"], referer: https://twitter.com/
[Mon Jul 20 06:46:18.305060 2026] [security2:error] [pid 1014214:tid 1014386] [client 104.234.53.83:40043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YmguRBFTcQNywdCId3QAAAbk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:18.367686 2026] [security2:error] [pid 1014214:tid 1014385] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4YmguRBFTcQNywdCId5AAAAbg"], referer: https://www.facebook.com/
[Mon Jul 20 06:46:18.370646 2026] [security2:error] [pid 1014214:tid 1014469] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmguRBFTcQNywdCId1gAAAgw"]
[Mon Jul 20 06:46:18.370678 2026] [security2:error] [pid 1014214:tid 1014469] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmguRBFTcQNywdCId1gAAAgw"]
[Mon Jul 20 06:46:18.375762 2026] [security2:error] [pid 1011111:tid 1011333] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/wordpress/"] [unique_id "al4YmhXES7Mv0Zfga-korwAAAOA"]
[Mon Jul 20 06:46:18.546160 2026] [security2:error] [pid 1014214:tid 1014430] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4YmguRBFTcQNywdCId7QAAAeU"], referer: https://www.google.com/search?q=m8p2kf
[Mon Jul 20 06:46:18.553227 2026] [security2:error] [pid 1014214:tid 1014442] [client 207.175.80.208:63836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YmguRBFTcQNywdCId7wAAAfE"]
[Mon Jul 20 06:46:18.580306 2026] [autoindex:error] [pid 1011111:tid 1011352] [client 143.244.57.118:54944] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:18.580772 2026] [security2:error] [pid 1011111:tid 1011352] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-admin/images/"] [unique_id "al4YmhXES7Mv0Zfga-kotQAAAPM"]
[Mon Jul 20 06:46:18.582964 2026] [security2:error] [pid 1014214:tid 1014350] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/etc/passwd"] [unique_id "al4YmguRBFTcQNywdCId8gAAAZU"], referer: https://duckduckgo.com/?q=s2cx7
[Mon Jul 20 06:46:18.622914 2026] [security2:error] [pid 1014214:tid 1014465] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4YmguRBFTcQNywdCId9QAAAgg"], referer: https://www.facebook.com/
[Mon Jul 20 06:46:18.675320 2026] [security2:error] [pid 1014214:tid 1014398] [client 207.175.80.208:62848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YmguRBFTcQNywdCId-AAAAcU"]
[Mon Jul 20 06:46:18.718734 2026] [security2:error] [pid 1014214:tid 1014423] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4YmguRBFTcQNywdCId-gAAAd4"], referer: https://www.bing.com/search?q=hut3sk
[Mon Jul 20 06:46:18.748159 2026] [security2:error] [pid 1014214:tid 1014457] [client 103.153.183.69:55928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/.env"] [unique_id "al4YmguRBFTcQNywdCIeAAAAAgA"], referer: https://www.bing.com/search?q=nq5yej
[Mon Jul 20 06:46:18.755465 2026] [autoindex:error] [pid 1011111:tid 1011335] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:18.755921 2026] [security2:error] [pid 1011111:tid 1011335] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YmhXES7Mv0Zfga-kovAAAAOI"]
[Mon Jul 20 06:46:18.758280 2026] [security2:error] [pid 1011111:tid 1011290] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "al4YmhXES7Mv0Zfga-kouwAAALU"]
[Mon Jul 20 06:46:18.777413 2026] [core:error] [pid 1014214:tid 1014409] [client 103.153.183.69:55928] AH10244: invalid URI path (/%2e%2e/etc/passwd?_=adx9otz3&v=tgbfp), referer: https://www.google.com/search?q=d03ydf
[Mon Jul 20 06:46:18.779882 2026] [security2:error] [pid 1014214:tid 1014418] [client 127.0.0.1:36230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4YmguRBFTcQNywdCIeAgAAAdk"], referer: https://www.google.com/search?q=d03ydf
[Mon Jul 20 06:46:18.876573 2026] [security2:error] [pid 1014214:tid 1014459] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlwuRBFTcQNywdCIc8gAAAgI"]
[Mon Jul 20 06:46:18.881003 2026] [security2:error] [pid 1014214:tid 1014406] [client 117.247.108.24:24402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YmguRBFTcQNywdCIeDQAAAc0"]
[Mon Jul 20 06:46:18.881165 2026] [security2:error] [pid 1014214:tid 1014406] [client 117.247.108.24:24402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YmguRBFTcQNywdCIeDQAAAc0"]
[Mon Jul 20 06:46:18.946314 2026] [security2:error] [pid 1014214:tid 1014433] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al4YmguRBFTcQNywdCIeEQAAAeg"]
[Mon Jul 20 06:46:18.948576 2026] [security2:error] [pid 1014214:tid 1014470] [client 171.61.165.146:13789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YmguRBFTcQNywdCIeFQAAAg0"]
[Mon Jul 20 06:46:18.949375 2026] [security2:error] [pid 1011111:tid 1011273] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "al4YmhXES7Mv0Zfga-kowAAAAKQ"]
[Mon Jul 20 06:46:18.949686 2026] [security2:error] [pid 1014214:tid 1014470] [client 171.61.165.146:13789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YmguRBFTcQNywdCIeFQAAAg0"]
[Mon Jul 20 06:46:18.971002 2026] [access_compat:error] [pid 1014214:tid 1014249] [remote 98.89.26.176:37096] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:19.016204 2026] [security2:error] [pid 1014214:tid 1014453] [client 14.225.17.146:57994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4YmguRBFTcQNywdCIdyQAAAfw"], referer: http://walkingandtalking.net/New
[Mon Jul 20 06:46:19.076734 2026] [security2:error] [pid 1014214:tid 1014367] [client 223.185.13.213:30545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YmwuRBFTcQNywdCIeFwAAAaY"]
[Mon Jul 20 06:46:19.076909 2026] [security2:error] [pid 1014214:tid 1014367] [client 223.185.13.213:30545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YmwuRBFTcQNywdCIeFwAAAaY"]
[Mon Jul 20 06:46:19.105244 2026] [security2:error] [pid 1014214:tid 1014230] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4YmwuRBFTcQNywdCIeGwABmw8"]
[Mon Jul 20 06:46:19.110811 2026] [security2:error] [pid 1011111:tid 1011304] [client 14.225.17.146:51769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4YmxXES7Mv0Zfga-kowgAAAMM"], referer: http://dasmarque.com/New
[Mon Jul 20 06:46:19.165660 2026] [security2:error] [pid 1014214:tid 1014427] [client 207.175.80.208:54958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YmwuRBFTcQNywdCIeIAAAAeI"]
[Mon Jul 20 06:46:19.232882 2026] [security2:error] [pid 1014214:tid 1014382] [client 143.244.57.118:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmwuRBFTcQNywdCIeHAAAAbU"]
[Mon Jul 20 06:46:19.232905 2026] [security2:error] [pid 1014214:tid 1014382] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmwuRBFTcQNywdCIeHAAAAbU"]
[Mon Jul 20 06:46:19.236536 2026] [security2:error] [pid 1011111:tid 1011285] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/js/"] [unique_id "al4YmxXES7Mv0Zfga-koxQAAALA"]
[Mon Jul 20 06:46:19.268348 2026] [security2:error] [pid 1011111:tid 1011364] [client 207.175.80.208:50410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YmxXES7Mv0Zfga-kozAAAAP8"]
[Mon Jul 20 06:46:19.298890 2026] [security2:error] [pid 1014214:tid 1014267] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4YmwuRBFTcQNywdCIeJwABjzQ"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:46:19.407592 2026] [autoindex:error] [pid 1014214:tid 1014462] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/plugins/woocommerce/assets/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:19.408140 2026] [security2:error] [pid 1014214:tid 1014462] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YmwuRBFTcQNywdCIeKwAAAgU"]
[Mon Jul 20 06:46:19.435998 2026] [security2:error] [pid 1011111:tid 1011329] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "al4YmxXES7Mv0Zfga-ko0wAAANw"]
[Mon Jul 20 06:46:19.478014 2026] [security2:error] [pid 1011111:tid 1011319] [client 57.141.18.58:53622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YlxXES7Mv0Zfga-koVwAA0k8"]
[Mon Jul 20 06:46:19.604692 2026] [autoindex:error] [pid 1014214:tid 1014433] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/plugins/woocommerce/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:19.605159 2026] [security2:error] [pid 1014214:tid 1014433] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YmwuRBFTcQNywdCIeNQAAAeg"]
[Mon Jul 20 06:46:19.629901 2026] [security2:error] [pid 1011111:tid 1011250] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "al4YmxXES7Mv0Zfga-ko3QAAAI0"]
[Mon Jul 20 06:46:19.771588 2026] [security2:error] [pid 1014214:tid 1014406] [client 207.175.80.208:49336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YmwuRBFTcQNywdCIePQAAAc0"]
[Mon Jul 20 06:46:19.833639 2026] [security2:error] [pid 1014214:tid 1014425] [client 207.175.80.208:64326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YmwuRBFTcQNywdCIeQgAAAeA"]
[Mon Jul 20 06:46:19.882642 2026] [core:error] [pid 1014214:tid 1014451] [client 103.153.183.69:36476] AH10244: invalid URI path (/%2e%2e/.env?_=w3h3q2jp&v=u6vgk), referer: https://www.bing.com/search?q=9fp6lk
[Mon Jul 20 06:46:19.923744 2026] [security2:error] [pid 1011111:tid 1011261] [client 14.225.17.146:65270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4YmxXES7Mv0Zfga-ko6AAAAJg"], referer: https://walkingandtalking.net/New
[Mon Jul 20 06:46:19.929336 2026] [security2:error] [pid 1011111:tid 1011300] [client 143.244.57.118:54944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmxXES7Mv0Zfga-ko5QAAAL8"]
[Mon Jul 20 06:46:19.929367 2026] [security2:error] [pid 1011111:tid 1011300] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/index.php"] [unique_id "al4YmxXES7Mv0Zfga-ko5QAAAL8"]
[Mon Jul 20 06:46:20.031029 2026] [security2:error] [pid 1014214:tid 1014452] [client 74.7.227.179:46140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4YmwuRBFTcQNywdCIeRgAB-wA"], referer: https://tejasenvironmental.com/p=785506
[Mon Jul 20 06:46:20.037730 2026] [security2:error] [pid 1014214:tid 1014464] [client 197.186.66.42:49392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YnAuRBFTcQNywdCIeVAAAAgc"]
[Mon Jul 20 06:46:20.037823 2026] [security2:error] [pid 1014214:tid 1014464] [client 197.186.66.42:49392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YnAuRBFTcQNywdCIeVAAAAgc"]
[Mon Jul 20 06:46:20.057614 2026] [security2:error] [pid 1014214:tid 1014455] [client 57.141.18.32:59654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmAuRBFTcQNywdCIdSQAB_jo"]
[Mon Jul 20 06:46:20.090039 2026] [security2:error] [pid 1014214:tid 1014346] [client 37.52.210.45:59731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YnAuRBFTcQNywdCIeVwAAAZE"]
[Mon Jul 20 06:46:20.090207 2026] [security2:error] [pid 1014214:tid 1014346] [client 37.52.210.45:59731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YnAuRBFTcQNywdCIeVwAAAZE"]
[Mon Jul 20 06:46:20.205859 2026] [security2:error] [pid 1011111:tid 1011312] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/network/index.php"] [unique_id "al4YnBXES7Mv0Zfga-ko8AAAAMs"]
[Mon Jul 20 06:46:20.244481 2026] [security2:error] [pid 1011111:tid 1011123] [remote 5.252.52.249:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YnBXES7Mv0Zfga-ko8wAA-go"]
[Mon Jul 20 06:46:20.244650 2026] [security2:error] [pid 1011111:tid 1011359] [client 5.252.52.249:49858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YnBXES7Mv0Zfga-ko8wAA-go"]
[Mon Jul 20 06:46:20.345568 2026] [security2:error] [pid 1014214:tid 1014413] [client 104.234.53.73:59001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YnAuRBFTcQNywdCIeYgAAAdQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:20.385764 2026] [security2:error] [pid 1011111:tid 1011339] [client 207.175.80.208:59364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YnBXES7Mv0Zfga-ko9wAAAOY"]
[Mon Jul 20 06:46:20.409281 2026] [security2:error] [pid 1014214:tid 1014406] [client 77.110.127.138:55194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YnAuRBFTcQNywdCIeZwAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:20.409360 2026] [security2:error] [pid 1014214:tid 1014406] [client 77.110.127.138:55194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YnAuRBFTcQNywdCIeZwAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:20.517047 2026] [proxy:error] [pid 1014214:tid 1014402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:20.517129 2026] [proxy_http:error] [pid 1014214:tid 1014402] [client 34.73.38.214:52302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:20.517571 2026] [proxy:error] [pid 1014214:tid 1014402] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:20.517596 2026] [proxy_http:error] [pid 1014214:tid 1014402] [client 34.73.38.214:52302] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:20.544561 2026] [security2:error] [pid 1014214:tid 1014453] [client 207.175.80.208:64545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YnAuRBFTcQNywdCIebwAAAfw"]
[Mon Jul 20 06:46:20.684149 2026] [security2:error] [pid 1011111:tid 1011349] [client 2a03:2880:16ff:54:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4YnBXES7Mv0Zfga-kpAwAA8Hw"]
[Mon Jul 20 06:46:20.773669 2026] [security2:error] [pid 1014214:tid 1014446] [client 143.244.57.118:51552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/network/index.php"] [unique_id "al4YnAuRBFTcQNywdCIedwAAAfU"]
[Mon Jul 20 06:46:20.812903 2026] [security2:error] [pid 1014214:tid 1014341] [remote 173.249.4.11:40481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YnAuRBFTcQNywdCIegwAB5n4"]
[Mon Jul 20 06:46:20.918951 2026] [security2:error] [pid 1014214:tid 1014470] [client 143.244.57.118:51552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YnAuRBFTcQNywdCIehwAAAg0"]
[Mon Jul 20 06:46:20.919073 2026] [security2:error] [pid 1014214:tid 1014470] [client 143.244.57.118:51552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YnAuRBFTcQNywdCIehwAAAg0"]
[Mon Jul 20 06:46:20.921457 2026] [security2:error] [pid 1014214:tid 1014383] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdngAAAbY"]
[Mon Jul 20 06:46:20.963139 2026] [security2:error] [pid 1014214:tid 1014243] [remote 78.46.157.202:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YnAuRBFTcQNywdCIeigAB0hw"]
[Mon Jul 20 06:46:21.104358 2026] [security2:error] [pid 1011111:tid 1011294] [client 207.175.80.208:54463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YnRXES7Mv0Zfga-kpFQAAALk"]
[Mon Jul 20 06:46:21.108562 2026] [security2:error] [pid 1014214:tid 1014426] [client 57.141.18.53:26068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmQuRBFTcQNywdCIdoQAB4RI"]
[Mon Jul 20 06:46:21.138007 2026] [security2:error] [pid 1011111:tid 1011354] [client 207.175.80.208:58208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YnRXES7Mv0Zfga-kpFgAAAPU"]
[Mon Jul 20 06:46:21.170758 2026] [security2:error] [pid 1014214:tid 1014220] [remote 78.46.157.202:50372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YnQuRBFTcQNywdCIekwACAQU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:46:21.197442 2026] [security2:error] [pid 1011111:tid 1011306] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/user/index.php"] [unique_id "al4YnRXES7Mv0Zfga-kpFAAAAMU"]
[Mon Jul 20 06:46:21.243954 2026] [security2:error] [pid 1014214:tid 1014433] [client 158.173.166.181:46981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YnQuRBFTcQNywdCIelQAAAeg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:46:21.294825 2026] [security2:error] [pid 1014214:tid 1014270] [remote 188.166.241.141:58188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4YnQuRBFTcQNywdCIelgABoDc"]
[Mon Jul 20 06:46:21.474649 2026] [proxy:error] [pid 1011111:tid 1011260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:21.474715 2026] [proxy_http:error] [pid 1011111:tid 1011260] [client 34.73.38.214:51884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:21.475368 2026] [proxy:error] [pid 1011111:tid 1011260] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:21.475395 2026] [proxy_http:error] [pid 1011111:tid 1011260] [client 34.73.38.214:51884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:21.673111 2026] [security2:error] [pid 1014214:tid 1014237] [remote 188.166.241.141:58188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4YnQuRBFTcQNywdCIenQABkRY"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 06:46:21.699945 2026] [security2:error] [pid 1014214:tid 1014460] [client 207.175.80.208:55635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YnQuRBFTcQNywdCIengAAAgM"]
[Mon Jul 20 06:46:21.711551 2026] [security2:error] [pid 1011111:tid 1011261] [client 207.175.80.208:62384] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YnRXES7Mv0Zfga-kpNAAAAJg"]
[Mon Jul 20 06:46:21.756865 2026] [security2:error] [pid 1011111:tid 1011351] [client 143.244.57.118:51562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/user/index.php"] [unique_id "al4YnRXES7Mv0Zfga-kpLwAAAPI"]
[Mon Jul 20 06:46:21.757566 2026] [proxy:error] [pid 1011111:tid 1011332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:21.757639 2026] [proxy_http:error] [pid 1011111:tid 1011332] [client 34.73.38.214:65038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:21.758402 2026] [proxy:error] [pid 1011111:tid 1011332] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:21.758432 2026] [proxy_http:error] [pid 1011111:tid 1011332] [client 34.73.38.214:65038] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:21.886899 2026] [security2:error] [pid 1014214:tid 1014400] [client 57.141.18.62:53152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmguRBFTcQNywdCId2wABx0w"]
[Mon Jul 20 06:46:21.902482 2026] [security2:error] [pid 1011111:tid 1011324] [client 143.244.57.118:51562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YnRXES7Mv0Zfga-kpPwAAANc"]
[Mon Jul 20 06:46:21.902561 2026] [security2:error] [pid 1011111:tid 1011324] [client 143.244.57.118:51562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YnRXES7Mv0Zfga-kpPwAAANc"]
[Mon Jul 20 06:46:22.088689 2026] [security2:error] [pid 1014214:tid 1014368] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/index.php"] [unique_id "al4YnguRBFTcQNywdCIewwAAAac"]
[Mon Jul 20 06:46:22.091724 2026] [security2:error] [pid 1011111:tid 1011329] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/"] [unique_id "al4YnhXES7Mv0Zfga-kpRQAAANw"]
[Mon Jul 20 06:46:22.277441 2026] [security2:error] [pid 1014214:tid 1014429] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/plugins/index.php"] [unique_id "al4YnguRBFTcQNywdCIezgAAAeQ"]
[Mon Jul 20 06:46:22.281128 2026] [security2:error] [pid 1011111:tid 1011297] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/plugins/"] [unique_id "al4YnhXES7Mv0Zfga-kpSgAAALw"]
[Mon Jul 20 06:46:22.312275 2026] [security2:error] [pid 1014214:tid 1014426] [client 207.175.80.208:63793] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YnguRBFTcQNywdCIe0gAAAeE"]
[Mon Jul 20 06:46:22.312477 2026] [security2:error] [pid 1014214:tid 1014444] [client 207.175.80.208:54512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YnguRBFTcQNywdCIe0wAAAfM"]
[Mon Jul 20 06:46:22.456215 2026] [security2:error] [pid 1014214:tid 1014398] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/themes/index.php"] [unique_id "al4YnguRBFTcQNywdCIe3wAAAcU"]
[Mon Jul 20 06:46:22.554540 2026] [security2:error] [pid 1011111:tid 1011265] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "socialputty.co"] [uri "/wp-content/themes/"] [unique_id "al4YnhXES7Mv0Zfga-kpTgAAAJw"]
[Mon Jul 20 06:46:22.565807 2026] [security2:error] [pid 1014214:tid 1014349] [client 57.141.18.88:36816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmwuRBFTcQNywdCIeHgABlBA"]
[Mon Jul 20 06:46:22.647277 2026] [security2:error] [pid 1014214:tid 1014356] [client 158.173.241.141:48315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4YnguRBFTcQNywdCIe3AAAAZs"], referer: http://sesamegreenbeans.com/about-sesame-green-beans/
[Mon Jul 20 06:46:22.749436 2026] [autoindex:error] [pid 1011111:tid 1011330] [client 143.244.57.118:54944] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:22.749988 2026] [security2:error] [pid 1011111:tid 1011330] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-admin/includes/"] [unique_id "al4YnhXES7Mv0Zfga-kpVQAAAN0"]
[Mon Jul 20 06:46:22.945687 2026] [security2:error] [pid 1014214:tid 1014447] [client 207.175.80.208:50142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YnguRBFTcQNywdCIe-gAAAfY"]
[Mon Jul 20 06:46:22.991576 2026] [security2:error] [pid 1011111:tid 1011303] [client 34.73.38.214:56650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.jennylouraya.com"] [uri "/xmlrpc.php"] [unique_id "al4YnhXES7Mv0Zfga-kpYwAAAMI"]
[Mon Jul 20 06:46:22.998419 2026] [security2:error] [pid 1011111:tid 1011270] [client 207.175.80.208:52692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YnhXES7Mv0Zfga-kpZQAAAKE"]
[Mon Jul 20 06:46:23.028743 2026] [security2:error] [pid 1011111:tid 1011367] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/index.php"] [unique_id "al4YnhXES7Mv0Zfga-kpXgAAAQI"]
[Mon Jul 20 06:46:23.037953 2026] [security2:error] [pid 1014214:tid 1014256] [remote 173.249.4.11:40481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YnwuRBFTcQNywdCIe_wABpCk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:46:23.112127 2026] [security2:error] [pid 1011111:tid 1011287] [client 14.225.17.146:58121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4YnhXES7Mv0Zfga-kpWgAAALI"]
[Mon Jul 20 06:46:23.345451 2026] [security2:error] [pid 1011111:tid 1011242] [client 112.208.70.94:44269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YnxXES7Mv0Zfga-kpcQAAAIU"]
[Mon Jul 20 06:46:23.345584 2026] [security2:error] [pid 1011111:tid 1011242] [client 112.208.70.94:44269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YnxXES7Mv0Zfga-kpcQAAAIU"]
[Mon Jul 20 06:46:23.384554 2026] [security2:error] [pid 1014214:tid 1014385] [client 104.234.53.68:45513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YnwuRBFTcQNywdCIfDQAAAbg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:23.457360 2026] [security2:error] [pid 1014214:tid 1014363] [client 57.141.18.94:26816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YmwuRBFTcQNywdCIeTAABomo"]
[Mon Jul 20 06:46:23.466047 2026] [security2:error] [pid 1011111:tid 1011310] [client 176.118.193.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4YnxXES7Mv0Zfga-kpbwAAAMk"]
[Mon Jul 20 06:46:23.576176 2026] [security2:error] [pid 1011111:tid 1011347] [client 207.175.80.208:55635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice.ca"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YnxXES7Mv0Zfga-kpfQAAAO4"]
[Mon Jul 20 06:46:23.606656 2026] [security2:error] [pid 1014214:tid 1014463] [client 143.244.57.118:51578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "socialputty.co"] [uri "/wp-admin/index.php"] [unique_id "al4YnwuRBFTcQNywdCIfEwAAAgY"]
[Mon Jul 20 06:46:23.615651 2026] [security2:error] [pid 1011111:tid 1011340] [client 207.175.80.208:49294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "newoffice-ca.innspace.ca"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YnxXES7Mv0Zfga-kpkQAAAOc"]
[Mon Jul 20 06:46:23.641562 2026] [security2:error] [pid 1014214:tid 1014406] [client 104.234.53.68:45513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YnwuRBFTcQNywdCIfGwAAAc0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:23.715802 2026] [security2:error] [pid 1011111:tid 1011139] [remote 57.141.18.40:28606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4YnxXES7Mv0Zfga-kpmAAAuBo"]
[Mon Jul 20 06:46:23.749976 2026] [security2:error] [pid 1014214:tid 1014402] [client 143.244.57.118:51578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YnwuRBFTcQNywdCIfIAAAAck"]
[Mon Jul 20 06:46:23.750091 2026] [security2:error] [pid 1014214:tid 1014402] [client 143.244.57.118:51578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "socialputty.co"] [uri "/wp-login.php"] [unique_id "al4YnwuRBFTcQNywdCIfIAAAAck"]
[Mon Jul 20 06:46:23.802846 2026] [security2:error] [pid 1011111:tid 1011251] [client 34.73.38.214:50323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YnxXES7Mv0Zfga-kpngAAAI4"]
[Mon Jul 20 06:46:23.931799 2026] [autoindex:error] [pid 1014214:tid 1014428] [client 143.244.57.118:0] AH01276: Cannot serve directory /home1/whytuomy/public_html/website_55cf0d41/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:46:23.932260 2026] [security2:error] [pid 1014214:tid 1014428] [client 143.244.57.118:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "socialputty.co"] [uri "/cgi-sys/403.html"] [unique_id "al4YnwuRBFTcQNywdCIfJwAAAeM"]
[Mon Jul 20 06:46:23.945377 2026] [security2:error] [pid 1011111:tid 1011295] [client 143.244.57.118:54944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "socialputty.co"] [uri "/wp-content/upgrade/"] [unique_id "al4YnxXES7Mv0Zfga-kpoAAAALo"]
[Mon Jul 20 06:46:24.067143 2026] [security2:error] [pid 1014214:tid 1014444] [client 50.116.65.227:29404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YoAuRBFTcQNywdCIfMQAAAfM"]
[Mon Jul 20 06:46:24.076909 2026] [security2:error] [pid 1011111:tid 1011356] [client 50.116.65.227:29418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YoBXES7Mv0Zfga-kpqwAAAPc"]
[Mon Jul 20 06:46:24.170293 2026] [security2:error] [pid 1011111:tid 1011326] [client 57.141.18.26:25858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YnBXES7Mv0Zfga-kpBQAA2QA"]
[Mon Jul 20 06:46:24.196812 2026] [security2:error] [pid 1011111:tid 1011250] [client 14.225.17.146:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4YnhXES7Mv0Zfga-kpVwAAAI0"], referer: http://inspirespublishing.com/New
[Mon Jul 20 06:46:24.307954 2026] [security2:error] [pid 1014214:tid 1014462] [client 14.225.17.146:58048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4YnguRBFTcQNywdCIe8wAAAgU"], referer: http://nurturemarple.co.uk/New
[Mon Jul 20 06:46:24.623868 2026] [security2:error] [pid 1014214:tid 1014434] [client 104.234.53.65:60373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YoAuRBFTcQNywdCIfTwAAAek"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:24.775427 2026] [security2:error] [pid 1011111:tid 1011335] [client 50.116.65.227:29434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4YoBXES7Mv0Zfga-kpvwAAAOI"]
[Mon Jul 20 06:46:24.954396 2026] [security2:error] [pid 1014214:tid 1014452] [client 50.116.65.227:29446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4YoAuRBFTcQNywdCIfXQAAAfs"]
[Mon Jul 20 06:46:25.054657 2026] [security2:error] [pid 1014214:tid 1014396] [client 103.238.106.162:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YoQuRBFTcQNywdCIfcAAAAcM"]
[Mon Jul 20 06:46:25.054790 2026] [security2:error] [pid 1014214:tid 1014396] [client 103.238.106.162:60931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YoQuRBFTcQNywdCIfcAAAAcM"]
[Mon Jul 20 06:46:25.120700 2026] [security2:error] [pid 1014214:tid 1014430] [client 104.234.53.65:60373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YoQuRBFTcQNywdCIfdAAAAeU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:25.220210 2026] [security2:error] [pid 1014214:tid 1014365] [client 14.225.17.146:64962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4YoQuRBFTcQNywdCIfcwAAAaQ"], referer: https://nurturemarple.co.uk/New
[Mon Jul 20 06:46:25.283149 2026] [security2:error] [pid 1014214:tid 1014397] [client 57.141.18.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YoQuRBFTcQNywdCIfegAAAcQ"]
[Mon Jul 20 06:46:25.338958 2026] [security2:error] [pid 1014214:tid 1014391] [client 57.141.18.38:59218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YnQuRBFTcQNywdCIergABvms"]
[Mon Jul 20 06:46:25.358774 2026] [security2:error] [pid 1011111:tid 1011232] [remote 176.56.118.182:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YoRXES7Mv0Zfga-kp0AAA6nc"]
[Mon Jul 20 06:46:25.428450 2026] [security2:error] [pid 1014214:tid 1014346] [client 14.224.227.113:54695] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YoQuRBFTcQNywdCIfgwAAAZE"]
[Mon Jul 20 06:46:25.429726 2026] [security2:error] [pid 1011111:tid 1011338] [client 163.172.135.240:35306] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4YoRXES7Mv0Zfga-kp0gAAAOU"]
[Mon Jul 20 06:46:25.482901 2026] [security2:error] [pid 1014214:tid 1014469] [client 106.219.188.178:53898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YoQuRBFTcQNywdCIfiQAAAgw"]
[Mon Jul 20 06:46:25.482994 2026] [security2:error] [pid 1014214:tid 1014469] [client 106.219.188.178:53898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YoQuRBFTcQNywdCIfiQAAAgw"]
[Mon Jul 20 06:46:25.528485 2026] [security2:error] [pid 1014214:tid 1014404] [client 14.225.17.146:58152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4YoQuRBFTcQNywdCIfhQAAAcs"], referer: http://adultdaycarereno.com/New
[Mon Jul 20 06:46:25.528982 2026] [security2:error] [pid 1011111:tid 1011291] [client 34.73.38.214:53142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YoRXES7Mv0Zfga-kp0wAAALY"]
[Mon Jul 20 06:46:25.596251 2026] [security2:error] [pid 1011111:tid 1011198] [remote 176.56.118.182:54664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YoRXES7Mv0Zfga-kp1QAAzlU"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:46:25.669542 2026] [security2:error] [pid 1014214:tid 1014349] [client 95.70.149.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4YoQuRBFTcQNywdCIfeQAAAZQ"], referer: https://blog.danwolfe.us
[Mon Jul 20 06:46:25.716267 2026] [security2:error] [pid 1014214:tid 1014454] [client 217.142.18.172:36816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YoQuRBFTcQNywdCIfkgAAAf0"]
[Mon Jul 20 06:46:25.716378 2026] [security2:error] [pid 1014214:tid 1014454] [client 217.142.18.172:36816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YoQuRBFTcQNywdCIfkgAAAf0"]
[Mon Jul 20 06:46:25.717130 2026] [security2:error] [pid 1014214:tid 1014388] [client 34.73.38.214:61281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YoQuRBFTcQNywdCIfkwAAAbs"]
[Mon Jul 20 06:46:25.992922 2026] [security2:error] [pid 1014214:tid 1014394] [client 57.141.18.44:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YnguRBFTcQNywdCIe6QABwWQ"]
[Mon Jul 20 06:46:25.993064 2026] [security2:error] [pid 1011111:tid 1011356] [client 185.91.123.62:38542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YoRXES7Mv0Zfga-kp5gAA9w8"]
[Mon Jul 20 06:46:25.994607 2026] [security2:error] [pid 1014214:tid 1014420] [client 45.3.41.19:49881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YoQuRBFTcQNywdCIfpAAAAds"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:26.167924 2026] [security2:error] [pid 1011111:tid 1011307] [client 49.36.168.65:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.168.36.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "notthesermon.com"] [uri "/xmlrpc.php"] [unique_id "al4YohXES7Mv0Zfga-kp5wAAAMY"]
[Mon Jul 20 06:46:26.168136 2026] [security2:error] [pid 1011111:tid 1011307] [client 49.36.168.65:60931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "notthesermon.com"] [uri "/xmlrpc.php"] [unique_id "al4YohXES7Mv0Zfga-kp5wAAAMY"]
[Mon Jul 20 06:46:26.168488 2026] [security2:error] [pid 1011111:tid 1011266] [client 57.141.18.73:46696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YnhXES7Mv0Zfga-kpWQAAnQM"]
[Mon Jul 20 06:46:26.191397 2026] [security2:error] [pid 1014214:tid 1014360] [client 187.108.85.186:58275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YoguRBFTcQNywdCIfswAAAZ8"]
[Mon Jul 20 06:46:26.191504 2026] [security2:error] [pid 1014214:tid 1014360] [client 187.108.85.186:58275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YoguRBFTcQNywdCIfswAAAZ8"]
[Mon Jul 20 06:46:26.288500 2026] [security2:error] [pid 1011111:tid 1011260] [client 57.141.18.7:50820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YnhXES7Mv0Zfga-kpXQAAl18"]
[Mon Jul 20 06:46:26.408674 2026] [security2:error] [pid 1014214:tid 1014414] [client 14.225.17.146:50420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4YoguRBFTcQNywdCIfvQAAAdU"], referer: https://adultdaycarereno.com/New
[Mon Jul 20 06:46:26.786400 2026] [security2:error] [pid 1014214:tid 1014397] [client 103.125.179.95:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YoguRBFTcQNywdCIf0gAAAcQ"]
[Mon Jul 20 06:46:26.786732 2026] [security2:error] [pid 1014214:tid 1014397] [client 103.125.179.95:56802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YoguRBFTcQNywdCIf0gAAAcQ"]
[Mon Jul 20 06:46:26.819406 2026] [security2:error] [pid 1011111:tid 1011349] [client 65.111.15.52:35167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YohXES7Mv0Zfga-kp9wAAAPA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:27.060071 2026] [security2:error] [pid 1011111:tid 1011318] [client 34.73.38.214:49659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YoxXES7Mv0Zfga-kqAAAAANE"]
[Mon Jul 20 06:46:27.088915 2026] [security2:error] [pid 1014214:tid 1014422] [client 183.82.98.154:64494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YowuRBFTcQNywdCIf4QAAAd0"]
[Mon Jul 20 06:46:27.089008 2026] [security2:error] [pid 1014214:tid 1014422] [client 183.82.98.154:64494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YowuRBFTcQNywdCIf4QAAAd0"]
[Mon Jul 20 06:46:27.221872 2026] [security2:error] [pid 1011111:tid 1011338] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YoxXES7Mv0Zfga-kqAQAAAOU"]
[Mon Jul 20 06:46:27.300220 2026] [security2:error] [pid 1011111:tid 1011303] [client 57.141.18.67:35470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YoBXES7Mv0Zfga-kpsQAAwlM"]
[Mon Jul 20 06:46:27.328310 2026] [security2:error] [pid 1011111:tid 1011157] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YoxXES7Mv0Zfga-kqCQAA4yw"]
[Mon Jul 20 06:46:27.328461 2026] [security2:error] [pid 1011111:tid 1011336] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YoxXES7Mv0Zfga-kqCQAA4yw"]
[Mon Jul 20 06:46:27.360143 2026] [security2:error] [pid 1014214:tid 1014376] [client 57.141.18.12:30696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YoAuRBFTcQNywdCIfOAABrw8"]
[Mon Jul 20 06:46:27.492385 2026] [security2:error] [pid 1014214:tid 1014241] [remote 57.141.18.64:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3688465"] [unique_id "al4YowuRBFTcQNywdCIf8AAB3ho"]
[Mon Jul 20 06:46:27.500314 2026] [security2:error] [pid 1014214:tid 1014450] [client 34.73.38.214:57060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YowuRBFTcQNywdCIf8QAAAfk"]
[Mon Jul 20 06:46:27.635677 2026] [security2:error] [pid 1011111:tid 1011342] [client 136.108.37.179:65461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allisonsatterfield.alaraycreative.com"] [uri "/index.php"] [unique_id "al4YoxXES7Mv0Zfga-kqDQAAAOk"]
[Mon Jul 20 06:46:27.645375 2026] [security2:error] [pid 1011111:tid 1011243] [client 57.141.18.90:60438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YoBXES7Mv0Zfga-kpwQAAhls"]
[Mon Jul 20 06:46:27.688248 2026] [security2:error] [pid 1011111:tid 1011339] [client 136.108.37.179:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.37.108.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allisonsatterfield.alaraycreative.com"] [uri "/xmlrpc.php"] [unique_id "al4YoxXES7Mv0Zfga-kqGQAAAOY"]
[Mon Jul 20 06:46:27.688407 2026] [security2:error] [pid 1011111:tid 1011339] [client 136.108.37.179:65461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "allisonsatterfield.alaraycreative.com"] [uri "/xmlrpc.php"] [unique_id "al4YoxXES7Mv0Zfga-kqGQAAAOY"]
[Mon Jul 20 06:46:27.884149 2026] [access_compat:error] [pid 1014214:tid 1014239] [remote 44.198.188.40:39698] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:27.989886 2026] [security2:error] [pid 1011111:tid 1011242] [client 124.243.188.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4YoxXES7Mv0Zfga-kqHQAAhQw"], referer: https://www.aleishapenny.ca/listing/page/578?paged=578&view=grid
[Mon Jul 20 06:46:28.201108 2026] [security2:error] [pid 1011111:tid 1011161] [remote 152.228.213.32:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4YpBXES7Mv0Zfga-kqJQAAmTA"]
[Mon Jul 20 06:46:28.220244 2026] [security2:error] [pid 1011111:tid 1011256] [client 14.225.17.146:64514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4YoxXES7Mv0Zfga-kqDAAAAJM"], referer: http://overloadcomedy.com/New
[Mon Jul 20 06:46:28.398239 2026] [security2:error] [pid 1011111:tid 1011148] [remote 152.228.213.32:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4YpBXES7Mv0Zfga-kqMQAA5yM"], referer: https://rtkenergypartners.com/wp-login.php
[Mon Jul 20 06:46:28.554634 2026] [security2:error] [pid 1014214:tid 1014439] [client 65.111.3.105:23045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YpAuRBFTcQNywdCIgFgAB7gs"]
[Mon Jul 20 06:46:28.581321 2026] [security2:error] [pid 1011111:tid 1011286] [client 34.73.38.214:57056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YpBXES7Mv0Zfga-kqPAAAALE"]
[Mon Jul 20 06:46:28.977835 2026] [security2:error] [pid 1014214:tid 1014317] [remote 216.73.216.55:24232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4YpAuRBFTcQNywdCIgJQABtmY"]
[Mon Jul 20 06:46:28.990113 2026] [security2:error] [pid 1011111:tid 1011126] [remote 57.141.18.91:37830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2714338"] [unique_id "al4YpBXES7Mv0Zfga-kqRAAA2w0"]
[Mon Jul 20 06:46:29.171772 2026] [security2:error] [pid 1014214:tid 1014452] [client 52.109.68.130:5888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YpQuRBFTcQNywdCIgLQAAAfs"]
[Mon Jul 20 06:46:29.322763 2026] [security2:error] [pid 1014214:tid 1014468] [client 52.109.68.130:5888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YpQuRBFTcQNywdCIgMwAAAgs"]
[Mon Jul 20 06:46:29.423645 2026] [security2:error] [pid 1011111:tid 1011341] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpRXES7Mv0Zfga-kqWQAAAOg"]
[Mon Jul 20 06:46:29.427084 2026] [security2:error] [pid 1011111:tid 1011255] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpRXES7Mv0Zfga-kqWwAAAJI"]
[Mon Jul 20 06:46:29.442938 2026] [security2:error] [pid 1014214:tid 1014402] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpQuRBFTcQNywdCIgNwAAAck"]
[Mon Jul 20 06:46:29.446608 2026] [security2:error] [pid 1014214:tid 1014413] [client 117.247.108.24:24773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YpQuRBFTcQNywdCIgOAAAAdQ"]
[Mon Jul 20 06:46:29.446707 2026] [security2:error] [pid 1014214:tid 1014413] [client 117.247.108.24:24773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YpQuRBFTcQNywdCIgOAAAAdQ"]
[Mon Jul 20 06:46:29.448883 2026] [security2:error] [pid 1014214:tid 1014422] [client 152.58.191.29:61010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YpQuRBFTcQNywdCIgOQAAAd0"]
[Mon Jul 20 06:46:29.448967 2026] [security2:error] [pid 1014214:tid 1014422] [client 152.58.191.29:61010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YpQuRBFTcQNywdCIgOQAAAd0"]
[Mon Jul 20 06:46:29.501875 2026] [security2:error] [pid 1014214:tid 1014406] [client 57.141.18.34:50666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YoguRBFTcQNywdCIfqQABzX4"]
[Mon Jul 20 06:46:29.702098 2026] [security2:error] [pid 1014214:tid 1014394] [client 223.185.13.213:29338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YpQuRBFTcQNywdCIgQwAAAcE"]
[Mon Jul 20 06:46:29.702228 2026] [security2:error] [pid 1014214:tid 1014394] [client 223.185.13.213:29338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YpQuRBFTcQNywdCIgQwAAAcE"]
[Mon Jul 20 06:46:29.763068 2026] [core:error] [pid 1014214:tid 1014371] [client 103.153.183.69:45454] AH10244: invalid URI path (/%2e%2e/.env?_=jdrgmgu7&v=ed2lt), referer: https://www.bing.com/search?q=kto1j7
[Mon Jul 20 06:46:29.974264 2026] [security2:error] [pid 1014214:tid 1014287] [remote 172.93.219.170:46692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.219.93.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YpQuRBFTcQNywdCIgVAAB4kg"]
[Mon Jul 20 06:46:29.998349 2026] [security2:error] [pid 1014214:tid 1014451] [client 172.200.24.58:44416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YpQuRBFTcQNywdCIgVwAAAfo"]
[Mon Jul 20 06:46:29.998400 2026] [security2:error] [pid 1011111:tid 1011281] [client 57.141.18.108:55942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YohXES7Mv0Zfga-kp8gAArB8"]
[Mon Jul 20 06:46:30.025169 2026] [security2:error] [pid 1011111:tid 1011324] [client 171.61.165.146:28707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YphXES7Mv0Zfga-kqZQAAANc"]
[Mon Jul 20 06:46:30.025283 2026] [security2:error] [pid 1011111:tid 1011324] [client 171.61.165.146:28707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YphXES7Mv0Zfga-kqZQAAANc"]
[Mon Jul 20 06:46:30.053142 2026] [security2:error] [pid 1014214:tid 1014347] [client 172.200.24.58:44416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YpguRBFTcQNywdCIgWwAAAZI"]
[Mon Jul 20 06:46:30.161158 2026] [security2:error] [pid 1014214:tid 1014429] [client 89.58.73.111:56403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpguRBFTcQNywdCIgXAAAAeQ"]
[Mon Jul 20 06:46:30.171040 2026] [security2:error] [pid 1011111:tid 1011279] [client 89.58.73.111:38730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YphXES7Mv0Zfga-kqZwAAAKo"]
[Mon Jul 20 06:46:30.194769 2026] [security2:error] [pid 1014214:tid 1014396] [client 14.225.17.146:53492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4YpQuRBFTcQNywdCIgVgAAAcM"], referer: http://amalia-capital.com/New
[Mon Jul 20 06:46:30.200679 2026] [security2:error] [pid 1014214:tid 1014452] [client 34.73.38.214:62168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YpguRBFTcQNywdCIgYQAAAfs"]
[Mon Jul 20 06:46:30.232971 2026] [security2:error] [pid 1011111:tid 1011193] [remote 57.141.18.80:41894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4252567"] [unique_id "al4YphXES7Mv0Zfga-kqbQAA0VA"]
[Mon Jul 20 06:46:30.321157 2026] [security2:error] [pid 1014214:tid 1014355] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YpguRBFTcQNywdCIgXwAAAZo"]
[Mon Jul 20 06:46:30.359513 2026] [security2:error] [pid 1014214:tid 1014303] [remote 172.93.219.170:46692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.219.93.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YpguRBFTcQNywdCIgcgABtFg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:46:30.388112 2026] [security2:error] [pid 1011111:tid 1011361] [client 14.225.17.146:53426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4YpRXES7Mv0Zfga-kqUgAAAPw"], referer: http://intelligentengineeringsolutions.com/New
[Mon Jul 20 06:46:30.509215 2026] [security2:error] [pid 1014214:tid 1014446] [client 199.167.138.22:60638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.138.167.199.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/index.php"] [unique_id "al4YpguRBFTcQNywdCIgegAAAfU"], referer: http://www.marscafe.com/index.php?board=39.0
[Mon Jul 20 06:46:30.623825 2026] [security2:error] [pid 1014214:tid 1014439] [client 199.167.138.22:60652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marscafe.com"] [uri "/index.php"] [unique_id "al4YpguRBFTcQNywdCIgfwAAAe4"], referer: http://www.marscafe.com/index.php?board=39.0
[Mon Jul 20 06:46:30.644186 2026] [security2:error] [pid 1014214:tid 1014423] [client 103.168.67.159:37812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.membresiabeyou.com"] [uri "/app/.env"] [unique_id "al4YpguRBFTcQNywdCIggQAAAd4"], referer: https://www.reddit.com/
[Mon Jul 20 06:46:30.688156 2026] [security2:error] [pid 1014214:tid 1014447] [client 57.141.18.16:57914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YowuRBFTcQNywdCIf5AAB9lk"]
[Mon Jul 20 06:46:30.786070 2026] [security2:error] [pid 1011111:tid 1011342] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YphXES7Mv0Zfga-kqeQAAAOk"]
[Mon Jul 20 06:46:30.804709 2026] [security2:error] [pid 1014214:tid 1014441] [client 114.119.133.158:41447] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/grantees"] [unique_id "al4YpguRBFTcQNywdCIgiAAAAfA"], referer: https://adambergeron.com/grantees?topic%5B0%5D=25&topic%5B1%5D=116&page=2
[Mon Jul 20 06:46:30.824216 2026] [security2:error] [pid 1011111:tid 1011336] [client 158.173.89.95:38003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YphXES7Mv0Zfga-kqfgAAAOM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:46:31.200907 2026] [security2:error] [pid 1014214:tid 1014412] [client 98.159.234.160:20111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YpwuRBFTcQNywdCIgmQAAAdM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:46:31.272347 2026] [security2:error] [pid 1011111:tid 1011307] [client 14.225.17.146:53611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4YpxXES7Mv0Zfga-kqjAAAAMY"], referer: http://xp-design.co/New
[Mon Jul 20 06:46:31.284842 2026] [security2:error] [pid 1014214:tid 1014386] [client 34.73.38.214:50118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YpwuRBFTcQNywdCIgoQAAAbk"]
[Mon Jul 20 06:46:31.378153 2026] [security2:error] [pid 1014214:tid 1014365] [client 37.52.210.45:60251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YpwuRBFTcQNywdCIgpAAAAaQ"]
[Mon Jul 20 06:46:31.378313 2026] [security2:error] [pid 1014214:tid 1014365] [client 37.52.210.45:60251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YpwuRBFTcQNywdCIgpAAAAaQ"]
[Mon Jul 20 06:46:31.523863 2026] [security2:error] [pid 1011111:tid 1011284] [client 57.141.18.27:46608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpBXES7Mv0Zfga-kqIQAAr3E"]
[Mon Jul 20 06:46:31.570313 2026] [security2:error] [pid 1011111:tid 1011345] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4YpxXES7Mv0Zfga-kqigAA7H8"], referer: http://ardhalwafaa.com/New
[Mon Jul 20 06:46:31.824238 2026] [security2:error] [pid 1011111:tid 1011353] [client 62.197.45.116:63710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.45.197.62.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YpxXES7Mv0Zfga-kqmAAAAPQ"], referer: https://swafforddetailing.com/
[Mon Jul 20 06:46:31.870843 2026] [security2:error] [pid 1011111:tid 1011354] [client 57.141.18.104:25724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpBXES7Mv0Zfga-kqNQAA9Xw"]
[Mon Jul 20 06:46:32.236702 2026] [security2:error] [pid 1014214:tid 1014254] [remote 45.90.123.233:54124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YqAuRBFTcQNywdCIg1wABmic"]
[Mon Jul 20 06:46:32.236916 2026] [security2:error] [pid 1014214:tid 1014355] [client 45.90.123.233:54124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YqAuRBFTcQNywdCIg1wABmic"]
[Mon Jul 20 06:46:32.332146 2026] [security2:error] [pid 1011111:tid 1011361] [client 34.73.38.214:60234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YqBXES7Mv0Zfga-kqqAAAAPw"]
[Mon Jul 20 06:46:32.465034 2026] [security2:error] [pid 1014214:tid 1014389] [client 14.225.17.146:64794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4YqAuRBFTcQNywdCIgzgAAAbw"], referer: http://idigress.group/New
[Mon Jul 20 06:46:32.491435 2026] [security2:error] [pid 1014214:tid 1014363] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpQuRBFTcQNywdCIgNgAAAaI"]
[Mon Jul 20 06:46:32.741327 2026] [security2:error] [pid 1014214:tid 1014429] [client 14.225.17.146:64651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4YpwuRBFTcQNywdCIgogAAAeQ"], referer: http://sarahsnyder.net/New
[Mon Jul 20 06:46:32.824012 2026] [security2:error] [pid 1011111:tid 1011300] [client 192.102.108.149:7385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YqBXES7Mv0Zfga-kqsQAAvzQ"]
[Mon Jul 20 06:46:33.085647 2026] [security2:error] [pid 1014214:tid 1014269] [remote 152.228.213.32:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4YqQuRBFTcQNywdCIhAQABkTY"]
[Mon Jul 20 06:46:33.116848 2026] [security2:error] [pid 1014214:tid 1014436] [client 57.141.18.113:51256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YpQuRBFTcQNywdCIgTQAB61M"]
[Mon Jul 20 06:46:33.120443 2026] [security2:error] [pid 1014214:tid 1014439] [client 77.110.127.138:55255] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampbnpa6Fzk' OR 828. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 828 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YqQuRBFTcQNywdCIhAgAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:33.294224 2026] [security2:error] [pid 1014214:tid 1014267] [remote 152.228.213.32:35382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4YqQuRBFTcQNywdCIhDAABzjQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:46:33.296893 2026] [security2:error] [pid 1014214:tid 1014238] [remote 47.128.58.206:43446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gertoger.org"] [uri "/tour/mongolia-car-tour-gobi-desert-nomad-lifestyle/"] [unique_id "al4YqQuRBFTcQNywdCIhDQAB4Bc"]
[Mon Jul 20 06:46:33.353789 2026] [security2:error] [pid 1014214:tid 1014470] [client 14.225.17.146:53782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4YpwuRBFTcQNywdCIgjgAAAg0"], referer: http://hilltopnurseryinc.com/New
[Mon Jul 20 06:46:33.425032 2026] [security2:error] [pid 1014214:tid 1014433] [client 34.73.38.214:57366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YqQuRBFTcQNywdCIhFAAAAeg"]
[Mon Jul 20 06:46:33.480178 2026] [security2:error] [pid 1011111:tid 1011363] [client 114.119.137.193:30401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.secretkeynumerology.com"] [uri "/sixth-sense/"] [unique_id "al4YqRXES7Mv0Zfga-kq5AAAAP4"], referer: https://www.secretkeynumerology.com/sixth-sense
[Mon Jul 20 06:46:33.610674 2026] [security2:error] [pid 1014214:tid 1014460] [client 197.186.66.42:49959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YqQuRBFTcQNywdCIhJAAAAgM"]
[Mon Jul 20 06:46:33.613265 2026] [security2:error] [pid 1014214:tid 1014460] [client 197.186.66.42:49959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YqQuRBFTcQNywdCIhJAAAAgM"]
[Mon Jul 20 06:46:33.648851 2026] [security2:error] [pid 1011111:tid 1011242] [client 14.225.17.146:64459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4YqRXES7Mv0Zfga-kq3wAAAIU"], referer: http://secretkeynumerology.com/New
[Mon Jul 20 06:46:33.714478 2026] [security2:error] [pid 1014214:tid 1014349] [client 14.225.17.146:64573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4YqQuRBFTcQNywdCIhHgAAAZQ"], referer: https://sarahsnyder.net/New
[Mon Jul 20 06:46:33.734486 2026] [security2:error] [pid 1011111:tid 1011249] [client 192.140.149.97:45331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YqRXES7Mv0Zfga-kq7wAAAIw"]
[Mon Jul 20 06:46:33.734607 2026] [security2:error] [pid 1011111:tid 1011249] [client 192.140.149.97:45331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YqRXES7Mv0Zfga-kq7wAAAIw"]
[Mon Jul 20 06:46:33.765654 2026] [core:error] [pid 1014214:tid 1014403] [client 14.225.17.146:64934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/New
[Mon Jul 20 06:46:33.765676 2026] [core:error] [pid 1014214:tid 1014403] [client 14.225.17.146:64934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/New
[Mon Jul 20 06:46:33.923257 2026] [security2:error] [pid 1014214:tid 1014431] [client 112.208.70.94:44711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YqQuRBFTcQNywdCIhOwAAAeY"]
[Mon Jul 20 06:46:33.923380 2026] [security2:error] [pid 1014214:tid 1014431] [client 112.208.70.94:44711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YqQuRBFTcQNywdCIhOwAAAeY"]
[Mon Jul 20 06:46:34.124306 2026] [security2:error] [pid 1014214:tid 1014382] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YqQuRBFTcQNywdCIhPAAAAbU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:34.293093 2026] [security2:error] [pid 1014214:tid 1014344] [client 103.153.183.69:45468] ModSecurity: Warning. Pattern match "%2e.%2e%2e" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1522"] [id "900917"] [msg "temporary CVE-2021-41773 logging rule"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/%2e%2e/%2e%2e/etc/passwd"] [unique_id "al4YqguRBFTcQNywdCIhVQAAAY8"], referer: https://twitter.com/
[Mon Jul 20 06:46:34.293156 2026] [core:error] [pid 1014214:tid 1014344] [client 103.153.183.69:45468] AH10244: invalid URI path (/%2e%2e/%2e%2e/etc/passwd?_=z6d8ob7q&v=oenzb), referer: https://twitter.com/
[Mon Jul 20 06:46:34.295452 2026] [security2:error] [pid 1014214:tid 1014349] [client 127.0.0.1:21996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4YqguRBFTcQNywdCIhVgAAAZQ"], referer: https://twitter.com/
[Mon Jul 20 06:46:34.332914 2026] [security2:error] [pid 1011111:tid 1011316] [client 77.110.127.138:55267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YqhXES7Mv0Zfga-krAAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:34.333005 2026] [security2:error] [pid 1011111:tid 1011316] [client 77.110.127.138:55267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YqhXES7Mv0Zfga-krAAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:34.637064 2026] [security2:error] [pid 1014214:tid 1014452] [client 14.225.17.146:52847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4YqguRBFTcQNywdCIhYAAAAfs"], referer: https://secretkeynumerology.com/New
[Mon Jul 20 06:46:34.737287 2026] [security2:error] [pid 1011111:tid 1011320] [client 34.73.38.214:61197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jennylouraya.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YqhXES7Mv0Zfga-krBQAAANM"]
[Mon Jul 20 06:46:34.834293 2026] [security2:error] [pid 1014214:tid 1014342] [remote 20.153.140.50:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4YqguRBFTcQNywdCIhdQAB938"]
[Mon Jul 20 06:46:35.018623 2026] [security2:error] [pid 1014214:tid 1014387] [client 104.234.53.57:39607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YqguRBFTcQNywdCIhewAAAbo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:35.247310 2026] [security2:error] [pid 1011111:tid 1011259] [client 57.141.18.10:41112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YqBXES7Mv0Zfga-kqnQAAljM"]
[Mon Jul 20 06:46:35.259723 2026] [security2:error] [pid 1014214:tid 1014229] [remote 20.153.140.50:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4YqwuRBFTcQNywdCIhigAByg4"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:46:35.269593 2026] [security2:error] [pid 1014214:tid 1014354] [client 14.225.17.146:55077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4YqguRBFTcQNywdCIhUQAAAZk"], referer: http://travelbyfire.com/New
[Mon Jul 20 06:46:35.291637 2026] [security2:error] [pid 1011111:tid 1011289] [client 57.141.18.78:39592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YqBXES7Mv0Zfga-kqowAAtEA"]
[Mon Jul 20 06:46:35.537255 2026] [security2:error] [pid 1011111:tid 1011344] [client 103.238.106.162:60586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YqxXES7Mv0Zfga-krFwAAAOs"]
[Mon Jul 20 06:46:35.537373 2026] [security2:error] [pid 1011111:tid 1011344] [client 103.238.106.162:60586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YqxXES7Mv0Zfga-krFwAAAOs"]
[Mon Jul 20 06:46:35.965513 2026] [security2:error] [pid 1011111:tid 1011251] [client 57.141.18.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4YqxXES7Mv0Zfga-krJwAAAI4"]
[Mon Jul 20 06:46:36.005086 2026] [security2:error] [pid 1014214:tid 1014406] [client 46.110.96.34:48818] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4YrAuRBFTcQNywdCIhqAAAAc0"]
[Mon Jul 20 06:46:36.068609 2026] [security2:error] [pid 1014214:tid 1014454] [client 14.225.17.146:55107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4YqguRBFTcQNywdCIhYgAAAf0"], referer: https://north-woods-engineering.com/New
[Mon Jul 20 06:46:36.175990 2026] [security2:error] [pid 1014214:tid 1014363] [client 14.225.17.146:64776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4YrAuRBFTcQNywdCIhuAAAAaI"], referer: https://travelbyfire.com/New
[Mon Jul 20 06:46:36.269181 2026] [security2:error] [pid 1014214:tid 1014365] [client 217.142.18.172:35264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YrAuRBFTcQNywdCIhvAAAAaQ"]
[Mon Jul 20 06:46:36.269321 2026] [security2:error] [pid 1014214:tid 1014365] [client 217.142.18.172:35264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YrAuRBFTcQNywdCIhvAAAAaQ"]
[Mon Jul 20 06:46:36.284044 2026] [security2:error] [pid 1014214:tid 1014410] [client 111.221.140.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4YrAuRBFTcQNywdCIhsgAAAdE"]
[Mon Jul 20 06:46:36.324931 2026] [security2:error] [pid 1011111:tid 1011233] [remote 115.74.105.156:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YrBXES7Mv0Zfga-krLQAAiHg"]
[Mon Jul 20 06:46:36.572738 2026] [security2:error] [pid 1014214:tid 1014402] [client 14.225.17.146:59217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4YqguRBFTcQNywdCIhXQAAAck"], referer: http://latiendadejorge.com.gt/New
[Mon Jul 20 06:46:36.710544 2026] [proxy:error] [pid 1014214:tid 1014463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:36.710615 2026] [proxy_http:error] [pid 1014214:tid 1014463] [client 34.73.38.214:53675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:36.711265 2026] [proxy:error] [pid 1014214:tid 1014463] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:36.711302 2026] [proxy_http:error] [pid 1014214:tid 1014463] [client 34.73.38.214:53675] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:36.738927 2026] [core:error] [pid 1014214:tid 1014368] [client 14.225.17.146:56400] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:46:36.738943 2026] [core:error] [pid 1014214:tid 1014368] [client 14.225.17.146:56400] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:46:36.924514 2026] [security2:error] [pid 1014214:tid 1014308] [remote 182.77.62.24:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4YrAuRBFTcQNywdCIh9QAB7l0"]
[Mon Jul 20 06:46:36.936000 2026] [security2:error] [pid 1014214:tid 1014426] [client 187.108.85.186:58832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YrAuRBFTcQNywdCIh9wAAAeE"]
[Mon Jul 20 06:46:36.936155 2026] [security2:error] [pid 1014214:tid 1014426] [client 187.108.85.186:58832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YrAuRBFTcQNywdCIh9wAAAeE"]
[Mon Jul 20 06:46:37.068897 2026] [security2:error] [pid 1014214:tid 1014266] [remote 217.61.143.92:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4YrQuRBFTcQNywdCIh_QAB8DM"]
[Mon Jul 20 06:46:37.175503 2026] [security2:error] [pid 1014214:tid 1014432] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiAQAAAec"]
[Mon Jul 20 06:46:37.264238 2026] [security2:error] [pid 1014214:tid 1014368] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiDgAAAac"]
[Mon Jul 20 06:46:37.269412 2026] [security2:error] [pid 1014214:tid 1014358] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiDQAAAZ0"]
[Mon Jul 20 06:46:37.298523 2026] [security2:error] [pid 1014214:tid 1014367] [client 8.228.127.164:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.127.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elv.xwy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiFgAAAaY"]
[Mon Jul 20 06:46:37.304001 2026] [security2:error] [pid 1014214:tid 1014233] [remote 217.61.143.92:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4YrQuRBFTcQNywdCIiGQABohI"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 06:46:37.359783 2026] [security2:error] [pid 1014214:tid 1014455] [client 13.215.47.127:17836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiHgAAAf4"]
[Mon Jul 20 06:46:37.359886 2026] [security2:error] [pid 1014214:tid 1014455] [client 13.215.47.127:17836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiHgAAAf4"]
[Mon Jul 20 06:46:37.455276 2026] [security2:error] [pid 1014214:tid 1014257] [remote 182.77.62.24:53130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4YrQuRBFTcQNywdCIiJwACBSo"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:46:37.468823 2026] [security2:error] [pid 1014214:tid 1014464] [client 103.125.179.95:57314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiKgAAAgc"]
[Mon Jul 20 06:46:37.468925 2026] [security2:error] [pid 1014214:tid 1014464] [client 103.125.179.95:57314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiKgAAAgc"]
[Mon Jul 20 06:46:37.499542 2026] [security2:error] [pid 1014214:tid 1014430] [client 57.141.18.77:44946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YqguRBFTcQNywdCIhXAAB5QM"]
[Mon Jul 20 06:46:37.557725 2026] [security2:error] [pid 1014214:tid 1014359] [client 154.83.211.58:56901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.211.83.154.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.frontecinc.com"] [uri "/s.php"] [unique_id "al4YrQuRBFTcQNywdCIiLgAAAZ4"]
[Mon Jul 20 06:46:37.616988 2026] [security2:error] [pid 1014214:tid 1014402] [client 8.228.127.164:54184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YrQuRBFTcQNywdCIiMgAAAck"]
[Mon Jul 20 06:46:37.640669 2026] [security2:error] [pid 1014214:tid 1014416] [client 39.48.81.23:60719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiMwAAAdc"]
[Mon Jul 20 06:46:37.640828 2026] [security2:error] [pid 1014214:tid 1014416] [client 39.48.81.23:60719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiMwAAAdc"]
[Mon Jul 20 06:46:37.687502 2026] [security2:error] [pid 1014214:tid 1014431] [client 89.58.73.111:56424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiMQAAAeY"]
[Mon Jul 20 06:46:37.836809 2026] [security2:error] [pid 1011111:tid 1011230] [remote 57.141.18.73:30946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YqhXES7Mv0Zfga-krBgAAkXU"]
[Mon Jul 20 06:46:37.857098 2026] [security2:error] [pid 1014214:tid 1014357] [client 89.58.73.111:38782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiOwAAAZw"]
[Mon Jul 20 06:46:37.916740 2026] [security2:error] [pid 1014214:tid 1014274] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiUAACBzs"]
[Mon Jul 20 06:46:37.916935 2026] [security2:error] [pid 1014214:tid 1014464] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YrQuRBFTcQNywdCIiUAACBzs"]
[Mon Jul 20 06:46:37.928898 2026] [security2:error] [pid 1014214:tid 1014381] [client 8.228.127.164:54195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YrQuRBFTcQNywdCIiVAAAAbQ"]
[Mon Jul 20 06:46:37.978263 2026] [security2:error] [pid 1014214:tid 1014447] [client 77.110.127.138:55316] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampLOQbuHRN') OR 578. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 578 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YrQuRBFTcQNywdCIiWwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:38.044692 2026] [proxy:error] [pid 1014214:tid 1014365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:38.044776 2026] [proxy_http:error] [pid 1014214:tid 1014365] [client 34.73.38.214:64513] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:38.045281 2026] [proxy:error] [pid 1014214:tid 1014365] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:38.045307 2026] [proxy_http:error] [pid 1014214:tid 1014365] [client 34.73.38.214:64513] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:38.068723 2026] [security2:error] [pid 1014214:tid 1014463] [client 183.82.98.154:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YrguRBFTcQNywdCIiZAAAAgY"]
[Mon Jul 20 06:46:38.068838 2026] [security2:error] [pid 1014214:tid 1014463] [client 183.82.98.154:65080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YrguRBFTcQNywdCIiZAAAAgY"]
[Mon Jul 20 06:46:38.165703 2026] [security2:error] [pid 1014214:tid 1014355] [client 14.225.17.146:64811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiQAAAAZo"], referer: http://backandneckpainrelieflaceychiropractor.com/New
[Mon Jul 20 06:46:38.380454 2026] [security2:error] [pid 1014214:tid 1014370] [client 8.228.127.164:51983] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YrguRBFTcQNywdCIieAAAAak"]
[Mon Jul 20 06:46:38.420542 2026] [security2:error] [pid 1014214:tid 1014352] [client 89.247.252.171:25659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YrguRBFTcQNywdCIidQABlxA"]
[Mon Jul 20 06:46:38.709228 2026] [security2:error] [pid 1014214:tid 1014403] [client 8.228.127.164:60806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YrguRBFTcQNywdCIimAAAAco"]
[Mon Jul 20 06:46:38.858273 2026] [security2:error] [pid 1011111:tid 1011123] [remote 57.141.18.31:22492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YqxXES7Mv0Zfga-krIwAAiwo"]
[Mon Jul 20 06:46:38.946394 2026] [security2:error] [pid 1014214:tid 1014358] [client 152.58.191.29:61494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YrguRBFTcQNywdCIiqwAAAZ0"]
[Mon Jul 20 06:46:38.946486 2026] [security2:error] [pid 1014214:tid 1014358] [client 152.58.191.29:61494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YrguRBFTcQNywdCIiqwAAAZ0"]
[Mon Jul 20 06:46:38.995720 2026] [security2:error] [pid 1014214:tid 1014370] [client 8.228.127.164:53662] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YrguRBFTcQNywdCIisQAAAak"]
[Mon Jul 20 06:46:39.252867 2026] [security2:error] [pid 1014214:tid 1014302] [remote 115.74.105.156:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YrwuRBFTcQNywdCIiwgABnFc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:46:39.258532 2026] [security2:error] [pid 1014214:tid 1014387] [client 8.228.127.164:50456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YrwuRBFTcQNywdCIixAAAAbo"]
[Mon Jul 20 06:46:39.273220 2026] [security2:error] [pid 1014214:tid 1014237] [remote 72.167.132.114:42496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YrwuRBFTcQNywdCIiwwAB7hY"]
[Mon Jul 20 06:46:39.442423 2026] [security2:error] [pid 1014214:tid 1014282] [remote 144.79.133.30:49022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgeamazon.com"] [uri "/wp-login.php"] [unique_id "al4YrwuRBFTcQNywdCIi1gAB3UM"]
[Mon Jul 20 06:46:39.487914 2026] [security2:error] [pid 1014214:tid 1014245] [remote 5.252.52.249:49628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YrwuRBFTcQNywdCIi7gAB5B4"]
[Mon Jul 20 06:46:39.573936 2026] [security2:error] [pid 1014214:tid 1014394] [client 8.228.127.164:54126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YrwuRBFTcQNywdCIi8QAAAcE"]
[Mon Jul 20 06:46:39.575724 2026] [security2:error] [pid 1014214:tid 1014397] [client 57.141.18.102:41766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrAuRBFTcQNywdCIh1gABxEY"]
[Mon Jul 20 06:46:39.599937 2026] [security2:error] [pid 1014214:tid 1014339] [remote 72.167.132.114:42496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YrwuRBFTcQNywdCIi8gACAnw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:46:39.617995 2026] [security2:error] [pid 1014214:tid 1014435] [client 77.110.127.138:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YrwuRBFTcQNywdCIi9QAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:39.618086 2026] [security2:error] [pid 1014214:tid 1014435] [client 77.110.127.138:55336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YrwuRBFTcQNywdCIi9QAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:39.815384 2026] [security2:error] [pid 1014214:tid 1014254] [remote 5.252.52.249:49628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YrwuRBFTcQNywdCIjCgABnic"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:46:39.854745 2026] [security2:error] [pid 1014214:tid 1014460] [client 8.228.127.164:53543] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YrwuRBFTcQNywdCIjDAAAAgM"]
[Mon Jul 20 06:46:39.873041 2026] [access_compat:error] [pid 1014214:tid 1014279] [remote 197.91.160.89:33194] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:39.887109 2026] [security2:error] [pid 1014214:tid 1014356] [client 216.73.217.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cimahmo.pro"] [uri "/index.php"] [unique_id "al4YrwuRBFTcQNywdCIjCQABmzM"]
[Mon Jul 20 06:46:39.889001 2026] [security2:error] [pid 1014214:tid 1014223] [remote 124.55.178.99:55110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YrwuRBFTcQNywdCIjEgAB-Qg"]
[Mon Jul 20 06:46:39.889207 2026] [security2:error] [pid 1014214:tid 1014450] [client 124.55.178.99:55110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YrwuRBFTcQNywdCIjEgAB-Qg"]
[Mon Jul 20 06:46:39.918362 2026] [security2:error] [pid 1014214:tid 1014350] [client 14.225.17.146:56359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4YrguRBFTcQNywdCIifgAAAZU"], referer: http://tntcatholic.com/New
[Mon Jul 20 06:46:39.967040 2026] [proxy:error] [pid 1014214:tid 1014446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:39.967121 2026] [proxy_http:error] [pid 1014214:tid 1014446] [client 34.73.38.214:64103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:39.967562 2026] [proxy:error] [pid 1014214:tid 1014446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:39.967595 2026] [proxy_http:error] [pid 1014214:tid 1014446] [client 34.73.38.214:64103] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:39.988164 2026] [security2:error] [pid 1014214:tid 1014411] [client 14.224.227.113:54699] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YrwuRBFTcQNywdCIjHgAAAdI"]
[Mon Jul 20 06:46:40.115215 2026] [security2:error] [pid 1014214:tid 1014402] [client 8.228.127.164:51711] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YsAuRBFTcQNywdCIjJwAAAck"]
[Mon Jul 20 06:46:40.115312 2026] [security2:error] [pid 1014214:tid 1014346] [client 2a11:fb80:3b3:5201:d89f:bc34:1b3c:5c0e:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrAuRBFTcQNywdCIh-gAAAZE"]
[Mon Jul 20 06:46:40.139503 2026] [security2:error] [pid 1014214:tid 1014449] [client 34.73.38.214:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YsAuRBFTcQNywdCIjKQAAAfg"]
[Mon Jul 20 06:46:40.272129 2026] [security2:error] [pid 1014214:tid 1014382] [client 57.141.18.57:54502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIh_AABtSs"]
[Mon Jul 20 06:46:40.339582 2026] [security2:error] [pid 1014214:tid 1014364] [client 74.208.214.194:42120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4YsAuRBFTcQNywdCIjMgAAAaM"]
[Mon Jul 20 06:46:40.424307 2026] [security2:error] [pid 1014214:tid 1014455] [client 8.228.127.164:59651] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YsAuRBFTcQNywdCIjRAAAAf4"]
[Mon Jul 20 06:46:40.507240 2026] [security2:error] [pid 1014214:tid 1014437] [client 117.247.108.24:25208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YsAuRBFTcQNywdCIjUQAAAew"]
[Mon Jul 20 06:46:40.507344 2026] [security2:error] [pid 1014214:tid 1014437] [client 117.247.108.24:25208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YsAuRBFTcQNywdCIjUQAAAew"]
[Mon Jul 20 06:46:40.546704 2026] [access_compat:error] [pid 1014214:tid 1014323] [remote 185.108.132.13:57046] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:40.629292 2026] [security2:error] [pid 1014214:tid 1014444] [client 57.141.18.49:62834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIiLQAB81M"]
[Mon Jul 20 06:46:40.684017 2026] [security2:error] [pid 1014214:tid 1014409] [client 8.228.127.164:63733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YsAuRBFTcQNywdCIjZQAAAdA"]
[Mon Jul 20 06:46:40.761077 2026] [security2:error] [pid 1014214:tid 1014452] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YsAuRBFTcQNywdCIjUgAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:40.855566 2026] [security2:error] [pid 1014214:tid 1014460] [client 171.61.165.146:1845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YsAuRBFTcQNywdCIjcwAAAgM"]
[Mon Jul 20 06:46:40.855689 2026] [security2:error] [pid 1014214:tid 1014460] [client 171.61.165.146:1845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YsAuRBFTcQNywdCIjcwAAAgM"]
[Mon Jul 20 06:46:40.908239 2026] [security2:error] [pid 1014214:tid 1014449] [client 34.73.38.214:49407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YsAuRBFTcQNywdCIjdwAAAfg"]
[Mon Jul 20 06:46:40.925927 2026] [security2:error] [pid 1014214:tid 1014467] [client 43.143.132.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4YrQuRBFTcQNywdCIh_wACCjg"]
[Mon Jul 20 06:46:40.975587 2026] [security2:error] [pid 1014214:tid 1014385] [client 8.228.127.164:62719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "elv.xwy.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YsAuRBFTcQNywdCIjfAAAAbg"]
[Mon Jul 20 06:46:41.135288 2026] [security2:error] [pid 1014214:tid 1014273] [remote 8.217.108.67:19924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4YsQuRBFTcQNywdCIjjgAB1Do"]
[Mon Jul 20 06:46:41.135510 2026] [security2:error] [pid 1014214:tid 1014413] [client 8.217.108.67:19924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4YsQuRBFTcQNywdCIjjgAB1Do"]
[Mon Jul 20 06:46:41.382424 2026] [security2:error] [pid 1014214:tid 1014418] [client 37.52.210.45:49349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YsQuRBFTcQNywdCIjoAAAAdk"]
[Mon Jul 20 06:46:41.382552 2026] [security2:error] [pid 1014214:tid 1014418] [client 37.52.210.45:49349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YsQuRBFTcQNywdCIjoAAAAdk"]
[Mon Jul 20 06:46:41.411943 2026] [security2:error] [pid 1014214:tid 1014363] [client 57.141.18.71:49870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrguRBFTcQNywdCIiagABonk"]
[Mon Jul 20 06:46:41.436966 2026] [security2:error] [pid 1014214:tid 1014361] [client 139.28.219.68:47748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eduardsales.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4YsQuRBFTcQNywdCIjpgAAAaA"]
[Mon Jul 20 06:46:41.655099 2026] [security2:error] [pid 1014214:tid 1014414] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YsQuRBFTcQNywdCIjsQAAAdU"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:46:41.658265 2026] [security2:error] [pid 1014214:tid 1014389] [client 223.185.13.213:12116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YsQuRBFTcQNywdCIjuAAAAbw"]
[Mon Jul 20 06:46:41.658345 2026] [security2:error] [pid 1014214:tid 1014389] [client 223.185.13.213:12116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YsQuRBFTcQNywdCIjuAAAAbw"]
[Mon Jul 20 06:46:41.685999 2026] [security2:error] [pid 1014214:tid 1014419] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YsQuRBFTcQNywdCIjoQAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:41.783176 2026] [security2:error] [pid 1014214:tid 1014416] [client 34.73.38.214:60884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YsQuRBFTcQNywdCIjvQAAAdc"]
[Mon Jul 20 06:46:42.264844 2026] [security2:error] [pid 1014214:tid 1014409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YsguRBFTcQNywdCIj2wAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:42.420652 2026] [security2:error] [pid 1014214:tid 1014368] [client 34.73.38.214:51820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YsguRBFTcQNywdCIj7QAAAac"]
[Mon Jul 20 06:46:42.489108 2026] [security2:error] [pid 1014214:tid 1014322] [remote 176.56.118.182:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YsguRBFTcQNywdCIj8AABsGs"]
[Mon Jul 20 06:46:42.489233 2026] [security2:error] [pid 1014214:tid 1014377] [client 176.56.118.182:56864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YsguRBFTcQNywdCIj8AABsGs"]
[Mon Jul 20 06:46:42.602786 2026] [security2:error] [pid 1014214:tid 1014410] [client 122.183.32.225:1141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YsguRBFTcQNywdCIj-QAAAdE"]
[Mon Jul 20 06:46:42.602935 2026] [security2:error] [pid 1014214:tid 1014410] [client 122.183.32.225:1141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YsguRBFTcQNywdCIj-QAAAdE"]
[Mon Jul 20 06:46:42.625622 2026] [security2:error] [pid 1014214:tid 1014305] [remote 144.79.133.30:49022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgeamazon.com"] [uri "/wp-login.php"] [unique_id "al4YsguRBFTcQNywdCIj-wABm1o"], referer: https://bridgeamazon.com/wp-login.php
[Mon Jul 20 06:46:42.683124 2026] [security2:error] [pid 1014214:tid 1014431] [client 57.141.18.6:56556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrwuRBFTcQNywdCIiywAB5kI"]
[Mon Jul 20 06:46:42.691764 2026] [security2:error] [pid 1014214:tid 1014442] [client 57.141.18.26:41982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YrwuRBFTcQNywdCIiyQAB8R0"]
[Mon Jul 20 06:46:42.848124 2026] [security2:error] [pid 1014214:tid 1014453] [client 52.109.68.130:15986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YsguRBFTcQNywdCIkDQAAAfw"]
[Mon Jul 20 06:46:42.968603 2026] [security2:error] [pid 1014214:tid 1014368] [client 34.73.38.214:49837] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YsguRBFTcQNywdCIkFAAAAac"]
[Mon Jul 20 06:46:43.005940 2026] [security2:error] [pid 1014214:tid 1014392] [client 52.109.68.130:15986] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YswuRBFTcQNywdCIkGAAAAb8"]
[Mon Jul 20 06:46:43.020928 2026] [security2:error] [pid 1014214:tid 1014427] [client 77.110.127.138:55377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampBOy86WKR')) OR 600. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 600 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4YswuRBFTcQNywdCIkGQAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:43.399800 2026] [security2:error] [pid 1014214:tid 1014383] [client 52.109.4.7:37632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4YswuRBFTcQNywdCIkQwAAAbY"]
[Mon Jul 20 06:46:43.461438 2026] [security2:error] [pid 1014214:tid 1014346] [client 52.109.4.7:37632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4YswuRBFTcQNywdCIkRQAAAZE"]
[Mon Jul 20 06:46:43.524419 2026] [security2:error] [pid 1014214:tid 1014470] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YswuRBFTcQNywdCIkQQAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:43.599768 2026] [security2:error] [pid 1014214:tid 1014376] [client 34.73.38.214:49979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YswuRBFTcQNywdCIkSwAAAa8"]
[Mon Jul 20 06:46:43.742966 2026] [security2:error] [pid 1014214:tid 1014427] [client 45.157.112.60:21761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4YswuRBFTcQNywdCIkXAAAAeI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:46:43.752849 2026] [security2:error] [pid 1014214:tid 1014442] [client 114.119.141.116:31197] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/robots.txt"] [unique_id "al4YswuRBFTcQNywdCIkXQAAAfE"], referer: https://areitoproducciones.com/robots.txt
[Mon Jul 20 06:46:43.820056 2026] [security2:error] [pid 1014214:tid 1014361] [client 54.169.146.187:55840] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "curlsnpearlsss.com"] [uri "/robots.txt"] [unique_id "al4YswuRBFTcQNywdCIkZQAAAaA"]
[Mon Jul 20 06:46:43.862499 2026] [security2:error] [pid 1014214:tid 1014422] [client 57.141.18.87:53192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YsAuRBFTcQNywdCIjNQAB3R8"]
[Mon Jul 20 06:46:44.061099 2026] [security2:error] [pid 1014214:tid 1014404] [client 139.28.219.68:47760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eduardsales.com"] [uri "/xmlrpc.php"] [unique_id "al4YtAuRBFTcQNywdCIkdQAAAcs"]
[Mon Jul 20 06:46:44.061234 2026] [security2:error] [pid 1014214:tid 1014404] [client 139.28.219.68:47760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "eduardsales.com"] [uri "/xmlrpc.php"] [unique_id "al4YtAuRBFTcQNywdCIkdQAAAcs"]
[Mon Jul 20 06:46:44.114511 2026] [security2:error] [pid 1014214:tid 1014415] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YswuRBFTcQNywdCIkYwAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:44.152704 2026] [security2:error] [pid 1014214:tid 1014469] [client 34.73.38.214:57730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YtAuRBFTcQNywdCIkewAAAgw"]
[Mon Jul 20 06:46:44.337914 2026] [security2:error] [pid 1014214:tid 1014435] [client 192.140.149.97:46018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YtAuRBFTcQNywdCIkjQAAAeo"]
[Mon Jul 20 06:46:44.338015 2026] [security2:error] [pid 1014214:tid 1014435] [client 192.140.149.97:46018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4YtAuRBFTcQNywdCIkjQAAAeo"]
[Mon Jul 20 06:46:44.565719 2026] [security2:error] [pid 1014214:tid 1014403] [client 57.141.18.20:63084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YsQuRBFTcQNywdCIjgAAByik"]
[Mon Jul 20 06:46:44.572354 2026] [security2:error] [pid 1014214:tid 1014384] [client 112.208.70.94:45155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YtAuRBFTcQNywdCIkoQAAAbc"]
[Mon Jul 20 06:46:44.572448 2026] [security2:error] [pid 1014214:tid 1014384] [client 112.208.70.94:45155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YtAuRBFTcQNywdCIkoQAAAbc"]
[Mon Jul 20 06:46:44.691082 2026] [security2:error] [pid 1014214:tid 1014452] [client 77.110.127.138:55399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YtAuRBFTcQNywdCIkrwAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:44.691165 2026] [security2:error] [pid 1014214:tid 1014452] [client 77.110.127.138:55399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YtAuRBFTcQNywdCIkrwAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:45.242874 2026] [security2:error] [pid 1014214:tid 1014435] [client 74.143.215.146:51088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YtQuRBFTcQNywdCIkzAAB6hM"]
[Mon Jul 20 06:46:45.336565 2026] [security2:error] [pid 1014214:tid 1014365] [client 34.73.38.214:50459] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4YtQuRBFTcQNywdCIk4gAAAaQ"]
[Mon Jul 20 06:46:45.337127 2026] [security2:error] [pid 1014214:tid 1014460] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YtQuRBFTcQNywdCIkygAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:45.341338 2026] [security2:error] [pid 1014214:tid 1014402] [client 57.141.18.34:65202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YsQuRBFTcQNywdCIjwgAByS8"]
[Mon Jul 20 06:46:45.416208 2026] [security2:error] [pid 1014214:tid 1014448] [client 50.116.65.227:47920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4YtQuRBFTcQNywdCIk5gAAAfc"]
[Mon Jul 20 06:46:45.424575 2026] [security2:error] [pid 1014214:tid 1014433] [client 50.116.65.227:47924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4YtQuRBFTcQNywdCIk5wAAAeg"]
[Mon Jul 20 06:46:45.434390 2026] [security2:error] [pid 1014214:tid 1014439] [client 39.48.81.23:61410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YtQuRBFTcQNywdCIk6AAAAe4"]
[Mon Jul 20 06:46:45.434887 2026] [security2:error] [pid 1014214:tid 1014439] [client 39.48.81.23:61410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YtQuRBFTcQNywdCIk6AAAAe4"]
[Mon Jul 20 06:46:45.578218 2026] [security2:error] [pid 1014214:tid 1014432] [client 157.85.211.87:10511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YtQuRBFTcQNywdCIk8AAAAec"]
[Mon Jul 20 06:46:45.578391 2026] [security2:error] [pid 1014214:tid 1014432] [client 157.85.211.87:10511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YtQuRBFTcQNywdCIk8AAAAec"]
[Mon Jul 20 06:46:45.868103 2026] [http2:info] [pid 1020501:tid 1020501] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:46:45.950788 2026] [security2:error] [pid 1014214:tid 1014454] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YtQuRBFTcQNywdCIlBgAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:46.127257 2026] [security2:error] [pid 1014214:tid 1014442] [client 103.238.106.162:42868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YtguRBFTcQNywdCIlHgAAAfE"]
[Mon Jul 20 06:46:46.128023 2026] [security2:error] [pid 1014214:tid 1014442] [client 103.238.106.162:42868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YtguRBFTcQNywdCIlHgAAAfE"]
[Mon Jul 20 06:46:46.196510 2026] [security2:error] [pid 1014214:tid 1014365] [client 34.73.38.214:59628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YtguRBFTcQNywdCIlIwAAAaQ"]
[Mon Jul 20 06:46:46.450285 2026] [security2:error] [pid 1014214:tid 1014397] [client 57.141.18.69:47022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YswuRBFTcQNywdCIkKwABxCM"]
[Mon Jul 20 06:46:46.632492 2026] [security2:error] [pid 1014214:tid 1014366] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YtguRBFTcQNywdCIlLwAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:46.665119 2026] [security2:error] [pid 1014214:tid 1014420] [client 197.186.66.42:50491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YtguRBFTcQNywdCIlPQAAAds"]
[Mon Jul 20 06:46:46.665230 2026] [security2:error] [pid 1014214:tid 1014420] [client 197.186.66.42:50491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YtguRBFTcQNywdCIlPQAAAds"]
[Mon Jul 20 06:46:46.858581 2026] [security2:error] [pid 1014214:tid 1014386] [client 217.142.18.172:13732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YtguRBFTcQNywdCIlTAAAAbk"]
[Mon Jul 20 06:46:46.862294 2026] [security2:error] [pid 1014214:tid 1014386] [client 217.142.18.172:13732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YtguRBFTcQNywdCIlTAAAAbk"]
[Mon Jul 20 06:46:46.881342 2026] [security2:error] [pid 1014214:tid 1014453] [client 34.73.38.214:52765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YtguRBFTcQNywdCIlTgAAAfw"]
[Mon Jul 20 06:46:47.564127 2026] [security2:error] [pid 1014214:tid 1014378] [client 104.234.53.55:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YtwuRBFTcQNywdCIlbAAAAbE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:47.603103 2026] [security2:error] [pid 1014214:tid 1014468] [client 187.108.85.186:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YtwuRBFTcQNywdCIlcQAAAgs"]
[Mon Jul 20 06:46:47.603202 2026] [security2:error] [pid 1014214:tid 1014468] [client 187.108.85.186:59379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YtwuRBFTcQNywdCIlcQAAAgs"]
[Mon Jul 20 06:46:48.096808 2026] [security2:error] [pid 1020501:tid 1020719] [client 34.73.38.214:62629] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.jwo.ral.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YuMS_oRsP4jdONhfccgAAAFY"]
[Mon Jul 20 06:46:48.192158 2026] [security2:error] [pid 1014214:tid 1014419] [client 77.110.127.138:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YuAuRBFTcQNywdCIllgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:48.192256 2026] [security2:error] [pid 1014214:tid 1014419] [client 77.110.127.138:55382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YuAuRBFTcQNywdCIllgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:48.193197 2026] [security2:error] [pid 1014214:tid 1014291] [remote 162.19.86.63:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YuAuRBFTcQNywdCIllwABvkw"]
[Mon Jul 20 06:46:48.215106 2026] [security2:error] [pid 1014214:tid 1014347] [client 103.125.179.95:57822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YuAuRBFTcQNywdCIlmQAAAZI"]
[Mon Jul 20 06:46:48.215531 2026] [security2:error] [pid 1014214:tid 1014347] [client 103.125.179.95:57822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YuAuRBFTcQNywdCIlmQAAAZI"]
[Mon Jul 20 06:46:48.405685 2026] [security2:error] [pid 1014214:tid 1014327] [remote 162.19.86.63:44224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4YuAuRBFTcQNywdCIlqAAB93A"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:46:48.520880 2026] [security2:error] [pid 1020501:tid 1020514] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YuMS_oRsP4jdONhfcfAAAZAo"]
[Mon Jul 20 06:46:48.521074 2026] [security2:error] [pid 1020501:tid 1020733] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YuMS_oRsP4jdONhfcfAAAZAo"]
[Mon Jul 20 06:46:48.880664 2026] [security2:error] [pid 1014214:tid 1014444] [client 57.141.18.106:40940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YtQuRBFTcQNywdCIk4wAB838"]
[Mon Jul 20 06:46:49.068758 2026] [security2:error] [pid 1014214:tid 1014384] [client 183.82.98.154:49277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YuQuRBFTcQNywdCIl0AAAAbc"]
[Mon Jul 20 06:46:49.068874 2026] [security2:error] [pid 1014214:tid 1014384] [client 183.82.98.154:49277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YuQuRBFTcQNywdCIl0AAAAbc"]
[Mon Jul 20 06:46:49.153730 2026] [security2:error] [pid 1014214:tid 1014370] [client 57.141.18.42:56768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YtQuRBFTcQNywdCIk_wABqQY"]
[Mon Jul 20 06:46:49.165337 2026] [proxy:error] [pid 1014214:tid 1014361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:49.165414 2026] [proxy_http:error] [pid 1014214:tid 1014361] [client 198.235.24.8:57898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:49.166169 2026] [proxy:error] [pid 1014214:tid 1014361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:46:49.166202 2026] [proxy_http:error] [pid 1014214:tid 1014361] [client 198.235.24.8:57898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:46:49.265576 2026] [security2:error] [pid 1014214:tid 1014416] [client 77.110.127.138:55519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YuQuRBFTcQNywdCIl2QAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:49.265676 2026] [security2:error] [pid 1014214:tid 1014416] [client 77.110.127.138:55519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YuQuRBFTcQNywdCIl2QAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:49.641965 2026] [security2:error] [pid 1014214:tid 1014385] [client 152.58.191.29:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YuQuRBFTcQNywdCIl6gAAAbg"]
[Mon Jul 20 06:46:49.642085 2026] [security2:error] [pid 1014214:tid 1014385] [client 152.58.191.29:62077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YuQuRBFTcQNywdCIl6gAAAbg"]
[Mon Jul 20 06:46:49.893642 2026] [security2:error] [pid 1020501:tid 1020677] [client 176.118.193.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4YucS_oRsP4jdONhfclwAAACw"]
[Mon Jul 20 06:46:50.022083 2026] [security2:error] [pid 1020501:tid 1020679] [client 114.119.142.140:61545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zonemist.com"] [uri "/testimonial/would-recommend-to-anyone"] [unique_id "al4YusS_oRsP4jdONhfcpQAAAC4"], referer: https://www.zonemist.com/testimonial/would-recommend-to-anyone/
[Mon Jul 20 06:46:50.258972 2026] [security2:error] [pid 1020501:tid 1020759] [client 104.234.53.80:31411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YusS_oRsP4jdONhfcrQAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:50.481687 2026] [security2:error] [pid 1014214:tid 1014450] [client 57.141.18.23:33116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YtguRBFTcQNywdCIlOgAB-Qw"]
[Mon Jul 20 06:46:50.773034 2026] [security2:error] [pid 1014214:tid 1014438] [client 82.39.236.250:65511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YuguRBFTcQNywdCImGwAB7Uk"]
[Mon Jul 20 06:46:50.897179 2026] [security2:error] [pid 1014214:tid 1014338] [remote 57.141.18.25:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3203006"] [unique_id "al4YuguRBFTcQNywdCImIgABr3s"]
[Mon Jul 20 06:46:50.971745 2026] [security2:error] [pid 1020501:tid 1020675] [client 57.141.18.111:30190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Yt8S_oRsP4jdONhfcXQAAKgQ"]
[Mon Jul 20 06:46:51.342856 2026] [security2:error] [pid 1020501:tid 1020746] [client 117.247.108.24:25207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Yu8S_oRsP4jdONhfcxAAAAHE"]
[Mon Jul 20 06:46:51.343001 2026] [security2:error] [pid 1020501:tid 1020746] [client 117.247.108.24:25207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Yu8S_oRsP4jdONhfcxAAAAHE"]
[Mon Jul 20 06:46:51.578482 2026] [security2:error] [pid 1014214:tid 1014429] [client 77.110.127.138:55537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YuwuRBFTcQNywdCImPwAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:51.578582 2026] [security2:error] [pid 1014214:tid 1014429] [client 77.110.127.138:55537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YuwuRBFTcQNywdCImPwAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:51.610804 2026] [security2:error] [pid 1020501:tid 1020706] [client 57.141.18.26:36014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Yt8S_oRsP4jdONhfcbgAASQY"]
[Mon Jul 20 06:46:51.732325 2026] [access_compat:error] [pid 1020501:tid 1020537] [remote 45.3.43.77:64745] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:51.827969 2026] [security2:error] [pid 1014214:tid 1014346] [client 57.141.18.53:31192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YuAuRBFTcQNywdCIljgABkXc"]
[Mon Jul 20 06:46:51.838959 2026] [security2:error] [pid 1020501:tid 1020662] [client 171.61.165.146:7697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Yu8S_oRsP4jdONhfc1gAAAB0"]
[Mon Jul 20 06:46:51.839093 2026] [security2:error] [pid 1020501:tid 1020662] [client 171.61.165.146:7697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Yu8S_oRsP4jdONhfc1gAAAB0"]
[Mon Jul 20 06:46:51.985157 2026] [security2:error] [pid 1020501:tid 1020677] [client 37.52.210.45:51485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Yu8S_oRsP4jdONhfc3AAAACw"]
[Mon Jul 20 06:46:51.985262 2026] [security2:error] [pid 1020501:tid 1020677] [client 37.52.210.45:51485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Yu8S_oRsP4jdONhfc3AAAACw"]
[Mon Jul 20 06:46:52.195470 2026] [security2:error] [pid 1014214:tid 1014350] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YvAuRBFTcQNywdCImUgAAAZU"]
[Mon Jul 20 06:46:52.373303 2026] [security2:error] [pid 1014214:tid 1014389] [client 104.234.53.92:30603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YvAuRBFTcQNywdCImXQAAAbw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:52.469140 2026] [security2:error] [pid 1020501:tid 1020638] [client 77.110.127.138:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvMS_oRsP4jdONhfc7gAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:52.469277 2026] [security2:error] [pid 1020501:tid 1020638] [client 77.110.127.138:55550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvMS_oRsP4jdONhfc7gAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:52.551262 2026] [security2:error] [pid 1014214:tid 1014357] [client 57.141.18.72:49210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YuAuRBFTcQNywdCIlwQABnDg"]
[Mon Jul 20 06:46:52.786615 2026] [security2:error] [pid 1020501:tid 1020743] [client 223.185.13.213:25616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YvMS_oRsP4jdONhfdAgAAAG4"]
[Mon Jul 20 06:46:52.786740 2026] [security2:error] [pid 1020501:tid 1020743] [client 223.185.13.213:25616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YvMS_oRsP4jdONhfdAgAAAG4"]
[Mon Jul 20 06:46:53.194558 2026] [security2:error] [pid 1014214:tid 1014403] [client 57.141.18.66:32520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YuQuRBFTcQNywdCIl7AABynk"]
[Mon Jul 20 06:46:53.579219 2026] [security2:error] [pid 1014214:tid 1014402] [client 103.153.183.69:42756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/%2e%2e/.env"] [unique_id "al4YvQuRBFTcQNywdCImmAAAAck"], referer: https://duckduckgo.com/?q=tbvu0
[Mon Jul 20 06:46:53.704939 2026] [security2:error] [pid 1020501:tid 1020734] [client 77.110.127.138:55564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/crochet/page/2/"] [unique_id "al4YvcS_oRsP4jdONhfdFQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:53.739903 2026] [security2:error] [pid 1020501:tid 1020702] [client 20.230.108.230:41820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4YvcS_oRsP4jdONhfdEAAAAEU"]
[Mon Jul 20 06:46:53.793820 2026] [security2:error] [pid 1014214:tid 1014363] [client 77.110.127.138:55518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvQuRBFTcQNywdCImqQAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:53.793925 2026] [security2:error] [pid 1014214:tid 1014363] [client 77.110.127.138:55518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvQuRBFTcQNywdCImqQAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:53.883737 2026] [security2:error] [pid 1014214:tid 1014342] [remote 188.40.28.4:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YvQuRBFTcQNywdCImrwAB5n8"]
[Mon Jul 20 06:46:53.944602 2026] [security2:error] [pid 1014214:tid 1014407] [client 77.110.127.138:55570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvQuRBFTcQNywdCImsQAAAc4"]
[Mon Jul 20 06:46:53.944694 2026] [security2:error] [pid 1014214:tid 1014407] [client 77.110.127.138:55570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvQuRBFTcQNywdCImsQAAAc4"]
[Mon Jul 20 06:46:54.011321 2026] [security2:error] [pid 1014214:tid 1014439] [client 103.153.183.69:42756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xc0\\xaf../etc/passwd"] [unique_id "al4YvguRBFTcQNywdCImtAAAAe4"], referer: https://www.reddit.com/
[Mon Jul 20 06:46:54.081174 2026] [security2:error] [pid 1014214:tid 1014299] [remote 188.40.28.4:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4YvguRBFTcQNywdCImuAAB8VQ"], referer: https://ouw.egd.mybluehost.me/wp-login.php
[Mon Jul 20 06:46:54.222984 2026] [security2:error] [pid 1020501:tid 1020709] [client 104.234.53.91:27057] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YvsS_oRsP4jdONhfdGQAAAEw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:54.306650 2026] [security2:error] [pid 1014214:tid 1014360] [client 103.153.183.69:42756] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/..\\xef\\xbc\\x8f../etc/passwd"] [unique_id "al4YvguRBFTcQNywdCImzAAAAZ8"], referer: https://twitter.com/
[Mon Jul 20 06:46:54.355595 2026] [security2:error] [pid 1014214:tid 1014451] [client 171.61.17.42:21655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "bbwipartnerconference.com"] [uri "/xmlrpc.php"] [unique_id "al4YvguRBFTcQNywdCImuwAAAfo"]
[Mon Jul 20 06:46:54.405331 2026] [security2:error] [pid 1020501:tid 1020663] [client 57.141.18.4:50362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YusS_oRsP4jdONhfcuQAAHh0"]
[Mon Jul 20 06:46:54.507956 2026] [security2:error] [pid 1014214:tid 1014470] [client 57.141.18.125:47906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YuguRBFTcQNywdCImIQACDTw"]
[Mon Jul 20 06:46:54.524683 2026] [security2:error] [pid 1020501:tid 1020658] [client 77.110.127.138:55575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvsS_oRsP4jdONhfdJQAAABk"]
[Mon Jul 20 06:46:54.524786 2026] [security2:error] [pid 1020501:tid 1020658] [client 77.110.127.138:55575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YvsS_oRsP4jdONhfdJQAAABk"]
[Mon Jul 20 06:46:54.705828 2026] [security2:error] [pid 1014214:tid 1014324] [remote 154.66.198.148:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YvguRBFTcQNywdCIm3AABxG0"]
[Mon Jul 20 06:46:54.832502 2026] [security2:error] [pid 1020501:tid 1020660] [client 104.234.53.91:27057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YvsS_oRsP4jdONhfdLwAAABs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:46:54.902704 2026] [security2:error] [pid 1014214:tid 1014389] [client 106.219.188.178:29740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YvguRBFTcQNywdCIm7AAAAbw"]
[Mon Jul 20 06:46:54.902842 2026] [security2:error] [pid 1014214:tid 1014389] [client 106.219.188.178:29740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YvguRBFTcQNywdCIm7AAAAbw"]
[Mon Jul 20 06:46:54.976558 2026] [security2:error] [pid 1014214:tid 1014234] [remote 72.167.132.114:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YvguRBFTcQNywdCIm7gAB8hM"]
[Mon Jul 20 06:46:54.976741 2026] [security2:error] [pid 1014214:tid 1014443] [client 72.167.132.114:41854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YvguRBFTcQNywdCIm7gAB8hM"]
[Mon Jul 20 06:46:55.038939 2026] [security2:error] [pid 1020501:tid 1020674] [client 57.141.18.19:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Yu8S_oRsP4jdONhfcxgAAKR8"]
[Mon Jul 20 06:46:55.075196 2026] [security2:error] [pid 1020501:tid 1020635] [client 39.48.81.23:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Yv8S_oRsP4jdONhfdNwAAAAI"]
[Mon Jul 20 06:46:55.075321 2026] [security2:error] [pid 1020501:tid 1020635] [client 39.48.81.23:61996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Yv8S_oRsP4jdONhfdNwAAAAI"]
[Mon Jul 20 06:46:55.163584 2026] [security2:error] [pid 1014214:tid 1014439] [client 112.208.70.94:45595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YvwuRBFTcQNywdCIm9QAAAe4"]
[Mon Jul 20 06:46:55.163707 2026] [security2:error] [pid 1014214:tid 1014439] [client 112.208.70.94:45595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YvwuRBFTcQNywdCIm9QAAAe4"]
[Mon Jul 20 06:46:55.252923 2026] [security2:error] [pid 1014214:tid 1014284] [remote 154.66.198.148:5266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4YvwuRBFTcQNywdCIm-wABt0U"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:46:55.401245 2026] [security2:error] [pid 1020501:tid 1020672] [client 14.224.227.113:54701] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Yv8S_oRsP4jdONhfdRgAAACc"]
[Mon Jul 20 06:46:55.557930 2026] [security2:error] [pid 1020501:tid 1020654] [client 109.107.226.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Yv8S_oRsP4jdONhfdPAAAABU"]
[Mon Jul 20 06:46:55.624788 2026] [security2:error] [pid 1020501:tid 1020656] [client 50.116.65.227:22456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Yv8S_oRsP4jdONhfdSwAAABc"]
[Mon Jul 20 06:46:55.635228 2026] [security2:error] [pid 1020501:tid 1020633] [client 50.116.65.227:22464] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Yv8S_oRsP4jdONhfdTAAAAAA"]
[Mon Jul 20 06:46:55.804081 2026] [security2:error] [pid 1020501:tid 1020726] [client 122.183.32.225:18240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Yv8S_oRsP4jdONhfdUAAAAF0"]
[Mon Jul 20 06:46:55.804267 2026] [security2:error] [pid 1020501:tid 1020726] [client 122.183.32.225:18240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Yv8S_oRsP4jdONhfdUAAAAF0"]
[Mon Jul 20 06:46:55.854841 2026] [security2:error] [pid 1014214:tid 1014411] [client 45.3.49.2:16431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.49.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YvwuRBFTcQNywdCInGwAAAdI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:56.119176 2026] [security2:error] [pid 1014214:tid 1014436] [client 50.116.65.227:22490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4YvwuRBFTcQNywdCInIwAAAes"]
[Mon Jul 20 06:46:56.138611 2026] [security2:error] [pid 1014214:tid 1014356] [client 57.141.18.15:33024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YvAuRBFTcQNywdCImYgABmzM"]
[Mon Jul 20 06:46:56.302066 2026] [security2:error] [pid 1014214:tid 1014439] [client 50.116.65.227:22500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4YwAuRBFTcQNywdCInKAAAAe4"]
[Mon Jul 20 06:46:56.377315 2026] [security2:error] [pid 1014214:tid 1014423] [client 77.110.127.138:55361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/crochet/page/2/"] [unique_id "al4YwAuRBFTcQNywdCInPwAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:56.595906 2026] [security2:error] [pid 1020501:tid 1020665] [client 45.3.41.223:34047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YwMS_oRsP4jdONhfdZQAAACA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:56.608816 2026] [security2:error] [pid 1014214:tid 1014347] [client 103.238.106.162:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YwAuRBFTcQNywdCInSQAAAZI"]
[Mon Jul 20 06:46:56.608900 2026] [security2:error] [pid 1014214:tid 1014347] [client 103.238.106.162:60936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YwAuRBFTcQNywdCInSQAAAZI"]
[Mon Jul 20 06:46:56.610133 2026] [security2:error] [pid 1020501:tid 1020705] [client 43.205.139.3:15662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YwMS_oRsP4jdONhfdaAAAAEg"]
[Mon Jul 20 06:46:56.610212 2026] [security2:error] [pid 1020501:tid 1020705] [client 43.205.139.3:15662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4YwMS_oRsP4jdONhfdaAAAAEg"]
[Mon Jul 20 06:46:56.652102 2026] [security2:error] [pid 1014214:tid 1014410] [client 157.85.211.87:10553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YwAuRBFTcQNywdCInSwAAAdE"]
[Mon Jul 20 06:46:56.652274 2026] [security2:error] [pid 1014214:tid 1014410] [client 157.85.211.87:10553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YwAuRBFTcQNywdCInSwAAAdE"]
[Mon Jul 20 06:46:56.800092 2026] [security2:error] [pid 1020501:tid 1020700] [client 57.141.18.119:46728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YvcS_oRsP4jdONhfdDgAAQyw"]
[Mon Jul 20 06:46:57.338513 2026] [security2:error] [pid 1020501:tid 1020564] [remote 57.141.18.52:42656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4117735"] [unique_id "al4YwcS_oRsP4jdONhfdgwAAczw"]
[Mon Jul 20 06:46:57.584695 2026] [security2:error] [pid 1020501:tid 1020742] [client 217.142.18.172:39046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YwcS_oRsP4jdONhfdjgAAAG0"]
[Mon Jul 20 06:46:57.591935 2026] [security2:error] [pid 1020501:tid 1020742] [client 217.142.18.172:39046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YwcS_oRsP4jdONhfdjgAAAG0"]
[Mon Jul 20 06:46:57.965527 2026] [security2:error] [pid 1020501:tid 1020688] [client 212.47.238.7:52782] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail.cpanel-box5936.bluehost.com"] [uri "/___proxy_subdomain_webmail/wp-json/batch/v1"] [unique_id "al4YwcS_oRsP4jdONhfdnAAAADc"]
[Mon Jul 20 06:46:57.968046 2026] [security2:error] [pid 1014214:tid 1014377] [client 104.207.50.173:56147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YwQuRBFTcQNywdCIniAAAAbA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:46:58.261911 2026] [security2:error] [pid 1014214:tid 1014446] [client 187.108.85.186:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YwguRBFTcQNywdCInlwAAAfU"]
[Mon Jul 20 06:46:58.262065 2026] [security2:error] [pid 1014214:tid 1014446] [client 187.108.85.186:59933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YwguRBFTcQNywdCInlwAAAfU"]
[Mon Jul 20 06:46:58.592886 2026] [security2:error] [pid 1014214:tid 1014385] [client 77.110.127.138:55616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YwguRBFTcQNywdCIntQAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:58.592980 2026] [security2:error] [pid 1014214:tid 1014385] [client 77.110.127.138:55616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YwguRBFTcQNywdCIntQAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:46:58.920168 2026] [security2:error] [pid 1014214:tid 1014384] [client 103.125.179.95:58331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YwguRBFTcQNywdCInxAAAAbc"]
[Mon Jul 20 06:46:58.920306 2026] [security2:error] [pid 1014214:tid 1014384] [client 103.125.179.95:58331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YwguRBFTcQNywdCInxAAAAbc"]
[Mon Jul 20 06:46:58.985704 2026] [security2:error] [pid 1014214:tid 1014388] [client 57.141.18.119:46738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YvwuRBFTcQNywdCInDQABu1c"]
[Mon Jul 20 06:46:59.211522 2026] [security2:error] [pid 1014214:tid 1014359] [client 151.3.187.174:49886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YwwuRBFTcQNywdCIn1AABnhs"]
[Mon Jul 20 06:46:59.214915 2026] [security2:error] [pid 1014214:tid 1014303] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YwwuRBFTcQNywdCIn1gAB7Vg"]
[Mon Jul 20 06:46:59.215082 2026] [security2:error] [pid 1014214:tid 1014438] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YwwuRBFTcQNywdCIn1gAB7Vg"]
[Mon Jul 20 06:46:59.410941 2026] [security2:error] [pid 1014214:tid 1014316] [remote 217.61.143.92:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4YwwuRBFTcQNywdCIn5AAB2WU"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:46:59.564532 2026] [access_compat:error] [pid 1014214:tid 1014341] [remote 104.207.38.94:34221] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:46:59.599296 2026] [security2:error] [pid 1020501:tid 1020749] [client 34.138.198.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4Yw8S_oRsP4jdONhfdwQAAdEk"]
[Mon Jul 20 06:46:59.737290 2026] [security2:error] [pid 1020501:tid 1020578] [remote 217.61.143.92:59246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Yw8S_oRsP4jdONhfdyQAAf0o"]
[Mon Jul 20 06:46:59.752070 2026] [security2:error] [pid 1020501:tid 1020703] [client 183.82.98.154:49861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Yw8S_oRsP4jdONhfdygAAAEY"]
[Mon Jul 20 06:46:59.752194 2026] [security2:error] [pid 1020501:tid 1020703] [client 183.82.98.154:49861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Yw8S_oRsP4jdONhfdygAAAEY"]
[Mon Jul 20 06:46:59.782381 2026] [security2:error] [pid 1014214:tid 1014215] [remote 167.233.114.32:34390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4YwwuRBFTcQNywdCIn-wABtAA"]
[Mon Jul 20 06:46:59.784229 2026] [security2:error] [pid 1014214:tid 1014249] [remote 217.61.143.92:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4YwwuRBFTcQNywdCIn_AABpiI"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 06:46:59.914139 2026] [security2:error] [pid 1014214:tid 1014428] [client 216.38.230.121:65412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maplecleaningandhomecare.ca"] [uri "/index.php"] [unique_id "al4YwwuRBFTcQNywdCIn_QAAAeM"]
[Mon Jul 20 06:46:59.922792 2026] [security2:error] [pid 1020501:tid 1020699] [client 57.141.18.54:40308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YwMS_oRsP4jdONhfdWgAAQjQ"]
[Mon Jul 20 06:46:59.922953 2026] [security2:error] [pid 1020501:tid 1020739] [client 57.141.18.73:34282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YwMS_oRsP4jdONhfdYwAAajY"]
[Mon Jul 20 06:46:59.992260 2026] [security2:error] [pid 1020501:tid 1020725] [client 34.138.198.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Yw8S_oRsP4jdONhfd0gAAXE0"]
[Mon Jul 20 06:46:59.992638 2026] [security2:error] [pid 1020501:tid 1020582] [remote 217.61.143.92:59246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Yw8S_oRsP4jdONhfd1gAAWk4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:47:00.003549 2026] [security2:error] [pid 1014214:tid 1014335] [remote 167.233.114.32:34390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.114.233.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4YxAuRBFTcQNywdCIoCQABqng"], referer: https://swafforddetailing.com/wp-login.php
[Mon Jul 20 06:47:00.298255 2026] [security2:error] [pid 1020501:tid 1020759] [client 104.234.53.56:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4YxMS_oRsP4jdONhfd3wAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:00.825568 2026] [security2:error] [pid 1020501:tid 1020676] [client 197.186.66.42:51043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YxMS_oRsP4jdONhfd7gAAACs"]
[Mon Jul 20 06:47:00.827467 2026] [security2:error] [pid 1014214:tid 1014384] [client 5.161.247.61:55350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YxAuRBFTcQNywdCIoIAABtzM"]
[Mon Jul 20 06:47:00.867836 2026] [security2:error] [pid 1020501:tid 1020676] [client 197.186.66.42:51043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YxMS_oRsP4jdONhfd7gAAACs"]
[Mon Jul 20 06:47:01.022369 2026] [security2:error] [pid 1014214:tid 1014377] [client 57.141.18.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4YwwuRBFTcQNywdCIn6AAAAbA"]
[Mon Jul 20 06:47:01.101463 2026] [security2:error] [pid 1014214:tid 1014370] [client 103.82.10.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4YwwuRBFTcQNywdCIn-AAAAak"]
[Mon Jul 20 06:47:01.124879 2026] [security2:error] [pid 1014214:tid 1014459] [client 216.73.217.138:58656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4YxAuRBFTcQNywdCIoKQACAiM"]
[Mon Jul 20 06:47:01.760694 2026] [security2:error] [pid 1020501:tid 1020725] [client 104.234.53.73:44017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4YxcS_oRsP4jdONhfeHQAAAFw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:02.082865 2026] [security2:error] [pid 1020501:tid 1020712] [client 57.141.18.35:32292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YwsS_oRsP4jdONhfdqAAAT0E"]
[Mon Jul 20 06:47:02.143609 2026] [security2:error] [pid 1020501:tid 1020659] [client 117.247.108.24:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YxsS_oRsP4jdONhfeKQAAABo"]
[Mon Jul 20 06:47:02.143725 2026] [security2:error] [pid 1020501:tid 1020659] [client 117.247.108.24:64308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4YxsS_oRsP4jdONhfeKQAAABo"]
[Mon Jul 20 06:47:02.366225 2026] [security2:error] [pid 1020501:tid 1020732] [client 57.141.18.87:28666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YwsS_oRsP4jdONhfdsAAAY0U"]
[Mon Jul 20 06:47:02.395793 2026] [security2:error] [pid 1014214:tid 1014357] [client 77.110.127.138:55659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YxguRBFTcQNywdCIoZAAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:02.395917 2026] [security2:error] [pid 1014214:tid 1014357] [client 77.110.127.138:55659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YxguRBFTcQNywdCIoZAAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:02.512738 2026] [security2:error] [pid 1014214:tid 1014455] [client 34.139.11.221:49919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/xmlrpc.php"] [unique_id "al4YxguRBFTcQNywdCIoaAAAAf4"]
[Mon Jul 20 06:47:02.605713 2026] [security2:error] [pid 1014214:tid 1014368] [client 37.52.210.45:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YxguRBFTcQNywdCIobwAAAac"]
[Mon Jul 20 06:47:02.605834 2026] [security2:error] [pid 1014214:tid 1014368] [client 37.52.210.45:54226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4YxguRBFTcQNywdCIobwAAAac"]
[Mon Jul 20 06:47:02.761446 2026] [security2:error] [pid 1020501:tid 1020747] [client 34.139.11.221:60783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YxsS_oRsP4jdONhfePwAAAHI"]
[Mon Jul 20 06:47:02.854988 2026] [security2:error] [pid 1014214:tid 1014458] [client 57.141.18.21:35940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YwwuRBFTcQNywdCIn1wACAWY"]
[Mon Jul 20 06:47:02.922263 2026] [security2:error] [pid 1014214:tid 1014440] [client 34.139.11.221:49241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YxguRBFTcQNywdCIoeQAAAe8"]
[Mon Jul 20 06:47:02.925988 2026] [security2:error] [pid 1014214:tid 1014370] [client 171.61.165.146:19402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YxguRBFTcQNywdCIodgAAAak"]
[Mon Jul 20 06:47:02.926118 2026] [security2:error] [pid 1014214:tid 1014370] [client 171.61.165.146:19402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4YxguRBFTcQNywdCIodgAAAak"]
[Mon Jul 20 06:47:03.084916 2026] [security2:error] [pid 1020501:tid 1020656] [client 34.139.11.221:53370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Yx8S_oRsP4jdONhfeTAAAABc"]
[Mon Jul 20 06:47:03.144318 2026] [security2:error] [pid 1020501:tid 1020715] [client 223.185.13.213:13963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Yx8S_oRsP4jdONhfeUAAAAFI"]
[Mon Jul 20 06:47:03.144423 2026] [security2:error] [pid 1020501:tid 1020715] [client 223.185.13.213:13963] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Yx8S_oRsP4jdONhfeUAAAAFI"]
[Mon Jul 20 06:47:03.213937 2026] [security2:error] [pid 1020501:tid 1020706] [client 34.139.11.221:57208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Yx8S_oRsP4jdONhfeUwAAAEk"]
[Mon Jul 20 06:47:03.295555 2026] [security2:error] [pid 1014214:tid 1014409] [client 77.110.127.138:55679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YxwuRBFTcQNywdCIoiwAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:03.295651 2026] [security2:error] [pid 1014214:tid 1014409] [client 77.110.127.138:55679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YxwuRBFTcQNywdCIoiwAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:03.327174 2026] [security2:error] [pid 1020501:tid 1020661] [client 34.139.11.221:58758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Yx8S_oRsP4jdONhfeVwAAABw"]
[Mon Jul 20 06:47:03.507435 2026] [security2:error] [pid 1020501:tid 1020718] [client 34.139.11.221:63770] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Yx8S_oRsP4jdONhfeYAAAAFU"]
[Mon Jul 20 06:47:03.636554 2026] [security2:error] [pid 1020501:tid 1020703] [client 34.139.11.221:64368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Yx8S_oRsP4jdONhfeYwAAAEY"]
[Mon Jul 20 06:47:03.675003 2026] [security2:error] [pid 1020501:tid 1020608] [remote 202.51.202.242:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Yx8S_oRsP4jdONhfeZQAAO2g"]
[Mon Jul 20 06:47:03.795768 2026] [security2:error] [pid 1014214:tid 1014349] [client 34.139.11.221:50583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YxwuRBFTcQNywdCIooQAAAZQ"]
[Mon Jul 20 06:47:03.958334 2026] [security2:error] [pid 1020501:tid 1020710] [client 34.139.11.221:59485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Yx8S_oRsP4jdONhfeagAAAE0"]
[Mon Jul 20 06:47:03.985648 2026] [security2:error] [pid 1014214:tid 1014404] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YxwuRBFTcQNywdCIonwAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:04.087735 2026] [security2:error] [pid 1014214:tid 1014372] [client 34.139.11.221:63156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4YyAuRBFTcQNywdCIosQAAAas"]
[Mon Jul 20 06:47:04.128211 2026] [access_compat:error] [pid 1014214:tid 1014219] [remote 82.40.110.36:50154] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:47:04.129336 2026] [security2:error] [pid 1020501:tid 1020736] [client 57.141.18.9:39808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YxMS_oRsP4jdONhfd4AAAZ1A"]
[Mon Jul 20 06:47:04.204921 2026] [security2:error] [pid 1014214:tid 1014392] [client 34.139.11.221:58330] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.latiendadejorge.com.gt"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4YyAuRBFTcQNywdCIouAAAAb8"]
[Mon Jul 20 06:47:04.219551 2026] [security2:error] [pid 1020501:tid 1020744] [client 109.115.32.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YyMS_oRsP4jdONhfecwAAAG8"]
[Mon Jul 20 06:47:04.228345 2026] [security2:error] [pid 1014214:tid 1014405] [client 43.205.139.3:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4YyAuRBFTcQNywdCIougAAAcw"]
[Mon Jul 20 06:47:04.228420 2026] [security2:error] [pid 1014214:tid 1014405] [client 43.205.139.3:62786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4YyAuRBFTcQNywdCIougAAAcw"]
[Mon Jul 20 06:47:04.239246 2026] [security2:error] [pid 1020501:tid 1020726] [client 34.138.198.0:33656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyMS_oRsP4jdONhfedQAAAF0"]
[Mon Jul 20 06:47:04.239703 2026] [security2:error] [pid 1014214:tid 1014416] [client 34.138.198.0:33730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.samdothan.org"] [uri "/wp-config.php.bak"] [unique_id "al4YyAuRBFTcQNywdCIouwAAAdc"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.281146 2026] [security2:error] [pid 1014214:tid 1014370] [client 34.138.198.0:33694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIotgAAAak"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.325653 2026] [security2:error] [pid 1020501:tid 1020615] [remote 202.51.202.242:46312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YyMS_oRsP4jdONhfegQAAIm8"]
[Mon Jul 20 06:47:04.325818 2026] [security2:error] [pid 1020501:tid 1020667] [client 202.51.202.242:46312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4YyMS_oRsP4jdONhfegQAAIm8"]
[Mon Jul 20 06:47:04.341643 2026] [security2:error] [pid 1020501:tid 1020734] [client 34.138.198.0:33678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.samdothan.org"] [uri "/.env.bak"] [unique_id "al4YyMS_oRsP4jdONhfegwAAAGU"]
[Mon Jul 20 06:47:04.386619 2026] [security2:error] [pid 1014214:tid 1014353] [client 34.138.198.0:33698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.198.138.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.samdothan.org"] [uri "/wp-config.php"] [unique_id "al4YyAuRBFTcQNywdCIoxQAAAZg"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.388623 2026] [security2:error] [pid 1014214:tid 1014410] [client 34.138.198.0:33710] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.samdothan.org"] [uri "/.env.backup"] [unique_id "al4YyAuRBFTcQNywdCIoxgAAAdE"]
[Mon Jul 20 06:47:04.403171 2026] [security2:error] [pid 1020501:tid 1020638] [client 34.138.198.0:33612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyMS_oRsP4jdONhfeewAAAAU"]
[Mon Jul 20 06:47:04.409438 2026] [security2:error] [pid 1014214:tid 1014383] [client 34.138.198.0:33644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIovwAAAbY"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.488533 2026] [security2:error] [pid 1014214:tid 1014400] [client 34.138.198.0:33686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIoxwAAAcc"]
[Mon Jul 20 06:47:04.531330 2026] [security2:error] [pid 1020501:tid 1020690] [client 34.138.198.0:33732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyMS_oRsP4jdONhfejAAAADk"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.547709 2026] [security2:error] [pid 1020501:tid 1020705] [client 77.110.127.138:55692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YyMS_oRsP4jdONhfelAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:04.547815 2026] [security2:error] [pid 1020501:tid 1020705] [client 77.110.127.138:55692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YyMS_oRsP4jdONhfelAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:04.553638 2026] [security2:error] [pid 1020501:tid 1020706] [client 34.138.198.0:33780] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.samdothan.org"] [uri "/.env"] [unique_id "al4YyMS_oRsP4jdONhfelgAAAEk"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.561187 2026] [security2:error] [pid 1014214:tid 1014448] [client 34.138.198.0:33742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIoyQAAAfc"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.642847 2026] [security2:error] [pid 1014214:tid 1014406] [client 34.138.198.0:33768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIozQAAAc0"]
[Mon Jul 20 06:47:04.654075 2026] [security2:error] [pid 1020501:tid 1020641] [client 34.138.198.0:33760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyMS_oRsP4jdONhfelQAAAAg"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.690220 2026] [security2:error] [pid 1014214:tid 1014443] [client 34.138.198.0:33628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIozgAAAfI"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.706427 2026] [security2:error] [pid 1014214:tid 1014470] [client 77.110.127.138:55693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YyAuRBFTcQNywdCIo1QAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:04.706536 2026] [security2:error] [pid 1014214:tid 1014470] [client 77.110.127.138:55693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YyAuRBFTcQNywdCIo1QAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:04.741965 2026] [security2:error] [pid 1014214:tid 1014468] [client 57.141.18.40:20446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YxAuRBFTcQNywdCIoIwACC2s"]
[Mon Jul 20 06:47:04.782554 2026] [security2:error] [pid 1014214:tid 1014447] [client 34.138.198.0:33786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIo1AAAAfY"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:04.849899 2026] [security2:error] [pid 1020501:tid 1020684] [client 34.138.198.0:33724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyMS_oRsP4jdONhfengAAADM"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:05.036861 2026] [security2:error] [pid 1014214:tid 1014429] [client 156.243.37.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4YyAuRBFTcQNywdCIo0QAB5GU"], referer: https://paultoursafari.com/fly-in-safari-zanzibar-serengeti-launch/
[Mon Jul 20 06:47:05.040357 2026] [security2:error] [pid 1020501:tid 1020679] [client 77.110.127.138:55697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YycS_oRsP4jdONhfepAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:05.040468 2026] [security2:error] [pid 1020501:tid 1020679] [client 77.110.127.138:55697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YycS_oRsP4jdONhfepAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:05.065181 2026] [security2:error] [pid 1020501:tid 1020621] [remote 192.241.143.148:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4YycS_oRsP4jdONhfepQAAEHU"]
[Mon Jul 20 06:47:05.074335 2026] [security2:error] [pid 1014214:tid 1014455] [client 104.234.53.81:30403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YyQuRBFTcQNywdCIo4QAAAf4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:05.133963 2026] [security2:error] [pid 1020501:tid 1020759] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfeowAAAH4"]
[Mon Jul 20 06:47:05.282234 2026] [security2:error] [pid 1014214:tid 1014215] [remote 45.90.123.233:58206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIo6QABowA"]
[Mon Jul 20 06:47:05.282343 2026] [security2:error] [pid 1014214:tid 1014364] [client 45.90.123.233:58206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIo6QABowA"]
[Mon Jul 20 06:47:05.286102 2026] [security2:error] [pid 1020501:tid 1020623] [remote 192.241.143.148:39204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4YycS_oRsP4jdONhfeqwAAKXc"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 06:47:05.328871 2026] [security2:error] [pid 1020501:tid 1020737] [client 34.138.198.0:33798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfeqAAAAGg"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:05.397459 2026] [security2:error] [pid 1014214:tid 1014378] [client 77.110.127.138:55707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YyQuRBFTcQNywdCIo8QAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:05.397552 2026] [security2:error] [pid 1014214:tid 1014378] [client 77.110.127.138:55707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YyQuRBFTcQNywdCIo8QAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:05.459855 2026] [security2:error] [pid 1014214:tid 1014360] [client 34.138.198.0:33842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YyQuRBFTcQNywdCIo7wAAAZ8"], referer: https://www.samdothan.org/.npmrc
[Mon Jul 20 06:47:05.482099 2026] [security2:error] [pid 1014214:tid 1014452] [client 106.219.188.178:15809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIo-gAAAfs"]
[Mon Jul 20 06:47:05.482213 2026] [security2:error] [pid 1014214:tid 1014452] [client 106.219.188.178:15809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIo-gAAAfs"]
[Mon Jul 20 06:47:05.548715 2026] [security2:error] [pid 1014214:tid 1014351] [client 39.48.81.23:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIo-wAAAZY"]
[Mon Jul 20 06:47:05.548843 2026] [security2:error] [pid 1014214:tid 1014351] [client 39.48.81.23:62531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIo-wAAAZY"]
[Mon Jul 20 06:47:05.593585 2026] [security2:error] [pid 1020501:tid 1020693] [client 34.138.198.0:33854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfetAAAADw"], referer: https://www.samdothan.org/config.yaml
[Mon Jul 20 06:47:05.595460 2026] [security2:error] [pid 1014214:tid 1014335] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.samdothan.org"] [uri "/.env.backup"] [unique_id "al4YyQuRBFTcQNywdCIo_QABtng"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:05.596073 2026] [security2:error] [pid 1020501:tid 1020681] [client 34.138.198.0:28704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfetQAAADA"], referer: https://www.samdothan.org/.git/HEAD
[Mon Jul 20 06:47:05.712775 2026] [security2:error] [pid 1020501:tid 1020650] [client 34.138.198.0:33806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfeugAAABE"], referer: https://www.samdothan.org/api/config
[Mon Jul 20 06:47:05.758404 2026] [security2:error] [pid 1014214:tid 1014409] [client 112.208.70.94:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIpBwAAAdA"]
[Mon Jul 20 06:47:05.758513 2026] [security2:error] [pid 1014214:tid 1014409] [client 112.208.70.94:41989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4YyQuRBFTcQNywdCIpBwAAAdA"]
[Mon Jul 20 06:47:05.773237 2026] [security2:error] [pid 1020501:tid 1020714] [client 34.138.198.0:33832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfevQAAAFE"], referer: https://www.samdothan.org/.env.test
[Mon Jul 20 06:47:05.784320 2026] [security2:error] [pid 1014214:tid 1014458] [client 104.234.53.66:46579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4YyQuRBFTcQNywdCIpAwAAAgE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:05.820310 2026] [security2:error] [pid 1020501:tid 1020656] [client 34.138.198.0:33834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfevwAAABc"], referer: https://www.samdothan.org/.env.local
[Mon Jul 20 06:47:05.822097 2026] [security2:error] [pid 1014214:tid 1014394] [client 34.138.198.0:33828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyQuRBFTcQNywdCIpBQAAAcE"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:05.844522 2026] [security2:error] [pid 1020501:tid 1020673] [client 77.110.127.138:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YycS_oRsP4jdONhfexQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:05.844600 2026] [security2:error] [pid 1020501:tid 1020673] [client 77.110.127.138:55718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4YycS_oRsP4jdONhfexQAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:05.848578 2026] [security2:error] [pid 1014214:tid 1014460] [client 14.225.17.146:49251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4YyQuRBFTcQNywdCIpAgAAAgM"], referer: http://taskidsvirginia.com/New
[Mon Jul 20 06:47:05.913956 2026] [security2:error] [pid 1020501:tid 1020627] [remote 202.51.202.242:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4YycS_oRsP4jdONhfeyAAALns"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:47:05.923614 2026] [security2:error] [pid 1020501:tid 1020739] [client 34.138.198.0:33868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YycS_oRsP4jdONhfewAAAAGo"], referer: https://www.samdothan.org/.git/config
[Mon Jul 20 06:47:06.021358 2026] [security2:error] [pid 1014214:tid 1014411] [client 34.138.198.0:28732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YyQuRBFTcQNywdCIpEAAAAdI"]
[Mon Jul 20 06:47:06.048431 2026] [security2:error] [pid 1014214:tid 1014420] [client 104.234.53.66:46579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4YyguRBFTcQNywdCIpEgAAAds"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:06.089991 2026] [security2:error] [pid 1020501:tid 1020759] [client 34.138.198.0:28774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.samdothan.org"] [uri "/.env.old"] [unique_id "al4YysS_oRsP4jdONhfe0QAAAH4"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:06.098085 2026] [security2:error] [pid 1020501:tid 1020669] [client 34.138.198.0:33812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfezwAAACQ"], referer: https://www.samdothan.org/.env.sample
[Mon Jul 20 06:47:06.124618 2026] [security2:error] [pid 1020501:tid 1020649] [client 34.138.198.0:28754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe0AAAABA"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:06.173533 2026] [security2:error] [pid 1014214:tid 1014337] [remote 2a06:98c0:3600::103:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.samdothan.org"] [uri "/.env"] [unique_id "al4YyguRBFTcQNywdCIpGgAB-Xo"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:06.182267 2026] [security2:error] [pid 1020501:tid 1020719] [client 34.138.198.0:28712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe0gAAAFY"], referer: https://www.samdothan.org/.dev.vars
[Mon Jul 20 06:47:06.186101 2026] [security2:error] [pid 1014214:tid 1014371] [client 34.138.198.0:28706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YyguRBFTcQNywdCIpEwAAAao"], referer: https://www.samdothan.org/.env.production
[Mon Jul 20 06:47:06.198934 2026] [security2:error] [pid 1014214:tid 1014400] [client 34.138.198.0:28728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YyguRBFTcQNywdCIpFAAAAcc"], referer: https://www.samdothan.org/.netrc
[Mon Jul 20 06:47:06.249931 2026] [security2:error] [pid 1020501:tid 1020639] [client 34.138.198.0:28744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe0wAAAAY"]
[Mon Jul 20 06:47:06.261242 2026] [security2:error] [pid 1020501:tid 1020741] [client 34.138.198.0:28730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe3AAAAGw"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:06.264635 2026] [security2:error] [pid 1014214:tid 1014448] [client 34.138.198.0:33862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YyguRBFTcQNywdCIpFgAAAfc"], referer: https://www.samdothan.org/.aws/credentials
[Mon Jul 20 06:47:06.342677 2026] [security2:error] [pid 1020501:tid 1020735] [client 34.138.198.0:33884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe3QAAAGY"], referer: https://www.samdothan.org/.env.save
[Mon Jul 20 06:47:06.403802 2026] [security2:error] [pid 1020501:tid 1020506] [remote 103.255.134.61:39852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YysS_oRsP4jdONhfe6gAAPgI"]
[Mon Jul 20 06:47:06.451673 2026] [security2:error] [pid 1020501:tid 1020713] [client 14.225.17.146:50794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe5gAAAFA"], referer: http://adirondackengineering.com/New
[Mon Jul 20 06:47:06.490030 2026] [security2:error] [pid 1020501:tid 1020660] [client 34.138.198.0:28764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe6wAAABs"], referer: https://www.google.com/search?q=www.samdothan.org
[Mon Jul 20 06:47:06.639182 2026] [security2:error] [pid 1020501:tid 1020722] [client 34.138.198.0:28808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe7AAAAFk"], referer: https://www.samdothan.org/.pypirc
[Mon Jul 20 06:47:06.644146 2026] [security2:error] [pid 1014214:tid 1014413] [client 34.138.198.0:28826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YyguRBFTcQNywdCIpKQAAAdQ"], referer: https://www.samdothan.org/config.yml
[Mon Jul 20 06:47:06.825538 2026] [security2:error] [pid 1020501:tid 1020509] [remote 57.141.18.111:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2596330"] [unique_id "al4YysS_oRsP4jdONhfe-QAADwU"]
[Mon Jul 20 06:47:06.862978 2026] [security2:error] [pid 1020501:tid 1020633] [client 109.115.32.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4YysS_oRsP4jdONhfe9wAAAAA"]
[Mon Jul 20 06:47:06.938804 2026] [security2:error] [pid 1020501:tid 1020705] [client 202.46.92.242:51292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YysS_oRsP4jdONhffAQAAAEg"]
[Mon Jul 20 06:47:06.938932 2026] [security2:error] [pid 1020501:tid 1020705] [client 202.46.92.242:51292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4YysS_oRsP4jdONhffAQAAAEg"]
[Mon Jul 20 06:47:07.042422 2026] [security2:error] [pid 1020501:tid 1020725] [client 57.141.18.89:57920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YxsS_oRsP4jdONhfeRwAAXGQ"]
[Mon Jul 20 06:47:07.147956 2026] [security2:error] [pid 1020501:tid 1020511] [remote 202.51.202.242:48260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Yy8S_oRsP4jdONhffBgAAMgc"]
[Mon Jul 20 06:47:07.153693 2026] [security2:error] [pid 1014214:tid 1014452] [client 103.238.106.162:60852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YywuRBFTcQNywdCIpQQAAAfs"]
[Mon Jul 20 06:47:07.153803 2026] [security2:error] [pid 1014214:tid 1014452] [client 103.238.106.162:60852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4YywuRBFTcQNywdCIpQQAAAfs"]
[Mon Jul 20 06:47:07.293319 2026] [security2:error] [pid 1020501:tid 1020514] [remote 103.255.134.61:39852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4Yy8S_oRsP4jdONhffDQAAbAo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:47:07.403866 2026] [security2:error] [pid 1020501:tid 1020706] [client 34.138.198.0:28850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Yy8S_oRsP4jdONhffDgAAAEk"], referer: https://www.samdothan.org/.env.development.local
[Mon Jul 20 06:47:07.435440 2026] [security2:error] [pid 1020501:tid 1020672] [client 34.138.198.0:28840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Yy8S_oRsP4jdONhffEAAAACc"], referer: https://www.samdothan.org/.env.production.local
[Mon Jul 20 06:47:07.491378 2026] [security2:error] [pid 1020501:tid 1020728] [client 34.138.198.0:28818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4Yy8S_oRsP4jdONhffFwAAAF8"], referer: https://www.samdothan.org/.env.dist
[Mon Jul 20 06:47:07.957488 2026] [security2:error] [pid 1020501:tid 1020707] [client 158.173.166.181:39985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Yy8S_oRsP4jdONhffLQAAAEo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:47:08.044329 2026] [security2:error] [pid 1020501:tid 1020713] [client 157.85.211.87:21723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YzMS_oRsP4jdONhffMgAAAFA"]
[Mon Jul 20 06:47:08.044423 2026] [security2:error] [pid 1020501:tid 1020713] [client 157.85.211.87:21723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YzMS_oRsP4jdONhffMgAAAFA"]
[Mon Jul 20 06:47:08.105459 2026] [security2:error] [pid 1020501:tid 1020656] [client 217.142.18.172:55279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YzMS_oRsP4jdONhffNAAAABc"]
[Mon Jul 20 06:47:08.111870 2026] [security2:error] [pid 1020501:tid 1020656] [client 217.142.18.172:55279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4YzMS_oRsP4jdONhffNAAAABc"]
[Mon Jul 20 06:47:08.168141 2026] [security2:error] [pid 1020501:tid 1020647] [client 45.3.48.173:35611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YzMS_oRsP4jdONhffNQAAAA4"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:08.364061 2026] [security2:error] [pid 1020501:tid 1020649] [client 14.225.17.146:54765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4YzMS_oRsP4jdONhffOwAAABA"], referer: http://aljosour-alarabia.com/New
[Mon Jul 20 06:47:08.400285 2026] [security2:error] [pid 1020501:tid 1020755] [client 34.138.198.0:28864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4YzMS_oRsP4jdONhffQAAAAHo"], referer: https://www.samdothan.org/secrets.yaml
[Mon Jul 20 06:47:08.503874 2026] [security2:error] [pid 1020501:tid 1020676] [client 34.21.41.254:61626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4YzMS_oRsP4jdONhffQQAAACs"]
[Mon Jul 20 06:47:08.570711 2026] [security2:error] [pid 1020501:tid 1020727] [client 34.21.41.254:61626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/xmlrpc.php"] [unique_id "al4YzMS_oRsP4jdONhffTwAAAF4"]
[Mon Jul 20 06:47:08.804735 2026] [security2:error] [pid 1014214:tid 1014350] [client 187.108.85.186:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YzAuRBFTcQNywdCIpgQAAAZU"]
[Mon Jul 20 06:47:08.804867 2026] [security2:error] [pid 1014214:tid 1014350] [client 187.108.85.186:60472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YzAuRBFTcQNywdCIpgQAAAZU"]
[Mon Jul 20 06:47:08.881134 2026] [security2:error] [pid 1020501:tid 1020634] [client 34.21.41.254:55241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4YzMS_oRsP4jdONhffXAAAAAE"]
[Mon Jul 20 06:47:08.885673 2026] [security2:error] [pid 1014214:tid 1014344] [client 104.234.53.73:38789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4YzAuRBFTcQNywdCIpigAAAY8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:08.926971 2026] [security2:error] [pid 1014214:tid 1014428] [client 14.225.17.146:55245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4YzAuRBFTcQNywdCIpfgAAAeM"], referer: http://headachescarpaltunnelfibromyalgia.com/New
[Mon Jul 20 06:47:08.961823 2026] [proxy:error] [pid 1014214:tid 1014426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:08.961882 2026] [proxy_http:error] [pid 1014214:tid 1014426] [client 34.73.38.214:64734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:08.962548 2026] [proxy:error] [pid 1014214:tid 1014426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:08.962575 2026] [proxy_http:error] [pid 1014214:tid 1014426] [client 34.73.38.214:64734] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:08.974194 2026] [security2:error] [pid 1020501:tid 1020669] [client 45.3.48.160:10359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.48.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4YzMS_oRsP4jdONhffXwAAACQ"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:08.986109 2026] [security2:error] [pid 1020501:tid 1020726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4YzMS_oRsP4jdONhffVwAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:09.156260 2026] [security2:error] [pid 1014214:tid 1014415] [client 34.21.41.254:51053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4YzQuRBFTcQNywdCIplAAAAdY"]
[Mon Jul 20 06:47:09.445053 2026] [security2:error] [pid 1020501:tid 1020721] [client 34.21.41.254:58281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4YzcS_oRsP4jdONhffZgAAAFg"]
[Mon Jul 20 06:47:09.452481 2026] [security2:error] [pid 1014214:tid 1014385] [client 14.225.17.146:54655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4YzAuRBFTcQNywdCIpYwAAAbg"], referer: http://chestermonty.com/New
[Mon Jul 20 06:47:09.686191 2026] [security2:error] [pid 1014214:tid 1014359] [client 57.141.18.67:50426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YyQuRBFTcQNywdCIo8AABnlA"]
[Mon Jul 20 06:47:09.702673 2026] [security2:error] [pid 1020501:tid 1020698] [client 103.125.179.95:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YzcS_oRsP4jdONhffbgAAAEE"]
[Mon Jul 20 06:47:09.702788 2026] [security2:error] [pid 1020501:tid 1020698] [client 103.125.179.95:58831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4YzcS_oRsP4jdONhffbgAAAEE"]
[Mon Jul 20 06:47:09.718677 2026] [security2:error] [pid 1014214:tid 1014443] [client 34.21.41.254:62727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4YzQuRBFTcQNywdCIpsQAAAfI"]
[Mon Jul 20 06:47:09.879425 2026] [proxy:error] [pid 1014214:tid 1014375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:09.879514 2026] [proxy_http:error] [pid 1014214:tid 1014375] [client 34.73.38.214:59627] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:09.880228 2026] [proxy:error] [pid 1014214:tid 1014375] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:09.880261 2026] [proxy_http:error] [pid 1014214:tid 1014375] [client 34.73.38.214:59627] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:09.895265 2026] [security2:error] [pid 1014214:tid 1014252] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YzQuRBFTcQNywdCIpvAAB-yU"]
[Mon Jul 20 06:47:09.895489 2026] [security2:error] [pid 1014214:tid 1014452] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4YzQuRBFTcQNywdCIpvAAB-yU"]
[Mon Jul 20 06:47:09.954702 2026] [security2:error] [pid 1020501:tid 1020668] [client 14.225.17.146:54787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4YzMS_oRsP4jdONhffPgAAACM"], referer: http://aandarealtygroup.com/New
[Mon Jul 20 06:47:10.007480 2026] [security2:error] [pid 1014214:tid 1014462] [client 14.225.17.146:55215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4YzAuRBFTcQNywdCIpegAAAgU"], referer: http://wathenbartlett.co.uk/New
[Mon Jul 20 06:47:10.036669 2026] [security2:error] [pid 1014214:tid 1014426] [client 14.224.227.113:54702] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4YzguRBFTcQNywdCIpwwAAAeE"]
[Mon Jul 20 06:47:10.089574 2026] [core:error] [pid 1014214:tid 1014347] [client 103.153.183.69:23904] AH10244: invalid URI path (/.%2e/etc/passwd?_=u73keqjf&v=kavp9), referer: https://www.bing.com/search?q=nmycev
[Mon Jul 20 06:47:10.093177 2026] [security2:error] [pid 1020501:tid 1020648] [client 127.0.0.1:36974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4YzsS_oRsP4jdONhfffQAAAA8"], referer: https://www.bing.com/search?q=nmycev
[Mon Jul 20 06:47:10.132450 2026] [security2:error] [pid 1014214:tid 1014389] [client 34.21.41.254:64625] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4YzguRBFTcQNywdCIpyAAAAbw"]
[Mon Jul 20 06:47:10.133514 2026] [security2:error] [pid 1014214:tid 1014470] [client 57.141.18.30:23450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YyQuRBFTcQNywdCIpDAACDQw"]
[Mon Jul 20 06:47:10.155439 2026] [security2:error] [pid 1020501:tid 1020645] [client 14.225.17.146:55281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4YzMS_oRsP4jdONhffWgAAAAw"], referer: http://effingweirdmuseums.com/New
[Mon Jul 20 06:47:10.385363 2026] [security2:error] [pid 1014214:tid 1014441] [client 14.225.17.146:49195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4YzguRBFTcQNywdCIpzwAAAfA"], referer: https://chestermonty.com/New
[Mon Jul 20 06:47:10.413410 2026] [security2:error] [pid 1020501:tid 1020726] [client 34.21.41.254:63936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4YzsS_oRsP4jdONhffiQAAAF0"]
[Mon Jul 20 06:47:10.682543 2026] [security2:error] [pid 1020501:tid 1020540] [remote 202.51.202.242:48260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4YzsS_oRsP4jdONhffkwAANyQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:47:10.722098 2026] [security2:error] [pid 1014214:tid 1014398] [client 34.21.41.254:64122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4YzguRBFTcQNywdCIp4AAAAcU"]
[Mon Jul 20 06:47:10.879212 2026] [security2:error] [pid 1020501:tid 1020707] [client 183.82.98.154:50442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YzsS_oRsP4jdONhffmgAAAEo"]
[Mon Jul 20 06:47:10.879317 2026] [security2:error] [pid 1020501:tid 1020707] [client 183.82.98.154:50442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4YzsS_oRsP4jdONhffmgAAAEo"]
[Mon Jul 20 06:47:10.913338 2026] [security2:error] [pid 1014214:tid 1014460] [client 14.225.17.146:52561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4YzguRBFTcQNywdCIp5QAAAgM"], referer: https://wathenbartlett.co.uk/New
[Mon Jul 20 06:47:10.980171 2026] [security2:error] [pid 1014214:tid 1014410] [client 96.77.64.222:50670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4YzguRBFTcQNywdCIp6QAB0Sg"]
[Mon Jul 20 06:47:10.981367 2026] [security2:error] [pid 1014214:tid 1014288] [remote 45.90.123.233:44702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sergnotes.com"] [uri "/wp-login.php"] [unique_id "al4YzguRBFTcQNywdCIp8AABtUk"]
[Mon Jul 20 06:47:11.007767 2026] [security2:error] [pid 1020501:tid 1020646] [client 34.21.41.254:62259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Yz8S_oRsP4jdONhffpgAAAA0"]
[Mon Jul 20 06:47:11.077663 2026] [security2:error] [pid 1020501:tid 1020741] [client 14.225.17.146:52658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4YzsS_oRsP4jdONhffoAAAAGw"], referer: https://effingweirdmuseums.com/New
[Mon Jul 20 06:47:11.082279 2026] [access_compat:error] [pid 1020501:tid 1020544] [remote 168.75.78.34:47614] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:47:11.115180 2026] [security2:error] [pid 1014214:tid 1014379] [client 57.141.18.12:58568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YyguRBFTcQNywdCIpKwABsg4"]
[Mon Jul 20 06:47:11.167868 2026] [proxy:error] [pid 1014214:tid 1014347] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:11.167950 2026] [proxy_http:error] [pid 1014214:tid 1014347] [client 34.73.38.214:62056] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:11.168442 2026] [proxy:error] [pid 1014214:tid 1014347] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:11.168455 2026] [security2:error] [pid 1020501:tid 1020756] [client 77.110.127.138:55781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Yz8S_oRsP4jdONhffqQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:11.168474 2026] [proxy_http:error] [pid 1014214:tid 1014347] [client 34.73.38.214:62056] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:11.168551 2026] [security2:error] [pid 1020501:tid 1020756] [client 77.110.127.138:55781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Yz8S_oRsP4jdONhffqQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:11.202326 2026] [security2:error] [pid 1020501:tid 1020546] [remote 182.77.62.24:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Yz8S_oRsP4jdONhffqgAAQCo"]
[Mon Jul 20 06:47:11.202464 2026] [security2:error] [pid 1020501:tid 1020697] [client 182.77.62.24:42260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Yz8S_oRsP4jdONhffqgAAQCo"]
[Mon Jul 20 06:47:11.226354 2026] [security2:error] [pid 1014214:tid 1014282] [remote 45.90.123.233:44702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sergnotes.com"] [uri "/wp-login.php"] [unique_id "al4YzwuRBFTcQNywdCIp-QABn0M"], referer: https://sergnotes.com/wp-login.php
[Mon Jul 20 06:47:11.298436 2026] [security2:error] [pid 1014214:tid 1014434] [client 34.21.41.254:64611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4YzwuRBFTcQNywdCIqAAAAAek"]
[Mon Jul 20 06:47:11.455108 2026] [security2:error] [pid 1020501:tid 1020644] [client 14.225.17.146:49266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4YzsS_oRsP4jdONhffhAAAAAs"], referer: http://sarahholyfield.com/New
[Mon Jul 20 06:47:11.533267 2026] [security2:error] [pid 1020501:tid 1020758] [client 34.73.38.214:64964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/xmlrpc.php"] [unique_id "al4Yz8S_oRsP4jdONhffsgAAAH0"]
[Mon Jul 20 06:47:11.540186 2026] [security2:error] [pid 1014214:tid 1014398] [client 34.21.41.254:63215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4YzwuRBFTcQNywdCIqFQAAAcU"]
[Mon Jul 20 06:47:11.806743 2026] [security2:error] [pid 1020501:tid 1020703] [client 34.21.41.254:58006] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Yz8S_oRsP4jdONhffwgAAAEY"]
[Mon Jul 20 06:47:11.953820 2026] [security2:error] [pid 1014214:tid 1014405] [client 34.147.91.161:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.rrf.lcd.mybluehost.me"] [uri "/"] [unique_id "al4YzwuRBFTcQNywdCIqJQAAAcw"]
[Mon Jul 20 06:47:11.953967 2026] [security2:error] [pid 1014214:tid 1014405] [client 34.147.91.161:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.rrf.lcd.mybluehost.me"] [uri "/"] [unique_id "al4YzwuRBFTcQNywdCIqJQAAAcw"]
[Mon Jul 20 06:47:11.961026 2026] [security2:error] [pid 1014214:tid 1014382] [client 57.141.18.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4YzwuRBFTcQNywdCIqGAAAAbU"]
[Mon Jul 20 06:47:12.075496 2026] [security2:error] [pid 1020501:tid 1020533] [remote 47.86.33.52:36088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4Y0MS_oRsP4jdONhffzQAASx0"]
[Mon Jul 20 06:47:12.089468 2026] [security2:error] [pid 1020501:tid 1020754] [client 34.21.41.254:56718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "swafforddetailing.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Y0MS_oRsP4jdONhffzgAAAHk"]
[Mon Jul 20 06:47:12.193056 2026] [security2:error] [pid 1014214:tid 1014434] [client 34.73.38.214:59494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Y0AuRBFTcQNywdCIqLwAAAek"]
[Mon Jul 20 06:47:12.249887 2026] [access_compat:error] [pid 1014214:tid 1014308] [remote 94.200.108.9:37514] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:47:12.473996 2026] [security2:error] [pid 1020501:tid 1020736] [client 57.141.18.88:47128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Yy8S_oRsP4jdONhffIwAAZxA"]
[Mon Jul 20 06:47:12.754892 2026] [security2:error] [pid 1020501:tid 1020557] [remote 47.86.33.52:36088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4Y0MS_oRsP4jdONhff7QAABTU"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 06:47:12.903290 2026] [autoindex:error] [pid 1020501:tid 1020641] [client 205.210.31.14:62514] AH01276: Cannot serve directory /home1/audtrpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.aud.trp.mybluehost.me/
[Mon Jul 20 06:47:12.972166 2026] [core:error] [pid 1020501:tid 1020671] [client 103.153.183.69:23920] AH10244: invalid URI path (/%2e./etc/passwd?_=ccyal4u4&v=xwkn8), referer: https://duckduckgo.com/?q=0pcbv
[Mon Jul 20 06:47:12.974064 2026] [security2:error] [pid 1020501:tid 1020672] [client 127.0.0.1:36984] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4Y0MS_oRsP4jdONhff_QAAACc"], referer: https://duckduckgo.com/?q=0pcbv
[Mon Jul 20 06:47:13.048233 2026] [security2:error] [pid 1020501:tid 1020691] [client 117.247.108.24:64884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y0cS_oRsP4jdONhff_wAAADo"]
[Mon Jul 20 06:47:13.048385 2026] [security2:error] [pid 1020501:tid 1020691] [client 117.247.108.24:64884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y0cS_oRsP4jdONhff_wAAADo"]
[Mon Jul 20 06:47:13.072859 2026] [security2:error] [pid 1020501:tid 1020711] [client 14.225.17.146:54432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4Yz8S_oRsP4jdONhffugAAAE4"], referer: http://ghivs.com/New
[Mon Jul 20 06:47:13.100936 2026] [security2:error] [pid 1020501:tid 1020716] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "avatrip.co"] [uri "/index.php"] [unique_id "al4Y0MS_oRsP4jdONhff_gAAAFM"]
[Mon Jul 20 06:47:13.253214 2026] [security2:error] [pid 1014214:tid 1014359] [client 37.52.210.45:56055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y0QuRBFTcQNywdCIqUQAAAZ4"]
[Mon Jul 20 06:47:13.253315 2026] [security2:error] [pid 1014214:tid 1014359] [client 37.52.210.45:56055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y0QuRBFTcQNywdCIqUQAAAZ4"]
[Mon Jul 20 06:47:13.585044 2026] [security2:error] [pid 1014214:tid 1014375] [client 176.118.193.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4Y0QuRBFTcQNywdCIqVwAAAa4"]
[Mon Jul 20 06:47:13.623557 2026] [security2:error] [pid 1020501:tid 1020751] [client 34.73.38.214:55404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Y0cS_oRsP4jdONhfgHAAAAHY"]
[Mon Jul 20 06:47:13.712289 2026] [security2:error] [pid 1014214:tid 1014361] [client 223.185.13.213:1954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y0QuRBFTcQNywdCIqXgAAAaA"]
[Mon Jul 20 06:47:13.712430 2026] [security2:error] [pid 1014214:tid 1014361] [client 223.185.13.213:1954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y0QuRBFTcQNywdCIqXgAAAaA"]
[Mon Jul 20 06:47:13.879210 2026] [security2:error] [pid 1020501:tid 1020745] [client 14.225.17.146:52748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4Y0MS_oRsP4jdONhff2gAAAHA"]
[Mon Jul 20 06:47:14.052935 2026] [security2:error] [pid 1020501:tid 1020678] [client 34.73.38.214:55227] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Y0sS_oRsP4jdONhfgMQAAAC0"]
[Mon Jul 20 06:47:14.148744 2026] [security2:error] [pid 1014214:tid 1014220] [remote 8.217.108.67:39452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4Y0guRBFTcQNywdCIqbwACBgU"]
[Mon Jul 20 06:47:14.321967 2026] [security2:error] [pid 1020501:tid 1020741] [client 197.186.66.42:51585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y0sS_oRsP4jdONhfgOAAAAGw"]
[Mon Jul 20 06:47:14.322078 2026] [security2:error] [pid 1020501:tid 1020741] [client 197.186.66.42:51585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y0sS_oRsP4jdONhfgOAAAAGw"]
[Mon Jul 20 06:47:14.371419 2026] [security2:error] [pid 1020501:tid 1020747] [client 104.234.53.57:51557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Y0sS_oRsP4jdONhfgNwAAAHI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:14.508013 2026] [security2:error] [pid 1020501:tid 1020572] [remote 160.187.68.132:43812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4Y0sS_oRsP4jdONhfgPQAABkQ"]
[Mon Jul 20 06:47:14.584950 2026] [security2:error] [pid 1020501:tid 1020692] [client 104.234.53.57:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y0sS_oRsP4jdONhfgRAAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:14.699894 2026] [security2:error] [pid 1014214:tid 1014252] [remote 8.217.108.67:39452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4Y0guRBFTcQNywdCIqhQAB-iU"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 06:47:14.729580 2026] [security2:error] [pid 1020501:tid 1020691] [client 34.73.38.214:62820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Y0sS_oRsP4jdONhfgUgAAADo"]
[Mon Jul 20 06:47:14.760600 2026] [security2:error] [pid 1020501:tid 1020673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y0sS_oRsP4jdONhfgQwAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:14.864677 2026] [security2:error] [pid 1020501:tid 1020700] [client 57.141.18.125:30198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YzcS_oRsP4jdONhffcwAAQyE"]
[Mon Jul 20 06:47:14.865851 2026] [security2:error] [pid 1014214:tid 1014455] [client 57.141.18.109:31634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YzQuRBFTcQNywdCIptwAB_mw"]
[Mon Jul 20 06:47:14.922262 2026] [security2:error] [pid 1020501:tid 1020640] [client 171.61.165.146:20631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.165.61.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Y0sS_oRsP4jdONhfgWQAAAAc"]
[Mon Jul 20 06:47:14.922369 2026] [security2:error] [pid 1020501:tid 1020640] [client 171.61.165.146:20631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "newoffice.ca"] [uri "/xmlrpc.php"] [unique_id "al4Y0sS_oRsP4jdONhfgWQAAAAc"]
[Mon Jul 20 06:47:15.044025 2026] [security2:error] [pid 1020501:tid 1020578] [remote 160.187.68.132:43812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4Y08S_oRsP4jdONhfgXAAAXUo"], referer: https://snctaxgroup.com/wp-login.php
[Mon Jul 20 06:47:15.376392 2026] [security2:error] [pid 1020501:tid 1020635] [client 34.73.38.214:62297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Y08S_oRsP4jdONhfgYQAAAAI"]
[Mon Jul 20 06:47:15.390293 2026] [security2:error] [pid 1014214:tid 1014404] [client 14.225.17.146:65510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4Y0wuRBFTcQNywdCIqnwAAAcs"]
[Mon Jul 20 06:47:15.464670 2026] [security2:error] [pid 1020501:tid 1020736] [client 216.24.212.16:25101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4Y08S_oRsP4jdONhfgZgAAAGc"]
[Mon Jul 20 06:47:15.494196 2026] [security2:error] [pid 1014214:tid 1014392] [client 216.24.212.52:30241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4Y0wuRBFTcQNywdCIqpAAAAb8"]
[Mon Jul 20 06:47:15.540446 2026] [security2:error] [pid 1020501:tid 1020652] [client 104.234.53.89:45419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Y08S_oRsP4jdONhfgbQAAABM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:15.683536 2026] [core:error] [pid 1020501:tid 1020660] [client 103.153.183.69:23936] AH10244: invalid URI path (/../../../etc/passwd?_=2lw6z92y&v=qi46t), referer: https://www.google.com/search?q=25957u
[Mon Jul 20 06:47:15.686706 2026] [security2:error] [pid 1020501:tid 1020738] [client 127.0.0.1:36990] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4Y08S_oRsP4jdONhfgdQAAAGk"], referer: https://www.google.com/search?q=25957u
[Mon Jul 20 06:47:15.736000 2026] [security2:error] [pid 1014214:tid 1014463] [client 14.225.17.146:62666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4Y0wuRBFTcQNywdCIqqgAAAgY"], referer: http://39ishlife.com/New
[Mon Jul 20 06:47:15.934975 2026] [security2:error] [pid 1020501:tid 1020704] [client 18.142.226.106:44570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Y08S_oRsP4jdONhfgfwAAAEc"]
[Mon Jul 20 06:47:15.935092 2026] [security2:error] [pid 1020501:tid 1020704] [client 18.142.226.106:44570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Y08S_oRsP4jdONhfgfwAAAEc"]
[Mon Jul 20 06:47:15.983310 2026] [core:error] [pid 1020501:tid 1020719] [client 14.225.17.146:52653] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/New
[Mon Jul 20 06:47:15.983334 2026] [core:error] [pid 1020501:tid 1020719] [client 14.225.17.146:52653] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/New
[Mon Jul 20 06:47:16.048093 2026] [security2:error] [pid 1020501:tid 1020678] [client 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4Y1MS_oRsP4jdONhfgiAAAAC0"]
[Mon Jul 20 06:47:16.060867 2026] [security2:error] [pid 1020501:tid 1020592] [remote 202.51.202.242:13471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfghwAADVg"]
[Mon Jul 20 06:47:16.061001 2026] [security2:error] [pid 1020501:tid 1020646] [client 202.51.202.242:13471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfghwAADVg"]
[Mon Jul 20 06:47:16.141738 2026] [security2:error] [pid 1014214:tid 1014455] [client 77.110.127.138:55809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y1AuRBFTcQNywdCIqvgAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:16.141835 2026] [security2:error] [pid 1014214:tid 1014455] [client 77.110.127.138:55809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y1AuRBFTcQNywdCIqvgAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:16.188294 2026] [security2:error] [pid 1014214:tid 1014398] [client 34.73.38.214:52842] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1AuRBFTcQNywdCIqwQAAAcU"]
[Mon Jul 20 06:47:16.255291 2026] [core:error] [pid 1014214:tid 1014382] [client 198.235.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:47:16.255309 2026] [core:error] [pid 1014214:tid 1014382] [client 198.235.24.145:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:47:16.280476 2026] [security2:error] [pid 1020501:tid 1020680] [client 54.169.146.187:10978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Y1MS_oRsP4jdONhfgkwAAAC8"]
[Mon Jul 20 06:47:16.335134 2026] [security2:error] [pid 1020501:tid 1020665] [client 112.208.70.94:42487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgmAAAACA"]
[Mon Jul 20 06:47:16.335237 2026] [security2:error] [pid 1020501:tid 1020665] [client 112.208.70.94:42487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgmAAAACA"]
[Mon Jul 20 06:47:16.342501 2026] [security2:error] [pid 1020501:tid 1020666] [client 5.252.52.249:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4Y1MS_oRsP4jdONhfgmQAAACE"], referer: https://thescarystory.com/wp-login.php
[Mon Jul 20 06:47:16.403286 2026] [security2:error] [pid 1020501:tid 1020744] [client 192.140.149.97:45559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgnQAAAG8"]
[Mon Jul 20 06:47:16.403400 2026] [security2:error] [pid 1020501:tid 1020744] [client 192.140.149.97:45559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgnQAAAG8"]
[Mon Jul 20 06:47:16.426270 2026] [security2:error] [pid 1020501:tid 1020727] [client 14.225.17.146:52664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4Y0sS_oRsP4jdONhfgUQAAAF4"]
[Mon Jul 20 06:47:16.512954 2026] [security2:error] [pid 1020501:tid 1020633] [client 39.48.81.23:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgpAAAAAA"]
[Mon Jul 20 06:47:16.513257 2026] [security2:error] [pid 1020501:tid 1020633] [client 39.48.81.23:63042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgpAAAAAA"]
[Mon Jul 20 06:47:16.693884 2026] [security2:error] [pid 1020501:tid 1020649] [client 14.225.17.146:62414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4Y1MS_oRsP4jdONhfgpQAAABA"], referer: https://39ishlife.com/New
[Mon Jul 20 06:47:16.794012 2026] [security2:error] [pid 1014214:tid 1014349] [client 57.141.18.8:34262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YzwuRBFTcQNywdCIqBgABlDM"]
[Mon Jul 20 06:47:16.821771 2026] [security2:error] [pid 1020501:tid 1020691] [client 98.159.234.160:31395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Y1MS_oRsP4jdONhfgsQAAADo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:47:16.890470 2026] [security2:error] [pid 1020501:tid 1020670] [client 104.234.53.73:63927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y1MS_oRsP4jdONhfgtAAAACU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:16.923838 2026] [security2:error] [pid 1020501:tid 1020681] [client 36.95.228.227:51751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgtwAAADA"]
[Mon Jul 20 06:47:16.924016 2026] [security2:error] [pid 1020501:tid 1020681] [client 36.95.228.227:51751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1MS_oRsP4jdONhfgtwAAADA"]
[Mon Jul 20 06:47:16.931144 2026] [security2:error] [pid 1020501:tid 1020653] [client 34.73.38.214:61927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1MS_oRsP4jdONhfguQAAABQ"]
[Mon Jul 20 06:47:16.983870 2026] [security2:error] [pid 1020501:tid 1020677] [client 57.141.18.77:40906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Yz8S_oRsP4jdONhffswAALBM"]
[Mon Jul 20 06:47:17.108259 2026] [security2:error] [pid 1020501:tid 1020692] [client 34.139.11.221:54689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y1cS_oRsP4jdONhfgxQAAADs"]
[Mon Jul 20 06:47:17.122535 2026] [security2:error] [pid 1014214:tid 1014402] [client 54.169.146.187:10982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Y1QuRBFTcQNywdCIq6QAAAck"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:47:17.223240 2026] [security2:error] [pid 1020501:tid 1020727] [client 34.139.11.221:52207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1cS_oRsP4jdONhfgyQAAAF4"]
[Mon Jul 20 06:47:17.286622 2026] [proxy:error] [pid 1014214:tid 1014439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:17.286697 2026] [proxy_http:error] [pid 1014214:tid 1014439] [client 34.73.38.214:57148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:17.287399 2026] [proxy:error] [pid 1014214:tid 1014439] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:17.287431 2026] [proxy_http:error] [pid 1014214:tid 1014439] [client 34.73.38.214:57148] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:17.329938 2026] [security2:error] [pid 1014214:tid 1014364] [client 50.116.65.227:46948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Y1QuRBFTcQNywdCIq9AAAAaM"]
[Mon Jul 20 06:47:17.341730 2026] [security2:error] [pid 1020501:tid 1020650] [client 50.116.65.227:46958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Y1cS_oRsP4jdONhfgzgAAABE"]
[Mon Jul 20 06:47:17.358402 2026] [security2:error] [pid 1014214:tid 1014407] [client 34.139.11.221:64949] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1QuRBFTcQNywdCIq9gAAAc4"]
[Mon Jul 20 06:47:17.387119 2026] [security2:error] [pid 1020501:tid 1020751] [client 34.73.38.214:62575] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1cS_oRsP4jdONhfg0AAAAHY"]
[Mon Jul 20 06:47:17.472625 2026] [security2:error] [pid 1014214:tid 1014432] [client 57.141.18.46:49782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4YzwuRBFTcQNywdCIqIAAB5yM"]
[Mon Jul 20 06:47:17.511217 2026] [security2:error] [pid 1014214:tid 1014450] [client 34.139.11.221:53548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1QuRBFTcQNywdCIq_AAAAfk"]
[Mon Jul 20 06:47:17.700601 2026] [security2:error] [pid 1020501:tid 1020695] [client 104.234.53.69:44067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Y1cS_oRsP4jdONhfg1gAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:17.702079 2026] [security2:error] [pid 1020501:tid 1020718] [client 34.139.11.221:52115] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1cS_oRsP4jdONhfg3AAAAFU"]
[Mon Jul 20 06:47:17.709289 2026] [security2:error] [pid 1014214:tid 1014383] [client 103.238.106.162:42791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y1QuRBFTcQNywdCIrBwAAAbY"]
[Mon Jul 20 06:47:17.709430 2026] [security2:error] [pid 1014214:tid 1014383] [client 103.238.106.162:42791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y1QuRBFTcQNywdCIrBwAAAbY"]
[Mon Jul 20 06:47:17.877759 2026] [security2:error] [pid 1020501:tid 1020730] [client 34.139.11.221:53568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1cS_oRsP4jdONhfg3wAAAGE"]
[Mon Jul 20 06:47:18.061978 2026] [security2:error] [pid 1020501:tid 1020660] [client 34.139.11.221:63573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1sS_oRsP4jdONhfg7gAAABs"]
[Mon Jul 20 06:47:18.110602 2026] [proxy:error] [pid 1020501:tid 1020734] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:18.110636 2026] [proxy_http:error] [pid 1020501:tid 1020734] [client 34.73.38.214:55010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:18.111331 2026] [proxy:error] [pid 1020501:tid 1020734] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:18.111356 2026] [proxy_http:error] [pid 1020501:tid 1020734] [client 34.73.38.214:55010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:18.175884 2026] [autoindex:error] [pid 1014214:tid 1014371] [client 162.14.66.219:0] AH01276: Cannot serve directory /home1/itdynami/public_html/misralrakamia/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:47:18.180465 2026] [security2:error] [pid 1014214:tid 1014347] [client 34.139.11.221:55069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1guRBFTcQNywdCIrHgAAAZI"]
[Mon Jul 20 06:47:18.344359 2026] [security2:error] [pid 1020501:tid 1020719] [client 34.139.11.221:57124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1sS_oRsP4jdONhfg_gAAAFY"]
[Mon Jul 20 06:47:18.351845 2026] [security2:error] [pid 1020501:tid 1020699] [client 57.141.18.49:26336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y0MS_oRsP4jdONhff7AAAQik"]
[Mon Jul 20 06:47:18.390494 2026] [security2:error] [pid 1014214:tid 1014426] [client 34.73.38.214:59856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1guRBFTcQNywdCIrKgAAAeE"]
[Mon Jul 20 06:47:18.415700 2026] [security2:error] [pid 1014214:tid 1014397] [client 14.225.17.146:65497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4Y1guRBFTcQNywdCIrIwAAAcQ"], referer: http://ivetstrategies.com/New
[Mon Jul 20 06:47:18.415863 2026] [security2:error] [pid 1020501:tid 1020647] [client 104.234.53.69:44067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y1sS_oRsP4jdONhfhCQAAAA4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:18.427832 2026] [security2:error] [pid 1014214:tid 1014278] [remote 173.249.4.11:30646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4Y1guRBFTcQNywdCIrKwACDT8"]
[Mon Jul 20 06:47:18.485960 2026] [security2:error] [pid 1014214:tid 1014370] [client 34.139.11.221:60660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1guRBFTcQNywdCIrLQAAAak"]
[Mon Jul 20 06:47:18.614130 2026] [security2:error] [pid 1020501:tid 1020707] [client 217.142.18.172:17951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1sS_oRsP4jdONhfhEQAAAEo"]
[Mon Jul 20 06:47:18.614383 2026] [security2:error] [pid 1020501:tid 1020748] [client 122.183.32.225:18523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1sS_oRsP4jdONhfhDgAAAHM"]
[Mon Jul 20 06:47:18.614475 2026] [security2:error] [pid 1020501:tid 1020748] [client 122.183.32.225:18523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1sS_oRsP4jdONhfhDgAAAHM"]
[Mon Jul 20 06:47:18.624321 2026] [security2:error] [pid 1020501:tid 1020707] [client 217.142.18.172:17951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1sS_oRsP4jdONhfhEQAAAEo"]
[Mon Jul 20 06:47:18.656560 2026] [security2:error] [pid 1014214:tid 1014434] [client 34.139.11.221:63340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1guRBFTcQNywdCIrNAAAAek"]
[Mon Jul 20 06:47:18.835199 2026] [security2:error] [pid 1020501:tid 1020642] [client 57.141.18.25:21042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y0cS_oRsP4jdONhfgBwAACTc"]
[Mon Jul 20 06:47:18.887246 2026] [security2:error] [pid 1020501:tid 1020727] [client 34.139.11.221:62961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.lgi.ful.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Y1sS_oRsP4jdONhfhJAAAAF4"]
[Mon Jul 20 06:47:18.973583 2026] [security2:error] [pid 1014214:tid 1014336] [remote 173.249.4.11:30646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4Y1guRBFTcQNywdCIrPwAB3Xk"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:47:18.988634 2026] [security2:error] [pid 1020501:tid 1020667] [client 156.243.37.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4Y1sS_oRsP4jdONhfhCwAAInc"], referer: https://paultoursafari.com/fly-in-safari-zanzibar-serengeti-launch/
[Mon Jul 20 06:47:19.005536 2026] [security2:error] [pid 1020501:tid 1020719] [client 34.73.38.214:50220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Y18S_oRsP4jdONhfhKwAAAFY"]
[Mon Jul 20 06:47:19.050843 2026] [proxy:error] [pid 1020501:tid 1020695] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:19.050911 2026] [proxy_http:error] [pid 1020501:tid 1020695] [client 34.73.38.214:62878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:19.051486 2026] [proxy:error] [pid 1020501:tid 1020695] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:19.051517 2026] [proxy_http:error] [pid 1020501:tid 1020695] [client 34.73.38.214:62878] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:19.237796 2026] [security2:error] [pid 1020501:tid 1020741] [client 34.73.38.214:63471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Y18S_oRsP4jdONhfhNwAAAGw"]
[Mon Jul 20 06:47:19.424073 2026] [security2:error] [pid 1020501:tid 1020651] [client 34.73.38.214:52565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y18S_oRsP4jdONhfhQQAAABI"]
[Mon Jul 20 06:47:19.487743 2026] [security2:error] [pid 1020501:tid 1020712] [client 104.234.53.79:43639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Y18S_oRsP4jdONhfhPgAAAE8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:19.503769 2026] [security2:error] [pid 1014214:tid 1014404] [client 111.93.61.179:33396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aviationsynergy.aero"] [uri "/wp-login.php"] [unique_id "al4Y1wuRBFTcQNywdCIrTwABy38"]
[Mon Jul 20 06:47:19.540435 2026] [security2:error] [pid 1014214:tid 1014386] [client 57.141.18.90:63344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y0QuRBFTcQNywdCIqYgABuTQ"]
[Mon Jul 20 06:47:19.553512 2026] [security2:error] [pid 1014214:tid 1014368] [client 14.225.17.146:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4Y1guRBFTcQNywdCIrJQAAAac"], referer: http://betterbonddogtraining.com/New
[Mon Jul 20 06:47:19.599858 2026] [security2:error] [pid 1014214:tid 1014419] [client 187.108.85.186:61025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1wuRBFTcQNywdCIrVAAAAdo"]
[Mon Jul 20 06:47:19.599987 2026] [security2:error] [pid 1014214:tid 1014419] [client 187.108.85.186:61025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y1wuRBFTcQNywdCIrVAAAAdo"]
[Mon Jul 20 06:47:19.739997 2026] [security2:error] [pid 1020501:tid 1020667] [client 113.160.97.242:50467] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Y18S_oRsP4jdONhfhUQAAACI"]
[Mon Jul 20 06:47:19.905195 2026] [security2:error] [pid 1020501:tid 1020730] [client 34.73.38.214:49470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.latiendadejorge.com.gt"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Y18S_oRsP4jdONhfhXgAAAGE"]
[Mon Jul 20 06:47:19.917769 2026] [security2:error] [pid 1020501:tid 1020646] [client 14.225.17.146:54090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4Y18S_oRsP4jdONhfhWQAAAA0"], referer: http://katsklar.com/New
[Mon Jul 20 06:47:19.967545 2026] [security2:error] [pid 1020501:tid 1020760] [client 34.73.38.214:50020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Y18S_oRsP4jdONhfhZQAAAH8"]
[Mon Jul 20 06:47:20.241178 2026] [security2:error] [pid 1020501:tid 1020717] [client 74.7.227.179:33246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Y2MS_oRsP4jdONhfhdwAAVAw"], referer: https://tejasenvironmental.com/p=2765611
[Mon Jul 20 06:47:20.426032 2026] [security2:error] [pid 1020501:tid 1020662] [client 57.141.18.30:51562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y0sS_oRsP4jdONhfgUwAAHUg"]
[Mon Jul 20 06:47:20.513112 2026] [security2:error] [pid 1014214:tid 1014470] [client 103.125.179.95:59335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2AuRBFTcQNywdCIreAAAAg0"]
[Mon Jul 20 06:47:20.513210 2026] [security2:error] [pid 1014214:tid 1014470] [client 103.125.179.95:59335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2AuRBFTcQNywdCIreAAAAg0"]
[Mon Jul 20 06:47:20.554311 2026] [security2:error] [pid 1020501:tid 1020524] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2MS_oRsP4jdONhfhiQAASxQ"]
[Mon Jul 20 06:47:20.554439 2026] [security2:error] [pid 1020501:tid 1020708] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2MS_oRsP4jdONhfhiQAASxQ"]
[Mon Jul 20 06:47:20.665916 2026] [security2:error] [pid 1020501:tid 1020637] [client 157.85.211.87:24681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2MS_oRsP4jdONhfhjQAAAAQ"]
[Mon Jul 20 06:47:20.666046 2026] [security2:error] [pid 1020501:tid 1020637] [client 157.85.211.87:24681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2MS_oRsP4jdONhfhjQAAAAQ"]
[Mon Jul 20 06:47:20.776209 2026] [security2:error] [pid 1020501:tid 1020680] [client 34.73.38.214:53339] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Y2MS_oRsP4jdONhfhlwAAAC8"]
[Mon Jul 20 06:47:20.805477 2026] [security2:error] [pid 1020501:tid 1020727] [client 104.234.53.79:43639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y2MS_oRsP4jdONhfhmQAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:20.968646 2026] [security2:error] [pid 1020501:tid 1020530] [remote 113.160.142.119:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4Y2MS_oRsP4jdONhfhpQAAURo"]
[Mon Jul 20 06:47:20.984527 2026] [security2:error] [pid 1020501:tid 1020676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y2MS_oRsP4jdONhfhiwAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:21.144821 2026] [security2:error] [pid 1020501:tid 1020508] [remote 152.228.213.32:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y2cS_oRsP4jdONhfhrgAAEwQ"]
[Mon Jul 20 06:47:21.253462 2026] [security2:error] [pid 1020501:tid 1020684] [client 57.141.18.57:22718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y08S_oRsP4jdONhfgcAAAMz4"]
[Mon Jul 20 06:47:21.266428 2026] [security2:error] [pid 1020501:tid 1020647] [client 14.225.17.146:53129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Y2MS_oRsP4jdONhfhjAAAAA4"], referer: http://alaraycreative.com/New
[Mon Jul 20 06:47:21.351608 2026] [security2:error] [pid 1020501:tid 1020536] [remote 152.228.213.32:38816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y2cS_oRsP4jdONhfhtwAALSA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:47:21.389808 2026] [security2:error] [pid 1014214:tid 1014335] [remote 216.73.216.55:17770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4Y2QuRBFTcQNywdCIrmQABsng"]
[Mon Jul 20 06:47:21.469372 2026] [security2:error] [pid 1020501:tid 1020538] [remote 113.160.142.119:49484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4Y2cS_oRsP4jdONhfhvAAAIiI"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 06:47:21.475533 2026] [security2:error] [pid 1020501:tid 1020714] [client 52.109.68.130:14144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Y2cS_oRsP4jdONhfhvwAAAFE"]
[Mon Jul 20 06:47:21.521871 2026] [security2:error] [pid 1020501:tid 1020513] [remote 188.166.241.141:53104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4Y2cS_oRsP4jdONhfhwgAAfQk"]
[Mon Jul 20 06:47:21.552896 2026] [security2:error] [pid 1020501:tid 1020688] [client 57.141.18.101:62224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y08S_oRsP4jdONhfgegAAN1k"]
[Mon Jul 20 06:47:21.632570 2026] [security2:error] [pid 1020501:tid 1020685] [client 52.109.68.130:14144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Y2cS_oRsP4jdONhfhxQAAADQ"]
[Mon Jul 20 06:47:21.785363 2026] [security2:error] [pid 1020501:tid 1020689] [client 34.73.38.214:60025] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Y2cS_oRsP4jdONhfhxwAAADg"]
[Mon Jul 20 06:47:21.794285 2026] [security2:error] [pid 1020501:tid 1020751] [client 14.225.17.146:52511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Y2cS_oRsP4jdONhfhqgAAAHY"], referer: http://healthylifegourmet.org/New
[Mon Jul 20 06:47:21.888791 2026] [security2:error] [pid 1020501:tid 1020539] [remote 188.166.241.141:53104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4Y2cS_oRsP4jdONhfhywAAZSM"], referer: https://allergyantidotes.com/wp-login.php
[Mon Jul 20 06:47:21.966385 2026] [security2:error] [pid 1020501:tid 1020662] [client 52.111.227.28:21249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Y2cS_oRsP4jdONhfh0QAAAB0"]
[Mon Jul 20 06:47:21.990008 2026] [access_compat:error] [pid 1020501:tid 1020543] [remote 34.228.112.96:49190] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 06:47:22.019923 2026] [security2:error] [pid 1020501:tid 1020690] [client 52.111.227.28:21249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Y2sS_oRsP4jdONhfh1AAAADk"]
[Mon Jul 20 06:47:22.138295 2026] [security2:error] [pid 1020501:tid 1020675] [client 34.73.38.214:60929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Y2sS_oRsP4jdONhfh1wAAACo"]
[Mon Jul 20 06:47:22.272213 2026] [security2:error] [pid 1020501:tid 1020687] [client 104.234.53.78:44943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Y2sS_oRsP4jdONhfh2AAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:22.276086 2026] [security2:error] [pid 1020501:tid 1020669] [client 158.173.89.95:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Y2sS_oRsP4jdONhfh2gAAACQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:47:22.610013 2026] [security2:error] [pid 1020501:tid 1020736] [client 14.225.17.146:62431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4Y2cS_oRsP4jdONhfhxAAAAGc"], referer: http://entuvy.com/New
[Mon Jul 20 06:47:22.802976 2026] [security2:error] [pid 1014214:tid 1014451] [client 57.141.18.45:35452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y1QuRBFTcQNywdCIq7AAB-nI"]
[Mon Jul 20 06:47:23.075234 2026] [security2:error] [pid 1020501:tid 1020691] [client 57.141.18.86:33358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y1cS_oRsP4jdONhfg1QAAOm0"]
[Mon Jul 20 06:47:23.118400 2026] [security2:error] [pid 1020501:tid 1020649] [client 34.73.38.214:52939] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Y28S_oRsP4jdONhfiBwAAABA"]
[Mon Jul 20 06:47:23.239114 2026] [security2:error] [pid 1020501:tid 1020700] [client 223.185.13.213:13231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y28S_oRsP4jdONhfiCgAAAEM"]
[Mon Jul 20 06:47:23.239203 2026] [security2:error] [pid 1020501:tid 1020700] [client 223.185.13.213:13231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y28S_oRsP4jdONhfiCgAAAEM"]
[Mon Jul 20 06:47:23.446481 2026] [security2:error] [pid 1020501:tid 1020748] [client 34.73.38.214:60013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Y28S_oRsP4jdONhfiEAAAAHM"]
[Mon Jul 20 06:47:23.732962 2026] [core:error] [pid 1020501:tid 1020731] [client 103.153.183.69:39924] AH10244: invalid URI path (/../../../../etc/passwd?_=z89vmopa&v=2ben1), referer: https://www.google.com/search?q=btnurp
[Mon Jul 20 06:47:23.735467 2026] [security2:error] [pid 1014214:tid 1014459] [client 127.0.0.1:41088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4Y2wuRBFTcQNywdCIr8wAAAgI"], referer: https://www.google.com/search?q=btnurp
[Mon Jul 20 06:47:23.834021 2026] [security2:error] [pid 1014214:tid 1014409] [client 34.73.38.214:65027] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Y2wuRBFTcQNywdCIr9QAAAdA"]
[Mon Jul 20 06:47:23.840661 2026] [security2:error] [pid 1020501:tid 1020661] [client 57.141.18.28:29262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y1sS_oRsP4jdONhfhAQAAHFI"]
[Mon Jul 20 06:47:23.876071 2026] [security2:error] [pid 1014214:tid 1014388] [client 117.247.108.24:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2wuRBFTcQNywdCIr9wAAAbs"]
[Mon Jul 20 06:47:23.876164 2026] [security2:error] [pid 1014214:tid 1014388] [client 117.247.108.24:65322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y2wuRBFTcQNywdCIr9wAAAbs"]
[Mon Jul 20 06:47:23.974280 2026] [security2:error] [pid 1020501:tid 1020715] [client 37.52.210.45:59377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y28S_oRsP4jdONhfiKQAAAFI"]
[Mon Jul 20 06:47:23.974359 2026] [security2:error] [pid 1020501:tid 1020715] [client 37.52.210.45:59377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y28S_oRsP4jdONhfiKQAAAFI"]
[Mon Jul 20 06:47:24.014613 2026] [security2:error] [pid 1020501:tid 1020686] [client 14.225.17.146:50864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4Y2sS_oRsP4jdONhfh9wAAADU"], referer: http://hammadownenterprises.com/New
[Mon Jul 20 06:47:24.070692 2026] [security2:error] [pid 1014214:tid 1014467] [client 77.110.127.138:55873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y3AuRBFTcQNywdCIr_wAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:24.070852 2026] [security2:error] [pid 1014214:tid 1014467] [client 77.110.127.138:55873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y3AuRBFTcQNywdCIr_wAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:24.307955 2026] [security2:error] [pid 1020501:tid 1020692] [client 57.141.18.9:30528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y1sS_oRsP4jdONhfhKgAAO34"]
[Mon Jul 20 06:47:24.428232 2026] [security2:error] [pid 1014214:tid 1014373] [client 14.225.17.146:55906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4Y3AuRBFTcQNywdCIsBgAAAaw"]
[Mon Jul 20 06:47:24.631535 2026] [security2:error] [pid 1014214:tid 1014360] [client 34.73.38.214:62534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Y3AuRBFTcQNywdCIsEwAAAZ8"]
[Mon Jul 20 06:47:24.783177 2026] [security2:error] [pid 1020501:tid 1020745] [client 104.234.53.79:57625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Y3MS_oRsP4jdONhfiTwAAAHA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:24.952589 2026] [security2:error] [pid 1020501:tid 1020649] [client 104.234.53.79:57625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y3MS_oRsP4jdONhfiVgAAABA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:25.251625 2026] [security2:error] [pid 1020501:tid 1020641] [client 57.141.18.18:44838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y18S_oRsP4jdONhfhWgAACAE"]
[Mon Jul 20 06:47:25.402728 2026] [security2:error] [pid 1014214:tid 1014435] [client 57.141.18.107:33180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y2AuRBFTcQNywdCIraAAB6hs"]
[Mon Jul 20 06:47:25.453145 2026] [security2:error] [pid 1020501:tid 1020660] [client 14.251.3.155:54705] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Y3cS_oRsP4jdONhfiawAAABs"]
[Mon Jul 20 06:47:25.474176 2026] [security2:error] [pid 1020501:tid 1020681] [client 57.141.18.15:38582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y2MS_oRsP4jdONhfhbAAAMA4"]
[Mon Jul 20 06:47:25.642083 2026] [security2:error] [pid 1014214:tid 1014436] [client 34.73.38.214:59405] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Y3QuRBFTcQNywdCIsnwAAAes"]
[Mon Jul 20 06:47:25.773923 2026] [security2:error] [pid 1020501:tid 1020662] [client 14.225.17.146:51124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4Y28S_oRsP4jdONhfiIAAAAB0"], referer: http://narv.co/New
[Mon Jul 20 06:47:25.853847 2026] [security2:error] [pid 1020501:tid 1020656] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y3cS_oRsP4jdONhfiZQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:25.874003 2026] [security2:error] [pid 1014214:tid 1014357] [client 74.208.214.194:33786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Y3QuRBFTcQNywdCIstQAAAZw"]
[Mon Jul 20 06:47:26.017402 2026] [security2:error] [pid 1020501:tid 1020575] [remote 144.79.133.30:33256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4Y3sS_oRsP4jdONhfigQAAf0c"]
[Mon Jul 20 06:47:26.071894 2026] [security2:error] [pid 1014214:tid 1014350] [client 52.109.68.130:14657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Y3guRBFTcQNywdCIswgAAAZU"]
[Mon Jul 20 06:47:26.140523 2026] [security2:error] [pid 1020501:tid 1020701] [client 173.252.95.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4Y3cS_oRsP4jdONhfiZAAAAEQ"]
[Mon Jul 20 06:47:26.162306 2026] [security2:error] [pid 1020501:tid 1020671] [client 14.225.17.146:61382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4Y3MS_oRsP4jdONhfiPgAAACY"], referer: http://windowtx.com/New
[Mon Jul 20 06:47:26.229642 2026] [security2:error] [pid 1014214:tid 1014428] [client 52.109.68.130:14657] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Y3guRBFTcQNywdCIsxgAAAeM"]
[Mon Jul 20 06:47:26.326397 2026] [security2:error] [pid 1014214:tid 1014467] [client 34.73.38.214:65445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.lgi.ful.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Y3guRBFTcQNywdCIsygAAAgo"]
[Mon Jul 20 06:47:26.803530 2026] [security2:error] [pid 1020501:tid 1020650] [client 39.48.81.23:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y3sS_oRsP4jdONhfiqwAAABE"]
[Mon Jul 20 06:47:26.803702 2026] [security2:error] [pid 1020501:tid 1020650] [client 39.48.81.23:63568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y3sS_oRsP4jdONhfiqwAAABE"]
[Mon Jul 20 06:47:26.839450 2026] [fcgid:warn] [pid 1020501:tid 1020714] (70014)End of file found: [client 199.45.155.101:42552] mod_fcgid: can't get data from http client
[Mon Jul 20 06:47:26.928392 2026] [security2:error] [pid 1014214:tid 1014413] [client 14.225.17.146:52616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4Y3guRBFTcQNywdCIs3gAAAdQ"], referer: https://narv.co/New
[Mon Jul 20 06:47:26.938510 2026] [security2:error] [pid 1020501:tid 1020730] [client 112.208.70.94:42927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y3sS_oRsP4jdONhfitQAAAGE"]
[Mon Jul 20 06:47:26.938618 2026] [security2:error] [pid 1020501:tid 1020730] [client 112.208.70.94:42927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y3sS_oRsP4jdONhfitQAAAGE"]
[Mon Jul 20 06:47:27.062202 2026] [fcgid:warn] [pid 1020501:tid 1020731] (70014)End of file found: [client 167.94.146.55:28358] mod_fcgid: can't get data from http client
[Mon Jul 20 06:47:27.160205 2026] [security2:error] [pid 1020501:tid 1020694] [client 100.31.58.60:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.58.31.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Y38S_oRsP4jdONhfivwAAAD0"]
[Mon Jul 20 06:47:27.405688 2026] [core:error] [pid 1014214:tid 1014430] [client 159.203.27.249:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:47:27.405710 2026] [core:error] [pid 1014214:tid 1014430] [client 159.203.27.249:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:47:27.550638 2026] [security2:error] [pid 1020501:tid 1020594] [remote 144.79.133.30:33256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4Y38S_oRsP4jdONhfi2gAAdFo"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:47:27.559846 2026] [security2:error] [pid 1020501:tid 1020753] [client 36.95.228.227:52219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y38S_oRsP4jdONhfi2wAAAHg"]
[Mon Jul 20 06:47:27.559958 2026] [security2:error] [pid 1020501:tid 1020753] [client 36.95.228.227:52219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y38S_oRsP4jdONhfi2wAAAHg"]
[Mon Jul 20 06:47:27.575247 2026] [security2:error] [pid 1014214:tid 1014358] [client 57.141.18.66:46412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y2guRBFTcQNywdCIrswABnVo"]
[Mon Jul 20 06:47:27.632563 2026] [security2:error] [pid 1020501:tid 1020726] [client 50.116.65.227:16516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Y38S_oRsP4jdONhfi3gAAAF0"]
[Mon Jul 20 06:47:27.642888 2026] [security2:error] [pid 1020501:tid 1020722] [client 50.116.65.227:16518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Y38S_oRsP4jdONhfi3wAAAFk"]
[Mon Jul 20 06:47:27.659277 2026] [security2:error] [pid 1020501:tid 1020735] [client 3.85.28.216:35296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Y38S_oRsP4jdONhfi3QAAAGY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:47:27.688800 2026] [security2:error] [pid 1020501:tid 1020643] [client 14.225.17.146:52554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4Y3sS_oRsP4jdONhfilwAAAAo"], referer: http://ravmike.com/New
[Mon Jul 20 06:47:27.735395 2026] [cgid:error] [pid 1020501:tid 1020739] [client 199.45.154.141:49502] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: http://website-fa490990.threethirds.co:80/cgi-bin
[Mon Jul 20 06:47:28.103285 2026] [security2:error] [pid 1020501:tid 1020645] [client 122.183.32.225:25456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y4MS_oRsP4jdONhfi7AAAAAw"]
[Mon Jul 20 06:47:28.103435 2026] [security2:error] [pid 1020501:tid 1020645] [client 122.183.32.225:25456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y4MS_oRsP4jdONhfi7AAAAAw"]
[Mon Jul 20 06:47:28.103856 2026] [security2:error] [pid 1014214:tid 1014394] [client 197.186.66.42:52177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y4AuRBFTcQNywdCItHgAAAcE"]
[Mon Jul 20 06:47:28.103997 2026] [security2:error] [pid 1014214:tid 1014394] [client 197.186.66.42:52177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y4AuRBFTcQNywdCItHgAAAcE"]
[Mon Jul 20 06:47:28.206201 2026] [security2:error] [pid 1014214:tid 1014389] [client 103.238.106.162:60990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y4AuRBFTcQNywdCItJgAAAbw"]
[Mon Jul 20 06:47:28.206360 2026] [security2:error] [pid 1014214:tid 1014389] [client 103.238.106.162:60990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y4AuRBFTcQNywdCItJgAAAbw"]
[Mon Jul 20 06:47:28.427958 2026] [security2:error] [pid 1014214:tid 1014468] [client 57.141.18.57:46290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y2wuRBFTcQNywdCIr2wACCwg"]
[Mon Jul 20 06:47:28.565683 2026] [security2:error] [pid 1014214:tid 1014385] [client 147.182.149.91:51302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4Y4AuRBFTcQNywdCItPgAAAbg"]
[Mon Jul 20 06:47:28.784998 2026] [security2:error] [pid 1014214:tid 1014370] [client 77.110.127.138:55931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y4AuRBFTcQNywdCItSAAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:28.785141 2026] [security2:error] [pid 1014214:tid 1014370] [client 77.110.127.138:55931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y4AuRBFTcQNywdCItSAAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:28.888869 2026] [security2:error] [pid 1020501:tid 1020732] [client 147.182.149.91:51399] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.roguedragonstudio.com"] [uri "/wp-login.php"] [unique_id "al4Y4MS_oRsP4jdONhfjEAAAAGM"]
[Mon Jul 20 06:47:28.935791 2026] [security2:error] [pid 1014214:tid 1014467] [client 14.225.17.146:55849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Y4AuRBFTcQNywdCItRwAAAgo"], referer: http://fkconstructionfunding.com/New
[Mon Jul 20 06:47:28.950374 2026] [security2:error] [pid 1020501:tid 1020709] [client 14.225.17.146:55512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4Y4MS_oRsP4jdONhfi9AAAAEw"], referer: http://onewingpictures.com/New
[Mon Jul 20 06:47:29.072679 2026] [security2:error] [pid 1014214:tid 1014459] [client 217.142.18.172:46869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y4QuRBFTcQNywdCItVwAAAgI"]
[Mon Jul 20 06:47:29.075699 2026] [security2:error] [pid 1014214:tid 1014459] [client 217.142.18.172:46869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y4QuRBFTcQNywdCItVwAAAgI"]
[Mon Jul 20 06:47:29.105166 2026] [security2:error] [pid 1014214:tid 1014442] [client 57.141.18.55:55096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y2wuRBFTcQNywdCIr_AAB8UQ"]
[Mon Jul 20 06:47:29.504464 2026] [security2:error] [pid 1020501:tid 1020602] [remote 5.161.225.162:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4Y4cS_oRsP4jdONhfjJgAAI2I"]
[Mon Jul 20 06:47:29.752991 2026] [security2:error] [pid 1020501:tid 1020648] [client 14.225.17.146:61571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4Y38S_oRsP4jdONhfiwwAAAA8"], referer: http://bruceledewitz.com/New
[Mon Jul 20 06:47:29.753544 2026] [security2:error] [pid 1020501:tid 1020617] [remote 5.161.225.162:42976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4Y4cS_oRsP4jdONhfjOAAAYHE"], referer: https://travelbyfire.com/wp-login.php
[Mon Jul 20 06:47:29.852291 2026] [security2:error] [pid 1020501:tid 1020678] [client 14.225.17.146:55524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Y4cS_oRsP4jdONhfjOgAAAC0"], referer: http://friendlyspreadsheet.com/New
[Mon Jul 20 06:47:30.066236 2026] [security2:error] [pid 1020501:tid 1020597] [remote 217.182.128.41:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4Y4sS_oRsP4jdONhfjVwAAE10"]
[Mon Jul 20 06:47:30.111133 2026] [security2:error] [pid 1020501:tid 1020644] [client 57.141.18.29:55886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y3MS_oRsP4jdONhfiVAAACzs"]
[Mon Jul 20 06:47:30.147985 2026] [security2:error] [pid 1020501:tid 1020748] [client 14.225.17.146:61421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4Y38S_oRsP4jdONhfi5QAAAHM"], referer: http://mrbambooplus.com/New
[Mon Jul 20 06:47:30.176129 2026] [security2:error] [pid 1020501:tid 1020731] [client 187.108.85.186:61572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y4sS_oRsP4jdONhfjYAAAAGI"]
[Mon Jul 20 06:47:30.176239 2026] [security2:error] [pid 1020501:tid 1020731] [client 187.108.85.186:61572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y4sS_oRsP4jdONhfjYAAAAGI"]
[Mon Jul 20 06:47:30.279286 2026] [security2:error] [pid 1020501:tid 1020514] [remote 217.182.128.41:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4Y4sS_oRsP4jdONhfjcAAAbAo"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:47:30.330432 2026] [security2:error] [pid 1020501:tid 1020609] [remote 51.195.39.149:43487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "avatrip.co"] [uri "/"] [unique_id "al4Y4sS_oRsP4jdONhfjfAAAWGk"]
[Mon Jul 20 06:47:30.345679 2026] [security2:error] [pid 1020501:tid 1020685] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y4sS_oRsP4jdONhfjXAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:30.602149 2026] [security2:error] [pid 1020501:tid 1020527] [remote 152.228.213.32:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Y4sS_oRsP4jdONhfjnwAAUBc"]
[Mon Jul 20 06:47:30.791482 2026] [security2:error] [pid 1020501:tid 1020543] [remote 152.228.213.32:32916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Y4sS_oRsP4jdONhfjswAAOSc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:47:31.018835 2026] [security2:error] [pid 1020501:tid 1020531] [remote 84.247.172.23:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Y48S_oRsP4jdONhfj0AAAVBs"]
[Mon Jul 20 06:47:31.168665 2026] [security2:error] [pid 1020501:tid 1020696] [client 103.125.179.95:59842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y48S_oRsP4jdONhfkGAAAAD8"]
[Mon Jul 20 06:47:31.168955 2026] [security2:error] [pid 1020501:tid 1020696] [client 103.125.179.95:59842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y48S_oRsP4jdONhfkGAAAAD8"]
[Mon Jul 20 06:47:31.197984 2026] [security2:error] [pid 1020501:tid 1020749] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y4sS_oRsP4jdONhfjygAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:31.252960 2026] [security2:error] [pid 1020501:tid 1020540] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y48S_oRsP4jdONhfkKgAAXSQ"]
[Mon Jul 20 06:47:31.253124 2026] [security2:error] [pid 1020501:tid 1020726] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y48S_oRsP4jdONhfkKgAAXSQ"]
[Mon Jul 20 06:47:31.443305 2026] [security2:error] [pid 1020501:tid 1020587] [remote 84.247.172.23:47648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4Y48S_oRsP4jdONhfkOwAAD1M"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:47:31.667992 2026] [security2:error] [pid 1020501:tid 1020687] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y48S_oRsP4jdONhfkPAAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:32.052872 2026] [security2:error] [pid 1020501:tid 1020669] [client 57.141.18.67:60054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y3sS_oRsP4jdONhfioQAAJE4"]
[Mon Jul 20 06:47:32.110841 2026] [security2:error] [pid 1020501:tid 1020664] [client 57.141.18.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Y48S_oRsP4jdONhfkbAAAAB8"]
[Mon Jul 20 06:47:32.146936 2026] [security2:error] [pid 1020501:tid 1020682] [client 199.45.155.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.cathybuffini.com"] [uri "/index.php"] [unique_id "al4Y5MS_oRsP4jdONhfkewAAADE"]
[Mon Jul 20 06:47:32.168494 2026] [security2:error] [pid 1020501:tid 1020760] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y48S_oRsP4jdONhfkawAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:32.262091 2026] [security2:error] [pid 1020501:tid 1020638] [client 57.141.18.66:46416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y3sS_oRsP4jdONhfitwAABU0"]
[Mon Jul 20 06:47:32.298634 2026] [security2:error] [pid 1020501:tid 1020643] [client 77.110.127.138:55975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y5MS_oRsP4jdONhfkhQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:32.298711 2026] [security2:error] [pid 1020501:tid 1020643] [client 77.110.127.138:55975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y5MS_oRsP4jdONhfkhQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:32.450942 2026] [security2:error] [pid 1020501:tid 1020635] [client 77.110.127.138:55982] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Y5MS_oRsP4jdONhfkmAAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:32.526891 2026] [security2:error] [pid 1020501:tid 1020626] [remote 217.61.143.92:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Y5MS_oRsP4jdONhfknAAAJ3o"]
[Mon Jul 20 06:47:32.616390 2026] [security2:error] [pid 1020501:tid 1020753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y5MS_oRsP4jdONhfklgAAAHg"]
[Mon Jul 20 06:47:32.636344 2026] [security2:error] [pid 1020501:tid 1020636] [client 183.82.98.154:51949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Y5MS_oRsP4jdONhfkogAAAAM"]
[Mon Jul 20 06:47:32.636443 2026] [security2:error] [pid 1020501:tid 1020636] [client 183.82.98.154:51949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Y5MS_oRsP4jdONhfkogAAAAM"]
[Mon Jul 20 06:47:32.752077 2026] [security2:error] [pid 1020501:tid 1020563] [remote 217.61.143.92:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Y5MS_oRsP4jdONhfkqgAAQzs"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:47:32.753200 2026] [security2:error] [pid 1014214:tid 1014286] [remote 57.141.18.109:38866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y3wuRBFTcQNywdCIs-AABlUc"]
[Mon Jul 20 06:47:32.953342 2026] [autoindex:error] [pid 1020501:tid 1020754] [client 195.96.139.224:52331] AH01276: Cannot serve directory /home2/cxrmhtmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:47:33.032906 2026] [security2:error] [pid 1020501:tid 1020634] [client 45.157.112.60:29421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Y5cS_oRsP4jdONhfkwAAAAAE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:47:33.131493 2026] [security2:error] [pid 1020501:tid 1020661] [client 74.208.214.194:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Y5cS_oRsP4jdONhfkxAAAABw"]
[Mon Jul 20 06:47:33.279057 2026] [security2:error] [pid 1014214:tid 1014334] [remote 57.141.18.29:55902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y4AuRBFTcQNywdCItJAAB93c"]
[Mon Jul 20 06:47:33.388164 2026] [security2:error] [pid 1020501:tid 1020512] [remote 130.185.118.215:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y5cS_oRsP4jdONhfk1wAAVAg"]
[Mon Jul 20 06:47:33.496864 2026] [security2:error] [pid 1020501:tid 1020638] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y5cS_oRsP4jdONhfkzwAAAAU"]
[Mon Jul 20 06:47:33.503003 2026] [security2:error] [pid 1020501:tid 1020670] [client 57.141.18.65:29642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y4MS_oRsP4jdONhfi9QAAJVU"]
[Mon Jul 20 06:47:33.584338 2026] [security2:error] [pid 1020501:tid 1020507] [remote 130.185.118.215:37386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y5cS_oRsP4jdONhfk5AAAMAM"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:47:33.785700 2026] [security2:error] [pid 1014214:tid 1014331] [remote 57.141.18.124:60022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y4AuRBFTcQNywdCItQwABrnQ"]
[Mon Jul 20 06:47:33.953173 2026] [security2:error] [pid 1020501:tid 1020724] [client 14.225.17.146:52130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4Y5MS_oRsP4jdONhfkfwAAAFs"], referer: http://ccsdifference.com/New
[Mon Jul 20 06:47:34.078443 2026] [security2:error] [pid 1020501:tid 1020693] [client 14.225.17.146:52105] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4Y5cS_oRsP4jdONhflCgAAADw"], referer: http://phillipbloch.com/New
[Mon Jul 20 06:47:34.178538 2026] [security2:error] [pid 1020501:tid 1020542] [remote 182.77.62.24:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4Y5sS_oRsP4jdONhflFwAAQSY"]
[Mon Jul 20 06:47:34.460475 2026] [security2:error] [pid 1020501:tid 1020748] [client 157.85.211.87:26866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y5sS_oRsP4jdONhflNwAAAHM"]
[Mon Jul 20 06:47:34.460584 2026] [security2:error] [pid 1020501:tid 1020748] [client 157.85.211.87:26866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y5sS_oRsP4jdONhflNwAAAHM"]
[Mon Jul 20 06:47:34.680191 2026] [security2:error] [pid 1020501:tid 1020529] [remote 182.77.62.24:56280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4Y5sS_oRsP4jdONhflPwAAThk"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 06:47:34.705610 2026] [security2:error] [pid 1020501:tid 1020639] [client 37.52.210.45:61276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y5sS_oRsP4jdONhflQAAAAAY"]
[Mon Jul 20 06:47:34.705781 2026] [security2:error] [pid 1020501:tid 1020639] [client 37.52.210.45:61276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y5sS_oRsP4jdONhflQAAAAAY"]
[Mon Jul 20 06:47:34.722296 2026] [security2:error] [pid 1020501:tid 1020646] [client 117.247.108.24:330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y5sS_oRsP4jdONhflQQAAAA0"]
[Mon Jul 20 06:47:34.722397 2026] [security2:error] [pid 1020501:tid 1020646] [client 117.247.108.24:330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y5sS_oRsP4jdONhflQQAAAA0"]
[Mon Jul 20 06:47:34.746034 2026] [security2:error] [pid 1020501:tid 1020743] [client 57.141.18.55:34096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y4cS_oRsP4jdONhfjMAAAbmc"]
[Mon Jul 20 06:47:34.821396 2026] [core:error] [pid 1020501:tid 1020642] [client 103.153.183.69:63454] AH10244: invalid URI path (/../../.env?_=0whmwsc4&v=oprbb), referer: https://duckduckgo.com/?q=s02gf
[Mon Jul 20 06:47:35.678921 2026] [security2:error] [pid 1020501:tid 1020738] [client 57.141.18.82:25512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y4sS_oRsP4jdONhfjowAAaT4"]
[Mon Jul 20 06:47:36.000919 2026] [security2:error] [pid 1020501:tid 1020598] [remote 91.134.248.230:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.248.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y58S_oRsP4jdONhflmwAAK14"]
[Mon Jul 20 06:47:36.109591 2026] [security2:error] [pid 1020501:tid 1020733] [client 77.110.127.138:56025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y6MS_oRsP4jdONhflqQAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:36.109673 2026] [security2:error] [pid 1020501:tid 1020733] [client 77.110.127.138:56025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y6MS_oRsP4jdONhflqQAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:36.171768 2026] [security2:error] [pid 1020501:tid 1020602] [remote 91.134.248.230:59944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.248.134.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y6MS_oRsP4jdONhflrQAAQWI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:47:36.275410 2026] [security2:error] [pid 1020501:tid 1020701] [client 77.110.127.138:56033] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Y6MS_oRsP4jdONhflswAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:36.386726 2026] [security2:error] [pid 1020501:tid 1020662] [client 57.141.18.53:30166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y48S_oRsP4jdONhfkMgAAHVo"]
[Mon Jul 20 06:47:36.498865 2026] [security2:error] [pid 1020501:tid 1020671] [client 14.225.17.146:57066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4Y58S_oRsP4jdONhflaQAAACY"], referer: http://mazzucelli.com/New
[Mon Jul 20 06:47:36.794096 2026] [security2:error] [pid 1020501:tid 1020654] [client 57.141.18.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Y6MS_oRsP4jdONhfl0gAAABU"]
[Mon Jul 20 06:47:37.253189 2026] [security2:error] [pid 1020501:tid 1020719] [client 14.225.17.146:52124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4Y6cS_oRsP4jdONhfl-QAAAFY"], referer: http://alrowad-hub.net/New
[Mon Jul 20 06:47:37.566196 2026] [security2:error] [pid 1020501:tid 1020534] [remote 91.142.222.105:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y6cS_oRsP4jdONhfmHwAAah4"]
[Mon Jul 20 06:47:37.601369 2026] [security2:error] [pid 1020501:tid 1020659] [client 223.185.13.213:24894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmJQAAABo"]
[Mon Jul 20 06:47:37.601489 2026] [security2:error] [pid 1020501:tid 1020659] [client 223.185.13.213:24894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmJQAAABo"]
[Mon Jul 20 06:47:37.614796 2026] [security2:error] [pid 1020501:tid 1020637] [client 122.183.32.225:20241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmKAAAAAQ"]
[Mon Jul 20 06:47:37.614898 2026] [security2:error] [pid 1020501:tid 1020637] [client 122.183.32.225:20241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmKAAAAAQ"]
[Mon Jul 20 06:47:37.632992 2026] [security2:error] [pid 1020501:tid 1020669] [client 112.208.70.94:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmIQAAACQ"]
[Mon Jul 20 06:47:37.633137 2026] [security2:error] [pid 1020501:tid 1020669] [client 112.208.70.94:43364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmIQAAACQ"]
[Mon Jul 20 06:47:37.637603 2026] [security2:error] [pid 1020501:tid 1020650] [client 39.48.81.23:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmLAAAABE"]
[Mon Jul 20 06:47:37.637721 2026] [security2:error] [pid 1020501:tid 1020650] [client 39.48.81.23:64093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6cS_oRsP4jdONhfmLAAAABE"]
[Mon Jul 20 06:47:37.777544 2026] [security2:error] [pid 1020501:tid 1020728] [client 14.225.17.146:61921] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4Y6MS_oRsP4jdONhflsAAAAF8"], referer: http://careysheatingandcooling.com/New
[Mon Jul 20 06:47:37.781857 2026] [security2:error] [pid 1020501:tid 1020593] [remote 100.42.189.89:33582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y6cS_oRsP4jdONhfmNAAARlk"]
[Mon Jul 20 06:47:37.791968 2026] [security2:error] [pid 1020501:tid 1020725] [client 57.141.18.81:24762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y5MS_oRsP4jdONhfktgAAXHY"]
[Mon Jul 20 06:47:37.829184 2026] [security2:error] [pid 1020501:tid 1020649] [client 65.111.3.236:24953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y6cS_oRsP4jdONhfmNQAAABA"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:37.849562 2026] [security2:error] [pid 1020501:tid 1020510] [remote 91.142.222.105:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y6cS_oRsP4jdONhfmOwAAUwY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:47:37.974505 2026] [security2:error] [pid 1020501:tid 1020572] [remote 100.42.189.89:33582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y6cS_oRsP4jdONhfmRAAAcEQ"], referer: https://mail.fvx.wyy.mybluehost.me/wp-login.php
[Mon Jul 20 06:47:38.040817 2026] [security2:error] [pid 1020501:tid 1020759] [client 192.140.149.97:44988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6sS_oRsP4jdONhfmSwAAAH4"]
[Mon Jul 20 06:47:38.040917 2026] [security2:error] [pid 1020501:tid 1020759] [client 192.140.149.97:44988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6sS_oRsP4jdONhfmSwAAAH4"]
[Mon Jul 20 06:47:38.087780 2026] [security2:error] [pid 1020501:tid 1020755] [client 36.95.228.227:52682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6sS_oRsP4jdONhfmTgAAAHo"]
[Mon Jul 20 06:47:38.087923 2026] [security2:error] [pid 1020501:tid 1020755] [client 36.95.228.227:52682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y6sS_oRsP4jdONhfmTgAAAHo"]
[Mon Jul 20 06:47:38.140967 2026] [security2:error] [pid 1020501:tid 1020736] [client 50.116.65.227:13344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Y6sS_oRsP4jdONhfmUwAAAGc"]
[Mon Jul 20 06:47:38.149479 2026] [security2:error] [pid 1020501:tid 1020682] [client 50.116.65.227:13346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Y6sS_oRsP4jdONhfmVAAAADE"]
[Mon Jul 20 06:47:38.645076 2026] [security2:error] [pid 1020501:tid 1020648] [client 65.111.8.98:21319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y6sS_oRsP4jdONhfmdQAAAA8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:38.732173 2026] [security2:error] [pid 1020501:tid 1020672] [client 103.238.106.162:42917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y6sS_oRsP4jdONhfmfgAAACc"]
[Mon Jul 20 06:47:38.732304 2026] [security2:error] [pid 1020501:tid 1020672] [client 103.238.106.162:42917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y6sS_oRsP4jdONhfmfgAAACc"]
[Mon Jul 20 06:47:39.236412 2026] [security2:error] [pid 1020501:tid 1020643] [client 57.141.18.9:45114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y5sS_oRsP4jdONhflJwAACkw"]
[Mon Jul 20 06:47:39.380818 2026] [security2:error] [pid 1020501:tid 1020668] [client 57.141.18.80:58586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y5sS_oRsP4jdONhflNAAAIxA"]
[Mon Jul 20 06:47:39.496445 2026] [security2:error] [pid 1020501:tid 1020639] [client 104.207.38.179:47847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y68S_oRsP4jdONhfmowAAAAY"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:39.608351 2026] [security2:error] [pid 1020501:tid 1020724] [client 217.142.18.172:23094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y68S_oRsP4jdONhfmrwAAAFs"]
[Mon Jul 20 06:47:39.611760 2026] [security2:error] [pid 1020501:tid 1020724] [client 217.142.18.172:23094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y68S_oRsP4jdONhfmrwAAAFs"]
[Mon Jul 20 06:47:40.114140 2026] [security2:error] [pid 1020501:tid 1020721] [client 14.224.227.113:54707] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Y7MS_oRsP4jdONhfmzwAAAFg"]
[Mon Jul 20 06:47:40.128910 2026] [security2:error] [pid 1020501:tid 1020634] [client 57.141.18.47:34788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y58S_oRsP4jdONhflXQAAAUA"]
[Mon Jul 20 06:47:40.134024 2026] [security2:error] [pid 1020501:tid 1020643] [client 77.110.127.138:56083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y7MS_oRsP4jdONhfm0gAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:40.134117 2026] [security2:error] [pid 1020501:tid 1020643] [client 77.110.127.138:56083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y7MS_oRsP4jdONhfm0gAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:40.139920 2026] [security2:error] [pid 1020501:tid 1020730] [client 13.74.155.112:31521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Y7MS_oRsP4jdONhfm0QAAAGE"]
[Mon Jul 20 06:47:40.272157 2026] [security2:error] [pid 1020501:tid 1020700] [client 13.74.155.112:31521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Y7MS_oRsP4jdONhfm3AAAAEM"]
[Mon Jul 20 06:47:40.287371 2026] [security2:error] [pid 1020501:tid 1020731] [client 77.110.127.138:56085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Y7MS_oRsP4jdONhfm3wAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:40.296053 2026] [security2:error] [pid 1020501:tid 1020659] [client 65.111.20.214:39453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y7MS_oRsP4jdONhfm2gAAABo"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:40.702240 2026] [security2:error] [pid 1020501:tid 1020642] [client 187.108.85.186:62105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y7MS_oRsP4jdONhfnAQAAAAk"]
[Mon Jul 20 06:47:40.702355 2026] [security2:error] [pid 1020501:tid 1020642] [client 187.108.85.186:62105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y7MS_oRsP4jdONhfnAQAAAAk"]
[Mon Jul 20 06:47:40.900973 2026] [security2:error] [pid 1020501:tid 1020617] [remote 15.235.219.232:34868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.219.235.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y7MS_oRsP4jdONhfnBwAAJHE"]
[Mon Jul 20 06:47:40.901161 2026] [security2:error] [pid 1020501:tid 1020669] [client 15.235.219.232:34868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y7MS_oRsP4jdONhfnBwAAJHE"]
[Mon Jul 20 06:47:40.953699 2026] [security2:error] [pid 1020501:tid 1020599] [remote 160.187.68.132:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Y7MS_oRsP4jdONhfnEQAAHl8"]
[Mon Jul 20 06:47:41.094501 2026] [security2:error] [pid 1020501:tid 1020715] [client 176.118.193.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4Y7MS_oRsP4jdONhfnEAAAAFI"]
[Mon Jul 20 06:47:41.095514 2026] [security2:error] [pid 1020501:tid 1020667] [client 104.207.38.204:50233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y7cS_oRsP4jdONhfnGwAAACI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:41.137852 2026] [security2:error] [pid 1020501:tid 1020516] [remote 45.117.83.212:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y7cS_oRsP4jdONhfnHAAAdww"]
[Mon Jul 20 06:47:41.413666 2026] [security2:error] [pid 1020501:tid 1020656] [client 57.141.18.119:54088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y6MS_oRsP4jdONhfluAAAF2s"]
[Mon Jul 20 06:47:41.417221 2026] [security2:error] [pid 1020501:tid 1020745] [client 197.186.66.42:52925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y7cS_oRsP4jdONhfnPQAAAHA"]
[Mon Jul 20 06:47:41.417294 2026] [security2:error] [pid 1020501:tid 1020745] [client 197.186.66.42:52925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y7cS_oRsP4jdONhfnPQAAAHA"]
[Mon Jul 20 06:47:41.493783 2026] [security2:error] [pid 1020501:tid 1020536] [remote 160.187.68.132:57196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Y7cS_oRsP4jdONhfnPwAAZCA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:47:41.527193 2026] [security2:error] [pid 1020501:tid 1020620] [remote 45.117.83.212:51146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.83.117.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y7cS_oRsP4jdONhfnQQAAInQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:47:41.804952 2026] [security2:error] [pid 1020501:tid 1020757] [client 103.125.179.95:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y7cS_oRsP4jdONhfnXQAAAHw"]
[Mon Jul 20 06:47:41.805108 2026] [security2:error] [pid 1020501:tid 1020757] [client 103.125.179.95:60351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y7cS_oRsP4jdONhfnXQAAAHw"]
[Mon Jul 20 06:47:41.889345 2026] [security2:error] [pid 1020501:tid 1020652] [client 45.3.53.211:20597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y7cS_oRsP4jdONhfnYAAAABM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:42.031403 2026] [security2:error] [pid 1020501:tid 1020543] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y7sS_oRsP4jdONhfnbgAAJyc"]
[Mon Jul 20 06:47:42.031564 2026] [security2:error] [pid 1020501:tid 1020672] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y7sS_oRsP4jdONhfnbgAAJyc"]
[Mon Jul 20 06:47:42.384684 2026] [security2:error] [pid 1020501:tid 1020564] [remote 192.241.143.148:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y7sS_oRsP4jdONhfniAAALTw"]
[Mon Jul 20 06:47:42.384821 2026] [security2:error] [pid 1020501:tid 1020678] [client 192.241.143.148:56870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y7sS_oRsP4jdONhfniAAALTw"]
[Mon Jul 20 06:47:42.805372 2026] [security2:error] [pid 1020501:tid 1020760] [client 14.225.17.146:59016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4Y7cS_oRsP4jdONhfnJAAAAH8"], referer: http://transparentservices.online/New
[Mon Jul 20 06:47:42.808120 2026] [security2:error] [pid 1020501:tid 1020748] [client 47.128.111.70:41568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nikkidesigns.net"] [uri "/robots.txt"] [unique_id "al4Y7sS_oRsP4jdONhfnoQAAAHM"]
[Mon Jul 20 06:47:42.859902 2026] [proxy:error] [pid 1020501:tid 1020702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:42.859966 2026] [proxy_http:error] [pid 1020501:tid 1020702] [client 34.73.38.214:53990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:42.860415 2026] [proxy:error] [pid 1020501:tid 1020702] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:42.860442 2026] [proxy_http:error] [pid 1020501:tid 1020702] [client 34.73.38.214:53990] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:43.043633 2026] [security2:error] [pid 1020501:tid 1020657] [client 14.225.17.146:52115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4Y7sS_oRsP4jdONhfntgAAABg"], referer: http://grndl.com/New
[Mon Jul 20 06:47:43.184875 2026] [proxy:error] [pid 1020501:tid 1020751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:43.184938 2026] [proxy_http:error] [pid 1020501:tid 1020751] [client 195.96.139.190:49691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:43.185916 2026] [proxy:error] [pid 1020501:tid 1020751] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:43.185963 2026] [proxy_http:error] [pid 1020501:tid 1020751] [client 195.96.139.190:49691] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:43.326264 2026] [security2:error] [pid 1020501:tid 1020758] [client 183.82.98.154:52544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Y78S_oRsP4jdONhfn2AAAAH0"]
[Mon Jul 20 06:47:43.326402 2026] [security2:error] [pid 1020501:tid 1020758] [client 183.82.98.154:52544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Y78S_oRsP4jdONhfn2AAAAH0"]
[Mon Jul 20 06:47:43.372039 2026] [proxy:error] [pid 1020501:tid 1020739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:43.372110 2026] [proxy_http:error] [pid 1020501:tid 1020739] [client 34.73.38.214:54742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:43.372922 2026] [proxy:error] [pid 1020501:tid 1020739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:43.372963 2026] [proxy_http:error] [pid 1020501:tid 1020739] [client 34.73.38.214:54742] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:43.399100 2026] [security2:error] [pid 1020501:tid 1020709] [client 14.225.17.146:57005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4Y7cS_oRsP4jdONhfnZQAAAEw"], referer: http://guidehunting.com/New
[Mon Jul 20 06:47:44.007581 2026] [security2:error] [pid 1020501:tid 1020684] [client 57.141.18.13:38828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y6sS_oRsP4jdONhfmcgAAMzI"]
[Mon Jul 20 06:47:44.212266 2026] [proxy:error] [pid 1020501:tid 1020725] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:44.212328 2026] [proxy_http:error] [pid 1020501:tid 1020725] [client 34.73.38.214:52269] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:44.212732 2026] [proxy:error] [pid 1020501:tid 1020725] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:47:44.212765 2026] [proxy_http:error] [pid 1020501:tid 1020725] [client 34.73.38.214:52269] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:47:44.239996 2026] [security2:error] [pid 1020501:tid 1020695] [client 14.225.17.146:62896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoBgAAAD4"], referer: http://laceycaraccident.com/New
[Mon Jul 20 06:47:44.358150 2026] [security2:error] [pid 1020501:tid 1020758] [client 14.225.17.146:51564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoGQAAAH0"], referer: http://nextlvlmarketingco.com/New
[Mon Jul 20 06:47:44.475070 2026] [security2:error] [pid 1020501:tid 1020651] [client 14.225.17.146:62898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoBwAAABI"], referer: http://uritems.net/New
[Mon Jul 20 06:47:44.592824 2026] [security2:error] [pid 1020501:tid 1020707] [client 14.225.17.146:57348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoIAAAAEo"], referer: https://guidehunting.com/New
[Mon Jul 20 06:47:44.623591 2026] [security2:error] [pid 1020501:tid 1020635] [client 57.141.18.115:23306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y6sS_oRsP4jdONhfmiQAAAjA"]
[Mon Jul 20 06:47:44.829607 2026] [security2:error] [pid 1020501:tid 1020747] [client 34.73.38.214:55158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/xmlrpc.php"] [unique_id "al4Y8MS_oRsP4jdONhfoTgAAAHI"]
[Mon Jul 20 06:47:44.881559 2026] [security2:error] [pid 1020501:tid 1020751] [client 77.110.127.138:56146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y8MS_oRsP4jdONhfoVAAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:44.881659 2026] [security2:error] [pid 1020501:tid 1020751] [client 77.110.127.138:56146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y8MS_oRsP4jdONhfoVAAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:45.034244 2026] [security2:error] [pid 1020501:tid 1020746] [client 77.110.127.138:56150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Y8cS_oRsP4jdONhfoXgAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:45.087784 2026] [security2:error] [pid 1020501:tid 1020690] [client 173.252.82.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.according2plant.com"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoVgAAADk"]
[Mon Jul 20 06:47:45.245143 2026] [security2:error] [pid 1020501:tid 1020661] [client 104.234.53.90:43157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y8cS_oRsP4jdONhfocQAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:45.268320 2026] [security2:error] [pid 1020501:tid 1020698] [client 57.141.18.117:46754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y68S_oRsP4jdONhfmtwAAQR8"]
[Mon Jul 20 06:47:45.344576 2026] [security2:error] [pid 1020501:tid 1020652] [client 37.52.210.45:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y8cS_oRsP4jdONhfoewAAABM"]
[Mon Jul 20 06:47:45.344723 2026] [security2:error] [pid 1020501:tid 1020652] [client 37.52.210.45:64169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y8cS_oRsP4jdONhfoewAAABM"]
[Mon Jul 20 06:47:45.356713 2026] [security2:error] [pid 1020501:tid 1020757] [client 14.225.17.146:57307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoIwAAAHw"], referer: http://ancestralidadytrance.space/New
[Mon Jul 20 06:47:45.415325 2026] [security2:error] [pid 1020501:tid 1020743] [client 117.247.108.24:721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y8cS_oRsP4jdONhfohAAAAG4"]
[Mon Jul 20 06:47:45.415419 2026] [security2:error] [pid 1020501:tid 1020743] [client 117.247.108.24:721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y8cS_oRsP4jdONhfohAAAAG4"]
[Mon Jul 20 06:47:45.523111 2026] [security2:error] [pid 1020501:tid 1020739] [client 34.73.38.214:51084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Y8cS_oRsP4jdONhfojQAAAGo"]
[Mon Jul 20 06:47:45.558098 2026] [security2:error] [pid 1020501:tid 1020604] [remote 192.241.143.148:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y8cS_oRsP4jdONhfokAAAVWQ"]
[Mon Jul 20 06:47:45.740225 2026] [security2:error] [pid 1020501:tid 1020543] [remote 192.241.143.148:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Y8cS_oRsP4jdONhfonQAACSc"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:47:45.780268 2026] [security2:error] [pid 1020501:tid 1020668] [client 14.225.17.146:64370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4Y8cS_oRsP4jdONhfolAAAACM"], referer: http://koaconsultants.com/New
[Mon Jul 20 06:47:45.865879 2026] [security2:error] [pid 1020501:tid 1020541] [remote 216.73.216.55:26744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4Y8cS_oRsP4jdONhfoqAAAZyU"]
[Mon Jul 20 06:47:45.926439 2026] [security2:error] [pid 1020501:tid 1020576] [remote 160.187.68.132:42278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Y8cS_oRsP4jdONhfoqQAAMUg"]
[Mon Jul 20 06:47:46.000645 2026] [security2:error] [pid 1020501:tid 1020757] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y8cS_oRsP4jdONhfopQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:46.144155 2026] [security2:error] [pid 1020501:tid 1020686] [client 34.73.38.214:59855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Y8sS_oRsP4jdONhfowAAAADU"]
[Mon Jul 20 06:47:46.394366 2026] [security2:error] [pid 1020501:tid 1020561] [remote 160.187.68.132:42278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Y8sS_oRsP4jdONhfo0AAARjk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:47:46.539178 2026] [security2:error] [pid 1020501:tid 1020660] [client 57.141.18.113:57668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y7MS_oRsP4jdONhfnAgAAG3w"]
[Mon Jul 20 06:47:46.592816 2026] [security2:error] [pid 1020501:tid 1020760] [client 106.219.188.178:10196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Y8sS_oRsP4jdONhfo5gAAAH8"]
[Mon Jul 20 06:47:46.594511 2026] [security2:error] [pid 1020501:tid 1020760] [client 106.219.188.178:10196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Y8sS_oRsP4jdONhfo5gAAAH8"]
[Mon Jul 20 06:47:46.617909 2026] [security2:error] [pid 1020501:tid 1020636] [client 14.225.17.146:64135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Y8sS_oRsP4jdONhfo0wAAAAM"], referer: http://savilerowtravel.com/New
[Mon Jul 20 06:47:46.765087 2026] [security2:error] [pid 1020501:tid 1020755] [client 104.234.53.89:21645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Y8sS_oRsP4jdONhfo8wAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:46.853193 2026] [security2:error] [pid 1020501:tid 1020696] [client 34.73.38.214:63003] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Y8sS_oRsP4jdONhfo-QAAAD8"]
[Mon Jul 20 06:47:47.030607 2026] [core:error] [pid 1020501:tid 1020679] [client 103.153.183.69:54192] AH10244: invalid URI path (/../../.env?_=9brrzgi2&v=1twgc), referer: https://www.google.com/
[Mon Jul 20 06:47:47.097665 2026] [security2:error] [pid 1020501:tid 1020741] [client 57.141.18.105:44206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y7cS_oRsP4jdONhfnQAAAbHY"]
[Mon Jul 20 06:47:47.480592 2026] [security2:error] [pid 1020501:tid 1020710] [client 57.141.18.103:28992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y7cS_oRsP4jdONhfnVQAATSI"]
[Mon Jul 20 06:47:47.573315 2026] [security2:error] [pid 1020501:tid 1020692] [client 34.73.38.214:63702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Y88S_oRsP4jdONhfpKAAAADs"]
[Mon Jul 20 06:47:47.613067 2026] [security2:error] [pid 1020501:tid 1020612] [remote 72.167.132.114:39714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4Y88S_oRsP4jdONhfpLQAAPmw"]
[Mon Jul 20 06:47:47.862147 2026] [security2:error] [pid 1020501:tid 1020597] [remote 72.167.132.114:39714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4Y88S_oRsP4jdONhfpOwAAZF0"], referer: https://cathybuffini.com/wp-login.php
[Mon Jul 20 06:47:48.003239 2026] [security2:error] [pid 1020501:tid 1020752] [client 34.73.38.214:51385] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9MS_oRsP4jdONhfpSQAAAHc"]
[Mon Jul 20 06:47:48.147314 2026] [security2:error] [pid 1020501:tid 1020747] [client 112.208.70.94:43793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9MS_oRsP4jdONhfpVQAAAHI"]
[Mon Jul 20 06:47:48.147461 2026] [security2:error] [pid 1020501:tid 1020747] [client 112.208.70.94:43793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9MS_oRsP4jdONhfpVQAAAHI"]
[Mon Jul 20 06:47:48.238168 2026] [security2:error] [pid 1020501:tid 1020730] [client 192.140.149.97:46239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9MS_oRsP4jdONhfpYQAAAGE"]
[Mon Jul 20 06:47:48.238282 2026] [security2:error] [pid 1020501:tid 1020730] [client 192.140.149.97:46239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9MS_oRsP4jdONhfpYQAAAGE"]
[Mon Jul 20 06:47:48.286227 2026] [security2:error] [pid 1020501:tid 1020734] [client 34.73.38.214:50984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9MS_oRsP4jdONhfpZAAAAGU"]
[Mon Jul 20 06:47:48.504974 2026] [security2:error] [pid 1020501:tid 1020677] [client 57.141.18.46:34202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y7sS_oRsP4jdONhfnngAALEI"]
[Mon Jul 20 06:47:48.718651 2026] [security2:error] [pid 1020501:tid 1020707] [client 36.95.228.227:53151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9MS_oRsP4jdONhfpggAAAEo"]
[Mon Jul 20 06:47:48.718764 2026] [security2:error] [pid 1020501:tid 1020707] [client 36.95.228.227:53151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9MS_oRsP4jdONhfpggAAAEo"]
[Mon Jul 20 06:47:48.718830 2026] [security2:error] [pid 1020501:tid 1020652] [client 34.73.38.214:63455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9MS_oRsP4jdONhfpgQAAABM"]
[Mon Jul 20 06:47:48.859459 2026] [security2:error] [pid 1020501:tid 1020739] [client 14.225.17.146:63768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Y8sS_oRsP4jdONhfo_wAAAGo"], referer: http://floorsourcestock.com/New
[Mon Jul 20 06:47:49.181175 2026] [security2:error] [pid 1020501:tid 1020715] [client 14.225.17.146:51625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4Y9MS_oRsP4jdONhfpSgAAAFI"], referer: http://getgarrison.com/New
[Mon Jul 20 06:47:49.236098 2026] [security2:error] [pid 1020501:tid 1020659] [client 151.123.176.66:43053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9cS_oRsP4jdONhfpvgAAABo"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 06:47:49.240717 2026] [security2:error] [pid 1020501:tid 1020693] [client 39.48.81.23:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9cS_oRsP4jdONhfpxQAAADw"]
[Mon Jul 20 06:47:49.240908 2026] [security2:error] [pid 1020501:tid 1020693] [client 39.48.81.23:64619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9cS_oRsP4jdONhfpxQAAADw"]
[Mon Jul 20 06:47:49.264692 2026] [security2:error] [pid 1020501:tid 1020748] [client 103.238.106.162:60678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y9cS_oRsP4jdONhfpxgAAAHM"]
[Mon Jul 20 06:47:49.264834 2026] [security2:error] [pid 1020501:tid 1020748] [client 103.238.106.162:60678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y9cS_oRsP4jdONhfpxgAAAHM"]
[Mon Jul 20 06:47:49.360976 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:56199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y9cS_oRsP4jdONhfpzgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:49.361079 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:56199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y9cS_oRsP4jdONhfpzgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:49.399062 2026] [security2:error] [pid 1020501:tid 1020561] [remote 116.179.32.82:9554] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4Y9cS_oRsP4jdONhfp1QAAWjk"]
[Mon Jul 20 06:47:49.499282 2026] [security2:error] [pid 1020501:tid 1020683] [client 34.73.38.214:56441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9cS_oRsP4jdONhfp3QAAADI"]
[Mon Jul 20 06:47:49.819557 2026] [security2:error] [pid 1020501:tid 1020677] [client 34.73.38.214:63806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9cS_oRsP4jdONhfp8wAAACw"]
[Mon Jul 20 06:47:49.822843 2026] [security2:error] [pid 1020501:tid 1020742] [client 14.225.17.146:64021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4Y9cS_oRsP4jdONhfp6gAAAG0"], referer: http://myspineworld.com/New
[Mon Jul 20 06:47:49.855674 2026] [security2:error] [pid 1020501:tid 1020660] [client 103.168.67.159:13916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "autodiscover.membresiabeyou.com"] [uri "/.aws/config.bak"] [unique_id "al4Y9cS_oRsP4jdONhfp9QAAABs"], referer: https://t.co/2bfv1pxo4e
[Mon Jul 20 06:47:49.935612 2026] [security2:error] [pid 1020501:tid 1020709] [client 43.205.139.3:55698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Y9cS_oRsP4jdONhfp_gAAAEw"]
[Mon Jul 20 06:47:50.053212 2026] [security2:error] [pid 1020501:tid 1020663] [client 57.141.18.49:38062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoHQAAHnA"]
[Mon Jul 20 06:47:50.142407 2026] [security2:error] [pid 1020501:tid 1020713] [client 217.142.18.172:2778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9sS_oRsP4jdONhfqCwAAAFA"]
[Mon Jul 20 06:47:50.142514 2026] [security2:error] [pid 1020501:tid 1020713] [client 217.142.18.172:2778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Y9sS_oRsP4jdONhfqCwAAAFA"]
[Mon Jul 20 06:47:50.247447 2026] [security2:error] [pid 1020501:tid 1020752] [client 34.73.38.214:58430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9sS_oRsP4jdONhfqEAAAAHc"]
[Mon Jul 20 06:47:50.409410 2026] [security2:error] [pid 1020501:tid 1020671] [client 14.225.17.146:64258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4Y9cS_oRsP4jdONhfppAAAACY"], referer: http://eframiproperties.com/New
[Mon Jul 20 06:47:50.442587 2026] [security2:error] [pid 1020501:tid 1020595] [remote 111.225.214.158:40028] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4Y9sS_oRsP4jdONhfqHQAABVs"]
[Mon Jul 20 06:47:50.493492 2026] [security2:error] [pid 1020501:tid 1020645] [client 57.141.18.30:62708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y8MS_oRsP4jdONhfoWwAADAQ"]
[Mon Jul 20 06:47:50.835283 2026] [security2:error] [pid 1020501:tid 1020713] [client 103.168.67.159:13924] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(wp-)?config\\\\.(php\\\\.)?(?:bac?k|o(?:ld|rig)|copy|s(?:ave|wp)|vim?\\\\.|~)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1254"] [id "390597"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data Leakage - attempt to access backup config file (disable this rule if you require access to these backup files)"] [severity "CRITICAL"] [hostname "autodiscover.membresiabeyou.com"] [uri "/.aws/config.old"] [unique_id "al4Y9sS_oRsP4jdONhfqOQAAAFA"], referer: https://www.google.com/search?q=r3c71h
[Mon Jul 20 06:47:50.861537 2026] [security2:error] [pid 1020501:tid 1020653] [client 34.73.38.214:59853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.makeupyourskin.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Y9sS_oRsP4jdONhfqOwAAABQ"]
[Mon Jul 20 06:47:50.879270 2026] [security2:error] [pid 1020501:tid 1020717] [client 13.233.207.33:13352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Y9sS_oRsP4jdONhfqPwAAAFQ"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:47:50.919468 2026] [security2:error] [pid 1020501:tid 1020639] [client 14.225.17.146:49371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4Y9sS_oRsP4jdONhfqNQAAAAY"], referer: https://myspineworld.com/New
[Mon Jul 20 06:47:50.926304 2026] [security2:error] [pid 1020501:tid 1020745] [client 57.141.18.45:43752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y8cS_oRsP4jdONhfokQAAcCY"]
[Mon Jul 20 06:47:51.007775 2026] [security2:error] [pid 1020501:tid 1020581] [remote 5.161.225.162:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y98S_oRsP4jdONhfqUQAAQk0"]
[Mon Jul 20 06:47:51.257893 2026] [security2:error] [pid 1020501:tid 1020591] [remote 5.161.225.162:47650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y98S_oRsP4jdONhfqZQAAEVc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:47:51.344537 2026] [security2:error] [pid 1020501:tid 1020724] [client 187.108.85.186:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y98S_oRsP4jdONhfqawAAAFs"]
[Mon Jul 20 06:47:51.344652 2026] [security2:error] [pid 1020501:tid 1020724] [client 187.108.85.186:62648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y98S_oRsP4jdONhfqawAAAFs"]
[Mon Jul 20 06:47:51.387430 2026] [security2:error] [pid 1020501:tid 1020714] [client 104.234.53.65:39989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Y98S_oRsP4jdONhfqZwAAAFE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:51.480248 2026] [security2:error] [pid 1020501:tid 1020560] [remote 111.225.214.214:24592] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4Y98S_oRsP4jdONhfqdwAAEzg"]
[Mon Jul 20 06:47:51.567190 2026] [security2:error] [pid 1020501:tid 1020512] [remote 100.42.189.89:33716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y98S_oRsP4jdONhfqgwAAGgg"]
[Mon Jul 20 06:47:51.692848 2026] [security2:error] [pid 1020501:tid 1020676] [client 104.234.53.65:39989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Y98S_oRsP4jdONhfqiAAAACs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:51.779865 2026] [security2:error] [pid 1020501:tid 1020516] [remote 100.42.189.89:33716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Y98S_oRsP4jdONhfqkgAAQQw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:47:51.983667 2026] [security2:error] [pid 1020501:tid 1020705] [client 65.111.7.148:26481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y98S_oRsP4jdONhfqnQAAAEg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:51.997401 2026] [security2:error] [pid 1020501:tid 1020666] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y98S_oRsP4jdONhfqlAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:52.156576 2026] [security2:error] [pid 1020501:tid 1020742] [client 157.85.211.87:24351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfqrgAAAG0"]
[Mon Jul 20 06:47:52.156680 2026] [security2:error] [pid 1020501:tid 1020742] [client 157.85.211.87:24351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfqrgAAAG0"]
[Mon Jul 20 06:47:52.479275 2026] [security2:error] [pid 1020501:tid 1020636] [client 57.141.18.73:58392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y88S_oRsP4jdONhfpGwAAAzI"]
[Mon Jul 20 06:47:52.589931 2026] [security2:error] [pid 1020501:tid 1020601] [remote 8.217.108.67:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfq0QAAKWE"]
[Mon Jul 20 06:47:52.590122 2026] [security2:error] [pid 1020501:tid 1020674] [client 8.217.108.67:52826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfq0QAAKWE"]
[Mon Jul 20 06:47:52.667810 2026] [security2:error] [pid 1020501:tid 1020604] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfq3AAAdmQ"]
[Mon Jul 20 06:47:52.668104 2026] [security2:error] [pid 1020501:tid 1020751] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfq3AAAdmQ"]
[Mon Jul 20 06:47:52.677023 2026] [security2:error] [pid 1020501:tid 1020713] [client 104.207.57.148:9801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Y-MS_oRsP4jdONhfq2wAAAFA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:47:52.726107 2026] [security2:error] [pid 1020501:tid 1020647] [client 57.141.18.90:20112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y88S_oRsP4jdONhfpJwAADno"]
[Mon Jul 20 06:47:52.733899 2026] [security2:error] [pid 1020501:tid 1020703] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y-MS_oRsP4jdONhfqwAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:52.773766 2026] [security2:error] [pid 1020501:tid 1020705] [client 104.207.39.69:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.39.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y-MS_oRsP4jdONhfq6QAAAEg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:52.804540 2026] [security2:error] [pid 1020501:tid 1020748] [client 14.225.17.146:58284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4Y98S_oRsP4jdONhfqYwAAAHM"], referer: http://margaretspeckogawa.com/New
[Mon Jul 20 06:47:52.891949 2026] [security2:error] [pid 1020501:tid 1020657] [client 103.125.179.95:60859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfq8QAAABg"]
[Mon Jul 20 06:47:52.892062 2026] [security2:error] [pid 1020501:tid 1020657] [client 103.125.179.95:60859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-MS_oRsP4jdONhfq8QAAABg"]
[Mon Jul 20 06:47:52.973041 2026] [security2:error] [pid 1020501:tid 1020659] [client 14.225.17.146:63733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4Y-MS_oRsP4jdONhfq5gAAABo"], referer: http://itdynamix.com/New
[Mon Jul 20 06:47:52.993260 2026] [security2:error] [pid 1020501:tid 1020688] [client 14.225.17.146:56916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4Y9sS_oRsP4jdONhfqTAAAADc"], referer: http://dollpassionista.com/New
[Mon Jul 20 06:47:53.224643 2026] [security2:error] [pid 1020501:tid 1020752] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y-cS_oRsP4jdONhfq-wAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:53.375339 2026] [security2:error] [pid 1020501:tid 1020695] [client 14.225.17.146:56573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4Y98S_oRsP4jdONhfqmAAAAD4"], referer: http://olearyplumbingllc.com/New
[Mon Jul 20 06:47:53.385449 2026] [security2:error] [pid 1020501:tid 1020743] [client 57.141.18.28:47192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y9MS_oRsP4jdONhfpUAAAblw"]
[Mon Jul 20 06:47:53.577024 2026] [security2:error] [pid 1020501:tid 1020655] [client 104.207.43.22:18575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.43.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4Y-cS_oRsP4jdONhfrIgAAABY"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:47:53.799338 2026] [security2:error] [pid 1020501:tid 1020662] [client 14.225.17.146:63783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4Y-MS_oRsP4jdONhfqvQAAAB0"], referer: http://dadanetnet.net/New
[Mon Jul 20 06:47:53.965770 2026] [security2:error] [pid 1020501:tid 1020715] [client 183.82.98.154:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-cS_oRsP4jdONhfrPgAAAFI"]
[Mon Jul 20 06:47:53.965936 2026] [security2:error] [pid 1020501:tid 1020715] [client 183.82.98.154:53120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-cS_oRsP4jdONhfrPgAAAFI"]
[Mon Jul 20 06:47:54.018246 2026] [security2:error] [pid 1020501:tid 1020709] [client 14.225.17.146:64032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4Y-MS_oRsP4jdONhfqzwAAAEw"], referer: http://slutilities.com/New
[Mon Jul 20 06:47:54.018699 2026] [security2:error] [pid 1020501:tid 1020668] [client 57.141.18.123:30946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y9MS_oRsP4jdONhfpmgAAIwU"]
[Mon Jul 20 06:47:54.047929 2026] [security2:error] [pid 1020501:tid 1020696] [client 14.225.17.146:58329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Y-cS_oRsP4jdONhfrNAAAAD8"], referer: https://itdynamix.com/New
[Mon Jul 20 06:47:54.052364 2026] [security2:error] [pid 1020501:tid 1020636] [client 14.225.17.146:58316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4Y-cS_oRsP4jdONhfrNQAAAAM"], referer: https://dollpassionista.com/New
[Mon Jul 20 06:47:54.314374 2026] [security2:error] [pid 1020501:tid 1020633] [client 77.110.127.138:56253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y-sS_oRsP4jdONhfrXwAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:54.314484 2026] [security2:error] [pid 1020501:tid 1020633] [client 77.110.127.138:56253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y-sS_oRsP4jdONhfrXwAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:54.438471 2026] [security2:error] [pid 1020501:tid 1020746] [client 34.139.11.221:62476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.makeupyourskin.online"] [uri "/xmlrpc.php"] [unique_id "al4Y-sS_oRsP4jdONhfrbgAAAHE"]
[Mon Jul 20 06:47:54.465698 2026] [security2:error] [pid 1020501:tid 1020661] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y-sS_oRsP4jdONhfrWQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:54.559509 2026] [security2:error] [pid 1020501:tid 1020701] [client 34.139.11.221:64136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-sS_oRsP4jdONhfrewAAAEQ"]
[Mon Jul 20 06:47:54.690272 2026] [security2:error] [pid 1020501:tid 1020672] [client 34.139.11.221:53038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-sS_oRsP4jdONhfrhgAAACc"]
[Mon Jul 20 06:47:54.737884 2026] [security2:error] [pid 1020501:tid 1020642] [client 87.199.205.156:31309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.205.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4Y-sS_oRsP4jdONhfrjAAAAAk"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:47:54.737950 2026] [security2:error] [pid 1020501:tid 1020642] [client 87.199.205.156:31309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4Y-sS_oRsP4jdONhfrjAAAAAk"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:47:54.819197 2026] [security2:error] [pid 1020501:tid 1020696] [client 158.173.166.181:20305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Y-sS_oRsP4jdONhfrkQAAAD8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:47:54.838950 2026] [security2:error] [pid 1020501:tid 1020728] [client 34.139.11.221:61087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-sS_oRsP4jdONhfrkgAAAF8"]
[Mon Jul 20 06:47:55.032944 2026] [security2:error] [pid 1020501:tid 1020713] [client 34.139.11.221:59523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfrpwAAAFA"]
[Mon Jul 20 06:47:55.163393 2026] [security2:error] [pid 1020501:tid 1020690] [client 223.185.13.213:23011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-8S_oRsP4jdONhfrsgAAADk"]
[Mon Jul 20 06:47:55.163584 2026] [security2:error] [pid 1020501:tid 1020690] [client 223.185.13.213:23011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Y-8S_oRsP4jdONhfrsgAAADk"]
[Mon Jul 20 06:47:55.174032 2026] [security2:error] [pid 1020501:tid 1020734] [client 34.139.11.221:55782] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfrswAAAGU"]
[Mon Jul 20 06:47:55.208020 2026] [security2:error] [pid 1020501:tid 1020717] [client 197.186.66.42:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y-8S_oRsP4jdONhfrtgAAAFQ"]
[Mon Jul 20 06:47:55.208836 2026] [security2:error] [pid 1020501:tid 1020717] [client 197.186.66.42:53569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y-8S_oRsP4jdONhfrtgAAAFQ"]
[Mon Jul 20 06:47:55.230693 2026] [security2:error] [pid 1020501:tid 1020745] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y-sS_oRsP4jdONhfriwAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:55.308659 2026] [security2:error] [pid 1020501:tid 1020695] [client 34.139.11.221:49694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfrvQAAAD4"]
[Mon Jul 20 06:47:55.336213 2026] [security2:error] [pid 1020501:tid 1020694] [client 57.141.18.11:29142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y9sS_oRsP4jdONhfqGAAAPVM"]
[Mon Jul 20 06:47:55.338778 2026] [security2:error] [pid 1020501:tid 1020752] [client 66.249.65.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "petpawo.com"] [uri "/index.php"] [unique_id "al4Y-sS_oRsP4jdONhfrigAAAHc"], referer: https://petpawo.com/
[Mon Jul 20 06:47:55.446504 2026] [security2:error] [pid 1020501:tid 1020700] [client 34.139.11.221:62074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfryQAAAEM"]
[Mon Jul 20 06:47:55.510233 2026] [security2:error] [pid 1020501:tid 1020652] [client 14.251.3.155:54709] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Y-8S_oRsP4jdONhfr1wAAABM"]
[Mon Jul 20 06:47:55.565329 2026] [security2:error] [pid 1020501:tid 1020725] [client 34.139.11.221:53171] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfr2gAAAFw"]
[Mon Jul 20 06:47:55.698848 2026] [security2:error] [pid 1020501:tid 1020728] [client 34.139.11.221:58741] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfr4wAAAF8"]
[Mon Jul 20 06:47:55.759791 2026] [security2:error] [pid 1020501:tid 1020663] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y-8S_oRsP4jdONhfr2AAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:55.887080 2026] [security2:error] [pid 1020501:tid 1020646] [client 34.139.11.221:65468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Y-8S_oRsP4jdONhfr8wAAAA0"]
[Mon Jul 20 06:47:55.956902 2026] [security2:error] [pid 1020501:tid 1020660] [client 37.52.210.45:1433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y-8S_oRsP4jdONhfr_gAAABs"]
[Mon Jul 20 06:47:55.957043 2026] [security2:error] [pid 1020501:tid 1020660] [client 37.52.210.45:1433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Y-8S_oRsP4jdONhfr_gAAABs"]
[Mon Jul 20 06:47:56.045138 2026] [security2:error] [pid 1020501:tid 1020703] [client 34.139.11.221:65467] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.makeupyourskin.online"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Y_MS_oRsP4jdONhfsCAAAAEY"]
[Mon Jul 20 06:47:56.231318 2026] [security2:error] [pid 1020501:tid 1020757] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y_MS_oRsP4jdONhfsBAAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:56.372204 2026] [security2:error] [pid 1020501:tid 1020721] [client 117.247.108.24:1143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_MS_oRsP4jdONhfsHgAAAFg"]
[Mon Jul 20 06:47:56.372337 2026] [security2:error] [pid 1020501:tid 1020721] [client 117.247.108.24:1143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_MS_oRsP4jdONhfsHgAAAFg"]
[Mon Jul 20 06:47:56.392781 2026] [security2:error] [pid 1020501:tid 1020737] [client 193.47.62.167:35352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "testing.alaraycreative.com"] [uri "/index.php"] [unique_id "al4Y-sS_oRsP4jdONhfrlwAAAGg"]
[Mon Jul 20 06:47:56.419041 2026] [security2:error] [pid 1020501:tid 1020731] [client 57.141.18.7:54830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y98S_oRsP4jdONhfqlgAAYgA"]
[Mon Jul 20 06:47:56.441255 2026] [security2:error] [pid 1020501:tid 1020669] [client 193.47.62.167:35366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.testing.alaraycreative.com"] [uri "/index.php"] [unique_id "al4Y-8S_oRsP4jdONhfrowAAACQ"]
[Mon Jul 20 06:47:56.570910 2026] [security2:error] [pid 1020501:tid 1020637] [client 14.225.17.146:64016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4Y-8S_oRsP4jdONhfrqQAAAAQ"], referer: http://709fx.com/New
[Mon Jul 20 06:47:56.718780 2026] [security2:error] [pid 1020501:tid 1020729] [client 57.141.18.72:53866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y-MS_oRsP4jdONhfqrAAAYGs"]
[Mon Jul 20 06:47:56.756390 2026] [security2:error] [pid 1020501:tid 1020730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Y_MS_oRsP4jdONhfsMAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:56.780768 2026] [security2:error] [pid 1020501:tid 1020714] [client 14.225.17.146:63633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4Y-sS_oRsP4jdONhfrZAAAAFE"], referer: http://gearwaterproof.com/New
[Mon Jul 20 06:47:57.082978 2026] [security2:error] [pid 1020501:tid 1020676] [client 104.234.53.70:46205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Y_cS_oRsP4jdONhfsXQAAACs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:57.284084 2026] [security2:error] [pid 1020501:tid 1020659] [client 38.49.215.238:39950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4Y_cS_oRsP4jdONhfsXwAAGhE"]
[Mon Jul 20 06:47:57.815380 2026] [security2:error] [pid 1020501:tid 1020565] [remote 72.167.132.114:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Y_cS_oRsP4jdONhfsmQAAUj0"]
[Mon Jul 20 06:47:57.878147 2026] [security2:error] [pid 1020501:tid 1020692] [client 113.180.234.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4Y_cS_oRsP4jdONhfsfgAAADs"]
[Mon Jul 20 06:47:58.103063 2026] [security2:error] [pid 1020501:tid 1020609] [remote 72.167.132.114:35628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4Y_sS_oRsP4jdONhfstgAAfWk"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 06:47:58.328603 2026] [security2:error] [pid 1020501:tid 1020683] [client 122.183.32.225:18599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfswAAAADI"]
[Mon Jul 20 06:47:58.328768 2026] [security2:error] [pid 1020501:tid 1020683] [client 122.183.32.225:18599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfswAAAADI"]
[Mon Jul 20 06:47:58.446961 2026] [security2:error] [pid 1020501:tid 1020705] [client 57.141.18.92:50168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y-cS_oRsP4jdONhfrOwAASEM"]
[Mon Jul 20 06:47:58.625278 2026] [security2:error] [pid 1020501:tid 1020523] [remote 60.205.8.163:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.8.205.60.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfs1QAAfxM"]
[Mon Jul 20 06:47:58.625420 2026] [security2:error] [pid 1020501:tid 1020760] [client 60.205.8.163:54848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfs1QAAfxM"]
[Mon Jul 20 06:47:58.706113 2026] [security2:error] [pid 1020501:tid 1020708] [client 112.208.70.94:44243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfs3wAAAEs"]
[Mon Jul 20 06:47:58.706239 2026] [security2:error] [pid 1020501:tid 1020708] [client 112.208.70.94:44243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfs3wAAAEs"]
[Mon Jul 20 06:47:58.846710 2026] [security2:error] [pid 1020501:tid 1020748] [client 116.179.33.79:48654] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4Y_sS_oRsP4jdONhfs6QAAAHM"]
[Mon Jul 20 06:47:58.892982 2026] [security2:error] [pid 1020501:tid 1020736] [client 63.177.52.239:57252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfs6wAAAGc"]
[Mon Jul 20 06:47:58.893066 2026] [security2:error] [pid 1020501:tid 1020736] [client 63.177.52.239:57252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_sS_oRsP4jdONhfs6wAAAGc"]
[Mon Jul 20 06:47:59.041399 2026] [security2:error] [pid 1020501:tid 1020674] [client 104.234.53.51:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Y_8S_oRsP4jdONhfs_gAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:47:59.131935 2026] [security2:error] [pid 1020501:tid 1020746] [client 202.46.92.242:53629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_8S_oRsP4jdONhftCQAAAHE"]
[Mon Jul 20 06:47:59.132042 2026] [security2:error] [pid 1020501:tid 1020746] [client 202.46.92.242:53629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Y_8S_oRsP4jdONhftCQAAAHE"]
[Mon Jul 20 06:47:59.279694 2026] [security2:error] [pid 1020501:tid 1020682] [client 14.225.17.146:56513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4Y_cS_oRsP4jdONhfssQAAADE"], referer: http://cloudspacesgroup.com/New
[Mon Jul 20 06:47:59.621020 2026] [security2:error] [pid 1020501:tid 1020708] [client 14.225.17.146:60347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4Y_8S_oRsP4jdONhftLwAAAEs"], referer: http://iagdevelopments.com/New
[Mon Jul 20 06:47:59.706906 2026] [security2:error] [pid 1020501:tid 1020686] [client 77.110.127.138:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y_8S_oRsP4jdONhftPwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:59.707043 2026] [security2:error] [pid 1020501:tid 1020686] [client 77.110.127.138:56316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Y_8S_oRsP4jdONhftPwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:47:59.796398 2026] [security2:error] [pid 1020501:tid 1020691] [client 103.238.106.162:61017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y_8S_oRsP4jdONhftRwAAADo"]
[Mon Jul 20 06:47:59.797154 2026] [security2:error] [pid 1020501:tid 1020691] [client 103.238.106.162:61017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Y_8S_oRsP4jdONhftRwAAADo"]
[Mon Jul 20 06:48:00.103442 2026] [security2:error] [pid 1020501:tid 1020754] [client 57.141.18.69:65396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y-8S_oRsP4jdONhfrygAAeXM"]
[Mon Jul 20 06:48:00.163972 2026] [security2:error] [pid 1020501:tid 1020732] [client 35.180.166.19:56798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZAMS_oRsP4jdONhftawAAAGM"]
[Mon Jul 20 06:48:00.206498 2026] [security2:error] [pid 1020501:tid 1020684] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4Y_8S_oRsP4jdONhftXgAAMw8"], referer: http://assasalnazaha.com/New
[Mon Jul 20 06:48:00.726718 2026] [security2:error] [pid 1020501:tid 1020681] [client 217.142.18.172:30703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZAMS_oRsP4jdONhftlQAAADA"]
[Mon Jul 20 06:48:00.738400 2026] [security2:error] [pid 1020501:tid 1020681] [client 217.142.18.172:30703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZAMS_oRsP4jdONhftlQAAADA"]
[Mon Jul 20 06:48:00.804565 2026] [proxy:error] [pid 1020501:tid 1020723] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:00.804639 2026] [proxy_http:error] [pid 1020501:tid 1020723] [client 34.73.38.214:50527] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:00.805475 2026] [proxy:error] [pid 1020501:tid 1020723] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:00.805523 2026] [proxy_http:error] [pid 1020501:tid 1020723] [client 34.73.38.214:50527] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:00.869848 2026] [security2:error] [pid 1020501:tid 1020670] [client 127.0.0.1:14014] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZAMS_oRsP4jdONhftowAAACU"], referer: https://duckduckgo.com/?q=0gk1d
[Mon Jul 20 06:48:00.964992 2026] [security2:error] [pid 1020501:tid 1020712] [client 14.225.17.146:57181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4ZAMS_oRsP4jdONhftZQAAAE8"], referer: http://retzkolonglogistics.com/New
[Mon Jul 20 06:48:01.232119 2026] [proxy:error] [pid 1020501:tid 1020646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:01.232209 2026] [proxy_http:error] [pid 1020501:tid 1020646] [client 34.73.38.214:59425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:01.233378 2026] [proxy:error] [pid 1020501:tid 1020646] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:01.233412 2026] [proxy_http:error] [pid 1020501:tid 1020646] [client 34.73.38.214:59425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:01.256456 2026] [security2:error] [pid 1020501:tid 1020677] [client 57.141.18.31:31068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y_MS_oRsP4jdONhfsMQAALDI"]
[Mon Jul 20 06:48:01.344606 2026] [lsapi:warn] [pid 1020501:tid 1020610] [remote 161.129.166.123:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:48:01.401176 2026] [security2:error] [pid 1020501:tid 1020524] [remote 162.19.86.63:58295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4ZAcS_oRsP4jdONhftzgAANxQ"]
[Mon Jul 20 06:48:01.489207 2026] [lsapi:warn] [pid 1020501:tid 1020601] [remote 104.223.39.77:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 06:48:01.507147 2026] [security2:error] [pid 1020501:tid 1020650] [client 77.110.127.138:56331] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/if(now()=sysdate(),sleep(15),0)/page/2/"] [unique_id "al4ZAcS_oRsP4jdONhft2AAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:01.761297 2026] [security2:error] [pid 1020501:tid 1020705] [client 114.119.156.181:40709] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/robots.txt"] [unique_id "al4ZAcS_oRsP4jdONhft7QAAAEg"], referer: https://lifeisbetterlakeside.com/robots.txt
[Mon Jul 20 06:48:01.820439 2026] [security2:error] [pid 1020501:tid 1020616] [remote 162.19.86.63:58295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4ZAcS_oRsP4jdONhft8wAAYHA"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:48:01.868672 2026] [proxy:error] [pid 1020501:tid 1020739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:01.868770 2026] [proxy_http:error] [pid 1020501:tid 1020739] [client 34.73.38.214:52109] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:01.869419 2026] [proxy:error] [pid 1020501:tid 1020739] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:01.869451 2026] [proxy_http:error] [pid 1020501:tid 1020739] [client 34.73.38.214:52109] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:01.904558 2026] [security2:error] [pid 1020501:tid 1020718] [client 57.141.18.56:38090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y_cS_oRsP4jdONhfsXgAAVX4"]
[Mon Jul 20 06:48:01.962373 2026] [security2:error] [pid 1020501:tid 1020686] [client 187.108.85.186:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZAcS_oRsP4jdONhft_AAAADU"]
[Mon Jul 20 06:48:01.962475 2026] [security2:error] [pid 1020501:tid 1020686] [client 187.108.85.186:63192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZAcS_oRsP4jdONhft_AAAADU"]
[Mon Jul 20 06:48:02.030842 2026] [security2:error] [pid 1020501:tid 1020628] [remote 68.183.43.38:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4ZAsS_oRsP4jdONhfuAgAAPXw"]
[Mon Jul 20 06:48:02.032730 2026] [security2:error] [pid 1020501:tid 1020666] [client 54.244.177.189:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4ZAsS_oRsP4jdONhfuBAAAACE"]
[Mon Jul 20 06:48:02.080184 2026] [security2:error] [pid 1020501:tid 1020654] [client 15.237.209.113:40318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZAMS_oRsP4jdONhfttAAAABU"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:48:02.215301 2026] [security2:error] [pid 1020501:tid 1020573] [remote 68.183.43.38:38118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4ZAsS_oRsP4jdONhfuEwAAf0U"], referer: https://website-19aec4aa.spencersadventures.com/wp-login.php
[Mon Jul 20 06:48:02.297954 2026] [security2:error] [pid 1020501:tid 1020701] [client 57.141.18.13:32684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y_cS_oRsP4jdONhfsigAARDk"]
[Mon Jul 20 06:48:02.509968 2026] [core:error] [pid 1020501:tid 1020718] [client 193.47.62.167:41458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://testtod.asliceofleadership.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:02.509990 2026] [core:error] [pid 1020501:tid 1020718] [client 193.47.62.167:41458] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://testtod.asliceofleadership.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:02.513821 2026] [core:error] [pid 1020501:tid 1020663] [client 193.47.62.167:41462] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.testtod.asliceofleadership.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:02.513838 2026] [core:error] [pid 1020501:tid 1020663] [client 193.47.62.167:41462] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://www.testtod.asliceofleadership.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:02.587481 2026] [security2:error] [pid 1020501:tid 1020710] [client 34.73.38.214:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/xmlrpc.php"] [unique_id "al4ZAsS_oRsP4jdONhfuKwAAAE0"]
[Mon Jul 20 06:48:02.637525 2026] [security2:error] [pid 1020501:tid 1020690] [client 46.110.96.34:9980] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZAsS_oRsP4jdONhfuMAAAADk"]
[Mon Jul 20 06:48:02.925196 2026] [security2:error] [pid 1020501:tid 1020696] [client 98.159.234.160:32713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZAsS_oRsP4jdONhfuRwAAAD8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:48:03.282073 2026] [security2:error] [pid 1020501:tid 1020600] [remote 5.252.52.249:44662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZA8S_oRsP4jdONhfuZwAAZWA"]
[Mon Jul 20 06:48:03.283436 2026] [security2:error] [pid 1020501:tid 1020590] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZA8S_oRsP4jdONhfuagAAF1Y"]
[Mon Jul 20 06:48:03.283559 2026] [security2:error] [pid 1020501:tid 1020656] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZA8S_oRsP4jdONhfuagAAF1Y"]
[Mon Jul 20 06:48:03.299368 2026] [security2:error] [pid 1020501:tid 1020730] [client 34.73.38.214:58132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZA8S_oRsP4jdONhfubAAAAGE"]
[Mon Jul 20 06:48:03.493122 2026] [security2:error] [pid 1020501:tid 1020738] [client 57.141.18.53:23168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y_sS_oRsP4jdONhfs7gAAaWU"]
[Mon Jul 20 06:48:03.544144 2026] [security2:error] [pid 1020501:tid 1020700] [client 103.153.183.69:7158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "../etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/%2e%2e%2f%2e%2e%2fetc%2fpasswd"] [unique_id "al4ZA8S_oRsP4jdONhfugwAAAEM"], referer: https://www.reddit.com/
[Mon Jul 20 06:48:03.568010 2026] [security2:error] [pid 1020501:tid 1020624] [remote 5.252.52.249:44662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZA8S_oRsP4jdONhfuhAAATXg"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:48:03.614569 2026] [security2:error] [pid 1020501:tid 1020747] [client 57.141.18.124:48312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y_8S_oRsP4jdONhftEAAAclM"]
[Mon Jul 20 06:48:03.710798 2026] [security2:error] [pid 1020501:tid 1020641] [client 34.73.38.214:58905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZA8S_oRsP4jdONhfumwAAAAg"]
[Mon Jul 20 06:48:03.749158 2026] [security2:error] [pid 1020501:tid 1020749] [client 103.125.179.95:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZA8S_oRsP4jdONhfungAAAHQ"]
[Mon Jul 20 06:48:03.749252 2026] [security2:error] [pid 1020501:tid 1020749] [client 103.125.179.95:61367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZA8S_oRsP4jdONhfungAAAHQ"]
[Mon Jul 20 06:48:03.782672 2026] [security2:error] [pid 1020501:tid 1020734] [client 57.141.18.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZA8S_oRsP4jdONhfukgAAAGU"]
[Mon Jul 20 06:48:03.967674 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:56358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZA8S_oRsP4jdONhfurAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:03.967772 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:56358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZA8S_oRsP4jdONhfurAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:04.119691 2026] [security2:error] [pid 1020501:tid 1020695] [client 34.73.38.214:65325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBMS_oRsP4jdONhfutQAAAD4"]
[Mon Jul 20 06:48:04.122439 2026] [security2:error] [pid 1020501:tid 1020705] [client 77.110.127.138:56364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/2/"] [unique_id "al4ZBMS_oRsP4jdONhfutgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:04.179333 2026] [security2:error] [pid 1020501:tid 1020714] [client 57.141.18.74:51094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Y_8S_oRsP4jdONhftRgAAUX8"]
[Mon Jul 20 06:48:04.435800 2026] [security2:error] [pid 1020501:tid 1020700] [client 146.103.116.11:29207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.116.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4ZBMS_oRsP4jdONhfuywAAAEM"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:48:04.435920 2026] [security2:error] [pid 1020501:tid 1020700] [client 146.103.116.11:29207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4ZBMS_oRsP4jdONhfuywAAAEM"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:48:04.519308 2026] [security2:error] [pid 1020501:tid 1020741] [client 57.141.18.78:36634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZAMS_oRsP4jdONhfteAAAbBU"]
[Mon Jul 20 06:48:04.548260 2026] [security2:error] [pid 1020501:tid 1020689] [client 34.73.38.214:59490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBMS_oRsP4jdONhfu1AAAADg"]
[Mon Jul 20 06:48:04.787968 2026] [security2:error] [pid 1020501:tid 1020748] [client 65.111.22.20:58641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZBMS_oRsP4jdONhfu6QAAAHM"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:04.845091 2026] [security2:error] [pid 1020501:tid 1020651] [client 34.73.38.214:63654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBMS_oRsP4jdONhfu8AAAABI"]
[Mon Jul 20 06:48:04.875727 2026] [security2:error] [pid 1020501:tid 1020679] [client 183.82.98.154:53705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZBMS_oRsP4jdONhfu8gAAAC4"]
[Mon Jul 20 06:48:04.875858 2026] [security2:error] [pid 1020501:tid 1020679] [client 183.82.98.154:53705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZBMS_oRsP4jdONhfu8gAAAC4"]
[Mon Jul 20 06:48:05.323972 2026] [security2:error] [pid 1020501:tid 1020659] [client 14.225.17.146:65051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4ZA8S_oRsP4jdONhfumAAAABo"], referer: http://soloceos.com/New
[Mon Jul 20 06:48:05.399170 2026] [security2:error] [pid 1020501:tid 1020732] [client 103.153.183.69:7158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/etc/passwd"] [unique_id "al4ZBcS_oRsP4jdONhfvJAAAAGM"], referer: https://www.facebook.com/
[Mon Jul 20 06:48:05.442509 2026] [security2:error] [pid 1020501:tid 1020673] [client 34.73.38.214:53815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBcS_oRsP4jdONhfvKQAAACg"]
[Mon Jul 20 06:48:05.659498 2026] [security2:error] [pid 1020501:tid 1020731] [client 45.3.52.110:51833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZBcS_oRsP4jdONhfvMAAAAGI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:05.676622 2026] [security2:error] [pid 1020501:tid 1020601] [remote 78.46.157.202:38622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZBcS_oRsP4jdONhfvMgAAQmE"]
[Mon Jul 20 06:48:05.697288 2026] [security2:error] [pid 1020501:tid 1020752] [client 103.153.183.69:7158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/\\xc0\\xae\\xc0\\xae/\\xc0\\xae\\xc0\\xae/.env"] [unique_id "al4ZBcS_oRsP4jdONhfvNAAAAHc"], referer: https://duckduckgo.com/?q=0lr1i
[Mon Jul 20 06:48:05.700358 2026] [security2:error] [pid 1020501:tid 1020748] [client 223.185.13.213:30208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZBcS_oRsP4jdONhfvNQAAAHM"]
[Mon Jul 20 06:48:05.700484 2026] [security2:error] [pid 1020501:tid 1020748] [client 223.185.13.213:30208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZBcS_oRsP4jdONhfvNQAAAHM"]
[Mon Jul 20 06:48:05.717245 2026] [security2:error] [pid 1020501:tid 1020754] [client 34.73.38.214:50134] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBcS_oRsP4jdONhfvOAAAAHk"]
[Mon Jul 20 06:48:05.747949 2026] [security2:error] [pid 1020501:tid 1020685] [client 104.234.53.52:49233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZBcS_oRsP4jdONhfvOgAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:05.885229 2026] [security2:error] [pid 1020501:tid 1020616] [remote 78.46.157.202:38622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZBcS_oRsP4jdONhfvSgAAPnA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:48:06.060257 2026] [core:error] [pid 1020501:tid 1020669] [client 103.153.183.69:7158] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=7i3yk2qc&v=w6vee), referer: https://duckduckgo.com/?q=af1a3
[Mon Jul 20 06:48:06.062178 2026] [security2:error] [pid 1020501:tid 1020691] [client 127.0.0.1:14032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZBsS_oRsP4jdONhfvWwAAADo"], referer: https://duckduckgo.com/?q=af1a3
[Mon Jul 20 06:48:06.231242 2026] [security2:error] [pid 1020501:tid 1020663] [client 34.73.38.214:63341] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBsS_oRsP4jdONhfvawAAAB4"]
[Mon Jul 20 06:48:06.379373 2026] [security2:error] [pid 1020501:tid 1020742] [client 45.3.41.223:32763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZBsS_oRsP4jdONhfvcgAAAG0"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:06.588536 2026] [security2:error] [pid 1020501:tid 1020685] [client 37.52.210.45:2869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZBsS_oRsP4jdONhfvggAAADQ"]
[Mon Jul 20 06:48:06.589958 2026] [security2:error] [pid 1020501:tid 1020685] [client 37.52.210.45:2869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZBsS_oRsP4jdONhfvggAAADQ"]
[Mon Jul 20 06:48:06.722870 2026] [security2:error] [pid 1020501:tid 1020699] [client 34.73.38.214:60223] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZBsS_oRsP4jdONhfviwAAAEI"]
[Mon Jul 20 06:48:06.966610 2026] [security2:error] [pid 1020501:tid 1020655] [client 14.225.17.146:49830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4ZBcS_oRsP4jdONhfvPQAAABY"], referer: http://collectingrealestate.com/New
[Mon Jul 20 06:48:06.974010 2026] [security2:error] [pid 1020501:tid 1020711] [client 50.116.65.227:21492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4ZBsS_oRsP4jdONhfvpQAAAE4"]
[Mon Jul 20 06:48:06.978238 2026] [security2:error] [pid 1020501:tid 1020716] [client 14.225.17.146:63361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4ZBcS_oRsP4jdONhfvKgAAAFM"], referer: http://recruitinginsight.us/New
[Mon Jul 20 06:48:07.231090 2026] [security2:error] [pid 1020501:tid 1020701] [client 117.247.108.24:1654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZB8S_oRsP4jdONhfvsgAAAEQ"]
[Mon Jul 20 06:48:07.231194 2026] [security2:error] [pid 1020501:tid 1020701] [client 117.247.108.24:1654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZB8S_oRsP4jdONhfvsgAAAEQ"]
[Mon Jul 20 06:48:07.286669 2026] [security2:error] [pid 1020501:tid 1020698] [client 34.73.38.214:63887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZB8S_oRsP4jdONhfvtwAAAEE"]
[Mon Jul 20 06:48:07.408629 2026] [security2:error] [pid 1020501:tid 1020755] [client 104.234.53.56:48943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZB8S_oRsP4jdONhfvxAAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:07.686782 2026] [security2:error] [pid 1020501:tid 1020746] [client 14.225.17.146:50029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZB8S_oRsP4jdONhfvzwAAAHE"], referer: http://mezzacraft.com/New
[Mon Jul 20 06:48:08.046674 2026] [security2:error] [pid 1020501:tid 1020668] [client 34.73.38.214:58825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZCMS_oRsP4jdONhfv9wAAACM"]
[Mon Jul 20 06:48:08.124699 2026] [security2:error] [pid 1020501:tid 1020635] [client 114.119.145.115:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toddnielsen.com"] [uri "/leadership-urgency/the-urgency-for-good-leadership/"] [unique_id "al4ZCMS_oRsP4jdONhfv-gAAAAI"], referer: https://katenasser.com/leaders-engage-employee-urgency-connect
[Mon Jul 20 06:48:08.164744 2026] [security2:error] [pid 1020501:tid 1020651] [client 14.225.17.146:60320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4ZBcS_oRsP4jdONhfvTwAAABI"], referer: http://superiorcopywriting.com/New
[Mon Jul 20 06:48:08.492484 2026] [security2:error] [pid 1020501:tid 1020731] [client 34.73.38.214:57701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.membresiabeyou.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZCMS_oRsP4jdONhfwHQAAAGI"]
[Mon Jul 20 06:48:08.573227 2026] [security2:error] [pid 1020501:tid 1020636] [client 197.186.66.42:54101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZCMS_oRsP4jdONhfwJgAAAAM"]
[Mon Jul 20 06:48:08.573900 2026] [security2:error] [pid 1020501:tid 1020636] [client 197.186.66.42:54101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZCMS_oRsP4jdONhfwJgAAAAM"]
[Mon Jul 20 06:48:08.594053 2026] [security2:error] [pid 1020501:tid 1020701] [client 52.109.52.84:15553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ZCMS_oRsP4jdONhfwJwAAAEQ"]
[Mon Jul 20 06:48:08.668451 2026] [security2:error] [pid 1020501:tid 1020510] [remote 38.242.157.30:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ZCMS_oRsP4jdONhfwLQAAQwY"]
[Mon Jul 20 06:48:08.706408 2026] [security2:error] [pid 1020501:tid 1020743] [client 52.109.52.84:15553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ZCMS_oRsP4jdONhfwMAAAAG4"]
[Mon Jul 20 06:48:08.716307 2026] [security2:error] [pid 1020501:tid 1020673] [client 14.225.17.146:58689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4ZCMS_oRsP4jdONhfwFQAAACg"], referer: http://maxenengineering.com/New
[Mon Jul 20 06:48:08.830327 2026] [security2:error] [pid 1020501:tid 1020669] [client 77.110.127.138:56408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZCMS_oRsP4jdONhfwOgAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:08.830420 2026] [security2:error] [pid 1020501:tid 1020669] [client 77.110.127.138:56408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZCMS_oRsP4jdONhfwOgAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:08.979149 2026] [core:error] [pid 1020501:tid 1020696] [client 103.153.183.69:19074] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.env?_=pm0vuofc&v=wij66), referer: https://www.google.com/
[Mon Jul 20 06:48:08.998243 2026] [security2:error] [pid 1020501:tid 1020716] [client 157.85.211.87:30376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCMS_oRsP4jdONhfwTgAAAFM"]
[Mon Jul 20 06:48:08.998377 2026] [security2:error] [pid 1020501:tid 1020716] [client 157.85.211.87:30376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCMS_oRsP4jdONhfwTgAAAFM"]
[Mon Jul 20 06:48:09.004774 2026] [security2:error] [pid 1020501:tid 1020721] [client 14.225.17.146:63427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4ZBsS_oRsP4jdONhfvkQAAAFg"], referer: http://younutrition.gr/New
[Mon Jul 20 06:48:09.179927 2026] [security2:error] [pid 1020501:tid 1020505] [remote 38.242.157.30:46860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ZCcS_oRsP4jdONhfwXQAAFQE"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:48:09.193298 2026] [security2:error] [pid 1020501:tid 1020642] [client 57.141.18.33:42664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZBcS_oRsP4jdONhfvIwAACVw"]
[Mon Jul 20 06:48:09.295168 2026] [security2:error] [pid 1020501:tid 1020685] [client 112.208.70.94:44689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCcS_oRsP4jdONhfwYgAAADQ"]
[Mon Jul 20 06:48:09.295330 2026] [security2:error] [pid 1020501:tid 1020685] [client 112.208.70.94:44689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCcS_oRsP4jdONhfwYgAAADQ"]
[Mon Jul 20 06:48:09.590639 2026] [security2:error] [pid 1020501:tid 1020679] [client 57.141.18.9:29858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZBcS_oRsP4jdONhfvNgAALjc"]
[Mon Jul 20 06:48:09.691464 2026] [security2:error] [pid 1020501:tid 1020730] [client 14.225.17.146:63375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4ZCcS_oRsP4jdONhfwdgAAAGE"], referer: https://maxenengineering.com/New
[Mon Jul 20 06:48:09.700091 2026] [security2:error] [pid 1020501:tid 1020698] [client 77.110.127.138:56418] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/2/"] [unique_id "al4ZCcS_oRsP4jdONhfwhgAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:09.736773 2026] [security2:error] [pid 1020501:tid 1020633] [client 104.234.53.70:39707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZCcS_oRsP4jdONhfwiAAAAAA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:09.813235 2026] [security2:error] [pid 1020501:tid 1020724] [client 14.225.17.146:60142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4ZCMS_oRsP4jdONhfwCwAAAFs"], referer: http://alexsandbergmusic.com/New
[Mon Jul 20 06:48:09.829506 2026] [security2:error] [pid 1020501:tid 1020661] [client 14.225.17.146:59564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4ZCMS_oRsP4jdONhfv9gAAABw"], referer: http://tacticaltreeoperations.com/New
[Mon Jul 20 06:48:09.905285 2026] [security2:error] [pid 1020501:tid 1020667] [client 77.110.127.138:56421] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 488 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZCcS_oRsP4jdONhfwkwAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:09.912200 2026] [security2:error] [pid 1020501:tid 1020669] [client 192.140.149.97:46037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCcS_oRsP4jdONhfwlgAAACQ"]
[Mon Jul 20 06:48:09.912326 2026] [security2:error] [pid 1020501:tid 1020669] [client 192.140.149.97:46037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCcS_oRsP4jdONhfwlgAAACQ"]
[Mon Jul 20 06:48:09.926648 2026] [security2:error] [pid 1020501:tid 1020666] [client 36.95.228.227:54096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCcS_oRsP4jdONhfwmQAAACE"]
[Mon Jul 20 06:48:09.926776 2026] [security2:error] [pid 1020501:tid 1020666] [client 36.95.228.227:54096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCcS_oRsP4jdONhfwmQAAACE"]
[Mon Jul 20 06:48:10.003247 2026] [security2:error] [pid 1020501:tid 1020640] [client 14.225.17.146:49986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4ZCMS_oRsP4jdONhfwKwAAAAc"], referer: http://mobilesurvsolutions.com/New
[Mon Jul 20 06:48:10.200158 2026] [security2:error] [pid 1020501:tid 1020702] [client 122.183.32.225:29593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCsS_oRsP4jdONhfwsgAAAEU"]
[Mon Jul 20 06:48:10.200277 2026] [security2:error] [pid 1020501:tid 1020702] [client 122.183.32.225:29593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCsS_oRsP4jdONhfwsgAAAEU"]
[Mon Jul 20 06:48:10.276460 2026] [security2:error] [pid 1020501:tid 1020650] [client 14.224.227.113:54710] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZCsS_oRsP4jdONhfwtwAAABE"]
[Mon Jul 20 06:48:10.410077 2026] [security2:error] [pid 1020501:tid 1020645] [client 103.238.106.162:60640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZCsS_oRsP4jdONhfwugAAAAw"]
[Mon Jul 20 06:48:10.410225 2026] [security2:error] [pid 1020501:tid 1020645] [client 103.238.106.162:60640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZCsS_oRsP4jdONhfwugAAAAw"]
[Mon Jul 20 06:48:10.452095 2026] [security2:error] [pid 1020501:tid 1020661] [client 13.233.207.33:11236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZCsS_oRsP4jdONhfwwQAAABw"]
[Mon Jul 20 06:48:10.496849 2026] [security2:error] [pid 1020501:tid 1020682] [client 138.249.169.117:33065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.169.249.138.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZCsS_oRsP4jdONhfwvwAAADE"], referer: https://schuttfarms.com/#comment-5184
[Mon Jul 20 06:48:10.496951 2026] [security2:error] [pid 1020501:tid 1020682] [client 138.249.169.117:33065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "schuttfarms.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZCsS_oRsP4jdONhfwvwAAADE"], referer: https://schuttfarms.com/#comment-5184
[Mon Jul 20 06:48:10.502424 2026] [security2:error] [pid 1020501:tid 1020595] [remote 130.51.180.8:48280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZCsS_oRsP4jdONhfwygAAVFs"]
[Mon Jul 20 06:48:10.549600 2026] [security2:error] [pid 1020501:tid 1020569] [remote 154.66.198.148:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ZCsS_oRsP4jdONhfwzQAAZEE"]
[Mon Jul 20 06:48:10.662562 2026] [security2:error] [pid 1020501:tid 1020568] [remote 130.51.180.8:48280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZCsS_oRsP4jdONhfw2wAAEkA"], referer: https://zlp.omk.mybluehost.me/wp-login.php
[Mon Jul 20 06:48:10.895129 2026] [security2:error] [pid 1020501:tid 1020711] [client 106.219.188.178:59904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCsS_oRsP4jdONhfw4wAAAE4"]
[Mon Jul 20 06:48:10.895299 2026] [security2:error] [pid 1020501:tid 1020711] [client 106.219.188.178:59904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZCsS_oRsP4jdONhfw4wAAAE4"]
[Mon Jul 20 06:48:11.078627 2026] [security2:error] [pid 1020501:tid 1020533] [remote 154.66.198.148:50596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4ZC8S_oRsP4jdONhfw9AAAMx0"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:48:11.266860 2026] [security2:error] [pid 1020501:tid 1020696] [client 217.142.18.172:56203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZC8S_oRsP4jdONhfw_AAAAD8"]
[Mon Jul 20 06:48:11.274352 2026] [security2:error] [pid 1020501:tid 1020696] [client 217.142.18.172:56203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZC8S_oRsP4jdONhfw_AAAAD8"]
[Mon Jul 20 06:48:11.293791 2026] [security2:error] [pid 1020501:tid 1020643] [client 57.141.18.19:29556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZB8S_oRsP4jdONhfvzQAACkI"]
[Mon Jul 20 06:48:11.557894 2026] [security2:error] [pid 1020501:tid 1020713] [client 43.205.139.3:23906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZC8S_oRsP4jdONhfxGgAAAFA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:48:11.906319 2026] [security2:error] [pid 1020501:tid 1020716] [client 77.110.127.138:56439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZC8S_oRsP4jdONhfxOAAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:11.906418 2026] [security2:error] [pid 1020501:tid 1020716] [client 77.110.127.138:56439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZC8S_oRsP4jdONhfxOAAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:12.317085 2026] [security2:error] [pid 1020501:tid 1020751] [client 57.141.18.6:26192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZCMS_oRsP4jdONhfwIwAAdmc"]
[Mon Jul 20 06:48:12.328769 2026] [security2:error] [pid 1020501:tid 1020739] [client 54.197.114.76:3468] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "willowbranchequines.org"] [uri "/robots.txt"] [unique_id "al4ZDMS_oRsP4jdONhfxZgAAAGo"]
[Mon Jul 20 06:48:12.724365 2026] [security2:error] [pid 1020501:tid 1020645] [client 187.108.85.186:63747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDMS_oRsP4jdONhfxhAAAAAw"]
[Mon Jul 20 06:48:12.724500 2026] [security2:error] [pid 1020501:tid 1020645] [client 187.108.85.186:63747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDMS_oRsP4jdONhfxhAAAAAw"]
[Mon Jul 20 06:48:13.183857 2026] [security2:error] [pid 1020501:tid 1020678] [client 57.141.18.27:39346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZCcS_oRsP4jdONhfwXgAALQg"]
[Mon Jul 20 06:48:13.187170 2026] [security2:error] [pid 1020501:tid 1020690] [client 57.141.18.74:41364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZCcS_oRsP4jdONhfwYAAAOSU"]
[Mon Jul 20 06:48:13.429862 2026] [security2:error] [pid 1020501:tid 1020738] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4ZDcS_oRsP4jdONhfxvAAAAGk"]
[Mon Jul 20 06:48:13.429979 2026] [security2:error] [pid 1020501:tid 1020738] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4ZDcS_oRsP4jdONhfxvAAAAGk"]
[Mon Jul 20 06:48:13.440368 2026] [security2:error] [pid 1020501:tid 1020748] [client 158.173.89.95:28935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZDcS_oRsP4jdONhfxwgAAAHM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:48:13.650274 2026] [security2:error] [pid 1020501:tid 1020649] [client 14.225.17.146:60077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4ZDcS_oRsP4jdONhfxwQAAABA"], referer: http://fineartsfactory.net/New
[Mon Jul 20 06:48:13.662883 2026] [security2:error] [pid 1020501:tid 1020650] [client 45.3.55.22:48065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZDcS_oRsP4jdONhfx1wAAABE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:48:13.812252 2026] [security2:error] [pid 1020501:tid 1020712] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4ZDcS_oRsP4jdONhfx6gAAAE8"]
[Mon Jul 20 06:48:13.812353 2026] [security2:error] [pid 1020501:tid 1020712] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4ZDcS_oRsP4jdONhfx6gAAAE8"]
[Mon Jul 20 06:48:13.949599 2026] [security2:error] [pid 1020501:tid 1020698] [client 57.141.18.16:30070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZCsS_oRsP4jdONhfwrAAAQQ4"]
[Mon Jul 20 06:48:13.981177 2026] [security2:error] [pid 1020501:tid 1020517] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDcS_oRsP4jdONhfx-AAAXw0"]
[Mon Jul 20 06:48:13.981361 2026] [security2:error] [pid 1020501:tid 1020728] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDcS_oRsP4jdONhfx-AAAXw0"]
[Mon Jul 20 06:48:14.163938 2026] [security2:error] [pid 1020501:tid 1020701] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xyn.php"] [unique_id "al4ZDsS_oRsP4jdONhfyBwAAAEQ"]
[Mon Jul 20 06:48:14.164084 2026] [security2:error] [pid 1020501:tid 1020701] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xyn.php"] [unique_id "al4ZDsS_oRsP4jdONhfyBwAAAEQ"]
[Mon Jul 20 06:48:14.189458 2026] [security2:error] [pid 1020501:tid 1020732] [client 216.73.217.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "scoophouse.com"] [uri "/index.php"] [unique_id "al4ZDMS_oRsP4jdONhfxgwAAY3o"]
[Mon Jul 20 06:48:14.319963 2026] [security2:error] [pid 1020501:tid 1020679] [client 104.234.53.74:41519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ZDsS_oRsP4jdONhfyFwAAAC4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:14.466896 2026] [security2:error] [pid 1020501:tid 1020725] [client 103.125.179.95:61875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDsS_oRsP4jdONhfyJAAAAFw"]
[Mon Jul 20 06:48:14.467117 2026] [security2:error] [pid 1020501:tid 1020725] [client 103.125.179.95:61875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDsS_oRsP4jdONhfyJAAAAFw"]
[Mon Jul 20 06:48:14.562257 2026] [security2:error] [pid 1020501:tid 1020713] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/patie.php"] [unique_id "al4ZDsS_oRsP4jdONhfyKwAAAFA"]
[Mon Jul 20 06:48:14.562371 2026] [security2:error] [pid 1020501:tid 1020713] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/patie.php"] [unique_id "al4ZDsS_oRsP4jdONhfyKwAAAFA"]
[Mon Jul 20 06:48:14.807695 2026] [security2:error] [pid 1020501:tid 1020685] [client 77.110.127.138:56480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 206 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZDsS_oRsP4jdONhfyNgAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:14.812757 2026] [core:error] [pid 1020501:tid 1020697] [client 103.153.183.69:19086] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.env?_=q55bk91i&v=hl947), referer: https://www.google.com/
[Mon Jul 20 06:48:14.887696 2026] [security2:error] [pid 1020501:tid 1020746] [client 43.205.139.3:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDsS_oRsP4jdONhfyQwAAAHE"]
[Mon Jul 20 06:48:14.887794 2026] [security2:error] [pid 1020501:tid 1020746] [client 43.205.139.3:49848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZDsS_oRsP4jdONhfyQwAAAHE"]
[Mon Jul 20 06:48:14.987108 2026] [security2:error] [pid 1020501:tid 1020668] [client 66.249.73.10:41701] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "ililac.com"] [uri "/robots.txt"] [unique_id "al4ZDsS_oRsP4jdONhfyTQAAACM"]
[Mon Jul 20 06:48:15.013796 2026] [security2:error] [pid 1020501:tid 1020709] [client 57.141.18.120:64610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZC8S_oRsP4jdONhfw_QAATDs"]
[Mon Jul 20 06:48:15.286263 2026] [security2:error] [pid 1020501:tid 1020623] [remote 57.141.18.91:54818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3652821"] [unique_id "al4ZD8S_oRsP4jdONhfyYAAAbXc"]
[Mon Jul 20 06:48:15.352757 2026] [security2:error] [pid 1020501:tid 1020655] [client 14.225.17.146:65433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4ZD8S_oRsP4jdONhfyWgAAABY"], referer: http://grecruit.online/New
[Mon Jul 20 06:48:15.492318 2026] [security2:error] [pid 1020501:tid 1020741] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/aa.php"] [unique_id "al4ZD8S_oRsP4jdONhfycQAAAGw"]
[Mon Jul 20 06:48:15.492431 2026] [security2:error] [pid 1020501:tid 1020741] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/aa.php"] [unique_id "al4ZD8S_oRsP4jdONhfycQAAAGw"]
[Mon Jul 20 06:48:15.740568 2026] [security2:error] [pid 1020501:tid 1020724] [client 77.110.127.138:56493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZD8S_oRsP4jdONhfyjgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:15.740679 2026] [security2:error] [pid 1020501:tid 1020724] [client 77.110.127.138:56493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZD8S_oRsP4jdONhfyjgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:15.750647 2026] [security2:error] [pid 1020501:tid 1020651] [client 14.225.17.146:58899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4ZD8S_oRsP4jdONhfyfgAAABI"]
[Mon Jul 20 06:48:15.862897 2026] [security2:error] [pid 1020501:tid 1020661] [client 14.225.17.146:58678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4ZD8S_oRsP4jdONhfykAAAABw"], referer: http://mcg.homes/New
[Mon Jul 20 06:48:15.884900 2026] [security2:error] [pid 1020501:tid 1020667] [client 45.3.33.166:47257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.33.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZD8S_oRsP4jdONhfylgAAACI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:48:15.890800 2026] [security2:error] [pid 1020501:tid 1020689] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xwpg.php"] [unique_id "al4ZD8S_oRsP4jdONhfymwAAADg"]
[Mon Jul 20 06:48:15.890942 2026] [security2:error] [pid 1020501:tid 1020689] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xwpg.php"] [unique_id "al4ZD8S_oRsP4jdONhfymwAAADg"]
[Mon Jul 20 06:48:15.898562 2026] [proxy:error] [pid 1020501:tid 1020648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:15.898647 2026] [proxy_http:error] [pid 1020501:tid 1020648] [client 94.154.43.185:49832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:15.899776 2026] [proxy:error] [pid 1020501:tid 1020648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:15.899815 2026] [proxy_http:error] [pid 1020501:tid 1020648] [client 94.154.43.185:49832] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:15.958835 2026] [http2:info] [pid 1025331:tid 1025331] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:48:15.975892 2026] [proxy:error] [pid 1020501:tid 1020678] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:15.975956 2026] [proxy_http:error] [pid 1020501:tid 1020678] [client 34.73.38.214:51681] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:15.976681 2026] [proxy:error] [pid 1020501:tid 1020678] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:15.976714 2026] [proxy_http:error] [pid 1020501:tid 1020678] [client 34.73.38.214:51681] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:15.999489 2026] [proxy:error] [pid 1020501:tid 1020642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:15.999550 2026] [proxy_http:error] [pid 1020501:tid 1020642] [client 94.154.43.179:49628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:16.000007 2026] [proxy:error] [pid 1020501:tid 1020642] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:16.000043 2026] [proxy_http:error] [pid 1020501:tid 1020642] [client 94.154.43.179:49628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:16.048434 2026] [security2:error] [pid 1020501:tid 1020637] [client 57.141.18.124:30872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZDMS_oRsP4jdONhfxZAAABGY"]
[Mon Jul 20 06:48:16.131319 2026] [security2:error] [pid 1020501:tid 1020691] [client 14.225.17.146:65354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4ZD8S_oRsP4jdONhfyUQAAADo"], referer: http://nikkidesigns.net/New
[Mon Jul 20 06:48:16.211078 2026] [security2:error] [pid 1020501:tid 1020759] [client 183.82.98.154:54291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEMS_oRsP4jdONhfyuAAAAH4"]
[Mon Jul 20 06:48:16.211204 2026] [security2:error] [pid 1020501:tid 1020759] [client 183.82.98.154:54291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEMS_oRsP4jdONhfyuAAAAH4"]
[Mon Jul 20 06:48:16.744881 2026] [proxy:error] [pid 1025331:tid 1025489] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:16.744941 2026] [proxy_http:error] [pid 1025331:tid 1025489] [client 34.73.38.214:54530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:16.745913 2026] [proxy:error] [pid 1025331:tid 1025489] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:16.745949 2026] [proxy_http:error] [pid 1025331:tid 1025489] [client 34.73.38.214:54530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:17.294535 2026] [security2:error] [pid 1020501:tid 1020701] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ops.php"] [unique_id "al4ZEcS_oRsP4jdONhfy4gAAAEQ"]
[Mon Jul 20 06:48:17.294632 2026] [security2:error] [pid 1020501:tid 1020701] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ops.php"] [unique_id "al4ZEcS_oRsP4jdONhfy4gAAAEQ"]
[Mon Jul 20 06:48:17.315005 2026] [security2:error] [pid 1025331:tid 1025495] [client 14.225.17.146:59461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4ZEUOu5aQNSViFaxM3dwAAASw"], referer: http://christiancountytrumpet.com/New
[Mon Jul 20 06:48:17.320925 2026] [security2:error] [pid 1025331:tid 1025494] [client 37.52.210.45:4851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZEUOu5aQNSViFaxM3ewAAASs"]
[Mon Jul 20 06:48:17.321117 2026] [security2:error] [pid 1025331:tid 1025494] [client 37.52.210.45:4851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZEUOu5aQNSViFaxM3ewAAASs"]
[Mon Jul 20 06:48:17.384969 2026] [security2:error] [pid 1020501:tid 1020755] [client 14.225.17.146:63494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4ZEMS_oRsP4jdONhfytAAAAHo"], referer: http://keywayconstructionclt.com/New
[Mon Jul 20 06:48:17.409912 2026] [security2:error] [pid 1025331:tid 1025488] [client 104.234.53.66:58535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZEUOu5aQNSViFaxM3egAAASU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:17.457978 2026] [security2:error] [pid 1020501:tid 1020759] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZEcS_oRsP4jdONhfy4AAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:17.677875 2026] [security2:error] [pid 1025331:tid 1025547] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/mac.php"] [unique_id "al4ZEUOu5aQNSViFaxM3jAAAAWA"]
[Mon Jul 20 06:48:17.677997 2026] [security2:error] [pid 1025331:tid 1025547] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/mac.php"] [unique_id "al4ZEUOu5aQNSViFaxM3jAAAAWA"]
[Mon Jul 20 06:48:17.713019 2026] [proxy:error] [pid 1025331:tid 1025550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:17.713105 2026] [proxy_http:error] [pid 1025331:tid 1025550] [client 34.73.38.214:59315] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:17.713719 2026] [proxy:error] [pid 1025331:tid 1025550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:17.713755 2026] [proxy_http:error] [pid 1025331:tid 1025550] [client 34.73.38.214:59315] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:17.736507 2026] [security2:error] [pid 1020501:tid 1020671] [client 57.141.18.85:51330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZDcS_oRsP4jdONhfx7gAAJjM"]
[Mon Jul 20 06:48:17.768154 2026] [security2:error] [pid 1025331:tid 1025554] [client 104.234.53.66:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZEUOu5aQNSViFaxM3lAAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:17.954510 2026] [security2:error] [pid 1025331:tid 1025498] [client 65.111.22.20:64779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZEUOu5aQNSViFaxM3nAAAAS8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:17.986539 2026] [security2:error] [pid 1025331:tid 1025524] [client 223.185.13.213:29624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEUOu5aQNSViFaxM3ngAAAUk"]
[Mon Jul 20 06:48:17.986681 2026] [security2:error] [pid 1025331:tid 1025524] [client 223.185.13.213:29624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEUOu5aQNSViFaxM3ngAAAUk"]
[Mon Jul 20 06:48:18.005374 2026] [security2:error] [pid 1020501:tid 1020697] [client 117.247.108.24:12107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEsS_oRsP4jdONhfzBQAAAEA"]
[Mon Jul 20 06:48:18.005486 2026] [security2:error] [pid 1020501:tid 1020697] [client 117.247.108.24:12107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEsS_oRsP4jdONhfzBQAAAEA"]
[Mon Jul 20 06:48:18.062980 2026] [security2:error] [pid 1025331:tid 1025577] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/mg.php"] [unique_id "al4ZEkOu5aQNSViFaxM3nwAAAX4"]
[Mon Jul 20 06:48:18.063103 2026] [security2:error] [pid 1025331:tid 1025577] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/mg.php"] [unique_id "al4ZEkOu5aQNSViFaxM3nwAAAX4"]
[Mon Jul 20 06:48:18.197319 2026] [security2:error] [pid 1020501:tid 1020715] [client 57.141.18.46:52358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZDsS_oRsP4jdONhfyEQAAUhM"]
[Mon Jul 20 06:48:18.302239 2026] [security2:error] [pid 1020501:tid 1020646] [client 34.73.38.214:55121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/xmlrpc.php"] [unique_id "al4ZEsS_oRsP4jdONhfzEAAAAA0"]
[Mon Jul 20 06:48:18.520115 2026] [security2:error] [pid 1025331:tid 1025476] [client 34.73.38.214:56612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZEkOu5aQNSViFaxM3pQAAARk"]
[Mon Jul 20 06:48:18.593700 2026] [security2:error] [pid 1025331:tid 1025479] [client 77.110.127.138:56524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZEkOu5aQNSViFaxM3qQAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:18.593811 2026] [security2:error] [pid 1025331:tid 1025479] [client 77.110.127.138:56524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZEkOu5aQNSViFaxM3qQAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:18.633204 2026] [security2:error] [pid 1020501:tid 1020643] [client 57.141.18.79:55422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZDsS_oRsP4jdONhfyNQAACis"]
[Mon Jul 20 06:48:18.879271 2026] [security2:error] [pid 1025331:tid 1025506] [client 77.110.127.138:56529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZEkOu5aQNSViFaxM3tQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:18.879382 2026] [security2:error] [pid 1025331:tid 1025506] [client 77.110.127.138:56529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZEkOu5aQNSViFaxM3tQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.007295 2026] [security2:error] [pid 1025331:tid 1025464] [client 14.225.17.146:51350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4ZEkOu5aQNSViFaxM3sQAAAQ0"], referer: http://idigress.agency/New
[Mon Jul 20 06:48:19.140938 2026] [security2:error] [pid 1025331:tid 1025537] [client 34.73.38.214:57465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZE0Ou5aQNSViFaxM3xQAAAVY"]
[Mon Jul 20 06:48:19.263356 2026] [security2:error] [pid 1020501:tid 1020759] [client 77.110.127.138:56532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE8S_oRsP4jdONhfzOQAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.263437 2026] [security2:error] [pid 1020501:tid 1020759] [client 77.110.127.138:56532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE8S_oRsP4jdONhfzOQAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.386042 2026] [security2:error] [pid 1025331:tid 1025505] [client 104.207.50.21:54917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZE0Ou5aQNSViFaxM3zAAAATY"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:19.457281 2026] [security2:error] [pid 1020501:tid 1020694] [client 106.219.188.178:53919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZE8S_oRsP4jdONhfzRAAAAD0"]
[Mon Jul 20 06:48:19.457943 2026] [security2:error] [pid 1020501:tid 1020694] [client 106.219.188.178:53919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZE8S_oRsP4jdONhfzRAAAAD0"]
[Mon Jul 20 06:48:19.467630 2026] [security2:error] [pid 1025331:tid 1025572] [client 77.110.127.138:56536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE0Ou5aQNSViFaxM3zwAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.467718 2026] [security2:error] [pid 1025331:tid 1025572] [client 77.110.127.138:56536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE0Ou5aQNSViFaxM3zwAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.634817 2026] [security2:error] [pid 1025331:tid 1025578] [client 34.73.38.214:62192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZE0Ou5aQNSViFaxM30QAAAX8"]
[Mon Jul 20 06:48:19.639074 2026] [security2:error] [pid 1025331:tid 1025566] [client 77.110.127.138:56540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE0Ou5aQNSViFaxM30gAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.639160 2026] [security2:error] [pid 1025331:tid 1025566] [client 77.110.127.138:56540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE0Ou5aQNSViFaxM30gAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:19.647984 2026] [security2:error] [pid 1020501:tid 1020670] [client 57.141.18.47:56506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZD8S_oRsP4jdONhfycgAAJX0"]
[Mon Jul 20 06:48:19.740743 2026] [security2:error] [pid 1025331:tid 1025561] [client 157.85.211.87:24320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZE0Ou5aQNSViFaxM31AAAAW4"]
[Mon Jul 20 06:48:19.740852 2026] [security2:error] [pid 1025331:tid 1025561] [client 157.85.211.87:24320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZE0Ou5aQNSViFaxM31AAAAW4"]
[Mon Jul 20 06:48:19.808352 2026] [security2:error] [pid 1025331:tid 1025587] [client 77.110.127.138:56542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE0Ou5aQNSViFaxM31wAAAYg"]
[Mon Jul 20 06:48:19.808509 2026] [security2:error] [pid 1025331:tid 1025587] [client 77.110.127.138:56542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZE0Ou5aQNSViFaxM31wAAAYg"]
[Mon Jul 20 06:48:19.855475 2026] [security2:error] [pid 1025331:tid 1025556] [client 112.208.70.94:45134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZE0Ou5aQNSViFaxM32QAAAWk"]
[Mon Jul 20 06:48:19.855617 2026] [security2:error] [pid 1025331:tid 1025556] [client 112.208.70.94:45134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZE0Ou5aQNSViFaxM32QAAAWk"]
[Mon Jul 20 06:48:19.910497 2026] [security2:error] [pid 1025331:tid 1025564] [client 14.225.17.146:51274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4ZE0Ou5aQNSViFaxM31QAAAXE"], referer: http://carolinapressurewashers.com/New
[Mon Jul 20 06:48:20.025333 2026] [security2:error] [pid 1020501:tid 1020748] [client 77.110.127.138:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZFMS_oRsP4jdONhfzVAAAAHM"]
[Mon Jul 20 06:48:20.025508 2026] [security2:error] [pid 1020501:tid 1020748] [client 77.110.127.138:56483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZFMS_oRsP4jdONhfzVAAAAHM"]
[Mon Jul 20 06:48:20.163804 2026] [security2:error] [pid 1020501:tid 1020673] [client 192.140.149.97:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZFMS_oRsP4jdONhfzYAAAACg"]
[Mon Jul 20 06:48:20.163921 2026] [security2:error] [pid 1020501:tid 1020673] [client 192.140.149.97:44712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZFMS_oRsP4jdONhfzYAAAACg"]
[Mon Jul 20 06:48:20.202727 2026] [security2:error] [pid 1020501:tid 1020725] [client 50.116.65.227:18570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZFMS_oRsP4jdONhfzYgAAAFw"]
[Mon Jul 20 06:48:20.214211 2026] [security2:error] [pid 1020501:tid 1020646] [client 50.116.65.227:18582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZFMS_oRsP4jdONhfzZAAAAA0"]
[Mon Jul 20 06:48:20.391576 2026] [security2:error] [pid 1025331:tid 1025471] [client 202.46.92.242:54571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZFEOu5aQNSViFaxM39gAAARQ"]
[Mon Jul 20 06:48:20.391707 2026] [security2:error] [pid 1025331:tid 1025471] [client 202.46.92.242:54571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZFEOu5aQNSViFaxM39gAAARQ"]
[Mon Jul 20 06:48:20.486570 2026] [security2:error] [pid 1020501:tid 1020657] [client 34.73.38.214:60304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZFMS_oRsP4jdONhfzcQAAABg"]
[Mon Jul 20 06:48:20.508468 2026] [security2:error] [pid 1025331:tid 1025468] [client 57.141.18.9:45536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZEEOu5aQNSViFaxM3YwABEX8"]
[Mon Jul 20 06:48:20.738353 2026] [security2:error] [pid 1020501:tid 1020730] [client 50.116.65.227:18610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZFMS_oRsP4jdONhfzdQAAAGE"]
[Mon Jul 20 06:48:20.925501 2026] [security2:error] [pid 1025331:tid 1025549] [client 50.116.65.227:18624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZFEOu5aQNSViFaxM3_QAAAWI"]
[Mon Jul 20 06:48:20.967067 2026] [security2:error] [pid 1020501:tid 1020718] [client 103.238.106.162:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZFMS_oRsP4jdONhfzjAAAAFU"]
[Mon Jul 20 06:48:20.967169 2026] [security2:error] [pid 1020501:tid 1020718] [client 103.238.106.162:63950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZFMS_oRsP4jdONhfzjAAAAFU"]
[Mon Jul 20 06:48:21.062854 2026] [security2:error] [pid 1025331:tid 1025571] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZFEOu5aQNSViFaxM4AwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:21.135194 2026] [security2:error] [pid 1025331:tid 1025490] [client 57.141.18.38:49600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZEEOu5aQNSViFaxM3bgABJwA"]
[Mon Jul 20 06:48:21.283059 2026] [security2:error] [pid 1020501:tid 1020681] [client 14.225.17.146:51322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4ZEsS_oRsP4jdONhfzGwAAADA"], referer: http://oldracelimited.com/New
[Mon Jul 20 06:48:21.604476 2026] [security2:error] [pid 1020501:tid 1020693] [client 34.73.38.214:60304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZFcS_oRsP4jdONhfzugAAADw"]
[Mon Jul 20 06:48:21.680167 2026] [security2:error] [pid 1020501:tid 1020662] [client 50.116.65.227:18644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4ZFcS_oRsP4jdONhfzsAAAAB0"]
[Mon Jul 20 06:48:21.746757 2026] [security2:error] [pid 1020501:tid 1020514] [remote 57.141.18.18:47464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4ZFcS_oRsP4jdONhfzwwAANgo"]
[Mon Jul 20 06:48:21.756896 2026] [security2:error] [pid 1020501:tid 1020677] [client 217.142.18.172:61556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZFcS_oRsP4jdONhfzxAAAACw"]
[Mon Jul 20 06:48:21.760951 2026] [security2:error] [pid 1020501:tid 1020677] [client 217.142.18.172:61556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZFcS_oRsP4jdONhfzxAAAACw"]
[Mon Jul 20 06:48:21.843033 2026] [security2:error] [pid 1025331:tid 1025480] [client 50.116.65.227:18656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4ZFUOu5aQNSViFaxM4EwAAAR0"]
[Mon Jul 20 06:48:21.876239 2026] [security2:error] [pid 1025331:tid 1025493] [client 34.73.38.214:56215] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZFUOu5aQNSViFaxM4FAAAASo"]
[Mon Jul 20 06:48:21.913232 2026] [security2:error] [pid 1025331:tid 1025477] [client 77.110.127.138:56565] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 294 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZFUOu5aQNSViFaxM4FwAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:22.308213 2026] [security2:error] [pid 1025331:tid 1025544] [client 104.234.53.53:22997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZFkOu5aQNSViFaxM4KAAAAV0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:22.454620 2026] [security2:error] [pid 1020501:tid 1020714] [client 193.37.252.163:52104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ZFsS_oRsP4jdONhfz2wAAAFE"]
[Mon Jul 20 06:48:22.454723 2026] [security2:error] [pid 1020501:tid 1020714] [client 193.37.252.163:52104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ZFsS_oRsP4jdONhfz2wAAAFE"]
[Mon Jul 20 06:48:22.511518 2026] [security2:error] [pid 1025331:tid 1025366] [remote 81.173.115.7:48108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZFkOu5aQNSViFaxM4LQABPCI"]
[Mon Jul 20 06:48:22.511818 2026] [security2:error] [pid 1025331:tid 1025511] [client 81.173.115.7:48108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZFkOu5aQNSViFaxM4LQABPCI"]
[Mon Jul 20 06:48:22.535261 2026] [security2:error] [pid 1020501:tid 1020693] [client 34.73.38.214:50483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZFsS_oRsP4jdONhfz4gAAADw"]
[Mon Jul 20 06:48:22.548487 2026] [security2:error] [pid 1020501:tid 1020678] [client 57.141.18.30:50026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZEsS_oRsP4jdONhfzDgAALWk"]
[Mon Jul 20 06:48:22.640834 2026] [security2:error] [pid 1025331:tid 1025510] [client 45.157.112.60:21229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZFkOu5aQNSViFaxM4MwAAATs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:48:22.706294 2026] [security2:error] [pid 1020501:tid 1020576] [remote 45.90.123.233:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZFsS_oRsP4jdONhfz6wAAckg"]
[Mon Jul 20 06:48:22.745557 2026] [security2:error] [pid 1020501:tid 1020555] [remote 192.241.143.148:35302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZFsS_oRsP4jdONhfz7gAAejM"]
[Mon Jul 20 06:48:22.745725 2026] [security2:error] [pid 1020501:tid 1020755] [client 192.241.143.148:35302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZFsS_oRsP4jdONhfz7gAAejM"]
[Mon Jul 20 06:48:22.918202 2026] [security2:error] [pid 1020501:tid 1020591] [remote 45.90.123.233:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZFsS_oRsP4jdONhfz-AAAcFc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:48:22.925738 2026] [security2:error] [pid 1025331:tid 1025562] [client 159.69.158.189:23494] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4ZFkOu5aQNSViFaxM4LwAAAW8"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:48:22.977229 2026] [security2:error] [pid 1020501:tid 1020732] [client 197.186.66.42:54659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZFsS_oRsP4jdONhfz_wAAAGM"]
[Mon Jul 20 06:48:22.983186 2026] [security2:error] [pid 1020501:tid 1020732] [client 197.186.66.42:54659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZFsS_oRsP4jdONhfz_wAAAGM"]
[Mon Jul 20 06:48:23.062816 2026] [proxy:error] [pid 1020501:tid 1020748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:23.062883 2026] [proxy_http:error] [pid 1020501:tid 1020748] [client 193.47.62.167:43776] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:23.063374 2026] [proxy:error] [pid 1020501:tid 1020748] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:23.063402 2026] [proxy_http:error] [pid 1020501:tid 1020748] [client 193.47.62.167:43776] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:23.298597 2026] [security2:error] [pid 1025331:tid 1025499] [client 34.73.38.214:63631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZF0Ou5aQNSViFaxM4SgAAATA"]
[Mon Jul 20 06:48:23.399984 2026] [security2:error] [pid 1025331:tid 1025556] [client 187.108.85.186:64531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZF0Ou5aQNSViFaxM4TwAAAWk"]
[Mon Jul 20 06:48:23.400141 2026] [security2:error] [pid 1025331:tid 1025556] [client 187.108.85.186:64531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZF0Ou5aQNSViFaxM4TwAAAWk"]
[Mon Jul 20 06:48:23.416426 2026] [security2:error] [pid 1020501:tid 1020676] [client 57.141.18.22:56138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZE8S_oRsP4jdONhfzNgAAKyY"]
[Mon Jul 20 06:48:23.474334 2026] [security2:error] [pid 1025331:tid 1025480] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4ZF0Ou5aQNSViFaxM4TAAAAR0"]
[Mon Jul 20 06:48:23.527379 2026] [security2:error] [pid 1020501:tid 1020692] [client 14.225.17.146:57878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ZF8S_oRsP4jdONhf0FgAAADs"]
[Mon Jul 20 06:48:23.539469 2026] [security2:error] [pid 1020501:tid 1020687] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-post-data.php"] [unique_id "al4ZF8S_oRsP4jdONhf0HgAAADY"]
[Mon Jul 20 06:48:23.539562 2026] [security2:error] [pid 1020501:tid 1020687] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-post-data.php"] [unique_id "al4ZF8S_oRsP4jdONhf0HgAAADY"]
[Mon Jul 20 06:48:23.705534 2026] [proxy:error] [pid 1020501:tid 1020732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:23.705610 2026] [proxy_http:error] [pid 1020501:tid 1020732] [client 34.73.38.214:62656] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:23.705785 2026] [security2:error] [pid 1025331:tid 1025585] [client 46.110.96.34:21722] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZF0Ou5aQNSViFaxM4VQAAAYY"]
[Mon Jul 20 06:48:23.706190 2026] [proxy:error] [pid 1020501:tid 1020732] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:23.706229 2026] [proxy_http:error] [pid 1020501:tid 1020732] [client 34.73.38.214:62656] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:23.919898 2026] [security2:error] [pid 1020501:tid 1020714] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/pucci.php"] [unique_id "al4ZF8S_oRsP4jdONhf0NwAAAFE"]
[Mon Jul 20 06:48:23.920012 2026] [security2:error] [pid 1020501:tid 1020714] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/pucci.php"] [unique_id "al4ZF8S_oRsP4jdONhf0NwAAAFE"]
[Mon Jul 20 06:48:23.932245 2026] [security2:error] [pid 1025331:tid 1025522] [client 34.73.38.214:61481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZF0Ou5aQNSViFaxM4VwAAAUc"]
[Mon Jul 20 06:48:24.156802 2026] [security2:error] [pid 1025331:tid 1025485] [client 57.141.18.111:42738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZFEOu5aQNSViFaxM34wABIhU"]
[Mon Jul 20 06:48:24.285816 2026] [security2:error] [pid 1020501:tid 1020646] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/black.php"] [unique_id "al4ZGMS_oRsP4jdONhf0SQAAAA0"]
[Mon Jul 20 06:48:24.285901 2026] [security2:error] [pid 1020501:tid 1020646] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/black.php"] [unique_id "al4ZGMS_oRsP4jdONhf0SQAAAA0"]
[Mon Jul 20 06:48:24.330103 2026] [security2:error] [pid 1025331:tid 1025497] [client 34.139.11.221:55688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.membresiabeyou.com"] [uri "/xmlrpc.php"] [unique_id "al4ZGEOu5aQNSViFaxM4aQAAAS4"]
[Mon Jul 20 06:48:24.353816 2026] [security2:error] [pid 1025331:tid 1025582] [client 77.110.127.138:56596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZGEOu5aQNSViFaxM4awAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:24.353920 2026] [security2:error] [pid 1025331:tid 1025582] [client 77.110.127.138:56596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZGEOu5aQNSViFaxM4awAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:24.452096 2026] [proxy:error] [pid 1025331:tid 1025570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:24.452193 2026] [proxy_http:error] [pid 1025331:tid 1025570] [client 34.73.38.214:54339] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:24.453797 2026] [proxy:error] [pid 1025331:tid 1025570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:24.453856 2026] [proxy_http:error] [pid 1025331:tid 1025570] [client 34.73.38.214:54339] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:24.504147 2026] [security2:error] [pid 1020501:tid 1020647] [client 34.139.11.221:54374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGMS_oRsP4jdONhf0VAAAAA4"]
[Mon Jul 20 06:48:24.567603 2026] [security2:error] [pid 1025331:tid 1025565] [client 14.225.17.146:58026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ZGEOu5aQNSViFaxM4bAAAAXI"], referer: http://falconarrowshop.com/New
[Mon Jul 20 06:48:24.618655 2026] [security2:error] [pid 1025331:tid 1025378] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZGEOu5aQNSViFaxM4fQABNC4"]
[Mon Jul 20 06:48:24.618854 2026] [security2:error] [pid 1025331:tid 1025503] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZGEOu5aQNSViFaxM4fQABNC4"]
[Mon Jul 20 06:48:24.621857 2026] [security2:error] [pid 1025331:tid 1025508] [client 74.7.227.179:39466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZGEOu5aQNSViFaxM4cAABOSw"], referer: https://tejasenvironmental.com/p=4246
[Mon Jul 20 06:48:24.631656 2026] [security2:error] [pid 1025331:tid 1025530] [client 34.139.11.221:56047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGEOu5aQNSViFaxM4fgAAAU8"]
[Mon Jul 20 06:48:24.655201 2026] [security2:error] [pid 1025331:tid 1025493] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/zlece.php"] [unique_id "al4ZGEOu5aQNSViFaxM4gAAAASo"]
[Mon Jul 20 06:48:24.655310 2026] [security2:error] [pid 1025331:tid 1025493] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/zlece.php"] [unique_id "al4ZGEOu5aQNSViFaxM4gAAAASo"]
[Mon Jul 20 06:48:24.682905 2026] [security2:error] [pid 1020501:tid 1020674] [client 57.141.18.112:63356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZFMS_oRsP4jdONhfzcwAAKTA"]
[Mon Jul 20 06:48:24.683958 2026] [security2:error] [pid 1020501:tid 1020745] [client 34.73.38.214:61218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mochawavepublishing.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGMS_oRsP4jdONhf0XAAAAHA"]
[Mon Jul 20 06:48:24.700916 2026] [security2:error] [pid 1020501:tid 1020600] [remote 217.182.128.41:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZGMS_oRsP4jdONhf0XwAANmA"]
[Mon Jul 20 06:48:24.778824 2026] [security2:error] [pid 1025331:tid 1025556] [client 34.139.11.221:56791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGEOu5aQNSViFaxM4ggAAAWk"]
[Mon Jul 20 06:48:24.914802 2026] [security2:error] [pid 1020501:tid 1020614] [remote 217.182.128.41:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZGMS_oRsP4jdONhf0ZwAAeW4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:48:24.918400 2026] [security2:error] [pid 1025331:tid 1025509] [client 34.139.11.221:59429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGEOu5aQNSViFaxM4hQAAATo"]
[Mon Jul 20 06:48:25.006031 2026] [security2:error] [pid 1020501:tid 1020708] [client 14.225.17.146:58134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4ZGMS_oRsP4jdONhf0aAAAAEs"], referer: http://mourgroup.com/New
[Mon Jul 20 06:48:25.024315 2026] [security2:error] [pid 1025331:tid 1025585] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/vssrs.php"] [unique_id "al4ZGUOu5aQNSViFaxM4hwAAAYY"]
[Mon Jul 20 06:48:25.024407 2026] [security2:error] [pid 1025331:tid 1025585] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/vssrs.php"] [unique_id "al4ZGUOu5aQNSViFaxM4hwAAAYY"]
[Mon Jul 20 06:48:25.088672 2026] [proxy:error] [pid 1025331:tid 1025471] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:25.088775 2026] [proxy_http:error] [pid 1025331:tid 1025471] [client 34.73.38.214:59526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:25.089287 2026] [proxy:error] [pid 1025331:tid 1025471] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:25.089326 2026] [proxy_http:error] [pid 1025331:tid 1025471] [client 34.73.38.214:59526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:25.093258 2026] [security2:error] [pid 1025331:tid 1025540] [client 34.139.11.221:57926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGUOu5aQNSViFaxM4iQAAAVk"]
[Mon Jul 20 06:48:25.093328 2026] [security2:error] [pid 1020501:tid 1020739] [client 14.225.17.146:59394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4ZF8S_oRsP4jdONhf0MQAAAGo"], referer: http://momheadquarters.com/New
[Mon Jul 20 06:48:25.248596 2026] [security2:error] [pid 1020501:tid 1020641] [client 34.139.11.221:61902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGcS_oRsP4jdONhf0eQAAAAg"]
[Mon Jul 20 06:48:25.249716 2026] [security2:error] [pid 1025331:tid 1025518] [client 103.125.179.95:62381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZGUOu5aQNSViFaxM4kAAAAUM"]
[Mon Jul 20 06:48:25.249840 2026] [security2:error] [pid 1025331:tid 1025518] [client 103.125.179.95:62381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZGUOu5aQNSViFaxM4kAAAAUM"]
[Mon Jul 20 06:48:25.312816 2026] [security2:error] [pid 1020501:tid 1020705] [client 14.225.17.146:53565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4ZGMS_oRsP4jdONhf0TAAAAEg"], referer: http://claysharecon.com/New
[Mon Jul 20 06:48:25.372730 2026] [security2:error] [pid 1025331:tid 1025569] [client 34.139.11.221:64844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGUOu5aQNSViFaxM4lQAAAXY"]
[Mon Jul 20 06:48:25.403593 2026] [security2:error] [pid 1020501:tid 1020751] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wicked.php"] [unique_id "al4ZGcS_oRsP4jdONhf0fwAAAHY"]
[Mon Jul 20 06:48:25.403738 2026] [security2:error] [pid 1020501:tid 1020751] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wicked.php"] [unique_id "al4ZGcS_oRsP4jdONhf0fwAAAHY"]
[Mon Jul 20 06:48:25.404851 2026] [security2:error] [pid 1025331:tid 1025547] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZGUOu5aQNSViFaxM4jgAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:25.557113 2026] [security2:error] [pid 1025331:tid 1025538] [client 34.139.11.221:61043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGUOu5aQNSViFaxM4ngAAAVc"]
[Mon Jul 20 06:48:25.558455 2026] [security2:error] [pid 1025331:tid 1025554] [client 34.73.38.214:60862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZGUOu5aQNSViFaxM4nwAAAWc"]
[Mon Jul 20 06:48:25.652823 2026] [security2:error] [pid 1020501:tid 1020694] [client 57.141.18.20:36794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZFcS_oRsP4jdONhfzpAAAPQc"]
[Mon Jul 20 06:48:25.671446 2026] [security2:error] [pid 1025331:tid 1025482] [client 34.139.11.221:51612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGUOu5aQNSViFaxM4pgAAAR8"]
[Mon Jul 20 06:48:25.682390 2026] [security2:error] [pid 1020501:tid 1020631] [remote 160.187.68.132:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4ZGcS_oRsP4jdONhf0hwAAMH8"]
[Mon Jul 20 06:48:25.689719 2026] [security2:error] [pid 1020501:tid 1020709] [client 14.251.3.155:54713] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZGcS_oRsP4jdONhf0igAAAEw"]
[Mon Jul 20 06:48:25.752777 2026] [security2:error] [pid 1020501:tid 1020612] [remote 192.241.143.148:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZGcS_oRsP4jdONhf0jgAABWw"]
[Mon Jul 20 06:48:25.784035 2026] [security2:error] [pid 1025331:tid 1025534] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/24.php"] [unique_id "al4ZGUOu5aQNSViFaxM4qgAAAVM"]
[Mon Jul 20 06:48:25.784210 2026] [security2:error] [pid 1025331:tid 1025534] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/24.php"] [unique_id "al4ZGUOu5aQNSViFaxM4qgAAAVM"]
[Mon Jul 20 06:48:25.885667 2026] [security2:error] [pid 1025331:tid 1025517] [client 34.139.11.221:62822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGUOu5aQNSViFaxM4rAAAAUI"]
[Mon Jul 20 06:48:25.926621 2026] [security2:error] [pid 1020501:tid 1020504] [remote 192.241.143.148:35304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZGcS_oRsP4jdONhf0lAAAJgA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:48:25.985365 2026] [security2:error] [pid 1025331:tid 1025383] [remote 103.118.29.185:5676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4ZGUOu5aQNSViFaxM4sAABWzM"]
[Mon Jul 20 06:48:26.036903 2026] [security2:error] [pid 1025331:tid 1025568] [client 34.139.11.221:57635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.membresiabeyou.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGkOu5aQNSViFaxM4tAAAAXU"]
[Mon Jul 20 06:48:26.160801 2026] [security2:error] [pid 1025331:tid 1025484] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xacs.php"] [unique_id "al4ZGkOu5aQNSViFaxM4twAAASE"]
[Mon Jul 20 06:48:26.160888 2026] [security2:error] [pid 1025331:tid 1025484] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xacs.php"] [unique_id "al4ZGkOu5aQNSViFaxM4twAAASE"]
[Mon Jul 20 06:48:26.203349 2026] [security2:error] [pid 1020501:tid 1020530] [remote 160.187.68.132:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4ZGsS_oRsP4jdONhf0nAAAWxo"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:48:26.229966 2026] [security2:error] [pid 1025331:tid 1025469] [client 77.110.127.138:56616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 811 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZGkOu5aQNSViFaxM4vAAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:26.256031 2026] [security2:error] [pid 1020501:tid 1020649] [client 34.73.38.214:63975] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGsS_oRsP4jdONhf0ogAAABA"]
[Mon Jul 20 06:48:26.398830 2026] [security2:error] [pid 1025331:tid 1025388] [remote 103.118.29.185:5676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4ZGkOu5aQNSViFaxM4wgABYzg"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:48:26.510463 2026] [security2:error] [pid 1025331:tid 1025567] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/zildan.php"] [unique_id "al4ZGkOu5aQNSViFaxM4xgAAAXQ"]
[Mon Jul 20 06:48:26.510597 2026] [security2:error] [pid 1025331:tid 1025567] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/zildan.php"] [unique_id "al4ZGkOu5aQNSViFaxM4xgAAAXQ"]
[Mon Jul 20 06:48:26.589441 2026] [security2:error] [pid 1025331:tid 1025537] [client 34.73.38.214:54218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZGkOu5aQNSViFaxM4yAAAAVY"]
[Mon Jul 20 06:48:26.695557 2026] [security2:error] [pid 1025331:tid 1025531] [client 14.225.17.146:59833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4ZGkOu5aQNSViFaxM4xwAAAVA"], referer: http://blaizeaccountingservices.com/New
[Mon Jul 20 06:48:26.882447 2026] [security2:error] [pid 1025331:tid 1025563] [client 57.141.18.114:47442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZFkOu5aQNSViFaxM4NwABcCQ"]
[Mon Jul 20 06:48:26.891418 2026] [security2:error] [pid 1025331:tid 1025491] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/csa.php"] [unique_id "al4ZGkOu5aQNSViFaxM4ywAAASg"]
[Mon Jul 20 06:48:26.891533 2026] [security2:error] [pid 1025331:tid 1025491] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/csa.php"] [unique_id "al4ZGkOu5aQNSViFaxM4ywAAASg"]
[Mon Jul 20 06:48:27.080893 2026] [security2:error] [pid 1020501:tid 1020741] [client 66.249.82.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kgsnsteel.com"] [uri "/index.php"] [unique_id "al4ZF8S_oRsP4jdONhf0NQAAbG0"]
[Mon Jul 20 06:48:27.123662 2026] [security2:error] [pid 1025331:tid 1025561] [client 34.73.38.214:59918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZG0Ou5aQNSViFaxM43AAAAW4"]
[Mon Jul 20 06:48:27.127071 2026] [security2:error] [pid 1025331:tid 1025485] [client 14.225.17.146:57951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4ZGUOu5aQNSViFaxM4qAAAASI"], referer: http://expertcultures.com/New
[Mon Jul 20 06:48:27.168008 2026] [security2:error] [pid 1025331:tid 1025560] [client 57.141.18.47:44290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZFkOu5aQNSViFaxM4PgABbSY"]
[Mon Jul 20 06:48:27.247981 2026] [security2:error] [pid 1020501:tid 1020681] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/w3llscc.php"] [unique_id "al4ZG8S_oRsP4jdONhf0wgAAADA"]
[Mon Jul 20 06:48:27.248082 2026] [security2:error] [pid 1020501:tid 1020681] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/w3llscc.php"] [unique_id "al4ZG8S_oRsP4jdONhf0wgAAADA"]
[Mon Jul 20 06:48:27.379479 2026] [security2:error] [pid 1025331:tid 1025572] [client 223.185.13.213:10265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZG0Ou5aQNSViFaxM45QAAAXk"]
[Mon Jul 20 06:48:27.379588 2026] [security2:error] [pid 1025331:tid 1025572] [client 223.185.13.213:10265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZG0Ou5aQNSViFaxM45QAAAXk"]
[Mon Jul 20 06:48:27.640475 2026] [security2:error] [pid 1025331:tid 1025585] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wpx.php"] [unique_id "al4ZG0Ou5aQNSViFaxM47gAAAYY"]
[Mon Jul 20 06:48:27.640620 2026] [security2:error] [pid 1025331:tid 1025585] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wpx.php"] [unique_id "al4ZG0Ou5aQNSViFaxM47gAAAYY"]
[Mon Jul 20 06:48:27.672152 2026] [security2:error] [pid 1025331:tid 1025568] [client 104.234.53.85:24521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZG0Ou5aQNSViFaxM46QAAAXU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:27.737926 2026] [security2:error] [pid 1025331:tid 1025468] [client 34.73.38.214:53277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZG0Ou5aQNSViFaxM48wAAARE"]
[Mon Jul 20 06:48:27.924767 2026] [security2:error] [pid 1020501:tid 1020697] [client 37.52.210.45:7529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZG8S_oRsP4jdONhf07AAAAEA"]
[Mon Jul 20 06:48:27.924862 2026] [security2:error] [pid 1020501:tid 1020697] [client 37.52.210.45:7529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZG8S_oRsP4jdONhf07AAAAEA"]
[Mon Jul 20 06:48:27.987871 2026] [security2:error] [pid 1025331:tid 1025545] [client 77.110.127.138:56635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZG0Ou5aQNSViFaxM49wAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:27.987983 2026] [security2:error] [pid 1025331:tid 1025545] [client 77.110.127.138:56635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZG0Ou5aQNSViFaxM49wAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.022360 2026] [security2:error] [pid 1025331:tid 1025540] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-css.php"] [unique_id "al4ZHEOu5aQNSViFaxM4-AAAAVk"]
[Mon Jul 20 06:48:28.022498 2026] [security2:error] [pid 1025331:tid 1025540] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-css.php"] [unique_id "al4ZHEOu5aQNSViFaxM4-AAAAVk"]
[Mon Jul 20 06:48:28.074060 2026] [security2:error] [pid 1020501:tid 1020684] [client 57.141.18.12:64664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZF8S_oRsP4jdONhf0MgAAM0E"]
[Mon Jul 20 06:48:28.078697 2026] [security2:error] [pid 1025331:tid 1025395] [remote 57.141.18.44:47730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3579229"] [unique_id "al4ZHEOu5aQNSViFaxM4-wABNj8"]
[Mon Jul 20 06:48:28.172984 2026] [security2:error] [pid 1025331:tid 1025574] [client 77.110.127.138:56639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHEOu5aQNSViFaxM4_gAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.173097 2026] [security2:error] [pid 1025331:tid 1025574] [client 77.110.127.138:56639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHEOu5aQNSViFaxM4_gAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.218182 2026] [security2:error] [pid 1025331:tid 1025550] [client 14.225.17.146:58090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4ZHEOu5aQNSViFaxM4-gAAAWM"], referer: http://swafforddetailing.com/New
[Mon Jul 20 06:48:28.356443 2026] [security2:error] [pid 1025331:tid 1025560] [client 34.73.38.214:53294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHEOu5aQNSViFaxM5CwAAAW0"]
[Mon Jul 20 06:48:28.408882 2026] [security2:error] [pid 1025331:tid 1025530] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/alfa_shell_4.1.php"] [unique_id "al4ZHEOu5aQNSViFaxM5DgAAAU8"]
[Mon Jul 20 06:48:28.409044 2026] [security2:error] [pid 1025331:tid 1025530] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/alfa_shell_4.1.php"] [unique_id "al4ZHEOu5aQNSViFaxM5DgAAAU8"]
[Mon Jul 20 06:48:28.434035 2026] [security2:error] [pid 1025331:tid 1025543] [client 104.234.53.85:24521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZHEOu5aQNSViFaxM5DwAAAVw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:28.460996 2026] [security2:error] [pid 1020501:tid 1020637] [client 77.110.127.138:56643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHMS_oRsP4jdONhf1BAAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.461083 2026] [security2:error] [pid 1020501:tid 1020637] [client 77.110.127.138:56643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHMS_oRsP4jdONhf1BAAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.538818 2026] [security2:error] [pid 1025331:tid 1025484] [client 34.73.38.214:55442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHEOu5aQNSViFaxM5FgAAASE"]
[Mon Jul 20 06:48:28.566177 2026] [security2:error] [pid 1025331:tid 1025585] [client 77.110.127.138:56581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHEOu5aQNSViFaxM5GwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.566284 2026] [security2:error] [pid 1025331:tid 1025585] [client 77.110.127.138:56581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHEOu5aQNSViFaxM5GwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.571740 2026] [security2:error] [pid 1025331:tid 1025399] [remote 188.166.241.141:44312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZHEOu5aQNSViFaxM5HAABM0M"]
[Mon Jul 20 06:48:28.571926 2026] [security2:error] [pid 1025331:tid 1025502] [client 188.166.241.141:44312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZHEOu5aQNSViFaxM5HAABM0M"]
[Mon Jul 20 06:48:28.643725 2026] [security2:error] [pid 1020501:tid 1020666] [client 77.110.127.138:56588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHMS_oRsP4jdONhf1DgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.643840 2026] [security2:error] [pid 1020501:tid 1020666] [client 77.110.127.138:56588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHMS_oRsP4jdONhf1DgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.701386 2026] [security2:error] [pid 1020501:tid 1020734] [client 57.141.18.13:31986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZGMS_oRsP4jdONhf0SwAAZQs"]
[Mon Jul 20 06:48:28.772637 2026] [security2:error] [pid 1025331:tid 1025400] [remote 72.167.132.114:58288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4ZHEOu5aQNSViFaxM5IAABcUQ"]
[Mon Jul 20 06:48:28.807872 2026] [security2:error] [pid 1025331:tid 1025483] [client 117.247.108.24:12539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZHEOu5aQNSViFaxM5IQAAASA"]
[Mon Jul 20 06:48:28.808006 2026] [security2:error] [pid 1025331:tid 1025483] [client 117.247.108.24:12539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZHEOu5aQNSViFaxM5IQAAASA"]
[Mon Jul 20 06:48:28.822252 2026] [security2:error] [pid 1025331:tid 1025469] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ho.php"] [unique_id "al4ZHEOu5aQNSViFaxM5IwAAARI"]
[Mon Jul 20 06:48:28.822348 2026] [security2:error] [pid 1025331:tid 1025469] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ho.php"] [unique_id "al4ZHEOu5aQNSViFaxM5IwAAARI"]
[Mon Jul 20 06:48:28.839948 2026] [security2:error] [pid 1020501:tid 1020636] [client 77.110.127.138:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHMS_oRsP4jdONhf1GQAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.840034 2026] [security2:error] [pid 1020501:tid 1020636] [client 77.110.127.138:56649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHMS_oRsP4jdONhf1GQAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.880042 2026] [security2:error] [pid 1025331:tid 1025562] [client 106.219.188.178:15835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZHEOu5aQNSViFaxM5JQAAAW8"]
[Mon Jul 20 06:48:28.880231 2026] [security2:error] [pid 1025331:tid 1025562] [client 106.219.188.178:15835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZHEOu5aQNSViFaxM5JQAAAW8"]
[Mon Jul 20 06:48:28.943717 2026] [security2:error] [pid 1025331:tid 1025526] [client 77.110.127.138:56591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHEOu5aQNSViFaxM5JwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.943860 2026] [security2:error] [pid 1025331:tid 1025526] [client 77.110.127.138:56591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZHEOu5aQNSViFaxM5JwAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.953582 2026] [security2:error] [pid 1025331:tid 1025539] [client 14.225.17.146:59795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4ZHEOu5aQNSViFaxM5JgAAAVg"], referer: http://thefriendlyspreadsheet.com/New
[Mon Jul 20 06:48:28.971584 2026] [security2:error] [pid 1020501:tid 1020698] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZHMS_oRsP4jdONhf1FQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:28.986775 2026] [security2:error] [pid 1020501:tid 1020733] [client 34.73.38.214:53277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHMS_oRsP4jdONhf1HwAAAGQ"]
[Mon Jul 20 06:48:29.025891 2026] [security2:error] [pid 1025331:tid 1025402] [remote 72.167.132.114:58288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4ZHUOu5aQNSViFaxM5KgABQEY"], referer: https://claysharecon.com/wp-login.php
[Mon Jul 20 06:48:29.216418 2026] [security2:error] [pid 1020501:tid 1020681] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xy.php"] [unique_id "al4ZHcS_oRsP4jdONhf1KAAAADA"]
[Mon Jul 20 06:48:29.216541 2026] [security2:error] [pid 1020501:tid 1020681] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xy.php"] [unique_id "al4ZHcS_oRsP4jdONhf1KAAAADA"]
[Mon Jul 20 06:48:29.247700 2026] [security2:error] [pid 1020501:tid 1020744] [client 34.73.38.214:60294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHcS_oRsP4jdONhf1KwAAAG8"]
[Mon Jul 20 06:48:29.551064 2026] [security2:error] [pid 1020501:tid 1020738] [client 14.225.17.146:59919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4ZHMS_oRsP4jdONhf1CAAAAGk"]
[Mon Jul 20 06:48:29.574341 2026] [security2:error] [pid 1025331:tid 1025495] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/loader.php"] [unique_id "al4ZHUOu5aQNSViFaxM5PwAAASw"]
[Mon Jul 20 06:48:29.574434 2026] [security2:error] [pid 1025331:tid 1025495] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/loader.php"] [unique_id "al4ZHUOu5aQNSViFaxM5PwAAASw"]
[Mon Jul 20 06:48:29.620494 2026] [security2:error] [pid 1020501:tid 1020736] [client 34.73.38.214:60545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHcS_oRsP4jdONhf1RAAAAGc"]
[Mon Jul 20 06:48:29.734485 2026] [security2:error] [pid 1025331:tid 1025484] [client 77.110.127.138:56607] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 297 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZHUOu5aQNSViFaxM5RQAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:29.769521 2026] [security2:error] [pid 1020501:tid 1020685] [client 57.141.18.105:34204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZGcS_oRsP4jdONhf0iAAANHM"]
[Mon Jul 20 06:48:29.928520 2026] [security2:error] [pid 1025331:tid 1025486] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/spadex.php"] [unique_id "al4ZHUOu5aQNSViFaxM5UgAAASM"]
[Mon Jul 20 06:48:29.928655 2026] [security2:error] [pid 1025331:tid 1025486] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/spadex.php"] [unique_id "al4ZHUOu5aQNSViFaxM5UgAAASM"]
[Mon Jul 20 06:48:30.138274 2026] [security2:error] [pid 1025331:tid 1025412] [remote 81.173.115.7:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4ZHkOu5aQNSViFaxM5XgABIlA"]
[Mon Jul 20 06:48:30.208993 2026] [security2:error] [pid 1025331:tid 1025562] [client 216.73.217.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.metodoshanti.com"] [uri "/index.php"] [unique_id "al4ZHkOu5aQNSViFaxM5XAABb04"]
[Mon Jul 20 06:48:30.219371 2026] [ssl:error] [pid 1020501:tid 1020644] [client 104.48.69.105:58568] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:48:30.274959 2026] [security2:error] [pid 1020501:tid 1020724] [client 151.123.176.66:49349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZHsS_oRsP4jdONhf1WQAAAFs"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:30.306520 2026] [security2:error] [pid 1025331:tid 1025578] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/2x.php"] [unique_id "al4ZHkOu5aQNSViFaxM5ZgAAAX8"]
[Mon Jul 20 06:48:30.306646 2026] [security2:error] [pid 1025331:tid 1025578] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/2x.php"] [unique_id "al4ZHkOu5aQNSViFaxM5ZgAAAX8"]
[Mon Jul 20 06:48:30.341202 2026] [security2:error] [pid 1025331:tid 1025567] [client 14.225.17.146:61400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4ZHUOu5aQNSViFaxM5MgAAAXQ"], referer: http://northbrookcpa.ca/New
[Mon Jul 20 06:48:30.371970 2026] [security2:error] [pid 1020501:tid 1020633] [client 34.73.38.214:60550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHsS_oRsP4jdONhf1XAAAAAA"]
[Mon Jul 20 06:48:30.382852 2026] [security2:error] [pid 1025331:tid 1025414] [remote 81.173.115.7:42404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4ZHkOu5aQNSViFaxM5bQABiVI"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:48:30.452906 2026] [security2:error] [pid 1020501:tid 1020641] [client 112.208.70.94:45554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.70.208.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZHsS_oRsP4jdONhf1YwAAAAg"]
[Mon Jul 20 06:48:30.453092 2026] [security2:error] [pid 1020501:tid 1020641] [client 112.208.70.94:45554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZHsS_oRsP4jdONhf1YwAAAAg"]
[Mon Jul 20 06:48:30.772035 2026] [security2:error] [pid 1020501:tid 1020688] [client 34.73.38.214:52499] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.mpp.jej.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZHsS_oRsP4jdONhf1bAAAADc"]
[Mon Jul 20 06:48:31.007280 2026] [security2:error] [pid 1025331:tid 1025421] [remote 81.173.115.7:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5fwABNVk"]
[Mon Jul 20 06:48:31.017202 2026] [security2:error] [pid 1025331:tid 1025551] [client 57.141.18.64:61960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZGkOu5aQNSViFaxM40gABZDk"]
[Mon Jul 20 06:48:31.110320 2026] [security2:error] [pid 1025331:tid 1025422] [remote 103.187.169.251:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5gAABW1o"]
[Mon Jul 20 06:48:31.253477 2026] [security2:error] [pid 1025331:tid 1025487] [client 36.95.228.227:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5hgAAASQ"]
[Mon Jul 20 06:48:31.253611 2026] [security2:error] [pid 1025331:tid 1025487] [client 36.95.228.227:55043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5hgAAASQ"]
[Mon Jul 20 06:48:31.275919 2026] [security2:error] [pid 1025331:tid 1025518] [client 181.191.65.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4ZHUOu5aQNSViFaxM5VQAAAUM"]
[Mon Jul 20 06:48:31.350150 2026] [security2:error] [pid 1020501:tid 1020660] [client 14.225.17.146:61457] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4ZHMS_oRsP4jdONhf1HQAAABs"], referer: http://drewsasburyparkbeachhouse.com/New
[Mon Jul 20 06:48:31.354097 2026] [security2:error] [pid 1025331:tid 1025520] [client 157.85.211.87:30028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5iwAAAUU"]
[Mon Jul 20 06:48:31.354235 2026] [security2:error] [pid 1025331:tid 1025520] [client 157.85.211.87:30028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5iwAAAUU"]
[Mon Jul 20 06:48:31.459416 2026] [security2:error] [pid 1025331:tid 1025426] [remote 81.173.115.7:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5jQABD14"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:48:31.469159 2026] [security2:error] [pid 1020501:tid 1020714] [client 103.238.106.162:42771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZH8S_oRsP4jdONhf1jgAAAFE"]
[Mon Jul 20 06:48:31.469293 2026] [security2:error] [pid 1020501:tid 1020714] [client 103.238.106.162:42771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZH8S_oRsP4jdONhf1jgAAAFE"]
[Mon Jul 20 06:48:31.561956 2026] [security2:error] [pid 1025331:tid 1025427] [remote 103.187.169.251:57198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5jwABXl8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:48:31.578446 2026] [security2:error] [pid 1025331:tid 1025462] [client 13.233.207.33:38800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5kQAAAQs"]
[Mon Jul 20 06:48:32.055617 2026] [security2:error] [pid 1025331:tid 1025544] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ctex1.php"] [unique_id "al4ZIEOu5aQNSViFaxM5sAAAAV0"]
[Mon Jul 20 06:48:32.055725 2026] [security2:error] [pid 1025331:tid 1025544] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ctex1.php"] [unique_id "al4ZIEOu5aQNSViFaxM5sAAAAV0"]
[Mon Jul 20 06:48:32.258281 2026] [security2:error] [pid 1020501:tid 1020685] [client 14.225.17.146:61150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4ZH8S_oRsP4jdONhf1fgAAADQ"]
[Mon Jul 20 06:48:32.282839 2026] [security2:error] [pid 1025331:tid 1025470] [client 217.142.18.172:65259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZIEOu5aQNSViFaxM5vQAAARM"]
[Mon Jul 20 06:48:32.282952 2026] [security2:error] [pid 1025331:tid 1025470] [client 217.142.18.172:65259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZIEOu5aQNSViFaxM5vQAAARM"]
[Mon Jul 20 06:48:32.426895 2026] [security2:error] [pid 1025331:tid 1025555] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/edorxrr.php"] [unique_id "al4ZIEOu5aQNSViFaxM5yQAAAWg"]
[Mon Jul 20 06:48:32.426999 2026] [security2:error] [pid 1025331:tid 1025555] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/edorxrr.php"] [unique_id "al4ZIEOu5aQNSViFaxM5yQAAAWg"]
[Mon Jul 20 06:48:32.610119 2026] [security2:error] [pid 1025331:tid 1025481] [client 57.141.18.3:53338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZHEOu5aQNSViFaxM5GAABHkI"]
[Mon Jul 20 06:48:32.612444 2026] [security2:error] [pid 1020501:tid 1020671] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZIMS_oRsP4jdONhf1pAAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:32.825958 2026] [security2:error] [pid 1025331:tid 1025530] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/miru1.php"] [unique_id "al4ZIEOu5aQNSViFaxM51QAAAU8"]
[Mon Jul 20 06:48:32.826083 2026] [security2:error] [pid 1025331:tid 1025530] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/miru1.php"] [unique_id "al4ZIEOu5aQNSViFaxM51QAAAU8"]
[Mon Jul 20 06:48:32.852727 2026] [security2:error] [pid 1025331:tid 1025549] [client 65.1.132.125:34270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZIEOu5aQNSViFaxM51gAAAWI"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:48:33.121444 2026] [security2:error] [pid 1025331:tid 1025468] [client 114.119.144.42:57493] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "itekphonerepair.com"] [uri "/"] [unique_id "al4ZIUOu5aQNSViFaxM53QAAARE"], referer: https://www.32w.top/ywlljjsa/%E5%A4%A7%E7%A8%AE%E9%A6%AC%E8%A8%88%E5%8A%83-6207641753/
[Mon Jul 20 06:48:33.177677 2026] [security2:error] [pid 1025331:tid 1025445] [remote 199.189.225.40:31483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZIUOu5aQNSViFaxM54gABZHE"]
[Mon Jul 20 06:48:33.218342 2026] [security2:error] [pid 1020501:tid 1020644] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/sump1.php"] [unique_id "al4ZIcS_oRsP4jdONhf1uwAAAAs"]
[Mon Jul 20 06:48:33.218430 2026] [security2:error] [pid 1020501:tid 1020644] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/sump1.php"] [unique_id "al4ZIcS_oRsP4jdONhf1uwAAAAs"]
[Mon Jul 20 06:48:33.302149 2026] [security2:error] [pid 1025331:tid 1025511] [client 57.141.18.98:29336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZHUOu5aQNSViFaxM5LgABPEg"]
[Mon Jul 20 06:48:33.367010 2026] [security2:error] [pid 1025331:tid 1025446] [remote 199.189.225.40:31483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZIUOu5aQNSViFaxM55gABS3I"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:48:33.422345 2026] [security2:error] [pid 1025331:tid 1025542] [client 74.208.214.194:50614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ZIUOu5aQNSViFaxM56QAAAVs"]
[Mon Jul 20 06:48:33.589815 2026] [security2:error] [pid 1025331:tid 1025506] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/file5.php"] [unique_id "al4ZIUOu5aQNSViFaxM56gAAATc"]
[Mon Jul 20 06:48:33.589941 2026] [security2:error] [pid 1025331:tid 1025506] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/file5.php"] [unique_id "al4ZIUOu5aQNSViFaxM56gAAATc"]
[Mon Jul 20 06:48:33.945819 2026] [security2:error] [pid 1025331:tid 1025486] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/0xD.php"] [unique_id "al4ZIUOu5aQNSViFaxM6CAAAASM"]
[Mon Jul 20 06:48:33.945928 2026] [security2:error] [pid 1025331:tid 1025486] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/0xD.php"] [unique_id "al4ZIUOu5aQNSViFaxM6CAAAASM"]
[Mon Jul 20 06:48:33.955868 2026] [security2:error] [pid 1025331:tid 1025552] [client 14.225.17.146:61099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ZIUOu5aQNSViFaxM57QAAAWU"]
[Mon Jul 20 06:48:33.986973 2026] [security2:error] [pid 1025331:tid 1025467] [client 40.77.167.132:1740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ZIUOu5aQNSViFaxM6AAABEH4"]
[Mon Jul 20 06:48:33.996424 2026] [security2:error] [pid 1025331:tid 1025530] [client 176.118.193.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "abilite.uk"] [uri "/index.php"] [unique_id "al4ZIUOu5aQNSViFaxM5-QAAAU8"]
[Mon Jul 20 06:48:34.024407 2026] [security2:error] [pid 1025331:tid 1025554] [client 187.108.85.186:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZIkOu5aQNSViFaxM6DQAAAWc"]
[Mon Jul 20 06:48:34.024502 2026] [security2:error] [pid 1025331:tid 1025554] [client 187.108.85.186:65218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZIkOu5aQNSViFaxM6DQAAAWc"]
[Mon Jul 20 06:48:34.043662 2026] [security2:error] [pid 1025331:tid 1025491] [client 77.110.127.138:56723] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZIkOu5aQNSViFaxM6EAAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:34.336281 2026] [security2:error] [pid 1020501:tid 1020760] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/fnstall.php"] [unique_id "al4ZIsS_oRsP4jdONhf13QAAAH8"]
[Mon Jul 20 06:48:34.336358 2026] [security2:error] [pid 1020501:tid 1020760] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/fnstall.php"] [unique_id "al4ZIsS_oRsP4jdONhf13QAAAH8"]
[Mon Jul 20 06:48:34.715790 2026] [security2:error] [pid 1025331:tid 1025355] [remote 182.77.62.24:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZIkOu5aQNSViFaxM6LAABexc"]
[Mon Jul 20 06:48:34.743515 2026] [security2:error] [pid 1025331:tid 1025512] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/acp.php"] [unique_id "al4ZIkOu5aQNSViFaxM6LgAAAT0"]
[Mon Jul 20 06:48:34.743591 2026] [security2:error] [pid 1025331:tid 1025512] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/acp.php"] [unique_id "al4ZIkOu5aQNSViFaxM6LgAAAT0"]
[Mon Jul 20 06:48:34.814568 2026] [security2:error] [pid 1025331:tid 1025479] [client 40.77.167.132:1740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ZIkOu5aQNSViFaxM6LQABHBQ"]
[Mon Jul 20 06:48:34.828738 2026] [security2:error] [pid 1025331:tid 1025356] [remote 173.212.252.15:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4ZIkOu5aQNSViFaxM6MQABXhg"]
[Mon Jul 20 06:48:34.990273 2026] [security2:error] [pid 1020501:tid 1020637] [client 74.208.214.194:47662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ZIsS_oRsP4jdONhf19gAAAAQ"]
[Mon Jul 20 06:48:35.020380 2026] [security2:error] [pid 1025331:tid 1025548] [client 14.225.17.146:64577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4ZIkOu5aQNSViFaxM6NwAAAWE"], referer: http://alchemygroup.ca/New
[Mon Jul 20 06:48:35.084118 2026] [security2:error] [pid 1025331:tid 1025335] [remote 173.212.252.15:37572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6PAABZAM"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:48:35.125028 2026] [security2:error] [pid 1020501:tid 1020738] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/mosty.php"] [unique_id "al4ZI8S_oRsP4jdONhf1-QAAAGk"]
[Mon Jul 20 06:48:35.125133 2026] [security2:error] [pid 1020501:tid 1020738] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/mosty.php"] [unique_id "al4ZI8S_oRsP4jdONhf1-QAAAGk"]
[Mon Jul 20 06:48:35.188818 2026] [security2:error] [pid 1025331:tid 1025580] [client 57.141.18.66:60494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZHkOu5aQNSViFaxM5fAABgVc"]
[Mon Jul 20 06:48:35.225944 2026] [security2:error] [pid 1025331:tid 1025366] [remote 103.187.169.251:47958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6QQABDiI"]
[Mon Jul 20 06:48:35.263412 2026] [security2:error] [pid 1025331:tid 1025367] [remote 182.77.62.24:34132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6QwABKSM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:48:35.348448 2026] [security2:error] [pid 1025331:tid 1025371] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6SQABhyc"]
[Mon Jul 20 06:48:35.348595 2026] [security2:error] [pid 1025331:tid 1025586] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6SQABhyc"]
[Mon Jul 20 06:48:35.532791 2026] [security2:error] [pid 1025331:tid 1025357] [remote 82.112.255.5:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.255.112.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6UwABOBk"]
[Mon Jul 20 06:48:35.575432 2026] [core:error] [pid 1025331:tid 1025520] [client 14.225.17.146:53345] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:48:35.575449 2026] [core:error] [pid 1025331:tid 1025520] [client 14.225.17.146:53345] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:48:35.667526 2026] [security2:error] [pid 1025331:tid 1025379] [remote 103.187.169.251:47958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6WwABay8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:48:35.731821 2026] [security2:error] [pid 1025331:tid 1025516] [client 14.224.227.113:58635] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZI0Ou5aQNSViFaxM6YAAAAUE"]
[Mon Jul 20 06:48:35.850575 2026] [security2:error] [pid 1025331:tid 1025383] [remote 82.112.255.5:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.255.112.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6ZgABbjM"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 06:48:36.008810 2026] [security2:error] [pid 1025331:tid 1025489] [client 103.125.179.95:62886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6dAAAASY"]
[Mon Jul 20 06:48:36.008980 2026] [security2:error] [pid 1025331:tid 1025489] [client 103.125.179.95:62886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6dAAAASY"]
[Mon Jul 20 06:48:36.108980 2026] [security2:error] [pid 1025331:tid 1025567] [client 57.141.18.97:26104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZH0Ou5aQNSViFaxM5nAABdGM"]
[Mon Jul 20 06:48:36.247709 2026] [security2:error] [pid 1020501:tid 1020684] [client 197.186.66.42:55199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZJMS_oRsP4jdONhf2EgAAADM"]
[Mon Jul 20 06:48:36.247837 2026] [security2:error] [pid 1020501:tid 1020684] [client 197.186.66.42:55199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZJMS_oRsP4jdONhf2EgAAADM"]
[Mon Jul 20 06:48:36.284847 2026] [security2:error] [pid 1020501:tid 1020656] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4ZI8S_oRsP4jdONhf2BgAAF0s"], referer: http://ali-alghanim.net/New
[Mon Jul 20 06:48:36.370318 2026] [security2:error] [pid 1020501:tid 1020670] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/6.php"] [unique_id "al4ZJMS_oRsP4jdONhf2FQAAACU"]
[Mon Jul 20 06:48:36.370425 2026] [security2:error] [pid 1020501:tid 1020670] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/6.php"] [unique_id "al4ZJMS_oRsP4jdONhf2FQAAACU"]
[Mon Jul 20 06:48:36.477960 2026] [security2:error] [pid 1025331:tid 1025546] [client 77.110.127.138:56749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZJEOu5aQNSViFaxM6iAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:36.478110 2026] [security2:error] [pid 1025331:tid 1025546] [client 77.110.127.138:56749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZJEOu5aQNSViFaxM6iAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:36.655464 2026] [ssl:error] [pid 1020501:tid 1020699] [client 104.48.69.105:58572] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:48:36.669624 2026] [security2:error] [pid 1025331:tid 1025485] [client 114.119.157.132:22135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/robots.txt"] [unique_id "al4ZJEOu5aQNSViFaxM6lQAAASI"], referer: https://www.ccsdifference.com/robots.txt
[Mon Jul 20 06:48:36.735199 2026] [security2:error] [pid 1025331:tid 1025513] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/32e17094cfindex.php"] [unique_id "al4ZJEOu5aQNSViFaxM6mAAAAT4"]
[Mon Jul 20 06:48:36.735282 2026] [security2:error] [pid 1025331:tid 1025513] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/32e17094cfindex.php"] [unique_id "al4ZJEOu5aQNSViFaxM6mAAAAT4"]
[Mon Jul 20 06:48:36.919076 2026] [security2:error] [pid 1025331:tid 1025536] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZJEOu5aQNSViFaxM6lwAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:36.932836 2026] [security2:error] [pid 1025331:tid 1025403] [remote 47.86.33.52:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZJEOu5aQNSViFaxM6owABS0c"]
[Mon Jul 20 06:48:37.087214 2026] [security2:error] [pid 1025331:tid 1025554] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/qqqa.php"] [unique_id "al4ZJUOu5aQNSViFaxM6swAAAWc"]
[Mon Jul 20 06:48:37.087338 2026] [security2:error] [pid 1025331:tid 1025554] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/qqqa.php"] [unique_id "al4ZJUOu5aQNSViFaxM6swAAAWc"]
[Mon Jul 20 06:48:37.481633 2026] [security2:error] [pid 1025331:tid 1025557] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/aunmc.php"] [unique_id "al4ZJUOu5aQNSViFaxM60QAAAWo"]
[Mon Jul 20 06:48:37.481732 2026] [security2:error] [pid 1025331:tid 1025557] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/aunmc.php"] [unique_id "al4ZJUOu5aQNSViFaxM60QAAAWo"]
[Mon Jul 20 06:48:37.611200 2026] [ssl:error] [pid 1020501:tid 1020733] [client 104.48.69.105:58574] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:48:37.763649 2026] [security2:error] [pid 1025331:tid 1025546] [client 183.82.98.154:55472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZJUOu5aQNSViFaxM64AAAAV8"]
[Mon Jul 20 06:48:37.763790 2026] [security2:error] [pid 1025331:tid 1025546] [client 183.82.98.154:55472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZJUOu5aQNSViFaxM64AAAAV8"]
[Mon Jul 20 06:48:37.781467 2026] [security2:error] [pid 1025331:tid 1025576] [client 193.47.62.167:35846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4ZJUOu5aQNSViFaxM6yAAAAX0"], referer: http://mail.secretkeynumerology.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:37.784349 2026] [security2:error] [pid 1020501:tid 1020697] [client 57.141.18.29:24644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZIcS_oRsP4jdONhf1wQAAQCw"]
[Mon Jul 20 06:48:37.795524 2026] [security2:error] [pid 1025331:tid 1025462] [client 193.47.62.167:35818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4ZJUOu5aQNSViFaxM6wgAAAQs"], referer: http://secretkeynumerology.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:37.800744 2026] [security2:error] [pid 1025331:tid 1025505] [client 193.47.62.167:35830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.htk.naq.mybluehost.me"] [uri "/index.php"] [unique_id "al4ZJUOu5aQNSViFaxM6xwAAATY"], referer: http://mail.htk.naq.mybluehost.me/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:37.862467 2026] [security2:error] [pid 1025331:tid 1025579] [client 223.185.13.213:23909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZJUOu5aQNSViFaxM65QAAAYA"]
[Mon Jul 20 06:48:37.862580 2026] [security2:error] [pid 1025331:tid 1025579] [client 223.185.13.213:23909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZJUOu5aQNSViFaxM65QAAAYA"]
[Mon Jul 20 06:48:37.862812 2026] [security2:error] [pid 1025331:tid 1025498] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/uoocf.php"] [unique_id "al4ZJUOu5aQNSViFaxM65AAAAS8"]
[Mon Jul 20 06:48:37.862914 2026] [security2:error] [pid 1025331:tid 1025498] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/uoocf.php"] [unique_id "al4ZJUOu5aQNSViFaxM65AAAAS8"]
[Mon Jul 20 06:48:37.876548 2026] [security2:error] [pid 1020501:tid 1020686] [client 193.47.62.167:35862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4ZJcS_oRsP4jdONhf2QAAAADU"], referer: http://www.secretkeynumerology.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:38.029602 2026] [security2:error] [pid 1020501:tid 1020571] [remote 103.118.29.185:10562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4ZJsS_oRsP4jdONhf2TQAAO0M"]
[Mon Jul 20 06:48:38.221327 2026] [security2:error] [pid 1025331:tid 1025575] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/iywwi.php"] [unique_id "al4ZJkOu5aQNSViFaxM6-gAAAXw"]
[Mon Jul 20 06:48:38.221486 2026] [security2:error] [pid 1025331:tid 1025575] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/iywwi.php"] [unique_id "al4ZJkOu5aQNSViFaxM6-gAAAXw"]
[Mon Jul 20 06:48:38.341184 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:56771] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZJsS_oRsP4jdONhf2UgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:38.408811 2026] [security2:error] [pid 1025331:tid 1025531] [client 57.141.18.102:55966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZIUOu5aQNSViFaxM6CgABUAc"]
[Mon Jul 20 06:48:38.455823 2026] [security2:error] [pid 1025331:tid 1025537] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZJkOu5aQNSViFaxM6_AAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:38.488376 2026] [security2:error] [pid 1025331:tid 1025555] [client 37.52.210.45:9491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZJkOu5aQNSViFaxM7CgAAAWg"]
[Mon Jul 20 06:48:38.488489 2026] [security2:error] [pid 1025331:tid 1025555] [client 37.52.210.45:9491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZJkOu5aQNSViFaxM7CgAAAWg"]
[Mon Jul 20 06:48:38.512085 2026] [security2:error] [pid 1020501:tid 1020630] [remote 103.118.29.185:10562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4ZJsS_oRsP4jdONhf2VwAAFn4"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:48:38.617906 2026] [security2:error] [pid 1020501:tid 1020666] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/gqgsa.php"] [unique_id "al4ZJsS_oRsP4jdONhf2WQAAACE"]
[Mon Jul 20 06:48:38.618008 2026] [security2:error] [pid 1020501:tid 1020666] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/gqgsa.php"] [unique_id "al4ZJsS_oRsP4jdONhf2WQAAACE"]
[Mon Jul 20 06:48:38.779098 2026] [security2:error] [pid 1020501:tid 1020568] [remote 41.186.86.12:63222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZJsS_oRsP4jdONhf2XQAAGUA"]
[Mon Jul 20 06:48:38.779278 2026] [security2:error] [pid 1020501:tid 1020658] [client 41.186.86.12:63222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZJsS_oRsP4jdONhf2XQAAGUA"]
[Mon Jul 20 06:48:38.897253 2026] [security2:error] [pid 1020501:tid 1020669] [client 13.233.207.33:56482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4ZJsS_oRsP4jdONhf2YwAAACQ"]
[Mon Jul 20 06:48:38.921187 2026] [security2:error] [pid 1025331:tid 1025496] [client 14.225.17.146:64513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4ZJUOu5aQNSViFaxM61wAAAS0"], referer: http://balticsteelmgmt.com/New
[Mon Jul 20 06:48:38.979624 2026] [security2:error] [pid 1020501:tid 1020760] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/elbzl.php"] [unique_id "al4ZJsS_oRsP4jdONhf2awAAAH8"]
[Mon Jul 20 06:48:38.979734 2026] [security2:error] [pid 1020501:tid 1020760] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/elbzl.php"] [unique_id "al4ZJsS_oRsP4jdONhf2awAAAH8"]
[Mon Jul 20 06:48:39.007081 2026] [security2:error] [pid 1020501:tid 1020693] [client 57.141.18.80:28832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZIsS_oRsP4jdONhf15gAAPEc"]
[Mon Jul 20 06:48:39.025009 2026] [security2:error] [pid 1020501:tid 1020725] [client 57.141.18.67:27840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZIsS_oRsP4jdONhf15QAAXAg"]
[Mon Jul 20 06:48:39.361661 2026] [security2:error] [pid 1025331:tid 1025502] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/adjig.php"] [unique_id "al4ZJ0Ou5aQNSViFaxM7MwAAATM"]
[Mon Jul 20 06:48:39.361766 2026] [security2:error] [pid 1025331:tid 1025502] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/adjig.php"] [unique_id "al4ZJ0Ou5aQNSViFaxM7MwAAATM"]
[Mon Jul 20 06:48:39.404434 2026] [security2:error] [pid 1020501:tid 1020671] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZJsS_oRsP4jdONhf2XwAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:39.577866 2026] [security2:error] [pid 1025331:tid 1025583] [client 14.225.17.146:53357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4ZJUOu5aQNSViFaxM65gAAAYQ"], referer: http://ksands.co.uk/New
[Mon Jul 20 06:48:39.598579 2026] [lsapi:warn] [pid 1020501:tid 1020685] [client 14.225.17.146:64937] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/New
[Mon Jul 20 06:48:39.598608 2026] [lsapi:warn] [pid 1020501:tid 1020685] [client 14.225.17.146:64937] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/New
[Mon Jul 20 06:48:39.710668 2026] [security2:error] [pid 1025331:tid 1025537] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/byp.php"] [unique_id "al4ZJ0Ou5aQNSViFaxM7RgAAAVY"]
[Mon Jul 20 06:48:39.710785 2026] [security2:error] [pid 1025331:tid 1025537] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/byp.php"] [unique_id "al4ZJ0Ou5aQNSViFaxM7RgAAAVY"]
[Mon Jul 20 06:48:39.723755 2026] [core:error] [pid 1020501:tid 1020760] [client 103.153.183.69:29260] AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/etc/passwd?_=7u9aap42&v=xz64h), referer: https://news.ycombinator.com/
[Mon Jul 20 06:48:39.726929 2026] [security2:error] [pid 1025331:tid 1025529] [client 127.0.0.1:37284] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZJ0Ou5aQNSViFaxM7SAAAAU4"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:48:39.784626 2026] [security2:error] [pid 1025331:tid 1025539] [client 57.141.18.92:29756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZI0Ou5aQNSViFaxM6SAABWCg"]
[Mon Jul 20 06:48:39.862236 2026] [security2:error] [pid 1020501:tid 1020687] [client 43.205.139.3:15870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4ZJ8S_oRsP4jdONhf2jgAAADY"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:48:40.102771 2026] [lsapi:warn] [pid 1025331:tid 1025497] [client 50.116.65.227:24680] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:48:40.102834 2026] [lsapi:warn] [pid 1025331:tid 1025497] [client 50.116.65.227:24680] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:48:40.117903 2026] [security2:error] [pid 1020501:tid 1020685] [client 14.225.17.146:64937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4ZJ8S_oRsP4jdONhf2bwAAADQ"], referer: http://oswegooperatheater.com/New
[Mon Jul 20 06:48:40.192607 2026] [security2:error] [pid 1025331:tid 1025467] [client 158.173.166.181:47979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZKEOu5aQNSViFaxM7bgAAARA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:48:40.264424 2026] [security2:error] [pid 1025331:tid 1025500] [client 14.225.17.146:64471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4ZJkOu5aQNSViFaxM7IgAAATE"], referer: http://cephasnext.com/New
[Mon Jul 20 06:48:40.281762 2026] [security2:error] [pid 1025331:tid 1025549] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ortasekerli1.php"] [unique_id "al4ZKEOu5aQNSViFaxM7cgAAAWI"]
[Mon Jul 20 06:48:40.281910 2026] [security2:error] [pid 1025331:tid 1025549] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ortasekerli1.php"] [unique_id "al4ZKEOu5aQNSViFaxM7cgAAAWI"]
[Mon Jul 20 06:48:40.409379 2026] [security2:error] [pid 1025331:tid 1025508] [client 14.224.227.113:54718] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZKEOu5aQNSViFaxM7eAAAATk"]
[Mon Jul 20 06:48:40.609939 2026] [security2:error] [pid 1020501:tid 1020690] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZJ8S_oRsP4jdONhf2kQAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:40.616356 2026] [security2:error] [pid 1020501:tid 1020691] [client 14.225.17.146:64497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4ZJsS_oRsP4jdONhf2YAAAADo"], referer: http://fluidtemple.org/New
[Mon Jul 20 06:48:40.660406 2026] [security2:error] [pid 1025331:tid 1025540] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/classwithtostring.php"] [unique_id "al4ZKEOu5aQNSViFaxM7gQAAAVk"]
[Mon Jul 20 06:48:40.660504 2026] [security2:error] [pid 1025331:tid 1025540] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/classwithtostring.php"] [unique_id "al4ZKEOu5aQNSViFaxM7gQAAAVk"]
[Mon Jul 20 06:48:40.677621 2026] [security2:error] [pid 1020501:tid 1020724] [client 117.247.108.24:12713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKMS_oRsP4jdONhf2sAAAAFs"]
[Mon Jul 20 06:48:40.677717 2026] [security2:error] [pid 1020501:tid 1020724] [client 117.247.108.24:12713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKMS_oRsP4jdONhf2sAAAAFs"]
[Mon Jul 20 06:48:40.717733 2026] [security2:error] [pid 1025331:tid 1025359] [remote 47.86.33.52:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZKEOu5aQNSViFaxM7hgABTxs"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:48:41.015181 2026] [security2:error] [pid 1025331:tid 1025577] [client 77.110.127.138:56814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZKUOu5aQNSViFaxM7nAAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:41.015277 2026] [security2:error] [pid 1025331:tid 1025577] [client 77.110.127.138:56814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZKUOu5aQNSViFaxM7nAAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:41.016932 2026] [security2:error] [pid 1020501:tid 1020646] [client 45.3.43.84:36141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.43.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZKMS_oRsP4jdONhf2ugAAAA0"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:41.039301 2026] [security2:error] [pid 1020501:tid 1020681] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/root.php"] [unique_id "al4ZKcS_oRsP4jdONhf2vAAAADA"]
[Mon Jul 20 06:48:41.039499 2026] [security2:error] [pid 1020501:tid 1020681] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/root.php"] [unique_id "al4ZKcS_oRsP4jdONhf2vAAAADA"]
[Mon Jul 20 06:48:41.149963 2026] [security2:error] [pid 1025331:tid 1025510] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZKEOu5aQNSViFaxM7lAAAATs"]
[Mon Jul 20 06:48:41.218521 2026] [lsapi:warn] [pid 1025331:tid 1025538] [client 14.225.17.146:57730] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/New
[Mon Jul 20 06:48:41.218542 2026] [lsapi:warn] [pid 1025331:tid 1025538] [client 14.225.17.146:57730] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/New
[Mon Jul 20 06:48:41.385488 2026] [security2:error] [pid 1025331:tid 1025545] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/sym403.php"] [unique_id "al4ZKUOu5aQNSViFaxM7pgAAAV4"]
[Mon Jul 20 06:48:41.385586 2026] [security2:error] [pid 1025331:tid 1025545] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/sym403.php"] [unique_id "al4ZKUOu5aQNSViFaxM7pgAAAV4"]
[Mon Jul 20 06:48:41.386284 2026] [security2:error] [pid 1020501:tid 1020643] [client 57.141.18.123:31222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZJMS_oRsP4jdONhf2JwAACk4"]
[Mon Jul 20 06:48:41.654673 2026] [security2:error] [pid 1020501:tid 1020757] [client 202.46.92.242:55508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKcS_oRsP4jdONhf23wAAAHw"]
[Mon Jul 20 06:48:41.654834 2026] [security2:error] [pid 1020501:tid 1020757] [client 202.46.92.242:55508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKcS_oRsP4jdONhf23wAAAHw"]
[Mon Jul 20 06:48:41.774455 2026] [security2:error] [pid 1025331:tid 1025567] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/v543.php"] [unique_id "al4ZKUOu5aQNSViFaxM7vgAAAXQ"]
[Mon Jul 20 06:48:41.774549 2026] [security2:error] [pid 1025331:tid 1025567] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/v543.php"] [unique_id "al4ZKUOu5aQNSViFaxM7vgAAAXQ"]
[Mon Jul 20 06:48:41.856264 2026] [security2:error] [pid 1025331:tid 1025377] [remote 5.252.52.249:43078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4ZKUOu5aQNSViFaxM7xgABWS0"]
[Mon Jul 20 06:48:41.859739 2026] [security2:error] [pid 1020501:tid 1020732] [client 17.246.19.124:58734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4ZKcS_oRsP4jdONhf22QAAYy0"]
[Mon Jul 20 06:48:42.009804 2026] [security2:error] [pid 1025331:tid 1025575] [client 50.116.65.227:24736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZKkOu5aQNSViFaxM7ygAAAXw"]
[Mon Jul 20 06:48:42.020667 2026] [security2:error] [pid 1025331:tid 1025472] [client 50.116.65.227:24744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZKkOu5aQNSViFaxM7zQAAARU"]
[Mon Jul 20 06:48:42.034742 2026] [security2:error] [pid 1025331:tid 1025491] [client 103.238.106.162:60629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZKkOu5aQNSViFaxM7zwAAASg"]
[Mon Jul 20 06:48:42.035501 2026] [security2:error] [pid 1025331:tid 1025491] [client 103.238.106.162:60629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZKkOu5aQNSViFaxM7zwAAASg"]
[Mon Jul 20 06:48:42.078713 2026] [security2:error] [pid 1025331:tid 1025362] [remote 5.252.52.249:43078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4ZKkOu5aQNSViFaxM70gABDx4"], referer: https://faadenergy.com/wp-login.php
[Mon Jul 20 06:48:42.122687 2026] [security2:error] [pid 1025331:tid 1025570] [client 57.141.18.0:51516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZJUOu5aQNSViFaxM62wABd1k"]
[Mon Jul 20 06:48:42.168119 2026] [security2:error] [pid 1025331:tid 1025563] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/sixxis.php"] [unique_id "al4ZKkOu5aQNSViFaxM71wAAAXA"]
[Mon Jul 20 06:48:42.168223 2026] [security2:error] [pid 1025331:tid 1025563] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/sixxis.php"] [unique_id "al4ZKkOu5aQNSViFaxM71wAAAXA"]
[Mon Jul 20 06:48:42.178591 2026] [security2:error] [pid 1025331:tid 1025387] [remote 216.73.216.55:6084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4ZKkOu5aQNSViFaxM72AABdjc"]
[Mon Jul 20 06:48:42.360102 2026] [security2:error] [pid 1025331:tid 1025546] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZKUOu5aQNSViFaxM7xQAAAV8"]
[Mon Jul 20 06:48:42.444563 2026] [security2:error] [pid 1025331:tid 1025556] [client 106.219.188.178:2902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKkOu5aQNSViFaxM77gAAAWk"]
[Mon Jul 20 06:48:42.445166 2026] [security2:error] [pid 1025331:tid 1025556] [client 106.219.188.178:2902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKkOu5aQNSViFaxM77gAAAWk"]
[Mon Jul 20 06:48:42.467879 2026] [security2:error] [pid 1025331:tid 1025549] [client 104.207.50.169:47953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZKkOu5aQNSViFaxM76wAAAWI"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:48:42.551790 2026] [security2:error] [pid 1020501:tid 1020759] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ip.php"] [unique_id "al4ZKsS_oRsP4jdONhf28gAAAH4"]
[Mon Jul 20 06:48:42.551893 2026] [security2:error] [pid 1020501:tid 1020759] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ip.php"] [unique_id "al4ZKsS_oRsP4jdONhf28gAAAH4"]
[Mon Jul 20 06:48:42.749247 2026] [security2:error] [pid 1020501:tid 1020689] [client 57.141.18.55:43618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZJsS_oRsP4jdONhf2UAAAOHo"]
[Mon Jul 20 06:48:42.830523 2026] [security2:error] [pid 1025331:tid 1025494] [client 217.142.18.172:35028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKkOu5aQNSViFaxM8BwAAASs"]
[Mon Jul 20 06:48:42.833863 2026] [security2:error] [pid 1025331:tid 1025494] [client 217.142.18.172:35028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZKkOu5aQNSViFaxM8BwAAASs"]
[Mon Jul 20 06:48:42.925825 2026] [security2:error] [pid 1025331:tid 1025497] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/kq1.php"] [unique_id "al4ZKkOu5aQNSViFaxM8EAAAAS4"]
[Mon Jul 20 06:48:42.925928 2026] [security2:error] [pid 1025331:tid 1025497] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/kq1.php"] [unique_id "al4ZKkOu5aQNSViFaxM8EAAAAS4"]
[Mon Jul 20 06:48:43.105258 2026] [security2:error] [pid 1025331:tid 1025552] [client 152.58.191.29:53508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8IAAAAWU"]
[Mon Jul 20 06:48:43.105381 2026] [security2:error] [pid 1025331:tid 1025552] [client 152.58.191.29:53508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8IAAAAWU"]
[Mon Jul 20 06:48:43.145927 2026] [security2:error] [pid 1025331:tid 1025468] [client 104.234.53.68:20789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8GAAAARE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:43.273531 2026] [security2:error] [pid 1025331:tid 1025485] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/fw/faiyy.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8KgAAASI"]
[Mon Jul 20 06:48:43.273637 2026] [security2:error] [pid 1025331:tid 1025485] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/fw/faiyy.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8KgAAASI"]
[Mon Jul 20 06:48:43.384631 2026] [security2:error] [pid 1025331:tid 1025412] [remote 8.217.108.67:36784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8MAABDVA"]
[Mon Jul 20 06:48:43.640732 2026] [proxy:error] [pid 1025331:tid 1025526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:43.640836 2026] [proxy_http:error] [pid 1025331:tid 1025526] [client 193.47.62.167:47724] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:43.642120 2026] [proxy:error] [pid 1025331:tid 1025526] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:43.642175 2026] [proxy_http:error] [pid 1025331:tid 1025526] [client 193.47.62.167:47724] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:43.644127 2026] [proxy:error] [pid 1025331:tid 1025491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:43.644185 2026] [proxy_http:error] [pid 1025331:tid 1025491] [client 193.47.62.167:47700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:43.644636 2026] [proxy:error] [pid 1025331:tid 1025491] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:43.644669 2026] [proxy_http:error] [pid 1025331:tid 1025491] [client 193.47.62.167:47700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:43.676159 2026] [security2:error] [pid 1025331:tid 1025524] [client 104.234.53.68:20789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8RAAAAUk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:43.687315 2026] [security2:error] [pid 1025331:tid 1025537] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/h02ugyh.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8SgAAAVY"]
[Mon Jul 20 06:48:43.687431 2026] [security2:error] [pid 1025331:tid 1025537] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/h02ugyh.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8SgAAAVY"]
[Mon Jul 20 06:48:43.911937 2026] [security2:error] [pid 1025331:tid 1025558] [client 57.141.18.75:49348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZJ0Ou5aQNSViFaxM7PAABa3o"]
[Mon Jul 20 06:48:43.929695 2026] [security2:error] [pid 1025331:tid 1025423] [remote 45.90.123.233:50184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8WgABEls"]
[Mon Jul 20 06:48:44.095423 2026] [security2:error] [pid 1025331:tid 1025533] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-temp.php"] [unique_id "al4ZLEOu5aQNSViFaxM8ZAAAAVI"]
[Mon Jul 20 06:48:44.095546 2026] [security2:error] [pid 1025331:tid 1025533] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-temp.php"] [unique_id "al4ZLEOu5aQNSViFaxM8ZAAAAVI"]
[Mon Jul 20 06:48:44.126050 2026] [security2:error] [pid 1025331:tid 1025424] [remote 45.90.123.233:50184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZLEOu5aQNSViFaxM8ZgABY1w"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:48:44.406234 2026] [security2:error] [pid 1020501:tid 1020723] [client 157.85.211.87:4628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZLMS_oRsP4jdONhf3IgAAAFo"]
[Mon Jul 20 06:48:44.406353 2026] [security2:error] [pid 1020501:tid 1020723] [client 157.85.211.87:4628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZLMS_oRsP4jdONhf3IgAAAFo"]
[Mon Jul 20 06:48:44.454091 2026] [security2:error] [pid 1020501:tid 1020639] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/cong.php"] [unique_id "al4ZLMS_oRsP4jdONhf3IwAAAAY"]
[Mon Jul 20 06:48:44.454168 2026] [security2:error] [pid 1020501:tid 1020639] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-content/cong.php"] [unique_id "al4ZLMS_oRsP4jdONhf3IwAAAAY"]
[Mon Jul 20 06:48:44.578484 2026] [security2:error] [pid 1020501:tid 1020674] [client 187.108.85.186:49374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZLMS_oRsP4jdONhf3JgAAACk"]
[Mon Jul 20 06:48:44.578587 2026] [security2:error] [pid 1020501:tid 1020674] [client 187.108.85.186:49374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZLMS_oRsP4jdONhf3JgAAACk"]
[Mon Jul 20 06:48:44.601541 2026] [security2:error] [pid 1025331:tid 1025518] [client 77.110.127.138:56869] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZLEOu5aQNSViFaxM8fAAAAUM"]
[Mon Jul 20 06:48:44.754728 2026] [security2:error] [pid 1025331:tid 1025496] [client 77.110.127.138:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZLEOu5aQNSViFaxM8iwAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:44.754820 2026] [security2:error] [pid 1025331:tid 1025496] [client 77.110.127.138:56872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZLEOu5aQNSViFaxM8iwAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:44.806867 2026] [security2:error] [pid 1020501:tid 1020688] [client 57.141.18.67:27850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZKMS_oRsP4jdONhf2qgAAN2A"]
[Mon Jul 20 06:48:45.062013 2026] [security2:error] [pid 1025331:tid 1025444] [remote 100.42.189.89:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZLUOu5aQNSViFaxM8mAABa3A"]
[Mon Jul 20 06:48:45.304432 2026] [security2:error] [pid 1025331:tid 1025446] [remote 100.42.189.89:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZLUOu5aQNSViFaxM8oAABZ3I"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:48:45.762841 2026] [security2:error] [pid 1020501:tid 1020718] [client 57.141.18.119:57078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZKcS_oRsP4jdONhf21gAAVXE"]
[Mon Jul 20 06:48:45.993442 2026] [security2:error] [pid 1020501:tid 1020730] [client 216.73.217.138:41149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZLcS_oRsP4jdONhf3YAAAYVA"]
[Mon Jul 20 06:48:46.087223 2026] [security2:error] [pid 1020501:tid 1020524] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZLsS_oRsP4jdONhf3ZgAAPhQ"]
[Mon Jul 20 06:48:46.087370 2026] [security2:error] [pid 1020501:tid 1020695] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZLsS_oRsP4jdONhf3ZgAAPhQ"]
[Mon Jul 20 06:48:46.148139 2026] [security2:error] [pid 1020501:tid 1020697] [client 57.141.18.21:27324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZKcS_oRsP4jdONhf25AAAQDg"]
[Mon Jul 20 06:48:46.443843 2026] [security2:error] [pid 1025331:tid 1025578] [client 50.116.65.227:24808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/05/IMG_4139-1.jpeg"] [unique_id "al4ZLkOu5aQNSViFaxM80gAAAX8"]
[Mon Jul 20 06:48:46.478692 2026] [security2:error] [pid 1020501:tid 1020531] [remote 103.82.22.235:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4ZLsS_oRsP4jdONhf3bgAAChs"]
[Mon Jul 20 06:48:46.768621 2026] [security2:error] [pid 1020501:tid 1020707] [client 57.141.18.13:35684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZKsS_oRsP4jdONhf29AAASnk"]
[Mon Jul 20 06:48:46.773025 2026] [security2:error] [pid 1025331:tid 1025354] [remote 8.217.108.67:36784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4ZLkOu5aQNSViFaxM84gABcxY"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:48:46.789809 2026] [security2:error] [pid 1025331:tid 1025485] [client 20.226.60.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4ZLEOu5aQNSViFaxM8jwAAASI"]
[Mon Jul 20 06:48:46.789842 2026] [security2:error] [pid 1025331:tid 1025485] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4ZLEOu5aQNSViFaxM8jwAAASI"]
[Mon Jul 20 06:48:46.837656 2026] [security2:error] [pid 1025331:tid 1025579] [client 57.141.18.63:23550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZKkOu5aQNSViFaxM7_AABgD4"]
[Mon Jul 20 06:48:46.992680 2026] [security2:error] [pid 1025331:tid 1025462] [client 51.68.111.207:16093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nevelow.com"] [uri "/robots.txt"] [unique_id "al4ZLkOu5aQNSViFaxM87AAAAQs"]
[Mon Jul 20 06:48:46.992806 2026] [security2:error] [pid 1025331:tid 1025462] [client 51.68.111.207:16093] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nevelow.com"] [uri "/robots.txt"] [unique_id "al4ZLkOu5aQNSViFaxM87AAAAQs"]
[Mon Jul 20 06:48:47.227933 2026] [security2:error] [pid 1020501:tid 1020569] [remote 103.82.22.235:50618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4ZL8S_oRsP4jdONhf3hwAAZEE"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 06:48:47.248420 2026] [security2:error] [pid 1025331:tid 1025475] [client 223.109.255.145:44110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ksands.co.uk"] [uri "/"] [unique_id "al4ZL0Ou5aQNSViFaxM8-wAAARg"]
[Mon Jul 20 06:48:47.248542 2026] [security2:error] [pid 1025331:tid 1025475] [client 223.109.255.145:44110] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "ksands.co.uk"] [uri "/"] [unique_id "al4ZL0Ou5aQNSViFaxM8-wAAARg"]
[Mon Jul 20 06:48:47.272774 2026] [security2:error] [pid 1025331:tid 1025527] [client 103.125.179.95:63399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZL0Ou5aQNSViFaxM8_wAAAUw"]
[Mon Jul 20 06:48:47.272887 2026] [security2:error] [pid 1025331:tid 1025527] [client 103.125.179.95:63399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZL0Ou5aQNSViFaxM8_wAAAUw"]
[Mon Jul 20 06:48:47.412263 2026] [security2:error] [pid 1025331:tid 1025507] [client 142.252.53.206:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4ZL0Ou5aQNSViFaxM8_AAAATg"]
[Mon Jul 20 06:48:47.412934 2026] [security2:error] [pid 1025331:tid 1025481] [client 142.252.53.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4ZL0Ou5aQNSViFaxM8_QAAAR4"]
[Mon Jul 20 06:48:47.494844 2026] [security2:error] [pid 1025331:tid 1025573] [client 20.226.60.151:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4ZLkOu5aQNSViFaxM86gAAAXo"]
[Mon Jul 20 06:48:47.494872 2026] [security2:error] [pid 1025331:tid 1025573] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4ZLkOu5aQNSViFaxM86gAAAXo"]
[Mon Jul 20 06:48:47.530911 2026] [security2:error] [pid 1025331:tid 1025477] [client 57.141.18.68:35414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZK0Ou5aQNSViFaxM8KwABGkk"]
[Mon Jul 20 06:48:47.581228 2026] [security2:error] [pid 1025331:tid 1025465] [client 77.110.127.138:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZL0Ou5aQNSViFaxM9EQAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:47.581340 2026] [security2:error] [pid 1025331:tid 1025465] [client 77.110.127.138:56888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZL0Ou5aQNSViFaxM9EQAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:47.656605 2026] [security2:error] [pid 1025331:tid 1025363] [remote 78.46.157.202:48934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZL0Ou5aQNSViFaxM9FgABMh8"]
[Mon Jul 20 06:48:47.758970 2026] [security2:error] [pid 1025331:tid 1025535] [client 14.225.17.146:50073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4ZLkOu5aQNSViFaxM8xwAAAVQ"], referer: http://reosportsboats.com/New
[Mon Jul 20 06:48:47.897439 2026] [security2:error] [pid 1025331:tid 1025348] [remote 78.46.157.202:48934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZL0Ou5aQNSViFaxM9KwABVRA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:48:47.899280 2026] [security2:error] [pid 1025331:tid 1025486] [client 104.234.53.91:27033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ZL0Ou5aQNSViFaxM9JQAAASM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:48.032493 2026] [security2:error] [pid 1025331:tid 1025530] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4ZMEOu5aQNSViFaxM9NQAAAU8"]
[Mon Jul 20 06:48:48.032618 2026] [security2:error] [pid 1025331:tid 1025530] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4ZMEOu5aQNSViFaxM9NQAAAU8"]
[Mon Jul 20 06:48:48.355011 2026] [security2:error] [pid 1025331:tid 1025421] [remote 152.228.213.32:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4ZMEOu5aQNSViFaxM9SAABglk"]
[Mon Jul 20 06:48:48.391101 2026] [security2:error] [pid 1025331:tid 1025461] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/jj.php"] [unique_id "al4ZMEOu5aQNSViFaxM9TAAAAQo"]
[Mon Jul 20 06:48:48.391208 2026] [security2:error] [pid 1025331:tid 1025461] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/jj.php"] [unique_id "al4ZMEOu5aQNSViFaxM9TAAAAQo"]
[Mon Jul 20 06:48:48.447856 2026] [security2:error] [pid 1020501:tid 1020662] [client 183.82.98.154:56062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMMS_oRsP4jdONhf3oQAAAB0"]
[Mon Jul 20 06:48:48.448015 2026] [security2:error] [pid 1020501:tid 1020662] [client 183.82.98.154:56062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMMS_oRsP4jdONhf3oQAAAB0"]
[Mon Jul 20 06:48:48.457467 2026] [security2:error] [pid 1025331:tid 1025535] [client 104.234.53.91:27033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZMEOu5aQNSViFaxM9TwAAAVQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:48:48.567850 2026] [security2:error] [pid 1025331:tid 1025387] [remote 152.228.213.32:59234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4ZMEOu5aQNSViFaxM9UwABgzc"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 06:48:48.692196 2026] [security2:error] [pid 1020501:tid 1020548] [remote 160.187.68.132:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZMMS_oRsP4jdONhf3pwAAKCw"]
[Mon Jul 20 06:48:48.707800 2026] [security2:error] [pid 1020501:tid 1020716] [client 57.141.18.3:26754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZLMS_oRsP4jdONhf3KgAAUzw"]
[Mon Jul 20 06:48:48.792810 2026] [security2:error] [pid 1020501:tid 1020694] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al4ZMMS_oRsP4jdONhf3sgAAAD0"]
[Mon Jul 20 06:48:48.792909 2026] [security2:error] [pid 1020501:tid 1020694] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/class-walker-footer-dev.php"] [unique_id "al4ZMMS_oRsP4jdONhf3sgAAAD0"]
[Mon Jul 20 06:48:48.877667 2026] [security2:error] [pid 1020501:tid 1020713] [client 34.139.11.221:59875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.mochawavepublishing.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMMS_oRsP4jdONhf3twAAAFA"]
[Mon Jul 20 06:48:48.900615 2026] [security2:error] [pid 1020501:tid 1020699] [client 14.225.17.146:59423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4ZMMS_oRsP4jdONhf3rgAAAEI"], referer: http://bbwipartnerconference.com/New
[Mon Jul 20 06:48:49.019892 2026] [security2:error] [pid 1025331:tid 1025564] [client 34.139.11.221:55509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMUOu5aQNSViFaxM9bAAAAXE"]
[Mon Jul 20 06:48:49.029764 2026] [security2:error] [pid 1025331:tid 1025399] [remote 160.187.68.132:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZMUOu5aQNSViFaxM9bQABbkM"]
[Mon Jul 20 06:48:49.034983 2026] [security2:error] [pid 1020501:tid 1020667] [client 57.141.18.118:46978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZLcS_oRsP4jdONhf3NQAAIkk"]
[Mon Jul 20 06:48:49.143774 2026] [security2:error] [pid 1025331:tid 1025520] [client 34.139.11.221:62449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMUOu5aQNSViFaxM9dwAAAUU"]
[Mon Jul 20 06:48:49.174975 2026] [security2:error] [pid 1020501:tid 1020607] [remote 160.187.68.132:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZMcS_oRsP4jdONhf3vwAAYWc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:48:49.236919 2026] [security2:error] [pid 1020501:tid 1020689] [client 37.52.210.45:12416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZMcS_oRsP4jdONhf3wgAAADg"]
[Mon Jul 20 06:48:49.237032 2026] [security2:error] [pid 1020501:tid 1020689] [client 37.52.210.45:12416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZMcS_oRsP4jdONhf3wgAAADg"]
[Mon Jul 20 06:48:49.341192 2026] [security2:error] [pid 1025331:tid 1025548] [client 34.139.11.221:60822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMUOu5aQNSViFaxM9ewAAAWE"]
[Mon Jul 20 06:48:49.493430 2026] [security2:error] [pid 1025331:tid 1025563] [client 34.139.11.221:56750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMUOu5aQNSViFaxM9gQAAAXA"]
[Mon Jul 20 06:48:49.507114 2026] [security2:error] [pid 1025331:tid 1025572] [client 50.116.65.227:10932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/05/IMG_4139-1.jpeg"] [unique_id "al4ZMUOu5aQNSViFaxM9ggAAAXk"]
[Mon Jul 20 06:48:49.593650 2026] [security2:error] [pid 1025331:tid 1025408] [remote 160.187.68.132:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZMUOu5aQNSViFaxM9iAABWUw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:48:49.643006 2026] [security2:error] [pid 1025331:tid 1025531] [client 34.139.11.221:53456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMUOu5aQNSViFaxM9jgAAAVA"]
[Mon Jul 20 06:48:49.670585 2026] [security2:error] [pid 1025331:tid 1025410] [remote 195.26.253.119:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4ZMUOu5aQNSViFaxM9jwABGU4"]
[Mon Jul 20 06:48:49.700866 2026] [security2:error] [pid 1020501:tid 1020648] [client 98.159.234.160:48643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZMcS_oRsP4jdONhf30QAAAA8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:48:49.762299 2026] [security2:error] [pid 1020501:tid 1020684] [client 223.185.13.213:30470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMcS_oRsP4jdONhf31AAAADM"]
[Mon Jul 20 06:48:49.762418 2026] [security2:error] [pid 1020501:tid 1020684] [client 223.185.13.213:30470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMcS_oRsP4jdONhf31AAAADM"]
[Mon Jul 20 06:48:49.819870 2026] [security2:error] [pid 1025331:tid 1025585] [client 34.139.11.221:52187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMUOu5aQNSViFaxM9ngAAAYY"]
[Mon Jul 20 06:48:49.841718 2026] [security2:error] [pid 1025331:tid 1025422] [remote 195.26.253.119:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.253.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4ZMUOu5aQNSViFaxM9oAABNFo"], referer: https://royalart-lb.com/wp-login.php
[Mon Jul 20 06:48:49.892440 2026] [security2:error] [pid 1020501:tid 1020660] [client 106.219.188.178:59924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMcS_oRsP4jdONhf32QAAABs"]
[Mon Jul 20 06:48:49.893906 2026] [security2:error] [pid 1020501:tid 1020660] [client 106.219.188.178:59924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMcS_oRsP4jdONhf32QAAABs"]
[Mon Jul 20 06:48:49.898230 2026] [security2:error] [pid 1020501:tid 1020712] [client 57.141.18.118:46994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZLcS_oRsP4jdONhf3XwAATyU"]
[Mon Jul 20 06:48:49.910439 2026] [security2:error] [pid 1025331:tid 1025515] [client 197.186.66.42:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZMUOu5aQNSViFaxM9pAAAAUA"]
[Mon Jul 20 06:48:49.910594 2026] [security2:error] [pid 1025331:tid 1025515] [client 197.186.66.42:55731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZMUOu5aQNSViFaxM9pAAAAUA"]
[Mon Jul 20 06:48:49.953321 2026] [security2:error] [pid 1020501:tid 1020656] [client 34.139.11.221:63756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMcS_oRsP4jdONhf32wAAABc"]
[Mon Jul 20 06:48:50.080706 2026] [security2:error] [pid 1020501:tid 1020709] [client 34.139.11.221:60905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMsS_oRsP4jdONhf33QAAAEw"]
[Mon Jul 20 06:48:50.093427 2026] [security2:error] [pid 1025331:tid 1025522] [client 14.225.17.146:56608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4ZMUOu5aQNSViFaxM9nQAAAUc"], referer: http://adastra.love/New
[Mon Jul 20 06:48:50.187389 2026] [security2:error] [pid 1025331:tid 1025563] [client 34.139.11.221:55009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMkOu5aQNSViFaxM9sgAAAXA"]
[Mon Jul 20 06:48:50.349681 2026] [security2:error] [pid 1025331:tid 1025531] [client 34.139.11.221:59246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mochawavepublishing.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZMkOu5aQNSViFaxM9uwAAAVA"]
[Mon Jul 20 06:48:50.438241 2026] [proxy:error] [pid 1025331:tid 1025583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:50.438321 2026] [proxy_http:error] [pid 1025331:tid 1025583] [client 34.73.38.214:56167] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:50.439001 2026] [proxy:error] [pid 1025331:tid 1025583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:50.439052 2026] [proxy_http:error] [pid 1025331:tid 1025583] [client 34.73.38.214:56167] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:50.494401 2026] [security2:error] [pid 1025331:tid 1025558] [client 57.141.18.39:53279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZLkOu5aQNSViFaxM8zwABawo"]
[Mon Jul 20 06:48:50.544970 2026] [security2:error] [pid 1025331:tid 1025469] [client 117.247.108.24:49639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMkOu5aQNSViFaxM91QAAARI"]
[Mon Jul 20 06:48:50.545078 2026] [security2:error] [pid 1025331:tid 1025469] [client 117.247.108.24:49639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZMkOu5aQNSViFaxM91QAAARI"]
[Mon Jul 20 06:48:51.192463 2026] [proxy:error] [pid 1025331:tid 1025520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:51.192538 2026] [proxy_http:error] [pid 1025331:tid 1025520] [client 34.73.38.214:51586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:51.193161 2026] [proxy:error] [pid 1025331:tid 1025520] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:51.193186 2026] [proxy_http:error] [pid 1025331:tid 1025520] [client 34.73.38.214:51586] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:51.237213 2026] [security2:error] [pid 1020501:tid 1020681] [client 65.1.132.125:55512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZM8S_oRsP4jdONhf39QAAADA"]
[Mon Jul 20 06:48:51.394149 2026] [security2:error] [pid 1025331:tid 1025533] [client 57.141.18.107:64924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZL0Ou5aQNSViFaxM88QABUgA"]
[Mon Jul 20 06:48:51.454486 2026] [security2:error] [pid 1025331:tid 1025478] [client 77.110.127.138:56938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZM0Ou5aQNSViFaxM-EAAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:51.454605 2026] [security2:error] [pid 1025331:tid 1025478] [client 77.110.127.138:56938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZM0Ou5aQNSViFaxM-EAAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:51.773480 2026] [security2:error] [pid 1025331:tid 1025484] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/txets.php"] [unique_id "al4ZM0Ou5aQNSViFaxM-JQAAASE"]
[Mon Jul 20 06:48:51.773573 2026] [security2:error] [pid 1025331:tid 1025484] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/txets.php"] [unique_id "al4ZM0Ou5aQNSViFaxM-JQAAASE"]
[Mon Jul 20 06:48:51.921908 2026] [security2:error] [pid 1020501:tid 1020552] [remote 95.217.78.234:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4ZM8S_oRsP4jdONhf3_QAACjA"]
[Mon Jul 20 06:48:51.968839 2026] [proxy:error] [pid 1020501:tid 1020705] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:51.968920 2026] [proxy_http:error] [pid 1020501:tid 1020705] [client 193.47.62.167:52402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:51.969537 2026] [proxy:error] [pid 1020501:tid 1020705] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:51.969566 2026] [proxy_http:error] [pid 1020501:tid 1020705] [client 193.47.62.167:52402] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:51.970114 2026] [proxy:error] [pid 1025331:tid 1025539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:51.970151 2026] [proxy_http:error] [pid 1025331:tid 1025539] [client 193.47.62.167:52416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:51.970557 2026] [proxy:error] [pid 1025331:tid 1025539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:51.970578 2026] [proxy_http:error] [pid 1025331:tid 1025539] [client 193.47.62.167:52416] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:52.034123 2026] [security2:error] [pid 1025331:tid 1025477] [client 192.140.149.97:44914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-OgAAARo"]
[Mon Jul 20 06:48:52.034208 2026] [security2:error] [pid 1025331:tid 1025477] [client 192.140.149.97:44914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-OgAAARo"]
[Mon Jul 20 06:48:52.055458 2026] [proxy:error] [pid 1025331:tid 1025558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:52.055509 2026] [proxy_http:error] [pid 1025331:tid 1025558] [client 34.73.38.214:53908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:52.055963 2026] [proxy:error] [pid 1025331:tid 1025558] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:48:52.055988 2026] [proxy_http:error] [pid 1025331:tid 1025558] [client 34.73.38.214:53908] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:48:52.106981 2026] [security2:error] [pid 1025331:tid 1025515] [client 50.116.65.227:10972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZNEOu5aQNSViFaxM-QQAAAUA"]
[Mon Jul 20 06:48:52.116963 2026] [security2:error] [pid 1025331:tid 1025494] [client 50.116.65.227:10980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZNEOu5aQNSViFaxM-QwAAASs"]
[Mon Jul 20 06:48:52.135653 2026] [security2:error] [pid 1025331:tid 1025518] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/dex.php"] [unique_id "al4ZNEOu5aQNSViFaxM-RQAAAUM"]
[Mon Jul 20 06:48:52.135786 2026] [security2:error] [pid 1025331:tid 1025518] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/dex.php"] [unique_id "al4ZNEOu5aQNSViFaxM-RQAAAUM"]
[Mon Jul 20 06:48:52.156597 2026] [security2:error] [pid 1020501:tid 1020619] [remote 95.217.78.234:41184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4ZNMS_oRsP4jdONhf4AwAABHM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:48:52.421012 2026] [security2:error] [pid 1020501:tid 1020660] [client 65.1.132.125:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZNMS_oRsP4jdONhf4BQAAABs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:48:52.448825 2026] [security2:error] [pid 1025331:tid 1025499] [client 57.141.18.53:31292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZMEOu5aQNSViFaxM9NwABMDA"]
[Mon Jul 20 06:48:52.466725 2026] [security2:error] [pid 1025331:tid 1025506] [client 36.95.228.227:55976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-WwAAATc"]
[Mon Jul 20 06:48:52.466863 2026] [security2:error] [pid 1025331:tid 1025506] [client 36.95.228.227:55976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-WwAAATc"]
[Mon Jul 20 06:48:52.522131 2026] [security2:error] [pid 1020501:tid 1020677] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xpwer1.php"] [unique_id "al4ZNMS_oRsP4jdONhf4BwAAACw"]
[Mon Jul 20 06:48:52.522234 2026] [security2:error] [pid 1020501:tid 1020677] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xpwer1.php"] [unique_id "al4ZNMS_oRsP4jdONhf4BwAAACw"]
[Mon Jul 20 06:48:52.540379 2026] [security2:error] [pid 1025331:tid 1025488] [client 122.183.32.225:5468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-XQAAASU"]
[Mon Jul 20 06:48:52.540529 2026] [security2:error] [pid 1025331:tid 1025488] [client 122.183.32.225:5468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-XQAAASU"]
[Mon Jul 20 06:48:52.563706 2026] [security2:error] [pid 1025331:tid 1025526] [client 103.238.106.162:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-ZQAAAUs"]
[Mon Jul 20 06:48:52.563807 2026] [security2:error] [pid 1025331:tid 1025526] [client 103.238.106.162:63540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-ZQAAAUs"]
[Mon Jul 20 06:48:52.767147 2026] [security2:error] [pid 1025331:tid 1025562] [client 34.73.38.214:55286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/xmlrpc.php"] [unique_id "al4ZNEOu5aQNSViFaxM-cgAAAW8"]
[Mon Jul 20 06:48:53.242968 2026] [security2:error] [pid 1025331:tid 1025516] [client 34.73.38.214:54127] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZNUOu5aQNSViFaxM-gwAAAUE"]
[Mon Jul 20 06:48:53.386644 2026] [security2:error] [pid 1025331:tid 1025564] [client 217.142.18.172:19371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNUOu5aQNSViFaxM-iQAAAXE"]
[Mon Jul 20 06:48:53.389830 2026] [security2:error] [pid 1025331:tid 1025564] [client 217.142.18.172:19371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNUOu5aQNSViFaxM-iQAAAXE"]
[Mon Jul 20 06:48:53.453991 2026] [security2:error] [pid 1020501:tid 1020708] [client 57.141.18.3:26764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZMcS_oRsP4jdONhf3wAAASyY"]
[Mon Jul 20 06:48:53.596524 2026] [security2:error] [pid 1025331:tid 1025587] [client 34.73.38.214:55560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZNUOu5aQNSViFaxM-kAAAAYg"]
[Mon Jul 20 06:48:53.994439 2026] [security2:error] [pid 1025331:tid 1025384] [remote 173.212.252.15:57002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZNUOu5aQNSViFaxM-pgABGzQ"]
[Mon Jul 20 06:48:54.167560 2026] [security2:error] [pid 1025331:tid 1025545] [client 34.73.38.214:49849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZNkOu5aQNSViFaxM-rwAAAV4"]
[Mon Jul 20 06:48:54.205097 2026] [security2:error] [pid 1025331:tid 1025408] [remote 173.212.252.15:57002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZNkOu5aQNSViFaxM-sgABFUw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:48:54.294268 2026] [security2:error] [pid 1025331:tid 1025584] [client 57.141.18.97:38930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZMUOu5aQNSViFaxM9pgABhVg"]
[Mon Jul 20 06:48:54.312946 2026] [security2:error] [pid 1025331:tid 1025548] [client 39.48.81.23:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNkOu5aQNSViFaxM-uwAAAWE"]
[Mon Jul 20 06:48:54.313043 2026] [security2:error] [pid 1025331:tid 1025548] [client 39.48.81.23:52861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZNkOu5aQNSViFaxM-uwAAAWE"]
[Mon Jul 20 06:48:54.434707 2026] [security2:error] [pid 1025331:tid 1025493] [client 193.47.62.167:45836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.lelandumc.org"] [uri "/index.php"] [unique_id "al4ZNEOu5aQNSViFaxM-cQAAASo"], referer: http://www.lelandumc.org/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 06:48:54.554894 2026] [security2:error] [pid 1025331:tid 1025511] [client 57.141.18.105:28140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZMkOu5aQNSViFaxM9tQABPGA"]
[Mon Jul 20 06:48:54.677466 2026] [security2:error] [pid 1025331:tid 1025429] [remote 182.77.62.24:32818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4ZNkOu5aQNSViFaxM-zAABR2E"]
[Mon Jul 20 06:48:54.679658 2026] [security2:error] [pid 1025331:tid 1025480] [client 57.141.18.41:30852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZMkOu5aQNSViFaxM9twABHWI"]
[Mon Jul 20 06:48:54.824117 2026] [security2:error] [pid 1025331:tid 1025532] [client 34.73.38.214:54847] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZNkOu5aQNSViFaxM-1AAAAVE"]
[Mon Jul 20 06:48:55.102305 2026] [security2:error] [pid 1025331:tid 1025505] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZNkOu5aQNSViFaxM-2QAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:55.137779 2026] [security2:error] [pid 1025331:tid 1025425] [remote 103.118.29.185:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZN0Ou5aQNSViFaxM-5QABVV0"]
[Mon Jul 20 06:48:55.137882 2026] [security2:error] [pid 1025331:tid 1025536] [client 103.118.29.185:17234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZN0Ou5aQNSViFaxM-5QABVV0"]
[Mon Jul 20 06:48:55.174255 2026] [security2:error] [pid 1025331:tid 1025435] [remote 182.77.62.24:32818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4ZN0Ou5aQNSViFaxM-5gABKWc"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:48:55.323830 2026] [security2:error] [pid 1025331:tid 1025539] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/flox.php"] [unique_id "al4ZN0Ou5aQNSViFaxM-9AAAAVg"]
[Mon Jul 20 06:48:55.323938 2026] [security2:error] [pid 1025331:tid 1025539] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/flox.php"] [unique_id "al4ZN0Ou5aQNSViFaxM-9AAAAVg"]
[Mon Jul 20 06:48:55.350341 2026] [security2:error] [pid 1025331:tid 1025554] [client 187.108.85.186:49938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZN0Ou5aQNSViFaxM--AAAAWc"]
[Mon Jul 20 06:48:55.350447 2026] [security2:error] [pid 1025331:tid 1025554] [client 187.108.85.186:49938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZN0Ou5aQNSViFaxM--AAAAWc"]
[Mon Jul 20 06:48:55.358572 2026] [security2:error] [pid 1025331:tid 1025440] [remote 192.241.143.148:40448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4ZN0Ou5aQNSViFaxM--QABhWw"]
[Mon Jul 20 06:48:55.531088 2026] [security2:error] [pid 1025331:tid 1025446] [remote 192.241.143.148:40448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_AgABInI"], referer: https://schuttfarms.com/wp-login.php
[Mon Jul 20 06:48:55.680803 2026] [security2:error] [pid 1020501:tid 1020701] [client 57.141.18.30:27540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZM8S_oRsP4jdONhf38wAARH0"]
[Mon Jul 20 06:48:55.701682 2026] [security2:error] [pid 1025331:tid 1025503] [client 34.73.38.214:59084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZN0Ou5aQNSViFaxM_DQAAATQ"]
[Mon Jul 20 06:48:55.722719 2026] [security2:error] [pid 1025331:tid 1025501] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/popo.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_EwAAATI"]
[Mon Jul 20 06:48:55.722810 2026] [security2:error] [pid 1025331:tid 1025501] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/popo.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_EwAAATI"]
[Mon Jul 20 06:48:55.858511 2026] [security2:error] [pid 1025331:tid 1025488] [client 14.224.227.113:54721] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZN0Ou5aQNSViFaxM_IAAAASU"]
[Mon Jul 20 06:48:55.901179 2026] [security2:error] [pid 1025331:tid 1025538] [client 152.58.191.29:54180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_IgAAAVc"]
[Mon Jul 20 06:48:55.904811 2026] [security2:error] [pid 1025331:tid 1025538] [client 152.58.191.29:54180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_IgAAAVc"]
[Mon Jul 20 06:48:55.916238 2026] [security2:error] [pid 1025331:tid 1025334] [remote 152.228.213.32:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_IwABdwI"]
[Mon Jul 20 06:48:55.997698 2026] [security2:error] [pid 1025331:tid 1025455] [remote 57.141.18.64:39012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4ZN0Ou5aQNSViFaxM_KgABhXs"]
[Mon Jul 20 06:48:56.012340 2026] [security2:error] [pid 1025331:tid 1025542] [client 57.141.18.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_IQAAAVs"]
[Mon Jul 20 06:48:56.104198 2026] [security2:error] [pid 1025331:tid 1025485] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/yas.php"] [unique_id "al4ZOEOu5aQNSViFaxM_MgAAASI"]
[Mon Jul 20 06:48:56.104300 2026] [security2:error] [pid 1025331:tid 1025485] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/yas.php"] [unique_id "al4ZOEOu5aQNSViFaxM_MgAAASI"]
[Mon Jul 20 06:48:56.117900 2026] [security2:error] [pid 1025331:tid 1025452] [remote 152.228.213.32:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ZOEOu5aQNSViFaxM_NQABX3g"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:48:56.124823 2026] [security2:error] [pid 1025331:tid 1025532] [client 34.73.38.214:55234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZOEOu5aQNSViFaxM_NwAAAVE"]
[Mon Jul 20 06:48:56.451303 2026] [security2:error] [pid 1020501:tid 1020758] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/file61.php"] [unique_id "al4ZOMS_oRsP4jdONhf4UgAAAH0"]
[Mon Jul 20 06:48:56.451383 2026] [security2:error] [pid 1020501:tid 1020758] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/file61.php"] [unique_id "al4ZOMS_oRsP4jdONhf4UgAAAH0"]
[Mon Jul 20 06:48:56.486076 2026] [security2:error] [pid 1020501:tid 1020666] [client 57.141.18.118:47012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZM8S_oRsP4jdONhf3-wAAIXY"]
[Mon Jul 20 06:48:56.584262 2026] [security2:error] [pid 1020501:tid 1020681] [client 34.73.38.214:64657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZOMS_oRsP4jdONhf4VQAAADA"]
[Mon Jul 20 06:48:56.637413 2026] [security2:error] [pid 1025331:tid 1025355] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZOEOu5aQNSViFaxM_UQABchc"]
[Mon Jul 20 06:48:56.637558 2026] [security2:error] [pid 1025331:tid 1025565] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZOEOu5aQNSViFaxM_UQABchc"]
[Mon Jul 20 06:48:56.667787 2026] [security2:error] [pid 1020501:tid 1020697] [client 77.110.127.138:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZOMS_oRsP4jdONhf4WAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:56.667883 2026] [security2:error] [pid 1020501:tid 1020697] [client 77.110.127.138:56989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZOMS_oRsP4jdONhf4WAAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:48:56.837841 2026] [security2:error] [pid 1020501:tid 1020644] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/water.php"] [unique_id "al4ZOMS_oRsP4jdONhf4XgAAAAs"]
[Mon Jul 20 06:48:56.837966 2026] [security2:error] [pid 1020501:tid 1020644] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/water.php"] [unique_id "al4ZOMS_oRsP4jdONhf4XgAAAAs"]
[Mon Jul 20 06:48:57.229137 2026] [security2:error] [pid 1025331:tid 1025568] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/nano.php"] [unique_id "al4ZOUOu5aQNSViFaxM_dAAAAXU"]
[Mon Jul 20 06:48:57.229219 2026] [security2:error] [pid 1025331:tid 1025568] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/nano.php"] [unique_id "al4ZOUOu5aQNSViFaxM_dAAAAXU"]
[Mon Jul 20 06:48:57.453864 2026] [security2:error] [pid 1025331:tid 1025481] [client 57.141.18.79:63934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZNEOu5aQNSViFaxM-bAABHi4"]
[Mon Jul 20 06:48:57.517847 2026] [security2:error] [pid 1025331:tid 1025526] [client 34.73.38.214:64156] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZOUOu5aQNSViFaxM_gQAAAUs"]
[Mon Jul 20 06:48:57.583016 2026] [security2:error] [pid 1025331:tid 1025544] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/moon.php"] [unique_id "al4ZOUOu5aQNSViFaxM_gwAAAV0"]
[Mon Jul 20 06:48:57.583115 2026] [security2:error] [pid 1025331:tid 1025544] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/moon.php"] [unique_id "al4ZOUOu5aQNSViFaxM_gwAAAV0"]
[Mon Jul 20 06:48:57.828133 2026] [security2:error] [pid 1025331:tid 1025529] [client 57.141.18.64:24622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZNUOu5aQNSViFaxM-fQABTlk"]
[Mon Jul 20 06:48:57.963857 2026] [security2:error] [pid 1020501:tid 1020674] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-info.php"] [unique_id "al4ZOcS_oRsP4jdONhf4fwAAACk"]
[Mon Jul 20 06:48:57.963943 2026] [security2:error] [pid 1020501:tid 1020674] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-info.php"] [unique_id "al4ZOcS_oRsP4jdONhf4fwAAACk"]
[Mon Jul 20 06:48:58.017121 2026] [security2:error] [pid 1020501:tid 1020734] [client 34.73.38.214:51409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZOsS_oRsP4jdONhf4gQAAAGU"]
[Mon Jul 20 06:48:58.301092 2026] [security2:error] [pid 1020501:tid 1020687] [client 57.141.18.76:42778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZNcS_oRsP4jdONhf4GgAANng"]
[Mon Jul 20 06:48:58.336320 2026] [security2:error] [pid 1025331:tid 1025543] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/2000.php"] [unique_id "al4ZOkOu5aQNSViFaxM_rwAAAVw"]
[Mon Jul 20 06:48:58.336403 2026] [security2:error] [pid 1025331:tid 1025543] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/2000.php"] [unique_id "al4ZOkOu5aQNSViFaxM_rwAAAVw"]
[Mon Jul 20 06:48:58.357005 2026] [security2:error] [pid 1025331:tid 1025481] [client 34.73.38.214:55955] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZOkOu5aQNSViFaxM_sQAAAR4"]
[Mon Jul 20 06:48:58.491720 2026] [security2:error] [pid 1025331:tid 1025474] [client 23.251.146.115:60416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZOkOu5aQNSViFaxM_swABFzM"]
[Mon Jul 20 06:48:58.606296 2026] [security2:error] [pid 1025331:tid 1025470] [client 23.251.146.115:60416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZOkOu5aQNSViFaxM_vAABEyY"]
[Mon Jul 20 06:48:58.672868 2026] [security2:error] [pid 1025331:tid 1025550] [client 34.31.203.120:11824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZOkOu5aQNSViFaxM_wgABYyQ"]
[Mon Jul 20 06:48:58.681261 2026] [security2:error] [pid 1020501:tid 1020633] [client 45.237.164.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4ZOcS_oRsP4jdONhf4bQAAAAA"]
[Mon Jul 20 06:48:58.689348 2026] [security2:error] [pid 1020501:tid 1020695] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/122.php"] [unique_id "al4ZOsS_oRsP4jdONhf4nAAAAD4"]
[Mon Jul 20 06:48:58.689457 2026] [security2:error] [pid 1020501:tid 1020695] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/122.php"] [unique_id "al4ZOsS_oRsP4jdONhf4nAAAAD4"]
[Mon Jul 20 06:48:58.694961 2026] [security2:error] [pid 1025331:tid 1025525] [client 45.237.164.228:42773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/13315.php"] [unique_id "al4ZOUOu5aQNSViFaxM_awABSn8"]
[Mon Jul 20 06:48:58.786911 2026] [security2:error] [pid 1025331:tid 1025553] [client 57.141.18.17:59230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZNkOu5aQNSViFaxM-qgABZlI"]
[Mon Jul 20 06:48:58.851699 2026] [security2:error] [pid 1025331:tid 1025403] [remote 152.228.213.32:41688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZOkOu5aQNSViFaxM_0wABWUc"]
[Mon Jul 20 06:48:58.855727 2026] [security2:error] [pid 1020501:tid 1020637] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZOsS_oRsP4jdONhf4ngAAAAQ"]
[Mon Jul 20 06:48:58.864864 2026] [security2:error] [pid 1025331:tid 1025494] [client 34.73.38.214:54071] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZOkOu5aQNSViFaxM_1QAAASs"]
[Mon Jul 20 06:48:58.865369 2026] [security2:error] [pid 1025331:tid 1025542] [client 34.31.203.120:11824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZOkOu5aQNSViFaxM_0AABWzQ"]
[Mon Jul 20 06:48:59.054547 2026] [security2:error] [pid 1025331:tid 1025420] [remote 152.228.213.32:41688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_4wABL1g"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:48:59.078894 2026] [security2:error] [pid 1025331:tid 1025577] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/mds.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_5QAAAX4"]
[Mon Jul 20 06:48:59.078985 2026] [security2:error] [pid 1025331:tid 1025577] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/mds.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_5QAAAX4"]
[Mon Jul 20 06:48:59.090093 2026] [security2:error] [pid 1025331:tid 1025517] [client 103.125.179.95:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_5gAAAUI"]
[Mon Jul 20 06:48:59.090172 2026] [security2:error] [pid 1025331:tid 1025517] [client 103.125.179.95:64087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_5gAAAUI"]
[Mon Jul 20 06:48:59.165391 2026] [security2:error] [pid 1025331:tid 1025489] [client 183.82.98.154:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_6QAAASY"]
[Mon Jul 20 06:48:59.165512 2026] [security2:error] [pid 1025331:tid 1025489] [client 183.82.98.154:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_6QAAASY"]
[Mon Jul 20 06:48:59.176084 2026] [security2:error] [pid 1025331:tid 1025502] [client 223.185.13.213:10584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_6wAAATM"]
[Mon Jul 20 06:48:59.176173 2026] [security2:error] [pid 1025331:tid 1025502] [client 223.185.13.213:10584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_6wAAATM"]
[Mon Jul 20 06:48:59.252056 2026] [security2:error] [pid 1025331:tid 1025471] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_7QAAARQ"]
[Mon Jul 20 06:48:59.450573 2026] [security2:error] [pid 1020501:tid 1020751] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-blink.php"] [unique_id "al4ZO8S_oRsP4jdONhf4sgAAAHY"]
[Mon Jul 20 06:48:59.450667 2026] [security2:error] [pid 1020501:tid 1020751] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-blink.php"] [unique_id "al4ZO8S_oRsP4jdONhf4sgAAAHY"]
[Mon Jul 20 06:48:59.513557 2026] [security2:error] [pid 1025331:tid 1025548] [client 34.139.11.221:63062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZO0Ou5aQNSViFaxNAEQAAAWE"]
[Mon Jul 20 06:48:59.643835 2026] [security2:error] [pid 1020501:tid 1020646] [client 34.139.11.221:55364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZO8S_oRsP4jdONhf4uAAAAA0"]
[Mon Jul 20 06:48:59.729327 2026] [security2:error] [pid 1025331:tid 1025541] [client 34.73.38.214:49746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.nikkidesigns.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZO0Ou5aQNSViFaxNAGwAAAVo"]
[Mon Jul 20 06:48:59.795393 2026] [security2:error] [pid 1020501:tid 1020688] [client 34.139.11.221:60166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZO8S_oRsP4jdONhf4uwAAADc"]
[Mon Jul 20 06:48:59.827493 2026] [security2:error] [pid 1025331:tid 1025578] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/zc-208.php"] [unique_id "al4ZO0Ou5aQNSViFaxNAIQAAAX8"]
[Mon Jul 20 06:48:59.827571 2026] [security2:error] [pid 1025331:tid 1025578] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/zc-208.php"] [unique_id "al4ZO0Ou5aQNSViFaxNAIQAAAX8"]
[Mon Jul 20 06:48:59.872053 2026] [security2:error] [pid 1020501:tid 1020682] [client 37.52.210.45:51366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZO8S_oRsP4jdONhf4vQAAADE"]
[Mon Jul 20 06:48:59.872188 2026] [security2:error] [pid 1020501:tid 1020682] [client 37.52.210.45:51366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZO8S_oRsP4jdONhf4vQAAADE"]
[Mon Jul 20 06:48:59.953576 2026] [security2:error] [pid 1025331:tid 1025553] [client 34.139.11.221:52286] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZO0Ou5aQNSViFaxNAMgAAAWY"]
[Mon Jul 20 06:48:59.984194 2026] [security2:error] [pid 1020501:tid 1020684] [client 216.73.216.50:1330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.project.jedalilly.com"] [uri "/index.php"] [unique_id "al4ZOsS_oRsP4jdONhf4mQAAM1A"]
[Mon Jul 20 06:49:00.080918 2026] [security2:error] [pid 1025331:tid 1025500] [client 57.141.18.27:37582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZN0Ou5aQNSViFaxM_AwABMW4"]
[Mon Jul 20 06:49:00.108525 2026] [security2:error] [pid 1020501:tid 1020678] [client 156.245.246.154:62856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.246.245.156.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "allisonsatterfield.alaraycreative.com"] [uri "/index.php"] [unique_id "al4ZPMS_oRsP4jdONhf4xwAAAC0"], referer: https://allisonsatterfield.alaraycreative.com
[Mon Jul 20 06:49:00.116079 2026] [security2:error] [pid 1025331:tid 1025510] [client 34.139.11.221:49734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPEOu5aQNSViFaxNAPwAAATs"]
[Mon Jul 20 06:49:00.195867 2026] [security2:error] [pid 1020501:tid 1020636] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/sid4.php"] [unique_id "al4ZPMS_oRsP4jdONhf4yAAAAAM"]
[Mon Jul 20 06:49:00.195967 2026] [security2:error] [pid 1020501:tid 1020636] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/sid4.php"] [unique_id "al4ZPMS_oRsP4jdONhf4yAAAAAM"]
[Mon Jul 20 06:49:00.206532 2026] [security2:error] [pid 1020501:tid 1020672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZO8S_oRsP4jdONhf4uQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:00.237104 2026] [security2:error] [pid 1025331:tid 1025461] [client 34.139.11.221:61956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPEOu5aQNSViFaxNASQAAAQo"]
[Mon Jul 20 06:49:00.240629 2026] [security2:error] [pid 1025331:tid 1025505] [client 23.251.146.115:23168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPEOu5aQNSViFaxNAQQABNnA"]
[Mon Jul 20 06:49:00.330985 2026] [security2:error] [pid 1020501:tid 1020729] [client 23.251.146.115:20480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPMS_oRsP4jdONhf4yQAAYAI"]
[Mon Jul 20 06:49:00.353786 2026] [security2:error] [pid 1025331:tid 1025517] [client 23.251.146.115:23168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPEOu5aQNSViFaxNATQABQnM"]
[Mon Jul 20 06:49:00.401438 2026] [security2:error] [pid 1025331:tid 1025534] [client 34.139.11.221:51610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPEOu5aQNSViFaxNAUwAAAVM"]
[Mon Jul 20 06:49:00.405070 2026] [security2:error] [pid 1025331:tid 1025577] [client 106.219.188.178:10176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPEOu5aQNSViFaxNAVAAAAX4"]
[Mon Jul 20 06:49:00.405647 2026] [security2:error] [pid 1025331:tid 1025577] [client 106.219.188.178:10176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPEOu5aQNSViFaxNAVAAAAX4"]
[Mon Jul 20 06:49:00.439456 2026] [security2:error] [pid 1020501:tid 1020725] [client 23.251.146.115:20480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPMS_oRsP4jdONhf4ywAAXGE"]
[Mon Jul 20 06:49:00.468573 2026] [security2:error] [pid 1025331:tid 1025465] [client 157.85.211.87:24684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPEOu5aQNSViFaxNAWQAAAQ4"]
[Mon Jul 20 06:49:00.468699 2026] [security2:error] [pid 1025331:tid 1025465] [client 157.85.211.87:24684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPEOu5aQNSViFaxNAWQAAAQ4"]
[Mon Jul 20 06:49:00.546558 2026] [security2:error] [pid 1025331:tid 1025553] [client 34.139.11.221:63046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPEOu5aQNSViFaxNAYgAAAWY"]
[Mon Jul 20 06:49:00.563728 2026] [security2:error] [pid 1025331:tid 1025532] [client 23.251.146.115:16864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPEOu5aQNSViFaxNAWgABUXk"]
[Mon Jul 20 06:49:00.580738 2026] [autoindex:error] [pid 1025331:tid 1025507] [client 20.226.60.151:0] AH01276: Cannot serve directory /home1/cjhtmumy/public_html/.website_2becb178/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:49:00.581339 2026] [security2:error] [pid 1025331:tid 1025507] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "innovativecleaningsvs.com"] [uri "/cgi-sys/403.html"] [unique_id "al4ZPEOu5aQNSViFaxNAZAAAATg"]
[Mon Jul 20 06:49:00.642999 2026] [security2:error] [pid 1025331:tid 1025544] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPEOu5aQNSViFaxNAYQAAAV0"]
[Mon Jul 20 06:49:00.682263 2026] [security2:error] [pid 1025331:tid 1025566] [client 23.251.146.115:16864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPEOu5aQNSViFaxNAaQABcwQ"]
[Mon Jul 20 06:49:00.685454 2026] [security2:error] [pid 1025331:tid 1025582] [client 34.139.11.221:59270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPEOu5aQNSViFaxNAbwAAAYM"]
[Mon Jul 20 06:49:00.735363 2026] [security2:error] [pid 1020501:tid 1020705] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPMS_oRsP4jdONhf41gAAAEg"]
[Mon Jul 20 06:49:00.768886 2026] [security2:error] [pid 1025331:tid 1025513] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wmore1.php"] [unique_id "al4ZPEOu5aQNSViFaxNAegAAAT4"]
[Mon Jul 20 06:49:00.768986 2026] [security2:error] [pid 1025331:tid 1025513] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wmore1.php"] [unique_id "al4ZPEOu5aQNSViFaxNAegAAAT4"]
[Mon Jul 20 06:49:00.784139 2026] [security2:error] [pid 1025331:tid 1025484] [client 77.110.127.138:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZPEOu5aQNSViFaxNAewAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:00.784232 2026] [security2:error] [pid 1025331:tid 1025484] [client 77.110.127.138:57087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZPEOu5aQNSViFaxNAewAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:00.863291 2026] [security2:error] [pid 1025331:tid 1025489] [client 34.139.11.221:49676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPEOu5aQNSViFaxNAgQAAASY"]
[Mon Jul 20 06:49:00.937467 2026] [security2:error] [pid 1020501:tid 1020662] [client 152.58.191.29:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPMS_oRsP4jdONhf43QAAAB0"]
[Mon Jul 20 06:49:00.950316 2026] [security2:error] [pid 1020501:tid 1020662] [client 152.58.191.29:54804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPMS_oRsP4jdONhf43QAAAB0"]
[Mon Jul 20 06:49:00.967186 2026] [security2:error] [pid 1025331:tid 1025536] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4ZPEOu5aQNSViFaxNAhwAAAVU"]
[Mon Jul 20 06:49:01.058090 2026] [security2:error] [pid 1020501:tid 1020655] [client 34.139.11.221:58877] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPcS_oRsP4jdONhf44QAAABY"]
[Mon Jul 20 06:49:01.165722 2026] [security2:error] [pid 1025331:tid 1025584] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/solo1.php"] [unique_id "al4ZPUOu5aQNSViFaxNAnAAAAYU"]
[Mon Jul 20 06:49:01.165863 2026] [security2:error] [pid 1025331:tid 1025584] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/solo1.php"] [unique_id "al4ZPUOu5aQNSViFaxNAnAAAAYU"]
[Mon Jul 20 06:49:01.185396 2026] [security2:error] [pid 1025331:tid 1025475] [client 34.139.11.221:52611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.mpp.jej.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZPUOu5aQNSViFaxNAnwAAARg"]
[Mon Jul 20 06:49:01.407318 2026] [security2:error] [pid 1020501:tid 1020660] [client 117.247.108.24:56189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPcS_oRsP4jdONhf45gAAABs"]
[Mon Jul 20 06:49:01.407425 2026] [security2:error] [pid 1020501:tid 1020660] [client 117.247.108.24:56189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZPcS_oRsP4jdONhf45gAAABs"]
[Mon Jul 20 06:49:01.446644 2026] [security2:error] [pid 1025331:tid 1025572] [client 57.141.18.45:52826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZOEOu5aQNSViFaxM_WgABeQ0"]
[Mon Jul 20 06:49:01.527077 2026] [security2:error] [pid 1020501:tid 1020742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZPcS_oRsP4jdONhf44wAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:01.590651 2026] [security2:error] [pid 1025331:tid 1025543] [client 114.119.135.207:26661] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bandsir.com"] [uri "/europe/bosnia-and-herzegovina/"] [unique_id "al4ZPUOu5aQNSViFaxNAwgAAAVw"], referer: https://www.bandsir.com/europe/bosnia-and-herzegovina/
[Mon Jul 20 06:49:01.602364 2026] [autoindex:error] [pid 1025331:tid 1025583] [client 20.226.60.151:0] AH01276: Cannot serve directory /home1/cjhtmumy/public_html/.website_2becb178/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:49:01.602880 2026] [security2:error] [pid 1025331:tid 1025583] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "innovativecleaningsvs.com"] [uri "/cgi-sys/403.html"] [unique_id "al4ZPUOu5aQNSViFaxNAwQAAAYQ"]
[Mon Jul 20 06:49:01.798217 2026] [security2:error] [pid 1025331:tid 1025547] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/cong.php"] [unique_id "al4ZPUOu5aQNSViFaxNAzwAAAWA"]
[Mon Jul 20 06:49:01.798291 2026] [security2:error] [pid 1025331:tid 1025547] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/cong.php"] [unique_id "al4ZPUOu5aQNSViFaxNAzwAAAWA"]
[Mon Jul 20 06:49:01.898848 2026] [security2:error] [pid 1025331:tid 1025509] [client 104.234.53.87:31081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZPUOu5aQNSViFaxNAzQAAATo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:01.920243 2026] [proxy:error] [pid 1020501:tid 1020745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:01.920308 2026] [proxy_http:error] [pid 1020501:tid 1020745] [client 205.210.31.43:59538] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:01.920889 2026] [proxy:error] [pid 1020501:tid 1020745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:01.920917 2026] [proxy_http:error] [pid 1020501:tid 1020745] [client 205.210.31.43:59538] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:02.073351 2026] [security2:error] [pid 1025331:tid 1025587] [client 65.111.20.177:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZPkOu5aQNSViFaxNA4gAAAYg"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:49:02.179280 2026] [autoindex:error] [pid 1025331:tid 1025548] [client 20.226.60.151:0] AH01276: Cannot serve directory /home1/cjhtmumy/public_html/.website_2becb178/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:49:02.179941 2026] [security2:error] [pid 1025331:tid 1025548] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "innovativecleaningsvs.com"] [uri "/cgi-sys/403.html"] [unique_id "al4ZPkOu5aQNSViFaxNA7QAAAWE"]
[Mon Jul 20 06:49:02.264616 2026] [security2:error] [pid 1025331:tid 1025477] [client 104.234.53.87:31081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZPkOu5aQNSViFaxNA8wAAARo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:02.388763 2026] [security2:error] [pid 1025331:tid 1025582] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/public/css.php"] [unique_id "al4ZPkOu5aQNSViFaxNBAAAAAYM"]
[Mon Jul 20 06:49:02.388887 2026] [security2:error] [pid 1025331:tid 1025582] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/public/css.php"] [unique_id "al4ZPkOu5aQNSViFaxNBAAAAAYM"]
[Mon Jul 20 06:49:02.413582 2026] [security2:error] [pid 1025331:tid 1025375] [remote 52.167.144.170:16983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.144.167.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/themes/daisy-theme/rslib/minify/load.php"] [unique_id "al4ZPkOu5aQNSViFaxNA_gABZys"], referer: https://lifeisbetterlakeside.com/lake-life-when-the-lake-takes-over-the-yard/
[Mon Jul 20 06:49:02.435733 2026] [security2:error] [pid 1025331:tid 1025578] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ZPUOu5aQNSViFaxNA0QAAAX8"]
[Mon Jul 20 06:49:02.535199 2026] [security2:error] [pid 1025331:tid 1025561] [client 57.141.18.51:40060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZOUOu5aQNSViFaxM_mAABbiE"]
[Mon Jul 20 06:49:02.672615 2026] [security2:error] [pid 1020501:tid 1020701] [client 57.141.18.2:36916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZOsS_oRsP4jdONhf4ggAARCc"]
[Mon Jul 20 06:49:02.746569 2026] [security2:error] [pid 1025331:tid 1025521] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/output.php"] [unique_id "al4ZPkOu5aQNSViFaxNBIQAAAUY"]
[Mon Jul 20 06:49:02.746663 2026] [security2:error] [pid 1025331:tid 1025521] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/output.php"] [unique_id "al4ZPkOu5aQNSViFaxNBIQAAAUY"]
[Mon Jul 20 06:49:02.799723 2026] [security2:error] [pid 1025331:tid 1025392] [remote 57.141.18.39:59621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3509628"] [unique_id "al4ZPkOu5aQNSViFaxNBHgABeTw"]
[Mon Jul 20 06:49:02.963084 2026] [security2:error] [pid 1025331:tid 1025491] [client 174.238.51.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4ZPUOu5aQNSViFaxNA2wAAASg"], referer: https://itekphonerepair.com/
[Mon Jul 20 06:49:03.013616 2026] [security2:error] [pid 1025331:tid 1025531] [client 202.46.92.242:56443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBOQAAAVA"]
[Mon Jul 20 06:49:03.014385 2026] [security2:error] [pid 1025331:tid 1025531] [client 202.46.92.242:56443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBOQAAAVA"]
[Mon Jul 20 06:49:03.119231 2026] [security2:error] [pid 1025331:tid 1025492] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-file-120.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBQgAAASk"]
[Mon Jul 20 06:49:03.119330 2026] [security2:error] [pid 1025331:tid 1025492] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-file-120.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBQgAAASk"]
[Mon Jul 20 06:49:03.187808 2026] [security2:error] [pid 1025331:tid 1025558] [client 103.238.106.162:60877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBRgAAAWs"]
[Mon Jul 20 06:49:03.187894 2026] [security2:error] [pid 1025331:tid 1025558] [client 103.238.106.162:60877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBRgAAAWs"]
[Mon Jul 20 06:49:03.475302 2026] [security2:error] [pid 1020501:tid 1020660] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/special.php"] [unique_id "al4ZP8S_oRsP4jdONhf5GQAAABs"]
[Mon Jul 20 06:49:03.475431 2026] [security2:error] [pid 1020501:tid 1020660] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/special.php"] [unique_id "al4ZP8S_oRsP4jdONhf5GQAAABs"]
[Mon Jul 20 06:49:03.483566 2026] [security2:error] [pid 1025331:tid 1025578] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBQwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:03.503202 2026] [security2:error] [pid 1025331:tid 1025485] [client 57.141.18.119:36398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZOkOu5aQNSViFaxM_zAABIj0"]
[Mon Jul 20 06:49:03.828899 2026] [security2:error] [pid 1025331:tid 1025579] [client 57.141.18.18:64396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZO0Ou5aQNSViFaxM_5wABgEs"]
[Mon Jul 20 06:49:03.877523 2026] [security2:error] [pid 1025331:tid 1025573] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/as.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBcQAAAXo"]
[Mon Jul 20 06:49:03.877620 2026] [security2:error] [pid 1025331:tid 1025573] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/as.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBcQAAAXo"]
[Mon Jul 20 06:49:03.966382 2026] [security2:error] [pid 1025331:tid 1025567] [client 158.173.89.95:59147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBeAAAAXQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:49:03.993495 2026] [security2:error] [pid 1025331:tid 1025499] [client 217.142.18.172:14204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBewAAATA"]
[Mon Jul 20 06:49:04.001149 2026] [security2:error] [pid 1025331:tid 1025499] [client 217.142.18.172:14204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZP0Ou5aQNSViFaxNBewAAATA"]
[Mon Jul 20 06:49:04.015485 2026] [security2:error] [pid 1025331:tid 1025541] [client 104.234.53.68:53679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZQEOu5aQNSViFaxNBgQAAAVo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:04.235986 2026] [security2:error] [pid 1025331:tid 1025547] [client 197.186.66.42:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZQEOu5aQNSViFaxNBmAAAAWA"]
[Mon Jul 20 06:49:04.236150 2026] [security2:error] [pid 1025331:tid 1025547] [client 197.186.66.42:56272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZQEOu5aQNSViFaxNBmAAAAWA"]
[Mon Jul 20 06:49:04.254259 2026] [security2:error] [pid 1025331:tid 1025568] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/cgi-bin/index.php"] [unique_id "al4ZQEOu5aQNSViFaxNBmQAAAXU"]
[Mon Jul 20 06:49:04.254370 2026] [security2:error] [pid 1025331:tid 1025568] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/cgi-bin/index.php"] [unique_id "al4ZQEOu5aQNSViFaxNBmQAAAXU"]
[Mon Jul 20 06:49:04.281589 2026] [security2:error] [pid 1025331:tid 1025514] [client 50.116.65.227:56604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZQEOu5aQNSViFaxNBmwAAAT8"]
[Mon Jul 20 06:49:04.295201 2026] [security2:error] [pid 1025331:tid 1025575] [client 50.116.65.227:56614] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZQEOu5aQNSViFaxNBngAAAXw"]
[Mon Jul 20 06:49:04.345361 2026] [security2:error] [pid 1025331:tid 1025487] [client 57.141.18.13:53212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZO0Ou5aQNSViFaxNAFwABJFw"]
[Mon Jul 20 06:49:04.516565 2026] [security2:error] [pid 1020501:tid 1020689] [client 57.141.18.9:31238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZO8S_oRsP4jdONhf4wAAAOHk"]
[Mon Jul 20 06:49:04.626221 2026] [security2:error] [pid 1025331:tid 1025541] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/w1px.php"] [unique_id "al4ZQEOu5aQNSViFaxNBrQAAAVo"]
[Mon Jul 20 06:49:04.626311 2026] [security2:error] [pid 1025331:tid 1025541] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/w1px.php"] [unique_id "al4ZQEOu5aQNSViFaxNBrQAAAVo"]
[Mon Jul 20 06:49:04.818911 2026] [security2:error] [pid 1025331:tid 1025486] [client 136.112.200.207:14854] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "bundleofjoyandpoop.com"] [uri "/wp-json/batch/v1"] [unique_id "al4ZQEOu5aQNSViFaxNBugAAASM"]
[Mon Jul 20 06:49:04.865389 2026] [security2:error] [pid 1025331:tid 1025534] [client 136.112.200.207:14854] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "bundleofjoyandpoop.com"] [uri "/"] [unique_id "al4ZQEOu5aQNSViFaxNBvAAAAVM"]
[Mon Jul 20 06:49:04.950680 2026] [security2:error] [pid 1020501:tid 1020690] [client 57.141.18.117:20246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZPMS_oRsP4jdONhf4zQAAOTU"]
[Mon Jul 20 06:49:04.981873 2026] [security2:error] [pid 1020501:tid 1020743] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/yawa.php"] [unique_id "al4ZQMS_oRsP4jdONhf5PAAAAG4"]
[Mon Jul 20 06:49:04.981980 2026] [security2:error] [pid 1020501:tid 1020743] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/yawa.php"] [unique_id "al4ZQMS_oRsP4jdONhf5PAAAAG4"]
[Mon Jul 20 06:49:05.358389 2026] [security2:error] [pid 1025331:tid 1025527] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/js.php"] [unique_id "al4ZQUOu5aQNSViFaxNB2gAAAUw"]
[Mon Jul 20 06:49:05.358466 2026] [security2:error] [pid 1025331:tid 1025527] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/js.php"] [unique_id "al4ZQUOu5aQNSViFaxNB2gAAAUw"]
[Mon Jul 20 06:49:05.643471 2026] [security2:error] [pid 1025331:tid 1025572] [client 193.47.62.167:60730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "hoomanr.com"] [uri "/index.php"] [unique_id "al4ZQUOu5aQNSViFaxNB6AAAAXk"]
[Mon Jul 20 06:49:05.644512 2026] [security2:error] [pid 1025331:tid 1025575] [client 193.47.62.167:60720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.hoomanr.com"] [uri "/index.php"] [unique_id "al4ZQUOu5aQNSViFaxNB6gAAAXw"]
[Mon Jul 20 06:49:05.708088 2026] [security2:error] [pid 1025331:tid 1025530] [client 193.47.62.167:60736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.hoomanr.com"] [uri "/index.php"] [unique_id "al4ZQUOu5aQNSViFaxNB7wAAAU8"]
[Mon Jul 20 06:49:05.739088 2026] [security2:error] [pid 1025331:tid 1025518] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/core.php"] [unique_id "al4ZQUOu5aQNSViFaxNB8wAAAUM"]
[Mon Jul 20 06:49:05.739161 2026] [security2:error] [pid 1025331:tid 1025518] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/core.php"] [unique_id "al4ZQUOu5aQNSViFaxNB8wAAAUM"]
[Mon Jul 20 06:49:05.996029 2026] [security2:error] [pid 1025331:tid 1025586] [client 57.141.18.19:30386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZPUOu5aQNSViFaxNAoQABhz4"]
[Mon Jul 20 06:49:06.004775 2026] [security2:error] [pid 1025331:tid 1025468] [client 187.108.85.186:50483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZQkOu5aQNSViFaxNCAAAAARE"]
[Mon Jul 20 06:49:06.005031 2026] [security2:error] [pid 1025331:tid 1025468] [client 187.108.85.186:50483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZQkOu5aQNSViFaxNCAAAAARE"]
[Mon Jul 20 06:49:06.033439 2026] [security2:error] [pid 1025331:tid 1025563] [client 104.234.53.58:51145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZQkOu5aQNSViFaxNCAQAAAXA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:06.101867 2026] [core:error] [pid 1020501:tid 1020687] [client 14.225.17.146:61322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/NEW
[Mon Jul 20 06:49:06.101889 2026] [core:error] [pid 1020501:tid 1020687] [client 14.225.17.146:61322] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/NEW
[Mon Jul 20 06:49:06.111330 2026] [security2:error] [pid 1025331:tid 1025508] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/19.php"] [unique_id "al4ZQkOu5aQNSViFaxNCBQAAATk"]
[Mon Jul 20 06:49:06.111426 2026] [security2:error] [pid 1025331:tid 1025508] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/19.php"] [unique_id "al4ZQkOu5aQNSViFaxNCBQAAATk"]
[Mon Jul 20 06:49:06.169789 2026] [security2:error] [pid 1025331:tid 1025504] [client 14.225.17.146:61267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4ZQkOu5aQNSViFaxNCAwAAATU"], referer: http://cloudspacesgroup.com/NEW
[Mon Jul 20 06:49:06.422376 2026] [security2:error] [pid 1020501:tid 1020692] [client 14.225.17.146:61271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4ZQsS_oRsP4jdONhf5TAAAADs"], referer: http://backandneckpainrelieflaceychiropractor.com/NEW
[Mon Jul 20 06:49:06.491739 2026] [security2:error] [pid 1025331:tid 1025585] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/inc.php"] [unique_id "al4ZQkOu5aQNSViFaxNCIQAAAYY"]
[Mon Jul 20 06:49:06.491851 2026] [security2:error] [pid 1025331:tid 1025585] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/inc.php"] [unique_id "al4ZQkOu5aQNSViFaxNCIQAAAYY"]
[Mon Jul 20 06:49:06.498629 2026] [security2:error] [pid 1025331:tid 1025473] [client 57.141.18.58:56254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZPUOu5aQNSViFaxNA0gABFhA"]
[Mon Jul 20 06:49:06.740635 2026] [security2:error] [pid 1025331:tid 1025479] [client 40.77.167.72:9232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ZQkOu5aQNSViFaxNCHQABHBE"], referer: https://lifeisbetterlakeside.com/lake-life-when-the-lake-takes-over-the-yard/
[Mon Jul 20 06:49:06.838196 2026] [security2:error] [pid 1025331:tid 1025565] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-ppoxua4.php"] [unique_id "al4ZQkOu5aQNSViFaxNCNAAAAXI"]
[Mon Jul 20 06:49:06.838309 2026] [security2:error] [pid 1025331:tid 1025565] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-ppoxua4.php"] [unique_id "al4ZQkOu5aQNSViFaxNCNAAAAXI"]
[Mon Jul 20 06:49:06.948494 2026] [autoindex:error] [pid 1025331:tid 1025575] [client 147.93.171.185:56469] AH01276: Cannot serve directory /home2/adultda1/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:49:07.083955 2026] [security2:error] [pid 1025331:tid 1025583] [client 57.141.18.110:49290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZPkOu5aQNSViFaxNA-QABhDc"]
[Mon Jul 20 06:49:07.100169 2026] [security2:error] [pid 1025331:tid 1025539] [client 39.48.81.23:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCQgAAAVg"]
[Mon Jul 20 06:49:07.100279 2026] [security2:error] [pid 1025331:tid 1025539] [client 39.48.81.23:53796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCQgAAAVg"]
[Mon Jul 20 06:49:07.205129 2026] [security2:error] [pid 1025331:tid 1025482] [client 57.141.18.41:26734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZPkOu5aQNSViFaxNBAQABH2Q"]
[Mon Jul 20 06:49:07.226078 2026] [security2:error] [pid 1025331:tid 1025494] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCSwAAASs"]
[Mon Jul 20 06:49:07.226157 2026] [security2:error] [pid 1025331:tid 1025494] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-u3nxbvx.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCSwAAASs"]
[Mon Jul 20 06:49:07.446507 2026] [security2:error] [pid 1025331:tid 1025370] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCWAABciY"]
[Mon Jul 20 06:49:07.446688 2026] [security2:error] [pid 1025331:tid 1025565] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCWAABciY"]
[Mon Jul 20 06:49:07.625381 2026] [security2:error] [pid 1020501:tid 1020695] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ss.php"] [unique_id "al4ZQ8S_oRsP4jdONhf5dQAAAD4"]
[Mon Jul 20 06:49:07.625496 2026] [security2:error] [pid 1020501:tid 1020695] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ss.php"] [unique_id "al4ZQ8S_oRsP4jdONhf5dQAAAD4"]
[Mon Jul 20 06:49:07.934304 2026] [security2:error] [pid 1025331:tid 1025500] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCbQAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:07.988893 2026] [security2:error] [pid 1025331:tid 1025491] [client 40.77.167.72:9232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCdgABKFE"], referer: https://lifeisbetterlakeside.com/lake-life-when-the-lake-takes-over-the-yard/
[Mon Jul 20 06:49:08.009226 2026] [security2:error] [pid 1025331:tid 1025526] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/min.php"] [unique_id "al4ZREOu5aQNSViFaxNCgQAAAUs"]
[Mon Jul 20 06:49:08.009317 2026] [security2:error] [pid 1025331:tid 1025526] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/min.php"] [unique_id "al4ZREOu5aQNSViFaxNCgQAAAUs"]
[Mon Jul 20 06:49:08.076645 2026] [fcgid:warn] [pid 1025331:tid 1025498] (70014)End of file found: [client 199.45.155.94:34366] mod_fcgid: can't get data from http client
[Mon Jul 20 06:49:08.136782 2026] [security2:error] [pid 1020501:tid 1020739] [client 14.225.17.146:64416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4ZQsS_oRsP4jdONhf5TQAAAGo"]
[Mon Jul 20 06:49:08.384843 2026] [security2:error] [pid 1025331:tid 1025496] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al4ZREOu5aQNSViFaxNClgAAAS0"]
[Mon Jul 20 06:49:08.384955 2026] [security2:error] [pid 1025331:tid 1025496] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-admin/wpyfiavs.php"] [unique_id "al4ZREOu5aQNSViFaxNClgAAAS0"]
[Mon Jul 20 06:49:08.744840 2026] [security2:error] [pid 1025331:tid 1025505] [client 57.141.18.51:47654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZQEOu5aQNSViFaxNBhQABNnI"]
[Mon Jul 20 06:49:08.765563 2026] [security2:error] [pid 1025331:tid 1025491] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/autoload_classmap.php"] [unique_id "al4ZREOu5aQNSViFaxNCsgAAASg"]
[Mon Jul 20 06:49:08.765706 2026] [security2:error] [pid 1025331:tid 1025491] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/autoload_classmap.php"] [unique_id "al4ZREOu5aQNSViFaxNCsgAAASg"]
[Mon Jul 20 06:49:08.779076 2026] [security2:error] [pid 1025331:tid 1025474] [client 77.110.127.138:57197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZREOu5aQNSViFaxNCswAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:08.779197 2026] [security2:error] [pid 1025331:tid 1025474] [client 77.110.127.138:57197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZREOu5aQNSViFaxNCswAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:08.812817 2026] [security2:error] [pid 1025331:tid 1025487] [client 14.225.17.146:54527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4ZREOu5aQNSViFaxNCowAAASQ"], referer: http://taskidsvirginia.com/NEW
[Mon Jul 20 06:49:08.937156 2026] [security2:error] [pid 1020501:tid 1020670] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZRMS_oRsP4jdONhf5mAAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:09.110453 2026] [security2:error] [pid 1025331:tid 1025497] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-link-zorm.php"] [unique_id "al4ZRUOu5aQNSViFaxNCzAAAAS4"]
[Mon Jul 20 06:49:09.110593 2026] [security2:error] [pid 1025331:tid 1025497] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-link-zorm.php"] [unique_id "al4ZRUOu5aQNSViFaxNCzAAAAS4"]
[Mon Jul 20 06:49:09.307054 2026] [security2:error] [pid 1025331:tid 1025504] [client 104.234.53.87:43871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZRUOu5aQNSViFaxNC1wAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:09.463075 2026] [security2:error] [pid 1025331:tid 1025525] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-link-szoppm.php"] [unique_id "al4ZRUOu5aQNSViFaxNC4QAAAUo"]
[Mon Jul 20 06:49:09.463191 2026] [security2:error] [pid 1025331:tid 1025525] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-link-szoppm.php"] [unique_id "al4ZRUOu5aQNSViFaxNC4QAAAUo"]
[Mon Jul 20 06:49:09.773505 2026] [security2:error] [pid 1020501:tid 1020539] [remote 182.77.62.24:48994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ZRcS_oRsP4jdONhf5sAAAVSM"]
[Mon Jul 20 06:49:09.861273 2026] [security2:error] [pid 1025331:tid 1025564] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/albin.php"] [unique_id "al4ZRUOu5aQNSViFaxNC-AAAAXE"]
[Mon Jul 20 06:49:09.861382 2026] [security2:error] [pid 1025331:tid 1025564] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/albin.php"] [unique_id "al4ZRUOu5aQNSViFaxNC-AAAAXE"]
[Mon Jul 20 06:49:09.881965 2026] [security2:error] [pid 1020501:tid 1020713] [client 223.185.13.213:16479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRcS_oRsP4jdONhf5tgAAAFA"]
[Mon Jul 20 06:49:09.882146 2026] [security2:error] [pid 1020501:tid 1020713] [client 223.185.13.213:16479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRcS_oRsP4jdONhf5tgAAAFA"]
[Mon Jul 20 06:49:10.163167 2026] [security2:error] [pid 1025331:tid 1025477] [client 14.225.17.146:54551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4ZRUOu5aQNSViFaxNC6AAAARo"], referer: http://drewsasburyparkbeachhouse.com/NEW
[Mon Jul 20 06:49:10.180565 2026] [security2:error] [pid 1025331:tid 1025474] [client 183.82.98.154:57248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRkOu5aQNSViFaxNDBAAAARc"]
[Mon Jul 20 06:49:10.180665 2026] [security2:error] [pid 1025331:tid 1025474] [client 183.82.98.154:57248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRkOu5aQNSViFaxNDBAAAARc"]
[Mon Jul 20 06:49:10.216549 2026] [security2:error] [pid 1025331:tid 1025563] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZRUOu5aQNSViFaxNC9gAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:10.220774 2026] [autoindex:error] [pid 1025331:tid 1025553] [client 147.93.171.186:56282] AH01276: Cannot serve directory /home3/etterbp3/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:49:10.231282 2026] [security2:error] [pid 1025331:tid 1025509] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/cilus.php"] [unique_id "al4ZRkOu5aQNSViFaxNDCAAAATo"]
[Mon Jul 20 06:49:10.231415 2026] [security2:error] [pid 1025331:tid 1025509] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/cilus.php"] [unique_id "al4ZRkOu5aQNSViFaxNDCAAAATo"]
[Mon Jul 20 06:49:10.249449 2026] [security2:error] [pid 1025331:tid 1025505] [client 103.125.179.95:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRkOu5aQNSViFaxNDCgAAATY"]
[Mon Jul 20 06:49:10.249604 2026] [security2:error] [pid 1025331:tid 1025505] [client 103.125.179.95:64753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRkOu5aQNSViFaxNDCgAAATY"]
[Mon Jul 20 06:49:10.322966 2026] [security2:error] [pid 1020501:tid 1020620] [remote 182.77.62.24:48994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ZRsS_oRsP4jdONhf5xwAAeXQ"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:49:10.461457 2026] [security2:error] [pid 1025331:tid 1025466] [client 14.251.3.155:54724] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZRkOu5aQNSViFaxNDGQAAAQ8"]
[Mon Jul 20 06:49:10.511606 2026] [security2:error] [pid 1020501:tid 1020660] [client 37.52.210.45:16434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZRsS_oRsP4jdONhf5ywAAABs"]
[Mon Jul 20 06:49:10.511722 2026] [security2:error] [pid 1020501:tid 1020660] [client 37.52.210.45:16434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZRsS_oRsP4jdONhf5ywAAABs"]
[Mon Jul 20 06:49:10.634509 2026] [security2:error] [pid 1025331:tid 1025475] [client 57.141.18.65:36018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZQkOu5aQNSViFaxNCCwABGBM"]
[Mon Jul 20 06:49:10.638361 2026] [proxy:error] [pid 1020501:tid 1020745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:10.638415 2026] [proxy_http:error] [pid 1020501:tid 1020745] [client 193.47.62.167:60744] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:10.638676 2026] [security2:error] [pid 1025331:tid 1025584] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/gptsh.php"] [unique_id "al4ZRkOu5aQNSViFaxNDIgAAAYU"]
[Mon Jul 20 06:49:10.638767 2026] [security2:error] [pid 1025331:tid 1025584] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/gptsh.php"] [unique_id "al4ZRkOu5aQNSViFaxNDIgAAAYU"]
[Mon Jul 20 06:49:10.639085 2026] [proxy:error] [pid 1020501:tid 1020745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:10.639121 2026] [proxy_http:error] [pid 1020501:tid 1020745] [client 193.47.62.167:60744] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:10.776546 2026] [security2:error] [pid 1025331:tid 1025520] [client 106.219.188.178:10277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRkOu5aQNSViFaxNDJwAAAUU"]
[Mon Jul 20 06:49:10.776664 2026] [security2:error] [pid 1025331:tid 1025520] [client 106.219.188.178:10277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZRkOu5aQNSViFaxNDJwAAAUU"]
[Mon Jul 20 06:49:10.803983 2026] [security2:error] [pid 1025331:tid 1025565] [client 14.225.17.146:49776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4ZRUOu5aQNSViFaxNC2gAAAXI"], referer: http://inspirespublishing.com/NEW
[Mon Jul 20 06:49:10.993606 2026] [security2:error] [pid 1020501:tid 1020635] [client 57.141.18.64:37788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZQsS_oRsP4jdONhf5YQAAAlo"]
[Mon Jul 20 06:49:11.027705 2026] [security2:error] [pid 1020501:tid 1020691] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/rithin.php"] [unique_id "al4ZR8S_oRsP4jdONhf54AAAADo"]
[Mon Jul 20 06:49:11.027806 2026] [security2:error] [pid 1020501:tid 1020691] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/rithin.php"] [unique_id "al4ZR8S_oRsP4jdONhf54AAAADo"]
[Mon Jul 20 06:49:11.160705 2026] [security2:error] [pid 1025331:tid 1025547] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZRkOu5aQNSViFaxNDHQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:11.413535 2026] [security2:error] [pid 1020501:tid 1020687] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/fffm.php"] [unique_id "al4ZR8S_oRsP4jdONhf58AAAADY"]
[Mon Jul 20 06:49:11.413645 2026] [security2:error] [pid 1020501:tid 1020687] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/fffm.php"] [unique_id "al4ZR8S_oRsP4jdONhf58AAAADY"]
[Mon Jul 20 06:49:11.667320 2026] [security2:error] [pid 1025331:tid 1025574] [client 57.141.18.74:58670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCTQABeyQ"]
[Mon Jul 20 06:49:11.681519 2026] [security2:error] [pid 1020501:tid 1020576] [remote 152.228.213.32:60116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4ZR8S_oRsP4jdONhf5-wAAI0g"]
[Mon Jul 20 06:49:11.684800 2026] [security2:error] [pid 1025331:tid 1025480] [client 122.183.32.225:4507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDWwAAAR0"]
[Mon Jul 20 06:49:11.684902 2026] [security2:error] [pid 1025331:tid 1025480] [client 122.183.32.225:4507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDWwAAAR0"]
[Mon Jul 20 06:49:11.802294 2026] [security2:error] [pid 1020501:tid 1020638] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/dfre.php"] [unique_id "al4ZR8S_oRsP4jdONhf6AwAAAAU"]
[Mon Jul 20 06:49:11.802423 2026] [security2:error] [pid 1020501:tid 1020638] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/dfre.php"] [unique_id "al4ZR8S_oRsP4jdONhf6AwAAAAU"]
[Mon Jul 20 06:49:11.813628 2026] [security2:error] [pid 1025331:tid 1025532] [client 74.208.214.194:59598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDYAAAAVE"]
[Mon Jul 20 06:49:11.876910 2026] [security2:error] [pid 1025331:tid 1025571] [client 57.141.18.56:54562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZQ0Ou5aQNSViFaxNCXgABeEc"]
[Mon Jul 20 06:49:11.883775 2026] [security2:error] [pid 1020501:tid 1020610] [remote 152.228.213.32:60116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4ZR8S_oRsP4jdONhf6BgAAZmo"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:49:12.076206 2026] [security2:error] [pid 1020501:tid 1020660] [client 65.111.20.214:19159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZSMS_oRsP4jdONhf6DwAAABs"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:49:12.158042 2026] [security2:error] [pid 1025331:tid 1025556] [client 207.46.13.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDaAAAAWk"]
[Mon Jul 20 06:49:12.167833 2026] [security2:error] [pid 1020501:tid 1020722] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-happy.php"] [unique_id "al4ZSMS_oRsP4jdONhf6FgAAAFk"]
[Mon Jul 20 06:49:12.167929 2026] [security2:error] [pid 1020501:tid 1020722] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/wp-happy.php"] [unique_id "al4ZSMS_oRsP4jdONhf6FgAAAFk"]
[Mon Jul 20 06:49:12.311071 2026] [security2:error] [pid 1025331:tid 1025491] [client 77.110.127.138:57242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZSEOu5aQNSViFaxNDewAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:12.311149 2026] [security2:error] [pid 1025331:tid 1025491] [client 77.110.127.138:57242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZSEOu5aQNSViFaxNDewAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:12.331026 2026] [security2:error] [pid 1025331:tid 1025489] [client 117.247.108.24:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSEOu5aQNSViFaxNDfQAAASY"]
[Mon Jul 20 06:49:12.331145 2026] [security2:error] [pid 1025331:tid 1025489] [client 117.247.108.24:57061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSEOu5aQNSViFaxNDfQAAASY"]
[Mon Jul 20 06:49:12.362001 2026] [security2:error] [pid 1020501:tid 1020643] [client 136.112.200.207:46554] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "bundleofjoyandpoop.com"] [uri "/"] [unique_id "al4ZSMS_oRsP4jdONhf6IQAAAAo"]
[Mon Jul 20 06:49:12.446193 2026] [security2:error] [pid 1025331:tid 1025495] [client 57.141.18.119:36412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZREOu5aQNSViFaxNChwABLDA"]
[Mon Jul 20 06:49:12.504426 2026] [security2:error] [pid 1025331:tid 1025485] [client 14.225.17.146:53179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4ZSEOu5aQNSViFaxNDfgAAASI"], referer: http://lutheranphilosopher.com/NEW
[Mon Jul 20 06:49:12.540706 2026] [security2:error] [pid 1025331:tid 1025475] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/fpr4.php"] [unique_id "al4ZSEOu5aQNSViFaxNDigAAARg"]
[Mon Jul 20 06:49:12.540824 2026] [security2:error] [pid 1025331:tid 1025475] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/fpr4.php"] [unique_id "al4ZSEOu5aQNSViFaxNDigAAARg"]
[Mon Jul 20 06:49:12.559539 2026] [security2:error] [pid 1025331:tid 1025541] [client 14.225.17.146:56133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDWAAAAVo"]
[Mon Jul 20 06:49:12.733549 2026] [security2:error] [pid 1025331:tid 1025512] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZSEOu5aQNSViFaxNDbAAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:12.765053 2026] [security2:error] [pid 1025331:tid 1025559] [client 152.58.191.29:55303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSEOu5aQNSViFaxNDngAAAWw"]
[Mon Jul 20 06:49:12.890713 2026] [security2:error] [pid 1025331:tid 1025510] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/file88.php"] [unique_id "al4ZSEOu5aQNSViFaxNDpwAAATs"]
[Mon Jul 20 06:49:12.890804 2026] [security2:error] [pid 1025331:tid 1025510] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/file88.php"] [unique_id "al4ZSEOu5aQNSViFaxNDpwAAATs"]
[Mon Jul 20 06:49:12.961135 2026] [security2:error] [pid 1025331:tid 1025583] [client 57.141.18.114:62940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZREOu5aQNSViFaxNCpgABhDs"]
[Mon Jul 20 06:49:12.984348 2026] [security2:error] [pid 1025331:tid 1025574] [client 45.157.112.60:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZSEOu5aQNSViFaxNDrgAAAXs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:49:12.985979 2026] [security2:error] [pid 1025331:tid 1025477] [client 49.36.80.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZSEOu5aQNSViFaxNDoQAAARo"], referer: https://mezzacraft.com/half-star-flower-crochet-motif-free-pattern/
[Mon Jul 20 06:49:13.133092 2026] [security2:error] [pid 1025331:tid 1025560] [client 14.225.17.146:54984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4ZSEOu5aQNSViFaxNDrQAAAW0"], referer: http://alchemygroup.ca/NEW
[Mon Jul 20 06:49:13.285332 2026] [security2:error] [pid 1025331:tid 1025548] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ccc.php"] [unique_id "al4ZSUOu5aQNSViFaxNDxwAAAWE"]
[Mon Jul 20 06:49:13.285445 2026] [security2:error] [pid 1025331:tid 1025548] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ccc.php"] [unique_id "al4ZSUOu5aQNSViFaxNDxwAAAWE"]
[Mon Jul 20 06:49:13.400283 2026] [security2:error] [pid 1025331:tid 1025482] [client 45.3.55.187:27757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZSUOu5aQNSViFaxND0wAAAR8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:49:13.449960 2026] [security2:error] [pid 1025331:tid 1025395] [remote 20.153.140.50:40036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZSUOu5aQNSViFaxND2gABQT8"]
[Mon Jul 20 06:49:13.569813 2026] [security2:error] [pid 1025331:tid 1025559] [client 152.58.191.29:55303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSEOu5aQNSViFaxNDngAAAWw"]
[Mon Jul 20 06:49:13.592079 2026] [security2:error] [pid 1020501:tid 1020736] [client 202.46.92.242:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZScS_oRsP4jdONhf6OgAAAGc"]
[Mon Jul 20 06:49:13.592197 2026] [security2:error] [pid 1020501:tid 1020736] [client 202.46.92.242:56909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZScS_oRsP4jdONhf6OgAAAGc"]
[Mon Jul 20 06:49:13.604229 2026] [security2:error] [pid 1025331:tid 1025469] [client 57.141.18.97:50122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZRUOu5aQNSViFaxNC2AABEm0"]
[Mon Jul 20 06:49:13.668739 2026] [security2:error] [pid 1020501:tid 1020677] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/777.php"] [unique_id "al4ZScS_oRsP4jdONhf6PQAAACw"]
[Mon Jul 20 06:49:13.668858 2026] [security2:error] [pid 1020501:tid 1020677] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/777.php"] [unique_id "al4ZScS_oRsP4jdONhf6PQAAACw"]
[Mon Jul 20 06:49:13.689532 2026] [security2:error] [pid 1025331:tid 1025521] [client 103.238.106.162:63803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZSUOu5aQNSViFaxND6QAAAUY"]
[Mon Jul 20 06:49:13.689630 2026] [security2:error] [pid 1025331:tid 1025521] [client 103.238.106.162:63803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZSUOu5aQNSViFaxND6QAAAUY"]
[Mon Jul 20 06:49:13.837184 2026] [security2:error] [pid 1025331:tid 1025454] [remote 20.153.140.50:40036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZSUOu5aQNSViFaxND9AABH3o"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:49:14.061852 2026] [security2:error] [pid 1025331:tid 1025479] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/for.php"] [unique_id "al4ZSkOu5aQNSViFaxNECgAAARw"]
[Mon Jul 20 06:49:14.061938 2026] [security2:error] [pid 1025331:tid 1025479] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/for.php"] [unique_id "al4ZSkOu5aQNSViFaxNECgAAARw"]
[Mon Jul 20 06:49:14.137478 2026] [security2:error] [pid 1025331:tid 1025485] [client 104.207.52.134:18161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZSkOu5aQNSViFaxNEDAAAASI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:14.152594 2026] [security2:error] [pid 1025331:tid 1025567] [client 49.36.80.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZSUOu5aQNSViFaxNEAAAAAXQ"], referer: https://mezzacraft.com/half-star-flower-crochet-motif-free-pattern/
[Mon Jul 20 06:49:14.422871 2026] [security2:error] [pid 1025331:tid 1025501] [client 57.141.18.117:62324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZRkOu5aQNSViFaxNDDQABMgI"]
[Mon Jul 20 06:49:14.443040 2026] [security2:error] [pid 1025331:tid 1025536] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/ssla.php"] [unique_id "al4ZSkOu5aQNSViFaxNEGgAAAVU"]
[Mon Jul 20 06:49:14.443135 2026] [security2:error] [pid 1025331:tid 1025536] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/ssla.php"] [unique_id "al4ZSkOu5aQNSViFaxNEGgAAAVU"]
[Mon Jul 20 06:49:14.498895 2026] [security2:error] [pid 1025331:tid 1025491] [client 39.48.81.23:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSkOu5aQNSViFaxNEHwAAASg"]
[Mon Jul 20 06:49:14.499055 2026] [security2:error] [pid 1025331:tid 1025491] [client 39.48.81.23:54703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSkOu5aQNSViFaxNEHwAAASg"]
[Mon Jul 20 06:49:14.520846 2026] [security2:error] [pid 1025331:tid 1025484] [client 217.142.18.172:37991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSkOu5aQNSViFaxNEIgAAASE"]
[Mon Jul 20 06:49:14.523871 2026] [security2:error] [pid 1025331:tid 1025484] [client 217.142.18.172:37991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZSkOu5aQNSViFaxNEIgAAASE"]
[Mon Jul 20 06:49:14.648156 2026] [security2:error] [pid 1025331:tid 1025393] [remote 154.66.198.148:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZSkOu5aQNSViFaxNEJwABHj0"]
[Mon Jul 20 06:49:14.648348 2026] [security2:error] [pid 1025331:tid 1025481] [client 154.66.198.148:56100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZSkOu5aQNSViFaxNEJwABHj0"]
[Mon Jul 20 06:49:14.807764 2026] [security2:error] [pid 1025331:tid 1025479] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/zc-131.php"] [unique_id "al4ZSkOu5aQNSViFaxNEMQAAARw"]
[Mon Jul 20 06:49:14.807883 2026] [security2:error] [pid 1025331:tid 1025479] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/zc-131.php"] [unique_id "al4ZSkOu5aQNSViFaxNEMQAAARw"]
[Mon Jul 20 06:49:14.954220 2026] [security2:error] [pid 1020501:tid 1020643] [client 14.225.17.146:53180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4ZSsS_oRsP4jdONhf6WwAAAAo"], referer: http://ravmike.com/NEW
[Mon Jul 20 06:49:15.397629 2026] [security2:error] [pid 1025331:tid 1025533] [client 77.110.127.138:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZS0Ou5aQNSViFaxNEXwAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:15.397710 2026] [security2:error] [pid 1025331:tid 1025533] [client 77.110.127.138:57310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZS0Ou5aQNSViFaxNEXwAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:15.478635 2026] [security2:error] [pid 1025331:tid 1025424] [remote 152.228.213.32:46828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZS0Ou5aQNSViFaxNEYgABDVw"]
[Mon Jul 20 06:49:15.553142 2026] [security2:error] [pid 1020501:tid 1020735] [client 77.110.127.138:57313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet/if(now()=sysdate(),sleep(15),0)/2/"] [unique_id "al4ZS8S_oRsP4jdONhf6dAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:15.607321 2026] [security2:error] [pid 1025331:tid 1025564] [client 57.141.18.61:40852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDVQABcRI"]
[Mon Jul 20 06:49:15.617820 2026] [security2:error] [pid 1020501:tid 1020668] [client 65.111.26.86:15413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZS8S_oRsP4jdONhf6dgAAACM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:15.679487 2026] [security2:error] [pid 1025331:tid 1025337] [remote 152.228.213.32:46828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZS0Ou5aQNSViFaxNEawABZQU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:49:15.691639 2026] [security2:error] [pid 1025331:tid 1025557] [client 57.141.18.107:36876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZR0Ou5aQNSViFaxNDVwABajI"]
[Mon Jul 20 06:49:16.301415 2026] [security2:error] [pid 1020501:tid 1020693] [client 57.141.18.10:33818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZSMS_oRsP4jdONhf6HwAAPFc"]
[Mon Jul 20 06:49:16.496373 2026] [security2:error] [pid 1025331:tid 1025472] [client 187.108.85.186:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZTEOu5aQNSViFaxNEngAAARU"]
[Mon Jul 20 06:49:16.496472 2026] [security2:error] [pid 1025331:tid 1025472] [client 187.108.85.186:51024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZTEOu5aQNSViFaxNEngAAARU"]
[Mon Jul 20 06:49:17.068615 2026] [security2:error] [pid 1025331:tid 1025491] [client 197.186.66.42:56802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZTUOu5aQNSViFaxNExAAAASg"]
[Mon Jul 20 06:49:17.068728 2026] [security2:error] [pid 1025331:tid 1025491] [client 197.186.66.42:56802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZTUOu5aQNSViFaxNExAAAASg"]
[Mon Jul 20 06:49:17.253103 2026] [security2:error] [pid 1025331:tid 1025476] [client 104.234.53.88:39817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZTUOu5aQNSViFaxNE1gAAARk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:17.528217 2026] [security2:error] [pid 1025331:tid 1025477] [client 57.141.18.124:53966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZSUOu5aQNSViFaxND3AABGjU"]
[Mon Jul 20 06:49:17.614754 2026] [security2:error] [pid 1025331:tid 1025512] [client 157.85.211.87:24676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZTUOu5aQNSViFaxNE6AAAAT0"]
[Mon Jul 20 06:49:17.614874 2026] [security2:error] [pid 1025331:tid 1025512] [client 157.85.211.87:24676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZTUOu5aQNSViFaxNE6AAAAT0"]
[Mon Jul 20 06:49:17.662201 2026] [security2:error] [pid 1020501:tid 1020641] [client 104.168.59.36:36720] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.detroitcsc.com"] [uri "/"] [unique_id "al4ZTcS_oRsP4jdONhf6rgAAAAg"]
[Mon Jul 20 06:49:18.066078 2026] [security2:error] [pid 1020501:tid 1020572] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZTsS_oRsP4jdONhf6uAAASkQ"]
[Mon Jul 20 06:49:18.066211 2026] [security2:error] [pid 1020501:tid 1020707] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZTsS_oRsP4jdONhf6uAAASkQ"]
[Mon Jul 20 06:49:18.169529 2026] [security2:error] [pid 1020501:tid 1020731] [client 57.141.18.60:64482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZSsS_oRsP4jdONhf6SQAAYiw"]
[Mon Jul 20 06:49:18.379376 2026] [fcgid:warn] [pid 1020501:tid 1020738] (70014)End of file found: [client 66.132.195.53:59648] mod_fcgid: can't get data from http client
[Mon Jul 20 06:49:18.712103 2026] [security2:error] [pid 1020501:tid 1020519] [remote 72.167.132.114:38310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZTsS_oRsP4jdONhf60gAADw8"]
[Mon Jul 20 06:49:18.769362 2026] [security2:error] [pid 1025331:tid 1025467] [client 57.141.18.20:59068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZSkOu5aQNSViFaxNEKAABEF0"]
[Mon Jul 20 06:49:18.858322 2026] [security2:error] [pid 1025331:tid 1025489] [client 57.141.18.77:40538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZSkOu5aQNSViFaxNEMwABJk4"]
[Mon Jul 20 06:49:19.027326 2026] [security2:error] [pid 1020501:tid 1020573] [remote 72.167.132.114:38310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZT8S_oRsP4jdONhf63QAANUU"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:49:19.064236 2026] [security2:error] [pid 1025331:tid 1025474] [client 57.141.18.4:45058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZS0Ou5aQNSViFaxNESwABF3M"]
[Mon Jul 20 06:49:19.304852 2026] [security2:error] [pid 1025331:tid 1025507] [client 77.110.127.138:57361] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/2/"] [unique_id "al4ZT0Ou5aQNSViFaxNFPgAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:19.458919 2026] [security2:error] [pid 1025331:tid 1025490] [client 77.110.127.138:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFSQAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:19.459028 2026] [security2:error] [pid 1025331:tid 1025490] [client 77.110.127.138:57364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFSQAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:19.532665 2026] [security2:error] [pid 1025331:tid 1025465] [client 57.141.18.111:51246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZS0Ou5aQNSViFaxNEZwABDmo"]
[Mon Jul 20 06:49:19.594878 2026] [proxy:error] [pid 1025331:tid 1025517] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:19.594957 2026] [proxy_http:error] [pid 1025331:tid 1025517] [client 34.73.38.214:63901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:19.595468 2026] [proxy:error] [pid 1025331:tid 1025517] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:19.595495 2026] [proxy_http:error] [pid 1025331:tid 1025517] [client 34.73.38.214:63901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:19.722392 2026] [security2:error] [pid 1025331:tid 1025334] [remote 50.28.1.50:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFUwABPQI"]
[Mon Jul 20 06:49:19.727359 2026] [security2:error] [pid 1025331:tid 1025449] [remote 20.153.140.50:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFVAABGnU"]
[Mon Jul 20 06:49:19.974855 2026] [security2:error] [pid 1025331:tid 1025372] [remote 50.28.1.50:48394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFZwABVSg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:49:20.400912 2026] [security2:error] [pid 1025331:tid 1025344] [remote 20.153.140.50:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ZUEOu5aQNSViFaxNFfwABDgw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:49:20.475603 2026] [proxy:error] [pid 1025331:tid 1025494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:20.475681 2026] [proxy_http:error] [pid 1025331:tid 1025494] [client 34.73.38.214:52372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:20.476328 2026] [proxy:error] [pid 1025331:tid 1025494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:20.476379 2026] [proxy_http:error] [pid 1025331:tid 1025494] [client 34.73.38.214:52372] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:20.696257 2026] [security2:error] [pid 1025331:tid 1025333] [remote 57.141.18.66:35640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6267794"] [unique_id "al4ZUEOu5aQNSViFaxNFjQABcwE"]
[Mon Jul 20 06:49:20.752898 2026] [security2:error] [pid 1025331:tid 1025575] [client 57.141.18.100:35278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZTEOu5aQNSViFaxNEtgABfCQ"]
[Mon Jul 20 06:49:21.102798 2026] [security2:error] [pid 1020501:tid 1020645] [client 104.168.114.154:60766] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.wesnile.com"] [uri "/"] [unique_id "al4ZUcS_oRsP4jdONhf7FQAAAAw"]
[Mon Jul 20 06:49:21.177672 2026] [security2:error] [pid 1025331:tid 1025504] [client 104.234.53.58:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ZUUOu5aQNSViFaxNFogAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:21.186606 2026] [security2:error] [pid 1025331:tid 1025503] [client 183.82.98.154:57837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUUOu5aQNSViFaxNFowAAATQ"]
[Mon Jul 20 06:49:21.186723 2026] [security2:error] [pid 1025331:tid 1025503] [client 183.82.98.154:57837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUUOu5aQNSViFaxNFowAAATQ"]
[Mon Jul 20 06:49:21.209274 2026] [security2:error] [pid 1025331:tid 1025544] [client 57.141.18.84:55396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZTUOu5aQNSViFaxNE1wABXSw"]
[Mon Jul 20 06:49:21.225537 2026] [security2:error] [pid 1025331:tid 1025514] [client 37.52.210.45:19119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZUUOu5aQNSViFaxNFpAAAAT8"]
[Mon Jul 20 06:49:21.225689 2026] [security2:error] [pid 1025331:tid 1025514] [client 37.52.210.45:19119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZUUOu5aQNSViFaxNFpAAAAT8"]
[Mon Jul 20 06:49:21.353146 2026] [security2:error] [pid 1020501:tid 1020739] [client 106.219.188.178:53904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUcS_oRsP4jdONhf7HAAAAGo"]
[Mon Jul 20 06:49:21.353257 2026] [security2:error] [pid 1020501:tid 1020739] [client 106.219.188.178:53904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUcS_oRsP4jdONhf7HAAAAGo"]
[Mon Jul 20 06:49:21.394336 2026] [proxy:error] [pid 1025331:tid 1025466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:21.394418 2026] [proxy_http:error] [pid 1025331:tid 1025466] [client 34.73.38.214:49803] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:21.395072 2026] [proxy:error] [pid 1025331:tid 1025466] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:21.395123 2026] [proxy_http:error] [pid 1025331:tid 1025466] [client 34.73.38.214:49803] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:21.491597 2026] [security2:error] [pid 1020501:tid 1020648] [client 152.58.191.29:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUcS_oRsP4jdONhf7IAAAAA8"]
[Mon Jul 20 06:49:21.491742 2026] [security2:error] [pid 1020501:tid 1020648] [client 152.58.191.29:55820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUcS_oRsP4jdONhf7IAAAAA8"]
[Mon Jul 20 06:49:21.647289 2026] [security2:error] [pid 1025331:tid 1025579] [client 77.110.127.138:57382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZUUOu5aQNSViFaxNFtgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:21.725283 2026] [security2:error] [pid 1025331:tid 1025578] [client 223.185.13.213:15677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUUOu5aQNSViFaxNFvQAAAX8"]
[Mon Jul 20 06:49:21.726396 2026] [security2:error] [pid 1025331:tid 1025578] [client 223.185.13.213:15677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUUOu5aQNSViFaxNFvQAAAX8"]
[Mon Jul 20 06:49:21.807793 2026] [security2:error] [pid 1020501:tid 1020684] [client 77.110.127.138:57387] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/2/"] [unique_id "al4ZUcS_oRsP4jdONhf7KQAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:22.358378 2026] [security2:error] [pid 1025331:tid 1025584] [client 34.73.38.214:60174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZUkOu5aQNSViFaxNF3QAAAYU"]
[Mon Jul 20 06:49:22.384857 2026] [security2:error] [pid 1020501:tid 1020666] [client 103.125.179.95:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUsS_oRsP4jdONhf7PgAAACE"]
[Mon Jul 20 06:49:22.384975 2026] [security2:error] [pid 1020501:tid 1020666] [client 103.125.179.95:65322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZUsS_oRsP4jdONhf7PgAAACE"]
[Mon Jul 20 06:49:22.506809 2026] [security2:error] [pid 1020501:tid 1020714] [client 104.154.170.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nandansonscharitablefoundation.com"] [uri "/index.php"] [unique_id "al4ZUMS_oRsP4jdONhf7AAAAAFE"]
[Mon Jul 20 06:49:22.599629 2026] [security2:error] [pid 1025331:tid 1025522] [client 77.110.127.138:57396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZUkOu5aQNSViFaxNF6QAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:22.599723 2026] [security2:error] [pid 1025331:tid 1025522] [client 77.110.127.138:57396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZUkOu5aQNSViFaxNF6QAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:22.733213 2026] [security2:error] [pid 1025331:tid 1025467] [client 51.68.111.243:34009] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bridgeamazon.com"] [uri "/robots.txt"] [unique_id "al4ZUkOu5aQNSViFaxNF7AAAARA"]
[Mon Jul 20 06:49:22.733345 2026] [security2:error] [pid 1025331:tid 1025467] [client 51.68.111.243:34009] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "bridgeamazon.com"] [uri "/robots.txt"] [unique_id "al4ZUkOu5aQNSViFaxNF7AAAARA"]
[Mon Jul 20 06:49:22.807835 2026] [proxy:error] [pid 1025331:tid 1025573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:22.807905 2026] [proxy_http:error] [pid 1025331:tid 1025573] [client 34.73.38.214:61300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:22.809547 2026] [proxy:error] [pid 1025331:tid 1025573] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:22.809597 2026] [proxy_http:error] [pid 1025331:tid 1025573] [client 34.73.38.214:61300] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:22.851942 2026] [security2:error] [pid 1020501:tid 1020663] [client 216.24.212.38:61511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4ZUsS_oRsP4jdONhf7TAAAAB4"]
[Mon Jul 20 06:49:23.267774 2026] [security2:error] [pid 1025331:tid 1025575] [client 117.247.108.24:58341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZU0Ou5aQNSViFaxNGDQAAAXw"]
[Mon Jul 20 06:49:23.267881 2026] [security2:error] [pid 1025331:tid 1025575] [client 117.247.108.24:58341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZU0Ou5aQNSViFaxNGDQAAAXw"]
[Mon Jul 20 06:49:23.443303 2026] [security2:error] [pid 1025331:tid 1025488] [client 104.168.59.36:37944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "detroitcsc.com"] [uri "/"] [unique_id "al4ZU0Ou5aQNSViFaxNGHgAAASU"]
[Mon Jul 20 06:49:23.530615 2026] [security2:error] [pid 1025331:tid 1025364] [remote 182.77.62.24:43106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4ZU0Ou5aQNSViFaxNGJwABViA"]
[Mon Jul 20 06:49:23.591955 2026] [security2:error] [pid 1025331:tid 1025524] [client 57.141.18.65:21528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFOQABSXo"]
[Mon Jul 20 06:49:23.630379 2026] [security2:error] [pid 1025331:tid 1025563] [client 192.236.168.43:45724] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.detroitcsc.wesnile.com"] [uri "/"] [unique_id "al4ZU0Ou5aQNSViFaxNGKwAAAXA"]
[Mon Jul 20 06:49:23.701036 2026] [security2:error] [pid 1025331:tid 1025519] [client 34.73.38.214:56905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZU0Ou5aQNSViFaxNGLgAAAUQ"]
[Mon Jul 20 06:49:23.703747 2026] [proxy:error] [pid 1025331:tid 1025550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:23.703829 2026] [proxy_http:error] [pid 1025331:tid 1025550] [client 34.73.38.214:56970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:23.704291 2026] [proxy:error] [pid 1025331:tid 1025550] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:23.704316 2026] [proxy_http:error] [pid 1025331:tid 1025550] [client 34.73.38.214:56970] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:23.736115 2026] [security2:error] [pid 1025331:tid 1025506] [client 57.141.18.33:60310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFRQABN2U"]
[Mon Jul 20 06:49:23.907413 2026] [security2:error] [pid 1025331:tid 1025496] [client 192.140.149.97:45923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZU0Ou5aQNSViFaxNGPAAAAS0"]
[Mon Jul 20 06:49:23.907522 2026] [security2:error] [pid 1025331:tid 1025496] [client 192.140.149.97:45923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZU0Ou5aQNSViFaxNGPAAAAS0"]
[Mon Jul 20 06:49:24.027795 2026] [security2:error] [pid 1025331:tid 1025402] [remote 182.77.62.24:43106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4ZVEOu5aQNSViFaxNGTQABJEY"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 06:49:24.047258 2026] [security2:error] [pid 1025331:tid 1025577] [client 57.141.18.115:26864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFWQABfnw"]
[Mon Jul 20 06:49:24.059668 2026] [security2:error] [pid 1025331:tid 1025489] [client 57.141.18.62:64766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZT0Ou5aQNSViFaxNFWwABJj0"]
[Mon Jul 20 06:49:24.192123 2026] [security2:error] [pid 1025331:tid 1025514] [client 65.111.23.7:55845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.agency"] [uri "/wp-login.php"] [unique_id "al4ZVEOu5aQNSViFaxNGUQAAAT8"], referer: https://idigress.agency/wp-login.php
[Mon Jul 20 06:49:24.235470 2026] [security2:error] [pid 1025331:tid 1025474] [client 103.238.106.162:63568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZVEOu5aQNSViFaxNGUwAAARc"]
[Mon Jul 20 06:49:24.235604 2026] [security2:error] [pid 1025331:tid 1025474] [client 103.238.106.162:63568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZVEOu5aQNSViFaxNGUwAAARc"]
[Mon Jul 20 06:49:24.352691 2026] [security2:error] [pid 1025331:tid 1025555] [client 36.95.228.227:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZVEOu5aQNSViFaxNGXAAAAWg"]
[Mon Jul 20 06:49:24.352836 2026] [security2:error] [pid 1025331:tid 1025555] [client 36.95.228.227:57381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZVEOu5aQNSViFaxNGXAAAAWg"]
[Mon Jul 20 06:49:24.629898 2026] [security2:error] [pid 1025331:tid 1025436] [remote 20.153.140.50:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4ZVEOu5aQNSViFaxNGdAABc2g"]
[Mon Jul 20 06:49:24.688086 2026] [security2:error] [pid 1020501:tid 1020641] [client 34.73.38.214:59230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZVMS_oRsP4jdONhf7ewAAAAg"]
[Mon Jul 20 06:49:24.743441 2026] [proxy:error] [pid 1025331:tid 1025474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:24.743524 2026] [proxy_http:error] [pid 1025331:tid 1025474] [client 34.73.38.214:62359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:24.743995 2026] [proxy:error] [pid 1025331:tid 1025474] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:24.744024 2026] [proxy_http:error] [pid 1025331:tid 1025474] [client 34.73.38.214:62359] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:24.818830 2026] [security2:error] [pid 1020501:tid 1020680] [client 57.141.18.42:34324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZUMS_oRsP4jdONhf7DQAALyA"]
[Mon Jul 20 06:49:24.835610 2026] [security2:error] [pid 1025331:tid 1025438] [remote 85.204.69.248:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZVEOu5aQNSViFaxNGfwABh2o"]
[Mon Jul 20 06:49:24.900802 2026] [security2:error] [pid 1020501:tid 1020655] [client 57.141.18.69:61084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZUMS_oRsP4jdONhf7DwAAFhE"]
[Mon Jul 20 06:49:24.913313 2026] [security2:error] [pid 1020501:tid 1020745] [client 39.48.81.23:55244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZVMS_oRsP4jdONhf7gAAAAHA"]
[Mon Jul 20 06:49:24.913423 2026] [security2:error] [pid 1020501:tid 1020745] [client 39.48.81.23:55244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZVMS_oRsP4jdONhf7gAAAAHA"]
[Mon Jul 20 06:49:25.012975 2026] [security2:error] [pid 1025331:tid 1025428] [remote 20.153.140.50:60624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4ZVUOu5aQNSViFaxNGiQABOmA"], referer: https://daseighty.net/wp-login.php
[Mon Jul 20 06:49:25.076630 2026] [security2:error] [pid 1020501:tid 1020697] [client 217.142.18.172:18138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZVcS_oRsP4jdONhf7hQAAAEA"]
[Mon Jul 20 06:49:25.076741 2026] [security2:error] [pid 1020501:tid 1020697] [client 217.142.18.172:18138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZVcS_oRsP4jdONhf7hQAAAEA"]
[Mon Jul 20 06:49:25.081063 2026] [security2:error] [pid 1025331:tid 1025449] [remote 85.204.69.248:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.69.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZVUOu5aQNSViFaxNGjwABhnU"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:49:25.326104 2026] [security2:error] [pid 1025331:tid 1025426] [remote 178.105.191.160:57290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.191.105.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZVUOu5aQNSViFaxNGmAABWV4"]
[Mon Jul 20 06:49:25.495614 2026] [security2:error] [pid 1025331:tid 1025484] [client 57.141.18.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZVUOu5aQNSViFaxNGmgAAASE"]
[Mon Jul 20 06:49:25.511236 2026] [security2:error] [pid 1025331:tid 1025354] [remote 178.105.191.160:57290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.191.105.178.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZVUOu5aQNSViFaxNGpAABXxY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:49:25.543527 2026] [security2:error] [pid 1020501:tid 1020729] [client 158.173.166.181:26449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZVcS_oRsP4jdONhf7kgAAAGA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:49:25.569926 2026] [security2:error] [pid 1025331:tid 1025490] [client 57.141.18.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZVUOu5aQNSViFaxNGngAAASc"]
[Mon Jul 20 06:49:25.614643 2026] [security2:error] [pid 1020501:tid 1020701] [client 57.141.18.122:55158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZUcS_oRsP4jdONhf7JAAARDg"]
[Mon Jul 20 06:49:25.908494 2026] [security2:error] [pid 1025331:tid 1025509] [client 14.251.3.155:54726] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZVUOu5aQNSViFaxNGuQAAATo"]
[Mon Jul 20 06:49:25.946812 2026] [security2:error] [pid 1025331:tid 1025519] [client 162.219.176.3:44606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ZVUOu5aQNSViFaxNGugAAAUQ"]
[Mon Jul 20 06:49:25.946906 2026] [security2:error] [pid 1025331:tid 1025519] [client 162.219.176.3:44606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ZVUOu5aQNSViFaxNGugAAAUQ"]
[Mon Jul 20 06:49:26.029234 2026] [security2:error] [pid 1025331:tid 1025567] [client 34.73.38.214:57184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZVkOu5aQNSViFaxNGvwAAAXQ"]
[Mon Jul 20 06:49:26.036741 2026] [security2:error] [pid 1025331:tid 1025532] [client 34.73.38.214:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZVkOu5aQNSViFaxNGwAAAAVE"]
[Mon Jul 20 06:49:26.241919 2026] [security2:error] [pid 1020501:tid 1020682] [client 77.110.127.138:57421] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZVsS_oRsP4jdONhf7pgAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:26.647806 2026] [security2:error] [pid 1020501:tid 1020695] [client 57.141.18.42:38200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZUsS_oRsP4jdONhf7RQAAPiE"]
[Mon Jul 20 06:49:26.721660 2026] [security2:error] [pid 1025331:tid 1025536] [client 49.36.80.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZVkOu5aQNSViFaxNG4AAAAVU"], referer: https://mezzacraft.com/half-star-flower-crochet-motif-free-pattern/
[Mon Jul 20 06:49:26.777202 2026] [security2:error] [pid 1025331:tid 1025502] [client 57.141.18.81:24012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZUkOu5aQNSViFaxNF8wABM1U"]
[Mon Jul 20 06:49:26.887901 2026] [security2:error] [pid 1020501:tid 1020739] [client 34.73.38.214:60688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZVsS_oRsP4jdONhf7tAAAAGo"]
[Mon Jul 20 06:49:26.898631 2026] [security2:error] [pid 1025331:tid 1025455] [remote 81.173.115.7:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4ZVkOu5aQNSViFaxNG-wABKXs"]
[Mon Jul 20 06:49:26.932833 2026] [security2:error] [pid 1020501:tid 1020703] [client 34.73.38.214:51686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZVsS_oRsP4jdONhf7tQAAAEY"]
[Mon Jul 20 06:49:27.058911 2026] [security2:error] [pid 1020501:tid 1020686] [client 77.110.127.138:57424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZV8S_oRsP4jdONhf7vQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:27.059029 2026] [security2:error] [pid 1020501:tid 1020686] [client 77.110.127.138:57424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZV8S_oRsP4jdONhf7vQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:27.099640 2026] [security2:error] [pid 1025331:tid 1025387] [remote 81.173.115.7:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHBQABaTc"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:49:27.222857 2026] [security2:error] [pid 1020501:tid 1020712] [client 187.108.85.186:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZV8S_oRsP4jdONhf7wwAAAE8"]
[Mon Jul 20 06:49:27.222978 2026] [security2:error] [pid 1020501:tid 1020712] [client 187.108.85.186:51574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZV8S_oRsP4jdONhf7wwAAAE8"]
[Mon Jul 20 06:49:27.243232 2026] [security2:error] [pid 1025331:tid 1025506] [client 104.234.53.84:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHCwAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:27.311689 2026] [security2:error] [pid 1025331:tid 1025462] [client 57.141.18.118:46810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZU0Ou5aQNSViFaxNGDgABCxE"]
[Mon Jul 20 06:49:27.397814 2026] [security2:error] [pid 1025331:tid 1025563] [client 34.74.185.202:57833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/xmlrpc.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHGgAAAXA"]
[Mon Jul 20 06:49:27.397954 2026] [security2:error] [pid 1025331:tid 1025563] [client 34.74.185.202:57833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "petpawo.com"] [uri "/xmlrpc.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHGgAAAXA"]
[Mon Jul 20 06:49:27.683542 2026] [security2:error] [pid 1025331:tid 1025576] [client 34.73.38.214:55560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZV0Ou5aQNSViFaxNHJAAAAX0"]
[Mon Jul 20 06:49:27.743087 2026] [security2:error] [pid 1025331:tid 1025550] [client 34.73.38.214:50893] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZV0Ou5aQNSViFaxNHKwAAAWM"]
[Mon Jul 20 06:49:27.807912 2026] [security2:error] [pid 1025331:tid 1025547] [client 14.225.17.146:51006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHIAAAAWA"], referer: http://blaizeaccountingservices.com/NEW
[Mon Jul 20 06:49:27.861462 2026] [security2:error] [pid 1020501:tid 1020735] [client 34.74.185.202:49255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.185.74.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/xmlrpc.php"] [unique_id "al4ZV8S_oRsP4jdONhf71AAAAGY"]
[Mon Jul 20 06:49:27.861579 2026] [security2:error] [pid 1020501:tid 1020735] [client 34.74.185.202:49255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "petpawo.com"] [uri "/xmlrpc.php"] [unique_id "al4ZV8S_oRsP4jdONhf71AAAAGY"]
[Mon Jul 20 06:49:28.167529 2026] [security2:error] [pid 1025331:tid 1025575] [client 34.73.38.214:53536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWEOu5aQNSViFaxNHQgAAAXw"]
[Mon Jul 20 06:49:28.169088 2026] [security2:error] [pid 1020501:tid 1020749] [client 34.73.38.214:60836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWMS_oRsP4jdONhf71wAAAHQ"]
[Mon Jul 20 06:49:28.430526 2026] [security2:error] [pid 1025331:tid 1025552] [client 57.141.18.50:36940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZVEOu5aQNSViFaxNGWgABZWY"]
[Mon Jul 20 06:49:28.560461 2026] [security2:error] [pid 1025331:tid 1025498] [client 57.141.18.123:47794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZVEOu5aQNSViFaxNGZQABL38"]
[Mon Jul 20 06:49:28.563886 2026] [security2:error] [pid 1020501:tid 1020678] [client 157.85.211.87:24351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZWMS_oRsP4jdONhf74QAAAC0"]
[Mon Jul 20 06:49:28.564014 2026] [security2:error] [pid 1020501:tid 1020678] [client 157.85.211.87:24351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZWMS_oRsP4jdONhf74QAAAC0"]
[Mon Jul 20 06:49:28.606403 2026] [security2:error] [pid 1025331:tid 1025524] [client 34.73.38.214:57108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWEOu5aQNSViFaxNHXwAAAUk"]
[Mon Jul 20 06:49:28.822155 2026] [security2:error] [pid 1020501:tid 1020689] [client 34.73.38.214:59690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWMS_oRsP4jdONhf76wAAADg"]
[Mon Jul 20 06:49:28.932430 2026] [security2:error] [pid 1020501:tid 1020526] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZWMS_oRsP4jdONhf78wAAChY"]
[Mon Jul 20 06:49:28.932607 2026] [security2:error] [pid 1020501:tid 1020643] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZWMS_oRsP4jdONhf78wAAChY"]
[Mon Jul 20 06:49:29.111958 2026] [security2:error] [pid 1025331:tid 1025576] [client 14.225.17.146:52760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ZWEOu5aQNSViFaxNHWQAAAX0"]
[Mon Jul 20 06:49:29.546234 2026] [security2:error] [pid 1020501:tid 1020699] [client 57.141.18.88:59798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZVcS_oRsP4jdONhf7igAAQnA"]
[Mon Jul 20 06:49:29.593467 2026] [security2:error] [pid 1025331:tid 1025477] [client 57.141.18.11:51548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZVUOu5aQNSViFaxNGogABGms"]
[Mon Jul 20 06:49:29.600702 2026] [security2:error] [pid 1020501:tid 1020661] [client 50.116.65.227:46730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/04/IMG_3041.jpeg"] [unique_id "al4ZWcS_oRsP4jdONhf8BgAAABw"]
[Mon Jul 20 06:49:29.750643 2026] [security2:error] [pid 1020501:tid 1020649] [client 104.234.53.52:58255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZWcS_oRsP4jdONhf8CwAAABA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:29.954181 2026] [security2:error] [pid 1025331:tid 1025555] [client 77.110.127.138:57433] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZWUOu5aQNSViFaxNHngAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:30.084582 2026] [security2:error] [pid 1025331:tid 1025530] [client 34.73.38.214:57079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWkOu5aQNSViFaxNHpgAAAU8"]
[Mon Jul 20 06:49:30.086997 2026] [security2:error] [pid 1025331:tid 1025533] [client 34.73.38.214:57232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWkOu5aQNSViFaxNHpwAAAVI"]
[Mon Jul 20 06:49:30.167181 2026] [security2:error] [pid 1020501:tid 1020734] [client 14.225.17.146:61391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ZWcS_oRsP4jdONhf8GAAAAGU"], referer: http://falconarrowshop.com/NEW
[Mon Jul 20 06:49:30.243763 2026] [security2:error] [pid 1025331:tid 1025534] [client 74.7.227.179:46566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZWkOu5aQNSViFaxNHrAABU08"], referer: https://tejasenvironmental.com/p=719655
[Mon Jul 20 06:49:30.262979 2026] [security2:error] [pid 1025331:tid 1025504] [client 34.73.38.214:64240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWkOu5aQNSViFaxNHsQAAATU"]
[Mon Jul 20 06:49:30.262979 2026] [security2:error] [pid 1020501:tid 1020745] [client 34.73.38.214:64854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZWsS_oRsP4jdONhf8JAAAAHA"]
[Mon Jul 20 06:49:30.295466 2026] [security2:error] [pid 1020501:tid 1020548] [remote 188.40.28.4:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4ZWsS_oRsP4jdONhf8JQAANCw"]
[Mon Jul 20 06:49:30.354569 2026] [security2:error] [pid 1025331:tid 1025494] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZWkOu5aQNSViFaxNHrQAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:30.434363 2026] [security2:error] [pid 1025331:tid 1025544] [client 197.186.66.42:57356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZWkOu5aQNSViFaxNHwgAAAV0"]
[Mon Jul 20 06:49:30.447707 2026] [security2:error] [pid 1025331:tid 1025544] [client 197.186.66.42:57356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZWkOu5aQNSViFaxNHwgAAAV0"]
[Mon Jul 20 06:49:30.501309 2026] [security2:error] [pid 1020501:tid 1020538] [remote 188.40.28.4:60772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4ZWsS_oRsP4jdONhf8KAAAYCI"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:49:30.505637 2026] [security2:error] [pid 1025331:tid 1025552] [client 65.1.132.125:25100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZWkOu5aQNSViFaxNHxAAAAWU"]
[Mon Jul 20 06:49:30.848475 2026] [security2:error] [pid 1020501:tid 1020689] [client 152.58.191.29:56303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZWsS_oRsP4jdONhf8MgAAADg"]
[Mon Jul 20 06:49:30.848583 2026] [security2:error] [pid 1020501:tid 1020689] [client 152.58.191.29:56303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZWsS_oRsP4jdONhf8MgAAADg"]
[Mon Jul 20 06:49:31.014408 2026] [security2:error] [pid 1025331:tid 1025537] [client 57.141.18.104:40874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZVkOu5aQNSViFaxNG5wABVm8"]
[Mon Jul 20 06:49:31.039071 2026] [security2:error] [pid 1025331:tid 1025586] [client 174.138.79.221:55053] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.karmaminds.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH5gAAAYc"]
[Mon Jul 20 06:49:31.146346 2026] [security2:error] [pid 1020501:tid 1020709] [client 34.73.38.214:54867] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZW8S_oRsP4jdONhf8OQAAAEw"]
[Mon Jul 20 06:49:31.186084 2026] [security2:error] [pid 1025331:tid 1025476] [client 77.110.127.138:57439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH6wAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:31.186191 2026] [security2:error] [pid 1025331:tid 1025476] [client 77.110.127.138:57439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH6wAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:31.355505 2026] [security2:error] [pid 1025331:tid 1025507] [client 223.185.13.213:3053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH9AAAATg"]
[Mon Jul 20 06:49:31.355591 2026] [security2:error] [pid 1025331:tid 1025507] [client 223.185.13.213:3053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH9AAAATg"]
[Mon Jul 20 06:49:31.587262 2026] [security2:error] [pid 1025331:tid 1025448] [remote 74.235.96.117:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH_QABTHQ"]
[Mon Jul 20 06:49:31.587444 2026] [security2:error] [pid 1025331:tid 1025527] [client 74.235.96.117:44072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH_QABTHQ"]
[Mon Jul 20 06:49:31.620225 2026] [security2:error] [pid 1025331:tid 1025516] [client 57.141.18.4:62230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHBgABQQM"]
[Mon Jul 20 06:49:31.632687 2026] [security2:error] [pid 1020501:tid 1020677] [client 34.73.38.214:62533] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZW8S_oRsP4jdONhf8SQAAACw"]
[Mon Jul 20 06:49:31.856454 2026] [security2:error] [pid 1025331:tid 1025541] [client 34.73.38.214:61108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.oqw.bur.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZW0Ou5aQNSViFaxNIBwAAAVo"]
[Mon Jul 20 06:49:31.905247 2026] [security2:error] [pid 1025331:tid 1025556] [client 37.52.210.45:21736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZW0Ou5aQNSViFaxNICAAAAWk"]
[Mon Jul 20 06:49:31.905429 2026] [security2:error] [pid 1025331:tid 1025556] [client 37.52.210.45:21736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZW0Ou5aQNSViFaxNICAAAAWk"]
[Mon Jul 20 06:49:32.004685 2026] [security2:error] [pid 1025331:tid 1025565] [client 183.82.98.154:58435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXEOu5aQNSViFaxNICwAAAXI"]
[Mon Jul 20 06:49:32.004805 2026] [security2:error] [pid 1025331:tid 1025565] [client 183.82.98.154:58435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXEOu5aQNSViFaxNICwAAAXI"]
[Mon Jul 20 06:49:32.050041 2026] [security2:error] [pid 1025331:tid 1025488] [client 106.219.188.178:27761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXEOu5aQNSViFaxNIDQAAASU"]
[Mon Jul 20 06:49:32.051529 2026] [security2:error] [pid 1025331:tid 1025488] [client 106.219.188.178:27761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXEOu5aQNSViFaxNIDQAAASU"]
[Mon Jul 20 06:49:32.093785 2026] [security2:error] [pid 1025331:tid 1025523] [client 57.141.18.31:61170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZV0Ou5aQNSViFaxNHIwABSHA"]
[Mon Jul 20 06:49:32.150674 2026] [security2:error] [pid 1025331:tid 1025471] [client 34.73.38.214:56237] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZXEOu5aQNSViFaxNIFQAAARQ"]
[Mon Jul 20 06:49:32.221074 2026] [security2:error] [pid 1025331:tid 1025557] [client 74.208.214.194:43370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ZXEOu5aQNSViFaxNIGgAAAWo"]
[Mon Jul 20 06:49:32.413701 2026] [security2:error] [pid 1025331:tid 1025562] [client 104.234.53.71:39975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZXEOu5aQNSViFaxNIHwAAAW8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:32.418435 2026] [security2:error] [pid 1020501:tid 1020649] [client 13.232.231.177:14722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZW8S_oRsP4jdONhf8SAAAABA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:49:32.764859 2026] [security2:error] [pid 1025331:tid 1025343] [remote 57.141.18.125:26394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4085058"] [unique_id "al4ZXEOu5aQNSViFaxNIOAABaAs"]
[Mon Jul 20 06:49:32.869859 2026] [security2:error] [pid 1025331:tid 1025581] [client 122.183.32.225:16043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXEOu5aQNSViFaxNIPAAAAYI"]
[Mon Jul 20 06:49:32.879662 2026] [security2:error] [pid 1025331:tid 1025581] [client 122.183.32.225:16043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXEOu5aQNSViFaxNIPAAAAYI"]
[Mon Jul 20 06:49:32.961270 2026] [security2:error] [pid 1020501:tid 1020675] [client 34.73.38.214:59520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZXMS_oRsP4jdONhf8egAAACo"]
[Mon Jul 20 06:49:32.963367 2026] [security2:error] [pid 1025331:tid 1025564] [client 104.234.53.71:39975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZXEOu5aQNSViFaxNIRQAAAXE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:33.110936 2026] [security2:error] [pid 1025331:tid 1025497] [client 57.141.18.31:61180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZWEOu5aQNSViFaxNHXgABLjE"]
[Mon Jul 20 06:49:33.359648 2026] [security2:error] [pid 1025331:tid 1025583] [client 34.73.38.214:51759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZXUOu5aQNSViFaxNIUAAAAYQ"]
[Mon Jul 20 06:49:33.467022 2026] [security2:error] [pid 1020501:tid 1020506] [remote 160.187.68.132:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZXcS_oRsP4jdONhf8iQAASAI"]
[Mon Jul 20 06:49:33.608330 2026] [security2:error] [pid 1025331:tid 1025520] [client 57.141.18.74:38484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZWUOu5aQNSViFaxNHdQABRWU"]
[Mon Jul 20 06:49:34.044989 2026] [security2:error] [pid 1025331:tid 1025549] [client 34.73.38.214:63519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.ouw.egd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZXkOu5aQNSViFaxNIZQAAAWI"]
[Mon Jul 20 06:49:34.055900 2026] [security2:error] [pid 1020501:tid 1020601] [remote 160.187.68.132:51794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZXsS_oRsP4jdONhf8ogAAD2E"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:49:34.098413 2026] [security2:error] [pid 1020501:tid 1020745] [client 43.205.139.3:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXsS_oRsP4jdONhf8pQAAAHA"]
[Mon Jul 20 06:49:34.098502 2026] [security2:error] [pid 1020501:tid 1020745] [client 43.205.139.3:60330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXsS_oRsP4jdONhf8pQAAAHA"]
[Mon Jul 20 06:49:34.325009 2026] [security2:error] [pid 1020501:tid 1020727] [client 103.125.179.95:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXsS_oRsP4jdONhf8rwAAAF4"]
[Mon Jul 20 06:49:34.325542 2026] [security2:error] [pid 1020501:tid 1020727] [client 103.125.179.95:49502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXsS_oRsP4jdONhf8rwAAAF4"]
[Mon Jul 20 06:49:34.358369 2026] [security2:error] [pid 1020501:tid 1020638] [client 57.141.18.100:26406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZWcS_oRsP4jdONhf8DwAABR8"]
[Mon Jul 20 06:49:34.383421 2026] [security2:error] [pid 1025331:tid 1025480] [client 13.233.207.33:19626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNIeAAAAR0"]
[Mon Jul 20 06:49:34.383554 2026] [security2:error] [pid 1025331:tid 1025480] [client 13.233.207.33:19626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNIeAAAAR0"]
[Mon Jul 20 06:49:34.676891 2026] [security2:error] [pid 1025331:tid 1025487] [client 104.234.53.67:34195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZXkOu5aQNSViFaxNIjAAAASQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:34.744085 2026] [security2:error] [pid 1025331:tid 1025495] [client 103.238.106.162:60758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNIkgAAASw"]
[Mon Jul 20 06:49:34.745372 2026] [security2:error] [pid 1025331:tid 1025495] [client 103.238.106.162:60758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNIkgAAASw"]
[Mon Jul 20 06:49:34.815521 2026] [security2:error] [pid 1025331:tid 1025481] [client 57.141.18.8:62774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZWkOu5aQNSViFaxNHrwABHjw"]
[Mon Jul 20 06:49:34.985448 2026] [security2:error] [pid 1025331:tid 1025535] [client 117.247.108.24:52257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNInQAAAVQ"]
[Mon Jul 20 06:49:34.985546 2026] [security2:error] [pid 1025331:tid 1025535] [client 117.247.108.24:52257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNInQAAAVQ"]
[Mon Jul 20 06:49:35.008008 2026] [security2:error] [pid 1025331:tid 1025575] [client 36.95.228.227:57851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNIngAAAXw"]
[Mon Jul 20 06:49:35.008137 2026] [security2:error] [pid 1025331:tid 1025575] [client 36.95.228.227:57851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZXkOu5aQNSViFaxNIngAAAXw"]
[Mon Jul 20 06:49:35.164957 2026] [security2:error] [pid 1025331:tid 1025480] [client 77.110.127.138:57449] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZX0Ou5aQNSViFaxNIpgAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:35.379259 2026] [security2:error] [pid 1020501:tid 1020647] [client 178.128.72.200:60591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4ZX8S_oRsP4jdONhf8ygAAAA4"]
[Mon Jul 20 06:49:35.488989 2026] [security2:error] [pid 1025331:tid 1025519] [client 57.141.18.43:39266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZWkOu5aQNSViFaxNH5AABRBY"]
[Mon Jul 20 06:49:35.529210 2026] [security2:error] [pid 1025331:tid 1025555] [client 178.128.72.200:60736] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIvwAAAWg"]
[Mon Jul 20 06:49:35.534892 2026] [security2:error] [pid 1020501:tid 1020668] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZX8S_oRsP4jdONhf8zAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:35.627265 2026] [security2:error] [pid 1025331:tid 1025558] [client 217.142.18.172:33652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIxAAAAWs"]
[Mon Jul 20 06:49:35.627382 2026] [security2:error] [pid 1025331:tid 1025558] [client 217.142.18.172:33652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIxAAAAWs"]
[Mon Jul 20 06:49:35.636837 2026] [security2:error] [pid 1025331:tid 1025568] [client 195.63.31.204:47941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIwQAAAXU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:35.667076 2026] [security2:error] [pid 1025331:tid 1025516] [client 39.48.81.23:55761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIyAAAAUE"]
[Mon Jul 20 06:49:35.667156 2026] [security2:error] [pid 1025331:tid 1025516] [client 39.48.81.23:55761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIyAAAAUE"]
[Mon Jul 20 06:49:35.756350 2026] [security2:error] [pid 1020501:tid 1020748] [client 98.159.234.160:60311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZX8S_oRsP4jdONhf82QAAAHM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:49:35.898466 2026] [security2:error] [pid 1025331:tid 1025503] [client 57.141.18.6:56556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH-QABNEs"]
[Mon Jul 20 06:49:35.992058 2026] [security2:error] [pid 1025331:tid 1025547] [client 57.141.18.58:45958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZW0Ou5aQNSViFaxNH-gABYH0"]
[Mon Jul 20 06:49:36.331958 2026] [security2:error] [pid 1020501:tid 1020672] [client 34.139.11.221:53929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.nikkidesigns.net"] [uri "/xmlrpc.php"] [unique_id "al4ZYMS_oRsP4jdONhf87QAAACc"]
[Mon Jul 20 06:49:36.470963 2026] [security2:error] [pid 1020501:tid 1020735] [client 34.139.11.221:50929] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYMS_oRsP4jdONhf88gAAAGY"]
[Mon Jul 20 06:49:36.480941 2026] [security2:error] [pid 1025331:tid 1025459] [remote 15.206.251.117:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4ZYEOu5aQNSViFaxNI5QABWH8"]
[Mon Jul 20 06:49:36.630298 2026] [security2:error] [pid 1020501:tid 1020666] [client 34.139.11.221:59539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYMS_oRsP4jdONhf8_gAAACE"]
[Mon Jul 20 06:49:36.768663 2026] [security2:error] [pid 1025331:tid 1025571] [client 34.139.11.221:59470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYEOu5aQNSViFaxNI7wAAAXg"]
[Mon Jul 20 06:49:36.917897 2026] [security2:error] [pid 1020501:tid 1020749] [client 34.139.11.221:55773] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYMS_oRsP4jdONhf9BAAAAHQ"]
[Mon Jul 20 06:49:36.943346 2026] [security2:error] [pid 1025331:tid 1025364] [remote 15.206.251.117:57066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4ZYEOu5aQNSViFaxNI-wABMSA"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:49:37.059609 2026] [security2:error] [pid 1025331:tid 1025499] [client 34.139.11.221:61431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYUOu5aQNSViFaxNJAgAAATA"]
[Mon Jul 20 06:49:37.061533 2026] [security2:error] [pid 1025331:tid 1025509] [client 77.110.127.138:57460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZYUOu5aQNSViFaxNJAwAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:37.061601 2026] [security2:error] [pid 1025331:tid 1025509] [client 77.110.127.138:57460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZYUOu5aQNSViFaxNJAwAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:37.122374 2026] [security2:error] [pid 1020501:tid 1020701] [client 62.150.67.110:41792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4ZYMS_oRsP4jdONhf8-QAAAEQ"]
[Mon Jul 20 06:49:37.123968 2026] [security2:error] [pid 1020501:tid 1020692] [client 57.141.18.52:27644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZXMS_oRsP4jdONhf8aQAAO3g"]
[Mon Jul 20 06:49:37.241693 2026] [security2:error] [pid 1025331:tid 1025473] [client 34.139.11.221:61087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYUOu5aQNSViFaxNJDAAAARY"]
[Mon Jul 20 06:49:37.307185 2026] [security2:error] [pid 1025331:tid 1025396] [remote 202.51.202.242:41822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZYUOu5aQNSViFaxNJDwABG0A"]
[Mon Jul 20 06:49:37.337400 2026] [security2:error] [pid 1025331:tid 1025532] [client 57.141.18.73:45304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZXEOu5aQNSViFaxNIOQABUXs"]
[Mon Jul 20 06:49:37.347575 2026] [security2:error] [pid 1025331:tid 1025578] [client 34.139.11.221:54488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYUOu5aQNSViFaxNJEgAAAX8"]
[Mon Jul 20 06:49:37.483501 2026] [security2:error] [pid 1025331:tid 1025575] [client 34.139.11.221:63523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYUOu5aQNSViFaxNJGgAAAXw"]
[Mon Jul 20 06:49:37.585152 2026] [security2:error] [pid 1025331:tid 1025456] [remote 45.90.123.233:38362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4ZYUOu5aQNSViFaxNJHwABgHw"]
[Mon Jul 20 06:49:37.638885 2026] [security2:error] [pid 1025331:tid 1025470] [client 34.139.11.221:51551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYUOu5aQNSViFaxNJIwAAARM"]
[Mon Jul 20 06:49:37.640842 2026] [security2:error] [pid 1020501:tid 1020559] [remote 47.86.33.52:53342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZYcS_oRsP4jdONhf9HAAAKjc"]
[Mon Jul 20 06:49:37.641082 2026] [security2:error] [pid 1020501:tid 1020675] [client 47.86.33.52:53342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZYcS_oRsP4jdONhf9HAAAKjc"]
[Mon Jul 20 06:49:37.775944 2026] [security2:error] [pid 1025331:tid 1025527] [client 34.139.11.221:50205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYUOu5aQNSViFaxNJLAAAAUw"]
[Mon Jul 20 06:49:37.777714 2026] [security2:error] [pid 1025331:tid 1025420] [remote 45.90.123.233:38362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4ZYUOu5aQNSViFaxNJLQABU1g"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:49:37.797340 2026] [security2:error] [pid 1025331:tid 1025565] [client 104.234.53.69:55605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ZYUOu5aQNSViFaxNJKwAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:37.892439 2026] [security2:error] [pid 1020501:tid 1020690] [client 34.139.11.221:63234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.nikkidesigns.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZYcS_oRsP4jdONhf9IgAAADk"]
[Mon Jul 20 06:49:37.923183 2026] [security2:error] [pid 1025331:tid 1025493] [client 45.3.55.187:21251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZYUOu5aQNSViFaxNJMgAAASo"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:37.943320 2026] [security2:error] [pid 1025331:tid 1025511] [client 187.108.85.186:52119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZYUOu5aQNSViFaxNJMwAAATw"]
[Mon Jul 20 06:49:37.943474 2026] [security2:error] [pid 1025331:tid 1025511] [client 187.108.85.186:52119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZYUOu5aQNSViFaxNJMwAAATw"]
[Mon Jul 20 06:49:38.237603 2026] [security2:error] [pid 1025331:tid 1025384] [remote 47.86.33.52:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4ZYkOu5aQNSViFaxNJPwABejQ"]
[Mon Jul 20 06:49:39.057744 2026] [security2:error] [pid 1020501:tid 1020511] [remote 20.153.140.50:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ZY8S_oRsP4jdONhf9TAAAegc"]
[Mon Jul 20 06:49:39.227870 2026] [security2:error] [pid 1025331:tid 1025432] [remote 47.86.33.52:53338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4ZY0Ou5aQNSViFaxNJZgABOGQ"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 06:49:39.307097 2026] [security2:error] [pid 1025331:tid 1025478] [client 77.110.127.138:57471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZY0Ou5aQNSViFaxNJagAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:39.307223 2026] [security2:error] [pid 1025331:tid 1025478] [client 77.110.127.138:57471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZY0Ou5aQNSViFaxNJagAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:39.356084 2026] [security2:error] [pid 1020501:tid 1020663] [client 104.207.54.119:43587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZY8S_oRsP4jdONhf9YQAAAB4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:39.466600 2026] [security2:error] [pid 1020501:tid 1020585] [remote 20.153.140.50:51008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ZY8S_oRsP4jdONhf9ZQAAWlE"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:49:39.619670 2026] [security2:error] [pid 1025331:tid 1025413] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZY0Ou5aQNSViFaxNJbQABRVE"]
[Mon Jul 20 06:49:39.619839 2026] [security2:error] [pid 1025331:tid 1025520] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZY0Ou5aQNSViFaxNJbQABRVE"]
[Mon Jul 20 06:49:40.018868 2026] [security2:error] [pid 1025331:tid 1025504] [client 57.141.18.25:62400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZX0Ou5aQNSViFaxNIvgABNUQ"]
[Mon Jul 20 06:49:40.099370 2026] [security2:error] [pid 1020501:tid 1020535] [remote 45.90.123.233:37858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZZMS_oRsP4jdONhf9cgAAWR8"]
[Mon Jul 20 06:49:40.232465 2026] [security2:error] [pid 1025331:tid 1025531] [client 65.111.15.110:60987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZZEOu5aQNSViFaxNJhwAAAVA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:40.305283 2026] [security2:error] [pid 1020501:tid 1020521] [remote 45.90.123.233:37858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZZMS_oRsP4jdONhf9fQAAWxE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:49:40.324846 2026] [security2:error] [pid 1025331:tid 1025471] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZZEOu5aQNSViFaxNJgQAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:40.470843 2026] [security2:error] [pid 1025331:tid 1025458] [remote 202.51.202.242:41822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZZEOu5aQNSViFaxNJlAABW34"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:49:40.520566 2026] [security2:error] [pid 1025331:tid 1025566] [client 14.251.3.155:54730] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZZEOu5aQNSViFaxNJlgAAAXM"]
[Mon Jul 20 06:49:40.879023 2026] [security2:error] [pid 1020501:tid 1020736] [client 57.141.18.99:54466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZYMS_oRsP4jdONhf87AAAZzs"]
[Mon Jul 20 06:49:41.068134 2026] [security2:error] [pid 1020501:tid 1020755] [client 157.85.211.87:30061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZcS_oRsP4jdONhf9kwAAAHo"]
[Mon Jul 20 06:49:41.068257 2026] [security2:error] [pid 1020501:tid 1020755] [client 157.85.211.87:30061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZcS_oRsP4jdONhf9kwAAAHo"]
[Mon Jul 20 06:49:41.206301 2026] [security2:error] [pid 1025331:tid 1025422] [remote 78.46.157.202:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZZUOu5aQNSViFaxNJugABPFo"]
[Mon Jul 20 06:49:41.396448 2026] [security2:error] [pid 1025331:tid 1025538] [client 152.58.191.29:44262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZUOu5aQNSViFaxNJxgAAAVc"]
[Mon Jul 20 06:49:41.404304 2026] [security2:error] [pid 1025331:tid 1025538] [client 152.58.191.29:44262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZUOu5aQNSViFaxNJxgAAAVc"]
[Mon Jul 20 06:49:41.425660 2026] [security2:error] [pid 1025331:tid 1025374] [remote 78.46.157.202:38214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZZUOu5aQNSViFaxNJxwABhyo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:49:41.895260 2026] [security2:error] [pid 1025331:tid 1025521] [client 13.232.231.177:62670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZUOu5aQNSViFaxNJvQAAAUY"]
[Mon Jul 20 06:49:42.035782 2026] [security2:error] [pid 1020501:tid 1020735] [client 223.185.13.213:6580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZsS_oRsP4jdONhf9uAAAAGY"]
[Mon Jul 20 06:49:42.035901 2026] [security2:error] [pid 1020501:tid 1020735] [client 223.185.13.213:6580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZsS_oRsP4jdONhf9uAAAAGY"]
[Mon Jul 20 06:49:42.207484 2026] [security2:error] [pid 1025331:tid 1025557] [client 57.141.18.72:28088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZYUOu5aQNSViFaxNJKgABako"]
[Mon Jul 20 06:49:42.258030 2026] [security2:error] [pid 1020501:tid 1020526] [remote 57.141.18.22:24610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6316507"] [unique_id "al4ZZsS_oRsP4jdONhf9xAAAARY"]
[Mon Jul 20 06:49:42.345834 2026] [security2:error] [pid 1020501:tid 1020677] [client 87.236.176.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ZZsS_oRsP4jdONhf9vAAALFc"]
[Mon Jul 20 06:49:42.366743 2026] [security2:error] [pid 1020501:tid 1020643] [client 57.141.18.101:34740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZYsS_oRsP4jdONhf9KQAAClU"]
[Mon Jul 20 06:49:42.381341 2026] [security2:error] [pid 1025331:tid 1025544] [client 106.219.188.178:58729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ5AAAAV0"]
[Mon Jul 20 06:49:42.381447 2026] [security2:error] [pid 1025331:tid 1025544] [client 106.219.188.178:58729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ5AAAAV0"]
[Mon Jul 20 06:49:42.471254 2026] [security2:error] [pid 1025331:tid 1025475] [client 57.141.18.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ3gAAARg"]
[Mon Jul 20 06:49:42.564091 2026] [security2:error] [pid 1025331:tid 1025531] [client 37.52.210.45:23667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ6gAAAVA"]
[Mon Jul 20 06:49:42.564300 2026] [security2:error] [pid 1025331:tid 1025531] [client 37.52.210.45:23667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ6gAAAVA"]
[Mon Jul 20 06:49:42.637791 2026] [security2:error] [pid 1020501:tid 1020695] [client 197.186.66.42:57882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZZsS_oRsP4jdONhf91gAAAD4"]
[Mon Jul 20 06:49:42.637891 2026] [security2:error] [pid 1020501:tid 1020695] [client 197.186.66.42:57882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZZsS_oRsP4jdONhf91gAAAD4"]
[Mon Jul 20 06:49:42.706414 2026] [security2:error] [pid 1020501:tid 1020743] [client 183.82.98.154:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZsS_oRsP4jdONhf92gAAAG4"]
[Mon Jul 20 06:49:42.706570 2026] [security2:error] [pid 1020501:tid 1020743] [client 183.82.98.154:59023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZsS_oRsP4jdONhf92gAAAG4"]
[Mon Jul 20 06:49:42.728816 2026] [security2:error] [pid 1025331:tid 1025523] [client 77.110.127.138:57487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ-gAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:42.728925 2026] [security2:error] [pid 1025331:tid 1025523] [client 77.110.127.138:57487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ-gAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:42.959702 2026] [security2:error] [pid 1025331:tid 1025533] [client 57.141.18.49:55052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZYkOu5aQNSViFaxNJRQABUj8"]
[Mon Jul 20 06:49:43.285576 2026] [security2:error] [pid 1025331:tid 1025485] [client 161.118.218.103:58176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZZ0Ou5aQNSViFaxNKEQAAASI"]
[Mon Jul 20 06:49:43.458167 2026] [security2:error] [pid 1020501:tid 1020710] [client 57.141.18.81:40520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZY8S_oRsP4jdONhf9TgAATVw"]
[Mon Jul 20 06:49:43.573592 2026] [security2:error] [pid 1025331:tid 1025467] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZZ0Ou5aQNSViFaxNKGgAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:43.633621 2026] [security2:error] [pid 1025331:tid 1025508] [client 122.183.32.225:16059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZ0Ou5aQNSViFaxNKHwAAATk"]
[Mon Jul 20 06:49:43.633771 2026] [security2:error] [pid 1025331:tid 1025508] [client 122.183.32.225:16059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZZ0Ou5aQNSViFaxNKHwAAATk"]
[Mon Jul 20 06:49:43.822121 2026] [security2:error] [pid 1025331:tid 1025381] [remote 173.249.4.11:19902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZZ0Ou5aQNSViFaxNKKQABXzE"]
[Mon Jul 20 06:49:44.519945 2026] [security2:error] [pid 1025331:tid 1025388] [remote 154.66.198.148:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4ZaEOu5aQNSViFaxNKUwABMDg"]
[Mon Jul 20 06:49:44.532701 2026] [security2:error] [pid 1025331:tid 1025468] [client 57.141.18.13:62602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZY0Ou5aQNSViFaxNJdwABEXM"]
[Mon Jul 20 06:49:44.556904 2026] [security2:error] [pid 1025331:tid 1025356] [remote 173.249.4.11:19902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZaEOu5aQNSViFaxNKVAABNRg"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 06:49:44.728677 2026] [security2:error] [pid 1025331:tid 1025360] [remote 78.46.157.202:37158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZaEOu5aQNSViFaxNKXAABaBw"]
[Mon Jul 20 06:49:44.800680 2026] [security2:error] [pid 1025331:tid 1025559] [client 117.247.108.24:14152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaEOu5aQNSViFaxNKXQAAAWw"]
[Mon Jul 20 06:49:44.800801 2026] [security2:error] [pid 1025331:tid 1025559] [client 117.247.108.24:14152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaEOu5aQNSViFaxNKXQAAAWw"]
[Mon Jul 20 06:49:44.814093 2026] [cgid:error] [pid 1020501:tid 1020698] [client 66.132.195.53:50922] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: http://www.smtracking.genesismbs.com:80/cgi-bin
[Mon Jul 20 06:49:44.946015 2026] [security2:error] [pid 1025331:tid 1025392] [remote 78.46.157.202:37158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZaEOu5aQNSViFaxNKZQABIjw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:49:45.006486 2026] [security2:error] [pid 1020501:tid 1020658] [client 34.21.84.81:64317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.84.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healingpwr.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4ZacS_oRsP4jdONhf-KQAAABk"]
[Mon Jul 20 06:49:45.006586 2026] [security2:error] [pid 1020501:tid 1020658] [client 34.21.84.81:64317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "healingpwr.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4ZacS_oRsP4jdONhf-KQAAABk"]
[Mon Jul 20 06:49:45.179869 2026] [security2:error] [pid 1025331:tid 1025505] [client 103.125.179.95:50017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKcQAAATY"]
[Mon Jul 20 06:49:45.179988 2026] [security2:error] [pid 1025331:tid 1025505] [client 103.125.179.95:50017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKcQAAATY"]
[Mon Jul 20 06:49:45.232183 2026] [security2:error] [pid 1020501:tid 1020688] [client 161.118.218.103:58508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZacS_oRsP4jdONhf-LwAAADc"]
[Mon Jul 20 06:49:45.243888 2026] [security2:error] [pid 1025331:tid 1025585] [client 103.238.106.162:60759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKdgAAAYY"]
[Mon Jul 20 06:49:45.243995 2026] [security2:error] [pid 1025331:tid 1025585] [client 103.238.106.162:60759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKdgAAAYY"]
[Mon Jul 20 06:49:45.363688 2026] [security2:error] [pid 1025331:tid 1025498] [client 39.48.81.23:56289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKeQAAAS8"]
[Mon Jul 20 06:49:45.363883 2026] [security2:error] [pid 1025331:tid 1025498] [client 39.48.81.23:56289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKeQAAAS8"]
[Mon Jul 20 06:49:45.467304 2026] [proxy:error] [pid 1025331:tid 1025462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.467355 2026] [proxy_http:error] [pid 1025331:tid 1025462] [client 109.202.246.128:60275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.467804 2026] [proxy:error] [pid 1025331:tid 1025462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.467829 2026] [proxy_http:error] [pid 1025331:tid 1025462] [client 109.202.246.128:60275] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.593737 2026] [security2:error] [pid 1025331:tid 1025348] [remote 182.77.62.24:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZaUOu5aQNSViFaxNKgwABPBA"]
[Mon Jul 20 06:49:45.614821 2026] [security2:error] [pid 1025331:tid 1025512] [client 36.95.228.227:58322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKhAAAAT0"]
[Mon Jul 20 06:49:45.614913 2026] [security2:error] [pid 1025331:tid 1025512] [client 36.95.228.227:58322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZaUOu5aQNSViFaxNKhAAAAT0"]
[Mon Jul 20 06:49:45.640397 2026] [security2:error] [pid 1020501:tid 1020723] [client 50.116.65.227:53192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZacS_oRsP4jdONhf-QwAAAFo"]
[Mon Jul 20 06:49:45.648862 2026] [security2:error] [pid 1020501:tid 1020736] [client 50.116.65.227:53202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZacS_oRsP4jdONhf-RAAAAGc"]
[Mon Jul 20 06:49:45.733072 2026] [proxy:error] [pid 1025331:tid 1025576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.733127 2026] [proxy_http:error] [pid 1025331:tid 1025576] [client 109.202.246.128:60313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.733547 2026] [proxy:error] [pid 1025331:tid 1025576] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.733571 2026] [proxy_http:error] [pid 1025331:tid 1025576] [client 109.202.246.128:60313] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.840848 2026] [proxy:error] [pid 1020501:tid 1020675] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.840909 2026] [proxy_http:error] [pid 1020501:tid 1020675] [client 3.139.242.79:59022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.841331 2026] [proxy:error] [pid 1020501:tid 1020675] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.841358 2026] [proxy_http:error] [pid 1020501:tid 1020675] [client 3.139.242.79:59022] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.853086 2026] [proxy:error] [pid 1025331:tid 1025494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.853147 2026] [proxy_http:error] [pid 1025331:tid 1025494] [client 3.139.242.79:37513] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.853542 2026] [security2:error] [pid 1025331:tid 1025482] [client 57.141.18.101:34752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZZUOu5aQNSViFaxNJvgABHww"]
[Mon Jul 20 06:49:45.853619 2026] [proxy:error] [pid 1025331:tid 1025494] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:45.853647 2026] [proxy_http:error] [pid 1025331:tid 1025494] [client 3.139.242.79:37513] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:45.895973 2026] [security2:error] [pid 1025331:tid 1025407] [remote 154.66.198.148:55582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4ZaUOu5aQNSViFaxNKqwABUks"], referer: https://thedoctorscuisine.com/wp-login.php
[Mon Jul 20 06:49:45.997258 2026] [security2:error] [pid 1025331:tid 1025467] [client 109.202.246.128:60355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4ZaUOu5aQNSViFaxNKtwAAARA"]
[Mon Jul 20 06:49:46.117572 2026] [security2:error] [pid 1025331:tid 1025364] [remote 182.77.62.24:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZakOu5aQNSViFaxNKwgABiSA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:49:46.174030 2026] [security2:error] [pid 1025331:tid 1025502] [client 50.116.65.227:53214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZaUOu5aQNSViFaxNKtgAAATM"]
[Mon Jul 20 06:49:46.174122 2026] [security2:error] [pid 1025331:tid 1025513] [client 161.118.218.103:59752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZakOu5aQNSViFaxNKxgAAAT4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:46.279124 2026] [security2:error] [pid 1025331:tid 1025524] [client 109.202.246.128:60406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.246.202.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZakOu5aQNSViFaxNKzAAAAUk"]
[Mon Jul 20 06:49:46.281605 2026] [security2:error] [pid 1025331:tid 1025520] [client 217.142.18.172:63324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZakOu5aQNSViFaxNKzgAAAUU"]
[Mon Jul 20 06:49:46.285142 2026] [security2:error] [pid 1025331:tid 1025520] [client 217.142.18.172:63324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZakOu5aQNSViFaxNKzgAAAUU"]
[Mon Jul 20 06:49:46.300454 2026] [security2:error] [pid 1025331:tid 1025419] [remote 45.90.123.233:37874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fiq.jjc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZakOu5aQNSViFaxNK0QABUVc"]
[Mon Jul 20 06:49:46.300584 2026] [security2:error] [pid 1025331:tid 1025532] [client 45.90.123.233:37874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fiq.jjc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZakOu5aQNSViFaxNK0QABUVc"]
[Mon Jul 20 06:49:46.363123 2026] [security2:error] [pid 1020501:tid 1020711] [client 50.116.65.227:53242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZasS_oRsP4jdONhf-YgAAAE4"]
[Mon Jul 20 06:49:46.547161 2026] [proxy:error] [pid 1025331:tid 1025540] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:46.547240 2026] [proxy_http:error] [pid 1025331:tid 1025540] [client 109.202.246.128:60486] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:46.547808 2026] [proxy:error] [pid 1025331:tid 1025540] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:49:46.547836 2026] [proxy_http:error] [pid 1025331:tid 1025540] [client 109.202.246.128:60486] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:49:46.642547 2026] [security2:error] [pid 1020501:tid 1020564] [remote 173.212.252.15:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZasS_oRsP4jdONhf-cgAAaDw"]
[Mon Jul 20 06:49:46.764439 2026] [security2:error] [pid 1020501:tid 1020681] [client 161.118.218.103:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZasS_oRsP4jdONhf-dwAAADA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:46.812453 2026] [security2:error] [pid 1025331:tid 1025565] [client 109.202.246.128:60549] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZakOu5aQNSViFaxNK6QAAAXI"]
[Mon Jul 20 06:49:46.828485 2026] [security2:error] [pid 1025331:tid 1025497] [client 77.110.127.138:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZakOu5aQNSViFaxNK6wAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:46.828576 2026] [security2:error] [pid 1025331:tid 1025497] [client 77.110.127.138:57513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZakOu5aQNSViFaxNK6wAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:46.836139 2026] [security2:error] [pid 1020501:tid 1020544] [remote 173.212.252.15:33490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZasS_oRsP4jdONhf-egAAHig"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:49:47.077063 2026] [security2:error] [pid 1020501:tid 1020637] [client 109.202.246.128:60612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Za8S_oRsP4jdONhf-iQAAAAQ"]
[Mon Jul 20 06:49:47.292520 2026] [security2:error] [pid 1020501:tid 1020751] [client 57.141.18.98:41596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZZsS_oRsP4jdONhf93gAAdis"]
[Mon Jul 20 06:49:47.296891 2026] [security2:error] [pid 1025331:tid 1025571] [client 57.141.18.43:47272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZZkOu5aQNSViFaxNJ_gABeAE"]
[Mon Jul 20 06:49:47.335586 2026] [security2:error] [pid 1020501:tid 1020633] [client 161.118.218.103:60722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Za8S_oRsP4jdONhf-lQAAAAA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:47.343987 2026] [security2:error] [pid 1020501:tid 1020712] [client 109.202.246.128:60686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Za8S_oRsP4jdONhf-lgAAAE8"]
[Mon Jul 20 06:49:47.609475 2026] [security2:error] [pid 1025331:tid 1025579] [client 109.202.246.128:60777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4Za0Ou5aQNSViFaxNK_AAAAYA"]
[Mon Jul 20 06:49:47.734028 2026] [security2:error] [pid 1020501:tid 1020639] [client 104.234.53.67:48085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Za8S_oRsP4jdONhf-qwAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:47.877296 2026] [security2:error] [pid 1025331:tid 1025512] [client 109.202.246.128:60887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Za0Ou5aQNSViFaxNLAQAAAT0"]
[Mon Jul 20 06:49:47.911092 2026] [security2:error] [pid 1020501:tid 1020734] [client 161.118.218.103:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Za8S_oRsP4jdONhf-swAAAGU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:48.143018 2026] [security2:error] [pid 1025331:tid 1025543] [client 109.202.246.128:60961] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbEOu5aQNSViFaxNLCQAAAVw"]
[Mon Jul 20 06:49:48.262463 2026] [security2:error] [pid 1020501:tid 1020597] [remote 162.19.246.208:47772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4ZbMS_oRsP4jdONhf-xQAAYF0"]
[Mon Jul 20 06:49:48.305336 2026] [security2:error] [pid 1025331:tid 1025359] [remote 130.51.180.8:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ZbEOu5aQNSViFaxNLEAABcRs"]
[Mon Jul 20 06:49:48.305489 2026] [security2:error] [pid 1025331:tid 1025564] [client 130.51.180.8:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ZbEOu5aQNSViFaxNLEAABcRs"]
[Mon Jul 20 06:49:48.373359 2026] [security2:error] [pid 1025331:tid 1025526] [client 187.108.85.186:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZbEOu5aQNSViFaxNLGQAAAUs"]
[Mon Jul 20 06:49:48.373466 2026] [security2:error] [pid 1025331:tid 1025526] [client 187.108.85.186:52646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZbEOu5aQNSViFaxNLGQAAAUs"]
[Mon Jul 20 06:49:48.409708 2026] [security2:error] [pid 1020501:tid 1020699] [client 109.202.246.128:61047] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbMS_oRsP4jdONhf-ywAAAEI"]
[Mon Jul 20 06:49:48.471027 2026] [security2:error] [pid 1020501:tid 1020623] [remote 162.19.246.208:47772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4ZbMS_oRsP4jdONhf-0AAAZnc"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:49:48.492914 2026] [security2:error] [pid 1025331:tid 1025485] [client 161.118.218.103:61447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZbEOu5aQNSViFaxNLIwAAASI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:48.565371 2026] [security2:error] [pid 1025331:tid 1025539] [client 57.141.18.76:63254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZaEOu5aQNSViFaxNKOwABWEE"]
[Mon Jul 20 06:49:48.622837 2026] [security2:error] [pid 1020501:tid 1020572] [remote 103.75.185.95:49226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZbMS_oRsP4jdONhf-2gAAFkQ"]
[Mon Jul 20 06:49:48.622984 2026] [security2:error] [pid 1020501:tid 1020655] [client 103.75.185.95:49226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZbMS_oRsP4jdONhf-2gAAFkQ"]
[Mon Jul 20 06:49:48.674850 2026] [security2:error] [pid 1025331:tid 1025557] [client 109.202.246.128:61118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbEOu5aQNSViFaxNLMgAAAWo"]
[Mon Jul 20 06:49:48.831484 2026] [security2:error] [pid 1025331:tid 1025476] [client 57.141.18.93:48182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZaEOu5aQNSViFaxNKTgABGXY"]
[Mon Jul 20 06:49:48.940546 2026] [security2:error] [pid 1025331:tid 1025551] [client 109.202.246.128:61183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbEOu5aQNSViFaxNLQAAAAWQ"]
[Mon Jul 20 06:49:48.967397 2026] [security2:error] [pid 1020501:tid 1020760] [client 51.15.140.81:41882] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "cpanel-box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4ZbMS_oRsP4jdONhf-6AAAAH8"]
[Mon Jul 20 06:49:49.066551 2026] [security2:error] [pid 1025331:tid 1025513] [client 161.118.218.103:61809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZbUOu5aQNSViFaxNLQwAAAT4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:49.207253 2026] [security2:error] [pid 1025331:tid 1025483] [client 109.202.246.128:61274] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbUOu5aQNSViFaxNLSAAAASA"]
[Mon Jul 20 06:49:49.303399 2026] [security2:error] [pid 1025331:tid 1025527] [client 103.97.160.117:40326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZbUOu5aQNSViFaxNLRQAAAUw"]
[Mon Jul 20 06:49:49.444433 2026] [security2:error] [pid 1020501:tid 1020675] [client 77.110.127.138:57522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZbcS_oRsP4jdONhf-8wAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:49.444598 2026] [security2:error] [pid 1020501:tid 1020675] [client 77.110.127.138:57522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZbcS_oRsP4jdONhf-8wAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:49.473027 2026] [security2:error] [pid 1025331:tid 1025523] [client 109.202.246.128:61344] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbUOu5aQNSViFaxNLUwAAAUg"]
[Mon Jul 20 06:49:49.517150 2026] [security2:error] [pid 1025331:tid 1025346] [remote 81.173.115.7:44364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZbUOu5aQNSViFaxNLVgABeA4"]
[Mon Jul 20 06:49:49.643381 2026] [security2:error] [pid 1020501:tid 1020745] [client 161.118.218.103:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZbcS_oRsP4jdONhf_BAAAAHA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:49.714406 2026] [security2:error] [pid 1025331:tid 1025438] [remote 81.173.115.7:44364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZbUOu5aQNSViFaxNLYAABN2o"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:49:49.738307 2026] [security2:error] [pid 1020501:tid 1020709] [client 109.202.246.128:61413] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbcS_oRsP4jdONhf_BgAAAEw"]
[Mon Jul 20 06:49:49.849588 2026] [security2:error] [pid 1025331:tid 1025552] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZbUOu5aQNSViFaxNLUQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:49.896036 2026] [security2:error] [pid 1025331:tid 1025511] [client 104.234.53.63:29941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZbUOu5aQNSViFaxNLZgAAATw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:50.036730 2026] [security2:error] [pid 1020501:tid 1020691] [client 109.202.246.128:61489] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbsS_oRsP4jdONhf_FgAAADo"]
[Mon Jul 20 06:49:50.075598 2026] [security2:error] [pid 1025331:tid 1025520] [client 104.234.53.63:29941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZbkOu5aQNSViFaxNLdAAAAUU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:50.081817 2026] [security2:error] [pid 1025331:tid 1025458] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZbkOu5aQNSViFaxNLdwABOH4"]
[Mon Jul 20 06:49:50.081988 2026] [security2:error] [pid 1025331:tid 1025507] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZbkOu5aQNSViFaxNLdwABOH4"]
[Mon Jul 20 06:49:50.114845 2026] [security2:error] [pid 1025331:tid 1025584] [client 77.110.127.138:57525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZbkOu5aQNSViFaxNLeAAAAYU"]
[Mon Jul 20 06:49:50.114980 2026] [security2:error] [pid 1025331:tid 1025584] [client 77.110.127.138:57525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZbkOu5aQNSViFaxNLeAAAAYU"]
[Mon Jul 20 06:49:50.137348 2026] [security2:error] [pid 1025331:tid 1025491] [client 142.93.64.197:59160] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.229"] [uri "/"] [unique_id "al4ZbkOu5aQNSViFaxNLewAAASg"]
[Mon Jul 20 06:49:50.231683 2026] [security2:error] [pid 1020501:tid 1020759] [client 161.118.218.103:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZbsS_oRsP4jdONhf_HAAAAH4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:50.301115 2026] [security2:error] [pid 1025331:tid 1025573] [client 109.202.246.128:61583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbkOu5aQNSViFaxNLggAAAXo"]
[Mon Jul 20 06:49:50.475106 2026] [security2:error] [pid 1025331:tid 1025572] [client 142.93.64.197:46630] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.229"] [uri "/"] [unique_id "al4ZbkOu5aQNSViFaxNLhgAAAXk"]
[Mon Jul 20 06:49:50.567292 2026] [security2:error] [pid 1025331:tid 1025493] [client 109.202.246.128:61683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbkOu5aQNSViFaxNLiAAAASo"]
[Mon Jul 20 06:49:50.631203 2026] [security2:error] [pid 1025331:tid 1025516] [client 57.141.18.116:26158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZakOu5aQNSViFaxNK6AABQRM"]
[Mon Jul 20 06:49:50.759413 2026] [security2:error] [pid 1020501:tid 1020630] [remote 154.61.75.100:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZbsS_oRsP4jdONhf_LAAAZ34"]
[Mon Jul 20 06:49:50.808340 2026] [security2:error] [pid 1025331:tid 1025577] [client 161.118.218.103:62990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZbkOu5aQNSViFaxNLlQAAAX4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:50.833926 2026] [security2:error] [pid 1025331:tid 1025564] [client 109.202.246.128:61787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ums.ebh.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4ZbkOu5aQNSViFaxNLlgAAAXE"]
[Mon Jul 20 06:49:50.875090 2026] [security2:error] [pid 1025331:tid 1025561] [client 65.111.23.6:48839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZbkOu5aQNSViFaxNLlwAAAW4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:50.979105 2026] [security2:error] [pid 1025331:tid 1025342] [remote 162.19.86.63:51266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4ZbkOu5aQNSViFaxNLmQABRwo"]
[Mon Jul 20 06:49:51.184114 2026] [security2:error] [pid 1025331:tid 1025524] [client 57.141.18.30:54750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Za0Ou5aQNSViFaxNK9gABSXw"]
[Mon Jul 20 06:49:51.192243 2026] [security2:error] [pid 1025331:tid 1025353] [remote 162.19.86.63:51266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4Zb0Ou5aQNSViFaxNLoQABWhU"], referer: https://adambergeron.com/wp-login.php
[Mon Jul 20 06:49:51.246999 2026] [security2:error] [pid 1020501:tid 1020674] [client 14.225.17.146:52248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4ZbsS_oRsP4jdONhf_HQAAACk"], referer: http://ancestralidadytrance.space/NEW
[Mon Jul 20 06:49:51.276268 2026] [security2:error] [pid 1020501:tid 1020625] [remote 154.61.75.100:46950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Zb8S_oRsP4jdONhf_QgAATHk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:49:51.384470 2026] [security2:error] [pid 1025331:tid 1025480] [client 161.118.218.103:63378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zb0Ou5aQNSViFaxNLsgAAAR0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:51.790260 2026] [security2:error] [pid 1025331:tid 1025550] [client 45.3.34.162:28607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Zb0Ou5aQNSViFaxNLuQAAAWM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:49:51.872166 2026] [security2:error] [pid 1025331:tid 1025514] [client 77.110.127.138:57539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zb0Ou5aQNSViFaxNLvAAAAT8"]
[Mon Jul 20 06:49:51.872273 2026] [security2:error] [pid 1025331:tid 1025514] [client 77.110.127.138:57539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zb0Ou5aQNSViFaxNLvAAAAT8"]
[Mon Jul 20 06:49:51.958834 2026] [security2:error] [pid 1020501:tid 1020690] [client 161.118.218.103:63759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zb8S_oRsP4jdONhf_XQAAADk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:52.074834 2026] [security2:error] [pid 1025331:tid 1025440] [remote 57.141.18.94:21714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4875613"] [unique_id "al4ZcEOu5aQNSViFaxNLwgABGGw"]
[Mon Jul 20 06:49:52.215231 2026] [security2:error] [pid 1025331:tid 1025516] [client 152.58.191.29:57204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZcEOu5aQNSViFaxNLxAAAAUE"]
[Mon Jul 20 06:49:52.215329 2026] [security2:error] [pid 1025331:tid 1025516] [client 152.58.191.29:57204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZcEOu5aQNSViFaxNLxAAAAUE"]
[Mon Jul 20 06:49:52.399974 2026] [security2:error] [pid 1020501:tid 1020715] [client 57.141.18.19:38226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZbMS_oRsP4jdONhf-3gAAUjE"]
[Mon Jul 20 06:49:52.534975 2026] [security2:error] [pid 1020501:tid 1020749] [client 161.118.218.103:64129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZcMS_oRsP4jdONhf_ewAAAHQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:52.588487 2026] [autoindex:error] [pid 1025331:tid 1025424] [remote 34.83.147.252:62691] AH01276: Cannot serve directory /home2/cssgdzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://css.gdz.mybluehost.me
[Mon Jul 20 06:49:53.050714 2026] [security2:error] [pid 1020501:tid 1020671] [client 106.219.188.178:40987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZccS_oRsP4jdONhf_mgAAACY"]
[Mon Jul 20 06:49:53.062369 2026] [security2:error] [pid 1020501:tid 1020748] [client 66.249.73.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4ZcMS_oRsP4jdONhf_jQAAAHM"]
[Mon Jul 20 06:49:53.065543 2026] [security2:error] [pid 1020501:tid 1020671] [client 106.219.188.178:40987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZccS_oRsP4jdONhf_mgAAACY"]
[Mon Jul 20 06:49:53.110996 2026] [security2:error] [pid 1020501:tid 1020654] [client 161.118.218.103:64477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZccS_oRsP4jdONhf_nAAAABU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:53.211290 2026] [security2:error] [pid 1020501:tid 1020727] [client 37.52.210.45:26689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZccS_oRsP4jdONhf_pAAAAF4"]
[Mon Jul 20 06:49:53.211473 2026] [security2:error] [pid 1020501:tid 1020727] [client 37.52.210.45:26689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZccS_oRsP4jdONhf_pAAAAF4"]
[Mon Jul 20 06:49:53.350048 2026] [security2:error] [pid 1025331:tid 1025548] [client 223.185.13.213:11035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZcUOu5aQNSViFaxNL8QAAAWE"]
[Mon Jul 20 06:49:53.350368 2026] [security2:error] [pid 1025331:tid 1025548] [client 223.185.13.213:11035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZcUOu5aQNSViFaxNL8QAAAWE"]
[Mon Jul 20 06:49:53.379359 2026] [security2:error] [pid 1025331:tid 1025554] [client 183.82.98.154:59616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZcUOu5aQNSViFaxNL8gAAAWc"]
[Mon Jul 20 06:49:53.379437 2026] [security2:error] [pid 1025331:tid 1025554] [client 183.82.98.154:59616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZcUOu5aQNSViFaxNL8gAAAWc"]
[Mon Jul 20 06:49:53.441183 2026] [security2:error] [pid 1020501:tid 1020641] [client 57.141.18.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZccS_oRsP4jdONhf_rAAAAAg"]
[Mon Jul 20 06:49:53.687615 2026] [security2:error] [pid 1020501:tid 1020636] [client 161.118.218.103:64845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZccS_oRsP4jdONhf_twAAAAM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:54.187832 2026] [security2:error] [pid 1025331:tid 1025579] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZcUOu5aQNSViFaxNMAwAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:54.266515 2026] [security2:error] [pid 1020501:tid 1020640] [client 161.118.218.103:65237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZcsS_oRsP4jdONhf_0wAAAAc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:54.302247 2026] [security2:error] [pid 1020501:tid 1020730] [client 14.225.17.146:61819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4ZcsS_oRsP4jdONhf_zgAAAGE"], referer: http://thesoloceos.com/NEW
[Mon Jul 20 06:49:54.420723 2026] [security2:error] [pid 1025331:tid 1025576] [client 57.141.18.29:40482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZbkOu5aQNSViFaxNLmAABfQc"]
[Mon Jul 20 06:49:54.678453 2026] [security2:error] [pid 1025331:tid 1025525] [client 122.183.32.225:10211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZckOu5aQNSViFaxNMLQAAAUo"]
[Mon Jul 20 06:49:54.688111 2026] [security2:error] [pid 1025331:tid 1025525] [client 122.183.32.225:10211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZckOu5aQNSViFaxNMLQAAAUo"]
[Mon Jul 20 06:49:54.847311 2026] [security2:error] [pid 1025331:tid 1025523] [client 161.118.218.103:49206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZckOu5aQNSViFaxNMOQAAAUg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:55.020821 2026] [security2:error] [pid 1025331:tid 1025489] [client 104.234.53.68:53533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMRgAAASY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:55.201371 2026] [security2:error] [pid 1025331:tid 1025360] [remote 57.141.18.19:35034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "areitoproducciones.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMVAABTBw"], referer: https://areitoproducciones.com/etiqueta-producto/vst/
[Mon Jul 20 06:49:55.386512 2026] [security2:error] [pid 1025331:tid 1025477] [client 14.225.17.146:62912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMVQAAARo"], referer: https://thesoloceos.com/NEW
[Mon Jul 20 06:49:55.428133 2026] [security2:error] [pid 1025331:tid 1025499] [client 161.118.218.103:49527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMYgAAATA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:55.506977 2026] [security2:error] [pid 1020501:tid 1020733] [client 57.141.18.65:57768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zb8S_oRsP4jdONhf_YAAAZGc"]
[Mon Jul 20 06:49:55.546827 2026] [security2:error] [pid 1020501:tid 1020729] [client 158.173.89.95:56413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Zc8S_oRsP4jdONhf_-QAAAGA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:49:55.561835 2026] [security2:error] [pid 1020501:tid 1020738] [client 117.247.108.24:14586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Zc8S_oRsP4jdONhf__QAAAGk"]
[Mon Jul 20 06:49:55.561926 2026] [security2:error] [pid 1020501:tid 1020738] [client 117.247.108.24:14586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Zc8S_oRsP4jdONhf__QAAAGk"]
[Mon Jul 20 06:49:55.631111 2026] [security2:error] [pid 1025331:tid 1025584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMYAAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:55.710539 2026] [security2:error] [pid 1020501:tid 1020701] [client 57.141.18.112:32324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZcMS_oRsP4jdONhf_ZgAARCc"]
[Mon Jul 20 06:49:55.836260 2026] [security2:error] [pid 1025331:tid 1025483] [client 157.85.211.87:8774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMcgAAASA"]
[Mon Jul 20 06:49:55.836406 2026] [security2:error] [pid 1025331:tid 1025483] [client 157.85.211.87:8774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMcgAAASA"]
[Mon Jul 20 06:49:55.868386 2026] [security2:error] [pid 1020501:tid 1020731] [client 103.238.106.162:63569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zc8S_oRsP4jdONhcACQAAAGI"]
[Mon Jul 20 06:49:55.868491 2026] [security2:error] [pid 1020501:tid 1020731] [client 103.238.106.162:63569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zc8S_oRsP4jdONhcACQAAAGI"]
[Mon Jul 20 06:49:55.872434 2026] [security2:error] [pid 1025331:tid 1025510] [client 57.141.18.114:53262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZcEOu5aQNSViFaxNLxwABO3A"]
[Mon Jul 20 06:49:55.911598 2026] [security2:error] [pid 1025331:tid 1025581] [client 77.110.127.138:57564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zc0Ou5aQNSViFaxNMdQAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:55.986302 2026] [security2:error] [pid 1020501:tid 1020679] [client 14.224.227.113:54731] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Zc8S_oRsP4jdONhcADwAAAC4"]
[Mon Jul 20 06:49:56.002261 2026] [security2:error] [pid 1020501:tid 1020730] [client 161.118.218.103:49914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZdMS_oRsP4jdONhcAEAAAAGE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:56.075736 2026] [security2:error] [pid 1020501:tid 1020748] [client 14.225.17.146:61906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ZcsS_oRsP4jdONhf_0QAAAHM"], referer: http://sesamegreenbeans.com/NEW
[Mon Jul 20 06:49:56.093238 2026] [security2:error] [pid 1025331:tid 1025468] [client 77.110.127.138:57565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZdEOu5aQNSViFaxNMgQAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:56.093322 2026] [security2:error] [pid 1025331:tid 1025468] [client 77.110.127.138:57565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZdEOu5aQNSViFaxNMgQAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:56.100289 2026] [security2:error] [pid 1020501:tid 1020673] [client 103.125.179.95:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdMS_oRsP4jdONhcAEwAAACg"]
[Mon Jul 20 06:49:56.100382 2026] [security2:error] [pid 1020501:tid 1020673] [client 103.125.179.95:50518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdMS_oRsP4jdONhcAEwAAACg"]
[Mon Jul 20 06:49:56.228073 2026] [security2:error] [pid 1025331:tid 1025469] [client 104.234.53.58:57899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZdEOu5aQNSViFaxNMhwAAARI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:56.313343 2026] [security2:error] [pid 1025331:tid 1025554] [client 36.95.228.227:58798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdEOu5aQNSViFaxNMiwAAAWc"]
[Mon Jul 20 06:49:56.313438 2026] [security2:error] [pid 1025331:tid 1025554] [client 36.95.228.227:58798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdEOu5aQNSViFaxNMiwAAAWc"]
[Mon Jul 20 06:49:56.389933 2026] [security2:error] [pid 1025331:tid 1025531] [client 197.186.66.42:58421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZdEOu5aQNSViFaxNMjQAAAVA"]
[Mon Jul 20 06:49:56.390067 2026] [security2:error] [pid 1025331:tid 1025531] [client 197.186.66.42:58421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZdEOu5aQNSViFaxNMjQAAAVA"]
[Mon Jul 20 06:49:56.420566 2026] [security2:error] [pid 1025331:tid 1025576] [client 39.48.81.23:56809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdEOu5aQNSViFaxNMjgAAAX0"]
[Mon Jul 20 06:49:56.420694 2026] [security2:error] [pid 1025331:tid 1025576] [client 39.48.81.23:56809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdEOu5aQNSViFaxNMjgAAAX0"]
[Mon Jul 20 06:49:56.494995 2026] [security2:error] [pid 1025331:tid 1025486] [client 14.225.17.146:50892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMdgAAASM"], referer: http://bruceledewitz.com/NEW
[Mon Jul 20 06:49:56.576541 2026] [security2:error] [pid 1020501:tid 1020694] [client 161.118.218.103:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZdMS_oRsP4jdONhcAKwAAAD0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:56.591587 2026] [security2:error] [pid 1020501:tid 1020601] [remote 72.167.132.114:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZdMS_oRsP4jdONhcAKgAAKWE"]
[Mon Jul 20 06:49:56.795363 2026] [security2:error] [pid 1025331:tid 1025510] [client 77.110.127.138:57568] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 357 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZdEOu5aQNSViFaxNMoQAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:56.798621 2026] [security2:error] [pid 1020501:tid 1020685] [client 217.142.18.172:22754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdMS_oRsP4jdONhcAMwAAADQ"]
[Mon Jul 20 06:49:56.805529 2026] [security2:error] [pid 1020501:tid 1020685] [client 217.142.18.172:22754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZdMS_oRsP4jdONhcAMwAAADQ"]
[Mon Jul 20 06:49:56.875134 2026] [security2:error] [pid 1020501:tid 1020550] [remote 72.167.132.114:53472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZdMS_oRsP4jdONhcAOAAACS4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:49:56.952350 2026] [security2:error] [pid 1020501:tid 1020717] [client 104.234.53.57:27855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZdMS_oRsP4jdONhcANAAAAFQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:57.077228 2026] [security2:error] [pid 1020501:tid 1020668] [client 57.141.18.82:25698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZccS_oRsP4jdONhf_sAAAI3s"]
[Mon Jul 20 06:49:57.149149 2026] [security2:error] [pid 1025331:tid 1025575] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZdEOu5aQNSViFaxNMpAAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:57.153549 2026] [security2:error] [pid 1020501:tid 1020638] [client 14.225.17.146:55679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ZdMS_oRsP4jdONhcAOwAAAAU"], referer: https://sesamegreenbeans.com/NEW
[Mon Jul 20 06:49:57.155432 2026] [security2:error] [pid 1020501:tid 1020693] [client 161.118.218.103:50622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZdcS_oRsP4jdONhcARgAAADw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:57.382611 2026] [security2:error] [pid 1025331:tid 1025477] [client 113.44.97.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ZdUOu5aQNSViFaxNMsgABGn8"], referer: https://www.aleishapenny.ca/listing/page/128?paged=1&view=grid&posts_per_page=12
[Mon Jul 20 06:49:57.630094 2026] [security2:error] [pid 1020501:tid 1020683] [client 104.234.53.57:27855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZdcS_oRsP4jdONhcAVwAAADI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:49:57.692346 2026] [security2:error] [pid 1025331:tid 1025538] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZdUOu5aQNSViFaxNMuAAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:57.736886 2026] [security2:error] [pid 1025331:tid 1025550] [client 161.118.218.103:50999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZdUOu5aQNSViFaxNM1gAAAWM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:57.974585 2026] [security2:error] [pid 1025331:tid 1025536] [client 57.141.18.44:50202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZckOu5aQNSViFaxNMFgABVU8"]
[Mon Jul 20 06:49:57.992274 2026] [security2:error] [pid 1025331:tid 1025467] [client 50.116.65.227:12042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZdUOu5aQNSViFaxNM4gAAARA"]
[Mon Jul 20 06:49:58.001635 2026] [security2:error] [pid 1025331:tid 1025495] [client 50.116.65.227:12058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZdkOu5aQNSViFaxNM4wAAASw"]
[Mon Jul 20 06:49:58.169336 2026] [security2:error] [pid 1025331:tid 1025571] [client 196.189.121.195:27082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZckOu5aQNSViFaxNMJQABeDE"], referer: https://toddnielsen.com
[Mon Jul 20 06:49:58.184691 2026] [security2:error] [pid 1020501:tid 1020692] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZdcS_oRsP4jdONhcAZgAAADs"]
[Mon Jul 20 06:49:58.311327 2026] [security2:error] [pid 1025331:tid 1025532] [client 161.118.218.103:51347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZdkOu5aQNSViFaxNM8QAAAVE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:58.379605 2026] [security2:error] [pid 1020501:tid 1020595] [remote 217.61.143.92:46238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZdsS_oRsP4jdONhcAdwAAcFs"]
[Mon Jul 20 06:49:58.379822 2026] [security2:error] [pid 1020501:tid 1020745] [client 217.61.143.92:46238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZdsS_oRsP4jdONhcAdwAAcFs"]
[Mon Jul 20 06:49:58.437964 2026] [security2:error] [pid 1020501:tid 1020686] [client 77.110.127.138:57600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZdsS_oRsP4jdONhcAegAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:58.459299 2026] [security2:error] [pid 1025331:tid 1025333] [remote 45.150.79.142:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4ZdkOu5aQNSViFaxNM9gABSgE"]
[Mon Jul 20 06:49:58.488984 2026] [security2:error] [pid 1025331:tid 1025466] [client 77.110.127.138:57557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZdkOu5aQNSViFaxNM-QAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:58.489077 2026] [security2:error] [pid 1025331:tid 1025466] [client 77.110.127.138:57557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZdkOu5aQNSViFaxNM-QAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:58.546437 2026] [security2:error] [pid 1025331:tid 1025573] [client 77.110.127.138:57559] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 192 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZdkOu5aQNSViFaxNM_QAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:58.626812 2026] [security2:error] [pid 1025331:tid 1025357] [remote 45.150.79.142:59968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4ZdkOu5aQNSViFaxNNBAABIhk"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 06:49:58.630635 2026] [security2:error] [pid 1025331:tid 1025524] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZdkOu5aQNSViFaxNM9QAAAUk"]
[Mon Jul 20 06:49:58.653002 2026] [security2:error] [pid 1025331:tid 1025513] [client 57.141.18.28:26744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZckOu5aQNSViFaxNMOAABPiw"]
[Mon Jul 20 06:49:58.878342 2026] [security2:error] [pid 1020501:tid 1020743] [client 77.110.127.138:57562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZdsS_oRsP4jdONhcAjAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:58.878440 2026] [security2:error] [pid 1020501:tid 1020743] [client 77.110.127.138:57562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZdsS_oRsP4jdONhcAjAAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:58.885930 2026] [security2:error] [pid 1025331:tid 1025467] [client 161.118.218.103:51702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZdkOu5aQNSViFaxNNDQAAARA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:58.913500 2026] [security2:error] [pid 1025331:tid 1025545] [client 57.141.18.91:63952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zc0Ou5aQNSViFaxNMSwABXmU"]
[Mon Jul 20 06:49:59.034233 2026] [security2:error] [pid 1020501:tid 1020718] [client 77.110.127.138:57604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zd8S_oRsP4jdONhcAlQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:59.034353 2026] [security2:error] [pid 1020501:tid 1020718] [client 77.110.127.138:57604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zd8S_oRsP4jdONhcAlQAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:59.073993 2026] [security2:error] [pid 1025331:tid 1025481] [client 187.108.85.186:53191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNFQAAAR4"]
[Mon Jul 20 06:49:59.074101 2026] [security2:error] [pid 1025331:tid 1025481] [client 187.108.85.186:53191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNFQAAAR4"]
[Mon Jul 20 06:49:59.429404 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:57610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zd8S_oRsP4jdONhcAqQAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:59.429499 2026] [security2:error] [pid 1020501:tid 1020654] [client 77.110.127.138:57610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zd8S_oRsP4jdONhcAqQAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:59.445207 2026] [security2:error] [pid 1020501:tid 1020624] [remote 72.167.132.114:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4Zd8S_oRsP4jdONhcAqwAAAXg"]
[Mon Jul 20 06:49:59.459452 2026] [security2:error] [pid 1020501:tid 1020702] [client 161.118.218.103:52071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zd8S_oRsP4jdONhcArAAAAEU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:49:59.701952 2026] [security2:error] [pid 1020501:tid 1020542] [remote 72.167.132.114:53488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4Zd8S_oRsP4jdONhcAvgAAByY"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 06:49:59.786393 2026] [security2:error] [pid 1025331:tid 1025564] [client 77.110.127.138:57616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNOAAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:59.786484 2026] [security2:error] [pid 1025331:tid 1025564] [client 77.110.127.138:57616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNOAAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:49:59.805351 2026] [security2:error] [pid 1020501:tid 1020524] [remote 156.67.31.167:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4Zd8S_oRsP4jdONhcAwgAAZhQ"]
[Mon Jul 20 06:50:00.003713 2026] [security2:error] [pid 1020501:tid 1020622] [remote 156.67.31.167:58194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4ZeMS_oRsP4jdONhcAxQAAbHY"], referer: https://north-woods-engineering.com/wp-login.php
[Mon Jul 20 06:50:00.027222 2026] [security2:error] [pid 1020501:tid 1020666] [client 14.225.17.146:64094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4Zd8S_oRsP4jdONhcAvwAAACE"], referer: http://guidehunting.com/NEW
[Mon Jul 20 06:50:00.034126 2026] [security2:error] [pid 1025331:tid 1025468] [client 161.118.218.103:52423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZeEOu5aQNSViFaxNNRQAAARE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:00.048676 2026] [security2:error] [pid 1025331:tid 1025560] [client 57.141.18.109:55770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZdEOu5aQNSViFaxNMfwABbRA"]
[Mon Jul 20 06:50:00.066073 2026] [security2:error] [pid 1025331:tid 1025574] [client 8.219.158.81:59682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sve.xka.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNQAAAAXs"]
[Mon Jul 20 06:50:00.086241 2026] [security2:error] [pid 1020501:tid 1020675] [client 77.110.127.138:57581] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZeMS_oRsP4jdONhcAyAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:00.111584 2026] [security2:error] [pid 1025331:tid 1025533] [client 77.110.127.138:57620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZeEOu5aQNSViFaxNNTAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:00.111674 2026] [security2:error] [pid 1025331:tid 1025533] [client 77.110.127.138:57620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZeEOu5aQNSViFaxNNTAAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:00.125589 2026] [security2:error] [pid 1025331:tid 1025586] [client 14.225.17.146:64185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNOQAAAYc"], referer: http://lifeisbetterlakeside.com/NEW
[Mon Jul 20 06:50:00.128611 2026] [lsapi:warn] [pid 1020501:tid 1020616] [remote 185.21.13.119:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://ALI-ALGHANIM.NET/
[Mon Jul 20 06:50:00.208773 2026] [security2:error] [pid 1020501:tid 1020758] [client 77.110.127.138:57591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZeMS_oRsP4jdONhcA0gAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:00.208878 2026] [security2:error] [pid 1020501:tid 1020758] [client 77.110.127.138:57591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZeMS_oRsP4jdONhcA0gAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:00.421196 2026] [security2:error] [pid 1025331:tid 1025463] [client 77.110.127.138:57622] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 275 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZeEOu5aQNSViFaxNNWAAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:00.563780 2026] [security2:error] [pid 1025331:tid 1025432] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZeEOu5aQNSViFaxNNXAABfGQ"]
[Mon Jul 20 06:50:00.563913 2026] [security2:error] [pid 1025331:tid 1025575] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZeEOu5aQNSViFaxNNXAABfGQ"]
[Mon Jul 20 06:50:00.595637 2026] [security2:error] [pid 1025331:tid 1025521] [client 14.225.17.146:63913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4Zd0Ou5aQNSViFaxNNIAAAAUY"], referer: http://betterbonddogtraining.com/NEW
[Mon Jul 20 06:50:00.608100 2026] [security2:error] [pid 1025331:tid 1025490] [client 161.118.218.103:52728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZeEOu5aQNSViFaxNNYAAAASc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:00.991262 2026] [security2:error] [pid 1025331:tid 1025372] [remote 20.173.88.122:41160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ZeEOu5aQNSViFaxNNaQABcSg"]
[Mon Jul 20 06:50:01.115526 2026] [security2:error] [pid 1025331:tid 1025516] [client 14.225.17.146:57269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4ZeEOu5aQNSViFaxNNZgAAAUE"], referer: https://guidehunting.com/NEW
[Mon Jul 20 06:50:01.185162 2026] [security2:error] [pid 1020501:tid 1020639] [client 161.118.218.103:53081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZecS_oRsP4jdONhcA_gAAAAY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:01.345586 2026] [security2:error] [pid 1025331:tid 1025403] [remote 20.173.88.122:41160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ZeUOu5aQNSViFaxNNdQABL0c"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:50:01.651086 2026] [security2:error] [pid 1025331:tid 1025535] [client 77.110.127.138:57628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZeUOu5aQNSViFaxNNhAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:01.707957 2026] [security2:error] [pid 1025331:tid 1025519] [client 77.110.127.138:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZeUOu5aQNSViFaxNNigAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:01.708073 2026] [security2:error] [pid 1025331:tid 1025519] [client 77.110.127.138:57601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZeUOu5aQNSViFaxNNigAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:01.756175 2026] [security2:error] [pid 1025331:tid 1025470] [client 34.79.36.59:51338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "webmail.oxs.abv.mybluehost.me"] [uri "/"] [unique_id "al4ZeUOu5aQNSViFaxNNkAAAARM"]
[Mon Jul 20 06:50:01.768348 2026] [security2:error] [pid 1025331:tid 1025499] [client 161.118.218.103:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZeUOu5aQNSViFaxNNkwAAATA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:01.901966 2026] [security2:error] [pid 1020501:tid 1020698] [client 57.141.18.75:28674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZdcS_oRsP4jdONhcAXQAAQWM"]
[Mon Jul 20 06:50:01.987198 2026] [security2:error] [pid 1025331:tid 1025583] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZeUOu5aQNSViFaxNNkgAAAYQ"]
[Mon Jul 20 06:50:02.039590 2026] [security2:error] [pid 1025331:tid 1025496] [client 104.207.34.153:23663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 153.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZekOu5aQNSViFaxNNowAAAS0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:02.208269 2026] [security2:error] [pid 1020501:tid 1020721] [client 47.128.55.103:15476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mollycahill.com"] [uri "/robots.txt"] [unique_id "al4ZesS_oRsP4jdONhcBIwAAAFg"]
[Mon Jul 20 06:50:02.341877 2026] [security2:error] [pid 1025331:tid 1025552] [client 161.118.218.103:53852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZekOu5aQNSViFaxNNvAAAAWU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:02.486434 2026] [security2:error] [pid 1025331:tid 1025535] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZekOu5aQNSViFaxNNtwAAAVQ"]
[Mon Jul 20 06:50:02.608408 2026] [security2:error] [pid 1025331:tid 1025506] [client 3.75.183.99:56146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZekOu5aQNSViFaxNNxQAAATc"]
[Mon Jul 20 06:50:02.640820 2026] [security2:error] [pid 1020501:tid 1020714] [client 77.110.127.138:57606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 588 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZesS_oRsP4jdONhcBMgAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:02.717458 2026] [security2:error] [pid 1025331:tid 1025522] [client 14.225.17.146:62731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4ZeUOu5aQNSViFaxNNdgAAAUc"]
[Mon Jul 20 06:50:02.915852 2026] [security2:error] [pid 1025331:tid 1025556] [client 161.118.218.103:54183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZekOu5aQNSViFaxNN4AAAAWk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:02.998220 2026] [security2:error] [pid 1025331:tid 1025565] [client 152.58.191.29:57657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZekOu5aQNSViFaxNN5QAAAXI"]
[Mon Jul 20 06:50:03.005967 2026] [security2:error] [pid 1025331:tid 1025565] [client 152.58.191.29:57657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZekOu5aQNSViFaxNN5QAAAXI"]
[Mon Jul 20 06:50:03.104960 2026] [security2:error] [pid 1025331:tid 1025495] [client 44.245.170.32:31518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Ze0Ou5aQNSViFaxNN7QAAASw"]
[Mon Jul 20 06:50:03.133692 2026] [security2:error] [pid 1025331:tid 1025493] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZekOu5aQNSViFaxNN2wAAASo"]
[Mon Jul 20 06:50:03.160512 2026] [security2:error] [pid 1025331:tid 1025550] [client 63.179.149.246:47302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Ze0Ou5aQNSViFaxNN7wAAAWM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:50:03.445504 2026] [security2:error] [pid 1025331:tid 1025524] [client 104.234.53.59:60175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Ze0Ou5aQNSViFaxNN-AAAAUk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:03.474510 2026] [proxy:error] [pid 1025331:tid 1025497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:03.474590 2026] [proxy_http:error] [pid 1025331:tid 1025497] [client 134.209.24.55:54238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:03.475193 2026] [proxy:error] [pid 1025331:tid 1025497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:03.475219 2026] [proxy_http:error] [pid 1025331:tid 1025497] [client 134.209.24.55:54238] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:03.493814 2026] [security2:error] [pid 1025331:tid 1025581] [client 161.118.218.103:54542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOAwAAAYI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:03.595514 2026] [security2:error] [pid 1020501:tid 1020636] [client 57.141.18.123:33770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zd8S_oRsP4jdONhcApwAAA28"]
[Mon Jul 20 06:50:03.608782 2026] [security2:error] [pid 1025331:tid 1025488] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ze0Ou5aQNSViFaxNN_AAAASU"]
[Mon Jul 20 06:50:03.761633 2026] [proxy:error] [pid 1020501:tid 1020731] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:03.761687 2026] [proxy_http:error] [pid 1020501:tid 1020731] [client 134.209.24.55:54254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.drewsasburyparkbeachhouse.com/
[Mon Jul 20 06:50:03.762141 2026] [proxy:error] [pid 1020501:tid 1020731] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:03.762166 2026] [proxy_http:error] [pid 1020501:tid 1020731] [client 134.209.24.55:54254] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.drewsasburyparkbeachhouse.com/
[Mon Jul 20 06:50:03.782569 2026] [security2:error] [pid 1025331:tid 1025424] [remote 5.161.225.162:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4Ze0Ou5aQNSViFaxNODwABPVw"]
[Mon Jul 20 06:50:03.901560 2026] [security2:error] [pid 1025331:tid 1025588] [client 106.219.188.178:3288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOFAAAAYk"]
[Mon Jul 20 06:50:03.902133 2026] [security2:error] [pid 1025331:tid 1025588] [client 106.219.188.178:3288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOFAAAAYk"]
[Mon Jul 20 06:50:03.903176 2026] [security2:error] [pid 1025331:tid 1025484] [client 37.52.210.45:29580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOEwAAASE"]
[Mon Jul 20 06:50:03.903346 2026] [security2:error] [pid 1025331:tid 1025484] [client 37.52.210.45:29580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOEwAAASE"]
[Mon Jul 20 06:50:03.928211 2026] [security2:error] [pid 1025331:tid 1025534] [client 45.157.112.60:40551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOFQAAAVM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:50:03.992664 2026] [security2:error] [pid 1020501:tid 1020707] [client 160.30.136.8:52084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Ze8S_oRsP4jdONhcBaQAAAEo"]
[Mon Jul 20 06:50:04.017528 2026] [security2:error] [pid 1025331:tid 1025406] [remote 5.161.225.162:43954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4ZfEOu5aQNSViFaxNOGAABQEo"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 06:50:04.071238 2026] [security2:error] [pid 1020501:tid 1020729] [client 161.118.218.103:54892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZfMS_oRsP4jdONhcBbgAAAGA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:04.134671 2026] [security2:error] [pid 1025331:tid 1025467] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Ze0Ou5aQNSViFaxNOEQAAARA"]
[Mon Jul 20 06:50:04.159924 2026] [security2:error] [pid 1020501:tid 1020642] [client 183.82.98.154:60210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfMS_oRsP4jdONhcBcgAAAAk"]
[Mon Jul 20 06:50:04.160070 2026] [security2:error] [pid 1020501:tid 1020642] [client 183.82.98.154:60210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfMS_oRsP4jdONhcBcgAAAAk"]
[Mon Jul 20 06:50:04.374571 2026] [core:error] [pid 1025331:tid 1025500] [client 134.209.24.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:04.374600 2026] [core:error] [pid 1025331:tid 1025500] [client 134.209.24.55:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:04.574822 2026] [security2:error] [pid 1020501:tid 1020697] [client 14.225.17.146:62436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4ZesS_oRsP4jdONhcBOgAAAEA"], referer: http://areitoproducciones.com/NEW
[Mon Jul 20 06:50:04.646090 2026] [security2:error] [pid 1025331:tid 1025538] [client 161.118.218.103:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZfEOu5aQNSViFaxNOQQAAAVc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:04.724450 2026] [security2:error] [pid 1020501:tid 1020759] [client 57.141.18.27:57718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZeMS_oRsP4jdONhcA5QAAfhU"]
[Mon Jul 20 06:50:04.729141 2026] [security2:error] [pid 1025331:tid 1025580] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfEOu5aQNSViFaxNOOAAAAYE"]
[Mon Jul 20 06:50:04.738339 2026] [security2:error] [pid 1020501:tid 1020677] [client 77.110.127.138:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZfMS_oRsP4jdONhcBhAAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:04.738426 2026] [security2:error] [pid 1020501:tid 1020677] [client 77.110.127.138:57658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZfMS_oRsP4jdONhcBhAAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:05.008218 2026] [security2:error] [pid 1025331:tid 1025475] [client 160.30.136.8:53081] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adastra.love"] [uri "/"] [unique_id "al4ZfUOu5aQNSViFaxNOUAAAARg"]
[Mon Jul 20 06:50:05.064175 2026] [security2:error] [pid 1025331:tid 1025535] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfEOu5aQNSViFaxNOSwAAAVQ"]
[Mon Jul 20 06:50:05.124259 2026] [security2:error] [pid 1025331:tid 1025566] [client 57.141.18.91:51448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZeEOu5aQNSViFaxNNaAABczo"]
[Mon Jul 20 06:50:05.154881 2026] [security2:error] [pid 1020501:tid 1020713] [client 14.225.17.146:64257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4Ze8S_oRsP4jdONhcBXQAAAFA"], referer: http://scott-assist.com/NEW
[Mon Jul 20 06:50:05.227098 2026] [security2:error] [pid 1025331:tid 1025544] [client 161.118.218.103:55554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZfUOu5aQNSViFaxNOWwAAAV0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:05.302783 2026] [security2:error] [pid 1020501:tid 1020626] [remote 5.161.225.162:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ZfcS_oRsP4jdONhcBlwAAFno"]
[Mon Jul 20 06:50:05.417091 2026] [security2:error] [pid 1025331:tid 1025478] [client 160.30.136.8:65318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZfUOu5aQNSViFaxNOZgAAARs"]
[Mon Jul 20 06:50:05.508864 2026] [security2:error] [pid 1020501:tid 1020729] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfcS_oRsP4jdONhcBlgAAAGA"]
[Mon Jul 20 06:50:05.515430 2026] [security2:error] [pid 1020501:tid 1020524] [remote 5.161.225.162:43968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ZfcS_oRsP4jdONhcBowAANxQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:50:05.544641 2026] [security2:error] [pid 1025331:tid 1025430] [remote 152.228.213.32:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZfUOu5aQNSViFaxNObQABeGI"]
[Mon Jul 20 06:50:05.560244 2026] [security2:error] [pid 1025331:tid 1025468] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfUOu5aQNSViFaxNOYwAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:05.721862 2026] [security2:error] [pid 1025331:tid 1025564] [client 77.110.127.138:57668] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 722 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZfUOu5aQNSViFaxNOfAAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:05.753122 2026] [security2:error] [pid 1025331:tid 1025349] [remote 152.228.213.32:38260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZfUOu5aQNSViFaxNOfQABNxE"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 06:50:05.804057 2026] [security2:error] [pid 1025331:tid 1025573] [client 161.118.218.103:55903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZfUOu5aQNSViFaxNOgQAAAXo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:05.911482 2026] [security2:error] [pid 1025331:tid 1025515] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfUOu5aQNSViFaxNOewAAAUA"]
[Mon Jul 20 06:50:05.919466 2026] [security2:error] [pid 1025331:tid 1025565] [client 14.225.17.146:62439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4ZfUOu5aQNSViFaxNOggAAAXI"], referer: http://aljosour-alarabia.com/NEW
[Mon Jul 20 06:50:06.201638 2026] [security2:error] [pid 1025331:tid 1025462] [client 57.141.18.117:55134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZeUOu5aQNSViFaxNNnwABCyU"]
[Mon Jul 20 06:50:06.258171 2026] [security2:error] [pid 1020501:tid 1020692] [client 143.244.57.86:36724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "lapietramedjugorje.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4ZfsS_oRsP4jdONhcBwwAAADs"]
[Mon Jul 20 06:50:06.378406 2026] [security2:error] [pid 1020501:tid 1020636] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfsS_oRsP4jdONhcBvAAAAAM"]
[Mon Jul 20 06:50:06.382612 2026] [security2:error] [pid 1025331:tid 1025514] [client 161.118.218.103:56267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZfkOu5aQNSViFaxNOlAAAAT8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:06.425779 2026] [security2:error] [pid 1025331:tid 1025503] [client 160.30.136.8:51557] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adastra.love"] [uri "/"] [unique_id "al4ZfkOu5aQNSViFaxNOlgAAATQ"]
[Mon Jul 20 06:50:06.438109 2026] [security2:error] [pid 1025331:tid 1025537] [client 39.48.81.23:57335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfkOu5aQNSViFaxNOlwAAAVY"]
[Mon Jul 20 06:50:06.438263 2026] [security2:error] [pid 1025331:tid 1025537] [client 39.48.81.23:57335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfkOu5aQNSViFaxNOlwAAAVY"]
[Mon Jul 20 06:50:06.489319 2026] [security2:error] [pid 1020501:tid 1020691] [client 117.247.108.24:62207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfsS_oRsP4jdONhcBzgAAADo"]
[Mon Jul 20 06:50:06.489413 2026] [security2:error] [pid 1020501:tid 1020691] [client 117.247.108.24:62207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfsS_oRsP4jdONhcBzgAAADo"]
[Mon Jul 20 06:50:06.770584 2026] [security2:error] [pid 1020501:tid 1020745] [client 202.46.92.242:59269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfsS_oRsP4jdONhcB1gAAAHA"]
[Mon Jul 20 06:50:06.770718 2026] [security2:error] [pid 1020501:tid 1020745] [client 202.46.92.242:59269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfsS_oRsP4jdONhcB1gAAAHA"]
[Mon Jul 20 06:50:06.785470 2026] [security2:error] [pid 1025331:tid 1025499] [client 14.225.17.146:65092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4ZfkOu5aQNSViFaxNOnQAAATA"], referer: http://oldracelimited.com/NEW
[Mon Jul 20 06:50:06.815293 2026] [security2:error] [pid 1020501:tid 1020651] [client 57.141.18.37:22160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZesS_oRsP4jdONhcBMwAAEkw"]
[Mon Jul 20 06:50:06.838719 2026] [security2:error] [pid 1025331:tid 1025472] [client 160.30.136.8:54830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZfkOu5aQNSViFaxNOrAAAARU"]
[Mon Jul 20 06:50:06.859429 2026] [security2:error] [pid 1025331:tid 1025564] [client 143.244.57.86:36732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfkOu5aQNSViFaxNOrQAAAXE"]
[Mon Jul 20 06:50:06.892109 2026] [security2:error] [pid 1025331:tid 1025482] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZfkOu5aQNSViFaxNOpAAAAR8"]
[Mon Jul 20 06:50:06.926922 2026] [security2:error] [pid 1020501:tid 1020649] [client 103.125.179.95:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfsS_oRsP4jdONhcB2wAAABA"]
[Mon Jul 20 06:50:06.927072 2026] [security2:error] [pid 1020501:tid 1020649] [client 103.125.179.95:51019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZfsS_oRsP4jdONhcB2wAAABA"]
[Mon Jul 20 06:50:06.959209 2026] [security2:error] [pid 1020501:tid 1020671] [client 161.118.218.103:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZfsS_oRsP4jdONhcB3QAAACY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:07.063734 2026] [security2:error] [pid 1025331:tid 1025429] [remote 5.223.65.249:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4Zf0Ou5aQNSViFaxNOuAABemE"]
[Mon Jul 20 06:50:07.182809 2026] [security2:error] [pid 1020501:tid 1020647] [client 103.238.106.162:42791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zf8S_oRsP4jdONhcB5QAAAA4"]
[Mon Jul 20 06:50:07.182881 2026] [security2:error] [pid 1020501:tid 1020647] [client 103.238.106.162:42791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zf8S_oRsP4jdONhcB5QAAAA4"]
[Mon Jul 20 06:50:07.307319 2026] [security2:error] [pid 1020501:tid 1020666] [client 217.142.18.172:23088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Zf8S_oRsP4jdONhcB6gAAACE"]
[Mon Jul 20 06:50:07.322654 2026] [security2:error] [pid 1020501:tid 1020666] [client 217.142.18.172:23088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Zf8S_oRsP4jdONhcB6gAAACE"]
[Mon Jul 20 06:50:07.477158 2026] [security2:error] [pid 1025331:tid 1025407] [remote 5.223.65.249:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4Zf0Ou5aQNSViFaxNOzwABFEs"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 06:50:07.533541 2026] [security2:error] [pid 1025331:tid 1025501] [client 161.118.218.103:56974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zf0Ou5aQNSViFaxNO1AAAATI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:07.558343 2026] [security2:error] [pid 1025331:tid 1025489] [client 57.141.18.41:21962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ze0Ou5aQNSViFaxNN_wABJjU"]
[Mon Jul 20 06:50:07.597514 2026] [security2:error] [pid 1020501:tid 1020690] [client 57.141.18.29:59858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ze8S_oRsP4jdONhcBTwAAOTg"]
[Mon Jul 20 06:50:07.866321 2026] [security2:error] [pid 1020501:tid 1020708] [client 160.30.136.8:56332] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adastra.love"] [uri "/"] [unique_id "al4Zf8S_oRsP4jdONhcB_AAAAEs"]
[Mon Jul 20 06:50:07.872324 2026] [security2:error] [pid 1025331:tid 1025540] [client 14.225.17.146:60448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4Zf0Ou5aQNSViFaxNO3wAAAVk"], referer: http://expertcultures.com/NEW
[Mon Jul 20 06:50:07.880007 2026] [security2:error] [pid 1025331:tid 1025516] [client 104.234.53.59:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Zf0Ou5aQNSViFaxNO4wAAAUE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:08.089960 2026] [security2:error] [pid 1025331:tid 1025554] [client 77.110.127.138:57685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZgEOu5aQNSViFaxNO8AAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:08.090068 2026] [security2:error] [pid 1025331:tid 1025554] [client 77.110.127.138:57685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZgEOu5aQNSViFaxNO8AAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:08.091244 2026] [security2:error] [pid 1020501:tid 1020730] [client 57.141.18.45:64092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Ze8S_oRsP4jdONhcBaAAAYVs"]
[Mon Jul 20 06:50:08.111672 2026] [security2:error] [pid 1020501:tid 1020707] [client 161.118.218.103:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZgMS_oRsP4jdONhcCDgAAAEo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:08.214532 2026] [security2:error] [pid 1025331:tid 1025576] [client 14.225.17.146:49829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4ZfkOu5aQNSViFaxNOqwAAAX0"], referer: http://thechancersband.com/NEW
[Mon Jul 20 06:50:08.413180 2026] [security2:error] [pid 1025331:tid 1025483] [client 160.30.136.8:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZgEOu5aQNSViFaxNPBQAAASA"]
[Mon Jul 20 06:50:08.568603 2026] [security2:error] [pid 1020501:tid 1020668] [client 197.186.66.42:58948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZgMS_oRsP4jdONhcCHQAAACM"]
[Mon Jul 20 06:50:08.584584 2026] [security2:error] [pid 1020501:tid 1020668] [client 197.186.66.42:58948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZgMS_oRsP4jdONhcCHQAAACM"]
[Mon Jul 20 06:50:08.688261 2026] [security2:error] [pid 1020501:tid 1020671] [client 161.118.218.103:57630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZgMS_oRsP4jdONhcCJAAAACY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:08.709269 2026] [security2:error] [pid 1020501:tid 1020754] [client 122.183.32.225:26053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZgMS_oRsP4jdONhcCJQAAAHk"]
[Mon Jul 20 06:50:08.709412 2026] [security2:error] [pid 1020501:tid 1020754] [client 122.183.32.225:26053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZgMS_oRsP4jdONhcCJQAAAHk"]
[Mon Jul 20 06:50:08.812708 2026] [security2:error] [pid 1025331:tid 1025492] [client 77.110.127.138:57689] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 784 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZgEOu5aQNSViFaxNPGgAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:09.058265 2026] [security2:error] [pid 1025331:tid 1025511] [client 103.153.183.69:16290] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "autodiscover.qjg.ihb.mybluehost.me"] [uri "/"] [unique_id "al4ZgUOu5aQNSViFaxNPLQAAATw"], referer: https://t.co/o11c7avjjk
[Mon Jul 20 06:50:09.150372 2026] [security2:error] [pid 1025331:tid 1025455] [remote 57.141.18.56:38612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3396212"] [unique_id "al4ZgUOu5aQNSViFaxNPMgABgXs"]
[Mon Jul 20 06:50:09.234911 2026] [security2:error] [pid 1020501:tid 1020681] [client 5.161.75.7:53030] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4ZgcS_oRsP4jdONhcCMAAAADA"], referer: https://windowtx.com
[Mon Jul 20 06:50:09.265180 2026] [security2:error] [pid 1025331:tid 1025499] [client 161.118.218.103:58024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZgUOu5aQNSViFaxNPPAAAATA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:09.270590 2026] [security2:error] [pid 1025331:tid 1025391] [remote 57.141.18.33:47454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4480482"] [unique_id "al4ZgUOu5aQNSViFaxNPPQABMjs"]
[Mon Jul 20 06:50:09.442869 2026] [security2:error] [pid 1025331:tid 1025564] [client 14.225.17.146:58494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4ZgUOu5aQNSViFaxNPRAAAAXE"], referer: http://northbrookcpa.ca/NEW
[Mon Jul 20 06:50:09.500666 2026] [security2:error] [pid 1025331:tid 1025402] [remote 72.167.132.114:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4ZgUOu5aQNSViFaxNPTwABVEY"]
[Mon Jul 20 06:50:09.521798 2026] [security2:error] [pid 1025331:tid 1025473] [client 160.30.136.8:60984] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "adastra.love"] [uri "/"] [unique_id "al4ZgUOu5aQNSViFaxNPUgAAARY"]
[Mon Jul 20 06:50:09.546954 2026] [security2:error] [pid 1020501:tid 1020658] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wealthynarrative.com"] [uri "/.well-known/about.php"] [unique_id "al4ZgcS_oRsP4jdONhcCPQAAABk"]
[Mon Jul 20 06:50:09.547067 2026] [security2:error] [pid 1020501:tid 1020658] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "wealthynarrative.com"] [uri "/.well-known/about.php"] [unique_id "al4ZgcS_oRsP4jdONhcCPQAAABk"]
[Mon Jul 20 06:50:09.558299 2026] [security2:error] [pid 1025331:tid 1025505] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZgUOu5aQNSViFaxNPQgAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:09.678629 2026] [security2:error] [pid 1025331:tid 1025573] [client 187.108.85.186:53734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZgUOu5aQNSViFaxNPWQAAAXo"]
[Mon Jul 20 06:50:09.678758 2026] [security2:error] [pid 1025331:tid 1025573] [client 187.108.85.186:53734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZgUOu5aQNSViFaxNPWQAAAXo"]
[Mon Jul 20 06:50:09.717856 2026] [security2:error] [pid 1025331:tid 1025365] [remote 72.167.132.114:47420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4ZgUOu5aQNSViFaxNPXwABFSE"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 06:50:09.790948 2026] [security2:error] [pid 1020501:tid 1020669] [client 157.85.211.87:21722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZgcS_oRsP4jdONhcCTAAAACQ"]
[Mon Jul 20 06:50:09.791102 2026] [security2:error] [pid 1020501:tid 1020669] [client 157.85.211.87:21722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZgcS_oRsP4jdONhcCTAAAACQ"]
[Mon Jul 20 06:50:09.843888 2026] [security2:error] [pid 1025331:tid 1025578] [client 161.118.218.103:58373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZgUOu5aQNSViFaxNPawAAAX8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:09.865357 2026] [security2:error] [pid 1025331:tid 1025586] [client 57.141.18.25:39472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZfUOu5aQNSViFaxNOcQABhzI"]
[Mon Jul 20 06:50:09.895190 2026] [core:error] [pid 1025331:tid 1025548] [client 103.153.183.69:16290] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e%u002e/.env?_=lm3qcgfb&v=f6toh), referer: https://www.google.com/search?q=yfe0po
[Mon Jul 20 06:50:09.982555 2026] [security2:error] [pid 1025331:tid 1025481] [client 57.141.18.18:56264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZfUOu5aQNSViFaxNOdgABHhc"]
[Mon Jul 20 06:50:10.160452 2026] [security2:error] [pid 1020501:tid 1020705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZgcS_oRsP4jdONhcCTgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:10.240179 2026] [proxy:error] [pid 1020501:tid 1020641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:10.240259 2026] [proxy_http:error] [pid 1020501:tid 1020641] [client 34.73.38.214:58602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:10.240869 2026] [proxy:error] [pid 1020501:tid 1020641] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:10.240898 2026] [proxy_http:error] [pid 1020501:tid 1020641] [client 34.73.38.214:58602] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:10.420051 2026] [security2:error] [pid 1020501:tid 1020699] [client 161.118.218.103:58712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZgsS_oRsP4jdONhcCYAAAAEI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:10.570742 2026] [security2:error] [pid 1025331:tid 1025384] [remote 160.187.68.132:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4ZgkOu5aQNSViFaxNPjwABRzQ"]
[Mon Jul 20 06:50:10.648396 2026] [security2:error] [pid 1025331:tid 1025492] [client 14.251.3.155:54734] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZgkOu5aQNSViFaxNPmwAAASk"]
[Mon Jul 20 06:50:10.739914 2026] [security2:error] [pid 1025331:tid 1025501] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZgkOu5aQNSViFaxNPjQAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:10.808775 2026] [security2:error] [pid 1025331:tid 1025372] [remote 152.228.213.32:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZgkOu5aQNSViFaxNPpAABeCg"]
[Mon Jul 20 06:50:10.962280 2026] [proxy:error] [pid 1020501:tid 1020663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:10.962368 2026] [proxy_http:error] [pid 1020501:tid 1020663] [client 34.73.38.214:62290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:10.962837 2026] [proxy:error] [pid 1020501:tid 1020663] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:10.962872 2026] [proxy_http:error] [pid 1020501:tid 1020663] [client 34.73.38.214:62290] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:10.992533 2026] [security2:error] [pid 1020501:tid 1020680] [client 161.118.218.103:59137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZgsS_oRsP4jdONhcCcAAAAC8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:11.005382 2026] [security2:error] [pid 1025331:tid 1025352] [remote 152.228.213.32:53222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Zg0Ou5aQNSViFaxNPqgABQxQ"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:50:11.039216 2026] [security2:error] [pid 1025331:tid 1025403] [remote 160.187.68.132:45824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4Zg0Ou5aQNSViFaxNPqwABdUc"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 06:50:11.040638 2026] [security2:error] [pid 1020501:tid 1020631] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Zg8S_oRsP4jdONhcCcgAAP38"]
[Mon Jul 20 06:50:11.040802 2026] [security2:error] [pid 1020501:tid 1020696] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Zg8S_oRsP4jdONhcCcgAAP38"]
[Mon Jul 20 06:50:11.243726 2026] [security2:error] [pid 1025331:tid 1025477] [client 57.141.18.7:25980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZfkOu5aQNSViFaxNOsAABGnA"]
[Mon Jul 20 06:50:11.566500 2026] [security2:error] [pid 1025331:tid 1025465] [client 161.118.218.103:59555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zg0Ou5aQNSViFaxNPxgAAAQ4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:11.659562 2026] [security2:error] [pid 1025331:tid 1025464] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZgkOu5aQNSViFaxNPqAAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:11.670812 2026] [security2:error] [pid 1020501:tid 1020655] [client 14.225.17.146:63183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4ZgcS_oRsP4jdONhcCUAAAABY"], referer: http://bigwormfishing.com/NEW
[Mon Jul 20 06:50:11.680949 2026] [security2:error] [pid 1020501:tid 1020687] [client 34.139.11.221:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Zg8S_oRsP4jdONhcCiAAAADY"]
[Mon Jul 20 06:50:11.852199 2026] [security2:error] [pid 1025331:tid 1025500] [client 34.139.11.221:63812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Zg0Ou5aQNSViFaxNP2QAAATE"]
[Mon Jul 20 06:50:11.994389 2026] [proxy:error] [pid 1025331:tid 1025585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:11.994487 2026] [proxy_http:error] [pid 1025331:tid 1025585] [client 34.73.38.214:63988] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:11.995428 2026] [proxy:error] [pid 1025331:tid 1025585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:11.995471 2026] [proxy_http:error] [pid 1025331:tid 1025585] [client 34.73.38.214:63988] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:12.011854 2026] [security2:error] [pid 1025331:tid 1025559] [client 34.139.11.221:63843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhEOu5aQNSViFaxNP3gAAAWw"]
[Mon Jul 20 06:50:12.139800 2026] [security2:error] [pid 1020501:tid 1020633] [client 34.139.11.221:55130] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhMS_oRsP4jdONhcCoAAAAAA"]
[Mon Jul 20 06:50:12.143023 2026] [security2:error] [pid 1020501:tid 1020639] [client 161.118.218.103:60010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZhMS_oRsP4jdONhcCoQAAAAY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:12.272795 2026] [security2:error] [pid 1025331:tid 1025533] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZhEOu5aQNSViFaxNP4AAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:12.272927 2026] [security2:error] [pid 1025331:tid 1025582] [client 34.139.11.221:49163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhEOu5aQNSViFaxNP6wAAAYM"]
[Mon Jul 20 06:50:12.425505 2026] [security2:error] [pid 1020501:tid 1020750] [client 34.73.38.214:54650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZhMS_oRsP4jdONhcCrgAAAHU"]
[Mon Jul 20 06:50:12.441955 2026] [security2:error] [pid 1025331:tid 1025462] [client 143.244.57.86:36748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4ZhEOu5aQNSViFaxNP9gAAAQs"]
[Mon Jul 20 06:50:12.442031 2026] [security2:error] [pid 1025331:tid 1025462] [client 143.244.57.86:36748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lapietramedjugorje.com"] [uri "/xmlrpc.php"] [unique_id "al4ZhEOu5aQNSViFaxNP9gAAAQs"]
[Mon Jul 20 06:50:12.444414 2026] [security2:error] [pid 1025331:tid 1025532] [client 34.139.11.221:51885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhEOu5aQNSViFaxNP9wAAAVE"]
[Mon Jul 20 06:50:12.444868 2026] [security2:error] [pid 1025331:tid 1025476] [client 57.141.18.19:33436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZgEOu5aQNSViFaxNO9QABGX0"]
[Mon Jul 20 06:50:12.479605 2026] [security2:error] [pid 1025331:tid 1025492] [client 77.110.127.138:57717] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:amp8EYexsuX' OR 132. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 132 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZhEOu5aQNSViFaxNP-QAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:12.575433 2026] [security2:error] [pid 1025331:tid 1025574] [client 34.139.11.221:57103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhEOu5aQNSViFaxNP_QAAAXs"]
[Mon Jul 20 06:50:12.633924 2026] [security2:error] [pid 1025331:tid 1025489] [client 77.110.127.138:57719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZhEOu5aQNSViFaxNQBgAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:12.634008 2026] [security2:error] [pid 1025331:tid 1025489] [client 77.110.127.138:57719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZhEOu5aQNSViFaxNQBgAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:12.655844 2026] [security2:error] [pid 1025331:tid 1025463] [client 57.141.18.87:53538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZgEOu5aQNSViFaxNO_gABDFY"]
[Mon Jul 20 06:50:12.718694 2026] [security2:error] [pid 1025331:tid 1025500] [client 161.118.218.103:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZhEOu5aQNSViFaxNQDwAAATE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:12.722076 2026] [security2:error] [pid 1025331:tid 1025547] [client 34.139.11.221:51838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhEOu5aQNSViFaxNQEAAAAWA"]
[Mon Jul 20 06:50:12.735727 2026] [security2:error] [pid 1025331:tid 1025569] [client 57.141.18.21:50472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZgEOu5aQNSViFaxNPBgABdk8"]
[Mon Jul 20 06:50:12.739426 2026] [security2:error] [pid 1020501:tid 1020710] [client 65.111.30.50:52341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZhMS_oRsP4jdONhcCtgAAAE0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:12.885492 2026] [security2:error] [pid 1025331:tid 1025514] [client 34.139.11.221:51382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhEOu5aQNSViFaxNQGAAAAT8"]
[Mon Jul 20 06:50:13.022744 2026] [security2:error] [pid 1020501:tid 1020698] [client 34.139.11.221:51886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.oqw.bur.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhcS_oRsP4jdONhcCwQAAAEE"]
[Mon Jul 20 06:50:13.030367 2026] [security2:error] [pid 1025331:tid 1025548] [client 158.173.166.181:62279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZhUOu5aQNSViFaxNQHgAAAWE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:50:13.104872 2026] [security2:error] [pid 1025331:tid 1025522] [client 34.73.38.214:61486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhUOu5aQNSViFaxNQIgAAAUc"]
[Mon Jul 20 06:50:13.173943 2026] [security2:error] [pid 1020501:tid 1020644] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZhMS_oRsP4jdONhcCvwAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:13.207446 2026] [security2:error] [pid 1020501:tid 1020667] [client 216.73.217.138:1718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZhcS_oRsP4jdONhcCwwAAIlA"]
[Mon Jul 20 06:50:13.295028 2026] [security2:error] [pid 1025331:tid 1025497] [client 161.118.218.103:60800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQMAAAAS4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:13.362434 2026] [security2:error] [pid 1020501:tid 1020702] [client 216.73.217.138:1718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZhcS_oRsP4jdONhcCywAARUE"]
[Mon Jul 20 06:50:13.383612 2026] [security2:error] [pid 1025331:tid 1025506] [client 77.110.127.138:57726] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZhUOu5aQNSViFaxNQNgAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:13.429454 2026] [security2:error] [pid 1025331:tid 1025373] [remote 72.167.132.114:47426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4ZhUOu5aQNSViFaxNQOgABgik"]
[Mon Jul 20 06:50:13.618808 2026] [security2:error] [pid 1025331:tid 1025536] [client 45.3.46.133:11529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZhUOu5aQNSViFaxNQPAAAAVU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:13.630822 2026] [security2:error] [pid 1025331:tid 1025542] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQOQAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:13.672202 2026] [security2:error] [pid 1025331:tid 1025442] [remote 72.167.132.114:47426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4ZhUOu5aQNSViFaxNQQwABCm4"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:50:13.709569 2026] [security2:error] [pid 1025331:tid 1025412] [remote 46.101.194.217:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.194.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ZhUOu5aQNSViFaxNQRAABMVA"]
[Mon Jul 20 06:50:13.727970 2026] [security2:error] [pid 1025331:tid 1025507] [client 57.141.18.70:45300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZgUOu5aQNSViFaxNPWwABODM"]
[Mon Jul 20 06:50:13.874176 2026] [security2:error] [pid 1025331:tid 1025518] [client 161.118.218.103:61159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZhUOu5aQNSViFaxNQWQAAAUM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:13.886519 2026] [security2:error] [pid 1025331:tid 1025350] [remote 46.101.194.217:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.194.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ZhUOu5aQNSViFaxNQWgABKRI"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:50:13.893945 2026] [security2:error] [pid 1025331:tid 1025566] [client 104.234.53.89:28913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZhUOu5aQNSViFaxNQWwAAAXM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:13.901793 2026] [security2:error] [pid 1025331:tid 1025483] [client 34.73.38.214:53295] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhUOu5aQNSViFaxNQXAAAASA"]
[Mon Jul 20 06:50:13.972291 2026] [security2:error] [pid 1025331:tid 1025499] [client 57.141.18.120:23076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZgUOu5aQNSViFaxNPcAABMEE"]
[Mon Jul 20 06:50:13.983913 2026] [security2:error] [pid 1025331:tid 1025466] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQUAAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:14.194986 2026] [security2:error] [pid 1025331:tid 1025555] [client 14.225.17.146:50152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQQAAAAWg"]
[Mon Jul 20 06:50:14.365252 2026] [core:error] [pid 1020501:tid 1020689] [client 103.153.183.69:55808] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e%u002e/etc/passwd?_=1ll14ar5&v=wvo74), referer: https://news.ycombinator.com/
[Mon Jul 20 06:50:14.368098 2026] [security2:error] [pid 1025331:tid 1025569] [client 127.0.0.1:55200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZhkOu5aQNSViFaxNQagAAAXY"], referer: https://news.ycombinator.com/
[Mon Jul 20 06:50:14.451508 2026] [security2:error] [pid 1025331:tid 1025493] [client 161.118.218.103:61564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZhkOu5aQNSViFaxNQcwAAASo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:14.526041 2026] [security2:error] [pid 1025331:tid 1025531] [client 37.52.210.45:30779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZhkOu5aQNSViFaxNQdwAAAVA"]
[Mon Jul 20 06:50:14.526233 2026] [security2:error] [pid 1025331:tid 1025531] [client 37.52.210.45:30779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZhkOu5aQNSViFaxNQdwAAAVA"]
[Mon Jul 20 06:50:14.645276 2026] [security2:error] [pid 1020501:tid 1020690] [client 34.73.38.214:62783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZhsS_oRsP4jdONhcC9QAAADk"]
[Mon Jul 20 06:50:14.687347 2026] [security2:error] [pid 1025331:tid 1025472] [client 106.219.188.178:27773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZhkOu5aQNSViFaxNQfAAAARU"]
[Mon Jul 20 06:50:14.687462 2026] [security2:error] [pid 1025331:tid 1025472] [client 106.219.188.178:27773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZhkOu5aQNSViFaxNQfAAAARU"]
[Mon Jul 20 06:50:14.866683 2026] [security2:error] [pid 1025331:tid 1025581] [client 223.185.13.213:9139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZhkOu5aQNSViFaxNQgwAAAYI"]
[Mon Jul 20 06:50:14.866834 2026] [security2:error] [pid 1025331:tid 1025581] [client 223.185.13.213:9139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZhkOu5aQNSViFaxNQgwAAAYI"]
[Mon Jul 20 06:50:15.028572 2026] [security2:error] [pid 1025331:tid 1025482] [client 161.118.218.103:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQkAAAAR8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:15.044196 2026] [security2:error] [pid 1025331:tid 1025447] [remote 8.217.108.67:32480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQkQABUXM"]
[Mon Jul 20 06:50:15.248570 2026] [security2:error] [pid 1020501:tid 1020589] [remote 84.247.172.23:35700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4Zh8S_oRsP4jdONhcDDgAAWVU"]
[Mon Jul 20 06:50:15.346769 2026] [security2:error] [pid 1025331:tid 1025563] [client 183.82.98.154:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQmwAAAXA"]
[Mon Jul 20 06:50:15.346875 2026] [security2:error] [pid 1025331:tid 1025563] [client 183.82.98.154:60802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQmwAAAXA"]
[Mon Jul 20 06:50:15.543597 2026] [security2:error] [pid 1025331:tid 1025523] [client 14.225.17.146:62847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQXQAAAUg"], referer: http://myspineworld.com/NEW
[Mon Jul 20 06:50:15.549790 2026] [security2:error] [pid 1025331:tid 1025519] [client 34.73.38.214:56409] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Zh0Ou5aQNSViFaxNQowAAAUQ"]
[Mon Jul 20 06:50:15.557162 2026] [security2:error] [pid 1025331:tid 1025491] [client 77.110.127.138:57737] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampKVQhRJG8') OR 458. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 458 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zh0Ou5aQNSViFaxNQpQAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:15.607143 2026] [security2:error] [pid 1020501:tid 1020741] [client 161.118.218.103:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zh8S_oRsP4jdONhcDIgAAAGw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:15.626594 2026] [security2:error] [pid 1025331:tid 1025511] [client 77.110.127.138:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQqgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:15.626710 2026] [security2:error] [pid 1025331:tid 1025511] [client 77.110.127.138:57702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQqgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:15.653426 2026] [security2:error] [pid 1025331:tid 1025467] [client 57.141.18.113:60876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zg0Ou5aQNSViFaxNPxwABEEw"]
[Mon Jul 20 06:50:16.175636 2026] [security2:error] [pid 1020501:tid 1020534] [remote 84.247.172.23:35700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4ZiMS_oRsP4jdONhcDOAAAWh4"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:50:16.183340 2026] [security2:error] [pid 1020501:tid 1020720] [client 161.118.218.103:62833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZiMS_oRsP4jdONhcDOQAAAFc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:16.394533 2026] [security2:error] [pid 1025331:tid 1025385] [remote 217.61.143.92:37074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZiEOu5aQNSViFaxNQwAABJTU"]
[Mon Jul 20 06:50:16.394659 2026] [security2:error] [pid 1025331:tid 1025488] [client 217.61.143.92:37074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZiEOu5aQNSViFaxNQwAABJTU"]
[Mon Jul 20 06:50:16.505832 2026] [security2:error] [pid 1025331:tid 1025513] [client 14.225.17.146:58951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4ZiEOu5aQNSViFaxNQvQAAAT4"], referer: https://myspineworld.com/NEW
[Mon Jul 20 06:50:16.548278 2026] [security2:error] [pid 1020501:tid 1020732] [client 77.110.127.138:57706] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet/page/2*if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4ZiMS_oRsP4jdONhcDSAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:16.555498 2026] [core:error] [pid 1025331:tid 1025584] [client 95.217.114.159:55576] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:16.555518 2026] [core:error] [pid 1025331:tid 1025584] [client 95.217.114.159:55576] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:16.715962 2026] [security2:error] [pid 1025331:tid 1025543] [client 34.73.38.214:51518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZiEOu5aQNSViFaxNQywAAAVw"]
[Mon Jul 20 06:50:16.761109 2026] [security2:error] [pid 1025331:tid 1025502] [client 161.118.218.103:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZiEOu5aQNSViFaxNQzQAAATM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:16.782885 2026] [security2:error] [pid 1020501:tid 1020715] [client 122.183.32.225:6937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZiMS_oRsP4jdONhcDUwAAAFI"]
[Mon Jul 20 06:50:16.782990 2026] [security2:error] [pid 1020501:tid 1020715] [client 122.183.32.225:6937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZiMS_oRsP4jdONhcDUwAAAFI"]
[Mon Jul 20 06:50:16.850739 2026] [security2:error] [pid 1020501:tid 1020539] [remote 162.19.246.208:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4ZiMS_oRsP4jdONhcDVQAAYiM"]
[Mon Jul 20 06:50:17.028166 2026] [security2:error] [pid 1020501:tid 1020686] [client 14.225.17.146:51079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4Zh8S_oRsP4jdONhcDFQAAADU"], referer: http://maplerespiteservices.com/NEW
[Mon Jul 20 06:50:17.037818 2026] [security2:error] [pid 1025331:tid 1025536] [client 104.234.53.59:32845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ3wAAAVU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:17.051289 2026] [security2:error] [pid 1025331:tid 1025516] [client 57.141.18.64:58166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZhEOu5aQNSViFaxNQGQABQVw"]
[Mon Jul 20 06:50:17.070939 2026] [security2:error] [pid 1020501:tid 1020507] [remote 162.19.246.208:51910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4ZicS_oRsP4jdONhcDXwAAAgM"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 06:50:17.083917 2026] [autoindex:error] [pid 1025331:tid 1025571] [client 95.217.114.159:55590] AH01276: Cannot serve directory /home1/uritemsn/public_html/aljosour-alarabia-net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:50:17.195484 2026] [security2:error] [pid 1025331:tid 1025477] [client 117.247.108.24:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ6gAAARo"]
[Mon Jul 20 06:50:17.195596 2026] [security2:error] [pid 1025331:tid 1025477] [client 117.247.108.24:62120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ6gAAARo"]
[Mon Jul 20 06:50:17.197348 2026] [security2:error] [pid 1020501:tid 1020637] [client 39.48.81.23:57860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZicS_oRsP4jdONhcDZQAAAAQ"]
[Mon Jul 20 06:50:17.197584 2026] [security2:error] [pid 1020501:tid 1020637] [client 39.48.81.23:57860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZicS_oRsP4jdONhcDZQAAAAQ"]
[Mon Jul 20 06:50:17.322170 2026] [security2:error] [pid 1025331:tid 1025478] [client 57.141.18.22:22222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQLQABGw0"]
[Mon Jul 20 06:50:17.327709 2026] [security2:error] [pid 1025331:tid 1025515] [client 14.225.17.146:65411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ5wAAAUA"], referer: http://careysheatingandcooling.com/NEW
[Mon Jul 20 06:50:17.335194 2026] [security2:error] [pid 1025331:tid 1025578] [client 161.118.218.103:63773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ7QAAAX8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:17.397839 2026] [security2:error] [pid 1020501:tid 1020613] [remote 91.142.222.105:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4ZicS_oRsP4jdONhcDagAAR20"]
[Mon Jul 20 06:50:17.438510 2026] [security2:error] [pid 1025331:tid 1025566] [client 77.110.127.138:57744] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampIa55gtUp')) OR 218. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 218 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZiUOu5aQNSViFaxNQ9AAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:17.519851 2026] [security2:error] [pid 1020501:tid 1020703] [client 34.73.38.214:61578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZicS_oRsP4jdONhcDdQAAAEY"]
[Mon Jul 20 06:50:17.558403 2026] [security2:error] [pid 1025331:tid 1025586] [client 36.95.228.227:59753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ-wAAAYc"]
[Mon Jul 20 06:50:17.558495 2026] [security2:error] [pid 1025331:tid 1025586] [client 36.95.228.227:59753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ-wAAAYc"]
[Mon Jul 20 06:50:17.590844 2026] [security2:error] [pid 1025331:tid 1025341] [remote 72.167.132.114:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ_AABegk"]
[Mon Jul 20 06:50:17.675586 2026] [security2:error] [pid 1020501:tid 1020746] [client 103.125.179.95:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZicS_oRsP4jdONhcDegAAAHE"]
[Mon Jul 20 06:50:17.675701 2026] [security2:error] [pid 1020501:tid 1020746] [client 103.125.179.95:51518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZicS_oRsP4jdONhcDegAAAHE"]
[Mon Jul 20 06:50:17.778240 2026] [security2:error] [pid 1020501:tid 1020510] [remote 91.142.222.105:52292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4ZicS_oRsP4jdONhcDfAAAHgY"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 06:50:17.814440 2026] [security2:error] [pid 1025331:tid 1025378] [remote 72.167.132.114:56380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4ZiUOu5aQNSViFaxNRCQABRS4"], referer: https://lutheranphilosopher.com/wp-login.php
[Mon Jul 20 06:50:17.851168 2026] [security2:error] [pid 1020501:tid 1020671] [client 217.142.18.172:13585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZicS_oRsP4jdONhcDggAAACY"]
[Mon Jul 20 06:50:17.851439 2026] [security2:error] [pid 1020501:tid 1020671] [client 217.142.18.172:13585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZicS_oRsP4jdONhcDggAAACY"]
[Mon Jul 20 06:50:17.856173 2026] [security2:error] [pid 1025331:tid 1025524] [client 57.141.18.6:34884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQTAABSV4"]
[Mon Jul 20 06:50:17.856812 2026] [security2:error] [pid 1025331:tid 1025464] [client 57.141.18.116:27784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZhUOu5aQNSViFaxNQTQABDSQ"]
[Mon Jul 20 06:50:17.891803 2026] [security2:error] [pid 1025331:tid 1025513] [client 103.238.106.162:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZiUOu5aQNSViFaxNRCgAAAT4"]
[Mon Jul 20 06:50:17.891924 2026] [security2:error] [pid 1025331:tid 1025513] [client 103.238.106.162:60781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZiUOu5aQNSViFaxNRCgAAAT4"]
[Mon Jul 20 06:50:17.908836 2026] [security2:error] [pid 1020501:tid 1020747] [client 161.118.218.103:64215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZicS_oRsP4jdONhcDhQAAAHI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:17.952769 2026] [security2:error] [pid 1025331:tid 1025463] [client 14.225.17.146:58851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4ZiUOu5aQNSViFaxNREAAAAQw"], referer: http://balticsteelmgmt.com/NEW
[Mon Jul 20 06:50:18.020258 2026] [security2:error] [pid 1020501:tid 1020658] [client 14.225.17.146:51253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4ZiMS_oRsP4jdONhcDWgAAABk"], referer: http://intelligentengineeringsolutions.com/NEW
[Mon Jul 20 06:50:18.156687 2026] [security2:error] [pid 1025331:tid 1025506] [client 40.77.167.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4ZiUOu5aQNSViFaxNRDwAAATc"]
[Mon Jul 20 06:50:18.257951 2026] [security2:error] [pid 1020501:tid 1020728] [client 34.73.38.214:55779] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZisS_oRsP4jdONhcDlgAAAF8"]
[Mon Jul 20 06:50:18.384256 2026] [security2:error] [pid 1025331:tid 1025358] [remote 173.212.252.15:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZikOu5aQNSViFaxNRKAABgRo"]
[Mon Jul 20 06:50:18.422951 2026] [security2:error] [pid 1025331:tid 1025543] [client 34.139.11.221:60201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZikOu5aQNSViFaxNRKgAAAVw"]
[Mon Jul 20 06:50:18.483292 2026] [security2:error] [pid 1025331:tid 1025465] [client 161.118.218.103:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZikOu5aQNSViFaxNRLQAAAQ4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:18.576158 2026] [security2:error] [pid 1025331:tid 1025382] [remote 173.212.252.15:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZikOu5aQNSViFaxNRMQABMDI"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:50:18.587596 2026] [security2:error] [pid 1025331:tid 1025495] [client 34.139.11.221:60370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZikOu5aQNSViFaxNRMwAAASw"]
[Mon Jul 20 06:50:18.722320 2026] [security2:error] [pid 1020501:tid 1020740] [client 34.139.11.221:65245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZisS_oRsP4jdONhcDrQAAAGs"]
[Mon Jul 20 06:50:18.843267 2026] [security2:error] [pid 1020501:tid 1020735] [client 34.139.11.221:59082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZisS_oRsP4jdONhcDsAAAAGY"]
[Mon Jul 20 06:50:18.907214 2026] [security2:error] [pid 1020501:tid 1020694] [client 57.141.18.14:46794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZhsS_oRsP4jdONhcC-AAAPTE"]
[Mon Jul 20 06:50:18.977332 2026] [core:error] [pid 1025331:tid 1025503] [client 103.153.183.69:10578] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e%u002e/%u002e%u002e/.env?_=bp7tk44g&v=7mjsh), referer: https://news.ycombinator.com/
[Mon Jul 20 06:50:19.033163 2026] [security2:error] [pid 1025331:tid 1025514] [client 34.139.11.221:63762] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNRQwAAAT8"]
[Mon Jul 20 06:50:19.060849 2026] [security2:error] [pid 1020501:tid 1020707] [client 161.118.218.103:65076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zi8S_oRsP4jdONhcDuQAAAEo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:19.118268 2026] [security2:error] [pid 1025331:tid 1025538] [client 34.73.38.214:51682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNRSQAAAVc"]
[Mon Jul 20 06:50:19.199597 2026] [security2:error] [pid 1020501:tid 1020727] [client 34.139.11.221:59530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi8S_oRsP4jdONhcDxAAAAF4"]
[Mon Jul 20 06:50:19.344139 2026] [security2:error] [pid 1025331:tid 1025530] [client 34.139.11.221:65239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNRXgAAAU8"]
[Mon Jul 20 06:50:19.481447 2026] [security2:error] [pid 1020501:tid 1020696] [client 34.139.11.221:64995] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi8S_oRsP4jdONhcDzAAAAD8"]
[Mon Jul 20 06:50:19.499185 2026] [security2:error] [pid 1025331:tid 1025508] [client 57.141.18.114:45508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zh0Ou5aQNSViFaxNQlAABOUI"]
[Mon Jul 20 06:50:19.636318 2026] [security2:error] [pid 1025331:tid 1025465] [client 161.118.218.103:65511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zi0Ou5aQNSViFaxNRaQAAAQ4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:19.640833 2026] [security2:error] [pid 1025331:tid 1025572] [client 34.139.11.221:55287] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNRagAAAXk"]
[Mon Jul 20 06:50:19.676205 2026] [security2:error] [pid 1020501:tid 1020640] [client 14.225.17.146:51173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4Zi8S_oRsP4jdONhcDvAAAAAc"], referer: http://idigress.studio/NEW
[Mon Jul 20 06:50:19.689647 2026] [security2:error] [pid 1025331:tid 1025518] [client 14.225.17.146:58876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4Zi0Ou5aQNSViFaxNRZwAAAUM"], referer: http://thefriendlyspreadsheet.com/NEW
[Mon Jul 20 06:50:19.745436 2026] [security2:error] [pid 1025331:tid 1025553] [client 50.116.65.227:41752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Zi0Ou5aQNSViFaxNRcAAAAWY"]
[Mon Jul 20 06:50:19.755502 2026] [security2:error] [pid 1025331:tid 1025571] [client 50.116.65.227:41766] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Zi0Ou5aQNSViFaxNRcgAAAXg"]
[Mon Jul 20 06:50:19.810856 2026] [security2:error] [pid 1025331:tid 1025484] [client 34.139.11.221:63703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNRdQAAASE"]
[Mon Jul 20 06:50:19.976527 2026] [security2:error] [pid 1025331:tid 1025501] [client 34.139.11.221:51105] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNRdwAAATI"]
[Mon Jul 20 06:50:19.985417 2026] [security2:error] [pid 1025331:tid 1025562] [client 34.73.38.214:50099] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Zi0Ou5aQNSViFaxNReQAAAW8"]
[Mon Jul 20 06:50:20.170180 2026] [security2:error] [pid 1025331:tid 1025466] [client 34.139.11.221:58217] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.ouw.egd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZjEOu5aQNSViFaxNRfgAAAQ8"]
[Mon Jul 20 06:50:20.208666 2026] [security2:error] [pid 1025331:tid 1025538] [client 161.118.218.103:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZjEOu5aQNSViFaxNRgAAAAVc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:20.340174 2026] [security2:error] [pid 1025331:tid 1025507] [client 187.108.85.186:54289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZjEOu5aQNSViFaxNRigAAATg"]
[Mon Jul 20 06:50:20.340307 2026] [security2:error] [pid 1025331:tid 1025507] [client 187.108.85.186:54289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZjEOu5aQNSViFaxNRigAAATg"]
[Mon Jul 20 06:50:20.454645 2026] [security2:error] [pid 1020501:tid 1020739] [client 152.58.191.29:18309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZjMS_oRsP4jdONhcEBAAAAGo"]
[Mon Jul 20 06:50:20.454739 2026] [security2:error] [pid 1020501:tid 1020739] [client 152.58.191.29:18309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZjMS_oRsP4jdONhcEBAAAAGo"]
[Mon Jul 20 06:50:20.609606 2026] [security2:error] [pid 1025331:tid 1025441] [remote 217.61.143.92:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4ZjEOu5aQNSViFaxNRkgABH20"]
[Mon Jul 20 06:50:20.612112 2026] [security2:error] [pid 1025331:tid 1025558] [client 50.116.65.227:19202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4ZjEOu5aQNSViFaxNRkwAAAWs"]
[Mon Jul 20 06:50:20.626036 2026] [security2:error] [pid 1025331:tid 1025521] [client 50.116.65.227:41794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4ZjEOu5aQNSViFaxNRlgAAAUY"]
[Mon Jul 20 06:50:20.691197 2026] [security2:error] [pid 1025331:tid 1025571] [client 77.110.127.138:57769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZjEOu5aQNSViFaxNRnwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:20.691307 2026] [security2:error] [pid 1025331:tid 1025571] [client 77.110.127.138:57769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZjEOu5aQNSViFaxNRnwAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:20.793229 2026] [security2:error] [pid 1025331:tid 1025477] [client 161.118.218.103:50013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZjEOu5aQNSViFaxNRqQAAARo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:20.846633 2026] [security2:error] [pid 1025331:tid 1025444] [remote 217.61.143.92:37080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4ZjEOu5aQNSViFaxNRqwABVHA"], referer: https://guidehunting.com/wp-login.php
[Mon Jul 20 06:50:20.893084 2026] [security2:error] [pid 1025331:tid 1025413] [remote 103.28.36.106:37254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZjEOu5aQNSViFaxNRrQABe1E"]
[Mon Jul 20 06:50:20.893331 2026] [security2:error] [pid 1025331:tid 1025574] [client 103.28.36.106:37254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZjEOu5aQNSViFaxNRrQABe1E"]
[Mon Jul 20 06:50:20.929070 2026] [security2:error] [pid 1025331:tid 1025464] [client 197.186.66.42:59459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZjEOu5aQNSViFaxNRrwAAAQ0"]
[Mon Jul 20 06:50:20.929722 2026] [security2:error] [pid 1025331:tid 1025464] [client 197.186.66.42:59459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZjEOu5aQNSViFaxNRrwAAAQ0"]
[Mon Jul 20 06:50:20.937805 2026] [security2:error] [pid 1025331:tid 1025519] [client 57.141.18.122:43952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZiEOu5aQNSViFaxNQ0gABRH8"]
[Mon Jul 20 06:50:21.178141 2026] [security2:error] [pid 1025331:tid 1025568] [client 34.73.38.214:54637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZjUOu5aQNSViFaxNRuAAAAXU"]
[Mon Jul 20 06:50:21.284730 2026] [security2:error] [pid 1020501:tid 1020520] [remote 5.161.225.162:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4ZjcS_oRsP4jdONhcEIAAABxA"]
[Mon Jul 20 06:50:21.367641 2026] [security2:error] [pid 1025331:tid 1025495] [client 161.118.218.103:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZjUOu5aQNSViFaxNRvwAAASw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:21.372888 2026] [security2:error] [pid 1025331:tid 1025490] [client 57.141.18.6:34896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZiUOu5aQNSViFaxNQ6wABJ2Y"]
[Mon Jul 20 06:50:21.458449 2026] [security2:error] [pid 1025331:tid 1025500] [client 34.73.38.214:52388] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.puk.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZjUOu5aQNSViFaxNRyAAAATE"]
[Mon Jul 20 06:50:21.500969 2026] [security2:error] [pid 1020501:tid 1020528] [remote 5.161.225.162:52258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4ZjcS_oRsP4jdONhcEJAAALRg"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:50:21.532015 2026] [security2:error] [pid 1025331:tid 1025347] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZjUOu5aQNSViFaxNRywABLg8"]
[Mon Jul 20 06:50:21.532210 2026] [security2:error] [pid 1025331:tid 1025497] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZjUOu5aQNSViFaxNRywABLg8"]
[Mon Jul 20 06:50:21.600788 2026] [security2:error] [pid 1025331:tid 1025361] [remote 5.161.225.162:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4ZjUOu5aQNSViFaxNR0wABEx0"]
[Mon Jul 20 06:50:21.696334 2026] [security2:error] [pid 1025331:tid 1025518] [client 14.225.17.146:58845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4ZjUOu5aQNSViFaxNR1AAAAUM"], referer: http://momheadquarters.com/NEW
[Mon Jul 20 06:50:21.807990 2026] [security2:error] [pid 1025331:tid 1025446] [remote 5.161.225.162:34966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4ZjUOu5aQNSViFaxNR3gABZHI"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 06:50:21.828540 2026] [security2:error] [pid 1025331:tid 1025578] [client 57.141.18.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4ZjUOu5aQNSViFaxNRxAAAAX8"]
[Mon Jul 20 06:50:21.874094 2026] [core:error] [pid 1025331:tid 1025577] [client 103.153.183.69:10586] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e%u002e%u002f%u002e%u002e%u002f.env?_=743y1x1s&v=invsp), referer: https://www.google.com/search?q=y4f9h1
[Mon Jul 20 06:50:21.952333 2026] [security2:error] [pid 1025331:tid 1025468] [client 161.118.218.103:50861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZjUOu5aQNSViFaxNSCwAAARE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:22.206493 2026] [security2:error] [pid 1025331:tid 1025579] [client 180.93.249.92:63942] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "50.116.64.31"] [uri "/.env"] [unique_id "al4ZjkOu5aQNSViFaxNSGwAAAYA"]
[Mon Jul 20 06:50:22.295590 2026] [security2:error] [pid 1025331:tid 1025516] [client 98.159.234.160:60695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZjkOu5aQNSViFaxNSIQAAAUE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:50:22.333827 2026] [security2:error] [pid 1025331:tid 1025584] [client 65.1.132.125:29378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4ZjkOu5aQNSViFaxNSIwAAAYU"]
[Mon Jul 20 06:50:22.418716 2026] [security2:error] [pid 1025331:tid 1025470] [client 162.219.176.3:53088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ZjkOu5aQNSViFaxNSKQAAARM"]
[Mon Jul 20 06:50:22.418813 2026] [security2:error] [pid 1025331:tid 1025470] [client 162.219.176.3:53088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ZjkOu5aQNSViFaxNSKQAAARM"]
[Mon Jul 20 06:50:22.467850 2026] [security2:error] [pid 1025331:tid 1025525] [client 57.141.18.41:32628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZikOu5aQNSViFaxNRIQABSmU"]
[Mon Jul 20 06:50:22.527096 2026] [security2:error] [pid 1025331:tid 1025562] [client 161.118.218.103:51295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZjkOu5aQNSViFaxNSLAAAAW8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:22.660248 2026] [security2:error] [pid 1020501:tid 1020742] [client 77.110.127.138:57787] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet/page/20'XOR(2*if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4ZjsS_oRsP4jdONhcEVgAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:22.725655 2026] [security2:error] [pid 1025331:tid 1025493] [client 180.93.249.92:64001] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "50.116.64.31"] [uri "/"] [unique_id "al4ZjkOu5aQNSViFaxNSNwAAASo"]
[Mon Jul 20 06:50:22.868470 2026] [proxy:error] [pid 1025331:tid 1025539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:22.868534 2026] [proxy_http:error] [pid 1025331:tid 1025539] [client 104.236.45.9:40814] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:22.869198 2026] [proxy:error] [pid 1025331:tid 1025539] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:22.869226 2026] [proxy_http:error] [pid 1025331:tid 1025539] [client 104.236.45.9:40814] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:23.000484 2026] [proxy:error] [pid 1025331:tid 1025537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:23.000572 2026] [proxy_http:error] [pid 1025331:tid 1025537] [client 104.236.45.9:40826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.almaz-aura.com/
[Mon Jul 20 06:50:23.001107 2026] [proxy:error] [pid 1025331:tid 1025537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:23.001149 2026] [proxy_http:error] [pid 1025331:tid 1025537] [client 104.236.45.9:40826] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.almaz-aura.com/
[Mon Jul 20 06:50:23.102573 2026] [security2:error] [pid 1025331:tid 1025523] [client 161.118.218.103:51734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zj0Ou5aQNSViFaxNSWwAAAUg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:23.237803 2026] [security2:error] [pid 1025331:tid 1025533] [client 57.141.18.48:52934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZikOu5aQNSViFaxNROgABUms"]
[Mon Jul 20 06:50:23.261678 2026] [security2:error] [pid 1025331:tid 1025526] [client 65.1.132.125:29388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4Zj0Ou5aQNSViFaxNSZAAAAUs"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 06:50:23.291591 2026] [security2:error] [pid 1020501:tid 1020555] [remote 8.217.108.67:7904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4Zj8S_oRsP4jdONhcEcgAANjM"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:50:23.303069 2026] [core:error] [pid 1025331:tid 1025585] [client 104.236.45.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:23.303096 2026] [core:error] [pid 1025331:tid 1025585] [client 104.236.45.9:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:23.324620 2026] [security2:error] [pid 1025331:tid 1025463] [client 57.141.18.10:28816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zi0Ou5aQNSViFaxNRQQABDFI"]
[Mon Jul 20 06:50:23.585961 2026] [security2:error] [pid 1020501:tid 1020666] [client 180.93.249.92:64057] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "50.116.64.31"] [uri "/.env"] [unique_id "al4Zj8S_oRsP4jdONhcEfAAAACE"]
[Mon Jul 20 06:50:23.668692 2026] [security2:error] [pid 1020501:tid 1020517] [remote 57.141.18.49:32024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4718904"] [unique_id "al4Zj8S_oRsP4jdONhcEfwAAEQ0"]
[Mon Jul 20 06:50:23.679704 2026] [security2:error] [pid 1020501:tid 1020744] [client 161.118.218.103:52168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zj8S_oRsP4jdONhcEgQAAAG8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:23.721107 2026] [security2:error] [pid 1020501:tid 1020633] [client 104.207.40.137:20587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Zj8S_oRsP4jdONhcEggAAAAA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:23.789624 2026] [core:error] [pid 1020501:tid 1020711] [client 50.62.183.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:23.789671 2026] [core:error] [pid 1020501:tid 1020711] [client 50.62.183.88:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:50:23.957001 2026] [security2:error] [pid 1025331:tid 1025475] [client 57.141.18.18:35124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zi0Ou5aQNSViFaxNRbQABGBA"]
[Mon Jul 20 06:50:24.042895 2026] [security2:error] [pid 1020501:tid 1020669] [client 57.141.18.29:49856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zi8S_oRsP4jdONhcD2wAAJCE"]
[Mon Jul 20 06:50:24.230497 2026] [security2:error] [pid 1025331:tid 1025343] [remote 100.42.189.89:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ZkEOu5aQNSViFaxNSigABiQs"]
[Mon Jul 20 06:50:24.255171 2026] [security2:error] [pid 1020501:tid 1020641] [client 161.118.218.103:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZkMS_oRsP4jdONhcEmgAAAAg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:24.359568 2026] [security2:error] [pid 1025331:tid 1025539] [client 152.58.191.29:58562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkEOu5aQNSViFaxNSkQAAAVg"]
[Mon Jul 20 06:50:24.367256 2026] [security2:error] [pid 1025331:tid 1025539] [client 152.58.191.29:58562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkEOu5aQNSViFaxNSkQAAAVg"]
[Mon Jul 20 06:50:24.441243 2026] [security2:error] [pid 1025331:tid 1025358] [remote 100.42.189.89:52362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ZkEOu5aQNSViFaxNSlQABKho"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:50:24.512463 2026] [security2:error] [pid 1025331:tid 1025466] [client 45.3.32.133:26961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.32.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZkEOu5aQNSViFaxNSlgAAAQ8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:24.568234 2026] [security2:error] [pid 1020501:tid 1020709] [client 180.93.249.92:64181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "50.116.64.31"] [uri "/"] [unique_id "al4ZkMS_oRsP4jdONhcEqwAAAEw"]
[Mon Jul 20 06:50:24.827958 2026] [security2:error] [pid 1025331:tid 1025489] [client 161.118.218.103:52955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZkEOu5aQNSViFaxNSowAAASY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:25.085689 2026] [security2:error] [pid 1020501:tid 1020696] [client 57.141.18.49:56514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZjMS_oRsP4jdONhcEEgAAPww"]
[Mon Jul 20 06:50:25.090376 2026] [core:error] [pid 1025331:tid 1025587] [client 103.153.183.69:10602] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e%u002e%u002f%u002e%u002e%u002fetc%u002fpasswd?_=9sge2rp8&v=tfpq6), referer: https://www.google.com/search?q=yr7t6p
[Mon Jul 20 06:50:25.092268 2026] [security2:error] [pid 1025331:tid 1025573] [client 127.0.0.1:15830] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZkUOu5aQNSViFaxNSswAAAXo"], referer: https://www.google.com/search?q=yr7t6p
[Mon Jul 20 06:50:25.102524 2026] [security2:error] [pid 1025331:tid 1025545] [client 157.85.211.87:10556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkUOu5aQNSViFaxNStwAAAV4"]
[Mon Jul 20 06:50:25.102652 2026] [security2:error] [pid 1025331:tid 1025545] [client 157.85.211.87:10556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkUOu5aQNSViFaxNStwAAAV4"]
[Mon Jul 20 06:50:25.236351 2026] [security2:error] [pid 1025331:tid 1025554] [client 37.52.210.45:33567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZkUOu5aQNSViFaxNSyAAAAWc"]
[Mon Jul 20 06:50:25.236462 2026] [security2:error] [pid 1025331:tid 1025554] [client 37.52.210.45:33567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZkUOu5aQNSViFaxNSyAAAAWc"]
[Mon Jul 20 06:50:25.357701 2026] [security2:error] [pid 1020501:tid 1020694] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4ZkcS_oRsP4jdONhcEuwAAAD0"]
[Mon Jul 20 06:50:25.395852 2026] [security2:error] [pid 1025331:tid 1025431] [remote 47.86.33.52:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZkUOu5aQNSViFaxNSygABIWM"]
[Mon Jul 20 06:50:25.410899 2026] [security2:error] [pid 1025331:tid 1025582] [client 161.118.218.103:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZkUOu5aQNSViFaxNSzQAAAYM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:25.447627 2026] [security2:error] [pid 1020501:tid 1020760] [client 106.219.188.178:59922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkcS_oRsP4jdONhcExAAAAH8"]
[Mon Jul 20 06:50:25.447718 2026] [security2:error] [pid 1020501:tid 1020760] [client 106.219.188.178:59922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkcS_oRsP4jdONhcExAAAAH8"]
[Mon Jul 20 06:50:25.456530 2026] [security2:error] [pid 1020501:tid 1020661] [client 223.185.13.213:13401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkcS_oRsP4jdONhcExQAAABw"]
[Mon Jul 20 06:50:25.456720 2026] [security2:error] [pid 1020501:tid 1020661] [client 223.185.13.213:13401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkcS_oRsP4jdONhcExQAAABw"]
[Mon Jul 20 06:50:25.528117 2026] [security2:error] [pid 1020501:tid 1020572] [remote 139.135.131.153:42128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZjcS_oRsP4jdONhcEHQAAFkQ"], referer: https://toddnielsen.com
[Mon Jul 20 06:50:25.863402 2026] [security2:error] [pid 1025331:tid 1025490] [client 104.207.56.117:55553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZkUOu5aQNSViFaxNS7AAAASc"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:25.945861 2026] [security2:error] [pid 1025331:tid 1025487] [client 14.225.17.146:65246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4ZkEOu5aQNSViFaxNSlwAAASQ"], referer: http://samdothan.org/NEW
[Mon Jul 20 06:50:25.985627 2026] [security2:error] [pid 1025331:tid 1025462] [client 161.118.218.103:53697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZkUOu5aQNSViFaxNS9QAAAQs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:25.989805 2026] [security2:error] [pid 1025331:tid 1025534] [client 14.182.195.220:52377] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZkUOu5aQNSViFaxNS9gAAAVM"]
[Mon Jul 20 06:50:26.005395 2026] [security2:error] [pid 1025331:tid 1025580] [client 14.182.195.220:52379] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZkkOu5aQNSViFaxNS9wAAAYE"]
[Mon Jul 20 06:50:26.011631 2026] [security2:error] [pid 1025331:tid 1025469] [client 14.182.195.220:52378] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZkkOu5aQNSViFaxNS-AAAARI"]
[Mon Jul 20 06:50:26.076560 2026] [security2:error] [pid 1020501:tid 1020693] [client 14.251.3.155:54736] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZksS_oRsP4jdONhcE3gAAADw"]
[Mon Jul 20 06:50:26.106356 2026] [security2:error] [pid 1025331:tid 1025515] [client 57.141.18.98:57216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZjUOu5aQNSViFaxNR2QABQCs"]
[Mon Jul 20 06:50:26.147160 2026] [security2:error] [pid 1025331:tid 1025529] [client 183.82.98.154:61408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkkOu5aQNSViFaxNS_wAAAU4"]
[Mon Jul 20 06:50:26.147287 2026] [security2:error] [pid 1025331:tid 1025529] [client 183.82.98.154:61408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZkkOu5aQNSViFaxNS_wAAAU4"]
[Mon Jul 20 06:50:26.318518 2026] [security2:error] [pid 1025331:tid 1025473] [client 52.187.75.220:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ZkkOu5aQNSViFaxNTBwAAARY"]
[Mon Jul 20 06:50:26.386483 2026] [security2:error] [pid 1020501:tid 1020662] [client 77.110.127.138:57813] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZksS_oRsP4jdONhcE5QAAAB0"]
[Mon Jul 20 06:50:26.507423 2026] [security2:error] [pid 1025331:tid 1025561] [client 52.187.75.220:8962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ZkkOu5aQNSViFaxNTDQAAAW4"]
[Mon Jul 20 06:50:26.560449 2026] [security2:error] [pid 1020501:tid 1020714] [client 161.118.218.103:54050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZksS_oRsP4jdONhcE7QAAAFE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:26.832352 2026] [security2:error] [pid 1020501:tid 1020616] [remote 217.61.143.92:51958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZksS_oRsP4jdONhcE_wAAMXA"]
[Mon Jul 20 06:50:26.919406 2026] [security2:error] [pid 1025331:tid 1025578] [client 57.141.18.20:26350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZjkOu5aQNSViFaxNSLgABfwI"]
[Mon Jul 20 06:50:27.041263 2026] [security2:error] [pid 1025331:tid 1025446] [remote 47.86.33.52:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTKwABDHI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:50:27.080626 2026] [security2:error] [pid 1020501:tid 1020612] [remote 217.61.143.92:51958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4Zk8S_oRsP4jdONhcFDgAAdmw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:50:27.137229 2026] [security2:error] [pid 1020501:tid 1020690] [client 161.118.218.103:54403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zk8S_oRsP4jdONhcFFgAAADk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:27.304311 2026] [security2:error] [pid 1025331:tid 1025542] [client 195.63.31.97:12177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTLgAAAVs"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:27.463057 2026] [security2:error] [pid 1020501:tid 1020705] [client 77.110.127.138:57820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zk8S_oRsP4jdONhcFIAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:27.463182 2026] [security2:error] [pid 1020501:tid 1020705] [client 77.110.127.138:57820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zk8S_oRsP4jdONhcFIAAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:27.473205 2026] [security2:error] [pid 1025331:tid 1025500] [client 41.249.121.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ZkkOu5aQNSViFaxNTJwAAATE"]
[Mon Jul 20 06:50:27.618217 2026] [security2:error] [pid 1025331:tid 1025508] [client 77.110.127.138:57821] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/crochet/page/20\\"XOR(2*if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4Zk0Ou5aQNSViFaxNTQQAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:27.635028 2026] [security2:error] [pid 1025331:tid 1025512] [client 14.225.17.146:56312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4ZkkOu5aQNSViFaxNS_QAAAT0"], referer: http://olearyplumbingllc.com/NEW
[Mon Jul 20 06:50:27.642988 2026] [security2:error] [pid 1025331:tid 1025474] [client 24.33.149.13:36824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zj0Ou5aQNSViFaxNSbAABFwk"], referer: https://toddnielsen.com
[Mon Jul 20 06:50:27.699432 2026] [security2:error] [pid 1025331:tid 1025484] [client 39.48.81.23:58392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTRgAAASE"]
[Mon Jul 20 06:50:27.699597 2026] [security2:error] [pid 1025331:tid 1025484] [client 39.48.81.23:58392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTRgAAASE"]
[Mon Jul 20 06:50:27.705426 2026] [security2:error] [pid 1025331:tid 1025535] [client 50.116.65.227:19210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTRwAAAVQ"]
[Mon Jul 20 06:50:27.708546 2026] [security2:error] [pid 1020501:tid 1020722] [client 14.225.17.146:58107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4ZksS_oRsP4jdONhcE_gAAAFk"]
[Mon Jul 20 06:50:27.711271 2026] [security2:error] [pid 1025331:tid 1025569] [client 161.118.218.103:54774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTSAAAAXY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:27.780557 2026] [security2:error] [pid 1025331:tid 1025513] [client 14.225.17.146:59889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTMgAAAT4"], referer: http://massagelacey.com/NEW
[Mon Jul 20 06:50:27.801370 2026] [security2:error] [pid 1025331:tid 1025577] [client 192.140.149.97:45011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTTgAAAX4"]
[Mon Jul 20 06:50:27.801480 2026] [security2:error] [pid 1025331:tid 1025577] [client 192.140.149.97:45011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Zk0Ou5aQNSViFaxNTTgAAAX4"]
[Mon Jul 20 06:50:27.918988 2026] [security2:error] [pid 1020501:tid 1020707] [client 57.141.18.37:38740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zj8S_oRsP4jdONhcEfQAASkE"]
[Mon Jul 20 06:50:27.995431 2026] [security2:error] [pid 1025331:tid 1025507] [client 57.141.18.119:31822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zj0Ou5aQNSViFaxNSdQABOC4"]
[Mon Jul 20 06:50:28.030974 2026] [security2:error] [pid 1025331:tid 1025516] [client 117.247.108.24:17332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTUQAAAUE"]
[Mon Jul 20 06:50:28.031088 2026] [security2:error] [pid 1025331:tid 1025516] [client 117.247.108.24:17332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTUQAAAUE"]
[Mon Jul 20 06:50:28.166789 2026] [security2:error] [pid 1025331:tid 1025477] [client 36.95.228.227:60231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTXwAAARo"]
[Mon Jul 20 06:50:28.166896 2026] [security2:error] [pid 1025331:tid 1025477] [client 36.95.228.227:60231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTXwAAARo"]
[Mon Jul 20 06:50:28.283435 2026] [security2:error] [pid 1025331:tid 1025466] [client 161.118.218.103:55089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZlEOu5aQNSViFaxNTYwAAAQ8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:28.396987 2026] [security2:error] [pid 1020501:tid 1020734] [client 57.141.18.15:38468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZkMS_oRsP4jdONhcElQAAZSA"]
[Mon Jul 20 06:50:28.413923 2026] [security2:error] [pid 1025331:tid 1025409] [remote 193.70.112.205:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZlEOu5aQNSViFaxNTagABak0"]
[Mon Jul 20 06:50:28.443381 2026] [security2:error] [pid 1025331:tid 1025534] [client 217.142.18.172:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTbAAAAVM"]
[Mon Jul 20 06:50:28.447286 2026] [security2:error] [pid 1025331:tid 1025534] [client 217.142.18.172:64835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTbAAAAVM"]
[Mon Jul 20 06:50:28.479451 2026] [security2:error] [pid 1020501:tid 1020702] [client 103.125.179.95:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlMS_oRsP4jdONhcFQQAAAEU"]
[Mon Jul 20 06:50:28.485204 2026] [security2:error] [pid 1020501:tid 1020702] [client 103.125.179.95:52027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlMS_oRsP4jdONhcFQQAAAEU"]
[Mon Jul 20 06:50:28.523107 2026] [security2:error] [pid 1020501:tid 1020709] [client 103.238.106.162:42877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZlMS_oRsP4jdONhcFRQAAAEw"]
[Mon Jul 20 06:50:28.523206 2026] [security2:error] [pid 1020501:tid 1020709] [client 103.238.106.162:42877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZlMS_oRsP4jdONhcFRQAAAEw"]
[Mon Jul 20 06:50:28.620499 2026] [security2:error] [pid 1025331:tid 1025451] [remote 193.70.112.205:60216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZlEOu5aQNSViFaxNTewABdnc"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:50:28.777078 2026] [security2:error] [pid 1025331:tid 1025476] [client 122.183.32.225:10853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTggAAARk"]
[Mon Jul 20 06:50:28.777176 2026] [security2:error] [pid 1025331:tid 1025476] [client 122.183.32.225:10853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZlEOu5aQNSViFaxNTggAAARk"]
[Mon Jul 20 06:50:28.857195 2026] [security2:error] [pid 1020501:tid 1020671] [client 161.118.218.103:55393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZlMS_oRsP4jdONhcFVAAAACY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:29.068341 2026] [security2:error] [pid 1020501:tid 1020732] [client 57.141.18.38:33954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZkMS_oRsP4jdONhcEsQAAY0c"]
[Mon Jul 20 06:50:29.440908 2026] [security2:error] [pid 1020501:tid 1020687] [client 161.118.218.103:55704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZlcS_oRsP4jdONhcFbwAAADY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:29.883918 2026] [security2:error] [pid 1025331:tid 1025495] [client 2a03:2880:11ff:48:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4ZlUOu5aQNSViFaxNTkAABLF0"]
[Mon Jul 20 06:50:29.974955 2026] [security2:error] [pid 1025331:tid 1025540] [client 57.141.18.116:50468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZkUOu5aQNSViFaxNS3QABWRw"]
[Mon Jul 20 06:50:30.022604 2026] [security2:error] [pid 1025331:tid 1025487] [client 161.118.218.103:56016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZlkOu5aQNSViFaxNTpgAAASQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:30.035932 2026] [security2:error] [pid 1020501:tid 1020652] [client 14.225.17.146:61527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4ZlMS_oRsP4jdONhcFUwAAABM"], referer: http://collectingrealestate.com/NEW
[Mon Jul 20 06:50:30.225058 2026] [security2:error] [pid 1025331:tid 1025494] [client 57.141.18.89:32504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZkUOu5aQNSViFaxNS7wABK38"]
[Mon Jul 20 06:50:30.328833 2026] [security2:error] [pid 1025331:tid 1025573] [client 50.116.65.227:56644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZlkOu5aQNSViFaxNTtgAAAXo"]
[Mon Jul 20 06:50:30.338897 2026] [security2:error] [pid 1025331:tid 1025529] [client 50.116.65.227:56648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZlkOu5aQNSViFaxNTuAAAAU4"]
[Mon Jul 20 06:50:30.598977 2026] [security2:error] [pid 1025331:tid 1025503] [client 161.118.218.103:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZlkOu5aQNSViFaxNTwQAAATQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:30.802259 2026] [security2:error] [pid 1020501:tid 1020643] [client 14.225.17.146:53405] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4ZlcS_oRsP4jdONhcFbAAAAAo"], referer: http://headachescarpaltunnelfibromyalgia.com/NEW
[Mon Jul 20 06:50:30.823217 2026] [security2:error] [pid 1025331:tid 1025564] [client 74.208.214.194:37316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ZlkOu5aQNSViFaxNTzQAAAXE"]
[Mon Jul 20 06:50:30.985608 2026] [security2:error] [pid 1025331:tid 1025561] [client 104.234.53.52:33749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZlkOu5aQNSViFaxNT1AAAAW4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:31.006880 2026] [security2:error] [pid 1020501:tid 1020677] [client 187.108.85.186:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zl8S_oRsP4jdONhcFnAAAACw"]
[Mon Jul 20 06:50:31.007039 2026] [security2:error] [pid 1020501:tid 1020677] [client 187.108.85.186:54846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zl8S_oRsP4jdONhcFnAAAACw"]
[Mon Jul 20 06:50:31.037382 2026] [security2:error] [pid 1025331:tid 1025547] [client 14.225.17.146:59982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4ZlkOu5aQNSViFaxNT0QAAAWA"], referer: http://windowtx.com/NEW
[Mon Jul 20 06:50:31.162863 2026] [security2:error] [pid 1025331:tid 1025462] [client 57.141.18.68:28764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZkkOu5aQNSViFaxNTHAABCw8"]
[Mon Jul 20 06:50:31.182585 2026] [security2:error] [pid 1025331:tid 1025513] [client 161.118.218.103:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zl0Ou5aQNSViFaxNT3wAAAT4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:31.762453 2026] [security2:error] [pid 1025331:tid 1025535] [client 161.118.218.103:57033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zl0Ou5aQNSViFaxNT-QAAAVQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:31.968989 2026] [security2:error] [pid 1025331:tid 1025579] [client 77.110.127.138:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zl0Ou5aQNSViFaxNT_gAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:31.969095 2026] [security2:error] [pid 1025331:tid 1025579] [client 77.110.127.138:57850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zl0Ou5aQNSViFaxNT_gAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:32.056559 2026] [security2:error] [pid 1025331:tid 1025448] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZmEOu5aQNSViFaxNUCgABXnQ"]
[Mon Jul 20 06:50:32.056772 2026] [security2:error] [pid 1025331:tid 1025545] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZmEOu5aQNSViFaxNUCgABXnQ"]
[Mon Jul 20 06:50:32.340265 2026] [security2:error] [pid 1025331:tid 1025493] [client 161.118.218.103:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZmEOu5aQNSViFaxNUFgAAASo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:32.362813 2026] [security2:error] [pid 1025331:tid 1025503] [client 74.7.227.179:32966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ZmEOu5aQNSViFaxNUEgABNCM"], referer: https://tejasenvironmental.com/p=821518
[Mon Jul 20 06:50:32.602027 2026] [security2:error] [pid 1025331:tid 1025516] [client 14.225.17.146:50628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4ZmEOu5aQNSViFaxNUHwAAAUE"], referer: http://katsklar.com/NEW
[Mon Jul 20 06:50:32.633800 2026] [security2:error] [pid 1025331:tid 1025473] [client 57.141.18.7:27512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZlEOu5aQNSViFaxNTXgABFlo"]
[Mon Jul 20 06:50:32.916736 2026] [security2:error] [pid 1025331:tid 1025483] [client 161.118.218.103:57740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZmEOu5aQNSViFaxNUMwAAASA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:33.044258 2026] [security2:error] [pid 1020501:tid 1020732] [client 197.186.66.42:59980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZmcS_oRsP4jdONhcF3wAAAGM"]
[Mon Jul 20 06:50:33.044803 2026] [security2:error] [pid 1020501:tid 1020732] [client 197.186.66.42:59980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZmcS_oRsP4jdONhcF3wAAAGM"]
[Mon Jul 20 06:50:33.173515 2026] [security2:error] [pid 1025331:tid 1025421] [remote 68.178.160.25:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4ZmUOu5aQNSViFaxNUPQABTlk"]
[Mon Jul 20 06:50:33.257434 2026] [security2:error] [pid 1025331:tid 1025562] [client 77.110.127.138:57857] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZmUOu5aQNSViFaxNUPgAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:33.456672 2026] [security2:error] [pid 1020501:tid 1020745] [client 114.119.140.113:52703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "worbals.com"] [uri "/how-to-select-the-best-legal-transcriptionist/"] [unique_id "al4ZmcS_oRsP4jdONhcF8gAAAHA"], referer: https://worbals.com/how-to-make-your-website-a-conversion-machine-with-copywriting/
[Mon Jul 20 06:50:33.500485 2026] [security2:error] [pid 1020501:tid 1020647] [client 161.118.218.103:58111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZmcS_oRsP4jdONhcF9AAAAA4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:33.553874 2026] [security2:error] [pid 1025331:tid 1025364] [remote 68.178.160.25:49068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4ZmUOu5aQNSViFaxNURwABNiA"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 06:50:33.744568 2026] [security2:error] [pid 1020501:tid 1020685] [client 104.234.53.72:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ZmcS_oRsP4jdONhcF_gAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:33.935719 2026] [security2:error] [pid 1025331:tid 1025519] [client 57.141.18.113:43060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZlUOu5aQNSViFaxNTjgABRAQ"]
[Mon Jul 20 06:50:33.983617 2026] [security2:error] [pid 1020501:tid 1020571] [remote 124.55.178.99:44424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZmcS_oRsP4jdONhcGEQAAUEM"]
[Mon Jul 20 06:50:34.087325 2026] [security2:error] [pid 1020501:tid 1020720] [client 161.118.218.103:58460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZmsS_oRsP4jdONhcGFgAAAFc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:34.423623 2026] [security2:error] [pid 1020501:tid 1020697] [client 14.182.195.220:52381] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZmsS_oRsP4jdONhcGJAAAAEA"]
[Mon Jul 20 06:50:34.435974 2026] [security2:error] [pid 1020501:tid 1020606] [remote 124.55.178.99:44424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZmsS_oRsP4jdONhcGJgAAbGY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:50:34.468290 2026] [security2:error] [pid 1020501:tid 1020735] [client 14.182.195.220:52383] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZmsS_oRsP4jdONhcGKAAAAGY"]
[Mon Jul 20 06:50:34.469298 2026] [security2:error] [pid 1020501:tid 1020650] [client 14.182.195.220:52382] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZmsS_oRsP4jdONhcGKQAAABE"]
[Mon Jul 20 06:50:34.469993 2026] [security2:error] [pid 1025331:tid 1025481] [client 57.141.18.21:28438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZlUOu5aQNSViFaxNToAABHng"]
[Mon Jul 20 06:50:34.588956 2026] [security2:error] [pid 1025331:tid 1025577] [client 57.141.18.87:36168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZlkOu5aQNSViFaxNTrAABfk4"]
[Mon Jul 20 06:50:34.603704 2026] [security2:error] [pid 1025331:tid 1025533] [client 63.176.132.15:27722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZmkOu5aQNSViFaxNUZAAAAVI"]
[Mon Jul 20 06:50:34.669438 2026] [security2:error] [pid 1020501:tid 1020745] [client 161.118.218.103:58809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZmsS_oRsP4jdONhcGMAAAAHA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:34.922383 2026] [security2:error] [pid 1020501:tid 1020758] [client 14.225.17.146:53872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4ZmcS_oRsP4jdONhcF9wAAAH0"], referer: http://hammadownenterprises.com/NEW
[Mon Jul 20 06:50:35.006241 2026] [security2:error] [pid 1020501:tid 1020696] [client 152.58.191.29:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Zm8S_oRsP4jdONhcGPgAAAD8"]
[Mon Jul 20 06:50:35.006363 2026] [security2:error] [pid 1020501:tid 1020696] [client 152.58.191.29:59019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Zm8S_oRsP4jdONhcGPgAAAD8"]
[Mon Jul 20 06:50:35.187478 2026] [security2:error] [pid 1020501:tid 1020640] [client 63.176.132.15:27738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Zm8S_oRsP4jdONhcGRQAAAAc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:50:35.234811 2026] [security2:error] [pid 1025331:tid 1025568] [client 104.234.53.61:35167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Zm0Ou5aQNSViFaxNUdwAAAXU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:35.247972 2026] [security2:error] [pid 1025331:tid 1025487] [client 161.118.218.103:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zm0Ou5aQNSViFaxNUggAAASQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:35.457540 2026] [security2:error] [pid 1025331:tid 1025579] [client 104.234.53.61:35167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Zm0Ou5aQNSViFaxNUiwAAAYA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:35.808766 2026] [security2:error] [pid 1025331:tid 1025463] [client 74.208.214.194:42908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Zm0Ou5aQNSViFaxNUrgAAAQw"]
[Mon Jul 20 06:50:35.822091 2026] [security2:error] [pid 1020501:tid 1020668] [client 161.118.218.103:59445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zm8S_oRsP4jdONhcGcgAAACM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:35.891680 2026] [proxy:error] [pid 1025331:tid 1025496] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:35.891767 2026] [proxy_http:error] [pid 1025331:tid 1025496] [client 34.73.38.214:53721] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:35.892219 2026] [proxy:error] [pid 1025331:tid 1025496] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:35.892257 2026] [proxy_http:error] [pid 1025331:tid 1025496] [client 34.73.38.214:53721] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:35.905313 2026] [security2:error] [pid 1020501:tid 1020733] [client 37.52.210.45:36153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Zm8S_oRsP4jdONhcGeAAAAGQ"]
[Mon Jul 20 06:50:35.905415 2026] [security2:error] [pid 1020501:tid 1020733] [client 37.52.210.45:36153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Zm8S_oRsP4jdONhcGeAAAAGQ"]
[Mon Jul 20 06:50:35.935083 2026] [security2:error] [pid 1025331:tid 1025575] [client 57.141.18.14:22860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zl0Ou5aQNSViFaxNT9QABfGk"]
[Mon Jul 20 06:50:36.161968 2026] [security2:error] [pid 1025331:tid 1025493] [client 77.110.127.138:57870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZnEOu5aQNSViFaxNUvgAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:36.162102 2026] [security2:error] [pid 1025331:tid 1025493] [client 77.110.127.138:57870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZnEOu5aQNSViFaxNUvgAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:36.301371 2026] [proxy:error] [pid 1025331:tid 1025482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:36.301455 2026] [proxy_http:error] [pid 1025331:tid 1025482] [client 34.73.38.214:57655] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:36.302114 2026] [proxy:error] [pid 1025331:tid 1025482] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:36.302147 2026] [proxy_http:error] [pid 1025331:tid 1025482] [client 34.73.38.214:57655] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:36.347580 2026] [security2:error] [pid 1025331:tid 1025488] [client 57.141.18.47:42966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZmEOu5aQNSViFaxNUCAABJRY"]
[Mon Jul 20 06:50:36.391114 2026] [security2:error] [pid 1020501:tid 1020636] [client 106.219.188.178:29745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnMS_oRsP4jdONhcGiQAAAAM"]
[Mon Jul 20 06:50:36.395400 2026] [security2:error] [pid 1020501:tid 1020636] [client 106.219.188.178:29745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnMS_oRsP4jdONhcGiQAAAAM"]
[Mon Jul 20 06:50:36.398137 2026] [security2:error] [pid 1020501:tid 1020664] [client 161.118.218.103:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZnMS_oRsP4jdONhcGiwAAAB8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:36.586853 2026] [security2:error] [pid 1025331:tid 1025498] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZnEOu5aQNSViFaxNUxAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:36.678897 2026] [security2:error] [pid 1020501:tid 1020749] [client 57.141.18.19:21820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZmMS_oRsP4jdONhcFzQAAdGo"]
[Mon Jul 20 06:50:36.733444 2026] [security2:error] [pid 1025331:tid 1025400] [remote 176.56.118.182:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4ZnEOu5aQNSViFaxNUzwABLkQ"]
[Mon Jul 20 06:50:36.767722 2026] [proxy:error] [pid 1025331:tid 1025503] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:36.767803 2026] [proxy_http:error] [pid 1025331:tid 1025503] [client 34.73.38.214:51126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:36.768442 2026] [proxy:error] [pid 1025331:tid 1025503] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:36.768474 2026] [proxy_http:error] [pid 1025331:tid 1025503] [client 34.73.38.214:51126] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:36.874811 2026] [security2:error] [pid 1025331:tid 1025548] [client 223.185.13.213:16406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnEOu5aQNSViFaxNU1wAAAWE"]
[Mon Jul 20 06:50:36.875091 2026] [security2:error] [pid 1025331:tid 1025548] [client 223.185.13.213:16406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnEOu5aQNSViFaxNU1wAAAWE"]
[Mon Jul 20 06:50:36.910538 2026] [security2:error] [pid 1020501:tid 1020709] [client 14.225.17.146:59620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4Zm8S_oRsP4jdONhcGZAAAAEw"], referer: http://alaraycreative.com/NEW
[Mon Jul 20 06:50:36.962717 2026] [security2:error] [pid 1025331:tid 1025428] [remote 176.56.118.182:40800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4ZnEOu5aQNSViFaxNU3AABPWA"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:50:36.984439 2026] [security2:error] [pid 1025331:tid 1025553] [client 161.118.218.103:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZnEOu5aQNSViFaxNU4AAAAWY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:37.122874 2026] [security2:error] [pid 1025331:tid 1025504] [client 104.234.53.52:45755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZnUOu5aQNSViFaxNU6wAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:37.163988 2026] [security2:error] [pid 1020501:tid 1020686] [client 34.221.219.204:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Zm8S_oRsP4jdONhcGbAAAADU"], referer: https://liquidationteam.com/
[Mon Jul 20 06:50:37.186251 2026] [proxy:error] [pid 1025331:tid 1025588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.186326 2026] [proxy_http:error] [pid 1025331:tid 1025588] [client 34.73.38.214:54921] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.187054 2026] [proxy:error] [pid 1025331:tid 1025588] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.187084 2026] [proxy_http:error] [pid 1025331:tid 1025588] [client 34.73.38.214:54921] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.268709 2026] [security2:error] [pid 1020501:tid 1020744] [client 183.82.98.154:62007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZncS_oRsP4jdONhcGpgAAAG8"]
[Mon Jul 20 06:50:37.268842 2026] [security2:error] [pid 1020501:tid 1020744] [client 183.82.98.154:62007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZncS_oRsP4jdONhcGpgAAAG8"]
[Mon Jul 20 06:50:37.355071 2026] [security2:error] [pid 1020501:tid 1020635] [client 14.225.17.146:64735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4Zm8S_oRsP4jdONhcGdwAAAAI"], referer: http://dadanetnet.net/NEW
[Mon Jul 20 06:50:37.396467 2026] [proxy:error] [pid 1020501:tid 1020682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.396558 2026] [proxy_http:error] [pid 1020501:tid 1020682] [client 94.154.43.183:39502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.397588 2026] [proxy:error] [pid 1020501:tid 1020682] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.397638 2026] [proxy_http:error] [pid 1020501:tid 1020682] [client 94.154.43.183:39502] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.435880 2026] [proxy:error] [pid 1025331:tid 1025587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.435934 2026] [proxy_http:error] [pid 1025331:tid 1025587] [client 94.154.43.178:28736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.436724 2026] [proxy:error] [pid 1025331:tid 1025587] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.436777 2026] [proxy_http:error] [pid 1025331:tid 1025587] [client 94.154.43.178:28736] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.438970 2026] [security2:error] [pid 1020501:tid 1020750] [client 57.141.18.24:63528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZmcS_oRsP4jdONhcF4gAAdQY"]
[Mon Jul 20 06:50:37.458644 2026] [security2:error] [pid 1025331:tid 1025552] [client 104.207.33.176:26111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZnUOu5aQNSViFaxNVAQAAAWU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:37.559338 2026] [security2:error] [pid 1020501:tid 1020734] [client 161.118.218.103:60521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZncS_oRsP4jdONhcGtgAAAGU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:37.586903 2026] [security2:error] [pid 1025331:tid 1025487] [client 157.85.211.87:29341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnUOu5aQNSViFaxNVCQAAASQ"]
[Mon Jul 20 06:50:37.586995 2026] [security2:error] [pid 1025331:tid 1025487] [client 157.85.211.87:29341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnUOu5aQNSViFaxNVCQAAASQ"]
[Mon Jul 20 06:50:37.615638 2026] [security2:error] [pid 1025331:tid 1025411] [remote 216.73.216.55:8968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4ZnUOu5aQNSViFaxNVCwABQU8"]
[Mon Jul 20 06:50:37.627495 2026] [security2:error] [pid 1020501:tid 1020726] [client 77.110.127.138:57877] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZncS_oRsP4jdONhcGugAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:37.804905 2026] [security2:error] [pid 1025331:tid 1025575] [client 13.232.231.177:63436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ZnUOu5aQNSViFaxNU5wAAAXw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:50:37.850832 2026] [proxy:error] [pid 1025331:tid 1025504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.850906 2026] [proxy_http:error] [pid 1025331:tid 1025504] [client 34.73.38.214:64092] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.851377 2026] [proxy:error] [pid 1025331:tid 1025504] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.851414 2026] [proxy_http:error] [pid 1025331:tid 1025504] [client 34.73.38.214:64092] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.857388 2026] [proxy:error] [pid 1025331:tid 1025583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.857479 2026] [proxy_http:error] [pid 1025331:tid 1025583] [client 34.73.38.214:64108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.858152 2026] [proxy:error] [pid 1025331:tid 1025583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:37.858182 2026] [proxy_http:error] [pid 1025331:tid 1025583] [client 34.73.38.214:64108] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:37.971825 2026] [security2:error] [pid 1025331:tid 1025409] [remote 182.77.62.24:45552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZnUOu5aQNSViFaxNVEQABGk0"]
[Mon Jul 20 06:50:38.079039 2026] [security2:error] [pid 1020501:tid 1020672] [client 57.141.18.41:47562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZmcS_oRsP4jdONhcGCAAAJ0E"]
[Mon Jul 20 06:50:38.138062 2026] [security2:error] [pid 1025331:tid 1025581] [client 161.118.218.103:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZnkOu5aQNSViFaxNVIgAAAYI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:38.344075 2026] [security2:error] [pid 1025331:tid 1025564] [client 34.73.38.214:52041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.representgrace.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnkOu5aQNSViFaxNVLAAAAXE"]
[Mon Jul 20 06:50:38.376550 2026] [security2:error] [pid 1020501:tid 1020735] [client 34.73.38.214:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.reosportsboats.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnsS_oRsP4jdONhcGzgAAAGY"]
[Mon Jul 20 06:50:38.443588 2026] [security2:error] [pid 1020501:tid 1020759] [client 57.141.18.79:62616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZmsS_oRsP4jdONhcGEwAAfhw"]
[Mon Jul 20 06:50:38.487022 2026] [security2:error] [pid 1025331:tid 1025383] [remote 182.77.62.24:45552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZnkOu5aQNSViFaxNVMgABNDM"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:50:38.583058 2026] [security2:error] [pid 1025331:tid 1025519] [client 34.73.38.214:54249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZnkOu5aQNSViFaxNVPgAAAUQ"]
[Mon Jul 20 06:50:38.645183 2026] [security2:error] [pid 1025331:tid 1025583] [client 34.139.11.221:56312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.peoplestrategies.us"] [uri "/xmlrpc.php"] [unique_id "al4ZnkOu5aQNSViFaxNVRgAAAYQ"]
[Mon Jul 20 06:50:38.672888 2026] [security2:error] [pid 1020501:tid 1020708] [client 36.95.228.227:60706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnsS_oRsP4jdONhcG3AAAAEs"]
[Mon Jul 20 06:50:38.673028 2026] [security2:error] [pid 1020501:tid 1020708] [client 36.95.228.227:60706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnsS_oRsP4jdONhcG3AAAAEs"]
[Mon Jul 20 06:50:38.717385 2026] [security2:error] [pid 1025331:tid 1025571] [client 161.118.218.103:61294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZnkOu5aQNSViFaxNVSgAAAXg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:38.759014 2026] [security2:error] [pid 1025331:tid 1025498] [client 34.139.11.221:50977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZnkOu5aQNSViFaxNVSwAAAS8"]
[Mon Jul 20 06:50:38.821818 2026] [security2:error] [pid 1020501:tid 1020682] [client 34.73.38.214:57507] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZnsS_oRsP4jdONhcG4gAAADE"]
[Mon Jul 20 06:50:38.868410 2026] [security2:error] [pid 1025331:tid 1025520] [client 117.247.108.24:18208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnkOu5aQNSViFaxNVTwAAAUU"]
[Mon Jul 20 06:50:38.868547 2026] [security2:error] [pid 1025331:tid 1025520] [client 117.247.108.24:18208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZnkOu5aQNSViFaxNVTwAAAUU"]
[Mon Jul 20 06:50:38.894013 2026] [security2:error] [pid 1025331:tid 1025486] [client 34.139.11.221:61557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZnkOu5aQNSViFaxNVUAAAASM"]
[Mon Jul 20 06:50:38.971817 2026] [core:error] [pid 1025331:tid 1025513] [client 103.153.183.69:34532] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e%u002e/%u002e%u002e/%u002e%u002e/etc/passwd?_=x0ql2its&v=91i9n), referer: https://twitter.com/
[Mon Jul 20 06:50:38.973480 2026] [security2:error] [pid 1025331:tid 1025511] [client 127.0.0.1:13814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini)\\\\b|\\\\/etc\\\\/|/\\\\.(?:history|bash_history|sh_history)$)" at REQUEST_HEADERS:X-Original-URL. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "218"] [id "390719"] [rev "6"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/etc/"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZnkOu5aQNSViFaxNVVwAAATw"], referer: https://twitter.com/
[Mon Jul 20 06:50:38.983193 2026] [security2:error] [pid 1025331:tid 1025515] [client 34.73.38.214:53100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZnkOu5aQNSViFaxNVWQAAAUA"]
[Mon Jul 20 06:50:39.010124 2026] [security2:error] [pid 1025331:tid 1025542] [client 217.142.18.172:30857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVWwAAAVs"]
[Mon Jul 20 06:50:39.010273 2026] [security2:error] [pid 1025331:tid 1025542] [client 217.142.18.172:30857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVWwAAAVs"]
[Mon Jul 20 06:50:39.014427 2026] [security2:error] [pid 1025331:tid 1025574] [client 34.73.38.214:61521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVXgAAAXs"]
[Mon Jul 20 06:50:39.029649 2026] [security2:error] [pid 1020501:tid 1020660] [client 34.139.11.221:49550] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn8S_oRsP4jdONhcG6wAAABs"]
[Mon Jul 20 06:50:39.133934 2026] [security2:error] [pid 1025331:tid 1025553] [client 34.139.11.221:50583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVagAAAWY"]
[Mon Jul 20 06:50:39.253508 2026] [security2:error] [pid 1025331:tid 1025558] [client 34.139.11.221:55780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVbQAAAWs"]
[Mon Jul 20 06:50:39.276399 2026] [security2:error] [pid 1025331:tid 1025501] [client 103.125.179.95:52531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVbwAAATI"]
[Mon Jul 20 06:50:39.276605 2026] [security2:error] [pid 1025331:tid 1025501] [client 103.125.179.95:52531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVbwAAATI"]
[Mon Jul 20 06:50:39.297070 2026] [security2:error] [pid 1025331:tid 1025545] [client 161.118.218.103:61652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVcQAAAV4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:39.319064 2026] [security2:error] [pid 1025331:tid 1025506] [client 34.73.38.214:61765] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVcwAAATc"]
[Mon Jul 20 06:50:39.366330 2026] [security2:error] [pid 1025331:tid 1025483] [client 34.139.11.221:55535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVeAAAASA"]
[Mon Jul 20 06:50:39.395284 2026] [security2:error] [pid 1025331:tid 1025537] [client 14.225.17.146:61282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4ZnUOu5aQNSViFaxNVCgAAAVY"], referer: http://mobilesurvsolutions.com/NEW
[Mon Jul 20 06:50:39.399776 2026] [security2:error] [pid 1025331:tid 1025535] [client 103.238.106.162:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVewAAAVQ"]
[Mon Jul 20 06:50:39.399873 2026] [security2:error] [pid 1025331:tid 1025535] [client 103.238.106.162:60844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVewAAAVQ"]
[Mon Jul 20 06:50:39.483757 2026] [security2:error] [pid 1025331:tid 1025527] [client 34.73.38.214:49298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVfgAAAUw"]
[Mon Jul 20 06:50:39.549136 2026] [security2:error] [pid 1025331:tid 1025488] [client 34.139.11.221:51805] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVgQAAASU"]
[Mon Jul 20 06:50:39.679853 2026] [security2:error] [pid 1025331:tid 1025574] [client 34.139.11.221:60476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVhgAAAXs"]
[Mon Jul 20 06:50:39.795581 2026] [security2:error] [pid 1025331:tid 1025538] [client 57.141.18.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4ZnkOu5aQNSViFaxNVGwAAAVc"]
[Mon Jul 20 06:50:39.809182 2026] [security2:error] [pid 1025331:tid 1025531] [client 34.139.11.221:51235] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.peoplestrategies.us"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn0Ou5aQNSViFaxNVjgAAAVA"]
[Mon Jul 20 06:50:39.876096 2026] [security2:error] [pid 1025331:tid 1025503] [client 161.118.218.103:62033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVkAAAATQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:39.877832 2026] [security2:error] [pid 1020501:tid 1020727] [client 34.73.38.214:57423] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Zn8S_oRsP4jdONhcHBAAAAF4"]
[Mon Jul 20 06:50:39.912420 2026] [security2:error] [pid 1020501:tid 1020725] [client 57.141.18.105:38792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zm8S_oRsP4jdONhcGWQAAXHw"]
[Mon Jul 20 06:50:40.032929 2026] [security2:error] [pid 1020501:tid 1020741] [client 34.73.38.214:57196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoMS_oRsP4jdONhcHBwAAAGw"]
[Mon Jul 20 06:50:40.331873 2026] [security2:error] [pid 1025331:tid 1025462] [client 34.73.38.214:61179] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoEOu5aQNSViFaxNVowAAAQs"]
[Mon Jul 20 06:50:40.368011 2026] [security2:error] [pid 1020501:tid 1020758] [client 34.73.38.214:64414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoMS_oRsP4jdONhcHFAAAAH0"]
[Mon Jul 20 06:50:40.457579 2026] [security2:error] [pid 1025331:tid 1025488] [client 161.118.218.103:62415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZoEOu5aQNSViFaxNVqAAAASU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:40.600813 2026] [security2:error] [pid 1025331:tid 1025572] [client 40.77.177.54:7621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4ZoEOu5aQNSViFaxNVpAABeTU"]
[Mon Jul 20 06:50:40.602504 2026] [security2:error] [pid 1020501:tid 1020723] [client 104.234.53.62:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZoMS_oRsP4jdONhcHHQAAAFo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:40.745074 2026] [security2:error] [pid 1020501:tid 1020731] [client 14.251.3.155:54738] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZoMS_oRsP4jdONhcHJgAAAGI"]
[Mon Jul 20 06:50:40.796262 2026] [security2:error] [pid 1020501:tid 1020680] [client 34.73.38.214:51139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoMS_oRsP4jdONhcHKwAAAC8"]
[Mon Jul 20 06:50:40.853542 2026] [security2:error] [pid 1025331:tid 1025585] [client 108.174.8.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4ZnkOu5aQNSViFaxNVIQABhhI"]
[Mon Jul 20 06:50:40.887040 2026] [security2:error] [pid 1020501:tid 1020695] [client 57.141.18.98:36388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZnMS_oRsP4jdONhcGkwAAPhg"]
[Mon Jul 20 06:50:40.969943 2026] [security2:error] [pid 1025331:tid 1025560] [client 34.73.38.214:51500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoEOu5aQNSViFaxNVugAAAW0"]
[Mon Jul 20 06:50:41.036824 2026] [security2:error] [pid 1025331:tid 1025502] [client 161.118.218.103:62772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZoUOu5aQNSViFaxNVvwAAATM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:41.163051 2026] [security2:error] [pid 1025331:tid 1025474] [client 57.141.18.105:38798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZnEOu5aQNSViFaxNU1QABF0c"]
[Mon Jul 20 06:50:41.266374 2026] [security2:error] [pid 1025331:tid 1025526] [client 77.110.127.138:57889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZoUOu5aQNSViFaxNVzQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:41.266461 2026] [security2:error] [pid 1025331:tid 1025526] [client 77.110.127.138:57889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZoUOu5aQNSViFaxNVzQAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:41.301582 2026] [security2:error] [pid 1020501:tid 1020759] [client 34.73.38.214:54249] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZocS_oRsP4jdONhcHNgAAAH4"]
[Mon Jul 20 06:50:41.377702 2026] [security2:error] [pid 1025331:tid 1025462] [client 34.73.38.214:55650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoUOu5aQNSViFaxNV0wAAAQs"]
[Mon Jul 20 06:50:41.524113 2026] [security2:error] [pid 1025331:tid 1025486] [client 14.225.17.146:59250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVjwAAASM"], referer: http://according2plant.com/NEW
[Mon Jul 20 06:50:41.613763 2026] [security2:error] [pid 1020501:tid 1020667] [client 161.118.218.103:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZocS_oRsP4jdONhcHPAAAACI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:41.644123 2026] [security2:error] [pid 1025331:tid 1025348] [remote 162.19.86.63:47908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ZoUOu5aQNSViFaxNV5wABPhA"]
[Mon Jul 20 06:50:41.675551 2026] [security2:error] [pid 1025331:tid 1025512] [client 50.116.65.227:41172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZoUOu5aQNSViFaxNV6QAAAT0"]
[Mon Jul 20 06:50:41.684579 2026] [security2:error] [pid 1025331:tid 1025545] [client 50.116.65.227:41180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZoUOu5aQNSViFaxNV7AAAAV4"]
[Mon Jul 20 06:50:41.710051 2026] [security2:error] [pid 1025331:tid 1025554] [client 34.73.38.214:63713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZoUOu5aQNSViFaxNV7gAAAWc"]
[Mon Jul 20 06:50:41.710467 2026] [security2:error] [pid 1020501:tid 1020741] [client 34.73.38.214:63596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZocS_oRsP4jdONhcHPwAAAGw"]
[Mon Jul 20 06:50:41.739534 2026] [security2:error] [pid 1025331:tid 1025518] [client 187.108.85.186:55389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZoUOu5aQNSViFaxNV9QAAAUM"]
[Mon Jul 20 06:50:41.739621 2026] [security2:error] [pid 1025331:tid 1025518] [client 187.108.85.186:55389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZoUOu5aQNSViFaxNV9QAAAUM"]
[Mon Jul 20 06:50:41.757337 2026] [security2:error] [pid 1025331:tid 1025402] [remote 217.182.128.41:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZoUOu5aQNSViFaxNV8wABFkY"]
[Mon Jul 20 06:50:41.780329 2026] [security2:error] [pid 1025331:tid 1025565] [client 57.141.18.33:44334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZnUOu5aQNSViFaxNVAwABcm8"]
[Mon Jul 20 06:50:41.783639 2026] [security2:error] [pid 1025331:tid 1025476] [client 52.35.117.102:7645] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.maplerespiteservices.com"] [uri "/"] [unique_id "al4ZoUOu5aQNSViFaxNV-gAAARk"]
[Mon Jul 20 06:50:41.804778 2026] [security2:error] [pid 1020501:tid 1020720] [client 39.48.81.23:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZocS_oRsP4jdONhcHRAAAAFc"]
[Mon Jul 20 06:50:41.804887 2026] [security2:error] [pid 1020501:tid 1020720] [client 39.48.81.23:58917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZocS_oRsP4jdONhcHRAAAAFc"]
[Mon Jul 20 06:50:41.857563 2026] [security2:error] [pid 1025331:tid 1025444] [remote 162.19.86.63:47908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ZoUOu5aQNSViFaxNWAQABXHA"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:50:41.947880 2026] [security2:error] [pid 1025331:tid 1025437] [remote 217.182.128.41:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZoUOu5aQNSViFaxNWBQABUmk"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:50:42.185942 2026] [security2:error] [pid 1025331:tid 1025574] [client 161.118.218.103:63467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZokOu5aQNSViFaxNWFwAAAXs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:42.230715 2026] [security2:error] [pid 1025331:tid 1025567] [client 34.73.38.214:61941] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZokOu5aQNSViFaxNWGQAAAXQ"]
[Mon Jul 20 06:50:42.250759 2026] [security2:error] [pid 1020501:tid 1020694] [client 34.73.38.214:50652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZosS_oRsP4jdONhcHSwAAAD0"]
[Mon Jul 20 06:50:42.271781 2026] [security2:error] [pid 1025331:tid 1025573] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZokOu5aQNSViFaxNWDAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:42.540882 2026] [security2:error] [pid 1025331:tid 1025580] [client 77.110.127.138:57897] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZokOu5aQNSViFaxNWMAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:42.631508 2026] [security2:error] [pid 1020501:tid 1020748] [client 34.73.38.214:59186] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZosS_oRsP4jdONhcHUAAAAHM"]
[Mon Jul 20 06:50:42.657959 2026] [security2:error] [pid 1020501:tid 1020578] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZosS_oRsP4jdONhcHUQAAQko"]
[Mon Jul 20 06:50:42.658109 2026] [security2:error] [pid 1020501:tid 1020699] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZosS_oRsP4jdONhcHUQAAQko"]
[Mon Jul 20 06:50:42.676099 2026] [security2:error] [pid 1025331:tid 1025585] [client 34.73.38.214:53063] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZokOu5aQNSViFaxNWOgAAAYY"]
[Mon Jul 20 06:50:42.767447 2026] [security2:error] [pid 1025331:tid 1025555] [client 161.118.218.103:63814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZokOu5aQNSViFaxNWPgAAAWg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:43.036551 2026] [security2:error] [pid 1025331:tid 1025511] [client 34.73.38.214:60567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Zo0Ou5aQNSViFaxNWUwAAATw"]
[Mon Jul 20 06:50:43.225010 2026] [security2:error] [pid 1025331:tid 1025479] [client 34.73.38.214:60357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.reosportsboats.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Zo0Ou5aQNSViFaxNWYgAAARw"]
[Mon Jul 20 06:50:43.245859 2026] [security2:error] [pid 1025331:tid 1025576] [client 57.141.18.94:27844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZnkOu5aQNSViFaxNVUgABfX8"]
[Mon Jul 20 06:50:43.342761 2026] [security2:error] [pid 1020501:tid 1020701] [client 161.118.218.103:64177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zo8S_oRsP4jdONhcHYwAAAEQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:43.356993 2026] [security2:error] [pid 1025331:tid 1025521] [client 14.225.17.146:50445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4ZoUOu5aQNSViFaxNV-QAAAUY"], referer: http://margaretspeckogawa.com/NEW
[Mon Jul 20 06:50:43.430882 2026] [security2:error] [pid 1025331:tid 1025341] [remote 103.187.169.251:41122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4Zo0Ou5aQNSViFaxNWcAABYAk"]
[Mon Jul 20 06:50:43.493344 2026] [security2:error] [pid 1025331:tid 1025477] [client 57.141.18.85:52284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVawABGik"]
[Mon Jul 20 06:50:43.535810 2026] [security2:error] [pid 1020501:tid 1020649] [client 34.73.38.214:58140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.representgrace.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Zo8S_oRsP4jdONhcHZgAAABA"]
[Mon Jul 20 06:50:43.829679 2026] [security2:error] [pid 1025331:tid 1025332] [remote 103.187.169.251:41122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4Zo0Ou5aQNSViFaxNWjwABHQA"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 06:50:43.921783 2026] [security2:error] [pid 1025331:tid 1025462] [client 161.118.218.103:64537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zo0Ou5aQNSViFaxNWlwAAAQs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:43.962158 2026] [security2:error] [pid 1025331:tid 1025484] [client 57.141.18.6:52184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zn0Ou5aQNSViFaxNVhAABIQ8"]
[Mon Jul 20 06:50:44.312905 2026] [security2:error] [pid 1025331:tid 1025523] [client 57.141.18.2:24160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZoEOu5aQNSViFaxNVmAABSF8"]
[Mon Jul 20 06:50:44.399965 2026] [security2:error] [pid 1020501:tid 1020738] [client 140.248.75.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.goyalsatyam.com"] [uri "/index.php"] [unique_id "al4ZosS_oRsP4jdONhcHTgAAAGk"]
[Mon Jul 20 06:50:44.428707 2026] [security2:error] [pid 1025331:tid 1025469] [client 140.248.75.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.goyalsatyam.com"] [uri "/index.php"] [unique_id "al4ZokOu5aQNSViFaxNWLgAAARI"]
[Mon Jul 20 06:50:44.505607 2026] [security2:error] [pid 1025331:tid 1025495] [client 161.118.218.103:64909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZpEOu5aQNSViFaxNWuAAAASw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:44.545235 2026] [security2:error] [pid 1025331:tid 1025541] [client 14.225.17.146:50789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZpEOu5aQNSViFaxNWsAAAAVo"], referer: http://mezzacraft.com/NEW
[Mon Jul 20 06:50:44.566171 2026] [security2:error] [pid 1025331:tid 1025512] [client 14.225.17.146:50827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4ZpEOu5aQNSViFaxNWtAAAAT0"], referer: http://effingweirdmuseums.com/NEW
[Mon Jul 20 06:50:44.749768 2026] [security2:error] [pid 1025331:tid 1025510] [client 57.141.18.81:35668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZoEOu5aQNSViFaxNVpgABO1Q"]
[Mon Jul 20 06:50:44.792863 2026] [security2:error] [pid 1020501:tid 1020551] [remote 182.77.62.24:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZpMS_oRsP4jdONhcHfwAAUS8"]
[Mon Jul 20 06:50:45.001472 2026] [security2:error] [pid 1020501:tid 1020674] [client 14.225.17.146:55130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4ZpMS_oRsP4jdONhcHfgAAACk"], referer: http://secretkeynumerology.com/NEW
[Mon Jul 20 06:50:45.012975 2026] [security2:error] [pid 1025331:tid 1025498] [client 14.225.17.146:55192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4Zo0Ou5aQNSViFaxNWlAAAAS8"], referer: http://grndl.com/NEW
[Mon Jul 20 06:50:45.079213 2026] [security2:error] [pid 1025331:tid 1025472] [client 161.118.218.103:65272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZpUOu5aQNSViFaxNW1gAAARU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:45.132883 2026] [security2:error] [pid 1025331:tid 1025422] [remote 116.203.133.192:42394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.133.203.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZpUOu5aQNSViFaxNW2gABPFo"]
[Mon Jul 20 06:50:45.182483 2026] [security2:error] [pid 1020501:tid 1020677] [client 57.141.18.18:26184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZoMS_oRsP4jdONhcHLQAALEg"]
[Mon Jul 20 06:50:45.268377 2026] [security2:error] [pid 1025331:tid 1025535] [client 104.234.53.83:22825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZpUOu5aQNSViFaxNW4wAAAVQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:45.326497 2026] [security2:error] [pid 1025331:tid 1025421] [remote 116.203.133.192:42394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.133.203.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZpUOu5aQNSViFaxNW6QABFFk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:50:45.346186 2026] [security2:error] [pid 1020501:tid 1020508] [remote 182.77.62.24:37160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ZpcS_oRsP4jdONhcHkgAAfQQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:50:45.379909 2026] [security2:error] [pid 1025331:tid 1025463] [client 197.186.66.42:60504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZpUOu5aQNSViFaxNW7wAAAQw"]
[Mon Jul 20 06:50:45.383897 2026] [security2:error] [pid 1025331:tid 1025463] [client 197.186.66.42:60504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZpUOu5aQNSViFaxNW7wAAAQw"]
[Mon Jul 20 06:50:45.476178 2026] [security2:error] [pid 1025331:tid 1025502] [client 14.225.17.146:53530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4ZpEOu5aQNSViFaxNWvAAAATM"], referer: http://healthylifegourmet.org/NEW
[Mon Jul 20 06:50:45.571114 2026] [security2:error] [pid 1025331:tid 1025479] [client 14.225.17.146:53597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4ZpUOu5aQNSViFaxNW9gAAARw"], referer: https://effingweirdmuseums.com/NEW
[Mon Jul 20 06:50:45.657352 2026] [security2:error] [pid 1025331:tid 1025583] [client 161.118.218.103:49211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZpUOu5aQNSViFaxNW_gAAAYQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:45.683146 2026] [security2:error] [pid 1025331:tid 1025520] [client 152.58.191.29:59467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZpUOu5aQNSViFaxNXAQAAAUU"]
[Mon Jul 20 06:50:45.683247 2026] [security2:error] [pid 1025331:tid 1025520] [client 152.58.191.29:59467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZpUOu5aQNSViFaxNXAQAAAUU"]
[Mon Jul 20 06:50:45.992900 2026] [security2:error] [pid 1020501:tid 1020648] [client 57.141.18.91:41288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZocS_oRsP4jdONhcHPgAADzE"]
[Mon Jul 20 06:50:45.995951 2026] [security2:error] [pid 1025331:tid 1025504] [client 57.141.18.55:61018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZoUOu5aQNSViFaxNV8AABNQs"]
[Mon Jul 20 06:50:46.170580 2026] [security2:error] [pid 1025331:tid 1025564] [client 14.225.17.146:50735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4ZpkOu5aQNSViFaxNXFgAAAXE"], referer: https://secretkeynumerology.com/NEW
[Mon Jul 20 06:50:46.236935 2026] [security2:error] [pid 1020501:tid 1020729] [client 161.118.218.103:49545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZpsS_oRsP4jdONhcHqwAAAGA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:46.277180 2026] [security2:error] [pid 1025331:tid 1025506] [client 51.195.39.149:14496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hamelrealestate.collectingrealestate.com"] [uri "/index.php"] [unique_id "al4Zo0Ou5aQNSViFaxNWjQABN2I"]
[Mon Jul 20 06:50:46.403953 2026] [proxy:error] [pid 1025331:tid 1025583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:46.404024 2026] [proxy_http:error] [pid 1025331:tid 1025583] [client 34.73.38.214:61592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:46.404832 2026] [proxy:error] [pid 1025331:tid 1025583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:46.404883 2026] [proxy_http:error] [pid 1025331:tid 1025583] [client 34.73.38.214:61592] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:46.410706 2026] [security2:error] [pid 1025331:tid 1025568] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4ZpkOu5aQNSViFaxNXIgABdRA"], referer: http://assasalnazaha.com/NEW
[Mon Jul 20 06:50:46.431080 2026] [security2:error] [pid 1025331:tid 1025569] [client 54.214.165.245:34364] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thecreole.com"] [uri "/index.cgi"] [unique_id "al4ZpkOu5aQNSViFaxNXKgAAAXY"]
[Mon Jul 20 06:50:46.452544 2026] [security2:error] [pid 1025331:tid 1025494] [client 77.110.127.138:57962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZpkOu5aQNSViFaxNXLgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:46.452683 2026] [security2:error] [pid 1025331:tid 1025494] [client 77.110.127.138:57962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZpkOu5aQNSViFaxNXLgAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:46.477341 2026] [security2:error] [pid 1020501:tid 1020737] [client 14.225.17.146:50955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4ZpMS_oRsP4jdONhcHfAAAAGg"], referer: http://grecruit.online/NEW
[Mon Jul 20 06:50:46.643338 2026] [security2:error] [pid 1020501:tid 1020666] [client 37.52.210.45:38026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZpsS_oRsP4jdONhcHuAAAACE"]
[Mon Jul 20 06:50:46.643481 2026] [security2:error] [pid 1020501:tid 1020666] [client 37.52.210.45:38026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZpsS_oRsP4jdONhcHuAAAACE"]
[Mon Jul 20 06:50:46.662324 2026] [security2:error] [pid 1025331:tid 1025523] [client 35.82.208.243:35402] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thecreole.com"] [uri "/index.cgi"] [unique_id "al4ZpkOu5aQNSViFaxNXOAAAAUg"]
[Mon Jul 20 06:50:46.687243 2026] [security2:error] [pid 1025331:tid 1025586] [client 57.141.18.80:35416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZokOu5aQNSViFaxNWIQABh0Q"]
[Mon Jul 20 06:50:46.813537 2026] [security2:error] [pid 1025331:tid 1025511] [client 161.118.218.103:49887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZpkOu5aQNSViFaxNXQwAAATw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:46.887568 2026] [security2:error] [pid 1020501:tid 1020661] [client 14.225.17.146:50922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4ZpsS_oRsP4jdONhcHuQAAABw"], referer: http://ivetstrategies.com/NEW
[Mon Jul 20 06:50:47.063037 2026] [security2:error] [pid 1025331:tid 1025516] [client 122.183.32.225:1092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXTwAAAUE"]
[Mon Jul 20 06:50:47.063169 2026] [security2:error] [pid 1025331:tid 1025516] [client 122.183.32.225:1092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXTwAAAUE"]
[Mon Jul 20 06:50:47.253143 2026] [security2:error] [pid 1025331:tid 1025548] [client 57.141.18.19:61210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZokOu5aQNSViFaxNWRwABYR4"]
[Mon Jul 20 06:50:47.262834 2026] [proxy:error] [pid 1025331:tid 1025486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:47.262930 2026] [proxy_http:error] [pid 1025331:tid 1025486] [client 34.73.38.214:56798] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:47.263939 2026] [proxy:error] [pid 1025331:tid 1025486] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:47.263980 2026] [proxy_http:error] [pid 1025331:tid 1025486] [client 34.73.38.214:56798] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:47.283101 2026] [security2:error] [pid 1025331:tid 1025555] [client 173.239.224.44:31989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXXwAAAWg"]
[Mon Jul 20 06:50:47.295278 2026] [security2:error] [pid 1025331:tid 1025556] [client 106.219.188.178:32942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXYQAAAWk"]
[Mon Jul 20 06:50:47.296999 2026] [security2:error] [pid 1025331:tid 1025556] [client 106.219.188.178:32942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXYQAAAWk"]
[Mon Jul 20 06:50:47.405264 2026] [security2:error] [pid 1025331:tid 1025510] [client 161.118.218.103:50237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXZQAAATs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:47.437818 2026] [security2:error] [pid 1020501:tid 1020678] [client 57.141.18.110:30822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zo8S_oRsP4jdONhcHXQAALXE"]
[Mon Jul 20 06:50:47.549181 2026] [security2:error] [pid 1020501:tid 1020656] [client 104.234.53.61:32783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Zp8S_oRsP4jdONhcH0QAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:47.586810 2026] [proxy:error] [pid 1025331:tid 1025483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:47.586868 2026] [proxy_http:error] [pid 1025331:tid 1025483] [client 34.73.38.214:57831] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:47.587480 2026] [proxy:error] [pid 1025331:tid 1025483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:47.587507 2026] [proxy_http:error] [pid 1025331:tid 1025483] [client 34.73.38.214:57831] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:47.657381 2026] [security2:error] [pid 1025331:tid 1025501] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXXAAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:47.709140 2026] [security2:error] [pid 1025331:tid 1025493] [client 158.173.89.95:58869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXfgAAASo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:50:47.861553 2026] [security2:error] [pid 1020501:tid 1020723] [client 223.185.13.213:21231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp8S_oRsP4jdONhcH2gAAAFo"]
[Mon Jul 20 06:50:47.861730 2026] [security2:error] [pid 1020501:tid 1020723] [client 223.185.13.213:21231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp8S_oRsP4jdONhcH2gAAAFo"]
[Mon Jul 20 06:50:47.863630 2026] [security2:error] [pid 1020501:tid 1020639] [client 57.141.18.53:41236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zo8S_oRsP4jdONhcHaQAABkU"]
[Mon Jul 20 06:50:47.867472 2026] [security2:error] [pid 1025331:tid 1025469] [client 77.110.127.138:57992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zp0Ou5aQNSViFaxNXgwAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:47.904294 2026] [security2:error] [pid 1020501:tid 1020717] [client 183.82.98.154:62606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp8S_oRsP4jdONhcH2wAAAFQ"]
[Mon Jul 20 06:50:47.904415 2026] [security2:error] [pid 1020501:tid 1020717] [client 183.82.98.154:62606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Zp8S_oRsP4jdONhcH2wAAAFQ"]
[Mon Jul 20 06:50:47.987847 2026] [security2:error] [pid 1025331:tid 1025474] [client 161.118.218.103:50641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXjQAAARc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:48.030057 2026] [proxy:error] [pid 1020501:tid 1020648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:48.030130 2026] [proxy_http:error] [pid 1020501:tid 1020648] [client 34.73.38.214:51052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:48.030799 2026] [proxy:error] [pid 1020501:tid 1020648] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:48.030829 2026] [proxy_http:error] [pid 1020501:tid 1020648] [client 34.73.38.214:51052] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:48.039018 2026] [proxy:error] [pid 1020501:tid 1020736] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:48.039104 2026] [proxy_http:error] [pid 1020501:tid 1020736] [client 34.73.38.214:65516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:48.039628 2026] [proxy:error] [pid 1020501:tid 1020736] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:48.039656 2026] [proxy_http:error] [pid 1020501:tid 1020736] [client 34.73.38.214:65516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:48.121057 2026] [security2:error] [pid 1025331:tid 1025531] [client 50.116.65.227:41328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/03/IMG_2599-1.jpeg"] [unique_id "al4ZqEOu5aQNSViFaxNXlgAAATQ"]
[Mon Jul 20 06:50:48.146335 2026] [security2:error] [pid 1020501:tid 1020670] [client 14.225.17.146:50801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4ZpsS_oRsP4jdONhcHqAAAACU"], referer: http://webgardensbypaula.com/NEW
[Mon Jul 20 06:50:48.282164 2026] [security2:error] [pid 1025331:tid 1025526] [client 14.225.17.146:51015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4ZqEOu5aQNSViFaxNXlQAAAUs"], referer: http://savilerowtravel.com/NEW
[Mon Jul 20 06:50:48.428849 2026] [security2:error] [pid 1020501:tid 1020645] [client 57.141.18.72:35482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZpMS_oRsP4jdONhcHdQAADCI"]
[Mon Jul 20 06:50:48.575087 2026] [security2:error] [pid 1025331:tid 1025541] [client 161.118.218.103:50977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZqEOu5aQNSViFaxNXsgAAAVo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:48.611199 2026] [security2:error] [pid 1025331:tid 1025478] [client 34.73.38.214:59575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.robertpierson.org"] [uri "/xmlrpc.php"] [unique_id "al4ZqEOu5aQNSViFaxNXtAAAARs"]
[Mon Jul 20 06:50:48.643467 2026] [proxy:error] [pid 1025331:tid 1025502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:48.643536 2026] [proxy_http:error] [pid 1025331:tid 1025502] [client 34.73.38.214:52399] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:48.644236 2026] [proxy:error] [pid 1025331:tid 1025502] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:48.644267 2026] [proxy_http:error] [pid 1025331:tid 1025502] [client 34.73.38.214:52399] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:48.645339 2026] [security2:error] [pid 1025331:tid 1025527] [client 50.116.65.227:47200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_d9d7fe47/wp-cron.php"] [unique_id "al4ZqEOu5aQNSViFaxNXtwAAAUw"]
[Mon Jul 20 06:50:48.967086 2026] [security2:error] [pid 1025331:tid 1025543] [client 39.48.81.23:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqEOu5aQNSViFaxNXzQAAAVw"]
[Mon Jul 20 06:50:48.967197 2026] [security2:error] [pid 1025331:tid 1025543] [client 39.48.81.23:59446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqEOu5aQNSViFaxNXzQAAAVw"]
[Mon Jul 20 06:50:49.071683 2026] [security2:error] [pid 1020501:tid 1020698] [client 202.46.92.242:61187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqcS_oRsP4jdONhcH7gAAAEE"]
[Mon Jul 20 06:50:49.071787 2026] [security2:error] [pid 1020501:tid 1020698] [client 202.46.92.242:61187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqcS_oRsP4jdONhcH7gAAAEE"]
[Mon Jul 20 06:50:49.079849 2026] [security2:error] [pid 1025331:tid 1025538] [client 34.73.38.214:50791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZqUOu5aQNSViFaxNX1gAAAVc"]
[Mon Jul 20 06:50:49.161191 2026] [security2:error] [pid 1025331:tid 1025571] [client 161.118.218.103:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZqUOu5aQNSViFaxNX2wAAAXg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:49.168729 2026] [security2:error] [pid 1025331:tid 1025518] [client 34.73.38.214:58616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqUOu5aQNSViFaxNX3QAAAUM"]
[Mon Jul 20 06:50:49.297170 2026] [security2:error] [pid 1025331:tid 1025581] [client 65.111.24.141:37903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZqUOu5aQNSViFaxNX3wAAAYI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:49.390372 2026] [security2:error] [pid 1025331:tid 1025479] [client 157.85.211.87:28522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqUOu5aQNSViFaxNX5wAAARw"]
[Mon Jul 20 06:50:49.390549 2026] [security2:error] [pid 1025331:tid 1025479] [client 157.85.211.87:28522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqUOu5aQNSViFaxNX5wAAARw"]
[Mon Jul 20 06:50:49.571912 2026] [security2:error] [pid 1020501:tid 1020758] [client 104.234.53.61:32783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZqcS_oRsP4jdONhcH_QAAAH0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:49.592443 2026] [security2:error] [pid 1020501:tid 1020704] [client 217.142.18.172:16380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqcS_oRsP4jdONhcH_gAAAEc"]
[Mon Jul 20 06:50:49.595269 2026] [security2:error] [pid 1020501:tid 1020704] [client 217.142.18.172:16380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqcS_oRsP4jdONhcH_gAAAEc"]
[Mon Jul 20 06:50:49.617724 2026] [security2:error] [pid 1025331:tid 1025493] [client 117.247.108.24:19258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqUOu5aQNSViFaxNX7wAAASo"]
[Mon Jul 20 06:50:49.617820 2026] [security2:error] [pid 1025331:tid 1025493] [client 117.247.108.24:19258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqUOu5aQNSViFaxNX7wAAASo"]
[Mon Jul 20 06:50:49.642683 2026] [security2:error] [pid 1020501:tid 1020696] [client 57.141.18.18:62346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZpcS_oRsP4jdONhcHkwAAP00"]
[Mon Jul 20 06:50:49.693067 2026] [security2:error] [pid 1025331:tid 1025491] [client 50.116.65.227:58792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4ZqUOu5aQNSViFaxNX9QAAASg"]
[Mon Jul 20 06:50:49.702741 2026] [security2:error] [pid 1025331:tid 1025543] [client 50.116.65.227:32336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4ZqUOu5aQNSViFaxNX9wAAAU4"]
[Mon Jul 20 06:50:49.744123 2026] [security2:error] [pid 1025331:tid 1025566] [client 161.118.218.103:51767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZqUOu5aQNSViFaxNX_AAAAXM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:49.907294 2026] [security2:error] [pid 1025331:tid 1025538] [client 34.73.38.214:52434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZqUOu5aQNSViFaxNYBQAAAVc"]
[Mon Jul 20 06:50:49.929285 2026] [security2:error] [pid 1020501:tid 1020639] [client 34.73.38.214:50962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZqcS_oRsP4jdONhcIDgAAAAY"]
[Mon Jul 20 06:50:49.962471 2026] [security2:error] [pid 1020501:tid 1020718] [client 103.125.179.95:53031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqcS_oRsP4jdONhcIEQAAAFU"]
[Mon Jul 20 06:50:49.962608 2026] [security2:error] [pid 1020501:tid 1020718] [client 103.125.179.95:53031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZqcS_oRsP4jdONhcIEQAAAFU"]
[Mon Jul 20 06:50:50.084213 2026] [security2:error] [pid 1025331:tid 1025519] [client 14.225.17.146:59188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZqUOu5aQNSViFaxNYAwAAAUQ"], referer: http://fkconstructionfunding.com/NEW
[Mon Jul 20 06:50:50.190065 2026] [security2:error] [pid 1020501:tid 1020687] [client 104.207.61.50:50549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZqsS_oRsP4jdONhcIGAAAADY"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:50.211916 2026] [security2:error] [pid 1025331:tid 1025522] [client 57.141.18.52:30610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZpUOu5aQNSViFaxNXCAABRwQ"]
[Mon Jul 20 06:50:50.296323 2026] [security2:error] [pid 1025331:tid 1025489] [client 14.225.17.146:53548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4ZqEOu5aQNSViFaxNXywAAASY"], referer: http://iagdevelopments.com/NEW
[Mon Jul 20 06:50:50.321152 2026] [security2:error] [pid 1025331:tid 1025469] [client 161.118.218.103:52127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZqkOu5aQNSViFaxNYFwAAARI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:50.374351 2026] [security2:error] [pid 1025331:tid 1025511] [client 77.110.127.138:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZqkOu5aQNSViFaxNYGQAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:50.374477 2026] [security2:error] [pid 1025331:tid 1025511] [client 77.110.127.138:57934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZqkOu5aQNSViFaxNYGQAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:50.497466 2026] [security2:error] [pid 1020501:tid 1020650] [client 57.141.18.37:22726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZpsS_oRsP4jdONhcHrgAAEVU"]
[Mon Jul 20 06:50:50.561447 2026] [security2:error] [pid 1020501:tid 1020641] [client 34.73.38.214:59703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZqsS_oRsP4jdONhcIIwAAAAg"]
[Mon Jul 20 06:50:50.711179 2026] [security2:error] [pid 1025331:tid 1025513] [client 57.141.18.24:53748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZpkOu5aQNSViFaxNXMwABPhc"]
[Mon Jul 20 06:50:50.762480 2026] [security2:error] [pid 1020501:tid 1020695] [client 104.234.53.67:62183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZqsS_oRsP4jdONhcILQAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:50.815441 2026] [security2:error] [pid 1020501:tid 1020741] [client 34.73.38.214:64571] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZqsS_oRsP4jdONhcILgAAAGw"]
[Mon Jul 20 06:50:50.899321 2026] [security2:error] [pid 1025331:tid 1025539] [client 161.118.218.103:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZqkOu5aQNSViFaxNYOQAAAVg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:50.971303 2026] [security2:error] [pid 1025331:tid 1025493] [client 14.225.17.146:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4ZqkOu5aQNSViFaxNYNAAAASo"], referer: http://swafforddetailing.com/NEW
[Mon Jul 20 06:50:50.971825 2026] [security2:error] [pid 1020501:tid 1020698] [client 65.111.8.98:56989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZqsS_oRsP4jdONhcILwAAAEE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:50.987110 2026] [security2:error] [pid 1025331:tid 1025464] [client 34.73.38.214:59912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZqkOu5aQNSViFaxNYQAAAAQ0"]
[Mon Jul 20 06:50:51.110419 2026] [security2:error] [pid 1025331:tid 1025367] [remote 103.82.22.235:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYTQABbSM"]
[Mon Jul 20 06:50:51.142552 2026] [security2:error] [pid 1025331:tid 1025345] [remote 152.228.213.32:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.botanicapatterndesigns.com"] [uri "/wp-login.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYTgABWQ0"]
[Mon Jul 20 06:50:51.163959 2026] [security2:error] [pid 1025331:tid 1025572] [client 34.73.38.214:58530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Zq0Ou5aQNSViFaxNYUwAAAXk"]
[Mon Jul 20 06:50:51.332986 2026] [security2:error] [pid 1025331:tid 1025399] [remote 152.228.213.32:53826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.botanicapatterndesigns.com"] [uri "/wp-login.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYWwABI0M"], referer: https://mail.botanicapatterndesigns.com/wp-login.php
[Mon Jul 20 06:50:51.396258 2026] [security2:error] [pid 1025331:tid 1025514] [client 103.238.106.162:61021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYYAAAAT8"]
[Mon Jul 20 06:50:51.396399 2026] [security2:error] [pid 1025331:tid 1025514] [client 103.238.106.162:61021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYYAAAAT8"]
[Mon Jul 20 06:50:51.476413 2026] [security2:error] [pid 1025331:tid 1025503] [client 161.118.218.103:52797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYZQAAATQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:51.609984 2026] [security2:error] [pid 1025331:tid 1025432] [remote 103.82.22.235:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYbQABVWQ"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:50:51.679196 2026] [security2:error] [pid 1025331:tid 1025563] [client 34.73.38.214:55797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Zq0Ou5aQNSViFaxNYdAAAAXA"]
[Mon Jul 20 06:50:51.770230 2026] [security2:error] [pid 1025331:tid 1025562] [client 65.111.2.77:18355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYeAAAAW8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:50:51.807788 2026] [security2:error] [pid 1025331:tid 1025487] [client 57.141.18.63:26190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zp0Ou5aQNSViFaxNXagABJCw"]
[Mon Jul 20 06:50:51.827503 2026] [security2:error] [pid 1025331:tid 1025426] [remote 57.141.18.56:38832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3096972"] [unique_id "al4Zq0Ou5aQNSViFaxNYfQABYV4"]
[Mon Jul 20 06:50:51.833917 2026] [security2:error] [pid 1025331:tid 1025491] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYXwAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:51.897206 2026] [security2:error] [pid 1025331:tid 1025523] [client 114.119.132.242:60967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "eminenceconsults.com"] [uri "/robots.txt"] [unique_id "al4Zq0Ou5aQNSViFaxNYiAAAAUg"], referer: https://eminenceconsults.com/robots.txt
[Mon Jul 20 06:50:51.904012 2026] [core:error] [pid 1020501:tid 1020651] [client 103.153.183.69:58844] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%u002e./%u002e./.env?_=la2v4yjr&v=ijq5e), referer: https://www.google.com/search?q=5rwfrt
[Mon Jul 20 06:50:52.049794 2026] [security2:error] [pid 1025331:tid 1025557] [client 161.118.218.103:53103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZrEOu5aQNSViFaxNYlQAAAWo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:52.093103 2026] [security2:error] [pid 1025331:tid 1025404] [remote 72.167.132.114:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4ZrEOu5aQNSViFaxNYlwABgkg"]
[Mon Jul 20 06:50:52.136281 2026] [security2:error] [pid 1025331:tid 1025587] [client 8.219.158.81:53542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sve.xka.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZrEOu5aQNSViFaxNYngAAAYg"]
[Mon Jul 20 06:50:52.212764 2026] [security2:error] [pid 1020501:tid 1020635] [client 34.73.38.214:60853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrMS_oRsP4jdONhcITAAAAAI"]
[Mon Jul 20 06:50:52.341001 2026] [security2:error] [pid 1025331:tid 1025352] [remote 72.167.132.114:37220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4ZrEOu5aQNSViFaxNYrQABOxQ"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:50:52.365835 2026] [security2:error] [pid 1025331:tid 1025490] [client 57.141.18.96:58274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZqEOu5aQNSViFaxNXkQABJ0s"]
[Mon Jul 20 06:50:52.393426 2026] [security2:error] [pid 1020501:tid 1020577] [remote 103.118.29.185:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4ZrMS_oRsP4jdONhcITgAAQEk"]
[Mon Jul 20 06:50:52.475297 2026] [security2:error] [pid 1020501:tid 1020636] [client 187.108.85.186:55936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZrMS_oRsP4jdONhcIUwAAAAM"]
[Mon Jul 20 06:50:52.475420 2026] [security2:error] [pid 1020501:tid 1020636] [client 187.108.85.186:55936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZrMS_oRsP4jdONhcIUwAAAAM"]
[Mon Jul 20 06:50:52.552910 2026] [security2:error] [pid 1025331:tid 1025569] [client 47.128.117.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4ZrEOu5aQNSViFaxNYowAAAXY"]
[Mon Jul 20 06:50:52.604218 2026] [security2:error] [pid 1025331:tid 1025566] [client 34.73.38.214:58087] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrEOu5aQNSViFaxNYuQAAAXM"]
[Mon Jul 20 06:50:52.604314 2026] [security2:error] [pid 1020501:tid 1020675] [client 34.73.38.214:58151] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrMS_oRsP4jdONhcIVAAAACo"]
[Mon Jul 20 06:50:52.626071 2026] [security2:error] [pid 1025331:tid 1025503] [client 161.118.218.103:53425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZrEOu5aQNSViFaxNYuwAAATQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:52.828603 2026] [security2:error] [pid 1020501:tid 1020523] [remote 103.118.29.185:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4ZrMS_oRsP4jdONhcIWgAAXBM"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 06:50:53.003131 2026] [security2:error] [pid 1025331:tid 1025565] [client 57.141.18.18:62358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZqEOu5aQNSViFaxNXxQABclc"]
[Mon Jul 20 06:50:53.004358 2026] [security2:error] [pid 1025331:tid 1025359] [remote 51.158.61.221:54162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ZrEOu5aQNSViFaxNY0gABCxs"]
[Mon Jul 20 06:50:53.085436 2026] [security2:error] [pid 1025331:tid 1025379] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZrUOu5aQNSViFaxNY1wABOC8"]
[Mon Jul 20 06:50:53.085593 2026] [security2:error] [pid 1025331:tid 1025507] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZrUOu5aQNSViFaxNY1wABOC8"]
[Mon Jul 20 06:50:53.096968 2026] [security2:error] [pid 1025331:tid 1025579] [client 104.234.53.90:36813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZrUOu5aQNSViFaxNY1gAAAYA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:50:53.101963 2026] [security2:error] [pid 1025331:tid 1025567] [client 57.141.18.78:33150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZqEOu5aQNSViFaxNXyAABdC4"]
[Mon Jul 20 06:50:53.202032 2026] [security2:error] [pid 1025331:tid 1025560] [client 161.118.218.103:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZrUOu5aQNSViFaxNY3AAAAW0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:53.231530 2026] [security2:error] [pid 1020501:tid 1020695] [client 34.73.38.214:53644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrcS_oRsP4jdONhcIZwAAAD4"]
[Mon Jul 20 06:50:53.274941 2026] [security2:error] [pid 1025331:tid 1025424] [remote 51.158.61.221:54162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ZrUOu5aQNSViFaxNY4AABh1w"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:50:53.290178 2026] [security2:error] [pid 1020501:tid 1020739] [client 57.141.18.67:60992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZqcS_oRsP4jdONhcH8QAAah4"]
[Mon Jul 20 06:50:53.621641 2026] [security2:error] [pid 1025331:tid 1025532] [client 34.73.38.214:50583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrUOu5aQNSViFaxNY8wAAAVE"]
[Mon Jul 20 06:50:53.776297 2026] [security2:error] [pid 1025331:tid 1025588] [client 161.118.218.103:54119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZrUOu5aQNSViFaxNZAwAAAYk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:53.917434 2026] [security2:error] [pid 1025331:tid 1025470] [client 45.157.112.60:35993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZrUOu5aQNSViFaxNZEgAAARM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:50:53.964552 2026] [security2:error] [pid 1025331:tid 1025586] [client 34.73.38.214:56815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrUOu5aQNSViFaxNZFQAAAYc"]
[Mon Jul 20 06:50:54.224263 2026] [security2:error] [pid 1025331:tid 1025577] [client 50.116.65.227:32398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZrkOu5aQNSViFaxNZIAAAAX4"]
[Mon Jul 20 06:50:54.234607 2026] [security2:error] [pid 1025331:tid 1025492] [client 50.116.65.227:32404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZrkOu5aQNSViFaxNZIQAAASk"]
[Mon Jul 20 06:50:54.351390 2026] [security2:error] [pid 1025331:tid 1025580] [client 161.118.218.103:54524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZrkOu5aQNSViFaxNZJwAAAYE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:54.464893 2026] [security2:error] [pid 1025331:tid 1025474] [client 57.141.18.109:31052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZqkOu5aQNSViFaxNYGgABFzw"]
[Mon Jul 20 06:50:54.483140 2026] [security2:error] [pid 1025331:tid 1025357] [remote 103.75.185.95:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4ZrkOu5aQNSViFaxNZMQABchk"]
[Mon Jul 20 06:50:54.591203 2026] [security2:error] [pid 1020501:tid 1020722] [client 57.141.18.110:37720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZqsS_oRsP4jdONhcIIgAAWXI"]
[Mon Jul 20 06:50:54.712049 2026] [security2:error] [pid 1025331:tid 1025490] [client 34.73.38.214:58868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZrkOu5aQNSViFaxNZPwAAASc"]
[Mon Jul 20 06:50:54.925225 2026] [security2:error] [pid 1025331:tid 1025540] [client 161.118.218.103:54896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZrkOu5aQNSViFaxNZTQAAAVk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:55.001235 2026] [security2:error] [pid 1020501:tid 1020505] [remote 162.19.86.63:37054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4Zr8S_oRsP4jdONhcIiQAASgE"]
[Mon Jul 20 06:50:55.012132 2026] [security2:error] [pid 1025331:tid 1025335] [remote 103.75.185.95:38392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4Zr0Ou5aQNSViFaxNZUQABQwM"], referer: https://dnsplumbing.com/wp-login.php
[Mon Jul 20 06:50:55.241501 2026] [security2:error] [pid 1025331:tid 1025559] [client 57.141.18.32:40470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zq0Ou5aQNSViFaxNYTwABbEc"]
[Mon Jul 20 06:50:55.247257 2026] [security2:error] [pid 1025331:tid 1025554] [client 34.73.38.214:56815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Zr0Ou5aQNSViFaxNZXwAAAWc"]
[Mon Jul 20 06:50:55.326510 2026] [security2:error] [pid 1020501:tid 1020516] [remote 162.19.86.63:37054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4Zr8S_oRsP4jdONhcIjQAAXAw"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 06:50:55.499528 2026] [security2:error] [pid 1025331:tid 1025582] [client 161.118.218.103:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zr0Ou5aQNSViFaxNZawAAAYM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:55.767021 2026] [security2:error] [pid 1025331:tid 1025485] [client 14.225.17.146:59421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4ZrkOu5aQNSViFaxNZKwAAASI"], referer: http://dnsplumbing.com/NEW
[Mon Jul 20 06:50:56.082492 2026] [security2:error] [pid 1020501:tid 1020708] [client 161.118.218.103:55587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZsMS_oRsP4jdONhcIqAAAAEs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:56.183522 2026] [security2:error] [pid 1025331:tid 1025532] [client 14.251.3.155:54739] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZsEOu5aQNSViFaxNZiQAAAVE"]
[Mon Jul 20 06:50:56.198967 2026] [security2:error] [pid 1020501:tid 1020704] [client 77.110.127.138:58123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZsMS_oRsP4jdONhcIrAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:56.199118 2026] [security2:error] [pid 1020501:tid 1020704] [client 77.110.127.138:58123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZsMS_oRsP4jdONhcIrAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:56.239172 2026] [security2:error] [pid 1020501:tid 1020742] [client 34.73.38.214:59119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZsMS_oRsP4jdONhcIrQAAAG0"]
[Mon Jul 20 06:50:56.290405 2026] [security2:error] [pid 1025331:tid 1025552] [client 57.141.18.51:42620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZrEOu5aQNSViFaxNYlgABZUY"]
[Mon Jul 20 06:50:56.333646 2026] [security2:error] [pid 1025331:tid 1025521] [client 152.58.191.29:59903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZsEOu5aQNSViFaxNZjgAAAUY"]
[Mon Jul 20 06:50:56.339085 2026] [security2:error] [pid 1025331:tid 1025521] [client 152.58.191.29:59903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZsEOu5aQNSViFaxNZjgAAAUY"]
[Mon Jul 20 06:50:56.448864 2026] [security2:error] [pid 1020501:tid 1020647] [client 57.141.18.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZsMS_oRsP4jdONhcIsAAAAA4"]
[Mon Jul 20 06:50:56.459552 2026] [security2:error] [pid 1025331:tid 1025572] [client 57.141.18.3:25038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZrEOu5aQNSViFaxNYpQABeTc"]
[Mon Jul 20 06:50:56.668123 2026] [security2:error] [pid 1020501:tid 1020700] [client 161.118.218.103:55914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZsMS_oRsP4jdONhcIwwAAAEM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:56.854889 2026] [security2:error] [pid 1025331:tid 1025472] [client 34.73.38.214:56817] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZsEOu5aQNSViFaxNZowAAARU"]
[Mon Jul 20 06:50:56.859144 2026] [proxy:error] [pid 1025331:tid 1025537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:56.859215 2026] [proxy_http:error] [pid 1025331:tid 1025537] [client 34.73.38.214:50622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:56.859742 2026] [proxy:error] [pid 1025331:tid 1025537] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:56.859779 2026] [proxy_http:error] [pid 1025331:tid 1025537] [client 34.73.38.214:50622] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:57.076159 2026] [security2:error] [pid 1025331:tid 1025508] [client 14.225.17.146:58080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4ZsEOu5aQNSViFaxNZhgAAATk"], referer: http://retzkolonglogistics.com/NEW
[Mon Jul 20 06:50:57.213507 2026] [security2:error] [pid 1020501:tid 1020664] [client 14.225.17.146:56726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4Zr8S_oRsP4jdONhcImgAAAB8"], referer: http://mollycahill.com/NEW
[Mon Jul 20 06:50:57.243309 2026] [security2:error] [pid 1020501:tid 1020650] [client 161.118.218.103:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZscS_oRsP4jdONhcI1QAAABE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:57.321476 2026] [security2:error] [pid 1025331:tid 1025518] [client 13.233.207.33:64380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZsUOu5aQNSViFaxNZwQAAAUM"]
[Mon Jul 20 06:50:57.321574 2026] [security2:error] [pid 1025331:tid 1025518] [client 13.233.207.33:64380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZsUOu5aQNSViFaxNZwQAAAUM"]
[Mon Jul 20 06:50:57.322035 2026] [security2:error] [pid 1025331:tid 1025495] [client 37.52.210.45:57044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZsUOu5aQNSViFaxNZwgAAASw"]
[Mon Jul 20 06:50:57.322193 2026] [security2:error] [pid 1025331:tid 1025495] [client 37.52.210.45:57044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZsUOu5aQNSViFaxNZwgAAASw"]
[Mon Jul 20 06:50:57.387555 2026] [security2:error] [pid 1025331:tid 1025543] [client 14.225.17.146:56652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4Zr0Ou5aQNSViFaxNZcgAAAVw"], referer: http://tacticaltreeoperations.com/NEW
[Mon Jul 20 06:50:57.418368 2026] [security2:error] [pid 1025331:tid 1025525] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZsEOu5aQNSViFaxNZqwAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:57.473203 2026] [security2:error] [pid 1025331:tid 1025522] [client 14.225.17.146:60784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZvAAAAUc"], referer: http://laceycaraccident.com/NEW
[Mon Jul 20 06:50:57.746018 2026] [security2:error] [pid 1025331:tid 1025510] [client 34.73.38.214:56641] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZsUOu5aQNSViFaxNZ4wAAATs"]
[Mon Jul 20 06:50:57.826349 2026] [security2:error] [pid 1025331:tid 1025481] [client 161.118.218.103:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZsUOu5aQNSViFaxNZ5gAAAR4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:57.844810 2026] [security2:error] [pid 1025331:tid 1025533] [client 57.141.18.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZ3QAAAVI"]
[Mon Jul 20 06:50:57.857547 2026] [security2:error] [pid 1025331:tid 1025461] [client 158.173.241.141:23207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZ2wAAAQo"], referer: http://sesamegreenbeans.com/tag/south-africa/
[Mon Jul 20 06:50:57.877409 2026] [security2:error] [pid 1025331:tid 1025398] [remote 209.42.18.223:46440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZsUOu5aQNSViFaxNZ5wABbkI"]
[Mon Jul 20 06:50:57.944229 2026] [proxy:error] [pid 1025331:tid 1025477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:57.944318 2026] [proxy_http:error] [pid 1025331:tid 1025477] [client 34.73.38.214:59019] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:57.945032 2026] [proxy:error] [pid 1025331:tid 1025477] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:57.945069 2026] [proxy_http:error] [pid 1025331:tid 1025477] [client 34.73.38.214:59019] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:57.952014 2026] [security2:error] [pid 1025331:tid 1025489] [client 57.141.18.45:39818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZrUOu5aQNSViFaxNY6gABJls"]
[Mon Jul 20 06:50:58.029885 2026] [security2:error] [pid 1025331:tid 1025507] [client 223.185.13.213:13075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZskOu5aQNSViFaxNZ8gAAATg"]
[Mon Jul 20 06:50:58.030016 2026] [security2:error] [pid 1025331:tid 1025507] [client 223.185.13.213:13075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZskOu5aQNSViFaxNZ8gAAATg"]
[Mon Jul 20 06:50:58.061296 2026] [security2:error] [pid 1025331:tid 1025393] [remote 209.42.18.223:46440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZskOu5aQNSViFaxNZ8wABej0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:50:58.078393 2026] [security2:error] [pid 1020501:tid 1020693] [client 106.219.188.178:3270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZssS_oRsP4jdONhcJAAAAADw"]
[Mon Jul 20 06:50:58.078538 2026] [security2:error] [pid 1020501:tid 1020693] [client 106.219.188.178:3270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZssS_oRsP4jdONhcJAAAAADw"]
[Mon Jul 20 06:50:58.116916 2026] [security2:error] [pid 1020501:tid 1020759] [client 57.141.18.56:39298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZrcS_oRsP4jdONhcIbAAAfic"]
[Mon Jul 20 06:50:58.168228 2026] [security2:error] [pid 1020501:tid 1020686] [client 122.183.32.225:26534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZssS_oRsP4jdONhcJAwAAADU"]
[Mon Jul 20 06:50:58.168332 2026] [security2:error] [pid 1020501:tid 1020686] [client 122.183.32.225:26534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZssS_oRsP4jdONhcJAwAAADU"]
[Mon Jul 20 06:50:58.240947 2026] [security2:error] [pid 1025331:tid 1025584] [client 34.73.38.214:56818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.robertpierson.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZskOu5aQNSViFaxNaAAAAAYU"]
[Mon Jul 20 06:50:58.242166 2026] [security2:error] [pid 1020501:tid 1020685] [client 14.225.17.146:61234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4ZsMS_oRsP4jdONhcIuAAAADQ"], referer: http://narv.co/NEW
[Mon Jul 20 06:50:58.282151 2026] [core:error] [pid 1025331:tid 1025541] [client 14.225.17.146:58258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/NEW
[Mon Jul 20 06:50:58.282175 2026] [core:error] [pid 1025331:tid 1025541] [client 14.225.17.146:58258] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/NEW
[Mon Jul 20 06:50:58.335295 2026] [security2:error] [pid 1025331:tid 1025548] [client 57.141.18.109:31064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZrUOu5aQNSViFaxNZBwABYXw"]
[Mon Jul 20 06:50:58.403249 2026] [security2:error] [pid 1020501:tid 1020646] [client 161.118.218.103:57028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZssS_oRsP4jdONhcJCgAAAA0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:58.432040 2026] [security2:error] [pid 1025331:tid 1025523] [client 57.141.18.51:58834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZrUOu5aQNSViFaxNZEwABSEk"]
[Mon Jul 20 06:50:58.518679 2026] [security2:error] [pid 1025331:tid 1025585] [client 14.225.17.146:60835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZyQAAAYY"], referer: http://travelbyfire.com/NEW
[Mon Jul 20 06:50:58.531786 2026] [security2:error] [pid 1020501:tid 1020710] [client 34.73.38.214:60868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZssS_oRsP4jdONhcJDQAAAE0"]
[Mon Jul 20 06:50:58.538256 2026] [security2:error] [pid 1020501:tid 1020652] [client 158.173.166.181:28915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ZssS_oRsP4jdONhcJDgAAABM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:50:58.552176 2026] [security2:error] [pid 1020501:tid 1020644] [client 50.116.65.227:58806] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4ZssS_oRsP4jdONhcJEQAAAAs"]
[Mon Jul 20 06:50:58.564931 2026] [security2:error] [pid 1025331:tid 1025477] [client 50.116.65.227:32482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4ZskOu5aQNSViFaxNaFQAAAX4"]
[Mon Jul 20 06:50:58.574240 2026] [security2:error] [pid 1025331:tid 1025527] [client 183.82.98.154:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZskOu5aQNSViFaxNaFgAAAUw"]
[Mon Jul 20 06:50:58.574345 2026] [security2:error] [pid 1025331:tid 1025527] [client 183.82.98.154:63196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZskOu5aQNSViFaxNaFgAAAUw"]
[Mon Jul 20 06:50:58.769611 2026] [proxy:error] [pid 1020501:tid 1020716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:58.769699 2026] [proxy_http:error] [pid 1020501:tid 1020716] [client 34.73.38.214:55264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:58.770929 2026] [proxy:error] [pid 1020501:tid 1020716] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:50:58.770970 2026] [proxy_http:error] [pid 1020501:tid 1020716] [client 34.73.38.214:55264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:50:58.778859 2026] [security2:error] [pid 1025331:tid 1025566] [client 197.186.66.42:61037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZskOu5aQNSViFaxNaIgAAAXM"]
[Mon Jul 20 06:50:58.791219 2026] [security2:error] [pid 1025331:tid 1025566] [client 197.186.66.42:61037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZskOu5aQNSViFaxNaIgAAAXM"]
[Mon Jul 20 06:50:58.803802 2026] [security2:error] [pid 1025331:tid 1025493] [client 77.110.127.138:58156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZskOu5aQNSViFaxNaIwAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:58.986646 2026] [security2:error] [pid 1020501:tid 1020725] [client 161.118.218.103:57395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZssS_oRsP4jdONhcJKQAAAFw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:59.285615 2026] [security2:error] [pid 1020501:tid 1020726] [client 14.225.17.146:56747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4Zs8S_oRsP4jdONhcJKwAAAF0"], referer: https://narv.co/NEW
[Mon Jul 20 06:50:59.461388 2026] [security2:error] [pid 1025331:tid 1025569] [client 14.225.17.146:56864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4Zs0Ou5aQNSViFaxNaTQAAAXY"], referer: https://travelbyfire.com/NEW
[Mon Jul 20 06:50:59.496800 2026] [security2:error] [pid 1025331:tid 1025471] [client 39.48.81.23:59971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zs0Ou5aQNSViFaxNaUQAAARQ"]
[Mon Jul 20 06:50:59.496947 2026] [security2:error] [pid 1025331:tid 1025471] [client 39.48.81.23:59971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zs0Ou5aQNSViFaxNaUQAAARQ"]
[Mon Jul 20 06:50:59.524104 2026] [security2:error] [pid 1020501:tid 1020640] [client 77.110.127.138:58170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zs8S_oRsP4jdONhcJMAAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:59.524196 2026] [security2:error] [pid 1020501:tid 1020640] [client 77.110.127.138:58170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zs8S_oRsP4jdONhcJMAAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:59.567293 2026] [security2:error] [pid 1025331:tid 1025487] [client 161.118.218.103:57735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zs0Ou5aQNSViFaxNaUwAAASQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:50:59.676119 2026] [security2:error] [pid 1025331:tid 1025572] [client 77.110.127.138:58176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:amphWtvpM2O' OR 513. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 513 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zs0Ou5aQNSViFaxNaVgAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:59.715683 2026] [security2:error] [pid 1020501:tid 1020735] [client 202.46.92.242:61662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Zs8S_oRsP4jdONhcJNgAAAGY"]
[Mon Jul 20 06:50:59.715813 2026] [security2:error] [pid 1020501:tid 1020735] [client 202.46.92.242:61662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Zs8S_oRsP4jdONhcJNgAAAGY"]
[Mon Jul 20 06:50:59.763895 2026] [security2:error] [pid 1025331:tid 1025535] [client 34.73.38.214:50634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.roguedragonstudio.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Zs0Ou5aQNSViFaxNaXwAAAVQ"]
[Mon Jul 20 06:50:59.826500 2026] [security2:error] [pid 1025331:tid 1025466] [client 77.110.127.138:58181] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zs0Ou5aQNSViFaxNaYgAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:50:59.957522 2026] [security2:error] [pid 1025331:tid 1025370] [remote 162.19.86.63:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4Zs0Ou5aQNSViFaxNacAABHCY"]
[Mon Jul 20 06:51:00.144816 2026] [security2:error] [pid 1025331:tid 1025577] [client 161.118.218.103:58103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZtEOu5aQNSViFaxNaggAAAX4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:00.164644 2026] [security2:error] [pid 1025331:tid 1025434] [remote 162.19.86.63:35498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ZtEOu5aQNSViFaxNahQABSWY"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:51:00.199239 2026] [security2:error] [pid 1025331:tid 1025521] [client 34.73.38.214:55091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNaiAAAAUY"]
[Mon Jul 20 06:51:00.214509 2026] [security2:error] [pid 1025331:tid 1025514] [client 217.142.18.172:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNaiQAAAT8"]
[Mon Jul 20 06:51:00.218951 2026] [security2:error] [pid 1025331:tid 1025514] [client 217.142.18.172:59605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNaiQAAAT8"]
[Mon Jul 20 06:51:00.231549 2026] [security2:error] [pid 1025331:tid 1025568] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZtEOu5aQNSViFaxNaeQAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:00.288328 2026] [security2:error] [pid 1025331:tid 1025548] [client 192.140.149.97:45020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNajQAAAWE"]
[Mon Jul 20 06:51:00.288463 2026] [security2:error] [pid 1025331:tid 1025548] [client 192.140.149.97:45020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNajQAAAWE"]
[Mon Jul 20 06:51:00.367900 2026] [security2:error] [pid 1025331:tid 1025480] [client 117.247.108.24:63736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNakAAAAR0"]
[Mon Jul 20 06:51:00.368064 2026] [security2:error] [pid 1025331:tid 1025480] [client 117.247.108.24:63736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNakAAAAR0"]
[Mon Jul 20 06:51:00.725065 2026] [security2:error] [pid 1025331:tid 1025538] [client 161.118.218.103:58412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZtEOu5aQNSViFaxNaqQAAAVc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:00.896322 2026] [security2:error] [pid 1025331:tid 1025521] [client 57.141.18.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZtEOu5aQNSViFaxNasAAAAUY"]
[Mon Jul 20 06:51:00.903432 2026] [security2:error] [pid 1020501:tid 1020651] [client 57.141.18.49:46392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZsMS_oRsP4jdONhcItQAAEi4"]
[Mon Jul 20 06:51:00.999868 2026] [security2:error] [pid 1025331:tid 1025576] [client 103.125.179.95:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNaugAAAX0"]
[Mon Jul 20 06:51:01.000333 2026] [security2:error] [pid 1025331:tid 1025576] [client 103.125.179.95:53541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZtEOu5aQNSViFaxNaugAAAX0"]
[Mon Jul 20 06:51:01.049290 2026] [security2:error] [pid 1020501:tid 1020535] [remote 192.241.143.148:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZtcS_oRsP4jdONhcJUgAADh8"]
[Mon Jul 20 06:51:01.300477 2026] [security2:error] [pid 1025331:tid 1025471] [client 161.118.218.103:58781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZtUOu5aQNSViFaxNaxgAAARQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:01.308613 2026] [security2:error] [pid 1025331:tid 1025534] [client 57.141.18.60:39032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZsEOu5aQNSViFaxNZoAABUzE"]
[Mon Jul 20 06:51:01.406785 2026] [autoindex:error] [pid 1025331:tid 1025495] [client 198.235.24.170:57576] AH01276: Cannot serve directory /home2/kdgjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://kdg.jiv.mybluehost.me/
[Mon Jul 20 06:51:01.565783 2026] [security2:error] [pid 1025331:tid 1025540] [client 57.141.18.35:30724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZrQABWW8"]
[Mon Jul 20 06:51:01.645199 2026] [security2:error] [pid 1025331:tid 1025477] [client 77.110.127.138:58224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZtUOu5aQNSViFaxNa1AAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:01.645670 2026] [security2:error] [pid 1020501:tid 1020506] [remote 192.241.143.148:60648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ZtcS_oRsP4jdONhcJYwAASgI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:51:01.708777 2026] [security2:error] [pid 1020501:tid 1020650] [client 8.228.127.164:59182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.127.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emil.manasyan.uk"] [uri "/xmlrpc.php"] [unique_id "al4ZtcS_oRsP4jdONhcJZQAAABE"]
[Mon Jul 20 06:51:01.785735 2026] [security2:error] [pid 1025331:tid 1025481] [client 34.73.38.214:57485] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtUOu5aQNSViFaxNa3AAAAR4"]
[Mon Jul 20 06:51:01.858925 2026] [security2:error] [pid 1020501:tid 1020726] [client 8.228.127.164:57791] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtcS_oRsP4jdONhcJbAAAAF0"]
[Mon Jul 20 06:51:01.875052 2026] [security2:error] [pid 1025331:tid 1025484] [client 161.118.218.103:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZtUOu5aQNSViFaxNa5QAAASE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:02.085636 2026] [security2:error] [pid 1025331:tid 1025535] [client 8.228.127.164:51996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtkOu5aQNSViFaxNa6wAAAVQ"]
[Mon Jul 20 06:51:02.133828 2026] [security2:error] [pid 1020501:tid 1020664] [client 103.238.106.162:63753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZtsS_oRsP4jdONhcJcQAAAB8"]
[Mon Jul 20 06:51:02.133929 2026] [security2:error] [pid 1020501:tid 1020664] [client 103.238.106.162:63753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZtsS_oRsP4jdONhcJcQAAAB8"]
[Mon Jul 20 06:51:02.142224 2026] [security2:error] [pid 1025331:tid 1025558] [client 14.225.17.146:57695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4ZtUOu5aQNSViFaxNawgAAAWs"], referer: http://walkingandtalking.net/NEW
[Mon Jul 20 06:51:02.214308 2026] [security2:error] [pid 1025331:tid 1025523] [client 8.228.127.164:54892] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtkOu5aQNSViFaxNa9gAAAUg"]
[Mon Jul 20 06:51:02.361792 2026] [security2:error] [pid 1025331:tid 1025557] [client 57.141.18.15:40328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZ4AABakQ"]
[Mon Jul 20 06:51:02.362100 2026] [security2:error] [pid 1020501:tid 1020682] [client 8.228.127.164:55138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtsS_oRsP4jdONhcJfAAAADE"]
[Mon Jul 20 06:51:02.429973 2026] [security2:error] [pid 1020501:tid 1020743] [client 104.207.56.15:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ZtsS_oRsP4jdONhcJfgAAAG4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:51:02.456765 2026] [security2:error] [pid 1020501:tid 1020730] [client 161.118.218.103:59410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZtsS_oRsP4jdONhcJgQAAAGE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:02.608100 2026] [security2:error] [pid 1025331:tid 1025514] [client 34.73.38.214:63397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtkOu5aQNSViFaxNbCgAAAT8"]
[Mon Jul 20 06:51:02.612454 2026] [security2:error] [pid 1025331:tid 1025526] [client 57.141.18.82:24358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZsUOu5aQNSViFaxNZ5AABSzg"]
[Mon Jul 20 06:51:02.626973 2026] [security2:error] [pid 1025331:tid 1025356] [remote 57.141.18.66:58440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4085058"] [unique_id "al4ZtkOu5aQNSViFaxNbCwABchg"]
[Mon Jul 20 06:51:02.666298 2026] [security2:error] [pid 1025331:tid 1025572] [client 8.228.127.164:54871] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZtkOu5aQNSViFaxNbDwAAAXk"]
[Mon Jul 20 06:51:02.692225 2026] [security2:error] [pid 1025331:tid 1025563] [client 14.225.17.146:57463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4ZtEOu5aQNSViFaxNapgAAAXA"], referer: http://securingmemories.com/NEW
[Mon Jul 20 06:51:02.910603 2026] [security2:error] [pid 1025331:tid 1025334] [remote 173.249.4.11:32690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZtkOu5aQNSViFaxNbGgABQwI"]
[Mon Jul 20 06:51:02.910791 2026] [security2:error] [pid 1025331:tid 1025518] [client 173.249.4.11:32690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZtkOu5aQNSViFaxNbGgABQwI"]
[Mon Jul 20 06:51:02.997103 2026] [security2:error] [pid 1025331:tid 1025588] [client 77.110.127.138:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZtkOu5aQNSViFaxNbHAAAAYk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:02.997241 2026] [security2:error] [pid 1025331:tid 1025588] [client 77.110.127.138:58231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZtkOu5aQNSViFaxNbHAAAAYk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:03.033196 2026] [security2:error] [pid 1025331:tid 1025507] [client 161.118.218.103:59727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbIAAAATg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:03.047404 2026] [security2:error] [pid 1025331:tid 1025558] [client 8.228.127.164:52670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Zt0Ou5aQNSViFaxNbIQAAAWs"]
[Mon Jul 20 06:51:03.097452 2026] [security2:error] [pid 1025331:tid 1025541] [client 187.108.85.186:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbJQAAAVo"]
[Mon Jul 20 06:51:03.097571 2026] [security2:error] [pid 1025331:tid 1025541] [client 187.108.85.186:56464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbJQAAAVo"]
[Mon Jul 20 06:51:03.098891 2026] [security2:error] [pid 1020501:tid 1020675] [client 14.225.17.146:58520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4Zt8S_oRsP4jdONhcJjgAAACo"], referer: https://walkingandtalking.net/NEW
[Mon Jul 20 06:51:03.155140 2026] [security2:error] [pid 1020501:tid 1020717] [client 77.110.127.138:58232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:amp9qBv3PUg') OR 176. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 176 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zt8S_oRsP4jdONhcJkQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:03.286824 2026] [security2:error] [pid 1020501:tid 1020708] [client 65.111.8.98:31947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Zt8S_oRsP4jdONhcJlgAAAEs"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:51:03.311868 2026] [security2:error] [pid 1025331:tid 1025483] [client 77.110.127.138:58233] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Zt0Ou5aQNSViFaxNbOAAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:03.338332 2026] [security2:error] [pid 1025331:tid 1025477] [client 114.119.158.31:21855] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "zastrow.com"] [uri "/robots.txt"] [unique_id "al4Zt0Ou5aQNSViFaxNbOQAAARo"], referer: http://zastrow.com/robots.txt
[Mon Jul 20 06:51:03.397459 2026] [security2:error] [pid 1025331:tid 1025564] [client 14.225.17.146:58507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbIwAAAXE"], referer: http://nextlevelpressurewashing.com/NEW
[Mon Jul 20 06:51:03.460114 2026] [security2:error] [pid 1025331:tid 1025514] [client 77.110.127.138:58234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbPgAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:03.460228 2026] [security2:error] [pid 1025331:tid 1025514] [client 77.110.127.138:58234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbPgAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:03.524745 2026] [security2:error] [pid 1025331:tid 1025568] [client 8.228.127.164:64520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Zt0Ou5aQNSViFaxNbQgAAAXU"]
[Mon Jul 20 06:51:03.558777 2026] [security2:error] [pid 1025331:tid 1025532] [client 14.225.17.146:58675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbOwAAAVE"], referer: http://alrowad-hub.net/NEW
[Mon Jul 20 06:51:03.562352 2026] [security2:error] [pid 1025331:tid 1025344] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbRQABXQw"]
[Mon Jul 20 06:51:03.562521 2026] [security2:error] [pid 1025331:tid 1025544] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbRQABXQw"]
[Mon Jul 20 06:51:03.607171 2026] [security2:error] [pid 1025331:tid 1025481] [client 161.118.218.103:60071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zt0Ou5aQNSViFaxNbSQAAAR4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:03.728230 2026] [security2:error] [pid 1020501:tid 1020702] [client 34.139.11.221:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.poopatrol608.com"] [uri "/xmlrpc.php"] [unique_id "al4Zt8S_oRsP4jdONhcJngAAAEU"]
[Mon Jul 20 06:51:03.752402 2026] [security2:error] [pid 1020501:tid 1020738] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Zt8S_oRsP4jdONhcJmQAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:03.778264 2026] [security2:error] [pid 1025331:tid 1025479] [client 14.225.17.146:58310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4ZtkOu5aQNSViFaxNbBgAAARw"], referer: http://nikkidesigns.net/NEW
[Mon Jul 20 06:51:03.794515 2026] [security2:error] [pid 1025331:tid 1025467] [client 57.141.18.107:57000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZskOu5aQNSViFaxNaKAABEAk"]
[Mon Jul 20 06:51:03.857432 2026] [security2:error] [pid 1025331:tid 1025473] [client 34.73.38.214:58533] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Zt0Ou5aQNSViFaxNbWgAAARY"]
[Mon Jul 20 06:51:03.910496 2026] [security2:error] [pid 1020501:tid 1020663] [client 34.139.11.221:51101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Zt8S_oRsP4jdONhcJpgAAAB4"]
[Mon Jul 20 06:51:03.987388 2026] [security2:error] [pid 1025331:tid 1025540] [client 8.228.127.164:64806] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Zt0Ou5aQNSViFaxNbYQAAAVk"]
[Mon Jul 20 06:51:04.042705 2026] [security2:error] [pid 1025331:tid 1025536] [client 34.139.11.221:55103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbYwAAAVU"]
[Mon Jul 20 06:51:04.058518 2026] [security2:error] [pid 1020501:tid 1020650] [client 157.85.211.87:8760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.211.85.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZuMS_oRsP4jdONhcJqQAAABE"]
[Mon Jul 20 06:51:04.058640 2026] [security2:error] [pid 1020501:tid 1020650] [client 157.85.211.87:8760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZuMS_oRsP4jdONhcJqQAAABE"]
[Mon Jul 20 06:51:04.092078 2026] [security2:error] [pid 1025331:tid 1025529] [client 77.110.127.138:58238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZuEOu5aQNSViFaxNbZAAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:04.092181 2026] [security2:error] [pid 1025331:tid 1025529] [client 77.110.127.138:58238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZuEOu5aQNSViFaxNbZAAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:04.180704 2026] [security2:error] [pid 1020501:tid 1020747] [client 161.118.218.103:60432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZuMS_oRsP4jdONhcJqgAAAHI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:04.194218 2026] [security2:error] [pid 1025331:tid 1025503] [client 8.228.127.164:50432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbbAAAATQ"]
[Mon Jul 20 06:51:04.198706 2026] [security2:error] [pid 1025331:tid 1025560] [client 34.139.11.221:58708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbbQAAAW0"]
[Mon Jul 20 06:51:04.285903 2026] [security2:error] [pid 1025331:tid 1025353] [remote 5.252.52.249:42386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4ZuEOu5aQNSViFaxNbdgABOxU"]
[Mon Jul 20 06:51:04.312782 2026] [security2:error] [pid 1025331:tid 1025576] [client 34.139.11.221:58437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbeAAAAX0"]
[Mon Jul 20 06:51:04.330713 2026] [security2:error] [pid 1025331:tid 1025567] [client 8.228.127.164:54234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbeQAAAXQ"]
[Mon Jul 20 06:51:04.452728 2026] [security2:error] [pid 1025331:tid 1025523] [client 34.139.11.221:60201] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbfQAAAUg"]
[Mon Jul 20 06:51:04.511395 2026] [security2:error] [pid 1020501:tid 1020720] [client 8.228.127.164:53864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "emil.manasyan.uk"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuMS_oRsP4jdONhcJtQAAAFc"]
[Mon Jul 20 06:51:04.570885 2026] [security2:error] [pid 1025331:tid 1025587] [client 34.139.11.221:58581] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbigAAAYg"]
[Mon Jul 20 06:51:04.572464 2026] [security2:error] [pid 1020501:tid 1020682] [client 77.110.127.138:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZuMS_oRsP4jdONhcJtwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:04.572569 2026] [security2:error] [pid 1020501:tid 1020682] [client 77.110.127.138:58243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZuMS_oRsP4jdONhcJtwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:04.704599 2026] [security2:error] [pid 1020501:tid 1020661] [client 34.139.11.221:51226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuMS_oRsP4jdONhcJvAAAABw"]
[Mon Jul 20 06:51:04.761629 2026] [security2:error] [pid 1025331:tid 1025493] [client 161.118.218.103:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZuEOu5aQNSViFaxNbkgAAASo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:04.811271 2026] [security2:error] [pid 1025331:tid 1025357] [remote 5.252.52.249:42386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4ZuEOu5aQNSViFaxNblAABShk"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:51:04.839551 2026] [security2:error] [pid 1025331:tid 1025551] [client 34.73.38.214:50371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNblwAAAWQ"]
[Mon Jul 20 06:51:04.866448 2026] [security2:error] [pid 1025331:tid 1025472] [client 34.139.11.221:59656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbngAAARU"]
[Mon Jul 20 06:51:04.974169 2026] [lsapi:warn] [pid 1025331:tid 1025550] [client 14.225.17.146:56912] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/NEW
[Mon Jul 20 06:51:04.974196 2026] [lsapi:warn] [pid 1025331:tid 1025550] [client 14.225.17.146:56912] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/NEW
[Mon Jul 20 06:51:04.994538 2026] [security2:error] [pid 1025331:tid 1025537] [client 34.139.11.221:55387] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuEOu5aQNSViFaxNbqgAAAVY"]
[Mon Jul 20 06:51:04.996392 2026] [security2:error] [pid 1025331:tid 1025498] [client 57.141.18.113:53772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtEOu5aQNSViFaxNaewABL1A"]
[Mon Jul 20 06:51:05.121958 2026] [security2:error] [pid 1020501:tid 1020697] [client 34.139.11.221:54577] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZucS_oRsP4jdONhcJxgAAAEA"]
[Mon Jul 20 06:51:05.147849 2026] [security2:error] [pid 1025331:tid 1025483] [client 104.234.53.68:37729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZuUOu5aQNSViFaxNbrAAAASA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:05.187494 2026] [security2:error] [pid 1020501:tid 1020703] [client 77.110.127.138:58245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZucS_oRsP4jdONhcJxwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:05.187601 2026] [security2:error] [pid 1020501:tid 1020703] [client 77.110.127.138:58245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZucS_oRsP4jdONhcJxwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:05.230937 2026] [security2:error] [pid 1025331:tid 1025527] [client 34.139.11.221:61069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.poopatrol608.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZuUOu5aQNSViFaxNbswAAAUw"]
[Mon Jul 20 06:51:05.238508 2026] [security2:error] [pid 1020501:tid 1020716] [client 77.110.127.138:58246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZucS_oRsP4jdONhcJyQAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:05.337114 2026] [security2:error] [pid 1025331:tid 1025491] [client 161.118.218.103:61141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZuUOu5aQNSViFaxNbuwAAASg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:05.372744 2026] [security2:error] [pid 1020501:tid 1020676] [client 50.116.65.227:35822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZucS_oRsP4jdONhcJyAAAACs"]
[Mon Jul 20 06:51:05.438576 2026] [security2:error] [pid 1025331:tid 1025478] [client 104.234.53.68:37729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZuUOu5aQNSViFaxNbvgAAARs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:05.495389 2026] [lsapi:warn] [pid 1025331:tid 1025472] [client 50.116.65.227:35836] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:51:05.495435 2026] [lsapi:warn] [pid 1025331:tid 1025472] [client 50.116.65.227:35836] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:51:05.511231 2026] [security2:error] [pid 1025331:tid 1025550] [client 14.225.17.146:56912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4ZuEOu5aQNSViFaxNbfwAAAWM"], referer: http://oswegooperatheater.com/NEW
[Mon Jul 20 06:51:05.567276 2026] [security2:error] [pid 1020501:tid 1020688] [client 50.116.65.227:35824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ZucS_oRsP4jdONhcJzQAAADc"]
[Mon Jul 20 06:51:05.629234 2026] [security2:error] [pid 1020501:tid 1020689] [client 14.225.17.146:58708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4Zt8S_oRsP4jdONhcJmAAAADg"], referer: http://younutrition.gr/NEW
[Mon Jul 20 06:51:05.702158 2026] [security2:error] [pid 1025331:tid 1025546] [client 57.141.18.1:60256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtEOu5aQNSViFaxNasgABXwg"]
[Mon Jul 20 06:51:05.798531 2026] [security2:error] [pid 1025331:tid 1025512] [client 77.110.127.138:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZuUOu5aQNSViFaxNb1wAAAT0"]
[Mon Jul 20 06:51:05.798626 2026] [security2:error] [pid 1025331:tid 1025512] [client 77.110.127.138:58249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZuUOu5aQNSViFaxNb1wAAAT0"]
[Mon Jul 20 06:51:05.801861 2026] [security2:error] [pid 1020501:tid 1020672] [client 34.73.38.214:54906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZucS_oRsP4jdONhcJ1wAAACc"]
[Mon Jul 20 06:51:05.821449 2026] [security2:error] [pid 1025331:tid 1025468] [client 14.225.17.146:59022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4ZuEOu5aQNSViFaxNbZgAAARE"], referer: http://fluidtemple.org/NEW
[Mon Jul 20 06:51:05.913895 2026] [security2:error] [pid 1025331:tid 1025567] [client 161.118.218.103:61455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZuUOu5aQNSViFaxNb4QAAAXQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:06.156690 2026] [security2:error] [pid 1025331:tid 1025371] [remote 97.74.87.194:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZukOu5aQNSViFaxNb6gABSCc"]
[Mon Jul 20 06:51:06.206625 2026] [security2:error] [pid 1025331:tid 1025564] [client 77.110.127.138:58254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZukOu5aQNSViFaxNb7gAAAXE"]
[Mon Jul 20 06:51:06.206730 2026] [security2:error] [pid 1025331:tid 1025564] [client 77.110.127.138:58254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZukOu5aQNSViFaxNb7gAAAXE"]
[Mon Jul 20 06:51:06.340483 2026] [lsapi:warn] [pid 1025331:tid 1025485] [client 14.225.17.146:50235] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/NEW
[Mon Jul 20 06:51:06.340508 2026] [lsapi:warn] [pid 1025331:tid 1025485] [client 14.225.17.146:50235] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/NEW
[Mon Jul 20 06:51:06.493540 2026] [security2:error] [pid 1020501:tid 1020754] [client 161.118.218.103:61764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZusS_oRsP4jdONhcJ5gAAAHk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:06.496929 2026] [security2:error] [pid 1025331:tid 1025516] [client 57.141.18.39:58253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtUOu5aQNSViFaxNayQABQWs"]
[Mon Jul 20 06:51:06.531517 2026] [security2:error] [pid 1025331:tid 1025443] [remote 97.74.87.194:33164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZukOu5aQNSViFaxNb-wABc28"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:51:06.603928 2026] [proxy:error] [pid 1025331:tid 1025568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:06.603982 2026] [proxy_http:error] [pid 1025331:tid 1025568] [client 34.73.38.214:55838] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:06.604397 2026] [proxy:error] [pid 1025331:tid 1025568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:06.604431 2026] [proxy_http:error] [pid 1025331:tid 1025568] [client 34.73.38.214:55838] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:06.639452 2026] [security2:error] [pid 1020501:tid 1020737] [client 34.73.38.214:63525] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZusS_oRsP4jdONhcJ6gAAAGg"]
[Mon Jul 20 06:51:06.658053 2026] [security2:error] [pid 1025331:tid 1025474] [client 77.110.127.138:58256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampX5bE0Gwj')) OR 149. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 149 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZukOu5aQNSViFaxNcBQAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:06.753531 2026] [security2:error] [pid 1025331:tid 1025539] [client 57.141.18.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ZukOu5aQNSViFaxNcAgAAAVg"]
[Mon Jul 20 06:51:06.866167 2026] [security2:error] [pid 1025331:tid 1025487] [client 57.141.18.2:37970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtUOu5aQNSViFaxNa3QABJCw"]
[Mon Jul 20 06:51:06.871953 2026] [security2:error] [pid 1025331:tid 1025496] [client 77.110.127.138:58257] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZukOu5aQNSViFaxNcGAAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:06.944471 2026] [security2:error] [pid 1025331:tid 1025559] [client 152.58.191.29:60345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZukOu5aQNSViFaxNcHgAAAWw"]
[Mon Jul 20 06:51:06.944597 2026] [security2:error] [pid 1025331:tid 1025559] [client 152.58.191.29:60345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZukOu5aQNSViFaxNcHgAAAWw"]
[Mon Jul 20 06:51:07.074968 2026] [security2:error] [pid 1025331:tid 1025465] [client 161.118.218.103:62128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcLQAAAQ4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:07.080558 2026] [security2:error] [pid 1025331:tid 1025531] [client 57.141.18.93:63428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtUOu5aQNSViFaxNa5wABUE4"]
[Mon Jul 20 06:51:07.289245 2026] [security2:error] [pid 1025331:tid 1025550] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcKAAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:07.360328 2026] [security2:error] [pid 1020501:tid 1020709] [client 14.225.17.146:55114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4ZucS_oRsP4jdONhcJ0QAAAEw"], referer: http://koaconsultants.com/NEW
[Mon Jul 20 06:51:07.578188 2026] [security2:error] [pid 1025331:tid 1025475] [client 34.73.38.214:52607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Zu0Ou5aQNSViFaxNcSAAAARg"]
[Mon Jul 20 06:51:07.580676 2026] [proxy:error] [pid 1025331:tid 1025483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:07.580767 2026] [proxy_http:error] [pid 1025331:tid 1025483] [client 34.73.38.214:53544] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:07.581233 2026] [proxy:error] [pid 1025331:tid 1025483] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:07.581264 2026] [proxy_http:error] [pid 1025331:tid 1025483] [client 34.73.38.214:53544] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:07.625030 2026] [security2:error] [pid 1025331:tid 1025573] [client 57.141.18.109:27870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtkOu5aQNSViFaxNbCQABem0"]
[Mon Jul 20 06:51:07.659135 2026] [security2:error] [pid 1025331:tid 1025462] [client 161.118.218.103:62520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcUAAAAQs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:07.805823 2026] [security2:error] [pid 1025331:tid 1025548] [client 57.141.18.45:37408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZtkOu5aQNSViFaxNbFwABYVs"]
[Mon Jul 20 06:51:07.817006 2026] [proxy:error] [pid 1025331:tid 1025529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:07.817111 2026] [proxy_http:error] [pid 1025331:tid 1025529] [client 34.73.38.214:65319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:07.817566 2026] [proxy:error] [pid 1025331:tid 1025529] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:07.817593 2026] [proxy_http:error] [pid 1025331:tid 1025529] [client 34.73.38.214:65319] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:07.931634 2026] [security2:error] [pid 1025331:tid 1025584] [client 98.159.234.160:56663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcZQAAAYU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:51:07.953923 2026] [security2:error] [pid 1020501:tid 1020675] [client 14.225.17.146:61102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4Zu8S_oRsP4jdONhcKAAAAACo"]
[Mon Jul 20 06:51:07.964735 2026] [security2:error] [pid 1025331:tid 1025487] [client 37.52.210.45:57564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcaAAAASQ"]
[Mon Jul 20 06:51:07.964834 2026] [security2:error] [pid 1025331:tid 1025487] [client 37.52.210.45:57564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcaAAAASQ"]
[Mon Jul 20 06:51:08.248126 2026] [security2:error] [pid 1025331:tid 1025499] [client 161.118.218.103:62924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZvEOu5aQNSViFaxNcegAAATA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:08.368699 2026] [security2:error] [pid 1020501:tid 1020666] [client 77.110.127.138:58263] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZvMS_oRsP4jdONhcKDgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:08.689152 2026] [security2:error] [pid 1025331:tid 1025408] [remote 45.90.123.233:53070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4ZvEOu5aQNSViFaxNcmQABM0w"]
[Mon Jul 20 06:51:08.824588 2026] [security2:error] [pid 1025331:tid 1025561] [client 161.118.218.103:63278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZvEOu5aQNSViFaxNcqgAAAW4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:08.876028 2026] [proxy:error] [pid 1025331:tid 1025534] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:08.876120 2026] [proxy_http:error] [pid 1025331:tid 1025534] [client 34.73.38.214:65428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:08.876691 2026] [proxy:error] [pid 1025331:tid 1025534] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:08.876719 2026] [proxy_http:error] [pid 1025331:tid 1025534] [client 34.73.38.214:65428] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:08.880058 2026] [security2:error] [pid 1025331:tid 1025531] [client 50.116.65.227:35896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZvEOu5aQNSViFaxNcsQAAAVA"]
[Mon Jul 20 06:51:08.885874 2026] [security2:error] [pid 1025331:tid 1025505] [client 106.219.188.178:42206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvEOu5aQNSViFaxNcsgAAATY"]
[Mon Jul 20 06:51:08.892875 2026] [security2:error] [pid 1025331:tid 1025492] [client 50.116.65.227:35904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZvEOu5aQNSViFaxNcswAAASk"]
[Mon Jul 20 06:51:08.902355 2026] [security2:error] [pid 1025331:tid 1025505] [client 106.219.188.178:42206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvEOu5aQNSViFaxNcsgAAATY"]
[Mon Jul 20 06:51:08.996764 2026] [security2:error] [pid 1025331:tid 1025508] [client 35.162.140.124:17168] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/"] [unique_id "al4ZvEOu5aQNSViFaxNcugAAATk"]
[Mon Jul 20 06:51:09.016504 2026] [security2:error] [pid 1025331:tid 1025436] [remote 192.241.143.148:42148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZvUOu5aQNSViFaxNcuwABRGg"]
[Mon Jul 20 06:51:09.036516 2026] [security2:error] [pid 1025331:tid 1025397] [remote 45.90.123.233:53070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4ZvUOu5aQNSViFaxNcvQABMUE"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 06:51:09.068210 2026] [security2:error] [pid 1020501:tid 1020661] [client 14.225.17.146:60964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4Zu8S_oRsP4jdONhcJ-wAAABw"], referer: http://tntcatholic.com/NEW
[Mon Jul 20 06:51:09.131882 2026] [security2:error] [pid 1025331:tid 1025526] [client 34.73.38.214:62950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZvUOu5aQNSViFaxNcwAAAAUs"]
[Mon Jul 20 06:51:09.162249 2026] [proxy:error] [pid 1025331:tid 1025541] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:09.162329 2026] [proxy_http:error] [pid 1025331:tid 1025541] [client 34.73.38.214:53418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:09.162935 2026] [proxy:error] [pid 1025331:tid 1025541] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:09.162964 2026] [proxy_http:error] [pid 1025331:tid 1025541] [client 34.73.38.214:53418] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:09.202991 2026] [security2:error] [pid 1025331:tid 1025370] [remote 192.241.143.148:42148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ZvUOu5aQNSViFaxNcywABTyY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:51:09.246402 2026] [security2:error] [pid 1025331:tid 1025495] [client 14.225.17.146:49766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4ZvUOu5aQNSViFaxNcxQAAASw"], referer: http://claysharecon.com/NEW
[Mon Jul 20 06:51:09.400473 2026] [security2:error] [pid 1020501:tid 1020670] [client 161.118.218.103:63677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZvcS_oRsP4jdONhcKJwAAACU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:09.556534 2026] [security2:error] [pid 1025331:tid 1025467] [client 57.141.18.96:41456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZuEOu5aQNSViFaxNbhQABEAA"]
[Mon Jul 20 06:51:09.659129 2026] [proxy:error] [pid 1025331:tid 1025559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:09.659204 2026] [proxy_http:error] [pid 1025331:tid 1025559] [client 34.73.38.214:61187] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:09.659682 2026] [proxy:error] [pid 1025331:tid 1025559] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:09.659725 2026] [proxy_http:error] [pid 1025331:tid 1025559] [client 34.73.38.214:61187] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:09.710299 2026] [security2:error] [pid 1025331:tid 1025537] [client 77.110.127.138:58267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZvUOu5aQNSViFaxNc7QAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:09.710392 2026] [security2:error] [pid 1025331:tid 1025537] [client 77.110.127.138:58267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZvUOu5aQNSViFaxNc7QAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:09.814743 2026] [security2:error] [pid 1020501:tid 1020724] [client 35.162.140.124:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4ZvcS_oRsP4jdONhcKIAAAAFs"], referer: http://koaconsultants.com/?rnd=1784551868886
[Mon Jul 20 06:51:09.823311 2026] [security2:error] [pid 1025331:tid 1025546] [client 35.162.140.124:56864] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koaconsultants.com"] [uri "/"] [unique_id "al4ZvUOu5aQNSViFaxNcygAAAV8"], referer: http://koaconsultants.com/?rnd=1784551868886
[Mon Jul 20 06:51:09.825496 2026] [security2:error] [pid 1025331:tid 1025582] [client 57.141.18.1:25154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZuEOu5aQNSViFaxNbmwABg3Y"]
[Mon Jul 20 06:51:09.980209 2026] [security2:error] [pid 1020501:tid 1020635] [client 161.118.218.103:64070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZvcS_oRsP4jdONhcKPQAAAAI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:09.981831 2026] [security2:error] [pid 1025331:tid 1025588] [client 122.183.32.225:32979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvUOu5aQNSViFaxNc-QAAAYk"]
[Mon Jul 20 06:51:09.981928 2026] [security2:error] [pid 1025331:tid 1025588] [client 122.183.32.225:32979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvUOu5aQNSViFaxNc-QAAAYk"]
[Mon Jul 20 06:51:09.991431 2026] [security2:error] [pid 1020501:tid 1020717] [client 34.73.38.214:57854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZvcS_oRsP4jdONhcKPgAAAFQ"]
[Mon Jul 20 06:51:10.024229 2026] [security2:error] [pid 1020501:tid 1020691] [client 34.73.38.214:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.sarahmusica.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvsS_oRsP4jdONhcKQQAAADo"]
[Mon Jul 20 06:51:10.213183 2026] [security2:error] [pid 1025331:tid 1025523] [client 223.185.13.213:21984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdBwAAAUg"]
[Mon Jul 20 06:51:10.213283 2026] [security2:error] [pid 1025331:tid 1025523] [client 223.185.13.213:21984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdBwAAAUg"]
[Mon Jul 20 06:51:10.237023 2026] [security2:error] [pid 1020501:tid 1020704] [client 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "undefeatedthe.com"] [uri "/.well-known/about.php"] [unique_id "al4ZvsS_oRsP4jdONhcKRwAAAEc"]
[Mon Jul 20 06:51:10.237132 2026] [security2:error] [pid 1020501:tid 1020704] [client 20.151.10.161:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "undefeatedthe.com"] [uri "/.well-known/about.php"] [unique_id "al4ZvsS_oRsP4jdONhcKRwAAAEc"]
[Mon Jul 20 06:51:10.282957 2026] [security2:error] [pid 1025331:tid 1025380] [remote 57.141.18.2:63594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2884714"] [unique_id "al4ZvkOu5aQNSViFaxNdCgABcDA"]
[Mon Jul 20 06:51:10.321125 2026] [security2:error] [pid 1020501:tid 1020668] [client 202.46.92.242:62146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvsS_oRsP4jdONhcKSgAAACM"]
[Mon Jul 20 06:51:10.321264 2026] [security2:error] [pid 1020501:tid 1020668] [client 202.46.92.242:62146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvsS_oRsP4jdONhcKSgAAACM"]
[Mon Jul 20 06:51:10.365848 2026] [security2:error] [pid 1025331:tid 1025530] [client 183.82.98.154:63803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdEAAAAU8"]
[Mon Jul 20 06:51:10.365976 2026] [security2:error] [pid 1025331:tid 1025530] [client 183.82.98.154:63803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdEAAAAU8"]
[Mon Jul 20 06:51:10.412114 2026] [security2:error] [pid 1020501:tid 1020695] [client 104.234.53.54:44795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZvsS_oRsP4jdONhcKSwAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:10.472606 2026] [security2:error] [pid 1025331:tid 1025526] [client 77.110.127.138:58273] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ZvkOu5aQNSViFaxNdFgAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:10.476399 2026] [security2:error] [pid 1025331:tid 1025422] [remote 20.89.80.94:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ZvkOu5aQNSViFaxNdFAABclo"]
[Mon Jul 20 06:51:10.556956 2026] [security2:error] [pid 1025331:tid 1025559] [client 161.118.218.103:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZvkOu5aQNSViFaxNdGQAAAWw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:10.688029 2026] [security2:error] [pid 1020501:tid 1020677] [client 34.73.38.214:50027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvsS_oRsP4jdONhcKWAAAACw"]
[Mon Jul 20 06:51:10.688991 2026] [security2:error] [pid 1025331:tid 1025467] [client 217.142.18.172:35014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdMwAAARA"]
[Mon Jul 20 06:51:10.689101 2026] [security2:error] [pid 1025331:tid 1025467] [client 217.142.18.172:35014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdMwAAARA"]
[Mon Jul 20 06:51:10.769159 2026] [security2:error] [pid 1025331:tid 1025532] [client 57.141.18.63:64814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZuUOu5aQNSViFaxNbygABUUc"]
[Mon Jul 20 06:51:10.808575 2026] [security2:error] [pid 1025331:tid 1025483] [client 14.251.3.155:54741] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZvkOu5aQNSViFaxNdPQAAASA"]
[Mon Jul 20 06:51:10.837647 2026] [security2:error] [pid 1025331:tid 1025452] [remote 20.89.80.94:10535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4ZvkOu5aQNSViFaxNdQQABQng"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:51:10.898419 2026] [security2:error] [pid 1025331:tid 1025470] [client 39.48.81.23:60495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdRAAAARM"]
[Mon Jul 20 06:51:10.898839 2026] [security2:error] [pid 1025331:tid 1025470] [client 39.48.81.23:60495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZvkOu5aQNSViFaxNdRAAAARM"]
[Mon Jul 20 06:51:10.925921 2026] [security2:error] [pid 1025331:tid 1025553] [client 57.141.18.0:49580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZuUOu5aQNSViFaxNb2wABZjs"]
[Mon Jul 20 06:51:11.032491 2026] [security2:error] [pid 1020501:tid 1020652] [client 34.73.38.214:57595] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.rzj.zfx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Zv8S_oRsP4jdONhcKZwAAABM"]
[Mon Jul 20 06:51:11.033836 2026] [security2:error] [pid 1020501:tid 1020730] [client 34.73.38.214:56898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Zv8S_oRsP4jdONhcKaAAAAGE"]
[Mon Jul 20 06:51:11.095409 2026] [security2:error] [pid 1020501:tid 1020734] [client 14.225.17.146:61267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4ZvcS_oRsP4jdONhcKLwAAAGU"], referer: http://alexsandbergmusic.com/NEW
[Mon Jul 20 06:51:11.119020 2026] [security2:error] [pid 1020501:tid 1020678] [client 74.208.214.194:39290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Zv8S_oRsP4jdONhcKawAAAC0"]
[Mon Jul 20 06:51:11.142101 2026] [security2:error] [pid 1025331:tid 1025563] [client 161.118.218.103:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdTgAAAXA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:11.333293 2026] [security2:error] [pid 1025331:tid 1025548] [client 197.186.66.42:61573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdXAAAAWE"]
[Mon Jul 20 06:51:11.333979 2026] [security2:error] [pid 1025331:tid 1025548] [client 197.186.66.42:61573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdXAAAAWE"]
[Mon Jul 20 06:51:11.404822 2026] [security2:error] [pid 1025331:tid 1025498] [client 117.247.108.24:22004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdYwAAAS8"]
[Mon Jul 20 06:51:11.404991 2026] [security2:error] [pid 1025331:tid 1025498] [client 117.247.108.24:22004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdYwAAAS8"]
[Mon Jul 20 06:51:11.591462 2026] [security2:error] [pid 1025331:tid 1025539] [client 34.73.38.214:64794] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Zv0Ou5aQNSViFaxNdbAAAAVg"]
[Mon Jul 20 06:51:11.608216 2026] [security2:error] [pid 1025331:tid 1025470] [client 34.73.38.214:54042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Zv0Ou5aQNSViFaxNdbgAAARM"]
[Mon Jul 20 06:51:11.718223 2026] [security2:error] [pid 1025331:tid 1025483] [client 161.118.218.103:65130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zv0Ou5aQNSViFaxNddAAAASA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:11.835518 2026] [security2:error] [pid 1025331:tid 1025540] [client 57.141.18.60:39842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZukOu5aQNSViFaxNcIwABWSE"]
[Mon Jul 20 06:51:11.910505 2026] [security2:error] [pid 1025331:tid 1025577] [client 103.125.179.95:54044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdfQAAAX4"]
[Mon Jul 20 06:51:11.910627 2026] [security2:error] [pid 1025331:tid 1025577] [client 103.125.179.95:54044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdfQAAAX4"]
[Mon Jul 20 06:51:11.924727 2026] [security2:error] [pid 1025331:tid 1025491] [client 192.140.149.97:45945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdggAAASg"]
[Mon Jul 20 06:51:11.924895 2026] [security2:error] [pid 1025331:tid 1025491] [client 192.140.149.97:45945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Zv0Ou5aQNSViFaxNdggAAASg"]
[Mon Jul 20 06:51:12.001402 2026] [security2:error] [pid 1020501:tid 1020651] [client 57.141.18.4:28546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zu8S_oRsP4jdONhcJ9gAAEi8"]
[Mon Jul 20 06:51:12.106735 2026] [security2:error] [pid 1025331:tid 1025482] [client 14.225.17.146:49319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4ZvkOu5aQNSViFaxNdEgAAAR8"], referer: http://cheesewithjam.com/NEW
[Mon Jul 20 06:51:12.295496 2026] [security2:error] [pid 1025331:tid 1025504] [client 161.118.218.103:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZwEOu5aQNSViFaxNdmAAAATU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:12.324895 2026] [security2:error] [pid 1025331:tid 1025572] [client 14.225.17.146:60863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4ZwEOu5aQNSViFaxNdhgAAAXk"], referer: http://maxenengineering.com/NEW
[Mon Jul 20 06:51:12.371606 2026] [security2:error] [pid 1025331:tid 1025466] [client 57.141.18.99:55038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcQwABDxA"]
[Mon Jul 20 06:51:12.492446 2026] [security2:error] [pid 1025331:tid 1025477] [client 34.73.38.214:64807] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwEOu5aQNSViFaxNdoQAAARo"]
[Mon Jul 20 06:51:12.541222 2026] [security2:error] [pid 1025331:tid 1025578] [client 34.73.38.214:55124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwEOu5aQNSViFaxNdogAAAX8"]
[Mon Jul 20 06:51:12.679708 2026] [security2:error] [pid 1025331:tid 1025545] [client 103.238.106.162:63718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZwEOu5aQNSViFaxNdrAAAAV4"]
[Mon Jul 20 06:51:12.679810 2026] [security2:error] [pid 1025331:tid 1025545] [client 103.238.106.162:63718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ZwEOu5aQNSViFaxNdrAAAAV4"]
[Mon Jul 20 06:51:12.740617 2026] [security2:error] [pid 1025331:tid 1025566] [client 57.141.18.121:44420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zu0Ou5aQNSViFaxNcYAABc0I"]
[Mon Jul 20 06:51:12.870065 2026] [security2:error] [pid 1020501:tid 1020700] [client 161.118.218.103:49426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZwMS_oRsP4jdONhcKhAAAAEM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:12.949742 2026] [security2:error] [pid 1025331:tid 1025539] [client 34.73.38.214:56935] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwEOu5aQNSViFaxNduwAAAVg"]
[Mon Jul 20 06:51:12.950327 2026] [security2:error] [pid 1025331:tid 1025535] [client 34.73.38.214:57518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwEOu5aQNSViFaxNdvAAAAVQ"]
[Mon Jul 20 06:51:13.233455 2026] [security2:error] [pid 1025331:tid 1025493] [client 57.141.18.25:32508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZvEOu5aQNSViFaxNcdgABKko"]
[Mon Jul 20 06:51:13.280970 2026] [security2:error] [pid 1020501:tid 1020707] [client 14.225.17.146:54849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4ZwcS_oRsP4jdONhcKiwAAAEo"], referer: https://maxenengineering.com/NEW
[Mon Jul 20 06:51:13.347657 2026] [security2:error] [pid 1020501:tid 1020672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZwcS_oRsP4jdONhcKiAAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:13.451382 2026] [security2:error] [pid 1025331:tid 1025551] [client 161.118.218.103:49783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZwUOu5aQNSViFaxNd2AAAAWQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:13.604654 2026] [security2:error] [pid 1025331:tid 1025469] [client 57.141.18.99:55054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZvEOu5aQNSViFaxNckQABEgU"]
[Mon Jul 20 06:51:13.626373 2026] [security2:error] [pid 1025331:tid 1025486] [client 34.73.38.214:57029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwUOu5aQNSViFaxNd4QAAASM"]
[Mon Jul 20 06:51:13.691631 2026] [security2:error] [pid 1025331:tid 1025526] [client 14.225.17.146:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4ZwUOu5aQNSViFaxNd3QAAAUs"], referer: http://colinkeyphotography.com/NEW
[Mon Jul 20 06:51:13.732111 2026] [security2:error] [pid 1020501:tid 1020710] [client 34.73.38.214:62970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwcS_oRsP4jdONhcKpAAAAE0"]
[Mon Jul 20 06:51:13.792536 2026] [security2:error] [pid 1025331:tid 1025472] [client 187.108.85.186:57006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZwUOu5aQNSViFaxNd7wAAARU"]
[Mon Jul 20 06:51:13.792697 2026] [security2:error] [pid 1025331:tid 1025472] [client 187.108.85.186:57006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZwUOu5aQNSViFaxNd7wAAARU"]
[Mon Jul 20 06:51:13.961408 2026] [security2:error] [pid 1025331:tid 1025488] [client 104.234.53.64:64599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ZwUOu5aQNSViFaxNd9gAAASU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:14.021165 2026] [security2:error] [pid 1025331:tid 1025357] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZwkOu5aQNSViFaxNd-gABiBk"]
[Mon Jul 20 06:51:14.021352 2026] [security2:error] [pid 1025331:tid 1025587] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZwkOu5aQNSViFaxNd-gABiBk"]
[Mon Jul 20 06:51:14.030969 2026] [security2:error] [pid 1025331:tid 1025555] [client 161.118.218.103:50103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZwkOu5aQNSViFaxNd-wAAAWg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:14.160396 2026] [security2:error] [pid 1020501:tid 1020691] [client 77.110.127.138:58293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZwsS_oRsP4jdONhcKrQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:14.160531 2026] [security2:error] [pid 1020501:tid 1020691] [client 77.110.127.138:58293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZwsS_oRsP4jdONhcKrQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:14.255067 2026] [core:error] [pid 1020501:tid 1020733] [client 103.153.183.69:43528] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%uff0e%uff0e/%uff0e%uff0e/etc/passwd?_=bxoy79jm&v=h2lwv), referer: https://www.reddit.com/
[Mon Jul 20 06:51:14.258472 2026] [security2:error] [pid 1025331:tid 1025551] [client 127.0.0.1:41744] ModSecurity: Access denied with code 406 (phase 2). Match of "rx (%uFFFD)" against "MATCHED_VAR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "100"] [id "390621"] [rev "5"] [msg "Atomicorp.com WAF Rules: Unicode Width Attack Attempt"] [data "%uff0e"] [severity "WARNING"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4ZwkOu5aQNSViFaxNeBQAAAWQ"], referer: https://www.reddit.com/
[Mon Jul 20 06:51:14.343350 2026] [security2:error] [pid 1020501:tid 1020676] [client 77.110.127.138:58296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZwsS_oRsP4jdONhcKtQAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:14.343461 2026] [security2:error] [pid 1020501:tid 1020676] [client 77.110.127.138:58296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZwsS_oRsP4jdONhcKtQAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:14.585272 2026] [security2:error] [pid 1025331:tid 1025585] [client 34.73.38.214:54460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZwkOu5aQNSViFaxNeIwAAAYY"]
[Mon Jul 20 06:51:14.612813 2026] [security2:error] [pid 1020501:tid 1020680] [client 14.225.17.146:55331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4ZwsS_oRsP4jdONhcKuAAAAC8"], referer: http://dasmarque.com/NEW
[Mon Jul 20 06:51:14.614449 2026] [security2:error] [pid 1025331:tid 1025486] [client 161.118.218.103:50439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZwkOu5aQNSViFaxNeJAAAASM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:14.758744 2026] [security2:error] [pid 1025331:tid 1025563] [client 104.234.53.52:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ZwkOu5aQNSViFaxNeKwAAAXA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:14.885972 2026] [security2:error] [pid 1025331:tid 1025555] [client 77.110.127.138:58302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZwkOu5aQNSViFaxNeLwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:14.886093 2026] [security2:error] [pid 1025331:tid 1025555] [client 77.110.127.138:58302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZwkOu5aQNSViFaxNeLwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:15.072639 2026] [security2:error] [pid 1025331:tid 1025533] [client 34.73.38.214:62601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Zw0Ou5aQNSViFaxNeOQAAAVI"]
[Mon Jul 20 06:51:15.191012 2026] [security2:error] [pid 1025331:tid 1025577] [client 161.118.218.103:50776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zw0Ou5aQNSViFaxNePgAAAX4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:15.295788 2026] [security2:error] [pid 1025331:tid 1025513] [client 82.135.202.97:45890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.202.135.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/shadow/shadow_results.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeRgAAAT4"]
[Mon Jul 20 06:51:15.370414 2026] [security2:error] [pid 1020501:tid 1020634] [client 57.141.18.94:34502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZvsS_oRsP4jdONhcKRAAAATA"]
[Mon Jul 20 06:51:15.415652 2026] [security2:error] [pid 1025331:tid 1025567] [client 77.110.127.138:58303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeSQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:15.415792 2026] [security2:error] [pid 1025331:tid 1025567] [client 77.110.127.138:58303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeSQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:15.767962 2026] [security2:error] [pid 1025331:tid 1025575] [client 161.118.218.103:51099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeYwAAAXw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:15.872541 2026] [security2:error] [pid 1025331:tid 1025346] [remote 95.217.78.234:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeagABIA4"]
[Mon Jul 20 06:51:15.880738 2026] [security2:error] [pid 1025331:tid 1025557] [client 34.73.38.214:54426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Zw0Ou5aQNSViFaxNebQAAAWo"]
[Mon Jul 20 06:51:15.913321 2026] [security2:error] [pid 1025331:tid 1025525] [client 45.3.42.32:48007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeaAAAAUo"]
[Mon Jul 20 06:51:16.149786 2026] [security2:error] [pid 1020501:tid 1020670] [client 57.141.18.48:36418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZvsS_oRsP4jdONhcKZAAAJUU"]
[Mon Jul 20 06:51:16.221928 2026] [security2:error] [pid 1025331:tid 1025565] [client 50.116.65.227:16968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ZxEOu5aQNSViFaxNehQAAAXI"]
[Mon Jul 20 06:51:16.233122 2026] [security2:error] [pid 1025331:tid 1025551] [client 50.116.65.227:16972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ZxEOu5aQNSViFaxNehwAAAWQ"]
[Mon Jul 20 06:51:16.289989 2026] [security2:error] [pid 1025331:tid 1025368] [remote 95.217.78.234:46296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4ZxEOu5aQNSViFaxNeigABfSQ"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:51:16.346970 2026] [security2:error] [pid 1025331:tid 1025571] [client 161.118.218.103:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZxEOu5aQNSViFaxNekQAAAXg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:16.354768 2026] [security2:error] [pid 1025331:tid 1025567] [client 14.225.17.146:62611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4ZxEOu5aQNSViFaxNeiQAAAXQ"], referer: http://friendlyspreadsheet.com/NEW
[Mon Jul 20 06:51:16.359317 2026] [security2:error] [pid 1025331:tid 1025562] [client 57.141.18.82:61476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZvkOu5aQNSViFaxNdRgABb14"]
[Mon Jul 20 06:51:16.384490 2026] [security2:error] [pid 1025331:tid 1025464] [client 14.225.17.146:54779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4ZwkOu5aQNSViFaxNd_QAAAQ0"], referer: http://adastra.love/NEW
[Mon Jul 20 06:51:16.477617 2026] [security2:error] [pid 1025331:tid 1025493] [client 45.3.42.46:31263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ZxEOu5aQNSViFaxNelQAAASo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:51:16.504829 2026] [security2:error] [pid 1020501:tid 1020706] [client 34.73.38.214:57074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4ZxMS_oRsP4jdONhcK2wAAAEk"]
[Mon Jul 20 06:51:16.714744 2026] [security2:error] [pid 1020501:tid 1020730] [client 77.110.127.138:58307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZxMS_oRsP4jdONhcK3wAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:16.714849 2026] [security2:error] [pid 1020501:tid 1020730] [client 77.110.127.138:58307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZxMS_oRsP4jdONhcK3wAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:16.741995 2026] [security2:error] [pid 1025331:tid 1025526] [client 114.119.144.176:62503] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/tours/malaysia-discover/petronas-towers/"] [unique_id "al4ZxEOu5aQNSViFaxNeqQAAAUs"], referer: https://www.savilerowtravel.com/tours/malaysia-discover/petronas-towers/
[Mon Jul 20 06:51:16.777259 2026] [security2:error] [pid 1025331:tid 1025475] [client 34.73.38.214:50434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4ZxEOu5aQNSViFaxNergAAARg"]
[Mon Jul 20 06:51:16.923161 2026] [security2:error] [pid 1025331:tid 1025548] [client 161.118.218.103:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZxEOu5aQNSViFaxNeugAAAWE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:16.923587 2026] [security2:error] [pid 1025331:tid 1025503] [client 34.73.38.214:56536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZxEOu5aQNSViFaxNeuwAAATQ"]
[Mon Jul 20 06:51:17.101911 2026] [security2:error] [pid 1025331:tid 1025579] [client 104.207.51.123:31367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ZxUOu5aQNSViFaxNexAAAAYA"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:51:17.154832 2026] [security2:error] [pid 1020501:tid 1020655] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZxMS_oRsP4jdONhcK5QAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:17.498897 2026] [security2:error] [pid 1025331:tid 1025469] [client 161.118.218.103:52214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZxUOu5aQNSViFaxNe8QAAARI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:17.518792 2026] [security2:error] [pid 1020501:tid 1020744] [client 104.234.53.82:52935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ZxcS_oRsP4jdONhcK7QAAAG8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:17.628688 2026] [security2:error] [pid 1020501:tid 1020675] [client 34.73.38.214:50430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ZxcS_oRsP4jdONhcK8wAAACo"]
[Mon Jul 20 06:51:17.641054 2026] [security2:error] [pid 1020501:tid 1020745] [client 152.58.191.29:36582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZxcS_oRsP4jdONhcK9QAAAHA"]
[Mon Jul 20 06:51:17.641200 2026] [security2:error] [pid 1020501:tid 1020745] [client 152.58.191.29:36582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZxcS_oRsP4jdONhcK9QAAAHA"]
[Mon Jul 20 06:51:17.740775 2026] [security2:error] [pid 1020501:tid 1020674] [client 34.73.38.214:58537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sarahmusica.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ZxcS_oRsP4jdONhcK-AAAACk"]
[Mon Jul 20 06:51:18.061269 2026] [security2:error] [pid 1025331:tid 1025517] [client 57.141.18.84:50224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZwEOu5aQNSViFaxNdrgABQkU"]
[Mon Jul 20 06:51:18.074420 2026] [security2:error] [pid 1025331:tid 1025512] [client 161.118.218.103:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZxkOu5aQNSViFaxNfFAAAAT0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:18.121081 2026] [security2:error] [pid 1025331:tid 1025564] [client 14.225.17.146:54448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4Zw0Ou5aQNSViFaxNeXwAAAXE"], referer: http://gearwaterproof.com/NEW
[Mon Jul 20 06:51:18.166212 2026] [security2:error] [pid 1025331:tid 1025550] [client 57.141.18.72:31158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZwEOu5aQNSViFaxNdtgABYxM"]
[Mon Jul 20 06:51:18.442105 2026] [security2:error] [pid 1025331:tid 1025471] [client 104.234.53.48:27349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZxkOu5aQNSViFaxNfJwAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:18.594920 2026] [security2:error] [pid 1025331:tid 1025477] [client 57.141.18.17:46102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZwUOu5aQNSViFaxNdzAABGkw"]
[Mon Jul 20 06:51:18.597129 2026] [security2:error] [pid 1025331:tid 1025543] [client 37.52.210.45:46092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZxkOu5aQNSViFaxNfLgAAAVw"]
[Mon Jul 20 06:51:18.597229 2026] [security2:error] [pid 1025331:tid 1025543] [client 37.52.210.45:46092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZxkOu5aQNSViFaxNfLgAAAVw"]
[Mon Jul 20 06:51:18.649789 2026] [security2:error] [pid 1025331:tid 1025559] [client 161.118.218.103:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZxkOu5aQNSViFaxNfMgAAAWw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:18.658100 2026] [security2:error] [pid 1025331:tid 1025584] [client 57.141.18.18:64262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZwUOu5aQNSViFaxNdzwABhSk"]
[Mon Jul 20 06:51:18.722134 2026] [security2:error] [pid 1020501:tid 1020662] [client 57.141.18.98:43900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZwcS_oRsP4jdONhcKmgAAHSM"]
[Mon Jul 20 06:51:18.988659 2026] [security2:error] [pid 1025331:tid 1025496] [client 34.73.38.214:54745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4ZxkOu5aQNSViFaxNfRwAAAS0"]
[Mon Jul 20 06:51:19.196943 2026] [security2:error] [pid 1025331:tid 1025560] [client 57.141.18.86:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZwUOu5aQNSViFaxNd8wABbSY"]
[Mon Jul 20 06:51:19.226875 2026] [security2:error] [pid 1025331:tid 1025501] [client 161.118.218.103:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfUAAAATI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:19.495870 2026] [security2:error] [pid 1025331:tid 1025584] [client 34.73.38.214:65481] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.sardimacmillan.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Zx0Ou5aQNSViFaxNfcAAAAYU"]
[Mon Jul 20 06:51:19.669467 2026] [security2:error] [pid 1025331:tid 1025503] [client 106.219.188.178:25951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfeAAAATQ"]
[Mon Jul 20 06:51:19.677168 2026] [security2:error] [pid 1025331:tid 1025503] [client 106.219.188.178:25951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfeAAAATQ"]
[Mon Jul 20 06:51:19.677241 2026] [security2:error] [pid 1025331:tid 1025487] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfZgAAASQ"]
[Mon Jul 20 06:51:19.732143 2026] [security2:error] [pid 1025331:tid 1025576] [client 223.185.13.213:15508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfewAAAX0"]
[Mon Jul 20 06:51:19.732384 2026] [security2:error] [pid 1025331:tid 1025576] [client 223.185.13.213:15508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfewAAAX0"]
[Mon Jul 20 06:51:19.816609 2026] [security2:error] [pid 1025331:tid 1025467] [client 161.118.218.103:53604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zx0Ou5aQNSViFaxNffgAAARA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:19.871565 2026] [security2:error] [pid 1025331:tid 1025578] [client 77.110.127.138:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfgwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:19.871652 2026] [security2:error] [pid 1025331:tid 1025578] [client 77.110.127.138:58313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfgwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:19.899214 2026] [security2:error] [pid 1025331:tid 1025475] [client 216.244.66.203:60242] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/robots.txt"] [unique_id "al4Zx0Ou5aQNSViFaxNfhQAAARg"]
[Mon Jul 20 06:51:19.899316 2026] [security2:error] [pid 1025331:tid 1025475] [client 216.244.66.203:60242] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.samdothan.org"] [uri "/robots.txt"] [unique_id "al4Zx0Ou5aQNSViFaxNfhQAAARg"]
[Mon Jul 20 06:51:20.390460 2026] [security2:error] [pid 1025331:tid 1025518] [client 161.118.218.103:53946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZyEOu5aQNSViFaxNfnAAAAUM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:20.419355 2026] [security2:error] [pid 1025331:tid 1025540] [client 57.141.18.84:50230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zw0Ou5aQNSViFaxNePQABWTA"]
[Mon Jul 20 06:51:20.666125 2026] [security2:error] [pid 1025331:tid 1025588] [client 45.3.54.203:47665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ZyEOu5aQNSViFaxNfrwAAAYk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:51:20.858989 2026] [security2:error] [pid 1025331:tid 1025478] [client 77.110.127.138:58316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZyEOu5aQNSViFaxNfxAAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:20.859082 2026] [security2:error] [pid 1025331:tid 1025478] [client 77.110.127.138:58316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ZyEOu5aQNSViFaxNfxAAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:20.875595 2026] [security2:error] [pid 1020501:tid 1020673] [client 14.225.17.146:54565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4Zx8S_oRsP4jdONhcLHwAAACg"], referer: http://aandarealtygroup.com/NEW
[Mon Jul 20 06:51:20.963038 2026] [security2:error] [pid 1025331:tid 1025475] [client 161.118.218.103:54244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZyEOu5aQNSViFaxNfywAAARg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:21.086384 2026] [security2:error] [pid 1025331:tid 1025452] [remote 47.86.33.52:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ZyUOu5aQNSViFaxNfzgABVng"]
[Mon Jul 20 06:51:21.138789 2026] [security2:error] [pid 1025331:tid 1025463] [client 36.95.228.227:62628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZyUOu5aQNSViFaxNf0wAAAQw"]
[Mon Jul 20 06:51:21.138908 2026] [security2:error] [pid 1025331:tid 1025463] [client 36.95.228.227:62628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ZyUOu5aQNSViFaxNf0wAAAQw"]
[Mon Jul 20 06:51:21.178038 2026] [security2:error] [pid 1025331:tid 1025581] [client 217.142.18.172:30402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZyUOu5aQNSViFaxNf1gAAAYI"]
[Mon Jul 20 06:51:21.178188 2026] [security2:error] [pid 1025331:tid 1025581] [client 217.142.18.172:30402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ZyUOu5aQNSViFaxNf1gAAAYI"]
[Mon Jul 20 06:51:21.312208 2026] [security2:error] [pid 1020501:tid 1020645] [client 39.48.81.23:61034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZycS_oRsP4jdONhcLXgAAAAw"]
[Mon Jul 20 06:51:21.312321 2026] [security2:error] [pid 1020501:tid 1020645] [client 39.48.81.23:61034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ZycS_oRsP4jdONhcLXgAAAAw"]
[Mon Jul 20 06:51:21.320220 2026] [security2:error] [pid 1025331:tid 1025500] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.epu.kzx.mybluehost.me"] [uri "/index.php"] [unique_id "al4ZxkOu5aQNSViFaxNfRQAAATE"]
[Mon Jul 20 06:51:21.407885 2026] [security2:error] [pid 1025331:tid 1025494] [client 49.36.80.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZyUOu5aQNSViFaxNf2AAAASs"], referer: https://mezzacraft.com/about-mezzacraft-crochet/
[Mon Jul 20 06:51:21.536722 2026] [security2:error] [pid 1025331:tid 1025525] [client 161.118.218.103:54577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZyUOu5aQNSViFaxNf6QAAAUo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:21.570060 2026] [security2:error] [pid 1025331:tid 1025557] [client 104.234.53.74:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ZyUOu5aQNSViFaxNf6wAAAWo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:21.771704 2026] [security2:error] [pid 1020501:tid 1020659] [client 14.225.17.146:54519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4ZyMS_oRsP4jdONhcLPgAAABo"], referer: http://superiorcopywriting.com/NEW
[Mon Jul 20 06:51:21.788424 2026] [security2:error] [pid 1025331:tid 1025395] [remote 47.128.121.60:64918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.121.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.adambergeron.com"] [uri "/13540.php"] [unique_id "al4ZyUOu5aQNSViFaxNf-QABFz8"]
[Mon Jul 20 06:51:21.853856 2026] [security2:error] [pid 1025331:tid 1025333] [remote 188.166.241.141:34898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4ZyUOu5aQNSViFaxNgAgABTAE"]
[Mon Jul 20 06:51:22.113394 2026] [security2:error] [pid 1025331:tid 1025572] [client 161.118.218.103:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZykOu5aQNSViFaxNgDwAAAXk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:22.119412 2026] [security2:error] [pid 1025331:tid 1025471] [client 117.247.108.24:23343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZykOu5aQNSViFaxNgDgAAARQ"]
[Mon Jul 20 06:51:22.119538 2026] [security2:error] [pid 1025331:tid 1025471] [client 117.247.108.24:23343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ZykOu5aQNSViFaxNgDgAAARQ"]
[Mon Jul 20 06:51:22.182080 2026] [security2:error] [pid 1020501:tid 1020708] [client 13.229.223.11:17144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZysS_oRsP4jdONhcLbAAAAEs"]
[Mon Jul 20 06:51:22.182260 2026] [security2:error] [pid 1020501:tid 1020708] [client 13.229.223.11:17144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ZysS_oRsP4jdONhcLbAAAAEs"]
[Mon Jul 20 06:51:22.246077 2026] [security2:error] [pid 1025331:tid 1025475] [client 103.125.179.95:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZykOu5aQNSViFaxNgGAAAARg"]
[Mon Jul 20 06:51:22.246227 2026] [security2:error] [pid 1025331:tid 1025475] [client 103.125.179.95:54553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZykOu5aQNSViFaxNgGAAAARg"]
[Mon Jul 20 06:51:22.251148 2026] [security2:error] [pid 1025331:tid 1025358] [remote 188.166.241.141:34898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4ZykOu5aQNSViFaxNgGQABUBo"], referer: https://fansarogroup.com/wp-login.php
[Mon Jul 20 06:51:22.271741 2026] [security2:error] [pid 1025331:tid 1025588] [client 122.183.32.225:4392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZykOu5aQNSViFaxNgGgAAAYk"]
[Mon Jul 20 06:51:22.271880 2026] [security2:error] [pid 1025331:tid 1025588] [client 122.183.32.225:4392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ZykOu5aQNSViFaxNgGgAAAYk"]
[Mon Jul 20 06:51:22.301060 2026] [security2:error] [pid 1025331:tid 1025546] [client 47.128.121.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4ZykOu5aQNSViFaxNgEwAAAV8"], referer: https://www.adambergeron.com/13540.php
[Mon Jul 20 06:51:22.308015 2026] [security2:error] [pid 1025331:tid 1025514] [client 47.128.121.60:64918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/13540.php"] [unique_id "al4ZykOu5aQNSViFaxNgEAABP0Y"], referer: https://www.adambergeron.com/13540.php
[Mon Jul 20 06:51:22.437991 2026] [security2:error] [pid 1025331:tid 1025476] [client 14.225.17.146:54849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4ZyEOu5aQNSViFaxNfyQAAARk"], referer: http://eduardsales.com/NEW
[Mon Jul 20 06:51:22.517413 2026] [security2:error] [pid 1020501:tid 1020701] [client 57.141.18.2:39270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZxMS_oRsP4jdONhcK4wAARAI"]
[Mon Jul 20 06:51:22.688866 2026] [security2:error] [pid 1025331:tid 1025587] [client 161.118.218.103:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZykOu5aQNSViFaxNgNwAAAYg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:22.877091 2026] [security2:error] [pid 1025331:tid 1025534] [client 14.225.17.146:62372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4ZykOu5aQNSViFaxNgLQAAAVM"], referer: http://uritems.net/NEW
[Mon Jul 20 06:51:22.877611 2026] [security2:error] [pid 1025331:tid 1025489] [client 14.225.17.146:49416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4ZyUOu5aQNSViFaxNf5wAAASY"], referer: http://phillipbloch.com/NEW
[Mon Jul 20 06:51:22.899866 2026] [security2:error] [pid 1020501:tid 1020758] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ZysS_oRsP4jdONhcLfAAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:22.901303 2026] [security2:error] [pid 1025331:tid 1025584] [client 14.225.17.146:54969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4ZyEOu5aQNSViFaxNfxgAAAYU"]
[Mon Jul 20 06:51:22.932710 2026] [security2:error] [pid 1025331:tid 1025553] [client 57.141.18.96:57240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZxUOu5aQNSViFaxNe3AABZmI"]
[Mon Jul 20 06:51:23.109871 2026] [security2:error] [pid 1025331:tid 1025341] [remote 47.128.121.60:18972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.121.128.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/13540.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgUgABZQk"], referer: https://www.adambergeron.com/13540.php
[Mon Jul 20 06:51:23.158029 2026] [security2:error] [pid 1025331:tid 1025486] [client 14.225.17.146:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4ZyUOu5aQNSViFaxNf7wAAASM"], referer: http://cephasnext.com/NEW
[Mon Jul 20 06:51:23.178702 2026] [security2:error] [pid 1025331:tid 1025479] [client 103.238.106.162:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgVwAAARw"]
[Mon Jul 20 06:51:23.178877 2026] [security2:error] [pid 1025331:tid 1025479] [client 103.238.106.162:63540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgVwAAARw"]
[Mon Jul 20 06:51:23.224019 2026] [core:error] [pid 1025331:tid 1025512] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.224036 2026] [core:error] [pid 1025331:tid 1025512] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.225523 2026] [core:error] [pid 1020501:tid 1020644] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.225542 2026] [core:error] [pid 1020501:tid 1020644] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.235405 2026] [core:error] [pid 1025331:tid 1025502] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.235429 2026] [core:error] [pid 1025331:tid 1025502] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.257002 2026] [core:error] [pid 1025331:tid 1025522] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.257022 2026] [core:error] [pid 1025331:tid 1025522] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.266350 2026] [security2:error] [pid 1020501:tid 1020739] [client 161.118.218.103:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zy8S_oRsP4jdONhcLoQAAAGo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:23.266781 2026] [core:error] [pid 1020501:tid 1020694] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.266800 2026] [core:error] [pid 1020501:tid 1020694] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:51:23.309345 2026] [security2:error] [pid 1025331:tid 1025466] [client 14.225.17.146:62820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgbwAAAQ8"]
[Mon Jul 20 06:51:23.364300 2026] [security2:error] [pid 1020501:tid 1020733] [client 57.141.18.94:60744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZxcS_oRsP4jdONhcK9wAAZDo"]
[Mon Jul 20 06:51:23.516447 2026] [security2:error] [pid 1020501:tid 1020735] [client 57.141.18.8:39120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZxcS_oRsP4jdONhcK-wAAZhs"]
[Mon Jul 20 06:51:23.594977 2026] [security2:error] [pid 1020501:tid 1020533] [remote 45.119.213.111:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.213.119.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Zy8S_oRsP4jdONhcLtAAATR0"]
[Mon Jul 20 06:51:23.609713 2026] [security2:error] [pid 1025331:tid 1025501] [client 216.73.217.138:18316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNggQABMlY"]
[Mon Jul 20 06:51:23.617862 2026] [security2:error] [pid 1025331:tid 1025557] [client 183.82.98.154:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgjQAAAWo"]
[Mon Jul 20 06:51:23.618006 2026] [security2:error] [pid 1025331:tid 1025557] [client 183.82.98.154:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgjQAAAWo"]
[Mon Jul 20 06:51:23.671138 2026] [security2:error] [pid 1020501:tid 1020695] [client 47.128.121.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4Zy8S_oRsP4jdONhcLsAAAAD4"], referer: https://adambergeron.com/13540.php
[Mon Jul 20 06:51:23.674615 2026] [security2:error] [pid 1025331:tid 1025580] [client 47.128.121.60:18972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/13540.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgggABgUo"], referer: https://adambergeron.com/13540.php
[Mon Jul 20 06:51:23.765412 2026] [security2:error] [pid 1020501:tid 1020651] [client 57.141.18.61:22432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZxcS_oRsP4jdONhcLAAAAEiA"]
[Mon Jul 20 06:51:23.841297 2026] [security2:error] [pid 1020501:tid 1020751] [client 161.118.218.103:55915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zy8S_oRsP4jdONhcLuwAAAHY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:23.865399 2026] [security2:error] [pid 1025331:tid 1025544] [client 14.1.64.100:5878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgeAABXUU"]
[Mon Jul 20 06:51:23.875910 2026] [security2:error] [pid 1025331:tid 1025544] [client 14.1.64.100:5878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgdwABXXk"]
[Mon Jul 20 06:51:23.914335 2026] [security2:error] [pid 1025331:tid 1025497] [client 66.249.73.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drawingthedog.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgnwAAAS4"]
[Mon Jul 20 06:51:24.049009 2026] [security2:error] [pid 1020501:tid 1020547] [remote 45.119.213.111:58718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.213.119.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4ZzMS_oRsP4jdONhcLvwAAFis"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:51:24.080485 2026] [security2:error] [pid 1025331:tid 1025512] [client 197.186.66.42:62103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZzEOu5aQNSViFaxNgvAAAAT0"]
[Mon Jul 20 06:51:24.097393 2026] [security2:error] [pid 1025331:tid 1025512] [client 197.186.66.42:62103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ZzEOu5aQNSViFaxNgvAAAAT0"]
[Mon Jul 20 06:51:24.420956 2026] [security2:error] [pid 1025331:tid 1025511] [client 161.118.218.103:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZzEOu5aQNSViFaxNg2QAAATw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:24.545131 2026] [security2:error] [pid 1025331:tid 1025349] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZzEOu5aQNSViFaxNg6wABLxE"]
[Mon Jul 20 06:51:24.545292 2026] [security2:error] [pid 1025331:tid 1025498] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ZzEOu5aQNSViFaxNg6wABLxE"]
[Mon Jul 20 06:51:24.624761 2026] [security2:error] [pid 1025331:tid 1025497] [client 187.108.85.186:57560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZzEOu5aQNSViFaxNg8gAAAS4"]
[Mon Jul 20 06:51:24.624903 2026] [security2:error] [pid 1025331:tid 1025497] [client 187.108.85.186:57560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ZzEOu5aQNSViFaxNg8gAAAS4"]
[Mon Jul 20 06:51:25.001543 2026] [security2:error] [pid 1025331:tid 1025478] [client 161.118.218.103:56636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZzUOu5aQNSViFaxNhBQAAARs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:25.012764 2026] [security2:error] [pid 1025331:tid 1025538] [client 57.141.18.22:65362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zx0Ou5aQNSViFaxNfXAABV3Y"]
[Mon Jul 20 06:51:25.189599 2026] [security2:error] [pid 1020501:tid 1020744] [client 57.141.18.113:37380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zx8S_oRsP4jdONhcLKgAAbzQ"]
[Mon Jul 20 06:51:25.196690 2026] [security2:error] [pid 1025331:tid 1025493] [client 37.139.53.11:52695] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4ZzUOu5aQNSViFaxNhDQAAASo"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:51:25.196781 2026] [security2:error] [pid 1025331:tid 1025493] [client 37.139.53.11:52695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4ZzUOu5aQNSViFaxNhDQAAASo"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:51:25.580423 2026] [security2:error] [pid 1025331:tid 1025474] [client 161.118.218.103:57004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZzUOu5aQNSViFaxNhJgAAARc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:25.834620 2026] [security2:error] [pid 1025331:tid 1025480] [client 14.182.195.220:52397] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ZzUOu5aQNSViFaxNhOwAAAR0"]
[Mon Jul 20 06:51:26.163184 2026] [security2:error] [pid 1025331:tid 1025470] [client 161.118.218.103:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ZzkOu5aQNSViFaxNhRwAAARM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:26.271540 2026] [security2:error] [pid 1025331:tid 1025465] [client 14.251.3.155:54744] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ZzkOu5aQNSViFaxNhTQAAAQ4"]
[Mon Jul 20 06:51:26.514104 2026] [security2:error] [pid 1025331:tid 1025467] [client 139.180.231.213:60401] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4ZzkOu5aQNSViFaxNhVAAAARA"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:51:26.591679 2026] [security2:error] [pid 1020501:tid 1020540] [remote 192.241.143.148:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZzsS_oRsP4jdONhcL7wAAISQ"]
[Mon Jul 20 06:51:26.663732 2026] [security2:error] [pid 1025331:tid 1025579] [client 14.225.17.146:63659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4ZzUOu5aQNSViFaxNhHgAAAYA"], referer: http://mazzucelli.com/NEW
[Mon Jul 20 06:51:26.677755 2026] [security2:error] [pid 1025331:tid 1025480] [client 34.139.11.221:52633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ZzkOu5aQNSViFaxNhaQAAAR0"]
[Mon Jul 20 06:51:26.737030 2026] [security2:error] [pid 1025331:tid 1025496] [client 161.118.218.103:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ZzkOu5aQNSViFaxNhbwAAAS0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:26.772949 2026] [security2:error] [pid 1025331:tid 1025495] [client 87.199.205.156:53114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.205.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4ZzkOu5aQNSViFaxNhcgAAASw"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:51:26.773075 2026] [security2:error] [pid 1025331:tid 1025495] [client 87.199.205.156:53114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4ZzkOu5aQNSViFaxNhcgAAASw"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:51:26.777061 2026] [security2:error] [pid 1020501:tid 1020524] [remote 192.241.143.148:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ZzsS_oRsP4jdONhcL9gAABRQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:51:26.794234 2026] [security2:error] [pid 1025331:tid 1025583] [client 34.139.11.221:62386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ZzkOu5aQNSViFaxNhdAAAAYQ"]
[Mon Jul 20 06:51:26.896814 2026] [security2:error] [pid 1025331:tid 1025503] [client 57.141.18.77:30344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZyUOu5aQNSViFaxNf4QABNCQ"]
[Mon Jul 20 06:51:26.909143 2026] [security2:error] [pid 1025331:tid 1025533] [client 34.139.11.221:52978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ZzkOu5aQNSViFaxNhdwAAAVI"]
[Mon Jul 20 06:51:27.029938 2026] [security2:error] [pid 1025331:tid 1025487] [client 34.139.11.221:51136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz0Ou5aQNSViFaxNhfAAAASQ"]
[Mon Jul 20 06:51:27.051213 2026] [security2:error] [pid 1025331:tid 1025465] [client 77.110.127.138:58342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zz0Ou5aQNSViFaxNhfgAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:27.051341 2026] [security2:error] [pid 1025331:tid 1025465] [client 77.110.127.138:58342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Zz0Ou5aQNSViFaxNhfgAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:27.139223 2026] [security2:error] [pid 1025331:tid 1025542] [client 34.139.11.221:52731] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz0Ou5aQNSViFaxNhhwAAAVs"]
[Mon Jul 20 06:51:27.298215 2026] [security2:error] [pid 1020501:tid 1020656] [client 50.116.65.227:28246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Zz8S_oRsP4jdONhcMAAAAABc"]
[Mon Jul 20 06:51:27.301031 2026] [security2:error] [pid 1020501:tid 1020748] [client 34.139.11.221:53100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz8S_oRsP4jdONhcMAQAAAHM"]
[Mon Jul 20 06:51:27.310008 2026] [security2:error] [pid 1020501:tid 1020698] [client 50.116.65.227:28248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Zz8S_oRsP4jdONhcMAgAAAEE"]
[Mon Jul 20 06:51:27.313812 2026] [security2:error] [pid 1025331:tid 1025546] [client 161.118.218.103:58059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Zz0Ou5aQNSViFaxNhkwAAAV8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:27.377434 2026] [security2:error] [pid 1020501:tid 1020680] [client 57.141.18.34:37418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZysS_oRsP4jdONhcLagAAL3g"]
[Mon Jul 20 06:51:27.457510 2026] [security2:error] [pid 1025331:tid 1025504] [client 34.139.11.221:53874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz0Ou5aQNSViFaxNhnAAAATU"]
[Mon Jul 20 06:51:27.540499 2026] [security2:error] [pid 1020501:tid 1020737] [client 146.103.116.11:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.116.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4Zz8S_oRsP4jdONhcMBQAAAGg"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:51:27.540611 2026] [security2:error] [pid 1020501:tid 1020737] [client 146.103.116.11:50886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4Zz8S_oRsP4jdONhcMBQAAAGg"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:51:27.675171 2026] [security2:error] [pid 1020501:tid 1020717] [client 34.139.11.221:53874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz8S_oRsP4jdONhcMCQAAAFQ"]
[Mon Jul 20 06:51:27.811022 2026] [security2:error] [pid 1025331:tid 1025484] [client 34.139.11.221:61653] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz0Ou5aQNSViFaxNhtQAAASE"]
[Mon Jul 20 06:51:27.814683 2026] [security2:error] [pid 1025331:tid 1025543] [client 57.141.18.95:22990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZykOu5aQNSViFaxNgLgABXBQ"]
[Mon Jul 20 06:51:27.893129 2026] [security2:error] [pid 1025331:tid 1025569] [client 161.118.218.103:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Zz0Ou5aQNSViFaxNhuwAAAXY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:27.950425 2026] [security2:error] [pid 1025331:tid 1025499] [client 34.139.11.221:54098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Zz0Ou5aQNSViFaxNhvgAAATA"]
[Mon Jul 20 06:51:27.964505 2026] [core:error] [pid 1025331:tid 1025536] [client 14.225.17.146:65523] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/NEW
[Mon Jul 20 06:51:27.964526 2026] [core:error] [pid 1025331:tid 1025536] [client 14.225.17.146:65523] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/NEW
[Mon Jul 20 06:51:27.981744 2026] [security2:error] [pid 1025331:tid 1025465] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Zz0Ou5aQNSViFaxNhsAAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:28.096397 2026] [security2:error] [pid 1020501:tid 1020659] [client 216.24.212.53:63001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4Z0MS_oRsP4jdONhcMFQAAABo"]
[Mon Jul 20 06:51:28.097420 2026] [security2:error] [pid 1020501:tid 1020660] [client 34.139.11.221:52967] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Z0MS_oRsP4jdONhcMFwAAABs"]
[Mon Jul 20 06:51:28.098949 2026] [security2:error] [pid 1020501:tid 1020757] [client 216.24.212.76:30105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4Z0MS_oRsP4jdONhcMFAAAAHw"]
[Mon Jul 20 06:51:28.220710 2026] [security2:error] [pid 1025331:tid 1025504] [client 34.85.238.37:56293] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "frugaltofi.com"] [uri "/xmlrpc.php"] [unique_id "al4Z0EOu5aQNSViFaxNhzgAAATU"]
[Mon Jul 20 06:51:28.220833 2026] [security2:error] [pid 1025331:tid 1025504] [client 34.85.238.37:56293] ModSecurity: Warning. Operator GE matched 2 at IP:dos_burst_counter. [file "/etc/httpd/modsecurity.d/03_asl_dos.conf"] [line "99"] [id "350114"] [rev "1"] [msg "Atomicorp.com WAF Rules: Potential Denial of Service (DoS) Attack from  - # of Request Bursts: 2"] [severity "ERROR"] [tag "no_ar"] [hostname "frugaltofi.com"] [uri "/xmlrpc.php"] [unique_id "al4Z0EOu5aQNSViFaxNhzgAAATU"]
[Mon Jul 20 06:51:28.222412 2026] [security2:error] [pid 1020501:tid 1020651] [client 34.139.11.221:64899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Z0MS_oRsP4jdONhcMJQAAABI"]
[Mon Jul 20 06:51:28.280573 2026] [security2:error] [pid 1025331:tid 1025483] [client 152.58.191.29:61235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z0EOu5aQNSViFaxNh1gAAASA"]
[Mon Jul 20 06:51:28.281214 2026] [security2:error] [pid 1025331:tid 1025483] [client 152.58.191.29:61235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z0EOu5aQNSViFaxNh1gAAASA"]
[Mon Jul 20 06:51:28.333053 2026] [security2:error] [pid 1025331:tid 1025537] [client 57.141.18.102:31746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgUwABVnw"]
[Mon Jul 20 06:51:28.353836 2026] [security2:error] [pid 1025331:tid 1025554] [client 34.139.11.221:52362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.puk.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Z0EOu5aQNSViFaxNh3AAAAWc"]
[Mon Jul 20 06:51:28.460140 2026] [security2:error] [pid 1020501:tid 1020661] [client 57.141.18.86:60542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zy8S_oRsP4jdONhcLkwAAHEY"]
[Mon Jul 20 06:51:28.467922 2026] [security2:error] [pid 1025331:tid 1025473] [client 161.118.218.103:58797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z0EOu5aQNSViFaxNh3wAAARY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:28.562948 2026] [security2:error] [pid 1025331:tid 1025526] [client 57.141.18.96:57250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgcwABSy4"]
[Mon Jul 20 06:51:28.807117 2026] [security2:error] [pid 1020501:tid 1020759] [client 74.7.228.6:55946] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.39ishlife.com"] [uri "/robots.txt"] [unique_id "al4Z0MS_oRsP4jdONhcMNQAAAH4"]
[Mon Jul 20 06:51:28.855427 2026] [security2:error] [pid 1025331:tid 1025418] [remote 47.86.33.52:28706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Z0EOu5aQNSViFaxNh8AABHlY"]
[Mon Jul 20 06:51:29.040960 2026] [security2:error] [pid 1020501:tid 1020714] [client 161.118.218.103:59189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z0cS_oRsP4jdONhcMOQAAAFE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:29.063757 2026] [security2:error] [pid 1020501:tid 1020633] [client 74.7.228.6:59868] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4Z0MS_oRsP4jdONhcMOAAAAEU"], referer: http://www.39ishlife.com/robots.txt
[Mon Jul 20 06:51:29.232230 2026] [security2:error] [pid 1025331:tid 1025508] [client 57.141.18.73:28042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgrwABOTY"]
[Mon Jul 20 06:51:29.264739 2026] [security2:error] [pid 1025331:tid 1025548] [client 57.141.18.110:21564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zy0Ou5aQNSViFaxNgsAABYTM"]
[Mon Jul 20 06:51:29.309258 2026] [security2:error] [pid 1025331:tid 1025467] [client 139.180.231.213:60401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4ZzkOu5aQNSViFaxNhVAAAARA"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:51:29.309324 2026] [security2:error] [pid 1025331:tid 1025467] [client 139.180.231.213:60401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4ZzkOu5aQNSViFaxNhVAAAARA"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 06:51:29.351846 2026] [security2:error] [pid 1025331:tid 1025534] [client 37.52.210.45:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z0UOu5aQNSViFaxNiDQAAAVM"]
[Mon Jul 20 06:51:29.352005 2026] [security2:error] [pid 1025331:tid 1025534] [client 37.52.210.45:48490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z0UOu5aQNSViFaxNiDQAAAVM"]
[Mon Jul 20 06:51:29.357815 2026] [security2:error] [pid 1025331:tid 1025516] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Z0UOu5aQNSViFaxNiAwAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:29.616817 2026] [security2:error] [pid 1025331:tid 1025531] [client 161.118.218.103:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z0UOu5aQNSViFaxNiGQAAAVA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:29.626077 2026] [security2:error] [pid 1025331:tid 1025525] [client 57.141.18.4:28766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZzEOu5aQNSViFaxNg3QABSgQ"]
[Mon Jul 20 06:51:30.036149 2026] [security2:error] [pid 1025331:tid 1025360] [remote 47.86.33.52:28706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Z0kOu5aQNSViFaxNiOAABTxw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:51:30.081857 2026] [security2:error] [pid 1020501:tid 1020638] [client 14.225.17.146:52591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4Z0MS_oRsP4jdONhcMMgAAAAU"], referer: http://sarahsnyder.net/NEW
[Mon Jul 20 06:51:30.192854 2026] [security2:error] [pid 1025331:tid 1025588] [client 161.118.218.103:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z0kOu5aQNSViFaxNiPQAAAYk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:30.242325 2026] [security2:error] [pid 1025331:tid 1025576] [client 45.3.54.78:53915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Z0kOu5aQNSViFaxNiQQAAAX0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:51:30.242548 2026] [security2:error] [pid 1025331:tid 1025466] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Z0UOu5aQNSViFaxNiMgAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:30.263286 2026] [security2:error] [pid 1025331:tid 1025438] [remote 102.134.101.35:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4Z0kOu5aQNSViFaxNiRQABf2o"]
[Mon Jul 20 06:51:30.273441 2026] [security2:error] [pid 1020501:tid 1020637] [client 57.141.18.67:38948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZzMS_oRsP4jdONhcL0QAABHc"]
[Mon Jul 20 06:51:30.521899 2026] [security2:error] [pid 1025331:tid 1025491] [client 106.219.188.178:32959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z0kOu5aQNSViFaxNiWQAAASg"]
[Mon Jul 20 06:51:30.528659 2026] [security2:error] [pid 1025331:tid 1025491] [client 106.219.188.178:32959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z0kOu5aQNSViFaxNiWQAAASg"]
[Mon Jul 20 06:51:30.737922 2026] [security2:error] [pid 1025331:tid 1025367] [remote 89.216.62.195:53758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.62.216.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4Z0kOu5aQNSViFaxNibwABSSM"]
[Mon Jul 20 06:51:30.738123 2026] [security2:error] [pid 1025331:tid 1025524] [client 89.216.62.195:53758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4Z0kOu5aQNSViFaxNibwABSSM"]
[Mon Jul 20 06:51:30.748681 2026] [security2:error] [pid 1025331:tid 1025422] [remote 102.134.101.35:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4Z0kOu5aQNSViFaxNicwABdFo"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 06:51:30.769648 2026] [security2:error] [pid 1025331:tid 1025565] [client 161.118.218.103:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z0kOu5aQNSViFaxNidgAAAXI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:30.847286 2026] [security2:error] [pid 1025331:tid 1025577] [client 57.141.18.71:28416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZzUOu5aQNSViFaxNhNwABfkA"]
[Mon Jul 20 06:51:30.941984 2026] [security2:error] [pid 1025331:tid 1025586] [client 57.141.18.0:31614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ZzUOu5aQNSViFaxNhOgABh3E"]
[Mon Jul 20 06:51:30.958010 2026] [security2:error] [pid 1020501:tid 1020734] [client 74.7.175.151:40462] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mollycahill.com"] [uri "/robots.txt"] [unique_id "al4Z0sS_oRsP4jdONhcMXgAAZSw"]
[Mon Jul 20 06:51:31.103281 2026] [security2:error] [pid 1025331:tid 1025511] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Z0kOu5aQNSViFaxNiWgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:31.242627 2026] [security2:error] [pid 1025331:tid 1025588] [client 14.225.17.146:51148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4Z00Ou5aQNSViFaxNihwAAAYk"], referer: https://sarahsnyder.net/NEW
[Mon Jul 20 06:51:31.266782 2026] [security2:error] [pid 1025331:tid 1025553] [client 77.110.127.138:58364] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 237 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z00Ou5aQNSViFaxNijgAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:31.341999 2026] [security2:error] [pid 1020501:tid 1020670] [client 161.118.218.103:60569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z08S_oRsP4jdONhcMZwAAACU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:31.414137 2026] [security2:error] [pid 1025331:tid 1025575] [client 14.225.17.146:52334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4Z0kOu5aQNSViFaxNiNwAAAXw"], referer: http://chestermonty.com/NEW
[Mon Jul 20 06:51:31.448100 2026] [security2:error] [pid 1020501:tid 1020735] [client 39.48.81.23:61562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z08S_oRsP4jdONhcMaAAAAGY"]
[Mon Jul 20 06:51:31.448204 2026] [security2:error] [pid 1020501:tid 1020735] [client 39.48.81.23:61562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z08S_oRsP4jdONhcMaAAAAGY"]
[Mon Jul 20 06:51:31.746424 2026] [security2:error] [pid 1020501:tid 1020661] [client 217.142.18.172:8170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z08S_oRsP4jdONhcMbAAAABw"]
[Mon Jul 20 06:51:31.746684 2026] [security2:error] [pid 1020501:tid 1020661] [client 217.142.18.172:8170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z08S_oRsP4jdONhcMbAAAABw"]
[Mon Jul 20 06:51:31.764667 2026] [security2:error] [pid 1025331:tid 1025508] [client 36.95.228.227:63103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.228.95.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z00Ou5aQNSViFaxNipgAAATk"]
[Mon Jul 20 06:51:31.764805 2026] [security2:error] [pid 1025331:tid 1025508] [client 36.95.228.227:63103] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z00Ou5aQNSViFaxNipgAAATk"]
[Mon Jul 20 06:51:31.874779 2026] [security2:error] [pid 1025331:tid 1025483] [client 2a03:2880:10ff:57:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4Z00Ou5aQNSViFaxNijAABIH4"]
[Mon Jul 20 06:51:31.875988 2026] [security2:error] [pid 1025331:tid 1025510] [client 74.208.214.194:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4Z00Ou5aQNSViFaxNiqgAAATs"]
[Mon Jul 20 06:51:31.916161 2026] [security2:error] [pid 1025331:tid 1025481] [client 45.3.35.73:24097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Z00Ou5aQNSViFaxNiqwAAAR4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:51:31.921318 2026] [security2:error] [pid 1020501:tid 1020681] [client 161.118.218.103:60943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z08S_oRsP4jdONhcMeAAAADA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:31.928715 2026] [security2:error] [pid 1025331:tid 1025574] [client 223.185.13.213:22130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z00Ou5aQNSViFaxNirQAAAXs"]
[Mon Jul 20 06:51:31.928866 2026] [security2:error] [pid 1025331:tid 1025574] [client 223.185.13.213:22130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z00Ou5aQNSViFaxNirQAAAXs"]
[Mon Jul 20 06:51:31.991630 2026] [security2:error] [pid 1020501:tid 1020730] [client 14.225.17.146:52526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4Z08S_oRsP4jdONhcMdwAAAGE"], referer: http://39ishlife.com/NEW
[Mon Jul 20 06:51:32.115927 2026] [security2:error] [pid 1025331:tid 1025547] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Z00Ou5aQNSViFaxNingAAAWA"]
[Mon Jul 20 06:51:32.294585 2026] [security2:error] [pid 1025331:tid 1025557] [client 77.110.127.138:58370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z1EOu5aQNSViFaxNivwAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:32.294692 2026] [security2:error] [pid 1025331:tid 1025557] [client 77.110.127.138:58370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z1EOu5aQNSViFaxNivwAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:32.507699 2026] [security2:error] [pid 1025331:tid 1025490] [client 161.118.218.103:61343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z1EOu5aQNSViFaxNi2QAAASc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:32.511634 2026] [security2:error] [pid 1025331:tid 1025503] [client 14.225.17.146:53107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4Z0kOu5aQNSViFaxNiVgAAATQ"], referer: http://www.justinagrayman.com/NEW
[Mon Jul 20 06:51:32.538102 2026] [security2:error] [pid 1025331:tid 1025561] [client 122.183.32.225:33134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1EOu5aQNSViFaxNi3AAAAW4"]
[Mon Jul 20 06:51:32.542625 2026] [security2:error] [pid 1025331:tid 1025561] [client 122.183.32.225:33134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1EOu5aQNSViFaxNi3AAAAW4"]
[Mon Jul 20 06:51:32.581321 2026] [security2:error] [pid 1020501:tid 1020656] [client 14.225.17.146:56075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4Z1MS_oRsP4jdONhcMfgAAABc"], referer: https://chestermonty.com/NEW
[Mon Jul 20 06:51:32.642084 2026] [security2:error] [pid 1025331:tid 1025543] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4Z1EOu5aQNSViFaxNizwAAAVw"]
[Mon Jul 20 06:51:32.788708 2026] [security2:error] [pid 1020501:tid 1020595] [remote 38.242.157.30:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4Z1MS_oRsP4jdONhcMigAAVFs"]
[Mon Jul 20 06:51:32.966150 2026] [security2:error] [pid 1020501:tid 1020729] [client 57.141.18.99:36254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Zz8S_oRsP4jdONhcMDgAAYGE"]
[Mon Jul 20 06:51:33.012569 2026] [security2:error] [pid 1020501:tid 1020517] [remote 38.242.157.30:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4Z1cS_oRsP4jdONhcMkAAAfA0"], referer: https://gertoger.org/wp-login.php
[Mon Jul 20 06:51:33.086027 2026] [security2:error] [pid 1025331:tid 1025535] [client 14.225.17.146:53046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4Z1EOu5aQNSViFaxNi9AAAAVQ"], referer: https://39ishlife.com/NEW
[Mon Jul 20 06:51:33.087642 2026] [security2:error] [pid 1025331:tid 1025557] [client 161.118.218.103:61713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z1UOu5aQNSViFaxNi_QAAAWo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:33.106212 2026] [security2:error] [pid 1025331:tid 1025467] [client 117.247.108.24:25470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1UOu5aQNSViFaxNi_gAAARA"]
[Mon Jul 20 06:51:33.106343 2026] [security2:error] [pid 1025331:tid 1025467] [client 117.247.108.24:25470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1UOu5aQNSViFaxNi_gAAARA"]
[Mon Jul 20 06:51:33.311295 2026] [security2:error] [pid 1025331:tid 1025522] [client 57.141.18.119:61640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z0EOu5aQNSViFaxNh0AABRww"]
[Mon Jul 20 06:51:33.374626 2026] [security2:error] [pid 1025331:tid 1025517] [client 103.125.179.95:55050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1UOu5aQNSViFaxNjCgAAAUI"]
[Mon Jul 20 06:51:33.374745 2026] [security2:error] [pid 1025331:tid 1025517] [client 103.125.179.95:55050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1UOu5aQNSViFaxNjCgAAAUI"]
[Mon Jul 20 06:51:33.663186 2026] [security2:error] [pid 1020501:tid 1020716] [client 161.118.218.103:62119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z1cS_oRsP4jdONhcMpQAAAFM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:33.753677 2026] [security2:error] [pid 1020501:tid 1020731] [client 103.238.106.162:42620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z1cS_oRsP4jdONhcMpwAAAGI"]
[Mon Jul 20 06:51:33.753812 2026] [security2:error] [pid 1020501:tid 1020731] [client 103.238.106.162:42620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z1cS_oRsP4jdONhcMpwAAAGI"]
[Mon Jul 20 06:51:34.239162 2026] [security2:error] [pid 1025331:tid 1025487] [client 161.118.218.103:62515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z1kOu5aQNSViFaxNjPQAAASQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:34.350733 2026] [security2:error] [pid 1025331:tid 1025504] [client 57.141.18.101:52012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z0UOu5aQNSViFaxNiAAABNWg"]
[Mon Jul 20 06:51:34.371139 2026] [security2:error] [pid 1025331:tid 1025561] [client 77.110.127.138:58381] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 585 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z1kOu5aQNSViFaxNjSAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:34.524169 2026] [security2:error] [pid 1025331:tid 1025512] [client 77.110.127.138:58383] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 336 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z1kOu5aQNSViFaxNjUwAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:34.655443 2026] [security2:error] [pid 1025331:tid 1025554] [client 183.82.98.154:65031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1kOu5aQNSViFaxNjXAAAAWc"]
[Mon Jul 20 06:51:34.655631 2026] [security2:error] [pid 1025331:tid 1025554] [client 183.82.98.154:65031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z1kOu5aQNSViFaxNjXAAAAWc"]
[Mon Jul 20 06:51:34.715711 2026] [security2:error] [pid 1025331:tid 1025577] [client 14.225.17.146:61409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4Z1UOu5aQNSViFaxNjHAAAAX4"], referer: http://ncsynchro.com/NEW
[Mon Jul 20 06:51:34.814370 2026] [security2:error] [pid 1025331:tid 1025535] [client 161.118.218.103:62885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z1kOu5aQNSViFaxNjZAAAAVQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:34.850914 2026] [security2:error] [pid 1025331:tid 1025485] [client 57.141.18.91:55772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z0UOu5aQNSViFaxNiHQABIjw"]
[Mon Jul 20 06:51:34.955988 2026] [security2:error] [pid 1025331:tid 1025576] [client 14.225.17.146:49253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4Z1UOu5aQNSViFaxNjCwAAAX0"], referer: http://nurturemarple.co.uk/NEW
[Mon Jul 20 06:51:34.993654 2026] [security2:error] [pid 1025331:tid 1025517] [client 174.138.79.221:62459] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.kidsklubz.org"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4Z1kOu5aQNSViFaxNjbAAAAUI"]
[Mon Jul 20 06:51:35.059405 2026] [security2:error] [pid 1025331:tid 1025451] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z10Ou5aQNSViFaxNjcwABDHc"]
[Mon Jul 20 06:51:35.059597 2026] [security2:error] [pid 1025331:tid 1025463] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z10Ou5aQNSViFaxNjcwABDHc"]
[Mon Jul 20 06:51:35.117125 2026] [security2:error] [pid 1025331:tid 1025491] [client 187.108.85.186:58091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z10Ou5aQNSViFaxNjdwAAASg"]
[Mon Jul 20 06:51:35.117233 2026] [security2:error] [pid 1025331:tid 1025491] [client 187.108.85.186:58091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z10Ou5aQNSViFaxNjdwAAASg"]
[Mon Jul 20 06:51:35.219932 2026] [security2:error] [pid 1025331:tid 1025582] [client 216.73.217.138:64341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Z10Ou5aQNSViFaxNjdgABg3U"]
[Mon Jul 20 06:51:35.390054 2026] [security2:error] [pid 1020501:tid 1020733] [client 161.118.218.103:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z18S_oRsP4jdONhcMwwAAAGQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:35.404895 2026] [security2:error] [pid 1025331:tid 1025531] [client 216.73.217.138:64341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Z10Ou5aQNSViFaxNjggABUBE"]
[Mon Jul 20 06:51:35.416883 2026] [security2:error] [pid 1025331:tid 1025340] [remote 188.166.241.141:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4Z10Ou5aQNSViFaxNjigABDQg"]
[Mon Jul 20 06:51:35.418283 2026] [security2:error] [pid 1020501:tid 1020680] [client 50.116.65.227:48440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4Z18S_oRsP4jdONhcMvQAAAC8"]
[Mon Jul 20 06:51:35.533306 2026] [security2:error] [pid 1025331:tid 1025551] [client 77.110.127.138:58387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z10Ou5aQNSViFaxNjlwAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:35.533671 2026] [security2:error] [pid 1025331:tid 1025551] [client 77.110.127.138:58387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z10Ou5aQNSViFaxNjlwAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:35.626015 2026] [security2:error] [pid 1025331:tid 1025554] [client 50.116.65.227:48450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4Z10Ou5aQNSViFaxNjjAAAAWc"]
[Mon Jul 20 06:51:35.696878 2026] [security2:error] [pid 1025331:tid 1025511] [client 104.234.53.73:30547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Z10Ou5aQNSViFaxNjmAAAATw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:35.939280 2026] [security2:error] [pid 1025331:tid 1025535] [client 14.225.17.146:55023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4Z10Ou5aQNSViFaxNjqAAAAVQ"], referer: https://nurturemarple.co.uk/NEW
[Mon Jul 20 06:51:35.966466 2026] [security2:error] [pid 1025331:tid 1025462] [client 161.118.218.103:63610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z10Ou5aQNSViFaxNjtQAAAQs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:36.085816 2026] [security2:error] [pid 1025331:tid 1025403] [remote 188.166.241.141:37412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4Z2EOu5aQNSViFaxNjwAABfkc"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 06:51:36.548618 2026] [security2:error] [pid 1025331:tid 1025574] [client 161.118.218.103:64018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z2EOu5aQNSViFaxNj0gAAAXs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:36.738565 2026] [security2:error] [pid 1025331:tid 1025476] [client 57.141.18.79:41500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z0kOu5aQNSViFaxNigQABGWw"]
[Mon Jul 20 06:51:36.804641 2026] [core:error] [pid 1025331:tid 1025538] [client 103.153.183.69:43288] AH10244: invalid URI path (http://autodiscover.qjg.ihb.mybluehost.me/%%32e%%32e/%%32e%%32e/.env?_=pdjbt7d4&v=an2cm), referer: https://news.ycombinator.com/
[Mon Jul 20 06:51:36.846838 2026] [security2:error] [pid 1025331:tid 1025346] [remote 74.7.227.179:37594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4Z2EOu5aQNSViFaxNj2wABFA4"], referer: https://tejasenvironmental.com/p=363924
[Mon Jul 20 06:51:36.938508 2026] [security2:error] [pid 1025331:tid 1025483] [client 77.110.127.138:58401] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 152 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z2EOu5aQNSViFaxNj9gAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:37.043312 2026] [security2:error] [pid 1020501:tid 1020706] [client 197.186.66.42:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z2cS_oRsP4jdONhcM4AAAAEk"]
[Mon Jul 20 06:51:37.043436 2026] [security2:error] [pid 1020501:tid 1020706] [client 197.186.66.42:62621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z2cS_oRsP4jdONhcM4AAAAEk"]
[Mon Jul 20 06:51:37.133556 2026] [security2:error] [pid 1025331:tid 1025525] [client 161.118.218.103:64389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z2UOu5aQNSViFaxNkAgAAAUo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:37.186081 2026] [security2:error] [pid 1025331:tid 1025500] [client 57.141.18.26:52148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z00Ou5aQNSViFaxNiiwABMSA"]
[Mon Jul 20 06:51:37.514758 2026] [security2:error] [pid 1025331:tid 1025576] [client 14.225.17.146:55073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4Z2EOu5aQNSViFaxNjuwAAAX0"], referer: http://reosportsboats.com/NEW
[Mon Jul 20 06:51:37.549148 2026] [security2:error] [pid 1020501:tid 1020714] [client 77.110.127.138:58414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 46 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z2cS_oRsP4jdONhcM6QAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:37.604628 2026] [security2:error] [pid 1025331:tid 1025560] [client 57.141.18.125:37386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z00Ou5aQNSViFaxNiowABbSw"]
[Mon Jul 20 06:51:37.650065 2026] [security2:error] [pid 1025331:tid 1025488] [client 172.59.121.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4Z2UOu5aQNSViFaxNkAQAAASU"]
[Mon Jul 20 06:51:37.655109 2026] [security2:error] [pid 1020501:tid 1020682] [client 14.225.17.146:55081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4Z2MS_oRsP4jdONhcMywAAADE"], referer: http://xp-design.co/NEW
[Mon Jul 20 06:51:37.703154 2026] [security2:error] [pid 1025331:tid 1025483] [client 77.110.127.138:58415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z2UOu5aQNSViFaxNkLwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:37.703283 2026] [security2:error] [pid 1025331:tid 1025483] [client 77.110.127.138:58415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z2UOu5aQNSViFaxNkLwAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:37.711818 2026] [security2:error] [pid 1025331:tid 1025543] [client 161.118.218.103:64790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z2UOu5aQNSViFaxNkMAAAAVw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:37.766984 2026] [security2:error] [pid 1025331:tid 1025477] [client 14.225.17.146:55109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4Z2EOu5aQNSViFaxNjwQAAARo"], referer: http://ksands.co.uk/NEW
[Mon Jul 20 06:51:37.787597 2026] [security2:error] [pid 1020501:tid 1020758] [client 57.141.18.65:26710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z08S_oRsP4jdONhcMbgAAfVE"]
[Mon Jul 20 06:51:37.825718 2026] [security2:error] [pid 1025331:tid 1025531] [client 14.225.17.146:49250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4Z2EOu5aQNSViFaxNj-AAAAVA"], referer: http://processorstudio.com/NEW
[Mon Jul 20 06:51:38.199123 2026] [security2:error] [pid 1025331:tid 1025511] [client 104.234.53.73:30547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Z2kOu5aQNSViFaxNkTwAAATw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:38.286900 2026] [security2:error] [pid 1025331:tid 1025464] [client 161.118.218.103:65197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z2kOu5aQNSViFaxNkUgAAAQ0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:38.589019 2026] [security2:error] [pid 1025331:tid 1025459] [remote 5.252.52.249:46810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4Z2kOu5aQNSViFaxNkXwABQX8"]
[Mon Jul 20 06:51:38.604869 2026] [security2:error] [pid 1020501:tid 1020669] [client 45.61.188.240:57027] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "swafforddetailing.com"] [uri "/"] [unique_id "al4Z2sS_oRsP4jdONhcM_QAAACQ"]
[Mon Jul 20 06:51:38.648418 2026] [security2:error] [pid 1025331:tid 1025560] [client 158.173.89.95:27885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Z2kOu5aQNSViFaxNkZgAAAW0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:51:38.735521 2026] [security2:error] [pid 1025331:tid 1025543] [client 14.225.17.146:52159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4Z2kOu5aQNSViFaxNkaQAAAVw"], referer: https://processorstudio.com/NEW
[Mon Jul 20 06:51:38.862177 2026] [security2:error] [pid 1025331:tid 1025578] [client 161.118.218.103:49174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z2kOu5aQNSViFaxNkdAAAAX8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:38.862719 2026] [security2:error] [pid 1020501:tid 1020668] [client 57.141.18.123:65300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z1MS_oRsP4jdONhcMhgAAIww"]
[Mon Jul 20 06:51:38.870529 2026] [security2:error] [pid 1025331:tid 1025486] [client 45.61.188.240:57071] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "swafforddetailing.com"] [uri "/"] [unique_id "al4Z2kOu5aQNSViFaxNkdQAAASM"]
[Mon Jul 20 06:51:38.877627 2026] [security2:error] [pid 1025331:tid 1025542] [client 38.253.224.89:40912] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "tco.chi.mybluehost.me"] [uri "/"] [unique_id "al4Z2kOu5aQNSViFaxNkdwAAAVs"]
[Mon Jul 20 06:51:38.900135 2026] [security2:error] [pid 1025331:tid 1025574] [client 152.58.191.29:61672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z2kOu5aQNSViFaxNkeQAAAXs"]
[Mon Jul 20 06:51:38.911004 2026] [security2:error] [pid 1025331:tid 1025574] [client 152.58.191.29:61672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z2kOu5aQNSViFaxNkeQAAAXs"]
[Mon Jul 20 06:51:38.920329 2026] [security2:error] [pid 1025331:tid 1025472] [client 57.141.18.60:51886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z1EOu5aQNSViFaxNi6AABFUs"]
[Mon Jul 20 06:51:38.940245 2026] [security2:error] [pid 1025331:tid 1025431] [remote 5.252.52.249:46810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4Z2kOu5aQNSViFaxNkfQABH2M"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 06:51:39.368852 2026] [security2:error] [pid 1025331:tid 1025436] [remote 91.142.222.105:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4Z20Ou5aQNSViFaxNkjwABGGg"]
[Mon Jul 20 06:51:39.436391 2026] [security2:error] [pid 1025331:tid 1025565] [client 161.118.218.103:49574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z20Ou5aQNSViFaxNkmgAAAXI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:39.609423 2026] [security2:error] [pid 1025331:tid 1025435] [remote 91.142.222.105:54234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4Z20Ou5aQNSViFaxNkpAABI2c"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 06:51:39.776307 2026] [security2:error] [pid 1025331:tid 1025529] [client 14.225.17.146:52489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4Z2UOu5aQNSViFaxNkKAAAAU4"], referer: http://latiendadejorge.com.gt/NEW
[Mon Jul 20 06:51:39.996406 2026] [security2:error] [pid 1025331:tid 1025541] [client 77.110.127.138:58422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 811 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z20Ou5aQNSViFaxNkwAAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:40.010991 2026] [security2:error] [pid 1025331:tid 1025484] [client 161.118.218.103:49973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z3EOu5aQNSViFaxNkwwAAASE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:40.022107 2026] [security2:error] [pid 1025331:tid 1025540] [client 57.141.18.79:41506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z1UOu5aQNSViFaxNjFgABWVg"]
[Mon Jul 20 06:51:40.170785 2026] [security2:error] [pid 1025331:tid 1025510] [client 14.225.17.146:49161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4Z2kOu5aQNSViFaxNkXAAAATs"], referer: https://north-woods-engineering.com/NEW
[Mon Jul 20 06:51:40.233354 2026] [security2:error] [pid 1025331:tid 1025480] [client 57.141.18.30:59960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z1UOu5aQNSViFaxNjHwABHR4"]
[Mon Jul 20 06:51:40.515990 2026] [security2:error] [pid 1020501:tid 1020532] [remote 57.141.18.76:30242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4367572"] [unique_id "al4Z3MS_oRsP4jdONhcNJQAAVhw"]
[Mon Jul 20 06:51:40.587342 2026] [security2:error] [pid 1020501:tid 1020663] [client 161.118.218.103:50327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z3MS_oRsP4jdONhcNJwAAAB4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:40.760138 2026] [security2:error] [pid 1020501:tid 1020653] [client 77.110.127.138:58426] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 492 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z3MS_oRsP4jdONhcNLAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:40.868607 2026] [security2:error] [pid 1020501:tid 1020651] [client 14.225.17.146:52546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4Z2sS_oRsP4jdONhcNBAAAABI"], referer: http://dollpassionista.com/NEW
[Mon Jul 20 06:51:40.885688 2026] [security2:error] [pid 1020501:tid 1020680] [client 14.224.227.113:54748] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Z3MS_oRsP4jdONhcNNQAAAC8"]
[Mon Jul 20 06:51:40.974635 2026] [security2:error] [pid 1025331:tid 1025371] [remote 100.42.189.89:36100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z3EOu5aQNSViFaxNlAgABMSc"]
[Mon Jul 20 06:51:40.974848 2026] [security2:error] [pid 1025331:tid 1025500] [client 100.42.189.89:36100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z3EOu5aQNSViFaxNlAgABMSc"]
[Mon Jul 20 06:51:41.156309 2026] [security2:error] [pid 1020501:tid 1020546] [remote 182.77.62.24:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Z3cS_oRsP4jdONhcNPQAAVyo"]
[Mon Jul 20 06:51:41.170322 2026] [security2:error] [pid 1025331:tid 1025478] [client 161.118.218.103:50714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z3UOu5aQNSViFaxNlCQAAARs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:41.436737 2026] [security2:error] [pid 1020501:tid 1020709] [client 106.219.188.178:10287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z3cS_oRsP4jdONhcNQgAAAEw"]
[Mon Jul 20 06:51:41.437169 2026] [security2:error] [pid 1020501:tid 1020709] [client 106.219.188.178:10287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z3cS_oRsP4jdONhcNQgAAAEw"]
[Mon Jul 20 06:51:41.654815 2026] [security2:error] [pid 1020501:tid 1020579] [remote 182.77.62.24:52096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4Z3cS_oRsP4jdONhcNRQAAbUs"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:51:41.679309 2026] [security2:error] [pid 1025331:tid 1025538] [client 77.110.127.138:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z3UOu5aQNSViFaxNlLAAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:41.679403 2026] [security2:error] [pid 1025331:tid 1025538] [client 77.110.127.138:58430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z3UOu5aQNSViFaxNlLAAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:41.710465 2026] [security2:error] [pid 1020501:tid 1020674] [client 57.141.18.121:65254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z18S_oRsP4jdONhcMwQAAKQI"]
[Mon Jul 20 06:51:41.746631 2026] [security2:error] [pid 1025331:tid 1025510] [client 161.118.218.103:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z3UOu5aQNSViFaxNlMgAAATs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:41.840886 2026] [security2:error] [pid 1025331:tid 1025332] [remote 173.249.4.11:19055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Z3UOu5aQNSViFaxNlNwABXwA"]
[Mon Jul 20 06:51:41.843672 2026] [security2:error] [pid 1025331:tid 1025504] [client 14.225.17.146:52148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4Z3UOu5aQNSViFaxNlKwAAATU"], referer: https://dollpassionista.com/NEW
[Mon Jul 20 06:51:42.041224 2026] [security2:error] [pid 1025331:tid 1025532] [client 104.207.34.137:36759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Z3kOu5aQNSViFaxNlRwAAAVE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:51:42.201599 2026] [security2:error] [pid 1020501:tid 1020574] [remote 91.142.222.105:60586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z3sS_oRsP4jdONhcNSwAAIUY"]
[Mon Jul 20 06:51:42.201712 2026] [security2:error] [pid 1020501:tid 1020666] [client 91.142.222.105:60586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z3sS_oRsP4jdONhcNSwAAIUY"]
[Mon Jul 20 06:51:42.219130 2026] [security2:error] [pid 1025331:tid 1025472] [client 202.46.92.242:63577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z3kOu5aQNSViFaxNlUgAAARU"]
[Mon Jul 20 06:51:42.219226 2026] [security2:error] [pid 1025331:tid 1025472] [client 202.46.92.242:63577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z3kOu5aQNSViFaxNlUgAAARU"]
[Mon Jul 20 06:51:42.220437 2026] [security2:error] [pid 1025331:tid 1025339] [remote 173.249.4.11:19055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4Z3kOu5aQNSViFaxNlUwABGQc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:51:42.331059 2026] [security2:error] [pid 1025331:tid 1025482] [client 161.118.218.103:51523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z3kOu5aQNSViFaxNlXQAAAR8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:42.374423 2026] [security2:error] [pid 1025331:tid 1025486] [client 217.142.18.172:2218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z3kOu5aQNSViFaxNlYwAAASM"]
[Mon Jul 20 06:51:42.379827 2026] [security2:error] [pid 1025331:tid 1025486] [client 217.142.18.172:2218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z3kOu5aQNSViFaxNlYwAAASM"]
[Mon Jul 20 06:51:42.564735 2026] [proxy:error] [pid 1025331:tid 1025546] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:42.564829 2026] [proxy_http:error] [pid 1025331:tid 1025546] [client 198.235.24.148:64850] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:42.565406 2026] [proxy:error] [pid 1025331:tid 1025546] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:42.565434 2026] [proxy_http:error] [pid 1025331:tid 1025546] [client 198.235.24.148:64850] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:42.733374 2026] [security2:error] [pid 1025331:tid 1025468] [client 57.141.18.37:58838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z2EOu5aQNSViFaxNjxQABESo"]
[Mon Jul 20 06:51:42.820799 2026] [security2:error] [pid 1025331:tid 1025520] [client 77.110.127.138:58434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 704 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z3kOu5aQNSViFaxNlfwAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:42.905806 2026] [security2:error] [pid 1025331:tid 1025563] [client 161.118.218.103:51969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z3kOu5aQNSViFaxNljAAAAXA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:43.013907 2026] [security2:error] [pid 1025331:tid 1025588] [client 192.140.149.97:46116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z30Ou5aQNSViFaxNlkgAAAYk"]
[Mon Jul 20 06:51:43.014085 2026] [security2:error] [pid 1025331:tid 1025588] [client 192.140.149.97:46116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z30Ou5aQNSViFaxNlkgAAAYk"]
[Mon Jul 20 06:51:43.025849 2026] [security2:error] [pid 1025331:tid 1025462] [client 77.110.127.138:58435] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 288 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z30Ou5aQNSViFaxNlkwAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:43.146373 2026] [security2:error] [pid 1020501:tid 1020699] [client 223.185.13.213:4444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.13.185.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z38S_oRsP4jdONhcNVAAAAEI"]
[Mon Jul 20 06:51:43.146481 2026] [security2:error] [pid 1020501:tid 1020699] [client 223.185.13.213:4444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z38S_oRsP4jdONhcNVAAAAEI"]
[Mon Jul 20 06:51:43.481271 2026] [security2:error] [pid 1025331:tid 1025496] [client 161.118.218.103:52418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z30Ou5aQNSViFaxNlsgAAAS0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:43.578470 2026] [security2:error] [pid 1025331:tid 1025517] [client 57.141.18.125:52374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z2UOu5aQNSViFaxNj-wABQno"]
[Mon Jul 20 06:51:43.831893 2026] [security2:error] [pid 1025331:tid 1025553] [client 14.225.17.146:61404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4Z3kOu5aQNSViFaxNlZwAAAWY"], referer: http://bbwipartnerconference.com/NEW
[Mon Jul 20 06:51:43.897920 2026] [security2:error] [pid 1025331:tid 1025579] [client 103.125.179.95:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z30Ou5aQNSViFaxNlxgAAAYA"]
[Mon Jul 20 06:51:43.898569 2026] [security2:error] [pid 1025331:tid 1025579] [client 103.125.179.95:55550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z30Ou5aQNSViFaxNlxgAAAYA"]
[Mon Jul 20 06:51:44.065162 2026] [security2:error] [pid 1020501:tid 1020703] [client 161.118.218.103:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z4MS_oRsP4jdONhcNaAAAAEY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:44.143474 2026] [security2:error] [pid 1020501:tid 1020659] [client 39.48.81.23:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4MS_oRsP4jdONhcNbAAAABo"]
[Mon Jul 20 06:51:44.144015 2026] [security2:error] [pid 1020501:tid 1020659] [client 39.48.81.23:62094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4MS_oRsP4jdONhcNbAAAABo"]
[Mon Jul 20 06:51:44.176964 2026] [security2:error] [pid 1025331:tid 1025503] [client 158.173.166.181:47769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Z4EOu5aQNSViFaxNl2wAAATQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:51:44.312544 2026] [security2:error] [pid 1025331:tid 1025476] [client 117.247.108.24:24837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4EOu5aQNSViFaxNl4gAAARk"]
[Mon Jul 20 06:51:44.312643 2026] [security2:error] [pid 1025331:tid 1025476] [client 117.247.108.24:24837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4EOu5aQNSViFaxNl4gAAARk"]
[Mon Jul 20 06:51:44.371890 2026] [security2:error] [pid 1025331:tid 1025569] [client 103.238.106.162:60876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z4EOu5aQNSViFaxNl5gAAAXY"]
[Mon Jul 20 06:51:44.371998 2026] [security2:error] [pid 1025331:tid 1025569] [client 103.238.106.162:60876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z4EOu5aQNSViFaxNl5gAAAXY"]
[Mon Jul 20 06:51:44.437061 2026] [security2:error] [pid 1020501:tid 1020637] [client 45.157.112.60:41125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Z4MS_oRsP4jdONhcNcwAAAAQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:51:44.476696 2026] [security2:error] [pid 1020501:tid 1020746] [client 57.141.18.93:25946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z2cS_oRsP4jdONhcM7wAAcSs"]
[Mon Jul 20 06:51:44.517763 2026] [security2:error] [pid 1025331:tid 1025578] [client 14.225.17.146:55832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4Z4EOu5aQNSViFaxNl1QAAAX8"], referer: http://idigress.group/NEW
[Mon Jul 20 06:51:44.632852 2026] [security2:error] [pid 1020501:tid 1020757] [client 122.183.32.225:9838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4MS_oRsP4jdONhcNfQAAAHw"]
[Mon Jul 20 06:51:44.637780 2026] [security2:error] [pid 1020501:tid 1020757] [client 122.183.32.225:9838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4MS_oRsP4jdONhcNfQAAAHw"]
[Mon Jul 20 06:51:44.643288 2026] [security2:error] [pid 1025331:tid 1025582] [client 161.118.218.103:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z4EOu5aQNSViFaxNl8QAAAYM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:44.820469 2026] [security2:error] [pid 1025331:tid 1025542] [client 104.234.53.64:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Z4EOu5aQNSViFaxNl_QAAAVs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:45.220323 2026] [security2:error] [pid 1025331:tid 1025483] [client 161.118.218.103:53636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z4UOu5aQNSViFaxNmJgAAASA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:45.409463 2026] [security2:error] [pid 1025331:tid 1025496] [client 183.82.98.154:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4UOu5aQNSViFaxNmLgAAAS0"]
[Mon Jul 20 06:51:45.409583 2026] [security2:error] [pid 1025331:tid 1025496] [client 183.82.98.154:49240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4UOu5aQNSViFaxNmLgAAAS0"]
[Mon Jul 20 06:51:45.429853 2026] [proxy:error] [pid 1025331:tid 1025467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:45.429910 2026] [proxy_http:error] [pid 1025331:tid 1025467] [client 205.210.31.186:63166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:45.430881 2026] [proxy:error] [pid 1025331:tid 1025467] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:45.430926 2026] [proxy_http:error] [pid 1025331:tid 1025467] [client 205.210.31.186:63166] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:45.499588 2026] [security2:error] [pid 1020501:tid 1020750] [client 14.225.17.146:56131] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4Z4MS_oRsP4jdONhcNfwAAAHU"]
[Mon Jul 20 06:51:45.550378 2026] [security2:error] [pid 1020501:tid 1020759] [client 14.225.17.146:55983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4Z4MS_oRsP4jdONhcNZgAAAH4"]
[Mon Jul 20 06:51:45.792452 2026] [security2:error] [pid 1020501:tid 1020575] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4cS_oRsP4jdONhcNmgAAUUc"]
[Mon Jul 20 06:51:45.792625 2026] [security2:error] [pid 1020501:tid 1020714] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4cS_oRsP4jdONhcNmgAAUUc"]
[Mon Jul 20 06:51:45.797809 2026] [security2:error] [pid 1020501:tid 1020649] [client 161.118.218.103:53983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z4cS_oRsP4jdONhcNmwAAABA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:45.888206 2026] [security2:error] [pid 1025331:tid 1025587] [client 187.108.85.186:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4UOu5aQNSViFaxNmSgAAAYg"]
[Mon Jul 20 06:51:45.888611 2026] [security2:error] [pid 1025331:tid 1025587] [client 187.108.85.186:58637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z4UOu5aQNSViFaxNmSgAAAYg"]
[Mon Jul 20 06:51:46.092264 2026] [security2:error] [pid 1025331:tid 1025463] [client 57.141.18.81:50290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z20Ou5aQNSViFaxNkiQABDHk"]
[Mon Jul 20 06:51:46.382141 2026] [security2:error] [pid 1020501:tid 1020696] [client 161.118.218.103:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z4sS_oRsP4jdONhcNqgAAAD8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:46.485129 2026] [security2:error] [pid 1020501:tid 1020578] [remote 74.235.96.117:40936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z4sS_oRsP4jdONhcNrQAAJEo"]
[Mon Jul 20 06:51:46.661524 2026] [security2:error] [pid 1020501:tid 1020620] [remote 74.235.96.117:40936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z4sS_oRsP4jdONhcNsQAAfHQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:51:46.685312 2026] [security2:error] [pid 1025331:tid 1025527] [client 57.141.18.78:40832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z20Ou5aQNSViFaxNkvAABTE0"]
[Mon Jul 20 06:51:46.820652 2026] [security2:error] [pid 1025331:tid 1025493] [client 57.141.18.12:47468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z3EOu5aQNSViFaxNkxQABKig"]
[Mon Jul 20 06:51:46.966142 2026] [security2:error] [pid 1025331:tid 1025525] [client 161.118.218.103:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z4kOu5aQNSViFaxNmggAAAUo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:47.044265 2026] [security2:error] [pid 1025331:tid 1025579] [client 104.234.53.86:63253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Z40Ou5aQNSViFaxNmhgAAAYA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:47.283172 2026] [security2:error] [pid 1025331:tid 1025516] [client 77.110.127.138:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z40Ou5aQNSViFaxNmkgAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:47.283259 2026] [security2:error] [pid 1025331:tid 1025516] [client 77.110.127.138:58459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z40Ou5aQNSViFaxNmkgAAAUE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:47.544160 2026] [security2:error] [pid 1020501:tid 1020708] [client 161.118.218.103:55132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z48S_oRsP4jdONhcNygAAAEs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:47.661627 2026] [security2:error] [pid 1025331:tid 1025586] [client 57.141.18.60:47212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z3EOu5aQNSViFaxNk_gABh18"]
[Mon Jul 20 06:51:47.792908 2026] [security2:error] [pid 1020501:tid 1020678] [client 52.109.20.47:18626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4Z48S_oRsP4jdONhcNzwAAAC0"]
[Mon Jul 20 06:51:47.809243 2026] [security2:error] [pid 1020501:tid 1020724] [client 57.141.18.82:27192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z3cS_oRsP4jdONhcNPAAAWzY"]
[Mon Jul 20 06:51:47.820469 2026] [security2:error] [pid 1020501:tid 1020673] [client 52.109.20.47:18626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4Z48S_oRsP4jdONhcN0AAAACg"]
[Mon Jul 20 06:51:47.981519 2026] [security2:error] [pid 1020501:tid 1020671] [client 14.225.17.146:62315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4Z4sS_oRsP4jdONhcNogAAACY"], referer: http://itdynamix.com/NEW
[Mon Jul 20 06:51:48.030546 2026] [security2:error] [pid 1025331:tid 1025496] [client 46.110.96.34:4548] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4Z5EOu5aQNSViFaxNmtwAAAS0"]
[Mon Jul 20 06:51:48.118976 2026] [security2:error] [pid 1025331:tid 1025565] [client 161.118.218.103:55504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z5EOu5aQNSViFaxNmvAAAAXI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:48.162113 2026] [security2:error] [pid 1020501:tid 1020687] [client 50.116.65.227:30768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Z5MS_oRsP4jdONhcN1QAAADY"]
[Mon Jul 20 06:51:48.170715 2026] [security2:error] [pid 1025331:tid 1025571] [client 50.116.65.227:30784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Z5EOu5aQNSViFaxNmwAAAAXg"]
[Mon Jul 20 06:51:48.662190 2026] [security2:error] [pid 1025331:tid 1025519] [client 57.141.18.11:56050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z3kOu5aQNSViFaxNlSgABRGU"]
[Mon Jul 20 06:51:48.696828 2026] [security2:error] [pid 1025331:tid 1025524] [client 161.118.218.103:55878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z5EOu5aQNSViFaxNm4wAAAUk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:48.816221 2026] [security2:error] [pid 1025331:tid 1025525] [client 104.234.53.82:57393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z5EOu5aQNSViFaxNm6QAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:48.837228 2026] [security2:error] [pid 1025331:tid 1025568] [client 77.110.127.138:58469] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 748 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z5EOu5aQNSViFaxNm7AAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:48.909628 2026] [security2:error] [pid 1025331:tid 1025375] [remote 95.217.78.234:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Z5EOu5aQNSViFaxNm9AABLSs"]
[Mon Jul 20 06:51:48.914957 2026] [security2:error] [pid 1025331:tid 1025454] [remote 57.141.18.105:43448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3379371"] [unique_id "al4Z5EOu5aQNSViFaxNm9QABHno"]
[Mon Jul 20 06:51:48.996451 2026] [security2:error] [pid 1025331:tid 1025468] [client 77.110.127.138:58472] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 160 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z5EOu5aQNSViFaxNm-AAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:49.020495 2026] [security2:error] [pid 1025331:tid 1025535] [client 14.225.17.146:57741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4Z5EOu5aQNSViFaxNm7QAAAVQ"], referer: https://itdynamix.com/NEW
[Mon Jul 20 06:51:49.148730 2026] [security2:error] [pid 1025331:tid 1025426] [remote 95.217.78.234:39104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4Z5UOu5aQNSViFaxNm_AABel4"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:51:49.201840 2026] [security2:error] [pid 1020501:tid 1020640] [client 57.141.18.108:61120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z3sS_oRsP4jdONhcNTgAABx8"]
[Mon Jul 20 06:51:49.222083 2026] [security2:error] [pid 1025331:tid 1025539] [client 202.29.232.118:48970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.44"] [uri "/"] [unique_id "al4Z5UOu5aQNSViFaxNm_wAAAVg"]
[Mon Jul 20 06:51:49.288236 2026] [security2:error] [pid 1025331:tid 1025490] [client 161.118.218.103:56250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z5UOu5aQNSViFaxNnBwAAASc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:49.426395 2026] [proxy:error] [pid 1025331:tid 1025554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:49.426472 2026] [proxy_http:error] [pid 1025331:tid 1025554] [client 34.73.38.214:64214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:49.427241 2026] [proxy:error] [pid 1025331:tid 1025554] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:49.427274 2026] [proxy_http:error] [pid 1025331:tid 1025554] [client 34.73.38.214:64214] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:49.484886 2026] [security2:error] [pid 1020501:tid 1020677] [client 202.29.232.118:59424] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.44"] [uri "/"] [unique_id "al4Z5cS_oRsP4jdONhcN8AAAACw"]
[Mon Jul 20 06:51:49.522353 2026] [security2:error] [pid 1020501:tid 1020696] [client 152.58.191.29:58200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z5cS_oRsP4jdONhcN8QAAAD8"]
[Mon Jul 20 06:51:49.522459 2026] [security2:error] [pid 1020501:tid 1020696] [client 152.58.191.29:58200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z5cS_oRsP4jdONhcN8QAAAD8"]
[Mon Jul 20 06:51:49.527578 2026] [proxy:error] [pid 1025331:tid 1025568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:49.527632 2026] [proxy_http:error] [pid 1025331:tid 1025568] [client 34.73.38.214:56819] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:49.528215 2026] [proxy:error] [pid 1025331:tid 1025568] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:49.528239 2026] [proxy_http:error] [pid 1025331:tid 1025568] [client 34.73.38.214:56819] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:49.667351 2026] [security2:error] [pid 1025331:tid 1025491] [client 14.251.3.155:58539] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Z5UOu5aQNSViFaxNnIQAAASg"]
[Mon Jul 20 06:51:49.732863 2026] [security2:error] [pid 1025331:tid 1025502] [client 77.110.127.138:58477] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z5UOu5aQNSViFaxNnJwAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:49.874928 2026] [security2:error] [pid 1025331:tid 1025552] [client 161.118.218.103:56612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z5UOu5aQNSViFaxNnNwAAAWU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:49.979274 2026] [security2:error] [pid 1020501:tid 1020732] [client 197.186.66.42:63153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z5cS_oRsP4jdONhcN9gAAAGM"]
[Mon Jul 20 06:51:49.980968 2026] [security2:error] [pid 1020501:tid 1020732] [client 197.186.66.42:63153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z5cS_oRsP4jdONhcN9gAAAGM"]
[Mon Jul 20 06:51:50.019288 2026] [proxy:error] [pid 1025331:tid 1025497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.019377 2026] [proxy_http:error] [pid 1025331:tid 1025497] [client 34.73.38.214:52351] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.020244 2026] [proxy:error] [pid 1025331:tid 1025497] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.020281 2026] [proxy_http:error] [pid 1025331:tid 1025497] [client 34.73.38.214:52351] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.111251 2026] [proxy:error] [pid 1025331:tid 1025563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.111341 2026] [proxy_http:error] [pid 1025331:tid 1025563] [client 34.73.38.214:50311] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.112308 2026] [proxy:error] [pid 1025331:tid 1025563] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.112348 2026] [proxy_http:error] [pid 1025331:tid 1025563] [client 34.73.38.214:50311] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.249745 2026] [security2:error] [pid 1020501:tid 1020647] [client 57.141.18.91:27152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z38S_oRsP4jdONhcNWwAADhM"]
[Mon Jul 20 06:51:50.269587 2026] [security2:error] [pid 1025331:tid 1025544] [client 14.225.17.146:57781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4Z5EOu5aQNSViFaxNm8gAAAV0"], referer: http://detroitcsc.com/NEW
[Mon Jul 20 06:51:50.457150 2026] [security2:error] [pid 1025331:tid 1025501] [client 161.118.218.103:56972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z5kOu5aQNSViFaxNnWgAAATI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:50.535466 2026] [proxy:error] [pid 1025331:tid 1025468] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.535535 2026] [proxy_http:error] [pid 1025331:tid 1025468] [client 34.73.38.214:63220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.536056 2026] [proxy:error] [pid 1025331:tid 1025468] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.536080 2026] [proxy_http:error] [pid 1025331:tid 1025468] [client 34.73.38.214:63220] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.550817 2026] [security2:error] [pid 1025331:tid 1025498] [client 77.110.127.138:58481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z5kOu5aQNSViFaxNnXgAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:50.550910 2026] [security2:error] [pid 1025331:tid 1025498] [client 77.110.127.138:58481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z5kOu5aQNSViFaxNnXgAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:50.646883 2026] [proxy:error] [pid 1025331:tid 1025517] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.646930 2026] [proxy_http:error] [pid 1025331:tid 1025517] [client 34.73.38.214:61941] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:50.647387 2026] [proxy:error] [pid 1025331:tid 1025517] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:51:50.647409 2026] [proxy_http:error] [pid 1025331:tid 1025517] [client 34.73.38.214:61941] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:51:51.037763 2026] [security2:error] [pid 1025331:tid 1025507] [client 161.118.218.103:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z50Ou5aQNSViFaxNnfgAAATg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:51.041875 2026] [security2:error] [pid 1025331:tid 1025566] [client 57.141.18.120:53696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z4EOu5aQNSViFaxNl3AABc2g"]
[Mon Jul 20 06:51:51.079309 2026] [security2:error] [pid 1025331:tid 1025487] [client 34.73.38.214:50224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/xmlrpc.php"] [unique_id "al4Z50Ou5aQNSViFaxNngQAAASQ"]
[Mon Jul 20 06:51:51.572841 2026] [security2:error] [pid 1025331:tid 1025486] [client 34.73.38.214:62069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Z50Ou5aQNSViFaxNnpAAAASM"]
[Mon Jul 20 06:51:51.618735 2026] [security2:error] [pid 1025331:tid 1025472] [client 161.118.218.103:57690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z50Ou5aQNSViFaxNnpwAAARU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:51.703715 2026] [security2:error] [pid 1020501:tid 1020660] [client 34.73.38.214:63155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/xmlrpc.php"] [unique_id "al4Z58S_oRsP4jdONhcOGQAAABs"]
[Mon Jul 20 06:51:51.845970 2026] [security2:error] [pid 1025331:tid 1025551] [client 77.110.127.138:58490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 187 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z50Ou5aQNSViFaxNnsAAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:52.020118 2026] [security2:error] [pid 1025331:tid 1025512] [client 77.110.127.138:58491] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z6EOu5aQNSViFaxNnwAAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:52.024666 2026] [security2:error] [pid 1025331:tid 1025494] [client 104.234.53.94:44953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4Z6EOu5aQNSViFaxNnwQAAASs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:52.140622 2026] [security2:error] [pid 1025331:tid 1025382] [remote 100.42.189.89:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z6EOu5aQNSViFaxNnxQABMzI"]
[Mon Jul 20 06:51:52.165204 2026] [security2:error] [pid 1025331:tid 1025542] [client 57.141.18.19:55820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z4UOu5aQNSViFaxNmMgABW2o"]
[Mon Jul 20 06:51:52.170445 2026] [security2:error] [pid 1025331:tid 1025503] [client 34.73.38.214:61270] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6EOu5aQNSViFaxNnxgAAATQ"]
[Mon Jul 20 06:51:52.185010 2026] [security2:error] [pid 1025331:tid 1025513] [client 77.110.127.138:58492] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z6EOu5aQNSViFaxNnxwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:52.195063 2026] [security2:error] [pid 1025331:tid 1025571] [client 161.118.218.103:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z6EOu5aQNSViFaxNnyAAAAXg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:52.214787 2026] [security2:error] [pid 1020501:tid 1020727] [client 106.219.188.178:15029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6MS_oRsP4jdONhcOIQAAAF4"]
[Mon Jul 20 06:51:52.214936 2026] [security2:error] [pid 1020501:tid 1020727] [client 106.219.188.178:15029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6MS_oRsP4jdONhcOIQAAAF4"]
[Mon Jul 20 06:51:52.347314 2026] [security2:error] [pid 1025331:tid 1025480] [client 34.73.38.214:64699] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6EOu5aQNSViFaxNnzAAAAR0"]
[Mon Jul 20 06:51:52.351930 2026] [security2:error] [pid 1025331:tid 1025340] [remote 100.42.189.89:36218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z6EOu5aQNSViFaxNnzQABcAg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:51:52.769937 2026] [security2:error] [pid 1025331:tid 1025471] [client 161.118.218.103:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z6EOu5aQNSViFaxNn4QAAARQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:52.800959 2026] [security2:error] [pid 1025331:tid 1025505] [client 34.73.38.214:52701] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6EOu5aQNSViFaxNn5QAAATY"]
[Mon Jul 20 06:51:52.801542 2026] [security2:error] [pid 1025331:tid 1025381] [remote 47.86.33.52:48838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z6EOu5aQNSViFaxNn5AABhjE"]
[Mon Jul 20 06:51:52.802013 2026] [security2:error] [pid 1025331:tid 1025585] [client 47.86.33.52:48838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z6EOu5aQNSViFaxNn5AABhjE"]
[Mon Jul 20 06:51:52.849552 2026] [security2:error] [pid 1020501:tid 1020745] [client 34.73.38.214:56253] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6MS_oRsP4jdONhcOMQAAAHA"]
[Mon Jul 20 06:51:52.861491 2026] [security2:error] [pid 1025331:tid 1025473] [client 202.46.92.242:64056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.92.46.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6EOu5aQNSViFaxNn6AAAARY"]
[Mon Jul 20 06:51:52.861883 2026] [security2:error] [pid 1025331:tid 1025473] [client 202.46.92.242:64056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6EOu5aQNSViFaxNn6AAAARY"]
[Mon Jul 20 06:51:52.897835 2026] [security2:error] [pid 1025331:tid 1025355] [remote 57.141.18.76:59370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z4kOu5aQNSViFaxNmXwABbhc"]
[Mon Jul 20 06:51:52.900289 2026] [security2:error] [pid 1025331:tid 1025534] [client 217.142.18.172:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6EOu5aQNSViFaxNn6QAAAVM"]
[Mon Jul 20 06:51:52.906528 2026] [security2:error] [pid 1025331:tid 1025534] [client 217.142.18.172:61201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6EOu5aQNSViFaxNn6QAAAVM"]
[Mon Jul 20 06:51:53.318379 2026] [security2:error] [pid 1020501:tid 1020755] [client 34.73.38.214:52616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6cS_oRsP4jdONhcOXgAAAHo"]
[Mon Jul 20 06:51:53.343600 2026] [security2:error] [pid 1025331:tid 1025440] [remote 57.141.18.29:54436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z4kOu5aQNSViFaxNmeQABKWw"]
[Mon Jul 20 06:51:53.345540 2026] [security2:error] [pid 1020501:tid 1020671] [client 161.118.218.103:58689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z6cS_oRsP4jdONhcOXwAAACY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:53.388340 2026] [security2:error] [pid 1020501:tid 1020747] [client 192.140.149.97:44812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6cS_oRsP4jdONhcOZQAAAHI"]
[Mon Jul 20 06:51:53.388439 2026] [security2:error] [pid 1020501:tid 1020747] [client 192.140.149.97:44812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6cS_oRsP4jdONhcOZQAAAHI"]
[Mon Jul 20 06:51:53.450499 2026] [security2:error] [pid 1020501:tid 1020712] [client 34.73.38.214:49811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6cS_oRsP4jdONhcObgAAAE8"]
[Mon Jul 20 06:51:53.774706 2026] [security2:error] [pid 1020501:tid 1020687] [client 34.73.38.214:59773] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6cS_oRsP4jdONhcOgQAAADY"]
[Mon Jul 20 06:51:53.924234 2026] [security2:error] [pid 1020501:tid 1020651] [client 161.118.218.103:59052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z6cS_oRsP4jdONhcOjwAAABI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:53.935674 2026] [security2:error] [pid 1020501:tid 1020683] [client 57.141.18.85:27860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z48S_oRsP4jdONhcNwQAAMik"]
[Mon Jul 20 06:51:53.948151 2026] [security2:error] [pid 1020501:tid 1020690] [client 14.225.17.146:62289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4Z6cS_oRsP4jdONhcOhQAAADk"], referer: http://mcg.homes/NEW
[Mon Jul 20 06:51:53.951918 2026] [security2:error] [pid 1020501:tid 1020634] [client 34.73.38.214:58754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6cS_oRsP4jdONhcOlgAAAAE"]
[Mon Jul 20 06:51:54.098936 2026] [security2:error] [pid 1020501:tid 1020733] [client 104.234.53.55:58301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Z6sS_oRsP4jdONhcOrAAAAGQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:54.138332 2026] [security2:error] [pid 1025331:tid 1025479] [client 39.48.81.23:62622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6kOu5aQNSViFaxNn6gAAARw"]
[Mon Jul 20 06:51:54.138457 2026] [security2:error] [pid 1025331:tid 1025479] [client 39.48.81.23:62622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6kOu5aQNSViFaxNn6gAAARw"]
[Mon Jul 20 06:51:54.145835 2026] [security2:error] [pid 1020501:tid 1020661] [client 77.110.127.138:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z6sS_oRsP4jdONhcOsQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:54.145917 2026] [security2:error] [pid 1020501:tid 1020661] [client 77.110.127.138:58499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z6sS_oRsP4jdONhcOsQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:54.335869 2026] [security2:error] [pid 1020501:tid 1020670] [client 14.225.17.146:64473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcOrwAAACU"], referer: http://longevityperformanceclinic.com/NEW
[Mon Jul 20 06:51:54.503787 2026] [security2:error] [pid 1020501:tid 1020700] [client 161.118.218.103:59428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z6sS_oRsP4jdONhcOywAAAEM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:54.534252 2026] [security2:error] [pid 1020501:tid 1020673] [client 34.73.38.214:64515] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6sS_oRsP4jdONhcO0AAAACg"]
[Mon Jul 20 06:51:54.548612 2026] [security2:error] [pid 1020501:tid 1020738] [client 98.159.234.160:29611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4Z6sS_oRsP4jdONhcO0QAAAGk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:51:54.648599 2026] [security2:error] [pid 1020501:tid 1020529] [remote 57.141.18.3:28000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5703786"] [unique_id "al4Z6sS_oRsP4jdONhcO2gAAbxk"]
[Mon Jul 20 06:51:54.662872 2026] [security2:error] [pid 1020501:tid 1020696] [client 103.125.179.95:56053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6sS_oRsP4jdONhcO3AAAAD8"]
[Mon Jul 20 06:51:54.663012 2026] [security2:error] [pid 1020501:tid 1020696] [client 103.125.179.95:56053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z6sS_oRsP4jdONhcO3AAAAD8"]
[Mon Jul 20 06:51:54.762138 2026] [security2:error] [pid 1020501:tid 1020686] [client 34.73.38.214:52979] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6sS_oRsP4jdONhcO4wAAADU"]
[Mon Jul 20 06:51:54.859006 2026] [security2:error] [pid 1020501:tid 1020723] [client 34.73.38.214:59656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Z6sS_oRsP4jdONhcO5wAAAFo"]
[Mon Jul 20 06:51:54.862703 2026] [security2:error] [pid 1020501:tid 1020683] [client 103.238.106.162:60743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z6sS_oRsP4jdONhcO6AAAADI"]
[Mon Jul 20 06:51:54.862814 2026] [security2:error] [pid 1020501:tid 1020683] [client 103.238.106.162:60743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z6sS_oRsP4jdONhcO6AAAADI"]
[Mon Jul 20 06:51:55.079656 2026] [security2:error] [pid 1020501:tid 1020721] [client 161.118.218.103:59768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z68S_oRsP4jdONhcO_gAAAFg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:55.081211 2026] [security2:error] [pid 1020501:tid 1020582] [remote 103.90.234.13:54288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z68S_oRsP4jdONhcO-wAAbU4"]
[Mon Jul 20 06:51:55.085601 2026] [security2:error] [pid 1020501:tid 1020688] [client 117.247.108.24:27758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z68S_oRsP4jdONhcPAAAAADc"]
[Mon Jul 20 06:51:55.085722 2026] [security2:error] [pid 1020501:tid 1020688] [client 117.247.108.24:27758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z68S_oRsP4jdONhcPAAAAADc"]
[Mon Jul 20 06:51:55.296927 2026] [security2:error] [pid 1020501:tid 1020568] [remote 72.167.132.114:41222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4Z68S_oRsP4jdONhcPFAAAVUA"]
[Mon Jul 20 06:51:55.297866 2026] [security2:error] [pid 1020501:tid 1020641] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcO4QAACFI"], referer: http://ardhalwafaa.com/NEW
[Mon Jul 20 06:51:55.335738 2026] [security2:error] [pid 1020501:tid 1020746] [client 34.73.38.214:53013] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Z68S_oRsP4jdONhcPFQAAAHE"]
[Mon Jul 20 06:51:55.350221 2026] [security2:error] [pid 1020501:tid 1020636] [client 34.73.38.214:52210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Z68S_oRsP4jdONhcPFwAAAAM"]
[Mon Jul 20 06:51:55.441356 2026] [security2:error] [pid 1020501:tid 1020662] [client 77.110.127.138:58504] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z68S_oRsP4jdONhcPHAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:55.504262 2026] [security2:error] [pid 1025331:tid 1025428] [remote 57.141.18.82:55324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z5EOu5aQNSViFaxNm5gABgmA"]
[Mon Jul 20 06:51:55.515861 2026] [security2:error] [pid 1020501:tid 1020616] [remote 72.167.132.114:41222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4Z68S_oRsP4jdONhcPIwAAXXA"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 06:51:55.524975 2026] [security2:error] [pid 1020501:tid 1020559] [remote 103.90.234.13:54288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z68S_oRsP4jdONhcPJQAAEzc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:51:55.535511 2026] [security2:error] [pid 1020501:tid 1020702] [client 54.224.22.173:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcO3gAAAEU"]
[Mon Jul 20 06:51:55.575378 2026] [security2:error] [pid 1020501:tid 1020684] [client 54.224.22.173:13546] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4Z6sS_oRsP4jdONhcO2QAAADM"]
[Mon Jul 20 06:51:55.597001 2026] [security2:error] [pid 1020501:tid 1020667] [client 77.110.127.138:58505] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z68S_oRsP4jdONhcPLgAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:55.655446 2026] [security2:error] [pid 1020501:tid 1020750] [client 161.118.218.103:60083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z68S_oRsP4jdONhcPOQAAAHU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:55.751621 2026] [security2:error] [pid 1020501:tid 1020701] [client 77.110.127.138:58506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z68S_oRsP4jdONhcPQgAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:55.789490 2026] [security2:error] [pid 1025331:tid 1025407] [remote 57.141.18.3:38144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z5UOu5aQNSViFaxNm-QABRUs"]
[Mon Jul 20 06:51:55.968623 2026] [security2:error] [pid 1020501:tid 1020729] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4Z68S_oRsP4jdONhcPOgAAAGA"]
[Mon Jul 20 06:51:55.969224 2026] [security2:error] [pid 1020501:tid 1020639] [client 113.176.178.148:52202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4Z68S_oRsP4jdONhcPTAAAAAY"]
[Mon Jul 20 06:51:55.980065 2026] [security2:error] [pid 1020501:tid 1020747] [client 70.115.45.82:60718] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/2024/08/01/omenana-speculative-fiction-magazine-issue-29/"] [unique_id "al4Z68S_oRsP4jdONhcPNAAAAHI"]
[Mon Jul 20 06:51:55.983572 2026] [security2:error] [pid 1020501:tid 1020706] [client 34.73.38.214:51202] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Z68S_oRsP4jdONhcPWAAAAEk"]
[Mon Jul 20 06:51:56.047660 2026] [security2:error] [pid 1020501:tid 1020642] [client 14.225.17.146:64391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcO4gAAAAk"], referer: http://christiancountytrumpet.com/NEW
[Mon Jul 20 06:51:56.073456 2026] [security2:error] [pid 1020501:tid 1020707] [client 183.82.98.154:49843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7MS_oRsP4jdONhcPYQAAAEo"]
[Mon Jul 20 06:51:56.073571 2026] [security2:error] [pid 1020501:tid 1020707] [client 183.82.98.154:49843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7MS_oRsP4jdONhcPYQAAAEo"]
[Mon Jul 20 06:51:56.117145 2026] [security2:error] [pid 1020501:tid 1020671] [client 34.73.38.214:54691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7MS_oRsP4jdONhcPZwAAACY"]
[Mon Jul 20 06:51:56.240085 2026] [security2:error] [pid 1020501:tid 1020731] [client 161.118.218.103:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z7MS_oRsP4jdONhcPdQAAAGI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:56.261628 2026] [security2:error] [pid 1025331:tid 1025386] [remote 57.141.18.82:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z5UOu5aQNSViFaxNnGwABSzY"]
[Mon Jul 20 06:51:56.299549 2026] [security2:error] [pid 1020501:tid 1020663] [client 104.168.114.154:40024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "zoa.jji.mybluehost.me"] [uri "/"] [unique_id "al4Z7MS_oRsP4jdONhcPeAAAAB4"]
[Mon Jul 20 06:51:56.316691 2026] [security2:error] [pid 1020501:tid 1020714] [client 104.168.59.36:45340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.zoa.jji.mybluehost.me"] [uri "/"] [unique_id "al4Z7MS_oRsP4jdONhcPewAAAFE"]
[Mon Jul 20 06:51:56.316835 2026] [security2:error] [pid 1020501:tid 1020686] [client 104.168.59.36:45334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "onewingpictures.com"] [uri "/"] [unique_id "al4Z7MS_oRsP4jdONhcPegAAADU"]
[Mon Jul 20 06:51:56.338479 2026] [security2:error] [pid 1020501:tid 1020640] [client 14.224.227.113:54751] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Z7MS_oRsP4jdONhcPfAAAAAc"]
[Mon Jul 20 06:51:56.350410 2026] [security2:error] [pid 1020501:tid 1020658] [client 104.168.114.154:40036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.onewingpictures.com"] [uri "/"] [unique_id "al4Z7MS_oRsP4jdONhcPfQAAABk"]
[Mon Jul 20 06:51:56.395333 2026] [security2:error] [pid 1020501:tid 1020698] [client 187.108.85.186:59164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7MS_oRsP4jdONhcPhAAAAEE"]
[Mon Jul 20 06:51:56.395415 2026] [security2:error] [pid 1020501:tid 1020698] [client 187.108.85.186:59164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7MS_oRsP4jdONhcPhAAAAEE"]
[Mon Jul 20 06:51:56.419133 2026] [security2:error] [pid 1020501:tid 1020510] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7MS_oRsP4jdONhcPigAAMQY"]
[Mon Jul 20 06:51:56.419252 2026] [security2:error] [pid 1020501:tid 1020682] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7MS_oRsP4jdONhcPigAAMQY"]
[Mon Jul 20 06:51:56.452648 2026] [security2:error] [pid 1020501:tid 1020722] [client 34.73.38.214:50282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundbathmiami.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7MS_oRsP4jdONhcPjwAAAFk"]
[Mon Jul 20 06:51:56.509198 2026] [security2:error] [pid 1020501:tid 1020641] [client 34.73.38.214:57625] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7MS_oRsP4jdONhcPkgAAAAg"]
[Mon Jul 20 06:51:56.717060 2026] [security2:error] [pid 1020501:tid 1020715] [client 14.225.17.146:62047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4Z68S_oRsP4jdONhcPEgAAAFI"], referer: http://eframiproperties.com/NEW
[Mon Jul 20 06:51:56.830251 2026] [security2:error] [pid 1020501:tid 1020655] [client 161.118.218.103:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z7MS_oRsP4jdONhcPqwAAABY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:56.988425 2026] [security2:error] [pid 1020501:tid 1020730] [client 104.234.53.74:44797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4Z7MS_oRsP4jdONhcPtAAAAGE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:51:57.074818 2026] [security2:error] [pid 1020501:tid 1020695] [client 34.73.38.214:54524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.soundhealingsouthflorida.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7cS_oRsP4jdONhcPvAAAAD4"]
[Mon Jul 20 06:51:57.107387 2026] [security2:error] [pid 1025331:tid 1025420] [remote 57.141.18.40:24710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z5kOu5aQNSViFaxNnSQABYVg"]
[Mon Jul 20 06:51:57.361938 2026] [security2:error] [pid 1020501:tid 1020739] [client 14.225.17.146:64476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcO8AAAAGo"], referer: http://overloadcomedy.com/NEW
[Mon Jul 20 06:51:57.416247 2026] [security2:error] [pid 1020501:tid 1020741] [client 161.118.218.103:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z7cS_oRsP4jdONhcP2AAAAGw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:57.481285 2026] [security2:error] [pid 1020501:tid 1020736] [client 14.225.17.146:52001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4Z7cS_oRsP4jdONhcPxgAAAGc"]
[Mon Jul 20 06:51:57.583330 2026] [security2:error] [pid 1020501:tid 1020511] [remote 113.160.142.119:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z7cS_oRsP4jdONhcP4wAAZAc"]
[Mon Jul 20 06:51:57.583593 2026] [security2:error] [pid 1020501:tid 1020733] [client 113.160.142.119:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z7cS_oRsP4jdONhcP4wAAZAc"]
[Mon Jul 20 06:51:57.620678 2026] [security2:error] [pid 1025331:tid 1025434] [remote 57.141.18.113:29356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z5kOu5aQNSViFaxNnbQABfmY"]
[Mon Jul 20 06:51:57.824920 2026] [security2:error] [pid 1020501:tid 1020634] [client 104.168.114.154:40408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.onewingpictures.com"] [uri "/"] [unique_id "al4Z7cS_oRsP4jdONhcP-AAAAAE"]
[Mon Jul 20 06:51:57.876021 2026] [security2:error] [pid 1020501:tid 1020739] [client 34.139.11.221:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.reosportsboats.com"] [uri "/xmlrpc.php"] [unique_id "al4Z7cS_oRsP4jdONhcP_gAAAGo"]
[Mon Jul 20 06:51:57.878664 2026] [security2:error] [pid 1020501:tid 1020660] [client 45.3.42.60:44369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Z7cS_oRsP4jdONhcP-QAAABs"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:51:57.969546 2026] [security2:error] [pid 1020501:tid 1020650] [client 14.225.17.146:49706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4Z7MS_oRsP4jdONhcPdgAAABE"], referer: http://nwcarvingacademy.com/NEW
[Mon Jul 20 06:51:57.995404 2026] [security2:error] [pid 1020501:tid 1020731] [client 161.118.218.103:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z7cS_oRsP4jdONhcQBAAAAGI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:58.039476 2026] [security2:error] [pid 1020501:tid 1020680] [client 34.139.11.221:56490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQCgAAAC8"]
[Mon Jul 20 06:51:58.153835 2026] [security2:error] [pid 1020501:tid 1020756] [client 50.116.65.227:50092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4Z7sS_oRsP4jdONhcQEQAAAHs"]
[Mon Jul 20 06:51:58.163957 2026] [security2:error] [pid 1020501:tid 1020633] [client 50.116.65.227:50096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4Z7sS_oRsP4jdONhcQFAAAAAA"]
[Mon Jul 20 06:51:58.209693 2026] [security2:error] [pid 1020501:tid 1020670] [client 34.139.11.221:57751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQFgAAACU"]
[Mon Jul 20 06:51:58.374604 2026] [security2:error] [pid 1020501:tid 1020712] [client 34.139.11.221:58742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQKQAAAE8"]
[Mon Jul 20 06:51:58.417871 2026] [security2:error] [pid 1020501:tid 1020693] [client 77.110.127.138:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z7sS_oRsP4jdONhcQMQAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:58.418205 2026] [security2:error] [pid 1020501:tid 1020693] [client 77.110.127.138:58512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z7sS_oRsP4jdONhcQMQAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:58.497347 2026] [security2:error] [pid 1020501:tid 1020718] [client 34.139.11.221:51902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQNwAAAFU"]
[Mon Jul 20 06:51:58.584503 2026] [security2:error] [pid 1020501:tid 1020705] [client 161.118.218.103:61904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z7sS_oRsP4jdONhcQPQAAAEg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:58.624148 2026] [security2:error] [pid 1020501:tid 1020738] [client 34.139.11.221:61038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQQQAAAGk"]
[Mon Jul 20 06:51:58.638352 2026] [security2:error] [pid 1020501:tid 1020709] [client 77.110.127.138:58513] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z7sS_oRsP4jdONhcQQgAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:51:58.706828 2026] [security2:error] [pid 1020501:tid 1020706] [client 14.225.17.146:51973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4Z7sS_oRsP4jdONhcQKgAAAEk"], referer: http://hilltopnurseryinc.com/NEW
[Mon Jul 20 06:51:58.800872 2026] [security2:error] [pid 1020501:tid 1020701] [client 34.139.11.221:51424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQUAAAAEQ"]
[Mon Jul 20 06:51:58.929166 2026] [security2:error] [pid 1020501:tid 1020690] [client 34.139.11.221:59093] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Z7sS_oRsP4jdONhcQaAAAADk"]
[Mon Jul 20 06:51:59.053205 2026] [security2:error] [pid 1020501:tid 1020736] [client 14.225.17.146:62967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4Z7sS_oRsP4jdONhcQVgAAAGc"], referer: https://nwcarvingacademy.com/NEW
[Mon Jul 20 06:51:59.115190 2026] [security2:error] [pid 1020501:tid 1020686] [client 34.139.11.221:58986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Z78S_oRsP4jdONhcQcwAAADU"]
[Mon Jul 20 06:51:59.163524 2026] [security2:error] [pid 1020501:tid 1020651] [client 161.118.218.103:62283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z78S_oRsP4jdONhcQdgAAABI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:59.234256 2026] [security2:error] [pid 1020501:tid 1020696] [client 34.139.11.221:64649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Z78S_oRsP4jdONhcQegAAAD8"]
[Mon Jul 20 06:51:59.354115 2026] [security2:error] [pid 1020501:tid 1020610] [remote 100.42.189.89:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4Z78S_oRsP4jdONhcQhAAATmo"]
[Mon Jul 20 06:51:59.369407 2026] [security2:error] [pid 1020501:tid 1020718] [client 34.139.11.221:52987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.reosportsboats.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Z78S_oRsP4jdONhcQhQAAAFU"]
[Mon Jul 20 06:51:59.584635 2026] [security2:error] [pid 1020501:tid 1020523] [remote 100.42.189.89:36296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4Z78S_oRsP4jdONhcQlQAANRM"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 06:51:59.734333 2026] [security2:error] [pid 1020501:tid 1020646] [client 57.141.18.90:23342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z6MS_oRsP4jdONhcOMwAADQM"]
[Mon Jul 20 06:51:59.739641 2026] [security2:error] [pid 1020501:tid 1020751] [client 161.118.218.103:62681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z78S_oRsP4jdONhcQmwAAAHY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:51:59.910273 2026] [security2:error] [pid 1020501:tid 1020745] [client 57.141.18.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4Z78S_oRsP4jdONhcQkQAAAHA"]
[Mon Jul 20 06:52:00.023215 2026] [security2:error] [pid 1020501:tid 1020754] [client 77.110.127.138:58519] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z8MS_oRsP4jdONhcQrAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:00.064717 2026] [security2:error] [pid 1020501:tid 1020656] [client 57.141.18.64:26840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z6cS_oRsP4jdONhcOWwAAFxg"]
[Mon Jul 20 06:52:00.186729 2026] [security2:error] [pid 1020501:tid 1020730] [client 77.110.127.138:58520] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z8MS_oRsP4jdONhcQvQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:00.242442 2026] [security2:error] [pid 1020501:tid 1020691] [client 152.58.191.29:58750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z8MS_oRsP4jdONhcQwgAAADo"]
[Mon Jul 20 06:52:00.242538 2026] [security2:error] [pid 1020501:tid 1020691] [client 152.58.191.29:58750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z8MS_oRsP4jdONhcQwgAAADo"]
[Mon Jul 20 06:52:00.317244 2026] [security2:error] [pid 1020501:tid 1020680] [client 161.118.218.103:63062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z8MS_oRsP4jdONhcQxQAAAC8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:00.358694 2026] [security2:error] [pid 1020501:tid 1020753] [client 57.141.18.122:31412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z6cS_oRsP4jdONhcOdAAAeEs"]
[Mon Jul 20 06:52:00.413082 2026] [security2:error] [pid 1020501:tid 1020760] [client 57.141.18.40:24724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z6cS_oRsP4jdONhcOdQAAfwI"]
[Mon Jul 20 06:52:00.583907 2026] [security2:error] [pid 1020501:tid 1020718] [client 117.222.139.248:51504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4Z8MS_oRsP4jdONhcQ2gAAAFU"]
[Mon Jul 20 06:52:00.584029 2026] [security2:error] [pid 1020501:tid 1020718] [client 117.222.139.248:51504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4Z8MS_oRsP4jdONhcQ2gAAAFU"]
[Mon Jul 20 06:52:00.893766 2026] [security2:error] [pid 1020501:tid 1020752] [client 161.118.218.103:63401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z8MS_oRsP4jdONhcQ6AAAAHc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:01.157940 2026] [security2:error] [pid 1020501:tid 1020720] [client 122.183.32.225:32500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Z8cS_oRsP4jdONhcRAgAAAFc"]
[Mon Jul 20 06:52:01.167680 2026] [security2:error] [pid 1020501:tid 1020720] [client 122.183.32.225:32500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4Z8cS_oRsP4jdONhcRAgAAAFc"]
[Mon Jul 20 06:52:01.242136 2026] [security2:error] [pid 1020501:tid 1020667] [client 104.234.53.70:36983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Z8cS_oRsP4jdONhcRDAAAACI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:01.409780 2026] [security2:error] [pid 1020501:tid 1020687] [client 65.111.8.122:37147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Z8cS_oRsP4jdONhcRGwAAADY"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:01.479897 2026] [security2:error] [pid 1020501:tid 1020709] [client 161.118.218.103:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z8cS_oRsP4jdONhcRKAAAAEw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:01.644291 2026] [security2:error] [pid 1020501:tid 1020727] [client 57.141.18.26:20624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcO1AAAXgE"]
[Mon Jul 20 06:52:01.690322 2026] [security2:error] [pid 1020501:tid 1020697] [client 57.141.18.31:27002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z6sS_oRsP4jdONhcO3QAAQCc"]
[Mon Jul 20 06:52:01.796633 2026] [security2:error] [pid 1020501:tid 1020738] [client 14.225.17.146:61711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4Z8cS_oRsP4jdONhcRMwAAAGk"]
[Mon Jul 20 06:52:01.796633 2026] [security2:error] [pid 1020501:tid 1020633] [client 77.110.127.138:58526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z8cS_oRsP4jdONhcRPQAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:02.055867 2026] [security2:error] [pid 1020501:tid 1020649] [client 161.118.218.103:64135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z8sS_oRsP4jdONhcRWgAAABA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:02.360241 2026] [security2:error] [pid 1020501:tid 1020716] [client 57.141.18.12:34138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z68S_oRsP4jdONhcO_AAAU3Q"]
[Mon Jul 20 06:52:02.367994 2026] [security2:error] [pid 1020501:tid 1020642] [client 197.186.66.42:63670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z8sS_oRsP4jdONhcRbQAAAAk"]
[Mon Jul 20 06:52:02.368097 2026] [security2:error] [pid 1020501:tid 1020642] [client 197.186.66.42:63670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z8sS_oRsP4jdONhcRbQAAAAk"]
[Mon Jul 20 06:52:02.479555 2026] [security2:error] [pid 1020501:tid 1020689] [client 57.141.18.114:38882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z68S_oRsP4jdONhcPFgAAOEI"]
[Mon Jul 20 06:52:02.565980 2026] [security2:error] [pid 1020501:tid 1020732] [client 14.225.17.146:60614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4Z8sS_oRsP4jdONhcRcAAAAGM"], referer: http://mtlegnews.gov/NEW
[Mon Jul 20 06:52:02.629082 2026] [security2:error] [pid 1020501:tid 1020646] [client 14.225.17.146:60364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4Z8sS_oRsP4jdONhcRdgAAAA0"], referer: http://fineartsfactory.net/NEW
[Mon Jul 20 06:52:02.648308 2026] [security2:error] [pid 1020501:tid 1020712] [client 161.118.218.103:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z8sS_oRsP4jdONhcRigAAAE8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:03.026426 2026] [security2:error] [pid 1020501:tid 1020691] [client 14.225.17.146:63833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4Z8sS_oRsP4jdONhcRowAAADo"], referer: http://keywayconstructionclt.com/NEW
[Mon Jul 20 06:52:03.030005 2026] [security2:error] [pid 1020501:tid 1020661] [client 57.141.18.88:46232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z68S_oRsP4jdONhcPSQAAHDo"]
[Mon Jul 20 06:52:03.078623 2026] [security2:error] [pid 1020501:tid 1020709] [client 106.219.188.178:29747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z88S_oRsP4jdONhcRsQAAAEw"]
[Mon Jul 20 06:52:03.078814 2026] [security2:error] [pid 1020501:tid 1020709] [client 106.219.188.178:29747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z88S_oRsP4jdONhcRsQAAAEw"]
[Mon Jul 20 06:52:03.209243 2026] [security2:error] [pid 1020501:tid 1020740] [client 77.110.127.138:58530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z88S_oRsP4jdONhcRvQAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:03.209363 2026] [security2:error] [pid 1020501:tid 1020740] [client 77.110.127.138:58530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z88S_oRsP4jdONhcRvQAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:03.226269 2026] [security2:error] [pid 1020501:tid 1020669] [client 161.118.218.103:64907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z88S_oRsP4jdONhcRwQAAACQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:03.513880 2026] [security2:error] [pid 1020501:tid 1020712] [client 217.142.18.172:16215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z88S_oRsP4jdONhcR0wAAAE8"]
[Mon Jul 20 06:52:03.514164 2026] [security2:error] [pid 1020501:tid 1020712] [client 217.142.18.172:16215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z88S_oRsP4jdONhcR0wAAAE8"]
[Mon Jul 20 06:52:03.610097 2026] [security2:error] [pid 1020501:tid 1020556] [remote 57.141.18.24:28480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z7MS_oRsP4jdONhcPiAAAHzQ"]
[Mon Jul 20 06:52:03.824013 2026] [security2:error] [pid 1020501:tid 1020756] [client 104.234.53.69:57853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z88S_oRsP4jdONhcR1AAAAHs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:03.834419 2026] [security2:error] [pid 1020501:tid 1020673] [client 39.48.81.23:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z88S_oRsP4jdONhcR1QAAACg"]
[Mon Jul 20 06:52:03.835038 2026] [security2:error] [pid 1020501:tid 1020673] [client 39.48.81.23:63145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z88S_oRsP4jdONhcR1QAAACg"]
[Mon Jul 20 06:52:04.190584 2026] [http2:info] [pid 1033876:tid 1033876] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:52:04.241340 2026] [security2:error] [pid 1020501:tid 1020726] [client 14.225.17.146:63703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4Z88S_oRsP4jdONhcRwgAAAF0"], referer: http://partnerselectricalllc.com/NEW
[Mon Jul 20 06:52:04.366171 2026] [security2:error] [pid 1020501:tid 1020685] [client 14.225.17.146:63655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4Z88S_oRsP4jdONhcRuAAAADQ"], referer: http://wathenbartlett.co.uk/NEW
[Mon Jul 20 06:52:04.398398 2026] [security2:error] [pid 1033876:tid 1034008] [client 161.118.218.103:65231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z9EfjhWEjDbtLXL5pzgAAAIY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:04.410367 2026] [security2:error] [pid 1033876:tid 1034078] [client 77.110.127.138:58538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z9EfjhWEjDbtLXL5pzwAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:04.411185 2026] [security2:error] [pid 1033876:tid 1034078] [client 77.110.127.138:58538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z9EfjhWEjDbtLXL5pzwAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:04.525448 2026] [security2:error] [pid 1033876:tid 1033901] [remote 95.217.78.234:39842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p2AAAtRc"]
[Mon Jul 20 06:52:04.525716 2026] [security2:error] [pid 1033876:tid 1034055] [client 95.217.78.234:39842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p2AAAtRc"]
[Mon Jul 20 06:52:04.633532 2026] [security2:error] [pid 1020501:tid 1020604] [remote 57.141.18.51:30192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z7cS_oRsP4jdONhcP3wAAdGQ"]
[Mon Jul 20 06:52:04.749630 2026] [security2:error] [pid 1033876:tid 1034021] [client 192.140.149.97:45365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p6wAAAJM"]
[Mon Jul 20 06:52:04.749762 2026] [security2:error] [pid 1033876:tid 1034021] [client 192.140.149.97:45365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p6wAAAJM"]
[Mon Jul 20 06:52:04.823107 2026] [security2:error] [pid 1033876:tid 1033908] [remote 217.61.143.92:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p7AAAoR4"]
[Mon Jul 20 06:52:04.974369 2026] [security2:error] [pid 1033876:tid 1034012] [client 161.118.218.103:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p9AAAAIo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:05.133978 2026] [security2:error] [pid 1033876:tid 1033918] [remote 198.46.152.106:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qBAAAmCg"]
[Mon Jul 20 06:52:05.215251 2026] [security2:error] [pid 1033876:tid 1034014] [client 14.225.17.146:64001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qAQAAAIw"], referer: http://adirondackengineering.com/NEW
[Mon Jul 20 06:52:05.293982 2026] [security2:error] [pid 1033876:tid 1034108] [client 20.206.89.130:19228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qFAAAAOo"]
[Mon Jul 20 06:52:05.294175 2026] [security2:error] [pid 1033876:tid 1034108] [client 20.206.89.130:19228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qFAAAAOo"]
[Mon Jul 20 06:52:05.363649 2026] [security2:error] [pid 1033876:tid 1034011] [client 14.225.17.146:63681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qEgAAAIk"], referer: https://wathenbartlett.co.uk/NEW
[Mon Jul 20 06:52:05.408162 2026] [security2:error] [pid 1020501:tid 1020619] [remote 57.141.18.54:37658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z7sS_oRsP4jdONhcQHgAABXM"]
[Mon Jul 20 06:52:05.422081 2026] [security2:error] [pid 1020501:tid 1020589] [remote 57.141.18.84:33860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z7sS_oRsP4jdONhcQIwAAM1U"]
[Mon Jul 20 06:52:05.426062 2026] [security2:error] [pid 1033876:tid 1034043] [client 103.125.179.95:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qGgAAAKk"]
[Mon Jul 20 06:52:05.429738 2026] [security2:error] [pid 1033876:tid 1034043] [client 103.125.179.95:56557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qGgAAAKk"]
[Mon Jul 20 06:52:05.491230 2026] [security2:error] [pid 1033876:tid 1034063] [client 103.238.106.162:42815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qIwAAAL0"]
[Mon Jul 20 06:52:05.491940 2026] [security2:error] [pid 1033876:tid 1034063] [client 103.238.106.162:42815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qIwAAAL0"]
[Mon Jul 20 06:52:05.548709 2026] [security2:error] [pid 1033876:tid 1034107] [client 161.118.218.103:49977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qKAAAAOk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:05.571640 2026] [security2:error] [pid 1033876:tid 1033932] [remote 217.61.143.92:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qLgAAuDY"], referer: https://sarakety.com/wp-login.php
[Mon Jul 20 06:52:05.605946 2026] [security2:error] [pid 1033876:tid 1033934] [remote 57.141.18.35:23250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5017581"] [unique_id "al4Z9UfjhWEjDbtLXL5qMgAAljg"]
[Mon Jul 20 06:52:05.779343 2026] [security2:error] [pid 1033876:tid 1034056] [client 20.206.89.130:19249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qRgAAALY"]
[Mon Jul 20 06:52:05.779446 2026] [security2:error] [pid 1033876:tid 1034056] [client 20.206.89.130:19249] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qRgAAALY"]
[Mon Jul 20 06:52:05.812236 2026] [security2:error] [pid 1033876:tid 1033940] [remote 198.46.152.106:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qRwAAtT4"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:52:05.846669 2026] [security2:error] [pid 1033876:tid 1034037] [client 77.110.127.138:58549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qSwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:05.846835 2026] [security2:error] [pid 1033876:tid 1034037] [client 77.110.127.138:58549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qSwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:05.929347 2026] [security2:error] [pid 1033876:tid 1034125] [client 117.247.108.24:28647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qTwAAAPs"]
[Mon Jul 20 06:52:05.929471 2026] [security2:error] [pid 1033876:tid 1034125] [client 117.247.108.24:28647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qTwAAAPs"]
[Mon Jul 20 06:52:06.132567 2026] [security2:error] [pid 1033876:tid 1034053] [client 161.118.218.103:50341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qZAAAALM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:06.142157 2026] [security2:error] [pid 1033876:tid 1033951] [remote 45.90.123.233:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qZQAAvEk"]
[Mon Jul 20 06:52:06.206103 2026] [security2:error] [pid 1033876:tid 1034010] [client 14.225.17.146:60655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4Z9EfjhWEjDbtLXL5p0wAAAIg"], referer: http://nomorewetsheets.net/NEW
[Mon Jul 20 06:52:06.283529 2026] [security2:error] [pid 1020501:tid 1020535] [remote 57.141.18.55:33518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z78S_oRsP4jdONhcQggAAUR8"]
[Mon Jul 20 06:52:06.369666 2026] [security2:error] [pid 1033876:tid 1034078] [client 20.206.89.130:18533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/x.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qcgAAAMw"]
[Mon Jul 20 06:52:06.369813 2026] [security2:error] [pid 1033876:tid 1034078] [client 20.206.89.130:18533] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/x.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qcgAAAMw"]
[Mon Jul 20 06:52:06.406524 2026] [security2:error] [pid 1033876:tid 1033959] [remote 45.90.123.233:57658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qdAAAtlE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:52:06.636736 2026] [security2:error] [pid 1033876:tid 1034020] [client 104.168.59.36:47836] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-714924ec.onewingpictures.com"] [uri "/wp-json/batch/v1"] [unique_id "al4Z9kfjhWEjDbtLXL5qgwAAAJI"]
[Mon Jul 20 06:52:06.718094 2026] [security2:error] [pid 1033876:tid 1034041] [client 161.118.218.103:50711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qjgAAAKc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:06.812219 2026] [security2:error] [pid 1033876:tid 1034062] [client 20.206.89.130:19246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/mgrr.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qkAAAALw"]
[Mon Jul 20 06:52:06.812341 2026] [security2:error] [pid 1033876:tid 1034062] [client 20.206.89.130:19246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/mgrr.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qkAAAALw"]
[Mon Jul 20 06:52:06.876388 2026] [security2:error] [pid 1033876:tid 1034112] [client 183.82.98.154:50442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qkgAAAO4"]
[Mon Jul 20 06:52:06.876499 2026] [security2:error] [pid 1033876:tid 1034112] [client 183.82.98.154:50442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qkgAAAO4"]
[Mon Jul 20 06:52:06.989494 2026] [security2:error] [pid 1033876:tid 1033976] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qowAAlmI"]
[Mon Jul 20 06:52:06.989706 2026] [security2:error] [pid 1033876:tid 1034024] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qowAAlmI"]
[Mon Jul 20 06:52:07.013913 2026] [autoindex:error] [pid 1033876:tid 1034081] [client 8.229.41.77:0] AH01276: Cannot serve directory /home4/fbjwyymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:52:07.097728 2026] [security2:error] [pid 1033876:tid 1034043] [client 187.108.85.186:59702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z90fjhWEjDbtLXL5qrgAAAKk"]
[Mon Jul 20 06:52:07.097883 2026] [security2:error] [pid 1033876:tid 1034043] [client 187.108.85.186:59702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4Z90fjhWEjDbtLXL5qrgAAAKk"]
[Mon Jul 20 06:52:07.196449 2026] [security2:error] [pid 1033876:tid 1034018] [client 77.110.127.138:58560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z90fjhWEjDbtLXL5qtwAAAJA"]
[Mon Jul 20 06:52:07.257224 2026] [security2:error] [pid 1033876:tid 1034108] [client 20.206.89.130:18510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/stdin.php"] [unique_id "al4Z90fjhWEjDbtLXL5qwAAAAOo"]
[Mon Jul 20 06:52:07.257319 2026] [security2:error] [pid 1033876:tid 1034108] [client 20.206.89.130:18510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/stdin.php"] [unique_id "al4Z90fjhWEjDbtLXL5qwAAAAOo"]
[Mon Jul 20 06:52:07.302709 2026] [security2:error] [pid 1033876:tid 1034056] [client 161.118.218.103:51076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z90fjhWEjDbtLXL5qwwAAALY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:07.329856 2026] [security2:error] [pid 1033876:tid 1034130] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.factsandminds.com"] [uri "/index.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qIgAAAQA"]
[Mon Jul 20 06:52:07.341048 2026] [security2:error] [pid 1033876:tid 1034051] [client 14.225.17.146:52108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qZgAAALE"], referer: http://sarahholyfield.com/NEW
[Mon Jul 20 06:52:07.346100 2026] [security2:error] [pid 1033876:tid 1033988] [remote 74.235.96.117:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z90fjhWEjDbtLXL5qxgAAhm4"]
[Mon Jul 20 06:52:07.346213 2026] [security2:error] [pid 1033876:tid 1034008] [client 74.235.96.117:45740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z90fjhWEjDbtLXL5qxgAAhm4"]
[Mon Jul 20 06:52:07.413844 2026] [security2:error] [pid 1033876:tid 1033990] [remote 62.146.227.211:34406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.227.146.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z90fjhWEjDbtLXL5qywABBHA"]
[Mon Jul 20 06:52:07.457173 2026] [security2:error] [pid 1033876:tid 1034025] [client 104.207.51.103:47515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Z90fjhWEjDbtLXL5qzAAAAJc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:07.662998 2026] [security2:error] [pid 1020501:tid 1020532] [remote 57.141.18.5:53034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z8MS_oRsP4jdONhcQ9AAAcBw"]
[Mon Jul 20 06:52:07.690615 2026] [security2:error] [pid 1033876:tid 1034105] [client 77.110.127.138:58561] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4Z90fjhWEjDbtLXL5q3gAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:07.701707 2026] [security2:error] [pid 1020501:tid 1020552] [remote 57.141.18.87:61588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z8cS_oRsP4jdONhcQ-wAAcTA"]
[Mon Jul 20 06:52:07.794984 2026] [security2:error] [pid 1033876:tid 1034003] [remote 62.146.227.211:34406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.227.146.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4Z90fjhWEjDbtLXL5q6wAAyX0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:52:07.831180 2026] [security2:error] [pid 1033876:tid 1034110] [client 20.206.89.130:19243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/BDKR28.php"] [unique_id "al4Z90fjhWEjDbtLXL5q7AAAAOw"]
[Mon Jul 20 06:52:07.831309 2026] [security2:error] [pid 1033876:tid 1034110] [client 20.206.89.130:19243] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/BDKR28.php"] [unique_id "al4Z90fjhWEjDbtLXL5q7AAAAOw"]
[Mon Jul 20 06:52:07.893135 2026] [security2:error] [pid 1033876:tid 1034059] [client 161.118.218.103:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z90fjhWEjDbtLXL5q7wAAALk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:08.027874 2026] [security2:error] [pid 1033876:tid 1034020] [client 45.3.42.247:24499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4Z90fjhWEjDbtLXL5q9AAAAJI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:08.281634 2026] [security2:error] [pid 1020501:tid 1020518] [remote 57.141.18.24:28482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z8cS_oRsP4jdONhcRSAAATg4"]
[Mon Jul 20 06:52:08.408009 2026] [security2:error] [pid 1033876:tid 1034047] [client 20.206.89.130:19242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/001.php"] [unique_id "al4Z-EfjhWEjDbtLXL5rEQAAAK0"]
[Mon Jul 20 06:52:08.408100 2026] [security2:error] [pid 1033876:tid 1034047] [client 20.206.89.130:19242] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/001.php"] [unique_id "al4Z-EfjhWEjDbtLXL5rEQAAAK0"]
[Mon Jul 20 06:52:08.469299 2026] [security2:error] [pid 1033876:tid 1034054] [client 161.118.218.103:51856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z-EfjhWEjDbtLXL5rGQAAALQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:08.515306 2026] [security2:error] [pid 1033876:tid 1033899] [remote 47.86.33.52:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4Z-EfjhWEjDbtLXL5rHQAAixU"]
[Mon Jul 20 06:52:08.840894 2026] [security2:error] [pid 1033876:tid 1034022] [client 65.1.132.125:44928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Z-EfjhWEjDbtLXL5rQAAAAJQ"]
[Mon Jul 20 06:52:09.006573 2026] [security2:error] [pid 1033876:tid 1034120] [client 146.190.242.48:60843] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4Z-EfjhWEjDbtLXL5rRQAAAPY"]
[Mon Jul 20 06:52:09.042428 2026] [security2:error] [pid 1033876:tid 1034035] [client 161.118.218.103:52265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rTwAAAKE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:09.130732 2026] [security2:error] [pid 1033876:tid 1034016] [client 20.206.89.130:19241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/dZ3wP5.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rWwAAAI4"]
[Mon Jul 20 06:52:09.130825 2026] [security2:error] [pid 1033876:tid 1034016] [client 20.206.89.130:19241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/dZ3wP5.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rWwAAAI4"]
[Mon Jul 20 06:52:09.307654 2026] [security2:error] [pid 1033876:tid 1034077] [client 104.234.53.77:31035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4Z-UfjhWEjDbtLXL5raQAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:09.488339 2026] [security2:error] [pid 1033876:tid 1034090] [client 20.206.89.130:18557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/yup.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rcAAAANg"]
[Mon Jul 20 06:52:09.488439 2026] [security2:error] [pid 1033876:tid 1034090] [client 20.206.89.130:18557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/yup.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rcAAAANg"]
[Mon Jul 20 06:52:09.611337 2026] [security2:error] [pid 1033876:tid 1034132] [client 14.225.17.146:60703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4Z-EfjhWEjDbtLXL5q-AAAAQI"], referer: http://lelandumc.org/NEW
[Mon Jul 20 06:52:09.616557 2026] [security2:error] [pid 1033876:tid 1034067] [client 161.118.218.103:52585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z-UfjhWEjDbtLXL5reQAAAME"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:09.853708 2026] [security2:error] [pid 1033876:tid 1034055] [client 20.206.89.130:19229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/X.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rkAAAALU"]
[Mon Jul 20 06:52:09.853889 2026] [security2:error] [pid 1033876:tid 1034055] [client 20.206.89.130:19229] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/X.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rkAAAALU"]
[Mon Jul 20 06:52:09.970684 2026] [security2:error] [pid 1033876:tid 1033944] [remote 47.86.33.52:3700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rmQAAkEI"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 06:52:10.000354 2026] [security2:error] [pid 1033876:tid 1034105] [client 50.116.65.227:29012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rjQAAAOc"]
[Mon Jul 20 06:52:10.180050 2026] [security2:error] [pid 1033876:tid 1034115] [client 50.116.65.227:29018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rnAAAAPE"]
[Mon Jul 20 06:52:10.190625 2026] [security2:error] [pid 1033876:tid 1034129] [client 161.118.218.103:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rqgAAAP8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:10.254136 2026] [security2:error] [pid 1033876:tid 1034113] [client 20.206.89.130:19263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/1polka.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rsAAAAO8"]
[Mon Jul 20 06:52:10.254299 2026] [security2:error] [pid 1033876:tid 1034113] [client 20.206.89.130:19263] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/1polka.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rsAAAAO8"]
[Mon Jul 20 06:52:10.371801 2026] [proxy:error] [pid 1033876:tid 1034068] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:10.371839 2026] [proxy_http:error] [pid 1033876:tid 1034068] [client 34.73.38.214:60994] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:10.372401 2026] [proxy:error] [pid 1033876:tid 1034068] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:10.372426 2026] [proxy_http:error] [pid 1033876:tid 1034068] [client 34.73.38.214:60994] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:10.482486 2026] [security2:error] [pid 1033876:tid 1034023] [client 144.76.32.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4Z-kfjhWEjDbtLXL5ruQAAAJU"]
[Mon Jul 20 06:52:10.621912 2026] [security2:error] [pid 1033876:tid 1034096] [client 20.206.89.130:19202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/gec.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rxwAAAN4"]
[Mon Jul 20 06:52:10.621998 2026] [security2:error] [pid 1033876:tid 1034096] [client 20.206.89.130:19202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/gec.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rxwAAAN4"]
[Mon Jul 20 06:52:10.669246 2026] [security2:error] [pid 1033876:tid 1034126] [client 44.245.170.32:23992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4Z-kfjhWEjDbtLXL5ryAAAAPw"]
[Mon Jul 20 06:52:10.726036 2026] [security2:error] [pid 1033876:tid 1034029] [client 43.205.139.3:38322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rzQAAAJs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:52:10.763690 2026] [security2:error] [pid 1033876:tid 1034037] [client 161.118.218.103:53221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z-kfjhWEjDbtLXL5r0gAAAKM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:10.813636 2026] [security2:error] [pid 1033876:tid 1034062] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rywAAvFE"], referer: http://aleishapenny.ca/NEW
[Mon Jul 20 06:52:10.823681 2026] [proxy:error] [pid 1033876:tid 1034111] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:10.823768 2026] [proxy_http:error] [pid 1033876:tid 1034111] [client 34.73.38.214:64700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:10.824454 2026] [proxy:error] [pid 1033876:tid 1034111] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:10.824500 2026] [proxy_http:error] [pid 1033876:tid 1034111] [client 34.73.38.214:64700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:10.828732 2026] [security2:error] [pid 1033876:tid 1034041] [client 114.119.165.136:58605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lutheranphilosopher.com"] [uri "/apps/members/membersList%3Bjsessionid=FE1324C197354575EBFCD5268BA66D31"] [unique_id "al4Z-kfjhWEjDbtLXL5r2AAAAKc"], referer: https://www.lutheranphilosopher.com/apps/members/membersList%3Bjsessionid=CB504E68E492270A7C4C27DBF9323B90?offset=1&q&sort=DISPLAY_NAME&view=list
[Mon Jul 20 06:52:10.912128 2026] [security2:error] [pid 1033876:tid 1034094] [client 152.58.191.29:59303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z-kfjhWEjDbtLXL5r4gAAANw"]
[Mon Jul 20 06:52:10.912259 2026] [security2:error] [pid 1033876:tid 1034094] [client 152.58.191.29:59303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4Z-kfjhWEjDbtLXL5r4gAAANw"]
[Mon Jul 20 06:52:10.940640 2026] [security2:error] [pid 1033876:tid 1034016] [client 112.82.218.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4Z-kfjhWEjDbtLXL5rxgAAAI4"]
[Mon Jul 20 06:52:10.949787 2026] [security2:error] [pid 1033876:tid 1034089] [client 117.222.139.248:52100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4Z-kfjhWEjDbtLXL5r5QAAANc"]
[Mon Jul 20 06:52:10.949887 2026] [security2:error] [pid 1033876:tid 1034089] [client 117.222.139.248:52100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4Z-kfjhWEjDbtLXL5r5QAAANc"]
[Mon Jul 20 06:52:10.968631 2026] [security2:error] [pid 1033876:tid 1034116] [client 14.224.227.113:54752] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4Z-kfjhWEjDbtLXL5r6AAAAPI"]
[Mon Jul 20 06:52:11.090845 2026] [security2:error] [pid 1033876:tid 1034045] [client 34.139.11.221:51520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.robertpierson.org"] [uri "/xmlrpc.php"] [unique_id "al4Z-0fjhWEjDbtLXL5r7wAAAKs"]
[Mon Jul 20 06:52:11.093218 2026] [security2:error] [pid 1033876:tid 1034023] [client 20.206.89.130:18500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/sky.php"] [unique_id "al4Z-0fjhWEjDbtLXL5r8AAAAJU"]
[Mon Jul 20 06:52:11.093305 2026] [security2:error] [pid 1033876:tid 1034023] [client 20.206.89.130:18500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/sky.php"] [unique_id "al4Z-0fjhWEjDbtLXL5r8AAAAJU"]
[Mon Jul 20 06:52:11.139149 2026] [security2:error] [pid 1033876:tid 1034099] [client 14.225.17.146:65338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4Z-UfjhWEjDbtLXL5rkwAAAOE"], referer: http://whiteoutcb.com/NEW
[Mon Jul 20 06:52:11.238471 2026] [security2:error] [pid 1033876:tid 1034112] [client 34.139.11.221:60185] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Z-0fjhWEjDbtLXL5r-gAAAO4"]
[Mon Jul 20 06:52:11.340184 2026] [security2:error] [pid 1033876:tid 1034010] [client 161.118.218.103:53542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z-0fjhWEjDbtLXL5sBAAAAIg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:11.361456 2026] [proxy:error] [pid 1033876:tid 1034128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:11.361536 2026] [proxy_http:error] [pid 1033876:tid 1034128] [client 34.73.38.214:63728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:11.362285 2026] [proxy:error] [pid 1033876:tid 1034128] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:11.362317 2026] [proxy_http:error] [pid 1033876:tid 1034128] [client 34.73.38.214:63728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:11.368829 2026] [security2:error] [pid 1033876:tid 1034111] [client 34.139.11.221:55226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Z-0fjhWEjDbtLXL5sBwAAAO0"]
[Mon Jul 20 06:52:11.553320 2026] [security2:error] [pid 1033876:tid 1034130] [client 34.139.11.221:59508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Z-0fjhWEjDbtLXL5sGQAAAQA"]
[Mon Jul 20 06:52:11.640284 2026] [security2:error] [pid 1033876:tid 1034024] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4Z-0fjhWEjDbtLXL5sFwAAlm0"], referer: https://aleishapenny.ca/NEW
[Mon Jul 20 06:52:11.694779 2026] [security2:error] [pid 1033876:tid 1034007] [client 20.206.89.130:18548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/fffm.php"] [unique_id "al4Z-0fjhWEjDbtLXL5sJQAAAIU"]
[Mon Jul 20 06:52:11.694866 2026] [security2:error] [pid 1033876:tid 1034007] [client 20.206.89.130:18548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/fffm.php"] [unique_id "al4Z-0fjhWEjDbtLXL5sJQAAAIU"]
[Mon Jul 20 06:52:11.718623 2026] [security2:error] [pid 1033876:tid 1034032] [client 34.139.11.221:50537] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Z-0fjhWEjDbtLXL5sJgAAAJ4"]
[Mon Jul 20 06:52:11.797463 2026] [security2:error] [pid 1033876:tid 1034112] [client 51.68.107.159:14977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "viennarotaryfoundation.org"] [uri "/robots.txt"] [unique_id "al4Z-0fjhWEjDbtLXL5sLAAAAO4"]
[Mon Jul 20 06:52:11.797563 2026] [security2:error] [pid 1033876:tid 1034112] [client 51.68.107.159:14977] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "viennarotaryfoundation.org"] [uri "/robots.txt"] [unique_id "al4Z-0fjhWEjDbtLXL5sLAAAAO4"]
[Mon Jul 20 06:52:11.897473 2026] [security2:error] [pid 1033876:tid 1034103] [client 34.139.11.221:58694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Z-0fjhWEjDbtLXL5sPQAAAOU"]
[Mon Jul 20 06:52:11.911605 2026] [security2:error] [pid 1033876:tid 1034093] [client 161.118.218.103:53860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z-0fjhWEjDbtLXL5sPwAAANs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:12.010741 2026] [security2:error] [pid 1033876:tid 1034115] [client 34.73.38.214:50871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.supportinghands22.org"] [uri "/xmlrpc.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sRgAAAPE"]
[Mon Jul 20 06:52:12.072883 2026] [security2:error] [pid 1033876:tid 1034075] [client 34.139.11.221:51590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5sTAAAAMk"]
[Mon Jul 20 06:52:12.076668 2026] [security2:error] [pid 1033876:tid 1034052] [client 20.206.89.130:18541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/sixxis.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sTQAAALI"]
[Mon Jul 20 06:52:12.076774 2026] [security2:error] [pid 1033876:tid 1034052] [client 20.206.89.130:18541] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/sixxis.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sTQAAALI"]
[Mon Jul 20 06:52:12.204696 2026] [security2:error] [pid 1033876:tid 1034008] [client 34.139.11.221:52908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5sUwAAAIY"]
[Mon Jul 20 06:52:12.220454 2026] [security2:error] [pid 1033876:tid 1034117] [client 104.207.56.247:57433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sUgAAAPM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:12.309200 2026] [security2:error] [pid 1033876:tid 1034038] [client 57.141.18.61:25208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z9UfjhWEjDbtLXL5qTQAApEE"]
[Mon Jul 20 06:52:12.315142 2026] [security2:error] [pid 1033876:tid 1034112] [client 34.139.11.221:58319] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5sWAAAAO4"]
[Mon Jul 20 06:52:12.423797 2026] [security2:error] [pid 1033876:tid 1034018] [client 34.73.38.214:64449] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5sYQAAAJA"]
[Mon Jul 20 06:52:12.460348 2026] [security2:error] [pid 1033876:tid 1034051] [client 34.139.11.221:57282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5sYgAAALE"]
[Mon Jul 20 06:52:12.483929 2026] [security2:error] [pid 1033876:tid 1034076] [client 161.118.218.103:54159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sZgAAAMo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:12.594948 2026] [security2:error] [pid 1033876:tid 1034113] [client 34.139.11.221:51666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5sbgAAAO8"]
[Mon Jul 20 06:52:12.697182 2026] [security2:error] [pid 1033876:tid 1034033] [client 20.206.89.130:19247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/yj09.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sfQAAAJ8"]
[Mon Jul 20 06:52:12.697293 2026] [security2:error] [pid 1033876:tid 1034033] [client 20.206.89.130:19247] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/yj09.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sfQAAAJ8"]
[Mon Jul 20 06:52:12.737067 2026] [security2:error] [pid 1033876:tid 1034045] [client 34.139.11.221:59109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_EfjhWEjDbtLXL5shAAAAKs"]
[Mon Jul 20 06:52:12.757455 2026] [security2:error] [pid 1033876:tid 1034079] [client 57.141.18.44:50588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z9kfjhWEjDbtLXL5qdQAAzVI"]
[Mon Jul 20 06:52:12.842092 2026] [security2:error] [pid 1033876:tid 1033898] [remote 72.167.132.114:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Z_EfjhWEjDbtLXL5siQAArxQ"]
[Mon Jul 20 06:52:12.888681 2026] [security2:error] [pid 1033876:tid 1034126] [client 50.116.65.227:60640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4Z_EfjhWEjDbtLXL5skQAAAPw"]
[Mon Jul 20 06:52:12.894796 2026] [security2:error] [pid 1033876:tid 1034068] [client 142.250.33.70:56287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4Z-0fjhWEjDbtLXL5sFgAAAMI"]
[Mon Jul 20 06:52:13.008926 2026] [security2:error] [pid 1033876:tid 1034093] [client 34.139.11.221:52370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.11.139.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_UfjhWEjDbtLXL5sngAAANs"]
[Mon Jul 20 06:52:13.010680 2026] [security2:error] [pid 1033876:tid 1034021] [client 104.234.53.70:32733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4Z_UfjhWEjDbtLXL5snwAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:13.039016 2026] [security2:error] [pid 1033876:tid 1034108] [client 20.206.89.130:18531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/f900.php"] [unique_id "al4Z_UfjhWEjDbtLXL5soQAAAOo"]
[Mon Jul 20 06:52:13.039142 2026] [security2:error] [pid 1033876:tid 1034108] [client 20.206.89.130:18531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/f900.php"] [unique_id "al4Z_UfjhWEjDbtLXL5soQAAAOo"]
[Mon Jul 20 06:52:13.059589 2026] [security2:error] [pid 1033876:tid 1034122] [client 161.118.218.103:54456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z_UfjhWEjDbtLXL5spQAAAPg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:13.070347 2026] [security2:error] [pid 1033876:tid 1034104] [client 34.73.38.214:62060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5spwAAAOY"]
[Mon Jul 20 06:52:13.089455 2026] [security2:error] [pid 1033876:tid 1033909] [remote 72.167.132.114:60910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4Z_UfjhWEjDbtLXL5sqAAA2R8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:52:13.179378 2026] [security2:error] [pid 1033876:tid 1034034] [client 34.139.11.221:59055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5sqwAAAKA"]
[Mon Jul 20 06:52:13.293475 2026] [security2:error] [pid 1033876:tid 1034094] [client 34.139.11.221:59802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5ssQAAANw"]
[Mon Jul 20 06:52:13.430674 2026] [security2:error] [pid 1033876:tid 1034120] [client 34.139.11.221:63553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5swgAAAPY"]
[Mon Jul 20 06:52:13.536901 2026] [security2:error] [pid 1033876:tid 1034061] [client 34.73.38.214:62043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5szQAAALs"]
[Mon Jul 20 06:52:13.549886 2026] [security2:error] [pid 1033876:tid 1034014] [client 34.139.11.221:56441] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5szgAAAIw"]
[Mon Jul 20 06:52:13.635218 2026] [security2:error] [pid 1033876:tid 1034047] [client 161.118.218.103:54841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s0gAAAK0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:13.638549 2026] [security2:error] [pid 1033876:tid 1034105] [client 20.206.89.130:19223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/ups.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s0wAAAOc"]
[Mon Jul 20 06:52:13.638658 2026] [security2:error] [pid 1033876:tid 1034105] [client 20.206.89.130:19223] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/ups.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s0wAAAOc"]
[Mon Jul 20 06:52:13.675939 2026] [security2:error] [pid 1033876:tid 1034081] [client 45.3.55.102:41839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s0QAAAM8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:13.694415 2026] [security2:error] [pid 1033876:tid 1034051] [client 34.139.11.221:61564] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5s1QAAALE"]
[Mon Jul 20 06:52:13.730848 2026] [core:error] [pid 1033876:tid 1034060] [client 14.225.17.146:60602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:13.730869 2026] [core:error] [pid 1033876:tid 1034060] [client 14.225.17.146:60602] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:13.809245 2026] [security2:error] [pid 1033876:tid 1034085] [client 34.139.11.221:62500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5s3wAAANM"]
[Mon Jul 20 06:52:13.870191 2026] [security2:error] [pid 1033876:tid 1034124] [client 34.73.38.214:61528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5s6QAAAPo"]
[Mon Jul 20 06:52:13.926738 2026] [security2:error] [pid 1033876:tid 1034009] [client 106.219.188.178:15816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s7gAAAIc"]
[Mon Jul 20 06:52:13.927501 2026] [security2:error] [pid 1033876:tid 1034009] [client 106.219.188.178:15816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s7gAAAIc"]
[Mon Jul 20 06:52:13.940076 2026] [security2:error] [pid 1033876:tid 1034022] [client 57.141.18.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s3QAAAJQ"]
[Mon Jul 20 06:52:13.953598 2026] [security2:error] [pid 1033876:tid 1034055] [client 34.139.11.221:51818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_UfjhWEjDbtLXL5s8QAAALU"]
[Mon Jul 20 06:52:13.982990 2026] [security2:error] [pid 1033876:tid 1034053] [client 20.206.89.130:19252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/k.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s-QAAALM"]
[Mon Jul 20 06:52:13.983088 2026] [security2:error] [pid 1033876:tid 1034053] [client 20.206.89.130:19252] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/k.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s-QAAALM"]
[Mon Jul 20 06:52:14.061218 2026] [security2:error] [pid 1033876:tid 1034087] [client 217.142.18.172:1077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tAgAAANU"]
[Mon Jul 20 06:52:14.073451 2026] [security2:error] [pid 1033876:tid 1034104] [client 34.139.11.221:53802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_kfjhWEjDbtLXL5tBAAAAOY"]
[Mon Jul 20 06:52:14.084855 2026] [security2:error] [pid 1033876:tid 1034087] [client 217.142.18.172:1077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tAgAAANU"]
[Mon Jul 20 06:52:14.116983 2026] [security2:error] [pid 1033876:tid 1034024] [client 14.225.17.146:49955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sZwAAAJY"], referer: http://ironcitywellness.com/NEW
[Mon Jul 20 06:52:14.191151 2026] [security2:error] [pid 1033876:tid 1034113] [client 34.139.11.221:52094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_kfjhWEjDbtLXL5tDwAAAO8"]
[Mon Jul 20 06:52:14.218519 2026] [security2:error] [pid 1033876:tid 1034122] [client 161.118.218.103:55232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tEAAAAPg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:14.350518 2026] [security2:error] [pid 1033876:tid 1034029] [client 34.139.11.221:63582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.roguedragonstudio.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_kfjhWEjDbtLXL5tFgAAAJs"]
[Mon Jul 20 06:52:14.390864 2026] [security2:error] [pid 1033876:tid 1034009] [client 34.73.38.214:55455] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_kfjhWEjDbtLXL5tGgAAAIc"]
[Mon Jul 20 06:52:14.412722 2026] [security2:error] [pid 1033876:tid 1033938] [remote 152.228.213.32:49820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tGwABAzw"]
[Mon Jul 20 06:52:14.412976 2026] [security2:error] [pid 1033876:tid 1034133] [client 152.228.213.32:49820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tGwABAzw"]
[Mon Jul 20 06:52:14.424131 2026] [security2:error] [pid 1033876:tid 1034099] [client 20.206.89.130:18508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/k2.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tHQAAAOE"]
[Mon Jul 20 06:52:14.424215 2026] [security2:error] [pid 1033876:tid 1034099] [client 20.206.89.130:18508] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/k2.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tHQAAAOE"]
[Mon Jul 20 06:52:14.518271 2026] [security2:error] [pid 1033876:tid 1034077] [client 65.111.21.60:34035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tKAAAAMs"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:14.618013 2026] [security2:error] [pid 1033876:tid 1034037] [client 14.225.17.146:62534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4Z_EfjhWEjDbtLXL5sVQAAAKM"], referer: http://talknutritionwithlesley.com/NEW
[Mon Jul 20 06:52:14.630896 2026] [security2:error] [pid 1033876:tid 1034012] [client 14.225.17.146:63686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tCAAAAIo"], referer: http://onewingpictures.com/NEW
[Mon Jul 20 06:52:14.744446 2026] [security2:error] [pid 1033876:tid 1034049] [client 14.225.17.146:63653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Z_UfjhWEjDbtLXL5s5gAAAK8"]
[Mon Jul 20 06:52:14.755770 2026] [security2:error] [pid 1033876:tid 1033964] [remote 192.241.143.148:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tQAAA7FY"]
[Mon Jul 20 06:52:14.792168 2026] [security2:error] [pid 1033876:tid 1034087] [client 161.118.218.103:55602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tQwAAANU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:14.811554 2026] [security2:error] [pid 1033876:tid 1034095] [client 192.140.149.97:46056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tRQAAAN0"]
[Mon Jul 20 06:52:14.811684 2026] [security2:error] [pid 1033876:tid 1034095] [client 192.140.149.97:46056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tRQAAAN0"]
[Mon Jul 20 06:52:14.856775 2026] [security2:error] [pid 1033876:tid 1034016] [client 20.206.89.130:19259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/w.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tSQAAAI4"]
[Mon Jul 20 06:52:14.856885 2026] [security2:error] [pid 1033876:tid 1034016] [client 20.206.89.130:19259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/w.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tSQAAAI4"]
[Mon Jul 20 06:52:14.980842 2026] [security2:error] [pid 1033876:tid 1033975] [remote 192.241.143.148:52194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tVgAAymE"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 06:52:15.103440 2026] [security2:error] [pid 1033876:tid 1034035] [client 34.73.38.214:65496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_0fjhWEjDbtLXL5tZwAAAKE"]
[Mon Jul 20 06:52:15.273849 2026] [security2:error] [pid 1033876:tid 1034059] [client 20.206.89.130:19212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/fpwch.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tcgAAALk"]
[Mon Jul 20 06:52:15.273980 2026] [security2:error] [pid 1033876:tid 1034059] [client 20.206.89.130:19212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/fpwch.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tcgAAALk"]
[Mon Jul 20 06:52:15.323184 2026] [security2:error] [pid 1033876:tid 1034115] [client 14.225.17.146:60045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tbAAAAPE"]
[Mon Jul 20 06:52:15.369262 2026] [security2:error] [pid 1033876:tid 1034030] [client 161.118.218.103:55986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4Z_0fjhWEjDbtLXL5teQAAAJw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:15.476925 2026] [security2:error] [pid 1033876:tid 1034124] [client 14.225.17.146:63503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tNwAAAPo"], referer: http://transparentservices.online/NEW
[Mon Jul 20 06:52:15.635902 2026] [security2:error] [pid 1033876:tid 1034072] [client 156.59.198.136:45464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/wp/wp-content/uploads/2015/02/Application-for-Employment-CCS.pdf"] [unique_id "al4Z_0fjhWEjDbtLXL5tlAAAAMY"]
[Mon Jul 20 06:52:15.683287 2026] [security2:error] [pid 1033876:tid 1034035] [client 20.206.89.130:18558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.89.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.securingmemories.com"] [uri "/w2025.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tlQAAAKE"]
[Mon Jul 20 06:52:15.683410 2026] [security2:error] [pid 1033876:tid 1034035] [client 20.206.89.130:18558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.securingmemories.com"] [uri "/w2025.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tlQAAAKE"]
[Mon Jul 20 06:52:15.696074 2026] [security2:error] [pid 1033876:tid 1034116] [client 34.73.38.214:57476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4Z_0fjhWEjDbtLXL5tlgAAAPI"]
[Mon Jul 20 06:52:15.750110 2026] [security2:error] [pid 1033876:tid 1034037] [client 50.116.65.227:29104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tmAAAAKM"]
[Mon Jul 20 06:52:15.754140 2026] [security2:error] [pid 1033876:tid 1034089] [client 14.225.17.146:63683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4Z_kfjhWEjDbtLXL5tDQAAANc"], referer: http://recruitinginsight.us/NEW
[Mon Jul 20 06:52:15.828215 2026] [security2:error] [pid 1033876:tid 1034125] [client 197.186.66.42:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tmgAAAPs"]
[Mon Jul 20 06:52:15.828605 2026] [security2:error] [pid 1033876:tid 1034125] [client 197.186.66.42:64206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tmgAAAPs"]
[Mon Jul 20 06:52:15.944241 2026] [security2:error] [pid 1033876:tid 1034117] [client 161.118.218.103:56316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tngAAAPM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:16.052875 2026] [security2:error] [pid 1033876:tid 1034107] [client 103.238.106.162:60794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5tqwAAAOk"]
[Mon Jul 20 06:52:16.053035 2026] [security2:error] [pid 1033876:tid 1034107] [client 103.238.106.162:60794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5tqwAAAOk"]
[Mon Jul 20 06:52:16.162527 2026] [security2:error] [pid 1033876:tid 1034034] [client 110.249.201.210:11368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tejasenvironmental.com"] [uri "/robots.txt"] [unique_id "al4aAEfjhWEjDbtLXL5tvAAAAKA"]
[Mon Jul 20 06:52:16.203763 2026] [security2:error] [pid 1033876:tid 1034091] [client 34.73.38.214:59776] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aAEfjhWEjDbtLXL5tvgAAANk"]
[Mon Jul 20 06:52:16.212368 2026] [security2:error] [pid 1033876:tid 1034022] [client 103.125.179.95:57049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5tvwAAAJQ"]
[Mon Jul 20 06:52:16.222102 2026] [security2:error] [pid 1033876:tid 1034022] [client 103.125.179.95:57049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5tvwAAAJQ"]
[Mon Jul 20 06:52:16.242370 2026] [security2:error] [pid 1033876:tid 1034073] [client 50.116.65.227:29092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tkQAAAMc"]
[Mon Jul 20 06:52:16.302347 2026] [security2:error] [pid 1033876:tid 1034056] [client 14.225.17.146:49965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tcAAAALY"], referer: http://adultdaycarereno.com/NEW
[Mon Jul 20 06:52:16.522892 2026] [security2:error] [pid 1033876:tid 1034049] [client 161.118.218.103:56679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aAEfjhWEjDbtLXL5t2QAAAK8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:16.550667 2026] [security2:error] [pid 1033876:tid 1033960] [remote 192.241.143.148:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4aAEfjhWEjDbtLXL5t3AAA1VI"]
[Mon Jul 20 06:52:16.644325 2026] [security2:error] [pid 1033876:tid 1034027] [client 39.48.81.23:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5t4gAAAJk"]
[Mon Jul 20 06:52:16.644424 2026] [security2:error] [pid 1033876:tid 1034027] [client 39.48.81.23:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5t4gAAAJk"]
[Mon Jul 20 06:52:16.725549 2026] [security2:error] [pid 1033876:tid 1034130] [client 117.247.108.24:29498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5t5wAAAQA"]
[Mon Jul 20 06:52:16.725657 2026] [security2:error] [pid 1033876:tid 1034130] [client 117.247.108.24:29498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aAEfjhWEjDbtLXL5t5wAAAQA"]
[Mon Jul 20 06:52:16.737266 2026] [security2:error] [pid 1033876:tid 1033902] [remote 192.241.143.148:52204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4aAEfjhWEjDbtLXL5t6gAAuhg"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:52:16.921640 2026] [security2:error] [pid 1033876:tid 1034113] [client 104.234.53.52:39175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4aAEfjhWEjDbtLXL5t-AAAAO8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:16.934809 2026] [security2:error] [pid 1033876:tid 1034055] [client 65.111.26.69:61753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aAEfjhWEjDbtLXL5t9gAAALU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:16.949793 2026] [security2:error] [pid 1033876:tid 1034119] [client 50.116.65.227:29116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4aAEfjhWEjDbtLXL5twQAAAPU"]
[Mon Jul 20 06:52:17.091149 2026] [security2:error] [pid 1033876:tid 1034099] [client 34.73.38.214:60427] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aAUfjhWEjDbtLXL5uCgAAAOE"]
[Mon Jul 20 06:52:17.097449 2026] [security2:error] [pid 1033876:tid 1034010] [client 161.118.218.103:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aAUfjhWEjDbtLXL5uCwAAAIg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:17.223092 2026] [security2:error] [pid 1033876:tid 1034017] [client 14.225.17.146:62811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4aAUfjhWEjDbtLXL5uCQAAAI8"], referer: http://ghivs.com/NEW
[Mon Jul 20 06:52:17.275641 2026] [security2:error] [pid 1033876:tid 1034126] [client 14.225.17.146:60231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4aAUfjhWEjDbtLXL5uFAAAAPw"], referer: https://adultdaycarereno.com/NEW
[Mon Jul 20 06:52:17.379623 2026] [security2:error] [pid 1033876:tid 1033917] [remote 57.141.18.37:60004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4aAUfjhWEjDbtLXL5uHAAAvyc"]
[Mon Jul 20 06:52:17.410528 2026] [security2:error] [pid 1033876:tid 1034098] [client 57.141.18.115:44410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4Z-0fjhWEjDbtLXL5r-wAA4GM"]
[Mon Jul 20 06:52:17.487131 2026] [security2:error] [pid 1033876:tid 1033922] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aAUfjhWEjDbtLXL5uIgAA3yw"]
[Mon Jul 20 06:52:17.487275 2026] [security2:error] [pid 1033876:tid 1034097] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aAUfjhWEjDbtLXL5uIgAA3yw"]
[Mon Jul 20 06:52:17.556701 2026] [security2:error] [pid 1033876:tid 1034053] [client 14.225.17.146:50199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4Z_0fjhWEjDbtLXL5tkAAAALM"], referer: http://floorsourcestock.com/NEW
[Mon Jul 20 06:52:17.630228 2026] [security2:error] [pid 1033876:tid 1034052] [client 65.111.23.96:39823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aAUfjhWEjDbtLXL5uLgAAALI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:17.672740 2026] [security2:error] [pid 1033876:tid 1034114] [client 161.118.218.103:57384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aAUfjhWEjDbtLXL5uMwAAAPA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:17.692789 2026] [security2:error] [pid 1033876:tid 1034079] [client 14.225.17.146:63395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4aAEfjhWEjDbtLXL5ttQAAAM0"], referer: http://amalia-capital.com/NEW
[Mon Jul 20 06:52:17.778096 2026] [security2:error] [pid 1033876:tid 1034105] [client 45.3.46.225:39291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aAUfjhWEjDbtLXL5uOwAAAOc"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:17.872791 2026] [security2:error] [pid 1033876:tid 1034008] [client 187.108.85.186:60248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aAUfjhWEjDbtLXL5uRAAAAIY"]
[Mon Jul 20 06:52:17.872939 2026] [security2:error] [pid 1033876:tid 1034008] [client 187.108.85.186:60248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aAUfjhWEjDbtLXL5uRAAAAIY"]
[Mon Jul 20 06:52:17.881412 2026] [security2:error] [pid 1033876:tid 1034121] [client 34.73.38.214:52692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aAUfjhWEjDbtLXL5uRgAAAPc"]
[Mon Jul 20 06:52:17.903463 2026] [security2:error] [pid 1033876:tid 1034112] [client 14.225.17.146:62863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4aAUfjhWEjDbtLXL5uNQAAAO4"], referer: http://ccsdifference.com/NEW
[Mon Jul 20 06:52:17.936448 2026] [security2:error] [pid 1033876:tid 1034067] [client 183.82.98.154:51249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aAUfjhWEjDbtLXL5uSgAAAME"]
[Mon Jul 20 06:52:17.936565 2026] [security2:error] [pid 1033876:tid 1034067] [client 183.82.98.154:51249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aAUfjhWEjDbtLXL5uSgAAAME"]
[Mon Jul 20 06:52:18.086094 2026] [security2:error] [pid 1033876:tid 1034104] [client 13.233.207.33:38458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4aAkfjhWEjDbtLXL5uWAAAAOY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:52:18.190319 2026] [core:error] [pid 1033876:tid 1034028] [client 14.225.17.146:51276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:18.190344 2026] [core:error] [pid 1033876:tid 1034028] [client 14.225.17.146:51276] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:18.252411 2026] [security2:error] [pid 1033876:tid 1034100] [client 161.118.218.103:57722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aAkfjhWEjDbtLXL5uaQAAAOI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:18.479681 2026] [security2:error] [pid 1033876:tid 1034079] [client 104.207.53.107:14281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aAkfjhWEjDbtLXL5ucwAAAM0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:18.585635 2026] [security2:error] [pid 1033876:tid 1034103] [client 104.207.34.65:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aAkfjhWEjDbtLXL5ueQAAAOU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:18.822567 2026] [security2:error] [pid 1033876:tid 1034032] [client 34.73.38.214:57544] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.supportinghands22.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aAkfjhWEjDbtLXL5ukQAAAJ4"]
[Mon Jul 20 06:52:18.829083 2026] [security2:error] [pid 1033876:tid 1034096] [client 161.118.218.103:58032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aAkfjhWEjDbtLXL5ukgAAAN4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:19.037593 2026] [security2:error] [pid 1033876:tid 1034024] [client 104.207.50.85:18057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aA0fjhWEjDbtLXL5unQAAAJY"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:19.116545 2026] [security2:error] [pid 1033876:tid 1033953] [remote 5.252.52.249:39252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aA0fjhWEjDbtLXL5upQAA_ks"]
[Mon Jul 20 06:52:19.116712 2026] [security2:error] [pid 1033876:tid 1034128] [client 5.252.52.249:39252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aA0fjhWEjDbtLXL5upQAA_ks"]
[Mon Jul 20 06:52:19.159028 2026] [autoindex:error] [pid 1033876:tid 1034049] [client 198.235.24.38:62598] AH01276: Cannot serve directory /home2/wmljivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:52:19.213217 2026] [autoindex:error] [pid 1033876:tid 1034112] [client 93.159.230.28:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:52:19.405786 2026] [security2:error] [pid 1033876:tid 1034075] [client 161.118.218.103:58374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aA0fjhWEjDbtLXL5uvgAAAMk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:19.576920 2026] [proxy:error] [pid 1033876:tid 1034034] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:19.576958 2026] [proxy_http:error] [pid 1033876:tid 1034034] [client 107.172.180.205:43422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:19.577548 2026] [proxy:error] [pid 1033876:tid 1034034] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:19.577574 2026] [proxy_http:error] [pid 1033876:tid 1034034] [client 107.172.180.205:43422] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:19.638884 2026] [security2:error] [pid 1033876:tid 1034066] [client 14.225.17.146:60235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4aAkfjhWEjDbtLXL5uWgAAAMA"], referer: http://kromosenergy.com/NEW
[Mon Jul 20 06:52:19.671567 2026] [security2:error] [pid 1033876:tid 1034072] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4aA0fjhWEjDbtLXL5uywAAAMY"]
[Mon Jul 20 06:52:19.774589 2026] [security2:error] [pid 1033876:tid 1033986] [remote 217.61.143.92:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4aA0fjhWEjDbtLXL5u4wABAGw"]
[Mon Jul 20 06:52:19.779332 2026] [security2:error] [pid 1033876:tid 1034047] [client 104.234.53.88:50525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aA0fjhWEjDbtLXL5u5AAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:19.966371 2026] [security2:error] [pid 1033876:tid 1034091] [client 14.225.17.146:51292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4aAkfjhWEjDbtLXL5ubwAAANk"], referer: http://vinovinhowine.com/NEW
[Mon Jul 20 06:52:19.979326 2026] [security2:error] [pid 1033876:tid 1034049] [client 161.118.218.103:58751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aA0fjhWEjDbtLXL5u7QAAAK8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:20.030079 2026] [security2:error] [pid 1033876:tid 1034002] [remote 217.61.143.92:39442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4aBEfjhWEjDbtLXL5u9gAAoXw"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 06:52:20.142879 2026] [security2:error] [pid 1033876:tid 1034018] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4aA0fjhWEjDbtLXL5u0AAAkGY"], referer: http://ali-alghanim.net/NEW
[Mon Jul 20 06:52:20.386326 2026] [security2:error] [pid 1033876:tid 1034077] [client 34.207.130.29:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4aBEfjhWEjDbtLXL5vFwAAAMs"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 06:52:20.402839 2026] [autoindex:error] [pid 1033876:tid 1034031] [client 93.159.230.84:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://noisepacks.com
[Mon Jul 20 06:52:20.560673 2026] [security2:error] [pid 1033876:tid 1034071] [client 161.118.218.103:59126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aBEfjhWEjDbtLXL5vJQAAAMU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:20.614223 2026] [core:error] [pid 1033876:tid 1034097] [client 14.225.17.146:51265] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:20.614241 2026] [core:error] [pid 1033876:tid 1034097] [client 14.225.17.146:51265] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:20.819590 2026] [security2:error] [pid 1033876:tid 1034024] [client 52.207.32.99:22552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aBEfjhWEjDbtLXL5vNgAAAJY"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 06:52:20.977205 2026] [security2:error] [pid 1033876:tid 1034058] [client 114.119.151.9:42431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "hammadownenterprises.com"] [uri "/category/site-preparation/excavation-and-grading"] [unique_id "al4aBEfjhWEjDbtLXL5vQgAAALg"], referer: https://hammadownenterprises.com/2017/12/
[Mon Jul 20 06:52:21.117403 2026] [autoindex:error] [pid 1033876:tid 1034056] [client 93.159.230.85:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:52:21.146369 2026] [security2:error] [pid 1033876:tid 1034126] [client 161.118.218.103:59463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aBUfjhWEjDbtLXL5vTQAAAPw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:21.334604 2026] [proxy:error] [pid 1033876:tid 1034101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:21.334666 2026] [proxy_http:error] [pid 1033876:tid 1034101] [client 107.172.180.205:43438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:21.335212 2026] [proxy:error] [pid 1033876:tid 1034101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:21.335240 2026] [proxy_http:error] [pid 1033876:tid 1034101] [client 107.172.180.205:43438] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:21.392958 2026] [security2:error] [pid 1033876:tid 1034043] [client 14.225.17.146:58985] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4aBEfjhWEjDbtLXL5vAAAAAKk"], referer: http://entuvy.com/NEW
[Mon Jul 20 06:52:21.513357 2026] [security2:error] [pid 1033876:tid 1034069] [client 117.222.139.248:52711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aBUfjhWEjDbtLXL5vdAAAAMM"]
[Mon Jul 20 06:52:21.513460 2026] [security2:error] [pid 1033876:tid 1034069] [client 117.222.139.248:52711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aBUfjhWEjDbtLXL5vdAAAAMM"]
[Mon Jul 20 06:52:21.587118 2026] [security2:error] [pid 1033876:tid 1034117] [client 34.23.246.146:39022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "charisandchesed.com"] [uri "/wp-json/batch/v1"] [unique_id "al4aBUfjhWEjDbtLXL5veQAAAPM"]
[Mon Jul 20 06:52:21.640369 2026] [security2:error] [pid 1033876:tid 1034021] [client 50.116.65.227:39200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aBUfjhWEjDbtLXL5vewAAAJM"]
[Mon Jul 20 06:52:21.649961 2026] [security2:error] [pid 1033876:tid 1034064] [client 50.116.65.227:39220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aBUfjhWEjDbtLXL5vfQAAAL4"]
[Mon Jul 20 06:52:21.662934 2026] [security2:error] [pid 1033876:tid 1034128] [client 152.58.191.29:59847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aBUfjhWEjDbtLXL5vgAAAAP4"]
[Mon Jul 20 06:52:21.668714 2026] [security2:error] [pid 1033876:tid 1034038] [client 14.225.17.146:51770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4aBUfjhWEjDbtLXL5vcwAAAKQ"], referer: http://carolinapressurewashers.com/NEW
[Mon Jul 20 06:52:21.674342 2026] [security2:error] [pid 1033876:tid 1034128] [client 152.58.191.29:59847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aBUfjhWEjDbtLXL5vgAAAAP4"]
[Mon Jul 20 06:52:21.723250 2026] [security2:error] [pid 1033876:tid 1034029] [client 161.118.218.103:59835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aBUfjhWEjDbtLXL5vhwAAAJs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:22.074986 2026] [security2:error] [pid 1033876:tid 1034056] [client 14.225.17.146:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4aBUfjhWEjDbtLXL5vlAAAALY"], referer: http://nextlvlmarketingco.com/NEW
[Mon Jul 20 06:52:22.300565 2026] [security2:error] [pid 1033876:tid 1034069] [client 161.118.218.103:60156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aBkfjhWEjDbtLXL5vpgAAAMM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:22.492088 2026] [autoindex:error] [pid 1033876:tid 1033932] [remote 34.177.113.16:64188] AH01276: Cannot serve directory /home2/dekbypmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://dek.byp.mybluehost.me
[Mon Jul 20 06:52:22.595865 2026] [autoindex:error] [pid 1033876:tid 1034052] [client 77.74.177.118:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.noisepacks.com
[Mon Jul 20 06:52:22.611394 2026] [security2:error] [pid 1033876:tid 1034055] [client 104.207.52.136:26167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aBkfjhWEjDbtLXL5vuAAAALU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:22.640996 2026] [security2:error] [pid 1033876:tid 1034083] [client 122.183.32.225:25157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aBkfjhWEjDbtLXL5vuwAAANE"]
[Mon Jul 20 06:52:22.650823 2026] [security2:error] [pid 1033876:tid 1034083] [client 122.183.32.225:25157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aBkfjhWEjDbtLXL5vuwAAANE"]
[Mon Jul 20 06:52:22.776543 2026] [security2:error] [pid 1033876:tid 1034089] [client 57.141.18.94:45820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aAEfjhWEjDbtLXL5uAgAA138"]
[Mon Jul 20 06:52:22.876834 2026] [security2:error] [pid 1033876:tid 1034079] [client 161.118.218.103:60502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aBkfjhWEjDbtLXL5v1wAAAM0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:23.107092 2026] [security2:error] [pid 1033876:tid 1033964] [remote 162.19.86.63:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5v8AAAvlY"]
[Mon Jul 20 06:52:23.232390 2026] [security2:error] [pid 1033876:tid 1034054] [client 65.111.22.251:12999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5v-QAAALQ"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:23.236551 2026] [security2:error] [pid 1033876:tid 1034077] [client 34.23.246.146:39022] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "charisandchesed.com"] [uri "/"] [unique_id "al4aB0fjhWEjDbtLXL5v-gAAAMs"]
[Mon Jul 20 06:52:23.325656 2026] [security2:error] [pid 1033876:tid 1033958] [remote 162.19.86.63:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5v_QAA3FA"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:52:23.337569 2026] [security2:error] [pid 1033876:tid 1034062] [client 104.234.53.83:50555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4aB0fjhWEjDbtLXL5wAAAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:23.385403 2026] [proxy:error] [pid 1033876:tid 1034123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:23.385472 2026] [proxy_http:error] [pid 1033876:tid 1034123] [client 34.73.38.214:50700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:23.386151 2026] [proxy:error] [pid 1033876:tid 1034123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:23.386178 2026] [proxy_http:error] [pid 1033876:tid 1034123] [client 34.73.38.214:50700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:23.430187 2026] [security2:error] [pid 1033876:tid 1033953] [remote 152.228.213.32:36542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5wBwAAr0s"]
[Mon Jul 20 06:52:23.452530 2026] [security2:error] [pid 1033876:tid 1034050] [client 43.135.142.37:34274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4aBkfjhWEjDbtLXL5vtgAAALA"], referer: https://techtradeinc.com/
[Mon Jul 20 06:52:23.455682 2026] [security2:error] [pid 1033876:tid 1034118] [client 161.118.218.103:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aB0fjhWEjDbtLXL5wEAAAAPQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:23.555405 2026] [security2:error] [pid 1033876:tid 1033957] [remote 188.166.241.141:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5wHAAAz08"]
[Mon Jul 20 06:52:23.616126 2026] [security2:error] [pid 1033876:tid 1033961] [remote 152.228.213.32:36542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5wHQAAuFM"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:52:23.726622 2026] [security2:error] [pid 1033876:tid 1034030] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4aB0fjhWEjDbtLXL5wHwAAAJw"]
[Mon Jul 20 06:52:23.839030 2026] [security2:error] [pid 1033876:tid 1034007] [client 14.225.17.146:51772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4aB0fjhWEjDbtLXL5wIwAAAIU"], referer: http://daseighty.net/NEW
[Mon Jul 20 06:52:23.891636 2026] [security2:error] [pid 1033876:tid 1033978] [remote 57.141.18.48:39590] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3623433"] [unique_id "al4aB0fjhWEjDbtLXL5wMAAA-GQ"]
[Mon Jul 20 06:52:23.973165 2026] [security2:error] [pid 1033876:tid 1033973] [remote 188.166.241.141:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4aB0fjhWEjDbtLXL5wNgAA-V8"], referer: https://samueldcohen.com/wp-login.php
[Mon Jul 20 06:52:24.034852 2026] [security2:error] [pid 1033876:tid 1034033] [client 161.118.218.103:61290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aCEfjhWEjDbtLXL5wPgAAAJ8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:24.164280 2026] [security2:error] [pid 1033876:tid 1034101] [client 87.199.205.156:57383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.205.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aCEfjhWEjDbtLXL5wRwAAAOM"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:52:24.164373 2026] [security2:error] [pid 1033876:tid 1034101] [client 87.199.205.156:57383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aCEfjhWEjDbtLXL5wRwAAAOM"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:52:24.356726 2026] [proxy:error] [pid 1033876:tid 1034126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:24.356822 2026] [proxy_http:error] [pid 1033876:tid 1034126] [client 34.73.38.214:54681] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:24.357685 2026] [proxy:error] [pid 1033876:tid 1034126] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:24.357737 2026] [proxy_http:error] [pid 1033876:tid 1034126] [client 34.73.38.214:54681] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:24.591912 2026] [security2:error] [pid 1033876:tid 1034081] [client 217.142.18.172:9852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aCEfjhWEjDbtLXL5wZgAAAM8"]
[Mon Jul 20 06:52:24.592016 2026] [security2:error] [pid 1033876:tid 1034081] [client 217.142.18.172:9852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aCEfjhWEjDbtLXL5wZgAAAM8"]
[Mon Jul 20 06:52:24.611683 2026] [security2:error] [pid 1033876:tid 1034095] [client 161.118.218.103:61655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aCEfjhWEjDbtLXL5wZwAAAN0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:24.674944 2026] [security2:error] [pid 1033876:tid 1034085] [client 106.219.188.178:10295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aCEfjhWEjDbtLXL5wawAAANM"]
[Mon Jul 20 06:52:24.675074 2026] [security2:error] [pid 1033876:tid 1034085] [client 106.219.188.178:10295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aCEfjhWEjDbtLXL5wawAAANM"]
[Mon Jul 20 06:52:24.686210 2026] [security2:error] [pid 1033876:tid 1034107] [client 146.103.116.11:55215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.116.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aCEfjhWEjDbtLXL5wbAAAAOk"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:52:24.686325 2026] [security2:error] [pid 1033876:tid 1034107] [client 146.103.116.11:55215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aCEfjhWEjDbtLXL5wbAAAAOk"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:52:24.837385 2026] [security2:error] [pid 1033876:tid 1034124] [client 74.208.214.194:52384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4aCEfjhWEjDbtLXL5wdQAAAPo"]
[Mon Jul 20 06:52:25.186616 2026] [security2:error] [pid 1033876:tid 1034058] [client 161.118.218.103:62023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aCUfjhWEjDbtLXL5wkQAAALg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:25.317324 2026] [security2:error] [pid 1033876:tid 1033893] [remote 72.167.132.114:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4aCUfjhWEjDbtLXL5wlgAAxA8"]
[Mon Jul 20 06:52:25.496933 2026] [security2:error] [pid 1033876:tid 1034086] [client 39.48.81.23:64196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aCUfjhWEjDbtLXL5wqAAAANQ"]
[Mon Jul 20 06:52:25.497077 2026] [security2:error] [pid 1033876:tid 1034086] [client 39.48.81.23:64196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aCUfjhWEjDbtLXL5wqAAAANQ"]
[Mon Jul 20 06:52:25.501677 2026] [proxy:error] [pid 1033876:tid 1034101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:25.501722 2026] [proxy_http:error] [pid 1033876:tid 1034101] [client 34.73.38.214:52509] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:25.502269 2026] [proxy:error] [pid 1033876:tid 1034101] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:25.502292 2026] [proxy_http:error] [pid 1033876:tid 1034101] [client 34.73.38.214:52509] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:25.524445 2026] [security2:error] [pid 1033876:tid 1033882] [remote 72.167.132.114:50348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4aCUfjhWEjDbtLXL5wrQAA2gQ"], referer: https://mail.grndl.com/wp-login.php
[Mon Jul 20 06:52:25.618468 2026] [security2:error] [pid 1033876:tid 1034089] [client 66.249.68.132:44516] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.americanbubbleball.com"] [uri "/robots.txt"] [unique_id "al4aCUfjhWEjDbtLXL5wuQAAANc"]
[Mon Jul 20 06:52:25.709060 2026] [security2:error] [pid 1033876:tid 1034094] [client 104.234.53.84:54721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aCUfjhWEjDbtLXL5wxQAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:25.759069 2026] [security2:error] [pid 1033876:tid 1034048] [client 161.118.218.103:62357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aCUfjhWEjDbtLXL5wygAAAK4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:25.759671 2026] [security2:error] [pid 1033876:tid 1033900] [remote 103.28.36.106:34482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4aCUfjhWEjDbtLXL5wyQAAwhY"]
[Mon Jul 20 06:52:25.781621 2026] [security2:error] [pid 1033876:tid 1034077] [client 57.141.18.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aCUfjhWEjDbtLXL5wvQAAAMs"]
[Mon Jul 20 06:52:25.856198 2026] [security2:error] [pid 1033876:tid 1033977] [remote 188.40.28.4:40892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aCUfjhWEjDbtLXL5wzAAA0mM"]
[Mon Jul 20 06:52:25.932654 2026] [security2:error] [pid 1033876:tid 1034014] [client 14.225.17.146:51953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4aCEfjhWEjDbtLXL5wbgAAAIw"], referer: http://mourgroup.com/NEW
[Mon Jul 20 06:52:26.064764 2026] [security2:error] [pid 1033876:tid 1033914] [remote 188.40.28.4:40892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aCkfjhWEjDbtLXL5w2QAA4yQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:52:26.300591 2026] [security2:error] [pid 1033876:tid 1033991] [remote 103.28.36.106:34482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4aCkfjhWEjDbtLXL5w6gAAuXE"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:52:26.312432 2026] [proxy:warn] [pid 1033876:tid 1034073] [client 43.134.68.29:54534] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 06:52:26.334782 2026] [security2:error] [pid 1033876:tid 1034062] [client 161.118.218.103:62732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aCkfjhWEjDbtLXL5w8AAAALw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:26.339697 2026] [security2:error] [pid 1033876:tid 1034020] [client 14.225.17.146:51928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4aCEfjhWEjDbtLXL5waQAAAJI"], referer: http://soloceos.com/NEW
[Mon Jul 20 06:52:26.374714 2026] [security2:error] [pid 1033876:tid 1034070] [client 14.225.17.146:51912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4aCkfjhWEjDbtLXL5w4gAAAMQ"], referer: http://jvcmotorsports.com/NEW
[Mon Jul 20 06:52:26.410912 2026] [security2:error] [pid 1033876:tid 1034122] [client 14.251.3.155:54755] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aCkfjhWEjDbtLXL5w9gAAAPg"]
[Mon Jul 20 06:52:26.412362 2026] [core:error] [pid 1033876:tid 1034068] [client 43.134.68.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:26.412378 2026] [core:error] [pid 1033876:tid 1034068] [client 43.134.68.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:26.412503 2026] [security2:error] [pid 1033876:tid 1034068] [client 43.134.68.29:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4aCkfjhWEjDbtLXL5w9QAAAMI"]
[Mon Jul 20 06:52:26.443085 2026] [security2:error] [pid 1033876:tid 1034073] [client 43.134.68.29:54534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/400.shtml"] [unique_id "al4aCkfjhWEjDbtLXL5w7QAAAMc"]
[Mon Jul 20 06:52:26.651235 2026] [security2:error] [pid 1033876:tid 1034133] [client 103.238.106.162:42557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aCkfjhWEjDbtLXL5xDwAAAQM"]
[Mon Jul 20 06:52:26.651343 2026] [security2:error] [pid 1033876:tid 1034133] [client 103.238.106.162:42557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aCkfjhWEjDbtLXL5xDwAAAQM"]
[Mon Jul 20 06:52:26.665073 2026] [security2:error] [pid 1033876:tid 1034030] [client 18.188.251.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4aCkfjhWEjDbtLXL5w6wAAAJw"]
[Mon Jul 20 06:52:26.805153 2026] [security2:error] [pid 1033876:tid 1034045] [client 14.225.17.146:53603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4aCkfjhWEjDbtLXL5w9wAAAKs"], referer: http://idigress.agency/NEW
[Mon Jul 20 06:52:26.908412 2026] [security2:error] [pid 1033876:tid 1034117] [client 161.118.218.103:63118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aCkfjhWEjDbtLXL5xHwAAAPM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:27.005355 2026] [security2:error] [pid 1033876:tid 1034068] [client 34.73.38.214:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xIwAAAMI"]
[Mon Jul 20 06:52:27.032511 2026] [security2:error] [pid 1033876:tid 1034047] [client 103.125.179.95:57565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xJAAAAK0"]
[Mon Jul 20 06:52:27.032627 2026] [security2:error] [pid 1033876:tid 1034047] [client 103.125.179.95:57565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xJAAAAK0"]
[Mon Jul 20 06:52:27.482888 2026] [security2:error] [pid 1033876:tid 1034085] [client 161.118.218.103:63481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aC0fjhWEjDbtLXL5xQgAAANM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:27.497864 2026] [security2:error] [pid 1033876:tid 1034042] [client 117.247.108.24:64835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xRAAAAKg"]
[Mon Jul 20 06:52:27.497968 2026] [security2:error] [pid 1033876:tid 1034042] [client 117.247.108.24:64835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xRAAAAKg"]
[Mon Jul 20 06:52:27.592352 2026] [security2:error] [pid 1033876:tid 1034092] [client 34.73.38.214:62691] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aC0fjhWEjDbtLXL5xTAAAANo"]
[Mon Jul 20 06:52:27.625765 2026] [security2:error] [pid 1033876:tid 1034035] [client 197.186.66.42:64730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xUgAAAKE"]
[Mon Jul 20 06:52:27.636964 2026] [security2:error] [pid 1033876:tid 1034035] [client 197.186.66.42:64730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xUgAAAKE"]
[Mon Jul 20 06:52:27.747944 2026] [security2:error] [pid 1033876:tid 1033976] [remote 57.141.18.122:25858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4aC0fjhWEjDbtLXL5xXgAA-WI"]
[Mon Jul 20 06:52:27.842250 2026] [security2:error] [pid 1033876:tid 1034063] [client 13.232.231.177:11622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xNQAAAL0"]
[Mon Jul 20 06:52:27.925661 2026] [security2:error] [pid 1033876:tid 1034015] [client 57.141.18.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aC0fjhWEjDbtLXL5xYAAAAI0"]
[Mon Jul 20 06:52:27.932551 2026] [security2:error] [pid 1033876:tid 1034067] [client 34.73.38.214:59333] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aC0fjhWEjDbtLXL5xbAAAAME"]
[Mon Jul 20 06:52:27.990565 2026] [security2:error] [pid 1033876:tid 1033971] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xcgAAyV0"]
[Mon Jul 20 06:52:27.990755 2026] [security2:error] [pid 1033876:tid 1034075] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aC0fjhWEjDbtLXL5xcgAAyV0"]
[Mon Jul 20 06:52:28.058267 2026] [security2:error] [pid 1033876:tid 1034058] [client 161.118.218.103:63815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aDEfjhWEjDbtLXL5xfAAAALg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:28.109260 2026] [security2:error] [pid 1033876:tid 1034036] [client 57.141.18.50:45106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aBUfjhWEjDbtLXL5vdQAAoiM"]
[Mon Jul 20 06:52:28.273384 2026] [security2:error] [pid 1033876:tid 1034096] [client 14.225.17.146:51300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4aC0fjhWEjDbtLXL5xLwAAAN4"], referer: http://getgarrison.com/NEW
[Mon Jul 20 06:52:28.419928 2026] [security2:error] [pid 1033876:tid 1034124] [client 187.108.85.186:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aDEfjhWEjDbtLXL5xkwAAAPo"]
[Mon Jul 20 06:52:28.420029 2026] [security2:error] [pid 1033876:tid 1034124] [client 187.108.85.186:60777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aDEfjhWEjDbtLXL5xkwAAAPo"]
[Mon Jul 20 06:52:28.454587 2026] [security2:error] [pid 1033876:tid 1034029] [client 34.73.38.214:49761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aDEfjhWEjDbtLXL5xlgAAAJs"]
[Mon Jul 20 06:52:28.633500 2026] [security2:error] [pid 1033876:tid 1034048] [client 161.118.218.103:64168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aDEfjhWEjDbtLXL5xnwAAAK4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:28.682852 2026] [security2:error] [pid 1033876:tid 1034044] [client 183.82.98.154:51971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aDEfjhWEjDbtLXL5xowAAAKo"]
[Mon Jul 20 06:52:28.682963 2026] [security2:error] [pid 1033876:tid 1034044] [client 183.82.98.154:51971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aDEfjhWEjDbtLXL5xowAAAKo"]
[Mon Jul 20 06:52:28.972813 2026] [security2:error] [pid 1033876:tid 1034016] [client 158.173.166.181:24675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aDEfjhWEjDbtLXL5xtgAAAI4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:52:29.066710 2026] [security2:error] [pid 1033876:tid 1034039] [client 158.173.89.95:36761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aDUfjhWEjDbtLXL5xvAAAAKU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:52:29.127692 2026] [security2:error] [pid 1033876:tid 1034028] [client 34.73.38.214:49751] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aDUfjhWEjDbtLXL5xwQAAAJo"]
[Mon Jul 20 06:52:29.207811 2026] [security2:error] [pid 1033876:tid 1034083] [client 161.118.218.103:64490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aDUfjhWEjDbtLXL5xzgAAANE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:29.208847 2026] [security2:error] [pid 1033876:tid 1034091] [client 104.207.52.183:22445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aDUfjhWEjDbtLXL5xyAAAANk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:29.787709 2026] [security2:error] [pid 1033876:tid 1034128] [client 161.118.218.103:64855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aDUfjhWEjDbtLXL5x8wAAAP4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:29.874728 2026] [security2:error] [pid 1033876:tid 1034116] [client 34.73.38.214:63282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4aDUfjhWEjDbtLXL5x_QAAAPI"]
[Mon Jul 20 06:52:30.089956 2026] [security2:error] [pid 1033876:tid 1034020] [client 45.3.35.4:57985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aDkfjhWEjDbtLXL5yEAAAAJI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:30.369023 2026] [security2:error] [pid 1033876:tid 1034066] [client 161.118.218.103:65251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aDkfjhWEjDbtLXL5yKwAAAMA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:30.684435 2026] [security2:error] [pid 1033876:tid 1034095] [client 104.131.100.174:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/xmlrpc.php"] [unique_id "al4aDkfjhWEjDbtLXL5yOgAAAN0"]
[Mon Jul 20 06:52:30.684583 2026] [security2:error] [pid 1033876:tid 1034095] [client 104.131.100.174:59936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/xmlrpc.php"] [unique_id "al4aDkfjhWEjDbtLXL5yOgAAAN0"]
[Mon Jul 20 06:52:30.709133 2026] [security2:error] [pid 1033876:tid 1034020] [client 34.73.38.214:56089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aDkfjhWEjDbtLXL5yPAAAAJI"]
[Mon Jul 20 06:52:30.756855 2026] [security2:error] [pid 1033876:tid 1034113] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4aDkfjhWEjDbtLXL5yNgAAAO8"]
[Mon Jul 20 06:52:30.808329 2026] [security2:error] [pid 1033876:tid 1034111] [client 104.131.100.174:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/xmlrpc.php"] [unique_id "al4aDkfjhWEjDbtLXL5yQwAAAO0"]
[Mon Jul 20 06:52:30.808426 2026] [security2:error] [pid 1033876:tid 1034111] [client 104.131.100.174:59940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/xmlrpc.php"] [unique_id "al4aDkfjhWEjDbtLXL5yQwAAAO0"]
[Mon Jul 20 06:52:30.907773 2026] [security2:error] [pid 1033876:tid 1034051] [client 2a03:2880:3ff:4d:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nzfoodstory.com"] [uri "/index.php"] [unique_id "al4aDkfjhWEjDbtLXL5yLwAAsSQ"]
[Mon Jul 20 06:52:30.948475 2026] [security2:error] [pid 1033876:tid 1034087] [client 161.118.218.103:49221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aDkfjhWEjDbtLXL5yUgAAANU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:31.072105 2026] [security2:error] [pid 1033876:tid 1034009] [client 104.131.100.174:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/blog/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yXgAAAIc"]
[Mon Jul 20 06:52:31.072277 2026] [security2:error] [pid 1033876:tid 1034009] [client 104.131.100.174:59950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/blog/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yXgAAAIc"]
[Mon Jul 20 06:52:31.119481 2026] [security2:error] [pid 1033876:tid 1034025] [client 34.73.38.214:61133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4aD0fjhWEjDbtLXL5yYAAAAJc"]
[Mon Jul 20 06:52:31.198869 2026] [security2:error] [pid 1033876:tid 1034127] [client 104.131.100.174:59966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/wp/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yYgAAAP0"]
[Mon Jul 20 06:52:31.198977 2026] [security2:error] [pid 1033876:tid 1034127] [client 104.131.100.174:59966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/wp/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yYgAAAP0"]
[Mon Jul 20 06:52:31.292793 2026] [security2:error] [pid 1033876:tid 1034088] [client 35.252.248.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ferrellroofing.com"] [uri "/index.php"] [unique_id "al4aDUfjhWEjDbtLXL5yAQAAANY"]
[Mon Jul 20 06:52:31.413020 2026] [security2:error] [pid 1033876:tid 1034061] [client 104.131.100.174:59974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yegAAALs"]
[Mon Jul 20 06:52:31.413151 2026] [security2:error] [pid 1033876:tid 1034061] [client 104.131.100.174:59974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yegAAALs"]
[Mon Jul 20 06:52:31.464742 2026] [security2:error] [pid 1033876:tid 1033929] [remote 74.235.96.117:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aD0fjhWEjDbtLXL5yfgAAijM"]
[Mon Jul 20 06:52:31.475945 2026] [security2:error] [pid 1033876:tid 1034035] [client 14.225.17.146:51861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4aDUfjhWEjDbtLXL5yCAAAAKE"], referer: http://709fx.com/NEW
[Mon Jul 20 06:52:31.533112 2026] [security2:error] [pid 1033876:tid 1034112] [client 161.118.218.103:49548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aD0fjhWEjDbtLXL5ygQAAAO4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:31.557383 2026] [security2:error] [pid 1033876:tid 1034051] [client 104.131.100.174:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/site/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yhQAAALE"]
[Mon Jul 20 06:52:31.557475 2026] [security2:error] [pid 1033876:tid 1034051] [client 104.131.100.174:59984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/site/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yhQAAALE"]
[Mon Jul 20 06:52:31.598994 2026] [security2:error] [pid 1033876:tid 1034132] [client 34.73.38.214:64370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aD0fjhWEjDbtLXL5yiAAAAQI"]
[Mon Jul 20 06:52:31.656328 2026] [security2:error] [pid 1033876:tid 1033941] [remote 74.235.96.117:57942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aD0fjhWEjDbtLXL5yigAAwT8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:52:31.687850 2026] [security2:error] [pid 1033876:tid 1034069] [client 104.131.100.174:59986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/news/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yjAAAAMM"]
[Mon Jul 20 06:52:31.687947 2026] [security2:error] [pid 1033876:tid 1034069] [client 104.131.100.174:59986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/news/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yjAAAAMM"]
[Mon Jul 20 06:52:31.817319 2026] [security2:error] [pid 1033876:tid 1034119] [client 104.131.100.174:59990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/web/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5ymQAAAPU"]
[Mon Jul 20 06:52:31.817429 2026] [security2:error] [pid 1033876:tid 1034119] [client 104.131.100.174:59990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/web/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5ymQAAAPU"]
[Mon Jul 20 06:52:31.950021 2026] [security2:error] [pid 1033876:tid 1034059] [client 104.131.100.174:60002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/main/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yqwAAALk"]
[Mon Jul 20 06:52:31.950125 2026] [security2:error] [pid 1033876:tid 1034059] [client 104.131.100.174:60002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/main/xmlrpc.php"] [unique_id "al4aD0fjhWEjDbtLXL5yqwAAALk"]
[Mon Jul 20 06:52:31.985658 2026] [proxy:error] [pid 1033876:tid 1034042] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:31.985743 2026] [proxy_http:error] [pid 1033876:tid 1034042] [client 34.73.38.214:64407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:31.987052 2026] [proxy:error] [pid 1033876:tid 1034042] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:31.987111 2026] [proxy_http:error] [pid 1033876:tid 1034042] [client 34.73.38.214:64407] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:31.987532 2026] [security2:error] [pid 1033876:tid 1034044] [client 34.73.38.214:51641] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aD0fjhWEjDbtLXL5yrwAAAKo"]
[Mon Jul 20 06:52:32.042721 2026] [security2:error] [pid 1033876:tid 1034089] [client 117.222.139.248:53168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5ytwAAANc"]
[Mon Jul 20 06:52:32.042834 2026] [security2:error] [pid 1033876:tid 1034089] [client 117.222.139.248:53168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5ytwAAANc"]
[Mon Jul 20 06:52:32.108153 2026] [security2:error] [pid 1033876:tid 1034061] [client 161.118.218.103:49933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aEEfjhWEjDbtLXL5yuwAAALs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:32.116132 2026] [security2:error] [pid 1033876:tid 1034011] [client 57.141.18.103:22272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aCUfjhWEjDbtLXL5wqgAAiRk"]
[Mon Jul 20 06:52:32.180515 2026] [security2:error] [pid 1033876:tid 1034030] [client 104.131.100.174:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/cms/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5ywAAAAJw"]
[Mon Jul 20 06:52:32.180612 2026] [security2:error] [pid 1033876:tid 1034030] [client 104.131.100.174:60006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/cms/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5ywAAAAJw"]
[Mon Jul 20 06:52:32.298860 2026] [security2:error] [pid 1033876:tid 1034070] [client 152.58.191.29:60382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5yywAAAMQ"]
[Mon Jul 20 06:52:32.298958 2026] [security2:error] [pid 1033876:tid 1034070] [client 152.58.191.29:60382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5yywAAAMQ"]
[Mon Jul 20 06:52:32.311677 2026] [security2:error] [pid 1033876:tid 1034023] [client 104.131.100.174:60018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5yzQAAAJU"]
[Mon Jul 20 06:52:32.311779 2026] [security2:error] [pid 1033876:tid 1034023] [client 104.131.100.174:60018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5yzQAAAJU"]
[Mon Jul 20 06:52:32.330979 2026] [security2:error] [pid 1033876:tid 1034018] [client 14.225.17.146:56318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4aDkfjhWEjDbtLXL5yTgAAAJA"], referer: http://slutilities.com/NEW
[Mon Jul 20 06:52:32.443610 2026] [security2:error] [pid 1033876:tid 1034088] [client 104.131.100.174:60028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5y1AAAANY"]
[Mon Jul 20 06:52:32.443728 2026] [security2:error] [pid 1033876:tid 1034088] [client 104.131.100.174:60028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5y1AAAANY"]
[Mon Jul 20 06:52:32.562064 2026] [security2:error] [pid 1033876:tid 1034089] [client 34.73.38.214:60659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4aEEfjhWEjDbtLXL5y4wAAANc"]
[Mon Jul 20 06:52:32.570503 2026] [security2:error] [pid 1033876:tid 1034099] [client 104.131.100.174:60044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/old/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5y5AAAAOE"]
[Mon Jul 20 06:52:32.570604 2026] [security2:error] [pid 1033876:tid 1034099] [client 104.131.100.174:60044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/old/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5y5AAAAOE"]
[Mon Jul 20 06:52:32.690193 2026] [security2:error] [pid 1033876:tid 1034050] [client 161.118.218.103:50254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aEEfjhWEjDbtLXL5y7wAAALA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:32.692587 2026] [security2:error] [pid 1033876:tid 1033978] [remote 57.141.18.27:60980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5276127"] [unique_id "al4aEEfjhWEjDbtLXL5y7gAAlmQ"]
[Mon Jul 20 06:52:32.699465 2026] [security2:error] [pid 1033876:tid 1034082] [client 14.225.17.146:58252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4aD0fjhWEjDbtLXL5ykwAAANA"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/NEW
[Mon Jul 20 06:52:32.719780 2026] [security2:error] [pid 1033876:tid 1034129] [client 104.131.100.174:60060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/new/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5y8AAAAP8"]
[Mon Jul 20 06:52:32.719898 2026] [security2:error] [pid 1033876:tid 1034129] [client 104.131.100.174:60060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "50.116.64.27"] [uri "/new/xmlrpc.php"] [unique_id "al4aEEfjhWEjDbtLXL5y8AAAAP8"]
[Mon Jul 20 06:52:32.764788 2026] [proxy:error] [pid 1033876:tid 1034030] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:32.764840 2026] [proxy_http:error] [pid 1033876:tid 1034030] [client 34.73.38.214:65124] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:32.765401 2026] [proxy:error] [pid 1033876:tid 1034030] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:32.765426 2026] [proxy_http:error] [pid 1033876:tid 1034030] [client 34.73.38.214:65124] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:32.862660 2026] [security2:error] [pid 1033876:tid 1034052] [client 65.111.23.13:11747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aEEfjhWEjDbtLXL5y-gAAALI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:33.068667 2026] [security2:error] [pid 1033876:tid 1034009] [client 104.131.100.174:60076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.100.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "50.116.64.27"] [uri "/wp-login.php"] [unique_id "al4aEUfjhWEjDbtLXL5zDgAAAIc"]
[Mon Jul 20 06:52:33.074455 2026] [security2:error] [pid 1033876:tid 1034010] [client 34.73.38.214:60942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tco.chi.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aEUfjhWEjDbtLXL5zEAAAAIg"]
[Mon Jul 20 06:52:33.082710 2026] [security2:error] [pid 1033876:tid 1034093] [client 57.141.18.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aEEfjhWEjDbtLXL5zBAAAANs"]
[Mon Jul 20 06:52:33.168790 2026] [security2:error] [pid 1033876:tid 1033972] [remote 173.249.4.11:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4aEUfjhWEjDbtLXL5zFQAA5V4"]
[Mon Jul 20 06:52:33.276738 2026] [security2:error] [pid 1033876:tid 1034029] [client 161.118.218.103:50577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aEUfjhWEjDbtLXL5zGwAAAJs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:33.330373 2026] [proxy:error] [pid 1033876:tid 1034024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:33.330431 2026] [proxy_http:error] [pid 1033876:tid 1034024] [client 34.73.38.214:54562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:33.330910 2026] [proxy:error] [pid 1033876:tid 1034024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:33.330937 2026] [proxy_http:error] [pid 1033876:tid 1034024] [client 34.73.38.214:54562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:33.365017 2026] [security2:error] [pid 1033876:tid 1034070] [client 104.234.53.47:20803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4aEUfjhWEjDbtLXL5zJgAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:33.388743 2026] [security2:error] [pid 1033876:tid 1034003] [remote 173.249.4.11:13078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4aEUfjhWEjDbtLXL5zLAAAiX0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:52:33.434910 2026] [security2:error] [pid 1033876:tid 1034012] [client 45.3.42.62:42983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aEUfjhWEjDbtLXL5zLgAAAIo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:33.675583 2026] [security2:error] [pid 1033876:tid 1034095] [client 45.157.112.60:61219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aEUfjhWEjDbtLXL5zQAAAAN0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:52:33.681905 2026] [security2:error] [pid 1033876:tid 1034134] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4aEUfjhWEjDbtLXL5zPgAAAQQ"]
[Mon Jul 20 06:52:33.860989 2026] [security2:error] [pid 1033876:tid 1034105] [client 161.118.218.103:50895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aEUfjhWEjDbtLXL5zRQAAAOc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:33.991055 2026] [security2:error] [pid 1033876:tid 1034009] [client 45.3.54.91:29359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aEUfjhWEjDbtLXL5zVAAAAIc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:34.091850 2026] [security2:error] [pid 1033876:tid 1033899] [remote 103.75.185.95:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aEkfjhWEjDbtLXL5zYgAAzxU"]
[Mon Jul 20 06:52:34.270007 2026] [security2:error] [pid 1033876:tid 1034013] [client 34.73.38.214:61633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aEkfjhWEjDbtLXL5zbQAAAIs"]
[Mon Jul 20 06:52:34.435459 2026] [security2:error] [pid 1033876:tid 1034037] [client 161.118.218.103:51270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aEkfjhWEjDbtLXL5zewAAAKM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:34.527094 2026] [security2:error] [pid 1033876:tid 1034008] [client 77.42.3.111:55672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4aEUfjhWEjDbtLXL5zNQAAAIY"]
[Mon Jul 20 06:52:34.578643 2026] [security2:error] [pid 1033876:tid 1033900] [remote 103.75.185.95:44390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aEkfjhWEjDbtLXL5zjwAA4RY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:52:34.812184 2026] [security2:error] [pid 1033876:tid 1034058] [client 34.73.38.214:63040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aEkfjhWEjDbtLXL5znAAAALg"]
[Mon Jul 20 06:52:35.009958 2026] [security2:error] [pid 1033876:tid 1034013] [client 161.118.218.103:51660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aE0fjhWEjDbtLXL5zxQAAAIs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:35.129520 2026] [security2:error] [pid 1033876:tid 1034121] [client 34.73.38.214:64372] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aE0fjhWEjDbtLXL5z0AAAAPc"]
[Mon Jul 20 06:52:35.143559 2026] [security2:error] [pid 1033876:tid 1034087] [client 14.225.17.146:50574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4aEUfjhWEjDbtLXL5zRAAAANU"], referer: http://elitetax-mi.com/NEW
[Mon Jul 20 06:52:35.187559 2026] [security2:error] [pid 1033876:tid 1034096] [client 217.142.18.172:20011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL5z0gAAAN4"]
[Mon Jul 20 06:52:35.187719 2026] [security2:error] [pid 1033876:tid 1034096] [client 217.142.18.172:20011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL5z0gAAAN4"]
[Mon Jul 20 06:52:35.218677 2026] [security2:error] [pid 1033876:tid 1034073] [client 216.73.217.138:37445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4aE0fjhWEjDbtLXL5zzAAAxyU"]
[Mon Jul 20 06:52:35.358002 2026] [security2:error] [pid 1033876:tid 1034079] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aEkfjhWEjDbtLXL5zrAAAAM0"]
[Mon Jul 20 06:52:35.367997 2026] [security2:error] [pid 1033876:tid 1034118] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aEkfjhWEjDbtLXL5zsAAAAPQ"]
[Mon Jul 20 06:52:35.372528 2026] [security2:error] [pid 1033876:tid 1034063] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aEkfjhWEjDbtLXL5zrgAAAL0"]
[Mon Jul 20 06:52:35.385456 2026] [security2:error] [pid 1033876:tid 1034082] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aEkfjhWEjDbtLXL5zrQAAANA"]
[Mon Jul 20 06:52:35.393530 2026] [security2:error] [pid 1033876:tid 1034053] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aEkfjhWEjDbtLXL5zrwAAALM"]
[Mon Jul 20 06:52:35.411313 2026] [security2:error] [pid 1033876:tid 1034131] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aEkfjhWEjDbtLXL5zsgAAAQE"]
[Mon Jul 20 06:52:35.507377 2026] [security2:error] [pid 1033876:tid 1034084] [client 18.140.64.130:47490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL5z-QAAANI"]
[Mon Jul 20 06:52:35.507498 2026] [security2:error] [pid 1033876:tid 1034084] [client 18.140.64.130:47490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL5z-QAAANI"]
[Mon Jul 20 06:52:35.589623 2026] [security2:error] [pid 1033876:tid 1034112] [client 161.118.218.103:52034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aE0fjhWEjDbtLXL50AwAAAO4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:35.629072 2026] [security2:error] [pid 1033876:tid 1034056] [client 106.219.188.178:42185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL50BAAAALY"]
[Mon Jul 20 06:52:35.629530 2026] [security2:error] [pid 1033876:tid 1034056] [client 106.219.188.178:42185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL50BAAAALY"]
[Mon Jul 20 06:52:35.692332 2026] [security2:error] [pid 1033876:tid 1034045] [client 39.48.81.23:64716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL50CQAAAKs"]
[Mon Jul 20 06:52:35.692507 2026] [security2:error] [pid 1033876:tid 1034045] [client 39.48.81.23:64716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL50CQAAAKs"]
[Mon Jul 20 06:52:35.721682 2026] [security2:error] [pid 1033876:tid 1034070] [client 34.73.38.214:64173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aE0fjhWEjDbtLXL50DQAAAMQ"]
[Mon Jul 20 06:52:35.861733 2026] [security2:error] [pid 1033876:tid 1034047] [client 122.183.32.225:25379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL50FAAAAK0"]
[Mon Jul 20 06:52:35.861892 2026] [security2:error] [pid 1033876:tid 1034047] [client 122.183.32.225:25379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aE0fjhWEjDbtLXL50FAAAAK0"]
[Mon Jul 20 06:52:35.959354 2026] [security2:error] [pid 1033876:tid 1034038] [client 104.234.53.59:44025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4aE0fjhWEjDbtLXL50EgAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:36.051608 2026] [security2:error] [pid 1033876:tid 1034049] [client 192.140.149.97:44737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aFEfjhWEjDbtLXL50JgAAAK8"]
[Mon Jul 20 06:52:36.051718 2026] [security2:error] [pid 1033876:tid 1034049] [client 192.140.149.97:44737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aFEfjhWEjDbtLXL50JgAAAK8"]
[Mon Jul 20 06:52:36.173141 2026] [security2:error] [pid 1033876:tid 1034008] [client 161.118.218.103:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aFEfjhWEjDbtLXL50MgAAAIY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:36.173506 2026] [security2:error] [pid 1033876:tid 1034093] [client 34.73.38.214:53774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4aFEfjhWEjDbtLXL50MwAAANs"]
[Mon Jul 20 06:52:36.189473 2026] [security2:error] [pid 1033876:tid 1034123] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aE0fjhWEjDbtLXL5z7AAAAPk"]
[Mon Jul 20 06:52:36.201942 2026] [security2:error] [pid 1033876:tid 1034010] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aE0fjhWEjDbtLXL5z7wAAAIg"]
[Mon Jul 20 06:52:36.226306 2026] [security2:error] [pid 1033876:tid 1034041] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aE0fjhWEjDbtLXL5z7gAAAKc"]
[Mon Jul 20 06:52:36.227130 2026] [security2:error] [pid 1033876:tid 1034051] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aE0fjhWEjDbtLXL5z7QAAALE"]
[Mon Jul 20 06:52:36.315486 2026] [security2:error] [pid 1033876:tid 1034026] [client 104.234.53.59:44025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aFEfjhWEjDbtLXL50OgAAAJg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:36.412125 2026] [security2:error] [pid 1033876:tid 1034038] [client 162.219.176.3:41594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4aFEfjhWEjDbtLXL50RgAAAKQ"]
[Mon Jul 20 06:52:36.412213 2026] [security2:error] [pid 1033876:tid 1034038] [client 162.219.176.3:41594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4aFEfjhWEjDbtLXL50RgAAAKQ"]
[Mon Jul 20 06:52:36.635013 2026] [security2:error] [pid 1033876:tid 1034067] [client 34.73.38.214:59702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aFEfjhWEjDbtLXL50VQAAAME"]
[Mon Jul 20 06:52:36.755283 2026] [security2:error] [pid 1033876:tid 1034064] [client 161.118.218.103:52791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aFEfjhWEjDbtLXL50XwAAAL4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:36.811364 2026] [security2:error] [pid 1033876:tid 1033978] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/.env.example"] [unique_id "al4aFEfjhWEjDbtLXL50ZgAAlGQ"]
[Mon Jul 20 06:52:36.811936 2026] [security2:error] [pid 1033876:tid 1033975] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.env"] [unique_id "al4aFEfjhWEjDbtLXL50ZwAAlGE"]
[Mon Jul 20 06:52:37.201943 2026] [security2:error] [pid 1033876:tid 1034008] [client 103.238.106.162:42840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aFUfjhWEjDbtLXL50fgAAAIY"]
[Mon Jul 20 06:52:37.202036 2026] [security2:error] [pid 1033876:tid 1034008] [client 103.238.106.162:42840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aFUfjhWEjDbtLXL50fgAAAIY"]
[Mon Jul 20 06:52:37.222729 2026] [security2:error] [pid 1033876:tid 1034037] [client 34.23.246.146:21816] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "charisandchesed.com"] [uri "/"] [unique_id "al4aFUfjhWEjDbtLXL50gQAAAKM"]
[Mon Jul 20 06:52:37.239734 2026] [security2:error] [pid 1033876:tid 1033974] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.env.backup"] [unique_id "al4aFUfjhWEjDbtLXL50ggAAlGA"]
[Mon Jul 20 06:52:37.277812 2026] [security2:error] [pid 1033876:tid 1034098] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFEfjhWEjDbtLXL50ZAAAAOA"]
[Mon Jul 20 06:52:37.335049 2026] [security2:error] [pid 1033876:tid 1034127] [client 161.118.218.103:53195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aFUfjhWEjDbtLXL50jAAAAP0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:37.340942 2026] [security2:error] [pid 1033876:tid 1034085] [client 34.73.38.214:49715] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4aFUfjhWEjDbtLXL50jgAAANM"]
[Mon Jul 20 06:52:37.441180 2026] [security2:error] [pid 1033876:tid 1033995] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.env.bak"] [unique_id "al4aFUfjhWEjDbtLXL50kwAA63U"]
[Mon Jul 20 06:52:37.441320 2026] [security2:error] [pid 1033876:tid 1034003] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.env.old"] [unique_id "al4aFUfjhWEjDbtLXL50lAAA630"]
[Mon Jul 20 06:52:37.583363 2026] [security2:error] [pid 1033876:tid 1034043] [client 104.207.51.150:60407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aFUfjhWEjDbtLXL50ngAAAKk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:37.787565 2026] [security2:error] [pid 1033876:tid 1034101] [client 103.125.179.95:58073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aFUfjhWEjDbtLXL50rwAAAOM"]
[Mon Jul 20 06:52:37.787653 2026] [security2:error] [pid 1033876:tid 1034101] [client 103.125.179.95:58073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aFUfjhWEjDbtLXL50rwAAAOM"]
[Mon Jul 20 06:52:37.909018 2026] [security2:error] [pid 1033876:tid 1034118] [client 161.118.218.103:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aFUfjhWEjDbtLXL50uwAAAPQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:38.111285 2026] [security2:error] [pid 1033876:tid 1033893] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/api/.env"] [unique_id "al4aFkfjhWEjDbtLXL50ygAAyA8"]
[Mon Jul 20 06:52:38.145779 2026] [security2:error] [pid 1033876:tid 1034041] [client 34.73.38.214:49721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aFkfjhWEjDbtLXL500QAAAKc"]
[Mon Jul 20 06:52:38.146080 2026] [security2:error] [pid 1033876:tid 1034097] [client 104.207.50.248:34143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aFkfjhWEjDbtLXL50ywAAAN8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:38.249712 2026] [security2:error] [pid 1033876:tid 1033883] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/secrets.yml"] [unique_id "al4aFkfjhWEjDbtLXL504QAAyAU"]
[Mon Jul 20 06:52:38.249879 2026] [security2:error] [pid 1033876:tid 1033888] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aosta.nz"] [uri "/graphql"] [unique_id "al4aFkfjhWEjDbtLXL503AAAyAo"]
[Mon Jul 20 06:52:38.250727 2026] [security2:error] [pid 1033876:tid 1033909] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/config/.env"] [unique_id "al4aFkfjhWEjDbtLXL502wAAyB8"]
[Mon Jul 20 06:52:38.250903 2026] [security2:error] [pid 1033876:tid 1033885] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/backend/.env"] [unique_id "al4aFkfjhWEjDbtLXL503QAAyAc"]
[Mon Jul 20 06:52:38.386389 2026] [security2:error] [pid 1033876:tid 1034019] [client 117.247.108.24:30368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aFkfjhWEjDbtLXL507gAAAJE"]
[Mon Jul 20 06:52:38.386543 2026] [security2:error] [pid 1033876:tid 1034019] [client 117.247.108.24:30368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aFkfjhWEjDbtLXL507gAAAJE"]
[Mon Jul 20 06:52:38.404177 2026] [security2:error] [pid 1033876:tid 1034020] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFUfjhWEjDbtLXL50vAAAAJI"]
[Mon Jul 20 06:52:38.473046 2026] [security2:error] [pid 1033876:tid 1033897] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aFkfjhWEjDbtLXL508AAAoRM"]
[Mon Jul 20 06:52:38.473211 2026] [security2:error] [pid 1033876:tid 1034035] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aFkfjhWEjDbtLXL508AAAoRM"]
[Mon Jul 20 06:52:38.486147 2026] [security2:error] [pid 1033876:tid 1034069] [client 161.118.218.103:53991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aFkfjhWEjDbtLXL508QAAAMM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:38.666232 2026] [proxy:error] [pid 1033876:tid 1034120] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:38.666278 2026] [proxy_http:error] [pid 1033876:tid 1034120] [client 205.210.31.161:60142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:38.666852 2026] [proxy:error] [pid 1033876:tid 1034120] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:38.666877 2026] [proxy_http:error] [pid 1033876:tid 1034120] [client 205.210.31.161:60142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:38.675533 2026] [security2:error] [pid 1033876:tid 1033922] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aosta.nz"] [uri "/api/graphql"] [unique_id "al4aFkfjhWEjDbtLXL51AwAAyCw"]
[Mon Jul 20 06:52:38.695257 2026] [security2:error] [pid 1033876:tid 1033928] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/.s3cfg"] [unique_id "al4aFkfjhWEjDbtLXL51BgAAyDI"]
[Mon Jul 20 06:52:38.695681 2026] [security2:error] [pid 1033876:tid 1033918] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/serviceAccountKey.json"] [unique_id "al4aFkfjhWEjDbtLXL51CAAAyCg"]
[Mon Jul 20 06:52:38.719227 2026] [authz_core:error] [pid 1033876:tid 1034110] [client 34.187.29.36:0] AH01630: client denied by server configuration: /home3/dbnvkfmy/public_html/website_c9c365b4/.htpasswd
[Mon Jul 20 06:52:38.749532 2026] [proxy:error] [pid 1033876:tid 1034097] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:38.749602 2026] [proxy_http:error] [pid 1033876:tid 1034097] [client 198.235.24.6:64768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:38.750231 2026] [proxy:error] [pid 1033876:tid 1034097] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:38.750273 2026] [proxy_http:error] [pid 1033876:tid 1034097] [client 198.235.24.6:64768] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:38.756971 2026] [security2:error] [pid 1033876:tid 1034081] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFkfjhWEjDbtLXL504wAAAM8"]
[Mon Jul 20 06:52:38.987856 2026] [security2:error] [pid 1033876:tid 1034019] [client 34.73.38.214:62886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aFkfjhWEjDbtLXL51JgAAAJE"]
[Mon Jul 20 06:52:39.034852 2026] [security2:error] [pid 1033876:tid 1033920] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "aosta.nz"] [uri "/v1/graphql"] [unique_id "al4aF0fjhWEjDbtLXL51KQAAyCo"]
[Mon Jul 20 06:52:39.043401 2026] [security2:error] [pid 1033876:tid 1033931] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.ssh/id_rsa"] [unique_id "al4aF0fjhWEjDbtLXL51KwAAyDU"]
[Mon Jul 20 06:52:39.060652 2026] [security2:error] [pid 1033876:tid 1034028] [client 161.118.218.103:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aF0fjhWEjDbtLXL51LwAAAJo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:39.175980 2026] [security2:error] [pid 1033876:tid 1034131] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFkfjhWEjDbtLXL51EgAAAQE"]
[Mon Jul 20 06:52:39.181412 2026] [security2:error] [pid 1033876:tid 1033949] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/terraform.tfstate"] [unique_id "al4aF0fjhWEjDbtLXL51NwAAyEc"]
[Mon Jul 20 06:52:39.190262 2026] [security2:error] [pid 1033876:tid 1034017] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFkfjhWEjDbtLXL51EwAAAI8"]
[Mon Jul 20 06:52:39.190890 2026] [security2:error] [pid 1033876:tid 1034031] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFkfjhWEjDbtLXL51FQAAAJ0"]
[Mon Jul 20 06:52:39.269679 2026] [security2:error] [pid 1033876:tid 1034094] [client 187.108.85.186:61334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aF0fjhWEjDbtLXL51PgAAANw"]
[Mon Jul 20 06:52:39.269824 2026] [security2:error] [pid 1033876:tid 1034094] [client 187.108.85.186:61334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aF0fjhWEjDbtLXL51PgAAANw"]
[Mon Jul 20 06:52:39.305698 2026] [security2:error] [pid 1033876:tid 1034111] [client 74.208.214.194:41844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4aF0fjhWEjDbtLXL51QQAAAO0"]
[Mon Jul 20 06:52:39.391071 2026] [security2:error] [pid 1033876:tid 1033964] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/.ssh/id_dsa"] [unique_id "al4aF0fjhWEjDbtLXL51RgAAyFY"]
[Mon Jul 20 06:52:39.391248 2026] [security2:error] [pid 1033876:tid 1033903] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/.ssh/authorized_keys"] [unique_id "al4aF0fjhWEjDbtLXL51SAAAyBk"]
[Mon Jul 20 06:52:39.439368 2026] [security2:error] [pid 1033876:tid 1033946] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/id_dsa"] [unique_id "al4aF0fjhWEjDbtLXL51UgAAyEQ"]
[Mon Jul 20 06:52:39.442053 2026] [security2:error] [pid 1033876:tid 1033929] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/.ssh/config"] [unique_id "al4aF0fjhWEjDbtLXL51VgAAyDM"]
[Mon Jul 20 06:52:39.442181 2026] [security2:error] [pid 1033876:tid 1034074] [client 34.187.29.36:51158] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aosta.nz"] [uri "/.ssh/config"] [unique_id "al4aF0fjhWEjDbtLXL51VgAAyDM"]
[Mon Jul 20 06:52:39.442852 2026] [security2:error] [pid 1033876:tid 1033924] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/id_rsa"] [unique_id "al4aF0fjhWEjDbtLXL51VQAAyC4"]
[Mon Jul 20 06:52:39.453678 2026] [security2:error] [pid 1033876:tid 1034045] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aFkfjhWEjDbtLXL51JQAAAKs"]
[Mon Jul 20 06:52:39.528117 2026] [security2:error] [pid 1033876:tid 1034020] [client 183.82.98.154:52582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aF0fjhWEjDbtLXL51YQAAAJI"]
[Mon Jul 20 06:52:39.528249 2026] [security2:error] [pid 1033876:tid 1034020] [client 183.82.98.154:52582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aF0fjhWEjDbtLXL51YQAAAJI"]
[Mon Jul 20 06:52:39.529290 2026] [security2:error] [pid 1033876:tid 1034110] [client 3.87.117.29:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.117.87.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4aF0fjhWEjDbtLXL51ZAAAAOw"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 06:52:39.566535 2026] [security2:error] [pid 1033876:tid 1034070] [client 34.73.38.214:52902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aF0fjhWEjDbtLXL51ZwAAAMQ"]
[Mon Jul 20 06:52:39.577018 2026] [security2:error] [pid 1033876:tid 1034128] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51MgAAAP4"]
[Mon Jul 20 06:52:39.634576 2026] [security2:error] [pid 1033876:tid 1033942] [remote 47.128.99.44:39652] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/jogos-internet-2024-01-27-id-26199.pdf"] [unique_id "al4aF0fjhWEjDbtLXL51bgAAoUA"]
[Mon Jul 20 06:52:39.640851 2026] [security2:error] [pid 1033876:tid 1034112] [client 161.118.218.103:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51cAAAAO4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:39.748504 2026] [security2:error] [pid 1033876:tid 1034054] [client 74.7.227.179:50154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51bwAAtGI"], referer: https://tejasenvironmental.com/p=920288
[Mon Jul 20 06:52:39.803946 2026] [security2:error] [pid 1033876:tid 1034066] [client 54.81.157.232:17812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.157.81.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aF0fjhWEjDbtLXL51fwAAAMA"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 06:52:39.853697 2026] [security2:error] [pid 1033876:tid 1033979] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/key.pem"] [unique_id "al4aF0fjhWEjDbtLXL51gwAAyGU"]
[Mon Jul 20 06:52:39.884276 2026] [security2:error] [pid 1033876:tid 1034118] [client 77.110.127.138:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aF0fjhWEjDbtLXL51gQAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:39.884474 2026] [security2:error] [pid 1033876:tid 1034118] [client 77.110.127.138:58583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aF0fjhWEjDbtLXL51gQAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:39.903053 2026] [security2:error] [pid 1033876:tid 1034036] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51TwAAAKI"]
[Mon Jul 20 06:52:39.965887 2026] [security2:error] [pid 1033876:tid 1034115] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51XgAAAPE"]
[Mon Jul 20 06:52:39.974287 2026] [security2:error] [pid 1033876:tid 1034052] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51XAAAALI"]
[Mon Jul 20 06:52:39.987522 2026] [security2:error] [pid 1033876:tid 1034082] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aF0fjhWEjDbtLXL51WwAAANA"]
[Mon Jul 20 06:52:40.041171 2026] [security2:error] [pid 1033876:tid 1034025] [client 77.110.127.138:58605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aGEfjhWEjDbtLXL51kwAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:40.041252 2026] [security2:error] [pid 1033876:tid 1034025] [client 77.110.127.138:58605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aGEfjhWEjDbtLXL51kwAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:40.168161 2026] [security2:error] [pid 1033876:tid 1033962] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/privatekey.key"] [unique_id "al4aGEfjhWEjDbtLXL51oQAA71Q"]
[Mon Jul 20 06:52:40.194357 2026] [security2:error] [pid 1033876:tid 1034028] [client 77.110.127.138:58608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aGEfjhWEjDbtLXL51qQAAAJo"]
[Mon Jul 20 06:52:40.194475 2026] [security2:error] [pid 1033876:tid 1034028] [client 77.110.127.138:58608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aGEfjhWEjDbtLXL51qQAAAJo"]
[Mon Jul 20 06:52:40.212964 2026] [security2:error] [pid 1033876:tid 1033996] [remote 192.241.143.148:58600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aGEfjhWEjDbtLXL51swAAjHY"]
[Mon Jul 20 06:52:40.219404 2026] [security2:error] [pid 1033876:tid 1034095] [client 161.118.218.103:55172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aGEfjhWEjDbtLXL51tQAAAN0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:40.246913 2026] [security2:error] [pid 1033876:tid 1034125] [client 34.73.38.214:64399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.tff.hws.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aGEfjhWEjDbtLXL51uAAAAPs"]
[Mon Jul 20 06:52:40.381831 2026] [security2:error] [pid 1033876:tid 1034036] [client 77.110.127.138:58613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aGEfjhWEjDbtLXL51wAAAAKI"]
[Mon Jul 20 06:52:40.381953 2026] [security2:error] [pid 1033876:tid 1034036] [client 77.110.127.138:58613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aGEfjhWEjDbtLXL51wAAAAKI"]
[Mon Jul 20 06:52:40.404238 2026] [security2:error] [pid 1033876:tid 1033990] [remote 192.241.143.148:58600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aGEfjhWEjDbtLXL51wwAA63A"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:52:40.421409 2026] [security2:error] [pid 1033876:tid 1034083] [client 197.186.66.42:65257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aGEfjhWEjDbtLXL51xAAAANE"]
[Mon Jul 20 06:52:40.421519 2026] [security2:error] [pid 1033876:tid 1034083] [client 197.186.66.42:65257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aGEfjhWEjDbtLXL51xAAAANE"]
[Mon Jul 20 06:52:40.447640 2026] [security2:error] [pid 1033876:tid 1034057] [client 98.159.234.160:50087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aGEfjhWEjDbtLXL51xQAAALc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:52:40.693796 2026] [security2:error] [pid 1033876:tid 1034008] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL51sgAAAIY"]
[Mon Jul 20 06:52:40.695103 2026] [security2:error] [pid 1033876:tid 1034029] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL51sAAAAJs"]
[Mon Jul 20 06:52:40.707566 2026] [security2:error] [pid 1033876:tid 1033994] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/.continue/config.json"] [unique_id "al4aGEfjhWEjDbtLXL512AAA73Q"]
[Mon Jul 20 06:52:40.707578 2026] [security2:error] [pid 1033876:tid 1033989] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/.aider.conf.yml"] [unique_id "al4aGEfjhWEjDbtLXL513QAA728"]
[Mon Jul 20 06:52:40.707805 2026] [security2:error] [pid 1033876:tid 1034113] [client 34.187.29.36:51158] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aosta.nz"] [uri "/.continue/config.json"] [unique_id "al4aGEfjhWEjDbtLXL512AAA73Q"]
[Mon Jul 20 06:52:40.708666 2026] [security2:error] [pid 1033876:tid 1033891] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.openclaw/.env"] [unique_id "al4aGEfjhWEjDbtLXL513AAA7w0"]
[Mon Jul 20 06:52:40.722509 2026] [security2:error] [pid 1033876:tid 1034071] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL51rwAAAMU"]
[Mon Jul 20 06:52:40.731651 2026] [security2:error] [pid 1033876:tid 1034024] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL51rgAAAJY"]
[Mon Jul 20 06:52:40.734474 2026] [security2:error] [pid 1033876:tid 1034061] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL51rQAAALs"]
[Mon Jul 20 06:52:40.742465 2026] [security2:error] [pid 1033876:tid 1034100] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL51tAAAAOI"]
[Mon Jul 20 06:52:40.793842 2026] [security2:error] [pid 1033876:tid 1034027] [client 161.118.218.103:55523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aGEfjhWEjDbtLXL517AAAAJk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:40.958070 2026] [security2:error] [pid 1033876:tid 1034048] [client 77.110.127.138:58623] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aGEfjhWEjDbtLXL51-QAAAK4"]
[Mon Jul 20 06:52:41.000028 2026] [security2:error] [pid 1033876:tid 1034106] [client 57.141.18.43:54110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aEUfjhWEjDbtLXL5zVQAA6AM"]
[Mon Jul 20 06:52:41.015284 2026] [security2:error] [pid 1033876:tid 1034043] [client 14.251.3.155:54756] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aGUfjhWEjDbtLXL51_AAAAKk"]
[Mon Jul 20 06:52:41.117871 2026] [security2:error] [pid 1033876:tid 1034055] [client 77.110.127.138:58628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aGUfjhWEjDbtLXL52BAAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:41.237953 2026] [security2:error] [pid 1033876:tid 1034114] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGEfjhWEjDbtLXL514wAAAPA"]
[Mon Jul 20 06:52:41.371081 2026] [security2:error] [pid 1033876:tid 1034029] [client 161.118.218.103:55891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aGUfjhWEjDbtLXL52GwAAAJs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:41.563356 2026] [security2:error] [pid 1033876:tid 1033902] [remote 130.185.118.215:40460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aGUfjhWEjDbtLXL52IgAAvhg"]
[Mon Jul 20 06:52:41.748255 2026] [security2:error] [pid 1033876:tid 1033921] [remote 130.185.118.215:40460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aGUfjhWEjDbtLXL52KwAA-Cs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:52:41.945428 2026] [security2:error] [pid 1033876:tid 1034070] [client 161.118.218.103:56243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aGUfjhWEjDbtLXL52PQAAAMQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:41.971648 2026] [proxy:error] [pid 1033876:tid 1034124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:41.971703 2026] [proxy_http:error] [pid 1033876:tid 1034124] [client 34.73.38.214:61390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:41.972144 2026] [proxy:error] [pid 1033876:tid 1034124] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:41.972168 2026] [proxy_http:error] [pid 1033876:tid 1034124] [client 34.73.38.214:61390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:41.972772 2026] [security2:error] [pid 1033876:tid 1034055] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aGUfjhWEjDbtLXL52MAAAALU"], referer: 1'"3000
[Mon Jul 20 06:52:42.085703 2026] [security2:error] [pid 1033876:tid 1033944] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aosta.nz"] [uri "/wp-config.php.bak"] [unique_id "al4aGkfjhWEjDbtLXL52UAAArUI"]
[Mon Jul 20 06:52:42.116422 2026] [security2:error] [pid 1033876:tid 1033935] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.hermes/.env"] [unique_id "al4aGkfjhWEjDbtLXL52UQAAtjk"]
[Mon Jul 20 06:52:42.169198 2026] [security2:error] [pid 1033876:tid 1034005] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/.zshrc"] [unique_id "al4aGkfjhWEjDbtLXL52XAAAtn8"]
[Mon Jul 20 06:52:42.169363 2026] [security2:error] [pid 1033876:tid 1034056] [client 34.187.29.36:51158] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aosta.nz"] [uri "/.zshrc"] [unique_id "al4aGkfjhWEjDbtLXL52XAAAtn8"]
[Mon Jul 20 06:52:42.466243 2026] [security2:error] [pid 1033876:tid 1034115] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aGkfjhWEjDbtLXL52bQAAAPE"], referer: 1'"3000
[Mon Jul 20 06:52:42.519282 2026] [security2:error] [pid 1033876:tid 1034122] [client 161.118.218.103:56611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aGkfjhWEjDbtLXL52fQAAAPg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:42.630124 2026] [security2:error] [pid 1033876:tid 1034012] [client 117.222.139.248:53614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aGkfjhWEjDbtLXL52gwAAAIo"]
[Mon Jul 20 06:52:42.630219 2026] [security2:error] [pid 1033876:tid 1034012] [client 117.222.139.248:53614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aGkfjhWEjDbtLXL52gwAAAIo"]
[Mon Jul 20 06:52:42.682465 2026] [security2:error] [pid 1033876:tid 1034019] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGkfjhWEjDbtLXL52VgAAAJE"]
[Mon Jul 20 06:52:42.690186 2026] [security2:error] [pid 1033876:tid 1034068] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGkfjhWEjDbtLXL52ZgAAAMI"]
[Mon Jul 20 06:52:42.705216 2026] [security2:error] [pid 1033876:tid 1034032] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGkfjhWEjDbtLXL52ZQAAAJ4"]
[Mon Jul 20 06:52:42.719293 2026] [security2:error] [pid 1033876:tid 1034051] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aGkfjhWEjDbtLXL52ZAAAALE"]
[Mon Jul 20 06:52:42.801101 2026] [proxy:error] [pid 1033876:tid 1034013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:42.801181 2026] [proxy_http:error] [pid 1033876:tid 1034013] [client 34.73.38.214:60613] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:42.801795 2026] [proxy:error] [pid 1033876:tid 1034013] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:42.801822 2026] [proxy_http:error] [pid 1033876:tid 1034013] [client 34.73.38.214:60613] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:42.898628 2026] [security2:error] [pid 1033876:tid 1034060] [client 142.93.150.151:56812] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.familiasconscientes.com"] [uri "/wp-login.php"] [unique_id "al4aGkfjhWEjDbtLXL52lQAAALo"]
[Mon Jul 20 06:52:42.997712 2026] [security2:error] [pid 1033876:tid 1033953] [remote 217.61.143.92:55764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aGkfjhWEjDbtLXL52oQAAqEs"]
[Mon Jul 20 06:52:43.062181 2026] [security2:error] [pid 1033876:tid 1034076] [client 152.58.191.29:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aG0fjhWEjDbtLXL52pgAAAMo"]
[Mon Jul 20 06:52:43.062290 2026] [security2:error] [pid 1033876:tid 1034076] [client 152.58.191.29:60936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aG0fjhWEjDbtLXL52pgAAAMo"]
[Mon Jul 20 06:52:43.064238 2026] [security2:error] [pid 1033876:tid 1033958] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/core/.env"] [unique_id "al4aG0fjhWEjDbtLXL52pQAAklA"]
[Mon Jul 20 06:52:43.093901 2026] [security2:error] [pid 1033876:tid 1034064] [client 161.118.218.103:56985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aG0fjhWEjDbtLXL52rAAAAL4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:43.106664 2026] [security2:error] [pid 1033876:tid 1033971] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/config.php.bak"] [unique_id "al4aG0fjhWEjDbtLXL52qgAAkl0"]
[Mon Jul 20 06:52:43.107380 2026] [security2:error] [pid 1033876:tid 1033979] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aosta.nz"] [uri "/wp-config.php.old"] [unique_id "al4aG0fjhWEjDbtLXL52sQAAkmU"]
[Mon Jul 20 06:52:43.107966 2026] [security2:error] [pid 1033876:tid 1033968] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/.env.php.bak"] [unique_id "al4aG0fjhWEjDbtLXL52sgAAklo"]
[Mon Jul 20 06:52:43.108794 2026] [security2:error] [pid 1033876:tid 1033956] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/laravel/.env"] [unique_id "al4aG0fjhWEjDbtLXL52rwAAkk4"]
[Mon Jul 20 06:52:43.209689 2026] [security2:error] [pid 1033876:tid 1033926] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/config/.env.php"] [unique_id "al4aG0fjhWEjDbtLXL52vwAAkjA"]
[Mon Jul 20 06:52:43.259934 2026] [security2:error] [pid 1033876:tid 1033967] [remote 217.61.143.92:55764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aG0fjhWEjDbtLXL52wwAA41k"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 06:52:43.315669 2026] [security2:error] [pid 1033876:tid 1033966] [remote 162.19.86.63:46460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4aG0fjhWEjDbtLXL52yAAA_lg"]
[Mon Jul 20 06:52:43.525246 2026] [security2:error] [pid 1033876:tid 1033984] [remote 162.19.86.63:46460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4aG0fjhWEjDbtLXL523QAAhWo"], referer: https://guidehunting.com/wp-login.php
[Mon Jul 20 06:52:43.575496 2026] [security2:error] [pid 1033876:tid 1034020] [client 34.187.29.36:51158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aG0fjhWEjDbtLXL52qAAAkmI"]
[Mon Jul 20 06:52:43.641909 2026] [proxy:error] [pid 1033876:tid 1034044] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:43.641993 2026] [proxy_http:error] [pid 1033876:tid 1034044] [client 34.73.38.214:63915] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:43.642744 2026] [proxy:error] [pid 1033876:tid 1034044] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:43.642791 2026] [proxy_http:error] [pid 1033876:tid 1034044] [client 34.73.38.214:63915] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:43.671213 2026] [security2:error] [pid 1033876:tid 1034088] [client 161.118.218.103:57358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aG0fjhWEjDbtLXL524gAAANY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:43.672227 2026] [security2:error] [pid 1033876:tid 1034125] [client 62.150.67.110:46384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4aG0fjhWEjDbtLXL52qQAAAPs"]
[Mon Jul 20 06:52:43.772788 2026] [security2:error] [pid 1033876:tid 1033997] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/configuration.php.bak"] [unique_id "al4aG0fjhWEjDbtLXL526AAAinc"]
[Mon Jul 20 06:52:43.773351 2026] [security2:error] [pid 1033876:tid 1033943] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/.env.swp"] [unique_id "al4aG0fjhWEjDbtLXL525wAAikE"]
[Mon Jul 20 06:52:43.773930 2026] [security2:error] [pid 1033876:tid 1033987] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/public/.env"] [unique_id "al4aG0fjhWEjDbtLXL526QAAim0"]
[Mon Jul 20 06:52:43.801108 2026] [security2:error] [pid 1033876:tid 1033983] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aosta.nz"] [uri "/web/.env"] [unique_id "al4aG0fjhWEjDbtLXL527QAAimk"]
[Mon Jul 20 06:52:43.832098 2026] [security2:error] [pid 1033876:tid 1033891] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/config.js"] [unique_id "al4aG0fjhWEjDbtLXL529AAAig0"]
[Mon Jul 20 06:52:43.832247 2026] [security2:error] [pid 1033876:tid 1034012] [client 34.187.29.36:51158] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aosta.nz"] [uri "/config.js"] [unique_id "al4aG0fjhWEjDbtLXL529AAAig0"]
[Mon Jul 20 06:52:43.975544 2026] [security2:error] [pid 1033876:tid 1033974] [remote 188.40.28.4:41430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aG0fjhWEjDbtLXL53DQAA8mA"]
[Mon Jul 20 06:52:44.190714 2026] [security2:error] [pid 1033876:tid 1033893] [remote 188.40.28.4:41430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aHEfjhWEjDbtLXL53GAAAhQ8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:52:44.254776 2026] [security2:error] [pid 1033876:tid 1034127] [client 161.118.218.103:57778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aHEfjhWEjDbtLXL53HAAAAP0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:44.314407 2026] [security2:error] [pid 1033876:tid 1034080] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aG0fjhWEjDbtLXL527gAAAM4"]
[Mon Jul 20 06:52:44.325127 2026] [security2:error] [pid 1033876:tid 1034110] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aG0fjhWEjDbtLXL529wAAAOw"]
[Mon Jul 20 06:52:44.362026 2026] [security2:error] [pid 1033876:tid 1033888] [remote 20.153.140.50:40116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aHEfjhWEjDbtLXL53IwAA_go"]
[Mon Jul 20 06:52:44.362245 2026] [security2:error] [pid 1033876:tid 1034128] [client 20.153.140.50:40116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aHEfjhWEjDbtLXL53IwAA_go"]
[Mon Jul 20 06:52:44.363093 2026] [security2:error] [pid 1033876:tid 1034126] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aG0fjhWEjDbtLXL52-gAAAPw"]
[Mon Jul 20 06:52:44.481925 2026] [security2:error] [pid 1033876:tid 1034049] [client 57.141.18.103:56086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aFUfjhWEjDbtLXL50wAAArwY"]
[Mon Jul 20 06:52:44.514533 2026] [security2:error] [pid 1033876:tid 1033890] [remote 47.86.33.52:55152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4aHEfjhWEjDbtLXL53OQAAzww"]
[Mon Jul 20 06:52:44.572336 2026] [security2:error] [pid 1033876:tid 1034108] [client 77.110.127.138:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aHEfjhWEjDbtLXL53PwAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:44.572419 2026] [security2:error] [pid 1033876:tid 1034108] [client 77.110.127.138:58672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aHEfjhWEjDbtLXL53PwAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:44.582086 2026] [security2:error] [pid 1033876:tid 1034018] [client 34.73.38.214:58507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.thepauze.com"] [uri "/xmlrpc.php"] [unique_id "al4aHEfjhWEjDbtLXL53QAAAAJA"]
[Mon Jul 20 06:52:44.740450 2026] [security2:error] [pid 1033876:tid 1033896] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/api/v1/config"] [unique_id "al4aHEfjhWEjDbtLXL53VAAAhRI"]
[Mon Jul 20 06:52:44.740873 2026] [security2:error] [pid 1033876:tid 1033923] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aosta.nz"] [uri "/firebase-config.json"] [unique_id "al4aHEfjhWEjDbtLXL53WAAAhS0"]
[Mon Jul 20 06:52:44.741029 2026] [security2:error] [pid 1033876:tid 1034007] [client 34.187.29.36:51158] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aosta.nz"] [uri "/firebase-config.json"] [unique_id "al4aHEfjhWEjDbtLXL53WAAAhS0"]
[Mon Jul 20 06:52:44.827158 2026] [security2:error] [pid 1033876:tid 1034068] [client 14.225.17.146:53371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4aHEfjhWEjDbtLXL53XQAAAMI"], referer: http://nikkidesigns.net/wp-old
[Mon Jul 20 06:52:44.830735 2026] [security2:error] [pid 1033876:tid 1034059] [client 161.118.218.103:58129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aHEfjhWEjDbtLXL53aAAAALk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:45.180056 2026] [security2:error] [pid 1033876:tid 1034038] [client 34.73.38.214:57917] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aHUfjhWEjDbtLXL53iAAAAKQ"]
[Mon Jul 20 06:52:45.219858 2026] [security2:error] [pid 1033876:tid 1034062] [client 14.225.17.146:50864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4aHEfjhWEjDbtLXL53ZAAAALw"], referer: http://mollycahill.com/wp-old
[Mon Jul 20 06:52:45.274991 2026] [security2:error] [pid 1033876:tid 1034134] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHEfjhWEjDbtLXL53XAAAAQQ"]
[Mon Jul 20 06:52:45.277906 2026] [autoindex:error] [pid 1033876:tid 1033917] [remote 8.229.41.77:64573] AH01276: Cannot serve directory /home2/fjyyvsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.fjy.yvs.mybluehost.me
[Mon Jul 20 06:52:45.281084 2026] [security2:error] [pid 1033876:tid 1034064] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHEfjhWEjDbtLXL53XwAAAL4"]
[Mon Jul 20 06:52:45.321269 2026] [security2:error] [pid 1033876:tid 1034128] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHEfjhWEjDbtLXL53ZQAAAP4"]
[Mon Jul 20 06:52:45.349578 2026] [security2:error] [pid 1033876:tid 1034096] [client 50.116.65.227:47552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aHUfjhWEjDbtLXL53lAAAAN4"]
[Mon Jul 20 06:52:45.358553 2026] [security2:error] [pid 1033876:tid 1034041] [client 50.116.65.227:47566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aHUfjhWEjDbtLXL53lgAAAKc"]
[Mon Jul 20 06:52:45.413871 2026] [security2:error] [pid 1033876:tid 1034090] [client 161.118.218.103:58512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53qwAAANg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:45.509584 2026] [security2:error] [pid 1033876:tid 1033941] [remote 47.86.33.52:55152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4aHUfjhWEjDbtLXL53uAAAqz8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:52:45.601612 2026] [security2:error] [pid 1033876:tid 1034060] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53hQAAALo"]
[Mon Jul 20 06:52:45.643719 2026] [security2:error] [pid 1033876:tid 1034131] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53hgAAAQE"]
[Mon Jul 20 06:52:45.740137 2026] [security2:error] [pid 1033876:tid 1034077] [client 217.142.18.172:38579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aHUfjhWEjDbtLXL53yAAAAMs"]
[Mon Jul 20 06:52:45.748327 2026] [security2:error] [pid 1033876:tid 1034077] [client 217.142.18.172:38579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aHUfjhWEjDbtLXL53yAAAAMs"]
[Mon Jul 20 06:52:45.888207 2026] [security2:error] [pid 1033876:tid 1034007] [client 34.187.29.36:51158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53oAAAhVE"]
[Mon Jul 20 06:52:45.932618 2026] [security2:error] [pid 1033876:tid 1034096] [client 34.73.38.214:56081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aHUfjhWEjDbtLXL532AAAAN4"]
[Mon Jul 20 06:52:45.936302 2026] [security2:error] [pid 1033876:tid 1034103] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53pgAAAOU"]
[Mon Jul 20 06:52:45.948893 2026] [security2:error] [pid 1033876:tid 1034013] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53qQAAAIs"]
[Mon Jul 20 06:52:45.992892 2026] [security2:error] [pid 1033876:tid 1034056] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL53tAAAALY"]
[Mon Jul 20 06:52:45.998273 2026] [security2:error] [pid 1033876:tid 1034114] [client 161.118.218.103:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aHUfjhWEjDbtLXL535gAAAPA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:46.136335 2026] [security2:error] [pid 1033876:tid 1033895] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/ngsw.json"] [unique_id "al4aHkfjhWEjDbtLXL538gAAhRE"]
[Mon Jul 20 06:52:46.195498 2026] [security2:error] [pid 1033876:tid 1034113] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL533gAAAO8"], referer: 1'"3000
[Mon Jul 20 06:52:46.211008 2026] [proxy:error] [pid 1033876:tid 1034039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:46.211098 2026] [proxy_http:error] [pid 1033876:tid 1034039] [client 34.73.38.214:55968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:46.211652 2026] [proxy:error] [pid 1033876:tid 1034039] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:46.211679 2026] [proxy_http:error] [pid 1033876:tid 1034039] [client 34.73.38.214:55968] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:46.360634 2026] [security2:error] [pid 1033876:tid 1033961] [remote 124.55.178.99:34396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4aHkfjhWEjDbtLXL53_AAAqFM"]
[Mon Jul 20 06:52:46.371017 2026] [security2:error] [pid 1033876:tid 1034091] [client 106.219.188.178:25944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aHkfjhWEjDbtLXL53_QAAANk"]
[Mon Jul 20 06:52:46.381739 2026] [security2:error] [pid 1033876:tid 1034091] [client 106.219.188.178:25944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aHkfjhWEjDbtLXL53_QAAANk"]
[Mon Jul 20 06:52:46.419072 2026] [security2:error] [pid 1033876:tid 1034067] [client 104.234.53.63:54831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aHkfjhWEjDbtLXL54AwAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:46.424988 2026] [security2:error] [pid 1033876:tid 1034024] [client 39.48.81.23:65241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aHkfjhWEjDbtLXL54BQAAAJY"]
[Mon Jul 20 06:52:46.425294 2026] [security2:error] [pid 1033876:tid 1034024] [client 39.48.81.23:65241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aHkfjhWEjDbtLXL54BQAAAJY"]
[Mon Jul 20 06:52:46.484209 2026] [security2:error] [pid 1033876:tid 1034085] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aHUfjhWEjDbtLXL535QAAANM"]
[Mon Jul 20 06:52:46.506185 2026] [security2:error] [pid 1033876:tid 1034084] [client 122.183.32.225:12364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aHkfjhWEjDbtLXL54DwAAANI"]
[Mon Jul 20 06:52:46.506282 2026] [security2:error] [pid 1033876:tid 1034084] [client 122.183.32.225:12364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aHkfjhWEjDbtLXL54DwAAANI"]
[Mon Jul 20 06:52:46.576859 2026] [security2:error] [pid 1033876:tid 1034098] [client 161.118.218.103:59304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aHkfjhWEjDbtLXL54GwAAAOA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:46.710418 2026] [security2:error] [pid 1033876:tid 1034117] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aHkfjhWEjDbtLXL54DQAAAPM"], referer: 1'"3000
[Mon Jul 20 06:52:46.804458 2026] [security2:error] [pid 1033876:tid 1034002] [remote 124.55.178.99:34396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4aHkfjhWEjDbtLXL54JwAAznw"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 06:52:46.928196 2026] [security2:error] [pid 1033876:tid 1034088] [client 34.73.38.214:53811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aHkfjhWEjDbtLXL54MwAAANY"]
[Mon Jul 20 06:52:47.134194 2026] [security2:error] [pid 1033876:tid 1034062] [client 104.234.53.87:64987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aH0fjhWEjDbtLXL54QAAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:47.151615 2026] [security2:error] [pid 1033876:tid 1034127] [client 161.118.218.103:59701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aH0fjhWEjDbtLXL54VAAAAP0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:47.262271 2026] [proxy:error] [pid 1033876:tid 1034113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:47.262348 2026] [proxy_http:error] [pid 1033876:tid 1034113] [client 34.73.38.214:57956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:47.262973 2026] [proxy:error] [pid 1033876:tid 1034113] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:47.263021 2026] [proxy_http:error] [pid 1033876:tid 1034113] [client 34.73.38.214:57956] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:47.434834 2026] [security2:error] [pid 1033876:tid 1034133] [client 51.158.124.4:49314] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5020.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4aH0fjhWEjDbtLXL54bQAAAQM"]
[Mon Jul 20 06:52:47.659084 2026] [security2:error] [pid 1033876:tid 1034096] [client 66.249.65.36:48603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.oldracelimited.com"] [uri "/index.php"] [unique_id "al4aH0fjhWEjDbtLXL54bgAAAN4"]
[Mon Jul 20 06:52:47.686649 2026] [security2:error] [pid 1033876:tid 1034117] [client 34.73.38.214:61849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aH0fjhWEjDbtLXL54gwAAAPM"]
[Mon Jul 20 06:52:47.714638 2026] [security2:error] [pid 1033876:tid 1034012] [client 103.238.106.162:42691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aH0fjhWEjDbtLXL54hAAAAIo"]
[Mon Jul 20 06:52:47.714777 2026] [security2:error] [pid 1033876:tid 1034012] [client 103.238.106.162:42691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aH0fjhWEjDbtLXL54hAAAAIo"]
[Mon Jul 20 06:52:47.725113 2026] [security2:error] [pid 1033876:tid 1034043] [client 161.118.218.103:60005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aH0fjhWEjDbtLXL54hQAAAKk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:47.769899 2026] [security2:error] [pid 1033876:tid 1034118] [client 65.111.23.14:29659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aH0fjhWEjDbtLXL54hwAAAPQ"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:47.932550 2026] [proxy:error] [pid 1033876:tid 1034105] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:47.932629 2026] [proxy_http:error] [pid 1033876:tid 1034105] [client 34.73.38.214:52828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:47.933240 2026] [proxy:error] [pid 1033876:tid 1034105] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:52:47.933271 2026] [proxy_http:error] [pid 1033876:tid 1034105] [client 34.73.38.214:52828] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:52:47.962207 2026] [security2:error] [pid 1033876:tid 1034052] [client 50.116.65.227:47638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4aH0fjhWEjDbtLXL54iQAAALI"]
[Mon Jul 20 06:52:47.998229 2026] [security2:error] [pid 1033876:tid 1034044] [client 104.234.53.87:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aH0fjhWEjDbtLXL54kgAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:48.130741 2026] [security2:error] [pid 1033876:tid 1034104] [client 50.116.65.227:47644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4aH0fjhWEjDbtLXL54kQAAAOY"]
[Mon Jul 20 06:52:48.304775 2026] [security2:error] [pid 1033876:tid 1034130] [client 161.118.218.103:60339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aIEfjhWEjDbtLXL54sgAAAQA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:48.321871 2026] [security2:error] [pid 1033876:tid 1034050] [client 34.73.38.214:59089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4aIEfjhWEjDbtLXL54tAAAALA"]
[Mon Jul 20 06:52:48.427730 2026] [security2:error] [pid 1033876:tid 1034021] [client 57.141.18.8:34836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aGkfjhWEjDbtLXL52TwAAky8"]
[Mon Jul 20 06:52:48.532113 2026] [security2:error] [pid 1033876:tid 1034127] [client 34.73.38.214:59317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aIEfjhWEjDbtLXL54xgAAAP0"]
[Mon Jul 20 06:52:48.551676 2026] [security2:error] [pid 1033876:tid 1034075] [client 103.125.179.95:58580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aIEfjhWEjDbtLXL54yAAAAMk"]
[Mon Jul 20 06:52:48.552430 2026] [security2:error] [pid 1033876:tid 1034075] [client 103.125.179.95:58580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aIEfjhWEjDbtLXL54yAAAAMk"]
[Mon Jul 20 06:52:48.635796 2026] [security2:error] [pid 1033876:tid 1034008] [client 45.61.185.216:49234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.185.61.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ancestralidadytrance.space"] [uri "/wp-login.php"] [unique_id "al4aIEfjhWEjDbtLXL54zAAAAIY"]
[Mon Jul 20 06:52:48.732403 2026] [security2:error] [pid 1033876:tid 1034025] [client 82.102.18.116:35256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4aIEfjhWEjDbtLXL541wAAAJc"]
[Mon Jul 20 06:52:48.846264 2026] [security2:error] [pid 1033876:tid 1034018] [client 34.73.38.214:53230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/xmlrpc.php"] [unique_id "al4aIEfjhWEjDbtLXL544wAAAJA"]
[Mon Jul 20 06:52:48.882737 2026] [security2:error] [pid 1033876:tid 1034035] [client 161.118.218.103:60691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aIEfjhWEjDbtLXL545QAAAKE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:48.976217 2026] [security2:error] [pid 1033876:tid 1033906] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aIEfjhWEjDbtLXL547AAA7Bw"]
[Mon Jul 20 06:52:48.976394 2026] [security2:error] [pid 1033876:tid 1034110] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aIEfjhWEjDbtLXL547AAA7Bw"]
[Mon Jul 20 06:52:49.068317 2026] [security2:error] [pid 1033876:tid 1034132] [client 34.73.38.214:63668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4aIUfjhWEjDbtLXL548wAAAQI"]
[Mon Jul 20 06:52:49.214573 2026] [security2:error] [pid 1033876:tid 1034031] [client 117.247.108.24:31957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aIUfjhWEjDbtLXL55AgAAAJ0"]
[Mon Jul 20 06:52:49.214664 2026] [security2:error] [pid 1033876:tid 1034031] [client 117.247.108.24:31957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aIUfjhWEjDbtLXL55AgAAAJ0"]
[Mon Jul 20 06:52:49.244492 2026] [security2:error] [pid 1033876:tid 1034041] [client 82.102.18.116:35268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aIUfjhWEjDbtLXL55BwAAAKc"]
[Mon Jul 20 06:52:49.261903 2026] [security2:error] [pid 1033876:tid 1034061] [client 14.225.17.146:64999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4aIUfjhWEjDbtLXL548AAAALs"], referer: http://ccsdifference.com/wp-old
[Mon Jul 20 06:52:49.434775 2026] [security2:error] [pid 1033876:tid 1034035] [client 34.73.38.214:53189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aIUfjhWEjDbtLXL55FwAAAKE"]
[Mon Jul 20 06:52:49.458852 2026] [security2:error] [pid 1033876:tid 1034040] [client 161.118.218.103:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aIUfjhWEjDbtLXL55GQAAAKY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:49.505815 2026] [security2:error] [pid 1033876:tid 1034014] [client 14.225.17.146:50842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4aIUfjhWEjDbtLXL55EQAAAIw"], referer: http://bbwipartnerconference.com/wp-old
[Mon Jul 20 06:52:49.569156 2026] [security2:error] [pid 1033876:tid 1034062] [client 82.102.18.116:35280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aIUfjhWEjDbtLXL55LAAAALw"]
[Mon Jul 20 06:52:49.577068 2026] [security2:error] [pid 1033876:tid 1034047] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4aIUfjhWEjDbtLXL548QAArSg"], referer: http://ali-alghanim.net/wp-old
[Mon Jul 20 06:52:49.644687 2026] [security2:error] [pid 1033876:tid 1034112] [client 77.110.127.138:58724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aIUfjhWEjDbtLXL55MwAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:49.644801 2026] [security2:error] [pid 1033876:tid 1034112] [client 77.110.127.138:58724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aIUfjhWEjDbtLXL55MwAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:49.709830 2026] [security2:error] [pid 1033876:tid 1034013] [client 34.201.171.57:44864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.171.201.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4aIUfjhWEjDbtLXL55OQAAAIs"]
[Mon Jul 20 06:52:49.711101 2026] [security2:error] [pid 1033876:tid 1034068] [client 14.225.17.146:51011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4aIUfjhWEjDbtLXL55JAAAAMI"], referer: http://fineartsfactory.net/wp-old
[Mon Jul 20 06:52:49.750676 2026] [security2:error] [pid 1033876:tid 1034059] [client 34.73.38.214:60952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aIUfjhWEjDbtLXL55PwAAALk"]
[Mon Jul 20 06:52:49.825490 2026] [security2:error] [pid 1033876:tid 1033979] [remote 162.19.86.63:44664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4aIUfjhWEjDbtLXL55QQAApWU"]
[Mon Jul 20 06:52:49.849888 2026] [security2:error] [pid 1033876:tid 1034015] [client 187.108.85.186:61868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aIUfjhWEjDbtLXL55RQAAAI0"]
[Mon Jul 20 06:52:49.850018 2026] [security2:error] [pid 1033876:tid 1034015] [client 187.108.85.186:61868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aIUfjhWEjDbtLXL55RQAAAI0"]
[Mon Jul 20 06:52:49.893950 2026] [security2:error] [pid 1033876:tid 1034115] [client 82.102.18.116:35294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aIUfjhWEjDbtLXL55SAAAAPE"]
[Mon Jul 20 06:52:49.984542 2026] [security2:error] [pid 1033876:tid 1033956] [remote 160.187.68.132:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4aIUfjhWEjDbtLXL55TAAAo04"]
[Mon Jul 20 06:52:50.031175 2026] [security2:error] [pid 1033876:tid 1033895] [remote 162.19.86.63:44664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4aIkfjhWEjDbtLXL55UQAA3hE"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:52:50.037687 2026] [security2:error] [pid 1033876:tid 1034100] [client 161.118.218.103:61444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aIkfjhWEjDbtLXL55UgAAAOI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:50.241415 2026] [security2:error] [pid 1033876:tid 1034044] [client 82.102.18.116:35304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4aIkfjhWEjDbtLXL55bQAAAKo"]
[Mon Jul 20 06:52:50.268806 2026] [security2:error] [pid 1033876:tid 1034072] [client 34.73.38.214:49634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aIkfjhWEjDbtLXL55cgAAAMY"]
[Mon Jul 20 06:52:50.268911 2026] [security2:error] [pid 1033876:tid 1034086] [client 183.82.98.154:53179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aIkfjhWEjDbtLXL55cwAAANQ"]
[Mon Jul 20 06:52:50.269010 2026] [security2:error] [pid 1033876:tid 1034086] [client 183.82.98.154:53179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aIkfjhWEjDbtLXL55cwAAANQ"]
[Mon Jul 20 06:52:50.315075 2026] [security2:error] [pid 1033876:tid 1034019] [client 14.225.17.146:58713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4aIkfjhWEjDbtLXL55XQAAAJE"], referer: https://ccsdifference.com/wp-old
[Mon Jul 20 06:52:50.371843 2026] [security2:error] [pid 1033876:tid 1034042] [client 216.73.217.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4aIkfjhWEjDbtLXL55eQAAAKg"]
[Mon Jul 20 06:52:50.445793 2026] [security2:error] [pid 1033876:tid 1033997] [remote 160.187.68.132:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4aIkfjhWEjDbtLXL55hQAArHc"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 06:52:50.516066 2026] [security2:error] [pid 1033876:tid 1034118] [client 216.73.217.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4aIkfjhWEjDbtLXL55hwAAAPQ"], referer: https://www.travelbyfire.com/sitemap.xml
[Mon Jul 20 06:52:50.558180 2026] [security2:error] [pid 1033876:tid 1034075] [client 82.102.18.116:35308] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aIkfjhWEjDbtLXL55jQAAAMk"]
[Mon Jul 20 06:52:50.616018 2026] [security2:error] [pid 1033876:tid 1034007] [client 161.118.218.103:61840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aIkfjhWEjDbtLXL55kwAAAIU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:50.635280 2026] [security2:error] [pid 1033876:tid 1034032] [client 34.73.38.214:50853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aIkfjhWEjDbtLXL55lQAAAJ4"]
[Mon Jul 20 06:52:50.742107 2026] [core:error] [pid 1033876:tid 1034013] [client 66.249.74.169:36453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:50.742129 2026] [core:error] [pid 1033876:tid 1034013] [client 66.249.74.169:36453] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:52:50.868870 2026] [security2:error] [pid 1033876:tid 1034129] [client 82.102.18.116:35318] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4aIkfjhWEjDbtLXL55qwAAAP8"]
[Mon Jul 20 06:52:50.901976 2026] [security2:error] [pid 1033876:tid 1034069] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aIkfjhWEjDbtLXL55kgAAAMM"]
[Mon Jul 20 06:52:50.941612 2026] [security2:error] [pid 1033876:tid 1034062] [client 98.87.13.111:37914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4aIkfjhWEjDbtLXL55XgAAALw"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:52:51.181206 2026] [security2:error] [pid 1033876:tid 1033887] [remote 188.166.241.141:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4aI0fjhWEjDbtLXL55tQAAxwk"]
[Mon Jul 20 06:52:51.182500 2026] [security2:error] [pid 1033876:tid 1034109] [client 82.102.18.116:35334] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4aI0fjhWEjDbtLXL55uAAAAOs"]
[Mon Jul 20 06:52:51.190785 2026] [security2:error] [pid 1033876:tid 1034110] [client 161.118.218.103:62192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aI0fjhWEjDbtLXL55ugAAAOw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:51.212612 2026] [security2:error] [pid 1033876:tid 1034051] [client 34.73.38.214:61999] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aI0fjhWEjDbtLXL55wQAAALE"]
[Mon Jul 20 06:52:51.368683 2026] [security2:error] [pid 1033876:tid 1034132] [client 14.225.17.146:64811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4aI0fjhWEjDbtLXL55swAAAQI"]
[Mon Jul 20 06:52:51.508718 2026] [security2:error] [pid 1033876:tid 1034021] [client 82.102.18.116:35346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aI0fjhWEjDbtLXL554QAAAJM"]
[Mon Jul 20 06:52:51.540518 2026] [security2:error] [pid 1033876:tid 1033883] [remote 188.166.241.141:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4aI0fjhWEjDbtLXL554gAAtwU"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 06:52:51.603334 2026] [security2:error] [pid 1033876:tid 1033884] [remote 81.173.115.7:53126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4aI0fjhWEjDbtLXL555AAA5QY"]
[Mon Jul 20 06:52:51.675649 2026] [security2:error] [pid 1033876:tid 1034066] [client 34.73.38.214:55133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aI0fjhWEjDbtLXL556AAAAMA"]
[Mon Jul 20 06:52:51.780519 2026] [security2:error] [pid 1033876:tid 1034018] [client 161.118.218.103:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aI0fjhWEjDbtLXL559QAAAJA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:51.802584 2026] [security2:error] [pid 1033876:tid 1033960] [remote 81.173.115.7:53126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4aI0fjhWEjDbtLXL559wAA8FI"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:52:51.825125 2026] [security2:error] [pid 1033876:tid 1034100] [client 82.102.18.116:35356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aI0fjhWEjDbtLXL55-gAAAOI"]
[Mon Jul 20 06:52:51.952262 2026] [security2:error] [pid 1033876:tid 1034014] [client 77.110.127.138:58733] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 478 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aI0fjhWEjDbtLXL56CQAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:52.133755 2026] [security2:error] [pid 1033876:tid 1034112] [client 82.102.18.116:35358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aJEfjhWEjDbtLXL56FwAAAO4"]
[Mon Jul 20 06:52:52.220130 2026] [security2:error] [pid 1033876:tid 1034015] [client 34.73.38.214:49634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aJEfjhWEjDbtLXL56HAAAAI0"]
[Mon Jul 20 06:52:52.279163 2026] [security2:error] [pid 1033876:tid 1034027] [client 197.186.66.42:49403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aJEfjhWEjDbtLXL56IAAAAJk"]
[Mon Jul 20 06:52:52.287985 2026] [security2:error] [pid 1033876:tid 1034027] [client 197.186.66.42:49403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aJEfjhWEjDbtLXL56IAAAAJk"]
[Mon Jul 20 06:52:52.359093 2026] [security2:error] [pid 1033876:tid 1034030] [client 161.118.218.103:62996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aJEfjhWEjDbtLXL56JwAAAJw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:52.443466 2026] [security2:error] [pid 1033876:tid 1034118] [client 77.110.127.138:58736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aJEfjhWEjDbtLXL56MgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:52.443538 2026] [security2:error] [pid 1033876:tid 1034118] [client 77.110.127.138:58736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aJEfjhWEjDbtLXL56MgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:52.479023 2026] [security2:error] [pid 1033876:tid 1034065] [client 82.102.18.116:35362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4aJEfjhWEjDbtLXL56MwAAAL8"]
[Mon Jul 20 06:52:52.600656 2026] [security2:error] [pid 1033876:tid 1034134] [client 14.225.17.146:53687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4aI0fjhWEjDbtLXL55ygAAAQQ"], referer: http://alaraycreative.com/wp-old
[Mon Jul 20 06:52:52.747364 2026] [security2:error] [pid 1033876:tid 1034044] [client 14.225.17.146:50592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4aJEfjhWEjDbtLXL56QQAAAKo"], referer: http://alrowad-hub.net/wp-old
[Mon Jul 20 06:52:52.794722 2026] [security2:error] [pid 1033876:tid 1034035] [client 82.102.18.116:35374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4aJEfjhWEjDbtLXL56VQAAAKE"]
[Mon Jul 20 06:52:52.837135 2026] [security2:error] [pid 1033876:tid 1034072] [client 14.225.17.146:64894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4aJEfjhWEjDbtLXL56VAAAAMY"], referer: http://grndl.com/wp-old
[Mon Jul 20 06:52:52.854003 2026] [security2:error] [pid 1033876:tid 1034078] [client 34.73.38.214:50531] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aJEfjhWEjDbtLXL56WgAAAMw"]
[Mon Jul 20 06:52:52.885317 2026] [security2:error] [pid 1033876:tid 1034064] [client 34.73.38.214:59565] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thepauze.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aJEfjhWEjDbtLXL56YAAAAL4"]
[Mon Jul 20 06:52:52.940969 2026] [security2:error] [pid 1033876:tid 1034085] [client 161.118.218.103:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aJEfjhWEjDbtLXL56ZQAAANM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:53.102651 2026] [security2:error] [pid 1033876:tid 1034086] [client 193.37.252.163:38216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4aJUfjhWEjDbtLXL56aAAAANQ"]
[Mon Jul 20 06:52:53.102738 2026] [security2:error] [pid 1033876:tid 1034086] [client 193.37.252.163:38216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4aJUfjhWEjDbtLXL56aAAAANQ"]
[Mon Jul 20 06:52:53.128436 2026] [security2:error] [pid 1033876:tid 1034103] [client 82.102.18.116:35390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4aJUfjhWEjDbtLXL56agAAAOU"]
[Mon Jul 20 06:52:53.212791 2026] [security2:error] [pid 1033876:tid 1034010] [client 104.234.53.93:57097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4aJUfjhWEjDbtLXL56cgAAAIg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:53.441186 2026] [security2:error] [pid 1033876:tid 1034043] [client 82.102.18.116:35406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aJUfjhWEjDbtLXL56kgAAAKk"]
[Mon Jul 20 06:52:53.515888 2026] [security2:error] [pid 1033876:tid 1034029] [client 161.118.218.103:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aJUfjhWEjDbtLXL56lQAAAJs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:53.520822 2026] [security2:error] [pid 1033876:tid 1034088] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aJUfjhWEjDbtLXL56cQAAANY"]
[Mon Jul 20 06:52:53.528184 2026] [security2:error] [pid 1033876:tid 1033959] [remote 130.185.118.215:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aJUfjhWEjDbtLXL56mAAAs1E"]
[Mon Jul 20 06:52:53.598292 2026] [security2:error] [pid 1033876:tid 1034023] [client 34.73.38.214:55294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4aJUfjhWEjDbtLXL56mwAAAJU"]
[Mon Jul 20 06:52:53.598600 2026] [security2:error] [pid 1033876:tid 1034078] [client 114.119.136.160:54291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "latiendadejorge.com.gt"] [uri "/product/teami-soothe/"] [unique_id "al4aJUfjhWEjDbtLXL56nAAAAMw"], referer: https://latiendadejorge.com.gt/product/teami-skinny/
[Mon Jul 20 06:52:53.738338 2026] [security2:error] [pid 1033876:tid 1033950] [remote 130.185.118.215:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aJUfjhWEjDbtLXL56rQAA1Ug"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:52:53.758615 2026] [security2:error] [pid 1033876:tid 1034010] [client 82.102.18.116:35412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.robertpierson.net"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4aJUfjhWEjDbtLXL56rgAAAIg"]
[Mon Jul 20 06:52:53.818903 2026] [security2:error] [pid 1033876:tid 1033958] [remote 91.142.222.105:33988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aJUfjhWEjDbtLXL56swAAjlA"]
[Mon Jul 20 06:52:53.819112 2026] [security2:error] [pid 1033876:tid 1034016] [client 91.142.222.105:33988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aJUfjhWEjDbtLXL56swAAjlA"]
[Mon Jul 20 06:52:53.831821 2026] [security2:error] [pid 1033876:tid 1034039] [client 152.58.191.29:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aJUfjhWEjDbtLXL56tgAAAKU"]
[Mon Jul 20 06:52:53.838530 2026] [security2:error] [pid 1033876:tid 1034039] [client 152.58.191.29:61477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aJUfjhWEjDbtLXL56tgAAAKU"]
[Mon Jul 20 06:52:53.956623 2026] [security2:error] [pid 1033876:tid 1033957] [remote 152.228.213.32:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4aJUfjhWEjDbtLXL56wgABAk8"]
[Mon Jul 20 06:52:53.975095 2026] [security2:error] [pid 1033876:tid 1034009] [client 14.225.17.146:53600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4aJUfjhWEjDbtLXL56sAAAAIc"], referer: http://secretkeynumerology.com/wp-old
[Mon Jul 20 06:52:54.058961 2026] [security2:error] [pid 1033876:tid 1034061] [client 34.73.38.214:63412] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aJkfjhWEjDbtLXL56ywAAALs"]
[Mon Jul 20 06:52:54.095948 2026] [security2:error] [pid 1033876:tid 1034110] [client 14.225.17.146:53559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4aJUfjhWEjDbtLXL56nQAAAOw"], referer: http://gearwaterproof.com/wp-old
[Mon Jul 20 06:52:54.098138 2026] [security2:error] [pid 1033876:tid 1034059] [client 161.118.218.103:64103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aJkfjhWEjDbtLXL560AAAALk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:54.166170 2026] [security2:error] [pid 1033876:tid 1034107] [client 117.222.139.248:54069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aJkfjhWEjDbtLXL561AAAAOk"]
[Mon Jul 20 06:52:54.166278 2026] [security2:error] [pid 1033876:tid 1034107] [client 117.222.139.248:54069] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aJkfjhWEjDbtLXL561AAAAOk"]
[Mon Jul 20 06:52:54.177687 2026] [security2:error] [pid 1033876:tid 1033926] [remote 188.166.241.141:40866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4aJkfjhWEjDbtLXL561gAAjTA"]
[Mon Jul 20 06:52:54.261279 2026] [security2:error] [pid 1033876:tid 1034003] [remote 152.228.213.32:36566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4aJkfjhWEjDbtLXL563AAAmn0"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:52:54.584093 2026] [security2:error] [pid 1033876:tid 1033999] [remote 188.166.241.141:40866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4aJkfjhWEjDbtLXL568QAAkXk"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:52:54.671966 2026] [security2:error] [pid 1033876:tid 1034043] [client 161.118.218.103:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aJkfjhWEjDbtLXL569AAAAKk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:54.979183 2026] [security2:error] [pid 1033876:tid 1034092] [client 14.225.17.146:60748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4aJkfjhWEjDbtLXL57BQAAANo"], referer: https://secretkeynumerology.com/wp-old
[Mon Jul 20 06:52:55.007523 2026] [security2:error] [pid 1033876:tid 1034039] [client 34.73.38.214:62282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aJ0fjhWEjDbtLXL57HwAAAKU"]
[Mon Jul 20 06:52:55.052569 2026] [security2:error] [pid 1033876:tid 1034029] [client 14.225.17.146:60780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4aJkfjhWEjDbtLXL57CQAAAJs"], referer: http://fkconstructionfunding.com/wp-old
[Mon Jul 20 06:52:55.249831 2026] [security2:error] [pid 1033876:tid 1034068] [client 161.118.218.103:64816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aJ0fjhWEjDbtLXL57KAAAAMI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:55.354544 2026] [security2:error] [pid 1033876:tid 1034096] [client 104.234.53.52:49905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4aJ0fjhWEjDbtLXL57MgAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:55.821173 2026] [security2:error] [pid 1033876:tid 1034067] [client 161.118.218.103:65118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aJ0fjhWEjDbtLXL57TwAAAME"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:55.903003 2026] [security2:error] [pid 1033876:tid 1034132] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aJ0fjhWEjDbtLXL57RgAAAQI"]
[Mon Jul 20 06:52:55.967676 2026] [security2:error] [pid 1033876:tid 1034080] [client 34.73.38.214:51005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.thewelloiledlife.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aJ0fjhWEjDbtLXL57YAAAAM4"]
[Mon Jul 20 06:52:55.985839 2026] [security2:error] [pid 1033876:tid 1034069] [client 77.110.127.138:58748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aJ0fjhWEjDbtLXL57YwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:55.985938 2026] [security2:error] [pid 1033876:tid 1034069] [client 77.110.127.138:58748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aJ0fjhWEjDbtLXL57YwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:56.116147 2026] [security2:error] [pid 1033876:tid 1034048] [client 14.225.17.146:59504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4aJ0fjhWEjDbtLXL57XwAAAK4"], referer: https://fkconstructionfunding.com/wp-old
[Mon Jul 20 06:52:56.206451 2026] [security2:error] [pid 1033876:tid 1034116] [client 57.141.18.20:52284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aIkfjhWEjDbtLXL55awAA8l8"]
[Mon Jul 20 06:52:56.258257 2026] [security2:error] [pid 1033876:tid 1034053] [client 217.142.18.172:45275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aKEfjhWEjDbtLXL57cgAAALM"]
[Mon Jul 20 06:52:56.258660 2026] [security2:error] [pid 1033876:tid 1034053] [client 217.142.18.172:45275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aKEfjhWEjDbtLXL57cgAAALM"]
[Mon Jul 20 06:52:56.393487 2026] [security2:error] [pid 1033876:tid 1034013] [client 161.118.218.103:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aKEfjhWEjDbtLXL57fAAAAIs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:56.432438 2026] [security2:error] [pid 1033876:tid 1034030] [client 14.251.3.155:54758] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aKEfjhWEjDbtLXL57hAAAAJw"]
[Mon Jul 20 06:52:56.682952 2026] [security2:error] [pid 1033876:tid 1034069] [client 50.116.65.227:31748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aKEfjhWEjDbtLXL57kwAAAMM"]
[Mon Jul 20 06:52:56.691458 2026] [security2:error] [pid 1033876:tid 1034040] [client 50.116.65.227:31762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aKEfjhWEjDbtLXL57lQAAAKY"]
[Mon Jul 20 06:52:56.760310 2026] [security2:error] [pid 1033876:tid 1034107] [client 77.110.127.138:58754] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 873 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aKEfjhWEjDbtLXL57lwAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:56.881807 2026] [security2:error] [pid 1033876:tid 1034021] [client 39.48.81.23:49380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.81.48.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aKEfjhWEjDbtLXL57owAAAJM"]
[Mon Jul 20 06:52:56.882284 2026] [security2:error] [pid 1033876:tid 1034021] [client 39.48.81.23:49380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4aKEfjhWEjDbtLXL57owAAAJM"]
[Mon Jul 20 06:52:56.923977 2026] [security2:error] [pid 1033876:tid 1034116] [client 77.110.127.138:58755] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 885 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aKEfjhWEjDbtLXL57pgAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:56.966556 2026] [security2:error] [pid 1033876:tid 1034075] [client 161.118.218.103:49385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aKEfjhWEjDbtLXL57sQAAAMk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:57.193620 2026] [security2:error] [pid 1033876:tid 1034042] [client 66.249.64.39:61023] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "damkor.com"] [uri "/robots.txt"] [unique_id "al4aKUfjhWEjDbtLXL57wgAAAKg"]
[Mon Jul 20 06:52:57.248484 2026] [security2:error] [pid 1033876:tid 1034018] [client 77.110.127.138:58761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aKUfjhWEjDbtLXL57yAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:57.248604 2026] [security2:error] [pid 1033876:tid 1034018] [client 77.110.127.138:58761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aKUfjhWEjDbtLXL57yAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:57.276199 2026] [security2:error] [pid 1033876:tid 1034015] [client 106.219.188.178:16450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.188.219.106.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aKUfjhWEjDbtLXL57ygAAAI0"]
[Mon Jul 20 06:52:57.279870 2026] [security2:error] [pid 1033876:tid 1034015] [client 106.219.188.178:16450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sbinframx.com"] [uri "/xmlrpc.php"] [unique_id "al4aKUfjhWEjDbtLXL57ygAAAI0"]
[Mon Jul 20 06:52:57.360187 2026] [security2:error] [pid 1033876:tid 1034008] [client 45.3.54.97:59621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aKUfjhWEjDbtLXL57zAAAAIY"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:57.505257 2026] [security2:error] [pid 1033876:tid 1034056] [client 192.140.149.97:45408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aKUfjhWEjDbtLXL572gAAALY"]
[Mon Jul 20 06:52:57.505368 2026] [security2:error] [pid 1033876:tid 1034056] [client 192.140.149.97:45408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aKUfjhWEjDbtLXL572gAAALY"]
[Mon Jul 20 06:52:57.540597 2026] [security2:error] [pid 1033876:tid 1034111] [client 161.118.218.103:49726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aKUfjhWEjDbtLXL573gAAAO0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:57.606903 2026] [security2:error] [pid 1033876:tid 1034122] [client 104.234.53.94:31803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aKUfjhWEjDbtLXL575AAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:52:57.642733 2026] [security2:error] [pid 1033876:tid 1034027] [client 122.183.32.225:20053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aKUfjhWEjDbtLXL575QAAAJk"]
[Mon Jul 20 06:52:57.642824 2026] [security2:error] [pid 1033876:tid 1034027] [client 122.183.32.225:20053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aKUfjhWEjDbtLXL575QAAAJk"]
[Mon Jul 20 06:52:57.902823 2026] [security2:error] [pid 1033876:tid 1034132] [client 104.207.52.144:62723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aKUfjhWEjDbtLXL578wAAAQI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:57.995584 2026] [security2:error] [pid 1033876:tid 1033956] [remote 160.187.68.132:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4aKUfjhWEjDbtLXL58AQAAoU4"]
[Mon Jul 20 06:52:58.134582 2026] [security2:error] [pid 1033876:tid 1034078] [client 161.118.218.103:50075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aKkfjhWEjDbtLXL58BwAAAMw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:58.204576 2026] [security2:error] [pid 1033876:tid 1033895] [remote 57.141.18.67:47624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5276127"] [unique_id "al4aKkfjhWEjDbtLXL58CwAAxhE"]
[Mon Jul 20 06:52:58.260431 2026] [security2:error] [pid 1033876:tid 1034118] [client 103.238.106.162:42676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aKkfjhWEjDbtLXL58EgAAAPQ"]
[Mon Jul 20 06:52:58.260550 2026] [security2:error] [pid 1033876:tid 1034118] [client 103.238.106.162:42676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aKkfjhWEjDbtLXL58EgAAAPQ"]
[Mon Jul 20 06:52:58.464960 2026] [security2:error] [pid 1033876:tid 1034103] [client 104.207.52.93:49987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aKkfjhWEjDbtLXL58GwAAAOU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:58.467512 2026] [security2:error] [pid 1033876:tid 1034077] [client 77.110.127.138:58767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aKkfjhWEjDbtLXL58HwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:58.467604 2026] [security2:error] [pid 1033876:tid 1034077] [client 77.110.127.138:58767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aKkfjhWEjDbtLXL58HwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:58.503240 2026] [security2:error] [pid 1033876:tid 1033941] [remote 160.187.68.132:54936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4aKkfjhWEjDbtLXL58IgAAwT8"], referer: https://file.learnthissecret.com/wp-login.php
[Mon Jul 20 06:52:58.629147 2026] [security2:error] [pid 1033876:tid 1033990] [remote 64.176.84.101:52522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.84.176.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4aKkfjhWEjDbtLXL58LAAAxHA"]
[Mon Jul 20 06:52:58.629359 2026] [security2:error] [pid 1033876:tid 1034070] [client 64.176.84.101:52522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4aKkfjhWEjDbtLXL58LAAAxHA"]
[Mon Jul 20 06:52:58.658805 2026] [security2:error] [pid 1033876:tid 1034100] [client 46.110.96.34:45548] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4aKkfjhWEjDbtLXL58LgAAAOI"]
[Mon Jul 20 06:52:58.701798 2026] [security2:error] [pid 1033876:tid 1034073] [client 46.110.96.34:61418] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4aKkfjhWEjDbtLXL58MwAAAMc"]
[Mon Jul 20 06:52:58.729974 2026] [security2:error] [pid 1033876:tid 1034017] [client 161.118.218.103:50451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aKkfjhWEjDbtLXL58NQAAAI8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:58.914728 2026] [security2:error] [pid 1033876:tid 1033945] [remote 95.217.78.234:59784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aKkfjhWEjDbtLXL58UQAAjkM"]
[Mon Jul 20 06:52:58.914894 2026] [security2:error] [pid 1033876:tid 1034016] [client 95.217.78.234:59784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aKkfjhWEjDbtLXL58UQAAjkM"]
[Mon Jul 20 06:52:58.946325 2026] [security2:error] [pid 1033876:tid 1034034] [client 104.207.32.30:58353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.32.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aKkfjhWEjDbtLXL58TgAAAKA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:52:59.009049 2026] [security2:error] [pid 1033876:tid 1034076] [client 45.3.42.110:65037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aKkfjhWEjDbtLXL58WQAAAMo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:52:59.034460 2026] [security2:error] [pid 1033876:tid 1034059] [client 77.110.127.138:58770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aK0fjhWEjDbtLXL58XQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:59.034560 2026] [security2:error] [pid 1033876:tid 1034059] [client 77.110.127.138:58770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aK0fjhWEjDbtLXL58XQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:59.206427 2026] [security2:error] [pid 1033876:tid 1034085] [client 103.125.179.95:59079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aK0fjhWEjDbtLXL58eQAAANM"]
[Mon Jul 20 06:52:59.206902 2026] [security2:error] [pid 1033876:tid 1034085] [client 103.125.179.95:59079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aK0fjhWEjDbtLXL58eQAAANM"]
[Mon Jul 20 06:52:59.306955 2026] [security2:error] [pid 1033876:tid 1034130] [client 161.118.218.103:50885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aK0fjhWEjDbtLXL58gAAAAQA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:59.504840 2026] [security2:error] [pid 1033876:tid 1034070] [client 50.116.65.227:22694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aK0fjhWEjDbtLXL58mwAAAMQ"]
[Mon Jul 20 06:52:59.516307 2026] [security2:error] [pid 1033876:tid 1034017] [client 50.116.65.227:19738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aK0fjhWEjDbtLXL58ngAAAI8"]
[Mon Jul 20 06:52:59.535694 2026] [security2:error] [pid 1033876:tid 1033893] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aK0fjhWEjDbtLXL58ogAA1A8"]
[Mon Jul 20 06:52:59.535822 2026] [security2:error] [pid 1033876:tid 1034086] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aK0fjhWEjDbtLXL58ogAA1A8"]
[Mon Jul 20 06:52:59.784668 2026] [security2:error] [pid 1033876:tid 1034094] [client 57.141.18.45:40318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aJkfjhWEjDbtLXL561wAA3Ds"]
[Mon Jul 20 06:52:59.831486 2026] [security2:error] [pid 1033876:tid 1034109] [client 77.110.127.138:58777] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 182 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aK0fjhWEjDbtLXL58uwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:59.832346 2026] [security2:error] [pid 1033876:tid 1034130] [client 77.110.127.138:58778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aK0fjhWEjDbtLXL58vQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:59.832474 2026] [security2:error] [pid 1033876:tid 1034130] [client 77.110.127.138:58778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aK0fjhWEjDbtLXL58vQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:52:59.836216 2026] [security2:error] [pid 1033876:tid 1033890] [remote 188.166.241.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northplating.com"] [uri "/wp-login.php"] [unique_id "al4aK0fjhWEjDbtLXL58vwAA8ww"]
[Mon Jul 20 06:52:59.879763 2026] [security2:error] [pid 1033876:tid 1034060] [client 161.118.218.103:51268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aK0fjhWEjDbtLXL58xgAAALo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:52:59.963745 2026] [autoindex:error] [pid 1033876:tid 1033923] [remote 34.16.17.67:61254] AH01276: Cannot serve directory /home2/jopjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://jop.jiv.mybluehost.me
[Mon Jul 20 06:53:00.003782 2026] [security2:error] [pid 1033876:tid 1034079] [client 45.61.188.240:54497] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.adambergeron.com"] [uri "/"] [unique_id "al4aLEfjhWEjDbtLXL58zwAAAM0"]
[Mon Jul 20 06:53:00.009177 2026] [security2:error] [pid 1033876:tid 1034111] [client 117.247.108.24:31994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aLEfjhWEjDbtLXL580QAAAO0"]
[Mon Jul 20 06:53:00.009262 2026] [security2:error] [pid 1033876:tid 1034111] [client 117.247.108.24:31994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aLEfjhWEjDbtLXL580QAAAO0"]
[Mon Jul 20 06:53:00.057925 2026] [security2:error] [pid 1033876:tid 1034118] [client 36.152.7.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4aK0fjhWEjDbtLXL58rwAAAPQ"]
[Mon Jul 20 06:53:00.296553 2026] [security2:error] [pid 1033876:tid 1034092] [client 45.61.188.240:54541] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.adambergeron.com"] [uri "/"] [unique_id "al4aLEfjhWEjDbtLXL585QAAANo"]
[Mon Jul 20 06:53:00.455815 2026] [security2:error] [pid 1033876:tid 1034037] [client 161.118.218.103:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aLEfjhWEjDbtLXL588AAAAKM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:00.503587 2026] [security2:error] [pid 1033876:tid 1034011] [client 187.108.85.186:62403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aLEfjhWEjDbtLXL58-AAAAIk"]
[Mon Jul 20 06:53:00.503726 2026] [security2:error] [pid 1033876:tid 1034011] [client 187.108.85.186:62403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aLEfjhWEjDbtLXL58-AAAAIk"]
[Mon Jul 20 06:53:00.637468 2026] [security2:error] [pid 1033876:tid 1034054] [client 77.110.127.138:58783] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 522 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aLEfjhWEjDbtLXL58_wAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:00.639971 2026] [security2:error] [pid 1033876:tid 1034036] [client 14.225.17.146:56740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4aLEfjhWEjDbtLXL588gAAAKI"]
[Mon Jul 20 06:53:00.695979 2026] [security2:error] [pid 1033876:tid 1033906] [remote 154.66.198.148:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aLEfjhWEjDbtLXL59BwAA_xw"]
[Mon Jul 20 06:53:00.779578 2026] [security2:error] [pid 1033876:tid 1034134] [client 34.221.76.50:56022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4aLEfjhWEjDbtLXL59CQAAAQQ"]
[Mon Jul 20 06:53:01.038024 2026] [security2:error] [pid 1033876:tid 1034007] [client 161.118.218.103:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aLUfjhWEjDbtLXL59IAAAAIU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:01.082361 2026] [security2:error] [pid 1033876:tid 1034079] [client 183.82.98.154:53779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aLUfjhWEjDbtLXL59JAAAAM0"]
[Mon Jul 20 06:53:01.082489 2026] [security2:error] [pid 1033876:tid 1034079] [client 183.82.98.154:53779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aLUfjhWEjDbtLXL59JAAAAM0"]
[Mon Jul 20 06:53:01.131156 2026] [security2:error] [pid 1033876:tid 1034071] [client 193.37.252.163:33836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4aLUfjhWEjDbtLXL59KgAAAMU"]
[Mon Jul 20 06:53:01.131261 2026] [security2:error] [pid 1033876:tid 1034071] [client 193.37.252.163:33836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4aLUfjhWEjDbtLXL59KgAAAMU"]
[Mon Jul 20 06:53:01.198999 2026] [security2:error] [pid 1033876:tid 1034125] [client 14.225.17.146:59560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4aLUfjhWEjDbtLXL59IgAAAPs"], referer: http://ncsynchro.com/wp-old
[Mon Jul 20 06:53:01.285523 2026] [security2:error] [pid 1033876:tid 1033949] [remote 154.66.198.148:58676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aLUfjhWEjDbtLXL59OAAA_0c"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:01.517927 2026] [security2:error] [pid 1033876:tid 1034012] [client 14.225.17.146:57094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4aLEfjhWEjDbtLXL584QAAAIo"], referer: http://cloudspacesgroup.com/wp-old
[Mon Jul 20 06:53:01.613790 2026] [security2:error] [pid 1033876:tid 1034040] [client 161.118.218.103:52412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aLUfjhWEjDbtLXL59UgAAAKY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:02.189541 2026] [security2:error] [pid 1033876:tid 1034020] [client 161.118.218.103:52753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aLkfjhWEjDbtLXL59hQAAAJI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:02.213760 2026] [security2:error] [pid 1033876:tid 1034062] [client 18.141.57.241:60572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "curlsnpearlsss.com"] [uri "/wprm_print/bistec-encebollado-puerto-rican-steak-and-onions"] [unique_id "al4aLkfjhWEjDbtLXL59iAAAALw"], referer: https://curlsnpearlsss.com/bistec-encebollado-puerto-rican-steak-and-onions/
[Mon Jul 20 06:53:02.365248 2026] [security2:error] [pid 1033876:tid 1034054] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aLUfjhWEjDbtLXL59awAAALQ"]
[Mon Jul 20 06:53:02.434215 2026] [security2:error] [pid 1033876:tid 1034038] [client 57.141.18.25:64130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aKUfjhWEjDbtLXL57xwAApAs"]
[Mon Jul 20 06:53:02.692267 2026] [security2:error] [pid 1033876:tid 1034040] [client 14.225.17.146:60877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59qgAAAKY"], referer: http://wathenbartlett.co.uk/wp-old
[Mon Jul 20 06:53:02.763899 2026] [security2:error] [pid 1033876:tid 1034128] [client 161.118.218.103:53060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59wAAAAP4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:02.865304 2026] [security2:error] [pid 1033876:tid 1034050] [client 98.91.104.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59twAAsGo"]
[Mon Jul 20 06:53:02.886654 2026] [security2:error] [pid 1033876:tid 1034102] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59qAAAAOQ"]
[Mon Jul 20 06:53:02.908173 2026] [security2:error] [pid 1033876:tid 1034119] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59qQAAAPU"]
[Mon Jul 20 06:53:03.066145 2026] [security2:error] [pid 1033876:tid 1034023] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59ugAAAJU"]
[Mon Jul 20 06:53:03.092082 2026] [security2:error] [pid 1033876:tid 1034093] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59pQAAANs"]
[Mon Jul 20 06:53:03.298162 2026] [security2:error] [pid 1033876:tid 1034045] [client 34.187.29.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4aLkfjhWEjDbtLXL59uQAAAKs"]
[Mon Jul 20 06:53:03.311535 2026] [security2:error] [pid 1033876:tid 1034001] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aL0fjhWEjDbtLXL594wAA93s"], referer: https://aosta.nz/login
[Mon Jul 20 06:53:03.337830 2026] [security2:error] [pid 1033876:tid 1034017] [client 161.118.218.103:53432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aL0fjhWEjDbtLXL597AAAAI8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:03.594919 2026] [security2:error] [pid 1033876:tid 1034079] [client 14.225.17.146:58621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4aL0fjhWEjDbtLXL597QAAAM0"], referer: http://idigress.agency/wp-old
[Mon Jul 20 06:53:03.608503 2026] [security2:error] [pid 1033876:tid 1034040] [client 14.225.17.146:58643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4aL0fjhWEjDbtLXL59-wAAAKY"], referer: https://wathenbartlett.co.uk/wp-old
[Mon Jul 20 06:53:03.731531 2026] [security2:error] [pid 1033876:tid 1034112] [client 117.222.139.248:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aL0fjhWEjDbtLXL5-EwAAAO4"]
[Mon Jul 20 06:53:03.731652 2026] [security2:error] [pid 1033876:tid 1034112] [client 117.222.139.248:54527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aL0fjhWEjDbtLXL5-EwAAAO4"]
[Mon Jul 20 06:53:03.735199 2026] [security2:error] [pid 1033876:tid 1034073] [client 14.225.17.146:59043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4aL0fjhWEjDbtLXL59_gAAAMc"], referer: http://laceycaraccident.com/wp-old
[Mon Jul 20 06:53:03.913870 2026] [security2:error] [pid 1033876:tid 1034080] [client 161.118.218.103:53767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aL0fjhWEjDbtLXL5-HAAAAM4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:04.227355 2026] [security2:error] [pid 1033876:tid 1033924] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aMEfjhWEjDbtLXL5-NgABAi4"], referer: https://aosta.nz/wp-admin/
[Mon Jul 20 06:53:04.227404 2026] [security2:error] [pid 1033876:tid 1033919] [remote 34.187.29.36:51158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.29.187.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aMEfjhWEjDbtLXL5-NQABAik"], referer: https://aosta.nz/wp-admin/
[Mon Jul 20 06:53:04.413743 2026] [security2:error] [pid 1033876:tid 1034024] [client 14.225.17.146:58468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4aMEfjhWEjDbtLXL5-MQAAAJY"], referer: http://savilerowtravel.com/wp-old
[Mon Jul 20 06:53:04.489443 2026] [security2:error] [pid 1033876:tid 1034085] [client 161.118.218.103:54114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aMEfjhWEjDbtLXL5-VAAAANM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:05.067360 2026] [security2:error] [pid 1033876:tid 1034090] [client 161.118.218.103:54411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aMUfjhWEjDbtLXL5-gQAAANg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:05.435683 2026] [security2:error] [pid 1033876:tid 1034023] [client 14.225.17.146:58378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4aMUfjhWEjDbtLXL5-jAAAAJU"], referer: https://savilerowtravel.com/wp-old
[Mon Jul 20 06:53:05.484233 2026] [security2:error] [pid 1033876:tid 1034079] [client 158.173.241.141:40887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMUfjhWEjDbtLXL5-mgAAAM0"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 06:53:05.484340 2026] [security2:error] [pid 1033876:tid 1034079] [client 158.173.241.141:40887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMUfjhWEjDbtLXL5-mgAAAM0"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 06:53:05.537985 2026] [security2:error] [pid 1033876:tid 1034103] [client 14.225.17.146:55145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4aMUfjhWEjDbtLXL5-ogAAAOU"], referer: http://processorstudio.com/wp-old
[Mon Jul 20 06:53:05.544372 2026] [security2:error] [pid 1033876:tid 1033946] [remote 152.228.213.32:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aMUfjhWEjDbtLXL5-qAAAmEQ"]
[Mon Jul 20 06:53:05.644457 2026] [security2:error] [pid 1033876:tid 1034046] [client 161.118.218.103:54806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aMUfjhWEjDbtLXL5-rwAAAKw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:05.774786 2026] [security2:error] [pid 1033876:tid 1033918] [remote 152.228.213.32:34538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aMUfjhWEjDbtLXL5-uQAAySg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:53:05.784437 2026] [security2:error] [pid 1033876:tid 1034061] [client 197.186.66.42:49944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aMUfjhWEjDbtLXL5-vQAAALs"]
[Mon Jul 20 06:53:05.785119 2026] [security2:error] [pid 1033876:tid 1034061] [client 197.186.66.42:49944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aMUfjhWEjDbtLXL5-vQAAALs"]
[Mon Jul 20 06:53:05.959762 2026] [security2:error] [pid 1033876:tid 1034035] [client 158.173.241.141:31793] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMUfjhWEjDbtLXL5-0gAAAKE"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 06:53:06.000468 2026] [security2:error] [pid 1033876:tid 1034070] [client 77.110.127.138:58816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aMUfjhWEjDbtLXL5-mAAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:06.217579 2026] [security2:error] [pid 1033876:tid 1034087] [client 161.118.218.103:55164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aMkfjhWEjDbtLXL5-4AAAANU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:06.285992 2026] [security2:error] [pid 1033876:tid 1034113] [client 77.110.127.138:58819] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 395 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aMkfjhWEjDbtLXL5-4gAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:06.422686 2026] [security2:error] [pid 1033876:tid 1034047] [client 14.225.17.146:59079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4aMkfjhWEjDbtLXL5-5gAAAK0"], referer: https://processorstudio.com/wp-old
[Mon Jul 20 06:53:06.440172 2026] [security2:error] [pid 1033876:tid 1034021] [client 77.110.127.138:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMkfjhWEjDbtLXL5-7QAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:06.440247 2026] [security2:error] [pid 1033876:tid 1034021] [client 77.110.127.138:58821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMkfjhWEjDbtLXL5-7QAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:06.617511 2026] [security2:error] [pid 1033876:tid 1034066] [client 77.110.127.138:58823] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 442 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aMkfjhWEjDbtLXL5-_AAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:06.669811 2026] [security2:error] [pid 1033876:tid 1033948] [remote 38.111.98.222:27195] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4aMkfjhWEjDbtLXL5_AgAA4kY"]
[Mon Jul 20 06:53:06.766657 2026] [security2:error] [pid 1033876:tid 1034105] [client 217.142.18.172:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aMkfjhWEjDbtLXL5_CgAAAOc"]
[Mon Jul 20 06:53:06.766804 2026] [security2:error] [pid 1033876:tid 1034105] [client 217.142.18.172:57808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aMkfjhWEjDbtLXL5_CgAAAOc"]
[Mon Jul 20 06:53:06.796668 2026] [security2:error] [pid 1033876:tid 1034132] [client 161.118.218.103:55525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aMkfjhWEjDbtLXL5_DAAAAQI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:06.809541 2026] [security2:error] [pid 1033876:tid 1033997] [remote 20.153.140.50:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aMkfjhWEjDbtLXL5_DQAAw3c"]
[Mon Jul 20 06:53:07.158345 2026] [security2:error] [pid 1033876:tid 1034035] [client 158.173.241.141:31793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMUfjhWEjDbtLXL5-0gAAAKE"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 06:53:07.158388 2026] [security2:error] [pid 1033876:tid 1034035] [client 158.173.241.141:31793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4aMUfjhWEjDbtLXL5-0gAAAKE"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 06:53:07.214408 2026] [security2:error] [pid 1033876:tid 1033965] [remote 20.153.140.50:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aM0fjhWEjDbtLXL5_KwAA1Fc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:53:07.385237 2026] [security2:error] [pid 1033876:tid 1034104] [client 161.118.218.103:55863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aM0fjhWEjDbtLXL5_NwAAAOY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:07.815788 2026] [security2:error] [pid 1033876:tid 1034045] [client 50.116.65.227:22714] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aM0fjhWEjDbtLXL5_VAAAAKs"]
[Mon Jul 20 06:53:07.826613 2026] [security2:error] [pid 1033876:tid 1034035] [client 50.116.65.227:19840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aM0fjhWEjDbtLXL5_VQAAANA"]
[Mon Jul 20 06:53:07.973474 2026] [security2:error] [pid 1033876:tid 1034124] [client 161.118.218.103:56159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aM0fjhWEjDbtLXL5_YwAAAPo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:08.114900 2026] [security2:error] [pid 1033876:tid 1034091] [client 77.110.127.138:58828] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 684 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aNEfjhWEjDbtLXL5_bQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:08.267907 2026] [security2:error] [pid 1033876:tid 1033878] [remote 217.182.128.41:51338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aNEfjhWEjDbtLXL5_dgAAkgA"]
[Mon Jul 20 06:53:08.268045 2026] [security2:error] [pid 1033876:tid 1034020] [client 217.182.128.41:51338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aNEfjhWEjDbtLXL5_dgAAkgA"]
[Mon Jul 20 06:53:08.381419 2026] [security2:error] [pid 1033876:tid 1034000] [remote 167.71.132.111:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aNEfjhWEjDbtLXL5_fQAA-Xo"]
[Mon Jul 20 06:53:08.557124 2026] [security2:error] [pid 1033876:tid 1034050] [client 161.118.218.103:56521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aNEfjhWEjDbtLXL5_kQAAALA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:08.566814 2026] [security2:error] [pid 1033876:tid 1033899] [remote 167.71.132.111:35358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.132.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aNEfjhWEjDbtLXL5_kAAA-hU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:53:08.820297 2026] [security2:error] [pid 1033876:tid 1034018] [client 185.223.152.109:22237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.152.223.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jedalilly.com"] [uri "/wp-login.php"] [unique_id "al4aNEfjhWEjDbtLXL5_owAAAJA"]
[Mon Jul 20 06:53:08.841504 2026] [security2:error] [pid 1033876:tid 1034021] [client 103.238.106.162:42822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aNEfjhWEjDbtLXL5_pgAAAJM"]
[Mon Jul 20 06:53:08.841616 2026] [security2:error] [pid 1033876:tid 1034021] [client 103.238.106.162:42822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aNEfjhWEjDbtLXL5_pgAAAJM"]
[Mon Jul 20 06:53:08.857591 2026] [security2:error] [pid 1033876:tid 1034020] [client 50.116.65.227:22726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aNEfjhWEjDbtLXL5_pwAAAJI"]
[Mon Jul 20 06:53:08.868713 2026] [security2:error] [pid 1033876:tid 1034117] [client 50.116.65.227:19884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aNEfjhWEjDbtLXL5_qAAAAK0"]
[Mon Jul 20 06:53:09.039317 2026] [security2:error] [pid 1033876:tid 1034087] [client 77.110.127.138:58830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aNEfjhWEjDbtLXL5_pQAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:09.135069 2026] [security2:error] [pid 1033876:tid 1034075] [client 161.118.218.103:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aNUfjhWEjDbtLXL5_wgAAAMk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:09.175988 2026] [security2:error] [pid 1033876:tid 1034109] [client 104.234.53.60:46905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aNUfjhWEjDbtLXL5_xAAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:09.178875 2026] [security2:error] [pid 1033876:tid 1034100] [client 122.183.32.225:14350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL5_xQAAAOI"]
[Mon Jul 20 06:53:09.192727 2026] [security2:error] [pid 1033876:tid 1034100] [client 122.183.32.225:14350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL5_xQAAAOI"]
[Mon Jul 20 06:53:09.723080 2026] [security2:error] [pid 1033876:tid 1034069] [client 161.118.218.103:57238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aNUfjhWEjDbtLXL5_9gAAAMM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:09.799133 2026] [security2:error] [pid 1033876:tid 1034073] [client 152.58.191.29:62017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL5_-QAAAMc"]
[Mon Jul 20 06:53:09.799235 2026] [security2:error] [pid 1033876:tid 1034073] [client 152.58.191.29:62017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL5_-QAAAMc"]
[Mon Jul 20 06:53:09.962775 2026] [security2:error] [pid 1033876:tid 1034094] [client 103.125.179.95:59586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL6ABQAAANw"]
[Mon Jul 20 06:53:09.962906 2026] [security2:error] [pid 1033876:tid 1034094] [client 103.125.179.95:59586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL6ABQAAANw"]
[Mon Jul 20 06:53:09.969069 2026] [security2:error] [pid 1033876:tid 1034127] [client 77.110.127.138:58837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aNUfjhWEjDbtLXL5_8QAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:09.986685 2026] [security2:error] [pid 1033876:tid 1033897] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL6ABwAA0RM"]
[Mon Jul 20 06:53:09.986839 2026] [security2:error] [pid 1033876:tid 1034083] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aNUfjhWEjDbtLXL6ABwAA0RM"]
[Mon Jul 20 06:53:10.119323 2026] [security2:error] [pid 1033876:tid 1034082] [client 103.47.54.187:51253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4aNkfjhWEjDbtLXL6ADAAAANA"], referer: https://recruitinginsight.us/subscribe/
[Mon Jul 20 06:53:10.192511 2026] [security2:error] [pid 1033876:tid 1034015] [client 50.116.65.227:57254] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aNkfjhWEjDbtLXL6AGgAAAI0"]
[Mon Jul 20 06:53:10.202894 2026] [security2:error] [pid 1033876:tid 1034071] [client 50.116.65.227:12356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4aNkfjhWEjDbtLXL6AGwAAAIc"]
[Mon Jul 20 06:53:10.301737 2026] [security2:error] [pid 1033876:tid 1034113] [client 161.118.218.103:57591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aNkfjhWEjDbtLXL6AIQAAAO8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:10.361917 2026] [security2:error] [pid 1033876:tid 1033901] [remote 47.86.33.52:19028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4aNkfjhWEjDbtLXL6AJgAA6hc"]
[Mon Jul 20 06:53:10.674419 2026] [security2:error] [pid 1033876:tid 1034123] [client 14.225.17.146:61133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4aNkfjhWEjDbtLXL6APgAAAPk"], referer: http://nextlvlmarketingco.com/wp-old
[Mon Jul 20 06:53:10.755971 2026] [security2:error] [pid 1033876:tid 1034010] [client 117.247.108.24:1062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aNkfjhWEjDbtLXL6ATQAAAIg"]
[Mon Jul 20 06:53:10.756086 2026] [security2:error] [pid 1033876:tid 1034010] [client 117.247.108.24:1062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aNkfjhWEjDbtLXL6ATQAAAIg"]
[Mon Jul 20 06:53:10.876009 2026] [security2:error] [pid 1033876:tid 1034029] [client 161.118.218.103:57935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aNkfjhWEjDbtLXL6AWQAAAJs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:10.916571 2026] [security2:error] [pid 1033876:tid 1034034] [client 187.108.85.186:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aNkfjhWEjDbtLXL6AWwAAAKA"]
[Mon Jul 20 06:53:10.916694 2026] [security2:error] [pid 1033876:tid 1034034] [client 187.108.85.186:62931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aNkfjhWEjDbtLXL6AWwAAAKA"]
[Mon Jul 20 06:53:11.060570 2026] [security2:error] [pid 1033876:tid 1033956] [remote 57.141.18.37:30124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5035118"] [unique_id "al4aN0fjhWEjDbtLXL6AaQAArU4"]
[Mon Jul 20 06:53:11.083480 2026] [security2:error] [pid 1033876:tid 1034023] [client 77.110.127.138:58838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aN0fjhWEjDbtLXL6AbgAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:11.083573 2026] [security2:error] [pid 1033876:tid 1034023] [client 77.110.127.138:58838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aN0fjhWEjDbtLXL6AbgAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:11.123774 2026] [security2:error] [pid 1033876:tid 1034046] [client 14.251.3.155:54765] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aN0fjhWEjDbtLXL6AdgAAAKw"]
[Mon Jul 20 06:53:11.237659 2026] [security2:error] [pid 1033876:tid 1034010] [client 77.110.127.138:58841] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:noamp"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aN0fjhWEjDbtLXL6AegAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:11.461661 2026] [security2:error] [pid 1033876:tid 1034080] [client 161.118.218.103:58269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aN0fjhWEjDbtLXL6AjAAAAM4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:11.506427 2026] [security2:error] [pid 1033876:tid 1034125] [client 14.225.17.146:55362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4aN0fjhWEjDbtLXL6AhwAAAPs"], referer: http://keywayconstructionclt.com/wp-old
[Mon Jul 20 06:53:11.617829 2026] [security2:error] [pid 1033876:tid 1033976] [remote 47.86.33.52:19028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4aN0fjhWEjDbtLXL6AlgAA6WI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:53:11.677393 2026] [security2:error] [pid 1033876:tid 1034090] [client 45.61.188.240:56351] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4aN0fjhWEjDbtLXL6AoAAAANg"]
[Mon Jul 20 06:53:11.874341 2026] [security2:error] [pid 1033876:tid 1034084] [client 77.110.127.138:58842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aN0fjhWEjDbtLXL6AgQAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:11.943196 2026] [security2:error] [pid 1033876:tid 1034050] [client 45.61.188.240:56408] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "adambergeron.com"] [uri "/"] [unique_id "al4aN0fjhWEjDbtLXL6AuAAAALA"]
[Mon Jul 20 06:53:12.004434 2026] [security2:error] [pid 1033876:tid 1034007] [client 183.82.98.154:54378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aOEfjhWEjDbtLXL6AvwAAAIU"]
[Mon Jul 20 06:53:12.004572 2026] [security2:error] [pid 1033876:tid 1034007] [client 183.82.98.154:54378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aOEfjhWEjDbtLXL6AvwAAAIU"]
[Mon Jul 20 06:53:12.035849 2026] [security2:error] [pid 1033876:tid 1034053] [client 161.118.218.103:58639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aOEfjhWEjDbtLXL6AwQAAALM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:12.262214 2026] [security2:error] [pid 1033876:tid 1034039] [client 77.110.127.138:58847] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 707 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aOEfjhWEjDbtLXL6A1QAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:12.367027 2026] [security2:error] [pid 1033876:tid 1034110] [client 77.110.127.138:58846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aOEfjhWEjDbtLXL6AywAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:12.459076 2026] [security2:error] [pid 1033876:tid 1034121] [client 14.225.17.146:49811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4aOEfjhWEjDbtLXL6A4AAAAPc"], referer: https://keywayconstructionclt.com/wp-old
[Mon Jul 20 06:53:12.611126 2026] [security2:error] [pid 1033876:tid 1034130] [client 161.118.218.103:58988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aOEfjhWEjDbtLXL6A9wAAAQA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:12.862472 2026] [security2:error] [pid 1033876:tid 1034000] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pricecuthomes.com"] [uri "/wp-login.php"] [unique_id "al4aOEfjhWEjDbtLXL6BCQABA3o"]
[Mon Jul 20 06:53:12.881771 2026] [security2:error] [pid 1033876:tid 1034033] [client 14.225.17.146:54313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4aOEfjhWEjDbtLXL6BBQAAAJ8"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/wp-old
[Mon Jul 20 06:53:13.186644 2026] [security2:error] [pid 1033876:tid 1034050] [client 161.118.218.103:59331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aOUfjhWEjDbtLXL6BLQAAALA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:13.408164 2026] [security2:error] [pid 1033876:tid 1033900] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pricecuthomes.com"] [uri "/wp-login.php"] [unique_id "al4aOUfjhWEjDbtLXL6BSQABBBY"], referer: https://pricecuthomes.com/wp-login.php
[Mon Jul 20 06:53:13.718887 2026] [security2:error] [pid 1033876:tid 1034034] [client 77.110.127.138:58854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aOUfjhWEjDbtLXL6BawAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:13.718994 2026] [security2:error] [pid 1033876:tid 1034034] [client 77.110.127.138:58854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aOUfjhWEjDbtLXL6BawAAAKA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:13.735666 2026] [security2:error] [pid 1033876:tid 1034109] [client 77.110.127.138:58853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aOUfjhWEjDbtLXL6BVgAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:13.764377 2026] [security2:error] [pid 1033876:tid 1034046] [client 161.118.218.103:59717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aOUfjhWEjDbtLXL6BdQAAAKw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:13.855693 2026] [fcgid:warn] [pid 1033876:tid 1034089] (70014)End of file found: [client 199.45.155.109:56508] mod_fcgid: can't get data from http client
[Mon Jul 20 06:53:13.857071 2026] [security2:error] [pid 1033876:tid 1034042] [client 158.173.166.181:25407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aOUfjhWEjDbtLXL6BfAAAAKg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:53:13.872839 2026] [security2:error] [pid 1033876:tid 1034055] [client 77.110.127.138:58857] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aOUfjhWEjDbtLXL6BfQAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:13.928315 2026] [security2:error] [pid 1033876:tid 1034121] [client 77.110.127.138:58831] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aOUfjhWEjDbtLXL6BgwAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:14.243850 2026] [security2:error] [pid 1033876:tid 1034133] [client 117.222.139.248:54995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aOkfjhWEjDbtLXL6BmQAAAQM"]
[Mon Jul 20 06:53:14.243971 2026] [security2:error] [pid 1033876:tid 1034133] [client 117.222.139.248:54995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aOkfjhWEjDbtLXL6BmQAAAQM"]
[Mon Jul 20 06:53:14.308116 2026] [security2:error] [pid 1033876:tid 1034126] [client 77.110.127.138:58837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aOkfjhWEjDbtLXL6BjwAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:14.341905 2026] [security2:error] [pid 1033876:tid 1034056] [client 161.118.218.103:60108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aOkfjhWEjDbtLXL6BpgAAALY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:14.563923 2026] [security2:error] [pid 1033876:tid 1034107] [client 104.234.53.56:49697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4aOkfjhWEjDbtLXL6BwQAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:14.915539 2026] [security2:error] [pid 1033876:tid 1034125] [client 161.118.218.103:60439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aOkfjhWEjDbtLXL6B4AAAAPs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:14.998684 2026] [security2:error] [pid 1033876:tid 1034114] [client 77.110.127.138:58859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aOkfjhWEjDbtLXL6B6QAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:14.998783 2026] [security2:error] [pid 1033876:tid 1034114] [client 77.110.127.138:58859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aOkfjhWEjDbtLXL6B6QAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:15.172533 2026] [security2:error] [pid 1033876:tid 1034048] [client 77.110.127.138:58860] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aO0fjhWEjDbtLXL6B9AAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:15.260075 2026] [security2:error] [pid 1033876:tid 1034066] [client 77.110.127.138:58839] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aO0fjhWEjDbtLXL6CAQAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:15.379227 2026] [security2:error] [pid 1033876:tid 1034059] [client 57.141.18.109:45230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aNUfjhWEjDbtLXL5_yQAAuTQ"]
[Mon Jul 20 06:53:15.428473 2026] [security2:error] [pid 1033876:tid 1034128] [client 77.110.127.138:58862] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aO0fjhWEjDbtLXL6CDwAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:15.490241 2026] [security2:error] [pid 1033876:tid 1034126] [client 161.118.218.103:60767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aO0fjhWEjDbtLXL6CFgAAAPw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:15.672642 2026] [proxy:error] [pid 1033876:tid 1034029] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:15.672677 2026] [proxy_http:error] [pid 1033876:tid 1034029] [client 107.172.180.205:37720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:15.673253 2026] [proxy:error] [pid 1033876:tid 1034029] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:15.673279 2026] [proxy_http:error] [pid 1033876:tid 1034029] [client 107.172.180.205:37720] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:15.781341 2026] [security2:error] [pid 1033876:tid 1034033] [client 77.110.127.138:58864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aO0fjhWEjDbtLXL6CHgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:15.827121 2026] [security2:error] [pid 1033876:tid 1034040] [client 195.242.214.166:42870] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4aO0fjhWEjDbtLXL6CLwAAAKY"]
[Mon Jul 20 06:53:16.001599 2026] [security2:error] [pid 1033876:tid 1033984] [remote 84.247.172.23:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aO0fjhWEjDbtLXL6CPAAA6mo"]
[Mon Jul 20 06:53:16.079174 2026] [security2:error] [pid 1033876:tid 1034132] [client 161.118.218.103:61091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aPEfjhWEjDbtLXL6CQgAAAQI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:16.098644 2026] [security2:error] [pid 1033876:tid 1034099] [client 77.110.127.138:58851] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:noamp. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aPEfjhWEjDbtLXL6CRgAAAOE"]
[Mon Jul 20 06:53:16.180101 2026] [security2:error] [pid 1033876:tid 1034046] [client 77.110.127.138:58868] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aPEfjhWEjDbtLXL6CUAAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:16.189680 2026] [security2:error] [pid 1033876:tid 1033981] [remote 84.247.172.23:53272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aPEfjhWEjDbtLXL6CUgAApGc"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 06:53:16.232467 2026] [security2:error] [pid 1033876:tid 1034042] [client 77.110.127.138:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aPEfjhWEjDbtLXL6CVwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:16.232574 2026] [security2:error] [pid 1033876:tid 1034042] [client 77.110.127.138:58852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aPEfjhWEjDbtLXL6CVwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:16.264879 2026] [security2:error] [pid 1033876:tid 1034028] [client 152.58.191.29:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aPEfjhWEjDbtLXL6CWwAAAJo"]
[Mon Jul 20 06:53:16.272544 2026] [security2:error] [pid 1033876:tid 1034028] [client 152.58.191.29:62462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aPEfjhWEjDbtLXL6CWwAAAJo"]
[Mon Jul 20 06:53:16.499145 2026] [core:error] [pid 1033876:tid 1034017] [client 14.225.17.146:60940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:16.499170 2026] [core:error] [pid 1033876:tid 1034017] [client 14.225.17.146:60940] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:16.505238 2026] [security2:error] [pid 1033876:tid 1034114] [client 74.208.214.194:38462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4aPEfjhWEjDbtLXL6CdQAAAPA"]
[Mon Jul 20 06:53:16.557578 2026] [security2:error] [pid 1033876:tid 1034063] [client 195.2.67.184:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4aPEfjhWEjDbtLXL6CUwAAAL0"], referer: https://schuttfarms.com/schutt-farms-the-blog/
[Mon Jul 20 06:53:16.565615 2026] [proxy:error] [pid 1033876:tid 1034064] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:16.565651 2026] [proxy_http:error] [pid 1033876:tid 1034064] [client 205.210.31.20:63268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:16.566782 2026] [proxy:error] [pid 1033876:tid 1034064] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:16.566823 2026] [proxy_http:error] [pid 1033876:tid 1034064] [client 205.210.31.20:63268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:16.595586 2026] [core:error] [pid 1033876:tid 1034039] [client 205.210.31.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:16.595611 2026] [core:error] [pid 1033876:tid 1034039] [client 205.210.31.20:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:16.618663 2026] [security2:error] [pid 1033876:tid 1033931] [remote 47.86.33.52:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4aPEfjhWEjDbtLXL6ChQAA4DU"]
[Mon Jul 20 06:53:16.654152 2026] [security2:error] [pid 1033876:tid 1034084] [client 161.118.218.103:61441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aPEfjhWEjDbtLXL6CiwAAANI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:16.703061 2026] [security2:error] [pid 1033876:tid 1034051] [client 77.110.127.138:58869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aPEfjhWEjDbtLXL6CVAAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:16.751403 2026] [proxy:error] [pid 1033876:tid 1034045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:16.751480 2026] [proxy_http:error] [pid 1033876:tid 1034045] [client 107.172.180.205:37748] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:16.752031 2026] [proxy:error] [pid 1033876:tid 1034045] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:16.752064 2026] [proxy_http:error] [pid 1033876:tid 1034045] [client 107.172.180.205:37748] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:17.117896 2026] [security2:error] [pid 1033876:tid 1033883] [remote 47.86.33.52:56102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4aPUfjhWEjDbtLXL6CxwABAQU"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:53:17.237628 2026] [security2:error] [pid 1033876:tid 1034020] [client 161.118.218.103:61783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aPUfjhWEjDbtLXL6CzAAAAJI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:17.288379 2026] [security2:error] [pid 1033876:tid 1034082] [client 217.142.18.172:44210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aPUfjhWEjDbtLXL6CzwAAANA"]
[Mon Jul 20 06:53:17.288479 2026] [security2:error] [pid 1033876:tid 1034082] [client 217.142.18.172:44210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aPUfjhWEjDbtLXL6CzwAAANA"]
[Mon Jul 20 06:53:17.455649 2026] [security2:error] [pid 1033876:tid 1033924] [remote 162.19.86.63:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4aPUfjhWEjDbtLXL6C2gAAvy4"]
[Mon Jul 20 06:53:17.653247 2026] [security2:error] [pid 1033876:tid 1034064] [client 41.74.56.192:8514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.56.74.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "betterbonddogtraining.com"] [uri "/xmlrpc.php"] [unique_id "al4aPUfjhWEjDbtLXL6C6wAAAL4"]
[Mon Jul 20 06:53:17.653379 2026] [security2:error] [pid 1033876:tid 1034064] [client 41.74.56.192:8514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "betterbonddogtraining.com"] [uri "/xmlrpc.php"] [unique_id "al4aPUfjhWEjDbtLXL6C6wAAAL4"]
[Mon Jul 20 06:53:17.753386 2026] [security2:error] [pid 1033876:tid 1034061] [client 77.110.127.138:58837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aPUfjhWEjDbtLXL6CxQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:17.798858 2026] [security2:error] [pid 1033876:tid 1033907] [remote 162.19.86.63:38943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4aPUfjhWEjDbtLXL6C_AAA1B0"], referer: https://mrbambooplus.com/wp-login.php
[Mon Jul 20 06:53:17.813516 2026] [security2:error] [pid 1033876:tid 1034034] [client 161.118.218.103:62086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aPUfjhWEjDbtLXL6C_QAAAKA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:18.322742 2026] [security2:error] [pid 1033876:tid 1034087] [client 14.225.17.146:53607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4aPkfjhWEjDbtLXL6DHQAAANU"], referer: http://entuvy.com/wp-old
[Mon Jul 20 06:53:18.390076 2026] [security2:error] [pid 1033876:tid 1034024] [client 161.118.218.103:62400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aPkfjhWEjDbtLXL6DIgAAAJY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:18.497258 2026] [security2:error] [pid 1033876:tid 1034131] [client 197.186.66.42:50472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aPkfjhWEjDbtLXL6DMQAAAQE"]
[Mon Jul 20 06:53:18.497348 2026] [security2:error] [pid 1033876:tid 1034131] [client 197.186.66.42:50472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aPkfjhWEjDbtLXL6DMQAAAQE"]
[Mon Jul 20 06:53:18.578313 2026] [security2:error] [pid 1033876:tid 1034080] [client 14.225.17.146:62773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4aPkfjhWEjDbtLXL6DKwAAAM4"], referer: http://koaconsultants.com/wp-old
[Mon Jul 20 06:53:18.595099 2026] [security2:error] [pid 1033876:tid 1034090] [client 158.173.89.95:25403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aPkfjhWEjDbtLXL6DPAAAANg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:53:18.602468 2026] [security2:error] [pid 1033876:tid 1034012] [client 14.225.17.146:62779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4aPkfjhWEjDbtLXL6DJgAAAIo"], referer: http://alexsandbergmusic.com/wp-old
[Mon Jul 20 06:53:18.609435 2026] [security2:error] [pid 1033876:tid 1034032] [client 77.110.127.138:58874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aPkfjhWEjDbtLXL6DQQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:18.609565 2026] [security2:error] [pid 1033876:tid 1034032] [client 77.110.127.138:58874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aPkfjhWEjDbtLXL6DQQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:18.619010 2026] [security2:error] [pid 1033876:tid 1034007] [client 14.225.17.146:53494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4aPUfjhWEjDbtLXL6C0AAAAIU"], referer: http://momheadquarters.com/wp-old
[Mon Jul 20 06:53:18.833152 2026] [security2:error] [pid 1033876:tid 1034068] [client 159.26.120.31:10519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.120.26.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aPkfjhWEjDbtLXL6DSwAAAMI"]
[Mon Jul 20 06:53:18.833269 2026] [security2:error] [pid 1033876:tid 1034068] [client 159.26.120.31:10519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ouw.egd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aPkfjhWEjDbtLXL6DSwAAAMI"]
[Mon Jul 20 06:53:18.970079 2026] [security2:error] [pid 1033876:tid 1034017] [client 161.118.218.103:62792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aPkfjhWEjDbtLXL6DWAAAAI8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:18.984514 2026] [security2:error] [pid 1033876:tid 1034040] [client 77.110.127.138:58860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aPkfjhWEjDbtLXL6DRgAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:19.185600 2026] [security2:error] [pid 1033876:tid 1034073] [client 192.140.149.97:44661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aP0fjhWEjDbtLXL6DcQAAAMc"]
[Mon Jul 20 06:53:19.185700 2026] [security2:error] [pid 1033876:tid 1034073] [client 192.140.149.97:44661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aP0fjhWEjDbtLXL6DcQAAAMc"]
[Mon Jul 20 06:53:19.195522 2026] [security2:error] [pid 1033876:tid 1034097] [client 151.123.177.203:11445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aP0fjhWEjDbtLXL6DZwAAAN8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:19.228998 2026] [security2:error] [pid 1033876:tid 1034083] [client 14.225.17.146:53296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4aP0fjhWEjDbtLXL6DZgAAANE"], referer: http://cephasnext.com/wp-old
[Mon Jul 20 06:53:19.314533 2026] [security2:error] [pid 1033876:tid 1034033] [client 103.238.106.162:63772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aP0fjhWEjDbtLXL6DfwAAAJ8"]
[Mon Jul 20 06:53:19.314699 2026] [security2:error] [pid 1033876:tid 1034033] [client 103.238.106.162:63772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aP0fjhWEjDbtLXL6DfwAAAJ8"]
[Mon Jul 20 06:53:19.428323 2026] [security2:error] [pid 1033876:tid 1034079] [client 104.234.53.92:38525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4aP0fjhWEjDbtLXL6DiAAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:19.548301 2026] [security2:error] [pid 1033876:tid 1034063] [client 161.118.218.103:63231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aP0fjhWEjDbtLXL6DkAAAAL0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:20.124299 2026] [security2:error] [pid 1033876:tid 1034070] [client 161.118.218.103:63595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aQEfjhWEjDbtLXL6DuQAAAMQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:20.295991 2026] [security2:error] [pid 1033876:tid 1034009] [client 77.110.127.138:58864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aP0fjhWEjDbtLXL6DmQAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:20.443255 2026] [security2:error] [pid 1033876:tid 1034110] [client 216.73.217.138:64569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4aQEfjhWEjDbtLXL6DwgAA7EU"]
[Mon Jul 20 06:53:20.629789 2026] [security2:error] [pid 1033876:tid 1034004] [remote 216.73.217.138:64569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.217.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/pindex.php"] [unique_id "al4aQEfjhWEjDbtLXL6D2QAAoX4"]
[Mon Jul 20 06:53:20.649195 2026] [security2:error] [pid 1033876:tid 1034065] [client 104.234.53.82:52485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aQEfjhWEjDbtLXL6D3QAAAL8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:20.695625 2026] [security2:error] [pid 1033876:tid 1034100] [client 161.118.218.103:63981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aQEfjhWEjDbtLXL6D4AAAAOI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:20.713802 2026] [security2:error] [pid 1033876:tid 1033891] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aQEfjhWEjDbtLXL6D4wAAkA0"]
[Mon Jul 20 06:53:20.713943 2026] [security2:error] [pid 1033876:tid 1034018] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aQEfjhWEjDbtLXL6D4wAAkA0"]
[Mon Jul 20 06:53:20.735719 2026] [security2:error] [pid 1033876:tid 1034082] [client 103.125.179.95:60085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aQEfjhWEjDbtLXL6D6wAAANA"]
[Mon Jul 20 06:53:20.735875 2026] [security2:error] [pid 1033876:tid 1034082] [client 103.125.179.95:60085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aQEfjhWEjDbtLXL6D6wAAANA"]
[Mon Jul 20 06:53:20.982083 2026] [security2:error] [pid 1033876:tid 1034002] [remote 114.119.145.7:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aasgroup.online"] [uri "/robots.txt"] [unique_id "al4aQEfjhWEjDbtLXL6EAQAAl3w"], referer: https://aasgroup.online/robots.txt
[Mon Jul 20 06:53:21.004320 2026] [security2:error] [pid 1033876:tid 1034099] [client 143.244.57.90:57256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4aQUfjhWEjDbtLXL6EBwAAAOE"]
[Mon Jul 20 06:53:21.268373 2026] [security2:error] [pid 1033876:tid 1034091] [client 161.118.218.103:64299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aQUfjhWEjDbtLXL6EGgAAANk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:21.319929 2026] [security2:error] [pid 1033876:tid 1034112] [client 143.244.57.90:57272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.north-woods-engineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aQUfjhWEjDbtLXL6EHwAAAO4"]
[Mon Jul 20 06:53:21.360542 2026] [security2:error] [pid 1033876:tid 1034094] [client 114.119.146.219:45649] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villa-m-medjugorje.com"] [uri "/robots.txt"] [unique_id "al4aQUfjhWEjDbtLXL6EIQAAANw"], referer: https://villa-m-medjugorje.com/robots.txt
[Mon Jul 20 06:53:21.480458 2026] [security2:error] [pid 1033876:tid 1034101] [client 187.108.85.186:63471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aQUfjhWEjDbtLXL6EMAAAAOM"]
[Mon Jul 20 06:53:21.480595 2026] [security2:error] [pid 1033876:tid 1034101] [client 187.108.85.186:63471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aQUfjhWEjDbtLXL6EMAAAAOM"]
[Mon Jul 20 06:53:21.485814 2026] [security2:error] [pid 1033876:tid 1034121] [client 173.239.224.20:43809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4aQUfjhWEjDbtLXL6EKwAAAPc"]
[Mon Jul 20 06:53:21.495589 2026] [security2:error] [pid 1033876:tid 1034020] [client 117.247.108.24:1430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aQUfjhWEjDbtLXL6EMQAAAJI"]
[Mon Jul 20 06:53:21.495695 2026] [security2:error] [pid 1033876:tid 1034020] [client 117.247.108.24:1430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aQUfjhWEjDbtLXL6EMQAAAJI"]
[Mon Jul 20 06:53:21.583978 2026] [core:error] [pid 1033876:tid 1034082] [client 205.210.31.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:21.584009 2026] [core:error] [pid 1033876:tid 1034082] [client 205.210.31.138:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:21.842943 2026] [security2:error] [pid 1033876:tid 1034030] [client 161.118.218.103:64621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aQUfjhWEjDbtLXL6ETwAAAJw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:21.922137 2026] [security2:error] [pid 1033876:tid 1034125] [client 143.244.57.90:14125] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aQUfjhWEjDbtLXL6EVgAAAPs"]
[Mon Jul 20 06:53:22.194213 2026] [security2:error] [pid 1033876:tid 1034092] [client 45.157.112.60:53443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aQkfjhWEjDbtLXL6EcQAAANo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:53:22.225455 2026] [security2:error] [pid 1033876:tid 1034104] [client 143.244.57.90:25254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aQkfjhWEjDbtLXL6EcwAAAOY"]
[Mon Jul 20 06:53:22.246251 2026] [security2:error] [pid 1033876:tid 1034097] [client 185.191.141.115:53970] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4aQkfjhWEjDbtLXL6EdQAAAN8"]
[Mon Jul 20 06:53:22.349340 2026] [security2:error] [pid 1033876:tid 1034101] [client 104.234.53.91:56077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4aQkfjhWEjDbtLXL6EdAAAAOM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:22.421745 2026] [security2:error] [pid 1033876:tid 1034102] [client 161.118.218.103:64950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aQkfjhWEjDbtLXL6EgwAAAOQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:22.426441 2026] [security2:error] [pid 1033876:tid 1034065] [client 77.110.127.138:58890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aQUfjhWEjDbtLXL6EOwAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:22.448768 2026] [security2:error] [pid 1033876:tid 1034129] [client 14.225.17.146:54993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4aQkfjhWEjDbtLXL6EewAAAP8"], referer: http://ironcitywellness.com/wp-old
[Mon Jul 20 06:53:22.460298 2026] [security2:error] [pid 1033876:tid 1034080] [client 185.191.141.115:36240] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4aQkfjhWEjDbtLXL6EhgAAAM4"]
[Mon Jul 20 06:53:22.524370 2026] [security2:error] [pid 1033876:tid 1034106] [client 143.244.57.90:57298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aQkfjhWEjDbtLXL6EiQAAAOg"]
[Mon Jul 20 06:53:22.578071 2026] [security2:error] [pid 1033876:tid 1034019] [client 57.141.18.69:44362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aPEfjhWEjDbtLXL6CiQAAkTo"]
[Mon Jul 20 06:53:22.591959 2026] [security2:error] [pid 1033876:tid 1034070] [client 77.110.127.138:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aQkfjhWEjDbtLXL6ElgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:22.592064 2026] [security2:error] [pid 1033876:tid 1034070] [client 77.110.127.138:58896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aQkfjhWEjDbtLXL6ElgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:22.821994 2026] [security2:error] [pid 1033876:tid 1034075] [client 143.244.57.90:57302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4aQkfjhWEjDbtLXL6EuwAAAMk"]
[Mon Jul 20 06:53:23.003679 2026] [security2:error] [pid 1033876:tid 1034011] [client 161.118.218.103:65260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aQ0fjhWEjDbtLXL6E1gAAAIk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:23.120143 2026] [security2:error] [pid 1033876:tid 1034126] [client 143.244.57.90:57312] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aQ0fjhWEjDbtLXL6E3wAAAPw"]
[Mon Jul 20 06:53:23.171883 2026] [security2:error] [pid 1033876:tid 1034118] [client 104.234.53.91:56077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aQ0fjhWEjDbtLXL6E4gAAAPQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:23.248090 2026] [security2:error] [pid 1033876:tid 1034034] [client 77.110.127.138:58858] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aQ0fjhWEjDbtLXL6E5QAAAKA"]
[Mon Jul 20 06:53:23.419901 2026] [security2:error] [pid 1033876:tid 1034115] [client 143.244.57.90:46545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4aQ0fjhWEjDbtLXL6E8AAAAPE"]
[Mon Jul 20 06:53:23.486567 2026] [security2:error] [pid 1033876:tid 1033901] [remote 47.86.33.52:16198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4aQ0fjhWEjDbtLXL6E-wAA1xc"]
[Mon Jul 20 06:53:23.486823 2026] [security2:error] [pid 1033876:tid 1034089] [client 47.86.33.52:16198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4aQ0fjhWEjDbtLXL6E-wAA1xc"]
[Mon Jul 20 06:53:23.582305 2026] [security2:error] [pid 1033876:tid 1034046] [client 161.118.218.103:49313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aQ0fjhWEjDbtLXL6E_wAAAKw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:23.652067 2026] [fcgid:warn] [pid 1033876:tid 1034038] (70014)End of file found: [client 199.45.155.73:52988] mod_fcgid: can't get data from http client
[Mon Jul 20 06:53:23.702601 2026] [security2:error] [pid 1033876:tid 1034128] [client 183.82.98.154:54992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aQ0fjhWEjDbtLXL6FDgAAAP4"]
[Mon Jul 20 06:53:23.702707 2026] [security2:error] [pid 1033876:tid 1034128] [client 183.82.98.154:54992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aQ0fjhWEjDbtLXL6FDgAAAP4"]
[Mon Jul 20 06:53:23.712672 2026] [security2:error] [pid 1033876:tid 1034080] [client 143.244.57.90:57328] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aQ0fjhWEjDbtLXL6FEgAAAM4"]
[Mon Jul 20 06:53:24.011200 2026] [security2:error] [pid 1033876:tid 1034106] [client 143.244.57.90:20658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aREfjhWEjDbtLXL6FKgAAAOg"]
[Mon Jul 20 06:53:24.159922 2026] [security2:error] [pid 1033876:tid 1034016] [client 161.118.218.103:49716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aREfjhWEjDbtLXL6FOgAAAI4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:24.305812 2026] [security2:error] [pid 1033876:tid 1034106] [client 143.244.57.90:57348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aREfjhWEjDbtLXL6FSwAAAOg"]
[Mon Jul 20 06:53:24.603180 2026] [security2:error] [pid 1033876:tid 1034088] [client 143.244.57.90:57362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aREfjhWEjDbtLXL6FagAAANY"]
[Mon Jul 20 06:53:24.743860 2026] [security2:error] [pid 1033876:tid 1034091] [client 161.118.218.103:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aREfjhWEjDbtLXL6FdgAAANk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:24.779890 2026] [security2:error] [pid 1033876:tid 1034019] [client 14.225.17.146:63083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4aREfjhWEjDbtLXL6FbgAAAJE"], referer: http://christiancountytrumpet.com/wp-old
[Mon Jul 20 06:53:24.803308 2026] [security2:error] [pid 1033876:tid 1034070] [client 104.234.53.73:50065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aREfjhWEjDbtLXL6FdQAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:24.854092 2026] [security2:error] [pid 1033876:tid 1034046] [client 117.222.139.248:55462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aREfjhWEjDbtLXL6FgwAAAKw"]
[Mon Jul 20 06:53:24.854198 2026] [security2:error] [pid 1033876:tid 1034046] [client 117.222.139.248:55462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aREfjhWEjDbtLXL6FgwAAAKw"]
[Mon Jul 20 06:53:24.901642 2026] [security2:error] [pid 1033876:tid 1034059] [client 143.244.57.90:11523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4aREfjhWEjDbtLXL6FhgAAALk"]
[Mon Jul 20 06:53:25.096531 2026] [security2:error] [pid 1033876:tid 1034100] [client 104.234.53.73:50065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aRUfjhWEjDbtLXL6FlwAAAOI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:25.118518 2026] [security2:error] [pid 1033876:tid 1033987] [remote 74.235.96.117:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aRUfjhWEjDbtLXL6FmQAAoG0"]
[Mon Jul 20 06:53:25.190173 2026] [security2:error] [pid 1033876:tid 1033965] [remote 5.161.225.162:43074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aRUfjhWEjDbtLXL6FnwAAjlc"]
[Mon Jul 20 06:53:25.190388 2026] [security2:error] [pid 1033876:tid 1034016] [client 5.161.225.162:43074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aRUfjhWEjDbtLXL6FnwAAjlc"]
[Mon Jul 20 06:53:25.201858 2026] [security2:error] [pid 1033876:tid 1034050] [client 143.244.57.90:57376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4aRUfjhWEjDbtLXL6FogAAALA"]
[Mon Jul 20 06:53:25.322472 2026] [security2:error] [pid 1033876:tid 1034039] [client 161.118.218.103:50440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aRUfjhWEjDbtLXL6FqQAAAKU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:25.487085 2026] [security2:error] [pid 1033876:tid 1034069] [client 57.141.18.31:36856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aP0fjhWEjDbtLXL6DkwAAwyY"]
[Mon Jul 20 06:53:25.502950 2026] [security2:error] [pid 1033876:tid 1034070] [client 143.244.57.90:1205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4aRUfjhWEjDbtLXL6FuAAAAMQ"]
[Mon Jul 20 06:53:25.610509 2026] [security2:error] [pid 1033876:tid 1033969] [remote 74.235.96.117:49144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aRUfjhWEjDbtLXL6FvQAAvls"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:25.636293 2026] [security2:error] [pid 1033876:tid 1034057] [client 14.182.195.220:52422] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aRUfjhWEjDbtLXL6FwwAAALc"]
[Mon Jul 20 06:53:25.770593 2026] [security2:error] [pid 1033876:tid 1033972] [remote 91.142.222.105:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4aRUfjhWEjDbtLXL6FzQAAmF4"]
[Mon Jul 20 06:53:25.802100 2026] [security2:error] [pid 1033876:tid 1034062] [client 45.190.69.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4aQkfjhWEjDbtLXL6EwwAAALw"]
[Mon Jul 20 06:53:25.813033 2026] [security2:error] [pid 1033876:tid 1034129] [client 143.244.57.90:57398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aRUfjhWEjDbtLXL6F1AAAAP8"]
[Mon Jul 20 06:53:25.838149 2026] [security2:error] [pid 1033876:tid 1034090] [client 77.110.127.138:58918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aRUfjhWEjDbtLXL6F1QAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:25.838242 2026] [security2:error] [pid 1033876:tid 1034090] [client 77.110.127.138:58918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aRUfjhWEjDbtLXL6F1QAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:25.896075 2026] [security2:error] [pid 1033876:tid 1034122] [client 152.58.191.29:62937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aRUfjhWEjDbtLXL6F3wAAAPg"]
[Mon Jul 20 06:53:25.896207 2026] [security2:error] [pid 1033876:tid 1034122] [client 152.58.191.29:62937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aRUfjhWEjDbtLXL6F3wAAAPg"]
[Mon Jul 20 06:53:25.896678 2026] [security2:error] [pid 1033876:tid 1034128] [client 161.118.218.103:50821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aRUfjhWEjDbtLXL6F4AAAAP4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:26.011235 2026] [security2:error] [pid 1033876:tid 1033883] [remote 91.142.222.105:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4aRkfjhWEjDbtLXL6F6wAAjQU"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:53:26.111324 2026] [security2:error] [pid 1033876:tid 1034055] [client 143.244.57.90:57404] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.north-woods-engineering.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4aRkfjhWEjDbtLXL6F7wAAALU"]
[Mon Jul 20 06:53:26.330026 2026] [security2:error] [pid 1033876:tid 1034105] [client 122.183.32.225:9552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aRkfjhWEjDbtLXL6F_gAAAOc"]
[Mon Jul 20 06:53:26.330141 2026] [security2:error] [pid 1033876:tid 1034105] [client 122.183.32.225:9552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aRkfjhWEjDbtLXL6F_gAAAOc"]
[Mon Jul 20 06:53:26.472250 2026] [security2:error] [pid 1033876:tid 1034018] [client 161.118.218.103:51183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aRkfjhWEjDbtLXL6GCgAAAJA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:26.514531 2026] [security2:error] [pid 1033876:tid 1034021] [client 14.225.17.146:49473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4aQkfjhWEjDbtLXL6EvAAAAJM"], referer: http://areitoproducciones.com/wp-old
[Mon Jul 20 06:53:26.556090 2026] [security2:error] [pid 1033876:tid 1034050] [client 14.224.227.113:54768] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aRkfjhWEjDbtLXL6GEwAAALA"]
[Mon Jul 20 06:53:26.787176 2026] [security2:error] [pid 1033876:tid 1034128] [client 14.225.17.146:55428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4aRkfjhWEjDbtLXL6GGgAAAP4"], referer: https://north-woods-engineering.com/wp-old
[Mon Jul 20 06:53:27.061776 2026] [security2:error] [pid 1033876:tid 1034055] [client 98.159.234.160:36903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aR0fjhWEjDbtLXL6GQwAAALU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:53:27.064506 2026] [security2:error] [pid 1033876:tid 1034097] [client 161.118.218.103:51586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aR0fjhWEjDbtLXL6GRAAAAN8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:27.452079 2026] [security2:error] [pid 1033876:tid 1033904] [remote 97.74.87.194:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aR0fjhWEjDbtLXL6GWAAAyxo"]
[Mon Jul 20 06:53:27.452272 2026] [security2:error] [pid 1033876:tid 1034077] [client 97.74.87.194:54356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aR0fjhWEjDbtLXL6GWAAAyxo"]
[Mon Jul 20 06:53:27.470409 2026] [security2:error] [pid 1033876:tid 1034100] [client 46.110.96.34:11203] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4aR0fjhWEjDbtLXL6GWwAAAOI"]
[Mon Jul 20 06:53:27.658093 2026] [security2:error] [pid 1033876:tid 1034113] [client 161.118.218.103:51990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aR0fjhWEjDbtLXL6GZgAAAO8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:27.977236 2026] [security2:error] [pid 1033876:tid 1034046] [client 217.142.18.172:54083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aR0fjhWEjDbtLXL6GhgAAAKw"]
[Mon Jul 20 06:53:27.984894 2026] [security2:error] [pid 1033876:tid 1034046] [client 217.142.18.172:54083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aR0fjhWEjDbtLXL6GhgAAAKw"]
[Mon Jul 20 06:53:28.042815 2026] [security2:error] [pid 1033876:tid 1033958] [remote 152.228.213.32:52970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4aSEfjhWEjDbtLXL6GkAAAjFA"]
[Mon Jul 20 06:53:28.246256 2026] [security2:error] [pid 1033876:tid 1034114] [client 161.118.218.103:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aSEfjhWEjDbtLXL6GnQAAAPA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:28.262109 2026] [security2:error] [pid 1033876:tid 1033930] [remote 152.228.213.32:52970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4aSEfjhWEjDbtLXL6GngAAwjQ"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 06:53:28.294221 2026] [security2:error] [pid 1033876:tid 1034043] [client 14.225.17.146:54792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4aR0fjhWEjDbtLXL6GgwAAAKk"], referer: http://adastra.love/wp-old
[Mon Jul 20 06:53:28.352914 2026] [security2:error] [pid 1033876:tid 1034127] [client 14.225.17.146:54545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4aR0fjhWEjDbtLXL6GewAAAP0"], referer: http://idigress.group/wp-old
[Mon Jul 20 06:53:28.410946 2026] [security2:error] [pid 1033876:tid 1034090] [client 49.13.134.145:33720] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4aSEfjhWEjDbtLXL6GoQAAANg"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:53:28.469869 2026] [security2:error] [pid 1033876:tid 1033949] [remote 160.187.68.132:34440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aSEfjhWEjDbtLXL6GtwAAq0c"]
[Mon Jul 20 06:53:28.470057 2026] [security2:error] [pid 1033876:tid 1034045] [client 160.187.68.132:34440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aSEfjhWEjDbtLXL6GtwAAq0c"]
[Mon Jul 20 06:53:28.524085 2026] [security2:error] [pid 1033876:tid 1034007] [client 65.1.132.125:35450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4aSEfjhWEjDbtLXL6GuQAAAIU"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:53:28.584274 2026] [security2:error] [pid 1033876:tid 1033927] [remote 42.200.84.61:54014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4aSEfjhWEjDbtLXL6GwgAA6jE"]
[Mon Jul 20 06:53:28.714917 2026] [security2:error] [pid 1033876:tid 1034098] [client 46.110.96.34:22279] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4aSEfjhWEjDbtLXL6G0AAAAOA"]
[Mon Jul 20 06:53:28.769135 2026] [security2:error] [pid 1033876:tid 1033986] [remote 18.61.192.253:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4aSEfjhWEjDbtLXL6G0gABBGw"]
[Mon Jul 20 06:53:28.834636 2026] [security2:error] [pid 1033876:tid 1034080] [client 161.118.218.103:52861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aSEfjhWEjDbtLXL6G1wAAAM4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:28.896418 2026] [security2:error] [pid 1033876:tid 1034023] [client 57.141.18.47:51742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aQ0fjhWEjDbtLXL6E9QAAlTc"]
[Mon Jul 20 06:53:29.125840 2026] [security2:error] [pid 1033876:tid 1033947] [remote 42.200.84.61:54014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6G9AAAl0U"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:53:29.209072 2026] [security2:error] [pid 1033876:tid 1033982] [remote 18.61.192.253:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6G-AAA92g"], referer: https://website-e4de5cd0.epu.kzx.mybluehost.me/wp/wp-login.php
[Mon Jul 20 06:53:29.209422 2026] [security2:error] [pid 1033876:tid 1033891] [remote 124.55.178.99:58790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6G-QAAsQ0"]
[Mon Jul 20 06:53:29.267685 2026] [security2:error] [pid 1033876:tid 1034031] [client 46.110.96.34:26705] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4aSUfjhWEjDbtLXL6G_QAAAJ0"]
[Mon Jul 20 06:53:29.409893 2026] [security2:error] [pid 1033876:tid 1034119] [client 161.118.218.103:53302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aSUfjhWEjDbtLXL6HBQAAAPU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:29.627951 2026] [security2:error] [pid 1033876:tid 1033878] [remote 100.42.189.89:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6HFwAAswA"]
[Mon Jul 20 06:53:29.639377 2026] [security2:error] [pid 1033876:tid 1033886] [remote 124.55.178.99:58790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6HGgAAxwg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:53:29.651953 2026] [ssl:error] [pid 1033876:tid 1034011] [client 104.48.69.105:38602] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:53:29.863292 2026] [security2:error] [pid 1033876:tid 1034001] [remote 100.42.189.89:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6HNAAA5Hs"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:53:29.987608 2026] [security2:error] [pid 1033876:tid 1034036] [client 161.118.218.103:53717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aSUfjhWEjDbtLXL6HQQAAAKI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:30.468408 2026] [security2:error] [pid 1033876:tid 1034113] [client 50.116.65.227:27920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4aSkfjhWEjDbtLXL6HVwAAAO8"]
[Mon Jul 20 06:53:30.540135 2026] [core:error] [pid 1033876:tid 1034036] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.540157 2026] [core:error] [pid 1033876:tid 1034036] [client 94.154.43.187:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.556090 2026] [core:error] [pid 1033876:tid 1034016] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.556112 2026] [core:error] [pid 1033876:tid 1034016] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.558839 2026] [core:error] [pid 1033876:tid 1034118] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.558864 2026] [core:error] [pid 1033876:tid 1034118] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.562169 2026] [security2:error] [pid 1033876:tid 1034110] [client 161.118.218.103:54151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aSkfjhWEjDbtLXL6HegAAAOw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:30.577349 2026] [core:error] [pid 1033876:tid 1034055] [client 94.154.43.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.577382 2026] [core:error] [pid 1033876:tid 1034055] [client 94.154.43.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.580152 2026] [core:error] [pid 1033876:tid 1034039] [client 94.154.43.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.580170 2026] [core:error] [pid 1033876:tid 1034039] [client 94.154.43.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:30.605696 2026] [security2:error] [pid 1033876:tid 1034057] [client 216.24.212.30:24215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4aSkfjhWEjDbtLXL6HhwAAALc"]
[Mon Jul 20 06:53:30.613135 2026] [security2:error] [pid 1033876:tid 1034112] [client 216.24.212.42:56797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4aSkfjhWEjDbtLXL6HhAAAAO4"]
[Mon Jul 20 06:53:30.664499 2026] [security2:error] [pid 1033876:tid 1034087] [client 50.116.65.227:27934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4aSkfjhWEjDbtLXL6HZgAAANU"]
[Mon Jul 20 06:53:30.894520 2026] [security2:error] [pid 1033876:tid 1034094] [client 103.238.106.162:42848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aSkfjhWEjDbtLXL6HnQAAANw"]
[Mon Jul 20 06:53:30.894621 2026] [security2:error] [pid 1033876:tid 1034094] [client 103.238.106.162:42848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aSkfjhWEjDbtLXL6HnQAAANw"]
[Mon Jul 20 06:53:30.977317 2026] [security2:error] [pid 1033876:tid 1033900] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aSkfjhWEjDbtLXL6HoQAA_RY"]
[Mon Jul 20 06:53:30.977478 2026] [security2:error] [pid 1033876:tid 1034127] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aSkfjhWEjDbtLXL6HoQAA_RY"]
[Mon Jul 20 06:53:31.135025 2026] [security2:error] [pid 1033876:tid 1034093] [client 161.118.218.103:54565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aS0fjhWEjDbtLXL6HswAAANs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:31.169889 2026] [security2:error] [pid 1033876:tid 1034050] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4aSkfjhWEjDbtLXL6HjQAAsGA"], referer: http://ardhalwafaa.com/wp-old
[Mon Jul 20 06:53:31.240909 2026] [security2:error] [pid 1033876:tid 1034060] [client 77.110.127.138:58931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aS0fjhWEjDbtLXL6HugAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:31.240995 2026] [security2:error] [pid 1033876:tid 1034060] [client 77.110.127.138:58931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aS0fjhWEjDbtLXL6HugAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:31.479896 2026] [security2:error] [pid 1033876:tid 1034110] [client 74.208.214.194:36642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4aS0fjhWEjDbtLXL6H0AAAAOw"]
[Mon Jul 20 06:53:31.514086 2026] [security2:error] [pid 1033876:tid 1034118] [client 103.125.179.95:60596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aS0fjhWEjDbtLXL6H0gAAAPQ"]
[Mon Jul 20 06:53:31.514237 2026] [security2:error] [pid 1033876:tid 1034118] [client 103.125.179.95:60596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aS0fjhWEjDbtLXL6H0gAAAPQ"]
[Mon Jul 20 06:53:31.588087 2026] [security2:error] [pid 1033876:tid 1034121] [client 77.110.127.138:58932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aS0fjhWEjDbtLXL6HyQAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:31.719289 2026] [security2:error] [pid 1033876:tid 1034038] [client 161.118.218.103:55069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aS0fjhWEjDbtLXL6H4wAAAKQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:31.902806 2026] [security2:error] [pid 1033876:tid 1034086] [client 14.225.17.146:52707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4aS0fjhWEjDbtLXL6H5QAAANQ"], referer: http://colinkeyphotography.com/wp-old
[Mon Jul 20 06:53:32.122133 2026] [security2:error] [pid 1033876:tid 1034106] [client 187.108.85.186:64145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aTEfjhWEjDbtLXL6IHwAAAOg"]
[Mon Jul 20 06:53:32.122840 2026] [security2:error] [pid 1033876:tid 1034106] [client 187.108.85.186:64145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aTEfjhWEjDbtLXL6IHwAAAOg"]
[Mon Jul 20 06:53:32.198880 2026] [security2:error] [pid 1033876:tid 1034120] [client 197.186.66.42:51014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aTEfjhWEjDbtLXL6IJgAAAPY"]
[Mon Jul 20 06:53:32.201296 2026] [security2:error] [pid 1033876:tid 1034120] [client 197.186.66.42:51014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aTEfjhWEjDbtLXL6IJgAAAPY"]
[Mon Jul 20 06:53:32.314385 2026] [security2:error] [pid 1033876:tid 1034088] [client 161.118.218.103:55522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aTEfjhWEjDbtLXL6ILwAAANY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:32.427640 2026] [security2:error] [pid 1033876:tid 1034116] [client 117.247.108.24:34305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aTEfjhWEjDbtLXL6IQwAAAPI"]
[Mon Jul 20 06:53:32.427730 2026] [security2:error] [pid 1033876:tid 1034116] [client 117.247.108.24:34305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aTEfjhWEjDbtLXL6IQwAAAPI"]
[Mon Jul 20 06:53:32.737965 2026] [core:error] [pid 1033876:tid 1034128] [client 14.225.17.146:51163] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wp-old
[Mon Jul 20 06:53:32.737993 2026] [core:error] [pid 1033876:tid 1034128] [client 14.225.17.146:51163] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/wp-old
[Mon Jul 20 06:53:32.887422 2026] [security2:error] [pid 1033876:tid 1034102] [client 161.118.218.103:55996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aTEfjhWEjDbtLXL6IZgAAAOQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:32.966405 2026] [security2:error] [pid 1033876:tid 1033886] [remote 192.241.143.148:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4aTEfjhWEjDbtLXL6IbAAA-Ag"]
[Mon Jul 20 06:53:32.981053 2026] [security2:error] [pid 1033876:tid 1034010] [client 134.122.94.138:59947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aTEfjhWEjDbtLXL6IcAAAAIg"]
[Mon Jul 20 06:53:32.982366 2026] [security2:error] [pid 1033876:tid 1034007] [client 134.122.94.138:59948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aTEfjhWEjDbtLXL6IcQAAAIU"]
[Mon Jul 20 06:53:33.136980 2026] [security2:error] [pid 1033876:tid 1033881] [remote 72.167.132.114:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aTUfjhWEjDbtLXL6IeQAAjQM"]
[Mon Jul 20 06:53:33.146066 2026] [security2:error] [pid 1033876:tid 1033931] [remote 160.187.68.132:56140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aTUfjhWEjDbtLXL6IfwABAzU"]
[Mon Jul 20 06:53:33.146211 2026] [security2:error] [pid 1033876:tid 1034133] [client 160.187.68.132:56140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aTUfjhWEjDbtLXL6IfwABAzU"]
[Mon Jul 20 06:53:33.175259 2026] [security2:error] [pid 1033876:tid 1033969] [remote 192.241.143.148:59422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4aTUfjhWEjDbtLXL6IggAA3Fs"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 06:53:33.334197 2026] [security2:error] [pid 1033876:tid 1034097] [client 14.225.17.146:52657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4aTEfjhWEjDbtLXL6IMwAAAN8"]
[Mon Jul 20 06:53:33.381389 2026] [security2:error] [pid 1033876:tid 1033994] [remote 72.167.132.114:60014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aTUfjhWEjDbtLXL6IjAAAnHQ"], referer: https://mail.idf.ldc.mybluehost.me/wp-login.php
[Mon Jul 20 06:53:33.439021 2026] [security2:error] [pid 1033876:tid 1034113] [client 134.122.94.138:60189] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aTUfjhWEjDbtLXL6IjwAAAO8"]
[Mon Jul 20 06:53:33.439971 2026] [security2:error] [pid 1033876:tid 1034076] [client 134.122.94.138:60195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aTUfjhWEjDbtLXL6IkQAAAMo"]
[Mon Jul 20 06:53:33.462740 2026] [security2:error] [pid 1033876:tid 1034121] [client 161.118.218.103:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aTUfjhWEjDbtLXL6IlQAAAPc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:33.826723 2026] [security2:error] [pid 1033876:tid 1034119] [client 104.234.53.93:25901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4aTUfjhWEjDbtLXL6IsAAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:33.914185 2026] [security2:error] [pid 1033876:tid 1034100] [client 134.122.94.138:60663] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aTUfjhWEjDbtLXL6ItAAAAOI"]
[Mon Jul 20 06:53:33.915001 2026] [security2:error] [pid 1033876:tid 1034041] [client 134.122.94.138:60658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aTUfjhWEjDbtLXL6ItQAAAKc"]
[Mon Jul 20 06:53:34.053883 2026] [security2:error] [pid 1033876:tid 1034094] [client 161.118.218.103:56958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aTkfjhWEjDbtLXL6IywAAANw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:34.381003 2026] [security2:error] [pid 1033876:tid 1034124] [client 134.122.94.138:61140] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aTkfjhWEjDbtLXL6I5AAAAPo"]
[Mon Jul 20 06:53:34.381451 2026] [security2:error] [pid 1033876:tid 1034110] [client 134.122.94.138:61138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aTkfjhWEjDbtLXL6I5QAAAOw"]
[Mon Jul 20 06:53:34.556198 2026] [security2:error] [pid 1033876:tid 1034105] [client 57.141.18.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4aTEfjhWEjDbtLXL6INAAAAOc"]
[Mon Jul 20 06:53:34.636794 2026] [security2:error] [pid 1033876:tid 1034062] [client 161.118.218.103:57432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aTkfjhWEjDbtLXL6I-gAAALw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:34.808478 2026] [security2:error] [pid 1033876:tid 1034052] [client 14.225.17.146:53092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4aTkfjhWEjDbtLXL6I-AAAALI"], referer: http://oldracelimited.com/wp-old
[Mon Jul 20 06:53:34.842021 2026] [security2:error] [pid 1033876:tid 1034116] [client 134.122.94.138:61593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aTkfjhWEjDbtLXL6JDAAAAPI"]
[Mon Jul 20 06:53:34.864309 2026] [security2:error] [pid 1033876:tid 1034120] [client 134.122.94.138:61594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aTkfjhWEjDbtLXL6JEAAAAPY"]
[Mon Jul 20 06:53:35.169061 2026] [proxy:error] [pid 1033876:tid 1034083] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:35.169143 2026] [proxy_http:error] [pid 1033876:tid 1034083] [client 34.73.38.214:50590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:35.169853 2026] [proxy:error] [pid 1033876:tid 1034083] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:35.169885 2026] [proxy_http:error] [pid 1033876:tid 1034083] [client 34.73.38.214:50590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:35.214018 2026] [security2:error] [pid 1033876:tid 1034068] [client 161.118.218.103:57847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aT0fjhWEjDbtLXL6JMAAAAMI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:35.321728 2026] [security2:error] [pid 1033876:tid 1034088] [client 134.122.94.138:62205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aT0fjhWEjDbtLXL6JPwAAANY"]
[Mon Jul 20 06:53:35.321876 2026] [security2:error] [pid 1033876:tid 1034104] [client 134.122.94.138:62187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aT0fjhWEjDbtLXL6JQAAAAOY"]
[Mon Jul 20 06:53:35.376569 2026] [security2:error] [pid 1033876:tid 1034111] [client 117.222.139.248:55936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aT0fjhWEjDbtLXL6JSgAAAO0"]
[Mon Jul 20 06:53:35.376682 2026] [security2:error] [pid 1033876:tid 1034111] [client 117.222.139.248:55936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aT0fjhWEjDbtLXL6JSgAAAO0"]
[Mon Jul 20 06:53:35.422021 2026] [security2:error] [pid 1033876:tid 1033953] [remote 103.90.234.13:58428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JTAAAkUs"]
[Mon Jul 20 06:53:35.463771 2026] [security2:error] [pid 1033876:tid 1033971] [remote 15.206.251.117:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JWQAA_V0"]
[Mon Jul 20 06:53:35.478112 2026] [security2:error] [pid 1033876:tid 1034007] [client 14.225.17.146:52602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4aTUfjhWEjDbtLXL6IsgAAAIU"], referer: http://guidehunting.com/wp-old
[Mon Jul 20 06:53:35.549442 2026] [security2:error] [pid 1033876:tid 1034043] [client 77.110.127.138:58944] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 619 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aT0fjhWEjDbtLXL6JYAAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:35.654852 2026] [security2:error] [pid 1033876:tid 1033927] [remote 154.66.198.148:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JZQAAnzE"]
[Mon Jul 20 06:53:35.666881 2026] [security2:error] [pid 1033876:tid 1034124] [client 104.207.50.210:23553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JZgAAAPo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:53:35.701066 2026] [security2:error] [pid 1033876:tid 1034066] [client 77.110.127.138:58945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aT0fjhWEjDbtLXL6JaQAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:35.701138 2026] [security2:error] [pid 1033876:tid 1034066] [client 77.110.127.138:58945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aT0fjhWEjDbtLXL6JaQAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:35.708998 2026] [security2:error] [pid 1033876:tid 1033935] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.env"] [unique_id "al4aT0fjhWEjDbtLXL6JagABAjk"]
[Mon Jul 20 06:53:35.709709 2026] [security2:error] [pid 1033876:tid 1033950] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.jeffjaeger.com"] [uri "/.git-credentials"] [unique_id "al4aT0fjhWEjDbtLXL6JbwABAkg"]
[Mon Jul 20 06:53:35.771033 2026] [security2:error] [pid 1033876:tid 1034051] [client 134.122.94.138:62548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aT0fjhWEjDbtLXL6JcwAAALE"]
[Mon Jul 20 06:53:35.772202 2026] [security2:error] [pid 1033876:tid 1034128] [client 134.122.94.138:62540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aT0fjhWEjDbtLXL6JdAAAAP4"]
[Mon Jul 20 06:53:35.797366 2026] [security2:error] [pid 1033876:tid 1034087] [client 161.118.218.103:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JeQAAANU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:35.866211 2026] [security2:error] [pid 1033876:tid 1033988] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/rclone.conf"] [unique_id "al4aT0fjhWEjDbtLXL6JfgABAm4"]
[Mon Jul 20 06:53:35.906374 2026] [security2:error] [pid 1033876:tid 1034042] [client 77.110.127.138:58947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aT0fjhWEjDbtLXL6JmQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:35.906475 2026] [security2:error] [pid 1033876:tid 1034042] [client 77.110.127.138:58947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aT0fjhWEjDbtLXL6JmQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:35.919601 2026] [security2:error] [pid 1033876:tid 1033969] [remote 192.241.143.148:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JmgAA11s"]
[Mon Jul 20 06:53:35.945978 2026] [security2:error] [pid 1033876:tid 1034001] [remote 160.187.68.132:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aT0fjhWEjDbtLXL6JngAA-3s"]
[Mon Jul 20 06:53:36.068581 2026] [security2:error] [pid 1033876:tid 1034120] [client 77.110.127.138:58946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aT0fjhWEjDbtLXL6JewAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.122460 2026] [security2:error] [pid 1033876:tid 1033932] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/.env.example"] [unique_id "al4aUEfjhWEjDbtLXL6J2wABAjY"]
[Mon Jul 20 06:53:36.122570 2026] [security2:error] [pid 1033876:tid 1033898] [remote 192.241.143.148:45598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aUEfjhWEjDbtLXL6J3AAAvxQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:53:36.211244 2026] [security2:error] [pid 1033876:tid 1033942] [remote 154.66.198.148:4522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4aUEfjhWEjDbtLXL6J5wAA-UA"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:53:36.217059 2026] [security2:error] [pid 1033876:tid 1034059] [client 45.3.42.236:51563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aUEfjhWEjDbtLXL6J4gAAALk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:53:36.227309 2026] [security2:error] [pid 1033876:tid 1034014] [client 134.122.94.138:62951] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aUEfjhWEjDbtLXL6J6QAAAIw"]
[Mon Jul 20 06:53:36.227694 2026] [security2:error] [pid 1033876:tid 1034067] [client 134.122.94.138:62946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aUEfjhWEjDbtLXL6J6gAAAME"]
[Mon Jul 20 06:53:36.245943 2026] [security2:error] [pid 1033876:tid 1033977] [remote 15.206.251.117:56844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4aUEfjhWEjDbtLXL6J7gAA9GM"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 06:53:36.264121 2026] [security2:error] [pid 1033876:tid 1034017] [client 77.110.127.138:58948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUEfjhWEjDbtLXL6J7wAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.264211 2026] [security2:error] [pid 1033876:tid 1034017] [client 77.110.127.138:58948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUEfjhWEjDbtLXL6J7wAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.362862 2026] [security2:error] [pid 1033876:tid 1034015] [client 57.141.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aUEfjhWEjDbtLXL6J6wAAAI0"]
[Mon Jul 20 06:53:36.374850 2026] [security2:error] [pid 1033876:tid 1034113] [client 161.118.218.103:58798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aUEfjhWEjDbtLXL6J-gAAAO8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:36.404153 2026] [security2:error] [pid 1033876:tid 1033953] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.env.old"] [unique_id "al4aUEfjhWEjDbtLXL6J_AABAks"]
[Mon Jul 20 06:53:36.421671 2026] [security2:error] [pid 1033876:tid 1034094] [client 77.110.127.138:58950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUEfjhWEjDbtLXL6J_gAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.421800 2026] [security2:error] [pid 1033876:tid 1034094] [client 77.110.127.138:58950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUEfjhWEjDbtLXL6J_gAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.462159 2026] [security2:error] [pid 1033876:tid 1034131] [client 152.58.191.29:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aUEfjhWEjDbtLXL6KAwAAAQE"]
[Mon Jul 20 06:53:36.462290 2026] [security2:error] [pid 1033876:tid 1034131] [client 152.58.191.29:63377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aUEfjhWEjDbtLXL6KAwAAAQE"]
[Mon Jul 20 06:53:36.482126 2026] [security2:error] [pid 1033876:tid 1033909] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.env.backup"] [unique_id "al4aUEfjhWEjDbtLXL6KCQABAh8"]
[Mon Jul 20 06:53:36.482148 2026] [security2:error] [pid 1033876:tid 1033993] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4aUEfjhWEjDbtLXL6KCwABAnM"]
[Mon Jul 20 06:53:36.566968 2026] [proxy:error] [pid 1033876:tid 1034120] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:36.567064 2026] [proxy_http:error] [pid 1033876:tid 1034120] [client 34.73.38.214:49240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:36.568100 2026] [proxy:error] [pid 1033876:tid 1034120] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:36.568149 2026] [proxy_http:error] [pid 1033876:tid 1034120] [client 34.73.38.214:49240] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:36.597089 2026] [security2:error] [pid 1033876:tid 1034020] [client 14.225.17.146:62596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4aUEfjhWEjDbtLXL6J9QAAAJI"], referer: https://guidehunting.com/wp-old
[Mon Jul 20 06:53:36.708462 2026] [security2:error] [pid 1033876:tid 1034075] [client 134.122.94.138:63394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aUEfjhWEjDbtLXL6KHgAAAMk"]
[Mon Jul 20 06:53:36.710087 2026] [security2:error] [pid 1033876:tid 1034072] [client 134.122.94.138:63418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aUEfjhWEjDbtLXL6KHwAAAMY"]
[Mon Jul 20 06:53:36.724245 2026] [security2:error] [pid 1033876:tid 1034040] [client 14.225.17.146:62604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4aUEfjhWEjDbtLXL6J8QAAAKY"], referer: http://partnerselectricalllc.com/wp-old
[Mon Jul 20 06:53:36.731540 2026] [security2:error] [pid 1033876:tid 1034048] [client 103.47.54.187:46227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4aUEfjhWEjDbtLXL6KIwAAAK4"], referer: https://recruitinginsight.us/subscribe/
[Mon Jul 20 06:53:36.731566 2026] [security2:error] [pid 1033876:tid 1034048] [client 103.47.54.187:46227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4aUEfjhWEjDbtLXL6KIwAAAK4"], referer: https://recruitinginsight.us/subscribe/
[Mon Jul 20 06:53:36.750032 2026] [security2:error] [pid 1033876:tid 1034010] [client 45.3.42.60:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aUEfjhWEjDbtLXL6KJAAAAIg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:53:36.924259 2026] [security2:error] [pid 1033876:tid 1034098] [client 77.110.127.138:58951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUEfjhWEjDbtLXL6KPAAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.924378 2026] [security2:error] [pid 1033876:tid 1034098] [client 77.110.127.138:58951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUEfjhWEjDbtLXL6KPAAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:36.948786 2026] [security2:error] [pid 1033876:tid 1034002] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/config/.env"] [unique_id "al4aUEfjhWEjDbtLXL6KRAABAnw"]
[Mon Jul 20 06:53:36.984071 2026] [security2:error] [pid 1033876:tid 1034032] [client 43.130.0.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4aUEfjhWEjDbtLXL6KNAAAnmc"], referer: https://www.aleishapenny.ca/listing/page/1346?paged=1&view=grid&posts_per_page=24
[Mon Jul 20 06:53:37.027053 2026] [ssl:error] [pid 1033876:tid 1034055] [client 104.48.69.105:38618] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:53:37.102896 2026] [security2:error] [pid 1033876:tid 1033985] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/secrets.yml"] [unique_id "al4aUUfjhWEjDbtLXL6KWAAA42s"]
[Mon Jul 20 06:53:37.103611 2026] [security2:error] [pid 1033876:tid 1033995] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/backend/.env"] [unique_id "al4aUUfjhWEjDbtLXL6KVwAA43U"]
[Mon Jul 20 06:53:37.104390 2026] [security2:error] [pid 1033876:tid 1033881] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/api/.env"] [unique_id "al4aUUfjhWEjDbtLXL6KWQAA4wM"]
[Mon Jul 20 06:53:37.159310 2026] [security2:error] [pid 1033876:tid 1034099] [client 77.110.127.138:58952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aUUfjhWEjDbtLXL6KXgAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:37.169392 2026] [security2:error] [pid 1033876:tid 1034047] [client 134.122.94.138:63879] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aUUfjhWEjDbtLXL6KYQAAAK0"]
[Mon Jul 20 06:53:37.170010 2026] [security2:error] [pid 1033876:tid 1034062] [client 134.122.94.138:63878] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aUUfjhWEjDbtLXL6KYwAAALw"]
[Mon Jul 20 06:53:37.447378 2026] [security2:error] [pid 1033876:tid 1033885] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/key.json"] [unique_id "al4aUUfjhWEjDbtLXL6KhAAAvgc"]
[Mon Jul 20 06:53:37.483920 2026] [security2:error] [pid 1033876:tid 1034126] [client 77.110.127.138:58954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUUfjhWEjDbtLXL6KiwAAAPw"]
[Mon Jul 20 06:53:37.484048 2026] [security2:error] [pid 1033876:tid 1034126] [client 77.110.127.138:58954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUUfjhWEjDbtLXL6KiwAAAPw"]
[Mon Jul 20 06:53:37.569031 2026] [security2:error] [pid 1033876:tid 1033917] [remote 160.187.68.132:44072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aUUfjhWEjDbtLXL6KkAAAtyc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:53:37.620701 2026] [security2:error] [pid 1033876:tid 1034032] [client 134.122.94.138:64470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aUUfjhWEjDbtLXL6KlQAAAJ4"]
[Mon Jul 20 06:53:37.621169 2026] [security2:error] [pid 1033876:tid 1034117] [client 134.122.94.138:64468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aUUfjhWEjDbtLXL6KlgAAAPM"]
[Mon Jul 20 06:53:37.643516 2026] [proxy:error] [pid 1033876:tid 1034106] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:37.643581 2026] [proxy_http:error] [pid 1033876:tid 1034106] [client 34.73.38.214:59305] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:37.644690 2026] [proxy:error] [pid 1033876:tid 1034106] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:37.644733 2026] [proxy_http:error] [pid 1033876:tid 1034106] [client 34.73.38.214:59305] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:37.709437 2026] [security2:error] [pid 1033876:tid 1034129] [client 104.234.53.90:40561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4aUUfjhWEjDbtLXL6KlAAAAP8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:37.840837 2026] [security2:error] [pid 1033876:tid 1034114] [client 77.110.127.138:58955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUUfjhWEjDbtLXL6KrwAAAPA"]
[Mon Jul 20 06:53:37.840917 2026] [security2:error] [pid 1033876:tid 1034114] [client 77.110.127.138:58955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aUUfjhWEjDbtLXL6KrwAAAPA"]
[Mon Jul 20 06:53:37.974916 2026] [ssl:error] [pid 1033876:tid 1034094] [client 104.48.69.105:38620] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:53:38.019237 2026] [security2:error] [pid 1033876:tid 1034075] [client 14.225.17.146:53208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4aUUfjhWEjDbtLXL6KswAAAMk"], referer: http://mcg.homes/wp-old
[Mon Jul 20 06:53:38.073275 2026] [security2:error] [pid 1033876:tid 1034077] [client 134.122.94.138:64922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aUkfjhWEjDbtLXL6KwgAAAMs"]
[Mon Jul 20 06:53:38.073525 2026] [security2:error] [pid 1033876:tid 1034074] [client 134.122.94.138:64921] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aUkfjhWEjDbtLXL6KwwAAAMg"]
[Mon Jul 20 06:53:38.074596 2026] [security2:error] [pid 1033876:tid 1034045] [client 114.119.141.112:34743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/affiliate_signup.asp"] [unique_id "al4aUkfjhWEjDbtLXL6KxAAAAKs"], referer: https://www.sarakety.com/login_sendpass.asp
[Mon Jul 20 06:53:38.221363 2026] [security2:error] [pid 1033876:tid 1033989] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.jeffjaeger.com"] [uri "/graphql"] [unique_id "al4aUkfjhWEjDbtLXL6KzgAAwG8"]
[Mon Jul 20 06:53:38.241029 2026] [authz_core:error] [pid 1033876:tid 1033895] [remote 34.156.104.72:43310] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 06:53:38.283225 2026] [security2:error] [pid 1033876:tid 1034081] [client 104.234.53.90:40561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aUkfjhWEjDbtLXL6K3gAAAM8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:38.338147 2026] [security2:error] [pid 1033876:tid 1034068] [client 217.142.18.172:2713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aUkfjhWEjDbtLXL6K4gAAAMI"]
[Mon Jul 20 06:53:38.349273 2026] [security2:error] [pid 1033876:tid 1034068] [client 217.142.18.172:2713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aUkfjhWEjDbtLXL6K4gAAAMI"]
[Mon Jul 20 06:53:38.425212 2026] [security2:error] [pid 1033876:tid 1034088] [client 134.122.94.138:65365] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aUkfjhWEjDbtLXL6K5wAAANY"]
[Mon Jul 20 06:53:38.426573 2026] [security2:error] [pid 1033876:tid 1034128] [client 134.122.94.138:65370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aUkfjhWEjDbtLXL6K6AAAAP4"]
[Mon Jul 20 06:53:38.490785 2026] [security2:error] [pid 1033876:tid 1034119] [client 34.73.38.214:60569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aUkfjhWEjDbtLXL6K8wAAAPU"]
[Mon Jul 20 06:53:38.683940 2026] [security2:error] [pid 1033876:tid 1033967] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.jeffjaeger.com"] [uri "/api/graphql"] [unique_id "al4aUkfjhWEjDbtLXL6LAgAArlk"]
[Mon Jul 20 06:53:38.708159 2026] [security2:error] [pid 1033876:tid 1033979] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.ssh/id_rsa"] [unique_id "al4aUkfjhWEjDbtLXL6LCgAArmU"]
[Mon Jul 20 06:53:38.708262 2026] [security2:error] [pid 1033876:tid 1033962] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.ssh/id_dsa"] [unique_id "al4aUkfjhWEjDbtLXL6LCQAArlQ"]
[Mon Jul 20 06:53:38.727278 2026] [security2:error] [pid 1033876:tid 1034109] [client 134.122.94.138:49383] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aUkfjhWEjDbtLXL6LDwAAAOs"]
[Mon Jul 20 06:53:38.730182 2026] [security2:error] [pid 1033876:tid 1034072] [client 134.122.94.138:49390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aUkfjhWEjDbtLXL6LEQAAAMY"]
[Mon Jul 20 06:53:39.024060 2026] [security2:error] [pid 1033876:tid 1034042] [client 134.122.94.138:49683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aU0fjhWEjDbtLXL6LLQAAAKg"]
[Mon Jul 20 06:53:39.031760 2026] [security2:error] [pid 1033876:tid 1034020] [client 134.122.94.138:49690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aU0fjhWEjDbtLXL6LMAAAAJI"]
[Mon Jul 20 06:53:39.175031 2026] [security2:error] [pid 1033876:tid 1034080] [client 104.154.184.83:52712] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "39ishlife.com"] [uri "/wp-json/batch/v1"] [unique_id "al4aU0fjhWEjDbtLXL6LPgAAAM4"]
[Mon Jul 20 06:53:39.222299 2026] [security2:error] [pid 1033876:tid 1034050] [client 104.154.184.83:52712] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "39ishlife.com"] [uri "/"] [unique_id "al4aU0fjhWEjDbtLXL6LQgAAALA"]
[Mon Jul 20 06:53:39.322026 2026] [security2:error] [pid 1033876:tid 1034041] [client 134.122.94.138:49946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/api"] [unique_id "al4aU0fjhWEjDbtLXL6LSwAAAKc"]
[Mon Jul 20 06:53:39.335512 2026] [security2:error] [pid 1033876:tid 1033947] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "panel.jeffjaeger.com"] [uri "/v1/graphql"] [unique_id "al4aU0fjhWEjDbtLXL6LTQAArkU"]
[Mon Jul 20 06:53:39.337470 2026] [security2:error] [pid 1033876:tid 1033975] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4aU0fjhWEjDbtLXL6LUQAArmE"]
[Mon Jul 20 06:53:39.369594 2026] [security2:error] [pid 1033876:tid 1034117] [client 134.122.94.138:49953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/api"] [unique_id "al4aU0fjhWEjDbtLXL6LUgAAAPM"]
[Mon Jul 20 06:53:39.425674 2026] [security2:error] [pid 1033876:tid 1034011] [client 151.123.177.203:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.177.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aU0fjhWEjDbtLXL6LWwAAAIk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:39.557521 2026] [security2:error] [pid 1033876:tid 1034034] [client 34.73.38.214:63920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aU0fjhWEjDbtLXL6LbQAAAKA"]
[Mon Jul 20 06:53:39.626110 2026] [security2:error] [pid 1033876:tid 1034092] [client 134.122.94.138:50163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aU0fjhWEjDbtLXL6LdAAAANo"]
[Mon Jul 20 06:53:39.650120 2026] [security2:error] [pid 1033876:tid 1033961] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/key.pem"] [unique_id "al4aU0fjhWEjDbtLXL6LdgAArlM"]
[Mon Jul 20 06:53:39.658999 2026] [security2:error] [pid 1033876:tid 1033931] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/id_ecdsa"] [unique_id "al4aU0fjhWEjDbtLXL6LewAArjU"]
[Mon Jul 20 06:53:39.660574 2026] [security2:error] [pid 1033876:tid 1033886] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/id_rsa"] [unique_id "al4aU0fjhWEjDbtLXL6LeAAArgg"]
[Mon Jul 20 06:53:39.660721 2026] [security2:error] [pid 1033876:tid 1033878] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.jeffjaeger.com"] [uri "/id_ed25519"] [unique_id "al4aU0fjhWEjDbtLXL6LeQAArgA"]
[Mon Jul 20 06:53:39.673225 2026] [security2:error] [pid 1033876:tid 1034030] [client 57.141.18.22:49682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aTkfjhWEjDbtLXL6I8wAAnGA"]
[Mon Jul 20 06:53:39.711731 2026] [security2:error] [pid 1033876:tid 1034118] [client 134.122.94.138:50234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aU0fjhWEjDbtLXL6LgQAAAPQ"]
[Mon Jul 20 06:53:39.712504 2026] [security2:error] [pid 1033876:tid 1034130] [client 104.234.53.51:65027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aU0fjhWEjDbtLXL6LfwAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:39.732422 2026] [security2:error] [pid 1033876:tid 1034007] [client 14.225.17.146:49191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4aU0fjhWEjDbtLXL6LfgAAAIU"], referer: http://travelbyfire.com/wp-old
[Mon Jul 20 06:53:39.761620 2026] [security2:error] [pid 1033876:tid 1033912] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.jeffjaeger.com"] [uri "/.ssh/config"] [unique_id "al4aU0fjhWEjDbtLXL6LhAABASI"]
[Mon Jul 20 06:53:39.762258 2026] [security2:error] [pid 1033876:tid 1033881] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/privatekey.key"] [unique_id "al4aU0fjhWEjDbtLXL6LhQABAQM"]
[Mon Jul 20 06:53:39.762726 2026] [security2:error] [pid 1033876:tid 1034072] [client 34.73.38.214:51642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aU0fjhWEjDbtLXL6LhgAAAMY"]
[Mon Jul 20 06:53:39.926499 2026] [security2:error] [pid 1033876:tid 1034024] [client 134.122.94.138:50428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aU0fjhWEjDbtLXL6LkQAAAJY"]
[Mon Jul 20 06:53:40.039185 2026] [security2:error] [pid 1033876:tid 1034116] [client 134.122.94.138:50509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aVEfjhWEjDbtLXL6LnQAAAPI"]
[Mon Jul 20 06:53:40.080674 2026] [security2:error] [pid 1033876:tid 1034038] [client 161.118.218.103:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aVEfjhWEjDbtLXL6LoQAAAKQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:40.239711 2026] [security2:error] [pid 1033876:tid 1034045] [client 134.122.94.138:50744] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aVEfjhWEjDbtLXL6LrAAAAKs"]
[Mon Jul 20 06:53:40.258627 2026] [security2:error] [pid 1033876:tid 1034091] [client 77.110.127.138:58969] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 643 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aVEfjhWEjDbtLXL6LrgAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:40.341650 2026] [security2:error] [pid 1033876:tid 1034007] [client 134.122.94.138:50848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aVEfjhWEjDbtLXL6LtwAAAIU"]
[Mon Jul 20 06:53:40.347601 2026] [security2:error] [pid 1033876:tid 1033960] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.openclaw/.env"] [unique_id "al4aVEfjhWEjDbtLXL6LugAA1VI"]
[Mon Jul 20 06:53:40.423688 2026] [security2:error] [pid 1033876:tid 1034062] [client 103.238.106.162:42943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aVEfjhWEjDbtLXL6LwwAAALw"]
[Mon Jul 20 06:53:40.423805 2026] [security2:error] [pid 1033876:tid 1034062] [client 103.238.106.162:42943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aVEfjhWEjDbtLXL6LwwAAALw"]
[Mon Jul 20 06:53:40.424440 2026] [security2:error] [pid 1033876:tid 1034133] [client 113.160.97.242:57851] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aVEfjhWEjDbtLXL6LwgAAAQM"]
[Mon Jul 20 06:53:40.589869 2026] [security2:error] [pid 1033876:tid 1034082] [client 134.122.94.138:50977] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/"] [unique_id "al4aVEfjhWEjDbtLXL6L2AAAANA"]
[Mon Jul 20 06:53:40.653609 2026] [security2:error] [pid 1033876:tid 1034029] [client 161.118.218.103:62252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aVEfjhWEjDbtLXL6L3wAAAJs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:40.682929 2026] [security2:error] [pid 1033876:tid 1034038] [client 34.73.38.214:56398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4aVEfjhWEjDbtLXL6L4wAAAKQ"]
[Mon Jul 20 06:53:40.704559 2026] [security2:error] [pid 1033876:tid 1034067] [client 134.122.94.138:51034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4aVEfjhWEjDbtLXL6L5AAAAME"]
[Mon Jul 20 06:53:40.727079 2026] [security2:error] [pid 1033876:tid 1034114] [client 14.225.17.146:49323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4aVEfjhWEjDbtLXL6L4QAAAPA"], referer: https://travelbyfire.com/wp-old
[Mon Jul 20 06:53:40.792618 2026] [security2:error] [pid 1033876:tid 1034068] [client 104.154.184.83:52712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4aU0fjhWEjDbtLXL6LWAAAAMI"], referer: http://39ishlife.com/wp-json/batch/v1
[Mon Jul 20 06:53:40.865870 2026] [security2:error] [pid 1033876:tid 1034083] [client 77.110.127.138:58972] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aVEfjhWEjDbtLXL6L9AAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:40.919988 2026] [security2:error] [pid 1033876:tid 1034066] [client 134.122.94.138:51261] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aVEfjhWEjDbtLXL6L9wAAAMA"]
[Mon Jul 20 06:53:40.958577 2026] [security2:error] [pid 1033876:tid 1034025] [client 14.225.17.146:49388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4aVEfjhWEjDbtLXL6L6gAAAJc"], referer: http://ghivs.com/wp-old
[Mon Jul 20 06:53:41.046372 2026] [security2:error] [pid 1033876:tid 1034008] [client 134.122.94.138:51401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MCAAAAIY"]
[Mon Jul 20 06:53:41.130816 2026] [security2:error] [pid 1033876:tid 1034126] [client 50.116.65.227:34914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aVUfjhWEjDbtLXL6MDgAAAPw"]
[Mon Jul 20 06:53:41.140811 2026] [security2:error] [pid 1033876:tid 1034084] [client 50.116.65.227:34924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aVUfjhWEjDbtLXL6MDwAAANI"]
[Mon Jul 20 06:53:41.198336 2026] [security2:error] [pid 1033876:tid 1034007] [client 14.251.3.155:54770] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aVUfjhWEjDbtLXL6MEwAAAIU"]
[Mon Jul 20 06:53:41.219662 2026] [security2:error] [pid 1033876:tid 1034076] [client 134.122.94.138:51547] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MFgAAAMo"]
[Mon Jul 20 06:53:41.234976 2026] [security2:error] [pid 1033876:tid 1034123] [client 161.118.218.103:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aVUfjhWEjDbtLXL6MGQAAAPk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:41.337633 2026] [security2:error] [pid 1033876:tid 1033940] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/.hermes/auth.json"] [unique_id "al4aVUfjhWEjDbtLXL6MLAAAqD4"]
[Mon Jul 20 06:53:41.338785 2026] [security2:error] [pid 1033876:tid 1033901] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.hermes/.env"] [unique_id "al4aVUfjhWEjDbtLXL6MLQAAqBc"]
[Mon Jul 20 06:53:41.349771 2026] [security2:error] [pid 1033876:tid 1034010] [client 134.122.94.138:51683] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MMAAAAIg"]
[Mon Jul 20 06:53:41.446463 2026] [security2:error] [pid 1033876:tid 1033953] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aVUfjhWEjDbtLXL6MMwAA9ks"]
[Mon Jul 20 06:53:41.446664 2026] [security2:error] [pid 1033876:tid 1034120] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aVUfjhWEjDbtLXL6MMwAA9ks"]
[Mon Jul 20 06:53:41.469512 2026] [security2:error] [pid 1033876:tid 1034054] [client 34.73.38.214:63527] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aVUfjhWEjDbtLXL6MNwAAALQ"]
[Mon Jul 20 06:53:41.485439 2026] [security2:error] [pid 1033876:tid 1033993] [remote 81.173.115.7:41142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aVUfjhWEjDbtLXL6MOgAAyHM"]
[Mon Jul 20 06:53:41.538997 2026] [security2:error] [pid 1033876:tid 1034067] [client 134.122.94.138:51894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MQgAAAME"]
[Mon Jul 20 06:53:41.658587 2026] [security2:error] [pid 1033876:tid 1034114] [client 134.122.94.138:52005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MSAAAAPA"]
[Mon Jul 20 06:53:41.708319 2026] [security2:error] [pid 1033876:tid 1033927] [remote 81.173.115.7:41142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aVUfjhWEjDbtLXL6MUQAAsjE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:53:41.765055 2026] [autoindex:error] [pid 1033876:tid 1033968] [remote 8.229.41.77:60336] AH01276: Cannot serve directory /home2/fscxcsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.fsc.xcs.mybluehost.me
[Mon Jul 20 06:53:41.795533 2026] [security2:error] [pid 1033876:tid 1034003] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.jeffjaeger.com"] [uri "/.claude/settings.json"] [unique_id "al4aVUfjhWEjDbtLXL6MWwAA130"]
[Mon Jul 20 06:53:41.808921 2026] [security2:error] [pid 1033876:tid 1034040] [client 161.118.218.103:63093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aVUfjhWEjDbtLXL6MXQAAAKY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:41.824690 2026] [security2:error] [pid 1033876:tid 1033986] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "panel.jeffjaeger.com"] [uri "/.hermes/config.yaml"] [unique_id "al4aVUfjhWEjDbtLXL6MYAAAv2w"]
[Mon Jul 20 06:53:41.840311 2026] [security2:error] [pid 1033876:tid 1034041] [client 134.122.94.138:52181] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com.kyb.xxp.mybluehost.me"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MYwAAAKc"]
[Mon Jul 20 06:53:41.856855 2026] [security2:error] [pid 1033876:tid 1034115] [client 57.141.18.73:28706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aUEfjhWEjDbtLXL6KEQAA8U4"]
[Mon Jul 20 06:53:41.963450 2026] [security2:error] [pid 1033876:tid 1034074] [client 134.122.94.138:52368] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "liquidationteam.com"] [uri "/login"] [unique_id "al4aVUfjhWEjDbtLXL6MbgAAAMg"]
[Mon Jul 20 06:53:41.996906 2026] [security2:error] [pid 1033876:tid 1033975] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.jeffjaeger.com"] [uri "/wp-config.php.bak"] [unique_id "al4aVUfjhWEjDbtLXL6McAAApGE"]
[Mon Jul 20 06:53:42.098031 2026] [security2:error] [pid 1033876:tid 1034028] [client 77.110.127.138:58979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aVkfjhWEjDbtLXL6MeQAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:42.098125 2026] [security2:error] [pid 1033876:tid 1034028] [client 77.110.127.138:58979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aVkfjhWEjDbtLXL6MeQAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:42.271504 2026] [security2:error] [pid 1033876:tid 1033961] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "panel.jeffjaeger.com"] [uri "/wp-config.php.old"] [unique_id "al4aVkfjhWEjDbtLXL6MiAAApFM"]
[Mon Jul 20 06:53:42.294570 2026] [security2:error] [pid 1033876:tid 1033981] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/laravel/.env"] [unique_id "al4aVkfjhWEjDbtLXL6MiwAApGc"]
[Mon Jul 20 06:53:42.306553 2026] [security2:error] [pid 1033876:tid 1034050] [client 103.125.179.95:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aVkfjhWEjDbtLXL6MigAAALA"]
[Mon Jul 20 06:53:42.306648 2026] [security2:error] [pid 1033876:tid 1034050] [client 103.125.179.95:61104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aVkfjhWEjDbtLXL6MigAAALA"]
[Mon Jul 20 06:53:42.326286 2026] [security2:error] [pid 1033876:tid 1034024] [client 34.73.38.214:51369] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4aVkfjhWEjDbtLXL6MkAAAAJY"]
[Mon Jul 20 06:53:42.392827 2026] [security2:error] [pid 1033876:tid 1034130] [client 161.118.218.103:63503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aVkfjhWEjDbtLXL6MlAAAAQA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:42.400617 2026] [security2:error] [pid 1033876:tid 1033878] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.jeffjaeger.com"] [uri "/config/.env.php"] [unique_id "al4aVkfjhWEjDbtLXL6MlQAApAA"]
[Mon Jul 20 06:53:42.454699 2026] [security2:error] [pid 1033876:tid 1033995] [remote 152.228.213.32:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4aVkfjhWEjDbtLXL6MnAAApnU"]
[Mon Jul 20 06:53:42.634628 2026] [security2:error] [pid 1033876:tid 1034131] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4aVEfjhWEjDbtLXL6L_gAAAQE"]
[Mon Jul 20 06:53:42.652389 2026] [security2:error] [pid 1033876:tid 1033914] [remote 152.228.213.32:49758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4aVkfjhWEjDbtLXL6MzwAAwiQ"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:53:42.773846 2026] [security2:error] [pid 1033876:tid 1034030] [client 187.108.85.186:64858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aVkfjhWEjDbtLXL6M4wAAAJw"]
[Mon Jul 20 06:53:42.773982 2026] [security2:error] [pid 1033876:tid 1034030] [client 187.108.85.186:64858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aVkfjhWEjDbtLXL6M4wAAAJw"]
[Mon Jul 20 06:53:42.811675 2026] [security2:error] [pid 1033876:tid 1033934] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.jeffjaeger.com"] [uri "/config.php.bak"] [unique_id "al4aVkfjhWEjDbtLXL6M6QAApDg"]
[Mon Jul 20 06:53:42.811700 2026] [security2:error] [pid 1033876:tid 1033957] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.jeffjaeger.com"] [uri "/configuration.php.bak"] [unique_id "al4aVkfjhWEjDbtLXL6M5wAApE8"]
[Mon Jul 20 06:53:42.812447 2026] [security2:error] [pid 1033876:tid 1033908] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/core/.env"] [unique_id "al4aVkfjhWEjDbtLXL6M6AAApB4"]
[Mon Jul 20 06:53:42.831663 2026] [security2:error] [pid 1033876:tid 1033940] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "panel.jeffjaeger.com"] [uri "/.env.php.bak"] [unique_id "al4aVkfjhWEjDbtLXL6M7QAApD4"]
[Mon Jul 20 06:53:42.969244 2026] [security2:error] [pid 1033876:tid 1034075] [client 161.118.218.103:63935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aVkfjhWEjDbtLXL6M-AAAAMk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:43.002436 2026] [security2:error] [pid 1033876:tid 1034120] [client 34.73.38.214:61275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aV0fjhWEjDbtLXL6M_gAAAPY"]
[Mon Jul 20 06:53:43.057564 2026] [security2:error] [pid 1033876:tid 1034109] [client 74.7.227.179:39662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4aVkfjhWEjDbtLXL6M9QAA62M"], referer: https://tejasenvironmental.com/p=326041
[Mon Jul 20 06:53:43.158964 2026] [security2:error] [pid 1033876:tid 1034084] [client 192.140.149.97:45857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aV0fjhWEjDbtLXL6NCAAAANI"]
[Mon Jul 20 06:53:43.159080 2026] [security2:error] [pid 1033876:tid 1034084] [client 192.140.149.97:45857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aV0fjhWEjDbtLXL6NCAAAANI"]
[Mon Jul 20 06:53:43.180998 2026] [security2:error] [pid 1033876:tid 1034118] [client 117.247.108.24:12431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aV0fjhWEjDbtLXL6NDQAAAPQ"]
[Mon Jul 20 06:53:43.181084 2026] [security2:error] [pid 1033876:tid 1034118] [client 117.247.108.24:12431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aV0fjhWEjDbtLXL6NDQAAAPQ"]
[Mon Jul 20 06:53:43.313331 2026] [security2:error] [pid 1033876:tid 1033880] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/.env.swp"] [unique_id "al4aV0fjhWEjDbtLXL6NHAAA5QI"]
[Mon Jul 20 06:53:43.382818 2026] [security2:error] [pid 1033876:tid 1034071] [client 104.234.53.69:53773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4aV0fjhWEjDbtLXL6NGQAAAMU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:43.559973 2026] [security2:error] [pid 1033876:tid 1034079] [client 161.118.218.103:64417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aV0fjhWEjDbtLXL6NMwAAAM0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:43.560083 2026] [security2:error] [pid 1033876:tid 1034097] [client 104.234.53.69:53773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aV0fjhWEjDbtLXL6NMAAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:43.586160 2026] [security2:error] [pid 1033876:tid 1033941] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/config/application.properties"] [unique_id "al4aV0fjhWEjDbtLXL6NPwAA-z8"]
[Mon Jul 20 06:53:43.586594 2026] [security2:error] [pid 1033876:tid 1033999] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/public/.env"] [unique_id "al4aV0fjhWEjDbtLXL6NPAAA-3k"]
[Mon Jul 20 06:53:43.590252 2026] [security2:error] [pid 1033876:tid 1033948] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/web/.env"] [unique_id "al4aV0fjhWEjDbtLXL6NQgAA-0Y"]
[Mon Jul 20 06:53:43.643592 2026] [security2:error] [pid 1033876:tid 1034112] [client 14.225.17.146:52262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4aV0fjhWEjDbtLXL6NFwAAAO4"], referer: http://overloadcomedy.com/wp-old
[Mon Jul 20 06:53:43.874671 2026] [security2:error] [pid 1033876:tid 1033992] [remote 57.141.18.23:21544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4aV0fjhWEjDbtLXL6NYwAA7HI"]
[Mon Jul 20 06:53:43.895737 2026] [security2:error] [pid 1033876:tid 1034099] [client 34.73.38.214:60190] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4aV0fjhWEjDbtLXL6NZwAAAOE"]
[Mon Jul 20 06:53:44.073132 2026] [security2:error] [pid 1033876:tid 1034013] [client 34.73.38.214:55165] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4aWEfjhWEjDbtLXL6NewAAAIs"]
[Mon Jul 20 06:53:44.142947 2026] [security2:error] [pid 1033876:tid 1034036] [client 161.118.218.103:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aWEfjhWEjDbtLXL6NiwAAAKI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:44.379728 2026] [security2:error] [pid 1033876:tid 1034085] [client 57.141.18.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aWEfjhWEjDbtLXL6NjwAAANM"]
[Mon Jul 20 06:53:44.421518 2026] [security2:error] [pid 1033876:tid 1033996] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/web.config"] [unique_id "al4aWEfjhWEjDbtLXL6NqAAA-3Y"]
[Mon Jul 20 06:53:44.497067 2026] [security2:error] [pid 1033876:tid 1034093] [client 104.234.53.79:47207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aWEfjhWEjDbtLXL6NowAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:44.530622 2026] [security2:error] [pid 1033876:tid 1033906] [remote 8.217.108.67:59214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4aWEfjhWEjDbtLXL6NrgAArxw"]
[Mon Jul 20 06:53:44.708397 2026] [security2:error] [pid 1033876:tid 1034020] [client 34.73.38.214:54704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aWEfjhWEjDbtLXL6NvQAAAJI"]
[Mon Jul 20 06:53:44.725613 2026] [security2:error] [pid 1033876:tid 1034057] [client 161.118.218.103:65325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aWEfjhWEjDbtLXL6NvgAAALc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:44.854646 2026] [security2:error] [pid 1033876:tid 1033989] [remote 162.19.86.63:36186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4aWEfjhWEjDbtLXL6NwAABAm8"]
[Mon Jul 20 06:53:44.963672 2026] [security2:error] [pid 1033876:tid 1034089] [client 46.110.96.34:43371] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4aWEfjhWEjDbtLXL6NzwAAANc"]
[Mon Jul 20 06:53:44.981943 2026] [security2:error] [pid 1033876:tid 1033951] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/config/storage.yml"] [unique_id "al4aWEfjhWEjDbtLXL6N1AAAv0k"]
[Mon Jul 20 06:53:45.049530 2026] [security2:error] [pid 1033876:tid 1033967] [remote 162.19.86.63:36186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4aWUfjhWEjDbtLXL6N2wAAmlk"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 06:53:45.199524 2026] [security2:error] [pid 1033876:tid 1034043] [client 34.73.38.214:58605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4aWUfjhWEjDbtLXL6N7gAAAKk"]
[Mon Jul 20 06:53:45.220210 2026] [security2:error] [pid 1033876:tid 1034039] [client 197.186.66.42:51554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aWUfjhWEjDbtLXL6N8AAAAKU"]
[Mon Jul 20 06:53:45.238997 2026] [security2:error] [pid 1033876:tid 1034039] [client 197.186.66.42:51554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aWUfjhWEjDbtLXL6N8AAAAKU"]
[Mon Jul 20 06:53:45.308741 2026] [security2:error] [pid 1033876:tid 1034110] [client 161.118.218.103:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aWUfjhWEjDbtLXL6N8wAAAOw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:45.387206 2026] [security2:error] [pid 1033876:tid 1034062] [client 14.225.17.146:52664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4aWUfjhWEjDbtLXL6N7QAAALw"], referer: http://soloceos.com/wp-old
[Mon Jul 20 06:53:45.395184 2026] [security2:error] [pid 1033876:tid 1033920] [remote 72.167.132.114:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aWUfjhWEjDbtLXL6OAwAA6Co"]
[Mon Jul 20 06:53:45.424189 2026] [security2:error] [pid 1033876:tid 1034103] [client 104.234.53.79:47207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aWUfjhWEjDbtLXL6ODAAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:45.468793 2026] [security2:error] [pid 1033876:tid 1034112] [client 77.110.127.138:59002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 146 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aWUfjhWEjDbtLXL6ODgAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:45.627900 2026] [security2:error] [pid 1033876:tid 1034083] [client 34.73.38.214:58377] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4aWUfjhWEjDbtLXL6OIgAAANE"]
[Mon Jul 20 06:53:45.637897 2026] [security2:error] [pid 1033876:tid 1034005] [remote 8.217.108.67:59214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4aWUfjhWEjDbtLXL6OIQAAqX8"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:53:45.754180 2026] [security2:error] [pid 1033876:tid 1033949] [remote 72.167.132.114:60452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aWUfjhWEjDbtLXL6OJwAAz0c"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:53:45.847895 2026] [security2:error] [pid 1033876:tid 1034105] [client 117.222.139.248:56410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aWUfjhWEjDbtLXL6OKgAAAOc"]
[Mon Jul 20 06:53:45.848030 2026] [security2:error] [pid 1033876:tid 1034105] [client 117.222.139.248:56410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aWUfjhWEjDbtLXL6OKgAAAOc"]
[Mon Jul 20 06:53:45.892743 2026] [security2:error] [pid 1033876:tid 1034042] [client 161.118.218.103:49971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aWUfjhWEjDbtLXL6OLQAAAKg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:46.123547 2026] [security2:error] [pid 1033876:tid 1034013] [client 34.73.38.214:55971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vbb.yvf.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4aWkfjhWEjDbtLXL6ORwAAAIs"]
[Mon Jul 20 06:53:46.216241 2026] [security2:error] [pid 1033876:tid 1034032] [client 77.110.127.138:59006] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aWkfjhWEjDbtLXL6OTQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.318108 2026] [security2:error] [pid 1033876:tid 1034014] [client 34.207.130.29:21810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aWkfjhWEjDbtLXL6OUgAAAIw"]
[Mon Jul 20 06:53:46.318198 2026] [security2:error] [pid 1033876:tid 1034014] [client 34.207.130.29:21810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aWkfjhWEjDbtLXL6OUgAAAIw"]
[Mon Jul 20 06:53:46.334634 2026] [security2:error] [pid 1033876:tid 1034045] [client 104.207.51.209:65067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aWkfjhWEjDbtLXL6OUwAAAKs"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:53:46.367729 2026] [security2:error] [pid 1033876:tid 1034029] [client 77.110.127.138:59007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OVgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.367841 2026] [security2:error] [pid 1033876:tid 1034029] [client 77.110.127.138:59007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OVgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.440793 2026] [security2:error] [pid 1033876:tid 1033881] [remote 5.161.225.162:43742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aWkfjhWEjDbtLXL6OXgAAiQM"]
[Mon Jul 20 06:53:46.440916 2026] [security2:error] [pid 1033876:tid 1034011] [client 5.161.225.162:43742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aWkfjhWEjDbtLXL6OXgAAiQM"]
[Mon Jul 20 06:53:46.471103 2026] [security2:error] [pid 1033876:tid 1034131] [client 161.118.218.103:50483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aWkfjhWEjDbtLXL6OYgAAAQE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:46.522334 2026] [security2:error] [pid 1033876:tid 1034018] [client 216.73.217.138:59599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4aWkfjhWEjDbtLXL6OXQAAkHw"]
[Mon Jul 20 06:53:46.525068 2026] [security2:error] [pid 1033876:tid 1034090] [client 77.110.127.138:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OcAAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.525140 2026] [security2:error] [pid 1033876:tid 1034090] [client 77.110.127.138:59010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OcAAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.531464 2026] [security2:error] [pid 1033876:tid 1033923] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/app/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OcQAA-S0"]
[Mon Jul 20 06:53:46.534201 2026] [security2:error] [pid 1033876:tid 1033924] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/server/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OcgAAii4"]
[Mon Jul 20 06:53:46.542112 2026] [security2:error] [pid 1033876:tid 1033991] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/dev/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OdQAAlXE"]
[Mon Jul 20 06:53:46.550218 2026] [security2:error] [pid 1033876:tid 1034001] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/frontend/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OdwAAvXs"]
[Mon Jul 20 06:53:46.550334 2026] [security2:error] [pid 1033876:tid 1034063] [client 34.156.104.72:43310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.jeffjaeger.com"] [uri "/frontend/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OdwAAvXs"]
[Mon Jul 20 06:53:46.550842 2026] [security2:error] [pid 1033876:tid 1033945] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/src/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OeAAAvUM"]
[Mon Jul 20 06:53:46.719286 2026] [security2:error] [pid 1033876:tid 1034015] [client 77.110.127.138:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OjQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.719401 2026] [security2:error] [pid 1033876:tid 1034015] [client 77.110.127.138:59011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OjQAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.895381 2026] [security2:error] [pid 1033876:tid 1034017] [client 104.207.50.38:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aWkfjhWEjDbtLXL6OmgAAAI8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:53:46.930768 2026] [security2:error] [pid 1033876:tid 1034073] [client 77.110.127.138:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OngAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.930839 2026] [security2:error] [pid 1033876:tid 1034073] [client 77.110.127.138:59013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aWkfjhWEjDbtLXL6OngAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:46.989791 2026] [security2:error] [pid 1033876:tid 1033919] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "panel.jeffjaeger.com"] [uri "/production/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OpQAAkSk"]
[Mon Jul 20 06:53:46.990025 2026] [security2:error] [pid 1033876:tid 1034019] [client 34.156.104.72:43310] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "panel.jeffjaeger.com"] [uri "/production/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OpQAAkSk"]
[Mon Jul 20 06:53:46.991646 2026] [security2:error] [pid 1033876:tid 1033928] [remote 34.156.104.72:43310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "panel.jeffjaeger.com"] [uri "/@fs/.env"] [unique_id "al4aWkfjhWEjDbtLXL6OpgAAkTI"]
[Mon Jul 20 06:53:46.999247 2026] [security2:error] [pid 1033876:tid 1033996] [remote 34.156.104.72:43310] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "panel.jeffjaeger.com"] [uri "/@fs/proc/self/environ"] [unique_id "al4aWkfjhWEjDbtLXL6OqAAAu3Y"]
[Mon Jul 20 06:53:47.046992 2026] [security2:error] [pid 1033876:tid 1034125] [client 161.118.218.103:50961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aW0fjhWEjDbtLXL6OrgAAAPs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:47.140036 2026] [security2:error] [pid 1033876:tid 1034113] [client 77.110.127.138:59015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aW0fjhWEjDbtLXL6OtQAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:47.140146 2026] [security2:error] [pid 1033876:tid 1034113] [client 77.110.127.138:59015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aW0fjhWEjDbtLXL6OtQAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:47.318287 2026] [security2:error] [pid 1033876:tid 1034124] [client 152.58.191.29:63826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aW0fjhWEjDbtLXL6OwAAAAPo"]
[Mon Jul 20 06:53:47.321075 2026] [security2:error] [pid 1033876:tid 1034124] [client 152.58.191.29:63826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aW0fjhWEjDbtLXL6OwAAAAPo"]
[Mon Jul 20 06:53:47.351611 2026] [security2:error] [pid 1033876:tid 1034087] [client 77.110.127.138:59017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aW0fjhWEjDbtLXL6OvwAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:47.351697 2026] [security2:error] [pid 1033876:tid 1034087] [client 77.110.127.138:59017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aW0fjhWEjDbtLXL6OvwAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:47.433515 2026] [security2:error] [pid 1033876:tid 1034082] [client 14.225.17.146:55736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4aW0fjhWEjDbtLXL6OvgAAANA"], referer: http://lelandumc.org/wp-old
[Mon Jul 20 06:53:47.503492 2026] [security2:error] [pid 1033876:tid 1034030] [client 77.110.127.138:59018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aW0fjhWEjDbtLXL6OyAAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:47.503596 2026] [security2:error] [pid 1033876:tid 1034030] [client 77.110.127.138:59018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aW0fjhWEjDbtLXL6OyAAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:47.507800 2026] [security2:error] [pid 1033876:tid 1034011] [client 122.183.32.225:13811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aW0fjhWEjDbtLXL6OxwAAAIk"]
[Mon Jul 20 06:53:47.507904 2026] [security2:error] [pid 1033876:tid 1034011] [client 122.183.32.225:13811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aW0fjhWEjDbtLXL6OxwAAAIk"]
[Mon Jul 20 06:53:47.624185 2026] [security2:error] [pid 1033876:tid 1034008] [client 161.118.218.103:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aW0fjhWEjDbtLXL6OzgAAAIY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:47.991799 2026] [security2:error] [pid 1033876:tid 1034029] [client 14.225.17.146:62575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4aW0fjhWEjDbtLXL6O4wAAAJs"], referer: http://recruitinginsight.us/wp-old
[Mon Jul 20 06:53:48.200248 2026] [security2:error] [pid 1033876:tid 1034024] [client 161.118.218.103:51916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aXEfjhWEjDbtLXL6PBAAAAJY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:48.252632 2026] [security2:error] [pid 1033876:tid 1033944] [remote 152.228.213.32:45380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aXEfjhWEjDbtLXL6PCAAA0UI"]
[Mon Jul 20 06:53:48.252890 2026] [security2:error] [pid 1033876:tid 1034083] [client 152.228.213.32:45380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aXEfjhWEjDbtLXL6PCAAA0UI"]
[Mon Jul 20 06:53:48.413249 2026] [security2:error] [pid 1033876:tid 1034069] [client 57.141.18.58:45624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aV0fjhWEjDbtLXL6NSwAAwyY"]
[Mon Jul 20 06:53:48.471645 2026] [security2:error] [pid 1033876:tid 1034057] [client 185.243.112.137:64830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.112.243.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/_profiler/phpinfo.php"] [unique_id "al4aXEfjhWEjDbtLXL6PGwAAALc"]
[Mon Jul 20 06:53:48.643122 2026] [security2:error] [pid 1033876:tid 1034043] [client 14.225.17.146:62490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4aW0fjhWEjDbtLXL6O3QAAAKk"], referer: http://walkingandtalking.net/wp-old
[Mon Jul 20 06:53:48.772598 2026] [security2:error] [pid 1033876:tid 1034040] [client 161.118.218.103:52400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aXEfjhWEjDbtLXL6PMwAAAKY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:48.811910 2026] [security2:error] [pid 1033876:tid 1034047] [client 217.142.18.172:7003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aXEfjhWEjDbtLXL6PNgAAAK0"]
[Mon Jul 20 06:53:48.812050 2026] [security2:error] [pid 1033876:tid 1034047] [client 217.142.18.172:7003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aXEfjhWEjDbtLXL6PNgAAAK0"]
[Mon Jul 20 06:53:49.286698 2026] [security2:error] [pid 1033876:tid 1034025] [client 114.119.143.55:54815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/robots.txt"] [unique_id "al4aXUfjhWEjDbtLXL6PWgAAAJc"], referer: http://headachescarpaltunnelfibromyalgia.com/robots.txt
[Mon Jul 20 06:53:49.359608 2026] [security2:error] [pid 1033876:tid 1034030] [client 161.118.218.103:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aXUfjhWEjDbtLXL6PYQAAAJw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:49.483374 2026] [security2:error] [pid 1033876:tid 1034132] [client 14.225.17.146:55784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4aW0fjhWEjDbtLXL6OwgAAAQI"], referer: http://swafforddetailing.com/wp-old
[Mon Jul 20 06:53:49.516224 2026] [security2:error] [pid 1033876:tid 1034036] [client 14.225.17.146:57810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4aXUfjhWEjDbtLXL6PcQAAAKI"], referer: https://walkingandtalking.net/wp-old
[Mon Jul 20 06:53:49.532361 2026] [security2:error] [pid 1033876:tid 1033981] [remote 8.217.108.67:37008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aXUfjhWEjDbtLXL6PcgAAvWc"]
[Mon Jul 20 06:53:49.596694 2026] [security2:error] [pid 1033876:tid 1034061] [client 104.207.38.251:39009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aXUfjhWEjDbtLXL6PdQAAALs"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:49.680101 2026] [security2:error] [pid 1033876:tid 1034015] [client 104.234.53.65:27513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4aXUfjhWEjDbtLXL6PdwAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:49.840614 2026] [core:error] [pid 1033876:tid 1034130] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:49.840636 2026] [core:error] [pid 1033876:tid 1034130] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:53:49.934432 2026] [security2:error] [pid 1033876:tid 1034066] [client 161.118.218.103:53371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aXUfjhWEjDbtLXL6PqgAAAMA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:49.951497 2026] [security2:error] [pid 1033876:tid 1034017] [client 14.225.17.146:62318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4aXUfjhWEjDbtLXL6PoAAAAI8"], referer: http://according2plant.com/wp-old
[Mon Jul 20 06:53:50.008054 2026] [security2:error] [pid 1033876:tid 1034087] [client 77.110.127.138:59023] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 651 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aXkfjhWEjDbtLXL6PrAAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:50.130350 2026] [security2:error] [pid 1033876:tid 1034042] [client 14.225.17.146:57874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4aXkfjhWEjDbtLXL6PrwAAAKg"]
[Mon Jul 20 06:53:50.336060 2026] [security2:error] [pid 1033876:tid 1034100] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.alaraycreative.com"] [uri "/index.php"] [unique_id "al4aXkfjhWEjDbtLXL6PtQAAAOI"]
[Mon Jul 20 06:53:50.371667 2026] [security2:error] [pid 1033876:tid 1034063] [client 104.207.33.176:16767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.33.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aXkfjhWEjDbtLXL6PygAAAL0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:50.515763 2026] [security2:error] [pid 1033876:tid 1034069] [client 161.118.218.103:53845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aXkfjhWEjDbtLXL6P1wAAAMM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:50.648253 2026] [security2:error] [pid 1033876:tid 1034086] [client 104.234.53.65:27513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aXkfjhWEjDbtLXL6P4AAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:50.651898 2026] [security2:error] [pid 1033876:tid 1034102] [client 192.140.149.97:45961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aXkfjhWEjDbtLXL6P4QAAAOQ"]
[Mon Jul 20 06:53:50.652011 2026] [security2:error] [pid 1033876:tid 1034102] [client 192.140.149.97:45961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aXkfjhWEjDbtLXL6P4QAAAOQ"]
[Mon Jul 20 06:53:50.689518 2026] [security2:error] [pid 1033876:tid 1034053] [client 77.110.127.138:59025] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aXkfjhWEjDbtLXL6P6QAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:50.749175 2026] [security2:error] [pid 1033876:tid 1033939] [remote 8.217.108.67:37008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aXkfjhWEjDbtLXL6P6wAAzD0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:53:51.027956 2026] [security2:error] [pid 1033876:tid 1034121] [client 103.238.106.162:42870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aX0fjhWEjDbtLXL6P-gAAAPc"]
[Mon Jul 20 06:53:51.028099 2026] [security2:error] [pid 1033876:tid 1034121] [client 103.238.106.162:42870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aX0fjhWEjDbtLXL6P-gAAAPc"]
[Mon Jul 20 06:53:51.094545 2026] [security2:error] [pid 1033876:tid 1034114] [client 161.118.218.103:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aX0fjhWEjDbtLXL6QAQAAAPA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:51.167080 2026] [security2:error] [pid 1033876:tid 1034094] [client 45.3.39.164:34607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aX0fjhWEjDbtLXL6QCAAAANw"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:51.208606 2026] [security2:error] [pid 1033876:tid 1034026] [client 14.225.17.146:57728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4aX0fjhWEjDbtLXL6P_AAAAJg"], referer: http://elitetax-mi.com/wp-old
[Mon Jul 20 06:53:51.483505 2026] [security2:error] [pid 1033876:tid 1034132] [client 77.110.127.138:59029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aX0fjhWEjDbtLXL6QIAAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:51.483621 2026] [security2:error] [pid 1033876:tid 1034132] [client 77.110.127.138:59029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aX0fjhWEjDbtLXL6QIAAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:51.649338 2026] [security2:error] [pid 1033876:tid 1034070] [client 77.110.127.138:59030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aX0fjhWEjDbtLXL6QKgAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:51.675446 2026] [security2:error] [pid 1033876:tid 1034120] [client 161.118.218.103:54682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aX0fjhWEjDbtLXL6QLAAAAPY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:51.895959 2026] [security2:error] [pid 1033876:tid 1034106] [client 65.111.20.147:60193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aX0fjhWEjDbtLXL6QOgAAAOg"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:53:51.955662 2026] [security2:error] [pid 1033876:tid 1033916] [remote 223.205.73.240:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.73.205.223.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aX0fjhWEjDbtLXL6QQwAA-SY"]
[Mon Jul 20 06:53:51.955813 2026] [security2:error] [pid 1033876:tid 1034123] [client 223.205.73.240:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4aX0fjhWEjDbtLXL6QQwAA-SY"]
[Mon Jul 20 06:53:52.260958 2026] [security2:error] [pid 1033876:tid 1034132] [client 161.118.218.103:55141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aYEfjhWEjDbtLXL6QXwAAAQI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:52.409939 2026] [security2:error] [pid 1033876:tid 1034035] [client 14.225.17.146:61687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4aXkfjhWEjDbtLXL6P9wAAAKE"], referer: http://tntcatholic.com/wp-old
[Mon Jul 20 06:53:52.794240 2026] [security2:error] [pid 1033876:tid 1034077] [client 50.116.65.227:45256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aYEfjhWEjDbtLXL6QigAAAMs"]
[Mon Jul 20 06:53:52.803895 2026] [security2:error] [pid 1033876:tid 1034120] [client 50.116.65.227:45270] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aYEfjhWEjDbtLXL6QiwAAAPY"]
[Mon Jul 20 06:53:52.842426 2026] [security2:error] [pid 1033876:tid 1034075] [client 161.118.218.103:55591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aYEfjhWEjDbtLXL6QjgAAAMk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:53.045231 2026] [security2:error] [pid 1033876:tid 1034100] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.almaz-aura.com"] [uri "/index.php"] [unique_id "al4aYEfjhWEjDbtLXL6QhwAAAOI"]
[Mon Jul 20 06:53:53.057844 2026] [security2:error] [pid 1033876:tid 1034040] [client 103.125.179.95:61614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6QpQAAAKY"]
[Mon Jul 20 06:53:53.057941 2026] [security2:error] [pid 1033876:tid 1034040] [client 103.125.179.95:61614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6QpQAAAKY"]
[Mon Jul 20 06:53:53.403089 2026] [security2:error] [pid 1033876:tid 1034103] [client 187.108.85.186:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6QxgAAAOU"]
[Mon Jul 20 06:53:53.403205 2026] [security2:error] [pid 1033876:tid 1034103] [client 187.108.85.186:65451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6QxgAAAOU"]
[Mon Jul 20 06:53:53.418576 2026] [security2:error] [pid 1033876:tid 1034077] [client 161.118.218.103:56062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aYUfjhWEjDbtLXL6QxwAAAMs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:53.455635 2026] [security2:error] [pid 1033876:tid 1033887] [remote 144.79.133.30:35578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6QzAAAjgk"]
[Mon Jul 20 06:53:53.455841 2026] [security2:error] [pid 1033876:tid 1034016] [client 144.79.133.30:35578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6QzAAAjgk"]
[Mon Jul 20 06:53:53.477608 2026] [security2:error] [pid 1033876:tid 1033976] [remote 124.55.178.99:41290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aYUfjhWEjDbtLXL6QzwAAtGI"]
[Mon Jul 20 06:53:53.667788 2026] [security2:error] [pid 1033876:tid 1034020] [client 104.234.53.50:45611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4aYUfjhWEjDbtLXL6Q2AAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:53.888796 2026] [security2:error] [pid 1033876:tid 1033992] [remote 124.55.178.99:41290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aYUfjhWEjDbtLXL6Q7AABAnI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:53:53.980050 2026] [security2:error] [pid 1033876:tid 1034097] [client 117.247.108.24:12854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6Q8QAAAN8"]
[Mon Jul 20 06:53:53.980145 2026] [security2:error] [pid 1033876:tid 1034097] [client 117.247.108.24:12854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aYUfjhWEjDbtLXL6Q8QAAAN8"]
[Mon Jul 20 06:53:54.017415 2026] [security2:error] [pid 1033876:tid 1034122] [client 161.118.218.103:56578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aYkfjhWEjDbtLXL6Q9AAAAPg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:54.111130 2026] [security2:error] [pid 1033876:tid 1034046] [client 77.110.127.138:59040] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 808 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aYkfjhWEjDbtLXL6Q-wAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:54.408807 2026] [security2:error] [pid 1033876:tid 1034019] [client 14.225.17.146:59146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4aYkfjhWEjDbtLXL6Q_wAAAJE"], referer: http://sarahsnyder.net/wp-old
[Mon Jul 20 06:53:54.421993 2026] [security2:error] [pid 1033876:tid 1034085] [client 104.234.53.50:45611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aYkfjhWEjDbtLXL6REAAAANM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:54.495286 2026] [security2:error] [pid 1033876:tid 1034107] [client 14.225.17.146:64532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4aYkfjhWEjDbtLXL6RCgAAAOk"], referer: http://maplerespiteservices.com/wp-old
[Mon Jul 20 06:53:54.598607 2026] [security2:error] [pid 1033876:tid 1034093] [client 161.118.218.103:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aYkfjhWEjDbtLXL6RJQAAANs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:55.176462 2026] [security2:error] [pid 1033876:tid 1034070] [client 161.118.218.103:57455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aY0fjhWEjDbtLXL6RVAAAAMQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:55.287608 2026] [security2:error] [pid 1033876:tid 1034074] [client 77.110.127.138:59045] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aY0fjhWEjDbtLXL6RXAAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:55.428965 2026] [security2:error] [pid 1033876:tid 1034044] [client 14.225.17.146:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4aY0fjhWEjDbtLXL6RXQAAAKo"], referer: https://sarahsnyder.net/wp-old
[Mon Jul 20 06:53:55.441423 2026] [security2:error] [pid 1033876:tid 1034049] [client 77.110.127.138:59048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aY0fjhWEjDbtLXL6RaAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:55.441507 2026] [security2:error] [pid 1033876:tid 1034049] [client 77.110.127.138:59048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aY0fjhWEjDbtLXL6RaAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:55.473941 2026] [security2:error] [pid 1033876:tid 1034042] [client 104.234.53.75:45195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aY0fjhWEjDbtLXL6RawAAAKg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:55.596615 2026] [security2:error] [pid 1033876:tid 1033908] [remote 20.153.140.50:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aY0fjhWEjDbtLXL6RcQAA4B4"]
[Mon Jul 20 06:53:55.596760 2026] [security2:error] [pid 1033876:tid 1034098] [client 20.153.140.50:36812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aY0fjhWEjDbtLXL6RcQAA4B4"]
[Mon Jul 20 06:53:55.694412 2026] [security2:error] [pid 1033876:tid 1033951] [remote 154.0.166.254:50016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aY0fjhWEjDbtLXL6RfgABAUk"]
[Mon Jul 20 06:53:55.694549 2026] [security2:error] [pid 1033876:tid 1034131] [client 154.0.166.254:50016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aY0fjhWEjDbtLXL6RfgABAUk"]
[Mon Jul 20 06:53:55.752510 2026] [security2:error] [pid 1033876:tid 1034026] [client 84.54.44.19:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.44.54.84.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigwormfishing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aY0fjhWEjDbtLXL6RfwAAAJg"], referer: https://www.bigwormfishing.com/contact-2/
[Mon Jul 20 06:53:55.759309 2026] [security2:error] [pid 1033876:tid 1034025] [client 161.118.218.103:57858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aY0fjhWEjDbtLXL6RggAAAJc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:55.882408 2026] [security2:error] [pid 1033876:tid 1034118] [client 178.20.47.39:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.47.20.178.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.bigwormfishing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aY0fjhWEjDbtLXL6RjQAAAPQ"], referer: https://www.bigwormfishing.com/contact-2/
[Mon Jul 20 06:53:55.886125 2026] [security2:error] [pid 1033876:tid 1034045] [client 178.62.220.120:53497] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.bluedoorbar.co.nz"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4aY0fjhWEjDbtLXL6RhwAAAKs"]
[Mon Jul 20 06:53:56.343332 2026] [security2:error] [pid 1033876:tid 1034059] [client 161.118.218.103:58268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aZEfjhWEjDbtLXL6RtAAAALk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:56.415390 2026] [security2:error] [pid 1033876:tid 1034101] [client 117.222.139.248:56881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aZEfjhWEjDbtLXL6RtgAAAOM"]
[Mon Jul 20 06:53:56.415505 2026] [security2:error] [pid 1033876:tid 1034101] [client 117.222.139.248:56881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aZEfjhWEjDbtLXL6RtgAAAOM"]
[Mon Jul 20 06:53:56.644291 2026] [security2:error] [pid 1033876:tid 1034055] [client 14.251.3.155:54773] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aZEfjhWEjDbtLXL6R0wAAALU"]
[Mon Jul 20 06:53:56.885991 2026] [security2:error] [pid 1033876:tid 1034132] [client 183.82.98.154:56805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aZEfjhWEjDbtLXL6R5AAAAQI"]
[Mon Jul 20 06:53:56.886127 2026] [security2:error] [pid 1033876:tid 1034132] [client 183.82.98.154:56805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aZEfjhWEjDbtLXL6R5AAAAQI"]
[Mon Jul 20 06:53:56.898288 2026] [security2:error] [pid 1033876:tid 1034017] [client 185.243.112.137:49340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.112.243.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/phpinfo.php"] [unique_id "al4aZEfjhWEjDbtLXL6R5QAAAI8"]
[Mon Jul 20 06:53:56.918109 2026] [security2:error] [pid 1033876:tid 1034085] [client 161.118.218.103:58665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aZEfjhWEjDbtLXL6R6AAAANM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:57.115572 2026] [security2:error] [pid 1033876:tid 1034030] [client 47.128.124.106:38000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/robots.txt"] [unique_id "al4aZUfjhWEjDbtLXL6R_AAAAJw"]
[Mon Jul 20 06:53:57.214170 2026] [security2:error] [pid 1033876:tid 1033904] [remote 100.42.189.89:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4aZUfjhWEjDbtLXL6SCgAAhRo"]
[Mon Jul 20 06:53:57.418142 2026] [security2:error] [pid 1033876:tid 1033948] [remote 100.42.189.89:55138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4aZUfjhWEjDbtLXL6SGQAA2kY"], referer: https://mail.factsandminds.com/wp-login.php
[Mon Jul 20 06:53:57.493386 2026] [security2:error] [pid 1033876:tid 1034041] [client 161.118.218.103:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aZUfjhWEjDbtLXL6SHwAAAKc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:57.661846 2026] [security2:error] [pid 1033876:tid 1034089] [client 14.225.17.146:64699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4aZUfjhWEjDbtLXL6SEAAAANc"], referer: http://hilltopnurseryinc.com/wp-old
[Mon Jul 20 06:53:57.725482 2026] [security2:error] [pid 1033876:tid 1034081] [client 62.150.67.110:48773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4aZUfjhWEjDbtLXL6R7QAAAM8"]
[Mon Jul 20 06:53:57.900058 2026] [security2:error] [pid 1033876:tid 1034121] [client 14.225.17.146:64629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4aZEfjhWEjDbtLXL6RtwAAAPc"], referer: http://dnsplumbing.com/wp-old
[Mon Jul 20 06:53:57.921438 2026] [proxy:error] [pid 1033876:tid 1034010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:57.921518 2026] [proxy_http:error] [pid 1033876:tid 1034010] [client 34.73.38.214:57790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:57.922142 2026] [proxy:error] [pid 1033876:tid 1034010] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:57.922170 2026] [proxy_http:error] [pid 1033876:tid 1034010] [client 34.73.38.214:57790] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:57.927822 2026] [security2:error] [pid 1033876:tid 1034057] [client 14.225.17.146:64295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4aZEfjhWEjDbtLXL6RvAAAALc"], referer: http://blaizeaccountingservices.com/wp-old
[Mon Jul 20 06:53:58.039671 2026] [security2:error] [pid 1033876:tid 1034105] [client 112.86.225.223:55084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/product/puma-34-length-active-legging/"] [unique_id "al4aZkfjhWEjDbtLXL6STAAAAOc"]
[Mon Jul 20 06:53:58.039847 2026] [security2:error] [pid 1033876:tid 1034105] [client 112.86.225.223:55084] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.liquidationteam.com"] [uri "/product/puma-34-length-active-legging/"] [unique_id "al4aZkfjhWEjDbtLXL6STAAAAOc"]
[Mon Jul 20 06:53:58.067058 2026] [security2:error] [pid 1033876:tid 1034101] [client 161.118.218.103:59496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aZkfjhWEjDbtLXL6STwAAAOM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:58.118052 2026] [security2:error] [pid 1033876:tid 1034027] [client 197.186.66.42:52095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aZkfjhWEjDbtLXL6SVgAAAJk"]
[Mon Jul 20 06:53:58.118163 2026] [security2:error] [pid 1033876:tid 1034027] [client 197.186.66.42:52095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aZkfjhWEjDbtLXL6SVgAAAJk"]
[Mon Jul 20 06:53:58.571214 2026] [security2:error] [pid 1033876:tid 1034019] [client 77.110.127.138:59079] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 651 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aZkfjhWEjDbtLXL6SegAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:58.623249 2026] [security2:error] [pid 1033876:tid 1034091] [client 185.243.112.137:49521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.112.243.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zonemist.com"] [uri "/info.php"] [unique_id "al4aZkfjhWEjDbtLXL6ShwAAANk"]
[Mon Jul 20 06:53:58.642772 2026] [security2:error] [pid 1033876:tid 1034034] [client 161.118.218.103:59983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aZkfjhWEjDbtLXL6SkAAAAKA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:58.812613 2026] [proxy:error] [pid 1033876:tid 1034119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:58.812683 2026] [proxy_http:error] [pid 1033876:tid 1034119] [client 34.73.38.214:52867] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:58.813910 2026] [proxy:error] [pid 1033876:tid 1034119] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:58.813959 2026] [proxy_http:error] [pid 1033876:tid 1034119] [client 34.73.38.214:52867] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:58.872351 2026] [security2:error] [pid 1033876:tid 1034046] [client 14.225.17.146:64388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4aZUfjhWEjDbtLXL6SJAAAAKw"], referer: http://scott-assist.com/wp-old
[Mon Jul 20 06:53:59.218167 2026] [security2:error] [pid 1033876:tid 1034061] [client 161.118.218.103:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aZ0fjhWEjDbtLXL6SwgAAALs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:59.330826 2026] [security2:error] [pid 1033876:tid 1034057] [client 217.142.18.172:21170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aZ0fjhWEjDbtLXL6SxgAAALc"]
[Mon Jul 20 06:53:59.333982 2026] [security2:error] [pid 1033876:tid 1034057] [client 217.142.18.172:21170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4aZ0fjhWEjDbtLXL6SxgAAALc"]
[Mon Jul 20 06:53:59.683107 2026] [security2:error] [pid 1033876:tid 1034112] [client 104.234.53.81:37239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S0wAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:53:59.697535 2026] [security2:error] [pid 1033876:tid 1034035] [client 77.110.127.138:59085] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aZ0fjhWEjDbtLXL6S4wAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:59.703061 2026] [proxy:error] [pid 1033876:tid 1034103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:59.703129 2026] [proxy_http:error] [pid 1033876:tid 1034103] [client 34.73.38.214:53191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:59.703603 2026] [proxy:error] [pid 1033876:tid 1034103] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:53:59.703629 2026] [proxy_http:error] [pid 1033876:tid 1034103] [client 34.73.38.214:53191] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:53:59.757938 2026] [security2:error] [pid 1033876:tid 1034008] [client 158.173.166.181:21361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S6QAAAIY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:53:59.764725 2026] [security2:error] [pid 1033876:tid 1033951] [remote 84.247.172.23:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S6gAAjkk"]
[Mon Jul 20 06:53:59.797007 2026] [security2:error] [pid 1033876:tid 1034026] [client 161.118.218.103:60785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S7QAAAJg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:53:59.849331 2026] [security2:error] [pid 1033876:tid 1034120] [client 77.110.127.138:59087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S8gAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:59.849395 2026] [security2:error] [pid 1033876:tid 1034120] [client 77.110.127.138:59087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S8gAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:53:59.980161 2026] [security2:error] [pid 1033876:tid 1033984] [remote 84.247.172.23:58476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aZ0fjhWEjDbtLXL6TAQAA7Go"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:54:00.012295 2026] [security2:error] [pid 1033876:tid 1034113] [client 57.141.18.58:31374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aZEfjhWEjDbtLXL6RpgAA7xc"]
[Mon Jul 20 06:54:00.360843 2026] [security2:error] [pid 1033876:tid 1034051] [client 104.234.53.81:37239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aaEfjhWEjDbtLXL6THAAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:00.371711 2026] [security2:error] [pid 1033876:tid 1034089] [client 161.118.218.103:61232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aaEfjhWEjDbtLXL6THQAAANc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:00.627331 2026] [security2:error] [pid 1033876:tid 1034050] [client 34.73.38.214:63199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4aaEfjhWEjDbtLXL6TMAAAALA"]
[Mon Jul 20 06:54:00.710895 2026] [security2:error] [pid 1033876:tid 1034071] [client 185.243.112.137:49680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aaEfjhWEjDbtLXL6TOAAAAMU"]
[Mon Jul 20 06:54:00.880601 2026] [security2:error] [pid 1033876:tid 1034063] [client 185.243.112.137:49680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4aaEfjhWEjDbtLXL6TUQAAAL0"]
[Mon Jul 20 06:54:00.896473 2026] [security2:error] [pid 1033876:tid 1034023] [client 17.246.15.133:52976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.suretybonds-california.com"] [uri "/index.php"] [unique_id "al4aZ0fjhWEjDbtLXL6S7wAAlV8"]
[Mon Jul 20 06:54:00.917534 2026] [security2:error] [pid 1033876:tid 1034078] [client 14.225.17.146:62433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4aZkfjhWEjDbtLXL6SogAAAMw"]
[Mon Jul 20 06:54:00.950553 2026] [security2:error] [pid 1033876:tid 1034025] [client 161.118.218.103:61644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aaEfjhWEjDbtLXL6TVwAAAJc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:01.146494 2026] [security2:error] [pid 1033876:tid 1034054] [client 152.58.191.29:64273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6TagAAALQ"]
[Mon Jul 20 06:54:01.146621 2026] [security2:error] [pid 1033876:tid 1034054] [client 152.58.191.29:64273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6TagAAALQ"]
[Mon Jul 20 06:54:01.219213 2026] [security2:error] [pid 1033876:tid 1034099] [client 34.73.38.214:60968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4aaUfjhWEjDbtLXL6TdAAAAOE"]
[Mon Jul 20 06:54:01.289842 2026] [security2:error] [pid 1033876:tid 1034092] [client 192.140.149.97:44652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6TeAAAANo"]
[Mon Jul 20 06:54:01.289967 2026] [security2:error] [pid 1033876:tid 1034092] [client 192.140.149.97:44652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6TeAAAANo"]
[Mon Jul 20 06:54:01.537280 2026] [security2:error] [pid 1033876:tid 1034056] [client 161.118.218.103:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aaUfjhWEjDbtLXL6TlAAAALY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:01.576812 2026] [security2:error] [pid 1033876:tid 1034128] [client 103.238.106.162:42569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6TlgAAAP4"]
[Mon Jul 20 06:54:01.576919 2026] [security2:error] [pid 1033876:tid 1034128] [client 103.238.106.162:42569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6TlgAAAP4"]
[Mon Jul 20 06:54:01.747969 2026] [security2:error] [pid 1033876:tid 1034119] [client 122.183.32.225:8972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6ToQAAAPU"]
[Mon Jul 20 06:54:01.748059 2026] [security2:error] [pid 1033876:tid 1034119] [client 122.183.32.225:8972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4aaUfjhWEjDbtLXL6ToQAAAPU"]
[Mon Jul 20 06:54:01.892162 2026] [security2:error] [pid 1033876:tid 1034048] [client 34.73.38.214:59584] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4aaUfjhWEjDbtLXL6TsQAAAK4"]
[Mon Jul 20 06:54:02.112839 2026] [security2:error] [pid 1033876:tid 1034097] [client 161.118.218.103:62453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aakfjhWEjDbtLXL6TvQAAAN8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:02.545964 2026] [security2:error] [pid 1033876:tid 1033899] [remote 91.142.222.105:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4aakfjhWEjDbtLXL6T1QAA_hU"]
[Mon Jul 20 06:54:02.687070 2026] [security2:error] [pid 1033876:tid 1034044] [client 161.118.218.103:62827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aakfjhWEjDbtLXL6T6AAAAKo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:02.708505 2026] [security2:error] [pid 1033876:tid 1034125] [client 34.73.38.214:60498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4aakfjhWEjDbtLXL6T6gAAAPs"]
[Mon Jul 20 06:54:02.772862 2026] [security2:error] [pid 1033876:tid 1034088] [client 104.234.53.53:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aakfjhWEjDbtLXL6T7wAAANY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:02.894400 2026] [security2:error] [pid 1033876:tid 1034034] [client 185.243.112.137:49818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aakfjhWEjDbtLXL6T-gAAAKA"]
[Mon Jul 20 06:54:02.947220 2026] [security2:error] [pid 1033876:tid 1034091] [client 77.110.127.138:59097] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aakfjhWEjDbtLXL6T_AAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:02.975536 2026] [security2:error] [pid 1033876:tid 1033906] [remote 91.142.222.105:56464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4aakfjhWEjDbtLXL6T_wAAixw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:54:02.988512 2026] [security2:error] [pid 1033876:tid 1034108] [client 57.141.18.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4aakfjhWEjDbtLXL6T7gAAAOo"]
[Mon Jul 20 06:54:03.044708 2026] [autoindex:error] [pid 1033876:tid 1034050] [client 34.23.167.213:0] AH01276: Cannot serve directory /home4/fbjwyymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:54:03.048593 2026] [security2:error] [pid 1033876:tid 1033969] [remote 84.247.172.23:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aa0fjhWEjDbtLXL6UBQAA7Fs"]
[Mon Jul 20 06:54:03.061224 2026] [security2:error] [pid 1033876:tid 1034054] [client 185.243.112.137:49818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4aa0fjhWEjDbtLXL6UBgAAALQ"]
[Mon Jul 20 06:54:03.237536 2026] [security2:error] [pid 1033876:tid 1034089] [client 34.73.38.214:62042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4aa0fjhWEjDbtLXL6UIAAAANc"]
[Mon Jul 20 06:54:03.246266 2026] [security2:error] [pid 1033876:tid 1034024] [client 14.225.17.146:62225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4aaUfjhWEjDbtLXL6TdwAAAJY"], referer: http://itdynamix.com/wp-old
[Mon Jul 20 06:54:03.266636 2026] [security2:error] [pid 1033876:tid 1034130] [client 161.118.218.103:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aa0fjhWEjDbtLXL6UIwAAAQA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:03.309122 2026] [security2:error] [pid 1033876:tid 1033939] [remote 188.166.241.141:53888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aa0fjhWEjDbtLXL6UJQAAqT0"]
[Mon Jul 20 06:54:03.423303 2026] [security2:error] [pid 1033876:tid 1033908] [remote 84.247.172.23:55606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aa0fjhWEjDbtLXL6UKwAAjR4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:54:03.689767 2026] [security2:error] [pid 1033876:tid 1033957] [remote 188.166.241.141:53888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4aa0fjhWEjDbtLXL6UNgAAv08"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:54:03.769697 2026] [security2:error] [pid 1033876:tid 1034012] [client 34.73.38.214:62048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aa0fjhWEjDbtLXL6UQgAAAIo"]
[Mon Jul 20 06:54:03.841022 2026] [security2:error] [pid 1033876:tid 1034056] [client 161.118.218.103:63602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aa0fjhWEjDbtLXL6USAAAALY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:03.870313 2026] [security2:error] [pid 1033876:tid 1034093] [client 103.125.179.95:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aa0fjhWEjDbtLXL6USwAAANs"]
[Mon Jul 20 06:54:03.870786 2026] [security2:error] [pid 1033876:tid 1034093] [client 103.125.179.95:62120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aa0fjhWEjDbtLXL6USwAAANs"]
[Mon Jul 20 06:54:04.024851 2026] [security2:error] [pid 1033876:tid 1034013] [client 187.108.85.186:49614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4abEfjhWEjDbtLXL6UVQAAAIs"]
[Mon Jul 20 06:54:04.024970 2026] [security2:error] [pid 1033876:tid 1034013] [client 187.108.85.186:49614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4abEfjhWEjDbtLXL6UVQAAAIs"]
[Mon Jul 20 06:54:04.103862 2026] [security2:error] [pid 1033876:tid 1034090] [client 77.110.127.138:59101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4abEfjhWEjDbtLXL6UWgAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:04.103990 2026] [security2:error] [pid 1033876:tid 1034090] [client 77.110.127.138:59101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4abEfjhWEjDbtLXL6UWgAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:04.299609 2026] [security2:error] [pid 1033876:tid 1034024] [client 14.225.17.146:59230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4abEfjhWEjDbtLXL6UXgAAAJY"], referer: https://itdynamix.com/wp-old
[Mon Jul 20 06:54:04.304988 2026] [security2:error] [pid 1033876:tid 1034065] [client 77.110.127.138:59102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4abEfjhWEjDbtLXL6UaQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:04.309992 2026] [security2:error] [pid 1033876:tid 1034021] [client 50.116.65.227:60900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4abEfjhWEjDbtLXL6UagAAAJM"]
[Mon Jul 20 06:54:04.321721 2026] [security2:error] [pid 1033876:tid 1034071] [client 50.116.65.227:25706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4abEfjhWEjDbtLXL6UbAAAAMU"]
[Mon Jul 20 06:54:04.412201 2026] [security2:error] [pid 1033876:tid 1034047] [client 14.225.17.146:57394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4abEfjhWEjDbtLXL6UYwAAAK0"], referer: http://headachescarpaltunnelfibromyalgia.com/wp-old
[Mon Jul 20 06:54:04.416653 2026] [security2:error] [pid 1033876:tid 1034019] [client 161.118.218.103:63994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4abEfjhWEjDbtLXL6UeAAAAJE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:04.501763 2026] [security2:error] [pid 1033876:tid 1034039] [client 47.128.122.225:35846] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "christiancountytrumpet.com"] [uri "/robots.txt"] [unique_id "al4abEfjhWEjDbtLXL6UggAAAKU"]
[Mon Jul 20 06:54:04.562240 2026] [security2:error] [pid 1033876:tid 1034067] [client 185.243.112.137:49909] ModSecurity: Access denied with code 400 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "67"] [id "390703"] [rev "5"] [msg "Atomicorp.com WAF Rules: Possible URL Encoding Abuse Attack Attempt"] [severity "NOTICE"] [hostname "zonemist.com"] [uri "/cgi-bin/.%%%2%e/.%%%2%e/.%%%2%e/.%%%2%e/.%%%2%e/bin/sh"] [unique_id "al4abEfjhWEjDbtLXL6UhgAAAME"]
[Mon Jul 20 06:54:04.570030 2026] [security2:error] [pid 1033876:tid 1034067] [client 185.243.112.137:49909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4abEfjhWEjDbtLXL6UhgAAAME"]
[Mon Jul 20 06:54:04.620500 2026] [security2:error] [pid 1033876:tid 1034123] [client 34.73.38.214:52511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4abEfjhWEjDbtLXL6UjAAAAPk"]
[Mon Jul 20 06:54:04.645920 2026] [core:error] [pid 1033876:tid 1034065] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:04.645939 2026] [core:error] [pid 1033876:tid 1034065] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:04.996858 2026] [security2:error] [pid 1033876:tid 1034050] [client 161.118.218.103:64304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4abEfjhWEjDbtLXL6UpAAAALA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:05.201586 2026] [security2:error] [pid 1033876:tid 1034042] [client 34.73.38.214:54199] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4abUfjhWEjDbtLXL6UuAAAAKg"]
[Mon Jul 20 06:54:05.303992 2026] [security2:error] [pid 1033876:tid 1034018] [client 117.247.108.24:49166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4abUfjhWEjDbtLXL6UvwAAAJA"]
[Mon Jul 20 06:54:05.304123 2026] [security2:error] [pid 1033876:tid 1034018] [client 117.247.108.24:49166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4abUfjhWEjDbtLXL6UvwAAAJA"]
[Mon Jul 20 06:54:05.521697 2026] [security2:error] [pid 1033876:tid 1034085] [client 57.141.18.30:56814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aaUfjhWEjDbtLXL6TqwAA0xg"]
[Mon Jul 20 06:54:05.534171 2026] [security2:error] [pid 1033876:tid 1034123] [client 185.243.112.137:50023] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/cgi-sys/404.html"] [unique_id "al4abUfjhWEjDbtLXL6U0AAAAPk"]
[Mon Jul 20 06:54:05.557743 2026] [security2:error] [pid 1033876:tid 1034031] [client 14.225.17.146:63900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4abUfjhWEjDbtLXL6UugAAAJ0"], referer: http://nextlevelpressurewashing.com/wp-old
[Mon Jul 20 06:54:05.570953 2026] [security2:error] [pid 1033876:tid 1034101] [client 161.118.218.103:64630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4abUfjhWEjDbtLXL6U0wAAAOM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:05.857144 2026] [security2:error] [pid 1033876:tid 1034012] [client 34.73.38.214:57521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4abUfjhWEjDbtLXL6U5wAAAIo"]
[Mon Jul 20 06:54:06.145956 2026] [security2:error] [pid 1033876:tid 1034008] [client 161.118.218.103:65000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4abkfjhWEjDbtLXL6VBgAAAIY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:06.188286 2026] [security2:error] [pid 1033876:tid 1034034] [client 14.225.17.146:63953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4abkfjhWEjDbtLXL6VBAAAAKA"], referer: http://ancestralidadytrance.space/wp-old
[Mon Jul 20 06:54:06.271182 2026] [autoindex:error] [pid 1033876:tid 1034049] [client 176.125.229.25:53324] AH01276: Cannot serve directory /home3/kybxxpmy/public_html/website_0ad88c1f/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:54:06.337329 2026] [security2:error] [pid 1033876:tid 1034056] [client 185.243.112.137:50137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4abkfjhWEjDbtLXL6VFwAAALY"]
[Mon Jul 20 06:54:06.525759 2026] [security2:error] [pid 1033876:tid 1034033] [client 185.243.112.137:50137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4abkfjhWEjDbtLXL6VIgAAAJ8"]
[Mon Jul 20 06:54:06.542446 2026] [security2:error] [pid 1033876:tid 1034100] [client 34.73.38.214:52997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4abkfjhWEjDbtLXL6VJQAAAOI"]
[Mon Jul 20 06:54:06.600683 2026] [security2:error] [pid 1033876:tid 1034021] [client 14.225.17.146:60440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4abkfjhWEjDbtLXL6VCQAAAJM"], referer: http://uritems.net/wp-old
[Mon Jul 20 06:54:06.722295 2026] [security2:error] [pid 1033876:tid 1034090] [client 161.118.218.103:65384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4abkfjhWEjDbtLXL6VNAAAANg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:06.910063 2026] [security2:error] [pid 1033876:tid 1034010] [client 117.222.139.248:57355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4abkfjhWEjDbtLXL6VPgAAAIg"]
[Mon Jul 20 06:54:06.910221 2026] [security2:error] [pid 1033876:tid 1034010] [client 117.222.139.248:57355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4abkfjhWEjDbtLXL6VPgAAAIg"]
[Mon Jul 20 06:54:07.181439 2026] [security2:error] [pid 1033876:tid 1034024] [client 34.73.38.214:49610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.wcn.ktk.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4ab0fjhWEjDbtLXL6VVAAAAJY"]
[Mon Jul 20 06:54:07.259362 2026] [security2:error] [pid 1033876:tid 1033917] [remote 100.42.189.89:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4ab0fjhWEjDbtLXL6VXAABAyc"]
[Mon Jul 20 06:54:07.296902 2026] [security2:error] [pid 1033876:tid 1034025] [client 161.118.218.103:49401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ab0fjhWEjDbtLXL6VZQAAAJc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:07.442054 2026] [security2:error] [pid 1033876:tid 1033888] [remote 100.42.189.89:37774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4ab0fjhWEjDbtLXL6VawAAyAo"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 06:54:07.488083 2026] [security2:error] [pid 1033876:tid 1034039] [client 185.243.112.137:50262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4ab0fjhWEjDbtLXL6VcAAAAKU"]
[Mon Jul 20 06:54:07.665122 2026] [security2:error] [pid 1033876:tid 1034062] [client 185.243.112.137:50262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4ab0fjhWEjDbtLXL6VgwAAALw"]
[Mon Jul 20 06:54:07.875387 2026] [security2:error] [pid 1033876:tid 1034117] [client 161.118.218.103:49854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ab0fjhWEjDbtLXL6VkgAAAPM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:07.924889 2026] [security2:error] [pid 1033876:tid 1034101] [client 57.141.18.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ab0fjhWEjDbtLXL6VjgAAAOM"]
[Mon Jul 20 06:54:07.951210 2026] [security2:error] [pid 1033876:tid 1034026] [client 14.225.17.146:64110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4abUfjhWEjDbtLXL6U5gAAAJg"], referer: http://younutrition.gr/wp-old
[Mon Jul 20 06:54:07.964341 2026] [security2:error] [pid 1033876:tid 1034064] [client 104.234.53.81:49171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ab0fjhWEjDbtLXL6VlwAAAL4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:08.033705 2026] [security2:error] [pid 1033876:tid 1034115] [client 77.110.127.138:59139] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4acEfjhWEjDbtLXL6VpAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:08.243027 2026] [security2:error] [pid 1033876:tid 1034033] [client 158.173.89.95:37565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4acEfjhWEjDbtLXL6VvAAAAJ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:54:08.245185 2026] [security2:error] [pid 1033876:tid 1033934] [remote 57.141.18.117:20354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4acEfjhWEjDbtLXL6VuwAA8Dg"]
[Mon Jul 20 06:54:08.449624 2026] [security2:error] [pid 1033876:tid 1034094] [client 161.118.218.103:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4acEfjhWEjDbtLXL6VzAAAANw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:08.691548 2026] [security2:error] [pid 1033876:tid 1034103] [client 14.225.17.146:60532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4abkfjhWEjDbtLXL6VFgAAAOU"], referer: http://healthylifegourmet.org/wp-old
[Mon Jul 20 06:54:08.724316 2026] [security2:error] [pid 1033876:tid 1034065] [client 152.58.191.29:64726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4acEfjhWEjDbtLXL6V6QAAAL8"]
[Mon Jul 20 06:54:08.727952 2026] [security2:error] [pid 1033876:tid 1034065] [client 152.58.191.29:64726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4acEfjhWEjDbtLXL6V6QAAAL8"]
[Mon Jul 20 06:54:08.764634 2026] [security2:error] [pid 1033876:tid 1034063] [client 14.225.17.146:64020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4ab0fjhWEjDbtLXL6VjwAAAL0"], referer: http://claysharecon.com/wp-old
[Mon Jul 20 06:54:08.941289 2026] [security2:error] [pid 1033876:tid 1034041] [client 185.243.112.137:50400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4acEfjhWEjDbtLXL6V9gAAAKc"]
[Mon Jul 20 06:54:09.002932 2026] [security2:error] [pid 1033876:tid 1034011] [client 14.225.17.146:60464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4acEfjhWEjDbtLXL6V7gAAAIk"], referer: http://slutilities.com/wp-old
[Mon Jul 20 06:54:09.024917 2026] [security2:error] [pid 1033876:tid 1034016] [client 161.118.218.103:50689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4acUfjhWEjDbtLXL6WAAAAAI4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:09.096271 2026] [security2:error] [pid 1033876:tid 1034047] [client 63.179.149.246:40928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4acUfjhWEjDbtLXL6WBgAAAK0"]
[Mon Jul 20 06:54:09.145501 2026] [security2:error] [pid 1033876:tid 1034099] [client 185.243.112.137:50400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4acUfjhWEjDbtLXL6WEQAAAOE"]
[Mon Jul 20 06:54:09.204184 2026] [security2:error] [pid 1033876:tid 1034045] [client 104.234.53.81:49171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4acUfjhWEjDbtLXL6WGQAAAKs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:09.315660 2026] [security2:error] [pid 1033876:tid 1034027] [client 14.225.17.146:63829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4acUfjhWEjDbtLXL6WCwAAAJk"], referer: http://sesamegreenbeans.com/wp-old
[Mon Jul 20 06:54:09.350066 2026] [security2:error] [pid 1033876:tid 1034075] [client 14.225.17.146:63964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4ab0fjhWEjDbtLXL6VjQAAAMk"], referer: http://olearyplumbingllc.com/wp-old
[Mon Jul 20 06:54:09.600968 2026] [security2:error] [pid 1033876:tid 1034055] [client 161.118.218.103:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4acUfjhWEjDbtLXL6WNgAAALU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:09.609186 2026] [security2:error] [pid 1033876:tid 1034059] [client 3.75.183.99:19082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4acUfjhWEjDbtLXL6WNQAAALk"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:54:09.664408 2026] [security2:error] [pid 1033876:tid 1034083] [client 74.7.228.42:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "greenvillemoving.com"] [uri "/robots.txt"] [unique_id "al4acUfjhWEjDbtLXL6WQAAAANE"], referer: https://greenvillemoving.co/robots.txt
[Mon Jul 20 06:54:09.668723 2026] [security2:error] [pid 1033876:tid 1034105] [client 74.7.228.42:57992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "greenvillemoving.com"] [uri "/robots.txt"] [unique_id "al4acUfjhWEjDbtLXL6WOgAA51w"], referer: https://greenvillemoving.co/robots.txt
[Mon Jul 20 06:54:09.760902 2026] [security2:error] [pid 1033876:tid 1034036] [client 14.225.17.146:60460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4acUfjhWEjDbtLXL6WMQAAAKI"]
[Mon Jul 20 06:54:09.772675 2026] [security2:error] [pid 1033876:tid 1034026] [client 66.249.68.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lowelldrycleaners.com"] [uri "/index.php"] [unique_id "al4acEfjhWEjDbtLXL6V1QAAmGo"]
[Mon Jul 20 06:54:09.842283 2026] [security2:error] [pid 1033876:tid 1034088] [client 185.243.112.137:50558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4acUfjhWEjDbtLXL6WSwAAANY"]
[Mon Jul 20 06:54:09.868654 2026] [security2:error] [pid 1033876:tid 1034064] [client 217.142.18.172:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4acUfjhWEjDbtLXL6WTQAAAL4"]
[Mon Jul 20 06:54:09.868766 2026] [security2:error] [pid 1033876:tid 1034064] [client 217.142.18.172:63377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4acUfjhWEjDbtLXL6WTQAAAL4"]
[Mon Jul 20 06:54:10.008582 2026] [security2:error] [pid 1033876:tid 1034017] [client 185.243.112.137:50558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4ackfjhWEjDbtLXL6WVwAAAI8"]
[Mon Jul 20 06:54:10.172859 2026] [security2:error] [pid 1033876:tid 1034100] [client 77.110.127.138:59154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ackfjhWEjDbtLXL6WbQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:10.172972 2026] [security2:error] [pid 1033876:tid 1034100] [client 77.110.127.138:59154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ackfjhWEjDbtLXL6WbQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:10.176440 2026] [security2:error] [pid 1033876:tid 1034110] [client 161.118.218.103:51477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ackfjhWEjDbtLXL6WbwAAAOw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:10.181652 2026] [security2:error] [pid 1033876:tid 1033892] [remote 162.19.86.63:50506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ackfjhWEjDbtLXL6WcAAAzA4"]
[Mon Jul 20 06:54:10.181807 2026] [security2:error] [pid 1033876:tid 1034078] [client 162.19.86.63:50506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ackfjhWEjDbtLXL6WcAAAzA4"]
[Mon Jul 20 06:54:10.314059 2026] [security2:error] [pid 1033876:tid 1034008] [client 14.225.17.146:64136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4ackfjhWEjDbtLXL6WWgAAAIY"], referer: http://grecruit.online/wp-old
[Mon Jul 20 06:54:10.330337 2026] [security2:error] [pid 1033876:tid 1034012] [client 197.186.66.42:52843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ackfjhWEjDbtLXL6WegAAAIo"]
[Mon Jul 20 06:54:10.338643 2026] [security2:error] [pid 1033876:tid 1034052] [client 14.225.17.146:60749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ackfjhWEjDbtLXL6WawAAALI"], referer: https://sesamegreenbeans.com/wp-old
[Mon Jul 20 06:54:10.347991 2026] [security2:error] [pid 1033876:tid 1034012] [client 197.186.66.42:52843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ackfjhWEjDbtLXL6WegAAAIo"]
[Mon Jul 20 06:54:10.404783 2026] [security2:error] [pid 1033876:tid 1034029] [client 45.157.112.60:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ackfjhWEjDbtLXL6WfwAAAJs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:54:10.743164 2026] [security2:error] [pid 1033876:tid 1034091] [client 57.141.18.98:50260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ab0fjhWEjDbtLXL6VaQAA2Rs"]
[Mon Jul 20 06:54:10.754773 2026] [security2:error] [pid 1033876:tid 1034123] [client 161.118.218.103:51887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ackfjhWEjDbtLXL6WqAAAAPk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:10.797023 2026] [security2:error] [pid 1033876:tid 1034072] [client 14.225.17.146:52102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ackfjhWEjDbtLXL6WkgAAAMY"], referer: http://falconarrowshop.com/wp-old
[Mon Jul 20 06:54:11.017803 2026] [security2:error] [pid 1033876:tid 1034100] [client 44.245.170.32:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4ac0fjhWEjDbtLXL6WwAAAAOI"]
[Mon Jul 20 06:54:11.116148 2026] [security2:error] [pid 1033876:tid 1034057] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/.env"] [unique_id "al4ac0fjhWEjDbtLXL6WxwAAALc"]
[Mon Jul 20 06:54:11.116304 2026] [security2:error] [pid 1033876:tid 1034057] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/.env"] [unique_id "al4ac0fjhWEjDbtLXL6WxwAAALc"]
[Mon Jul 20 06:54:11.170678 2026] [security2:error] [pid 1033876:tid 1034096] [client 14.225.17.146:64056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4acUfjhWEjDbtLXL6WTgAAAN4"], referer: http://effingweirdmuseums.com/wp-old
[Mon Jul 20 06:54:11.279412 2026] [security2:error] [pid 1033876:tid 1034059] [client 14.224.227.113:54776] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ac0fjhWEjDbtLXL6W1gAAALk"]
[Mon Jul 20 06:54:11.287987 2026] [security2:error] [pid 1033876:tid 1034081] [client 52.233.165.60:4929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ac0fjhWEjDbtLXL6W1QAAAM8"]
[Mon Jul 20 06:54:11.312630 2026] [security2:error] [pid 1033876:tid 1034023] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4ac0fjhWEjDbtLXL6W1wAAAJU"]
[Mon Jul 20 06:54:11.330910 2026] [security2:error] [pid 1033876:tid 1034091] [client 161.118.218.103:52221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ac0fjhWEjDbtLXL6W2QAAANk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:11.341032 2026] [security2:error] [pid 1033876:tid 1034004] [remote 202.51.202.242:34542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ac0fjhWEjDbtLXL6W2AAA0H4"]
[Mon Jul 20 06:54:11.417197 2026] [security2:error] [pid 1033876:tid 1034107] [client 104.207.61.42:33997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ac0fjhWEjDbtLXL6W2wAAAOk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:54:11.436655 2026] [security2:error] [pid 1033876:tid 1034020] [client 52.233.165.60:4929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ac0fjhWEjDbtLXL6W4AAAAJI"]
[Mon Jul 20 06:54:11.486248 2026] [security2:error] [pid 1033876:tid 1034048] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4ac0fjhWEjDbtLXL6W4gAAAK4"]
[Mon Jul 20 06:54:11.628223 2026] [security2:error] [pid 1033876:tid 1033899] [remote 130.185.118.215:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ac0fjhWEjDbtLXL6W8AAAtRU"]
[Mon Jul 20 06:54:11.826491 2026] [security2:error] [pid 1033876:tid 1033890] [remote 130.185.118.215:38280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ac0fjhWEjDbtLXL6XBAAApQw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:54:11.877359 2026] [security2:error] [pid 1033876:tid 1033925] [remote 41.185.8.147:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ac0fjhWEjDbtLXL6XBwAAni8"]
[Mon Jul 20 06:54:11.904963 2026] [security2:error] [pid 1033876:tid 1034122] [client 122.183.32.225:13575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ac0fjhWEjDbtLXL6XCgAAAPg"]
[Mon Jul 20 06:54:11.905083 2026] [security2:error] [pid 1033876:tid 1034122] [client 122.183.32.225:13575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ac0fjhWEjDbtLXL6XCgAAAPg"]
[Mon Jul 20 06:54:11.913533 2026] [security2:error] [pid 1033876:tid 1034071] [client 161.118.218.103:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ac0fjhWEjDbtLXL6XCwAAAMU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:11.928140 2026] [security2:error] [pid 1033876:tid 1034019] [client 192.140.149.97:44807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ac0fjhWEjDbtLXL6XDAAAAJE"]
[Mon Jul 20 06:54:11.928238 2026] [security2:error] [pid 1033876:tid 1034019] [client 192.140.149.97:44807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ac0fjhWEjDbtLXL6XDAAAAJE"]
[Mon Jul 20 06:54:12.049766 2026] [security2:error] [pid 1033876:tid 1034010] [client 103.238.106.162:42623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4adEfjhWEjDbtLXL6XGAAAAIg"]
[Mon Jul 20 06:54:12.049974 2026] [security2:error] [pid 1033876:tid 1034010] [client 103.238.106.162:42623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4adEfjhWEjDbtLXL6XGAAAAIg"]
[Mon Jul 20 06:54:12.107641 2026] [security2:error] [pid 1033876:tid 1034044] [client 14.225.17.146:60356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4adEfjhWEjDbtLXL6XFQAAAKo"], referer: https://effingweirdmuseums.com/wp-old
[Mon Jul 20 06:54:12.231909 2026] [security2:error] [pid 1033876:tid 1034015] [client 104.207.42.64:16321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4adEfjhWEjDbtLXL6XJgAAAI0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:54:12.364857 2026] [security2:error] [pid 1033876:tid 1033911] [remote 41.185.8.147:43268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4adEfjhWEjDbtLXL6XOAAAlSE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:54:12.368066 2026] [security2:error] [pid 1033876:tid 1034041] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/application/.env"] [unique_id "al4adEfjhWEjDbtLXL6XOQAAAKc"]
[Mon Jul 20 06:54:12.368180 2026] [security2:error] [pid 1033876:tid 1034041] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/application/.env"] [unique_id "al4adEfjhWEjDbtLXL6XOQAAAKc"]
[Mon Jul 20 06:54:12.488177 2026] [security2:error] [pid 1033876:tid 1034021] [client 161.118.218.103:52935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4adEfjhWEjDbtLXL6XQgAAAJM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:12.710292 2026] [security2:error] [pid 1033876:tid 1034011] [client 14.225.17.146:60407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4ackfjhWEjDbtLXL6WsQAAAIk"], referer: http://narv.co/wp-old
[Mon Jul 20 06:54:12.717137 2026] [security2:error] [pid 1033876:tid 1034101] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/prod/.env"] [unique_id "al4adEfjhWEjDbtLXL6XXAAAAOM"]
[Mon Jul 20 06:54:12.717272 2026] [security2:error] [pid 1033876:tid 1034101] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/prod/.env"] [unique_id "al4adEfjhWEjDbtLXL6XXAAAAOM"]
[Mon Jul 20 06:54:13.025047 2026] [security2:error] [pid 1033876:tid 1034118] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4adUfjhWEjDbtLXL6XcwAAAPQ"]
[Mon Jul 20 06:54:13.034536 2026] [security2:error] [pid 1033876:tid 1033916] [remote 202.51.202.242:34542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4adUfjhWEjDbtLXL6XdAAA1SY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:54:13.062544 2026] [security2:error] [pid 1033876:tid 1034017] [client 161.118.218.103:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4adUfjhWEjDbtLXL6XdgAAAI8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:13.137992 2026] [security2:error] [pid 1033876:tid 1034083] [client 77.110.127.138:59172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4adUfjhWEjDbtLXL6XfQAAANE"]
[Mon Jul 20 06:54:13.170578 2026] [security2:error] [pid 1033876:tid 1034112] [client 98.159.234.160:39953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4adUfjhWEjDbtLXL6XggAAAO4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:54:13.196577 2026] [security2:error] [pid 1033876:tid 1034077] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4adUfjhWEjDbtLXL6XhQAAAMs"]
[Mon Jul 20 06:54:13.642540 2026] [security2:error] [pid 1033876:tid 1034130] [client 161.118.218.103:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4adUfjhWEjDbtLXL6XoQAAAQA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:13.642858 2026] [security2:error] [pid 1033876:tid 1034013] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/beta/.env"] [unique_id "al4adUfjhWEjDbtLXL6XoAAAAIs"]
[Mon Jul 20 06:54:13.643005 2026] [security2:error] [pid 1033876:tid 1034013] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/beta/.env"] [unique_id "al4adUfjhWEjDbtLXL6XoAAAAIs"]
[Mon Jul 20 06:54:13.684151 2026] [security2:error] [pid 1033876:tid 1034012] [client 65.111.28.196:25223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4adUfjhWEjDbtLXL6XngAAAIo"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:54:13.734585 2026] [security2:error] [pid 1033876:tid 1034026] [client 14.225.17.146:65296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4adUfjhWEjDbtLXL6XmgAAAJg"], referer: https://narv.co/wp-old
[Mon Jul 20 06:54:13.868854 2026] [security2:error] [pid 1033876:tid 1034072] [client 77.110.127.138:59174] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 646 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4adUfjhWEjDbtLXL6XvAAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:14.053489 2026] [security2:error] [pid 1033876:tid 1034105] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4adkfjhWEjDbtLXL6X1QAAAOc"]
[Mon Jul 20 06:54:14.220469 2026] [security2:error] [pid 1033876:tid 1034132] [client 161.118.218.103:54275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4adkfjhWEjDbtLXL6X8AAAAQI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:14.238217 2026] [security2:error] [pid 1033876:tid 1034088] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4adkfjhWEjDbtLXL6X8gAAANY"]
[Mon Jul 20 06:54:14.478123 2026] [security2:error] [pid 1033876:tid 1034046] [client 77.110.127.138:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4adkfjhWEjDbtLXL6YCwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:14.478275 2026] [security2:error] [pid 1033876:tid 1034046] [client 77.110.127.138:59176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4adkfjhWEjDbtLXL6YCwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:14.507072 2026] [security2:error] [pid 1033876:tid 1034048] [client 45.3.54.13:19609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4adkfjhWEjDbtLXL6YDAAAAK4"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:14.528217 2026] [security2:error] [pid 1033876:tid 1034042] [client 103.125.179.95:62636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4adkfjhWEjDbtLXL6YEgAAAKg"]
[Mon Jul 20 06:54:14.528359 2026] [security2:error] [pid 1033876:tid 1034042] [client 103.125.179.95:62636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4adkfjhWEjDbtLXL6YEgAAAKg"]
[Mon Jul 20 06:54:14.603225 2026] [security2:error] [pid 1033876:tid 1034089] [client 104.234.53.84:46555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4adkfjhWEjDbtLXL6YFgAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:14.604503 2026] [security2:error] [pid 1033876:tid 1034107] [client 65.111.5.144:15363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.5.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4adkfjhWEjDbtLXL6YFQAAAOk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:54:14.611303 2026] [security2:error] [pid 1033876:tid 1034121] [client 14.225.17.146:65160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4adUfjhWEjDbtLXL6XiAAAAPc"], referer: http://betterbonddogtraining.com/wp-old
[Mon Jul 20 06:54:14.649418 2026] [security2:error] [pid 1033876:tid 1034126] [client 14.225.17.146:57442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4adUfjhWEjDbtLXL6XgQAAAPw"], referer: http://eduardsales.com/wp-old
[Mon Jul 20 06:54:14.657891 2026] [security2:error] [pid 1033876:tid 1034123] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/app/.env"] [unique_id "al4adkfjhWEjDbtLXL6YHAAAAPk"]
[Mon Jul 20 06:54:14.658027 2026] [security2:error] [pid 1033876:tid 1034123] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/app/.env"] [unique_id "al4adkfjhWEjDbtLXL6YHAAAAPk"]
[Mon Jul 20 06:54:14.799331 2026] [security2:error] [pid 1033876:tid 1034092] [client 161.118.218.103:54706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4adkfjhWEjDbtLXL6YJAAAANo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:14.906130 2026] [security2:error] [pid 1033876:tid 1034064] [client 187.108.85.186:50166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4adkfjhWEjDbtLXL6YKQAAAL4"]
[Mon Jul 20 06:54:14.906256 2026] [security2:error] [pid 1033876:tid 1034064] [client 187.108.85.186:50166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4adkfjhWEjDbtLXL6YKQAAAL4"]
[Mon Jul 20 06:54:14.980721 2026] [security2:error] [pid 1033876:tid 1034007] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/config/.env"] [unique_id "al4adkfjhWEjDbtLXL6YMgAAAIU"]
[Mon Jul 20 06:54:14.980849 2026] [security2:error] [pid 1033876:tid 1034007] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/config/.env"] [unique_id "al4adkfjhWEjDbtLXL6YMgAAAIU"]
[Mon Jul 20 06:54:15.059483 2026] [security2:error] [pid 1033876:tid 1034027] [client 104.207.51.56:57127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ad0fjhWEjDbtLXL6YNgAAAJk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:15.322523 2026] [security2:error] [pid 1033876:tid 1034017] [client 24.199.115.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cathybuffini.com"] [uri "/index.php"] [unique_id "al4ad0fjhWEjDbtLXL6YUAAAAI8"], referer: http://cathybuffini.com/
[Mon Jul 20 06:54:15.376162 2026] [security2:error] [pid 1033876:tid 1034123] [client 161.118.218.103:55173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ad0fjhWEjDbtLXL6YXAAAAPk"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:15.430092 2026] [security2:error] [pid 1033876:tid 1034014] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/api/.env"] [unique_id "al4ad0fjhWEjDbtLXL6YYgAAAIw"]
[Mon Jul 20 06:54:15.430213 2026] [security2:error] [pid 1033876:tid 1034014] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/api/.env"] [unique_id "al4ad0fjhWEjDbtLXL6YYgAAAIw"]
[Mon Jul 20 06:54:15.554603 2026] [core:error] [pid 1033876:tid 1034060] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:15.554622 2026] [core:error] [pid 1033876:tid 1034060] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:15.949416 2026] [security2:error] [pid 1033876:tid 1034128] [client 161.118.218.103:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ad0fjhWEjDbtLXL6YnQAAAP4"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:15.980949 2026] [security2:error] [pid 1033876:tid 1034076] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/laravel/.env"] [unique_id "al4ad0fjhWEjDbtLXL6YoQAAAMo"]
[Mon Jul 20 06:54:15.981108 2026] [security2:error] [pid 1033876:tid 1034076] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/laravel/.env"] [unique_id "al4ad0fjhWEjDbtLXL6YoQAAAMo"]
[Mon Jul 20 06:54:16.050136 2026] [security2:error] [pid 1033876:tid 1034064] [client 24.199.115.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cathybuffini.com"] [uri "/index.php"] [unique_id "al4aeEfjhWEjDbtLXL6YpAAAAL4"], referer: https://cathybuffini.com/
[Mon Jul 20 06:54:16.092497 2026] [security2:error] [pid 1033876:tid 1034115] [client 104.234.53.48:54455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aeEfjhWEjDbtLXL6YqQAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:16.301866 2026] [security2:error] [pid 1033876:tid 1034071] [client 15.204.114.164:25478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "omegacompass.com"] [uri "/"] [unique_id "al4aeEfjhWEjDbtLXL6YwQAAAMU"]
[Mon Jul 20 06:54:16.525122 2026] [security2:error] [pid 1033876:tid 1034035] [client 161.118.218.103:56057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aeEfjhWEjDbtLXL6YzAAAAKE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:16.564573 2026] [security2:error] [pid 1033876:tid 1034043] [client 14.225.17.146:49957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4adkfjhWEjDbtLXL6YKwAAAKk"], referer: http://nwcarvingacademy.com/wp-old
[Mon Jul 20 06:54:16.673390 2026] [security2:error] [pid 1033876:tid 1034082] [client 50.116.65.227:49550] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aeEfjhWEjDbtLXL6Y5QAAANA"]
[Mon Jul 20 06:54:16.681722 2026] [security2:error] [pid 1033876:tid 1034101] [client 50.116.65.227:49566] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aeEfjhWEjDbtLXL6Y5gAAAOM"]
[Mon Jul 20 06:54:16.783372 2026] [security2:error] [pid 1033876:tid 1034049] [client 193.37.252.163:41326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.252.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4aeEfjhWEjDbtLXL6Y8wAAAK8"]
[Mon Jul 20 06:54:16.783447 2026] [security2:error] [pid 1033876:tid 1034049] [client 193.37.252.163:41326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4aeEfjhWEjDbtLXL6Y8wAAAK8"]
[Mon Jul 20 06:54:16.870257 2026] [security2:error] [pid 1033876:tid 1034083] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aeEfjhWEjDbtLXL6Y9gAAANE"]
[Mon Jul 20 06:54:17.037544 2026] [security2:error] [pid 1033876:tid 1034098] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4aeUfjhWEjDbtLXL6ZAQAAAOA"]
[Mon Jul 20 06:54:17.098729 2026] [security2:error] [pid 1033876:tid 1034094] [client 161.118.218.103:56466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZCgAAANw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:17.273999 2026] [security2:error] [pid 1033876:tid 1033943] [remote 217.61.143.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZHAAA10E"]
[Mon Jul 20 06:54:17.326071 2026] [security2:error] [pid 1033876:tid 1034021] [client 15.204.114.164:25480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "omegaecho.com"] [uri "/"] [unique_id "al4aeUfjhWEjDbtLXL6ZHgAAAJM"]
[Mon Jul 20 06:54:17.396527 2026] [security2:error] [pid 1033876:tid 1034130] [client 185.243.112.137:50682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?i)(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)|u(?:221[56]|002f)|%32(?:%46|F)|e0%80%af|1u|5c)|\\\\/))(?:%(?:2(?:(?:52)?e|%45)|(?:e0%8|c)0%ae|u(?:002e|2024)|%32(?:%45|E))|\\\\.){2}(?:\\\\x5c|(?:%(?:2(?:5(?:2f|5c)|%46|f)|c(?:0%(?:9v|af)|1%1c)| ..." at ARGS:file_name. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "198"] [id "340007"] [rev "47"] [msg "Atomicorp.com WAF Rules: Generic Path Recursion denied"] [data "/../,ARGS:file_name"] [severity "CRITICAL"] [hostname "zonemist.com"] [uri "/pms"] [unique_id "al4aeUfjhWEjDbtLXL6ZIwAAAQA"]
[Mon Jul 20 06:54:17.396620 2026] [security2:error] [pid 1033876:tid 1034130] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "zonemist.com"] [uri "/pms"] [unique_id "al4aeUfjhWEjDbtLXL6ZIwAAAQA"]
[Mon Jul 20 06:54:17.479107 2026] [security2:error] [pid 1033876:tid 1034088] [client 20.151.205.204:23859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZKQAAANY"]
[Mon Jul 20 06:54:17.479205 2026] [security2:error] [pid 1033876:tid 1034088] [client 20.151.205.204:23859] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZKQAAANY"]
[Mon Jul 20 06:54:17.496493 2026] [security2:error] [pid 1033876:tid 1033931] [remote 217.61.143.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZKgAApjU"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 06:54:17.574223 2026] [security2:error] [pid 1033876:tid 1034039] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aeUfjhWEjDbtLXL6ZLQAAAKU"]
[Mon Jul 20 06:54:17.638300 2026] [security2:error] [pid 1033876:tid 1034125] [client 14.225.17.146:63365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZIgAAAPs"], referer: https://nwcarvingacademy.com/wp-old
[Mon Jul 20 06:54:17.683897 2026] [security2:error] [pid 1033876:tid 1034042] [client 161.118.218.103:56882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZOwAAAKg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:17.685238 2026] [security2:error] [pid 1033876:tid 1034016] [client 117.247.108.24:36580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZPAAAAI4"]
[Mon Jul 20 06:54:17.685319 2026] [security2:error] [pid 1033876:tid 1034016] [client 117.247.108.24:36580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZPAAAAI4"]
[Mon Jul 20 06:54:17.750861 2026] [security2:error] [pid 1033876:tid 1034108] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4aeUfjhWEjDbtLXL6ZQgAAAOo"]
[Mon Jul 20 06:54:17.777588 2026] [security2:error] [pid 1033876:tid 1034024] [client 183.82.98.154:57986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZRgAAAJY"]
[Mon Jul 20 06:54:17.777679 2026] [security2:error] [pid 1033876:tid 1034024] [client 183.82.98.154:57986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZRgAAAJY"]
[Mon Jul 20 06:54:17.916408 2026] [security2:error] [pid 1033876:tid 1034071] [client 14.225.17.146:60636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZQQAAAMU"], referer: http://mezzacraft.com/wp-old
[Mon Jul 20 06:54:17.927567 2026] [security2:error] [pid 1033876:tid 1034084] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aeUfjhWEjDbtLXL6ZTAAAANI"]
[Mon Jul 20 06:54:17.935313 2026] [security2:error] [pid 1033876:tid 1034082] [client 20.151.205.204:27339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZTgAAANA"]
[Mon Jul 20 06:54:17.935385 2026] [security2:error] [pid 1033876:tid 1034082] [client 20.151.205.204:27339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZTgAAANA"]
[Mon Jul 20 06:54:18.093983 2026] [security2:error] [pid 1033876:tid 1034066] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4aekfjhWEjDbtLXL6ZaQAAAMA"]
[Mon Jul 20 06:54:18.170610 2026] [security2:error] [pid 1033876:tid 1034089] [client 18.142.226.106:43480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aekfjhWEjDbtLXL6ZcQAAANc"]
[Mon Jul 20 06:54:18.170717 2026] [security2:error] [pid 1033876:tid 1034089] [client 18.142.226.106:43480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4aekfjhWEjDbtLXL6ZcQAAANc"]
[Mon Jul 20 06:54:18.179923 2026] [security2:error] [pid 1033876:tid 1034110] [client 104.234.53.49:51445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4aekfjhWEjDbtLXL6ZcgAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:18.260193 2026] [security2:error] [pid 1033876:tid 1034055] [client 161.118.218.103:57308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4aekfjhWEjDbtLXL6ZfAAAALU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:18.269462 2026] [security2:error] [pid 1033876:tid 1034115] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aekfjhWEjDbtLXL6ZewAAAPE"]
[Mon Jul 20 06:54:18.276824 2026] [security2:error] [pid 1033876:tid 1033890] [remote 57.141.18.14:27702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4aekfjhWEjDbtLXL6ZfQAA7ww"]
[Mon Jul 20 06:54:18.363281 2026] [security2:error] [pid 1033876:tid 1034096] [client 14.225.17.146:65190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4aekfjhWEjDbtLXL6ZdwAAAN4"], referer: http://aljosour-alarabia.com/wp-old
[Mon Jul 20 06:54:18.380405 2026] [security2:error] [pid 1033876:tid 1034116] [client 20.151.205.204:24444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/x.php"] [unique_id "al4aekfjhWEjDbtLXL6ZhwAAAPI"]
[Mon Jul 20 06:54:18.380536 2026] [security2:error] [pid 1033876:tid 1034116] [client 20.151.205.204:24444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/x.php"] [unique_id "al4aekfjhWEjDbtLXL6ZhwAAAPI"]
[Mon Jul 20 06:54:18.554339 2026] [security2:error] [pid 1033876:tid 1034097] [client 117.222.139.248:57831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aekfjhWEjDbtLXL6ZlgAAAN8"]
[Mon Jul 20 06:54:18.554548 2026] [security2:error] [pid 1033876:tid 1034097] [client 117.222.139.248:57831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aekfjhWEjDbtLXL6ZlgAAAN8"]
[Mon Jul 20 06:54:18.716215 2026] [security2:error] [pid 1033876:tid 1034080] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4aekfjhWEjDbtLXL6ZpQAAAM4"]
[Mon Jul 20 06:54:18.726909 2026] [security2:error] [pid 1033876:tid 1034129] [client 20.151.205.204:24422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/j260624_13.php"] [unique_id "al4aekfjhWEjDbtLXL6ZpgAAAP8"]
[Mon Jul 20 06:54:18.727004 2026] [security2:error] [pid 1033876:tid 1034129] [client 20.151.205.204:24422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/j260624_13.php"] [unique_id "al4aekfjhWEjDbtLXL6ZpgAAAP8"]
[Mon Jul 20 06:54:18.842015 2026] [security2:error] [pid 1033876:tid 1034125] [client 161.118.218.103:57768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4aekfjhWEjDbtLXL6ZrgAAAPs"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:18.869448 2026] [security2:error] [pid 1033876:tid 1034021] [client 14.225.17.146:65211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4aekfjhWEjDbtLXL6ZegAAAJM"], referer: http://idigress.studio/wp-old
[Mon Jul 20 06:54:18.897913 2026] [security2:error] [pid 1033876:tid 1034036] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4aekfjhWEjDbtLXL6ZswAAAKI"]
[Mon Jul 20 06:54:18.916641 2026] [security2:error] [pid 1033876:tid 1033951] [remote 20.153.140.50:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aekfjhWEjDbtLXL6ZtAAA4kk"]
[Mon Jul 20 06:54:19.065209 2026] [security2:error] [pid 1033876:tid 1034099] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4ae0fjhWEjDbtLXL6ZwQAAAOE"]
[Mon Jul 20 06:54:19.287106 2026] [security2:error] [pid 1033876:tid 1034102] [client 216.73.217.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.sacredpathway.net"] [uri "/index.php"] [unique_id "al4aeUfjhWEjDbtLXL6ZGQAAAOQ"]
[Mon Jul 20 06:54:19.315689 2026] [security2:error] [pid 1033876:tid 1033901] [remote 20.153.140.50:41650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z1wAA0Rc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:19.327085 2026] [security2:error] [pid 1033876:tid 1034132] [client 20.151.205.204:24425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/d62.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z2wAAAQI"]
[Mon Jul 20 06:54:19.327176 2026] [security2:error] [pid 1033876:tid 1034132] [client 20.151.205.204:24425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/d62.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z2wAAAQI"]
[Mon Jul 20 06:54:19.371101 2026] [security2:error] [pid 1033876:tid 1034103] [client 14.225.17.146:63738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4aekfjhWEjDbtLXL6ZfwAAAOU"], referer: http://ravmike.com/wp-old
[Mon Jul 20 06:54:19.417858 2026] [security2:error] [pid 1033876:tid 1034018] [client 77.110.127.138:59200] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 514 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ae0fjhWEjDbtLXL6Z6QAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:19.419417 2026] [security2:error] [pid 1033876:tid 1034065] [client 161.118.218.103:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z6gAAAL8"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:19.422449 2026] [security2:error] [pid 1033876:tid 1034057] [client 152.58.191.29:65229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z6wAAALc"]
[Mon Jul 20 06:54:19.422531 2026] [security2:error] [pid 1033876:tid 1034057] [client 152.58.191.29:65229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z6wAAALc"]
[Mon Jul 20 06:54:19.499677 2026] [security2:error] [pid 1033876:tid 1034086] [client 57.141.18.123:33376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ad0fjhWEjDbtLXL6YlgAA1E0"]
[Mon Jul 20 06:54:19.653308 2026] [security2:error] [pid 1033876:tid 1034035] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4ae0fjhWEjDbtLXL6Z9QAAAKE"]
[Mon Jul 20 06:54:19.775633 2026] [security2:error] [pid 1033876:tid 1034041] [client 104.234.53.59:23489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ae0fjhWEjDbtLXL6Z9gAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:19.911698 2026] [security2:error] [pid 1033876:tid 1034123] [client 20.151.205.204:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/ups.php"] [unique_id "al4ae0fjhWEjDbtLXL6aDAAAAPk"]
[Mon Jul 20 06:54:19.911849 2026] [security2:error] [pid 1033876:tid 1034123] [client 20.151.205.204:54824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/ups.php"] [unique_id "al4ae0fjhWEjDbtLXL6aDAAAAPk"]
[Mon Jul 20 06:54:19.995384 2026] [security2:error] [pid 1033876:tid 1034108] [client 161.118.218.103:58724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ae0fjhWEjDbtLXL6aGQAAAOo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:20.017674 2026] [security2:error] [pid 1033876:tid 1034096] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4afEfjhWEjDbtLXL6aGgAAAN4"]
[Mon Jul 20 06:54:20.139371 2026] [security2:error] [pid 1033876:tid 1034009] [client 104.234.53.59:23489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4afEfjhWEjDbtLXL6aHgAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:20.242679 2026] [security2:error] [pid 1033876:tid 1034098] [client 14.225.17.146:56768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4aekfjhWEjDbtLXL6ZlQAAAOA"], referer: http://windowtx.com/wp-old
[Mon Jul 20 06:54:20.276624 2026] [security2:error] [pid 1033876:tid 1034094] [client 14.225.17.146:59439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4afEfjhWEjDbtLXL6aJgAAANw"], referer: https://ravmike.com/wp-old
[Mon Jul 20 06:54:20.322240 2026] [security2:error] [pid 1033876:tid 1034056] [client 217.142.18.172:16758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4afEfjhWEjDbtLXL6aNAAAALY"]
[Mon Jul 20 06:54:20.325883 2026] [security2:error] [pid 1033876:tid 1034056] [client 217.142.18.172:16758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4afEfjhWEjDbtLXL6aNAAAALY"]
[Mon Jul 20 06:54:20.345146 2026] [security2:error] [pid 1033876:tid 1034028] [client 77.110.127.138:59207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4afEfjhWEjDbtLXL6aNQAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:20.345228 2026] [security2:error] [pid 1033876:tid 1034028] [client 77.110.127.138:59207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4afEfjhWEjDbtLXL6aNQAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:20.571204 2026] [security2:error] [pid 1033876:tid 1034062] [client 161.118.218.103:59205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4afEfjhWEjDbtLXL6aQwAAALw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:20.672775 2026] [security2:error] [pid 1033876:tid 1033987] [remote 152.228.213.32:51412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4afEfjhWEjDbtLXL6aUAAA920"]
[Mon Jul 20 06:54:20.760074 2026] [security2:error] [pid 1033876:tid 1034103] [client 20.151.205.204:27354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k.php"] [unique_id "al4afEfjhWEjDbtLXL6aXgAAAOU"]
[Mon Jul 20 06:54:20.760185 2026] [security2:error] [pid 1033876:tid 1034103] [client 20.151.205.204:27354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k.php"] [unique_id "al4afEfjhWEjDbtLXL6aXgAAAOU"]
[Mon Jul 20 06:54:20.867125 2026] [security2:error] [pid 1033876:tid 1034043] [client 162.219.176.3:50014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4afEfjhWEjDbtLXL6aZwAAAKk"]
[Mon Jul 20 06:54:20.867210 2026] [security2:error] [pid 1033876:tid 1034043] [client 162.219.176.3:50014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4afEfjhWEjDbtLXL6aZwAAAKk"]
[Mon Jul 20 06:54:20.983479 2026] [security2:error] [pid 1033876:tid 1033956] [remote 152.228.213.32:51412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4afEfjhWEjDbtLXL6adAAA8U4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:21.105179 2026] [security2:error] [pid 1033876:tid 1034027] [client 14.225.17.146:59713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4afUfjhWEjDbtLXL6aegAAAJk"]
[Mon Jul 20 06:54:21.146088 2026] [security2:error] [pid 1033876:tid 1034052] [client 161.118.218.103:59567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4afUfjhWEjDbtLXL6aggAAALI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:21.322535 2026] [security2:error] [pid 1033876:tid 1034104] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4afEfjhWEjDbtLXL6aaQAAAOY"]
[Mon Jul 20 06:54:21.349474 2026] [security2:error] [pid 1033876:tid 1034130] [client 14.225.17.146:63613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4ae0fjhWEjDbtLXL6aEAAAAQA"], referer: http://thechancersband.com/wp-old
[Mon Jul 20 06:54:21.650877 2026] [security2:error] [pid 1033876:tid 1034021] [client 20.151.205.204:21758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k2.php"] [unique_id "al4afUfjhWEjDbtLXL6apwAAAJM"]
[Mon Jul 20 06:54:21.650980 2026] [security2:error] [pid 1033876:tid 1034021] [client 20.151.205.204:21758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k2.php"] [unique_id "al4afUfjhWEjDbtLXL6apwAAAJM"]
[Mon Jul 20 06:54:21.706636 2026] [security2:error] [pid 1033876:tid 1034133] [client 50.116.65.227:40960] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "longevityperformanceclinic.com"] [uri "/wp-cron.php"] [unique_id "al4afUfjhWEjDbtLXL6aqQAAAQM"]
[Mon Jul 20 06:54:21.710248 2026] [security2:error] [pid 1033876:tid 1034030] [client 14.225.17.146:63619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4ae0fjhWEjDbtLXL6aDwAAAJw"], referer: http://longevityperformanceclinic.com/wp-old
[Mon Jul 20 06:54:21.720269 2026] [security2:error] [pid 1033876:tid 1034122] [client 161.118.218.103:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4afUfjhWEjDbtLXL6argAAAPg"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:22.006627 2026] [security2:error] [pid 1033876:tid 1034069] [client 20.151.205.204:54871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k3.php"] [unique_id "al4afkfjhWEjDbtLXL6ayAAAAMM"]
[Mon Jul 20 06:54:22.006715 2026] [security2:error] [pid 1033876:tid 1034069] [client 20.151.205.204:54871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k3.php"] [unique_id "al4afkfjhWEjDbtLXL6ayAAAAMM"]
[Mon Jul 20 06:54:22.296272 2026] [security2:error] [pid 1033876:tid 1034067] [client 161.118.218.103:60389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4afkfjhWEjDbtLXL6a3wAAAME"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:22.434399 2026] [security2:error] [pid 1033876:tid 1034082] [client 14.225.17.146:63030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4afkfjhWEjDbtLXL6azwAAANA"]
[Mon Jul 20 06:54:22.585962 2026] [security2:error] [pid 1033876:tid 1033963] [remote 188.166.241.141:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4afkfjhWEjDbtLXL6a9gAA6VU"]
[Mon Jul 20 06:54:22.586067 2026] [security2:error] [pid 1033876:tid 1034107] [client 188.166.241.141:60590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4afkfjhWEjDbtLXL6a9gAA6VU"]
[Mon Jul 20 06:54:22.591531 2026] [security2:error] [pid 1033876:tid 1034083] [client 103.238.106.162:63844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4afkfjhWEjDbtLXL6a9wAAANE"]
[Mon Jul 20 06:54:22.591614 2026] [security2:error] [pid 1033876:tid 1034083] [client 103.238.106.162:63844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4afkfjhWEjDbtLXL6a9wAAANE"]
[Mon Jul 20 06:54:22.611602 2026] [security2:error] [pid 1033876:tid 1034060] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4afkfjhWEjDbtLXL6a-QAAALo"]
[Mon Jul 20 06:54:22.685260 2026] [security2:error] [pid 1033876:tid 1034066] [client 104.234.53.60:35171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4afkfjhWEjDbtLXL6a-wAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:22.825113 2026] [security2:error] [pid 1033876:tid 1034128] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4afkfjhWEjDbtLXL6bCQAAAP4"]
[Mon Jul 20 06:54:22.871357 2026] [security2:error] [pid 1033876:tid 1034079] [client 161.118.218.103:60792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4afkfjhWEjDbtLXL6bEAAAAM0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:22.939333 2026] [security2:error] [pid 1033876:tid 1034112] [client 20.151.205.204:42922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k4.php"] [unique_id "al4afkfjhWEjDbtLXL6bFgAAAO4"]
[Mon Jul 20 06:54:22.939454 2026] [security2:error] [pid 1033876:tid 1034112] [client 20.151.205.204:42922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k4.php"] [unique_id "al4afkfjhWEjDbtLXL6bFgAAAO4"]
[Mon Jul 20 06:54:23.455863 2026] [security2:error] [pid 1033876:tid 1034126] [client 161.118.218.103:61219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4af0fjhWEjDbtLXL6bPAAAAPw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:23.532064 2026] [security2:error] [pid 1033876:tid 1034124] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "zonemist.com"] [uri "/index.cgi"] [unique_id "al4af0fjhWEjDbtLXL6bPgAAAPo"]
[Mon Jul 20 06:54:23.615942 2026] [security2:error] [pid 1033876:tid 1033880] [remote 152.228.213.32:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4af0fjhWEjDbtLXL6bRwAAvAI"]
[Mon Jul 20 06:54:23.699704 2026] [security2:error] [pid 1033876:tid 1034074] [client 185.243.112.137:50682] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "zonemist.com"] [uri "/404.html"] [unique_id "al4af0fjhWEjDbtLXL6bTQAAAMg"]
[Mon Jul 20 06:54:23.743197 2026] [security2:error] [pid 1033876:tid 1034023] [client 20.151.205.204:24387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k5.php"] [unique_id "al4af0fjhWEjDbtLXL6bVwAAAJU"]
[Mon Jul 20 06:54:23.743283 2026] [security2:error] [pid 1033876:tid 1034023] [client 20.151.205.204:24387] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/k5.php"] [unique_id "al4af0fjhWEjDbtLXL6bVwAAAJU"]
[Mon Jul 20 06:54:23.787843 2026] [security2:error] [pid 1033876:tid 1034079] [client 104.234.53.91:23019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4af0fjhWEjDbtLXL6bUwAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:23.851579 2026] [security2:error] [pid 1033876:tid 1034020] [client 197.186.66.42:53487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4af0fjhWEjDbtLXL6bXAAAAJI"]
[Mon Jul 20 06:54:23.870952 2026] [security2:error] [pid 1033876:tid 1034020] [client 197.186.66.42:53487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4af0fjhWEjDbtLXL6bXAAAAJI"]
[Mon Jul 20 06:54:24.010550 2026] [core:error] [pid 1033876:tid 1034058] [client 14.225.17.146:60149] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:24.010573 2026] [core:error] [pid 1033876:tid 1034058] [client 14.225.17.146:60149] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:24.064935 2026] [security2:error] [pid 1033876:tid 1034040] [client 161.118.218.103:61725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4agEfjhWEjDbtLXL6bawAAAKY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:24.165112 2026] [security2:error] [pid 1033876:tid 1034098] [client 114.119.158.45:49443] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bruceledewitz.com"] [uri "/empty-secular-society/"] [unique_id "al4agEfjhWEjDbtLXL6bcQAAAOA"], referer: https://bruceledewitz.com/blog/
[Mon Jul 20 06:54:24.261347 2026] [security2:error] [pid 1033876:tid 1034028] [client 104.234.53.91:23019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4agEfjhWEjDbtLXL6bewAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:24.307598 2026] [security2:error] [pid 1033876:tid 1033986] [remote 152.228.213.32:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4agEfjhWEjDbtLXL6bhQAA2mw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:54:24.601243 2026] [security2:error] [pid 1033876:tid 1034096] [client 14.225.17.146:51356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4agEfjhWEjDbtLXL6bmQAAAN4"], referer: http://alchemygroup.ca/wp-old
[Mon Jul 20 06:54:24.653788 2026] [security2:error] [pid 1033876:tid 1034132] [client 104.207.50.229:64991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4agEfjhWEjDbtLXL6bpgAAAQI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:24.657467 2026] [security2:error] [pid 1033876:tid 1034095] [client 161.118.218.103:62196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4agEfjhWEjDbtLXL6bqgAAAN0"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:24.854993 2026] [security2:error] [pid 1033876:tid 1034029] [client 20.151.205.204:50731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/w.php"] [unique_id "al4agEfjhWEjDbtLXL6buAAAAJs"]
[Mon Jul 20 06:54:24.855106 2026] [security2:error] [pid 1033876:tid 1034029] [client 20.151.205.204:50731] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/w.php"] [unique_id "al4agEfjhWEjDbtLXL6buAAAAJs"]
[Mon Jul 20 06:54:24.858889 2026] [security2:error] [pid 1033876:tid 1034058] [client 14.225.17.146:60356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4agEfjhWEjDbtLXL6btAAAALg"], referer: http://katsklar.com/wp-old
[Mon Jul 20 06:54:24.907582 2026] [security2:error] [pid 1033876:tid 1034033] [client 14.225.17.146:60301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4agEfjhWEjDbtLXL6bpAAAAJ8"], referer: http://webgardensbypaula.com/wp-old
[Mon Jul 20 06:54:25.205650 2026] [security2:error] [pid 1033876:tid 1034122] [client 151.123.176.125:23657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4agUfjhWEjDbtLXL6b1QAAAPg"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:54:25.232293 2026] [security2:error] [pid 1033876:tid 1034050] [client 161.118.218.103:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4agUfjhWEjDbtLXL6b3AAAALA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:25.245170 2026] [security2:error] [pid 1033876:tid 1034073] [client 104.207.51.72:18773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4agUfjhWEjDbtLXL6b1wAAAMc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:25.278810 2026] [security2:error] [pid 1033876:tid 1034018] [client 77.110.127.138:59231] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 740 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4agUfjhWEjDbtLXL6b3gAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:25.341621 2026] [security2:error] [pid 1033876:tid 1034110] [client 103.125.179.95:63145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4agUfjhWEjDbtLXL6b4AAAAOw"]
[Mon Jul 20 06:54:25.341777 2026] [security2:error] [pid 1033876:tid 1034110] [client 103.125.179.95:63145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4agUfjhWEjDbtLXL6b4AAAAOw"]
[Mon Jul 20 06:54:25.377106 2026] [security2:error] [pid 1033876:tid 1033988] [remote 103.82.22.235:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4agUfjhWEjDbtLXL6b4QAAnW4"]
[Mon Jul 20 06:54:25.390492 2026] [security2:error] [pid 1033876:tid 1034067] [client 187.108.85.186:50699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4agUfjhWEjDbtLXL6b5QAAAME"]
[Mon Jul 20 06:54:25.390581 2026] [security2:error] [pid 1033876:tid 1034067] [client 187.108.85.186:50699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4agUfjhWEjDbtLXL6b5QAAAME"]
[Mon Jul 20 06:54:25.754654 2026] [security2:error] [pid 1033876:tid 1034050] [client 146.103.115.115:52567] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.115.115" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4agUfjhWEjDbtLXL6cBAAAALA"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:54:25.754761 2026] [security2:error] [pid 1033876:tid 1034050] [client 146.103.115.115:52567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4agUfjhWEjDbtLXL6cBAAAALA"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:54:25.773326 2026] [security2:error] [pid 1033876:tid 1034107] [client 14.225.17.146:60111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4agEfjhWEjDbtLXL6bdwAAAOk"], referer: http://careysheatingandcooling.com/wp-old
[Mon Jul 20 06:54:25.793658 2026] [security2:error] [pid 1033876:tid 1034049] [client 104.207.51.150:54301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4agUfjhWEjDbtLXL6cCQAAAK8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:25.806204 2026] [security2:error] [pid 1033876:tid 1034116] [client 161.118.218.103:62975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4agUfjhWEjDbtLXL6cCgAAAPI"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:25.897964 2026] [security2:error] [pid 1033876:tid 1033928] [remote 103.82.22.235:47634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4agUfjhWEjDbtLXL6cEAAAsjI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:54:25.912633 2026] [security2:error] [pid 1033876:tid 1034123] [client 14.225.17.146:51625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4agUfjhWEjDbtLXL6cBQAAAPk"], referer: http://709fx.com/wp-old
[Mon Jul 20 06:54:25.934952 2026] [security2:error] [pid 1033876:tid 1034124] [client 77.110.127.138:59233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4agUfjhWEjDbtLXL6cFwAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:25.935083 2026] [security2:error] [pid 1033876:tid 1034124] [client 77.110.127.138:59233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4agUfjhWEjDbtLXL6cFwAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:25.977305 2026] [security2:error] [pid 1033876:tid 1034057] [client 20.151.205.204:55343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/fpwch.php"] [unique_id "al4agUfjhWEjDbtLXL6cGQAAALc"]
[Mon Jul 20 06:54:25.977425 2026] [security2:error] [pid 1033876:tid 1034057] [client 20.151.205.204:55343] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/fpwch.php"] [unique_id "al4agUfjhWEjDbtLXL6cGQAAALc"]
[Mon Jul 20 06:54:26.027790 2026] [security2:error] [pid 1033876:tid 1034119] [client 14.225.17.146:65510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4agEfjhWEjDbtLXL6btwAAAPU"], referer: http://northbrookcpa.ca/wp-old
[Mon Jul 20 06:54:26.104354 2026] [security2:error] [pid 1033876:tid 1034105] [client 14.225.17.146:51962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4agUfjhWEjDbtLXL6cGAAAAOc"], referer: http://lutheranphilosopher.com/wp-old
[Mon Jul 20 06:54:26.178094 2026] [security2:error] [pid 1033876:tid 1034074] [client 114.119.143.104:25297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "50.116.64.44"] [uri "/robots.txt"] [unique_id "al4agkfjhWEjDbtLXL6cIwAAAMg"], referer: https://50.116.64.44/robots.txt
[Mon Jul 20 06:54:26.382709 2026] [security2:error] [pid 1033876:tid 1034102] [client 161.118.218.103:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4agkfjhWEjDbtLXL6cNwAAAOQ"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:26.416818 2026] [security2:error] [pid 1033876:tid 1034088] [client 104.234.53.53:29717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4agkfjhWEjDbtLXL6cPAAAANY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:26.455160 2026] [security2:error] [pid 1033876:tid 1034012] [client 20.151.205.204:42848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/w2025.php"] [unique_id "al4agkfjhWEjDbtLXL6cQQAAAIo"]
[Mon Jul 20 06:54:26.455273 2026] [security2:error] [pid 1033876:tid 1034012] [client 20.151.205.204:42848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/w2025.php"] [unique_id "al4agkfjhWEjDbtLXL6cQQAAAIo"]
[Mon Jul 20 06:54:26.478577 2026] [security2:error] [pid 1033876:tid 1034033] [client 14.225.17.146:59757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4agkfjhWEjDbtLXL6cMgAAAJ8"], referer: http://adirondackengineering.com/wp-old
[Mon Jul 20 06:54:26.489269 2026] [security2:error] [pid 1033876:tid 1034007] [client 14.225.17.146:51392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4agkfjhWEjDbtLXL6cPgAAAIU"], referer: http://friendlyspreadsheet.com/wp-old
[Mon Jul 20 06:54:26.612029 2026] [security2:error] [pid 1033876:tid 1034084] [client 104.207.51.103:61389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4agkfjhWEjDbtLXL6cTgAAANI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:54:26.630265 2026] [security2:error] [pid 1033876:tid 1034011] [client 14.225.17.146:51510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4agUfjhWEjDbtLXL6b2gAAAIk"], referer: http://chestermonty.com/wp-old
[Mon Jul 20 06:54:26.631608 2026] [security2:error] [pid 1033876:tid 1034013] [client 113.160.132.26:8356] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 26.132.160.113.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4agkfjhWEjDbtLXL6cUgAAAIs"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:54:26.631724 2026] [security2:error] [pid 1033876:tid 1034013] [client 113.160.132.26:8356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "icemarc.org"] [uri "/wp-comments-post.php"] [unique_id "al4agkfjhWEjDbtLXL6cUgAAAIs"], referer: http://icemarc.org/using-ai-in-your-ham-radio-hobby/
[Mon Jul 20 06:54:26.631893 2026] [security2:error] [pid 1033876:tid 1033911] [remote 20.173.88.122:38230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4agkfjhWEjDbtLXL6cUwAA6yE"]
[Mon Jul 20 06:54:26.683596 2026] [security2:error] [pid 1033876:tid 1034075] [client 20.151.205.204:42929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/scxy.php"] [unique_id "al4agkfjhWEjDbtLXL6cWAAAAMk"]
[Mon Jul 20 06:54:26.683676 2026] [security2:error] [pid 1033876:tid 1034075] [client 20.151.205.204:42929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/scxy.php"] [unique_id "al4agkfjhWEjDbtLXL6cWAAAAMk"]
[Mon Jul 20 06:54:26.702252 2026] [security2:error] [pid 1033876:tid 1034071] [client 14.224.227.113:54778] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4agkfjhWEjDbtLXL6cWQAAAMU"]
[Mon Jul 20 06:54:26.718577 2026] [security2:error] [pid 1033876:tid 1033971] [remote 154.66.198.148:2228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4agkfjhWEjDbtLXL6cWwAAnF0"]
[Mon Jul 20 06:54:26.780869 2026] [security2:error] [pid 1033876:tid 1033919] [remote 192.241.143.148:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4agkfjhWEjDbtLXL6cZQAAwyk"]
[Mon Jul 20 06:54:26.875479 2026] [security2:error] [pid 1033876:tid 1034116] [client 20.151.205.204:32327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/FWAZ.php"] [unique_id "al4agkfjhWEjDbtLXL6cZwAAAPI"]
[Mon Jul 20 06:54:26.875554 2026] [security2:error] [pid 1033876:tid 1034116] [client 20.151.205.204:32327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/FWAZ.php"] [unique_id "al4agkfjhWEjDbtLXL6cZwAAAPI"]
[Mon Jul 20 06:54:26.960077 2026] [security2:error] [pid 1033876:tid 1034046] [client 161.118.218.103:63734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4agkfjhWEjDbtLXL6cbQAAAKw"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:27.001936 2026] [security2:error] [pid 1033876:tid 1033914] [remote 192.241.143.148:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ag0fjhWEjDbtLXL6cdAAA0SQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:54:27.080146 2026] [security2:error] [pid 1033876:tid 1034115] [client 14.225.17.146:51439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4agUfjhWEjDbtLXL6b7AAAAPE"], referer: http://superiorcopywriting.com/wp-old
[Mon Jul 20 06:54:27.122809 2026] [security2:error] [pid 1033876:tid 1034042] [client 20.151.205.204:55323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/qterm.php"] [unique_id "al4ag0fjhWEjDbtLXL6cewAAAKg"]
[Mon Jul 20 06:54:27.122918 2026] [security2:error] [pid 1033876:tid 1034042] [client 20.151.205.204:55323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/qterm.php"] [unique_id "al4ag0fjhWEjDbtLXL6cewAAAKg"]
[Mon Jul 20 06:54:27.311178 2026] [security2:error] [pid 1033876:tid 1034112] [client 57.141.18.11:54850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4af0fjhWEjDbtLXL6bQQAA7kw"]
[Mon Jul 20 06:54:27.339152 2026] [security2:error] [pid 1033876:tid 1034055] [client 20.151.205.204:14727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/blurbs.php"] [unique_id "al4ag0fjhWEjDbtLXL6cjwAAALU"]
[Mon Jul 20 06:54:27.339245 2026] [security2:error] [pid 1033876:tid 1034055] [client 20.151.205.204:14727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/blurbs.php"] [unique_id "al4ag0fjhWEjDbtLXL6cjwAAALU"]
[Mon Jul 20 06:54:27.349556 2026] [security2:error] [pid 1033876:tid 1034024] [client 45.156.129.161:19624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ag0fjhWEjDbtLXL6cfAAAAJY"]
[Mon Jul 20 06:54:27.361390 2026] [security2:error] [pid 1033876:tid 1033957] [remote 20.173.88.122:38230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ag0fjhWEjDbtLXL6ckAAAu08"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:54:27.377015 2026] [security2:error] [pid 1033876:tid 1033981] [remote 154.66.198.148:2228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4ag0fjhWEjDbtLXL6ckgAA-Gc"], referer: https://alaraycreative.com/wp-login.php
[Mon Jul 20 06:54:27.404723 2026] [security2:error] [pid 1033876:tid 1034088] [client 117.247.108.24:51109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ag0fjhWEjDbtLXL6clAAAANY"]
[Mon Jul 20 06:54:27.404827 2026] [security2:error] [pid 1033876:tid 1034088] [client 117.247.108.24:51109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ag0fjhWEjDbtLXL6clAAAANY"]
[Mon Jul 20 06:54:27.445785 2026] [security2:error] [pid 1033876:tid 1034119] [client 14.225.17.146:51908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4ag0fjhWEjDbtLXL6ckwAAAPU"], referer: https://friendlyspreadsheet.com/wp-old
[Mon Jul 20 06:54:27.538585 2026] [security2:error] [pid 1033876:tid 1034041] [client 161.118.218.103:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ag0fjhWEjDbtLXL6cngAAAKc"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:27.561912 2026] [security2:error] [pid 1033876:tid 1034126] [client 14.225.17.146:52011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4ag0fjhWEjDbtLXL6cmAAAAPw"], referer: https://chestermonty.com/wp-old
[Mon Jul 20 06:54:27.669461 2026] [security2:error] [pid 1033876:tid 1034029] [client 20.151.205.204:59537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/v543.php"] [unique_id "al4ag0fjhWEjDbtLXL6cqgAAAJs"]
[Mon Jul 20 06:54:27.669581 2026] [security2:error] [pid 1033876:tid 1034029] [client 20.151.205.204:59537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/v543.php"] [unique_id "al4ag0fjhWEjDbtLXL6cqgAAAJs"]
[Mon Jul 20 06:54:27.919336 2026] [security2:error] [pid 1033876:tid 1034081] [client 20.151.205.204:48726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/w3lls.php"] [unique_id "al4ag0fjhWEjDbtLXL6ctAAAAM8"]
[Mon Jul 20 06:54:27.919420 2026] [security2:error] [pid 1033876:tid 1034081] [client 20.151.205.204:48726] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/w3lls.php"] [unique_id "al4ag0fjhWEjDbtLXL6ctAAAAM8"]
[Mon Jul 20 06:54:28.057943 2026] [security2:error] [pid 1033876:tid 1034088] [client 20.151.205.204:50616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-ws68.php"] [unique_id "al4ahEfjhWEjDbtLXL6cwgAAANY"]
[Mon Jul 20 06:54:28.058061 2026] [security2:error] [pid 1033876:tid 1034088] [client 20.151.205.204:50616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-ws68.php"] [unique_id "al4ahEfjhWEjDbtLXL6cwgAAANY"]
[Mon Jul 20 06:54:28.069338 2026] [security2:error] [pid 1033876:tid 1034060] [client 117.222.139.248:58304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ahEfjhWEjDbtLXL6cwwAAALo"]
[Mon Jul 20 06:54:28.069475 2026] [security2:error] [pid 1033876:tid 1034060] [client 117.222.139.248:58304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ahEfjhWEjDbtLXL6cwwAAALo"]
[Mon Jul 20 06:54:28.116770 2026] [security2:error] [pid 1033876:tid 1034021] [client 161.118.218.103:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ahEfjhWEjDbtLXL6cxQAAAJM"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:28.199665 2026] [security2:error] [pid 1033876:tid 1034046] [client 20.151.205.204:50723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/xyn.php"] [unique_id "al4ahEfjhWEjDbtLXL6c0AAAAKw"]
[Mon Jul 20 06:54:28.199776 2026] [security2:error] [pid 1033876:tid 1034046] [client 20.151.205.204:50723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/xyn.php"] [unique_id "al4ahEfjhWEjDbtLXL6c0AAAAKw"]
[Mon Jul 20 06:54:28.397323 2026] [security2:error] [pid 1033876:tid 1034130] [client 45.156.129.160:53826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ahEfjhWEjDbtLXL6czwAAAQA"]
[Mon Jul 20 06:54:28.414995 2026] [security2:error] [pid 1033876:tid 1034087] [client 20.151.205.204:50593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/green3.php"] [unique_id "al4ahEfjhWEjDbtLXL6c5AAAANU"]
[Mon Jul 20 06:54:28.415131 2026] [security2:error] [pid 1033876:tid 1034087] [client 20.151.205.204:50593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/green3.php"] [unique_id "al4ahEfjhWEjDbtLXL6c5AAAANU"]
[Mon Jul 20 06:54:28.561962 2026] [security2:error] [pid 1033876:tid 1034054] [client 183.82.98.154:58583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ahEfjhWEjDbtLXL6c7gAAALQ"]
[Mon Jul 20 06:54:28.562079 2026] [security2:error] [pid 1033876:tid 1034054] [client 183.82.98.154:58583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ahEfjhWEjDbtLXL6c7gAAALQ"]
[Mon Jul 20 06:54:28.574372 2026] [security2:error] [pid 1033876:tid 1034088] [client 20.151.205.204:21745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/ccs.php"] [unique_id "al4ahEfjhWEjDbtLXL6c8AAAANY"]
[Mon Jul 20 06:54:28.574488 2026] [security2:error] [pid 1033876:tid 1034088] [client 20.151.205.204:21745] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/ccs.php"] [unique_id "al4ahEfjhWEjDbtLXL6c8AAAANY"]
[Mon Jul 20 06:54:28.690539 2026] [security2:error] [pid 1033876:tid 1034082] [client 161.118.218.103:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ahEfjhWEjDbtLXL6c-AAAANA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:28.768155 2026] [security2:error] [pid 1033876:tid 1034083] [client 20.151.205.204:60829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/ccc.php"] [unique_id "al4ahEfjhWEjDbtLXL6dCgAAANE"]
[Mon Jul 20 06:54:28.768289 2026] [security2:error] [pid 1033876:tid 1034083] [client 20.151.205.204:60829] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/ccc.php"] [unique_id "al4ahEfjhWEjDbtLXL6dCgAAANE"]
[Mon Jul 20 06:54:28.801201 2026] [security2:error] [pid 1033876:tid 1034092] [client 14.225.17.146:58895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4agkfjhWEjDbtLXL6cRAAAANo"], referer: http://onewingpictures.com/wp-old
[Mon Jul 20 06:54:28.905284 2026] [security2:error] [pid 1033876:tid 1034020] [client 20.151.205.204:32358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/get.php"] [unique_id "al4ahEfjhWEjDbtLXL6dEgAAAJI"]
[Mon Jul 20 06:54:28.905385 2026] [security2:error] [pid 1033876:tid 1034020] [client 20.151.205.204:32358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/get.php"] [unique_id "al4ahEfjhWEjDbtLXL6dEgAAAJI"]
[Mon Jul 20 06:54:29.033878 2026] [security2:error] [pid 1033876:tid 1034087] [client 77.110.127.138:59254] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 519 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ahUfjhWEjDbtLXL6dGAAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:29.119101 2026] [security2:error] [pid 1033876:tid 1034040] [client 20.151.205.204:42853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/images.php"] [unique_id "al4ahUfjhWEjDbtLXL6dHAAAAKY"]
[Mon Jul 20 06:54:29.119189 2026] [security2:error] [pid 1033876:tid 1034040] [client 20.151.205.204:42853] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/images.php"] [unique_id "al4ahUfjhWEjDbtLXL6dHAAAAKY"]
[Mon Jul 20 06:54:29.265233 2026] [security2:error] [pid 1033876:tid 1034018] [client 161.118.218.103:65269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ahUfjhWEjDbtLXL6dNAAAAJA"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:29.298810 2026] [security2:error] [pid 1033876:tid 1034008] [client 20.151.205.204:33278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/alls.php"] [unique_id "al4ahUfjhWEjDbtLXL6dNQAAAIY"]
[Mon Jul 20 06:54:29.298997 2026] [security2:error] [pid 1033876:tid 1034008] [client 20.151.205.204:33278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/alls.php"] [unique_id "al4ahUfjhWEjDbtLXL6dNQAAAIY"]
[Mon Jul 20 06:54:29.464916 2026] [security2:error] [pid 1033876:tid 1034089] [client 50.116.65.227:48564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ahUfjhWEjDbtLXL6dQAAAANc"]
[Mon Jul 20 06:54:29.475460 2026] [security2:error] [pid 1033876:tid 1034073] [client 50.116.65.227:48568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ahUfjhWEjDbtLXL6dQwAAAMc"]
[Mon Jul 20 06:54:29.478004 2026] [security2:error] [pid 1033876:tid 1034042] [client 20.151.205.204:59531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/yyu.php"] [unique_id "al4ahUfjhWEjDbtLXL6dRAAAAKg"]
[Mon Jul 20 06:54:29.478086 2026] [security2:error] [pid 1033876:tid 1034042] [client 20.151.205.204:59531] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/yyu.php"] [unique_id "al4ahUfjhWEjDbtLXL6dRAAAAKg"]
[Mon Jul 20 06:54:29.558703 2026] [security2:error] [pid 1033876:tid 1033905] [remote 68.178.165.65:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ahUfjhWEjDbtLXL6dTAAA5xs"]
[Mon Jul 20 06:54:29.638027 2026] [security2:error] [pid 1033876:tid 1033885] [remote 8.217.108.67:35600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ahUfjhWEjDbtLXL6dUAAAxAc"]
[Mon Jul 20 06:54:29.638291 2026] [security2:error] [pid 1033876:tid 1034070] [client 8.217.108.67:35600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ahUfjhWEjDbtLXL6dUAAAxAc"]
[Mon Jul 20 06:54:29.694422 2026] [security2:error] [pid 1033876:tid 1034101] [client 20.151.205.204:60845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/by.php"] [unique_id "al4ahUfjhWEjDbtLXL6dVAAAAOM"]
[Mon Jul 20 06:54:29.694559 2026] [security2:error] [pid 1033876:tid 1034101] [client 20.151.205.204:60845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/by.php"] [unique_id "al4ahUfjhWEjDbtLXL6dVAAAAOM"]
[Mon Jul 20 06:54:29.729323 2026] [security2:error] [pid 1033876:tid 1034028] [client 45.156.129.163:53416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ahUfjhWEjDbtLXL6dSQAAAJo"]
[Mon Jul 20 06:54:29.817455 2026] [security2:error] [pid 1033876:tid 1033956] [remote 192.241.143.148:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ahUfjhWEjDbtLXL6daAABBE4"]
[Mon Jul 20 06:54:29.843843 2026] [security2:error] [pid 1033876:tid 1034007] [client 161.118.218.103:49245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ahUfjhWEjDbtLXL6dbAAAAIU"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:29.973454 2026] [security2:error] [pid 1033876:tid 1034012] [client 20.151.205.204:21713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/FAQ.php"] [unique_id "al4ahUfjhWEjDbtLXL6dbwAAAIo"]
[Mon Jul 20 06:54:29.973542 2026] [security2:error] [pid 1033876:tid 1034012] [client 20.151.205.204:21713] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/FAQ.php"] [unique_id "al4ahUfjhWEjDbtLXL6dbwAAAIo"]
[Mon Jul 20 06:54:30.022136 2026] [security2:error] [pid 1033876:tid 1033883] [remote 68.178.165.65:57574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ahkfjhWEjDbtLXL6deAAAxAU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:30.135084 2026] [security2:error] [pid 1033876:tid 1033887] [remote 192.241.143.148:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ahkfjhWEjDbtLXL6dhAAAkQk"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:30.158258 2026] [security2:error] [pid 1033876:tid 1034104] [client 20.151.205.204:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/coffexium.php"] [unique_id "al4ahkfjhWEjDbtLXL6dhgAAAOY"]
[Mon Jul 20 06:54:30.158339 2026] [security2:error] [pid 1033876:tid 1034104] [client 20.151.205.204:56306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/coffexium.php"] [unique_id "al4ahkfjhWEjDbtLXL6dhgAAAOY"]
[Mon Jul 20 06:54:30.223057 2026] [security2:error] [pid 1033876:tid 1034047] [client 122.183.32.225:13915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ahkfjhWEjDbtLXL6djQAAAK0"]
[Mon Jul 20 06:54:30.223233 2026] [security2:error] [pid 1033876:tid 1034047] [client 122.183.32.225:13915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ahkfjhWEjDbtLXL6djQAAAK0"]
[Mon Jul 20 06:54:30.230277 2026] [security2:error] [pid 1033876:tid 1034075] [client 104.234.53.69:56063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6dhwAAAMk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:30.239482 2026] [security2:error] [pid 1033876:tid 1034087] [client 152.58.191.29:49298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ahkfjhWEjDbtLXL6dkAAAANU"]
[Mon Jul 20 06:54:30.240229 2026] [security2:error] [pid 1033876:tid 1034087] [client 152.58.191.29:49298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4ahkfjhWEjDbtLXL6dkAAAANU"]
[Mon Jul 20 06:54:30.280633 2026] [security2:error] [pid 1033876:tid 1034082] [client 77.110.127.138:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ahkfjhWEjDbtLXL6dkwAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:30.280768 2026] [security2:error] [pid 1033876:tid 1034082] [client 77.110.127.138:59267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ahkfjhWEjDbtLXL6dkwAAANA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:30.422403 2026] [security2:error] [pid 1033876:tid 1034035] [client 161.118.218.103:49617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6dngAAAKE"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:30.438722 2026] [security2:error] [pid 1033876:tid 1034033] [client 77.110.127.138:59269] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 13 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ahkfjhWEjDbtLXL6dnwAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:30.752017 2026] [core:error] [pid 1033876:tid 1034052] [client 14.225.17.146:60053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:30.752050 2026] [core:error] [pid 1033876:tid 1034052] [client 14.225.17.146:60053] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:30.831504 2026] [security2:error] [pid 1033876:tid 1034073] [client 45.156.129.160:53854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6dpgAAAMc"]
[Mon Jul 20 06:54:30.911786 2026] [security2:error] [pid 1033876:tid 1034130] [client 14.225.17.146:51356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4ahUfjhWEjDbtLXL6dRQAAAQA"]
[Mon Jul 20 06:54:30.920623 2026] [security2:error] [pid 1033876:tid 1033952] [remote 41.186.86.12:35116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ahkfjhWEjDbtLXL6dwwAA0Uo"]
[Mon Jul 20 06:54:30.954166 2026] [security2:error] [pid 1033876:tid 1034066] [client 217.142.18.172:29887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ahkfjhWEjDbtLXL6dxgAAAMA"]
[Mon Jul 20 06:54:30.957633 2026] [security2:error] [pid 1033876:tid 1034066] [client 217.142.18.172:29887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ahkfjhWEjDbtLXL6dxgAAAMA"]
[Mon Jul 20 06:54:31.003977 2026] [security2:error] [pid 1033876:tid 1034028] [client 161.118.218.103:50025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-login.php"] [unique_id "al4ah0fjhWEjDbtLXL6dywAAAJo"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:31.047089 2026] [security2:error] [pid 1033876:tid 1033995] [remote 188.166.241.141:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4ah0fjhWEjDbtLXL6dzAAAoHU"]
[Mon Jul 20 06:54:31.255169 2026] [security2:error] [pid 1033876:tid 1034015] [client 104.234.53.69:56063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ah0fjhWEjDbtLXL6d3gAAAI0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:31.418800 2026] [security2:error] [pid 1033876:tid 1034026] [client 14.225.17.146:51432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6ddQAAAJg"], referer: http://detroitcsc.com/wp-old
[Mon Jul 20 06:54:31.437571 2026] [security2:error] [pid 1033876:tid 1033989] [remote 188.166.241.141:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4ah0fjhWEjDbtLXL6d7gAApm8"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 06:54:31.527486 2026] [security2:error] [pid 1033876:tid 1034076] [client 14.225.17.146:51891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6dgwAAAMo"], referer: http://balticsteelmgmt.com/wp-old
[Mon Jul 20 06:54:31.583432 2026] [security2:error] [pid 1033876:tid 1034104] [client 161.118.218.103:50413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.218.118.161.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tadlarsen.com"] [uri "/wp-admin/index.php"] [unique_id "al4ah0fjhWEjDbtLXL6d9wAAAOY"], referer: https://tadlarsen.com/wp-login.php
[Mon Jul 20 06:54:31.589509 2026] [security2:error] [pid 1033876:tid 1033897] [remote 41.186.86.12:35116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ah0fjhWEjDbtLXL6d-AAAzhM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:54:32.276832 2026] [security2:error] [pid 1033876:tid 1034041] [client 45.156.129.163:53430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4aiEfjhWEjDbtLXL6eKQAAAKc"]
[Mon Jul 20 06:54:32.420491 2026] [security2:error] [pid 1033876:tid 1034124] [client 174.138.89.209:56528] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.27"] [uri "/"] [unique_id "al4aiEfjhWEjDbtLXL6eNwAAAPo"]
[Mon Jul 20 06:54:32.548447 2026] [security2:error] [pid 1033876:tid 1034106] [client 174.138.89.209:47826] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.64.27"] [uri "/"] [unique_id "al4aiEfjhWEjDbtLXL6ePgAAAOg"]
[Mon Jul 20 06:54:32.819715 2026] [security2:error] [pid 1033876:tid 1034128] [client 14.225.17.146:51628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6duwAAAP4"], referer: http://www.justinagrayman.com/wp-old
[Mon Jul 20 06:54:33.131847 2026] [security2:error] [pid 1033876:tid 1034111] [client 103.238.106.162:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aiUfjhWEjDbtLXL6eagAAAO0"]
[Mon Jul 20 06:54:33.132000 2026] [security2:error] [pid 1033876:tid 1034111] [client 103.238.106.162:42636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aiUfjhWEjDbtLXL6eagAAAO0"]
[Mon Jul 20 06:54:33.159678 2026] [security2:error] [pid 1033876:tid 1034015] [client 50.116.47.181:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4aiEfjhWEjDbtLXL6eRQAAAI0"]
[Mon Jul 20 06:54:33.168631 2026] [security2:error] [pid 1033876:tid 1034047] [client 50.116.47.181:52388] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/"] [unique_id "al4aiEfjhWEjDbtLXL6eQQAAAK0"]
[Mon Jul 20 06:54:33.351021 2026] [security2:error] [pid 1033876:tid 1034021] [client 77.110.127.138:59275] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 818 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aiUfjhWEjDbtLXL6efgAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:33.453943 2026] [security2:error] [pid 1033876:tid 1034115] [client 45.156.129.161:19632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4aiUfjhWEjDbtLXL6edwAAAPE"]
[Mon Jul 20 06:54:33.843619 2026] [security2:error] [pid 1033876:tid 1034113] [client 57.141.18.28:59536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ahkfjhWEjDbtLXL6drgAA7wQ"]
[Mon Jul 20 06:54:33.981160 2026] [security2:error] [pid 1033876:tid 1034121] [client 50.116.47.181:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4aiUfjhWEjDbtLXL6edQAAAPc"]
[Mon Jul 20 06:54:33.982626 2026] [security2:error] [pid 1033876:tid 1034125] [client 50.116.47.181:52388] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/ar/"] [unique_id "al4aiUfjhWEjDbtLXL6ecAAAAPs"]
[Mon Jul 20 06:54:34.299379 2026] [core:error] [pid 1033876:tid 1034101] [client 14.225.17.146:60031] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wp-old
[Mon Jul 20 06:54:34.299400 2026] [core:error] [pid 1033876:tid 1034101] [client 14.225.17.146:60031] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/wp-old
[Mon Jul 20 06:54:34.569805 2026] [security2:error] [pid 1033876:tid 1034079] [client 104.234.53.83:23283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aikfjhWEjDbtLXL6e1wAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:34.792333 2026] [security2:error] [pid 1033876:tid 1034083] [client 14.225.17.146:50224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4aiUfjhWEjDbtLXL6eawAAANE"], referer: http://fluidtemple.org/wp-old
[Mon Jul 20 06:54:34.966883 2026] [security2:error] [pid 1033876:tid 1034015] [client 77.110.127.138:59283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aikfjhWEjDbtLXL6e9AAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:34.966970 2026] [security2:error] [pid 1033876:tid 1034015] [client 77.110.127.138:59283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aikfjhWEjDbtLXL6e9AAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:35.119714 2026] [security2:error] [pid 1033876:tid 1034063] [client 77.110.127.138:59285] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 618 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ai0fjhWEjDbtLXL6fCQAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:35.147743 2026] [security2:error] [pid 1033876:tid 1034042] [client 77.110.127.138:59286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ai0fjhWEjDbtLXL6fCwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:35.147871 2026] [security2:error] [pid 1033876:tid 1034042] [client 77.110.127.138:59286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ai0fjhWEjDbtLXL6fCwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:35.269776 2026] [security2:error] [pid 1033876:tid 1034115] [client 45.79.207.127:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4aikfjhWEjDbtLXL6e4gAAAPE"]
[Mon Jul 20 06:54:35.272397 2026] [security2:error] [pid 1033876:tid 1034045] [client 45.79.207.127:48130] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/"] [unique_id "al4aikfjhWEjDbtLXL6e3QAAAKs"]
[Mon Jul 20 06:54:35.338846 2026] [security2:error] [pid 1033876:tid 1034106] [client 45.3.42.62:28419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ai0fjhWEjDbtLXL6fGgAAAOg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:35.401409 2026] [security2:error] [pid 1033876:tid 1033906] [remote 156.67.31.167:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ai0fjhWEjDbtLXL6fIQAA5Rw"]
[Mon Jul 20 06:54:35.553560 2026] [security2:error] [pid 1033876:tid 1034012] [client 14.225.17.146:56499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4ai0fjhWEjDbtLXL6fJgAAAIo"], referer: http://mourgroup.com/wp-old
[Mon Jul 20 06:54:35.616982 2026] [security2:error] [pid 1033876:tid 1033995] [remote 156.67.31.167:47388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ai0fjhWEjDbtLXL6fLgAAr3U"], referer: https://rcq.nst.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:35.784674 2026] [security2:error] [pid 1033876:tid 1034032] [client 77.110.127.138:59291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ai0fjhWEjDbtLXL6fQQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:35.784784 2026] [security2:error] [pid 1033876:tid 1034032] [client 77.110.127.138:59291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ai0fjhWEjDbtLXL6fQQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:35.878641 2026] [security2:error] [pid 1033876:tid 1034042] [client 45.3.42.199:9551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ai0fjhWEjDbtLXL6fRwAAAKg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:35.912942 2026] [security2:error] [pid 1033876:tid 1034133] [client 82.102.18.182:51356] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4ai0fjhWEjDbtLXL6fTAAAAQM"]
[Mon Jul 20 06:54:35.916388 2026] [security2:error] [pid 1033876:tid 1034036] [client 187.108.85.186:51240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ai0fjhWEjDbtLXL6fTgAAAKI"]
[Mon Jul 20 06:54:35.916503 2026] [security2:error] [pid 1033876:tid 1034036] [client 187.108.85.186:51240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ai0fjhWEjDbtLXL6fTgAAAKI"]
[Mon Jul 20 06:54:36.007004 2026] [security2:error] [pid 1033876:tid 1034024] [client 45.79.207.127:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4ai0fjhWEjDbtLXL6fGwAAAJY"]
[Mon Jul 20 06:54:36.041712 2026] [security2:error] [pid 1033876:tid 1034132] [client 45.79.207.127:48130] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/ar/"] [unique_id "al4ai0fjhWEjDbtLXL6fFwAAAQI"]
[Mon Jul 20 06:54:36.090212 2026] [security2:error] [pid 1033876:tid 1034117] [client 45.156.129.163:42688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ai0fjhWEjDbtLXL6fSwAAAPM"]
[Mon Jul 20 06:54:36.240646 2026] [security2:error] [pid 1033876:tid 1034129] [client 82.102.18.182:12804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ajEfjhWEjDbtLXL6fcAAAAP8"]
[Mon Jul 20 06:54:36.271335 2026] [security2:error] [pid 1033876:tid 1034065] [client 103.125.179.95:63751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ajEfjhWEjDbtLXL6fdQAAAL8"]
[Mon Jul 20 06:54:36.271503 2026] [security2:error] [pid 1033876:tid 1034065] [client 103.125.179.95:63751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ajEfjhWEjDbtLXL6fdQAAAL8"]
[Mon Jul 20 06:54:36.298830 2026] [security2:error] [pid 1033876:tid 1034091] [client 14.225.17.146:60034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4ai0fjhWEjDbtLXL6fIwAAANk"]
[Mon Jul 20 06:54:36.436730 2026] [security2:error] [pid 1033876:tid 1034071] [client 45.3.42.6:32995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ajEfjhWEjDbtLXL6fggAAAMU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:36.511535 2026] [security2:error] [pid 1033876:tid 1034115] [client 197.186.66.42:54026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ajEfjhWEjDbtLXL6figAAAPE"]
[Mon Jul 20 06:54:36.511668 2026] [security2:error] [pid 1033876:tid 1034115] [client 197.186.66.42:54026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ajEfjhWEjDbtLXL6figAAAPE"]
[Mon Jul 20 06:54:36.612007 2026] [security2:error] [pid 1033876:tid 1034053] [client 45.156.129.162:44554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ajEfjhWEjDbtLXL6fgwAAALM"]
[Mon Jul 20 06:54:36.636247 2026] [security2:error] [pid 1033876:tid 1034068] [client 77.110.127.138:59298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajEfjhWEjDbtLXL6fjwAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:36.636360 2026] [security2:error] [pid 1033876:tid 1034068] [client 77.110.127.138:59298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajEfjhWEjDbtLXL6fjwAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:36.787320 2026] [security2:error] [pid 1033876:tid 1034066] [client 77.110.127.138:59302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajEfjhWEjDbtLXL6fngAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:36.787432 2026] [security2:error] [pid 1033876:tid 1034066] [client 77.110.127.138:59302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajEfjhWEjDbtLXL6fngAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:36.880171 2026] [security2:error] [pid 1033876:tid 1034008] [client 82.102.18.182:38809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ajEfjhWEjDbtLXL6fowAAAIY"]
[Mon Jul 20 06:54:37.031433 2026] [security2:error] [pid 1033876:tid 1034055] [client 65.111.22.238:25109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ajUfjhWEjDbtLXL6fpwAAALU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:37.116314 2026] [security2:error] [pid 1033876:tid 1034076] [client 14.225.17.146:65384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4ajEfjhWEjDbtLXL6fpgAAAMo"], referer: http://39ishlife.com/wp-old
[Mon Jul 20 06:54:37.124857 2026] [security2:error] [pid 1033876:tid 1034018] [client 45.156.129.160:37842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ajEfjhWEjDbtLXL6fpAAAAJA"]
[Mon Jul 20 06:54:37.213466 2026] [security2:error] [pid 1033876:tid 1034071] [client 82.102.18.182:59713] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ajUfjhWEjDbtLXL6ftQAAAMU"]
[Mon Jul 20 06:54:37.249584 2026] [security2:error] [pid 1033876:tid 1034023] [client 77.110.127.138:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajUfjhWEjDbtLXL6fugAAAJU"]
[Mon Jul 20 06:54:37.249680 2026] [security2:error] [pid 1033876:tid 1034023] [client 77.110.127.138:59306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajUfjhWEjDbtLXL6fugAAAJU"]
[Mon Jul 20 06:54:37.335310 2026] [security2:error] [pid 1033876:tid 1034082] [client 57.141.18.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ajUfjhWEjDbtLXL6fswAAANA"]
[Mon Jul 20 06:54:37.525118 2026] [security2:error] [pid 1033876:tid 1034058] [client 14.225.17.146:61636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4ajEfjhWEjDbtLXL6fbwAAALg"], referer: http://whiteoutcb.com/wp-old
[Mon Jul 20 06:54:37.558049 2026] [security2:error] [pid 1033876:tid 1034008] [client 82.102.18.182:34616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4ajUfjhWEjDbtLXL6f0AAAAIY"]
[Mon Jul 20 06:54:37.611986 2026] [security2:error] [pid 1033876:tid 1034116] [client 65.111.23.133:53407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ajUfjhWEjDbtLXL6f1QAAAPI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:37.752589 2026] [security2:error] [pid 1033876:tid 1034092] [client 77.110.127.138:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajUfjhWEjDbtLXL6f4gAAANo"]
[Mon Jul 20 06:54:37.752707 2026] [security2:error] [pid 1033876:tid 1034092] [client 77.110.127.138:59274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ajUfjhWEjDbtLXL6f4gAAANo"]
[Mon Jul 20 06:54:37.887134 2026] [security2:error] [pid 1033876:tid 1034128] [client 77.110.127.138:59313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 804 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ajUfjhWEjDbtLXL6f8wAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:37.894860 2026] [security2:error] [pid 1033876:tid 1034094] [client 82.102.18.182:54053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ajUfjhWEjDbtLXL6f9QAAANw"]
[Mon Jul 20 06:54:38.095553 2026] [security2:error] [pid 1033876:tid 1034054] [client 45.156.129.161:36674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4ajUfjhWEjDbtLXL6f9AAAALQ"]
[Mon Jul 20 06:54:38.099153 2026] [security2:error] [pid 1033876:tid 1034079] [client 14.225.17.146:65292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4ajkfjhWEjDbtLXL6f-gAAAM0"], referer: https://39ishlife.com/wp-old
[Mon Jul 20 06:54:38.183687 2026] [security2:error] [pid 1033876:tid 1034078] [client 198.235.24.16:59432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.testing.ghivs.com"] [uri "/public/index.php"] [unique_id "al4ajkfjhWEjDbtLXL6gAQAAAMw"]
[Mon Jul 20 06:54:38.211856 2026] [security2:error] [pid 1033876:tid 1034059] [client 104.207.52.76:11487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ajkfjhWEjDbtLXL6gDQAAALk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:38.221183 2026] [security2:error] [pid 1033876:tid 1034091] [client 82.102.18.182:34636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4ajkfjhWEjDbtLXL6gEwAAANk"]
[Mon Jul 20 06:54:38.249708 2026] [security2:error] [pid 1033876:tid 1034056] [client 14.225.17.146:60100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4ai0fjhWEjDbtLXL6fRgAAALY"], referer: http://drewsasburyparkbeachhouse.com/wp-old
[Mon Jul 20 06:54:38.252799 2026] [security2:error] [pid 1033876:tid 1034112] [client 57.141.18.49:44560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ai0fjhWEjDbtLXL6fKQAA7is"]
[Mon Jul 20 06:54:38.279193 2026] [security2:error] [pid 1033876:tid 1034120] [client 74.208.214.194:60580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ajkfjhWEjDbtLXL6gGwAAAPY"]
[Mon Jul 20 06:54:38.454163 2026] [security2:error] [pid 1033876:tid 1033918] [remote 20.153.140.50:57224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4ajkfjhWEjDbtLXL6gIwAAwCg"]
[Mon Jul 20 06:54:38.544188 2026] [core:error] [pid 1033876:tid 1034086] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:38.544210 2026] [core:error] [pid 1033876:tid 1034086] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:54:38.544788 2026] [security2:error] [pid 1033876:tid 1034070] [client 82.102.18.182:34648] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4ajkfjhWEjDbtLXL6gMQAAAMQ"]
[Mon Jul 20 06:54:38.586177 2026] [security2:error] [pid 1033876:tid 1034032] [client 117.222.139.248:58789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ajkfjhWEjDbtLXL6gNAAAAJ4"]
[Mon Jul 20 06:54:38.586310 2026] [security2:error] [pid 1033876:tid 1034032] [client 117.222.139.248:58789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ajkfjhWEjDbtLXL6gNAAAAJ4"]
[Mon Jul 20 06:54:38.757988 2026] [security2:error] [pid 1033876:tid 1034090] [client 117.247.108.24:58173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ajkfjhWEjDbtLXL6gRAAAANg"]
[Mon Jul 20 06:54:38.758083 2026] [security2:error] [pid 1033876:tid 1034090] [client 117.247.108.24:58173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ajkfjhWEjDbtLXL6gRAAAANg"]
[Mon Jul 20 06:54:38.761187 2026] [security2:error] [pid 1033876:tid 1034134] [client 45.3.42.14:42847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4ajkfjhWEjDbtLXL6gQgAAAQQ"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:38.827308 2026] [security2:error] [pid 1033876:tid 1034004] [remote 209.42.18.223:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ajkfjhWEjDbtLXL6gRwAAzH4"]
[Mon Jul 20 06:54:39.357614 2026] [http2:info] [pid 15216:tid 15216] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:54:39.380023 2026] [security2:error] [pid 15216:tid 15346] [client 82.102.18.182:8031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4aj9tIy0gkFcVddGZgKAAAAQo"]
[Mon Jul 20 06:54:39.439539 2026] [security2:error] [pid 1033876:tid 1034030] [client 14.225.17.146:50612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4ajkfjhWEjDbtLXL6gLQAAAJw"], referer: http://retzkolonglogistics.com/wp-old
[Mon Jul 20 06:54:39.556435 2026] [security2:error] [pid 15216:tid 15232] [remote 209.42.18.223:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aj9tIy0gkFcVddGZgUgABHg8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:54:39.563442 2026] [security2:error] [pid 15216:tid 15353] [client 45.156.129.162:44568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4aj9tIy0gkFcVddGZgTQAAARE"]
[Mon Jul 20 06:54:39.712965 2026] [security2:error] [pid 15216:tid 15426] [client 82.102.18.182:34670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4aj9tIy0gkFcVddGZgWQAAAVo"]
[Mon Jul 20 06:54:39.846670 2026] [security2:error] [pid 15216:tid 15348] [client 183.82.98.154:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aj9tIy0gkFcVddGZgZgAAAQw"]
[Mon Jul 20 06:54:39.846789 2026] [security2:error] [pid 15216:tid 15348] [client 183.82.98.154:59179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aj9tIy0gkFcVddGZgZgAAAQw"]
[Mon Jul 20 06:54:39.868765 2026] [security2:error] [pid 15216:tid 15449] [client 77.110.127.138:59318] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 378 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aj9tIy0gkFcVddGZgagAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:40.055170 2026] [security2:error] [pid 15216:tid 15380] [client 82.102.18.182:64960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4akNtIy0gkFcVddGZgdQAAASw"]
[Mon Jul 20 06:54:40.072156 2026] [security2:error] [pid 15216:tid 15435] [client 45.156.129.160:37850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4aj9tIy0gkFcVddGZgZwAAAWM"]
[Mon Jul 20 06:54:40.076979 2026] [security2:error] [pid 15216:tid 15245] [remote 20.153.140.50:57226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4akNtIy0gkFcVddGZgdgABVBw"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 06:54:40.323688 2026] [security2:error] [pid 15216:tid 15254] [remote 57.141.18.57:57844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4akNtIy0gkFcVddGZgjQABQCU"]
[Mon Jul 20 06:54:40.381678 2026] [security2:error] [pid 15216:tid 15410] [client 82.102.18.182:34682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4akNtIy0gkFcVddGZglAAAAUo"]
[Mon Jul 20 06:54:40.674345 2026] [security2:error] [pid 15216:tid 15261] [remote 217.61.143.92:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4akNtIy0gkFcVddGZgowABJiw"]
[Mon Jul 20 06:54:40.710755 2026] [security2:error] [pid 15216:tid 15447] [client 82.102.18.182:34686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4akNtIy0gkFcVddGZgpgAAAW8"]
[Mon Jul 20 06:54:40.753410 2026] [security2:error] [pid 15216:tid 15360] [client 104.234.53.63:39927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4akNtIy0gkFcVddGZgngAAARg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:40.919663 2026] [security2:error] [pid 15216:tid 15270] [remote 217.61.143.92:34376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4akNtIy0gkFcVddGZgvAABKzU"], referer: https://maa.hws.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:40.935301 2026] [security2:error] [pid 15216:tid 15405] [client 152.58.191.29:50000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4akNtIy0gkFcVddGZgvgAAAUU"]
[Mon Jul 20 06:54:40.940046 2026] [security2:error] [pid 15216:tid 15405] [client 152.58.191.29:50000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4akNtIy0gkFcVddGZgvgAAAUU"]
[Mon Jul 20 06:54:41.021351 2026] [security2:error] [pid 15216:tid 15399] [client 82.102.18.182:34702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4akdtIy0gkFcVddGZgxQAAAT8"]
[Mon Jul 20 06:54:41.200516 2026] [security2:error] [pid 15216:tid 15417] [client 122.183.32.225:10760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4akdtIy0gkFcVddGZgzQAAAVE"]
[Mon Jul 20 06:54:41.200630 2026] [security2:error] [pid 15216:tid 15417] [client 122.183.32.225:10760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4akdtIy0gkFcVddGZgzQAAAVE"]
[Mon Jul 20 06:54:41.200771 2026] [security2:error] [pid 15216:tid 15361] [client 77.110.127.138:59323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4akdtIy0gkFcVddGZgzAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:41.200843 2026] [security2:error] [pid 15216:tid 15361] [client 77.110.127.138:59323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4akdtIy0gkFcVddGZgzAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:41.352832 2026] [security2:error] [pid 15216:tid 15369] [client 77.110.127.138:59324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4akdtIy0gkFcVddGZg4QAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:41.369383 2026] [security2:error] [pid 15216:tid 15437] [client 82.102.18.182:34704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.vnz.tzd.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4akdtIy0gkFcVddGZg4wAAAWU"]
[Mon Jul 20 06:54:41.411838 2026] [security2:error] [pid 15216:tid 15450] [client 14.251.3.155:54779] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4akdtIy0gkFcVddGZg5QAAAXI"]
[Mon Jul 20 06:54:41.452232 2026] [security2:error] [pid 15216:tid 15377] [client 217.142.18.172:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4akdtIy0gkFcVddGZg5wAAASk"]
[Mon Jul 20 06:54:41.458988 2026] [security2:error] [pid 15216:tid 15352] [client 45.156.129.161:36690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4akdtIy0gkFcVddGZg0gAAARA"]
[Mon Jul 20 06:54:41.459694 2026] [security2:error] [pid 15216:tid 15377] [client 217.142.18.172:40300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4akdtIy0gkFcVddGZg5wAAASk"]
[Mon Jul 20 06:54:41.643907 2026] [security2:error] [pid 15216:tid 15453] [client 50.116.65.227:28998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4akdtIy0gkFcVddGZg6QAAAXU"]
[Mon Jul 20 06:54:41.838373 2026] [security2:error] [pid 15216:tid 15388] [client 50.116.65.227:29012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4akdtIy0gkFcVddGZg-AAAATQ"]
[Mon Jul 20 06:54:42.008211 2026] [security2:error] [pid 15216:tid 15418] [client 119.28.140.106:51566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4akNtIy0gkFcVddGZglQAAAVI"]
[Mon Jul 20 06:54:42.030061 2026] [security2:error] [pid 15216:tid 15303] [remote 188.166.241.141:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4akttIy0gkFcVddGZhHwABbVY"]
[Mon Jul 20 06:54:42.142275 2026] [security2:error] [pid 15216:tid 15464] [client 20.151.205.204:20591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/red.php"] [unique_id "al4akttIy0gkFcVddGZhKgAAAYA"]
[Mon Jul 20 06:54:42.142398 2026] [security2:error] [pid 15216:tid 15464] [client 20.151.205.204:20591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/red.php"] [unique_id "al4akttIy0gkFcVddGZhKgAAAYA"]
[Mon Jul 20 06:54:42.156208 2026] [security2:error] [pid 15216:tid 15414] [client 57.141.18.52:22302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aj9tIy0gkFcVddGZgVAABThE"]
[Mon Jul 20 06:54:42.228578 2026] [security2:error] [pid 15216:tid 15370] [client 4.194.24.143:7604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/nine2code.php"] [unique_id "al4akttIy0gkFcVddGZhMQAAASI"]
[Mon Jul 20 06:54:42.427248 2026] [security2:error] [pid 15216:tid 15316] [remote 188.166.241.141:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4akttIy0gkFcVddGZhQAABVmM"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 06:54:42.461797 2026] [security2:error] [pid 15216:tid 15393] [client 14.225.17.146:54167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4akdtIy0gkFcVddGZg2AAAATk"], referer: http://collectingrealestate.com/wp-old
[Mon Jul 20 06:54:42.463977 2026] [security2:error] [pid 15216:tid 15426] [client 104.234.53.63:39927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4akttIy0gkFcVddGZhRAAAAVo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:42.499302 2026] [security2:error] [pid 15216:tid 15318] [remote 144.79.133.30:52564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4akttIy0gkFcVddGZhSAABYWU"]
[Mon Jul 20 06:54:42.753160 2026] [security2:error] [pid 15216:tid 15446] [client 77.110.127.138:59330] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4akttIy0gkFcVddGZhVgAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:42.780159 2026] [security2:error] [pid 15216:tid 15361] [client 4.194.24.143:6492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/num.php"] [unique_id "al4akttIy0gkFcVddGZhWgAAARk"]
[Mon Jul 20 06:54:42.924951 2026] [security2:error] [pid 15216:tid 15436] [client 77.110.127.138:59334] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 748 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4akttIy0gkFcVddGZhbgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:43.038288 2026] [security2:error] [pid 15216:tid 15407] [client 14.225.17.146:54065] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4akNtIy0gkFcVddGZgwQAAAUc"], referer: http://jvcmotorsports.com/wp-old
[Mon Jul 20 06:54:43.272538 2026] [security2:error] [pid 15216:tid 15418] [client 14.225.17.146:54793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4akttIy0gkFcVddGZhQwAAAVI"]
[Mon Jul 20 06:54:43.326440 2026] [security2:error] [pid 15216:tid 15455] [client 74.208.214.194:60582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ak9tIy0gkFcVddGZhkAAAAXc"]
[Mon Jul 20 06:54:43.359310 2026] [security2:error] [pid 15216:tid 15384] [client 14.225.17.146:54877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4akttIy0gkFcVddGZhagAAATA"], referer: http://backandneckpainrelieflaceychiropractor.com/wp-old
[Mon Jul 20 06:54:43.363344 2026] [security2:error] [pid 15216:tid 15351] [client 4.194.24.143:46644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4ak9tIy0gkFcVddGZhlQAAAQ8"]
[Mon Jul 20 06:54:43.555457 2026] [security2:error] [pid 15216:tid 15225] [remote 68.183.43.38:50292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.43.183.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4ak9tIy0gkFcVddGZhogABXwg"]
[Mon Jul 20 06:54:43.555661 2026] [security2:error] [pid 15216:tid 15431] [client 68.183.43.38:50292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4ak9tIy0gkFcVddGZhogABXwg"]
[Mon Jul 20 06:54:43.623381 2026] [security2:error] [pid 15216:tid 15422] [client 103.238.106.162:60730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ak9tIy0gkFcVddGZhqAAAAVY"]
[Mon Jul 20 06:54:43.624294 2026] [security2:error] [pid 15216:tid 15422] [client 103.238.106.162:60730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ak9tIy0gkFcVddGZhqAAAAVY"]
[Mon Jul 20 06:54:43.656711 2026] [security2:error] [pid 15216:tid 15230] [remote 144.79.133.30:52564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4ak9tIy0gkFcVddGZhqQABPg0"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 06:54:43.686138 2026] [security2:error] [pid 15216:tid 15465] [client 77.110.127.138:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ak9tIy0gkFcVddGZhrQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:43.686227 2026] [security2:error] [pid 15216:tid 15465] [client 77.110.127.138:59338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ak9tIy0gkFcVddGZhrQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:43.988609 2026] [security2:error] [pid 15216:tid 15452] [client 4.194.24.143:7383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/option.php"] [unique_id "al4ak9tIy0gkFcVddGZhxQAAAXQ"]
[Mon Jul 20 06:54:44.329461 2026] [security2:error] [pid 15216:tid 15380] [client 57.141.18.109:38694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4akttIy0gkFcVddGZhJwABLFg"]
[Mon Jul 20 06:54:44.333967 2026] [security2:error] [pid 15216:tid 15246] [remote 8.217.108.67:7484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4alNtIy0gkFcVddGZh3AABOB0"]
[Mon Jul 20 06:54:44.334120 2026] [security2:error] [pid 15216:tid 15392] [client 8.217.108.67:7484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4alNtIy0gkFcVddGZh3AABOB0"]
[Mon Jul 20 06:54:44.368078 2026] [security2:error] [pid 15216:tid 15461] [client 77.110.127.138:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4alNtIy0gkFcVddGZh3gAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:44.368162 2026] [security2:error] [pid 15216:tid 15461] [client 77.110.127.138:59317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4alNtIy0gkFcVddGZh3gAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:44.432238 2026] [security2:error] [pid 15216:tid 15347] [client 77.110.127.138:59342] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_hit"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4alNtIy0gkFcVddGZh4wAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:44.496594 2026] [core:error] [pid 15216:tid 15468] [client 14.225.17.146:64790] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/wp-old
[Mon Jul 20 06:54:44.496610 2026] [core:error] [pid 15216:tid 15468] [client 14.225.17.146:64790] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/wp-old
[Mon Jul 20 06:54:44.544398 2026] [security2:error] [pid 15216:tid 15381] [client 77.110.127.138:59343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4alNtIy0gkFcVddGZh8AAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:44.544503 2026] [security2:error] [pid 15216:tid 15381] [client 77.110.127.138:59343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4alNtIy0gkFcVddGZh8AAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:44.550147 2026] [security2:error] [pid 15216:tid 15403] [client 4.194.24.143:6469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/p.php"] [unique_id "al4alNtIy0gkFcVddGZh8QAAAUM"]
[Mon Jul 20 06:54:44.739422 2026] [security2:error] [pid 15216:tid 15390] [client 170.64.190.70:57648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4alNtIy0gkFcVddGZh-AAAATY"]
[Mon Jul 20 06:54:44.806599 2026] [proxy:error] [pid 15216:tid 15432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:54:44.806648 2026] [proxy_http:error] [pid 15216:tid 15432] [client 20.151.205.204:62491] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:54:44.807141 2026] [proxy:error] [pid 15216:tid 15432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:54:44.807171 2026] [proxy_http:error] [pid 15216:tid 15432] [client 20.151.205.204:62491] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:54:44.807274 2026] [security2:error] [pid 15216:tid 15432] [client 20.151.205.204:62491] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4alNtIy0gkFcVddGZiBwAAAWA"]
[Mon Jul 20 06:54:45.091369 2026] [security2:error] [pid 15216:tid 15392] [client 4.194.24.143:6520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/past.php"] [unique_id "al4aldtIy0gkFcVddGZiIQAAATg"]
[Mon Jul 20 06:54:45.151145 2026] [security2:error] [pid 15216:tid 15269] [remote 154.66.198.148:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4aldtIy0gkFcVddGZiKAABKDQ"]
[Mon Jul 20 06:54:45.188530 2026] [security2:error] [pid 15216:tid 15380] [client 45.156.129.161:17830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4alNtIy0gkFcVddGZiFgAAASw"]
[Mon Jul 20 06:54:45.218341 2026] [security2:error] [pid 15216:tid 15349] [client 77.110.127.138:59346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aldtIy0gkFcVddGZiMAAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:45.218458 2026] [security2:error] [pid 15216:tid 15349] [client 77.110.127.138:59346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aldtIy0gkFcVddGZiMAAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:45.254033 2026] [security2:error] [pid 15216:tid 15457] [client 74.7.227.179:41912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4aldtIy0gkFcVddGZiJQABeTY"], referer: https://tejasenvironmental.com/p=295689
[Mon Jul 20 06:54:45.375814 2026] [security2:error] [pid 15216:tid 15434] [client 77.110.127.138:59347] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 547 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aldtIy0gkFcVddGZiPQAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:45.389130 2026] [security2:error] [pid 15216:tid 15350] [client 170.64.190.70:57701] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "kidsklubz.org"] [uri "/wp-login.php"] [unique_id "al4aldtIy0gkFcVddGZiQAAAAQ4"]
[Mon Jul 20 06:54:45.632465 2026] [security2:error] [pid 15216:tid 15429] [client 4.194.24.143:16098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/php.php"] [unique_id "al4aldtIy0gkFcVddGZiVQAAAV0"]
[Mon Jul 20 06:54:45.689815 2026] [security2:error] [pid 15216:tid 15451] [client 45.156.129.163:52044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4aldtIy0gkFcVddGZiRAAAAXM"]
[Mon Jul 20 06:54:45.711613 2026] [security2:error] [pid 15216:tid 15292] [remote 154.66.198.148:64838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4aldtIy0gkFcVddGZiXAABWEs"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:54:45.814716 2026] [security2:error] [pid 15216:tid 15460] [client 158.173.166.181:40107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4aldtIy0gkFcVddGZiYwAAAXw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:54:45.960866 2026] [security2:error] [pid 15216:tid 15415] [client 14.225.17.146:59648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4aldtIy0gkFcVddGZiYQAAAU8"], referer: http://thesoloceos.com/wp-old
[Mon Jul 20 06:54:46.100604 2026] [security2:error] [pid 15216:tid 15445] [client 77.110.127.138:59356] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4alttIy0gkFcVddGZiiQAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:46.104522 2026] [security2:error] [pid 15216:tid 15348] [client 77.110.127.138:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4alttIy0gkFcVddGZiigAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:46.104622 2026] [security2:error] [pid 15216:tid 15348] [client 77.110.127.138:59357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4alttIy0gkFcVddGZiigAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:46.187792 2026] [security2:error] [pid 15216:tid 15398] [client 45.156.129.163:52060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4aldtIy0gkFcVddGZiegAAAT4"]
[Mon Jul 20 06:54:46.228877 2026] [security2:error] [pid 15216:tid 15394] [client 4.194.24.143:16065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/php8.php"] [unique_id "al4alttIy0gkFcVddGZikQAAATo"]
[Mon Jul 20 06:54:46.319207 2026] [security2:error] [pid 15216:tid 15470] [client 20.151.205.204:29002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4alttIy0gkFcVddGZipQAAAYY"]
[Mon Jul 20 06:54:46.319384 2026] [security2:error] [pid 15216:tid 15470] [client 20.151.205.204:29002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4alttIy0gkFcVddGZipQAAAYY"]
[Mon Jul 20 06:54:46.350869 2026] [security2:error] [pid 15216:tid 15304] [remote 167.71.240.77:38406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.240.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4alttIy0gkFcVddGZiqAABfVc"]
[Mon Jul 20 06:54:46.351110 2026] [security2:error] [pid 15216:tid 15461] [client 167.71.240.77:38406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4alttIy0gkFcVddGZiqAABfVc"]
[Mon Jul 20 06:54:46.687375 2026] [security2:error] [pid 15216:tid 15349] [client 187.108.85.186:51778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4alttIy0gkFcVddGZiywAAAQ0"]
[Mon Jul 20 06:54:46.687538 2026] [security2:error] [pid 15216:tid 15349] [client 187.108.85.186:51778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4alttIy0gkFcVddGZiywAAAQ0"]
[Mon Jul 20 06:54:46.769238 2026] [security2:error] [pid 15216:tid 15404] [client 4.194.24.143:16117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/phpinfo.php"] [unique_id "al4alttIy0gkFcVddGZizwAAAUQ"]
[Mon Jul 20 06:54:46.800395 2026] [security2:error] [pid 15216:tid 15356] [client 66.249.69.33:39366] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "bundleofjoyandpoop.com"] [uri "/robots.txt"] [unique_id "al4alttIy0gkFcVddGZi0gAAARQ"]
[Mon Jul 20 06:54:46.989925 2026] [security2:error] [pid 15216:tid 15431] [client 14.225.17.146:50820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4alttIy0gkFcVddGZi1QAAAV8"], referer: https://thesoloceos.com/wp-old
[Mon Jul 20 06:54:46.993050 2026] [security2:error] [pid 15216:tid 15454] [client 103.125.179.95:64401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4alttIy0gkFcVddGZi3QAAAXY"]
[Mon Jul 20 06:54:46.993206 2026] [security2:error] [pid 15216:tid 15454] [client 103.125.179.95:64401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4alttIy0gkFcVddGZi3QAAAXY"]
[Mon Jul 20 06:54:47.199346 2026] [security2:error] [pid 15216:tid 15369] [client 14.225.17.146:64940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4aldtIy0gkFcVddGZiWgAAASE"], referer: http://eframiproperties.com/wp-old
[Mon Jul 20 06:54:47.363501 2026] [security2:error] [pid 15216:tid 15427] [client 45.156.129.163:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4al9tIy0gkFcVddGZi9wAAAVs"]
[Mon Jul 20 06:54:47.415821 2026] [security2:error] [pid 15216:tid 15397] [client 77.110.127.138:59339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4al9tIy0gkFcVddGZjCwAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:47.415946 2026] [security2:error] [pid 15216:tid 15397] [client 77.110.127.138:59339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4al9tIy0gkFcVddGZjCwAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:47.569812 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4al9tIy0gkFcVddGZjJQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:47.569951 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:59373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4al9tIy0gkFcVddGZjJQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:47.573774 2026] [security2:error] [pid 15216:tid 15358] [client 4.194.24.143:7408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/post.php"] [unique_id "al4al9tIy0gkFcVddGZjJgAAARY"]
[Mon Jul 20 06:54:47.806697 2026] [security2:error] [pid 15216:tid 15353] [client 57.141.18.82:62280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aldtIy0gkFcVddGZiRwABET4"]
[Mon Jul 20 06:54:47.953092 2026] [security2:error] [pid 15216:tid 15400] [client 45.156.129.161:17834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4al9tIy0gkFcVddGZjNAAAAUA"]
[Mon Jul 20 06:54:48.117598 2026] [security2:error] [pid 15216:tid 15471] [client 4.194.24.143:7373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4amNtIy0gkFcVddGZjTgAAAYc"]
[Mon Jul 20 06:54:48.182101 2026] [security2:error] [pid 15216:tid 15356] [client 77.110.127.138:59380] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 68 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4amNtIy0gkFcVddGZjUwAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:48.198216 2026] [security2:error] [pid 15216:tid 15349] [client 14.225.17.146:64746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4al9tIy0gkFcVddGZjRQAAAQ0"], referer: http://myspineworld.com/wp-old
[Mon Jul 20 06:54:48.326658 2026] [security2:error] [pid 15216:tid 15379] [client 14.225.17.146:54005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4amNtIy0gkFcVddGZjWwAAASs"], referer: http://dasmarque.com/wp-old
[Mon Jul 20 06:54:48.333956 2026] [security2:error] [pid 15216:tid 15361] [client 104.207.52.123:11959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4amNtIy0gkFcVddGZjXgAAARk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:48.379205 2026] [security2:error] [pid 15216:tid 15373] [client 14.225.17.146:59888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4alttIy0gkFcVddGZixwAAASU"], referer: http://vinovinhowine.com/wp-old
[Mon Jul 20 06:54:48.560555 2026] [security2:error] [pid 15216:tid 15391] [client 45.156.129.163:52078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4amNtIy0gkFcVddGZjZgAAATc"]
[Mon Jul 20 06:54:48.646383 2026] [security2:error] [pid 15216:tid 15424] [client 52.47.76.32:45820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4amNtIy0gkFcVddGZjfQAAAVg"]
[Mon Jul 20 06:54:48.646490 2026] [security2:error] [pid 15216:tid 15424] [client 52.47.76.32:45820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4amNtIy0gkFcVddGZjfQAAAVg"]
[Mon Jul 20 06:54:48.659081 2026] [security2:error] [pid 15216:tid 15416] [client 4.194.24.143:7581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/public/css.php"] [unique_id "al4amNtIy0gkFcVddGZjgAAAAVA"]
[Mon Jul 20 06:54:48.912681 2026] [security2:error] [pid 15216:tid 15364] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.cheesewithjam.com"] [uri "/index.php"] [unique_id "al4alttIy0gkFcVddGZixQAAARw"]
[Mon Jul 20 06:54:48.926184 2026] [security2:error] [pid 15216:tid 15363] [client 65.111.22.70:32781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4amNtIy0gkFcVddGZjoAAAARs"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:54:49.017379 2026] [security2:error] [pid 15216:tid 15393] [client 104.234.53.64:65415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4amdtIy0gkFcVddGZjrgAAATk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:49.096694 2026] [security2:error] [pid 15216:tid 15462] [client 117.222.139.248:59274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4amdtIy0gkFcVddGZjswAAAX4"]
[Mon Jul 20 06:54:49.096836 2026] [security2:error] [pid 15216:tid 15462] [client 117.222.139.248:59274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4amdtIy0gkFcVddGZjswAAAX4"]
[Mon Jul 20 06:54:49.211847 2026] [security2:error] [pid 15216:tid 15418] [client 197.186.66.42:54550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4amdtIy0gkFcVddGZjvgAAAVI"]
[Mon Jul 20 06:54:49.220895 2026] [security2:error] [pid 15216:tid 15459] [client 4.194.24.143:24180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/r.php"] [unique_id "al4amdtIy0gkFcVddGZjwAAAAXs"]
[Mon Jul 20 06:54:49.224856 2026] [security2:error] [pid 15216:tid 15418] [client 197.186.66.42:54550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4amdtIy0gkFcVddGZjvgAAAVI"]
[Mon Jul 20 06:54:49.304802 2026] [security2:error] [pid 15216:tid 15368] [client 14.225.17.146:54138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4amdtIy0gkFcVddGZjugAAASA"], referer: https://myspineworld.com/wp-old
[Mon Jul 20 06:54:49.325967 2026] [security2:error] [pid 15216:tid 15391] [client 77.110.127.138:59394] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4amdtIy0gkFcVddGZjyQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:49.472714 2026] [security2:error] [pid 15216:tid 15381] [client 117.247.108.24:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4amdtIy0gkFcVddGZj0wAAAS0"]
[Mon Jul 20 06:54:49.472836 2026] [security2:error] [pid 15216:tid 15381] [client 117.247.108.24:52312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4amdtIy0gkFcVddGZj0wAAAS0"]
[Mon Jul 20 06:54:49.499175 2026] [security2:error] [pid 15216:tid 15444] [client 15.204.114.164:31382] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "omenana.com"] [uri "/"] [unique_id "al4amdtIy0gkFcVddGZj1AAAAWw"]
[Mon Jul 20 06:54:49.582718 2026] [security2:error] [pid 15216:tid 15401] [client 77.110.127.138:59345] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_hit. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4amdtIy0gkFcVddGZj3wAAAUE"]
[Mon Jul 20 06:54:49.588265 2026] [security2:error] [pid 15216:tid 15271] [remote 72.167.132.114:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4amdtIy0gkFcVddGZj3QABPjY"]
[Mon Jul 20 06:54:49.761600 2026] [security2:error] [pid 15216:tid 15353] [client 4.194.24.143:46640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/radio.php"] [unique_id "al4amdtIy0gkFcVddGZj8gAAARE"]
[Mon Jul 20 06:54:49.974209 2026] [security2:error] [pid 15216:tid 15286] [remote 72.167.132.114:42510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4amdtIy0gkFcVddGZkAwABREU"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:54:49.988102 2026] [security2:error] [pid 15216:tid 15428] [client 77.110.127.138:59396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4amdtIy0gkFcVddGZkBQAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:50.039972 2026] [security2:error] [pid 15216:tid 15446] [client 183.82.98.154:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4amttIy0gkFcVddGZkCAAAAW4"]
[Mon Jul 20 06:54:50.040102 2026] [security2:error] [pid 15216:tid 15446] [client 183.82.98.154:59781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4amttIy0gkFcVddGZkCAAAAW4"]
[Mon Jul 20 06:54:50.089043 2026] [security2:error] [pid 15216:tid 15382] [client 45.156.129.160:48340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4amdtIy0gkFcVddGZkAQAAAS4"]
[Mon Jul 20 06:54:50.335458 2026] [security2:error] [pid 15216:tid 15435] [client 4.194.24.143:6478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/randkeyword.php7"] [unique_id "al4amttIy0gkFcVddGZkGwAAAWM"]
[Mon Jul 20 06:54:50.480977 2026] [security2:error] [pid 15216:tid 15306] [remote 162.19.86.63:40414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4amttIy0gkFcVddGZkKAABEVk"]
[Mon Jul 20 06:54:50.481114 2026] [security2:error] [pid 15216:tid 15353] [client 162.19.86.63:40414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4amttIy0gkFcVddGZkKAABEVk"]
[Mon Jul 20 06:54:50.543563 2026] [security2:error] [pid 15216:tid 15301] [remote 20.153.140.50:43390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4amttIy0gkFcVddGZkLAABZVQ"]
[Mon Jul 20 06:54:50.618303 2026] [security2:error] [pid 15216:tid 15359] [client 77.110.127.138:59398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4amttIy0gkFcVddGZkMAAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:50.618444 2026] [security2:error] [pid 15216:tid 15359] [client 77.110.127.138:59398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4amttIy0gkFcVddGZkMAAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:50.664511 2026] [security2:error] [pid 15216:tid 15399] [client 14.225.17.146:50683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4amdtIy0gkFcVddGZjwQAAAT8"], referer: http://inspirespublishing.com/wp-old
[Mon Jul 20 06:54:50.905526 2026] [security2:error] [pid 15216:tid 15446] [client 4.194.24.143:7405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/readme.php"] [unique_id "al4amttIy0gkFcVddGZkSQAAAW4"]
[Mon Jul 20 06:54:51.022559 2026] [security2:error] [pid 15216:tid 15318] [remote 20.153.140.50:43390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4am9tIy0gkFcVddGZkUgABUWU"], referer: https://pscmedicalbilling.com/wp-login.php
[Mon Jul 20 06:54:51.402105 2026] [autoindex:error] [pid 15216:tid 15362] [client 185.193.167.42:13081] AH01276: Cannot serve directory /home3/soverex2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:54:51.446721 2026] [security2:error] [pid 15216:tid 15360] [client 4.194.24.143:60161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/reze.php"] [unique_id "al4am9tIy0gkFcVddGZkdQAAARg"]
[Mon Jul 20 06:54:51.478707 2026] [security2:error] [pid 15216:tid 15381] [client 57.141.18.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4am9tIy0gkFcVddGZkagAAAS0"]
[Mon Jul 20 06:54:51.825902 2026] [security2:error] [pid 15216:tid 15428] [client 152.58.191.29:50447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4am9tIy0gkFcVddGZkkgAAAVw"]
[Mon Jul 20 06:54:51.825994 2026] [security2:error] [pid 15216:tid 15428] [client 152.58.191.29:50447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4am9tIy0gkFcVddGZkkgAAAVw"]
[Mon Jul 20 06:54:51.852045 2026] [security2:error] [pid 15216:tid 15341] [remote 47.86.33.52:25218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4am9tIy0gkFcVddGZklAABcHw"]
[Mon Jul 20 06:54:52.004393 2026] [security2:error] [pid 15216:tid 15373] [client 4.194.24.143:50422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/rh.php"] [unique_id "al4anNtIy0gkFcVddGZkoQAAASU"]
[Mon Jul 20 06:54:52.051499 2026] [security2:error] [pid 15216:tid 15416] [client 217.142.18.172:34624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4anNtIy0gkFcVddGZkogAAAVA"]
[Mon Jul 20 06:54:52.056444 2026] [security2:error] [pid 15216:tid 15416] [client 217.142.18.172:34624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4anNtIy0gkFcVddGZkogAAAVA"]
[Mon Jul 20 06:54:52.154349 2026] [security2:error] [pid 15216:tid 15415] [client 122.183.32.225:29340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4anNtIy0gkFcVddGZkpQAAAU8"]
[Mon Jul 20 06:54:52.154545 2026] [security2:error] [pid 15216:tid 15415] [client 122.183.32.225:29340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4anNtIy0gkFcVddGZkpQAAAU8"]
[Mon Jul 20 06:54:52.381015 2026] [security2:error] [pid 15216:tid 15343] [remote 162.19.86.63:47855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4anNtIy0gkFcVddGZksgABQX4"]
[Mon Jul 20 06:54:52.381133 2026] [security2:error] [pid 15216:tid 15401] [client 162.19.86.63:47855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4anNtIy0gkFcVddGZksgABQX4"]
[Mon Jul 20 06:54:52.448409 2026] [proxy:error] [pid 15216:tid 15431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:54:52.448462 2026] [proxy_http:error] [pid 15216:tid 15431] [client 20.151.205.204:39946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:54:52.448888 2026] [proxy:error] [pid 15216:tid 15431] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:54:52.448923 2026] [proxy_http:error] [pid 15216:tid 15431] [client 20.151.205.204:39946] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:54:52.449004 2026] [security2:error] [pid 15216:tid 15431] [client 20.151.205.204:39946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4anNtIy0gkFcVddGZktwAAAV8"]
[Mon Jul 20 06:54:52.545937 2026] [security2:error] [pid 15216:tid 15393] [client 4.194.24.143:5867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/rip.php"] [unique_id "al4anNtIy0gkFcVddGZkvwAAATk"]
[Mon Jul 20 06:54:52.885032 2026] [security2:error] [pid 15216:tid 15382] [client 45.156.129.163:52096] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/iwp-client/readme.txt"] [unique_id "al4anNtIy0gkFcVddGZk3AAAAS4"]
[Mon Jul 20 06:54:53.113930 2026] [security2:error] [pid 15216:tid 15438] [client 4.194.24.143:6477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/root.php"] [unique_id "al4andtIy0gkFcVddGZk6QAAAWY"]
[Mon Jul 20 06:54:53.166596 2026] [security2:error] [pid 15216:tid 15371] [client 14.225.17.146:55293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4am9tIy0gkFcVddGZkhQAAASM"], referer: http://reosportsboats.com/wp-old
[Mon Jul 20 06:54:53.225890 2026] [security2:error] [pid 15216:tid 15247] [remote 97.74.87.194:46214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4andtIy0gkFcVddGZk7QABQB4"]
[Mon Jul 20 06:54:53.240815 2026] [security2:error] [pid 15216:tid 15240] [remote 47.86.33.52:25218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4andtIy0gkFcVddGZk7gABGRc"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 06:54:53.403738 2026] [security2:error] [pid 15216:tid 15455] [client 65.1.132.125:51974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4andtIy0gkFcVddGZk_gAAAXc"]
[Mon Jul 20 06:54:53.619809 2026] [security2:error] [pid 15216:tid 15263] [remote 97.74.87.194:46214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4andtIy0gkFcVddGZlGAABRi4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:53.656366 2026] [security2:error] [pid 15216:tid 15445] [client 4.194.24.143:60176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/s.php"] [unique_id "al4andtIy0gkFcVddGZlHAAAAW0"]
[Mon Jul 20 06:54:53.981447 2026] [security2:error] [pid 15216:tid 15464] [client 45.156.129.162:12362] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wordpress-database-reset/readme.txt"] [unique_id "al4andtIy0gkFcVddGZlLAAAAYA"]
[Mon Jul 20 06:54:54.115028 2026] [security2:error] [pid 15216:tid 15410] [client 77.110.127.138:59419] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4anttIy0gkFcVddGZlMgAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:54.172176 2026] [security2:error] [pid 15216:tid 15403] [client 103.238.106.162:63591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4anttIy0gkFcVddGZlOQAAAUM"]
[Mon Jul 20 06:54:54.172286 2026] [security2:error] [pid 15216:tid 15403] [client 103.238.106.162:63591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4anttIy0gkFcVddGZlOQAAAUM"]
[Mon Jul 20 06:54:54.215314 2026] [security2:error] [pid 15216:tid 15415] [client 4.194.24.143:2083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sang.php"] [unique_id "al4anttIy0gkFcVddGZlOgAAAU8"]
[Mon Jul 20 06:54:54.238030 2026] [security2:error] [pid 15216:tid 15443] [client 14.225.17.146:51049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4anttIy0gkFcVddGZlNAAAAWs"], referer: https://reosportsboats.com/wp-old
[Mon Jul 20 06:54:54.265872 2026] [security2:error] [pid 15216:tid 15470] [client 77.110.127.138:59422] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4anttIy0gkFcVddGZlPwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:54.405888 2026] [security2:error] [pid 15216:tid 15380] [client 13.233.207.33:45850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4anttIy0gkFcVddGZlUAAAASw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:54:54.678359 2026] [security2:error] [pid 15216:tid 15446] [client 20.151.205.204:32758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/footer.php"] [unique_id "al4anttIy0gkFcVddGZlXgAAAW4"]
[Mon Jul 20 06:54:54.678453 2026] [security2:error] [pid 15216:tid 15446] [client 20.151.205.204:32758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/footer.php"] [unique_id "al4anttIy0gkFcVddGZlXgAAAW4"]
[Mon Jul 20 06:54:54.788430 2026] [security2:error] [pid 15216:tid 15442] [client 4.194.24.143:50381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/scxy.php"] [unique_id "al4anttIy0gkFcVddGZlYQAAAWo"]
[Mon Jul 20 06:54:54.946770 2026] [security2:error] [pid 15216:tid 15473] [client 192.140.149.97:45445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4anttIy0gkFcVddGZlcAAAAYk"]
[Mon Jul 20 06:54:54.946877 2026] [security2:error] [pid 15216:tid 15473] [client 192.140.149.97:45445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4anttIy0gkFcVddGZlcAAAAYk"]
[Mon Jul 20 06:54:55.043393 2026] [security2:error] [pid 15216:tid 15364] [client 77.110.127.138:59427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4an9tIy0gkFcVddGZleQAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:55.043494 2026] [security2:error] [pid 15216:tid 15364] [client 77.110.127.138:59427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4an9tIy0gkFcVddGZleQAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:55.277463 2026] [security2:error] [pid 15216:tid 15371] [client 45.156.129.162:56522] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-video-lightbox/readme.txt"] [unique_id "al4an9tIy0gkFcVddGZliwAAASM"]
[Mon Jul 20 06:54:55.328850 2026] [security2:error] [pid 15216:tid 15377] [client 4.194.24.143:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sd.php"] [unique_id "al4an9tIy0gkFcVddGZljgAAASk"]
[Mon Jul 20 06:54:55.879162 2026] [security2:error] [pid 15216:tid 15354] [client 4.194.24.143:5838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sf.php"] [unique_id "al4an9tIy0gkFcVddGZltgAAARI"]
[Mon Jul 20 06:54:55.990996 2026] [security2:error] [pid 15216:tid 15328] [remote 49.12.216.176:35550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4an9tIy0gkFcVddGZlwAABVm8"]
[Mon Jul 20 06:54:56.135189 2026] [security2:error] [pid 15216:tid 15425] [client 104.234.53.67:64141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4aoNtIy0gkFcVddGZlywAAAVk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:54:56.181043 2026] [security2:error] [pid 15216:tid 15315] [remote 49.12.216.176:35550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4aoNtIy0gkFcVddGZlzAABNWI"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:54:56.236336 2026] [security2:error] [pid 15216:tid 15366] [client 45.156.129.160:52626] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/optinmonster/readme.txt"] [unique_id "al4aoNtIy0gkFcVddGZl1QAAAR4"]
[Mon Jul 20 06:54:56.339923 2026] [security2:error] [pid 15216:tid 15435] [client 14.225.17.146:53768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4aoNtIy0gkFcVddGZl0wAAAWM"], referer: http://cheesewithjam.com/wp-old
[Mon Jul 20 06:54:56.391582 2026] [security2:error] [pid 15216:tid 15396] [client 14.251.3.155:55861] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aoNtIy0gkFcVddGZl3gAAATw"]
[Mon Jul 20 06:54:56.418443 2026] [security2:error] [pid 15216:tid 15445] [client 4.194.24.143:2073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/shell.php"] [unique_id "al4aoNtIy0gkFcVddGZl4QAAAW0"]
[Mon Jul 20 06:54:56.836098 2026] [security2:error] [pid 15216:tid 15365] [client 66.249.74.134:56051] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "testingroomtv.com"] [uri "/robots.txt"] [unique_id "al4aoNtIy0gkFcVddGZmBwAAAR0"]
[Mon Jul 20 06:54:56.836327 2026] [security2:error] [pid 15216:tid 15405] [client 14.224.227.113:54781] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4aoNtIy0gkFcVddGZmCAAAAUU"]
[Mon Jul 20 06:54:56.852056 2026] [proxy:error] [pid 15216:tid 15446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:54:56.852127 2026] [proxy_http:error] [pid 15216:tid 15446] [client 20.151.205.204:55939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:54:56.852675 2026] [proxy:error] [pid 15216:tid 15446] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:54:56.852701 2026] [proxy_http:error] [pid 15216:tid 15446] [client 20.151.205.204:55939] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:54:56.852793 2026] [security2:error] [pid 15216:tid 15446] [client 20.151.205.204:55939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4aoNtIy0gkFcVddGZmCQAAAW4"]
[Mon Jul 20 06:54:57.028627 2026] [security2:error] [pid 15216:tid 15382] [client 57.141.18.103:22734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4anttIy0gkFcVddGZldQABLko"]
[Mon Jul 20 06:54:57.161846 2026] [security2:error] [pid 15216:tid 15367] [client 4.194.24.143:2761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sid3.php"] [unique_id "al4aodtIy0gkFcVddGZmJQAAAR8"]
[Mon Jul 20 06:54:57.192441 2026] [security2:error] [pid 15216:tid 15384] [client 45.156.129.163:60568] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/code-snippets/readme.txt"] [unique_id "al4aodtIy0gkFcVddGZmKgAAATA"]
[Mon Jul 20 06:54:57.215944 2026] [security2:error] [pid 15216:tid 15381] [client 187.108.85.186:52312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aodtIy0gkFcVddGZmLQAAAS0"]
[Mon Jul 20 06:54:57.216080 2026] [security2:error] [pid 15216:tid 15381] [client 187.108.85.186:52312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aodtIy0gkFcVddGZmLQAAAS0"]
[Mon Jul 20 06:54:57.375863 2026] [security2:error] [pid 15216:tid 15437] [client 41.141.20.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4aoNtIy0gkFcVddGZmAQAAAWU"]
[Mon Jul 20 06:54:57.744164 2026] [security2:error] [pid 15216:tid 15454] [client 4.194.24.143:2791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/simple.php"] [unique_id "al4aodtIy0gkFcVddGZmVwAAAXY"]
[Mon Jul 20 06:54:57.749619 2026] [security2:error] [pid 15216:tid 15351] [client 103.125.179.95:64967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aodtIy0gkFcVddGZmVQAAAQ8"]
[Mon Jul 20 06:54:57.749745 2026] [security2:error] [pid 15216:tid 15351] [client 103.125.179.95:64967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aodtIy0gkFcVddGZmVQAAAQ8"]
[Mon Jul 20 06:54:57.830308 2026] [security2:error] [pid 15216:tid 15394] [client 14.225.17.146:59647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4aodtIy0gkFcVddGZmVAAAATo"], referer: http://thefriendlyspreadsheet.com/wp-old
[Mon Jul 20 06:54:57.996626 2026] [security2:error] [pid 15216:tid 15431] [client 14.225.17.146:59676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4aoNtIy0gkFcVddGZl_AAAAV8"], referer: http://iagdevelopments.com/wp-old
[Mon Jul 20 06:54:58.114936 2026] [security2:error] [pid 15216:tid 15396] [client 50.116.65.227:47810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4aottIy0gkFcVddGZmcwAAATw"]
[Mon Jul 20 06:54:58.119339 2026] [security2:error] [pid 15216:tid 15388] [client 14.225.17.146:60751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4aodtIy0gkFcVddGZmZgAAATQ"]
[Mon Jul 20 06:54:58.150257 2026] [security2:error] [pid 15216:tid 15428] [client 34.162.230.222:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4aottIy0gkFcVddGZmaQAAAVw"]
[Mon Jul 20 06:54:58.308157 2026] [security2:error] [pid 15216:tid 15457] [client 4.194.24.143:2081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sitemap.php"] [unique_id "al4aottIy0gkFcVddGZmggAAAXk"]
[Mon Jul 20 06:54:58.395693 2026] [security2:error] [pid 15216:tid 15349] [client 45.156.129.161:55878] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-time-capsule/readme.txt"] [unique_id "al4aottIy0gkFcVddGZmjgAAAQ0"]
[Mon Jul 20 06:54:58.601497 2026] [security2:error] [pid 15216:tid 15450] [client 14.225.17.146:53700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4aodtIy0gkFcVddGZmJwAAAXI"], referer: http://samdothan.org/wp-old
[Mon Jul 20 06:54:58.603338 2026] [security2:error] [pid 15216:tid 15459] [client 20.151.205.204:15288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-content/index.php"] [unique_id "al4aottIy0gkFcVddGZmpgAAAXs"]
[Mon Jul 20 06:54:58.603444 2026] [security2:error] [pid 15216:tid 15459] [client 20.151.205.204:15288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/wp-content/index.php"] [unique_id "al4aottIy0gkFcVddGZmpgAAAXs"]
[Mon Jul 20 06:54:58.849195 2026] [security2:error] [pid 15216:tid 15401] [client 4.194.24.143:7561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/size.php"] [unique_id "al4aottIy0gkFcVddGZmwAAAAUE"]
[Mon Jul 20 06:54:58.919142 2026] [security2:error] [pid 15216:tid 15462] [client 14.225.17.146:64996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4aottIy0gkFcVddGZmuwAAAX4"], referer: https://iagdevelopments.com/wp-old
[Mon Jul 20 06:54:58.924550 2026] [security2:error] [pid 15216:tid 15272] [remote 100.42.189.89:38306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4aottIy0gkFcVddGZmwgABhDc"]
[Mon Jul 20 06:54:58.941694 2026] [security2:error] [pid 15216:tid 15361] [client 34.162.230.222:1025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4aottIy0gkFcVddGZmvwAAARk"]
[Mon Jul 20 06:54:59.025427 2026] [security2:error] [pid 15216:tid 15456] [client 57.141.18.87:33016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aoNtIy0gkFcVddGZmBAABeAs"]
[Mon Jul 20 06:54:59.036371 2026] [security2:error] [pid 15216:tid 15274] [remote 81.173.115.7:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZmxAABLTk"]
[Mon Jul 20 06:54:59.145216 2026] [security2:error] [pid 15216:tid 15238] [remote 100.42.189.89:38306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZm0AABFRU"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 06:54:59.228674 2026] [security2:error] [pid 15216:tid 15281] [remote 81.173.115.7:44086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZm1wABSUA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:54:59.232159 2026] [security2:error] [pid 15216:tid 15383] [client 158.173.89.95:37859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ao9tIy0gkFcVddGZm2AAAAS8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:54:59.368961 2026] [security2:error] [pid 15216:tid 15366] [client 173.252.82.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4ao9tIy0gkFcVddGZmzQAAAR4"]
[Mon Jul 20 06:54:59.408592 2026] [security2:error] [pid 15216:tid 15415] [client 4.194.24.143:2807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sm.php"] [unique_id "al4ao9tIy0gkFcVddGZm5QAAAU8"]
[Mon Jul 20 06:54:59.429240 2026] [security2:error] [pid 15216:tid 15385] [client 45.156.129.160:52638] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/kingcomposer/readme.txt"] [unique_id "al4ao9tIy0gkFcVddGZm5wAAATE"]
[Mon Jul 20 06:54:59.597888 2026] [security2:error] [pid 15216:tid 15293] [remote 84.247.172.23:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZm9wABF0w"]
[Mon Jul 20 06:54:59.654426 2026] [security2:error] [pid 15216:tid 15434] [client 117.222.139.248:59755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ao9tIy0gkFcVddGZnAQAAAWI"]
[Mon Jul 20 06:54:59.654562 2026] [security2:error] [pid 15216:tid 15434] [client 117.222.139.248:59755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ao9tIy0gkFcVddGZnAQAAAWI"]
[Mon Jul 20 06:54:59.683459 2026] [security2:error] [pid 15216:tid 15302] [remote 47.86.33.52:46914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZnBAABEFU"]
[Mon Jul 20 06:54:59.722015 2026] [security2:error] [pid 15216:tid 15433] [client 14.225.17.146:59792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4aottIy0gkFcVddGZmdwAAAWE"], referer: http://nurturemarple.co.uk/wp-old
[Mon Jul 20 06:54:59.784922 2026] [security2:error] [pid 15216:tid 15234] [remote 84.247.172.23:53972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZnDAABSRE"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 06:54:59.788921 2026] [security2:error] [pid 15216:tid 15381] [client 34.162.230.222:1344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ao9tIy0gkFcVddGZnAAAAAS0"]
[Mon Jul 20 06:54:59.859659 2026] [security2:error] [pid 15216:tid 15440] [client 77.110.127.138:59446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ao9tIy0gkFcVddGZnEQAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:59.859783 2026] [security2:error] [pid 15216:tid 15440] [client 77.110.127.138:59446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ao9tIy0gkFcVddGZnEQAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:54:59.919646 2026] [security2:error] [pid 15216:tid 15378] [client 98.159.234.160:41367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ao9tIy0gkFcVddGZnFAAAASo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:54:59.946187 2026] [security2:error] [pid 15216:tid 15455] [client 143.110.218.69:62407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techtradeinc.com"] [uri "/wp-login.php"] [unique_id "al4ao9tIy0gkFcVddGZnEwAAAXc"]
[Mon Jul 20 06:54:59.955764 2026] [security2:error] [pid 15216:tid 15445] [client 4.194.24.143:5849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sql.php"] [unique_id "al4ao9tIy0gkFcVddGZnGQAAAW0"]
[Mon Jul 20 06:55:00.200673 2026] [security2:error] [pid 15216:tid 15388] [client 50.116.65.227:17946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4ao9tIy0gkFcVddGZnEAAAATQ"]
[Mon Jul 20 06:55:00.203470 2026] [security2:error] [pid 15216:tid 15354] [client 117.247.108.24:13943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4apNtIy0gkFcVddGZnLwAAARI"]
[Mon Jul 20 06:55:00.203586 2026] [security2:error] [pid 15216:tid 15354] [client 117.247.108.24:13943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4apNtIy0gkFcVddGZnLwAAARI"]
[Mon Jul 20 06:55:00.238816 2026] [security2:error] [pid 15216:tid 15359] [client 143.110.218.69:62437] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "techtradeinc.com"] [uri "/wp-login.php"] [unique_id "al4apNtIy0gkFcVddGZnNAAAARc"]
[Mon Jul 20 06:55:00.239881 2026] [security2:error] [pid 15216:tid 15419] [client 14.225.17.146:58149] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4apNtIy0gkFcVddGZnHwAAAVM"], referer: http://mobilesurvsolutions.com/wp-old
[Mon Jul 20 06:55:00.266594 2026] [security2:error] [pid 15216:tid 15460] [client 20.151.205.204:39997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/zoro.php"] [unique_id "al4apNtIy0gkFcVddGZnNQAAAXw"]
[Mon Jul 20 06:55:00.266687 2026] [security2:error] [pid 15216:tid 15460] [client 20.151.205.204:39997] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/zoro.php"] [unique_id "al4apNtIy0gkFcVddGZnNQAAAXw"]
[Mon Jul 20 06:55:00.302052 2026] [security2:error] [pid 15216:tid 15322] [remote 47.86.33.52:46914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4apNtIy0gkFcVddGZnNwABKmk"], referer: https://mail.indiraskitchenllc.com/wp-login.php
[Mon Jul 20 06:55:00.317030 2026] [security2:error] [pid 15216:tid 15410] [client 45.156.129.162:56538] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/elementor/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnOwAAAUo"]
[Mon Jul 20 06:55:00.321063 2026] [security2:error] [pid 15216:tid 15357] [client 45.156.129.162:56548] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wordfence/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnPAAAARU"]
[Mon Jul 20 06:55:00.330176 2026] [security2:error] [pid 15216:tid 15375] [client 45.156.129.162:56560] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/all-in-one-seo-pack/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnPgAAASc"]
[Mon Jul 20 06:55:00.333531 2026] [security2:error] [pid 15216:tid 15408] [client 45.156.129.161:55896] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wpforms-lite/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnQAAAAUg"]
[Mon Jul 20 06:55:00.343108 2026] [security2:error] [pid 15216:tid 15422] [client 45.156.129.162:56564] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/google-analytics-for-wordpress/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnQQAAAVY"]
[Mon Jul 20 06:55:00.353198 2026] [security2:error] [pid 15216:tid 15381] [client 45.156.129.163:60576] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnQwAAAS0"]
[Mon Jul 20 06:55:00.353202 2026] [security2:error] [pid 15216:tid 15411] [client 45.156.129.162:56578] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/redirection/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnQgAAAUs"]
[Mon Jul 20 06:55:00.353374 2026] [security2:error] [pid 15216:tid 15394] [client 45.156.129.160:52672] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/woocommerce/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnRAAAATo"]
[Mon Jul 20 06:55:00.354002 2026] [security2:error] [pid 15216:tid 15383] [client 45.156.129.160:52686] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/duplicate-page/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnRQAAAS8"]
[Mon Jul 20 06:55:00.354056 2026] [security2:error] [pid 15216:tid 15425] [client 45.156.129.160:52658] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/really-simple-ssl/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnRgAAAVk"]
[Mon Jul 20 06:55:00.354537 2026] [security2:error] [pid 15216:tid 15471] [client 45.156.129.162:56566] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/contact-form-7/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnRwAAAYc"]
[Mon Jul 20 06:55:00.354538 2026] [security2:error] [pid 15216:tid 15434] [client 45.156.129.163:60574] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/limit-login-attempts-reloaded/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnSAAAAWI"]
[Mon Jul 20 06:55:00.354798 2026] [security2:error] [pid 15216:tid 15372] [client 45.156.129.160:52644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/advanced-custom-fields/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnSQAAASQ"]
[Mon Jul 20 06:55:00.358718 2026] [security2:error] [pid 15216:tid 15439] [client 45.156.129.160:52642] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/google-site-kit/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnSgAAAWc"]
[Mon Jul 20 06:55:00.358814 2026] [security2:error] [pid 15216:tid 15386] [client 45.156.129.161:55894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/litespeed-cache/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnSwAAATI"]
[Mon Jul 20 06:55:00.374442 2026] [security2:error] [pid 15216:tid 15428] [client 104.234.53.64:37891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4apNtIy0gkFcVddGZnTQAAAVw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:00.380685 2026] [security2:error] [pid 15216:tid 15435] [client 45.156.129.161:55908] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/insert-headers-and-footers/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnTgAAAWM"]
[Mon Jul 20 06:55:00.382632 2026] [security2:error] [pid 15216:tid 15450] [client 45.156.129.161:55940] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/smart-slider-3/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnTwAAAXI"]
[Mon Jul 20 06:55:00.384341 2026] [http2:info] [pid 16093:tid 16093] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:55:00.393539 2026] [security2:error] [pid 15216:tid 15351] [client 45.156.129.162:56610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/updraftplus/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnUAAAAQ8"]
[Mon Jul 20 06:55:00.393697 2026] [security2:error] [pid 15216:tid 15470] [client 45.156.129.163:60608] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/hostinger/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnUQAAAYY"]
[Mon Jul 20 06:55:00.394052 2026] [security2:error] [pid 15216:tid 15468] [client 45.156.129.162:56600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/autoptimize/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnUwAAAYQ"]
[Mon Jul 20 06:55:00.399119 2026] [security2:error] [pid 15216:tid 15358] [client 50.116.65.227:17960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4apNtIy0gkFcVddGZnMQAAARY"]
[Mon Jul 20 06:55:00.408030 2026] [security2:error] [pid 15216:tid 15427] [client 45.156.129.163:60586] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-super-cache/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnVQAAAVs"]
[Mon Jul 20 06:55:00.408219 2026] [security2:error] [pid 15216:tid 15459] [client 45.156.129.160:52724] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wps-hide-login/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnWAAAAXs"]
[Mon Jul 20 06:55:00.408243 2026] [security2:error] [pid 15216:tid 15393] [client 45.156.129.162:56592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/better-search-replace/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnVwAAATk"]
[Mon Jul 20 06:55:00.408322 2026] [security2:error] [pid 15216:tid 15380] [client 45.156.129.160:52714] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/disable-comments/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnWgAAASw"]
[Mon Jul 20 06:55:00.408324 2026] [security2:error] [pid 15216:tid 15449] [client 45.156.129.161:55914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-file-manager/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnWQAAAXE"]
[Mon Jul 20 06:55:00.408570 2026] [security2:error] [pid 15216:tid 15403] [client 45.156.129.160:52698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/seo-by-rank-math/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnWwAAAUM"]
[Mon Jul 20 06:55:00.409700 2026] [security2:error] [pid 15216:tid 15440] [client 45.156.129.163:60592] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/duplicate-post/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnXAAAAWg"]
[Mon Jul 20 06:55:00.410863 2026] [security2:error] [pid 15216:tid 15365] [client 45.156.129.161:55924] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/loginizer/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnXQAAAR0"]
[Mon Jul 20 06:55:00.420859 2026] [security2:error] [pid 15216:tid 15420] [client 45.156.129.163:60610] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/akismet/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnXgAAAVQ"]
[Mon Jul 20 06:55:00.420860 2026] [security2:error] [pid 15216:tid 15443] [client 45.156.129.161:55944] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/essential-addons-for-elementor-lite/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnXwAAAWs"]
[Mon Jul 20 06:55:00.421212 2026] [security2:error] [pid 15216:tid 15414] [client 45.156.129.163:60616] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/all-in-one-wp-security-and-firewall/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnYAAAAU4"]
[Mon Jul 20 06:55:00.421655 2026] [security2:error] [pid 15216:tid 15429] [client 45.156.129.160:52728] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/coming-soon/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnYQAAAV0"]
[Mon Jul 20 06:55:00.432199 2026] [security2:error] [pid 15216:tid 15469] [client 45.156.129.160:52732] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/all-in-one-wp-migration/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnYgAAAYU"]
[Mon Jul 20 06:55:00.435854 2026] [security2:error] [pid 15216:tid 15445] [client 45.156.129.162:56620] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/header-footer-elementor/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnYwAAAW0"]
[Mon Jul 20 06:55:00.436464 2026] [security2:error] [pid 15216:tid 15415] [client 45.156.129.163:60634] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/duplicator/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnZAAAAU8"]
[Mon Jul 20 06:55:00.445892 2026] [security2:error] [pid 15216:tid 15350] [client 45.156.129.162:56614] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/envato-elements/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnZwAAAQ4"]
[Mon Jul 20 06:55:00.445895 2026] [security2:error] [pid 15216:tid 15379] [client 45.156.129.162:56646] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/ultimate-addons-for-gutenberg/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnZgAAASs"]
[Mon Jul 20 06:55:00.445899 2026] [security2:error] [pid 15216:tid 15385] [client 45.156.129.163:60648] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/complianz-gdpr/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnaAAAATE"]
[Mon Jul 20 06:55:00.446185 2026] [security2:error] [pid 15216:tid 15413] [client 45.156.129.160:52750] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/astra-sites/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnaQAAAU0"]
[Mon Jul 20 06:55:00.446309 2026] [security2:error] [pid 15216:tid 15371] [client 45.156.129.163:60624] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/better-wp-security/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnagAAASM"]
[Mon Jul 20 06:55:00.446425 2026] [security2:error] [pid 15216:tid 15473] [client 45.156.129.161:55958] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/redux-framework/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnawAAAYk"]
[Mon Jul 20 06:55:00.449177 2026] [security2:error] [pid 15216:tid 15390] [client 45.156.129.162:56636] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/svg-support/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnbAAAATY"]
[Mon Jul 20 06:55:00.449553 2026] [security2:error] [pid 15216:tid 15454] [client 45.156.129.163:60644] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-fastest-cache/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnbQAAAXY"]
[Mon Jul 20 06:55:00.449960 2026] [security2:error] [pid 15216:tid 15356] [client 45.156.129.163:60620] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/mailchimp-for-wp/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZnbgAAARQ"]
[Mon Jul 20 06:55:00.460315 2026] [security2:error] [pid 15216:tid 15355] [client 45.156.129.160:52754] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/ewww-image-optimizer/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZncAAAARM"]
[Mon Jul 20 06:55:00.460621 2026] [security2:error] [pid 15216:tid 15418] [client 45.156.129.160:52738] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wordpress-seo/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZncQAAAVI"]
[Mon Jul 20 06:55:00.494492 2026] [security2:error] [pid 15216:tid 15417] [client 45.156.129.161:55966] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-optimize/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZndAAAAVE"]
[Mon Jul 20 06:55:00.515737 2026] [security2:error] [pid 15216:tid 15442] [client 45.156.129.162:56656] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/w3-total-cache/readme.txt"] [unique_id "al4apNtIy0gkFcVddGZndQAAAWo"]
[Mon Jul 20 06:55:00.520302 2026] [security2:error] [pid 15216:tid 15456] [client 4.194.24.143:2780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/ss.php"] [unique_id "al4apNtIy0gkFcVddGZndgAAAXg"]
[Mon Jul 20 06:55:00.545132 2026] [security2:error] [pid 16093:tid 16224] [client 45.156.129.162:56668] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/sg-security/readme.txt"] [unique_id "al4apJuybMv3z_zMVBSclAAAAY8"]
[Mon Jul 20 06:55:00.737651 2026] [security2:error] [pid 15216:tid 15367] [client 14.225.17.146:50148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4apNtIy0gkFcVddGZnfAAAAR8"], referer: https://nurturemarple.co.uk/wp-old
[Mon Jul 20 06:55:00.869090 2026] [security2:error] [pid 16093:tid 16232] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4apJuybMv3z_zMVBScmQAAAZc"]
[Mon Jul 20 06:55:00.897128 2026] [security2:error] [pid 15216:tid 15400] [client 14.225.17.146:59554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4ao9tIy0gkFcVddGZm7QAAAUA"], referer: http://phillipbloch.com/wp-old
[Mon Jul 20 06:55:01.083743 2026] [security2:error] [pid 15216:tid 15388] [client 4.194.24.143:5847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/stats.php"] [unique_id "al4apdtIy0gkFcVddGZnlgAAATQ"]
[Mon Jul 20 06:55:01.381581 2026] [security2:error] [pid 15216:tid 15453] [client 57.141.18.44:30600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ao9tIy0gkFcVddGZm2QABdVE"]
[Mon Jul 20 06:55:01.424342 2026] [security2:error] [pid 15216:tid 15396] [client 183.82.98.154:60379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4apdtIy0gkFcVddGZnpwAAATw"]
[Mon Jul 20 06:55:01.424453 2026] [security2:error] [pid 15216:tid 15396] [client 183.82.98.154:60379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4apdtIy0gkFcVddGZnpwAAATw"]
[Mon Jul 20 06:55:01.612541 2026] [security2:error] [pid 15216:tid 15389] [client 45.157.112.60:34715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4apdtIy0gkFcVddGZnrAAAATU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:55:01.624189 2026] [security2:error] [pid 16093:tid 16281] [client 4.194.24.143:5875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/sump1.php"] [unique_id "al4apZuybMv3z_zMVBScuQAAAcg"]
[Mon Jul 20 06:55:01.673543 2026] [security2:error] [pid 15216:tid 15236] [remote 154.0.166.254:43112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4apdtIy0gkFcVddGZnrgABMxM"]
[Mon Jul 20 06:55:01.793736 2026] [security2:error] [pid 15216:tid 15407] [client 77.110.127.138:59450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4apdtIy0gkFcVddGZntgAAAUc"]
[Mon Jul 20 06:55:01.809908 2026] [security2:error] [pid 15216:tid 15390] [client 45.156.129.162:56670] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-central/readme.txt"] [unique_id "al4apdtIy0gkFcVddGZnuAAAATY"]
[Mon Jul 20 06:55:01.958389 2026] [security2:error] [pid 16093:tid 16280] [client 14.225.17.146:59531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4apZuybMv3z_zMVBScugAAAcc"], referer: http://floorsourcestock.com/wp-old
[Mon Jul 20 06:55:01.965442 2026] [security2:error] [pid 15216:tid 15229] [remote 20.153.140.50:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4apdtIy0gkFcVddGZnwAABbgw"]
[Mon Jul 20 06:55:02.171852 2026] [security2:error] [pid 15216:tid 15245] [remote 154.0.166.254:43112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4apttIy0gkFcVddGZnxgABEhw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:55:02.187273 2026] [security2:error] [pid 16093:tid 16328] [client 4.194.24.143:60179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/system.php"] [unique_id "al4appuybMv3z_zMVBScywAAAfc"]
[Mon Jul 20 06:55:02.203377 2026] [autoindex:error] [pid 15216:tid 15368] [client 34.53.117.107:56881] AH01276: Cannot serve directory /home2/dkhjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:55:02.325081 2026] [security2:error] [pid 16093:tid 16297] [client 122.183.32.225:30352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4appuybMv3z_zMVBSczgAAAdg"]
[Mon Jul 20 06:55:02.325261 2026] [security2:error] [pid 16093:tid 16297] [client 122.183.32.225:30352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4appuybMv3z_zMVBSczgAAAdg"]
[Mon Jul 20 06:55:02.359009 2026] [security2:error] [pid 15216:tid 15240] [remote 20.153.140.50:40856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4apttIy0gkFcVddGZn2gABeBc"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:55:02.573273 2026] [security2:error] [pid 16093:tid 16325] [client 152.58.191.29:50886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4appuybMv3z_zMVBSc1QAAAfQ"]
[Mon Jul 20 06:55:02.577867 2026] [security2:error] [pid 16093:tid 16325] [client 152.58.191.29:50886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4appuybMv3z_zMVBSc1QAAAfQ"]
[Mon Jul 20 06:55:02.645375 2026] [security2:error] [pid 15216:tid 15421] [client 217.142.18.172:3323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4apttIy0gkFcVddGZn6AAAAVU"]
[Mon Jul 20 06:55:02.645475 2026] [security2:error] [pid 15216:tid 15421] [client 217.142.18.172:3323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4apttIy0gkFcVddGZn6AAAAVU"]
[Mon Jul 20 06:55:02.780145 2026] [security2:error] [pid 16093:tid 16235] [client 4.194.24.143:60221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4appuybMv3z_zMVBSc4gAAAZo"]
[Mon Jul 20 06:55:02.944822 2026] [core:error] [pid 16093:tid 16274] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:55:02.944844 2026] [core:error] [pid 16093:tid 16274] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:55:02.992575 2026] [security2:error] [pid 15216:tid 15371] [client 13.233.207.33:40252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4apttIy0gkFcVddGZn-wAAASM"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:55:03.211209 2026] [security2:error] [pid 16093:tid 16109] [remote 217.61.143.92:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ap5uybMv3z_zMVBSc9AABxA4"]
[Mon Jul 20 06:55:03.321089 2026] [security2:error] [pid 16093:tid 16281] [client 4.194.24.143:60190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4ap5uybMv3z_zMVBSc-gAAAcg"]
[Mon Jul 20 06:55:03.393942 2026] [security2:error] [pid 16093:tid 16314] [client 20.230.108.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4ap5uybMv3z_zMVBSc_AAAAek"]
[Mon Jul 20 06:55:03.463011 2026] [security2:error] [pid 15216:tid 15377] [client 20.230.108.230:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4ap9tIy0gkFcVddGZoDwAAASk"]
[Mon Jul 20 06:55:03.474598 2026] [security2:error] [pid 16093:tid 16110] [remote 217.61.143.92:47580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ap5uybMv3z_zMVBSdAwAB-A8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:55:03.622053 2026] [security2:error] [pid 15216:tid 15366] [client 57.141.18.11:49630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4apdtIy0gkFcVddGZnvAABHgA"]
[Mon Jul 20 06:55:03.630940 2026] [security2:error] [pid 16093:tid 16111] [remote 8.217.108.67:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ap5uybMv3z_zMVBSdBQAB0RA"]
[Mon Jul 20 06:55:03.702167 2026] [security2:error] [pid 16093:tid 16282] [client 14.225.17.146:59532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4apZuybMv3z_zMVBScvAAAAck"], referer: http://dollpassionista.com/wp-old
[Mon Jul 20 06:55:03.850958 2026] [security2:error] [pid 16093:tid 16114] [remote 173.212.252.15:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ap5uybMv3z_zMVBSdEwAB3BM"]
[Mon Jul 20 06:55:03.851206 2026] [security2:error] [pid 16093:tid 16301] [client 173.212.252.15:52566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ap5uybMv3z_zMVBSdEwAB3BM"]
[Mon Jul 20 06:55:03.870337 2026] [security2:error] [pid 16093:tid 16297] [client 4.194.24.143:2102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/system_log.php"] [unique_id "al4ap5uybMv3z_zMVBSdFwAAAdg"]
[Mon Jul 20 06:55:03.900616 2026] [security2:error] [pid 15216:tid 15363] [client 197.186.66.42:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ap9tIy0gkFcVddGZoIAAAARs"]
[Mon Jul 20 06:55:03.900726 2026] [security2:error] [pid 15216:tid 15363] [client 197.186.66.42:55075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ap9tIy0gkFcVddGZoIAAAARs"]
[Mon Jul 20 06:55:04.142647 2026] [security2:error] [pid 16093:tid 16232] [client 50.116.65.227:17990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4aqJuybMv3z_zMVBSdIgAAAZc"]
[Mon Jul 20 06:55:04.153014 2026] [security2:error] [pid 16093:tid 16272] [client 50.116.65.227:18002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4aqJuybMv3z_zMVBSdIwAAAb8"]
[Mon Jul 20 06:55:04.221600 2026] [security2:error] [pid 16093:tid 16269] [client 45.156.129.163:34384] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/fancy-product-designer/readme.txt"] [unique_id "al4aqJuybMv3z_zMVBSdJAAAAbw"]
[Mon Jul 20 06:55:04.413507 2026] [security2:error] [pid 16093:tid 16273] [client 4.194.24.143:2101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/t.php"] [unique_id "al4aqJuybMv3z_zMVBSdKAAAAcA"]
[Mon Jul 20 06:55:04.457194 2026] [security2:error] [pid 15216:tid 15367] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aqNtIy0gkFcVddGZoMAAAAR8"]
[Mon Jul 20 06:55:04.661828 2026] [security2:error] [pid 16093:tid 16306] [client 20.151.205.204:20603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/admin.php"] [unique_id "al4aqJuybMv3z_zMVBSdLwAAAeE"]
[Mon Jul 20 06:55:04.661972 2026] [security2:error] [pid 16093:tid 16306] [client 20.151.205.204:20603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/admin.php"] [unique_id "al4aqJuybMv3z_zMVBSdLwAAAeE"]
[Mon Jul 20 06:55:04.685871 2026] [security2:error] [pid 16093:tid 16275] [client 14.225.17.146:56668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4aqJuybMv3z_zMVBSdKgAAAcI"], referer: https://dollpassionista.com/wp-old
[Mon Jul 20 06:55:04.706505 2026] [security2:error] [pid 16093:tid 16274] [client 103.238.106.162:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aqJuybMv3z_zMVBSdMAAAAcE"]
[Mon Jul 20 06:55:04.706647 2026] [security2:error] [pid 16093:tid 16274] [client 103.238.106.162:60801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4aqJuybMv3z_zMVBSdMAAAAcE"]
[Mon Jul 20 06:55:04.733238 2026] [security2:error] [pid 16093:tid 16270] [client 14.225.17.146:56820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4ap5uybMv3z_zMVBSc8wAAAb0"], referer: http://amalia-capital.com/wp-old
[Mon Jul 20 06:55:04.780795 2026] [security2:error] [pid 16093:tid 16118] [remote 8.217.108.67:48936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4aqJuybMv3z_zMVBSdMQAB5Bc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:55:04.846263 2026] [core:error] [pid 16093:tid 16318] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:55:04.846292 2026] [core:error] [pid 16093:tid 16318] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:55:04.953858 2026] [security2:error] [pid 16093:tid 16310] [client 4.194.24.143:54666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/term.php"] [unique_id "al4aqJuybMv3z_zMVBSdOAAAAeU"]
[Mon Jul 20 06:55:05.059191 2026] [security2:error] [pid 16093:tid 16248] [client 77.110.127.138:59461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aqZuybMv3z_zMVBSdOQAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:05.059352 2026] [security2:error] [pid 16093:tid 16248] [client 77.110.127.138:59461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aqZuybMv3z_zMVBSdOQAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:05.232262 2026] [security2:error] [pid 16093:tid 16304] [client 192.140.149.97:45689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aqZuybMv3z_zMVBSdQwAAAd8"]
[Mon Jul 20 06:55:05.232395 2026] [security2:error] [pid 16093:tid 16304] [client 192.140.149.97:45689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4aqZuybMv3z_zMVBSdQwAAAd8"]
[Mon Jul 20 06:55:05.485015 2026] [security2:error] [pid 16093:tid 16346] [client 45.156.129.160:23540] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wpschoolpress/readme.txt"] [unique_id "al4aqZuybMv3z_zMVBSdVQAAAgk"]
[Mon Jul 20 06:55:05.515378 2026] [security2:error] [pid 16093:tid 16260] [client 114.119.166.63:55597] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.hedgerow-crafts.com"] [uri "/2015/05/"] [unique_id "al4aqZuybMv3z_zMVBSdVwAAAbM"], referer: http://www.hedgerow-crafts.com/shop/
[Mon Jul 20 06:55:05.519362 2026] [security2:error] [pid 16093:tid 16292] [client 14.225.17.146:58410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4ap5uybMv3z_zMVBSc_wAAAdM"], referer: http://latiendadejorge.com.gt/wp-old
[Mon Jul 20 06:55:05.528067 2026] [security2:error] [pid 15216:tid 15411] [client 4.194.24.143:5874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/test.php"] [unique_id "al4aqdtIy0gkFcVddGZoagAAAUs"]
[Mon Jul 20 06:55:06.062650 2026] [security2:error] [pid 15216:tid 15410] [client 57.141.18.67:32410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aqNtIy0gkFcVddGZoKwABSkM"]
[Mon Jul 20 06:55:06.069956 2026] [security2:error] [pid 16093:tid 16270] [client 4.194.24.143:7568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/test1.php"] [unique_id "al4aqpuybMv3z_zMVBSdaAAAAb0"]
[Mon Jul 20 06:55:06.216784 2026] [security2:error] [pid 15216:tid 15354] [client 14.225.17.146:58857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4aqttIy0gkFcVddGZofQAAARI"], referer: http://mtlegnews.gov/wp-old
[Mon Jul 20 06:55:06.413706 2026] [security2:error] [pid 16093:tid 16310] [client 45.156.129.161:14012] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/bbpress/readme.txt"] [unique_id "al4aqpuybMv3z_zMVBSdcAAAAeU"]
[Mon Jul 20 06:55:06.609556 2026] [security2:error] [pid 15216:tid 15399] [client 4.194.24.143:2096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/tfm.php"] [unique_id "al4aqttIy0gkFcVddGZokwAAAT8"]
[Mon Jul 20 06:55:06.678466 2026] [security2:error] [pid 15216:tid 15460] [client 14.225.17.146:58387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4aqttIy0gkFcVddGZomAAAAXw"], referer: http://adultdaycarereno.com/wp-old
[Mon Jul 20 06:55:06.966799 2026] [security2:error] [pid 16093:tid 16247] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dadanetnet.net"] [uri "/index.php"] [unique_id "al4aqZuybMv3z_zMVBSdUwAAAaY"]
[Mon Jul 20 06:55:07.045874 2026] [security2:error] [pid 16093:tid 16325] [client 20.151.205.204:45536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/greap.php"] [unique_id "al4aq5uybMv3z_zMVBSdigAAAfQ"]
[Mon Jul 20 06:55:07.045971 2026] [security2:error] [pid 16093:tid 16325] [client 20.151.205.204:45536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/greap.php"] [unique_id "al4aq5uybMv3z_zMVBSdigAAAfQ"]
[Mon Jul 20 06:55:07.127879 2026] [security2:error] [pid 16093:tid 16281] [client 104.234.53.58:45059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4aq5uybMv3z_zMVBSdiAAAAcg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:07.150438 2026] [security2:error] [pid 16093:tid 16251] [client 4.194.24.143:15518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/thebe.php"] [unique_id "al4aq5uybMv3z_zMVBSdkQAAAao"]
[Mon Jul 20 06:55:07.526054 2026] [security2:error] [pid 15216:tid 15390] [client 45.3.54.175:12207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aq9tIy0gkFcVddGZosgAAATY"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:07.527273 2026] [security2:error] [pid 15216:tid 15436] [client 45.156.129.161:14026] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatchFromFile sitelock.txt" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "398"] [id "900247"] [msg "Wordpress Plugin README.txt file access attempt"] [hostname "gertoger.org"] [uri "/wp-content/plugins/wp-user-avatar/readme.txt"] [unique_id "al4aq9tIy0gkFcVddGZoswAAAWQ"]
[Mon Jul 20 06:55:07.550710 2026] [security2:error] [pid 16093:tid 16137] [remote 217.182.128.41:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4aq5uybMv3z_zMVBSdogAByio"]
[Mon Jul 20 06:55:07.598000 2026] [security2:error] [pid 16093:tid 16309] [client 14.225.17.146:58977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4aq5uybMv3z_zMVBSdowAAAeQ"], referer: https://adultdaycarereno.com/wp-old
[Mon Jul 20 06:55:07.632804 2026] [security2:error] [pid 16093:tid 16271] [client 14.225.17.146:57030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4aq5uybMv3z_zMVBSdjwAAAb4"]
[Mon Jul 20 06:55:07.711918 2026] [security2:error] [pid 15216:tid 15450] [client 4.194.24.143:2109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/themes.php"] [unique_id "al4aq9tIy0gkFcVddGZougAAAXI"]
[Mon Jul 20 06:55:07.744932 2026] [security2:error] [pid 16093:tid 16138] [remote 217.182.128.41:45362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4aq5uybMv3z_zMVBSdpgAB6Cs"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 06:55:07.817206 2026] [security2:error] [pid 15216:tid 15393] [client 14.225.17.146:50460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4aqttIy0gkFcVddGZofgAAATk"], referer: http://tacticaltreeoperations.com/wp-old
[Mon Jul 20 06:55:07.874711 2026] [security2:error] [pid 16093:tid 16140] [remote 95.217.78.234:39608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aq5uybMv3z_zMVBSdrAAB7C0"]
[Mon Jul 20 06:55:07.935745 2026] [security2:error] [pid 16093:tid 16348] [client 187.108.85.186:52853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aq5uybMv3z_zMVBSdrgAAAgs"]
[Mon Jul 20 06:55:07.935919 2026] [security2:error] [pid 16093:tid 16348] [client 187.108.85.186:52853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4aq5uybMv3z_zMVBSdrgAAAgs"]
[Mon Jul 20 06:55:07.996268 2026] [security2:error] [pid 16093:tid 16314] [client 57.141.18.39:36483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4aqZuybMv3z_zMVBSdZwAB6SA"]
[Mon Jul 20 06:55:08.086498 2026] [security2:error] [pid 15216:tid 15388] [client 104.207.53.229:65309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4arNtIy0gkFcVddGZoyQAAATQ"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:08.093134 2026] [security2:error] [pid 16093:tid 16290] [client 40.77.167.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4aq5uybMv3z_zMVBSdrQAAAdE"]
[Mon Jul 20 06:55:08.259922 2026] [security2:error] [pid 16093:tid 16143] [remote 95.217.78.234:39608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4arJuybMv3z_zMVBSdwQABrzA"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:55:08.305309 2026] [security2:error] [pid 16093:tid 16297] [client 4.194.24.143:5879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/tiny.php"] [unique_id "al4arJuybMv3z_zMVBSdwwAAAdg"]
[Mon Jul 20 06:55:08.358690 2026] [security2:error] [pid 15216:tid 15403] [client 14.225.17.146:58717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4aqttIy0gkFcVddGZomgAAAUM"], referer: http://nomorewetsheets.net/wp-old
[Mon Jul 20 06:55:08.484081 2026] [security2:error] [pid 16093:tid 16350] [client 103.125.179.95:65483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4arJuybMv3z_zMVBSdygAAAg0"]
[Mon Jul 20 06:55:08.484235 2026] [security2:error] [pid 16093:tid 16350] [client 103.125.179.95:65483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4arJuybMv3z_zMVBSdygAAAg0"]
[Mon Jul 20 06:55:08.698760 2026] [security2:error] [pid 16093:tid 16306] [client 65.111.22.58:18491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4arJuybMv3z_zMVBSdzwAAAeE"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:08.727728 2026] [security2:error] [pid 15216:tid 15363] [client 114.119.150.209:44313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "massagelacey.com"] [uri "/whole-body-massage-near-me-warwick-massage-lacey"] [unique_id "al4arNtIy0gkFcVddGZo4AAAARs"], referer: https://massagelacey.com/blog/page/2
[Mon Jul 20 06:55:08.781522 2026] [security2:error] [pid 16093:tid 16275] [client 45.156.129.161:14040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4arJuybMv3z_zMVBSdywAAAcI"]
[Mon Jul 20 06:55:08.845890 2026] [security2:error] [pid 16093:tid 16285] [client 4.194.24.143:15531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "elementalkneads.com"] [uri "/tmp/byp.php"] [unique_id "al4arJuybMv3z_zMVBSd3gAAAcw"]
[Mon Jul 20 06:55:08.886091 2026] [security2:error] [pid 16093:tid 16336] [client 104.234.53.58:45059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4arJuybMv3z_zMVBSd4AAAAf8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:09.257099 2026] [security2:error] [pid 16093:tid 16347] [client 45.3.42.46:59885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4arZuybMv3z_zMVBSd7QAAAgo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:09.379785 2026] [security2:error] [pid 16093:tid 16338] [client 14.225.17.146:58113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4arZuybMv3z_zMVBSd6gAAAgE"], referer: http://bigwormfishing.com/wp-old
[Mon Jul 20 06:55:09.398721 2026] [security2:error] [pid 15216:tid 15457] [client 20.151.205.204:64841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/177.php"] [unique_id "al4ardtIy0gkFcVddGZo9wAAAXk"]
[Mon Jul 20 06:55:09.398835 2026] [security2:error] [pid 15216:tid 15457] [client 20.151.205.204:64841] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/177.php"] [unique_id "al4ardtIy0gkFcVddGZo9wAAAXk"]
[Mon Jul 20 06:55:09.790952 2026] [security2:error] [pid 16093:tid 16239] [client 77.110.127.138:59485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4arZuybMv3z_zMVBSeBQAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:09.791074 2026] [security2:error] [pid 16093:tid 16239] [client 77.110.127.138:59485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4arZuybMv3z_zMVBSeBQAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:10.019761 2026] [security2:error] [pid 16093:tid 16286] [client 45.156.129.162:59032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4arZuybMv3z_zMVBSeBwAAAc0"]
[Mon Jul 20 06:55:10.111540 2026] [security2:error] [pid 16093:tid 16312] [client 20.151.205.204:39984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/199.php"] [unique_id "al4arpuybMv3z_zMVBSeEQAAAec"]
[Mon Jul 20 06:55:10.111647 2026] [security2:error] [pid 16093:tid 16312] [client 20.151.205.204:39984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/199.php"] [unique_id "al4arpuybMv3z_zMVBSeEQAAAec"]
[Mon Jul 20 06:55:10.210137 2026] [security2:error] [pid 15216:tid 15440] [client 117.222.139.248:60232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4arttIy0gkFcVddGZpFQAAAWg"]
[Mon Jul 20 06:55:10.210244 2026] [security2:error] [pid 15216:tid 15440] [client 117.222.139.248:60232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4arttIy0gkFcVddGZpFQAAAWg"]
[Mon Jul 20 06:55:10.276583 2026] [security2:error] [pid 16093:tid 16325] [client 13.232.231.177:10972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4arZuybMv3z_zMVBSd_gAAAfQ"]
[Mon Jul 20 06:55:10.380425 2026] [security2:error] [pid 16093:tid 16152] [remote 20.173.88.122:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4arpuybMv3z_zMVBSeGAAB_Tk"]
[Mon Jul 20 06:55:10.397975 2026] [security2:error] [pid 16093:tid 16280] [client 57.141.18.8:21422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4arJuybMv3z_zMVBSd2QABxzM"]
[Mon Jul 20 06:55:10.578109 2026] [security2:error] [pid 16093:tid 16154] [remote 54.184.226.94:9357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.226.184.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "youpositive.co"] [uri "/sucuri-sss-downloader_4aa5a158-69ff-4b4f-9ea0-7b5420f94c3b.php"] [unique_id "al4arpuybMv3z_zMVBSeHwABmTs"], referer: https://youpositive.co/sucuri-sss-downloader_4aa5a158-69ff-4b4f-9ea0-7b5420f94c3b.php
[Mon Jul 20 06:55:10.578328 2026] [security2:error] [pid 16093:tid 16234] [client 54.184.226.94:9357] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "409"] [hostname "youpositive.co"] [uri "/sucuri-sss-downloader_4aa5a158-69ff-4b4f-9ea0-7b5420f94c3b.php"] [unique_id "al4arpuybMv3z_zMVBSeHwABmTs"], referer: https://youpositive.co/sucuri-sss-downloader_4aa5a158-69ff-4b4f-9ea0-7b5420f94c3b.php
[Mon Jul 20 06:55:10.680088 2026] [security2:error] [pid 15216:tid 15381] [client 14.225.17.146:50413] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4arttIy0gkFcVddGZpJQAAAS0"], referer: https://bigwormfishing.com/wp-old
[Mon Jul 20 06:55:10.712324 2026] [security2:error] [pid 16093:tid 16155] [remote 20.173.88.122:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4arpuybMv3z_zMVBSeIgABvTw"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 06:55:10.876902 2026] [security2:error] [pid 15216:tid 15347] [client 14.225.17.146:59062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4ardtIy0gkFcVddGZo_gAAAQs"], referer: http://mazzucelli.com/wp-old
[Mon Jul 20 06:55:10.891258 2026] [security2:error] [pid 16093:tid 16159] [remote 103.28.36.106:37530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4arpuybMv3z_zMVBSeLgACA0A"]
[Mon Jul 20 06:55:10.973568 2026] [security2:error] [pid 15216:tid 15387] [client 117.247.108.24:14223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4arttIy0gkFcVddGZpOAAAATM"]
[Mon Jul 20 06:55:10.973695 2026] [security2:error] [pid 15216:tid 15387] [client 117.247.108.24:14223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4arttIy0gkFcVddGZpOAAAATM"]
[Mon Jul 20 06:55:10.996592 2026] [security2:error] [pid 15216:tid 15436] [client 57.141.18.55:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4arttIy0gkFcVddGZpNQAAAWQ"]
[Mon Jul 20 06:55:11.007238 2026] [security2:error] [pid 15216:tid 15380] [client 20.151.205.204:57546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/file52.php"] [unique_id "al4ar9tIy0gkFcVddGZpOwAAASw"]
[Mon Jul 20 06:55:11.007330 2026] [security2:error] [pid 15216:tid 15380] [client 20.151.205.204:57546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/file52.php"] [unique_id "al4ar9tIy0gkFcVddGZpOwAAASw"]
[Mon Jul 20 06:55:11.039292 2026] [security2:error] [pid 15216:tid 15470] [client 74.208.214.194:37362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ar9tIy0gkFcVddGZpPAAAAYY"]
[Mon Jul 20 06:55:11.486866 2026] [security2:error] [pid 16093:tid 16273] [client 14.224.227.113:54783] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ar5uybMv3z_zMVBSeSQAAAcA"]
[Mon Jul 20 06:55:11.492589 2026] [security2:error] [pid 16093:tid 16293] [client 13.232.231.177:10980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "503"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ar5uybMv3z_zMVBSeRQAAAdQ"]
[Mon Jul 20 06:55:11.506500 2026] [security2:error] [pid 16093:tid 16162] [remote 154.61.75.100:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ar5uybMv3z_zMVBSeSAABwUM"]
[Mon Jul 20 06:55:11.506688 2026] [security2:error] [pid 16093:tid 16274] [client 154.61.75.100:53358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ar5uybMv3z_zMVBSeSAABwUM"]
[Mon Jul 20 06:55:11.554008 2026] [security2:error] [pid 16093:tid 16346] [client 20.151.205.204:45561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/122.php"] [unique_id "al4ar5uybMv3z_zMVBSeSwAAAgk"]
[Mon Jul 20 06:55:11.554102 2026] [security2:error] [pid 16093:tid 16346] [client 20.151.205.204:45561] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/122.php"] [unique_id "al4ar5uybMv3z_zMVBSeSwAAAgk"]
[Mon Jul 20 06:55:11.812483 2026] [security2:error] [pid 16093:tid 16165] [remote 103.28.36.106:37530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4ar5uybMv3z_zMVBSeVgABvkY"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 06:55:12.137714 2026] [security2:error] [pid 15216:tid 15359] [client 183.82.98.154:60985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4asNtIy0gkFcVddGZpcwAAARc"]
[Mon Jul 20 06:55:12.137900 2026] [security2:error] [pid 15216:tid 15359] [client 183.82.98.154:60985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4asNtIy0gkFcVddGZpcwAAARc"]
[Mon Jul 20 06:55:12.385464 2026] [security2:error] [pid 15216:tid 15380] [client 20.151.205.204:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/green1.php"] [unique_id "al4asNtIy0gkFcVddGZpfQAAASw"]
[Mon Jul 20 06:55:12.385579 2026] [security2:error] [pid 15216:tid 15380] [client 20.151.205.204:62521] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.finalcialsgroup.com"] [uri "/green1.php"] [unique_id "al4asNtIy0gkFcVddGZpfQAAASw"]
[Mon Jul 20 06:55:12.423918 2026] [security2:error] [pid 15216:tid 15373] [client 14.225.17.146:61238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4asNtIy0gkFcVddGZpdAAAASU"], referer: http://transparentservices.online/wp-old
[Mon Jul 20 06:55:12.907154 2026] [security2:error] [pid 16093:tid 16261] [client 14.225.17.146:55166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4arpuybMv3z_zMVBSeMgAAAbQ"], referer: http://securingmemories.com/wp-old
[Mon Jul 20 06:55:12.957817 2026] [security2:error] [pid 16093:tid 16173] [remote 13.232.189.155:43040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4asJuybMv3z_zMVBSegAAB504"]
[Mon Jul 20 06:55:12.964194 2026] [security2:error] [pid 16093:tid 16295] [client 122.183.32.225:29759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4asJuybMv3z_zMVBSegQAAAdY"]
[Mon Jul 20 06:55:12.964313 2026] [security2:error] [pid 16093:tid 16295] [client 122.183.32.225:29759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4asJuybMv3z_zMVBSegQAAAdY"]
[Mon Jul 20 06:55:13.119189 2026] [security2:error] [pid 15216:tid 15413] [client 104.234.53.48:45149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4asdtIy0gkFcVddGZpoAAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:13.168418 2026] [security2:error] [pid 16093:tid 16290] [client 217.142.18.172:2781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4asZuybMv3z_zMVBSehwAAAdE"]
[Mon Jul 20 06:55:13.168547 2026] [security2:error] [pid 16093:tid 16290] [client 217.142.18.172:2781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4asZuybMv3z_zMVBSehwAAAdE"]
[Mon Jul 20 06:55:13.225159 2026] [security2:error] [pid 15216:tid 15229] [remote 89.216.62.195:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.62.216.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4asdtIy0gkFcVddGZpowABhAw"]
[Mon Jul 20 06:55:13.234726 2026] [security2:error] [pid 15216:tid 15235] [remote 217.61.143.92:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4asdtIy0gkFcVddGZppgABEBI"]
[Mon Jul 20 06:55:13.351480 2026] [security2:error] [pid 16093:tid 16176] [remote 13.232.189.155:43040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4asZuybMv3z_zMVBSejAABqlE"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 06:55:13.395858 2026] [security2:error] [pid 16093:tid 16274] [client 152.58.191.29:32748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4asZuybMv3z_zMVBSejwAAAcE"]
[Mon Jul 20 06:55:13.404454 2026] [security2:error] [pid 16093:tid 16274] [client 152.58.191.29:32748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4asZuybMv3z_zMVBSejwAAAcE"]
[Mon Jul 20 06:55:13.460669 2026] [security2:error] [pid 15216:tid 15245] [remote 217.61.143.92:57258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4asdtIy0gkFcVddGZpsAABJBw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:55:13.704839 2026] [security2:error] [pid 16093:tid 16288] [client 14.225.17.146:58353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4asJuybMv3z_zMVBSeYgAAAc8"], referer: http://margaretspeckogawa.com/wp-old
[Mon Jul 20 06:55:14.186093 2026] [security2:error] [pid 15216:tid 15252] [remote 89.216.62.195:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.62.216.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4asttIy0gkFcVddGZpywABMSM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:55:14.226104 2026] [security2:error] [pid 16093:tid 16307] [client 65.111.20.73:42289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4aspuybMv3z_zMVBSerwAAAeI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:55:14.368866 2026] [security2:error] [pid 15216:tid 15440] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.dereckcastellon.com"] [uri "/~dereckca/index.php"] [unique_id "al4asNtIy0gkFcVddGZpmAAAAWg"]
[Mon Jul 20 06:55:14.465725 2026] [security2:error] [pid 16093:tid 16280] [client 14.225.17.146:58445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4asZuybMv3z_zMVBSegwAAAcc"], referer: http://kromosenergy.com/wp-old
[Mon Jul 20 06:55:14.592778 2026] [security2:error] [pid 16093:tid 16295] [client 197.186.66.42:55611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aspuybMv3z_zMVBSevwAAAdY"]
[Mon Jul 20 06:55:14.592937 2026] [security2:error] [pid 16093:tid 16295] [client 197.186.66.42:55611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4aspuybMv3z_zMVBSevwAAAdY"]
[Mon Jul 20 06:55:14.600284 2026] [security2:error] [pid 15216:tid 15451] [client 77.110.127.138:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4asttIy0gkFcVddGZp2AAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:14.600396 2026] [security2:error] [pid 15216:tid 15451] [client 77.110.127.138:59518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4asttIy0gkFcVddGZp2AAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:14.812268 2026] [security2:error] [pid 15216:tid 15443] [client 5.161.177.47:17028] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4asttIy0gkFcVddGZp4AAAAWs"], referer: https://windowtx.com
[Mon Jul 20 06:55:15.189451 2026] [security2:error] [pid 16093:tid 16260] [client 103.238.106.162:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4as5uybMv3z_zMVBSe0QAAAbM"]
[Mon Jul 20 06:55:15.190224 2026] [security2:error] [pid 16093:tid 16260] [client 103.238.106.162:60958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4as5uybMv3z_zMVBSe0QAAAbM"]
[Mon Jul 20 06:55:15.364010 2026] [security2:error] [pid 15216:tid 15359] [client 50.116.65.227:58958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4as9tIy0gkFcVddGZp8QAAARc"]
[Mon Jul 20 06:55:15.374462 2026] [security2:error] [pid 15216:tid 15445] [client 50.116.65.227:58970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4as9tIy0gkFcVddGZp8gAAAW0"]
[Mon Jul 20 06:55:15.739560 2026] [security2:error] [pid 16093:tid 16328] [client 14.225.17.146:54320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4as5uybMv3z_zMVBSe5AAAAfc"], referer: http://ivetstrategies.com/wp-old
[Mon Jul 20 06:55:16.141545 2026] [security2:error] [pid 15216:tid 15414] [client 14.225.17.146:55256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4asttIy0gkFcVddGZp5wAAAU4"], referer: http://sarahholyfield.com/wp-old
[Mon Jul 20 06:55:16.607183 2026] [security2:error] [pid 16093:tid 16346] [client 104.234.53.72:25315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4atJuybMv3z_zMVBSfCwAAAgk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:16.671093 2026] [security2:error] [pid 15216:tid 15456] [client 77.110.127.138:59535] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4atNtIy0gkFcVddGZqHgAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:16.786157 2026] [security2:error] [pid 15216:tid 15316] [remote 188.166.241.141:40626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4atNtIy0gkFcVddGZqIQABVWM"]
[Mon Jul 20 06:55:17.195565 2026] [security2:error] [pid 15216:tid 15338] [remote 188.166.241.141:40626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4atdtIy0gkFcVddGZqLwABVnk"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:55:17.205845 2026] [security2:error] [pid 16093:tid 16329] [client 57.141.18.1:48110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4as5uybMv3z_zMVBSe3gAB-Fw"]
[Mon Jul 20 06:55:17.712060 2026] [security2:error] [pid 16093:tid 16334] [client 77.110.127.138:59539] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 62 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4atZuybMv3z_zMVBSfNwAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:17.759531 2026] [security2:error] [pid 16093:tid 16326] [client 50.116.65.227:58998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4atZuybMv3z_zMVBSfOAAAAfU"]
[Mon Jul 20 06:55:18.087301 2026] [security2:error] [pid 15216:tid 15381] [client 14.225.17.146:54323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4atdtIy0gkFcVddGZqRwAAAS0"], referer: http://getgarrison.com/wp-old
[Mon Jul 20 06:55:18.101881 2026] [security2:error] [pid 16093:tid 16254] [client 14.225.17.146:49838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4atZuybMv3z_zMVBSfPAAAAa0"], referer: http://lifeisbetterlakeside.com/wp-old
[Mon Jul 20 06:55:18.104163 2026] [security2:error] [pid 16093:tid 16204] [remote 91.142.222.105:40126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4atpuybMv3z_zMVBSfRQABmm0"]
[Mon Jul 20 06:55:18.281486 2026] [security2:error] [pid 16093:tid 16283] [client 14.225.17.146:55211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4atpuybMv3z_zMVBSfRwAAAco"], referer: http://ksands.co.uk/wp-old
[Mon Jul 20 06:55:18.346608 2026] [security2:error] [pid 16093:tid 16207] [remote 91.142.222.105:40126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4atpuybMv3z_zMVBSfTgABk3A"], referer: https://mail.legallyknownaszacharyhoy999.com/wp-login.php
[Mon Jul 20 06:55:18.554393 2026] [security2:error] [pid 15216:tid 15236] [remote 38.242.157.30:55798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4atttIy0gkFcVddGZqYwABThM"]
[Mon Jul 20 06:55:18.554586 2026] [security2:error] [pid 15216:tid 15414] [client 38.242.157.30:55798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4atttIy0gkFcVddGZqYwABThM"]
[Mon Jul 20 06:55:18.558549 2026] [security2:error] [pid 15216:tid 15361] [client 216.73.216.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.3ddynamics.org"] [uri "/index.php"] [unique_id "al4atttIy0gkFcVddGZqXQAAARk"]
[Mon Jul 20 06:55:18.621910 2026] [security2:error] [pid 15216:tid 15350] [client 14.225.17.146:55108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4atttIy0gkFcVddGZqXwAAAQ4"], referer: http://taskidsvirginia.com/wp-old
[Mon Jul 20 06:55:18.655879 2026] [security2:error] [pid 15216:tid 15419] [client 187.108.85.186:53390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4atttIy0gkFcVddGZqZwAAAVM"]
[Mon Jul 20 06:55:18.655975 2026] [security2:error] [pid 15216:tid 15419] [client 187.108.85.186:53390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4atttIy0gkFcVddGZqZwAAAVM"]
[Mon Jul 20 06:55:18.693253 2026] [security2:error] [pid 16093:tid 16305] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4atpuybMv3z_zMVBSfWAAB4HI"], referer: http://assasalnazaha.com/wp-old
[Mon Jul 20 06:55:18.871780 2026] [security2:error] [pid 16093:tid 16234] [client 104.207.53.192:55177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4atpuybMv3z_zMVBSfYwAAAZk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:18.915943 2026] [security2:error] [pid 16093:tid 16261] [client 77.110.127.138:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4atpuybMv3z_zMVBSfZwAAAbQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:18.916108 2026] [security2:error] [pid 16093:tid 16261] [client 77.110.127.138:59546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4atpuybMv3z_zMVBSfZwAAAbQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:19.151936 2026] [security2:error] [pid 16093:tid 16304] [client 23.94.28.190:51638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "thewelloiledlife.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "al4at5uybMv3z_zMVBSfdgAAAd8"]
[Mon Jul 20 06:55:19.223784 2026] [security2:error] [pid 15216:tid 15465] [client 103.125.179.95:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4at9tIy0gkFcVddGZqfwAAAYE"]
[Mon Jul 20 06:55:19.224234 2026] [security2:error] [pid 15216:tid 15465] [client 103.125.179.95:49622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4at9tIy0gkFcVddGZqfwAAAYE"]
[Mon Jul 20 06:55:19.406333 2026] [security2:error] [pid 15216:tid 15427] [client 14.225.17.146:56116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4atttIy0gkFcVddGZqWAAAAVs"], referer: http://intelligentengineeringsolutions.com/wp-old
[Mon Jul 20 06:55:19.423430 2026] [security2:error] [pid 16093:tid 16241] [client 57.141.18.65:40562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4atZuybMv3z_zMVBSfOQABoGs"]
[Mon Jul 20 06:55:19.464093 2026] [security2:error] [pid 16093:tid 16227] [client 23.94.28.190:51657] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "thewelloiledlife.com"] [uri "/Telerik.Web.UI.WebResource.axd"] [unique_id "al4at5uybMv3z_zMVBSfhwAAAZI"]
[Mon Jul 20 06:55:19.494576 2026] [security2:error] [pid 16093:tid 16279] [client 66.249.81.32:53030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4at5uybMv3z_zMVBSfdQAAAcY"]
[Mon Jul 20 06:55:19.536487 2026] [security2:error] [pid 15216:tid 15402] [client 14.225.17.146:53476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4at9tIy0gkFcVddGZqhQAAAUI"], referer: http://dadanetnet.net/wp-old
[Mon Jul 20 06:55:19.664574 2026] [security2:error] [pid 16093:tid 16238] [client 216.73.216.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.3ddynamics.org"] [uri "/index.php"] [unique_id "al4at5uybMv3z_zMVBSfjQAAAZ0"]
[Mon Jul 20 06:55:19.749769 2026] [lsapi:warn] [pid 16093:tid 16257] [client 14.225.17.146:55129] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wp-old
[Mon Jul 20 06:55:19.749787 2026] [lsapi:warn] [pid 16093:tid 16257] [client 14.225.17.146:55129] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/wp-old
[Mon Jul 20 06:55:20.013844 2026] [security2:error] [pid 16093:tid 16338] [client 104.234.53.73:49511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4at5uybMv3z_zMVBSfmgAAAgE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:20.089386 2026] [security2:error] [pid 16093:tid 16222] [remote 216.73.216.6:10946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/index.php/sitemap_index.xml"] [unique_id "al4auJuybMv3z_zMVBSfnQAB-n8"]
[Mon Jul 20 06:55:20.240003 2026] [lsapi:warn] [pid 16093:tid 16249] [client 50.116.65.227:16228] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:55:20.240026 2026] [lsapi:warn] [pid 16093:tid 16249] [client 50.116.65.227:16228] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:55:20.254231 2026] [security2:error] [pid 16093:tid 16257] [client 14.225.17.146:55129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4at5uybMv3z_zMVBSffAAAAbA"], referer: http://oswegooperatheater.com/wp-old
[Mon Jul 20 06:55:20.292474 2026] [security2:error] [pid 15216:tid 15280] [remote 103.118.29.185:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4auNtIy0gkFcVddGZqrwABWD8"]
[Mon Jul 20 06:55:20.421843 2026] [security2:error] [pid 15216:tid 15358] [client 103.144.65.217:58715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4auNtIy0gkFcVddGZqvQAAARY"]
[Mon Jul 20 06:55:20.422073 2026] [security2:error] [pid 15216:tid 15358] [client 103.144.65.217:58715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4auNtIy0gkFcVddGZqvQAAARY"]
[Mon Jul 20 06:55:20.758452 2026] [security2:error] [pid 15216:tid 15392] [client 117.222.139.248:60721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4auNtIy0gkFcVddGZqygAAATg"]
[Mon Jul 20 06:55:20.758552 2026] [security2:error] [pid 15216:tid 15392] [client 117.222.139.248:60721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4auNtIy0gkFcVddGZqygAAATg"]
[Mon Jul 20 06:55:20.840768 2026] [security2:error] [pid 15216:tid 15274] [remote 103.118.29.185:42100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4auNtIy0gkFcVddGZqzgABZzk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:55:20.893490 2026] [security2:error] [pid 15216:tid 15426] [client 77.110.127.138:59558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4auNtIy0gkFcVddGZq0gAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:21.094937 2026] [lsapi:warn] [pid 15216:tid 15381] [client 14.225.17.146:54473] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wp-old
[Mon Jul 20 06:55:21.094978 2026] [lsapi:warn] [pid 15216:tid 15381] [client 14.225.17.146:54473] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/wp-old
[Mon Jul 20 06:55:21.147707 2026] [security2:error] [pid 15216:tid 15381] [client 14.225.17.146:54473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4audtIy0gkFcVddGZq2wAAAS0"], referer: https://oswegooperatheater.com/wp-old
[Mon Jul 20 06:55:21.515514 2026] [security2:error] [pid 15216:tid 15393] [client 14.225.17.146:56046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4audtIy0gkFcVddGZq5AAAATk"]
[Mon Jul 20 06:55:21.797501 2026] [security2:error] [pid 16093:tid 16297] [client 117.247.108.24:62231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4auZuybMv3z_zMVBSfxwAAAdg"]
[Mon Jul 20 06:55:21.797637 2026] [security2:error] [pid 16093:tid 16297] [client 117.247.108.24:62231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4auZuybMv3z_zMVBSfxwAAAdg"]
[Mon Jul 20 06:55:21.917676 2026] [security2:error] [pid 16093:tid 16290] [client 14.225.17.146:53383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4auJuybMv3z_zMVBSfpwAAAdE"], referer: http://expertcultures.com/wp-old
[Mon Jul 20 06:55:22.413963 2026] [security2:error] [pid 16093:tid 16312] [client 45.3.54.175:39099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aupuybMv3z_zMVBSf4gAAAec"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:22.482158 2026] [security2:error] [pid 15216:tid 15453] [client 14.225.17.146:54376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4auNtIy0gkFcVddGZq1AAAAXU"], referer: http://xp-design.co/wp-old
[Mon Jul 20 06:55:22.485219 2026] [security2:error] [pid 15216:tid 15444] [client 77.110.127.138:59569] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 256 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4auttIy0gkFcVddGZrFQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:22.666529 2026] [security2:error] [pid 16093:tid 16316] [client 77.110.127.138:59571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aupuybMv3z_zMVBSf6wAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:22.666630 2026] [security2:error] [pid 16093:tid 16316] [client 77.110.127.138:59571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aupuybMv3z_zMVBSf6wAAAes"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:22.986978 2026] [security2:error] [pid 16093:tid 16295] [client 183.82.98.154:61585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aupuybMv3z_zMVBSf9AAAAdY"]
[Mon Jul 20 06:55:22.987126 2026] [security2:error] [pid 16093:tid 16295] [client 183.82.98.154:61585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4aupuybMv3z_zMVBSf9AAAAdY"]
[Mon Jul 20 06:55:23.040972 2026] [security2:error] [pid 16093:tid 16256] [client 104.234.53.54:27683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4au5uybMv3z_zMVBSf-QAAAa8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:23.689941 2026] [security2:error] [pid 15216:tid 15300] [remote 45.150.79.142:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4au9tIy0gkFcVddGZrQgABSlM"]
[Mon Jul 20 06:55:23.874228 2026] [security2:error] [pid 15216:tid 15227] [remote 45.150.79.142:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4au9tIy0gkFcVddGZrSgABKAo"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 06:55:24.032878 2026] [security2:error] [pid 16093:tid 16272] [client 152.58.191.29:51761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4avJuybMv3z_zMVBSgIwAAAb8"]
[Mon Jul 20 06:55:24.033025 2026] [security2:error] [pid 16093:tid 16272] [client 152.58.191.29:51761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4avJuybMv3z_zMVBSgIwAAAb8"]
[Mon Jul 20 06:55:24.317775 2026] [security2:error] [pid 15216:tid 15401] [client 65.111.13.176:51301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.13.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4avNtIy0gkFcVddGZrXAAAAUE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:55:24.743554 2026] [security2:error] [pid 16093:tid 16120] [remote 192.241.143.148:40514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4avJuybMv3z_zMVBSgQAABnBk"]
[Mon Jul 20 06:55:25.198640 2026] [security2:error] [pid 16093:tid 16121] [remote 192.241.143.148:40514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4avZuybMv3z_zMVBSgTAABtho"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:55:25.291600 2026] [security2:error] [pid 15216:tid 15420] [client 77.110.127.138:59583] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4avdtIy0gkFcVddGZrgAAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:25.318606 2026] [security2:error] [pid 15216:tid 15452] [client 217.142.18.172:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4avdtIy0gkFcVddGZrgQAAAXQ"]
[Mon Jul 20 06:55:25.318810 2026] [security2:error] [pid 15216:tid 15452] [client 217.142.18.172:63454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4avdtIy0gkFcVddGZrgQAAAXQ"]
[Mon Jul 20 06:55:25.387393 2026] [security2:error] [pid 15216:tid 15359] [client 14.225.17.146:54953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4au9tIy0gkFcVddGZrQwAAARc"], referer: http://maxenengineering.com/wp-old
[Mon Jul 20 06:55:25.735209 2026] [security2:error] [pid 16093:tid 16274] [client 103.238.106.162:63592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4avZuybMv3z_zMVBSgXgAAAcE"]
[Mon Jul 20 06:55:25.735351 2026] [security2:error] [pid 16093:tid 16274] [client 103.238.106.162:63592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4avZuybMv3z_zMVBSgXgAAAcE"]
[Mon Jul 20 06:55:26.112457 2026] [security2:error] [pid 15216:tid 15369] [client 104.234.53.88:53489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4avttIy0gkFcVddGZrlwAAASE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:26.172211 2026] [security2:error] [pid 16093:tid 16250] [client 77.110.127.138:59586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 771 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4avpuybMv3z_zMVBSgaQAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:26.257061 2026] [security2:error] [pid 16093:tid 16346] [client 194.5.53.221:27545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/bless.php"] [unique_id "al4avpuybMv3z_zMVBSgbQAAAgk"]
[Mon Jul 20 06:55:26.266983 2026] [security2:error] [pid 15216:tid 15462] [client 64.203.48.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4avNtIy0gkFcVddGZrbwAAAX4"]
[Mon Jul 20 06:55:26.269660 2026] [security2:error] [pid 16093:tid 16292] [client 64.203.48.179:55451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/13540.php"] [unique_id "al4avJuybMv3z_zMVBSgQQAB0xs"]
[Mon Jul 20 06:55:26.327452 2026] [security2:error] [pid 16093:tid 16245] [client 77.110.127.138:59587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4avpuybMv3z_zMVBSgcgAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:26.327572 2026] [security2:error] [pid 16093:tid 16245] [client 77.110.127.138:59587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4avpuybMv3z_zMVBSgcgAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:26.417883 2026] [security2:error] [pid 16093:tid 16261] [client 14.225.17.146:49958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4avpuybMv3z_zMVBSgcAAAAbQ"], referer: https://maxenengineering.com/wp-old
[Mon Jul 20 06:55:26.443736 2026] [security2:error] [pid 16093:tid 16262] [client 34.74.242.206:1719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sanifidensolutions.com"] [uri "/robots.txt"] [unique_id "al4avpuybMv3z_zMVBSgegAAAbU"]
[Mon Jul 20 06:55:26.443856 2026] [security2:error] [pid 16093:tid 16262] [client 34.74.242.206:1719] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sanifidensolutions.com"] [uri "/robots.txt"] [unique_id "al4avpuybMv3z_zMVBSgegAAAbU"]
[Mon Jul 20 06:55:26.549002 2026] [security2:error] [pid 16093:tid 16279] [client 34.74.242.206:1698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sanifidensolutions.com"] [uri "/"] [unique_id "al4avpuybMv3z_zMVBSgfwAAAcY"]
[Mon Jul 20 06:55:26.549076 2026] [security2:error] [pid 16093:tid 16279] [client 34.74.242.206:1698] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sanifidensolutions.com"] [uri "/"] [unique_id "al4avpuybMv3z_zMVBSgfwAAAcY"]
[Mon Jul 20 06:55:26.636565 2026] [security2:error] [pid 16093:tid 16229] [client 197.186.66.42:56111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4avpuybMv3z_zMVBSghQAAAZQ"]
[Mon Jul 20 06:55:26.637206 2026] [security2:error] [pid 16093:tid 16229] [client 197.186.66.42:56111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4avpuybMv3z_zMVBSghQAAAZQ"]
[Mon Jul 20 06:55:26.642507 2026] [security2:error] [pid 15216:tid 15412] [client 14.225.17.146:63018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4avttIy0gkFcVddGZrpwAAAUw"], referer: http://carolinapressurewashers.com/wp-old
[Mon Jul 20 06:55:26.938826 2026] [security2:error] [pid 15216:tid 15430] [client 14.224.227.113:54785] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4avttIy0gkFcVddGZruQAAAV4"]
[Mon Jul 20 06:55:26.998031 2026] [security2:error] [pid 16093:tid 16349] [client 14.225.17.146:49847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4avZuybMv3z_zMVBSgXQAAAgw"], referer: http://hammadownenterprises.com/wp-old
[Mon Jul 20 06:55:27.309261 2026] [security2:error] [pid 15216:tid 15301] [remote 100.42.189.89:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4av9tIy0gkFcVddGZr0gABg1Q"]
[Mon Jul 20 06:55:27.339937 2026] [security2:error] [pid 16093:tid 16260] [client 14.225.17.146:49938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4avpuybMv3z_zMVBSgiAAAAbM"]
[Mon Jul 20 06:55:27.524094 2026] [security2:error] [pid 15216:tid 15302] [remote 100.42.189.89:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4av9tIy0gkFcVddGZr1wABNlU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:55:27.631188 2026] [security2:error] [pid 16093:tid 16251] [client 194.5.53.54:23481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/O-Simple.php"] [unique_id "al4av5uybMv3z_zMVBSgoAAAAao"]
[Mon Jul 20 06:55:27.886569 2026] [security2:error] [pid 15216:tid 15416] [client 64.203.48.179:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4av9tIy0gkFcVddGZr4QAAAVA"], referer: https://www.adambergeron.com/13540.php
[Mon Jul 20 06:55:27.892085 2026] [security2:error] [pid 15216:tid 15427] [client 64.203.48.179:35601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/13540.php"] [unique_id "al4av9tIy0gkFcVddGZr3gABW1o"], referer: https://www.adambergeron.com/13540.php
[Mon Jul 20 06:55:28.076234 2026] [security2:error] [pid 15216:tid 15371] [client 124.217.84.255:6627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "juniper3medical.com"] [uri "/index.php"] [unique_id "al4av9tIy0gkFcVddGZr4AABI10"], referer: https://juniper3medical.com/contact-us/
[Mon Jul 20 06:55:28.076383 2026] [security2:error] [pid 15216:tid 15371] [client 124.217.84.255:6627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "juniper3medical.com"] [uri "/index.php"] [unique_id "al4av9tIy0gkFcVddGZr5wABI2g"], referer: https://juniper3medical.com/contact-us/
[Mon Jul 20 06:55:28.076465 2026] [security2:error] [pid 15216:tid 15371] [client 124.217.84.255:6627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "juniper3medical.com"] [uri "/index.php"] [unique_id "al4av9tIy0gkFcVddGZr5gABI1w"], referer: https://juniper3medical.com/contact-us/
[Mon Jul 20 06:55:28.106105 2026] [security2:error] [pid 16093:tid 16300] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4av5uybMv3z_zMVBSgtwAB2y0"], referer: http://aleishapenny.ca/wp-old
[Mon Jul 20 06:55:28.126613 2026] [security2:error] [pid 15216:tid 15465] [client 14.225.17.146:63238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4av9tIy0gkFcVddGZsCQAAAYE"], referer: http://talknutritionwithlesley.com/wp-old
[Mon Jul 20 06:55:28.663492 2026] [security2:error] [pid 16093:tid 16232] [client 57.141.18.118:44248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4avpuybMv3z_zMVBSgfgABlyY"]
[Mon Jul 20 06:55:28.713227 2026] [security2:error] [pid 15216:tid 15454] [client 194.5.53.237:37543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/lock360.php"] [unique_id "al4awNtIy0gkFcVddGZsJgAAAXY"]
[Mon Jul 20 06:55:28.917407 2026] [security2:error] [pid 16093:tid 16286] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4awJuybMv3z_zMVBSg1gABzS8"], referer: https://aleishapenny.ca/wp-old
[Mon Jul 20 06:55:28.962479 2026] [security2:error] [pid 15216:tid 15396] [client 14.225.17.146:63668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4awNtIy0gkFcVddGZsLQAAATw"], referer: http://daseighty.net/wp-old
[Mon Jul 20 06:55:29.021292 2026] [security2:error] [pid 16093:tid 16275] [client 14.225.17.146:62989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4avpuybMv3z_zMVBSgeQAAAcI"], referer: http://bruceledewitz.com/wp-old
[Mon Jul 20 06:55:29.186620 2026] [security2:error] [pid 15216:tid 15467] [client 187.108.85.186:53937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4awdtIy0gkFcVddGZsPAAAAYM"]
[Mon Jul 20 06:55:29.186745 2026] [security2:error] [pid 15216:tid 15467] [client 187.108.85.186:53937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4awdtIy0gkFcVddGZsPAAAAYM"]
[Mon Jul 20 06:55:29.306391 2026] [security2:error] [pid 16093:tid 16242] [client 8.228.127.164:49525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.127.228.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "emsbodystorm.com"] [uri "/xmlrpc.php"] [unique_id "al4awZuybMv3z_zMVBSg6wAAAaE"]
[Mon Jul 20 06:55:29.306516 2026] [security2:error] [pid 16093:tid 16242] [client 8.228.127.164:49525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "emsbodystorm.com"] [uri "/xmlrpc.php"] [unique_id "al4awZuybMv3z_zMVBSg6wAAAaE"]
[Mon Jul 20 06:55:29.804191 2026] [security2:error] [pid 15216:tid 15466] [client 74.7.241.133:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "undefeatedthe.com"] [uri "/index.php"] [unique_id "al4av9tIy0gkFcVddGZrwwABgkY"]
[Mon Jul 20 06:55:29.903945 2026] [security2:error] [pid 15216:tid 15365] [client 77.110.127.138:59600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4awdtIy0gkFcVddGZsYgAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:29.969680 2026] [security2:error] [pid 16093:tid 16293] [client 103.125.179.95:50147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4awZuybMv3z_zMVBShAAAAAdQ"]
[Mon Jul 20 06:55:29.969895 2026] [security2:error] [pid 16093:tid 16293] [client 103.125.179.95:50147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4awZuybMv3z_zMVBShAAAAAdQ"]
[Mon Jul 20 06:55:30.627615 2026] [security2:error] [pid 16093:tid 16298] [client 77.110.127.138:59603] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 808 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4awpuybMv3z_zMVBShKAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:30.633919 2026] [security2:error] [pid 16093:tid 16275] [client 103.144.65.217:59353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4awpuybMv3z_zMVBShKQAAAcI"]
[Mon Jul 20 06:55:30.634594 2026] [security2:error] [pid 16093:tid 16275] [client 103.144.65.217:59353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4awpuybMv3z_zMVBShKQAAAcI"]
[Mon Jul 20 06:55:30.776784 2026] [security2:error] [pid 16093:tid 16244] [client 77.110.127.138:59605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4awpuybMv3z_zMVBShLQAAAaM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:30.776870 2026] [security2:error] [pid 16093:tid 16244] [client 77.110.127.138:59605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4awpuybMv3z_zMVBShLQAAAaM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:30.882268 2026] [security2:error] [pid 16093:tid 16236] [client 158.173.166.181:30561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4awpuybMv3z_zMVBShMAAAAZs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:55:31.024829 2026] [security2:error] [pid 16093:tid 16229] [client 77.110.127.138:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aw5uybMv3z_zMVBShPgAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.024924 2026] [security2:error] [pid 16093:tid 16229] [client 77.110.127.138:59607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aw5uybMv3z_zMVBShPgAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.070210 2026] [security2:error] [pid 16093:tid 16315] [client 57.141.18.98:58710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4awJuybMv3z_zMVBSgzgAB6iw"]
[Mon Jul 20 06:55:31.182320 2026] [security2:error] [pid 16093:tid 16253] [client 77.110.127.138:59608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aw5uybMv3z_zMVBShRQAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.182413 2026] [security2:error] [pid 16093:tid 16253] [client 77.110.127.138:59608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aw5uybMv3z_zMVBShRQAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.204658 2026] [security2:error] [pid 15216:tid 15366] [client 54.244.177.189:36488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4aw9tIy0gkFcVddGZsfAAAAR4"]
[Mon Jul 20 06:55:31.248899 2026] [security2:error] [pid 15216:tid 15419] [client 13.232.231.177:13108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4awdtIy0gkFcVddGZsOAAAAVM"]
[Mon Jul 20 06:55:31.253856 2026] [security2:error] [pid 15216:tid 15417] [client 117.222.139.248:61209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aw9tIy0gkFcVddGZsfgAAAVE"]
[Mon Jul 20 06:55:31.253968 2026] [security2:error] [pid 15216:tid 15417] [client 117.222.139.248:61209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4aw9tIy0gkFcVddGZsfgAAAVE"]
[Mon Jul 20 06:55:31.333476 2026] [security2:error] [pid 16093:tid 16243] [client 194.5.53.249:29121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/zwso.php"] [unique_id "al4aw5uybMv3z_zMVBShSAAAAaI"]
[Mon Jul 20 06:55:31.492229 2026] [security2:error] [pid 15216:tid 15346] [client 14.225.17.146:63841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4awdtIy0gkFcVddGZsXQAAAQo"], referer: http://aandarealtygroup.com/wp-old
[Mon Jul 20 06:55:31.807094 2026] [security2:error] [pid 15216:tid 15324] [remote 95.217.78.234:41588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4aw9tIy0gkFcVddGZskwABNWs"]
[Mon Jul 20 06:55:31.845203 2026] [security2:error] [pid 16093:tid 16236] [client 77.110.127.138:59612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aw5uybMv3z_zMVBShZAAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.845287 2026] [security2:error] [pid 16093:tid 16236] [client 77.110.127.138:59612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4aw5uybMv3z_zMVBShZAAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.951119 2026] [security2:error] [pid 16093:tid 16265] [client 77.110.127.138:59613] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4aw5uybMv3z_zMVBShbAAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:31.997403 2026] [security2:error] [pid 16093:tid 16279] [client 104.207.50.117:62887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4aw5uybMv3z_zMVBShbQAAAcY"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:32.025368 2026] [security2:error] [pid 16093:tid 16167] [remote 95.217.78.234:41598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4axJuybMv3z_zMVBShcAABy0g"]
[Mon Jul 20 06:55:32.151440 2026] [security2:error] [pid 15216:tid 15338] [remote 95.217.78.234:41588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4axNtIy0gkFcVddGZsogABW3k"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:55:32.263055 2026] [security2:error] [pid 16093:tid 16169] [remote 95.217.78.234:41598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4axJuybMv3z_zMVBShdQAB0ko"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 06:55:32.267224 2026] [security2:error] [pid 15216:tid 15439] [client 194.5.53.237:42251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/chosen.php"] [unique_id "al4axNtIy0gkFcVddGZspAAAAWc"]
[Mon Jul 20 06:55:32.337364 2026] [security2:error] [pid 16093:tid 16243] [client 77.110.127.138:59624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4axJuybMv3z_zMVBShdgAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:32.337450 2026] [security2:error] [pid 16093:tid 16243] [client 77.110.127.138:59624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4axJuybMv3z_zMVBShdgAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:32.537547 2026] [security2:error] [pid 15216:tid 15376] [client 117.247.108.24:62238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4axNtIy0gkFcVddGZssAAAASg"]
[Mon Jul 20 06:55:32.537644 2026] [security2:error] [pid 15216:tid 15376] [client 117.247.108.24:62238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4axNtIy0gkFcVddGZssAAAASg"]
[Mon Jul 20 06:55:32.723700 2026] [security2:error] [pid 16093:tid 16233] [client 74.235.9.104:39464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4axJuybMv3z_zMVBShhAAAAZg"]
[Mon Jul 20 06:55:32.924845 2026] [security2:error] [pid 16093:tid 16298] [client 77.110.127.138:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4axJuybMv3z_zMVBShkAAAAdk"]
[Mon Jul 20 06:55:32.924960 2026] [security2:error] [pid 16093:tid 16298] [client 77.110.127.138:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4axJuybMv3z_zMVBShkAAAAdk"]
[Mon Jul 20 06:55:33.160861 2026] [security2:error] [pid 16093:tid 16175] [remote 57.141.18.73:33628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/5667576"] [unique_id "al4axZuybMv3z_zMVBShnAAB61A"]
[Mon Jul 20 06:55:33.217736 2026] [security2:error] [pid 16093:tid 16247] [client 194.5.53.55:47465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/about.php"] [unique_id "al4axZuybMv3z_zMVBShngAAAaY"]
[Mon Jul 20 06:55:33.235350 2026] [security2:error] [pid 15216:tid 15360] [client 74.235.9.104:39482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4axdtIy0gkFcVddGZs0QAAARg"]
[Mon Jul 20 06:55:33.253384 2026] [security2:error] [pid 15216:tid 15350] [client 74.235.9.104:39470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4axdtIy0gkFcVddGZs0AAAAQ4"]
[Mon Jul 20 06:55:33.394305 2026] [security2:error] [pid 16093:tid 16300] [client 162.219.176.3:44128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.176.219.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4axZuybMv3z_zMVBShpAAAAds"]
[Mon Jul 20 06:55:33.394442 2026] [security2:error] [pid 16093:tid 16300] [client 162.219.176.3:44128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4axZuybMv3z_zMVBShpAAAAds"]
[Mon Jul 20 06:55:33.397795 2026] [security2:error] [pid 16093:tid 16330] [client 74.235.9.104:39466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4axZuybMv3z_zMVBShoQAAAfk"]
[Mon Jul 20 06:55:33.537947 2026] [security2:error] [pid 16093:tid 16343] [client 77.110.127.138:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4axZuybMv3z_zMVBShqQAAAgY"]
[Mon Jul 20 06:55:33.538074 2026] [security2:error] [pid 16093:tid 16343] [client 77.110.127.138:59631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4axZuybMv3z_zMVBShqQAAAgY"]
[Mon Jul 20 06:55:33.613955 2026] [security2:error] [pid 15216:tid 15422] [client 74.235.9.104:56234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4axdtIy0gkFcVddGZs4QAAAVY"]
[Mon Jul 20 06:55:33.710150 2026] [security2:error] [pid 16093:tid 16284] [client 183.82.98.154:62174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4axZuybMv3z_zMVBShtQAAAcs"]
[Mon Jul 20 06:55:33.710247 2026] [security2:error] [pid 16093:tid 16284] [client 183.82.98.154:62174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4axZuybMv3z_zMVBShtQAAAcs"]
[Mon Jul 20 06:55:33.879756 2026] [security2:error] [pid 15216:tid 15424] [client 122.183.32.225:18911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4axdtIy0gkFcVddGZs6wAAAVg"]
[Mon Jul 20 06:55:33.894458 2026] [security2:error] [pid 15216:tid 15424] [client 122.183.32.225:18911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4axdtIy0gkFcVddGZs6wAAAVg"]
[Mon Jul 20 06:55:34.138115 2026] [security2:error] [pid 15216:tid 15462] [client 217.142.18.172:47245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4axttIy0gkFcVddGZs-AAAAX4"]
[Mon Jul 20 06:55:34.138228 2026] [security2:error] [pid 15216:tid 15462] [client 217.142.18.172:47245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4axttIy0gkFcVddGZs-AAAAX4"]
[Mon Jul 20 06:55:34.178939 2026] [security2:error] [pid 16093:tid 16263] [client 194.5.53.211:59925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/admin.php"] [unique_id "al4axpuybMv3z_zMVBShyQAAAbY"]
[Mon Jul 20 06:55:34.477454 2026] [security2:error] [pid 16093:tid 16288] [client 194.180.48.253:37854] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "fluidtemple.org"] [uri "/"] [unique_id "al4axpuybMv3z_zMVBSh0wAAAc8"]
[Mon Jul 20 06:55:34.657152 2026] [security2:error] [pid 16093:tid 16294] [client 152.58.191.29:52207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4axpuybMv3z_zMVBSh4QAAAdU"]
[Mon Jul 20 06:55:34.657259 2026] [security2:error] [pid 16093:tid 16294] [client 152.58.191.29:52207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4axpuybMv3z_zMVBSh4QAAAdU"]
[Mon Jul 20 06:55:34.707419 2026] [security2:error] [pid 16093:tid 16289] [client 50.116.65.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4axpuybMv3z_zMVBSh3QAAAdA"]
[Mon Jul 20 06:55:34.897418 2026] [security2:error] [pid 16093:tid 16183] [remote 154.66.198.148:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4axpuybMv3z_zMVBSh6AAB6Vg"]
[Mon Jul 20 06:55:35.048132 2026] [security2:error] [pid 15216:tid 15416] [client 77.110.127.138:59637] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 426 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ax9tIy0gkFcVddGZtIwAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:35.360485 2026] [security2:error] [pid 16093:tid 16326] [client 158.173.241.141:51111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ax5uybMv3z_zMVBSh7wAAAfU"], referer: http://sesamegreenbeans.com/nine-days-south-africa-iv/
[Mon Jul 20 06:55:35.427157 2026] [security2:error] [pid 16093:tid 16185] [remote 154.66.198.148:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ax5uybMv3z_zMVBSh9QACA1o"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:55:35.498782 2026] [security2:error] [pid 16093:tid 16260] [client 74.208.214.194:39224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ax5uybMv3z_zMVBSh9gAAAbM"]
[Mon Jul 20 06:55:35.500824 2026] [security2:error] [pid 16093:tid 16273] [client 104.234.53.56:63815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ax5uybMv3z_zMVBSh9wAAAcA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:35.992659 2026] [security2:error] [pid 16093:tid 16191] [remote 192.241.143.148:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4ax5uybMv3z_zMVBSiCwABj2A"]
[Mon Jul 20 06:55:36.019996 2026] [security2:error] [pid 15216:tid 15418] [client 50.116.65.227:18770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4ayNtIy0gkFcVddGZtQAAAAVI"]
[Mon Jul 20 06:55:36.033098 2026] [security2:error] [pid 16093:tid 16298] [client 50.116.65.227:27164] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4ayJuybMv3z_zMVBSiDAAAAfs"]
[Mon Jul 20 06:55:36.168088 2026] [security2:error] [pid 16093:tid 16254] [client 194.5.53.55:41371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/mah.php"] [unique_id "al4ayJuybMv3z_zMVBSiFQAAAa0"]
[Mon Jul 20 06:55:36.182152 2026] [security2:error] [pid 16093:tid 16321] [client 103.238.106.162:42849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ayJuybMv3z_zMVBSiFgAAAfA"]
[Mon Jul 20 06:55:36.182232 2026] [security2:error] [pid 16093:tid 16321] [client 103.238.106.162:42849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ayJuybMv3z_zMVBSiFgAAAfA"]
[Mon Jul 20 06:55:36.251946 2026] [security2:error] [pid 16093:tid 16313] [client 77.110.127.138:59646] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ayJuybMv3z_zMVBSiHAAAAeg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:36.393792 2026] [security2:error] [pid 15216:tid 15379] [client 104.234.53.79:62633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ayNtIy0gkFcVddGZtTAAAASs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:36.639550 2026] [security2:error] [pid 15216:tid 15389] [client 50.116.65.227:27192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ayNtIy0gkFcVddGZtVwAAATU"]
[Mon Jul 20 06:55:36.649625 2026] [security2:error] [pid 15216:tid 15437] [client 50.116.65.227:27202] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ayNtIy0gkFcVddGZtWAAAAWU"]
[Mon Jul 20 06:55:36.695399 2026] [security2:error] [pid 15216:tid 15404] [client 104.234.53.79:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ayNtIy0gkFcVddGZtWgAAAUQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:36.741216 2026] [security2:error] [pid 16093:tid 16196] [remote 192.241.143.148:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4ayJuybMv3z_zMVBSiLAABnGU"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 06:55:36.893933 2026] [security2:error] [pid 15216:tid 15373] [client 57.141.18.108:23460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ax9tIy0gkFcVddGZtIgABJS4"]
[Mon Jul 20 06:55:36.951263 2026] [security2:error] [pid 16093:tid 16302] [client 74.7.228.37:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4ayJuybMv3z_zMVBSiMQAAAd0"]
[Mon Jul 20 06:55:36.954448 2026] [security2:error] [pid 16093:tid 16347] [client 74.7.228.37:44260] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "christiancountytrumpet.com"] [uri "/robots.txt"] [unique_id "al4ayJuybMv3z_zMVBSiLgACClw"]
[Mon Jul 20 06:55:37.680203 2026] [security2:error] [pid 16093:tid 16278] [client 77.110.127.138:59649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ayZuybMv3z_zMVBSiUQAAAcU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:37.680284 2026] [security2:error] [pid 16093:tid 16278] [client 77.110.127.138:59649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ayZuybMv3z_zMVBSiUQAAAcU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:37.689789 2026] [security2:error] [pid 15216:tid 15352] [client 216.24.212.20:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4aydtIy0gkFcVddGZtigAAARA"]
[Mon Jul 20 06:55:37.692835 2026] [security2:error] [pid 16093:tid 16248] [client 216.24.212.32:63029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4ayZuybMv3z_zMVBSiTwAAAac"]
[Mon Jul 20 06:55:38.227855 2026] [security2:error] [pid 15216:tid 15401] [client 194.5.53.195:33665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.wp/wso.php"] [unique_id "al4ayttIy0gkFcVddGZtoAAAAUE"]
[Mon Jul 20 06:55:38.554259 2026] [security2:error] [pid 16093:tid 16274] [client 194.5.53.206:51363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/core.php"] [unique_id "al4aypuybMv3z_zMVBSibwAAAcE"]
[Mon Jul 20 06:55:38.586146 2026] [security2:error] [pid 15216:tid 15413] [client 57.141.18.22:54400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ayNtIy0gkFcVddGZtbAABTUw"]
[Mon Jul 20 06:55:38.885082 2026] [security2:error] [pid 16093:tid 16241] [client 194.5.53.222:26401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/robots.php"] [unique_id "al4aypuybMv3z_zMVBSiewAAAaA"]
[Mon Jul 20 06:55:38.896195 2026] [security2:error] [pid 16093:tid 16215] [remote 188.166.241.141:41298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4aypuybMv3z_zMVBSifAACAXg"]
[Mon Jul 20 06:55:39.125957 2026] [security2:error] [pid 16093:tid 16289] [client 57.141.18.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4aypuybMv3z_zMVBSifgAAAdA"]
[Mon Jul 20 06:55:39.238518 2026] [security2:error] [pid 15216:tid 15374] [client 194.5.53.217:32349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/inputs.php"] [unique_id "al4ay9tIy0gkFcVddGZtzAAAASY"]
[Mon Jul 20 06:55:39.276253 2026] [security2:error] [pid 16093:tid 16212] [remote 188.166.241.141:41298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ay5uybMv3z_zMVBSigQAB5HU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:55:39.509906 2026] [security2:error] [pid 15216:tid 15361] [client 77.110.127.138:59656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 209 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4ay9tIy0gkFcVddGZt1QAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:39.906955 2026] [security2:error] [pid 15216:tid 15411] [client 187.108.85.186:54490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ay9tIy0gkFcVddGZt5gAAAUs"]
[Mon Jul 20 06:55:39.907068 2026] [security2:error] [pid 15216:tid 15411] [client 187.108.85.186:54490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ay9tIy0gkFcVddGZt5gAAAUs"]
[Mon Jul 20 06:55:40.220184 2026] [security2:error] [pid 15216:tid 15233] [remote 45.148.121.173:48458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.121.148.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4azNtIy0gkFcVddGZt9wABGBA"]
[Mon Jul 20 06:55:40.278850 2026] [security2:error] [pid 16093:tid 16263] [client 197.186.66.42:56649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4azJuybMv3z_zMVBSisAAAAbY"]
[Mon Jul 20 06:55:40.279468 2026] [security2:error] [pid 16093:tid 16263] [client 197.186.66.42:56649] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4azJuybMv3z_zMVBSisAAAAbY"]
[Mon Jul 20 06:55:40.397901 2026] [security2:error] [pid 15216:tid 15262] [remote 45.148.121.173:48458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.121.148.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4azNtIy0gkFcVddGZt_gABWC0"], referer: https://michiganhomecaregroup.com/wp-login.php
[Mon Jul 20 06:55:40.584054 2026] [security2:error] [pid 15216:tid 15414] [client 194.5.53.235:34331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/mini.php"] [unique_id "al4azNtIy0gkFcVddGZuBQAAAU4"]
[Mon Jul 20 06:55:40.752688 2026] [security2:error] [pid 15216:tid 15418] [client 77.110.127.138:59666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4azNtIy0gkFcVddGZuCQAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:40.810254 2026] [security2:error] [pid 16093:tid 16277] [client 103.125.179.95:50657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4azJuybMv3z_zMVBSiwAAAAcQ"]
[Mon Jul 20 06:55:40.810390 2026] [security2:error] [pid 16093:tid 16277] [client 103.125.179.95:50657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4azJuybMv3z_zMVBSiwAAAAcQ"]
[Mon Jul 20 06:55:40.891207 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.195:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/goods.php"] [unique_id "al4azJuybMv3z_zMVBSixQAAAZY"]
[Mon Jul 20 06:55:41.219379 2026] [security2:error] [pid 16093:tid 16287] [client 103.144.65.217:59759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4azZuybMv3z_zMVBSi4gAAAc4"]
[Mon Jul 20 06:55:41.219473 2026] [security2:error] [pid 16093:tid 16287] [client 103.144.65.217:59759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4azZuybMv3z_zMVBSi4gAAAc4"]
[Mon Jul 20 06:55:41.307024 2026] [security2:error] [pid 16093:tid 16340] [client 194.5.53.241:40691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/file5.php"] [unique_id "al4azZuybMv3z_zMVBSi5QAAAgM"]
[Mon Jul 20 06:55:41.584311 2026] [security2:error] [pid 15216:tid 15378] [client 14.251.3.155:54791] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4azdtIy0gkFcVddGZuJQAAASo"]
[Mon Jul 20 06:55:41.589374 2026] [security2:error] [pid 16093:tid 16326] [client 104.207.50.0:56005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4azZuybMv3z_zMVBSjAAAAAfU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:41.683547 2026] [security2:error] [pid 16093:tid 16112] [remote 188.166.241.141:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4azZuybMv3z_zMVBSjAQACARE"]
[Mon Jul 20 06:55:41.762302 2026] [security2:error] [pid 16093:tid 16235] [client 104.234.53.62:59543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4azZuybMv3z_zMVBSjAwAAAZo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:41.838149 2026] [security2:error] [pid 16093:tid 16262] [client 117.222.139.248:61698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4azZuybMv3z_zMVBSjBAAAAbU"]
[Mon Jul 20 06:55:41.838281 2026] [security2:error] [pid 16093:tid 16262] [client 117.222.139.248:61698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4azZuybMv3z_zMVBSjBAAAAbU"]
[Mon Jul 20 06:55:42.102254 2026] [security2:error] [pid 15216:tid 15413] [client 194.5.53.211:49287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/ahax.php"] [unique_id "al4azttIy0gkFcVddGZuOAAAAU0"]
[Mon Jul 20 06:55:42.121561 2026] [security2:error] [pid 16093:tid 16114] [remote 188.166.241.141:35528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4azpuybMv3z_zMVBSjFQABuhM"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 06:55:42.141916 2026] [security2:error] [pid 16093:tid 16247] [client 104.207.53.107:16911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4azpuybMv3z_zMVBSjFgAAAaY"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:42.180402 2026] [security2:error] [pid 16093:tid 16301] [client 77.110.127.138:59674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4azpuybMv3z_zMVBSjFwAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:42.180580 2026] [security2:error] [pid 16093:tid 16301] [client 77.110.127.138:59674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4azpuybMv3z_zMVBSjFwAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:42.453896 2026] [security2:error] [pid 16093:tid 16287] [client 43.205.139.3:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4azpuybMv3z_zMVBSjGgAAAc4"]
[Mon Jul 20 06:55:42.454030 2026] [security2:error] [pid 16093:tid 16287] [client 43.205.139.3:61064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4azpuybMv3z_zMVBSjGgAAAc4"]
[Mon Jul 20 06:55:42.495281 2026] [security2:error] [pid 16093:tid 16271] [client 77.110.127.138:59677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4azpuybMv3z_zMVBSjHQAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:42.495394 2026] [security2:error] [pid 16093:tid 16271] [client 77.110.127.138:59677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4azpuybMv3z_zMVBSjHQAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:42.722310 2026] [security2:error] [pid 15216:tid 15393] [client 104.207.52.19:35301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4azttIy0gkFcVddGZuTAAAATk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:42.757151 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4azttIy0gkFcVddGZuUQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:42.757244 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:59678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4azttIy0gkFcVddGZuUQAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:42.915238 2026] [security2:error] [pid 16093:tid 16276] [client 57.141.18.68:23574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4azZuybMv3z_zMVBSi1AABwwY"]
[Mon Jul 20 06:55:43.144997 2026] [security2:error] [pid 16093:tid 16254] [client 77.110.127.138:59681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4az5uybMv3z_zMVBSjOgAAAa0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:43.145102 2026] [security2:error] [pid 16093:tid 16254] [client 77.110.127.138:59681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4az5uybMv3z_zMVBSjOgAAAa0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:43.261916 2026] [security2:error] [pid 16093:tid 16324] [client 194.5.53.230:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/f35.php"] [unique_id "al4az5uybMv3z_zMVBSjPgAAAfM"]
[Mon Jul 20 06:55:43.279301 2026] [security2:error] [pid 15216:tid 15396] [client 45.3.42.122:45121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4az9tIy0gkFcVddGZuawAAATw"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:43.413443 2026] [security2:error] [pid 16093:tid 16285] [client 117.247.108.24:17050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4az5uybMv3z_zMVBSjSAAAAcw"]
[Mon Jul 20 06:55:43.413561 2026] [security2:error] [pid 16093:tid 16285] [client 117.247.108.24:17050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4az5uybMv3z_zMVBSjSAAAAcw"]
[Mon Jul 20 06:55:43.490341 2026] [security2:error] [pid 16093:tid 16328] [client 77.110.127.138:59683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4az5uybMv3z_zMVBSjTgAAAfc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:43.490439 2026] [security2:error] [pid 16093:tid 16328] [client 77.110.127.138:59683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4az5uybMv3z_zMVBSjTgAAAfc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:43.663521 2026] [security2:error] [pid 16093:tid 16347] [client 194.5.53.250:30561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/simple.php"] [unique_id "al4az5uybMv3z_zMVBSjVgAAAgo"]
[Mon Jul 20 06:55:43.831574 2026] [security2:error] [pid 15216:tid 15373] [client 77.110.127.138:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4az9tIy0gkFcVddGZufAAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:43.831677 2026] [security2:error] [pid 15216:tid 15373] [client 77.110.127.138:59686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4az9tIy0gkFcVddGZufAAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:43.856605 2026] [security2:error] [pid 16093:tid 16226] [client 65.111.22.120:29021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4az5uybMv3z_zMVBSjXgAAAZE"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:44.067470 2026] [security2:error] [pid 15216:tid 15376] [client 77.110.127.138:59654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a0NtIy0gkFcVddGZuhwAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:44.067607 2026] [security2:error] [pid 15216:tid 15376] [client 77.110.127.138:59654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a0NtIy0gkFcVddGZuhwAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:44.068731 2026] [security2:error] [pid 15216:tid 15424] [client 77.110.127.138:59687] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a0NtIy0gkFcVddGZuhQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:44.334643 2026] [security2:error] [pid 16093:tid 16282] [client 183.82.98.154:62765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a0JuybMv3z_zMVBSjggAAAck"]
[Mon Jul 20 06:55:44.334763 2026] [security2:error] [pid 16093:tid 16282] [client 183.82.98.154:62765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a0JuybMv3z_zMVBSjggAAAck"]
[Mon Jul 20 06:55:44.417111 2026] [security2:error] [pid 16093:tid 16317] [client 194.5.53.223:53673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/amax.php"] [unique_id "al4a0JuybMv3z_zMVBSjhQAAAew"]
[Mon Jul 20 06:55:44.424290 2026] [security2:error] [pid 16093:tid 16328] [client 45.3.42.19:24927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a0JuybMv3z_zMVBSjhAAAAfc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:44.618604 2026] [security2:error] [pid 15216:tid 15374] [client 77.110.127.138:59659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a0NtIy0gkFcVddGZurAAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:44.755711 2026] [security2:error] [pid 16093:tid 16233] [client 217.142.18.172:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a0JuybMv3z_zMVBSjmwAAAZg"]
[Mon Jul 20 06:55:44.770052 2026] [security2:error] [pid 16093:tid 16233] [client 217.142.18.172:53148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a0JuybMv3z_zMVBSjmwAAAZg"]
[Mon Jul 20 06:55:44.856860 2026] [security2:error] [pid 16093:tid 16291] [client 57.141.18.103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4a0JuybMv3z_zMVBSjmAAAAdI"]
[Mon Jul 20 06:55:44.908822 2026] [security2:error] [pid 16093:tid 16268] [client 194.5.53.249:58419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/update/f35.php"] [unique_id "al4a0JuybMv3z_zMVBSjngAAAbs"]
[Mon Jul 20 06:55:44.981539 2026] [security2:error] [pid 15216:tid 15357] [client 104.207.53.148:55881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a0NtIy0gkFcVddGZuwgAAARU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:45.162275 2026] [security2:error] [pid 15216:tid 15379] [client 50.116.65.227:10088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4a0dtIy0gkFcVddGZuzQAAASs"]
[Mon Jul 20 06:55:45.175500 2026] [security2:error] [pid 16093:tid 16282] [client 50.116.65.227:28896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4a0ZuybMv3z_zMVBSjqgAAAck"]
[Mon Jul 20 06:55:45.270360 2026] [security2:error] [pid 16093:tid 16224] [client 152.58.191.29:52695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a0ZuybMv3z_zMVBSj5AAAAY8"]
[Mon Jul 20 06:55:45.270461 2026] [security2:error] [pid 16093:tid 16224] [client 152.58.191.29:52695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a0ZuybMv3z_zMVBSj5AAAAY8"]
[Mon Jul 20 06:55:45.751223 2026] [security2:error] [pid 15216:tid 15389] [client 122.183.32.225:27045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a0dtIy0gkFcVddGZu8wAAATU"]
[Mon Jul 20 06:55:45.751322 2026] [security2:error] [pid 15216:tid 15389] [client 122.183.32.225:27045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a0dtIy0gkFcVddGZu8wAAATU"]
[Mon Jul 20 06:55:46.140069 2026] [security2:error] [pid 16093:tid 16287] [client 194.5.53.201:38073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/hello.php"] [unique_id "al4a0puybMv3z_zMVBSkJgAAAc4"]
[Mon Jul 20 06:55:46.469954 2026] [security2:error] [pid 16093:tid 16264] [client 47.128.117.91:63228] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.drawingthedog.com"] [uri "/robots.txt"] [unique_id "al4a0puybMv3z_zMVBSkPgAAAbc"]
[Mon Jul 20 06:55:46.739916 2026] [security2:error] [pid 16093:tid 16335] [client 103.238.106.162:60778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a0puybMv3z_zMVBSkRQAAAf4"]
[Mon Jul 20 06:55:46.739999 2026] [security2:error] [pid 16093:tid 16335] [client 103.238.106.162:60778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a0puybMv3z_zMVBSkRQAAAf4"]
[Mon Jul 20 06:55:46.977397 2026] [security2:error] [pid 16093:tid 16095] [remote 72.167.132.114:41762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4a0puybMv3z_zMVBSkTwABuAA"]
[Mon Jul 20 06:55:47.044904 2026] [security2:error] [pid 16093:tid 16341] [client 98.159.234.160:59901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4a05uybMv3z_zMVBSkWAAAAgQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:55:47.118849 2026] [security2:error] [pid 16093:tid 16316] [client 14.225.17.146:62732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4a05uybMv3z_zMVBSkWQAAAes"], referer: http://grndl.com/2022
[Mon Jul 20 06:55:47.225172 2026] [security2:error] [pid 16093:tid 16111] [remote 72.167.132.114:41762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4a05uybMv3z_zMVBSkYwAB_BA"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:55:47.265272 2026] [security2:error] [pid 16093:tid 16344] [client 74.7.227.179:54796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4a05uybMv3z_zMVBSkXAACBxE"], referer: https://tejasenvironmental.com/p=110484
[Mon Jul 20 06:55:47.325645 2026] [security2:error] [pid 16093:tid 16293] [client 104.234.53.92:62279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4a05uybMv3z_zMVBSkawAAAdQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:47.756626 2026] [security2:error] [pid 16093:tid 16246] [client 50.116.65.227:28942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4a05uybMv3z_zMVBSkfQAAAaU"]
[Mon Jul 20 06:55:47.769234 2026] [security2:error] [pid 16093:tid 16281] [client 50.116.65.227:28946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4a05uybMv3z_zMVBSkfwAAAcg"]
[Mon Jul 20 06:55:47.817997 2026] [security2:error] [pid 16093:tid 16324] [client 57.141.18.37:40974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a0puybMv3z_zMVBSkJAAB830"]
[Mon Jul 20 06:55:47.869920 2026] [security2:error] [pid 16093:tid 16311] [client 192.140.149.97:45093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4a05uybMv3z_zMVBSkgwAAAeY"]
[Mon Jul 20 06:55:47.870025 2026] [security2:error] [pid 16093:tid 16311] [client 192.140.149.97:45093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4a05uybMv3z_zMVBSkgwAAAeY"]
[Mon Jul 20 06:55:47.875932 2026] [security2:error] [pid 15216:tid 15450] [client 77.110.127.138:59696] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a09tIy0gkFcVddGZvQgAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:47.888741 2026] [security2:error] [pid 15216:tid 15369] [client 194.5.53.219:30375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "al4a09tIy0gkFcVddGZvQQAAASE"]
[Mon Jul 20 06:55:48.029899 2026] [security2:error] [pid 15216:tid 15398] [client 77.110.127.138:59697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a1NtIy0gkFcVddGZvTwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:48.029997 2026] [security2:error] [pid 15216:tid 15398] [client 77.110.127.138:59697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a1NtIy0gkFcVddGZvTwAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:48.094539 2026] [lsapi:warn] [pid 16093:tid 16104] [remote 34.182.199.186:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: http://ali-alghanim.com
[Mon Jul 20 06:55:48.390375 2026] [security2:error] [pid 16093:tid 16232] [client 194.5.53.240:59825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/themes/zMousse/otuz1.php"] [unique_id "al4a1JuybMv3z_zMVBSkowAAAZc"]
[Mon Jul 20 06:55:48.467574 2026] [security2:error] [pid 16093:tid 16293] [client 14.225.17.146:55814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4a1JuybMv3z_zMVBSkogAAAdQ"], referer: http://nextlvlmarketingco.com/2022
[Mon Jul 20 06:55:48.576873 2026] [security2:error] [pid 16093:tid 16349] [client 104.207.51.64:26723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a1JuybMv3z_zMVBSkqgAAAgw"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:48.755994 2026] [lsapi:warn] [pid 16093:tid 16109] [remote 34.182.199.186:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://ali-alghanim-com.aasgroup.online/
[Mon Jul 20 06:55:48.786334 2026] [security2:error] [pid 16093:tid 16309] [client 63.176.132.15:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4a05uybMv3z_zMVBSkiAAAAeQ"]
[Mon Jul 20 06:55:48.806504 2026] [security2:error] [pid 16093:tid 16269] [client 2a03:2880:7ff:41:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4a1JuybMv3z_zMVBSkngABvBY"]
[Mon Jul 20 06:55:48.807204 2026] [security2:error] [pid 16093:tid 16248] [client 63.176.132.15:34546] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-beans-habichuelas-guisadas/"] [unique_id "al4a05uybMv3z_zMVBSkhQAAAac"]
[Mon Jul 20 06:55:49.154573 2026] [security2:error] [pid 16093:tid 16229] [client 110.249.201.233:31158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/robots.txt"] [unique_id "al4a1ZuybMv3z_zMVBSkxAAAAZQ"]
[Mon Jul 20 06:55:49.437089 2026] [security2:error] [pid 15216:tid 15460] [client 104.234.53.49:31553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4a1dtIy0gkFcVddGZvlwAAAXw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:49.501238 2026] [security2:error] [pid 15216:tid 15369] [client 194.5.53.240:37605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/edit-wolf.php"] [unique_id "al4a1dtIy0gkFcVddGZvmgAAASE"]
[Mon Jul 20 06:55:50.030866 2026] [proxy:error] [pid 16093:tid 16288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:55:50.030911 2026] [proxy_http:error] [pid 16093:tid 16288] [client 107.172.180.205:33766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:55:50.031537 2026] [proxy:error] [pid 16093:tid 16288] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:55:50.031565 2026] [proxy_http:error] [pid 16093:tid 16288] [client 107.172.180.205:33766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:55:50.165777 2026] [security2:error] [pid 16093:tid 16247] [client 194.5.53.223:52625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "al4a1puybMv3z_zMVBSk6AAAAaY"]
[Mon Jul 20 06:55:50.412669 2026] [security2:error] [pid 16093:tid 16328] [client 187.108.85.186:55031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a1puybMv3z_zMVBSk9QAAAfc"]
[Mon Jul 20 06:55:50.412801 2026] [security2:error] [pid 16093:tid 16328] [client 187.108.85.186:55031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a1puybMv3z_zMVBSk9QAAAfc"]
[Mon Jul 20 06:55:50.692214 2026] [security2:error] [pid 15216:tid 15404] [client 194.5.53.54:53733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "al4a1ttIy0gkFcVddGZvxwAAAUQ"]
[Mon Jul 20 06:55:51.100082 2026] [security2:error] [pid 16093:tid 16142] [remote 98.156.100.191:42716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4a15uybMv3z_zMVBSlBwABpC8"]
[Mon Jul 20 06:55:51.125736 2026] [security2:error] [pid 15216:tid 15330] [remote 72.167.132.114:41772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a19tIy0gkFcVddGZv3gABeHE"]
[Mon Jul 20 06:55:51.159395 2026] [security2:error] [pid 15216:tid 15453] [client 82.102.18.126:48394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4a19tIy0gkFcVddGZv4AAAAXU"]
[Mon Jul 20 06:55:51.258956 2026] [security2:error] [pid 16093:tid 16285] [client 158.173.89.95:64371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4a15uybMv3z_zMVBSlCgAAAcw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:55:51.324872 2026] [security2:error] [pid 16093:tid 16341] [client 50.116.65.227:39956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4a15uybMv3z_zMVBSlDAAAAgQ"]
[Mon Jul 20 06:55:51.334460 2026] [security2:error] [pid 16093:tid 16266] [client 103.125.179.95:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a15uybMv3z_zMVBSlDgAAAbk"]
[Mon Jul 20 06:55:51.334583 2026] [security2:error] [pid 16093:tid 16266] [client 103.125.179.95:51151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a15uybMv3z_zMVBSlDgAAAbk"]
[Mon Jul 20 06:55:51.335915 2026] [security2:error] [pid 16093:tid 16263] [client 50.116.65.227:58046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-8-Feature-Image.jpg"] [unique_id "al4a15uybMv3z_zMVBSlDQAAAaw"]
[Mon Jul 20 06:55:51.373440 2026] [security2:error] [pid 15216:tid 15332] [remote 72.167.132.114:41772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a19tIy0gkFcVddGZv6QABW3M"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:55:51.599380 2026] [security2:error] [pid 16093:tid 16319] [client 104.234.53.70:42725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4a15uybMv3z_zMVBSlGAAAAe4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:51.706970 2026] [security2:error] [pid 16093:tid 16261] [client 194.5.53.236:35251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/upload.php"] [unique_id "al4a15uybMv3z_zMVBSlHAAAAbQ"]
[Mon Jul 20 06:55:51.783673 2026] [security2:error] [pid 16093:tid 16342] [client 103.144.65.217:60149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a15uybMv3z_zMVBSlHwAAAgU"]
[Mon Jul 20 06:55:51.783746 2026] [security2:error] [pid 16093:tid 16342] [client 103.144.65.217:60149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a15uybMv3z_zMVBSlHwAAAgU"]
[Mon Jul 20 06:55:51.849936 2026] [security2:error] [pid 15216:tid 15433] [client 82.102.18.126:48406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keyq8.com"] [uri "/xmlrpc.php"] [unique_id "al4a19tIy0gkFcVddGZv_AAAAWE"]
[Mon Jul 20 06:55:52.073591 2026] [security2:error] [pid 16093:tid 16273] [client 194.5.53.239:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "al4a2JuybMv3z_zMVBSlLwAAAcA"]
[Mon Jul 20 06:55:52.190507 2026] [security2:error] [pid 16093:tid 16290] [client 45.157.112.60:28227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4a2JuybMv3z_zMVBSlNQAAAdE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:55:52.299884 2026] [security2:error] [pid 15216:tid 15352] [client 57.141.18.48:29388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a1ttIy0gkFcVddGZvvwABEFk"]
[Mon Jul 20 06:55:52.381594 2026] [security2:error] [pid 16093:tid 16251] [client 117.222.139.248:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a2JuybMv3z_zMVBSlOQAAAao"]
[Mon Jul 20 06:55:52.381714 2026] [security2:error] [pid 16093:tid 16251] [client 117.222.139.248:62189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a2JuybMv3z_zMVBSlOQAAAao"]
[Mon Jul 20 06:55:52.438318 2026] [security2:error] [pid 16093:tid 16312] [client 77.110.127.138:59719] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 712 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a2JuybMv3z_zMVBSlOwAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:52.465723 2026] [security2:error] [pid 15216:tid 15364] [client 194.5.53.243:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al4a2NtIy0gkFcVddGZwEwAAARw"]
[Mon Jul 20 06:55:52.828916 2026] [security2:error] [pid 16093:tid 16257] [client 194.5.53.207:51629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "al4a2JuybMv3z_zMVBSlSwAAAbA"]
[Mon Jul 20 06:55:52.850775 2026] [security2:error] [pid 15216:tid 15424] [client 82.102.18.126:48408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4a2NtIy0gkFcVddGZwKgAAAVg"]
[Mon Jul 20 06:55:52.970275 2026] [security2:error] [pid 16093:tid 16322] [client 104.207.37.169:27819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4a2JuybMv3z_zMVBSlUQAAAfE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:55:53.154551 2026] [security2:error] [pid 16093:tid 16248] [client 197.186.66.42:57191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a2ZuybMv3z_zMVBSlXQAAAac"]
[Mon Jul 20 06:55:53.154695 2026] [security2:error] [pid 16093:tid 16248] [client 197.186.66.42:57191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a2ZuybMv3z_zMVBSlXQAAAac"]
[Mon Jul 20 06:55:53.364182 2026] [security2:error] [pid 15216:tid 15387] [client 77.110.127.138:59729] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a2dtIy0gkFcVddGZwPgAAATM"]
[Mon Jul 20 06:55:53.409610 2026] [security2:error] [pid 15216:tid 15222] [remote 162.19.86.63:33535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4a2dtIy0gkFcVddGZwQAABXQU"]
[Mon Jul 20 06:55:53.475449 2026] [security2:error] [pid 15216:tid 15425] [client 82.102.18.126:55596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4a2dtIy0gkFcVddGZwRAAAAVk"]
[Mon Jul 20 06:55:53.610850 2026] [security2:error] [pid 16093:tid 16149] [remote 8.217.108.67:14164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a2ZuybMv3z_zMVBSlaAAB-zY"]
[Mon Jul 20 06:55:53.618683 2026] [security2:error] [pid 15216:tid 15266] [remote 162.19.86.63:33535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4a2dtIy0gkFcVddGZwTQABQDE"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 06:55:53.697198 2026] [security2:error] [pid 16093:tid 16251] [client 77.110.127.138:59732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a2ZuybMv3z_zMVBSlbgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:53.697287 2026] [security2:error] [pid 16093:tid 16251] [client 77.110.127.138:59732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a2ZuybMv3z_zMVBSlbgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:53.759176 2026] [security2:error] [pid 16093:tid 16232] [client 45.3.38.233:38141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4a2ZuybMv3z_zMVBSlcAAAAZc"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:55:53.853402 2026] [security2:error] [pid 15216:tid 15447] [client 194.5.53.245:63473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "al4a2dtIy0gkFcVddGZwVQAAAW8"]
[Mon Jul 20 06:55:53.993746 2026] [security2:error] [pid 16093:tid 16246] [client 57.141.18.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4a2JuybMv3z_zMVBSlQAAAAaU"]
[Mon Jul 20 06:55:54.030324 2026] [security2:error] [pid 16093:tid 16167] [remote 8.217.108.67:14164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a2puybMv3z_zMVBSlfgACDUg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:55:54.099297 2026] [security2:error] [pid 16093:tid 16291] [client 82.102.18.126:55598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4a2puybMv3z_zMVBSliAAAAdI"]
[Mon Jul 20 06:55:54.142320 2026] [security2:error] [pid 16093:tid 16347] [client 57.141.18.48:29404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a2JuybMv3z_zMVBSlNAACCjM"]
[Mon Jul 20 06:55:54.167758 2026] [security2:error] [pid 16093:tid 16321] [client 117.247.108.24:17818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a2puybMv3z_zMVBSligAAAfA"]
[Mon Jul 20 06:55:54.167873 2026] [security2:error] [pid 16093:tid 16321] [client 117.247.108.24:17818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a2puybMv3z_zMVBSligAAAfA"]
[Mon Jul 20 06:55:54.183495 2026] [security2:error] [pid 16093:tid 16168] [remote 98.156.100.191:42716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4a2puybMv3z_zMVBSliwAB70k"], referer: https://musichaven.info/wp-login.php
[Mon Jul 20 06:55:54.725867 2026] [security2:error] [pid 16093:tid 16335] [client 82.102.18.126:55602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4a2puybMv3z_zMVBSlnAAAAf4"]
[Mon Jul 20 06:55:55.010425 2026] [security2:error] [pid 16093:tid 16274] [client 14.225.17.146:57801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4a2puybMv3z_zMVBSloAAAAcE"], referer: http://whiteoutcb.com/2022
[Mon Jul 20 06:55:55.068993 2026] [security2:error] [pid 16093:tid 16314] [client 183.82.98.154:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a25uybMv3z_zMVBSlpgAAAek"]
[Mon Jul 20 06:55:55.069097 2026] [security2:error] [pid 16093:tid 16314] [client 183.82.98.154:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a25uybMv3z_zMVBSlpgAAAek"]
[Mon Jul 20 06:55:55.267361 2026] [security2:error] [pid 16093:tid 16263] [client 217.142.18.172:12763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a25uybMv3z_zMVBSlqwAAAbY"]
[Mon Jul 20 06:55:55.274602 2026] [security2:error] [pid 16093:tid 16263] [client 217.142.18.172:12763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a25uybMv3z_zMVBSlqwAAAbY"]
[Mon Jul 20 06:55:55.305834 2026] [security2:error] [pid 16093:tid 16175] [remote 114.119.137.28:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.origine.nz"] [uri "/cocktail-kitchen/&sa=U"] [unique_id "al4a25uybMv3z_zMVBSlrQABolA"], referer: https://www.origine.nz/cocktail-kitchen/&sa=U
[Mon Jul 20 06:55:55.329667 2026] [security2:error] [pid 16093:tid 16174] [remote 5.161.225.162:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a25uybMv3z_zMVBSlrwACBE8"]
[Mon Jul 20 06:55:55.392902 2026] [security2:error] [pid 16093:tid 16311] [client 82.102.18.126:55606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4a25uybMv3z_zMVBSltAAAAeY"]
[Mon Jul 20 06:55:55.537217 2026] [security2:error] [pid 16093:tid 16191] [remote 5.161.225.162:52314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a25uybMv3z_zMVBSlwAABt2A"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:55:55.554116 2026] [security2:error] [pid 15216:tid 15365] [client 104.234.53.79:59163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4a29tIy0gkFcVddGZwhgAAAR0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:55.584135 2026] [security2:error] [pid 15216:tid 15425] [client 50.116.65.227:39960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4a29tIy0gkFcVddGZwjwAAAVk"]
[Mon Jul 20 06:55:55.597517 2026] [security2:error] [pid 15216:tid 15350] [client 50.116.65.227:58096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4a29tIy0gkFcVddGZwkAAAAR4"]
[Mon Jul 20 06:55:55.778577 2026] [proxy:error] [pid 15216:tid 15451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:55:55.778611 2026] [proxy_http:error] [pid 15216:tid 15451] [client 107.172.180.205:33784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:55:55.779210 2026] [proxy:error] [pid 15216:tid 15451] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:55:55.779238 2026] [proxy_http:error] [pid 15216:tid 15451] [client 107.172.180.205:33784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:55:56.009561 2026] [security2:error] [pid 16093:tid 16314] [client 194.5.53.247:37973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al4a25uybMv3z_zMVBSl2wAAAek"]
[Mon Jul 20 06:55:56.031476 2026] [security2:error] [pid 16093:tid 16290] [client 82.102.18.126:55608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4a3JuybMv3z_zMVBSl4AAAAdE"]
[Mon Jul 20 06:55:56.048113 2026] [security2:error] [pid 15216:tid 15431] [client 77.110.127.138:59746] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 935 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a3NtIy0gkFcVddGZwoAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:56.078906 2026] [security2:error] [pid 16093:tid 16266] [client 152.58.191.29:9675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a3JuybMv3z_zMVBSl4QAAAbk"]
[Mon Jul 20 06:55:56.083438 2026] [security2:error] [pid 16093:tid 16266] [client 152.58.191.29:9675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a3JuybMv3z_zMVBSl4QAAAbk"]
[Mon Jul 20 06:55:56.246968 2026] [security2:error] [pid 16093:tid 16242] [client 14.225.17.146:57708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4a3JuybMv3z_zMVBSl5gAAAaE"], referer: http://christiancountytrumpet.com/2022
[Mon Jul 20 06:55:56.636849 2026] [security2:error] [pid 16093:tid 16246] [client 14.225.17.146:64571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4a3JuybMv3z_zMVBSl9wAAAaU"], referer: http://floorsourcestock.com/2022
[Mon Jul 20 06:55:56.657800 2026] [security2:error] [pid 16093:tid 16264] [client 82.102.18.126:55624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4a3JuybMv3z_zMVBSl_gAAAbc"]
[Mon Jul 20 06:55:56.843865 2026] [security2:error] [pid 15216:tid 15463] [client 104.234.53.79:59163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4a3NtIy0gkFcVddGZwugAAAX8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:55:57.058124 2026] [security2:error] [pid 16093:tid 16275] [client 14.224.227.113:54792] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4a3ZuybMv3z_zMVBSmEQAAAcI"]
[Mon Jul 20 06:55:57.187388 2026] [security2:error] [pid 16093:tid 16176] [remote 160.187.68.132:47828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a3ZuybMv3z_zMVBSmGAAB5lE"]
[Mon Jul 20 06:55:57.261398 2026] [security2:error] [pid 16093:tid 16256] [client 103.238.106.162:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a3ZuybMv3z_zMVBSmIAAAAa8"]
[Mon Jul 20 06:55:57.261532 2026] [security2:error] [pid 16093:tid 16256] [client 103.238.106.162:63914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a3ZuybMv3z_zMVBSmIAAAAa8"]
[Mon Jul 20 06:55:57.284277 2026] [security2:error] [pid 16093:tid 16244] [client 82.102.18.126:55634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4a3ZuybMv3z_zMVBSmJAAAAaM"]
[Mon Jul 20 06:55:57.431013 2026] [security2:error] [pid 16093:tid 16226] [client 14.225.17.146:64591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4a25uybMv3z_zMVBSltgAAAZE"], referer: http://mollycahill.com/2022
[Mon Jul 20 06:55:57.453705 2026] [security2:error] [pid 15216:tid 15422] [client 57.141.18.101:58566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a3NtIy0gkFcVddGZwoQABVi4"]
[Mon Jul 20 06:55:57.899441 2026] [security2:error] [pid 16093:tid 16331] [client 82.102.18.126:55642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4a3ZuybMv3z_zMVBSmOQAAAfo"]
[Mon Jul 20 06:55:58.024969 2026] [security2:error] [pid 15216:tid 15371] [client 194.5.53.47:38667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "al4a3ttIy0gkFcVddGZw6AAAASM"]
[Mon Jul 20 06:55:58.175775 2026] [security2:error] [pid 16093:tid 16232] [client 104.207.53.227:38437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a3puybMv3z_zMVBSmPgAAAZc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:58.230992 2026] [security2:error] [pid 16093:tid 16312] [client 77.110.127.138:59757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a3puybMv3z_zMVBSmQQAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:58.231117 2026] [security2:error] [pid 16093:tid 16312] [client 77.110.127.138:59757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a3puybMv3z_zMVBSmQQAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 06:55:58.309229 2026] [security2:error] [pid 15216:tid 15291] [remote 188.40.28.4:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4a3ttIy0gkFcVddGZw-wABR0o"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:55:58.403720 2026] [security2:error] [pid 16093:tid 16235] [client 14.225.17.146:57272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4a3puybMv3z_zMVBSmQwAAAZo"], referer: http://northbrookcpa.ca/2022
[Mon Jul 20 06:55:58.410959 2026] [security2:error] [pid 15216:tid 15373] [client 66.249.74.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4a3ttIy0gkFcVddGZxAQAAASU"]
[Mon Jul 20 06:55:58.462388 2026] [security2:error] [pid 15216:tid 15266] [remote 124.55.178.99:40372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4a3ttIy0gkFcVddGZxGAABSDE"]
[Mon Jul 20 06:55:58.529232 2026] [security2:error] [pid 15216:tid 15243] [remote 188.40.28.4:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4a3ttIy0gkFcVddGZxKgABcRo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:55:58.539576 2026] [security2:error] [pid 15216:tid 15386] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4a3ttIy0gkFcVddGZw_AABMls"], referer: http://assasalnazaha.com/2022
[Mon Jul 20 06:55:58.541220 2026] [security2:error] [pid 15216:tid 15415] [client 192.140.149.97:46152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4a3ttIy0gkFcVddGZxLAAAAU8"]
[Mon Jul 20 06:55:58.541323 2026] [security2:error] [pid 15216:tid 15415] [client 192.140.149.97:46152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4a3ttIy0gkFcVddGZxLAAAAU8"]
[Mon Jul 20 06:55:58.563638 2026] [security2:error] [pid 15216:tid 15460] [client 82.102.18.126:55656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4a3ttIy0gkFcVddGZxLwAAAXw"]
[Mon Jul 20 06:55:58.760963 2026] [security2:error] [pid 15216:tid 15349] [client 65.111.23.183:32419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a3ttIy0gkFcVddGZxUAAAAQ0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:58.787971 2026] [security2:error] [pid 16093:tid 16340] [client 14.225.17.146:57845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4a3JuybMv3z_zMVBSmCwAAAgM"], referer: http://areitoproducciones.com/2022
[Mon Jul 20 06:55:58.886390 2026] [security2:error] [pid 15216:tid 15301] [remote 124.55.178.99:40372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4a3ttIy0gkFcVddGZxXAABQFQ"], referer: https://sbinframx.com/wp-login.php
[Mon Jul 20 06:55:58.927384 2026] [security2:error] [pid 16093:tid 16258] [client 50.116.65.227:12486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4a3puybMv3z_zMVBSmWgAAAbE"]
[Mon Jul 20 06:55:58.937294 2026] [security2:error] [pid 16093:tid 16271] [client 50.116.65.227:12488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4a3puybMv3z_zMVBSmWwAAAb4"]
[Mon Jul 20 06:55:58.984613 2026] [security2:error] [pid 15216:tid 15396] [client 194.5.53.228:49953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "al4a3ttIy0gkFcVddGZxXgAAATw"]
[Mon Jul 20 06:55:59.160689 2026] [security2:error] [pid 16093:tid 16279] [client 57.141.18.102:49622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a3ZuybMv3z_zMVBSmOAABxj8"]
[Mon Jul 20 06:55:59.167788 2026] [security2:error] [pid 16093:tid 16140] [remote 160.187.68.132:47828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a35uybMv3z_zMVBSmYwABzi0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:55:59.189067 2026] [security2:error] [pid 16093:tid 16294] [client 82.102.18.126:55668] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4a35uybMv3z_zMVBSmZQAAAdU"]
[Mon Jul 20 06:55:59.376945 2026] [security2:error] [pid 16093:tid 16274] [client 65.111.22.39:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a35uybMv3z_zMVBSmagAAAcE"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:55:59.406918 2026] [security2:error] [pid 16093:tid 16265] [client 194.5.53.249:49481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "al4a35uybMv3z_zMVBSmbAAAAbg"]
[Mon Jul 20 06:55:59.610634 2026] [security2:error] [pid 16093:tid 16304] [client 14.225.17.146:64742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4a35uybMv3z_zMVBSmYgAAAd8"], referer: http://partnerselectricalllc.com/2022
[Mon Jul 20 06:55:59.670652 2026] [security2:error] [pid 16093:tid 16184] [remote 188.166.241.141:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4a35uybMv3z_zMVBSmfgABklk"]
[Mon Jul 20 06:55:59.671514 2026] [security2:error] [pid 16093:tid 16332] [client 14.225.17.146:62428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4a35uybMv3z_zMVBSmdwAAAfs"], referer: http://headachescarpaltunnelfibromyalgia.com/2022
[Mon Jul 20 06:55:59.823837 2026] [security2:error] [pid 15216:tid 15443] [client 82.102.18.126:55680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4a39tIy0gkFcVddGZxeAAAAWs"]
[Mon Jul 20 06:55:59.930486 2026] [security2:error] [pid 16093:tid 16348] [client 194.5.53.246:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "al4a35uybMv3z_zMVBSmhgAAAgs"]
[Mon Jul 20 06:55:59.948803 2026] [security2:error] [pid 16093:tid 16285] [client 104.207.52.68:38011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a35uybMv3z_zMVBSmhwAAAcw"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:00.037543 2026] [security2:error] [pid 16093:tid 16329] [client 104.234.53.70:41851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4a35uybMv3z_zMVBSmjAAAAfg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:00.089646 2026] [security2:error] [pid 16093:tid 16195] [remote 188.166.241.141:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4a4JuybMv3z_zMVBSmkwABt2Q"], referer: https://fineartsfactory.net/wp-login.php
[Mon Jul 20 06:56:00.438557 2026] [security2:error] [pid 15216:tid 15426] [client 82.102.18.126:55686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4a4NtIy0gkFcVddGZxlAAAAVo"]
[Mon Jul 20 06:56:00.450942 2026] [security2:error] [pid 16093:tid 16266] [client 77.110.127.138:59777] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 235 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a4JuybMv3z_zMVBSmmQAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:00.507203 2026] [security2:error] [pid 15216:tid 15462] [client 45.3.54.135:44871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a4NtIy0gkFcVddGZxlgAAAX4"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:00.577236 2026] [security2:error] [pid 16093:tid 16242] [client 194.5.53.204:20527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "al4a4JuybMv3z_zMVBSmnwAAAaE"]
[Mon Jul 20 06:56:00.640382 2026] [security2:error] [pid 16093:tid 16314] [client 14.225.17.146:57752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4a4JuybMv3z_zMVBSmmwAAAek"], referer: http://alaraycreative.com/2022
[Mon Jul 20 06:56:01.061192 2026] [security2:error] [pid 16093:tid 16304] [client 104.207.53.5:56123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a4ZuybMv3z_zMVBSmsQAAAd8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:01.099445 2026] [security2:error] [pid 15216:tid 15414] [client 82.102.18.126:55694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4a4dtIy0gkFcVddGZxqwAAAU4"]
[Mon Jul 20 06:56:01.138378 2026] [security2:error] [pid 16093:tid 16291] [client 187.108.85.186:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a4ZuybMv3z_zMVBSmugAAAdI"]
[Mon Jul 20 06:56:01.138463 2026] [security2:error] [pid 16093:tid 16291] [client 187.108.85.186:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a4ZuybMv3z_zMVBSmugAAAdI"]
[Mon Jul 20 06:56:01.332811 2026] [security2:error] [pid 16093:tid 16271] [client 194.5.53.226:62247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al4a4ZuybMv3z_zMVBSmvQAAAb4"]
[Mon Jul 20 06:56:01.340766 2026] [security2:error] [pid 16093:tid 16339] [client 114.119.131.123:37885] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4a4ZuybMv3z_zMVBSmwAAAAgI"], referer: https://newstral.com/en/article/en/1179763378/it-s-time-for-a-party
[Mon Jul 20 06:56:01.433244 2026] [security2:error] [pid 16093:tid 16272] [client 14.225.17.146:62192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4a4ZuybMv3z_zMVBSmwwAAAb8"], referer: http://intelligentengineeringsolutions.com/2022
[Mon Jul 20 06:56:01.717431 2026] [security2:error] [pid 16093:tid 16279] [client 82.102.18.126:55710] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4a4ZuybMv3z_zMVBSm2QAAAcY"]
[Mon Jul 20 06:56:01.790917 2026] [security2:error] [pid 15216:tid 15413] [client 194.5.53.228:46417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "al4a4dtIy0gkFcVddGZxvwAAAU0"]
[Mon Jul 20 06:56:02.183163 2026] [security2:error] [pid 16093:tid 16295] [client 194.5.53.223:42737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/classwithtostring.php"] [unique_id "al4a4puybMv3z_zMVBSm5QAAAdY"]
[Mon Jul 20 06:56:02.215677 2026] [security2:error] [pid 16093:tid 16312] [client 103.125.179.95:51659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a4puybMv3z_zMVBSm6AAAAec"]
[Mon Jul 20 06:56:02.215888 2026] [security2:error] [pid 16093:tid 16312] [client 103.125.179.95:51659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a4puybMv3z_zMVBSm6AAAAec"]
[Mon Jul 20 06:56:02.393388 2026] [security2:error] [pid 16093:tid 16326] [client 103.144.65.217:60543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a4puybMv3z_zMVBSm7QAAAfU"]
[Mon Jul 20 06:56:02.393531 2026] [security2:error] [pid 16093:tid 16326] [client 103.144.65.217:60543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a4puybMv3z_zMVBSm7QAAAfU"]
[Mon Jul 20 06:56:02.394325 2026] [security2:error] [pid 16093:tid 16338] [client 82.102.18.126:55726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "keyq8.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4a4puybMv3z_zMVBSm7gAAAgE"]
[Mon Jul 20 06:56:02.398271 2026] [security2:error] [pid 15216:tid 15246] [remote 188.40.28.4:44826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4a4ttIy0gkFcVddGZx0gABhR0"]
[Mon Jul 20 06:56:02.617334 2026] [security2:error] [pid 15216:tid 15236] [remote 188.40.28.4:44826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4a4ttIy0gkFcVddGZx3AABJhM"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:56:02.826404 2026] [security2:error] [pid 16093:tid 16286] [client 77.110.127.138:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a4puybMv3z_zMVBSm_gAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:02.826518 2026] [security2:error] [pid 16093:tid 16286] [client 77.110.127.138:59786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a4puybMv3z_zMVBSm_gAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:02.984591 2026] [security2:error] [pid 15216:tid 15353] [client 117.222.139.248:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a4ttIy0gkFcVddGZx5QAAARE"]
[Mon Jul 20 06:56:02.985400 2026] [security2:error] [pid 15216:tid 15353] [client 117.222.139.248:62683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a4ttIy0gkFcVddGZx5QAAARE"]
[Mon Jul 20 06:56:03.083667 2026] [security2:error] [pid 16093:tid 16343] [client 194.5.53.226:47915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/index/function.php"] [unique_id "al4a45uybMv3z_zMVBSnDQAAAgY"]
[Mon Jul 20 06:56:03.202285 2026] [security2:error] [pid 16093:tid 16314] [client 14.225.17.146:52067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4a45uybMv3z_zMVBSnDwAAAek"], referer: http://keywayconstructionclt.com/2022
[Mon Jul 20 06:56:03.222963 2026] [security2:error] [pid 16093:tid 16285] [client 14.225.17.146:52333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4a4puybMv3z_zMVBSm7AAAAcw"], referer: http://processorstudio.com/2022
[Mon Jul 20 06:56:03.495788 2026] [security2:error] [pid 15216:tid 15381] [client 162.62.213.165:57026] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4a49tIy0gkFcVddGZx-AAAAS0"]
[Mon Jul 20 06:56:03.684306 2026] [security2:error] [pid 16093:tid 16310] [client 14.225.17.146:52296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4a45uybMv3z_zMVBSnFQAAAeU"], referer: http://dadanetnet.net/2022
[Mon Jul 20 06:56:04.052715 2026] [security2:error] [pid 16093:tid 16349] [client 14.225.17.146:62190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4a5JuybMv3z_zMVBSnKwAAAgw"], referer: https://keywayconstructionclt.com/2022
[Mon Jul 20 06:56:04.107379 2026] [security2:error] [pid 16093:tid 16333] [client 14.225.17.146:51708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4a5JuybMv3z_zMVBSnMgAAAfw"], referer: https://processorstudio.com/2022
[Mon Jul 20 06:56:04.481875 2026] [security2:error] [pid 16093:tid 16226] [client 194.5.53.213:46029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/tinyfilemanager.php"] [unique_id "al4a5JuybMv3z_zMVBSnQgAAAZE"]
[Mon Jul 20 06:56:04.901795 2026] [security2:error] [pid 15216:tid 15356] [client 57.141.18.100:32098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a49tIy0gkFcVddGZx9gABFDY"]
[Mon Jul 20 06:56:04.971956 2026] [security2:error] [pid 15216:tid 15417] [client 194.5.53.245:63745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/js/bas.php"] [unique_id "al4a5NtIy0gkFcVddGZyJwAAAVE"]
[Mon Jul 20 06:56:05.092109 2026] [security2:error] [pid 16093:tid 16239] [client 117.247.108.24:18736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a5ZuybMv3z_zMVBSnWwAAAZ4"]
[Mon Jul 20 06:56:05.092197 2026] [security2:error] [pid 16093:tid 16239] [client 117.247.108.24:18736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a5ZuybMv3z_zMVBSnWwAAAZ4"]
[Mon Jul 20 06:56:05.455998 2026] [security2:error] [pid 15216:tid 15369] [client 194.5.53.218:59999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "al4a5dtIy0gkFcVddGZyPwAAASE"]
[Mon Jul 20 06:56:05.730739 2026] [security2:error] [pid 16093:tid 16318] [client 77.110.127.138:59791] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 603 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a5ZuybMv3z_zMVBSnbwAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:05.773526 2026] [security2:error] [pid 16093:tid 16349] [client 122.183.32.225:25564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a5ZuybMv3z_zMVBSndwAAAgw"]
[Mon Jul 20 06:56:05.773606 2026] [security2:error] [pid 16093:tid 16349] [client 122.183.32.225:25564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a5ZuybMv3z_zMVBSndwAAAgw"]
[Mon Jul 20 06:56:05.804162 2026] [security2:error] [pid 15216:tid 15337] [remote 45.90.123.233:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4a5dtIy0gkFcVddGZyTAABPHg"]
[Mon Jul 20 06:56:05.815445 2026] [security2:error] [pid 16093:tid 16254] [client 217.142.18.172:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a5ZuybMv3z_zMVBSneQAAAa0"]
[Mon Jul 20 06:56:05.815550 2026] [security2:error] [pid 16093:tid 16254] [client 217.142.18.172:58852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a5ZuybMv3z_zMVBSneQAAAa0"]
[Mon Jul 20 06:56:05.894781 2026] [security2:error] [pid 15216:tid 15414] [client 183.82.98.154:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a5dtIy0gkFcVddGZyTwAAAU4"]
[Mon Jul 20 06:56:05.894885 2026] [security2:error] [pid 15216:tid 15414] [client 183.82.98.154:63949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a5dtIy0gkFcVddGZyTwAAAU4"]
[Mon Jul 20 06:56:05.907940 2026] [security2:error] [pid 15216:tid 15468] [client 14.225.17.146:52450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4a5dtIy0gkFcVddGZyRwAAAYQ"], referer: http://webgardensbypaula.com/2022
[Mon Jul 20 06:56:06.200280 2026] [security2:error] [pid 15216:tid 15300] [remote 45.90.123.233:32882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4a5ttIy0gkFcVddGZyWQABVFM"], referer: https://peoplestrategies.us/wp-login.php
[Mon Jul 20 06:56:06.293070 2026] [security2:error] [pid 16093:tid 16313] [client 197.186.66.42:57737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a5puybMv3z_zMVBSnkgAAAeg"]
[Mon Jul 20 06:56:06.305668 2026] [security2:error] [pid 16093:tid 16313] [client 197.186.66.42:57737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a5puybMv3z_zMVBSnkgAAAeg"]
[Mon Jul 20 06:56:06.713280 2026] [security2:error] [pid 16093:tid 16250] [client 152.58.191.29:53747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a5puybMv3z_zMVBSnnwAAAak"]
[Mon Jul 20 06:56:06.713405 2026] [security2:error] [pid 16093:tid 16250] [client 152.58.191.29:53747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a5puybMv3z_zMVBSnnwAAAak"]
[Mon Jul 20 06:56:06.959205 2026] [security2:error] [pid 15216:tid 15378] [client 14.225.17.146:64559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4a5ttIy0gkFcVddGZydgAAASo"], referer: http://hammadownenterprises.com/2022
[Mon Jul 20 06:56:07.729852 2026] [security2:error] [pid 16093:tid 16300] [client 52.109.124.141:35776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4a55uybMv3z_zMVBSnvAAAAds"]
[Mon Jul 20 06:56:07.862341 2026] [security2:error] [pid 16093:tid 16324] [client 103.238.106.162:60801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a55uybMv3z_zMVBSnwgAAAfM"]
[Mon Jul 20 06:56:07.863135 2026] [security2:error] [pid 16093:tid 16324] [client 103.238.106.162:60801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a55uybMv3z_zMVBSnwgAAAfM"]
[Mon Jul 20 06:56:07.868670 2026] [security2:error] [pid 16093:tid 16220] [remote 154.66.198.148:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a55uybMv3z_zMVBSnwwABo30"]
[Mon Jul 20 06:56:07.901589 2026] [security2:error] [pid 15216:tid 15373] [client 14.225.17.146:52483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4a59tIy0gkFcVddGZyngAAASU"], referer: http://betterbonddogtraining.com/2022
[Mon Jul 20 06:56:07.911146 2026] [security2:error] [pid 16093:tid 16258] [client 52.109.124.141:35776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4a55uybMv3z_zMVBSnxQAAAbE"]
[Mon Jul 20 06:56:08.045689 2026] [security2:error] [pid 15216:tid 15368] [client 52.109.0.142:30913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4a6NtIy0gkFcVddGZypAAAASA"]
[Mon Jul 20 06:56:08.057005 2026] [security2:error] [pid 16093:tid 16279] [client 77.110.127.138:59812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a6JuybMv3z_zMVBSnzAAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:08.057079 2026] [security2:error] [pid 16093:tid 16279] [client 77.110.127.138:59812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a6JuybMv3z_zMVBSnzAAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:08.066296 2026] [security2:error] [pid 15216:tid 15350] [client 52.109.0.142:30913] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4a6NtIy0gkFcVddGZypQAAAQ4"]
[Mon Jul 20 06:56:08.089806 2026] [security2:error] [pid 15216:tid 15382] [client 194.5.53.47:50267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/file.php"] [unique_id "al4a6NtIy0gkFcVddGZypwAAAS4"]
[Mon Jul 20 06:56:08.207401 2026] [security2:error] [pid 15216:tid 15246] [remote 124.55.178.99:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4a6NtIy0gkFcVddGZyrAABSx0"]
[Mon Jul 20 06:56:08.409724 2026] [security2:error] [pid 16093:tid 16107] [remote 154.66.198.148:51216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a6JuybMv3z_zMVBSn2gACBAw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:56:08.642567 2026] [security2:error] [pid 15216:tid 15265] [remote 124.55.178.99:59376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4a6NtIy0gkFcVddGZyvAABMzA"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:56:08.852687 2026] [security2:error] [pid 16093:tid 16117] [remote 100.42.189.89:39048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4a6JuybMv3z_zMVBSn9gAB6hY"]
[Mon Jul 20 06:56:08.852817 2026] [security2:error] [pid 16093:tid 16315] [client 100.42.189.89:39048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4a6JuybMv3z_zMVBSn9gAB6hY"]
[Mon Jul 20 06:56:09.617793 2026] [security2:error] [pid 16093:tid 16280] [client 14.225.17.146:64063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4a6ZuybMv3z_zMVBSoGQAAAcc"]
[Mon Jul 20 06:56:09.633740 2026] [security2:error] [pid 16093:tid 16306] [client 77.110.127.138:59825] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 99 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a6ZuybMv3z_zMVBSoHQAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:09.864620 2026] [security2:error] [pid 15216:tid 15280] [remote 95.217.78.234:58252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4a6dtIy0gkFcVddGZy5gABMD8"]
[Mon Jul 20 06:56:09.875195 2026] [security2:error] [pid 15216:tid 15452] [client 194.5.53.55:56373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/js/index.php"] [unique_id "al4a6dtIy0gkFcVddGZy5wAAAXQ"]
[Mon Jul 20 06:56:10.114592 2026] [security2:error] [pid 15216:tid 15292] [remote 95.217.78.234:58252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4a6ttIy0gkFcVddGZy7QABQ0s"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 06:56:10.214680 2026] [security2:error] [pid 16093:tid 16318] [client 194.5.53.220:40365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/upgrade/item.php"] [unique_id "al4a6puybMv3z_zMVBSoNgAAAe0"]
[Mon Jul 20 06:56:10.373022 2026] [security2:error] [pid 15216:tid 15448] [client 57.141.18.120:42160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a6NtIy0gkFcVddGZyyQABcCk"]
[Mon Jul 20 06:56:10.406157 2026] [security2:error] [pid 15216:tid 15444] [client 77.110.127.138:59832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 318 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a6ttIy0gkFcVddGZy8wAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:10.602508 2026] [security2:error] [pid 16093:tid 16248] [client 194.5.53.205:55381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/buy.php"] [unique_id "al4a6puybMv3z_zMVBSoSwAAAac"]
[Mon Jul 20 06:56:10.659240 2026] [security2:error] [pid 15216:tid 15354] [client 45.3.54.110:57167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a6ttIy0gkFcVddGZy-gAAARI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:10.726563 2026] [security2:error] [pid 15216:tid 15373] [client 104.234.53.65:21029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4a6ttIy0gkFcVddGZy-QAAASU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:11.095014 2026] [security2:error] [pid 16093:tid 16279] [client 194.5.53.206:30059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/languages/wp-conflg.php"] [unique_id "al4a65uybMv3z_zMVBSoaQAAAcY"]
[Mon Jul 20 06:56:11.295109 2026] [security2:error] [pid 16093:tid 16281] [client 14.225.17.146:64102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4a65uybMv3z_zMVBSobgAAAcg"], referer: http://mourgroup.com/2022
[Mon Jul 20 06:56:11.361577 2026] [security2:error] [pid 15216:tid 15410] [client 104.234.53.65:21029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4a69tIy0gkFcVddGZzDgAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:11.561099 2026] [security2:error] [pid 16093:tid 16258] [client 57.141.18.32:61186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a6ZuybMv3z_zMVBSoJwABsRg"]
[Mon Jul 20 06:56:11.603042 2026] [security2:error] [pid 16093:tid 16146] [remote 84.247.172.23:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a65uybMv3z_zMVBSodwABuzM"]
[Mon Jul 20 06:56:11.654888 2026] [security2:error] [pid 15216:tid 15428] [client 14.225.17.146:60885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4a69tIy0gkFcVddGZzEwAAAVw"], referer: http://aandarealtygroup.com/2022
[Mon Jul 20 06:56:11.700672 2026] [security2:error] [pid 16093:tid 16340] [client 14.251.3.155:54796] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4a65uybMv3z_zMVBSofQAAAgM"]
[Mon Jul 20 06:56:11.852072 2026] [security2:error] [pid 16093:tid 16232] [client 14.225.17.146:60397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4a6puybMv3z_zMVBSoLQAAAZc"], referer: http://ccsdifference.com/2022
[Mon Jul 20 06:56:11.911880 2026] [security2:error] [pid 16093:tid 16342] [client 187.108.85.186:56121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a65uybMv3z_zMVBSohgAAAgU"]
[Mon Jul 20 06:56:11.912709 2026] [security2:error] [pid 16093:tid 16342] [client 187.108.85.186:56121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a65uybMv3z_zMVBSohgAAAgU"]
[Mon Jul 20 06:56:12.155745 2026] [proxy:error] [pid 16093:tid 16229] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:12.155793 2026] [proxy_http:error] [pid 16093:tid 16229] [client 107.172.180.205:52580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:12.156314 2026] [proxy:error] [pid 16093:tid 16229] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:12.156337 2026] [proxy_http:error] [pid 16093:tid 16229] [client 107.172.180.205:52580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:12.240319 2026] [security2:error] [pid 16093:tid 16227] [client 77.110.127.138:59844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a7JuybMv3z_zMVBSooQAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:12.240434 2026] [security2:error] [pid 16093:tid 16227] [client 77.110.127.138:59844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a7JuybMv3z_zMVBSooQAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:12.259818 2026] [access_compat:error] [pid 16093:tid 16228] [client 66.249.74.166:38736] AH01797: client denied by server configuration: /home1/marscafe/public_html/ads.txt
[Mon Jul 20 06:56:12.493216 2026] [security2:error] [pid 16093:tid 16280] [client 194.5.53.227:61435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/themes/classwithtostring.php"] [unique_id "al4a7JuybMv3z_zMVBSouwAAAcc"]
[Mon Jul 20 06:56:12.533243 2026] [security2:error] [pid 16093:tid 16315] [client 50.116.65.227:38104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4a7JuybMv3z_zMVBSovAAAAeo"]
[Mon Jul 20 06:56:12.546489 2026] [security2:error] [pid 16093:tid 16319] [client 50.116.65.227:38106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4a7JuybMv3z_zMVBSovgAAAe4"]
[Mon Jul 20 06:56:12.847597 2026] [security2:error] [pid 16093:tid 16253] [client 194.5.53.47:52503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/elementor/wp-wjvngrh.php"] [unique_id "al4a7JuybMv3z_zMVBSozgAAAaw"]
[Mon Jul 20 06:56:12.872049 2026] [security2:error] [pid 16093:tid 16170] [remote 84.247.172.23:52598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a7JuybMv3z_zMVBSo0AABqEs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:56:12.874619 2026] [security2:error] [pid 15216:tid 15452] [client 14.225.17.146:60879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4a7NtIy0gkFcVddGZzLwAAAXQ"], referer: https://ccsdifference.com/2022
[Mon Jul 20 06:56:12.905960 2026] [security2:error] [pid 16093:tid 16288] [client 52.207.32.99:11088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4a7JuybMv3z_zMVBSo0wAAAc8"]
[Mon Jul 20 06:56:12.964205 2026] [security2:error] [pid 16093:tid 16278] [client 103.144.65.217:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a7JuybMv3z_zMVBSo2wAAAcU"]
[Mon Jul 20 06:56:12.966112 2026] [security2:error] [pid 16093:tid 16278] [client 103.144.65.217:60956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a7JuybMv3z_zMVBSo2wAAAcU"]
[Mon Jul 20 06:56:13.071634 2026] [security2:error] [pid 16093:tid 16340] [client 103.125.179.95:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a7ZuybMv3z_zMVBSo6QAAAgM"]
[Mon Jul 20 06:56:13.071778 2026] [security2:error] [pid 16093:tid 16340] [client 103.125.179.95:52179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a7ZuybMv3z_zMVBSo6QAAAgM"]
[Mon Jul 20 06:56:13.074595 2026] [security2:error] [pid 16093:tid 16238] [client 50.116.65.227:38118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4a7JuybMv3z_zMVBSo1AAAAZ0"]
[Mon Jul 20 06:56:13.085141 2026] [security2:error] [pid 16093:tid 16312] [client 57.141.18.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4a7JuybMv3z_zMVBSo1QAAAec"]
[Mon Jul 20 06:56:13.177139 2026] [security2:error] [pid 16093:tid 16316] [client 194.5.53.216:58025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/IXR/fix.php7"] [unique_id "al4a7ZuybMv3z_zMVBSo7wAAAes"]
[Mon Jul 20 06:56:13.286635 2026] [security2:error] [pid 16093:tid 16322] [client 50.116.65.227:38132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4a7ZuybMv3z_zMVBSo6wAAAfE"]
[Mon Jul 20 06:56:13.364492 2026] [security2:error] [pid 16093:tid 16244] [client 34.201.171.57:20748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.171.201.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4a7ZuybMv3z_zMVBSo9wAAAaM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:56:13.432333 2026] [security2:error] [pid 15216:tid 15466] [client 66.249.73.168:38550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4a69tIy0gkFcVddGZzIwAAAYI"]
[Mon Jul 20 06:56:13.492644 2026] [security2:error] [pid 15216:tid 15421] [client 194.5.53.218:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/widgets/dyqvcfqv.php"] [unique_id "al4a7dtIy0gkFcVddGZzPwAAAVU"]
[Mon Jul 20 06:56:13.505215 2026] [core:error] [pid 16093:tid 16236] [client 14.225.17.146:63918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2022
[Mon Jul 20 06:56:13.505242 2026] [core:error] [pid 16093:tid 16236] [client 14.225.17.146:63918] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2022
[Mon Jul 20 06:56:13.514968 2026] [security2:error] [pid 16093:tid 16285] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4a7ZuybMv3z_zMVBSo-QABzGc"], referer: http://aleishapenny.ca/2022
[Mon Jul 20 06:56:13.555824 2026] [security2:error] [pid 16093:tid 16329] [client 117.222.139.248:63175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a7ZuybMv3z_zMVBSpAAAAAfg"]
[Mon Jul 20 06:56:13.555899 2026] [security2:error] [pid 16093:tid 16329] [client 117.222.139.248:63175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a7ZuybMv3z_zMVBSpAAAAAfg"]
[Mon Jul 20 06:56:13.585090 2026] [proxy:error] [pid 16093:tid 16246] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:13.585183 2026] [proxy_http:error] [pid 16093:tid 16246] [client 107.172.180.205:52598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:13.586017 2026] [proxy:error] [pid 16093:tid 16246] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:13.586081 2026] [proxy_http:error] [pid 16093:tid 16246] [client 107.172.180.205:52598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:14.063560 2026] [security2:error] [pid 15216:tid 15426] [client 178.62.216.39:60883] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.besoundful.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4a7ttIy0gkFcVddGZzSgAAAVo"]
[Mon Jul 20 06:56:14.141384 2026] [security2:error] [pid 16093:tid 16264] [client 194.5.53.215:31289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/admin/function.php"] [unique_id "al4a7puybMv3z_zMVBSpIwAAAbc"]
[Mon Jul 20 06:56:14.170937 2026] [security2:error] [pid 16093:tid 16209] [remote 160.187.68.132:43736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4a7puybMv3z_zMVBSpJwABzXI"]
[Mon Jul 20 06:56:14.249584 2026] [security2:error] [pid 16093:tid 16324] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4a7puybMv3z_zMVBSpJgAB83E"], referer: https://aleishapenny.ca/2022
[Mon Jul 20 06:56:14.350074 2026] [autoindex:error] [pid 16093:tid 16261] [client 147.93.171.184:51885] AH01276: Cannot serve directory /home1/vgfdujmy/public_html/website_9d7542e7/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:56:14.402129 2026] [security2:error] [pid 16093:tid 16249] [client 77.110.127.138:59861] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 612 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a7puybMv3z_zMVBSpTQAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:14.462180 2026] [security2:error] [pid 15216:tid 15348] [client 194.5.53.241:24911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "al4a7ttIy0gkFcVddGZzUAAAAQw"]
[Mon Jul 20 06:56:14.636000 2026] [security2:error] [pid 16093:tid 16123] [remote 160.187.68.132:43736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4a7puybMv3z_zMVBSpWAAB2xw"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 06:56:14.643313 2026] [security2:error] [pid 15216:tid 15356] [client 77.110.127.138:59863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 206 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a7ttIy0gkFcVddGZzWwAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:14.693920 2026] [autoindex:error] [pid 16093:tid 16131] [remote 34.73.253.87:56234] AH01276: Cannot serve directory /home2/enxbgpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://enx.bgp.mybluehost.me
[Mon Jul 20 06:56:14.788406 2026] [security2:error] [pid 16093:tid 16260] [client 14.225.17.146:60803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4a7puybMv3z_zMVBSpWgAAAbM"], referer: http://lutheranphilosopher.com/2022
[Mon Jul 20 06:56:14.828340 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.246:42055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/js/crop/admin.php"] [unique_id "al4a7puybMv3z_zMVBSpYAAAAZY"]
[Mon Jul 20 06:56:14.928385 2026] [security2:error] [pid 16093:tid 16328] [client 57.141.18.49:39344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a7ZuybMv3z_zMVBSo7gAB92Q"]
[Mon Jul 20 06:56:15.192087 2026] [security2:error] [pid 16093:tid 16254] [client 14.225.17.146:60912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4a7ZuybMv3z_zMVBSpDAAAAa0"], referer: http://momheadquarters.com/2022
[Mon Jul 20 06:56:15.260055 2026] [security2:error] [pid 16093:tid 16137] [remote 192.241.143.148:40036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4a75uybMv3z_zMVBSphwABzCo"]
[Mon Jul 20 06:56:15.260223 2026] [security2:error] [pid 16093:tid 16285] [client 192.241.143.148:40036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4a75uybMv3z_zMVBSphwABzCo"]
[Mon Jul 20 06:56:15.270850 2026] [security2:error] [pid 16093:tid 16294] [client 194.5.53.220:43275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al4a75uybMv3z_zMVBSpiAAAAdU"]
[Mon Jul 20 06:56:15.572849 2026] [proxy:error] [pid 16093:tid 16297] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:15.572899 2026] [proxy_http:error] [pid 16093:tid 16297] [client 107.172.180.205:39340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:15.573340 2026] [proxy:error] [pid 16093:tid 16297] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:15.573366 2026] [proxy_http:error] [pid 16093:tid 16297] [client 107.172.180.205:39340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:15.630914 2026] [security2:error] [pid 16093:tid 16314] [client 66.249.73.231:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4a75uybMv3z_zMVBSpggAAAek"]
[Mon Jul 20 06:56:15.633581 2026] [security2:error] [pid 16093:tid 16257] [client 194.5.53.217:63527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "al4a75uybMv3z_zMVBSpqAAAAbA"]
[Mon Jul 20 06:56:15.797572 2026] [security2:error] [pid 15216:tid 15467] [client 117.247.108.24:19064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a79tIy0gkFcVddGZzbwAAAYM"]
[Mon Jul 20 06:56:15.797666 2026] [security2:error] [pid 15216:tid 15467] [client 117.247.108.24:19064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a79tIy0gkFcVddGZzbwAAAYM"]
[Mon Jul 20 06:56:15.815730 2026] [security2:error] [pid 15216:tid 15437] [client 104.234.53.56:49963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4a79tIy0gkFcVddGZzcQAAAWU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:15.872808 2026] [security2:error] [pid 16093:tid 16169] [remote 182.77.62.24:44544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4a75uybMv3z_zMVBSpugABuUo"]
[Mon Jul 20 06:56:16.031864 2026] [security2:error] [pid 16093:tid 16245] [client 194.5.53.240:49011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/widgets/wp-login.php"] [unique_id "al4a75uybMv3z_zMVBSpwQAAAaQ"]
[Mon Jul 20 06:56:16.217062 2026] [security2:error] [pid 16093:tid 16307] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ghivs.com"] [uri "/index.php"] [unique_id "al4a8JuybMv3z_zMVBSpwgAAAeI"]
[Mon Jul 20 06:56:16.361930 2026] [security2:error] [pid 15216:tid 15448] [client 217.142.18.172:36460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a8NtIy0gkFcVddGZzhQAAAXA"]
[Mon Jul 20 06:56:16.373292 2026] [security2:error] [pid 15216:tid 15448] [client 217.142.18.172:36460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a8NtIy0gkFcVddGZzhQAAAXA"]
[Mon Jul 20 06:56:16.387307 2026] [security2:error] [pid 16093:tid 16176] [remote 182.77.62.24:44544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4a8JuybMv3z_zMVBSp4QAB-FE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:56:16.394225 2026] [security2:error] [pid 16093:tid 16230] [client 14.225.17.146:65464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4a8JuybMv3z_zMVBSpygAAAZU"], referer: http://www.justinagrayman.com/2022
[Mon Jul 20 06:56:16.480057 2026] [proxy:error] [pid 16093:tid 16264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:16.480128 2026] [proxy_http:error] [pid 16093:tid 16264] [client 107.172.180.205:39354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:16.480727 2026] [proxy:error] [pid 16093:tid 16264] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:16.480769 2026] [proxy_http:error] [pid 16093:tid 16264] [client 107.172.180.205:39354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:16.517629 2026] [security2:error] [pid 16093:tid 16154] [remote 182.77.62.24:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a8JuybMv3z_zMVBSp5wAB4Ts"]
[Mon Jul 20 06:56:16.555884 2026] [security2:error] [pid 15216:tid 15412] [client 14.225.17.146:60820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4a8NtIy0gkFcVddGZzhgAAAUw"], referer: http://reosportsboats.com/2022
[Mon Jul 20 06:56:16.597839 2026] [security2:error] [pid 16093:tid 16325] [client 194.5.53.232:20247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/files/index.php"] [unique_id "al4a8JuybMv3z_zMVBSp6gAAAfQ"]
[Mon Jul 20 06:56:16.656654 2026] [security2:error] [pid 15216:tid 15372] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4a8NtIy0gkFcVddGZzgAABJH8"], referer: http://ardhalwafaa.com/2022
[Mon Jul 20 06:56:16.856499 2026] [security2:error] [pid 16093:tid 16340] [client 183.82.98.154:64547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a8JuybMv3z_zMVBSp_QAAAgM"]
[Mon Jul 20 06:56:16.856607 2026] [security2:error] [pid 16093:tid 16340] [client 183.82.98.154:64547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a8JuybMv3z_zMVBSp_QAAAgM"]
[Mon Jul 20 06:56:16.915550 2026] [security2:error] [pid 16093:tid 16305] [client 77.110.127.138:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a8JuybMv3z_zMVBSqAAAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:16.915628 2026] [security2:error] [pid 16093:tid 16305] [client 77.110.127.138:59876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a8JuybMv3z_zMVBSqAAAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:17.020545 2026] [security2:error] [pid 16093:tid 16191] [remote 182.77.62.24:59010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a8ZuybMv3z_zMVBSqDAAB6WA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:56:17.051377 2026] [security2:error] [pid 16093:tid 16310] [client 194.5.53.229:28953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/PHPMailer/options.php"] [unique_id "al4a8ZuybMv3z_zMVBSqEwAAAeU"]
[Mon Jul 20 06:56:17.133002 2026] [security2:error] [pid 16093:tid 16233] [client 158.173.166.181:41775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4a8ZuybMv3z_zMVBSqHgAAAZg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:56:17.328344 2026] [security2:error] [pid 15216:tid 15347] [client 122.183.32.225:21668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a8dtIy0gkFcVddGZzogAAAQs"]
[Mon Jul 20 06:56:17.328479 2026] [security2:error] [pid 15216:tid 15347] [client 122.183.32.225:21668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a8dtIy0gkFcVddGZzogAAAQs"]
[Mon Jul 20 06:56:17.431237 2026] [security2:error] [pid 15216:tid 15409] [client 152.58.191.29:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a8dtIy0gkFcVddGZzpAAAAUk"]
[Mon Jul 20 06:56:17.431352 2026] [security2:error] [pid 15216:tid 15409] [client 152.58.191.29:54230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a8dtIy0gkFcVddGZzpAAAAUk"]
[Mon Jul 20 06:56:17.491828 2026] [security2:error] [pid 16093:tid 16259] [client 14.225.17.146:63795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4a8ZuybMv3z_zMVBSqLwAAAbI"], referer: https://reosportsboats.com/2022
[Mon Jul 20 06:56:17.678617 2026] [security2:error] [pid 16093:tid 16287] [client 77.110.127.138:59883] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a8ZuybMv3z_zMVBSqTAAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:17.836735 2026] [security2:error] [pid 16093:tid 16323] [client 77.110.127.138:59886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 477 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a8ZuybMv3z_zMVBSqVAAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:17.960212 2026] [security2:error] [pid 15216:tid 15445] [client 194.5.53.249:54885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/inc.php"] [unique_id "al4a8dtIy0gkFcVddGZzsgAAAW0"]
[Mon Jul 20 06:56:18.333377 2026] [security2:error] [pid 15216:tid 15413] [client 103.238.106.162:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a8ttIy0gkFcVddGZzugAAAU0"]
[Mon Jul 20 06:56:18.333482 2026] [security2:error] [pid 15216:tid 15413] [client 103.238.106.162:60599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a8ttIy0gkFcVddGZzugAAAU0"]
[Mon Jul 20 06:56:18.457050 2026] [security2:error] [pid 16093:tid 16226] [client 194.5.53.223:60597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/index.php"] [unique_id "al4a8puybMv3z_zMVBSqgAAAAZE"]
[Mon Jul 20 06:56:18.458331 2026] [security2:error] [pid 15216:tid 15473] [client 54.244.177.189:39260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4a8ttIy0gkFcVddGZzvgAAAYk"]
[Mon Jul 20 06:56:18.494168 2026] [security2:error] [pid 16093:tid 16108] [remote 124.55.178.99:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4a8puybMv3z_zMVBSqhQABng0"]
[Mon Jul 20 06:56:18.906931 2026] [security2:error] [pid 16093:tid 16128] [remote 124.55.178.99:48736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4a8puybMv3z_zMVBSqmgACBiE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:56:19.046987 2026] [security2:error] [pid 15216:tid 15431] [client 35.90.38.209:56574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4a89tIy0gkFcVddGZzzAAAAV8"]
[Mon Jul 20 06:56:19.113216 2026] [security2:error] [pid 15216:tid 15405] [client 194.5.53.210:46043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/filemanager.php"] [unique_id "al4a89tIy0gkFcVddGZz0AAAAUU"]
[Mon Jul 20 06:56:19.172562 2026] [security2:error] [pid 15216:tid 15469] [client 14.225.17.146:63825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4a89tIy0gkFcVddGZz0gAAAYU"], referer: http://ancestralidadytrance.space/2022
[Mon Jul 20 06:56:19.191956 2026] [security2:error] [pid 15216:tid 15305] [remote 57.141.18.125:49258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3741619"] [unique_id "al4a89tIy0gkFcVddGZz1AABflg"]
[Mon Jul 20 06:56:19.471408 2026] [security2:error] [pid 15216:tid 15451] [client 197.186.66.42:58279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a89tIy0gkFcVddGZz2wAAAXM"]
[Mon Jul 20 06:56:19.477646 2026] [security2:error] [pid 16093:tid 16279] [client 194.5.53.55:27215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/cgi-bin/bypass.php"] [unique_id "al4a85uybMv3z_zMVBSqwQAAAcY"]
[Mon Jul 20 06:56:19.479831 2026] [security2:error] [pid 15216:tid 15451] [client 197.186.66.42:58279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a89tIy0gkFcVddGZz2wAAAXM"]
[Mon Jul 20 06:56:19.804569 2026] [security2:error] [pid 16093:tid 16246] [client 194.5.53.230:57119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "al4a85uybMv3z_zMVBSqywAAAaU"]
[Mon Jul 20 06:56:19.819236 2026] [security2:error] [pid 16093:tid 16242] [client 57.141.18.43:21810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a8puybMv3z_zMVBSqbgABoQw"]
[Mon Jul 20 06:56:20.084276 2026] [security2:error] [pid 16093:tid 16339] [client 77.110.127.138:59908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a9JuybMv3z_zMVBSq2gAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:20.084384 2026] [security2:error] [pid 16093:tid 16339] [client 77.110.127.138:59908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a9JuybMv3z_zMVBSq2gAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:20.190210 2026] [security2:error] [pid 16093:tid 16250] [client 194.5.53.249:24699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/IXR/admin.php"] [unique_id "al4a9JuybMv3z_zMVBSq4wAAAak"]
[Mon Jul 20 06:56:20.466873 2026] [security2:error] [pid 16093:tid 16262] [client 14.225.17.146:63831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4a85uybMv3z_zMVBSqqwAAAbU"], referer: http://scott-assist.com/2022
[Mon Jul 20 06:56:20.606163 2026] [security2:error] [pid 15216:tid 15388] [client 14.225.17.146:50378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4a9NtIy0gkFcVddGZz9AAAATQ"], referer: http://latiendadejorge.com.gt/2022
[Mon Jul 20 06:56:20.798035 2026] [security2:error] [pid 16093:tid 16274] [client 77.110.127.138:59910] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_origin"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a9JuybMv3z_zMVBSrBwAAAcE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:20.919231 2026] [security2:error] [pid 16093:tid 16272] [client 194.5.53.238:58595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4a9JuybMv3z_zMVBSrCwAAAb8"]
[Mon Jul 20 06:56:21.031063 2026] [security2:error] [pid 15216:tid 15466] [client 66.249.73.166:51096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4a9NtIy0gkFcVddGZz_gAAAYI"]
[Mon Jul 20 06:56:21.327368 2026] [security2:error] [pid 15216:tid 15437] [client 14.225.17.146:50135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4a9NtIy0gkFcVddGZz7AAAAWU"], referer: http://cloudspacesgroup.com/2022
[Mon Jul 20 06:56:21.519773 2026] [security2:error] [pid 16093:tid 16235] [client 194.5.53.241:23537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/js/jquery/jquery.php"] [unique_id "al4a9ZuybMv3z_zMVBSrJgAAAZo"]
[Mon Jul 20 06:56:21.653844 2026] [security2:error] [pid 15216:tid 15446] [client 14.225.17.146:50392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4a9dtIy0gkFcVddGZ0GQAAAW4"], referer: http://maxenengineering.com/2022
[Mon Jul 20 06:56:21.819099 2026] [security2:error] [pid 16093:tid 16191] [remote 182.77.62.24:45628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4a9ZuybMv3z_zMVBSrNQABmGA"]
[Mon Jul 20 06:56:21.982699 2026] [security2:error] [pid 15216:tid 15468] [client 77.110.127.138:59916] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 283 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a9dtIy0gkFcVddGZ0IwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:21.987623 2026] [security2:error] [pid 16093:tid 16284] [client 194.5.53.240:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/function.php"] [unique_id "al4a9ZuybMv3z_zMVBSrOwAAAcs"]
[Mon Jul 20 06:56:22.334227 2026] [security2:error] [pid 16093:tid 16206] [remote 182.77.62.24:45628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4a9puybMv3z_zMVBSrVAAB_G8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:56:22.362922 2026] [security2:error] [pid 15216:tid 15402] [client 194.5.53.240:58303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "al4a9ttIy0gkFcVddGZ0MAAAAUI"]
[Mon Jul 20 06:56:22.576568 2026] [security2:error] [pid 16093:tid 16228] [client 187.108.85.186:56665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a9puybMv3z_zMVBSrYQAAAZM"]
[Mon Jul 20 06:56:22.576709 2026] [security2:error] [pid 16093:tid 16228] [client 187.108.85.186:56665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a9puybMv3z_zMVBSrYQAAAZM"]
[Mon Jul 20 06:56:22.676278 2026] [security2:error] [pid 15216:tid 15359] [client 104.234.53.79:52215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4a9ttIy0gkFcVddGZ0OwAAARc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:22.760956 2026] [security2:error] [pid 15216:tid 15449] [client 194.5.53.227:50867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-signup.php"] [unique_id "al4a9ttIy0gkFcVddGZ0RQAAAXE"]
[Mon Jul 20 06:56:23.092909 2026] [security2:error] [pid 16093:tid 16300] [client 194.5.53.220:47409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/network/network.php"] [unique_id "al4a95uybMv3z_zMVBSreAAAAds"]
[Mon Jul 20 06:56:23.484250 2026] [security2:error] [pid 16093:tid 16213] [remote 20.153.140.50:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a95uybMv3z_zMVBSriAAB4HY"]
[Mon Jul 20 06:56:23.555653 2026] [security2:error] [pid 16093:tid 16307] [client 103.144.65.217:61424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a95uybMv3z_zMVBSrjwAAAeI"]
[Mon Jul 20 06:56:23.557272 2026] [security2:error] [pid 16093:tid 16307] [client 103.144.65.217:61424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4a95uybMv3z_zMVBSrjwAAAeI"]
[Mon Jul 20 06:56:23.603071 2026] [security2:error] [pid 15216:tid 15428] [client 50.116.65.227:47120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4a99tIy0gkFcVddGZ0WgAAAVw"]
[Mon Jul 20 06:56:23.613730 2026] [security2:error] [pid 15216:tid 15454] [client 50.116.65.227:47126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4a99tIy0gkFcVddGZ0WwAAAXY"]
[Mon Jul 20 06:56:23.849949 2026] [security2:error] [pid 16093:tid 16293] [client 194.5.53.225:63821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/admin/upload/css.php"] [unique_id "al4a95uybMv3z_zMVBSroAAAAdQ"]
[Mon Jul 20 06:56:23.873289 2026] [security2:error] [pid 16093:tid 16106] [remote 20.153.140.50:47548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4a95uybMv3z_zMVBSrowABkAs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:56:24.031435 2026] [security2:error] [pid 15216:tid 15398] [client 117.222.139.248:63676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a-NtIy0gkFcVddGZ0ZAAAAT4"]
[Mon Jul 20 06:56:24.031523 2026] [security2:error] [pid 15216:tid 15398] [client 117.222.139.248:63676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4a-NtIy0gkFcVddGZ0ZAAAAT4"]
[Mon Jul 20 06:56:24.460416 2026] [security2:error] [pid 16093:tid 16279] [client 20.48.236.161:51609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4a-JuybMv3z_zMVBSrvgAAAcY"]
[Mon Jul 20 06:56:24.460525 2026] [security2:error] [pid 16093:tid 16279] [client 20.48.236.161:51609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4a-JuybMv3z_zMVBSrvgAAAcY"]
[Mon Jul 20 06:56:24.586446 2026] [security2:error] [pid 16093:tid 16312] [client 20.48.236.161:51698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4a-JuybMv3z_zMVBSrxAAAAec"]
[Mon Jul 20 06:56:24.586539 2026] [security2:error] [pid 16093:tid 16312] [client 20.48.236.161:51698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4a-JuybMv3z_zMVBSrxAAAAec"]
[Mon Jul 20 06:56:24.598375 2026] [security2:error] [pid 16093:tid 16292] [client 194.5.53.217:60851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-blog.php"] [unique_id "al4a-JuybMv3z_zMVBSrxgAAAdM"]
[Mon Jul 20 06:56:24.645681 2026] [security2:error] [pid 15216:tid 15361] [client 14.225.17.146:58589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4a-NtIy0gkFcVddGZ0dQAAARk"], referer: http://jvcmotorsports.com/2022
[Mon Jul 20 06:56:24.704774 2026] [security2:error] [pid 16093:tid 16233] [client 20.48.236.161:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/x.php"] [unique_id "al4a-JuybMv3z_zMVBSrzwAAAZg"]
[Mon Jul 20 06:56:24.704855 2026] [security2:error] [pid 16093:tid 16233] [client 20.48.236.161:61120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/x.php"] [unique_id "al4a-JuybMv3z_zMVBSrzwAAAZg"]
[Mon Jul 20 06:56:24.834621 2026] [security2:error] [pid 16093:tid 16290] [client 20.48.236.161:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/mgrr.php"] [unique_id "al4a-JuybMv3z_zMVBSr0wAAAdE"]
[Mon Jul 20 06:56:24.834729 2026] [security2:error] [pid 16093:tid 16290] [client 20.48.236.161:61129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/mgrr.php"] [unique_id "al4a-JuybMv3z_zMVBSr0wAAAdE"]
[Mon Jul 20 06:56:24.917968 2026] [security2:error] [pid 15216:tid 15387] [client 57.141.18.55:59232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a9ttIy0gkFcVddGZ0SgABM1U"]
[Mon Jul 20 06:56:24.959016 2026] [security2:error] [pid 15216:tid 15427] [client 20.48.236.161:51663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/stdin.php"] [unique_id "al4a-NtIy0gkFcVddGZ0gAAAAVs"]
[Mon Jul 20 06:56:24.959096 2026] [security2:error] [pid 15216:tid 15427] [client 20.48.236.161:51663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/stdin.php"] [unique_id "al4a-NtIy0gkFcVddGZ0gAAAAVs"]
[Mon Jul 20 06:56:24.983107 2026] [security2:error] [pid 16093:tid 16301] [client 14.225.17.146:60235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4a-JuybMv3z_zMVBSrvwAAAdw"], referer: http://drewsasburyparkbeachhouse.com/2022
[Mon Jul 20 06:56:25.109046 2026] [security2:error] [pid 16093:tid 16338] [client 20.48.236.161:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/BDKR28.php"] [unique_id "al4a-ZuybMv3z_zMVBSr3AAAAgE"]
[Mon Jul 20 06:56:25.109133 2026] [security2:error] [pid 16093:tid 16338] [client 20.48.236.161:61129] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/BDKR28.php"] [unique_id "al4a-ZuybMv3z_zMVBSr3AAAAgE"]
[Mon Jul 20 06:56:25.257257 2026] [security2:error] [pid 16093:tid 16235] [client 103.125.179.95:52706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a-ZuybMv3z_zMVBSr5QAAAZo"]
[Mon Jul 20 06:56:25.257587 2026] [security2:error] [pid 16093:tid 16235] [client 103.125.179.95:52706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4a-ZuybMv3z_zMVBSr5QAAAZo"]
[Mon Jul 20 06:56:25.271977 2026] [security2:error] [pid 16093:tid 16343] [client 20.48.236.161:61158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/001.php"] [unique_id "al4a-ZuybMv3z_zMVBSr5gAAAgY"]
[Mon Jul 20 06:56:25.272090 2026] [security2:error] [pid 16093:tid 16343] [client 20.48.236.161:61158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/001.php"] [unique_id "al4a-ZuybMv3z_zMVBSr5gAAAgY"]
[Mon Jul 20 06:56:25.367949 2026] [security2:error] [pid 15216:tid 15469] [client 66.249.73.130:43240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4a-dtIy0gkFcVddGZ0hAAAAYU"]
[Mon Jul 20 06:56:25.390927 2026] [security2:error] [pid 16093:tid 16118] [remote 113.160.142.119:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a-ZuybMv3z_zMVBSr6wAB-xc"]
[Mon Jul 20 06:56:25.401843 2026] [security2:error] [pid 16093:tid 16304] [client 20.48.236.161:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/dZ3wP5.php"] [unique_id "al4a-ZuybMv3z_zMVBSr7wAAAd8"]
[Mon Jul 20 06:56:25.401962 2026] [security2:error] [pid 16093:tid 16304] [client 20.48.236.161:51621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/dZ3wP5.php"] [unique_id "al4a-ZuybMv3z_zMVBSr7wAAAd8"]
[Mon Jul 20 06:56:25.546116 2026] [security2:error] [pid 16093:tid 16294] [client 20.48.236.161:51676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/yup.php"] [unique_id "al4a-ZuybMv3z_zMVBSr_AAAAdU"]
[Mon Jul 20 06:56:25.546219 2026] [security2:error] [pid 16093:tid 16294] [client 20.48.236.161:51676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/yup.php"] [unique_id "al4a-ZuybMv3z_zMVBSr_AAAAdU"]
[Mon Jul 20 06:56:25.669954 2026] [security2:error] [pid 16093:tid 16341] [client 20.48.236.161:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/X.php"] [unique_id "al4a-ZuybMv3z_zMVBSsAwAAAgQ"]
[Mon Jul 20 06:56:25.670073 2026] [security2:error] [pid 16093:tid 16341] [client 20.48.236.161:61175] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/X.php"] [unique_id "al4a-ZuybMv3z_zMVBSsAwAAAgQ"]
[Mon Jul 20 06:56:25.677767 2026] [security2:error] [pid 16093:tid 16315] [client 14.225.17.146:50288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4a-ZuybMv3z_zMVBSr_wAAAeo"]
[Mon Jul 20 06:56:25.789299 2026] [security2:error] [pid 16093:tid 16272] [client 20.48.236.161:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/1polka.php"] [unique_id "al4a-ZuybMv3z_zMVBSsCwAAAb8"]
[Mon Jul 20 06:56:25.789391 2026] [security2:error] [pid 16093:tid 16272] [client 20.48.236.161:51701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/1polka.php"] [unique_id "al4a-ZuybMv3z_zMVBSsCwAAAb8"]
[Mon Jul 20 06:56:25.910771 2026] [security2:error] [pid 16093:tid 16337] [client 20.48.236.161:61178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/gec.php"] [unique_id "al4a-ZuybMv3z_zMVBSsFQAAAgA"]
[Mon Jul 20 06:56:25.910864 2026] [security2:error] [pid 16093:tid 16337] [client 20.48.236.161:61178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/gec.php"] [unique_id "al4a-ZuybMv3z_zMVBSsFQAAAgA"]
[Mon Jul 20 06:56:25.947191 2026] [security2:error] [pid 16093:tid 16253] [client 194.5.53.249:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/file.php"] [unique_id "al4a-ZuybMv3z_zMVBSsGQAAAaw"]
[Mon Jul 20 06:56:26.033289 2026] [security2:error] [pid 16093:tid 16247] [client 20.48.236.161:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/sky.php"] [unique_id "al4a-puybMv3z_zMVBSsHgAAAaY"]
[Mon Jul 20 06:56:26.033374 2026] [security2:error] [pid 16093:tid 16247] [client 20.48.236.161:51647] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/sky.php"] [unique_id "al4a-puybMv3z_zMVBSsHgAAAaY"]
[Mon Jul 20 06:56:26.157920 2026] [security2:error] [pid 15216:tid 15358] [client 20.48.236.161:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/fffm.php"] [unique_id "al4a-ttIy0gkFcVddGZ0mAAAARY"]
[Mon Jul 20 06:56:26.158005 2026] [security2:error] [pid 15216:tid 15358] [client 20.48.236.161:51626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/fffm.php"] [unique_id "al4a-ttIy0gkFcVddGZ0mAAAARY"]
[Mon Jul 20 06:56:26.279879 2026] [security2:error] [pid 16093:tid 16242] [client 20.48.236.161:61168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/sixxis.php"] [unique_id "al4a-puybMv3z_zMVBSsLQAAAaE"]
[Mon Jul 20 06:56:26.280011 2026] [security2:error] [pid 16093:tid 16242] [client 20.48.236.161:61168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/sixxis.php"] [unique_id "al4a-puybMv3z_zMVBSsLQAAAaE"]
[Mon Jul 20 06:56:26.305133 2026] [security2:error] [pid 16093:tid 16107] [remote 113.160.142.119:53254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4a-puybMv3z_zMVBSsNAABpAw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:56:26.405570 2026] [security2:error] [pid 16093:tid 16232] [client 20.48.236.161:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/yj09.php"] [unique_id "al4a-puybMv3z_zMVBSsPgAAAZc"]
[Mon Jul 20 06:56:26.405741 2026] [security2:error] [pid 16093:tid 16232] [client 20.48.236.161:61153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/yj09.php"] [unique_id "al4a-puybMv3z_zMVBSsPgAAAZc"]
[Mon Jul 20 06:56:26.478728 2026] [security2:error] [pid 16093:tid 16309] [client 77.110.127.138:59929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a-puybMv3z_zMVBSsRAAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:26.478852 2026] [security2:error] [pid 16093:tid 16309] [client 77.110.127.138:59929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a-puybMv3z_zMVBSsRAAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:26.520987 2026] [security2:error] [pid 16093:tid 16301] [client 194.5.53.216:44681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/admin.php"] [unique_id "al4a-puybMv3z_zMVBSsSAAAAdw"]
[Mon Jul 20 06:56:26.558861 2026] [security2:error] [pid 16093:tid 16283] [client 20.48.236.161:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/f900.php"] [unique_id "al4a-puybMv3z_zMVBSsSQAAAco"]
[Mon Jul 20 06:56:26.558942 2026] [security2:error] [pid 16093:tid 16283] [client 20.48.236.161:61128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/f900.php"] [unique_id "al4a-puybMv3z_zMVBSsSQAAAco"]
[Mon Jul 20 06:56:26.685063 2026] [security2:error] [pid 16093:tid 16260] [client 20.48.236.161:61131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ups.php"] [unique_id "al4a-puybMv3z_zMVBSsVAAAAbM"]
[Mon Jul 20 06:56:26.685143 2026] [security2:error] [pid 16093:tid 16260] [client 20.48.236.161:61131] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ups.php"] [unique_id "al4a-puybMv3z_zMVBSsVAAAAbM"]
[Mon Jul 20 06:56:26.715254 2026] [security2:error] [pid 16093:tid 16322] [client 117.247.108.24:21674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a-puybMv3z_zMVBSsVgAAAfE"]
[Mon Jul 20 06:56:26.715360 2026] [security2:error] [pid 16093:tid 16322] [client 117.247.108.24:21674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4a-puybMv3z_zMVBSsVgAAAfE"]
[Mon Jul 20 06:56:26.820100 2026] [security2:error] [pid 16093:tid 16263] [client 20.48.236.161:51599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/k.php"] [unique_id "al4a-puybMv3z_zMVBSsYgAAAbY"]
[Mon Jul 20 06:56:26.820170 2026] [security2:error] [pid 16093:tid 16263] [client 20.48.236.161:51599] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/k.php"] [unique_id "al4a-puybMv3z_zMVBSsYgAAAbY"]
[Mon Jul 20 06:56:26.901408 2026] [security2:error] [pid 16093:tid 16316] [client 194.5.53.230:40897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/blocks/table/int/tmpl/index.php"] [unique_id "al4a-puybMv3z_zMVBSsaAAAAes"]
[Mon Jul 20 06:56:26.942113 2026] [security2:error] [pid 16093:tid 16324] [client 20.48.236.161:57304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/k2.php"] [unique_id "al4a-puybMv3z_zMVBSsagAAAfM"]
[Mon Jul 20 06:56:26.942201 2026] [security2:error] [pid 16093:tid 16324] [client 20.48.236.161:57304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/k2.php"] [unique_id "al4a-puybMv3z_zMVBSsagAAAfM"]
[Mon Jul 20 06:56:27.009644 2026] [security2:error] [pid 16093:tid 16333] [client 217.142.18.172:57047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a-5uybMv3z_zMVBSsbAAAAfw"]
[Mon Jul 20 06:56:27.016679 2026] [security2:error] [pid 16093:tid 16333] [client 217.142.18.172:57047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4a-5uybMv3z_zMVBSsbAAAAfw"]
[Mon Jul 20 06:56:27.073775 2026] [security2:error] [pid 15216:tid 15384] [client 20.48.236.161:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/w.php"] [unique_id "al4a-9tIy0gkFcVddGZ0owAAATA"]
[Mon Jul 20 06:56:27.073875 2026] [security2:error] [pid 15216:tid 15384] [client 20.48.236.161:61166] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/w.php"] [unique_id "al4a-9tIy0gkFcVddGZ0owAAATA"]
[Mon Jul 20 06:56:27.077250 2026] [security2:error] [pid 15216:tid 15382] [client 104.234.53.79:52215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4a-9tIy0gkFcVddGZ0pAAAAS4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:27.152649 2026] [security2:error] [pid 16093:tid 16278] [client 14.224.227.113:54799] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4a-5uybMv3z_zMVBSsdgAAAcU"]
[Mon Jul 20 06:56:27.168416 2026] [security2:error] [pid 16093:tid 16277] [client 14.225.17.146:49283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4a-puybMv3z_zMVBSsYQAAAcQ"], referer: http://grecruit.online/2022
[Mon Jul 20 06:56:27.200821 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:51688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/fpwch.php"] [unique_id "al4a-5uybMv3z_zMVBSsfAAAAcI"]
[Mon Jul 20 06:56:27.200913 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:51688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/fpwch.php"] [unique_id "al4a-5uybMv3z_zMVBSsfAAAAcI"]
[Mon Jul 20 06:56:27.227420 2026] [security2:error] [pid 15216:tid 15444] [client 77.110.127.138:59936] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 410 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a-9tIy0gkFcVddGZ0qQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:27.232911 2026] [security2:error] [pid 16093:tid 16235] [client 194.5.53.246:49373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-l0gin.php"] [unique_id "al4a-5uybMv3z_zMVBSsfQAAAZo"]
[Mon Jul 20 06:56:27.334243 2026] [security2:error] [pid 16093:tid 16264] [client 20.48.236.161:51589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/w2025.php"] [unique_id "al4a-5uybMv3z_zMVBSsgAAAAbc"]
[Mon Jul 20 06:56:27.334350 2026] [security2:error] [pid 16093:tid 16264] [client 20.48.236.161:51589] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/w2025.php"] [unique_id "al4a-5uybMv3z_zMVBSsgAAAAbc"]
[Mon Jul 20 06:56:27.470274 2026] [security2:error] [pid 15216:tid 15436] [client 20.48.236.161:61170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/FWAZ.php"] [unique_id "al4a-9tIy0gkFcVddGZ0rwAAAWQ"]
[Mon Jul 20 06:56:27.470367 2026] [security2:error] [pid 15216:tid 15436] [client 20.48.236.161:61170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/FWAZ.php"] [unique_id "al4a-9tIy0gkFcVddGZ0rwAAAWQ"]
[Mon Jul 20 06:56:27.578665 2026] [security2:error] [pid 16093:tid 16254] [client 57.141.18.71:30356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a-ZuybMv3z_zMVBSr6QABrR4"]
[Mon Jul 20 06:56:27.580229 2026] [security2:error] [pid 16093:tid 16338] [client 194.5.53.228:34597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/js/jquery/suggest.php"] [unique_id "al4a-5uybMv3z_zMVBSsigAAAgE"]
[Mon Jul 20 06:56:27.595017 2026] [security2:error] [pid 16093:tid 16299] [client 20.48.236.161:61143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/qterm.php"] [unique_id "al4a-5uybMv3z_zMVBSsiwAAAdo"]
[Mon Jul 20 06:56:27.595107 2026] [security2:error] [pid 16093:tid 16299] [client 20.48.236.161:61143] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/qterm.php"] [unique_id "al4a-5uybMv3z_zMVBSsiwAAAdo"]
[Mon Jul 20 06:56:27.605472 2026] [security2:error] [pid 16093:tid 16286] [client 110.249.201.186:58510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/robots.txt"] [unique_id "al4a-5uybMv3z_zMVBSsjwAAAc0"]
[Mon Jul 20 06:56:27.633709 2026] [security2:error] [pid 15216:tid 15372] [client 183.82.98.154:65154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a-9tIy0gkFcVddGZ0tgAAASQ"]
[Mon Jul 20 06:56:27.633843 2026] [security2:error] [pid 15216:tid 15372] [client 183.82.98.154:65154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4a-9tIy0gkFcVddGZ0tgAAASQ"]
[Mon Jul 20 06:56:27.730493 2026] [security2:error] [pid 16093:tid 16316] [client 20.48.236.161:51660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/blurbs.php"] [unique_id "al4a-5uybMv3z_zMVBSsmgAAAes"]
[Mon Jul 20 06:56:27.730600 2026] [security2:error] [pid 16093:tid 16316] [client 20.48.236.161:51660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/blurbs.php"] [unique_id "al4a-5uybMv3z_zMVBSsmgAAAes"]
[Mon Jul 20 06:56:27.736073 2026] [security2:error] [pid 15216:tid 15439] [client 14.225.17.146:49296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4a-9tIy0gkFcVddGZ0twAAAWc"], referer: http://adultdaycarereno.com/2022
[Mon Jul 20 06:56:27.859861 2026] [security2:error] [pid 15216:tid 15359] [client 20.48.236.161:51624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/v543.php"] [unique_id "al4a-9tIy0gkFcVddGZ0uwAAARc"]
[Mon Jul 20 06:56:27.859994 2026] [security2:error] [pid 15216:tid 15359] [client 20.48.236.161:51624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/v543.php"] [unique_id "al4a-9tIy0gkFcVddGZ0uwAAARc"]
[Mon Jul 20 06:56:27.941594 2026] [security2:error] [pid 15216:tid 15424] [client 194.5.53.212:48983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/new.php"] [unique_id "al4a-9tIy0gkFcVddGZ0vwAAAVg"]
[Mon Jul 20 06:56:27.996741 2026] [security2:error] [pid 15216:tid 15379] [client 20.48.236.161:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/w3lls.php"] [unique_id "al4a-9tIy0gkFcVddGZ0xAAAASs"]
[Mon Jul 20 06:56:27.996854 2026] [security2:error] [pid 15216:tid 15379] [client 20.48.236.161:51662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/w3lls.php"] [unique_id "al4a-9tIy0gkFcVddGZ0xAAAASs"]
[Mon Jul 20 06:56:28.078554 2026] [security2:error] [pid 15216:tid 15413] [client 152.58.191.29:49030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a_NtIy0gkFcVddGZ0xgAAAU0"]
[Mon Jul 20 06:56:28.079187 2026] [security2:error] [pid 15216:tid 15413] [client 152.58.191.29:49030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4a_NtIy0gkFcVddGZ0xgAAAU0"]
[Mon Jul 20 06:56:28.279891 2026] [security2:error] [pid 15216:tid 15388] [client 14.225.17.146:62941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4a_NtIy0gkFcVddGZ0xQAAATQ"], referer: http://talknutritionwithlesley.com/2022
[Mon Jul 20 06:56:28.313991 2026] [security2:error] [pid 16093:tid 16296] [client 194.5.53.201:32781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/pwnd-1/admin.php"] [unique_id "al4a_JuybMv3z_zMVBSsvAAAAdc"]
[Mon Jul 20 06:56:28.370019 2026] [security2:error] [pid 15216:tid 15377] [client 14.225.17.146:50310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4a-dtIy0gkFcVddGZ0lQAAASk"], referer: http://overloadcomedy.com/2022
[Mon Jul 20 06:56:28.434347 2026] [core:error] [pid 16093:tid 16334] [client 14.225.17.146:60296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:56:28.434365 2026] [core:error] [pid 16093:tid 16334] [client 14.225.17.146:60296] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:56:28.505546 2026] [security2:error] [pid 16093:tid 16207] [remote 147.50.252.213:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4a_JuybMv3z_zMVBSsywABmnA"]
[Mon Jul 20 06:56:28.584947 2026] [security2:error] [pid 15216:tid 15425] [client 122.183.32.225:14991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a_NtIy0gkFcVddGZ00wAAAVk"]
[Mon Jul 20 06:56:28.585059 2026] [security2:error] [pid 15216:tid 15425] [client 122.183.32.225:14991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4a_NtIy0gkFcVddGZ00wAAAVk"]
[Mon Jul 20 06:56:28.620523 2026] [security2:error] [pid 16093:tid 16250] [client 14.225.17.146:49167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4a_JuybMv3z_zMVBSszAAAAak"], referer: http://transparentservices.online/2022
[Mon Jul 20 06:56:28.659464 2026] [security2:error] [pid 15216:tid 15437] [client 77.110.127.138:59946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_origin. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a_NtIy0gkFcVddGZ01gAAAWU"]
[Mon Jul 20 06:56:28.728909 2026] [security2:error] [pid 16093:tid 16284] [client 14.225.17.146:50277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4a_JuybMv3z_zMVBSs0wAAAcs"], referer: https://adultdaycarereno.com/2022
[Mon Jul 20 06:56:28.785700 2026] [security2:error] [pid 15216:tid 15433] [client 103.238.106.162:42753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a_NtIy0gkFcVddGZ02QAAAWE"]
[Mon Jul 20 06:56:28.785806 2026] [security2:error] [pid 15216:tid 15433] [client 103.238.106.162:42753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4a_NtIy0gkFcVddGZ02QAAAWE"]
[Mon Jul 20 06:56:28.880071 2026] [security2:error] [pid 15216:tid 15387] [client 43.153.48.240:58422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.48.153.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/fhevaluator/fhevaluator_results.php"] [unique_id "al4a_NtIy0gkFcVddGZ03AAAATM"]
[Mon Jul 20 06:56:28.911585 2026] [security2:error] [pid 16093:tid 16252] [client 194.5.53.244:41301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/defaults.php"] [unique_id "al4a_JuybMv3z_zMVBSs4AAAAas"]
[Mon Jul 20 06:56:28.933672 2026] [security2:error] [pid 16093:tid 16226] [client 14.225.17.146:49327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4a_JuybMv3z_zMVBSs1QAAAZE"], referer: http://samdothan.org/2022
[Mon Jul 20 06:56:28.947410 2026] [security2:error] [pid 15216:tid 15354] [client 20.48.236.161:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-ws68.php"] [unique_id "al4a_NtIy0gkFcVddGZ03QAAARI"]
[Mon Jul 20 06:56:28.947499 2026] [security2:error] [pid 15216:tid 15354] [client 20.48.236.161:51652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-ws68.php"] [unique_id "al4a_NtIy0gkFcVddGZ03QAAARI"]
[Mon Jul 20 06:56:29.026532 2026] [security2:error] [pid 16093:tid 16211] [remote 147.50.252.213:52704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4a_ZuybMv3z_zMVBSs6gABm3Q"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 06:56:29.253196 2026] [security2:error] [pid 16093:tid 16296] [client 104.207.51.27:36873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a_ZuybMv3z_zMVBSs9gAAAdc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:29.276777 2026] [security2:error] [pid 15216:tid 15362] [client 194.5.53.55:59671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/DJP9.php"] [unique_id "al4a_dtIy0gkFcVddGZ04QAAARo"]
[Mon Jul 20 06:56:29.409082 2026] [security2:error] [pid 16093:tid 16318] [client 77.110.127.138:59952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_ZuybMv3z_zMVBSs_gAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:29.409186 2026] [security2:error] [pid 16093:tid 16318] [client 77.110.127.138:59952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_ZuybMv3z_zMVBSs_gAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:29.642315 2026] [security2:error] [pid 15216:tid 15423] [client 194.5.53.210:59499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/customize/index.php"] [unique_id "al4a_dtIy0gkFcVddGZ08QAAAVc"]
[Mon Jul 20 06:56:29.756041 2026] [fcgid:warn] [pid 16093:tid 16271] (70014)End of file found: [client 66.132.195.116:56040] mod_fcgid: can't get data from http client
[Mon Jul 20 06:56:29.813529 2026] [security2:error] [pid 16093:tid 16310] [client 104.207.50.163:23673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a_ZuybMv3z_zMVBStGQAAAeU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:29.836722 2026] [security2:error] [pid 16093:tid 16224] [client 20.48.236.161:51690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xyn.php"] [unique_id "al4a_ZuybMv3z_zMVBStHQAAAY8"]
[Mon Jul 20 06:56:29.836845 2026] [security2:error] [pid 16093:tid 16224] [client 20.48.236.161:51690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xyn.php"] [unique_id "al4a_ZuybMv3z_zMVBStHQAAAY8"]
[Mon Jul 20 06:56:29.979498 2026] [security2:error] [pid 16093:tid 16241] [client 20.48.236.161:51702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/green3.php"] [unique_id "al4a_ZuybMv3z_zMVBStKwAAAaA"]
[Mon Jul 20 06:56:29.979594 2026] [security2:error] [pid 16093:tid 16241] [client 20.48.236.161:51702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/green3.php"] [unique_id "al4a_ZuybMv3z_zMVBStKwAAAaA"]
[Mon Jul 20 06:56:30.024287 2026] [security2:error] [pid 16093:tid 16328] [client 194.5.53.226:20427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/shell20211028.php"] [unique_id "al4a_puybMv3z_zMVBStLAAAAfc"]
[Mon Jul 20 06:56:30.143426 2026] [security2:error] [pid 15216:tid 15456] [client 20.48.236.161:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ccc.php"] [unique_id "al4a_ttIy0gkFcVddGZ0_gAAAXg"]
[Mon Jul 20 06:56:30.143543 2026] [security2:error] [pid 15216:tid 15456] [client 20.48.236.161:61150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ccc.php"] [unique_id "al4a_ttIy0gkFcVddGZ0_gAAAXg"]
[Mon Jul 20 06:56:30.158788 2026] [security2:error] [pid 16093:tid 16304] [client 77.110.127.138:59927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_puybMv3z_zMVBStNAAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.158880 2026] [security2:error] [pid 16093:tid 16304] [client 77.110.127.138:59927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_puybMv3z_zMVBStNAAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.163063 2026] [security2:error] [pid 15216:tid 15467] [client 77.110.127.138:59956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 519 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4a_ttIy0gkFcVddGZ0_wAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.177025 2026] [security2:error] [pid 16093:tid 16235] [client 50.116.65.227:29020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4a_puybMv3z_zMVBStNQAAAZo"]
[Mon Jul 20 06:56:30.187477 2026] [security2:error] [pid 16093:tid 16305] [client 50.116.65.227:29022] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4a_puybMv3z_zMVBStNgAAAeA"]
[Mon Jul 20 06:56:30.271733 2026] [security2:error] [pid 16093:tid 16291] [client 20.48.236.161:61172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/get.php"] [unique_id "al4a_puybMv3z_zMVBStOQAAAdI"]
[Mon Jul 20 06:56:30.271838 2026] [security2:error] [pid 16093:tid 16291] [client 20.48.236.161:61172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/get.php"] [unique_id "al4a_puybMv3z_zMVBStOQAAAdI"]
[Mon Jul 20 06:56:30.309720 2026] [security2:error] [pid 16093:tid 16250] [client 77.110.127.138:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_puybMv3z_zMVBStOgAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.309870 2026] [security2:error] [pid 16093:tid 16250] [client 77.110.127.138:59959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_puybMv3z_zMVBStOgAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.412980 2026] [security2:error] [pid 16093:tid 16281] [client 65.111.22.70:13467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a_puybMv3z_zMVBStPwAAAcg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:30.440448 2026] [security2:error] [pid 15216:tid 15468] [client 194.5.53.205:32461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/natural.php"] [unique_id "al4a_ttIy0gkFcVddGZ1BgAAAYQ"]
[Mon Jul 20 06:56:30.441907 2026] [security2:error] [pid 15216:tid 15365] [client 74.208.214.194:44978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4a_ttIy0gkFcVddGZ1BwAAAR0"]
[Mon Jul 20 06:56:30.447667 2026] [security2:error] [pid 15216:tid 15356] [client 20.48.236.161:61093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/images.php"] [unique_id "al4a_ttIy0gkFcVddGZ1CAAAARQ"]
[Mon Jul 20 06:56:30.447782 2026] [security2:error] [pid 15216:tid 15356] [client 20.48.236.161:61093] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/images.php"] [unique_id "al4a_ttIy0gkFcVddGZ1CAAAARQ"]
[Mon Jul 20 06:56:30.529222 2026] [security2:error] [pid 16093:tid 16263] [client 14.225.17.146:49329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4a_JuybMv3z_zMVBSs1gAAAbY"], referer: http://fineartsfactory.net/2022
[Mon Jul 20 06:56:30.567485 2026] [security2:error] [pid 16093:tid 16264] [client 192.140.149.97:45247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4a_puybMv3z_zMVBStTAAAAbc"]
[Mon Jul 20 06:56:30.567636 2026] [security2:error] [pid 16093:tid 16264] [client 192.140.149.97:45247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4a_puybMv3z_zMVBStTAAAAbc"]
[Mon Jul 20 06:56:30.635322 2026] [security2:error] [pid 16093:tid 16224] [client 20.48.236.161:51632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/alls.php"] [unique_id "al4a_puybMv3z_zMVBStUAAAAY8"]
[Mon Jul 20 06:56:30.635464 2026] [security2:error] [pid 16093:tid 16224] [client 20.48.236.161:51632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/alls.php"] [unique_id "al4a_puybMv3z_zMVBStUAAAAY8"]
[Mon Jul 20 06:56:30.644450 2026] [security2:error] [pid 15216:tid 15308] [remote 152.228.213.32:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4a_ttIy0gkFcVddGZ1DwABP1s"]
[Mon Jul 20 06:56:30.816409 2026] [security2:error] [pid 16093:tid 16302] [client 77.110.127.138:59964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_puybMv3z_zMVBStXAAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.816521 2026] [security2:error] [pid 16093:tid 16302] [client 77.110.127.138:59964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_puybMv3z_zMVBStXAAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:30.900653 2026] [security2:error] [pid 15216:tid 15255] [remote 152.228.213.32:33048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4a_ttIy0gkFcVddGZ1FAABeyY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:56:30.956366 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.47:49571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/item.php"] [unique_id "al4a_puybMv3z_zMVBStZAAAAZY"]
[Mon Jul 20 06:56:31.012179 2026] [security2:error] [pid 16093:tid 16228] [client 14.225.17.146:59937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4a_puybMv3z_zMVBStPgAAAZM"], referer: http://idigress.studio/2022
[Mon Jul 20 06:56:31.024422 2026] [security2:error] [pid 16093:tid 16236] [client 65.111.23.122:35917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4a_5uybMv3z_zMVBStZwAAAZs"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:31.162268 2026] [security2:error] [pid 15216:tid 15471] [client 20.48.236.161:61159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/coffexium.php"] [unique_id "al4a_9tIy0gkFcVddGZ1GgAAAYc"]
[Mon Jul 20 06:56:31.162404 2026] [security2:error] [pid 15216:tid 15471] [client 20.48.236.161:61159] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/coffexium.php"] [unique_id "al4a_9tIy0gkFcVddGZ1GgAAAYc"]
[Mon Jul 20 06:56:31.347423 2026] [security2:error] [pid 16093:tid 16234] [client 77.110.127.138:59932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_5uybMv3z_zMVBStgAAAAZk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:31.347531 2026] [security2:error] [pid 16093:tid 16234] [client 77.110.127.138:59932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_5uybMv3z_zMVBStgAAAAZk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:31.439798 2026] [security2:error] [pid 16093:tid 16260] [client 50.116.65.227:29042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4a_puybMv3z_zMVBStWAAAAbM"]
[Mon Jul 20 06:56:31.458606 2026] [security2:error] [pid 16093:tid 16273] [client 14.225.17.146:63339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4a_5uybMv3z_zMVBSteQAAAcA"], referer: http://thechancersband.com/2022
[Mon Jul 20 06:56:31.617864 2026] [security2:error] [pid 16093:tid 16142] [remote 110.249.202.61:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "onpoint-evsolutions.com"] [uri "/robots.txt"] [unique_id "al4a_5uybMv3z_zMVBStlwABsC8"]
[Mon Jul 20 06:56:31.678081 2026] [security2:error] [pid 15216:tid 15396] [client 20.48.236.161:51623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/red.php"] [unique_id "al4a_9tIy0gkFcVddGZ1IgAAATw"]
[Mon Jul 20 06:56:31.678230 2026] [security2:error] [pid 15216:tid 15396] [client 20.48.236.161:51623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/red.php"] [unique_id "al4a_9tIy0gkFcVddGZ1IgAAATw"]
[Mon Jul 20 06:56:31.695006 2026] [security2:error] [pid 16093:tid 16264] [client 197.186.66.42:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a_5uybMv3z_zMVBStmQAAAbc"]
[Mon Jul 20 06:56:31.695121 2026] [security2:error] [pid 16093:tid 16264] [client 197.186.66.42:58786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4a_5uybMv3z_zMVBStmQAAAbc"]
[Mon Jul 20 06:56:31.751862 2026] [security2:error] [pid 16093:tid 16307] [client 77.110.127.138:59972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_5uybMv3z_zMVBStoAAAAeI"]
[Mon Jul 20 06:56:31.751982 2026] [security2:error] [pid 16093:tid 16307] [client 77.110.127.138:59972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4a_5uybMv3z_zMVBStoAAAAeI"]
[Mon Jul 20 06:56:31.917638 2026] [security2:error] [pid 16093:tid 16285] [client 103.86.197.152:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4a_5uybMv3z_zMVBStnQABzCU"]
[Mon Jul 20 06:56:32.097893 2026] [security2:error] [pid 16093:tid 16320] [client 50.116.65.227:29076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4a_5uybMv3z_zMVBStjAAAAe8"]
[Mon Jul 20 06:56:32.165572 2026] [proxy:error] [pid 16093:tid 16256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:32.165608 2026] [proxy_http:error] [pid 16093:tid 16256] [client 20.48.236.161:61141] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:32.166053 2026] [proxy:error] [pid 16093:tid 16256] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:32.166076 2026] [proxy_http:error] [pid 16093:tid 16256] [client 20.48.236.161:61141] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:32.166143 2026] [security2:error] [pid 16093:tid 16256] [client 20.48.236.161:61141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bAJuybMv3z_zMVBStvgAAAa8"]
[Mon Jul 20 06:56:32.286374 2026] [security2:error] [pid 15216:tid 15421] [client 194.5.53.205:47487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/function/function.php"] [unique_id "al4bANtIy0gkFcVddGZ1MQAAAVU"]
[Mon Jul 20 06:56:32.308734 2026] [security2:error] [pid 16093:tid 16241] [client 66.249.65.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4bAJuybMv3z_zMVBSttwAAAaA"]
[Mon Jul 20 06:56:32.405633 2026] [security2:error] [pid 16093:tid 16264] [client 77.110.127.138:59940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bAJuybMv3z_zMVBStzQAAAbc"]
[Mon Jul 20 06:56:32.405738 2026] [security2:error] [pid 16093:tid 16264] [client 77.110.127.138:59940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bAJuybMv3z_zMVBStzQAAAbc"]
[Mon Jul 20 06:56:32.450435 2026] [security2:error] [pid 16093:tid 16236] [client 51.15.143.46:49052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4bAJuybMv3z_zMVBSt0gAAAZs"]
[Mon Jul 20 06:56:32.465734 2026] [security2:error] [pid 15216:tid 15274] [remote 124.55.178.99:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4bANtIy0gkFcVddGZ1NgABJTk"]
[Mon Jul 20 06:56:32.542606 2026] [security2:error] [pid 16093:tid 16238] [client 74.208.214.194:44986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4bAJuybMv3z_zMVBSt1gAAAZ0"]
[Mon Jul 20 06:56:32.653403 2026] [security2:error] [pid 15216:tid 15449] [client 194.5.53.194:53291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al4bANtIy0gkFcVddGZ1QQAAAXE"]
[Mon Jul 20 06:56:32.781647 2026] [security2:error] [pid 15216:tid 15438] [client 20.48.236.161:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4bANtIy0gkFcVddGZ1RgAAAWY"]
[Mon Jul 20 06:56:32.781742 2026] [security2:error] [pid 15216:tid 15438] [client 20.48.236.161:61148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4bANtIy0gkFcVddGZ1RgAAAWY"]
[Mon Jul 20 06:56:32.895351 2026] [security2:error] [pid 15216:tid 15260] [remote 124.55.178.99:36664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4bANtIy0gkFcVddGZ1RwABaCs"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:56:32.927283 2026] [security2:error] [pid 15216:tid 15287] [remote 45.90.123.233:39410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bANtIy0gkFcVddGZ1SAABHUY"]
[Mon Jul 20 06:56:32.937796 2026] [security2:error] [pid 16093:tid 16164] [remote 188.40.28.4:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bAJuybMv3z_zMVBSt5AABj0U"]
[Mon Jul 20 06:56:33.022195 2026] [security2:error] [pid 16093:tid 16268] [client 194.5.53.195:29485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/images/admin.php"] [unique_id "al4bAZuybMv3z_zMVBSt6QAAAbs"]
[Mon Jul 20 06:56:33.029879 2026] [security2:error] [pid 15216:tid 15381] [client 14.225.17.146:51512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4a_9tIy0gkFcVddGZ1JgAAAS0"], referer: http://travelbyfire.com/2022
[Mon Jul 20 06:56:33.153074 2026] [security2:error] [pid 15216:tid 15379] [client 14.225.17.146:60007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4bAdtIy0gkFcVddGZ1VQAAASs"], referer: http://inspirespublishing.com/2022
[Mon Jul 20 06:56:33.155529 2026] [security2:error] [pid 15216:tid 15280] [remote 45.90.123.233:39410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bAdtIy0gkFcVddGZ1WgABYz8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:56:33.158620 2026] [proxy:error] [pid 16093:tid 16294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:33.158662 2026] [proxy_http:error] [pid 16093:tid 16294] [client 20.48.236.161:51591] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:33.159157 2026] [proxy:error] [pid 16093:tid 16294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:33.159181 2026] [proxy_http:error] [pid 16093:tid 16294] [client 20.48.236.161:51591] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:33.159249 2026] [security2:error] [pid 16093:tid 16294] [client 20.48.236.161:51591] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bAZuybMv3z_zMVBSt7QAAAdU"]
[Mon Jul 20 06:56:33.174034 2026] [security2:error] [pid 16093:tid 16320] [client 98.159.234.160:26869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bAZuybMv3z_zMVBSt7gAAAe8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:56:33.204129 2026] [security2:error] [pid 15216:tid 15429] [client 187.108.85.186:57204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bAdtIy0gkFcVddGZ1YgAAAV0"]
[Mon Jul 20 06:56:33.204235 2026] [security2:error] [pid 15216:tid 15429] [client 187.108.85.186:57204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bAdtIy0gkFcVddGZ1YgAAAV0"]
[Mon Jul 20 06:56:33.234966 2026] [security2:error] [pid 16093:tid 16182] [remote 188.40.28.4:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bAZuybMv3z_zMVBSt8AACAFc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:56:33.335536 2026] [proxy:error] [pid 15216:tid 15395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:33.335610 2026] [proxy_http:error] [pid 15216:tid 15395] [client 20.48.236.161:61110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:33.336262 2026] [proxy:error] [pid 15216:tid 15395] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:33.336298 2026] [proxy_http:error] [pid 15216:tid 15395] [client 20.48.236.161:61110] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:33.336391 2026] [security2:error] [pid 15216:tid 15395] [client 20.48.236.161:61110] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bAdtIy0gkFcVddGZ1ZgAAATs"]
[Mon Jul 20 06:56:33.465892 2026] [security2:error] [pid 16093:tid 16249] [client 57.141.18.47:38694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4a_5uybMv3z_zMVBStnwABqCs"]
[Mon Jul 20 06:56:33.471996 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/index.php"] [unique_id "al4bAZuybMv3z_zMVBSt_gAAAgM"]
[Mon Jul 20 06:56:33.472126 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:51670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/index.php"] [unique_id "al4bAZuybMv3z_zMVBSt_gAAAgM"]
[Mon Jul 20 06:56:33.495536 2026] [security2:error] [pid 16093:tid 16291] [client 194.5.53.207:35165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/theme-compat/about.php"] [unique_id "al4bAZuybMv3z_zMVBSt_wAAAdI"]
[Mon Jul 20 06:56:33.742667 2026] [security2:error] [pid 16093:tid 16286] [client 20.48.236.161:51601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/admin.php"] [unique_id "al4bAZuybMv3z_zMVBSuDQAAAc0"]
[Mon Jul 20 06:56:33.742775 2026] [security2:error] [pid 16093:tid 16286] [client 20.48.236.161:51601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/admin.php"] [unique_id "al4bAZuybMv3z_zMVBSuDQAAAc0"]
[Mon Jul 20 06:56:33.906361 2026] [security2:error] [pid 16093:tid 16347] [client 194.5.53.226:47567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/about/function.php"] [unique_id "al4bAZuybMv3z_zMVBSuGQAAAgo"]
[Mon Jul 20 06:56:33.907797 2026] [security2:error] [pid 16093:tid 16260] [client 20.48.236.161:61171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/177.php"] [unique_id "al4bAZuybMv3z_zMVBSuGgAAAbM"]
[Mon Jul 20 06:56:33.907874 2026] [security2:error] [pid 16093:tid 16260] [client 20.48.236.161:61171] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/177.php"] [unique_id "al4bAZuybMv3z_zMVBSuGgAAAbM"]
[Mon Jul 20 06:56:33.938964 2026] [security2:error] [pid 16093:tid 16300] [client 14.225.17.146:56400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4bAZuybMv3z_zMVBSuFgAAAds"], referer: https://travelbyfire.com/2022
[Mon Jul 20 06:56:34.047527 2026] [security2:error] [pid 16093:tid 16266] [client 20.48.236.161:51658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/199.php"] [unique_id "al4bApuybMv3z_zMVBSuIgAAAbk"]
[Mon Jul 20 06:56:34.047620 2026] [security2:error] [pid 16093:tid 16266] [client 20.48.236.161:51658] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/199.php"] [unique_id "al4bApuybMv3z_zMVBSuIgAAAbk"]
[Mon Jul 20 06:56:34.200465 2026] [security2:error] [pid 16093:tid 16254] [client 20.48.236.161:51651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file52.php"] [unique_id "al4bApuybMv3z_zMVBSuLQAAAa0"]
[Mon Jul 20 06:56:34.200567 2026] [security2:error] [pid 16093:tid 16254] [client 20.48.236.161:51651] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file52.php"] [unique_id "al4bApuybMv3z_zMVBSuLQAAAa0"]
[Mon Jul 20 06:56:34.205843 2026] [security2:error] [pid 16093:tid 16325] [client 103.144.65.217:61827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bApuybMv3z_zMVBSuLAAAAfQ"]
[Mon Jul 20 06:56:34.205970 2026] [security2:error] [pid 16093:tid 16325] [client 103.144.65.217:61827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bApuybMv3z_zMVBSuLAAAAfQ"]
[Mon Jul 20 06:56:34.262391 2026] [security2:error] [pid 16093:tid 16338] [client 50.116.65.227:29116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bApuybMv3z_zMVBSuLwAAAgE"]
[Mon Jul 20 06:56:34.272467 2026] [security2:error] [pid 16093:tid 16340] [client 50.116.65.227:29124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bApuybMv3z_zMVBSuMAAAAgM"]
[Mon Jul 20 06:56:34.324139 2026] [security2:error] [pid 15216:tid 15468] [client 20.48.236.161:57333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/geck.php"] [unique_id "al4bAttIy0gkFcVddGZ1fwAAAYQ"]
[Mon Jul 20 06:56:34.324250 2026] [security2:error] [pid 15216:tid 15468] [client 20.48.236.161:57333] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/geck.php"] [unique_id "al4bAttIy0gkFcVddGZ1fwAAAYQ"]
[Mon Jul 20 06:56:34.457252 2026] [security2:error] [pid 15216:tid 15459] [client 20.48.236.161:51612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/biufile.php"] [unique_id "al4bAttIy0gkFcVddGZ1hgAAAXs"]
[Mon Jul 20 06:56:34.457373 2026] [security2:error] [pid 15216:tid 15459] [client 20.48.236.161:51612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/biufile.php"] [unique_id "al4bAttIy0gkFcVddGZ1hgAAAXs"]
[Mon Jul 20 06:56:34.581963 2026] [security2:error] [pid 16093:tid 16256] [client 117.222.139.248:64163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bApuybMv3z_zMVBSuNgAAAa8"]
[Mon Jul 20 06:56:34.582149 2026] [security2:error] [pid 16093:tid 16256] [client 117.222.139.248:64163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bApuybMv3z_zMVBSuNgAAAa8"]
[Mon Jul 20 06:56:34.592553 2026] [security2:error] [pid 16093:tid 16267] [client 20.48.236.161:51706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/mosty.php"] [unique_id "al4bApuybMv3z_zMVBSuNwAAAbo"]
[Mon Jul 20 06:56:34.592652 2026] [security2:error] [pid 16093:tid 16267] [client 20.48.236.161:51706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/mosty.php"] [unique_id "al4bApuybMv3z_zMVBSuNwAAAbo"]
[Mon Jul 20 06:56:34.742518 2026] [security2:error] [pid 16093:tid 16313] [client 20.48.236.161:51625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/dejavu.php"] [unique_id "al4bApuybMv3z_zMVBSuSgAAAeg"]
[Mon Jul 20 06:56:34.742603 2026] [security2:error] [pid 16093:tid 16313] [client 20.48.236.161:51625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/dejavu.php"] [unique_id "al4bApuybMv3z_zMVBSuSgAAAeg"]
[Mon Jul 20 06:56:34.868581 2026] [security2:error] [pid 16093:tid 16339] [client 20.48.236.161:51699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/aaf.php"] [unique_id "al4bApuybMv3z_zMVBSuTQAAAgI"]
[Mon Jul 20 06:56:34.868661 2026] [security2:error] [pid 16093:tid 16339] [client 20.48.236.161:51699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/aaf.php"] [unique_id "al4bApuybMv3z_zMVBSuTQAAAgI"]
[Mon Jul 20 06:56:35.066718 2026] [security2:error] [pid 16093:tid 16320] [client 20.48.236.161:51684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ha.php"] [unique_id "al4bA5uybMv3z_zMVBSuVgAAAe8"]
[Mon Jul 20 06:56:35.066833 2026] [security2:error] [pid 16093:tid 16320] [client 20.48.236.161:51684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ha.php"] [unique_id "al4bA5uybMv3z_zMVBSuVgAAAe8"]
[Mon Jul 20 06:56:35.154423 2026] [security2:error] [pid 15216:tid 15395] [client 194.5.53.245:44607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/Requests/index.php"] [unique_id "al4bA9tIy0gkFcVddGZ1mQAAATs"]
[Mon Jul 20 06:56:35.255364 2026] [security2:error] [pid 16093:tid 16345] [client 20.48.236.161:51604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/hur.php"] [unique_id "al4bA5uybMv3z_zMVBSuZwAAAgg"]
[Mon Jul 20 06:56:35.255458 2026] [security2:error] [pid 16093:tid 16345] [client 20.48.236.161:51604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/hur.php"] [unique_id "al4bA5uybMv3z_zMVBSuZwAAAgg"]
[Mon Jul 20 06:56:35.419187 2026] [security2:error] [pid 16093:tid 16283] [client 20.48.236.161:51677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/h02ugyh.php"] [unique_id "al4bA5uybMv3z_zMVBSubgAAAco"]
[Mon Jul 20 06:56:35.419302 2026] [security2:error] [pid 16093:tid 16283] [client 20.48.236.161:51677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/h02ugyh.php"] [unique_id "al4bA5uybMv3z_zMVBSubgAAAco"]
[Mon Jul 20 06:56:35.464244 2026] [security2:error] [pid 16093:tid 16227] [client 57.141.18.48:53798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bApuybMv3z_zMVBSuJAABkik"]
[Mon Jul 20 06:56:35.506886 2026] [security2:error] [pid 16093:tid 16315] [client 23.251.146.115:2432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bA5uybMv3z_zMVBSubQAB6gM"]
[Mon Jul 20 06:56:35.537615 2026] [security2:error] [pid 16093:tid 16281] [client 23.251.146.115:43136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bA5uybMv3z_zMVBSucAAByHQ"]
[Mon Jul 20 06:56:35.554716 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:51606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/155.php"] [unique_id "al4bA5uybMv3z_zMVBSudQAAAdw"]
[Mon Jul 20 06:56:35.554841 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:51606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/155.php"] [unique_id "al4bA5uybMv3z_zMVBSudQAAAdw"]
[Mon Jul 20 06:56:35.617329 2026] [security2:error] [pid 16093:tid 16262] [client 23.251.146.115:2432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bA5uybMv3z_zMVBSudAABtXo"]
[Mon Jul 20 06:56:35.655120 2026] [security2:error] [pid 16093:tid 16332] [client 23.251.146.115:43136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bA5uybMv3z_zMVBSudgAB-3w"]
[Mon Jul 20 06:56:35.682993 2026] [security2:error] [pid 15216:tid 15446] [client 20.48.236.161:57282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/pp.php"] [unique_id "al4bA9tIy0gkFcVddGZ1qQAAAW4"]
[Mon Jul 20 06:56:35.683140 2026] [security2:error] [pid 15216:tid 15446] [client 20.48.236.161:57282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/pp.php"] [unique_id "al4bA9tIy0gkFcVddGZ1qQAAAW4"]
[Mon Jul 20 06:56:35.786623 2026] [security2:error] [pid 16093:tid 16292] [client 194.5.53.218:64839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/ID3/about.php/wp-content/x/index.php"] [unique_id "al4bA5uybMv3z_zMVBSufgAAAdM"]
[Mon Jul 20 06:56:35.797932 2026] [autoindex:error] [pid 15216:tid 15338] [remote 80.85.247.231:58562] AH01276: Cannot serve directory /home1/uritemsn/public_html/aljosour-alarabia-net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://ALJOSOUR-ALARABIA.NET
[Mon Jul 20 06:56:35.814708 2026] [security2:error] [pid 15216:tid 15404] [client 20.48.236.161:61137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ops.php"] [unique_id "al4bA9tIy0gkFcVddGZ1sAAAAUQ"]
[Mon Jul 20 06:56:35.814790 2026] [security2:error] [pid 15216:tid 15404] [client 20.48.236.161:61137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ops.php"] [unique_id "al4bA9tIy0gkFcVddGZ1sAAAAUQ"]
[Mon Jul 20 06:56:35.938869 2026] [security2:error] [pid 16093:tid 16277] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bA5uybMv3z_zMVBSuiQAAAcQ"]
[Mon Jul 20 06:56:35.958729 2026] [security2:error] [pid 16093:tid 16314] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bA5uybMv3z_zMVBSuiwAAAek"]
[Mon Jul 20 06:56:36.021185 2026] [security2:error] [pid 15216:tid 15427] [client 20.48.236.161:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ingfo.php"] [unique_id "al4bBNtIy0gkFcVddGZ1tQAAAVs"]
[Mon Jul 20 06:56:36.021287 2026] [security2:error] [pid 15216:tid 15427] [client 20.48.236.161:51638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ingfo.php"] [unique_id "al4bBNtIy0gkFcVddGZ1tQAAAVs"]
[Mon Jul 20 06:56:36.129010 2026] [security2:error] [pid 15216:tid 15314] [remote 31.207.36.13:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bBNtIy0gkFcVddGZ1uAABN2E"]
[Mon Jul 20 06:56:36.175867 2026] [security2:error] [pid 16093:tid 16296] [client 20.48.236.161:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/error_log.php"] [unique_id "al4bBJuybMv3z_zMVBSupgAAAdc"]
[Mon Jul 20 06:56:36.175978 2026] [security2:error] [pid 16093:tid 16296] [client 20.48.236.161:61087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/error_log.php"] [unique_id "al4bBJuybMv3z_zMVBSupgAAAdc"]
[Mon Jul 20 06:56:36.216005 2026] [security2:error] [pid 16093:tid 16267] [client 194.5.53.54:30255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4bBJuybMv3z_zMVBSuqQAAAbo"]
[Mon Jul 20 06:56:36.238409 2026] [security2:error] [pid 16093:tid 16099] [remote 130.185.118.215:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bBJuybMv3z_zMVBSuqgACAwQ"]
[Mon Jul 20 06:56:36.332629 2026] [security2:error] [pid 15216:tid 15431] [client 20.48.236.161:51675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/test10.php"] [unique_id "al4bBNtIy0gkFcVddGZ1vwAAAV8"]
[Mon Jul 20 06:56:36.332726 2026] [security2:error] [pid 15216:tid 15431] [client 20.48.236.161:51675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/test10.php"] [unique_id "al4bBNtIy0gkFcVddGZ1vwAAAV8"]
[Mon Jul 20 06:56:36.351942 2026] [security2:error] [pid 15216:tid 15329] [remote 31.207.36.13:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bBNtIy0gkFcVddGZ1wQABMnA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:56:36.420800 2026] [security2:error] [pid 16093:tid 16104] [remote 130.185.118.215:60900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bBJuybMv3z_zMVBSutAABswk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:56:36.459652 2026] [security2:error] [pid 16093:tid 16293] [client 103.125.179.95:53250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bBJuybMv3z_zMVBSutwAAAdQ"]
[Mon Jul 20 06:56:36.459767 2026] [security2:error] [pid 16093:tid 16293] [client 103.125.179.95:53250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bBJuybMv3z_zMVBSutwAAAdQ"]
[Mon Jul 20 06:56:36.480313 2026] [security2:error] [pid 16093:tid 16300] [client 20.48.236.161:57310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/koala.php"] [unique_id "al4bBJuybMv3z_zMVBSuuAAAAds"]
[Mon Jul 20 06:56:36.480381 2026] [security2:error] [pid 16093:tid 16300] [client 20.48.236.161:57310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/koala.php"] [unique_id "al4bBJuybMv3z_zMVBSuuAAAAds"]
[Mon Jul 20 06:56:36.566298 2026] [security2:error] [pid 16093:tid 16259] [client 194.5.53.248:63349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/languages/404.php"] [unique_id "al4bBJuybMv3z_zMVBSuugAAAbI"]
[Mon Jul 20 06:56:36.603342 2026] [security2:error] [pid 15216:tid 15352] [client 20.48.236.161:51639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/mac.php"] [unique_id "al4bBNtIy0gkFcVddGZ1wgAAARA"]
[Mon Jul 20 06:56:36.603432 2026] [security2:error] [pid 15216:tid 15352] [client 20.48.236.161:51639] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/mac.php"] [unique_id "al4bBNtIy0gkFcVddGZ1wgAAARA"]
[Mon Jul 20 06:56:36.727421 2026] [security2:error] [pid 15216:tid 15461] [client 20.48.236.161:51597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wefile.php"] [unique_id "al4bBNtIy0gkFcVddGZ1xgAAAX0"]
[Mon Jul 20 06:56:36.727533 2026] [security2:error] [pid 15216:tid 15461] [client 20.48.236.161:51597] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wefile.php"] [unique_id "al4bBNtIy0gkFcVddGZ1xgAAAX0"]
[Mon Jul 20 06:56:36.795556 2026] [security2:error] [pid 15216:tid 15358] [client 77.110.127.138:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bBNtIy0gkFcVddGZ1yQAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:36.795655 2026] [security2:error] [pid 15216:tid 15358] [client 77.110.127.138:59987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bBNtIy0gkFcVddGZ1yQAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:36.870711 2026] [proxy:error] [pid 15216:tid 15462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:36.870802 2026] [proxy_http:error] [pid 15216:tid 15462] [client 20.48.236.161:51590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:36.871390 2026] [proxy:error] [pid 15216:tid 15462] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:36.871418 2026] [proxy_http:error] [pid 15216:tid 15462] [client 20.48.236.161:51590] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:36.871513 2026] [security2:error] [pid 15216:tid 15462] [client 20.48.236.161:51590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bBNtIy0gkFcVddGZ1ywAAAX4"]
[Mon Jul 20 06:56:36.887527 2026] [security2:error] [pid 16093:tid 16256] [client 194.5.53.224:61273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/update/403.php"] [unique_id "al4bBJuybMv3z_zMVBSuzgAAAa8"]
[Mon Jul 20 06:56:37.028486 2026] [proxy:error] [pid 16093:tid 16301] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:37.028570 2026] [proxy_http:error] [pid 16093:tid 16301] [client 20.48.236.161:51616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:37.029807 2026] [proxy:error] [pid 16093:tid 16301] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:37.029875 2026] [proxy_http:error] [pid 16093:tid 16301] [client 20.48.236.161:51616] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:37.029994 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:51616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bBZuybMv3z_zMVBSu2wAAAdw"]
[Mon Jul 20 06:56:37.101421 2026] [security2:error] [pid 15216:tid 15472] [client 14.225.17.146:58939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4bBNtIy0gkFcVddGZ1twAAAYg"], referer: http://entuvy.com/2022
[Mon Jul 20 06:56:37.171300 2026] [security2:error] [pid 16093:tid 16254] [client 87.199.199.98:56642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-comments-post.php"] [unique_id "al4bBZuybMv3z_zMVBSu4AAAAa0"], referer: https://giftsurprizo.com/product/wreath-pearl-sakura-rabbit-keychain-bag-pendant-diy-gift-u-disk-pendant-female-gift/?v=84de8e2b14bb
[Mon Jul 20 06:56:37.171431 2026] [security2:error] [pid 16093:tid 16254] [client 87.199.199.98:56642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "giftsurprizo.com"] [uri "/wp-comments-post.php"] [unique_id "al4bBZuybMv3z_zMVBSu4AAAAa0"], referer: https://giftsurprizo.com/product/wreath-pearl-sakura-rabbit-keychain-bag-pendant-diy-gift-u-disk-pendant-female-gift/?v=84de8e2b14bb
[Mon Jul 20 06:56:37.183975 2026] [security2:error] [pid 15216:tid 15408] [client 20.48.236.161:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/makeasmtp.php"] [unique_id "al4bBdtIy0gkFcVddGZ11AAAAUg"]
[Mon Jul 20 06:56:37.184078 2026] [security2:error] [pid 15216:tid 15408] [client 20.48.236.161:57288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/makeasmtp.php"] [unique_id "al4bBdtIy0gkFcVddGZ11AAAAUg"]
[Mon Jul 20 06:56:37.221796 2026] [security2:error] [pid 15216:tid 15390] [client 14.225.17.146:59946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4bA9tIy0gkFcVddGZ1rwAAATY"], referer: http://bbwipartnerconference.com/2022
[Mon Jul 20 06:56:37.240226 2026] [security2:error] [pid 16093:tid 16260] [client 23.251.146.115:4160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bBZuybMv3z_zMVBSu4wABsxo"]
[Mon Jul 20 06:56:37.271272 2026] [security2:error] [pid 16093:tid 16233] [client 117.247.108.24:22941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bBZuybMv3z_zMVBSu7gAAAZg"]
[Mon Jul 20 06:56:37.271371 2026] [security2:error] [pid 16093:tid 16233] [client 117.247.108.24:22941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bBZuybMv3z_zMVBSu7gAAAZg"]
[Mon Jul 20 06:56:37.273647 2026] [security2:error] [pid 15216:tid 15367] [client 23.251.146.115:12320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bBdtIy0gkFcVddGZ11QABH2Y"]
[Mon Jul 20 06:56:37.328217 2026] [security2:error] [pid 15216:tid 15445] [client 20.48.236.161:51646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/2P.php"] [unique_id "al4bBdtIy0gkFcVddGZ13gAAAW0"]
[Mon Jul 20 06:56:37.328328 2026] [security2:error] [pid 15216:tid 15445] [client 20.48.236.161:51646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/2P.php"] [unique_id "al4bBdtIy0gkFcVddGZ13gAAAW0"]
[Mon Jul 20 06:56:37.365601 2026] [security2:error] [pid 16093:tid 16302] [client 23.251.146.115:4160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bBZuybMv3z_zMVBSu8AAB3SQ"]
[Mon Jul 20 06:56:37.387622 2026] [security2:error] [pid 15216:tid 15438] [client 23.251.146.115:12320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bBdtIy0gkFcVddGZ13AABZmc"]
[Mon Jul 20 06:56:37.454009 2026] [security2:error] [pid 16093:tid 16282] [client 104.234.53.68:32963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bBZuybMv3z_zMVBSu-gAAAck"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:37.479219 2026] [security2:error] [pid 16093:tid 16283] [client 20.48.236.161:61096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/.well-known/about.php"] [unique_id "al4bBZuybMv3z_zMVBSu_QAAAco"]
[Mon Jul 20 06:56:37.479334 2026] [security2:error] [pid 16093:tid 16283] [client 20.48.236.161:61096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/.well-known/about.php"] [unique_id "al4bBZuybMv3z_zMVBSu_QAAAco"]
[Mon Jul 20 06:56:37.533445 2026] [security2:error] [pid 16093:tid 16257] [client 194.5.53.226:31677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/default.php"] [unique_id "al4bBZuybMv3z_zMVBSvAAAAAbA"]
[Mon Jul 20 06:56:37.565915 2026] [security2:error] [pid 15216:tid 15434] [client 217.142.18.172:3776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bBdtIy0gkFcVddGZ15AAAAWI"]
[Mon Jul 20 06:56:37.566042 2026] [security2:error] [pid 15216:tid 15434] [client 217.142.18.172:3776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bBdtIy0gkFcVddGZ15AAAAWI"]
[Mon Jul 20 06:56:37.628800 2026] [security2:error] [pid 15216:tid 15353] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bBdtIy0gkFcVddGZ15QAAARE"]
[Mon Jul 20 06:56:37.632186 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:61157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4bBZuybMv3z_zMVBSvBAAAAZ8"]
[Mon Jul 20 06:56:37.632340 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:61157] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4bBZuybMv3z_zMVBSvBAAAAZ8"]
[Mon Jul 20 06:56:37.688915 2026] [security2:error] [pid 15216:tid 15404] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bBdtIy0gkFcVddGZ17AAAAUQ"]
[Mon Jul 20 06:56:37.761319 2026] [security2:error] [pid 16093:tid 16332] [client 20.48.236.161:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/system_log.php"] [unique_id "al4bBZuybMv3z_zMVBSvDQAAAfs"]
[Mon Jul 20 06:56:37.761404 2026] [security2:error] [pid 16093:tid 16332] [client 20.48.236.161:51613] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/system_log.php"] [unique_id "al4bBZuybMv3z_zMVBSvDQAAAfs"]
[Mon Jul 20 06:56:37.814454 2026] [security2:error] [pid 15216:tid 15362] [client 122.183.32.225:1209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bBdtIy0gkFcVddGZ19QAAARo"]
[Mon Jul 20 06:56:37.819409 2026] [security2:error] [pid 15216:tid 15362] [client 122.183.32.225:1209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bBdtIy0gkFcVddGZ19QAAARo"]
[Mon Jul 20 06:56:37.846309 2026] [security2:error] [pid 15216:tid 15440] [client 57.141.18.26:62070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bBNtIy0gkFcVddGZ1vQABaGQ"]
[Mon Jul 20 06:56:37.846857 2026] [security2:error] [pid 15216:tid 15470] [client 66.249.73.169:59147] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.legallyknownaszacharyhoy999.online"] [uri "/robots.txt"] [unique_id "al4bBdtIy0gkFcVddGZ1-AAAAYY"]
[Mon Jul 20 06:56:37.892207 2026] [proxy:error] [pid 16093:tid 16313] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:37.892273 2026] [proxy_http:error] [pid 16093:tid 16313] [client 20.48.236.161:61160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:37.892728 2026] [proxy:error] [pid 16093:tid 16313] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:37.892773 2026] [proxy_http:error] [pid 16093:tid 16313] [client 20.48.236.161:61160] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:37.892853 2026] [security2:error] [pid 16093:tid 16313] [client 20.48.236.161:61160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bBZuybMv3z_zMVBSvGAAAAeg"]
[Mon Jul 20 06:56:37.954985 2026] [security2:error] [pid 16093:tid 16266] [client 194.5.53.222:37355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/assets/info.php"] [unique_id "al4bBZuybMv3z_zMVBSvHwAAAbk"]
[Mon Jul 20 06:56:38.051199 2026] [proxy:error] [pid 15216:tid 15424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:38.051274 2026] [proxy_http:error] [pid 15216:tid 15424] [client 20.48.236.161:61167] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:38.051954 2026] [proxy:error] [pid 15216:tid 15424] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:38.051992 2026] [proxy_http:error] [pid 15216:tid 15424] [client 20.48.236.161:61167] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:38.052088 2026] [security2:error] [pid 15216:tid 15424] [client 20.48.236.161:61167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bBttIy0gkFcVddGZ1_AAAAVg"]
[Mon Jul 20 06:56:38.173944 2026] [security2:error] [pid 16093:tid 16232] [client 20.48.236.161:51608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/crgio.php"] [unique_id "al4bBpuybMv3z_zMVBSvKwAAAZc"]
[Mon Jul 20 06:56:38.174050 2026] [security2:error] [pid 16093:tid 16232] [client 20.48.236.161:51608] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/crgio.php"] [unique_id "al4bBpuybMv3z_zMVBSvKwAAAZc"]
[Mon Jul 20 06:56:38.306819 2026] [security2:error] [pid 15216:tid 15365] [client 20.48.236.161:51607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/pucci.php"] [unique_id "al4bBttIy0gkFcVddGZ1_gAAAR0"]
[Mon Jul 20 06:56:38.306917 2026] [security2:error] [pid 15216:tid 15365] [client 20.48.236.161:51607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/pucci.php"] [unique_id "al4bBttIy0gkFcVddGZ1_gAAAR0"]
[Mon Jul 20 06:56:38.347272 2026] [security2:error] [pid 16093:tid 16252] [client 183.82.98.154:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bBpuybMv3z_zMVBSvMwAAAas"]
[Mon Jul 20 06:56:38.347902 2026] [security2:error] [pid 16093:tid 16252] [client 183.82.98.154:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bBpuybMv3z_zMVBSvMwAAAas"]
[Mon Jul 20 06:56:38.511288 2026] [proxy:error] [pid 15216:tid 15452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:38.511356 2026] [proxy_http:error] [pid 15216:tid 15452] [client 20.48.236.161:61146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:38.512005 2026] [proxy:error] [pid 15216:tid 15452] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:38.512050 2026] [proxy_http:error] [pid 15216:tid 15452] [client 20.48.236.161:61146] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:38.512126 2026] [security2:error] [pid 15216:tid 15452] [client 20.48.236.161:61146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bBttIy0gkFcVddGZ2AQAAAXQ"]
[Mon Jul 20 06:56:38.641274 2026] [proxy:error] [pid 15216:tid 15448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:38.641344 2026] [proxy_http:error] [pid 15216:tid 15448] [client 20.48.236.161:57262] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:38.641815 2026] [proxy:error] [pid 15216:tid 15448] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:38.641850 2026] [proxy_http:error] [pid 15216:tid 15448] [client 20.48.236.161:57262] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:38.641925 2026] [security2:error] [pid 15216:tid 15448] [client 20.48.236.161:57262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bBttIy0gkFcVddGZ2AwAAAXA"]
[Mon Jul 20 06:56:38.731920 2026] [security2:error] [pid 16093:tid 16268] [client 77.110.127.138:59996] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bBpuybMv3z_zMVBSvWQAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:38.772539 2026] [security2:error] [pid 16093:tid 16225] [client 20.48.236.161:61144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-temp.php"] [unique_id "al4bBpuybMv3z_zMVBSvXAAAAZA"]
[Mon Jul 20 06:56:38.772651 2026] [security2:error] [pid 16093:tid 16225] [client 20.48.236.161:61144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-temp.php"] [unique_id "al4bBpuybMv3z_zMVBSvXAAAAZA"]
[Mon Jul 20 06:56:38.819328 2026] [security2:error] [pid 16093:tid 16334] [client 152.58.191.29:55305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bBpuybMv3z_zMVBSvXwAAAf0"]
[Mon Jul 20 06:56:38.819412 2026] [security2:error] [pid 16093:tid 16334] [client 152.58.191.29:55305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bBpuybMv3z_zMVBSvXwAAAf0"]
[Mon Jul 20 06:56:38.907056 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:61057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-admin/js/index.php"] [unique_id "al4bBpuybMv3z_zMVBSvYwAAAgM"]
[Mon Jul 20 06:56:38.907174 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:61057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-admin/js/index.php"] [unique_id "al4bBpuybMv3z_zMVBSvYwAAAgM"]
[Mon Jul 20 06:56:39.038252 2026] [security2:error] [pid 16093:tid 16343] [client 20.48.236.161:51617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/puc.php"] [unique_id "al4bB5uybMv3z_zMVBSvcQAAAgY"]
[Mon Jul 20 06:56:39.038349 2026] [security2:error] [pid 16093:tid 16343] [client 20.48.236.161:51617] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/puc.php"] [unique_id "al4bB5uybMv3z_zMVBSvcQAAAgY"]
[Mon Jul 20 06:56:39.214808 2026] [security2:error] [pid 16093:tid 16260] [client 20.48.236.161:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/dx.php"] [unique_id "al4bB5uybMv3z_zMVBSvegAAAbM"]
[Mon Jul 20 06:56:39.214918 2026] [security2:error] [pid 16093:tid 16260] [client 20.48.236.161:51692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/dx.php"] [unique_id "al4bB5uybMv3z_zMVBSvegAAAbM"]
[Mon Jul 20 06:56:39.380269 2026] [proxy:error] [pid 16093:tid 16304] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:39.380352 2026] [proxy_http:error] [pid 16093:tid 16304] [client 20.48.236.161:57294] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:39.381081 2026] [proxy:error] [pid 16093:tid 16304] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:39.381116 2026] [proxy_http:error] [pid 16093:tid 16304] [client 20.48.236.161:57294] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:39.381209 2026] [security2:error] [pid 16093:tid 16304] [client 20.48.236.161:57294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bB5uybMv3z_zMVBSvgQAAAd8"]
[Mon Jul 20 06:56:39.466890 2026] [security2:error] [pid 16093:tid 16278] [client 103.238.106.162:60540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bB5uybMv3z_zMVBSvhwAAAcU"]
[Mon Jul 20 06:56:39.466977 2026] [security2:error] [pid 16093:tid 16278] [client 103.238.106.162:60540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bB5uybMv3z_zMVBSvhwAAAcU"]
[Mon Jul 20 06:56:39.583132 2026] [security2:error] [pid 16093:tid 16239] [client 20.48.236.161:51708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/bthil.php"] [unique_id "al4bB5uybMv3z_zMVBSvkwAAAZ4"]
[Mon Jul 20 06:56:39.583282 2026] [security2:error] [pid 16093:tid 16239] [client 20.48.236.161:51708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/bthil.php"] [unique_id "al4bB5uybMv3z_zMVBSvkwAAAZ4"]
[Mon Jul 20 06:56:39.767167 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/7.php"] [unique_id "al4bB5uybMv3z_zMVBSvoAAAAgM"]
[Mon Jul 20 06:56:39.767314 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:61075] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/7.php"] [unique_id "al4bB5uybMv3z_zMVBSvoAAAAgM"]
[Mon Jul 20 06:56:39.791977 2026] [security2:error] [pid 16093:tid 16259] [client 14.225.17.146:59994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4bB5uybMv3z_zMVBSvfAAAAbI"], referer: http://idigress.group/2022
[Mon Jul 20 06:56:39.816506 2026] [security2:error] [pid 16093:tid 16268] [client 14.225.17.146:61750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4bB5uybMv3z_zMVBSvmAAAAbs"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2022
[Mon Jul 20 06:56:39.914257 2026] [security2:error] [pid 16093:tid 16250] [client 20.48.236.161:61180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/8.php"] [unique_id "al4bB5uybMv3z_zMVBSvrAAAAak"]
[Mon Jul 20 06:56:39.914343 2026] [security2:error] [pid 16093:tid 16250] [client 20.48.236.161:61180] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/8.php"] [unique_id "al4bB5uybMv3z_zMVBSvrAAAAak"]
[Mon Jul 20 06:56:39.920074 2026] [security2:error] [pid 16093:tid 16321] [client 104.234.53.81:44457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bB5uybMv3z_zMVBSvrQAAAfA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:39.966303 2026] [security2:error] [pid 16093:tid 16253] [client 57.141.18.18:23348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bBpuybMv3z_zMVBSvSAABrCw"]
[Mon Jul 20 06:56:40.067324 2026] [security2:error] [pid 15216:tid 15396] [client 20.48.236.161:61085] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcalendars.musichaven.info"] [uri "/1.php"] [unique_id "al4bCNtIy0gkFcVddGZ2HwAAATw"]
[Mon Jul 20 06:56:40.067445 2026] [security2:error] [pid 15216:tid 15396] [client 20.48.236.161:61085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/1.php"] [unique_id "al4bCNtIy0gkFcVddGZ2HwAAATw"]
[Mon Jul 20 06:56:40.067545 2026] [security2:error] [pid 15216:tid 15396] [client 20.48.236.161:61085] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/1.php"] [unique_id "al4bCNtIy0gkFcVddGZ2HwAAATw"]
[Mon Jul 20 06:56:40.219371 2026] [security2:error] [pid 16093:tid 16349] [client 20.48.236.161:51654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/100.php"] [unique_id "al4bCJuybMv3z_zMVBSvvAAAAgw"]
[Mon Jul 20 06:56:40.219459 2026] [security2:error] [pid 16093:tid 16349] [client 20.48.236.161:51654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/100.php"] [unique_id "al4bCJuybMv3z_zMVBSvvAAAAgw"]
[Mon Jul 20 06:56:40.427042 2026] [security2:error] [pid 15216:tid 15427] [client 20.48.236.161:61102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/about.php"] [unique_id "al4bCNtIy0gkFcVddGZ2JQAAAVs"]
[Mon Jul 20 06:56:40.427121 2026] [security2:error] [pid 15216:tid 15427] [client 20.48.236.161:61102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/about.php"] [unique_id "al4bCNtIy0gkFcVddGZ2JQAAAVs"]
[Mon Jul 20 06:56:40.556244 2026] [security2:error] [pid 15216:tid 15473] [client 20.48.236.161:51592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/admin.php"] [unique_id "al4bCNtIy0gkFcVddGZ2KQAAAYk"]
[Mon Jul 20 06:56:40.556343 2026] [security2:error] [pid 15216:tid 15473] [client 20.48.236.161:51592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/admin.php"] [unique_id "al4bCNtIy0gkFcVddGZ2KQAAAYk"]
[Mon Jul 20 06:56:40.597920 2026] [security2:error] [pid 15216:tid 15441] [client 14.225.17.146:62038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4bCNtIy0gkFcVddGZ2JAAAAWk"], referer: http://amalia-capital.com/2022
[Mon Jul 20 06:56:40.602537 2026] [security2:error] [pid 15216:tid 15360] [client 104.207.51.27:37829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bCNtIy0gkFcVddGZ2KwAAARg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:40.670792 2026] [security2:error] [pid 16093:tid 16231] [client 100.31.58.60:15006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.58.31.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bCJuybMv3z_zMVBSvzgAAAZY"]
[Mon Jul 20 06:56:40.670924 2026] [security2:error] [pid 16093:tid 16231] [client 100.31.58.60:15006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bCJuybMv3z_zMVBSvzgAAAZY"]
[Mon Jul 20 06:56:40.725328 2026] [security2:error] [pid 15216:tid 15371] [client 20.48.236.161:51629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/edit.php"] [unique_id "al4bCNtIy0gkFcVddGZ2LgAAASM"]
[Mon Jul 20 06:56:40.725406 2026] [security2:error] [pid 15216:tid 15371] [client 20.48.236.161:51629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/edit.php"] [unique_id "al4bCNtIy0gkFcVddGZ2LgAAASM"]
[Mon Jul 20 06:56:40.893841 2026] [security2:error] [pid 16093:tid 16281] [client 20.48.236.161:51697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/admin.php"] [unique_id "al4bCJuybMv3z_zMVBSv2wAAAcg"]
[Mon Jul 20 06:56:40.893965 2026] [security2:error] [pid 16093:tid 16281] [client 20.48.236.161:51697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/admin.php"] [unique_id "al4bCJuybMv3z_zMVBSv2wAAAcg"]
[Mon Jul 20 06:56:40.942011 2026] [security2:error] [pid 15216:tid 15414] [client 77.110.127.138:60003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCNtIy0gkFcVddGZ2NQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:40.942106 2026] [security2:error] [pid 15216:tid 15414] [client 77.110.127.138:60003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCNtIy0gkFcVddGZ2NQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:41.058525 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:51711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ss.php"] [unique_id "al4bCZuybMv3z_zMVBSv4wAAAZ8"]
[Mon Jul 20 06:56:41.058630 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:51711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ss.php"] [unique_id "al4bCZuybMv3z_zMVBSv4wAAAZ8"]
[Mon Jul 20 06:56:41.181516 2026] [security2:error] [pid 16093:tid 16323] [client 20.48.236.161:51620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/inputs.php"] [unique_id "al4bCZuybMv3z_zMVBSv6wAAAfI"]
[Mon Jul 20 06:56:41.181607 2026] [security2:error] [pid 16093:tid 16323] [client 20.48.236.161:51620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/inputs.php"] [unique_id "al4bCZuybMv3z_zMVBSv6wAAAfI"]
[Mon Jul 20 06:56:41.187002 2026] [security2:error] [pid 16093:tid 16301] [client 77.110.127.138:60006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCZuybMv3z_zMVBSv7AAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:41.187093 2026] [security2:error] [pid 16093:tid 16301] [client 77.110.127.138:60006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCZuybMv3z_zMVBSv7AAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:41.200083 2026] [security2:error] [pid 16093:tid 16253] [client 65.111.22.182:59305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bCZuybMv3z_zMVBSv6QAAAaw"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:41.316563 2026] [security2:error] [pid 16093:tid 16314] [client 20.48.236.161:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/av.php"] [unique_id "al4bCZuybMv3z_zMVBSv8wAAAek"]
[Mon Jul 20 06:56:41.316659 2026] [security2:error] [pid 16093:tid 16314] [client 20.48.236.161:61126] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/av.php"] [unique_id "al4bCZuybMv3z_zMVBSv8wAAAek"]
[Mon Jul 20 06:56:41.477328 2026] [security2:error] [pid 16093:tid 16315] [client 20.48.236.161:51637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/classwithtostring.php"] [unique_id "al4bCZuybMv3z_zMVBSwAAAAAeo"]
[Mon Jul 20 06:56:41.477592 2026] [security2:error] [pid 16093:tid 16315] [client 20.48.236.161:51637] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/classwithtostring.php"] [unique_id "al4bCZuybMv3z_zMVBSwAAAAAeo"]
[Mon Jul 20 06:56:41.496277 2026] [security2:error] [pid 15216:tid 15428] [client 194.5.53.239:29311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/class.api.php"] [unique_id "al4bCdtIy0gkFcVddGZ2QgAAAVw"]
[Mon Jul 20 06:56:41.632522 2026] [security2:error] [pid 15216:tid 15350] [client 20.48.236.161:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/themes/index.php"] [unique_id "al4bCdtIy0gkFcVddGZ2TgAAAQ4"]
[Mon Jul 20 06:56:41.632615 2026] [security2:error] [pid 15216:tid 15350] [client 20.48.236.161:51642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/themes/index.php"] [unique_id "al4bCdtIy0gkFcVddGZ2TgAAAQ4"]
[Mon Jul 20 06:56:41.723958 2026] [security2:error] [pid 15216:tid 15389] [client 14.224.227.113:54802] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bCdtIy0gkFcVddGZ2UAAAATU"]
[Mon Jul 20 06:56:41.753946 2026] [security2:error] [pid 16093:tid 16346] [client 14.225.17.146:61702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4bCJuybMv3z_zMVBSvyAAAAgk"], referer: http://aljosour-alarabia.com/2022
[Mon Jul 20 06:56:41.764986 2026] [security2:error] [pid 15216:tid 15423] [client 20.48.236.161:57312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-blog.php"] [unique_id "al4bCdtIy0gkFcVddGZ2UgAAAVc"]
[Mon Jul 20 06:56:41.765106 2026] [security2:error] [pid 15216:tid 15423] [client 20.48.236.161:57312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-blog.php"] [unique_id "al4bCdtIy0gkFcVddGZ2UgAAAVc"]
[Mon Jul 20 06:56:41.790408 2026] [security2:error] [pid 15216:tid 15447] [client 45.3.42.199:16071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bCdtIy0gkFcVddGZ2VAAAAW8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:41.867642 2026] [security2:error] [pid 16093:tid 16284] [client 77.110.127.138:60009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCZuybMv3z_zMVBSwEgAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:41.867743 2026] [security2:error] [pid 16093:tid 16284] [client 77.110.127.138:60009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCZuybMv3z_zMVBSwEgAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:41.889699 2026] [security2:error] [pid 15216:tid 15362] [client 57.141.18.35:26510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bCNtIy0gkFcVddGZ2KgABGgM"]
[Mon Jul 20 06:56:41.898500 2026] [proxy:error] [pid 16093:tid 16244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:41.898572 2026] [proxy_http:error] [pid 16093:tid 16244] [client 20.48.236.161:51636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:41.899185 2026] [proxy:error] [pid 16093:tid 16244] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:41.899213 2026] [proxy_http:error] [pid 16093:tid 16244] [client 20.48.236.161:51636] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:41.899302 2026] [security2:error] [pid 16093:tid 16244] [client 20.48.236.161:51636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bCZuybMv3z_zMVBSwFQAAAaM"]
[Mon Jul 20 06:56:41.949345 2026] [security2:error] [pid 16093:tid 16228] [client 194.5.53.228:47261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/fonts/index.php"] [unique_id "al4bCZuybMv3z_zMVBSwGgAAAZM"]
[Mon Jul 20 06:56:42.070573 2026] [security2:error] [pid 16093:tid 16253] [client 20.48.236.161:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/admin.php"] [unique_id "al4bCpuybMv3z_zMVBSwJwAAAaw"]
[Mon Jul 20 06:56:42.070658 2026] [security2:error] [pid 16093:tid 16253] [client 20.48.236.161:61079] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-content/admin.php"] [unique_id "al4bCpuybMv3z_zMVBSwJwAAAaw"]
[Mon Jul 20 06:56:42.230396 2026] [security2:error] [pid 16093:tid 16342] [client 20.48.236.161:61138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/adminfuns.php"] [unique_id "al4bCpuybMv3z_zMVBSwOAAAAgU"]
[Mon Jul 20 06:56:42.230506 2026] [security2:error] [pid 16093:tid 16342] [client 20.48.236.161:61138] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/adminfuns.php"] [unique_id "al4bCpuybMv3z_zMVBSwOAAAAgU"]
[Mon Jul 20 06:56:42.286426 2026] [security2:error] [pid 16093:tid 16331] [client 23.251.146.115:23680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bCpuybMv3z_zMVBSwNAAB-gU"]
[Mon Jul 20 06:56:42.376100 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:51710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/goods.php"] [unique_id "al4bCpuybMv3z_zMVBSwPwAAAgM"]
[Mon Jul 20 06:56:42.376239 2026] [security2:error] [pid 16093:tid 16340] [client 20.48.236.161:51710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/goods.php"] [unique_id "al4bCpuybMv3z_zMVBSwPwAAAgM"]
[Mon Jul 20 06:56:42.416163 2026] [security2:error] [pid 16093:tid 16289] [client 194.5.53.235:62573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/chosen.php"] [unique_id "al4bCpuybMv3z_zMVBSwRAAAAdA"]
[Mon Jul 20 06:56:42.481982 2026] [security2:error] [pid 16093:tid 16270] [client 158.173.89.95:23513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bCpuybMv3z_zMVBSwRwAAAb0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:56:42.493721 2026] [security2:error] [pid 16093:tid 16224] [client 45.157.112.60:31157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bCpuybMv3z_zMVBSwSgAAAY8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:56:42.507500 2026] [security2:error] [pid 16093:tid 16266] [client 20.48.236.161:61147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ms-edit.php"] [unique_id "al4bCpuybMv3z_zMVBSwSwAAAbk"]
[Mon Jul 20 06:56:42.507606 2026] [security2:error] [pid 16093:tid 16266] [client 20.48.236.161:61147] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ms-edit.php"] [unique_id "al4bCpuybMv3z_zMVBSwSwAAAbk"]
[Mon Jul 20 06:56:42.516084 2026] [security2:error] [pid 15216:tid 15455] [client 104.234.53.55:22819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bCttIy0gkFcVddGZ2XwAAAXc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:42.646665 2026] [security2:error] [pid 16093:tid 16298] [client 20.48.236.161:51640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/222.php"] [unique_id "al4bCpuybMv3z_zMVBSwUwAAAdk"]
[Mon Jul 20 06:56:42.646756 2026] [security2:error] [pid 16093:tid 16298] [client 20.48.236.161:51640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/222.php"] [unique_id "al4bCpuybMv3z_zMVBSwUwAAAdk"]
[Mon Jul 20 06:56:42.681546 2026] [security2:error] [pid 16093:tid 16343] [client 23.251.146.115:23680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bCpuybMv3z_zMVBSwTwACBgo"]
[Mon Jul 20 06:56:42.737630 2026] [security2:error] [pid 16093:tid 16123] [remote 84.247.172.23:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4bCpuybMv3z_zMVBSwYAAByBw"]
[Mon Jul 20 06:56:42.780963 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:51695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/cgi-bin/index.php"] [unique_id "al4bCpuybMv3z_zMVBSwYwAAAcI"]
[Mon Jul 20 06:56:42.781050 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:51695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/cgi-bin/index.php"] [unique_id "al4bCpuybMv3z_zMVBSwYwAAAcI"]
[Mon Jul 20 06:56:42.835557 2026] [security2:error] [pid 15216:tid 15376] [client 194.5.53.204:42769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/autoload_classmap/bypass.php"] [unique_id "al4bCttIy0gkFcVddGZ2ZwAAASg"]
[Mon Jul 20 06:56:42.930474 2026] [security2:error] [pid 16093:tid 16109] [remote 84.247.172.23:52032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4bCpuybMv3z_zMVBSwaAAB_w4"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 06:56:42.950417 2026] [proxy:error] [pid 16093:tid 16315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:42.950507 2026] [proxy_http:error] [pid 16093:tid 16315] [client 20.48.236.161:61067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:42.951671 2026] [proxy:error] [pid 16093:tid 16315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:42.951722 2026] [proxy_http:error] [pid 16093:tid 16315] [client 20.48.236.161:61067] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:42.951851 2026] [security2:error] [pid 16093:tid 16315] [client 20.48.236.161:61067] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bCpuybMv3z_zMVBSwagAAAeo"]
[Mon Jul 20 06:56:42.951858 2026] [security2:error] [pid 16093:tid 16303] [client 77.110.127.138:60011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCpuybMv3z_zMVBSwawAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:42.951976 2026] [security2:error] [pid 16093:tid 16303] [client 77.110.127.138:60011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bCpuybMv3z_zMVBSwawAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:43.104851 2026] [security2:error] [pid 16093:tid 16232] [client 20.48.236.161:61069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/BDKR28WP.php"] [unique_id "al4bC5uybMv3z_zMVBSwcgAAAZc"]
[Mon Jul 20 06:56:43.104952 2026] [security2:error] [pid 16093:tid 16232] [client 20.48.236.161:61069] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/BDKR28WP.php"] [unique_id "al4bC5uybMv3z_zMVBSwcgAAAZc"]
[Mon Jul 20 06:56:43.150207 2026] [security2:error] [pid 16093:tid 16287] [client 77.110.127.138:60015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bC5uybMv3z_zMVBSwdgAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:43.150306 2026] [security2:error] [pid 16093:tid 16287] [client 77.110.127.138:60015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bC5uybMv3z_zMVBSwdgAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:43.279886 2026] [security2:error] [pid 16093:tid 16230] [client 104.234.53.72:60209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bC5uybMv3z_zMVBSwgQAAAZU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:43.282789 2026] [proxy:error] [pid 16093:tid 16318] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:43.282848 2026] [proxy_http:error] [pid 16093:tid 16318] [client 20.48.236.161:61130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:43.283455 2026] [proxy:error] [pid 16093:tid 16318] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:43.283486 2026] [proxy_http:error] [pid 16093:tid 16318] [client 20.48.236.161:61130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:43.283567 2026] [security2:error] [pid 16093:tid 16318] [client 20.48.236.161:61130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bC5uybMv3z_zMVBSwggAAAe0"]
[Mon Jul 20 06:56:43.415504 2026] [proxy:error] [pid 16093:tid 16311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:43.415581 2026] [proxy_http:error] [pid 16093:tid 16311] [client 20.48.236.161:57315] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:43.416331 2026] [proxy:error] [pid 16093:tid 16311] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:43.416369 2026] [proxy_http:error] [pid 16093:tid 16311] [client 20.48.236.161:57315] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:43.416442 2026] [security2:error] [pid 16093:tid 16311] [client 20.48.236.161:57315] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bC5uybMv3z_zMVBSwjgAAAeY"]
[Mon Jul 20 06:56:43.427837 2026] [security2:error] [pid 16093:tid 16321] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bC5uybMv3z_zMVBSwhgAAAfA"]
[Mon Jul 20 06:56:43.542671 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:51643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp.php"] [unique_id "al4bC5uybMv3z_zMVBSwmgAAAdw"]
[Mon Jul 20 06:56:43.542768 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:51643] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp.php"] [unique_id "al4bC5uybMv3z_zMVBSwmgAAAdw"]
[Mon Jul 20 06:56:43.673426 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:61114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/abcd.php"] [unique_id "al4bC5uybMv3z_zMVBSwngAAAcI"]
[Mon Jul 20 06:56:43.673544 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:61114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/abcd.php"] [unique_id "al4bC5uybMv3z_zMVBSwngAAAcI"]
[Mon Jul 20 06:56:43.675315 2026] [security2:error] [pid 16093:tid 16245] [client 77.110.127.138:60016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bC5uybMv3z_zMVBSwoAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:43.675405 2026] [security2:error] [pid 16093:tid 16245] [client 77.110.127.138:60016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bC5uybMv3z_zMVBSwoAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:43.700396 2026] [security2:error] [pid 16093:tid 16305] [client 194.5.53.223:49397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/dropdown.php"] [unique_id "al4bC5uybMv3z_zMVBSwpwAAAeA"]
[Mon Jul 20 06:56:43.769679 2026] [security2:error] [pid 16093:tid 16325] [client 14.225.17.146:56622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4bC5uybMv3z_zMVBSwnQAAAfQ"], referer: http://cephasnext.com/2022
[Mon Jul 20 06:56:43.840835 2026] [security2:error] [pid 16093:tid 16287] [client 20.48.236.161:51680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/a1.php"] [unique_id "al4bC5uybMv3z_zMVBSwrgAAAc4"]
[Mon Jul 20 06:56:43.840945 2026] [security2:error] [pid 16093:tid 16287] [client 20.48.236.161:51680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/a1.php"] [unique_id "al4bC5uybMv3z_zMVBSwrgAAAc4"]
[Mon Jul 20 06:56:43.905863 2026] [security2:error] [pid 16093:tid 16281] [client 187.108.85.186:57747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bC5uybMv3z_zMVBSwsgAAAcg"]
[Mon Jul 20 06:56:43.906012 2026] [security2:error] [pid 16093:tid 16281] [client 187.108.85.186:57747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bC5uybMv3z_zMVBSwsgAAAcg"]
[Mon Jul 20 06:56:43.917933 2026] [security2:error] [pid 16093:tid 16231] [client 77.110.127.138:60018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bC5uybMv3z_zMVBSwtAAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:43.918043 2026] [security2:error] [pid 16093:tid 16231] [client 77.110.127.138:60018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bC5uybMv3z_zMVBSwtAAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:44.005132 2026] [security2:error] [pid 15216:tid 15354] [client 20.48.236.161:61127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4bDNtIy0gkFcVddGZ2fAAAARI"]
[Mon Jul 20 06:56:44.005274 2026] [security2:error] [pid 15216:tid 15354] [client 20.48.236.161:61127] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4bDNtIy0gkFcVddGZ2fAAAARI"]
[Mon Jul 20 06:56:44.116545 2026] [security2:error] [pid 15216:tid 15402] [client 194.5.53.242:45153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/admin.php"] [unique_id "al4bDNtIy0gkFcVddGZ2fgAAAUI"]
[Mon Jul 20 06:56:44.140091 2026] [security2:error] [pid 15216:tid 15367] [client 20.48.236.161:51694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/cgi-bin/admin.php"] [unique_id "al4bDNtIy0gkFcVddGZ2hAAAAR8"]
[Mon Jul 20 06:56:44.140169 2026] [security2:error] [pid 15216:tid 15367] [client 20.48.236.161:51694] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/cgi-bin/admin.php"] [unique_id "al4bDNtIy0gkFcVddGZ2hAAAAR8"]
[Mon Jul 20 06:56:44.290612 2026] [security2:error] [pid 16093:tid 16256] [client 20.48.236.161:57332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/gettest.php"] [unique_id "al4bDJuybMv3z_zMVBSw0gAAAa8"]
[Mon Jul 20 06:56:44.290705 2026] [security2:error] [pid 16093:tid 16256] [client 20.48.236.161:57332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/gettest.php"] [unique_id "al4bDJuybMv3z_zMVBSw0gAAAa8"]
[Mon Jul 20 06:56:44.423830 2026] [proxy:error] [pid 16093:tid 16315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:44.423909 2026] [proxy_http:error] [pid 16093:tid 16315] [client 20.48.236.161:51596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:44.424938 2026] [proxy:error] [pid 16093:tid 16315] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:44.424977 2026] [proxy_http:error] [pid 16093:tid 16315] [client 20.48.236.161:51596] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:44.425079 2026] [security2:error] [pid 16093:tid 16315] [client 20.48.236.161:51596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bDJuybMv3z_zMVBSw2gAAAeo"]
[Mon Jul 20 06:56:44.539879 2026] [security2:error] [pid 16093:tid 16161] [remote 8.217.108.67:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4bDJuybMv3z_zMVBSw3QABkEI"]
[Mon Jul 20 06:56:44.560492 2026] [security2:error] [pid 16093:tid 16277] [client 20.48.236.161:61134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/simple.php"] [unique_id "al4bDJuybMv3z_zMVBSw3gAAAcQ"]
[Mon Jul 20 06:56:44.560577 2026] [security2:error] [pid 16093:tid 16277] [client 20.48.236.161:61134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/simple.php"] [unique_id "al4bDJuybMv3z_zMVBSw3gAAAcQ"]
[Mon Jul 20 06:56:44.682128 2026] [security2:error] [pid 16093:tid 16293] [client 20.48.236.161:61161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xxx.php"] [unique_id "al4bDJuybMv3z_zMVBSw7AAAAdQ"]
[Mon Jul 20 06:56:44.682249 2026] [security2:error] [pid 16093:tid 16293] [client 20.48.236.161:61161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xxx.php"] [unique_id "al4bDJuybMv3z_zMVBSw7AAAAdQ"]
[Mon Jul 20 06:56:44.722383 2026] [security2:error] [pid 16093:tid 16267] [client 103.144.65.217:62234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bDJuybMv3z_zMVBSw9AAAAbo"]
[Mon Jul 20 06:56:44.722471 2026] [security2:error] [pid 16093:tid 16267] [client 103.144.65.217:62234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bDJuybMv3z_zMVBSw9AAAAbo"]
[Mon Jul 20 06:56:44.801599 2026] [security2:error] [pid 16093:tid 16343] [client 20.48.236.161:51705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/hypo.php"] [unique_id "al4bDJuybMv3z_zMVBSw-wAAAgY"]
[Mon Jul 20 06:56:44.801763 2026] [security2:error] [pid 16093:tid 16343] [client 20.48.236.161:51705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/hypo.php"] [unique_id "al4bDJuybMv3z_zMVBSw-wAAAgY"]
[Mon Jul 20 06:56:44.966805 2026] [proxy:error] [pid 16093:tid 16275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:44.966877 2026] [proxy_http:error] [pid 16093:tid 16275] [client 20.48.236.161:51701] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:44.967418 2026] [proxy:error] [pid 16093:tid 16275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:44.967446 2026] [proxy_http:error] [pid 16093:tid 16275] [client 20.48.236.161:51701] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:44.967527 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:51701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bDJuybMv3z_zMVBSxAwAAAcI"]
[Mon Jul 20 06:56:45.075988 2026] [security2:error] [pid 16093:tid 16314] [client 104.234.53.61:36409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bDZuybMv3z_zMVBSxCgAAAek"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:45.097405 2026] [security2:error] [pid 16093:tid 16331] [client 20.48.236.161:61139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/chosen.php"] [unique_id "al4bDZuybMv3z_zMVBSxDAAAAfo"]
[Mon Jul 20 06:56:45.097529 2026] [security2:error] [pid 16093:tid 16331] [client 20.48.236.161:61139] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/chosen.php"] [unique_id "al4bDZuybMv3z_zMVBSxDAAAAfo"]
[Mon Jul 20 06:56:45.107393 2026] [security2:error] [pid 15216:tid 15423] [client 117.222.139.248:64657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bDdtIy0gkFcVddGZ2kAAAAVc"]
[Mon Jul 20 06:56:45.107516 2026] [security2:error] [pid 15216:tid 15423] [client 117.222.139.248:64657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bDdtIy0gkFcVddGZ2kAAAAVc"]
[Mon Jul 20 06:56:45.200876 2026] [security2:error] [pid 16093:tid 16248] [client 197.186.66.42:59318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bDZuybMv3z_zMVBSxEwAAAac"]
[Mon Jul 20 06:56:45.200971 2026] [security2:error] [pid 16093:tid 16248] [client 197.186.66.42:59318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bDZuybMv3z_zMVBSxEwAAAac"]
[Mon Jul 20 06:56:45.244412 2026] [proxy:error] [pid 15216:tid 15432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:45.244491 2026] [proxy_http:error] [pid 15216:tid 15432] [client 20.48.236.161:51689] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:45.244959 2026] [proxy:error] [pid 15216:tid 15432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:45.244989 2026] [proxy_http:error] [pid 15216:tid 15432] [client 20.48.236.161:51689] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:45.245069 2026] [security2:error] [pid 15216:tid 15432] [client 20.48.236.161:51689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bDdtIy0gkFcVddGZ2lAAAAWA"]
[Mon Jul 20 06:56:45.273740 2026] [security2:error] [pid 16093:tid 16154] [remote 188.166.241.141:36934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.com"] [uri "/wp-login.php"] [unique_id "al4bDZuybMv3z_zMVBSxGQAB1js"]
[Mon Jul 20 06:56:45.279132 2026] [security2:error] [pid 16093:tid 16287] [client 50.116.65.227:48092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bDZuybMv3z_zMVBSxGwAAAc4"]
[Mon Jul 20 06:56:45.288502 2026] [security2:error] [pid 16093:tid 16347] [client 50.116.65.227:48108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bDZuybMv3z_zMVBSxHAAAAgo"]
[Mon Jul 20 06:56:45.385521 2026] [security2:error] [pid 16093:tid 16311] [client 20.48.236.161:51649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/als.php"] [unique_id "al4bDZuybMv3z_zMVBSxIwAAAeY"]
[Mon Jul 20 06:56:45.385620 2026] [security2:error] [pid 16093:tid 16311] [client 20.48.236.161:51649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/als.php"] [unique_id "al4bDZuybMv3z_zMVBSxIwAAAeY"]
[Mon Jul 20 06:56:45.515147 2026] [security2:error] [pid 15216:tid 15464] [client 20.48.236.161:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/pol.php"] [unique_id "al4bDdtIy0gkFcVddGZ2mAAAAYA"]
[Mon Jul 20 06:56:45.515239 2026] [security2:error] [pid 15216:tid 15464] [client 20.48.236.161:51668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/pol.php"] [unique_id "al4bDdtIy0gkFcVddGZ2mAAAAYA"]
[Mon Jul 20 06:56:45.560250 2026] [security2:error] [pid 15216:tid 15434] [client 194.5.53.225:53359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/db.php"] [unique_id "al4bDdtIy0gkFcVddGZ2ngAAAWI"]
[Mon Jul 20 06:56:45.620821 2026] [security2:error] [pid 16093:tid 16321] [client 51.158.104.150:45280] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "webmail-box5023.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4bDZuybMv3z_zMVBSxMgAAAfA"]
[Mon Jul 20 06:56:45.641664 2026] [security2:error] [pid 16093:tid 16320] [client 20.48.236.161:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file5.php"] [unique_id "al4bDZuybMv3z_zMVBSxNgAAAe8"]
[Mon Jul 20 06:56:45.641807 2026] [security2:error] [pid 16093:tid 16320] [client 20.48.236.161:61142] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file5.php"] [unique_id "al4bDZuybMv3z_zMVBSxNgAAAe8"]
[Mon Jul 20 06:56:45.684997 2026] [security2:error] [pid 16093:tid 16175] [remote 188.166.241.141:36934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.com"] [uri "/wp-login.php"] [unique_id "al4bDZuybMv3z_zMVBSxPQACAlA"], referer: https://fkconstructionfunding.com/wp-login.php
[Mon Jul 20 06:56:45.786613 2026] [security2:error] [pid 15216:tid 15468] [client 20.48.236.161:61163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file.php"] [unique_id "al4bDdtIy0gkFcVddGZ2rAAAAYQ"]
[Mon Jul 20 06:56:45.786694 2026] [security2:error] [pid 15216:tid 15468] [client 20.48.236.161:61163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file.php"] [unique_id "al4bDdtIy0gkFcVddGZ2rAAAAYQ"]
[Mon Jul 20 06:56:45.911876 2026] [security2:error] [pid 15216:tid 15361] [client 20.48.236.161:57316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/cfile.php"] [unique_id "al4bDdtIy0gkFcVddGZ2rwAAARk"]
[Mon Jul 20 06:56:45.911975 2026] [security2:error] [pid 15216:tid 15361] [client 20.48.236.161:57316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/cfile.php"] [unique_id "al4bDdtIy0gkFcVddGZ2rwAAARk"]
[Mon Jul 20 06:56:46.031844 2026] [security2:error] [pid 15216:tid 15412] [client 194.5.53.237:39903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "al4bDttIy0gkFcVddGZ2tgAAAUw"]
[Mon Jul 20 06:56:46.035602 2026] [security2:error] [pid 15216:tid 15368] [client 57.141.18.85:30430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bDNtIy0gkFcVddGZ2igABICw"]
[Mon Jul 20 06:56:46.060087 2026] [security2:error] [pid 15216:tid 15357] [client 20.48.236.161:51689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/admin.php"] [unique_id "al4bDttIy0gkFcVddGZ2uAAAARU"]
[Mon Jul 20 06:56:46.060205 2026] [security2:error] [pid 15216:tid 15357] [client 20.48.236.161:51689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/admin.php"] [unique_id "al4bDttIy0gkFcVddGZ2uAAAARU"]
[Mon Jul 20 06:56:46.114806 2026] [security2:error] [pid 16093:tid 16177] [remote 8.217.108.67:55628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4bDpuybMv3z_zMVBSxTgABvlI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:56:46.186932 2026] [security2:error] [pid 15216:tid 15364] [client 20.48.236.161:57283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/aa2.php"] [unique_id "al4bDttIy0gkFcVddGZ2vgAAARw"]
[Mon Jul 20 06:56:46.187043 2026] [security2:error] [pid 15216:tid 15364] [client 20.48.236.161:57283] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/aa2.php"] [unique_id "al4bDttIy0gkFcVddGZ2vgAAARw"]
[Mon Jul 20 06:56:46.253121 2026] [security2:error] [pid 15216:tid 15289] [remote 192.241.143.148:58588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4bDttIy0gkFcVddGZ2wQABEEg"]
[Mon Jul 20 06:56:46.327203 2026] [security2:error] [pid 16093:tid 16328] [client 20.48.236.161:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ccou.php"] [unique_id "al4bDpuybMv3z_zMVBSxWwAAAfc"]
[Mon Jul 20 06:56:46.327281 2026] [security2:error] [pid 16093:tid 16328] [client 20.48.236.161:61154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ccou.php"] [unique_id "al4bDpuybMv3z_zMVBSxWwAAAfc"]
[Mon Jul 20 06:56:46.340502 2026] [security2:error] [pid 15216:tid 15373] [client 104.234.53.61:39729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bDttIy0gkFcVddGZ2wwAAASU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:46.438409 2026] [security2:error] [pid 15216:tid 15451] [client 194.5.53.229:54155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/mah/function.php"] [unique_id "al4bDttIy0gkFcVddGZ2yQAAAXM"]
[Mon Jul 20 06:56:46.453586 2026] [security2:error] [pid 15216:tid 15358] [client 20.48.236.161:51595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/dr.php"] [unique_id "al4bDttIy0gkFcVddGZ2ygAAARY"]
[Mon Jul 20 06:56:46.453679 2026] [security2:error] [pid 15216:tid 15358] [client 20.48.236.161:51595] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/dr.php"] [unique_id "al4bDttIy0gkFcVddGZ2ygAAARY"]
[Mon Jul 20 06:56:46.520268 2026] [security2:error] [pid 15216:tid 15259] [remote 192.241.143.148:58588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4bDttIy0gkFcVddGZ2zgABVio"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:56:46.536390 2026] [security2:error] [pid 15216:tid 15269] [remote 154.61.75.100:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4bDttIy0gkFcVddGZ2zQABXzQ"]
[Mon Jul 20 06:56:46.582817 2026] [security2:error] [pid 15216:tid 15457] [client 20.48.236.161:61106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xamp.php"] [unique_id "al4bDttIy0gkFcVddGZ20QAAAXk"]
[Mon Jul 20 06:56:46.582923 2026] [security2:error] [pid 15216:tid 15457] [client 20.48.236.161:61106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xamp.php"] [unique_id "al4bDttIy0gkFcVddGZ20QAAAXk"]
[Mon Jul 20 06:56:46.619841 2026] [security2:error] [pid 16093:tid 16302] [client 14.225.17.146:56647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4bDJuybMv3z_zMVBSxBAAAAd0"], referer: http://nwcarvingacademy.com/2022
[Mon Jul 20 06:56:46.712007 2026] [security2:error] [pid 15216:tid 15432] [client 20.48.236.161:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/bless.php"] [unique_id "al4bDttIy0gkFcVddGZ22AAAAWA"]
[Mon Jul 20 06:56:46.712152 2026] [security2:error] [pid 15216:tid 15432] [client 20.48.236.161:51619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/bless.php"] [unique_id "al4bDttIy0gkFcVddGZ22AAAAWA"]
[Mon Jul 20 06:56:46.778002 2026] [security2:error] [pid 15216:tid 15270] [remote 154.66.198.148:5026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4bDttIy0gkFcVddGZ22gABKzU"]
[Mon Jul 20 06:56:46.846516 2026] [security2:error] [pid 15216:tid 15419] [client 20.48.236.161:61072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file25.php"] [unique_id "al4bDttIy0gkFcVddGZ23QAAAVM"]
[Mon Jul 20 06:56:46.846651 2026] [security2:error] [pid 15216:tid 15419] [client 20.48.236.161:61072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file25.php"] [unique_id "al4bDttIy0gkFcVddGZ23QAAAVM"]
[Mon Jul 20 06:56:46.885679 2026] [security2:error] [pid 16093:tid 16232] [client 194.5.53.239:20189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/bypass.php"] [unique_id "al4bDpuybMv3z_zMVBSxcQAAAZc"]
[Mon Jul 20 06:56:46.976202 2026] [security2:error] [pid 16093:tid 16291] [client 20.48.236.161:61183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file6.php"] [unique_id "al4bDpuybMv3z_zMVBSxdgAAAdI"]
[Mon Jul 20 06:56:46.976288 2026] [security2:error] [pid 16093:tid 16291] [client 20.48.236.161:61183] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file6.php"] [unique_id "al4bDpuybMv3z_zMVBSxdgAAAdI"]
[Mon Jul 20 06:56:47.009674 2026] [security2:error] [pid 15216:tid 15244] [remote 154.61.75.100:44806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4bD9tIy0gkFcVddGZ23wABQBs"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 06:56:47.096537 2026] [security2:error] [pid 16093:tid 16253] [client 77.110.127.138:60034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bD5uybMv3z_zMVBSxggAAAaw"]
[Mon Jul 20 06:56:47.104925 2026] [security2:error] [pid 16093:tid 16298] [client 20.48.236.161:51697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/a2.php"] [unique_id "al4bD5uybMv3z_zMVBSxgwAAAdk"]
[Mon Jul 20 06:56:47.105046 2026] [security2:error] [pid 16093:tid 16298] [client 20.48.236.161:51697] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/a2.php"] [unique_id "al4bD5uybMv3z_zMVBSxgwAAAdk"]
[Mon Jul 20 06:56:47.233243 2026] [security2:error] [pid 16093:tid 16262] [client 20.48.236.161:51693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file15.php"] [unique_id "al4bD5uybMv3z_zMVBSxiwAAAbU"]
[Mon Jul 20 06:56:47.233346 2026] [security2:error] [pid 16093:tid 16262] [client 20.48.236.161:51693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file15.php"] [unique_id "al4bD5uybMv3z_zMVBSxiwAAAbU"]
[Mon Jul 20 06:56:47.238518 2026] [security2:error] [pid 15216:tid 15417] [client 103.125.179.95:53768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bD9tIy0gkFcVddGZ24wAAAVE"]
[Mon Jul 20 06:56:47.239060 2026] [security2:error] [pid 15216:tid 15417] [client 103.125.179.95:53768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bD9tIy0gkFcVddGZ24wAAAVE"]
[Mon Jul 20 06:56:47.267584 2026] [security2:error] [pid 16093:tid 16217] [remote 47.128.49.83:23364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joaoceitil.com"] [uri "/news/"] [unique_id "al4bD5uybMv3z_zMVBSxjwABmHo"]
[Mon Jul 20 06:56:47.298683 2026] [security2:error] [pid 16093:tid 16347] [client 194.5.53.250:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/admin.php"] [unique_id "al4bD5uybMv3z_zMVBSxlAAAAgo"]
[Mon Jul 20 06:56:47.348083 2026] [security2:error] [pid 15216:tid 15301] [remote 154.66.198.148:5026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4bD9tIy0gkFcVddGZ25wABOFQ"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 06:56:47.359217 2026] [security2:error] [pid 16093:tid 16334] [client 20.48.236.161:51628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/f35.php"] [unique_id "al4bD5uybMv3z_zMVBSxlgAAAf0"]
[Mon Jul 20 06:56:47.359292 2026] [security2:error] [pid 16093:tid 16334] [client 20.48.236.161:51628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/f35.php"] [unique_id "al4bD5uybMv3z_zMVBSxlgAAAf0"]
[Mon Jul 20 06:56:47.499972 2026] [security2:error] [pid 15216:tid 15360] [client 20.48.236.161:61125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-load.php"] [unique_id "al4bD9tIy0gkFcVddGZ26wAAARg"]
[Mon Jul 20 06:56:47.500075 2026] [security2:error] [pid 15216:tid 15360] [client 20.48.236.161:61125] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-load.php"] [unique_id "al4bD9tIy0gkFcVddGZ26wAAARg"]
[Mon Jul 20 06:56:47.628508 2026] [security2:error] [pid 15216:tid 15361] [client 20.48.236.161:61123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xwpg.php"] [unique_id "al4bD9tIy0gkFcVddGZ27wAAARk"]
[Mon Jul 20 06:56:47.628655 2026] [security2:error] [pid 15216:tid 15361] [client 20.48.236.161:61123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xwpg.php"] [unique_id "al4bD9tIy0gkFcVddGZ27wAAARk"]
[Mon Jul 20 06:56:47.755522 2026] [proxy:error] [pid 16093:tid 16275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:47.755587 2026] [proxy_http:error] [pid 16093:tid 16275] [client 20.48.236.161:61181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:47.756018 2026] [proxy:error] [pid 16093:tid 16275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:47.756078 2026] [proxy_http:error] [pid 16093:tid 16275] [client 20.48.236.161:61181] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:47.756159 2026] [security2:error] [pid 16093:tid 16275] [client 20.48.236.161:61181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bD5uybMv3z_zMVBSxtgAAAcI"]
[Mon Jul 20 06:56:47.844760 2026] [security2:error] [pid 16093:tid 16236] [client 194.5.53.227:31097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "al4bD5uybMv3z_zMVBSxvwAAAZs"]
[Mon Jul 20 06:56:47.902357 2026] [proxy:error] [pid 16093:tid 16272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:47.902427 2026] [proxy_http:error] [pid 16093:tid 16272] [client 20.48.236.161:61145] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:47.902948 2026] [proxy:error] [pid 16093:tid 16272] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:56:47.902977 2026] [proxy_http:error] [pid 16093:tid 16272] [client 20.48.236.161:61145] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:56:47.903067 2026] [security2:error] [pid 16093:tid 16272] [client 20.48.236.161:61145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/cgi-sys/503.html"] [unique_id "al4bD5uybMv3z_zMVBSxxAAAAb8"]
[Mon Jul 20 06:56:48.035906 2026] [security2:error] [pid 16093:tid 16251] [client 20.48.236.161:61149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xstelth.php"] [unique_id "al4bEJuybMv3z_zMVBSxygAAAao"]
[Mon Jul 20 06:56:48.036024 2026] [security2:error] [pid 16093:tid 16251] [client 20.48.236.161:61149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xstelth.php"] [unique_id "al4bEJuybMv3z_zMVBSxygAAAao"]
[Mon Jul 20 06:56:48.086191 2026] [security2:error] [pid 16093:tid 16258] [client 117.247.108.24:24131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bEJuybMv3z_zMVBSxzgAAAbE"]
[Mon Jul 20 06:56:48.086283 2026] [security2:error] [pid 16093:tid 16258] [client 117.247.108.24:24131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bEJuybMv3z_zMVBSxzgAAAbE"]
[Mon Jul 20 06:56:48.127340 2026] [security2:error] [pid 15216:tid 15371] [client 217.142.18.172:27557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bENtIy0gkFcVddGZ29QAAASM"]
[Mon Jul 20 06:56:48.127442 2026] [security2:error] [pid 15216:tid 15371] [client 217.142.18.172:27557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bENtIy0gkFcVddGZ29QAAASM"]
[Mon Jul 20 06:56:48.168338 2026] [security2:error] [pid 16093:tid 16267] [client 20.48.236.161:24445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4bEJuybMv3z_zMVBSx0wAAAbo"]
[Mon Jul 20 06:56:48.168432 2026] [security2:error] [pid 16093:tid 16267] [client 20.48.236.161:24445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4bEJuybMv3z_zMVBSx0wAAAbo"]
[Mon Jul 20 06:56:48.207273 2026] [security2:error] [pid 16093:tid 16257] [client 77.110.127.138:60042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bEJuybMv3z_zMVBSx1gAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:48.207365 2026] [security2:error] [pid 16093:tid 16257] [client 77.110.127.138:60042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bEJuybMv3z_zMVBSx1gAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:48.218136 2026] [security2:error] [pid 15216:tid 15458] [client 57.141.18.79:50130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bDttIy0gkFcVddGZ20AABejI"]
[Mon Jul 20 06:56:48.241565 2026] [security2:error] [pid 16093:tid 16302] [client 194.5.53.41:46189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/function.php"] [unique_id "al4bEJuybMv3z_zMVBSx2QAAAd0"]
[Mon Jul 20 06:56:48.314825 2026] [security2:error] [pid 16093:tid 16294] [client 20.48.236.161:57255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/aaa.php"] [unique_id "al4bEJuybMv3z_zMVBSx2wAAAdU"]
[Mon Jul 20 06:56:48.314934 2026] [security2:error] [pid 16093:tid 16294] [client 20.48.236.161:57255] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/aaa.php"] [unique_id "al4bEJuybMv3z_zMVBSx2wAAAdU"]
[Mon Jul 20 06:56:48.357276 2026] [security2:error] [pid 16093:tid 16100] [remote 8.217.108.67:40076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bEJuybMv3z_zMVBSx3QACAAU"]
[Mon Jul 20 06:56:48.422725 2026] [security2:error] [pid 16093:tid 16299] [client 122.183.32.225:18323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bEJuybMv3z_zMVBSx5QAAAdo"]
[Mon Jul 20 06:56:48.422837 2026] [security2:error] [pid 16093:tid 16299] [client 122.183.32.225:18323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bEJuybMv3z_zMVBSx5QAAAdo"]
[Mon Jul 20 06:56:48.458768 2026] [security2:error] [pid 15216:tid 15377] [client 20.48.236.161:57256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/gecko.php"] [unique_id "al4bENtIy0gkFcVddGZ2_gAAASk"]
[Mon Jul 20 06:56:48.458847 2026] [security2:error] [pid 15216:tid 15377] [client 20.48.236.161:57256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/gecko.php"] [unique_id "al4bENtIy0gkFcVddGZ2_gAAASk"]
[Mon Jul 20 06:56:48.587844 2026] [security2:error] [pid 15216:tid 15418] [client 20.48.236.161:51634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/sh3ll.php"] [unique_id "al4bENtIy0gkFcVddGZ3AQAAAVI"]
[Mon Jul 20 06:56:48.587955 2026] [security2:error] [pid 15216:tid 15418] [client 20.48.236.161:51634] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/sh3ll.php"] [unique_id "al4bENtIy0gkFcVddGZ3AQAAAVI"]
[Mon Jul 20 06:56:48.618381 2026] [security2:error] [pid 16093:tid 16255] [client 194.5.53.223:24711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/templates/beez3/index.php"] [unique_id "al4bEJuybMv3z_zMVBSx9QAAAa4"]
[Mon Jul 20 06:56:48.710966 2026] [security2:error] [pid 16093:tid 16245] [client 20.48.236.161:61092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/pbck.php"] [unique_id "al4bEJuybMv3z_zMVBSyBQAAAaQ"]
[Mon Jul 20 06:56:48.711096 2026] [security2:error] [pid 16093:tid 16245] [client 20.48.236.161:61092] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/pbck.php"] [unique_id "al4bEJuybMv3z_zMVBSyBQAAAaQ"]
[Mon Jul 20 06:56:48.785937 2026] [security2:error] [pid 16093:tid 16316] [client 14.225.17.146:59851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4bD5uybMv3z_zMVBSxmQAAAes"], referer: http://balticsteelmgmt.com/2022
[Mon Jul 20 06:56:48.840179 2026] [security2:error] [pid 16093:tid 16341] [client 20.48.236.161:51665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xiugai.php"] [unique_id "al4bEJuybMv3z_zMVBSyCwAAAgQ"]
[Mon Jul 20 06:56:48.840292 2026] [security2:error] [pid 16093:tid 16341] [client 20.48.236.161:51665] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xiugai.php"] [unique_id "al4bEJuybMv3z_zMVBSyCwAAAgQ"]
[Mon Jul 20 06:56:48.910859 2026] [security2:error] [pid 16093:tid 16265] [client 14.225.17.146:64737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4bEJuybMv3z_zMVBSx8gAAAbg"], referer: http://healthylifegourmet.org/2022
[Mon Jul 20 06:56:48.971336 2026] [security2:error] [pid 15216:tid 15401] [client 20.48.236.161:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/e.php"] [unique_id "al4bENtIy0gkFcVddGZ3BQAAAUE"]
[Mon Jul 20 06:56:48.971433 2026] [security2:error] [pid 15216:tid 15401] [client 20.48.236.161:51661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/e.php"] [unique_id "al4bENtIy0gkFcVddGZ3BQAAAUE"]
[Mon Jul 20 06:56:49.039847 2026] [security2:error] [pid 15216:tid 15294] [remote 188.166.241.141:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4bEdtIy0gkFcVddGZ3BwABhk0"]
[Mon Jul 20 06:56:49.040405 2026] [security2:error] [pid 16093:tid 16226] [client 194.5.53.236:29461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/js/wp-login.php"] [unique_id "al4bEJuybMv3z_zMVBSyHQAAAZE"]
[Mon Jul 20 06:56:49.050103 2026] [security2:error] [pid 16093:tid 16269] [client 40.77.167.77:44577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "drawingthedog.com"] [uri "/index.php"] [unique_id "al4bEJuybMv3z_zMVBSyEAABvBY"]
[Mon Jul 20 06:56:49.059217 2026] [security2:error] [pid 16093:tid 16286] [client 14.225.17.146:65038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4bD5uybMv3z_zMVBSxyAAAAc0"], referer: http://nikkidesigns.net/2022
[Mon Jul 20 06:56:49.119940 2026] [security2:error] [pid 16093:tid 16228] [client 20.48.236.161:61065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/for.php"] [unique_id "al4bEZuybMv3z_zMVBSyJAAAAZM"]
[Mon Jul 20 06:56:49.120045 2026] [security2:error] [pid 16093:tid 16228] [client 20.48.236.161:61065] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/for.php"] [unique_id "al4bEZuybMv3z_zMVBSyJAAAAZM"]
[Mon Jul 20 06:56:49.165823 2026] [security2:error] [pid 16093:tid 16232] [client 183.82.98.154:49981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bEZuybMv3z_zMVBSyKAAAAZc"]
[Mon Jul 20 06:56:49.165913 2026] [security2:error] [pid 16093:tid 16232] [client 183.82.98.154:49981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bEZuybMv3z_zMVBSyKAAAAZc"]
[Mon Jul 20 06:56:49.258478 2026] [security2:error] [pid 16093:tid 16248] [client 20.48.236.161:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/ssh3ll.php"] [unique_id "al4bEZuybMv3z_zMVBSyMAAAAac"]
[Mon Jul 20 06:56:49.258566 2026] [security2:error] [pid 16093:tid 16248] [client 20.48.236.161:61059] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/ssh3ll.php"] [unique_id "al4bEZuybMv3z_zMVBSyMAAAAac"]
[Mon Jul 20 06:56:49.409209 2026] [security2:error] [pid 16093:tid 16333] [client 20.48.236.161:61165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/adminner.php"] [unique_id "al4bEZuybMv3z_zMVBSyOwAAAfw"]
[Mon Jul 20 06:56:49.409328 2026] [security2:error] [pid 16093:tid 16333] [client 20.48.236.161:61165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/adminner.php"] [unique_id "al4bEZuybMv3z_zMVBSyOwAAAfw"]
[Mon Jul 20 06:56:49.454854 2026] [security2:error] [pid 16093:tid 16257] [client 152.58.191.29:11588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bEZuybMv3z_zMVBSyPgAAAbA"]
[Mon Jul 20 06:56:49.454984 2026] [security2:error] [pid 16093:tid 16257] [client 152.58.191.29:11588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bEZuybMv3z_zMVBSyPgAAAbA"]
[Mon Jul 20 06:56:49.495843 2026] [security2:error] [pid 16093:tid 16348] [client 194.5.53.243:33271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/install.php"] [unique_id "al4bEZuybMv3z_zMVBSyQAAAAgs"]
[Mon Jul 20 06:56:49.498607 2026] [security2:error] [pid 15216:tid 15330] [remote 188.166.241.141:36936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4bEdtIy0gkFcVddGZ3EwABSHE"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:56:49.564277 2026] [security2:error] [pid 15216:tid 15415] [client 20.48.236.161:61132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/82.php"] [unique_id "al4bEdtIy0gkFcVddGZ3FQAAAU8"]
[Mon Jul 20 06:56:49.564391 2026] [security2:error] [pid 15216:tid 15415] [client 20.48.236.161:61132] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/82.php"] [unique_id "al4bEdtIy0gkFcVddGZ3FQAAAU8"]
[Mon Jul 20 06:56:49.583385 2026] [security2:error] [pid 15216:tid 15428] [client 74.7.227.179:34066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4bEdtIy0gkFcVddGZ3EAABXFc"], referer: https://tejasenvironmental.com/p=2409674
[Mon Jul 20 06:56:49.685146 2026] [core:error] [pid 16093:tid 16345] [client 14.225.17.146:59897] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:56:49.685169 2026] [core:error] [pid 16093:tid 16345] [client 14.225.17.146:59897] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:56:49.695094 2026] [security2:error] [pid 16093:tid 16242] [client 20.48.236.161:51707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/kir.php"] [unique_id "al4bEZuybMv3z_zMVBSyUAAAAaE"]
[Mon Jul 20 06:56:49.695181 2026] [security2:error] [pid 16093:tid 16242] [client 20.48.236.161:51707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/kir.php"] [unique_id "al4bEZuybMv3z_zMVBSyUAAAAaE"]
[Mon Jul 20 06:56:49.823070 2026] [security2:error] [pid 16093:tid 16298] [client 14.225.17.146:65089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4bEZuybMv3z_zMVBSySQAAAdk"], referer: http://oldracelimited.com/2022
[Mon Jul 20 06:56:49.824596 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:57296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/up4.php"] [unique_id "al4bEZuybMv3z_zMVBSyXAAAAdw"]
[Mon Jul 20 06:56:49.824678 2026] [security2:error] [pid 16093:tid 16301] [client 20.48.236.161:57296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/up4.php"] [unique_id "al4bEZuybMv3z_zMVBSyXAAAAdw"]
[Mon Jul 20 06:56:49.950379 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:51622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/xhar.php"] [unique_id "al4bEZuybMv3z_zMVBSyZQAAAZ8"]
[Mon Jul 20 06:56:49.950489 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:51622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/xhar.php"] [unique_id "al4bEZuybMv3z_zMVBSyZQAAAZ8"]
[Mon Jul 20 06:56:49.987562 2026] [security2:error] [pid 15216:tid 15432] [client 103.238.106.162:60944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bEdtIy0gkFcVddGZ3GwAAAWA"]
[Mon Jul 20 06:56:49.988213 2026] [security2:error] [pid 15216:tid 15432] [client 103.238.106.162:60944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bEdtIy0gkFcVddGZ3GwAAAWA"]
[Mon Jul 20 06:56:50.085134 2026] [security2:error] [pid 16093:tid 16288] [client 20.48.236.161:24137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/file1221.php"] [unique_id "al4bEpuybMv3z_zMVBSycQAAAc8"]
[Mon Jul 20 06:56:50.085243 2026] [security2:error] [pid 16093:tid 16288] [client 20.48.236.161:24137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/file1221.php"] [unique_id "al4bEpuybMv3z_zMVBSycQAAAc8"]
[Mon Jul 20 06:56:50.104092 2026] [security2:error] [pid 15216:tid 15398] [client 194.5.53.217:24123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/blue/rk2.php"] [unique_id "al4bEttIy0gkFcVddGZ3HwAAAT4"]
[Mon Jul 20 06:56:50.169933 2026] [security2:error] [pid 16093:tid 16327] [client 14.225.17.146:61759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4bEZuybMv3z_zMVBSyZwAAAfY"], referer: http://expertcultures.com/2022
[Mon Jul 20 06:56:50.171550 2026] [security2:error] [pid 15216:tid 15442] [client 50.116.65.227:22214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4bEdtIy0gkFcVddGZ3HQAAAWo"]
[Mon Jul 20 06:56:50.226139 2026] [security2:error] [pid 15216:tid 15404] [client 20.48.236.161:61169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/inx.php"] [unique_id "al4bEttIy0gkFcVddGZ3KgAAAUQ"]
[Mon Jul 20 06:56:50.226260 2026] [security2:error] [pid 15216:tid 15404] [client 20.48.236.161:61169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/inx.php"] [unique_id "al4bEttIy0gkFcVddGZ3KgAAAUQ"]
[Mon Jul 20 06:56:50.338814 2026] [security2:error] [pid 15216:tid 15427] [client 50.116.65.227:22236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4bEttIy0gkFcVddGZ3IgAAAVs"]
[Mon Jul 20 06:56:50.377593 2026] [security2:error] [pid 16093:tid 16239] [client 20.48.236.161:51673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/qqqa.php"] [unique_id "al4bEpuybMv3z_zMVBSyfAAAAZ4"]
[Mon Jul 20 06:56:50.377691 2026] [security2:error] [pid 16093:tid 16239] [client 20.48.236.161:51673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/qqqa.php"] [unique_id "al4bEpuybMv3z_zMVBSyfAAAAZ4"]
[Mon Jul 20 06:56:50.514321 2026] [security2:error] [pid 16093:tid 16318] [client 20.48.236.161:61133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/gk.php"] [unique_id "al4bEpuybMv3z_zMVBSyiwAAAe0"]
[Mon Jul 20 06:56:50.514397 2026] [security2:error] [pid 16093:tid 16318] [client 20.48.236.161:61133] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/gk.php"] [unique_id "al4bEpuybMv3z_zMVBSyiwAAAe0"]
[Mon Jul 20 06:56:50.651111 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/005.php"] [unique_id "al4bEpuybMv3z_zMVBSylAAAAZ8"]
[Mon Jul 20 06:56:50.651201 2026] [security2:error] [pid 16093:tid 16240] [client 20.48.236.161:61104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/005.php"] [unique_id "al4bEpuybMv3z_zMVBSylAAAAZ8"]
[Mon Jul 20 06:56:50.715979 2026] [security2:error] [pid 16093:tid 16272] [client 14.225.17.146:65083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4bEJuybMv3z_zMVBSyDAAAAb8"], referer: http://narv.co/2022
[Mon Jul 20 06:56:50.773489 2026] [security2:error] [pid 15216:tid 15465] [client 20.48.236.161:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/norn.php"] [unique_id "al4bEttIy0gkFcVddGZ3MgAAAYE"]
[Mon Jul 20 06:56:50.773608 2026] [security2:error] [pid 15216:tid 15465] [client 20.48.236.161:61086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/norn.php"] [unique_id "al4bEttIy0gkFcVddGZ3MgAAAYE"]
[Mon Jul 20 06:56:50.910115 2026] [security2:error] [pid 16093:tid 16300] [client 20.48.236.161:51627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.236.48.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/dmin.php"] [unique_id "al4bEpuybMv3z_zMVBSypQAAAds"]
[Mon Jul 20 06:56:50.910208 2026] [security2:error] [pid 16093:tid 16300] [client 20.48.236.161:51627] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcalendars.musichaven.info"] [uri "/dmin.php"] [unique_id "al4bEpuybMv3z_zMVBSypQAAAds"]
[Mon Jul 20 06:56:50.961424 2026] [security2:error] [pid 16093:tid 16302] [client 14.225.17.146:54072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4bEpuybMv3z_zMVBSynAAAAd0"], referer: http://thesoloceos.com/2022
[Mon Jul 20 06:56:51.240669 2026] [security2:error] [pid 15216:tid 15466] [client 14.225.17.146:50579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4bE9tIy0gkFcVddGZ3OwAAAYI"]
[Mon Jul 20 06:56:51.321331 2026] [security2:error] [pid 16093:tid 16251] [client 57.141.18.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4bE5uybMv3z_zMVBSyqwAAAao"]
[Mon Jul 20 06:56:51.383533 2026] [security2:error] [pid 16093:tid 16267] [client 104.207.51.215:19957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bE5uybMv3z_zMVBSyuAAAAbo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:51.697977 2026] [security2:error] [pid 16093:tid 16236] [client 77.110.127.138:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bE5uybMv3z_zMVBSyzAAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:51.698102 2026] [security2:error] [pid 16093:tid 16236] [client 77.110.127.138:60034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bE5uybMv3z_zMVBSyzAAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:51.769279 2026] [security2:error] [pid 15216:tid 15354] [client 14.225.17.146:54027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4bE9tIy0gkFcVddGZ3SQAAARI"], referer: https://narv.co/2022
[Mon Jul 20 06:56:51.839124 2026] [security2:error] [pid 16093:tid 16338] [client 45.3.55.187:57863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bE5uybMv3z_zMVBSy1gAAAgE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:56:51.866035 2026] [security2:error] [pid 16093:tid 16322] [client 194.5.53.246:61361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/class-config.php"] [unique_id "al4bE5uybMv3z_zMVBSy1wAAAfE"]
[Mon Jul 20 06:56:52.278614 2026] [security2:error] [pid 16093:tid 16299] [client 194.5.53.204:49785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/components/com_jea/views/form/tmpl/size.php"] [unique_id "al4bFJuybMv3z_zMVBSy-AAAAdo"]
[Mon Jul 20 06:56:52.399891 2026] [security2:error] [pid 16093:tid 16302] [client 187.16.64.216:51400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bFJuybMv3z_zMVBSy_QAAAd0"]
[Mon Jul 20 06:56:52.400004 2026] [security2:error] [pid 16093:tid 16302] [client 187.16.64.216:51400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bFJuybMv3z_zMVBSy_QAAAd0"]
[Mon Jul 20 06:56:52.422016 2026] [security2:error] [pid 16093:tid 16198] [remote 182.77.62.24:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4bFJuybMv3z_zMVBSy_wAB5mc"]
[Mon Jul 20 06:56:52.640793 2026] [security2:error] [pid 16093:tid 16228] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4bFJuybMv3z_zMVBSzBAAAAZM"]
[Mon Jul 20 06:56:52.645903 2026] [security2:error] [pid 16093:tid 16248] [client 194.5.53.217:20785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/templates/beez/index.php"] [unique_id "al4bFJuybMv3z_zMVBSzCQAAAac"]
[Mon Jul 20 06:56:52.979601 2026] [security2:error] [pid 16093:tid 16206] [remote 182.77.62.24:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4bFJuybMv3z_zMVBSzJQAB528"], referer: https://thslogistics.net/wp-login.php
[Mon Jul 20 06:56:52.987165 2026] [security2:error] [pid 16093:tid 16332] [client 104.207.53.248:23007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bFJuybMv3z_zMVBSzIwAAAfs"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:53.308066 2026] [security2:error] [pid 15216:tid 15467] [client 14.225.17.146:59391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4bFdtIy0gkFcVddGZ3awAAAYM"], referer: http://koaconsultants.com/2022
[Mon Jul 20 06:56:53.547859 2026] [security2:error] [pid 15216:tid 15463] [client 45.3.54.237:41161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bFdtIy0gkFcVddGZ3cwAAAX8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:53.675324 2026] [security2:error] [pid 16093:tid 16136] [remote 152.228.213.32:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bFZuybMv3z_zMVBSzTgABryk"]
[Mon Jul 20 06:56:53.899949 2026] [security2:error] [pid 16093:tid 16212] [remote 152.228.213.32:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bFZuybMv3z_zMVBSzXAABt3U"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:56:53.982673 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.195:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/bypass.php"] [unique_id "al4bFZuybMv3z_zMVBSzZAAAAZY"]
[Mon Jul 20 06:56:54.105742 2026] [security2:error] [pid 16093:tid 16339] [client 45.3.54.17:57375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bFpuybMv3z_zMVBSzbgAAAgI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:56:54.117497 2026] [security2:error] [pid 16093:tid 16293] [client 57.141.18.37:45270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bFJuybMv3z_zMVBSy6wAB1B4"]
[Mon Jul 20 06:56:54.358269 2026] [security2:error] [pid 16093:tid 16243] [client 194.5.53.243:27987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/class.php"] [unique_id "al4bFpuybMv3z_zMVBSzggAAAaI"]
[Mon Jul 20 06:56:54.575842 2026] [security2:error] [pid 16093:tid 16248] [client 187.108.85.186:58300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bFpuybMv3z_zMVBSzigAAAac"]
[Mon Jul 20 06:56:54.575985 2026] [security2:error] [pid 16093:tid 16248] [client 187.108.85.186:58300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bFpuybMv3z_zMVBSzigAAAac"]
[Mon Jul 20 06:56:55.019653 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:60063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bF9tIy0gkFcVddGZ3mgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:55.019760 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:60063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bF9tIy0gkFcVddGZ3mgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:55.167964 2026] [security2:error] [pid 16093:tid 16348] [client 14.225.17.146:54083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4bF5uybMv3z_zMVBSznwAAAgs"], referer: http://sarahholyfield.com/2022
[Mon Jul 20 06:56:55.315044 2026] [security2:error] [pid 16093:tid 16275] [client 148.251.126.195:46354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4bF5uybMv3z_zMVBSzsAAAAcI"]
[Mon Jul 20 06:56:55.419418 2026] [security2:error] [pid 16093:tid 16244] [client 103.144.65.217:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bF5uybMv3z_zMVBSzugAAAaM"]
[Mon Jul 20 06:56:55.419534 2026] [security2:error] [pid 16093:tid 16244] [client 103.144.65.217:62643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bF5uybMv3z_zMVBSzugAAAaM"]
[Mon Jul 20 06:56:55.654140 2026] [security2:error] [pid 16093:tid 16326] [client 117.222.139.248:65145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bF5uybMv3z_zMVBSzxQAAAfU"]
[Mon Jul 20 06:56:55.654264 2026] [security2:error] [pid 16093:tid 16326] [client 117.222.139.248:65145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bF5uybMv3z_zMVBSzxQAAAfU"]
[Mon Jul 20 06:56:55.779426 2026] [security2:error] [pid 15216:tid 15394] [client 194.5.53.236:42813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/light/profile.php"] [unique_id "al4bF9tIy0gkFcVddGZ3sAAAATo"]
[Mon Jul 20 06:56:56.316478 2026] [security2:error] [pid 16093:tid 16167] [remote 130.51.180.8:36530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4bGJuybMv3z_zMVBSz9AABv0g"]
[Mon Jul 20 06:56:56.316591 2026] [security2:error] [pid 16093:tid 16272] [client 130.51.180.8:36530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4bGJuybMv3z_zMVBSz9AABv0g"]
[Mon Jul 20 06:56:56.394527 2026] [security2:error] [pid 16093:tid 16232] [client 194.5.53.234:31473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/product.php"] [unique_id "al4bGJuybMv3z_zMVBSz-AAAAZc"]
[Mon Jul 20 06:56:56.423638 2026] [security2:error] [pid 16093:tid 16224] [client 148.251.126.195:46354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4bGJuybMv3z_zMVBSz9wAAAY8"]
[Mon Jul 20 06:56:56.427959 2026] [security2:error] [pid 16093:tid 16268] [client 57.141.18.41:27100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bFpuybMv3z_zMVBSzfgABu3k"]
[Mon Jul 20 06:56:56.481828 2026] [security2:error] [pid 16093:tid 16313] [client 14.225.17.146:51211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4bF5uybMv3z_zMVBSzvAAAAeg"], referer: http://claysharecon.com/2022
[Mon Jul 20 06:56:56.564139 2026] [security2:error] [pid 16093:tid 16171] [remote 173.249.4.11:24186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bGJuybMv3z_zMVBSz_wAB6kw"]
[Mon Jul 20 06:56:56.811202 2026] [security2:error] [pid 16093:tid 16261] [client 14.225.17.146:59378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4bGJuybMv3z_zMVBSz_QAAAbQ"], referer: http://eframiproperties.com/2022
[Mon Jul 20 06:56:56.852382 2026] [security2:error] [pid 15216:tid 15413] [client 65.1.132.125:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bGNtIy0gkFcVddGZ3yAAAAU0"]
[Mon Jul 20 06:56:56.852471 2026] [security2:error] [pid 15216:tid 15413] [client 65.1.132.125:37442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bGNtIy0gkFcVddGZ3yAAAAU0"]
[Mon Jul 20 06:56:56.876444 2026] [security2:error] [pid 16093:tid 16264] [client 50.116.65.227:22348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bGJuybMv3z_zMVBS0IAAAAbc"]
[Mon Jul 20 06:56:56.888914 2026] [security2:error] [pid 16093:tid 16236] [client 50.116.65.227:22362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bGJuybMv3z_zMVBS0IwAAAZs"]
[Mon Jul 20 06:56:57.031294 2026] [security2:error] [pid 16093:tid 16144] [remote 173.249.4.11:24186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bGZuybMv3z_zMVBS0LAABrzE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:56:57.128053 2026] [security2:error] [pid 16093:tid 16278] [client 14.225.17.146:51342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4bGJuybMv3z_zMVBS0KAAAAcU"]
[Mon Jul 20 06:56:57.137585 2026] [security2:error] [pid 16093:tid 16308] [client 14.224.227.113:54806] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bGZuybMv3z_zMVBS0OAAAAeM"]
[Mon Jul 20 06:56:57.451454 2026] [security2:error] [pid 16093:tid 16314] [client 197.186.66.42:59836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bGZuybMv3z_zMVBS0UwAAAek"]
[Mon Jul 20 06:56:57.451720 2026] [security2:error] [pid 16093:tid 16314] [client 197.186.66.42:59836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bGZuybMv3z_zMVBS0UwAAAek"]
[Mon Jul 20 06:56:57.546874 2026] [security2:error] [pid 16093:tid 16326] [client 34.24.137.199:57499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.137.24.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cfy.cnq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bGZuybMv3z_zMVBS0WwAAAfU"]
[Mon Jul 20 06:56:57.558058 2026] [security2:error] [pid 16093:tid 16284] [client 77.110.127.138:60084] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bGZuybMv3z_zMVBS0XgAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:57.798282 2026] [security2:error] [pid 16093:tid 16323] [client 34.24.137.199:53738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4bGZuybMv3z_zMVBS0cAAAAfI"]
[Mon Jul 20 06:56:57.969173 2026] [security2:error] [pid 15216:tid 15436] [client 114.119.135.232:60399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thierry-henry.fr"] [uri "/regle-de-72-doubler-capital"] [unique_id "al4bGdtIy0gkFcVddGZ31wAAAWQ"], referer: https://thierry-henry.fr/acheter-immeuble-de-rapport?ak_action=accept_mobile
[Mon Jul 20 06:56:57.971631 2026] [security2:error] [pid 16093:tid 16141] [remote 81.173.115.7:47252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4bGZuybMv3z_zMVBS0ewAB-i4"]
[Mon Jul 20 06:56:57.971876 2026] [security2:error] [pid 16093:tid 16331] [client 81.173.115.7:47252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4bGZuybMv3z_zMVBS0ewAB-i4"]
[Mon Jul 20 06:56:58.029229 2026] [security2:error] [pid 16093:tid 16333] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4bGZuybMv3z_zMVBS0VAAB_E4"], referer: http://ali-alghanim.net/2022
[Mon Jul 20 06:56:58.035665 2026] [security2:error] [pid 15216:tid 15461] [client 34.24.137.199:50526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4bGttIy0gkFcVddGZ32gAAAX0"]
[Mon Jul 20 06:56:58.202236 2026] [security2:error] [pid 15216:tid 15417] [client 104.234.53.76:65343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bGttIy0gkFcVddGZ33QAAAVE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:56:58.289311 2026] [security2:error] [pid 15216:tid 15396] [client 34.24.137.199:59772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4bGttIy0gkFcVddGZ33wAAATw"]
[Mon Jul 20 06:56:58.302916 2026] [security2:error] [pid 16093:tid 16322] [client 14.225.17.146:51322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4bGJuybMv3z_zMVBS0KQAAAfE"], referer: http://colinkeyphotography.com/2022
[Mon Jul 20 06:56:58.314567 2026] [security2:error] [pid 15216:tid 15428] [client 103.125.179.95:54298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bGttIy0gkFcVddGZ34gAAAVw"]
[Mon Jul 20 06:56:58.326255 2026] [security2:error] [pid 15216:tid 15428] [client 103.125.179.95:54298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bGttIy0gkFcVddGZ34gAAAVw"]
[Mon Jul 20 06:56:58.575592 2026] [security2:error] [pid 15216:tid 15447] [client 14.225.17.146:53883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4bGttIy0gkFcVddGZ34wAAAW8"], referer: http://margaretspeckogawa.com/2022
[Mon Jul 20 06:56:58.611173 2026] [security2:error] [pid 16093:tid 16237] [client 217.142.18.172:60601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bGpuybMv3z_zMVBS0pAAAAZw"]
[Mon Jul 20 06:56:58.622627 2026] [security2:error] [pid 16093:tid 16237] [client 217.142.18.172:60601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bGpuybMv3z_zMVBS0pAAAAZw"]
[Mon Jul 20 06:56:58.652080 2026] [security2:error] [pid 16093:tid 16323] [client 34.24.137.199:57819] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4bGpuybMv3z_zMVBS0pwAAAfI"]
[Mon Jul 20 06:56:58.923113 2026] [security2:error] [pid 15216:tid 15356] [client 34.24.137.199:59772] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4bGttIy0gkFcVddGZ37wAAARQ"]
[Mon Jul 20 06:56:59.035639 2026] [security2:error] [pid 16093:tid 16308] [client 14.225.17.146:50972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4bGpuybMv3z_zMVBS0swAAAeM"], referer: http://nomorewetsheets.net/2022
[Mon Jul 20 06:56:59.050252 2026] [security2:error] [pid 15216:tid 15400] [client 117.247.108.24:24790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bG9tIy0gkFcVddGZ39QAAAUA"]
[Mon Jul 20 06:56:59.050387 2026] [security2:error] [pid 15216:tid 15400] [client 117.247.108.24:24790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bG9tIy0gkFcVddGZ39QAAAUA"]
[Mon Jul 20 06:56:59.127019 2026] [security2:error] [pid 15216:tid 15398] [client 122.183.32.225:31154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bG9tIy0gkFcVddGZ39gAAAT4"]
[Mon Jul 20 06:56:59.127174 2026] [security2:error] [pid 15216:tid 15398] [client 122.183.32.225:31154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bG9tIy0gkFcVddGZ39gAAAT4"]
[Mon Jul 20 06:56:59.239564 2026] [security2:error] [pid 15216:tid 15435] [client 34.24.137.199:55811] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4bG9tIy0gkFcVddGZ3_wAAAWM"]
[Mon Jul 20 06:56:59.311126 2026] [security2:error] [pid 16093:tid 16274] [client 40.77.167.132:1751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bG5uybMv3z_zMVBS0wgABwRs"]
[Mon Jul 20 06:56:59.602615 2026] [security2:error] [pid 16093:tid 16321] [client 34.24.137.199:50023] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4bG5uybMv3z_zMVBS02AAAAfA"]
[Mon Jul 20 06:56:59.795138 2026] [security2:error] [pid 16093:tid 16110] [remote 57.141.18.79:23872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4bG5uybMv3z_zMVBS04wABzg8"]
[Mon Jul 20 06:56:59.811114 2026] [security2:error] [pid 16093:tid 16290] [client 77.110.127.138:60092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bG5uybMv3z_zMVBS05AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:59.811215 2026] [security2:error] [pid 16093:tid 16290] [client 77.110.127.138:60092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bG5uybMv3z_zMVBS05AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:56:59.868418 2026] [security2:error] [pid 16093:tid 16334] [client 183.82.98.154:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bG5uybMv3z_zMVBS07wAAAf0"]
[Mon Jul 20 06:56:59.868525 2026] [security2:error] [pid 16093:tid 16334] [client 183.82.98.154:50620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bG5uybMv3z_zMVBS07wAAAf0"]
[Mon Jul 20 06:56:59.875924 2026] [security2:error] [pid 16093:tid 16323] [client 34.24.137.199:65200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4bG5uybMv3z_zMVBS08gAAAfI"]
[Mon Jul 20 06:57:00.020998 2026] [security2:error] [pid 15216:tid 15379] [client 194.5.53.237:35847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/autoload_classmap.php"] [unique_id "al4bHNtIy0gkFcVddGZ4FgAAASs"]
[Mon Jul 20 06:57:00.050804 2026] [security2:error] [pid 16093:tid 16289] [client 155.2.212.10:54601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4bG5uybMv3z_zMVBS09QAAAdA"]
[Mon Jul 20 06:57:00.081914 2026] [security2:error] [pid 16093:tid 16226] [client 57.141.18.2:25842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bGZuybMv3z_zMVBS0bAABkWY"]
[Mon Jul 20 06:57:00.088432 2026] [security2:error] [pid 16093:tid 16244] [client 185.238.231.121:36743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4bG5uybMv3z_zMVBS09gAAAaM"]
[Mon Jul 20 06:57:00.180535 2026] [security2:error] [pid 16093:tid 16305] [client 34.24.137.199:49513] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4bHJuybMv3z_zMVBS1AgAAAeA"]
[Mon Jul 20 06:57:00.336611 2026] [security2:error] [pid 16093:tid 16224] [client 152.58.191.29:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bHJuybMv3z_zMVBS1CwAAAY8"]
[Mon Jul 20 06:57:00.336688 2026] [security2:error] [pid 16093:tid 16224] [client 152.58.191.29:56205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bHJuybMv3z_zMVBS1CwAAAY8"]
[Mon Jul 20 06:57:00.356200 2026] [security2:error] [pid 15216:tid 15461] [client 194.5.53.245:24093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/ask.php"] [unique_id "al4bHNtIy0gkFcVddGZ4GQAAAX0"]
[Mon Jul 20 06:57:00.412426 2026] [security2:error] [pid 16093:tid 16228] [client 34.24.137.199:56596] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4bHJuybMv3z_zMVBS1EQAAAZM"]
[Mon Jul 20 06:57:00.444625 2026] [security2:error] [pid 16093:tid 16208] [remote 8.217.108.67:44794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bHJuybMv3z_zMVBS1EgAB5XE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:57:00.495325 2026] [security2:error] [pid 15216:tid 15446] [client 103.238.106.162:63965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bHNtIy0gkFcVddGZ4HQAAAW4"]
[Mon Jul 20 06:57:00.495424 2026] [security2:error] [pid 15216:tid 15446] [client 103.238.106.162:63965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bHNtIy0gkFcVddGZ4HQAAAW4"]
[Mon Jul 20 06:57:00.653320 2026] [security2:error] [pid 16093:tid 16343] [client 34.24.137.199:65297] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4bHJuybMv3z_zMVBS1IgAAAgY"]
[Mon Jul 20 06:57:00.681478 2026] [security2:error] [pid 15216:tid 15455] [client 194.5.53.241:30607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/rest-api/about.php"] [unique_id "al4bHNtIy0gkFcVddGZ4IwAAAXc"]
[Mon Jul 20 06:57:00.899294 2026] [security2:error] [pid 15216:tid 15456] [client 34.24.137.199:58851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cfy.cnq.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4bHNtIy0gkFcVddGZ4JwAAAXg"]
[Mon Jul 20 06:57:01.141165 2026] [security2:error] [pid 15216:tid 15463] [client 57.141.18.24:28604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bGttIy0gkFcVddGZ38QABfwI"]
[Mon Jul 20 06:57:01.220402 2026] [security2:error] [pid 15216:tid 15420] [client 104.234.53.74:31141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bHdtIy0gkFcVddGZ4NQAAAVQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:01.423072 2026] [security2:error] [pid 15216:tid 15453] [client 194.5.53.221:53793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/css/css.php"] [unique_id "al4bHdtIy0gkFcVddGZ4NwAAAXU"]
[Mon Jul 20 06:57:01.482581 2026] [core:error] [pid 16093:tid 16311] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:01.482605 2026] [core:error] [pid 16093:tid 16311] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:01.494158 2026] [security2:error] [pid 16093:tid 16230] [client 14.225.17.146:54019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4bG5uybMv3z_zMVBS06gAAAZU"], referer: http://swafforddetailing.com/2022
[Mon Jul 20 06:57:01.813295 2026] [security2:error] [pid 16093:tid 16317] [client 194.5.53.250:21927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/init.php"] [unique_id "al4bHZuybMv3z_zMVBS1YgAAAew"]
[Mon Jul 20 06:57:01.880239 2026] [security2:error] [pid 15216:tid 15353] [client 14.225.17.146:59876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4bHNtIy0gkFcVddGZ4HgAAARE"], referer: http://elitetax-mi.com/2022
[Mon Jul 20 06:57:01.997791 2026] [security2:error] [pid 15216:tid 15379] [client 77.110.127.138:60102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bHdtIy0gkFcVddGZ4VwAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:02.023929 2026] [security2:error] [pid 16093:tid 16340] [client 14.225.17.146:59792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4bHZuybMv3z_zMVBS1ZQAAAgM"], referer: http://ncsynchro.com/2022
[Mon Jul 20 06:57:02.329672 2026] [security2:error] [pid 16093:tid 16348] [client 194.5.53.206:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/user/wp-login.php"] [unique_id "al4bHpuybMv3z_zMVBS1ewAAAgs"]
[Mon Jul 20 06:57:02.545103 2026] [security2:error] [pid 16093:tid 16268] [client 65.111.28.216:61061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bHpuybMv3z_zMVBS1iQAAAbs"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:02.724816 2026] [security2:error] [pid 15216:tid 15447] [client 14.225.17.146:59687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4bHdtIy0gkFcVddGZ4MwAAAW8"], referer: http://laceycaraccident.com/2022
[Mon Jul 20 06:57:02.765014 2026] [security2:error] [pid 16093:tid 16331] [client 194.5.53.237:60251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/autoload_classmap/function.php"] [unique_id "al4bHpuybMv3z_zMVBS1lQAAAfo"]
[Mon Jul 20 06:57:02.776587 2026] [security2:error] [pid 16093:tid 16322] [client 187.16.64.216:51906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bHpuybMv3z_zMVBS1lgAAAfE"]
[Mon Jul 20 06:57:02.776691 2026] [security2:error] [pid 16093:tid 16322] [client 187.16.64.216:51906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bHpuybMv3z_zMVBS1lgAAAfE"]
[Mon Jul 20 06:57:02.797622 2026] [security2:error] [pid 16093:tid 16258] [client 192.140.149.97:44506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bHpuybMv3z_zMVBS1mgAAAbE"]
[Mon Jul 20 06:57:02.797724 2026] [security2:error] [pid 16093:tid 16258] [client 192.140.149.97:44506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bHpuybMv3z_zMVBS1mgAAAbE"]
[Mon Jul 20 06:57:02.929570 2026] [security2:error] [pid 16093:tid 16329] [client 14.225.17.146:59397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4bHZuybMv3z_zMVBS1QwAAAfg"], referer: http://maplerespiteservices.com/2022
[Mon Jul 20 06:57:03.322708 2026] [security2:error] [pid 15216:tid 15386] [client 194.5.53.238:58665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/item.php"] [unique_id "al4bH9tIy0gkFcVddGZ4fwAAATI"]
[Mon Jul 20 06:57:03.468037 2026] [security2:error] [pid 16093:tid 16327] [client 158.173.166.181:40687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bH5uybMv3z_zMVBS1vQAAAfY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:57:03.684202 2026] [security2:error] [pid 15216:tid 15413] [client 104.207.51.83:55829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bH9tIy0gkFcVddGZ4hwAAAU0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:03.832579 2026] [security2:error] [pid 16093:tid 16328] [client 194.5.53.54:38515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/assets/index.php"] [unique_id "al4bH5uybMv3z_zMVBS10gAAAfc"]
[Mon Jul 20 06:57:03.987021 2026] [security2:error] [pid 16093:tid 16304] [client 65.111.23.6:45771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bH5uybMv3z_zMVBS11wAAAd8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:04.224165 2026] [security2:error] [pid 15216:tid 15362] [client 77.110.127.138:60107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bINtIy0gkFcVddGZ4lAAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:04.224274 2026] [security2:error] [pid 15216:tid 15362] [client 77.110.127.138:60107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bINtIy0gkFcVddGZ4lAAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:04.248941 2026] [security2:error] [pid 16093:tid 16318] [client 104.207.51.77:35613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bIJuybMv3z_zMVBS15QAAAe0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:04.377948 2026] [security2:error] [pid 15216:tid 15417] [client 194.5.53.201:22161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.well-known/pki-validation/index.php"] [unique_id "al4bINtIy0gkFcVddGZ4lgAAAVE"]
[Mon Jul 20 06:57:04.505005 2026] [security2:error] [pid 16093:tid 16274] [client 57.141.18.2:47398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bHpuybMv3z_zMVBS1gQABwUg"]
[Mon Jul 20 06:57:04.625526 2026] [security2:error] [pid 16093:tid 16306] [client 14.225.17.146:58354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4bIJuybMv3z_zMVBS1-gAAAeE"], referer: http://mtlegnews.gov/2022
[Mon Jul 20 06:57:04.945784 2026] [security2:error] [pid 16093:tid 16310] [client 157.245.205.168:54691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4bIJuybMv3z_zMVBS2EAAAAeU"]
[Mon Jul 20 06:57:05.139078 2026] [security2:error] [pid 16093:tid 16304] [client 187.108.85.186:58845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bIZuybMv3z_zMVBS2KgAAAd8"]
[Mon Jul 20 06:57:05.139239 2026] [security2:error] [pid 16093:tid 16304] [client 187.108.85.186:58845] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bIZuybMv3z_zMVBS2KgAAAd8"]
[Mon Jul 20 06:57:05.363846 2026] [security2:error] [pid 16093:tid 16191] [remote 74.12.64.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4bIZuybMv3z_zMVBS2LAABlGA"], referer: https://www.aleishapenny.ca/
[Mon Jul 20 06:57:05.567906 2026] [security2:error] [pid 16093:tid 16335] [client 77.110.127.138:60115] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bIZuybMv3z_zMVBS2UAAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:05.740409 2026] [security2:error] [pid 16093:tid 16262] [client 14.225.17.146:56810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4bIZuybMv3z_zMVBS2LgAAAbU"], referer: http://bruceledewitz.com/2022
[Mon Jul 20 06:57:06.005520 2026] [security2:error] [pid 15216:tid 15416] [client 103.144.65.217:63057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bIttIy0gkFcVddGZ4sgAAAVA"]
[Mon Jul 20 06:57:06.005626 2026] [security2:error] [pid 15216:tid 15416] [client 103.144.65.217:63057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bIttIy0gkFcVddGZ4sgAAAVA"]
[Mon Jul 20 06:57:06.035052 2026] [security2:error] [pid 16093:tid 16281] [client 194.5.53.206:63443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4bIpuybMv3z_zMVBS2bwAAAcg"]
[Mon Jul 20 06:57:06.057603 2026] [security2:error] [pid 16093:tid 16187] [remote 72.167.132.114:37390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bIpuybMv3z_zMVBS2cAAB_1w"]
[Mon Jul 20 06:57:06.219719 2026] [security2:error] [pid 15216:tid 15398] [client 117.222.139.248:49260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bIttIy0gkFcVddGZ4twAAAT4"]
[Mon Jul 20 06:57:06.220365 2026] [security2:error] [pid 15216:tid 15398] [client 117.222.139.248:49260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bIttIy0gkFcVddGZ4twAAAT4"]
[Mon Jul 20 06:57:06.276360 2026] [security2:error] [pid 16093:tid 16253] [client 57.141.18.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bIpuybMv3z_zMVBS2fQAAAaw"]
[Mon Jul 20 06:57:06.277331 2026] [security2:error] [pid 16093:tid 16110] [remote 72.167.132.114:37390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bIpuybMv3z_zMVBS2iwABsw8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:57:06.431321 2026] [security2:error] [pid 16093:tid 16205] [remote 20.153.140.50:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4bIpuybMv3z_zMVBS2lQABum4"]
[Mon Jul 20 06:57:06.460377 2026] [security2:error] [pid 16093:tid 16104] [remote 154.66.198.148:48714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4bIpuybMv3z_zMVBS2lwAB5wk"]
[Mon Jul 20 06:57:06.460496 2026] [security2:error] [pid 16093:tid 16312] [client 154.66.198.148:48714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4bIpuybMv3z_zMVBS2lwAB5wk"]
[Mon Jul 20 06:57:06.470916 2026] [security2:error] [pid 16093:tid 16286] [client 57.141.18.72:26620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bIJuybMv3z_zMVBS14QABzSs"]
[Mon Jul 20 06:57:06.530242 2026] [security2:error] [pid 15216:tid 15377] [client 14.225.17.146:57416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4bIttIy0gkFcVddGZ4vQAAASk"], referer: http://mazzucelli.com/2022
[Mon Jul 20 06:57:06.598231 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.240:61865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/css/admin.php"] [unique_id "al4bIpuybMv3z_zMVBS2nQAAAZY"]
[Mon Jul 20 06:57:06.747114 2026] [security2:error] [pid 16093:tid 16256] [client 57.141.0.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4bIZuybMv3z_zMVBS2PQAAAa8"]
[Mon Jul 20 06:57:06.869639 2026] [security2:error] [pid 16093:tid 16116] [remote 20.153.140.50:37592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4bIpuybMv3z_zMVBS2swACCBU"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 06:57:06.983730 2026] [security2:error] [pid 16093:tid 16308] [client 50.116.65.227:18418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4bIpuybMv3z_zMVBS2uQAAAeM"]
[Mon Jul 20 06:57:06.997723 2026] [security2:error] [pid 16093:tid 16272] [client 50.116.65.227:39420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4bIpuybMv3z_zMVBS2ugAAAb8"]
[Mon Jul 20 06:57:07.522939 2026] [security2:error] [pid 16093:tid 16334] [client 185.209.196.216:54520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.196.209.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "buildwithbluestem.com"] [uri "/xmlrpc.php"] [unique_id "al4bI5uybMv3z_zMVBS25gAAAf0"]
[Mon Jul 20 06:57:07.703734 2026] [security2:error] [pid 16093:tid 16281] [client 194.180.48.253:58040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "timespans.org"] [uri "/"] [unique_id "al4bI5uybMv3z_zMVBS28QAAAcg"]
[Mon Jul 20 06:57:07.792153 2026] [security2:error] [pid 16093:tid 16252] [client 104.234.53.49:38531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bI5uybMv3z_zMVBS2-wAAAas"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:07.995760 2026] [security2:error] [pid 16093:tid 16333] [client 14.225.17.146:57456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4bI5uybMv3z_zMVBS3AQAAAfw"], referer: http://xp-design.co/2022
[Mon Jul 20 06:57:08.025062 2026] [security2:error] [pid 16093:tid 16226] [client 194.5.53.221:58815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/adminfuns.php"] [unique_id "al4bJJuybMv3z_zMVBS3DQAAAZE"]
[Mon Jul 20 06:57:08.102126 2026] [security2:error] [pid 16093:tid 16271] [client 14.225.17.146:57513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4bI5uybMv3z_zMVBS3CgAAAb4"], referer: http://cheesewithjam.com/2022
[Mon Jul 20 06:57:08.493675 2026] [security2:error] [pid 16093:tid 16321] [client 194.5.53.227:29103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/autoload_classmap.php"] [unique_id "al4bJJuybMv3z_zMVBS3LwAAAfA"]
[Mon Jul 20 06:57:08.818688 2026] [security2:error] [pid 16093:tid 16294] [client 194.5.53.235:53013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp_wlx.php"] [unique_id "al4bJJuybMv3z_zMVBS3SwAAAdU"]
[Mon Jul 20 06:57:08.908711 2026] [security2:error] [pid 16093:tid 16225] [client 14.225.17.146:58754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4bJJuybMv3z_zMVBS3QQAAAZA"], referer: http://bigwormfishing.com/2022
[Mon Jul 20 06:57:09.051507 2026] [security2:error] [pid 15216:tid 15446] [client 104.234.53.69:45125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bJNtIy0gkFcVddGZ43AAAAW4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:09.155239 2026] [security2:error] [pid 16093:tid 16351] [client 57.141.18.48:55046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bIpuybMv3z_zMVBS2twACDnE"]
[Mon Jul 20 06:57:09.207469 2026] [security2:error] [pid 16093:tid 16256] [client 217.142.18.172:45765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bJZuybMv3z_zMVBS3ZAAAAa8"]
[Mon Jul 20 06:57:09.207589 2026] [security2:error] [pid 16093:tid 16256] [client 217.142.18.172:45765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bJZuybMv3z_zMVBS3ZAAAAa8"]
[Mon Jul 20 06:57:09.209496 2026] [security2:error] [pid 16093:tid 16308] [client 103.125.179.95:54809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bJZuybMv3z_zMVBS3ZQAAAeM"]
[Mon Jul 20 06:57:09.209595 2026] [security2:error] [pid 16093:tid 16308] [client 103.125.179.95:54809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bJZuybMv3z_zMVBS3ZQAAAeM"]
[Mon Jul 20 06:57:09.278531 2026] [security2:error] [pid 15216:tid 15357] [client 104.234.53.69:45125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bJdtIy0gkFcVddGZ44QAAARU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:09.784219 2026] [security2:error] [pid 16093:tid 16291] [client 122.183.32.225:32648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bJZuybMv3z_zMVBS3igAAAdI"]
[Mon Jul 20 06:57:09.784331 2026] [security2:error] [pid 16093:tid 16291] [client 122.183.32.225:32648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bJZuybMv3z_zMVBS3igAAAdI"]
[Mon Jul 20 06:57:09.842676 2026] [security2:error] [pid 16093:tid 16182] [remote 124.55.178.99:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4bJZuybMv3z_zMVBS3jwABpVc"]
[Mon Jul 20 06:57:09.931347 2026] [security2:error] [pid 16093:tid 16304] [client 14.225.17.146:59634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4bJZuybMv3z_zMVBS3jAAAAd8"], referer: https://bigwormfishing.com/2022
[Mon Jul 20 06:57:10.049250 2026] [security2:error] [pid 15216:tid 15444] [client 14.225.17.146:58803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4bJNtIy0gkFcVddGZ41gAAAWw"], referer: http://careysheatingandcooling.com/2022
[Mon Jul 20 06:57:10.093438 2026] [authz_core:error] [pid 16093:tid 16346] [client 205.210.31.173:60504] AH01630: client denied by server configuration: /home1/asliceo1/public_html/upsurgecommunications/php.ini, referer: http://www.upsurgecommunications.com/
[Mon Jul 20 06:57:10.194763 2026] [security2:error] [pid 16093:tid 16329] [client 57.141.18.103:30920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bI5uybMv3z_zMVBS3CQAB-CI"]
[Mon Jul 20 06:57:10.250846 2026] [security2:error] [pid 16093:tid 16154] [remote 124.55.178.99:40932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4bJpuybMv3z_zMVBS3pwABsTs"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 06:57:10.471896 2026] [security2:error] [pid 16093:tid 16323] [client 197.186.66.42:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS3tQAAAfI"]
[Mon Jul 20 06:57:10.471995 2026] [security2:error] [pid 16093:tid 16323] [client 197.186.66.42:60366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS3tQAAAfI"]
[Mon Jul 20 06:57:10.553937 2026] [security2:error] [pid 16093:tid 16271] [client 77.110.127.138:60150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bJpuybMv3z_zMVBS3uQAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:10.554035 2026] [security2:error] [pid 16093:tid 16271] [client 77.110.127.138:60150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bJpuybMv3z_zMVBS3uQAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:10.568519 2026] [security2:error] [pid 15216:tid 15398] [client 104.234.53.79:62813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bJttIy0gkFcVddGZ5AwAAAT4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:10.569518 2026] [security2:error] [pid 16093:tid 16235] [client 66.249.65.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4bJpuybMv3z_zMVBS3ogAAAZo"]
[Mon Jul 20 06:57:10.794783 2026] [security2:error] [pid 16093:tid 16280] [client 117.247.108.24:27369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS3ygAAAcc"]
[Mon Jul 20 06:57:10.794954 2026] [security2:error] [pid 16093:tid 16280] [client 117.247.108.24:27369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS3ygAAAcc"]
[Mon Jul 20 06:57:10.918286 2026] [security2:error] [pid 16093:tid 16339] [client 152.58.191.29:56652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS30AAAAgI"]
[Mon Jul 20 06:57:10.918961 2026] [security2:error] [pid 16093:tid 16339] [client 152.58.191.29:56652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS30AAAAgI"]
[Mon Jul 20 06:57:10.971946 2026] [security2:error] [pid 16093:tid 16225] [client 103.238.106.162:60536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS30wAAAZA"]
[Mon Jul 20 06:57:10.972089 2026] [security2:error] [pid 16093:tid 16225] [client 103.238.106.162:60536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bJpuybMv3z_zMVBS30wAAAZA"]
[Mon Jul 20 06:57:11.050623 2026] [security2:error] [pid 15216:tid 15430] [client 104.234.53.79:62813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bJ9tIy0gkFcVddGZ5EgAAAV4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:11.240617 2026] [security2:error] [pid 16093:tid 16299] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jodiraye.com"] [uri "/.well-known/about.php"] [unique_id "al4bJ5uybMv3z_zMVBS32gAAAdo"]
[Mon Jul 20 06:57:11.240800 2026] [security2:error] [pid 16093:tid 16299] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "jodiraye.com"] [uri "/.well-known/about.php"] [unique_id "al4bJ5uybMv3z_zMVBS32gAAAdo"]
[Mon Jul 20 06:57:11.370385 2026] [security2:error] [pid 16093:tid 16351] [client 77.110.127.138:60155] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bJ5uybMv3z_zMVBS36QAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:11.502435 2026] [security2:error] [pid 16093:tid 16250] [client 14.225.17.146:57484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4bJ5uybMv3z_zMVBS35AAAAak"], referer: http://alexsandbergmusic.com/2022
[Mon Jul 20 06:57:11.824616 2026] [security2:error] [pid 16093:tid 16321] [client 14.224.227.113:54809] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bJ5uybMv3z_zMVBS4FwAAAfA"]
[Mon Jul 20 06:57:12.062833 2026] [security2:error] [pid 16093:tid 16232] [client 57.141.18.18:51950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bJZuybMv3z_zMVBS3eAABl0k"]
[Mon Jul 20 06:57:12.169066 2026] [security2:error] [pid 16093:tid 16187] [remote 103.187.169.251:54480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4bKJuybMv3z_zMVBS4NAAB3lw"]
[Mon Jul 20 06:57:12.317223 2026] [security2:error] [pid 16093:tid 16340] [client 183.82.98.154:51396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bKJuybMv3z_zMVBS4PAAAAgM"]
[Mon Jul 20 06:57:12.317387 2026] [security2:error] [pid 16093:tid 16340] [client 183.82.98.154:51396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bKJuybMv3z_zMVBS4PAAAAgM"]
[Mon Jul 20 06:57:12.579355 2026] [security2:error] [pid 15216:tid 15357] [client 117.50.194.130:49804] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "117.50.194.130" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bKNtIy0gkFcVddGZ5NAAAARU"]
[Mon Jul 20 06:57:12.579477 2026] [security2:error] [pid 15216:tid 15357] [client 117.50.194.130:49804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bKNtIy0gkFcVddGZ5NAAAARU"]
[Mon Jul 20 06:57:12.842667 2026] [security2:error] [pid 16093:tid 16116] [remote 103.187.169.251:54480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4bKJuybMv3z_zMVBS4aQABzRU"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 06:57:12.977980 2026] [security2:error] [pid 16093:tid 16241] [client 57.141.18.48:55060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bJpuybMv3z_zMVBS3vQABoFQ"]
[Mon Jul 20 06:57:13.236705 2026] [security2:error] [pid 16093:tid 16304] [client 192.140.149.97:45599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bKZuybMv3z_zMVBS4kgAAAd8"]
[Mon Jul 20 06:57:13.236876 2026] [security2:error] [pid 16093:tid 16304] [client 192.140.149.97:45599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bKZuybMv3z_zMVBS4kgAAAd8"]
[Mon Jul 20 06:57:13.486985 2026] [security2:error] [pid 16093:tid 16242] [client 187.16.64.216:52399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bKZuybMv3z_zMVBS4vAAAAaE"]
[Mon Jul 20 06:57:13.487116 2026] [security2:error] [pid 16093:tid 16242] [client 187.16.64.216:52399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bKZuybMv3z_zMVBS4vAAAAaE"]
[Mon Jul 20 06:57:13.543327 2026] [security2:error] [pid 16093:tid 16154] [remote 52.35.117.102:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.origine.nz"] [uri "/"] [unique_id "al4bKZuybMv3z_zMVBS4xwAB4Ts"]
[Mon Jul 20 06:57:13.600724 2026] [security2:error] [pid 16093:tid 16348] [client 148.251.126.195:25654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4bKZuybMv3z_zMVBS4vgAAAgs"]
[Mon Jul 20 06:57:13.600946 2026] [security2:error] [pid 16093:tid 16312] [client 104.234.53.74:38829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bKZuybMv3z_zMVBS4yQAAAec"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:13.886984 2026] [security2:error] [pid 15216:tid 15433] [client 74.7.175.189:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "upi.wyv.mybluehost.me"] [uri "/index.php"] [unique_id "al4bJdtIy0gkFcVddGZ47AAAAWE"]
[Mon Jul 20 06:57:13.890700 2026] [security2:error] [pid 16093:tid 16239] [client 74.7.175.189:55202] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "upi.wyv.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4bJZuybMv3z_zMVBS3jQABnjo"]
[Mon Jul 20 06:57:14.192732 2026] [security2:error] [pid 16093:tid 16261] [client 104.207.35.138:13571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.35.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bKpuybMv3z_zMVBS46AAAAbQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:14.596046 2026] [security2:error] [pid 15216:tid 15375] [client 77.110.127.138:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bKttIy0gkFcVddGZ5aAAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:14.596172 2026] [security2:error] [pid 15216:tid 15375] [client 77.110.127.138:60166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bKttIy0gkFcVddGZ5aAAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:14.650378 2026] [security2:error] [pid 16093:tid 16296] [client 74.208.214.194:47714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4bKpuybMv3z_zMVBS5AAAAAdc"]
[Mon Jul 20 06:57:14.734578 2026] [security2:error] [pid 16093:tid 16227] [client 117.50.194.130:49816] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "117.50.194.130" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bKpuybMv3z_zMVBS5CAAAAZI"]
[Mon Jul 20 06:57:14.734670 2026] [security2:error] [pid 16093:tid 16227] [client 117.50.194.130:49816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bKpuybMv3z_zMVBS5CAAAAZI"]
[Mon Jul 20 06:57:14.834741 2026] [security2:error] [pid 15216:tid 15361] [client 220.181.108.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4bKttIy0gkFcVddGZ5ZAAAARk"]
[Mon Jul 20 06:57:15.129243 2026] [security2:error] [pid 16093:tid 16302] [client 104.234.53.48:46245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bK5uybMv3z_zMVBS5KAAAAd0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:15.141150 2026] [security2:error] [pid 16093:tid 16247] [client 57.141.18.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4bKZuybMv3z_zMVBS4xQAAAaY"]
[Mon Jul 20 06:57:15.238452 2026] [security2:error] [pid 16093:tid 16350] [client 14.225.17.146:61524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4bKpuybMv3z_zMVBS5HgAAAg0"], referer: http://idigress.agency/2022
[Mon Jul 20 06:57:15.681058 2026] [security2:error] [pid 15216:tid 15358] [client 66.249.70.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4bK9tIy0gkFcVddGZ5dwABFjo"]
[Mon Jul 20 06:57:15.786105 2026] [security2:error] [pid 16093:tid 16250] [client 187.108.85.186:59395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bK5uybMv3z_zMVBS5WQAAAak"]
[Mon Jul 20 06:57:15.786228 2026] [security2:error] [pid 16093:tid 16250] [client 187.108.85.186:59395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bK5uybMv3z_zMVBS5WQAAAak"]
[Mon Jul 20 06:57:16.037364 2026] [security2:error] [pid 15216:tid 15468] [client 117.50.194.130:49822] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "117.50.194.130" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bLNtIy0gkFcVddGZ5ggAAAYQ"]
[Mon Jul 20 06:57:16.037456 2026] [security2:error] [pid 15216:tid 15468] [client 117.50.194.130:49822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bLNtIy0gkFcVddGZ5ggAAAYQ"]
[Mon Jul 20 06:57:16.701551 2026] [security2:error] [pid 16093:tid 16288] [client 103.144.65.217:63469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bLJuybMv3z_zMVBS5lwAAAc8"]
[Mon Jul 20 06:57:16.702464 2026] [security2:error] [pid 16093:tid 16288] [client 103.144.65.217:63469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bLJuybMv3z_zMVBS5lwAAAc8"]
[Mon Jul 20 06:57:16.751228 2026] [security2:error] [pid 15216:tid 15347] [client 117.222.139.248:49765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bLNtIy0gkFcVddGZ5jwAAAQs"]
[Mon Jul 20 06:57:16.751319 2026] [security2:error] [pid 15216:tid 15347] [client 117.222.139.248:49765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bLNtIy0gkFcVddGZ5jwAAAQs"]
[Mon Jul 20 06:57:17.020636 2026] [security2:error] [pid 16093:tid 16127] [remote 5.252.52.249:38038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4bLZuybMv3z_zMVBS5qAAB_SA"]
[Mon Jul 20 06:57:17.046111 2026] [security2:error] [pid 16093:tid 16238] [client 104.234.53.90:20399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bLJuybMv3z_zMVBS5owAAAZ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:17.100746 2026] [security2:error] [pid 15216:tid 15360] [client 32.198.12.77:54790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bLdtIy0gkFcVddGZ5lgAAARg"]
[Mon Jul 20 06:57:17.100904 2026] [security2:error] [pid 15216:tid 15360] [client 32.198.12.77:54790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bLdtIy0gkFcVddGZ5lgAAARg"]
[Mon Jul 20 06:57:17.117916 2026] [security2:error] [pid 16093:tid 16331] [client 54.169.146.187:48976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bLZuybMv3z_zMVBS5qgAAAfo"]
[Mon Jul 20 06:57:17.118002 2026] [security2:error] [pid 16093:tid 16331] [client 54.169.146.187:48976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bLZuybMv3z_zMVBS5qgAAAfo"]
[Mon Jul 20 06:57:17.328170 2026] [security2:error] [pid 16093:tid 16166] [remote 5.252.52.249:38038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4bLZuybMv3z_zMVBS5xAABtkc"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 06:57:17.385599 2026] [security2:error] [pid 16093:tid 16255] [client 194.5.53.206:38281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "al4bLZuybMv3z_zMVBS5yQAAAa4"]
[Mon Jul 20 06:57:17.439105 2026] [security2:error] [pid 16093:tid 16327] [client 117.50.194.130:49828] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "117.50.194.130" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bLZuybMv3z_zMVBS5ywAAAfY"]
[Mon Jul 20 06:57:17.439209 2026] [security2:error] [pid 16093:tid 16327] [client 117.50.194.130:49828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "bluedoorbar.co.nz"] [uri "/wp-comments-post.php"] [unique_id "al4bLZuybMv3z_zMVBS5ywAAAfY"]
[Mon Jul 20 06:57:17.549404 2026] [security2:error] [pid 16093:tid 16242] [client 104.234.53.90:20399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bLZuybMv3z_zMVBS5zwAAAaE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:17.550664 2026] [security2:error] [pid 16093:tid 16293] [client 14.225.17.146:61353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4bLJuybMv3z_zMVBS5bAAAAdQ"], referer: http://sarahsnyder.net/2022
[Mon Jul 20 06:57:17.705169 2026] [security2:error] [pid 15216:tid 15465] [client 14.225.17.146:55319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4bLdtIy0gkFcVddGZ5rAAAAYE"], referer: http://getgarrison.com/2022
[Mon Jul 20 06:57:17.757139 2026] [security2:error] [pid 15216:tid 15444] [client 194.5.53.54:44359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/assets/husky301.php"] [unique_id "al4bLdtIy0gkFcVddGZ5sQAAAWw"]
[Mon Jul 20 06:57:18.078245 2026] [security2:error] [pid 16093:tid 16316] [client 194.5.53.243:22729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp.php"] [unique_id "al4bLpuybMv3z_zMVBS55wAAAes"]
[Mon Jul 20 06:57:18.297002 2026] [security2:error] [pid 16093:tid 16275] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4bLJuybMv3z_zMVBS5hgAAAcI"]
[Mon Jul 20 06:57:18.389185 2026] [security2:error] [pid 16093:tid 16318] [client 14.225.17.146:59103] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4bLJuybMv3z_zMVBS5pAAAAe0"]
[Mon Jul 20 06:57:18.534891 2026] [security2:error] [pid 15216:tid 15359] [client 14.225.17.146:55265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4bLttIy0gkFcVddGZ5wwAAARc"], referer: https://sarahsnyder.net/2022
[Mon Jul 20 06:57:18.550039 2026] [security2:error] [pid 16093:tid 16225] [client 194.5.53.238:37027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/blue/wp-trackback.php"] [unique_id "al4bLpuybMv3z_zMVBS6AgAAAZA"]
[Mon Jul 20 06:57:18.929385 2026] [security2:error] [pid 15216:tid 15455] [client 194.5.53.250:32617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/themes/chosen.php"] [unique_id "al4bLttIy0gkFcVddGZ50wAAAXc"]
[Mon Jul 20 06:57:18.945574 2026] [security2:error] [pid 16093:tid 16295] [client 14.225.17.146:55963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4bLJuybMv3z_zMVBS5ngAAAdY"], referer: http://younutrition.gr/2022
[Mon Jul 20 06:57:19.178719 2026] [security2:error] [pid 15216:tid 15460] [client 66.249.74.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4bL9tIy0gkFcVddGZ52AAAAXw"]
[Mon Jul 20 06:57:19.336274 2026] [security2:error] [pid 16093:tid 16340] [client 194.5.53.195:54315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-header.php"] [unique_id "al4bL5uybMv3z_zMVBS6LwAAAgM"]
[Mon Jul 20 06:57:19.612468 2026] [security2:error] [pid 16093:tid 16251] [client 77.110.127.138:60181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bL5uybMv3z_zMVBS6PQAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:19.612559 2026] [security2:error] [pid 16093:tid 16251] [client 77.110.127.138:60181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bL5uybMv3z_zMVBS6PQAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:19.641536 2026] [security2:error] [pid 15216:tid 15451] [client 14.225.17.146:59166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4bLttIy0gkFcVddGZ5xQAAAXM"], referer: http://uritems.net/2022
[Mon Jul 20 06:57:19.703218 2026] [security2:error] [pid 16093:tid 16323] [client 217.142.18.172:57911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bL5uybMv3z_zMVBS6QAAAAfI"]
[Mon Jul 20 06:57:19.710588 2026] [security2:error] [pid 16093:tid 16323] [client 217.142.18.172:57911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bL5uybMv3z_zMVBS6QAAAAfI"]
[Mon Jul 20 06:57:19.710694 2026] [security2:error] [pid 16093:tid 16329] [client 57.141.18.7:37938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bLZuybMv3z_zMVBS5rgAB-EM"]
[Mon Jul 20 06:57:19.759904 2026] [security2:error] [pid 16093:tid 16351] [client 194.5.53.54:45471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/themes/admin.php"] [unique_id "al4bL5uybMv3z_zMVBS6RgAAAg4"]
[Mon Jul 20 06:57:19.775499 2026] [security2:error] [pid 16093:tid 16327] [client 103.125.179.95:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bL5uybMv3z_zMVBS6SgAAAfY"]
[Mon Jul 20 06:57:19.775605 2026] [security2:error] [pid 16093:tid 16327] [client 103.125.179.95:55322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bL5uybMv3z_zMVBS6SgAAAfY"]
[Mon Jul 20 06:57:20.099073 2026] [security2:error] [pid 15216:tid 15452] [client 194.5.53.228:56053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/Marvins.php"] [unique_id "al4bMNtIy0gkFcVddGZ5-wAAAXQ"]
[Mon Jul 20 06:57:20.331953 2026] [security2:error] [pid 15216:tid 15379] [client 113.160.97.242:50587] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bMNtIy0gkFcVddGZ6AgAAASs"]
[Mon Jul 20 06:57:20.373953 2026] [security2:error] [pid 15216:tid 15426] [client 98.159.234.160:20625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bMNtIy0gkFcVddGZ6BQAAAVo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:57:20.434735 2026] [security2:error] [pid 16093:tid 16283] [client 110.249.201.26:15516] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/sites/default/files/pdf_file/thainc2.pdf"] [unique_id "al4bMJuybMv3z_zMVBS6ZQAAAco"]
[Mon Jul 20 06:57:20.487356 2026] [security2:error] [pid 15216:tid 15367] [client 114.119.145.7:48495] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.karimnawfal.com"] [uri "/robots.txt"] [unique_id "al4bMNtIy0gkFcVddGZ6CQAAAR8"], referer: https://www.karimnawfal.com/robots.txt
[Mon Jul 20 06:57:20.544252 2026] [security2:error] [pid 16093:tid 16230] [client 14.225.17.146:54357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4bMJuybMv3z_zMVBS6YQAAAZU"], referer: http://mobilesurvsolutions.com/2022
[Mon Jul 20 06:57:20.702908 2026] [security2:error] [pid 16093:tid 16241] [client 185.139.55.91:59709] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "midnightcarabao.studio"] [uri "/"] [unique_id "al4bMJuybMv3z_zMVBS6bwAAAaA"]
[Mon Jul 20 06:57:21.497969 2026] [security2:error] [pid 15216:tid 15417] [client 103.238.106.162:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bMdtIy0gkFcVddGZ6LgAAAVE"]
[Mon Jul 20 06:57:21.498083 2026] [security2:error] [pid 15216:tid 15417] [client 103.238.106.162:60777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bMdtIy0gkFcVddGZ6LgAAAVE"]
[Mon Jul 20 06:57:21.566535 2026] [security2:error] [pid 16093:tid 16303] [client 152.58.191.29:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bMZuybMv3z_zMVBS6kgAAAd4"]
[Mon Jul 20 06:57:21.566640 2026] [security2:error] [pid 16093:tid 16303] [client 152.58.191.29:57108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bMZuybMv3z_zMVBS6kgAAAd4"]
[Mon Jul 20 06:57:21.606699 2026] [security2:error] [pid 16093:tid 16293] [client 117.247.108.24:28190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bMZuybMv3z_zMVBS6kwAAAdQ"]
[Mon Jul 20 06:57:21.606827 2026] [security2:error] [pid 16093:tid 16293] [client 117.247.108.24:28190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bMZuybMv3z_zMVBS6kwAAAdQ"]
[Mon Jul 20 06:57:21.843057 2026] [security2:error] [pid 16093:tid 16305] [client 122.183.32.225:1475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bMZuybMv3z_zMVBS6nAAAAeA"]
[Mon Jul 20 06:57:21.843151 2026] [security2:error] [pid 16093:tid 16305] [client 122.183.32.225:1475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bMZuybMv3z_zMVBS6nAAAAeA"]
[Mon Jul 20 06:57:21.874499 2026] [security2:error] [pid 15216:tid 15450] [client 194.5.53.235:37465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/about.php"] [unique_id "al4bMdtIy0gkFcVddGZ6PwAAAXI"]
[Mon Jul 20 06:57:21.935533 2026] [security2:error] [pid 15216:tid 15449] [client 57.141.18.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bMdtIy0gkFcVddGZ6OwAAAXE"]
[Mon Jul 20 06:57:22.325525 2026] [security2:error] [pid 16093:tid 16260] [client 104.234.53.83:21189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bMpuybMv3z_zMVBS6tQAAAbM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:22.429385 2026] [security2:error] [pid 16093:tid 16139] [remote 188.166.241.141:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4bMpuybMv3z_zMVBS6ugAB_Sw"]
[Mon Jul 20 06:57:22.454586 2026] [security2:error] [pid 16093:tid 16267] [client 65.1.132.125:48768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bMpuybMv3z_zMVBS6vAAAAbo"]
[Mon Jul 20 06:57:22.454709 2026] [security2:error] [pid 16093:tid 16267] [client 65.1.132.125:48768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bMpuybMv3z_zMVBS6vAAAAbo"]
[Mon Jul 20 06:57:22.695285 2026] [security2:error] [pid 16093:tid 16290] [client 52.206.29.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4bMpuybMv3z_zMVBS6wQAB0VM"]
[Mon Jul 20 06:57:22.759544 2026] [security2:error] [pid 16093:tid 16341] [client 144.172.104.62:32788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.karimnawfal.com"] [uri "/index.php"] [unique_id "al4bMpuybMv3z_zMVBS6rQAAAgQ"]
[Mon Jul 20 06:57:22.787132 2026] [security2:error] [pid 16093:tid 16155] [remote 188.166.241.141:39632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4bMpuybMv3z_zMVBS62wABvTw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:57:22.906360 2026] [security2:error] [pid 15216:tid 15351] [client 206.160.93.221:50531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4bMdtIy0gkFcVddGZ6PQABDww"]
[Mon Jul 20 06:57:23.079547 2026] [lsapi:warn] [pid 16093:tid 16323] [client 14.225.17.146:54385] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2022
[Mon Jul 20 06:57:23.079586 2026] [lsapi:warn] [pid 16093:tid 16323] [client 14.225.17.146:54385] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2022
[Mon Jul 20 06:57:23.161687 2026] [lsapi:warn] [pid 16093:tid 16322] [client 50.116.65.227:12942] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:57:23.161710 2026] [lsapi:warn] [pid 16093:tid 16322] [client 50.116.65.227:12942] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 06:57:23.177187 2026] [security2:error] [pid 16093:tid 16323] [client 14.225.17.146:54385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4bM5uybMv3z_zMVBS66QAAAfI"], referer: http://oswegooperatheater.com/2022
[Mon Jul 20 06:57:23.178794 2026] [security2:error] [pid 16093:tid 16260] [client 104.234.53.49:65361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bM5uybMv3z_zMVBS68AAAAbM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:23.290105 2026] [security2:error] [pid 16093:tid 16212] [remote 103.255.134.61:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4bM5uybMv3z_zMVBS6-gACAHU"]
[Mon Jul 20 06:57:23.344515 2026] [security2:error] [pid 16093:tid 16230] [client 194.5.53.246:43235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-class.php"] [unique_id "al4bM5uybMv3z_zMVBS6_gAAAZU"]
[Mon Jul 20 06:57:23.375078 2026] [security2:error] [pid 15216:tid 15425] [client 197.186.66.42:60911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bM9tIy0gkFcVddGZ6bgAAAVk"]
[Mon Jul 20 06:57:23.375212 2026] [security2:error] [pid 15216:tid 15425] [client 197.186.66.42:60911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bM9tIy0gkFcVddGZ6bgAAAVk"]
[Mon Jul 20 06:57:23.697491 2026] [security2:error] [pid 16093:tid 16321] [client 14.225.17.146:54304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4bMpuybMv3z_zMVBS63wAAAfA"]
[Mon Jul 20 06:57:23.731336 2026] [security2:error] [pid 15216:tid 15465] [client 104.234.53.88:53377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bM9tIy0gkFcVddGZ6hQAAAYE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:23.833240 2026] [security2:error] [pid 16093:tid 16257] [client 192.140.149.97:46039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bM5uybMv3z_zMVBS7CwAAAbA"]
[Mon Jul 20 06:57:23.833423 2026] [security2:error] [pid 16093:tid 16257] [client 192.140.149.97:46039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bM5uybMv3z_zMVBS7CwAAAbA"]
[Mon Jul 20 06:57:23.850660 2026] [security2:error] [pid 16093:tid 16332] [client 194.5.53.227:54803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/images/smilies/index.php"] [unique_id "al4bM5uybMv3z_zMVBS7DQAAAfs"]
[Mon Jul 20 06:57:23.898246 2026] [security2:error] [pid 16093:tid 16215] [remote 103.255.134.61:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4bM5uybMv3z_zMVBS7EAABzXg"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 06:57:23.999968 2026] [lsapi:warn] [pid 16093:tid 16284] [client 14.225.17.146:54192] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2022
[Mon Jul 20 06:57:23.999989 2026] [lsapi:warn] [pid 16093:tid 16284] [client 14.225.17.146:54192] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2022
[Mon Jul 20 06:57:24.042762 2026] [security2:error] [pid 16093:tid 16248] [client 14.225.17.146:53739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4bMpuybMv3z_zMVBS6vQAAAac"], referer: http://ironcitywellness.com/2022
[Mon Jul 20 06:57:24.157408 2026] [security2:error] [pid 16093:tid 16297] [client 187.16.64.216:52896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bNJuybMv3z_zMVBS7IgAAAdg"]
[Mon Jul 20 06:57:24.157581 2026] [security2:error] [pid 16093:tid 16297] [client 187.16.64.216:52896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bNJuybMv3z_zMVBS7IgAAAdg"]
[Mon Jul 20 06:57:24.236583 2026] [security2:error] [pid 16093:tid 16265] [client 2001:4490:4ec9:b1ad:9f3b:b478:20d3:e4a2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4bNJuybMv3z_zMVBS7HQABuHQ"], referer: https://origine.nz/?utm_source=ig&utm_medium=social&utm_content=link_in_bio&fbclid=PAZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQPNTY3MDY3MzQzMzUyNDI3AAGnikyXXS5W05XayxmVRclf44m-YFka3s4_M-ztNMBkCIpnvfBRDMx6xuS-Kj0_aem_qZrlV5sAQXxbt0PgCytrUg
[Mon Jul 20 06:57:24.253541 2026] [security2:error] [pid 16093:tid 16233] [client 57.141.18.73:23640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4bNJuybMv3z_zMVBS7HAABmG8"]
[Mon Jul 20 06:57:24.261961 2026] [security2:error] [pid 16093:tid 16258] [client 194.5.53.248:35263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/xx.php"] [unique_id "al4bNJuybMv3z_zMVBS7JgAAAbE"]
[Mon Jul 20 06:57:24.263103 2026] [security2:error] [pid 16093:tid 16277] [client 65.111.3.115:34515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bNJuybMv3z_zMVBS7JQAAAcQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:24.823399 2026] [security2:error] [pid 16093:tid 16228] [client 14.225.17.146:56274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4bNJuybMv3z_zMVBS7QwAAAZM"], referer: http://taskidsvirginia.com/2022
[Mon Jul 20 06:57:24.861621 2026] [security2:error] [pid 16093:tid 16280] [client 14.225.17.146:54435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4bMpuybMv3z_zMVBS6yQAAAcc"]
[Mon Jul 20 06:57:24.969423 2026] [security2:error] [pid 16093:tid 16328] [client 194.5.53.220:55919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/autoload_classmap.php"] [unique_id "al4bNJuybMv3z_zMVBS7VAAAAfc"]
[Mon Jul 20 06:57:25.008148 2026] [security2:error] [pid 16093:tid 16323] [client 104.234.53.49:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bNZuybMv3z_zMVBS7WgAAAfI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:25.641193 2026] [security2:error] [pid 16093:tid 16228] [client 194.5.53.243:34131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al4bNZuybMv3z_zMVBS7ewAAAZM"]
[Mon Jul 20 06:57:25.999217 2026] [security2:error] [pid 16093:tid 16315] [client 14.225.17.146:54485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4bNZuybMv3z_zMVBS7fgAAAeo"], referer: http://falconarrowshop.com/2022
[Mon Jul 20 06:57:26.080279 2026] [security2:error] [pid 16093:tid 16347] [client 194.5.53.212:43199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/blue.php"] [unique_id "al4bNpuybMv3z_zMVBS7kwAAAgo"]
[Mon Jul 20 06:57:26.140046 2026] [security2:error] [pid 16093:tid 16242] [client 57.141.18.8:47762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bM5uybMv3z_zMVBS68gABoW0"]
[Mon Jul 20 06:57:26.165461 2026] [security2:error] [pid 15216:tid 15364] [client 77.110.127.138:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bNttIy0gkFcVddGZ62QAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:26.165545 2026] [security2:error] [pid 15216:tid 15364] [client 77.110.127.138:60225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bNttIy0gkFcVddGZ62QAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:26.505432 2026] [security2:error] [pid 15216:tid 15284] [remote 5.252.52.249:42306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bNttIy0gkFcVddGZ64wABLUM"]
[Mon Jul 20 06:57:26.505584 2026] [security2:error] [pid 15216:tid 15381] [client 5.252.52.249:42306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bNttIy0gkFcVddGZ64wABLUM"]
[Mon Jul 20 06:57:26.576038 2026] [security2:error] [pid 16093:tid 16232] [client 194.5.53.248:54019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/content.php"] [unique_id "al4bNpuybMv3z_zMVBS7qAAAAZc"]
[Mon Jul 20 06:57:26.626046 2026] [security2:error] [pid 15216:tid 15396] [client 187.108.85.186:59949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bNttIy0gkFcVddGZ65wAAATw"]
[Mon Jul 20 06:57:26.626164 2026] [security2:error] [pid 15216:tid 15396] [client 187.108.85.186:59949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bNttIy0gkFcVddGZ65wAAATw"]
[Mon Jul 20 06:57:26.760210 2026] [security2:error] [pid 15216:tid 15335] [remote 103.187.169.251:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bNttIy0gkFcVddGZ68gABF3Y"]
[Mon Jul 20 06:57:26.821268 2026] [security2:error] [pid 15216:tid 15383] [client 110.249.201.10:46844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vfcthomasville.org"] [uri "/robots.txt"] [unique_id "al4bNttIy0gkFcVddGZ68wAAAS8"]
[Mon Jul 20 06:57:26.928683 2026] [security2:error] [pid 15216:tid 15370] [client 13.232.231.177:28902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bNttIy0gkFcVddGZ69gAAASI"]
[Mon Jul 20 06:57:27.189624 2026] [security2:error] [pid 16093:tid 16300] [client 66.249.74.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.alaraycreative.com"] [uri "/index.php"] [unique_id "al4bN5uybMv3z_zMVBS7ugAAAds"]
[Mon Jul 20 06:57:27.197791 2026] [security2:error] [pid 15216:tid 15322] [remote 103.187.169.251:52812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bN9tIy0gkFcVddGZ7AwABiWk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:57:27.260008 2026] [security2:error] [pid 15216:tid 15455] [client 117.222.139.248:50274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bN9tIy0gkFcVddGZ7CAAAAXc"]
[Mon Jul 20 06:57:27.260222 2026] [security2:error] [pid 15216:tid 15455] [client 117.222.139.248:50274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bN9tIy0gkFcVddGZ7CAAAAXc"]
[Mon Jul 20 06:57:27.271850 2026] [security2:error] [pid 16093:tid 16262] [client 103.144.65.217:63885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bN5uybMv3z_zMVBS7xgAAAbU"]
[Mon Jul 20 06:57:27.271984 2026] [security2:error] [pid 16093:tid 16262] [client 103.144.65.217:63885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bN5uybMv3z_zMVBS7xgAAAbU"]
[Mon Jul 20 06:57:27.273265 2026] [security2:error] [pid 15216:tid 15346] [client 14.251.3.155:54816] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bN9tIy0gkFcVddGZ7CQAAAQo"]
[Mon Jul 20 06:57:27.716647 2026] [security2:error] [pid 16093:tid 16310] [client 14.225.17.146:49760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4bN5uybMv3z_zMVBS7zQAAAeU"], referer: http://fkconstructionfunding.com/2022
[Mon Jul 20 06:57:27.747637 2026] [security2:error] [pid 16093:tid 16269] [client 104.234.53.86:54517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bN5uybMv3z_zMVBS72AAAAbw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:27.957012 2026] [security2:error] [pid 16093:tid 16340] [client 13.233.207.33:33318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bN5uybMv3z_zMVBS74QAAAgM"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:57:27.996667 2026] [security2:error] [pid 15216:tid 15441] [client 50.116.65.227:56708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4bN9tIy0gkFcVddGZ7NAAAAWk"]
[Mon Jul 20 06:57:28.009339 2026] [security2:error] [pid 15216:tid 15363] [client 50.116.65.227:13054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4bONtIy0gkFcVddGZ7NQAAASQ"]
[Mon Jul 20 06:57:28.062644 2026] [security2:error] [pid 15216:tid 15392] [client 50.116.65.227:13046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4bN9tIy0gkFcVddGZ7LAAAATg"]
[Mon Jul 20 06:57:28.255909 2026] [security2:error] [pid 15216:tid 15428] [client 50.116.65.227:13058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4bONtIy0gkFcVddGZ7OQAAAVw"]
[Mon Jul 20 06:57:28.434608 2026] [security2:error] [pid 16093:tid 16242] [client 194.5.53.243:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/about.php"] [unique_id "al4bOJuybMv3z_zMVBS77AAAAaE"]
[Mon Jul 20 06:57:28.472203 2026] [security2:error] [pid 15216:tid 15407] [client 14.225.17.146:56328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4bNttIy0gkFcVddGZ6-AAAAUc"], referer: http://kromosenergy.com/2022
[Mon Jul 20 06:57:28.800636 2026] [security2:error] [pid 15216:tid 15433] [client 194.5.53.219:45953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/wp-login.php"] [unique_id "al4bONtIy0gkFcVddGZ7WgAAAWE"]
[Mon Jul 20 06:57:29.115135 2026] [security2:error] [pid 16093:tid 16271] [client 104.234.53.80:62101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bOZuybMv3z_zMVBS7_AAAAb4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:29.161779 2026] [security2:error] [pid 15216:tid 15424] [client 194.5.53.237:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/rest-api/endpoints/index.php"] [unique_id "al4bOdtIy0gkFcVddGZ7aAAAAVg"]
[Mon Jul 20 06:57:29.286227 2026] [security2:error] [pid 16093:tid 16240] [client 14.225.17.146:53351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4bOJuybMv3z_zMVBS7-AAAAZ8"]
[Mon Jul 20 06:57:29.543996 2026] [security2:error] [pid 16093:tid 16347] [client 194.5.53.54:53761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/languages/about.php"] [unique_id "al4bOZuybMv3z_zMVBS8FgAAAgo"]
[Mon Jul 20 06:57:30.019934 2026] [security2:error] [pid 16093:tid 16230] [client 194.5.53.244:60835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "al4bOpuybMv3z_zMVBS8PAAAAZU"]
[Mon Jul 20 06:57:30.306548 2026] [security2:error] [pid 16093:tid 16289] [client 217.142.18.172:36953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bOpuybMv3z_zMVBS8TAAAAdA"]
[Mon Jul 20 06:57:30.306666 2026] [security2:error] [pid 16093:tid 16289] [client 217.142.18.172:36953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bOpuybMv3z_zMVBS8TAAAAdA"]
[Mon Jul 20 06:57:30.338435 2026] [security2:error] [pid 16093:tid 16310] [client 194.5.53.236:46579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/up/main.php"] [unique_id "al4bOpuybMv3z_zMVBS8UQAAAeU"]
[Mon Jul 20 06:57:30.417876 2026] [access_compat:error] [pid 16093:tid 16247] [client 66.249.73.128:62081] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/robots.txt
[Mon Jul 20 06:57:30.500013 2026] [security2:error] [pid 15216:tid 15423] [client 14.225.17.146:63230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4bOttIy0gkFcVddGZ7kAAAAVc"], referer: http://friendlyspreadsheet.com/2022
[Mon Jul 20 06:57:30.507191 2026] [security2:error] [pid 16093:tid 16145] [remote 64.225.121.94:37146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bOpuybMv3z_zMVBS8ZwABkDI"]
[Mon Jul 20 06:57:30.507489 2026] [security2:error] [pid 16093:tid 16225] [client 64.225.121.94:37146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bOpuybMv3z_zMVBS8ZwABkDI"]
[Mon Jul 20 06:57:30.614398 2026] [security2:error] [pid 15216:tid 15350] [client 103.125.179.95:55843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bOttIy0gkFcVddGZ7mQAAAQ4"]
[Mon Jul 20 06:57:30.614527 2026] [security2:error] [pid 15216:tid 15350] [client 103.125.179.95:55843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bOttIy0gkFcVddGZ7mQAAAQ4"]
[Mon Jul 20 06:57:30.617871 2026] [security2:error] [pid 16093:tid 16290] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplecleaningandhomecare.ca"] [uri "/index.php"] [unique_id "al4bOpuybMv3z_zMVBS8UgAAAdE"]
[Mon Jul 20 06:57:30.632830 2026] [security2:error] [pid 16093:tid 16304] [client 57.141.18.29:27886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bN5uybMv3z_zMVBS74AAB334"]
[Mon Jul 20 06:57:30.652137 2026] [security2:error] [pid 16093:tid 16350] [client 194.5.53.244:65137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/fonts/fontawesome-webfont.php"] [unique_id "al4bOpuybMv3z_zMVBS8fQAAAg0"]
[Mon Jul 20 06:57:30.706187 2026] [security2:error] [pid 16093:tid 16301] [client 104.234.53.89:21833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bOpuybMv3z_zMVBS8ggAAAdw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:31.122709 2026] [security2:error] [pid 15216:tid 15468] [client 194.5.53.55:28061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al4bO9tIy0gkFcVddGZ7qQAAAYQ"]
[Mon Jul 20 06:57:31.488964 2026] [security2:error] [pid 15216:tid 15367] [client 117.247.108.24:28758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bO9tIy0gkFcVddGZ7wAAAAR8"]
[Mon Jul 20 06:57:31.489086 2026] [security2:error] [pid 15216:tid 15367] [client 117.247.108.24:28758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bO9tIy0gkFcVddGZ7wAAAAR8"]
[Mon Jul 20 06:57:31.498914 2026] [security2:error] [pid 16093:tid 16336] [client 50.116.65.227:43612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bO5uybMv3z_zMVBS8mwAAAf8"]
[Mon Jul 20 06:57:31.508040 2026] [security2:error] [pid 16093:tid 16321] [client 50.116.65.227:43616] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bO5uybMv3z_zMVBS8nAAAAfA"]
[Mon Jul 20 06:57:31.548514 2026] [security2:error] [pid 16093:tid 16229] [client 194.5.53.47:37469] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/includes/about.php"] [unique_id "al4bO5uybMv3z_zMVBS8nQAAAZQ"]
[Mon Jul 20 06:57:31.665594 2026] [security2:error] [pid 15216:tid 15469] [client 14.225.17.146:56271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4bOdtIy0gkFcVddGZ7gwAAAYU"], referer: http://according2plant.com/2022
[Mon Jul 20 06:57:31.779908 2026] [security2:error] [pid 16093:tid 16284] [client 14.225.17.146:49628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4bOpuybMv3z_zMVBS8fwAAAcs"], referer: http://gearwaterproof.com/2022
[Mon Jul 20 06:57:31.909395 2026] [security2:error] [pid 16093:tid 16292] [client 104.207.51.85:61051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bO5uybMv3z_zMVBS8rQAAAdM"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:31.926426 2026] [security2:error] [pid 16093:tid 16138] [remote 212.95.34.85:40722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4bO5uybMv3z_zMVBS8sgAB6Ss"]
[Mon Jul 20 06:57:32.039221 2026] [security2:error] [pid 15216:tid 15442] [client 103.238.106.162:63761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bPNtIy0gkFcVddGZ70gAAAWo"]
[Mon Jul 20 06:57:32.039338 2026] [security2:error] [pid 15216:tid 15442] [client 103.238.106.162:63761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bPNtIy0gkFcVddGZ70gAAAWo"]
[Mon Jul 20 06:57:32.148453 2026] [security2:error] [pid 16093:tid 16140] [remote 47.86.33.52:63178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4bPJuybMv3z_zMVBS8uwACBy0"]
[Mon Jul 20 06:57:32.150345 2026] [security2:error] [pid 16093:tid 16209] [remote 212.95.34.85:40722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4bPJuybMv3z_zMVBS8vAAB5XI"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 06:57:32.229618 2026] [security2:error] [pid 16093:tid 16139] [remote 159.65.81.207:59114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bPJuybMv3z_zMVBS8vwABvSw"]
[Mon Jul 20 06:57:32.229805 2026] [security2:error] [pid 16093:tid 16270] [client 159.65.81.207:59114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bPJuybMv3z_zMVBS8vwABvSw"]
[Mon Jul 20 06:57:32.273510 2026] [security2:error] [pid 16093:tid 16262] [client 152.58.191.29:57556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bPJuybMv3z_zMVBS8wgAAAbU"]
[Mon Jul 20 06:57:32.273629 2026] [security2:error] [pid 16093:tid 16262] [client 152.58.191.29:57556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bPJuybMv3z_zMVBS8wgAAAbU"]
[Mon Jul 20 06:57:32.499769 2026] [security2:error] [pid 15216:tid 15377] [client 65.111.23.36:26017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bPNtIy0gkFcVddGZ73gAAASk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:32.761076 2026] [core:error] [pid 16093:tid 16225] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:32.761079 2026] [core:error] [pid 16093:tid 16224] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:32.761102 2026] [core:error] [pid 16093:tid 16225] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:32.761109 2026] [core:error] [pid 16093:tid 16224] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:32.769630 2026] [security2:error] [pid 15216:tid 15437] [client 194.5.53.227:26427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "al4bPNtIy0gkFcVddGZ76gAAAWU"]
[Mon Jul 20 06:57:32.777967 2026] [core:error] [pid 16093:tid 16323] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:32.777993 2026] [core:error] [pid 16093:tid 16323] [client 94.154.43.179:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:57:33.051652 2026] [security2:error] [pid 16093:tid 16334] [client 57.141.18.23:25786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bOpuybMv3z_zMVBS8fgAB_TU"]
[Mon Jul 20 06:57:33.059615 2026] [security2:error] [pid 16093:tid 16277] [client 104.207.52.43:54807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bPZuybMv3z_zMVBS85QAAAcQ"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:33.255932 2026] [security2:error] [pid 15216:tid 15466] [client 77.110.127.138:60256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPdtIy0gkFcVddGZ8AgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.256092 2026] [security2:error] [pid 15216:tid 15466] [client 77.110.127.138:60256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPdtIy0gkFcVddGZ8AgAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.408566 2026] [security2:error] [pid 16093:tid 16349] [client 77.110.127.138:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPZuybMv3z_zMVBS88gAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.408647 2026] [security2:error] [pid 16093:tid 16349] [client 77.110.127.138:60260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPZuybMv3z_zMVBS88gAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.474595 2026] [security2:error] [pid 16093:tid 16315] [client 54.244.177.189:51702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4bPZuybMv3z_zMVBS89wAAAeo"]
[Mon Jul 20 06:57:33.498164 2026] [security2:error] [pid 15216:tid 15367] [client 45.157.112.60:42601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bPdtIy0gkFcVddGZ8CAAAAR8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:57:33.563346 2026] [security2:error] [pid 16093:tid 16163] [remote 188.40.28.4:55414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4bPZuybMv3z_zMVBS8_QABpUQ"]
[Mon Jul 20 06:57:33.588883 2026] [security2:error] [pid 16093:tid 16258] [client 77.110.127.138:60261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPZuybMv3z_zMVBS8_gAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.588960 2026] [security2:error] [pid 16093:tid 16258] [client 77.110.127.138:60261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPZuybMv3z_zMVBS8_gAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.605184 2026] [security2:error] [pid 15216:tid 15357] [client 45.3.42.26:28597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bPdtIy0gkFcVddGZ8DAAAARU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:33.749422 2026] [security2:error] [pid 16093:tid 16215] [remote 188.40.28.4:55414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4bPZuybMv3z_zMVBS9AgABlHg"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 06:57:33.759974 2026] [security2:error] [pid 15216:tid 15432] [client 77.110.127.138:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPdtIy0gkFcVddGZ8EAAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.760077 2026] [security2:error] [pid 15216:tid 15432] [client 77.110.127.138:60262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPdtIy0gkFcVddGZ8EAAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:33.964039 2026] [security2:error] [pid 16093:tid 16211] [remote 5.252.52.249:42480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bPZuybMv3z_zMVBS9CgAB03Q"]
[Mon Jul 20 06:57:34.005291 2026] [security2:error] [pid 16093:tid 16291] [client 57.141.18.91:27912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bO5uybMv3z_zMVBS8qQAB0nM"]
[Mon Jul 20 06:57:34.157318 2026] [security2:error] [pid 16093:tid 16206] [remote 5.252.52.249:42480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bPpuybMv3z_zMVBS9DAABvG8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:57:34.160580 2026] [security2:error] [pid 16093:tid 16278] [client 104.207.50.101:29267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bPpuybMv3z_zMVBS9CwAAAcU"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:34.527364 2026] [security2:error] [pid 15216:tid 15423] [client 192.140.149.97:44613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bPttIy0gkFcVddGZ8OQAAAVc"]
[Mon Jul 20 06:57:34.527471 2026] [security2:error] [pid 15216:tid 15423] [client 192.140.149.97:44613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bPttIy0gkFcVddGZ8OQAAAVc"]
[Mon Jul 20 06:57:34.540475 2026] [security2:error] [pid 16093:tid 16266] [client 45.3.34.197:26827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bPpuybMv3z_zMVBS9GgAAAbk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:34.581706 2026] [security2:error] [pid 16093:tid 16326] [client 158.173.89.95:25561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bPpuybMv3z_zMVBS9IAAAAfU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:57:34.594273 2026] [security2:error] [pid 15216:tid 15465] [client 77.110.127.138:60266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPttIy0gkFcVddGZ8QAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:34.594382 2026] [security2:error] [pid 15216:tid 15465] [client 77.110.127.138:60266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPttIy0gkFcVddGZ8QAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:34.631920 2026] [security2:error] [pid 15216:tid 15460] [client 194.5.53.241:46953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/images/about.php"] [unique_id "al4bPttIy0gkFcVddGZ8QgAAAXw"]
[Mon Jul 20 06:57:34.821997 2026] [security2:error] [pid 16093:tid 16243] [client 187.16.64.216:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bPpuybMv3z_zMVBS9JwAAAaI"]
[Mon Jul 20 06:57:34.822103 2026] [security2:error] [pid 16093:tid 16243] [client 187.16.64.216:53392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bPpuybMv3z_zMVBS9JwAAAaI"]
[Mon Jul 20 06:57:34.951973 2026] [security2:error] [pid 16093:tid 16110] [remote 47.86.33.52:63178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4bPpuybMv3z_zMVBS9KQACAQ8"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 06:57:34.969587 2026] [security2:error] [pid 15216:tid 15413] [client 77.110.127.138:60269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPttIy0gkFcVddGZ8WwAAAU0"]
[Mon Jul 20 06:57:34.969683 2026] [security2:error] [pid 15216:tid 15413] [client 77.110.127.138:60269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bPttIy0gkFcVddGZ8WwAAAU0"]
[Mon Jul 20 06:57:34.991388 2026] [security2:error] [pid 15216:tid 15386] [client 183.82.98.154:52724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bPttIy0gkFcVddGZ8XQAAATI"]
[Mon Jul 20 06:57:34.991516 2026] [security2:error] [pid 15216:tid 15386] [client 183.82.98.154:52724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bPttIy0gkFcVddGZ8XQAAATI"]
[Mon Jul 20 06:57:35.033927 2026] [security2:error] [pid 15216:tid 15428] [client 174.200.2.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4bPttIy0gkFcVddGZ8VQAAAVw"]
[Mon Jul 20 06:57:35.055050 2026] [security2:error] [pid 16093:tid 16258] [client 74.208.214.194:40200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4bP5uybMv3z_zMVBS9LwAAAbE"]
[Mon Jul 20 06:57:35.263838 2026] [security2:error] [pid 16093:tid 16231] [client 45.3.41.7:13017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bP5uybMv3z_zMVBS9NQAAAZY"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:35.291045 2026] [security2:error] [pid 15216:tid 15444] [client 57.141.18.116:29804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bPdtIy0gkFcVddGZ7_wABbFE"]
[Mon Jul 20 06:57:35.368713 2026] [security2:error] [pid 16093:tid 16269] [client 160.30.136.8:60375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bP5uybMv3z_zMVBS9PAAAAbw"]
[Mon Jul 20 06:57:35.396498 2026] [security2:error] [pid 15216:tid 15388] [client 77.110.127.138:60271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bP9tIy0gkFcVddGZ8bgAAATQ"]
[Mon Jul 20 06:57:35.396583 2026] [security2:error] [pid 15216:tid 15388] [client 77.110.127.138:60271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bP9tIy0gkFcVddGZ8bgAAATQ"]
[Mon Jul 20 06:57:35.470766 2026] [security2:error] [pid 15216:tid 15373] [client 14.225.17.146:55135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4bPdtIy0gkFcVddGZ8EwAAASU"], referer: http://myspineworld.com/2022
[Mon Jul 20 06:57:35.616762 2026] [security2:error] [pid 16093:tid 16329] [client 104.234.53.58:21943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bP5uybMv3z_zMVBS9SgAAAfg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:36.119449 2026] [security2:error] [pid 16093:tid 16242] [client 197.186.66.42:61452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bQJuybMv3z_zMVBS9XQAAAaE"]
[Mon Jul 20 06:57:36.131466 2026] [security2:error] [pid 16093:tid 16242] [client 197.186.66.42:61452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bQJuybMv3z_zMVBS9XQAAAaE"]
[Mon Jul 20 06:57:36.408091 2026] [security2:error] [pid 16093:tid 16230] [client 160.30.136.8:60059] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alexsandbergmusic.com"] [uri "/"] [unique_id "al4bQJuybMv3z_zMVBS9bgAAAZU"]
[Mon Jul 20 06:57:36.622725 2026] [security2:error] [pid 16093:tid 16291] [client 65.111.22.221:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bQJuybMv3z_zMVBS9fQAAAdI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:36.699219 2026] [security2:error] [pid 15216:tid 15356] [client 194.5.53.244:28505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/class.php"] [unique_id "al4bQNtIy0gkFcVddGZ8kwAAARQ"]
[Mon Jul 20 06:57:36.878020 2026] [security2:error] [pid 16093:tid 16263] [client 160.30.136.8:51865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bQJuybMv3z_zMVBS9jgAAAbY"]
[Mon Jul 20 06:57:36.959989 2026] [security2:error] [pid 16093:tid 16299] [client 57.141.18.23:53434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bPpuybMv3z_zMVBS9JQAB2ig"]
[Mon Jul 20 06:57:37.060071 2026] [security2:error] [pid 16093:tid 16246] [client 187.108.85.186:60482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bQZuybMv3z_zMVBS9kgAAAaU"]
[Mon Jul 20 06:57:37.060216 2026] [security2:error] [pid 16093:tid 16246] [client 187.108.85.186:60482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bQZuybMv3z_zMVBS9kgAAAaU"]
[Mon Jul 20 06:57:37.160016 2026] [security2:error] [pid 15216:tid 15447] [client 57.141.18.116:29818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bP9tIy0gkFcVddGZ8XwABbxo"]
[Mon Jul 20 06:57:37.197763 2026] [security2:error] [pid 16093:tid 16240] [client 14.225.17.146:53656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4bP5uybMv3z_zMVBS9VgAAAZ8"], referer: http://wathenbartlett.co.uk/2022
[Mon Jul 20 06:57:37.323384 2026] [security2:error] [pid 15216:tid 15420] [client 14.225.17.146:53544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4bP9tIy0gkFcVddGZ8dQAAAVQ"], referer: http://tacticaltreeoperations.com/2022
[Mon Jul 20 06:57:37.427973 2026] [security2:error] [pid 16093:tid 16314] [client 114.119.141.118:40675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2023/02/Miller-2023-2032House_CommissionCompetitivenessMetric.pdf"] [unique_id "al4bQZuybMv3z_zMVBS9qAAAAek"], referer: https://mtredistricting.gov/document-library/
[Mon Jul 20 06:57:37.516307 2026] [security2:error] [pid 16093:tid 16233] [client 104.234.53.92:65423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bQZuybMv3z_zMVBS9sgAAAZg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:37.839056 2026] [security2:error] [pid 16093:tid 16259] [client 117.222.139.248:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bQZuybMv3z_zMVBS9wQAAAbI"]
[Mon Jul 20 06:57:37.839155 2026] [security2:error] [pid 16093:tid 16259] [client 117.222.139.248:50774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bQZuybMv3z_zMVBS9wQAAAbI"]
[Mon Jul 20 06:57:37.903215 2026] [security2:error] [pid 16093:tid 16350] [client 160.30.136.8:57723] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alexsandbergmusic.com"] [uri "/"] [unique_id "al4bQZuybMv3z_zMVBS9xAAAAg0"]
[Mon Jul 20 06:57:37.904636 2026] [security2:error] [pid 16093:tid 16312] [client 103.144.65.217:64300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bQZuybMv3z_zMVBS9xQAAAec"]
[Mon Jul 20 06:57:37.904736 2026] [security2:error] [pid 16093:tid 16312] [client 103.144.65.217:64300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bQZuybMv3z_zMVBS9xQAAAec"]
[Mon Jul 20 06:57:38.095873 2026] [security2:error] [pid 16093:tid 16229] [client 65.111.25.83:60815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bQpuybMv3z_zMVBS9ygAAAZQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:38.140426 2026] [security2:error] [pid 16093:tid 16193] [remote 154.61.75.100:60140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4bQpuybMv3z_zMVBS9zwABtmI"]
[Mon Jul 20 06:57:38.207595 2026] [security2:error] [pid 16093:tid 16273] [client 57.141.18.121:46218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bQJuybMv3z_zMVBS9ZAABwBA"]
[Mon Jul 20 06:57:38.234763 2026] [security2:error] [pid 15216:tid 15373] [client 14.225.17.146:54294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4bQttIy0gkFcVddGZ8wQAAASU"], referer: https://wathenbartlett.co.uk/2022
[Mon Jul 20 06:57:38.248208 2026] [security2:error] [pid 16093:tid 16317] [client 194.5.53.54:47273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al4bQpuybMv3z_zMVBS92wAAAew"]
[Mon Jul 20 06:57:38.312736 2026] [security2:error] [pid 15216:tid 15385] [client 160.30.136.8:59724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bQttIy0gkFcVddGZ8xwAAATE"]
[Mon Jul 20 06:57:38.618791 2026] [security2:error] [pid 16093:tid 16102] [remote 154.61.75.100:60140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4bQpuybMv3z_zMVBS97gABsgc"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:57:38.657707 2026] [security2:error] [pid 16093:tid 16305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bQpuybMv3z_zMVBS93AAAAeA"], referer: 1'"3000
[Mon Jul 20 06:57:38.709187 2026] [security2:error] [pid 15216:tid 15414] [client 194.5.53.212:26075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/web.php"] [unique_id "al4bQttIy0gkFcVddGZ80AAAAU4"]
[Mon Jul 20 06:57:38.735522 2026] [autoindex:error] [pid 16093:tid 16194] [remote 107.178.218.72:56811] AH01276: Cannot serve directory /home2/cgadunmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://cga.dun.mybluehost.me
[Mon Jul 20 06:57:39.157499 2026] [security2:error] [pid 16093:tid 16308] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bQpuybMv3z_zMVBS-AwAAAeM"], referer: 1'"3000
[Mon Jul 20 06:57:39.173460 2026] [security2:error] [pid 16093:tid 16241] [client 194.5.53.222:53117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/ocean/about.php"] [unique_id "al4bQ5uybMv3z_zMVBS-BwAAAaA"]
[Mon Jul 20 06:57:39.303909 2026] [security2:error] [pid 16093:tid 16338] [client 85.208.98.202:40374] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/robots.txt"] [unique_id "al4bQ5uybMv3z_zMVBS-DAAAAgE"]
[Mon Jul 20 06:57:39.309935 2026] [security2:error] [pid 15216:tid 15346] [client 57.141.18.6:52436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bQdtIy0gkFcVddGZ8qAABCnk"]
[Mon Jul 20 06:57:39.364237 2026] [security2:error] [pid 16093:tid 16291] [client 160.30.136.8:57768] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alexsandbergmusic.com"] [uri "/"] [unique_id "al4bQ5uybMv3z_zMVBS-FgAAAdI"]
[Mon Jul 20 06:57:39.525781 2026] [security2:error] [pid 16093:tid 16295] [client 85.208.98.202:23499] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aosta.nz"] [uri "/robots.txt"] [unique_id "al4bQ5uybMv3z_zMVBS-IQAAAdY"]
[Mon Jul 20 06:57:39.791874 2026] [security2:error] [pid 16093:tid 16332] [client 194.5.53.210:63101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/index.php"] [unique_id "al4bQ5uybMv3z_zMVBS-KwAAAfs"]
[Mon Jul 20 06:57:39.827968 2026] [security2:error] [pid 16093:tid 16344] [client 160.30.136.8:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.136.30.160.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bQ5uybMv3z_zMVBS-LwAAAgc"]
[Mon Jul 20 06:57:40.109685 2026] [security2:error] [pid 16093:tid 16232] [client 158.51.126.91:60052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-MgAAAZc"]
[Mon Jul 20 06:57:40.131575 2026] [security2:error] [pid 16093:tid 16301] [client 57.141.18.26:29408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bQpuybMv3z_zMVBS96gAB3CA"]
[Mon Jul 20 06:57:40.175269 2026] [security2:error] [pid 16093:tid 16318] [client 158.51.126.91:60100] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "whiteoutcb.com"] [uri "/.env"] [unique_id "al4bRJuybMv3z_zMVBS-OQAAAe0"]
[Mon Jul 20 06:57:40.175479 2026] [security2:error] [pid 16093:tid 16288] [client 158.51.126.91:60096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whiteoutcb.com"] [uri "/.env.bak"] [unique_id "al4bRJuybMv3z_zMVBS-PQAAAc8"]
[Mon Jul 20 06:57:40.175588 2026] [security2:error] [pid 16093:tid 16288] [client 158.51.126.91:60096] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "whiteoutcb.com"] [uri "/.env.bak"] [unique_id "al4bRJuybMv3z_zMVBS-PQAAAc8"]
[Mon Jul 20 06:57:40.175865 2026] [security2:error] [pid 16093:tid 16241] [client 158.51.126.91:60112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/appsettings.json"] [unique_id "al4bRJuybMv3z_zMVBS-PwAAAaA"]
[Mon Jul 20 06:57:40.176337 2026] [security2:error] [pid 16093:tid 16251] [client 158.51.126.91:60120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "whiteoutcb.com"] [uri "/.env.backup"] [unique_id "al4bRJuybMv3z_zMVBS-OwAAAao"]
[Mon Jul 20 06:57:40.289200 2026] [security2:error] [pid 15216:tid 15371] [client 158.51.126.91:60136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRNtIy0gkFcVddGZ8-wAAASM"]
[Mon Jul 20 06:57:40.302194 2026] [security2:error] [pid 15216:tid 15388] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRNtIy0gkFcVddGZ8_gAAATQ"]
[Mon Jul 20 06:57:40.306289 2026] [security2:error] [pid 16093:tid 16321] [client 158.51.126.91:60126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-PAAAAfA"]
[Mon Jul 20 06:57:40.331196 2026] [security2:error] [pid 16093:tid 16227] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-RwAAAZI"]
[Mon Jul 20 06:57:40.335437 2026] [security2:error] [pid 15216:tid 15409] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRNtIy0gkFcVddGZ8_wAAAUk"]
[Mon Jul 20 06:57:40.339790 2026] [security2:error] [pid 15216:tid 15468] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRNtIy0gkFcVddGZ9AAAAAYQ"]
[Mon Jul 20 06:57:40.341349 2026] [security2:error] [pid 16093:tid 16257] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-RQAAAbA"]
[Mon Jul 20 06:57:40.343196 2026] [security2:error] [pid 16093:tid 16317] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-RgAAAew"]
[Mon Jul 20 06:57:40.501365 2026] [security2:error] [pid 16093:tid 16266] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-VQAAAbk"]
[Mon Jul 20 06:57:40.570269 2026] [security2:error] [pid 15216:tid 15367] [client 54.244.177.189:51706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bRNtIy0gkFcVddGZ9FwAAAR8"]
[Mon Jul 20 06:57:40.728719 2026] [security2:error] [pid 15216:tid 15355] [client 77.110.127.138:60300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 48 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bRNtIy0gkFcVddGZ9HAAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:40.783517 2026] [security2:error] [pid 16093:tid 16290] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRJuybMv3z_zMVBS-YAAAAdE"]
[Mon Jul 20 06:57:40.839095 2026] [security2:error] [pid 15216:tid 15455] [client 160.30.136.8:56885] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "alexsandbergmusic.com"] [uri "/"] [unique_id "al4bRNtIy0gkFcVddGZ9IwAAAXc"]
[Mon Jul 20 06:57:40.969034 2026] [security2:error] [pid 16093:tid 16341] [client 217.142.18.172:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bRJuybMv3z_zMVBS-cwAAAgQ"]
[Mon Jul 20 06:57:40.973282 2026] [security2:error] [pid 16093:tid 16226] [client 34.221.76.50:50324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bRJuybMv3z_zMVBS-cQAAAZE"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:57:40.978927 2026] [security2:error] [pid 16093:tid 16341] [client 217.142.18.172:54102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bRJuybMv3z_zMVBS-cwAAAgQ"]
[Mon Jul 20 06:57:41.032052 2026] [security2:error] [pid 15216:tid 15383] [client 194.5.53.235:32127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/bypass.php"] [unique_id "al4bRdtIy0gkFcVddGZ9LQAAAS8"]
[Mon Jul 20 06:57:41.039685 2026] [security2:error] [pid 16093:tid 16225] [client 114.119.130.116:20541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jennylouraya.com"] [uri "/clinical-fire-ice-facial-skincare-boutique-north-san-diego"] [unique_id "al4bRZuybMv3z_zMVBS-eAAAAZA"], referer: https://www.jennylouraya.com/author/mrs-sawahm/page/10
[Mon Jul 20 06:57:41.070846 2026] [security2:error] [pid 15216:tid 15378] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRdtIy0gkFcVddGZ9LAAAASo"]
[Mon Jul 20 06:57:41.139368 2026] [security2:error] [pid 16093:tid 16342] [client 158.51.126.91:60120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whiteoutcb.com"] [uri "/src/.git/HEAD"] [unique_id "al4bRZuybMv3z_zMVBS-fgAAAgU"]
[Mon Jul 20 06:57:41.139452 2026] [security2:error] [pid 16093:tid 16342] [client 158.51.126.91:60120] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "whiteoutcb.com"] [uri "/src/.git/HEAD"] [unique_id "al4bRZuybMv3z_zMVBS-fgAAAgU"]
[Mon Jul 20 06:57:41.252270 2026] [security2:error] [pid 16093:tid 16246] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4bRZuybMv3z_zMVBS-hgAAAaU"]
[Mon Jul 20 06:57:41.424401 2026] [security2:error] [pid 16093:tid 16330] [client 103.125.179.95:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bRZuybMv3z_zMVBS-lQAAAfk"]
[Mon Jul 20 06:57:41.424557 2026] [security2:error] [pid 16093:tid 16330] [client 103.125.179.95:56353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bRZuybMv3z_zMVBS-lQAAAfk"]
[Mon Jul 20 06:57:41.610899 2026] [security2:error] [pid 16093:tid 16250] [client 85.208.98.202:40374] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/"] [unique_id "al4bRZuybMv3z_zMVBS-lgAAAak"]
[Mon Jul 20 06:57:41.683647 2026] [security2:error] [pid 16093:tid 16287] [client 14.225.17.146:54919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4bQ5uybMv3z_zMVBS-KAAAAc4"], referer: http://dollpassionista.com/2022
[Mon Jul 20 06:57:41.898247 2026] [security2:error] [pid 15216:tid 15466] [client 14.224.227.113:54822] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bRdtIy0gkFcVddGZ9VwAAAYI"]
[Mon Jul 20 06:57:41.948160 2026] [security2:error] [pid 16093:tid 16282] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bRZuybMv3z_zMVBS-mQAAAck"], referer: 1'"3000
[Mon Jul 20 06:57:42.134609 2026] [security2:error] [pid 15216:tid 15368] [client 122.183.32.225:26282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bRttIy0gkFcVddGZ9YAAAASA"]
[Mon Jul 20 06:57:42.134763 2026] [security2:error] [pid 15216:tid 15368] [client 122.183.32.225:26282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bRttIy0gkFcVddGZ9YAAAASA"]
[Mon Jul 20 06:57:42.252385 2026] [security2:error] [pid 16093:tid 16257] [client 117.247.108.24:64807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bRpuybMv3z_zMVBS-wAAAAbA"]
[Mon Jul 20 06:57:42.252511 2026] [security2:error] [pid 16093:tid 16257] [client 117.247.108.24:64807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bRpuybMv3z_zMVBS-wAAAAbA"]
[Mon Jul 20 06:57:42.288830 2026] [security2:error] [pid 16093:tid 16279] [client 14.225.17.146:56005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4bRpuybMv3z_zMVBS-vwAAAcY"], referer: http://walkingandtalking.net/2022
[Mon Jul 20 06:57:42.610174 2026] [security2:error] [pid 16093:tid 16266] [client 103.238.106.162:60589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bRpuybMv3z_zMVBS-0gAAAbk"]
[Mon Jul 20 06:57:42.610341 2026] [security2:error] [pid 16093:tid 16266] [client 103.238.106.162:60589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bRpuybMv3z_zMVBS-0gAAAbk"]
[Mon Jul 20 06:57:42.655725 2026] [security2:error] [pid 15216:tid 15393] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bRttIy0gkFcVddGZ9YwAAATk"], referer: 1'"3000
[Mon Jul 20 06:57:42.847671 2026] [security2:error] [pid 16093:tid 16236] [client 4.218.23.144:27149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4bRpuybMv3z_zMVBS-3AAAAZs"]
[Mon Jul 20 06:57:42.864034 2026] [security2:error] [pid 15216:tid 15359] [client 14.225.17.146:56178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4bRttIy0gkFcVddGZ9cAAAARc"], referer: https://dollpassionista.com/2022
[Mon Jul 20 06:57:42.881008 2026] [security2:error] [pid 15216:tid 15434] [client 50.116.65.227:29016] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bRttIy0gkFcVddGZ9dQAAAWI"]
[Mon Jul 20 06:57:42.889843 2026] [security2:error] [pid 16093:tid 16344] [client 50.116.65.227:29030] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bRpuybMv3z_zMVBS-4QAAAgc"]
[Mon Jul 20 06:57:42.907171 2026] [security2:error] [pid 15216:tid 15396] [client 152.58.191.29:58011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bRttIy0gkFcVddGZ9dgAAATw"]
[Mon Jul 20 06:57:42.920886 2026] [security2:error] [pid 15216:tid 15396] [client 152.58.191.29:58011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bRttIy0gkFcVddGZ9dgAAATw"]
[Mon Jul 20 06:57:42.977295 2026] [security2:error] [pid 16093:tid 16326] [client 4.218.23.144:27149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4bRpuybMv3z_zMVBS-5gAAAfU"]
[Mon Jul 20 06:57:43.156435 2026] [security2:error] [pid 16093:tid 16162] [remote 188.166.241.141:55630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4bR5uybMv3z_zMVBS-8AABtEM"]
[Mon Jul 20 06:57:43.156579 2026] [security2:error] [pid 16093:tid 16261] [client 188.166.241.141:55630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-5ab144f7.uritems.net"] [uri "/xmlrpc.php"] [unique_id "al4bR5uybMv3z_zMVBS-8AABtEM"]
[Mon Jul 20 06:57:43.162114 2026] [security2:error] [pid 16093:tid 16245] [client 14.225.17.146:55911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4bRZuybMv3z_zMVBS-tAAAAaQ"], referer: http://collectingrealestate.com/2022
[Mon Jul 20 06:57:43.164223 2026] [security2:error] [pid 16093:tid 16145] [remote 152.228.213.32:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bR5uybMv3z_zMVBS-7gAB-zI"]
[Mon Jul 20 06:57:43.170386 2026] [security2:error] [pid 16093:tid 16257] [client 194.5.53.241:47761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al4bR5uybMv3z_zMVBS-8wAAAbA"]
[Mon Jul 20 06:57:43.211117 2026] [security2:error] [pid 16093:tid 16329] [client 14.225.17.146:54253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4bR5uybMv3z_zMVBS-8gAAAfg"], referer: https://walkingandtalking.net/2022
[Mon Jul 20 06:57:43.353483 2026] [security2:error] [pid 16093:tid 16175] [remote 152.228.213.32:40242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bR5uybMv3z_zMVBS-_gABklA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:57:43.385630 2026] [security2:error] [pid 15216:tid 15465] [client 57.141.18.17:35824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bRdtIy0gkFcVddGZ9SgABgXQ"]
[Mon Jul 20 06:57:43.562803 2026] [security2:error] [pid 16093:tid 16311] [client 194.5.53.41:46455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/midnight/install.php"] [unique_id "al4bR5uybMv3z_zMVBS_DwAAAeY"]
[Mon Jul 20 06:57:43.948366 2026] [security2:error] [pid 15216:tid 15405] [client 194.5.53.195:38613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-trackback.php"] [unique_id "al4bR9tIy0gkFcVddGZ9lQAAAUU"]
[Mon Jul 20 06:57:43.968792 2026] [security2:error] [pid 15216:tid 15365] [client 57.141.18.34:23748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bRttIy0gkFcVddGZ9XwABHS8"]
[Mon Jul 20 06:57:44.301350 2026] [security2:error] [pid 15216:tid 15466] [client 14.225.17.146:63263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4bSNtIy0gkFcVddGZ9ogAAAYI"]
[Mon Jul 20 06:57:44.347459 2026] [security2:error] [pid 15216:tid 15431] [client 146.103.115.115:58410] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.115.115" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4bSNtIy0gkFcVddGZ9pAAAAV8"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:57:44.347547 2026] [security2:error] [pid 15216:tid 15431] [client 146.103.115.115:58410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4bSNtIy0gkFcVddGZ9pAAAAV8"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:57:44.439554 2026] [security2:error] [pid 16093:tid 16336] [client 104.234.53.53:44893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bSJuybMv3z_zMVBS_KAAAAf8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:44.618033 2026] [security2:error] [pid 16093:tid 16230] [client 57.141.18.111:30004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bRpuybMv3z_zMVBS-1wABlQI"]
[Mon Jul 20 06:57:44.715355 2026] [security2:error] [pid 16093:tid 16305] [client 216.24.212.38:34051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4bSJuybMv3z_zMVBS_MQAAAeA"]
[Mon Jul 20 06:57:44.723043 2026] [security2:error] [pid 15216:tid 15414] [client 216.24.212.41:48021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4bSNtIy0gkFcVddGZ9uQAAAU4"]
[Mon Jul 20 06:57:45.336235 2026] [security2:error] [pid 16093:tid 16261] [client 104.234.53.86:43841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bSZuybMv3z_zMVBS_TAAAAbQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:45.621886 2026] [security2:error] [pid 16093:tid 16349] [client 187.16.64.216:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bSZuybMv3z_zMVBS_XAAAAgw"]
[Mon Jul 20 06:57:45.621983 2026] [security2:error] [pid 16093:tid 16349] [client 187.16.64.216:53896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bSZuybMv3z_zMVBS_XAAAAgw"]
[Mon Jul 20 06:57:45.733858 2026] [security2:error] [pid 16093:tid 16332] [client 183.82.98.154:53318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bSZuybMv3z_zMVBS_YwAAAfs"]
[Mon Jul 20 06:57:45.733969 2026] [security2:error] [pid 16093:tid 16332] [client 183.82.98.154:53318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bSZuybMv3z_zMVBS_YwAAAfs"]
[Mon Jul 20 06:57:45.743293 2026] [security2:error] [pid 15216:tid 15453] [client 13.233.207.33:21670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bSdtIy0gkFcVddGZ95AAAAXU"]
[Mon Jul 20 06:57:45.743364 2026] [security2:error] [pid 15216:tid 15453] [client 13.233.207.33:21670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bSdtIy0gkFcVddGZ95AAAAXU"]
[Mon Jul 20 06:57:45.874878 2026] [security2:error] [pid 16093:tid 16140] [remote 47.86.33.52:10158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bSZuybMv3z_zMVBS_aQAB0y0"]
[Mon Jul 20 06:57:46.365318 2026] [security2:error] [pid 16093:tid 16269] [client 14.225.17.146:53145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4bSpuybMv3z_zMVBS_eAAAAbw"], referer: http://guidehunting.com/2022
[Mon Jul 20 06:57:46.422045 2026] [security2:error] [pid 16093:tid 16199] [remote 47.86.33.52:10158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bSpuybMv3z_zMVBS_hQAB5Wg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:57:46.569450 2026] [security2:error] [pid 16093:tid 16342] [client 194.5.53.210:22911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/style-engine/bypass.php"] [unique_id "al4bSpuybMv3z_zMVBS_jQAAAgU"]
[Mon Jul 20 06:57:46.809829 2026] [security2:error] [pid 16093:tid 16240] [client 57.141.18.21:62806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bSJuybMv3z_zMVBS_NgABny4"]
[Mon Jul 20 06:57:46.831530 2026] [security2:error] [pid 15216:tid 15241] [remote 8.217.108.67:37356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4bSttIy0gkFcVddGZ-AQABUhg"]
[Mon Jul 20 06:57:46.897775 2026] [security2:error] [pid 16093:tid 16230] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bSpuybMv3z_zMVBS_lQAAAZU"], referer: 1'"3000
[Mon Jul 20 06:57:46.935976 2026] [security2:error] [pid 16093:tid 16326] [client 113.160.132.26:6375] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 26.132.160.113.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4bSpuybMv3z_zMVBS_ngAAAfU"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:57:46.936080 2026] [security2:error] [pid 16093:tid 16326] [client 113.160.132.26:6375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4bSpuybMv3z_zMVBS_ngAAAfU"], referer: http://blog.danwolfe.us/resist/
[Mon Jul 20 06:57:46.940726 2026] [security2:error] [pid 16093:tid 16315] [client 77.110.127.138:60335] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 429 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bSpuybMv3z_zMVBS_nwAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:47.396105 2026] [security2:error] [pid 16093:tid 16231] [client 14.225.17.146:53083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4bSZuybMv3z_zMVBS_bAAAAZY"], referer: http://olearyplumbingllc.com/2022
[Mon Jul 20 06:57:47.447478 2026] [security2:error] [pid 15216:tid 15457] [client 35.180.166.19:19990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bS9tIy0gkFcVddGZ-GQAAAXk"]
[Mon Jul 20 06:57:47.530467 2026] [security2:error] [pid 15216:tid 15434] [client 14.225.17.146:62653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4bS9tIy0gkFcVddGZ-FAAAAWI"], referer: https://guidehunting.com/2022
[Mon Jul 20 06:57:47.542443 2026] [security2:error] [pid 16093:tid 16291] [client 57.141.18.19:53368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bSZuybMv3z_zMVBS_VAAB0is"]
[Mon Jul 20 06:57:47.645524 2026] [security2:error] [pid 15216:tid 15469] [client 187.108.85.186:61024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bS9tIy0gkFcVddGZ-IgAAAYU"]
[Mon Jul 20 06:57:47.645630 2026] [security2:error] [pid 15216:tid 15469] [client 187.108.85.186:61024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bS9tIy0gkFcVddGZ-IgAAAYU"]
[Mon Jul 20 06:57:47.744603 2026] [security2:error] [pid 16093:tid 16260] [client 194.5.53.194:46151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/radio.php"] [unique_id "al4bS5uybMv3z_zMVBS_vAAAAbM"]
[Mon Jul 20 06:57:47.766902 2026] [security2:error] [pid 16093:tid 16155] [remote 188.40.28.4:35874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4bS5uybMv3z_zMVBS_vQAB5Tw"]
[Mon Jul 20 06:57:47.873400 2026] [security2:error] [pid 15216:tid 15348] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bS9tIy0gkFcVddGZ-FwAAAQw"], referer: 1'"3000
[Mon Jul 20 06:57:47.970651 2026] [security2:error] [pid 16093:tid 16148] [remote 188.40.28.4:35874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4bS5uybMv3z_zMVBS_wwAByTU"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 06:57:48.213946 2026] [security2:error] [pid 15216:tid 15253] [remote 8.217.108.67:37356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4bTNtIy0gkFcVddGZ-QAABaCQ"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:57:48.311724 2026] [security2:error] [pid 16093:tid 16239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bTJuybMv3z_zMVBS_xgAAAZ4"], referer: 1'"3000
[Mon Jul 20 06:57:48.320334 2026] [security2:error] [pid 16093:tid 16299] [client 117.222.139.248:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bTJuybMv3z_zMVBS_1gAAAdo"]
[Mon Jul 20 06:57:48.320513 2026] [security2:error] [pid 16093:tid 16299] [client 117.222.139.248:51290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bTJuybMv3z_zMVBS_1gAAAdo"]
[Mon Jul 20 06:57:48.407616 2026] [security2:error] [pid 16093:tid 16256] [client 197.186.66.42:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bTJuybMv3z_zMVBS_3wAAAa8"]
[Mon Jul 20 06:57:48.407721 2026] [security2:error] [pid 16093:tid 16256] [client 197.186.66.42:61975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bTJuybMv3z_zMVBS_3wAAAa8"]
[Mon Jul 20 06:57:48.409531 2026] [security2:error] [pid 15216:tid 15274] [remote 8.217.108.67:62966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4bTNtIy0gkFcVddGZ-SgABXTk"]
[Mon Jul 20 06:57:48.433247 2026] [security2:error] [pid 16093:tid 16281] [client 103.144.65.217:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bTJuybMv3z_zMVBS_4AAAAcg"]
[Mon Jul 20 06:57:48.433425 2026] [security2:error] [pid 16093:tid 16281] [client 103.144.65.217:64718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bTJuybMv3z_zMVBS_4AAAAcg"]
[Mon Jul 20 06:57:48.640957 2026] [security2:error] [pid 16093:tid 16266] [client 13.233.207.33:21674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bTJuybMv3z_zMVBS_5gAAAbk"]
[Mon Jul 20 06:57:48.768919 2026] [security2:error] [pid 16093:tid 16312] [client 15.237.209.113:22172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bS5uybMv3z_zMVBS_wgAAAec"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:57:48.823766 2026] [security2:error] [pid 15216:tid 15410] [client 194.5.53.225:65097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/mah.php"] [unique_id "al4bTNtIy0gkFcVddGZ-WQAAAUo"]
[Mon Jul 20 06:57:48.997624 2026] [security2:error] [pid 15216:tid 15383] [client 151.123.178.18:34897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bTNtIy0gkFcVddGZ-YAAAAS8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:49.218922 2026] [security2:error] [pid 15216:tid 15467] [client 77.110.127.138:60316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bTdtIy0gkFcVddGZ-ZQAAAYM"], referer: https://mezzacraft.com/baby-suri-tips-for-crochet/
[Mon Jul 20 06:57:49.219048 2026] [security2:error] [pid 15216:tid 15467] [client 77.110.127.138:60316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bTdtIy0gkFcVddGZ-ZQAAAYM"], referer: https://mezzacraft.com/baby-suri-tips-for-crochet/
[Mon Jul 20 06:57:49.247635 2026] [security2:error] [pid 15216:tid 15389] [client 57.141.18.125:48090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bS9tIy0gkFcVddGZ-DgABNR0"]
[Mon Jul 20 06:57:49.313210 2026] [security2:error] [pid 16093:tid 16202] [remote 162.19.86.63:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bTZuybMv3z_zMVBTAAQACC2s"]
[Mon Jul 20 06:57:49.370299 2026] [autoindex:error] [pid 15216:tid 15398] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/genesis/lib/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/themes/genesis/lib/js/
[Mon Jul 20 06:57:49.406920 2026] [security2:error] [pid 16093:tid 16257] [client 77.110.127.138:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/free-form/0um3ypi9ou6y.php"] [unique_id "al4bTZuybMv3z_zMVBTAEwAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:49.501835 2026] [security2:error] [pid 16093:tid 16196] [remote 162.19.86.63:51397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bTZuybMv3z_zMVBTAHQAB9mU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:57:49.618114 2026] [security2:error] [pid 15216:tid 15258] [remote 8.217.108.67:62966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4bTdtIy0gkFcVddGZ-gAABOyk"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 06:57:49.668538 2026] [security2:error] [pid 16093:tid 16226] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bTZuybMv3z_zMVBTAAAAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:49.709554 2026] [security2:error] [pid 16093:tid 16258] [client 194.5.53.230:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "al4bTZuybMv3z_zMVBTAKwAAAbE"]
[Mon Jul 20 06:57:49.748683 2026] [security2:error] [pid 16093:tid 16266] [client 77.110.127.138:60328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bTZuybMv3z_zMVBTAFwAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:49.843811 2026] [security2:error] [pid 16093:tid 16268] [client 43.205.139.3:63998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bTZuybMv3z_zMVBTANAAAAbs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:57:49.882524 2026] [security2:error] [pid 15216:tid 15411] [client 104.207.38.202:18063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bTdtIy0gkFcVddGZ-iQAAAUs"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:50.220145 2026] [security2:error] [pid 16093:tid 16257] [client 66.249.73.64:62435] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.midnightcarabao.studio"] [uri "/robots.txt"] [unique_id "al4bTpuybMv3z_zMVBTAPwAAAbA"]
[Mon Jul 20 06:57:50.500844 2026] [security2:error] [pid 15216:tid 15304] [remote 124.55.178.99:40620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bTttIy0gkFcVddGZ-nAABgFc"]
[Mon Jul 20 06:57:50.500952 2026] [security2:error] [pid 15216:tid 15464] [client 124.55.178.99:40620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bTttIy0gkFcVddGZ-nAABgFc"]
[Mon Jul 20 06:57:50.647912 2026] [security2:error] [pid 15216:tid 15391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bTdtIy0gkFcVddGZ-gQAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:50.687282 2026] [security2:error] [pid 16093:tid 16351] [client 65.111.10.55:13151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bTpuybMv3z_zMVBTAVAAAAg4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:50.703660 2026] [autoindex:error] [pid 16093:tid 16112] [remote 8.234.213.150:58509] AH01276: Cannot serve directory /home2/zajlqimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.zaj.lqi.mybluehost.me
[Mon Jul 20 06:57:51.056664 2026] [security2:error] [pid 16093:tid 16260] [client 57.141.18.22:37686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bTJuybMv3z_zMVBS_6wABs0Q"]
[Mon Jul 20 06:57:51.089675 2026] [security2:error] [pid 16093:tid 16331] [client 158.173.166.181:37275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bT5uybMv3z_zMVBTAcwAAAfo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:57:51.423153 2026] [security2:error] [pid 16093:tid 16272] [client 104.234.53.89:43759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bT5uybMv3z_zMVBTAgAAAAb8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:51.483935 2026] [security2:error] [pid 15216:tid 15437] [client 104.207.38.204:62803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.38.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bT9tIy0gkFcVddGZ-vQAAAWU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:51.505683 2026] [security2:error] [pid 16093:tid 16349] [client 217.142.18.172:42017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bT5uybMv3z_zMVBTAggAAAgw"]
[Mon Jul 20 06:57:51.505798 2026] [security2:error] [pid 16093:tid 16349] [client 217.142.18.172:42017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bT5uybMv3z_zMVBTAggAAAgw"]
[Mon Jul 20 06:57:51.543969 2026] [security2:error] [pid 15216:tid 15451] [client 43.172.196.198:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4bTttIy0gkFcVddGZ-rAAAAXM"]
[Mon Jul 20 06:57:51.658332 2026] [security2:error] [pid 15216:tid 15349] [client 194.5.53.242:43815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "al4bT9tIy0gkFcVddGZ-vwAAAQ0"]
[Mon Jul 20 06:57:51.690696 2026] [security2:error] [pid 16093:tid 16244] [client 74.7.227.179:51144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4bT5uybMv3z_zMVBTAhAABo20"], referer: https://tejasenvironmental.com/p=184759
[Mon Jul 20 06:57:51.900000 2026] [security2:error] [pid 15216:tid 15470] [client 14.225.17.146:51241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4bT9tIy0gkFcVddGZ-wgAAAYY"]
[Mon Jul 20 06:57:52.201074 2026] [security2:error] [pid 15216:tid 15357] [client 103.125.179.95:56857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bUNtIy0gkFcVddGZ-4AAAARU"]
[Mon Jul 20 06:57:52.201887 2026] [security2:error] [pid 15216:tid 15357] [client 103.125.179.95:56857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bUNtIy0gkFcVddGZ-4AAAARU"]
[Mon Jul 20 06:57:52.282588 2026] [security2:error] [pid 15216:tid 15452] [client 65.111.6.254:58173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bUNtIy0gkFcVddGZ-4gAAAXQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:52.424758 2026] [security2:error] [pid 16093:tid 16342] [client 34.67.218.220:45416] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "darkknightsolutions.com"] [uri "/wp-json/batch/v1"] [unique_id "al4bUJuybMv3z_zMVBTAogAAAgU"]
[Mon Jul 20 06:57:52.472198 2026] [security2:error] [pid 16093:tid 16330] [client 194.5.53.245:43693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-conflg.php"] [unique_id "al4bUJuybMv3z_zMVBTAqAAAAfk"]
[Mon Jul 20 06:57:52.686880 2026] [security2:error] [pid 16093:tid 16312] [client 77.110.127.138:60340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 211 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bUJuybMv3z_zMVBTArwAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:52.715936 2026] [security2:error] [pid 16093:tid 16284] [client 45.3.54.237:45985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bUJuybMv3z_zMVBTAsAAAAcs"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:57:52.909059 2026] [security2:error] [pid 16093:tid 16333] [client 194.5.53.230:25519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-setup.php"] [unique_id "al4bUJuybMv3z_zMVBTAuQAAAfw"]
[Mon Jul 20 06:57:52.920323 2026] [security2:error] [pid 15216:tid 15451] [client 135.148.32.173:51258] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "codykkline.com"] [uri "/"] [unique_id "al4bUNtIy0gkFcVddGZ_BQAAAXM"]
[Mon Jul 20 06:57:52.997453 2026] [security2:error] [pid 16093:tid 16287] [client 77.110.127.138:60361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-stitch/zlgvge5ewe7d.php"] [unique_id "al4bUJuybMv3z_zMVBTAwwAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:53.005864 2026] [security2:error] [pid 16093:tid 16323] [client 117.247.108.24:31044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bUZuybMv3z_zMVBTAxwAAAfI"]
[Mon Jul 20 06:57:53.005949 2026] [security2:error] [pid 16093:tid 16323] [client 117.247.108.24:31044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bUZuybMv3z_zMVBTAxwAAAfI"]
[Mon Jul 20 06:57:53.054672 2026] [security2:error] [pid 16093:tid 16308] [client 45.3.41.19:35653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bUZuybMv3z_zMVBTAyQAAAeM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:57:53.071338 2026] [security2:error] [pid 15216:tid 15350] [client 122.183.32.225:18086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bUdtIy0gkFcVddGZ_EwAAAQ4"]
[Mon Jul 20 06:57:53.071452 2026] [security2:error] [pid 15216:tid 15350] [client 122.183.32.225:18086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bUdtIy0gkFcVddGZ_EwAAAQ4"]
[Mon Jul 20 06:57:53.142905 2026] [security2:error] [pid 15216:tid 15408] [client 103.238.106.162:60799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bUdtIy0gkFcVddGZ_FQAAAUg"]
[Mon Jul 20 06:57:53.143036 2026] [security2:error] [pid 15216:tid 15408] [client 103.238.106.162:60799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bUdtIy0gkFcVddGZ_FQAAAUg"]
[Mon Jul 20 06:57:53.268029 2026] [security2:error] [pid 16093:tid 16316] [client 194.5.53.224:41989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/ms-themes.php"] [unique_id "al4bUZuybMv3z_zMVBTAzwAAAes"]
[Mon Jul 20 06:57:53.370459 2026] [security2:error] [pid 16093:tid 16299] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nicherealestate.co"] [uri "/wp-admin/install.php"] [unique_id "al4bUZuybMv3z_zMVBTA1AAAAdo"]
[Mon Jul 20 06:57:53.462517 2026] [security2:error] [pid 16093:tid 16264] [client 57.141.18.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bUZuybMv3z_zMVBTA0gAAAbc"]
[Mon Jul 20 06:57:53.470537 2026] [security2:error] [pid 16093:tid 16337] [client 14.225.17.146:62829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4bUZuybMv3z_zMVBTAzgAAAgA"], referer: http://soloceos.com/2022
[Mon Jul 20 06:57:53.483074 2026] [security2:error] [pid 16093:tid 16341] [client 14.225.17.146:52817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4bUZuybMv3z_zMVBTAygAAAgQ"], referer: http://nextlevelpressurewashing.com/2022
[Mon Jul 20 06:57:53.581611 2026] [security2:error] [pid 16093:tid 16297] [client 77.110.127.138:60363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bUJuybMv3z_zMVBTAwgAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:53.601978 2026] [security2:error] [pid 15216:tid 15383] [client 152.58.191.29:58459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bUdtIy0gkFcVddGZ_LQAAAS8"]
[Mon Jul 20 06:57:53.607729 2026] [security2:error] [pid 15216:tid 15383] [client 152.58.191.29:58459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bUdtIy0gkFcVddGZ_LQAAAS8"]
[Mon Jul 20 06:57:53.623073 2026] [security2:error] [pid 15216:tid 15379] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bUdtIy0gkFcVddGZ_EAAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:53.647071 2026] [security2:error] [pid 16093:tid 16328] [client 34.67.218.220:45416] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "darkknightsolutions.com"] [uri "/"] [unique_id "al4bUZuybMv3z_zMVBTA4AAAAfc"]
[Mon Jul 20 06:57:53.679181 2026] [security2:error] [pid 15216:tid 15425] [client 194.5.53.227:60915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/assets/about.php"] [unique_id "al4bUdtIy0gkFcVddGZ_MAAAAVk"]
[Mon Jul 20 06:57:53.696533 2026] [security2:error] [pid 15216:tid 15371] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bUdtIy0gkFcVddGZ_EgAAASM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:53.746189 2026] [security2:error] [pid 15216:tid 15412] [client 50.116.65.227:49884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4bUdtIy0gkFcVddGZ_NAAAAUw"]
[Mon Jul 20 06:57:53.749671 2026] [security2:error] [pid 16093:tid 16288] [client 14.225.17.146:62743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4bUZuybMv3z_zMVBTA3wAAAc8"]
[Mon Jul 20 06:57:54.123098 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.237:35541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/style.php"] [unique_id "al4bUpuybMv3z_zMVBTA-AAAAZY"]
[Mon Jul 20 06:57:54.906306 2026] [security2:error] [pid 15216:tid 15383] [client 77.110.127.138:60374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/free/pskyo4aq65xo.php"] [unique_id "al4bUttIy0gkFcVddGZ_eAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:54.950847 2026] [security2:error] [pid 15216:tid 15416] [client 194.5.53.195:49327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/infi.php"] [unique_id "al4bUttIy0gkFcVddGZ_fgAAAVA"]
[Mon Jul 20 06:57:55.004563 2026] [security2:error] [pid 16093:tid 16339] [client 77.110.127.138:60335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bUpuybMv3z_zMVBTBBwAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:55.009770 2026] [security2:error] [pid 16093:tid 16351] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bUpuybMv3z_zMVBTBCAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:55.372260 2026] [security2:error] [pid 15216:tid 15439] [client 104.234.53.62:25515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bU9tIy0gkFcVddGZ_jwAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:55.375780 2026] [security2:error] [pid 15216:tid 15316] [remote 117.0.21.154:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4bU9tIy0gkFcVddGZ_kAABf2M"]
[Mon Jul 20 06:57:55.389624 2026] [security2:error] [pid 15216:tid 15432] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bUttIy0gkFcVddGZ_fQAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:55.644496 2026] [core:error] [pid 15216:tid 15427] [client 14.225.17.146:57294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2022
[Mon Jul 20 06:57:55.644518 2026] [core:error] [pid 15216:tid 15427] [client 14.225.17.146:57294] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2022
[Mon Jul 20 06:57:55.748864 2026] [security2:error] [pid 16093:tid 16283] [client 194.5.53.206:61377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/maint/index.php"] [unique_id "al4bU5uybMv3z_zMVBTBMgAAAco"]
[Mon Jul 20 06:57:55.849008 2026] [security2:error] [pid 15216:tid 15290] [remote 117.0.21.154:55592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4bU9tIy0gkFcVddGZ_rQABR0k"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 06:57:55.859139 2026] [security2:error] [pid 15216:tid 15362] [client 192.140.149.97:44635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bU9tIy0gkFcVddGZ_sAAAARo"]
[Mon Jul 20 06:57:55.859221 2026] [security2:error] [pid 15216:tid 15362] [client 192.140.149.97:44635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bU9tIy0gkFcVddGZ_sAAAARo"]
[Mon Jul 20 06:57:56.126210 2026] [security2:error] [pid 15216:tid 15430] [client 57.141.18.69:38478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bUttIy0gkFcVddGZ_SAABXjk"]
[Mon Jul 20 06:57:56.147731 2026] [security2:error] [pid 16093:tid 16240] [client 194.5.53.220:44871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/x.php"] [unique_id "al4bVJuybMv3z_zMVBTBQgAAAZ8"]
[Mon Jul 20 06:57:56.340928 2026] [security2:error] [pid 16093:tid 16294] [client 187.16.64.216:54406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bVJuybMv3z_zMVBTBTwAAAdU"]
[Mon Jul 20 06:57:56.341034 2026] [security2:error] [pid 16093:tid 16294] [client 187.16.64.216:54406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bVJuybMv3z_zMVBTBTwAAAdU"]
[Mon Jul 20 06:57:56.479090 2026] [security2:error] [pid 16093:tid 16287] [client 50.116.65.227:24576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bVJuybMv3z_zMVBTBVQAAAc4"]
[Mon Jul 20 06:57:56.488101 2026] [security2:error] [pid 15216:tid 15419] [client 50.116.65.227:24578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bVNtIy0gkFcVddGZ_ygAAAVM"]
[Mon Jul 20 06:57:56.638084 2026] [security2:error] [pid 16093:tid 16230] [client 183.82.98.154:53923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bVJuybMv3z_zMVBTBWAAAAZU"]
[Mon Jul 20 06:57:56.638201 2026] [security2:error] [pid 16093:tid 16230] [client 183.82.98.154:53923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bVJuybMv3z_zMVBTBWAAAAZU"]
[Mon Jul 20 06:57:56.759922 2026] [security2:error] [pid 15216:tid 15446] [client 57.141.18.109:62870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bUttIy0gkFcVddGZ_WQABbj8"]
[Mon Jul 20 06:57:57.026919 2026] [security2:error] [pid 16093:tid 16264] [client 14.225.17.146:57766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4bU5uybMv3z_zMVBTBJAAAAbc"], referer: http://adirondackengineering.com/2022
[Mon Jul 20 06:57:57.173086 2026] [security2:error] [pid 15216:tid 15358] [client 14.225.17.146:57965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4bU9tIy0gkFcVddGZ_rAAAARY"], referer: http://dnsplumbing.com/2022
[Mon Jul 20 06:57:57.265444 2026] [security2:error] [pid 15216:tid 15445] [client 194.5.53.207:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/IXR/index.php"] [unique_id "al4bVdtIy0gkFcVddGZ_4QAAAW0"]
[Mon Jul 20 06:57:57.372937 2026] [security2:error] [pid 16093:tid 16224] [client 14.251.3.155:54827] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bVZuybMv3z_zMVBTBbgAAAY8"]
[Mon Jul 20 06:57:58.174114 2026] [security2:error] [pid 16093:tid 16286] [client 14.225.17.146:57975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4bVJuybMv3z_zMVBTBWgAAAc0"], referer: http://vinovinhowine.com/2022
[Mon Jul 20 06:57:58.258255 2026] [security2:error] [pid 16093:tid 16336] [client 194.5.53.243:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/css/index.php"] [unique_id "al4bVpuybMv3z_zMVBTBeAAAAf8"]
[Mon Jul 20 06:57:58.293001 2026] [security2:error] [pid 15216:tid 15368] [client 187.108.85.186:61576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bVttIy0gkFcVddGaAKAAAASA"]
[Mon Jul 20 06:57:58.293100 2026] [security2:error] [pid 15216:tid 15368] [client 187.108.85.186:61576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bVttIy0gkFcVddGaAKAAAASA"]
[Mon Jul 20 06:57:58.961035 2026] [security2:error] [pid 16093:tid 16230] [client 117.222.139.248:52091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bVpuybMv3z_zMVBTBoQAAAZU"]
[Mon Jul 20 06:57:58.961153 2026] [security2:error] [pid 16093:tid 16230] [client 117.222.139.248:52091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bVpuybMv3z_zMVBTBoQAAAZU"]
[Mon Jul 20 06:57:59.003306 2026] [security2:error] [pid 16093:tid 16282] [client 103.144.65.217:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bV5uybMv3z_zMVBTBogAAAck"]
[Mon Jul 20 06:57:59.003435 2026] [security2:error] [pid 16093:tid 16282] [client 103.144.65.217:65129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bV5uybMv3z_zMVBTBogAAAck"]
[Mon Jul 20 06:57:59.083114 2026] [security2:error] [pid 16093:tid 16285] [client 57.141.18.0:29686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bVJuybMv3z_zMVBTBVgABzAE"]
[Mon Jul 20 06:57:59.146064 2026] [security2:error] [pid 16093:tid 16243] [client 14.225.17.146:58025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTBpQAAAaI"], referer: http://thefriendlyspreadsheet.com/2022
[Mon Jul 20 06:57:59.251952 2026] [security2:error] [pid 16093:tid 16235] [client 14.225.17.146:58008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTBpAAAAZo"], referer: http://secretkeynumerology.com/2022
[Mon Jul 20 06:57:59.567170 2026] [security2:error] [pid 16093:tid 16248] [client 104.234.53.54:26065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bV5uybMv3z_zMVBTBugAAAac"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:57:59.691373 2026] [security2:error] [pid 16093:tid 16259] [client 77.110.127.138:60392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-surrey/69yrvhpcgazz.php"] [unique_id "al4bV5uybMv3z_zMVBTBxAAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:57:59.694973 2026] [security2:error] [pid 16093:tid 16281] [client 194.5.53.55:21559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/images/index22.php"] [unique_id "al4bV5uybMv3z_zMVBTByQAAAcg"]
[Mon Jul 20 06:58:00.009723 2026] [security2:error] [pid 16093:tid 16319] [client 45.3.54.159:10035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/xmlrpc.php"] [unique_id "al4bV5uybMv3z_zMVBTB5gAAAe4"], referer: https://www.bing.com/
[Mon Jul 20 06:58:00.051450 2026] [security2:error] [pid 16093:tid 16297] [client 77.110.127.138:60394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTBxwAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:00.098850 2026] [security2:error] [pid 16093:tid 16306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTBzwAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:00.192207 2026] [security2:error] [pid 16093:tid 16347] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTB0gAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:00.320881 2026] [security2:error] [pid 16093:tid 16230] [client 197.186.66.42:62522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bWJuybMv3z_zMVBTB-AAAAZU"]
[Mon Jul 20 06:58:00.335887 2026] [security2:error] [pid 16093:tid 16230] [client 197.186.66.42:62522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bWJuybMv3z_zMVBTB-AAAAZU"]
[Mon Jul 20 06:58:00.435099 2026] [security2:error] [pid 16093:tid 16143] [remote 124.55.178.99:35118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bWJuybMv3z_zMVBTCAgAB-jA"]
[Mon Jul 20 06:58:00.628265 2026] [security2:error] [pid 16093:tid 16316] [client 194.5.53.220:64195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-user.php"] [unique_id "al4bWJuybMv3z_zMVBTCDwAAAes"]
[Mon Jul 20 06:58:00.680056 2026] [security2:error] [pid 16093:tid 16323] [client 14.225.17.146:59319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4bWJuybMv3z_zMVBTCBgAAAfI"], referer: http://adastra.love/2022
[Mon Jul 20 06:58:00.862640 2026] [security2:error] [pid 16093:tid 16149] [remote 124.55.178.99:35118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bWJuybMv3z_zMVBTCIAABtzY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:58:00.925427 2026] [security2:error] [pid 16093:tid 16250] [client 57.141.18.97:31616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bVpuybMv3z_zMVBTBfwABqV4"]
[Mon Jul 20 06:58:01.020280 2026] [security2:error] [pid 16093:tid 16301] [client 14.225.17.146:57861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTB1gAAAdw"], referer: http://39ishlife.com/2022
[Mon Jul 20 06:58:01.143506 2026] [security2:error] [pid 16093:tid 16277] [client 65.1.132.125:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.132.1.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bWZuybMv3z_zMVBTCMAAAAcQ"]
[Mon Jul 20 06:58:01.143589 2026] [security2:error] [pid 16093:tid 16277] [client 65.1.132.125:52062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bWZuybMv3z_zMVBTCMAAAAcQ"]
[Mon Jul 20 06:58:01.481629 2026] [security2:error] [pid 16093:tid 16247] [client 18.211.148.239:62088] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/our-story/"] [unique_id "al4bWZuybMv3z_zMVBTCPQAAAaY"]
[Mon Jul 20 06:58:01.949919 2026] [security2:error] [pid 16093:tid 16302] [client 194.5.53.218:54579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/pomo/about.php"] [unique_id "al4bWZuybMv3z_zMVBTCVgAAAd0"]
[Mon Jul 20 06:58:01.999684 2026] [security2:error] [pid 16093:tid 16279] [client 57.141.18.90:47226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bV5uybMv3z_zMVBTBuwABxiA"]
[Mon Jul 20 06:58:02.059129 2026] [security2:error] [pid 15216:tid 15462] [client 217.142.18.172:31740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bWttIy0gkFcVddGaAqQAAAX4"]
[Mon Jul 20 06:58:02.063084 2026] [security2:error] [pid 15216:tid 15462] [client 217.142.18.172:31740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bWttIy0gkFcVddGaAqQAAAX4"]
[Mon Jul 20 06:58:02.131357 2026] [security2:error] [pid 16093:tid 16304] [client 14.225.17.146:62431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4bWpuybMv3z_zMVBTCWwAAAd8"], referer: https://39ishlife.com/2022
[Mon Jul 20 06:58:02.251785 2026] [security2:error] [pid 16093:tid 16342] [client 63.246.157.39:39708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4bWpuybMv3z_zMVBTCWgACBU8"]
[Mon Jul 20 06:58:02.467890 2026] [security2:error] [pid 15216:tid 15387] [client 14.225.17.146:58216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4bWttIy0gkFcVddGaAsQAAATM"], referer: http://savilerowtravel.com/2022
[Mon Jul 20 06:58:02.916454 2026] [security2:error] [pid 15216:tid 15357] [client 13.233.207.33:52826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bWttIy0gkFcVddGaAwAAAARU"]
[Mon Jul 20 06:58:02.916552 2026] [security2:error] [pid 15216:tid 15357] [client 13.233.207.33:52826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bWttIy0gkFcVddGaAwAAAARU"]
[Mon Jul 20 06:58:02.962409 2026] [security2:error] [pid 16093:tid 16295] [client 14.225.17.146:57680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4bWZuybMv3z_zMVBTCNQAAAdY"], referer: http://lelandumc.org/2022
[Mon Jul 20 06:58:02.982160 2026] [security2:error] [pid 16093:tid 16278] [client 104.234.53.48:53193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bWpuybMv3z_zMVBTCiQAAAcU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:02.997579 2026] [security2:error] [pid 16093:tid 16281] [client 194.5.53.247:23217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/pomo/index.php"] [unique_id "al4bWpuybMv3z_zMVBTCigAAAcg"]
[Mon Jul 20 06:58:03.024535 2026] [security2:error] [pid 16093:tid 16323] [client 103.125.179.95:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bW5uybMv3z_zMVBTCiwAAAfI"]
[Mon Jul 20 06:58:03.024655 2026] [security2:error] [pid 16093:tid 16323] [client 103.125.179.95:57381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bW5uybMv3z_zMVBTCiwAAAfI"]
[Mon Jul 20 06:58:03.159277 2026] [security2:error] [pid 16093:tid 16302] [client 65.111.11.65:27787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bW5uybMv3z_zMVBTCjAAAAd0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:03.523630 2026] [security2:error] [pid 15216:tid 15237] [remote 8.217.108.67:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bW9tIy0gkFcVddGaA3gABNBQ"]
[Mon Jul 20 06:58:03.621314 2026] [security2:error] [pid 16093:tid 16313] [client 103.238.106.162:42697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bW5uybMv3z_zMVBTCnAAAAeg"]
[Mon Jul 20 06:58:03.622060 2026] [security2:error] [pid 16093:tid 16313] [client 103.238.106.162:42697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bW5uybMv3z_zMVBTCnAAAAeg"]
[Mon Jul 20 06:58:03.762664 2026] [security2:error] [pid 15216:tid 15348] [client 57.141.18.56:48458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bWdtIy0gkFcVddGaAjgABDAc"]
[Mon Jul 20 06:58:03.836384 2026] [security2:error] [pid 15216:tid 15459] [client 117.247.108.24:31570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bW9tIy0gkFcVddGaA7QAAAXs"]
[Mon Jul 20 06:58:03.836502 2026] [security2:error] [pid 15216:tid 15459] [client 117.247.108.24:31570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bW9tIy0gkFcVddGaA7QAAAXs"]
[Mon Jul 20 06:58:03.881590 2026] [security2:error] [pid 16093:tid 16317] [client 194.5.53.241:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/config.php"] [unique_id "al4bW5uybMv3z_zMVBTCqQAAAew"]
[Mon Jul 20 06:58:03.977100 2026] [security2:error] [pid 16093:tid 16306] [client 193.56.28.166:51581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.28.56.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bW5uybMv3z_zMVBTCrAAAAeE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:04.202625 2026] [security2:error] [pid 16093:tid 16297] [client 14.225.17.146:62354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4bWpuybMv3z_zMVBTChQAAAdg"], referer: http://effingweirdmuseums.com/2022
[Mon Jul 20 06:58:04.244654 2026] [security2:error] [pid 15216:tid 15440] [client 152.58.191.29:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bXNtIy0gkFcVddGaA-wAAAWg"]
[Mon Jul 20 06:58:04.244778 2026] [security2:error] [pid 15216:tid 15440] [client 152.58.191.29:58922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bXNtIy0gkFcVddGaA-wAAAWg"]
[Mon Jul 20 06:58:04.257670 2026] [security2:error] [pid 16093:tid 16229] [client 194.5.53.238:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/special.php"] [unique_id "al4bXJuybMv3z_zMVBTCwAAAAZQ"]
[Mon Jul 20 06:58:04.477115 2026] [security2:error] [pid 16093:tid 16250] [client 13.229.223.11:20490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bXJuybMv3z_zMVBTCxwAAAak"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:04.673928 2026] [security2:error] [pid 16093:tid 16221] [remote 47.86.33.52:21856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4bXJuybMv3z_zMVBTC0AAB1H4"]
[Mon Jul 20 06:58:04.743142 2026] [security2:error] [pid 16093:tid 16224] [client 45.3.46.225:50753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bXJuybMv3z_zMVBTC1AAAAY8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:04.900120 2026] [security2:error] [pid 15216:tid 15380] [client 194.5.53.230:52945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/assets/script.js.php"] [unique_id "al4bXNtIy0gkFcVddGaBFQAAASw"]
[Mon Jul 20 06:58:05.018505 2026] [security2:error] [pid 16093:tid 16274] [client 47.129.222.11:45444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bXJuybMv3z_zMVBTC2AAAAcE"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:05.037626 2026] [security2:error] [pid 16093:tid 16301] [client 15.237.209.113:26276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bXJuybMv3z_zMVBTCwwAAAdw"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:58:05.081255 2026] [security2:error] [pid 16093:tid 16317] [client 77.110.127.138:60416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 968 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bXZuybMv3z_zMVBTC3gAAAew"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:05.140103 2026] [security2:error] [pid 16093:tid 16254] [client 14.225.17.146:62685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4bXZuybMv3z_zMVBTC2wAAAa0"], referer: http://dasmarque.com/2022
[Mon Jul 20 06:58:05.145885 2026] [security2:error] [pid 15216:tid 15403] [client 14.225.17.146:62697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4bXdtIy0gkFcVddGaBGgAAAUM"], referer: https://effingweirdmuseums.com/2022
[Mon Jul 20 06:58:05.259253 2026] [security2:error] [pid 16093:tid 16229] [client 34.67.218.220:58832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "darkknightsolutions.com"] [uri "/wp-json/batch/v1"] [unique_id "al4bXZuybMv3z_zMVBTC6wAAAZQ"]
[Mon Jul 20 06:58:05.282911 2026] [security2:error] [pid 16093:tid 16331] [client 194.5.53.237:40953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "al4bXZuybMv3z_zMVBTC7QAAAfo"]
[Mon Jul 20 06:58:05.303531 2026] [security2:error] [pid 16093:tid 16330] [client 13.229.223.11:20496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bXZuybMv3z_zMVBTC7gAAAfk"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:05.438173 2026] [security2:error] [pid 15216:tid 15437] [client 13.215.47.127:38850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bXdtIy0gkFcVddGaBKAAAAWU"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:05.471059 2026] [security2:error] [pid 16093:tid 16257] [client 216.244.66.203:56568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/benicar-40-125-mg-772a.pdf"] [unique_id "al4bXZuybMv3z_zMVBTC9wAAAbA"]
[Mon Jul 20 06:58:05.471197 2026] [security2:error] [pid 16093:tid 16257] [client 216.244.66.203:56568] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.samdothan.org"] [uri "/benicar-40-125-mg-772a.pdf"] [unique_id "al4bXZuybMv3z_zMVBTC9wAAAbA"]
[Mon Jul 20 06:58:05.514558 2026] [security2:error] [pid 15216:tid 15448] [client 45.3.39.164:36963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bXdtIy0gkFcVddGaBLAAAAXA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:05.567490 2026] [security2:error] [pid 16093:tid 16342] [client 14.225.17.146:62689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4bW5uybMv3z_zMVBTClAAAAgU"], referer: http://hilltopnurseryinc.com/2022
[Mon Jul 20 06:58:05.793367 2026] [security2:error] [pid 16093:tid 16275] [client 77.110.127.138:60419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bXZuybMv3z_zMVBTDAgAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:05.793491 2026] [security2:error] [pid 16093:tid 16275] [client 77.110.127.138:60419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bXZuybMv3z_zMVBTDAgAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:05.841942 2026] [security2:error] [pid 16093:tid 16348] [client 57.141.18.39:35431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bW5uybMv3z_zMVBTCkwACC1A"]
[Mon Jul 20 06:58:05.954082 2026] [core:error] [pid 16093:tid 16265] [client 14.225.17.146:57704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2022
[Mon Jul 20 06:58:05.954127 2026] [core:error] [pid 16093:tid 16265] [client 14.225.17.146:57704] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2022
[Mon Jul 20 06:58:06.161615 2026] [security2:error] [pid 15216:tid 15384] [client 14.225.17.146:57706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4bXdtIy0gkFcVddGaBRQAAATA"], referer: http://longevityperformanceclinic.com/2022
[Mon Jul 20 06:58:06.180642 2026] [security2:error] [pid 16093:tid 16177] [remote 47.86.33.52:21856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4bXpuybMv3z_zMVBTDEgABy1I"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 06:58:06.195970 2026] [security2:error] [pid 16093:tid 16239] [client 14.225.17.146:64686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4bXZuybMv3z_zMVBTC6gAAAZ4"], referer: http://retzkolonglogistics.com/2022
[Mon Jul 20 06:58:06.279362 2026] [security2:error] [pid 16093:tid 16278] [client 47.129.222.11:45456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bXpuybMv3z_zMVBTDGAAAAcU"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:06.418198 2026] [security2:error] [pid 16093:tid 16238] [client 57.141.18.46:32936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bW5uybMv3z_zMVBTCqAABnVY"]
[Mon Jul 20 06:58:06.440138 2026] [security2:error] [pid 15216:tid 15382] [client 220.181.108.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4bXttIy0gkFcVddGaBTwAAAS4"]
[Mon Jul 20 06:58:06.453376 2026] [security2:error] [pid 16093:tid 16140] [remote 192.241.143.148:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bXpuybMv3z_zMVBTDHQAB3i0"]
[Mon Jul 20 06:58:06.500358 2026] [security2:error] [pid 16093:tid 16252] [client 216.73.216.170:4806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "pattyspractice.com"] [uri "/index.php"] [unique_id "al4bXpuybMv3z_zMVBTDGQABqwQ"]
[Mon Jul 20 06:58:06.515908 2026] [security2:error] [pid 15216:tid 15466] [client 104.234.53.66:53375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bXttIy0gkFcVddGaBWQAAAYI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:06.516257 2026] [security2:error] [pid 15216:tid 15258] [remote 8.217.108.67:59328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bXttIy0gkFcVddGaBWwABOCk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:06.633358 2026] [security2:error] [pid 15216:tid 15383] [client 18.142.226.106:45038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bXttIy0gkFcVddGaBXwAAAS8"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:06.655449 2026] [security2:error] [pid 16093:tid 16209] [remote 192.241.143.148:58430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bXpuybMv3z_zMVBTDJgACB3I"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:58:06.683561 2026] [security2:error] [pid 15216:tid 15426] [client 112.86.225.175:41094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.danwolfe.us"] [uri "/2015/04/im-giving-away-my-2016-presidential-vote/"] [unique_id "al4bXttIy0gkFcVddGaBYQAAAVo"]
[Mon Jul 20 06:58:06.683668 2026] [security2:error] [pid 15216:tid 15426] [client 112.86.225.175:41094] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/2015/04/im-giving-away-my-2016-presidential-vote/"] [unique_id "al4bXttIy0gkFcVddGaBYQAAAVo"]
[Mon Jul 20 06:58:06.744673 2026] [security2:error] [pid 16093:tid 16313] [client 14.225.17.146:62452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4bXZuybMv3z_zMVBTC7AAAAeg"], referer: http://709fx.com/2022
[Mon Jul 20 06:58:06.975433 2026] [security2:error] [pid 16093:tid 16233] [client 34.67.218.220:58832] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "darkknightsolutions.com"] [uri "/"] [unique_id "al4bXpuybMv3z_zMVBTDOQAAAZg"]
[Mon Jul 20 06:58:06.998423 2026] [security2:error] [pid 15216:tid 15448] [client 194.5.53.212:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/sunrise/colors_95.php"] [unique_id "al4bXttIy0gkFcVddGaBdQAAAXA"]
[Mon Jul 20 06:58:07.079745 2026] [security2:error] [pid 16093:tid 16267] [client 44.245.170.32:36600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bX5uybMv3z_zMVBTDPQAAAbo"]
[Mon Jul 20 06:58:07.104647 2026] [security2:error] [pid 16093:tid 16225] [client 187.16.64.216:54927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bX5uybMv3z_zMVBTDPgAAAZA"]
[Mon Jul 20 06:58:07.104743 2026] [security2:error] [pid 16093:tid 16225] [client 187.16.64.216:54927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bX5uybMv3z_zMVBTDPgAAAZA"]
[Mon Jul 20 06:58:07.301513 2026] [security2:error] [pid 15216:tid 15421] [client 14.225.17.146:59351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4bX9tIy0gkFcVddGaBeAAAAVU"], referer: http://carolinapressurewashers.com/2022
[Mon Jul 20 06:58:07.438311 2026] [security2:error] [pid 16093:tid 16343] [client 194.5.53.246:43467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/block-patterns/autoload_classmap.php"] [unique_id "al4bX5uybMv3z_zMVBTDTAAAAgY"]
[Mon Jul 20 06:58:07.515386 2026] [security2:error] [pid 16093:tid 16318] [client 13.229.223.11:20502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bX5uybMv3z_zMVBTDWAAAAe0"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:07.551363 2026] [security2:error] [pid 16093:tid 16278] [client 104.234.53.72:48069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bX5uybMv3z_zMVBTDWQAAAcU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:07.725017 2026] [authz_core:error] [pid 16093:tid 16341] [client 147.93.171.187:57523] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-admin/includes/error_log, referer: binance.com
[Mon Jul 20 06:58:07.854698 2026] [security2:error] [pid 16093:tid 16255] [client 194.5.53.237:44623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/uploads/wp.php"] [unique_id "al4bX5uybMv3z_zMVBTDYAAAAa4"]
[Mon Jul 20 06:58:07.898793 2026] [security2:error] [pid 15216:tid 15472] [client 13.229.223.11:20506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bX9tIy0gkFcVddGaBlgAAAYg"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:58:08.009069 2026] [security2:error] [pid 15216:tid 15356] [client 98.159.234.160:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bYNtIy0gkFcVddGaBnwAAARQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:58:08.081450 2026] [security2:error] [pid 16093:tid 16340] [client 183.82.98.154:54519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bYJuybMv3z_zMVBTDbwAAAgM"]
[Mon Jul 20 06:58:08.081594 2026] [security2:error] [pid 16093:tid 16340] [client 183.82.98.154:54519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bYJuybMv3z_zMVBTDbwAAAgM"]
[Mon Jul 20 06:58:08.150817 2026] [autoindex:error] [pid 15216:tid 15234] [remote 34.83.147.252:62290] AH01276: Cannot serve directory /home2/cxrmhtmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://cxr.mht.mybluehost.me
[Mon Jul 20 06:58:08.352682 2026] [security2:error] [pid 16093:tid 16277] [client 194.5.53.226:52635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/certificates/about.php"] [unique_id "al4bYJuybMv3z_zMVBTDdAAAAcQ"]
[Mon Jul 20 06:58:08.573784 2026] [security2:error] [pid 16093:tid 16328] [client 50.116.65.227:17898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bYJuybMv3z_zMVBTDiQAAAfc"]
[Mon Jul 20 06:58:08.586049 2026] [security2:error] [pid 15216:tid 15456] [client 50.116.65.227:17900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bYNtIy0gkFcVddGaBuAAAAXg"]
[Mon Jul 20 06:58:08.694043 2026] [security2:error] [pid 15216:tid 15451] [client 220.181.108.158:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4bYNtIy0gkFcVddGaBtQAAAXM"]
[Mon Jul 20 06:58:08.718499 2026] [security2:error] [pid 15216:tid 15386] [client 57.141.18.102:27366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bXttIy0gkFcVddGaBUgABMlY"]
[Mon Jul 20 06:58:09.010141 2026] [security2:error] [pid 15216:tid 15435] [client 194.5.53.55:43471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/cgi-bin/class.api.php"] [unique_id "al4bYdtIy0gkFcVddGaBzAAAAWM"]
[Mon Jul 20 06:58:09.060617 2026] [security2:error] [pid 15216:tid 15404] [client 187.108.85.186:62117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bYdtIy0gkFcVddGaBzgAAAUQ"]
[Mon Jul 20 06:58:09.060800 2026] [security2:error] [pid 15216:tid 15404] [client 187.108.85.186:62117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bYdtIy0gkFcVddGaBzgAAAUQ"]
[Mon Jul 20 06:58:09.157810 2026] [security2:error] [pid 16093:tid 16244] [client 104.234.53.58:23821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bYZuybMv3z_zMVBTDmQAAAaM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:09.235389 2026] [security2:error] [pid 16093:tid 16315] [client 57.141.18.120:25040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bXpuybMv3z_zMVBTDMAAB6lU"]
[Mon Jul 20 06:58:09.436691 2026] [security2:error] [pid 15216:tid 15462] [client 14.225.17.146:62315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4bYdtIy0gkFcVddGaB1wAAAX4"], referer: http://tntcatholic.com/2022
[Mon Jul 20 06:58:09.454160 2026] [security2:error] [pid 15216:tid 15467] [client 117.222.139.248:52726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bYdtIy0gkFcVddGaB4QAAAYM"]
[Mon Jul 20 06:58:09.454406 2026] [security2:error] [pid 15216:tid 15467] [client 117.222.139.248:52726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bYdtIy0gkFcVddGaB4QAAAYM"]
[Mon Jul 20 06:58:09.504854 2026] [security2:error] [pid 16093:tid 16342] [client 194.5.53.229:48419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/cache/index.php"] [unique_id "al4bYZuybMv3z_zMVBTDqwAAAgU"]
[Mon Jul 20 06:58:09.619594 2026] [security2:error] [pid 16093:tid 16285] [client 103.144.65.217:49159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bYZuybMv3z_zMVBTDrgAAAcw"]
[Mon Jul 20 06:58:09.619731 2026] [security2:error] [pid 16093:tid 16285] [client 103.144.65.217:49159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bYZuybMv3z_zMVBTDrgAAAcw"]
[Mon Jul 20 06:58:09.631015 2026] [security2:error] [pid 16093:tid 16302] [client 65.111.22.136:32777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bYZuybMv3z_zMVBTDrQAAAd0"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:09.784201 2026] [security2:error] [pid 15216:tid 15427] [client 77.110.127.138:60437] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 300 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bYdtIy0gkFcVddGaB6AAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:09.946260 2026] [security2:error] [pid 16093:tid 16232] [client 104.234.53.78:26451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bYZuybMv3z_zMVBTDsQAAAZc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:10.197990 2026] [security2:error] [pid 16093:tid 16296] [client 104.207.52.8:28561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bYpuybMv3z_zMVBTDwAAAAdc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:10.218298 2026] [security2:error] [pid 16093:tid 16282] [client 104.234.53.78:26451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bYpuybMv3z_zMVBTDwwAAAck"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:10.309705 2026] [security2:error] [pid 15216:tid 15386] [client 194.5.53.217:22399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4bYttIy0gkFcVddGaCBAAAATI"]
[Mon Jul 20 06:58:10.648522 2026] [security2:error] [pid 16093:tid 16249] [client 194.5.53.241:65071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/edit.php"] [unique_id "al4bYpuybMv3z_zMVBTDygAAAag"]
[Mon Jul 20 06:58:10.701093 2026] [security2:error] [pid 16093:tid 16338] [client 57.141.18.40:42588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bYJuybMv3z_zMVBTDcwACASs"]
[Mon Jul 20 06:58:10.718668 2026] [security2:error] [pid 16093:tid 16225] [client 14.225.17.146:62326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4bYZuybMv3z_zMVBTDnwAAAZA"], referer: http://eduardsales.com/2022
[Mon Jul 20 06:58:10.756878 2026] [security2:error] [pid 16093:tid 16242] [client 104.207.50.16:47871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bYpuybMv3z_zMVBTD0AAAAaE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:10.926284 2026] [security2:error] [pid 16093:tid 16327] [client 104.234.53.93:62149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bYpuybMv3z_zMVBTD2AAAAfY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:10.937119 2026] [security2:error] [pid 16093:tid 16349] [client 77.110.127.138:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bYpuybMv3z_zMVBTD2QAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:10.937227 2026] [security2:error] [pid 16093:tid 16349] [client 77.110.127.138:60450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bYpuybMv3z_zMVBTD2QAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:11.122440 2026] [security2:error] [pid 16093:tid 16244] [client 14.225.17.146:52390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4bYpuybMv3z_zMVBTD1wAAAaM"], referer: http://lifeisbetterlakeside.com/2022
[Mon Jul 20 06:58:11.299413 2026] [security2:error] [pid 16093:tid 16278] [client 194.5.53.242:54687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/webdb.php"] [unique_id "al4bY5uybMv3z_zMVBTD6gAAAcU"]
[Mon Jul 20 06:58:11.346321 2026] [security2:error] [pid 16093:tid 16256] [client 104.207.51.161:21947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bY5uybMv3z_zMVBTD6AAAAa8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:11.348529 2026] [security2:error] [pid 16093:tid 16325] [client 65.111.22.207:32897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bY5uybMv3z_zMVBTD7gAAAfQ"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:58:11.387264 2026] [authz_core:error] [pid 16093:tid 16333] [client 147.93.171.187:50350] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-admin/includes/error_log, referer: binance.com
[Mon Jul 20 06:58:11.700259 2026] [security2:error] [pid 15216:tid 15458] [client 157.55.39.14:40241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4bYttIy0gkFcVddGaCCgABeh8"]
[Mon Jul 20 06:58:11.797144 2026] [security2:error] [pid 16093:tid 16310] [client 77.110.127.138:60452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bY5uybMv3z_zMVBTD6wAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:11.952582 2026] [security2:error] [pid 16093:tid 16259] [client 66.249.73.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.getgarrison.com"] [uri "/index.php"] [unique_id "al4bY5uybMv3z_zMVBTEBAAAAbI"]
[Mon Jul 20 06:58:12.012433 2026] [security2:error] [pid 16093:tid 16276] [client 14.251.3.155:54828] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bZJuybMv3z_zMVBTECgAAAcM"]
[Mon Jul 20 06:58:12.062889 2026] [security2:error] [pid 16093:tid 16268] [client 57.141.18.108:27192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bYZuybMv3z_zMVBTDrAABu3o"]
[Mon Jul 20 06:58:12.101763 2026] [security2:error] [pid 16093:tid 16350] [client 194.5.53.207:38837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/assets/images/doc.php"] [unique_id "al4bZJuybMv3z_zMVBTEDAAAAg0"]
[Mon Jul 20 06:58:12.157987 2026] [security2:error] [pid 16093:tid 16341] [client 14.225.17.146:52593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4bYpuybMv3z_zMVBTD0gAAAgQ"], referer: http://detroitcsc.com/2022
[Mon Jul 20 06:58:12.239589 2026] [security2:error] [pid 15216:tid 15410] [client 14.225.17.146:52101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4bZNtIy0gkFcVddGaCWAAAAUo"], referer: http://katsklar.com/2022
[Mon Jul 20 06:58:12.329560 2026] [security2:error] [pid 16093:tid 16110] [remote 97.74.87.194:50434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bZJuybMv3z_zMVBTEFwAB3w8"]
[Mon Jul 20 06:58:12.329682 2026] [security2:error] [pid 16093:tid 16304] [client 97.74.87.194:50434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bZJuybMv3z_zMVBTEFwAB3w8"]
[Mon Jul 20 06:58:12.694820 2026] [security2:error] [pid 16093:tid 16295] [client 77.110.127.138:60463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bZJuybMv3z_zMVBTEHQAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:12.750935 2026] [security2:error] [pid 16093:tid 16265] [client 217.142.18.172:41798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bZJuybMv3z_zMVBTEJwAAAbg"]
[Mon Jul 20 06:58:12.758312 2026] [security2:error] [pid 16093:tid 16265] [client 217.142.18.172:41798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bZJuybMv3z_zMVBTEJwAAAbg"]
[Mon Jul 20 06:58:12.767373 2026] [security2:error] [pid 15216:tid 15448] [client 57.141.18.65:34354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bYttIy0gkFcVddGaB_wABcC0"]
[Mon Jul 20 06:58:12.775270 2026] [security2:error] [pid 15216:tid 15415] [client 157.55.39.14:40241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4bZNtIy0gkFcVddGaCXgABT2M"]
[Mon Jul 20 06:58:12.878244 2026] [security2:error] [pid 16093:tid 16323] [client 194.5.53.229:22755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/file2.php"] [unique_id "al4bZJuybMv3z_zMVBTELgAAAfI"]
[Mon Jul 20 06:58:13.153829 2026] [security2:error] [pid 16093:tid 16255] [client 197.186.66.42:63037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bZZuybMv3z_zMVBTESAAAAa4"]
[Mon Jul 20 06:58:13.154030 2026] [security2:error] [pid 16093:tid 16255] [client 197.186.66.42:63037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bZZuybMv3z_zMVBTESAAAAa4"]
[Mon Jul 20 06:58:13.206153 2026] [proxy:error] [pid 15216:tid 15426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:13.206231 2026] [proxy_http:error] [pid 15216:tid 15426] [client 206.189.96.6:33456] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:13.206991 2026] [proxy:error] [pid 15216:tid 15426] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:13.207029 2026] [proxy_http:error] [pid 15216:tid 15426] [client 206.189.96.6:33456] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:13.553564 2026] [proxy:error] [pid 15216:tid 15432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:13.553657 2026] [proxy_http:error] [pid 15216:tid 15432] [client 206.189.96.6:33462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.tvb.fln.mybluehost.me/
[Mon Jul 20 06:58:13.554455 2026] [proxy:error] [pid 15216:tid 15432] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:13.554489 2026] [proxy_http:error] [pid 15216:tid 15432] [client 206.189.96.6:33462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.tvb.fln.mybluehost.me/
[Mon Jul 20 06:58:13.584952 2026] [security2:error] [pid 16093:tid 16278] [client 14.225.17.146:64206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4bZJuybMv3z_zMVBTEGAAAAcU"]
[Mon Jul 20 06:58:13.620975 2026] [security2:error] [pid 16093:tid 16254] [client 77.110.127.138:60468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bZZuybMv3z_zMVBTEVwAAAa0"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:13.821211 2026] [security2:error] [pid 16093:tid 16292] [client 77.110.127.138:60467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bZJuybMv3z_zMVBTEMQAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:13.826176 2026] [security2:error] [pid 15216:tid 15362] [client 14.225.17.146:64199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4bZNtIy0gkFcVddGaCXwAAARo"], referer: http://slutilities.com/2022
[Mon Jul 20 06:58:13.870124 2026] [security2:error] [pid 16093:tid 16342] [client 103.125.179.95:57899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.179.125.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bZZuybMv3z_zMVBTEYgAAAgU"]
[Mon Jul 20 06:58:13.870226 2026] [security2:error] [pid 16093:tid 16342] [client 103.125.179.95:57899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bZZuybMv3z_zMVBTEYgAAAgU"]
[Mon Jul 20 06:58:13.998176 2026] [security2:error] [pid 16093:tid 16324] [client 57.141.18.62:56438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bY5uybMv3z_zMVBTD5QAB80k"]
[Mon Jul 20 06:58:14.121204 2026] [proxy:error] [pid 15216:tid 15387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:14.121255 2026] [proxy_http:error] [pid 15216:tid 15387] [client 206.189.96.6:41912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:14.122227 2026] [proxy:error] [pid 15216:tid 15387] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:14.122262 2026] [proxy_http:error] [pid 15216:tid 15387] [client 206.189.96.6:41912] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:14.277059 2026] [security2:error] [pid 16093:tid 16289] [client 103.238.106.162:42695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bZpuybMv3z_zMVBTEdQAAAdA"]
[Mon Jul 20 06:58:14.277738 2026] [security2:error] [pid 16093:tid 16289] [client 103.238.106.162:42695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bZpuybMv3z_zMVBTEdQAAAdA"]
[Mon Jul 20 06:58:14.356253 2026] [security2:error] [pid 16093:tid 16338] [client 117.247.108.24:944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bZpuybMv3z_zMVBTEegAAAgE"]
[Mon Jul 20 06:58:14.356357 2026] [security2:error] [pid 16093:tid 16338] [client 117.247.108.24:944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bZpuybMv3z_zMVBTEegAAAgE"]
[Mon Jul 20 06:58:14.364429 2026] [autoindex:error] [pid 16093:tid 16135] [remote 34.75.24.227:49576] AH01276: Cannot serve directory /home2/fscxcsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://fsc.xcs.mybluehost.me
[Mon Jul 20 06:58:14.519719 2026] [security2:error] [pid 15216:tid 15414] [client 57.141.18.9:62884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bY9tIy0gkFcVddGaCPgABTic"]
[Mon Jul 20 06:58:14.715156 2026] [security2:error] [pid 16093:tid 16251] [client 104.234.53.89:43675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bZpuybMv3z_zMVBTEjgAAAao"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:14.825272 2026] [security2:error] [pid 16093:tid 16279] [client 194.5.53.243:56215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/ID3/wp-work.php"] [unique_id "al4bZpuybMv3z_zMVBTElQAAAcY"]
[Mon Jul 20 06:58:15.009745 2026] [security2:error] [pid 16093:tid 16232] [client 77.110.127.138:60474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bZpuybMv3z_zMVBTEhAAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:15.153107 2026] [lsapi:warn] [pid 16093:tid 16331] [client 49.51.39.209:58682] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: http://oldracelimited.com
[Mon Jul 20 06:58:15.156791 2026] [lsapi:warn] [pid 16093:tid 16331] [client 49.51.39.209:58682] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: http://oldracelimited.com
[Mon Jul 20 06:58:15.201236 2026] [security2:error] [pid 16093:tid 16288] [client 14.225.17.146:65533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4bZ5uybMv3z_zMVBTEnwAAAc8"], referer: http://ghivs.com/2022
[Mon Jul 20 06:58:15.488834 2026] [security2:error] [pid 16093:tid 16105] [remote 152.228.213.32:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4bZ5uybMv3z_zMVBTEwQAB5Qo"]
[Mon Jul 20 06:58:15.559898 2026] [security2:error] [pid 16093:tid 16301] [client 152.58.191.29:59373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bZ5uybMv3z_zMVBTEwgAAAdw"]
[Mon Jul 20 06:58:15.563399 2026] [security2:error] [pid 16093:tid 16301] [client 152.58.191.29:59373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bZ5uybMv3z_zMVBTEwgAAAdw"]
[Mon Jul 20 06:58:15.596249 2026] [security2:error] [pid 15216:tid 15439] [client 65.111.10.211:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bZ9tIy0gkFcVddGaCxgAAAWc"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:15.598527 2026] [security2:error] [pid 16093:tid 16318] [client 122.183.32.225:19372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bZ5uybMv3z_zMVBTExAAAAe0"]
[Mon Jul 20 06:58:15.598645 2026] [security2:error] [pid 16093:tid 16318] [client 122.183.32.225:19372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bZ5uybMv3z_zMVBTExAAAAe0"]
[Mon Jul 20 06:58:15.627873 2026] [security2:error] [pid 16093:tid 16262] [client 77.110.127.138:60480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bZ5uybMv3z_zMVBTEvQAAAbU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:15.690428 2026] [security2:error] [pid 16093:tid 16115] [remote 152.228.213.32:55590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4bZ5uybMv3z_zMVBTExgAB6BQ"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 06:58:15.801444 2026] [security2:error] [pid 16093:tid 16264] [client 14.225.17.146:64476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4bZpuybMv3z_zMVBTEZwAAAbc"], referer: http://fluidtemple.org/2022
[Mon Jul 20 06:58:15.966318 2026] [security2:error] [pid 16093:tid 16225] [client 80.114.19.211:41726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4bZ5uybMv3z_zMVBTEzgAAAZA"]
[Mon Jul 20 06:58:16.297802 2026] [security2:error] [pid 15216:tid 15410] [client 216.244.66.243:60566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4baNtIy0gkFcVddGaC6AAAAUo"]
[Mon Jul 20 06:58:16.297893 2026] [security2:error] [pid 15216:tid 15410] [client 216.244.66.243:60566] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4baNtIy0gkFcVddGaC6AAAAUo"]
[Mon Jul 20 06:58:16.323902 2026] [security2:error] [pid 15216:tid 15242] [remote 57.141.18.80:37888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3924907"] [unique_id "al4baNtIy0gkFcVddGaC6wABOhk"]
[Mon Jul 20 06:58:16.365576 2026] [security2:error] [pid 15216:tid 15466] [client 104.207.49.80:48791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4baNtIy0gkFcVddGaC7AAAAYI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:16.400168 2026] [security2:error] [pid 16093:tid 16111] [remote 154.66.198.148:7828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4baJuybMv3z_zMVBTE3gABuxA"]
[Mon Jul 20 06:58:16.409326 2026] [security2:error] [pid 16093:tid 16283] [client 14.225.17.146:64016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4bZpuybMv3z_zMVBTEmwAAAco"], referer: http://alchemygroup.ca/2022
[Mon Jul 20 06:58:16.411733 2026] [security2:error] [pid 16093:tid 16319] [client 194.5.53.244:53979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/alfa.php"] [unique_id "al4baJuybMv3z_zMVBTE3wAAAe4"]
[Mon Jul 20 06:58:16.614127 2026] [security2:error] [pid 15216:tid 15362] [client 77.110.127.138:60485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bZ9tIy0gkFcVddGaC2AAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:16.689893 2026] [security2:error] [pid 16093:tid 16318] [client 15.204.114.164:49046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "omrobuildingcenter.com"] [uri "/"] [unique_id "al4baJuybMv3z_zMVBTE8AAAAe0"]
[Mon Jul 20 06:58:16.791522 2026] [security2:error] [pid 15216:tid 15430] [client 116.179.32.108:23395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4bZ9tIy0gkFcVddGaC1wABXgY"]
[Mon Jul 20 06:58:16.933197 2026] [security2:error] [pid 16093:tid 16121] [remote 154.66.198.148:7828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4baJuybMv3z_zMVBTE_wAB6ho"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 06:58:17.201304 2026] [security2:error] [pid 15216:tid 15436] [client 192.140.149.97:44824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4badtIy0gkFcVddGaDDgAAAWQ"]
[Mon Jul 20 06:58:17.201397 2026] [security2:error] [pid 15216:tid 15436] [client 192.140.149.97:44824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4badtIy0gkFcVddGaDDgAAAWQ"]
[Mon Jul 20 06:58:17.203985 2026] [security2:error] [pid 15216:tid 15289] [remote 84.247.172.23:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4badtIy0gkFcVddGaDDQABRUg"]
[Mon Jul 20 06:58:17.402295 2026] [security2:error] [pid 15216:tid 15273] [remote 84.247.172.23:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4badtIy0gkFcVddGaDFgABejg"], referer: https://detroitcsc.com/wp-login.php
[Mon Jul 20 06:58:17.596458 2026] [proxy:error] [pid 16093:tid 16323] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:17.596522 2026] [proxy_http:error] [pid 16093:tid 16323] [client 206.189.96.6:40822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.tvb.fln.mybluehost.me/
[Mon Jul 20 06:58:17.597339 2026] [proxy:error] [pid 16093:tid 16323] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:17.597370 2026] [proxy_http:error] [pid 16093:tid 16323] [client 206.189.96.6:40822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.tvb.fln.mybluehost.me/
[Mon Jul 20 06:58:17.648759 2026] [security2:error] [pid 16093:tid 16324] [client 194.5.53.237:43991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "al4baZuybMv3z_zMVBTFLwAAAfM"]
[Mon Jul 20 06:58:17.660669 2026] [security2:error] [pid 16093:tid 16235] [client 80.114.19.211:56038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ghivs.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al4baZuybMv3z_zMVBTFMgAAAZo"]
[Mon Jul 20 06:58:17.757645 2026] [security2:error] [pid 16093:tid 16307] [client 77.110.127.138:60465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4baJuybMv3z_zMVBTFAwAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:17.774858 2026] [security2:error] [pid 16093:tid 16296] [client 65.111.28.216:10329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4baZuybMv3z_zMVBTFOQAAAdc"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:17.865149 2026] [security2:error] [pid 15216:tid 15468] [client 187.16.64.216:55441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4badtIy0gkFcVddGaDJAAAAYQ"]
[Mon Jul 20 06:58:17.865291 2026] [security2:error] [pid 15216:tid 15468] [client 187.16.64.216:55441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4badtIy0gkFcVddGaDJAAAAYQ"]
[Mon Jul 20 06:58:18.249391 2026] [security2:error] [pid 15216:tid 15354] [client 74.208.214.194:59134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4battIy0gkFcVddGaDNQAAARI"]
[Mon Jul 20 06:58:18.252883 2026] [security2:error] [pid 15216:tid 15453] [client 57.141.18.58:37512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bZ9tIy0gkFcVddGaCywABdQ0"]
[Mon Jul 20 06:58:18.271362 2026] [security2:error] [pid 15216:tid 15417] [client 50.116.65.227:16822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4battIy0gkFcVddGaDNwAAAVE"]
[Mon Jul 20 06:58:18.277179 2026] [security2:error] [pid 16093:tid 16300] [client 14.225.17.146:64242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4baJuybMv3z_zMVBTE-AAAAds"], referer: http://recruitinginsight.us/2022
[Mon Jul 20 06:58:18.302315 2026] [security2:error] [pid 15216:tid 15447] [client 104.234.53.79:42125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4battIy0gkFcVddGaDNAAAAW8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:18.320171 2026] [security2:error] [pid 16093:tid 16308] [client 14.225.17.146:52323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4baZuybMv3z_zMVBTFNAAAAeM"], referer: http://alrowad-hub.net/2022
[Mon Jul 20 06:58:18.346441 2026] [security2:error] [pid 16093:tid 16149] [remote 8.217.108.67:58012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4bapuybMv3z_zMVBTFVQAB5TY"]
[Mon Jul 20 06:58:18.428944 2026] [security2:error] [pid 15216:tid 15407] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4battIy0gkFcVddGaDMQAAAUc"]
[Mon Jul 20 06:58:18.430288 2026] [security2:error] [pid 16093:tid 16189] [remote 162.19.246.208:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4bapuybMv3z_zMVBTFVgACDV4"]
[Mon Jul 20 06:58:18.475148 2026] [security2:error] [pid 15216:tid 15365] [client 104.234.53.79:42125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4battIy0gkFcVddGaDSAAAAR0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:18.620568 2026] [security2:error] [pid 16093:tid 16132] [remote 162.19.246.208:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4bapuybMv3z_zMVBTFXQABpSU"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 06:58:18.690042 2026] [security2:error] [pid 15216:tid 15385] [client 77.110.127.138:60491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4battIy0gkFcVddGaDMwAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:18.738442 2026] [security2:error] [pid 16093:tid 16283] [client 14.225.17.146:60523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4bapuybMv3z_zMVBTFUQAAAco"]
[Mon Jul 20 06:58:18.751835 2026] [security2:error] [pid 15216:tid 15467] [client 80.114.19.211:56048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4battIy0gkFcVddGaDTAAAAYM"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:58:18.762621 2026] [security2:error] [pid 15216:tid 15358] [client 194.5.53.247:41135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/click.php"] [unique_id "al4battIy0gkFcVddGaDTgAAARY"]
[Mon Jul 20 06:58:18.846701 2026] [security2:error] [pid 15216:tid 15424] [client 77.110.127.138:60493] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts_position"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4battIy0gkFcVddGaDUwAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:18.936475 2026] [security2:error] [pid 15216:tid 15267] [remote 162.19.86.63:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4battIy0gkFcVddGaDWAABKDI"]
[Mon Jul 20 06:58:18.938650 2026] [security2:error] [pid 15216:tid 15372] [client 57.141.18.12:61446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4baNtIy0gkFcVddGaC4wABJBM"]
[Mon Jul 20 06:58:18.960163 2026] [security2:error] [pid 16093:tid 16119] [remote 8.217.108.67:58012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4bapuybMv3z_zMVBTFbwABmBg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 06:58:19.173441 2026] [security2:error] [pid 15216:tid 15263] [remote 162.19.86.63:55938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ba9tIy0gkFcVddGaDYwABhC4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:19.174284 2026] [security2:error] [pid 16093:tid 16160] [remote 192.241.143.148:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ba5uybMv3z_zMVBTFegAB-UE"]
[Mon Jul 20 06:58:19.263016 2026] [security2:error] [pid 15216:tid 15371] [client 65.111.25.233:62257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.25.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4ba9tIy0gkFcVddGaDZwAAASM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:19.338443 2026] [security2:error] [pid 16093:tid 16171] [remote 192.241.143.148:51106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ba5uybMv3z_zMVBTFfgAB40w"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:19.597355 2026] [security2:error] [pid 16093:tid 16228] [client 187.108.85.186:62660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ba5uybMv3z_zMVBTFkQAAAZM"]
[Mon Jul 20 06:58:19.597478 2026] [security2:error] [pid 16093:tid 16228] [client 187.108.85.186:62660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4ba5uybMv3z_zMVBTFkQAAAZM"]
[Mon Jul 20 06:58:19.608918 2026] [security2:error] [pid 16093:tid 16339] [client 50.116.65.227:57804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ba5uybMv3z_zMVBTFkgAAAgI"]
[Mon Jul 20 06:58:19.619275 2026] [security2:error] [pid 16093:tid 16266] [client 50.116.65.227:57818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ba5uybMv3z_zMVBTFkwAAAbk"]
[Mon Jul 20 06:58:19.640562 2026] [security2:error] [pid 15216:tid 15387] [client 80.114.19.211:56062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4ba9tIy0gkFcVddGaDcgAAATM"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:58:19.702232 2026] [security2:error] [pid 16093:tid 16292] [client 14.225.17.146:60926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ba5uybMv3z_zMVBTFiQAAAdM"], referer: http://mezzacraft.com/2022
[Mon Jul 20 06:58:19.803379 2026] [security2:error] [pid 15216:tid 15469] [client 77.110.127.138:60497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ba9tIy0gkFcVddGaDZAAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:19.807930 2026] [security2:error] [pid 16093:tid 16127] [remote 217.61.143.92:35046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ba5uybMv3z_zMVBTFmQABvCA"]
[Mon Jul 20 06:58:19.915973 2026] [security2:error] [pid 15216:tid 15462] [client 194.5.53.232:39987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/.well-known/wp-conflg.php"] [unique_id "al4ba9tIy0gkFcVddGaDfwAAAX4"]
[Mon Jul 20 06:58:20.042296 2026] [security2:error] [pid 16093:tid 16176] [remote 217.61.143.92:35046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4bbJuybMv3z_zMVBTFrAAB41E"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:58:20.133780 2026] [security2:error] [pid 16093:tid 16258] [client 14.225.17.146:63084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4ba5uybMv3z_zMVBTFnwAAAbE"]
[Mon Jul 20 06:58:20.172449 2026] [security2:error] [pid 16093:tid 16345] [client 14.225.17.146:62327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4bapuybMv3z_zMVBTFTAAAAgg"], referer: http://itdynamix.com/2022
[Mon Jul 20 06:58:20.209975 2026] [security2:error] [pid 16093:tid 16226] [client 103.144.65.217:49577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bbJuybMv3z_zMVBTFtQAAAZE"]
[Mon Jul 20 06:58:20.210096 2026] [security2:error] [pid 16093:tid 16226] [client 103.144.65.217:49577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bbJuybMv3z_zMVBTFtQAAAZE"]
[Mon Jul 20 06:58:20.308151 2026] [security2:error] [pid 15216:tid 15446] [client 194.5.53.226:26343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "al4bbNtIy0gkFcVddGaDmAAAAW4"]
[Mon Jul 20 06:58:20.352580 2026] [security2:error] [pid 16093:tid 16234] [client 111.225.214.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4bbJuybMv3z_zMVBTFsQAAAZk"]
[Mon Jul 20 06:58:20.709998 2026] [proxy:error] [pid 15216:tid 15359] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:20.710044 2026] [proxy_http:error] [pid 15216:tid 15359] [client 107.172.180.205:52842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:20.710738 2026] [proxy:error] [pid 15216:tid 15359] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:20.710781 2026] [proxy_http:error] [pid 15216:tid 15359] [client 107.172.180.205:52842] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:20.741014 2026] [security2:error] [pid 16093:tid 16303] [client 80.114.19.211:56072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4bbJuybMv3z_zMVBTFygAAAd4"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:58:20.809728 2026] [security2:error] [pid 15216:tid 15356] [client 77.110.127.138:60485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bbNtIy0gkFcVddGaDkAAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:20.820123 2026] [security2:error] [pid 15216:tid 15439] [client 14.225.17.146:60702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4bbNtIy0gkFcVddGaDpAAAAWc"], referer: http://sesamegreenbeans.com/2022
[Mon Jul 20 06:58:20.921412 2026] [security2:error] [pid 16093:tid 16343] [client 104.207.52.33:49095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bbJuybMv3z_zMVBTFzgAAAgY"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:21.022744 2026] [security2:error] [pid 16093:tid 16256] [client 104.234.53.53:35209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bbJuybMv3z_zMVBTF0AAAAa8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:21.072331 2026] [security2:error] [pid 16093:tid 16274] [client 183.82.98.154:55146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bbZuybMv3z_zMVBTF0gAAAcE"]
[Mon Jul 20 06:58:21.072488 2026] [security2:error] [pid 16093:tid 16274] [client 183.82.98.154:55146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bbZuybMv3z_zMVBTF0gAAAcE"]
[Mon Jul 20 06:58:21.114463 2026] [security2:error] [pid 16093:tid 16341] [client 77.110.127.138:60453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bbJuybMv3z_zMVBTFzwAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:21.241595 2026] [security2:error] [pid 15216:tid 15471] [client 57.141.18.42:49646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4battIy0gkFcVddGaDSQABh2M"]
[Mon Jul 20 06:58:21.721117 2026] [security2:error] [pid 16093:tid 16333] [client 77.110.127.138:60463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bbZuybMv3z_zMVBTF1AAAAfw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:21.723433 2026] [security2:error] [pid 15216:tid 15455] [client 14.225.17.146:60533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4bbdtIy0gkFcVddGaD9AAAAXc"], referer: http://mcg.homes/2022
[Mon Jul 20 06:58:21.729956 2026] [security2:error] [pid 15216:tid 15385] [client 80.114.19.211:56086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4bbdtIy0gkFcVddGaD9QAAATE"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:58:21.784160 2026] [security2:error] [pid 15216:tid 15448] [client 14.225.17.146:50093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4bbNtIy0gkFcVddGaDkwAAAXA"], referer: http://nurturemarple.co.uk/2022
[Mon Jul 20 06:58:21.842643 2026] [security2:error] [pid 15216:tid 15405] [client 14.225.17.146:56465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4bbdtIy0gkFcVddGaDzgAAAUU"], referer: https://itdynamix.com/2022
[Mon Jul 20 06:58:21.907105 2026] [proxy:error] [pid 15216:tid 15440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:21.907189 2026] [proxy_http:error] [pid 15216:tid 15440] [client 107.172.180.205:52858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:21.907905 2026] [proxy:error] [pid 15216:tid 15440] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:58:21.907965 2026] [proxy_http:error] [pid 15216:tid 15440] [client 107.172.180.205:52858] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:58:21.924608 2026] [security2:error] [pid 15216:tid 15334] [remote 193.70.112.205:47482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4bbdtIy0gkFcVddGaEAgABD3U"]
[Mon Jul 20 06:58:22.054699 2026] [security2:error] [pid 16093:tid 16346] [client 185.223.152.100:53761] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thegpsapproach.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4bbpuybMv3z_zMVBTF5QAAAgk"]
[Mon Jul 20 06:58:22.117473 2026] [security2:error] [pid 16093:tid 16323] [client 57.141.18.102:50564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ba5uybMv3z_zMVBTFhAAB8jM"]
[Mon Jul 20 06:58:22.124583 2026] [security2:error] [pid 16093:tid 16292] [client 194.5.53.235:32493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/js/widgets/bypass.php"] [unique_id "al4bbpuybMv3z_zMVBTF7AAAAdM"]
[Mon Jul 20 06:58:22.133077 2026] [security2:error] [pid 15216:tid 15342] [remote 193.70.112.205:47482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4bbttIy0gkFcVddGaEDgABHn0"], referer: https://solkeetw.com/wp-login.php
[Mon Jul 20 06:58:22.248228 2026] [security2:error] [pid 16093:tid 16228] [client 50.116.65.227:57900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4bbZuybMv3z_zMVBTF3wAAAZM"]
[Mon Jul 20 06:58:22.339014 2026] [security2:error] [pid 16093:tid 16337] [client 14.225.17.146:63763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4bbpuybMv3z_zMVBTF8QAAAgA"], referer: http://ivetstrategies.com/2022
[Mon Jul 20 06:58:22.400207 2026] [security2:error] [pid 15216:tid 15412] [client 45.157.112.60:44299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bbttIy0gkFcVddGaEGQAAAUw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:58:22.447622 2026] [security2:error] [pid 16093:tid 16238] [client 50.116.65.227:57906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4bbpuybMv3z_zMVBTF9QAAAZ0"]
[Mon Jul 20 06:58:22.563303 2026] [security2:error] [pid 16093:tid 16349] [client 178.62.204.64:63600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4bbpuybMv3z_zMVBTGAgAAAgw"]
[Mon Jul 20 06:58:22.577161 2026] [security2:error] [pid 15216:tid 15416] [client 117.222.139.248:53242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bbttIy0gkFcVddGaEHgAAAVA"]
[Mon Jul 20 06:58:22.577250 2026] [security2:error] [pid 15216:tid 15416] [client 117.222.139.248:53242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bbttIy0gkFcVddGaEHgAAAVA"]
[Mon Jul 20 06:58:22.646061 2026] [security2:error] [pid 16093:tid 16342] [client 80.114.19.211:56102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4bbpuybMv3z_zMVBTGBAAAAgU"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:58:22.659624 2026] [security2:error] [pid 15216:tid 15365] [client 158.173.89.95:30375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bbttIy0gkFcVddGaEIwAAAR0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:58:22.775462 2026] [security2:error] [pid 16093:tid 16261] [client 14.225.17.146:50483] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4bbpuybMv3z_zMVBTGEwAAAbQ"], referer: https://nurturemarple.co.uk/2022
[Mon Jul 20 06:58:23.157653 2026] [security2:error] [pid 15216:tid 15373] [client 178.62.204.64:63708] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4bb9tIy0gkFcVddGaEMwAAASU"]
[Mon Jul 20 06:58:23.194551 2026] [security2:error] [pid 16093:tid 16227] [client 217.142.18.172:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bb5uybMv3z_zMVBTGKwAAAZI"]
[Mon Jul 20 06:58:23.198099 2026] [security2:error] [pid 16093:tid 16227] [client 217.142.18.172:44371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bb5uybMv3z_zMVBTGKwAAAZI"]
[Mon Jul 20 06:58:23.317969 2026] [security2:error] [pid 16093:tid 16351] [client 77.110.127.138:60519] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts_position. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/baby-suri-tips-for-crochet/"] [unique_id "al4bb5uybMv3z_zMVBTGMgAAAg4"]
[Mon Jul 20 06:58:23.417639 2026] [security2:error] [pid 16093:tid 16304] [client 14.225.17.146:52371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4bb5uybMv3z_zMVBTGMQAAAd8"], referer: http://superiorcopywriting.com/2022
[Mon Jul 20 06:58:23.456306 2026] [security2:error] [pid 16093:tid 16294] [client 104.234.53.68:47567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bb5uybMv3z_zMVBTGOAAAAdU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:23.543948 2026] [security2:error] [pid 16093:tid 16305] [client 194.5.53.204:22515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/random_compat/chosen.php"] [unique_id "al4bb5uybMv3z_zMVBTGQAAAAeA"]
[Mon Jul 20 06:58:23.560089 2026] [security2:error] [pid 16093:tid 16257] [client 80.114.19.211:56114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4bb5uybMv3z_zMVBTGNQAAAbA"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 06:58:23.933948 2026] [security2:error] [pid 15216:tid 15377] [client 57.141.18.11:31916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bbdtIy0gkFcVddGaD5AABKRY"]
[Mon Jul 20 06:58:23.965198 2026] [security2:error] [pid 16093:tid 16258] [client 34.221.76.50:22638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4bb5uybMv3z_zMVBTGUwAAAbE"]
[Mon Jul 20 06:58:24.400795 2026] [security2:error] [pid 16093:tid 16299] [client 14.225.17.146:60765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4bbpuybMv3z_zMVBTGHQAAAdo"], referer: http://blaizeaccountingservices.com/2022
[Mon Jul 20 06:58:24.435216 2026] [security2:error] [pid 16093:tid 16304] [client 194.5.53.239:22171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/index.php"] [unique_id "al4bcJuybMv3z_zMVBTGZAAAAd8"]
[Mon Jul 20 06:58:24.648545 2026] [security2:error] [pid 15216:tid 15271] [remote 5.161.225.162:50844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4bcNtIy0gkFcVddGaEcAABezY"]
[Mon Jul 20 06:58:24.734456 2026] [security2:error] [pid 16093:tid 16230] [client 57.141.18.123:65082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bbpuybMv3z_zMVBTF9wABlTc"]
[Mon Jul 20 06:58:24.740949 2026] [security2:error] [pid 15216:tid 15432] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.msandreaadams.net"] [uri "/index.php"] [unique_id "al4bcNtIy0gkFcVddGaEbAAAAWA"]
[Mon Jul 20 06:58:24.752963 2026] [security2:error] [pid 16093:tid 16316] [client 103.238.106.162:42781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bcJuybMv3z_zMVBTGagAAAes"]
[Mon Jul 20 06:58:24.753758 2026] [security2:error] [pid 16093:tid 16316] [client 103.238.106.162:42781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bcJuybMv3z_zMVBTGagAAAes"]
[Mon Jul 20 06:58:24.779520 2026] [security2:error] [pid 15216:tid 15320] [remote 154.66.198.148:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bcNtIy0gkFcVddGaEfgABhmc"]
[Mon Jul 20 06:58:24.796611 2026] [security2:error] [pid 15216:tid 15410] [client 77.110.127.138:60497] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4bcNtIy0gkFcVddGaEgAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:24.831924 2026] [security2:error] [pid 15216:tid 15280] [remote 5.161.225.162:50844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4bcNtIy0gkFcVddGaEgQABFD8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 06:58:24.832544 2026] [security2:error] [pid 15216:tid 15436] [client 117.247.108.24:930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bcNtIy0gkFcVddGaEggAAAWQ"]
[Mon Jul 20 06:58:24.832632 2026] [security2:error] [pid 15216:tid 15436] [client 117.247.108.24:930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bcNtIy0gkFcVddGaEggAAAWQ"]
[Mon Jul 20 06:58:24.976737 2026] [security2:error] [pid 16093:tid 16209] [remote 5.161.225.162:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4bcJuybMv3z_zMVBTGcAAB9XI"]
[Mon Jul 20 06:58:25.200757 2026] [security2:error] [pid 16093:tid 16345] [client 194.5.53.237:29857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/edit.php"] [unique_id "al4bcZuybMv3z_zMVBTGeAAAAgg"]
[Mon Jul 20 06:58:25.226917 2026] [core:error] [pid 15216:tid 15347] [client 14.225.17.146:60335] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:58:25.226939 2026] [core:error] [pid 15216:tid 15347] [client 14.225.17.146:60335] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:58:25.236337 2026] [security2:error] [pid 16093:tid 16173] [remote 5.161.225.162:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4bcZuybMv3z_zMVBTGewABuE4"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 06:58:25.334472 2026] [security2:error] [pid 16093:tid 16199] [remote 188.166.241.141:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4bcZuybMv3z_zMVBTGggABuWg"]
[Mon Jul 20 06:58:25.370333 2026] [security2:error] [pid 15216:tid 15303] [remote 154.66.198.148:7836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bcdtIy0gkFcVddGaEkwABIlY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:25.575786 2026] [core:error] [pid 16093:tid 16303] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:58:25.575809 2026] [core:error] [pid 16093:tid 16303] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:58:25.616620 2026] [security2:error] [pid 16093:tid 16165] [remote 57.141.18.61:61608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4604958"] [unique_id "al4bcZuybMv3z_zMVBTGiwABykY"]
[Mon Jul 20 06:58:25.706806 2026] [security2:error] [pid 16093:tid 16185] [remote 188.166.241.141:43222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4bcZuybMv3z_zMVBTGkQAB0lo"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 06:58:25.827428 2026] [security2:error] [pid 16093:tid 16321] [client 197.186.66.42:63591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bcZuybMv3z_zMVBTGmgAAAfA"]
[Mon Jul 20 06:58:25.827573 2026] [security2:error] [pid 16093:tid 16321] [client 197.186.66.42:63591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bcZuybMv3z_zMVBTGmgAAAfA"]
[Mon Jul 20 06:58:25.928044 2026] [security2:error] [pid 15216:tid 15383] [client 13.215.47.127:58444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bcdtIy0gkFcVddGaEpQAAAS8"]
[Mon Jul 20 06:58:25.969263 2026] [security2:error] [pid 16093:tid 16231] [client 194.5.53.247:44369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/WordPressCore/index.php"] [unique_id "al4bcZuybMv3z_zMVBTGogAAAZY"]
[Mon Jul 20 06:58:26.263791 2026] [security2:error] [pid 15216:tid 15318] [remote 162.19.86.63:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bcttIy0gkFcVddGaEsgABemU"]
[Mon Jul 20 06:58:26.290851 2026] [security2:error] [pid 15216:tid 15375] [client 57.141.18.87:61656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bb9tIy0gkFcVddGaESwABJ0E"]
[Mon Jul 20 06:58:26.491742 2026] [security2:error] [pid 15216:tid 15316] [remote 162.19.86.63:55731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bcttIy0gkFcVddGaEwQABOWM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:26.539123 2026] [autoindex:error] [pid 16093:tid 16244] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/genesis/lib/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:58:26.797009 2026] [security2:error] [pid 16093:tid 16266] [client 14.225.17.146:60328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4bcpuybMv3z_zMVBTGuQAAAbk"], referer: https://north-woods-engineering.com/2022
[Mon Jul 20 06:58:26.933132 2026] [security2:error] [pid 16093:tid 16259] [client 13.229.223.11:41046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bcpuybMv3z_zMVBTGxgAAAbI"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:58:26.969795 2026] [autoindex:error] [pid 16093:tid 16180] [remote 8.229.41.77:56799] AH01276: Cannot serve directory /home2/hsdrromy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.hsd.rro.mybluehost.me
[Mon Jul 20 06:58:27.126604 2026] [security2:error] [pid 15216:tid 15464] [client 194.5.53.47:25195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/cgi-bin/autoload_classmap.php"] [unique_id "al4bc9tIy0gkFcVddGaE2AAAAYA"]
[Mon Jul 20 06:58:27.462523 2026] [security2:error] [pid 15216:tid 15346] [client 14.224.227.113:54831] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bc9tIy0gkFcVddGaE6wAAAQo"]
[Mon Jul 20 06:58:28.048258 2026] [security2:error] [pid 16093:tid 16196] [remote 57.141.18.5:56026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4bdJuybMv3z_zMVBTG8AAB6GU"]
[Mon Jul 20 06:58:28.099093 2026] [security2:error] [pid 15216:tid 15391] [client 104.234.53.58:56967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bdNtIy0gkFcVddGaE_wAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:28.216767 2026] [security2:error] [pid 15216:tid 15394] [client 77.110.127.138:60529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4bdNtIy0gkFcVddGaFAwAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:28.230696 2026] [security2:error] [pid 15216:tid 15414] [client 43.205.139.3:48930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bdNtIy0gkFcVddGaFBAAAAU4"]
[Mon Jul 20 06:58:28.230777 2026] [security2:error] [pid 15216:tid 15414] [client 43.205.139.3:48930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bdNtIy0gkFcVddGaFBAAAAU4"]
[Mon Jul 20 06:58:28.295858 2026] [security2:error] [pid 15216:tid 15419] [client 104.234.53.58:56967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bdNtIy0gkFcVddGaFBwAAAVM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:28.553345 2026] [security2:error] [pid 15216:tid 15402] [client 187.16.64.216:55961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bdNtIy0gkFcVddGaFEgAAAUI"]
[Mon Jul 20 06:58:28.553472 2026] [security2:error] [pid 15216:tid 15402] [client 187.16.64.216:55961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bdNtIy0gkFcVddGaFEgAAAUI"]
[Mon Jul 20 06:58:28.936768 2026] [security2:error] [pid 15216:tid 15452] [client 194.5.53.225:60809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-links-opml.php"] [unique_id "al4bdNtIy0gkFcVddGaFIAAAAXQ"]
[Mon Jul 20 06:58:28.981288 2026] [security2:error] [pid 16093:tid 16328] [client 50.116.65.227:33220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bdJuybMv3z_zMVBTHFQAAAfc"]
[Mon Jul 20 06:58:28.991249 2026] [security2:error] [pid 15216:tid 15453] [client 50.116.65.227:33228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bdNtIy0gkFcVddGaFIwAAAXU"]
[Mon Jul 20 06:58:29.119877 2026] [security2:error] [pid 16093:tid 16305] [client 147.93.171.187:49863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-login.php"] [unique_id "al4bdZuybMv3z_zMVBTHGwAAAeA"], referer: binance.com
[Mon Jul 20 06:58:29.314444 2026] [security2:error] [pid 16093:tid 16313] [client 194.5.53.239:21867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/user/network.php"] [unique_id "al4bdZuybMv3z_zMVBTHIAAAAeg"]
[Mon Jul 20 06:58:29.512024 2026] [security2:error] [pid 15216:tid 15398] [client 103.245.194.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4bddtIy0gkFcVddGaFLAABPh0"]
[Mon Jul 20 06:58:29.683854 2026] [security2:error] [pid 16093:tid 16332] [client 194.5.53.228:28899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/atomlib.php"] [unique_id "al4bdZuybMv3z_zMVBTHKwAAAfs"]
[Mon Jul 20 06:58:29.763550 2026] [autoindex:error] [pid 15216:tid 15219] [remote 35.185.95.129:64834] AH01276: Cannot serve directory /home2/fjyyvsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.fjy.yvs.mybluehost.me
[Mon Jul 20 06:58:29.786986 2026] [security2:error] [pid 15216:tid 15450] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bddtIy0gkFcVddGaFPAAAAXI"]
[Mon Jul 20 06:58:29.941270 2026] [security2:error] [pid 15216:tid 15413] [client 14.225.17.146:49613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4bddtIy0gkFcVddGaFQgAAAU0"], referer: http://daseighty.net/2022
[Mon Jul 20 06:58:30.004803 2026] [ssl:error] [pid 16093:tid 16267] [client 104.48.69.105:52062] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:58:30.065369 2026] [security2:error] [pid 16093:tid 16328] [client 194.5.53.210:26873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/js/jquery/bypass.php"] [unique_id "al4bdpuybMv3z_zMVBTHRQAAAfc"]
[Mon Jul 20 06:58:30.172158 2026] [core:alert] [pid 16093:tid 16269] [client 66.249.74.106:51577] /home3/princfv3/public_html/.htaccess: php_value takes two arguments, PHP Value
[Mon Jul 20 06:58:30.298666 2026] [security2:error] [pid 16093:tid 16263] [client 187.108.85.186:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bdpuybMv3z_zMVBTHVAAAAbY"]
[Mon Jul 20 06:58:30.298785 2026] [security2:error] [pid 16093:tid 16263] [client 187.108.85.186:63200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bdpuybMv3z_zMVBTHVAAAAbY"]
[Mon Jul 20 06:58:30.475339 2026] [security2:error] [pid 15216:tid 15422] [client 194.5.53.226:36807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 226.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/xl2023.php"] [unique_id "al4bdttIy0gkFcVddGaFUQAAAVY"]
[Mon Jul 20 06:58:30.491565 2026] [security2:error] [pid 16093:tid 16287] [client 14.225.17.146:49318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4bdpuybMv3z_zMVBTHVQAAAc4"], referer: http://phillipbloch.com/2022
[Mon Jul 20 06:58:30.494461 2026] [security2:error] [pid 16093:tid 16271] [client 45.3.54.124:39855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bdpuybMv3z_zMVBTHWgAAAb4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:30.639377 2026] [security2:error] [pid 15216:tid 15355] [client 117.222.139.248:53757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bdttIy0gkFcVddGaFWQAAARM"]
[Mon Jul 20 06:58:30.639509 2026] [security2:error] [pid 15216:tid 15355] [client 117.222.139.248:53757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bdttIy0gkFcVddGaFWQAAARM"]
[Mon Jul 20 06:58:30.719960 2026] [security2:error] [pid 16093:tid 16250] [client 104.234.53.93:44059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bdpuybMv3z_zMVBTHZAAAAak"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:30.793933 2026] [security2:error] [pid 15216:tid 15468] [client 103.144.65.217:49997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bdttIy0gkFcVddGaFXQAAAYQ"]
[Mon Jul 20 06:58:30.794043 2026] [security2:error] [pid 15216:tid 15468] [client 103.144.65.217:49997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bdttIy0gkFcVddGaFXQAAAYQ"]
[Mon Jul 20 06:58:30.819881 2026] [security2:error] [pid 16093:tid 16307] [client 14.225.17.146:63019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4bdpuybMv3z_zMVBTHVwAAAeI"]
[Mon Jul 20 06:58:30.820596 2026] [security2:error] [pid 15216:tid 15431] [client 194.5.53.205:62719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/certificates/admin.php"] [unique_id "al4bdttIy0gkFcVddGaFXwAAAV8"]
[Mon Jul 20 06:58:30.995803 2026] [security2:error] [pid 16093:tid 16327] [client 57.141.18.121:37914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bdJuybMv3z_zMVBTG_QAB9g8"]
[Mon Jul 20 06:58:31.047607 2026] [security2:error] [pid 15216:tid 15399] [client 104.207.51.192:61609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bd9tIy0gkFcVddGaFZQAAAT8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:31.490554 2026] [security2:error] [pid 16093:tid 16342] [client 194.5.53.244:36777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/images/media/dog.php"] [unique_id "al4bd5uybMv3z_zMVBTHcQAAAgU"]
[Mon Jul 20 06:58:31.588804 2026] [security2:error] [pid 16093:tid 16258] [client 14.225.17.146:49309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4bdpuybMv3z_zMVBTHWwAAAbE"], referer: http://ravmike.com/2022
[Mon Jul 20 06:58:31.608612 2026] [security2:error] [pid 15216:tid 15390] [client 104.207.53.111:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bd9tIy0gkFcVddGaFfwAAATY"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:31.830684 2026] [security2:error] [pid 16093:tid 16323] [client 183.82.98.154:55741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bd5uybMv3z_zMVBTHfgAAAfI"]
[Mon Jul 20 06:58:31.830843 2026] [security2:error] [pid 16093:tid 16323] [client 183.82.98.154:55741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bd5uybMv3z_zMVBTHfgAAAfI"]
[Mon Jul 20 06:58:31.844233 2026] [security2:error] [pid 15216:tid 15470] [client 57.141.18.107:35848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bddtIy0gkFcVddGaFMAABhks"]
[Mon Jul 20 06:58:31.879894 2026] [security2:error] [pid 16093:tid 16222] [remote 154.0.166.254:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bd5uybMv3z_zMVBTHgAABy38"]
[Mon Jul 20 06:58:31.948095 2026] [security2:error] [pid 15216:tid 15385] [client 194.5.53.55:32549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/xp.php"] [unique_id "al4bd9tIy0gkFcVddGaFhwAAATE"]
[Mon Jul 20 06:58:32.125223 2026] [security2:error] [pid 16093:tid 16316] [client 50.116.65.227:33262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4bd5uybMv3z_zMVBTHgwAAAes"]
[Mon Jul 20 06:58:32.304926 2026] [security2:error] [pid 16093:tid 16246] [client 50.116.65.227:33276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4beJuybMv3z_zMVBTHiwAAAaU"]
[Mon Jul 20 06:58:32.372451 2026] [security2:error] [pid 16093:tid 16115] [remote 154.0.166.254:55450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4beJuybMv3z_zMVBTHjwAB-RQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:32.557521 2026] [security2:error] [pid 16093:tid 16267] [client 194.5.53.201:40019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/SimplePie/applicationd.php"] [unique_id "al4beJuybMv3z_zMVBTHnAAAAbo"]
[Mon Jul 20 06:58:32.700045 2026] [security2:error] [pid 16093:tid 16238] [client 14.225.17.146:60322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4beJuybMv3z_zMVBTHngAAAZ0"], referer: https://ravmike.com/2022
[Mon Jul 20 06:58:32.749340 2026] [security2:error] [pid 15216:tid 15387] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4beNtIy0gkFcVddGaFmgAAATM"], referer: 1'"3000
[Mon Jul 20 06:58:32.831524 2026] [security2:error] [pid 16093:tid 16265] [client 119.249.100.175:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4beJuybMv3z_zMVBTHoAAAAbg"]
[Mon Jul 20 06:58:32.933191 2026] [security2:error] [pid 15216:tid 15449] [client 194.5.53.217:59125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/assets/index.php"] [unique_id "al4beNtIy0gkFcVddGaFsAAAAXE"]
[Mon Jul 20 06:58:33.100649 2026] [security2:error] [pid 16093:tid 16240] [client 14.225.17.146:60310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4beJuybMv3z_zMVBTHnwAAAZ8"], referer: http://onewingpictures.com/2022
[Mon Jul 20 06:58:33.330707 2026] [security2:error] [pid 15216:tid 15351] [client 194.5.53.221:52223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-links.php"] [unique_id "al4bedtIy0gkFcVddGaFugAAAQ8"]
[Mon Jul 20 06:58:33.760479 2026] [security2:error] [pid 16093:tid 16225] [client 194.5.53.230:35933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/as.php"] [unique_id "al4beZuybMv3z_zMVBTH2QAAAZA"]
[Mon Jul 20 06:58:33.774902 2026] [security2:error] [pid 16093:tid 16283] [client 217.142.18.172:9144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4beZuybMv3z_zMVBTH2gAAAco"]
[Mon Jul 20 06:58:33.778479 2026] [security2:error] [pid 16093:tid 16283] [client 217.142.18.172:9144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4beZuybMv3z_zMVBTH2gAAAco"]
[Mon Jul 20 06:58:33.842198 2026] [security2:error] [pid 16093:tid 16234] [client 3.77.67.4:13620] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4beZuybMv3z_zMVBTH1QAAAZk"], referer: https://mtlegnews.gov/
[Mon Jul 20 06:58:34.033387 2026] [security2:error] [pid 15216:tid 15389] [client 104.234.53.62:49233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bettIy0gkFcVddGaFzgAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:34.052591 2026] [security2:error] [pid 16093:tid 16305] [client 14.225.17.146:49482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4beZuybMv3z_zMVBTH3gAAAeA"]
[Mon Jul 20 06:58:34.088533 2026] [security2:error] [pid 16093:tid 16235] [client 57.141.18.24:38052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bd5uybMv3z_zMVBTHdgABmgU"]
[Mon Jul 20 06:58:34.366173 2026] [security2:error] [pid 16093:tid 16349] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bepuybMv3z_zMVBTH5gAAAgw"], referer: 1'"3000
[Mon Jul 20 06:58:34.428425 2026] [security2:error] [pid 16093:tid 16296] [client 14.225.17.146:51994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4beZuybMv3z_zMVBTHsgAAAdc"], referer: http://iagdevelopments.com/2022
[Mon Jul 20 06:58:34.503454 2026] [security2:error] [pid 15216:tid 15418] [client 122.183.32.225:10453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bettIy0gkFcVddGaF2QAAAVI"]
[Mon Jul 20 06:58:34.513053 2026] [security2:error] [pid 15216:tid 15418] [client 122.183.32.225:10453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bettIy0gkFcVddGaF2QAAAVI"]
[Mon Jul 20 06:58:34.672940 2026] [security2:error] [pid 16093:tid 16307] [client 77.110.127.138:60554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4bepuybMv3z_zMVBTIAAAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:35.031021 2026] [security2:error] [pid 16093:tid 16330] [client 14.225.17.146:51858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4bepuybMv3z_zMVBTIAQAAAfk"], referer: http://securingmemories.com/2022
[Mon Jul 20 06:58:35.238832 2026] [security2:error] [pid 16093:tid 16324] [client 194.5.53.214:44825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/css/index.php"] [unique_id "al4be5uybMv3z_zMVBTIGAAAAfM"]
[Mon Jul 20 06:58:35.316801 2026] [security2:error] [pid 16093:tid 16238] [client 103.238.106.162:42612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4be5uybMv3z_zMVBTIGQAAAZ0"]
[Mon Jul 20 06:58:35.316928 2026] [security2:error] [pid 16093:tid 16238] [client 103.238.106.162:42612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4be5uybMv3z_zMVBTIGQAAAZ0"]
[Mon Jul 20 06:58:35.347575 2026] [security2:error] [pid 15216:tid 15405] [client 117.247.108.24:33163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4be9tIy0gkFcVddGaF8QAAAUU"]
[Mon Jul 20 06:58:35.347670 2026] [security2:error] [pid 15216:tid 15405] [client 117.247.108.24:33163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4be9tIy0gkFcVddGaF8QAAAUU"]
[Mon Jul 20 06:58:35.570595 2026] [security2:error] [pid 16093:tid 16101] [remote 188.166.241.141:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4be5uybMv3z_zMVBTILgABvgY"]
[Mon Jul 20 06:58:35.621930 2026] [security2:error] [pid 16093:tid 16260] [client 194.5.53.238:60603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/ID3/index.php"] [unique_id "al4be5uybMv3z_zMVBTIMgAAAbM"]
[Mon Jul 20 06:58:35.673883 2026] [security2:error] [pid 15216:tid 15392] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bettIy0gkFcVddGaF6gABOBA"]
[Mon Jul 20 06:58:35.759418 2026] [security2:error] [pid 16093:tid 16287] [client 14.225.17.146:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4be5uybMv3z_zMVBTIOwAAAc4"], referer: https://iagdevelopments.com/2022
[Mon Jul 20 06:58:35.827207 2026] [security2:error] [pid 16093:tid 16174] [remote 162.19.86.63:56524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4be5uybMv3z_zMVBTIPQACDU8"]
[Mon Jul 20 06:58:35.988157 2026] [security2:error] [pid 15216:tid 15430] [client 194.5.53.221:59655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/pomo/admin.php"] [unique_id "al4be9tIy0gkFcVddGaGDAAAAV4"]
[Mon Jul 20 06:58:36.042621 2026] [security2:error] [pid 16093:tid 16208] [remote 188.166.241.141:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bfJuybMv3z_zMVBTIRQABn3E"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:36.057521 2026] [security2:error] [pid 16093:tid 16186] [remote 162.19.86.63:56524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4bfJuybMv3z_zMVBTIRgAB_Fs"], referer: https://mail.cathybuffini.com/wp-login.php
[Mon Jul 20 06:58:36.182952 2026] [security2:error] [pid 15216:tid 15380] [client 20.125.96.254:2515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.socalledsam.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4bfNtIy0gkFcVddGaGGQAAASw"]
[Mon Jul 20 06:58:36.183050 2026] [security2:error] [pid 15216:tid 15380] [client 20.125.96.254:2515] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.socalledsam.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4bfNtIy0gkFcVddGaGGQAAASw"]
[Mon Jul 20 06:58:36.246846 2026] [security2:error] [pid 16093:tid 16302] [client 14.224.227.113:58711] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bfJuybMv3z_zMVBTITAAAAd0"]
[Mon Jul 20 06:58:36.295525 2026] [security2:error] [pid 15216:tid 15410] [client 14.225.17.146:51854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4be9tIy0gkFcVddGaGAgAAAUo"], referer: http://backandneckpainrelieflaceychiropractor.com/2022
[Mon Jul 20 06:58:36.437043 2026] [ssl:error] [pid 16093:tid 16248] [client 104.48.69.105:52068] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:58:36.489159 2026] [security2:error] [pid 15216:tid 15439] [client 194.5.53.220:58437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/IXR/security.php"] [unique_id "al4bfNtIy0gkFcVddGaGHgAAAWc"]
[Mon Jul 20 06:58:36.921953 2026] [security2:error] [pid 15216:tid 15448] [client 104.234.53.84:39287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bfNtIy0gkFcVddGaGKwAAAXA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:36.927282 2026] [security2:error] [pid 16093:tid 16287] [client 194.5.53.195:34233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 195.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/phpadmin/as.php"] [unique_id "al4bfJuybMv3z_zMVBTIagAAAc4"]
[Mon Jul 20 06:58:37.180433 2026] [security2:error] [pid 15216:tid 15368] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bfNtIy0gkFcVddGaGHQABIAw"]
[Mon Jul 20 06:58:37.333011 2026] [ssl:error] [pid 16093:tid 16240] [client 104.48.69.105:52072] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 06:58:37.358976 2026] [security2:error] [pid 16093:tid 16324] [client 50.116.65.227:33362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bfZuybMv3z_zMVBTIggAAAfM"]
[Mon Jul 20 06:58:37.361468 2026] [security2:error] [pid 16093:tid 16281] [client 194.5.53.246:35693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/Requests/autoload_classmap.php"] [unique_id "al4bfZuybMv3z_zMVBTIhQAAAcg"]
[Mon Jul 20 06:58:37.369550 2026] [security2:error] [pid 16093:tid 16298] [client 50.116.65.227:33368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bfZuybMv3z_zMVBTIhgAAAdk"]
[Mon Jul 20 06:58:37.373305 2026] [security2:error] [pid 16093:tid 16162] [remote 130.51.180.8:41766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4bfZuybMv3z_zMVBTIhAAB0UM"]
[Mon Jul 20 06:58:37.447716 2026] [security2:error] [pid 16093:tid 16341] [client 158.173.166.181:36187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bfZuybMv3z_zMVBTIiwAAAgQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:58:37.531075 2026] [security2:error] [pid 16093:tid 16190] [remote 130.51.180.8:41766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4bfZuybMv3z_zMVBTIjwABnV8"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 06:58:37.601290 2026] [security2:error] [pid 16093:tid 16245] [client 14.225.17.146:60215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4be5uybMv3z_zMVBTIQAAAAaQ"], referer: http://ksands.co.uk/2022
[Mon Jul 20 06:58:37.929802 2026] [security2:error] [pid 16093:tid 16319] [client 197.186.66.42:64130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bfZuybMv3z_zMVBTIrgAAAe4"]
[Mon Jul 20 06:58:37.941902 2026] [security2:error] [pid 16093:tid 16319] [client 197.186.66.42:64130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bfZuybMv3z_zMVBTIrgAAAe4"]
[Mon Jul 20 06:58:37.959173 2026] [security2:error] [pid 16093:tid 16230] [client 146.103.115.115:62856] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.115.115" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bfZuybMv3z_zMVBTIsAAAAZU"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:58:37.959303 2026] [security2:error] [pid 16093:tid 16230] [client 146.103.115.115:62856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bfZuybMv3z_zMVBTIsAAAAZU"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:58:38.067397 2026] [security2:error] [pid 16093:tid 16324] [client 74.208.214.194:60924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4bfpuybMv3z_zMVBTIuAAAAfM"]
[Mon Jul 20 06:58:38.110198 2026] [security2:error] [pid 15216:tid 15402] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bfdtIy0gkFcVddGaGPAABQnU"]
[Mon Jul 20 06:58:38.151586 2026] [security2:error] [pid 16093:tid 16327] [client 186.22.57.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4bfZuybMv3z_zMVBTIsgAB9lo"]
[Mon Jul 20 06:58:38.333911 2026] [security2:error] [pid 16093:tid 16350] [client 104.234.53.90:21039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bfpuybMv3z_zMVBTIxQAAAg0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:38.389511 2026] [security2:error] [pid 16093:tid 16331] [client 63.176.132.15:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4bfZuybMv3z_zMVBTIlwAAAfo"]
[Mon Jul 20 06:58:38.420691 2026] [security2:error] [pid 16093:tid 16299] [client 63.176.132.15:10408] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/chuletas-fritas-puerto-rican-pan-fried-pork-chops/"] [unique_id "al4bfZuybMv3z_zMVBTIkwAAAdo"]
[Mon Jul 20 06:58:38.468218 2026] [security2:error] [pid 16093:tid 16280] [client 147.93.171.187:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-login.php"] [unique_id "al4bfpuybMv3z_zMVBTI0gAAAcc"], referer: binance.com
[Mon Jul 20 06:58:38.543158 2026] [security2:error] [pid 16093:tid 16311] [client 192.140.149.97:45560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bfpuybMv3z_zMVBTI1AAAAeY"]
[Mon Jul 20 06:58:38.543261 2026] [security2:error] [pid 16093:tid 16311] [client 192.140.149.97:45560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bfpuybMv3z_zMVBTI1AAAAeY"]
[Mon Jul 20 06:58:38.742232 2026] [security2:error] [pid 16093:tid 16321] [client 194.5.53.230:59019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4bfpuybMv3z_zMVBTI4QAAAfA"]
[Mon Jul 20 06:58:38.746952 2026] [security2:error] [pid 15216:tid 15457] [client 14.225.17.146:51946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4bfNtIy0gkFcVddGaGKgAAAXk"], referer: http://windowtx.com/2022
[Mon Jul 20 06:58:38.753940 2026] [security2:error] [pid 16093:tid 16301] [client 20.125.96.254:1645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.socalledsam.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4bfpuybMv3z_zMVBTI4gAAAdw"]
[Mon Jul 20 06:58:38.754023 2026] [security2:error] [pid 16093:tid 16301] [client 20.125.96.254:1645] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.socalledsam.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4bfpuybMv3z_zMVBTI4gAAAdw"]
[Mon Jul 20 06:58:38.835699 2026] [security2:error] [pid 16093:tid 16241] [client 104.234.53.90:21039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bfpuybMv3z_zMVBTI5wAAAaA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:39.020437 2026] [security2:error] [pid 16093:tid 16266] [client 65.111.23.161:21771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bfpuybMv3z_zMVBTI9AAAAbk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:58:39.132234 2026] [security2:error] [pid 16093:tid 16276] [client 57.141.18.2:42594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bfJuybMv3z_zMVBTIUQABwzM"]
[Mon Jul 20 06:58:39.459908 2026] [security2:error] [pid 15216:tid 15412] [client 45.3.55.54:18957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bf9tIy0gkFcVddGaGYwAAAUw"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:39.461428 2026] [security2:error] [pid 16093:tid 16244] [client 104.234.53.63:52109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bf5uybMv3z_zMVBTJEQAAAaM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:39.619311 2026] [security2:error] [pid 16093:tid 16334] [client 104.207.52.231:21781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bf5uybMv3z_zMVBTJHQAAAf0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:58:39.671911 2026] [security2:error] [pid 16093:tid 16257] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bfpuybMv3z_zMVBTI5gABsGs"]
[Mon Jul 20 06:58:39.671929 2026] [security2:error] [pid 16093:tid 16333] [client 14.225.17.146:51490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4bfpuybMv3z_zMVBTIxwAAAfw"], referer: http://chestermonty.com/2022
[Mon Jul 20 06:58:39.685313 2026] [security2:error] [pid 16093:tid 16303] [client 104.234.53.63:52109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bf5uybMv3z_zMVBTJIgAAAd4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:39.768309 2026] [security2:error] [pid 16093:tid 16335] [client 187.16.64.216:56497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bf5uybMv3z_zMVBTJKQAAAf4"]
[Mon Jul 20 06:58:39.768439 2026] [security2:error] [pid 16093:tid 16335] [client 187.16.64.216:56497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bf5uybMv3z_zMVBTJKQAAAf4"]
[Mon Jul 20 06:58:39.790393 2026] [security2:error] [pid 16093:tid 16276] [client 194.5.53.240:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-content/plugins/seoo/about.php"] [unique_id "al4bf5uybMv3z_zMVBTJKgAAAcM"]
[Mon Jul 20 06:58:39.900142 2026] [security2:error] [pid 16093:tid 16270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bf5uybMv3z_zMVBTJIwAAAb0"], referer: 1'"3000
[Mon Jul 20 06:58:40.314134 2026] [security2:error] [pid 15216:tid 15371] [client 65.111.12.119:57507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bgNtIy0gkFcVddGaGegAAASM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:40.642349 2026] [security2:error] [pid 16093:tid 16347] [client 14.225.17.146:65322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4bgJuybMv3z_zMVBTJUQAAAgo"], referer: https://chestermonty.com/2022
[Mon Jul 20 06:58:40.695720 2026] [security2:error] [pid 16093:tid 16292] [client 57.141.18.41:29720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bfZuybMv3z_zMVBTImwAB0wQ"]
[Mon Jul 20 06:58:40.924170 2026] [security2:error] [pid 15216:tid 15408] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bgNtIy0gkFcVddGaGeQABSEY"]
[Mon Jul 20 06:58:40.943470 2026] [security2:error] [pid 16093:tid 16258] [client 57.141.18.59:46030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bfZuybMv3z_zMVBTIqwABsTQ"]
[Mon Jul 20 06:58:41.062642 2026] [security2:error] [pid 15216:tid 15416] [client 187.108.85.186:63754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bgdtIy0gkFcVddGaGkgAAAVA"]
[Mon Jul 20 06:58:41.062772 2026] [security2:error] [pid 15216:tid 15416] [client 187.108.85.186:63754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bgdtIy0gkFcVddGaGkgAAAVA"]
[Mon Jul 20 06:58:41.086539 2026] [security2:error] [pid 15216:tid 15391] [client 194.5.53.207:29395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/fonts/about.php"] [unique_id "al4bgdtIy0gkFcVddGaGkwAAATc"]
[Mon Jul 20 06:58:41.175658 2026] [security2:error] [pid 15216:tid 15430] [client 117.222.139.248:54267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bgdtIy0gkFcVddGaGlwAAAV4"]
[Mon Jul 20 06:58:41.175779 2026] [security2:error] [pid 15216:tid 15430] [client 117.222.139.248:54267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bgdtIy0gkFcVddGaGlwAAAV4"]
[Mon Jul 20 06:58:41.289515 2026] [security2:error] [pid 16093:tid 16285] [client 103.144.65.217:50417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bgZuybMv3z_zMVBTJdQAAAcw"]
[Mon Jul 20 06:58:41.289609 2026] [security2:error] [pid 16093:tid 16285] [client 103.144.65.217:50417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bgZuybMv3z_zMVBTJdQAAAcw"]
[Mon Jul 20 06:58:41.684168 2026] [security2:error] [pid 16093:tid 16297] [client 195.63.31.206:45777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bgZuybMv3z_zMVBTJhgAAAdg"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:41.886014 2026] [security2:error] [pid 15216:tid 15349] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bgdtIy0gkFcVddGaGmwABDS0"]
[Mon Jul 20 06:58:42.132843 2026] [security2:error] [pid 16093:tid 16236] [client 14.251.3.155:54832] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bgpuybMv3z_zMVBTJogAAAZs"]
[Mon Jul 20 06:58:42.221528 2026] [security2:error] [pid 15216:tid 15423] [client 194.5.53.220:49473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/moon.php"] [unique_id "al4bgttIy0gkFcVddGaGtAAAAVc"]
[Mon Jul 20 06:58:42.490958 2026] [security2:error] [pid 16093:tid 16346] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bgpuybMv3z_zMVBTJnwAAAgk"], referer: 1'"3000
[Mon Jul 20 06:58:42.543636 2026] [security2:error] [pid 15216:tid 15473] [client 183.82.98.154:56339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bgttIy0gkFcVddGaGvQAAAYk"]
[Mon Jul 20 06:58:42.543740 2026] [security2:error] [pid 15216:tid 15473] [client 183.82.98.154:56339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bgttIy0gkFcVddGaGvQAAAYk"]
[Mon Jul 20 06:58:42.570413 2026] [security2:error] [pid 15216:tid 15464] [client 194.5.53.239:41269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/user/about.php"] [unique_id "al4bgttIy0gkFcVddGaGwAAAAYA"]
[Mon Jul 20 06:58:42.670636 2026] [security2:error] [pid 15216:tid 15346] [client 45.61.188.240:59425] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "idigress.agency"] [uri "/"] [unique_id "al4bgttIy0gkFcVddGaGwwAAAQo"]
[Mon Jul 20 06:58:42.902511 2026] [security2:error] [pid 15216:tid 15363] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bgttIy0gkFcVddGaGuAABG08"]
[Mon Jul 20 06:58:42.907328 2026] [security2:error] [pid 15216:tid 15424] [client 194.5.53.234:42727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al4bgttIy0gkFcVddGaGygAAAVg"]
[Mon Jul 20 06:58:42.952594 2026] [security2:error] [pid 15216:tid 15429] [client 45.61.188.240:59480] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "idigress.agency"] [uri "/"] [unique_id "al4bgttIy0gkFcVddGaGywAAAV0"]
[Mon Jul 20 06:58:43.096913 2026] [security2:error] [pid 15216:tid 15421] [client 113.160.132.26:17928] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 26.132.160.113.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bg9tIy0gkFcVddGaG0wAAAVU"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:58:43.097038 2026] [security2:error] [pid 15216:tid 15421] [client 113.160.132.26:17928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bg9tIy0gkFcVddGaG0wAAAVU"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 06:58:43.108916 2026] [security2:error] [pid 16093:tid 16315] [client 37.114.147.228:8961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4bgpuybMv3z_zMVBTJvAAAAeo"]
[Mon Jul 20 06:58:43.453441 2026] [security2:error] [pid 16093:tid 16253] [client 194.5.53.47:48661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/webadmin.php"] [unique_id "al4bg5uybMv3z_zMVBTJ2AAAAaw"]
[Mon Jul 20 06:58:43.820148 2026] [security2:error] [pid 16093:tid 16297] [client 194.5.53.240:55145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-includes/PHPMailer/about.php"] [unique_id "al4bg5uybMv3z_zMVBTJ8QAAAdg"]
[Mon Jul 20 06:58:43.896620 2026] [security2:error] [pid 15216:tid 15397] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bg9tIy0gkFcVddGaG1wABPWQ"]
[Mon Jul 20 06:58:44.256126 2026] [security2:error] [pid 15216:tid 15433] [client 217.142.18.172:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bhNtIy0gkFcVddGaG6wAAAWE"]
[Mon Jul 20 06:58:44.256247 2026] [security2:error] [pid 15216:tid 15433] [client 217.142.18.172:58006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bhNtIy0gkFcVddGaG6wAAAWE"]
[Mon Jul 20 06:58:44.305935 2026] [security2:error] [pid 16093:tid 16251] [client 194.5.53.232:37533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/about.php"] [unique_id "al4bhJuybMv3z_zMVBTKDgAAAao"]
[Mon Jul 20 06:58:44.580162 2026] [security2:error] [pid 15216:tid 15428] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4bhNtIy0gkFcVddGaG5wAAAVw"]
[Mon Jul 20 06:58:44.585482 2026] [access_compat:error] [pid 15216:tid 15455] [client 122.51.236.174:37546] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/
[Mon Jul 20 06:58:44.698847 2026] [security2:error] [pid 16093:tid 16303] [client 194.5.53.41:47063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/xl2023.php"] [unique_id "al4bhJuybMv3z_zMVBTKHgAAAd4"]
[Mon Jul 20 06:58:44.853658 2026] [security2:error] [pid 15216:tid 15349] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bhNtIy0gkFcVddGaG6AABDTI"]
[Mon Jul 20 06:58:45.130778 2026] [security2:error] [pid 16093:tid 16290] [client 194.5.53.211:47227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/go.php"] [unique_id "al4bhZuybMv3z_zMVBTKLQAAAdE"]
[Mon Jul 20 06:58:45.149608 2026] [security2:error] [pid 16093:tid 16257] [client 122.183.32.225:32227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bhZuybMv3z_zMVBTKMQAAAbA"]
[Mon Jul 20 06:58:45.149686 2026] [security2:error] [pid 16093:tid 16257] [client 122.183.32.225:32227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bhZuybMv3z_zMVBTKMQAAAbA"]
[Mon Jul 20 06:58:45.689377 2026] [security2:error] [pid 15216:tid 15422] [client 57.141.18.3:46332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bgttIy0gkFcVddGaGuQABVi4"]
[Mon Jul 20 06:58:45.869430 2026] [security2:error] [pid 16093:tid 16251] [client 103.238.106.162:42587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bhZuybMv3z_zMVBTKagAAAao"]
[Mon Jul 20 06:58:45.869561 2026] [security2:error] [pid 16093:tid 16251] [client 103.238.106.162:42587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bhZuybMv3z_zMVBTKagAAAao"]
[Mon Jul 20 06:58:45.924064 2026] [security2:error] [pid 16093:tid 16319] [client 117.247.108.24:32911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bhZuybMv3z_zMVBTKbQAAAe4"]
[Mon Jul 20 06:58:45.924736 2026] [security2:error] [pid 16093:tid 16319] [client 117.247.108.24:32911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bhZuybMv3z_zMVBTKbQAAAe4"]
[Mon Jul 20 06:58:45.938451 2026] [security2:error] [pid 16093:tid 16277] [client 77.110.127.138:60604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4bhZuybMv3z_zMVBTKbwAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:46.107411 2026] [security2:error] [pid 15216:tid 15467] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bhdtIy0gkFcVddGaHBQABgz4"]
[Mon Jul 20 06:58:46.192104 2026] [security2:error] [pid 15216:tid 15391] [client 194.5.53.246:42027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.53.5.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/xleet.php"] [unique_id "al4bhttIy0gkFcVddGaHDwAAATc"]
[Mon Jul 20 06:58:46.960819 2026] [security2:error] [pid 15216:tid 15470] [client 45.205.1.223:43610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4bhttIy0gkFcVddGaHLgAAAYY"]
[Mon Jul 20 06:58:47.227618 2026] [security2:error] [pid 15216:tid 15373] [client 182.8.226.25:24366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "apolloinfrastructureholdings.com"] [uri "/wp-json/batch/v1"] [unique_id "al4bh9tIy0gkFcVddGaHTAAAASU"]
[Mon Jul 20 06:58:47.232539 2026] [security2:error] [pid 15216:tid 15450] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bhttIy0gkFcVddGaHIwABciA"]
[Mon Jul 20 06:58:47.524438 2026] [security2:error] [pid 15216:tid 15416] [client 114.119.154.229:63679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "timespans.org"] [uri "/wp-sitemap-taxonomies-season-1.xml"] [unique_id "al4bh9tIy0gkFcVddGaHZgAAAVA"], referer: https://timespans.org/wp-sitemap-taxonomies-season-1.xml
[Mon Jul 20 06:58:47.711538 2026] [security2:error] [pid 16093:tid 16177] [remote 57.141.18.19:59266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bhJuybMv3z_zMVBTKAAABmVI"]
[Mon Jul 20 06:58:47.856119 2026] [security2:error] [pid 15216:tid 15348] [client 45.205.1.223:45754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4bh9tIy0gkFcVddGaHegAAAQw"]
[Mon Jul 20 06:58:47.993993 2026] [security2:error] [pid 15216:tid 15471] [client 82.102.18.116:49760] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4bh9tIy0gkFcVddGaHhAAAAYc"]
[Mon Jul 20 06:58:48.223814 2026] [security2:error] [pid 15216:tid 15353] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bh9tIy0gkFcVddGaHbwABETw"]
[Mon Jul 20 06:58:48.303481 2026] [security2:error] [pid 15216:tid 15382] [client 182.8.226.25:23675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "apolloinfrastructureholdings.com"] [uri "/"] [unique_id "al4biNtIy0gkFcVddGaHmAAAAS4"]
[Mon Jul 20 06:58:48.337703 2026] [security2:error] [pid 15216:tid 15435] [client 82.102.18.116:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.prontomc.co.uk"] [uri "/xmlrpc.php"] [unique_id "al4biNtIy0gkFcVddGaHmQAAAWM"]
[Mon Jul 20 06:58:48.649069 2026] [security2:error] [pid 15216:tid 15446] [client 82.102.18.116:45968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4biNtIy0gkFcVddGaHtwAAAW4"]
[Mon Jul 20 06:58:48.695634 2026] [security2:error] [pid 15216:tid 15434] [client 57.141.18.83:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bhdtIy0gkFcVddGaHAAABYmg"]
[Mon Jul 20 06:58:48.962981 2026] [security2:error] [pid 15216:tid 15346] [client 82.102.18.116:45974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4biNtIy0gkFcVddGaHwgAAAQo"]
[Mon Jul 20 06:58:49.144239 2026] [security2:error] [pid 15216:tid 15425] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4biNtIy0gkFcVddGaHpAABWQU"]
[Mon Jul 20 06:58:49.198803 2026] [security2:error] [pid 15216:tid 15404] [client 216.180.246.125:41730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4bidtIy0gkFcVddGaH1wAAAUQ"]
[Mon Jul 20 06:58:49.205699 2026] [security2:error] [pid 15216:tid 15361] [client 104.207.50.217:20147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bidtIy0gkFcVddGaH2gAAARk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:58:49.229375 2026] [security2:error] [pid 15216:tid 15419] [client 182.8.226.25:23636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "apolloinfrastructureholdings.com"] [uri "/wp-json/batch/v1"] [unique_id "al4bidtIy0gkFcVddGaH3QAAAVM"]
[Mon Jul 20 06:58:49.275294 2026] [security2:error] [pid 15216:tid 15380] [client 82.102.18.116:45986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4bidtIy0gkFcVddGaH4wAAASw"]
[Mon Jul 20 06:58:49.317514 2026] [security2:error] [pid 15216:tid 15440] [client 192.140.149.97:45460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bidtIy0gkFcVddGaH5QAAAWg"]
[Mon Jul 20 06:58:49.317624 2026] [security2:error] [pid 15216:tid 15440] [client 192.140.149.97:45460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bidtIy0gkFcVddGaH5QAAAWg"]
[Mon Jul 20 06:58:49.371389 2026] [security2:error] [pid 15216:tid 15343] [remote 162.19.86.63:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4bidtIy0gkFcVddGaH6gABbH4"]
[Mon Jul 20 06:58:49.618326 2026] [security2:error] [pid 15216:tid 15455] [client 82.102.18.116:45992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4bidtIy0gkFcVddGaH_QAAAXc"]
[Mon Jul 20 06:58:49.629204 2026] [security2:error] [pid 15216:tid 15234] [remote 162.19.86.63:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4bidtIy0gkFcVddGaIAAABRRE"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 06:58:49.767607 2026] [security2:error] [pid 15216:tid 15407] [client 45.3.54.11:54209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bidtIy0gkFcVddGaIBQAAAUc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:58:49.936842 2026] [security2:error] [pid 15216:tid 15453] [client 82.102.18.116:45996] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4bidtIy0gkFcVddGaIFAAAAXU"]
[Mon Jul 20 06:58:50.060581 2026] [security2:error] [pid 15216:tid 15472] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bidtIy0gkFcVddGaH7wABiFM"]
[Mon Jul 20 06:58:50.075058 2026] [security2:error] [pid 15216:tid 15419] [client 77.110.127.138:60617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phplPuvtk2t'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4bittIy0gkFcVddGaIGgAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:50.210968 2026] [security2:error] [pid 15216:tid 15449] [client 216.180.246.125:10698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4bittIy0gkFcVddGaIJQAAAXE"]
[Mon Jul 20 06:58:50.267057 2026] [security2:error] [pid 15216:tid 15428] [client 82.102.18.116:46012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4bittIy0gkFcVddGaILgAAAVw"]
[Mon Jul 20 06:58:50.585692 2026] [security2:error] [pid 15216:tid 15453] [client 82.102.18.116:44370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4bittIy0gkFcVddGaIRAAAAXU"]
[Mon Jul 20 06:58:50.734191 2026] [security2:error] [pid 15216:tid 15422] [client 57.141.18.67:33136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bh9tIy0gkFcVddGaHTgABViY"]
[Mon Jul 20 06:58:50.934009 2026] [security2:error] [pid 15216:tid 15420] [client 82.102.18.116:46034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4bittIy0gkFcVddGaIZQAAAVQ"]
[Mon Jul 20 06:58:51.050733 2026] [security2:error] [pid 15216:tid 15398] [client 197.186.66.42:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIawAAAT4"]
[Mon Jul 20 06:58:51.052308 2026] [security2:error] [pid 15216:tid 15398] [client 197.186.66.42:64664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIawAAAT4"]
[Mon Jul 20 06:58:51.091789 2026] [security2:error] [pid 15216:tid 15431] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bittIy0gkFcVddGaIOgABXzY"]
[Mon Jul 20 06:58:51.245027 2026] [security2:error] [pid 15216:tid 15348] [client 187.16.64.216:57061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIfwAAAQw"]
[Mon Jul 20 06:58:51.245129 2026] [security2:error] [pid 15216:tid 15348] [client 187.16.64.216:57061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIfwAAAQw"]
[Mon Jul 20 06:58:51.246135 2026] [security2:error] [pid 15216:tid 15349] [client 82.102.18.116:47326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4bi9tIy0gkFcVddGaIgAAAAQ0"]
[Mon Jul 20 06:58:51.508102 2026] [security2:error] [pid 15216:tid 15460] [client 104.234.53.94:37235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bi9tIy0gkFcVddGaIjQAAAXw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:51.522340 2026] [security2:error] [pid 15216:tid 15391] [client 187.108.85.186:64514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.85.108.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIjwAAATc"]
[Mon Jul 20 06:58:51.522416 2026] [security2:error] [pid 15216:tid 15391] [client 187.108.85.186:64514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adirondackengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIjwAAATc"]
[Mon Jul 20 06:58:51.559502 2026] [security2:error] [pid 15216:tid 15389] [client 82.102.18.116:46050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4bi9tIy0gkFcVddGaIkwAAATU"]
[Mon Jul 20 06:58:51.746516 2026] [security2:error] [pid 15216:tid 15393] [client 117.222.139.248:54784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIpQAAATk"]
[Mon Jul 20 06:58:51.746608 2026] [security2:error] [pid 15216:tid 15393] [client 117.222.139.248:54784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bi9tIy0gkFcVddGaIpQAAATk"]
[Mon Jul 20 06:58:51.845794 2026] [security2:error] [pid 15216:tid 15413] [client 57.141.18.66:60250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4biNtIy0gkFcVddGaHmwABTUU"]
[Mon Jul 20 06:58:51.876413 2026] [security2:error] [pid 15216:tid 15380] [client 82.102.18.116:46058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4bi9tIy0gkFcVddGaIsgAAASw"]
[Mon Jul 20 06:58:51.994912 2026] [security2:error] [pid 15216:tid 15453] [client 66.249.73.231:42490] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "thecreole.com"] [uri "/robots.txt"] [unique_id "al4bi9tIy0gkFcVddGaItgAAAXU"]
[Mon Jul 20 06:58:52.022590 2026] [security2:error] [pid 15216:tid 15386] [client 20.125.96.254:4282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.socalledsam.com"] [uri "/wp.php"] [unique_id "al4bjNtIy0gkFcVddGaIuQAAATI"]
[Mon Jul 20 06:58:52.022670 2026] [security2:error] [pid 15216:tid 15386] [client 20.125.96.254:4282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.socalledsam.com"] [uri "/wp.php"] [unique_id "al4bjNtIy0gkFcVddGaIuQAAATI"]
[Mon Jul 20 06:58:52.027630 2026] [security2:error] [pid 15216:tid 15428] [client 103.144.65.217:50834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bjNtIy0gkFcVddGaIuwAAAVw"]
[Mon Jul 20 06:58:52.028382 2026] [security2:error] [pid 15216:tid 15422] [client 66.249.73.67:64464] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "greenport-us.com"] [uri "/robots.txt"] [unique_id "al4bjNtIy0gkFcVddGaIugAAAVY"]
[Mon Jul 20 06:58:52.028399 2026] [security2:error] [pid 15216:tid 15428] [client 103.144.65.217:50834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bjNtIy0gkFcVddGaIuwAAAVw"]
[Mon Jul 20 06:58:52.042398 2026] [security2:error] [pid 15216:tid 15426] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bi9tIy0gkFcVddGaIjAABWhk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:58:52.203498 2026] [security2:error] [pid 15216:tid 15382] [client 82.102.18.116:56376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4bjNtIy0gkFcVddGaI2AAAAS4"]
[Mon Jul 20 06:58:52.296945 2026] [security2:error] [pid 15216:tid 15427] [client 57.141.18.74:20726] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4biNtIy0gkFcVddGaHugABWxY"]
[Mon Jul 20 06:58:52.568881 2026] [security2:error] [pid 15216:tid 15453] [client 82.102.18.116:61833] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4bjNtIy0gkFcVddGaI9AAAAXU"]
[Mon Jul 20 06:58:52.570301 2026] [security2:error] [pid 15216:tid 15389] [client 65.111.28.196:36743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bjNtIy0gkFcVddGaI8AAAATU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:58:52.846652 2026] [security2:error] [pid 15216:tid 15371] [client 47.128.18.31:47162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kromosenergy.com"] [uri "/robots.txt"] [unique_id "al4bjNtIy0gkFcVddGaJCAAAASM"]
[Mon Jul 20 06:58:52.856200 2026] [security2:error] [pid 15216:tid 15459] [client 66.249.65.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4bjNtIy0gkFcVddGaI5wAAAXs"]
[Mon Jul 20 06:58:52.888309 2026] [security2:error] [pid 15216:tid 15361] [client 82.102.18.116:46090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4bjNtIy0gkFcVddGaJDwAAARk"]
[Mon Jul 20 06:58:52.904858 2026] [security2:error] [pid 15216:tid 15432] [client 14.225.17.146:61581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4bi9tIy0gkFcVddGaIpgAAAWA"], referer: http://mourgroup.com/2025
[Mon Jul 20 06:58:53.060923 2026] [security2:error] [pid 15216:tid 15397] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bjNtIy0gkFcVddGaI4gABPTU"]
[Mon Jul 20 06:58:53.201864 2026] [security2:error] [pid 15216:tid 15357] [client 82.102.18.116:46104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.prontomc.co.uk"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4bjdtIy0gkFcVddGaJLAAAARU"]
[Mon Jul 20 06:58:53.332853 2026] [security2:error] [pid 15216:tid 15414] [client 14.225.17.146:65303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4bjdtIy0gkFcVddGaJKgAAAU4"], referer: http://lelandumc.org/2025
[Mon Jul 20 06:58:53.491308 2026] [security2:error] [pid 15216:tid 15471] [client 77.110.127.138:60628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpbwMl4Owe'%20OR%20956=(SELECT%20956%20FROM%20PG_SLEEP(15))--"] [unique_id "al4bjdtIy0gkFcVddGaJQAAAAYc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:53.502299 2026] [security2:error] [pid 15216:tid 15292] [remote 124.55.178.99:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bjdtIy0gkFcVddGaJQQABIEs"]
[Mon Jul 20 06:58:53.508812 2026] [security2:error] [pid 15216:tid 15456] [client 66.249.74.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4bjNtIy0gkFcVddGaJDAAAAXg"]
[Mon Jul 20 06:58:53.901092 2026] [security2:error] [pid 15216:tid 15217] [remote 124.55.178.99:49712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bjdtIy0gkFcVddGaJawABOwA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:53.967540 2026] [security2:error] [pid 15216:tid 15380] [client 98.159.234.160:25129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bjdtIy0gkFcVddGaJbwAAASw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:58:54.314347 2026] [security2:error] [pid 15216:tid 15425] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bjdtIy0gkFcVddGaJTgABWXI"]
[Mon Jul 20 06:58:54.706326 2026] [security2:error] [pid 15216:tid 15411] [client 104.234.53.59:65075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bjttIy0gkFcVddGaJsAAAAUs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:54.726010 2026] [security2:error] [pid 15216:tid 15318] [remote 114.119.143.59:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "primefocushrc.com"] [uri "/robots.txt"] [unique_id "al4bjttIy0gkFcVddGaJsQABW2U"], referer: https://primefocushrc.com/robots.txt
[Mon Jul 20 06:58:54.753377 2026] [security2:error] [pid 15216:tid 15439] [client 14.225.17.146:50614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4bjttIy0gkFcVddGaJowAAAWc"], referer: http://aandarealtygroup.com/2025
[Mon Jul 20 06:58:54.756105 2026] [security2:error] [pid 15216:tid 15359] [client 14.225.17.146:65035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4bjttIy0gkFcVddGaJngAAARc"], referer: http://ccsdifference.com/2025
[Mon Jul 20 06:58:54.876653 2026] [security2:error] [pid 15216:tid 15469] [client 217.142.18.172:60897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bjttIy0gkFcVddGaJvQAAAYU"]
[Mon Jul 20 06:58:54.879962 2026] [security2:error] [pid 15216:tid 15469] [client 217.142.18.172:60897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bjttIy0gkFcVddGaJvQAAAYU"]
[Mon Jul 20 06:58:55.304946 2026] [security2:error] [pid 15216:tid 15457] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bjttIy0gkFcVddGaJpgABeVU"]
[Mon Jul 20 06:58:55.334080 2026] [security2:error] [pid 15216:tid 15387] [client 66.249.73.231:42490] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "thecreole.com"] [uri "/ads.txt"] [unique_id "al4bj9tIy0gkFcVddGaJ3wAAATM"]
[Mon Jul 20 06:58:55.488468 2026] [security2:error] [pid 15216:tid 15451] [client 134.199.153.155:59148] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.familiaconsciente.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4bj9tIy0gkFcVddGaJ5AAAAXM"]
[Mon Jul 20 06:58:55.622473 2026] [security2:error] [pid 15216:tid 15453] [client 14.225.17.146:59462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4bj9tIy0gkFcVddGaJzwAAAXU"], referer: http://drewsasburyparkbeachhouse.com/2025
[Mon Jul 20 06:58:55.633419 2026] [security2:error] [pid 15216:tid 15403] [client 50.116.65.227:35468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bj9tIy0gkFcVddGaJ_wAAAUM"]
[Mon Jul 20 06:58:55.643481 2026] [security2:error] [pid 15216:tid 15447] [client 50.116.65.227:35482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bj9tIy0gkFcVddGaKAgAAAW8"]
[Mon Jul 20 06:58:55.867130 2026] [security2:error] [pid 15216:tid 15445] [client 122.183.32.225:10777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bj9tIy0gkFcVddGaKHAAAAW0"]
[Mon Jul 20 06:58:55.867255 2026] [security2:error] [pid 15216:tid 15445] [client 122.183.32.225:10777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bj9tIy0gkFcVddGaKHAAAAW0"]
[Mon Jul 20 06:58:56.091739 2026] [security2:error] [pid 15216:tid 15395] [client 74.7.227.179:49732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4bj9tIy0gkFcVddGaKIQABO2w"], referer: https://tejasenvironmental.com/p=1766
[Mon Jul 20 06:58:56.378599 2026] [security2:error] [pid 15216:tid 15454] [client 103.238.106.162:61031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bkNtIy0gkFcVddGaKPgAAAXY"]
[Mon Jul 20 06:58:56.378700 2026] [security2:error] [pid 15216:tid 15454] [client 103.238.106.162:61031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bkNtIy0gkFcVddGaKPgAAAXY"]
[Mon Jul 20 06:58:56.420880 2026] [security2:error] [pid 15216:tid 15425] [client 197.214.238.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4bj9tIy0gkFcVddGaKGQAAAVk"]
[Mon Jul 20 06:58:56.524149 2026] [security2:error] [pid 15216:tid 15473] [client 117.247.108.24:12221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bkNtIy0gkFcVddGaKQwAAAYk"]
[Mon Jul 20 06:58:56.524264 2026] [security2:error] [pid 15216:tid 15473] [client 117.247.108.24:12221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bkNtIy0gkFcVddGaKQwAAAYk"]
[Mon Jul 20 06:58:56.605044 2026] [security2:error] [pid 15216:tid 15408] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bj9tIy0gkFcVddGaKJAABSAw"]
[Mon Jul 20 06:58:56.996763 2026] [security2:error] [pid 15216:tid 15230] [remote 47.86.33.52:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4bkNtIy0gkFcVddGaKagABhA0"]
[Mon Jul 20 06:58:57.029692 2026] [security2:error] [pid 15216:tid 15357] [client 57.141.18.47:60728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gertoger.org"] [uri "/index.php"] [unique_id "al4bkNtIy0gkFcVddGaKUwABFRs"]
[Mon Jul 20 06:58:57.368639 2026] [security2:error] [pid 15216:tid 15450] [client 77.110.127.138:60642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpvSz786ef')%20OR%20271=(SELECT%20271%20FROM%20PG_SLEEP(15))--"] [unique_id "al4bkdtIy0gkFcVddGaKhAAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:58:57.560576 2026] [security2:error] [pid 15216:tid 15464] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bkNtIy0gkFcVddGaKYwABgFQ"]
[Mon Jul 20 06:58:57.624194 2026] [security2:error] [pid 15216:tid 15431] [client 14.251.3.155:54834] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bkdtIy0gkFcVddGaKlwAAAV8"]
[Mon Jul 20 06:58:57.982354 2026] [security2:error] [pid 15216:tid 15385] [client 14.225.17.146:50760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4bkdtIy0gkFcVddGaKpQAAATE"], referer: http://ghivs.com/2025
[Mon Jul 20 06:58:58.076297 2026] [security2:error] [pid 15216:tid 15350] [client 104.234.53.65:23823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4bkdtIy0gkFcVddGaKsAAAAQ4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:58.728070 2026] [security2:error] [pid 15216:tid 15402] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bkttIy0gkFcVddGaKuQABQm0"]
[Mon Jul 20 06:58:58.879786 2026] [security2:error] [pid 15216:tid 15399] [client 14.225.17.146:59459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4bkdtIy0gkFcVddGaKmwAAAT8"], referer: http://northbrookcpa.ca/2025
[Mon Jul 20 06:58:59.051935 2026] [security2:error] [pid 15216:tid 15464] [client 104.234.53.65:23823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaK_wAAAYA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:58:59.187630 2026] [security2:error] [pid 15216:tid 15255] [remote 103.75.185.95:34682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLEAABfSY"]
[Mon Jul 20 06:58:59.200690 2026] [security2:error] [pid 15216:tid 15431] [client 57.141.18.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bk9tIy0gkFcVddGaLAwAAAV8"]
[Mon Jul 20 06:58:59.216084 2026] [security2:error] [pid 15216:tid 15447] [client 66.249.65.97:61171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4bkttIy0gkFcVddGaK8AAAAW8"]
[Mon Jul 20 06:58:59.235066 2026] [security2:error] [pid 15216:tid 15352] [client 45.3.42.170:30031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLEwAAARA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:59.408836 2026] [security2:error] [pid 15216:tid 15396] [client 65.111.22.211:16615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLIAAAATw"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:58:59.686395 2026] [security2:error] [pid 15216:tid 15419] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bk9tIy0gkFcVddGaLAgABUwc"]
[Mon Jul 20 06:58:59.722167 2026] [security2:error] [pid 15216:tid 15247] [remote 103.75.185.95:34682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLPgABGh4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:58:59.791469 2026] [security2:error] [pid 15216:tid 15363] [client 45.3.54.163:23461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLPwAAARs"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:58:59.885240 2026] [security2:error] [pid 15216:tid 15252] [remote 91.142.222.105:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLRQABWSM"]
[Mon Jul 20 06:58:59.971100 2026] [security2:error] [pid 15216:tid 15346] [client 45.3.42.221:33863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bk9tIy0gkFcVddGaLTAAAAQo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:00.021193 2026] [security2:error] [pid 15216:tid 15434] [client 14.225.17.146:51004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4bk9tIy0gkFcVddGaLUAAAAWI"], referer: http://retzkolonglogistics.com/2025
[Mon Jul 20 06:59:00.097730 2026] [security2:error] [pid 15216:tid 15307] [remote 47.86.33.52:60796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4blNtIy0gkFcVddGaLWwABW1o"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 06:59:00.202716 2026] [security2:error] [pid 15216:tid 15305] [remote 91.142.222.105:50486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4blNtIy0gkFcVddGaLaAABR1g"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 06:59:00.346572 2026] [security2:error] [pid 15216:tid 15403] [client 104.207.53.161:42499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4blNtIy0gkFcVddGaLbwAAAUM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:00.624276 2026] [security2:error] [pid 15216:tid 15376] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bk9tIy0gkFcVddGaLUgABKFE"]
[Mon Jul 20 06:59:00.992829 2026] [security2:error] [pid 15216:tid 15413] [client 14.225.17.146:59517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4blNtIy0gkFcVddGaLlgAAAU0"], referer: http://superiorcopywriting.com/2025
[Mon Jul 20 06:59:01.176706 2026] [security2:error] [pid 15216:tid 15360] [client 43.134.15.174:41252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.15.134.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4bldtIy0gkFcVddGaLsgAAARg"]
[Mon Jul 20 06:59:01.209847 2026] [security2:error] [pid 15216:tid 15391] [client 14.225.17.146:54124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4bldtIy0gkFcVddGaLqgAAATc"], referer: http://sarahsnyder.net/2025
[Mon Jul 20 06:59:01.419312 2026] [security2:error] [pid 15216:tid 15439] [client 57.141.18.45:42126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bkdtIy0gkFcVddGaKngABZ0I"]
[Mon Jul 20 06:59:01.612801 2026] [security2:error] [pid 15216:tid 15353] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4blNtIy0gkFcVddGaLogABET0"]
[Mon Jul 20 06:59:01.899918 2026] [security2:error] [pid 15216:tid 15313] [remote 130.185.118.215:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4bldtIy0gkFcVddGaL7AABPGA"]
[Mon Jul 20 06:59:02.098533 2026] [security2:error] [pid 15216:tid 15417] [client 104.234.53.89:48937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4blttIy0gkFcVddGaMAAAAAVE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:02.199100 2026] [security2:error] [pid 15216:tid 15343] [remote 130.185.118.215:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4blttIy0gkFcVddGaMCgABTn4"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 06:59:02.209543 2026] [security2:error] [pid 15216:tid 15462] [client 117.222.139.248:55288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4blttIy0gkFcVddGaMDQAAAX4"]
[Mon Jul 20 06:59:02.209633 2026] [security2:error] [pid 15216:tid 15438] [client 14.225.17.146:54113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4blttIy0gkFcVddGaL-wAAAWY"], referer: https://sarahsnyder.net/2025
[Mon Jul 20 06:59:02.209658 2026] [security2:error] [pid 15216:tid 15462] [client 117.222.139.248:55288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4blttIy0gkFcVddGaMDQAAAX4"]
[Mon Jul 20 06:59:02.438553 2026] [security2:error] [pid 15216:tid 15408] [client 77.110.127.138:60660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpKmIdLq4j'))%20OR%20291=(SELECT%20291%20FROM%20PG_SLEEP(15))--"] [unique_id "al4blttIy0gkFcVddGaMIwAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:02.592587 2026] [security2:error] [pid 15216:tid 15416] [client 14.225.17.146:54163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4bldtIy0gkFcVddGaL9wAAAVA"], referer: http://idigress.studio/2025
[Mon Jul 20 06:59:02.613125 2026] [security2:error] [pid 15216:tid 15444] [client 187.16.64.216:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4blttIy0gkFcVddGaMMwAAAWw"]
[Mon Jul 20 06:59:02.613255 2026] [security2:error] [pid 15216:tid 15444] [client 187.16.64.216:57606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4blttIy0gkFcVddGaMMwAAAWw"]
[Mon Jul 20 06:59:02.630708 2026] [security2:error] [pid 15216:tid 15350] [client 103.144.65.217:51254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4blttIy0gkFcVddGaMNAAAAQ4"]
[Mon Jul 20 06:59:02.630890 2026] [security2:error] [pid 15216:tid 15350] [client 103.144.65.217:51254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4blttIy0gkFcVddGaMNAAAAQ4"]
[Mon Jul 20 06:59:02.631239 2026] [security2:error] [pid 15216:tid 15403] [client 14.225.17.146:50253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4blttIy0gkFcVddGaMHwAAAUM"], referer: http://maxenengineering.com/2025
[Mon Jul 20 06:59:02.723962 2026] [security2:error] [pid 15216:tid 15362] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4blttIy0gkFcVddGaL-gABGi0"]
[Mon Jul 20 06:59:02.785337 2026] [autoindex:error] [pid 15216:tid 15455] [client 194.5.53.243:35077] AH01276: Cannot serve directory /home3/pjrzkpmy/public_html/hilltopnurseryinc/.well-known/pki-validation/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:59:03.381929 2026] [security2:error] [pid 15216:tid 15437] [client 57.141.0.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4blttIy0gkFcVddGaMUAAAAWU"]
[Mon Jul 20 06:59:03.460117 2026] [security2:error] [pid 15216:tid 15464] [client 197.186.66.42:65188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bl9tIy0gkFcVddGaMgAAAAYA"]
[Mon Jul 20 06:59:03.460537 2026] [security2:error] [pid 15216:tid 15464] [client 197.186.66.42:65188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bl9tIy0gkFcVddGaMgAAAAYA"]
[Mon Jul 20 06:59:03.588193 2026] [security2:error] [pid 15216:tid 15429] [client 14.225.17.146:59820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4bl9tIy0gkFcVddGaMfwAAAV0"], referer: https://maxenengineering.com/2025
[Mon Jul 20 06:59:03.725370 2026] [security2:error] [pid 15216:tid 15363] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bl9tIy0gkFcVddGaMWAABGyc"]
[Mon Jul 20 06:59:03.758156 2026] [autoindex:error] [pid 15216:tid 15458] [client 173.239.198.157:58976] AH01276: Cannot serve directory /home3/soverex2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:59:04.142359 2026] [security2:error] [pid 15216:tid 15359] [client 183.82.98.154:57530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bmNtIy0gkFcVddGaMuQAAARc"]
[Mon Jul 20 06:59:04.142489 2026] [security2:error] [pid 15216:tid 15359] [client 183.82.98.154:57530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bmNtIy0gkFcVddGaMuQAAARc"]
[Mon Jul 20 06:59:04.391153 2026] [security2:error] [pid 15216:tid 15372] [client 14.225.17.146:59731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4bmNtIy0gkFcVddGaMywAAASQ"]
[Mon Jul 20 06:59:04.400045 2026] [security2:error] [pid 15216:tid 15396] [client 14.225.17.146:50159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4bl9tIy0gkFcVddGaMWgAAATw"]
[Mon Jul 20 06:59:04.614029 2026] [security2:error] [pid 15216:tid 15413] [client 104.234.53.69:43853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bmNtIy0gkFcVddGaM2QAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:04.691432 2026] [security2:error] [pid 15216:tid 15362] [client 14.225.17.146:54011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4bmNtIy0gkFcVddGaM2gAAARo"], referer: http://nurturemarple.co.uk/2025
[Mon Jul 20 06:59:04.724683 2026] [security2:error] [pid 15216:tid 15457] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bmNtIy0gkFcVddGaMtQABeRI"]
[Mon Jul 20 06:59:05.085959 2026] [security2:error] [pid 15216:tid 15365] [client 14.225.17.146:59852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4bmNtIy0gkFcVddGaM6gAAAR0"], referer: http://backandneckpainrelieflaceychiropractor.com/2025
[Mon Jul 20 06:59:05.130954 2026] [security2:error] [pid 15216:tid 15422] [client 57.141.18.31:44960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bldtIy0gkFcVddGaL5wABVlc"]
[Mon Jul 20 06:59:05.396227 2026] [security2:error] [pid 15216:tid 15442] [client 217.142.18.172:44026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bmdtIy0gkFcVddGaNKQAAAWo"]
[Mon Jul 20 06:59:05.396355 2026] [security2:error] [pid 15216:tid 15442] [client 217.142.18.172:44026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bmdtIy0gkFcVddGaNKQAAAWo"]
[Mon Jul 20 06:59:05.486644 2026] [security2:error] [pid 15216:tid 15270] [remote 192.241.143.148:34380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4bmdtIy0gkFcVddGaNLQABfzU"]
[Mon Jul 20 06:59:05.665435 2026] [security2:error] [pid 15216:tid 15258] [remote 192.241.143.148:34380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4bmdtIy0gkFcVddGaNQQABiCk"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:59:05.671563 2026] [security2:error] [pid 15216:tid 15373] [client 14.225.17.146:59824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4bmdtIy0gkFcVddGaNLwAAASU"], referer: https://nurturemarple.co.uk/2025
[Mon Jul 20 06:59:05.734516 2026] [security2:error] [pid 15216:tid 15355] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bmdtIy0gkFcVddGaNCAABEzw"]
[Mon Jul 20 06:59:05.763467 2026] [security2:error] [pid 15216:tid 15379] [client 14.225.17.146:53980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4bmdtIy0gkFcVddGaNNgAAASs"], referer: http://olearyplumbingllc.com/2025
[Mon Jul 20 06:59:05.887874 2026] [security2:error] [pid 15216:tid 15462] [client 20.125.96.254:2896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.socalledsam.com"] [uri "/new.php"] [unique_id "al4bmdtIy0gkFcVddGaNXQAAAX4"]
[Mon Jul 20 06:59:05.887967 2026] [security2:error] [pid 15216:tid 15462] [client 20.125.96.254:2896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.socalledsam.com"] [uri "/new.php"] [unique_id "al4bmdtIy0gkFcVddGaNXQAAAX4"]
[Mon Jul 20 06:59:06.071042 2026] [security2:error] [pid 15216:tid 15360] [client 57.141.18.35:31648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4blttIy0gkFcVddGaMJgABGFk"]
[Mon Jul 20 06:59:06.255586 2026] [security2:error] [pid 15216:tid 15419] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaNaAAAAVM"]
[Mon Jul 20 06:59:06.414991 2026] [security2:error] [pid 15216:tid 15467] [client 104.234.53.69:43853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bmttIy0gkFcVddGaNjwAAAYM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:06.423870 2026] [security2:error] [pid 15216:tid 15471] [client 122.183.32.225:20609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bmttIy0gkFcVddGaNkwAAAYc"]
[Mon Jul 20 06:59:06.423972 2026] [security2:error] [pid 15216:tid 15471] [client 122.183.32.225:20609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bmttIy0gkFcVddGaNkwAAAYc"]
[Mon Jul 20 06:59:06.452000 2026] [security2:error] [pid 15216:tid 15426] [client 114.119.131.185:22823] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bigwormfishing.com"] [uri "/robots.txt"] [unique_id "al4bmttIy0gkFcVddGaNlwAAAVo"], referer: https://www.bigwormfishing.com/robots.txt
[Mon Jul 20 06:59:06.814480 2026] [security2:error] [pid 15216:tid 15405] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaNswAAAUU"]
[Mon Jul 20 06:59:06.884204 2026] [security2:error] [pid 15216:tid 15353] [client 103.238.106.162:42994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bmttIy0gkFcVddGaNyQAAARE"]
[Mon Jul 20 06:59:06.884335 2026] [security2:error] [pid 15216:tid 15353] [client 103.238.106.162:42994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bmttIy0gkFcVddGaNyQAAARE"]
[Mon Jul 20 06:59:06.903989 2026] [security2:error] [pid 15216:tid 15471] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaNuAAAAYc"]
[Mon Jul 20 06:59:06.975264 2026] [security2:error] [pid 15216:tid 15462] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaNgQABfnM"]
[Mon Jul 20 06:59:07.030363 2026] [security2:error] [pid 15216:tid 15381] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaN0AAAAS0"]
[Mon Jul 20 06:59:07.054140 2026] [security2:error] [pid 15216:tid 15448] [client 14.225.17.146:50940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaNygAAAXA"], referer: http://cheesewithjam.com/2025
[Mon Jul 20 06:59:07.252919 2026] [security2:error] [pid 15216:tid 15389] [client 50.116.65.227:42808] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bm9tIy0gkFcVddGaN-QAAATU"]
[Mon Jul 20 06:59:07.262529 2026] [security2:error] [pid 15216:tid 15408] [client 50.116.65.227:42812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bm9tIy0gkFcVddGaN-wAAAUg"]
[Mon Jul 20 06:59:07.312687 2026] [security2:error] [pid 15216:tid 15399] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bm9tIy0gkFcVddGaN9AAAAT8"]
[Mon Jul 20 06:59:07.658472 2026] [security2:error] [pid 15216:tid 15346] [client 77.110.127.138:60701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4bm9tIy0gkFcVddGaOIAAAAQo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:07.713371 2026] [autoindex:error] [pid 15216:tid 15368] [client 167.86.117.252:56686] AH01276: Cannot serve directory /home4/ksandsco/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 06:59:07.715251 2026] [security2:error] [pid 15216:tid 15423] [client 57.141.18.49:38242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bmNtIy0gkFcVddGaMwQABVxA"]
[Mon Jul 20 06:59:07.794043 2026] [security2:error] [pid 15216:tid 15356] [client 14.225.17.146:60808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4bm9tIy0gkFcVddGaOLgAAARQ"], referer: http://katsklar.com/2025
[Mon Jul 20 06:59:07.851782 2026] [security2:error] [pid 15216:tid 15467] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bm9tIy0gkFcVddGaOMAAAAYM"]
[Mon Jul 20 06:59:07.948338 2026] [security2:error] [pid 15216:tid 15430] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bm9tIy0gkFcVddGaN_AABXkU"]
[Mon Jul 20 06:59:08.041121 2026] [security2:error] [pid 15216:tid 15366] [client 14.225.17.146:59912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4bm9tIy0gkFcVddGaOOwAAAR4"], referer: http://aljosour-alarabia.com/2025
[Mon Jul 20 06:59:08.058998 2026] [security2:error] [pid 15216:tid 15370] [client 20.125.96.254:5865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.socalledsam.com"] [uri "/wpls.php"] [unique_id "al4bnNtIy0gkFcVddGaORwAAASI"]
[Mon Jul 20 06:59:08.059088 2026] [security2:error] [pid 15216:tid 15370] [client 20.125.96.254:5865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.socalledsam.com"] [uri "/wpls.php"] [unique_id "al4bnNtIy0gkFcVddGaORwAAASI"]
[Mon Jul 20 06:59:08.186563 2026] [security2:error] [pid 15216:tid 15396] [client 117.247.108.24:12489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bnNtIy0gkFcVddGaOWwAAATw"]
[Mon Jul 20 06:59:08.186642 2026] [security2:error] [pid 15216:tid 15396] [client 117.247.108.24:12489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bnNtIy0gkFcVddGaOWwAAATw"]
[Mon Jul 20 06:59:08.295769 2026] [security2:error] [pid 15216:tid 15356] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bnNtIy0gkFcVddGaOWAAAARQ"]
[Mon Jul 20 06:59:08.750822 2026] [security2:error] [pid 15216:tid 15378] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bnNtIy0gkFcVddGaOggAAASo"]
[Mon Jul 20 06:59:08.786043 2026] [security2:error] [pid 15216:tid 15421] [client 77.110.127.138:60705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bnNtIy0gkFcVddGaOjAAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:08.786129 2026] [security2:error] [pid 15216:tid 15421] [client 77.110.127.138:60705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bnNtIy0gkFcVddGaOjAAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:08.892422 2026] [security2:error] [pid 15216:tid 15442] [client 14.225.17.146:59267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4bnNtIy0gkFcVddGaOiwAAAWo"], referer: http://alaraycreative.com/2025
[Mon Jul 20 06:59:08.902500 2026] [security2:error] [pid 15216:tid 15471] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bnNtIy0gkFcVddGaOYAABhwY"]
[Mon Jul 20 06:59:09.184879 2026] [security2:error] [pid 15216:tid 15465] [client 77.110.127.138:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4bndtIy0gkFcVddGaOuQAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:09.291477 2026] [security2:error] [pid 15216:tid 15458] [client 14.225.17.146:58907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4bndtIy0gkFcVddGaOwAAAAXo"], referer: http://friendlyspreadsheet.com/2025
[Mon Jul 20 06:59:09.304957 2026] [security2:error] [pid 15216:tid 15403] [client 57.141.18.0:61862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bmttIy0gkFcVddGaNhAABQz8"]
[Mon Jul 20 06:59:09.312802 2026] [security2:error] [pid 15216:tid 15431] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bndtIy0gkFcVddGaOvQAAAV8"]
[Mon Jul 20 06:59:09.578165 2026] [security2:error] [pid 15216:tid 15381] [client 104.207.53.13:56117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bndtIy0gkFcVddGaO3QAAAS0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:09.836713 2026] [security2:error] [pid 15216:tid 15392] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bndtIy0gkFcVddGaO6gAAATg"]
[Mon Jul 20 06:59:09.931613 2026] [security2:error] [pid 15216:tid 15379] [client 104.207.52.167:29281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bndtIy0gkFcVddGaO_AAAASs"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:10.027850 2026] [security2:error] [pid 15216:tid 15347] [client 14.225.17.146:59582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4bndtIy0gkFcVddGaO9QAAAQs"], referer: http://windowtx.com/2025
[Mon Jul 20 06:59:10.051935 2026] [security2:error] [pid 15216:tid 15422] [client 14.225.17.146:59224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4bndtIy0gkFcVddGaO-gAAAVY"], referer: http://fluidtemple.org/2025
[Mon Jul 20 06:59:10.094189 2026] [security2:error] [pid 15216:tid 15453] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bndtIy0gkFcVddGaO0gABdUI"]
[Mon Jul 20 06:59:10.170954 2026] [security2:error] [pid 15216:tid 15353] [client 65.111.22.185:24161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bnttIy0gkFcVddGaPEwAAARE"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:10.193084 2026] [security2:error] [pid 15216:tid 15395] [client 77.110.127.138:60713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4bnttIy0gkFcVddGaPGgAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:10.220787 2026] [security2:error] [pid 15216:tid 15437] [client 14.225.17.146:57108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPFAAAAWU"], referer: https://friendlyspreadsheet.com/2025
[Mon Jul 20 06:59:10.322352 2026] [security2:error] [pid 15216:tid 15415] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPHQAAAU8"]
[Mon Jul 20 06:59:10.523928 2026] [security2:error] [pid 15216:tid 15373] [client 104.207.51.148:50449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bnttIy0gkFcVddGaPOQAAASU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:10.672256 2026] [security2:error] [pid 15216:tid 15439] [client 57.141.18.100:20298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bm9tIy0gkFcVddGaONwABZ3k"]
[Mon Jul 20 06:59:10.746361 2026] [security2:error] [pid 15216:tid 15381] [client 45.3.54.201:61201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bnttIy0gkFcVddGaPXAAAAS0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:10.819830 2026] [security2:error] [pid 15216:tid 15377] [client 14.225.17.146:58466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPPwAAASk"], referer: http://younutrition.gr/2025
[Mon Jul 20 06:59:10.820659 2026] [security2:error] [pid 15216:tid 15390] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPWQAAATY"]
[Mon Jul 20 06:59:11.070802 2026] [security2:error] [pid 15216:tid 15440] [client 45.3.54.204:38127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bn9tIy0gkFcVddGaPdgAAAWg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:11.086137 2026] [security2:error] [pid 15216:tid 15435] [client 77.110.127.138:60723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPZgAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:11.101790 2026] [security2:error] [pid 15216:tid 15379] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPNAABKwU"]
[Mon Jul 20 06:59:11.111339 2026] [security2:error] [pid 15216:tid 15371] [client 57.141.18.29:22340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bnNtIy0gkFcVddGaOZAABIwo"]
[Mon Jul 20 06:59:11.173313 2026] [security2:error] [pid 15216:tid 15473] [client 66.249.93.197:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4bnttIy0gkFcVddGaPSQAAAYk"]
[Mon Jul 20 06:59:11.288374 2026] [security2:error] [pid 15216:tid 15367] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bn9tIy0gkFcVddGaPjQAAAR8"]
[Mon Jul 20 06:59:11.412398 2026] [security2:error] [pid 15216:tid 15428] [client 158.173.89.95:29947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bn9tIy0gkFcVddGaPqAAAAVw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:59:11.429269 2026] [security2:error] [pid 15216:tid 15364] [client 45.157.112.60:36721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bn9tIy0gkFcVddGaPrQAAARw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:59:11.529457 2026] [security2:error] [pid 15216:tid 15421] [client 194.5.53.243:35077] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "hilltopnurseryinc.com"] [uri "/wp-admin/user/"] [unique_id "al4bn9tIy0gkFcVddGaPtAAAAVU"]
[Mon Jul 20 06:59:11.643463 2026] [security2:error] [pid 15216:tid 15257] [remote 8.217.108.67:29762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4bn9tIy0gkFcVddGaPwAABQyg"]
[Mon Jul 20 06:59:11.773849 2026] [security2:error] [pid 15216:tid 15368] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bn9tIy0gkFcVddGaPxAAAASA"]
[Mon Jul 20 06:59:12.082127 2026] [security2:error] [pid 15216:tid 15462] [client 45.3.35.0:36647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.35.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4boNtIy0gkFcVddGaP7gAAAX4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:59:12.195605 2026] [security2:error] [pid 15216:tid 15447] [client 77.110.127.138:60737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bn9tIy0gkFcVddGaPzAAAAW8"]
[Mon Jul 20 06:59:12.233443 2026] [security2:error] [pid 15216:tid 15353] [client 14.251.3.155:54836] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4boNtIy0gkFcVddGaQDQAAARE"]
[Mon Jul 20 06:59:12.273356 2026] [security2:error] [pid 15216:tid 15423] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bn9tIy0gkFcVddGaPtwABVyY"]
[Mon Jul 20 06:59:12.285094 2026] [security2:error] [pid 15216:tid 15364] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4boNtIy0gkFcVddGaQBQAAARw"]
[Mon Jul 20 06:59:12.396036 2026] [proxy:error] [pid 15216:tid 15366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:59:12.396076 2026] [proxy_http:error] [pid 15216:tid 15366] [client 107.172.180.205:54512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:59:12.396482 2026] [proxy:error] [pid 15216:tid 15366] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:59:12.396505 2026] [proxy_http:error] [pid 15216:tid 15366] [client 107.172.180.205:54512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:59:12.804889 2026] [security2:error] [pid 15216:tid 15456] [client 117.222.139.248:55804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4boNtIy0gkFcVddGaQRAAAAXg"]
[Mon Jul 20 06:59:12.804986 2026] [security2:error] [pid 15216:tid 15456] [client 117.222.139.248:55804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4boNtIy0gkFcVddGaQRAAAAXg"]
[Mon Jul 20 06:59:12.819828 2026] [security2:error] [pid 15216:tid 15378] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4boNtIy0gkFcVddGaQPQAAASo"]
[Mon Jul 20 06:59:12.868640 2026] [security2:error] [pid 15216:tid 15385] [client 65.111.10.55:26331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.10.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4boNtIy0gkFcVddGaQSQAAATE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:59:13.141853 2026] [security2:error] [pid 15216:tid 15395] [client 103.144.65.217:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bodtIy0gkFcVddGaQcgAAATs"]
[Mon Jul 20 06:59:13.141960 2026] [security2:error] [pid 15216:tid 15395] [client 103.144.65.217:51670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bodtIy0gkFcVddGaQcgAAATs"]
[Mon Jul 20 06:59:13.186359 2026] [security2:error] [pid 15216:tid 15362] [client 14.225.17.146:57118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4bn9tIy0gkFcVddGaPfwAAARo"], referer: http://jvcmotorsports.com/2025
[Mon Jul 20 06:59:13.254538 2026] [security2:error] [pid 15216:tid 15458] [client 187.16.64.216:58131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bodtIy0gkFcVddGaQfgAAAXo"]
[Mon Jul 20 06:59:13.254657 2026] [security2:error] [pid 15216:tid 15458] [client 187.16.64.216:58131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bodtIy0gkFcVddGaQfgAAAXo"]
[Mon Jul 20 06:59:13.292870 2026] [security2:error] [pid 15216:tid 15371] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQdgAAASM"]
[Mon Jul 20 06:59:13.346462 2026] [security2:error] [pid 15216:tid 15448] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4boNtIy0gkFcVddGaQNgABcCQ"]
[Mon Jul 20 06:59:13.401030 2026] [security2:error] [pid 15216:tid 15468] [client 77.110.127.138:60742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQeQAAAYQ"]
[Mon Jul 20 06:59:13.448694 2026] [proxy:error] [pid 15216:tid 15455] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:59:13.448787 2026] [proxy_http:error] [pid 15216:tid 15455] [client 107.172.180.205:54536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:59:13.449658 2026] [proxy:error] [pid 15216:tid 15455] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 06:59:13.449698 2026] [proxy_http:error] [pid 15216:tid 15455] [client 107.172.180.205:54536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 06:59:13.663901 2026] [security2:error] [pid 15216:tid 15349] [client 65.111.8.78:63721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4bodtIy0gkFcVddGaQpQAAAQ0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 06:59:13.710974 2026] [security2:error] [pid 15216:tid 15415] [client 14.225.17.146:58826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4bn9tIy0gkFcVddGaPxQAAAU8"], referer: http://www.justinagrayman.com/2025
[Mon Jul 20 06:59:13.753052 2026] [security2:error] [pid 15216:tid 15365] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQogAAAR0"]
[Mon Jul 20 06:59:13.804355 2026] [security2:error] [pid 15216:tid 15377] [client 104.234.53.74:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bodtIy0gkFcVddGaQuAAAASk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:13.832489 2026] [security2:error] [pid 15216:tid 15327] [remote 8.217.108.67:29762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4bodtIy0gkFcVddGaQuwABL24"], referer: https://uninursity.com/wp-login.php
[Mon Jul 20 06:59:14.055481 2026] [security2:error] [pid 15216:tid 15441] [client 14.225.17.146:57601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQwgAAAWk"], referer: http://eduardsales.com/2025
[Mon Jul 20 06:59:14.273671 2026] [security2:error] [pid 15216:tid 15428] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bottIy0gkFcVddGaQ3gAAAVw"]
[Mon Jul 20 06:59:14.305179 2026] [security2:error] [pid 15216:tid 15394] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQpwABOjk"]
[Mon Jul 20 06:59:14.423312 2026] [security2:error] [pid 15216:tid 15468] [client 14.225.17.146:58445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4bottIy0gkFcVddGaQ5AAAAYQ"]
[Mon Jul 20 06:59:14.646663 2026] [security2:error] [pid 15216:tid 15418] [client 45.3.42.90:23127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bottIy0gkFcVddGaRAAAAAVI"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:14.803416 2026] [security2:error] [pid 15216:tid 15413] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bottIy0gkFcVddGaRBQAAAU0"]
[Mon Jul 20 06:59:15.075816 2026] [security2:error] [pid 15216:tid 15460] [client 14.225.17.146:57620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4bottIy0gkFcVddGaRIwAAAXw"], referer: http://nextlvlmarketingco.com/2025
[Mon Jul 20 06:59:15.255793 2026] [security2:error] [pid 15216:tid 15430] [client 183.82.98.154:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bo9tIy0gkFcVddGaRQQAAAV4"]
[Mon Jul 20 06:59:15.255949 2026] [security2:error] [pid 15216:tid 15430] [client 183.82.98.154:58136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bo9tIy0gkFcVddGaRQQAAAV4"]
[Mon Jul 20 06:59:15.275733 2026] [security2:error] [pid 15216:tid 15423] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bo9tIy0gkFcVddGaRNQAAAVc"]
[Mon Jul 20 06:59:15.356326 2026] [security2:error] [pid 15216:tid 15395] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bottIy0gkFcVddGaRCgABO3I"]
[Mon Jul 20 06:59:15.453841 2026] [security2:error] [pid 15216:tid 15352] [client 57.141.18.92:39776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQXAABEHQ"]
[Mon Jul 20 06:59:15.796192 2026] [security2:error] [pid 15216:tid 15427] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bo9tIy0gkFcVddGaRXgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:15.806049 2026] [security2:error] [pid 15216:tid 15444] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bo9tIy0gkFcVddGaRawAAAWw"]
[Mon Jul 20 06:59:15.840716 2026] [security2:error] [pid 15216:tid 15398] [client 20.125.96.254:2507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.96.125.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.socalledsam.com"] [uri "/mjq.php"] [unique_id "al4bo9tIy0gkFcVddGaRfAAAAT4"]
[Mon Jul 20 06:59:15.840854 2026] [security2:error] [pid 15216:tid 15398] [client 20.125.96.254:2507] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.socalledsam.com"] [uri "/mjq.php"] [unique_id "al4bo9tIy0gkFcVddGaRfAAAAT4"]
[Mon Jul 20 06:59:16.001414 2026] [security2:error] [pid 15216:tid 15439] [client 217.142.18.172:22042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bpNtIy0gkFcVddGaRhAAAAWc"]
[Mon Jul 20 06:59:16.008874 2026] [security2:error] [pid 15216:tid 15439] [client 217.142.18.172:22042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bpNtIy0gkFcVddGaRhAAAAWc"]
[Mon Jul 20 06:59:16.110607 2026] [security2:error] [pid 15216:tid 15353] [client 57.141.18.82:45426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bodtIy0gkFcVddGaQqQABEQg"]
[Mon Jul 20 06:59:16.297562 2026] [security2:error] [pid 15216:tid 15451] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bpNtIy0gkFcVddGaRkwAAAXM"]
[Mon Jul 20 06:59:16.414251 2026] [security2:error] [pid 15216:tid 15430] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bo9tIy0gkFcVddGaRbwABXiU"]
[Mon Jul 20 06:59:16.546006 2026] [security2:error] [pid 15216:tid 15437] [client 57.141.18.12:41828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bottIy0gkFcVddGaQ0gABZVY"]
[Mon Jul 20 06:59:16.604691 2026] [security2:error] [pid 15216:tid 15364] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4bo9tIy0gkFcVddGaRPAAAARw"]
[Mon Jul 20 06:59:16.688074 2026] [security2:error] [pid 15216:tid 15325] [remote 160.187.68.132:49388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bpNtIy0gkFcVddGaRxgABWWw"]
[Mon Jul 20 06:59:16.774823 2026] [security2:error] [pid 15216:tid 15365] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bpNtIy0gkFcVddGaRwQAAAR0"]
[Mon Jul 20 06:59:16.784101 2026] [security2:error] [pid 15216:tid 15444] [client 213.152.161.101:34600] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bpNtIy0gkFcVddGaRzAAAAWw"]
[Mon Jul 20 06:59:16.784179 2026] [security2:error] [pid 15216:tid 15444] [client 213.152.161.101:34600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bpNtIy0gkFcVddGaRzAAAAWw"]
[Mon Jul 20 06:59:17.146737 2026] [security2:error] [pid 15216:tid 15376] [client 197.186.66.42:49362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaR-QAAASg"]
[Mon Jul 20 06:59:17.146888 2026] [security2:error] [pid 15216:tid 15376] [client 197.186.66.42:49362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaR-QAAASg"]
[Mon Jul 20 06:59:17.185244 2026] [security2:error] [pid 15216:tid 15353] [client 14.225.17.146:57463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4bpNtIy0gkFcVddGaR3gAAARE"], referer: http://oldracelimited.com/2025
[Mon Jul 20 06:59:17.185873 2026] [security2:error] [pid 15216:tid 15229] [remote 130.185.118.215:60506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4bpdtIy0gkFcVddGaSBwABQww"]
[Mon Jul 20 06:59:17.205579 2026] [security2:error] [pid 15216:tid 15379] [client 18.184.179.151:28742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSCQAAASs"]
[Mon Jul 20 06:59:17.273834 2026] [security2:error] [pid 15216:tid 15422] [client 14.225.17.146:58549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4bpdtIy0gkFcVddGaR8AAAAVY"], referer: http://tntcatholic.com/2025
[Mon Jul 20 06:59:17.334110 2026] [security2:error] [pid 15216:tid 15434] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bpdtIy0gkFcVddGaSBQAAAWI"]
[Mon Jul 20 06:59:17.437057 2026] [security2:error] [pid 15216:tid 15270] [remote 130.185.118.215:60506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4bpdtIy0gkFcVddGaSHQABJTU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 06:59:17.462143 2026] [security2:error] [pid 15216:tid 15430] [client 103.238.106.162:42772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSIQAAAV4"]
[Mon Jul 20 06:59:17.462917 2026] [security2:error] [pid 15216:tid 15430] [client 103.238.106.162:42772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSIQAAAV4"]
[Mon Jul 20 06:59:17.487368 2026] [security2:error] [pid 15216:tid 15463] [client 122.183.32.225:28368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSJwAAAX8"]
[Mon Jul 20 06:59:17.487470 2026] [security2:error] [pid 15216:tid 15463] [client 122.183.32.225:28368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSJwAAAX8"]
[Mon Jul 20 06:59:17.547389 2026] [security2:error] [pid 15216:tid 15364] [client 50.116.65.227:39160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4bpdtIy0gkFcVddGaSGgAAARw"]
[Mon Jul 20 06:59:17.551910 2026] [security2:error] [pid 15216:tid 15243] [remote 160.187.68.132:49388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bpdtIy0gkFcVddGaSLwABExo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:59:17.764886 2026] [security2:error] [pid 15216:tid 15395] [client 50.116.65.227:39168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4bpdtIy0gkFcVddGaSMwAAATs"]
[Mon Jul 20 06:59:17.774916 2026] [security2:error] [pid 15216:tid 15358] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bpdtIy0gkFcVddGaSPwAAARY"]
[Mon Jul 20 06:59:17.827315 2026] [security2:error] [pid 15216:tid 15376] [client 63.176.132.15:22784] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4bpdtIy0gkFcVddGaSTgAAASg"]
[Mon Jul 20 06:59:17.832543 2026] [security2:error] [pid 15216:tid 15439] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bpdtIy0gkFcVddGaR7gABZx8"]
[Mon Jul 20 06:59:17.886225 2026] [security2:error] [pid 15216:tid 15389] [client 117.247.108.24:35264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSUwAAATU"]
[Mon Jul 20 06:59:17.886354 2026] [security2:error] [pid 15216:tid 15389] [client 117.247.108.24:35264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bpdtIy0gkFcVddGaSUwAAATU"]
[Mon Jul 20 06:59:17.909329 2026] [security2:error] [pid 15216:tid 15447] [client 14.225.17.146:61570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4bpNtIy0gkFcVddGaRsQAAAW8"], referer: http://colinkeyphotography.com/2025
[Mon Jul 20 06:59:18.269413 2026] [security2:error] [pid 15216:tid 15375] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bpttIy0gkFcVddGaSbAAAASc"]
[Mon Jul 20 06:59:18.460725 2026] [security2:error] [pid 15216:tid 15454] [client 63.176.132.15:40244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4bpttIy0gkFcVddGaSgwAAAXY"]
[Mon Jul 20 06:59:18.528610 2026] [security2:error] [pid 15216:tid 15410] [client 43.205.139.3:38962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bpttIy0gkFcVddGaShwAAAUo"]
[Mon Jul 20 06:59:18.545200 2026] [security2:error] [pid 15216:tid 15442] [client 77.110.127.138:60771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bpttIy0gkFcVddGaSiwAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:18.545274 2026] [security2:error] [pid 15216:tid 15442] [client 77.110.127.138:60771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bpttIy0gkFcVddGaSiwAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:18.638388 2026] [security2:error] [pid 15216:tid 15458] [client 74.208.214.194:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4bpttIy0gkFcVddGaSmQAAAXo"]
[Mon Jul 20 06:59:18.737190 2026] [security2:error] [pid 15216:tid 15428] [client 14.225.17.146:61435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4bpttIy0gkFcVddGaSkgAAAVw"], referer: http://mcg.homes/2025
[Mon Jul 20 06:59:18.795193 2026] [security2:error] [pid 15216:tid 15441] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bpttIy0gkFcVddGaSnAAAAWk"]
[Mon Jul 20 06:59:19.043210 2026] [security2:error] [pid 15216:tid 15439] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bpttIy0gkFcVddGaSegABZzw"]
[Mon Jul 20 06:59:19.114068 2026] [security2:error] [pid 15216:tid 15460] [client 3.67.192.83:33398] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4bp9tIy0gkFcVddGaSzQAAAXw"]
[Mon Jul 20 06:59:19.115988 2026] [security2:error] [pid 15216:tid 15400] [client 14.225.17.146:57456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4bpNtIy0gkFcVddGaR3AAAAUA"], referer: http://latiendadejorge.com.gt/2025
[Mon Jul 20 06:59:19.182588 2026] [security2:error] [pid 15216:tid 15381] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4bp9tIy0gkFcVddGaSywAAAS0"]
[Mon Jul 20 06:59:19.213004 2026] [security2:error] [pid 15216:tid 15431] [client 57.141.18.32:51004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bpNtIy0gkFcVddGaRswABXzc"]
[Mon Jul 20 06:59:19.278958 2026] [security2:error] [pid 15216:tid 15434] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bp9tIy0gkFcVddGaS0gAAAWI"]
[Mon Jul 20 06:59:19.721127 2026] [security2:error] [pid 15216:tid 15438] [client 3.67.192.83:33406] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4bp9tIy0gkFcVddGaTFQAAAWY"]
[Mon Jul 20 06:59:19.761213 2026] [security2:error] [pid 15216:tid 15464] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bp9tIy0gkFcVddGaTDQAAAYA"]
[Mon Jul 20 06:59:19.812330 2026] [security2:error] [pid 15216:tid 15312] [remote 124.55.178.99:43106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bp9tIy0gkFcVddGaTHwABD18"]
[Mon Jul 20 06:59:20.076441 2026] [security2:error] [pid 15216:tid 15349] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bp9tIy0gkFcVddGaS7gABDUo"]
[Mon Jul 20 06:59:20.211376 2026] [security2:error] [pid 15216:tid 15467] [client 13.233.207.33:18942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4bqNtIy0gkFcVddGaTRAAAAYM"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 06:59:20.234877 2026] [security2:error] [pid 15216:tid 15422] [client 50.116.65.227:53450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4bqNtIy0gkFcVddGaTRgAAAVY"]
[Mon Jul 20 06:59:20.246207 2026] [security2:error] [pid 15216:tid 15440] [client 50.116.65.227:53454] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4bqNtIy0gkFcVddGaTRwAAAWg"]
[Mon Jul 20 06:59:20.254845 2026] [security2:error] [pid 15216:tid 15404] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTPwAAAUQ"]
[Mon Jul 20 06:59:20.335182 2026] [security2:error] [pid 15216:tid 15437] [client 63.179.149.246:58428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4bqNtIy0gkFcVddGaTUgAAAWU"]
[Mon Jul 20 06:59:20.345363 2026] [security2:error] [pid 15216:tid 15251] [remote 124.55.178.99:43106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bqNtIy0gkFcVddGaTVgABMiI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:20.370095 2026] [fcgid:warn] [pid 15216:tid 15358] (70014)End of file found: [client 103.168.67.159:30248] mod_fcgid: can't get data from http client
[Mon Jul 20 06:59:20.377811 2026] [security2:error] [pid 15216:tid 15448] [client 65.111.23.140:12203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bqNtIy0gkFcVddGaTUwAAAXA"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:20.414401 2026] [security2:error] [pid 15216:tid 15347] [client 14.225.17.146:57608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTVwAAAQs"], referer: http://thefriendlyspreadsheet.com/2025
[Mon Jul 20 06:59:20.497342 2026] [security2:error] [pid 15216:tid 15446] [client 14.225.17.146:58677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTSwAAAW4"], referer: http://laceycaraccident.com/2025
[Mon Jul 20 06:59:20.510309 2026] [security2:error] [pid 15216:tid 15352] [client 104.234.53.81:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4bqNtIy0gkFcVddGaTYQAAARA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:20.857949 2026] [security2:error] [pid 15216:tid 15379] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTgQAAASs"]
[Mon Jul 20 06:59:20.975699 2026] [security2:error] [pid 15216:tid 15347] [client 52.59.238.198:36986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4bqNtIy0gkFcVddGaTlwAAAQs"]
[Mon Jul 20 06:59:20.991736 2026] [security2:error] [pid 15216:tid 15465] [client 147.93.171.187:53240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaThQAAAYE"], referer: binance.com
[Mon Jul 20 06:59:21.179162 2026] [security2:error] [pid 15216:tid 15281] [remote 51.158.61.221:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bqdtIy0gkFcVddGaTrwABNkA"]
[Mon Jul 20 06:59:21.203619 2026] [security2:error] [pid 15216:tid 15411] [client 151.236.178.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4bpttIy0gkFcVddGaSswAAAUs"]
[Mon Jul 20 06:59:21.229167 2026] [security2:error] [pid 15216:tid 15289] [remote 51.195.39.149:11987] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "peoplestrategies.us"] [uri "/"] [unique_id "al4bqdtIy0gkFcVddGaTugABQ0g"]
[Mon Jul 20 06:59:21.242674 2026] [security2:error] [pid 15216:tid 15457] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bqdtIy0gkFcVddGaTrQAAAXk"]
[Mon Jul 20 06:59:21.255254 2026] [security2:error] [pid 15216:tid 15407] [client 91.195.184.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4bp9tIy0gkFcVddGaSyAAAAUc"]
[Mon Jul 20 06:59:21.362051 2026] [security2:error] [pid 15216:tid 15243] [remote 51.158.61.221:60330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bqdtIy0gkFcVddGaTwwABURo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:59:21.509507 2026] [security2:error] [pid 15216:tid 15449] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTiQABcQY"]
[Mon Jul 20 06:59:21.557377 2026] [security2:error] [pid 15216:tid 15395] [client 14.225.17.146:55884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4bqdtIy0gkFcVddGaTxwAAATs"], referer: http://soloceos.com/2025
[Mon Jul 20 06:59:21.617278 2026] [security2:error] [pid 15216:tid 15442] [client 63.176.132.15:40246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4bqdtIy0gkFcVddGaT3QAAAWo"]
[Mon Jul 20 06:59:21.755441 2026] [security2:error] [pid 15216:tid 15404] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bqdtIy0gkFcVddGaT3wAAAUQ"]
[Mon Jul 20 06:59:21.982367 2026] [security2:error] [pid 15216:tid 15434] [client 14.225.17.146:61363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTagAAAWI"], referer: http://eframiproperties.com/2025
[Mon Jul 20 06:59:22.171772 2026] [security2:error] [pid 15216:tid 15412] [client 77.110.127.138:60804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bqttIy0gkFcVddGaUFQAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:22.171874 2026] [security2:error] [pid 15216:tid 15412] [client 77.110.127.138:60804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bqttIy0gkFcVddGaUFQAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:22.258193 2026] [security2:error] [pid 15216:tid 15377] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bqttIy0gkFcVddGaUEQAAASk"]
[Mon Jul 20 06:59:22.279195 2026] [security2:error] [pid 15216:tid 15466] [client 63.176.132.15:40248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "curlsnpearlsss.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4bqttIy0gkFcVddGaUIQAAAYI"]
[Mon Jul 20 06:59:22.384970 2026] [security2:error] [pid 15216:tid 15294] [remote 47.86.33.52:30274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4bqttIy0gkFcVddGaULQABUU0"]
[Mon Jul 20 06:59:22.401228 2026] [security2:error] [pid 15216:tid 15360] [client 77.110.127.138:60807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bqttIy0gkFcVddGaUMAAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:22.401375 2026] [security2:error] [pid 15216:tid 15360] [client 77.110.127.138:60807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bqttIy0gkFcVddGaUMAAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:22.542263 2026] [security2:error] [pid 15216:tid 15335] [remote 217.113.60.80:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4bqttIy0gkFcVddGaUOgABE3Y"]
[Mon Jul 20 06:59:22.576972 2026] [security2:error] [pid 15216:tid 15368] [client 57.141.18.35:59418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bqNtIy0gkFcVddGaTVAABIFY"]
[Mon Jul 20 06:59:22.589976 2026] [autoindex:error] [pid 15216:tid 15394] [client 194.5.53.207:45325] AH01276: Cannot serve directory /home3/pjrzkpmy/public_html/hilltopnurseryinc/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 06:59:22.669407 2026] [security2:error] [pid 15216:tid 15460] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bqttIy0gkFcVddGaT_wABfHk"]
[Mon Jul 20 06:59:22.740246 2026] [core:error] [pid 15216:tid 15381] [client 14.225.17.146:55906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2025
[Mon Jul 20 06:59:22.740265 2026] [core:error] [pid 15216:tid 15381] [client 14.225.17.146:55906] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2025
[Mon Jul 20 06:59:22.749620 2026] [security2:error] [pid 15216:tid 15465] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bqttIy0gkFcVddGaURwAAAYE"]
[Mon Jul 20 06:59:22.762901 2026] [security2:error] [pid 15216:tid 15241] [remote 217.113.60.80:50212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4bqttIy0gkFcVddGaUUAABQhg"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 06:59:23.182274 2026] [security2:error] [pid 15216:tid 15407] [client 158.173.166.181:54333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bq9tIy0gkFcVddGaUeAAAAUc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:59:23.248411 2026] [security2:error] [pid 15216:tid 15433] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bq9tIy0gkFcVddGaUcgAAAWE"]
[Mon Jul 20 06:59:23.440932 2026] [security2:error] [pid 15216:tid 15385] [client 117.222.139.248:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bq9tIy0gkFcVddGaUjgAAATE"]
[Mon Jul 20 06:59:23.441058 2026] [security2:error] [pid 15216:tid 15385] [client 117.222.139.248:56325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bq9tIy0gkFcVddGaUjgAAATE"]
[Mon Jul 20 06:59:23.480717 2026] [security2:error] [pid 15216:tid 15256] [remote 8.217.108.67:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4bq9tIy0gkFcVddGaUkQABDic"]
[Mon Jul 20 06:59:23.703481 2026] [security2:error] [pid 15216:tid 15423] [client 77.110.127.138:60812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bq9tIy0gkFcVddGaUrwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:23.703600 2026] [security2:error] [pid 15216:tid 15423] [client 77.110.127.138:60812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bq9tIy0gkFcVddGaUrwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:23.722337 2026] [security2:error] [pid 15216:tid 15376] [client 103.144.65.217:52090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bq9tIy0gkFcVddGaUswAAASg"]
[Mon Jul 20 06:59:23.722428 2026] [security2:error] [pid 15216:tid 15376] [client 103.144.65.217:52090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bq9tIy0gkFcVddGaUswAAASg"]
[Mon Jul 20 06:59:23.754902 2026] [security2:error] [pid 15216:tid 15435] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bq9tIy0gkFcVddGaUpQAAAWM"]
[Mon Jul 20 06:59:23.824510 2026] [security2:error] [pid 15216:tid 15427] [client 152.58.191.29:63196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bq9tIy0gkFcVddGaUvwAAAVs"]
[Mon Jul 20 06:59:23.828890 2026] [security2:error] [pid 15216:tid 15427] [client 152.58.191.29:63196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bq9tIy0gkFcVddGaUvwAAAVs"]
[Mon Jul 20 06:59:23.903919 2026] [security2:error] [pid 15216:tid 15268] [remote 47.86.33.52:30274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4bq9tIy0gkFcVddGaUzAABczM"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 06:59:24.004909 2026] [security2:error] [pid 15216:tid 15348] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bq9tIy0gkFcVddGaUgwABDGo"]
[Mon Jul 20 06:59:24.016658 2026] [security2:error] [pid 15216:tid 15436] [client 77.110.127.138:60818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brNtIy0gkFcVddGaU2gAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.016798 2026] [security2:error] [pid 15216:tid 15436] [client 77.110.127.138:60818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brNtIy0gkFcVddGaU2gAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.137491 2026] [security2:error] [pid 15216:tid 15426] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bq9tIy0gkFcVddGaUywAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.273294 2026] [security2:error] [pid 15216:tid 15371] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4brNtIy0gkFcVddGaU5QAAASM"]
[Mon Jul 20 06:59:24.295116 2026] [security2:error] [pid 15216:tid 15425] [client 14.225.17.146:61231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4bq9tIy0gkFcVddGaUggAAAVk"], referer: http://gearwaterproof.com/2025
[Mon Jul 20 06:59:24.364041 2026] [security2:error] [pid 15216:tid 15415] [client 57.141.18.42:35300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bqdtIy0gkFcVddGaT-AABT24"]
[Mon Jul 20 06:59:24.435335 2026] [security2:error] [pid 15216:tid 15404] [client 187.16.64.216:58661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4brNtIy0gkFcVddGaVCAAAAUQ"]
[Mon Jul 20 06:59:24.435499 2026] [security2:error] [pid 15216:tid 15404] [client 187.16.64.216:58661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4brNtIy0gkFcVddGaVCAAAAUQ"]
[Mon Jul 20 06:59:24.456979 2026] [security2:error] [pid 15216:tid 15449] [client 104.207.51.72:51787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4brNtIy0gkFcVddGaVCQAAAXE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:24.779503 2026] [security2:error] [pid 15216:tid 15380] [client 77.110.127.138:60823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brNtIy0gkFcVddGaVKwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.779585 2026] [security2:error] [pid 15216:tid 15380] [client 77.110.127.138:60823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brNtIy0gkFcVddGaVKwAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.788794 2026] [security2:error] [pid 15216:tid 15411] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4brNtIy0gkFcVddGaVGgAAAUs"]
[Mon Jul 20 06:59:24.873832 2026] [security2:error] [pid 15216:tid 15436] [client 77.110.127.138:60779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brNtIy0gkFcVddGaVNQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.873941 2026] [security2:error] [pid 15216:tid 15436] [client 77.110.127.138:60779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brNtIy0gkFcVddGaVNQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.902206 2026] [security2:error] [pid 15216:tid 15443] [client 185.238.231.248:24615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4brNtIy0gkFcVddGaU8AAAAWs"]
[Mon Jul 20 06:59:24.905030 2026] [security2:error] [pid 15216:tid 15434] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4brNtIy0gkFcVddGaVGwAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:24.923884 2026] [security2:error] [pid 15216:tid 15289] [remote 57.141.18.115:52318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3036711"] [unique_id "al4brNtIy0gkFcVddGaVPgABGkg"]
[Mon Jul 20 06:59:24.929896 2026] [security2:error] [pid 15216:tid 15467] [client 185.238.231.202:60477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4brNtIy0gkFcVddGaU8gAAAYM"]
[Mon Jul 20 06:59:25.027529 2026] [security2:error] [pid 15216:tid 15395] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4brNtIy0gkFcVddGaVAAABOyY"]
[Mon Jul 20 06:59:25.049375 2026] [security2:error] [pid 15216:tid 15355] [client 77.110.127.138:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brdtIy0gkFcVddGaVTgAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:25.049473 2026] [security2:error] [pid 15216:tid 15355] [client 77.110.127.138:60824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4brdtIy0gkFcVddGaVTgAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:25.272796 2026] [security2:error] [pid 15216:tid 15373] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4brdtIy0gkFcVddGaVWAAAASU"]
[Mon Jul 20 06:59:25.485638 2026] [security2:error] [pid 15216:tid 15391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4brdtIy0gkFcVddGaVZAAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:25.507419 2026] [security2:error] [pid 15216:tid 15386] [client 57.141.18.116:49110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bq9tIy0gkFcVddGaUfAABMg8"]
[Mon Jul 20 06:59:25.957655 2026] [security2:error] [pid 15216:tid 15301] [remote 100.42.189.89:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4brdtIy0gkFcVddGaVjwABHFQ"]
[Mon Jul 20 06:59:25.971770 2026] [security2:error] [pid 15216:tid 15426] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4brdtIy0gkFcVddGaVcQABWgY"]
[Mon Jul 20 06:59:26.024344 2026] [security2:error] [pid 15216:tid 15397] [client 183.82.98.154:58731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4brttIy0gkFcVddGaVmAAAAT0"]
[Mon Jul 20 06:59:26.024466 2026] [security2:error] [pid 15216:tid 15397] [client 183.82.98.154:58731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4brttIy0gkFcVddGaVmAAAAT0"]
[Mon Jul 20 06:59:26.265061 2026] [security2:error] [pid 15216:tid 15240] [remote 100.42.189.89:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4brttIy0gkFcVddGaVtAABdhc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:26.344842 2026] [security2:error] [pid 15216:tid 15384] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4brttIy0gkFcVddGaVsgAAATA"]
[Mon Jul 20 06:59:26.496529 2026] [security2:error] [pid 15216:tid 15391] [client 217.142.18.172:40852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4brttIy0gkFcVddGaV1gAAATc"]
[Mon Jul 20 06:59:26.508423 2026] [security2:error] [pid 15216:tid 15391] [client 217.142.18.172:40852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4brttIy0gkFcVddGaV1gAAATc"]
[Mon Jul 20 06:59:26.654115 2026] [core:error] [pid 15216:tid 15241] [remote 205.210.31.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:26.654141 2026] [core:error] [pid 15216:tid 15241] [remote 205.210.31.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:26.750260 2026] [security2:error] [pid 15216:tid 15332] [remote 182.77.62.24:41732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4brttIy0gkFcVddGaWAwABXXM"]
[Mon Jul 20 06:59:26.750477 2026] [security2:error] [pid 15216:tid 15429] [client 182.77.62.24:41732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4brttIy0gkFcVddGaWAwABXXM"]
[Mon Jul 20 06:59:26.756701 2026] [security2:error] [pid 15216:tid 15384] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4brttIy0gkFcVddGaV8AAAATA"]
[Mon Jul 20 06:59:26.790701 2026] [security2:error] [pid 15216:tid 15359] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4brttIy0gkFcVddGaV9gAAARc"]
[Mon Jul 20 06:59:26.935570 2026] [security2:error] [pid 15216:tid 15318] [remote 8.217.108.67:48084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4brttIy0gkFcVddGaWDwABSmU"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 06:59:26.965248 2026] [security2:error] [pid 15216:tid 15411] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4brttIy0gkFcVddGaVtwABS2M"]
[Mon Jul 20 06:59:27.238431 2026] [security2:error] [pid 15216:tid 15398] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4br9tIy0gkFcVddGaWJAAAAT4"]
[Mon Jul 20 06:59:27.354518 2026] [security2:error] [pid 15216:tid 15465] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4brttIy0gkFcVddGaV_gAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:27.545560 2026] [security2:error] [pid 15216:tid 15351] [client 173.239.224.22:33683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathyspeed.org"] [uri "/wp-login.php"] [unique_id "al4br9tIy0gkFcVddGaWRAAAAQ8"]
[Mon Jul 20 06:59:27.701866 2026] [security2:error] [pid 15216:tid 15424] [client 14.251.3.155:54839] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4br9tIy0gkFcVddGaWYAAAAVg"]
[Mon Jul 20 06:59:27.769228 2026] [security2:error] [pid 15216:tid 15440] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4br9tIy0gkFcVddGaWWAAAAWg"]
[Mon Jul 20 06:59:27.963891 2026] [security2:error] [pid 15216:tid 15404] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4br9tIy0gkFcVddGaWZwAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:27.984001 2026] [security2:error] [pid 15216:tid 15438] [client 103.238.106.162:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4br9tIy0gkFcVddGaWdgAAAWY"]
[Mon Jul 20 06:59:27.984115 2026] [security2:error] [pid 15216:tid 15438] [client 103.238.106.162:60949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4br9tIy0gkFcVddGaWdgAAAWY"]
[Mon Jul 20 06:59:28.010459 2026] [security2:error] [pid 15216:tid 15307] [remote 91.142.222.105:56554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4br9tIy0gkFcVddGaWegABQFo"]
[Mon Jul 20 06:59:28.018656 2026] [security2:error] [pid 15216:tid 15376] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4br9tIy0gkFcVddGaWNQABKCc"]
[Mon Jul 20 06:59:28.072434 2026] [security2:error] [pid 15216:tid 15407] [client 14.225.17.146:61412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4br9tIy0gkFcVddGaWFwAAAUc"], referer: http://adultdaycarereno.com/2025
[Mon Jul 20 06:59:28.139068 2026] [security2:error] [pid 15216:tid 15462] [client 14.225.17.146:53496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4br9tIy0gkFcVddGaWeQAAAX4"], referer: http://blaizeaccountingservices.com/2025
[Mon Jul 20 06:59:28.255989 2026] [security2:error] [pid 15216:tid 15355] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bsNtIy0gkFcVddGaWkgAAARM"]
[Mon Jul 20 06:59:28.496113 2026] [security2:error] [pid 15216:tid 15284] [remote 91.142.222.105:56554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bsNtIy0gkFcVddGaWsQABN0M"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:28.621543 2026] [security2:error] [pid 15216:tid 15440] [client 117.247.108.24:49512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bsNtIy0gkFcVddGaWvgAAAWg"]
[Mon Jul 20 06:59:28.621645 2026] [security2:error] [pid 15216:tid 15440] [client 117.247.108.24:49512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bsNtIy0gkFcVddGaWvgAAAWg"]
[Mon Jul 20 06:59:28.812907 2026] [security2:error] [pid 15216:tid 15319] [remote 8.217.108.67:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4bsNtIy0gkFcVddGaW0wABcGY"]
[Mon Jul 20 06:59:28.882764 2026] [security2:error] [pid 15216:tid 15362] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bsNtIy0gkFcVddGaW0AAAARo"]
[Mon Jul 20 06:59:28.900475 2026] [security2:error] [pid 15216:tid 15463] [client 57.141.18.42:46386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4brttIy0gkFcVddGaV2QABfwA"]
[Mon Jul 20 06:59:28.906611 2026] [security2:error] [pid 15216:tid 15436] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bsNtIy0gkFcVddGaWrQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:29.004384 2026] [security2:error] [pid 15216:tid 15405] [client 14.225.17.146:61165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4bsNtIy0gkFcVddGaW5AAAAUU"], referer: https://adultdaycarereno.com/2025
[Mon Jul 20 06:59:29.275473 2026] [security2:error] [pid 15216:tid 15461] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bsdtIy0gkFcVddGaW9wAAAX0"]
[Mon Jul 20 06:59:29.390983 2026] [security2:error] [pid 15216:tid 15441] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bsNtIy0gkFcVddGaWzQABaQw"]
[Mon Jul 20 06:59:29.468482 2026] [security2:error] [pid 15216:tid 15458] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bsdtIy0gkFcVddGaXCAAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:29.479089 2026] [security2:error] [pid 15216:tid 15280] [remote 34.74.242.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.origine.nz"] [uri "/robots.txt"] [unique_id "al4bsdtIy0gkFcVddGaXHAABLD8"]
[Mon Jul 20 06:59:29.479261 2026] [security2:error] [pid 15216:tid 15380] [client 34.74.242.206:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.origine.nz"] [uri "/robots.txt"] [unique_id "al4bsdtIy0gkFcVddGaXHAABLD8"]
[Mon Jul 20 06:59:29.660456 2026] [security2:error] [pid 15216:tid 15425] [client 77.110.127.138:60848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bsdtIy0gkFcVddGaXLgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:29.660607 2026] [security2:error] [pid 15216:tid 15425] [client 77.110.127.138:60848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bsdtIy0gkFcVddGaXLgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:29.709870 2026] [security2:error] [pid 15216:tid 15301] [remote 34.74.242.206:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.origine.nz"] [uri "/"] [unique_id "al4bsdtIy0gkFcVddGaXOAABJVQ"]
[Mon Jul 20 06:59:29.710028 2026] [security2:error] [pid 15216:tid 15373] [client 34.74.242.206:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.origine.nz"] [uri "/"] [unique_id "al4bsdtIy0gkFcVddGaXOAABJVQ"]
[Mon Jul 20 06:59:29.739390 2026] [security2:error] [pid 15216:tid 15462] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bsdtIy0gkFcVddGaXLAAAAX4"]
[Mon Jul 20 06:59:29.747883 2026] [security2:error] [pid 15216:tid 15435] [client 122.183.32.225:10732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bsdtIy0gkFcVddGaXQgAAAWM"]
[Mon Jul 20 06:59:29.748023 2026] [security2:error] [pid 15216:tid 15435] [client 122.183.32.225:10732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bsdtIy0gkFcVddGaXQgAAAWM"]
[Mon Jul 20 06:59:29.861692 2026] [security2:error] [pid 15216:tid 15464] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bsdtIy0gkFcVddGaXKwAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:29.950343 2026] [security2:error] [pid 15216:tid 15287] [remote 217.61.143.92:55898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4bsdtIy0gkFcVddGaXUQABVkY"]
[Mon Jul 20 06:59:29.966693 2026] [security2:error] [pid 15216:tid 15405] [client 66.249.74.169:61242] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "primecutpainting.com"] [uri "/robots.txt"] [unique_id "al4bsdtIy0gkFcVddGaXUwAAAUU"]
[Mon Jul 20 06:59:30.026230 2026] [security2:error] [pid 15216:tid 15240] [remote 8.217.108.67:48088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4bsttIy0gkFcVddGaXVQABHhc"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 06:59:30.200790 2026] [security2:error] [pid 15216:tid 15296] [remote 217.61.143.92:55898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4bsttIy0gkFcVddGaXYwABTE8"], referer: https://technicalseohouse.com/wp-login.php
[Mon Jul 20 06:59:30.247981 2026] [security2:error] [pid 15216:tid 15462] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bsttIy0gkFcVddGaXYAAAAX4"]
[Mon Jul 20 06:59:30.321487 2026] [core:error] [pid 15216:tid 15386] [client 14.225.17.146:53667] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:30.321517 2026] [core:error] [pid 15216:tid 15386] [client 14.225.17.146:53667] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:30.408884 2026] [security2:error] [pid 15216:tid 15378] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bsdtIy0gkFcVddGaXPAABKmg"]
[Mon Jul 20 06:59:30.412480 2026] [security2:error] [pid 15216:tid 15447] [client 34.84.236.5:4007] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.jennylouraya.com"] [uri "/wp-content/uploads/2015/07/Screen-Shot-2015-07-15-at-12.43.25-AM.png"] [unique_id "al4bsttIy0gkFcVddGaXgAAAAW8"]
[Mon Jul 20 06:59:30.487619 2026] [security2:error] [pid 15216:tid 15456] [client 57.141.18.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4bsNtIy0gkFcVddGaWhgAAAXg"]
[Mon Jul 20 06:59:30.554961 2026] [security2:error] [pid 15216:tid 15435] [client 197.186.66.42:49902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bsttIy0gkFcVddGaXlAAAAWM"]
[Mon Jul 20 06:59:30.575526 2026] [security2:error] [pid 15216:tid 15435] [client 197.186.66.42:49902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bsttIy0gkFcVddGaXlAAAAWM"]
[Mon Jul 20 06:59:30.713845 2026] [security2:error] [pid 15216:tid 15267] [remote 182.77.62.24:41742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bsttIy0gkFcVddGaXpAABdjI"]
[Mon Jul 20 06:59:30.714000 2026] [security2:error] [pid 15216:tid 15454] [client 182.77.62.24:41742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4bsttIy0gkFcVddGaXpAABdjI"]
[Mon Jul 20 06:59:30.770939 2026] [security2:error] [pid 15216:tid 15411] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bsttIy0gkFcVddGaXoQAAAUs"]
[Mon Jul 20 06:59:30.843854 2026] [security2:error] [pid 15216:tid 15318] [remote 115.74.105.156:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4bsttIy0gkFcVddGaXsgABXGU"]
[Mon Jul 20 06:59:31.240129 2026] [security2:error] [pid 15216:tid 15430] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bs9tIy0gkFcVddGaXzAAAAV4"]
[Mon Jul 20 06:59:31.312661 2026] [security2:error] [pid 15216:tid 15436] [client 14.225.17.146:50024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4bs9tIy0gkFcVddGaXxAAAAWQ"], referer: http://securingmemories.com/2025
[Mon Jul 20 06:59:31.439531 2026] [security2:error] [pid 15216:tid 15385] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bsttIy0gkFcVddGaXqwABMW0"]
[Mon Jul 20 06:59:31.773069 2026] [security2:error] [pid 15216:tid 15381] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bs9tIy0gkFcVddGaYCQAAAS0"]
[Mon Jul 20 06:59:31.928096 2026] [security2:error] [pid 15216:tid 15459] [client 139.28.219.68:46626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "talknutritionwithlesley.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4bs9tIy0gkFcVddGaYJgAAAXs"]
[Mon Jul 20 06:59:32.055809 2026] [security2:error] [pid 15216:tid 15426] [client 74.208.214.194:49134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4btNtIy0gkFcVddGaYNgAAAVo"]
[Mon Jul 20 06:59:32.093126 2026] [security2:error] [pid 15216:tid 15444] [client 192.140.149.97:46055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4btNtIy0gkFcVddGaYOQAAAWw"]
[Mon Jul 20 06:59:32.093738 2026] [security2:error] [pid 15216:tid 15444] [client 192.140.149.97:46055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4btNtIy0gkFcVddGaYOQAAAWw"]
[Mon Jul 20 06:59:32.098292 2026] [security2:error] [pid 15216:tid 15462] [client 50.116.65.227:33968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4btNtIy0gkFcVddGaYOgAAAX4"]
[Mon Jul 20 06:59:32.109112 2026] [security2:error] [pid 15216:tid 15366] [client 50.116.65.227:33984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4btNtIy0gkFcVddGaYOwAAAR4"]
[Mon Jul 20 06:59:32.243664 2026] [security2:error] [pid 15216:tid 15372] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4btNtIy0gkFcVddGaYQQAAASQ"]
[Mon Jul 20 06:59:32.407412 2026] [security2:error] [pid 15216:tid 15357] [client 14.225.17.146:49779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4btNtIy0gkFcVddGaYWQAAARU"], referer: http://grndl.com/2025
[Mon Jul 20 06:59:32.450271 2026] [security2:error] [pid 15216:tid 15464] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bs9tIy0gkFcVddGaYFAABgBQ"]
[Mon Jul 20 06:59:32.525537 2026] [security2:error] [pid 15216:tid 15355] [client 139.28.219.68:46642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/xmlrpc.php"] [unique_id "al4btNtIy0gkFcVddGaYbgAAARM"]
[Mon Jul 20 06:59:32.773498 2026] [security2:error] [pid 15216:tid 15404] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4btNtIy0gkFcVddGaYfgAAAUQ"]
[Mon Jul 20 06:59:32.882133 2026] [security2:error] [pid 15216:tid 15450] [client 152.58.191.29:63932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4btNtIy0gkFcVddGaYlgAAAXI"]
[Mon Jul 20 06:59:32.882288 2026] [security2:error] [pid 15216:tid 15450] [client 152.58.191.29:63932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4btNtIy0gkFcVddGaYlgAAAXI"]
[Mon Jul 20 06:59:33.115966 2026] [security2:error] [pid 15216:tid 15354] [client 14.225.17.146:53514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4bs9tIy0gkFcVddGaX6wAAARI"], referer: http://nwcarvingacademy.com/2025
[Mon Jul 20 06:59:33.214445 2026] [security2:error] [pid 15216:tid 15390] [client 77.110.127.138:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4btdtIy0gkFcVddGaYwwAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:33.214528 2026] [security2:error] [pid 15216:tid 15390] [client 77.110.127.138:60867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4btdtIy0gkFcVddGaYwwAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:33.216561 2026] [security2:error] [pid 15216:tid 15229] [remote 47.128.54.187:11374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omegacompass.com"] [uri "/omega-prime-intelligence/"] [unique_id "al4btdtIy0gkFcVddGaYxAABKww"]
[Mon Jul 20 06:59:33.293951 2026] [security2:error] [pid 15216:tid 15373] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4btdtIy0gkFcVddGaYvgAAASU"]
[Mon Jul 20 06:59:33.449639 2026] [security2:error] [pid 15216:tid 15375] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4btNtIy0gkFcVddGaYhgABJ0g"]
[Mon Jul 20 06:59:33.455161 2026] [security2:error] [pid 15216:tid 15471] [client 57.141.18.33:29028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bs9tIy0gkFcVddGaXygABh0c"]
[Mon Jul 20 06:59:33.525739 2026] [security2:error] [pid 15216:tid 15452] [client 3.85.28.216:45564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4btdtIy0gkFcVddGaY4QAAAXQ"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:59:33.748399 2026] [security2:error] [pid 15216:tid 15448] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4btdtIy0gkFcVddGaY7gAAAXA"]
[Mon Jul 20 06:59:33.905285 2026] [security2:error] [pid 15216:tid 15468] [client 117.222.139.248:56834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4btdtIy0gkFcVddGaZCQAAAYQ"]
[Mon Jul 20 06:59:33.905380 2026] [security2:error] [pid 15216:tid 15468] [client 117.222.139.248:56834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4btdtIy0gkFcVddGaZCQAAAYQ"]
[Mon Jul 20 06:59:34.033459 2026] [security2:error] [pid 15216:tid 15373] [client 45.3.54.87:53925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4btttIy0gkFcVddGaZFAAAASU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:34.090224 2026] [security2:error] [pid 15216:tid 15422] [client 163.172.166.82:40402] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests[0][path]" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests[0][path]=http://"] [hostname "box5024.bluehost.com"] [uri "/wp-json/batch/v1"] [unique_id "al4btttIy0gkFcVddGaZGgAAAVY"]
[Mon Jul 20 06:59:34.273872 2026] [security2:error] [pid 15216:tid 15381] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4btttIy0gkFcVddGaZJAAAAS0"]
[Mon Jul 20 06:59:34.406864 2026] [autoindex:error] [pid 15216:tid 15294] [remote 34.86.31.247:52275] AH01276: Cannot serve directory /home2/uwljivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://uwl.jiv.mybluehost.me
[Mon Jul 20 06:59:34.416035 2026] [security2:error] [pid 15216:tid 15367] [client 14.225.17.146:49860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4btttIy0gkFcVddGaZLQAAAR8"], referer: https://nwcarvingacademy.com/2025
[Mon Jul 20 06:59:34.459432 2026] [security2:error] [pid 15216:tid 15395] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4btdtIy0gkFcVddGaY_AABOxM"]
[Mon Jul 20 06:59:34.483211 2026] [security2:error] [pid 15216:tid 15347] [client 103.144.65.217:52513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4btttIy0gkFcVddGaZTQAAAQs"]
[Mon Jul 20 06:59:34.483312 2026] [security2:error] [pid 15216:tid 15347] [client 103.144.65.217:52513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4btttIy0gkFcVddGaZTQAAAQs"]
[Mon Jul 20 06:59:34.519828 2026] [security2:error] [pid 15216:tid 15455] [client 77.110.127.138:60870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/2/"] [unique_id "al4btttIy0gkFcVddGaZUwAAAXc"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:34.794815 2026] [security2:error] [pid 15216:tid 15366] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4btttIy0gkFcVddGaZaQAAAR4"]
[Mon Jul 20 06:59:34.965792 2026] [security2:error] [pid 15216:tid 15429] [client 14.225.17.146:63592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4btttIy0gkFcVddGaZdgAAAV0"], referer: http://ironcitywellness.com/2025
[Mon Jul 20 06:59:35.128156 2026] [security2:error] [pid 15216:tid 15398] [client 14.225.17.146:53337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4btttIy0gkFcVddGaZegAAAT4"]
[Mon Jul 20 06:59:35.260794 2026] [security2:error] [pid 15216:tid 15455] [client 187.16.64.216:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaZrwAAAXc"]
[Mon Jul 20 06:59:35.260916 2026] [security2:error] [pid 15216:tid 15455] [client 187.16.64.216:59188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaZrwAAAXc"]
[Mon Jul 20 06:59:35.273623 2026] [security2:error] [pid 15216:tid 15448] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bt9tIy0gkFcVddGaZnAAAAXA"]
[Mon Jul 20 06:59:35.392703 2026] [security2:error] [pid 15216:tid 15411] [client 139.28.219.68:46646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaZ0QAAAUs"]
[Mon Jul 20 06:59:35.392895 2026] [security2:error] [pid 15216:tid 15411] [client 139.28.219.68:46646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "talknutritionwithlesley.com"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaZ0QAAAUs"]
[Mon Jul 20 06:59:35.452307 2026] [security2:error] [pid 15216:tid 15417] [client 57.141.18.56:29548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4btdtIy0gkFcVddGaYsQABUQ0"]
[Mon Jul 20 06:59:35.466714 2026] [security2:error] [pid 15216:tid 15247] [remote 115.74.105.156:58406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4bt9tIy0gkFcVddGaZ2wABLh4"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 06:59:35.599093 2026] [security2:error] [pid 15216:tid 15462] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4btttIy0gkFcVddGaZeAABfjI"]
[Mon Jul 20 06:59:35.684989 2026] [security2:error] [pid 15216:tid 15396] [client 213.152.186.163:60516] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaZ9AAAATw"]
[Mon Jul 20 06:59:35.685098 2026] [security2:error] [pid 15216:tid 15396] [client 213.152.186.163:60516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaZ9AAAATw"]
[Mon Jul 20 06:59:35.766996 2026] [security2:error] [pid 15216:tid 15425] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bt9tIy0gkFcVddGaZ8QAAAVk"]
[Mon Jul 20 06:59:35.904547 2026] [security2:error] [pid 15216:tid 15384] [client 57.141.18.70:62930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4btdtIy0gkFcVddGaY9AABMBo"]
[Mon Jul 20 06:59:35.981361 2026] [security2:error] [pid 15216:tid 15423] [client 139.28.219.68:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaaHAAAAVc"]
[Mon Jul 20 06:59:35.981484 2026] [security2:error] [pid 15216:tid 15423] [client 139.28.219.68:54648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "talknutritionwithlesley.com"] [uri "/xmlrpc.php"] [unique_id "al4bt9tIy0gkFcVddGaaHAAAAVc"]
[Mon Jul 20 06:59:36.283363 2026] [security2:error] [pid 15216:tid 15451] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4buNtIy0gkFcVddGaaMAAAAXM"]
[Mon Jul 20 06:59:36.675534 2026] [security2:error] [pid 15216:tid 15453] [client 183.82.98.154:59319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4buNtIy0gkFcVddGaaZgAAAXU"]
[Mon Jul 20 06:59:36.675657 2026] [security2:error] [pid 15216:tid 15453] [client 183.82.98.154:59319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4buNtIy0gkFcVddGaaZgAAAXU"]
[Mon Jul 20 06:59:36.765764 2026] [security2:error] [pid 15216:tid 15446] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4buNtIy0gkFcVddGaaYgAAAW4"]
[Mon Jul 20 06:59:36.798209 2026] [security2:error] [pid 15216:tid 15437] [client 14.225.17.146:53698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4buNtIy0gkFcVddGaaZAAAAWU"]
[Mon Jul 20 06:59:36.944794 2026] [security2:error] [pid 15216:tid 15419] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4buNtIy0gkFcVddGaaOgABU24"]
[Mon Jul 20 06:59:37.129612 2026] [security2:error] [pid 15216:tid 15444] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4budtIy0gkFcVddGaaggAAAWw"]
[Mon Jul 20 06:59:37.170184 2026] [security2:error] [pid 15216:tid 15455] [client 217.142.18.172:47296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4budtIy0gkFcVddGaangAAAXc"]
[Mon Jul 20 06:59:37.173290 2026] [security2:error] [pid 15216:tid 15455] [client 217.142.18.172:47296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4budtIy0gkFcVddGaangAAAXc"]
[Mon Jul 20 06:59:37.312150 2026] [security2:error] [pid 15216:tid 15349] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4budtIy0gkFcVddGaanAAAAQ0"]
[Mon Jul 20 06:59:37.607639 2026] [security2:error] [pid 15216:tid 15439] [client 14.225.17.146:63172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4bt9tIy0gkFcVddGaZ4wAAAWc"], referer: http://floorsourcestock.com/2025
[Mon Jul 20 06:59:37.654635 2026] [security2:error] [pid 15216:tid 15381] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4budtIy0gkFcVddGaawwAAAS0"]
[Mon Jul 20 06:59:37.786860 2026] [security2:error] [pid 15216:tid 15398] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4budtIy0gkFcVddGaa3QAAAT4"]
[Mon Jul 20 06:59:37.982139 2026] [security2:error] [pid 15216:tid 15430] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4budtIy0gkFcVddGaargABXgw"]
[Mon Jul 20 06:59:38.136083 2026] [security2:error] [pid 15216:tid 15433] [client 77.110.127.138:60885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4buttIy0gkFcVddGabDQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:38.136205 2026] [security2:error] [pid 15216:tid 15433] [client 77.110.127.138:60885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4buttIy0gkFcVddGabDQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:38.204575 2026] [security2:error] [pid 15216:tid 15443] [client 14.225.17.146:56614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4budtIy0gkFcVddGaa7AAAAWs"], referer: http://nextlevelpressurewashing.com/2025
[Mon Jul 20 06:59:38.313970 2026] [security2:error] [pid 15216:tid 15387] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4buttIy0gkFcVddGabCwAAATM"]
[Mon Jul 20 06:59:38.693853 2026] [security2:error] [pid 15216:tid 15446] [client 103.238.106.162:42772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4buttIy0gkFcVddGabVwAAAW4"]
[Mon Jul 20 06:59:38.694035 2026] [security2:error] [pid 15216:tid 15446] [client 103.238.106.162:42772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4buttIy0gkFcVddGabVwAAAW4"]
[Mon Jul 20 06:59:38.776098 2026] [security2:error] [pid 15216:tid 15407] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4buttIy0gkFcVddGabTwAAAUc"]
[Mon Jul 20 06:59:38.996343 2026] [security2:error] [pid 15216:tid 15434] [client 45.3.54.106:42911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4buttIy0gkFcVddGabdgAAAWI"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:39.143542 2026] [security2:error] [pid 15216:tid 15350] [client 117.247.108.24:53253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bu9tIy0gkFcVddGabigAAAQ4"]
[Mon Jul 20 06:59:39.143629 2026] [security2:error] [pid 15216:tid 15350] [client 117.247.108.24:53253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bu9tIy0gkFcVddGabigAAAQ4"]
[Mon Jul 20 06:59:39.146434 2026] [authz_core:error] [pid 15216:tid 15430] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/error_log, referer: binance.com
[Mon Jul 20 06:59:39.257967 2026] [security2:error] [pid 15216:tid 15439] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bu9tIy0gkFcVddGabiAAAAWc"]
[Mon Jul 20 06:59:39.285664 2026] [security2:error] [pid 15216:tid 15455] [client 98.159.234.160:29163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bu9tIy0gkFcVddGabnwAAAXc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 06:59:39.323090 2026] [security2:error] [pid 15216:tid 15443] [client 122.183.32.225:13993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bu9tIy0gkFcVddGabpgAAAWs"]
[Mon Jul 20 06:59:39.323193 2026] [security2:error] [pid 15216:tid 15443] [client 122.183.32.225:13993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bu9tIy0gkFcVddGabpgAAAWs"]
[Mon Jul 20 06:59:39.374377 2026] [security2:error] [pid 15216:tid 15354] [client 142.147.219.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4bu9tIy0gkFcVddGabjQAAARI"]
[Mon Jul 20 06:59:39.465642 2026] [security2:error] [pid 15216:tid 15454] [client 77.110.127.138:60906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/2/"] [unique_id "al4bu9tIy0gkFcVddGabtAAAAXY"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:39.563047 2026] [security2:error] [pid 15216:tid 15331] [remote 124.55.178.99:55040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bu9tIy0gkFcVddGabtQABKHI"]
[Mon Jul 20 06:59:39.667298 2026] [http2:info] [pid 28702:tid 28702] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 06:59:39.711584 2026] [security2:error] [pid 15216:tid 15396] [client 14.225.17.146:54766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4bu9tIy0gkFcVddGabqQAAATw"], referer: http://getgarrison.com/2025
[Mon Jul 20 06:59:39.746210 2026] [security2:error] [pid 15216:tid 15347] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4buttIy0gkFcVddGabdAABC3M"]
[Mon Jul 20 06:59:39.914107 2026] [security2:error] [pid 28702:tid 28865] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bu7F4957xPw9VVBmZzAAAAKU"]
[Mon Jul 20 06:59:40.268740 2026] [security2:error] [pid 28702:tid 28958] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaAQAAAQI"]
[Mon Jul 20 06:59:40.760596 2026] [security2:error] [pid 28702:tid 28897] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaMwAAAMU"]
[Mon Jul 20 06:59:40.819837 2026] [security2:error] [pid 28702:tid 28874] [client 14.225.17.146:54965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaLgAAAK4"], referer: http://idigress.agency/2025
[Mon Jul 20 06:59:41.034786 2026] [security2:error] [pid 28702:tid 28747] [remote 173.249.4.11:4890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4bvbF4957xPw9VVBmaYwAA7ys"]
[Mon Jul 20 06:59:41.103109 2026] [security2:error] [pid 15216:tid 15338] [remote 57.141.18.92:57600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4buttIy0gkFcVddGabZwABDXk"]
[Mon Jul 20 06:59:41.139754 2026] [security2:error] [pid 28702:tid 28882] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaIgAAthw"]
[Mon Jul 20 06:59:41.173758 2026] [security2:error] [pid 28702:tid 28751] [remote 124.55.178.99:50400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bvbF4957xPw9VVBmacwAAqC8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:41.252896 2026] [security2:error] [pid 28702:tid 28754] [remote 173.249.4.11:4890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4bvbF4957xPw9VVBmafAAAmTI"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 06:59:41.280604 2026] [security2:error] [pid 28702:tid 28756] [remote 97.74.93.24:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bvbF4957xPw9VVBmafwAA0DQ"]
[Mon Jul 20 06:59:41.302215 2026] [security2:error] [pid 28702:tid 28880] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bvbF4957xPw9VVBmadQAAALQ"]
[Mon Jul 20 06:59:41.759715 2026] [security2:error] [pid 28702:tid 28844] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bvbF4957xPw9VVBmapQAAAJA"]
[Mon Jul 20 06:59:41.770832 2026] [security2:error] [pid 28702:tid 28866] [client 14.225.17.146:54932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaKQAAAKY"], referer: http://mazzucelli.com/2025
[Mon Jul 20 06:59:41.805740 2026] [security2:error] [pid 28702:tid 28771] [remote 97.74.93.24:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bvbF4957xPw9VVBmaugAA9EM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:42.167566 2026] [security2:error] [pid 28702:tid 28893] [client 114.119.137.116:44219] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/"] [unique_id "al4bvrF4957xPw9VVBma3QAAAME"], referer: https://streamworld.top/tntqlynr/%E9%A2%A8%E6%99%AF%E7%B9%AA%E7%95%AB%E5%9C%96-06092a637c/
[Mon Jul 20 06:59:42.248485 2026] [security2:error] [pid 28702:tid 28957] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bvrF4957xPw9VVBma2QAAAQE"]
[Mon Jul 20 06:59:42.262304 2026] [security2:error] [pid 28702:tid 28894] [client 14.224.227.113:54840] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bvrF4957xPw9VVBma5QAAAMI"]
[Mon Jul 20 06:59:42.274785 2026] [security2:error] [pid 28702:tid 28889] [client 37.59.21.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4bvrF4957xPw9VVBma1QAAAL0"]
[Mon Jul 20 06:59:42.290771 2026] [security2:error] [pid 28702:tid 28909] [client 152.58.191.29:64628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bvrF4957xPw9VVBma7QAAANE"]
[Mon Jul 20 06:59:42.290875 2026] [security2:error] [pid 28702:tid 28909] [client 152.58.191.29:64628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4bvrF4957xPw9VVBma7QAAANE"]
[Mon Jul 20 06:59:42.343845 2026] [security2:error] [pid 28702:tid 28884] [client 14.225.17.146:55120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4bvrF4957xPw9VVBma4wAAALg"], referer: http://iagdevelopments.com/2025
[Mon Jul 20 06:59:42.385400 2026] [security2:error] [pid 28702:tid 28842] [client 216.24.212.27:26547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4bvrF4957xPw9VVBma-QAAAI4"]
[Mon Jul 20 06:59:42.396517 2026] [security2:error] [pid 28702:tid 28883] [client 216.24.212.43:55167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4bvrF4957xPw9VVBma-AAAALc"]
[Mon Jul 20 06:59:42.416811 2026] [security2:error] [pid 28702:tid 28902] [client 57.141.18.15:40786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bu7F4957xPw9VVBmZ5wAAyg0"]
[Mon Jul 20 06:59:42.566220 2026] [security2:error] [pid 28702:tid 28792] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4bvrF4957xPw9VVBmbDgAAo1g"]
[Mon Jul 20 06:59:42.730164 2026] [security2:error] [pid 28702:tid 28871] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bvbF4957xPw9VVBmaywAAq0g"]
[Mon Jul 20 06:59:42.780218 2026] [security2:error] [pid 28702:tid 28835] [client 192.140.149.97:46060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bvrF4957xPw9VVBmbKwAAAIc"]
[Mon Jul 20 06:59:42.780338 2026] [security2:error] [pid 28702:tid 28835] [client 192.140.149.97:46060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4bvrF4957xPw9VVBmbKwAAAIc"]
[Mon Jul 20 06:59:42.830921 2026] [security2:error] [pid 28702:tid 28859] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bvrF4957xPw9VVBmbHQAAAJ8"]
[Mon Jul 20 06:59:42.834145 2026] [security2:error] [pid 28702:tid 28803] [remote 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4bvrF4957xPw9VVBmbMwAA1WM"], referer: https://benbayly.co.nz/wp-login.php
[Mon Jul 20 06:59:42.979134 2026] [security2:error] [pid 28702:tid 28849] [client 14.225.17.146:54987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaXAAAAJU"], referer: http://webgardensbypaula.com/2025
[Mon Jul 20 06:59:43.246370 2026] [security2:error] [pid 28702:tid 28865] [client 14.225.17.146:55706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4bvrF4957xPw9VVBmbOwAAAKU"], referer: http://healthylifegourmet.org/2025
[Mon Jul 20 06:59:43.283174 2026] [security2:error] [pid 28702:tid 28866] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bv7F4957xPw9VVBmbYgAAAKY"]
[Mon Jul 20 06:59:43.294399 2026] [security2:error] [pid 28702:tid 28860] [client 14.225.17.146:55574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4bv7F4957xPw9VVBmbZQAAAKA"], referer: https://iagdevelopments.com/2025
[Mon Jul 20 06:59:43.347757 2026] [security2:error] [pid 28702:tid 28903] [client 188.39.109.162:2618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4bv7F4957xPw9VVBmbVQAAAMs"]
[Mon Jul 20 06:59:43.461267 2026] [security2:error] [pid 28702:tid 28858] [client 77.110.127.138:60921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bv7F4957xPw9VVBmbhQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:43.461405 2026] [security2:error] [pid 28702:tid 28858] [client 77.110.127.138:60921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bv7F4957xPw9VVBmbhQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:43.543159 2026] [security2:error] [pid 28702:tid 28881] [client 197.186.66.42:50445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.66.186.197.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bv7F4957xPw9VVBmbkAAAALU"]
[Mon Jul 20 06:59:43.543315 2026] [security2:error] [pid 28702:tid 28881] [client 197.186.66.42:50445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4bv7F4957xPw9VVBmbkAAAALU"]
[Mon Jul 20 06:59:43.640002 2026] [security2:error] [pid 28702:tid 28938] [client 57.141.18.24:27870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bvbF4957xPw9VVBmadAAA7jA"]
[Mon Jul 20 06:59:43.680347 2026] [security2:error] [pid 28702:tid 28947] [client 65.111.22.130:32927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bv7F4957xPw9VVBmboQAAAPc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:43.743255 2026] [security2:error] [pid 28702:tid 28916] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bv7F4957xPw9VVBmbmwAAANg"]
[Mon Jul 20 06:59:44.225525 2026] [security2:error] [pid 28702:tid 28863] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bv7F4957xPw9VVBmbfQAAo3g"]
[Mon Jul 20 06:59:44.226997 2026] [security2:error] [pid 28702:tid 28937] [client 14.225.17.146:54971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4bwLF4957xPw9VVBmbzgAAAO0"], referer: http://christiancountytrumpet.com/2025
[Mon Jul 20 06:59:44.247388 2026] [security2:error] [pid 28702:tid 28929] [client 104.207.51.216:36911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bwLF4957xPw9VVBmb3wAAAOU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:44.270898 2026] [security2:error] [pid 28702:tid 28850] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bwLF4957xPw9VVBmb1gAAAJY"]
[Mon Jul 20 06:59:44.388476 2026] [security2:error] [pid 28702:tid 28725] [remote 182.77.62.24:33392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bwLF4957xPw9VVBmb7wAAjhU"]
[Mon Jul 20 06:59:44.414100 2026] [security2:error] [pid 28702:tid 28921] [client 14.225.17.146:56500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4bvLF4957xPw9VVBmaOwAAAN0"], referer: http://areitoproducciones.com/2025
[Mon Jul 20 06:59:44.461420 2026] [security2:error] [pid 28702:tid 28839] [client 117.222.139.248:57344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bwLF4957xPw9VVBmb-wAAAIs"]
[Mon Jul 20 06:59:44.461546 2026] [security2:error] [pid 28702:tid 28839] [client 117.222.139.248:57344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4bwLF4957xPw9VVBmb-wAAAIs"]
[Mon Jul 20 06:59:44.475463 2026] [security2:error] [pid 28702:tid 28914] [client 14.225.17.146:55001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4bvbF4957xPw9VVBmatAAAANY"], referer: http://bruceledewitz.com/2025
[Mon Jul 20 06:59:44.650739 2026] [security2:error] [pid 28702:tid 28733] [remote 192.241.143.148:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4bwLF4957xPw9VVBmcGgAA2h0"]
[Mon Jul 20 06:59:44.668046 2026] [security2:error] [pid 28702:tid 28833] [client 77.110.127.138:60926] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/2/"] [unique_id "al4bwLF4957xPw9VVBmcIAAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:44.669813 2026] [security2:error] [pid 28702:tid 28947] [client 13.221.132.12:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.132.221.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bwLF4957xPw9VVBmcGQAAAPc"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:59:44.781474 2026] [security2:error] [pid 28702:tid 28897] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bwLF4957xPw9VVBmcGwAAAMU"]
[Mon Jul 20 06:59:44.801051 2026] [security2:error] [pid 28702:tid 28853] [client 45.3.54.174:64679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bwLF4957xPw9VVBmcMwAAAJk"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:44.830698 2026] [security2:error] [pid 28702:tid 28745] [remote 192.241.143.148:43892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4bwLF4957xPw9VVBmcOgAArSk"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 06:59:44.912065 2026] [security2:error] [pid 28702:tid 28932] [client 57.141.18.99:61510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bvrF4957xPw9VVBma-gAA6FI"]
[Mon Jul 20 06:59:44.934432 2026] [security2:error] [pid 28702:tid 28913] [client 50.116.65.227:33944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4bwLF4957xPw9VVBmcKwAAANU"]
[Mon Jul 20 06:59:44.957934 2026] [security2:error] [pid 28702:tid 28748] [remote 182.77.62.24:33392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bwLF4957xPw9VVBmcRQAA8Sw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:45.095504 2026] [security2:error] [pid 28702:tid 28848] [client 103.144.65.217:52941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bwbF4957xPw9VVBmcYQAAAJQ"]
[Mon Jul 20 06:59:45.095653 2026] [security2:error] [pid 28702:tid 28848] [client 103.144.65.217:52941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4bwbF4957xPw9VVBmcYQAAAJQ"]
[Mon Jul 20 06:59:45.130672 2026] [security2:error] [pid 28702:tid 28917] [client 50.116.65.227:33948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4bwLF4957xPw9VVBmcRAAAANk"]
[Mon Jul 20 06:59:45.139090 2026] [authz_core:error] [pid 28702:tid 28912] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/error_log, referer: binance.com
[Mon Jul 20 06:59:45.257124 2026] [security2:error] [pid 28702:tid 28834] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmcZQAAAIY"]
[Mon Jul 20 06:59:45.292392 2026] [security2:error] [pid 28702:tid 28866] [client 14.225.17.146:56145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmcXAAAAKY"], referer: http://taskidsvirginia.com/2025
[Mon Jul 20 06:59:45.388795 2026] [security2:error] [pid 28702:tid 28874] [client 65.111.23.14:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bwbF4957xPw9VVBmcgQAAAK4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:45.507585 2026] [security2:error] [pid 28702:tid 28853] [client 158.173.241.141:60145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmccgAAAJk"], referer: http://sesamegreenbeans.com/tag/south-africa/
[Mon Jul 20 06:59:45.565990 2026] [security2:error] [pid 28702:tid 28883] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bwLF4957xPw9VVBmcPAAAtyg"]
[Mon Jul 20 06:59:45.597850 2026] [security2:error] [pid 28702:tid 28856] [client 57.141.18.64:53846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bv7F4957xPw9VVBmbWQAAnG4"]
[Mon Jul 20 06:59:45.749280 2026] [security2:error] [pid 28702:tid 28777] [remote 130.185.118.215:37978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bwbF4957xPw9VVBmcvAAAq0k"]
[Mon Jul 20 06:59:45.787995 2026] [security2:error] [pid 28702:tid 28844] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmcsQAAAJA"]
[Mon Jul 20 06:59:45.907477 2026] [security2:error] [pid 28702:tid 28927] [client 187.16.64.216:59702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bwbF4957xPw9VVBmcyQAAAOM"]
[Mon Jul 20 06:59:45.907601 2026] [security2:error] [pid 28702:tid 28927] [client 187.16.64.216:59702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bwbF4957xPw9VVBmcyQAAAOM"]
[Mon Jul 20 06:59:45.958540 2026] [security2:error] [pid 28702:tid 28918] [client 189.19.175.226:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmckQAAANo"]
[Mon Jul 20 06:59:45.959811 2026] [security2:error] [pid 28702:tid 28780] [remote 130.185.118.215:37978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4bwbF4957xPw9VVBmczgAAmUw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 06:59:45.977320 2026] [security2:error] [pid 28702:tid 28869] [client 104.207.52.84:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4bwbF4957xPw9VVBmczAAAAKk"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:46.194441 2026] [security2:error] [pid 28702:tid 28904] [client 50.116.65.227:27302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4bwrF4957xPw9VVBmc9AAAAMw"]
[Mon Jul 20 06:59:46.208492 2026] [security2:error] [pid 28702:tid 28882] [client 50.116.65.227:34020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4bwrF4957xPw9VVBmc9gAAALY"]
[Mon Jul 20 06:59:46.300535 2026] [security2:error] [pid 28702:tid 28871] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bwrF4957xPw9VVBmc8QAAAKs"]
[Mon Jul 20 06:59:46.510813 2026] [security2:error] [pid 28702:tid 28799] [remote 5.161.225.162:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4bwrF4957xPw9VVBmdFgAAwV8"]
[Mon Jul 20 06:59:46.745005 2026] [security2:error] [pid 28702:tid 28954] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bwrF4957xPw9VVBmc3QAA_lM"]
[Mon Jul 20 06:59:46.776502 2026] [security2:error] [pid 28702:tid 28845] [client 14.225.17.146:54753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmcigAAAJE"], referer: http://elitetax-mi.com/2025
[Mon Jul 20 06:59:46.777568 2026] [security2:error] [pid 28702:tid 28842] [client 87.199.205.156:48947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.205.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4bwrF4957xPw9VVBmdNQAAAI4"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 06:59:46.777667 2026] [security2:error] [pid 28702:tid 28842] [client 87.199.205.156:48947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4bwrF4957xPw9VVBmdNQAAAI4"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 06:59:46.784578 2026] [security2:error] [pid 28702:tid 28835] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bwrF4957xPw9VVBmdKgAAAIc"]
[Mon Jul 20 06:59:46.984110 2026] [security2:error] [pid 28702:tid 28923] [client 14.225.17.146:54788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4bwrF4957xPw9VVBmdSAAAAN8"], referer: http://keywayconstructionclt.com/2025
[Mon Jul 20 06:59:46.991771 2026] [security2:error] [pid 28702:tid 28915] [client 146.103.116.11:46206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.116.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4bwrF4957xPw9VVBmdTAAAANc"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 06:59:46.991918 2026] [security2:error] [pid 28702:tid 28915] [client 146.103.116.11:46206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4bwrF4957xPw9VVBmdTAAAANc"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 06:59:47.164688 2026] [security2:error] [pid 28702:tid 28820] [remote 5.161.225.162:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4bw7F4957xPw9VVBmdaQAA7HQ"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 06:59:47.387233 2026] [security2:error] [pid 28702:tid 28884] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bw7F4957xPw9VVBmddQAAALg"]
[Mon Jul 20 06:59:47.646697 2026] [core:error] [pid 28702:tid 28838] [client 195.211.77.141:34428] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:47.646717 2026] [core:error] [pid 28702:tid 28838] [client 195.211.77.141:34428] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:47.708046 2026] [core:error] [pid 28702:tid 28867] [client 195.211.77.141:34432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:47.708074 2026] [core:error] [pid 28702:tid 28867] [client 195.211.77.141:34432] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:47.709499 2026] [security2:error] [pid 28702:tid 28866] [client 217.142.18.172:37525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bw7F4957xPw9VVBmdvAAAAKY"]
[Mon Jul 20 06:59:47.709596 2026] [security2:error] [pid 28702:tid 28866] [client 217.142.18.172:37525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bw7F4957xPw9VVBmdvAAAAKY"]
[Mon Jul 20 06:59:47.767017 2026] [security2:error] [pid 28702:tid 28956] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bw7F4957xPw9VVBmdrwAAAQA"]
[Mon Jul 20 06:59:47.795988 2026] [security2:error] [pid 28702:tid 28930] [client 23.251.146.115:16192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bw7F4957xPw9VVBmduQAA5gk"]
[Mon Jul 20 06:59:47.895726 2026] [security2:error] [pid 28702:tid 28948] [client 104.234.53.79:56411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4bw7F4957xPw9VVBmdyAAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:47.928451 2026] [security2:error] [pid 28702:tid 28896] [client 23.251.146.115:16192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bw7F4957xPw9VVBmdzAAAxAU"]
[Mon Jul 20 06:59:47.929811 2026] [security2:error] [pid 28702:tid 28900] [client 57.141.18.75:20950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bwbF4957xPw9VVBmcgAAAyDc"]
[Mon Jul 20 06:59:48.076759 2026] [security2:error] [pid 28702:tid 28929] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bw7F4957xPw9VVBmdhAAA5Xs"]
[Mon Jul 20 06:59:48.186987 2026] [security2:error] [pid 28702:tid 28876] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4bxLF4957xPw9VVBmd2gAAALA"]
[Mon Jul 20 06:59:48.253241 2026] [security2:error] [pid 28702:tid 28883] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bxLF4957xPw9VVBmd5AAAALc"]
[Mon Jul 20 06:59:48.379177 2026] [security2:error] [pid 28702:tid 28858] [client 114.119.146.159:42615] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mezzacraft.com"] [uri "/robots.txt"] [unique_id "al4bxLF4957xPw9VVBmd-gAAAJ4"], referer: http://www.mezzacraft.com/robots.txt
[Mon Jul 20 06:59:48.612154 2026] [security2:error] [pid 28702:tid 28868] [client 65.111.22.81:62825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bxLF4957xPw9VVBmeBgAAAKg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:48.638797 2026] [security2:error] [pid 28702:tid 28859] [client 57.141.18.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4bxLF4957xPw9VVBmeAAAAAJ8"]
[Mon Jul 20 06:59:48.661866 2026] [security2:error] [pid 28702:tid 28957] [client 14.225.17.146:54918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4bw7F4957xPw9VVBmdcAAAAQE"], referer: http://thechancersband.com/2025
[Mon Jul 20 06:59:48.770702 2026] [security2:error] [pid 28702:tid 28897] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bxLF4957xPw9VVBmeEAAAAMU"]
[Mon Jul 20 06:59:48.825117 2026] [security2:error] [pid 28702:tid 28894] [client 54.166.194.245:44684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.194.166.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bxLF4957xPw9VVBmeIQAAAMI"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:59:49.196552 2026] [security2:error] [pid 28702:tid 28884] [client 104.207.51.246:40355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bxbF4957xPw9VVBmeSQAAALg"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:49.261311 2026] [security2:error] [pid 28702:tid 28953] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bxbF4957xPw9VVBmeRAAAAP0"]
[Mon Jul 20 06:59:49.270289 2026] [security2:error] [pid 28702:tid 28834] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bxLF4957xPw9VVBmeBwAAhiI"]
[Mon Jul 20 06:59:49.347937 2026] [security2:error] [pid 28702:tid 28940] [client 14.225.17.146:53377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4bxbF4957xPw9VVBmeQgAAAPA"], referer: http://talknutritionwithlesley.com/2025
[Mon Jul 20 06:59:49.535942 2026] [security2:error] [pid 28702:tid 28942] [client 147.93.171.187:49449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/abilities-api.php"] [unique_id "al4bxbF4957xPw9VVBmebQAAAPI"], referer: binance.com
[Mon Jul 20 06:59:49.681114 2026] [security2:error] [pid 28702:tid 28881] [client 117.247.108.24:50752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bxbF4957xPw9VVBmeewAAALU"]
[Mon Jul 20 06:59:49.681285 2026] [security2:error] [pid 28702:tid 28881] [client 117.247.108.24:50752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4bxbF4957xPw9VVBmeewAAALU"]
[Mon Jul 20 06:59:49.753145 2026] [security2:error] [pid 28702:tid 28915] [client 45.3.54.113:34225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4bxbF4957xPw9VVBmefAAAANc"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 06:59:49.767879 2026] [security2:error] [pid 28702:tid 28835] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bxbF4957xPw9VVBmedQAAAIc"]
[Mon Jul 20 06:59:49.790025 2026] [security2:error] [pid 28702:tid 28844] [client 77.110.127.138:60967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bxbF4957xPw9VVBmehAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:49.790113 2026] [security2:error] [pid 28702:tid 28844] [client 77.110.127.138:60967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bxbF4957xPw9VVBmehAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:49.866810 2026] [security2:error] [pid 28702:tid 28854] [client 178.20.47.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4bxbF4957xPw9VVBmeUwAAAJo"], referer: https://blog.danwolfe.us/2021/02/18/we-have-landed/#comment-41471
[Mon Jul 20 06:59:50.226533 2026] [security2:error] [pid 28702:tid 28838] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bxbF4957xPw9VVBmecQAAij4"]
[Mon Jul 20 06:59:50.270225 2026] [security2:error] [pid 28702:tid 28958] [client 103.238.106.162:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bxrF4957xPw9VVBmetAAAAQI"]
[Mon Jul 20 06:59:50.270360 2026] [security2:error] [pid 28702:tid 28958] [client 103.238.106.162:60959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4bxrF4957xPw9VVBmetAAAAQI"]
[Mon Jul 20 06:59:50.274799 2026] [security2:error] [pid 28702:tid 28866] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bxrF4957xPw9VVBmeogAAAKY"]
[Mon Jul 20 06:59:50.756911 2026] [security2:error] [pid 28702:tid 28933] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bxrF4957xPw9VVBme1gAAAOk"]
[Mon Jul 20 06:59:50.780591 2026] [security2:error] [pid 28702:tid 28893] [client 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4bxrF4957xPw9VVBme4gAAAME"]
[Mon Jul 20 06:59:50.867896 2026] [security2:error] [pid 28702:tid 28941] [client 32.198.12.77:19644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4bxrF4957xPw9VVBme5QAAAPE"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:59:51.011055 2026] [security2:error] [pid 28702:tid 28891] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4bxbF4957xPw9VVBmeYAAAvzk"], referer: http://ali-alghanim.net/2025
[Mon Jul 20 06:59:51.070182 2026] [security2:error] [pid 28702:tid 28960] [client 192.241.143.148:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4bx7F4957xPw9VVBme_wAAAQQ"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 06:59:51.181213 2026] [security2:error] [pid 28702:tid 28869] [client 3.85.191.173:34656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.191.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4bx7F4957xPw9VVBmfBQAAAKk"], referer: https://curlsnpearlsss.com/es/arroz-con-pechuga-de-pollo-recipe/
[Mon Jul 20 06:59:51.194626 2026] [security2:error] [pid 28702:tid 28915] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bxrF4957xPw9VVBme0QAA1w0"]
[Mon Jul 20 06:59:51.261411 2026] [security2:error] [pid 28702:tid 28934] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bx7F4957xPw9VVBmfBgAAAOo"]
[Mon Jul 20 06:59:51.261745 2026] [security2:error] [pid 28702:tid 28902] [client 14.225.17.146:54829] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4bx7F4957xPw9VVBmfAAAAAMo"], referer: http://detroitcsc.com/2025
[Mon Jul 20 06:59:51.297683 2026] [security2:error] [pid 28702:tid 28914] [client 14.225.17.146:53265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4bxrF4957xPw9VVBmenQAAANY"], referer: http://lutheranphilosopher.com/2025
[Mon Jul 20 06:59:51.338784 2026] [security2:error] [pid 28702:tid 28818] [remote 20.153.140.50:38990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4bx7F4957xPw9VVBmfGAAA4HI"]
[Mon Jul 20 06:59:51.732306 2026] [security2:error] [pid 28702:tid 28752] [remote 20.153.140.50:38990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4bx7F4957xPw9VVBmfSAAAzzA"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 06:59:51.760446 2026] [security2:error] [pid 28702:tid 28959] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bx7F4957xPw9VVBmfQwAAAQM"]
[Mon Jul 20 06:59:51.762077 2026] [security2:error] [pid 28702:tid 28825] [remote 182.77.62.24:60504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4bx7F4957xPw9VVBmfTAAAk3k"]
[Mon Jul 20 06:59:51.857460 2026] [security2:error] [pid 28702:tid 28908] [client 14.225.17.146:52731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4bx7F4957xPw9VVBmfRwAAANA"], referer: http://slutilities.com/2025
[Mon Jul 20 06:59:51.911144 2026] [security2:error] [pid 28702:tid 28885] [client 147.93.171.187:49555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/abilities.php"] [unique_id "al4bx7F4957xPw9VVBmfXwAAALk"], referer: binance.com
[Mon Jul 20 06:59:52.032730 2026] [security2:error] [pid 28702:tid 28866] [client 114.119.144.202:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zanjan-fromer.com"] [uri "/robots.txt"] [unique_id "al4byLF4957xPw9VVBmfaAAAAKY"], referer: http://www.zanjan-fromer.com/robots.txt
[Mon Jul 20 06:59:52.101451 2026] [security2:error] [pid 28702:tid 28878] [client 194.180.48.253:60752] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "careysheatingandcooling.com"] [uri "/"] [unique_id "al4byLF4957xPw9VVBmfawAAALI"]
[Mon Jul 20 06:59:52.217358 2026] [security2:error] [pid 28702:tid 28840] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bx7F4957xPw9VVBmfLwAAjG8"]
[Mon Jul 20 06:59:52.257937 2026] [security2:error] [pid 28702:tid 28941] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4byLF4957xPw9VVBmfdQAAAPE"]
[Mon Jul 20 06:59:52.280650 2026] [security2:error] [pid 28702:tid 28826] [remote 182.77.62.24:60504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4byLF4957xPw9VVBmffwAA3Ho"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 06:59:52.340337 2026] [security2:error] [pid 28702:tid 28881] [client 152.58.191.29:65116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4byLF4957xPw9VVBmfiQAAALU"]
[Mon Jul 20 06:59:52.340463 2026] [security2:error] [pid 28702:tid 28881] [client 152.58.191.29:65116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4byLF4957xPw9VVBmfiQAAALU"]
[Mon Jul 20 06:59:52.748361 2026] [security2:error] [pid 28702:tid 28907] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4byLF4957xPw9VVBmfpgAAAM8"]
[Mon Jul 20 06:59:52.891032 2026] [security2:error] [pid 28702:tid 28926] [client 57.141.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4byLF4957xPw9VVBmfsAAAAOI"]
[Mon Jul 20 06:59:53.066024 2026] [security2:error] [pid 28702:tid 28731] [remote 176.56.118.182:44524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bybF4957xPw9VVBmfyAAAwBs"]
[Mon Jul 20 06:59:53.297944 2026] [security2:error] [pid 28702:tid 28941] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bybF4957xPw9VVBmf3AAAAPE"]
[Mon Jul 20 06:59:53.298274 2026] [security2:error] [pid 28702:tid 28735] [remote 176.56.118.182:44524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4bybF4957xPw9VVBmf5AAA9x8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 06:59:53.356901 2026] [security2:error] [pid 28702:tid 28857] [client 57.141.18.33:48516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bxrF4957xPw9VVBme8AAAnWU"]
[Mon Jul 20 06:59:53.357421 2026] [security2:error] [pid 28702:tid 28843] [client 14.225.17.146:53100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4byLF4957xPw9VVBmfagAAAI8"], referer: http://hammadownenterprises.com/2025
[Mon Jul 20 06:59:53.524147 2026] [core:error] [pid 28702:tid 28958] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.524168 2026] [core:error] [pid 28702:tid 28958] [client 94.154.43.184:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.526351 2026] [core:error] [pid 28702:tid 28933] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.526374 2026] [core:error] [pid 28702:tid 28933] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.546604 2026] [core:error] [pid 28702:tid 28845] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.546628 2026] [core:error] [pid 28702:tid 28845] [client 94.154.43.186:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.574297 2026] [core:error] [pid 28702:tid 28936] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.574323 2026] [core:error] [pid 28702:tid 28936] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.732709 2026] [core:error] [pid 28702:tid 28926] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.732738 2026] [core:error] [pid 28702:tid 28926] [client 94.154.43.229:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 06:59:53.771042 2026] [security2:error] [pid 28702:tid 28959] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bybF4957xPw9VVBmgHwAAAQM"]
[Mon Jul 20 06:59:53.812685 2026] [security2:error] [pid 28702:tid 28929] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bybF4957xPw9VVBmf2gAA5SE"]
[Mon Jul 20 06:59:54.278092 2026] [security2:error] [pid 28702:tid 28849] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgSgAAAJU"]
[Mon Jul 20 06:59:54.351380 2026] [security2:error] [pid 28702:tid 28895] [client 77.110.127.138:60989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4byrF4957xPw9VVBmgWAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:54.351474 2026] [security2:error] [pid 28702:tid 28895] [client 77.110.127.138:60989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4byrF4957xPw9VVBmgWAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:54.766622 2026] [security2:error] [pid 28702:tid 28918] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgfwAAANo"]
[Mon Jul 20 06:59:54.980210 2026] [security2:error] [pid 28702:tid 28844] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgVgAAkD8"]
[Mon Jul 20 06:59:55.040165 2026] [security2:error] [pid 28702:tid 28910] [client 117.222.139.248:57855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4by7F4957xPw9VVBmgpQAAANI"]
[Mon Jul 20 06:59:55.040306 2026] [security2:error] [pid 28702:tid 28910] [client 117.222.139.248:57855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4by7F4957xPw9VVBmgpQAAANI"]
[Mon Jul 20 06:59:55.063905 2026] [security2:error] [pid 28702:tid 28799] [remote 57.141.18.83:26570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5076100"] [unique_id "al4by7F4957xPw9VVBmgowAA-V8"]
[Mon Jul 20 06:59:55.161342 2026] [security2:error] [pid 28702:tid 28879] [client 104.234.53.54:56871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4by7F4957xPw9VVBmgsQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:55.307684 2026] [security2:error] [pid 28702:tid 28867] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4by7F4957xPw9VVBmguQAAAKc"]
[Mon Jul 20 06:59:55.313890 2026] [security2:error] [pid 28702:tid 28954] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4by7F4957xPw9VVBmgrgAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:55.487742 2026] [security2:error] [pid 28702:tid 28855] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgVAAAm00"], referer: http://ardhalwafaa.com/2025
[Mon Jul 20 06:59:55.567245 2026] [security2:error] [pid 28702:tid 28881] [client 103.144.65.217:53365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4by7F4957xPw9VVBmg2wAAALU"]
[Mon Jul 20 06:59:55.567461 2026] [security2:error] [pid 28702:tid 28881] [client 103.144.65.217:53365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4by7F4957xPw9VVBmg2wAAALU"]
[Mon Jul 20 06:59:55.571304 2026] [security2:error] [pid 28702:tid 28931] [client 104.207.50.86:29143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4by7F4957xPw9VVBmg1gAAAOc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 06:59:55.747991 2026] [security2:error] [pid 28702:tid 28866] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4by7F4957xPw9VVBmg5gAAAKY"]
[Mon Jul 20 06:59:55.904830 2026] [security2:error] [pid 28702:tid 28915] [client 57.141.18.43:35210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bybF4957xPw9VVBmf9wAA1zE"]
[Mon Jul 20 06:59:55.905344 2026] [security2:error] [pid 28702:tid 28875] [client 50.116.65.227:32158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4by7F4957xPw9VVBmg-gAAAK8"]
[Mon Jul 20 06:59:55.916720 2026] [security2:error] [pid 28702:tid 28834] [client 50.116.65.227:32170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4by7F4957xPw9VVBmg-wAAAIY"]
[Mon Jul 20 06:59:56.003618 2026] [security2:error] [pid 28702:tid 28883] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4by7F4957xPw9VVBmgwQAAt2o"]
[Mon Jul 20 06:59:56.208074 2026] [security2:error] [pid 28702:tid 28928] [client 14.225.17.146:52804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgkQAAAOQ"], referer: http://scott-assist.com/2025
[Mon Jul 20 06:59:56.252394 2026] [security2:error] [pid 28702:tid 28844] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bzLF4957xPw9VVBmhGAAAAJA"]
[Mon Jul 20 06:59:56.449310 2026] [security2:error] [pid 28702:tid 28926] [client 14.225.17.146:52862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgkwAAAOI"], referer: http://margaretspeckogawa.com/2025
[Mon Jul 20 06:59:56.468658 2026] [security2:error] [pid 28702:tid 28872] [client 147.93.171.187:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/ai-client.php"] [unique_id "al4bzLF4957xPw9VVBmhQAAAAKw"], referer: binance.com
[Mon Jul 20 06:59:56.642047 2026] [security2:error] [pid 28702:tid 28935] [client 187.16.64.216:60220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bzLF4957xPw9VVBmhVgAAAOs"]
[Mon Jul 20 06:59:56.642160 2026] [security2:error] [pid 28702:tid 28935] [client 187.16.64.216:60220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4bzLF4957xPw9VVBmhVgAAAOs"]
[Mon Jul 20 06:59:56.759923 2026] [security2:error] [pid 28702:tid 28949] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bzLF4957xPw9VVBmhVAAAAPk"]
[Mon Jul 20 06:59:56.865506 2026] [security2:error] [pid 28702:tid 28904] [client 57.141.18.56:42714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4byrF4957xPw9VVBmgWwAAzEs"]
[Mon Jul 20 06:59:57.074397 2026] [security2:error] [pid 28702:tid 28940] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bzLF4957xPw9VVBmhOAAA8EY"]
[Mon Jul 20 06:59:57.283732 2026] [security2:error] [pid 28702:tid 28844] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bzbF4957xPw9VVBmhfQAAAJA"]
[Mon Jul 20 06:59:57.432685 2026] [security2:error] [pid 28702:tid 28924] [client 14.225.17.146:55933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4by7F4957xPw9VVBmhBgAAAOA"], referer: http://expertcultures.com/2025
[Mon Jul 20 06:59:57.705067 2026] [security2:error] [pid 28702:tid 28905] [client 14.224.227.113:54843] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4bzbF4957xPw9VVBmhxAAAAM0"]
[Mon Jul 20 06:59:57.756195 2026] [security2:error] [pid 28702:tid 28883] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bzbF4957xPw9VVBmhuwAAALc"]
[Mon Jul 20 06:59:57.884448 2026] [security2:error] [pid 28702:tid 28925] [client 104.234.53.66:54817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4bzbF4957xPw9VVBmh3AAAAOE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 06:59:57.939595 2026] [security2:error] [pid 28702:tid 28899] [client 52.47.76.32:53926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bzbF4957xPw9VVBmh5QAAAMc"]
[Mon Jul 20 06:59:57.939726 2026] [security2:error] [pid 28702:tid 28899] [client 52.47.76.32:53926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4bzbF4957xPw9VVBmh5QAAAMc"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:59:58.225261 2026] [security2:error] [pid 28702:tid 28928] [client 217.142.18.172:38758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bzrF4957xPw9VVBmiBgAAAOQ"]
[Mon Jul 20 06:59:58.236285 2026] [security2:error] [pid 28702:tid 28928] [client 217.142.18.172:38758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4bzrF4957xPw9VVBmiBgAAAOQ"]
[Mon Jul 20 06:59:58.262241 2026] [security2:error] [pid 28702:tid 28893] [client 183.82.98.154:60501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bzrF4957xPw9VVBmiCwAAAME"]
[Mon Jul 20 06:59:58.262396 2026] [security2:error] [pid 28702:tid 28893] [client 183.82.98.154:60501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4bzrF4957xPw9VVBmiCwAAAME"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 06:59:58.290824 2026] [security2:error] [pid 28702:tid 28857] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bzrF4957xPw9VVBmh-wAAAJ0"]
[Mon Jul 20 06:59:58.783086 2026] [security2:error] [pid 28702:tid 28908] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bzrF4957xPw9VVBmiPgAAANA"]
[Mon Jul 20 06:59:58.888915 2026] [security2:error] [pid 28702:tid 28924] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bzrF4957xPw9VVBmh8gAA4Cg"]
[Mon Jul 20 06:59:59.047848 2026] [security2:error] [pid 28702:tid 28791] [remote 111.225.148.58:39644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/impress-ex-772a.pdf"] [unique_id "al4bz7F4957xPw9VVBmicAAAklc"]
[Mon Jul 20 06:59:59.267041 2026] [security2:error] [pid 28702:tid 28957] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bz7F4957xPw9VVBmifgAAAQE"]
[Mon Jul 20 06:59:59.620970 2026] [security2:error] [pid 28702:tid 28940] [client 14.225.17.146:58276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4bz7F4957xPw9VVBmi0QAAAPA"]
[Mon Jul 20 06:59:59.728352 2026] [security2:error] [pid 28702:tid 28895] [client 57.141.18.90:58810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4bzbF4957xPw9VVBmhvwAAw2U"]
[Mon Jul 20 06:59:59.766829 2026] [security2:error] [pid 28702:tid 28906] [client 122.183.32.225:23903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bz7F4957xPw9VVBmi8AAAAM4"]
[Mon Jul 20 06:59:59.766921 2026] [security2:error] [pid 28702:tid 28906] [client 122.183.32.225:23903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4bz7F4957xPw9VVBmi8AAAAM4"]
[Mon Jul 20 06:59:59.769086 2026] [security2:error] [pid 28702:tid 28907] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4bz7F4957xPw9VVBmi4QAAAM8"]
[Mon Jul 20 06:59:59.866938 2026] [security2:error] [pid 28702:tid 28863] [client 77.110.127.138:61023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bz7F4957xPw9VVBmi_AAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:59.867059 2026] [security2:error] [pid 28702:tid 28863] [client 77.110.127.138:61023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4bz7F4957xPw9VVBmi_AAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 06:59:59.992570 2026] [security2:error] [pid 28702:tid 28868] [client 104.234.53.89:24253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4bz7F4957xPw9VVBmjAwAAAKg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:00.192443 2026] [security2:error] [pid 28702:tid 28951] [client 158.173.89.95:29569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4b0LF4957xPw9VVBmjGAAAAPs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:00:00.213777 2026] [security2:error] [pid 28702:tid 28878] [client 158.51.126.91:52632] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/wp-content/themes/wp-yellow-hats/assets/css/fonts.css"] [unique_id "al4b0LF4957xPw9VVBmjIgAAALI"]
[Mon Jul 20 07:00:00.224552 2026] [security2:error] [pid 28702:tid 28892] [client 158.51.126.91:52570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "whiteoutcb.com"] [uri "/wp-content/uploads/2022/09/favicon-300x300.png"] [unique_id "al4b0LF4957xPw9VVBmjJwAAAMA"]
[Mon Jul 20 07:00:00.224636 2026] [security2:error] [pid 28702:tid 28894] [client 158.51.126.91:52664] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/contact-us/"] [unique_id "al4b0LF4957xPw9VVBmjKAAAAMI"]
[Mon Jul 20 07:00:00.224660 2026] [security2:error] [pid 28702:tid 28892] [client 158.51.126.91:52570] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "whiteoutcb.com"] [uri "/wp-content/uploads/2022/09/favicon-300x300.png"] [unique_id "al4b0LF4957xPw9VVBmjJwAAAMA"]
[Mon Jul 20 07:00:00.239886 2026] [security2:error] [pid 28702:tid 28858] [client 158.51.126.91:52594] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/wp-content/plugins/user-press/acess/css/remodal.css"] [unique_id "al4b0LF4957xPw9VVBmjLAAAAJ4"]
[Mon Jul 20 07:00:00.252173 2026] [security2:error] [pid 28702:tid 28893] [client 158.51.126.91:52690] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/wp-content/themes/wp-yellow-hats/assets/css/elegant-icon.css"] [unique_id "al4b0LF4957xPw9VVBmjMgAAAME"]
[Mon Jul 20 07:00:00.253804 2026] [security2:error] [pid 28702:tid 28935] [client 158.51.126.91:52548] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/wp-content/themes/wp-yellow-hats/assets/css/static.css"] [unique_id "al4b0LF4957xPw9VVBmjNAAAAOs"]
[Mon Jul 20 07:00:00.298116 2026] [security2:error] [pid 28702:tid 28865] [client 158.51.126.91:52516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.126.51.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "whiteoutcb.com"] [uri "/xmlrpc.php"] [unique_id "al4b0LF4957xPw9VVBmjLgAAAKU"]
[Mon Jul 20 07:00:00.301340 2026] [security2:error] [pid 28702:tid 28871] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0LF4957xPw9VVBmjFgAAAKs"]
[Mon Jul 20 07:00:00.319624 2026] [security2:error] [pid 28702:tid 28886] [client 45.157.112.60:31785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4b0LF4957xPw9VVBmjWwAAALo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:00:00.355944 2026] [security2:error] [pid 28702:tid 28894] [client 158.51.126.91:52522] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "whiteoutcb.com"] [uri "/wp-content/plugins/cmssuperheroes/assets/css/Pe-icon-7-stroke.css"] [unique_id "al4b0LF4957xPw9VVBmjZQAAAMI"]
[Mon Jul 20 07:00:00.367987 2026] [security2:error] [pid 28702:tid 28922] [client 117.247.108.24:58136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b0LF4957xPw9VVBmjZgAAAN4"]
[Mon Jul 20 07:00:00.368175 2026] [security2:error] [pid 28702:tid 28922] [client 117.247.108.24:58136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b0LF4957xPw9VVBmjZgAAAN4"]
[Mon Jul 20 07:00:00.482626 2026] [security2:error] [pid 28702:tid 28918] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4bz7F4957xPw9VVBmi8QAA2ic"]
[Mon Jul 20 07:00:00.699082 2026] [http2:info] [pid 29744:tid 29744] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:00:00.766426 2026] [security2:error] [pid 28702:tid 28875] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0LF4957xPw9VVBmjggAAAK8"]
[Mon Jul 20 07:00:00.845582 2026] [security2:error] [pid 28702:tid 28953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b0LF4957xPw9VVBmjgQAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:00.866109 2026] [security2:error] [pid 28702:tid 28900] [client 103.238.106.162:42941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b0LF4957xPw9VVBmjogAAAMg"]
[Mon Jul 20 07:00:00.866217 2026] [security2:error] [pid 28702:tid 28900] [client 103.238.106.162:42941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b0LF4957xPw9VVBmjogAAAMg"]
[Mon Jul 20 07:00:01.230573 2026] [security2:error] [pid 29744:tid 29747] [remote 74.7.227.179:39108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4b0eGINCUUz5GA9YIRNQACHgE"], referer: https://tejasenvironmental.com/p=2236816
[Mon Jul 20 07:00:01.355276 2026] [security2:error] [pid 28702:tid 28878] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0bF4957xPw9VVBmjuQAAALI"]
[Mon Jul 20 07:00:01.615584 2026] [security2:error] [pid 29744:tid 29918] [client 147.93.171.187:54665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/block-bindings.php"] [unique_id "al4b0eGINCUUz5GA9YIRRQAAAj8"], referer: binance.com
[Mon Jul 20 07:00:01.663531 2026] [security2:error] [pid 28702:tid 28933] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b0LF4957xPw9VVBmjkQAA6Uc"]
[Mon Jul 20 07:00:01.757102 2026] [security2:error] [pid 28702:tid 28776] [remote 103.118.29.185:39126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4b0bF4957xPw9VVBmj2QAA50g"]
[Mon Jul 20 07:00:01.807398 2026] [security2:error] [pid 28702:tid 28848] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0bF4957xPw9VVBmj1wAAAJQ"]
[Mon Jul 20 07:00:01.871503 2026] [security2:error] [pid 28702:tid 28873] [client 14.225.17.146:57397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4b0LF4957xPw9VVBmjFQAAAK0"], referer: http://reosportsboats.com/2025
[Mon Jul 20 07:00:02.199189 2026] [security2:error] [pid 28702:tid 28821] [remote 103.118.29.185:39126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4b0rF4957xPw9VVBmj-gAA5HU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:00:02.273187 2026] [security2:error] [pid 29744:tid 29921] [client 14.225.17.146:58051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4b0eGINCUUz5GA9YIRUgAAAkI"], referer: http://savilerowtravel.com/2025
[Mon Jul 20 07:00:02.377671 2026] [security2:error] [pid 29744:tid 29969] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0uGINCUUz5GA9YIRYgAAAnI"]
[Mon Jul 20 07:00:02.857016 2026] [security2:error] [pid 29744:tid 29992] [client 14.225.17.146:58254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4b0uGINCUUz5GA9YIRcwAAAok"], referer: https://reosportsboats.com/2025
[Mon Jul 20 07:00:02.862480 2026] [security2:error] [pid 28702:tid 28842] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0rF4957xPw9VVBmkEQAAAI4"]
[Mon Jul 20 07:00:02.998321 2026] [security2:error] [pid 29744:tid 29990] [client 152.58.191.29:49207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4b0uGINCUUz5GA9YIRiwAAAoc"]
[Mon Jul 20 07:00:02.998893 2026] [security2:error] [pid 29744:tid 29990] [client 152.58.191.29:49207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4b0uGINCUUz5GA9YIRiwAAAoc"]
[Mon Jul 20 07:00:03.013186 2026] [security2:error] [pid 28702:tid 28881] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b0bF4957xPw9VVBmj6AAAtTY"]
[Mon Jul 20 07:00:03.049231 2026] [security2:error] [pid 28702:tid 28863] [client 14.225.17.146:57901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4b0bF4957xPw9VVBmj1AAAAKM"], referer: http://collectingrealestate.com/2025
[Mon Jul 20 07:00:03.367423 2026] [security2:error] [pid 28702:tid 28901] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b07F4957xPw9VVBmkOgAAAMk"]
[Mon Jul 20 07:00:03.938865 2026] [security2:error] [pid 29744:tid 29943] [client 57.141.18.97:44222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b0eGINCUUz5GA9YIRUQACWAU"]
[Mon Jul 20 07:00:04.049923 2026] [security2:error] [pid 29744:tid 29916] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b0-GINCUUz5GA9YIRsQAAAj0"]
[Mon Jul 20 07:00:04.267253 2026] [security2:error] [pid 28702:tid 28890] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b07F4957xPw9VVBmkSAAAvns"]
[Mon Jul 20 07:00:04.361248 2026] [security2:error] [pid 29744:tid 29924] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b1OGINCUUz5GA9YIRtgAAAkU"]
[Mon Jul 20 07:00:04.557058 2026] [security2:error] [pid 29744:tid 29906] [client 66.249.74.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.gaantfootball.co.uk"] [uri "/index.php"] [unique_id "al4b0uGINCUUz5GA9YIRfgAAAjM"]
[Mon Jul 20 07:00:04.777167 2026] [security2:error] [pid 28702:tid 28924] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b1LF4957xPw9VVBmktwAAAOA"]
[Mon Jul 20 07:00:05.258770 2026] [security2:error] [pid 28702:tid 28843] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b1LF4957xPw9VVBmkpwAAjz8"]
[Mon Jul 20 07:00:05.285049 2026] [security2:error] [pid 29744:tid 29877] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b1eGINCUUz5GA9YIR3QAAAhY"]
[Mon Jul 20 07:00:05.609281 2026] [security2:error] [pid 29744:tid 29875] [client 117.222.139.248:58361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b1eGINCUUz5GA9YIR7wAAAhQ"]
[Mon Jul 20 07:00:05.609400 2026] [security2:error] [pid 29744:tid 29875] [client 117.222.139.248:58361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b1eGINCUUz5GA9YIR7wAAAhQ"]
[Mon Jul 20 07:00:05.787055 2026] [security2:error] [pid 28702:tid 28863] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b1bF4957xPw9VVBmk_gAAAKM"]
[Mon Jul 20 07:00:05.978132 2026] [security2:error] [pid 29744:tid 29771] [remote 62.210.185.4:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4b1eGINCUUz5GA9YIR9AACLRk"]
[Mon Jul 20 07:00:06.105153 2026] [security2:error] [pid 28702:tid 28838] [client 57.141.18.24:59674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b1LF4957xPw9VVBmkjwAAik4"]
[Mon Jul 20 07:00:06.154218 2026] [security2:error] [pid 28702:tid 28872] [client 103.144.65.217:53796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b1rF4957xPw9VVBmlIgAAAKw"]
[Mon Jul 20 07:00:06.154383 2026] [security2:error] [pid 28702:tid 28872] [client 103.144.65.217:53796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b1rF4957xPw9VVBmlIgAAAKw"]
[Mon Jul 20 07:00:06.159929 2026] [security2:error] [pid 29744:tid 29773] [remote 62.210.185.4:38918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.185.210.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4b1uGINCUUz5GA9YIR_AAChRs"], referer: https://zbj.ahr.mybluehost.me/wp-login.php
[Mon Jul 20 07:00:06.166392 2026] [security2:error] [pid 28702:tid 28900] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b1bF4957xPw9VVBmk-AAAyEo"]
[Mon Jul 20 07:00:06.198401 2026] [security2:error] [pid 29744:tid 29954] [client 57.141.18.87:32334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b1OGINCUUz5GA9YIRxQACYxE"]
[Mon Jul 20 07:00:06.277016 2026] [security2:error] [pid 29744:tid 29893] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b1uGINCUUz5GA9YIR_gAAAiY"]
[Mon Jul 20 07:00:06.282631 2026] [security2:error] [pid 28702:tid 28805] [remote 130.51.180.8:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4b1rF4957xPw9VVBmlJgAAzWU"]
[Mon Jul 20 07:00:06.573591 2026] [security2:error] [pid 29744:tid 29934] [client 104.234.53.62:58301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4b1uGINCUUz5GA9YISCQAAAk8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:06.723897 2026] [security2:error] [pid 29744:tid 29923] [client 77.110.127.138:61078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b1uGINCUUz5GA9YISEQAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:06.724041 2026] [security2:error] [pid 29744:tid 29923] [client 77.110.127.138:61078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b1uGINCUUz5GA9YISEQAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:06.751184 2026] [security2:error] [pid 28702:tid 28942] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b1rF4957xPw9VVBmlRAAAAPI"]
[Mon Jul 20 07:00:06.756945 2026] [security2:error] [pid 28702:tid 28811] [remote 130.51.180.8:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4b1rF4957xPw9VVBmlRwAAkWs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:00:06.963794 2026] [security2:error] [pid 29744:tid 29779] [remote 173.212.252.15:42376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4b1uGINCUUz5GA9YISHQACiiE"]
[Mon Jul 20 07:00:07.003444 2026] [security2:error] [pid 28702:tid 28925] [client 147.93.171.187:53845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/block-editor.php"] [unique_id "al4b17F4957xPw9VVBmlUAAAAOE"], referer: binance.com
[Mon Jul 20 07:00:07.121764 2026] [security2:error] [pid 28702:tid 28931] [client 57.141.18.17:21818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b1bF4957xPw9VVBmk8gAA5ww"]
[Mon Jul 20 07:00:07.151176 2026] [security2:error] [pid 28702:tid 28958] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b1rF4957xPw9VVBmlMgABAjU"]
[Mon Jul 20 07:00:07.238270 2026] [security2:error] [pid 29744:tid 29921] [client 50.116.65.227:32828] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4b1-GINCUUz5GA9YISNgAAAkI"]
[Mon Jul 20 07:00:07.248564 2026] [security2:error] [pid 28702:tid 28936] [client 50.116.65.227:32836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4b17F4957xPw9VVBmlVwAAAOw"]
[Mon Jul 20 07:00:07.309020 2026] [security2:error] [pid 28702:tid 28900] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b17F4957xPw9VVBmlVgAAAMg"]
[Mon Jul 20 07:00:07.341789 2026] [security2:error] [pid 29744:tid 29903] [client 13.233.207.33:22224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4b1-GINCUUz5GA9YISOQAAAjA"]
[Mon Jul 20 07:00:07.341887 2026] [security2:error] [pid 29744:tid 29903] [client 13.233.207.33:22224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4b1-GINCUUz5GA9YISOQAAAjA"]
[Mon Jul 20 07:00:07.351796 2026] [security2:error] [pid 29744:tid 29891] [client 187.16.64.216:60735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b1-GINCUUz5GA9YISOwAAAiQ"]
[Mon Jul 20 07:00:07.351908 2026] [security2:error] [pid 29744:tid 29891] [client 187.16.64.216:60735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b1-GINCUUz5GA9YISOwAAAiQ"]
[Mon Jul 20 07:00:07.504260 2026] [security2:error] [pid 28702:tid 28844] [client 57.141.18.109:25800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b1bF4957xPw9VVBmlCAAAkG8"]
[Mon Jul 20 07:00:07.753337 2026] [security2:error] [pid 28702:tid 28945] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b17F4957xPw9VVBmlbwAAAPU"]
[Mon Jul 20 07:00:07.914514 2026] [security2:error] [pid 29744:tid 29887] [client 34.73.38.214:51822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4b1-GINCUUz5GA9YISVQAAAiA"]
[Mon Jul 20 07:00:08.072478 2026] [security2:error] [pid 29744:tid 29962] [client 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4b2OGINCUUz5GA9YISXAAAAms"]
[Mon Jul 20 07:00:08.072652 2026] [security2:error] [pid 29744:tid 29962] [client 20.153.140.50:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4b2OGINCUUz5GA9YISXAAAAms"]
[Mon Jul 20 07:00:08.132000 2026] [security2:error] [pid 28702:tid 28919] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b17F4957xPw9VVBmlYQAA23k"]
[Mon Jul 20 07:00:08.239742 2026] [security2:error] [pid 29744:tid 29897] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2OGINCUUz5GA9YISXgAAAio"]
[Mon Jul 20 07:00:08.372107 2026] [security2:error] [pid 29744:tid 29967] [client 104.207.53.55:17507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b2OGINCUUz5GA9YISbwAAAnA"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:08.614771 2026] [security2:error] [pid 28702:tid 28848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b2LF4957xPw9VVBmliwAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:08.717822 2026] [security2:error] [pid 29744:tid 29971] [client 34.73.38.214:54267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4b2OGINCUUz5GA9YISfgAAAnQ"]
[Mon Jul 20 07:00:08.741139 2026] [security2:error] [pid 28702:tid 28912] [client 217.142.18.172:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4b2LF4957xPw9VVBmloQAAANQ"]
[Mon Jul 20 07:00:08.744395 2026] [security2:error] [pid 28702:tid 28912] [client 217.142.18.172:40380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4b2LF4957xPw9VVBmloQAAANQ"]
[Mon Jul 20 07:00:08.757581 2026] [security2:error] [pid 29744:tid 29883] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2OGINCUUz5GA9YISdgAAAhw"]
[Mon Jul 20 07:00:08.953129 2026] [security2:error] [pid 28702:tid 28914] [client 14.225.17.146:62555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4b2LF4957xPw9VVBmlogAAANY"], referer: http://careysheatingandcooling.com/2025
[Mon Jul 20 07:00:08.993268 2026] [security2:error] [pid 29744:tid 29913] [client 45.3.54.125:52479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b2OGINCUUz5GA9YISgAAAAjo"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:09.114856 2026] [security2:error] [pid 28702:tid 28893] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b2LF4957xPw9VVBmlkAAAwVM"]
[Mon Jul 20 07:00:09.156773 2026] [security2:error] [pid 28702:tid 28941] [client 34.73.38.214:55322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4b2bF4957xPw9VVBmltwAAAPE"]
[Mon Jul 20 07:00:09.260058 2026] [security2:error] [pid 28702:tid 28846] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2bF4957xPw9VVBmltQAAAJI"]
[Mon Jul 20 07:00:09.353797 2026] [security2:error] [pid 28702:tid 28872] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4b2bF4957xPw9VVBmluQAAAKw"]
[Mon Jul 20 07:00:09.460104 2026] [security2:error] [pid 29744:tid 29958] [client 57.141.18.11:27818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b1-GINCUUz5GA9YISTQACZyk"]
[Mon Jul 20 07:00:09.492608 2026] [security2:error] [pid 28702:tid 28850] [client 158.173.166.181:27127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4b2bF4957xPw9VVBmlwwAAAJY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:00:09.734985 2026] [security2:error] [pid 29744:tid 29917] [client 50.116.65.227:21752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4b2eGINCUUz5GA9YISrQAAAj4"]
[Mon Jul 20 07:00:09.750961 2026] [security2:error] [pid 28702:tid 28912] [client 50.116.65.227:35562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4b2bF4957xPw9VVBml1QAAANQ"]
[Mon Jul 20 07:00:09.764321 2026] [security2:error] [pid 28702:tid 28936] [client 14.225.17.146:64429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4b2bF4957xPw9VVBmlyAAAAOw"], referer: http://mtlegnews.gov/2025
[Mon Jul 20 07:00:09.805939 2026] [security2:error] [pid 29744:tid 29985] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2eGINCUUz5GA9YISpwAAAoI"]
[Mon Jul 20 07:00:09.875432 2026] [security2:error] [pid 28702:tid 28750] [remote 156.67.31.167:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4b2bF4957xPw9VVBml2gAA4S4"]
[Mon Jul 20 07:00:10.146755 2026] [security2:error] [pid 28702:tid 28914] [client 34.73.38.214:53438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4b2rF4957xPw9VVBml6QAAANY"]
[Mon Jul 20 07:00:10.150886 2026] [security2:error] [pid 28702:tid 28732] [remote 173.212.252.15:54694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4b2rF4957xPw9VVBml6gAAxBw"]
[Mon Jul 20 07:00:10.269832 2026] [security2:error] [pid 28702:tid 28848] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b2bF4957xPw9VVBmlwgAAlDw"]
[Mon Jul 20 07:00:10.342094 2026] [security2:error] [pid 29744:tid 29981] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2uGINCUUz5GA9YISvQAAAn4"]
[Mon Jul 20 07:00:10.348198 2026] [security2:error] [pid 28702:tid 28920] [client 65.111.4.32:25089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.4.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b2rF4957xPw9VVBml8QAAANw"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:10.563954 2026] [security2:error] [pid 28702:tid 28767] [remote 156.67.31.167:50556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4b2rF4957xPw9VVBmmAAAA6T8"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 07:00:10.762576 2026] [security2:error] [pid 28702:tid 28891] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2rF4957xPw9VVBmmCAAAAL8"]
[Mon Jul 20 07:00:10.849519 2026] [security2:error] [pid 29744:tid 29974] [client 34.73.38.214:56660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4b2uGINCUUz5GA9YIS3AAAAnc"]
[Mon Jul 20 07:00:10.857704 2026] [security2:error] [pid 29744:tid 29879] [client 57.141.18.69:39816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b2eGINCUUz5GA9YIShwACGDI"]
[Mon Jul 20 07:00:11.014797 2026] [security2:error] [pid 28702:tid 28918] [client 14.225.17.146:64440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4b2rF4957xPw9VVBmmGAAAANo"], referer: http://whiteoutcb.com/2025
[Mon Jul 20 07:00:11.065874 2026] [security2:error] [pid 29744:tid 29999] [client 14.225.17.146:59488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4b2eGINCUUz5GA9YISsQAAApA"], referer: http://sarahholyfield.com/2025
[Mon Jul 20 07:00:11.250088 2026] [security2:error] [pid 28702:tid 28847] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b2rF4957xPw9VVBmmAQAAkwk"]
[Mon Jul 20 07:00:11.254020 2026] [security2:error] [pid 29744:tid 29882] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b2-GINCUUz5GA9YIS5wAAAhs"]
[Mon Jul 20 07:00:11.452128 2026] [security2:error] [pid 29744:tid 29926] [client 34.73.38.214:51798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4b2-GINCUUz5GA9YIS8gAAAkc"]
[Mon Jul 20 07:00:11.754391 2026] [security2:error] [pid 28702:tid 28924] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b27F4957xPw9VVBmmNAAAAOA"]
[Mon Jul 20 07:00:11.944695 2026] [security2:error] [pid 28702:tid 28942] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4b27F4957xPw9VVBmmHQAAAPI"]
[Mon Jul 20 07:00:11.952228 2026] [security2:error] [pid 28702:tid 28914] [client 3.85.28.216:65224] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/puerto-rican-meatballs-in-sofrito-sauce-recipe/"] [unique_id "al4b27F4957xPw9VVBmmGwAAANY"]
[Mon Jul 20 07:00:11.960865 2026] [security2:error] [pid 29744:tid 29897] [client 103.238.106.162:60988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b2-GINCUUz5GA9YITEgAAAio"]
[Mon Jul 20 07:00:11.960990 2026] [security2:error] [pid 29744:tid 29897] [client 103.238.106.162:60988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b2-GINCUUz5GA9YITEgAAAio"]
[Mon Jul 20 07:00:11.998947 2026] [security2:error] [pid 29744:tid 29977] [client 147.93.171.187:52955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/block-template-utils.php"] [unique_id "al4b2-GINCUUz5GA9YITEwAAAno"], referer: binance.com
[Mon Jul 20 07:00:12.193501 2026] [security2:error] [pid 29744:tid 29947] [client 34.73.38.214:57963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4b3OGINCUUz5GA9YITIAAAAlw"]
[Mon Jul 20 07:00:12.229439 2026] [security2:error] [pid 28702:tid 28861] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b27F4957xPw9VVBmmLQAAoU4"]
[Mon Jul 20 07:00:12.245429 2026] [security2:error] [pid 29744:tid 29890] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b3OGINCUUz5GA9YITHQAAAiM"]
[Mon Jul 20 07:00:12.270228 2026] [security2:error] [pid 29744:tid 29930] [client 14.224.227.113:54845] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4b3OGINCUUz5GA9YITIgAAAks"]
[Mon Jul 20 07:00:12.613736 2026] [security2:error] [pid 29744:tid 29939] [client 74.7.241.133:45666] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "nandansonscharitablefoundation.com"] [uri "/robots.txt"] [unique_id "al4b3OGINCUUz5GA9YITMAAAAlQ"]
[Mon Jul 20 07:00:12.670656 2026] [security2:error] [pid 29744:tid 30000] [client 117.247.108.24:53029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b3OGINCUUz5GA9YITMgAAApE"]
[Mon Jul 20 07:00:12.670884 2026] [security2:error] [pid 29744:tid 30000] [client 117.247.108.24:53029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b3OGINCUUz5GA9YITMgAAApE"]
[Mon Jul 20 07:00:12.771709 2026] [security2:error] [pid 28702:tid 28916] [client 74.7.241.133:47112] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nandansonscharitablefoundation.com"] [uri "/robots.txt"] [unique_id "al4b3LF4957xPw9VVBmmcQAA2Ek"], referer: http://nandansonscharitablefoundation.com/robots.txt
[Mon Jul 20 07:00:12.781959 2026] [security2:error] [pid 28702:tid 28847] [client 45.3.42.95:11323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b3LF4957xPw9VVBmmcwAAAJM"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:12.784205 2026] [security2:error] [pid 29744:tid 29884] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b3OGINCUUz5GA9YITMwAAAh0"]
[Mon Jul 20 07:00:12.804159 2026] [security2:error] [pid 29744:tid 29885] [client 35.180.166.19:60356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4b3OGINCUUz5GA9YITNwAAAh4"]
[Mon Jul 20 07:00:12.804277 2026] [security2:error] [pid 29744:tid 29885] [client 35.180.166.19:60356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4b3OGINCUUz5GA9YITNwAAAh4"]
[Mon Jul 20 07:00:13.058906 2026] [security2:error] [pid 29744:tid 29979] [client 34.73.38.214:54101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4b3eGINCUUz5GA9YITTwAAAnw"]
[Mon Jul 20 07:00:13.235033 2026] [security2:error] [pid 28702:tid 28948] [client 14.225.17.146:64742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4b3bF4957xPw9VVBmmfQAAAPg"], referer: http://recruitinginsight.us/2025
[Mon Jul 20 07:00:13.280623 2026] [security2:error] [pid 28702:tid 28912] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b3bF4957xPw9VVBmmgAAAANQ"]
[Mon Jul 20 07:00:13.293126 2026] [security2:error] [pid 29744:tid 29983] [client 14.225.17.146:60658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4b2-GINCUUz5GA9YIS-AAAAoA"], referer: http://mobilesurvsolutions.com/2025
[Mon Jul 20 07:00:13.371841 2026] [security2:error] [pid 28702:tid 28939] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b3LF4957xPw9VVBmmbgAA70w"]
[Mon Jul 20 07:00:13.732797 2026] [security2:error] [pid 29744:tid 29972] [client 104.234.53.51:48331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4b3eGINCUUz5GA9YITbwAAAnU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:13.749797 2026] [security2:error] [pid 28702:tid 28841] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b3bF4957xPw9VVBmmlwAAAI0"]
[Mon Jul 20 07:00:13.830351 2026] [security2:error] [pid 29744:tid 29918] [client 34.73.38.214:53825] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4b3eGINCUUz5GA9YITewAAAj8"]
[Mon Jul 20 07:00:13.834327 2026] [security2:error] [pid 29744:tid 29924] [client 77.110.127.138:61111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b3eGINCUUz5GA9YITfAAAAkU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:13.834418 2026] [security2:error] [pid 29744:tid 29924] [client 77.110.127.138:61111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b3eGINCUUz5GA9YITfAAAAkU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:13.892884 2026] [security2:error] [pid 28702:tid 28723] [remote 216.73.216.55:2220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4b3bF4957xPw9VVBmmnQAA-hM"]
[Mon Jul 20 07:00:13.956203 2026] [security2:error] [pid 29744:tid 29914] [client 152.58.191.29:49945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4b3eGINCUUz5GA9YIThgAAAjs"]
[Mon Jul 20 07:00:13.960817 2026] [security2:error] [pid 29744:tid 29914] [client 152.58.191.29:49945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4b3eGINCUUz5GA9YIThgAAAjs"]
[Mon Jul 20 07:00:14.187970 2026] [security2:error] [pid 29744:tid 29886] [client 104.207.53.147:48009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4b3uGINCUUz5GA9YITlgAAAh8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:14.233200 2026] [security2:error] [pid 29744:tid 29932] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b3uGINCUUz5GA9YITjgAAAk0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:14.259035 2026] [security2:error] [pid 29744:tid 29952] [client 57.141.18.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4b3uGINCUUz5GA9YITlAAAAmE"]
[Mon Jul 20 07:00:14.267332 2026] [security2:error] [pid 29744:tid 29951] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b3uGINCUUz5GA9YITlQAAAmA"]
[Mon Jul 20 07:00:14.466791 2026] [security2:error] [pid 28702:tid 28959] [client 185.155.233.254:42148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4b3rF4957xPw9VVBmmtAAAAQM"], referer: https://recruitinginsight.us/2022/06/27/the-importance-of-second-impressions/
[Mon Jul 20 07:00:14.660420 2026] [security2:error] [pid 28702:tid 28845] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b3bF4957xPw9VVBmmogAAkVY"]
[Mon Jul 20 07:00:14.738399 2026] [security2:error] [pid 28702:tid 28781] [remote 72.167.132.114:35886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4b3rF4957xPw9VVBmmyAAAv00"]
[Mon Jul 20 07:00:14.815433 2026] [security2:error] [pid 29744:tid 29947] [client 34.73.38.214:60192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4b3uGINCUUz5GA9YITuAAAAlw"]
[Mon Jul 20 07:00:14.826819 2026] [security2:error] [pid 28702:tid 28890] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b3rF4957xPw9VVBmmxwAAAL4"]
[Mon Jul 20 07:00:14.952343 2026] [security2:error] [pid 28702:tid 28810] [remote 72.167.132.114:35886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4b3rF4957xPw9VVBmm2AAAoWo"], referer: https://thechancersband.com/wp-login.php
[Mon Jul 20 07:00:15.090127 2026] [lsapi:warn] [pid 29744:tid 29903] [client 14.225.17.146:52608] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2025
[Mon Jul 20 07:00:15.090151 2026] [lsapi:warn] [pid 29744:tid 29903] [client 14.225.17.146:52608] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2025
[Mon Jul 20 07:00:15.247527 2026] [security2:error] [pid 28702:tid 28908] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b37F4957xPw9VVBmm3QAAANA"]
[Mon Jul 20 07:00:15.284036 2026] [security2:error] [pid 29744:tid 29993] [client 104.234.53.80:51501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4b3-GINCUUz5GA9YITxgAAAoo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:15.413272 2026] [security2:error] [pid 29744:tid 29955] [client 57.141.18.119:65210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b3eGINCUUz5GA9YITjAACZFk"]
[Mon Jul 20 07:00:15.644707 2026] [lsapi:warn] [pid 28702:tid 28927] [client 50.116.65.227:35690] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:00:15.644731 2026] [lsapi:warn] [pid 28702:tid 28927] [client 50.116.65.227:35690] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:00:15.661801 2026] [security2:error] [pid 29744:tid 29903] [client 14.225.17.146:52608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4b3uGINCUUz5GA9YITrwAAAjA"], referer: http://oswegooperatheater.com/2025
[Mon Jul 20 07:00:15.719088 2026] [security2:error] [pid 28702:tid 28960] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b37F4957xPw9VVBmm2gABBGY"]
[Mon Jul 20 07:00:15.751484 2026] [security2:error] [pid 28702:tid 28840] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b37F4957xPw9VVBmm8gAAAIw"]
[Mon Jul 20 07:00:15.830501 2026] [security2:error] [pid 29744:tid 29982] [client 4.204.201.85:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "almaz-aura.com"] [uri "/.well-known/about.php"] [unique_id "al4b3-GINCUUz5GA9YIT4wAAAn8"]
[Mon Jul 20 07:00:15.830622 2026] [security2:error] [pid 29744:tid 29982] [client 4.204.201.85:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "almaz-aura.com"] [uri "/.well-known/about.php"] [unique_id "al4b3-GINCUUz5GA9YIT4wAAAn8"]
[Mon Jul 20 07:00:16.001036 2026] [security2:error] [pid 29744:tid 29919] [client 34.73.38.214:51725] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4b4OGINCUUz5GA9YIT8QAAAkA"]
[Mon Jul 20 07:00:16.113429 2026] [security2:error] [pid 28702:tid 28948] [client 43.205.139.3:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4b4LF4957xPw9VVBmnCAAAAPg"]
[Mon Jul 20 07:00:16.113519 2026] [security2:error] [pid 28702:tid 28948] [client 43.205.139.3:65218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4b4LF4957xPw9VVBmnCAAAAPg"]
[Mon Jul 20 07:00:16.168077 2026] [security2:error] [pid 28702:tid 28913] [client 117.222.139.248:58875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b4LF4957xPw9VVBmnCgAAANU"]
[Mon Jul 20 07:00:16.168198 2026] [security2:error] [pid 28702:tid 28913] [client 117.222.139.248:58875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b4LF4957xPw9VVBmnCgAAANU"]
[Mon Jul 20 07:00:16.252580 2026] [security2:error] [pid 28702:tid 28939] [client 57.141.18.0:50888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b3rF4957xPw9VVBmmzwAA71c"]
[Mon Jul 20 07:00:16.252853 2026] [security2:error] [pid 29744:tid 29886] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4OGINCUUz5GA9YIT_gAAAh8"]
[Mon Jul 20 07:00:16.340459 2026] [security2:error] [pid 29744:tid 29970] [client 104.207.52.68:33897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b4OGINCUUz5GA9YIUAAAAAnM"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:16.374721 2026] [security2:error] [pid 29744:tid 29851] [remote 20.153.140.50:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4b4OGINCUUz5GA9YIUAQACJWk"]
[Mon Jul 20 07:00:16.525495 2026] [lsapi:warn] [pid 29744:tid 29969] [client 14.225.17.146:52332] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2025
[Mon Jul 20 07:00:16.525512 2026] [lsapi:warn] [pid 29744:tid 29969] [client 14.225.17.146:52332] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2025
[Mon Jul 20 07:00:16.576284 2026] [security2:error] [pid 29744:tid 29969] [client 14.225.17.146:52332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4b4OGINCUUz5GA9YIUCAAAAnI"], referer: https://oswegooperatheater.com/2025
[Mon Jul 20 07:00:16.670444 2026] [security2:error] [pid 29744:tid 29901] [client 103.144.65.217:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b4OGINCUUz5GA9YIUDgAAAi4"]
[Mon Jul 20 07:00:16.670888 2026] [security2:error] [pid 29744:tid 29901] [client 103.144.65.217:54230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b4OGINCUUz5GA9YIUDgAAAi4"]
[Mon Jul 20 07:00:16.750507 2026] [security2:error] [pid 28702:tid 28897] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4LF4957xPw9VVBmnIwAAAMU"]
[Mon Jul 20 07:00:16.769797 2026] [security2:error] [pid 29744:tid 29853] [remote 20.153.140.50:35970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4b4OGINCUUz5GA9YIUEQACf2s"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 07:00:16.936829 2026] [security2:error] [pid 28702:tid 28842] [client 65.111.22.39:44823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b4LF4957xPw9VVBmnMQAAAI4"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:17.016222 2026] [security2:error] [pid 28702:tid 28944] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b4LF4957xPw9VVBmnEQAA9AI"]
[Mon Jul 20 07:00:17.253552 2026] [security2:error] [pid 28702:tid 28892] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4bF4957xPw9VVBmnQgAAAMA"]
[Mon Jul 20 07:00:17.457467 2026] [proxy:error] [pid 29744:tid 29967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:17.457524 2026] [proxy_http:error] [pid 29744:tid 29967] [client 167.71.75.215:34464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:17.458807 2026] [proxy:error] [pid 29744:tid 29967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:17.458842 2026] [proxy_http:error] [pid 29744:tid 29967] [client 167.71.75.215:34464] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:17.531902 2026] [security2:error] [pid 29744:tid 29890] [client 147.93.171.187:53719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/block-template.php"] [unique_id "al4b4eGINCUUz5GA9YIUMQAAAiM"], referer: binance.com
[Mon Jul 20 07:00:17.733280 2026] [security2:error] [pid 29744:tid 29898] [client 34.73.38.214:57173] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4b4eGINCUUz5GA9YIUPgAAAis"]
[Mon Jul 20 07:00:17.746827 2026] [proxy:error] [pid 29744:tid 29978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:17.746882 2026] [proxy_http:error] [pid 29744:tid 29978] [client 167.71.75.215:34474] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.eliteeventsleaders.com/
[Mon Jul 20 07:00:17.747598 2026] [proxy:error] [pid 29744:tid 29978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:17.747627 2026] [proxy_http:error] [pid 29744:tid 29978] [client 167.71.75.215:34474] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.eliteeventsleaders.com/
[Mon Jul 20 07:00:17.766720 2026] [security2:error] [pid 29744:tid 29900] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4eGINCUUz5GA9YIUPAAAAi0"]
[Mon Jul 20 07:00:17.786375 2026] [security2:error] [pid 29744:tid 29876] [client 104.207.50.194:41617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4b4eGINCUUz5GA9YIUPwAAAhU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:17.863676 2026] [security2:error] [pid 29744:tid 29995] [client 14.225.17.146:53258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4b4eGINCUUz5GA9YIUKwAAAow"]
[Mon Jul 20 07:00:18.007184 2026] [security2:error] [pid 29744:tid 29976] [client 187.16.64.216:61258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b4uGINCUUz5GA9YIUUQAAAnk"]
[Mon Jul 20 07:00:18.007301 2026] [security2:error] [pid 29744:tid 29976] [client 187.16.64.216:61258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b4uGINCUUz5GA9YIUUQAAAnk"]
[Mon Jul 20 07:00:18.070483 2026] [security2:error] [pid 28702:tid 28910] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b4bF4957xPw9VVBmnVAAA0j0"]
[Mon Jul 20 07:00:18.198256 2026] [security2:error] [pid 29744:tid 29962] [client 50.116.65.227:35738] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4b4uGINCUUz5GA9YIUWgAAAms"]
[Mon Jul 20 07:00:18.210001 2026] [security2:error] [pid 29744:tid 29957] [client 50.116.65.227:35752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4b4uGINCUUz5GA9YIUXQAAAmY"]
[Mon Jul 20 07:00:18.257091 2026] [security2:error] [pid 29744:tid 29915] [client 57.141.18.113:20580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b4eGINCUUz5GA9YIUHAACPGw"]
[Mon Jul 20 07:00:18.279021 2026] [security2:error] [pid 29744:tid 29984] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4uGINCUUz5GA9YIUWQAAAoE"]
[Mon Jul 20 07:00:18.320239 2026] [proxy:error] [pid 29744:tid 29916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:18.320313 2026] [proxy_http:error] [pid 29744:tid 29916] [client 167.71.75.215:45306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:18.320810 2026] [security2:error] [pid 29744:tid 29933] [client 57.141.18.69:53342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b4eGINCUUz5GA9YIUIAACTm0"]
[Mon Jul 20 07:00:18.321037 2026] [proxy:error] [pid 29744:tid 29916] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:18.321071 2026] [proxy_http:error] [pid 29744:tid 29916] [client 167.71.75.215:45306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:18.331671 2026] [autoindex:error] [pid 29744:tid 29972] [client 123.207.65.62:52562] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:00:18.343134 2026] [security2:error] [pid 28702:tid 28943] [client 14.225.17.146:52365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4b4LF4957xPw9VVBmnIQAAAPM"], referer: http://according2plant.com/2025
[Mon Jul 20 07:00:18.687695 2026] [security2:error] [pid 29744:tid 29864] [remote 100.42.189.89:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4b4uGINCUUz5GA9YIUeQACUnY"]
[Mon Jul 20 07:00:18.750148 2026] [security2:error] [pid 29744:tid 29912] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4uGINCUUz5GA9YIUeAAAAjk"]
[Mon Jul 20 07:00:18.854228 2026] [security2:error] [pid 29744:tid 29935] [client 57.141.18.33:20530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b4eGINCUUz5GA9YIUPQACUHI"]
[Mon Jul 20 07:00:18.906111 2026] [security2:error] [pid 29744:tid 29868] [remote 100.42.189.89:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4b4uGINCUUz5GA9YIUiAACcHo"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 07:00:19.074074 2026] [security2:error] [pid 28702:tid 28854] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b4rF4957xPw9VVBmndwAAmkQ"]
[Mon Jul 20 07:00:19.087017 2026] [security2:error] [pid 29744:tid 29871] [remote 152.228.213.32:40750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4b4-GINCUUz5GA9YIUkwACFn0"]
[Mon Jul 20 07:00:19.274280 2026] [security2:error] [pid 29744:tid 29746] [remote 152.228.213.32:40750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4b4-GINCUUz5GA9YIUoAACUwA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:00:19.275728 2026] [security2:error] [pid 29744:tid 29923] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b4-GINCUUz5GA9YIUmQAAAkQ"]
[Mon Jul 20 07:00:19.365127 2026] [security2:error] [pid 29744:tid 29998] [client 217.142.18.172:31962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.18.142.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4b4-GINCUUz5GA9YIUoQAAAo8"]
[Mon Jul 20 07:00:19.365230 2026] [security2:error] [pid 29744:tid 29998] [client 217.142.18.172:31962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4b4-GINCUUz5GA9YIUoQAAAo8"]
[Mon Jul 20 07:00:19.447085 2026] [security2:error] [pid 29744:tid 29981] [client 77.110.127.138:61150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b4-GINCUUz5GA9YIUpAAAAn4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:19.447177 2026] [security2:error] [pid 29744:tid 29981] [client 77.110.127.138:61150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b4-GINCUUz5GA9YIUpAAAAn4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:19.736092 2026] [security2:error] [pid 29744:tid 29919] [client 5.161.73.160:64284] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4b4-GINCUUz5GA9YIUsQAAAkA"], referer: https://windowtx.com
[Mon Jul 20 07:00:19.750690 2026] [security2:error] [pid 28702:tid 28838] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b47F4957xPw9VVBmnswAAAIo"]
[Mon Jul 20 07:00:19.881869 2026] [security2:error] [pid 29744:tid 29896] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b4-GINCUUz5GA9YIUrQAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:20.075759 2026] [security2:error] [pid 28702:tid 28954] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b47F4957xPw9VVBmnmwAA_m0"]
[Mon Jul 20 07:00:20.208286 2026] [security2:error] [pid 29744:tid 29996] [client 183.82.98.154:61695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4b5OGINCUUz5GA9YIUyQAAAo0"]
[Mon Jul 20 07:00:20.208522 2026] [security2:error] [pid 29744:tid 29996] [client 183.82.98.154:61695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4b5OGINCUUz5GA9YIUyQAAAo0"]
[Mon Jul 20 07:00:20.288641 2026] [security2:error] [pid 29744:tid 29931] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5OGINCUUz5GA9YIUxgAAAkw"]
[Mon Jul 20 07:00:20.422485 2026] [security2:error] [pid 28702:tid 28810] [remote 173.212.252.15:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4b5LF4957xPw9VVBmn3QAA92o"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 07:00:20.456516 2026] [security2:error] [pid 28702:tid 28856] [client 122.183.32.225:6953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4b5LF4957xPw9VVBmn3wAAAJw"]
[Mon Jul 20 07:00:20.456618 2026] [security2:error] [pid 28702:tid 28856] [client 122.183.32.225:6953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4b5LF4957xPw9VVBmn3wAAAJw"]
[Mon Jul 20 07:00:20.457753 2026] [security2:error] [pid 28702:tid 28901] [client 65.111.3.175:63803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.3.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b5LF4957xPw9VVBmn3gAAAMk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:20.544965 2026] [security2:error] [pid 29744:tid 29988] [client 14.225.17.146:60474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4b5OGINCUUz5GA9YIUzAAAAoU"], referer: http://thesoloceos.com/2025
[Mon Jul 20 07:00:20.762596 2026] [security2:error] [pid 28702:tid 28855] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5LF4957xPw9VVBmn6AAAAJs"]
[Mon Jul 20 07:00:21.085283 2026] [security2:error] [pid 29744:tid 29917] [client 14.225.17.146:64391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4b4-GINCUUz5GA9YIUrwAAAj4"], referer: http://dadanetnet.net/2025
[Mon Jul 20 07:00:21.209347 2026] [security2:error] [pid 29744:tid 29751] [remote 193.70.112.205:49142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4b5eGINCUUz5GA9YIU_AACTQU"]
[Mon Jul 20 07:00:21.209624 2026] [security2:error] [pid 29744:tid 29932] [client 193.70.112.205:49142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4b5eGINCUUz5GA9YIU_AACTQU"]
[Mon Jul 20 07:00:21.267765 2026] [security2:error] [pid 29744:tid 29996] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5eGINCUUz5GA9YIU-QAAAo0"]
[Mon Jul 20 07:00:21.272627 2026] [security2:error] [pid 28702:tid 28944] [client 65.111.11.231:38619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.11.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b5bF4957xPw9VVBmoAwAAAPQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:21.376817 2026] [security2:error] [pid 29744:tid 29962] [client 45.3.42.99:18175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4b5eGINCUUz5GA9YIVAgAAAms"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:21.441190 2026] [security2:error] [pid 28702:tid 28869] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b5LF4957xPw9VVBmn7gAAqVo"]
[Mon Jul 20 07:00:21.503204 2026] [security2:error] [pid 29744:tid 29889] [client 57.141.18.7:37080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b5OGINCUUz5GA9YIUywACIgo"]
[Mon Jul 20 07:00:21.529674 2026] [security2:error] [pid 28702:tid 28848] [client 50.116.65.227:49410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4b5bF4957xPw9VVBmoDwAAAJQ"]
[Mon Jul 20 07:00:21.593735 2026] [security2:error] [pid 29744:tid 29915] [client 14.225.17.146:49573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4b5eGINCUUz5GA9YIVAwAAAjw"], referer: https://thesoloceos.com/2025
[Mon Jul 20 07:00:21.754504 2026] [security2:error] [pid 28702:tid 28839] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5bF4957xPw9VVBmoHwAAAIs"]
[Mon Jul 20 07:00:21.809211 2026] [proxy:error] [pid 29744:tid 29914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:21.809314 2026] [proxy_http:error] [pid 29744:tid 29914] [client 167.71.75.215:56972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.eliteeventsleaders.com/
[Mon Jul 20 07:00:21.810661 2026] [proxy:error] [pid 29744:tid 29914] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:21.810728 2026] [proxy_http:error] [pid 29744:tid 29914] [client 167.71.75.215:56972] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.eliteeventsleaders.com/
[Mon Jul 20 07:00:21.838032 2026] [security2:error] [pid 29744:tid 29908] [client 14.225.17.146:56523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4b5eGINCUUz5GA9YIVBwAAAjU"]
[Mon Jul 20 07:00:21.933415 2026] [security2:error] [pid 29744:tid 29902] [client 117.247.108.24:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b5eGINCUUz5GA9YIVDgAAAi8"]
[Mon Jul 20 07:00:21.933561 2026] [security2:error] [pid 29744:tid 29902] [client 117.247.108.24:59926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b5eGINCUUz5GA9YIVDgAAAi8"]
[Mon Jul 20 07:00:21.985396 2026] [security2:error] [pid 29744:tid 29951] [client 14.225.17.146:65379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4b5eGINCUUz5GA9YIVBgAAAmA"], referer: http://entuvy.com/2025
[Mon Jul 20 07:00:22.024448 2026] [security2:error] [pid 28702:tid 28941] [client 85.208.96.199:51814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4b5rF4957xPw9VVBmoMQAAAPE"]
[Mon Jul 20 07:00:22.024589 2026] [security2:error] [pid 28702:tid 28941] [client 85.208.96.199:51814] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/robots.txt"] [unique_id "al4b5rF4957xPw9VVBmoMQAAAPE"]
[Mon Jul 20 07:00:22.073126 2026] [security2:error] [pid 29744:tid 29986] [client 84.54.44.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4b5eGINCUUz5GA9YIVBQAAAoM"], referer: https://blog.danwolfe.us/2021/02/18/we-have-landed/#comment-41471
[Mon Jul 20 07:00:22.100619 2026] [security2:error] [pid 29744:tid 29892] [client 185.155.233.254:43590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4b5uGINCUUz5GA9YIVEgAAAiU"], referer: https://recruitinginsight.us/2022/06/27/the-importance-of-second-impressions/
[Mon Jul 20 07:00:22.100653 2026] [security2:error] [pid 29744:tid 29892] [client 185.155.233.254:43590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/xmlrpc.php"] [unique_id "al4b5uGINCUUz5GA9YIVEgAAAiU"], referer: https://recruitinginsight.us/2022/06/27/the-importance-of-second-impressions/
[Mon Jul 20 07:00:22.135857 2026] [security2:error] [pid 28702:tid 28936] [client 14.225.17.146:61138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4b5LF4957xPw9VVBmn6wAAAOw"], referer: http://bbwipartnerconference.com/2025
[Mon Jul 20 07:00:22.154920 2026] [security2:error] [pid 28702:tid 28852] [client 147.93.171.187:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-avif-info.php"] [unique_id "al4b5rF4957xPw9VVBmoPgAAAJg"], referer: binance.com
[Mon Jul 20 07:00:22.216585 2026] [core:error] [pid 28702:tid 28943] [client 14.225.17.146:60794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:00:22.216605 2026] [core:error] [pid 28702:tid 28943] [client 14.225.17.146:60794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:00:22.273955 2026] [security2:error] [pid 28702:tid 28916] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5rF4957xPw9VVBmoPwAAANg"]
[Mon Jul 20 07:00:22.336719 2026] [security2:error] [pid 29744:tid 29913] [client 185.191.171.17:52154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/is-acrylic-sealer-food-safe-what-you-need-to-know/"] [unique_id "al4b5uGINCUUz5GA9YIVHAAAAjo"]
[Mon Jul 20 07:00:22.336880 2026] [security2:error] [pid 29744:tid 29913] [client 185.191.171.17:52154] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/is-acrylic-sealer-food-safe-what-you-need-to-know/"] [unique_id "al4b5uGINCUUz5GA9YIVHAAAAjo"]
[Mon Jul 20 07:00:22.483501 2026] [security2:error] [pid 28702:tid 28911] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b5bF4957xPw9VVBmoJQAA0wY"]
[Mon Jul 20 07:00:22.508997 2026] [security2:error] [pid 29744:tid 29900] [client 14.225.17.146:61029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4b5uGINCUUz5GA9YIVIAAAAi0"], referer: http://ravmike.com/2025
[Mon Jul 20 07:00:22.528041 2026] [security2:error] [pid 28702:tid 28867] [client 103.238.106.162:60646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b5rF4957xPw9VVBmoVAAAAKc"]
[Mon Jul 20 07:00:22.528151 2026] [security2:error] [pid 28702:tid 28867] [client 103.238.106.162:60646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b5rF4957xPw9VVBmoVAAAAKc"]
[Mon Jul 20 07:00:22.785634 2026] [security2:error] [pid 29744:tid 29989] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5uGINCUUz5GA9YIVJAAAAoY"]
[Mon Jul 20 07:00:23.096345 2026] [proxy:error] [pid 29744:tid 29977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:23.096419 2026] [proxy_http:error] [pid 29744:tid 29977] [client 143.244.57.86:52452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:23.097051 2026] [proxy:error] [pid 29744:tid 29977] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:23.097080 2026] [proxy_http:error] [pid 29744:tid 29977] [client 143.244.57.86:52452] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:23.275710 2026] [security2:error] [pid 28702:tid 28943] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b57F4957xPw9VVBmodwAAAPM"]
[Mon Jul 20 07:00:23.403874 2026] [security2:error] [pid 29744:tid 29923] [client 14.225.17.146:60517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4b5-GINCUUz5GA9YIVQgAAAkQ"], referer: https://ravmike.com/2025
[Mon Jul 20 07:00:23.409315 2026] [proxy:error] [pid 29744:tid 29986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:23.409389 2026] [proxy_http:error] [pid 29744:tid 29986] [client 143.244.57.86:52468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:23.410130 2026] [proxy:error] [pid 29744:tid 29986] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:23.410161 2026] [proxy_http:error] [pid 29744:tid 29986] [client 143.244.57.86:52468] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:23.527539 2026] [security2:error] [pid 29744:tid 29953] [client 57.141.18.122:43048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b5uGINCUUz5GA9YIVGwACYg8"]
[Mon Jul 20 07:00:23.705314 2026] [security2:error] [pid 29744:tid 29917] [client 143.244.57.86:52482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4b5-GINCUUz5GA9YIVWwAAAj4"]
[Mon Jul 20 07:00:23.757519 2026] [security2:error] [pid 29744:tid 29983] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b5-GINCUUz5GA9YIVVwAAAoA"]
[Mon Jul 20 07:00:23.957676 2026] [security2:error] [pid 28702:tid 28910] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b57F4957xPw9VVBmoegAA0ms"]
[Mon Jul 20 07:00:23.995023 2026] [proxy:error] [pid 29744:tid 29985] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:23.995104 2026] [proxy_http:error] [pid 29744:tid 29985] [client 143.244.57.86:56620] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:23.995710 2026] [proxy:error] [pid 29744:tid 29985] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:23.995737 2026] [proxy_http:error] [pid 29744:tid 29985] [client 143.244.57.86:56620] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:24.247718 2026] [security2:error] [pid 28702:tid 28838] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6LF4957xPw9VVBmomgAAAIo"]
[Mon Jul 20 07:00:24.296500 2026] [security2:error] [pid 29744:tid 29963] [client 143.244.57.86:56624] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4b6OGINCUUz5GA9YIVfwAAAmw"]
[Mon Jul 20 07:00:24.592513 2026] [security2:error] [pid 28702:tid 28883] [client 143.244.57.86:56638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4b6LF4957xPw9VVBmoqgAAALc"]
[Mon Jul 20 07:00:24.762000 2026] [security2:error] [pid 29744:tid 29952] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6OGINCUUz5GA9YIVjAAAAmE"]
[Mon Jul 20 07:00:24.832607 2026] [security2:error] [pid 29744:tid 29784] [remote 113.160.142.119:38442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4b6OGINCUUz5GA9YIVkwACdCY"]
[Mon Jul 20 07:00:24.883537 2026] [security2:error] [pid 29744:tid 29934] [client 143.244.57.86:56640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4b6OGINCUUz5GA9YIVlgAAAk8"]
[Mon Jul 20 07:00:24.912216 2026] [security2:error] [pid 28702:tid 28919] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b6LF4957xPw9VVBmonwAA224"]
[Mon Jul 20 07:00:25.131407 2026] [security2:error] [pid 28702:tid 28933] [client 104.234.53.92:64455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4b6bF4957xPw9VVBmoxQAAAOk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:25.173768 2026] [security2:error] [pid 29744:tid 29912] [client 143.244.57.86:56654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4b6eGINCUUz5GA9YIVrQAAAjk"]
[Mon Jul 20 07:00:25.251211 2026] [security2:error] [pid 29744:tid 29953] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6eGINCUUz5GA9YIVqgAAAmI"]
[Mon Jul 20 07:00:25.312598 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:61169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b6eGINCUUz5GA9YIVsQAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:25.312719 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:61169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b6eGINCUUz5GA9YIVsQAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:25.352539 2026] [security2:error] [pid 29744:tid 29792] [remote 113.160.142.119:38442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4b6eGINCUUz5GA9YIVsgACIi4"], referer: https://technicalseohouse.com/wp-login.php
[Mon Jul 20 07:00:25.386274 2026] [security2:error] [pid 29744:tid 29795] [remote 57.141.18.57:49208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3359665"] [unique_id "al4b6eGINCUUz5GA9YIVswACiDE"]
[Mon Jul 20 07:00:25.404388 2026] [security2:error] [pid 29744:tid 29994] [client 192.140.149.97:45150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4b6eGINCUUz5GA9YIVtAAAAos"]
[Mon Jul 20 07:00:25.404647 2026] [security2:error] [pid 29744:tid 29994] [client 192.140.149.97:45150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4b6eGINCUUz5GA9YIVtAAAAos"]
[Mon Jul 20 07:00:25.466146 2026] [security2:error] [pid 29744:tid 29978] [client 143.244.57.86:56658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4b6eGINCUUz5GA9YIVuQAAAns"]
[Mon Jul 20 07:00:25.552909 2026] [security2:error] [pid 29744:tid 29960] [client 57.141.18.72:58926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b6OGINCUUz5GA9YIVcwACaSU"]
[Mon Jul 20 07:00:25.760862 2026] [security2:error] [pid 29744:tid 29943] [client 143.244.57.86:56674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4b6eGINCUUz5GA9YIVyAAAAlg"]
[Mon Jul 20 07:00:25.821924 2026] [security2:error] [pid 28702:tid 28930] [client 14.225.17.146:61003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4b6LF4957xPw9VVBmowgAAAOY"], referer: http://processorstudio.com/2025
[Mon Jul 20 07:00:25.843568 2026] [security2:error] [pid 28702:tid 28904] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6bF4957xPw9VVBmo3gAAAMw"]
[Mon Jul 20 07:00:26.060272 2026] [security2:error] [pid 28702:tid 28903] [client 143.244.57.86:56680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4b6rF4957xPw9VVBmo7AAAAMs"]
[Mon Jul 20 07:00:26.075108 2026] [security2:error] [pid 28702:tid 28914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b6bF4957xPw9VVBmo0gAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:26.108602 2026] [security2:error] [pid 29744:tid 29883] [client 147.93.171.187:61612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "al4b6uGINCUUz5GA9YIV4wAAAhw"], referer: binance.com
[Mon Jul 20 07:00:26.130565 2026] [security2:error] [pid 29744:tid 29884] [client 98.159.234.160:46783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4b6uGINCUUz5GA9YIV5gAAAh0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:00:26.135142 2026] [security2:error] [pid 28702:tid 28910] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b6bF4957xPw9VVBmo0QAA0jk"]
[Mon Jul 20 07:00:26.206272 2026] [security2:error] [pid 29744:tid 29988] [client 14.225.17.146:60984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIV3wAAAoU"], referer: http://ivetstrategies.com/2025
[Mon Jul 20 07:00:26.288222 2026] [security2:error] [pid 29744:tid 29938] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIV5wAAAlM"]
[Mon Jul 20 07:00:26.357972 2026] [security2:error] [pid 29744:tid 29930] [client 143.244.57.86:56682] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4b6uGINCUUz5GA9YIV8gAAAks"]
[Mon Jul 20 07:00:26.478838 2026] [security2:error] [pid 29744:tid 29889] [client 14.225.17.146:60402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIV8QAAAiI"], referer: http://chestermonty.com/2025
[Mon Jul 20 07:00:26.649480 2026] [security2:error] [pid 29744:tid 29984] [client 143.244.57.86:56690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4b6uGINCUUz5GA9YIV_QAAAoE"]
[Mon Jul 20 07:00:26.684430 2026] [security2:error] [pid 29744:tid 29888] [client 14.225.17.146:63862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIV_gAAAiE"], referer: https://processorstudio.com/2025
[Mon Jul 20 07:00:26.739626 2026] [security2:error] [pid 29744:tid 29982] [client 117.222.139.248:59384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b6uGINCUUz5GA9YIWBgAAAn8"]
[Mon Jul 20 07:00:26.739734 2026] [security2:error] [pid 29744:tid 29982] [client 117.222.139.248:59384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b6uGINCUUz5GA9YIWBgAAAn8"]
[Mon Jul 20 07:00:26.801290 2026] [security2:error] [pid 29744:tid 29902] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIWAAAAAi8"]
[Mon Jul 20 07:00:26.950699 2026] [security2:error] [pid 28702:tid 28939] [client 143.244.57.86:56704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4b6rF4957xPw9VVBmpHQAAAO8"]
[Mon Jul 20 07:00:27.100134 2026] [security2:error] [pid 28702:tid 28872] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4b6rF4957xPw9VVBmo_AAArAc"]
[Mon Jul 20 07:00:27.205140 2026] [security2:error] [pid 28702:tid 28824] [remote 91.142.222.105:41334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4b67F4957xPw9VVBmpMAAA-Hg"]
[Mon Jul 20 07:00:27.205452 2026] [security2:error] [pid 28702:tid 28948] [client 91.142.222.105:41334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4b67F4957xPw9VVBmpMAAA-Hg"]
[Mon Jul 20 07:00:27.244296 2026] [security2:error] [pid 29744:tid 29881] [client 143.244.57.86:56706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4b6-GINCUUz5GA9YIWEgAAAho"]
[Mon Jul 20 07:00:27.258494 2026] [security2:error] [pid 29744:tid 29944] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6-GINCUUz5GA9YIWDgAAAlk"]
[Mon Jul 20 07:00:27.336195 2026] [security2:error] [pid 28702:tid 28847] [client 103.144.65.217:54661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b67F4957xPw9VVBmpNgAAAJM"]
[Mon Jul 20 07:00:27.336307 2026] [security2:error] [pid 28702:tid 28847] [client 103.144.65.217:54661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b67F4957xPw9VVBmpNgAAAJM"]
[Mon Jul 20 07:00:27.368242 2026] [security2:error] [pid 28702:tid 28704] [remote 112.213.89.124:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.89.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4b67F4957xPw9VVBmpOAAA7gA"]
[Mon Jul 20 07:00:27.402925 2026] [security2:error] [pid 28702:tid 28908] [client 14.225.17.146:60474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4b67F4957xPw9VVBmpNAAAANA"], referer: https://chestermonty.com/2025
[Mon Jul 20 07:00:27.533891 2026] [security2:error] [pid 28702:tid 28889] [client 34.221.76.50:44676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4b67F4957xPw9VVBmpRgAAAL0"]
[Mon Jul 20 07:00:27.534149 2026] [security2:error] [pid 28702:tid 28933] [client 34.221.76.50:44684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4b67F4957xPw9VVBmpRwAAAOk"]
[Mon Jul 20 07:00:27.541386 2026] [security2:error] [pid 29744:tid 29892] [client 143.244.57.86:56716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4b6-GINCUUz5GA9YIWKgAAAiU"]
[Mon Jul 20 07:00:27.543532 2026] [security2:error] [pid 28702:tid 28720] [remote 5.161.225.162:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4b67F4957xPw9VVBmpSAAA3BA"]
[Mon Jul 20 07:00:27.554399 2026] [security2:error] [pid 29744:tid 29939] [client 34.221.76.50:44698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4b6-GINCUUz5GA9YIWKwAAAlQ"]
[Mon Jul 20 07:00:27.557353 2026] [security2:error] [pid 29744:tid 29934] [client 44.245.170.32:57862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4b6-GINCUUz5GA9YIWLAAAAk8"]
[Mon Jul 20 07:00:27.724932 2026] [security2:error] [pid 28702:tid 28756] [remote 5.161.225.162:53124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4b67F4957xPw9VVBmpUAAA_zQ"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:00:27.748794 2026] [security2:error] [pid 29744:tid 30000] [client 14.251.3.155:54848] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4b6-GINCUUz5GA9YIWPgAAApE"]
[Mon Jul 20 07:00:27.793195 2026] [security2:error] [pid 29744:tid 29965] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b6-GINCUUz5GA9YIWOwAAAm4"]
[Mon Jul 20 07:00:27.808518 2026] [security2:error] [pid 28702:tid 28770] [remote 112.213.89.124:41568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.89.213.112.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4b67F4957xPw9VVBmpVAAA50I"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:00:27.829263 2026] [security2:error] [pid 29744:tid 29938] [client 143.244.57.86:56728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kdg.jiv.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4b6-GINCUUz5GA9YIWRAAAAlM"]
[Mon Jul 20 07:00:27.855344 2026] [security2:error] [pid 29744:tid 29956] [client 57.141.18.27:26690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIV-gACZTU"]
[Mon Jul 20 07:00:27.883156 2026] [security2:error] [pid 29744:tid 29971] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b6-GINCUUz5GA9YIWJAAAAnQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:28.283446 2026] [security2:error] [pid 28702:tid 28956] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7LF4957xPw9VVBmpbQAAAQA"]
[Mon Jul 20 07:00:28.303294 2026] [security2:error] [pid 29744:tid 29950] [client 14.225.17.146:63823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4b6uGINCUUz5GA9YIV_AAAAl8"], referer: http://transparentservices.online/2025
[Mon Jul 20 07:00:28.635483 2026] [security2:error] [pid 29744:tid 29890] [client 57.141.18.119:61142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b6-GINCUUz5GA9YIWFAACIzw"]
[Mon Jul 20 07:00:28.766069 2026] [security2:error] [pid 28702:tid 28893] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7LF4957xPw9VVBmpiQAAAME"]
[Mon Jul 20 07:00:28.791900 2026] [security2:error] [pid 28702:tid 28843] [client 187.16.64.216:61812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b7LF4957xPw9VVBmpkwAAAI8"]
[Mon Jul 20 07:00:28.792052 2026] [security2:error] [pid 28702:tid 28843] [client 187.16.64.216:61812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b7LF4957xPw9VVBmpkwAAAI8"]
[Mon Jul 20 07:00:29.081306 2026] [security2:error] [pid 29744:tid 29909] [client 50.116.65.227:33770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4b7eGINCUUz5GA9YIWaAAAAjY"]
[Mon Jul 20 07:00:29.093451 2026] [security2:error] [pid 28702:tid 28941] [client 50.116.65.227:33774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4b7bF4957xPw9VVBmpuQAAAPE"]
[Mon Jul 20 07:00:29.131179 2026] [security2:error] [pid 28702:tid 28920] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b7LF4957xPw9VVBmpfQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:29.249393 2026] [security2:error] [pid 29744:tid 29987] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7eGINCUUz5GA9YIWbQAAAoQ"]
[Mon Jul 20 07:00:29.378934 2026] [security2:error] [pid 29744:tid 29911] [client 213.152.186.163:42972] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4b7eGINCUUz5GA9YIWcAAAAjg"]
[Mon Jul 20 07:00:29.379028 2026] [security2:error] [pid 29744:tid 29911] [client 213.152.186.163:42972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4b7eGINCUUz5GA9YIWcAAAAjg"]
[Mon Jul 20 07:00:29.401058 2026] [security2:error] [pid 28702:tid 28818] [remote 68.178.160.25:39150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4b7bF4957xPw9VVBmp6QAAinI"]
[Mon Jul 20 07:00:29.401233 2026] [security2:error] [pid 28702:tid 28838] [client 68.178.160.25:39150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4b7bF4957xPw9VVBmp6QAAinI"]
[Mon Jul 20 07:00:29.432992 2026] [security2:error] [pid 28702:tid 28902] [client 50.116.65.227:33790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4b7bF4957xPw9VVBmp7QAAAMo"]
[Mon Jul 20 07:00:29.442770 2026] [security2:error] [pid 28702:tid 28867] [client 50.116.65.227:33794] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4b7bF4957xPw9VVBmp7gAAAKc"]
[Mon Jul 20 07:00:29.671656 2026] [security2:error] [pid 29744:tid 29934] [client 147.93.171.187:64064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "al4b7eGINCUUz5GA9YIWgwAAAk8"], referer: binance.com
[Mon Jul 20 07:00:29.770965 2026] [security2:error] [pid 29744:tid 29966] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b7eGINCUUz5GA9YIWcwAAAm8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:29.789635 2026] [security2:error] [pid 29744:tid 29932] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7eGINCUUz5GA9YIWggAAAk0"]
[Mon Jul 20 07:00:29.846149 2026] [security2:error] [pid 29744:tid 29907] [client 14.225.17.146:50530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4b7eGINCUUz5GA9YIWhgAAAjQ"], referer: http://vinovinhowine.com/2025
[Mon Jul 20 07:00:29.848356 2026] [security2:error] [pid 29744:tid 29958] [client 144.172.104.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.str.cly.mybluehost.me"] [uri "/index.php"] [unique_id "al4b6-GINCUUz5GA9YIWIQAAAmc"]
[Mon Jul 20 07:00:29.999530 2026] [security2:error] [pid 29744:tid 29931] [client 104.234.53.56:50227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4b7eGINCUUz5GA9YIWlAAAAkw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:30.294892 2026] [security2:error] [pid 29744:tid 29898] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7uGINCUUz5GA9YIWogAAAis"]
[Mon Jul 20 07:00:30.805794 2026] [security2:error] [pid 28702:tid 28852] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b7rF4957xPw9VVBmqHwAAAJg"]
[Mon Jul 20 07:00:30.813075 2026] [security2:error] [pid 29744:tid 29997] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7uGINCUUz5GA9YIW4AAAAo4"]
[Mon Jul 20 07:00:30.911643 2026] [security2:error] [pid 29744:tid 29918] [client 183.82.98.154:62290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4b7uGINCUUz5GA9YIW6gAAAj8"]
[Mon Jul 20 07:00:30.911778 2026] [security2:error] [pid 29744:tid 29918] [client 183.82.98.154:62290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4b7uGINCUUz5GA9YIW6gAAAj8"]
[Mon Jul 20 07:00:31.183662 2026] [security2:error] [pid 28702:tid 28895] [client 74.208.214.194:42136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4b77F4957xPw9VVBmqSgAAAMM"]
[Mon Jul 20 07:00:31.288835 2026] [security2:error] [pid 29744:tid 29939] [client 77.110.127.138:61195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b7-GINCUUz5GA9YIW_gAAAlQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:31.288992 2026] [security2:error] [pid 29744:tid 29939] [client 77.110.127.138:61195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b7-GINCUUz5GA9YIW_gAAAlQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:31.291048 2026] [security2:error] [pid 29744:tid 29962] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7-GINCUUz5GA9YIW-AAAAms"]
[Mon Jul 20 07:00:31.296284 2026] [security2:error] [pid 29744:tid 29934] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4b7-GINCUUz5GA9YIW8AAAAk8"]
[Mon Jul 20 07:00:31.783176 2026] [security2:error] [pid 29744:tid 29938] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b7-GINCUUz5GA9YIXEgAAAlM"]
[Mon Jul 20 07:00:31.875868 2026] [security2:error] [pid 29744:tid 29972] [client 151.123.178.177:23479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.178.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b7-GINCUUz5GA9YIXIQAAAnU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:32.255042 2026] [autoindex:error] [pid 29744:tid 29848] [remote 34.48.227.185:50501] AH01276: Cannot serve directory /home2/ysslifmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://yss.lif.mybluehost.me
[Mon Jul 20 07:00:32.518592 2026] [security2:error] [pid 29744:tid 29886] [client 14.225.17.146:60434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4b7-GINCUUz5GA9YIW8QAAAh8"], referer: http://dnsplumbing.com/2025
[Mon Jul 20 07:00:32.669284 2026] [security2:error] [pid 29744:tid 29909] [client 117.247.108.24:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b8OGINCUUz5GA9YIXWQAAAjY"]
[Mon Jul 20 07:00:32.669390 2026] [security2:error] [pid 29744:tid 29909] [client 117.247.108.24:55436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b8OGINCUUz5GA9YIXWQAAAjY"]
[Mon Jul 20 07:00:32.978818 2026] [security2:error] [pid 29744:tid 30000] [client 14.225.17.146:63743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4b8OGINCUUz5GA9YIXXAAAApE"], referer: http://sesamegreenbeans.com/2025
[Mon Jul 20 07:00:33.069376 2026] [security2:error] [pid 29744:tid 29912] [client 57.141.18.5:20680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b7-GINCUUz5GA9YIXBwACOVY"]
[Mon Jul 20 07:00:33.106833 2026] [security2:error] [pid 28702:tid 28914] [client 103.238.106.162:60752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b8bF4957xPw9VVBmqeAAAANY"]
[Mon Jul 20 07:00:33.106922 2026] [security2:error] [pid 28702:tid 28914] [client 103.238.106.162:60752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b8bF4957xPw9VVBmqeAAAANY"]
[Mon Jul 20 07:00:33.429012 2026] [security2:error] [pid 28702:tid 28960] [client 65.111.29.159:33275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b8bF4957xPw9VVBmqfAAAAQQ"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:33.634309 2026] [security2:error] [pid 29744:tid 29867] [remote 100.42.189.89:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4b8eGINCUUz5GA9YIXjgACP3k"]
[Mon Jul 20 07:00:33.822077 2026] [security2:error] [pid 29744:tid 29749] [remote 100.42.189.89:41854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4b8eGINCUUz5GA9YIXrAACQQM"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 07:00:34.570785 2026] [security2:error] [pid 29744:tid 29982] [client 147.93.171.187:55632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "al4b8uGINCUUz5GA9YIX5gAAAn8"], referer: binance.com
[Mon Jul 20 07:00:34.824959 2026] [security2:error] [pid 29744:tid 29761] [remote 97.74.93.24:45766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4b8uGINCUUz5GA9YIX9wACig8"]
[Mon Jul 20 07:00:34.868157 2026] [proxy:error] [pid 29744:tid 29875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:34.868208 2026] [proxy_http:error] [pid 29744:tid 29875] [client 193.47.62.167:38944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:34.868625 2026] [proxy:error] [pid 29744:tid 29875] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:34.868648 2026] [proxy_http:error] [pid 29744:tid 29875] [client 193.47.62.167:38944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:34.871909 2026] [proxy:error] [pid 29744:tid 29946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:34.871950 2026] [proxy_http:error] [pid 29744:tid 29946] [client 193.47.62.167:38948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:34.872352 2026] [proxy:error] [pid 29744:tid 29946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:34.872375 2026] [proxy_http:error] [pid 29744:tid 29946] [client 193.47.62.167:38948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:34.922999 2026] [security2:error] [pid 29744:tid 29960] [client 104.207.52.235:45939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b8uGINCUUz5GA9YIYAAAAAmk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:35.250442 2026] [security2:error] [pid 29744:tid 29776] [remote 97.74.93.24:45766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4b8-GINCUUz5GA9YIYKwACkh4"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:00:35.258656 2026] [security2:error] [pid 28702:tid 28882] [client 57.141.18.29:36210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b8bF4957xPw9VVBmqfgAAtgI"]
[Mon Jul 20 07:00:35.533739 2026] [security2:error] [pid 29744:tid 29955] [client 57.141.18.33:24906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b8eGINCUUz5GA9YIXkwACZHs"]
[Mon Jul 20 07:00:35.680219 2026] [security2:error] [pid 28702:tid 28902] [client 213.152.186.163:42986] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b87F4957xPw9VVBmq3QAAAMo"]
[Mon Jul 20 07:00:35.680304 2026] [security2:error] [pid 28702:tid 28902] [client 213.152.186.163:42986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b87F4957xPw9VVBmq3QAAAMo"]
[Mon Jul 20 07:00:35.768865 2026] [security2:error] [pid 29744:tid 29984] [client 54.235.172.96:12743] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "willowbranchequines.org"] [uri "/volunteer/"] [unique_id "al4b8-GINCUUz5GA9YIYVAAAAoE"]
[Mon Jul 20 07:00:36.091498 2026] [security2:error] [pid 28702:tid 28855] [client 192.140.149.97:45319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4b9LF4957xPw9VVBmq7QAAAJs"]
[Mon Jul 20 07:00:36.091603 2026] [security2:error] [pid 28702:tid 28855] [client 192.140.149.97:45319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4b9LF4957xPw9VVBmq7QAAAJs"]
[Mon Jul 20 07:00:36.107145 2026] [security2:error] [pid 29744:tid 29993] [client 193.47.62.167:57812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.thechancersband.com"] [uri "/index.php"] [unique_id "al4b8-GINCUUz5GA9YIYPQAAAoo"], referer: http://mail.thechancersband.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:00:36.109560 2026] [security2:error] [pid 28702:tid 28955] [client 193.47.62.167:57826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4b87F4957xPw9VVBmq1QAAAP8"], referer: http://thechancersband.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:00:36.248541 2026] [security2:error] [pid 29744:tid 29997] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4b9OGINCUUz5GA9YIYeAACjiU"], referer: http://aleishapenny.ca/2025
[Mon Jul 20 07:00:36.441249 2026] [security2:error] [pid 29744:tid 29880] [client 52.35.117.102:48567] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "tacticaltreeoperations.com"] [uri "/"] [unique_id "al4b9OGINCUUz5GA9YIYhwAAAhk"]
[Mon Jul 20 07:00:36.503785 2026] [security2:error] [pid 29744:tid 29916] [client 216.73.217.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4b9OGINCUUz5GA9YIYhAAAAj0"]
[Mon Jul 20 07:00:36.571698 2026] [security2:error] [pid 29744:tid 29966] [client 14.225.17.146:60115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4b9OGINCUUz5GA9YIYiAAAAm8"], referer: http://alexsandbergmusic.com/2025
[Mon Jul 20 07:00:36.783860 2026] [security2:error] [pid 29744:tid 29953] [client 14.225.17.146:51916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4b9OGINCUUz5GA9YIYmAAAAmI"]
[Mon Jul 20 07:00:36.825942 2026] [security2:error] [pid 28702:tid 28814] [remote 152.228.213.32:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4b9LF4957xPw9VVBmrBwAA0G4"]
[Mon Jul 20 07:00:36.826257 2026] [security2:error] [pid 28702:tid 28908] [client 152.228.213.32:51814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4b9LF4957xPw9VVBmrBwAA0G4"]
[Mon Jul 20 07:00:37.065937 2026] [security2:error] [pid 28702:tid 28867] [client 14.225.17.146:52064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4b87F4957xPw9VVBmq3wAAAKc"], referer: http://effingweirdmuseums.com/2025
[Mon Jul 20 07:00:37.097423 2026] [security2:error] [pid 28702:tid 28922] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4b9LF4957xPw9VVBmrCgAA3kg"], referer: https://aleishapenny.ca/2025
[Mon Jul 20 07:00:37.148357 2026] [security2:error] [pid 28702:tid 28840] [client 57.141.18.38:54056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b87F4957xPw9VVBmqxQAAjDs"]
[Mon Jul 20 07:00:37.180786 2026] [security2:error] [pid 29744:tid 29991] [client 57.141.18.76:55698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b8-GINCUUz5GA9YIYIgACiB0"]
[Mon Jul 20 07:00:37.284301 2026] [security2:error] [pid 28702:tid 28873] [client 117.222.139.248:59889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b9bF4957xPw9VVBmrEAAAAK0"]
[Mon Jul 20 07:00:37.284444 2026] [security2:error] [pid 28702:tid 28873] [client 117.222.139.248:59889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b9bF4957xPw9VVBmrEAAAAK0"]
[Mon Jul 20 07:00:37.357598 2026] [security2:error] [pid 28702:tid 28902] [client 77.110.127.138:61217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b9bF4957xPw9VVBmrEQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:37.357692 2026] [security2:error] [pid 28702:tid 28902] [client 77.110.127.138:61217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b9bF4957xPw9VVBmrEQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:37.641431 2026] [security2:error] [pid 29744:tid 29992] [client 104.234.53.88:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4b9eGINCUUz5GA9YIY1AAAAok"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:37.928580 2026] [security2:error] [pid 29744:tid 29905] [client 47.128.56.202:15982] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musichaven.info"] [uri "/robots.txt"] [unique_id "al4b9eGINCUUz5GA9YIY9AAAAjI"]
[Mon Jul 20 07:00:37.929017 2026] [security2:error] [pid 29744:tid 29953] [client 103.144.65.217:55093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b9eGINCUUz5GA9YIY9QAAAmI"]
[Mon Jul 20 07:00:37.929111 2026] [security2:error] [pid 29744:tid 29953] [client 103.144.65.217:55093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4b9eGINCUUz5GA9YIY9QAAAmI"]
[Mon Jul 20 07:00:37.959502 2026] [security2:error] [pid 29744:tid 29959] [client 14.225.17.146:49465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4b9eGINCUUz5GA9YIY7wAAAmg"], referer: https://effingweirdmuseums.com/2025
[Mon Jul 20 07:00:38.302160 2026] [security2:error] [pid 28702:tid 28869] [client 57.141.18.26:46228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b9LF4957xPw9VVBmq8gAAqSc"]
[Mon Jul 20 07:00:38.475693 2026] [security2:error] [pid 29744:tid 29961] [client 14.225.17.146:51810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4b9uGINCUUz5GA9YIZBQAAAmo"], referer: http://secretkeynumerology.com/2025
[Mon Jul 20 07:00:38.876427 2026] [security2:error] [pid 29744:tid 29939] [client 147.93.171.187:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "al4b9uGINCUUz5GA9YIZNAAAAlQ"], referer: binance.com
[Mon Jul 20 07:00:39.282028 2026] [security2:error] [pid 28702:tid 28905] [client 14.225.17.146:65222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4b9rF4957xPw9VVBmrKgAAAM0"], referer: http://walkingandtalking.net/2025
[Mon Jul 20 07:00:39.558249 2026] [security2:error] [pid 29744:tid 29917] [client 187.16.64.216:62360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b9-GINCUUz5GA9YIZXAAAAj4"]
[Mon Jul 20 07:00:39.558377 2026] [security2:error] [pid 29744:tid 29917] [client 187.16.64.216:62360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4b9-GINCUUz5GA9YIZXAAAAj4"]
[Mon Jul 20 07:00:39.589824 2026] [security2:error] [pid 29744:tid 29913] [client 104.234.53.51:40725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4b9-GINCUUz5GA9YIZYAAAAjo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:39.699843 2026] [security2:error] [pid 29744:tid 30002] [client 14.225.17.146:59027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4b9-GINCUUz5GA9YIZWwAAApM"], referer: http://carolinapressurewashers.com/2025
[Mon Jul 20 07:00:39.989998 2026] [security2:error] [pid 28702:tid 28957] [client 45.3.54.150:47451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4b97F4957xPw9VVBmrVgAAAQE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:40.161878 2026] [security2:error] [pid 28702:tid 28819] [remote 41.76.214.143:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4b-LF4957xPw9VVBmrXwAAq3M"]
[Mon Jul 20 07:00:40.162388 2026] [security2:error] [pid 29744:tid 29875] [client 14.225.17.146:51733] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4b-OGINCUUz5GA9YIZcgAAAhQ"], referer: https://walkingandtalking.net/2025
[Mon Jul 20 07:00:40.570835 2026] [security2:error] [pid 29744:tid 29908] [client 65.111.23.2:51293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4b-OGINCUUz5GA9YIZhQAAAjU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:40.656848 2026] [security2:error] [pid 28702:tid 28806] [remote 41.76.214.143:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4b-LF4957xPw9VVBmrdQAAuWY"], referer: https://thefriendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:40.800243 2026] [security2:error] [pid 29744:tid 29877] [client 57.141.18.98:42872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b9uGINCUUz5GA9YIZKgACFl4"]
[Mon Jul 20 07:00:41.191065 2026] [security2:error] [pid 28702:tid 28847] [client 14.225.17.146:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4b-LF4957xPw9VVBmrfQAAAJM"], referer: http://fkconstructionfunding.com/2025
[Mon Jul 20 07:00:41.299527 2026] [security2:error] [pid 29744:tid 29936] [client 74.208.214.194:59148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4b-eGINCUUz5GA9YIZsAAAAlE"]
[Mon Jul 20 07:00:41.417010 2026] [security2:error] [pid 29744:tid 29906] [client 14.225.17.146:56777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4b-eGINCUUz5GA9YIZqwAAAjM"], referer: http://phillipbloch.com/2025
[Mon Jul 20 07:00:41.536371 2026] [security2:error] [pid 29744:tid 29911] [client 50.116.65.227:32876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4b-eGINCUUz5GA9YIZygAAAjg"]
[Mon Jul 20 07:00:41.549984 2026] [security2:error] [pid 28702:tid 28884] [client 50.116.65.227:32884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4b-bF4957xPw9VVBmrkQAAALg"]
[Mon Jul 20 07:00:41.583120 2026] [security2:error] [pid 29744:tid 29912] [client 104.207.50.2:55143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b-eGINCUUz5GA9YIZzQAAAjk"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:41.658273 2026] [security2:error] [pid 28702:tid 28856] [client 122.183.32.225:28501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4b-bF4957xPw9VVBmrmwAAAJw"]
[Mon Jul 20 07:00:41.658413 2026] [security2:error] [pid 28702:tid 28856] [client 122.183.32.225:28501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4b-bF4957xPw9VVBmrmwAAAJw"]
[Mon Jul 20 07:00:41.667814 2026] [security2:error] [pid 29744:tid 29980] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-eGINCUUz5GA9YIZxwAAAn0"]
[Mon Jul 20 07:00:41.684187 2026] [security2:error] [pid 29744:tid 29916] [client 183.82.98.154:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4b-eGINCUUz5GA9YIZ1gAAAj0"]
[Mon Jul 20 07:00:41.684375 2026] [security2:error] [pid 29744:tid 29916] [client 183.82.98.154:62883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4b-eGINCUUz5GA9YIZ1gAAAj0"]
[Mon Jul 20 07:00:41.806962 2026] [security2:error] [pid 28702:tid 28837] [client 57.141.18.32:59700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b97F4957xPw9VVBmrSgAAiXY"]
[Mon Jul 20 07:00:41.855450 2026] [security2:error] [pid 29744:tid 29909] [client 50.116.65.227:25636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4b-eGINCUUz5GA9YIZ8AAAAjY"]
[Mon Jul 20 07:00:41.869585 2026] [security2:error] [pid 29744:tid 29898] [client 50.116.65.227:32908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4b-eGINCUUz5GA9YIZ8gAAAog"]
[Mon Jul 20 07:00:41.936426 2026] [security2:error] [pid 29744:tid 29883] [client 104.234.53.92:31177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4b-eGINCUUz5GA9YIZ_QAAAhw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:42.089495 2026] [security2:error] [pid 28702:tid 28865] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-bF4957xPw9VVBmroQAAAKU"]
[Mon Jul 20 07:00:42.116764 2026] [security2:error] [pid 29744:tid 29936] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-eGINCUUz5GA9YIZ_AAAAlE"]
[Mon Jul 20 07:00:42.205913 2026] [security2:error] [pid 28702:tid 28726] [remote 57.141.18.103:48538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4b-rF4957xPw9VVBmrpwAAtBY"]
[Mon Jul 20 07:00:42.230502 2026] [security2:error] [pid 28702:tid 28889] [client 65.111.23.192:33325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4b-rF4957xPw9VVBmrpgAAAL0"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:42.233581 2026] [security2:error] [pid 29744:tid 29897] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-uGINCUUz5GA9YIaBgAAAio"]
[Mon Jul 20 07:00:42.304102 2026] [security2:error] [pid 28702:tid 28915] [client 14.224.227.113:54851] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4b-rF4957xPw9VVBmrrAAAANc"]
[Mon Jul 20 07:00:42.325496 2026] [security2:error] [pid 29744:tid 29928] [client 77.110.127.138:61240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b-uGINCUUz5GA9YIaGQAAAkk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:42.325620 2026] [security2:error] [pid 29744:tid 29928] [client 77.110.127.138:61240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b-uGINCUUz5GA9YIaGQAAAkk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:42.374072 2026] [security2:error] [pid 29744:tid 29926] [client 14.225.17.146:59076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4b-eGINCUUz5GA9YIZnAAAAkc"], referer: http://betterbonddogtraining.com/2025
[Mon Jul 20 07:00:42.415771 2026] [security2:error] [pid 29744:tid 29957] [client 50.116.65.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-uGINCUUz5GA9YIaFgAAAmY"]
[Mon Jul 20 07:00:42.617400 2026] [security2:error] [pid 29744:tid 29969] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-uGINCUUz5GA9YIaMAAAAnI"]
[Mon Jul 20 07:00:42.740130 2026] [security2:error] [pid 29744:tid 29895] [client 14.225.17.146:51576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4b-OGINCUUz5GA9YIZigAAAig"], referer: http://itdynamix.com/2025
[Mon Jul 20 07:00:42.819501 2026] [security2:error] [pid 29744:tid 29907] [client 103.220.204.73:51340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4b-eGINCUUz5GA9YIZtQACNAw"]
[Mon Jul 20 07:00:43.116011 2026] [security2:error] [pid 29744:tid 29901] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-uGINCUUz5GA9YIaWwAAAi4"]
[Mon Jul 20 07:00:43.141990 2026] [security2:error] [pid 28702:tid 28883] [client 147.93.171.187:65113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "al4b-7F4957xPw9VVBmrzwAAALc"], referer: binance.com
[Mon Jul 20 07:00:43.154363 2026] [security2:error] [pid 29744:tid 29987] [client 13.232.231.177:24312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4b--GINCUUz5GA9YIaagAAAoQ"]
[Mon Jul 20 07:00:43.199584 2026] [security2:error] [pid 29744:tid 29903] [client 117.247.108.24:13192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b--GINCUUz5GA9YIabQAAAjA"]
[Mon Jul 20 07:00:43.199679 2026] [security2:error] [pid 29744:tid 29903] [client 117.247.108.24:13192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4b--GINCUUz5GA9YIabQAAAjA"]
[Mon Jul 20 07:00:43.217912 2026] [security2:error] [pid 28702:tid 28942] [client 57.141.18.97:59960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b-bF4957xPw9VVBmrnQAA8go"]
[Mon Jul 20 07:00:43.418074 2026] [security2:error] [pid 29744:tid 29924] [client 57.141.18.46:39178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b-eGINCUUz5GA9YIZ8wACRS4"]
[Mon Jul 20 07:00:43.616029 2026] [security2:error] [pid 28702:tid 28885] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4b-7F4957xPw9VVBmr2gAAALk"]
[Mon Jul 20 07:00:43.619110 2026] [security2:error] [pid 28702:tid 28844] [client 14.225.17.146:51819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4b-bF4957xPw9VVBmrogAAAJA"], referer: https://north-woods-engineering.com/2025
[Mon Jul 20 07:00:43.659559 2026] [security2:error] [pid 28702:tid 28915] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b-7F4957xPw9VVBmr4AAAANc"]
[Mon Jul 20 07:00:43.673819 2026] [security2:error] [pid 29744:tid 29950] [client 14.225.17.146:51629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4b-uGINCUUz5GA9YIaAQAAAl8"], referer: http://xp-design.co/2025
[Mon Jul 20 07:00:43.737027 2026] [security2:error] [pid 29744:tid 29889] [client 103.238.106.162:42954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b--GINCUUz5GA9YIapQAAAiI"]
[Mon Jul 20 07:00:43.737171 2026] [security2:error] [pid 29744:tid 29889] [client 103.238.106.162:42954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4b--GINCUUz5GA9YIapQAAAiI"]
[Mon Jul 20 07:00:43.746577 2026] [security2:error] [pid 29744:tid 29890] [client 14.225.17.146:52106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4b--GINCUUz5GA9YIalQAAAiM"], referer: http://709fx.com/2025
[Mon Jul 20 07:00:43.825221 2026] [security2:error] [pid 29744:tid 29964] [client 14.225.17.146:51681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4b--GINCUUz5GA9YIanQAAAm0"], referer: https://itdynamix.com/2025
[Mon Jul 20 07:00:44.155020 2026] [security2:error] [pid 29744:tid 29904] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_OGINCUUz5GA9YIawwAAAjE"]
[Mon Jul 20 07:00:44.219928 2026] [security2:error] [pid 29744:tid 29993] [client 14.225.17.146:51648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4b--GINCUUz5GA9YIaZQAAAoo"], referer: http://claysharecon.com/2025
[Mon Jul 20 07:00:44.275916 2026] [security2:error] [pid 29744:tid 29928] [client 13.232.231.177:24320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4b_OGINCUUz5GA9YIa0wAAAkk"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:00:44.388728 2026] [security2:error] [pid 29744:tid 29910] [client 57.141.18.0:56240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b-uGINCUUz5GA9YIaQwACN0M"]
[Mon Jul 20 07:00:44.487894 2026] [security2:error] [pid 29744:tid 29964] [client 104.168.59.36:58654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.soloceos.com"] [uri "/"] [unique_id "al4b_OGINCUUz5GA9YIa4QAAAm0"]
[Mon Jul 20 07:00:44.531858 2026] [security2:error] [pid 29744:tid 29966] [client 50.116.65.227:33002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4b--GINCUUz5GA9YIakwAAAm8"]
[Mon Jul 20 07:00:44.568691 2026] [security2:error] [pid 28702:tid 28882] [client 14.225.17.146:51778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4b-7F4957xPw9VVBmr2AAAALY"]
[Mon Jul 20 07:00:44.642328 2026] [security2:error] [pid 29744:tid 29945] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_OGINCUUz5GA9YIa5gAAAlo"]
[Mon Jul 20 07:00:44.778491 2026] [security2:error] [pid 28702:tid 28856] [client 104.234.53.93:26529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4b_LF4957xPw9VVBmsAQAAAJw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:44.920432 2026] [security2:error] [pid 29744:tid 29885] [client 82.102.18.116:46734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "learnthissecret.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4b_OGINCUUz5GA9YIbAQAAAh4"]
[Mon Jul 20 07:00:44.964595 2026] [security2:error] [pid 29744:tid 29960] [client 50.116.65.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_OGINCUUz5GA9YIa-AAAAmk"]
[Mon Jul 20 07:00:45.025938 2026] [security2:error] [pid 29744:tid 30001] [client 104.207.49.80:28059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b_eGINCUUz5GA9YIbDQAAApI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:45.077130 2026] [security2:error] [pid 29744:tid 29920] [client 14.225.17.146:51604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4b--GINCUUz5GA9YIalgAAAkE"], referer: http://inspirespublishing.com/2025
[Mon Jul 20 07:00:45.144294 2026] [security2:error] [pid 29744:tid 29977] [client 103.190.132.50:62180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4b_OGINCUUz5GA9YIbCgACehM"]
[Mon Jul 20 07:00:45.158929 2026] [security2:error] [pid 28702:tid 28849] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_bF4957xPw9VVBmsEQAAAJU"]
[Mon Jul 20 07:00:45.271323 2026] [security2:error] [pid 29744:tid 29891] [client 50.116.65.227:33046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4b_OGINCUUz5GA9YIa6wAAAiQ"]
[Mon Jul 20 07:00:45.498265 2026] [security2:error] [pid 29744:tid 29913] [client 57.141.18.23:53252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b--GINCUUz5GA9YIatAACOnI"]
[Mon Jul 20 07:00:45.549860 2026] [security2:error] [pid 28702:tid 28892] [client 82.102.18.116:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/xmlrpc.php"] [unique_id "al4b_bF4957xPw9VVBmsIgAAAMA"]
[Mon Jul 20 07:00:45.626596 2026] [security2:error] [pid 28702:tid 28858] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_bF4957xPw9VVBmsIQAAAJ4"]
[Mon Jul 20 07:00:46.057556 2026] [security2:error] [pid 29744:tid 29960] [client 104.234.53.58:53383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4b_eGINCUUz5GA9YIbSgAAAmk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:46.129332 2026] [security2:error] [pid 29744:tid 29908] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_uGINCUUz5GA9YIbVQAAAjU"]
[Mon Jul 20 07:00:46.157672 2026] [security2:error] [pid 28702:tid 28846] [client 147.93.171.187:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "al4b_rF4957xPw9VVBmsMQAAAJI"], referer: binance.com
[Mon Jul 20 07:00:46.406096 2026] [security2:error] [pid 29744:tid 29984] [client 65.111.29.113:57511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.29.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4b_uGINCUUz5GA9YIbaQAAAoE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:46.633848 2026] [security2:error] [pid 29744:tid 29954] [client 14.225.17.146:60106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4b_eGINCUUz5GA9YIbHQAAAmM"], referer: http://alchemygroup.ca/2025
[Mon Jul 20 07:00:46.784159 2026] [security2:error] [pid 29744:tid 29920] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_uGINCUUz5GA9YIbdwAAAkE"]
[Mon Jul 20 07:00:46.866075 2026] [security2:error] [pid 29744:tid 29804] [remote 15.206.251.117:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4b_uGINCUUz5GA9YIbhwACijo"]
[Mon Jul 20 07:00:47.135275 2026] [security2:error] [pid 28702:tid 28887] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_7F4957xPw9VVBmsUwAAALs"]
[Mon Jul 20 07:00:47.284238 2026] [security2:error] [pid 29744:tid 29768] [remote 15.206.251.117:55946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4b_-GINCUUz5GA9YIbnAACSxY"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:00:47.485902 2026] [security2:error] [pid 29744:tid 29927] [client 14.225.17.146:51710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4b_eGINCUUz5GA9YIbQwAAAkg"], referer: http://amalia-capital.com/2025
[Mon Jul 20 07:00:47.589922 2026] [security2:error] [pid 29744:tid 29897] [client 14.225.17.146:51830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4b_uGINCUUz5GA9YIbXAAAAio"], referer: http://cephasnext.com/2025
[Mon Jul 20 07:00:47.632739 2026] [security2:error] [pid 29744:tid 29951] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4b_-GINCUUz5GA9YIbqgAAAmA"]
[Mon Jul 20 07:00:47.714093 2026] [security2:error] [pid 29744:tid 29989] [client 57.141.18.124:35432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4b_uGINCUUz5GA9YIbXgAChi0"]
[Mon Jul 20 07:00:47.821930 2026] [security2:error] [pid 29744:tid 29970] [client 117.222.139.248:60399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b_-GINCUUz5GA9YIbzQAAAnM"]
[Mon Jul 20 07:00:47.822065 2026] [security2:error] [pid 29744:tid 29970] [client 117.222.139.248:60399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4b_-GINCUUz5GA9YIbzQAAAnM"]
[Mon Jul 20 07:00:47.829857 2026] [security2:error] [pid 28702:tid 28890] [client 77.110.127.138:61267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b_7F4957xPw9VVBmscQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:47.829950 2026] [security2:error] [pid 28702:tid 28890] [client 77.110.127.138:61267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4b_7F4957xPw9VVBmscQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:47.885539 2026] [security2:error] [pid 29744:tid 29886] [client 192.140.149.97:45443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4b_-GINCUUz5GA9YIb2AAAAh8"]
[Mon Jul 20 07:00:47.885638 2026] [security2:error] [pid 29744:tid 29886] [client 192.140.149.97:45443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4b_-GINCUUz5GA9YIb2AAAAh8"]
[Mon Jul 20 07:00:48.011663 2026] [security2:error] [pid 29744:tid 29945] [client 104.234.53.58:53383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4b_-GINCUUz5GA9YIb7wAAAlo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:48.139022 2026] [security2:error] [pid 28702:tid 28882] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cALF4957xPw9VVBmshgAAALY"]
[Mon Jul 20 07:00:48.243382 2026] [security2:error] [pid 29744:tid 29962] [client 188.166.64.27:61086] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.membresiabeyou.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4cAOGINCUUz5GA9YIcCAAAAms"]
[Mon Jul 20 07:00:48.478302 2026] [security2:error] [pid 29744:tid 29899] [client 103.144.65.217:55537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cAOGINCUUz5GA9YIcLAAAAiw"]
[Mon Jul 20 07:00:48.478426 2026] [security2:error] [pid 29744:tid 29899] [client 103.144.65.217:55537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cAOGINCUUz5GA9YIcLAAAAiw"]
[Mon Jul 20 07:00:48.628724 2026] [security2:error] [pid 28702:tid 28732] [remote 157.66.26.183:52604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cALF4957xPw9VVBmslwAA0Bw"]
[Mon Jul 20 07:00:48.682361 2026] [security2:error] [pid 28702:tid 28922] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cALF4957xPw9VVBmslQAAAN4"]
[Mon Jul 20 07:00:48.987731 2026] [security2:error] [pid 29744:tid 29962] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cAOGINCUUz5GA9YIcTAAAAms"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:49.016579 2026] [security2:error] [pid 28702:tid 28803] [remote 157.66.26.183:52604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cAbF4957xPw9VVBmspgAA4mM"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:00:49.176349 2026] [security2:error] [pid 29744:tid 29951] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cAeGINCUUz5GA9YIcXgAAAmA"]
[Mon Jul 20 07:00:49.281488 2026] [security2:error] [pid 29744:tid 29934] [client 14.225.17.146:50124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4cAeGINCUUz5GA9YIcagAAAk8"], referer: http://nikkidesigns.net/2025
[Mon Jul 20 07:00:49.435104 2026] [security2:error] [pid 29744:tid 29877] [client 57.141.18.72:62898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cAOGINCUUz5GA9YIb_QACFkw"]
[Mon Jul 20 07:00:49.463516 2026] [security2:error] [pid 29744:tid 29912] [client 14.225.17.146:49573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4b_-GINCUUz5GA9YIb4wAAAjk"], referer: http://headachescarpaltunnelfibromyalgia.com/2025
[Mon Jul 20 07:00:49.651868 2026] [security2:error] [pid 29744:tid 29955] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cAeGINCUUz5GA9YIcjAAAAmQ"]
[Mon Jul 20 07:00:49.881158 2026] [security2:error] [pid 29744:tid 29926] [client 104.168.59.36:59802] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "adventure-studio.zanjan-fromer.com"] [uri "/"] [unique_id "al4cAeGINCUUz5GA9YIctwAAAkc"]
[Mon Jul 20 07:00:49.952961 2026] [security2:error] [pid 28702:tid 28950] [client 104.168.59.36:59826] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.terrapro-org.zanjan-fromer.com"] [uri "/"] [unique_id "al4cAbF4957xPw9VVBmswwAAAPo"]
[Mon Jul 20 07:00:49.972667 2026] [security2:error] [pid 29744:tid 29888] [client 57.141.18.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cAeGINCUUz5GA9YIcswAAAiE"]
[Mon Jul 20 07:00:50.068867 2026] [security2:error] [pid 29744:tid 29807] [remote 47.128.49.49:28066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joaoceitil.com"] [uri "/news/"] [unique_id "al4cAuGINCUUz5GA9YIc1gACYD0"]
[Mon Jul 20 07:00:50.069603 2026] [security2:error] [pid 29744:tid 29916] [client 147.93.171.187:64302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "al4cAuGINCUUz5GA9YIc1wAAAj0"], referer: binance.com
[Mon Jul 20 07:00:50.140266 2026] [security2:error] [pid 29744:tid 29901] [client 187.16.64.216:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cAuGINCUUz5GA9YIc2wAAAi4"]
[Mon Jul 20 07:00:50.140377 2026] [security2:error] [pid 29744:tid 29901] [client 187.16.64.216:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cAuGINCUUz5GA9YIc2wAAAi4"]
[Mon Jul 20 07:00:50.153142 2026] [security2:error] [pid 29744:tid 29922] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cAuGINCUUz5GA9YIcygAAAkM"]
[Mon Jul 20 07:00:50.158810 2026] [security2:error] [pid 29744:tid 29988] [client 45.3.54.6:23401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cAuGINCUUz5GA9YIc2gAAAoU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:50.261965 2026] [security2:error] [pid 28702:tid 28912] [client 104.234.53.78:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cArF4957xPw9VVBms0gAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:50.610645 2026] [security2:error] [pid 29744:tid 29995] [client 104.168.59.36:60018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.thesoloceos.com"] [uri "/"] [unique_id "al4cAuGINCUUz5GA9YIdDwAAAow"]
[Mon Jul 20 07:00:50.628076 2026] [security2:error] [pid 29744:tid 29968] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cAuGINCUUz5GA9YIdBgAAAnE"]
[Mon Jul 20 07:00:50.632207 2026] [security2:error] [pid 28702:tid 28867] [client 104.168.59.36:60030] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "arunavabanerjee.com"] [uri "/"] [unique_id "al4cArF4957xPw9VVBms3gAAAKc"]
[Mon Jul 20 07:00:50.689082 2026] [security2:error] [pid 29744:tid 29964] [client 104.168.59.36:60050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "thesoloceos.com"] [uri "/"] [unique_id "al4cAuGINCUUz5GA9YIdHQAAAm0"]
[Mon Jul 20 07:00:50.774344 2026] [security2:error] [pid 29744:tid 29967] [client 104.168.59.36:60078] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.soloceos.com"] [uri "/"] [unique_id "al4cAuGINCUUz5GA9YIdIgAAAnA"]
[Mon Jul 20 07:00:50.793084 2026] [security2:error] [pid 29744:tid 29930] [client 65.111.22.69:32421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cAuGINCUUz5GA9YIdIAAAAks"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:50.832245 2026] [security2:error] [pid 28702:tid 28927] [client 14.225.17.146:50637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4cArF4957xPw9VVBms1AAAAOM"], referer: http://idigress.group/2025
[Mon Jul 20 07:00:50.922039 2026] [security2:error] [pid 29744:tid 29951] [client 35.221.62.63:50398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.faadenergy.com"] [uri "/index.php"] [unique_id "al4cAuGINCUUz5GA9YIdIwAAAmA"]
[Mon Jul 20 07:00:51.031946 2026] [security2:error] [pid 29744:tid 29990] [client 35.221.62.63:50398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.62.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.faadenergy.com"] [uri "/xmlrpc.php"] [unique_id "al4cA-GINCUUz5GA9YIdNwAAAoc"]
[Mon Jul 20 07:00:51.032063 2026] [security2:error] [pid 29744:tid 29990] [client 35.221.62.63:50398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kromosenergy.faadenergy.com"] [uri "/xmlrpc.php"] [unique_id "al4cA-GINCUUz5GA9YIdNwAAAoc"]
[Mon Jul 20 07:00:51.068969 2026] [security2:error] [pid 29744:tid 29994] [client 35.221.62.63:62866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.62.221.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/xmlrpc.php"] [unique_id "al4cA-GINCUUz5GA9YIdOgAAAos"]
[Mon Jul 20 07:00:51.069111 2026] [security2:error] [pid 29744:tid 29994] [client 35.221.62.63:62866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kromosenergy.com"] [uri "/xmlrpc.php"] [unique_id "al4cA-GINCUUz5GA9YIdOgAAAos"]
[Mon Jul 20 07:00:51.159555 2026] [security2:error] [pid 29744:tid 29993] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cA-GINCUUz5GA9YIdOQAAAoo"]
[Mon Jul 20 07:00:51.394104 2026] [security2:error] [pid 29744:tid 29984] [client 65.111.22.7:43445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cA-GINCUUz5GA9YIdVAAAAoE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:51.531338 2026] [security2:error] [pid 29744:tid 29904] [client 57.141.18.113:22838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cAuGINCUUz5GA9YIc3AACMTo"]
[Mon Jul 20 07:00:51.604549 2026] [security2:error] [pid 29744:tid 29966] [client 82.102.18.116:22034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/xmlrpc.php"] [unique_id "al4cA-GINCUUz5GA9YIdaAAAAm8"]
[Mon Jul 20 07:00:51.604716 2026] [security2:error] [pid 29744:tid 29966] [client 82.102.18.116:22034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "learnthissecret.com"] [uri "/xmlrpc.php"] [unique_id "al4cA-GINCUUz5GA9YIdaAAAAm8"]
[Mon Jul 20 07:00:51.651638 2026] [security2:error] [pid 29744:tid 29981] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cA-GINCUUz5GA9YIdYQAAAn4"]
[Mon Jul 20 07:00:51.809556 2026] [security2:error] [pid 28702:tid 28907] [client 104.168.114.154:53232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.terrapro.media"] [uri "/"] [unique_id "al4cA7F4957xPw9VVBms-wAAAM8"]
[Mon Jul 20 07:00:51.811779 2026] [security2:error] [pid 29744:tid 29844] [remote 188.166.241.141:50890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4cA-GINCUUz5GA9YIdeQACSmI"]
[Mon Jul 20 07:00:51.854860 2026] [security2:error] [pid 28702:tid 28954] [client 45.3.54.171:38573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4cA7F4957xPw9VVBms_AAAAP4"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:51.893712 2026] [security2:error] [pid 29744:tid 29923] [client 14.225.17.146:59187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4cAuGINCUUz5GA9YIdJAAAAkQ"], referer: http://ancestralidadytrance.space/2025
[Mon Jul 20 07:00:51.947428 2026] [security2:error] [pid 29744:tid 30002] [client 45.3.42.72:37401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cA-GINCUUz5GA9YIdiwAAApM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:00:51.947581 2026] [security2:error] [pid 29744:tid 29930] [client 192.236.168.43:39090] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.adventure-studio.zanjan-fromer.com"] [uri "/"] [unique_id "al4cA-GINCUUz5GA9YIdkAAAAks"]
[Mon Jul 20 07:00:51.958606 2026] [security2:error] [pid 29744:tid 29961] [client 104.168.114.154:53264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.arunavabanerjee.com"] [uri "/"] [unique_id "al4cA-GINCUUz5GA9YIdkQAAAmo"]
[Mon Jul 20 07:00:51.977856 2026] [security2:error] [pid 28702:tid 28930] [client 192.236.168.43:39104] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "terrapro-media.zanjan-fromer.com"] [uri "/"] [unique_id "al4cA7F4957xPw9VVBmtAwAAAOY"]
[Mon Jul 20 07:00:52.011362 2026] [security2:error] [pid 29744:tid 29951] [client 104.168.114.154:53276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.arunavabanerjee.com"] [uri "/"] [unique_id "al4cBOGINCUUz5GA9YIdmAAAAmA"]
[Mon Jul 20 07:00:52.043870 2026] [security2:error] [pid 29744:tid 29966] [client 192.236.168.43:39120] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.terrapro-media.zanjan-fromer.com"] [uri "/"] [unique_id "al4cBOGINCUUz5GA9YIdmQAAAm8"]
[Mon Jul 20 07:00:52.114287 2026] [security2:error] [pid 29744:tid 29981] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cBOGINCUUz5GA9YIdlwAAAn4"]
[Mon Jul 20 07:00:52.178852 2026] [security2:error] [pid 29744:tid 29853] [remote 188.166.241.141:50890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4cBOGINCUUz5GA9YIdowACa2s"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:00:52.414877 2026] [security2:error] [pid 29744:tid 29970] [client 104.207.52.253:11575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4cBOGINCUUz5GA9YIdrgAAAnM"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:00:52.525523 2026] [security2:error] [pid 28702:tid 28900] [client 183.82.98.154:63480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cBLF4957xPw9VVBmtGQAAAMg"]
[Mon Jul 20 07:00:52.525681 2026] [security2:error] [pid 28702:tid 28900] [client 183.82.98.154:63480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cBLF4957xPw9VVBmtGQAAAMg"]
[Mon Jul 20 07:00:52.546279 2026] [security2:error] [pid 29744:tid 29855] [remote 5.252.52.249:58080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cBOGINCUUz5GA9YIdvAACI20"]
[Mon Jul 20 07:00:52.704604 2026] [security2:error] [pid 29744:tid 29894] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cBOGINCUUz5GA9YIdwQAAAic"]
[Mon Jul 20 07:00:52.894476 2026] [security2:error] [pid 28702:tid 28936] [client 14.225.17.146:59312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4cA7F4957xPw9VVBms5QAAAOw"], referer: http://tacticaltreeoperations.com/2025
[Mon Jul 20 07:00:52.909470 2026] [security2:error] [pid 29744:tid 29817] [remote 5.252.52.249:58080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cBOGINCUUz5GA9YId2AACk0c"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:00:52.997341 2026] [security2:error] [pid 29744:tid 29934] [client 50.116.65.227:37958] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cBOGINCUUz5GA9YId5QAAAk8"]
[Mon Jul 20 07:00:53.010737 2026] [security2:error] [pid 29744:tid 29958] [client 50.116.65.227:37968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cBeGINCUUz5GA9YId5wAAAmc"]
[Mon Jul 20 07:00:53.190854 2026] [security2:error] [pid 29744:tid 29954] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cBeGINCUUz5GA9YId6AAAAmM"]
[Mon Jul 20 07:00:53.269517 2026] [security2:error] [pid 29744:tid 29936] [client 57.141.18.81:28820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cA-GINCUUz5GA9YIdcAACUWE"]
[Mon Jul 20 07:00:53.358869 2026] [security2:error] [pid 28702:tid 28947] [client 74.7.244.43:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "twz.oin.mybluehost.me"] [uri "/index.php"] [unique_id "al4cBLF4957xPw9VVBmtDQAAAPc"]
[Mon Jul 20 07:00:53.360280 2026] [security2:error] [pid 28702:tid 28881] [client 74.7.244.43:60770] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "twz.oin.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4cBLF4957xPw9VVBmtDAAAALU"]
[Mon Jul 20 07:00:53.368449 2026] [security2:error] [pid 29744:tid 29947] [client 104.234.53.72:44683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cBeGINCUUz5GA9YId-QAAAlw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:53.419348 2026] [security2:error] [pid 29744:tid 29903] [client 192.236.168.43:39476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.thesoloceos.com"] [uri "/"] [unique_id "al4cBeGINCUUz5GA9YId_QAAAjA"]
[Mon Jul 20 07:00:53.611359 2026] [security2:error] [pid 29744:tid 30000] [client 192.236.168.43:39516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "soloceos.com"] [uri "/"] [unique_id "al4cBeGINCUUz5GA9YIeDQAAApE"]
[Mon Jul 20 07:00:53.632780 2026] [security2:error] [pid 29744:tid 29875] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cBeGINCUUz5GA9YIeBwAAAhQ"]
[Mon Jul 20 07:00:53.688177 2026] [security2:error] [pid 29744:tid 29978] [client 147.93.171.187:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "al4cBeGINCUUz5GA9YIeDwAAAns"], referer: binance.com
[Mon Jul 20 07:00:53.712168 2026] [security2:error] [pid 29744:tid 29943] [client 117.247.108.24:61816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cBeGINCUUz5GA9YIeEAAAAlg"]
[Mon Jul 20 07:00:53.712328 2026] [security2:error] [pid 29744:tid 29943] [client 117.247.108.24:61816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cBeGINCUUz5GA9YIeEAAAAlg"]
[Mon Jul 20 07:00:54.229342 2026] [security2:error] [pid 29744:tid 29990] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cBuGINCUUz5GA9YIeKgAAAoc"]
[Mon Jul 20 07:00:54.610695 2026] [security2:error] [pid 29744:tid 29988] [client 103.238.106.162:60726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cBuGINCUUz5GA9YIeRgAAAoU"]
[Mon Jul 20 07:00:54.610825 2026] [security2:error] [pid 29744:tid 29988] [client 103.238.106.162:60726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cBuGINCUUz5GA9YIeRgAAAoU"]
[Mon Jul 20 07:00:54.652200 2026] [security2:error] [pid 28702:tid 28880] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cBrF4957xPw9VVBmtWwAAALQ"]
[Mon Jul 20 07:00:54.694014 2026] [proxy:error] [pid 29744:tid 29979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:54.694095 2026] [proxy_http:error] [pid 29744:tid 29979] [client 193.47.62.167:46316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:54.694711 2026] [proxy:error] [pid 29744:tid 29979] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:54.694746 2026] [proxy_http:error] [pid 29744:tid 29979] [client 193.47.62.167:46316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:54.724528 2026] [proxy:error] [pid 28702:tid 28926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:54.724566 2026] [proxy_http:error] [pid 28702:tid 28926] [client 193.47.62.167:46354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:54.725342 2026] [proxy:error] [pid 28702:tid 28926] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:54.725373 2026] [proxy_http:error] [pid 28702:tid 28926] [client 193.47.62.167:46354] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:54.878336 2026] [security2:error] [pid 29744:tid 29888] [client 14.225.17.146:52225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4cBOGINCUUz5GA9YIdqQAAAiE"], referer: http://overloadcomedy.com/2025
[Mon Jul 20 07:00:55.134535 2026] [security2:error] [pid 29744:tid 29912] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cB-GINCUUz5GA9YIeZgAAAjk"]
[Mon Jul 20 07:00:55.199172 2026] [security2:error] [pid 29744:tid 29881] [client 57.141.18.3:56288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cBeGINCUUz5GA9YIeEwACGgk"]
[Mon Jul 20 07:00:55.279120 2026] [security2:error] [pid 29744:tid 29973] [client 77.110.127.138:61286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cB-GINCUUz5GA9YIedQAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:55.279257 2026] [security2:error] [pid 29744:tid 29973] [client 77.110.127.138:61286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cB-GINCUUz5GA9YIedQAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:55.293909 2026] [security2:error] [pid 28702:tid 28836] [client 14.225.17.146:62132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4cBbF4957xPw9VVBmtPgAAAIg"], referer: http://samdothan.org/2025
[Mon Jul 20 07:00:55.399784 2026] [security2:error] [pid 29744:tid 29993] [client 104.234.53.90:33975] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cB-GINCUUz5GA9YIedgAAAoo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:55.430716 2026] [security2:error] [pid 29744:tid 29896] [client 43.205.139.3:52442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cB-GINCUUz5GA9YIegQAAAik"]
[Mon Jul 20 07:00:55.430869 2026] [security2:error] [pid 29744:tid 29896] [client 43.205.139.3:52442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cB-GINCUUz5GA9YIegQAAAik"]
[Mon Jul 20 07:00:55.501036 2026] [security2:error] [pid 28702:tid 28875] [client 77.110.127.138:61289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cB7F4957xPw9VVBmtdwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:55.501135 2026] [security2:error] [pid 28702:tid 28875] [client 77.110.127.138:61289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cB7F4957xPw9VVBmtdwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:55.522291 2026] [security2:error] [pid 29744:tid 29924] [client 193.47.62.167:54616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4cB-GINCUUz5GA9YIecAAAAkU"], referer: http://mail.webgardensbypaula.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:00:55.542457 2026] [security2:error] [pid 29744:tid 29926] [client 193.47.62.167:54600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4cB-GINCUUz5GA9YIebQAAAkc"], referer: http://webgardensbypaula.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:00:55.635052 2026] [security2:error] [pid 29744:tid 29936] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cB-GINCUUz5GA9YIeiAAAAlE"]
[Mon Jul 20 07:00:55.800828 2026] [security2:error] [pid 29744:tid 29992] [client 193.47.62.167:54634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4cB-GINCUUz5GA9YIejQAAAok"], referer: http://www.webgardensbypaula.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:00:55.800843 2026] [security2:error] [pid 29744:tid 29923] [client 77.110.127.138:61292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cB-GINCUUz5GA9YIenQAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:55.800931 2026] [security2:error] [pid 29744:tid 29923] [client 77.110.127.138:61292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cB-GINCUUz5GA9YIenQAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:56.135061 2026] [security2:error] [pid 29744:tid 29877] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cCOGINCUUz5GA9YIeswAAAhY"]
[Mon Jul 20 07:00:56.165821 2026] [security2:error] [pid 29744:tid 29994] [client 147.93.171.187:52021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "al4cCOGINCUUz5GA9YIexAAAAos"], referer: binance.com
[Mon Jul 20 07:00:56.184356 2026] [security2:error] [pid 29744:tid 29981] [client 104.234.53.90:33975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cCOGINCUUz5GA9YIexQAAAn4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:56.241233 2026] [security2:error] [pid 29744:tid 29976] [client 77.110.127.138:61297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCOGINCUUz5GA9YIeygAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:56.241386 2026] [security2:error] [pid 29744:tid 29976] [client 77.110.127.138:61297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCOGINCUUz5GA9YIeygAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:56.360412 2026] [security2:error] [pid 29744:tid 29911] [client 34.147.91.161:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.robertpierson.org"] [uri "/"] [unique_id "al4cCOGINCUUz5GA9YIe1AAAAjg"]
[Mon Jul 20 07:00:56.360525 2026] [security2:error] [pid 29744:tid 29911] [client 34.147.91.161:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.robertpierson.org"] [uri "/"] [unique_id "al4cCOGINCUUz5GA9YIe1AAAAjg"]
[Mon Jul 20 07:00:56.647062 2026] [security2:error] [pid 29744:tid 29894] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cCOGINCUUz5GA9YIe5wAAAic"]
[Mon Jul 20 07:00:56.781731 2026] [security2:error] [pid 29744:tid 30000] [client 77.110.127.138:61303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCOGINCUUz5GA9YIe9QAAApE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:56.781836 2026] [security2:error] [pid 29744:tid 30000] [client 77.110.127.138:61303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCOGINCUUz5GA9YIe9QAAApE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:56.832545 2026] [security2:error] [pid 29744:tid 29884] [client 45.157.112.60:29265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cCOGINCUUz5GA9YIe-QAAAh0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:00:56.840976 2026] [security2:error] [pid 28702:tid 28850] [client 122.129.68.27:43373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "expertcultures.com"] [uri "/xmlrpc.php"] [unique_id "al4cCLF4957xPw9VVBmtlgAAAJY"]
[Mon Jul 20 07:00:56.936807 2026] [security2:error] [pid 29744:tid 29911] [client 77.110.127.138:61306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCOGINCUUz5GA9YIe_wAAAjg"]
[Mon Jul 20 07:00:56.936897 2026] [security2:error] [pid 29744:tid 29911] [client 77.110.127.138:61306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCOGINCUUz5GA9YIe_wAAAjg"]
[Mon Jul 20 07:00:56.985094 2026] [security2:error] [pid 28702:tid 28849] [client 14.225.17.146:64882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4cB7F4957xPw9VVBmtfgAAAJU"], referer: http://cloudspacesgroup.com/2025
[Mon Jul 20 07:00:57.068584 2026] [security2:error] [pid 29744:tid 29915] [client 158.173.89.95:31885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cCeGINCUUz5GA9YIfDgAAAjw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:00:57.152648 2026] [security2:error] [pid 29744:tid 29980] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cCeGINCUUz5GA9YIfCAAAAn0"]
[Mon Jul 20 07:00:57.324370 2026] [security2:error] [pid 28702:tid 28837] [client 65.111.28.170:39597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cCbF4957xPw9VVBmtxgAAAIk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:57.353186 2026] [security2:error] [pid 29744:tid 29973] [client 57.141.18.121:49696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cB-GINCUUz5GA9YIerAACdjM"]
[Mon Jul 20 07:00:57.360734 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:61314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCbF4957xPw9VVBmtyAAAAPc"]
[Mon Jul 20 07:00:57.360897 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:61314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cCbF4957xPw9VVBmtyAAAAPc"]
[Mon Jul 20 07:00:57.366447 2026] [security2:error] [pid 29744:tid 29836] [remote 103.75.185.95:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4cCeGINCUUz5GA9YIfJwACe1o"]
[Mon Jul 20 07:00:57.746989 2026] [security2:error] [pid 29744:tid 29980] [client 14.251.3.155:54852] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cCeGINCUUz5GA9YIfQAAAAn0"]
[Mon Jul 20 07:00:57.776940 2026] [security2:error] [pid 29744:tid 29993] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cCeGINCUUz5GA9YIfPAAAAoo"]
[Mon Jul 20 07:00:57.837959 2026] [security2:error] [pid 29744:tid 29815] [remote 162.19.86.63:36730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cCeGINCUUz5GA9YIfRgACTEU"]
[Mon Jul 20 07:00:57.838150 2026] [security2:error] [pid 29744:tid 29931] [client 162.19.86.63:36730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cCeGINCUUz5GA9YIfRgACTEU"]
[Mon Jul 20 07:00:58.044333 2026] [security2:error] [pid 29744:tid 29839] [remote 103.75.185.95:37578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4cCuGINCUUz5GA9YIfWwACkV0"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 07:00:58.144845 2026] [security2:error] [pid 29744:tid 29878] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cCuGINCUUz5GA9YIfWQAAAhc"]
[Mon Jul 20 07:00:58.303842 2026] [security2:error] [pid 29744:tid 29971] [client 14.225.17.146:61669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4cCOGINCUUz5GA9YIe_gAAAnQ"], referer: http://balticsteelmgmt.com/2025
[Mon Jul 20 07:00:58.326203 2026] [proxy:error] [pid 29744:tid 29880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:58.326283 2026] [proxy_http:error] [pid 29744:tid 29880] [client 64.225.61.107:35692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:58.326918 2026] [proxy:error] [pid 29744:tid 29880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:58.326945 2026] [proxy_http:error] [pid 29744:tid 29880] [client 64.225.61.107:35692] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:58.343092 2026] [security2:error] [pid 29744:tid 29936] [client 117.222.139.248:60909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cCuGINCUUz5GA9YIfdAAAAlE"]
[Mon Jul 20 07:00:58.343233 2026] [security2:error] [pid 29744:tid 29936] [client 117.222.139.248:60909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cCuGINCUUz5GA9YIfdAAAAlE"]
[Mon Jul 20 07:00:58.470100 2026] [proxy:error] [pid 29744:tid 29955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:58.470170 2026] [proxy_http:error] [pid 29744:tid 29955] [client 64.225.61.107:35700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.crmpfilms.com/
[Mon Jul 20 07:00:58.470885 2026] [proxy:error] [pid 29744:tid 29955] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:58.470929 2026] [proxy_http:error] [pid 29744:tid 29955] [client 64.225.61.107:35700] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.crmpfilms.com/
[Mon Jul 20 07:00:58.626250 2026] [security2:error] [pid 29744:tid 29966] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cCuGINCUUz5GA9YIfhQAAAm8"]
[Mon Jul 20 07:00:58.645787 2026] [security2:error] [pid 29744:tid 29916] [client 209.242.198.236:54070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4cCuGINCUUz5GA9YIfcwACPWc"], referer: https://www.justinagrayman.com/contact/
[Mon Jul 20 07:00:58.662546 2026] [security2:error] [pid 29744:tid 29832] [remote 45.90.123.233:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4cCuGINCUUz5GA9YIflwACglY"]
[Mon Jul 20 07:00:58.738303 2026] [proxy:error] [pid 29744:tid 29995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:58.738363 2026] [proxy_http:error] [pid 29744:tid 29995] [client 64.225.61.107:46562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:58.739708 2026] [proxy:error] [pid 29744:tid 29995] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:00:58.739763 2026] [proxy_http:error] [pid 29744:tid 29995] [client 64.225.61.107:46562] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:00:58.851826 2026] [security2:error] [pid 29744:tid 29913] [client 104.234.53.84:62419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cCuGINCUUz5GA9YIfqAAAAjo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:00:58.861420 2026] [security2:error] [pid 28702:tid 28847] [client 65.111.24.76:20897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cCrF4957xPw9VVBmt8gAAAJM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:58.862911 2026] [security2:error] [pid 29744:tid 29749] [remote 45.90.123.233:59562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4cCuGINCUUz5GA9YIfqgACSwM"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 07:00:59.114133 2026] [security2:error] [pid 29744:tid 29975] [client 103.144.65.217:55974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cC-GINCUUz5GA9YIfvgAAAng"]
[Mon Jul 20 07:00:59.114262 2026] [security2:error] [pid 29744:tid 29975] [client 103.144.65.217:55974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cC-GINCUUz5GA9YIfvgAAAng"]
[Mon Jul 20 07:00:59.162530 2026] [security2:error] [pid 28702:tid 28859] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cC7F4957xPw9VVBmt_wAAAJ8"]
[Mon Jul 20 07:00:59.278678 2026] [security2:error] [pid 28702:tid 28943] [client 82.102.18.116:10986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4cC7F4957xPw9VVBmuFQAAAPM"]
[Mon Jul 20 07:00:59.592278 2026] [security2:error] [pid 29744:tid 29908] [client 82.102.18.116:45600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cC-GINCUUz5GA9YIf4gAAAjU"]
[Mon Jul 20 07:00:59.638532 2026] [security2:error] [pid 29744:tid 29997] [client 147.93.171.187:52506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "al4cC-GINCUUz5GA9YIf4wAAAo4"], referer: binance.com
[Mon Jul 20 07:00:59.644917 2026] [security2:error] [pid 29744:tid 29931] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cC-GINCUUz5GA9YIf3AAAAkw"]
[Mon Jul 20 07:00:59.760219 2026] [security2:error] [pid 28702:tid 28856] [client 45.3.37.117:27123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cC7F4957xPw9VVBmuHwAAAJw"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:00:59.914151 2026] [security2:error] [pid 28702:tid 28868] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cC7F4957xPw9VVBmuCQAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:00:59.941877 2026] [security2:error] [pid 29744:tid 29956] [client 57.141.18.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cC-GINCUUz5GA9YIf6wAAAmU"]
[Mon Jul 20 07:00:59.972904 2026] [security2:error] [pid 29744:tid 29882] [client 57.141.18.29:20956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cCuGINCUUz5GA9YIfiAACGz8"]
[Mon Jul 20 07:01:00.119455 2026] [security2:error] [pid 29744:tid 29978] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDOGINCUUz5GA9YIf_QAAAns"]
[Mon Jul 20 07:01:00.250016 2026] [security2:error] [pid 29744:tid 29994] [client 14.225.17.146:51174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4cC-GINCUUz5GA9YIf0AAAAos"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2025
[Mon Jul 20 07:01:00.286931 2026] [security2:error] [pid 28702:tid 28928] [client 82.102.18.116:45614] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4cDLF4957xPw9VVBmuMwAAAOQ"]
[Mon Jul 20 07:01:00.502384 2026] [security2:error] [pid 28702:tid 28875] [client 57.141.18.121:49710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cC7F4957xPw9VVBmuAwAArxU"]
[Mon Jul 20 07:01:00.515442 2026] [proxy:error] [pid 29744:tid 29934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:00.515518 2026] [proxy_http:error] [pid 29744:tid 29934] [client 64.225.61.107:46674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.crmpfilms.com/
[Mon Jul 20 07:01:00.515980 2026] [proxy:error] [pid 29744:tid 29934] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:00.516015 2026] [proxy_http:error] [pid 29744:tid 29934] [client 64.225.61.107:46674] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.crmpfilms.com/
[Mon Jul 20 07:01:00.604365 2026] [security2:error] [pid 29744:tid 29979] [client 82.102.18.116:45616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4cDOGINCUUz5GA9YIgLQAAAnw"]
[Mon Jul 20 07:01:00.626526 2026] [security2:error] [pid 28702:tid 28916] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDLF4957xPw9VVBmuNQAAANg"]
[Mon Jul 20 07:01:00.643308 2026] [security2:error] [pid 29744:tid 29953] [client 14.225.17.146:50763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4cCuGINCUUz5GA9YIfZgAAAmI"], referer: http://onewingpictures.com/2025
[Mon Jul 20 07:01:00.859562 2026] [security2:error] [pid 28702:tid 28952] [client 187.16.64.216:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cDLF4957xPw9VVBmuQQAAAPw"]
[Mon Jul 20 07:01:00.859683 2026] [security2:error] [pid 28702:tid 28952] [client 187.16.64.216:63454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cDLF4957xPw9VVBmuQQAAAPw"]
[Mon Jul 20 07:01:00.924623 2026] [security2:error] [pid 29744:tid 30002] [client 82.102.18.116:45622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4cDOGINCUUz5GA9YIgSAAAApM"]
[Mon Jul 20 07:01:01.116017 2026] [security2:error] [pid 29744:tid 29894] [client 217.181.92.200:15707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cDeGINCUUz5GA9YIgWwAAAic"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:01.165884 2026] [security2:error] [pid 29744:tid 29925] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDeGINCUUz5GA9YIgVQAAAkY"]
[Mon Jul 20 07:01:01.177683 2026] [security2:error] [pid 29744:tid 29937] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cDOGINCUUz5GA9YIgEAAAAlI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:01.261862 2026] [security2:error] [pid 29744:tid 29990] [client 82.102.18.116:45636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4cDeGINCUUz5GA9YIgaAAAAoc"]
[Mon Jul 20 07:01:01.554107 2026] [security2:error] [pid 28702:tid 28943] [client 65.111.22.101:48007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cDbF4957xPw9VVBmuWwAAAPM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:01.602073 2026] [security2:error] [pid 29744:tid 29892] [client 82.102.18.116:45638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cDeGINCUUz5GA9YIgggAAAiU"]
[Mon Jul 20 07:01:01.631533 2026] [security2:error] [pid 29744:tid 29894] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDeGINCUUz5GA9YIgfgAAAic"]
[Mon Jul 20 07:01:01.666159 2026] [security2:error] [pid 29744:tid 29974] [client 13.233.207.33:22446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cDeGINCUUz5GA9YIghAAAAnc"]
[Mon Jul 20 07:01:01.666271 2026] [security2:error] [pid 29744:tid 29974] [client 13.233.207.33:22446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cDeGINCUUz5GA9YIghAAAAnc"]
[Mon Jul 20 07:01:01.724967 2026] [security2:error] [pid 29744:tid 29925] [client 77.110.127.138:61345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cDeGINCUUz5GA9YIgjQAAAkY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:01.725070 2026] [security2:error] [pid 29744:tid 29925] [client 77.110.127.138:61345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cDeGINCUUz5GA9YIgjQAAAkY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:01.930932 2026] [security2:error] [pid 29744:tid 29907] [client 82.102.18.116:45644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4cDeGINCUUz5GA9YIgnAAAAjQ"]
[Mon Jul 20 07:01:01.961699 2026] [security2:error] [pid 29744:tid 29946] [client 14.225.17.146:65055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4cDOGINCUUz5GA9YIgAgAAAls"], referer: http://fineartsfactory.net/2025
[Mon Jul 20 07:01:02.076021 2026] [security2:error] [pid 29744:tid 29924] [client 14.225.17.146:65041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4cDeGINCUUz5GA9YIgiwAAAkU"], referer: http://hilltopnurseryinc.com/2025
[Mon Jul 20 07:01:02.103693 2026] [security2:error] [pid 29744:tid 29928] [client 104.207.50.194:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cDuGINCUUz5GA9YIgpgAAAkk"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:02.132340 2026] [security2:error] [pid 29744:tid 29889] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDuGINCUUz5GA9YIgpAAAAiI"]
[Mon Jul 20 07:01:02.236573 2026] [security2:error] [pid 29744:tid 29972] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cDeGINCUUz5GA9YIgegAAAnU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:02.269784 2026] [security2:error] [pid 29744:tid 29881] [client 82.102.18.116:45656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4cDuGINCUUz5GA9YIgtQAAAho"]
[Mon Jul 20 07:01:02.427365 2026] [security2:error] [pid 29744:tid 29890] [client 147.93.171.187:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "al4cDuGINCUUz5GA9YIgzAAAAiM"], referer: binance.com
[Mon Jul 20 07:01:02.596514 2026] [security2:error] [pid 29744:tid 29966] [client 82.102.18.116:45660] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cDuGINCUUz5GA9YIg1wAAAm8"]
[Mon Jul 20 07:01:02.621903 2026] [security2:error] [pid 29744:tid 29887] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDuGINCUUz5GA9YIg0QAAAiA"]
[Mon Jul 20 07:01:02.856259 2026] [security2:error] [pid 29744:tid 29829] [remote 45.90.123.233:37570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4cDuGINCUUz5GA9YIg6QACF1M"]
[Mon Jul 20 07:01:02.941067 2026] [security2:error] [pid 29744:tid 29958] [client 82.102.18.116:45664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cDuGINCUUz5GA9YIg8gAAAmc"]
[Mon Jul 20 07:01:02.988177 2026] [security2:error] [pid 29744:tid 29993] [client 158.173.166.181:51571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cDuGINCUUz5GA9YIg-QAAAoo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:01:03.028268 2026] [security2:error] [pid 29744:tid 29894] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cDuGINCUUz5GA9YIg7AAAAic"]
[Mon Jul 20 07:01:03.150885 2026] [security2:error] [pid 29744:tid 29925] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIg-gAAAkY"]
[Mon Jul 20 07:01:03.184704 2026] [security2:error] [pid 29744:tid 29889] [client 154.17.98.101:17602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIg_AAAAiI"]
[Mon Jul 20 07:01:03.188527 2026] [security2:error] [pid 29744:tid 29931] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cDuGINCUUz5GA9YIgygAAAkw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:03.189230 2026] [security2:error] [pid 28702:tid 28907] [client 104.234.53.51:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cD7F4957xPw9VVBmuhgAAAM8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:03.263999 2026] [security2:error] [pid 29744:tid 29876] [client 82.102.18.116:45670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cD-GINCUUz5GA9YIhBAAAAhU"]
[Mon Jul 20 07:01:03.388531 2026] [security2:error] [pid 29744:tid 29901] [client 14.225.17.146:50906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIhCQAAAi4"], referer: http://dasmarque.com/2025
[Mon Jul 20 07:01:03.512091 2026] [security2:error] [pid 29744:tid 29939] [client 14.225.17.146:64851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIg-wAAAlQ"]
[Mon Jul 20 07:01:03.536659 2026] [security2:error] [pid 29744:tid 29880] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIhDwAAAhk"]
[Mon Jul 20 07:01:03.607209 2026] [security2:error] [pid 29744:tid 29922] [client 82.102.18.116:45680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cD-GINCUUz5GA9YIhIwAAAkM"]
[Mon Jul 20 07:01:03.635525 2026] [security2:error] [pid 29744:tid 29930] [client 57.141.18.107:39012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cDeGINCUUz5GA9YIgngACSz4"]
[Mon Jul 20 07:01:03.668504 2026] [security2:error] [pid 28702:tid 28886] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cD7F4957xPw9VVBmulQAAALo"]
[Mon Jul 20 07:01:03.763854 2026] [security2:error] [pid 29744:tid 29986] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIhDgAAAoM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:03.944790 2026] [security2:error] [pid 29744:tid 29978] [client 14.225.17.146:59538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4cDuGINCUUz5GA9YIgqwAAAns"], referer: http://nomorewetsheets.net/2025
[Mon Jul 20 07:01:03.954013 2026] [security2:error] [pid 29744:tid 29963] [client 82.102.18.116:45690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4cD-GINCUUz5GA9YIhRAAAAmw"]
[Mon Jul 20 07:01:04.074767 2026] [security2:error] [pid 28702:tid 28898] [client 74.7.227.179:51996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4cD7F4957xPw9VVBmunQAAxm4"], referer: https://tejasenvironmental.com/p=599736
[Mon Jul 20 07:01:04.177941 2026] [security2:error] [pid 29744:tid 29942] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cEOGINCUUz5GA9YIhWgAAAlc"]
[Mon Jul 20 07:01:04.203882 2026] [security2:error] [pid 29744:tid 29760] [remote 182.77.62.24:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4cEOGINCUUz5GA9YIhYAACIQ4"]
[Mon Jul 20 07:01:04.231601 2026] [core:error] [pid 29744:tid 29908] [client 14.225.17.146:61744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2025
[Mon Jul 20 07:01:04.231625 2026] [core:error] [pid 29744:tid 29908] [client 14.225.17.146:61744] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2025
[Mon Jul 20 07:01:04.275423 2026] [security2:error] [pid 29744:tid 29931] [client 82.102.18.116:45692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4cEOGINCUUz5GA9YIhZAAAAkw"]
[Mon Jul 20 07:01:04.328398 2026] [security2:error] [pid 29744:tid 29989] [client 117.247.108.24:63596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cEOGINCUUz5GA9YIhZwAAAoY"]
[Mon Jul 20 07:01:04.328494 2026] [security2:error] [pid 29744:tid 29989] [client 117.247.108.24:63596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cEOGINCUUz5GA9YIhZwAAAoY"]
[Mon Jul 20 07:01:04.353332 2026] [security2:error] [pid 29744:tid 29873] [remote 45.90.123.233:37570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4cEOGINCUUz5GA9YIhaQACbn8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:01:04.509217 2026] [security2:error] [pid 29744:tid 29970] [client 77.110.127.138:61362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhdwAAAnM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.509310 2026] [security2:error] [pid 29744:tid 29970] [client 77.110.127.138:61362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhdwAAAnM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.569403 2026] [security2:error] [pid 28702:tid 28883] [client 213.152.161.101:33180] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4cELF4957xPw9VVBmupwAAALc"]
[Mon Jul 20 07:01:04.569485 2026] [security2:error] [pid 28702:tid 28883] [client 213.152.161.101:33180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4cELF4957xPw9VVBmupwAAALc"]
[Mon Jul 20 07:01:04.604224 2026] [security2:error] [pid 28702:tid 28866] [client 82.102.18.116:45696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cELF4957xPw9VVBmuqwAAAKY"]
[Mon Jul 20 07:01:04.619979 2026] [security2:error] [pid 29744:tid 29968] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4cEOGINCUUz5GA9YIheAAAAnE"]
[Mon Jul 20 07:01:04.704482 2026] [security2:error] [pid 29744:tid 29817] [remote 182.77.62.24:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4cEOGINCUUz5GA9YIhgAACfEc"], referer: https://mail.transamericagrid.com/wp-login.php
[Mon Jul 20 07:01:04.721662 2026] [security2:error] [pid 29744:tid 29924] [client 77.110.127.138:61287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhggAAAkU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.721795 2026] [security2:error] [pid 29744:tid 29924] [client 77.110.127.138:61287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhggAAAkU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.728181 2026] [security2:error] [pid 29744:tid 29972] [client 57.141.18.75:56260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cDuGINCUUz5GA9YIg6AACdWI"]
[Mon Jul 20 07:01:04.772419 2026] [security2:error] [pid 29744:tid 29975] [client 77.110.127.138:61335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhhAAAAng"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.772520 2026] [security2:error] [pid 29744:tid 29975] [client 77.110.127.138:61335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhhAAAAng"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.782735 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cEOGINCUUz5GA9YIhUwAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.788351 2026] [security2:error] [pid 29744:tid 29988] [client 122.183.32.225:13018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cEOGINCUUz5GA9YIhhQAAAoU"]
[Mon Jul 20 07:01:04.788447 2026] [security2:error] [pid 29744:tid 29988] [client 122.183.32.225:13018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cEOGINCUUz5GA9YIhhQAAAoU"]
[Mon Jul 20 07:01:04.808941 2026] [security2:error] [pid 29744:tid 29955] [client 103.238.106.162:63739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cEOGINCUUz5GA9YIhhgAAAmQ"]
[Mon Jul 20 07:01:04.809434 2026] [security2:error] [pid 29744:tid 29955] [client 103.238.106.162:63739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cEOGINCUUz5GA9YIhhgAAAmQ"]
[Mon Jul 20 07:01:04.825110 2026] [security2:error] [pid 29744:tid 29885] [client 77.110.127.138:61336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhiAAAAh4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.825209 2026] [security2:error] [pid 29744:tid 29885] [client 77.110.127.138:61336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEOGINCUUz5GA9YIhiAAAAh4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:04.939278 2026] [security2:error] [pid 29744:tid 29954] [client 82.102.18.116:45702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cEOGINCUUz5GA9YIhlgAAAmM"]
[Mon Jul 20 07:01:04.959150 2026] [security2:error] [pid 29744:tid 29898] [client 50.116.65.227:12822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cEOGINCUUz5GA9YIhmQAAAis"]
[Mon Jul 20 07:01:04.971429 2026] [security2:error] [pid 29744:tid 29904] [client 50.116.65.227:12838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cEOGINCUUz5GA9YIhmgAAAjE"]
[Mon Jul 20 07:01:05.009686 2026] [security2:error] [pid 28702:tid 28849] [client 77.110.127.138:61366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEbF4957xPw9VVBmutQAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.009783 2026] [security2:error] [pid 28702:tid 28849] [client 77.110.127.138:61366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEbF4957xPw9VVBmutQAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.061632 2026] [security2:error] [pid 28702:tid 28879] [client 77.110.127.138:61342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEbF4957xPw9VVBmuuAAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.061738 2026] [security2:error] [pid 28702:tid 28879] [client 77.110.127.138:61342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEbF4957xPw9VVBmuuAAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.099948 2026] [security2:error] [pid 29744:tid 29941] [client 114.119.137.122:64451] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sesamegreenbeans.com"] [uri "/baba-chews-feastcoastroad"] [unique_id "al4cEeGINCUUz5GA9YIhrQAAAlY"], referer: https://www.sesamegreenbeans.com/baba-chews-feastcoastroad
[Mon Jul 20 07:01:05.110007 2026] [security2:error] [pid 29744:tid 29926] [client 14.225.17.146:54186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4cD-GINCUUz5GA9YIhFwAAAkc"], referer: http://maplerespiteservices.com/2025
[Mon Jul 20 07:01:05.127365 2026] [security2:error] [pid 29744:tid 29928] [client 77.110.127.138:61346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEeGINCUUz5GA9YIhrwAAAkk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.127483 2026] [security2:error] [pid 29744:tid 29928] [client 77.110.127.138:61346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cEeGINCUUz5GA9YIhrwAAAkk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.158591 2026] [security2:error] [pid 28702:tid 28843] [client 154.208.48.130:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cEbF4957xPw9VVBmuuwAAAI8"]
[Mon Jul 20 07:01:05.158770 2026] [security2:error] [pid 28702:tid 28843] [client 154.208.48.130:60867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cEbF4957xPw9VVBmuuwAAAI8"]
[Mon Jul 20 07:01:05.264317 2026] [security2:error] [pid 28702:tid 28894] [client 82.102.18.116:45708] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fic.zzt.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4cEbF4957xPw9VVBmuwAAAAMI"]
[Mon Jul 20 07:01:05.365108 2026] [security2:error] [pid 29744:tid 29961] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cEeGINCUUz5GA9YIhpgAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.465488 2026] [security2:error] [pid 29744:tid 29948] [client 104.234.53.94:36613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cEeGINCUUz5GA9YIhvgAAAl0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:05.537944 2026] [security2:error] [pid 28702:tid 28919] [client 50.116.65.227:12874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4cEbF4957xPw9VVBmuwQAAANs"]
[Mon Jul 20 07:01:05.684763 2026] [security2:error] [pid 28702:tid 28918] [client 57.141.18.117:27464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4cEbF4957xPw9VVBmuywAA2lY"]
[Mon Jul 20 07:01:05.729515 2026] [security2:error] [pid 28702:tid 28844] [client 50.116.65.227:12880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4cEbF4957xPw9VVBmuzAAAAJA"]
[Mon Jul 20 07:01:05.732559 2026] [security2:error] [pid 28702:tid 28933] [client 147.93.171.187:52198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "al4cEbF4957xPw9VVBmu0AAAAOk"], referer: binance.com
[Mon Jul 20 07:01:05.761855 2026] [security2:error] [pid 29744:tid 29822] [remote 57.141.18.88:30282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4cEeGINCUUz5GA9YIh2wACfUw"]
[Mon Jul 20 07:01:05.824459 2026] [proxy:error] [pid 28702:tid 28946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.824531 2026] [proxy_http:error] [pid 28702:tid 28946] [client 208.84.100.245:57488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.825250 2026] [proxy:error] [pid 28702:tid 28946] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.825301 2026] [proxy_http:error] [pid 28702:tid 28946] [client 208.84.100.245:57488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.856949 2026] [security2:error] [pid 28702:tid 28841] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cEbF4957xPw9VVBmuzgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:05.870826 2026] [proxy:error] [pid 29744:tid 29941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.870877 2026] [proxy_http:error] [pid 29744:tid 29941] [client 208.84.100.245:49526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.871611 2026] [proxy:error] [pid 29744:tid 29941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.871651 2026] [proxy_http:error] [pid 29744:tid 29941] [client 208.84.100.245:49526] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.975835 2026] [proxy:error] [pid 29744:tid 29958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.975906 2026] [proxy_http:error] [pid 29744:tid 29958] [client 208.84.100.245:49550] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.976330 2026] [proxy:error] [pid 29744:tid 29958] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.976358 2026] [proxy_http:error] [pid 29744:tid 29958] [client 208.84.100.245:49550] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.976707 2026] [proxy:error] [pid 29744:tid 29889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.976812 2026] [proxy_http:error] [pid 29744:tid 29889] [client 208.84.100.245:49534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.977576 2026] [proxy:error] [pid 29744:tid 29889] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:05.977626 2026] [proxy_http:error] [pid 29744:tid 29889] [client 208.84.100.245:49534] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:05.986890 2026] [security2:error] [pid 29744:tid 29934] [client 50.116.65.227:12902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4cEeGINCUUz5GA9YIh3QAAAk8"]
[Mon Jul 20 07:01:06.181941 2026] [security2:error] [pid 29744:tid 29901] [client 50.116.65.227:12906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4cEeGINCUUz5GA9YIh6gAAAi4"]
[Mon Jul 20 07:01:06.713515 2026] [security2:error] [pid 29744:tid 29769] [remote 95.217.78.234:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4cEuGINCUUz5GA9YIiFgACdhc"]
[Mon Jul 20 07:01:06.935239 2026] [security2:error] [pid 29744:tid 29772] [remote 95.217.78.234:51092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4cEuGINCUUz5GA9YIiJAACWBo"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:01:07.704809 2026] [security2:error] [pid 28702:tid 28873] [client 14.225.17.146:59547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4cErF4957xPw9VVBmu3AAAAK0"], referer: http://momheadquarters.com/2025
[Mon Jul 20 07:01:07.733766 2026] [security2:error] [pid 29744:tid 29860] [remote 173.212.252.15:59534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cE-GINCUUz5GA9YIiTAACYHI"]
[Mon Jul 20 07:01:07.733892 2026] [security2:error] [pid 29744:tid 29951] [client 173.212.252.15:59534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cE-GINCUUz5GA9YIiTAACYHI"]
[Mon Jul 20 07:01:07.780366 2026] [security2:error] [pid 29744:tid 29971] [client 57.141.18.40:20578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cEuGINCUUz5GA9YIh-AACdAc"]
[Mon Jul 20 07:01:08.181904 2026] [security2:error] [pid 29744:tid 29979] [client 192.140.149.97:45337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cFOGINCUUz5GA9YIiYAAAAnw"]
[Mon Jul 20 07:01:08.182035 2026] [security2:error] [pid 29744:tid 29979] [client 192.140.149.97:45337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cFOGINCUUz5GA9YIiYAAAAnw"]
[Mon Jul 20 07:01:08.243126 2026] [security2:error] [pid 29744:tid 29985] [client 57.141.18.86:51294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cEuGINCUUz5GA9YIiFwACgic"]
[Mon Jul 20 07:01:08.775090 2026] [security2:error] [pid 28702:tid 28791] [remote 57.141.18.35:54122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6055825"] [unique_id "al4cFLF4957xPw9VVBmvHQAAyFc"]
[Mon Jul 20 07:01:08.830707 2026] [security2:error] [pid 29744:tid 29912] [client 117.222.139.248:61422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cFOGINCUUz5GA9YIifwAAAjk"]
[Mon Jul 20 07:01:08.831465 2026] [security2:error] [pid 29744:tid 29912] [client 117.222.139.248:61422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cFOGINCUUz5GA9YIifwAAAjk"]
[Mon Jul 20 07:01:08.848873 2026] [security2:error] [pid 29744:tid 29993] [client 66.249.65.36:34844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.techtradeinc.com"] [uri "/index.php"] [unique_id "al4cE-GINCUUz5GA9YIiVwAAAoo"]
[Mon Jul 20 07:01:09.410034 2026] [security2:error] [pid 28702:tid 28835] [client 147.93.171.187:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "al4cFbF4957xPw9VVBmvMQAAAIc"], referer: binance.com
[Mon Jul 20 07:01:09.747778 2026] [security2:error] [pid 29744:tid 29955] [client 103.144.65.217:56421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cFeGINCUUz5GA9YIiuQAAAmQ"]
[Mon Jul 20 07:01:09.747889 2026] [security2:error] [pid 29744:tid 29955] [client 103.144.65.217:56421] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cFeGINCUUz5GA9YIiuQAAAmQ"]
[Mon Jul 20 07:01:10.141489 2026] [security2:error] [pid 29744:tid 29889] [client 193.47.62.167:60826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-be93471d.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4cFOGINCUUz5GA9YIibwAAAiI"]
[Mon Jul 20 07:01:10.145559 2026] [security2:error] [pid 29744:tid 29981] [client 193.47.62.167:60832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-be93471d.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4cFOGINCUUz5GA9YIicQAAAn4"]
[Mon Jul 20 07:01:10.554378 2026] [security2:error] [pid 28702:tid 28864] [client 165.101.250.169:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "willowbranchequines.org"] [uri "/index.php"] [unique_id "al4cFLF4957xPw9VVBmvIAAAAKQ"]
[Mon Jul 20 07:01:10.581625 2026] [security2:error] [pid 29744:tid 29984] [client 66.249.73.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.terrapro.marketing"] [uri "/index.php"] [unique_id "al4cFuGINCUUz5GA9YIi6QAAAoE"]
[Mon Jul 20 07:01:10.595237 2026] [authz_core:error] [pid 28702:tid 28724] [remote 34.29.15.208:64928] AH01630: client denied by server configuration: /home1/asliceo1/public_html/jmark/php.ini, referer: http://www.jmark.asliceofleadership.com
[Mon Jul 20 07:01:10.647797 2026] [security2:error] [pid 29744:tid 29901] [client 14.225.17.146:54218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4cFOGINCUUz5GA9YIigwAAAi4"], referer: http://koaconsultants.com/2025
[Mon Jul 20 07:01:10.748397 2026] [security2:error] [pid 29744:tid 29955] [client 14.225.17.146:58310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4cFuGINCUUz5GA9YIi7AAAAmQ"], referer: http://adirondackengineering.com/2025
[Mon Jul 20 07:01:11.285078 2026] [security2:error] [pid 28702:tid 28890] [client 77.110.127.138:61381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cF7F4957xPw9VVBmvWgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:11.285171 2026] [security2:error] [pid 28702:tid 28890] [client 77.110.127.138:61381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cF7F4957xPw9VVBmvWgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:11.462893 2026] [security2:error] [pid 28702:tid 28869] [client 104.234.53.73:61859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cF7F4957xPw9VVBmvXwAAAKk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:11.511041 2026] [security2:error] [pid 29744:tid 29941] [client 45.3.38.126:31073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.38.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cF-GINCUUz5GA9YIjHAAAAlY"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:11.609808 2026] [security2:error] [pid 29744:tid 29894] [client 187.16.64.216:64008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cF-GINCUUz5GA9YIjJgAAAic"]
[Mon Jul 20 07:01:11.609913 2026] [security2:error] [pid 29744:tid 29894] [client 187.16.64.216:64008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cF-GINCUUz5GA9YIjJgAAAic"]
[Mon Jul 20 07:01:11.714207 2026] [security2:error] [pid 28702:tid 28895] [client 104.207.53.99:28803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cF7F4957xPw9VVBmvZwAAAMM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:11.774136 2026] [security2:error] [pid 28702:tid 28939] [client 98.159.234.160:20091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cF7F4957xPw9VVBmvaQAAAO8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:01:12.212473 2026] [security2:error] [pid 29744:tid 29986] [client 77.110.127.138:61383] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/2/"] [unique_id "al4cGOGINCUUz5GA9YIjPgAAAoM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:12.274557 2026] [security2:error] [pid 28702:tid 28858] [client 104.207.53.49:33451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cGLF4957xPw9VVBmvdAAAAJ4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:12.307411 2026] [security2:error] [pid 28702:tid 28931] [client 14.225.17.146:59716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cGLF4957xPw9VVBmvcwAAAOc"], referer: http://mezzacraft.com/2025
[Mon Jul 20 07:01:12.391137 2026] [security2:error] [pid 29744:tid 29984] [client 14.224.227.113:54854] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cGOGINCUUz5GA9YIjTAAAAoE"]
[Mon Jul 20 07:01:12.628421 2026] [security2:error] [pid 29744:tid 29883] [client 14.225.17.146:58736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4cGOGINCUUz5GA9YIjUQAAAhw"], referer: http://kromosenergy.com/2025
[Mon Jul 20 07:01:12.747940 2026] [security2:error] [pid 28702:tid 28844] [client 14.225.17.146:59624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4cGLF4957xPw9VVBmveQAAAJA"]
[Mon Jul 20 07:01:12.754575 2026] [security2:error] [pid 29744:tid 29957] [client 57.141.18.3:49276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cF-GINCUUz5GA9YIjDwACZgA"]
[Mon Jul 20 07:01:12.765931 2026] [security2:error] [pid 29744:tid 29947] [client 147.93.171.187:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "al4cGOGINCUUz5GA9YIjZgAAAlw"], referer: binance.com
[Mon Jul 20 07:01:12.814441 2026] [security2:error] [pid 29744:tid 29971] [client 74.208.214.194:52142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4cGOGINCUUz5GA9YIjagAAAnQ"]
[Mon Jul 20 07:01:12.835908 2026] [security2:error] [pid 29744:tid 29921] [client 104.207.52.37:36769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cGOGINCUUz5GA9YIjaQAAAkI"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:12.844811 2026] [security2:error] [pid 29744:tid 29999] [client 45.3.54.43:13181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cGOGINCUUz5GA9YIjawAAApA"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:13.406571 2026] [security2:error] [pid 28702:tid 28757] [remote 84.247.172.23:45202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cGbF4957xPw9VVBmvlAAAtDU"]
[Mon Jul 20 07:01:13.484205 2026] [core:error] [pid 29744:tid 29989] [client 14.225.17.146:59794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:01:13.484226 2026] [core:error] [pid 29744:tid 29989] [client 14.225.17.146:59794] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:01:13.569339 2026] [security2:error] [pid 29744:tid 29780] [remote 57.141.18.15:55856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4cGeGINCUUz5GA9YIjkgACXCI"]
[Mon Jul 20 07:01:13.587207 2026] [security2:error] [pid 29744:tid 29970] [client 57.141.18.81:31824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cGOGINCUUz5GA9YIjPAACcxs"]
[Mon Jul 20 07:01:13.661035 2026] [security2:error] [pid 28702:tid 28737] [remote 72.167.132.114:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cGbF4957xPw9VVBmvmgAA6CE"]
[Mon Jul 20 07:01:13.909551 2026] [security2:error] [pid 28702:tid 28741] [remote 72.167.132.114:49804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cGbF4957xPw9VVBmvnQAAmCU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:01:14.769334 2026] [security2:error] [pid 29744:tid 29903] [client 45.74.3.196:59839] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.74.3.196" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4cGuGINCUUz5GA9YIjxQAAAjA"], referer: https://youpositive.co/wp-login.php?action=register
[Mon Jul 20 07:01:14.897480 2026] [security2:error] [pid 28702:tid 28874] [client 183.82.98.154:64685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cGrF4957xPw9VVBmvwwAAAK4"]
[Mon Jul 20 07:01:14.897617 2026] [security2:error] [pid 28702:tid 28874] [client 183.82.98.154:64685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cGrF4957xPw9VVBmvwwAAAK4"]
[Mon Jul 20 07:01:15.136408 2026] [security2:error] [pid 28702:tid 28940] [client 117.247.108.24:14753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cG7F4957xPw9VVBmvzAAAAPA"]
[Mon Jul 20 07:01:15.136529 2026] [security2:error] [pid 28702:tid 28940] [client 117.247.108.24:14753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cG7F4957xPw9VVBmvzAAAAPA"]
[Mon Jul 20 07:01:15.393310 2026] [security2:error] [pid 29744:tid 29968] [client 103.238.106.162:42543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cG-GINCUUz5GA9YIj4AAAAnE"]
[Mon Jul 20 07:01:15.393414 2026] [security2:error] [pid 29744:tid 29968] [client 103.238.106.162:42543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cG-GINCUUz5GA9YIj4AAAAnE"]
[Mon Jul 20 07:01:15.580922 2026] [lsapi:error] [pid 29744:tid 29913] [client 66.249.73.198:0] [host www.deltat24.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 2916; user ID 2916), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.581128 2026] [lsapi:error] [pid 29744:tid 29942] [client 66.249.73.199:0] [host www.deltat24.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 2916; user ID 2916), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.581576 2026] [lsapi:error] [pid 29744:tid 29939] [client 66.249.73.192:0] [host www.deltat24.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 2916; user ID 2916), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.581658 2026] [lsapi:error] [pid 29744:tid 29965] [client 66.249.73.192:0] [host www.deltat24.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 2916; user ID 2916), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.581774 2026] [lsapi:error] [pid 28702:tid 28956] [client 66.249.73.199:0] [host www.deltat24.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 2916; user ID 2916), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.582228 2026] [lsapi:error] [pid 28702:tid 28906] [client 66.249.73.198:0] [host www.deltat24.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 2916; user ID 2916), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.584033 2026] [lsapi:error] [pid 28702:tid 28760] [remote 57.141.18.44:28386] [host toddnielsen.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1196; user ID 1196), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html
[Mon Jul 20 07:01:15.586314 2026] [lsapi:error] [pid 29744:tid 29906] [client 77.110.127.138:61409] [host mezzacraft.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1300; user ID 1300), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://mezzacraft.com/
[Mon Jul 20 07:01:15.586891 2026] [lsapi:error] [pid 29744:tid 29981] [client 77.110.127.138:61410] [host mezzacraft.com] Error receiving response header (lsphp is killed?): ReceiveResponseHeader: receive pkg hdr failed: ReceivePkgHdr: nothing to read from backend (LVE ID 1300; user ID 1300), check http://docs.cloudlinux.com/mod_lsapi_troubleshooting.html, referer: https://mezzacraft.com/
[Mon Jul 20 07:01:15.657078 2026] [security2:error] [pid 29744:tid 29991] [client 45.74.3.196:59869] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.74.3.196" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4cG-GINCUUz5GA9YIkHgAAAog"], referer: https://youpositive.co/wp-login.php?action=register
[Mon Jul 20 07:01:15.836711 2026] [security2:error] [pid 29744:tid 29764] [remote 47.86.33.52:15812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4cG-GINCUUz5GA9YIkLQACZRI"]
[Mon Jul 20 07:01:16.150377 2026] [security2:error] [pid 29744:tid 29777] [remote 5.161.225.162:47386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4cHOGINCUUz5GA9YIkSAACUh8"]
[Mon Jul 20 07:01:16.152972 2026] [security2:error] [pid 28702:tid 28885] [client 154.208.48.130:61472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cHLF4957xPw9VVBmv5wAAALk"]
[Mon Jul 20 07:01:16.153082 2026] [security2:error] [pid 28702:tid 28885] [client 154.208.48.130:61472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cHLF4957xPw9VVBmv5wAAALk"]
[Mon Jul 20 07:01:16.171267 2026] [security2:error] [pid 29744:tid 29896] [client 158.173.241.141:40383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4cG-GINCUUz5GA9YIkNwAAAik"], referer: http://sesamegreenbeans.com/tag/Japan/
[Mon Jul 20 07:01:16.370103 2026] [security2:error] [pid 29744:tid 29788] [remote 5.161.225.162:47386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4cHOGINCUUz5GA9YIkVwACeSo"], referer: https://karimnawfal.com/wp-login.php
[Mon Jul 20 07:01:16.420792 2026] [security2:error] [pid 28702:tid 28954] [client 65.111.22.128:44071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cHLF4957xPw9VVBmv6QAAAP4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:16.430235 2026] [security2:error] [pid 29744:tid 29988] [client 77.110.127.138:61416] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/2/"] [unique_id "al4cHOGINCUUz5GA9YIkXAAAAoU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:16.456589 2026] [security2:error] [pid 29744:tid 29892] [client 14.225.17.146:58926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4cGuGINCUUz5GA9YIjxAAAAiU"], referer: http://bigwormfishing.com/2025
[Mon Jul 20 07:01:16.579146 2026] [security2:error] [pid 29744:tid 29884] [client 45.74.3.196:59904] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.74.3.196" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4cHOGINCUUz5GA9YIkaAAAAh0"], referer: https://youpositive.co/wp-login.php?action=register
[Mon Jul 20 07:01:16.582934 2026] [security2:error] [pid 29744:tid 29920] [client 77.110.127.138:61417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cHOGINCUUz5GA9YIkaQAAAkE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:16.583031 2026] [security2:error] [pid 29744:tid 29920] [client 77.110.127.138:61417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cHOGINCUUz5GA9YIkaQAAAkE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:16.730593 2026] [security2:error] [pid 28702:tid 28925] [client 147.93.171.187:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-http.php"] [unique_id "al4cHLF4957xPw9VVBmv9wAAAOE"], referer: binance.com
[Mon Jul 20 07:01:16.853498 2026] [security2:error] [pid 29744:tid 29766] [remote 72.167.132.114:58772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cHOGINCUUz5GA9YIkeQACKhQ"]
[Mon Jul 20 07:01:16.868861 2026] [security2:error] [pid 29744:tid 29934] [client 50.116.65.227:49470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4cHOGINCUUz5GA9YIkfQAAAk8"]
[Mon Jul 20 07:01:16.881859 2026] [security2:error] [pid 29744:tid 29983] [client 14.225.17.146:50573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4cHOGINCUUz5GA9YIkXQAAAoA"], referer: http://alrowad-hub.net/2025
[Mon Jul 20 07:01:16.883426 2026] [security2:error] [pid 29744:tid 29926] [client 50.116.65.227:26472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4cHOGINCUUz5GA9YIkfgAAAmc"]
[Mon Jul 20 07:01:17.008400 2026] [security2:error] [pid 29744:tid 29890] [client 104.207.51.193:13373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cHOGINCUUz5GA9YIkhQAAAiM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:17.077827 2026] [security2:error] [pid 29744:tid 29796] [remote 72.167.132.114:58772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cHeGINCUUz5GA9YIkjwACGDI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:01:17.331112 2026] [security2:error] [pid 29744:tid 29818] [remote 47.86.33.52:15812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4cHeGINCUUz5GA9YIkoQACOUg"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:01:17.479438 2026] [security2:error] [pid 29744:tid 29928] [client 45.74.3.196:59954] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "45.74.3.196" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4cHeGINCUUz5GA9YIkqAAAAkk"], referer: https://youpositive.co/wp-login.php?action=register
[Mon Jul 20 07:01:17.564065 2026] [security2:error] [pid 28702:tid 28909] [client 14.225.17.146:57447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4cHbF4957xPw9VVBmwAwAAANE"], referer: https://bigwormfishing.com/2025
[Mon Jul 20 07:01:17.575683 2026] [security2:error] [pid 28702:tid 28948] [client 57.141.18.123:33500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cHLF4957xPw9VVBmv5AAA-Ek"]
[Mon Jul 20 07:01:17.602401 2026] [security2:error] [pid 29744:tid 29922] [client 65.111.22.160:23475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cHeGINCUUz5GA9YIksAAAAkM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:17.989144 2026] [security2:error] [pid 29744:tid 29935] [client 14.225.17.146:59833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4cG-GINCUUz5GA9YIkOwAAAlA"], referer: http://dollpassionista.com/2025
[Mon Jul 20 07:01:18.028058 2026] [security2:error] [pid 28702:tid 28908] [client 114.119.154.113:45017] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.betterbonddogtraining.com"] [uri "/robots.txt"] [unique_id "al4cHrF4957xPw9VVBmwGgAAANA"], referer: http://www.betterbonddogtraining.com/robots.txt
[Mon Jul 20 07:01:18.172513 2026] [security2:error] [pid 28702:tid 28843] [client 104.207.53.255:15409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cHrF4957xPw9VVBmwIwAAAI8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:18.671538 2026] [security2:error] [pid 29744:tid 29944] [client 47.128.114.144:22986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.allergyantidotes.com"] [uri "/robots.txt"] [unique_id "al4cHuGINCUUz5GA9YIk6gAAAlk"]
[Mon Jul 20 07:01:18.866701 2026] [security2:error] [pid 29744:tid 29965] [client 104.234.53.64:46145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cHuGINCUUz5GA9YIk8QAAAm4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:18.980495 2026] [security2:error] [pid 29744:tid 29939] [client 192.140.149.97:45312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cHuGINCUUz5GA9YIk-AAAAlQ"]
[Mon Jul 20 07:01:18.980603 2026] [security2:error] [pid 29744:tid 29939] [client 192.140.149.97:45312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cHuGINCUUz5GA9YIk-AAAAlQ"]
[Mon Jul 20 07:01:18.985051 2026] [security2:error] [pid 28702:tid 28898] [client 14.225.17.146:57560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4cHrF4957xPw9VVBmwMgAAAMY"], referer: https://dollpassionista.com/2025
[Mon Jul 20 07:01:19.384518 2026] [security2:error] [pid 28702:tid 28847] [client 117.222.139.248:61933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cH7F4957xPw9VVBmwPwAAAJM"]
[Mon Jul 20 07:01:19.384637 2026] [security2:error] [pid 28702:tid 28847] [client 117.222.139.248:61933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cH7F4957xPw9VVBmwPwAAAJM"]
[Mon Jul 20 07:01:19.696183 2026] [fcgid:warn] [pid 28702:tid 28840] (70014)End of file found: [client 198.143.60.7:5294] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.696227 2026] [fcgid:warn] [pid 29744:tid 29980] (70014)End of file found: [client 198.143.60.7:5282] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.696370 2026] [fcgid:warn] [pid 29744:tid 30001] (70014)End of file found: [client 198.143.60.7:5306] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.696713 2026] [fcgid:warn] [pid 29744:tid 29941] (70014)End of file found: [client 198.143.60.7:5318] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.699441 2026] [fcgid:warn] [pid 29744:tid 30000] (70014)End of file found: [client 198.143.60.7:5284] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.806297 2026] [fcgid:warn] [pid 29744:tid 29977] (70014)End of file found: [client 198.143.60.7:5328] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.912297 2026] [security2:error] [pid 29744:tid 29908] [client 50.116.65.227:58288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cH-GINCUUz5GA9YIlLwAAAjU"]
[Mon Jul 20 07:01:19.917967 2026] [fcgid:warn] [pid 29744:tid 29932] (70014)End of file found: [client 198.143.60.7:5336] mod_fcgid: can't get data from http client
[Mon Jul 20 07:01:19.921328 2026] [security2:error] [pid 29744:tid 29975] [client 50.116.65.227:58304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cH-GINCUUz5GA9YIlMQAAAng"]
[Mon Jul 20 07:01:20.251977 2026] [security2:error] [pid 29744:tid 29892] [client 147.93.171.187:62735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "al4cIOGINCUUz5GA9YIlQQAAAiU"], referer: binance.com
[Mon Jul 20 07:01:20.311102 2026] [security2:error] [pid 29744:tid 29884] [client 103.144.65.217:56867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cIOGINCUUz5GA9YIlSAAAAh0"]
[Mon Jul 20 07:01:20.311207 2026] [security2:error] [pid 29744:tid 29884] [client 103.144.65.217:56867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cIOGINCUUz5GA9YIlSAAAAh0"]
[Mon Jul 20 07:01:21.198196 2026] [security2:error] [pid 29744:tid 29882] [client 57.141.18.106:48574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cHOGINCUUz5GA9YIkewACG0M"]
[Mon Jul 20 07:01:21.339070 2026] [security2:error] [pid 29744:tid 29920] [client 136.107.64.51:65491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4cIeGINCUUz5GA9YIlfAAAAkE"]
[Mon Jul 20 07:01:21.428971 2026] [security2:error] [pid 29744:tid 29944] [client 52.167.144.210:1619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4cIOGINCUUz5GA9YIlTwACWUc"]
[Mon Jul 20 07:01:21.449939 2026] [security2:error] [pid 29744:tid 29969] [client 104.234.53.73:55043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cIeGINCUUz5GA9YIlgQAAAnI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:21.476334 2026] [security2:error] [pid 29744:tid 29992] [client 136.107.64.51:65491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/xmlrpc.php"] [unique_id "al4cIeGINCUUz5GA9YIliwAAAok"]
[Mon Jul 20 07:01:21.476454 2026] [security2:error] [pid 29744:tid 29992] [client 136.107.64.51:65491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "slutilities.com"] [uri "/xmlrpc.php"] [unique_id "al4cIeGINCUUz5GA9YIliwAAAok"]
[Mon Jul 20 07:01:21.773162 2026] [security2:error] [pid 29744:tid 29897] [client 104.234.53.73:55043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cIeGINCUUz5GA9YIlnAAAAio"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:22.306769 2026] [security2:error] [pid 29744:tid 29879] [client 147.93.171.187:49306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "al4cIuGINCUUz5GA9YIluQAAAhg"], referer: binance.com
[Mon Jul 20 07:01:22.360715 2026] [security2:error] [pid 29744:tid 29977] [client 187.16.64.216:64558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cIuGINCUUz5GA9YIlvAAAAno"]
[Mon Jul 20 07:01:22.360826 2026] [security2:error] [pid 29744:tid 29977] [client 187.16.64.216:64558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cIuGINCUUz5GA9YIlvAAAAno"]
[Mon Jul 20 07:01:22.444942 2026] [security2:error] [pid 29744:tid 29746] [remote 152.53.111.131:59730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cIuGINCUUz5GA9YIlvgACSwA"]
[Mon Jul 20 07:01:22.653384 2026] [security2:error] [pid 29744:tid 29747] [remote 192.241.143.148:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cIuGINCUUz5GA9YIlyAACUAE"]
[Mon Jul 20 07:01:22.667395 2026] [security2:error] [pid 29744:tid 29759] [remote 152.53.111.131:59730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cIuGINCUUz5GA9YIlywACKg0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:01:22.837456 2026] [security2:error] [pid 29744:tid 29802] [remote 192.241.143.148:57022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cIuGINCUUz5GA9YIl2AACYzg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:01:23.187793 2026] [security2:error] [pid 29744:tid 29919] [client 77.110.127.138:61452] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/2/"] [unique_id "al4cI-GINCUUz5GA9YIl7gAAAkA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:23.221934 2026] [security2:error] [pid 29744:tid 29928] [client 104.234.53.61:59355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cI-GINCUUz5GA9YIl8gAAAkk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:23.343181 2026] [security2:error] [pid 28702:tid 28920] [client 57.141.18.32:62326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cHbF4957xPw9VVBmwAgAA3HU"]
[Mon Jul 20 07:01:23.383333 2026] [security2:error] [pid 29744:tid 29906] [client 77.110.127.138:61453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cI-GINCUUz5GA9YIl_QAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:23.383436 2026] [security2:error] [pid 29744:tid 29906] [client 77.110.127.138:61453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cI-GINCUUz5GA9YIl_QAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:23.867356 2026] [security2:error] [pid 28702:tid 28728] [remote 202.51.202.242:34486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cI7F4957xPw9VVBmwpwAAhxg"]
[Mon Jul 20 07:01:23.955501 2026] [security2:error] [pid 29744:tid 29912] [client 104.234.53.59:35849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cI-GINCUUz5GA9YImIAAAAjk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:24.317224 2026] [security2:error] [pid 28702:tid 28745] [remote 202.51.202.242:34486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cJLF4957xPw9VVBmwuQAAjSk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:01:24.395858 2026] [security2:error] [pid 28702:tid 28829] [remote 5.252.52.249:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4cJLF4957xPw9VVBmwwgAA8H0"]
[Mon Jul 20 07:01:24.568201 2026] [security2:error] [pid 28702:tid 28896] [client 78.167.166.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4cJLF4957xPw9VVBmwtAAAAMQ"]
[Mon Jul 20 07:01:24.600770 2026] [security2:error] [pid 28702:tid 28737] [remote 5.252.52.249:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4cJLF4957xPw9VVBmwywAA_CE"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:01:24.913965 2026] [security2:error] [pid 29744:tid 29976] [client 104.234.53.59:35849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cJOGINCUUz5GA9YImVAAAAnk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:25.079073 2026] [security2:error] [pid 29744:tid 29850] [remote 103.75.185.95:33170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cJeGINCUUz5GA9YImXwACJWg"]
[Mon Jul 20 07:01:25.616385 2026] [security2:error] [pid 29744:tid 29856] [remote 103.75.185.95:33170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cJeGINCUUz5GA9YImeQACkW4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:01:25.703665 2026] [security2:error] [pid 28702:tid 28900] [client 114.119.130.96:39109] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "50.116.64.31"] [uri "/robots.txt"] [unique_id "al4cJbF4957xPw9VVBmw5gAAAMg"], referer: http://50.116.64.31/robots.txt
[Mon Jul 20 07:01:25.882987 2026] [security2:error] [pid 28702:tid 28855] [client 57.141.18.40:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cJbF4957xPw9VVBmw6AAAAJs"]
[Mon Jul 20 07:01:25.924997 2026] [security2:error] [pid 28702:tid 28892] [client 103.238.106.162:60568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cJbF4957xPw9VVBmw6gAAAMA"]
[Mon Jul 20 07:01:25.925490 2026] [security2:error] [pid 28702:tid 28892] [client 103.238.106.162:60568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cJbF4957xPw9VVBmw6gAAAMA"]
[Mon Jul 20 07:01:25.984494 2026] [security2:error] [pid 29744:tid 29909] [client 117.247.108.24:15260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cJeGINCUUz5GA9YImhgAAAjY"]
[Mon Jul 20 07:01:25.984613 2026] [security2:error] [pid 29744:tid 29909] [client 117.247.108.24:15260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cJeGINCUUz5GA9YImhgAAAjY"]
[Mon Jul 20 07:01:26.417532 2026] [security2:error] [pid 28702:tid 28878] [client 183.82.98.154:65281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cJrF4957xPw9VVBmxAgAAALI"]
[Mon Jul 20 07:01:26.417647 2026] [security2:error] [pid 28702:tid 28878] [client 183.82.98.154:65281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cJrF4957xPw9VVBmxAgAAALI"]
[Mon Jul 20 07:01:26.655891 2026] [security2:error] [pid 28702:tid 28932] [client 136.107.64.51:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/xmlrpc.php"] [unique_id "al4cJrF4957xPw9VVBmxDwAAAOg"]
[Mon Jul 20 07:01:26.783307 2026] [security2:error] [pid 29744:tid 29979] [client 136.107.64.51:52138] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4cJuGINCUUz5GA9YImtQAAAnw"]
[Mon Jul 20 07:01:26.903741 2026] [security2:error] [pid 28702:tid 28851] [client 136.107.64.51:57707] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/web/wp-includes/wlwmanifest.xml"] [unique_id "al4cJrF4957xPw9VVBmxEQAAAJc"]
[Mon Jul 20 07:01:26.944961 2026] [core:error] [pid 28702:tid 28852] [client 14.225.17.146:53845] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2025
[Mon Jul 20 07:01:26.944985 2026] [core:error] [pid 28702:tid 28852] [client 14.225.17.146:53845] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2025
[Mon Jul 20 07:01:26.958578 2026] [security2:error] [pid 29744:tid 29891] [client 104.234.53.94:45441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cJuGINCUUz5GA9YImvAAAAiQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:27.013091 2026] [security2:error] [pid 29744:tid 29989] [client 154.208.48.130:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cJ-GINCUUz5GA9YImxwAAAoY"]
[Mon Jul 20 07:01:27.013259 2026] [security2:error] [pid 29744:tid 29989] [client 154.208.48.130:62040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cJ-GINCUUz5GA9YImxwAAAoY"]
[Mon Jul 20 07:01:27.035696 2026] [security2:error] [pid 29744:tid 29956] [client 136.107.64.51:60594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ-GINCUUz5GA9YImyAAAAmU"]
[Mon Jul 20 07:01:27.136611 2026] [security2:error] [pid 29744:tid 29770] [remote 188.166.241.141:38188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4cJ-GINCUUz5GA9YImzgACfxg"]
[Mon Jul 20 07:01:27.189268 2026] [security2:error] [pid 28702:tid 28833] [client 136.107.64.51:60953] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ7F4957xPw9VVBmxIQAAAIU"]
[Mon Jul 20 07:01:27.279823 2026] [security2:error] [pid 29744:tid 29988] [client 57.141.18.10:63972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cHuGINCUUz5GA9YIk9wAChVE"]
[Mon Jul 20 07:01:27.325125 2026] [security2:error] [pid 29744:tid 29896] [client 122.183.32.225:2970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cJ-GINCUUz5GA9YIm1QAAAik"]
[Mon Jul 20 07:01:27.325222 2026] [security2:error] [pid 29744:tid 29896] [client 122.183.32.225:2970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cJ-GINCUUz5GA9YIm1QAAAik"]
[Mon Jul 20 07:01:27.331677 2026] [security2:error] [pid 28702:tid 28850] [client 136.107.64.51:60758] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ7F4957xPw9VVBmxJwAAAJY"]
[Mon Jul 20 07:01:27.447997 2026] [security2:error] [pid 29744:tid 29887] [client 136.107.64.51:64991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ-GINCUUz5GA9YIm2AAAAiA"]
[Mon Jul 20 07:01:27.526163 2026] [security2:error] [pid 29744:tid 29788] [remote 188.166.241.141:38188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4cJ-GINCUUz5GA9YIm4QACiio"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 07:01:27.616333 2026] [security2:error] [pid 28702:tid 28896] [client 136.107.64.51:55089] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ7F4957xPw9VVBmxLwAAAMQ"]
[Mon Jul 20 07:01:27.681497 2026] [security2:error] [pid 29744:tid 29903] [client 147.93.171.187:58823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "al4cJ-GINCUUz5GA9YIm6QAAAjA"], referer: binance.com
[Mon Jul 20 07:01:27.693243 2026] [security2:error] [pid 28702:tid 28898] [client 13.232.231.177:60318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cJ7F4957xPw9VVBmxMQAAAMY"]
[Mon Jul 20 07:01:27.738259 2026] [security2:error] [pid 29744:tid 29976] [client 136.107.64.51:58509] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ-GINCUUz5GA9YIm7QAAAnk"]
[Mon Jul 20 07:01:27.780304 2026] [security2:error] [pid 28702:tid 28910] [client 104.207.51.39:40191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cJ7F4957xPw9VVBmxMwAAANI"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:27.829235 2026] [security2:error] [pid 29744:tid 29989] [client 14.251.3.155:54857] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cJ-GINCUUz5GA9YIm9wAAAoY"]
[Mon Jul 20 07:01:27.928295 2026] [security2:error] [pid 28702:tid 28904] [client 136.107.64.51:57506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cJ7F4957xPw9VVBmxNgAAAMw"]
[Mon Jul 20 07:01:28.076762 2026] [security2:error] [pid 28702:tid 28874] [client 136.107.64.51:56698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cKLF4957xPw9VVBmxPgAAAK4"]
[Mon Jul 20 07:01:28.244249 2026] [security2:error] [pid 29744:tid 29983] [client 136.107.64.51:57587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cKOGINCUUz5GA9YInCQAAAoA"]
[Mon Jul 20 07:01:28.350792 2026] [security2:error] [pid 28702:tid 28879] [client 104.234.53.89:27987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cKLF4957xPw9VVBmxSQAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:28.406981 2026] [security2:error] [pid 28702:tid 28872] [client 136.107.64.51:59625] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "slydogdevelopment.com"] [uri "/cgi-sys/suspendedpage.cgi/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cKLF4957xPw9VVBmxSgAAAKw"]
[Mon Jul 20 07:01:28.635519 2026] [security2:error] [pid 29744:tid 29984] [client 13.233.207.33:61050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cKOGINCUUz5GA9YInGQAAAoE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:01:28.638135 2026] [security2:error] [pid 28702:tid 28903] [client 14.225.17.146:54041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4cKLF4957xPw9VVBmxUQAAAMs"]
[Mon Jul 20 07:01:29.101806 2026] [security2:error] [pid 29744:tid 29953] [client 144.172.104.62:45350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wgs.doq.mybluehost.me"] [uri "/index.php"] [unique_id "al4cKOGINCUUz5GA9YIm_wAAAmI"]
[Mon Jul 20 07:01:29.617681 2026] [security2:error] [pid 28702:tid 28856] [client 192.140.149.97:44798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cKbF4957xPw9VVBmxcQAAAJw"]
[Mon Jul 20 07:01:29.617799 2026] [security2:error] [pid 28702:tid 28856] [client 192.140.149.97:44798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cKbF4957xPw9VVBmxcQAAAJw"]
[Mon Jul 20 07:01:29.850168 2026] [security2:error] [pid 29744:tid 29990] [client 77.110.127.138:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cKeGINCUUz5GA9YInYQAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:29.850255 2026] [security2:error] [pid 29744:tid 29990] [client 77.110.127.138:61476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cKeGINCUUz5GA9YInYQAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:29.899030 2026] [security2:error] [pid 29744:tid 29963] [client 117.222.139.248:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cKeGINCUUz5GA9YInZAAAAmw"]
[Mon Jul 20 07:01:29.899117 2026] [security2:error] [pid 29744:tid 29963] [client 117.222.139.248:62447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cKeGINCUUz5GA9YInZAAAAmw"]
[Mon Jul 20 07:01:29.974447 2026] [security2:error] [pid 29744:tid 29814] [remote 87.106.67.224:50098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4cKeGINCUUz5GA9YInZgACTUQ"]
[Mon Jul 20 07:01:30.078948 2026] [security2:error] [pid 29744:tid 29902] [client 14.225.17.146:53937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4cJ-GINCUUz5GA9YIm8AAAAi8"], referer: http://adastra.love/2025
[Mon Jul 20 07:01:30.157911 2026] [security2:error] [pid 29744:tid 29850] [remote 87.106.67.224:50098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.67.106.87.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4cKuGINCUUz5GA9YIncgACKmg"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 07:01:30.344568 2026] [security2:error] [pid 29744:tid 29879] [client 14.225.17.146:61524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4cKuGINCUUz5GA9YIndQAAAhg"], referer: http://longevityperformanceclinic.com/2025
[Mon Jul 20 07:01:30.765780 2026] [security2:error] [pid 29744:tid 29903] [client 104.234.53.72:51677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cKuGINCUUz5GA9YInjAAAAjA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:30.857049 2026] [security2:error] [pid 29744:tid 29911] [client 103.144.65.217:57318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cKuGINCUUz5GA9YInjwAAAjg"]
[Mon Jul 20 07:01:30.857180 2026] [security2:error] [pid 29744:tid 29911] [client 103.144.65.217:57318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cKuGINCUUz5GA9YInjwAAAjg"]
[Mon Jul 20 07:01:30.971809 2026] [security2:error] [pid 28702:tid 28704] [remote 100.42.189.89:42414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cKrF4957xPw9VVBmxogAA_gA"]
[Mon Jul 20 07:01:31.192261 2026] [security2:error] [pid 28702:tid 28764] [remote 100.42.189.89:42414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cK7F4957xPw9VVBmxrAAAzDw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:01:31.324020 2026] [security2:error] [pid 28702:tid 28822] [remote 47.86.33.52:11648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4cK7F4957xPw9VVBmxswAAoXY"]
[Mon Jul 20 07:01:31.345217 2026] [security2:error] [pid 29744:tid 29977] [client 14.225.17.146:53575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4cK-GINCUUz5GA9YInngAAAno"]
[Mon Jul 20 07:01:31.370318 2026] [security2:error] [pid 28702:tid 28874] [client 14.225.17.146:56193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4cKrF4957xPw9VVBmxfQAAAK4"], referer: http://wathenbartlett.co.uk/2025
[Mon Jul 20 07:01:31.561083 2026] [security2:error] [pid 29744:tid 29914] [client 147.93.171.187:60349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "al4cK-GINCUUz5GA9YInqwAAAjs"], referer: binance.com
[Mon Jul 20 07:01:31.822125 2026] [security2:error] [pid 28702:tid 28756] [remote 47.86.33.52:11648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4cK7F4957xPw9VVBmxwQAA0DQ"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:01:32.066364 2026] [security2:error] [pid 29744:tid 29886] [client 50.116.65.227:56736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cLOGINCUUz5GA9YInvwAAAh8"]
[Mon Jul 20 07:01:32.076283 2026] [security2:error] [pid 29744:tid 29883] [client 50.116.65.227:56748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cLOGINCUUz5GA9YInwQAAAhw"]
[Mon Jul 20 07:01:32.307137 2026] [security2:error] [pid 28702:tid 28854] [client 104.234.53.89:37085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cLLF4957xPw9VVBmxyAAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:32.311381 2026] [security2:error] [pid 28702:tid 28936] [client 14.225.17.146:56224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4cK7F4957xPw9VVBmxrQAAAOw"], referer: http://intelligentengineeringsolutions.com/2025
[Mon Jul 20 07:01:32.334942 2026] [security2:error] [pid 29744:tid 29877] [client 14.225.17.146:56355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4cLOGINCUUz5GA9YInyQAAAhY"], referer: https://wathenbartlett.co.uk/2025
[Mon Jul 20 07:01:32.404912 2026] [security2:error] [pid 29744:tid 29761] [remote 50.28.1.50:49720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4cLOGINCUUz5GA9YIn0QACVg8"]
[Mon Jul 20 07:01:32.778356 2026] [security2:error] [pid 29744:tid 29750] [remote 50.28.1.50:49720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4cLOGINCUUz5GA9YIn4wACIQQ"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:01:33.213212 2026] [security2:error] [pid 29744:tid 29912] [client 187.16.64.216:65119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cLeGINCUUz5GA9YIn-AAAAjk"]
[Mon Jul 20 07:01:33.213316 2026] [security2:error] [pid 29744:tid 29912] [client 187.16.64.216:65119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cLeGINCUUz5GA9YIn-AAAAjk"]
[Mon Jul 20 07:01:33.235253 2026] [security2:error] [pid 28702:tid 28906] [client 57.141.18.73:23458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cIrF4957xPw9VVBmwiwAAzhc"]
[Mon Jul 20 07:01:33.654413 2026] [security2:error] [pid 28702:tid 28925] [client 74.7.230.26:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sunsupplyservices.com"] [uri "/index.php"] [unique_id "al4cKLF4957xPw9VVBmxTQAA4Wo"]
[Mon Jul 20 07:01:33.668485 2026] [security2:error] [pid 29744:tid 29752] [remote 47.86.33.52:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4cLeGINCUUz5GA9YIoEwACZAY"]
[Mon Jul 20 07:01:33.916430 2026] [security2:error] [pid 28702:tid 28879] [client 20.65.194.84:55554] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.65.227"] [uri "/index.cgi"] [unique_id "al4cLbF4957xPw9VVBmx9gAAALM"]
[Mon Jul 20 07:01:34.343600 2026] [security2:error] [pid 29744:tid 29866] [remote 47.86.33.52:57642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4cLuGINCUUz5GA9YIoUwACcng"], referer: https://fluidtemple.org/wp-login.php
[Mon Jul 20 07:01:34.389501 2026] [security2:error] [pid 28702:tid 28845] [client 14.225.17.146:57636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4cLbF4957xPw9VVBmx5gAAAJE"], referer: http://ncsynchro.com/2025
[Mon Jul 20 07:01:34.473106 2026] [autoindex:error] [pid 29744:tid 29934] [client 198.235.24.169:64188] AH01276: Cannot serve directory /home2/dekbypmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:01:34.713653 2026] [proxy:error] [pid 28702:tid 28947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:34.713688 2026] [proxy_http:error] [pid 28702:tid 28947] [client 107.172.180.205:34920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:34.714136 2026] [proxy:error] [pid 28702:tid 28947] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:34.714159 2026] [proxy_http:error] [pid 28702:tid 28947] [client 107.172.180.205:34920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:34.730761 2026] [security2:error] [pid 28702:tid 28815] [remote 100.42.189.89:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4cLrF4957xPw9VVBmyDAAA7G8"]
[Mon Jul 20 07:01:34.922934 2026] [security2:error] [pid 29744:tid 29991] [client 147.93.171.187:55887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "al4cLuGINCUUz5GA9YIocAAAAog"], referer: binance.com
[Mon Jul 20 07:01:34.952627 2026] [security2:error] [pid 28702:tid 28706] [remote 100.42.189.89:42440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4cLrF4957xPw9VVBmyDwAApwI"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:01:35.113917 2026] [security2:error] [pid 28702:tid 28942] [client 46.110.96.34:3390] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4cL7F4957xPw9VVBmyEwAAAPI"]
[Mon Jul 20 07:01:35.177161 2026] [security2:error] [pid 29744:tid 29879] [client 54.204.158.117:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4cLeGINCUUz5GA9YIoEAAAAhg"]
[Mon Jul 20 07:01:35.179878 2026] [security2:error] [pid 29744:tid 29897] [client 54.204.158.117:15304] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4cLeGINCUUz5GA9YIoDgAAAio"]
[Mon Jul 20 07:01:35.282460 2026] [security2:error] [pid 29744:tid 29895] [client 104.234.53.93:41853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cL-GINCUUz5GA9YIokwAAAig"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:35.304148 2026] [security2:error] [pid 29744:tid 29946] [client 122.192.133.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4cL-GINCUUz5GA9YIoggAAAls"]
[Mon Jul 20 07:01:35.305844 2026] [security2:error] [pid 29744:tid 29869] [remote 154.66.198.148:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4cL-GINCUUz5GA9YIolAACbHs"]
[Mon Jul 20 07:01:35.306865 2026] [security2:error] [pid 29744:tid 29930] [client 122.192.133.49:47241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/works.php"] [unique_id "al4cL-GINCUUz5GA9YIofwAAAks"]
[Mon Jul 20 07:01:35.781424 2026] [autoindex:error] [pid 28702:tid 28883] [client 188.39.109.162:19895] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:01:35.842778 2026] [security2:error] [pid 29744:tid 29837] [remote 154.66.198.148:37194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4cL-GINCUUz5GA9YIorgACNFs"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:01:36.085848 2026] [security2:error] [pid 28702:tid 28921] [client 104.234.53.83:61335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cMLF4957xPw9VVBmyMAAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:36.215889 2026] [security2:error] [pid 28702:tid 28852] [client 122.183.32.225:21419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cMLF4957xPw9VVBmyNAAAAJg"]
[Mon Jul 20 07:01:36.216085 2026] [security2:error] [pid 28702:tid 28852] [client 122.183.32.225:21419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cMLF4957xPw9VVBmyNAAAAJg"]
[Mon Jul 20 07:01:36.221975 2026] [security2:error] [pid 28702:tid 28879] [client 122.192.133.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4cMLF4957xPw9VVBmyLwAAALM"]
[Mon Jul 20 07:01:36.244284 2026] [core:alert] [pid 29744:tid 29972] [client 136.67.100.54:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:01:36.300996 2026] [security2:error] [pid 28702:tid 28918] [client 14.225.17.146:63605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4cL7F4957xPw9VVBmyJwAAANo"], referer: http://guidehunting.com/2025
[Mon Jul 20 07:01:36.327390 2026] [security2:error] [pid 29744:tid 29758] [remote 188.166.241.141:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cMOGINCUUz5GA9YIoygACFQw"]
[Mon Jul 20 07:01:36.499712 2026] [security2:error] [pid 29744:tid 29902] [client 103.238.106.162:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cMOGINCUUz5GA9YIo0wAAAi8"]
[Mon Jul 20 07:01:36.499857 2026] [security2:error] [pid 29744:tid 29902] [client 103.238.106.162:60864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cMOGINCUUz5GA9YIo0wAAAi8"]
[Mon Jul 20 07:01:36.569141 2026] [security2:error] [pid 28702:tid 28937] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cMLF4957xPw9VVBmyNwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:36.583714 2026] [security2:error] [pid 29744:tid 29908] [client 14.225.17.146:50166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4cLuGINCUUz5GA9YIobwAAAjU"], referer: http://ksands.co.uk/2025
[Mon Jul 20 07:01:36.619393 2026] [security2:error] [pid 29744:tid 30000] [client 14.225.17.146:50191] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4cLuGINCUUz5GA9YIocgAAApE"], referer: http://myspineworld.com/2025
[Mon Jul 20 07:01:36.707503 2026] [security2:error] [pid 29744:tid 29835] [remote 188.166.241.141:49170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cMOGINCUUz5GA9YIo3wACW1k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:01:36.714570 2026] [security2:error] [pid 28702:tid 28948] [client 57.141.18.104:61602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cJLF4957xPw9VVBmwygAA-C0"]
[Mon Jul 20 07:01:36.783670 2026] [security2:error] [pid 28702:tid 28878] [client 77.110.127.138:61507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cMLF4957xPw9VVBmySAAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:36.783810 2026] [security2:error] [pid 28702:tid 28878] [client 77.110.127.138:61507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cMLF4957xPw9VVBmySAAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:37.117266 2026] [security2:error] [pid 29744:tid 29972] [client 117.247.108.24:15994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cMeGINCUUz5GA9YIo8gAAAnU"]
[Mon Jul 20 07:01:37.117401 2026] [security2:error] [pid 29744:tid 29972] [client 117.247.108.24:15994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cMeGINCUUz5GA9YIo8gAAAnU"]
[Mon Jul 20 07:01:37.167460 2026] [security2:error] [pid 29744:tid 29897] [client 14.225.17.146:53827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4cMOGINCUUz5GA9YIo5QAAAio"], referer: http://grecruit.online/2025
[Mon Jul 20 07:01:37.227416 2026] [proxy:error] [pid 29744:tid 29993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:37.227476 2026] [proxy_http:error] [pid 29744:tid 29993] [client 107.172.180.205:34940] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:37.228975 2026] [proxy:error] [pid 29744:tid 29993] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:37.229031 2026] [proxy_http:error] [pid 29744:tid 29993] [client 107.172.180.205:34940] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:37.361396 2026] [security2:error] [pid 29744:tid 29958] [client 104.207.53.95:51781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cMeGINCUUz5GA9YIpBAAAAmc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:37.451019 2026] [security2:error] [pid 29744:tid 29801] [remote 5.252.52.249:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4cMeGINCUUz5GA9YIpCQACMzc"]
[Mon Jul 20 07:01:37.464232 2026] [security2:error] [pid 28702:tid 28935] [client 14.225.17.146:49895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4cMbF4957xPw9VVBmyYAAAAOs"], referer: https://guidehunting.com/2025
[Mon Jul 20 07:01:37.619365 2026] [security2:error] [pid 29744:tid 29853] [remote 5.252.52.249:58384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4cMeGINCUUz5GA9YIpFAACR2s"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 07:01:37.761886 2026] [security2:error] [pid 29744:tid 29893] [client 14.225.17.146:53761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4cMOGINCUUz5GA9YIo4AAAAiY"], referer: http://partnerselectricalllc.com/2025
[Mon Jul 20 07:01:38.019357 2026] [security2:error] [pid 28702:tid 28865] [client 104.234.53.92:32723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cMrF4957xPw9VVBmydAAAAKU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:38.262970 2026] [security2:error] [pid 29744:tid 29914] [client 183.82.98.154:49514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cMuGINCUUz5GA9YIpNAAAAjs"]
[Mon Jul 20 07:01:38.263206 2026] [security2:error] [pid 29744:tid 29914] [client 183.82.98.154:49514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cMuGINCUUz5GA9YIpNAAAAjs"]
[Mon Jul 20 07:01:38.356204 2026] [security2:error] [pid 29744:tid 29938] [client 114.119.133.89:45915] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/robots.txt"] [unique_id "al4cMuGINCUUz5GA9YIpPQAAAlM"], referer: http://www.ccsdifference.com/robots.txt
[Mon Jul 20 07:01:38.542508 2026] [security2:error] [pid 29744:tid 29954] [client 57.141.18.83:54076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cJOGINCUUz5GA9YImQwACY00"]
[Mon Jul 20 07:01:38.802857 2026] [security2:error] [pid 29744:tid 29984] [client 154.208.48.130:62532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cMuGINCUUz5GA9YIpUQAAAoE"]
[Mon Jul 20 07:01:38.802948 2026] [security2:error] [pid 29744:tid 29984] [client 154.208.48.130:62532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cMuGINCUUz5GA9YIpUQAAAoE"]
[Mon Jul 20 07:01:39.092504 2026] [security2:error] [pid 29744:tid 29981] [client 74.208.214.194:42972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4cM-GINCUUz5GA9YIpWAAAAn4"]
[Mon Jul 20 07:01:39.245866 2026] [security2:error] [pid 29744:tid 29914] [client 147.93.171.187:51917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "al4cM-GINCUUz5GA9YIpXgAAAjs"], referer: binance.com
[Mon Jul 20 07:01:39.266135 2026] [security2:error] [pid 28702:tid 28864] [client 14.225.17.146:63926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4cM7F4957xPw9VVBmypAAAAKQ"], referer: http://uritems.net/2025
[Mon Jul 20 07:01:39.712458 2026] [security2:error] [pid 29744:tid 29970] [client 34.221.76.50:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4cM-GINCUUz5GA9YIpcQAAAnM"]
[Mon Jul 20 07:01:39.757019 2026] [security2:error] [pid 29744:tid 29883] [client 14.225.17.146:53407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4cM-GINCUUz5GA9YIpcAAAAhw"], referer: http://daseighty.net/2025
[Mon Jul 20 07:01:39.983885 2026] [security2:error] [pid 29744:tid 29964] [client 104.234.53.88:26239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cM-GINCUUz5GA9YIpewAAAm0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:40.228964 2026] [security2:error] [pid 28702:tid 28816] [remote 8.217.108.67:49018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4cNLF4957xPw9VVBmywwAApnA"]
[Mon Jul 20 07:01:40.495524 2026] [security2:error] [pid 29744:tid 29827] [remote 188.40.28.4:56136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cNOGINCUUz5GA9YIplwACPlE"]
[Mon Jul 20 07:01:40.502978 2026] [security2:error] [pid 29744:tid 29948] [client 14.225.17.146:63608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4cMeGINCUUz5GA9YIpHwAAAl0"]
[Mon Jul 20 07:01:40.512374 2026] [security2:error] [pid 28702:tid 28888] [client 117.222.139.248:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cNLF4957xPw9VVBmyyAAAALw"]
[Mon Jul 20 07:01:40.512478 2026] [security2:error] [pid 28702:tid 28888] [client 117.222.139.248:62955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cNLF4957xPw9VVBmyyAAAALw"]
[Mon Jul 20 07:01:40.628601 2026] [security2:error] [pid 29744:tid 29898] [client 57.141.18.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4cNOGINCUUz5GA9YIpkgAAAis"]
[Mon Jul 20 07:01:40.685229 2026] [security2:error] [pid 29744:tid 29784] [remote 188.40.28.4:56136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cNOGINCUUz5GA9YIpqAACiyY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:01:40.703332 2026] [security2:error] [pid 28702:tid 28758] [remote 8.217.108.67:49018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4cNLF4957xPw9VVBmyzAAA1zY"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 07:01:40.749137 2026] [autoindex:error] [pid 29744:tid 29759] [remote 35.196.99.113:64078] AH01276: Cannot serve directory /home2/shnhbfmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://shn.hbf.mybluehost.me
[Mon Jul 20 07:01:41.146579 2026] [security2:error] [pid 29744:tid 29877] [client 104.234.53.88:21501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cNeGINCUUz5GA9YIpwgAAAhY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:41.337514 2026] [security2:error] [pid 29744:tid 29780] [remote 57.141.18.97:45620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4cNeGINCUUz5GA9YIp1gACPyI"]
[Mon Jul 20 07:01:41.352657 2026] [security2:error] [pid 29744:tid 29926] [client 103.144.65.217:57756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cNeGINCUUz5GA9YIp1wAAAkc"]
[Mon Jul 20 07:01:41.352826 2026] [security2:error] [pid 29744:tid 29926] [client 103.144.65.217:57756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cNeGINCUUz5GA9YIp1wAAAkc"]
[Mon Jul 20 07:01:41.558949 2026] [security2:error] [pid 28702:tid 28909] [client 14.225.17.146:54643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4cNbF4957xPw9VVBmy2QAAANE"], referer: http://falconarrowshop.com/2025
[Mon Jul 20 07:01:41.608326 2026] [security2:error] [pid 29744:tid 29886] [client 43.173.180.76:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.180.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bandsir.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cNeGINCUUz5GA9YIp5QAAAh8"], referer: https://bandsir.com/playlist-errors-should-be-resolved/
[Mon Jul 20 07:01:42.230289 2026] [security2:error] [pid 29744:tid 29879] [client 161.35.40.239:51835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4cNuGINCUUz5GA9YIqGAAAAhg"]
[Mon Jul 20 07:01:42.268515 2026] [ssl:error] [pid 29744:tid 29939] [client 2.194.183.79:52724] AH02032: Hostname www.phillipbloch.com provided via SNI and hostname open.spotify.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:01:42.324273 2026] [security2:error] [pid 29744:tid 29988] [client 65.111.30.3:16653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cNuGINCUUz5GA9YIqJgAAAoU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:42.448663 2026] [security2:error] [pid 28702:tid 28838] [client 14.224.227.113:54860] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cNrF4957xPw9VVBmy8wAAAIo"]
[Mon Jul 20 07:01:42.539337 2026] [security2:error] [pid 29744:tid 29923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cNuGINCUUz5GA9YIqKAAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:42.750543 2026] [security2:error] [pid 28702:tid 28879] [client 77.110.127.138:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cNrF4957xPw9VVBmy-wAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:42.750653 2026] [security2:error] [pid 28702:tid 28879] [client 77.110.127.138:61539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cNrF4957xPw9VVBmy-wAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:42.800476 2026] [security2:error] [pid 29744:tid 29904] [client 161.35.40.239:51908] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4cNuGINCUUz5GA9YIqSwAAAjE"]
[Mon Jul 20 07:01:42.997719 2026] [security2:error] [pid 29744:tid 29963] [client 66.249.74.5:55673] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "futuredepthcharts.com"] [uri "/robots.txt"] [unique_id "al4cNuGINCUUz5GA9YIqVAAAAmw"]
[Mon Jul 20 07:01:43.099160 2026] [security2:error] [pid 29744:tid 29823] [remote 84.247.172.23:40592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cN-GINCUUz5GA9YIqVwACa00"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:01:43.242483 2026] [security2:error] [pid 28702:tid 28833] [client 45.3.37.90:10695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.37.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cN7F4957xPw9VVBmzDwAAAIU"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:43.335502 2026] [security2:error] [pid 29744:tid 29899] [client 50.116.65.227:56082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cN-GINCUUz5GA9YIqYAAAAiw"]
[Mon Jul 20 07:01:43.345102 2026] [security2:error] [pid 28702:tid 28936] [client 50.116.65.227:56088] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cN7F4957xPw9VVBmzGQAAAOw"]
[Mon Jul 20 07:01:43.390034 2026] [security2:error] [pid 29744:tid 29901] [client 57.141.18.118:35278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cJuGINCUUz5GA9YImkAACLmI"]
[Mon Jul 20 07:01:43.550587 2026] [security2:error] [pid 29744:tid 29946] [client 34.48.79.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4cNuGINCUUz5GA9YIqMwAAAls"]
[Mon Jul 20 07:01:43.641356 2026] [security2:error] [pid 28702:tid 28855] [client 34.48.79.16:61671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.79.48.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/xmlrpc.php"] [unique_id "al4cN7F4957xPw9VVBmzKAAAAJs"]
[Mon Jul 20 07:01:43.787818 2026] [proxy:error] [pid 29744:tid 30000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:43.787883 2026] [proxy_http:error] [pid 29744:tid 30000] [client 87.236.176.201:52973] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:43.788384 2026] [proxy:error] [pid 29744:tid 30000] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:01:43.788408 2026] [proxy_http:error] [pid 29744:tid 30000] [client 87.236.176.201:52973] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:01:43.989724 2026] [security2:error] [pid 29744:tid 29939] [client 34.48.79.16:61674] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4cN-GINCUUz5GA9YIqhgAAAlQ"]
[Mon Jul 20 07:01:44.016059 2026] [security2:error] [pid 29744:tid 29904] [client 187.16.64.216:49284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cOOGINCUUz5GA9YIqiAAAAjE"]
[Mon Jul 20 07:01:44.016167 2026] [security2:error] [pid 29744:tid 29904] [client 187.16.64.216:49284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cOOGINCUUz5GA9YIqiAAAAjE"]
[Mon Jul 20 07:01:44.261929 2026] [security2:error] [pid 29744:tid 29915] [client 34.48.79.16:54843] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4cOOGINCUUz5GA9YIqmQAAAjw"]
[Mon Jul 20 07:01:44.543299 2026] [security2:error] [pid 29744:tid 29886] [client 34.48.79.16:62434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4cOOGINCUUz5GA9YIqpwAAAh8"]
[Mon Jul 20 07:01:44.661265 2026] [security2:error] [pid 29744:tid 29912] [client 65.111.26.203:12011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cOOGINCUUz5GA9YIqrwAAAjk"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:44.768713 2026] [security2:error] [pid 29744:tid 29980] [client 14.225.17.146:55574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4cOOGINCUUz5GA9YIqsgAAAn0"], referer: http://travelbyfire.com/2025
[Mon Jul 20 07:01:44.787301 2026] [security2:error] [pid 29744:tid 29971] [client 34.48.79.16:56420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cOOGINCUUz5GA9YIquAAAAnQ"]
[Mon Jul 20 07:01:44.802136 2026] [security2:error] [pid 28702:tid 28913] [client 57.141.18.52:61432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cJ7F4957xPw9VVBmxIwAA1RE"]
[Mon Jul 20 07:01:44.816845 2026] [security2:error] [pid 29744:tid 29976] [client 147.93.171.187:61383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "al4cOOGINCUUz5GA9YIqvAAAAnk"], referer: binance.com
[Mon Jul 20 07:01:44.961279 2026] [security2:error] [pid 28702:tid 28841] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4cOLF4957xPw9VVBmzPAAAjSM"], referer: http://assasalnazaha.com/2025
[Mon Jul 20 07:01:45.085161 2026] [security2:error] [pid 29744:tid 29934] [client 34.48.79.16:61578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4cOeGINCUUz5GA9YIqyAAAAk8"]
[Mon Jul 20 07:01:45.129406 2026] [security2:error] [pid 28702:tid 28870] [client 45.157.112.60:26821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cObF4957xPw9VVBmzSwAAAKo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:01:45.369639 2026] [security2:error] [pid 28702:tid 28872] [client 34.48.79.16:49422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cObF4957xPw9VVBmzVAAAAKw"]
[Mon Jul 20 07:01:45.544171 2026] [security2:error] [pid 28702:tid 28948] [client 14.225.17.146:55568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4cN7F4957xPw9VVBmzKgAAAPg"], referer: http://narv.co/2025
[Mon Jul 20 07:01:45.625150 2026] [security2:error] [pid 28702:tid 28814] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4cObF4957xPw9VVBmzYQAApm4"]
[Mon Jul 20 07:01:45.671425 2026] [security2:error] [pid 29744:tid 29912] [client 34.48.79.16:52241] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4cOeGINCUUz5GA9YIq5AAAAjk"]
[Mon Jul 20 07:01:45.855678 2026] [security2:error] [pid 29744:tid 29973] [client 14.225.17.146:55138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4cOeGINCUUz5GA9YIq5gAAAnY"], referer: https://travelbyfire.com/2025
[Mon Jul 20 07:01:45.980600 2026] [security2:error] [pid 29744:tid 29878] [client 34.48.79.16:52437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cOeGINCUUz5GA9YIq-QAAAhc"]
[Mon Jul 20 07:01:46.199231 2026] [security2:error] [pid 29744:tid 29901] [client 13.233.207.33:24474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cOuGINCUUz5GA9YIrBwAAAi4"]
[Mon Jul 20 07:01:46.201565 2026] [security2:error] [pid 29744:tid 29906] [client 104.234.53.80:51605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cOuGINCUUz5GA9YIrCAAAAjM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:46.374212 2026] [security2:error] [pid 29744:tid 29922] [client 34.48.79.16:60326] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cOuGINCUUz5GA9YIrGwAAAkM"]
[Mon Jul 20 07:01:46.381944 2026] [security2:error] [pid 29744:tid 29997] [client 57.141.18.114:26678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cJ-GINCUUz5GA9YIm7AACjjY"]
[Mon Jul 20 07:01:46.435901 2026] [security2:error] [pid 29744:tid 29920] [client 14.225.17.146:63253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4cOuGINCUUz5GA9YIrAwAAAkE"], referer: http://lifeisbetterlakeside.com/2025
[Mon Jul 20 07:01:46.459537 2026] [security2:error] [pid 29744:tid 29825] [remote 8.217.108.67:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4cOuGINCUUz5GA9YIrHwACNE8"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 07:01:46.613362 2026] [security2:error] [pid 29744:tid 29945] [client 14.225.17.146:54588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4cOuGINCUUz5GA9YIrIgAAAlo"], referer: http://39ishlife.com/2025
[Mon Jul 20 07:01:46.642118 2026] [security2:error] [pid 28702:tid 28835] [client 34.48.79.16:56719] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cOrF4957xPw9VVBmzdAAAAIc"]
[Mon Jul 20 07:01:46.675507 2026] [security2:error] [pid 29744:tid 29964] [client 14.225.17.146:56722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4cOuGINCUUz5GA9YIrIwAAAm0"], referer: https://narv.co/2025
[Mon Jul 20 07:01:46.791238 2026] [security2:error] [pid 29744:tid 29925] [client 158.173.89.95:55357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cOuGINCUUz5GA9YIrLQAAAkY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:01:46.889585 2026] [security2:error] [pid 29744:tid 29814] [remote 152.228.213.32:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4cOuGINCUUz5GA9YIrMQACZUQ"]
[Mon Jul 20 07:01:46.958719 2026] [security2:error] [pid 28702:tid 28915] [client 34.48.79.16:49267] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cOrF4957xPw9VVBmzfAAAANc"]
[Mon Jul 20 07:01:46.999602 2026] [security2:error] [pid 28702:tid 28933] [client 103.238.106.162:60730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cOrF4957xPw9VVBmzgAAAAOk"]
[Mon Jul 20 07:01:46.999700 2026] [security2:error] [pid 28702:tid 28933] [client 103.238.106.162:60730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cOrF4957xPw9VVBmzgAAAAOk"]
[Mon Jul 20 07:01:47.086538 2026] [security2:error] [pid 29744:tid 29858] [remote 152.228.213.32:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4cO-GINCUUz5GA9YIrOQACQ3A"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:01:47.166487 2026] [security2:error] [pid 28702:tid 28849] [client 14.225.17.146:56079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4cOrF4957xPw9VVBmzdQAAAJU"], referer: http://mollycahill.com/2025
[Mon Jul 20 07:01:47.170123 2026] [security2:error] [pid 28702:tid 28852] [client 155.2.212.8:58243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4cO7F4957xPw9VVBmzgQAAAJg"]
[Mon Jul 20 07:01:47.222959 2026] [security2:error] [pid 28702:tid 28925] [client 43.205.139.3:54624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cO7F4957xPw9VVBmzhwAAAOE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:01:47.294874 2026] [security2:error] [pid 29744:tid 29973] [client 34.48.79.16:60651] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "travelbyfire.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cO-GINCUUz5GA9YIrPwAAAnY"]
[Mon Jul 20 07:01:47.554931 2026] [security2:error] [pid 29744:tid 29896] [client 14.225.17.146:54563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4cO-GINCUUz5GA9YIrRgAAAik"], referer: https://39ishlife.com/2025
[Mon Jul 20 07:01:47.804790 2026] [security2:error] [pid 29744:tid 29913] [client 57.141.18.105:49218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cKOGINCUUz5GA9YInCwACOi8"]
[Mon Jul 20 07:01:47.874721 2026] [security2:error] [pid 29744:tid 29847] [remote 91.142.222.105:42306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4cO-GINCUUz5GA9YIrWgACbWU"]
[Mon Jul 20 07:01:47.912307 2026] [security2:error] [pid 29744:tid 29948] [client 117.247.108.24:16821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cO-GINCUUz5GA9YIrYAAAAl0"]
[Mon Jul 20 07:01:47.912422 2026] [security2:error] [pid 29744:tid 29948] [client 117.247.108.24:16821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cO-GINCUUz5GA9YIrYAAAAl0"]
[Mon Jul 20 07:01:47.977255 2026] [security2:error] [pid 29744:tid 29936] [client 14.225.17.146:56655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4cOuGINCUUz5GA9YIrFQAAAlE"], referer: http://swafforddetailing.com/2025
[Mon Jul 20 07:01:48.004501 2026] [security2:error] [pid 29744:tid 29886] [client 65.111.23.64:45533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cO-GINCUUz5GA9YIrZwAAAh8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:01:48.189140 2026] [security2:error] [pid 29744:tid 29950] [client 46.110.96.34:47842] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4cPOGINCUUz5GA9YIrdQAAAl8"]
[Mon Jul 20 07:01:48.270399 2026] [security2:error] [pid 29744:tid 29873] [remote 91.142.222.105:42306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4cPOGINCUUz5GA9YIrdwACTX8"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 07:01:48.416473 2026] [security2:error] [pid 29744:tid 29945] [client 50.116.65.227:56174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4cPOGINCUUz5GA9YIrcQAAAlo"]
[Mon Jul 20 07:01:48.608277 2026] [security2:error] [pid 29744:tid 29968] [client 50.116.65.227:56196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4cPOGINCUUz5GA9YIrgQAAAnE"]
[Mon Jul 20 07:01:48.972138 2026] [security2:error] [pid 28702:tid 28845] [client 158.173.166.181:60161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cPLF4957xPw9VVBmzrAAAAJE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:01:49.068378 2026] [security2:error] [pid 29744:tid 29986] [client 114.119.135.30:40069] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4cPeGINCUUz5GA9YIrpQAAAoM"], referer: https://savilerowtravel.com/robots.txt
[Mon Jul 20 07:01:49.131780 2026] [security2:error] [pid 28702:tid 28873] [client 183.82.98.154:50118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cPbF4957xPw9VVBmzsgAAAK0"]
[Mon Jul 20 07:01:49.131865 2026] [security2:error] [pid 28702:tid 28873] [client 183.82.98.154:50118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cPbF4957xPw9VVBmzsgAAAK0"]
[Mon Jul 20 07:01:49.177471 2026] [security2:error] [pid 29744:tid 29813] [remote 72.167.132.114:59754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cPeGINCUUz5GA9YIrqwACjEM"]
[Mon Jul 20 07:01:49.177606 2026] [security2:error] [pid 29744:tid 29995] [client 72.167.132.114:59754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cPeGINCUUz5GA9YIrqwACjEM"]
[Mon Jul 20 07:01:49.480203 2026] [security2:error] [pid 29744:tid 29954] [client 147.93.171.187:62941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "al4cPeGINCUUz5GA9YIrsQAAAmM"], referer: binance.com
[Mon Jul 20 07:01:49.518241 2026] [security2:error] [pid 29744:tid 29917] [client 122.183.32.225:30503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cPeGINCUUz5GA9YIrswAAAj4"]
[Mon Jul 20 07:01:49.518331 2026] [security2:error] [pid 29744:tid 29917] [client 122.183.32.225:30503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cPeGINCUUz5GA9YIrswAAAj4"]
[Mon Jul 20 07:01:49.975341 2026] [security2:error] [pid 29744:tid 29965] [client 104.234.53.49:43803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cPeGINCUUz5GA9YIryQAAAm4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:50.227801 2026] [security2:error] [pid 29744:tid 29904] [client 14.224.227.113:58568] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cPuGINCUUz5GA9YIr1AAAAjE"]
[Mon Jul 20 07:01:50.495300 2026] [security2:error] [pid 29744:tid 29920] [client 154.208.48.130:63036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cPuGINCUUz5GA9YIr3QAAAkE"]
[Mon Jul 20 07:01:50.495444 2026] [security2:error] [pid 29744:tid 29920] [client 154.208.48.130:63036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cPuGINCUUz5GA9YIr3QAAAkE"]
[Mon Jul 20 07:01:50.798067 2026] [security2:error] [pid 28702:tid 28764] [remote 173.249.4.11:57585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cPrF4957xPw9VVBmz8AAAtDw"]
[Mon Jul 20 07:01:50.870022 2026] [security2:error] [pid 29744:tid 29978] [client 57.141.18.60:23200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cKeGINCUUz5GA9YInSwACe1M"]
[Mon Jul 20 07:01:50.913167 2026] [security2:error] [pid 28702:tid 28904] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cPrF4957xPw9VVBmz7gAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:51.025151 2026] [security2:error] [pid 29744:tid 29897] [client 117.222.139.248:63477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cP-GINCUUz5GA9YIsAQAAAio"]
[Mon Jul 20 07:01:51.025322 2026] [security2:error] [pid 29744:tid 29897] [client 117.222.139.248:63477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cP-GINCUUz5GA9YIsAQAAAio"]
[Mon Jul 20 07:01:51.044475 2026] [security2:error] [pid 28702:tid 28774] [remote 173.249.4.11:57585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cP7F4957xPw9VVBmz9QAA80Y"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:01:51.128019 2026] [security2:error] [pid 29744:tid 29907] [client 77.110.127.138:61563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cP-GINCUUz5GA9YIsCQAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:51.128114 2026] [security2:error] [pid 29744:tid 29907] [client 77.110.127.138:61563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cP-GINCUUz5GA9YIsCQAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:51.813230 2026] [security2:error] [pid 28702:tid 28955] [client 103.144.65.217:58256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cP7F4957xPw9VVBm0CwAAAP8"]
[Mon Jul 20 07:01:51.813320 2026] [security2:error] [pid 28702:tid 28955] [client 103.144.65.217:58256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cP7F4957xPw9VVBm0CwAAAP8"]
[Mon Jul 20 07:01:52.829950 2026] [security2:error] [pid 29744:tid 29905] [client 147.93.171.187:51922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "al4cQOGINCUUz5GA9YIsbQAAAjI"], referer: binance.com
[Mon Jul 20 07:01:53.138609 2026] [security2:error] [pid 29744:tid 29917] [client 104.234.53.52:58871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cQeGINCUUz5GA9YIsdQAAAj4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:53.937424 2026] [security2:error] [pid 28702:tid 28730] [remote 95.217.78.234:48492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cQbF4957xPw9VVBm0OAAAvBo"]
[Mon Jul 20 07:01:54.173302 2026] [security2:error] [pid 28702:tid 28735] [remote 95.217.78.234:48492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cQrF4957xPw9VVBm0OwAA6R8"], referer: https://friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:01:54.174950 2026] [security2:error] [pid 29744:tid 29824] [remote 8.217.108.67:47012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cQuGINCUUz5GA9YIsowACGk4"]
[Mon Jul 20 07:01:54.175067 2026] [security2:error] [pid 29744:tid 29881] [client 8.217.108.67:47012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cQuGINCUUz5GA9YIsowACGk4"]
[Mon Jul 20 07:01:54.519259 2026] [security2:error] [pid 28702:tid 28876] [client 98.159.234.160:32285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cQrF4957xPw9VVBm0SAAAALA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:01:54.714585 2026] [security2:error] [pid 28702:tid 28924] [client 187.16.64.216:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cQrF4957xPw9VVBm0SwAAAOA"]
[Mon Jul 20 07:01:54.714709 2026] [security2:error] [pid 28702:tid 28924] [client 187.16.64.216:49832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cQrF4957xPw9VVBm0SwAAAOA"]
[Mon Jul 20 07:01:54.804260 2026] [security2:error] [pid 29744:tid 29893] [client 190.92.96.252:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4cQuGINCUUz5GA9YIstgAAAiY"]
[Mon Jul 20 07:01:54.846194 2026] [security2:error] [pid 29744:tid 29970] [client 65.111.7.148:44593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cQuGINCUUz5GA9YIsyAAAAnM"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:01:54.850276 2026] [security2:error] [pid 29744:tid 29909] [client 66.249.73.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4cQuGINCUUz5GA9YIswAAAAjY"]
[Mon Jul 20 07:01:54.872405 2026] [security2:error] [pid 29744:tid 29904] [client 114.119.133.245:47357] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asliceofleadership.com"] [uri "/ultimatesuccessplanner"] [unique_id "al4cQuGINCUUz5GA9YIsyQAAAjE"], referer: https://asliceofleadership.com/ultimatesuccessplanner?C=N%3BO%3DD
[Mon Jul 20 07:01:55.139814 2026] [security2:error] [pid 29744:tid 29978] [client 114.119.130.221:53539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/category/product-news/page/8/"] [unique_id "al4cQ-GINCUUz5GA9YIs3AAAAns"], referer: https://locketsandcharms.com/category/product-news/page/7/
[Mon Jul 20 07:01:55.346555 2026] [security2:error] [pid 28702:tid 28917] [client 57.141.18.43:35604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cK7F4957xPw9VVBmxpgAA2QE"]
[Mon Jul 20 07:01:56.345188 2026] [security2:error] [pid 28702:tid 28853] [client 46.110.96.34:50764] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4cRLF4957xPw9VVBm0gwAAAJk"]
[Mon Jul 20 07:01:56.499447 2026] [security2:error] [pid 29744:tid 29889] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cROGINCUUz5GA9YItBgAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:56.740099 2026] [security2:error] [pid 28702:tid 28916] [client 77.110.127.138:61606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cRLF4957xPw9VVBm0mwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:56.740182 2026] [security2:error] [pid 28702:tid 28916] [client 77.110.127.138:61606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cRLF4957xPw9VVBm0mwAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:01:56.819063 2026] [security2:error] [pid 28702:tid 28726] [remote 57.141.18.32:26644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cK7F4957xPw9VVBmxtQAAxRY"]
[Mon Jul 20 07:01:56.819464 2026] [security2:error] [pid 29744:tid 29888] [client 147.93.171.187:51670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "al4cROGINCUUz5GA9YItFwAAAiE"], referer: binance.com
[Mon Jul 20 07:01:56.961212 2026] [security2:error] [pid 28702:tid 28953] [client 134.122.94.138:53239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cRLF4957xPw9VVBm0pAAAAP0"]
[Mon Jul 20 07:01:57.260099 2026] [security2:error] [pid 29744:tid 29902] [client 14.225.17.146:54355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4cReGINCUUz5GA9YItKQAAAi8"], referer: http://intelligentengineeringsolutions.com/2026
[Mon Jul 20 07:01:57.417548 2026] [security2:error] [pid 29744:tid 29880] [client 134.122.94.138:53754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cReGINCUUz5GA9YItNgAAAhk"]
[Mon Jul 20 07:01:57.638664 2026] [security2:error] [pid 28702:tid 28956] [client 103.238.106.162:60713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cRbF4957xPw9VVBm0tAAAAQA"]
[Mon Jul 20 07:01:57.638782 2026] [security2:error] [pid 28702:tid 28956] [client 103.238.106.162:60713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cRbF4957xPw9VVBm0tAAAAQA"]
[Mon Jul 20 07:01:57.841490 2026] [security2:error] [pid 28702:tid 28848] [client 14.225.17.146:54830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4cRbF4957xPw9VVBm0tQAAAJQ"], referer: http://wathenbartlett.co.uk/2026
[Mon Jul 20 07:01:57.870921 2026] [security2:error] [pid 29744:tid 29888] [client 134.122.94.138:54101] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cReGINCUUz5GA9YItTgAAAiE"]
[Mon Jul 20 07:01:57.871174 2026] [security2:error] [pid 29744:tid 29945] [client 216.24.212.53:24371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4cReGINCUUz5GA9YItTQAAAlo"]
[Mon Jul 20 07:01:57.876659 2026] [security2:error] [pid 28702:tid 28942] [client 216.24.212.11:55107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4cRbF4957xPw9VVBm0tgAAAPI"]
[Mon Jul 20 07:01:57.884397 2026] [security2:error] [pid 28702:tid 28924] [client 14.224.227.113:54861] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cRbF4957xPw9VVBm0twAAAOA"]
[Mon Jul 20 07:01:58.318338 2026] [security2:error] [pid 29744:tid 29979] [client 134.122.94.138:54505] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cRuGINCUUz5GA9YItXAAAAnw"]
[Mon Jul 20 07:01:58.358443 2026] [security2:error] [pid 29744:tid 29936] [client 14.224.227.113:62178] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cRuGINCUUz5GA9YItYAAAAlE"]
[Mon Jul 20 07:01:58.394238 2026] [security2:error] [pid 28702:tid 28824] [remote 57.141.18.91:64256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cLLF4957xPw9VVBmxzgAA03g"]
[Mon Jul 20 07:01:58.541115 2026] [security2:error] [pid 28702:tid 28862] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/uploads/"] [unique_id "al4cRrF4957xPw9VVBm0zgAAAKI"]
[Mon Jul 20 07:01:58.743246 2026] [security2:error] [pid 28702:tid 28937] [client 14.225.17.146:54373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4cRbF4957xPw9VVBm0rgAAAO0"], referer: http://olearyplumbingllc.com/2026
[Mon Jul 20 07:01:58.793025 2026] [security2:error] [pid 28702:tid 28890] [client 134.122.94.138:54870] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cRrF4957xPw9VVBm02AAAAL4"]
[Mon Jul 20 07:01:59.216863 2026] [security2:error] [pid 29744:tid 29864] [remote 217.61.143.92:53896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cR-GINCUUz5GA9YItgwACZnY"]
[Mon Jul 20 07:01:59.217027 2026] [security2:error] [pid 29744:tid 29957] [client 217.61.143.92:53896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cR-GINCUUz5GA9YItgwACZnY"]
[Mon Jul 20 07:01:59.269078 2026] [security2:error] [pid 28702:tid 28853] [client 134.122.94.138:55243] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cR7F4957xPw9VVBm06gAAAJk"]
[Mon Jul 20 07:01:59.481737 2026] [autoindex:error] [pid 29744:tid 29899] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:01:59.482238 2026] [security2:error] [pid 29744:tid 29899] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/cgi-sys/403.html"] [unique_id "al4cR-GINCUUz5GA9YItlwAAAiw"]
[Mon Jul 20 07:01:59.502609 2026] [security2:error] [pid 29744:tid 29950] [client 14.225.17.146:55862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4cR-GINCUUz5GA9YItkQAAAl8"], referer: http://cloudspacesgroup.com/2026
[Mon Jul 20 07:01:59.709122 2026] [security2:error] [pid 29744:tid 29979] [client 14.225.17.146:52897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4cR-GINCUUz5GA9YItmgAAAnw"], referer: http://709fx.com/2026
[Mon Jul 20 07:01:59.738994 2026] [security2:error] [pid 29744:tid 29876] [client 134.122.94.138:55551] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cR-GINCUUz5GA9YItrQAAAhU"]
[Mon Jul 20 07:01:59.741433 2026] [security2:error] [pid 29744:tid 29931] [client 183.82.98.154:50808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cR-GINCUUz5GA9YItrgAAAkw"]
[Mon Jul 20 07:01:59.741555 2026] [security2:error] [pid 29744:tid 29931] [client 183.82.98.154:50808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cR-GINCUUz5GA9YItrgAAAkw"]
[Mon Jul 20 07:01:59.742022 2026] [security2:error] [pid 29744:tid 29754] [remote 57.141.18.122:55542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cLeGINCUUz5GA9YIn9wAChwg"]
[Mon Jul 20 07:01:59.791178 2026] [security2:error] [pid 29744:tid 29914] [client 117.247.108.24:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cR-GINCUUz5GA9YItsAAAAjs"]
[Mon Jul 20 07:01:59.791291 2026] [security2:error] [pid 29744:tid 29914] [client 117.247.108.24:59634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cR-GINCUUz5GA9YItsAAAAjs"]
[Mon Jul 20 07:01:59.854871 2026] [security2:error] [pid 28702:tid 28849] [client 14.225.17.146:53379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4cR7F4957xPw9VVBm09QAAAJU"], referer: https://wathenbartlett.co.uk/2026
[Mon Jul 20 07:01:59.949376 2026] [security2:error] [pid 28702:tid 28859] [client 194.180.48.253:36766] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "swafforddetailing.com"] [uri "/"] [unique_id "al4cR7F4957xPw9VVBm09gAAAJ8"]
[Mon Jul 20 07:01:59.995303 2026] [security2:error] [pid 29744:tid 29997] [client 14.224.227.113:62185] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cR-GINCUUz5GA9YItuAAAAo4"]
[Mon Jul 20 07:02:00.083903 2026] [autoindex:error] [pid 29744:tid 29971] [client 43.135.138.186:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:00.188456 2026] [security2:error] [pid 29744:tid 29913] [client 134.122.94.138:55738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cSOGINCUUz5GA9YItywAAAjo"]
[Mon Jul 20 07:02:00.723693 2026] [security2:error] [pid 29744:tid 29879] [client 134.122.94.138:55989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cSOGINCUUz5GA9YIt8AAAAhg"]
[Mon Jul 20 07:02:00.964818 2026] [security2:error] [pid 28702:tid 28948] [client 135.232.20.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "onpoint-evsolutions.com"] [uri "/index.php"] [unique_id "al4cRrF4957xPw9VVBm0wwAA-A0"], referer: https://onpoint-evsolutions.com/terms
[Mon Jul 20 07:02:00.997111 2026] [security2:error] [pid 29744:tid 29937] [client 147.93.171.187:51236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "al4cSOGINCUUz5GA9YIt-wAAAlI"], referer: binance.com
[Mon Jul 20 07:02:01.016583 2026] [security2:error] [pid 28702:tid 28908] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/"] [unique_id "al4cSbF4957xPw9VVBm1GgAAANA"]
[Mon Jul 20 07:02:01.216309 2026] [security2:error] [pid 29744:tid 29954] [client 134.122.94.138:56207] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cSeGINCUUz5GA9YIuBgAAAmM"]
[Mon Jul 20 07:02:01.258041 2026] [autoindex:error] [pid 29744:tid 29914] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:01.258480 2026] [security2:error] [pid 29744:tid 29914] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/"] [unique_id "al4cSeGINCUUz5GA9YIuCQAAAjs"]
[Mon Jul 20 07:02:01.338552 2026] [security2:error] [pid 28702:tid 28861] [client 154.208.48.130:63517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1OQAAAKE"]
[Mon Jul 20 07:02:01.338645 2026] [security2:error] [pid 28702:tid 28861] [client 154.208.48.130:63517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1OQAAAKE"]
[Mon Jul 20 07:02:01.394878 2026] [security2:error] [pid 28702:tid 28941] [client 82.102.18.116:38392] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4cSbF4957xPw9VVBm1QAAAAPE"]
[Mon Jul 20 07:02:01.467333 2026] [security2:error] [pid 29744:tid 29957] [client 14.225.17.146:57406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4cSeGINCUUz5GA9YIuDgAAAmY"], referer: http://koaconsultants.com/2026
[Mon Jul 20 07:02:01.650944 2026] [security2:error] [pid 28702:tid 28882] [client 117.222.139.248:63997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1SgAAALY"]
[Mon Jul 20 07:02:01.651049 2026] [security2:error] [pid 28702:tid 28882] [client 117.222.139.248:63997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1SgAAALY"]
[Mon Jul 20 07:02:01.705952 2026] [security2:error] [pid 29744:tid 29962] [client 134.122.94.138:56452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cSeGINCUUz5GA9YIuKAAAAms"]
[Mon Jul 20 07:02:01.725227 2026] [security2:error] [pid 28702:tid 28843] [client 82.102.18.116:38398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-abdf6969.robertpierson.org"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1TwAAAI8"]
[Mon Jul 20 07:02:01.751182 2026] [security2:error] [pid 28702:tid 28834] [client 192.140.149.97:44526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1UAAAAIY"]
[Mon Jul 20 07:02:01.751308 2026] [security2:error] [pid 28702:tid 28834] [client 192.140.149.97:44526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cSbF4957xPw9VVBm1UAAAAIY"]
[Mon Jul 20 07:02:01.913056 2026] [security2:error] [pid 29744:tid 29977] [client 122.183.32.225:27552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cSeGINCUUz5GA9YIuMgAAAno"]
[Mon Jul 20 07:02:01.913181 2026] [security2:error] [pid 29744:tid 29977] [client 122.183.32.225:27552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cSeGINCUUz5GA9YIuMgAAAno"]
[Mon Jul 20 07:02:02.070186 2026] [security2:error] [pid 29744:tid 29839] [remote 57.141.18.5:26042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cLuGINCUUz5GA9YIoXgACIF0"]
[Mon Jul 20 07:02:02.185715 2026] [security2:error] [pid 28702:tid 28880] [client 134.122.94.138:56739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cSrF4957xPw9VVBm1ZAAAALQ"]
[Mon Jul 20 07:02:02.236176 2026] [security2:error] [pid 29744:tid 29939] [client 82.102.18.116:38410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4cSuGINCUUz5GA9YIuRAAAAlQ"]
[Mon Jul 20 07:02:02.383120 2026] [security2:error] [pid 28702:tid 28833] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/css/"] [unique_id "al4cSrF4957xPw9VVBm1cAAAAIU"]
[Mon Jul 20 07:02:02.440967 2026] [security2:error] [pid 29744:tid 29884] [client 103.144.65.217:58958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cSuGINCUUz5GA9YIuSAAAAh0"]
[Mon Jul 20 07:02:02.441081 2026] [security2:error] [pid 29744:tid 29884] [client 103.144.65.217:58958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cSuGINCUUz5GA9YIuSAAAAh0"]
[Mon Jul 20 07:02:02.519774 2026] [security2:error] [pid 29744:tid 29988] [client 134.122.94.138:57049] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cSuGINCUUz5GA9YIuTQAAAoU"]
[Mon Jul 20 07:02:02.525878 2026] [security2:error] [pid 28702:tid 28875] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cSrF4957xPw9VVBm1aAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:02.555764 2026] [security2:error] [pid 29744:tid 29903] [client 98.91.91.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cSuGINCUUz5GA9YIuSQACMHs"]
[Mon Jul 20 07:02:02.571786 2026] [security2:error] [pid 29744:tid 29922] [client 82.102.18.116:38418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4cSuGINCUUz5GA9YIuVAAAAkM"]
[Mon Jul 20 07:02:02.612507 2026] [autoindex:error] [pid 29744:tid 29880] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:02.613033 2026] [security2:error] [pid 29744:tid 29880] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/css/"] [unique_id "al4cSuGINCUUz5GA9YIuVwAAAhk"]
[Mon Jul 20 07:02:02.821265 2026] [security2:error] [pid 29744:tid 29888] [client 134.122.94.138:57255] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cSuGINCUUz5GA9YIuYgAAAiE"]
[Mon Jul 20 07:02:02.878395 2026] [security2:error] [pid 29744:tid 29883] [client 77.110.127.138:61621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cSuGINCUUz5GA9YIuZAAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:02.878474 2026] [security2:error] [pid 29744:tid 29883] [client 77.110.127.138:61621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cSuGINCUUz5GA9YIuZAAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:02.903901 2026] [security2:error] [pid 29744:tid 29886] [client 54.158.133.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cSuGINCUUz5GA9YIuYAACHzo"]
[Mon Jul 20 07:02:02.912289 2026] [security2:error] [pid 28702:tid 28861] [client 82.102.18.116:38422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4cSrF4957xPw9VVBm1gwAAAKE"]
[Mon Jul 20 07:02:03.011097 2026] [security2:error] [pid 29744:tid 29972] [client 14.251.3.155:62192] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cS-GINCUUz5GA9YIubgAAAnU"]
[Mon Jul 20 07:02:03.128355 2026] [security2:error] [pid 28702:tid 28839] [client 134.122.94.138:57494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cS7F4957xPw9VVBm1jQAAAIs"]
[Mon Jul 20 07:02:03.215053 2026] [security2:error] [pid 28702:tid 28924] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/ID3/"] [unique_id "al4cS7F4957xPw9VVBm1kAAAAOA"]
[Mon Jul 20 07:02:03.250649 2026] [security2:error] [pid 28702:tid 28844] [client 82.102.18.116:38426] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4cS7F4957xPw9VVBm1lAAAAJA"]
[Mon Jul 20 07:02:03.290168 2026] [security2:error] [pid 28702:tid 28867] [client 57.141.18.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cS7F4957xPw9VVBm1iAAAAKc"]
[Mon Jul 20 07:02:03.348950 2026] [security2:error] [pid 29744:tid 29806] [remote 57.141.18.31:41426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cL-GINCUUz5GA9YIojgACLTw"]
[Mon Jul 20 07:02:03.415931 2026] [autoindex:error] [pid 29744:tid 29942] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:03.416379 2026] [security2:error] [pid 29744:tid 29942] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/ID3/"] [unique_id "al4cS-GINCUUz5GA9YIuiwAAAlc"]
[Mon Jul 20 07:02:03.433531 2026] [security2:error] [pid 29744:tid 29986] [client 134.122.94.138:57687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/api"] [unique_id "al4cS-GINCUUz5GA9YIujgAAAoM"]
[Mon Jul 20 07:02:03.596159 2026] [security2:error] [pid 29744:tid 29951] [client 82.102.18.116:38430] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cS-GINCUUz5GA9YIuowAAAmA"]
[Mon Jul 20 07:02:03.741811 2026] [security2:error] [pid 29744:tid 29958] [client 134.122.94.138:57940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cS-GINCUUz5GA9YIurAAAAmc"]
[Mon Jul 20 07:02:03.795377 2026] [security2:error] [pid 29744:tid 29890] [client 14.251.3.155:62192] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cS-GINCUUz5GA9YIutAAAAiM"]
[Mon Jul 20 07:02:03.872687 2026] [security2:error] [pid 29744:tid 29909] [client 104.234.53.83:40029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cS-GINCUUz5GA9YIuugAAAjY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:03.889071 2026] [security2:error] [pid 28702:tid 28819] [remote 81.173.115.7:39818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cS7F4957xPw9VVBm1pwAAtHM"]
[Mon Jul 20 07:02:03.936301 2026] [security2:error] [pid 28702:tid 28894] [client 82.102.18.116:38434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4cS7F4957xPw9VVBm1qAAAAMI"]
[Mon Jul 20 07:02:04.040666 2026] [security2:error] [pid 29744:tid 29997] [client 134.122.94.138:58131] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cTOGINCUUz5GA9YIuvwAAAo4"]
[Mon Jul 20 07:02:04.085863 2026] [security2:error] [pid 28702:tid 28816] [remote 81.173.115.7:39818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cTLF4957xPw9VVBm1swAAtXA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:02:04.215931 2026] [security2:error] [pid 28702:tid 28936] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/IXR/"] [unique_id "al4cTLF4957xPw9VVBm1tgAAAOw"]
[Mon Jul 20 07:02:04.271459 2026] [security2:error] [pid 28702:tid 28876] [client 82.102.18.116:38446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4cTLF4957xPw9VVBm1uQAAALA"]
[Mon Jul 20 07:02:04.337929 2026] [security2:error] [pid 29744:tid 29973] [client 134.122.94.138:58259] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cTOGINCUUz5GA9YIu2AAAAnY"]
[Mon Jul 20 07:02:04.500204 2026] [security2:error] [pid 29744:tid 29902] [client 14.225.17.146:57321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4cS-GINCUUz5GA9YIueAAAAi8"], referer: http://eframiproperties.com/2026
[Mon Jul 20 07:02:04.507031 2026] [autoindex:error] [pid 29744:tid 29898] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:04.507463 2026] [security2:error] [pid 29744:tid 29898] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/IXR/"] [unique_id "al4cTOGINCUUz5GA9YIu4AAAAis"]
[Mon Jul 20 07:02:04.600821 2026] [security2:error] [pid 29744:tid 29997] [client 147.93.171.187:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "al4cTOGINCUUz5GA9YIu5wAAAo4"], referer: binance.com
[Mon Jul 20 07:02:04.611307 2026] [security2:error] [pid 29744:tid 29949] [client 82.102.18.116:38456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cTOGINCUUz5GA9YIu6AAAAl4"]
[Mon Jul 20 07:02:04.660465 2026] [security2:error] [pid 29744:tid 29945] [client 134.122.94.138:58454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/"] [unique_id "al4cTOGINCUUz5GA9YIu6gAAAlo"]
[Mon Jul 20 07:02:04.695993 2026] [security2:error] [pid 29744:tid 29894] [client 14.225.17.146:62785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4cTOGINCUUz5GA9YIu6QAAAic"], referer: http://walkingandtalking.net/2026
[Mon Jul 20 07:02:04.848839 2026] [security2:error] [pid 29744:tid 29789] [remote 57.141.18.71:60888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cL-GINCUUz5GA9YIoqgACKCs"]
[Mon Jul 20 07:02:04.907387 2026] [security2:error] [pid 29744:tid 29879] [client 14.225.17.146:58080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4cTOGINCUUz5GA9YIu5gAAAhg"]
[Mon Jul 20 07:02:04.931806 2026] [security2:error] [pid 29744:tid 29954] [client 82.102.18.116:38470] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cTOGINCUUz5GA9YIu_gAAAmM"]
[Mon Jul 20 07:02:04.964347 2026] [security2:error] [pid 29744:tid 29907] [client 134.122.94.138:58630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cTOGINCUUz5GA9YIvAQAAAjQ"]
[Mon Jul 20 07:02:05.244171 2026] [security2:error] [pid 29744:tid 29932] [client 82.102.18.116:38480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cTeGINCUUz5GA9YIvDwAAAk0"]
[Mon Jul 20 07:02:05.282582 2026] [security2:error] [pid 29744:tid 29878] [client 134.122.94.138:58795] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cTeGINCUUz5GA9YIvEQAAAhc"]
[Mon Jul 20 07:02:05.497392 2026] [security2:error] [pid 28702:tid 28922] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/Requests/"] [unique_id "al4cTbF4957xPw9VVBm12AAAAN4"]
[Mon Jul 20 07:02:05.543911 2026] [security2:error] [pid 29744:tid 29782] [remote 216.73.216.55:35003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4cTeGINCUUz5GA9YIvHAACcyQ"]
[Mon Jul 20 07:02:05.550782 2026] [security2:error] [pid 28702:tid 28924] [client 187.16.64.216:50570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cTbF4957xPw9VVBm12wAAAOA"]
[Mon Jul 20 07:02:05.550869 2026] [security2:error] [pid 28702:tid 28924] [client 187.16.64.216:50570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cTbF4957xPw9VVBm12wAAAOA"]
[Mon Jul 20 07:02:05.555041 2026] [security2:error] [pid 29744:tid 29995] [client 82.102.18.116:38496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cTeGINCUUz5GA9YIvHwAAAow"]
[Mon Jul 20 07:02:05.581408 2026] [security2:error] [pid 28702:tid 28870] [client 134.122.94.138:58946] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cTbF4957xPw9VVBm13QAAAKo"]
[Mon Jul 20 07:02:05.590076 2026] [security2:error] [pid 29744:tid 29917] [client 14.225.17.146:58102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4cTeGINCUUz5GA9YIvHgAAAj4"], referer: https://walkingandtalking.net/2026
[Mon Jul 20 07:02:05.619887 2026] [proxy:error] [pid 29744:tid 29996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:02:05.619965 2026] [proxy_http:error] [pid 29744:tid 29996] [client 193.47.62.167:42718] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:02:05.621116 2026] [proxy:error] [pid 29744:tid 29996] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:02:05.621150 2026] [proxy_http:error] [pid 29744:tid 29996] [client 193.47.62.167:42718] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:02:05.701193 2026] [autoindex:error] [pid 29744:tid 29999] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:05.701733 2026] [security2:error] [pid 29744:tid 29999] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/Requests/"] [unique_id "al4cTeGINCUUz5GA9YIvKgAAApA"]
[Mon Jul 20 07:02:05.708727 2026] [proxy:error] [pid 29744:tid 29907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:02:05.708817 2026] [proxy_http:error] [pid 29744:tid 29907] [client 193.47.62.167:42760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:02:05.709316 2026] [proxy:error] [pid 29744:tid 29907] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:02:05.709347 2026] [proxy_http:error] [pid 29744:tid 29907] [client 193.47.62.167:42760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:02:05.871286 2026] [security2:error] [pid 29744:tid 29982] [client 82.102.18.116:38500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4cTeGINCUUz5GA9YIvMgAAAn8"]
[Mon Jul 20 07:02:05.878689 2026] [security2:error] [pid 29744:tid 29909] [client 134.122.94.138:59079] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "littleaosta.nz"] [uri "/login"] [unique_id "al4cTeGINCUUz5GA9YIvMwAAAjY"]
[Mon Jul 20 07:02:05.945683 2026] [security2:error] [pid 29744:tid 29807] [remote 5.161.225.162:51024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4cTeGINCUUz5GA9YIvNQACeD0"]
[Mon Jul 20 07:02:06.029157 2026] [security2:error] [pid 28702:tid 28873] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/SimplePie/"] [unique_id "al4cTrF4957xPw9VVBm17wAAAK0"]
[Mon Jul 20 07:02:06.183297 2026] [security2:error] [pid 28702:tid 28875] [client 82.102.18.116:38512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4cTrF4957xPw9VVBm19AAAAK8"]
[Mon Jul 20 07:02:06.237424 2026] [autoindex:error] [pid 29744:tid 29903] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:06.237880 2026] [security2:error] [pid 29744:tid 29903] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/SimplePie/"] [unique_id "al4cTuGINCUUz5GA9YIvRAAAAjA"]
[Mon Jul 20 07:02:06.327090 2026] [security2:error] [pid 28702:tid 28913] [client 122.183.32.225:7704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cTrF4957xPw9VVBm1-AAAANU"]
[Mon Jul 20 07:02:06.327178 2026] [security2:error] [pid 28702:tid 28913] [client 122.183.32.225:7704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cTrF4957xPw9VVBm1-AAAANU"]
[Mon Jul 20 07:02:06.499134 2026] [security2:error] [pid 29744:tid 29894] [client 13.232.231.177:15778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cTuGINCUUz5GA9YIvVgAAAic"]
[Mon Jul 20 07:02:06.522099 2026] [security2:error] [pid 29744:tid 29982] [client 82.102.18.116:38518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cTuGINCUUz5GA9YIvWgAAAn8"]
[Mon Jul 20 07:02:06.550729 2026] [security2:error] [pid 28702:tid 28936] [client 14.225.17.146:52104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4cTrF4957xPw9VVBm1-QAAAOw"], referer: http://thesoloceos.com/2026
[Mon Jul 20 07:02:06.637128 2026] [security2:error] [pid 29744:tid 29947] [client 104.207.51.12:43657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cTuGINCUUz5GA9YIvYQAAAlw"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:06.793378 2026] [security2:error] [pid 29744:tid 29836] [remote 152.228.213.32:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cTuGINCUUz5GA9YIvawACR1o"]
[Mon Jul 20 07:02:06.844298 2026] [security2:error] [pid 29744:tid 29922] [client 82.102.18.116:38530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cTuGINCUUz5GA9YIvbwAAAkM"]
[Mon Jul 20 07:02:06.950921 2026] [security2:error] [pid 28702:tid 28861] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/Text/"] [unique_id "al4cTrF4957xPw9VVBm2AQAAAKE"]
[Mon Jul 20 07:02:06.995467 2026] [security2:error] [pid 29744:tid 29758] [remote 152.228.213.32:48472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cTuGINCUUz5GA9YIvfAACYww"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:02:07.157479 2026] [security2:error] [pid 29744:tid 29977] [client 82.102.18.116:38536] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-abdf6969.robertpierson.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4cT-GINCUUz5GA9YIvhQAAAno"]
[Mon Jul 20 07:02:07.190921 2026] [security2:error] [pid 29744:tid 29831] [remote 57.141.18.42:49538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cMOGINCUUz5GA9YIozQACG1U"]
[Mon Jul 20 07:02:07.204969 2026] [autoindex:error] [pid 29744:tid 29932] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:07.206114 2026] [security2:error] [pid 29744:tid 29932] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/Text/"] [unique_id "al4cT-GINCUUz5GA9YIviwAAAk0"]
[Mon Jul 20 07:02:07.228759 2026] [security2:error] [pid 29744:tid 29962] [client 65.111.23.11:21227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cT-GINCUUz5GA9YIvjAAAAms"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:07.569598 2026] [security2:error] [pid 28702:tid 28917] [client 14.225.17.146:62717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4cT7F4957xPw9VVBm2FgAAANk"], referer: https://thesoloceos.com/2026
[Mon Jul 20 07:02:07.678624 2026] [security2:error] [pid 29744:tid 29939] [client 13.233.207.33:29620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cT-GINCUUz5GA9YIvoQAAAlQ"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:02:07.957733 2026] [core:error] [pid 28702:tid 28905] [client 14.225.17.146:58051] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:02:07.957773 2026] [core:error] [pid 28702:tid 28905] [client 14.225.17.146:58051] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:02:07.973383 2026] [autoindex:error] [pid 29744:tid 29864] [remote 8.229.41.77:55389] AH01276: Cannot serve directory /home2/jopjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.jop.jiv.mybluehost.me
[Mon Jul 20 07:02:08.145468 2026] [security2:error] [pid 28702:tid 28939] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/mu-plugins-old/"] [unique_id "al4cULF4957xPw9VVBm2LgAAAO8"]
[Mon Jul 20 07:02:08.250828 2026] [security2:error] [pid 29744:tid 29984] [client 103.238.106.162:42901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cUOGINCUUz5GA9YIvvwAAAoE"]
[Mon Jul 20 07:02:08.250959 2026] [security2:error] [pid 29744:tid 29984] [client 103.238.106.162:42901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cUOGINCUUz5GA9YIvvwAAAoE"]
[Mon Jul 20 07:02:08.551553 2026] [security2:error] [pid 28702:tid 28773] [remote 82.112.255.5:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.255.112.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4cULF4957xPw9VVBm2QQAAzkU"]
[Mon Jul 20 07:02:08.715497 2026] [security2:error] [pid 29744:tid 29949] [client 74.7.227.179:58588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4cT-GINCUUz5GA9YIvkQACXlk"], referer: https://tejasenvironmental.com/p=619277
[Mon Jul 20 07:02:08.736519 2026] [security2:error] [pid 28702:tid 28721] [remote 82.112.255.5:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.255.112.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4cULF4957xPw9VVBm2QwAAhxE"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:02:09.244300 2026] [security2:error] [pid 28702:tid 28838] [client 147.93.171.187:50415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "al4cUbF4957xPw9VVBm2SwAAAIo"], referer: binance.com
[Mon Jul 20 07:02:09.312500 2026] [security2:error] [pid 29744:tid 29904] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cUeGINCUUz5GA9YIv8AAAAjE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:09.602507 2026] [security2:error] [pid 29744:tid 29909] [client 117.247.108.24:18651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cUeGINCUUz5GA9YIwCgAAAjY"]
[Mon Jul 20 07:02:09.602635 2026] [security2:error] [pid 29744:tid 29909] [client 117.247.108.24:18651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cUeGINCUUz5GA9YIwCgAAAjY"]
[Mon Jul 20 07:02:09.613891 2026] [proxy:error] [pid 29744:tid 29880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:02:09.613962 2026] [proxy_http:error] [pid 29744:tid 29880] [client 205.210.31.164:64018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:02:09.614639 2026] [proxy:error] [pid 29744:tid 29880] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:02:09.614675 2026] [proxy_http:error] [pid 29744:tid 29880] [client 205.210.31.164:64018] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:02:09.738398 2026] [security2:error] [pid 29744:tid 29879] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cUOGINCUUz5GA9YIvwAAAAns"]
[Mon Jul 20 07:02:09.738424 2026] [security2:error] [pid 29744:tid 29879] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cUOGINCUUz5GA9YIvwAAAAns"]
[Mon Jul 20 07:02:09.744278 2026] [security2:error] [pid 29744:tid 29763] [remote 182.77.62.24:38196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4cUeGINCUUz5GA9YIwGwACKxE"]
[Mon Jul 20 07:02:09.872870 2026] [security2:error] [pid 29744:tid 29959] [client 57.141.18.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cUeGINCUUz5GA9YIwGgAAAmg"]
[Mon Jul 20 07:02:10.137798 2026] [security2:error] [pid 29744:tid 29932] [client 77.110.127.138:61692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cUuGINCUUz5GA9YIwNQAAAk0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:10.137933 2026] [security2:error] [pid 29744:tid 29932] [client 77.110.127.138:61692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cUuGINCUUz5GA9YIwNQAAAk0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:10.145267 2026] [security2:error] [pid 29744:tid 29781] [remote 5.252.52.249:39536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cUuGINCUUz5GA9YIwNAACLyM"]
[Mon Jul 20 07:02:10.208601 2026] [security2:error] [pid 29744:tid 29746] [remote 162.19.246.208:58046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cUuGINCUUz5GA9YIwNwACgQA"]
[Mon Jul 20 07:02:10.208786 2026] [security2:error] [pid 29744:tid 29984] [client 162.19.246.208:58046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cUuGINCUUz5GA9YIwNwACgQA"]
[Mon Jul 20 07:02:10.250423 2026] [security2:error] [pid 29744:tid 29755] [remote 182.77.62.24:38196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4cUuGINCUUz5GA9YIwOgACFwk"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:02:10.309215 2026] [security2:error] [pid 29744:tid 29947] [client 14.225.17.146:62840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4cUuGINCUUz5GA9YIwLwAAAlw"], referer: http://jvcmotorsports.com/2026
[Mon Jul 20 07:02:10.311092 2026] [security2:error] [pid 29744:tid 29769] [remote 5.252.52.249:39536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cUuGINCUUz5GA9YIwQAACXhc"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 07:02:10.585485 2026] [security2:error] [pid 28702:tid 28914] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/themes/classic/inc/"] [unique_id "al4cUrF4957xPw9VVBm2awAAANY"]
[Mon Jul 20 07:02:10.846035 2026] [security2:error] [pid 29744:tid 29927] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cUuGINCUUz5GA9YIwWQAAAkg"]
[Mon Jul 20 07:02:10.846066 2026] [security2:error] [pid 29744:tid 29927] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cUuGINCUUz5GA9YIwWQAAAkg"]
[Mon Jul 20 07:02:10.919037 2026] [security2:error] [pid 29744:tid 29886] [client 77.110.127.138:61708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cUuGINCUUz5GA9YIwXwAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:10.919134 2026] [security2:error] [pid 29744:tid 29886] [client 77.110.127.138:61708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cUuGINCUUz5GA9YIwXwAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:10.927738 2026] [security2:error] [pid 28702:tid 28848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cUrF4957xPw9VVBm2cQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:10.990119 2026] [security2:error] [pid 29744:tid 29965] [client 14.225.17.146:57848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4cUOGINCUUz5GA9YIv4gAAAm4"], referer: http://latiendadejorge.com.gt/2026
[Mon Jul 20 07:02:11.260769 2026] [security2:error] [pid 28702:tid 28922] [client 193.47.62.167:56382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4cU7F4957xPw9VVBm2hgAAAN4"], referer: http://mail.betterbonddogtraining.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:02:11.311635 2026] [security2:error] [pid 28702:tid 28864] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "al4cU7F4957xPw9VVBm2iwAAAKQ"]
[Mon Jul 20 07:02:11.429967 2026] [security2:error] [pid 28702:tid 28917] [client 193.47.62.167:56390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4cU7F4957xPw9VVBm2jQAAANk"], referer: http://www.betterbonddogtraining.com/wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings
[Mon Jul 20 07:02:11.519636 2026] [security2:error] [pid 29744:tid 29999] [client 112.82.218.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4cU-GINCUUz5GA9YIwcwAAApA"]
[Mon Jul 20 07:02:11.522942 2026] [security2:error] [pid 28702:tid 28935] [client 112.82.218.159:44611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/works.php"] [unique_id "al4cU7F4957xPw9VVBm2jAAAAOs"]
[Mon Jul 20 07:02:11.607062 2026] [security2:error] [pid 29744:tid 29974] [client 77.110.127.138:61715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cU-GINCUUz5GA9YIwhAAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:11.607196 2026] [security2:error] [pid 29744:tid 29974] [client 77.110.127.138:61715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cU-GINCUUz5GA9YIwhAAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:11.619620 2026] [security2:error] [pid 29744:tid 29954] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cU-GINCUUz5GA9YIwfAAAAmM"]
[Mon Jul 20 07:02:11.619646 2026] [security2:error] [pid 29744:tid 29954] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cU-GINCUUz5GA9YIwfAAAAmM"]
[Mon Jul 20 07:02:11.700723 2026] [security2:error] [pid 28702:tid 28932] [client 183.82.98.154:20560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cU7F4957xPw9VVBm2lQAAAOg"]
[Mon Jul 20 07:02:11.700846 2026] [security2:error] [pid 28702:tid 28932] [client 183.82.98.154:20560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cU7F4957xPw9VVBm2lQAAAOg"]
[Mon Jul 20 07:02:11.822123 2026] [security2:error] [pid 28702:tid 28854] [client 77.110.127.138:61718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cU7F4957xPw9VVBm2nQAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:11.822245 2026] [security2:error] [pid 28702:tid 28854] [client 77.110.127.138:61718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cU7F4957xPw9VVBm2nQAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:11.862244 2026] [security2:error] [pid 28702:tid 28880] [client 112.82.218.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4cU7F4957xPw9VVBm2mQAAALQ"]
[Mon Jul 20 07:02:11.917202 2026] [security2:error] [pid 29744:tid 29830] [remote 5.252.52.249:41820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4cU-GINCUUz5GA9YIwlwACYFQ"]
[Mon Jul 20 07:02:11.970913 2026] [security2:error] [pid 28702:tid 28771] [remote 162.19.86.63:37342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4cU7F4957xPw9VVBm2oQAA20M"]
[Mon Jul 20 07:02:12.031040 2026] [security2:error] [pid 28702:tid 28752] [remote 100.42.189.89:42798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cVLF4957xPw9VVBm2pAAAzzA"]
[Mon Jul 20 07:02:12.031157 2026] [security2:error] [pid 28702:tid 28907] [client 100.42.189.89:42798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cVLF4957xPw9VVBm2pAAAzzA"]
[Mon Jul 20 07:02:12.092198 2026] [security2:error] [pid 29744:tid 29841] [remote 5.252.52.249:41820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4cVOGINCUUz5GA9YIwowACVF8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:02:12.164882 2026] [security2:error] [pid 28702:tid 28806] [remote 162.19.86.63:37342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4cVLF4957xPw9VVBm2qwAA1mY"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:02:12.182196 2026] [security2:error] [pid 28702:tid 28911] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/mu-plugins/"] [unique_id "al4cVLF4957xPw9VVBm2rAAAANM"]
[Mon Jul 20 07:02:12.191456 2026] [security2:error] [pid 29744:tid 29899] [client 117.222.139.248:64513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cVOGINCUUz5GA9YIwqQAAAiw"]
[Mon Jul 20 07:02:12.191582 2026] [security2:error] [pid 29744:tid 29899] [client 117.222.139.248:64513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cVOGINCUUz5GA9YIwqQAAAiw"]
[Mon Jul 20 07:02:12.345139 2026] [security2:error] [pid 29744:tid 29974] [client 77.110.127.138:61720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cVOGINCUUz5GA9YIwrgAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:12.345275 2026] [security2:error] [pid 29744:tid 29974] [client 77.110.127.138:61720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cVOGINCUUz5GA9YIwrgAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:12.348860 2026] [security2:error] [pid 29744:tid 29913] [client 154.208.48.130:64015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cVOGINCUUz5GA9YIwrwAAAjo"]
[Mon Jul 20 07:02:12.348971 2026] [security2:error] [pid 29744:tid 29913] [client 154.208.48.130:64015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cVOGINCUUz5GA9YIwrwAAAjo"]
[Mon Jul 20 07:02:12.397157 2026] [autoindex:error] [pid 29744:tid 29927] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:12.397706 2026] [security2:error] [pid 29744:tid 29927] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-content/mu-plugins/"] [unique_id "al4cVOGINCUUz5GA9YIwsAAAAkg"]
[Mon Jul 20 07:02:12.403673 2026] [security2:error] [pid 28702:tid 28853] [client 192.140.149.97:44972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cVLF4957xPw9VVBm2rQAAAJk"]
[Mon Jul 20 07:02:12.403798 2026] [security2:error] [pid 28702:tid 28853] [client 192.140.149.97:44972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cVLF4957xPw9VVBm2rQAAAJk"]
[Mon Jul 20 07:02:12.437549 2026] [security2:error] [pid 28702:tid 28732] [remote 57.141.18.123:24006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cMrF4957xPw9VVBmynAAAnhw"]
[Mon Jul 20 07:02:12.446411 2026] [security2:error] [pid 29744:tid 29950] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cU-GINCUUz5GA9YIwhwAAAl8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:12.539122 2026] [security2:error] [pid 29744:tid 29949] [client 14.251.3.155:54863] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cVOGINCUUz5GA9YIwvQAAAl4"]
[Mon Jul 20 07:02:12.865057 2026] [security2:error] [pid 29744:tid 29950] [client 77.110.127.138:61723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cVOGINCUUz5GA9YIw4wAAAl8"]
[Mon Jul 20 07:02:12.865161 2026] [security2:error] [pid 29744:tid 29950] [client 77.110.127.138:61723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cVOGINCUUz5GA9YIw4wAAAl8"]
[Mon Jul 20 07:02:12.901336 2026] [security2:error] [pid 29744:tid 29905] [client 14.225.17.146:64772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4cVOGINCUUz5GA9YIw1QAAAjI"], referer: http://expertcultures.com/2026
[Mon Jul 20 07:02:12.923682 2026] [security2:error] [pid 28702:tid 28898] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al4cVLF4957xPw9VVBm2tAAAAMY"]
[Mon Jul 20 07:02:12.951526 2026] [security2:error] [pid 29744:tid 29953] [client 103.144.65.217:59504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cVOGINCUUz5GA9YIw6AAAAmI"]
[Mon Jul 20 07:02:12.952134 2026] [security2:error] [pid 29744:tid 29953] [client 103.144.65.217:59504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cVOGINCUUz5GA9YIw6AAAAmI"]
[Mon Jul 20 07:02:13.028615 2026] [security2:error] [pid 29744:tid 29911] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cVOGINCUUz5GA9YIw2wAAAjg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:13.177505 2026] [security2:error] [pid 29744:tid 29889] [client 14.225.17.146:62566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4cVeGINCUUz5GA9YIw7QAAAiI"], referer: http://mtlegnews.gov/2026
[Mon Jul 20 07:02:13.204240 2026] [autoindex:error] [pid 29744:tid 29879] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:13.204792 2026] [security2:error] [pid 29744:tid 29879] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al4cVeGINCUUz5GA9YIw9QAAAhg"]
[Mon Jul 20 07:02:13.220277 2026] [security2:error] [pid 29744:tid 29984] [client 77.110.127.138:61664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cVeGINCUUz5GA9YIw9wAAAoE"]
[Mon Jul 20 07:02:13.220427 2026] [security2:error] [pid 29744:tid 29984] [client 77.110.127.138:61664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cVeGINCUUz5GA9YIw9wAAAoE"]
[Mon Jul 20 07:02:13.418420 2026] [security2:error] [pid 29744:tid 29823] [remote 158.69.59.6:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.59.69.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4cVeGINCUUz5GA9YIxAAACM00"]
[Mon Jul 20 07:02:13.527362 2026] [security2:error] [pid 28702:tid 28881] [client 14.225.17.146:62564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4cVLF4957xPw9VVBm2pwAAALU"], referer: http://blaizeaccountingservices.com/2026
[Mon Jul 20 07:02:13.545067 2026] [security2:error] [pid 29744:tid 29990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cVeGINCUUz5GA9YIw9gAAAoc"]
[Mon Jul 20 07:02:13.627700 2026] [security2:error] [pid 28702:tid 28859] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/blocks/"] [unique_id "al4cVbF4957xPw9VVBm20AAAAJ8"]
[Mon Jul 20 07:02:13.635523 2026] [security2:error] [pid 29744:tid 29760] [remote 158.69.59.6:55910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.59.69.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4cVeGINCUUz5GA9YIxEAACjw4"], referer: https://allergyantidotes.com/wp-login.php
[Mon Jul 20 07:02:13.749743 2026] [security2:error] [pid 29744:tid 29887] [client 14.225.17.146:62255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4cVeGINCUUz5GA9YIxFQAAAiA"], referer: http://balticsteelmgmt.com/2026
[Mon Jul 20 07:02:13.839355 2026] [security2:error] [pid 29744:tid 29963] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.musichaven.info"] [uri "/wp-includes/blocks/index.php"] [unique_id "al4cVeGINCUUz5GA9YIxGwAAAmw"]
[Mon Jul 20 07:02:14.344127 2026] [security2:error] [pid 29744:tid 29942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cVeGINCUUz5GA9YIxJQAAAlc"]
[Mon Jul 20 07:02:14.442422 2026] [security2:error] [pid 28702:tid 28710] [remote 78.46.157.202:44176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cVrF4957xPw9VVBm27QAAxgY"]
[Mon Jul 20 07:02:14.472591 2026] [security2:error] [pid 28702:tid 28895] [client 14.225.17.146:55764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4cVrF4957xPw9VVBm26gAAAMM"], referer: http://ivetstrategies.com/2026
[Mon Jul 20 07:02:14.624086 2026] [core:error] [pid 28702:tid 28921] [client 14.225.17.146:64691] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2026
[Mon Jul 20 07:02:14.624119 2026] [core:error] [pid 28702:tid 28921] [client 14.225.17.146:64691] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2026
[Mon Jul 20 07:02:14.704536 2026] [security2:error] [pid 28702:tid 28884] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/certificates/"] [unique_id "al4cVrF4957xPw9VVBm29wAAALg"]
[Mon Jul 20 07:02:14.747962 2026] [security2:error] [pid 29744:tid 29957] [client 195.63.31.206:59263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cVuGINCUUz5GA9YIxRwAAAmY"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:02:14.865202 2026] [security2:error] [pid 28702:tid 28740] [remote 78.46.157.202:44176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cVrF4957xPw9VVBm2-wABAiQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:02:14.904228 2026] [autoindex:error] [pid 29744:tid 29916] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:14.904791 2026] [security2:error] [pid 29744:tid 29916] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/certificates/"] [unique_id "al4cVuGINCUUz5GA9YIxSgAAAj0"]
[Mon Jul 20 07:02:15.425656 2026] [security2:error] [pid 28702:tid 28952] [client 14.225.17.146:55813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4cV7F4957xPw9VVBm3AwAAAPw"], referer: http://mobilesurvsolutions.com/2026
[Mon Jul 20 07:02:15.515415 2026] [security2:error] [pid 28702:tid 28902] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/customize/"] [unique_id "al4cV7F4957xPw9VVBm3BwAAAMo"]
[Mon Jul 20 07:02:15.809862 2026] [autoindex:error] [pid 29744:tid 29907] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:15.810415 2026] [security2:error] [pid 29744:tid 29907] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/customize/"] [unique_id "al4cV-GINCUUz5GA9YIxgQAAAjQ"]
[Mon Jul 20 07:02:15.989611 2026] [security2:error] [pid 29744:tid 29932] [client 14.225.17.146:64639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4cV-GINCUUz5GA9YIxkgAAAk0"], referer: http://dasmarque.com/2026
[Mon Jul 20 07:02:16.206613 2026] [security2:error] [pid 29744:tid 29752] [remote 57.141.18.76:52908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cNOGINCUUz5GA9YIpmwACNwY"]
[Mon Jul 20 07:02:16.351527 2026] [security2:error] [pid 29744:tid 29906] [client 187.16.64.216:51331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cWOGINCUUz5GA9YIxqwAAAjM"]
[Mon Jul 20 07:02:16.351659 2026] [security2:error] [pid 29744:tid 29906] [client 187.16.64.216:51331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cWOGINCUUz5GA9YIxqwAAAjM"]
[Mon Jul 20 07:02:16.422206 2026] [security2:error] [pid 29744:tid 29938] [client 74.125.208.108:56299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecaalma.com"] [uri "/index.php"] [unique_id "al4cVuGINCUUz5GA9YIxMAAAAlM"]
[Mon Jul 20 07:02:16.687922 2026] [security2:error] [pid 29744:tid 29963] [client 50.116.65.227:48938] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2025/02/IMG_9124.jpeg"] [unique_id "al4cWOGINCUUz5GA9YIxuQAAAi8"]
[Mon Jul 20 07:02:16.787240 2026] [security2:error] [pid 28702:tid 28932] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/fonts/"] [unique_id "al4cWLF4957xPw9VVBm3KwAAAOg"]
[Mon Jul 20 07:02:16.945236 2026] [security2:error] [pid 29744:tid 29938] [client 147.93.171.187:61087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "al4cWOGINCUUz5GA9YIxxgAAAlM"], referer: binance.com
[Mon Jul 20 07:02:17.000274 2026] [autoindex:error] [pid 29744:tid 29949] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:17.000826 2026] [security2:error] [pid 29744:tid 29949] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/fonts/"] [unique_id "al4cWOGINCUUz5GA9YIxxwAAAl4"]
[Mon Jul 20 07:02:17.090929 2026] [security2:error] [pid 29744:tid 29993] [client 103.148.214.136:42429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4cWeGINCUUz5GA9YIxywACimw"], referer: https://sustaintheart.com/how-to-store-oil-paintings-while-theyre-drying/
[Mon Jul 20 07:02:17.605271 2026] [security2:error] [pid 28702:tid 28908] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/images/"] [unique_id "al4cWbF4957xPw9VVBm3PgAAANA"]
[Mon Jul 20 07:02:17.907354 2026] [autoindex:error] [pid 29744:tid 29882] [client 143.244.57.120:59196] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:17.907952 2026] [security2:error] [pid 29744:tid 29882] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/images/"] [unique_id "al4cWeGINCUUz5GA9YIx9AAAAhs"]
[Mon Jul 20 07:02:17.978010 2026] [security2:error] [pid 29744:tid 29889] [client 77.110.127.138:61757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cWeGINCUUz5GA9YIx-QAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:17.978099 2026] [security2:error] [pid 29744:tid 29889] [client 77.110.127.138:61757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cWeGINCUUz5GA9YIx-QAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:18.055685 2026] [security2:error] [pid 29744:tid 29903] [client 14.225.17.146:64545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4cWeGINCUUz5GA9YIx9QAAAjA"], referer: http://thechancersband.com/2026
[Mon Jul 20 07:02:18.073569 2026] [security2:error] [pid 29744:tid 29757] [remote 216.73.216.55:35003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4cWuGINCUUz5GA9YIx_gACjQs"]
[Mon Jul 20 07:02:18.416923 2026] [security2:error] [pid 28702:tid 28930] [client 104.234.53.54:43981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cWrF4957xPw9VVBm3YgAAAOY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:18.509855 2026] [security2:error] [pid 28702:tid 28904] [client 14.225.17.146:52569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4cWrF4957xPw9VVBm3XwAAAMw"], referer: http://uritems.net/2026
[Mon Jul 20 07:02:18.569935 2026] [security2:error] [pid 29744:tid 29861] [remote 188.166.241.141:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4cWuGINCUUz5GA9YIyEgACkHM"]
[Mon Jul 20 07:02:18.597606 2026] [autoindex:error] [pid 28702:tid 28906] [client 143.244.57.120:53414] AH01276: Cannot serve directory /home1/musichav/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:18.598325 2026] [security2:error] [pid 28702:tid 28906] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/.well-known/"] [unique_id "al4cWrF4957xPw9VVBm3dgAAAM4"]
[Mon Jul 20 07:02:18.652106 2026] [security2:error] [pid 28702:tid 28751] [remote 147.50.252.213:33662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cWrF4957xPw9VVBm3dwAAnC8"]
[Mon Jul 20 07:02:18.765589 2026] [security2:error] [pid 28702:tid 28840] [client 103.238.106.162:60712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cWrF4957xPw9VVBm3fgAAAIw"]
[Mon Jul 20 07:02:18.765709 2026] [security2:error] [pid 28702:tid 28840] [client 103.238.106.162:60712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cWrF4957xPw9VVBm3fgAAAIw"]
[Mon Jul 20 07:02:18.950338 2026] [security2:error] [pid 29744:tid 29781] [remote 188.166.241.141:60434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4cWuGINCUUz5GA9YIyHwACSSM"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 07:02:19.109891 2026] [security2:error] [pid 28702:tid 28811] [remote 147.50.252.213:33662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cW7F4957xPw9VVBm3kQAAhWs"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:02:19.492288 2026] [security2:error] [pid 28702:tid 28936] [client 43.173.175.125:46418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.175.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cW7F4957xPw9VVBm3qAAAAOw"], referer: https://mezzacraft.com/twinkling-granny-square-crochet-pattern-with-video/
[Mon Jul 20 07:02:19.588886 2026] [security2:error] [pid 28702:tid 28912] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/ALFA_DATA/"] [unique_id "al4cW7F4957xPw9VVBm3sgAAANQ"]
[Mon Jul 20 07:02:19.755111 2026] [security2:error] [pid 29744:tid 29878] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4cW-GINCUUz5GA9YIyLgACFzg"], referer: http://assasalnazaha.com/2026
[Mon Jul 20 07:02:19.885780 2026] [security2:error] [pid 29744:tid 29957] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cW-GINCUUz5GA9YIyTwAAAmY"]
[Mon Jul 20 07:02:19.885825 2026] [security2:error] [pid 29744:tid 29957] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cW-GINCUUz5GA9YIyTwAAAmY"]
[Mon Jul 20 07:02:20.432043 2026] [security2:error] [pid 28702:tid 28715] [remote 57.141.18.95:38812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cNrF4957xPw9VVBmy9QAAqws"]
[Mon Jul 20 07:02:20.447077 2026] [security2:error] [pid 29744:tid 29836] [remote 81.173.115.7:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4cXOGINCUUz5GA9YIyZwACf1o"]
[Mon Jul 20 07:02:20.574342 2026] [security2:error] [pid 28702:tid 28958] [client 117.247.108.24:19584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cXLF4957xPw9VVBm38QAAAQI"]
[Mon Jul 20 07:02:20.574472 2026] [security2:error] [pid 28702:tid 28958] [client 117.247.108.24:19584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cXLF4957xPw9VVBm38QAAAQI"]
[Mon Jul 20 07:02:20.644157 2026] [security2:error] [pid 29744:tid 29830] [remote 81.173.115.7:33182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4cXOGINCUUz5GA9YIybgACQlQ"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 07:02:20.681519 2026] [security2:error] [pid 28702:tid 28928] [client 122.183.32.225:17848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cXLF4957xPw9VVBm39wAAAOQ"]
[Mon Jul 20 07:02:20.682336 2026] [security2:error] [pid 28702:tid 28928] [client 122.183.32.225:17848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cXLF4957xPw9VVBm39wAAAOQ"]
[Mon Jul 20 07:02:20.850969 2026] [security2:error] [pid 28702:tid 28863] [client 14.225.17.146:60686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4cXLF4957xPw9VVBm37QAAAKM"], referer: http://alrowad-hub.net/2026
[Mon Jul 20 07:02:20.987980 2026] [security2:error] [pid 28702:tid 28833] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/.well-knownold/"] [unique_id "al4cXLF4957xPw9VVBm3_QAAAIU"]
[Mon Jul 20 07:02:21.150941 2026] [security2:error] [pid 29744:tid 29885] [client 14.225.17.146:52334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4cW-GINCUUz5GA9YIySAAAAh4"], referer: http://tntcatholic.com/2026
[Mon Jul 20 07:02:21.327107 2026] [security2:error] [pid 29744:tid 29888] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cXeGINCUUz5GA9YIykQAAAiE"]
[Mon Jul 20 07:02:21.327141 2026] [security2:error] [pid 29744:tid 29888] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cXeGINCUUz5GA9YIykQAAAiE"]
[Mon Jul 20 07:02:21.360653 2026] [security2:error] [pid 28702:tid 28850] [client 14.225.17.146:64309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4cXbF4957xPw9VVBm4BwAAAJY"], referer: http://recruitinginsight.us/2026
[Mon Jul 20 07:02:21.672097 2026] [security2:error] [pid 28702:tid 28926] [client 183.82.98.154:52207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cXbF4957xPw9VVBm4HwAAAOI"]
[Mon Jul 20 07:02:21.672175 2026] [security2:error] [pid 28702:tid 28926] [client 183.82.98.154:52207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cXbF4957xPw9VVBm4HwAAAOI"]
[Mon Jul 20 07:02:22.031444 2026] [autoindex:error] [pid 28702:tid 28915] [client 143.244.57.120:53414] AH01276: Cannot serve directory /home1/musichav/public_html/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:22.032013 2026] [security2:error] [pid 28702:tid 28915] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/.well-known/acme-challenge/"] [unique_id "al4cXrF4957xPw9VVBm4LgAAANc"]
[Mon Jul 20 07:02:22.161551 2026] [security2:error] [pid 28702:tid 28737] [remote 57.141.18.64:63190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cN7F4957xPw9VVBmzGgAAuSE"]
[Mon Jul 20 07:02:22.440136 2026] [security2:error] [pid 29744:tid 29872] [remote 47.86.33.52:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cXuGINCUUz5GA9YIyygACa34"]
[Mon Jul 20 07:02:22.657066 2026] [security2:error] [pid 29744:tid 29916] [client 14.225.17.146:64397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4cXuGINCUUz5GA9YIyywAAAj0"], referer: http://ksands.co.uk/2026
[Mon Jul 20 07:02:22.725535 2026] [security2:error] [pid 28702:tid 28888] [client 104.234.53.77:28555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cXrF4957xPw9VVBm4OQAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:22.831095 2026] [security2:error] [pid 28702:tid 28869] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/cgi-bin/"] [unique_id "al4cXrF4957xPw9VVBm4RgAAAKk"]
[Mon Jul 20 07:02:22.998169 2026] [cgid:error] [pid 29744:tid 29943] [client 143.244.57.120:59196] AH01265: stderr from /home1/musichav/public_html/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 07:02:22.998659 2026] [security2:error] [pid 29744:tid 29943] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/cgi-bin/"] [unique_id "al4cXuGINCUUz5GA9YIy6QAAAlg"]
[Mon Jul 20 07:02:23.027423 2026] [security2:error] [pid 29744:tid 29973] [client 57.141.18.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cXuGINCUUz5GA9YIy4gAAAnY"]
[Mon Jul 20 07:02:23.071368 2026] [security2:error] [pid 29744:tid 29981] [client 14.225.17.146:64559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4cXuGINCUUz5GA9YIy4wAAAn4"], referer: http://phillipbloch.com/2026
[Mon Jul 20 07:02:23.093678 2026] [security2:error] [pid 28702:tid 28891] [client 192.140.149.97:45467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cX7F4957xPw9VVBm4TgAAAL8"]
[Mon Jul 20 07:02:23.093794 2026] [security2:error] [pid 28702:tid 28891] [client 192.140.149.97:45467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cX7F4957xPw9VVBm4TgAAAL8"]
[Mon Jul 20 07:02:23.135936 2026] [security2:error] [pid 28702:tid 28848] [client 104.234.53.77:28555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cX7F4957xPw9VVBm4TwAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:23.300801 2026] [security2:error] [pid 29744:tid 29947] [client 77.110.127.138:61788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cX-GINCUUz5GA9YIy_AAAAlw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:23.300920 2026] [security2:error] [pid 29744:tid 29947] [client 77.110.127.138:61788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cX-GINCUUz5GA9YIy_AAAAlw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:23.340897 2026] [security2:error] [pid 29744:tid 29897] [client 154.208.48.130:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cX-GINCUUz5GA9YIy_gAAAio"]
[Mon Jul 20 07:02:23.341021 2026] [security2:error] [pid 29744:tid 29897] [client 154.208.48.130:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cX-GINCUUz5GA9YIy_gAAAio"]
[Mon Jul 20 07:02:23.454829 2026] [security2:error] [pid 29744:tid 29999] [client 77.110.127.138:61793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cX-GINCUUz5GA9YIzBQAAApA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:23.454952 2026] [security2:error] [pid 29744:tid 29999] [client 77.110.127.138:61793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cX-GINCUUz5GA9YIzBQAAApA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:23.459556 2026] [security2:error] [pid 29744:tid 29910] [client 103.144.65.217:59954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cX-GINCUUz5GA9YIzBgAAAjc"]
[Mon Jul 20 07:02:23.459656 2026] [security2:error] [pid 29744:tid 29910] [client 103.144.65.217:59954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cX-GINCUUz5GA9YIzBgAAAjc"]
[Mon Jul 20 07:02:23.694528 2026] [security2:error] [pid 29744:tid 29807] [remote 47.86.33.52:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cX-GINCUUz5GA9YIzFgACdD0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:02:23.729890 2026] [security2:error] [pid 29744:tid 29900] [client 77.110.127.138:61796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cX-GINCUUz5GA9YIzGQAAAi0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:23.730033 2026] [security2:error] [pid 29744:tid 29900] [client 77.110.127.138:61796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cX-GINCUUz5GA9YIzGQAAAi0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:23.797134 2026] [security2:error] [pid 29744:tid 29904] [client 117.222.139.248:65036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cX-GINCUUz5GA9YIzGwAAAjE"]
[Mon Jul 20 07:02:23.797246 2026] [security2:error] [pid 29744:tid 29904] [client 117.222.139.248:65036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cX-GINCUUz5GA9YIzGwAAAjE"]
[Mon Jul 20 07:02:23.866744 2026] [security2:error] [pid 28702:tid 28746] [remote 57.141.18.43:23026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cN7F4957xPw9VVBmzHAAA7io"]
[Mon Jul 20 07:02:24.371149 2026] [security2:error] [pid 29744:tid 29971] [client 77.110.127.138:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYOGINCUUz5GA9YIzNgAAAnQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.371239 2026] [security2:error] [pid 29744:tid 29971] [client 77.110.127.138:61767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYOGINCUUz5GA9YIzNgAAAnQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.545249 2026] [security2:error] [pid 29744:tid 29998] [client 77.110.127.138:61802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYOGINCUUz5GA9YIzQQAAAo8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.545349 2026] [security2:error] [pid 29744:tid 29998] [client 77.110.127.138:61802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYOGINCUUz5GA9YIzQQAAAo8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.646455 2026] [security2:error] [pid 28702:tid 28866] [client 77.110.127.138:61771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYLF4957xPw9VVBm4egAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.646561 2026] [security2:error] [pid 28702:tid 28866] [client 77.110.127.138:61771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYLF4957xPw9VVBm4egAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.682345 2026] [security2:error] [pid 28702:tid 28872] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/index/"] [unique_id "al4cYLF4957xPw9VVBm4fAAAAKw"]
[Mon Jul 20 07:02:24.701403 2026] [security2:error] [pid 28702:tid 28902] [client 77.110.127.138:61773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYLF4957xPw9VVBm4fQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.701541 2026] [security2:error] [pid 28702:tid 28902] [client 77.110.127.138:61773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cYLF4957xPw9VVBm4fQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:24.879618 2026] [security2:error] [pid 29744:tid 29990] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cYOGINCUUz5GA9YIzTwAAAoc"], referer: 1'"3000
[Mon Jul 20 07:02:24.963399 2026] [security2:error] [pid 29744:tid 29890] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cYOGINCUUz5GA9YIzYAAAAiM"]
[Mon Jul 20 07:02:24.963424 2026] [security2:error] [pid 29744:tid 29890] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cYOGINCUUz5GA9YIzYAAAAiM"]
[Mon Jul 20 07:02:24.966990 2026] [security2:error] [pid 29744:tid 29858] [remote 57.141.18.63:20710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3656248"] [unique_id "al4cYOGINCUUz5GA9YIzZAACZXA"]
[Mon Jul 20 07:02:25.429725 2026] [security2:error] [pid 29744:tid 29974] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cYeGINCUUz5GA9YIzaQAAAnc"], referer: 1'"3000
[Mon Jul 20 07:02:25.503495 2026] [security2:error] [pid 29744:tid 29916] [client 14.225.17.146:64484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4cX-GINCUUz5GA9YIzDgAAAj0"], referer: http://areitoproducciones.com/2026
[Mon Jul 20 07:02:25.506610 2026] [security2:error] [pid 29744:tid 29956] [client 147.93.171.187:52561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "al4cYeGINCUUz5GA9YIzggAAAmU"], referer: binance.com
[Mon Jul 20 07:02:25.657409 2026] [security2:error] [pid 29744:tid 29931] [client 50.116.65.227:34798] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cYeGINCUUz5GA9YIzkQAAAkw"]
[Mon Jul 20 07:02:25.668278 2026] [security2:error] [pid 29744:tid 29889] [client 50.116.65.227:34802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cYeGINCUUz5GA9YIzkgAAAiI"]
[Mon Jul 20 07:02:25.704095 2026] [security2:error] [pid 29744:tid 29953] [client 50.116.65.227:34776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4cYeGINCUUz5GA9YIzfAAAAmI"]
[Mon Jul 20 07:02:25.910001 2026] [security2:error] [pid 29744:tid 29888] [client 50.116.65.227:34806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4cYeGINCUUz5GA9YIzmgAAAiE"]
[Mon Jul 20 07:02:26.104253 2026] [core:error] [pid 29744:tid 29973] [client 14.225.17.146:61149] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:02:26.104276 2026] [core:error] [pid 29744:tid 29973] [client 14.225.17.146:61149] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:02:26.486467 2026] [security2:error] [pid 28702:tid 28839] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/id/"] [unique_id "al4cYrF4957xPw9VVBm4qgAAAIs"]
[Mon Jul 20 07:02:26.605504 2026] [security2:error] [pid 29744:tid 29857] [remote 130.51.180.8:47610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4cYuGINCUUz5GA9YIzxQACZW8"]
[Mon Jul 20 07:02:26.644460 2026] [security2:error] [pid 29744:tid 29973] [client 188.166.64.27:54064] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.miamimeditations.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4cYuGINCUUz5GA9YIzxwAAAnY"]
[Mon Jul 20 07:02:26.761729 2026] [security2:error] [pid 29744:tid 29761] [remote 130.51.180.8:47610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4cYuGINCUUz5GA9YIz0QACjA8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:02:26.767256 2026] [security2:error] [pid 29744:tid 29913] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cYuGINCUUz5GA9YIzzQAAAjo"]
[Mon Jul 20 07:02:26.767286 2026] [security2:error] [pid 29744:tid 29913] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cYuGINCUUz5GA9YIzzQAAAjo"]
[Mon Jul 20 07:02:26.794166 2026] [security2:error] [pid 29744:tid 29963] [client 50.116.65.227:34808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4cYuGINCUUz5GA9YIz1AAAAmw"]
[Mon Jul 20 07:02:27.102385 2026] [security2:error] [pid 29744:tid 29941] [client 187.16.64.216:51895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cY-GINCUUz5GA9YIz4AAAAlY"]
[Mon Jul 20 07:02:27.102516 2026] [security2:error] [pid 29744:tid 29941] [client 187.16.64.216:51895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cY-GINCUUz5GA9YIz4AAAAlY"]
[Mon Jul 20 07:02:27.105528 2026] [security2:error] [pid 29744:tid 29939] [client 47.128.115.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4cYuGINCUUz5GA9YIzwQAAAlQ"]
[Mon Jul 20 07:02:27.219475 2026] [security2:error] [pid 28702:tid 28858] [client 104.234.53.73:61403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cY7F4957xPw9VVBm4wQAAAJ4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:27.475425 2026] [security2:error] [pid 28702:tid 28952] [client 14.225.17.146:52394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4cYrF4957xPw9VVBm4uAAAAPw"], referer: http://drewsasburyparkbeachhouse.com/2026
[Mon Jul 20 07:02:27.516250 2026] [security2:error] [pid 29744:tid 29909] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cY-GINCUUz5GA9YIz8gAAAjY"], referer: 1'"3000
[Mon Jul 20 07:02:27.550344 2026] [security2:error] [pid 28702:tid 28713] [remote 95.217.78.234:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cY7F4957xPw9VVBm4zQAAsAk"]
[Mon Jul 20 07:02:27.550483 2026] [security2:error] [pid 28702:tid 28876] [client 95.217.78.234:57156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cY7F4957xPw9VVBm4zQAAsAk"]
[Mon Jul 20 07:02:27.554099 2026] [security2:error] [pid 29744:tid 29890] [client 14.225.17.146:60948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4cY-GINCUUz5GA9YIz8wAAAiM"], referer: http://sesamegreenbeans.com/2026
[Mon Jul 20 07:02:27.700617 2026] [security2:error] [pid 28702:tid 28838] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/www/"] [unique_id "al4cY7F4957xPw9VVBm40QAAAIo"]
[Mon Jul 20 07:02:27.818527 2026] [security2:error] [pid 28702:tid 28830] [remote 5.252.52.249:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4cY7F4957xPw9VVBm41wAAvH4"]
[Mon Jul 20 07:02:28.013279 2026] [security2:error] [pid 28702:tid 28710] [remote 5.252.52.249:50568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "slutilities.com"] [uri "/wp-login.php"] [unique_id "al4cZLF4957xPw9VVBm42wAAxAY"], referer: https://slutilities.com/wp-login.php
[Mon Jul 20 07:02:28.030308 2026] [security2:error] [pid 29744:tid 29998] [client 14.251.3.155:54865] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cZOGINCUUz5GA9YI0HQAAAo8"]
[Mon Jul 20 07:02:28.066164 2026] [security2:error] [pid 29744:tid 29906] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZOGINCUUz5GA9YI0GwAAAjM"]
[Mon Jul 20 07:02:28.066208 2026] [security2:error] [pid 29744:tid 29906] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZOGINCUUz5GA9YI0GwAAAjM"]
[Mon Jul 20 07:02:28.170156 2026] [security2:error] [pid 28702:tid 28928] [client 14.225.17.146:61056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4cYbF4957xPw9VVBm4ogAAAOQ"], referer: http://securingmemories.com/2026
[Mon Jul 20 07:02:28.187219 2026] [security2:error] [pid 28702:tid 28924] [client 14.225.17.146:63876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4cY7F4957xPw9VVBm42gAAAOA"], referer: http://itdynamix.com/2026
[Mon Jul 20 07:02:28.326170 2026] [security2:error] [pid 29744:tid 29977] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cY-GINCUUz5GA9YI0DgAAAno"], referer: 1'"3000
[Mon Jul 20 07:02:28.439538 2026] [security2:error] [pid 28702:tid 28910] [client 50.116.65.227:34876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cZLF4957xPw9VVBm47QAAANI"]
[Mon Jul 20 07:02:28.449317 2026] [security2:error] [pid 29744:tid 29906] [client 50.116.65.227:34886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cZOGINCUUz5GA9YI0OAAAAjM"]
[Mon Jul 20 07:02:28.463402 2026] [security2:error] [pid 28702:tid 28880] [client 77.110.127.138:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cZLF4957xPw9VVBm47gAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:28.463489 2026] [security2:error] [pid 28702:tid 28880] [client 77.110.127.138:61824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cZLF4957xPw9VVBm47gAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:28.465292 2026] [security2:error] [pid 28702:tid 28836] [client 34.221.76.50:53654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4cZLF4957xPw9VVBm47wAAAIg"]
[Mon Jul 20 07:02:28.597018 2026] [security2:error] [pid 28702:tid 28925] [client 14.225.17.146:50151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4cZLF4957xPw9VVBm47AAAAOE"], referer: https://sesamegreenbeans.com/2026
[Mon Jul 20 07:02:28.835592 2026] [security2:error] [pid 28702:tid 28867] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cZLF4957xPw9VVBm49QAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:29.099279 2026] [security2:error] [pid 29744:tid 29939] [client 50.116.65.227:46298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cZeGINCUUz5GA9YI0YgAAAlQ"]
[Mon Jul 20 07:02:29.109426 2026] [security2:error] [pid 29744:tid 29959] [client 50.116.65.227:46308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cZeGINCUUz5GA9YI0ZAAAAmg"]
[Mon Jul 20 07:02:29.159802 2026] [security2:error] [pid 29744:tid 29971] [client 14.225.17.146:57338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4cZOGINCUUz5GA9YI0VgAAAnQ"], referer: http://tacticaltreeoperations.com/2026
[Mon Jul 20 07:02:29.201004 2026] [security2:error] [pid 29744:tid 29905] [client 14.225.17.146:61037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4cZOGINCUUz5GA9YI0WgAAAjI"], referer: https://itdynamix.com/2026
[Mon Jul 20 07:02:29.206551 2026] [security2:error] [pid 28702:tid 28835] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/web/"] [unique_id "al4cZbF4957xPw9VVBm5AAAAAIc"]
[Mon Jul 20 07:02:29.353955 2026] [security2:error] [pid 29744:tid 29995] [client 103.238.106.162:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cZeGINCUUz5GA9YI0dQAAAow"]
[Mon Jul 20 07:02:29.354105 2026] [security2:error] [pid 29744:tid 29995] [client 103.238.106.162:60942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cZeGINCUUz5GA9YI0dQAAAow"]
[Mon Jul 20 07:02:29.474042 2026] [security2:error] [pid 29744:tid 29902] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZeGINCUUz5GA9YI0ewAAAi8"]
[Mon Jul 20 07:02:29.474079 2026] [security2:error] [pid 29744:tid 29902] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZeGINCUUz5GA9YI0ewAAAi8"]
[Mon Jul 20 07:02:29.545447 2026] [security2:error] [pid 29744:tid 29938] [client 14.225.17.146:60289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4cZeGINCUUz5GA9YI0fQAAAlM"], referer: http://grecruit.online/2026
[Mon Jul 20 07:02:29.557968 2026] [security2:error] [pid 29744:tid 29820] [remote 173.212.252.15:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4cZeGINCUUz5GA9YI0hgACbko"]
[Mon Jul 20 07:02:29.747739 2026] [security2:error] [pid 29744:tid 29816] [remote 173.212.252.15:56996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4cZeGINCUUz5GA9YI0lAACKkY"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:02:29.848962 2026] [security2:error] [pid 29744:tid 29926] [client 14.225.17.146:61269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4cZeGINCUUz5GA9YI0iwAAAkc"], referer: http://oldracelimited.com/2026
[Mon Jul 20 07:02:29.981293 2026] [security2:error] [pid 28702:tid 28786] [remote 182.77.62.24:39466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4cZbF4957xPw9VVBm5CwAAzVI"]
[Mon Jul 20 07:02:30.074942 2026] [security2:error] [pid 29744:tid 29795] [remote 57.141.18.102:41176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cOeGINCUUz5GA9YIqzQACkzE"]
[Mon Jul 20 07:02:30.168462 2026] [security2:error] [pid 29744:tid 29931] [client 50.116.65.227:46340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4cZuGINCUUz5GA9YI0pgAAAkw"]
[Mon Jul 20 07:02:30.252640 2026] [security2:error] [pid 28702:tid 28891] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/uploads/"] [unique_id "al4cZrF4957xPw9VVBm5DQAAAL8"]
[Mon Jul 20 07:02:30.336675 2026] [autoindex:error] [pid 29744:tid 29968] [client 43.134.91.35:38600] AH01276: Cannot serve directory /home1/thesums1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://thesummercampstore.com
[Mon Jul 20 07:02:30.345340 2026] [security2:error] [pid 29744:tid 29971] [client 50.116.65.227:46342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4cZuGINCUUz5GA9YI0tAAAAnQ"]
[Mon Jul 20 07:02:30.456814 2026] [security2:error] [pid 29744:tid 29941] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZuGINCUUz5GA9YI0wwAAAlY"]
[Mon Jul 20 07:02:30.456846 2026] [security2:error] [pid 29744:tid 29941] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZuGINCUUz5GA9YI0wwAAAlY"]
[Mon Jul 20 07:02:30.482846 2026] [security2:error] [pid 29744:tid 29957] [client 14.225.17.146:50503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4cZuGINCUUz5GA9YI0wgAAAmY"], referer: http://ravmike.com/2026
[Mon Jul 20 07:02:30.541175 2026] [security2:error] [pid 28702:tid 28706] [remote 182.77.62.24:39466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "stepupstepmom.com"] [uri "/wp-login.php"] [unique_id "al4cZrF4957xPw9VVBm5EwAAmgI"], referer: https://stepupstepmom.com/wp-login.php
[Mon Jul 20 07:02:30.714143 2026] [security2:error] [pid 29744:tid 29981] [client 104.234.53.94:59573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cZuGINCUUz5GA9YI00wAAAn4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:31.131300 2026] [security2:error] [pid 29744:tid 29748] [remote 72.167.132.114:50300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4cZ-GINCUUz5GA9YI07QACVgI"]
[Mon Jul 20 07:02:31.244739 2026] [security2:error] [pid 28702:tid 28918] [client 14.225.17.146:50538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4cZ7F4957xPw9VVBm5JAAAANo"], referer: http://betterbonddogtraining.com/2026
[Mon Jul 20 07:02:31.316065 2026] [security2:error] [pid 28702:tid 28877] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4cZ7F4957xPw9VVBm5JQAAALE"]
[Mon Jul 20 07:02:31.326400 2026] [security2:error] [pid 29744:tid 29992] [client 117.247.108.24:62254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cZ-GINCUUz5GA9YI0-gAAAok"]
[Mon Jul 20 07:02:31.326543 2026] [security2:error] [pid 29744:tid 29992] [client 117.247.108.24:62254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cZ-GINCUUz5GA9YI0-gAAAok"]
[Mon Jul 20 07:02:31.330677 2026] [security2:error] [pid 29744:tid 29746] [remote 15.206.251.117:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4cZ-GINCUUz5GA9YI0-wACRwA"]
[Mon Jul 20 07:02:31.341039 2026] [security2:error] [pid 29744:tid 29759] [remote 72.167.132.114:50300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4cZ-GINCUUz5GA9YI0_AACLQ0"], referer: https://ncsynchro.com/wp-login.php
[Mon Jul 20 07:02:31.386774 2026] [security2:error] [pid 28702:tid 28833] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/upload/"] [unique_id "al4cZ7F4957xPw9VVBm5KwAAAIU"]
[Mon Jul 20 07:02:31.460517 2026] [security2:error] [pid 28702:tid 28922] [client 14.225.17.146:61278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4cZ7F4957xPw9VVBm5LAAAAN4"], referer: https://ravmike.com/2026
[Mon Jul 20 07:02:31.460788 2026] [security2:error] [pid 29744:tid 29956] [client 112.86.225.126:56394] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/about-ccs/"] [unique_id "al4cZ-GINCUUz5GA9YI1AwAAAmU"]
[Mon Jul 20 07:02:31.460949 2026] [security2:error] [pid 29744:tid 29956] [client 112.86.225.126:56394] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ccsdifference.com"] [uri "/about-ccs/"] [unique_id "al4cZ-GINCUUz5GA9YI1AwAAAmU"]
[Mon Jul 20 07:02:31.652310 2026] [security2:error] [pid 29744:tid 29946] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZ-GINCUUz5GA9YI1CwAAAls"]
[Mon Jul 20 07:02:31.652337 2026] [security2:error] [pid 29744:tid 29946] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cZ-GINCUUz5GA9YI1CwAAAls"]
[Mon Jul 20 07:02:31.781566 2026] [security2:error] [pid 29744:tid 29773] [remote 15.206.251.117:57852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4cZ-GINCUUz5GA9YI1EAACRxs"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:02:32.220477 2026] [security2:error] [pid 29744:tid 29889] [client 103.183.8.185:60730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.8.183.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-comments-post.php"] [unique_id "al4caOGINCUUz5GA9YI1KQAAAiI"]
[Mon Jul 20 07:02:32.220560 2026] [security2:error] [pid 29744:tid 29889] [client 103.183.8.185:60730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "jhavoctattoos.com"] [uri "/wp-comments-post.php"] [unique_id "al4caOGINCUUz5GA9YI1KQAAAiI"]
[Mon Jul 20 07:02:32.229973 2026] [security2:error] [pid 29744:tid 29964] [client 45.157.112.60:36427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4caOGINCUUz5GA9YI1MAAAAm0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:02:32.291157 2026] [autoindex:error] [pid 29744:tid 29902] [client 167.86.117.252:57848] AH01276: Cannot serve directory /home2/fiqjjcmy/public_html/yourenotadummywahealthguideforcaraccidentvictims/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:02:32.412137 2026] [security2:error] [pid 28702:tid 28847] [client 183.82.98.154:22689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4caLF4957xPw9VVBm5TAAAAJM"]
[Mon Jul 20 07:02:32.412305 2026] [security2:error] [pid 28702:tid 28847] [client 183.82.98.154:22689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4caLF4957xPw9VVBm5TAAAAJM"]
[Mon Jul 20 07:02:32.543341 2026] [security2:error] [pid 28702:tid 28863] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/uploads/"] [unique_id "al4caLF4957xPw9VVBm5TwAAAKM"]
[Mon Jul 20 07:02:32.594678 2026] [security2:error] [pid 29744:tid 29804] [remote 5.161.225.162:39120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4caOGINCUUz5GA9YI1SAACIzo"]
[Mon Jul 20 07:02:32.594873 2026] [security2:error] [pid 29744:tid 29890] [client 5.161.225.162:39120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4caOGINCUUz5GA9YI1SAACIzo"]
[Mon Jul 20 07:02:32.768742 2026] [security2:error] [pid 29744:tid 29819] [remote 57.141.18.33:28462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cOeGINCUUz5GA9YIq6AAChEk"]
[Mon Jul 20 07:02:32.780468 2026] [security2:error] [pid 29744:tid 29914] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4caOGINCUUz5GA9YI1UAAAAjs"]
[Mon Jul 20 07:02:32.780488 2026] [security2:error] [pid 29744:tid 29914] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4caOGINCUUz5GA9YI1UAAAAjs"]
[Mon Jul 20 07:02:33.178699 2026] [security2:error] [pid 29744:tid 29888] [client 77.110.127.138:61873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4caeGINCUUz5GA9YI1bwAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:33.178840 2026] [security2:error] [pid 29744:tid 29888] [client 77.110.127.138:61873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4caeGINCUUz5GA9YI1bwAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:33.241824 2026] [security2:error] [pid 29744:tid 29964] [client 47.128.119.250:35182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/"] [unique_id "al4caeGINCUUz5GA9YI1cwAAAm0"]
[Mon Jul 20 07:02:33.275986 2026] [security2:error] [pid 29744:tid 29954] [client 117.222.139.248:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4caeGINCUUz5GA9YI1dQAAAmM"]
[Mon Jul 20 07:02:33.276136 2026] [security2:error] [pid 29744:tid 29954] [client 117.222.139.248:49164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4caeGINCUUz5GA9YI1dQAAAmM"]
[Mon Jul 20 07:02:33.284470 2026] [security2:error] [pid 28702:tid 28904] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/Admin/uploads/"] [unique_id "al4cabF4957xPw9VVBm5YgAAAMw"]
[Mon Jul 20 07:02:33.327588 2026] [security2:error] [pid 29744:tid 29816] [remote 182.77.62.24:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4caeGINCUUz5GA9YI1eQACOEY"]
[Mon Jul 20 07:02:33.561809 2026] [security2:error] [pid 29744:tid 29889] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4caeGINCUUz5GA9YI1gwAAAiI"]
[Mon Jul 20 07:02:33.561840 2026] [security2:error] [pid 29744:tid 29889] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4caeGINCUUz5GA9YI1gwAAAiI"]
[Mon Jul 20 07:02:34.024336 2026] [security2:error] [pid 29744:tid 29789] [remote 182.77.62.24:37842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cauGINCUUz5GA9YI1pAACjys"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:02:34.038224 2026] [security2:error] [pid 29744:tid 29981] [client 103.144.65.217:60402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cauGINCUUz5GA9YI1pwAAAn4"]
[Mon Jul 20 07:02:34.038314 2026] [security2:error] [pid 29744:tid 29981] [client 103.144.65.217:60402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cauGINCUUz5GA9YI1pwAAAn4"]
[Mon Jul 20 07:02:34.121925 2026] [security2:error] [pid 29744:tid 29908] [client 154.208.48.130:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cauGINCUUz5GA9YI1rgAAAjU"]
[Mon Jul 20 07:02:34.122076 2026] [security2:error] [pid 29744:tid 29908] [client 154.208.48.130:65011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cauGINCUUz5GA9YI1rgAAAjU"]
[Mon Jul 20 07:02:34.165718 2026] [security2:error] [pid 28702:tid 28915] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/"] [unique_id "al4carF4957xPw9VVBm5eQAAANc"]
[Mon Jul 20 07:02:34.308524 2026] [security2:error] [pid 28702:tid 28953] [client 158.173.166.181:33743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4carF4957xPw9VVBm5iwAAAP0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:02:34.375593 2026] [security2:error] [pid 29744:tid 29888] [client 143.244.57.120:59196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cauGINCUUz5GA9YI1uAAAAiE"]
[Mon Jul 20 07:02:34.375621 2026] [security2:error] [pid 29744:tid 29888] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cauGINCUUz5GA9YI1uAAAAiE"]
[Mon Jul 20 07:02:34.438250 2026] [security2:error] [pid 29744:tid 29936] [client 14.225.17.146:60927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4cauGINCUUz5GA9YI1ugAAAlE"], referer: http://momheadquarters.com/2026
[Mon Jul 20 07:02:34.568333 2026] [security2:error] [pid 28702:tid 28818] [remote 176.56.118.182:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4carF4957xPw9VVBm5kgAA5nI"]
[Mon Jul 20 07:02:34.697600 2026] [security2:error] [pid 28702:tid 28863] [client 158.173.89.95:50085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4carF4957xPw9VVBm5mAAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:02:34.827064 2026] [security2:error] [pid 29744:tid 29914] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.musichaven.info"] [uri "/wp-admin/index.php"] [unique_id "al4cauGINCUUz5GA9YI1ywAAAjs"]
[Mon Jul 20 07:02:34.838791 2026] [security2:error] [pid 28702:tid 28798] [remote 176.56.118.182:59244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4carF4957xPw9VVBm5mgAA6F4"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 07:02:34.884416 2026] [security2:error] [pid 29744:tid 29897] [client 14.225.17.146:60407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4caOGINCUUz5GA9YI1XQAAAio"], referer: http://nextlvlmarketingco.com/2026
[Mon Jul 20 07:02:34.999600 2026] [security2:error] [pid 28702:tid 28870] [client 147.93.171.187:64523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/class-wpdb.php"] [unique_id "al4carF4957xPw9VVBm5nwAAAKo"], referer: binance.com
[Mon Jul 20 07:02:35.079324 2026] [security2:error] [pid 29744:tid 29886] [client 143.244.57.120:59196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4ca-GINCUUz5GA9YI14gAAAh8"]
[Mon Jul 20 07:02:35.079438 2026] [security2:error] [pid 29744:tid 29886] [client 143.244.57.120:59196] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4ca-GINCUUz5GA9YI14gAAAh8"]
[Mon Jul 20 07:02:35.381820 2026] [security2:error] [pid 28702:tid 28861] [client 74.208.214.194:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ca7F4957xPw9VVBm5rgAAAKE"]
[Mon Jul 20 07:02:35.739351 2026] [security2:error] [pid 28702:tid 28775] [remote 57.141.18.117:55546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cOrF4957xPw9VVBmzfgAA90c"]
[Mon Jul 20 07:02:36.211963 2026] [security2:error] [pid 28702:tid 28880] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/images/"] [unique_id "al4cbLF4957xPw9VVBm5vAAAALQ"]
[Mon Jul 20 07:02:36.670058 2026] [security2:error] [pid 29744:tid 29926] [client 14.225.17.146:49537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4cbOGINCUUz5GA9YI2QgAAAkc"], referer: http://careysheatingandcooling.com/2026
[Mon Jul 20 07:02:36.733529 2026] [security2:error] [pid 29744:tid 29918] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ca-GINCUUz5GA9YI2GQAAAj8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:36.984259 2026] [security2:error] [pid 29744:tid 29939] [client 77.110.127.138:61901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cbOGINCUUz5GA9YI2ZAAAAlQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:36.984363 2026] [security2:error] [pid 29744:tid 29939] [client 77.110.127.138:61901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cbOGINCUUz5GA9YI2ZAAAAlQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:37.106578 2026] [security2:error] [pid 29744:tid 29910] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cbOGINCUUz5GA9YI2XQAAAjc"]
[Mon Jul 20 07:02:37.106605 2026] [security2:error] [pid 29744:tid 29910] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cbOGINCUUz5GA9YI2XQAAAjc"]
[Mon Jul 20 07:02:37.193949 2026] [security2:error] [pid 29744:tid 29881] [client 98.159.234.160:28033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cbeGINCUUz5GA9YI2egAAAho"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:02:37.881833 2026] [security2:error] [pid 29744:tid 29999] [client 187.16.64.216:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cbeGINCUUz5GA9YI2lgAAApA"]
[Mon Jul 20 07:02:37.881940 2026] [security2:error] [pid 29744:tid 29999] [client 187.16.64.216:52463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cbeGINCUUz5GA9YI2lgAAApA"]
[Mon Jul 20 07:02:37.998575 2026] [security2:error] [pid 29744:tid 29992] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cbOGINCUUz5GA9YI2VwAAAok"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:38.048965 2026] [security2:error] [pid 29744:tid 29990] [client 147.93.171.187:64102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/compat-utf8.php"] [unique_id "al4cbuGINCUUz5GA9YI2pwAAAoc"], referer: binance.com
[Mon Jul 20 07:02:38.146480 2026] [security2:error] [pid 29744:tid 29888] [client 74.208.214.194:49818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4cbuGINCUUz5GA9YI2rAAAAiE"]
[Mon Jul 20 07:02:38.262323 2026] [access_compat:error] [pid 29744:tid 29995] [client 112.90.14.68:45841] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:02:38.400287 2026] [security2:error] [pid 28702:tid 28777] [remote 57.141.18.116:54550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cO7F4957xPw9VVBmzhQAAjUk"]
[Mon Jul 20 07:02:38.415689 2026] [security2:error] [pid 28702:tid 28874] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/assets/"] [unique_id "al4cbrF4957xPw9VVBm56QAAAK4"]
[Mon Jul 20 07:02:38.666439 2026] [security2:error] [pid 29744:tid 29968] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cbuGINCUUz5GA9YI2yAAAAnE"]
[Mon Jul 20 07:02:38.666469 2026] [security2:error] [pid 29744:tid 29968] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cbuGINCUUz5GA9YI2yAAAAnE"]
[Mon Jul 20 07:02:38.697930 2026] [security2:error] [pid 28702:tid 28870] [client 65.111.8.12:32025] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4cbrF4957xPw9VVBm57wAAAKo"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:02:38.725347 2026] [security2:error] [pid 28702:tid 28834] [client 23.22.59.87:64855] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "aosta.nz"] [uri "/our-story"] [unique_id "al4cbrF4957xPw9VVBm59AAAAIY"]
[Mon Jul 20 07:02:38.797679 2026] [security2:error] [pid 28702:tid 28714] [remote 100.42.189.89:43074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4cbrF4957xPw9VVBm59gAAvAo"]
[Mon Jul 20 07:02:39.042322 2026] [security2:error] [pid 28702:tid 28770] [remote 100.42.189.89:43074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4cb7F4957xPw9VVBm5_gAAkEI"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:02:39.044386 2026] [security2:error] [pid 28702:tid 28899] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "al4cb7F4957xPw9VVBm5_wAAAMc"]
[Mon Jul 20 07:02:39.097250 2026] [security2:error] [pid 29744:tid 29956] [client 14.225.17.146:61706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4cb-GINCUUz5GA9YI22wAAAmU"], referer: http://claysharecon.com/2026
[Mon Jul 20 07:02:39.117829 2026] [security2:error] [pid 29744:tid 29892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cbuGINCUUz5GA9YI2twAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:39.363860 2026] [security2:error] [pid 29744:tid 29987] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cb-GINCUUz5GA9YI27gAAAoQ"]
[Mon Jul 20 07:02:39.363891 2026] [security2:error] [pid 29744:tid 29987] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cb-GINCUUz5GA9YI27gAAAoQ"]
[Mon Jul 20 07:02:39.409203 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:61913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cb-GINCUUz5GA9YI29gAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:39.409286 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:61913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cb-GINCUUz5GA9YI29gAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:39.618125 2026] [security2:error] [pid 29744:tid 29959] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cb-GINCUUz5GA9YI29QAAAmg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:39.855824 2026] [security2:error] [pid 29744:tid 29902] [client 103.238.106.162:42837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cb-GINCUUz5GA9YI3EgAAAi8"]
[Mon Jul 20 07:02:39.855946 2026] [security2:error] [pid 29744:tid 29902] [client 103.238.106.162:42837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4cb-GINCUUz5GA9YI3EgAAAi8"]
[Mon Jul 20 07:02:39.873969 2026] [security2:error] [pid 28702:tid 28874] [client 50.116.65.227:35872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cb7F4957xPw9VVBm6GQAAAK4"]
[Mon Jul 20 07:02:39.886640 2026] [security2:error] [pid 28702:tid 28880] [client 50.116.65.227:35888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cb7F4957xPw9VVBm6GgAAALQ"]
[Mon Jul 20 07:02:40.155870 2026] [security2:error] [pid 29744:tid 29804] [remote 97.74.93.24:37710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4ccOGINCUUz5GA9YI3JwACNTo"]
[Mon Jul 20 07:02:40.202394 2026] [security2:error] [pid 28702:tid 28925] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/upload/image/"] [unique_id "al4ccLF4957xPw9VVBm6IQAAAOE"]
[Mon Jul 20 07:02:40.479686 2026] [security2:error] [pid 29744:tid 29884] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ccOGINCUUz5GA9YI3NQAAAh0"]
[Mon Jul 20 07:02:40.479711 2026] [security2:error] [pid 29744:tid 29884] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ccOGINCUUz5GA9YI3NQAAAh0"]
[Mon Jul 20 07:02:40.538889 2026] [security2:error] [pid 29744:tid 29865] [remote 97.74.93.24:37710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4ccOGINCUUz5GA9YI3PQACVXc"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 07:02:40.755517 2026] [security2:error] [pid 28702:tid 28913] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cb7F4957xPw9VVBm6FgAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:40.891732 2026] [security2:error] [pid 29744:tid 29832] [remote 57.141.18.46:40256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cO-GINCUUz5GA9YIraQACT1Y"]
[Mon Jul 20 07:02:40.938689 2026] [security2:error] [pid 28702:tid 28934] [client 66.132.195.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.cathybuffini.com"] [uri "/index.php"] [unique_id "al4ccLF4957xPw9VVBm6NAAAAOo"]
[Mon Jul 20 07:02:41.062367 2026] [security2:error] [pid 28702:tid 28870] [client 65.111.8.12:32025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4cbrF4957xPw9VVBm57wAAAKo"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:02:41.062427 2026] [security2:error] [pid 28702:tid 28870] [client 65.111.8.12:32025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4cbrF4957xPw9VVBm57wAAAKo"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:02:41.118362 2026] [security2:error] [pid 29744:tid 29940] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ccOGINCUUz5GA9YI3UAAAAlU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:41.223921 2026] [security2:error] [pid 29744:tid 29963] [client 57.141.18.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cathyspeed.org"] [uri "/index.php"] [unique_id "al4ccOGINCUUz5GA9YI3JAAAAmw"]
[Mon Jul 20 07:02:41.262335 2026] [security2:error] [pid 28702:tid 28926] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/assets/images/"] [unique_id "al4ccbF4957xPw9VVBm6PwAAAOI"]
[Mon Jul 20 07:02:41.478768 2026] [security2:error] [pid 29744:tid 29937] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cceGINCUUz5GA9YI3bwAAAlI"]
[Mon Jul 20 07:02:41.478798 2026] [security2:error] [pid 29744:tid 29937] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cceGINCUUz5GA9YI3bwAAAlI"]
[Mon Jul 20 07:02:41.781689 2026] [security2:error] [pid 28702:tid 28721] [remote 173.249.4.11:32058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ccbF4957xPw9VVBm6TAAA1xE"]
[Mon Jul 20 07:02:41.944070 2026] [security2:error] [pid 28702:tid 28888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ccbF4957xPw9VVBm6RAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:41.992537 2026] [security2:error] [pid 28702:tid 28783] [remote 173.249.4.11:32058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ccbF4957xPw9VVBm6UgABAU8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:02:42.038769 2026] [security2:error] [pid 29744:tid 29757] [remote 202.51.202.242:33382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ccuGINCUUz5GA9YI3jgACNgs"]
[Mon Jul 20 07:02:42.089691 2026] [security2:error] [pid 28702:tid 28867] [client 77.110.127.138:61854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ccrF4957xPw9VVBm6VQAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:42.089834 2026] [security2:error] [pid 28702:tid 28867] [client 77.110.127.138:61854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ccrF4957xPw9VVBm6VQAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:42.175925 2026] [security2:error] [pid 28702:tid 28955] [client 117.247.108.24:61942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ccrF4957xPw9VVBm6VwAAAP8"]
[Mon Jul 20 07:02:42.176110 2026] [security2:error] [pid 28702:tid 28955] [client 117.247.108.24:61942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ccrF4957xPw9VVBm6VwAAAP8"]
[Mon Jul 20 07:02:42.398846 2026] [security2:error] [pid 29744:tid 29954] [client 14.225.17.146:60358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4cb-GINCUUz5GA9YI3FwAAAmM"], referer: http://bruceledewitz.com/2026
[Mon Jul 20 07:02:42.494739 2026] [security2:error] [pid 29744:tid 29773] [remote 202.51.202.242:33382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ccuGINCUUz5GA9YI3rQACOBs"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 07:02:42.511870 2026] [security2:error] [pid 29744:tid 29899] [client 147.93.171.187:62231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/connectors.php"] [unique_id "al4ccuGINCUUz5GA9YI3rwAAAiw"], referer: binance.com
[Mon Jul 20 07:02:42.590070 2026] [security2:error] [pid 29744:tid 29979] [client 14.224.227.113:54871] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ccuGINCUUz5GA9YI3sQAAAnw"]
[Mon Jul 20 07:02:42.649577 2026] [security2:error] [pid 29744:tid 29927] [client 74.7.230.57:58162] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bundleofjoyandpoop.com"] [uri "/robots.txt"] [unique_id "al4ccuGINCUUz5GA9YI3tgAAAkg"]
[Mon Jul 20 07:02:42.694335 2026] [security2:error] [pid 29744:tid 29995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ccuGINCUUz5GA9YI3qgAAAow"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:42.714482 2026] [security2:error] [pid 28702:tid 28885] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/Public/"] [unique_id "al4ccrF4957xPw9VVBm6ZwAAALk"]
[Mon Jul 20 07:02:42.973112 2026] [security2:error] [pid 29744:tid 29958] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ccuGINCUUz5GA9YI3ywAAAmc"]
[Mon Jul 20 07:02:42.973147 2026] [security2:error] [pid 29744:tid 29958] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ccuGINCUUz5GA9YI3ywAAAmc"]
[Mon Jul 20 07:02:43.137763 2026] [security2:error] [pid 28702:tid 28908] [client 104.234.53.94:47623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cc7F4957xPw9VVBm6cgAAANA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:43.158330 2026] [security2:error] [pid 29744:tid 29890] [client 183.82.98.154:23788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cc-GINCUUz5GA9YI34QAAAiM"]
[Mon Jul 20 07:02:43.158438 2026] [security2:error] [pid 29744:tid 29890] [client 183.82.98.154:23788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cc-GINCUUz5GA9YI34QAAAiM"]
[Mon Jul 20 07:02:43.341974 2026] [security2:error] [pid 28702:tid 28869] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/vendor/"] [unique_id "al4cc7F4957xPw9VVBm6eAAAAKk"]
[Mon Jul 20 07:02:43.659990 2026] [security2:error] [pid 29744:tid 29937] [client 65.111.15.145:16675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.15.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cc-GINCUUz5GA9YI3_gAAAlI"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:02:43.668904 2026] [security2:error] [pid 29744:tid 29946] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cc-GINCUUz5GA9YI3_QAAAls"]
[Mon Jul 20 07:02:43.668927 2026] [security2:error] [pid 29744:tid 29946] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cc-GINCUUz5GA9YI3_QAAAls"]
[Mon Jul 20 07:02:43.804378 2026] [security2:error] [pid 29744:tid 29926] [client 117.222.139.248:49687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cc-GINCUUz5GA9YI4DgAAAkc"]
[Mon Jul 20 07:02:43.804515 2026] [security2:error] [pid 29744:tid 29926] [client 117.222.139.248:49687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cc-GINCUUz5GA9YI4DgAAAkc"]
[Mon Jul 20 07:02:43.805333 2026] [security2:error] [pid 29744:tid 29914] [client 14.225.17.146:60493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4ccuGINCUUz5GA9YI3lQAAAjs"], referer: http://superiorcopywriting.com/2026
[Mon Jul 20 07:02:43.931696 2026] [security2:error] [pid 29744:tid 29981] [client 104.207.52.196:22761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cc-GINCUUz5GA9YI4EQAAAn4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:44.272596 2026] [security2:error] [pid 28702:tid 28945] [client 14.225.17.146:60085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4cdLF4957xPw9VVBm6hwAAAPU"]
[Mon Jul 20 07:02:44.295093 2026] [security2:error] [pid 29744:tid 29906] [client 14.225.17.146:60273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4ccuGINCUUz5GA9YI3wgAAAjM"], referer: http://eduardsales.com/2026
[Mon Jul 20 07:02:44.490336 2026] [security2:error] [pid 28702:tid 28934] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/local/"] [unique_id "al4cdLF4957xPw9VVBm6kQAAAOo"]
[Mon Jul 20 07:02:44.497741 2026] [security2:error] [pid 28702:tid 28885] [client 104.207.50.254:44143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cdLF4957xPw9VVBm6kAAAALk"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:44.548577 2026] [security2:error] [pid 28702:tid 28953] [client 103.144.65.217:60855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cdLF4957xPw9VVBm6lQAAAP0"]
[Mon Jul 20 07:02:44.548706 2026] [security2:error] [pid 28702:tid 28953] [client 103.144.65.217:60855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cdLF4957xPw9VVBm6lQAAAP0"]
[Mon Jul 20 07:02:44.770142 2026] [security2:error] [pid 29744:tid 29908] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cdOGINCUUz5GA9YI4RAAAAjU"]
[Mon Jul 20 07:02:44.770168 2026] [security2:error] [pid 29744:tid 29908] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cdOGINCUUz5GA9YI4RAAAAjU"]
[Mon Jul 20 07:02:44.896906 2026] [security2:error] [pid 28702:tid 28847] [client 14.225.17.146:51914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4cdLF4957xPw9VVBm6mQAAAJM"]
[Mon Jul 20 07:02:45.000546 2026] [security2:error] [pid 29744:tid 29886] [client 45.3.55.116:62705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cdOGINCUUz5GA9YI4UQAAAh8"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:02:45.056478 2026] [security2:error] [pid 28702:tid 28877] [client 45.3.42.3:65447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cdbF4957xPw9VVBm6pQAAALE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:45.105645 2026] [security2:error] [pid 29744:tid 29956] [client 77.110.127.138:61919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/newsletter-privacy-policy/a6yoj05e77qi.php"] [unique_id "al4cdeGINCUUz5GA9YI4VgAAAmU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:45.117499 2026] [security2:error] [pid 28702:tid 28906] [client 77.110.127.138:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cdbF4957xPw9VVBm6pwAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:45.117584 2026] [security2:error] [pid 28702:tid 28906] [client 77.110.127.138:61941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cdbF4957xPw9VVBm6pwAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:45.132346 2026] [security2:error] [pid 29744:tid 29926] [client 154.208.48.130:65504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cdeGINCUUz5GA9YI4WQAAAkc"]
[Mon Jul 20 07:02:45.132617 2026] [security2:error] [pid 29744:tid 29926] [client 154.208.48.130:65504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cdeGINCUUz5GA9YI4WQAAAkc"]
[Mon Jul 20 07:02:45.185009 2026] [security2:error] [pid 29744:tid 29905] [client 14.225.17.146:51529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4cdOGINCUUz5GA9YI4LQAAAjI"], referer: http://processorstudio.com/2026
[Mon Jul 20 07:02:45.282122 2026] [security2:error] [pid 28702:tid 28797] [remote 20.153.140.50:40380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cdbF4957xPw9VVBm6sAAA-V0"]
[Mon Jul 20 07:02:45.282361 2026] [security2:error] [pid 28702:tid 28949] [client 20.153.140.50:40380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cdbF4957xPw9VVBm6sAAA-V0"]
[Mon Jul 20 07:02:45.316055 2026] [security2:error] [pid 29744:tid 29973] [client 77.110.127.138:61889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4VwAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:45.493872 2026] [security2:error] [pid 29744:tid 29914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4aQAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:45.497304 2026] [security2:error] [pid 29744:tid 29892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4awAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:45.507140 2026] [security2:error] [pid 28702:tid 28960] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/modules/"] [unique_id "al4cdbF4957xPw9VVBm6tQAAAQQ"]
[Mon Jul 20 07:02:45.695519 2026] [security2:error] [pid 29744:tid 29931] [client 147.93.171.187:60565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/fonts.php"] [unique_id "al4cdeGINCUUz5GA9YI4hAAAAkw"], referer: binance.com
[Mon Jul 20 07:02:45.764322 2026] [security2:error] [pid 29744:tid 29916] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4hQAAAj0"]
[Mon Jul 20 07:02:45.764351 2026] [security2:error] [pid 29744:tid 29916] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4hQAAAj0"]
[Mon Jul 20 07:02:45.773985 2026] [security2:error] [pid 29744:tid 29940] [client 47.128.19.53:61090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "deltat24.com"] [uri "/robots.txt"] [unique_id "al4cdeGINCUUz5GA9YI4iQAAAlU"]
[Mon Jul 20 07:02:45.813606 2026] [security2:error] [pid 28702:tid 28935] [client 14.225.17.146:51579] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4cdbF4957xPw9VVBm6ugAAAOs"], referer: http://aandarealtygroup.com/2026
[Mon Jul 20 07:02:45.925191 2026] [security2:error] [pid 29744:tid 29764] [remote 182.77.62.24:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cdeGINCUUz5GA9YI4lwACZxI"]
[Mon Jul 20 07:02:45.977521 2026] [security2:error] [pid 28702:tid 28882] [client 77.110.127.138:61956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/join-as-you-go/wazyyicumw0f.php"] [unique_id "al4cdbF4957xPw9VVBm60QAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:46.096795 2026] [security2:error] [pid 28702:tid 28904] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdbF4957xPw9VVBm6zQAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:46.138083 2026] [security2:error] [pid 29744:tid 29911] [client 14.225.17.146:51575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4cduGINCUUz5GA9YI4qAAAAjg"], referer: https://processorstudio.com/2026
[Mon Jul 20 07:02:46.222910 2026] [security2:error] [pid 28702:tid 28888] [client 77.110.127.138:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdbF4957xPw9VVBm60gAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:46.372740 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4oQAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:46.399663 2026] [security2:error] [pid 29744:tid 29810] [remote 182.77.62.24:58896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cduGINCUUz5GA9YI4vQACW0A"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:02:46.431517 2026] [security2:error] [pid 29744:tid 29918] [client 104.234.53.74:41935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cduGINCUUz5GA9YI4vwAAAj8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:46.484840 2026] [security2:error] [pid 28702:tid 28859] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/Site/"] [unique_id "al4cdrF4957xPw9VVBm64wAAAJ8"]
[Mon Jul 20 07:02:46.513236 2026] [security2:error] [pid 29744:tid 29849] [remote 192.241.143.148:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4cduGINCUUz5GA9YI4wwACVGc"]
[Mon Jul 20 07:02:46.629392 2026] [security2:error] [pid 28702:tid 28876] [client 77.110.127.138:61962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-tutorial/qfsxhhnubghk.php"] [unique_id "al4cdrF4957xPw9VVBm65gAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:46.678679 2026] [security2:error] [pid 29744:tid 29865] [remote 192.241.143.148:35604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4cduGINCUUz5GA9YI43QACVHc"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 07:02:46.696565 2026] [security2:error] [pid 29744:tid 29856] [remote 8.217.108.67:26750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cduGINCUUz5GA9YI43gACbG4"]
[Mon Jul 20 07:02:46.696780 2026] [security2:error] [pid 29744:tid 29963] [client 8.217.108.67:26750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cduGINCUUz5GA9YI43gACbG4"]
[Mon Jul 20 07:02:46.738348 2026] [qos:error] [pid 28702:tid 28719] [remote 57.141.18.95:34052] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al4cdrF4957xPw9VVBm67AAAqw8
[Mon Jul 20 07:02:46.798325 2026] [security2:error] [pid 29744:tid 29881] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cduGINCUUz5GA9YI44gAAAho"]
[Mon Jul 20 07:02:46.798361 2026] [security2:error] [pid 29744:tid 29881] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cduGINCUUz5GA9YI44gAAAho"]
[Mon Jul 20 07:02:46.866178 2026] [security2:error] [pid 29744:tid 29859] [remote 57.141.18.101:61202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cPeGINCUUz5GA9YIrowACLnE"]
[Mon Jul 20 07:02:46.978072 2026] [security2:error] [pid 28702:tid 28896] [client 14.225.17.146:51610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4cdbF4957xPw9VVBm6wAAAAMQ"], referer: http://mazzucelli.com/2026
[Mon Jul 20 07:02:46.989469 2026] [security2:error] [pid 29744:tid 29910] [client 77.110.127.138:61966] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/if(now()=sysdate(),sleep(15),0)/2/"] [unique_id "al4cduGINCUUz5GA9YI49wAAAjc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:47.154866 2026] [security2:error] [pid 29744:tid 29934] [client 77.110.127.138:61964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cduGINCUUz5GA9YI40QAAAk8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:47.157460 2026] [security2:error] [pid 28702:tid 28881] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdrF4957xPw9VVBm66AAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:47.243941 2026] [security2:error] [pid 28702:tid 28870] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cdrF4957xPw9VVBm65wAAAKo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:47.311468 2026] [security2:error] [pid 29744:tid 29899] [client 14.225.17.146:51552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4cduGINCUUz5GA9YI45QAAAiw"]
[Mon Jul 20 07:02:47.484392 2026] [security2:error] [pid 28702:tid 28807] [remote 188.40.28.4:41306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cd7F4957xPw9VVBm6_QAAiGc"]
[Mon Jul 20 07:02:47.512020 2026] [security2:error] [pid 28702:tid 28878] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/system/"] [unique_id "al4cd7F4957xPw9VVBm6_gAAALI"]
[Mon Jul 20 07:02:47.630039 2026] [security2:error] [pid 29744:tid 29937] [client 104.28.163.40:49996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "chestermonty.com"] [uri "/wp-login.php"] [unique_id "al4cd-GINCUUz5GA9YI5GAAAAlI"]
[Mon Jul 20 07:02:47.639612 2026] [security2:error] [pid 29744:tid 29881] [client 77.110.127.138:61926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/online-granny-square-sweater-course-2nd-payment/9rynhd6bwor2.php"] [unique_id "al4cd-GINCUUz5GA9YI5IAAAAho"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:47.701906 2026] [security2:error] [pid 28702:tid 28704] [remote 188.40.28.4:41306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cd7F4957xPw9VVBm7CgAA6gA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:02:47.764255 2026] [security2:error] [pid 29744:tid 29971] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cd-GINCUUz5GA9YI5KQAAAnQ"]
[Mon Jul 20 07:02:47.764287 2026] [security2:error] [pid 29744:tid 29971] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cd-GINCUUz5GA9YI5KQAAAnQ"]
[Mon Jul 20 07:02:47.892130 2026] [qos:error] [pid 29744:tid 29757] [remote 57.141.18.94:64750] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.94, id=al4cd-GINCUUz5GA9YI5NQACRws
[Mon Jul 20 07:02:48.027006 2026] [security2:error] [pid 28702:tid 28863] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cd7F4957xPw9VVBm7CQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.042798 2026] [security2:error] [pid 28702:tid 28888] [client 14.225.17.146:60093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4cd7F4957xPw9VVBm7CwAAALw"], referer: http://idigress.agency/2026
[Mon Jul 20 07:02:48.093765 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cd7F4957xPw9VVBm7CAAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.124637 2026] [security2:error] [pid 29744:tid 29888] [client 77.110.127.138:61968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cd-GINCUUz5GA9YI5KwAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.145908 2026] [security2:error] [pid 28702:tid 28946] [client 14.225.17.146:52023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4cdrF4957xPw9VVBm63wAAAPY"], referer: http://fluidtemple.org/2026
[Mon Jul 20 07:02:48.277563 2026] [security2:error] [pid 29744:tid 29936] [client 14.225.17.146:51864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4ceOGINCUUz5GA9YI5QQAAAlE"], referer: http://soloceos.com/2026
[Mon Jul 20 07:02:48.319957 2026] [security2:error] [pid 29744:tid 29956] [client 77.110.127.138:61963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/knitting/iiqg1yez55ws.php"] [unique_id "al4ceOGINCUUz5GA9YI5VQAAAmU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.417882 2026] [security2:error] [pid 28702:tid 28932] [client 187.16.64.216:53016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ceLF4957xPw9VVBm7GQAAAOg"]
[Mon Jul 20 07:02:48.418056 2026] [security2:error] [pid 28702:tid 28932] [client 187.16.64.216:53016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ceLF4957xPw9VVBm7GQAAAOg"]
[Mon Jul 20 07:02:48.495957 2026] [qos:error] [pid 29744:tid 29812] [remote 57.141.18.47:20432] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.47, id=al4ceOGINCUUz5GA9YI5aAACJUI
[Mon Jul 20 07:02:48.522171 2026] [security2:error] [pid 28702:tid 28906] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/template/"] [unique_id "al4ceLF4957xPw9VVBm7HQAAAM4"]
[Mon Jul 20 07:02:48.523541 2026] [qos:error] [pid 29744:tid 29802] [remote 57.141.18.118:64292] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.118, id=al4ceOGINCUUz5GA9YI5aQACHjg
[Mon Jul 20 07:02:48.575493 2026] [security2:error] [pid 29744:tid 29981] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceOGINCUUz5GA9YI5XgAAAn4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.627942 2026] [security2:error] [pid 29744:tid 29993] [client 77.110.127.138:61971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceOGINCUUz5GA9YI5YAAAAoo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.697053 2026] [autoindex:error] [pid 28702:tid 28893] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/uploads/2016/
[Mon Jul 20 07:02:48.793700 2026] [security2:error] [pid 29744:tid 29968] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ceOGINCUUz5GA9YI5fAAAAnE"]
[Mon Jul 20 07:02:48.793731 2026] [security2:error] [pid 29744:tid 29968] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ceOGINCUUz5GA9YI5fAAAAnE"]
[Mon Jul 20 07:02:48.821837 2026] [security2:error] [pid 29744:tid 29943] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceOGINCUUz5GA9YI5ZwAAAlg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:48.873526 2026] [security2:error] [pid 29744:tid 29940] [client 122.183.32.225:27651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ceOGINCUUz5GA9YI5hQAAAlU"]
[Mon Jul 20 07:02:48.873656 2026] [security2:error] [pid 29744:tid 29940] [client 122.183.32.225:27651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4ceOGINCUUz5GA9YI5hQAAAlU"]
[Mon Jul 20 07:02:49.012151 2026] [security2:error] [pid 29744:tid 29943] [client 77.110.127.138:61929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-video/kc8laavx8j1m.php"] [unique_id "al4ceeGINCUUz5GA9YI5jQAAAlg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.106048 2026] [qos:error] [pid 29744:tid 29773] [remote 57.141.18.49:35740] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.49, id=al4ceeGINCUUz5GA9YI5mgACdBs
[Mon Jul 20 07:02:49.200253 2026] [security2:error] [pid 29744:tid 29964] [client 77.110.127.138:61943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ceeGINCUUz5GA9YI5rAAAAm0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.200363 2026] [security2:error] [pid 29744:tid 29964] [client 77.110.127.138:61943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ceeGINCUUz5GA9YI5rAAAAm0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.251769 2026] [core:error] [pid 28702:tid 28952] [client 14.225.17.146:49885] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2026
[Mon Jul 20 07:02:49.251794 2026] [core:error] [pid 28702:tid 28952] [client 14.225.17.146:49885] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2026
[Mon Jul 20 07:02:49.255644 2026] [security2:error] [pid 29744:tid 29881] [client 77.110.127.138:61889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceeGINCUUz5GA9YI5jwAAAho"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.257280 2026] [security2:error] [pid 29744:tid 29940] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceeGINCUUz5GA9YI5kwAAAlU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.307305 2026] [qos:error] [pid 28702:tid 28731] [remote 57.141.18.86:58050] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.86, id=al4cebF4957xPw9VVBm7NgAAqxs
[Mon Jul 20 07:02:49.362876 2026] [security2:error] [pid 29744:tid 29888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceeGINCUUz5GA9YI5pgAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.695087 2026] [security2:error] [pid 28702:tid 28922] [client 77.110.127.138:61982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/online-granny-square-sweater-course-signups/xx3wrrh6bea0.php"] [unique_id "al4cebF4957xPw9VVBm7PgAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:49.780517 2026] [security2:error] [pid 29744:tid 29908] [client 147.93.171.187:53402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "al4ceeGINCUUz5GA9YI52wAAAjU"], referer: binance.com
[Mon Jul 20 07:02:49.891770 2026] [security2:error] [pid 29744:tid 29931] [client 104.234.53.91:38615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ceeGINCUUz5GA9YI53QAAAkw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:50.002871 2026] [security2:error] [pid 28702:tid 28856] [client 77.110.127.138:61957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cebF4957xPw9VVBm7OQAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:50.005484 2026] [security2:error] [pid 28702:tid 28957] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/shop/"] [unique_id "al4cerF4957xPw9VVBm7TAAAAQE"]
[Mon Jul 20 07:02:50.025239 2026] [qos:error] [pid 29744:tid 29829] [remote 57.141.18.103:31730] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.103, id=al4ceuGINCUUz5GA9YI57AACNVM
[Mon Jul 20 07:02:50.059509 2026] [security2:error] [pid 29744:tid 29923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceeGINCUUz5GA9YI5ygAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:50.070576 2026] [security2:error] [pid 29744:tid 29823] [remote 152.228.213.32:41314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ceuGINCUUz5GA9YI57QACHk0"]
[Mon Jul 20 07:02:50.094557 2026] [security2:error] [pid 29744:tid 29886] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ceeGINCUUz5GA9YI51gAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:50.242594 2026] [qos:error] [pid 28702:tid 28715] [remote 57.141.18.0:25488] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.0, id=al4cerF4957xPw9VVBm7VAAAkAs
[Mon Jul 20 07:02:50.254197 2026] [security2:error] [pid 29744:tid 29794] [remote 152.228.213.32:41314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ceuGINCUUz5GA9YI59QACWzA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:02:50.259741 2026] [security2:error] [pid 29744:tid 29963] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ceuGINCUUz5GA9YI58wAAAmw"]
[Mon Jul 20 07:02:50.259778 2026] [security2:error] [pid 29744:tid 29963] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ceuGINCUUz5GA9YI58wAAAmw"]
[Mon Jul 20 07:02:50.394200 2026] [security2:error] [pid 29744:tid 29926] [client 103.238.106.162:42632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.106.238.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ceuGINCUUz5GA9YI5-gAAAkc"]
[Mon Jul 20 07:02:50.394356 2026] [security2:error] [pid 29744:tid 29926] [client 103.238.106.162:42632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "transparentservices.online"] [uri "/xmlrpc.php"] [unique_id "al4ceuGINCUUz5GA9YI5-gAAAkc"]
[Mon Jul 20 07:02:50.407136 2026] [security2:error] [pid 29744:tid 29809] [remote 57.141.18.71:29364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cPeGINCUUz5GA9YIrqQACSz8"]
[Mon Jul 20 07:02:50.464336 2026] [security2:error] [pid 29744:tid 29761] [remote 182.77.62.24:45626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ceuGINCUUz5GA9YI5_QACcQ8"]
[Mon Jul 20 07:02:50.464597 2026] [security2:error] [pid 29744:tid 29968] [client 182.77.62.24:45626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ceuGINCUUz5GA9YI5_QACcQ8"]
[Mon Jul 20 07:02:50.665667 2026] [security2:error] [pid 28702:tid 28754] [remote 47.86.33.52:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cerF4957xPw9VVBm7YAAAjTI"]
[Mon Jul 20 07:02:50.773656 2026] [security2:error] [pid 29744:tid 29918] [client 82.102.18.116:50487] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4ceuGINCUUz5GA9YI6EQAAAj8"]
[Mon Jul 20 07:02:50.984831 2026] [security2:error] [pid 29744:tid 29926] [client 77.110.127.138:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/themes/mai-lifestyle-pro/uc4ev6hcx2c4.php"] [unique_id "al4ceuGINCUUz5GA9YI6JQAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:51.061435 2026] [autoindex:error] [pid 29744:tid 29908] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/mai-lifestyle-pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:51.066247 2026] [autoindex:error] [pid 29744:tid 29918] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/mai-lifestyle-pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:02:51.097256 2026] [security2:error] [pid 28702:tid 28738] [remote 47.86.33.52:34064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ce7F4957xPw9VVBm7dQAArSI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:02:51.109186 2026] [security2:error] [pid 29744:tid 29974] [client 14.225.17.146:49296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4ceeGINCUUz5GA9YI5vgAAAnc"], referer: http://cheesewithjam.com/2026
[Mon Jul 20 07:02:51.113701 2026] [security2:error] [pid 29744:tid 29900] [client 82.102.18.116:54006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.innspace.ca"] [uri "/xmlrpc.php"] [unique_id "al4ce-GINCUUz5GA9YI6MwAAAi0"]
[Mon Jul 20 07:02:51.159612 2026] [qos:error] [pid 29744:tid 29746] [remote 57.141.18.62:32288] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.62, id=al4ce-GINCUUz5GA9YI6NAACjwA
[Mon Jul 20 07:02:51.249982 2026] [security2:error] [pid 28702:tid 28867] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ce7F4957xPw9VVBm7cQAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:51.254821 2026] [security2:error] [pid 28702:tid 28833] [client 14.225.17.146:65335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4cerF4957xPw9VVBm7ZwAAAIU"], referer: http://mollycahill.com/2026
[Mon Jul 20 07:02:51.281870 2026] [security2:error] [pid 28702:tid 28918] [client 77.110.127.138:61992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ce7F4957xPw9VVBm7bwAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:51.283693 2026] [security2:error] [pid 29744:tid 29940] [client 14.225.17.146:65369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4ceuGINCUUz5GA9YI6GgAAAlU"], referer: http://onewingpictures.com/2026
[Mon Jul 20 07:02:51.288511 2026] [security2:error] [pid 28702:tid 28878] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/files/"] [unique_id "al4ce7F4957xPw9VVBm7eQAAALI"]
[Mon Jul 20 07:02:51.327737 2026] [security2:error] [pid 29744:tid 29878] [client 77.110.127.138:61932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/2/"] [unique_id "al4ce-GINCUUz5GA9YI6QwAAAhc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:51.386169 2026] [security2:error] [pid 28702:tid 28747] [remote 147.50.252.213:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ce7F4957xPw9VVBm7fwAA6Cs"]
[Mon Jul 20 07:02:51.552029 2026] [security2:error] [pid 29744:tid 29881] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ce-GINCUUz5GA9YI6SwAAAho"]
[Mon Jul 20 07:02:51.552058 2026] [security2:error] [pid 29744:tid 29881] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ce-GINCUUz5GA9YI6SwAAAho"]
[Mon Jul 20 07:02:51.572943 2026] [qos:error] [pid 29744:tid 29758] [remote 57.141.18.31:55070] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.31, id=al4ce-GINCUUz5GA9YI6UAACZQw
[Mon Jul 20 07:02:51.753954 2026] [security2:error] [pid 28702:tid 28861] [client 82.102.18.116:54020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ce7F4957xPw9VVBm7jgAAAKE"]
[Mon Jul 20 07:02:51.787837 2026] [qos:error] [pid 29744:tid 29785] [remote 57.141.18.42:23508] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.42, id=al4ce-GINCUUz5GA9YI6YAACXic
[Mon Jul 20 07:02:51.822259 2026] [security2:error] [pid 28702:tid 28783] [remote 147.50.252.213:42154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ce7F4957xPw9VVBm7kAAAsU8"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:02:52.046556 2026] [security2:error] [pid 28702:tid 28907] [client 40.77.167.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4cebF4957xPw9VVBm7MQAAAM8"]
[Mon Jul 20 07:02:52.073307 2026] [security2:error] [pid 29744:tid 29930] [client 82.102.18.116:54030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4cfOGINCUUz5GA9YI6cAAAAks"]
[Mon Jul 20 07:02:52.169239 2026] [security2:error] [pid 29744:tid 29911] [client 194.61.41.88:36547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/bless.php"] [unique_id "al4cfOGINCUUz5GA9YI6dwAAAjg"]
[Mon Jul 20 07:02:52.411355 2026] [security2:error] [pid 29744:tid 29994] [client 82.102.18.116:54040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4cfOGINCUUz5GA9YI6hQAAAos"]
[Mon Jul 20 07:02:52.429972 2026] [security2:error] [pid 28702:tid 28914] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/editor/"] [unique_id "al4cfLF4957xPw9VVBm7mgAAANY"]
[Mon Jul 20 07:02:52.556144 2026] [security2:error] [pid 29744:tid 29900] [client 114.119.143.58:44759] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "topspot.com.pk"] [uri "/robots.txt"] [unique_id "al4cfOGINCUUz5GA9YI6igAAAi0"], referer: http://topspot.com.pk/robots.txt
[Mon Jul 20 07:02:52.671357 2026] [security2:error] [pid 29744:tid 29998] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cfOGINCUUz5GA9YI6iwAAAo8"]
[Mon Jul 20 07:02:52.671397 2026] [security2:error] [pid 29744:tid 29998] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cfOGINCUUz5GA9YI6iwAAAo8"]
[Mon Jul 20 07:02:52.697041 2026] [qos:error] [pid 29744:tid 29865] [remote 57.141.18.35:56910] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.35, id=al4cfOGINCUUz5GA9YI6lgACdnc
[Mon Jul 20 07:02:52.729785 2026] [security2:error] [pid 29744:tid 29963] [client 82.102.18.116:54042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4cfOGINCUUz5GA9YI6mQAAAmw"]
[Mon Jul 20 07:02:52.781607 2026] [security2:error] [pid 29744:tid 29859] [remote 78.46.157.202:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cfOGINCUUz5GA9YI6oAACfnE"]
[Mon Jul 20 07:02:52.932260 2026] [security2:error] [pid 29744:tid 29968] [client 182.8.97.191:18214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.97.8.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cfOGINCUUz5GA9YI6oQAAAnE"]
[Mon Jul 20 07:02:52.932384 2026] [security2:error] [pid 29744:tid 29968] [client 182.8.97.191:18214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cfOGINCUUz5GA9YI6oQAAAnE"]
[Mon Jul 20 07:02:52.951027 2026] [security2:error] [pid 29744:tid 29888] [client 194.61.41.93:35731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/O-Simple.php"] [unique_id "al4cfOGINCUUz5GA9YI6pgAAAiE"]
[Mon Jul 20 07:02:52.983387 2026] [security2:error] [pid 29744:tid 29848] [remote 78.46.157.202:36358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cfOGINCUUz5GA9YI6qgACaWY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:02:53.025202 2026] [security2:error] [pid 28702:tid 28942] [client 14.225.17.146:61855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4cfLF4957xPw9VVBm7ogAAAPI"]
[Mon Jul 20 07:02:53.066409 2026] [security2:error] [pid 29744:tid 29949] [client 82.102.18.116:44063] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cfeGINCUUz5GA9YI6sgAAAl4"]
[Mon Jul 20 07:02:53.383195 2026] [qos:error] [pid 29744:tid 29823] [remote 57.141.18.89:39080] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.89, id=al4cfeGINCUUz5GA9YI6vAACdk0
[Mon Jul 20 07:02:53.413138 2026] [security2:error] [pid 29744:tid 29992] [client 82.102.18.116:54068] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4cfeGINCUUz5GA9YI6vQAAAok"]
[Mon Jul 20 07:02:53.590490 2026] [security2:error] [pid 28702:tid 28864] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/include/"] [unique_id "al4cfbF4957xPw9VVBm7wQAAAKQ"]
[Mon Jul 20 07:02:53.682031 2026] [security2:error] [pid 28702:tid 28935] [client 14.225.17.146:50473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4cfbF4957xPw9VVBm7wAAAAOs"], referer: http://ncsynchro.com/2026
[Mon Jul 20 07:02:53.751792 2026] [security2:error] [pid 29744:tid 29906] [client 82.102.18.116:54076] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4cfeGINCUUz5GA9YI60QAAAjM"]
[Mon Jul 20 07:02:53.797659 2026] [security2:error] [pid 29744:tid 29992] [client 194.61.41.80:38965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/lock360.php"] [unique_id "al4cfeGINCUUz5GA9YI60gAAAok"]
[Mon Jul 20 07:02:53.803374 2026] [security2:error] [pid 29744:tid 29973] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cfeGINCUUz5GA9YI6zwAAAnY"]
[Mon Jul 20 07:02:53.803391 2026] [security2:error] [pid 29744:tid 29973] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cfeGINCUUz5GA9YI6zwAAAnY"]
[Mon Jul 20 07:02:53.878338 2026] [security2:error] [pid 29744:tid 29993] [client 183.82.98.154:24849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cfeGINCUUz5GA9YI61wAAAoo"]
[Mon Jul 20 07:02:53.878456 2026] [security2:error] [pid 29744:tid 29993] [client 183.82.98.154:24849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cfeGINCUUz5GA9YI61wAAAoo"]
[Mon Jul 20 07:02:54.023700 2026] [security2:error] [pid 29744:tid 29949] [client 117.247.108.24:21747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cfuGINCUUz5GA9YI62gAAAl4"]
[Mon Jul 20 07:02:54.023834 2026] [security2:error] [pid 29744:tid 29949] [client 117.247.108.24:21747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cfuGINCUUz5GA9YI62gAAAl4"]
[Mon Jul 20 07:02:54.072785 2026] [security2:error] [pid 28702:tid 28878] [client 82.102.18.116:54088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cfrF4957xPw9VVBm70wAAALI"]
[Mon Jul 20 07:02:54.100504 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:61955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cfuGINCUUz5GA9YI62wAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:54.100612 2026] [security2:error] [pid 29744:tid 29921] [client 77.110.127.138:61955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cfuGINCUUz5GA9YI62wAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:54.164627 2026] [security2:error] [pid 29744:tid 29974] [client 14.225.17.146:49187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4cfuGINCUUz5GA9YI63QAAAnc"]
[Mon Jul 20 07:02:54.169911 2026] [security2:error] [pid 29744:tid 29980] [client 14.225.17.146:59983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4cfuGINCUUz5GA9YI63gAAAn0"], referer: http://friendlyspreadsheet.com/2026
[Mon Jul 20 07:02:54.248047 2026] [security2:error] [pid 28702:tid 28718] [remote 57.141.18.116:54554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cPrF4957xPw9VVBmz2QAA3A4"]
[Mon Jul 20 07:02:54.323631 2026] [qos:error] [pid 29744:tid 29817] [remote 57.141.18.95:23178] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al4cfuGINCUUz5GA9YI66gACaUc
[Mon Jul 20 07:02:54.388439 2026] [security2:error] [pid 29744:tid 29911] [client 117.222.139.248:50206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cfuGINCUUz5GA9YI66wAAAjg"]
[Mon Jul 20 07:02:54.388538 2026] [security2:error] [pid 29744:tid 29911] [client 117.222.139.248:50206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cfuGINCUUz5GA9YI66wAAAjg"]
[Mon Jul 20 07:02:54.393341 2026] [security2:error] [pid 28702:tid 28835] [client 82.102.18.116:54094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cfrF4957xPw9VVBm73gAAAIc"]
[Mon Jul 20 07:02:54.550846 2026] [security2:error] [pid 29744:tid 29999] [client 194.61.41.242:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/zwso.php"] [unique_id "al4cfuGINCUUz5GA9YI68wAAApA"]
[Mon Jul 20 07:02:54.639493 2026] [security2:error] [pid 29744:tid 29930] [client 104.207.51.120:19345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cfuGINCUUz5GA9YI69gAAAks"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:54.734044 2026] [security2:error] [pid 29744:tid 29963] [client 82.102.18.116:54100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cfuGINCUUz5GA9YI6-QAAAmw"]
[Mon Jul 20 07:02:54.895068 2026] [security2:error] [pid 28702:tid 28960] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/Assets/"] [unique_id "al4cfrF4957xPw9VVBm77AAAAQQ"]
[Mon Jul 20 07:02:55.047504 2026] [security2:error] [pid 28702:tid 28864] [client 82.102.18.116:54106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cf7F4957xPw9VVBm78wAAAKQ"]
[Mon Jul 20 07:02:55.097681 2026] [security2:error] [pid 28702:tid 28866] [client 103.144.65.217:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cf7F4957xPw9VVBm79wAAAKY"]
[Mon Jul 20 07:02:55.097851 2026] [security2:error] [pid 28702:tid 28866] [client 103.144.65.217:61384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cf7F4957xPw9VVBm79wAAAKY"]
[Mon Jul 20 07:02:55.100107 2026] [qos:error] [pid 28702:tid 28717] [remote 57.141.18.77:40540] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.77, id=al4cf7F4957xPw9VVBm7-QAAvQ0
[Mon Jul 20 07:02:55.126316 2026] [security2:error] [pid 28702:tid 28880] [client 14.225.17.146:49186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4cf7F4957xPw9VVBm79gAAALQ"], referer: https://friendlyspreadsheet.com/2026
[Mon Jul 20 07:02:55.141544 2026] [security2:error] [pid 29744:tid 29885] [client 65.111.12.162:14703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.12.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4cf-GINCUUz5GA9YI7DAAAAh4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:02:55.182805 2026] [security2:error] [pid 29744:tid 29909] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cf-GINCUUz5GA9YI7CwAAAjY"]
[Mon Jul 20 07:02:55.182846 2026] [security2:error] [pid 29744:tid 29909] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cf-GINCUUz5GA9YI7CwAAAjY"]
[Mon Jul 20 07:02:55.198881 2026] [security2:error] [pid 28702:tid 28931] [client 147.93.171.187:54845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/https-detection.php"] [unique_id "al4cf7F4957xPw9VVBm7_gAAAOc"], referer: binance.com
[Mon Jul 20 07:02:55.235843 2026] [security2:error] [pid 28702:tid 28908] [client 65.111.23.190:38331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cf7F4957xPw9VVBm7_wAAANA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:55.333729 2026] [security2:error] [pid 29744:tid 29899] [client 194.61.41.100:54163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/chosen.php"] [unique_id "al4cf-GINCUUz5GA9YI7DwAAAiw"]
[Mon Jul 20 07:02:55.372309 2026] [security2:error] [pid 29744:tid 29930] [client 82.102.18.116:54112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4cf-GINCUUz5GA9YI7EwAAAks"]
[Mon Jul 20 07:02:55.495720 2026] [security2:error] [pid 29744:tid 29959] [client 192.140.149.97:44858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cf-GINCUUz5GA9YI7FQAAAmg"]
[Mon Jul 20 07:02:55.495865 2026] [security2:error] [pid 29744:tid 29959] [client 192.140.149.97:44858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cf-GINCUUz5GA9YI7FQAAAmg"]
[Mon Jul 20 07:02:55.619705 2026] [security2:error] [pid 28702:tid 28949] [client 77.110.127.138:62026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/2/"] [unique_id "al4cf7F4957xPw9VVBm8CgAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:55.664054 2026] [security2:error] [pid 29744:tid 29934] [client 14.225.17.146:50783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4cf-GINCUUz5GA9YI7GQAAAk8"]
[Mon Jul 20 07:02:55.700650 2026] [security2:error] [pid 29744:tid 29923] [client 82.102.18.116:54118] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4cf-GINCUUz5GA9YI7IwAAAkQ"]
[Mon Jul 20 07:02:55.805300 2026] [security2:error] [pid 29744:tid 29946] [client 104.207.52.85:27753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cf-GINCUUz5GA9YI7JQAAAls"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:55.827403 2026] [security2:error] [pid 29744:tid 29967] [client 14.225.17.146:50701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4cf-GINCUUz5GA9YI7JAAAAnA"], referer: http://nikkidesigns.net/2026
[Mon Jul 20 07:02:55.899020 2026] [security2:error] [pid 28702:tid 28844] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/images/stories/"] [unique_id "al4cf7F4957xPw9VVBm8EwAAAJA"]
[Mon Jul 20 07:02:55.993279 2026] [security2:error] [pid 29744:tid 29981] [client 104.234.53.48:38369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cf-GINCUUz5GA9YI7NAAAAn4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:56.024319 2026] [security2:error] [pid 29744:tid 29943] [client 82.102.18.116:54128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cgOGINCUUz5GA9YI7NgAAAlg"]
[Mon Jul 20 07:02:56.162803 2026] [security2:error] [pid 29744:tid 29901] [client 194.61.41.85:36345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/about.php"] [unique_id "al4cgOGINCUUz5GA9YI7QgAAAi4"]
[Mon Jul 20 07:02:56.179300 2026] [security2:error] [pid 29744:tid 29960] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cgOGINCUUz5GA9YI7PgAAAmk"]
[Mon Jul 20 07:02:56.179324 2026] [security2:error] [pid 29744:tid 29960] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cgOGINCUUz5GA9YI7PgAAAmk"]
[Mon Jul 20 07:02:56.343014 2026] [security2:error] [pid 29744:tid 29897] [client 82.102.18.116:54144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cgOGINCUUz5GA9YI7SAAAAio"]
[Mon Jul 20 07:02:56.354163 2026] [security2:error] [pid 29744:tid 29884] [client 104.207.52.144:50783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 144.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cgOGINCUUz5GA9YI7SQAAAh0"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:56.527122 2026] [core:error] [pid 28702:tid 28931] [client 14.225.17.146:50716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:02:56.527151 2026] [core:error] [pid 28702:tid 28931] [client 14.225.17.146:50716] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:02:56.658417 2026] [security2:error] [pid 28702:tid 28948] [client 82.102.18.116:54154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.innspace.ca"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4cgLF4957xPw9VVBm8LwAAAPg"]
[Mon Jul 20 07:02:56.804874 2026] [security2:error] [pid 28702:tid 28836] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/plugins/"] [unique_id "al4cgLF4957xPw9VVBm8MwAAAIg"]
[Mon Jul 20 07:02:56.819258 2026] [security2:error] [pid 28702:tid 28760] [remote 18.61.192.253:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4cgLF4957xPw9VVBm8NAAA1zg"]
[Mon Jul 20 07:02:56.902603 2026] [security2:error] [pid 29744:tid 29993] [client 45.3.54.92:28995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cgOGINCUUz5GA9YI7WgAAAoo"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:02:56.960338 2026] [security2:error] [pid 29744:tid 29897] [client 194.61.41.77:50605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin.php"] [unique_id "al4cgOGINCUUz5GA9YI7XAAAAio"]
[Mon Jul 20 07:02:57.056668 2026] [security2:error] [pid 29744:tid 29931] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cgOGINCUUz5GA9YI7YAAAAkw"]
[Mon Jul 20 07:02:57.056701 2026] [security2:error] [pid 29744:tid 29931] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cgOGINCUUz5GA9YI7YAAAAkw"]
[Mon Jul 20 07:02:57.240885 2026] [security2:error] [pid 29744:tid 29918] [client 154.208.48.130:49626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cgeGINCUUz5GA9YI7bAAAAj8"]
[Mon Jul 20 07:02:57.240976 2026] [security2:error] [pid 29744:tid 29918] [client 154.208.48.130:49626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cgeGINCUUz5GA9YI7bAAAAj8"]
[Mon Jul 20 07:02:57.313832 2026] [security2:error] [pid 28702:tid 28780] [remote 18.61.192.253:58204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4cgbF4957xPw9VVBm8RQAAoUw"], referer: https://justinagrayman.com/wp-login.php
[Mon Jul 20 07:02:57.512081 2026] [qos:error] [pid 29744:tid 29776] [remote 57.141.18.88:37412] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.88, id=al4cgeGINCUUz5GA9YI7egACFx4
[Mon Jul 20 07:02:57.616216 2026] [security2:error] [pid 29744:tid 29899] [client 103.183.8.185:33254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.8.183.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-comments-post.php"] [unique_id "al4cgeGINCUUz5GA9YI7ewAAAiw"]
[Mon Jul 20 07:02:57.616303 2026] [security2:error] [pid 29744:tid 29899] [client 103.183.8.185:33254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "jhavoctattoos.com"] [uri "/wp-comments-post.php"] [unique_id "al4cgeGINCUUz5GA9YI7ewAAAiw"]
[Mon Jul 20 07:02:57.765847 2026] [security2:error] [pid 29744:tid 29903] [client 194.61.41.57:56015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/mah.php"] [unique_id "al4cgeGINCUUz5GA9YI7ggAAAjA"]
[Mon Jul 20 07:02:57.827535 2026] [qos:error] [pid 29744:tid 29807] [remote 57.141.18.56:54596] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.56, id=al4cgeGINCUUz5GA9YI7hwACQj0
[Mon Jul 20 07:02:57.952876 2026] [security2:error] [pid 28702:tid 28846] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/php/"] [unique_id "al4cgbF4957xPw9VVBm8WwAAAJI"]
[Mon Jul 20 07:02:58.060087 2026] [security2:error] [pid 28702:tid 28888] [client 14.251.3.155:54872] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cgrF4957xPw9VVBm8XgAAALw"]
[Mon Jul 20 07:02:58.285039 2026] [security2:error] [pid 29744:tid 29921] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cguGINCUUz5GA9YI7mAAAAkI"]
[Mon Jul 20 07:02:58.285071 2026] [security2:error] [pid 29744:tid 29921] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cguGINCUUz5GA9YI7mAAAAkI"]
[Mon Jul 20 07:02:58.417831 2026] [security2:error] [pid 29744:tid 29956] [client 14.225.17.146:50878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4cguGINCUUz5GA9YI7lgAAAmU"], referer: http://narv.co/2026
[Mon Jul 20 07:02:58.442407 2026] [security2:error] [pid 29744:tid 29968] [client 14.225.17.146:50042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4cguGINCUUz5GA9YI7kQAAAnE"], referer: http://hilltopnurseryinc.com/2026
[Mon Jul 20 07:02:58.540413 2026] [security2:error] [pid 29744:tid 29888] [client 194.61.41.71:21427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.wp/wso.php"] [unique_id "al4cguGINCUUz5GA9YI7owAAAiE"]
[Mon Jul 20 07:02:58.680032 2026] [security2:error] [pid 29744:tid 29934] [client 147.93.171.187:58768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/https-migration.php"] [unique_id "al4cguGINCUUz5GA9YI7qgAAAk8"], referer: binance.com
[Mon Jul 20 07:02:58.808059 2026] [security2:error] [pid 29744:tid 29826] [remote 47.128.34.208:39262] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "terrapro.marketing"] [uri "/blog/"] [unique_id "al4cguGINCUUz5GA9YI7sAACGlA"]
[Mon Jul 20 07:02:58.839096 2026] [security2:error] [pid 29744:tid 29923] [client 46.110.96.34:31692] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4cguGINCUUz5GA9YI7swAAAkQ"]
[Mon Jul 20 07:02:58.853212 2026] [security2:error] [pid 28702:tid 28937] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/css/"] [unique_id "al4cgrF4957xPw9VVBm8eQAAAO0"]
[Mon Jul 20 07:02:58.869313 2026] [security2:error] [pid 29744:tid 29885] [client 46.110.96.34:39108] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4cguGINCUUz5GA9YI7tAAAAh4"]
[Mon Jul 20 07:02:59.075615 2026] [autoindex:error] [pid 29744:tid 29956] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:02:59.076156 2026] [security2:error] [pid 29744:tid 29956] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-admin/css/"] [unique_id "al4cg-GINCUUz5GA9YI7vgAAAmU"]
[Mon Jul 20 07:02:59.141192 2026] [security2:error] [pid 29744:tid 29884] [client 77.110.127.138:62043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cg-GINCUUz5GA9YI7wAAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:59.141292 2026] [security2:error] [pid 29744:tid 29884] [client 77.110.127.138:62043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cg-GINCUUz5GA9YI7wAAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:02:59.141859 2026] [security2:error] [pid 29744:tid 29975] [client 104.234.53.69:35295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cg-GINCUUz5GA9YI7vwAAAng"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:02:59.179890 2026] [security2:error] [pid 28702:tid 28864] [client 187.16.64.216:53567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cg7F4957xPw9VVBm8ggAAAKQ"]
[Mon Jul 20 07:02:59.179979 2026] [security2:error] [pid 28702:tid 28864] [client 187.16.64.216:53567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cg7F4957xPw9VVBm8ggAAAKQ"]
[Mon Jul 20 07:02:59.359980 2026] [security2:error] [pid 29744:tid 29908] [client 194.61.41.241:48275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/core.php"] [unique_id "al4cg-GINCUUz5GA9YI7zAAAAjU"]
[Mon Jul 20 07:02:59.408018 2026] [security2:error] [pid 29744:tid 29921] [client 14.225.17.146:49166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4cg-GINCUUz5GA9YI7wwAAAkI"], referer: https://narv.co/2026
[Mon Jul 20 07:02:59.544567 2026] [security2:error] [pid 29744:tid 29905] [client 122.183.32.225:7997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cg-GINCUUz5GA9YI71AAAAjI"]
[Mon Jul 20 07:02:59.544694 2026] [security2:error] [pid 29744:tid 29905] [client 122.183.32.225:7997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cg-GINCUUz5GA9YI71AAAAjI"]
[Mon Jul 20 07:02:59.599501 2026] [security2:error] [pid 28702:tid 28948] [client 46.110.96.34:31378] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4cg7F4957xPw9VVBm8jwAAAPg"]
[Mon Jul 20 07:02:59.801648 2026] [security2:error] [pid 28702:tid 28924] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "al4cg7F4957xPw9VVBm8mAAAAOA"]
[Mon Jul 20 07:03:00.050876 2026] [security2:error] [pid 29744:tid 29936] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cg-GINCUUz5GA9YI76wAAAlE"]
[Mon Jul 20 07:03:00.050900 2026] [security2:error] [pid 29744:tid 29936] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cg-GINCUUz5GA9YI76wAAAlE"]
[Mon Jul 20 07:03:00.148503 2026] [security2:error] [pid 29744:tid 29931] [client 194.61.41.54:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/robots.php"] [unique_id "al4chOGINCUUz5GA9YI78QAAAkw"]
[Mon Jul 20 07:03:00.487740 2026] [security2:error] [pid 28702:tid 28853] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/cache/"] [unique_id "al4chLF4957xPw9VVBm8tgAAAJk"]
[Mon Jul 20 07:03:00.766210 2026] [security2:error] [pid 29744:tid 29884] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4chOGINCUUz5GA9YI8BwAAAh0"]
[Mon Jul 20 07:03:00.766239 2026] [security2:error] [pid 29744:tid 29884] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4chOGINCUUz5GA9YI8BwAAAh0"]
[Mon Jul 20 07:03:00.985014 2026] [security2:error] [pid 29744:tid 29939] [client 194.61.41.240:38117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/inputs.php"] [unique_id "al4chOGINCUUz5GA9YI8GQAAAlQ"]
[Mon Jul 20 07:03:01.279954 2026] [security2:error] [pid 29744:tid 29940] [client 14.225.17.146:62226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4cg-GINCUUz5GA9YI72gAAAlU"], referer: http://cephasnext.com/2026
[Mon Jul 20 07:03:01.318308 2026] [security2:error] [pid 28702:tid 28953] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/maint/"] [unique_id "al4chbF4957xPw9VVBm81AAAAP0"]
[Mon Jul 20 07:03:01.320733 2026] [security2:error] [pid 28702:tid 28865] [client 216.73.216.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ferrarimenezes.com"] [uri "/index.php"] [unique_id "al4chbF4957xPw9VVBm8zwAApVI"]
[Mon Jul 20 07:03:01.491287 2026] [qos:error] [pid 28702:tid 28730] [remote 57.141.18.44:32470] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.44, id=al4chbF4957xPw9VVBm83gAAoRo
[Mon Jul 20 07:03:01.666601 2026] [autoindex:error] [pid 29744:tid 29992] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:01.667200 2026] [security2:error] [pid 29744:tid 29992] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-admin/maint/"] [unique_id "al4cheGINCUUz5GA9YI8NAAAAok"]
[Mon Jul 20 07:03:01.796662 2026] [security2:error] [pid 29744:tid 29901] [client 194.61.41.104:41639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/mini.php"] [unique_id "al4cheGINCUUz5GA9YI8NwAAAi4"]
[Mon Jul 20 07:03:02.037565 2026] [security2:error] [pid 28702:tid 28834] [client 146.190.84.29:56589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4chbF4957xPw9VVBm86gAAAIY"], referer: https://yandex.com/
[Mon Jul 20 07:03:02.154473 2026] [security2:error] [pid 29744:tid 29926] [client 14.225.17.146:62294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4cheGINCUUz5GA9YI8RwAAAkc"], referer: http://dnsplumbing.com/2026
[Mon Jul 20 07:03:02.195983 2026] [security2:error] [pid 29744:tid 29982] [client 147.93.171.187:56745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/robots-template.php"] [unique_id "al4chuGINCUUz5GA9YI8UAAAAn8"], referer: binance.com
[Mon Jul 20 07:03:02.326350 2026] [security2:error] [pid 29744:tid 29886] [client 14.225.17.146:51231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4chuGINCUUz5GA9YI8SwAAAh8"], referer: http://maplerespiteservices.com/2026
[Mon Jul 20 07:03:02.504017 2026] [security2:error] [pid 28702:tid 28899] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/akismet/"] [unique_id "al4chrF4957xPw9VVBm9FgAAAMc"]
[Mon Jul 20 07:03:02.588496 2026] [autoindex:error] [pid 28702:tid 28861] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:02.589483 2026] [security2:error] [pid 28702:tid 28861] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4chrF4957xPw9VVBm9HAAAAKE"]
[Mon Jul 20 07:03:02.590319 2026] [security2:error] [pid 29744:tid 29912] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/uploads/"] [unique_id "al4chuGINCUUz5GA9YI8YAAAAjk"]
[Mon Jul 20 07:03:02.593978 2026] [security2:error] [pid 28702:tid 28871] [client 146.190.84.29:56589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4chrF4957xPw9VVBm9FAAAAKs"], referer: https://www.bing.com/
[Mon Jul 20 07:03:02.686817 2026] [security2:error] [pid 29744:tid 29956] [client 194.61.41.98:42167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/goods.php"] [unique_id "al4chuGINCUUz5GA9YI8aAAAAmU"]
[Mon Jul 20 07:03:02.696660 2026] [authz_core:error] [pid 29744:tid 29992] [client 143.244.57.120:43520] AH01630: client denied by server configuration: /home1/musichav/public_html/wp-content/plugins/akismet/
[Mon Jul 20 07:03:02.697625 2026] [security2:error] [pid 29744:tid 29992] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/akismet/"] [unique_id "al4chuGINCUUz5GA9YI8awAAAok"]
[Mon Jul 20 07:03:02.756299 2026] [autoindex:error] [pid 29744:tid 29885] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:02.757456 2026] [security2:error] [pid 29744:tid 29885] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4chuGINCUUz5GA9YI8cAAAAh4"]
[Mon Jul 20 07:03:02.758371 2026] [security2:error] [pid 29744:tid 29886] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/"] [unique_id "al4chuGINCUUz5GA9YI8bgAAAh8"]
[Mon Jul 20 07:03:02.873554 2026] [security2:error] [pid 29744:tid 29815] [remote 20.153.140.50:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4chuGINCUUz5GA9YI8eAACY0U"]
[Mon Jul 20 07:03:02.890431 2026] [security2:error] [pid 28702:tid 28913] [client 146.190.84.29:56589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4chrF4957xPw9VVBm9KAAAANU"], referer: https://www.bing.com/
[Mon Jul 20 07:03:02.967063 2026] [autoindex:error] [pid 29744:tid 29951] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:02.967569 2026] [security2:error] [pid 29744:tid 29951] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4chuGINCUUz5GA9YI8fQAAAmA"]
[Mon Jul 20 07:03:02.981522 2026] [security2:error] [pid 29744:tid 29910] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/css/"] [unique_id "al4chuGINCUUz5GA9YI8ewAAAjc"]
[Mon Jul 20 07:03:02.985376 2026] [security2:error] [pid 29744:tid 29936] [client 18.141.57.241:57270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4chuGINCUUz5GA9YI8fgAAAlE"]
[Mon Jul 20 07:03:02.985488 2026] [security2:error] [pid 29744:tid 29936] [client 18.141.57.241:57270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4chuGINCUUz5GA9YI8fgAAAlE"]
[Mon Jul 20 07:03:03.156883 2026] [autoindex:error] [pid 28702:tid 28904] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:03.157367 2026] [security2:error] [pid 28702:tid 28904] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ch7F4957xPw9VVBm9RgAAAMw"]
[Mon Jul 20 07:03:03.159722 2026] [security2:error] [pid 29744:tid 29959] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/ID3/"] [unique_id "al4ch-GINCUUz5GA9YI8gwAAAmg"]
[Mon Jul 20 07:03:03.243529 2026] [security2:error] [pid 28702:tid 28833] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/assets/"] [unique_id "al4ch7F4957xPw9VVBm9TwAAAIU"]
[Mon Jul 20 07:03:03.364796 2026] [autoindex:error] [pid 28702:tid 28907] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:03.365527 2026] [security2:error] [pid 28702:tid 28907] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ch7F4957xPw9VVBm9VAAAAM8"]
[Mon Jul 20 07:03:03.368833 2026] [security2:error] [pid 29744:tid 29918] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/IXR/"] [unique_id "al4ch-GINCUUz5GA9YI8kgAAAj8"]
[Mon Jul 20 07:03:03.379108 2026] [security2:error] [pid 29744:tid 29845] [remote 20.153.140.50:54552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ch-GINCUUz5GA9YI8lQACHWM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:03:03.387701 2026] [autoindex:error] [pid 28702:tid 28837] [client 146.190.84.29:56589] AH01276: Cannot serve directory /home4/tejasenv/public_html/.well-known/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive, referer: https://duckduckgo.com/
[Mon Jul 20 07:03:03.413158 2026] [autoindex:error] [pid 29744:tid 29878] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:03.413647 2026] [security2:error] [pid 29744:tid 29878] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/assets/"] [unique_id "al4ch-GINCUUz5GA9YI8lgAAAhc"]
[Mon Jul 20 07:03:03.574618 2026] [security2:error] [pid 29744:tid 29994] [client 194.61.41.54:20051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/file5.php"] [unique_id "al4ch-GINCUUz5GA9YI8mQAAAos"]
[Mon Jul 20 07:03:03.755609 2026] [autoindex:error] [pid 29744:tid 29982] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:03.756089 2026] [security2:error] [pid 29744:tid 29982] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ch-GINCUUz5GA9YI8ngAAAn8"]
[Mon Jul 20 07:03:03.776309 2026] [security2:error] [pid 28702:tid 28930] [client 117.247.108.24:21854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ch7F4957xPw9VVBm9ZwAAAOY"]
[Mon Jul 20 07:03:03.776419 2026] [security2:error] [pid 28702:tid 28930] [client 117.247.108.24:21854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ch7F4957xPw9VVBm9ZwAAAOY"]
[Mon Jul 20 07:03:03.785555 2026] [security2:error] [pid 29744:tid 29912] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/Requests/"] [unique_id "al4ch-GINCUUz5GA9YI8nAAAAjk"]
[Mon Jul 20 07:03:03.970151 2026] [autoindex:error] [pid 29744:tid 29900] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:03.970621 2026] [security2:error] [pid 29744:tid 29900] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ch-GINCUUz5GA9YI8rAAAAi0"]
[Mon Jul 20 07:03:03.973976 2026] [security2:error] [pid 29744:tid 29962] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/SimplePie/"] [unique_id "al4ch-GINCUUz5GA9YI8pwAAAms"]
[Mon Jul 20 07:03:03.985634 2026] [security2:error] [pid 28702:tid 28918] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/block-patterns/"] [unique_id "al4ch7F4957xPw9VVBm9dgAAANo"]
[Mon Jul 20 07:03:04.189711 2026] [autoindex:error] [pid 29744:tid 29992] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:04.190231 2026] [security2:error] [pid 29744:tid 29992] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ciOGINCUUz5GA9YI8vwAAAok"]
[Mon Jul 20 07:03:04.198865 2026] [autoindex:error] [pid 29744:tid 29993] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:04.199325 2026] [security2:error] [pid 29744:tid 29993] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/block-patterns/"] [unique_id "al4ciOGINCUUz5GA9YI8wAAAAoo"]
[Mon Jul 20 07:03:04.225056 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/Text/"] [unique_id "al4ciOGINCUUz5GA9YI8vAAAApA"]
[Mon Jul 20 07:03:04.326719 2026] [security2:error] [pid 29744:tid 29927] [client 104.234.53.64:39495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ciOGINCUUz5GA9YI8zwAAAkg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:04.401151 2026] [security2:error] [pid 29744:tid 29881] [client 194.61.41.86:46407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ahax.php"] [unique_id "al4ciOGINCUUz5GA9YI80AAAAho"]
[Mon Jul 20 07:03:04.606624 2026] [security2:error] [pid 29744:tid 29888] [client 14.225.17.146:51174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4ciOGINCUUz5GA9YI81QAAAiE"], referer: http://longevityperformanceclinic.com/2026
[Mon Jul 20 07:03:04.638511 2026] [security2:error] [pid 28702:tid 28870] [client 146.190.84.29:56589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.84.190.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4ciLF4957xPw9VVBm9jAAAAKo"], referer: https://yandex.com/
[Mon Jul 20 07:03:04.684610 2026] [security2:error] [pid 29744:tid 29910] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ciOGINCUUz5GA9YI81AAAAjc"]
[Mon Jul 20 07:03:04.684637 2026] [security2:error] [pid 29744:tid 29910] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ciOGINCUUz5GA9YI81AAAAjc"]
[Mon Jul 20 07:03:04.688984 2026] [security2:error] [pid 29744:tid 29921] [client 183.82.98.154:54553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ciOGINCUUz5GA9YI83wAAAkI"]
[Mon Jul 20 07:03:04.689112 2026] [security2:error] [pid 29744:tid 29921] [client 183.82.98.154:54553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ciOGINCUUz5GA9YI83wAAAkI"]
[Mon Jul 20 07:03:04.691106 2026] [security2:error] [pid 29744:tid 29923] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/mu-plugins-old/"] [unique_id "al4ciOGINCUUz5GA9YI80QAAAkQ"]
[Mon Jul 20 07:03:04.789713 2026] [security2:error] [pid 29744:tid 29881] [client 50.116.65.227:13004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ciOGINCUUz5GA9YI86AAAAho"]
[Mon Jul 20 07:03:04.798426 2026] [security2:error] [pid 29744:tid 29949] [client 50.116.65.227:13014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ciOGINCUUz5GA9YI87QAAAl4"]
[Mon Jul 20 07:03:04.952653 2026] [security2:error] [pid 29744:tid 29993] [client 117.222.139.248:50721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ciOGINCUUz5GA9YI89wAAAoo"]
[Mon Jul 20 07:03:04.952798 2026] [security2:error] [pid 29744:tid 29993] [client 117.222.139.248:50721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ciOGINCUUz5GA9YI89wAAAoo"]
[Mon Jul 20 07:03:05.028772 2026] [security2:error] [pid 29744:tid 29774] [remote 64.90.47.163:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.47.90.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cieGINCUUz5GA9YI8-wACWBw"]
[Mon Jul 20 07:03:05.037692 2026] [security2:error] [pid 29744:tid 29881] [client 77.110.127.138:62078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cieGINCUUz5GA9YI9AQAAAho"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:05.037799 2026] [security2:error] [pid 29744:tid 29881] [client 77.110.127.138:62078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cieGINCUUz5GA9YI9AQAAAho"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:05.079245 2026] [security2:error] [pid 29744:tid 29813] [remote 47.86.33.52:36642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4cieGINCUUz5GA9YI9AwACi0M"]
[Mon Jul 20 07:03:05.141962 2026] [security2:error] [pid 29744:tid 29946] [client 14.225.17.146:51035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4cieGINCUUz5GA9YI8_AAAAls"], referer: http://aljosour-alarabia.com/2026
[Mon Jul 20 07:03:05.142139 2026] [security2:error] [pid 29744:tid 29938] [client 194.61.41.79:63815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/f35.php"] [unique_id "al4cieGINCUUz5GA9YI9CwAAAlM"]
[Mon Jul 20 07:03:05.157943 2026] [security2:error] [pid 28702:tid 28939] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/block-supports/"] [unique_id "al4cibF4957xPw9VVBm9ogAAAO8"]
[Mon Jul 20 07:03:05.190269 2026] [security2:error] [pid 28702:tid 28933] [client 77.110.127.138:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cibF4957xPw9VVBm9pQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:05.190388 2026] [security2:error] [pid 28702:tid 28933] [client 77.110.127.138:62080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cibF4957xPw9VVBm9pQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:05.252349 2026] [security2:error] [pid 29744:tid 29788] [remote 64.90.47.163:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.47.90.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cieGINCUUz5GA9YI9EQACbCo"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:03:05.349876 2026] [autoindex:error] [pid 29744:tid 29909] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:05.350692 2026] [security2:error] [pid 29744:tid 29909] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/block-supports/"] [unique_id "al4cieGINCUUz5GA9YI9FAAAAjY"]
[Mon Jul 20 07:03:05.353682 2026] [security2:error] [pid 28702:tid 28889] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cibF4957xPw9VVBm9oQAAAL0"]
[Mon Jul 20 07:03:05.353705 2026] [security2:error] [pid 28702:tid 28889] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cibF4957xPw9VVBm9oQAAAL0"]
[Mon Jul 20 07:03:05.359667 2026] [security2:error] [pid 29744:tid 29923] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/themes/classic/inc/"] [unique_id "al4cieGINCUUz5GA9YI9BwAAAkQ"]
[Mon Jul 20 07:03:05.400581 2026] [lsapi:warn] [pid 28702:tid 28922] [client 14.225.17.146:65241] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2026
[Mon Jul 20 07:03:05.400603 2026] [lsapi:warn] [pid 28702:tid 28922] [client 14.225.17.146:65241] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2026
[Mon Jul 20 07:03:05.400931 2026] [security2:error] [pid 29744:tid 29936] [client 104.234.53.72:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cieGINCUUz5GA9YI9GAAAAlE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:05.469249 2026] [security2:error] [pid 29744:tid 29866] [remote 47.86.33.52:36642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4cieGINCUUz5GA9YI9GQACF3g"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 07:03:05.654719 2026] [qos:error] [pid 29744:tid 29799] [remote 57.141.18.70:28612] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.70, id=al4cieGINCUUz5GA9YI9JgACHjU
[Mon Jul 20 07:03:05.676531 2026] [security2:error] [pid 29744:tid 29938] [client 77.110.127.138:62081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cieGINCUUz5GA9YI9JwAAAlM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:05.676608 2026] [security2:error] [pid 29744:tid 29938] [client 77.110.127.138:62081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cieGINCUUz5GA9YI9JwAAAlM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:05.690018 2026] [security2:error] [pid 29744:tid 29881] [client 103.144.65.217:61839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cieGINCUUz5GA9YI9KAAAAho"]
[Mon Jul 20 07:03:05.690595 2026] [security2:error] [pid 29744:tid 29881] [client 103.144.65.217:61839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cieGINCUUz5GA9YI9KAAAAho"]
[Mon Jul 20 07:03:05.770864 2026] [security2:error] [pid 29744:tid 29918] [client 192.140.149.97:45773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cieGINCUUz5GA9YI9KwAAAj8"]
[Mon Jul 20 07:03:05.771007 2026] [security2:error] [pid 29744:tid 29918] [client 192.140.149.97:45773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cieGINCUUz5GA9YI9KwAAAj8"]
[Mon Jul 20 07:03:05.803402 2026] [security2:error] [pid 28702:tid 28837] [client 147.93.171.187:50722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/script-modules.php"] [unique_id "al4cibF4957xPw9VVBm9twAAAIk"], referer: binance.com
[Mon Jul 20 07:03:05.838018 2026] [security2:error] [pid 28702:tid 28838] [client 145.223.130.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4cibF4957xPw9VVBm9rgAAAIo"]
[Mon Jul 20 07:03:05.857049 2026] [security2:error] [pid 29744:tid 29931] [client 14.225.17.146:59584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4ciOGINCUUz5GA9YI80wAAAkw"], referer: http://inspirespublishing.com/2026
[Mon Jul 20 07:03:05.900226 2026] [lsapi:warn] [pid 28702:tid 28929] [client 50.116.65.227:13048] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:03:05.900260 2026] [lsapi:warn] [pid 28702:tid 28929] [client 50.116.65.227:13048] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:03:05.915413 2026] [security2:error] [pid 28702:tid 28922] [client 14.225.17.146:65241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4ciLF4957xPw9VVBm9kwAAAN4"], referer: http://oswegooperatheater.com/2026
[Mon Jul 20 07:03:05.948923 2026] [security2:error] [pid 28702:tid 28835] [client 194.61.41.254:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/simple.php"] [unique_id "al4cibF4957xPw9VVBm9xAAAAIc"]
[Mon Jul 20 07:03:05.958483 2026] [security2:error] [pid 28702:tid 28920] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cibF4957xPw9VVBm9tAAAANw"]
[Mon Jul 20 07:03:05.958515 2026] [security2:error] [pid 28702:tid 28920] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cibF4957xPw9VVBm9tAAAANw"]
[Mon Jul 20 07:03:05.961074 2026] [security2:error] [pid 29744:tid 29964] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/ninja-forms/"] [unique_id "al4cieGINCUUz5GA9YI9KgAAAm0"]
[Mon Jul 20 07:03:06.029997 2026] [security2:error] [pid 29744:tid 29980] [client 77.110.127.138:62083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ciuGINCUUz5GA9YI9MwAAAn0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:06.030087 2026] [security2:error] [pid 29744:tid 29980] [client 77.110.127.138:62083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ciuGINCUUz5GA9YI9MwAAAn0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:06.156008 2026] [autoindex:error] [pid 29744:tid 29951] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:06.156554 2026] [security2:error] [pid 29744:tid 29951] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ciuGINCUUz5GA9YI9OAAAAmA"]
[Mon Jul 20 07:03:06.183701 2026] [security2:error] [pid 29744:tid 29931] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/mu-plugins/"] [unique_id "al4ciuGINCUUz5GA9YI9NQAAAkw"]
[Mon Jul 20 07:03:06.215370 2026] [security2:error] [pid 28702:tid 28748] [remote 57.141.18.75:31110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cP7F4957xPw9VVBmz_QAAjiw"]
[Mon Jul 20 07:03:06.227346 2026] [security2:error] [pid 29744:tid 29910] [client 50.116.65.227:11028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4ciuGINCUUz5GA9YI9PAAAAjc"]
[Mon Jul 20 07:03:06.231643 2026] [security2:error] [pid 29744:tid 29940] [client 141.94.194.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.locketsandcharms.com"] [uri "/index.php"] [unique_id "al4ciOGINCUUz5GA9YI87gAAAlU"]
[Mon Jul 20 07:03:06.234236 2026] [security2:error] [pid 29744:tid 29773] [remote 95.217.79.18:58038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.79.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4ciuGINCUUz5GA9YI9OwACYxs"]
[Mon Jul 20 07:03:06.234390 2026] [security2:error] [pid 29744:tid 29954] [client 95.217.79.18:58038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4ciuGINCUUz5GA9YI9OwACYxs"]
[Mon Jul 20 07:03:06.252793 2026] [security2:error] [pid 29744:tid 29905] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9MgAAAjI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:06.345493 2026] [security2:error] [pid 29744:tid 29914] [client 77.110.127.138:62084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ciuGINCUUz5GA9YI9TQAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:06.345566 2026] [security2:error] [pid 29744:tid 29914] [client 77.110.127.138:62084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ciuGINCUUz5GA9YI9TQAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:06.362119 2026] [autoindex:error] [pid 29744:tid 29901] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:06.362604 2026] [security2:error] [pid 29744:tid 29901] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ciuGINCUUz5GA9YI9TgAAAi4"]
[Mon Jul 20 07:03:06.365178 2026] [security2:error] [pid 29744:tid 29906] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/Text/Diff/Renderer/"] [unique_id "al4ciuGINCUUz5GA9YI9SwAAAjM"]
[Mon Jul 20 07:03:06.419287 2026] [security2:error] [pid 29744:tid 29934] [client 14.225.17.146:51088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4cieGINCUUz5GA9YI9BQAAAk8"], referer: http://hammadownenterprises.com/2026
[Mon Jul 20 07:03:06.539457 2026] [security2:error] [pid 29744:tid 29967] [client 14.225.17.146:50930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4cieGINCUUz5GA9YI9EgAAAnA"], referer: http://whiteoutcb.com/2026
[Mon Jul 20 07:03:06.565366 2026] [security2:error] [pid 29744:tid 29906] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/blocks/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9ZgAAAjM"]
[Mon Jul 20 07:03:06.568145 2026] [security2:error] [pid 29744:tid 29959] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/blocks/"] [unique_id "al4ciuGINCUUz5GA9YI9ZAAAAmg"]
[Mon Jul 20 07:03:06.576258 2026] [security2:error] [pid 28702:tid 28896] [client 77.110.127.138:62086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cirF4957xPw9VVBm92gAAAMQ"]
[Mon Jul 20 07:03:06.576396 2026] [security2:error] [pid 28702:tid 28896] [client 77.110.127.138:62086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cirF4957xPw9VVBm92gAAAMQ"]
[Mon Jul 20 07:03:06.591777 2026] [security2:error] [pid 29744:tid 29927] [client 66.249.65.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jhavoctattoos.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9WgAAAkg"]
[Mon Jul 20 07:03:06.715499 2026] [security2:error] [pid 29744:tid 29940] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9YAAAAlU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:06.742015 2026] [security2:error] [pid 29744:tid 29923] [client 194.61.41.244:44811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/amax.php"] [unique_id "al4ciuGINCUUz5GA9YI9cQAAAkQ"]
[Mon Jul 20 07:03:06.790963 2026] [autoindex:error] [pid 29744:tid 29888] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:06.791476 2026] [security2:error] [pid 29744:tid 29888] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ciuGINCUUz5GA9YI9ewAAAiE"]
[Mon Jul 20 07:03:06.794471 2026] [security2:error] [pid 29744:tid 29998] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/certificates/"] [unique_id "al4ciuGINCUUz5GA9YI9dwAAAo8"]
[Mon Jul 20 07:03:06.822646 2026] [lsapi:warn] [pid 29744:tid 29909] [client 14.225.17.146:50992] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2026
[Mon Jul 20 07:03:06.822684 2026] [lsapi:warn] [pid 29744:tid 29909] [client 14.225.17.146:50992] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2026
[Mon Jul 20 07:03:06.878804 2026] [security2:error] [pid 29744:tid 29909] [client 14.225.17.146:50992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9hAAAAjY"], referer: https://oswegooperatheater.com/2026
[Mon Jul 20 07:03:06.926305 2026] [security2:error] [pid 28702:tid 28912] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/html-api/"] [unique_id "al4cirF4957xPw9VVBm94wAAANQ"]
[Mon Jul 20 07:03:06.966986 2026] [autoindex:error] [pid 29744:tid 29934] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:06.967448 2026] [security2:error] [pid 29744:tid 29934] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ciuGINCUUz5GA9YI9iwAAAk8"]
[Mon Jul 20 07:03:06.969814 2026] [security2:error] [pid 29744:tid 29900] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/customize/"] [unique_id "al4ciuGINCUUz5GA9YI9iAAAAi0"]
[Mon Jul 20 07:03:06.986493 2026] [security2:error] [pid 29744:tid 29865] [remote 97.74.93.24:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ciuGINCUUz5GA9YI9jQACP3c"]
[Mon Jul 20 07:03:07.019945 2026] [security2:error] [pid 29744:tid 29884] [client 14.225.17.146:50970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9dgAAAh0"], referer: http://www.justinagrayman.com/2026
[Mon Jul 20 07:03:07.063722 2026] [security2:error] [pid 29744:tid 29994] [client 145.223.130.127:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9XwAAAos"]
[Mon Jul 20 07:03:07.098669 2026] [security2:error] [pid 28702:tid 28847] [client 14.225.17.146:61807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4cibF4957xPw9VVBm9wwAAAJM"], referer: http://northbrookcpa.ca/2026
[Mon Jul 20 07:03:07.122018 2026] [autoindex:error] [pid 29744:tid 29909] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:07.122484 2026] [security2:error] [pid 29744:tid 29909] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/html-api/"] [unique_id "al4ci-GINCUUz5GA9YI9lAAAAjY"]
[Mon Jul 20 07:03:07.150857 2026] [autoindex:error] [pid 29744:tid 29993] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:07.151323 2026] [security2:error] [pid 29744:tid 29993] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ci-GINCUUz5GA9YI9lwAAAoo"]
[Mon Jul 20 07:03:07.159831 2026] [security2:error] [pid 29744:tid 29973] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/fonts/"] [unique_id "al4ci-GINCUUz5GA9YI9lQAAAnY"]
[Mon Jul 20 07:03:07.388033 2026] [autoindex:error] [pid 28702:tid 28931] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:07.388462 2026] [security2:error] [pid 28702:tid 28931] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ci7F4957xPw9VVBm98gAAAOc"]
[Mon Jul 20 07:03:07.389914 2026] [security2:error] [pid 29744:tid 29980] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/images/"] [unique_id "al4ci-GINCUUz5GA9YI9nwAAAn0"]
[Mon Jul 20 07:03:07.407687 2026] [security2:error] [pid 28702:tid 28906] [client 77.110.127.138:62089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ci7F4957xPw9VVBm98wAAAM4"]
[Mon Jul 20 07:03:07.407777 2026] [security2:error] [pid 28702:tid 28906] [client 77.110.127.138:62089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ci7F4957xPw9VVBm98wAAAM4"]
[Mon Jul 20 07:03:07.409838 2026] [security2:error] [pid 29744:tid 29854] [remote 97.74.93.24:54200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ci-GINCUUz5GA9YI9owACU2w"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:03:07.443286 2026] [security2:error] [pid 28702:tid 28857] [client 13.233.207.33:41802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ci7F4957xPw9VVBm99QAAAJ0"]
[Mon Jul 20 07:03:07.443355 2026] [security2:error] [pid 28702:tid 28857] [client 13.233.207.33:41802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ci7F4957xPw9VVBm99QAAAJ0"]
[Mon Jul 20 07:03:07.547172 2026] [security2:error] [pid 29744:tid 29911] [client 194.61.41.75:27807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/update/f35.php"] [unique_id "al4ci-GINCUUz5GA9YI9rQAAAjg"]
[Mon Jul 20 07:03:07.550365 2026] [security2:error] [pid 29744:tid 29954] [client 14.225.17.146:54126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4ci-GINCUUz5GA9YI9qwAAAmM"], referer: http://entuvy.com/2026
[Mon Jul 20 07:03:07.561874 2026] [autoindex:error] [pid 29744:tid 29923] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:07.562427 2026] [security2:error] [pid 29744:tid 29923] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4ci-GINCUUz5GA9YI9sgAAAkQ"]
[Mon Jul 20 07:03:07.565025 2026] [security2:error] [pid 29744:tid 29956] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/.well-known/"] [unique_id "al4ci-GINCUUz5GA9YI9rwAAAmU"]
[Mon Jul 20 07:03:07.800483 2026] [security2:error] [pid 29744:tid 29951] [client 14.225.17.146:54179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4ciuGINCUUz5GA9YI9aQAAAmA"], referer: http://lutheranphilosopher.com/2026
[Mon Jul 20 07:03:07.927411 2026] [security2:error] [pid 28702:tid 28955] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/js/"] [unique_id "al4ci7F4957xPw9VVBm9_wAAAP8"]
[Mon Jul 20 07:03:07.933127 2026] [security2:error] [pid 29744:tid 29999] [client 114.119.136.238:61399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tomokaoakshistory.com"] [uri "/robots.txt"] [unique_id "al4ci-GINCUUz5GA9YI9xgAAApA"], referer: https://tomokaoakshistory.com/robots.txt
[Mon Jul 20 07:03:07.942314 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ci-GINCUUz5GA9YI9vgAAAjg"]
[Mon Jul 20 07:03:07.942334 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ci-GINCUUz5GA9YI9vgAAAjg"]
[Mon Jul 20 07:03:07.963931 2026] [security2:error] [pid 29744:tid 29900] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/ALFA_DATA/"] [unique_id "al4ci-GINCUUz5GA9YI9vAAAAi0"]
[Mon Jul 20 07:03:08.113552 2026] [autoindex:error] [pid 29744:tid 29901] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:08.114324 2026] [security2:error] [pid 29744:tid 29901] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/js/"] [unique_id "al4cjOGINCUUz5GA9YI91gAAAi4"]
[Mon Jul 20 07:03:08.349065 2026] [security2:error] [pid 29744:tid 29884] [client 194.61.41.80:26847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/hello.php"] [unique_id "al4cjOGINCUUz5GA9YI97AAAAh0"]
[Mon Jul 20 07:03:08.352128 2026] [security2:error] [pid 28702:tid 28889] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjLF4957xPw9VVBm-BAAAAL0"]
[Mon Jul 20 07:03:08.352159 2026] [security2:error] [pid 28702:tid 28889] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjLF4957xPw9VVBm-BAAAAL0"]
[Mon Jul 20 07:03:08.356880 2026] [security2:error] [pid 29744:tid 29964] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/.well-knownold/"] [unique_id "al4cjOGINCUUz5GA9YI92gAAAm0"]
[Mon Jul 20 07:03:08.560349 2026] [autoindex:error] [pid 29744:tid 29981] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:08.560841 2026] [security2:error] [pid 29744:tid 29981] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cjOGINCUUz5GA9YI98wAAAn4"]
[Mon Jul 20 07:03:08.563244 2026] [security2:error] [pid 29744:tid 29900] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/.well-known/acme-challenge/"] [unique_id "al4cjOGINCUUz5GA9YI98AAAAi0"]
[Mon Jul 20 07:03:08.713795 2026] [security2:error] [pid 28702:tid 28859] [client 154.208.48.130:50140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cjLF4957xPw9VVBm-HQAAAJ8"]
[Mon Jul 20 07:03:08.713886 2026] [security2:error] [pid 28702:tid 28859] [client 154.208.48.130:50140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cjLF4957xPw9VVBm-HQAAAJ8"]
[Mon Jul 20 07:03:08.789162 2026] [cgid:error] [pid 28702:tid 28936] [client 85.204.70.104:0] AH01265: stderr from /home3/dbnvkfmy/public_html/website_23836bfd/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 07:03:08.789620 2026] [security2:error] [pid 28702:tid 28936] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cjLF4957xPw9VVBm-IQAAAOw"]
[Mon Jul 20 07:03:08.791913 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-bin/"] [unique_id "al4cjOGINCUUz5GA9YI99QAAAmw"]
[Mon Jul 20 07:03:08.834727 2026] [security2:error] [pid 28702:tid 28947] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/php-compat/"] [unique_id "al4cjLF4957xPw9VVBm-JAAAAPc"]
[Mon Jul 20 07:03:08.976177 2026] [security2:error] [pid 29744:tid 29903] [client 14.225.17.146:64952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4cjOGINCUUz5GA9YI9-wAAAjA"], referer: http://thefriendlyspreadsheet.com/2026
[Mon Jul 20 07:03:09.034697 2026] [autoindex:error] [pid 29744:tid 29962] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:09.035360 2026] [security2:error] [pid 29744:tid 29962] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/php-compat/"] [unique_id "al4cjeGINCUUz5GA9YI-AgAAAms"]
[Mon Jul 20 07:03:09.142388 2026] [security2:error] [pid 28702:tid 28842] [client 194.61.41.87:25569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/bootstrap.php"] [unique_id "al4cjbF4957xPw9VVBm-MwAAAI4"]
[Mon Jul 20 07:03:09.165238 2026] [security2:error] [pid 29744:tid 29951] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjOGINCUUz5GA9YI-AAAAAmA"]
[Mon Jul 20 07:03:09.165262 2026] [security2:error] [pid 29744:tid 29951] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjOGINCUUz5GA9YI-AAAAAmA"]
[Mon Jul 20 07:03:09.169792 2026] [security2:error] [pid 29744:tid 29908] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index/"] [unique_id "al4cjOGINCUUz5GA9YI9_gAAAjU"]
[Mon Jul 20 07:03:09.348787 2026] [security2:error] [pid 29744:tid 29963] [client 147.93.171.187:63342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/speculative-loading.php"] [unique_id "al4cjeGINCUUz5GA9YI-EgAAAmw"], referer: binance.com
[Mon Jul 20 07:03:09.554321 2026] [security2:error] [pid 29744:tid 29878] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjeGINCUUz5GA9YI-EwAAAhc"]
[Mon Jul 20 07:03:09.554352 2026] [security2:error] [pid 29744:tid 29878] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjeGINCUUz5GA9YI-EwAAAhc"]
[Mon Jul 20 07:03:09.560771 2026] [security2:error] [pid 29744:tid 29975] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/id/"] [unique_id "al4cjeGINCUUz5GA9YI-EAAAAng"]
[Mon Jul 20 07:03:09.591884 2026] [security2:error] [pid 28702:tid 28856] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/PHPMailer/"] [unique_id "al4cjbF4957xPw9VVBm-RwAAAJw"]
[Mon Jul 20 07:03:09.692010 2026] [security2:error] [pid 28702:tid 28926] [client 187.16.64.216:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cjbF4957xPw9VVBm-SwAAAOI"]
[Mon Jul 20 07:03:09.692150 2026] [security2:error] [pid 28702:tid 28926] [client 187.16.64.216:54118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cjbF4957xPw9VVBm-SwAAAOI"]
[Mon Jul 20 07:03:09.699072 2026] [security2:error] [pid 28702:tid 28915] [client 74.7.227.179:45892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4cjbF4957xPw9VVBm-RgAA12E"], referer: https://tejasenvironmental.com/p=554316
[Mon Jul 20 07:03:09.719520 2026] [qos:error] [pid 29744:tid 29794] [remote 57.141.18.30:63298] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.30, id=al4cjeGINCUUz5GA9YI-HAACMjA
[Mon Jul 20 07:03:09.805246 2026] [autoindex:error] [pid 29744:tid 29888] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:09.805809 2026] [security2:error] [pid 29744:tid 29888] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/PHPMailer/"] [unique_id "al4cjeGINCUUz5GA9YI-JQAAAiE"]
[Mon Jul 20 07:03:10.000225 2026] [security2:error] [pid 29744:tid 29900] [client 194.61.41.62:30057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/themes/zMousse/otuz1.php"] [unique_id "al4cjeGINCUUz5GA9YI-KgAAAi0"]
[Mon Jul 20 07:03:10.058210 2026] [security2:error] [pid 29744:tid 29886] [client 104.234.53.81:36811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cjuGINCUUz5GA9YI-LAAAAh8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:10.064378 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjeGINCUUz5GA9YI-IwAAAmw"]
[Mon Jul 20 07:03:10.064398 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjeGINCUUz5GA9YI-IwAAAmw"]
[Mon Jul 20 07:03:10.075532 2026] [security2:error] [pid 28702:tid 28947] [client 13.233.207.33:41814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cjrF4957xPw9VVBm-XgAAAPc"]
[Mon Jul 20 07:03:10.075614 2026] [security2:error] [pid 28702:tid 28947] [client 13.233.207.33:41814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cjrF4957xPw9VVBm-XgAAAPc"]
[Mon Jul 20 07:03:10.101159 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/www/"] [unique_id "al4cjeGINCUUz5GA9YI-IAAAAkg"]
[Mon Jul 20 07:03:10.303555 2026] [security2:error] [pid 29744:tid 29909] [client 122.183.32.225:10012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cjuGINCUUz5GA9YI-NgAAAjY"]
[Mon Jul 20 07:03:10.303703 2026] [security2:error] [pid 29744:tid 29909] [client 122.183.32.225:10012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cjuGINCUUz5GA9YI-NgAAAjY"]
[Mon Jul 20 07:03:10.351192 2026] [security2:error] [pid 29744:tid 29912] [client 14.225.17.146:54324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4cjOGINCUUz5GA9YI-AQAAAjk"], referer: http://backandneckpainrelieflaceychiropractor.com/2026
[Mon Jul 20 07:03:10.577190 2026] [security2:error] [pid 28702:tid 28866] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjrF4957xPw9VVBm-aAAAAKY"]
[Mon Jul 20 07:03:10.577241 2026] [security2:error] [pid 28702:tid 28866] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjrF4957xPw9VVBm-aAAAAKY"]
[Mon Jul 20 07:03:10.608365 2026] [security2:error] [pid 29744:tid 29967] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/web/"] [unique_id "al4cjuGINCUUz5GA9YI-OAAAAnA"]
[Mon Jul 20 07:03:10.651997 2026] [security2:error] [pid 28702:tid 28836] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/pomo/"] [unique_id "al4cjrF4957xPw9VVBm-dwAAAIg"]
[Mon Jul 20 07:03:10.785099 2026] [security2:error] [pid 29744:tid 29963] [client 194.61.41.73:40513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/edit-wolf.php"] [unique_id "al4cjuGINCUUz5GA9YI-QAAAAmw"]
[Mon Jul 20 07:03:10.835542 2026] [autoindex:error] [pid 29744:tid 29897] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:10.836113 2026] [security2:error] [pid 29744:tid 29897] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/pomo/"] [unique_id "al4cjuGINCUUz5GA9YI-RgAAAio"]
[Mon Jul 20 07:03:11.002760 2026] [security2:error] [pid 28702:tid 28917] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjrF4957xPw9VVBm-fwAAANk"]
[Mon Jul 20 07:03:11.002782 2026] [security2:error] [pid 28702:tid 28917] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cjrF4957xPw9VVBm-fwAAANk"]
[Mon Jul 20 07:03:11.007237 2026] [security2:error] [pid 29744:tid 29901] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/uploads/"] [unique_id "al4cjuGINCUUz5GA9YI-QgAAAi4"]
[Mon Jul 20 07:03:11.447916 2026] [security2:error] [pid 29744:tid 29926] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cj-GINCUUz5GA9YI-UAAAAkc"]
[Mon Jul 20 07:03:11.447953 2026] [security2:error] [pid 29744:tid 29926] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cj-GINCUUz5GA9YI-UAAAAkc"]
[Mon Jul 20 07:03:11.461245 2026] [security2:error] [pid 29744:tid 29956] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/upload/"] [unique_id "al4cj-GINCUUz5GA9YI-TwAAAmU"]
[Mon Jul 20 07:03:11.577404 2026] [security2:error] [pid 28702:tid 28913] [client 14.225.17.146:54025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4cj7F4957xPw9VVBm-nQAAANU"]
[Mon Jul 20 07:03:11.609232 2026] [security2:error] [pid 29744:tid 29938] [client 194.61.41.60:49515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ubh/up.php"] [unique_id "al4cj-GINCUUz5GA9YI-WwAAAlM"]
[Mon Jul 20 07:03:11.906141 2026] [security2:error] [pid 29744:tid 29946] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cj-GINCUUz5GA9YI-YwAAAls"]
[Mon Jul 20 07:03:11.906167 2026] [security2:error] [pid 29744:tid 29946] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cj-GINCUUz5GA9YI-YwAAAls"]
[Mon Jul 20 07:03:11.908742 2026] [security2:error] [pid 29744:tid 29901] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/admin/uploads/"] [unique_id "al4cj-GINCUUz5GA9YI-YQAAAi4"]
[Mon Jul 20 07:03:12.108696 2026] [security2:error] [pid 29744:tid 29981] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cj-GINCUUz5GA9YI-bAAAAn4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:12.148725 2026] [security2:error] [pid 28702:tid 28931] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/random_compat/"] [unique_id "al4ckLF4957xPw9VVBm-uQAAAOc"]
[Mon Jul 20 07:03:12.164004 2026] [security2:error] [pid 29744:tid 29867] [remote 81.173.115.7:34962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ckOGINCUUz5GA9YI-fgACRnk"]
[Mon Jul 20 07:03:12.164150 2026] [security2:error] [pid 29744:tid 29925] [client 81.173.115.7:34962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ckOGINCUUz5GA9YI-fgACRnk"]
[Mon Jul 20 07:03:12.371558 2026] [security2:error] [pid 29744:tid 29967] [client 194.61.41.70:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/bootstrap.php"] [unique_id "al4ckOGINCUUz5GA9YI-hgAAAnA"]
[Mon Jul 20 07:03:12.381110 2026] [security2:error] [pid 29744:tid 29975] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-ewAAAng"]
[Mon Jul 20 07:03:12.381135 2026] [security2:error] [pid 29744:tid 29975] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-ewAAAng"]
[Mon Jul 20 07:03:12.385773 2026] [security2:error] [pid 29744:tid 29998] [client 143.244.57.120:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-hAAAAo8"]
[Mon Jul 20 07:03:12.385803 2026] [security2:error] [pid 29744:tid 29998] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-hAAAAo8"]
[Mon Jul 20 07:03:12.386653 2026] [security2:error] [pid 29744:tid 29934] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/Admin/uploads/"] [unique_id "al4ckOGINCUUz5GA9YI-eAAAAk8"]
[Mon Jul 20 07:03:12.424658 2026] [security2:error] [pid 28702:tid 28942] [client 14.225.17.146:59693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4cj7F4957xPw9VVBm-jgAAAPI"], referer: http://alchemygroup.ca/2026
[Mon Jul 20 07:03:12.463947 2026] [access_compat:error] [pid 28702:tid 28866] [client 146.190.84.29:56954] AH01797: client denied by server configuration: /home4/tejasenv/public_html/wp-content/uploads/index.php, referer: https://yandex.com/
[Mon Jul 20 07:03:12.613418 2026] [security2:error] [pid 28702:tid 28927] [client 77.110.127.138:62133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ckLF4957xPw9VVBm-0gAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:12.613513 2026] [security2:error] [pid 28702:tid 28927] [client 77.110.127.138:62133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ckLF4957xPw9VVBm-0gAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:12.655432 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-kgAAAkg"]
[Mon Jul 20 07:03:12.655466 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-kgAAAkg"]
[Mon Jul 20 07:03:12.656871 2026] [security2:error] [pid 29744:tid 29885] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/admin/"] [unique_id "al4ckOGINCUUz5GA9YI-kAAAAh4"]
[Mon Jul 20 07:03:12.665326 2026] [security2:error] [pid 29744:tid 29992] [client 14.225.17.146:57117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ckOGINCUUz5GA9YI-iwAAAok"], referer: http://falconarrowshop.com/2026
[Mon Jul 20 07:03:12.697055 2026] [security2:error] [pid 29744:tid 29967] [client 14.251.3.155:54876] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4ckOGINCUUz5GA9YI-mwAAAnA"]
[Mon Jul 20 07:03:13.122521 2026] [security2:error] [pid 29744:tid 29974] [client 194.61.41.244:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/upload.php"] [unique_id "al4ckeGINCUUz5GA9YI-sgAAAnc"]
[Mon Jul 20 07:03:13.122859 2026] [security2:error] [pid 28702:tid 28922] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/rest-api/"] [unique_id "al4ckbF4957xPw9VVBm-3wAAAN4"]
[Mon Jul 20 07:03:13.341402 2026] [security2:error] [pid 29744:tid 29797] [remote 162.19.86.63:35282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ckeGINCUUz5GA9YI-vAACbDM"]
[Mon Jul 20 07:03:13.346115 2026] [autoindex:error] [pid 29744:tid 29998] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:13.346823 2026] [security2:error] [pid 29744:tid 29998] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/rest-api/"] [unique_id "al4ckeGINCUUz5GA9YI-ugAAAo8"]
[Mon Jul 20 07:03:13.487505 2026] [security2:error] [pid 29744:tid 29936] [client 14.225.17.146:57074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4cj-GINCUUz5GA9YI-aAAAAlE"], referer: http://ironcitywellness.com/2026
[Mon Jul 20 07:03:13.536737 2026] [security2:error] [pid 29744:tid 29807] [remote 162.19.86.63:35282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ckeGINCUUz5GA9YI-ywACZT0"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:13.567481 2026] [security2:error] [pid 29744:tid 29980] [client 85.204.70.104:48676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/index.php"] [unique_id "al4ckeGINCUUz5GA9YI-tgAAAn0"]
[Mon Jul 20 07:03:13.711624 2026] [security2:error] [pid 29744:tid 29910] [client 147.93.171.187:59348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/style-engine.php"] [unique_id "al4ckeGINCUUz5GA9YI-zgAAAjc"], referer: binance.com
[Mon Jul 20 07:03:13.778251 2026] [security2:error] [pid 29744:tid 29964] [client 85.204.70.104:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ckeGINCUUz5GA9YI-zwAAAm0"]
[Mon Jul 20 07:03:13.778427 2026] [security2:error] [pid 29744:tid 29964] [client 85.204.70.104:48676] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ckeGINCUUz5GA9YI-zwAAAm0"]
[Mon Jul 20 07:03:13.795532 2026] [security2:error] [pid 28702:tid 28907] [client 104.234.53.67:36677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ckbF4957xPw9VVBm-8gAAAM8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:13.842400 2026] [security2:error] [pid 29744:tid 29967] [client 194.61.41.246:31951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/seoplugins/db.php"] [unique_id "al4ckeGINCUUz5GA9YI-1wAAAnA"]
[Mon Jul 20 07:03:13.861435 2026] [security2:error] [pid 29744:tid 29839] [remote 81.173.115.7:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ckeGINCUUz5GA9YI-2AACF10"]
[Mon Jul 20 07:03:13.908312 2026] [security2:error] [pid 29744:tid 29943] [client 14.225.17.146:54148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4ckeGINCUUz5GA9YI-0AAAAlg"], referer: http://swafforddetailing.com/2026
[Mon Jul 20 07:03:14.014985 2026] [security2:error] [pid 29744:tid 29899] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ckeGINCUUz5GA9YI-1AAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:14.119604 2026] [security2:error] [pid 29744:tid 29773] [remote 81.173.115.7:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ckuGINCUUz5GA9YI-6QACcBs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:14.135925 2026] [security2:error] [pid 28702:tid 28889] [client 114.119.137.224:52521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "myhealthspot.org"] [uri "/"] [unique_id "al4ckrF4957xPw9VVBm-_wAAAL0"], referer: https://myhealthspot.org/?y=2649635109200
[Mon Jul 20 07:03:14.203695 2026] [security2:error] [pid 28702:tid 28833] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckbF4957xPw9VVBm--wAAAIU"]
[Mon Jul 20 07:03:14.203717 2026] [security2:error] [pid 28702:tid 28833] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckbF4957xPw9VVBm--wAAAIU"]
[Mon Jul 20 07:03:14.208314 2026] [security2:error] [pid 29744:tid 29923] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/images/"] [unique_id "al4ckeGINCUUz5GA9YI-3wAAAkQ"]
[Mon Jul 20 07:03:14.293310 2026] [security2:error] [pid 28702:tid 28863] [client 146.190.84.29:56954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ckrF4957xPw9VVBm_BAAAAKM"], referer: https://duckduckgo.com/
[Mon Jul 20 07:03:14.358289 2026] [security2:error] [pid 29744:tid 29785] [remote 5.252.52.249:45328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ckuGINCUUz5GA9YI-8AACZyc"]
[Mon Jul 20 07:03:14.358443 2026] [security2:error] [pid 29744:tid 29958] [client 5.252.52.249:45328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ckuGINCUUz5GA9YI-8AACZyc"]
[Mon Jul 20 07:03:14.414917 2026] [security2:error] [pid 28702:tid 28870] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/sitemaps/"] [unique_id "al4ckrF4957xPw9VVBm_DgAAAKo"]
[Mon Jul 20 07:03:14.614849 2026] [autoindex:error] [pid 29744:tid 29958] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:14.616031 2026] [security2:error] [pid 29744:tid 29958] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/sitemaps/"] [unique_id "al4ckuGINCUUz5GA9YI_GAAAAmc"]
[Mon Jul 20 07:03:14.628212 2026] [security2:error] [pid 29744:tid 29943] [client 194.61.41.63:53519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al4ckuGINCUUz5GA9YI_HAAAAlg"]
[Mon Jul 20 07:03:14.628881 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI-8gAAApA"]
[Mon Jul 20 07:03:14.628908 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI-8gAAApA"]
[Mon Jul 20 07:03:14.632411 2026] [security2:error] [pid 29744:tid 29918] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/assets/"] [unique_id "al4ckuGINCUUz5GA9YI-8QAAAj8"]
[Mon Jul 20 07:03:14.702665 2026] [security2:error] [pid 28702:tid 28927] [client 117.247.108.24:88] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ckrF4957xPw9VVBm_IQAAAOM"]
[Mon Jul 20 07:03:14.702863 2026] [security2:error] [pid 28702:tid 28927] [client 117.247.108.24:88] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ckrF4957xPw9VVBm_IQAAAOM"]
[Mon Jul 20 07:03:14.749019 2026] [security2:error] [pid 29744:tid 29963] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI_DgAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:14.844975 2026] [security2:error] [pid 28702:tid 28882] [client 14.225.17.146:54257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4ckLF4957xPw9VVBm-3QAAALY"], referer: http://windowtx.com/2026
[Mon Jul 20 07:03:14.847636 2026] [security2:error] [pid 29744:tid 29899] [client 14.225.17.146:57224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI_HwAAAiw"], referer: https://north-woods-engineering.com/2026
[Mon Jul 20 07:03:15.074579 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI_JQAAAjg"]
[Mon Jul 20 07:03:15.074605 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI_JQAAAjg"]
[Mon Jul 20 07:03:15.077383 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/"] [unique_id "al4ckuGINCUUz5GA9YI_IwAAApA"]
[Mon Jul 20 07:03:15.322376 2026] [security2:error] [pid 28702:tid 28891] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ck7F4957xPw9VVBm_LgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:15.351220 2026] [security2:error] [pid 28702:tid 28901] [client 213.152.186.163:43130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ck7F4957xPw9VVBm_NgAAAMk"]
[Mon Jul 20 07:03:15.351319 2026] [security2:error] [pid 28702:tid 28901] [client 213.152.186.163:43130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ck7F4957xPw9VVBm_NgAAAMk"]
[Mon Jul 20 07:03:15.379635 2026] [security2:error] [pid 29744:tid 29963] [client 194.61.41.83:54071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/linkpreview/db.php"] [unique_id "al4ck-GINCUUz5GA9YI_PQAAAmw"]
[Mon Jul 20 07:03:15.387511 2026] [security2:error] [pid 29744:tid 29856] [remote 57.141.18.114:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6102656"] [unique_id "al4ck-GINCUUz5GA9YI_PwACOG4"]
[Mon Jul 20 07:03:15.407202 2026] [security2:error] [pid 29744:tid 29805] [remote 57.141.18.12:34682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4729264"] [unique_id "al4ck-GINCUUz5GA9YI_RQACcTs"]
[Mon Jul 20 07:03:15.493017 2026] [security2:error] [pid 29744:tid 29900] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ck-GINCUUz5GA9YI_OAAAAi0"]
[Mon Jul 20 07:03:15.493045 2026] [security2:error] [pid 29744:tid 29900] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ck-GINCUUz5GA9YI_OAAAAi0"]
[Mon Jul 20 07:03:15.497406 2026] [security2:error] [pid 29744:tid 29943] [client 117.222.139.248:51233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ck-GINCUUz5GA9YI_SgAAAlg"]
[Mon Jul 20 07:03:15.497511 2026] [security2:error] [pid 29744:tid 29943] [client 117.222.139.248:51233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4ck-GINCUUz5GA9YI_SgAAAlg"]
[Mon Jul 20 07:03:15.499046 2026] [security2:error] [pid 29744:tid 29962] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/upload/image/"] [unique_id "al4ck-GINCUUz5GA9YI_NgAAAms"]
[Mon Jul 20 07:03:15.510552 2026] [security2:error] [pid 28702:tid 28913] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4ck7F4957xPw9VVBm_PgAAANU"]
[Mon Jul 20 07:03:15.521527 2026] [security2:error] [pid 28702:tid 28914] [client 65.111.22.207:18109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4ck7F4957xPw9VVBm_PwAAANY"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:15.660066 2026] [security2:error] [pid 29744:tid 29921] [client 14.225.17.146:57178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4ckeGINCUUz5GA9YI-4QAAAkI"], referer: http://amalia-capital.com/2026
[Mon Jul 20 07:03:15.661553 2026] [autoindex:error] [pid 28702:tid 28935] [client 146.190.84.29:56954] AH01276: Cannot serve directory /home4/tejasenv/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive, referer: https://duckduckgo.com/
[Mon Jul 20 07:03:15.725868 2026] [autoindex:error] [pid 29744:tid 29878] [client 143.244.57.120:43520] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:15.726358 2026] [security2:error] [pid 29744:tid 29878] [client 143.244.57.120:43520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4ck-GINCUUz5GA9YI_XAAAAhc"]
[Mon Jul 20 07:03:15.730393 2026] [security2:error] [pid 29744:tid 29886] [client 34.90.66.217:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.poopatrol608.com"] [uri "/"] [unique_id "al4ck-GINCUUz5GA9YI_XgAAAh8"]
[Mon Jul 20 07:03:15.730491 2026] [security2:error] [pid 29744:tid 29886] [client 34.90.66.217:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.poopatrol608.com"] [uri "/"] [unique_id "al4ck-GINCUUz5GA9YI_XgAAAh8"]
[Mon Jul 20 07:03:15.762953 2026] [security2:error] [pid 29744:tid 29934] [client 183.82.98.154:55149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ck-GINCUUz5GA9YI_YwAAAk8"]
[Mon Jul 20 07:03:15.763094 2026] [security2:error] [pid 29744:tid 29934] [client 183.82.98.154:55149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ck-GINCUUz5GA9YI_YwAAAk8"]
[Mon Jul 20 07:03:15.923465 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ck-GINCUUz5GA9YI_WgAAAkg"]
[Mon Jul 20 07:03:15.923487 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4ck-GINCUUz5GA9YI_WgAAAkg"]
[Mon Jul 20 07:03:15.928325 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/assets/images/"] [unique_id "al4ck-GINCUUz5GA9YI_VgAAAmw"]
[Mon Jul 20 07:03:15.975738 2026] [security2:error] [pid 28702:tid 28907] [client 114.119.139.226:43421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.secretkeynumerology.com"] [uri "/robots.txt"] [unique_id "al4ck7F4957xPw9VVBm_UwAAAM8"], referer: http://www.secretkeynumerology.com/robots.txt
[Mon Jul 20 07:03:16.045137 2026] [security2:error] [pid 29744:tid 29926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ck-GINCUUz5GA9YI_WAAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:16.101282 2026] [security2:error] [pid 28702:tid 28899] [client 104.207.53.8:29583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4clLF4957xPw9VVBm_WAAAAMc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:16.188417 2026] [security2:error] [pid 29744:tid 29968] [client 103.144.65.217:62294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4clOGINCUUz5GA9YI_fgAAAnE"]
[Mon Jul 20 07:03:16.188560 2026] [security2:error] [pid 29744:tid 29968] [client 103.144.65.217:62294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4clOGINCUUz5GA9YI_fgAAAnE"]
[Mon Jul 20 07:03:16.200396 2026] [security2:error] [pid 29744:tid 29927] [client 23.251.146.115:35072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4clOGINCUUz5GA9YI_cQACSDE"]
[Mon Jul 20 07:03:16.234686 2026] [security2:error] [pid 28702:tid 28856] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/style-engine/"] [unique_id "al4clLF4957xPw9VVBm_XwAAAJw"]
[Mon Jul 20 07:03:16.340770 2026] [security2:error] [pid 29744:tid 29943] [client 23.251.146.115:35072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4clOGINCUUz5GA9YI_gAACWE0"]
[Mon Jul 20 07:03:16.347262 2026] [security2:error] [pid 29744:tid 29888] [client 192.140.149.97:45912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4clOGINCUUz5GA9YI_hAAAAiE"]
[Mon Jul 20 07:03:16.347368 2026] [security2:error] [pid 29744:tid 29888] [client 192.140.149.97:45912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4clOGINCUUz5GA9YI_hAAAAiE"]
[Mon Jul 20 07:03:16.456286 2026] [security2:error] [pid 29744:tid 29998] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clOGINCUUz5GA9YI_ewAAAo8"]
[Mon Jul 20 07:03:16.456311 2026] [security2:error] [pid 29744:tid 29998] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clOGINCUUz5GA9YI_ewAAAo8"]
[Mon Jul 20 07:03:16.458349 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/Public/"] [unique_id "al4clOGINCUUz5GA9YI_eQAAAjg"]
[Mon Jul 20 07:03:16.605184 2026] [security2:error] [pid 28702:tid 28953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4clLF4957xPw9VVBm_ZAAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:16.614039 2026] [security2:error] [pid 29744:tid 29938] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4clOGINCUUz5GA9YI_jwAAAlM"]
[Mon Jul 20 07:03:16.644891 2026] [security2:error] [pid 28702:tid 28865] [client 45.3.42.19:47835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4clLF4957xPw9VVBm_dgAAAKU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:16.901325 2026] [security2:error] [pid 28702:tid 28935] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clLF4957xPw9VVBm_dwAAAOs"]
[Mon Jul 20 07:03:16.901349 2026] [security2:error] [pid 28702:tid 28935] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clLF4957xPw9VVBm_dwAAAOs"]
[Mon Jul 20 07:03:16.916108 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/vendor/"] [unique_id "al4clOGINCUUz5GA9YI_lgAAAjg"]
[Mon Jul 20 07:03:16.948689 2026] [autoindex:error] [pid 29744:tid 29918] [client 143.244.57.120:45596] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:16.949379 2026] [security2:error] [pid 29744:tid 29918] [client 143.244.57.120:45596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/cgi-sys/403.html"] [unique_id "al4clOGINCUUz5GA9YI_owAAAj8"]
[Mon Jul 20 07:03:17.151737 2026] [security2:error] [pid 28702:tid 28861] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4clLF4957xPw9VVBm_ggAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.176545 2026] [security2:error] [pid 28702:tid 28942] [client 146.190.84.29:56954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4clbF4957xPw9VVBm_hgAAAPI"], referer: https://duckduckgo.com/
[Mon Jul 20 07:03:17.186693 2026] [security2:error] [pid 28702:tid 28914] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/theme-compat/"] [unique_id "al4clbF4957xPw9VVBm_kwAAANY"]
[Mon Jul 20 07:03:17.204871 2026] [security2:error] [pid 28702:tid 28887] [client 104.207.52.162:55447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4clbF4957xPw9VVBm_kgAAALs"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:17.336903 2026] [security2:error] [pid 28702:tid 28837] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4clbF4957xPw9VVBm_iQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.337512 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clbF4957xPw9VVBm_iAAAAOQ"]
[Mon Jul 20 07:03:17.337541 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clbF4957xPw9VVBm_iAAAAOQ"]
[Mon Jul 20 07:03:17.370476 2026] [security2:error] [pid 28702:tid 28953] [client 77.110.127.138:62160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4clbF4957xPw9VVBm_mgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.370624 2026] [security2:error] [pid 28702:tid 28953] [client 77.110.127.138:62160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4clbF4957xPw9VVBm_mgAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.372067 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/local/"] [unique_id "al4cleGINCUUz5GA9YI_qAAAAjg"]
[Mon Jul 20 07:03:17.401453 2026] [security2:error] [pid 28702:tid 28853] [client 114.119.152.54:22311] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lizrichter.com.au"] [uri "/robots.txt"] [unique_id "al4clbF4957xPw9VVBm_mwAAAJk"], referer: https://www.lizrichter.com.au/robots.txt
[Mon Jul 20 07:03:17.428702 2026] [lsapi:warn] [pid 29744:tid 29810] [remote 168.187.50.99:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:03:17.597329 2026] [security2:error] [pid 29744:tid 29899] [client 77.110.127.138:62163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cleGINCUUz5GA9YI_wwAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.597419 2026] [security2:error] [pid 29744:tid 29899] [client 77.110.127.138:62163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cleGINCUUz5GA9YI_wwAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.755023 2026] [security2:error] [pid 29744:tid 29926] [client 14.225.17.146:59048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4cleGINCUUz5GA9YI_vgAAAkc"]
[Mon Jul 20 07:03:17.816256 2026] [security2:error] [pid 28702:tid 28924] [client 14.225.17.146:57189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4clLF4957xPw9VVBm_aAAAAOA"], referer: http://colinkeyphotography.com/2026
[Mon Jul 20 07:03:17.822316 2026] [security2:error] [pid 28702:tid 28876] [client 65.111.23.71:44777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4clbF4957xPw9VVBm_sgAAALA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:17.838737 2026] [autoindex:error] [pid 29744:tid 29968] [client 143.244.57.120:45604] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:17.839335 2026] [security2:error] [pid 29744:tid 29968] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/cgi-sys/403.html"] [unique_id "al4cleGINCUUz5GA9YI_0wAAAnE"]
[Mon Jul 20 07:03:17.849857 2026] [security2:error] [pid 28702:tid 28901] [client 77.110.127.138:62169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4clbF4957xPw9VVBm_swAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.849965 2026] [security2:error] [pid 28702:tid 28901] [client 77.110.127.138:62169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4clbF4957xPw9VVBm_swAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:17.858655 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cleGINCUUz5GA9YI_xgAAApA"]
[Mon Jul 20 07:03:17.858702 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cleGINCUUz5GA9YI_xgAAApA"]
[Mon Jul 20 07:03:17.860839 2026] [autoindex:error] [pid 28702:tid 28834] [client 146.190.84.29:56954] AH01276: Cannot serve directory /home4/tejasenv/public_html/wp-content/mu-plugins/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive, referer: https://yandex.com/
[Mon Jul 20 07:03:17.910273 2026] [security2:error] [pid 29744:tid 29918] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/modules/"] [unique_id "al4cleGINCUUz5GA9YI_xAAAAj8"]
[Mon Jul 20 07:03:18.024703 2026] [security2:error] [pid 28702:tid 28914] [client 147.93.171.187:54077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/template-canvas.php"] [unique_id "al4clrF4957xPw9VVBm_ugAAANY"], referer: binance.com
[Mon Jul 20 07:03:18.054087 2026] [security2:error] [pid 29744:tid 29757] [remote 78.46.157.202:43438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cluGINCUUz5GA9YI_1gACRws"]
[Mon Jul 20 07:03:18.105344 2026] [security2:error] [pid 29744:tid 29946] [client 194.61.41.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4clOGINCUUz5GA9YI_fAAAAls"]
[Mon Jul 20 07:03:18.222078 2026] [security2:error] [pid 28702:tid 28934] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-includes/widgets/"] [unique_id "al4clrF4957xPw9VVBm_xAAAAOo"]
[Mon Jul 20 07:03:18.244183 2026] [security2:error] [pid 29744:tid 29973] [client 104.234.53.70:37697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cluGINCUUz5GA9YI_4wAAAnY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:18.257596 2026] [security2:error] [pid 29744:tid 29943] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cleGINCUUz5GA9YI_zwAAAlg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:18.261021 2026] [security2:error] [pid 29744:tid 29861] [remote 78.46.157.202:43438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cluGINCUUz5GA9YI_5AACaHM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:03:18.331691 2026] [security2:error] [pid 28702:tid 28941] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_vQAAAPE"]
[Mon Jul 20 07:03:18.331717 2026] [security2:error] [pid 28702:tid 28941] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_vQAAAPE"]
[Mon Jul 20 07:03:18.335652 2026] [security2:error] [pid 29744:tid 29934] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/Site/"] [unique_id "al4cluGINCUUz5GA9YI_1wAAAk8"]
[Mon Jul 20 07:03:18.373938 2026] [security2:error] [pid 29744:tid 29998] [client 45.3.42.199:9251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cluGINCUUz5GA9YI_6wAAAo8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:18.374325 2026] [autoindex:error] [pid 28702:tid 28946] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:18.417470 2026] [autoindex:error] [pid 29744:tid 29971] [client 143.244.57.120:45604] AH01276: Cannot serve directory /home1/musichav/public_html/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:18.418282 2026] [security2:error] [pid 29744:tid 29971] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-includes/widgets/"] [unique_id "al4cluGINCUUz5GA9YI_7gAAAnQ"]
[Mon Jul 20 07:03:18.432056 2026] [security2:error] [pid 29744:tid 29960] [client 77.110.127.138:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cluGINCUUz5GA9YI_8QAAAmk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:18.432194 2026] [security2:error] [pid 29744:tid 29960] [client 77.110.127.138:62171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cluGINCUUz5GA9YI_8QAAAmk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:18.573173 2026] [security2:error] [pid 28702:tid 28893] [client 146.190.84.29:56954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_0gAAAME"], referer: https://search.yahoo.com/
[Mon Jul 20 07:03:18.594075 2026] [security2:error] [pid 28702:tid 28872] [client 77.110.127.138:62175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4clrF4957xPw9VVBm_2gAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:18.594207 2026] [security2:error] [pid 28702:tid 28872] [client 77.110.127.138:62175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4clrF4957xPw9VVBm_2gAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:18.689733 2026] [security2:error] [pid 28702:tid 28726] [remote 173.212.252.15:50860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4clrF4957xPw9VVBm_3wAAvhY"]
[Mon Jul 20 07:03:18.772499 2026] [security2:error] [pid 28702:tid 28926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_2AAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:18.777072 2026] [security2:error] [pid 28702:tid 28935] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_1QAAAOs"]
[Mon Jul 20 07:03:18.777087 2026] [security2:error] [pid 28702:tid 28935] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_1QAAAOs"]
[Mon Jul 20 07:03:18.795888 2026] [security2:error] [pid 29744:tid 29951] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/system/"] [unique_id "al4cluGINCUUz5GA9YI_8wAAAmA"]
[Mon Jul 20 07:03:18.828590 2026] [security2:error] [pid 28702:tid 28809] [remote 154.66.198.148:25736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4clrF4957xPw9VVBm_5AAAiGk"]
[Mon Jul 20 07:03:18.828713 2026] [security2:error] [pid 28702:tid 28836] [client 154.66.198.148:25736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4clrF4957xPw9VVBm_5AAAiGk"]
[Mon Jul 20 07:03:18.862784 2026] [security2:error] [pid 29744:tid 29812] [remote 20.153.140.50:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4cluGINCUUz5GA9YI__wACXkI"]
[Mon Jul 20 07:03:18.885597 2026] [security2:error] [pid 28702:tid 28746] [remote 173.212.252.15:50860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4clrF4957xPw9VVBm_5wAA1io"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:03:18.972048 2026] [security2:error] [pid 29744:tid 29973] [client 194.61.41.56:45693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/udd.php"] [unique_id "al4cluGINCUUz5GA9YJAAQAAAnY"]
[Mon Jul 20 07:03:19.006914 2026] [security2:error] [pid 28702:tid 28863] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "al4cl7F4957xPw9VVBm_7gAAAKM"]
[Mon Jul 20 07:03:19.086688 2026] [security2:error] [pid 29744:tid 29931] [client 77.110.127.138:62177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cl-GINCUUz5GA9YJABgAAAkw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:19.086801 2026] [security2:error] [pid 29744:tid 29931] [client 77.110.127.138:62177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cl-GINCUUz5GA9YJABgAAAkw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:19.214299 2026] [http2:warn] [pid 28702:tid 28845] [client 57.141.18.71:61452] h2_stream(28702-636-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:19.245374 2026] [security2:error] [pid 29744:tid 29760] [remote 20.153.140.50:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4cl-GINCUUz5GA9YJADQACWA4"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:03:19.259950 2026] [autoindex:error] [pid 29744:tid 29949] [client 143.244.57.120:45604] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:19.260402 2026] [autoindex:error] [pid 28702:tid 28946] [client 146.190.84.29:56954] AH01276: Cannot serve directory /home4/tejasenv/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive, referer: https://search.yahoo.com/
[Mon Jul 20 07:03:19.260705 2026] [security2:error] [pid 29744:tid 29949] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "al4cl-GINCUUz5GA9YJACAAAAl4"]
[Mon Jul 20 07:03:19.301100 2026] [security2:error] [pid 29744:tid 29933] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cl-GINCUUz5GA9YJABQAAAk4"]
[Mon Jul 20 07:03:19.301141 2026] [security2:error] [pid 29744:tid 29933] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cl-GINCUUz5GA9YJABQAAAk4"]
[Mon Jul 20 07:03:19.314542 2026] [security2:error] [pid 29744:tid 29982] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/template/"] [unique_id "al4cl-GINCUUz5GA9YJABAAAAn8"]
[Mon Jul 20 07:03:19.356873 2026] [security2:error] [pid 28702:tid 28945] [client 77.110.127.138:62179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cl7F4957xPw9VVBm__wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:19.356999 2026] [security2:error] [pid 28702:tid 28945] [client 77.110.127.138:62179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cl7F4957xPw9VVBm__wAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:19.703604 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cl-GINCUUz5GA9YJAGQAAAkg"]
[Mon Jul 20 07:03:19.703635 2026] [security2:error] [pid 29744:tid 29927] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cl-GINCUUz5GA9YJAGQAAAkg"]
[Mon Jul 20 07:03:19.721175 2026] [security2:error] [pid 29744:tid 29994] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/shop/"] [unique_id "al4cl-GINCUUz5GA9YJAGAAAAos"]
[Mon Jul 20 07:03:19.725795 2026] [security2:error] [pid 29744:tid 29959] [client 154.208.48.130:50632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cl-GINCUUz5GA9YJAIgAAAmg"]
[Mon Jul 20 07:03:19.725894 2026] [security2:error] [pid 29744:tid 29959] [client 154.208.48.130:50632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cl-GINCUUz5GA9YJAIgAAAmg"]
[Mon Jul 20 07:03:19.736398 2026] [security2:error] [pid 28702:tid 28914] [client 34.21.41.254:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/xmlrpc.php"] [unique_id "al4cl7F4957xPw9VVBnADgAAANY"]
[Mon Jul 20 07:03:19.747686 2026] [security2:error] [pid 28702:tid 28880] [client 15.237.142.234:26640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cl7F4957xPw9VVBnADQAAALQ"]
[Mon Jul 20 07:03:19.747837 2026] [security2:error] [pid 28702:tid 28880] [client 15.237.142.234:26640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cl7F4957xPw9VVBnADQAAALQ"]
[Mon Jul 20 07:03:19.783372 2026] [security2:error] [pid 28702:tid 28913] [client 194.61.41.102:59511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/pwnd.php"] [unique_id "al4cl7F4957xPw9VVBnAEAAAANU"]
[Mon Jul 20 07:03:19.918631 2026] [security2:error] [pid 28702:tid 28918] [client 14.225.17.146:58651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_4QAAANo"], referer: http://mourgroup.com/2026
[Mon Jul 20 07:03:19.999699 2026] [security2:error] [pid 28702:tid 28857] [client 14.225.17.146:58433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4cl7F4957xPw9VVBnAEwAAAJ0"], referer: http://xp-design.co/2026
[Mon Jul 20 07:03:20.008622 2026] [security2:error] [pid 28702:tid 28866] [client 34.21.41.254:53424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4cmLF4957xPw9VVBnAHgAAAKY"]
[Mon Jul 20 07:03:20.041125 2026] [security2:error] [pid 29744:tid 29946] [client 14.225.17.146:58612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4cluGINCUUz5GA9YI_9QAAAls"], referer: http://scott-assist.com/2026
[Mon Jul 20 07:03:20.072389 2026] [http2:warn] [pid 29744:tid 29935] [client 57.141.18.50:48122] h2_stream(29744-850-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:20.090311 2026] [security2:error] [pid 28702:tid 28833] [client 14.225.17.146:58473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4clrF4957xPw9VVBm_2QAAAIU"], referer: http://ghivs.com/2026
[Mon Jul 20 07:03:20.179139 2026] [lsapi:warn] [pid 29744:tid 29802] [remote 168.187.50.99:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:03:20.205709 2026] [security2:error] [pid 28702:tid 28877] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/css/colors/"] [unique_id "al4cmLF4957xPw9VVBnAJwAAALE"]
[Mon Jul 20 07:03:20.214248 2026] [security2:error] [pid 29744:tid 29993] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cl-GINCUUz5GA9YJALAAAAoo"]
[Mon Jul 20 07:03:20.214272 2026] [security2:error] [pid 29744:tid 29993] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cl-GINCUUz5GA9YJALAAAAoo"]
[Mon Jul 20 07:03:20.218485 2026] [security2:error] [pid 29744:tid 29939] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/files/"] [unique_id "al4cl-GINCUUz5GA9YJAKgAAAlQ"]
[Mon Jul 20 07:03:20.260098 2026] [security2:error] [pid 28702:tid 28848] [client 34.21.41.254:50930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4cmLF4957xPw9VVBnAKQAAAJQ"]
[Mon Jul 20 07:03:20.325808 2026] [security2:error] [pid 29744:tid 29992] [client 187.16.64.216:54679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cmOGINCUUz5GA9YJAOwAAAok"]
[Mon Jul 20 07:03:20.325973 2026] [security2:error] [pid 29744:tid 29992] [client 187.16.64.216:54679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cmOGINCUUz5GA9YJAOwAAAok"]
[Mon Jul 20 07:03:20.344371 2026] [http2:warn] [pid 28702:tid 28879] [client 57.141.18.58:61130] h2_stream(28702-643-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:20.405181 2026] [security2:error] [pid 29744:tid 29899] [client 14.225.17.146:58416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4cmOGINCUUz5GA9YJANAAAAiw"], referer: http://guidehunting.com/2026
[Mon Jul 20 07:03:20.461212 2026] [autoindex:error] [pid 29744:tid 29959] [client 143.244.57.120:45604] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:20.461722 2026] [security2:error] [pid 29744:tid 29959] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-admin/css/colors/"] [unique_id "al4cmOGINCUUz5GA9YJARAAAAmg"]
[Mon Jul 20 07:03:20.493360 2026] [security2:error] [pid 29744:tid 29943] [client 34.21.41.254:56692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4cmOGINCUUz5GA9YJARwAAAlg"]
[Mon Jul 20 07:03:20.552986 2026] [security2:error] [pid 29744:tid 29926] [client 194.61.41.253:26347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd-1/pwnd.php"] [unique_id "al4cmOGINCUUz5GA9YJATQAAAkc"]
[Mon Jul 20 07:03:20.604693 2026] [security2:error] [pid 29744:tid 29958] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmOGINCUUz5GA9YJAQgAAAmc"]
[Mon Jul 20 07:03:20.604715 2026] [security2:error] [pid 29744:tid 29958] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmOGINCUUz5GA9YJAQgAAAmc"]
[Mon Jul 20 07:03:20.611050 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/admin/editor/"] [unique_id "al4cmOGINCUUz5GA9YJAQAAAAjg"]
[Mon Jul 20 07:03:20.729474 2026] [security2:error] [pid 29744:tid 29938] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cmOGINCUUz5GA9YJATwACUww"], referer: http://aleishapenny.ca/2026
[Mon Jul 20 07:03:20.762637 2026] [security2:error] [pid 29744:tid 29964] [client 34.21.41.254:60408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cmOGINCUUz5GA9YJAUwAAAm0"]
[Mon Jul 20 07:03:20.922902 2026] [security2:error] [pid 28702:tid 28927] [client 122.183.32.225:16063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cmLF4957xPw9VVBnARgAAAOM"]
[Mon Jul 20 07:03:20.923005 2026] [security2:error] [pid 28702:tid 28927] [client 122.183.32.225:16063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cmLF4957xPw9VVBnARgAAAOM"]
[Mon Jul 20 07:03:20.963180 2026] [security2:error] [pid 29744:tid 29807] [remote 97.74.87.194:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cmOGINCUUz5GA9YJAXAACcD0"]
[Mon Jul 20 07:03:21.009906 2026] [security2:error] [pid 28702:tid 28955] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmLF4957xPw9VVBnAPAAAAP8"]
[Mon Jul 20 07:03:21.009941 2026] [security2:error] [pid 28702:tid 28955] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmLF4957xPw9VVBnAPAAAAP8"]
[Mon Jul 20 07:03:21.013849 2026] [security2:error] [pid 29744:tid 29905] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/include/"] [unique_id "al4cmOGINCUUz5GA9YJAUgAAAjI"]
[Mon Jul 20 07:03:21.017695 2026] [security2:error] [pid 29744:tid 29992] [client 213.152.161.101:36924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4cmOGINCUUz5GA9YJAYAAAAok"]
[Mon Jul 20 07:03:21.017804 2026] [security2:error] [pid 29744:tid 29992] [client 213.152.161.101:36924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4cmOGINCUUz5GA9YJAYAAAAok"]
[Mon Jul 20 07:03:21.020260 2026] [security2:error] [pid 29744:tid 29960] [client 34.21.41.254:51517] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4cmeGINCUUz5GA9YJAZAAAAmk"]
[Mon Jul 20 07:03:21.086705 2026] [http2:warn] [pid 28702:tid 28868] [client 57.141.18.18:40472] h2_stream(28702-646-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:21.269331 2026] [security2:error] [pid 29744:tid 29959] [client 34.21.41.254:54205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cmeGINCUUz5GA9YJAcAAAAmg"]
[Mon Jul 20 07:03:21.322212 2026] [security2:error] [pid 29744:tid 29886] [client 194.61.41.85:40727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/midnight/admin.php"] [unique_id "al4cmeGINCUUz5GA9YJAcgAAAh8"]
[Mon Jul 20 07:03:21.345520 2026] [security2:error] [pid 28702:tid 28893] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/images/slider/"] [unique_id "al4cmbF4957xPw9VVBnAVAAAAME"]
[Mon Jul 20 07:03:21.372478 2026] [security2:error] [pid 28702:tid 28838] [client 158.173.166.181:64779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cmbF4957xPw9VVBnAVQAAAIo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:03:21.388781 2026] [security2:error] [pid 29744:tid 29799] [remote 97.74.87.194:44782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cmeGINCUUz5GA9YJAeAACVTU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:21.397140 2026] [security2:error] [pid 29744:tid 29938] [client 147.93.171.187:59705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/theme-previews.php"] [unique_id "al4cmeGINCUUz5GA9YJAegAAAlM"], referer: binance.com
[Mon Jul 20 07:03:21.448894 2026] [security2:error] [pid 29744:tid 29973] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAdAACdl0"], referer: https://aleishapenny.ca/2026
[Mon Jul 20 07:03:21.476078 2026] [security2:error] [pid 29744:tid 29967] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAbQAAAnA"]
[Mon Jul 20 07:03:21.476103 2026] [security2:error] [pid 29744:tid 29967] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAbQAAAnA"]
[Mon Jul 20 07:03:21.477268 2026] [security2:error] [pid 29744:tid 29918] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/Assets/"] [unique_id "al4cmeGINCUUz5GA9YJAagAAAj8"]
[Mon Jul 20 07:03:21.521778 2026] [security2:error] [pid 28702:tid 28929] [client 14.225.17.146:58532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4cmbF4957xPw9VVBnATgAAAOU"], referer: https://guidehunting.com/2026
[Mon Jul 20 07:03:21.538370 2026] [security2:error] [pid 29744:tid 29923] [client 34.21.41.254:53474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4cmeGINCUUz5GA9YJAfgAAAkQ"]
[Mon Jul 20 07:03:21.732565 2026] [http2:warn] [pid 29744:tid 29893] [client 57.141.18.8:36186] h2_stream(29744-859-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:21.775951 2026] [security2:error] [pid 29744:tid 29897] [client 34.21.41.254:59209] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cmeGINCUUz5GA9YJAiQAAAio"]
[Mon Jul 20 07:03:21.832191 2026] [security2:error] [pid 29744:tid 29923] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAfQAAAm0"]
[Mon Jul 20 07:03:21.832218 2026] [security2:error] [pid 29744:tid 29923] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAfQAAAm0"]
[Mon Jul 20 07:03:21.870353 2026] [security2:error] [pid 29744:tid 29916] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAhAAAAj0"]
[Mon Jul 20 07:03:21.870383 2026] [security2:error] [pid 29744:tid 29916] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAhAAAAj0"]
[Mon Jul 20 07:03:21.874948 2026] [security2:error] [pid 29744:tid 29995] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/images/stories/"] [unique_id "al4cmeGINCUUz5GA9YJAggAAAow"]
[Mon Jul 20 07:03:21.971596 2026] [http2:warn] [pid 29744:tid 30000] [client 57.141.18.113:56336] h2_stream(29744-861-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:22.014236 2026] [security2:error] [pid 29744:tid 29901] [client 34.21.41.254:56716] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cmuGINCUUz5GA9YJAlQAAAi4"]
[Mon Jul 20 07:03:22.021831 2026] [security2:error] [pid 29744:tid 29963] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cmeGINCUUz5GA9YJAjAAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:22.056872 2026] [security2:error] [pid 29744:tid 29964] [client 194.61.41.70:20991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/kill.php"] [unique_id "al4cmuGINCUUz5GA9YJAmwAAAm0"]
[Mon Jul 20 07:03:22.109318 2026] [security2:error] [pid 28702:tid 28933] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cmbF4957xPw9VVBnAaQAAAOk"]
[Mon Jul 20 07:03:22.136573 2026] [security2:error] [pid 29744:tid 29933] [client 45.157.112.60:29155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cmuGINCUUz5GA9YJAnQAAAk4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:03:22.248862 2026] [http2:warn] [pid 29744:tid 29966] [client 57.141.18.81:61452] h2_stream(29744-863-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:22.249073 2026] [security2:error] [pid 29744:tid 29897] [client 34.21.41.254:56056] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cmuGINCUUz5GA9YJAoAAAAio"]
[Mon Jul 20 07:03:22.287136 2026] [security2:error] [pid 29744:tid 29925] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAmQAAAkY"]
[Mon Jul 20 07:03:22.287160 2026] [security2:error] [pid 29744:tid 29925] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAmQAAAkY"]
[Mon Jul 20 07:03:22.291865 2026] [security2:error] [pid 29744:tid 29911] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/plugins/"] [unique_id "al4cmuGINCUUz5GA9YJAlwAAAjg"]
[Mon Jul 20 07:03:22.373889 2026] [security2:error] [pid 28702:tid 28773] [remote 95.217.78.234:36616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cmrF4957xPw9VVBnAgQAA50U"]
[Mon Jul 20 07:03:22.414607 2026] [security2:error] [pid 28702:tid 28763] [remote 45.90.123.233:46916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cmrF4957xPw9VVBnAgwAA_zs"]
[Mon Jul 20 07:03:22.415259 2026] [security2:error] [pid 29744:tid 29960] [client 14.225.17.146:58525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAogAAAmk"], referer: http://elitetax-mi.com/2026
[Mon Jul 20 07:03:22.512447 2026] [security2:error] [pid 29744:tid 29963] [client 34.21.41.254:58320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cmuGINCUUz5GA9YJAqgAAAmw"]
[Mon Jul 20 07:03:22.612966 2026] [security2:error] [pid 28702:tid 28834] [client 143.244.57.120:53414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "al4cmrF4957xPw9VVBnAjAAAAIY"]
[Mon Jul 20 07:03:22.616436 2026] [security2:error] [pid 28702:tid 28823] [remote 45.90.123.233:46916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cmrF4957xPw9VVBnAjgAAjXc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:03:22.629721 2026] [security2:error] [pid 28702:tid 28726] [remote 95.217.78.234:36616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cmrF4957xPw9VVBnAkAAA0xY"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:22.684818 2026] [security2:error] [pid 28702:tid 28886] [client 14.225.17.146:58544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4cmbF4957xPw9VVBnATwAAALo"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2026
[Mon Jul 20 07:03:22.691222 2026] [security2:error] [pid 29744:tid 29937] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAqQAAAlI"]
[Mon Jul 20 07:03:22.691241 2026] [security2:error] [pid 29744:tid 29937] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAqQAAAlI"]
[Mon Jul 20 07:03:22.696497 2026] [security2:error] [pid 28702:tid 28893] [client 104.234.53.86:49853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4cmrF4957xPw9VVBnAkQAAAME"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:22.697415 2026] [security2:error] [pid 29744:tid 29992] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/php/"] [unique_id "al4cmuGINCUUz5GA9YJApwAAAok"]
[Mon Jul 20 07:03:22.743840 2026] [http2:warn] [pid 29744:tid 29919] [client 57.141.18.29:36132] h2_stream(29744-865-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:22.755950 2026] [security2:error] [pid 28702:tid 28890] [client 34.21.41.254:57258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tallerherbal-com-mx.safe-systems.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cmrF4957xPw9VVBnAkwAAAL4"]
[Mon Jul 20 07:03:22.831023 2026] [security2:error] [pid 29744:tid 29926] [client 194.61.41.62:39897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/worksec.php"] [unique_id "al4cmuGINCUUz5GA9YJAvAAAAkc"]
[Mon Jul 20 07:03:22.899020 2026] [security2:error] [pid 29744:tid 29901] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAugAAAi4"]
[Mon Jul 20 07:03:22.899050 2026] [security2:error] [pid 29744:tid 29901] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAugAAAi4"]
[Mon Jul 20 07:03:22.903943 2026] [autoindex:error] [pid 29744:tid 29899] [client 85.204.70.104:37978] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:22.904527 2026] [security2:error] [pid 29744:tid 29899] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/css/"] [unique_id "al4cmuGINCUUz5GA9YJAvgAAAiw"]
[Mon Jul 20 07:03:23.058349 2026] [security2:error] [pid 28702:tid 28836] [client 13.233.207.33:56474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cm7F4957xPw9VVBnArQAAAIg"]
[Mon Jul 20 07:03:23.058529 2026] [security2:error] [pid 28702:tid 28836] [client 13.233.207.33:56474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cm7F4957xPw9VVBnArQAAAIg"]
[Mon Jul 20 07:03:23.180531 2026] [security2:error] [pid 29744:tid 29960] [client 14.225.17.146:61691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4cmuGINCUUz5GA9YJAwAAAAmk"]
[Mon Jul 20 07:03:23.259258 2026] [security2:error] [pid 29744:tid 29853] [remote 8.217.108.67:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4cm-GINCUUz5GA9YJA6AACMms"]
[Mon Jul 20 07:03:23.260386 2026] [security2:error] [pid 29744:tid 29967] [client 194.180.48.253:34398] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "dollpassionista.com"] [uri "/"] [unique_id "al4cm-GINCUUz5GA9YJA6QAAAnA"]
[Mon Jul 20 07:03:23.370641 2026] [security2:error] [pid 28702:tid 28872] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cm7F4957xPw9VVBnArwAAAKw"]
[Mon Jul 20 07:03:23.370671 2026] [security2:error] [pid 28702:tid 28872] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cm7F4957xPw9VVBnArwAAAKw"]
[Mon Jul 20 07:03:23.374320 2026] [security2:error] [pid 29744:tid 29994] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/themes/twentytwenty/"] [unique_id "al4cm-GINCUUz5GA9YJA2QAAAos"]
[Mon Jul 20 07:03:23.380808 2026] [security2:error] [pid 28702:tid 28847] [client 47.129.222.11:19464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cm7F4957xPw9VVBnAtwAAAJM"]
[Mon Jul 20 07:03:23.580879 2026] [security2:error] [pid 29744:tid 29967] [client 77.110.127.138:62191] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/21/"] [unique_id "al4cm-GINCUUz5GA9YJA8gAAAnA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:23.649652 2026] [security2:error] [pid 29744:tid 29931] [client 98.159.234.160:23935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cm-GINCUUz5GA9YJA9AAAAkw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:03:23.679864 2026] [security2:error] [pid 28702:tid 28848] [client 194.61.41.65:47183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/wp-conflg.php"] [unique_id "al4cm7F4957xPw9VVBnAygAAAJQ"]
[Mon Jul 20 07:03:23.777109 2026] [security2:error] [pid 29744:tid 29854] [remote 8.217.108.67:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4cm-GINCUUz5GA9YJA-wACMmw"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 07:03:23.784519 2026] [security2:error] [pid 28702:tid 28929] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cm7F4957xPw9VVBnAxwAAAOU"]
[Mon Jul 20 07:03:23.784547 2026] [security2:error] [pid 28702:tid 28929] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cm7F4957xPw9VVBnAxwAAAOU"]
[Mon Jul 20 07:03:23.789132 2026] [security2:error] [pid 29744:tid 29933] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/cache/"] [unique_id "al4cm-GINCUUz5GA9YJA7wAAAk4"]
[Mon Jul 20 07:03:23.805553 2026] [http2:warn] [pid 29744:tid 29924] [client 57.141.18.67:49814] h2_stream(29744-871-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:23.886464 2026] [security2:error] [pid 29744:tid 29943] [client 74.208.214.194:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4cm-GINCUUz5GA9YJA_wAAAlg"]
[Mon Jul 20 07:03:23.903312 2026] [security2:error] [pid 29744:tid 29886] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cm-GINCUUz5GA9YJA7gAAAh8"], referer: 1'"3000
[Mon Jul 20 07:03:23.992663 2026] [http2:warn] [pid 28702:tid 28909] [client 57.141.18.52:53054] h2_stream(28702-654-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:24.074889 2026] [autoindex:error] [pid 29744:tid 29901] [client 85.204.70.104:37978] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:24.075419 2026] [security2:error] [pid 29744:tid 29901] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/maint/"] [unique_id "al4cnOGINCUUz5GA9YJBDgAAAi4"]
[Mon Jul 20 07:03:24.243218 2026] [authz_core:error] [pid 29744:tid 29964] [client 85.204.70.104:0] AH01630: client denied by server configuration: /home3/dbnvkfmy/public_html/website_23836bfd/wp-content/plugins/akismet/
[Mon Jul 20 07:03:24.244438 2026] [security2:error] [pid 29744:tid 29964] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnOGINCUUz5GA9YJBFQAAAm0"]
[Mon Jul 20 07:03:24.255215 2026] [security2:error] [pid 29744:tid 29878] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/akismet/"] [unique_id "al4cnOGINCUUz5GA9YJBFAAAAhc"]
[Mon Jul 20 07:03:24.271466 2026] [security2:error] [pid 29744:tid 29912] [client 104.234.53.64:37223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cnOGINCUUz5GA9YJBGgAAAjk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:24.332638 2026] [security2:error] [pid 28702:tid 28957] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/sites/default/files/"] [unique_id "al4cnLF4957xPw9VVBnA3QAAAQE"]
[Mon Jul 20 07:03:24.351307 2026] [security2:error] [pid 29744:tid 29994] [client 77.110.127.138:62195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cnOGINCUUz5GA9YJBHwAAAos"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:24.351399 2026] [security2:error] [pid 29744:tid 29994] [client 77.110.127.138:62195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cnOGINCUUz5GA9YJBHwAAAos"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:24.414661 2026] [security2:error] [pid 29744:tid 29954] [client 194.61.41.65:54507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/core-plugin/include.php"] [unique_id "al4cnOGINCUUz5GA9YJBIwAAAmM"]
[Mon Jul 20 07:03:24.478732 2026] [autoindex:error] [pid 28702:tid 28870] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:24.479189 2026] [security2:error] [pid 28702:tid 28870] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnLF4957xPw9VVBnA5AAAAKo"]
[Mon Jul 20 07:03:24.481583 2026] [security2:error] [pid 29744:tid 29939] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/assets/"] [unique_id "al4cnOGINCUUz5GA9YJBKAAAAlQ"]
[Mon Jul 20 07:03:24.578339 2026] [security2:error] [pid 29744:tid 29994] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cnOGINCUUz5GA9YJBLAAAAos"]
[Mon Jul 20 07:03:24.578375 2026] [security2:error] [pid 29744:tid 29994] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cnOGINCUUz5GA9YJBLAAAAos"]
[Mon Jul 20 07:03:24.605134 2026] [security2:error] [pid 29744:tid 29910] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cnOGINCUUz5GA9YJBKQAAAjc"]
[Mon Jul 20 07:03:24.684804 2026] [autoindex:error] [pid 28702:tid 28945] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:24.685290 2026] [security2:error] [pid 28702:tid 28945] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnLF4957xPw9VVBnA7QAAAPU"]
[Mon Jul 20 07:03:24.687673 2026] [security2:error] [pid 29744:tid 29923] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/block-patterns/"] [unique_id "al4cnOGINCUUz5GA9YJBMAAAAkQ"]
[Mon Jul 20 07:03:24.723011 2026] [security2:error] [pid 29744:tid 29951] [client 18.142.226.106:50630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4cnOGINCUUz5GA9YJBMgAAAmA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:03:24.813318 2026] [http2:warn] [pid 29744:tid 29976] [client 57.141.18.76:58564] h2_stream(29744-880-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:24.814939 2026] [security2:error] [pid 29744:tid 29835] [remote 8.217.108.67:55314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cnOGINCUUz5GA9YJBNAACUlk"]
[Mon Jul 20 07:03:24.850066 2026] [security2:error] [pid 28702:tid 28926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cnLF4957xPw9VVBnA2gAAAOI"], referer: 1'"3000
[Mon Jul 20 07:03:24.854209 2026] [security2:error] [pid 28702:tid 28719] [remote 192.241.143.148:38178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4cnLF4957xPw9VVBnA-AAA3w8"]
[Mon Jul 20 07:03:24.855935 2026] [autoindex:error] [pid 28702:tid 28906] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:24.856367 2026] [security2:error] [pid 28702:tid 28906] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnLF4957xPw9VVBnA9gAAAM4"]
[Mon Jul 20 07:03:24.877626 2026] [security2:error] [pid 29744:tid 29960] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/block-supports/"] [unique_id "al4cnOGINCUUz5GA9YJBOAAAAmk"]
[Mon Jul 20 07:03:25.037239 2026] [security2:error] [pid 29744:tid 29910] [client 147.93.171.187:64271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/theme-templates.php"] [unique_id "al4cneGINCUUz5GA9YJBSQAAAjc"], referer: binance.com
[Mon Jul 20 07:03:25.042706 2026] [security2:error] [pid 28702:tid 28708] [remote 192.241.143.148:38178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4cnbF4957xPw9VVBnA_QAA3AQ"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 07:03:25.064540 2026] [autoindex:error] [pid 28702:tid 28872] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:25.065146 2026] [security2:error] [pid 28702:tid 28872] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnbF4957xPw9VVBnA_gAAAKw"]
[Mon Jul 20 07:03:25.066496 2026] [security2:error] [pid 29744:tid 29886] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/html-api/"] [unique_id "al4cneGINCUUz5GA9YJBSgAAAh8"]
[Mon Jul 20 07:03:25.155824 2026] [security2:error] [pid 28702:tid 28847] [client 194.61.41.242:44257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/envato-css.php"] [unique_id "al4cnbF4957xPw9VVBnBAQAAAJM"]
[Mon Jul 20 07:03:25.238028 2026] [security2:error] [pid 29744:tid 29779] [remote 57.141.18.50:48122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cQ-GINCUUz5GA9YIs2wACUCE"]
[Mon Jul 20 07:03:25.263867 2026] [autoindex:error] [pid 29744:tid 29908] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:25.264627 2026] [security2:error] [pid 29744:tid 29908] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cneGINCUUz5GA9YJBVwAAAjU"]
[Mon Jul 20 07:03:25.266029 2026] [security2:error] [pid 29744:tid 29937] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/js/"] [unique_id "al4cneGINCUUz5GA9YJBVQAAAlI"]
[Mon Jul 20 07:03:25.287481 2026] [security2:error] [pid 28702:tid 28836] [client 158.173.89.95:43975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cnbF4957xPw9VVBnBBQAAAIg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:03:25.324736 2026] [security2:error] [pid 28702:tid 28936] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/controller/extension/extension/"] [unique_id "al4cnbF4957xPw9VVBnBBwAAAOw"]
[Mon Jul 20 07:03:25.371792 2026] [security2:error] [pid 29744:tid 29960] [client 114.119.145.56:22437] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "3dprintrecycling.com"] [uri "/robots.txt"] [unique_id "al4cneGINCUUz5GA9YJBWQAAAmk"], referer: https://3dprintrecycling.com/robots.txt
[Mon Jul 20 07:03:25.384348 2026] [security2:error] [pid 29744:tid 29767] [remote 8.217.108.67:55314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cneGINCUUz5GA9YJBWgACYBU"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:25.395322 2026] [security2:error] [pid 28702:tid 28886] [client 117.247.108.24:156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cnbF4957xPw9VVBnBCwAAALo"]
[Mon Jul 20 07:03:25.395404 2026] [security2:error] [pid 28702:tid 28886] [client 117.247.108.24:156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cnbF4957xPw9VVBnBCwAAALo"]
[Mon Jul 20 07:03:25.485238 2026] [autoindex:error] [pid 28702:tid 28844] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/php-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:25.485663 2026] [security2:error] [pid 28702:tid 28844] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnbF4957xPw9VVBnBEAAAAJA"]
[Mon Jul 20 07:03:25.488022 2026] [security2:error] [pid 29744:tid 29923] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/php-compat/"] [unique_id "al4cneGINCUUz5GA9YJBXAAAAkQ"]
[Mon Jul 20 07:03:25.549419 2026] [http2:warn] [pid 28702:tid 28954] [client 57.141.18.125:56408] h2_stream(28702-661-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:25.571614 2026] [security2:error] [pid 29744:tid 29931] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cneGINCUUz5GA9YJBXQAAAkw"]
[Mon Jul 20 07:03:25.571646 2026] [security2:error] [pid 29744:tid 29931] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cneGINCUUz5GA9YJBXQAAAkw"]
[Mon Jul 20 07:03:25.593637 2026] [security2:error] [pid 29744:tid 29939] [client 14.225.17.146:59075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4cneGINCUUz5GA9YJBXgAAAlQ"], referer: http://mcg.homes/2026
[Mon Jul 20 07:03:25.664832 2026] [autoindex:error] [pid 29744:tid 29934] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:25.665387 2026] [security2:error] [pid 29744:tid 29934] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cneGINCUUz5GA9YJBaQAAAk8"]
[Mon Jul 20 07:03:25.674575 2026] [security2:error] [pid 29744:tid 29964] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/PHPMailer/"] [unique_id "al4cneGINCUUz5GA9YJBZQAAAm0"]
[Mon Jul 20 07:03:25.866498 2026] [autoindex:error] [pid 29744:tid 29946] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:25.867251 2026] [security2:error] [pid 29744:tid 29946] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cneGINCUUz5GA9YJBcwAAAls"]
[Mon Jul 20 07:03:25.869635 2026] [security2:error] [pid 29744:tid 29999] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/pomo/"] [unique_id "al4cneGINCUUz5GA9YJBcQAAApA"]
[Mon Jul 20 07:03:25.970209 2026] [security2:error] [pid 29744:tid 29938] [client 194.61.41.78:45105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/classwithtostring.php"] [unique_id "al4cneGINCUUz5GA9YJBdwAAAlM"]
[Mon Jul 20 07:03:25.972919 2026] [security2:error] [pid 28702:tid 28955] [client 117.222.139.248:51999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cnbF4957xPw9VVBnBJwAAAP8"]
[Mon Jul 20 07:03:25.973051 2026] [security2:error] [pid 28702:tid 28955] [client 117.222.139.248:51999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cnbF4957xPw9VVBnBJwAAAP8"]
[Mon Jul 20 07:03:26.045756 2026] [security2:error] [pid 28702:tid 28873] [client 14.225.17.146:58854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4cnLF4957xPw9VVBnA7AAAAK0"]
[Mon Jul 20 07:03:26.241772 2026] [http2:warn] [pid 29744:tid 29948] [client 57.141.18.62:38948] h2_stream(29744-888-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:26.312111 2026] [security2:error] [pid 29744:tid 29951] [client 14.182.195.220:52497] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cnuGINCUUz5GA9YJBiQAAAmA"]
[Mon Jul 20 07:03:26.332249 2026] [security2:error] [pid 29744:tid 29838] [remote 57.141.18.28:61676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5735655"] [unique_id "al4cnuGINCUUz5GA9YJBjAACbVw"]
[Mon Jul 20 07:03:26.333672 2026] [security2:error] [pid 29744:tid 29959] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cnuGINCUUz5GA9YJBewAAAmg"]
[Mon Jul 20 07:03:26.333694 2026] [security2:error] [pid 29744:tid 29959] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cnuGINCUUz5GA9YJBewAAAmg"]
[Mon Jul 20 07:03:26.336999 2026] [security2:error] [pid 29744:tid 29910] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/random_compat/"] [unique_id "al4cnuGINCUUz5GA9YJBeQAAAjc"]
[Mon Jul 20 07:03:26.373295 2026] [security2:error] [pid 29744:tid 29994] [client 14.225.17.146:59665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4cneGINCUUz5GA9YJBTwAAAos"], referer: http://sarahholyfield.com/2026
[Mon Jul 20 07:03:26.557732 2026] [autoindex:error] [pid 29744:tid 29958] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:26.558261 2026] [security2:error] [pid 29744:tid 29958] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnuGINCUUz5GA9YJBkwAAAmc"]
[Mon Jul 20 07:03:26.559490 2026] [security2:error] [pid 29744:tid 29897] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/rest-api/"] [unique_id "al4cnuGINCUUz5GA9YJBkgAAAio"]
[Mon Jul 20 07:03:26.687694 2026] [security2:error] [pid 28702:tid 28834] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "al4cnrF4957xPw9VVBnBSAAAAIY"]
[Mon Jul 20 07:03:26.709661 2026] [http2:warn] [pid 29744:tid 30001] [client 57.141.18.5:24088] h2_stream(29744-894-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:26.747420 2026] [security2:error] [pid 28702:tid 28900] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cnrF4957xPw9VVBnBLQAAAMg"], referer: 1'"3000
[Mon Jul 20 07:03:26.769234 2026] [autoindex:error] [pid 29744:tid 29916] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:26.770166 2026] [security2:error] [pid 29744:tid 29916] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnuGINCUUz5GA9YJBnAAAAj0"]
[Mon Jul 20 07:03:26.772029 2026] [security2:error] [pid 29744:tid 29934] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/sitemaps/"] [unique_id "al4cnuGINCUUz5GA9YJBmQAAAk8"]
[Mon Jul 20 07:03:26.946303 2026] [security2:error] [pid 28702:tid 28874] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4cnrF4957xPw9VVBnBSwAAAK4"]
[Mon Jul 20 07:03:26.969465 2026] [autoindex:error] [pid 29744:tid 29998] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:26.969967 2026] [security2:error] [pid 29744:tid 29998] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cnuGINCUUz5GA9YJBowAAAo8"]
[Mon Jul 20 07:03:26.975013 2026] [security2:error] [pid 29744:tid 29995] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4cnuGINCUUz5GA9YJBoQAAAow"]
[Mon Jul 20 07:03:27.025846 2026] [security2:error] [pid 28702:tid 28846] [client 192.140.149.97:44492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cn7F4957xPw9VVBnBXQAAAJI"]
[Mon Jul 20 07:03:27.026059 2026] [security2:error] [pid 28702:tid 28846] [client 192.140.149.97:44492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cn7F4957xPw9VVBnBXQAAAJI"]
[Mon Jul 20 07:03:27.041368 2026] [security2:error] [pid 29744:tid 29993] [client 14.225.17.146:56554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4cnuGINCUUz5GA9YJBkAAAAoo"], referer: http://idigress.studio/2026
[Mon Jul 20 07:03:27.147647 2026] [autoindex:error] [pid 29744:tid 29963] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:27.148172 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cn-GINCUUz5GA9YJBsAAAAmw"]
[Mon Jul 20 07:03:27.149685 2026] [security2:error] [pid 29744:tid 29968] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/style-engine/"] [unique_id "al4cn-GINCUUz5GA9YJBrQAAAnE"]
[Mon Jul 20 07:03:27.200907 2026] [security2:error] [pid 29744:tid 29994] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cn-GINCUUz5GA9YJBrwAAAos"]
[Mon Jul 20 07:03:27.200938 2026] [security2:error] [pid 29744:tid 29994] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cn-GINCUUz5GA9YJBrwAAAos"]
[Mon Jul 20 07:03:27.228194 2026] [security2:error] [pid 28702:tid 28899] [client 103.144.65.217:62754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cn7F4957xPw9VVBnBZQAAAMc"]
[Mon Jul 20 07:03:27.228311 2026] [security2:error] [pid 28702:tid 28899] [client 103.144.65.217:62754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cn7F4957xPw9VVBnBZQAAAMc"]
[Mon Jul 20 07:03:27.286410 2026] [http2:warn] [pid 28702:tid 28892] [client 57.141.18.23:40730] h2_stream(28702-664-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:27.320985 2026] [security2:error] [pid 28702:tid 28873] [client 137.184.184.209:35390] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://"] [hostname "elitetax-mi.com"] [uri "/wp-json/batch/v1"] [unique_id "al4cn7F4957xPw9VVBnBZAAAAK0"]
[Mon Jul 20 07:03:27.365877 2026] [security2:error] [pid 29744:tid 29808] [remote 173.249.4.11:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4cn-GINCUUz5GA9YJBuwACGj4"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:03:27.382212 2026] [autoindex:error] [pid 28702:tid 28842] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:27.382970 2026] [security2:error] [pid 28702:tid 28842] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cn7F4957xPw9VVBnBawAAAI4"]
[Mon Jul 20 07:03:27.385395 2026] [security2:error] [pid 29744:tid 29946] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/theme-compat/"] [unique_id "al4cn-GINCUUz5GA9YJBugAAAls"]
[Mon Jul 20 07:03:27.389959 2026] [security2:error] [pid 29744:tid 29910] [client 46.110.96.34:9680] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4cn-GINCUUz5GA9YJBvAAAAjc"]
[Mon Jul 20 07:03:27.437308 2026] [security2:error] [pid 29744:tid 29940] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cn-GINCUUz5GA9YJBtAAAAlU"], referer: 1'"3000
[Mon Jul 20 07:03:27.489124 2026] [http2:warn] [pid 29744:tid 29989] [client 57.141.18.64:57358] h2_stream(29744-897-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:27.552226 2026] [autoindex:error] [pid 29744:tid 29934] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:27.552733 2026] [security2:error] [pid 29744:tid 29934] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cn-GINCUUz5GA9YJBxAAAAk8"]
[Mon Jul 20 07:03:27.555059 2026] [security2:error] [pid 29744:tid 29935] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-includes/widgets/"] [unique_id "al4cn-GINCUUz5GA9YJBwQAAAlA"]
[Mon Jul 20 07:03:27.581333 2026] [security2:error] [pid 28702:tid 28881] [client 14.225.17.146:59777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4cnrF4957xPw9VVBnBKQAAALU"], referer: http://reosportsboats.com/2026
[Mon Jul 20 07:03:27.623316 2026] [security2:error] [pid 29744:tid 29759] [remote 173.249.4.11:40370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4cn-GINCUUz5GA9YJByAACNw0"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:03:27.742193 2026] [security2:error] [pid 28702:tid 28801] [remote 202.51.202.242:40752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4cn7F4957xPw9VVBnBcwAA1GE"]
[Mon Jul 20 07:03:27.799968 2026] [autoindex:error] [pid 29744:tid 29963] [client 85.204.70.104:37978] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-admin/css/colors/ectoplasm/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:27.800460 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/css/colors/ectoplasm/"] [unique_id "al4cn-GINCUUz5GA9YJB1wAAAmw"]
[Mon Jul 20 07:03:27.845397 2026] [security2:error] [pid 29744:tid 29923] [client 194.61.41.241:59585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/index/function.php"] [unique_id "al4cn-GINCUUz5GA9YJB3QAAAkQ"]
[Mon Jul 20 07:03:27.981186 2026] [security2:error] [pid 29744:tid 29934] [client 104.207.52.140:46761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cn-GINCUUz5GA9YJB3gAAAk8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:28.017377 2026] [autoindex:error] [pid 29744:tid 29906] [client 85.204.70.104:37978] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:28.017914 2026] [security2:error] [pid 29744:tid 29906] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/css/colors/"] [unique_id "al4cn-GINCUUz5GA9YJB3wAAAjM"]
[Mon Jul 20 07:03:28.051557 2026] [security2:error] [pid 28702:tid 28949] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cn7F4957xPw9VVBnBZgAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:28.136325 2026] [security2:error] [pid 28702:tid 28882] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/components/"] [unique_id "al4coLF4957xPw9VVBnBeQAAALY"]
[Mon Jul 20 07:03:28.194394 2026] [security2:error] [pid 29744:tid 29899] [client 14.251.3.155:54879] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4coOGINCUUz5GA9YJB6gAAAiw"]
[Mon Jul 20 07:03:28.237711 2026] [security2:error] [pid 29744:tid 29999] [client 183.82.98.154:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4coOGINCUUz5GA9YJB7gAAApA"]
[Mon Jul 20 07:03:28.237857 2026] [security2:error] [pid 29744:tid 29999] [client 183.82.98.154:55740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4coOGINCUUz5GA9YJB7gAAApA"]
[Mon Jul 20 07:03:28.260348 2026] [security2:error] [pid 28702:tid 28861] [client 147.93.171.187:49249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/utf8.php"] [unique_id "al4coLF4957xPw9VVBnBfQAAAKE"], referer: binance.com
[Mon Jul 20 07:03:28.363238 2026] [security2:error] [pid 29744:tid 29940] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4coOGINCUUz5GA9YJB8AAAAlU"]
[Mon Jul 20 07:03:28.363268 2026] [security2:error] [pid 29744:tid 29940] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4coOGINCUUz5GA9YJB8AAAAlU"]
[Mon Jul 20 07:03:28.403166 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4coOGINCUUz5GA9YJB6AAAAmw"]
[Mon Jul 20 07:03:28.403193 2026] [security2:error] [pid 29744:tid 29963] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4coOGINCUUz5GA9YJB6AAAAmw"]
[Mon Jul 20 07:03:28.422411 2026] [security2:error] [pid 29744:tid 29935] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/admin/images/slider/"] [unique_id "al4coOGINCUUz5GA9YJB5QAAAlA"]
[Mon Jul 20 07:03:28.432975 2026] [security2:error] [pid 29744:tid 29746] [remote 97.74.93.24:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4coOGINCUUz5GA9YJB8gACNQA"]
[Mon Jul 20 07:03:28.541951 2026] [security2:error] [pid 28702:tid 28927] [client 14.225.17.146:55399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4coLF4957xPw9VVBnBiQAAAOM"], referer: https://reosportsboats.com/2026
[Mon Jul 20 07:03:28.623351 2026] [security2:error] [pid 29744:tid 29802] [remote 103.118.29.185:50390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4coOGINCUUz5GA9YJB_wACaTg"]
[Mon Jul 20 07:03:28.653115 2026] [security2:error] [pid 28702:tid 28858] [client 194.61.41.243:33311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/tinyfilemanager.php"] [unique_id "al4coLF4957xPw9VVBnBlwAAAJ4"]
[Mon Jul 20 07:03:28.658601 2026] [http2:warn] [pid 28702:tid 28860] [client 57.141.18.107:47206] h2_stream(28702-666-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:28.783758 2026] [security2:error] [pid 28702:tid 28748] [remote 20.153.140.50:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4coLF4957xPw9VVBnBngAAtCw"]
[Mon Jul 20 07:03:28.815051 2026] [security2:error] [pid 28702:tid 28873] [client 114.119.132.114:29491] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jndsupport.com"] [uri "/category/cybersecurity/t%3Cbr%3Eel:18882883007"] [unique_id "al4coLF4957xPw9VVBnBoQAAAK0"], referer: https://jndsupport.com/category/cybersecurity/
[Mon Jul 20 07:03:28.849637 2026] [security2:error] [pid 29744:tid 29758] [remote 97.74.93.24:50304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4coOGINCUUz5GA9YJCCgACRAw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:03:28.852603 2026] [security2:error] [pid 28702:tid 28758] [remote 57.141.18.34:43026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6417944"] [unique_id "al4coLF4957xPw9VVBnBpAAA3zY"]
[Mon Jul 20 07:03:28.916085 2026] [security2:error] [pid 28702:tid 28881] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4coLF4957xPw9VVBnBmQAAALU"]
[Mon Jul 20 07:03:28.916107 2026] [security2:error] [pid 28702:tid 28881] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4coLF4957xPw9VVBnBmQAAALU"]
[Mon Jul 20 07:03:28.921856 2026] [security2:error] [pid 29744:tid 29943] [client 85.204.70.104:37978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/admin/fckeditor/editor/filemanager/"] [unique_id "al4coOGINCUUz5GA9YJCAAAAAlg"]
[Mon Jul 20 07:03:28.997950 2026] [http2:warn] [pid 29744:tid 29985] [client 57.141.18.17:64958] h2_stream(29744-915-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:29.037460 2026] [security2:error] [pid 29744:tid 29770] [remote 103.118.29.185:50390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4coeGINCUUz5GA9YJCFAACixg"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 07:03:29.193118 2026] [security2:error] [pid 28702:tid 28729] [remote 20.153.140.50:58364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cobF4957xPw9VVBnBrQAApRk"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:03:29.229488 2026] [security2:error] [pid 28702:tid 28804] [remote 57.141.18.58:61130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cQ7F4957xPw9VVBm0YQAAs2Q"]
[Mon Jul 20 07:03:29.243394 2026] [security2:error] [pid 28702:tid 28835] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/admin/uploads/images/"] [unique_id "al4cobF4957xPw9VVBnBsAAAAIc"]
[Mon Jul 20 07:03:29.284246 2026] [security2:error] [pid 28702:tid 28741] [remote 202.51.202.242:40752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4cobF4957xPw9VVBnBsQAA3CU"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:03:29.325744 2026] [security2:error] [pid 29744:tid 29903] [client 104.234.53.76:53715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4coeGINCUUz5GA9YJCJwAAAjA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:29.363309 2026] [security2:error] [pid 28702:tid 28927] [client 50.116.65.227:60832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cobF4957xPw9VVBnBvAAAAOM"]
[Mon Jul 20 07:03:29.371095 2026] [security2:error] [pid 28702:tid 28866] [client 77.110.127.138:62224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/21/"] [unique_id "al4cobF4957xPw9VVBnBvQAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:29.373480 2026] [security2:error] [pid 28702:tid 28938] [client 50.116.65.227:60842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cobF4957xPw9VVBnBvgAAAO4"]
[Mon Jul 20 07:03:29.383498 2026] [security2:error] [pid 29744:tid 29906] [client 66.249.75.103:39717] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "quangminhltd.vn"] [uri "/robots.txt"] [unique_id "al4coeGINCUUz5GA9YJCLgAAAjM"]
[Mon Jul 20 07:03:29.418263 2026] [ssl:error] [pid 29744:tid 29905] [client 104.48.69.105:42612] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:03:29.442410 2026] [security2:error] [pid 28702:tid 28894] [client 194.61.41.56:40891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/bas.php"] [unique_id "al4cobF4957xPw9VVBnBwAAAAMI"]
[Mon Jul 20 07:03:29.464918 2026] [security2:error] [pid 29744:tid 29964] [client 143.244.57.120:45604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4coeGINCUUz5GA9YJCMwAAAm0"]
[Mon Jul 20 07:03:29.464951 2026] [security2:error] [pid 29744:tid 29964] [client 143.244.57.120:45604] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4coeGINCUUz5GA9YJCMwAAAm0"]
[Mon Jul 20 07:03:29.519155 2026] [proxy:error] [pid 29744:tid 29923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:03:29.519246 2026] [proxy_http:error] [pid 29744:tid 29923] [client 82.102.18.116:54850] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:03:29.519789 2026] [proxy:error] [pid 29744:tid 29923] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:03:29.519820 2026] [proxy_http:error] [pid 29744:tid 29923] [client 82.102.18.116:54850] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:03:29.564896 2026] [security2:error] [pid 28702:tid 28867] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cobF4957xPw9VVBnBtwAAAKc"], referer: 1'"3000
[Mon Jul 20 07:03:29.611642 2026] [security2:error] [pid 29744:tid 29974] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4coeGINCUUz5GA9YJCMgAAAnc"]
[Mon Jul 20 07:03:29.611676 2026] [security2:error] [pid 29744:tid 29974] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4coeGINCUUz5GA9YJCMgAAAnc"]
[Mon Jul 20 07:03:29.633470 2026] [security2:error] [pid 29744:tid 29980] [client 85.204.70.104:59902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/sites/default/files/"] [unique_id "al4coeGINCUUz5GA9YJCLwAAAn0"]
[Mon Jul 20 07:03:29.862802 2026] [proxy:error] [pid 28702:tid 28904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:03:29.862899 2026] [proxy_http:error] [pid 28702:tid 28904] [client 82.102.18.116:54852] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:03:29.863602 2026] [proxy:error] [pid 28702:tid 28904] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:03:29.863646 2026] [proxy_http:error] [pid 28702:tid 28904] [client 82.102.18.116:54852] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:03:29.872539 2026] [security2:error] [pid 29744:tid 29992] [client 14.225.17.146:65046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4coOGINCUUz5GA9YJCCAAAAok"], referer: http://laceycaraccident.com/2026
[Mon Jul 20 07:03:29.922385 2026] [security2:error] [pid 29744:tid 29982] [client 50.116.65.227:60870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4coeGINCUUz5GA9YJCRAAAAn8"]
[Mon Jul 20 07:03:30.118855 2026] [security2:error] [pid 29744:tid 29935] [client 50.116.65.227:60894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4coeGINCUUz5GA9YJCSQAAAlA"]
[Mon Jul 20 07:03:30.198182 2026] [security2:error] [pid 28702:tid 28934] [client 82.102.18.116:54864] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4corF4957xPw9VVBnB4gAAAOo"]
[Mon Jul 20 07:03:30.203243 2026] [security2:error] [pid 29744:tid 29912] [client 77.110.127.138:62229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4couGINCUUz5GA9YJCUAAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:30.203334 2026] [security2:error] [pid 29744:tid 29912] [client 77.110.127.138:62229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4couGINCUUz5GA9YJCUAAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:30.239531 2026] [security2:error] [pid 28702:tid 28835] [client 194.61.41.100:21035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/moon.php"] [unique_id "al4corF4957xPw9VVBnB4wAAAIc"]
[Mon Jul 20 07:03:30.273411 2026] [security2:error] [pid 28702:tid 28870] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cobF4957xPw9VVBnB2gAAAKo"], referer: 1'"3000
[Mon Jul 20 07:03:30.309671 2026] [http2:warn] [pid 29744:tid 29920] [client 57.141.18.39:42987] h2_stream(29744-925-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:30.314078 2026] [security2:error] [pid 29744:tid 29881] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4couGINCUUz5GA9YJCTQAAAho"]
[Mon Jul 20 07:03:30.314096 2026] [security2:error] [pid 29744:tid 29881] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4couGINCUUz5GA9YJCTQAAAho"]
[Mon Jul 20 07:03:30.315173 2026] [security2:error] [pid 29744:tid 29993] [client 85.204.70.104:59902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/admin/controller/extension/extension/"] [unique_id "al4couGINCUUz5GA9YJCSwAAAoo"]
[Mon Jul 20 07:03:30.404042 2026] [security2:error] [pid 28702:tid 28867] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "al4corF4957xPw9VVBnB-QAAAKc"]
[Mon Jul 20 07:03:30.445229 2026] [http2:warn] [pid 29744:tid 29961] [client 57.141.18.54:51500] h2_stream(29744-926-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:30.451237 2026] [http2:warn] [pid 28702:tid 28943] [client 57.141.18.7:52634] h2_stream(28702-671-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:30.531193 2026] [security2:error] [pid 28702:tid 28881] [client 82.102.18.116:54866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCAwAAALU"]
[Mon Jul 20 07:03:30.575019 2026] [security2:error] [pid 28702:tid 28738] [remote 95.217.78.234:34502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCBgABBCI"]
[Mon Jul 20 07:03:30.575146 2026] [security2:error] [pid 28702:tid 28960] [client 95.217.78.234:34502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCBgABBCI"]
[Mon Jul 20 07:03:30.581159 2026] [security2:error] [pid 28702:tid 28918] [client 154.208.48.130:51137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCCAAAANo"]
[Mon Jul 20 07:03:30.581288 2026] [security2:error] [pid 28702:tid 28918] [client 154.208.48.130:51137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCCAAAANo"]
[Mon Jul 20 07:03:30.863938 2026] [proxy:error] [pid 28702:tid 28838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:03:30.864339 2026] [proxy_http:error] [pid 28702:tid 28838] [client 82.102.18.116:54872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:03:30.865169 2026] [proxy:error] [pid 28702:tid 28838] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:03:30.865203 2026] [proxy_http:error] [pid 28702:tid 28838] [client 82.102.18.116:54872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:03:30.885195 2026] [security2:error] [pid 28702:tid 28882] [client 187.16.64.216:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCHQAAALY"]
[Mon Jul 20 07:03:30.885306 2026] [security2:error] [pid 28702:tid 28882] [client 187.16.64.216:55233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4corF4957xPw9VVBnCHQAAALY"]
[Mon Jul 20 07:03:31.012277 2026] [security2:error] [pid 28702:tid 28941] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4corF4957xPw9VVBnCEAAAAPE"]
[Mon Jul 20 07:03:31.012306 2026] [security2:error] [pid 28702:tid 28941] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4corF4957xPw9VVBnCEAAAAPE"]
[Mon Jul 20 07:03:31.018326 2026] [security2:error] [pid 28702:tid 28953] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/"] [unique_id "al4corF4957xPw9VVBnCDgAAAP0"]
[Mon Jul 20 07:03:31.084885 2026] [security2:error] [pid 28702:tid 28863] [client 194.61.41.249:23273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/file.php"] [unique_id "al4co7F4957xPw9VVBnCLQAAAKM"]
[Mon Jul 20 07:03:31.148458 2026] [security2:error] [pid 28702:tid 28960] [client 185.242.177.19:40566] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "mail.elementalkneads.com"] [uri "/"] [unique_id "al4co7F4957xPw9VVBnCMAAAAQQ"]
[Mon Jul 20 07:03:31.185072 2026] [security2:error] [pid 28702:tid 28918] [client 82.102.18.116:54884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4co7F4957xPw9VVBnCMQAAANo"]
[Mon Jul 20 07:03:31.276933 2026] [security2:error] [pid 28702:tid 28861] [client 147.93.171.187:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/view-transitions.php"] [unique_id "al4co7F4957xPw9VVBnCNQAAAKE"], referer: binance.com
[Mon Jul 20 07:03:31.510839 2026] [security2:error] [pid 28702:tid 28859] [client 82.102.18.116:65278] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4co7F4957xPw9VVBnCSwAAAJ8"]
[Mon Jul 20 07:03:31.563449 2026] [security2:error] [pid 28702:tid 28923] [client 65.111.23.13:35471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4co7F4957xPw9VVBnCTwAAAN8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:31.600319 2026] [security2:error] [pid 28702:tid 28942] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCMwAAAMk"]
[Mon Jul 20 07:03:31.600352 2026] [security2:error] [pid 28702:tid 28942] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCMwAAAMk"]
[Mon Jul 20 07:03:31.648212 2026] [security2:error] [pid 28702:tid 28911] [client 122.183.32.225:17757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4co7F4957xPw9VVBnCVAAAANM"]
[Mon Jul 20 07:03:31.652009 2026] [http2:warn] [pid 29744:tid 29883] [client 57.141.18.87:21086] h2_stream(29744-935-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:31.662497 2026] [security2:error] [pid 28702:tid 28911] [client 122.183.32.225:17757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4co7F4957xPw9VVBnCVAAAANM"]
[Mon Jul 20 07:03:31.673343 2026] [security2:error] [pid 28702:tid 28857] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCQAAAAJ0"]
[Mon Jul 20 07:03:31.673373 2026] [security2:error] [pid 28702:tid 28857] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCQAAAAJ0"]
[Mon Jul 20 07:03:31.675554 2026] [security2:error] [pid 28702:tid 28844] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/components/"] [unique_id "al4co7F4957xPw9VVBnCPgAAAJA"]
[Mon Jul 20 07:03:31.761676 2026] [security2:error] [pid 28702:tid 28908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCSgAAANA"], referer: 1'"3000
[Mon Jul 20 07:03:31.825846 2026] [security2:error] [pid 28702:tid 28861] [client 194.61.41.242:49515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/index.php"] [unique_id "al4co7F4957xPw9VVBnCZAAAAKE"]
[Mon Jul 20 07:03:31.859855 2026] [security2:error] [pid 28702:tid 28893] [client 82.102.18.116:54894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4co7F4957xPw9VVBnCaQAAAME"]
[Mon Jul 20 07:03:31.925984 2026] [http2:info] [pid 45040:tid 45040] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:03:31.948257 2026] [security2:error] [pid 28702:tid 28953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCXwAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:32.007197 2026] [http2:warn] [pid 29744:tid 29944] [client 57.141.18.98:25678] h2_stream(29744-940-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:32.053353 2026] [autoindex:error] [pid 28702:tid 28941] [client 44.201.152.248:40044] AH01276: Cannot serve directory /home3/vergotek/vergotek.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:32.053869 2026] [http2:warn] [pid 28702:tid 28956] [client 57.141.18.82:64926] h2_stream(28702-676-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:32.058899 2026] [security2:error] [pid 28702:tid 28958] [client 14.225.17.146:61545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4corF4957xPw9VVBnB3wAAAQI"], referer: http://nwcarvingacademy.com/2026
[Mon Jul 20 07:03:32.093409 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCaAAAAOQ"]
[Mon Jul 20 07:03:32.093444 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCaAAAAOQ"]
[Mon Jul 20 07:03:32.100175 2026] [security2:error] [pid 28702:tid 28931] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/admin/uploads/images/"] [unique_id "al4co7F4957xPw9VVBnCZgAAAOc"]
[Mon Jul 20 07:03:32.109794 2026] [security2:error] [pid 28702:tid 28890] [client 45.3.54.175:51487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cpLF4957xPw9VVBnChAAAAL4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:32.122158 2026] [security2:error] [pid 28702:tid 28912] [client 14.225.17.146:53610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4co7F4957xPw9VVBnCXgAAANQ"], referer: http://maxenengineering.com/2026
[Mon Jul 20 07:03:32.182606 2026] [security2:error] [pid 45040:tid 45190] [client 82.102.18.116:54910] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4cpLEFnm79ltp0SFAxHQAAABI"]
[Mon Jul 20 07:03:32.397442 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/21/"] [unique_id "al4cpLEFnm79ltp0SFAxIQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:32.402051 2026] [security2:error] [pid 45040:tid 45042] [remote 124.55.178.99:40474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cpLEFnm79ltp0SFAxIAAABAE"]
[Mon Jul 20 07:03:32.470596 2026] [security2:error] [pid 28702:tid 28937] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cpLF4957xPw9VVBnCggAAAO0"], referer: 1'"3000
[Mon Jul 20 07:03:32.499471 2026] [security2:error] [pid 45040:tid 45192] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpLEFnm79ltp0SFAxHgAAABQ"]
[Mon Jul 20 07:03:32.499498 2026] [security2:error] [pid 45040:tid 45192] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpLEFnm79ltp0SFAxHgAAABQ"]
[Mon Jul 20 07:03:32.505279 2026] [security2:error] [pid 28702:tid 28878] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/classic-editor/"] [unique_id "al4cpLF4957xPw9VVBnCigAAALI"]
[Mon Jul 20 07:03:32.530588 2026] [security2:error] [pid 28702:tid 28885] [client 82.102.18.116:54914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4cpLF4957xPw9VVBnCmQAAALk"]
[Mon Jul 20 07:03:32.555297 2026] [security2:error] [pid 28702:tid 28918] [client 194.61.41.71:22781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/upgrade/item.php"] [unique_id "al4cpLF4957xPw9VVBnCnQAAANo"]
[Mon Jul 20 07:03:32.726813 2026] [security2:error] [pid 28702:tid 28880] [client 65.111.22.56:35219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cpLF4957xPw9VVBnCpwAAALQ"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:32.824414 2026] [security2:error] [pid 45040:tid 45043] [remote 124.55.178.99:40474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cpLEFnm79ltp0SFAxLQAALQI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:03:32.854709 2026] [security2:error] [pid 28702:tid 28864] [client 82.102.18.116:54918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4cpLF4957xPw9VVBnCrwAAAKQ"]
[Mon Jul 20 07:03:32.893161 2026] [security2:error] [pid 45040:tid 45206] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpLEFnm79ltp0SFAxJwAAACI"]
[Mon Jul 20 07:03:32.893189 2026] [security2:error] [pid 45040:tid 45206] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpLEFnm79ltp0SFAxJwAAACI"]
[Mon Jul 20 07:03:32.911040 2026] [security2:error] [pid 28702:tid 28914] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/fonts/"] [unique_id "al4cpLF4957xPw9VVBnCowAAANY"]
[Mon Jul 20 07:03:32.973173 2026] [security2:error] [pid 28702:tid 28806] [remote 72.167.132.114:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4cpLF4957xPw9VVBnCtgAAiGY"]
[Mon Jul 20 07:03:33.041556 2026] [security2:error] [pid 28702:tid 28920] [client 14.225.17.146:61561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCKwAAANw"], referer: http://dollpassionista.com/2026
[Mon Jul 20 07:03:33.093704 2026] [security2:error] [pid 45040:tid 45207] [client 14.225.17.146:54618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4cpLEFnm79ltp0SFAxMAAAACM"], referer: https://maxenengineering.com/2026
[Mon Jul 20 07:03:33.146458 2026] [security2:error] [pid 28702:tid 28866] [client 14.225.17.146:61618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4cpLF4957xPw9VVBnCswAAAKY"], referer: https://nwcarvingacademy.com/2026
[Mon Jul 20 07:03:33.171082 2026] [security2:error] [pid 28702:tid 28947] [client 82.102.18.116:54920] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4cpbF4957xPw9VVBnCyAAAAPc"]
[Mon Jul 20 07:03:33.196180 2026] [security2:error] [pid 28702:tid 28949] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cpLF4957xPw9VVBnCvAAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:33.209322 2026] [security2:error] [pid 28702:tid 28741] [remote 72.167.132.114:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4cpbF4957xPw9VVBnCyQAAzCU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:03:33.286740 2026] [security2:error] [pid 45040:tid 45236] [client 45.3.54.98:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cpbEFnm79ltp0SFAxPgAAAEA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:33.315089 2026] [security2:error] [pid 45040:tid 45235] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxOQAAAD8"]
[Mon Jul 20 07:03:33.315117 2026] [security2:error] [pid 45040:tid 45235] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxOQAAAD8"]
[Mon Jul 20 07:03:33.323112 2026] [security2:error] [pid 28702:tid 28844] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "al4cpbF4957xPw9VVBnCwwAAAJA"]
[Mon Jul 20 07:03:33.346401 2026] [security2:error] [pid 45040:tid 45046] [remote 47.128.54.241:52748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omegacompass.com"] [uri "/omega-prime-intelligence/"] [unique_id "al4cpbEFnm79ltp0SFAxQQAAUgU"]
[Mon Jul 20 07:03:33.364702 2026] [security2:error] [pid 45040:tid 45258] [client 194.61.41.98:47069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/buy.php"] [unique_id "al4cpbEFnm79ltp0SFAxQgAAAFY"]
[Mon Jul 20 07:03:33.386547 2026] [security2:error] [pid 28702:tid 28936] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/fonts/"] [unique_id "al4cpbF4957xPw9VVBnC0wAAAOw"]
[Mon Jul 20 07:03:33.470468 2026] [http2:warn] [pid 28702:tid 28940] [client 57.141.18.56:64010] h2_stream(28702-684-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:33.484318 2026] [security2:error] [pid 45040:tid 45265] [client 82.102.18.116:54924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4cpbEFnm79ltp0SFAxRgAAAF0"]
[Mon Jul 20 07:03:33.529475 2026] [security2:error] [pid 28702:tid 28865] [client 77.110.127.138:62224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cpbF4957xPw9VVBnC3AAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:33.529607 2026] [security2:error] [pid 28702:tid 28865] [client 77.110.127.138:62224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cpbF4957xPw9VVBnC3AAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:33.587094 2026] [security2:error] [pid 28702:tid 28926] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cpbF4957xPw9VVBnC3QAAAOI"]
[Mon Jul 20 07:03:33.587123 2026] [security2:error] [pid 28702:tid 28926] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cpbF4957xPw9VVBnC3QAAAOI"]
[Mon Jul 20 07:03:33.706205 2026] [security2:error] [pid 45040:tid 45264] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxRQAAAFw"]
[Mon Jul 20 07:03:33.706231 2026] [security2:error] [pid 45040:tid 45264] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxRQAAAFw"]
[Mon Jul 20 07:03:33.720460 2026] [security2:error] [pid 45040:tid 45267] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxSQAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:33.735838 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "al4cpbF4957xPw9VVBnC1wAAAOQ"]
[Mon Jul 20 07:03:33.832061 2026] [security2:error] [pid 45040:tid 45174] [client 82.102.18.116:54926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4cpbEFnm79ltp0SFAxVgAAAAI"]
[Mon Jul 20 07:03:33.899217 2026] [security2:error] [pid 28702:tid 28889] [client 14.225.17.146:61577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4co7F4957xPw9VVBnCYAAAAL0"]
[Mon Jul 20 07:03:34.004272 2026] [http2:warn] [pid 29744:tid 29876] [client 57.141.18.101:49450] h2_stream(29744-952-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:34.016563 2026] [security2:error] [pid 45040:tid 45278] [client 14.225.17.146:53526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxWAAAAGo"], referer: https://dollpassionista.com/2026
[Mon Jul 20 07:03:34.049489 2026] [security2:error] [pid 28702:tid 28929] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/contact-form-7/admin/js/"] [unique_id "al4cprF4957xPw9VVBnC-QAAAOU"]
[Mon Jul 20 07:03:34.116126 2026] [security2:error] [pid 28702:tid 28890] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpbF4957xPw9VVBnC7QAAAL4"]
[Mon Jul 20 07:03:34.116154 2026] [security2:error] [pid 28702:tid 28890] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cpbF4957xPw9VVBnC7QAAAL4"]
[Mon Jul 20 07:03:34.120762 2026] [security2:error] [pid 28702:tid 28947] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wordpress/"] [unique_id "al4cpbF4957xPw9VVBnC6gAAAPc"]
[Mon Jul 20 07:03:34.121965 2026] [security2:error] [pid 45040:tid 45280] [client 14.225.17.146:53521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4cpbEFnm79ltp0SFAxWQAAAGw"], referer: http://fkconstructionfunding.com/2026
[Mon Jul 20 07:03:34.155656 2026] [security2:error] [pid 45040:tid 45193] [client 82.102.18.116:45061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4cprEFnm79ltp0SFAxYAAAABU"]
[Mon Jul 20 07:03:34.181893 2026] [security2:error] [pid 45040:tid 45191] [client 194.61.41.247:31397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/wp-conflg.php"] [unique_id "al4cprEFnm79ltp0SFAxXwAAABM"]
[Mon Jul 20 07:03:34.267654 2026] [security2:error] [pid 45040:tid 45178] [client 104.234.53.91:50367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4cprEFnm79ltp0SFAxbAAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:34.271431 2026] [security2:error] [pid 28702:tid 28868] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cprF4957xPw9VVBnC-wAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:34.353361 2026] [http2:warn] [pid 28702:tid 28851] [client 57.141.18.80:37762] h2_stream(28702-688-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:34.372778 2026] [security2:error] [pid 28702:tid 28914] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cprF4957xPw9VVBnDBgAAANY"]
[Mon Jul 20 07:03:34.372803 2026] [security2:error] [pid 28702:tid 28914] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cprF4957xPw9VVBnDBgAAANY"]
[Mon Jul 20 07:03:34.386108 2026] [autoindex:error] [pid 28702:tid 28846] [client 85.204.70.104:59906] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:34.386633 2026] [security2:error] [pid 28702:tid 28846] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/images/"] [unique_id "al4cprF4957xPw9VVBnDBwAAAJI"]
[Mon Jul 20 07:03:34.470357 2026] [security2:error] [pid 28702:tid 28920] [client 82.102.18.116:54944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4cprF4957xPw9VVBnDDAAAANw"]
[Mon Jul 20 07:03:34.564273 2026] [autoindex:error] [pid 45040:tid 45226] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-content/plugins/wordpress-seo/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:34.564741 2026] [security2:error] [pid 45040:tid 45226] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4cprEFnm79ltp0SFAxeAAAADY"]
[Mon Jul 20 07:03:34.567043 2026] [security2:error] [pid 28702:tid 28888] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "al4cprF4957xPw9VVBnDEgAAALw"]
[Mon Jul 20 07:03:34.760313 2026] [security2:error] [pid 45040:tid 45257] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/wordpress-seo/index.php"] [unique_id "al4cprEFnm79ltp0SFAxhgAAAFU"]
[Mon Jul 20 07:03:34.761734 2026] [security2:error] [pid 28702:tid 28859] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "al4cprF4957xPw9VVBnDHAAAAJ8"]
[Mon Jul 20 07:03:34.789785 2026] [security2:error] [pid 45040:tid 45263] [client 82.102.18.116:54960] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4cprEFnm79ltp0SFAxiQAAAFs"]
[Mon Jul 20 07:03:34.804100 2026] [http2:warn] [pid 29744:tid 29922] [client 57.141.18.39:42995] h2_stream(29744-959-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:34.938922 2026] [security2:error] [pid 45040:tid 45202] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cprEFnm79ltp0SFAxbQAAAB4"], referer: 1'"3000
[Mon Jul 20 07:03:34.962201 2026] [security2:error] [pid 45040:tid 45275] [client 194.61.41.84:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/classwithtostring.php"] [unique_id "al4cprEFnm79ltp0SFAxiwAAAGc"]
[Mon Jul 20 07:03:34.972390 2026] [security2:error] [pid 45040:tid 45239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cprEFnm79ltp0SFAxgQAAAEM"]
[Mon Jul 20 07:03:34.994974 2026] [security2:error] [pid 45040:tid 45057] [remote 20.153.140.50:37052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cprEFnm79ltp0SFAxkgAARg8"]
[Mon Jul 20 07:03:35.045452 2026] [security2:error] [pid 28702:tid 28880] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/contact-form-7/"] [unique_id "al4cp7F4957xPw9VVBnDKAAAALQ"]
[Mon Jul 20 07:03:35.104179 2026] [security2:error] [pid 28702:tid 28901] [client 82.102.18.116:54962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4cp7F4957xPw9VVBnDKwAAAMk"]
[Mon Jul 20 07:03:35.195232 2026] [security2:error] [pid 45040:tid 45283] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cprEFnm79ltp0SFAxkAAAAG8"]
[Mon Jul 20 07:03:35.195263 2026] [security2:error] [pid 45040:tid 45283] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cprEFnm79ltp0SFAxkAAAAG8"]
[Mon Jul 20 07:03:35.198888 2026] [security2:error] [pid 28702:tid 28958] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/js/"] [unique_id "al4cprF4957xPw9VVBnDIQAAAQI"]
[Mon Jul 20 07:03:35.256635 2026] [security2:error] [pid 45040:tid 45251] [client 14.225.17.146:56211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4cprEFnm79ltp0SFAxjgAAAE8"], referer: http://healthylifegourmet.org/2026
[Mon Jul 20 07:03:35.264080 2026] [security2:error] [pid 28702:tid 28912] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cp7F4957xPw9VVBnDMAAAANQ"]
[Mon Jul 20 07:03:35.264106 2026] [security2:error] [pid 28702:tid 28912] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cp7F4957xPw9VVBnDMAAAANQ"]
[Mon Jul 20 07:03:35.392898 2026] [security2:error] [pid 45040:tid 45060] [remote 20.153.140.50:37052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cp7EFnm79ltp0SFAxpAAACRI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:03:35.407197 2026] [security2:error] [pid 28702:tid 28873] [client 14.225.17.146:61512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4cprF4957xPw9VVBnDBAAAAK0"], referer: http://getgarrison.com/2026
[Mon Jul 20 07:03:35.421275 2026] [security2:error] [pid 28702:tid 28838] [client 82.102.18.116:54972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4cp7F4957xPw9VVBnDOwAAAIo"]
[Mon Jul 20 07:03:35.454545 2026] [security2:error] [pid 45040:tid 45295] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cp7EFnm79ltp0SFAxmgAAAHs"], referer: 1'"3000
[Mon Jul 20 07:03:35.547806 2026] [http2:warn] [pid 29744:tid 29929] [client 57.141.18.100:64056] h2_stream(29744-966-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:35.596410 2026] [security2:error] [pid 28702:tid 28834] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cp7F4957xPw9VVBnDOQAAAIY"]
[Mon Jul 20 07:03:35.699253 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cp7F4957xPw9VVBnDPwAAAOQ"]
[Mon Jul 20 07:03:35.699277 2026] [security2:error] [pid 28702:tid 28928] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cp7F4957xPw9VVBnDPwAAAOQ"]
[Mon Jul 20 07:03:35.699723 2026] [security2:error] [pid 45040:tid 45191] [client 104.28.130.189:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4cp7EFnm79ltp0SFAxqwAAABM"]
[Mon Jul 20 07:03:35.706247 2026] [security2:error] [pid 28702:tid 28923] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "al4cp7F4957xPw9VVBnDPQAAAN8"]
[Mon Jul 20 07:03:35.746223 2026] [security2:error] [pid 45040:tid 45234] [client 82.102.18.116:54974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.ogx.sbv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4cp7EFnm79ltp0SFAxtwAAAD4"]
[Mon Jul 20 07:03:35.790152 2026] [security2:error] [pid 45040:tid 45246] [client 194.61.41.97:22523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/elementor/wp-wjvngrh.php"] [unique_id "al4cp7EFnm79ltp0SFAxuAAAAEo"]
[Mon Jul 20 07:03:36.030886 2026] [security2:error] [pid 28702:tid 28890] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wordpress/"] [unique_id "al4cqLF4957xPw9VVBnDVAAAAL4"]
[Mon Jul 20 07:03:36.088145 2026] [http2:warn] [pid 28702:tid 28862] [client 57.141.18.49:25408] h2_stream(28702-693-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:36.178168 2026] [security2:error] [pid 45040:tid 45203] [client 85.204.70.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cp7EFnm79ltp0SFAxwgAAAB8"]
[Mon Jul 20 07:03:36.178195 2026] [security2:error] [pid 45040:tid 45203] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cp7EFnm79ltp0SFAxwgAAAB8"]
[Mon Jul 20 07:03:36.180923 2026] [security2:error] [pid 28702:tid 28835] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "al4cp7F4957xPw9VVBnDUAAAAIc"]
[Mon Jul 20 07:03:36.266859 2026] [security2:error] [pid 28702:tid 28952] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cqLF4957xPw9VVBnDWgAAAPw"]
[Mon Jul 20 07:03:36.266884 2026] [security2:error] [pid 28702:tid 28952] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cqLF4957xPw9VVBnDWgAAAPw"]
[Mon Jul 20 07:03:36.283962 2026] [security2:error] [pid 45040:tid 45241] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4cp7EFnm79ltp0SFAxtgAARRc"], referer: http://ardhalwafaa.com/2026
[Mon Jul 20 07:03:36.289979 2026] [security2:error] [pid 45040:tid 45275] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cqLEFnm79ltp0SFAxxgAAZxg"]
[Mon Jul 20 07:03:36.295490 2026] [security2:error] [pid 45040:tid 45263] [client 117.247.108.24:23365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cqLEFnm79ltp0SFAx0QAAAFs"]
[Mon Jul 20 07:03:36.295604 2026] [security2:error] [pid 45040:tid 45263] [client 117.247.108.24:23365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cqLEFnm79ltp0SFAx0QAAAFs"]
[Mon Jul 20 07:03:36.533039 2026] [security2:error] [pid 45040:tid 45184] [client 194.61.41.84:40785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/fix.php7"] [unique_id "al4cqLEFnm79ltp0SFAx1gAAAAw"]
[Mon Jul 20 07:03:36.541397 2026] [security2:error] [pid 45040:tid 45298] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cqLEFnm79ltp0SFAx0AAAAH4"]
[Mon Jul 20 07:03:36.585595 2026] [security2:error] [pid 28702:tid 28882] [client 85.204.70.104:59906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cqLF4957xPw9VVBnDYQAAALY"]
[Mon Jul 20 07:03:36.585617 2026] [security2:error] [pid 28702:tid 28882] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4cqLF4957xPw9VVBnDYQAAALY"]
[Mon Jul 20 07:03:36.587502 2026] [security2:error] [pid 45040:tid 45260] [client 14.225.17.146:57005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4cp7EFnm79ltp0SFAxlQAAAFg"], referer: http://vinovinhowine.com/2026
[Mon Jul 20 07:03:36.599936 2026] [security2:error] [pid 45040:tid 45236] [client 117.222.139.248:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cqLEFnm79ltp0SFAx3gAAAEA"]
[Mon Jul 20 07:03:36.600033 2026] [security2:error] [pid 45040:tid 45236] [client 117.222.139.248:52646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cqLEFnm79ltp0SFAx3gAAAEA"]
[Mon Jul 20 07:03:36.774085 2026] [http2:warn] [pid 28702:tid 28855] [client 57.141.18.121:56574] h2_stream(28702-695-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:36.836375 2026] [security2:error] [pid 28702:tid 28893] [client 103.183.8.185:34320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.8.183.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-comments-post.php"] [unique_id "al4cqLF4957xPw9VVBnDdgAAAME"]
[Mon Jul 20 07:03:36.836476 2026] [security2:error] [pid 28702:tid 28893] [client 103.183.8.185:34320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "jhavoctattoos.com"] [uri "/wp-comments-post.php"] [unique_id "al4cqLF4957xPw9VVBnDdgAAAME"]
[Mon Jul 20 07:03:36.849628 2026] [ssl:error] [pid 28702:tid 28896] [client 104.48.69.105:42628] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:03:36.865651 2026] [security2:error] [pid 28702:tid 28872] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/network/index.php"] [unique_id "al4cqLF4957xPw9VVBnDcAAAAKw"]
[Mon Jul 20 07:03:36.918470 2026] [security2:error] [pid 28702:tid 28889] [client 51.68.236.68:27607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.vfcthomasville.org"] [uri "/robots.txt"] [unique_id "al4cqLF4957xPw9VVBnDeQAAAL0"]
[Mon Jul 20 07:03:36.918561 2026] [security2:error] [pid 28702:tid 28889] [client 51.68.236.68:27607] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.vfcthomasville.org"] [uri "/robots.txt"] [unique_id "al4cqLF4957xPw9VVBnDeQAAAL0"]
[Mon Jul 20 07:03:36.971617 2026] [security2:error] [pid 28702:tid 28923] [client 170.64.227.219:61965] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.maplerespiteservices.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4cqLF4957xPw9VVBnDegAAAN8"]
[Mon Jul 20 07:03:37.041017 2026] [security2:error] [pid 28702:tid 28933] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/images/"] [unique_id "al4cqbF4957xPw9VVBnDfQAAAOk"]
[Mon Jul 20 07:03:37.207254 2026] [http2:warn] [pid 29744:tid 29955] [client 57.141.18.81:21662] h2_stream(29744-976-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:37.220852 2026] [security2:error] [pid 45040:tid 45192] [client 183.82.98.154:56333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cqbEFnm79ltp0SFAx-AAAABQ"]
[Mon Jul 20 07:03:37.221003 2026] [security2:error] [pid 45040:tid 45192] [client 183.82.98.154:56333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cqbEFnm79ltp0SFAx-AAAABQ"]
[Mon Jul 20 07:03:37.246067 2026] [autoindex:error] [pid 28702:tid 28887] [client 143.244.57.120:33326] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:37.246586 2026] [security2:error] [pid 28702:tid 28887] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-admin/images/"] [unique_id "al4cqbF4957xPw9VVBnDggAAALs"]
[Mon Jul 20 07:03:37.271666 2026] [security2:error] [pid 45040:tid 45191] [client 104.28.130.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4cqLEFnm79ltp0SFAx5AAAABM"]
[Mon Jul 20 07:03:37.343461 2026] [security2:error] [pid 45040:tid 45290] [client 194.61.41.72:23285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/dyqvcfqv.php"] [unique_id "al4cqbEFnm79ltp0SFAx_wAAAHY"]
[Mon Jul 20 07:03:37.344218 2026] [security2:error] [pid 45040:tid 45218] [client 103.144.65.217:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cqbEFnm79ltp0SFAyAAAAAC4"]
[Mon Jul 20 07:03:37.344299 2026] [security2:error] [pid 45040:tid 45218] [client 103.144.65.217:63218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cqbEFnm79ltp0SFAyAAAAAC4"]
[Mon Jul 20 07:03:37.489012 2026] [security2:error] [pid 45040:tid 45274] [client 85.204.70.104:41916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/network/index.php"] [unique_id "al4cqbEFnm79ltp0SFAyAQAAAGY"]
[Mon Jul 20 07:03:37.647496 2026] [security2:error] [pid 45040:tid 45295] [client 85.204.70.104:41916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cqbEFnm79ltp0SFAyCQAAAHs"]
[Mon Jul 20 07:03:37.647633 2026] [security2:error] [pid 45040:tid 45295] [client 85.204.70.104:41916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cqbEFnm79ltp0SFAyCQAAAHs"]
[Mon Jul 20 07:03:37.701932 2026] [ssl:error] [pid 45040:tid 45188] [client 104.48.69.105:42644] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:03:37.719230 2026] [http2:warn] [pid 29744:tid 29915] [client 57.141.18.106:39630] h2_stream(29744-983-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:37.728568 2026] [security2:error] [pid 45040:tid 45268] [client 192.140.149.97:46248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cqbEFnm79ltp0SFAyDgAAAGA"]
[Mon Jul 20 07:03:37.728795 2026] [security2:error] [pid 45040:tid 45268] [client 192.140.149.97:46248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cqbEFnm79ltp0SFAyDgAAAGA"]
[Mon Jul 20 07:03:37.807967 2026] [http2:warn] [pid 29744:tid 29945] [client 57.141.18.2:41452] h2_stream(29744-986-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:37.954576 2026] [security2:error] [pid 28702:tid 28894] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/user/index.php"] [unique_id "al4cqbF4957xPw9VVBnDmQAAAMI"]
[Mon Jul 20 07:03:38.000686 2026] [security2:error] [pid 28702:tid 28889] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/wordpress-seo/js/dist/"] [unique_id "al4cqbF4957xPw9VVBnDnwAAAL0"]
[Mon Jul 20 07:03:38.179854 2026] [security2:error] [pid 45040:tid 45221] [client 194.61.41.76:39255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin/function.php"] [unique_id "al4cqrEFnm79ltp0SFAyEgAAADE"]
[Mon Jul 20 07:03:38.245150 2026] [security2:error] [pid 28702:tid 28770] [remote 45.148.10.120:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "aleishapenny.ca"] [uri "/.env"] [unique_id "al4cqrF4957xPw9VVBnDqwAAq0I"]
[Mon Jul 20 07:03:38.257494 2026] [security2:error] [pid 28702:tid 28881] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cqrF4957xPw9VVBnDpgAAALU"]
[Mon Jul 20 07:03:38.257527 2026] [security2:error] [pid 28702:tid 28881] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cqrF4957xPw9VVBnDpgAAALU"]
[Mon Jul 20 07:03:38.331911 2026] [security2:error] [pid 28702:tid 28918] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cqrF4957xPw9VVBnDpQAA2gA"]
[Mon Jul 20 07:03:38.355226 2026] [security2:error] [pid 45040:tid 45238] [client 45.148.10.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cqrEFnm79ltp0SFAyFwAAQiY"]
[Mon Jul 20 07:03:38.531346 2026] [security2:error] [pid 28702:tid 28913] [client 14.225.17.146:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4cqrF4957xPw9VVBnDtwAAANU"], referer: http://39ishlife.com/2026
[Mon Jul 20 07:03:38.599695 2026] [security2:error] [pid 45040:tid 45189] [client 85.204.70.104:41924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/user/index.php"] [unique_id "al4cqrEFnm79ltp0SFAyJQAAABE"]
[Mon Jul 20 07:03:38.632414 2026] [security2:error] [pid 28702:tid 28853] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/wordpress-seo/"] [unique_id "al4cqrF4957xPw9VVBnDuwAAAJk"]
[Mon Jul 20 07:03:38.740192 2026] [security2:error] [pid 45040:tid 45256] [client 85.204.70.104:41924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cqrEFnm79ltp0SFAyLQAAAFQ"]
[Mon Jul 20 07:03:38.740316 2026] [security2:error] [pid 45040:tid 45256] [client 85.204.70.104:41924] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4cqrEFnm79ltp0SFAyLQAAAFQ"]
[Mon Jul 20 07:03:38.768144 2026] [security2:error] [pid 28702:tid 28955] [client 104.234.53.76:49683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4cqrF4957xPw9VVBnDvQAAAP8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:38.926191 2026] [security2:error] [pid 45040:tid 45190] [client 194.61.41.78:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/smilies/about.php"] [unique_id "al4cqrEFnm79ltp0SFAyNwAAABI"]
[Mon Jul 20 07:03:38.973712 2026] [security2:error] [pid 28702:tid 28893] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/index.php"] [unique_id "al4cqrF4957xPw9VVBnDyQAAAME"]
[Mon Jul 20 07:03:38.976020 2026] [security2:error] [pid 28702:tid 28907] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/"] [unique_id "al4cqrF4957xPw9VVBnDxwAAAM8"]
[Mon Jul 20 07:03:39.018994 2026] [security2:error] [pid 45040:tid 45178] [client 14.225.17.146:63556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4cqrEFnm79ltp0SFAyNQAAAAY"], referer: http://carolinapressurewashers.com/2026
[Mon Jul 20 07:03:39.044213 2026] [http2:warn] [pid 28702:tid 28959] [client 57.141.18.112:33404] h2_stream(28702-705-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:39.050692 2026] [security2:error] [pid 28702:tid 28934] [client 104.234.53.76:49683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cq7F4957xPw9VVBnDzAAAAOo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:39.127583 2026] [security2:error] [pid 45040:tid 45259] [client 93.152.221.121:56205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cq7EFnm79ltp0SFAyPAAAAFc"]
[Mon Jul 20 07:03:39.128457 2026] [security2:error] [pid 28702:tid 28738] [remote 192.241.143.148:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4cq7F4957xPw9VVBnDzgAAuiI"]
[Mon Jul 20 07:03:39.170990 2026] [security2:error] [pid 45040:tid 45215] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/index.php"] [unique_id "al4cq7EFnm79ltp0SFAyQQAAACs"]
[Mon Jul 20 07:03:39.173262 2026] [security2:error] [pid 28702:tid 28859] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/plugins/"] [unique_id "al4cq7F4957xPw9VVBnD0AAAAJ8"]
[Mon Jul 20 07:03:39.268825 2026] [security2:error] [pid 28702:tid 28894] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cq7F4957xPw9VVBnD0QAAAMI"]
[Mon Jul 20 07:03:39.268860 2026] [security2:error] [pid 28702:tid 28894] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cq7F4957xPw9VVBnD0QAAAMI"]
[Mon Jul 20 07:03:39.327831 2026] [security2:error] [pid 28702:tid 28730] [remote 192.241.143.148:56186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4cq7F4957xPw9VVBnD2QAA0Bo"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 07:03:39.376928 2026] [security2:error] [pid 45040:tid 45278] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/themes/index.php"] [unique_id "al4cq7EFnm79ltp0SFAySgAAAGo"]
[Mon Jul 20 07:03:39.379306 2026] [security2:error] [pid 28702:tid 28867] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/themes/"] [unique_id "al4cq7F4957xPw9VVBnD2wAAAKc"]
[Mon Jul 20 07:03:39.496281 2026] [security2:error] [pid 28702:tid 28931] [client 14.225.17.146:63122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4cq7F4957xPw9VVBnD3QAAAOc"], referer: https://39ishlife.com/2026
[Mon Jul 20 07:03:39.545188 2026] [security2:error] [pid 45040:tid 45238] [client 93.152.221.121:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cq7EFnm79ltp0SFAyTQAAAEI"]
[Mon Jul 20 07:03:39.601045 2026] [autoindex:error] [pid 28702:tid 28920] [client 85.204.70.104:59906] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:39.601546 2026] [security2:error] [pid 28702:tid 28920] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/includes/"] [unique_id "al4cq7F4957xPw9VVBnD4QAAANw"]
[Mon Jul 20 07:03:39.681456 2026] [security2:error] [pid 45040:tid 45253] [client 194.61.41.68:41661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/crop/admin.php"] [unique_id "al4cq7EFnm79ltp0SFAyUQAAAFE"]
[Mon Jul 20 07:03:39.684466 2026] [http2:warn] [pid 29744:tid 29978] [client 57.141.18.75:50278] h2_stream(29744-996-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:39.730715 2026] [security2:error] [pid 45040:tid 45280] [client 77.110.127.138:62267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cq7EFnm79ltp0SFAyVQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:39.730821 2026] [security2:error] [pid 45040:tid 45280] [client 77.110.127.138:62267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cq7EFnm79ltp0SFAyVQAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:39.884674 2026] [security2:error] [pid 28702:tid 28870] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/index.php"] [unique_id "al4cq7F4957xPw9VVBnD6AAAAKo"]
[Mon Jul 20 07:03:40.208269 2026] [security2:error] [pid 28702:tid 28896] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/js/"] [unique_id "al4crLF4957xPw9VVBnD-wAAAMQ"]
[Mon Jul 20 07:03:40.217352 2026] [http2:warn] [pid 29744:tid 29984] [client 57.141.18.95:21990] h2_stream(29744-1001-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:40.225840 2026] [security2:error] [pid 45040:tid 45091] [remote 74.235.96.117:44850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4crLEFnm79ltp0SFAyaAAAfTA"]
[Mon Jul 20 07:03:40.226117 2026] [security2:error] [pid 45040:tid 45297] [client 74.235.96.117:44850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4crLEFnm79ltp0SFAyaAAAfTA"]
[Mon Jul 20 07:03:40.269341 2026] [security2:error] [pid 45040:tid 45188] [client 50.116.65.227:27220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2024/07/IMG_6047.jpeg"] [unique_id "al4crLEFnm79ltp0SFAybQAAABA"]
[Mon Jul 20 07:03:40.286031 2026] [security2:error] [pid 28702:tid 28955] [client 88.99.80.227:25222] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4crLF4957xPw9VVBnD9gAAAP8"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:03:40.434914 2026] [security2:error] [pid 45040:tid 45247] [client 194.61.41.91:47713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/wp-conflg.php"] [unique_id "al4crLEFnm79ltp0SFAyegAAAEs"]
[Mon Jul 20 07:03:40.460578 2026] [security2:error] [pid 28702:tid 28833] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4crLF4957xPw9VVBnEAgAAAIU"]
[Mon Jul 20 07:03:40.460612 2026] [security2:error] [pid 28702:tid 28833] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4crLF4957xPw9VVBnEAgAAAIU"]
[Mon Jul 20 07:03:40.483773 2026] [security2:error] [pid 45040:tid 45239] [client 85.204.70.104:41936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "bluedoorbar.co.nz"] [uri "/wp-admin/index.php"] [unique_id "al4crLEFnm79ltp0SFAycwAAAEM"]
[Mon Jul 20 07:03:40.610882 2026] [security2:error] [pid 28702:tid 28746] [remote 97.74.93.24:34812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4crLF4957xPw9VVBnEBwAAnio"]
[Mon Jul 20 07:03:40.636387 2026] [security2:error] [pid 45040:tid 45177] [client 93.152.221.121:56254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4crLEFnm79ltp0SFAygQAAAAU"]
[Mon Jul 20 07:03:40.638451 2026] [security2:error] [pid 45040:tid 45246] [client 85.204.70.104:41936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4crLEFnm79ltp0SFAyggAAAEo"]
[Mon Jul 20 07:03:40.638537 2026] [security2:error] [pid 45040:tid 45246] [client 85.204.70.104:41936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4crLEFnm79ltp0SFAyggAAAEo"]
[Mon Jul 20 07:03:40.688884 2026] [http2:warn] [pid 29744:tid 29942] [client 57.141.18.50:27652] h2_stream(29744-1005-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:40.862686 2026] [security2:error] [pid 45040:tid 45255] [client 113.160.97.242:57920] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4crLEFnm79ltp0SFAyigAAAFM"]
[Mon Jul 20 07:03:40.880735 2026] [autoindex:error] [pid 28702:tid 28881] [client 85.204.70.104:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_23836bfd/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:40.881210 2026] [security2:error] [pid 28702:tid 28881] [client 85.204.70.104:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/cgi-sys/403.html"] [unique_id "al4crLF4957xPw9VVBnEEQAAALU"]
[Mon Jul 20 07:03:40.882482 2026] [security2:error] [pid 28702:tid 28869] [client 85.204.70.104:59906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "bluedoorbar.co.nz"] [uri "/wp-content/upgrade/"] [unique_id "al4crLF4957xPw9VVBnEEAAAAKk"]
[Mon Jul 20 07:03:40.976708 2026] [security2:error] [pid 45040:tid 45266] [client 14.225.17.146:63722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4cq7EFnm79ltp0SFAyOQAAAF4"], referer: http://floorsourcestock.com/2026
[Mon Jul 20 07:03:41.056998 2026] [security2:error] [pid 45040:tid 45234] [client 93.152.221.121:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4crbEFnm79ltp0SFAylAAAAD4"]
[Mon Jul 20 07:03:41.077247 2026] [security2:error] [pid 28702:tid 28825] [remote 97.74.93.24:34812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4crbF4957xPw9VVBnEGwAA3Hk"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 07:03:41.258458 2026] [security2:error] [pid 45040:tid 45196] [client 194.61.41.84:52733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/admin.php"] [unique_id "al4crbEFnm79ltp0SFAymQAAABg"]
[Mon Jul 20 07:03:41.491262 2026] [security2:error] [pid 28702:tid 28917] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/woocommerce/assets/js/"] [unique_id "al4crbF4957xPw9VVBnEMAAAANk"]
[Mon Jul 20 07:03:41.528661 2026] [security2:error] [pid 45040:tid 45179] [client 187.16.64.216:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4crbEFnm79ltp0SFAypgAAAAc"]
[Mon Jul 20 07:03:41.528797 2026] [security2:error] [pid 45040:tid 45179] [client 187.16.64.216:55789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4crbEFnm79ltp0SFAypgAAAAc"]
[Mon Jul 20 07:03:41.531356 2026] [security2:error] [pid 29744:tid 29768] [remote 57.141.18.113:56336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cReGINCUUz5GA9YItJQACkRY"]
[Mon Jul 20 07:03:41.531565 2026] [security2:error] [pid 28702:tid 28912] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4crbF4957xPw9VVBnEIgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:41.573919 2026] [security2:error] [pid 45040:tid 45195] [client 154.208.48.130:51636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4crbEFnm79ltp0SFAyqAAAABc"]
[Mon Jul 20 07:03:41.574060 2026] [security2:error] [pid 45040:tid 45195] [client 154.208.48.130:51636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4crbEFnm79ltp0SFAyqAAAABc"]
[Mon Jul 20 07:03:41.761431 2026] [security2:error] [pid 28702:tid 28939] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4crbF4957xPw9VVBnENwAAAO8"]
[Mon Jul 20 07:03:41.761464 2026] [security2:error] [pid 28702:tid 28939] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4crbF4957xPw9VVBnENwAAAO8"]
[Mon Jul 20 07:03:41.810353 2026] [http2:warn] [pid 29744:tid 29917] [client 57.141.18.119:42432] h2_stream(29744-1013-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:41.885493 2026] [security2:error] [pid 45040:tid 45100] [remote 209.42.18.223:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4crbEFnm79ltp0SFAytwAALDk"]
[Mon Jul 20 07:03:41.920770 2026] [security2:error] [pid 45040:tid 45279] [client 34.23.246.146:26556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "greenport-texas.com"] [uri "/wp-json/batch/v1"] [unique_id "al4crbEFnm79ltp0SFAyvwAAAGs"]
[Mon Jul 20 07:03:41.927224 2026] [security2:error] [pid 28702:tid 28844] [client 194.5.65.206:49655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "50.116.65.228"] [uri "/.env"] [unique_id "al4crbF4957xPw9VVBnEQQAAAJA"]
[Mon Jul 20 07:03:42.031261 2026] [http2:warn] [pid 28702:tid 28944] [client 57.141.18.108:24546] h2_stream(28702-713-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:42.059610 2026] [security2:error] [pid 45040:tid 45102] [remote 209.42.18.223:58568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4crrEFnm79ltp0SFAyyQAACzs"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:03:42.082055 2026] [security2:error] [pid 45040:tid 45298] [client 194.61.41.243:58915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/wp-login.php"] [unique_id "al4crrEFnm79ltp0SFAyyAAAAH4"]
[Mon Jul 20 07:03:42.240178 2026] [security2:error] [pid 28702:tid 28915] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/woocommerce/"] [unique_id "al4crrF4957xPw9VVBnETgAAANc"]
[Mon Jul 20 07:03:42.312698 2026] [security2:error] [pid 45040:tid 45210] [client 122.183.32.225:13560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4crrEFnm79ltp0SFAy1AAAACY"]
[Mon Jul 20 07:03:42.312857 2026] [security2:error] [pid 45040:tid 45210] [client 122.183.32.225:13560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4crrEFnm79ltp0SFAy1AAAACY"]
[Mon Jul 20 07:03:42.385832 2026] [security2:error] [pid 45040:tid 45196] [client 77.110.127.138:62272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4crrEFnm79ltp0SFAyywAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:42.408190 2026] [security2:error] [pid 45040:tid 45274] [client 14.225.17.146:64069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4crrEFnm79ltp0SFAy0AAAAGY"], referer: http://lifeisbetterlakeside.com/2026
[Mon Jul 20 07:03:42.418638 2026] [security2:error] [pid 45040:tid 45235] [client 14.225.17.146:56697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4crrEFnm79ltp0SFAyzgAAAD8"], referer: http://ccsdifference.com/2026
[Mon Jul 20 07:03:42.425351 2026] [security2:error] [pid 45040:tid 45224] [client 194.5.65.206:49700] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "50.116.65.228"] [uri "/"] [unique_id "al4crrEFnm79ltp0SFAy2AAAADQ"]
[Mon Jul 20 07:03:42.436020 2026] [security2:error] [pid 28702:tid 28918] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4crrF4957xPw9VVBnESwAAANo"]
[Mon Jul 20 07:03:42.455879 2026] [security2:error] [pid 45040:tid 45226] [client 74.208.214.194:43474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4crrEFnm79ltp0SFAy2gAAADY"]
[Mon Jul 20 07:03:42.459344 2026] [http2:warn] [pid 29744:tid 29970] [client 57.141.18.51:51662] h2_stream(29744-1017-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:42.461955 2026] [security2:error] [pid 28702:tid 28865] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4crrF4957xPw9VVBnEWQAAAKU"]
[Mon Jul 20 07:03:42.461989 2026] [security2:error] [pid 28702:tid 28865] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4crrF4957xPw9VVBnEWQAAAKU"]
[Mon Jul 20 07:03:42.494712 2026] [http2:warn] [pid 29744:tid 29907] [client 57.141.18.15:50058] h2_stream(29744-1019-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:42.519453 2026] [security2:error] [pid 45040:tid 45200] [client 34.23.246.146:26556] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "greenport-texas.com"] [uri "/"] [unique_id "al4crrEFnm79ltp0SFAy3AAAABw"]
[Mon Jul 20 07:03:42.597848 2026] [security2:error] [pid 28702:tid 28838] [client 50.116.65.227:27284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4crrF4957xPw9VVBnEYwAAAIo"]
[Mon Jul 20 07:03:42.607192 2026] [security2:error] [pid 28702:tid 28879] [client 50.116.65.227:27292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4crrF4957xPw9VVBnEZAAAALM"]
[Mon Jul 20 07:03:42.783183 2026] [security2:error] [pid 45040:tid 45219] [client 14.251.3.155:54885] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4crrEFnm79ltp0SFAy6QAAAC8"]
[Mon Jul 20 07:03:42.789015 2026] [security2:error] [pid 28702:tid 28912] [client 43.172.198.242:44342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.drawingthedog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4crrF4957xPw9VVBnEZwAAANQ"], referer: https://www.drawingthedog.com/border-terrier/
[Mon Jul 20 07:03:42.810237 2026] [security2:error] [pid 28702:tid 28857] [client 43.172.198.43:41942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.drawingthedog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4crrF4957xPw9VVBnEagAAAJ0"], referer: https://www.drawingthedog.com/border-terrier/
[Mon Jul 20 07:03:42.850835 2026] [security2:error] [pid 28702:tid 28947] [client 194.61.41.254:39743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/files/index.php"] [unique_id "al4crrF4957xPw9VVBnEbQAAAPc"]
[Mon Jul 20 07:03:42.869667 2026] [security2:error] [pid 28702:tid 28810] [remote 154.61.75.100:32854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4crrF4957xPw9VVBnEbwAAqGo"]
[Mon Jul 20 07:03:42.905297 2026] [security2:error] [pid 28702:tid 28908] [client 104.207.51.111:46911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4crrF4957xPw9VVBnEbAAAANA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:43.062948 2026] [security2:error] [pid 45040:tid 45279] [client 194.5.65.206:49735] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "50.116.65.228"] [uri "/.env"] [unique_id "al4cr7EFnm79ltp0SFAy-wAAAGs"]
[Mon Jul 20 07:03:43.130249 2026] [security2:error] [pid 28702:tid 28894] [client 77.110.127.138:62278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cr7F4957xPw9VVBnEegAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:43.130347 2026] [security2:error] [pid 28702:tid 28894] [client 77.110.127.138:62278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cr7F4957xPw9VVBnEegAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:43.196147 2026] [security2:error] [pid 45040:tid 45268] [client 34.23.246.146:39488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "greenport-texas.com"] [uri "/wp-json/batch/v1"] [unique_id "al4cr7EFnm79ltp0SFAzAQAAAGA"]
[Mon Jul 20 07:03:43.256151 2026] [security2:error] [pid 28702:tid 28958] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/meta/"] [unique_id "al4cr7F4957xPw9VVBnEfgAAAQI"]
[Mon Jul 20 07:03:43.365828 2026] [security2:error] [pid 28702:tid 28738] [remote 154.61.75.100:32854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4cr7F4957xPw9VVBnEhAAAtiI"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 07:03:43.415957 2026] [security2:error] [pid 45040:tid 45196] [client 34.23.246.146:39488] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "greenport-texas.com"] [uri "/"] [unique_id "al4cr7EFnm79ltp0SFAzCAAAABg"]
[Mon Jul 20 07:03:43.458515 2026] [security2:error] [pid 28702:tid 28865] [client 143.244.57.120:33326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cr7F4957xPw9VVBnEhgAAAKU"]
[Mon Jul 20 07:03:43.458549 2026] [security2:error] [pid 28702:tid 28865] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4cr7F4957xPw9VVBnEhgAAAKU"]
[Mon Jul 20 07:03:43.655237 2026] [security2:error] [pid 45040:tid 45179] [client 194.61.41.106:46075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/options.php"] [unique_id "al4cr7EFnm79ltp0SFAzDwAAAAc"]
[Mon Jul 20 07:03:43.667853 2026] [authz_core:error] [pid 45040:tid 45297] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/IXR/error_log, referer: binance.com
[Mon Jul 20 07:03:43.840678 2026] [http2:warn] [pid 29744:tid 29896] [client 57.141.18.20:54446] h2_stream(29744-1030-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:43.893225 2026] [security2:error] [pid 45040:tid 45177] [client 194.5.65.206:49780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "50.116.65.228"] [uri "/"] [unique_id "al4cr7EFnm79ltp0SFAzHAAAAAU"]
[Mon Jul 20 07:03:44.217418 2026] [security2:error] [pid 45040:tid 45208] [client 14.225.17.146:53478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4crbEFnm79ltp0SFAywQAAACQ"], referer: http://talknutritionwithlesley.com/2026
[Mon Jul 20 07:03:44.257659 2026] [security2:error] [pid 28702:tid 28901] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/network/"] [unique_id "al4csLF4957xPw9VVBnEpQAAAMk"]
[Mon Jul 20 07:03:44.354517 2026] [http2:warn] [pid 28702:tid 28883] [client 57.141.18.8:36382] h2_stream(28702-724-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:44.432543 2026] [security2:error] [pid 45040:tid 45193] [client 194.61.41.84:22783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/inc.php"] [unique_id "al4csLEFnm79ltp0SFAzNQAAABU"]
[Mon Jul 20 07:03:44.616696 2026] [security2:error] [pid 28702:tid 28935] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.musichaven.info"] [uri "/wp-admin/network/index.php"] [unique_id "al4csLF4957xPw9VVBnErQAAAOs"]
[Mon Jul 20 07:03:44.747501 2026] [ssl:error] [pid 45040:tid 45270] [client 66.132.195.45:19874] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.cathybuffini.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:03:44.831552 2026] [http2:warn] [pid 29744:tid 29887] [client 57.141.18.41:53046] h2_stream(29744-1038-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:44.885475 2026] [security2:error] [pid 28702:tid 28882] [client 143.244.57.120:33326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4csLF4957xPw9VVBnEtAAAALY"]
[Mon Jul 20 07:03:44.885678 2026] [security2:error] [pid 28702:tid 28882] [client 143.244.57.120:33326] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4csLF4957xPw9VVBnEtAAAALY"]
[Mon Jul 20 07:03:44.901127 2026] [security2:error] [pid 45040:tid 45226] [client 18.141.57.241:13608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4csLEFnm79ltp0SFAzTAAAADY"]
[Mon Jul 20 07:03:44.901212 2026] [security2:error] [pid 45040:tid 45226] [client 18.141.57.241:13608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4csLEFnm79ltp0SFAzTAAAADY"]
[Mon Jul 20 07:03:45.071921 2026] [autoindex:error] [pid 45040:tid 45176] [client 185.242.226.80:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:45.174761 2026] [security2:error] [pid 45040:tid 45250] [client 194.61.41.95:62137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/index.php"] [unique_id "al4csbEFnm79ltp0SFAzVAAAAE4"]
[Mon Jul 20 07:03:45.297351 2026] [security2:error] [pid 28702:tid 28937] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/user/"] [unique_id "al4csbF4957xPw9VVBnEvgAAAO0"]
[Mon Jul 20 07:03:45.466150 2026] [security2:error] [pid 28702:tid 28912] [client 14.225.17.146:63359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4csLF4957xPw9VVBnEpgAAANQ"], referer: http://collectingrealestate.com/2026
[Mon Jul 20 07:03:45.663533 2026] [security2:error] [pid 28702:tid 28845] [client 14.225.17.146:53547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4csLF4957xPw9VVBnEogAAAJE"], referer: http://dadanetnet.net/2026
[Mon Jul 20 07:03:45.736723 2026] [access_compat:error] [pid 45040:tid 45220] [client 183.47.122.213:48231] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:03:45.778073 2026] [security2:error] [pid 45040:tid 45276] [client 77.110.127.138:62281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4csbEFnm79ltp0SFAzZwAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:45.800408 2026] [security2:error] [pid 28702:tid 28948] [client 14.225.17.146:55370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4csbF4957xPw9VVBnEzgAAAPg"], referer: http://savilerowtravel.com/2026
[Mon Jul 20 07:03:45.821080 2026] [security2:error] [pid 45040:tid 45210] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4csbEFnm79ltp0SFAzawAAACY"]
[Mon Jul 20 07:03:45.868069 2026] [security2:error] [pid 45040:tid 45201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4csbEFnm79ltp0SFAzcAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:45.899774 2026] [http2:warn] [pid 29744:tid 29891] [client 57.141.18.60:30554] h2_stream(29744-1045-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:45.940460 2026] [http2:warn] [pid 29744:tid 29898] [client 57.141.18.78:57632] h2_stream(29744-1046-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:45.954709 2026] [security2:error] [pid 28702:tid 28881] [client 194.61.41.86:40597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/filemanager.php"] [unique_id "al4csbF4957xPw9VVBnE5AAAALU"]
[Mon Jul 20 07:03:46.008791 2026] [security2:error] [pid 45040:tid 45194] [client 143.244.57.120:42106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.musichaven.info"] [uri "/wp-admin/user/index.php"] [unique_id "al4csbEFnm79ltp0SFAzhQAAABY"]
[Mon Jul 20 07:03:46.280914 2026] [security2:error] [pid 45040:tid 45288] [client 143.244.57.120:42106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4csrEFnm79ltp0SFAzjAAAAHQ"]
[Mon Jul 20 07:03:46.281017 2026] [security2:error] [pid 45040:tid 45288] [client 143.244.57.120:42106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4csrEFnm79ltp0SFAzjAAAAHQ"]
[Mon Jul 20 07:03:46.564972 2026] [security2:error] [pid 28702:tid 28941] [client 14.225.17.146:63937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4csrF4957xPw9VVBnE-gAAAPE"], referer: http://myspineworld.com/2026
[Mon Jul 20 07:03:46.675642 2026] [http2:warn] [pid 28702:tid 28916] [client 57.141.18.59:49206] h2_stream(28702-731-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:46.698504 2026] [security2:error] [pid 28702:tid 28917] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/"] [unique_id "al4csrF4957xPw9VVBnFCAAAANk"]
[Mon Jul 20 07:03:46.727592 2026] [security2:error] [pid 45040:tid 45249] [client 194.61.41.77:39927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cgi-bin/bypass.php"] [unique_id "al4csrEFnm79ltp0SFAznwAAAE0"]
[Mon Jul 20 07:03:46.824018 2026] [security2:error] [pid 45040:tid 45290] [client 14.225.17.146:55606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4csrEFnm79ltp0SFAzmAAAAHY"], referer: https://savilerowtravel.com/2026
[Mon Jul 20 07:03:46.918823 2026] [security2:error] [pid 28702:tid 28933] [client 77.110.127.138:62289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4csrF4957xPw9VVBnFBgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:46.953001 2026] [security2:error] [pid 45040:tid 45270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4csrEFnm79ltp0SFAzmwAAAGI"]
[Mon Jul 20 07:03:47.119221 2026] [access_compat:error] [pid 45040:tid 45260] [client 112.90.14.81:43535] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:03:47.165533 2026] [security2:error] [pid 45040:tid 45221] [client 117.222.139.248:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cs7EFnm79ltp0SFAzrgAAADE"]
[Mon Jul 20 07:03:47.166303 2026] [security2:error] [pid 45040:tid 45221] [client 117.222.139.248:53162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cs7EFnm79ltp0SFAzrgAAADE"]
[Mon Jul 20 07:03:47.209069 2026] [security2:error] [pid 45040:tid 45219] [client 143.244.57.120:42116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.musichaven.info"] [uri "/wp-content/index.php"] [unique_id "al4cs7EFnm79ltp0SFAzrwAAAC8"]
[Mon Jul 20 07:03:47.257732 2026] [security2:error] [pid 28702:tid 28939] [client 117.247.108.24:23746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cs7F4957xPw9VVBnFHwAAAO8"]
[Mon Jul 20 07:03:47.257893 2026] [security2:error] [pid 28702:tid 28939] [client 117.247.108.24:23746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cs7F4957xPw9VVBnFHwAAAO8"]
[Mon Jul 20 07:03:47.315210 2026] [http2:warn] [pid 29744:tid 29997] [client 57.141.18.39:22361] h2_stream(29744-1053-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:47.449125 2026] [security2:error] [pid 45040:tid 45293] [client 194.61.41.60:37251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/admin.php"] [unique_id "al4cs7EFnm79ltp0SFAzvgAAAHk"]
[Mon Jul 20 07:03:47.506917 2026] [access_compat:error] [pid 45040:tid 45197] [client 157.148.43.195:42017] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:03:47.537421 2026] [security2:error] [pid 28702:tid 28923] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/"] [unique_id "al4cs7F4957xPw9VVBnFJgAAAN8"]
[Mon Jul 20 07:03:47.712350 2026] [security2:error] [pid 45040:tid 45187] [client 143.244.57.120:42116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.musichaven.info"] [uri "/wp-content/plugins/index.php"] [unique_id "al4cs7EFnm79ltp0SFAz0wAAAA8"]
[Mon Jul 20 07:03:47.872897 2026] [security2:error] [pid 28702:tid 28952] [client 103.144.65.217:63669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cs7F4957xPw9VVBnFMwAAAPw"]
[Mon Jul 20 07:03:47.873029 2026] [security2:error] [pid 28702:tid 28952] [client 103.144.65.217:63669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cs7F4957xPw9VVBnFMwAAAPw"]
[Mon Jul 20 07:03:47.881181 2026] [security2:error] [pid 45040:tid 45283] [client 77.110.127.138:62292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cs7EFnm79ltp0SFAz2AAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:47.881299 2026] [security2:error] [pid 45040:tid 45283] [client 77.110.127.138:62292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cs7EFnm79ltp0SFAz2AAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:47.896028 2026] [http2:warn] [pid 29744:tid 29988] [client 57.141.18.72:54872] h2_stream(29744-1060-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:47.953144 2026] [authz_core:error] [pid 45040:tid 45186] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/IXR/error_log, referer: binance.com
[Mon Jul 20 07:03:47.975111 2026] [security2:error] [pid 28702:tid 28842] [client 183.82.98.154:29801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cs7F4957xPw9VVBnFOAAAAI4"]
[Mon Jul 20 07:03:47.975209 2026] [security2:error] [pid 28702:tid 28842] [client 183.82.98.154:29801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cs7F4957xPw9VVBnFOAAAAI4"]
[Mon Jul 20 07:03:48.008313 2026] [access_compat:error] [pid 28702:tid 28836] [client 112.90.14.23:56565] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:03:48.069918 2026] [security2:error] [pid 28702:tid 28833] [client 14.225.17.146:56638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4csrF4957xPw9VVBnFCwAAAIU"], referer: http://effingweirdmuseums.com/2026
[Mon Jul 20 07:03:48.228772 2026] [security2:error] [pid 45040:tid 45241] [client 194.61.41.94:20265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/admin.php"] [unique_id "al4ctLEFnm79ltp0SFAz9gAAAEU"]
[Mon Jul 20 07:03:48.251077 2026] [security2:error] [pid 45040:tid 45274] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cs7EFnm79ltp0SFAz6QAAAGY"]
[Mon Jul 20 07:03:48.287648 2026] [security2:error] [pid 45040:tid 45159] [remote 217.61.143.92:47778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ctLEFnm79ltp0SFAz-gAAA3Q"]
[Mon Jul 20 07:03:48.292964 2026] [security2:error] [pid 28702:tid 28926] [client 77.110.127.138:62294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ctLF4957xPw9VVBnFPAAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:48.326068 2026] [security2:error] [pid 45040:tid 45209] [client 192.140.149.97:45724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ctLEFnm79ltp0SFAz-wAAACU"]
[Mon Jul 20 07:03:48.326228 2026] [security2:error] [pid 45040:tid 45209] [client 192.140.149.97:45724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ctLEFnm79ltp0SFAz-wAAACU"]
[Mon Jul 20 07:03:48.528811 2026] [security2:error] [pid 45040:tid 45162] [remote 217.61.143.92:47778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ctLEFnm79ltp0SFA0BQAAGHc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:03:48.592395 2026] [http2:warn] [pid 29744:tid 29969] [client 57.141.18.47:60104] h2_stream(29744-1063-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:48.819509 2026] [security2:error] [pid 28702:tid 28893] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/themes/"] [unique_id "al4ctLF4957xPw9VVBnFWwAAAME"]
[Mon Jul 20 07:03:48.830030 2026] [http2:warn] [pid 29744:tid 29947] [client 57.141.18.121:40990] h2_stream(29744-1065-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:48.935559 2026] [security2:error] [pid 45040:tid 45227] [client 14.225.17.146:56721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4ctLEFnm79ltp0SFA0DQAAADc"], referer: http://adirondackengineering.com/2026
[Mon Jul 20 07:03:48.956245 2026] [security2:error] [pid 28702:tid 28948] [client 194.61.41.77:26647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/index.php"] [unique_id "al4ctLF4957xPw9VVBnFaAAAAPg"]
[Mon Jul 20 07:03:48.992714 2026] [security2:error] [pid 45040:tid 45283] [client 14.225.17.146:55479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4ctLEFnm79ltp0SFA0EAAAAG8"], referer: https://effingweirdmuseums.com/2026
[Mon Jul 20 07:03:49.011590 2026] [security2:error] [pid 45040:tid 45297] [client 143.244.57.120:42116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.musichaven.info"] [uri "/wp-content/themes/index.php"] [unique_id "al4ctLEFnm79ltp0SFA0EgAAAH0"]
[Mon Jul 20 07:03:49.011644 2026] [http2:warn] [pid 29744:tid 29972] [client 57.141.18.55:44778] h2_stream(29744-1066-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:49.075565 2026] [security2:error] [pid 28702:tid 28801] [remote 57.141.18.18:38460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3629515"] [unique_id "al4ctbF4957xPw9VVBnFbAAA12E"]
[Mon Jul 20 07:03:49.175945 2026] [security2:error] [pid 28702:tid 28928] [client 14.225.17.146:55317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4ctbF4957xPw9VVBnFbQAAAOQ"], referer: http://daseighty.net/2026
[Mon Jul 20 07:03:49.320259 2026] [security2:error] [pid 45040:tid 45221] [client 13.232.231.177:63678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ctbEFnm79ltp0SFA0GQAAADE"]
[Mon Jul 20 07:03:49.715298 2026] [security2:error] [pid 45040:tid 45167] [remote 47.86.33.52:13990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ctbEFnm79ltp0SFA0LAAAfnw"]
[Mon Jul 20 07:03:49.715464 2026] [security2:error] [pid 45040:tid 45298] [client 47.86.33.52:13990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ctbEFnm79ltp0SFA0LAAAfnw"]
[Mon Jul 20 07:03:49.736519 2026] [security2:error] [pid 45040:tid 45208] [client 194.61.41.98:27597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/jquery/jquery.php"] [unique_id "al4ctbEFnm79ltp0SFA0LQAAACQ"]
[Mon Jul 20 07:03:49.769037 2026] [security2:error] [pid 45040:tid 45238] [client 14.225.17.146:54634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4ctbEFnm79ltp0SFA0JQAAAEI"], referer: http://transparentservices.online/2026
[Mon Jul 20 07:03:49.932652 2026] [access_compat:error] [pid 28702:tid 28893] [client 112.90.2.230:49909] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:03:49.989112 2026] [security2:error] [pid 28702:tid 28927] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/includes/"] [unique_id "al4ctbF4957xPw9VVBnFjwAAAOM"]
[Mon Jul 20 07:03:50.129803 2026] [http2:warn] [pid 29744:tid 29879] [client 57.141.18.101:21698] h2_stream(29744-1073-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:50.282403 2026] [autoindex:error] [pid 45040:tid 45299] [client 143.244.57.120:42116] AH01276: Cannot serve directory /home1/musichav/public_html/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:50.282894 2026] [security2:error] [pid 45040:tid 45299] [client 143.244.57.120:42116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "www.musichaven.info"] [uri "/wp-admin/includes/"] [unique_id "al4ctrEFnm79ltp0SFA0OAAAAH8"]
[Mon Jul 20 07:03:50.323634 2026] [security2:error] [pid 45040:tid 45228] [client 43.205.139.3:43930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ctrEFnm79ltp0SFA0OgAAADg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:03:50.516195 2026] [security2:error] [pid 45040:tid 45260] [client 194.61.41.98:55909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/function.php"] [unique_id "al4ctrEFnm79ltp0SFA0QwAAAFg"]
[Mon Jul 20 07:03:50.654307 2026] [security2:error] [pid 29744:tid 29811] [remote 57.141.18.29:36132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cReGINCUUz5GA9YItSgACQEE"]
[Mon Jul 20 07:03:50.698451 2026] [http2:warn] [pid 29744:tid 29895] [client 57.141.18.92:61670] h2_stream(29744-1078-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:50.768565 2026] [http2:warn] [pid 28702:tid 28895] [client 57.141.18.70:63122] h2_stream(28702-751-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:50.865708 2026] [security2:error] [pid 45040:tid 45178] [client 14.225.17.146:54627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4ctbEFnm79ltp0SFA0IgAAAAY"], referer: http://detroitcsc.com/2026
[Mon Jul 20 07:03:50.891096 2026] [security2:error] [pid 45040:tid 45280] [client 104.234.53.53:55667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ctrEFnm79ltp0SFA0RgAAAGw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:50.953339 2026] [security2:error] [pid 28702:tid 28899] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-admin/"] [unique_id "al4ctrF4957xPw9VVBnFvQAAAMc"]
[Mon Jul 20 07:03:51.206137 2026] [security2:error] [pid 45040:tid 45191] [client 143.244.57.120:42116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "www.musichaven.info"] [uri "/wp-admin/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0SAAAABM"]
[Mon Jul 20 07:03:51.251430 2026] [security2:error] [pid 28702:tid 28844] [client 194.61.41.87:53061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/block-supports/autoload_classmap.php"] [unique_id "al4ct7F4957xPw9VVBnFxgAAAJA"]
[Mon Jul 20 07:03:51.364499 2026] [security2:error] [pid 45040:tid 45200] [client 143.244.57.120:42116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4ct7EFnm79ltp0SFA0UAAAABw"]
[Mon Jul 20 07:03:51.364628 2026] [security2:error] [pid 45040:tid 45200] [client 143.244.57.120:42116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "www.musichaven.info"] [uri "/wp-login.php"] [unique_id "al4ct7EFnm79ltp0SFA0UAAAABw"]
[Mon Jul 20 07:03:51.467007 2026] [http2:warn] [pid 28702:tid 28875] [client 57.141.18.93:49278] h2_stream(28702-752-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:51.626806 2026] [authz_core:error] [pid 45040:tid 45287] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Mon Jul 20 07:03:51.674701 2026] [security2:error] [pid 45040:tid 45055] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.gitlab-ci.yml"] [unique_id "al4ct7EFnm79ltp0SFA0ZwAAFQ0"]
[Mon Jul 20 07:03:51.674701 2026] [security2:error] [pid 45040:tid 45056] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.git-credentials"] [unique_id "al4ct7EFnm79ltp0SFA0agAAFQ4"]
[Mon Jul 20 07:03:51.674887 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jenfarley.com"] [uri "/.gitlab-ci.yml"] [unique_id "al4ct7EFnm79ltp0SFA0ZwAAFQ0"]
[Mon Jul 20 07:03:51.675874 2026] [security2:error] [pid 45040:tid 45053] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env"] [unique_id "al4ct7EFnm79ltp0SFA0aQAAFQs"]
[Mon Jul 20 07:03:51.844333 2026] [security2:error] [pid 45040:tid 45271] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0YgAAYwg"], referer: http://ali-alghanim.net/2026
[Mon Jul 20 07:03:52.031224 2026] [security2:error] [pid 45040:tid 45294] [client 194.61.41.82:54881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-signup.php"] [unique_id "al4cuLEFnm79ltp0SFA0hwAAAHo"]
[Mon Jul 20 07:03:52.097030 2026] [security2:error] [pid 45040:tid 45067] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/.env.local"] [unique_id "al4cuLEFnm79ltp0SFA0jgAAFRg"]
[Mon Jul 20 07:03:52.105601 2026] [security2:error] [pid 28702:tid 28848] [client 13.233.207.33:34854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cuLF4957xPw9VVBnF8AAAAJQ"]
[Mon Jul 20 07:03:52.105675 2026] [security2:error] [pid 28702:tid 28848] [client 13.233.207.33:34854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4cuLF4957xPw9VVBnF8AAAAJQ"]
[Mon Jul 20 07:03:52.106024 2026] [security2:error] [pid 28702:tid 28911] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ct7F4957xPw9VVBnF4QAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:52.152802 2026] [security2:error] [pid 28702:tid 28924] [client 187.16.64.216:56355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cuLF4957xPw9VVBnF9gAAAOA"]
[Mon Jul 20 07:03:52.152956 2026] [security2:error] [pid 28702:tid 28924] [client 187.16.64.216:56355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cuLF4957xPw9VVBnF9gAAAOA"]
[Mon Jul 20 07:03:52.166599 2026] [security2:error] [pid 45040:tid 45071] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "jenfarley.com"] [uri "/.env.example"] [unique_id "al4cuLEFnm79ltp0SFA0lQAAFRw"]
[Mon Jul 20 07:03:52.186344 2026] [security2:error] [pid 28702:tid 28942] [client 143.244.57.120:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.musichaven.info"] [uri "/wp-content/upgrade/"] [unique_id "al4cuLF4957xPw9VVBnF-AAAAPI"]
[Mon Jul 20 07:03:52.386851 2026] [http2:warn] [pid 28702:tid 28921] [client 57.141.18.26:43408] h2_stream(28702-755-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:52.403732 2026] [security2:error] [pid 45040:tid 45277] [client 14.225.17.146:54898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0VwAAAGk"], referer: http://retzkolonglogistics.com/2026
[Mon Jul 20 07:03:52.471902 2026] [security2:error] [pid 45040:tid 45200] [client 104.207.51.130:17821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cuLEFnm79ltp0SFA0pQAAABw"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:03:52.540275 2026] [security2:error] [pid 28702:tid 28929] [client 104.234.53.63:56013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4cuLF4957xPw9VVBnGBwAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:03:52.611766 2026] [http2:warn] [pid 28702:tid 28849] [client 57.141.18.120:35522] h2_stream(28702-757-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:52.738067 2026] [autoindex:error] [pid 45040:tid 45210] [client 143.244.57.120:42118] AH01276: Cannot serve directory /home1/musichav/public_html/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:03:52.738849 2026] [security2:error] [pid 45040:tid 45210] [client 143.244.57.120:42118] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/cgi-sys/403.html"] [unique_id "al4cuLEFnm79ltp0SFA0sAAAACY"]
[Mon Jul 20 07:03:52.847809 2026] [security2:error] [pid 28702:tid 28859] [client 194.61.41.84:54105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/network.php"] [unique_id "al4cuLF4957xPw9VVBnGDgAAAJ8"]
[Mon Jul 20 07:03:52.938189 2026] [security2:error] [pid 45040:tid 45215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cuLEFnm79ltp0SFA0sQAAACs"]
[Mon Jul 20 07:03:52.949919 2026] [security2:error] [pid 45040:tid 45078] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.bak"] [unique_id "al4cuLEFnm79ltp0SFA0ugAAFSM"]
[Mon Jul 20 07:03:52.949925 2026] [security2:error] [pid 45040:tid 45079] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.backup"] [unique_id "al4cuLEFnm79ltp0SFA0uwAAFSQ"]
[Mon Jul 20 07:03:52.968170 2026] [security2:error] [pid 45040:tid 45244] [client 77.110.127.138:62303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cuLEFnm79ltp0SFA0sgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:53.008135 2026] [security2:error] [pid 45040:tid 45217] [client 66.249.74.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fansarogroup.com"] [uri "/index.php"] [unique_id "al4cuLEFnm79ltp0SFA0iwAAAC0"]
[Mon Jul 20 07:03:53.287896 2026] [security2:error] [pid 45040:tid 45175] [client 14.225.17.146:55359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4cubEFnm79ltp0SFA0xwAAAAM"], referer: http://katsklar.com/2026
[Mon Jul 20 07:03:53.377035 2026] [security2:error] [pid 28702:tid 28820] [remote 5.161.225.162:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cubF4957xPw9VVBnGJAAArnQ"]
[Mon Jul 20 07:03:53.547587 2026] [security2:error] [pid 28702:tid 28927] [client 154.208.48.130:52128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cubF4957xPw9VVBnGKwAAAOM"]
[Mon Jul 20 07:03:53.547800 2026] [security2:error] [pid 28702:tid 28927] [client 154.208.48.130:52128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cubF4957xPw9VVBnGKwAAAOM"]
[Mon Jul 20 07:03:53.575058 2026] [security2:error] [pid 45040:tid 45084] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.env.old"] [unique_id "al4cubEFnm79ltp0SFA02wAAFSk"]
[Mon Jul 20 07:03:53.634806 2026] [security2:error] [pid 45040:tid 45267] [client 194.61.41.84:29233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin/upload/css.php"] [unique_id "al4cubEFnm79ltp0SFA03wAAAF8"]
[Mon Jul 20 07:03:53.650548 2026] [security2:error] [pid 28702:tid 28749] [remote 5.161.225.162:42078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cubF4957xPw9VVBnGMAAA1S0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:53.654214 2026] [security2:error] [pid 45040:tid 45086] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/api/.env"] [unique_id "al4cubEFnm79ltp0SFA04AAAFSs"]
[Mon Jul 20 07:03:53.703692 2026] [security2:error] [pid 45040:tid 45298] [client 103.131.71.228:49059] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/robots.txt"] [unique_id "al4cubEFnm79ltp0SFA04QAAAH4"]
[Mon Jul 20 07:03:53.740126 2026] [security2:error] [pid 45040:tid 45291] [client 116.179.33.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4cubEFnm79ltp0SFA02gAAAHc"]
[Mon Jul 20 07:03:53.864562 2026] [security2:error] [pid 45040:tid 45089] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "jenfarley.com"] [uri "/backend/.env"] [unique_id "al4cubEFnm79ltp0SFA08QAAFS4"]
[Mon Jul 20 07:03:53.905465 2026] [security2:error] [pid 45040:tid 45218] [client 14.225.17.146:55264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4cuLEFnm79ltp0SFA0vAAAAC4"], referer: http://partnerselectricalllc.com/2026
[Mon Jul 20 07:03:53.963773 2026] [http2:warn] [pid 29744:tid 29953] [client 57.141.18.72:54886] h2_stream(29744-1098-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:54.106589 2026] [http2:warn] [pid 29744:tid 29880] [client 57.141.18.81:28130] h2_stream(29744-1099-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:54.160148 2026] [security2:error] [pid 28702:tid 28867] [client 50.116.65.227:13488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4curF4957xPw9VVBnGQgAAAKc"]
[Mon Jul 20 07:03:54.175343 2026] [security2:error] [pid 28702:tid 28834] [client 50.116.65.227:13496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4curF4957xPw9VVBnGRAAAAIY"]
[Mon Jul 20 07:03:54.209667 2026] [security2:error] [pid 45040:tid 45259] [client 45.206.82.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0XAAAAFc"]
[Mon Jul 20 07:03:54.232286 2026] [security2:error] [pid 45040:tid 45194] [client 57.141.18.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4cuLEFnm79ltp0SFA0pgAAABY"]
[Mon Jul 20 07:03:54.270644 2026] [security2:error] [pid 45040:tid 45093] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/config/.env"] [unique_id "al4curEFnm79ltp0SFA0_QAAFTI"]
[Mon Jul 20 07:03:54.439112 2026] [security2:error] [pid 45040:tid 45208] [client 194.61.41.60:37669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-blog.php"] [unique_id "al4curEFnm79ltp0SFA1BAAAACQ"]
[Mon Jul 20 07:03:54.567566 2026] [security2:error] [pid 45040:tid 45264] [client 14.225.17.146:55295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4cubEFnm79ltp0SFA0wAAAAFw"], referer: http://kromosenergy.com/2026
[Mon Jul 20 07:03:54.890444 2026] [http2:warn] [pid 28702:tid 28850] [client 57.141.18.72:54896] h2_stream(28702-764-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:54.900068 2026] [http2:warn] [pid 29744:tid 29913] [client 57.141.18.80:44724] h2_stream(29744-1106-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:55.122114 2026] [security2:error] [pid 45040:tid 45265] [client 14.225.17.146:55758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4cubEFnm79ltp0SFA05AAAAF0"], referer: http://sarahsnyder.net/2026
[Mon Jul 20 07:03:55.179563 2026] [security2:error] [pid 28702:tid 28878] [client 77.110.127.138:62317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cu7F4957xPw9VVBnGcgAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:55.179735 2026] [security2:error] [pid 28702:tid 28878] [client 77.110.127.138:62317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cu7F4957xPw9VVBnGcgAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:55.223792 2026] [security2:error] [pid 45040:tid 45227] [client 194.61.41.65:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/file.php"] [unique_id "al4cu7EFnm79ltp0SFA1GAAAADc"]
[Mon Jul 20 07:03:55.403721 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:62315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cu7EFnm79ltp0SFA1FgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:55.426981 2026] [security2:error] [pid 28702:tid 28704] [remote 34.21.244.199:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cu7F4957xPw9VVBnGfwAA3wA"]
[Mon Jul 20 07:03:55.577817 2026] [security2:error] [pid 28702:tid 28914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cu7F4957xPw9VVBnGcwAAANY"]
[Mon Jul 20 07:03:55.725004 2026] [security2:error] [pid 45040:tid 45225] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cu7EFnm79ltp0SFA1HwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:55.754924 2026] [authz_core:error] [pid 45040:tid 45264] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Mon Jul 20 07:03:55.833016 2026] [security2:error] [pid 28702:tid 28805] [remote 34.21.244.199:6484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cu7F4957xPw9VVBnGjwAA02U"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:03:55.957540 2026] [security2:error] [pid 45040:tid 45294] [client 194.61.41.99:21037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/admin.php"] [unique_id "al4cu7EFnm79ltp0SFA1NgAAAHo"]
[Mon Jul 20 07:03:56.080028 2026] [security2:error] [pid 28702:tid 28931] [client 122.183.32.225:7189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cvLF4957xPw9VVBnGmwAAAOc"]
[Mon Jul 20 07:03:56.080113 2026] [security2:error] [pid 28702:tid 28931] [client 122.183.32.225:7189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cvLF4957xPw9VVBnGmwAAAOc"]
[Mon Jul 20 07:03:56.119923 2026] [security2:error] [pid 45040:tid 45187] [client 14.225.17.146:55193] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4cu7EFnm79ltp0SFA1OAAAAA8"], referer: https://sarahsnyder.net/2026
[Mon Jul 20 07:03:56.180426 2026] [security2:error] [pid 45040:tid 45255] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0cwAAAFM"]
[Mon Jul 20 07:03:56.192697 2026] [security2:error] [pid 45040:tid 45214] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0dAAAACo"]
[Mon Jul 20 07:03:56.197201 2026] [security2:error] [pid 28702:tid 28934] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7F4957xPw9VVBnF4gAAAOo"]
[Mon Jul 20 07:03:56.200341 2026] [security2:error] [pid 45040:tid 45173] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0cgAAAAE"]
[Mon Jul 20 07:03:56.214525 2026] [security2:error] [pid 45040:tid 45268] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0hQAAAGA"]
[Mon Jul 20 07:03:56.217009 2026] [security2:error] [pid 28702:tid 28936] [client 57.141.18.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4curF4957xPw9VVBnGVAAAAOw"]
[Mon Jul 20 07:03:56.218964 2026] [security2:error] [pid 45040:tid 45249] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0hAAAAE0"]
[Mon Jul 20 07:03:56.223611 2026] [security2:error] [pid 45040:tid 45201] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7EFnm79ltp0SFA0dQAAAB0"]
[Mon Jul 20 07:03:56.231525 2026] [security2:error] [pid 28702:tid 28935] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4ct7F4957xPw9VVBnF0gAAAOs"]
[Mon Jul 20 07:03:56.242895 2026] [security2:error] [pid 28702:tid 28953] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cuLF4957xPw9VVBnF7wAAAP0"]
[Mon Jul 20 07:03:56.272623 2026] [security2:error] [pid 28702:tid 28721] [remote 156.67.31.167:38836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cvLF4957xPw9VVBnGqQAAxxE"]
[Mon Jul 20 07:03:56.272793 2026] [security2:error] [pid 28702:tid 28899] [client 156.67.31.167:38836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cvLF4957xPw9VVBnGqQAAxxE"]
[Mon Jul 20 07:03:56.354490 2026] [security2:error] [pid 45040:tid 45270] [client 103.131.71.228:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1PAAAAGI"]
[Mon Jul 20 07:03:56.354517 2026] [security2:error] [pid 45040:tid 45270] [client 103.131.71.228:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1PAAAAGI"]
[Mon Jul 20 07:03:56.357317 2026] [security2:error] [pid 28702:tid 28908] [client 103.131.71.228:17663] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/robots.txt"] [unique_id "al4cvLF4957xPw9VVBnGnAAAANA"]
[Mon Jul 20 07:03:56.379554 2026] [security2:error] [pid 45040:tid 45242] [client 174.138.57.46:52032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4cvLEFnm79ltp0SFA1QgAAAEY"]
[Mon Jul 20 07:03:56.485655 2026] [security2:error] [pid 45040:tid 45095] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/service-account.json"] [unique_id "al4cvLEFnm79ltp0SFA1SwAAFTQ"]
[Mon Jul 20 07:03:56.485859 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "jenfarley.com"] [uri "/service-account.json"] [unique_id "al4cvLEFnm79ltp0SFA1SwAAFTQ"]
[Mon Jul 20 07:03:56.521930 2026] [http2:warn] [pid 29744:tid 29941] [client 57.141.18.29:46708] h2_stream(29744-1115-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:56.527171 2026] [security2:error] [pid 45040:tid 45100] [remote 5.252.52.249:36924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sergnotes.com"] [uri "/wp-login.php"] [unique_id "al4cvLEFnm79ltp0SFA1TwAAFDk"]
[Mon Jul 20 07:03:56.593423 2026] [security2:error] [pid 45040:tid 45101] [remote 91.142.222.105:50492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4cvLEFnm79ltp0SFA1UwAAHzo"]
[Mon Jul 20 07:03:56.626944 2026] [security2:error] [pid 45040:tid 45105] [remote 130.51.180.8:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4cvLEFnm79ltp0SFA1VAAAdz4"]
[Mon Jul 20 07:03:56.630744 2026] [security2:error] [pid 45040:tid 45172] [client 174.138.57.46:1220] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4cvLEFnm79ltp0SFA1VgAAAAA"]
[Mon Jul 20 07:03:56.724595 2026] [security2:error] [pid 45040:tid 45106] [remote 5.252.52.249:36924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sergnotes.com"] [uri "/wp-login.php"] [unique_id "al4cvLEFnm79ltp0SFA1ZQAAYD8"], referer: https://sergnotes.com/wp-login.php
[Mon Jul 20 07:03:56.766333 2026] [security2:error] [pid 45040:tid 45271] [client 168.144.100.227:60102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.100.144.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hfl.khd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4cvLEFnm79ltp0SFA1aAAAAGM"], referer: https://heyitsruss.com//wp-login.php
[Mon Jul 20 07:03:56.769766 2026] [security2:error] [pid 45040:tid 45259] [client 194.61.41.58:33623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/blocks/table/int/tmpl/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1ZgAAAFc"]
[Mon Jul 20 07:03:56.798298 2026] [security2:error] [pid 45040:tid 45110] [remote 130.51.180.8:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4cvLEFnm79ltp0SFA1agAASUM"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 07:03:56.835952 2026] [security2:error] [pid 45040:tid 45109] [remote 91.142.222.105:50492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4cvLEFnm79ltp0SFA1awAAT0I"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 07:03:57.017759 2026] [http2:warn] [pid 28702:tid 28910] [client 57.141.18.93:49294] h2_stream(28702-773-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:57.018511 2026] [http2:warn] [pid 28702:tid 28919] [client 57.141.18.102:40298] h2_stream(28702-774-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:57.482896 2026] [security2:error] [pid 45040:tid 45218] [client 14.225.17.146:56296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4cvbEFnm79ltp0SFA1iQAAAC4"], referer: http://samdothan.org/2026
[Mon Jul 20 07:03:57.488500 2026] [security2:error] [pid 45040:tid 45121] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/graphql"] [unique_id "al4cvbEFnm79ltp0SFA1kwAAFU4"]
[Mon Jul 20 07:03:57.537382 2026] [security2:error] [pid 28702:tid 28912] [client 194.61.41.72:31289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-l0gin.php"] [unique_id "al4cvbF4957xPw9VVBnG0wAAANQ"]
[Mon Jul 20 07:03:57.556263 2026] [security2:error] [pid 45040:tid 45214] [client 66.249.65.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ferrellroofing.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1XwAAACo"]
[Mon Jul 20 07:03:57.603838 2026] [http2:warn] [pid 29744:tid 29996] [client 57.141.18.102:40302] h2_stream(29744-1125-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:57.668119 2026] [security2:error] [pid 28702:tid 28858] [client 117.222.139.248:53676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cvbF4957xPw9VVBnG2AAAAJ4"]
[Mon Jul 20 07:03:57.668241 2026] [security2:error] [pid 28702:tid 28858] [client 117.222.139.248:53676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cvbF4957xPw9VVBnG2AAAAJ4"]
[Mon Jul 20 07:03:57.755365 2026] [security2:error] [pid 45040:tid 45123] [remote 5.161.225.162:34932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4cvbEFnm79ltp0SFA1nQAAFlA"]
[Mon Jul 20 07:03:57.909537 2026] [security2:error] [pid 45040:tid 45125] [remote 82.223.97.42:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cvbEFnm79ltp0SFA1rQAAJVI"]
[Mon Jul 20 07:03:57.914560 2026] [http2:warn] [pid 29744:tid 29904] [client 57.141.18.45:55108] h2_stream(29744-1127-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:57.975116 2026] [security2:error] [pid 45040:tid 45131] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/api/graphql"] [unique_id "al4cvbEFnm79ltp0SFA1rwAAFVg"]
[Mon Jul 20 07:03:58.046094 2026] [security2:error] [pid 28702:tid 28833] [client 14.225.17.146:56775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4cvbF4957xPw9VVBnGvwAAAIU"], referer: http://ancestralidadytrance.space/2026
[Mon Jul 20 07:03:58.070333 2026] [security2:error] [pid 28702:tid 28894] [client 77.110.127.138:62326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cvbF4957xPw9VVBnG2wAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:58.121091 2026] [security2:error] [pid 45040:tid 45220] [client 117.247.108.24:12022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cvrEFnm79ltp0SFA1tAAAADA"]
[Mon Jul 20 07:03:58.121228 2026] [security2:error] [pid 45040:tid 45220] [client 117.247.108.24:12022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cvrEFnm79ltp0SFA1tAAAADA"]
[Mon Jul 20 07:03:58.148304 2026] [security2:error] [pid 45040:tid 45134] [remote 82.223.97.42:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4cvrEFnm79ltp0SFA1twAARls"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:03:58.253165 2026] [http2:warn] [pid 28702:tid 28852] [client 57.141.18.91:49702] h2_stream(28702-779-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:58.297705 2026] [security2:error] [pid 45040:tid 45244] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cvbEFnm79ltp0SFA1qAAAAEg"]
[Mon Jul 20 07:03:58.318030 2026] [security2:error] [pid 45040:tid 45207] [client 194.61.41.58:39065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/jquery/suggest.php"] [unique_id "al4cvrEFnm79ltp0SFA1vwAAACM"]
[Mon Jul 20 07:03:58.333219 2026] [security2:error] [pid 45040:tid 45205] [client 14.251.3.155:54894] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4cvrEFnm79ltp0SFA1wQAAACE"]
[Mon Jul 20 07:03:58.371860 2026] [security2:error] [pid 45040:tid 45135] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jenfarley.com"] [uri "/v1/graphql"] [unique_id "al4cvrEFnm79ltp0SFA1yAAAFVw"]
[Mon Jul 20 07:03:58.452996 2026] [security2:error] [pid 28702:tid 28948] [client 103.144.65.217:64127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cvrF4957xPw9VVBnHAwAAAPg"]
[Mon Jul 20 07:03:58.454019 2026] [security2:error] [pid 28702:tid 28948] [client 103.144.65.217:64127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cvrF4957xPw9VVBnHAwAAAPg"]
[Mon Jul 20 07:03:58.573420 2026] [security2:error] [pid 45040:tid 45175] [client 103.131.71.228:0] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4cvrEFnm79ltp0SFA1zQAAAAM"]
[Mon Jul 20 07:03:58.587504 2026] [security2:error] [pid 28702:tid 28923] [client 103.131.71.228:22041] ModSecurity: Warning. Matched phrase "coccocbot-web" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.secretkeynumerology.com"] [uri "/robots.txt"] [unique_id "al4cvrF4957xPw9VVBnG-gAAAN8"]
[Mon Jul 20 07:03:58.625596 2026] [security2:error] [pid 45040:tid 45228] [client 14.225.17.146:53313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4cvrEFnm79ltp0SFA1swAAADg"], referer: http://idigress.group/2026
[Mon Jul 20 07:03:58.763653 2026] [security2:error] [pid 45040:tid 45137] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "jenfarley.com"] [uri "/.htpasswd"] [unique_id "al4cvrEFnm79ltp0SFA11AAAFV4"]
[Mon Jul 20 07:03:58.881798 2026] [http2:warn] [pid 28702:tid 28898] [client 57.141.18.96:48208] h2_stream(28702-781-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:03:58.984504 2026] [security2:error] [pid 45040:tid 45206] [client 77.110.127.138:62333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cvrEFnm79ltp0SFA13AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:58.984589 2026] [security2:error] [pid 45040:tid 45206] [client 77.110.127.138:62333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cvrEFnm79ltp0SFA13AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:59.073852 2026] [security2:error] [pid 45040:tid 45205] [client 194.61.41.107:25475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/new.php"] [unique_id "al4cv7EFnm79ltp0SFA13wAAACE"]
[Mon Jul 20 07:03:59.202010 2026] [security2:error] [pid 45040:tid 45248] [client 216.24.212.53:42139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4cv7EFnm79ltp0SFA16QAAAEw"]
[Mon Jul 20 07:03:59.202045 2026] [security2:error] [pid 45040:tid 45214] [client 216.24.212.53:30127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4cv7EFnm79ltp0SFA16AAAACo"]
[Mon Jul 20 07:03:59.223282 2026] [security2:error] [pid 45040:tid 45189] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cubEFnm79ltp0SFA09QAAABE"]
[Mon Jul 20 07:03:59.324786 2026] [security2:error] [pid 45040:tid 45140] [remote 5.161.225.162:34932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4cv7EFnm79ltp0SFA16wAAMGE"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 07:03:59.425576 2026] [security2:error] [pid 28702:tid 28907] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cv7F4957xPw9VVBnHFgAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:03:59.434503 2026] [security2:error] [pid 45040:tid 45200] [client 183.82.98.154:57518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cv7EFnm79ltp0SFA1-AAAABw"]
[Mon Jul 20 07:03:59.434586 2026] [security2:error] [pid 45040:tid 45200] [client 183.82.98.154:57518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cv7EFnm79ltp0SFA1-AAAABw"]
[Mon Jul 20 07:03:59.751010 2026] [security2:error] [pid 45040:tid 45177] [client 147.93.171.187:52513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "al4cv7EFnm79ltp0SFA2CAAAAAU"], referer: binance.com
[Mon Jul 20 07:03:59.839430 2026] [security2:error] [pid 45040:tid 45246] [client 194.61.41.73:41663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd-1/admin.php"] [unique_id "al4cv7EFnm79ltp0SFA2CwAAAEo"]
[Mon Jul 20 07:04:00.065019 2026] [http2:warn] [pid 29744:tid 29986] [client 57.141.18.43:33742] h2_stream(29744-1141-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:00.106090 2026] [security2:error] [pid 45040:tid 45201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cv7EFnm79ltp0SFA18gAAAB0"]
[Mon Jul 20 07:04:00.152711 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4curEFnm79ltp0SFA1DQAAFTU"]
[Mon Jul 20 07:04:00.301904 2026] [security2:error] [pid 45040:tid 45233] [client 77.110.127.138:62340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cv7EFnm79ltp0SFA1-wAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:00.658245 2026] [security2:error] [pid 28702:tid 28835] [client 194.61.41.65:41755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/defaults.php"] [unique_id "al4cwLF4957xPw9VVBnHRQAAAIc"]
[Mon Jul 20 07:04:00.823183 2026] [http2:warn] [pid 28702:tid 28843] [client 57.141.18.7:31590] h2_stream(28702-791-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:01.010421 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:62343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cwbEFnm79ltp0SFA2MQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:01.010530 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:62343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cwbEFnm79ltp0SFA2MQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:01.410941 2026] [http2:warn] [pid 29744:tid 29965] [client 57.141.18.101:24044] h2_stream(29744-1151-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:01.464115 2026] [security2:error] [pid 28702:tid 28906] [client 194.61.41.89:38653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/DJP9.php"] [unique_id "al4cwbF4957xPw9VVBnHXAAAAM4"]
[Mon Jul 20 07:04:01.633506 2026] [security2:error] [pid 28702:tid 28863] [client 14.225.17.146:53045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4cwLF4957xPw9VVBnHMAAAAKM"], referer: http://margaretspeckogawa.com/2026
[Mon Jul 20 07:04:01.790543 2026] [http2:warn] [pid 29744:tid 29882] [client 57.141.18.93:44122] h2_stream(29744-1154-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:02.037818 2026] [security2:error] [pid 45040:tid 45210] [client 50.116.65.227:16910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4cwrEFnm79ltp0SFA2hQAAACY"]
[Mon Jul 20 07:04:02.042002 2026] [security2:error] [pid 45040:tid 45274] [client 14.225.17.146:53195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4cwLEFnm79ltp0SFA2IAAAAGY"]
[Mon Jul 20 07:04:02.075776 2026] [security2:error] [pid 45040:tid 45234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cwbEFnm79ltp0SFA2PgAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:02.111176 2026] [security2:error] [pid 45040:tid 45253] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cwbEFnm79ltp0SFA2QAAAAFE"]
[Mon Jul 20 07:04:02.135031 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1WQAAFTw"]
[Mon Jul 20 07:04:02.139982 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1bQAAFUc"]
[Mon Jul 20 07:04:02.147145 2026] [security2:error] [pid 28702:tid 28933] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLF4957xPw9VVBnGuQAAAOk"]
[Mon Jul 20 07:04:02.148005 2026] [security2:error] [pid 45040:tid 45217] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1VQAAAC0"]
[Mon Jul 20 07:04:02.155622 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1cwAAFUs"]
[Mon Jul 20 07:04:02.162489 2026] [security2:error] [pid 28702:tid 28926] [client 77.110.127.138:62350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cwbF4957xPw9VVBnHWQAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:02.165954 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1WgAAFUE"]
[Mon Jul 20 07:04:02.171862 2026] [security2:error] [pid 45040:tid 45260] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1eQAAAFg"]
[Mon Jul 20 07:04:02.172528 2026] [security2:error] [pid 45040:tid 45193] [client 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLEFnm79ltp0SFA1cgAAFUg"]
[Mon Jul 20 07:04:02.195439 2026] [security2:error] [pid 28702:tid 28869] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cvLF4957xPw9VVBnGugAAAKk"]
[Mon Jul 20 07:04:02.233560 2026] [security2:error] [pid 45040:tid 45276] [client 194.61.41.253:29351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2mgAAAGg"]
[Mon Jul 20 07:04:02.303166 2026] [security2:error] [pid 45040:tid 45099] [remote 47.86.33.52:18708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4cwrEFnm79ltp0SFA2owAAVDg"]
[Mon Jul 20 07:04:02.342007 2026] [http2:warn] [pid 29744:tid 29932] [client 57.141.18.101:24054] h2_stream(29744-1161-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:02.346673 2026] [security2:error] [pid 28702:tid 28871] [client 77.110.127.138:62352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cwrF4957xPw9VVBnHdQAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:02.346786 2026] [security2:error] [pid 28702:tid 28871] [client 77.110.127.138:62352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cwrF4957xPw9VVBnHdQAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:02.388904 2026] [http2:warn] [pid 29744:tid 29889] [client 57.141.18.63:42516] h2_stream(29744-1162-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:02.561948 2026] [security2:error] [pid 45040:tid 45123] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.ssh/id_rsa"] [unique_id "al4cwrEFnm79ltp0SFA2wgAAFVA"]
[Mon Jul 20 07:04:02.562046 2026] [security2:error] [pid 45040:tid 45128] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/.ssh/id_dsa"] [unique_id "al4cwrEFnm79ltp0SFA2xAAAFVU"]
[Mon Jul 20 07:04:02.744215 2026] [security2:error] [pid 45040:tid 45290] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2sgAAAHY"]
[Mon Jul 20 07:04:02.794637 2026] [security2:error] [pid 45040:tid 45260] [client 187.16.64.216:56920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cwrEFnm79ltp0SFA24AAAAFg"]
[Mon Jul 20 07:04:02.794744 2026] [security2:error] [pid 45040:tid 45260] [client 187.16.64.216:56920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4cwrEFnm79ltp0SFA24AAAAFg"]
[Mon Jul 20 07:04:02.821096 2026] [security2:error] [pid 45040:tid 45293] [client 77.110.127.138:62331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cwrEFnm79ltp0SFA24gAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:02.821231 2026] [security2:error] [pid 45040:tid 45293] [client 77.110.127.138:62331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cwrEFnm79ltp0SFA24gAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:02.930293 2026] [security2:error] [pid 45040:tid 45162] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/id_dsa"] [unique_id "al4cwrEFnm79ltp0SFA27QAAFXc"]
[Mon Jul 20 07:04:02.999463 2026] [security2:error] [pid 45040:tid 45122] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/id_rsa"] [unique_id "al4cwrEFnm79ltp0SFA29wAAFU8"]
[Mon Jul 20 07:04:03.029802 2026] [security2:error] [pid 45040:tid 45208] [client 194.61.41.65:60701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/shell20211028.php"] [unique_id "al4cw7EFnm79ltp0SFA2_AAAACQ"]
[Mon Jul 20 07:04:03.208961 2026] [security2:error] [pid 45040:tid 45228] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cv7EFnm79ltp0SFA18QAAADg"]
[Mon Jul 20 07:04:03.250556 2026] [security2:error] [pid 45040:tid 45236] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cv7EFnm79ltp0SFA2FwAAAEA"]
[Mon Jul 20 07:04:03.257005 2026] [security2:error] [pid 45040:tid 45219] [client 154.208.48.130:52628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cw7EFnm79ltp0SFA3EAAAAC8"]
[Mon Jul 20 07:04:03.257145 2026] [security2:error] [pid 45040:tid 45219] [client 154.208.48.130:52628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4cw7EFnm79ltp0SFA3EAAAAC8"]
[Mon Jul 20 07:04:03.275699 2026] [security2:error] [pid 45040:tid 45170] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "jenfarley.com"] [uri "/id_ecdsa"] [unique_id "al4cw7EFnm79ltp0SFA3EQAAFX8"]
[Mon Jul 20 07:04:03.352680 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA23wAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:03.477002 2026] [http2:warn] [pid 28702:tid 28897] [client 57.141.18.94:24480] h2_stream(28702-796-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:03.542094 2026] [security2:error] [pid 45040:tid 45224] [client 14.225.17.146:54506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4cwbEFnm79ltp0SFA2SgAAADQ"], referer: http://webgardensbypaula.com/2026
[Mon Jul 20 07:04:03.599564 2026] [security2:error] [pid 45040:tid 45056] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/key.pem"] [unique_id "al4cw7EFnm79ltp0SFA3LAAAFQ4"]
[Mon Jul 20 07:04:03.600127 2026] [security2:error] [pid 45040:tid 45053] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "jenfarley.com"] [uri "/privatekey.key"] [unique_id "al4cw7EFnm79ltp0SFA3LQAAFQs"]
[Mon Jul 20 07:04:03.749565 2026] [security2:error] [pid 45040:tid 45269] [client 14.225.17.146:53150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2mQAAAGE"], referer: http://slutilities.com/2026
[Mon Jul 20 07:04:03.756212 2026] [security2:error] [pid 28702:tid 28918] [client 194.61.41.54:51975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/natural.php"] [unique_id "al4cw7F4957xPw9VVBnHswAAANo"]
[Mon Jul 20 07:04:03.873109 2026] [security2:error] [pid 28702:tid 28906] [client 147.93.171.187:51468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "al4cw7F4957xPw9VVBnHuwAAAM4"], referer: binance.com
[Mon Jul 20 07:04:04.244596 2026] [security2:error] [pid 45040:tid 45195] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cwbEFnm79ltp0SFA2UQAAABc"]
[Mon Jul 20 07:04:04.270094 2026] [security2:error] [pid 28702:tid 28740] [remote 103.161.172.221:43004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cxLF4957xPw9VVBnHzAAAkiQ"]
[Mon Jul 20 07:04:04.274205 2026] [http2:warn] [pid 29744:tid 30002] [client 57.141.18.108:64328] h2_stream(29744-1170-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:04.493835 2026] [security2:error] [pid 28702:tid 28836] [client 14.225.17.146:54556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4cw7F4957xPw9VVBnHlAAAAIg"], referer: http://iagdevelopments.com/2026
[Mon Jul 20 07:04:04.580856 2026] [security2:error] [pid 45040:tid 45186] [client 194.61.41.61:37619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/item.php"] [unique_id "al4cxLEFnm79ltp0SFA3RgAAAA4"]
[Mon Jul 20 07:04:04.603174 2026] [http2:warn] [pid 28702:tid 28840] [client 57.141.18.58:39464] h2_stream(28702-801-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:04.687284 2026] [security2:error] [pid 45040:tid 45271] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxLEFnm79ltp0SFA3RAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:04.734681 2026] [security2:error] [pid 45040:tid 45075] [remote 8.217.108.67:26248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4cxLEFnm79ltp0SFA3VgAAWiA"]
[Mon Jul 20 07:04:05.091586 2026] [security2:error] [pid 28702:tid 28730] [remote 103.161.172.221:43004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4cxbF4957xPw9VVBnH9gAA6ho"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:04:05.206361 2026] [http2:warn] [pid 29744:tid 29894] [client 57.141.18.96:31598] h2_stream(29744-1178-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:05.252539 2026] [security2:error] [pid 45040:tid 45052] [remote 8.217.108.67:26248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4cxbEFnm79ltp0SFA3ZgAASgo"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 07:04:05.376764 2026] [security2:error] [pid 45040:tid 45241] [client 14.225.17.146:62946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4cxbEFnm79ltp0SFA3aQAAAEU"], referer: https://iagdevelopments.com/2026
[Mon Jul 20 07:04:05.390329 2026] [security2:error] [pid 45040:tid 45194] [client 194.61.41.66:61107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/function/function.php"] [unique_id "al4cxbEFnm79ltp0SFA3agAAABY"]
[Mon Jul 20 07:04:05.433572 2026] [security2:error] [pid 45040:tid 45232] [client 77.110.127.138:62345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxbEFnm79ltp0SFA3YwAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:05.668611 2026] [security2:error] [pid 28702:tid 28887] [client 77.110.127.138:62365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/motif/zm5hmu2fv28c.php"] [unique_id "al4cxbF4957xPw9VVBnIGAAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:05.826703 2026] [security2:error] [pid 45040:tid 45181] [client 77.110.127.138:62371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cxbEFnm79ltp0SFA3gQAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:05.826829 2026] [security2:error] [pid 45040:tid 45181] [client 77.110.127.138:62371] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cxbEFnm79ltp0SFA3gQAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:05.836045 2026] [security2:error] [pid 28702:tid 28890] [client 77.110.127.138:62350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxbF4957xPw9VVBnIEAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:05.888720 2026] [security2:error] [pid 45040:tid 45236] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxbEFnm79ltp0SFA3dwAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:06.146270 2026] [security2:error] [pid 45040:tid 45245] [client 194.61.41.100:43443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/index.php"] [unique_id "al4cxrEFnm79ltp0SFA3lwAAAEk"]
[Mon Jul 20 07:04:06.186795 2026] [security2:error] [pid 45040:tid 45196] [client 185.223.152.46:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "goodtravelfun.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4cxrEFnm79ltp0SFA3mAAAABg"]
[Mon Jul 20 07:04:06.227714 2026] [http2:warn] [pid 28702:tid 28903] [client 57.141.18.90:42818] h2_stream(28702-807-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:06.235552 2026] [security2:error] [pid 45040:tid 45277] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2yQAAAGk"]
[Mon Jul 20 07:04:06.235897 2026] [security2:error] [pid 45040:tid 45248] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2yAAAAEw"]
[Mon Jul 20 07:04:06.236996 2026] [security2:error] [pid 45040:tid 45295] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cw7EFnm79ltp0SFA2_wAAAHs"]
[Mon Jul 20 07:04:06.244335 2026] [security2:error] [pid 45040:tid 45235] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2xwAAAD8"]
[Mon Jul 20 07:04:06.244538 2026] [security2:error] [pid 45040:tid 45212] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA26wAAACg"]
[Mon Jul 20 07:04:06.255634 2026] [security2:error] [pid 45040:tid 45089] [remote 217.61.143.92:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4cxrEFnm79ltp0SFA3mwAANC4"]
[Mon Jul 20 07:04:06.260368 2026] [security2:error] [pid 45040:tid 45087] [remote 104.28.251.199:14397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA2vQAAFSw"]
[Mon Jul 20 07:04:06.263499 2026] [security2:error] [pid 45040:tid 45292] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cw7EFnm79ltp0SFA2_gAAAHg"]
[Mon Jul 20 07:04:06.330223 2026] [qos:error] [pid 45040:tid 45274] [client 50.116.65.227:51800] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=50.116.65.227, id=al4cxrEFnm79ltp0SFA3nwAAAGY
[Mon Jul 20 07:04:06.332104 2026] [security2:error] [pid 29744:tid 29821] [remote 57.141.18.76:58564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cR-GINCUUz5GA9YIttQACeUs"]
[Mon Jul 20 07:04:06.528703 2026] [security2:error] [pid 45040:tid 45060] [remote 217.61.143.92:53120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4cxrEFnm79ltp0SFA3owAAfRI"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 07:04:06.680603 2026] [security2:error] [pid 45040:tid 45263] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxbEFnm79ltp0SFA3eAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:06.748829 2026] [security2:error] [pid 28702:tid 28709] [remote 81.173.115.7:55874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4cxrF4957xPw9VVBnIOgAAkgU"]
[Mon Jul 20 07:04:06.826036 2026] [security2:error] [pid 45040:tid 45201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxbEFnm79ltp0SFA3iQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:06.827736 2026] [security2:error] [pid 28702:tid 28848] [client 158.173.166.181:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cxrF4957xPw9VVBnIPAAAAJQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:04:06.831357 2026] [http2:warn] [pid 29744:tid 29957] [client 57.141.18.55:26838] h2_stream(29744-1188-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:06.860524 2026] [security2:error] [pid 45040:tid 45200] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxrEFnm79ltp0SFA3jAAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:06.860723 2026] [security2:error] [pid 28702:tid 28942] [client 14.225.17.146:54519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4cxbF4957xPw9VVBnH-QAAAPI"], referer: http://nomorewetsheets.net/2026
[Mon Jul 20 07:04:06.921039 2026] [security2:error] [pid 45040:tid 45241] [client 194.61.41.75:60295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/admin.php"] [unique_id "al4cxrEFnm79ltp0SFA3tgAAAEU"]
[Mon Jul 20 07:04:06.947166 2026] [security2:error] [pid 28702:tid 28790] [remote 81.173.115.7:55874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colinkeyphotography.com"] [uri "/wp-login.php"] [unique_id "al4cxrF4957xPw9VVBnIRQAArFY"], referer: https://colinkeyphotography.com/wp-login.php
[Mon Jul 20 07:04:06.950240 2026] [security2:error] [pid 28702:tid 28920] [client 77.110.127.138:62376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxrF4957xPw9VVBnIJwAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:07.100415 2026] [security2:error] [pid 45040:tid 45265] [client 50.116.65.227:28882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4cx7EFnm79ltp0SFA3wAAAAF0"]
[Mon Jul 20 07:04:07.112209 2026] [security2:error] [pid 28702:tid 28835] [client 50.116.65.227:28884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4cx7F4957xPw9VVBnISwAAAIc"]
[Mon Jul 20 07:04:07.135617 2026] [security2:error] [pid 28702:tid 28873] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cw7F4957xPw9VVBnHlQAAAK0"]
[Mon Jul 20 07:04:07.197724 2026] [security2:error] [pid 28702:tid 28922] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cw7F4957xPw9VVBnHqwAAAN4"]
[Mon Jul 20 07:04:07.285598 2026] [security2:error] [pid 45040:tid 45224] [client 49.51.245.243:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4cx7EFnm79ltp0SFA3wQAANDI"], referer: https://www.aleishapenny.ca/listing/page/1234?paged=1&view=grid&posts_per_page=24
[Mon Jul 20 07:04:07.335200 2026] [security2:error] [pid 45040:tid 45262] [client 77.110.127.138:62341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cx7EFnm79ltp0SFA3ygAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:07.335359 2026] [security2:error] [pid 45040:tid 45262] [client 77.110.127.138:62341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cx7EFnm79ltp0SFA3ygAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:07.366643 2026] [security2:error] [pid 28702:tid 28899] [client 77.110.127.138:62390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-videos/b3lfsbileoxx.php"] [unique_id "al4cx7F4957xPw9VVBnIWQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:07.396390 2026] [http2:warn] [pid 28702:tid 28902] [client 57.141.18.106:60548] h2_stream(28702-813-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:07.549550 2026] [security2:error] [pid 45040:tid 45204] [client 14.225.17.146:64964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4cx7EFnm79ltp0SFA3vAAAACA"], referer: http://overloadcomedy.com/2026
[Mon Jul 20 07:04:07.575390 2026] [http2:warn] [pid 29744:tid 29987] [client 57.141.18.51:23044] h2_stream(29744-1196-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:07.601442 2026] [security2:error] [pid 45040:tid 45174] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cxrEFnm79ltp0SFA3uQAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:07.647807 2026] [security2:error] [pid 28702:tid 28927] [client 14.225.17.146:57999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4cx7F4957xPw9VVBnIYgAAAOM"], referer: http://alexsandbergmusic.com/2026
[Mon Jul 20 07:04:07.653590 2026] [security2:error] [pid 28702:tid 28937] [client 194.61.41.99:50829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/theme-compat/about.php"] [unique_id "al4cx7F4957xPw9VVBnIbgAAAO0"]
[Mon Jul 20 07:04:07.855793 2026] [security2:error] [pid 28702:tid 28861] [client 77.110.127.138:62353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cx7F4957xPw9VVBnIVgAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:07.981115 2026] [http2:warn] [pid 29744:tid 29877] [client 57.141.18.62:21638] h2_stream(29744-1202-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:08.037565 2026] [security2:error] [pid 28702:tid 28958] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cx7F4957xPw9VVBnIXgAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.047049 2026] [proxy:error] [pid 45040:tid 45294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:08.047089 2026] [proxy_http:error] [pid 45040:tid 45294] [client 107.172.180.205:34584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:08.047499 2026] [proxy:error] [pid 45040:tid 45294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:08.047522 2026] [proxy_http:error] [pid 45040:tid 45294] [client 107.172.180.205:34584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:08.082226 2026] [security2:error] [pid 28702:tid 28926] [client 77.110.127.138:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/private-crochet-tuition-follow-up-sessions-or-advanced-students/qoywi5hlt79o.php"] [unique_id "al4cyLF4957xPw9VVBnIigAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.275565 2026] [security2:error] [pid 28702:tid 28931] [client 147.93.171.187:50534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "al4cyLF4957xPw9VVBnIlwAAAOc"], referer: binance.com
[Mon Jul 20 07:04:08.302369 2026] [security2:error] [pid 45040:tid 45206] [client 185.238.231.131:61065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4cyLEFnm79ltp0SFA39wAAACI"]
[Mon Jul 20 07:04:08.310926 2026] [security2:error] [pid 28702:tid 28864] [client 185.238.231.163:28265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4cyLF4957xPw9VVBnIjwAAAKQ"]
[Mon Jul 20 07:04:08.366942 2026] [security2:error] [pid 28702:tid 28915] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cx7F4957xPw9VVBnIaQAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.448320 2026] [security2:error] [pid 45040:tid 45232] [client 194.61.41.84:41667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/about/function.php"] [unique_id "al4cyLEFnm79ltp0SFA4DgAAADw"]
[Mon Jul 20 07:04:08.449606 2026] [security2:error] [pid 45040:tid 45263] [client 173.252.95.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ladybugscoops.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA4AwAAAFs"], referer: http://ladybugscoops.com/?fbclid=IwZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMjU2MjgxMDQwNTU4AAEem7mZOrOGdCSk4fEUW7_IeOyag0SJJ_BjcLwWOY2FzI04UOChp9E4hVZ0HMs_aem_z9IHebTLXB0scCzI-qxK4w
[Mon Jul 20 07:04:08.475937 2026] [security2:error] [pid 45040:tid 45257] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA39AAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.491929 2026] [security2:error] [pid 28702:tid 28861] [client 77.110.127.138:62361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/online-courses/qx9ow8r506ev.php"] [unique_id "al4cyLF4957xPw9VVBnIoQAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.511052 2026] [security2:error] [pid 45040:tid 45250] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA37wAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.547343 2026] [security2:error] [pid 28702:tid 28904] [client 77.110.127.138:62350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLF4957xPw9VVBnIhwAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:08.597711 2026] [security2:error] [pid 45040:tid 45235] [client 14.225.17.146:63036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4cx7EFnm79ltp0SFA3yQAAAD8"], referer: http://keywayconstructionclt.com/2026
[Mon Jul 20 07:04:08.716326 2026] [proxy:error] [pid 28702:tid 28901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:08.716382 2026] [proxy_http:error] [pid 28702:tid 28901] [client 107.172.180.205:34608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:08.718086 2026] [proxy:error] [pid 28702:tid 28901] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:08.718140 2026] [proxy_http:error] [pid 28702:tid 28901] [client 107.172.180.205:34608] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:08.790454 2026] [http2:warn] [pid 29744:tid 29928] [client 57.141.18.98:22764] h2_stream(29744-1208-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:08.916527 2026] [security2:error] [pid 45040:tid 45243] [client 117.247.108.24:1806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cyLEFnm79ltp0SFA4LQAAAEc"]
[Mon Jul 20 07:04:08.916664 2026] [security2:error] [pid 45040:tid 45243] [client 117.247.108.24:1806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4cyLEFnm79ltp0SFA4LQAAAEc"]
[Mon Jul 20 07:04:08.966435 2026] [security2:error] [pid 45040:tid 45177] [client 103.144.65.217:64580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cyLEFnm79ltp0SFA4MAAAAAU"]
[Mon Jul 20 07:04:08.966610 2026] [security2:error] [pid 45040:tid 45177] [client 103.144.65.217:64580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4cyLEFnm79ltp0SFA4MAAAAAU"]
[Mon Jul 20 07:04:09.221600 2026] [security2:error] [pid 28702:tid 28844] [client 117.222.139.248:54197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cybF4957xPw9VVBnIxgAAAJA"]
[Mon Jul 20 07:04:09.221727 2026] [security2:error] [pid 28702:tid 28844] [client 117.222.139.248:54197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4cybF4957xPw9VVBnIxgAAAJA"]
[Mon Jul 20 07:04:09.224419 2026] [security2:error] [pid 28702:tid 28918] [client 194.61.41.249:41337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/index.php"] [unique_id "al4cybF4957xPw9VVBnIxwAAANo"]
[Mon Jul 20 07:04:09.249612 2026] [security2:error] [pid 45040:tid 45298] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA4DwAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:09.260413 2026] [security2:error] [pid 45040:tid 45234] [client 77.110.127.138:62372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/doilies/ovs8n3th7rqd.php"] [unique_id "al4cybEFnm79ltp0SFA4OgAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:09.293108 2026] [security2:error] [pid 45040:tid 45292] [client 77.110.127.138:62363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA4EQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:09.295927 2026] [security2:error] [pid 45040:tid 45297] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA4EwAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:09.329561 2026] [http2:warn] [pid 28702:tid 28884] [client 57.141.18.31:50810] h2_stream(28702-816-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:09.413646 2026] [security2:error] [pid 45040:tid 45207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyLEFnm79ltp0SFA4HwAAACM"]
[Mon Jul 20 07:04:09.519618 2026] [security2:error] [pid 45040:tid 45065] [remote 50.28.1.50:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cybEFnm79ltp0SFA4SwAACRY"]
[Mon Jul 20 07:04:09.550426 2026] [autoindex:error] [pid 45040:tid 45201] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:09.585579 2026] [autoindex:error] [pid 45040:tid 45174] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:04:09.619548 2026] [security2:error] [pid 45040:tid 45051] [remote 20.153.140.50:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cybEFnm79ltp0SFA4WwAADQk"]
[Mon Jul 20 07:04:09.670260 2026] [http2:warn] [pid 29744:tid 29890] [client 57.141.18.23:60932] h2_stream(29744-1215-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:09.723465 2026] [security2:error] [pid 45040:tid 45151] [remote 50.28.1.50:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4cybEFnm79ltp0SFA4ZAAASGw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:04:09.731356 2026] [security2:error] [pid 45040:tid 45267] [client 77.110.127.138:62425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2024/twrtt1ljamqb.php"] [unique_id "al4cybEFnm79ltp0SFA4ZQAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:10.026583 2026] [http2:warn] [pid 29744:tid 29983] [client 57.141.18.106:60560] h2_stream(29744-1217-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:10.044058 2026] [security2:error] [pid 45040:tid 45264] [client 192.140.149.97:45970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cyrEFnm79ltp0SFA4igAAAFw"]
[Mon Jul 20 07:04:10.044195 2026] [security2:error] [pid 45040:tid 45264] [client 192.140.149.97:45970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4cyrEFnm79ltp0SFA4igAAAFw"]
[Mon Jul 20 07:04:10.061370 2026] [security2:error] [pid 45040:tid 45229] [client 194.61.41.86:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/about.php/wp-content/x/index.php"] [unique_id "al4cyrEFnm79ltp0SFA4iwAAADk"]
[Mon Jul 20 07:04:10.091622 2026] [security2:error] [pid 45040:tid 45063] [remote 20.153.140.50:37542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4cyrEFnm79ltp0SFA4jAAACxU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:04:10.313895 2026] [security2:error] [pid 45040:tid 45184] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cybEFnm79ltp0SFA4PAAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:10.341279 2026] [security2:error] [pid 45040:tid 45230] [client 77.110.127.138:62328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cybEFnm79ltp0SFA4QQAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:10.430958 2026] [security2:error] [pid 45040:tid 45218] [client 183.82.98.154:58115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cyrEFnm79ltp0SFA4pQAAAC4"]
[Mon Jul 20 07:04:10.431079 2026] [security2:error] [pid 45040:tid 45218] [client 183.82.98.154:58115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4cyrEFnm79ltp0SFA4pQAAAC4"]
[Mon Jul 20 07:04:10.434849 2026] [security2:error] [pid 45040:tid 45287] [client 14.225.17.146:58144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4cyrEFnm79ltp0SFA4mAAAAHM"], referer: http://adultdaycarereno.com/2026
[Mon Jul 20 07:04:10.435693 2026] [security2:error] [pid 45040:tid 45241] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cybEFnm79ltp0SFA4VwAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:10.449126 2026] [security2:error] [pid 45040:tid 45174] [client 74.7.227.179:58894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4cyrEFnm79ltp0SFA4lQAAAnI"], referer: https://tejasenvironmental.com/p=936361
[Mon Jul 20 07:04:10.527265 2026] [security2:error] [pid 28702:tid 28958] [client 77.110.127.138:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cyrF4957xPw9VVBnJAQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:10.527394 2026] [security2:error] [pid 28702:tid 28958] [client 77.110.127.138:62394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4cyrF4957xPw9VVBnJAQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:10.757633 2026] [security2:error] [pid 28702:tid 28743] [remote 182.77.62.24:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4cyrF4957xPw9VVBnJBwAA1yc"]
[Mon Jul 20 07:04:10.824590 2026] [security2:error] [pid 45040:tid 45184] [client 194.61.41.106:39307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4cyrEFnm79ltp0SFA4vQAAAAw"]
[Mon Jul 20 07:04:10.872536 2026] [security2:error] [pid 45040:tid 45219] [client 14.225.17.146:57847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4cyrEFnm79ltp0SFA4sgAAAC8"], referer: http://secretkeynumerology.com/2026
[Mon Jul 20 07:04:11.093288 2026] [security2:error] [pid 45040:tid 45249] [client 104.207.50.248:46221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4cy7EFnm79ltp0SFA4wQAAAE0"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:11.097614 2026] [security2:error] [pid 45040:tid 45265] [client 104.234.53.59:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4cy7EFnm79ltp0SFA4wwAAAF0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:11.150103 2026] [security2:error] [pid 45040:tid 45273] [client 77.110.127.138:62385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cybEFnm79ltp0SFA4ZgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:11.152708 2026] [security2:error] [pid 45040:tid 45225] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cybEFnm79ltp0SFA4RgAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:11.221773 2026] [security2:error] [pid 45040:tid 45197] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cybEFnm79ltp0SFA4gQAAABk"]
[Mon Jul 20 07:04:11.261768 2026] [http2:warn] [pid 29744:tid 29979] [client 57.141.18.51:23060] h2_stream(29744-1232-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:11.289820 2026] [autoindex:error] [pid 28702:tid 28837] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/01/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:04:11.291998 2026] [autoindex:error] [pid 28702:tid 28877] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/01/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:11.317223 2026] [security2:error] [pid 45040:tid 45279] [client 14.225.17.146:62925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4cy7EFnm79ltp0SFA4zgAAAGs"], referer: https://adultdaycarereno.com/2026
[Mon Jul 20 07:04:11.352335 2026] [security2:error] [pid 45040:tid 45218] [client 98.159.234.160:25689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4cy7EFnm79ltp0SFA40wAAAC4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:04:11.427732 2026] [security2:error] [pid 45040:tid 45216] [client 77.110.127.138:62433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2024/01/ml8tcljg6qt8.php"] [unique_id "al4cy7EFnm79ltp0SFA43QAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:11.467313 2026] [security2:error] [pid 28702:tid 28809] [remote 182.77.62.24:52108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4cy7F4957xPw9VVBnJKgAAkWk"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 07:04:11.494262 2026] [autoindex:error] [pid 28702:tid 28918] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/01/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/about-mezzacraft-crochet/img_4196-2/
[Mon Jul 20 07:04:11.567218 2026] [security2:error] [pid 28702:tid 28887] [client 194.61.41.80:52393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/404.php"] [unique_id "al4cy7F4957xPw9VVBnJMAAAALs"]
[Mon Jul 20 07:04:11.567583 2026] [security2:error] [pid 45040:tid 45126] [remote 8.217.108.67:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4cy7EFnm79ltp0SFA45AAAPVM"]
[Mon Jul 20 07:04:11.768896 2026] [security2:error] [pid 28702:tid 28941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cyrF4957xPw9VVBnJCAAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:11.802453 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cy7EFnm79ltp0SFA4zwAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:12.138371 2026] [security2:error] [pid 28702:tid 28858] [client 77.110.127.138:62409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cy7F4957xPw9VVBnJJgAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:12.202891 2026] [security2:error] [pid 45040:tid 45291] [client 77.110.127.138:62404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cy7EFnm79ltp0SFA45wAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:12.257422 2026] [security2:error] [pid 45040:tid 45178] [client 77.110.127.138:62410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4czLEFnm79ltp0SFA4-AAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:12.257552 2026] [security2:error] [pid 45040:tid 45178] [client 77.110.127.138:62410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4czLEFnm79ltp0SFA4-AAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:12.321739 2026] [security2:error] [pid 28702:tid 28926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4cy7F4957xPw9VVBnJPgAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:12.350394 2026] [security2:error] [pid 45040:tid 45196] [client 194.61.41.102:56329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/update/403.php"] [unique_id "al4czLEFnm79ltp0SFA5AQAAABg"]
[Mon Jul 20 07:04:12.470327 2026] [http2:warn] [pid 29744:tid 29977] [client 57.141.18.95:34068] h2_stream(29744-1244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:12.519731 2026] [security2:error] [pid 45040:tid 45161] [remote 8.217.108.67:58128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4czLEFnm79ltp0SFA5GQAAMXY"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:04:12.546800 2026] [security2:error] [pid 45040:tid 45280] [client 85.208.96.198:51848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/how-to-seal-acrylic-paint-on-plastic-phone-cases/"] [unique_id "al4czLEFnm79ltp0SFA5HAAAAGw"]
[Mon Jul 20 07:04:12.546945 2026] [security2:error] [pid 45040:tid 45280] [client 85.208.96.198:51848] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/how-to-seal-acrylic-paint-on-plastic-phone-cases/"] [unique_id "al4czLEFnm79ltp0SFA5HAAAAGw"]
[Mon Jul 20 07:04:12.611768 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4czLEFnm79ltp0SFA5DwAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:13.033585 2026] [security2:error] [pid 45040:tid 45232] [client 147.93.171.187:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "al4czbEFnm79ltp0SFA5NQAAADw"], referer: binance.com
[Mon Jul 20 07:04:13.133112 2026] [security2:error] [pid 45040:tid 45260] [client 194.61.41.95:48809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/default.php"] [unique_id "al4czbEFnm79ltp0SFA5PQAAAFg"]
[Mon Jul 20 07:04:13.450911 2026] [security2:error] [pid 45040:tid 45250] [client 187.16.64.216:57494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4czbEFnm79ltp0SFA5RQAAAE4"]
[Mon Jul 20 07:04:13.451077 2026] [security2:error] [pid 45040:tid 45250] [client 187.16.64.216:57494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4czbEFnm79ltp0SFA5RQAAAE4"]
[Mon Jul 20 07:04:13.776725 2026] [security2:error] [pid 45040:tid 45238] [client 45.157.112.60:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4czbEFnm79ltp0SFA5UAAAAEI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:04:13.872041 2026] [security2:error] [pid 28702:tid 28878] [client 104.234.53.89:49205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4czbF4957xPw9VVBnJjwAAALI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:13.926772 2026] [security2:error] [pid 45040:tid 45295] [client 194.61.41.102:60873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/info.php"] [unique_id "al4czbEFnm79ltp0SFA5UgAAAHs"]
[Mon Jul 20 07:04:14.322923 2026] [security2:error] [pid 45040:tid 45225] [client 154.208.48.130:53139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4czrEFnm79ltp0SFA5XQAAADU"]
[Mon Jul 20 07:04:14.323041 2026] [security2:error] [pid 45040:tid 45225] [client 154.208.48.130:53139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4czrEFnm79ltp0SFA5XQAAADU"]
[Mon Jul 20 07:04:14.617067 2026] [security2:error] [pid 45040:tid 45226] [client 77.110.127.138:62374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4czrEFnm79ltp0SFA5XgAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:14.675109 2026] [security2:error] [pid 45040:tid 45236] [client 77.110.127.138:62328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4czrEFnm79ltp0SFA5eQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:14.675219 2026] [security2:error] [pid 45040:tid 45236] [client 77.110.127.138:62328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4czrEFnm79ltp0SFA5eQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:14.695461 2026] [security2:error] [pid 45040:tid 45173] [client 57.141.18.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4czrEFnm79ltp0SFA5ZwAAAAE"]
[Mon Jul 20 07:04:14.724328 2026] [security2:error] [pid 45040:tid 45292] [client 194.61.41.87:36893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class.api.php"] [unique_id "al4czrEFnm79ltp0SFA5fAAAAHg"]
[Mon Jul 20 07:04:15.035542 2026] [security2:error] [pid 45040:tid 45222] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4czrEFnm79ltp0SFA5cQAAADI"]
[Mon Jul 20 07:04:15.078199 2026] [security2:error] [pid 45040:tid 45273] [client 122.183.32.225:25554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cz7EFnm79ltp0SFA5iwAAAGU"]
[Mon Jul 20 07:04:15.078345 2026] [security2:error] [pid 45040:tid 45273] [client 122.183.32.225:25554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4cz7EFnm79ltp0SFA5iwAAAGU"]
[Mon Jul 20 07:04:15.084209 2026] [security2:error] [pid 45040:tid 45252] [client 14.225.17.146:62760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4czbEFnm79ltp0SFA5TQAAAFA"], referer: http://alaraycreative.com/2026
[Mon Jul 20 07:04:15.140169 2026] [security2:error] [pid 45040:tid 45216] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4czrEFnm79ltp0SFA5egAAACw"]
[Mon Jul 20 07:04:15.212126 2026] [security2:error] [pid 45040:tid 45207] [client 213.152.186.163:34904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4cz7EFnm79ltp0SFA5lQAAACM"]
[Mon Jul 20 07:04:15.212257 2026] [security2:error] [pid 45040:tid 45207] [client 213.152.186.163:34904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4cz7EFnm79ltp0SFA5lQAAACM"]
[Mon Jul 20 07:04:15.252006 2026] [security2:error] [pid 45040:tid 45201] [client 14.225.17.146:63003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4czbEFnm79ltp0SFA5SAAAAB0"]
[Mon Jul 20 07:04:15.365066 2026] [security2:error] [pid 45040:tid 45248] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cz7EFnm79ltp0SFA5iAAAAEw"]
[Mon Jul 20 07:04:15.429346 2026] [security2:error] [pid 45040:tid 45236] [client 194.61.41.58:65479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/fonts/index.php"] [unique_id "al4cz7EFnm79ltp0SFA5ngAAAEA"]
[Mon Jul 20 07:04:15.443199 2026] [security2:error] [pid 28702:tid 28958] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cz7F4957xPw9VVBnJtwAAAQI"]
[Mon Jul 20 07:04:15.451979 2026] [security2:error] [pid 45040:tid 45299] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cz7EFnm79ltp0SFA5kQAAAH8"]
[Mon Jul 20 07:04:15.492433 2026] [security2:error] [pid 45040:tid 45225] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4cz7EFnm79ltp0SFA5kwAAADU"]
[Mon Jul 20 07:04:15.539249 2026] [http2:warn] [pid 29744:tid 29902] [client 57.141.18.78:48342] h2_stream(29744-1271-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:15.636003 2026] [security2:error] [pid 45040:tid 45179] [client 14.225.17.146:62757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4czbEFnm79ltp0SFA5SwAAAAc"], referer: http://fineartsfactory.net/2026
[Mon Jul 20 07:04:15.670630 2026] [security2:error] [pid 45040:tid 45277] [client 14.225.17.146:62681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4cz7EFnm79ltp0SFA5nQAAAGk"], referer: http://younutrition.gr/2026
[Mon Jul 20 07:04:16.067650 2026] [security2:error] [pid 45040:tid 45158] [remote 5.161.225.162:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4c0LEFnm79ltp0SFA5wwAAP3M"]
[Mon Jul 20 07:04:16.134704 2026] [security2:error] [pid 45040:tid 45121] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4c0LEFnm79ltp0SFA5wQAATE4"], referer: https://jenfarley.com/login
[Mon Jul 20 07:04:16.135455 2026] [proxy:error] [pid 28702:tid 28876] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:16.135542 2026] [proxy_http:error] [pid 28702:tid 28876] [client 143.244.57.90:33530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:16.136813 2026] [proxy:error] [pid 28702:tid 28876] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:16.136859 2026] [proxy_http:error] [pid 28702:tid 28876] [client 143.244.57.90:33530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:16.140052 2026] [security2:error] [pid 28702:tid 28906] [client 194.61.41.84:52879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/chosen.php"] [unique_id "al4c0LF4957xPw9VVBnJ3gAAAM4"]
[Mon Jul 20 07:04:16.305672 2026] [security2:error] [pid 45040:tid 45098] [remote 5.161.225.162:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4c0LEFnm79ltp0SFA5ywAADjc"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 07:04:16.434558 2026] [proxy:error] [pid 45040:tid 45176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:16.434591 2026] [proxy_http:error] [pid 45040:tid 45176] [client 143.244.57.90:33536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:16.435064 2026] [proxy:error] [pid 45040:tid 45176] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:16.435087 2026] [proxy_http:error] [pid 45040:tid 45176] [client 143.244.57.90:33536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:16.731241 2026] [security2:error] [pid 45040:tid 45288] [client 143.244.57.90:33548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4c0LEFnm79ltp0SFA51wAAAHQ"]
[Mon Jul 20 07:04:16.768739 2026] [security2:error] [pid 45040:tid 45215] [client 104.234.53.84:35747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4c0LEFnm79ltp0SFA52AAAACs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:16.979497 2026] [security2:error] [pid 28702:tid 28954] [client 194.61.41.102:22749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/autoload_classmap/bypass.php"] [unique_id "al4c0LF4957xPw9VVBnKCAAAAP4"]
[Mon Jul 20 07:04:17.035890 2026] [security2:error] [pid 28702:tid 28869] [client 143.244.57.90:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/xmlrpc.php"] [unique_id "al4c0bF4957xPw9VVBnKCgAAAKk"]
[Mon Jul 20 07:04:17.105505 2026] [qos:error] [pid 45040:tid 45074] [remote 57.141.18.0:48108] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.0, id=al4c0bEFnm79ltp0SFA55QAAPx8
[Mon Jul 20 07:04:17.206901 2026] [security2:error] [pid 45040:tid 45060] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4c0bEFnm79ltp0SFA56QAAaxI"], referer: https://jenfarley.com/wp-admin/
[Mon Jul 20 07:04:17.276008 2026] [security2:error] [pid 45040:tid 45059] [remote 104.28.251.199:14397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/wp-login.php"] [unique_id "al4c0bEFnm79ltp0SFA57QAANRE"], referer: https://jenfarley.com/wp-admin/
[Mon Jul 20 07:04:17.332228 2026] [proxy:error] [pid 45040:tid 45186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:17.332308 2026] [proxy_http:error] [pid 45040:tid 45186] [client 143.244.57.90:33408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:17.333115 2026] [proxy:error] [pid 45040:tid 45186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:04:17.333148 2026] [proxy_http:error] [pid 45040:tid 45186] [client 143.244.57.90:33408] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:04:17.648887 2026] [security2:error] [pid 28702:tid 28889] [client 143.244.57.90:19553] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4c0bF4957xPw9VVBnKJAAAAL0"]
[Mon Jul 20 07:04:17.749654 2026] [security2:error] [pid 45040:tid 45198] [client 194.61.41.93:27463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/dropdown.php"] [unique_id "al4c0bEFnm79ltp0SFA6CAAAABo"]
[Mon Jul 20 07:04:17.874993 2026] [security2:error] [pid 45040:tid 45278] [client 158.173.89.95:54489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4c0bEFnm79ltp0SFA6CwAAAGo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:04:17.951656 2026] [security2:error] [pid 28702:tid 28911] [client 143.244.57.90:8616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4c0bF4957xPw9VVBnKLgAAANM"]
[Mon Jul 20 07:04:18.041759 2026] [security2:error] [pid 29744:tid 29783] [remote 57.141.18.62:38948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cSeGINCUUz5GA9YIuCgACXSU"]
[Mon Jul 20 07:04:18.118691 2026] [security2:error] [pid 28702:tid 28938] [client 77.110.127.138:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c0rF4957xPw9VVBnKOAAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:18.118794 2026] [security2:error] [pid 28702:tid 28938] [client 77.110.127.138:62457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c0rF4957xPw9VVBnKOAAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:18.248100 2026] [security2:error] [pid 28702:tid 28941] [client 143.244.57.90:33602] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4c0rF4957xPw9VVBnKQAAAAPE"]
[Mon Jul 20 07:04:18.444446 2026] [security2:error] [pid 28702:tid 28848] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c0rF4957xPw9VVBnKOQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:18.490960 2026] [security2:error] [pid 45040:tid 45246] [client 14.225.17.146:62593] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4c0rEFnm79ltp0SFA6FgAAAEo"], referer: http://nextlevelpressurewashing.com/2026
[Mon Jul 20 07:04:18.549795 2026] [security2:error] [pid 45040:tid 45215] [client 143.244.57.90:33618] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4c0rEFnm79ltp0SFA6IwAAACs"]
[Mon Jul 20 07:04:18.575526 2026] [security2:error] [pid 45040:tid 45265] [client 194.61.41.108:62047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/admin.php"] [unique_id "al4c0rEFnm79ltp0SFA6IQAAAF0"]
[Mon Jul 20 07:04:18.759522 2026] [security2:error] [pid 45040:tid 45227] [client 117.222.139.248:54718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c0rEFnm79ltp0SFA6MQAAADc"]
[Mon Jul 20 07:04:18.759720 2026] [security2:error] [pid 45040:tid 45227] [client 117.222.139.248:54718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c0rEFnm79ltp0SFA6MQAAADc"]
[Mon Jul 20 07:04:18.814768 2026] [security2:error] [pid 45040:tid 45295] [client 77.110.127.138:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c0rEFnm79ltp0SFA6MgAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:18.814887 2026] [security2:error] [pid 45040:tid 45295] [client 77.110.127.138:62459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c0rEFnm79ltp0SFA6MgAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:18.845089 2026] [security2:error] [pid 28702:tid 28947] [client 143.244.57.90:40407] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4c0rF4957xPw9VVBnKWQAAAPc"]
[Mon Jul 20 07:04:18.868484 2026] [security2:error] [pid 45040:tid 45231] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c0rEFnm79ltp0SFA6LAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:18.912706 2026] [security2:error] [pid 28702:tid 28913] [client 14.225.17.146:57814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4c0rF4957xPw9VVBnKUgAAANU"], referer: http://adastra.love/2026
[Mon Jul 20 07:04:18.977739 2026] [security2:error] [pid 45040:tid 45274] [client 104.234.53.82:27147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4c0rEFnm79ltp0SFA6NwAAAGY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:19.118560 2026] [security2:error] [pid 45040:tid 45175] [client 51.195.39.149:52416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4c0rEFnm79ltp0SFA6NAAAA0Y"]
[Mon Jul 20 07:04:19.143968 2026] [security2:error] [pid 45040:tid 45176] [client 143.244.57.90:25252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4c07EFnm79ltp0SFA6QQAAAAQ"]
[Mon Jul 20 07:04:19.202605 2026] [security2:error] [pid 28702:tid 28853] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c0rF4957xPw9VVBnKYgAAAJk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:19.263922 2026] [http2:warn] [pid 29744:tid 29892] [client 57.141.18.62:32300] h2_stream(29744-1299-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:19.361707 2026] [security2:error] [pid 45040:tid 45187] [client 194.61.41.69:39733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/db.php"] [unique_id "al4c07EFnm79ltp0SFA6TAAAAA8"]
[Mon Jul 20 07:04:19.437063 2026] [security2:error] [pid 45040:tid 45263] [client 143.244.57.90:33630] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4c07EFnm79ltp0SFA6UgAAAFs"]
[Mon Jul 20 07:04:19.449156 2026] [security2:error] [pid 45040:tid 45238] [client 50.116.65.227:56836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4c07EFnm79ltp0SFA6UwAAAEI"]
[Mon Jul 20 07:04:19.458304 2026] [security2:error] [pid 45040:tid 45209] [client 50.116.65.227:56840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4c07EFnm79ltp0SFA6VQAAACU"]
[Mon Jul 20 07:04:19.594733 2026] [security2:error] [pid 45040:tid 45229] [client 103.144.65.217:65041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c07EFnm79ltp0SFA6YgAAADk"]
[Mon Jul 20 07:04:19.594847 2026] [security2:error] [pid 45040:tid 45229] [client 103.144.65.217:65041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c07EFnm79ltp0SFA6YgAAADk"]
[Mon Jul 20 07:04:19.738046 2026] [security2:error] [pid 45040:tid 45245] [client 143.244.57.90:33640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4c07EFnm79ltp0SFA6cQAAAEk"]
[Mon Jul 20 07:04:19.781331 2026] [security2:error] [pid 45040:tid 45189] [client 117.247.108.24:25048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c07EFnm79ltp0SFA6cwAAABE"]
[Mon Jul 20 07:04:19.781461 2026] [security2:error] [pid 45040:tid 45189] [client 117.247.108.24:25048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c07EFnm79ltp0SFA6cwAAABE"]
[Mon Jul 20 07:04:19.863221 2026] [security2:error] [pid 45040:tid 45155] [remote 51.195.39.149:56996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4c07EFnm79ltp0SFA6aAAAPXA"]
[Mon Jul 20 07:04:20.034174 2026] [security2:error] [pid 45040:tid 45192] [client 143.244.57.90:33646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4c1LEFnm79ltp0SFA6ewAAABQ"]
[Mon Jul 20 07:04:20.086555 2026] [security2:error] [pid 28702:tid 28907] [client 77.110.127.138:62470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c1LF4957xPw9VVBnKhAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:20.086641 2026] [security2:error] [pid 28702:tid 28907] [client 77.110.127.138:62470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c1LF4957xPw9VVBnKhAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:20.129932 2026] [security2:error] [pid 45040:tid 45248] [client 194.61.41.61:54157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/mariju.php"] [unique_id "al4c1LEFnm79ltp0SFA6gQAAAEw"]
[Mon Jul 20 07:04:20.334952 2026] [security2:error] [pid 45040:tid 45276] [client 14.225.17.146:52537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4c07EFnm79ltp0SFA6XwAAAGg"]
[Mon Jul 20 07:04:20.338839 2026] [security2:error] [pid 45040:tid 45278] [client 143.244.57.90:51532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4c1LEFnm79ltp0SFA6hAAAAGo"]
[Mon Jul 20 07:04:20.648488 2026] [security2:error] [pid 45040:tid 45243] [client 143.244.57.90:51540] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4c1LEFnm79ltp0SFA6kAAAAEc"]
[Mon Jul 20 07:04:20.704366 2026] [security2:error] [pid 45040:tid 45202] [client 104.207.51.83:14787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c1LEFnm79ltp0SFA6kgAAAB4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:20.925976 2026] [security2:error] [pid 45040:tid 45288] [client 194.61.41.93:57519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/mah/function.php"] [unique_id "al4c1LEFnm79ltp0SFA6nAAAAHQ"]
[Mon Jul 20 07:04:20.942798 2026] [security2:error] [pid 28702:tid 28859] [client 143.244.57.90:24408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4c1LF4957xPw9VVBnKpAAAAJ8"]
[Mon Jul 20 07:04:21.187115 2026] [security2:error] [pid 28702:tid 28960] [client 183.82.98.154:58707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c1bF4957xPw9VVBnKqwAAAQQ"]
[Mon Jul 20 07:04:21.187268 2026] [security2:error] [pid 28702:tid 28960] [client 183.82.98.154:58707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c1bF4957xPw9VVBnKqwAAAQQ"]
[Mon Jul 20 07:04:21.209298 2026] [security2:error] [pid 28702:tid 28704] [remote 157.55.39.57:5206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.39ishlife.com"] [uri "/wp-content/themes/daisy-theme/rslib/minify/load.php"] [unique_id "al4c1bF4957xPw9VVBnKrgAArQA"], referer: https://www.39ishlife.com/finding-balance/
[Mon Jul 20 07:04:21.238150 2026] [security2:error] [pid 45040:tid 45212] [client 143.244.57.90:51556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4c1bEFnm79ltp0SFA6sAAAACg"]
[Mon Jul 20 07:04:21.530938 2026] [security2:error] [pid 28702:tid 28846] [client 143.244.57.90:51572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.garyjonathanmaddox.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4c1bF4957xPw9VVBnKvAAAAJI"]
[Mon Jul 20 07:04:21.745792 2026] [security2:error] [pid 28702:tid 28870] [client 50.116.65.227:56862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4c1bF4957xPw9VVBnKpgAAAKo"]
[Mon Jul 20 07:04:21.780845 2026] [security2:error] [pid 45040:tid 45251] [client 194.61.41.101:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/bypass.php"] [unique_id "al4c1bEFnm79ltp0SFA6xAAAAE8"]
[Mon Jul 20 07:04:21.781922 2026] [security2:error] [pid 28702:tid 28721] [remote 117.0.21.154:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c1bF4957xPw9VVBnKyAAAqRE"]
[Mon Jul 20 07:04:22.030392 2026] [qos:error] [pid 28702:tid 28739] [remote 57.141.18.31:49766] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.31, id=al4c1rF4957xPw9VVBnK1QAArSM
[Mon Jul 20 07:04:22.116544 2026] [security2:error] [pid 28702:tid 28937] [client 14.225.17.146:64253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4c1LF4957xPw9VVBnKlAAAAO0"], referer: http://nurturemarple.co.uk/2026
[Mon Jul 20 07:04:22.226317 2026] [security2:error] [pid 45040:tid 45206] [client 14.225.17.146:65527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4c1bEFnm79ltp0SFA6rAAAACI"], referer: http://travelbyfire.com/2026
[Mon Jul 20 07:04:22.279516 2026] [security2:error] [pid 28702:tid 28734] [remote 117.0.21.154:35172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c1rF4957xPw9VVBnK5gAA1h4"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:04:22.435770 2026] [security2:error] [pid 28702:tid 28894] [client 50.116.65.227:56878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4c1bF4957xPw9VVBnKxwAAAMI"]
[Mon Jul 20 07:04:22.548703 2026] [security2:error] [pid 28702:tid 28952] [client 194.61.41.243:30933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/admin.php"] [unique_id "al4c1rF4957xPw9VVBnK7wAAAPw"]
[Mon Jul 20 07:04:22.582030 2026] [security2:error] [pid 28702:tid 28836] [client 50.116.65.227:56918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4c1rF4957xPw9VVBnK4QAAAIg"]
[Mon Jul 20 07:04:22.756148 2026] [security2:error] [pid 45040:tid 45198] [client 77.110.127.138:62482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c1rEFnm79ltp0SFA66AAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:22.756238 2026] [security2:error] [pid 45040:tid 45198] [client 77.110.127.138:62482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c1rEFnm79ltp0SFA66AAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:22.772162 2026] [security2:error] [pid 28702:tid 28864] [client 50.116.65.227:56928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4c1rF4957xPw9VVBnK8QAAAKQ"]
[Mon Jul 20 07:04:23.055756 2026] [security2:error] [pid 45040:tid 45250] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c1rEFnm79ltp0SFA66wAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:23.060323 2026] [security2:error] [pid 45040:tid 45295] [client 14.225.17.146:64350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4c1rEFnm79ltp0SFA67QAAAHs"], referer: https://nurturemarple.co.uk/2026
[Mon Jul 20 07:04:23.123195 2026] [security2:error] [pid 45040:tid 45175] [client 14.225.17.146:64667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4c17EFnm79ltp0SFA6-AAAAAM"], referer: https://travelbyfire.com/2026
[Mon Jul 20 07:04:23.253996 2026] [security2:error] [pid 28702:tid 28914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c17F4957xPw9VVBnLDAAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:23.298967 2026] [security2:error] [pid 45040:tid 45289] [client 104.234.53.75:32039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4c17EFnm79ltp0SFA7AAAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:23.331239 2026] [security2:error] [pid 45040:tid 45187] [client 194.61.41.85:34537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/tflow/up.php"] [unique_id "al4c17EFnm79ltp0SFA7AgAAAA8"]
[Mon Jul 20 07:04:23.856915 2026] [security2:error] [pid 45040:tid 45207] [client 14.225.17.146:62371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4c1rEFnm79ltp0SFA62wAAACM"], referer: http://bbwipartnerconference.com/2026
[Mon Jul 20 07:04:23.915049 2026] [security2:error] [pid 28702:tid 28858] [client 57.141.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4c17F4957xPw9VVBnLIwAAAJ4"]
[Mon Jul 20 07:04:24.121086 2026] [security2:error] [pid 45040:tid 45181] [client 194.61.41.83:38477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/function.php"] [unique_id "al4c2LEFnm79ltp0SFA7HgAAAAk"]
[Mon Jul 20 07:04:24.154958 2026] [security2:error] [pid 45040:tid 45183] [client 187.16.64.216:58060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c2LEFnm79ltp0SFA7IQAAAAs"]
[Mon Jul 20 07:04:24.155085 2026] [security2:error] [pid 45040:tid 45183] [client 187.16.64.216:58060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c2LEFnm79ltp0SFA7IQAAAAs"]
[Mon Jul 20 07:04:24.844219 2026] [security2:error] [pid 45040:tid 45217] [client 194.61.41.247:46831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/templates/beez3/index.php"] [unique_id "al4c2LEFnm79ltp0SFA7QAAAAC0"]
[Mon Jul 20 07:04:25.309486 2026] [http2:warn] [pid 28702:tid 28839] [client 57.141.18.116:31842] h2_stream(28702-863-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:25.370709 2026] [core:error] [pid 45040:tid 45194] [client 34.206.50.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:04:25.370732 2026] [core:error] [pid 45040:tid 45194] [client 34.206.50.36:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:04:25.698360 2026] [security2:error] [pid 45040:tid 45189] [client 194.61.41.97:25073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/wp-login.php"] [unique_id "al4c2bEFnm79ltp0SFA7agAAABE"]
[Mon Jul 20 07:04:26.290737 2026] [security2:error] [pid 45040:tid 45245] [client 124.156.157.91:40066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.157.156.124.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/shadow/shadow_results.php"] [unique_id "al4c2rEFnm79ltp0SFA7ewAAAEk"]
[Mon Jul 20 07:04:26.449688 2026] [security2:error] [pid 28702:tid 28909] [client 194.61.41.80:44029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/install.php"] [unique_id "al4c2rF4957xPw9VVBnLiQAAANE"]
[Mon Jul 20 07:04:26.829598 2026] [security2:error] [pid 45040:tid 45117] [remote 97.74.87.194:58838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4c2rEFnm79ltp0SFA7kwAAUUo"]
[Mon Jul 20 07:04:26.829713 2026] [security2:error] [pid 45040:tid 45253] [client 97.74.87.194:58838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4c2rEFnm79ltp0SFA7kwAAUUo"]
[Mon Jul 20 07:04:26.851932 2026] [security2:error] [pid 45040:tid 45122] [remote 91.142.222.105:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c2rEFnm79ltp0SFA7lAAAJU8"]
[Mon Jul 20 07:04:27.077780 2026] [security2:error] [pid 45040:tid 45259] [client 122.183.32.225:17864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4c27EFnm79ltp0SFA7pAAAAFc"]
[Mon Jul 20 07:04:27.077861 2026] [security2:error] [pid 45040:tid 45259] [client 122.183.32.225:17864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4c27EFnm79ltp0SFA7pAAAAFc"]
[Mon Jul 20 07:04:27.140106 2026] [security2:error] [pid 45040:tid 45161] [remote 91.142.222.105:36214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c27EFnm79ltp0SFA7pwAAD3Y"], referer: https://str.cly.mybluehost.me/wp-login.php
[Mon Jul 20 07:04:27.150466 2026] [security2:error] [pid 28702:tid 28954] [client 194.61.41.241:53347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/rk2.php"] [unique_id "al4c27F4957xPw9VVBnLrAAAAP4"]
[Mon Jul 20 07:04:27.278155 2026] [security2:error] [pid 45040:tid 45166] [remote 182.77.62.24:50072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4c27EFnm79ltp0SFA7qQAAIns"]
[Mon Jul 20 07:04:27.286497 2026] [http2:warn] [pid 28702:tid 28892] [client 57.141.18.23:40730] h2_stream(28702-664-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:27.411646 2026] [security2:error] [pid 45040:tid 45170] [remote 173.249.4.11:38107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4c27EFnm79ltp0SFA7tQAAOX8"]
[Mon Jul 20 07:04:27.430646 2026] [security2:error] [pid 45040:tid 45245] [client 43.205.139.3:42344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4c27EFnm79ltp0SFA7twAAAEk"]
[Mon Jul 20 07:04:27.489218 2026] [http2:warn] [pid 29744:tid 29989] [client 57.141.18.64:57358] h2_stream(29744-897-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:27.609526 2026] [security2:error] [pid 45040:tid 45156] [remote 173.249.4.11:38107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4c27EFnm79ltp0SFA7vwAAWnE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:04:27.724230 2026] [security2:error] [pid 45040:tid 45218] [client 154.208.48.130:53640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c27EFnm79ltp0SFA7wwAAAC4"]
[Mon Jul 20 07:04:27.724367 2026] [security2:error] [pid 45040:tid 45218] [client 154.208.48.130:53640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c27EFnm79ltp0SFA7wwAAAC4"]
[Mon Jul 20 07:04:27.809871 2026] [security2:error] [pid 45040:tid 45044] [remote 182.77.62.24:50072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4c27EFnm79ltp0SFA7xwAABQM"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 07:04:27.908627 2026] [qos:error] [pid 28702:tid 28774] [remote 57.141.18.95:32364] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.95, id=al4c27F4957xPw9VVBnLyQAA6kY
[Mon Jul 20 07:04:27.972521 2026] [security2:error] [pid 45040:tid 45270] [client 194.61.41.96:27815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/class-config.php"] [unique_id "al4c27EFnm79ltp0SFA7zQAAAGI"]
[Mon Jul 20 07:04:28.658691 2026] [http2:warn] [pid 28702:tid 28860] [client 57.141.18.107:47206] h2_stream(28702-666-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:28.738537 2026] [security2:error] [pid 45040:tid 45217] [client 194.61.41.84:48251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/components/com_jea/views/form/tmpl/size.php"] [unique_id "al4c3LEFnm79ltp0SFA75AAAAC0"]
[Mon Jul 20 07:04:28.787590 2026] [security2:error] [pid 45040:tid 45043] [remote 57.141.18.122:44416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4c3LEFnm79ltp0SFA76QAAKQI"]
[Mon Jul 20 07:04:28.827381 2026] [security2:error] [pid 28702:tid 28900] [client 14.225.17.146:62385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4c27F4957xPw9VVBnLyAAAAMg"], referer: http://headachescarpaltunnelfibromyalgia.com/2026
[Mon Jul 20 07:04:28.966329 2026] [security2:error] [pid 28702:tid 28949] [client 74.208.214.194:43546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4c3LF4957xPw9VVBnMEAAAAPk"]
[Mon Jul 20 07:04:28.998050 2026] [http2:warn] [pid 29744:tid 29985] [client 57.141.18.17:64958] h2_stream(29744-915-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:29.057295 2026] [security2:error] [pid 28702:tid 28873] [client 43.205.139.3:42358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4c3bF4957xPw9VVBnMGgAAAK0"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:04:29.062951 2026] [autoindex:error] [pid 28702:tid 28764] [remote 45.95.169.32:40230] AH01276: Cannot serve directory /home1/uritemsn/public_html/aljosour-alarabia-net/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:29.108438 2026] [security2:error] [pid 45040:tid 45273] [client 66.249.79.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.socalledsam.com"] [uri "/index.php"] [unique_id "al4c27EFnm79ltp0SFA7yAAAZQg"]
[Mon Jul 20 07:04:29.342965 2026] [security2:error] [pid 45040:tid 45196] [client 117.222.139.248:55243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c3bEFnm79ltp0SFA79QAAABg"]
[Mon Jul 20 07:04:29.343078 2026] [security2:error] [pid 45040:tid 45196] [client 117.222.139.248:55243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c3bEFnm79ltp0SFA79QAAABg"]
[Mon Jul 20 07:04:29.467976 2026] [security2:error] [pid 28702:tid 28796] [remote 57.141.18.23:40730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cSrF4957xPw9VVBm1bwAAwFw"]
[Mon Jul 20 07:04:29.549905 2026] [security2:error] [pid 45040:tid 45219] [client 194.61.41.58:29709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/templates/beez/index.php"] [unique_id "al4c3bEFnm79ltp0SFA8AgAAAC8"]
[Mon Jul 20 07:04:29.668279 2026] [security2:error] [pid 28702:tid 28742] [remote 45.150.79.142:50664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4c3bF4957xPw9VVBnMKwAAkyY"]
[Mon Jul 20 07:04:29.889191 2026] [http2:warn] [pid 28702:tid 28930] [client 57.141.18.114:22418] h2_stream(28702-883-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:29.983804 2026] [autoindex:error] [pid 45040:tid 45197] [client 34.73.38.214:0] AH01276: Cannot serve directory /home1/ipqbpvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:30.089369 2026] [security2:error] [pid 45040:tid 45236] [client 103.144.65.217:65493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8HAAAAEA"]
[Mon Jul 20 07:04:30.091102 2026] [security2:error] [pid 45040:tid 45236] [client 103.144.65.217:65493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8HAAAAEA"]
[Mon Jul 20 07:04:30.177042 2026] [http2:warn] [pid 29744:tid 29885] [client 57.141.18.27:23464] h2_stream(29744-1425-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.177092 2026] [http2:warn] [pid 29744:tid 29956] [client 57.141.18.61:24852] h2_stream(29744-1490-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.177424 2026] [http2:warn] [pid 29744:tid 29909] [client 57.141.18.102:38574] h2_stream(29744-1423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.183294 2026] [http2:warn] [pid 29744:tid 29911] [client 57.141.18.27:24224] h2_stream(29744-1518-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.217442 2026] [security2:error] [pid 45040:tid 45228] [client 34.73.38.214:57808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 214.38.73.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ctb.zro.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8JQAAADg"]
[Mon Jul 20 07:04:30.287480 2026] [security2:error] [pid 28702:tid 28735] [remote 45.150.79.142:50664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/wp-login.php"] [unique_id "al4c3rF4957xPw9VVBnMQAAAxB8"], referer: https://claysharecon.com/wp-login.php
[Mon Jul 20 07:04:30.309766 2026] [http2:warn] [pid 29744:tid 29920] [client 57.141.18.39:42987] h2_stream(29744-925-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.347419 2026] [security2:error] [pid 45040:tid 45278] [client 65.111.22.170:48771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c3rEFnm79ltp0SFA8KgAAAGo"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:30.362584 2026] [security2:error] [pid 45040:tid 45282] [client 194.61.41.94:25737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/bypass.php"] [unique_id "al4c3rEFnm79ltp0SFA8LgAAAG4"]
[Mon Jul 20 07:04:30.445319 2026] [http2:warn] [pid 29744:tid 29961] [client 57.141.18.54:51500] h2_stream(29744-926-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.451323 2026] [http2:warn] [pid 28702:tid 28943] [client 57.141.18.7:52634] h2_stream(28702-671-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:30.465844 2026] [security2:error] [pid 28702:tid 28924] [client 14.225.17.146:52890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4c3rF4957xPw9VVBnMOgAAAOA"]
[Mon Jul 20 07:04:30.485631 2026] [security2:error] [pid 45040:tid 45182] [client 117.247.108.24:13034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8NwAAAAo"]
[Mon Jul 20 07:04:30.485729 2026] [security2:error] [pid 45040:tid 45182] [client 117.247.108.24:13034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8NwAAAAo"]
[Mon Jul 20 07:04:30.597070 2026] [security2:error] [pid 45040:tid 45207] [client 77.110.127.138:62492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c3rEFnm79ltp0SFA8OQAAACM"]
[Mon Jul 20 07:04:30.597170 2026] [security2:error] [pid 45040:tid 45207] [client 77.110.127.138:62492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c3rEFnm79ltp0SFA8OQAAACM"]
[Mon Jul 20 07:04:30.659736 2026] [security2:error] [pid 28702:tid 28865] [client 34.73.38.214:53882] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4c3rF4957xPw9VVBnMWgAAAKU"]
[Mon Jul 20 07:04:30.918591 2026] [security2:error] [pid 28702:tid 28954] [client 45.3.42.118:14677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c3rF4957xPw9VVBnMYAAAAP4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:30.939183 2026] [security2:error] [pid 45040:tid 45196] [client 192.140.149.97:45527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8QwAAABg"]
[Mon Jul 20 07:04:30.939305 2026] [security2:error] [pid 45040:tid 45196] [client 192.140.149.97:45527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4c3rEFnm79ltp0SFA8QwAAABg"]
[Mon Jul 20 07:04:30.998240 2026] [security2:error] [pid 28702:tid 28933] [client 34.73.38.214:58613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4c3rF4957xPw9VVBnMZAAAAOk"]
[Mon Jul 20 07:04:31.110232 2026] [security2:error] [pid 45040:tid 45187] [client 14.225.17.146:52359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4c3bEFnm79ltp0SFA7-AAAAA8"], referer: http://lelandumc.org/2026
[Mon Jul 20 07:04:31.158312 2026] [security2:error] [pid 45040:tid 45225] [client 104.234.53.71:46737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4c37EFnm79ltp0SFA8SwAAADU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:31.172142 2026] [security2:error] [pid 28702:tid 28912] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c3rF4957xPw9VVBnMVgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:31.207044 2026] [security2:error] [pid 45040:tid 45250] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c3rEFnm79ltp0SFA8PQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:31.411706 2026] [security2:error] [pid 28702:tid 28889] [client 34.73.38.214:54687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4c37F4957xPw9VVBnMcwAAAL0"]
[Mon Jul 20 07:04:31.599195 2026] [security2:error] [pid 28702:tid 28886] [client 14.225.17.146:52842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4c3bF4957xPw9VVBnMIQAAALo"], referer: http://gearwaterproof.com/2026
[Mon Jul 20 07:04:31.652096 2026] [http2:warn] [pid 29744:tid 29883] [client 57.141.18.87:21086] h2_stream(29744-935-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:31.677499 2026] [security2:error] [pid 45040:tid 45213] [client 183.82.98.154:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c37EFnm79ltp0SFA8XgAAACk"]
[Mon Jul 20 07:04:31.677596 2026] [security2:error] [pid 45040:tid 45213] [client 183.82.98.154:59293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c37EFnm79ltp0SFA8XgAAACk"]
[Mon Jul 20 07:04:31.916697 2026] [security2:error] [pid 45040:tid 45280] [client 34.73.38.214:64111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4c37EFnm79ltp0SFA8ZwAAAGw"]
[Mon Jul 20 07:04:31.947055 2026] [security2:error] [pid 45040:tid 45203] [client 50.116.65.227:17084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4c37EFnm79ltp0SFA8aAAAAB8"]
[Mon Jul 20 07:04:31.956400 2026] [security2:error] [pid 45040:tid 45272] [client 50.116.65.227:17096] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4c37EFnm79ltp0SFA8agAAAGQ"]
[Mon Jul 20 07:04:32.007284 2026] [http2:warn] [pid 29744:tid 29944] [client 57.141.18.98:25678] h2_stream(29744-940-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:32.053953 2026] [http2:warn] [pid 28702:tid 28956] [client 57.141.18.82:64926] h2_stream(28702-676-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:32.502430 2026] [security2:error] [pid 45040:tid 45149] [remote 202.51.202.242:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c4LEFnm79ltp0SFA8gQAAAWo"]
[Mon Jul 20 07:04:32.563974 2026] [security2:error] [pid 45040:tid 45195] [client 34.73.38.214:60613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4c4LEFnm79ltp0SFA8gwAAABc"]
[Mon Jul 20 07:04:32.598043 2026] [security2:error] [pid 45040:tid 45120] [remote 72.167.132.114:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4c4LEFnm79ltp0SFA8hAAASE0"]
[Mon Jul 20 07:04:32.678576 2026] [security2:error] [pid 45040:tid 45242] [client 44.215.99.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4c4LEFnm79ltp0SFA8ggAARgQ"]
[Mon Jul 20 07:04:32.820846 2026] [security2:error] [pid 45040:tid 45060] [remote 72.167.132.114:53550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4c4LEFnm79ltp0SFA8jAAAKhI"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:04:32.877833 2026] [security2:error] [pid 28702:tid 28924] [client 194.61.41.242:43353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/class.php"] [unique_id "al4c4LF4957xPw9VVBnMpQAAAOA"]
[Mon Jul 20 07:04:33.180455 2026] [security2:error] [pid 28702:tid 28892] [client 34.73.38.214:63583] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4c4bF4957xPw9VVBnMsgAAAMA"]
[Mon Jul 20 07:04:33.405412 2026] [security2:error] [pid 45040:tid 45237] [client 34.73.38.214:57371] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4c4bEFnm79ltp0SFA8mAAAAEE"]
[Mon Jul 20 07:04:33.470550 2026] [http2:warn] [pid 28702:tid 28940] [client 57.141.18.56:64010] h2_stream(28702-684-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:33.904322 2026] [security2:error] [pid 28702:tid 28889] [client 34.73.38.214:50963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4c4bF4957xPw9VVBnM0wAAAL0"]
[Mon Jul 20 07:04:34.004385 2026] [http2:warn] [pid 29744:tid 29876] [client 57.141.18.101:49450] h2_stream(29744-952-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:34.107652 2026] [security2:error] [pid 45040:tid 45299] [client 14.225.17.146:50600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4c4rEFnm79ltp0SFA8owAAAH8"], referer: http://grndl.com/2026
[Mon Jul 20 07:04:34.282236 2026] [http2:warn] [pid 28702:tid 28932] [client 57.141.18.120:42598] h2_stream(28702-894-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:34.298978 2026] [security2:error] [pid 45040:tid 45297] [client 213.152.186.163:36294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4c4rEFnm79ltp0SFA8rwAAAH0"]
[Mon Jul 20 07:04:34.299083 2026] [security2:error] [pid 45040:tid 45297] [client 213.152.186.163:36294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4c4rEFnm79ltp0SFA8rwAAAH0"]
[Mon Jul 20 07:04:34.353467 2026] [http2:warn] [pid 28702:tid 28851] [client 57.141.18.80:37762] h2_stream(28702-688-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:34.421067 2026] [security2:error] [pid 28702:tid 28960] [client 34.73.38.214:59511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4c4rF4957xPw9VVBnM6wAAAQQ"]
[Mon Jul 20 07:04:34.613953 2026] [security2:error] [pid 45040:tid 45108] [remote 45.90.123.233:44346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4c4rEFnm79ltp0SFA8uQAAJUE"]
[Mon Jul 20 07:04:34.804194 2026] [http2:warn] [pid 29744:tid 29922] [client 57.141.18.39:42995] h2_stream(29744-959-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:34.805244 2026] [security2:error] [pid 45040:tid 45103] [remote 45.90.123.233:44346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4c4rEFnm79ltp0SFA8ugAAOTw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:04:34.832224 2026] [security2:error] [pid 45040:tid 45245] [client 34.73.38.214:57332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4c4rEFnm79ltp0SFA8uwAAAEk"]
[Mon Jul 20 07:04:34.894250 2026] [security2:error] [pid 45040:tid 45275] [client 187.16.64.216:58637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c4rEFnm79ltp0SFA8vwAAAGc"]
[Mon Jul 20 07:04:34.894350 2026] [security2:error] [pid 45040:tid 45275] [client 187.16.64.216:58637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c4rEFnm79ltp0SFA8vwAAAGc"]
[Mon Jul 20 07:04:34.896897 2026] [qos:error] [pid 45040:tid 45112] [remote 57.141.18.34:23900] mod_qos(010): access denied, QS_LocRequestLimit* rule: /(100), concurrent requests=101, c=57.141.18.34, id=al4c4rEFnm79ltp0SFA8wAAAP0U
[Mon Jul 20 07:04:34.908301 2026] [security2:error] [pid 28702:tid 28736] [remote 5.252.52.249:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c4rF4957xPw9VVBnM_wAA1CA"]
[Mon Jul 20 07:04:35.040646 2026] [security2:error] [pid 45040:tid 45225] [client 194.61.41.240:41121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/light/profile.php"] [unique_id "al4c47EFnm79ltp0SFA8yAAAADU"]
[Mon Jul 20 07:04:35.057453 2026] [autoindex:error] [pid 45040:tid 45271] [client 93.159.230.84:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:35.098777 2026] [security2:error] [pid 28702:tid 28818] [remote 5.252.52.249:58924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c47F4957xPw9VVBnNBwAAzXI"], referer: https://mail.ait.afz.mybluehost.me/wp-login.php
[Mon Jul 20 07:04:35.315439 2026] [security2:error] [pid 45040:tid 45286] [client 34.73.38.214:59986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ctb.zro.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4c47EFnm79ltp0SFA81wAAAHI"]
[Mon Jul 20 07:04:35.367406 2026] [security2:error] [pid 28702:tid 28844] [client 104.234.53.93:58991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4c47F4957xPw9VVBnNDQAAAJA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:35.491669 2026] [security2:error] [pid 45040:tid 45231] [client 14.225.17.146:60632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4c47EFnm79ltp0SFA82gAAADs"], referer: http://christiancountytrumpet.com/2026
[Mon Jul 20 07:04:35.522298 2026] [security2:error] [pid 28702:tid 28933] [client 14.225.17.146:50533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4c4bF4957xPw9VVBnM0QAAAOk"], referer: http://according2plant.com/2026
[Mon Jul 20 07:04:35.547913 2026] [http2:warn] [pid 29744:tid 29929] [client 57.141.18.100:64056] h2_stream(29744-966-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:35.748703 2026] [security2:error] [pid 45040:tid 45102] [remote 100.42.189.89:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.think-islam.com"] [uri "/wp-login.php"] [unique_id "al4c47EFnm79ltp0SFA86QAAbzs"]
[Mon Jul 20 07:04:35.825836 2026] [security2:error] [pid 28702:tid 28872] [client 194.61.41.56:24609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/product.php"] [unique_id "al4c47F4957xPw9VVBnNHAAAAKw"]
[Mon Jul 20 07:04:35.939387 2026] [security2:error] [pid 45040:tid 45058] [remote 100.42.189.89:44324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.think-islam.com"] [uri "/wp-login.php"] [unique_id "al4c47EFnm79ltp0SFA88wAAJxA"], referer: https://mail.think-islam.com/wp-login.php
[Mon Jul 20 07:04:35.981382 2026] [security2:error] [pid 45040:tid 45113] [remote 81.173.115.7:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c47EFnm79ltp0SFA89wAAIkY"]
[Mon Jul 20 07:04:35.995231 2026] [security2:error] [pid 45040:tid 45179] [client 14.225.17.146:60941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c47EFnm79ltp0SFA86wAAAAc"], referer: http://mezzacraft.com/2026
[Mon Jul 20 07:04:36.088237 2026] [http2:warn] [pid 28702:tid 28862] [client 57.141.18.49:25408] h2_stream(28702-693-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:36.223717 2026] [security2:error] [pid 45040:tid 45116] [remote 81.173.115.7:39980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c5LEFnm79ltp0SFA9BgAAeUk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:04:36.530545 2026] [security2:error] [pid 45040:tid 45274] [client 194.61.41.102:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/autoload_classmap.php"] [unique_id "al4c5LEFnm79ltp0SFA9DwAAAGY"]
[Mon Jul 20 07:04:36.543931 2026] [security2:error] [pid 28702:tid 28894] [client 14.225.17.146:61091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4c4rF4957xPw9VVBnNAAAAAMI"], referer: http://bigwormfishing.com/2026
[Mon Jul 20 07:04:36.714987 2026] [autoindex:error] [pid 28702:tid 28844] [client 77.74.177.118:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://noisepacks.com
[Mon Jul 20 07:04:36.774181 2026] [http2:warn] [pid 28702:tid 28855] [client 57.141.18.121:56574] h2_stream(28702-695-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:37.207349 2026] [http2:warn] [pid 29744:tid 29955] [client 57.141.18.81:21662] h2_stream(29744-976-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:37.339323 2026] [security2:error] [pid 28702:tid 28833] [client 194.61.41.104:42025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/ask.php"] [unique_id "al4c5bF4957xPw9VVBnNTQAAAIU"]
[Mon Jul 20 07:04:37.495015 2026] [autoindex:error] [pid 45040:tid 45276] [client 77.74.177.118:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:37.511630 2026] [security2:error] [pid 28702:tid 28939] [client 14.225.17.146:60967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4c5bF4957xPw9VVBnNUgAAAO8"], referer: https://bigwormfishing.com/2026
[Mon Jul 20 07:04:37.719320 2026] [http2:warn] [pid 29744:tid 29915] [client 57.141.18.106:39630] h2_stream(29744-983-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:37.808065 2026] [http2:warn] [pid 29744:tid 29945] [client 57.141.18.2:41452] h2_stream(29744-986-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:38.132065 2026] [security2:error] [pid 28702:tid 28934] [client 194.61.41.94:42953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/rest-api/about.php"] [unique_id "al4c5rF4957xPw9VVBnNbgAAAOo"]
[Mon Jul 20 07:04:38.205694 2026] [security2:error] [pid 45040:tid 45229] [client 34.221.76.50:44250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4c5rEFnm79ltp0SFA9RQAAADk"]
[Mon Jul 20 07:04:38.286046 2026] [security2:error] [pid 28702:tid 28890] [client 154.208.48.130:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c5rF4957xPw9VVBnNdAAAAL4"]
[Mon Jul 20 07:04:38.286547 2026] [security2:error] [pid 28702:tid 28890] [client 154.208.48.130:54146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c5rF4957xPw9VVBnNdAAAAL4"]
[Mon Jul 20 07:04:38.901051 2026] [security2:error] [pid 28702:tid 28924] [client 104.234.53.54:33443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4c5rF4957xPw9VVBnNiQAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:38.944164 2026] [security2:error] [pid 45040:tid 45277] [client 194.61.41.94:38545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/css.php"] [unique_id "al4c5rEFnm79ltp0SFA9hQAAAGk"]
[Mon Jul 20 07:04:38.961449 2026] [autoindex:error] [pid 28702:tid 28958] [client 93.159.230.84:0] AH01276: Cannot serve directory /home3/alpchxmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.noisepacks.com
[Mon Jul 20 07:04:39.044296 2026] [http2:warn] [pid 28702:tid 28959] [client 57.141.18.112:33404] h2_stream(28702-705-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:39.291589 2026] [core:error] [pid 28702:tid 28865] [client 14.225.17.146:63827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2026
[Mon Jul 20 07:04:39.291614 2026] [core:error] [pid 28702:tid 28865] [client 14.225.17.146:63827] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2026
[Mon Jul 20 07:04:39.684554 2026] [http2:warn] [pid 29744:tid 29978] [client 57.141.18.75:50278] h2_stream(29744-996-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:39.743577 2026] [security2:error] [pid 45040:tid 45250] [client 194.61.41.101:21399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/init.php"] [unique_id "al4c57EFnm79ltp0SFA9qQAAAE4"]
[Mon Jul 20 07:04:39.840121 2026] [security2:error] [pid 45040:tid 45270] [client 117.222.139.248:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c57EFnm79ltp0SFA9qgAAAGI"]
[Mon Jul 20 07:04:39.840257 2026] [security2:error] [pid 45040:tid 45270] [client 117.222.139.248:55752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c57EFnm79ltp0SFA9qgAAAGI"]
[Mon Jul 20 07:04:39.942968 2026] [security2:error] [pid 28702:tid 28842] [client 74.208.214.194:39774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4c57F4957xPw9VVBnNuwAAAI4"]
[Mon Jul 20 07:04:40.090674 2026] [security2:error] [pid 28702:tid 28743] [remote 103.161.172.221:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4c6LF4957xPw9VVBnNxAAAqCc"]
[Mon Jul 20 07:04:40.140610 2026] [security2:error] [pid 28702:tid 28894] [client 14.225.17.146:60846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4c57F4957xPw9VVBnNvQAAAMI"], referer: http://taskidsvirginia.com/2026
[Mon Jul 20 07:04:40.217441 2026] [http2:warn] [pid 29744:tid 29984] [client 57.141.18.95:21990] h2_stream(29744-1001-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:40.488387 2026] [security2:error] [pid 28702:tid 28923] [client 104.207.51.12:35697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c6LF4957xPw9VVBnN0gAAAN8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:40.517365 2026] [security2:error] [pid 28702:tid 28776] [remote 103.161.172.221:32926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4c6LF4957xPw9VVBnN1QAAhUg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:04:40.562004 2026] [security2:error] [pid 45040:tid 45184] [client 194.61.41.97:57445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/user/wp-login.php"] [unique_id "al4c6LEFnm79ltp0SFA9xQAAAAw"]
[Mon Jul 20 07:04:40.615488 2026] [security2:error] [pid 45040:tid 45178] [client 103.144.65.217:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c6LEFnm79ltp0SFA9ywAAAAY"]
[Mon Jul 20 07:04:40.615631 2026] [security2:error] [pid 45040:tid 45178] [client 103.144.65.217:49570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c6LEFnm79ltp0SFA9ywAAAAY"]
[Mon Jul 20 07:04:40.652111 2026] [security2:error] [pid 28702:tid 28723] [remote 57.141.18.107:47206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cS7F4957xPw9VVBm1oAAAoBM"]
[Mon Jul 20 07:04:40.689453 2026] [http2:warn] [pid 29744:tid 29942] [client 57.141.18.50:27652] h2_stream(29744-1005-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:41.037901 2026] [security2:error] [pid 28702:tid 28836] [client 45.3.42.32:34953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c6bF4957xPw9VVBnN6AAAAIg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:41.343361 2026] [security2:error] [pid 28702:tid 28918] [client 194.61.41.92:38581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/autoload_classmap/function.php"] [unique_id "al4c6bF4957xPw9VVBnN9QAAANo"]
[Mon Jul 20 07:04:41.399389 2026] [security2:error] [pid 28702:tid 28907] [client 117.247.108.24:25795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c6bF4957xPw9VVBnN-QAAAM8"]
[Mon Jul 20 07:04:41.399521 2026] [security2:error] [pid 28702:tid 28907] [client 117.247.108.24:25795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c6bF4957xPw9VVBnN-QAAAM8"]
[Mon Jul 20 07:04:41.426739 2026] [security2:error] [pid 45040:tid 45067] [remote 100.42.189.89:34908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4c6bEFnm79ltp0SFA94wAAMxg"]
[Mon Jul 20 07:04:41.603202 2026] [security2:error] [pid 28702:tid 28928] [client 104.207.51.146:30383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 146.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c6bF4957xPw9VVBnOBAAAAOQ"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:41.620822 2026] [security2:error] [pid 28702:tid 28872] [client 192.140.149.97:44415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4c6bF4957xPw9VVBnOCQAAAKw"]
[Mon Jul 20 07:04:41.620902 2026] [security2:error] [pid 28702:tid 28872] [client 192.140.149.97:44415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4c6bF4957xPw9VVBnOCQAAAKw"]
[Mon Jul 20 07:04:41.635308 2026] [security2:error] [pid 45040:tid 45062] [remote 100.42.189.89:34908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4c6bEFnm79ltp0SFA96AAAPBQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:04:41.810446 2026] [http2:warn] [pid 29744:tid 29917] [client 57.141.18.119:42432] h2_stream(29744-1013-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:42.031352 2026] [http2:warn] [pid 28702:tid 28944] [client 57.141.18.108:24546] h2_stream(28702-713-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:42.121711 2026] [security2:error] [pid 28702:tid 28938] [client 194.61.41.83:22811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/item.php"] [unique_id "al4c6rF4957xPw9VVBnOHQAAAO4"]
[Mon Jul 20 07:04:42.165035 2026] [security2:error] [pid 28702:tid 28838] [client 104.207.52.143:49229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c6rF4957xPw9VVBnOHwAAAIo"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:42.218157 2026] [security2:error] [pid 45040:tid 45218] [client 57.141.18.125:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4c6rEFnm79ltp0SFA99AAAAC4"]
[Mon Jul 20 07:04:42.219152 2026] [security2:error] [pid 28702:tid 28936] [client 183.82.98.154:34704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c6rF4957xPw9VVBnOJQAAAOw"]
[Mon Jul 20 07:04:42.219264 2026] [security2:error] [pid 28702:tid 28936] [client 183.82.98.154:34704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c6rF4957xPw9VVBnOJQAAAOw"]
[Mon Jul 20 07:04:42.459462 2026] [http2:warn] [pid 29744:tid 29970] [client 57.141.18.51:51662] h2_stream(29744-1017-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:42.477244 2026] [security2:error] [pid 45040:tid 45245] [client 14.225.17.146:52333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4c6bEFnm79ltp0SFA93wAAAEk"], referer: http://chestermonty.com/2026
[Mon Jul 20 07:04:42.494765 2026] [http2:warn] [pid 29744:tid 29907] [client 57.141.18.15:50058] h2_stream(29744-1019-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:42.720969 2026] [security2:error] [pid 45040:tid 45183] [client 45.3.42.12:42303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c6rEFnm79ltp0SFA-DgAAAAs"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:42.833975 2026] [security2:error] [pid 45040:tid 45250] [client 194.61.41.61:62933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/index.php"] [unique_id "al4c6rEFnm79ltp0SFA-EAAAAE4"]
[Mon Jul 20 07:04:43.259064 2026] [security2:error] [pid 28702:tid 28927] [client 50.116.65.227:20446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4c67F4957xPw9VVBnOTgAAAOM"]
[Mon Jul 20 07:04:43.267346 2026] [security2:error] [pid 45040:tid 45194] [client 50.116.65.227:20452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4c67EFnm79ltp0SFA-KQAAABY"]
[Mon Jul 20 07:04:43.273635 2026] [security2:error] [pid 45040:tid 45244] [client 104.207.53.94:43069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c67EFnm79ltp0SFA-KAAAAEg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:43.326316 2026] [security2:error] [pid 28702:tid 28909] [client 57.141.18.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4c67F4957xPw9VVBnORwAAANE"]
[Mon Jul 20 07:04:43.390379 2026] [security2:error] [pid 45040:tid 45179] [client 14.225.17.146:60983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4c67EFnm79ltp0SFA-LAAAAAc"], referer: https://chestermonty.com/2026
[Mon Jul 20 07:04:43.445277 2026] [security2:error] [pid 45040:tid 45249] [client 144.76.32.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4c67EFnm79ltp0SFA-IAAAAE0"]
[Mon Jul 20 07:04:43.554335 2026] [security2:error] [pid 45040:tid 45219] [client 194.61.41.61:49909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/index.php"] [unique_id "al4c67EFnm79ltp0SFA-OAAAAC8"]
[Mon Jul 20 07:04:43.787789 2026] [security2:error] [pid 28702:tid 28861] [client 50.116.65.227:20480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4c67F4957xPw9VVBnOWQAAAKE"]
[Mon Jul 20 07:04:43.840773 2026] [http2:warn] [pid 29744:tid 29896] [client 57.141.18.20:54446] h2_stream(29744-1030-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:43.883640 2026] [security2:error] [pid 45040:tid 45282] [client 65.111.23.175:53389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c67EFnm79ltp0SFA-QwAAAG4"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:43.966786 2026] [security2:error] [pid 28702:tid 28867] [client 50.116.65.227:20494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4c67F4957xPw9VVBnOXwAAAKc"]
[Mon Jul 20 07:04:44.227846 2026] [security2:error] [pid 28702:tid 28892] [client 103.15.213.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4c6rF4957xPw9VVBnOOAAAAMA"]
[Mon Jul 20 07:04:44.340950 2026] [security2:error] [pid 45040:tid 45204] [client 194.61.41.92:40181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4c7LEFnm79ltp0SFA-WgAAACA"]
[Mon Jul 20 07:04:44.344681 2026] [security2:error] [pid 45040:tid 45285] [client 77.110.127.138:62504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7LEFnm79ltp0SFA-WwAAAHE"]
[Mon Jul 20 07:04:44.344776 2026] [security2:error] [pid 45040:tid 45285] [client 77.110.127.138:62504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7LEFnm79ltp0SFA-WwAAAHE"]
[Mon Jul 20 07:04:44.354602 2026] [http2:warn] [pid 28702:tid 28883] [client 57.141.18.8:36382] h2_stream(28702-724-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:44.373354 2026] [http2:warn] [pid 28702:tid 28891] [client 57.141.18.19:32270] h2_stream(28702-932-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:44.404978 2026] [security2:error] [pid 45040:tid 45228] [client 114.119.130.40:55353] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.itdynamix.com"] [uri "/services/telecommunication-solutions/managed-networking-services/"] [unique_id "al4c7LEFnm79ltp0SFA-ZQAAADg"], referer: http://www.itdynamix.com/
[Mon Jul 20 07:04:44.455963 2026] [security2:error] [pid 45040:tid 45179] [client 104.207.50.177:33947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c7LEFnm79ltp0SFA-ZgAAAAc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:44.831645 2026] [http2:warn] [pid 29744:tid 29887] [client 57.141.18.41:53046] h2_stream(29744-1038-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:44.880456 2026] [security2:error] [pid 45040:tid 45046] [remote 5.252.52.249:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4c7LEFnm79ltp0SFA-dQAABQU"]
[Mon Jul 20 07:04:44.899722 2026] [security2:error] [pid 45040:tid 45276] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c7LEFnm79ltp0SFA-ZAAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:44.930919 2026] [security2:error] [pid 45040:tid 45284] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c7LEFnm79ltp0SFA-YwAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:45.017666 2026] [security2:error] [pid 28702:tid 28872] [client 104.207.50.182:52651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c7LF4957xPw9VVBnOhAAAAKw"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:45.028684 2026] [security2:error] [pid 28702:tid 28914] [client 57.141.18.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c7LF4957xPw9VVBnOfwAAANY"]
[Mon Jul 20 07:04:45.061785 2026] [security2:error] [pid 28702:tid 28803] [remote 173.212.252.15:36636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4c7bF4957xPw9VVBnOhgAA42M"]
[Mon Jul 20 07:04:45.071512 2026] [security2:error] [pid 45040:tid 45265] [client 77.110.127.138:62516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7bEFnm79ltp0SFA-gAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:45.071586 2026] [security2:error] [pid 45040:tid 45265] [client 77.110.127.138:62516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7bEFnm79ltp0SFA-gAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:45.104768 2026] [security2:error] [pid 45040:tid 45098] [remote 5.252.52.249:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4c7bEFnm79ltp0SFA-ggAAYDc"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 07:04:45.131063 2026] [security2:error] [pid 29744:tid 29790] [remote 57.141.18.17:64958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cTOGINCUUz5GA9YIuwwACgiw"]
[Mon Jul 20 07:04:45.147323 2026] [security2:error] [pid 45040:tid 45174] [client 194.61.41.100:35149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/admin.php"] [unique_id "al4c7bEFnm79ltp0SFA-gwAAAAI"]
[Mon Jul 20 07:04:45.402727 2026] [security2:error] [pid 28702:tid 28931] [client 122.183.32.225:9198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4c7bF4957xPw9VVBnOjQAAAOc"]
[Mon Jul 20 07:04:45.402847 2026] [security2:error] [pid 28702:tid 28931] [client 122.183.32.225:9198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4c7bF4957xPw9VVBnOjQAAAOc"]
[Mon Jul 20 07:04:45.513511 2026] [security2:error] [pid 28702:tid 28731] [remote 173.212.252.15:36636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4c7bF4957xPw9VVBnOlgAA3Bs"], referer: https://iagdevelopments.com/wp-login.php
[Mon Jul 20 07:04:45.706926 2026] [security2:error] [pid 45040:tid 45186] [client 187.16.64.216:59217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c7bEFnm79ltp0SFA-mwAAAA4"]
[Mon Jul 20 07:04:45.707026 2026] [security2:error] [pid 45040:tid 45186] [client 187.16.64.216:59217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c7bEFnm79ltp0SFA-mwAAAA4"]
[Mon Jul 20 07:04:45.880916 2026] [security2:error] [pid 28702:tid 28797] [remote 152.228.213.32:34140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4c7bF4957xPw9VVBnOrwAA1V0"]
[Mon Jul 20 07:04:45.899684 2026] [security2:error] [pid 28702:tid 28885] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c7bF4957xPw9VVBnOoAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:45.899868 2026] [http2:warn] [pid 29744:tid 29891] [client 57.141.18.60:30554] h2_stream(29744-1045-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:45.940556 2026] [http2:warn] [pid 29744:tid 29898] [client 57.141.18.78:57632] h2_stream(29744-1046-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:45.949284 2026] [security2:error] [pid 28702:tid 28935] [client 194.61.41.94:38519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/adminfuns.php"] [unique_id "al4c7bF4957xPw9VVBnOsgAAAOs"]
[Mon Jul 20 07:04:46.065400 2026] [security2:error] [pid 28702:tid 28779] [remote 152.228.213.32:34140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4c7rF4957xPw9VVBnOtgAA8Us"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:04:46.142673 2026] [security2:error] [pid 28702:tid 28915] [client 104.234.53.83:63321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4c7rF4957xPw9VVBnOugAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:46.167258 2026] [security2:error] [pid 45040:tid 45060] [remote 156.67.31.167:38182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4c7rEFnm79ltp0SFA-qwAAKRI"]
[Mon Jul 20 07:04:46.277457 2026] [security2:error] [pid 28702:tid 28911] [client 77.110.127.138:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnOvgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.277544 2026] [security2:error] [pid 28702:tid 28911] [client 77.110.127.138:62525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnOvgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.385639 2026] [security2:error] [pid 45040:tid 45059] [remote 156.67.31.167:38182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4c7rEFnm79ltp0SFA-swAAOhE"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:04:46.432362 2026] [security2:error] [pid 45040:tid 45265] [client 77.110.127.138:62527] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/2*if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4c7rEFnm79ltp0SFA-tAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.434971 2026] [security2:error] [pid 28702:tid 28893] [client 77.110.127.138:62528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnOxAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.435072 2026] [security2:error] [pid 28702:tid 28893] [client 77.110.127.138:62528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnOxAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.443230 2026] [security2:error] [pid 45040:tid 45185] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c7rEFnm79ltp0SFA-sQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.580451 2026] [security2:error] [pid 45040:tid 45093] [remote 8.217.108.67:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4c7rEFnm79ltp0SFA-uAAAdjI"]
[Mon Jul 20 07:04:46.606411 2026] [security2:error] [pid 28702:tid 28942] [client 77.110.127.138:62530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnOzAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.606483 2026] [security2:error] [pid 28702:tid 28942] [client 77.110.127.138:62530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnOzAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.675737 2026] [http2:warn] [pid 28702:tid 28916] [client 57.141.18.59:49206] h2_stream(28702-731-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:46.725816 2026] [security2:error] [pid 28702:tid 28833] [client 194.61.41.77:22505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/autoload_classmap.php"] [unique_id "al4c7rF4957xPw9VVBnO0QAAAIU"]
[Mon Jul 20 07:04:46.766568 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnO1AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.766667 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:62531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnO1AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.932787 2026] [security2:error] [pid 28702:tid 28725] [remote 57.141.18.7:42422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6520800"] [unique_id "al4c7rF4957xPw9VVBnO3gAA_hU"]
[Mon Jul 20 07:04:46.933924 2026] [security2:error] [pid 28702:tid 28918] [client 77.110.127.138:62534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnO3wAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.934001 2026] [security2:error] [pid 28702:tid 28918] [client 77.110.127.138:62534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c7rF4957xPw9VVBnO3wAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:46.977249 2026] [security2:error] [pid 28702:tid 28726] [remote 57.141.18.53:30656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5480614"] [unique_id "al4c7rF4957xPw9VVBnO4gAA1BY"]
[Mon Jul 20 07:04:47.094277 2026] [security2:error] [pid 28702:tid 28876] [client 77.110.127.138:62537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c77F4957xPw9VVBnO6AAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:47.094399 2026] [security2:error] [pid 28702:tid 28876] [client 77.110.127.138:62537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c77F4957xPw9VVBnO6AAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:47.103167 2026] [security2:error] [pid 45040:tid 45289] [client 154.208.48.130:54639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c77EFnm79ltp0SFA-wwAAAHU"]
[Mon Jul 20 07:04:47.103290 2026] [security2:error] [pid 45040:tid 45289] [client 154.208.48.130:54639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c77EFnm79ltp0SFA-wwAAAHU"]
[Mon Jul 20 07:04:47.176777 2026] [security2:error] [pid 28702:tid 28889] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c7rF4957xPw9VVBnO4QAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:47.279593 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:62538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c77EFnm79ltp0SFA-xQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:47.279724 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:62538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c77EFnm79ltp0SFA-xQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:47.315304 2026] [http2:warn] [pid 29744:tid 29997] [client 57.141.18.39:22361] h2_stream(29744-1053-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:47.450762 2026] [security2:error] [pid 28702:tid 28949] [client 194.61.41.244:41559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp_wlx.php"] [unique_id "al4c77F4957xPw9VVBnO-wAAAPk"]
[Mon Jul 20 07:04:47.575340 2026] [access_compat:error] [pid 45040:tid 45292] [client 157.148.43.108:37785] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:04:47.587412 2026] [access_compat:error] [pid 28702:tid 28870] [client 112.90.2.143:60841] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:04:47.652595 2026] [security2:error] [pid 28702:tid 28896] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c77F4957xPw9VVBnO_AAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:47.676655 2026] [security2:error] [pid 28702:tid 28952] [client 201.27.111.74:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4c77F4957xPw9VVBnPCgAAAPw"]
[Mon Jul 20 07:04:47.676772 2026] [security2:error] [pid 28702:tid 28952] [client 201.27.111.74:65382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4c77F4957xPw9VVBnPCgAAAPw"]
[Mon Jul 20 07:04:47.677540 2026] [autoindex:error] [pid 28702:tid 28837] [client 15.204.183.221:18406] AH01276: Cannot serve directory /home3/vergotek/vergotek.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:47.730579 2026] [access_compat:error] [pid 28702:tid 28947] [client 157.148.43.75:59689] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:04:47.896114 2026] [http2:warn] [pid 29744:tid 29988] [client 57.141.18.72:54872] h2_stream(29744-1060-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:48.219233 2026] [security2:error] [pid 45040:tid 45177] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c8LEFnm79ltp0SFA-2QAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:48.248400 2026] [security2:error] [pid 45040:tid 45280] [client 194.61.41.251:42081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/wp-conflg.php"] [unique_id "al4c8LEFnm79ltp0SFA-4QAAAGw"]
[Mon Jul 20 07:04:48.592488 2026] [http2:warn] [pid 29744:tid 29969] [client 57.141.18.47:60104] h2_stream(29744-1063-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:48.603222 2026] [security2:error] [pid 28702:tid 28912] [client 104.207.50.138:53019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c8LF4957xPw9VVBnPMwAAANQ"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:48.830117 2026] [http2:warn] [pid 29744:tid 29947] [client 57.141.18.121:40990] h2_stream(29744-1065-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:48.877648 2026] [security2:error] [pid 28702:tid 28904] [client 34.173.238.42:50798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "ferrellroofing.com"] [uri "/wp-json/batch/v1"] [unique_id "al4c8LF4957xPw9VVBnPPQAAAMw"]
[Mon Jul 20 07:04:49.011733 2026] [http2:warn] [pid 29744:tid 29972] [client 57.141.18.55:44778] h2_stream(29744-1066-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:49.056622 2026] [security2:error] [pid 45040:tid 45253] [client 194.61.41.69:48919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/husky301.php"] [unique_id "al4c8bEFnm79ltp0SFA_BgAAAFE"]
[Mon Jul 20 07:04:49.140807 2026] [security2:error] [pid 45040:tid 45211] [client 77.110.127.138:62517] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/20'XOR(2*if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4c8bEFnm79ltp0SFA_CQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:49.158582 2026] [security2:error] [pid 28702:tid 28872] [client 104.234.53.57:27527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4c8bF4957xPw9VVBnPRgAAAKw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:49.198504 2026] [security2:error] [pid 45040:tid 45173] [client 65.111.23.32:50119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c8bEFnm79ltp0SFA_CgAAAAE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:49.199968 2026] [security2:error] [pid 45040:tid 45214] [client 77.110.127.138:62521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c8bEFnm79ltp0SFA_DQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:49.200061 2026] [security2:error] [pid 45040:tid 45214] [client 77.110.127.138:62521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c8bEFnm79ltp0SFA_DQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:49.590726 2026] [access_compat:error] [pid 45040:tid 45176] [client 183.47.107.69:48177] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:04:49.767406 2026] [security2:error] [pid 45040:tid 45226] [client 104.207.51.216:14837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c8bEFnm79ltp0SFA_JAAAADY"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:49.850339 2026] [security2:error] [pid 45040:tid 45296] [client 194.61.41.66:40095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp.php"] [unique_id "al4c8bEFnm79ltp0SFA_KQAAAHw"]
[Mon Jul 20 07:04:49.853928 2026] [security2:error] [pid 45040:tid 45197] [client 13.229.223.11:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4c8bEFnm79ltp0SFA_KAAAABk"]
[Mon Jul 20 07:04:50.099848 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:62565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c8bEFnm79ltp0SFA_LQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:50.129911 2026] [http2:warn] [pid 29744:tid 29879] [client 57.141.18.101:21698] h2_stream(29744-1073-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:50.333114 2026] [security2:error] [pid 45040:tid 45202] [client 77.110.127.138:62567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/21/"] [unique_id "al4c8rEFnm79ltp0SFA_QgAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:50.344052 2026] [security2:error] [pid 28702:tid 28954] [client 117.222.139.248:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.139.222.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c8rF4957xPw9VVBnPbwAAAP4"]
[Mon Jul 20 07:04:50.344162 2026] [security2:error] [pid 28702:tid 28954] [client 117.222.139.248:56282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecruit.online"] [uri "/xmlrpc.php"] [unique_id "al4c8rF4957xPw9VVBnPbwAAAP4"]
[Mon Jul 20 07:04:50.353438 2026] [security2:error] [pid 45040:tid 45290] [client 65.111.22.104:35999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c8rEFnm79ltp0SFA_QQAAAHY"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:50.413005 2026] [security2:error] [pid 45040:tid 45155] [remote 8.217.108.67:53520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4c8rEFnm79ltp0SFA_RwAATnA"], referer: https://grndl.com/wp-login.php
[Mon Jul 20 07:04:50.597290 2026] [security2:error] [pid 45040:tid 45193] [client 77.110.127.138:62568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c8rEFnm79ltp0SFA_RgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:50.652682 2026] [security2:error] [pid 28702:tid 28847] [client 194.61.41.88:62363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/wp-trackback.php"] [unique_id "al4c8rF4957xPw9VVBnPfQAAAJM"]
[Mon Jul 20 07:04:50.698544 2026] [http2:warn] [pid 29744:tid 29895] [client 57.141.18.92:61670] h2_stream(29744-1078-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:50.768666 2026] [http2:warn] [pid 28702:tid 28895] [client 57.141.18.70:63122] h2_stream(28702-751-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:50.775234 2026] [security2:error] [pid 45040:tid 45217] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c8rEFnm79ltp0SFA_TAAAAC0"]
[Mon Jul 20 07:04:50.835723 2026] [security2:error] [pid 45040:tid 45231] [client 18.141.57.241:11220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4c8rEFnm79ltp0SFA_VgAAADs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:04:50.933054 2026] [security2:error] [pid 28702:tid 28892] [client 104.207.52.163:28383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c8rF4957xPw9VVBnPhgAAAMA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:51.142045 2026] [security2:error] [pid 28702:tid 28865] [client 103.144.65.217:50029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c87F4957xPw9VVBnPkAAAAKU"]
[Mon Jul 20 07:04:51.142164 2026] [security2:error] [pid 28702:tid 28865] [client 103.144.65.217:50029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c87F4957xPw9VVBnPkAAAAKU"]
[Mon Jul 20 07:04:51.180372 2026] [security2:error] [pid 28702:tid 28931] [client 158.173.166.181:21535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4c87F4957xPw9VVBnPkgAAAOc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:04:51.260266 2026] [security2:error] [pid 28702:tid 28929] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c8rF4957xPw9VVBnPhwAAAOU"]
[Mon Jul 20 07:04:51.286668 2026] [security2:error] [pid 45040:tid 45195] [client 77.110.127.138:62571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c8rEFnm79ltp0SFA_WQAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:51.423141 2026] [security2:error] [pid 28702:tid 28858] [client 194.61.41.69:58125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/chosen.php"] [unique_id "al4c87F4957xPw9VVBnPmwAAAJ4"]
[Mon Jul 20 07:04:51.441574 2026] [security2:error] [pid 45040:tid 45236] [client 13.232.231.177:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4c87EFnm79ltp0SFA_ZQAAAEA"]
[Mon Jul 20 07:04:51.446812 2026] [security2:error] [pid 45040:tid 45249] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4c87EFnm79ltp0SFA_YwAAAE0"]
[Mon Jul 20 07:04:51.467104 2026] [http2:warn] [pid 28702:tid 28875] [client 57.141.18.93:49278] h2_stream(28702-752-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:51.519699 2026] [security2:error] [pid 28702:tid 28876] [client 65.111.23.56:25143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4c87F4957xPw9VVBnPoAAAALA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:04:51.727047 2026] [security2:error] [pid 45040:tid 45181] [client 77.110.127.138:62575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c87EFnm79ltp0SFA_aQAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:51.756815 2026] [security2:error] [pid 28702:tid 28873] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c87F4957xPw9VVBnPpQAAAK0"]
[Mon Jul 20 07:04:51.837194 2026] [security2:error] [pid 45040:tid 45277] [client 77.110.127.138:62576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c87EFnm79ltp0SFA_eAAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:51.837271 2026] [security2:error] [pid 45040:tid 45277] [client 77.110.127.138:62576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c87EFnm79ltp0SFA_eAAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:51.837666 2026] [autoindex:error] [pid 45040:tid 45159] [remote 34.29.15.208:57634] AH01276: Cannot serve directory /home2/jopjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.jop.jiv.mybluehost.me
[Mon Jul 20 07:04:51.987553 2026] [security2:error] [pid 28702:tid 28946] [client 77.110.127.138:62578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/20\\"XOR(2*if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4c87F4957xPw9VVBnPsgAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:52.040866 2026] [security2:error] [pid 28702:tid 28892] [client 77.110.127.138:62546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c87F4957xPw9VVBnPrAAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:52.073166 2026] [security2:error] [pid 45040:tid 45297] [client 213.152.186.163:38860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4c9LEFnm79ltp0SFA_hwAAAH0"]
[Mon Jul 20 07:04:52.073262 2026] [security2:error] [pid 45040:tid 45297] [client 213.152.186.163:38860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4c9LEFnm79ltp0SFA_hwAAAH0"]
[Mon Jul 20 07:04:52.129431 2026] [security2:error] [pid 45040:tid 45110] [remote 152.228.213.32:45506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4c9LEFnm79ltp0SFA_jwAAKUM"]
[Mon Jul 20 07:04:52.151025 2026] [security2:error] [pid 28702:tid 28915] [client 194.61.41.94:44659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-header.php"] [unique_id "al4c9LF4957xPw9VVBnPuAAAANc"]
[Mon Jul 20 07:04:52.205513 2026] [security2:error] [pid 45040:tid 45194] [client 89.124.113.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4c87EFnm79ltp0SFA_ggAAABY"], referer: https://secretkeynumerology.com/hold-down-the-fourt/
[Mon Jul 20 07:04:52.218291 2026] [security2:error] [pid 45040:tid 45273] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c87EFnm79ltp0SFA_hAAAAGU"]
[Mon Jul 20 07:04:52.245110 2026] [security2:error] [pid 45040:tid 45228] [client 117.247.108.24:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c9LEFnm79ltp0SFA_lAAAADg"]
[Mon Jul 20 07:04:52.245210 2026] [security2:error] [pid 45040:tid 45228] [client 117.247.108.24:49204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c9LEFnm79ltp0SFA_lAAAADg"]
[Mon Jul 20 07:04:52.330395 2026] [security2:error] [pid 45040:tid 45128] [remote 152.228.213.32:45506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4c9LEFnm79ltp0SFA_mAAAHVU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:04:52.386942 2026] [http2:warn] [pid 28702:tid 28921] [client 57.141.18.26:43408] h2_stream(28702-755-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:52.447164 2026] [security2:error] [pid 28702:tid 28950] [client 77.110.127.138:62580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9LF4957xPw9VVBnPugAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:52.593355 2026] [security2:error] [pid 45040:tid 45208] [client 43.205.139.3:40574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4c9LEFnm79ltp0SFA_ogAAACQ"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:04:52.611855 2026] [http2:warn] [pid 28702:tid 28849] [client 57.141.18.120:35522] h2_stream(28702-757-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:52.618878 2026] [security2:error] [pid 45040:tid 45292] [client 77.110.127.138:62517] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/21/"] [unique_id "al4c9LEFnm79ltp0SFA_pQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:52.659051 2026] [security2:error] [pid 45040:tid 45287] [client 183.82.98.154:60479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c9LEFnm79ltp0SFA_qgAAAHM"]
[Mon Jul 20 07:04:52.659179 2026] [security2:error] [pid 45040:tid 45287] [client 183.82.98.154:60479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c9LEFnm79ltp0SFA_qgAAAHM"]
[Mon Jul 20 07:04:52.771083 2026] [security2:error] [pid 45040:tid 45247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9LEFnm79ltp0SFA_oAAAAEs"]
[Mon Jul 20 07:04:52.895339 2026] [security2:error] [pid 28702:tid 28953] [client 77.110.127.138:62562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9LF4957xPw9VVBnPywAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:52.928528 2026] [security2:error] [pid 45040:tid 45263] [client 194.61.41.62:62955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/admin.php"] [unique_id "al4c9LEFnm79ltp0SFA_sgAAAFs"]
[Mon Jul 20 07:04:53.054937 2026] [security2:error] [pid 28702:tid 28836] [client 4.194.24.143:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/nine2code.php"] [unique_id "al4c9bF4957xPw9VVBnP1AAAAIg"]
[Mon Jul 20 07:04:53.166881 2026] [security2:error] [pid 45040:tid 45107] [remote 45.90.123.233:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4c9bEFnm79ltp0SFA_xwAAPUA"]
[Mon Jul 20 07:04:53.202937 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9LEFnm79ltp0SFA_twAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:53.256490 2026] [security2:error] [pid 45040:tid 45198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9bEFnm79ltp0SFA_vAAAABo"]
[Mon Jul 20 07:04:53.433333 2026] [security2:error] [pid 45040:tid 45109] [remote 45.90.123.233:37388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4c9bEFnm79ltp0SFA_zQAACUI"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 07:04:53.487467 2026] [security2:error] [pid 45040:tid 45282] [client 77.110.127.138:62567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9bEFnm79ltp0SFA_ywAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:53.595326 2026] [security2:error] [pid 28702:tid 28861] [client 4.194.24.143:32520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/num.php"] [unique_id "al4c9bF4957xPw9VVBnP7QAAAKE"]
[Mon Jul 20 07:04:53.662139 2026] [security2:error] [pid 45040:tid 45252] [client 194.61.41.77:51865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/Marvins.php"] [unique_id "al4c9bEFnm79ltp0SFA_1QAAAFA"]
[Mon Jul 20 07:04:53.699601 2026] [security2:error] [pid 45040:tid 45212] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9bEFnm79ltp0SFA_zgAAACg"]
[Mon Jul 20 07:04:53.824297 2026] [security2:error] [pid 45040:tid 45287] [client 77.110.127.138:62568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9bEFnm79ltp0SFA_0AAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:53.827137 2026] [security2:error] [pid 45040:tid 45297] [client 57.141.18.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4c9bEFnm79ltp0SFA_0wAAAH0"]
[Mon Jul 20 07:04:53.841755 2026] [security2:error] [pid 28702:tid 28926] [client 104.234.53.68:64743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4c9bF4957xPw9VVBnP9gAAAOI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:53.963865 2026] [http2:warn] [pid 29744:tid 29953] [client 57.141.18.72:54886] h2_stream(29744-1098-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:54.106681 2026] [http2:warn] [pid 29744:tid 29880] [client 57.141.18.81:28130] h2_stream(29744-1099-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:54.166328 2026] [security2:error] [pid 45040:tid 45275] [client 4.194.24.143:26737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4c9rEFnm79ltp0SFA_7AAAAGc"]
[Mon Jul 20 07:04:54.303332 2026] [security2:error] [pid 28702:tid 28847] [client 89.124.113.107:60542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4c9rF4957xPw9VVBnQDwAAAJM"], referer: https://www.secretkeynumerology.com/hold-down-the-fourt/
[Mon Jul 20 07:04:54.303464 2026] [security2:error] [pid 28702:tid 28847] [client 89.124.113.107:60542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4c9rF4957xPw9VVBnQDwAAAJM"], referer: https://www.secretkeynumerology.com/hold-down-the-fourt/
[Mon Jul 20 07:04:54.369558 2026] [security2:error] [pid 45040:tid 45173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9rEFnm79ltp0SFA_7gAAAAE"]
[Mon Jul 20 07:04:54.438673 2026] [security2:error] [pid 28702:tid 28879] [client 194.61.41.78:41157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/about.php"] [unique_id "al4c9rF4957xPw9VVBnQFQAAALM"]
[Mon Jul 20 07:04:54.439940 2026] [security2:error] [pid 28702:tid 28946] [client 77.110.127.138:62529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9rF4957xPw9VVBnQDQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:54.708528 2026] [security2:error] [pid 45040:tid 45208] [client 4.194.24.143:32553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/option.php"] [unique_id "al4c9rEFnm79ltp0SFA__QAAACQ"]
[Mon Jul 20 07:04:54.890550 2026] [http2:warn] [pid 28702:tid 28850] [client 57.141.18.72:54896] h2_stream(28702-764-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:54.900161 2026] [http2:warn] [pid 29744:tid 29913] [client 57.141.18.80:44724] h2_stream(29744-1106-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:55.054415 2026] [security2:error] [pid 45040:tid 45259] [client 77.110.127.138:62535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9rEFnm79ltp0SFBAAQAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:55.101822 2026] [security2:error] [pid 28702:tid 28923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c9rF4957xPw9VVBnQIQAAAN8"]
[Mon Jul 20 07:04:55.146911 2026] [security2:error] [pid 45040:tid 45232] [client 77.110.127.138:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c97EFnm79ltp0SFBAEAAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:55.147003 2026] [security2:error] [pid 45040:tid 45232] [client 77.110.127.138:62575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c97EFnm79ltp0SFBAEAAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:55.249514 2026] [security2:error] [pid 45040:tid 45186] [client 4.194.24.143:2883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/p.php"] [unique_id "al4c97EFnm79ltp0SFBAFQAAAA4"]
[Mon Jul 20 07:04:55.250946 2026] [security2:error] [pid 28702:tid 28933] [client 194.61.41.54:20439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-class.php"] [unique_id "al4c97F4957xPw9VVBnQMgAAAOk"]
[Mon Jul 20 07:04:55.490427 2026] [security2:error] [pid 28702:tid 28920] [client 104.234.53.56:51425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4c97F4957xPw9VVBnQRQAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:55.620798 2026] [security2:error] [pid 28702:tid 28865] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c97F4957xPw9VVBnQQgAAAKU"]
[Mon Jul 20 07:04:55.808722 2026] [security2:error] [pid 45040:tid 45217] [client 4.194.24.143:4650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/past.php"] [unique_id "al4c97EFnm79ltp0SFBAJgAAAC0"]
[Mon Jul 20 07:04:55.890900 2026] [security2:error] [pid 45040:tid 45187] [client 77.110.127.138:62577] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/21/"] [unique_id "al4c97EFnm79ltp0SFBALAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:55.957834 2026] [security2:error] [pid 28702:tid 28938] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c97F4957xPw9VVBnQUQAAAO4"]
[Mon Jul 20 07:04:56.029311 2026] [security2:error] [pid 45040:tid 45267] [client 194.61.41.108:24349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/smilies/index.php"] [unique_id "al4c-LEFnm79ltp0SFBAMwAAAF8"]
[Mon Jul 20 07:04:56.192003 2026] [authz_core:error] [pid 45040:tid 45226] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Mon Jul 20 07:04:56.286520 2026] [security2:error] [pid 28702:tid 28954] [client 122.183.32.225:30565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4c-LF4957xPw9VVBnQaAAAAP4"]
[Mon Jul 20 07:04:56.286626 2026] [security2:error] [pid 28702:tid 28954] [client 122.183.32.225:30565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4c-LF4957xPw9VVBnQaAAAAP4"]
[Mon Jul 20 07:04:56.384906 2026] [security2:error] [pid 45040:tid 45254] [client 98.159.234.160:25449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4c-LEFnm79ltp0SFBAUgAAAFI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:04:56.403654 2026] [security2:error] [pid 28702:tid 28922] [client 4.194.24.143:4622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/php.php"] [unique_id "al4c-LF4957xPw9VVBnQbAAAAN4"]
[Mon Jul 20 07:04:56.416010 2026] [security2:error] [pid 45040:tid 45204] [client 187.16.64.216:59788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c-LEFnm79ltp0SFBAVAAAACA"]
[Mon Jul 20 07:04:56.416131 2026] [security2:error] [pid 45040:tid 45204] [client 187.16.64.216:59788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4c-LEFnm79ltp0SFBAVAAAACA"]
[Mon Jul 20 07:04:56.506085 2026] [security2:error] [pid 28702:tid 28929] [client 66.249.82.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jenfarley.com"] [uri "/index.php"] [unique_id "al4c97F4957xPw9VVBnQTwAAAOU"]
[Mon Jul 20 07:04:56.522008 2026] [http2:warn] [pid 29744:tid 29941] [client 57.141.18.29:46708] h2_stream(29744-1115-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:56.664797 2026] [security2:error] [pid 28702:tid 28853] [client 50.116.65.227:22116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4c-LF4957xPw9VVBnQcgAAAJk"]
[Mon Jul 20 07:04:56.674899 2026] [security2:error] [pid 45040:tid 45217] [client 50.116.65.227:22124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4c-LEFnm79ltp0SFBAWAAAAC0"]
[Mon Jul 20 07:04:56.761460 2026] [security2:error] [pid 28702:tid 28861] [client 194.61.41.108:21047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/xx.php"] [unique_id "al4c-LF4957xPw9VVBnQeAAAAKE"]
[Mon Jul 20 07:04:56.925083 2026] [security2:error] [pid 45040:tid 45271] [client 14.251.3.155:55898] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4c-LEFnm79ltp0SFBAXwAAAGM"]
[Mon Jul 20 07:04:56.951933 2026] [security2:error] [pid 45040:tid 45244] [client 104.234.53.86:39091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4c-LEFnm79ltp0SFBAYwAAAEg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:56.977610 2026] [security2:error] [pid 45040:tid 45126] [remote 51.158.61.221:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4c-LEFnm79ltp0SFBAZgAAG1M"]
[Mon Jul 20 07:04:57.010218 2026] [security2:error] [pid 28702:tid 28907] [client 4.194.24.143:2894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/php8.php"] [unique_id "al4c-bF4957xPw9VVBnQgAAAAM8"]
[Mon Jul 20 07:04:57.017840 2026] [http2:warn] [pid 28702:tid 28910] [client 57.141.18.93:49294] h2_stream(28702-773-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:57.018585 2026] [http2:warn] [pid 28702:tid 28919] [client 57.141.18.102:40298] h2_stream(28702-774-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:57.167320 2026] [security2:error] [pid 45040:tid 45150] [remote 51.158.61.221:42668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4c-bEFnm79ltp0SFBAcgAAYms"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 07:04:57.310197 2026] [security2:error] [pid 45040:tid 45203] [client 114.119.133.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4c-bEFnm79ltp0SFBAaQAAAB8"], referer: http://bluedoorbar.co.nz/pagine/43569-AZQPGKQCFM.html
[Mon Jul 20 07:04:57.364700 2026] [security2:error] [pid 28702:tid 28719] [remote 97.74.93.24:45372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4c-bF4957xPw9VVBnQlQABAg8"]
[Mon Jul 20 07:04:57.506763 2026] [security2:error] [pid 45040:tid 45264] [client 201.27.111.74:49570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4c-bEFnm79ltp0SFBAegAAAFw"]
[Mon Jul 20 07:04:57.506944 2026] [security2:error] [pid 45040:tid 45264] [client 201.27.111.74:49570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4c-bEFnm79ltp0SFBAegAAAFw"]
[Mon Jul 20 07:04:57.535681 2026] [autoindex:error] [pid 28702:tid 28846] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/01/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:04:57.563312 2026] [security2:error] [pid 45040:tid 45278] [client 4.194.24.143:1080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/phpinfo.php"] [unique_id "al4c-bEFnm79ltp0SFBAfgAAAGo"]
[Mon Jul 20 07:04:57.566306 2026] [security2:error] [pid 28702:tid 28861] [client 194.61.41.250:57349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/autoload_classmap.php"] [unique_id "al4c-bF4957xPw9VVBnQowAAAKE"]
[Mon Jul 20 07:04:57.603931 2026] [http2:warn] [pid 29744:tid 29996] [client 57.141.18.102:40302] h2_stream(29744-1125-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:57.700488 2026] [autoindex:error] [pid 28702:tid 28934] [client 167.86.82.167:54618] AH01276: Cannot serve directory /home3/wathenba/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:04:57.742237 2026] [security2:error] [pid 28702:tid 28838] [client 77.110.127.138:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c-bF4957xPw9VVBnQrgAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:57.742323 2026] [security2:error] [pid 28702:tid 28838] [client 77.110.127.138:62562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c-bF4957xPw9VVBnQrgAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:57.783813 2026] [security2:error] [pid 28702:tid 28749] [remote 97.74.93.24:45372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4c-bF4957xPw9VVBnQsAAAqC0"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:04:57.914676 2026] [http2:warn] [pid 29744:tid 29904] [client 57.141.18.45:55108] h2_stream(29744-1127-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:57.942622 2026] [security2:error] [pid 28702:tid 28929] [client 34.173.238.42:64508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "ferrellroofing.com"] [uri "/wp-json/batch/v1"] [unique_id "al4c-bF4957xPw9VVBnQvAAAAOU"]
[Mon Jul 20 07:04:58.028250 2026] [security2:error] [pid 45040:tid 45193] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c-bEFnm79ltp0SFBAiAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:58.102184 2026] [security2:error] [pid 45040:tid 45237] [client 154.208.48.130:55143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c-rEFnm79ltp0SFBAiwAAAEE"]
[Mon Jul 20 07:04:58.102283 2026] [security2:error] [pid 45040:tid 45237] [client 154.208.48.130:55143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4c-rEFnm79ltp0SFBAiwAAAEE"]
[Mon Jul 20 07:04:58.229352 2026] [security2:error] [pid 29744:tid 29775] [remote 57.141.18.54:51500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cTeGINCUUz5GA9YIvGgACah0"]
[Mon Jul 20 07:04:58.253254 2026] [http2:warn] [pid 28702:tid 28852] [client 57.141.18.91:49702] h2_stream(28702-779-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:58.301297 2026] [security2:error] [pid 28702:tid 28859] [client 4.194.24.143:1081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/post.php"] [unique_id "al4c-rF4957xPw9VVBnQyQAAAJ8"]
[Mon Jul 20 07:04:58.320555 2026] [authz_core:error] [pid 45040:tid 45276] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Mon Jul 20 07:04:58.331637 2026] [security2:error] [pid 45040:tid 45273] [client 194.61.41.79:36053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/classwithtostring.php"] [unique_id "al4c-rEFnm79ltp0SFBAmQAAAGU"]
[Mon Jul 20 07:04:58.478788 2026] [security2:error] [pid 45040:tid 45244] [client 77.110.127.138:62607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4c-rEFnm79ltp0SFBAkwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:04:58.565572 2026] [http2:warn] [pid 45040:tid 45281] [client 57.141.18.58:22764] h2_stream(45040-7-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:58.841649 2026] [security2:error] [pid 45040:tid 45291] [client 4.194.24.143:4628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4c-rEFnm79ltp0SFBApQAAAHc"]
[Mon Jul 20 07:04:58.881901 2026] [http2:warn] [pid 28702:tid 28898] [client 57.141.18.96:48208] h2_stream(28702-781-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:04:59.037603 2026] [security2:error] [pid 45040:tid 45224] [client 194.61.41.253:37341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/blue.php"] [unique_id "al4c-7EFnm79ltp0SFBArwAAADQ"]
[Mon Jul 20 07:04:59.253047 2026] [security2:error] [pid 28702:tid 28866] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4c-rF4957xPw9VVBnQ3gAApiQ"], referer: http://assasalnazaha.com/2023
[Mon Jul 20 07:04:59.328688 2026] [security2:error] [pid 28702:tid 28922] [client 104.234.53.88:55817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4c-7F4957xPw9VVBnQ-QAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:04:59.388016 2026] [security2:error] [pid 45040:tid 45247] [client 4.194.24.143:32538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/public/css.php"] [unique_id "al4c-7EFnm79ltp0SFBAuwAAAEs"]
[Mon Jul 20 07:04:59.555945 2026] [security2:error] [pid 45040:tid 45178] [client 14.225.17.146:52592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4c-7EFnm79ltp0SFBAvAAAAAY"], referer: http://elitetax-mi.com/2023
[Mon Jul 20 07:04:59.845182 2026] [security2:error] [pid 28702:tid 28872] [client 104.168.59.36:33814] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "www.website-485f7426.pfl.ail.mybluehost.me"] [uri "/"] [unique_id "al4c-7F4957xPw9VVBnREAAAAKw"]
[Mon Jul 20 07:04:59.857495 2026] [security2:error] [pid 45040:tid 45249] [client 194.61.41.95:49731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/content.php"] [unique_id "al4c-7EFnm79ltp0SFBA0wAAAE0"]
[Mon Jul 20 07:04:59.875273 2026] [security2:error] [pid 45040:tid 45274] [client 104.168.59.36:33822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-485f7426.pfl.ail.mybluehost.me"] [uri "/"] [unique_id "al4c-7EFnm79ltp0SFBA1QAAAGY"]
[Mon Jul 20 07:04:59.952128 2026] [security2:error] [pid 28702:tid 28954] [client 4.194.24.143:32528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/r.php"] [unique_id "al4c-7F4957xPw9VVBnRGAAAAP4"]
[Mon Jul 20 07:05:00.065115 2026] [http2:warn] [pid 29744:tid 29986] [client 57.141.18.43:33742] h2_stream(29744-1141-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:00.146931 2026] [security2:error] [pid 28702:tid 28788] [remote 173.249.4.11:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c_LF4957xPw9VVBnRHQAAklQ"]
[Mon Jul 20 07:05:00.333492 2026] [security2:error] [pid 28702:tid 28708] [remote 173.249.4.11:57208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4c_LF4957xPw9VVBnRIQAAwQQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:05:00.527310 2026] [security2:error] [pid 45040:tid 45277] [client 4.194.24.143:2910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/radio.php"] [unique_id "al4c_LEFnm79ltp0SFBA5gAAAGk"]
[Mon Jul 20 07:05:00.630713 2026] [security2:error] [pid 45040:tid 45206] [client 14.225.17.146:49611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4c_LEFnm79ltp0SFBA4QAAACI"], referer: http://sesamegreenbeans.com/2023
[Mon Jul 20 07:05:00.666018 2026] [security2:error] [pid 45040:tid 45178] [client 194.61.41.240:28567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/about.php"] [unique_id "al4c_LEFnm79ltp0SFBA8gAAAAY"]
[Mon Jul 20 07:05:00.701011 2026] [authz_core:error] [pid 45040:tid 45207] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/widgets/error_log, referer: binance.com
[Mon Jul 20 07:05:00.781507 2026] [security2:error] [pid 28702:tid 28918] [client 14.225.17.146:51559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4c-rF4957xPw9VVBnQxAAAANo"], referer: http://bruceledewitz.com/2023
[Mon Jul 20 07:05:00.823267 2026] [http2:warn] [pid 28702:tid 28843] [client 57.141.18.7:31590] h2_stream(28702-791-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:00.849512 2026] [security2:error] [pid 28702:tid 28939] [client 14.225.17.146:59020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4c-7F4957xPw9VVBnRAQAAAO8"], referer: http://eframiproperties.com/2023
[Mon Jul 20 07:05:00.894510 2026] [security2:error] [pid 45040:tid 45079] [remote 124.55.178.99:46388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4c_LEFnm79ltp0SFBBAAAAVSQ"]
[Mon Jul 20 07:05:00.894725 2026] [security2:error] [pid 45040:tid 45257] [client 124.55.178.99:46388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4c_LEFnm79ltp0SFBBAAAAVSQ"]
[Mon Jul 20 07:05:00.899334 2026] [security2:error] [pid 28702:tid 28946] [client 34.173.238.42:64508] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ferrellroofing.com"] [uri "/"] [unique_id "al4c_LF4957xPw9VVBnRMgAAAPY"]
[Mon Jul 20 07:05:01.067563 2026] [security2:error] [pid 45040:tid 45055] [remote 162.19.86.63:58358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4c_bEFnm79ltp0SFBBCgAAXA0"]
[Mon Jul 20 07:05:01.074466 2026] [security2:error] [pid 45040:tid 45218] [client 4.194.24.143:32573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/randkeyword.php7"] [unique_id "al4c_bEFnm79ltp0SFBBCwAAAC4"]
[Mon Jul 20 07:05:01.161887 2026] [security2:error] [pid 28702:tid 28860] [client 31.13.127.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "ladybugscoops.com"] [uri "/index.php"] [unique_id "al4c_bF4957xPw9VVBnRNwAAAKA"]
[Mon Jul 20 07:05:01.411060 2026] [http2:warn] [pid 29744:tid 29965] [client 57.141.18.101:24044] h2_stream(29744-1151-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:01.516296 2026] [security2:error] [pid 28702:tid 28882] [client 194.61.41.247:29287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/wp-login.php"] [unique_id "al4c_bF4957xPw9VVBnRUQAAALY"]
[Mon Jul 20 07:05:01.619008 2026] [security2:error] [pid 28702:tid 28893] [client 4.194.24.143:32548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/readme.php"] [unique_id "al4c_bF4957xPw9VVBnRWwAAAME"]
[Mon Jul 20 07:05:01.635370 2026] [security2:error] [pid 45040:tid 45075] [remote 162.19.86.63:58358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4c_bEFnm79ltp0SFBBEgAAcCA"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:05:01.645444 2026] [security2:error] [pid 28702:tid 28913] [client 14.225.17.146:50478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4c_bF4957xPw9VVBnRTAAAANU"], referer: https://sesamegreenbeans.com/2023
[Mon Jul 20 07:05:01.692857 2026] [security2:error] [pid 28702:tid 28841] [client 40.77.177.100:19522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4c_bF4957xPw9VVBnRTQAAjT4"]
[Mon Jul 20 07:05:01.750297 2026] [security2:error] [pid 45040:tid 45241] [client 103.144.65.217:50491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c_bEFnm79ltp0SFBBGAAAAEU"]
[Mon Jul 20 07:05:01.752097 2026] [security2:error] [pid 45040:tid 45241] [client 103.144.65.217:50491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4c_bEFnm79ltp0SFBBGAAAAEU"]
[Mon Jul 20 07:05:01.790650 2026] [http2:warn] [pid 29744:tid 29882] [client 57.141.18.93:44122] h2_stream(29744-1154-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:02.234224 2026] [security2:error] [pid 45040:tid 45222] [client 4.194.24.143:2885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/reze.php"] [unique_id "al4c_rEFnm79ltp0SFBBJgAAADI"]
[Mon Jul 20 07:05:02.342102 2026] [http2:warn] [pid 29744:tid 29932] [client 57.141.18.101:24054] h2_stream(29744-1161-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:02.389015 2026] [http2:warn] [pid 29744:tid 29889] [client 57.141.18.63:42516] h2_stream(29744-1162-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:02.477502 2026] [security2:error] [pid 28702:tid 28867] [client 194.61.41.86:45477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/rest-api/endpoints/index.php"] [unique_id "al4c_rF4957xPw9VVBnRhgAAAKc"]
[Mon Jul 20 07:05:02.494828 2026] [security2:error] [pid 45040:tid 45220] [client 45.157.112.60:37849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4c_rEFnm79ltp0SFBBKwAAADA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:05:02.516627 2026] [security2:error] [pid 29744:tid 29796] [remote 57.141.18.87:21086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cTuGINCUUz5GA9YIvZAACHDI"]
[Mon Jul 20 07:05:02.697257 2026] [security2:error] [pid 45040:tid 45234] [client 24.225.198.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4c_rEFnm79ltp0SFBBLAAAPjc"]
[Mon Jul 20 07:05:02.802120 2026] [security2:error] [pid 45040:tid 45261] [client 14.225.17.146:60170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4c_bEFnm79ltp0SFBBDgAAAFk"], referer: http://blaizeaccountingservices.com/2023
[Mon Jul 20 07:05:02.806870 2026] [security2:error] [pid 28702:tid 28938] [client 4.194.24.143:2894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/rh.php"] [unique_id "al4c_rF4957xPw9VVBnRlwAAAO4"]
[Mon Jul 20 07:05:02.877961 2026] [security2:error] [pid 45040:tid 45228] [client 104.234.53.57:30001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4c_rEFnm79ltp0SFBBPQAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:02.910069 2026] [security2:error] [pid 45040:tid 45187] [client 74.7.228.42:60784] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "notthesermon.com"] [uri "/robots.txt"] [unique_id "al4c_rEFnm79ltp0SFBBPgAADx8"]
[Mon Jul 20 07:05:02.969832 2026] [security2:error] [pid 28702:tid 28909] [client 117.247.108.24:49784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c_rF4957xPw9VVBnRnQAAANE"]
[Mon Jul 20 07:05:02.969945 2026] [security2:error] [pid 28702:tid 28909] [client 117.247.108.24:49784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4c_rF4957xPw9VVBnRnQAAANE"]
[Mon Jul 20 07:05:03.234498 2026] [http2:warn] [pid 28702:tid 28925] [client 57.141.18.95:54112] h2_stream(28702-1012-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:03.296775 2026] [security2:error] [pid 45040:tid 45244] [client 194.61.41.81:39179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/about.php"] [unique_id "al4c_7EFnm79ltp0SFBBTAAAAEg"]
[Mon Jul 20 07:05:03.342107 2026] [security2:error] [pid 45040:tid 45226] [client 183.82.98.154:61075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c_7EFnm79ltp0SFBBTQAAADY"]
[Mon Jul 20 07:05:03.342227 2026] [security2:error] [pid 45040:tid 45226] [client 183.82.98.154:61075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4c_7EFnm79ltp0SFBBTQAAADY"]
[Mon Jul 20 07:05:03.346708 2026] [security2:error] [pid 45040:tid 45265] [client 4.194.24.143:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/rip.php"] [unique_id "al4c_7EFnm79ltp0SFBBTgAAAF0"]
[Mon Jul 20 07:05:03.477084 2026] [http2:warn] [pid 28702:tid 28897] [client 57.141.18.94:24480] h2_stream(28702-796-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:03.514773 2026] [security2:error] [pid 28702:tid 28838] [client 77.110.127.138:62619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c_7F4957xPw9VVBnRtgAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:03.514883 2026] [security2:error] [pid 28702:tid 28838] [client 77.110.127.138:62619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4c_7F4957xPw9VVBnRtgAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:03.887185 2026] [security2:error] [pid 45040:tid 45291] [client 4.194.24.143:32533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/root.php"] [unique_id "al4c_7EFnm79ltp0SFBBVQAAAHc"]
[Mon Jul 20 07:05:04.040377 2026] [security2:error] [pid 45040:tid 45227] [client 194.61.41.241:49235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/wp-theme-editor/include.php"] [unique_id "al4dALEFnm79ltp0SFBBXQAAADc"]
[Mon Jul 20 07:05:04.058265 2026] [security2:error] [pid 45040:tid 45224] [client 104.168.114.154:55708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.dotx.com"] [uri "/"] [unique_id "al4dALEFnm79ltp0SFBBXgAAADQ"]
[Mon Jul 20 07:05:04.274297 2026] [http2:warn] [pid 29744:tid 30002] [client 57.141.18.108:64328] h2_stream(29744-1170-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:04.297228 2026] [authz_core:error] [pid 45040:tid 45283] [client 147.93.171.187:0] AH01630: client denied by server configuration: /home3/ciraorg/public_html/wp-includes/widgets/error_log, referer: binance.com
[Mon Jul 20 07:05:04.446436 2026] [security2:error] [pid 28702:tid 28857] [client 4.194.24.143:2891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/s.php"] [unique_id "al4dALF4957xPw9VVBnR6gAAAJ0"]
[Mon Jul 20 07:05:04.603264 2026] [http2:warn] [pid 28702:tid 28840] [client 57.141.18.58:39464] h2_stream(28702-801-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:04.760496 2026] [security2:error] [pid 45040:tid 45282] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dALEFnm79ltp0SFBBeQAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:04.762488 2026] [security2:error] [pid 45040:tid 45118] [remote 47.86.33.52:20354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dALEFnm79ltp0SFBBgQAAa0s"]
[Mon Jul 20 07:05:04.834682 2026] [security2:error] [pid 45040:tid 45293] [client 194.61.41.64:20869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/up/main.php"] [unique_id "al4dALEFnm79ltp0SFBBggAAAHk"]
[Mon Jul 20 07:05:05.038532 2026] [security2:error] [pid 28702:tid 28867] [client 4.194.24.143:32570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sang.php"] [unique_id "al4dAbF4957xPw9VVBnSAgAAAKc"]
[Mon Jul 20 07:05:05.152469 2026] [security2:error] [pid 45040:tid 45288] [client 14.225.17.146:51741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4dALEFnm79ltp0SFBBhQAAAHQ"], referer: http://lifeisbetterlakeside.com/2023
[Mon Jul 20 07:05:05.206474 2026] [http2:warn] [pid 29744:tid 29894] [client 57.141.18.96:31598] h2_stream(29744-1178-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:05.614834 2026] [security2:error] [pid 28702:tid 28939] [client 194.61.41.70:29875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/fonts/fontawesome-webfont.php"] [unique_id "al4dAbF4957xPw9VVBnSJAAAAO8"]
[Mon Jul 20 07:05:05.635444 2026] [security2:error] [pid 45040:tid 45209] [client 4.194.24.143:2901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/scxy.php"] [unique_id "al4dAbEFnm79ltp0SFBBqgAAACU"]
[Mon Jul 20 07:05:05.705108 2026] [security2:error] [pid 45040:tid 45206] [client 77.110.127.138:62630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dAbEFnm79ltp0SFBBnAAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:06.023487 2026] [security2:error] [pid 45040:tid 45201] [client 57.141.18.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4dAbEFnm79ltp0SFBBtwAAAB0"]
[Mon Jul 20 07:05:06.055998 2026] [security2:error] [pid 45040:tid 45184] [client 66.249.73.204:62860] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.trinacria.ca"] [uri "/robots.txt"] [unique_id "al4dArEFnm79ltp0SFBBwQAAAAw"]
[Mon Jul 20 07:05:06.177622 2026] [security2:error] [pid 45040:tid 45250] [client 4.194.24.143:24020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sd.php"] [unique_id "al4dArEFnm79ltp0SFBBygAAAE4"]
[Mon Jul 20 07:05:06.227772 2026] [http2:warn] [pid 28702:tid 28903] [client 57.141.18.90:42818] h2_stream(28702-807-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:06.328176 2026] [security2:error] [pid 45040:tid 45235] [client 194.61.41.246:49045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/wp-conflg.php"] [unique_id "al4dArEFnm79ltp0SFBB0wAAAD8"]
[Mon Jul 20 07:05:06.543100 2026] [security2:error] [pid 45040:tid 45214] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dArEFnm79ltp0SFBB1AAAACo"], referer: 1'"3000
[Mon Jul 20 07:05:06.727229 2026] [security2:error] [pid 45040:tid 45283] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dArEFnm79ltp0SFBB2wAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:06.770608 2026] [security2:error] [pid 45040:tid 45247] [client 4.194.24.143:32542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sf.php"] [unique_id "al4dArEFnm79ltp0SFBB6gAAAEs"]
[Mon Jul 20 07:05:06.831448 2026] [http2:warn] [pid 29744:tid 29957] [client 57.141.18.55:26838] h2_stream(29744-1188-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:07.047620 2026] [security2:error] [pid 28702:tid 28947] [client 194.61.41.246:43267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/includes/about.php"] [unique_id "al4dA7F4957xPw9VVBnSVQAAAPc"]
[Mon Jul 20 07:05:07.129907 2026] [security2:error] [pid 45040:tid 45209] [client 122.183.32.225:31923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dA7EFnm79ltp0SFBB9AAAACU"]
[Mon Jul 20 07:05:07.130035 2026] [security2:error] [pid 45040:tid 45209] [client 122.183.32.225:31923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dA7EFnm79ltp0SFBB9AAAACU"]
[Mon Jul 20 07:05:07.172720 2026] [security2:error] [pid 45040:tid 45201] [client 187.16.64.216:60368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dA7EFnm79ltp0SFBB9gAAAB0"]
[Mon Jul 20 07:05:07.172862 2026] [security2:error] [pid 45040:tid 45201] [client 187.16.64.216:60368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dA7EFnm79ltp0SFBB9gAAAB0"]
[Mon Jul 20 07:05:07.313325 2026] [security2:error] [pid 45040:tid 45263] [client 147.93.171.187:61673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "al4dA7EFnm79ltp0SFBCBAAAAFs"], referer: binance.com
[Mon Jul 20 07:05:07.321937 2026] [security2:error] [pid 45040:tid 45250] [client 4.194.24.143:1086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/shell.php"] [unique_id "al4dA7EFnm79ltp0SFBCBQAAAE4"]
[Mon Jul 20 07:05:07.396488 2026] [http2:warn] [pid 28702:tid 28902] [client 57.141.18.106:60548] h2_stream(28702-813-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:07.575477 2026] [http2:warn] [pid 29744:tid 29987] [client 57.141.18.51:23044] h2_stream(29744-1196-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:07.783806 2026] [security2:error] [pid 45040:tid 45293] [client 103.132.219.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4dA7EFnm79ltp0SFBCGQAAAHk"]
[Mon Jul 20 07:05:07.846635 2026] [security2:error] [pid 45040:tid 45251] [client 194.61.41.247:56703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/index.php"] [unique_id "al4dA7EFnm79ltp0SFBCLgAAAE8"]
[Mon Jul 20 07:05:07.981221 2026] [http2:warn] [pid 29744:tid 29877] [client 57.141.18.62:21638] h2_stream(29744-1202-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:08.088504 2026] [security2:error] [pid 45040:tid 45266] [client 4.194.24.143:2940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sid3.php"] [unique_id "al4dBLEFnm79ltp0SFBCOAAAAF4"]
[Mon Jul 20 07:05:08.161430 2026] [http2:warn] [pid 45040:tid 45190] [client 57.141.18.42:56414] h2_stream(45040-69-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:08.267488 2026] [security2:error] [pid 45040:tid 45292] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4dBLEFnm79ltp0SFBCPAAAeGI"], referer: http://aleishapenny.ca/2023
[Mon Jul 20 07:05:08.389277 2026] [security2:error] [pid 45040:tid 45220] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4dBLEFnm79ltp0SFBCRwAAADA"]
[Mon Jul 20 07:05:08.625172 2026] [security2:error] [pid 45040:tid 45241] [client 194.61.41.99:35325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/images/about.php"] [unique_id "al4dBLEFnm79ltp0SFBCUgAAAEU"]
[Mon Jul 20 07:05:08.681029 2026] [security2:error] [pid 45040:tid 45259] [client 4.194.24.143:24026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/simple.php"] [unique_id "al4dBLEFnm79ltp0SFBCVAAAAFc"]
[Mon Jul 20 07:05:08.691289 2026] [security2:error] [pid 45040:tid 45173] [client 158.173.89.95:42399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dBLEFnm79ltp0SFBCVwAAAAE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:05:08.725361 2026] [security2:error] [pid 28702:tid 28864] [client 170.64.167.87:55534] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.balticsteelmgmt.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4dBLF4957xPw9VVBnSlAAAAKQ"]
[Mon Jul 20 07:05:08.790544 2026] [http2:warn] [pid 29744:tid 29928] [client 57.141.18.98:22764] h2_stream(29744-1208-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:08.794349 2026] [security2:error] [pid 45040:tid 45263] [client 77.110.127.138:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dBLEFnm79ltp0SFBCWwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:08.794493 2026] [security2:error] [pid 45040:tid 45263] [client 77.110.127.138:62650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dBLEFnm79ltp0SFBCWwAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:08.936237 2026] [security2:error] [pid 28702:tid 28941] [client 50.116.65.227:53570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dBLF4957xPw9VVBnSngAAAPE"]
[Mon Jul 20 07:05:08.945272 2026] [security2:error] [pid 28702:tid 28934] [client 50.116.65.227:53582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dBLF4957xPw9VVBnSoAAAAOo"]
[Mon Jul 20 07:05:09.043348 2026] [security2:error] [pid 45040:tid 45156] [remote 100.42.189.89:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4dBbEFnm79ltp0SFBCZQAACnE"]
[Mon Jul 20 07:05:09.051604 2026] [security2:error] [pid 45040:tid 45187] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dBLEFnm79ltp0SFBCYQAAAA8"], referer: 1'"3000
[Mon Jul 20 07:05:09.105772 2026] [security2:error] [pid 28702:tid 28943] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4dBLF4957xPw9VVBnSpAAA8zY"], referer: https://aleishapenny.ca/2023
[Mon Jul 20 07:05:09.105911 2026] [security2:error] [pid 45040:tid 45287] [client 154.208.48.130:55646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dBbEFnm79ltp0SFBCaAAAAHM"]
[Mon Jul 20 07:05:09.106017 2026] [security2:error] [pid 45040:tid 45287] [client 154.208.48.130:55646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dBbEFnm79ltp0SFBCaAAAAHM"]
[Mon Jul 20 07:05:09.210851 2026] [security2:error] [pid 45040:tid 45247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dBbEFnm79ltp0SFBCZAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:09.221910 2026] [security2:error] [pid 28702:tid 28888] [client 4.194.24.143:24033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sitemap.php"] [unique_id "al4dBbF4957xPw9VVBnSqwAAALw"]
[Mon Jul 20 07:05:09.242333 2026] [security2:error] [pid 45040:tid 45148] [remote 100.42.189.89:44712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4dBbEFnm79ltp0SFBCcAAAVmk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:05:09.327649 2026] [security2:error] [pid 45040:tid 45254] [client 14.225.17.146:65315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4dA7EFnm79ltp0SFBB_gAAAFI"], referer: http://jvcmotorsports.com/2023
[Mon Jul 20 07:05:09.329677 2026] [http2:warn] [pid 28702:tid 28884] [client 57.141.18.31:50810] h2_stream(28702-816-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:09.335931 2026] [security2:error] [pid 45040:tid 45192] [client 194.61.41.63:31335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/class.php"] [unique_id "al4dBbEFnm79ltp0SFBCeQAAABQ"]
[Mon Jul 20 07:05:09.431572 2026] [security2:error] [pid 28702:tid 28868] [client 14.225.17.146:51041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4dBbF4957xPw9VVBnSsgAAAKg"], referer: http://colinkeyphotography.com/2023
[Mon Jul 20 07:05:09.491177 2026] [security2:error] [pid 28702:tid 28953] [client 14.225.17.146:61998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4dA7F4957xPw9VVBnSVgAAAP0"], referer: http://drewsasburyparkbeachhouse.com/2023
[Mon Jul 20 07:05:09.554528 2026] [security2:error] [pid 28702:tid 28942] [client 201.27.111.74:50205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dBbF4957xPw9VVBnSugAAAPI"]
[Mon Jul 20 07:05:09.554648 2026] [security2:error] [pid 28702:tid 28942] [client 201.27.111.74:50205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dBbF4957xPw9VVBnSugAAAPI"]
[Mon Jul 20 07:05:09.660119 2026] [security2:error] [pid 28702:tid 28923] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4dBbF4957xPw9VVBnSuwAA3wk"], referer: http://ali-alghanim.net/2023
[Mon Jul 20 07:05:09.670353 2026] [http2:warn] [pid 29744:tid 29890] [client 57.141.18.23:60932] h2_stream(29744-1215-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:09.768724 2026] [security2:error] [pid 45040:tid 45259] [client 4.194.24.143:24051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/size.php"] [unique_id "al4dBbEFnm79ltp0SFBCjwAAAFc"]
[Mon Jul 20 07:05:09.866496 2026] [security2:error] [pid 45040:tid 45244] [client 66.249.74.35:48555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bruceledewitz.com"] [uri "/index.php"] [unique_id "al4dBbEFnm79ltp0SFBCdAAAAEg"]
[Mon Jul 20 07:05:10.026695 2026] [http2:warn] [pid 29744:tid 29983] [client 57.141.18.106:60560] h2_stream(29744-1217-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:10.122453 2026] [security2:error] [pid 45040:tid 45187] [client 77.110.127.138:62656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dBbEFnm79ltp0SFBClAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:10.140559 2026] [security2:error] [pid 28702:tid 28838] [client 194.61.41.104:54173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/autoload_classmap.php"] [unique_id "al4dBrF4957xPw9VVBnS2gAAAIo"]
[Mon Jul 20 07:05:10.216531 2026] [security2:error] [pid 28702:tid 28866] [client 23.251.146.115:4560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4dBrF4957xPw9VVBnS1QAApkM"]
[Mon Jul 20 07:05:10.331993 2026] [security2:error] [pid 28702:tid 28931] [client 23.251.146.115:4560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4dBrF4957xPw9VVBnS3QAA5zw"]
[Mon Jul 20 07:05:10.343464 2026] [security2:error] [pid 28702:tid 28889] [client 4.194.24.143:1055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sm.php"] [unique_id "al4dBrF4957xPw9VVBnS5AAAAL0"]
[Mon Jul 20 07:05:10.433800 2026] [security2:error] [pid 28702:tid 28836] [client 34.31.203.120:48640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4dBrF4957xPw9VVBnS5QAAiDA"]
[Mon Jul 20 07:05:10.543421 2026] [security2:error] [pid 28702:tid 28857] [client 34.31.203.120:48640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4dBrF4957xPw9VVBnS7gAAnSQ"]
[Mon Jul 20 07:05:10.588451 2026] [security2:error] [pid 28702:tid 28912] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4dBrF4957xPw9VVBnS8wAAANQ"]
[Mon Jul 20 07:05:10.792858 2026] [security2:error] [pid 45040:tid 45277] [client 34.31.203.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4dBrEFnm79ltp0SFBCvgAAAGk"]
[Mon Jul 20 07:05:10.886599 2026] [security2:error] [pid 28702:tid 28859] [client 4.194.24.143:2927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sql.php"] [unique_id "al4dBrF4957xPw9VVBnTCAAAAJ8"]
[Mon Jul 20 07:05:10.968966 2026] [security2:error] [pid 45040:tid 45247] [client 194.61.41.245:45001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/web.php"] [unique_id "al4dBrEFnm79ltp0SFBC1gAAAEs"]
[Mon Jul 20 07:05:11.125530 2026] [security2:error] [pid 28702:tid 28778] [remote 57.141.18.82:64926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cT7F4957xPw9VVBm2AwABAEo"]
[Mon Jul 20 07:05:11.207858 2026] [security2:error] [pid 45040:tid 45178] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dBrEFnm79ltp0SFBC3QAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:11.261863 2026] [http2:warn] [pid 29744:tid 29979] [client 57.141.18.51:23060] h2_stream(29744-1232-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:11.351693 2026] [security2:error] [pid 45040:tid 45220] [client 14.225.17.146:54299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4dB7EFnm79ltp0SFBDEQAAADA"], referer: http://travelbyfire.com/2023
[Mon Jul 20 07:05:11.486497 2026] [security2:error] [pid 45040:tid 45234] [client 4.194.24.143:24019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/ss.php"] [unique_id "al4dB7EFnm79ltp0SFBDLAAAAD4"]
[Mon Jul 20 07:05:11.723818 2026] [security2:error] [pid 28702:tid 28842] [client 194.61.41.66:41947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/ocean/about.php"] [unique_id "al4dB7F4957xPw9VVBnTHwAAAI4"]
[Mon Jul 20 07:05:11.736446 2026] [security2:error] [pid 45040:tid 45291] [client 104.234.53.92:44847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dB7EFnm79ltp0SFBDMAAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:12.038682 2026] [security2:error] [pid 28702:tid 28846] [client 4.194.24.143:6933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/stats.php"] [unique_id "al4dCLF4957xPw9VVBnTKAAAAJI"]
[Mon Jul 20 07:05:12.090333 2026] [security2:error] [pid 45040:tid 45219] [client 14.225.17.146:51084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4dB7EFnm79ltp0SFBC5AAAAC8"], referer: http://intelligentengineeringsolutions.com/2023
[Mon Jul 20 07:05:12.203939 2026] [security2:error] [pid 28702:tid 28918] [client 14.225.17.146:51633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4dCLF4957xPw9VVBnTJwAAANo"], referer: http://samdothan.org/2023
[Mon Jul 20 07:05:12.248247 2026] [security2:error] [pid 45040:tid 45194] [client 103.144.65.217:50949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dCLEFnm79ltp0SFBDTwAAABY"]
[Mon Jul 20 07:05:12.248374 2026] [security2:error] [pid 45040:tid 45194] [client 103.144.65.217:50949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dCLEFnm79ltp0SFBDTwAAABY"]
[Mon Jul 20 07:05:12.255762 2026] [security2:error] [pid 28702:tid 28960] [client 14.225.17.146:50996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4dCLF4957xPw9VVBnTMAAAAQQ"], referer: https://travelbyfire.com/2023
[Mon Jul 20 07:05:12.456313 2026] [security2:error] [pid 45040:tid 45270] [client 194.61.41.80:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/index.php"] [unique_id "al4dCLEFnm79ltp0SFBDUgAAAGI"]
[Mon Jul 20 07:05:12.470433 2026] [http2:warn] [pid 29744:tid 29977] [client 57.141.18.95:34068] h2_stream(29744-1244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:12.578558 2026] [security2:error] [pid 45040:tid 45233] [client 4.194.24.143:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/sump1.php"] [unique_id "al4dCLEFnm79ltp0SFBDWQAAAD0"]
[Mon Jul 20 07:05:12.632471 2026] [security2:error] [pid 45040:tid 45228] [client 14.225.17.146:51623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4dBrEFnm79ltp0SFBC2AAAADg"], referer: http://aandarealtygroup.com/2023
[Mon Jul 20 07:05:12.739308 2026] [http2:warn] [pid 45040:tid 45239] [client 57.141.18.41:21414] h2_stream(45040-101-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:13.120988 2026] [security2:error] [pid 45040:tid 45250] [client 4.194.24.143:2904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/system.php"] [unique_id "al4dCbEFnm79ltp0SFBDbwAAAE4"]
[Mon Jul 20 07:05:13.156487 2026] [security2:error] [pid 45040:tid 45296] [client 77.110.127.138:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dCbEFnm79ltp0SFBDcQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:13.156564 2026] [security2:error] [pid 45040:tid 45296] [client 77.110.127.138:62670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dCbEFnm79ltp0SFBDcQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:13.227557 2026] [security2:error] [pid 45040:tid 45273] [client 194.61.41.96:50321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/bypass.php"] [unique_id "al4dCbEFnm79ltp0SFBDcgAAAGU"]
[Mon Jul 20 07:05:13.412794 2026] [security2:error] [pid 28702:tid 28865] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dCbF4957xPw9VVBnTYQAAAKU"], referer: 1'"3000
[Mon Jul 20 07:05:13.599412 2026] [security2:error] [pid 45040:tid 45207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dCbEFnm79ltp0SFBDdwAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:13.616059 2026] [security2:error] [pid 45040:tid 45243] [client 192.140.149.97:44585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dCbEFnm79ltp0SFBDgAAAAEc"]
[Mon Jul 20 07:05:13.616180 2026] [security2:error] [pid 45040:tid 45243] [client 192.140.149.97:44585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dCbEFnm79ltp0SFBDgAAAAEc"]
[Mon Jul 20 07:05:13.696688 2026] [security2:error] [pid 45040:tid 45266] [client 4.194.24.143:24005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4dCbEFnm79ltp0SFBDhAAAAF4"]
[Mon Jul 20 07:05:13.727200 2026] [security2:error] [pid 45040:tid 45282] [client 117.247.108.24:50425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dCbEFnm79ltp0SFBDhwAAAG4"]
[Mon Jul 20 07:05:13.727292 2026] [security2:error] [pid 45040:tid 45282] [client 117.247.108.24:50425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dCbEFnm79ltp0SFBDhwAAAG4"]
[Mon Jul 20 07:05:13.802686 2026] [security2:error] [pid 45040:tid 45189] [client 74.7.227.179:55282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4dCbEFnm79ltp0SFBDgQAAEVY"], referer: https://tejasenvironmental.com/p=896843
[Mon Jul 20 07:05:13.972894 2026] [security2:error] [pid 45040:tid 45175] [client 194.61.41.105:23933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/gecko-litespeed.php"] [unique_id "al4dCbEFnm79ltp0SFBDigAAAAM"]
[Mon Jul 20 07:05:13.982958 2026] [security2:error] [pid 45040:tid 45285] [client 183.82.98.154:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dCbEFnm79ltp0SFBDjQAAAHE"]
[Mon Jul 20 07:05:13.983071 2026] [security2:error] [pid 45040:tid 45285] [client 183.82.98.154:61670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dCbEFnm79ltp0SFBDjQAAAHE"]
[Mon Jul 20 07:05:14.238919 2026] [security2:error] [pid 45040:tid 45272] [client 4.194.24.143:2942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4dCrEFnm79ltp0SFBDlwAAAGQ"]
[Mon Jul 20 07:05:14.270119 2026] [security2:error] [pid 28702:tid 28881] [client 14.225.17.146:54249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4dCrF4957xPw9VVBnTiwAAALU"], referer: http://xp-design.co/2023
[Mon Jul 20 07:05:14.410604 2026] [security2:error] [pid 28702:tid 28871] [client 14.225.17.146:59658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4dCrF4957xPw9VVBnTjwAAAKs"]
[Mon Jul 20 07:05:14.556238 2026] [security2:error] [pid 28702:tid 28846] [client 213.152.161.101:33642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dCrF4957xPw9VVBnToQAAAJI"]
[Mon Jul 20 07:05:14.556350 2026] [security2:error] [pid 28702:tid 28846] [client 213.152.161.101:33642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dCrF4957xPw9VVBnToQAAAJI"]
[Mon Jul 20 07:05:14.700937 2026] [security2:error] [pid 28702:tid 28906] [client 216.244.66.243:59240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/next"] [unique_id "al4dCrF4957xPw9VVBnTqwAAAM4"]
[Mon Jul 20 07:05:14.701092 2026] [security2:error] [pid 28702:tid 28906] [client 216.244.66.243:59240] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/apps/blog/show/next"] [unique_id "al4dCrF4957xPw9VVBnTqwAAAM4"]
[Mon Jul 20 07:05:14.713010 2026] [security2:error] [pid 28702:tid 28835] [client 14.225.17.146:51465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4dCrF4957xPw9VVBnTngAAAIc"], referer: http://taskidsvirginia.com/2023
[Mon Jul 20 07:05:14.741425 2026] [security2:error] [pid 28702:tid 28956] [client 194.61.41.84:36611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/midnight/install.php"] [unique_id "al4dCrF4957xPw9VVBnTrAAAAQA"]
[Mon Jul 20 07:05:14.780235 2026] [security2:error] [pid 45040:tid 45220] [client 4.194.24.143:1045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/system_log.php"] [unique_id "al4dCrEFnm79ltp0SFBDrgAAADA"]
[Mon Jul 20 07:05:15.071125 2026] [security2:error] [pid 28702:tid 28941] [client 104.234.53.77:46653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4dCrF4957xPw9VVBnTsgAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:15.327973 2026] [security2:error] [pid 28702:tid 28866] [client 4.194.24.143:15911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/t.php"] [unique_id "al4dC7F4957xPw9VVBnTvgAAAKY"]
[Mon Jul 20 07:05:15.386118 2026] [security2:error] [pid 28702:tid 28859] [client 104.234.53.77:46653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dC7F4957xPw9VVBnTvwAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:15.539341 2026] [http2:warn] [pid 29744:tid 29902] [client 57.141.18.78:48342] h2_stream(29744-1271-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:15.554350 2026] [security2:error] [pid 45040:tid 45286] [client 194.61.41.242:40973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-trackback.php"] [unique_id "al4dC7EFnm79ltp0SFBD1AAAAHI"]
[Mon Jul 20 07:05:15.602109 2026] [security2:error] [pid 45040:tid 45232] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dC7EFnm79ltp0SFBDzwAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:15.813498 2026] [security2:error] [pid 45040:tid 45225] [client 14.225.17.146:59874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4dC7EFnm79ltp0SFBDyQAAADU"]
[Mon Jul 20 07:05:15.880129 2026] [security2:error] [pid 28702:tid 28882] [client 4.194.24.143:24044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/term.php"] [unique_id "al4dC7F4957xPw9VVBnT1gAAALY"]
[Mon Jul 20 07:05:15.893500 2026] [security2:error] [pid 28702:tid 28948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dC7F4957xPw9VVBnTzAAAAPg"], referer: 1'"3000
[Mon Jul 20 07:05:16.324391 2026] [security2:error] [pid 28702:tid 28856] [client 194.61.41.253:34365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/bypass.php"] [unique_id "al4dDLF4957xPw9VVBnT6QAAAJw"]
[Mon Jul 20 07:05:16.419564 2026] [security2:error] [pid 28702:tid 28872] [client 4.194.24.143:1032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/test.php"] [unique_id "al4dDLF4957xPw9VVBnT7wAAAKw"]
[Mon Jul 20 07:05:16.657894 2026] [security2:error] [pid 28702:tid 28728] [remote 100.42.189.89:44796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dDLF4957xPw9VVBnT-gAA1Bg"]
[Mon Jul 20 07:05:16.786825 2026] [security2:error] [pid 28702:tid 28918] [client 147.93.171.187:60273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "al4dDLF4957xPw9VVBnT_wAAANo"], referer: binance.com
[Mon Jul 20 07:05:16.861388 2026] [security2:error] [pid 28702:tid 28709] [remote 100.42.189.89:44796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dDLF4957xPw9VVBnUAgAA4gU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:05:16.959054 2026] [security2:error] [pid 45040:tid 45282] [client 4.194.24.143:32518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/test1.php"] [unique_id "al4dDLEFnm79ltp0SFBEAQAAAG4"]
[Mon Jul 20 07:05:17.032813 2026] [security2:error] [pid 45040:tid 45251] [client 194.61.41.60:52333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/radio.php"] [unique_id "al4dDbEFnm79ltp0SFBEBAAAAE8"]
[Mon Jul 20 07:05:17.196173 2026] [security2:error] [pid 45040:tid 45156] [remote 38.242.157.30:33956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dDbEFnm79ltp0SFBECQAAS3E"]
[Mon Jul 20 07:05:17.196388 2026] [security2:error] [pid 45040:tid 45247] [client 38.242.157.30:33956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dDbEFnm79ltp0SFBECQAAS3E"]
[Mon Jul 20 07:05:17.309223 2026] [proxy:error] [pid 28702:tid 28846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:05:17.309297 2026] [proxy_http:error] [pid 28702:tid 28846] [client 3.254.125.138:44612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:05:17.310040 2026] [proxy:error] [pid 28702:tid 28846] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:05:17.310072 2026] [proxy_http:error] [pid 28702:tid 28846] [client 3.254.125.138:44612] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:05:17.500094 2026] [security2:error] [pid 28702:tid 28950] [client 4.194.24.143:24025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/tfm.php"] [unique_id "al4dDbF4957xPw9VVBnUJQAAAPo"]
[Mon Jul 20 07:05:17.532182 2026] [security2:error] [pid 28702:tid 28865] [client 14.225.17.146:59831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4dDbF4957xPw9VVBnUIgAAAKU"], referer: http://mtlegnews.gov/2023
[Mon Jul 20 07:05:17.572943 2026] [security2:error] [pid 28702:tid 28935] [client 77.110.127.138:62697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dDbF4957xPw9VVBnUKQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:17.573060 2026] [security2:error] [pid 28702:tid 28935] [client 77.110.127.138:62697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dDbF4957xPw9VVBnUKQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:17.593251 2026] [security2:error] [pid 28702:tid 28955] [client 14.225.17.146:60070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4dDbF4957xPw9VVBnUIAAAAP8"], referer: http://idigress.agency/2023
[Mon Jul 20 07:05:17.605040 2026] [security2:error] [pid 28702:tid 28877] [client 47.128.49.250:18216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "joaoceitil.com"] [uri "/robots.txt"] [unique_id "al4dDbF4957xPw9VVBnULgAAALE"]
[Mon Jul 20 07:05:17.739269 2026] [http2:warn] [pid 45040:tid 45191] [client 57.141.18.103:34046] h2_stream(45040-136-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:17.743546 2026] [security2:error] [pid 45040:tid 45263] [client 194.61.41.88:55671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/mah.php"] [unique_id "al4dDbEFnm79ltp0SFBEHAAAAFs"]
[Mon Jul 20 07:05:17.843938 2026] [security2:error] [pid 28702:tid 28912] [client 187.16.64.216:60942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dDbF4957xPw9VVBnUOgAAANQ"]
[Mon Jul 20 07:05:17.844216 2026] [security2:error] [pid 28702:tid 28912] [client 187.16.64.216:60942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dDbF4957xPw9VVBnUOgAAANQ"]
[Mon Jul 20 07:05:17.866912 2026] [security2:error] [pid 45040:tid 45145] [remote 47.86.33.52:42742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dDbEFnm79ltp0SFBEIwAAemY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:05:17.954690 2026] [security2:error] [pid 45040:tid 45179] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dDbEFnm79ltp0SFBEHQAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:18.042499 2026] [security2:error] [pid 45040:tid 45289] [client 4.194.24.143:24058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/thebe.php"] [unique_id "al4dDrEFnm79ltp0SFBEKwAAAHU"]
[Mon Jul 20 07:05:18.059843 2026] [security2:error] [pid 45040:tid 45186] [client 201.27.111.74:50661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dDrEFnm79ltp0SFBELwAAAA4"]
[Mon Jul 20 07:05:18.063069 2026] [security2:error] [pid 45040:tid 45186] [client 201.27.111.74:50661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dDrEFnm79ltp0SFBELwAAAA4"]
[Mon Jul 20 07:05:18.450743 2026] [security2:error] [pid 45040:tid 45219] [client 122.183.32.225:24606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dDrEFnm79ltp0SFBEPQAAAC8"]
[Mon Jul 20 07:05:18.450965 2026] [security2:error] [pid 45040:tid 45219] [client 122.183.32.225:24606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dDrEFnm79ltp0SFBEPQAAAC8"]
[Mon Jul 20 07:05:18.455543 2026] [security2:error] [pid 29744:tid 29843] [remote 57.141.18.101:49450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cUeGINCUUz5GA9YIv7QACFWE"]
[Mon Jul 20 07:05:18.526533 2026] [security2:error] [pid 45040:tid 45222] [client 194.61.41.100:58909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/dummyyummy/wp-signup.php"] [unique_id "al4dDrEFnm79ltp0SFBEQwAAADI"]
[Mon Jul 20 07:05:18.585314 2026] [security2:error] [pid 45040:tid 45235] [client 4.194.24.143:6942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/themes.php"] [unique_id "al4dDrEFnm79ltp0SFBESQAAAD8"]
[Mon Jul 20 07:05:19.092500 2026] [security2:error] [pid 45040:tid 45225] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dDrEFnm79ltp0SFBEWAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:19.146017 2026] [security2:error] [pid 45040:tid 45299] [client 4.194.24.143:1161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/tiny.php"] [unique_id "al4dD7EFnm79ltp0SFBEXQAAAH8"]
[Mon Jul 20 07:05:19.192911 2026] [security2:error] [pid 28702:tid 28904] [client 65.111.22.225:34913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dD7F4957xPw9VVBnUcwAAAMw"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:19.264023 2026] [http2:warn] [pid 29744:tid 29892] [client 57.141.18.62:32300] h2_stream(29744-1299-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:19.282660 2026] [security2:error] [pid 45040:tid 45248] [client 194.61.41.54:56059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/midnight/wp-login.php"] [unique_id "al4dD7EFnm79ltp0SFBEYQAAAEw"]
[Mon Jul 20 07:05:19.317536 2026] [security2:error] [pid 45040:tid 45154] [remote 72.167.132.114:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dD7EFnm79ltp0SFBEZgAAYG8"]
[Mon Jul 20 07:05:19.553968 2026] [security2:error] [pid 45040:tid 45158] [remote 72.167.132.114:40164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dD7EFnm79ltp0SFBEagAAK3M"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:05:19.696297 2026] [security2:error] [pid 28702:tid 28926] [client 4.194.24.143:2892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/tmp/byp.php"] [unique_id "al4dD7F4957xPw9VVBnUhQAAAOI"]
[Mon Jul 20 07:05:20.049396 2026] [security2:error] [pid 45040:tid 45261] [client 194.61.41.87:37295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-conflg.php"] [unique_id "al4dELEFnm79ltp0SFBEhgAAAFk"]
[Mon Jul 20 07:05:20.207332 2026] [security2:error] [pid 45040:tid 45279] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dD7EFnm79ltp0SFBEgwAAAGs"], referer: 1'"3000
[Mon Jul 20 07:05:20.326484 2026] [security2:error] [pid 28702:tid 28889] [client 104.234.53.73:33869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dELF4957xPw9VVBnUkAAAAL0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:20.570011 2026] [security2:error] [pid 28702:tid 28870] [client 50.116.65.227:10002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dELF4957xPw9VVBnUmAAAAKo"]
[Mon Jul 20 07:05:20.580601 2026] [security2:error] [pid 28702:tid 28857] [client 50.116.65.227:10014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dELF4957xPw9VVBnUmQAAAJ0"]
[Mon Jul 20 07:05:20.838832 2026] [security2:error] [pid 45040:tid 45273] [client 14.225.17.146:58761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4dD7EFnm79ltp0SFBEbAAAAGU"], referer: http://wathenbartlett.co.uk/2023
[Mon Jul 20 07:05:20.845036 2026] [security2:error] [pid 45040:tid 45245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dELEFnm79ltp0SFBErwAAAEk"], referer: 1'"3000
[Mon Jul 20 07:05:20.858772 2026] [security2:error] [pid 45040:tid 45283] [client 154.208.48.130:56153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dELEFnm79ltp0SFBEvwAAAG8"]
[Mon Jul 20 07:05:20.858910 2026] [security2:error] [pid 45040:tid 45283] [client 154.208.48.130:56153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dELEFnm79ltp0SFBEvwAAAG8"]
[Mon Jul 20 07:05:20.859657 2026] [security2:error] [pid 45040:tid 45224] [client 194.61.41.101:22331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-setup.php"] [unique_id "al4dELEFnm79ltp0SFBEwAAAADQ"]
[Mon Jul 20 07:05:21.342343 2026] [security2:error] [pid 45040:tid 45115] [remote 192.241.143.148:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4dEbEFnm79ltp0SFBE2wAAe0g"]
[Mon Jul 20 07:05:21.473651 2026] [security2:error] [pid 45040:tid 45279] [client 50.116.65.227:10050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dEbEFnm79ltp0SFBE5AAAAGs"]
[Mon Jul 20 07:05:21.483945 2026] [security2:error] [pid 45040:tid 45250] [client 50.116.65.227:10064] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dEbEFnm79ltp0SFBE5gAAAE4"]
[Mon Jul 20 07:05:21.514911 2026] [security2:error] [pid 45040:tid 45155] [remote 192.241.143.148:52190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4dEbEFnm79ltp0SFBE6wAATHA"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 07:05:21.527451 2026] [security2:error] [pid 45040:tid 45297] [client 77.110.127.138:62729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dEbEFnm79ltp0SFBE7QAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:21.527632 2026] [security2:error] [pid 45040:tid 45297] [client 77.110.127.138:62729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dEbEFnm79ltp0SFBE7QAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:21.639585 2026] [security2:error] [pid 45040:tid 45227] [client 194.61.41.71:21479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ms-themes.php"] [unique_id "al4dEbEFnm79ltp0SFBE8wAAADc"]
[Mon Jul 20 07:05:21.808180 2026] [security2:error] [pid 45040:tid 45243] [client 14.225.17.146:59069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4dEbEFnm79ltp0SFBE-QAAAEc"], referer: https://wathenbartlett.co.uk/2023
[Mon Jul 20 07:05:21.940871 2026] [security2:error] [pid 28702:tid 28958] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dEbF4957xPw9VVBnUtgAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:22.178011 2026] [security2:error] [pid 45040:tid 45292] [client 143.244.57.90:55234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4dErEFnm79ltp0SFBFEQAAAHg"]
[Mon Jul 20 07:05:22.273887 2026] [security2:error] [pid 45040:tid 45082] [remote 64.225.121.94:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dErEFnm79ltp0SFBFFAAAYCc"]
[Mon Jul 20 07:05:22.432108 2026] [security2:error] [pid 45040:tid 45294] [client 194.61.41.58:21429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/about.php"] [unique_id "al4dErEFnm79ltp0SFBFHQAAAHo"]
[Mon Jul 20 07:05:22.450918 2026] [http2:warn] [pid 28702:tid 28880] [client 57.141.18.57:25736] h2_stream(28702-1070-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:22.464967 2026] [security2:error] [pid 45040:tid 45262] [client 13.215.47.127:27566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dErEFnm79ltp0SFBFIAAAAFo"]
[Mon Jul 20 07:05:22.475011 2026] [security2:error] [pid 45040:tid 45107] [remote 64.225.121.94:44766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dErEFnm79ltp0SFBFJAAADUA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:05:22.779646 2026] [security2:error] [pid 45040:tid 45233] [client 143.244.57.90:36004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.garyjonathanmaddox.com"] [uri "/xmlrpc.php"] [unique_id "al4dErEFnm79ltp0SFBFPAAAAD0"]
[Mon Jul 20 07:05:22.802086 2026] [security2:error] [pid 28702:tid 28913] [client 103.144.65.217:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dErF4957xPw9VVBnUxwAAANU"]
[Mon Jul 20 07:05:22.802211 2026] [security2:error] [pid 28702:tid 28913] [client 103.144.65.217:51407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dErF4957xPw9VVBnUxwAAANU"]
[Mon Jul 20 07:05:22.887970 2026] [security2:error] [pid 45040:tid 45178] [client 14.225.17.146:58462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4dErEFnm79ltp0SFBFPQAAAAY"], referer: http://iagdevelopments.com/2023
[Mon Jul 20 07:05:23.000084 2026] [security2:error] [pid 45040:tid 45215] [client 14.225.17.146:60076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4dErEFnm79ltp0SFBFHgAAACs"], referer: http://effingweirdmuseums.com/2023
[Mon Jul 20 07:05:23.008719 2026] [security2:error] [pid 28702:tid 28931] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dErF4957xPw9VVBnUyAAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:23.193378 2026] [core:error] [pid 28702:tid 28909] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:23.193403 2026] [core:error] [pid 28702:tid 28909] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:23.244481 2026] [security2:error] [pid 28702:tid 28900] [client 194.61.41.99:45873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/style.php"] [unique_id "al4dE7F4957xPw9VVBnU2wAAAMg"]
[Mon Jul 20 07:05:23.328491 2026] [core:error] [pid 28702:tid 28845] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:23.328515 2026] [core:error] [pid 28702:tid 28845] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:23.331846 2026] [core:error] [pid 28702:tid 28947] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:23.331867 2026] [core:error] [pid 28702:tid 28947] [client 142.248.80.30:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:23.377046 2026] [security2:error] [pid 28702:tid 28928] [client 143.244.57.90:36010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4dE7F4957xPw9VVBnU5AAAAOQ"]
[Mon Jul 20 07:05:23.709480 2026] [security2:error] [pid 45040:tid 45288] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dE7EFnm79ltp0SFBFYQAAAHQ"], referer: 1'"3000
[Mon Jul 20 07:05:23.760063 2026] [security2:error] [pid 45040:tid 45201] [client 54.169.146.187:23820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dE7EFnm79ltp0SFBFbwAAAB0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:05:23.833395 2026] [security2:error] [pid 28702:tid 28920] [client 14.225.17.146:58814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4dE7F4957xPw9VVBnU7QAAANw"], referer: https://iagdevelopments.com/2023
[Mon Jul 20 07:05:23.896711 2026] [security2:error] [pid 28702:tid 28960] [client 14.225.17.146:58474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4dE7F4957xPw9VVBnU7gAAAQQ"], referer: https://effingweirdmuseums.com/2023
[Mon Jul 20 07:05:23.951102 2026] [security2:error] [pid 45040:tid 45229] [client 5.161.113.195:59066] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4dE7EFnm79ltp0SFBFgAAAADk"], referer: https://windowtx.com
[Mon Jul 20 07:05:23.986245 2026] [security2:error] [pid 45040:tid 45208] [client 143.244.57.90:36012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4dE7EFnm79ltp0SFBFhQAAACQ"]
[Mon Jul 20 07:05:24.042783 2026] [security2:error] [pid 45040:tid 45253] [client 194.61.41.76:50021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/infi.php"] [unique_id "al4dFLEFnm79ltp0SFBFiwAAAFE"]
[Mon Jul 20 07:05:24.511396 2026] [security2:error] [pid 45040:tid 45294] [client 117.247.108.24:51015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dFLEFnm79ltp0SFBFqAAAAHo"]
[Mon Jul 20 07:05:24.511528 2026] [security2:error] [pid 45040:tid 45294] [client 117.247.108.24:51015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dFLEFnm79ltp0SFBFqAAAAHo"]
[Mon Jul 20 07:05:24.534813 2026] [security2:error] [pid 28702:tid 28941] [client 183.82.98.154:62219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dFLF4957xPw9VVBnU-gAAAPE"]
[Mon Jul 20 07:05:24.534931 2026] [security2:error] [pid 28702:tid 28941] [client 183.82.98.154:62219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dFLF4957xPw9VVBnU-gAAAPE"]
[Mon Jul 20 07:05:24.595492 2026] [security2:error] [pid 45040:tid 45177] [client 143.244.57.90:36026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4dFLEFnm79ltp0SFBFqgAAAAU"]
[Mon Jul 20 07:05:24.629189 2026] [security2:error] [pid 45040:tid 45269] [client 14.225.17.146:57714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4dFLEFnm79ltp0SFBFpgAAAGE"], referer: http://slutilities.com/2023
[Mon Jul 20 07:05:24.683980 2026] [security2:error] [pid 45040:tid 45070] [remote 4.205.168.44:35636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4dFLEFnm79ltp0SFBFswAAdxs"]
[Mon Jul 20 07:05:24.741739 2026] [security2:error] [pid 28702:tid 28842] [client 74.208.214.194:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dFLF4957xPw9VVBnVBQAAAI4"]
[Mon Jul 20 07:05:24.790921 2026] [security2:error] [pid 45040:tid 45044] [remote 57.141.18.14:30026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5872995"] [unique_id "al4dFLEFnm79ltp0SFBFwAAAKgM"]
[Mon Jul 20 07:05:24.794874 2026] [security2:error] [pid 45040:tid 45154] [remote 216.73.216.55:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4dFLEFnm79ltp0SFBFwwAAIm8"]
[Mon Jul 20 07:05:24.828331 2026] [security2:error] [pid 45040:tid 45207] [client 194.61.41.106:41335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/index.php"] [unique_id "al4dFLEFnm79ltp0SFBFyAAAACM"]
[Mon Jul 20 07:05:24.879482 2026] [security2:error] [pid 45040:tid 45158] [remote 4.205.168.44:35636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4dFLEFnm79ltp0SFBFzgAANXM"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:05:25.002951 2026] [security2:error] [pid 45040:tid 45287] [client 14.225.17.146:57759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4dFLEFnm79ltp0SFBF0QAAAHM"], referer: http://collectingrealestate.com/2023
[Mon Jul 20 07:05:25.104635 2026] [security2:error] [pid 28702:tid 28923] [client 13.221.132.12:35718] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/carne-guisada-recipe-puerto-rican-beef-stew"] [unique_id "al4dFbF4957xPw9VVBnVFwAAAN8"]
[Mon Jul 20 07:05:25.197135 2026] [security2:error] [pid 28702:tid 28868] [client 143.244.57.90:36040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4dFbF4957xPw9VVBnVHAAAAKg"]
[Mon Jul 20 07:05:25.309575 2026] [http2:warn] [pid 28702:tid 28839] [client 57.141.18.116:31842] h2_stream(28702-863-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:25.355317 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dFLEFnm79ltp0SFBFzwAAADE"], referer: 1'"3000
[Mon Jul 20 07:05:25.375009 2026] [security2:error] [pid 45040:tid 45081] [remote 100.42.189.89:44900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4dFbEFnm79ltp0SFBF7wAAVyY"]
[Mon Jul 20 07:05:25.540082 2026] [security2:error] [pid 28702:tid 28920] [client 14.225.17.146:61808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4dFbF4957xPw9VVBnVHgAAANw"], referer: http://vinovinhowine.com/2023
[Mon Jul 20 07:05:25.550213 2026] [security2:error] [pid 45040:tid 45262] [client 194.61.41.66:53733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/x.php"] [unique_id "al4dFbEFnm79ltp0SFBF-AAAAFo"]
[Mon Jul 20 07:05:25.577344 2026] [security2:error] [pid 45040:tid 45074] [remote 100.42.189.89:44900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "daseighty.net"] [uri "/wp-login.php"] [unique_id "al4dFbEFnm79ltp0SFBF-gAADR8"], referer: https://daseighty.net/wp-login.php
[Mon Jul 20 07:05:25.796249 2026] [security2:error] [pid 45040:tid 45199] [client 143.244.57.90:36054] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4dFbEFnm79ltp0SFBGFAAAABs"]
[Mon Jul 20 07:05:25.991168 2026] [security2:error] [pid 45040:tid 45214] [client 98.92.1.119:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBF8gAAACo"]
[Mon Jul 20 07:05:25.994380 2026] [security2:error] [pid 45040:tid 45284] [client 98.92.1.119:65302] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/carne-guisada-recipe-puerto-rican-beef-stew"] [unique_id "al4dFbEFnm79ltp0SFBF7QAAAHA"]
[Mon Jul 20 07:05:26.029534 2026] [security2:error] [pid 45040:tid 45266] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBGHgAAAF4"]
[Mon Jul 20 07:05:26.109495 2026] [security2:error] [pid 45040:tid 45205] [client 14.225.17.146:58639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBGIgAAACE"], referer: http://adirondackengineering.com/2023
[Mon Jul 20 07:05:26.133817 2026] [security2:error] [pid 45040:tid 45226] [client 77.110.127.138:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dFrEFnm79ltp0SFBGPwAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:26.133921 2026] [security2:error] [pid 45040:tid 45226] [client 77.110.127.138:62774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dFrEFnm79ltp0SFBGPwAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:26.328534 2026] [security2:error] [pid 45040:tid 45278] [client 74.235.9.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4dFrEFnm79ltp0SFBGRgAAAGo"]
[Mon Jul 20 07:05:26.332229 2026] [security2:error] [pid 45040:tid 45219] [client 194.61.41.248:63095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/index.php"] [unique_id "al4dFrEFnm79ltp0SFBGTgAAAC8"]
[Mon Jul 20 07:05:26.385324 2026] [security2:error] [pid 45040:tid 45295] [client 143.244.57.90:36060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4dFrEFnm79ltp0SFBGVAAAAHs"]
[Mon Jul 20 07:05:26.407924 2026] [security2:error] [pid 45040:tid 45229] [client 14.225.17.146:58729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBF4gAAADk"]
[Mon Jul 20 07:05:26.430591 2026] [security2:error] [pid 28702:tid 28835] [client 104.234.53.79:51179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dFrF4957xPw9VVBnVLAAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:26.483660 2026] [security2:error] [pid 45040:tid 45187] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4dFrEFnm79ltp0SFBGVQAAAA8"]
[Mon Jul 20 07:05:26.569246 2026] [security2:error] [pid 28702:tid 28934] [client 43.173.179.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dFbF4957xPw9VVBnVGAAAAOo"]
[Mon Jul 20 07:05:26.569246 2026] [security2:error] [pid 45040:tid 45236] [client 43.172.196.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBGGAAAAEA"]
[Mon Jul 20 07:05:26.577297 2026] [security2:error] [pid 45040:tid 45201] [client 43.173.176.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBF2wAAAB0"]
[Mon Jul 20 07:05:26.578578 2026] [security2:error] [pid 45040:tid 45283] [client 43.173.179.165:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBF3QAAAG8"]
[Mon Jul 20 07:05:26.578623 2026] [security2:error] [pid 28702:tid 28882] [client 43.173.182.240:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dFbF4957xPw9VVBnVFgAAALY"]
[Mon Jul 20 07:05:26.586491 2026] [security2:error] [pid 45040:tid 45279] [client 43.173.180.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBGIwAAAGs"]
[Mon Jul 20 07:05:26.979686 2026] [security2:error] [pid 45040:tid 45246] [client 143.244.57.90:36070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4dFrEFnm79ltp0SFBGeAAAAEo"]
[Mon Jul 20 07:05:27.119787 2026] [security2:error] [pid 45040:tid 45252] [client 54.196.52.99:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4dFrEFnm79ltp0SFBGSAAAAFA"]
[Mon Jul 20 07:05:27.137077 2026] [security2:error] [pid 45040:tid 45211] [client 54.196.52.99:37564] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/carne-guisada-recipe-puerto-rican-beef-stew/"] [unique_id "al4dFrEFnm79ltp0SFBGRQAAACc"]
[Mon Jul 20 07:05:27.142518 2026] [security2:error] [pid 45040:tid 45236] [client 194.61.41.70:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/index.php"] [unique_id "al4dF7EFnm79ltp0SFBGgAAAAEA"]
[Mon Jul 20 07:05:27.186000 2026] [security2:error] [pid 45040:tid 45226] [client 114.119.130.18:27609] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.maxenengineering.com"] [uri "/products/cart"] [unique_id "al4dF7EFnm79ltp0SFBGhQAAADY"], referer: https://www.maxenengineering.com/products/cart?remove_item=0b7e926154c1274e8b602ff0d7c133d7
[Mon Jul 20 07:05:27.375606 2026] [security2:error] [pid 45040:tid 45201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dF7EFnm79ltp0SFBGggAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:27.468087 2026] [security2:error] [pid 45040:tid 45247] [client 20.106.196.4:43474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4dF7EFnm79ltp0SFBGoAAAAEs"]
[Mon Jul 20 07:05:27.484573 2026] [security2:error] [pid 45040:tid 45159] [remote 173.212.252.15:58938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dF7EFnm79ltp0SFBGpwAAK3Q"]
[Mon Jul 20 07:05:27.484717 2026] [security2:error] [pid 45040:tid 45215] [client 173.212.252.15:58938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dF7EFnm79ltp0SFBGpwAAK3Q"]
[Mon Jul 20 07:05:27.511558 2026] [security2:error] [pid 45040:tid 45275] [client 104.234.53.81:23225] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dF7EFnm79ltp0SFBGnQAAAGc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:27.573758 2026] [security2:error] [pid 28702:tid 28853] [client 143.244.57.90:13486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4dF7F4957xPw9VVBnVSwAAAJk"]
[Mon Jul 20 07:05:27.681003 2026] [security2:error] [pid 45040:tid 45250] [client 14.225.17.146:57724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4dF7EFnm79ltp0SFBGgQAAAE4"], referer: http://idigress.group/2023
[Mon Jul 20 07:05:27.765452 2026] [http2:warn] [pid 45040:tid 45188] [client 57.141.18.45:59266] h2_stream(45040-193-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:27.918931 2026] [security2:error] [pid 45040:tid 45266] [client 194.61.41.253:22813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/index22.php"] [unique_id "al4dF7EFnm79ltp0SFBGxwAAAF4"]
[Mon Jul 20 07:05:27.983871 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dF7F4957xPw9VVBnVTAAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:28.099319 2026] [security2:error] [pid 45040:tid 45245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dF7EFnm79ltp0SFBGwwAAAEk"]
[Mon Jul 20 07:05:28.177330 2026] [security2:error] [pid 28702:tid 28954] [client 143.244.57.90:36094] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4dGLF4957xPw9VVBnVVgAAAP4"]
[Mon Jul 20 07:05:28.242179 2026] [security2:error] [pid 45040:tid 45221] [client 104.234.53.81:23225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dGLEFnm79ltp0SFBG3AAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:28.496741 2026] [security2:error] [pid 45040:tid 45276] [client 187.16.64.216:61521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dGLEFnm79ltp0SFBG6gAAAGg"]
[Mon Jul 20 07:05:28.496854 2026] [security2:error] [pid 45040:tid 45276] [client 187.16.64.216:61521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dGLEFnm79ltp0SFBG6gAAAGg"]
[Mon Jul 20 07:05:28.690813 2026] [security2:error] [pid 45040:tid 45195] [client 194.61.41.74:46231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-user.php"] [unique_id "al4dGLEFnm79ltp0SFBG7wAAABc"]
[Mon Jul 20 07:05:28.771228 2026] [security2:error] [pid 45040:tid 45285] [client 143.244.57.90:36102] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4dGLEFnm79ltp0SFBG9wAAAHE"]
[Mon Jul 20 07:05:28.792614 2026] [security2:error] [pid 28702:tid 28720] [remote 194.164.192.228:39542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4dGLF4957xPw9VVBnVaAAA3xA"]
[Mon Jul 20 07:05:28.804648 2026] [security2:error] [pid 28702:tid 28913] [client 45.3.42.102:50637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dGLF4957xPw9VVBnVaQAAANU"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:28.890891 2026] [security2:error] [pid 28702:tid 28931] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dGLF4957xPw9VVBnVZAAAAOc"]
[Mon Jul 20 07:05:28.982930 2026] [security2:error] [pid 28702:tid 28801] [remote 194.164.192.228:39542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4dGLF4957xPw9VVBnVcgAA5GE"], referer: https://faadenergy.com/wp-login.php
[Mon Jul 20 07:05:29.110515 2026] [security2:error] [pid 45040:tid 45126] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.env"] [unique_id "al4dGbEFnm79ltp0SFBHEwAAalM"]
[Mon Jul 20 07:05:29.112039 2026] [security2:error] [pid 45040:tid 45170] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.aws/config"] [unique_id "al4dGbEFnm79ltp0SFBHFgAAan8"]
[Mon Jul 20 07:05:29.112159 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/.aws/config"] [unique_id "al4dGbEFnm79ltp0SFBHFgAAan8"]
[Mon Jul 20 07:05:29.113694 2026] [security2:error] [pid 45040:tid 45141] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.gitlab-ci.yml"] [unique_id "al4dGbEFnm79ltp0SFBHFwAAamI"]
[Mon Jul 20 07:05:29.270831 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHEgAAak8"]
[Mon Jul 20 07:05:29.270918 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHFAAAakw"]
[Mon Jul 20 07:05:29.270961 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHFQAAams"]
[Mon Jul 20 07:05:29.271003 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHGQAAamk"]
[Mon Jul 20 07:05:29.360926 2026] [security2:error] [pid 45040:tid 45257] [client 143.244.57.90:57737] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4dGbEFnm79ltp0SFBHQgAAAFU"]
[Mon Jul 20 07:05:29.386117 2026] [security2:error] [pid 45040:tid 45259] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHGwAAAFc"]
[Mon Jul 20 07:05:29.396663 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHNQAAans"]
[Mon Jul 20 07:05:29.397795 2026] [security2:error] [pid 45040:tid 45156] [remote 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHMwAAanE"]
[Mon Jul 20 07:05:29.399569 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHNAAAanU"]
[Mon Jul 20 07:05:29.407206 2026] [security2:error] [pid 45040:tid 45071] [remote 72.167.132.114:35442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dGbEFnm79ltp0SFBHSQAAAhw"]
[Mon Jul 20 07:05:29.429661 2026] [security2:error] [pid 45040:tid 45267] [client 194.61.41.68:52469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/about.php"] [unique_id "al4dGbEFnm79ltp0SFBHSwAAAF8"]
[Mon Jul 20 07:05:29.461773 2026] [security2:error] [pid 45040:tid 45278] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHPQAAahs"]
[Mon Jul 20 07:05:29.592441 2026] [security2:error] [pid 45040:tid 45256] [client 201.27.111.74:51115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dGbEFnm79ltp0SFBHVAAAAFQ"]
[Mon Jul 20 07:05:29.592614 2026] [security2:error] [pid 45040:tid 45256] [client 201.27.111.74:51115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dGbEFnm79ltp0SFBHVAAAAFQ"]
[Mon Jul 20 07:05:29.603184 2026] [security2:error] [pid 45040:tid 45270] [client 43.173.173.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHJgAAAGI"]
[Mon Jul 20 07:05:29.618737 2026] [security2:error] [pid 45040:tid 45285] [client 43.173.174.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHLQAAAHE"]
[Mon Jul 20 07:05:29.638246 2026] [security2:error] [pid 45040:tid 45173] [client 43.173.181.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHMAAAAAE"]
[Mon Jul 20 07:05:29.655637 2026] [security2:error] [pid 45040:tid 45273] [client 43.173.175.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHMQAAAGU"]
[Mon Jul 20 07:05:29.656698 2026] [security2:error] [pid 45040:tid 45264] [client 43.173.176.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHNgAAAFw"]
[Mon Jul 20 07:05:29.663894 2026] [security2:error] [pid 45040:tid 45067] [remote 72.167.132.114:35442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dGbEFnm79ltp0SFBHVwAAMxg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:05:29.720919 2026] [security2:error] [pid 45040:tid 45299] [client 116.179.32.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHSgAAAH8"]
[Mon Jul 20 07:05:29.753266 2026] [security2:error] [pid 45040:tid 45194] [client 43.172.195.250:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dGbEFnm79ltp0SFBHRwAAABY"]
[Mon Jul 20 07:05:29.882431 2026] [autoindex:error] [pid 45040:tid 45269] [client 144.172.114.51:35914] AH01276: Cannot serve directory /home4/orthero5/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:05:29.889280 2026] [http2:warn] [pid 28702:tid 28930] [client 57.141.18.114:22418] h2_stream(28702-883-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:29.941397 2026] [security2:error] [pid 45040:tid 45288] [client 77.110.127.138:62796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dGbEFnm79ltp0SFBHbQAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:29.941526 2026] [security2:error] [pid 45040:tid 45288] [client 77.110.127.138:62796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dGbEFnm79ltp0SFBHbQAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:29.943521 2026] [security2:error] [pid 45040:tid 45216] [client 143.244.57.90:36112] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4dGbEFnm79ltp0SFBHbgAAACw"]
[Mon Jul 20 07:05:30.167318 2026] [security2:error] [pid 45040:tid 45207] [client 194.61.41.80:57381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHggAAACM"]
[Mon Jul 20 07:05:30.177128 2026] [http2:warn] [pid 29744:tid 29885] [client 57.141.18.27:23464] h2_stream(29744-1425-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:30.177130 2026] [http2:warn] [pid 29744:tid 29956] [client 57.141.18.61:24852] h2_stream(29744-1490-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:30.177502 2026] [http2:warn] [pid 29744:tid 29909] [client 57.141.18.102:38574] h2_stream(29744-1423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:30.183356 2026] [http2:warn] [pid 29744:tid 29911] [client 57.141.18.27:24224] h2_stream(29744-1518-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:30.346167 2026] [security2:error] [pid 45040:tid 45285] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHcwAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:30.359264 2026] [security2:error] [pid 28702:tid 28857] [client 104.207.53.94:22669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dGrF4957xPw9VVBnVkwAAAJ0"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:30.378472 2026] [security2:error] [pid 45040:tid 45213] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHegAAACk"]
[Mon Jul 20 07:05:30.512400 2026] [security2:error] [pid 45040:tid 45079] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.env.local"] [unique_id "al4dGrEFnm79ltp0SFBHrgAAYiQ"]
[Mon Jul 20 07:05:30.512647 2026] [security2:error] [pid 45040:tid 45121] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.env.example"] [unique_id "al4dGrEFnm79ltp0SFBHrwAAYk4"]
[Mon Jul 20 07:05:30.512759 2026] [security2:error] [pid 45040:tid 45270] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/.env.example"] [unique_id "al4dGrEFnm79ltp0SFBHrwAAYk4"]
[Mon Jul 20 07:05:30.523597 2026] [security2:error] [pid 28702:tid 28960] [client 143.244.57.90:36152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4dGrF4957xPw9VVBnVlgAAAQQ"]
[Mon Jul 20 07:05:30.615601 2026] [security2:error] [pid 45040:tid 45270] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHrAAAYgU"]
[Mon Jul 20 07:05:30.689145 2026] [security2:error] [pid 45040:tid 45214] [client 15.237.209.113:33362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.209.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dGrEFnm79ltp0SFBHsgAAACo"]
[Mon Jul 20 07:05:30.753331 2026] [security2:error] [pid 28702:tid 28922] [client 14.225.17.146:56036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4dGrF4957xPw9VVBnVlwAAAN4"], referer: http://margaretspeckogawa.com/2023
[Mon Jul 20 07:05:30.881793 2026] [security2:error] [pid 45040:tid 45139] [remote 216.73.216.55:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4dGrEFnm79ltp0SFBHwwAAMGA"]
[Mon Jul 20 07:05:30.941061 2026] [security2:error] [pid 45040:tid 45175] [client 194.61.41.253:59987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/config.php"] [unique_id "al4dGrEFnm79ltp0SFBHxwAAAAM"]
[Mon Jul 20 07:05:31.026513 2026] [security2:error] [pid 45040:tid 45235] [client 14.225.17.146:59376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHugAAAD8"], referer: http://savilerowtravel.com/2023
[Mon Jul 20 07:05:31.117995 2026] [security2:error] [pid 45040:tid 45283] [client 143.244.57.90:61428] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4dG7EFnm79ltp0SFBH0wAAAG8"]
[Mon Jul 20 07:05:31.137825 2026] [security2:error] [pid 28702:tid 28946] [client 74.208.214.194:52966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dG7F4957xPw9VVBnVqgAAAPY"]
[Mon Jul 20 07:05:31.142268 2026] [security2:error] [pid 45040:tid 45267] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHvQAAAF8"]
[Mon Jul 20 07:05:31.222890 2026] [security2:error] [pid 28702:tid 28908] [client 52.47.76.32:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dG7F4957xPw9VVBnVrwAAANA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:05:31.225807 2026] [core:error] [pid 28702:tid 28847] [client 205.210.31.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:31.225823 2026] [core:error] [pid 28702:tid 28847] [client 205.210.31.46:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:31.320558 2026] [security2:error] [pid 45040:tid 45244] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dG7EFnm79ltp0SFBH0QAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:31.542641 2026] [security2:error] [pid 28702:tid 28949] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dG7F4957xPw9VVBnVtgAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:31.559931 2026] [security2:error] [pid 45040:tid 45291] [client 154.208.48.130:56655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dG7EFnm79ltp0SFBH-gAAAHc"]
[Mon Jul 20 07:05:31.560081 2026] [security2:error] [pid 45040:tid 45291] [client 154.208.48.130:56655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dG7EFnm79ltp0SFBH-gAAAHc"]
[Mon Jul 20 07:05:31.624595 2026] [security2:error] [pid 45040:tid 45192] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dG7EFnm79ltp0SFBH7gAAABQ"]
[Mon Jul 20 07:05:31.683094 2026] [security2:error] [pid 28702:tid 28940] [client 43.173.175.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dG7F4957xPw9VVBnVtwAAAPA"]
[Mon Jul 20 07:05:31.710902 2026] [security2:error] [pid 45040:tid 45211] [client 143.244.57.90:36162] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4dG7EFnm79ltp0SFBIBQAAACc"]
[Mon Jul 20 07:05:31.723702 2026] [security2:error] [pid 28702:tid 28953] [client 194.61.41.88:42611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/special.php"] [unique_id "al4dG7F4957xPw9VVBnVxAAAAP0"]
[Mon Jul 20 07:05:31.741448 2026] [security2:error] [pid 45040:tid 45262] [client 43.173.176.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dG7EFnm79ltp0SFBH6wAAAFo"]
[Mon Jul 20 07:05:31.769908 2026] [security2:error] [pid 28702:tid 28896] [client 43.173.180.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dG7F4957xPw9VVBnVuwAAAMQ"]
[Mon Jul 20 07:05:31.772318 2026] [security2:error] [pid 28702:tid 28960] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dG7F4957xPw9VVBnVvgAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:31.801374 2026] [security2:error] [pid 45040:tid 45236] [client 43.173.177.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4dG7EFnm79ltp0SFBH8AAAAEA"]
[Mon Jul 20 07:05:31.856022 2026] [security2:error] [pid 45040:tid 45183] [client 145.239.10.137:41666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/class.php"] [unique_id "al4dG7EFnm79ltp0SFBIEQAAAAs"], referer: http://suretybonds-california.com/class.php
[Mon Jul 20 07:05:31.910426 2026] [security2:error] [pid 28702:tid 28955] [client 104.234.53.86:61893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dG7F4957xPw9VVBnVygAAAP8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:32.120053 2026] [security2:error] [pid 28702:tid 28928] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dG7F4957xPw9VVBnVyAAAAOQ"]
[Mon Jul 20 07:05:32.137983 2026] [http2:warn] [pid 45040:tid 45180] [client 57.141.18.107:58604] h2_stream(45040-211-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:32.231276 2026] [security2:error] [pid 28702:tid 28947] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHLF4957xPw9VVBnV0AAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:32.291114 2026] [security2:error] [pid 45040:tid 45278] [client 143.244.57.90:36170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.garyjonathanmaddox.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4dHLEFnm79ltp0SFBIJgAAAGo"]
[Mon Jul 20 07:05:32.343791 2026] [security2:error] [pid 45040:tid 45222] [client 14.225.17.146:65198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4dGrEFnm79ltp0SFBHuwAAADI"], referer: http://709fx.com/2023
[Mon Jul 20 07:05:32.454251 2026] [security2:error] [pid 45040:tid 45106] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/backend/.env"] [unique_id "al4dHLEFnm79ltp0SFBITQAAOj8"]
[Mon Jul 20 07:05:32.454710 2026] [security2:error] [pid 45040:tid 45054] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.env.bak"] [unique_id "al4dHLEFnm79ltp0SFBITgAAOgw"]
[Mon Jul 20 07:05:32.454768 2026] [security2:error] [pid 45040:tid 45144] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.env.old"] [unique_id "al4dHLEFnm79ltp0SFBITwAAOmU"]
[Mon Jul 20 07:05:32.472205 2026] [security2:error] [pid 45040:tid 45251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHLEFnm79ltp0SFBIIwAAAE8"]
[Mon Jul 20 07:05:32.561256 2026] [security2:error] [pid 45040:tid 45192] [client 194.61.41.252:43055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/script.js.php"] [unique_id "al4dHLEFnm79ltp0SFBIXwAAABQ"]
[Mon Jul 20 07:05:32.577686 2026] [security2:error] [pid 45040:tid 45230] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHLEFnm79ltp0SFBIUQAAOjU"]
[Mon Jul 20 07:05:32.582440 2026] [security2:error] [pid 45040:tid 45230] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHLEFnm79ltp0SFBIUAAAOjY"]
[Mon Jul 20 07:05:32.648442 2026] [security2:error] [pid 45040:tid 45164] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.env.backup"] [unique_id "al4dHLEFnm79ltp0SFBIYwAAWnk"]
[Mon Jul 20 07:05:32.648491 2026] [security2:error] [pid 45040:tid 45134] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/api/.env"] [unique_id "al4dHLEFnm79ltp0SFBIZAAAWls"]
[Mon Jul 20 07:05:32.649636 2026] [security2:error] [pid 45040:tid 45157] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/config/.env"] [unique_id "al4dHLEFnm79ltp0SFBIZQAAWnI"]
[Mon Jul 20 07:05:32.832220 2026] [security2:error] [pid 45040:tid 45141] [remote 57.141.18.61:31802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5979734"] [unique_id "al4dHLEFnm79ltp0SFBIbwAAV2I"]
[Mon Jul 20 07:05:33.108509 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:62787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dHbEFnm79ltp0SFBIjwAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:33.108650 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:62787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dHbEFnm79ltp0SFBIjwAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:33.185405 2026] [security2:error] [pid 45040:tid 45222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHLEFnm79ltp0SFBIgwAAADI"]
[Mon Jul 20 07:05:33.284597 2026] [security2:error] [pid 45040:tid 45225] [client 122.183.32.225:24324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dHbEFnm79ltp0SFBImAAAADU"]
[Mon Jul 20 07:05:33.284713 2026] [security2:error] [pid 45040:tid 45225] [client 122.183.32.225:24324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dHbEFnm79ltp0SFBImAAAADU"]
[Mon Jul 20 07:05:33.288744 2026] [security2:error] [pid 28702:tid 28871] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHbF4957xPw9VVBnV7gAAAKs"]
[Mon Jul 20 07:05:33.308900 2026] [security2:error] [pid 28702:tid 28949] [client 103.144.65.217:51861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dHbF4957xPw9VVBnV8QAAAPk"]
[Mon Jul 20 07:05:33.309043 2026] [security2:error] [pid 28702:tid 28949] [client 103.144.65.217:51861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dHbF4957xPw9VVBnV8QAAAPk"]
[Mon Jul 20 07:05:33.311842 2026] [security2:error] [pid 28702:tid 28861] [client 194.61.41.76:53855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentythree/patterns/index.php"] [unique_id "al4dHbF4957xPw9VVBnV8gAAAKE"]
[Mon Jul 20 07:05:33.481758 2026] [security2:error] [pid 45040:tid 45270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIlwAAAGI"]
[Mon Jul 20 07:05:33.493627 2026] [security2:error] [pid 45040:tid 45283] [client 50.116.65.227:46662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_43ccd705/wp-cron.php"] [unique_id "al4dHbEFnm79ltp0SFBIpAAAAG8"]
[Mon Jul 20 07:05:33.534646 2026] [security2:error] [pid 45040:tid 45070] [remote 91.142.222.105:48980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dHbEFnm79ltp0SFBIpgAAOhs"]
[Mon Jul 20 07:05:33.534811 2026] [security2:error] [pid 45040:tid 45230] [client 91.142.222.105:48980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dHbEFnm79ltp0SFBIpgAAOhs"]
[Mon Jul 20 07:05:33.579506 2026] [security2:error] [pid 45040:tid 45285] [client 104.234.53.52:55197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dHbEFnm79ltp0SFBIrQAAAHE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:33.900507 2026] [security2:error] [pid 45040:tid 45061] [remote 216.73.216.55:61988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4dHbEFnm79ltp0SFBIxAAAThM"]
[Mon Jul 20 07:05:33.906328 2026] [security2:error] [pid 45040:tid 45086] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/serviceAccountKey.json"] [unique_id "al4dHbEFnm79ltp0SFBIxgAAGSs"]
[Mon Jul 20 07:05:33.906511 2026] [security2:error] [pid 45040:tid 45197] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/serviceAccountKey.json"] [unique_id "al4dHbEFnm79ltp0SFBIxgAAGSs"]
[Mon Jul 20 07:05:33.914917 2026] [security2:error] [pid 45040:tid 45273] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIrAAAAGU"]
[Mon Jul 20 07:05:33.967002 2026] [security2:error] [pid 45040:tid 45259] [client 14.225.17.146:56462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIsQAAAFc"], referer: http://nextlevelpressurewashing.com/2023
[Mon Jul 20 07:05:33.986643 2026] [security2:error] [pid 45040:tid 45197] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIwQAAGVk"]
[Mon Jul 20 07:05:34.025326 2026] [security2:error] [pid 45040:tid 45197] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIxwAAGQo"]
[Mon Jul 20 07:05:34.025787 2026] [security2:error] [pid 45040:tid 45197] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIxQAAGSY"]
[Mon Jul 20 07:05:34.028331 2026] [security2:error] [pid 45040:tid 45296] [client 194.61.41.93:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/sunrise/colors_95.php"] [unique_id "al4dHrEFnm79ltp0SFBI2QAAAHw"]
[Mon Jul 20 07:05:34.038188 2026] [authz_core:error] [pid 45040:tid 45076] [remote 34.75.50.82:48964] AH01630: client denied by server configuration: /home1/polishe5/public_html/.htpasswd
[Mon Jul 20 07:05:34.073030 2026] [security2:error] [pid 45040:tid 45118] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.boto"] [unique_id "al4dHrEFnm79ltp0SFBI6AAAUEs"]
[Mon Jul 20 07:05:34.073188 2026] [security2:error] [pid 45040:tid 45252] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/.boto"] [unique_id "al4dHrEFnm79ltp0SFBI6AAAUEs"]
[Mon Jul 20 07:05:34.138046 2026] [security2:error] [pid 45040:tid 45282] [client 50.116.65.227:54350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dHrEFnm79ltp0SFBI8AAAAG4"]
[Mon Jul 20 07:05:34.153014 2026] [security2:error] [pid 28702:tid 28881] [client 50.116.65.227:54354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dHrF4957xPw9VVBnWCAAAALU"]
[Mon Jul 20 07:05:34.158636 2026] [security2:error] [pid 45040:tid 45252] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI3QAAUBI"]
[Mon Jul 20 07:05:34.172679 2026] [security2:error] [pid 45040:tid 45252] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI4QAAUCw"]
[Mon Jul 20 07:05:34.181938 2026] [security2:error] [pid 45040:tid 45252] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI3wAAUA4"]
[Mon Jul 20 07:05:34.185821 2026] [security2:error] [pid 45040:tid 45252] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI3AAAUAU"]
[Mon Jul 20 07:05:34.186113 2026] [security2:error] [pid 45040:tid 45139] [remote 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI4AAAUGA"]
[Mon Jul 20 07:05:34.234427 2026] [security2:error] [pid 45040:tid 45252] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI5wAAUEY"]
[Mon Jul 20 07:05:34.282332 2026] [http2:warn] [pid 28702:tid 28932] [client 57.141.18.120:42598] h2_stream(28702-894-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:34.292968 2026] [security2:error] [pid 45040:tid 45059] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/terraform.tfstate"] [unique_id "al4dHrEFnm79ltp0SFBI_gAAWBE"]
[Mon Jul 20 07:05:34.436248 2026] [security2:error] [pid 45040:tid 45182] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI_wAAChA"]
[Mon Jul 20 07:05:34.447336 2026] [security2:error] [pid 45040:tid 45184] [client 14.225.17.146:56637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4dHbEFnm79ltp0SFBIhgAAAAw"], referer: http://alchemygroup.ca/2023
[Mon Jul 20 07:05:34.453312 2026] [security2:error] [pid 45040:tid 45187] [client 14.225.17.146:61520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJAwAAAA8"], referer: http://keywayconstructionclt.com/2023
[Mon Jul 20 07:05:34.462285 2026] [security2:error] [pid 45040:tid 45182] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJAgAACkg"]
[Mon Jul 20 07:05:34.502834 2026] [security2:error] [pid 45040:tid 45114] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al4dHrEFnm79ltp0SFBJCQAAEUc"]
[Mon Jul 20 07:05:34.502984 2026] [security2:error] [pid 45040:tid 45189] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al4dHrEFnm79ltp0SFBJCQAAEUc"]
[Mon Jul 20 07:05:34.504704 2026] [security2:error] [pid 45040:tid 45151] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.ssh/id_rsa"] [unique_id "al4dHrEFnm79ltp0SFBJCAAAEWw"]
[Mon Jul 20 07:05:34.584954 2026] [security2:error] [pid 28702:tid 28876] [client 14.225.17.146:61493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4dHbF4957xPw9VVBnV-gAAALA"], referer: http://processorstudio.com/2023
[Mon Jul 20 07:05:34.635640 2026] [security2:error] [pid 45040:tid 45235] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBI-gAAAD8"]
[Mon Jul 20 07:05:34.744124 2026] [security2:error] [pid 28702:tid 28848] [client 194.61.41.77:40259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/block-patterns/autoload_classmap.php"] [unique_id "al4dHrF4957xPw9VVBnWHgAAAJQ"]
[Mon Jul 20 07:05:34.746347 2026] [security2:error] [pid 45040:tid 45219] [client 77.110.127.138:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/feed/ya09ev2meamc.php"] [unique_id "al4dHrEFnm79ltp0SFBJFwAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:34.931704 2026] [security2:error] [pid 45040:tid 45125] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.ssh/id_dsa"] [unique_id "al4dHrEFnm79ltp0SFBJKAAATlI"]
[Mon Jul 20 07:05:34.931994 2026] [security2:error] [pid 45040:tid 45250] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/.ssh/id_dsa"] [unique_id "al4dHrEFnm79ltp0SFBJKAAATlI"]
[Mon Jul 20 07:05:34.937016 2026] [security2:error] [pid 45040:tid 45105] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.ssh/authorized_keys"] [unique_id "al4dHrEFnm79ltp0SFBJKQAARj4"]
[Mon Jul 20 07:05:34.985095 2026] [security2:error] [pid 45040:tid 45248] [client 183.82.98.154:62768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dHrEFnm79ltp0SFBJLgAAAEw"]
[Mon Jul 20 07:05:34.985194 2026] [security2:error] [pid 45040:tid 45248] [client 183.82.98.154:62768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dHrEFnm79ltp0SFBJLgAAAEw"]
[Mon Jul 20 07:05:35.035029 2026] [security2:error] [pid 45040:tid 45123] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/id_rsa"] [unique_id "al4dH7EFnm79ltp0SFBJNQAAZFA"]
[Mon Jul 20 07:05:35.035398 2026] [security2:error] [pid 45040:tid 45107] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/id_dsa"] [unique_id "al4dH7EFnm79ltp0SFBJNgAAZEA"]
[Mon Jul 20 07:05:35.056783 2026] [security2:error] [pid 45040:tid 45272] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJKgAAZHQ"]
[Mon Jul 20 07:05:35.075564 2026] [security2:error] [pid 45040:tid 45290] [client 14.225.17.146:61562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJJAAAAHY"], referer: http://oldracelimited.com/2023
[Mon Jul 20 07:05:35.134120 2026] [security2:error] [pid 28702:tid 28842] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHrF4957xPw9VVBnWHQAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:35.153705 2026] [security2:error] [pid 45040:tid 45272] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJNAAAZGQ"]
[Mon Jul 20 07:05:35.172213 2026] [security2:error] [pid 45040:tid 45272] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJMwAAZAk"]
[Mon Jul 20 07:05:35.216099 2026] [security2:error] [pid 45040:tid 45206] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJHQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:35.318773 2026] [security2:error] [pid 28702:tid 28862] [client 117.247.108.24:51630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dH7F4957xPw9VVBnWMAAAAKI"]
[Mon Jul 20 07:05:35.318912 2026] [security2:error] [pid 28702:tid 28862] [client 117.247.108.24:51630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dH7F4957xPw9VVBnWMAAAAKI"]
[Mon Jul 20 07:05:35.352326 2026] [security2:error] [pid 45040:tid 45182] [client 14.225.17.146:57633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJSAAAAAo"], referer: https://keywayconstructionclt.com/2023
[Mon Jul 20 07:05:35.410631 2026] [security2:error] [pid 45040:tid 45128] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.openclaw/.env"] [unique_id "al4dH7EFnm79ltp0SFBJUgAAIVU"]
[Mon Jul 20 07:05:35.412702 2026] [security2:error] [pid 45040:tid 45129] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/id_ecdsa"] [unique_id "al4dH7EFnm79ltp0SFBJVwAAIVY"]
[Mon Jul 20 07:05:35.412869 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/id_ecdsa"] [unique_id "al4dH7EFnm79ltp0SFBJVwAAIVY"]
[Mon Jul 20 07:05:35.413994 2026] [security2:error] [pid 45040:tid 45142] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/privatekey.key"] [unique_id "al4dH7EFnm79ltp0SFBJWwAAIWM"]
[Mon Jul 20 07:05:35.414130 2026] [security2:error] [pid 45040:tid 45054] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/key.pem"] [unique_id "al4dH7EFnm79ltp0SFBJWAAAIQw"]
[Mon Jul 20 07:05:35.414153 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/privatekey.key"] [unique_id "al4dH7EFnm79ltp0SFBJWwAAIWM"]
[Mon Jul 20 07:05:35.480122 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJTwAAIVQ"]
[Mon Jul 20 07:05:35.488628 2026] [security2:error] [pid 45040:tid 45195] [client 14.225.17.146:53625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJXgAAABc"], referer: https://processorstudio.com/2023
[Mon Jul 20 07:05:35.493412 2026] [security2:error] [pid 45040:tid 45267] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJIQAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:35.534149 2026] [security2:error] [pid 45040:tid 45187] [client 147.93.171.187:59522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "al4dH7EFnm79ltp0SFBJZQAAAA8"], referer: binance.com
[Mon Jul 20 07:05:35.535816 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJWgAAIWU"]
[Mon Jul 20 07:05:35.542330 2026] [security2:error] [pid 45040:tid 45175] [client 194.61.41.56:59781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/wp.php"] [unique_id "al4dH7EFnm79ltp0SFBJaAAAAAM"]
[Mon Jul 20 07:05:35.543033 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJVQAAIVg"]
[Mon Jul 20 07:05:35.546909 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJVgAAITg"]
[Mon Jul 20 07:05:35.547603 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJVAAAIR0"]
[Mon Jul 20 07:05:35.548249 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJWQAAIT8"]
[Mon Jul 20 07:05:35.561074 2026] [security2:error] [pid 45040:tid 45205] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJUwAAISc"]
[Mon Jul 20 07:05:35.585393 2026] [security2:error] [pid 45040:tid 45225] [client 77.110.127.138:62820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dHrEFnm79ltp0SFBJIgAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:35.757264 2026] [security2:error] [pid 45040:tid 45261] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJbwAAWXc"]
[Mon Jul 20 07:05:36.106614 2026] [security2:error] [pid 45040:tid 45173] [client 104.234.53.59:38957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJigAAAAE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:36.123139 2026] [security2:error] [pid 45040:tid 45195] [client 116.179.32.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4dH7EFnm79ltp0SFBJgwAAABc"]
[Mon Jul 20 07:05:36.330555 2026] [security2:error] [pid 45040:tid 45224] [client 194.61.41.66:48421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/about.php"] [unique_id "al4dILEFnm79ltp0SFBJpAAAADQ"]
[Mon Jul 20 07:05:36.351130 2026] [security2:error] [pid 45040:tid 45185] [client 104.234.53.59:38957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dILEFnm79ltp0SFBJpQAAAA0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:36.390480 2026] [security2:error] [pid 45040:tid 45260] [client 77.110.127.138:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dILEFnm79ltp0SFBJqAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:36.390594 2026] [security2:error] [pid 45040:tid 45260] [client 77.110.127.138:62785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dILEFnm79ltp0SFBJqAAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:36.400021 2026] [security2:error] [pid 28702:tid 28931] [client 14.225.17.146:56046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4dILF4957xPw9VVBnWTgAAAOc"], referer: http://katsklar.com/2023
[Mon Jul 20 07:05:36.774274 2026] [http2:warn] [pid 28702:tid 28855] [client 57.141.18.121:56574] h2_stream(28702-695-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:37.037596 2026] [security2:error] [pid 45040:tid 45182] [client 194.61.41.108:20785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cgi-bin/class.api.php"] [unique_id "al4dIbEFnm79ltp0SFBJzAAAAAo"]
[Mon Jul 20 07:05:37.149327 2026] [http2:warn] [pid 45040:tid 45172] [client 57.141.18.43:36476] h2_stream(45040-244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:37.207447 2026] [http2:warn] [pid 29744:tid 29955] [client 57.141.18.81:21662] h2_stream(29744-976-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:37.633478 2026] [security2:error] [pid 45040:tid 45236] [client 213.152.186.163:40536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dIbEFnm79ltp0SFBJ5QAAAEA"]
[Mon Jul 20 07:05:37.633577 2026] [security2:error] [pid 45040:tid 45236] [client 213.152.186.163:40536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dIbEFnm79ltp0SFBJ5QAAAEA"]
[Mon Jul 20 07:05:37.651051 2026] [security2:error] [pid 28702:tid 28731] [remote 91.142.222.105:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4dIbF4957xPw9VVBnWcAAA-xs"]
[Mon Jul 20 07:05:37.656790 2026] [security2:error] [pid 45040:tid 45186] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dIbEFnm79ltp0SFBJ3QAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:37.719424 2026] [http2:warn] [pid 29744:tid 29915] [client 57.141.18.106:39630] h2_stream(29744-983-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:37.790388 2026] [security2:error] [pid 45040:tid 45237] [client 158.173.166.181:20163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dIbEFnm79ltp0SFBJ7QAAAEE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:05:37.808153 2026] [http2:warn] [pid 29744:tid 29945] [client 57.141.18.2:41452] h2_stream(29744-986-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:37.813279 2026] [security2:error] [pid 28702:tid 28848] [client 194.61.41.85:40567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/cache/index.php"] [unique_id "al4dIbF4957xPw9VVBnWcgAAAJQ"]
[Mon Jul 20 07:05:37.866921 2026] [security2:error] [pid 45040:tid 45081] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.thewelloiledlife.com"] [uri "/graphql"] [unique_id "al4dIbEFnm79ltp0SFBJ8wAAKSY"]
[Mon Jul 20 07:05:37.887416 2026] [security2:error] [pid 28702:tid 28861] [client 77.110.127.138:62835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/filet-crochet/9y92kaweqwrs.php"] [unique_id "al4dIbF4957xPw9VVBnWeAAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:38.012635 2026] [security2:error] [pid 28702:tid 28805] [remote 91.142.222.105:59038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4dIrF4957xPw9VVBnWfQAAkmU"], referer: https://website-5ab144f7.uritems.net/wp-login.php
[Mon Jul 20 07:05:38.223326 2026] [security2:error] [pid 45040:tid 45270] [client 77.110.127.138:62836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dIbEFnm79ltp0SFBJ9wAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:38.227356 2026] [security2:error] [pid 45040:tid 45218] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dIbEFnm79ltp0SFBJ-wAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:38.542185 2026] [security2:error] [pid 45040:tid 45288] [client 173.239.254.15:20481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4dIbEFnm79ltp0SFBJ1wAAAHQ"]
[Mon Jul 20 07:05:38.547044 2026] [security2:error] [pid 45040:tid 45253] [client 194.61.41.250:28923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4dIrEFnm79ltp0SFBKGAAAAFE"]
[Mon Jul 20 07:05:38.778038 2026] [security2:error] [pid 45040:tid 45175] [client 77.110.127.138:62831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dIrEFnm79ltp0SFBKFQAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:38.779739 2026] [security2:error] [pid 28702:tid 28927] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dIrF4957xPw9VVBnWnAAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:38.804123 2026] [security2:error] [pid 45040:tid 45046] [remote 57.141.18.120:56890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4dIrEFnm79ltp0SFBKJQAAfQU"]
[Mon Jul 20 07:05:38.851061 2026] [security2:error] [pid 45040:tid 45271] [client 47.128.32.89:34640] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.keywayconstructionclt.com"] [uri "/robots.txt"] [unique_id "al4dIrEFnm79ltp0SFBKKwAAAGM"]
[Mon Jul 20 07:05:38.858985 2026] [security2:error] [pid 45040:tid 45236] [client 77.110.127.138:62845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/student-resources/8n9sricbegln.php"] [unique_id "al4dIrEFnm79ltp0SFBKLQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:39.022602 2026] [security2:error] [pid 28702:tid 28950] [client 14.225.17.146:50124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4dIbF4957xPw9VVBnWaQAAAPo"], referer: http://careysheatingandcooling.com/2023
[Mon Jul 20 07:05:39.044383 2026] [http2:warn] [pid 28702:tid 28959] [client 57.141.18.112:33404] h2_stream(28702-705-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:39.064172 2026] [security2:error] [pid 45040:tid 45254] [client 14.225.17.146:56924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4dIrEFnm79ltp0SFBKMgAAAFI"], referer: https://north-woods-engineering.com/2023
[Mon Jul 20 07:05:39.170966 2026] [security2:error] [pid 28702:tid 28946] [client 201.27.111.74:51572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dI7F4957xPw9VVBnWqwAAAPY"]
[Mon Jul 20 07:05:39.171110 2026] [security2:error] [pid 28702:tid 28946] [client 201.27.111.74:51572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dI7F4957xPw9VVBnWqwAAAPY"]
[Mon Jul 20 07:05:39.182886 2026] [security2:error] [pid 45040:tid 45275] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dIrEFnm79ltp0SFBKNgAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:39.218617 2026] [security2:error] [pid 45040:tid 45226] [client 187.16.64.216:62096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dI7EFnm79ltp0SFBKSAAAADY"]
[Mon Jul 20 07:05:39.218723 2026] [security2:error] [pid 45040:tid 45226] [client 187.16.64.216:62096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dI7EFnm79ltp0SFBKSAAAADY"]
[Mon Jul 20 07:05:39.298798 2026] [security2:error] [pid 45040:tid 45267] [client 147.93.171.187:60365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "al4dI7EFnm79ltp0SFBKSwAAAF8"], referer: binance.com
[Mon Jul 20 07:05:39.330672 2026] [security2:error] [pid 45040:tid 45208] [client 194.61.41.63:33345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/edit.php"] [unique_id "al4dI7EFnm79ltp0SFBKTAAAACQ"]
[Mon Jul 20 07:05:39.499655 2026] [security2:error] [pid 28702:tid 28855] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dI7F4957xPw9VVBnWqgAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:39.684640 2026] [http2:warn] [pid 29744:tid 29978] [client 57.141.18.75:50278] h2_stream(29744-996-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:39.846814 2026] [security2:error] [pid 45040:tid 45203] [client 77.110.127.138:62836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/pixelyoursite/q24x5l4i8ck8.php"] [unique_id "al4dI7EFnm79ltp0SFBKZgAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:39.902811 2026] [autoindex:error] [pid 45040:tid 45282] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/pixelyoursite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:05:39.909507 2026] [autoindex:error] [pid 45040:tid 45254] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/pixelyoursite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:05:40.045203 2026] [security2:error] [pid 28702:tid 28955] [client 194.61.41.83:40979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/webdb.php"] [unique_id "al4dJLF4957xPw9VVBnWyAAAAP8"]
[Mon Jul 20 07:05:40.212103 2026] [security2:error] [pid 45040:tid 45105] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/.claude/settings.json"] [unique_id "al4dJLEFnm79ltp0SFBKgQAAXz4"]
[Mon Jul 20 07:05:40.212297 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thewelloiledlife.com"] [uri "/.claude/settings.json"] [unique_id "al4dJLEFnm79ltp0SFBKgQAAXz4"]
[Mon Jul 20 07:05:40.212393 2026] [security2:error] [pid 45040:tid 45125] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.thewelloiledlife.com"] [uri "/api/graphql"] [unique_id "al4dJLEFnm79ltp0SFBKgAAAX1I"]
[Mon Jul 20 07:05:40.213246 2026] [security2:error] [pid 45040:tid 45159] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/.hermes/.env"] [unique_id "al4dJLEFnm79ltp0SFBKhgAAX3Q"]
[Mon Jul 20 07:05:40.217526 2026] [http2:warn] [pid 29744:tid 29984] [client 57.141.18.95:21990] h2_stream(29744-1001-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:40.260521 2026] [security2:error] [pid 45040:tid 45247] [client 77.110.127.138:62859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dI7EFnm79ltp0SFBKcgAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.264839 2026] [security2:error] [pid 45040:tid 45290] [client 14.182.195.220:52523] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dJLEFnm79ltp0SFBKjAAAAHY"]
[Mon Jul 20 07:05:40.267676 2026] [security2:error] [pid 45040:tid 45222] [client 14.182.195.220:52522] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dJLEFnm79ltp0SFBKjQAAADI"]
[Mon Jul 20 07:05:40.272818 2026] [security2:error] [pid 28702:tid 28858] [client 14.182.195.220:52521] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dJLF4957xPw9VVBnWywAAAJ4"]
[Mon Jul 20 07:05:40.298448 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKeQAAXzM"]
[Mon Jul 20 07:05:40.304813 2026] [security2:error] [pid 45040:tid 45186] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dI7EFnm79ltp0SFBKcwAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.347222 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKhwAAX1w"]
[Mon Jul 20 07:05:40.354423 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKfwAAXx4"]
[Mon Jul 20 07:05:40.355195 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKhQAAX1A"]
[Mon Jul 20 07:05:40.356110 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKiQAAXy8"]
[Mon Jul 20 07:05:40.356268 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKigAAXwk"]
[Mon Jul 20 07:05:40.356362 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKiAAAX2Q"]
[Mon Jul 20 07:05:40.357150 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKhAAAX0M"]
[Mon Jul 20 07:05:40.361405 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKgwAAX1o"]
[Mon Jul 20 07:05:40.362415 2026] [security2:error] [pid 45040:tid 45267] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKggAAX0A"]
[Mon Jul 20 07:05:40.513454 2026] [autoindex:error] [pid 45040:tid 45272] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/pixelyoursite/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.515608 2026] [autoindex:error] [pid 45040:tid 45284] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/pixelyoursite/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:05:40.567321 2026] [security2:error] [pid 45040:tid 45291] [client 77.110.127.138:62863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/pixelyoursite/dist/j547ovxt8zmm.php"] [unique_id "al4dJLEFnm79ltp0SFBKoQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.689537 2026] [http2:warn] [pid 29744:tid 29942] [client 57.141.18.50:27652] h2_stream(29744-1005-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:40.787104 2026] [security2:error] [pid 45040:tid 45251] [client 77.110.127.138:62864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKogAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.792040 2026] [security2:error] [pid 45040:tid 45242] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKqAAAAEY"]
[Mon Jul 20 07:05:40.802499 2026] [security2:error] [pid 45040:tid 45129] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.thewelloiledlife.com"] [uri "/v1/graphql"] [unique_id "al4dJLEFnm79ltp0SFBKrQAAUVY"]
[Mon Jul 20 07:05:40.826065 2026] [security2:error] [pid 45040:tid 45243] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKowAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.856666 2026] [security2:error] [pid 45040:tid 45257] [client 194.61.41.54:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/images/doc.php"] [unique_id "al4dJLEFnm79ltp0SFBKsgAAAFU"]
[Mon Jul 20 07:05:40.892104 2026] [security2:error] [pid 45040:tid 45054] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.50.75.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/.env.php.bak"] [unique_id "al4dJLEFnm79ltp0SFBKsQAAegw"]
[Mon Jul 20 07:05:40.961207 2026] [security2:error] [pid 45040:tid 45179] [client 77.110.127.138:62865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dJLEFnm79ltp0SFBKuQAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.961284 2026] [security2:error] [pid 45040:tid 45179] [client 77.110.127.138:62865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dJLEFnm79ltp0SFBKuQAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:40.967618 2026] [security2:error] [pid 45040:tid 45294] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJLEFnm79ltp0SFBKsAAAel4"]
[Mon Jul 20 07:05:41.030622 2026] [security2:error] [pid 45040:tid 45106] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.50.75.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/config.php.bak"] [unique_id "al4dJbEFnm79ltp0SFBKvAAALz8"]
[Mon Jul 20 07:05:41.031041 2026] [security2:error] [pid 45040:tid 45100] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.thewelloiledlife.com"] [uri "/wp-config.php.old"] [unique_id "al4dJbEFnm79ltp0SFBKvwAALzk"]
[Mon Jul 20 07:05:41.031434 2026] [security2:error] [pid 45040:tid 45164] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.thewelloiledlife.com"] [uri "/wp-config.php.bak"] [unique_id "al4dJbEFnm79ltp0SFBKwQAAL3k"]
[Mon Jul 20 07:05:41.032029 2026] [security2:error] [pid 45040:tid 45157] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/laravel/.env"] [unique_id "al4dJbEFnm79ltp0SFBKxAAAL3I"]
[Mon Jul 20 07:05:41.032143 2026] [security2:error] [pid 45040:tid 45162] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.50.75.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/config/.env.php"] [unique_id "al4dJbEFnm79ltp0SFBKwgAAL3c"]
[Mon Jul 20 07:05:41.032626 2026] [security2:error] [pid 45040:tid 45134] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.thewelloiledlife.com"] [uri "/core/.env"] [unique_id "al4dJbEFnm79ltp0SFBKwwAAL1s"]
[Mon Jul 20 07:05:41.145530 2026] [security2:error] [pid 45040:tid 45219] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBKwAAALzU"]
[Mon Jul 20 07:05:41.145662 2026] [security2:error] [pid 45040:tid 45219] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBKuwAALx0"]
[Mon Jul 20 07:05:41.145780 2026] [security2:error] [pid 45040:tid 45219] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBKvgAALyc"]
[Mon Jul 20 07:05:41.149808 2026] [security2:error] [pid 45040:tid 45219] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBKvQAAL2E"]
[Mon Jul 20 07:05:41.216635 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:62786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/pixelyoursite/dist/scripts/avnfka2uuk58.php"] [unique_id "al4dJbEFnm79ltp0SFBKzQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:41.259414 2026] [autoindex:error] [pid 28702:tid 28846] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/pixelyoursite/dist/scripts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:05:41.319893 2026] [security2:error] [pid 28702:tid 28936] [client 122.183.32.225:10751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dJbF4957xPw9VVBnW-AAAAOw"]
[Mon Jul 20 07:05:41.320002 2026] [security2:error] [pid 28702:tid 28936] [client 122.183.32.225:10751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dJbF4957xPw9VVBnW-AAAAOw"]
[Mon Jul 20 07:05:41.393832 2026] [autoindex:error] [pid 45040:tid 45297] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/pixelyoursite/dist/scripts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:05:41.415185 2026] [security2:error] [pid 45040:tid 45263] [client 77.110.127.138:62838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBKzgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:41.457946 2026] [security2:error] [pid 45040:tid 45284] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK0wAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:41.588393 2026] [security2:error] [pid 45040:tid 45042] [remote 34.75.50.82:48964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.50.75.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/test.php"] [unique_id "al4dJbEFnm79ltp0SFBK7AAADQE"]
[Mon Jul 20 07:05:41.596802 2026] [security2:error] [pid 45040:tid 45141] [remote 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK4gAADWI"]
[Mon Jul 20 07:05:41.599896 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK4wAADXY"]
[Mon Jul 20 07:05:41.606702 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK5gAADX4"]
[Mon Jul 20 07:05:41.609782 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK5QAADX8"]
[Mon Jul 20 07:05:41.627825 2026] [security2:error] [pid 28702:tid 28862] [client 194.61.41.106:45311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/file2.php"] [unique_id "al4dJbF4957xPw9VVBnW_wAAAKI"]
[Mon Jul 20 07:05:41.702734 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK6wAADXE"]
[Mon Jul 20 07:05:41.702843 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK6QAADW0"]
[Mon Jul 20 07:05:41.705865 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK7QAADRw"]
[Mon Jul 20 07:05:41.719653 2026] [security2:error] [pid 45040:tid 45185] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJbEFnm79ltp0SFBK6gAADXU"]
[Mon Jul 20 07:05:41.780372 2026] [security2:error] [pid 45040:tid 45289] [client 104.234.53.47:30055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dJbEFnm79ltp0SFBK_wAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:41.796319 2026] [security2:error] [pid 45040:tid 45247] [client 147.93.171.187:50947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "al4dJbEFnm79ltp0SFBLAgAAAEs"], referer: binance.com
[Mon Jul 20 07:05:41.810542 2026] [http2:warn] [pid 29744:tid 29917] [client 57.141.18.119:42432] h2_stream(29744-1013-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:41.962073 2026] [security2:error] [pid 45040:tid 45109] [remote 103.82.22.235:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4dJbEFnm79ltp0SFBLDQAAT0I"]
[Mon Jul 20 07:05:42.031436 2026] [http2:warn] [pid 28702:tid 28944] [client 57.141.18.108:24546] h2_stream(28702-713-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:42.066891 2026] [security2:error] [pid 45040:tid 45242] [client 154.208.48.130:57158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dJrEFnm79ltp0SFBLFAAAAEY"]
[Mon Jul 20 07:05:42.068339 2026] [security2:error] [pid 45040:tid 45242] [client 154.208.48.130:57158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dJrEFnm79ltp0SFBLFAAAAEY"]
[Mon Jul 20 07:05:42.095638 2026] [security2:error] [pid 45040:tid 45296] [client 74.249.226.166:42880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4dJrEFnm79ltp0SFBLFQAAAHw"]
[Mon Jul 20 07:05:42.148441 2026] [security2:error] [pid 45040:tid 45291] [client 74.249.226.166:42880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4dJrEFnm79ltp0SFBLFwAAAHc"]
[Mon Jul 20 07:05:42.349513 2026] [security2:error] [pid 28702:tid 28954] [client 194.61.41.243:35731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/wp-work.php"] [unique_id "al4dJrF4957xPw9VVBnXCgAAAP4"]
[Mon Jul 20 07:05:42.454800 2026] [security2:error] [pid 45040:tid 45243] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJrEFnm79ltp0SFBLHwAARyA"]
[Mon Jul 20 07:05:42.455673 2026] [security2:error] [pid 45040:tid 45243] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJrEFnm79ltp0SFBLIQAARw0"]
[Mon Jul 20 07:05:42.459564 2026] [http2:warn] [pid 29744:tid 29970] [client 57.141.18.51:51662] h2_stream(29744-1017-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:42.461881 2026] [security2:error] [pid 45040:tid 45243] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJrEFnm79ltp0SFBLIAAARys"]
[Mon Jul 20 07:05:42.467616 2026] [security2:error] [pid 45040:tid 45052] [remote 103.82.22.235:36790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4dJrEFnm79ltp0SFBLKwAAdQo"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:05:42.483991 2026] [security2:error] [pid 45040:tid 45288] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJrEFnm79ltp0SFBLGwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:42.494853 2026] [http2:warn] [pid 29744:tid 29907] [client 57.141.18.15:50058] h2_stream(29744-1019-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:42.524538 2026] [security2:error] [pid 28702:tid 28802] [remote 192.241.143.148:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4dJrF4957xPw9VVBnXEQAAwWI"]
[Mon Jul 20 07:05:42.687345 2026] [security2:error] [pid 28702:tid 28735] [remote 192.241.143.148:48490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4dJrF4957xPw9VVBnXEwAA-x8"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 07:05:42.769176 2026] [security2:error] [pid 45040:tid 45275] [client 14.225.17.146:50387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4dJrEFnm79ltp0SFBLLgAAAGc"], referer: http://talknutritionwithlesley.com/2023
[Mon Jul 20 07:05:42.782883 2026] [security2:error] [pid 28702:tid 28960] [client 98.159.234.160:20369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dJrF4957xPw9VVBnXFQAAAQQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:05:42.891146 2026] [security2:error] [pid 28702:tid 28922] [client 77.110.127.138:62817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dJrF4957xPw9VVBnXFwAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:42.891291 2026] [security2:error] [pid 28702:tid 28922] [client 77.110.127.138:62817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dJrF4957xPw9VVBnXFwAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:43.033982 2026] [access_compat:error] [pid 45040:tid 45230] [client 112.90.2.155:60423] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:05:43.125286 2026] [security2:error] [pid 45040:tid 45243] [client 194.61.41.67:31257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/alfa.php"] [unique_id "al4dJ7EFnm79ltp0SFBLWAAAAEc"]
[Mon Jul 20 07:05:43.285429 2026] [security2:error] [pid 45040:tid 45247] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJ7EFnm79ltp0SFBLWwAAS0E"]
[Mon Jul 20 07:05:43.287761 2026] [security2:error] [pid 45040:tid 45247] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJ7EFnm79ltp0SFBLWgAAS2A"]
[Mon Jul 20 07:05:43.288423 2026] [security2:error] [pid 45040:tid 45247] [client 34.75.50.82:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dJ7EFnm79ltp0SFBLXAAAS0Y"]
[Mon Jul 20 07:05:43.440106 2026] [security2:error] [pid 45040:tid 45277] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJ7EFnm79ltp0SFBLYwAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:43.467376 2026] [security2:error] [pid 45040:tid 45236] [client 114.119.130.57:33463] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/what-should-oil-paint-not-be-mixed-with/&sa=U"] [unique_id "al4dJ7EFnm79ltp0SFBLcgAAAEA"], referer: https://sustaintheart.com/what-should-oil-paint-not-be-mixed-with/&sa=U
[Mon Jul 20 07:05:43.786526 2026] [security2:error] [pid 45040:tid 45285] [client 192.236.168.43:50988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "algol.yungmedusa.com"] [uri "/"] [unique_id "al4dJ7EFnm79ltp0SFBLigAAAHE"]
[Mon Jul 20 07:05:43.820717 2026] [security2:error] [pid 45040:tid 45208] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJ7EFnm79ltp0SFBLfQAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:43.840867 2026] [http2:warn] [pid 29744:tid 29896] [client 57.141.18.20:54446] h2_stream(29744-1030-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:43.859157 2026] [security2:error] [pid 28702:tid 28899] [client 194.61.41.89:50643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/admin.php"] [unique_id "al4dJ7F4957xPw9VVBnXMwAAAMc"]
[Mon Jul 20 07:05:43.935226 2026] [security2:error] [pid 45040:tid 45256] [client 103.144.65.217:52318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dJ7EFnm79ltp0SFBLjwAAAFQ"]
[Mon Jul 20 07:05:43.935345 2026] [security2:error] [pid 45040:tid 45256] [client 103.144.65.217:52318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dJ7EFnm79ltp0SFBLjwAAAFQ"]
[Mon Jul 20 07:05:44.027419 2026] [security2:error] [pid 28702:tid 28862] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dJ7F4957xPw9VVBnXLQAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:44.210554 2026] [security2:error] [pid 45040:tid 45276] [client 147.93.171.187:50869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "al4dKLEFnm79ltp0SFBLlwAAAGg"], referer: binance.com
[Mon Jul 20 07:05:44.349522 2026] [core:error] [pid 45040:tid 45224] [client 14.225.17.146:63650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:44.349550 2026] [core:error] [pid 45040:tid 45224] [client 14.225.17.146:63650] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:05:44.354687 2026] [http2:warn] [pid 28702:tid 28883] [client 57.141.18.8:36382] h2_stream(28702-724-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:44.373453 2026] [http2:warn] [pid 28702:tid 28891] [client 57.141.18.19:32270] h2_stream(28702-932-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:44.491727 2026] [security2:error] [pid 45040:tid 45249] [client 14.225.17.146:49846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4dJ7EFnm79ltp0SFBLbQAAAE0"], referer: http://ravmike.com/2023
[Mon Jul 20 07:05:44.546234 2026] [security2:error] [pid 45040:tid 45244] [client 14.225.17.146:63706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4dKLEFnm79ltp0SFBLpgAAAEg"]
[Mon Jul 20 07:05:44.606437 2026] [security2:error] [pid 45040:tid 45297] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dKLEFnm79ltp0SFBLmwAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:44.643790 2026] [security2:error] [pid 28702:tid 28892] [client 194.61.41.105:35281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/click.php"] [unique_id "al4dKLF4957xPw9VVBnXUwAAAMA"]
[Mon Jul 20 07:05:44.831734 2026] [http2:warn] [pid 29744:tid 29887] [client 57.141.18.41:53046] h2_stream(29744-1038-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:45.043016 2026] [security2:error] [pid 45040:tid 45261] [client 77.110.127.138:62775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKbEFnm79ltp0SFBL0QAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:45.043103 2026] [security2:error] [pid 45040:tid 45261] [client 77.110.127.138:62775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKbEFnm79ltp0SFBL0QAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:45.114599 2026] [security2:error] [pid 28702:tid 28841] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dKLF4957xPw9VVBnXVAAAAI0"]
[Mon Jul 20 07:05:45.116108 2026] [access_compat:error] [pid 45040:tid 45223] [client 112.90.14.103:48493] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:05:45.411352 2026] [security2:error] [pid 45040:tid 45185] [client 14.225.17.146:53753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4dKbEFnm79ltp0SFBL5gAAAA0"], referer: https://ravmike.com/2023
[Mon Jul 20 07:05:45.431831 2026] [security2:error] [pid 28702:tid 28935] [client 194.61.41.250:45715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/wp-conflg.php"] [unique_id "al4dKbF4957xPw9VVBnXXAAAAOs"]
[Mon Jul 20 07:05:45.502215 2026] [security2:error] [pid 45040:tid 45179] [client 183.82.98.154:63311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dKbEFnm79ltp0SFBL9gAAAAc"]
[Mon Jul 20 07:05:45.502316 2026] [security2:error] [pid 45040:tid 45179] [client 183.82.98.154:63311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dKbEFnm79ltp0SFBL9gAAAAc"]
[Mon Jul 20 07:05:45.581835 2026] [security2:error] [pid 45040:tid 45232] [client 77.110.127.138:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKbEFnm79ltp0SFBL-QAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:45.581932 2026] [security2:error] [pid 45040:tid 45232] [client 77.110.127.138:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKbEFnm79ltp0SFBL-QAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:45.676351 2026] [security2:error] [pid 28702:tid 28899] [client 192.140.149.97:46010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dKbF4957xPw9VVBnXZAAAAMc"]
[Mon Jul 20 07:05:45.676492 2026] [security2:error] [pid 28702:tid 28899] [client 192.140.149.97:46010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dKbF4957xPw9VVBnXZAAAAMc"]
[Mon Jul 20 07:05:45.787145 2026] [security2:error] [pid 45040:tid 45096] [remote 154.66.198.148:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4dKbEFnm79ltp0SFBMCgAAYDU"]
[Mon Jul 20 07:05:45.795638 2026] [security2:error] [pid 45040:tid 45267] [client 14.225.17.146:55018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4dKbEFnm79ltp0SFBL-wAAAF8"], referer: http://kromosenergy.com/2023
[Mon Jul 20 07:05:45.797154 2026] [security2:error] [pid 28702:tid 28790] [remote 57.141.18.4:28656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4dKbF4957xPw9VVBnXbAAA1lY"]
[Mon Jul 20 07:05:45.859905 2026] [security2:error] [pid 45040:tid 45140] [remote 100.42.189.89:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dKbEFnm79ltp0SFBMDQAAI2E"]
[Mon Jul 20 07:05:45.899949 2026] [http2:warn] [pid 29744:tid 29891] [client 57.141.18.60:30554] h2_stream(29744-1045-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:45.931288 2026] [security2:error] [pid 45040:tid 45285] [client 104.234.53.94:36339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dKbEFnm79ltp0SFBMFQAAAHE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:45.940644 2026] [http2:warn] [pid 29744:tid 29898] [client 57.141.18.78:57632] h2_stream(29744-1046-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:45.986077 2026] [security2:error] [pid 45040:tid 45197] [client 77.110.127.138:62773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKbEFnm79ltp0SFBMHAAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:45.986167 2026] [security2:error] [pid 45040:tid 45197] [client 77.110.127.138:62773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKbEFnm79ltp0SFBMHAAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:46.014829 2026] [security2:error] [pid 45040:tid 45173] [client 14.225.17.146:55014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4dKbEFnm79ltp0SFBMFwAAAAE"], referer: http://friendlyspreadsheet.com/2023
[Mon Jul 20 07:05:46.038483 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:62860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKrEFnm79ltp0SFBMIQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:46.038609 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:62860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKrEFnm79ltp0SFBMIQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:46.041998 2026] [security2:error] [pid 45040:tid 45169] [remote 100.42.189.89:45156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dKrEFnm79ltp0SFBMJAAAWH4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:05:46.130556 2026] [security2:error] [pid 45040:tid 45224] [client 117.247.108.24:52209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dKrEFnm79ltp0SFBMLwAAADQ"]
[Mon Jul 20 07:05:46.130660 2026] [security2:error] [pid 45040:tid 45224] [client 117.247.108.24:52209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dKrEFnm79ltp0SFBMLwAAADQ"]
[Mon Jul 20 07:05:46.139603 2026] [security2:error] [pid 45040:tid 45249] [client 138.197.209.165:54965] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.goodtravelfun.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4dKrEFnm79ltp0SFBMJQAAAE0"]
[Mon Jul 20 07:05:46.156373 2026] [security2:error] [pid 45040:tid 45185] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dKbEFnm79ltp0SFBMFgAAAA0"]
[Mon Jul 20 07:05:46.160731 2026] [security2:error] [pid 45040:tid 45294] [client 194.61.41.63:51003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/atomlib.php"] [unique_id "al4dKrEFnm79ltp0SFBMMAAAAHo"]
[Mon Jul 20 07:05:46.190897 2026] [security2:error] [pid 45040:tid 45192] [client 77.110.127.138:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKrEFnm79ltp0SFBMMQAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:46.191018 2026] [security2:error] [pid 45040:tid 45192] [client 77.110.127.138:62912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKrEFnm79ltp0SFBMMQAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:46.290397 2026] [security2:error] [pid 45040:tid 45273] [client 147.93.171.187:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.171.93.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cira.org"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "al4dKrEFnm79ltp0SFBMNwAAAGU"], referer: binance.com
[Mon Jul 20 07:05:46.539885 2026] [security2:error] [pid 45040:tid 45130] [remote 154.66.198.148:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4dKrEFnm79ltp0SFBMQAAAS1c"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 07:05:46.563248 2026] [http2:warn] [pid 28702:tid 28874] [client 57.141.18.52:57444] h2_stream(28702-1136-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:46.675836 2026] [http2:warn] [pid 28702:tid 28916] [client 57.141.18.59:49206] h2_stream(28702-731-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:46.851430 2026] [security2:error] [pid 28702:tid 28803] [remote 57.141.18.76:27202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4dKrF4957xPw9VVBnXiwAA_mM"]
[Mon Jul 20 07:05:46.865162 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKrEFnm79ltp0SFBMWQAAADE"]
[Mon Jul 20 07:05:46.865277 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dKrEFnm79ltp0SFBMWQAAADE"]
[Mon Jul 20 07:05:46.921613 2026] [security2:error] [pid 45040:tid 45184] [client 194.61.41.67:23617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/bypass.php"] [unique_id "al4dKrEFnm79ltp0SFBMXQAAAAw"]
[Mon Jul 20 07:05:46.925522 2026] [security2:error] [pid 28702:tid 28923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dKrF4957xPw9VVBnXgQAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:47.214025 2026] [security2:error] [pid 45040:tid 45256] [client 77.110.127.138:62818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dK7EFnm79ltp0SFBMdwAAAFQ"]
[Mon Jul 20 07:05:47.214131 2026] [security2:error] [pid 45040:tid 45256] [client 77.110.127.138:62818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dK7EFnm79ltp0SFBMdwAAAFQ"]
[Mon Jul 20 07:05:47.274282 2026] [security2:error] [pid 45040:tid 45055] [remote 173.249.4.11:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMfAAAbw0"]
[Mon Jul 20 07:05:47.309864 2026] [security2:error] [pid 45040:tid 45052] [remote 5.252.52.249:47566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMgAAADwo"]
[Mon Jul 20 07:05:47.315405 2026] [http2:warn] [pid 29744:tid 29997] [client 57.141.18.39:22361] h2_stream(29744-1053-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:47.408369 2026] [security2:error] [pid 45040:tid 45074] [remote 20.173.88.122:38058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMjAAAXR8"]
[Mon Jul 20 07:05:47.442141 2026] [security2:error] [pid 28702:tid 28908] [client 46.4.220.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/index.php"] [unique_id "al4dKrF4957xPw9VVBnXgwAAANA"]
[Mon Jul 20 07:05:47.483274 2026] [security2:error] [pid 45040:tid 45085] [remote 173.249.4.11:14811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMkgAAIio"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:05:47.562134 2026] [security2:error] [pid 45040:tid 45060] [remote 5.252.52.249:47566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMmwAAJBI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:05:47.590842 2026] [security2:error] [pid 45040:tid 45254] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dK7EFnm79ltp0SFBMhgAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:47.652577 2026] [security2:error] [pid 45040:tid 45285] [client 194.61.41.89:29111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/random_compat/chosen.php"] [unique_id "al4dK7EFnm79ltp0SFBMogAAAHE"]
[Mon Jul 20 07:05:47.740040 2026] [security2:error] [pid 45040:tid 45136] [remote 57.141.18.60:45816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6279416"] [unique_id "al4dK7EFnm79ltp0SFBMpwAAIV0"]
[Mon Jul 20 07:05:47.763011 2026] [security2:error] [pid 45040:tid 45108] [remote 20.173.88.122:38058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "get.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMqwAAeUE"], referer: https://get.learnthissecret.com/wp-login.php
[Mon Jul 20 07:05:47.896214 2026] [http2:warn] [pid 29744:tid 29988] [client 57.141.18.72:54872] h2_stream(29744-1060-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:47.966347 2026] [security2:error] [pid 45040:tid 45093] [remote 173.249.4.11:34318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dK7EFnm79ltp0SFBMtgAAYjI"]
[Mon Jul 20 07:05:48.168633 2026] [security2:error] [pid 45040:tid 45059] [remote 173.249.4.11:34318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dLLEFnm79ltp0SFBMxgAAZhE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:05:48.314600 2026] [security2:error] [pid 28702:tid 28836] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dK7F4957xPw9VVBnXnwAAAIg"], referer: 1'"3000
[Mon Jul 20 07:05:48.387968 2026] [security2:error] [pid 45040:tid 45061] [remote 100.42.189.89:45198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dLLEFnm79ltp0SFBM2QAAdBM"]
[Mon Jul 20 07:05:48.415994 2026] [security2:error] [pid 45040:tid 45282] [client 194.61.41.88:62523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/index.php"] [unique_id "al4dLLEFnm79ltp0SFBM2gAAAG4"]
[Mon Jul 20 07:05:48.445010 2026] [security2:error] [pid 28702:tid 28911] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dK7F4957xPw9VVBnXqgAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:48.496260 2026] [security2:error] [pid 28702:tid 28889] [client 77.110.127.138:62909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dLLF4957xPw9VVBnXtgAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:48.496378 2026] [security2:error] [pid 28702:tid 28889] [client 77.110.127.138:62909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dLLF4957xPw9VVBnXtgAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:48.589358 2026] [security2:error] [pid 45040:tid 45083] [remote 124.55.178.99:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dLLEFnm79ltp0SFBM6wAAXig"]
[Mon Jul 20 07:05:48.592580 2026] [http2:warn] [pid 29744:tid 29969] [client 57.141.18.47:60104] h2_stream(29744-1063-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:48.593003 2026] [security2:error] [pid 28702:tid 28856] [client 14.225.17.146:63409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4dLLF4957xPw9VVBnXswAAAJw"], referer: http://dnsplumbing.com/2023
[Mon Jul 20 07:05:48.596626 2026] [security2:error] [pid 45040:tid 45254] [client 14.225.17.146:55104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4dLLEFnm79ltp0SFBM4gAAAFI"], referer: http://39ishlife.com/2023
[Mon Jul 20 07:05:48.607674 2026] [security2:error] [pid 45040:tid 45105] [remote 100.42.189.89:45198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dLLEFnm79ltp0SFBM7AAAZj4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:05:48.702699 2026] [security2:error] [pid 45040:tid 45181] [client 14.182.195.220:52526] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dLLEFnm79ltp0SFBM_gAAAAk"]
[Mon Jul 20 07:05:48.705957 2026] [security2:error] [pid 45040:tid 45199] [client 14.182.195.220:52527] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dLLEFnm79ltp0SFBM_wAAABs"]
[Mon Jul 20 07:05:48.738656 2026] [security2:error] [pid 28702:tid 28857] [client 14.182.195.220:52525] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dLLF4957xPw9VVBnXwQAAAJ0"]
[Mon Jul 20 07:05:48.830208 2026] [http2:warn] [pid 29744:tid 29947] [client 57.141.18.121:40990] h2_stream(29744-1065-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:48.878971 2026] [security2:error] [pid 45040:tid 45230] [client 46.4.220.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/index.php"] [unique_id "al4dLLEFnm79ltp0SFBM5gAAADo"]
[Mon Jul 20 07:05:48.907473 2026] [security2:error] [pid 45040:tid 45291] [client 14.225.17.146:64274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4dLLEFnm79ltp0SFBMuQAAAHc"]
[Mon Jul 20 07:05:48.937731 2026] [security2:error] [pid 28702:tid 28859] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dLLF4957xPw9VVBnXvwAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:48.964803 2026] [security2:error] [pid 45040:tid 45212] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dLLEFnm79ltp0SFBM-gAAACg"], referer: 1'"3000
[Mon Jul 20 07:05:48.967390 2026] [security2:error] [pid 45040:tid 45260] [client 45.3.42.0:36509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dLLEFnm79ltp0SFBNEgAAAFg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:49.011839 2026] [http2:warn] [pid 29744:tid 29972] [client 57.141.18.55:44778] h2_stream(29744-1066-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:49.012932 2026] [security2:error] [pid 28702:tid 28848] [client 77.110.127.138:62929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dLLF4957xPw9VVBnXvQAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:49.025057 2026] [security2:error] [pid 45040:tid 45063] [remote 124.55.178.99:55670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dLbEFnm79ltp0SFBNGAAAYRU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:05:49.158186 2026] [security2:error] [pid 45040:tid 45194] [client 194.61.41.55:35629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/edit.php"] [unique_id "al4dLbEFnm79ltp0SFBNLgAAABY"]
[Mon Jul 20 07:05:49.533651 2026] [security2:error] [pid 45040:tid 45276] [client 104.207.53.124:35969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dLbEFnm79ltp0SFBNQwAAAGg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:49.624428 2026] [security2:error] [pid 45040:tid 45221] [client 14.225.17.146:64335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4dLLEFnm79ltp0SFBNCgAAADE"], referer: http://idigress.studio/2023
[Mon Jul 20 07:05:49.900778 2026] [security2:error] [pid 45040:tid 45253] [client 187.16.64.216:62677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dLbEFnm79ltp0SFBNXwAAAFE"]
[Mon Jul 20 07:05:49.900948 2026] [security2:error] [pid 45040:tid 45253] [client 187.16.64.216:62677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dLbEFnm79ltp0SFBNXwAAAFE"]
[Mon Jul 20 07:05:49.948575 2026] [security2:error] [pid 45040:tid 45208] [client 194.61.41.65:54469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/WordPressCore/index.php"] [unique_id "al4dLbEFnm79ltp0SFBNYwAAACQ"]
[Mon Jul 20 07:05:50.035732 2026] [security2:error] [pid 45040:tid 45268] [client 14.225.17.146:63414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4dLbEFnm79ltp0SFBNWgAAAGA"], referer: http://windowtx.com/2023
[Mon Jul 20 07:05:50.055660 2026] [security2:error] [pid 45040:tid 45225] [client 14.225.17.146:56838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dLbEFnm79ltp0SFBNVwAAADU"], referer: http://adastra.love/2023
[Mon Jul 20 07:05:50.066636 2026] [security2:error] [pid 45040:tid 45097] [remote 162.19.86.63:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4dLrEFnm79ltp0SFBNagAALjY"]
[Mon Jul 20 07:05:50.100339 2026] [security2:error] [pid 28702:tid 28837] [client 14.225.17.146:63478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4dLbF4957xPw9VVBnX1wAAAIk"], referer: http://carolinapressurewashers.com/2023
[Mon Jul 20 07:05:50.130021 2026] [http2:warn] [pid 29744:tid 29879] [client 57.141.18.101:21698] h2_stream(29744-1073-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:50.191004 2026] [security2:error] [pid 45040:tid 45263] [client 104.234.53.50:65501] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dLrEFnm79ltp0SFBNaQAAAFs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:50.203275 2026] [security2:error] [pid 45040:tid 45279] [client 46.4.220.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4dLbEFnm79ltp0SFBNUAAAAGs"]
[Mon Jul 20 07:05:50.310316 2026] [security2:error] [pid 45040:tid 45150] [remote 162.19.86.63:44068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4dLrEFnm79ltp0SFBNfgAASWs"], referer: https://adambergeron.com/wp-login.php
[Mon Jul 20 07:05:50.443381 2026] [security2:error] [pid 45040:tid 45255] [client 104.168.114.154:38140] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.undefeatedthe.com"] [uri "/"] [unique_id "al4dLrEFnm79ltp0SFBNjAAAAFM"]
[Mon Jul 20 07:05:50.471191 2026] [security2:error] [pid 45040:tid 45285] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dLrEFnm79ltp0SFBNeQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:50.473390 2026] [security2:error] [pid 28702:tid 28866] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dLrF4957xPw9VVBnX4AAAAKY"], referer: 1'"3000
[Mon Jul 20 07:05:50.615686 2026] [security2:error] [pid 29744:tid 29755] [remote 57.141.18.75:50278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cVuGINCUUz5GA9YIxSAACewk"]
[Mon Jul 20 07:05:50.657398 2026] [security2:error] [pid 28702:tid 28946] [client 77.110.127.138:62807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dLrF4957xPw9VVBnX7wAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:50.657553 2026] [security2:error] [pid 28702:tid 28946] [client 77.110.127.138:62807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dLrF4957xPw9VVBnX7wAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:50.698638 2026] [http2:warn] [pid 29744:tid 29895] [client 57.141.18.92:61670] h2_stream(29744-1078-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:50.721597 2026] [security2:error] [pid 45040:tid 45271] [client 104.234.53.50:65501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dLrEFnm79ltp0SFBNnAAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:50.747542 2026] [security2:error] [pid 45040:tid 45296] [client 194.61.41.106:22675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cgi-bin/autoload_classmap.php"] [unique_id "al4dLrEFnm79ltp0SFBNoAAAAHw"]
[Mon Jul 20 07:05:50.768766 2026] [http2:warn] [pid 28702:tid 28895] [client 57.141.18.70:63122] h2_stream(28702-751-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:51.301194 2026] [security2:error] [pid 45040:tid 45235] [client 77.110.127.138:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBNyQAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.301354 2026] [security2:error] [pid 45040:tid 45235] [client 77.110.127.138:62921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBNyQAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.405127 2026] [security2:error] [pid 45040:tid 45088] [remote 182.77.62.24:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dL7EFnm79ltp0SFBNzwAAdi0"]
[Mon Jul 20 07:05:51.457496 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBN2AAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.457624 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBN2AAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.466037 2026] [security2:error] [pid 45040:tid 45250] [client 14.225.17.146:55789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4dL7EFnm79ltp0SFBNzQAAAE4"], referer: http://uritems.net/2023
[Mon Jul 20 07:05:51.467219 2026] [http2:warn] [pid 28702:tid 28875] [client 57.141.18.93:49278] h2_stream(28702-752-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:51.532997 2026] [security2:error] [pid 28702:tid 28888] [client 194.61.41.82:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-links-opml.php"] [unique_id "al4dL7F4957xPw9VVBnYAgAAALw"]
[Mon Jul 20 07:05:51.567867 2026] [security2:error] [pid 45040:tid 45263] [client 45.157.112.60:35177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dL7EFnm79ltp0SFBN3QAAAFs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:05:51.583282 2026] [security2:error] [pid 28702:tid 28951] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dL7F4957xPw9VVBnX_gAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.605120 2026] [security2:error] [pid 45040:tid 45299] [client 201.27.111.74:52038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dL7EFnm79ltp0SFBN3wAAAH8"]
[Mon Jul 20 07:05:51.605287 2026] [security2:error] [pid 45040:tid 45299] [client 201.27.111.74:52038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dL7EFnm79ltp0SFBN3wAAAH8"]
[Mon Jul 20 07:05:51.619013 2026] [security2:error] [pid 45040:tid 45193] [client 77.110.127.138:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBN4AAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.619141 2026] [security2:error] [pid 45040:tid 45193] [client 77.110.127.138:62925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBN4AAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.728763 2026] [security2:error] [pid 45040:tid 45174] [client 111.225.214.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4dL7EFnm79ltp0SFBN3AAAAAI"]
[Mon Jul 20 07:05:51.769720 2026] [security2:error] [pid 45040:tid 45268] [client 77.110.127.138:62952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBN7gAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.769834 2026] [security2:error] [pid 45040:tid 45268] [client 77.110.127.138:62952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dL7EFnm79ltp0SFBN7gAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:51.903727 2026] [security2:error] [pid 45040:tid 45085] [remote 182.77.62.24:39906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dL7EFnm79ltp0SFBN-AAAcCo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:05:52.030049 2026] [security2:error] [pid 45040:tid 45199] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dL7EFnm79ltp0SFBN8AAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:52.107437 2026] [security2:error] [pid 45040:tid 45187] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dL7EFnm79ltp0SFBN9wAAAA8"], referer: 1'"3000
[Mon Jul 20 07:05:52.129322 2026] [security2:error] [pid 45040:tid 45183] [client 77.110.127.138:62910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dMLEFnm79ltp0SFBOCgAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:52.129478 2026] [security2:error] [pid 45040:tid 45183] [client 77.110.127.138:62910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dMLEFnm79ltp0SFBOCgAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:52.297218 2026] [http2:warn] [pid 45040:tid 45210] [client 57.141.18.53:35558] h2_stream(45040-338-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:52.307350 2026] [security2:error] [pid 45040:tid 45205] [client 77.110.127.138:62960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dMLEFnm79ltp0SFBOHAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:52.307467 2026] [security2:error] [pid 45040:tid 45205] [client 77.110.127.138:62960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dMLEFnm79ltp0SFBOHAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:52.347289 2026] [security2:error] [pid 45040:tid 45284] [client 194.61.41.247:33003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/user/network.php"] [unique_id "al4dMLEFnm79ltp0SFBOIAAAAHA"]
[Mon Jul 20 07:05:52.387046 2026] [http2:warn] [pid 28702:tid 28921] [client 57.141.18.26:43408] h2_stream(28702-755-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:52.529262 2026] [security2:error] [pid 45040:tid 45289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dMLEFnm79ltp0SFBOFQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:52.611946 2026] [http2:warn] [pid 28702:tid 28849] [client 57.141.18.120:35522] h2_stream(28702-757-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:52.617571 2026] [security2:error] [pid 45040:tid 45279] [client 14.225.17.146:55619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4dLrEFnm79ltp0SFBNsgAAAGs"], referer: http://amalia-capital.com/2023
[Mon Jul 20 07:05:52.782694 2026] [security2:error] [pid 45040:tid 45192] [client 192.236.168.43:53060] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "iwc.nmy.mybluehost.me"] [uri "/"] [unique_id "al4dMLEFnm79ltp0SFBOQAAAABQ"]
[Mon Jul 20 07:05:52.796365 2026] [security2:error] [pid 29744:tid 29771] [remote 57.141.18.95:21990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cV-GINCUUz5GA9YIxYwACgRk"]
[Mon Jul 20 07:05:52.800124 2026] [security2:error] [pid 45040:tid 45262] [client 146.103.115.115:53355] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.115.115" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4dMLEFnm79ltp0SFBOQQAAAFo"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 07:05:52.800223 2026] [security2:error] [pid 45040:tid 45262] [client 146.103.115.115:53355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4dMLEFnm79ltp0SFBOQQAAAFo"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 07:05:52.809852 2026] [security2:error] [pid 45040:tid 45112] [remote 84.247.172.23:47468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4dMLEFnm79ltp0SFBOQgAAT0U"]
[Mon Jul 20 07:05:52.943404 2026] [security2:error] [pid 45040:tid 45297] [client 154.208.48.130:57659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dMLEFnm79ltp0SFBOSAAAAH0"]
[Mon Jul 20 07:05:52.943556 2026] [security2:error] [pid 45040:tid 45297] [client 154.208.48.130:57659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dMLEFnm79ltp0SFBOSAAAAH0"]
[Mon Jul 20 07:05:52.978838 2026] [security2:error] [pid 45040:tid 45276] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dMLEFnm79ltp0SFBOPQAAAGg"], referer: 1'"3000
[Mon Jul 20 07:05:53.145860 2026] [security2:error] [pid 28702:tid 28906] [client 194.61.41.85:33021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/atomlib.php"] [unique_id "al4dMbF4957xPw9VVBnYIQAAAM4"]
[Mon Jul 20 07:05:53.184324 2026] [security2:error] [pid 45040:tid 45257] [client 14.225.17.146:63432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4dL7EFnm79ltp0SFBN1wAAAFU"], referer: http://thesoloceos.com/2023
[Mon Jul 20 07:05:53.563040 2026] [security2:error] [pid 45040:tid 45211] [client 122.183.32.225:18378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dMbEFnm79ltp0SFBObwAAACc"]
[Mon Jul 20 07:05:53.572570 2026] [security2:error] [pid 45040:tid 45211] [client 122.183.32.225:18378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dMbEFnm79ltp0SFBObwAAACc"]
[Mon Jul 20 07:05:53.596068 2026] [security2:error] [pid 28702:tid 28802] [remote 91.142.222.105:40644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4dMbF4957xPw9VVBnYMgAAs2I"]
[Mon Jul 20 07:05:53.848828 2026] [security2:error] [pid 28702:tid 28735] [remote 91.142.222.105:40644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4dMbF4957xPw9VVBnYNwAA-h8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:05:53.923620 2026] [security2:error] [pid 45040:tid 45185] [client 194.61.41.55:42051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/jquery/bypass.php"] [unique_id "al4dMbEFnm79ltp0SFBOiQAAAA0"]
[Mon Jul 20 07:05:53.948085 2026] [security2:error] [pid 45040:tid 45138] [remote 84.247.172.23:47468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4dMbEFnm79ltp0SFBOjQAATl8"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 07:05:53.963957 2026] [http2:warn] [pid 29744:tid 29953] [client 57.141.18.72:54886] h2_stream(29744-1098-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:54.106772 2026] [http2:warn] [pid 29744:tid 29880] [client 57.141.18.81:28130] h2_stream(29744-1099-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:54.356953 2026] [security2:error] [pid 45040:tid 45265] [client 14.225.17.146:55518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4dMbEFnm79ltp0SFBOjAAAAF0"], referer: http://overloadcomedy.com/2023
[Mon Jul 20 07:05:54.455457 2026] [security2:error] [pid 45040:tid 45208] [client 14.225.17.146:64315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4dL7EFnm79ltp0SFBOAwAAACQ"], referer: http://hilltopnurseryinc.com/2023
[Mon Jul 20 07:05:54.514028 2026] [security2:error] [pid 45040:tid 45217] [client 103.144.65.217:52775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dMrEFnm79ltp0SFBOsQAAAC0"]
[Mon Jul 20 07:05:54.514158 2026] [security2:error] [pid 45040:tid 45217] [client 103.144.65.217:52775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dMrEFnm79ltp0SFBOsQAAAC0"]
[Mon Jul 20 07:05:54.646662 2026] [security2:error] [pid 45040:tid 45268] [client 194.61.41.56:22983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/xl2023.php"] [unique_id "al4dMrEFnm79ltp0SFBOwAAAAGA"]
[Mon Jul 20 07:05:54.890634 2026] [http2:warn] [pid 28702:tid 28850] [client 57.141.18.72:54896] h2_stream(28702-764-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:54.900257 2026] [http2:warn] [pid 29744:tid 29913] [client 57.141.18.80:44724] h2_stream(29744-1106-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:55.075666 2026] [security2:error] [pid 45040:tid 45099] [remote 188.40.28.4:44282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dM7EFnm79ltp0SFBO0QAAJzg"]
[Mon Jul 20 07:05:55.076213 2026] [security2:error] [pid 45040:tid 45211] [client 188.40.28.4:44282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dM7EFnm79ltp0SFBO0QAAJzg"]
[Mon Jul 20 07:05:55.109174 2026] [security2:error] [pid 45040:tid 45262] [client 113.160.132.26:5874] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 26.132.160.113.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4dM7EFnm79ltp0SFBO1AAAAFo"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 07:05:55.109294 2026] [security2:error] [pid 45040:tid 45262] [client 113.160.132.26:5874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.guidehunting.com"] [uri "/wp-comments-post.php"] [unique_id "al4dM7EFnm79ltp0SFBO1AAAAFo"], referer: https://www.guidehunting.com/guide-school-and-training-in-washington/
[Mon Jul 20 07:05:55.415014 2026] [security2:error] [pid 45040:tid 45275] [client 194.61.41.107:21207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/admin.php"] [unique_id "al4dM7EFnm79ltp0SFBO6gAAAGc"]
[Mon Jul 20 07:05:55.475102 2026] [security2:error] [pid 45040:tid 45230] [client 77.110.127.138:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dM7EFnm79ltp0SFBO8gAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:55.475212 2026] [security2:error] [pid 45040:tid 45230] [client 77.110.127.138:62951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dM7EFnm79ltp0SFBO8gAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:55.526021 2026] [security2:error] [pid 45040:tid 45294] [client 77.110.127.138:62946] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/if(now()=sysdate(),sleep(15),0)/21/"] [unique_id "al4dM7EFnm79ltp0SFBO9wAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:55.941243 2026] [security2:error] [pid 45040:tid 45289] [client 183.82.98.154:63852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dM7EFnm79ltp0SFBPGwAAAHU"]
[Mon Jul 20 07:05:55.941389 2026] [security2:error] [pid 45040:tid 45289] [client 183.82.98.154:63852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dM7EFnm79ltp0SFBPGwAAAHU"]
[Mon Jul 20 07:05:56.085985 2026] [security2:error] [pid 45040:tid 45070] [remote 15.206.251.117:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dNLEFnm79ltp0SFBPIAAAcRs"]
[Mon Jul 20 07:05:56.115992 2026] [security2:error] [pid 45040:tid 45181] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dM7EFnm79ltp0SFBPDwAAAAk"], referer: 1'"3000
[Mon Jul 20 07:05:56.142866 2026] [security2:error] [pid 45040:tid 45250] [client 194.61.41.102:54639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/media/dog.php"] [unique_id "al4dNLEFnm79ltp0SFBPKQAAAE4"]
[Mon Jul 20 07:05:56.522096 2026] [http2:warn] [pid 29744:tid 29941] [client 57.141.18.29:46708] h2_stream(29744-1115-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:56.619735 2026] [security2:error] [pid 45040:tid 45067] [remote 57.141.18.51:23318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4dNLEFnm79ltp0SFBPUwAAbhg"]
[Mon Jul 20 07:05:56.670797 2026] [security2:error] [pid 45040:tid 45043] [remote 15.206.251.117:48772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dNLEFnm79ltp0SFBPWgAAGgI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:05:56.795133 2026] [security2:error] [pid 45040:tid 45181] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dNLEFnm79ltp0SFBPTgAAAAk"], referer: 1'"3000
[Mon Jul 20 07:05:56.811069 2026] [security2:error] [pid 45040:tid 45060] [remote 152.228.213.32:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dNLEFnm79ltp0SFBPaQAAdxI"]
[Mon Jul 20 07:05:56.811230 2026] [security2:error] [pid 45040:tid 45291] [client 152.228.213.32:53410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dNLEFnm79ltp0SFBPaQAAdxI"]
[Mon Jul 20 07:05:56.818960 2026] [security2:error] [pid 45040:tid 45206] [client 14.225.17.146:55360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4dNLEFnm79ltp0SFBPWwAAACI"], referer: http://alaraycreative.com/2023
[Mon Jul 20 07:05:56.919991 2026] [security2:error] [pid 45040:tid 45219] [client 194.61.41.58:59497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/xp.php"] [unique_id "al4dNLEFnm79ltp0SFBPcQAAAC8"]
[Mon Jul 20 07:05:57.010599 2026] [security2:error] [pid 45040:tid 45218] [client 117.247.108.24:52834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dNbEFnm79ltp0SFBPewAAAC4"]
[Mon Jul 20 07:05:57.010766 2026] [security2:error] [pid 45040:tid 45218] [client 117.247.108.24:52834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dNbEFnm79ltp0SFBPewAAAC4"]
[Mon Jul 20 07:05:57.017940 2026] [http2:warn] [pid 28702:tid 28910] [client 57.141.18.93:49294] h2_stream(28702-773-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:57.018666 2026] [http2:warn] [pid 28702:tid 28919] [client 57.141.18.102:40298] h2_stream(28702-774-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:57.544065 2026] [security2:error] [pid 45040:tid 45138] [remote 5.161.225.162:55008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4dNbEFnm79ltp0SFBPugAAdV8"]
[Mon Jul 20 07:05:57.563563 2026] [security2:error] [pid 45040:tid 45110] [remote 5.252.52.249:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dNbEFnm79ltp0SFBPvgAAB0M"]
[Mon Jul 20 07:05:57.604022 2026] [http2:warn] [pid 29744:tid 29996] [client 57.141.18.102:40302] h2_stream(29744-1125-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:57.643603 2026] [security2:error] [pid 45040:tid 45299] [client 194.61.41.64:28303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/applicationd.php"] [unique_id "al4dNbEFnm79ltp0SFBPwgAAAH8"]
[Mon Jul 20 07:05:57.693412 2026] [security2:error] [pid 45040:tid 45256] [client 66.249.65.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.laceycaraccident.com"] [uri "/index.php"] [unique_id "al4dNLEFnm79ltp0SFBPJgAAAFQ"]
[Mon Jul 20 07:05:57.726212 2026] [security2:error] [pid 45040:tid 45277] [client 147.93.171.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4dNLEFnm79ltp0SFBPRQAAAGk"], referer: binance.com
[Mon Jul 20 07:05:57.763650 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dNbEFnm79ltp0SFBP1AAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:57.763737 2026] [security2:error] [pid 45040:tid 45194] [client 77.110.127.138:62989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dNbEFnm79ltp0SFBP1AAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:57.779245 2026] [security2:error] [pid 45040:tid 45095] [remote 5.252.52.249:59660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dNbEFnm79ltp0SFBP2wAALzQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:05:57.914791 2026] [http2:warn] [pid 29744:tid 29904] [client 57.141.18.45:55108] h2_stream(29744-1127-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:57.948818 2026] [security2:error] [pid 45040:tid 45100] [remote 5.161.225.162:55008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4dNbEFnm79ltp0SFBP7gAAczk"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 07:05:57.967442 2026] [security2:error] [pid 45040:tid 45262] [client 77.110.127.138:62991] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/21/"] [unique_id "al4dNbEFnm79ltp0SFBP8gAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:05:57.971067 2026] [security2:error] [pid 45040:tid 45209] [client 13.233.207.33:56008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dNbEFnm79ltp0SFBP7wAAACU"]
[Mon Jul 20 07:05:58.126489 2026] [security2:error] [pid 45040:tid 45251] [client 50.116.65.227:12638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dNrEFnm79ltp0SFBQFQAAAE8"]
[Mon Jul 20 07:05:58.135135 2026] [security2:error] [pid 45040:tid 45204] [client 50.116.65.227:12642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dNrEFnm79ltp0SFBQFgAAACA"]
[Mon Jul 20 07:05:58.253344 2026] [http2:warn] [pid 28702:tid 28852] [client 57.141.18.91:49702] h2_stream(28702-779-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:58.452342 2026] [security2:error] [pid 45040:tid 45291] [client 194.61.41.81:20905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/index.php"] [unique_id "al4dNrEFnm79ltp0SFBQMQAAAHc"]
[Mon Jul 20 07:05:58.477471 2026] [security2:error] [pid 45040:tid 45249] [client 104.234.53.60:60355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dNrEFnm79ltp0SFBQMgAAAE0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:05:58.538866 2026] [security2:error] [pid 45040:tid 45245] [client 14.225.17.146:53349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4dNrEFnm79ltp0SFBQNQAAAEk"], referer: http://thefriendlyspreadsheet.com/2023
[Mon Jul 20 07:05:58.565676 2026] [http2:warn] [pid 45040:tid 45281] [client 57.141.18.58:22764] h2_stream(45040-7-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:58.577000 2026] [security2:error] [pid 45040:tid 45088] [remote 72.167.132.114:37208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4dNrEFnm79ltp0SFBQPgAAeS0"]
[Mon Jul 20 07:05:58.647647 2026] [security2:error] [pid 45040:tid 45193] [client 14.225.17.146:54953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4dNrEFnm79ltp0SFBQNAAAABU"]
[Mon Jul 20 07:05:58.707448 2026] [security2:error] [pid 45040:tid 45211] [client 50.116.65.227:12670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dNrEFnm79ltp0SFBQNgAAACc"]
[Mon Jul 20 07:05:58.795703 2026] [security2:error] [pid 45040:tid 45132] [remote 72.167.132.114:37208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4dNrEFnm79ltp0SFBQUgAAZ1k"], referer: https://north-woods-engineering.com/wp-login.php
[Mon Jul 20 07:05:58.881994 2026] [http2:warn] [pid 28702:tid 28898] [client 57.141.18.96:48208] h2_stream(28702-781-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:58.907222 2026] [security2:error] [pid 45040:tid 45218] [client 50.116.65.227:12672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dNrEFnm79ltp0SFBQSwAAAC4"]
[Mon Jul 20 07:05:59.118842 2026] [security2:error] [pid 45040:tid 45220] [client 43.205.139.3:27134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dN7EFnm79ltp0SFBQcAAAADA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:05:59.122364 2026] [security2:error] [pid 45040:tid 45260] [client 65.111.22.128:10539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dN7EFnm79ltp0SFBQcQAAAFg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:59.229319 2026] [security2:error] [pid 45040:tid 45261] [client 194.61.41.69:43991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-links.php"] [unique_id "al4dN7EFnm79ltp0SFBQeQAAAFk"]
[Mon Jul 20 07:05:59.352224 2026] [security2:error] [pid 45040:tid 45264] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dN7EFnm79ltp0SFBQaQAAAFw"]
[Mon Jul 20 07:05:59.377762 2026] [security2:error] [pid 45040:tid 45146] [remote 152.228.213.32:53426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dN7EFnm79ltp0SFBQigAAOmc"]
[Mon Jul 20 07:05:59.378070 2026] [security2:error] [pid 45040:tid 45230] [client 152.228.213.32:53426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dN7EFnm79ltp0SFBQigAAOmc"]
[Mon Jul 20 07:05:59.418047 2026] [security2:error] [pid 45040:tid 45276] [client 192.140.149.97:44658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dN7EFnm79ltp0SFBQkwAAAGg"]
[Mon Jul 20 07:05:59.418147 2026] [security2:error] [pid 45040:tid 45276] [client 192.140.149.97:44658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dN7EFnm79ltp0SFBQkwAAAGg"]
[Mon Jul 20 07:05:59.516118 2026] [security2:error] [pid 45040:tid 45056] [remote 217.61.143.92:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dN7EFnm79ltp0SFBQlQAAWg4"]
[Mon Jul 20 07:05:59.538071 2026] [security2:error] [pid 45040:tid 45293] [client 158.173.89.95:56317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dN7EFnm79ltp0SFBQmwAAAHk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:05:59.571659 2026] [security2:error] [pid 45040:tid 45253] [client 14.225.17.146:55220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4dN7EFnm79ltp0SFBQkQAAAFE"], referer: http://detroitcsc.com/2023
[Mon Jul 20 07:05:59.675838 2026] [security2:error] [pid 45040:tid 45297] [client 45.3.54.215:24807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dN7EFnm79ltp0SFBQpwAAAH0"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:05:59.747767 2026] [security2:error] [pid 45040:tid 45098] [remote 217.61.143.92:50904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dN7EFnm79ltp0SFBQrAAAUjc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:05:59.832745 2026] [http2:warn] [pid 28702:tid 28887] [client 57.141.18.94:26662] h2_stream(28702-1187-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:05:59.968431 2026] [security2:error] [pid 45040:tid 45253] [client 194.61.41.54:40887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/as.php"] [unique_id "al4dN7EFnm79ltp0SFBQyAAAAFE"]
[Mon Jul 20 07:06:00.018281 2026] [security2:error] [pid 45040:tid 45283] [client 74.125.213.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dN7EFnm79ltp0SFBQswAAAG8"]
[Mon Jul 20 07:06:00.065214 2026] [http2:warn] [pid 29744:tid 29986] [client 57.141.18.43:33742] h2_stream(29744-1141-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:00.140475 2026] [security2:error] [pid 45040:tid 45264] [client 201.27.111.74:52503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dOLEFnm79ltp0SFBQ2QAAAFw"]
[Mon Jul 20 07:06:00.141207 2026] [security2:error] [pid 45040:tid 45264] [client 201.27.111.74:52503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dOLEFnm79ltp0SFBQ2QAAAFw"]
[Mon Jul 20 07:06:00.185622 2026] [security2:error] [pid 45040:tid 45193] [client 111.225.214.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4dOLEFnm79ltp0SFBQ0gAAABU"]
[Mon Jul 20 07:06:00.228889 2026] [security2:error] [pid 45040:tid 45101] [remote 20.153.140.50:45592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4dOLEFnm79ltp0SFBQ4gAAMjo"]
[Mon Jul 20 07:06:00.256824 2026] [security2:error] [pid 45040:tid 45217] [client 45.3.54.55:60983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dOLEFnm79ltp0SFBQ3wAAAC0"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:00.346883 2026] [security2:error] [pid 45040:tid 45263] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dOLEFnm79ltp0SFBQ1QAAAFs"]
[Mon Jul 20 07:06:00.363685 2026] [security2:error] [pid 45040:tid 45258] [client 14.225.17.146:53274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4dOLEFnm79ltp0SFBQ5wAAAFY"], referer: http://cloudspacesgroup.com/2023
[Mon Jul 20 07:06:00.580625 2026] [security2:error] [pid 45040:tid 45244] [client 14.225.17.146:53240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4dOLEFnm79ltp0SFBQ5QAAAEg"], referer: http://healthylifegourmet.org/2023
[Mon Jul 20 07:06:00.630744 2026] [security2:error] [pid 45040:tid 45054] [remote 20.153.140.50:45592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4dOLEFnm79ltp0SFBRCAAAZww"], referer: https://supportinghands22.org/wp-login.php
[Mon Jul 20 07:06:00.632152 2026] [security2:error] [pid 45040:tid 45278] [client 95.182.90.246:65179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.90.182.95.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dOLEFnm79ltp0SFBRBQAAAGo"], referer: https://mezzacraft.com/tunisian-crochet-entrelac-5-week-course/
[Mon Jul 20 07:06:00.632268 2026] [security2:error] [pid 45040:tid 45278] [client 95.182.90.246:65179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dOLEFnm79ltp0SFBRBQAAAGo"], referer: https://mezzacraft.com/tunisian-crochet-entrelac-5-week-course/
[Mon Jul 20 07:06:00.635781 2026] [security2:error] [pid 45040:tid 45292] [client 187.16.64.216:63250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dOLEFnm79ltp0SFBRCgAAAHg"]
[Mon Jul 20 07:06:00.635885 2026] [security2:error] [pid 45040:tid 45292] [client 187.16.64.216:63250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dOLEFnm79ltp0SFBRCgAAAHg"]
[Mon Jul 20 07:06:00.739776 2026] [security2:error] [pid 45040:tid 45232] [client 194.61.41.56:65471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/index.php"] [unique_id "al4dOLEFnm79ltp0SFBRFAAAADw"]
[Mon Jul 20 07:06:00.823359 2026] [http2:warn] [pid 28702:tid 28843] [client 57.141.18.7:31590] h2_stream(28702-791-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:00.907394 2026] [security2:error] [pid 45040:tid 45248] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dOLEFnm79ltp0SFBREQAAAEw"]
[Mon Jul 20 07:06:00.921355 2026] [security2:error] [pid 45040:tid 45224] [client 14.225.17.146:54454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4dN7EFnm79ltp0SFBQlAAAADQ"], referer: http://dadanetnet.net/2023
[Mon Jul 20 07:06:01.050281 2026] [security2:error] [pid 45040:tid 45269] [client 147.93.171.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4dOLEFnm79ltp0SFBRIgAAAGE"], referer: binance.com
[Mon Jul 20 07:06:01.411160 2026] [http2:warn] [pid 29744:tid 29965] [client 57.141.18.101:24044] h2_stream(29744-1151-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:01.553238 2026] [security2:error] [pid 45040:tid 45282] [client 194.61.41.55:54869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/index.php"] [unique_id "al4dObEFnm79ltp0SFBRWAAAAG4"]
[Mon Jul 20 07:06:01.775022 2026] [security2:error] [pid 45040:tid 45278] [client 77.110.127.138:63011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dObEFnm79ltp0SFBRYgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:01.775124 2026] [security2:error] [pid 45040:tid 45278] [client 77.110.127.138:63011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dObEFnm79ltp0SFBRYgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:01.790769 2026] [http2:warn] [pid 29744:tid 29882] [client 57.141.18.93:44122] h2_stream(29744-1154-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:01.927343 2026] [security2:error] [pid 45040:tid 45244] [client 77.110.127.138:63013] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/21/"] [unique_id "al4dObEFnm79ltp0SFBRcwAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:02.123876 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dObEFnm79ltp0SFBRbwAAADE"]
[Mon Jul 20 07:06:02.339178 2026] [security2:error] [pid 45040:tid 45233] [client 194.61.41.72:23885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/admin.php"] [unique_id "al4dOrEFnm79ltp0SFBRmAAAAD0"]
[Mon Jul 20 07:06:02.342194 2026] [http2:warn] [pid 29744:tid 29932] [client 57.141.18.101:24054] h2_stream(29744-1161-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:02.389119 2026] [http2:warn] [pid 29744:tid 29889] [client 57.141.18.63:42516] h2_stream(29744-1162-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:02.598403 2026] [security2:error] [pid 45040:tid 45291] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dOrEFnm79ltp0SFBRnwAAAHc"]
[Mon Jul 20 07:06:02.625435 2026] [security2:error] [pid 45040:tid 45219] [client 14.225.17.146:54428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4dObEFnm79ltp0SFBRUQAAAC8"], referer: http://sarahholyfield.com/2023
[Mon Jul 20 07:06:02.710360 2026] [security2:error] [pid 29744:tid 29750] [remote 57.141.18.20:54446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cWuGINCUUz5GA9YIyHQACKQQ"]
[Mon Jul 20 07:06:03.121639 2026] [security2:error] [pid 45040:tid 45241] [client 194.61.41.242:41737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/security.php"] [unique_id "al4dO7EFnm79ltp0SFBR2wAAAEU"]
[Mon Jul 20 07:06:03.234584 2026] [http2:warn] [pid 28702:tid 28925] [client 57.141.18.95:54112] h2_stream(28702-1012-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:03.477165 2026] [http2:warn] [pid 28702:tid 28897] [client 57.141.18.94:24480] h2_stream(28702-796-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:03.641257 2026] [security2:error] [pid 45040:tid 45245] [client 14.225.17.146:54773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dO7EFnm79ltp0SFBR6wAAAEk"], referer: http://fkconstructionfunding.com/2023
[Mon Jul 20 07:06:03.656847 2026] [security2:error] [pid 45040:tid 45296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dO7EFnm79ltp0SFBR9QAAAHw"]
[Mon Jul 20 07:06:03.759565 2026] [security2:error] [pid 45040:tid 45251] [client 154.208.48.130:58150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dO7EFnm79ltp0SFBSBQAAAE8"]
[Mon Jul 20 07:06:03.759737 2026] [security2:error] [pid 45040:tid 45251] [client 154.208.48.130:58150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dO7EFnm79ltp0SFBSBQAAAE8"]
[Mon Jul 20 07:06:03.850459 2026] [security2:error] [pid 45040:tid 45230] [client 194.61.41.54:58177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/phpadmin/as.php"] [unique_id "al4dO7EFnm79ltp0SFBSDwAAADo"]
[Mon Jul 20 07:06:03.990252 2026] [security2:error] [pid 45040:tid 45270] [client 14.225.17.146:53056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4dO7EFnm79ltp0SFBSCgAAAGI"], referer: http://according2plant.com/2023
[Mon Jul 20 07:06:04.077603 2026] [security2:error] [pid 28702:tid 28781] [remote 57.141.18.8:36382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cW7F4957xPw9VVBm3oQAAt00"]
[Mon Jul 20 07:06:04.183166 2026] [security2:error] [pid 45040:tid 45229] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dO7EFnm79ltp0SFBSFwAAADk"]
[Mon Jul 20 07:06:04.274398 2026] [http2:warn] [pid 29744:tid 30002] [client 57.141.18.108:64328] h2_stream(29744-1170-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:04.388254 2026] [security2:error] [pid 45040:tid 45205] [client 122.183.32.225:12736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dPLEFnm79ltp0SFBSZAAAACE"]
[Mon Jul 20 07:06:04.388402 2026] [security2:error] [pid 45040:tid 45205] [client 122.183.32.225:12736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dPLEFnm79ltp0SFBSZAAAACE"]
[Mon Jul 20 07:06:04.603355 2026] [http2:warn] [pid 28702:tid 28840] [client 57.141.18.58:39464] h2_stream(28702-801-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:04.630529 2026] [security2:error] [pid 45040:tid 45234] [client 194.61.41.94:45957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/autoload_classmap.php"] [unique_id "al4dPLEFnm79ltp0SFBSegAAAD4"]
[Mon Jul 20 07:06:04.927726 2026] [security2:error] [pid 45040:tid 45288] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dPLEFnm79ltp0SFBSfwAAAHQ"]
[Mon Jul 20 07:06:05.206566 2026] [http2:warn] [pid 29744:tid 29894] [client 57.141.18.96:31598] h2_stream(29744-1178-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:05.234213 2026] [security2:error] [pid 45040:tid 45256] [client 103.144.65.217:53236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dPbEFnm79ltp0SFBStAAAAFQ"]
[Mon Jul 20 07:06:05.234308 2026] [security2:error] [pid 45040:tid 45256] [client 103.144.65.217:53236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dPbEFnm79ltp0SFBStAAAAFQ"]
[Mon Jul 20 07:06:05.285287 2026] [security2:error] [pid 45040:tid 45286] [client 104.234.53.94:48089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4dPbEFnm79ltp0SFBSuQAAAHI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:05.356451 2026] [security2:error] [pid 45040:tid 45227] [client 194.61.41.89:36013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4dPbEFnm79ltp0SFBSvwAAADc"]
[Mon Jul 20 07:06:05.464185 2026] [security2:error] [pid 45040:tid 45130] [remote 72.167.132.114:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dPbEFnm79ltp0SFBSygAAYVc"]
[Mon Jul 20 07:06:05.504992 2026] [security2:error] [pid 45040:tid 45296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dPbEFnm79ltp0SFBSugAAAHw"]
[Mon Jul 20 07:06:05.688055 2026] [security2:error] [pid 45040:tid 45146] [remote 72.167.132.114:54608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dPbEFnm79ltp0SFBS1gAACmc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:06:05.711410 2026] [security2:error] [pid 45040:tid 45222] [client 14.225.17.146:53300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4dPLEFnm79ltp0SFBSPAAAADI"], referer: http://superiorcopywriting.com/2023
[Mon Jul 20 07:06:05.840814 2026] [security2:error] [pid 45040:tid 45254] [client 77.110.127.138:63036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dPbEFnm79ltp0SFBS3wAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:05.840890 2026] [security2:error] [pid 45040:tid 45254] [client 77.110.127.138:63036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dPbEFnm79ltp0SFBS3wAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:06.227866 2026] [http2:warn] [pid 28702:tid 28903] [client 57.141.18.90:42818] h2_stream(28702-807-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:06.239055 2026] [security2:error] [pid 45040:tid 45194] [client 194.61.41.251:26155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/seoo/about.php"] [unique_id "al4dPrEFnm79ltp0SFBTCgAAABY"]
[Mon Jul 20 07:06:06.263969 2026] [http2:warn] [pid 28702:tid 28890] [client 57.141.18.27:55602] h2_stream(28702-1208-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:06.276232 2026] [http2:warn] [pid 28702:tid 28945] [client 57.141.18.44:49286] h2_stream(28702-1209-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:06.338316 2026] [security2:error] [pid 45040:tid 45289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dPrEFnm79ltp0SFBTAwAAAHU"]
[Mon Jul 20 07:06:06.366546 2026] [security2:error] [pid 45040:tid 45105] [remote 192.241.143.148:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4dPrEFnm79ltp0SFBTFgAAFD4"]
[Mon Jul 20 07:06:06.418634 2026] [security2:error] [pid 45040:tid 45220] [client 183.82.98.154:64397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dPrEFnm79ltp0SFBTGwAAADA"]
[Mon Jul 20 07:06:06.418780 2026] [security2:error] [pid 45040:tid 45220] [client 183.82.98.154:64397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dPrEFnm79ltp0SFBTGwAAADA"]
[Mon Jul 20 07:06:06.549967 2026] [security2:error] [pid 45040:tid 45073] [remote 192.241.143.148:41168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4dPrEFnm79ltp0SFBTKgAAYR4"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 07:06:06.558716 2026] [security2:error] [pid 45040:tid 45149] [remote 20.153.140.50:48506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4dPrEFnm79ltp0SFBTKAAAc2o"]
[Mon Jul 20 07:06:06.831544 2026] [http2:warn] [pid 29744:tid 29957] [client 57.141.18.55:26838] h2_stream(29744-1188-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:06.879599 2026] [security2:error] [pid 45040:tid 45245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dPrEFnm79ltp0SFBTPwAAAEk"]
[Mon Jul 20 07:06:07.023499 2026] [security2:error] [pid 45040:tid 45127] [remote 20.153.140.50:48506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4dP7EFnm79ltp0SFBTXAAAQFQ"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 07:06:07.023848 2026] [security2:error] [pid 45040:tid 45242] [client 194.61.41.75:29887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/fonts/about.php"] [unique_id "al4dP7EFnm79ltp0SFBTXgAAAEY"]
[Mon Jul 20 07:06:07.086956 2026] [security2:error] [pid 45040:tid 45219] [client 216.24.212.17:50071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4dP7EFnm79ltp0SFBTZAAAAC8"]
[Mon Jul 20 07:06:07.304724 2026] [security2:error] [pid 45040:tid 45244] [client 216.24.212.39:30465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4dP7EFnm79ltp0SFBTcQAAAEg"]
[Mon Jul 20 07:06:07.323333 2026] [security2:error] [pid 45040:tid 45266] [client 104.234.53.48:34501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dP7EFnm79ltp0SFBTcwAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:07.396570 2026] [http2:warn] [pid 28702:tid 28902] [client 57.141.18.106:60548] h2_stream(28702-813-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:07.403463 2026] [security2:error] [pid 45040:tid 45140] [remote 216.73.216.55:17891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4dP7EFnm79ltp0SFBTfgAAFWE"]
[Mon Jul 20 07:06:07.575568 2026] [http2:warn] [pid 29744:tid 29987] [client 57.141.18.51:23044] h2_stream(29744-1196-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:07.654254 2026] [security2:error] [pid 45040:tid 45203] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dP7EFnm79ltp0SFBTegAAAB8"]
[Mon Jul 20 07:06:07.751171 2026] [security2:error] [pid 45040:tid 45280] [client 117.247.108.24:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dP7EFnm79ltp0SFBTnAAAAGw"]
[Mon Jul 20 07:06:07.751276 2026] [security2:error] [pid 45040:tid 45280] [client 117.247.108.24:53474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dP7EFnm79ltp0SFBTnAAAAGw"]
[Mon Jul 20 07:06:07.765099 2026] [security2:error] [pid 45040:tid 45291] [client 194.61.41.91:61565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/moon.php"] [unique_id "al4dP7EFnm79ltp0SFBTnQAAAHc"]
[Mon Jul 20 07:06:07.793805 2026] [security2:error] [pid 45040:tid 45198] [client 14.225.17.146:52877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4dP7EFnm79ltp0SFBTjQAAABo"], referer: http://guidehunting.com/2023
[Mon Jul 20 07:06:07.981326 2026] [http2:warn] [pid 29744:tid 29877] [client 57.141.18.62:21638] h2_stream(29744-1202-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:08.161510 2026] [http2:warn] [pid 45040:tid 45190] [client 57.141.18.42:56414] h2_stream(45040-69-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:08.247427 2026] [security2:error] [pid 45040:tid 45185] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dQLEFnm79ltp0SFBTtwAAAA0"]
[Mon Jul 20 07:06:08.454531 2026] [security2:error] [pid 45040:tid 45245] [client 14.225.17.146:64970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4dQLEFnm79ltp0SFBTyQAAAEk"], referer: http://younutrition.gr/2023
[Mon Jul 20 07:06:08.531839 2026] [security2:error] [pid 45040:tid 45257] [client 194.61.41.85:25577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/user/about.php"] [unique_id "al4dQLEFnm79ltp0SFBT6gAAAFU"]
[Mon Jul 20 07:06:08.790646 2026] [http2:warn] [pid 29744:tid 29928] [client 57.141.18.98:22764] h2_stream(29744-1208-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:08.846270 2026] [security2:error] [pid 45040:tid 45266] [client 104.234.53.94:50975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dQLEFnm79ltp0SFBUCQAAAF4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:08.903141 2026] [security2:error] [pid 45040:tid 45196] [client 14.225.17.146:54612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4dQLEFnm79ltp0SFBT8AAAABg"], referer: https://guidehunting.com/2023
[Mon Jul 20 07:06:08.953319 2026] [core:error] [pid 45040:tid 45270] [client 14.225.17.146:54516] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2023
[Mon Jul 20 07:06:08.953346 2026] [core:error] [pid 45040:tid 45270] [client 14.225.17.146:54516] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2023
[Mon Jul 20 07:06:09.079084 2026] [security2:error] [pid 45040:tid 45213] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dQLEFnm79ltp0SFBUDAAAACk"]
[Mon Jul 20 07:06:09.148490 2026] [security2:error] [pid 45040:tid 45285] [client 77.110.127.138:63027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dQbEFnm79ltp0SFBUHQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:09.148616 2026] [security2:error] [pid 45040:tid 45285] [client 77.110.127.138:63027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dQbEFnm79ltp0SFBUHQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:09.258825 2026] [security2:error] [pid 45040:tid 45294] [client 194.61.41.106:53759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/index.php"] [unique_id "al4dQbEFnm79ltp0SFBUKQAAAHo"]
[Mon Jul 20 07:06:09.329780 2026] [http2:warn] [pid 28702:tid 28884] [client 57.141.18.31:50810] h2_stream(28702-816-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:09.372730 2026] [security2:error] [pid 45040:tid 45245] [client 50.116.65.227:27478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4dQbEFnm79ltp0SFBULwAAAEk"]
[Mon Jul 20 07:06:09.376955 2026] [security2:error] [pid 45040:tid 45249] [client 14.225.17.146:52987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4dQbEFnm79ltp0SFBUJwAAAE0"], referer: http://recruitinginsight.us/2023
[Mon Jul 20 07:06:09.423992 2026] [security2:error] [pid 45040:tid 45174] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dQbEFnm79ltp0SFBUJgAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:09.560860 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dQbEFnm79ltp0SFBULQAAAH8"]
[Mon Jul 20 07:06:09.670444 2026] [http2:warn] [pid 29744:tid 29890] [client 57.141.18.23:60932] h2_stream(29744-1215-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:09.752034 2026] [security2:error] [pid 45040:tid 45084] [remote 100.42.189.89:45418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4dQbEFnm79ltp0SFBUUQAAZyk"]
[Mon Jul 20 07:06:09.866014 2026] [security2:error] [pid 45040:tid 45179] [client 65.111.22.112:40975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dQbEFnm79ltp0SFBUWQAAAAc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:09.970471 2026] [security2:error] [pid 45040:tid 45116] [remote 100.42.189.89:45418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4dQbEFnm79ltp0SFBUbAAAYUk"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 07:06:09.980826 2026] [security2:error] [pid 45040:tid 45262] [client 116.179.33.148:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4dQbEFnm79ltp0SFBUVwAAAFo"]
[Mon Jul 20 07:06:10.023965 2026] [security2:error] [pid 45040:tid 45205] [client 194.61.41.247:37427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/webadmin.php"] [unique_id "al4dQrEFnm79ltp0SFBUcwAAACE"]
[Mon Jul 20 07:06:10.026764 2026] [http2:warn] [pid 29744:tid 29983] [client 57.141.18.106:60560] h2_stream(29744-1217-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:10.419316 2026] [security2:error] [pid 45040:tid 45291] [client 45.3.54.124:12547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dQrEFnm79ltp0SFBUlQAAAHc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:10.426283 2026] [security2:error] [pid 45040:tid 45290] [client 201.27.111.74:52967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dQrEFnm79ltp0SFBUlAAAAHY"]
[Mon Jul 20 07:06:10.426448 2026] [security2:error] [pid 45040:tid 45290] [client 201.27.111.74:52967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dQrEFnm79ltp0SFBUlAAAAHY"]
[Mon Jul 20 07:06:10.510231 2026] [security2:error] [pid 45040:tid 45222] [client 50.116.65.227:27510] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dQrEFnm79ltp0SFBUngAAADI"]
[Mon Jul 20 07:06:10.520100 2026] [security2:error] [pid 45040:tid 45233] [client 50.116.65.227:27522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dQrEFnm79ltp0SFBUnwAAAD0"]
[Mon Jul 20 07:06:10.650239 2026] [security2:error] [pid 45040:tid 45284] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dQrEFnm79ltp0SFBUkwAAAHA"]
[Mon Jul 20 07:06:10.749104 2026] [security2:error] [pid 45040:tid 45227] [client 194.61.41.66:36619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/about.php"] [unique_id "al4dQrEFnm79ltp0SFBUswAAADc"]
[Mon Jul 20 07:06:11.038255 2026] [security2:error] [pid 45040:tid 45258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dQrEFnm79ltp0SFBUvgAAAFY"]
[Mon Jul 20 07:06:11.079849 2026] [http2:info] [pid 49578:tid 49578] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:06:11.261955 2026] [http2:warn] [pid 29744:tid 29979] [client 57.141.18.51:23060] h2_stream(29744-1232-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:11.275185 2026] [security2:error] [pid 45040:tid 45285] [client 14.225.17.146:65003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4dQbEFnm79ltp0SFBUXAAAAHE"], referer: http://expertcultures.com/2023
[Mon Jul 20 07:06:11.417640 2026] [security2:error] [pid 49578:tid 49580] [remote 81.173.115.7:58578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dQ7U3yPMQnn6Oehc-yAABDQE"]
[Mon Jul 20 07:06:11.417883 2026] [security2:error] [pid 49578:tid 49711] [client 81.173.115.7:58578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dQ7U3yPMQnn6Oehc-yAABDQE"]
[Mon Jul 20 07:06:11.445721 2026] [security2:error] [pid 45040:tid 45193] [client 187.16.64.216:63836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dQ7EFnm79ltp0SFBU5wAAABU"]
[Mon Jul 20 07:06:11.445842 2026] [security2:error] [pid 45040:tid 45193] [client 187.16.64.216:63836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dQ7EFnm79ltp0SFBU5wAAABU"]
[Mon Jul 20 07:06:11.549154 2026] [security2:error] [pid 45040:tid 45254] [client 194.61.41.70:38937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/about.php"] [unique_id "al4dQ7EFnm79ltp0SFBU7gAAAFI"]
[Mon Jul 20 07:06:11.675170 2026] [security2:error] [pid 49578:tid 49717] [client 14.225.17.146:57568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4dQ7U3yPMQnn6Oehc-ygAAARM"], referer: http://mcg.homes/2023
[Mon Jul 20 07:06:12.085720 2026] [security2:error] [pid 45040:tid 45131] [remote 57.141.18.87:48050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4dRLEFnm79ltp0SFBVCAAARVg"]
[Mon Jul 20 07:06:12.178821 2026] [security2:error] [pid 45040:tid 45297] [client 14.225.17.146:53012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4dQrEFnm79ltp0SFBUmgAAAH0"], referer: http://maxenengineering.com/2023
[Mon Jul 20 07:06:12.243617 2026] [security2:error] [pid 29744:tid 29840] [remote 57.141.18.92:61670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cYeGINCUUz5GA9YIzmwACKF4"]
[Mon Jul 20 07:06:12.314371 2026] [security2:error] [pid 45040:tid 45203] [client 104.234.53.70:22981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dRLEFnm79ltp0SFBVEgAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:12.364647 2026] [security2:error] [pid 49578:tid 49799] [client 194.61.41.78:43833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/xl2023.php"] [unique_id "al4dRLU3yPMQnn6Oehc-7QAAAWU"]
[Mon Jul 20 07:06:12.405524 2026] [security2:error] [pid 45040:tid 45053] [remote 182.77.62.24:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4dRLEFnm79ltp0SFBVFwAAegs"]
[Mon Jul 20 07:06:12.470548 2026] [http2:warn] [pid 29744:tid 29977] [client 57.141.18.95:34068] h2_stream(29744-1244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:12.473651 2026] [security2:error] [pid 45040:tid 45252] [client 14.225.17.146:58464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4dQrEFnm79ltp0SFBUpAAAAFA"], referer: http://narv.co/2023
[Mon Jul 20 07:06:12.739399 2026] [http2:warn] [pid 45040:tid 45239] [client 57.141.18.41:21414] h2_stream(45040-101-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:12.824461 2026] [security2:error] [pid 45040:tid 45253] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dRLEFnm79ltp0SFBVGgAAAFE"]
[Mon Jul 20 07:06:12.917892 2026] [security2:error] [pid 45040:tid 45192] [client 77.110.127.138:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dRLEFnm79ltp0SFBVKQAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:12.918008 2026] [security2:error] [pid 45040:tid 45192] [client 77.110.127.138:63047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dRLEFnm79ltp0SFBVKQAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:13.017575 2026] [security2:error] [pid 45040:tid 45069] [remote 182.77.62.24:50450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4dRbEFnm79ltp0SFBVLwAAFRo"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 07:06:13.125933 2026] [security2:error] [pid 45040:tid 45224] [client 194.61.41.89:57485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/go.php"] [unique_id "al4dRbEFnm79ltp0SFBVNQAAADQ"]
[Mon Jul 20 07:06:13.140353 2026] [security2:error] [pid 49578:tid 49828] [client 14.225.17.146:63166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4dRbU3yPMQnn6Oehc_CgAAAYI"], referer: https://maxenengineering.com/2023
[Mon Jul 20 07:06:13.141723 2026] [security2:error] [pid 45040:tid 45293] [client 122.183.32.225:18417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dRbEFnm79ltp0SFBVNgAAAHk"]
[Mon Jul 20 07:06:13.141861 2026] [security2:error] [pid 45040:tid 45293] [client 122.183.32.225:18417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dRbEFnm79ltp0SFBVNgAAAHk"]
[Mon Jul 20 07:06:13.308308 2026] [security2:error] [pid 45040:tid 45289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dRbEFnm79ltp0SFBVNAAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:13.311833 2026] [security2:error] [pid 45040:tid 45072] [remote 97.74.87.194:47494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dRbEFnm79ltp0SFBVPwAAAh0"]
[Mon Jul 20 07:06:13.465431 2026] [security2:error] [pid 49578:tid 49717] [client 14.225.17.146:58029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4dRbU3yPMQnn6Oehc_DgAAARM"], referer: https://narv.co/2023
[Mon Jul 20 07:06:13.528478 2026] [security2:error] [pid 45040:tid 45245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dRbEFnm79ltp0SFBVQAAAAEk"]
[Mon Jul 20 07:06:13.538280 2026] [security2:error] [pid 45040:tid 45249] [client 14.225.17.146:57967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4dRbEFnm79ltp0SFBVRgAAAE0"], referer: http://aljosour-alarabia.com/2023
[Mon Jul 20 07:06:13.620983 2026] [security2:error] [pid 45040:tid 45093] [remote 45.90.123.233:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4dRbEFnm79ltp0SFBVTwAAWDI"]
[Mon Jul 20 07:06:13.742123 2026] [security2:error] [pid 49578:tid 49761] [client 104.234.53.69:49337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dRbU3yPMQnn6Oehc_GwAAAT8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:13.848762 2026] [security2:error] [pid 49578:tid 49785] [client 194.61.41.91:49377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/xleet.php"] [unique_id "al4dRbU3yPMQnn6Oehc_IQAAAVc"]
[Mon Jul 20 07:06:13.917317 2026] [security2:error] [pid 45040:tid 45115] [remote 97.74.87.194:47494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dRbEFnm79ltp0SFBVXgAAIkg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:06:14.091871 2026] [security2:error] [pid 45040:tid 45105] [remote 45.90.123.233:47126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4dRrEFnm79ltp0SFBVbwAAHz4"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:06:14.337680 2026] [security2:error] [pid 45040:tid 45289] [client 104.234.53.53:34837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4dRrEFnm79ltp0SFBVegAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:14.497617 2026] [http2:warn] [pid 28702:tid 28834] [client 57.141.18.89:54754] h2_stream(28702-1240-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:14.634109 2026] [security2:error] [pid 49578:tid 49834] [client 14.225.17.146:59540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4dRbU3yPMQnn6Oehc_DQAAAYg"], referer: http://cephasnext.com/2023
[Mon Jul 20 07:06:14.653637 2026] [security2:error] [pid 49578:tid 49749] [client 194.61.41.86:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/templates/beez3/bypass.php"] [unique_id "al4dRrU3yPMQnn6Oehc_RgAAATM"]
[Mon Jul 20 07:06:14.703562 2026] [security2:error] [pid 28702:tid 28724] [remote 57.141.18.120:35522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cY7F4957xPw9VVBm40AAAlRQ"]
[Mon Jul 20 07:06:14.805609 2026] [security2:error] [pid 49578:tid 49746] [client 152.55.176.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4dRrU3yPMQnn6Oehc_RwAAATA"]
[Mon Jul 20 07:06:15.006433 2026] [security2:error] [pid 49578:tid 49768] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dRrU3yPMQnn6Oehc_UgAAAUY"]
[Mon Jul 20 07:06:15.231362 2026] [security2:error] [pid 49578:tid 49745] [client 66.249.65.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.legallyknownaszacharyhoy999.com"] [uri "/index.php"] [unique_id "al4dRbU3yPMQnn6Oehc_FAAAAS8"]
[Mon Jul 20 07:06:15.435534 2026] [security2:error] [pid 45040:tid 45294] [client 194.61.41.106:35379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/ahax.php"] [unique_id "al4dR7EFnm79ltp0SFBVrAAAAHo"]
[Mon Jul 20 07:06:15.459251 2026] [security2:error] [pid 49578:tid 49713] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dR7U3yPMQnn6Oehc_aAAAAQ8"]
[Mon Jul 20 07:06:15.504210 2026] [core:error] [pid 49578:tid 49723] [client 14.225.17.146:62923] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:06:15.504233 2026] [core:error] [pid 49578:tid 49723] [client 14.225.17.146:62923] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:06:15.539437 2026] [http2:warn] [pid 29744:tid 29902] [client 57.141.18.78:48342] h2_stream(29744-1271-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:15.549485 2026] [security2:error] [pid 29744:tid 29850] [remote 57.141.18.72:54886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cZeGINCUUz5GA9YI0WwACYmg"]
[Mon Jul 20 07:06:15.557958 2026] [security2:error] [pid 45040:tid 45196] [client 154.208.48.130:58671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dR7EFnm79ltp0SFBVtAAAABg"]
[Mon Jul 20 07:06:15.558497 2026] [security2:error] [pid 45040:tid 45196] [client 154.208.48.130:58671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dR7EFnm79ltp0SFBVtAAAABg"]
[Mon Jul 20 07:06:15.584690 2026] [security2:error] [pid 45040:tid 45256] [client 152.55.176.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4dR7EFnm79ltp0SFBVsQAAAFQ"]
[Mon Jul 20 07:06:15.591143 2026] [security2:error] [pid 45040:tid 45137] [remote 98.156.100.191:33358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dR7EFnm79ltp0SFBVtgAAZl4"]
[Mon Jul 20 07:06:15.890675 2026] [security2:error] [pid 49578:tid 49718] [client 103.144.65.217:53692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dR7U3yPMQnn6Oehc_fAAAARQ"]
[Mon Jul 20 07:06:15.890838 2026] [security2:error] [pid 49578:tid 49718] [client 103.144.65.217:53692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dR7U3yPMQnn6Oehc_fAAAARQ"]
[Mon Jul 20 07:06:16.095719 2026] [security2:error] [pid 49578:tid 49607] [remote 47.242.45.34:48126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.45.242.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4dSLU3yPMQnn6Oehc_fwABDRw"]
[Mon Jul 20 07:06:16.172503 2026] [security2:error] [pid 45040:tid 45198] [client 14.225.17.146:58272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4dR7EFnm79ltp0SFBVyQAAABo"], referer: http://longevityperformanceclinic.com/2023
[Mon Jul 20 07:06:16.223945 2026] [security2:error] [pid 45040:tid 45290] [client 194.61.41.101:49897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/admin.php"] [unique_id "al4dSLEFnm79ltp0SFBV1gAAAHY"]
[Mon Jul 20 07:06:16.232337 2026] [security2:error] [pid 49578:tid 49716] [client 114.119.136.139:27111] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "youpositive.co"] [uri "/ar/bag-of-money-icon/"] [unique_id "al4dSLU3yPMQnn6Oehc_iQAAARI"], referer: https://youpositive.co/en/bag-of-money-icon-2
[Mon Jul 20 07:06:16.489070 2026] [security2:error] [pid 49578:tid 49775] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dSLU3yPMQnn6Oehc_iAAAAU0"]
[Mon Jul 20 07:06:16.597398 2026] [security2:error] [pid 45040:tid 45185] [client 74.7.227.179:48872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4dSLEFnm79ltp0SFBV5gAADVg"], referer: https://tejasenvironmental.com/p=684521
[Mon Jul 20 07:06:16.627961 2026] [security2:error] [pid 49578:tid 49736] [client 14.225.17.146:57511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4dRrU3yPMQnn6Oehc_WQAAASY"], referer: http://transparentservices.online/2023
[Mon Jul 20 07:06:16.633424 2026] [security2:error] [pid 49578:tid 49610] [remote 47.242.45.34:48126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.45.242.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4dSLU3yPMQnn6Oehc_lwABXx8"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 07:06:16.941149 2026] [security2:error] [pid 49578:tid 49780] [client 152.55.176.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4dSLU3yPMQnn6Oehc_pwAAAVI"]
[Mon Jul 20 07:06:16.976279 2026] [security2:error] [pid 45040:tid 45283] [client 194.61.41.55:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/file.php"] [unique_id "al4dSLEFnm79ltp0SFBV-AAAAG8"]
[Mon Jul 20 07:06:16.982557 2026] [security2:error] [pid 49578:tid 49829] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dSLU3yPMQnn6Oehc_ogAAAYM"]
[Mon Jul 20 07:06:17.014684 2026] [security2:error] [pid 49578:tid 49714] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4dSLU3yPMQnn6Oehc_qQAAARA"]
[Mon Jul 20 07:06:17.098650 2026] [security2:error] [pid 49578:tid 49806] [client 183.82.98.154:64953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dSbU3yPMQnn6Oehc_rwAAAWw"]
[Mon Jul 20 07:06:17.098801 2026] [security2:error] [pid 49578:tid 49806] [client 183.82.98.154:64953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dSbU3yPMQnn6Oehc_rwAAAWw"]
[Mon Jul 20 07:06:17.134421 2026] [security2:error] [pid 28702:tid 28757] [remote 57.141.18.72:54896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cZbF4957xPw9VVBm5CgAAljU"]
[Mon Jul 20 07:06:17.344653 2026] [security2:error] [pid 45040:tid 45279] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dSbEFnm79ltp0SFBWBAAAa1k"], referer: http://www.thewelloiledlife.com/order
[Mon Jul 20 07:06:17.570601 2026] [security2:error] [pid 45040:tid 45245] [client 192.140.149.97:45115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dSbEFnm79ltp0SFBWGAAAAEk"]
[Mon Jul 20 07:06:17.570775 2026] [security2:error] [pid 45040:tid 45245] [client 192.140.149.97:45115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dSbEFnm79ltp0SFBWGAAAAEk"]
[Mon Jul 20 07:06:17.579408 2026] [security2:error] [pid 45040:tid 45081] [remote 103.255.134.61:44194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4dSbEFnm79ltp0SFBWFwAAKiY"]
[Mon Jul 20 07:06:17.608294 2026] [security2:error] [pid 45040:tid 45287] [client 14.225.17.146:62867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4dSbEFnm79ltp0SFBWFgAAAHM"], referer: http://hammadownenterprises.com/2023
[Mon Jul 20 07:06:17.652352 2026] [security2:error] [pid 45040:tid 45250] [client 77.110.127.138:63104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dSbEFnm79ltp0SFBWIgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:17.652490 2026] [security2:error] [pid 45040:tid 45250] [client 77.110.127.138:63104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dSbEFnm79ltp0SFBWIgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:17.662969 2026] [security2:error] [pid 45040:tid 45271] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dSbEFnm79ltp0SFBWEAAAAGM"]
[Mon Jul 20 07:06:17.673986 2026] [security2:error] [pid 45040:tid 45093] [remote 103.255.134.61:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dSbEFnm79ltp0SFBWKwAAIzI"]
[Mon Jul 20 07:06:17.724052 2026] [security2:error] [pid 45040:tid 45186] [client 194.61.41.245:49699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cgi-bin/index.php"] [unique_id "al4dSbEFnm79ltp0SFBWMAAAAA4"]
[Mon Jul 20 07:06:17.739361 2026] [http2:warn] [pid 45040:tid 45191] [client 57.141.18.103:34046] h2_stream(45040-136-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:17.847023 2026] [security2:error] [pid 45040:tid 45115] [remote 38.242.157.30:59538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4dSbEFnm79ltp0SFBWOAAAKUg"]
[Mon Jul 20 07:06:17.933335 2026] [security2:error] [pid 45040:tid 45286] [client 14.225.17.146:62817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4dSLEFnm79ltp0SFBV5wAAAHI"], referer: http://inspirespublishing.com/2023
[Mon Jul 20 07:06:18.029454 2026] [security2:error] [pid 45040:tid 45058] [remote 47.86.33.52:36704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4dSrEFnm79ltp0SFBWRQAATxA"]
[Mon Jul 20 07:06:18.041268 2026] [security2:error] [pid 45040:tid 45292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dSbEFnm79ltp0SFBWNgAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:18.095416 2026] [security2:error] [pid 45040:tid 45135] [remote 98.156.100.191:33358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dSrEFnm79ltp0SFBWTgAAKlw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:06:18.149052 2026] [security2:error] [pid 45040:tid 45149] [remote 38.242.157.30:59538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4dSrEFnm79ltp0SFBWUAAAJ2o"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 07:06:18.171062 2026] [security2:error] [pid 45040:tid 45083] [remote 103.255.134.61:44194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4dSrEFnm79ltp0SFBWVAAAOSg"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 07:06:18.193009 2026] [security2:error] [pid 45040:tid 45279] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dSbEFnm79ltp0SFBWQQAAAGs"]
[Mon Jul 20 07:06:18.269578 2026] [security2:error] [pid 45040:tid 45090] [remote 103.255.134.61:33568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dSrEFnm79ltp0SFBWWAAAIy8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:06:18.436019 2026] [security2:error] [pid 45040:tid 45283] [client 194.61.41.72:51699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/file.php"] [unique_id "al4dSrEFnm79ltp0SFBWXQAAAG8"]
[Mon Jul 20 07:06:18.578079 2026] [security2:error] [pid 49578:tid 49754] [client 14.225.17.146:62702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4dSLU3yPMQnn6Oehc_qgAAATg"], referer: http://koaconsultants.com/2023
[Mon Jul 20 07:06:18.671135 2026] [security2:error] [pid 45040:tid 45261] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dSrEFnm79ltp0SFBWXwAAAFk"]
[Mon Jul 20 07:06:18.689738 2026] [security2:error] [pid 45040:tid 45187] [client 117.247.108.24:54833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dSrEFnm79ltp0SFBWawAAAA8"]
[Mon Jul 20 07:06:18.689884 2026] [security2:error] [pid 45040:tid 45187] [client 117.247.108.24:54833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dSrEFnm79ltp0SFBWawAAAA8"]
[Mon Jul 20 07:06:18.757628 2026] [security2:error] [pid 49578:tid 49749] [client 152.55.176.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4dSrU3yPMQnn6Oehc_7AAAATM"]
[Mon Jul 20 07:06:19.025331 2026] [security2:error] [pid 29744:tid 29782] [remote 57.141.18.29:46708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cZ-GINCUUz5GA9YI1CgACViQ"]
[Mon Jul 20 07:06:19.235392 2026] [security2:error] [pid 49578:tid 49824] [client 194.61.41.93:31959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/view-more/ioxi.php"] [unique_id "al4dS7U3yPMQnn6OehdABQAAAX4"]
[Mon Jul 20 07:06:19.264118 2026] [http2:warn] [pid 29744:tid 29892] [client 57.141.18.62:32300] h2_stream(29744-1299-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:19.308949 2026] [security2:error] [pid 45040:tid 45169] [remote 47.86.33.52:36704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4dS7EFnm79ltp0SFBWkgAAZH4"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 07:06:19.328263 2026] [security2:error] [pid 49578:tid 49768] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dS7U3yPMQnn6Oehc__wAAAUY"]
[Mon Jul 20 07:06:19.348469 2026] [security2:error] [pid 49578:tid 49787] [client 213.152.186.163:48894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dS7U3yPMQnn6OehdACgAAAVk"]
[Mon Jul 20 07:06:19.348600 2026] [security2:error] [pid 49578:tid 49787] [client 213.152.186.163:48894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dS7U3yPMQnn6OehdACgAAAVk"]
[Mon Jul 20 07:06:19.818153 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dS7EFnm79ltp0SFBWowAAADA"]
[Mon Jul 20 07:06:20.013079 2026] [security2:error] [pid 49578:tid 49826] [client 104.207.50.192:18325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 192.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dS7U3yPMQnn6OehdAIwAAAYA"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:20.047929 2026] [security2:error] [pid 45040:tid 45234] [client 194.61.41.245:23459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/dedi1.php"] [unique_id "al4dTLEFnm79ltp0SFBWuQAAAD4"]
[Mon Jul 20 07:06:20.186684 2026] [security2:error] [pid 28702:tid 28744] [remote 57.141.18.93:49294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4caLF4957xPw9VVBm5QwAA0ig"]
[Mon Jul 20 07:06:20.271359 2026] [security2:error] [pid 45040:tid 45282] [client 104.234.53.60:21981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dTLEFnm79ltp0SFBWxgAAAG4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:20.372438 2026] [security2:error] [pid 49578:tid 49743] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTLU3yPMQnn6OehdAKAAAAS0"]
[Mon Jul 20 07:06:20.499690 2026] [security2:error] [pid 49578:tid 49645] [remote 162.19.86.63:46546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dTLU3yPMQnn6OehdANgABDEI"]
[Mon Jul 20 07:06:20.499833 2026] [security2:error] [pid 49578:tid 49710] [client 162.19.86.63:46546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dTLU3yPMQnn6OehdANgABDEI"]
[Mon Jul 20 07:06:20.558004 2026] [security2:error] [pid 49578:tid 49647] [remote 78.46.157.202:40678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dTLU3yPMQnn6OehdAPAABMkQ"]
[Mon Jul 20 07:06:20.565453 2026] [security2:error] [pid 49578:tid 49766] [client 45.3.42.154:28697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dTLU3yPMQnn6OehdAOgAAAUQ"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:20.666437 2026] [security2:error] [pid 49578:tid 49793] [client 14.225.17.146:57880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4dS7U3yPMQnn6OehdADAAAAV8"], referer: http://lutheranphilosopher.com/2023
[Mon Jul 20 07:06:20.766492 2026] [security2:error] [pid 49578:tid 49650] [remote 78.46.157.202:40678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dTLU3yPMQnn6OehdARwABUkc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:06:20.857445 2026] [security2:error] [pid 49578:tid 49792] [client 194.61.41.249:22239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/autoload_classmap.php"] [unique_id "al4dTLU3yPMQnn6OehdATQAAAV4"]
[Mon Jul 20 07:06:20.884110 2026] [http2:warn] [pid 28702:tid 28937] [client 57.141.18.70:56346] h2_stream(28702-1262-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:20.982736 2026] [security2:error] [pid 45040:tid 45291] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTLEFnm79ltp0SFBW2QAAAHc"]
[Mon Jul 20 07:06:21.052653 2026] [security2:error] [pid 49578:tid 49816] [client 201.27.111.74:53436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dTbU3yPMQnn6OehdAVAAAAXY"]
[Mon Jul 20 07:06:21.052762 2026] [security2:error] [pid 49578:tid 49816] [client 201.27.111.74:53436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dTbU3yPMQnn6OehdAVAAAAXY"]
[Mon Jul 20 07:06:21.143145 2026] [security2:error] [pid 49578:tid 49738] [client 65.111.23.71:52751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dTbU3yPMQnn6OehdAVwAAASg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:21.148681 2026] [security2:error] [pid 28702:tid 28737] [remote 57.141.18.102:40298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4caLF4957xPw9VVBm5RAAA2yE"]
[Mon Jul 20 07:06:21.273199 2026] [security2:error] [pid 45040:tid 45046] [remote 216.73.216.55:39692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4dTbEFnm79ltp0SFBW9wAAPwU"]
[Mon Jul 20 07:06:21.486513 2026] [security2:error] [pid 49578:tid 49815] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTbU3yPMQnn6OehdAXQAAAXU"]
[Mon Jul 20 07:06:21.621059 2026] [security2:error] [pid 45040:tid 45275] [client 194.61.41.76:20777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/index.php"] [unique_id "al4dTbEFnm79ltp0SFBXCAAAAGc"]
[Mon Jul 20 07:06:21.719422 2026] [security2:error] [pid 45040:tid 45227] [client 45.3.54.143:32861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dTbEFnm79ltp0SFBXDwAAADc"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:21.749156 2026] [security2:error] [pid 49578:tid 49658] [remote 5.161.225.162:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4dTbU3yPMQnn6OehdAcwABek8"]
[Mon Jul 20 07:06:21.778093 2026] [security2:error] [pid 45040:tid 45296] [client 18.140.64.130:42852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dTbEFnm79ltp0SFBXFQAAAHw"]
[Mon Jul 20 07:06:22.049949 2026] [security2:error] [pid 49578:tid 49659] [remote 5.161.225.162:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4dTrU3yPMQnn6OehdAfQABPVA"], referer: https://oldracelimited.com/wp-login.php
[Mon Jul 20 07:06:22.057417 2026] [security2:error] [pid 45040:tid 45293] [client 187.16.64.216:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dTrEFnm79ltp0SFBXKAAAAHk"]
[Mon Jul 20 07:06:22.057512 2026] [security2:error] [pid 45040:tid 45293] [client 187.16.64.216:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dTrEFnm79ltp0SFBXKAAAAHk"]
[Mon Jul 20 07:06:22.097391 2026] [security2:error] [pid 29744:tid 29869] [remote 57.141.18.102:40302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4caOGINCUUz5GA9YI1TgACjXs"]
[Mon Jul 20 07:06:22.158259 2026] [security2:error] [pid 49578:tid 49761] [client 77.110.127.138:63122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dTrU3yPMQnn6OehdAfwAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:22.158378 2026] [security2:error] [pid 49578:tid 49761] [client 77.110.127.138:63122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dTrU3yPMQnn6OehdAfwAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:22.160275 2026] [security2:error] [pid 45040:tid 45234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTbEFnm79ltp0SFBXJAAAAD4"]
[Mon Jul 20 07:06:22.451022 2026] [http2:warn] [pid 28702:tid 28880] [client 57.141.18.57:25736] h2_stream(28702-1070-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:22.583922 2026] [security2:error] [pid 45040:tid 45242] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTrEFnm79ltp0SFBXMgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:22.606844 2026] [security2:error] [pid 45040:tid 45243] [client 14.225.17.146:62641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4dTrEFnm79ltp0SFBXPAAAAEc"]
[Mon Jul 20 07:06:22.622596 2026] [security2:error] [pid 45040:tid 45203] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTrEFnm79ltp0SFBXOQAAAB8"]
[Mon Jul 20 07:06:22.770626 2026] [security2:error] [pid 49578:tid 49814] [client 77.110.127.138:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/pattern-review/pmbkwpoc6xwl.php"] [unique_id "al4dTrU3yPMQnn6OehdAmwAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:22.776795 2026] [security2:error] [pid 45040:tid 45063] [remote 216.73.216.55:39692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4dTrEFnm79ltp0SFBXSQAAORU"]
[Mon Jul 20 07:06:22.819685 2026] [security2:error] [pid 45040:tid 45230] [client 194.61.41.108:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4dTrEFnm79ltp0SFBXNAAAADo"]
[Mon Jul 20 07:06:22.880986 2026] [security2:error] [pid 49578:tid 49798] [client 47.129.222.11:37884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dTrU3yPMQnn6OehdApAAAAWQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:06:22.923191 2026] [security2:error] [pid 45040:tid 45186] [client 14.225.17.146:52655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4dTbEFnm79ltp0SFBXCwAAAA4"], referer: http://betterbonddogtraining.com/2023
[Mon Jul 20 07:06:22.979261 2026] [security2:error] [pid 49578:tid 49756] [client 77.110.127.138:63109] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTrU3yPMQnn6OehdAnAAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:23.127189 2026] [security2:error] [pid 45040:tid 45270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTrEFnm79ltp0SFBXVQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:23.212235 2026] [security2:error] [pid 45040:tid 45221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dTrEFnm79ltp0SFBXUwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:23.455085 2026] [security2:error] [pid 45040:tid 45224] [client 194.61.41.108:20227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/admin.php"] [unique_id "al4dT7EFnm79ltp0SFBXcAAAADQ"]
[Mon Jul 20 07:06:23.759992 2026] [security2:error] [pid 49578:tid 49764] [client 158.173.166.181:36559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dT7U3yPMQnn6OehdAxQAAAUI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:06:23.788138 2026] [security2:error] [pid 45040:tid 45091] [remote 216.73.216.55:39692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4dT7EFnm79ltp0SFBXeQAAYjA"]
[Mon Jul 20 07:06:23.835687 2026] [security2:error] [pid 49578:tid 49670] [remote 20.153.140.50:55890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dT7U3yPMQnn6OehdAyAABNFs"]
[Mon Jul 20 07:06:23.835926 2026] [security2:error] [pid 49578:tid 49750] [client 20.153.140.50:55890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dT7U3yPMQnn6OehdAyAABNFs"]
[Mon Jul 20 07:06:23.839360 2026] [security2:error] [pid 45040:tid 45251] [client 77.110.127.138:63141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/free-pattern/7lwjbylj7dev.php"] [unique_id "al4dT7EFnm79ltp0SFBXgAAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:24.159490 2026] [security2:error] [pid 49578:tid 49755] [client 77.110.127.138:63143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dT7U3yPMQnn6OehdA0wAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:24.214787 2026] [security2:error] [pid 49578:tid 49813] [client 194.61.41.62:30383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/seotheme/mar.php"] [unique_id "al4dULU3yPMQnn6OehdA4wAAAXM"]
[Mon Jul 20 07:06:24.268679 2026] [security2:error] [pid 49578:tid 49756] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dT7U3yPMQnn6OehdA2gAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:24.299353 2026] [security2:error] [pid 49578:tid 49749] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dT7U3yPMQnn6OehdA2AAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:24.954251 2026] [security2:error] [pid 49578:tid 49777] [client 77.110.127.138:63152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/teaching-under-18s-in-group-classes/842b5trldlnn.php"] [unique_id "al4dULU3yPMQnn6OehdA_gAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:25.007295 2026] [security2:error] [pid 49578:tid 49718] [client 194.61.41.63:53265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/wp-login.php"] [unique_id "al4dULU3yPMQnn6OehdBAgAAARQ"]
[Mon Jul 20 07:06:25.114682 2026] [security2:error] [pid 28702:tid 28767] [remote 57.141.18.96:48208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cabF4957xPw9VVBm5dAAAxj8"]
[Mon Jul 20 07:06:25.160046 2026] [security2:error] [pid 49578:tid 49820] [client 88.241.67.160:55827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dUbU3yPMQnn6OehdBDgAAAXo"]
[Mon Jul 20 07:06:25.160306 2026] [security2:error] [pid 49578:tid 49820] [client 88.241.67.160:55827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dUbU3yPMQnn6OehdBDgAAAXo"]
[Mon Jul 20 07:06:25.253047 2026] [security2:error] [pid 45040:tid 45247] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dUbEFnm79ltp0SFBXxgAAS30"]
[Mon Jul 20 07:06:25.309671 2026] [http2:warn] [pid 28702:tid 28839] [client 57.141.18.116:31842] h2_stream(28702-863-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:25.316022 2026] [security2:error] [pid 49578:tid 49675] [remote 173.249.4.11:51081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dUbU3yPMQnn6OehdBFQABF2A"]
[Mon Jul 20 07:06:25.358259 2026] [security2:error] [pid 49578:tid 49677] [remote 57.141.18.75:41122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5066974"] [unique_id "al4dUbU3yPMQnn6OehdBGwABG2I"]
[Mon Jul 20 07:06:25.414623 2026] [security2:error] [pid 49578:tid 49750] [client 77.110.127.138:63154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dULU3yPMQnn6OehdBAQAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:25.460377 2026] [security2:error] [pid 45040:tid 45218] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dULEFnm79ltp0SFBXwQAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:25.462874 2026] [security2:error] [pid 45040:tid 45299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dULEFnm79ltp0SFBXwAAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:25.469591 2026] [security2:error] [pid 49578:tid 49809] [client 104.28.219.199:45153] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/.env"] [unique_id "al4dUbU3yPMQnn6OehdBIwAAAW8"]
[Mon Jul 20 07:06:25.499376 2026] [security2:error] [pid 49578:tid 49760] [client 144.76.19.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wealthynarrative.com"] [uri "/index.php"] [unique_id "al4dT7U3yPMQnn6OehdAuwABPlg"]
[Mon Jul 20 07:06:25.518192 2026] [security2:error] [pid 49578:tid 49678] [remote 162.19.86.63:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4dUbU3yPMQnn6OehdBJAABamM"]
[Mon Jul 20 07:06:25.540754 2026] [security2:error] [pid 49578:tid 49679] [remote 173.249.4.11:51081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dUbU3yPMQnn6OehdBJwABEGQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:06:25.560161 2026] [security2:error] [pid 45040:tid 45202] [client 154.208.48.130:59161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dUbEFnm79ltp0SFBX2QAAAB4"]
[Mon Jul 20 07:06:25.560247 2026] [security2:error] [pid 45040:tid 45202] [client 154.208.48.130:59161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dUbEFnm79ltp0SFBX2QAAAB4"]
[Mon Jul 20 07:06:25.721117 2026] [security2:error] [pid 49578:tid 49769] [client 104.28.219.199:45150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4dUbU3yPMQnn6OehdBHgAAAXM"]
[Mon Jul 20 07:06:25.730649 2026] [security2:error] [pid 49578:tid 49681] [remote 162.19.86.63:58914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4dUbU3yPMQnn6OehdBPAABh2Y"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:06:25.731885 2026] [security2:error] [pid 49578:tid 49729] [client 104.28.219.199:45148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4dUbU3yPMQnn6OehdBIgAAAX4"]
[Mon Jul 20 07:06:25.755499 2026] [security2:error] [pid 49578:tid 49822] [client 104.28.219.199:45146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4dUbU3yPMQnn6OehdBHwAAAUs"]
[Mon Jul 20 07:06:25.762640 2026] [security2:error] [pid 49578:tid 49777] [client 104.28.219.199:45159] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/wp-config.php~"] [unique_id "al4dUbU3yPMQnn6OehdBPgAAAU8"]
[Mon Jul 20 07:06:25.765417 2026] [security2:error] [pid 45040:tid 45223] [client 104.28.219.199:45170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/wp-config.php.bak"] [unique_id "al4dUbEFnm79ltp0SFBX6QAAADM"]
[Mon Jul 20 07:06:25.770387 2026] [security2:error] [pid 49578:tid 49803] [client 104.28.219.199:45163] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/wp-config.php.old"] [unique_id "al4dUbU3yPMQnn6OehdBQAAAAWk"]
[Mon Jul 20 07:06:25.775900 2026] [security2:error] [pid 49578:tid 49733] [client 104.28.219.199:45165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.219.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/wp-config.php"] [unique_id "al4dUbU3yPMQnn6OehdBPwAAASM"]
[Mon Jul 20 07:06:25.816358 2026] [security2:error] [pid 49578:tid 49800] [client 14.225.17.146:52606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4dULU3yPMQnn6OehdA8gAAAWY"], referer: http://northbrookcpa.ca/2023
[Mon Jul 20 07:06:25.824275 2026] [security2:error] [pid 49578:tid 49828] [client 194.61.41.86:38073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ioxi/ioxiworm.php"] [unique_id "al4dUbU3yPMQnn6OehdBQgAAAYI"]
[Mon Jul 20 07:06:25.886849 2026] [security2:error] [pid 49578:tid 49712] [client 104.28.219.199:45153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4dUbU3yPMQnn6OehdBMQAAAYg"]
[Mon Jul 20 07:06:25.917584 2026] [security2:error] [pid 49578:tid 49738] [client 77.110.127.138:63117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/hand-dyed-yarn/2sy0biixdxfg.php"] [unique_id "al4dUbU3yPMQnn6OehdBSgAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.067852 2026] [security2:error] [pid 49578:tid 49797] [client 104.28.219.199:45146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4dUbU3yPMQnn6OehdBTAAAAWM"]
[Mon Jul 20 07:06:26.192330 2026] [security2:error] [pid 45040:tid 45284] [client 77.110.127.138:63119] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dUbEFnm79ltp0SFBX8gAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.192861 2026] [security2:error] [pid 49578:tid 49748] [client 104.28.219.199:45153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-9d4c7530.zanjan-fromer.com"] [uri "/index.php"] [unique_id "al4dUrU3yPMQnn6OehdBWAAAATI"]
[Mon Jul 20 07:06:26.245531 2026] [security2:error] [pid 29744:tid 29873] [remote 57.141.18.43:33742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ca-GINCUUz5GA9YI16QACg38"]
[Mon Jul 20 07:06:26.328840 2026] [security2:error] [pid 49578:tid 49796] [client 14.225.17.146:52709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4dUrU3yPMQnn6OehdBXwAAAWI"], referer: http://bbwipartnerconference.com/2023
[Mon Jul 20 07:06:26.363252 2026] [security2:error] [pid 49578:tid 49765] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dUrU3yPMQnn6OehdBWgAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.397793 2026] [security2:error] [pid 49578:tid 49819] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dUrU3yPMQnn6OehdBWQAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.451251 2026] [security2:error] [pid 49578:tid 49731] [client 103.144.65.217:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dUrU3yPMQnn6OehdBZQAAASE"]
[Mon Jul 20 07:06:26.451377 2026] [security2:error] [pid 49578:tid 49731] [client 103.144.65.217:54154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dUrU3yPMQnn6OehdBZQAAASE"]
[Mon Jul 20 07:06:26.548419 2026] [security2:error] [pid 45040:tid 45282] [client 194.61.41.71:39873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/blog/wp-content/about.php"] [unique_id "al4dUrEFnm79ltp0SFBYGAAAAG4"]
[Mon Jul 20 07:06:26.715384 2026] [security2:error] [pid 49578:tid 49740] [client 77.110.127.138:63139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dUrU3yPMQnn6OehdBaQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.715511 2026] [security2:error] [pid 49578:tid 49740] [client 77.110.127.138:63139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dUrU3yPMQnn6OehdBaQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.982655 2026] [security2:error] [pid 49578:tid 49713] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dUrU3yPMQnn6OehdBbgAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:26.988812 2026] [security2:error] [pid 45040:tid 45250] [client 14.225.17.146:64699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4dUbEFnm79ltp0SFBXxQAAAE4"], referer: http://eduardsales.com/2023
[Mon Jul 20 07:06:27.330804 2026] [security2:error] [pid 45040:tid 45209] [client 194.61.41.54:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/hehehehe.php"] [unique_id "al4dU7EFnm79ltp0SFBYPwAAACU"]
[Mon Jul 20 07:06:27.358131 2026] [security2:error] [pid 45040:tid 45262] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dU7EFnm79ltp0SFBYOAAAAFo"], referer: 1'"3000
[Mon Jul 20 07:06:27.376505 2026] [security2:error] [pid 28702:tid 28762] [remote 57.141.18.7:31590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ca7F4957xPw9VVBm5tAAAjzo"]
[Mon Jul 20 07:06:27.671535 2026] [security2:error] [pid 45040:tid 45284] [client 183.82.98.154:65498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dU7EFnm79ltp0SFBYSwAAAHA"]
[Mon Jul 20 07:06:27.671648 2026] [security2:error] [pid 45040:tid 45284] [client 183.82.98.154:65498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dU7EFnm79ltp0SFBYSwAAAHA"]
[Mon Jul 20 07:06:27.765544 2026] [http2:warn] [pid 45040:tid 45188] [client 57.141.18.45:59266] h2_stream(45040-193-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:27.809068 2026] [security2:error] [pid 45040:tid 45187] [client 14.225.17.146:64564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4dU7EFnm79ltp0SFBYTgAAAA8"], referer: http://christiancountytrumpet.com/2023
[Mon Jul 20 07:06:27.864935 2026] [security2:error] [pid 49578:tid 49791] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dU7U3yPMQnn6OehdBlQAAAV0"], referer: 1'"3000
[Mon Jul 20 07:06:28.056323 2026] [security2:error] [pid 49578:tid 49752] [client 194.61.41.83:25259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/install.php"] [unique_id "al4dVLU3yPMQnn6OehdBqQAAATY"]
[Mon Jul 20 07:06:28.391452 2026] [http2:warn] [pid 28702:tid 28907] [client 57.141.18.2:51716] h2_stream(28702-1306-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:28.493210 2026] [security2:error] [pid 49578:tid 49712] [client 114.119.143.1:24899] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.appelmanimages.com"] [uri "/naperville-photographer-punk-princess-kid-lifestyle-photography-2"] [unique_id "al4dVLU3yPMQnn6OehdBvAAAAQ4"], referer: https://www.appelmanimages.com/tag/lifestyle-photographer
[Mon Jul 20 07:06:28.756075 2026] [security2:error] [pid 49578:tid 49828] [client 14.225.17.146:52989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4dVLU3yPMQnn6OehdByAAAAYI"], referer: http://chestermonty.com/2023
[Mon Jul 20 07:06:28.838948 2026] [security2:error] [pid 49578:tid 49773] [client 194.61.41.241:29301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/plugins.php"] [unique_id "al4dVLU3yPMQnn6OehdB0QAAAUs"]
[Mon Jul 20 07:06:29.231520 2026] [security2:error] [pid 45040:tid 45173] [client 98.159.234.160:25169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dVbEFnm79ltp0SFBYjAAAAAE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:06:29.339586 2026] [security2:error] [pid 49578:tid 49772] [client 14.225.17.146:52950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4dU7U3yPMQnn6OehdBlgAAAUo"], referer: http://fluidtemple.org/2023
[Mon Jul 20 07:06:29.477061 2026] [security2:error] [pid 49578:tid 49816] [client 14.225.17.146:64777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4dU7U3yPMQnn6OehdBpgAAAXY"], referer: http://ironcitywellness.com/2023
[Mon Jul 20 07:06:29.500892 2026] [security2:error] [pid 49578:tid 49806] [client 117.247.108.24:59364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dVbU3yPMQnn6OehdB7AAAAWw"]
[Mon Jul 20 07:06:29.501098 2026] [security2:error] [pid 49578:tid 49806] [client 117.247.108.24:59364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dVbU3yPMQnn6OehdB7AAAAWw"]
[Mon Jul 20 07:06:29.571672 2026] [security2:error] [pid 45040:tid 45207] [client 194.61.41.95:29511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/license.php"] [unique_id "al4dVbEFnm79ltp0SFBYngAAACM"]
[Mon Jul 20 07:06:29.619623 2026] [security2:error] [pid 49578:tid 49728] [client 114.119.155.235:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sergnotes.com"] [uri "/topics/learning"] [unique_id "al4dVbU3yPMQnn6OehdB7wAAAR4"], referer: http://www.sergnotes.com/
[Mon Jul 20 07:06:29.684874 2026] [security2:error] [pid 45040:tid 45199] [client 14.225.17.146:52490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4dVbEFnm79ltp0SFBYoAAAABs"], referer: https://chestermonty.com/2023
[Mon Jul 20 07:06:29.789895 2026] [security2:error] [pid 49578:tid 49741] [client 89.124.94.93:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.94.124.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4dVbU3yPMQnn6OehdB9gAAASs"], referer: https://mezzacraft.com/tunisian-crochet-entrelac-5-week-course/
[Mon Jul 20 07:06:29.793250 2026] [security2:error] [pid 45040:tid 45284] [client 77.110.127.138:63107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dVbEFnm79ltp0SFBYqwAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:29.793327 2026] [security2:error] [pid 45040:tid 45284] [client 77.110.127.138:63107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dVbEFnm79ltp0SFBYqwAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:29.889371 2026] [http2:warn] [pid 28702:tid 28930] [client 57.141.18.114:22418] h2_stream(28702-883-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:30.037592 2026] [security2:error] [pid 49578:tid 49812] [client 213.152.186.163:50374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dVrU3yPMQnn6OehdCAQAAAXI"]
[Mon Jul 20 07:06:30.037710 2026] [security2:error] [pid 49578:tid 49812] [client 213.152.186.163:50374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dVrU3yPMQnn6OehdCAQAAAXI"]
[Mon Jul 20 07:06:30.166369 2026] [security2:error] [pid 45040:tid 45154] [remote 57.141.18.58:42472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4dVrEFnm79ltp0SFBYvAAAMW8"]
[Mon Jul 20 07:06:30.177219 2026] [http2:warn] [pid 29744:tid 29885] [client 57.141.18.27:23464] h2_stream(29744-1425-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:30.177237 2026] [http2:warn] [pid 29744:tid 29956] [client 57.141.18.61:24852] h2_stream(29744-1490-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:30.177593 2026] [http2:warn] [pid 29744:tid 29909] [client 57.141.18.102:38574] h2_stream(29744-1423-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:30.183436 2026] [http2:warn] [pid 29744:tid 29911] [client 57.141.18.27:24224] h2_stream(29744-1518-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:30.343509 2026] [security2:error] [pid 45040:tid 45244] [client 194.61.41.82:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/astra/inc/ki1k.php"] [unique_id "al4dVrEFnm79ltp0SFBYzAAAAEg"]
[Mon Jul 20 07:06:30.361103 2026] [security2:error] [pid 45040:tid 45214] [client 14.225.17.146:62451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4dVrEFnm79ltp0SFBYwwAAACo"], referer: http://dasmarque.com/2023
[Mon Jul 20 07:06:30.428339 2026] [security2:error] [pid 45040:tid 45258] [client 104.234.53.82:50981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dVrEFnm79ltp0SFBY0AAAAFY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:30.960302 2026] [security2:error] [pid 49578:tid 49730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dVrU3yPMQnn6OehdCEgAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:31.137919 2026] [security2:error] [pid 49578:tid 49734] [client 194.61.41.250:48801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/astra/inc/fm.php"] [unique_id "al4dV7U3yPMQnn6OehdCIAAAASQ"]
[Mon Jul 20 07:06:31.333604 2026] [security2:error] [pid 49578:tid 49761] [client 65.111.23.79:11327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dV7U3yPMQnn6OehdCLQAAAT8"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:31.408471 2026] [proxy:error] [pid 45040:tid 45258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:06:31.408530 2026] [proxy_http:error] [pid 45040:tid 45258] [client 134.199.235.236:44778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:06:31.409071 2026] [proxy:error] [pid 45040:tid 45258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:06:31.409097 2026] [proxy_http:error] [pid 45040:tid 45258] [client 134.199.235.236:44778] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:06:31.494730 2026] [proxy:error] [pid 45040:tid 45284] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:06:31.494803 2026] [proxy_http:error] [pid 45040:tid 45284] [client 134.199.235.236:44780] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lue.sup.mybluehost.me/
[Mon Jul 20 07:06:31.495418 2026] [proxy:error] [pid 45040:tid 45284] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:06:31.495445 2026] [proxy_http:error] [pid 45040:tid 45284] [client 134.199.235.236:44780] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.lue.sup.mybluehost.me/
[Mon Jul 20 07:06:31.516915 2026] [security2:error] [pid 45040:tid 45251] [client 201.27.111.74:53907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dV7EFnm79ltp0SFBZCAAAAE8"]
[Mon Jul 20 07:06:31.577061 2026] [security2:error] [pid 49578:tid 49603] [remote 72.167.132.114:41124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4dV7U3yPMQnn6OehdCPAABdRg"]
[Mon Jul 20 07:06:31.704356 2026] [security2:error] [pid 49578:tid 49722] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dV7U3yPMQnn6OehdCLgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:31.751241 2026] [core:error] [pid 45040:tid 45236] [client 134.199.235.236:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:06:31.751267 2026] [core:error] [pid 45040:tid 45236] [client 134.199.235.236:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:06:31.823095 2026] [security2:error] [pid 49578:tid 49607] [remote 72.167.132.114:41124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4dV7U3yPMQnn6OehdCQwABOxw"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 07:06:31.879531 2026] [security2:error] [pid 45040:tid 45114] [remote 5.252.52.249:40202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4dV7EFnm79ltp0SFBZFwAAKEc"]
[Mon Jul 20 07:06:31.906980 2026] [security2:error] [pid 49578:tid 49780] [client 45.3.42.103:25193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 103.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dV7U3yPMQnn6OehdCSgAAAVI"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:31.922662 2026] [security2:error] [pid 49578:tid 49733] [client 194.61.41.79:60259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ccx/index.php"] [unique_id "al4dV7U3yPMQnn6OehdCTAAAASM"]
[Mon Jul 20 07:06:32.087524 2026] [security2:error] [pid 49578:tid 49754] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dV7U3yPMQnn6OehdCSQAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:32.133406 2026] [security2:error] [pid 45040:tid 45251] [client 201.27.111.74:53907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dV7EFnm79ltp0SFBZCAAAAE8"]
[Mon Jul 20 07:06:32.138072 2026] [http2:warn] [pid 45040:tid 45180] [client 57.141.18.107:58604] h2_stream(45040-211-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:32.145498 2026] [security2:error] [pid 45040:tid 45118] [remote 5.252.52.249:40202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4dWLEFnm79ltp0SFBZHgAAFEs"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:06:32.313573 2026] [security2:error] [pid 49578:tid 49828] [client 77.110.127.138:63183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dWLU3yPMQnn6OehdCXAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:32.313678 2026] [security2:error] [pid 49578:tid 49828] [client 77.110.127.138:63183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dWLU3yPMQnn6OehdCXAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:32.405308 2026] [security2:error] [pid 45040:tid 45237] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dWLEFnm79ltp0SFBZIQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:32.480182 2026] [security2:error] [pid 49578:tid 49774] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWLU3yPMQnn6OehdCXwABTCA"]
[Mon Jul 20 07:06:32.538556 2026] [security2:error] [pid 49578:tid 49724] [client 57.141.18.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4dWLU3yPMQnn6OehdCYAAAARo"]
[Mon Jul 20 07:06:32.571497 2026] [security2:error] [pid 49578:tid 49752] [client 122.183.32.225:9274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dWLU3yPMQnn6OehdCbwAAATY"]
[Mon Jul 20 07:06:32.571603 2026] [security2:error] [pid 49578:tid 49752] [client 122.183.32.225:9274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dWLU3yPMQnn6OehdCbwAAATY"]
[Mon Jul 20 07:06:32.653438 2026] [security2:error] [pid 45040:tid 45293] [client 194.61.41.68:31389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/index.php"] [unique_id "al4dWLEFnm79ltp0SFBZMwAAAHk"]
[Mon Jul 20 07:06:32.694360 2026] [security2:error] [pid 45040:tid 45260] [client 187.16.64.216:65002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dWLEFnm79ltp0SFBZNQAAAFg"]
[Mon Jul 20 07:06:32.694480 2026] [security2:error] [pid 45040:tid 45260] [client 187.16.64.216:65002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dWLEFnm79ltp0SFBZNQAAAFg"]
[Mon Jul 20 07:06:32.720435 2026] [security2:error] [pid 49578:tid 49746] [client 35.90.38.209:34534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4dWLU3yPMQnn6OehdCcgAAATA"]
[Mon Jul 20 07:06:32.766835 2026] [security2:error] [pid 49578:tid 49809] [client 54.81.157.232:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cryptomeaning.com"] [uri "/index.php"] [unique_id "al4dWLU3yPMQnn6OehdCWwAAAW8"]
[Mon Jul 20 07:06:33.036062 2026] [security2:error] [pid 49578:tid 49830] [client 14.225.17.146:50210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4dV7U3yPMQnn6OehdCPwAAAYQ"], referer: http://balticsteelmgmt.com/2023
[Mon Jul 20 07:06:33.086255 2026] [security2:error] [pid 49578:tid 49803] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dWLU3yPMQnn6OehdCfwAAAWk"]
[Mon Jul 20 07:06:33.394878 2026] [security2:error] [pid 49578:tid 49741] [client 50.116.65.227:12542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4dWbU3yPMQnn6OehdCiwAAASs"]
[Mon Jul 20 07:06:33.409355 2026] [security2:error] [pid 45040:tid 45278] [client 50.116.65.227:30854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4dWbEFnm79ltp0SFBZWAAAAGo"]
[Mon Jul 20 07:06:33.446714 2026] [security2:error] [pid 49578:tid 49620] [remote 202.51.202.242:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dWbU3yPMQnn6OehdCjwABJik"]
[Mon Jul 20 07:06:33.447664 2026] [security2:error] [pid 49578:tid 49717] [client 216.73.217.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4dWLU3yPMQnn6OehdCdQAAARM"]
[Mon Jul 20 07:06:33.540588 2026] [security2:error] [pid 45040:tid 45218] [client 194.61.41.98:30291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/about.php"] [unique_id "al4dWbEFnm79ltp0SFBZXQAAAC4"]
[Mon Jul 20 07:06:33.691725 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCmAABISQ"]
[Mon Jul 20 07:06:33.691927 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCmQABIS0"]
[Mon Jul 20 07:06:33.748302 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCnAABISw"]
[Mon Jul 20 07:06:33.751030 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCmwABIS4"]
[Mon Jul 20 07:06:33.756141 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCnQABISo"]
[Mon Jul 20 07:06:33.816016 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCogABITA"]
[Mon Jul 20 07:06:33.821095 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCpgABITU"]
[Mon Jul 20 07:06:33.828037 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCpAABITI"]
[Mon Jul 20 07:06:33.828887 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCpQABITQ"]
[Mon Jul 20 07:06:33.833253 2026] [security2:error] [pid 49578:tid 49731] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCoQABITE"]
[Mon Jul 20 07:06:34.054022 2026] [security2:error] [pid 49578:tid 49724] [client 14.225.17.146:64553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCsQAAARo"], referer: http://lelandumc.org/2023
[Mon Jul 20 07:06:34.107205 2026] [security2:error] [pid 49578:tid 49807] [client 14.225.17.146:61344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4dWLU3yPMQnn6OehdCbQAAAW0"], referer: http://reosportsboats.com/2023
[Mon Jul 20 07:06:34.201593 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dWbU3yPMQnn6OehdCtQAAARE"]
[Mon Jul 20 07:06:34.261628 2026] [security2:error] [pid 49578:tid 49733] [client 185.238.231.234:34921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4dWbU3yPMQnn6OehdChwAAASM"]
[Mon Jul 20 07:06:34.282436 2026] [http2:warn] [pid 28702:tid 28932] [client 57.141.18.120:42598] h2_stream(28702-894-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:34.283947 2026] [security2:error] [pid 45040:tid 45208] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWrEFnm79ltp0SFBZgQAAJAA"], referer: https://thewelloiledlife.com/.aws/credentials
[Mon Jul 20 07:06:34.291391 2026] [security2:error] [pid 49578:tid 49827] [client 185.238.231.66:51681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4dWbU3yPMQnn6OehdCiAAAAYE"]
[Mon Jul 20 07:06:34.292397 2026] [security2:error] [pid 45040:tid 45208] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWrEFnm79ltp0SFBZfwAAJCc"], referer: https://thewelloiledlife.com/z9x8c7v6b5-debug-trigger-thewelloiledlife.com
[Mon Jul 20 07:06:34.294725 2026] [security2:error] [pid 45040:tid 45208] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWrEFnm79ltp0SFBZggAAJGI"], referer: https://thewelloiledlife.com/.aws/config
[Mon Jul 20 07:06:34.295962 2026] [security2:error] [pid 45040:tid 45158] [remote 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWrEFnm79ltp0SFBZgAAAJHM"], referer: https://thewelloiledlife.com/.git/config
[Mon Jul 20 07:06:34.296512 2026] [security2:error] [pid 45040:tid 45208] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWrEFnm79ltp0SFBZfgAAJG0"], referer: https://thewelloiledlife.com/_next/build-manifest.json
[Mon Jul 20 07:06:34.299385 2026] [security2:error] [pid 45040:tid 45208] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dWrEFnm79ltp0SFBZfQAAJHY"], referer: https://thewelloiledlife.com/webpack-stats.json
[Mon Jul 20 07:06:34.320682 2026] [security2:error] [pid 29744:tid 29780] [remote 57.141.18.108:64328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cb-GINCUUz5GA9YI27wACkyI"]
[Mon Jul 20 07:06:34.326672 2026] [security2:error] [pid 49578:tid 49803] [client 194.61.41.94:26091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/edit-widgets/index.php"] [unique_id "al4dWrU3yPMQnn6OehdCwQAAAWk"]
[Mon Jul 20 07:06:34.841583 2026] [security2:error] [pid 49578:tid 49744] [client 77.110.127.138:63202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dWrU3yPMQnn6OehdCzwAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:34.841704 2026] [security2:error] [pid 49578:tid 49744] [client 77.110.127.138:63202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dWrU3yPMQnn6OehdCzwAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:35.020883 2026] [security2:error] [pid 49578:tid 49736] [client 14.225.17.146:61504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4dWrU3yPMQnn6OehdC0AAAASY"], referer: https://reosportsboats.com/2023
[Mon Jul 20 07:06:35.041318 2026] [security2:error] [pid 49578:tid 49805] [client 194.61.41.87:40137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/edit-widgets/about.php"] [unique_id "al4dW7U3yPMQnn6OehdC1wAAAWs"]
[Mon Jul 20 07:06:35.194616 2026] [security2:error] [pid 45040:tid 45238] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dW7EFnm79ltp0SFBZrgAAQnU"], referer: https://thewelloiledlife.com/manifest.json
[Mon Jul 20 07:06:35.195081 2026] [security2:error] [pid 45040:tid 45238] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dW7EFnm79ltp0SFBZrQAAQg0"], referer: https://thewelloiledlife.com/build-manifest.json
[Mon Jul 20 07:06:35.198236 2026] [security2:error] [pid 45040:tid 45238] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dW7EFnm79ltp0SFBZsAAAQn0"], referer: https://thewelloiledlife.com/asset-manifest.json
[Mon Jul 20 07:06:35.198503 2026] [security2:error] [pid 45040:tid 45238] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dW7EFnm79ltp0SFBZrwAAQmc"], referer: https://thewelloiledlife.com/rclone.conf
[Mon Jul 20 07:06:35.203413 2026] [security2:error] [pid 45040:tid 45238] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dW7EFnm79ltp0SFBZsQAAQiY"], referer: https://thewelloiledlife.com/_next/static/buildManifest.js
[Mon Jul 20 07:06:35.253852 2026] [security2:error] [pid 28702:tid 28826] [remote 57.141.18.58:39464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cb7F4957xPw9VVBm6DgAAjHo"]
[Mon Jul 20 07:06:35.420695 2026] [core:error] [pid 45040:tid 45195] [client 14.225.17.146:61235] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:06:35.420715 2026] [core:error] [pid 45040:tid 45195] [client 14.225.17.146:61235] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:06:35.423881 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dW7U3yPMQnn6OehdC4QAAAWY"], referer: 1'"3000
[Mon Jul 20 07:06:35.590488 2026] [security2:error] [pid 49578:tid 49711] [client 88.241.67.160:55329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dW7U3yPMQnn6OehdC8QAAAQ0"]
[Mon Jul 20 07:06:35.591773 2026] [security2:error] [pid 49578:tid 49711] [client 88.241.67.160:55329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dW7U3yPMQnn6OehdC8QAAAQ0"]
[Mon Jul 20 07:06:35.852776 2026] [security2:error] [pid 45040:tid 45185] [client 194.61.41.70:46595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/src/Exception/Http/about.php"] [unique_id "al4dW7EFnm79ltp0SFBZywAAAA0"]
[Mon Jul 20 07:06:35.982440 2026] [security2:error] [pid 45040:tid 45130] [remote 209.42.18.223:45556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4dW7EFnm79ltp0SFBZzQAAHlc"]
[Mon Jul 20 07:06:36.108004 2026] [http2:warn] [pid 45040:tid 45298] [client 57.141.18.102:23550] h2_stream(45040-610-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:36.140862 2026] [security2:error] [pid 49578:tid 49793] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXLU3yPMQnn6OehdC_gABX0M"]
[Mon Jul 20 07:06:36.146866 2026] [security2:error] [pid 45040:tid 45078] [remote 209.42.18.223:45556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4dXLEFnm79ltp0SFBZ4gAAJCM"], referer: https://joulecommunications.com/wp-login.php
[Mon Jul 20 07:06:36.266556 2026] [security2:error] [pid 29744:tid 29787] [remote 57.141.18.96:31598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ccOGINCUUz5GA9YI3LgACJyk"]
[Mon Jul 20 07:06:36.488647 2026] [security2:error] [pid 45040:tid 45257] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dXLEFnm79ltp0SFBZ6gAAAFU"], referer: 1'"3000
[Mon Jul 20 07:06:36.551483 2026] [security2:error] [pid 45040:tid 45260] [client 154.208.48.130:59673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dXLEFnm79ltp0SFBZ_AAAAFg"]
[Mon Jul 20 07:06:36.551604 2026] [security2:error] [pid 45040:tid 45260] [client 154.208.48.130:59673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dXLEFnm79ltp0SFBZ_AAAAFg"]
[Mon Jul 20 07:06:36.623773 2026] [security2:error] [pid 45040:tid 45274] [client 50.116.65.227:30906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dXLEFnm79ltp0SFBaBQAAAGY"]
[Mon Jul 20 07:06:36.634124 2026] [security2:error] [pid 49578:tid 49755] [client 50.116.65.227:30916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dXLU3yPMQnn6OehdDIAAAATk"]
[Mon Jul 20 07:06:36.657271 2026] [security2:error] [pid 45040:tid 45051] [remote 31.59.129.193:59940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.git/config"] [unique_id "al4dXLEFnm79ltp0SFBaBwAAdAk"]
[Mon Jul 20 07:06:36.684205 2026] [security2:error] [pid 45040:tid 45236] [client 194.61.41.97:36819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/Diff/Renderer/index.php"] [unique_id "al4dXLEFnm79ltp0SFBaCgAAAEA"]
[Mon Jul 20 07:06:36.901526 2026] [security2:error] [pid 45040:tid 45269] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXLEFnm79ltp0SFBaDwAAYRU"], referer: https://thewelloiledlife.com/.git/HEAD
[Mon Jul 20 07:06:36.922069 2026] [security2:error] [pid 49578:tid 49712] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dXLU3yPMQnn6OehdDHAAAAQ4"]
[Mon Jul 20 07:06:36.937185 2026] [security2:error] [pid 49578:tid 49799] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dXLU3yPMQnn6OehdDHQAAAWU"]
[Mon Jul 20 07:06:37.008941 2026] [security2:error] [pid 49578:tid 49819] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dXLU3yPMQnn6OehdDJQAAAXk"]
[Mon Jul 20 07:06:37.149428 2026] [http2:warn] [pid 45040:tid 45172] [client 57.141.18.43:36476] h2_stream(45040-244-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:37.206413 2026] [security2:error] [pid 45040:tid 45284] [client 103.144.65.217:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dXbEFnm79ltp0SFBaHQAAAHA"]
[Mon Jul 20 07:06:37.206524 2026] [security2:error] [pid 45040:tid 45284] [client 103.144.65.217:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dXbEFnm79ltp0SFBaHQAAAHA"]
[Mon Jul 20 07:06:37.414112 2026] [security2:error] [pid 49578:tid 49764] [client 74.208.214.194:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dXbU3yPMQnn6OehdDQQAAAUI"]
[Mon Jul 20 07:06:37.444121 2026] [security2:error] [pid 45040:tid 45287] [client 194.61.41.249:27207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/Diff/index.php"] [unique_id "al4dXbEFnm79ltp0SFBaIwAAAHM"]
[Mon Jul 20 07:06:37.764032 2026] [security2:error] [pid 49578:tid 49724] [client 14.225.17.146:60880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4dXbU3yPMQnn6OehdDWAAAARo"], referer: http://nextlvlmarketingco.com/2023
[Mon Jul 20 07:06:38.028102 2026] [security2:error] [pid 45040:tid 45234] [client 14.225.17.146:61296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4dXbEFnm79ltp0SFBaGgAAAD4"], referer: http://walkingandtalking.net/2023
[Mon Jul 20 07:06:38.046309 2026] [security2:error] [pid 45040:tid 45185] [client 183.82.98.154:49660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dXrEFnm79ltp0SFBaPwAAAA0"]
[Mon Jul 20 07:06:38.046436 2026] [security2:error] [pid 45040:tid 45185] [client 183.82.98.154:49660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dXrEFnm79ltp0SFBaPwAAAA0"]
[Mon Jul 20 07:06:38.055844 2026] [security2:error] [pid 45040:tid 45266] [client 77.110.127.138:63221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dXrEFnm79ltp0SFBaQQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:38.055954 2026] [security2:error] [pid 45040:tid 45266] [client 77.110.127.138:63221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dXrEFnm79ltp0SFBaQQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:38.218554 2026] [security2:error] [pid 45040:tid 45283] [client 194.61.41.72:50467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/ocean/index.php"] [unique_id "al4dXrEFnm79ltp0SFBaTgAAAG8"]
[Mon Jul 20 07:06:38.294299 2026] [security2:error] [pid 45040:tid 45092] [remote 31.59.129.193:59940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/debug/pprof/cmdline"] [unique_id "al4dXrEFnm79ltp0SFBaUwAAczE"]
[Mon Jul 20 07:06:38.330535 2026] [security2:error] [pid 49578:tid 49711] [client 74.208.214.194:54454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dXrU3yPMQnn6OehdDcwAAAQ0"]
[Mon Jul 20 07:06:38.338328 2026] [security2:error] [pid 49578:tid 49762] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDcAABQFk"]
[Mon Jul 20 07:06:38.349043 2026] [security2:error] [pid 49578:tid 49669] [remote 202.51.202.242:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dXrU3yPMQnn6OehdDdAABP1o"], referer: https://mail.yok.mqz.mybluehost.me/wp-login.php
[Mon Jul 20 07:06:38.525782 2026] [security2:error] [pid 49578:tid 49655] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/.env"] [unique_id "al4dXrU3yPMQnn6OehdDegABYkw"]
[Mon Jul 20 07:06:38.751897 2026] [security2:error] [pid 49578:tid 49748] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDhQABMmA"]
[Mon Jul 20 07:06:38.755588 2026] [security2:error] [pid 49578:tid 49748] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDhAABMl8"]
[Mon Jul 20 07:06:38.758724 2026] [security2:error] [pid 49578:tid 49748] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDhgABMmI"]
[Mon Jul 20 07:06:38.884694 2026] [security2:error] [pid 45040:tid 45193] [client 192.140.149.97:46008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dXrEFnm79ltp0SFBabgAAABU"]
[Mon Jul 20 07:06:38.884818 2026] [security2:error] [pid 45040:tid 45193] [client 192.140.149.97:46008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dXrEFnm79ltp0SFBabgAAABU"]
[Mon Jul 20 07:06:38.895911 2026] [security2:error] [pid 45040:tid 45209] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dXrEFnm79ltp0SFBaXwAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:38.914583 2026] [security2:error] [pid 49578:tid 49815] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDlAABdWU"]
[Mon Jul 20 07:06:38.916072 2026] [security2:error] [pid 49578:tid 49815] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDkwABdWE"]
[Mon Jul 20 07:06:38.924089 2026] [security2:error] [pid 45040:tid 45291] [client 194.61.41.247:21855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/media/index.php"] [unique_id "al4dXrEFnm79ltp0SFBacAAAAHc"]
[Mon Jul 20 07:06:38.943849 2026] [security2:error] [pid 45040:tid 45154] [remote 31.59.129.193:59940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/.env.example"] [unique_id "al4dXrEFnm79ltp0SFBacQAAMm8"]
[Mon Jul 20 07:06:38.944405 2026] [security2:error] [pid 45040:tid 45052] [remote 31.59.129.193:59940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/storage/logs/laravel.log"] [unique_id "al4dXrEFnm79ltp0SFBacwAAMgo"]
[Mon Jul 20 07:06:39.030899 2026] [security2:error] [pid 45040:tid 45285] [client 52.109.108.111:18994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4dX7EFnm79ltp0SFBadwAAAHE"]
[Mon Jul 20 07:06:39.117333 2026] [security2:error] [pid 45040:tid 45284] [client 13.74.155.112:30752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4dX7EFnm79ltp0SFBafAAAAHA"]
[Mon Jul 20 07:06:39.191400 2026] [security2:error] [pid 45040:tid 45262] [client 52.109.108.111:18994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4dX7EFnm79ltp0SFBagwAAAFo"]
[Mon Jul 20 07:06:39.232463 2026] [security2:error] [pid 28702:tid 28795] [remote 57.141.18.106:60548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ccrF4957xPw9VVBm6XwAAyls"]
[Mon Jul 20 07:06:39.250967 2026] [security2:error] [pid 45040:tid 45212] [client 13.74.155.112:30752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4dX7EFnm79ltp0SFBahgAAACg"]
[Mon Jul 20 07:06:39.337080 2026] [security2:error] [pid 49578:tid 49723] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDmQAAARk"]
[Mon Jul 20 07:06:39.631284 2026] [security2:error] [pid 45040:tid 45269] [client 194.61.41.55:35239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/index.php"] [unique_id "al4dX7EFnm79ltp0SFBakAAAAGE"]
[Mon Jul 20 07:06:39.903861 2026] [security2:error] [pid 49578:tid 49688] [remote 57.141.18.12:42096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5265072"] [unique_id "al4dX7U3yPMQnn6OehdDxAABRW0"]
[Mon Jul 20 07:06:39.986805 2026] [security2:error] [pid 49578:tid 49771] [client 77.110.127.138:63230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dX7U3yPMQnn6OehdDyQAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:39.986897 2026] [security2:error] [pid 49578:tid 49771] [client 77.110.127.138:63230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dX7U3yPMQnn6OehdDyQAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:40.120398 2026] [security2:error] [pid 29744:tid 29777] [remote 57.141.18.51:23044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ccuGINCUUz5GA9YI3tAAChB8"]
[Mon Jul 20 07:06:40.121013 2026] [security2:error] [pid 49578:tid 49692] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/api/.env"] [unique_id "al4dYLU3yPMQnn6OehdD1AABanE"]
[Mon Jul 20 07:06:40.122341 2026] [security2:error] [pid 49578:tid 49694] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thewelloiledlife.com"] [uri "/.env.backup"] [unique_id "al4dYLU3yPMQnn6OehdD1QABanM"]
[Mon Jul 20 07:06:40.122843 2026] [security2:error] [pid 45040:tid 45258] [client 14.225.17.146:61104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4dYLEFnm79ltp0SFBaoAAAAFY"], referer: https://walkingandtalking.net/2023
[Mon Jul 20 07:06:40.128296 2026] [security2:error] [pid 49578:tid 49698] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/.env.bak"] [unique_id "al4dYLU3yPMQnn6OehdD1gABanc"]
[Mon Jul 20 07:06:40.128722 2026] [security2:error] [pid 49578:tid 49697] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/.env.old"] [unique_id "al4dYLU3yPMQnn6OehdD1wABanY"]
[Mon Jul 20 07:06:40.130444 2026] [security2:error] [pid 49578:tid 49792] [client 186.78.101.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4dXbU3yPMQnn6OehdDNQABXk4"], referer: https://tiokubito.cl/wp-admin/admin.php?page=wc-status&tab=action-scheduler
[Mon Jul 20 07:06:40.190691 2026] [security2:error] [pid 49578:tid 49730] [client 14.182.195.220:52542] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4dYLU3yPMQnn6OehdD3wAAASA"]
[Mon Jul 20 07:06:40.214532 2026] [security2:error] [pid 49578:tid 49804] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYLU3yPMQnn6OehdD0QABamw"]
[Mon Jul 20 07:06:40.248646 2026] [security2:error] [pid 49578:tid 49741] [client 14.225.17.146:60717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4dYLU3yPMQnn6OehdDzAAAASs"], referer: http://soloceos.com/2023
[Mon Jul 20 07:06:40.354368 2026] [security2:error] [pid 49578:tid 49725] [client 194.61.41.80:33355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/about.php"] [unique_id "al4dYLU3yPMQnn6OehdD6AAAARs"]
[Mon Jul 20 07:06:40.556483 2026] [security2:error] [pid 49578:tid 49766] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-7471409a.uritems.net"] [uri "/index.php"] [unique_id "al4dXrU3yPMQnn6OehdDbAAAAUQ"]
[Mon Jul 20 07:06:40.629953 2026] [security2:error] [pid 45040:tid 45078] [remote 47.86.33.52:29324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4dYLEFnm79ltp0SFBarwAAHCM"]
[Mon Jul 20 07:06:40.691769 2026] [security2:error] [pid 49578:tid 49706] [remote 47.86.33.52:60838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dYLU3yPMQnn6OehdEBAABY38"]
[Mon Jul 20 07:06:40.691957 2026] [security2:error] [pid 49578:tid 49797] [client 47.86.33.52:60838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dYLU3yPMQnn6OehdEBAABY38"]
[Mon Jul 20 07:06:40.751124 2026] [security2:error] [pid 45040:tid 45233] [client 117.247.108.24:63945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dYLEFnm79ltp0SFBaswAAAD0"]
[Mon Jul 20 07:06:40.751245 2026] [security2:error] [pid 45040:tid 45233] [client 117.247.108.24:63945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dYLEFnm79ltp0SFBaswAAAD0"]
[Mon Jul 20 07:06:40.861001 2026] [security2:error] [pid 49578:tid 49583] [remote 5.252.52.249:57888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4dYLU3yPMQnn6OehdEEAABgwQ"]
[Mon Jul 20 07:06:40.953176 2026] [security2:error] [pid 29744:tid 29825] [remote 57.141.18.62:21638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cc-GINCUUz5GA9YI31AACFk8"]
[Mon Jul 20 07:06:40.964772 2026] [security2:error] [pid 49578:tid 49790] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4dYLU3yPMQnn6OehdEDgAAAVw"]
[Mon Jul 20 07:06:41.065193 2026] [security2:error] [pid 49578:tid 49592] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thewelloiledlife.com"] [uri "/secrets.json"] [unique_id "al4dYbU3yPMQnn6OehdEIwABOw0"]
[Mon Jul 20 07:06:41.065511 2026] [security2:error] [pid 49578:tid 49757] [client 34.75.50.82:33952] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thewelloiledlife.com"] [uri "/secrets.json"] [unique_id "al4dYbU3yPMQnn6OehdEIwABOw0"]
[Mon Jul 20 07:06:41.066618 2026] [security2:error] [pid 49578:tid 49598] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "thewelloiledlife.com"] [uri "/config/.env"] [unique_id "al4dYbU3yPMQnn6OehdEJwABOxM"]
[Mon Jul 20 07:06:41.067686 2026] [security2:error] [pid 49578:tid 49595] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/backend/.env"] [unique_id "al4dYbU3yPMQnn6OehdEJgABOxA"]
[Mon Jul 20 07:06:41.165873 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBaxQAAIFY"], referer: https://thewelloiledlife.com/.env.production
[Mon Jul 20 07:06:41.167297 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBawgAAIDw"], referer: https://thewelloiledlife.com/.github/workflows/deploy.yml
[Mon Jul 20 07:06:41.170216 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBaxgAAIAk"], referer: https://thewelloiledlife.com/.env.local
[Mon Jul 20 07:06:41.171613 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBaxAAAIEk"], referer: https://thewelloiledlife.com/.env.example
[Mon Jul 20 07:06:41.171821 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBawAAAIFw"], referer: https://thewelloiledlife.com/.gitlab-ci.yml
[Mon Jul 20 07:06:41.173290 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBawQAAIEU"], referer: https://thewelloiledlife.com/.git-credentials
[Mon Jul 20 07:06:41.178593 2026] [security2:error] [pid 45040:tid 45204] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBawwAAIBk"], referer: https://thewelloiledlife.com/.gitconfig
[Mon Jul 20 07:06:41.191320 2026] [security2:error] [pid 49578:tid 49757] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEJQABOws"]
[Mon Jul 20 07:06:41.195646 2026] [security2:error] [pid 49578:tid 49757] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEJAABOww"]
[Mon Jul 20 07:06:41.198432 2026] [security2:error] [pid 45040:tid 45249] [client 194.61.41.93:20113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/tinymce/skins/lightgray/img/wp-login.php"] [unique_id "al4dYbEFnm79ltp0SFBayQAAAE0"]
[Mon Jul 20 07:06:41.202190 2026] [security2:error] [pid 45040:tid 45066] [remote 47.86.33.52:29324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4dYbEFnm79ltp0SFBaywAAXxc"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:06:41.393437 2026] [security2:error] [pid 49578:tid 49599] [remote 5.252.52.249:57888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4dYbU3yPMQnn6OehdEQwABORQ"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 07:06:41.410680 2026] [security2:error] [pid 49578:tid 49597] [remote 188.166.241.141:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4dYbU3yPMQnn6OehdERAABHxI"]
[Mon Jul 20 07:06:41.424066 2026] [security2:error] [pid 49578:tid 49788] [client 45.157.112.60:44523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dYbU3yPMQnn6OehdERgAAAVo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:06:41.471653 2026] [security2:error] [pid 49578:tid 49737] [client 114.119.128.218:38721] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "myhealthspot.org"] [uri "/robots.txt"] [unique_id "al4dYbU3yPMQnn6OehdESgAAASc"], referer: https://myhealthspot.org/robots.txt
[Mon Jul 20 07:06:41.508789 2026] [security2:error] [pid 49578:tid 49764] [client 65.111.23.32:27623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4dYbU3yPMQnn6OehdETAAAAUI"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:41.540055 2026] [security2:error] [pid 49578:tid 49779] [client 14.225.17.146:50545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEQQAAAVE"], referer: http://grecruit.online/2023
[Mon Jul 20 07:06:41.580484 2026] [security2:error] [pid 49578:tid 49769] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdELwAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:41.588450 2026] [security2:error] [pid 49578:tid 49808] [client 14.225.17.146:61192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEIQAAAW4"], referer: http://gearwaterproof.com/2023
[Mon Jul 20 07:06:41.673572 2026] [authz_core:error] [pid 49578:tid 49622] [remote 34.75.50.82:33952] AH01630: client denied by server configuration: /home1/polishe5/public_html/.htpasswd
[Mon Jul 20 07:06:41.717634 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEUQABeh8"]
[Mon Jul 20 07:06:41.734445 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEUgABeiU"]
[Mon Jul 20 07:06:41.766980 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEVQABeiM"]
[Mon Jul 20 07:06:41.769530 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEVAABeiY"]
[Mon Jul 20 07:06:41.771265 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEWwABei0"]
[Mon Jul 20 07:06:41.775892 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEVgABeiE"]
[Mon Jul 20 07:06:41.779897 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEVwABeic"]
[Mon Jul 20 07:06:41.785368 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEWgABeiQ"]
[Mon Jul 20 07:06:41.786801 2026] [security2:error] [pid 45040:tid 45211] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBa3wAAJ14"], referer: https://thewelloiledlife.com/secrets.yml
[Mon Jul 20 07:06:41.787415 2026] [security2:error] [pid 49578:tid 49820] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdEWAABeik"]
[Mon Jul 20 07:06:41.791129 2026] [security2:error] [pid 49578:tid 49627] [remote 188.166.241.141:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4dYbU3yPMQnn6OehdEZQABaTA"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 07:06:41.792758 2026] [security2:error] [pid 45040:tid 45211] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYbEFnm79ltp0SFBa3QAAJ0o"], referer: https://thewelloiledlife.com/admin/.env
[Mon Jul 20 07:06:41.860802 2026] [security2:error] [pid 49578:tid 49797] [client 45.131.194.2:62621] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "giftsurprizo.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4dYbU3yPMQnn6OehdEZwAAAWM"]
[Mon Jul 20 07:06:41.928521 2026] [security2:error] [pid 49578:tid 49799] [client 194.61.41.56:49703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/themes.php"] [unique_id "al4dYbU3yPMQnn6OehdEawAAAWU"]
[Mon Jul 20 07:06:41.988554 2026] [security2:error] [pid 49578:tid 49735] [client 104.234.53.67:24719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dYbU3yPMQnn6OehdEbQAAASU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:42.003747 2026] [security2:error] [pid 45040:tid 45185] [client 201.27.111.74:54377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dYrEFnm79ltp0SFBa7wAAAA0"]
[Mon Jul 20 07:06:42.003907 2026] [security2:error] [pid 45040:tid 45185] [client 201.27.111.74:54377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dYrEFnm79ltp0SFBa7wAAAA0"]
[Mon Jul 20 07:06:42.226116 2026] [security2:error] [pid 45040:tid 45259] [client 77.110.127.138:63244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dYrEFnm79ltp0SFBa_QAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:42.226207 2026] [security2:error] [pid 45040:tid 45259] [client 77.110.127.138:63244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dYrEFnm79ltp0SFBa_QAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:42.237700 2026] [security2:error] [pid 45040:tid 45216] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dYrEFnm79ltp0SFBa8AAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:42.426531 2026] [security2:error] [pid 49578:tid 49814] [client 44.245.170.32:64500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4dYrU3yPMQnn6OehdEjwAAAXQ"]
[Mon Jul 20 07:06:42.476953 2026] [security2:error] [pid 49578:tid 49809] [client 54.81.157.232:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4dYbU3yPMQnn6OehdENgAAAW8"]
[Mon Jul 20 07:06:42.479542 2026] [security2:error] [pid 45040:tid 45205] [client 54.81.157.232:57846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/pastel-al-horno-easy-recipe/"] [unique_id "al4dYbEFnm79ltp0SFBazAAAACE"]
[Mon Jul 20 07:06:42.650905 2026] [security2:error] [pid 49578:tid 49735] [client 194.61.41.60:57457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/seoplugins/index.php"] [unique_id "al4dYrU3yPMQnn6OehdEnAAAASU"]
[Mon Jul 20 07:06:42.666889 2026] [security2:error] [pid 49578:tid 49827] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYrU3yPMQnn6OehdElQABgUI"]
[Mon Jul 20 07:06:42.697510 2026] [security2:error] [pid 49578:tid 49827] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dYrU3yPMQnn6OehdEmQABgT4"]
[Mon Jul 20 07:06:42.844767 2026] [security2:error] [pid 49578:tid 49799] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dYrU3yPMQnn6OehdEnQAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:43.061271 2026] [security2:error] [pid 49578:tid 49787] [client 122.183.32.225:23209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dY7U3yPMQnn6OehdEtwAAAVk"]
[Mon Jul 20 07:06:43.061389 2026] [security2:error] [pid 49578:tid 49787] [client 122.183.32.225:23209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dY7U3yPMQnn6OehdEtwAAAVk"]
[Mon Jul 20 07:06:43.083572 2026] [security2:error] [pid 49578:tid 49649] [remote 51.195.39.149:35142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "sesamegreenbeans.com"] [uri "/"] [unique_id "al4dY7U3yPMQnn6OehdEuQABJ0Y"]
[Mon Jul 20 07:06:43.448310 2026] [security2:error] [pid 49578:tid 49714] [client 194.61.41.76:58905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/fonts/themes.php"] [unique_id "al4dY7U3yPMQnn6OehdEygAAARA"]
[Mon Jul 20 07:06:43.472276 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbJgAAV0Y"], referer: https://thewelloiledlife.com/.docker/config.json
[Mon Jul 20 07:06:43.473723 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbHwAAV28"], referer: https://thewelloiledlife.com/serviceAccountKey.json
[Mon Jul 20 07:06:43.476140 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbJAAAVy0"], referer: https://thewelloiledlife.com/firebase-adminsdk.json
[Mon Jul 20 07:06:43.477909 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbIQAAVwo"], referer: https://thewelloiledlife.com/.npmrc
[Mon Jul 20 07:06:43.478582 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbIwAAV0E"], referer: https://thewelloiledlife.com/credentials.json
[Mon Jul 20 07:06:43.479764 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbJwAAVwE"], referer: https://thewelloiledlife.com/terraform.tfstate
[Mon Jul 20 07:06:43.481386 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbIgAAV1k"], referer: https://thewelloiledlife.com/.s3cfg
[Mon Jul 20 07:06:43.482317 2026] [security2:error] [pid 45040:tid 45055] [remote 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbKAAAVw0"], referer: https://thewelloiledlife.com/.svn/entries
[Mon Jul 20 07:06:43.483469 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbJQAAVxs"], referer: https://thewelloiledlife.com/.boto
[Mon Jul 20 07:06:43.483536 2026] [security2:error] [pid 45040:tid 45119] [remote 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbHgAAV0w"], referer: https://thewelloiledlife.com/key.json
[Mon Jul 20 07:06:43.484046 2026] [security2:error] [pid 45040:tid 45259] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7EFnm79ltp0SFBbIAAAVwI"], referer: https://thewelloiledlife.com/service-account.json
[Mon Jul 20 07:06:43.494144 2026] [security2:error] [pid 49578:tid 49746] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dY7U3yPMQnn6OehdEyAABMEk"]
[Mon Jul 20 07:06:43.560693 2026] [http2:warn] [pid 45040:tid 45176] [client 57.141.18.100:43694] h2_stream(45040-654-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:43.734816 2026] [security2:error] [pid 49578:tid 49659] [remote 97.74.93.24:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4dY7U3yPMQnn6OehdE1QABYVA"]
[Mon Jul 20 07:06:44.084922 2026] [security2:error] [pid 49578:tid 49799] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dY7U3yPMQnn6OehdE2QAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:44.162822 2026] [security2:error] [pid 49578:tid 49666] [remote 97.74.93.24:51626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4dZLU3yPMQnn6OehdE5QABW1c"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:06:44.168793 2026] [security2:error] [pid 29744:tid 29857] [remote 57.141.18.106:60560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cdeGINCUUz5GA9YI4VQACgG8"]
[Mon Jul 20 07:06:44.203037 2026] [security2:error] [pid 49578:tid 49754] [client 77.110.127.138:63220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZLU3yPMQnn6OehdE5gAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:44.203158 2026] [security2:error] [pid 49578:tid 49754] [client 77.110.127.138:63220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZLU3yPMQnn6OehdE5gAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:44.238398 2026] [security2:error] [pid 49578:tid 49829] [client 194.61.41.101:43531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentytwo/assets/fonts/index.php"] [unique_id "al4dZLU3yPMQnn6OehdE5wAAAYM"]
[Mon Jul 20 07:06:44.373543 2026] [http2:warn] [pid 28702:tid 28891] [client 57.141.18.19:32270] h2_stream(28702-932-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:44.406593 2026] [security2:error] [pid 45040:tid 45208] [client 187.16.64.216:49196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dZLEFnm79ltp0SFBbUAAAACQ"]
[Mon Jul 20 07:06:44.406712 2026] [security2:error] [pid 45040:tid 45208] [client 187.16.64.216:49196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dZLEFnm79ltp0SFBbUAAAACQ"]
[Mon Jul 20 07:06:44.676061 2026] [security2:error] [pid 49578:tid 49670] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thewelloiledlife.com"] [uri "/.ssh/id_ed25519"] [unique_id "al4dZLU3yPMQnn6OehdE_AABCls"]
[Mon Jul 20 07:06:44.677029 2026] [security2:error] [pid 49578:tid 49675] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thewelloiledlife.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al4dZLU3yPMQnn6OehdE_wABCmA"]
[Mon Jul 20 07:06:44.677161 2026] [security2:error] [pid 49578:tid 49708] [client 34.75.50.82:33952] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thewelloiledlife.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al4dZLU3yPMQnn6OehdE_wABCmA"]
[Mon Jul 20 07:06:44.677795 2026] [security2:error] [pid 49578:tid 49672] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/.ssh/id_rsa"] [unique_id "al4dZLU3yPMQnn6OehdE_gABCl0"]
[Mon Jul 20 07:06:44.677796 2026] [security2:error] [pid 49578:tid 49671] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/.ssh/id_dsa"] [unique_id "al4dZLU3yPMQnn6OehdE_QABClw"]
[Mon Jul 20 07:06:44.766461 2026] [security2:error] [pid 49578:tid 49708] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZLU3yPMQnn6OehdE-wABCkw"]
[Mon Jul 20 07:06:44.769265 2026] [security2:error] [pid 45040:tid 45198] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZLEFnm79ltp0SFBbWAAAGik"], referer: https://thewelloiledlife.com/docker-compose.yaml
[Mon Jul 20 07:06:44.844814 2026] [security2:error] [pid 49578:tid 49751] [client 77.110.127.138:63263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZLU3yPMQnn6OehdFCAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:44.844929 2026] [security2:error] [pid 49578:tid 49751] [client 77.110.127.138:63263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZLU3yPMQnn6OehdFCAAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:44.853490 2026] [security2:error] [pid 49578:tid 49677] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thewelloiledlife.com"] [uri "/graphql"] [unique_id "al4dZLU3yPMQnn6OehdFCQABeWI"]
[Mon Jul 20 07:06:44.898782 2026] [security2:error] [pid 29744:tid 29841] [remote 57.141.18.51:23060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cduGINCUUz5GA9YI4uAACfF8"]
[Mon Jul 20 07:06:45.049491 2026] [security2:error] [pid 45040:tid 45121] [remote 95.217.78.234:52202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dZbEFnm79ltp0SFBbYwAAV04"]
[Mon Jul 20 07:06:45.054658 2026] [security2:error] [pid 49578:tid 49832] [client 194.61.41.56:31071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/index.php"] [unique_id "al4dZbU3yPMQnn6OehdFEwAAAYY"]
[Mon Jul 20 07:06:45.070454 2026] [security2:error] [pid 49578:tid 49722] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dZLU3yPMQnn6OehdFDgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:45.315078 2026] [security2:error] [pid 45040:tid 45138] [remote 95.217.78.234:52202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dZbEFnm79ltp0SFBbbQAAZV8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:06:45.418530 2026] [security2:error] [pid 49578:tid 49748] [client 77.110.127.138:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZbU3yPMQnn6OehdFJwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:45.418615 2026] [security2:error] [pid 49578:tid 49748] [client 77.110.127.138:63242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZbU3yPMQnn6OehdFJwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:45.526340 2026] [security2:error] [pid 49578:tid 49776] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZbU3yPMQnn6OehdFKQABTmc"]
[Mon Jul 20 07:06:45.532854 2026] [security2:error] [pid 49578:tid 49776] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZbU3yPMQnn6OehdFKAABTms"]
[Mon Jul 20 07:06:45.596956 2026] [security2:error] [pid 29744:tid 29818] [remote 57.141.18.95:34068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cd-GINCUUz5GA9YI5EgACekg"]
[Mon Jul 20 07:06:45.668253 2026] [security2:error] [pid 49578:tid 49689] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thewelloiledlife.com"] [uri "/api/graphql"] [unique_id "al4dZbU3yPMQnn6OehdFOAABWW4"]
[Mon Jul 20 07:06:45.691206 2026] [security2:error] [pid 49578:tid 49685] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/key.pem"] [unique_id "al4dZbU3yPMQnn6OehdFOwABDWo"]
[Mon Jul 20 07:06:45.715362 2026] [security2:error] [pid 49578:tid 49692] [remote 91.142.222.105:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dZbU3yPMQnn6OehdFPQABJXE"]
[Mon Jul 20 07:06:45.724016 2026] [security2:error] [pid 49578:tid 49814] [client 77.110.127.138:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZbU3yPMQnn6OehdFPgAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:45.724100 2026] [security2:error] [pid 49578:tid 49814] [client 77.110.127.138:63227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZbU3yPMQnn6OehdFPgAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:45.780654 2026] [security2:error] [pid 49578:tid 49711] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZbU3yPMQnn6OehdFOgABDW8"]
[Mon Jul 20 07:06:45.792392 2026] [security2:error] [pid 45040:tid 45290] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZbEFnm79ltp0SFBbdwAAdhc"], referer: https://thewelloiledlife.com/.vscode/launch.json
[Mon Jul 20 07:06:45.834110 2026] [security2:error] [pid 45040:tid 45249] [client 14.225.17.146:49547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4dZbEFnm79ltp0SFBbegAAAE0"], referer: http://getgarrison.com/2023
[Mon Jul 20 07:06:45.847103 2026] [security2:error] [pid 49578:tid 49774] [client 194.61.41.64:31259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/byp.php"] [unique_id "al4dZbU3yPMQnn6OehdFSQAAAUw"]
[Mon Jul 20 07:06:45.953027 2026] [security2:error] [pid 49578:tid 49698] [remote 91.142.222.105:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dZbU3yPMQnn6OehdFTwABLHc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:06:46.050118 2026] [security2:error] [pid 49578:tid 49788] [client 14.225.17.146:49808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4dZbU3yPMQnn6OehdFUAAAAVo"], referer: http://nikkidesigns.net/2023
[Mon Jul 20 07:06:46.068307 2026] [security2:error] [pid 49578:tid 49718] [client 77.110.127.138:63271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZrU3yPMQnn6OehdFXAAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:46.069660 2026] [security2:error] [pid 49578:tid 49718] [client 77.110.127.138:63271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZrU3yPMQnn6OehdFXAAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:46.117112 2026] [security2:error] [pid 49578:tid 49736] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dZbU3yPMQnn6OehdFRgAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:46.240887 2026] [security2:error] [pid 49578:tid 49791] [client 88.241.67.160:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dZrU3yPMQnn6OehdFZAAAAV0"]
[Mon Jul 20 07:06:46.240993 2026] [security2:error] [pid 49578:tid 49791] [client 88.241.67.160:56876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dZrU3yPMQnn6OehdFZAAAAV0"]
[Mon Jul 20 07:06:46.292212 2026] [security2:error] [pid 29744:tid 29863] [remote 57.141.18.78:48342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ceuGINCUUz5GA9YI6BQACL3U"]
[Mon Jul 20 07:06:46.425727 2026] [security2:error] [pid 49578:tid 49696] [remote 72.167.132.114:34552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dZrU3yPMQnn6OehdFagABCnU"]
[Mon Jul 20 07:06:46.425905 2026] [security2:error] [pid 49578:tid 49708] [client 72.167.132.114:34552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dZrU3yPMQnn6OehdFagABCnU"]
[Mon Jul 20 07:06:46.460563 2026] [security2:error] [pid 49578:tid 49691] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/id_dsa"] [unique_id "al4dZrU3yPMQnn6OehdFbwABDXA"]
[Mon Jul 20 07:06:46.466511 2026] [security2:error] [pid 49578:tid 49700] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thewelloiledlife.com"] [uri "/id_rsa"] [unique_id "al4dZrU3yPMQnn6OehdFdQABDXk"]
[Mon Jul 20 07:06:46.484304 2026] [security2:error] [pid 49578:tid 49704] [remote 81.173.115.7:38044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4dZrU3yPMQnn6OehdFeAABNn0"]
[Mon Jul 20 07:06:46.484474 2026] [security2:error] [pid 49578:tid 49752] [client 81.173.115.7:38044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4dZrU3yPMQnn6OehdFeAABNn0"]
[Mon Jul 20 07:06:46.485728 2026] [security2:error] [pid 45040:tid 45280] [client 77.110.127.138:63255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZrEFnm79ltp0SFBbiwAAAGw"]
[Mon Jul 20 07:06:46.485838 2026] [security2:error] [pid 45040:tid 45280] [client 77.110.127.138:63255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZrEFnm79ltp0SFBbiwAAAGw"]
[Mon Jul 20 07:06:46.521733 2026] [security2:error] [pid 49578:tid 49706] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "thewelloiledlife.com"] [uri "/privatekey.key"] [unique_id "al4dZrU3yPMQnn6OehdFgAABDX8"]
[Mon Jul 20 07:06:46.562013 2026] [security2:error] [pid 49578:tid 49711] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFcQABDXg"]
[Mon Jul 20 07:06:46.563332 2026] [http2:warn] [pid 28702:tid 28874] [client 57.141.18.52:57444] h2_stream(28702-1136-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:46.563585 2026] [security2:error] [pid 49578:tid 49711] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFcAABDXQ"]
[Mon Jul 20 07:06:46.615290 2026] [security2:error] [pid 49578:tid 49711] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFfgABDQE"]
[Mon Jul 20 07:06:46.615582 2026] [security2:error] [pid 49578:tid 49584] [remote 34.75.50.82:33952] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thewelloiledlife.com"] [uri "/v1/graphql"] [unique_id "al4dZrU3yPMQnn6OehdFhAABDQU"]
[Mon Jul 20 07:06:46.622008 2026] [security2:error] [pid 49578:tid 49711] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFgQABDQA"]
[Mon Jul 20 07:06:46.636708 2026] [security2:error] [pid 45040:tid 45185] [client 77.110.127.138:63275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZrEFnm79ltp0SFBblQAAAA0"]
[Mon Jul 20 07:06:46.636827 2026] [security2:error] [pid 45040:tid 45185] [client 77.110.127.138:63275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dZrEFnm79ltp0SFBblQAAAA0"]
[Mon Jul 20 07:06:46.650463 2026] [security2:error] [pid 49578:tid 49788] [client 194.61.41.61:51231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/blog/wp-includes/about.php"] [unique_id "al4dZrU3yPMQnn6OehdFhgAAAVo"]
[Mon Jul 20 07:06:46.719631 2026] [security2:error] [pid 49578:tid 49784] [client 34.75.50.82:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFhQABVgQ"]
[Mon Jul 20 07:06:46.747194 2026] [security2:error] [pid 45040:tid 45251] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrEFnm79ltp0SFBblAAAT3k"], referer: https://thewelloiledlife.com/id_ecdsa
[Mon Jul 20 07:06:46.749426 2026] [security2:error] [pid 45040:tid 45251] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrEFnm79ltp0SFBbkgAAT14"], referer: https://thewelloiledlife.com/.ssh/config
[Mon Jul 20 07:06:46.753151 2026] [security2:error] [pid 45040:tid 45251] [client 34.75.50.82:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dZrEFnm79ltp0SFBbkwAAT0o"], referer: https://thewelloiledlife.com/.ssh/authorized_keys
[Mon Jul 20 07:06:46.783258 2026] [security2:error] [pid 49578:tid 49805] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFdAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:46.880614 2026] [security2:error] [pid 29744:tid 29791] [remote 57.141.18.62:32300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cfuGINCUUz5GA9YI66QACJS0"]
[Mon Jul 20 07:06:47.099714 2026] [security2:error] [pid 49578:tid 49727] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFkQAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:47.107507 2026] [security2:error] [pid 49578:tid 49762] [client 165.232.55.228:53421] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.alexsandbergmusic.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4dZ7U3yPMQnn6OehdFlwAAAUA"]
[Mon Jul 20 07:06:47.237186 2026] [security2:error] [pid 49578:tid 49588] [remote 57.141.18.9:40248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4dZ7U3yPMQnn6OehdFnwABCwk"]
[Mon Jul 20 07:06:47.237702 2026] [security2:error] [pid 49578:tid 49582] [remote 154.66.198.148:26302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dZ7U3yPMQnn6OehdFoAABGgM"]
[Mon Jul 20 07:06:47.252760 2026] [security2:error] [pid 49578:tid 49823] [client 14.225.17.146:63928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4dZ7U3yPMQnn6OehdFngAAAX0"]
[Mon Jul 20 07:06:47.427256 2026] [security2:error] [pid 45040:tid 45203] [client 154.208.48.130:60184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dZ7EFnm79ltp0SFBbqwAAAB8"]
[Mon Jul 20 07:06:47.427944 2026] [security2:error] [pid 45040:tid 45203] [client 154.208.48.130:60184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dZ7EFnm79ltp0SFBbqwAAAB8"]
[Mon Jul 20 07:06:47.500871 2026] [security2:error] [pid 45040:tid 45201] [client 194.61.41.65:56591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/media/wp-login.php"] [unique_id "al4dZ7EFnm79ltp0SFBbrQAAAB0"]
[Mon Jul 20 07:06:47.505520 2026] [authz_core:error] [pid 49578:tid 49601] [remote 34.148.53.6:46558] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 07:06:47.665515 2026] [security2:error] [pid 45040:tid 45241] [client 104.234.53.60:56381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dZ7EFnm79ltp0SFBbtQAAAEU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:47.802291 2026] [security2:error] [pid 49578:tid 49590] [remote 154.66.198.148:26302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dZ7U3yPMQnn6OehdFvQABHgs"], referer: https://vyx.sbv.mybluehost.me/wp-login.php
[Mon Jul 20 07:06:47.888556 2026] [security2:error] [pid 49578:tid 49827] [client 103.144.65.217:55080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dZ7U3yPMQnn6OehdFwgAAAYE"]
[Mon Jul 20 07:06:47.888659 2026] [security2:error] [pid 49578:tid 49827] [client 103.144.65.217:55080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dZ7U3yPMQnn6OehdFwgAAAYE"]
[Mon Jul 20 07:06:47.976179 2026] [security2:error] [pid 28702:tid 28821] [remote 57.141.18.116:31842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4chLF4957xPw9VVBm8rgAAi3U"]
[Mon Jul 20 07:06:48.244224 2026] [security2:error] [pid 45040:tid 45207] [client 194.61.41.89:20317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/blog/wp-admin/about.php"] [unique_id "al4daLEFnm79ltp0SFBbwQAAACM"]
[Mon Jul 20 07:06:48.533584 2026] [security2:error] [pid 49578:tid 49767] [client 14.176.163.80:45628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4daLU3yPMQnn6OehdF6QABRRQ"]
[Mon Jul 20 07:06:48.576071 2026] [security2:error] [pid 49578:tid 49782] [client 183.82.98.154:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4daLU3yPMQnn6OehdF7gAAAVQ"]
[Mon Jul 20 07:06:48.576202 2026] [security2:error] [pid 49578:tid 49782] [client 183.82.98.154:50211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4daLU3yPMQnn6OehdF7gAAAVQ"]
[Mon Jul 20 07:06:48.674555 2026] [security2:error] [pid 45040:tid 45291] [client 158.173.89.95:53451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4daLEFnm79ltp0SFBb1gAAAHc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:06:48.720008 2026] [security2:error] [pid 49578:tid 49821] [client 14.225.17.146:60515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4dZrU3yPMQnn6OehdFiQAAAXs"], referer: http://dollpassionista.com/2023
[Mon Jul 20 07:06:49.022534 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dabU3yPMQnn6OehdGAwAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:49.022615 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:63284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dabU3yPMQnn6OehdGAwAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:49.054808 2026] [security2:error] [pid 49578:tid 49801] [client 194.61.41.75:28243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentyfive/include.php"] [unique_id "al4dabU3yPMQnn6OehdGCgAAAWc"]
[Mon Jul 20 07:06:49.321767 2026] [security2:error] [pid 28702:tid 28792] [remote 57.141.18.120:42598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cjbF4957xPw9VVBm-OgAA6Fg"]
[Mon Jul 20 07:06:49.515731 2026] [security2:error] [pid 49578:tid 49717] [client 77.110.127.138:63268] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/feed/"] [unique_id "al4dabU3yPMQnn6OehdGHQAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:49.604310 2026] [security2:error] [pid 49578:tid 49784] [client 192.140.149.97:45744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dabU3yPMQnn6OehdGJAAAAVY"]
[Mon Jul 20 07:06:49.604516 2026] [security2:error] [pid 49578:tid 49784] [client 192.140.149.97:45744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dabU3yPMQnn6OehdGJAAAAVY"]
[Mon Jul 20 07:06:49.765819 2026] [security2:error] [pid 49578:tid 49734] [client 14.225.17.146:49696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4dabU3yPMQnn6OehdGIgAAASQ"], referer: https://dollpassionista.com/2023
[Mon Jul 20 07:06:49.870941 2026] [security2:error] [pid 49578:tid 49763] [client 194.61.41.93:58793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/about.php"] [unique_id "al4dabU3yPMQnn6OehdGQQAAAUE"]
[Mon Jul 20 07:06:50.083287 2026] [security2:error] [pid 29744:tid 29842] [remote 57.141.18.102:38574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ckeGINCUUz5GA9YI-4gACNmA"]
[Mon Jul 20 07:06:50.140505 2026] [security2:error] [pid 49578:tid 49719] [client 77.110.127.138:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4darU3yPMQnn6OehdGUAAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:50.140656 2026] [security2:error] [pid 49578:tid 49719] [client 77.110.127.138:63291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4darU3yPMQnn6OehdGUAAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:50.199315 2026] [security2:error] [pid 49578:tid 49797] [client 14.225.17.146:60386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4darU3yPMQnn6OehdGSwAAAWM"], referer: http://alexsandbergmusic.com/2023
[Mon Jul 20 07:06:50.297208 2026] [security2:error] [pid 49578:tid 49762] [client 77.110.127.138:63293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4darU3yPMQnn6OehdGUgAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:50.297306 2026] [security2:error] [pid 49578:tid 49762] [client 77.110.127.138:63293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4darU3yPMQnn6OehdGUgAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:50.653187 2026] [security2:error] [pid 49578:tid 49731] [client 194.61.41.83:27469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cgi-bin/install.php"] [unique_id "al4darU3yPMQnn6OehdGaQAAASE"]
[Mon Jul 20 07:06:50.696400 2026] [security2:error] [pid 49578:tid 49635] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.areitoproducciones.com"] [uri "/key.json"] [unique_id "al4darU3yPMQnn6OehdGbQABCzg"]
[Mon Jul 20 07:06:50.697001 2026] [security2:error] [pid 49578:tid 49640] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/rclone.conf"] [unique_id "al4darU3yPMQnn6OehdGcQABCz0"]
[Mon Jul 20 07:06:50.736633 2026] [http2:warn] [pid 45040:tid 45178] [client 57.141.18.50:53446] h2_stream(45040-709-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:50.749272 2026] [security2:error] [pid 45040:tid 45138] [remote 188.95.113.76:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4darEFnm79ltp0SFBcGgAAKF8"]
[Mon Jul 20 07:06:50.913411 2026] [security2:error] [pid 29744:tid 29826] [remote 57.141.18.27:23464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ckuGINCUUz5GA9YI-9AACHlA"]
[Mon Jul 20 07:06:50.925537 2026] [security2:error] [pid 49578:tid 49768] [client 77.110.127.138:63295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4darU3yPMQnn6OehdGgQAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:50.925697 2026] [security2:error] [pid 49578:tid 49768] [client 77.110.127.138:63295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4darU3yPMQnn6OehdGgQAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:50.977162 2026] [security2:error] [pid 45040:tid 45135] [remote 188.95.113.76:55594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4darEFnm79ltp0SFBcHgAAR1w"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:06:51.126957 2026] [security2:error] [pid 45040:tid 45264] [client 14.225.17.146:64237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4darEFnm79ltp0SFBcGAAAAFw"], referer: http://mollycahill.com/2023
[Mon Jul 20 07:06:51.138341 2026] [security2:error] [pid 49578:tid 49717] [client 65.111.22.219:47055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4da7U3yPMQnn6OehdGkQAAARM"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:51.173209 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4da7U3yPMQnn6OehdGlAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.173338 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4da7U3yPMQnn6OehdGlAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.207245 2026] [security2:error] [pid 49578:tid 49727] [client 104.234.53.79:44001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4da7U3yPMQnn6OehdGhQAAAR0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:51.328446 2026] [security2:error] [pid 45040:tid 45257] [client 77.110.127.138:63299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4da7EFnm79ltp0SFBcKwAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.328556 2026] [security2:error] [pid 45040:tid 45257] [client 77.110.127.138:63299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4da7EFnm79ltp0SFBcKwAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.437193 2026] [security2:error] [pid 45040:tid 45211] [client 194.61.41.56:41821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/wso.php"] [unique_id "al4da7EFnm79ltp0SFBcMQAAACc"]
[Mon Jul 20 07:06:51.440383 2026] [security2:error] [pid 45040:tid 45181] [client 117.247.108.24:62979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4da7EFnm79ltp0SFBcMgAAAAk"]
[Mon Jul 20 07:06:51.440528 2026] [security2:error] [pid 45040:tid 45181] [client 117.247.108.24:62979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4da7EFnm79ltp0SFBcMgAAAAk"]
[Mon Jul 20 07:06:51.503185 2026] [security2:error] [pid 28702:tid 28824] [remote 57.141.18.19:32270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cl7F4957xPw9VVBnAAwAAv3g"]
[Mon Jul 20 07:06:51.658235 2026] [security2:error] [pid 49578:tid 49832] [client 14.225.17.146:64173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4darU3yPMQnn6OehdGZwAAAYY"], referer: http://claysharecon.com/2023
[Mon Jul 20 07:06:51.777009 2026] [security2:error] [pid 49578:tid 49734] [client 77.110.127.138:63300] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/feed/"] [unique_id "al4da7U3yPMQnn6OehdGpgAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.780516 2026] [security2:error] [pid 45040:tid 45292] [client 45.3.42.116:31331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4da7EFnm79ltp0SFBcRgAAAHg"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:06:51.830782 2026] [security2:error] [pid 45040:tid 45279] [client 14.225.17.146:49293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4da7EFnm79ltp0SFBcPAAAAGs"]
[Mon Jul 20 07:06:51.870850 2026] [security2:error] [pid 49578:tid 49720] [client 77.110.127.138:63268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4da7U3yPMQnn6OehdGqAAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.870993 2026] [security2:error] [pid 49578:tid 49720] [client 77.110.127.138:63268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4da7U3yPMQnn6OehdGqAAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:51.998897 2026] [security2:error] [pid 49578:tid 49772] [client 104.234.53.79:44001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4da7U3yPMQnn6OehdGqwAAAUo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:52.044400 2026] [security2:error] [pid 49578:tid 49658] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "app.areitoproducciones.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al4dbLU3yPMQnn6OehdGsAABW08"]
[Mon Jul 20 07:06:52.050155 2026] [security2:error] [pid 49578:tid 49713] [client 77.110.127.138:63302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dbLU3yPMQnn6OehdGswAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:52.050243 2026] [security2:error] [pid 49578:tid 49713] [client 77.110.127.138:63302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dbLU3yPMQnn6OehdGswAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:52.101295 2026] [security2:error] [pid 29744:tid 29829] [remote 57.141.18.61:24852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cm-GINCUUz5GA9YJBCAACZVM"]
[Mon Jul 20 07:06:52.149245 2026] [security2:error] [pid 49578:tid 49660] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/.ssh/id_rsa"] [unique_id "al4dbLU3yPMQnn6OehdGuwABLlE"]
[Mon Jul 20 07:06:52.238711 2026] [security2:error] [pid 49578:tid 49783] [client 194.61.41.79:20729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/class.api.php"] [unique_id "al4dbLU3yPMQnn6OehdGvwAAAVU"]
[Mon Jul 20 07:06:52.263093 2026] [security2:error] [pid 49578:tid 49806] [client 201.27.111.74:54846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dbLU3yPMQnn6OehdGwAAAAWw"]
[Mon Jul 20 07:06:52.263211 2026] [security2:error] [pid 49578:tid 49806] [client 201.27.111.74:54846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dbLU3yPMQnn6OehdGwAAAAWw"]
[Mon Jul 20 07:06:52.295466 2026] [security2:error] [pid 49578:tid 49778] [client 14.225.17.146:49507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4dbLU3yPMQnn6OehdGuAAAAVA"]
[Mon Jul 20 07:06:52.297305 2026] [http2:warn] [pid 45040:tid 45210] [client 57.141.18.53:35558] h2_stream(45040-338-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:52.597261 2026] [security2:error] [pid 49578:tid 49668] [remote 124.55.178.99:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dbLU3yPMQnn6OehdGzgABfVk"]
[Mon Jul 20 07:06:52.597404 2026] [security2:error] [pid 49578:tid 49823] [client 124.55.178.99:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dbLU3yPMQnn6OehdGzgABfVk"]
[Mon Jul 20 07:06:52.604683 2026] [security2:error] [pid 45040:tid 45201] [client 114.119.146.215:29257] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oswegooperatheater.com"] [uri "/robots.txt"] [unique_id "al4dbLEFnm79ltp0SFBcYgAAAB0"], referer: https://oswegooperatheater.com/robots.txt
[Mon Jul 20 07:06:53.091108 2026] [security2:error] [pid 49578:tid 49670] [remote 38.242.157.30:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dbbU3yPMQnn6OehdG5QABa1s"]
[Mon Jul 20 07:06:53.116387 2026] [security2:error] [pid 45040:tid 45284] [client 194.61.41.243:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/wp-login.php"] [unique_id "al4dbbEFnm79ltp0SFBcegAAAHA"]
[Mon Jul 20 07:06:53.275586 2026] [security2:error] [pid 49578:tid 49714] [client 14.225.17.146:49711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4dbLU3yPMQnn6OehdG4AAAARA"], referer: http://alrowad-hub.net/2023
[Mon Jul 20 07:06:53.459496 2026] [security2:error] [pid 49578:tid 49675] [remote 38.242.157.30:49864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dbbU3yPMQnn6OehdG7AABbmA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:06:53.725216 2026] [security2:error] [pid 45040:tid 45194] [client 14.225.17.146:49468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4dbLEFnm79ltp0SFBcWQAAABY"], referer: http://sarahsnyder.net/2023
[Mon Jul 20 07:06:53.857806 2026] [security2:error] [pid 49578:tid 49774] [client 194.61.41.83:59631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/radio.php"] [unique_id "al4dbbU3yPMQnn6OehdG-QAAAUw"]
[Mon Jul 20 07:06:53.953823 2026] [security2:error] [pid 49578:tid 49731] [client 77.110.127.138:63311] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/feed/"] [unique_id "al4dbbU3yPMQnn6OehdHAwAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:53.957775 2026] [security2:error] [pid 49578:tid 49676] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "app.areitoproducciones.com"] [uri "/.ssh/known_hosts"] [unique_id "al4dbbU3yPMQnn6OehdHBAABiGE"]
[Mon Jul 20 07:06:54.003760 2026] [security2:error] [pid 49578:tid 49809] [client 77.110.127.138:63278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dbrU3yPMQnn6OehdHBwAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:54.003862 2026] [security2:error] [pid 49578:tid 49809] [client 77.110.127.138:63278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dbrU3yPMQnn6OehdHBwAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:54.010262 2026] [security2:error] [pid 45040:tid 45052] [remote 47.86.33.52:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4dbbEFnm79ltp0SFBcpwAAPAo"]
[Mon Jul 20 07:06:54.012321 2026] [security2:error] [pid 49578:tid 49682] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.ssh/id_dsa"] [unique_id "al4dbrU3yPMQnn6OehdHCQABgGc"]
[Mon Jul 20 07:06:54.060644 2026] [security2:error] [pid 45040:tid 45262] [client 187.16.64.216:49791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dbrEFnm79ltp0SFBcqQAAAFo"]
[Mon Jul 20 07:06:54.060780 2026] [security2:error] [pid 45040:tid 45262] [client 187.16.64.216:49791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dbrEFnm79ltp0SFBcqQAAAFo"]
[Mon Jul 20 07:06:54.253399 2026] [security2:error] [pid 45040:tid 45173] [client 14.177.96.131:44578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4dbrEFnm79ltp0SFBcuwAAAWc"]
[Mon Jul 20 07:06:54.399293 2026] [security2:error] [pid 45040:tid 45291] [client 14.225.17.146:49933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4dbbEFnm79ltp0SFBcjAAAAHc"], referer: http://entuvy.com/2023
[Mon Jul 20 07:06:54.504909 2026] [security2:error] [pid 45040:tid 45286] [client 14.225.17.146:49540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4dbLEFnm79ltp0SFBcXwAAAHI"], referer: http://www.justinagrayman.com/2023
[Mon Jul 20 07:06:54.545031 2026] [security2:error] [pid 45040:tid 45166] [remote 47.86.33.52:56998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4dbrEFnm79ltp0SFBcwwAAH3s"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:06:54.652124 2026] [security2:error] [pid 45040:tid 45201] [client 194.61.41.73:63845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/system_log.php"] [unique_id "al4dbrEFnm79ltp0SFBcyAAAAB0"]
[Mon Jul 20 07:06:54.698108 2026] [security2:error] [pid 49578:tid 49812] [client 104.234.53.64:32339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dbrU3yPMQnn6OehdHJQAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:54.741422 2026] [security2:error] [pid 28702:tid 28727] [remote 57.141.18.95:54112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cqrF4957xPw9VVBnDsAAA4Rc"]
[Mon Jul 20 07:06:54.826838 2026] [security2:error] [pid 45040:tid 45175] [client 14.225.17.146:50366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4dbrEFnm79ltp0SFBcywAAAAM"], referer: https://sarahsnyder.net/2023
[Mon Jul 20 07:06:55.180560 2026] [security2:error] [pid 45040:tid 45111] [remote 57.141.18.42:56414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cr7EFnm79ltp0SFAzAgAAEkQ"]
[Mon Jul 20 07:06:55.443462 2026] [security2:error] [pid 49578:tid 49779] [client 194.61.41.85:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.alf.php"] [unique_id "al4db7U3yPMQnn6OehdHQgAAAVE"]
[Mon Jul 20 07:06:55.551306 2026] [security2:error] [pid 49578:tid 49694] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.areitoproducciones.com"] [uri "/graphql"] [unique_id "al4db7U3yPMQnn6OehdHSQABgnM"]
[Mon Jul 20 07:06:55.553008 2026] [security2:error] [pid 49578:tid 49696] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/key.pem"] [unique_id "al4db7U3yPMQnn6OehdHTAABgnU"]
[Mon Jul 20 07:06:55.554700 2026] [security2:error] [pid 49578:tid 49691] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/private-key"] [unique_id "al4db7U3yPMQnn6OehdHTQABgnA"]
[Mon Jul 20 07:06:55.554789 2026] [security2:error] [pid 49578:tid 49828] [client 34.148.53.6:46558] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.areitoproducciones.com"] [uri "/private-key"] [unique_id "al4db7U3yPMQnn6OehdHTQABgnA"]
[Mon Jul 20 07:06:55.855353 2026] [security2:error] [pid 49578:tid 49747] [client 77.110.127.138:63286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4db7U3yPMQnn6OehdHagAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:55.855471 2026] [security2:error] [pid 49578:tid 49747] [client 77.110.127.138:63286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4db7U3yPMQnn6OehdHagAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:55.864707 2026] [security2:error] [pid 49578:tid 49794] [client 122.183.32.225:27755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4db7U3yPMQnn6OehdHawAAAWA"]
[Mon Jul 20 07:06:55.864851 2026] [security2:error] [pid 49578:tid 49794] [client 122.183.32.225:27755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4db7U3yPMQnn6OehdHawAAAWA"]
[Mon Jul 20 07:06:55.892594 2026] [security2:error] [pid 45040:tid 45212] [client 14.225.17.146:50024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4dbbEFnm79ltp0SFBclQAAACg"], referer: http://fineartsfactory.net/2023
[Mon Jul 20 07:06:55.954107 2026] [security2:error] [pid 45040:tid 45257] [client 14.225.17.146:51049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4db7EFnm79ltp0SFBc_gAAAFU"]
[Mon Jul 20 07:06:56.000549 2026] [security2:error] [pid 45040:tid 45264] [client 34.75.50.82:35026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4db7EFnm79ltp0SFBc_wAAXCg"]
[Mon Jul 20 07:06:56.120067 2026] [security2:error] [pid 49578:tid 49703] [remote 5.252.52.249:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dcLU3yPMQnn6OehdHfwABQHw"]
[Mon Jul 20 07:06:56.250287 2026] [security2:error] [pid 49578:tid 49792] [client 194.61.41.61:58871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wso.php"] [unique_id "al4dcLU3yPMQnn6OehdHgwAAAV4"]
[Mon Jul 20 07:06:56.386706 2026] [security2:error] [pid 49578:tid 49581] [remote 5.252.52.249:46964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dcLU3yPMQnn6OehdHiAABbgI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:06:56.408240 2026] [security2:error] [pid 49578:tid 49588] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/server.key"] [unique_id "al4dcLU3yPMQnn6OehdHiQABFwk"]
[Mon Jul 20 07:06:56.408413 2026] [security2:error] [pid 49578:tid 49721] [client 34.148.53.6:46558] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.areitoproducciones.com"] [uri "/server.key"] [unique_id "al4dcLU3yPMQnn6OehdHiQABFwk"]
[Mon Jul 20 07:06:56.421560 2026] [security2:error] [pid 45040:tid 45184] [client 66.249.73.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allisonsatterfield.com"] [uri "/index.php"] [unique_id "al4dbrEFnm79ltp0SFBcxgAAAAw"]
[Mon Jul 20 07:06:56.422489 2026] [security2:error] [pid 49578:tid 49587] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/id_rsa"] [unique_id "al4dcLU3yPMQnn6OehdHjQABdQg"]
[Mon Jul 20 07:06:56.445372 2026] [security2:error] [pid 49578:tid 49595] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/privatekey.key"] [unique_id "al4dcLU3yPMQnn6OehdHjwABNhA"]
[Mon Jul 20 07:06:56.446046 2026] [security2:error] [pid 49578:tid 49601] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/id_dsa"] [unique_id "al4dcLU3yPMQnn6OehdHkAABNhY"]
[Mon Jul 20 07:06:56.593300 2026] [security2:error] [pid 45040:tid 45262] [client 13.74.155.112:22081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4dcLEFnm79ltp0SFBdGgAAAFo"]
[Mon Jul 20 07:06:56.657859 2026] [security2:error] [pid 49578:tid 49714] [client 14.225.17.146:51100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4dcLU3yPMQnn6OehdHjgAAARA"], referer: http://itdynamix.com/2023
[Mon Jul 20 07:06:56.684228 2026] [security2:error] [pid 45040:tid 45104] [remote 57.141.18.45:59266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4cwrEFnm79ltp0SFA24QAAED0"]
[Mon Jul 20 07:06:56.726560 2026] [security2:error] [pid 45040:tid 45240] [client 13.74.155.112:22081] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4dcLEFnm79ltp0SFBdIAAAAEQ"]
[Mon Jul 20 07:06:56.814904 2026] [security2:error] [pid 45040:tid 45284] [client 34.75.50.82:35026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dcLEFnm79ltp0SFBdHwAAcDc"]
[Mon Jul 20 07:06:56.817589 2026] [security2:error] [pid 45040:tid 45284] [client 34.75.50.82:35026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dcLEFnm79ltp0SFBdIwAAcEM"]
[Mon Jul 20 07:06:56.819441 2026] [security2:error] [pid 45040:tid 45284] [client 34.75.50.82:35026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dcLEFnm79ltp0SFBdIgAAcDo"]
[Mon Jul 20 07:06:56.821833 2026] [security2:error] [pid 45040:tid 45284] [client 34.75.50.82:35026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dcLEFnm79ltp0SFBdIQAAcDs"]
[Mon Jul 20 07:06:56.859205 2026] [security2:error] [pid 49578:tid 49832] [client 51.143.183.75:7426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4dcLU3yPMQnn6OehdHoQAAAYY"]
[Mon Jul 20 07:06:56.895630 2026] [security2:error] [pid 45040:tid 45299] [client 14.225.17.146:50787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4db7EFnm79ltp0SFBc8gAAAH8"], referer: http://phillipbloch.com/2023
[Mon Jul 20 07:06:56.968480 2026] [security2:error] [pid 49578:tid 49801] [client 88.241.67.160:56147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dcLU3yPMQnn6OehdHpQAAAWc"]
[Mon Jul 20 07:06:56.968692 2026] [security2:error] [pid 49578:tid 49801] [client 88.241.67.160:56147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dcLU3yPMQnn6OehdHpQAAAWc"]
[Mon Jul 20 07:06:56.992396 2026] [security2:error] [pid 49578:tid 49779] [client 51.143.183.75:7426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4dcLU3yPMQnn6OehdHpgAAAVE"]
[Mon Jul 20 07:06:57.026851 2026] [security2:error] [pid 49578:tid 49731] [client 14.225.17.146:50763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4db7U3yPMQnn6OehdHQwAAASE"], referer: http://olearyplumbingllc.com/2023
[Mon Jul 20 07:06:57.051392 2026] [security2:error] [pid 49578:tid 49820] [client 194.61.41.91:64051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/blocks/about.php"] [unique_id "al4dcbU3yPMQnn6OehdHqAAAAXo"]
[Mon Jul 20 07:06:57.345820 2026] [security2:error] [pid 45040:tid 45137] [remote 130.185.118.215:51306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dcbEFnm79ltp0SFBdNQAAFF4"]
[Mon Jul 20 07:06:57.345960 2026] [security2:error] [pid 45040:tid 45192] [client 130.185.118.215:51306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dcbEFnm79ltp0SFBdNQAAFF4"]
[Mon Jul 20 07:06:57.532225 2026] [security2:error] [pid 45040:tid 45167] [remote 57.141.18.43:36476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4czLEFnm79ltp0SFA49QAAAHw"]
[Mon Jul 20 07:06:57.541203 2026] [security2:error] [pid 45040:tid 45238] [client 34.75.50.82:35026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dcbEFnm79ltp0SFBdOgAAQj8"]
[Mon Jul 20 07:06:57.591986 2026] [security2:error] [pid 49578:tid 49591] [remote 216.73.216.55:54940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4dcbU3yPMQnn6OehdHvgABeAw"]
[Mon Jul 20 07:06:57.718585 2026] [security2:error] [pid 45040:tid 45204] [client 14.225.17.146:50047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4dcbEFnm79ltp0SFBdRAAAACA"], referer: https://itdynamix.com/2023
[Mon Jul 20 07:06:57.745949 2026] [security2:error] [pid 49578:tid 49604] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.areitoproducciones.com"] [uri "/api/graphql"] [unique_id "al4dcbU3yPMQnn6OehdHxQABLBk"]
[Mon Jul 20 07:06:57.776341 2026] [security2:error] [pid 49578:tid 49603] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/ssl/server.key"] [unique_id "al4dcbU3yPMQnn6OehdHyQABaRg"]
[Mon Jul 20 07:06:57.808685 2026] [security2:error] [pid 49578:tid 49594] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/.openclaw/.env"] [unique_id "al4dcbU3yPMQnn6OehdHzgABGA8"]
[Mon Jul 20 07:06:57.849546 2026] [security2:error] [pid 49578:tid 49764] [client 194.61.41.80:54599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/flower.php"] [unique_id "al4dcbU3yPMQnn6OehdH0gAAAUI"]
[Mon Jul 20 07:06:58.137210 2026] [http2:warn] [pid 45040:tid 45215] [client 57.141.18.67:35478] h2_stream(45040-758-1,CLEANUP): started=1, scheduled=1, ready=0, out_buffer=0
[Mon Jul 20 07:06:58.248915 2026] [security2:error] [pid 49578:tid 49750] [client 104.234.53.81:26197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dcrU3yPMQnn6OehdH2wAAATQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:06:58.259935 2026] [security2:error] [pid 49578:tid 49616] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.aider.conf.yml"] [unique_id "al4dcrU3yPMQnn6OehdH3wABHyU"]
[Mon Jul 20 07:06:58.310663 2026] [security2:error] [pid 45040:tid 45187] [client 154.208.48.130:60931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dcrEFnm79ltp0SFBdZgAAAA8"]
[Mon Jul 20 07:06:58.310801 2026] [security2:error] [pid 45040:tid 45187] [client 154.208.48.130:60931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dcrEFnm79ltp0SFBdZgAAAA8"]
[Mon Jul 20 07:06:58.315424 2026] [security2:error] [pid 45040:tid 45237] [client 66.249.73.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cathybuffini.com"] [uri "/index.php"] [unique_id "al4dcbEFnm79ltp0SFBdNgAAAEE"]
[Mon Jul 20 07:06:58.426551 2026] [security2:error] [pid 49578:tid 49625] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.codex/config.toml"] [unique_id "al4dcrU3yPMQnn6OehdH5AABKC4"]
[Mon Jul 20 07:06:58.539632 2026] [security2:error] [pid 45040:tid 45258] [client 103.144.65.217:55535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dcrEFnm79ltp0SFBdbAAAAFY"]
[Mon Jul 20 07:06:58.539730 2026] [security2:error] [pid 45040:tid 45258] [client 103.144.65.217:55535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dcrEFnm79ltp0SFBdbAAAAFY"]
[Mon Jul 20 07:06:58.591245 2026] [security2:error] [pid 49578:tid 49610] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "app.areitoproducciones.com"] [uri "/v1/graphql"] [unique_id "al4dcrU3yPMQnn6OehdH6gABhB8"]
[Mon Jul 20 07:06:58.609163 2026] [security2:error] [pid 49578:tid 49624] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/.hermes/.env"] [unique_id "al4dcrU3yPMQnn6OehdH8gABZi0"]
[Mon Jul 20 07:06:58.646375 2026] [security2:error] [pid 49578:tid 49734] [client 194.61.41.81:52417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/wp-class.php"] [unique_id "al4dcrU3yPMQnn6OehdH_QAAASQ"]
[Mon Jul 20 07:06:58.893219 2026] [security2:error] [pid 45040:tid 45154] [remote 47.128.34.207:19072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "terrapro.marketing"] [uri "/blog/"] [unique_id "al4dcrEFnm79ltp0SFBdegAAAm8"]
[Mon Jul 20 07:06:58.985095 2026] [security2:error] [pid 28702:tid 28780] [remote 57.141.18.94:26662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4c4rF4957xPw9VVBnM_gAAu0w"]
[Mon Jul 20 07:06:59.058319 2026] [security2:error] [pid 45040:tid 45172] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dcrEFnm79ltp0SFBdeAAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:59.101519 2026] [security2:error] [pid 45040:tid 45173] [client 50.116.65.227:42804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4dcrEFnm79ltp0SFBdaQAAAAE"]
[Mon Jul 20 07:06:59.110431 2026] [security2:error] [pid 49578:tid 49719] [client 183.82.98.154:50871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dc7U3yPMQnn6OehdIEwAAARU"]
[Mon Jul 20 07:06:59.110571 2026] [security2:error] [pid 49578:tid 49719] [client 183.82.98.154:50871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dc7U3yPMQnn6OehdIEwAAARU"]
[Mon Jul 20 07:06:59.452148 2026] [security2:error] [pid 45040:tid 45220] [client 194.61.41.97:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/autoload_classmap.php"] [unique_id "al4dc7EFnm79ltp0SFBdjAAAADA"]
[Mon Jul 20 07:06:59.526883 2026] [security2:error] [pid 49578:tid 49755] [client 50.116.65.227:24960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4dc7U3yPMQnn6OehdIKwAAATk"]
[Mon Jul 20 07:06:59.530273 2026] [security2:error] [pid 45040:tid 45290] [client 14.225.17.146:60430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4dcrEFnm79ltp0SFBdXgAAAHY"]
[Mon Jul 20 07:06:59.544088 2026] [security2:error] [pid 28702:tid 28729] [remote 57.141.18.27:55602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4c6bF4957xPw9VVBnN8wAAvhk"]
[Mon Jul 20 07:06:59.581872 2026] [security2:error] [pid 49578:tid 49744] [client 34.75.50.82:35030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4dc7U3yPMQnn6OehdIKAABLkE"], referer: https://thewelloiledlife.com/console
[Mon Jul 20 07:06:59.737064 2026] [security2:error] [pid 45040:tid 45242] [client 77.110.127.138:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dc7EFnm79ltp0SFBdlwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:59.737207 2026] [security2:error] [pid 45040:tid 45242] [client 77.110.127.138:63329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dc7EFnm79ltp0SFBdlwAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:06:59.759394 2026] [security2:error] [pid 45040:tid 45208] [client 50.116.65.227:22884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4dc7EFnm79ltp0SFBdggAAACQ"]
[Mon Jul 20 07:07:00.143377 2026] [security2:error] [pid 45040:tid 45209] [client 14.225.17.146:49411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4dc7EFnm79ltp0SFBdgwAAACU"], referer: http://retzkolonglogistics.com/2023
[Mon Jul 20 07:07:00.161448 2026] [security2:error] [pid 49578:tid 49717] [client 192.140.149.97:45243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ddLU3yPMQnn6OehdISQAAARM"]
[Mon Jul 20 07:07:00.161550 2026] [security2:error] [pid 49578:tid 49717] [client 192.140.149.97:45243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4ddLU3yPMQnn6OehdISQAAARM"]
[Mon Jul 20 07:07:00.200023 2026] [security2:error] [pid 49578:tid 49740] [client 34.75.50.82:35030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ddLU3yPMQnn6OehdIRgABKkc"], referer: https://thewelloiledlife.com/dashboard
[Mon Jul 20 07:07:00.221395 2026] [security2:error] [pid 49578:tid 49658] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "app.areitoproducciones.com"] [uri "/wp-config.php.old"] [unique_id "al4ddLU3yPMQnn6OehdIUgABC08"]
[Mon Jul 20 07:07:00.221719 2026] [security2:error] [pid 49578:tid 49654] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.bash_profile"] [unique_id "al4ddLU3yPMQnn6OehdIUwABC0s"]
[Mon Jul 20 07:07:00.221846 2026] [security2:error] [pid 49578:tid 49709] [client 34.148.53.6:46558] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.areitoproducciones.com"] [uri "/.bash_profile"] [unique_id "al4ddLU3yPMQnn6OehdIUwABC0s"]
[Mon Jul 20 07:07:00.222056 2026] [security2:error] [pid 49578:tid 49754] [client 40.77.167.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4ddLU3yPMQnn6OehdIQQAAATg"]
[Mon Jul 20 07:07:00.223023 2026] [security2:error] [pid 49578:tid 49660] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "app.areitoproducciones.com"] [uri "/wp-config.php.bak"] [unique_id "al4ddLU3yPMQnn6OehdIVQABC1E"]
[Mon Jul 20 07:07:00.238630 2026] [security2:error] [pid 45040:tid 45285] [client 194.61.41.78:50255] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/wp-content/1.php"] [unique_id "al4ddLEFnm79ltp0SFBdqQAAAHE"]
[Mon Jul 20 07:07:00.238740 2026] [security2:error] [pid 45040:tid 45285] [client 194.61.41.78:50255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/1.php"] [unique_id "al4ddLEFnm79ltp0SFBdqQAAAHE"]
[Mon Jul 20 07:07:00.333016 2026] [security2:error] [pid 49578:tid 49835] [client 34.75.50.82:35030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ddLU3yPMQnn6OehdIVwABiVA"], referer: https://thewelloiledlife.com/login
[Mon Jul 20 07:07:00.460845 2026] [security2:error] [pid 28702:tid 28777] [remote 57.141.18.89:54754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4c8bF4957xPw9VVBnPUwAAhkk"]
[Mon Jul 20 07:07:00.727422 2026] [security2:error] [pid 49578:tid 49662] [remote 117.0.21.154:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4ddLU3yPMQnn6OehdIZgABHFM"]
[Mon Jul 20 07:07:00.764659 2026] [security2:error] [pid 49578:tid 49670] [remote 57.141.18.105:29884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4ddLU3yPMQnn6OehdIZwABFFs"]
[Mon Jul 20 07:07:00.976879 2026] [security2:error] [pid 28702:tid 28726] [remote 57.141.18.70:56346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4c97F4957xPw9VVBnQWgAA7RY"]
[Mon Jul 20 07:07:00.977306 2026] [security2:error] [pid 49578:tid 49789] [client 34.75.50.82:35030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ddLU3yPMQnn6OehdIagABW1I"], referer: https://thewelloiledlife.com/settings
[Mon Jul 20 07:07:01.024528 2026] [security2:error] [pid 49578:tid 49745] [client 194.61.41.95:49977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ioxi-o.php"] [unique_id "al4ddbU3yPMQnn6OehdIdgAAAS8"]
[Mon Jul 20 07:07:01.258950 2026] [security2:error] [pid 49578:tid 49677] [remote 124.55.178.99:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4ddbU3yPMQnn6OehdIggABNGI"]
[Mon Jul 20 07:07:01.263304 2026] [security2:error] [pid 49578:tid 49671] [remote 34.75.50.82:35030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.50.75.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ddbU3yPMQnn6OehdIfgABiFw"], referer: https://www.thewelloiledlife.com/login
[Mon Jul 20 07:07:01.271031 2026] [security2:error] [pid 49578:tid 49674] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.git/config"] [unique_id "al4ddbU3yPMQnn6OehdIhAABH18"]
[Mon Jul 20 07:07:01.271604 2026] [security2:error] [pid 49578:tid 49680] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.gitconfig"] [unique_id "al4ddbU3yPMQnn6OehdIhgABH2U"]
[Mon Jul 20 07:07:01.271722 2026] [security2:error] [pid 49578:tid 49729] [client 34.148.53.6:46558] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.areitoproducciones.com"] [uri "/.gitconfig"] [unique_id "al4ddbU3yPMQnn6OehdIhgABH2U"]
[Mon Jul 20 07:07:01.283995 2026] [security2:error] [pid 49578:tid 49676] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/.env"] [unique_id "al4ddbU3yPMQnn6OehdIigABR2E"]
[Mon Jul 20 07:07:01.392280 2026] [security2:error] [pid 49578:tid 49811] [client 65.111.23.188:43119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aandarealtygroup.com"] [uri "/wp-login.php"] [unique_id "al4ddbU3yPMQnn6OehdIjAAAAXE"], referer: https://aandarealtygroup.com/wp-login.php
[Mon Jul 20 07:07:01.546048 2026] [security2:error] [pid 45040:tid 45138] [remote 182.77.62.24:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4ddbEFnm79ltp0SFBd0wAAOV8"]
[Mon Jul 20 07:07:01.676527 2026] [security2:error] [pid 49578:tid 49692] [remote 124.55.178.99:44478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4ddbU3yPMQnn6OehdIoAABRHE"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 07:07:01.694576 2026] [security2:error] [pid 49578:tid 49681] [remote 117.0.21.154:42104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4ddbU3yPMQnn6OehdIoQABJmY"], referer: https://thesoloceos.com/wp-login.php
[Mon Jul 20 07:07:01.730014 2026] [security2:error] [pid 45040:tid 45279] [client 194.61.41.244:43711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/info.php"] [unique_id "al4ddbEFnm79ltp0SFBd2gAAAGs"]
[Mon Jul 20 07:07:01.738495 2026] [security2:error] [pid 49578:tid 49685] [remote 57.141.18.38:58996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3566199"] [unique_id "al4ddbU3yPMQnn6OehdIpAABV2o"]
[Mon Jul 20 07:07:01.922382 2026] [security2:error] [pid 49578:tid 49746] [client 50.116.65.227:22900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ddbU3yPMQnn6OehdIpgAAATA"]
[Mon Jul 20 07:07:01.932806 2026] [security2:error] [pid 45040:tid 45260] [client 50.116.65.227:22906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ddbEFnm79ltp0SFBd4wAAAFg"]
[Mon Jul 20 07:07:01.976194 2026] [security2:error] [pid 49578:tid 49813] [client 117.247.108.24:14133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ddbU3yPMQnn6OehdIpwAAAXM"]
[Mon Jul 20 07:07:01.976385 2026] [security2:error] [pid 49578:tid 49813] [client 117.247.108.24:14133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4ddbU3yPMQnn6OehdIpwAAAXM"]
[Mon Jul 20 07:07:02.032634 2026] [security2:error] [pid 45040:tid 45198] [client 159.89.114.44:50972] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.thegpsapproach.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4ddbEFnm79ltp0SFBd5AAAABo"]
[Mon Jul 20 07:07:02.035971 2026] [security2:error] [pid 45040:tid 45051] [remote 182.77.62.24:56454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4ddrEFnm79ltp0SFBd5wAAAgk"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 07:07:02.041663 2026] [security2:error] [pid 49578:tid 49694] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4ddrU3yPMQnn6OehdIqQABWnM"]
[Mon Jul 20 07:07:02.042084 2026] [security2:error] [pid 49578:tid 49698] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "app.areitoproducciones.com"] [uri "/.git-credentials"] [unique_id "al4ddrU3yPMQnn6OehdIrAABWnc"]
[Mon Jul 20 07:07:02.042187 2026] [security2:error] [pid 49578:tid 49788] [client 34.148.53.6:46558] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "app.areitoproducciones.com"] [uri "/.git-credentials"] [unique_id "al4ddrU3yPMQnn6OehdIrAABWnc"]
[Mon Jul 20 07:07:02.043103 2026] [security2:error] [pid 49578:tid 49696] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/.env.backup"] [unique_id "al4ddrU3yPMQnn6OehdIrQABWnU"]
[Mon Jul 20 07:07:02.065743 2026] [security2:error] [pid 45040:tid 45050] [remote 57.141.18.100:43694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dDrEFnm79ltp0SFBETAAABAg"]
[Mon Jul 20 07:07:02.319529 2026] [security2:error] [pid 49578:tid 49833] [client 34.75.50.82:35030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ddrU3yPMQnn6OehdItgABh30"], referer: https://thewelloiledlife.com/admin
[Mon Jul 20 07:07:02.360125 2026] [security2:error] [pid 49578:tid 49833] [client 34.75.50.82:35030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4ddrU3yPMQnn6OehdItwABh3k"], referer: https://thewelloiledlife.com/app
[Mon Jul 20 07:07:02.370144 2026] [security2:error] [pid 49578:tid 49657] [remote 34.75.50.82:35030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.50.75.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ddrU3yPMQnn6OehdIxQABgk4"], referer: https://www.thewelloiledlife.com/wp-admin/
[Mon Jul 20 07:07:02.451715 2026] [security2:error] [pid 49578:tid 49739] [client 194.61.41.71:58983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/setup.php"] [unique_id "al4ddrU3yPMQnn6OehdIygAAASk"]
[Mon Jul 20 07:07:02.453209 2026] [security2:error] [pid 45040:tid 45045] [remote 57.141.18.50:53446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dFbEFnm79ltp0SFBGEQAABgQ"]
[Mon Jul 20 07:07:02.703002 2026] [security2:error] [pid 45040:tid 45142] [remote 152.228.213.32:42648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4ddrEFnm79ltp0SFBd_QAAaWM"]
[Mon Jul 20 07:07:02.729337 2026] [security2:error] [pid 45040:tid 45224] [client 100.25.153.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ddrEFnm79ltp0SFBd-gAANGw"]
[Mon Jul 20 07:07:02.892371 2026] [security2:error] [pid 49578:tid 49754] [client 20.64.106.118:48878] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "108.179.214.134"] [uri "/index.php"] [unique_id "al4ddrU3yPMQnn6OehdIwAAAATg"]
[Mon Jul 20 07:07:02.892412 2026] [security2:error] [pid 49578:tid 49754] [client 20.64.106.118:48878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "108.179.214.134"] [uri "/index.php"] [unique_id "al4ddrU3yPMQnn6OehdIwAAAATg"]
[Mon Jul 20 07:07:02.932317 2026] [security2:error] [pid 45040:tid 45238] [client 201.27.111.74:55316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ddrEFnm79ltp0SFBeBAAAAEI"]
[Mon Jul 20 07:07:02.932435 2026] [security2:error] [pid 45040:tid 45238] [client 201.27.111.74:55316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ddrEFnm79ltp0SFBeBAAAAEI"]
[Mon Jul 20 07:07:02.935309 2026] [security2:error] [pid 45040:tid 45100] [remote 152.228.213.32:42648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4ddrEFnm79ltp0SFBeAwAATzk"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 07:07:03.115601 2026] [security2:error] [pid 49578:tid 49601] [remote 34.148.53.6:46558] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "app.areitoproducciones.com"] [uri "/backend/.env"] [unique_id "al4dd7U3yPMQnn6OehdI7gABYhY"]
[Mon Jul 20 07:07:03.243844 2026] [security2:error] [pid 49578:tid 49801] [client 194.61.41.92:52347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.bod/.ll/ss.php"] [unique_id "al4dd7U3yPMQnn6OehdI8QAAAWc"]
[Mon Jul 20 07:07:03.317212 2026] [security2:error] [pid 45040:tid 45155] [remote 57.141.18.49:55418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dI7EFnm79ltp0SFBKWgAAOHA"]
[Mon Jul 20 07:07:03.589837 2026] [security2:error] [pid 45040:tid 45237] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4ddbEFnm79ltp0SFBd2QAAAEE"]
[Mon Jul 20 07:07:04.019957 2026] [security2:error] [pid 45040:tid 45204] [client 194.61.41.240:62063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/radio.php"] [unique_id "al4deLEFnm79ltp0SFBeNQAAACA"]
[Mon Jul 20 07:07:04.377944 2026] [security2:error] [pid 45040:tid 45145] [remote 57.141.18.54:62562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dOrEFnm79ltp0SFBRkgAAe2Y"]
[Mon Jul 20 07:07:04.432153 2026] [security2:error] [pid 49578:tid 49796] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4deLU3yPMQnn6OehdJGwAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:04.567640 2026] [security2:error] [pid 49578:tid 49718] [client 14.225.17.146:52164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4ddrU3yPMQnn6OehdI2QAAARQ"], referer: http://areitoproducciones.com/2023
[Mon Jul 20 07:07:04.624595 2026] [security2:error] [pid 49578:tid 49713] [client 52.47.76.32:18984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4deLU3yPMQnn6OehdJKwAAAQ8"]
[Mon Jul 20 07:07:04.624723 2026] [security2:error] [pid 49578:tid 49713] [client 52.47.76.32:18984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4deLU3yPMQnn6OehdJKwAAAQ8"]
[Mon Jul 20 07:07:04.640292 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:63353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4deLU3yPMQnn6OehdJLAAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:04.640388 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:63353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4deLU3yPMQnn6OehdJLAAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:04.753211 2026] [security2:error] [pid 49578:tid 49767] [client 187.16.64.216:50506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4deLU3yPMQnn6OehdJLQAAAUU"]
[Mon Jul 20 07:07:04.753359 2026] [security2:error] [pid 49578:tid 49767] [client 187.16.64.216:50506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4deLU3yPMQnn6OehdJLQAAAUU"]
[Mon Jul 20 07:07:04.763654 2026] [security2:error] [pid 49578:tid 49783] [client 194.61.41.66:45595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugin.php"] [unique_id "al4deLU3yPMQnn6OehdJLwAAAVU"]
[Mon Jul 20 07:07:04.920334 2026] [security2:error] [pid 49578:tid 49766] [client 104.234.53.47:47301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4deLU3yPMQnn6OehdJOwAAAUQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:05.273959 2026] [autoindex:error] [pid 45040:tid 45229] [client 109.199.118.117:0] AH01276: Cannot serve directory /home3/cimexenv/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:07:05.425354 2026] [security2:error] [pid 49578:tid 49716] [client 14.225.17.146:52025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4debU3yPMQnn6OehdJRAAAARI"], referer: http://secretkeynumerology.com/2023
[Mon Jul 20 07:07:05.429715 2026] [security2:error] [pid 45040:tid 45253] [client 14.225.17.146:49995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4dd7EFnm79ltp0SFBeJwAAAFE"], referer: http://tacticaltreeoperations.com/2023
[Mon Jul 20 07:07:05.520980 2026] [security2:error] [pid 49578:tid 49835] [client 14.225.17.146:51660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4dd7U3yPMQnn6OehdI_QAAAYk"], referer: http://floorsourcestock.com/2023
[Mon Jul 20 07:07:05.532534 2026] [security2:error] [pid 45040:tid 45239] [client 194.61.41.67:54189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/ectoplasm/about.php"] [unique_id "al4debEFnm79ltp0SFBeYgAAAEM"]
[Mon Jul 20 07:07:05.897432 2026] [security2:error] [pid 45040:tid 45060] [remote 31.59.129.193:46802] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adastra.love"] [uri "/__/firebase/init.json"] [unique_id "al4debEFnm79ltp0SFBebwAAHxI"]
[Mon Jul 20 07:07:05.897624 2026] [security2:error] [pid 45040:tid 45203] [client 31.59.129.193:46802] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "adastra.love"] [uri "/__/firebase/init.json"] [unique_id "al4debEFnm79ltp0SFBebwAAHxI"]
[Mon Jul 20 07:07:05.927420 2026] [security2:error] [pid 49578:tid 49718] [client 104.234.53.80:20131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4debU3yPMQnn6OehdJagAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:06.331450 2026] [security2:error] [pid 45040:tid 45224] [client 194.61.41.87:48795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/as.php"] [unique_id "al4derEFnm79ltp0SFBegAAAADQ"]
[Mon Jul 20 07:07:06.989110 2026] [security2:error] [pid 45040:tid 45202] [client 14.225.17.146:52063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4derEFnm79ltp0SFBelwAAAB4"], referer: http://grndl.com/2023
[Mon Jul 20 07:07:07.029943 2026] [security2:error] [pid 49578:tid 49815] [client 122.183.32.225:1249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4de7U3yPMQnn6OehdJnAAAAXU"]
[Mon Jul 20 07:07:07.039564 2026] [security2:error] [pid 49578:tid 49815] [client 122.183.32.225:1249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4de7U3yPMQnn6OehdJnAAAAXU"]
[Mon Jul 20 07:07:07.137432 2026] [security2:error] [pid 49578:tid 49721] [client 194.61.41.91:51157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cc.php"] [unique_id "al4de7U3yPMQnn6OehdJnwAAARc"]
[Mon Jul 20 07:07:07.452347 2026] [security2:error] [pid 49578:tid 49628] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/.env"] [unique_id "al4de7U3yPMQnn6OehdJrwABVDE"]
[Mon Jul 20 07:07:07.471212 2026] [security2:error] [pid 49578:tid 49634] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/.aws/config"] [unique_id "al4de7U3yPMQnn6OehdJtgABVDc"]
[Mon Jul 20 07:07:07.570227 2026] [security2:error] [pid 49578:tid 49739] [client 88.241.67.160:53869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4de7U3yPMQnn6OehdJ1AAAASk"]
[Mon Jul 20 07:07:07.571058 2026] [security2:error] [pid 49578:tid 49739] [client 88.241.67.160:53869] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4de7U3yPMQnn6OehdJ1AAAASk"]
[Mon Jul 20 07:07:07.931033 2026] [security2:error] [pid 45040:tid 45200] [client 194.61.41.69:43529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/index.php"] [unique_id "al4de7EFnm79ltp0SFBeugAAABw"]
[Mon Jul 20 07:07:07.972776 2026] [security2:error] [pid 49578:tid 49760] [client 158.173.166.181:38129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4de7U3yPMQnn6OehdJ7AAAAT4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:07:08.073861 2026] [security2:error] [pid 49578:tid 49806] [client 14.225.17.146:62141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4derU3yPMQnn6OehdJggAAAWw"], referer: http://nurturemarple.co.uk/2023
[Mon Jul 20 07:07:08.103736 2026] [security2:error] [pid 49578:tid 49788] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJyQAAAVo"]
[Mon Jul 20 07:07:08.127230 2026] [security2:error] [pid 49578:tid 49710] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJzQAAAQw"]
[Mon Jul 20 07:07:08.211864 2026] [security2:error] [pid 49578:tid 49811] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJzwAAAXE"]
[Mon Jul 20 07:07:08.520036 2026] [ssl:error] [pid 49578:tid 49819] [client 199.45.154.148:55176] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.bruceledewitz.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:07:08.586148 2026] [security2:error] [pid 49578:tid 49731] [client 50.116.65.227:22986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4dfLU3yPMQnn6OehdJ-AAAASE"]
[Mon Jul 20 07:07:08.652894 2026] [security2:error] [pid 49578:tid 49809] [client 194.61.41.58:57125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ab.php"] [unique_id "al4dfLU3yPMQnn6OehdKCQAAAW8"]
[Mon Jul 20 07:07:08.853245 2026] [security2:error] [pid 49578:tid 49773] [client 50.116.65.227:23002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4dfLU3yPMQnn6OehdKBQAAAUs"]
[Mon Jul 20 07:07:08.998961 2026] [security2:error] [pid 49578:tid 49658] [remote 57.141.18.12:42520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2896560"] [unique_id "al4dfLU3yPMQnn6OehdKEwABDE8"]
[Mon Jul 20 07:07:09.028962 2026] [security2:error] [pid 49578:tid 49822] [client 77.110.127.138:63372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dfbU3yPMQnn6OehdKFQAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:09.029061 2026] [security2:error] [pid 49578:tid 49822] [client 77.110.127.138:63372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dfbU3yPMQnn6OehdKFQAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:09.033873 2026] [security2:error] [pid 45040:tid 45299] [client 103.144.65.217:55987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dfbEFnm79ltp0SFBe8wAAAH8"]
[Mon Jul 20 07:07:09.033979 2026] [security2:error] [pid 45040:tid 45299] [client 103.144.65.217:55987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dfbEFnm79ltp0SFBe8wAAAH8"]
[Mon Jul 20 07:07:09.146034 2026] [security2:error] [pid 49578:tid 49784] [client 57.141.18.95:63484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJ7gABVkA"]
[Mon Jul 20 07:07:09.161033 2026] [security2:error] [pid 49578:tid 49733] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dfLU3yPMQnn6OehdKDAAAASM"]
[Mon Jul 20 07:07:09.198744 2026] [security2:error] [pid 49578:tid 49825] [client 14.225.17.146:50766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJqgAAAX8"], referer: http://nwcarvingacademy.com/2023
[Mon Jul 20 07:07:09.422087 2026] [security2:error] [pid 49578:tid 49752] [client 194.61.41.254:57667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/about.php"] [unique_id "al4dfbU3yPMQnn6OehdKMAAAATY"]
[Mon Jul 20 07:07:09.442519 2026] [security2:error] [pid 49578:tid 49759] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJwAAAAT0"]
[Mon Jul 20 07:07:09.452844 2026] [security2:error] [pid 49578:tid 49799] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dfbU3yPMQnn6OehdKKAAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:09.512414 2026] [security2:error] [pid 49578:tid 49778] [client 14.225.17.146:62145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4de7U3yPMQnn6OehdJ3gAAAVA"], referer: http://maplerespiteservices.com/2023
[Mon Jul 20 07:07:09.523153 2026] [security2:error] [pid 45040:tid 45155] [remote 47.86.33.52:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dfbEFnm79ltp0SFBfBgAAQHA"]
[Mon Jul 20 07:07:09.706924 2026] [security2:error] [pid 49578:tid 49727] [client 183.82.98.154:51543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dfbU3yPMQnn6OehdKPwAAAR0"]
[Mon Jul 20 07:07:09.707022 2026] [security2:error] [pid 49578:tid 49727] [client 183.82.98.154:51543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dfbU3yPMQnn6OehdKPwAAAR0"]
[Mon Jul 20 07:07:10.072963 2026] [security2:error] [pid 45040:tid 45157] [remote 47.86.33.52:18354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dfrEFnm79ltp0SFBfHQAAX3I"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:07:10.147858 2026] [security2:error] [pid 49578:tid 49670] [remote 160.187.68.132:49398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dfrU3yPMQnn6OehdKTgABX1s"]
[Mon Jul 20 07:07:10.172467 2026] [security2:error] [pid 49578:tid 49780] [client 194.61.41.253:24335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentytwo/index.php"] [unique_id "al4dfrU3yPMQnn6OehdKUQAAAVI"]
[Mon Jul 20 07:07:10.263556 2026] [security2:error] [pid 49578:tid 49735] [client 14.225.17.146:62078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4dfrU3yPMQnn6OehdKSQAAASU"], referer: https://nwcarvingacademy.com/2023
[Mon Jul 20 07:07:10.397693 2026] [security2:error] [pid 49578:tid 49661] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/backend/.env"] [unique_id "al4dfrU3yPMQnn6OehdKVwABGlI"]
[Mon Jul 20 07:07:10.412666 2026] [security2:error] [pid 49578:tid 49665] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "areitoproducciones.com"] [uri "/.env.bak"] [unique_id "al4dfrU3yPMQnn6OehdKWAABY1Y"]
[Mon Jul 20 07:07:10.432610 2026] [security2:error] [pid 45040:tid 45219] [client 104.234.53.68:51781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4dfrEFnm79ltp0SFBfKAAAAC8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:10.432620 2026] [security2:error] [pid 49578:tid 49677] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/secrets.json"] [unique_id "al4dfrU3yPMQnn6OehdKWgABY2I"]
[Mon Jul 20 07:07:10.575367 2026] [security2:error] [pid 49578:tid 49679] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/.env.backup"] [unique_id "al4dfrU3yPMQnn6OehdKYAABY2Q"]
[Mon Jul 20 07:07:10.575429 2026] [security2:error] [pid 49578:tid 49682] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/secrets.yml"] [unique_id "al4dfrU3yPMQnn6OehdKYwABY2c"]
[Mon Jul 20 07:07:10.575477 2026] [security2:error] [pid 49578:tid 49655] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "areitoproducciones.com"] [uri "/config/.env"] [unique_id "al4dfrU3yPMQnn6OehdKYQABY0w"]
[Mon Jul 20 07:07:10.575482 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "areitoproducciones.com"] [uri "/.env.backup"] [unique_id "al4dfrU3yPMQnn6OehdKYAABY2Q"]
[Mon Jul 20 07:07:10.575718 2026] [security2:error] [pid 49578:tid 49671] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/.env.old"] [unique_id "al4dfrU3yPMQnn6OehdKXQABY1w"]
[Mon Jul 20 07:07:10.576234 2026] [security2:error] [pid 49578:tid 49676] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/api/.env"] [unique_id "al4dfrU3yPMQnn6OehdKYgABY2E"]
[Mon Jul 20 07:07:10.627468 2026] [security2:error] [pid 49578:tid 49692] [remote 160.187.68.132:49398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dfrU3yPMQnn6OehdKawABRnE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:07:10.952829 2026] [security2:error] [pid 49578:tid 49731] [client 194.61.41.67:24469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/doc.php"] [unique_id "al4dfrU3yPMQnn6OehdKdAAAASE"]
[Mon Jul 20 07:07:10.989673 2026] [security2:error] [pid 49578:tid 49801] [client 154.208.48.130:61604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dfrU3yPMQnn6OehdKdQAAAWc"]
[Mon Jul 20 07:07:10.989817 2026] [security2:error] [pid 49578:tid 49801] [client 154.208.48.130:61604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dfrU3yPMQnn6OehdKdQAAAWc"]
[Mon Jul 20 07:07:11.163485 2026] [security2:error] [pid 49578:tid 49722] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dfrU3yPMQnn6OehdKaQAAARg"]
[Mon Jul 20 07:07:11.179721 2026] [security2:error] [pid 49578:tid 49815] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dfrU3yPMQnn6OehdKagAAAXU"]
[Mon Jul 20 07:07:11.387109 2026] [security2:error] [pid 49578:tid 49698] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/.boto"] [unique_id "al4df7U3yPMQnn6OehdKiwABY3c"]
[Mon Jul 20 07:07:11.440165 2026] [security2:error] [pid 49578:tid 49696] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4df7U3yPMQnn6OehdKjgABY3U"]
[Mon Jul 20 07:07:11.440372 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "areitoproducciones.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4df7U3yPMQnn6OehdKjgABY3U"]
[Mon Jul 20 07:07:11.468552 2026] [authz_core:error] [pid 49578:tid 49817] [client 34.148.53.6:0] AH01630: client denied by server configuration: /home3/folehnmy/public_html/.htpasswd
[Mon Jul 20 07:07:11.594782 2026] [core:error] [pid 49578:tid 49796] [client 14.225.17.146:50886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2023
[Mon Jul 20 07:07:11.594802 2026] [core:error] [pid 49578:tid 49796] [client 14.225.17.146:50886] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2023
[Mon Jul 20 07:07:11.721620 2026] [security2:error] [pid 49578:tid 49827] [client 194.61.41.54:32683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/html-api/chosen.php"] [unique_id "al4df7U3yPMQnn6OehdKqQAAAYE"]
[Mon Jul 20 07:07:12.458953 2026] [security2:error] [pid 49578:tid 49713] [client 194.61.41.71:45011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/autoload_classmap.php"] [unique_id "al4dgLU3yPMQnn6OehdKzgAAAQ8"]
[Mon Jul 20 07:07:12.543114 2026] [security2:error] [pid 49578:tid 49581] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/.ssh/id_rsa"] [unique_id "al4dgLU3yPMQnn6OehdK1AABYwI"]
[Mon Jul 20 07:07:12.625231 2026] [security2:error] [pid 45040:tid 45132] [remote 31.59.129.193:46802] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "adastra.love"] [uri "/config.js"] [unique_id "al4dgLEFnm79ltp0SFBfbwAAHVk"]
[Mon Jul 20 07:07:12.907291 2026] [security2:error] [pid 45040:tid 45293] [client 117.247.108.24:15144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dgLEFnm79ltp0SFBfegAAAHk"]
[Mon Jul 20 07:07:12.907429 2026] [security2:error] [pid 45040:tid 45293] [client 117.247.108.24:15144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dgLEFnm79ltp0SFBfegAAAHk"]
[Mon Jul 20 07:07:12.940073 2026] [security2:error] [pid 49578:tid 49796] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dgLU3yPMQnn6OehdK3wAAAWI"]
[Mon Jul 20 07:07:12.944595 2026] [security2:error] [pid 49578:tid 49803] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dgLU3yPMQnn6OehdK3QAAAWk"]
[Mon Jul 20 07:07:12.973036 2026] [security2:error] [pid 49578:tid 49720] [client 14.225.17.146:50781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKjQAAARY"], referer: http://tntcatholic.com/2023
[Mon Jul 20 07:07:12.978278 2026] [security2:error] [pid 49578:tid 49601] [remote 45.90.123.233:38876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dgLU3yPMQnn6OehdK7gABGxY"]
[Mon Jul 20 07:07:12.978469 2026] [security2:error] [pid 49578:tid 49725] [client 45.90.123.233:38876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dgLU3yPMQnn6OehdK7gABGxY"]
[Mon Jul 20 07:07:13.180902 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKkgABY2g"]
[Mon Jul 20 07:07:13.202175 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKjwABY3Y"]
[Mon Jul 20 07:07:13.206319 2026] [security2:error] [pid 49578:tid 49741] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKmwAAASs"]
[Mon Jul 20 07:07:13.231007 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKkQABY28"]
[Mon Jul 20 07:07:13.241684 2026] [security2:error] [pid 49578:tid 49821] [client 194.61.41.60:43409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/mar.php"] [unique_id "al4dgbU3yPMQnn6OehdK_AAAAXs"]
[Mon Jul 20 07:07:13.254305 2026] [security2:error] [pid 49578:tid 49776] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKnQAAAU4"]
[Mon Jul 20 07:07:13.270423 2026] [security2:error] [pid 49578:tid 49585] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/.ssh/id_ed25519"] [unique_id "al4dgbU3yPMQnn6OehdLAQABYwY"]
[Mon Jul 20 07:07:13.312411 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKkwABY3A"]
[Mon Jul 20 07:07:13.322559 2026] [security2:error] [pid 45040:tid 45198] [client 201.27.111.74:55789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dgbEFnm79ltp0SFBffwAAABo"]
[Mon Jul 20 07:07:13.322658 2026] [security2:error] [pid 45040:tid 45198] [client 201.27.111.74:55789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dgbEFnm79ltp0SFBffwAAABo"]
[Mon Jul 20 07:07:13.481498 2026] [security2:error] [pid 49578:tid 49809] [client 14.225.17.146:65399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKrAAAAW8"], referer: http://swafforddetailing.com/2023
[Mon Jul 20 07:07:13.506191 2026] [security2:error] [pid 45040:tid 45115] [remote 57.141.18.41:31816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4dgbEFnm79ltp0SFBfhQAABkg"]
[Mon Jul 20 07:07:13.595401 2026] [autoindex:error] [pid 49578:tid 49790] [client 199.45.155.111:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:07:13.654674 2026] [security2:error] [pid 49578:tid 49734] [client 104.234.53.50:25133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dgbU3yPMQnn6OehdLEgAAASQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:13.951586 2026] [security2:error] [pid 49578:tid 49597] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "areitoproducciones.com"] [uri "/graphql"] [unique_id "al4dgbU3yPMQnn6OehdLLgABYxI"]
[Mon Jul 20 07:07:14.042016 2026] [security2:error] [pid 45040:tid 45185] [client 194.61.41.66:58301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sitemaps/providers/index.php"] [unique_id "al4dgrEFnm79ltp0SFBfmQAAAA0"]
[Mon Jul 20 07:07:14.079491 2026] [security2:error] [pid 45040:tid 45179] [client 50.116.65.227:42348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dgbEFnm79ltp0SFBflAAAAAc"]
[Mon Jul 20 07:07:14.126864 2026] [security2:error] [pid 49578:tid 49808] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dfrU3yPMQnn6OehdKWwAAAW4"]
[Mon Jul 20 07:07:14.131493 2026] [security2:error] [pid 49578:tid 49605] [remote 91.142.222.105:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dgrU3yPMQnn6OehdLNwABCho"]
[Mon Jul 20 07:07:14.150270 2026] [security2:error] [pid 49578:tid 49768] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dgbU3yPMQnn6OehdLJwAAAUY"]
[Mon Jul 20 07:07:14.284128 2026] [security2:error] [pid 49578:tid 49828] [client 50.116.65.227:42374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dgrU3yPMQnn6OehdLNgAAAYI"]
[Mon Jul 20 07:07:14.319784 2026] [security2:error] [pid 49578:tid 49798] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dgLU3yPMQnn6OehdK1gAAAWQ"]
[Mon Jul 20 07:07:14.324487 2026] [security2:error] [pid 49578:tid 49805] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dgLU3yPMQnn6OehdK2wAAAWs"]
[Mon Jul 20 07:07:14.343145 2026] [security2:error] [pid 45040:tid 45191] [client 14.225.17.146:51256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4dgLEFnm79ltp0SFBfeAAAABM"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2023
[Mon Jul 20 07:07:14.380663 2026] [security2:error] [pid 45040:tid 45284] [client 57.141.18.85:52790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dgrEFnm79ltp0SFBfngAAcG4"]
[Mon Jul 20 07:07:14.392175 2026] [security2:error] [pid 49578:tid 49611] [remote 91.142.222.105:53536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dgrU3yPMQnn6OehdLRAABJCA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:07:14.534801 2026] [security2:error] [pid 49578:tid 49714] [client 104.234.53.50:25133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dgrU3yPMQnn6OehdLTgAAARA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:14.745620 2026] [security2:error] [pid 45040:tid 45230] [client 122.183.32.225:14428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.32.183.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dgrEFnm79ltp0SFBfrAAAADo"]
[Mon Jul 20 07:07:14.745777 2026] [security2:error] [pid 45040:tid 45230] [client 122.183.32.225:14428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "momheadquarters.com"] [uri "/xmlrpc.php"] [unique_id "al4dgrEFnm79ltp0SFBfrAAAADo"]
[Mon Jul 20 07:07:14.826531 2026] [security2:error] [pid 45040:tid 45241] [client 194.61.41.63:45727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/wp-conflg.php"] [unique_id "al4dgrEFnm79ltp0SFBfsAAAAEU"]
[Mon Jul 20 07:07:15.021295 2026] [security2:error] [pid 49578:tid 49806] [client 77.110.127.138:63392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dg7U3yPMQnn6OehdLaQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:15.021390 2026] [security2:error] [pid 49578:tid 49806] [client 77.110.127.138:63392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dg7U3yPMQnn6OehdLaQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:15.185269 2026] [security2:error] [pid 45040:tid 45178] [client 114.119.150.252:39083] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "phillipbloch.com"] [uri "/news/view/lupita-in-lip-to-toe-orange"] [unique_id "al4dg7EFnm79ltp0SFBfuwAAAAY"], referer: http://phillipbloch.com/news/P155
[Mon Jul 20 07:07:15.388868 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4df7U3yPMQnn6OehdKigABY3M"]
[Mon Jul 20 07:07:15.395252 2026] [security2:error] [pid 49578:tid 49786] [client 98.159.234.160:20377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dg7U3yPMQnn6OehdLcwAAAVg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:07:15.405660 2026] [security2:error] [pid 49578:tid 49797] [client 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dgLU3yPMQnn6OehdK2AABYwM"]
[Mon Jul 20 07:07:15.409075 2026] [security2:error] [pid 49578:tid 49741] [client 187.16.64.216:51290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dg7U3yPMQnn6OehdLdQAAASs"]
[Mon Jul 20 07:07:15.409168 2026] [security2:error] [pid 49578:tid 49741] [client 187.16.64.216:51290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dg7U3yPMQnn6OehdLdQAAASs"]
[Mon Jul 20 07:07:15.442885 2026] [security2:error] [pid 45040:tid 45138] [remote 173.212.252.15:47024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4dg7EFnm79ltp0SFBfxgAAKl8"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:07:15.531696 2026] [security2:error] [pid 45040:tid 45256] [client 194.61.41.87:48013] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/1.php"] [unique_id "al4dg7EFnm79ltp0SFBfzAAAAFQ"]
[Mon Jul 20 07:07:15.531808 2026] [security2:error] [pid 45040:tid 45256] [client 194.61.41.87:48013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/1.php"] [unique_id "al4dg7EFnm79ltp0SFBfzAAAAFQ"]
[Mon Jul 20 07:07:15.665534 2026] [security2:error] [pid 45040:tid 45203] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dg7EFnm79ltp0SFBfxwAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:15.686488 2026] [security2:error] [pid 45040:tid 45259] [client 14.225.17.146:54212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4dg7EFnm79ltp0SFBfzgAAAFc"], referer: http://adultdaycarereno.com/2023
[Mon Jul 20 07:07:15.733282 2026] [security2:error] [pid 49578:tid 49736] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4dg7U3yPMQnn6OehdLggAAASY"], referer: https://www.google.com/search?q=www.saudalsubaie.com
[Mon Jul 20 07:07:15.874795 2026] [security2:error] [pid 45040:tid 45068] [remote 173.212.252.15:47024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4dg7EFnm79ltp0SFBf2wAAShk"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:07:15.921980 2026] [security2:error] [pid 49578:tid 49815] [client 57.141.18.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4dg7U3yPMQnn6OehdLjgAAAXU"]
[Mon Jul 20 07:07:15.997401 2026] [security2:error] [pid 49578:tid 49811] [client 104.234.53.77:22001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dg7U3yPMQnn6OehdLpgAAAXE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:16.253954 2026] [security2:error] [pid 45040:tid 45260] [client 194.61.41.77:20403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/Diff/Engine/index.php"] [unique_id "al4dhLEFnm79ltp0SFBf5QAAAFg"]
[Mon Jul 20 07:07:16.586678 2026] [security2:error] [pid 45040:tid 45236] [client 14.225.17.146:50968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4dhLEFnm79ltp0SFBf6QAAAEA"], referer: https://adultdaycarereno.com/2023
[Mon Jul 20 07:07:16.640729 2026] [security2:error] [pid 49578:tid 49758] [client 104.234.53.77:22001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dhLU3yPMQnn6OehdLygAAATw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:16.722089 2026] [security2:error] [pid 49578:tid 49735] [client 14.225.17.146:59788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4dg7U3yPMQnn6OehdLpwAAASU"], referer: http://partnerselectricalllc.com/2023
[Mon Jul 20 07:07:16.725407 2026] [security2:error] [pid 49578:tid 49722] [client 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4dhLU3yPMQnn6OehdL0wAAARg"]
[Mon Jul 20 07:07:17.036878 2026] [security2:error] [pid 49578:tid 49668] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/.ssh/id_dsa"] [unique_id "al4dhbU3yPMQnn6OehdL6QABGlk"]
[Mon Jul 20 07:07:17.054686 2026] [security2:error] [pid 45040:tid 45215] [client 194.61.41.107:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/index.php"] [unique_id "al4dhbEFnm79ltp0SFBf9wAAACs"]
[Mon Jul 20 07:07:17.060772 2026] [security2:error] [pid 49578:tid 49819] [client 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4dhbU3yPMQnn6OehdL7gAAAXk"], referer: https://thescarystory.com/wp-login.php
[Mon Jul 20 07:07:17.174459 2026] [security2:error] [pid 49578:tid 49669] [remote 20.153.140.50:34742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4dhbU3yPMQnn6OehdL9AABRFo"]
[Mon Jul 20 07:07:17.354534 2026] [security2:error] [pid 49578:tid 49679] [remote 5.252.52.249:51364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4dhbU3yPMQnn6OehdMBAABaWQ"]
[Mon Jul 20 07:07:17.531339 2026] [security2:error] [pid 49578:tid 49671] [remote 5.252.52.249:51364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4dhbU3yPMQnn6OehdMDAABPVw"], referer: https://allandbeckson.com/wp-login.php
[Mon Jul 20 07:07:17.572454 2026] [security2:error] [pid 49578:tid 49676] [remote 20.153.140.50:34742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4dhbU3yPMQnn6OehdMDgABR2E"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 07:07:17.685889 2026] [security2:error] [pid 45040:tid 45269] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhbEFnm79ltp0SFBf9gAAAGE"]
[Mon Jul 20 07:07:17.738257 2026] [security2:error] [pid 49578:tid 49747] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhbU3yPMQnn6OehdL8AAAATE"]
[Mon Jul 20 07:07:17.818165 2026] [security2:error] [pid 49578:tid 49749] [client 194.61.41.61:26793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/fm.php"] [unique_id "al4dhbU3yPMQnn6OehdMGgAAATM"]
[Mon Jul 20 07:07:18.024141 2026] [security2:error] [pid 49578:tid 49696] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/id_rsa"] [unique_id "al4dhrU3yPMQnn6OehdMKwABGnU"]
[Mon Jul 20 07:07:18.056512 2026] [security2:error] [pid 49578:tid 49816] [client 14.225.17.146:59680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4dhLU3yPMQnn6OehdLzgAAAXY"], referer: http://scott-assist.com/2023
[Mon Jul 20 07:07:18.272722 2026] [security2:error] [pid 49578:tid 49756] [client 88.241.67.160:55622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dhrU3yPMQnn6OehdMPQAAATo"]
[Mon Jul 20 07:07:18.272895 2026] [security2:error] [pid 49578:tid 49756] [client 88.241.67.160:55622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dhrU3yPMQnn6OehdMPQAAATo"]
[Mon Jul 20 07:07:18.385783 2026] [security2:error] [pid 49578:tid 49581] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/privatekey.key"] [unique_id "al4dhrU3yPMQnn6OehdMSwABGgI"]
[Mon Jul 20 07:07:18.386182 2026] [security2:error] [pid 49578:tid 49693] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/id_dsa"] [unique_id "al4dhrU3yPMQnn6OehdMTAABGnI"]
[Mon Jul 20 07:07:18.440535 2026] [security2:error] [pid 49578:tid 49579] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/key.pem"] [unique_id "al4dhrU3yPMQnn6OehdMUQABGgA"]
[Mon Jul 20 07:07:18.543538 2026] [security2:error] [pid 49578:tid 49732] [client 194.61.41.96:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/index.php"] [unique_id "al4dhrU3yPMQnn6OehdMVwAAASI"]
[Mon Jul 20 07:07:19.169079 2026] [security2:error] [pid 45040:tid 45211] [client 14.225.17.146:57281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dhrEFnm79ltp0SFBgHAAAACc"], referer: http://mezzacraft.com/2023
[Mon Jul 20 07:07:19.177820 2026] [security2:error] [pid 49578:tid 49585] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "areitoproducciones.com"] [uri "/api/graphql"] [unique_id "al4dh7U3yPMQnn6OehdMdAABGgY"]
[Mon Jul 20 07:07:19.193260 2026] [security2:error] [pid 49578:tid 49821] [client 14.225.17.146:59731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4dhrU3yPMQnn6OehdMMwAAAXs"], referer: http://ncsynchro.com/2023
[Mon Jul 20 07:07:19.219537 2026] [security2:error] [pid 49578:tid 49593] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "areitoproducciones.com"] [uri "/localhost.key"] [unique_id "al4dh7U3yPMQnn6OehdMfgABGg4"]
[Mon Jul 20 07:07:19.240506 2026] [security2:error] [pid 45040:tid 45182] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhrEFnm79ltp0SFBgEQAAAAo"]
[Mon Jul 20 07:07:19.258958 2026] [security2:error] [pid 45040:tid 45253] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhrEFnm79ltp0SFBgEwAAAFE"]
[Mon Jul 20 07:07:19.283698 2026] [security2:error] [pid 49578:tid 49796] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhbU3yPMQnn6OehdL5gAAAWI"]
[Mon Jul 20 07:07:19.321879 2026] [security2:error] [pid 49578:tid 49830] [client 194.61.41.244:52845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/wp-conflg.php"] [unique_id "al4dh7U3yPMQnn6OehdMigAAAYQ"]
[Mon Jul 20 07:07:19.413675 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:63411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dh7U3yPMQnn6OehdMjwAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:19.413835 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:63411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dh7U3yPMQnn6OehdMjwAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:19.484344 2026] [security2:error] [pid 49578:tid 49716] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhrU3yPMQnn6OehdMUgAAARI"]
[Mon Jul 20 07:07:19.524226 2026] [security2:error] [pid 49578:tid 49608] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "areitoproducciones.com"] [uri "/.openclaw/.env"] [unique_id "al4dh7U3yPMQnn6OehdMoQABGh0"]
[Mon Jul 20 07:07:19.659678 2026] [security2:error] [pid 49578:tid 49723] [client 14.225.17.146:50767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4dhbU3yPMQnn6OehdMGQAAARk"], referer: http://ccsdifference.com/2023
[Mon Jul 20 07:07:19.662522 2026] [security2:error] [pid 49578:tid 49739] [client 103.144.65.217:56445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dh7U3yPMQnn6OehdMsAAAASk"]
[Mon Jul 20 07:07:19.662627 2026] [security2:error] [pid 49578:tid 49739] [client 103.144.65.217:56445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dh7U3yPMQnn6OehdMsAAAASk"]
[Mon Jul 20 07:07:19.789591 2026] [security2:error] [pid 49578:tid 49828] [client 74.7.227.179:43666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMrgABgiI"], referer: https://tejasenvironmental.com/p=178802
[Mon Jul 20 07:07:19.832677 2026] [security2:error] [pid 49578:tid 49785] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMrAAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:20.125720 2026] [security2:error] [pid 49578:tid 49805] [client 154.208.48.130:62160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4diLU3yPMQnn6OehdM1AAAAWs"]
[Mon Jul 20 07:07:20.125872 2026] [security2:error] [pid 49578:tid 49805] [client 154.208.48.130:62160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4diLU3yPMQnn6OehdM1AAAAWs"]
[Mon Jul 20 07:07:20.156873 2026] [security2:error] [pid 49578:tid 49782] [client 194.61.41.252:23203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/file.php"] [unique_id "al4diLU3yPMQnn6OehdM1gAAAVQ"]
[Mon Jul 20 07:07:20.441278 2026] [security2:error] [pid 49578:tid 49784] [client 183.82.98.154:45724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4diLU3yPMQnn6OehdM6QAAAVY"]
[Mon Jul 20 07:07:20.441378 2026] [security2:error] [pid 49578:tid 49784] [client 183.82.98.154:45724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4diLU3yPMQnn6OehdM6QAAAVY"]
[Mon Jul 20 07:07:20.626254 2026] [security2:error] [pid 49578:tid 49823] [client 14.225.17.146:60114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4diLU3yPMQnn6OehdM7AAAAX0"], referer: https://ccsdifference.com/2023
[Mon Jul 20 07:07:20.665039 2026] [security2:error] [pid 49578:tid 49644] [remote 152.228.213.32:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omegacompass.com"] [uri "/wp-login.php"] [unique_id "al4diLU3yPMQnn6OehdM_gABbkE"]
[Mon Jul 20 07:07:20.831473 2026] [security2:error] [pid 49578:tid 49745] [client 113.160.97.242:50660] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4diLU3yPMQnn6OehdNDwAAAS8"]
[Mon Jul 20 07:07:20.854147 2026] [security2:error] [pid 49578:tid 49635] [remote 152.228.213.32:54276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omegacompass.com"] [uri "/wp-login.php"] [unique_id "al4diLU3yPMQnn6OehdNEQABgTg"], referer: https://omegacompass.com/wp-login.php
[Mon Jul 20 07:07:20.926474 2026] [security2:error] [pid 49578:tid 49788] [client 194.61.41.55:32673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4diLU3yPMQnn6OehdNFQAAAVo"]
[Mon Jul 20 07:07:21.494877 2026] [security2:error] [pid 45040:tid 45285] [client 74.208.214.194:39688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dibEFnm79ltp0SFBgTQAAAHE"]
[Mon Jul 20 07:07:21.648501 2026] [security2:error] [pid 49578:tid 49806] [client 194.61.41.99:35303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/fm.php"] [unique_id "al4dibU3yPMQnn6OehdNLQAAAWw"]
[Mon Jul 20 07:07:21.936477 2026] [security2:error] [pid 49578:tid 49749] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4dibU3yPMQnn6OehdNJQABM0c"], referer: http://ardhalwafaa.com/2023
[Mon Jul 20 07:07:21.984122 2026] [security2:error] [pid 49578:tid 49791] [client 31.59.129.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4dibU3yPMQnn6OehdNNQAAAV0"]
[Mon Jul 20 07:07:22.272406 2026] [security2:error] [pid 49578:tid 49794] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMhgAAAWA"]
[Mon Jul 20 07:07:22.275634 2026] [security2:error] [pid 45040:tid 45251] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7EFnm79ltp0SFBgJQAAAE8"]
[Mon Jul 20 07:07:22.363950 2026] [security2:error] [pid 49578:tid 49747] [client 14.225.17.146:57302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4dibU3yPMQnn6OehdNPQAAATE"]
[Mon Jul 20 07:07:22.416827 2026] [security2:error] [pid 49578:tid 49769] [client 194.61.41.243:33949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/cloud.php"] [unique_id "al4dirU3yPMQnn6OehdNVAAAAUc"]
[Mon Jul 20 07:07:22.619795 2026] [security2:error] [pid 45040:tid 45181] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4dirEFnm79ltp0SFBgawAAAAk"]
[Mon Jul 20 07:07:23.148341 2026] [security2:error] [pid 49578:tid 49749] [client 194.61.41.106:44373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/adminfuns.php7"] [unique_id "al4di7U3yPMQnn6OehdNbwAAATM"]
[Mon Jul 20 07:07:23.251011 2026] [security2:error] [pid 49578:tid 49586] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMmwABGgc"]
[Mon Jul 20 07:07:23.306038 2026] [security2:error] [pid 49578:tid 49616] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMngABGiU"]
[Mon Jul 20 07:07:23.480081 2026] [autoindex:error] [pid 49578:tid 49580] [remote 34.48.227.185:50896] AH01276: Cannot serve directory /home2/zajlqimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://zaj.lqi.mybluehost.me
[Mon Jul 20 07:07:23.676046 2026] [security2:error] [pid 45040:tid 45277] [client 201.27.111.74:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4di7EFnm79ltp0SFBgjQAAAGk"]
[Mon Jul 20 07:07:23.676166 2026] [security2:error] [pid 45040:tid 45277] [client 201.27.111.74:56260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4di7EFnm79ltp0SFBgjQAAAGk"]
[Mon Jul 20 07:07:23.702509 2026] [security2:error] [pid 49578:tid 49717] [client 117.247.108.24:15483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4di7U3yPMQnn6OehdNjQAAARM"]
[Mon Jul 20 07:07:23.702611 2026] [security2:error] [pid 49578:tid 49717] [client 117.247.108.24:15483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4di7U3yPMQnn6OehdNjQAAARM"]
[Mon Jul 20 07:07:23.858880 2026] [security2:error] [pid 49578:tid 49701] [remote 152.228.213.32:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4di7U3yPMQnn6OehdNlwABCno"]
[Mon Jul 20 07:07:23.942543 2026] [security2:error] [pid 49578:tid 49741] [client 194.61.41.57:57985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/about.php"] [unique_id "al4di7U3yPMQnn6OehdNnAAAASs"]
[Mon Jul 20 07:07:24.117605 2026] [security2:error] [pid 49578:tid 49596] [remote 152.228.213.32:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4djLU3yPMQnn6OehdNpgABSxE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:07:24.156833 2026] [security2:error] [pid 49578:tid 49607] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMlQABGhw"]
[Mon Jul 20 07:07:24.158202 2026] [security2:error] [pid 49578:tid 49672] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMoAABGl0"]
[Mon Jul 20 07:07:24.169335 2026] [security2:error] [pid 49578:tid 49598] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMpAABGhM"]
[Mon Jul 20 07:07:24.172220 2026] [security2:error] [pid 49578:tid 49742] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dhbU3yPMQnn6OehdMKAAAASw"]
[Mon Jul 20 07:07:24.218567 2026] [security2:error] [pid 49578:tid 49673] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMmgABGl4"]
[Mon Jul 20 07:07:24.230430 2026] [security2:error] [pid 49578:tid 49815] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMqAAAAXU"]
[Mon Jul 20 07:07:24.230430 2026] [security2:error] [pid 49578:tid 49798] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMpQAAAWQ"]
[Mon Jul 20 07:07:24.265908 2026] [security2:error] [pid 49578:tid 49678] [remote 34.148.53.6:59038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMnAABGmM"]
[Mon Jul 20 07:07:24.294644 2026] [security2:error] [pid 49578:tid 49794] [client 77.110.127.138:63427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4djLU3yPMQnn6OehdNsgAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:24.294736 2026] [security2:error] [pid 49578:tid 49794] [client 77.110.127.138:63427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4djLU3yPMQnn6OehdNsgAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:24.666185 2026] [security2:error] [pid 49578:tid 49722] [client 192.140.149.97:44474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4djLU3yPMQnn6OehdNywAAARg"]
[Mon Jul 20 07:07:24.666309 2026] [security2:error] [pid 49578:tid 49722] [client 192.140.149.97:44474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4djLU3yPMQnn6OehdNywAAARg"]
[Mon Jul 20 07:07:24.718206 2026] [security2:error] [pid 45040:tid 45263] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4djLEFnm79ltp0SFBgoAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:24.755487 2026] [security2:error] [pid 49578:tid 49753] [client 194.61.41.73:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ini.php"] [unique_id "al4djLU3yPMQnn6OehdNzwAAATc"]
[Mon Jul 20 07:07:24.894603 2026] [security2:error] [pid 49578:tid 49763] [client 104.234.53.73:51559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4djLU3yPMQnn6OehdN0QAAAUE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:25.129634 2026] [security2:error] [pid 45040:tid 45052] [remote 113.160.142.119:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgeamazon.com"] [uri "/wp-login.php"] [unique_id "al4djbEFnm79ltp0SFBgqwAABAo"]
[Mon Jul 20 07:07:25.200676 2026] [security2:error] [pid 45040:tid 45195] [client 178.221.235.98:50981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4djbEFnm79ltp0SFBgqgAAABc"]
[Mon Jul 20 07:07:25.412662 2026] [security2:error] [pid 49578:tid 49778] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMggAAAVA"]
[Mon Jul 20 07:07:25.497435 2026] [security2:error] [pid 45040:tid 45174] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4djbEFnm79ltp0SFBgrgAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:25.545417 2026] [security2:error] [pid 45040:tid 45219] [client 194.61.41.86:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/coffee/cloud.php"] [unique_id "al4djbEFnm79ltp0SFBgvAAAAC8"]
[Mon Jul 20 07:07:25.670087 2026] [security2:error] [pid 45040:tid 45070] [remote 113.160.142.119:40872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgeamazon.com"] [uri "/wp-login.php"] [unique_id "al4djbEFnm79ltp0SFBgvwAARxs"], referer: https://bridgeamazon.com/wp-login.php
[Mon Jul 20 07:07:25.883743 2026] [security2:error] [pid 49578:tid 49813] [client 14.225.17.146:57239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4djbU3yPMQnn6OehdN9gAAAXM"]
[Mon Jul 20 07:07:25.950831 2026] [security2:error] [pid 49578:tid 49782] [client 14.225.17.146:60053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4djLU3yPMQnn6OehdNxgAAAVQ"], referer: http://ghivs.com/2023
[Mon Jul 20 07:07:26.054490 2026] [security2:error] [pid 49578:tid 49775] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dh7U3yPMQnn6OehdMmQAAAU0"]
[Mon Jul 20 07:07:26.075283 2026] [security2:error] [pid 49578:tid 49818] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4diLU3yPMQnn6OehdM5gAAAXg"]
[Mon Jul 20 07:07:26.079617 2026] [security2:error] [pid 49578:tid 49603] [remote 34.148.53.6:59038] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "areitoproducciones.com"] [uri "/v1/graphql"] [unique_id "al4diLU3yPMQnn6OehdOHgABhRg"]
[Mon Jul 20 07:07:26.136311 2026] [security2:error] [pid 49578:tid 49768] [client 50.116.65.227:17586] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4djrU3yPMQnn6OehdOJAAAAUY"]
[Mon Jul 20 07:07:26.146833 2026] [security2:error] [pid 45040:tid 45222] [client 50.116.65.227:17594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4djrEFnm79ltp0SFBgzwAAADI"]
[Mon Jul 20 07:07:26.190074 2026] [security2:error] [pid 49578:tid 49715] [client 187.16.64.216:51895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4djrU3yPMQnn6OehdOJgAAARE"]
[Mon Jul 20 07:07:26.190193 2026] [security2:error] [pid 49578:tid 49715] [client 187.16.64.216:51895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4djrU3yPMQnn6OehdOJgAAARE"]
[Mon Jul 20 07:07:26.215288 2026] [security2:error] [pid 49578:tid 49777] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4djbU3yPMQnn6OehdOEwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:26.217392 2026] [security2:error] [pid 49578:tid 49631] [remote 192.241.143.148:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4djrU3yPMQnn6OehdOJwABIDQ"]
[Mon Jul 20 07:07:26.324596 2026] [security2:error] [pid 49578:tid 49806] [client 194.61.41.66:39735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/blocks/calendar/index.php"] [unique_id "al4djrU3yPMQnn6OehdOKwAAAWw"]
[Mon Jul 20 07:07:26.409328 2026] [security2:error] [pid 49578:tid 49649] [remote 192.241.143.148:51668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4djrU3yPMQnn6OehdONgABKEY"], referer: https://dlu.cjf.mybluehost.me/blog/wp-login.php
[Mon Jul 20 07:07:26.772881 2026] [security2:error] [pid 49578:tid 49651] [remote 18.61.192.253:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4djrU3yPMQnn6OehdOUAABaUg"]
[Mon Jul 20 07:07:26.773132 2026] [security2:error] [pid 49578:tid 49803] [client 18.61.192.253:43706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4djrU3yPMQnn6OehdOUAABaUg"]
[Mon Jul 20 07:07:26.829169 2026] [security2:error] [pid 49578:tid 49653] [remote 152.228.213.32:33544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4djrU3yPMQnn6OehdOUgABV0o"]
[Mon Jul 20 07:07:26.829352 2026] [security2:error] [pid 49578:tid 49785] [client 152.228.213.32:33544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4djrU3yPMQnn6OehdOUgABV0o"]
[Mon Jul 20 07:07:26.831874 2026] [security2:error] [pid 49578:tid 49787] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4djrU3yPMQnn6OehdOQwAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:27.038674 2026] [security2:error] [pid 49578:tid 49808] [client 194.61.41.73:56167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/fix/up.php"] [unique_id "al4dj7U3yPMQnn6OehdOXgAAAW4"]
[Mon Jul 20 07:07:27.216816 2026] [core:error] [pid 45040:tid 45259] [client 14.225.17.146:59047] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2023
[Mon Jul 20 07:07:27.216836 2026] [core:error] [pid 45040:tid 45259] [client 14.225.17.146:59047] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2023
[Mon Jul 20 07:07:27.313244 2026] [security2:error] [pid 49578:tid 49753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dj7U3yPMQnn6OehdOZgAAATc"]
[Mon Jul 20 07:07:27.761429 2026] [security2:error] [pid 49578:tid 49780] [client 14.225.17.146:58738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4dj7U3yPMQnn6OehdOfAAAAVI"], referer: http://laceycaraccident.com/2023
[Mon Jul 20 07:07:27.767502 2026] [security2:error] [pid 49578:tid 49735] [client 185.223.152.104:23425] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "nevelow.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4dj7U3yPMQnn6OehdOgwAAASU"]
[Mon Jul 20 07:07:27.802236 2026] [security2:error] [pid 49578:tid 49744] [client 122.176.107.52:29473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.107.176.122.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cira.org"] [uri "/xmlrpc.php"] [unique_id "al4dj7U3yPMQnn6OehdOhQAAAS4"]
[Mon Jul 20 07:07:27.802368 2026] [security2:error] [pid 49578:tid 49744] [client 122.176.107.52:29473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cira.org"] [uri "/xmlrpc.php"] [unique_id "al4dj7U3yPMQnn6OehdOhQAAAS4"]
[Mon Jul 20 07:07:27.845815 2026] [security2:error] [pid 49578:tid 49757] [client 194.61.41.93:48455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/atomlib.php"] [unique_id "al4dj7U3yPMQnn6OehdOhgAAATs"]
[Mon Jul 20 07:07:28.350669 2026] [security2:error] [pid 49578:tid 49665] [remote 103.161.172.221:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4dkLU3yPMQnn6OehdOrwABPFY"]
[Mon Jul 20 07:07:28.448266 2026] [security2:error] [pid 49578:tid 49686] [remote 199.189.225.40:58915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4dkLU3yPMQnn6OehdOuQABDms"]
[Mon Jul 20 07:07:28.507782 2026] [security2:error] [pid 49578:tid 49826] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dkLU3yPMQnn6OehdOrAAAAYA"]
[Mon Jul 20 07:07:28.528200 2026] [security2:error] [pid 49578:tid 49733] [client 57.141.18.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4dkLU3yPMQnn6OehdOtQAAASM"]
[Mon Jul 20 07:07:28.633149 2026] [security2:error] [pid 49578:tid 49764] [client 194.61.41.87:41561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/instaall.php"] [unique_id "al4dkLU3yPMQnn6OehdOzQAAAUI"]
[Mon Jul 20 07:07:28.701697 2026] [security2:error] [pid 49578:tid 49580] [remote 199.189.225.40:58915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4dkLU3yPMQnn6OehdO0wABWgE"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:07:28.743605 2026] [security2:error] [pid 49578:tid 49674] [remote 103.161.172.221:38828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4dkLU3yPMQnn6OehdO1QABVl8"], referer: https://jvcmotorsports.com/wp-login.php
[Mon Jul 20 07:07:28.805424 2026] [security2:error] [pid 49578:tid 49825] [client 207.175.93.198:50555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lue.sup.mybluehost.me"] [uri "/index.php"] [unique_id "al4dkLU3yPMQnn6OehdOzgAAAX8"]
[Mon Jul 20 07:07:28.826863 2026] [security2:error] [pid 49578:tid 49768] [client 88.241.67.160:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dkLU3yPMQnn6OehdO2gAAAUY"]
[Mon Jul 20 07:07:28.827146 2026] [security2:error] [pid 49578:tid 49768] [client 88.241.67.160:57300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dkLU3yPMQnn6OehdO2gAAAUY"]
[Mon Jul 20 07:07:29.017959 2026] [security2:error] [pid 49578:tid 49741] [client 14.225.17.146:58559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4dj7U3yPMQnn6OehdOfgAAASs"], referer: http://thechancersband.com/2023
[Mon Jul 20 07:07:29.073518 2026] [security2:error] [pid 49578:tid 49791] [client 20.118.232.75:54086] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.64.27"] [uri "/index.cgi"] [unique_id "al4dkbU3yPMQnn6OehdO6QAAAV0"]
[Mon Jul 20 07:07:29.090687 2026] [security2:error] [pid 49578:tid 49824] [client 207.175.93.198:50555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.93.175.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lue.sup.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dkbU3yPMQnn6OehdO6gAAAX4"]
[Mon Jul 20 07:07:29.090794 2026] [security2:error] [pid 49578:tid 49824] [client 207.175.93.198:50555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lue.sup.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dkbU3yPMQnn6OehdO6gAAAX4"]
[Mon Jul 20 07:07:29.222547 2026] [ssl:error] [pid 49578:tid 49762] [client 199.45.154.114:35268] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.allandbeckson.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:07:29.362942 2026] [security2:error] [pid 45040:tid 45295] [client 194.61.41.97:38801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/function.php"] [unique_id "al4dkbEFnm79ltp0SFBhEgAAAHs"]
[Mon Jul 20 07:07:29.469296 2026] [security2:error] [pid 49578:tid 49798] [client 77.110.127.138:63454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dkbU3yPMQnn6OehdPAQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:29.469386 2026] [security2:error] [pid 49578:tid 49798] [client 77.110.127.138:63454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dkbU3yPMQnn6OehdPAQAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:29.661208 2026] [security2:error] [pid 49578:tid 49779] [client 104.234.53.73:51559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dkbU3yPMQnn6OehdPDAAAAVE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:29.684067 2026] [security2:error] [pid 49578:tid 49825] [client 207.175.93.198:53074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.93.175.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lue.sup.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dkbU3yPMQnn6OehdPEAAAAX8"]
[Mon Jul 20 07:07:29.684196 2026] [security2:error] [pid 49578:tid 49825] [client 207.175.93.198:53074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lue.sup.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dkbU3yPMQnn6OehdPEAAAAX8"]
[Mon Jul 20 07:07:29.835830 2026] [security2:error] [pid 45040:tid 45090] [remote 13.232.189.155:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.botanicapatterndesigns.com"] [uri "/wp-login.php"] [unique_id "al4dkbEFnm79ltp0SFBhJgAAFC8"]
[Mon Jul 20 07:07:30.104712 2026] [security2:error] [pid 49578:tid 49731] [client 14.225.17.146:58816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4dkbU3yPMQnn6OehdO7AAAASE"], referer: http://ancestralidadytrance.space/2023
[Mon Jul 20 07:07:30.135736 2026] [security2:error] [pid 49578:tid 49806] [client 194.61.41.91:20347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/plugins.php"] [unique_id "al4dkrU3yPMQnn6OehdPLAAAAWw"]
[Mon Jul 20 07:07:30.217726 2026] [security2:error] [pid 45040:tid 45254] [client 103.144.65.217:56912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dkrEFnm79ltp0SFBhLAAAAFI"]
[Mon Jul 20 07:07:30.218292 2026] [security2:error] [pid 45040:tid 45254] [client 103.144.65.217:56912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dkrEFnm79ltp0SFBhLAAAAFI"]
[Mon Jul 20 07:07:30.238829 2026] [security2:error] [pid 49578:tid 49824] [client 45.157.112.60:27009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dkrU3yPMQnn6OehdPNgAAAX4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:07:30.264919 2026] [security2:error] [pid 45040:tid 45120] [remote 13.232.189.155:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.botanicapatterndesigns.com"] [uri "/wp-login.php"] [unique_id "al4dkrEFnm79ltp0SFBhLwAAS00"], referer: https://mail.botanicapatterndesigns.com/wp-login.php
[Mon Jul 20 07:07:30.940643 2026] [security2:error] [pid 45040:tid 45293] [client 194.61.41.84:28417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/atomlib.php"] [unique_id "al4dkrEFnm79ltp0SFBhQgAAAHk"]
[Mon Jul 20 07:07:31.067340 2026] [security2:error] [pid 49578:tid 49775] [client 183.82.98.154:52708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dk7U3yPMQnn6OehdPcQAAAU0"]
[Mon Jul 20 07:07:31.067506 2026] [security2:error] [pid 49578:tid 49775] [client 183.82.98.154:52708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dk7U3yPMQnn6OehdPcQAAAU0"]
[Mon Jul 20 07:07:31.364910 2026] [security2:error] [pid 49578:tid 49610] [remote 74.235.96.117:46976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dk7U3yPMQnn6OehdPkQABUB8"]
[Mon Jul 20 07:07:31.612211 2026] [security2:error] [pid 45040:tid 45255] [client 154.208.48.130:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dk7EFnm79ltp0SFBhVAAAAFM"]
[Mon Jul 20 07:07:31.612322 2026] [security2:error] [pid 45040:tid 45255] [client 154.208.48.130:62662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dk7EFnm79ltp0SFBhVAAAAFM"]
[Mon Jul 20 07:07:31.680469 2026] [security2:error] [pid 49578:tid 49699] [remote 74.235.96.117:46976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dk7U3yPMQnn6OehdPqAABEHg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:07:31.727401 2026] [security2:error] [pid 49578:tid 49819] [client 194.61.41.87:62457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content.php"] [unique_id "al4dk7U3yPMQnn6OehdPrwAAAXk"]
[Mon Jul 20 07:07:32.148168 2026] [security2:error] [pid 45040:tid 45178] [client 104.234.53.89:28877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dlLEFnm79ltp0SFBhXwAAAAY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:32.156180 2026] [security2:error] [pid 49578:tid 49761] [client 57.141.18.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4dlLU3yPMQnn6OehdPxwAAAT8"]
[Mon Jul 20 07:07:32.303301 2026] [security2:error] [pid 49578:tid 49791] [client 14.225.17.146:61784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4dkrU3yPMQnn6OehdPSgAAAV0"]
[Mon Jul 20 07:07:32.353211 2026] [security2:error] [pid 49578:tid 49714] [client 77.110.127.138:63476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlLU3yPMQnn6OehdP4QAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:32.353289 2026] [security2:error] [pid 49578:tid 49714] [client 77.110.127.138:63476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlLU3yPMQnn6OehdP4QAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:32.433206 2026] [security2:error] [pid 45040:tid 45197] [client 194.61.41.89:34655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/chosen.php"] [unique_id "al4dlLEFnm79ltp0SFBhagAAABk"]
[Mon Jul 20 07:07:32.457206 2026] [security2:error] [pid 49578:tid 49749] [client 14.225.17.146:57750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4dlLU3yPMQnn6OehdP5wAAATM"], referer: http://mourgroup.com/2023
[Mon Jul 20 07:07:32.615822 2026] [security2:error] [pid 49578:tid 49645] [remote 154.66.198.148:17378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4dlLU3yPMQnn6OehdP8gABPEI"]
[Mon Jul 20 07:07:32.686279 2026] [security2:error] [pid 49578:tid 49778] [client 74.208.214.194:45548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dlLU3yPMQnn6OehdP8wAAAVA"]
[Mon Jul 20 07:07:32.728491 2026] [security2:error] [pid 49578:tid 49750] [client 77.110.127.138:63478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlLU3yPMQnn6OehdP9AAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:32.728612 2026] [security2:error] [pid 49578:tid 49750] [client 77.110.127.138:63478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlLU3yPMQnn6OehdP9AAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:32.886700 2026] [security2:error] [pid 49578:tid 49654] [remote 47.86.33.52:56004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dlLU3yPMQnn6OehdP_gABdEs"]
[Mon Jul 20 07:07:33.012865 2026] [security2:error] [pid 49578:tid 49757] [client 77.110.127.138:63484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQDgAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:33.012998 2026] [security2:error] [pid 49578:tid 49757] [client 77.110.127.138:63484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQDgAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:33.048578 2026] [security2:error] [pid 49578:tid 49829] [client 14.225.17.146:60031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4dk7U3yPMQnn6OehdPlwAAAYM"], referer: http://myspineworld.com/2023
[Mon Jul 20 07:07:33.092454 2026] [security2:error] [pid 49578:tid 49808] [client 43.172.198.202:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4dlbU3yPMQnn6OehdQFAAAAW4"], referer: https://www.savilerowtravel.com/?p=2985
[Mon Jul 20 07:07:33.151916 2026] [security2:error] [pid 49578:tid 49744] [client 77.110.127.138:63448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQGgAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:33.152056 2026] [security2:error] [pid 49578:tid 49744] [client 77.110.127.138:63448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQGgAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:33.152322 2026] [security2:error] [pid 49578:tid 49756] [client 194.61.41.73:57539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/Diff/Renderer/about.php"] [unique_id "al4dlbU3yPMQnn6OehdQGwAAATo"]
[Mon Jul 20 07:07:33.218170 2026] [security2:error] [pid 49578:tid 49644] [remote 154.66.198.148:17378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4dlbU3yPMQnn6OehdQHgABJkE"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 07:07:33.288460 2026] [security2:error] [pid 49578:tid 49778] [client 77.110.127.138:63449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQIwAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:33.288560 2026] [security2:error] [pid 49578:tid 49778] [client 77.110.127.138:63449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQIwAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:33.364573 2026] [security2:error] [pid 49578:tid 49777] [client 43.172.197.5:36850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4dlbU3yPMQnn6OehdQJgAAAU8"], referer: https://www.savilerowtravel.com/?p=2985
[Mon Jul 20 07:07:33.453997 2026] [security2:error] [pid 49578:tid 49803] [client 77.110.127.138:63486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQLwAAAWk"]
[Mon Jul 20 07:07:33.454144 2026] [security2:error] [pid 49578:tid 49803] [client 77.110.127.138:63486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQLwAAAWk"]
[Mon Jul 20 07:07:33.550788 2026] [security2:error] [pid 49578:tid 49820] [client 43.172.195.41:49898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4dlbU3yPMQnn6OehdQMwAAAXo"], referer: https://www.savilerowtravel.com/?p=2985
[Mon Jul 20 07:07:33.562393 2026] [security2:error] [pid 49578:tid 49788] [client 43.173.174.162:53704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.174.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4dlbU3yPMQnn6OehdQNQAAAVo"], referer: https://www.savilerowtravel.com/?p=2985
[Mon Jul 20 07:07:33.603021 2026] [security2:error] [pid 49578:tid 49781] [client 77.110.127.138:63488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQOwAAAVM"]
[Mon Jul 20 07:07:33.603111 2026] [security2:error] [pid 49578:tid 49781] [client 77.110.127.138:63488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dlbU3yPMQnn6OehdQOwAAAVM"]
[Mon Jul 20 07:07:33.810900 2026] [security2:error] [pid 49578:tid 49833] [client 14.225.17.146:56160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4dlbU3yPMQnn6OehdQPQAAAYc"], referer: http://mobilesurvsolutions.com/2023
[Mon Jul 20 07:07:33.945208 2026] [security2:error] [pid 45040:tid 45239] [client 194.61.41.251:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/index.php"] [unique_id "al4dlbEFnm79ltp0SFBhhAAAAEM"]
[Mon Jul 20 07:07:34.187261 2026] [security2:error] [pid 45040:tid 45137] [remote 162.19.246.208:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4dlrEFnm79ltp0SFBhkAAAb14"]
[Mon Jul 20 07:07:34.326277 2026] [security2:error] [pid 45040:tid 45198] [client 201.27.111.74:56730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dlrEFnm79ltp0SFBhlgAAABo"]
[Mon Jul 20 07:07:34.326422 2026] [security2:error] [pid 45040:tid 45198] [client 201.27.111.74:56730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dlrEFnm79ltp0SFBhlgAAABo"]
[Mon Jul 20 07:07:34.402623 2026] [security2:error] [pid 45040:tid 45106] [remote 162.19.246.208:52782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4dlrEFnm79ltp0SFBhmwAALT8"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 07:07:34.419779 2026] [security2:error] [pid 49578:tid 49586] [remote 47.86.33.52:56004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4dlrU3yPMQnn6OehdQXwABaQc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:07:34.608684 2026] [security2:error] [pid 45040:tid 45215] [client 117.247.108.24:16957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dlrEFnm79ltp0SFBhoAAAACs"]
[Mon Jul 20 07:07:34.608778 2026] [security2:error] [pid 45040:tid 45215] [client 117.247.108.24:16957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dlrEFnm79ltp0SFBhoAAAACs"]
[Mon Jul 20 07:07:34.645887 2026] [security2:error] [pid 49578:tid 49785] [client 43.173.176.98:36256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4dlrU3yPMQnn6OehdQbgAAAVc"], referer: https://www.savilerowtravel.com/?p=18896
[Mon Jul 20 07:07:34.735567 2026] [security2:error] [pid 45040:tid 45173] [client 194.61.41.244:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/light/about.php"] [unique_id "al4dlrEFnm79ltp0SFBhpwAAAAE"]
[Mon Jul 20 07:07:34.922716 2026] [security2:error] [pid 45040:tid 45235] [client 43.172.195.208:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.195.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4dlrEFnm79ltp0SFBhsAAAAD8"], referer: https://www.savilerowtravel.com/?p=18896
[Mon Jul 20 07:07:35.085105 2026] [security2:error] [pid 49578:tid 49657] [remote 41.185.8.229:37074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dl7U3yPMQnn6OehdQiAABWU4"]
[Mon Jul 20 07:07:35.128287 2026] [security2:error] [pid 49578:tid 49753] [client 43.172.197.101:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4dl7U3yPMQnn6OehdQiwAAATc"], referer: https://www.savilerowtravel.com/?p=18896
[Mon Jul 20 07:07:35.178449 2026] [security2:error] [pid 49578:tid 49741] [client 43.172.197.158:39726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4dl7U3yPMQnn6OehdQjgAAASs"], referer: https://www.savilerowtravel.com/?p=18896
[Mon Jul 20 07:07:35.286949 2026] [security2:error] [pid 45040:tid 45255] [client 104.234.53.47:59443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4dl7EFnm79ltp0SFBhuQAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:35.528035 2026] [security2:error] [pid 49578:tid 49829] [client 194.61.41.93:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/customize.php"] [unique_id "al4dl7U3yPMQnn6OehdQogAAAYM"]
[Mon Jul 20 07:07:35.619922 2026] [security2:error] [pid 49578:tid 49805] [client 14.225.17.146:59356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4dl7U3yPMQnn6OehdQmwAAAWs"], referer: http://mazzucelli.com/2023
[Mon Jul 20 07:07:35.748196 2026] [security2:error] [pid 45040:tid 45224] [client 43.173.173.39:58944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.173.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4dl7EFnm79ltp0SFBhxAAAADQ"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:07:35.787560 2026] [security2:error] [pid 49578:tid 49684] [remote 41.185.8.229:37074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dl7U3yPMQnn6OehdQsQABZ2k"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:36.013713 2026] [security2:error] [pid 45040:tid 45283] [client 43.172.198.145:37672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4dmLEFnm79ltp0SFBhzAAAAG8"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:07:36.073259 2026] [security2:error] [pid 49578:tid 49709] [client 43.173.177.38:54962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4dmLU3yPMQnn6OehdQxwAAAQs"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:07:36.166433 2026] [security2:error] [pid 49578:tid 49800] [client 43.172.198.210:51766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.198.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4dmLU3yPMQnn6OehdQywAAAWY"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:07:36.265536 2026] [security2:error] [pid 49578:tid 49728] [client 194.61.41.100:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/license.php"] [unique_id "al4dmLU3yPMQnn6OehdQ1QAAAR4"]
[Mon Jul 20 07:07:36.591586 2026] [security2:error] [pid 49578:tid 49815] [client 43.154.224.104:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4dmLU3yPMQnn6OehdQ3wABdQ4"], referer: https://www.aleishapenny.ca/listing/page/93?paged=93&view=list
[Mon Jul 20 07:07:36.682466 2026] [security2:error] [pid 45040:tid 45192] [client 57.141.18.41:31788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dmLEFnm79ltp0SFBh1gAAFHc"]
[Mon Jul 20 07:07:36.767180 2026] [security2:error] [pid 49578:tid 49744] [client 43.173.176.173:59032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4dmLU3yPMQnn6OehdQ7gAAAS4"], referer: https://www.savilerowtravel.com/?p=8361
[Mon Jul 20 07:07:36.824927 2026] [security2:error] [pid 49578:tid 49767] [client 43.173.176.240:40236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4dmLU3yPMQnn6OehdQ8wAAAUU"], referer: https://www.savilerowtravel.com/?p=8361
[Mon Jul 20 07:07:36.840728 2026] [security2:error] [pid 49578:tid 49783] [client 43.173.178.27:55790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.178.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4dmLU3yPMQnn6OehdQ8QAAAVU"], referer: https://www.savilerowtravel.com/?p=8361
[Mon Jul 20 07:07:36.846639 2026] [security2:error] [pid 49578:tid 49810] [client 187.16.64.216:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dmLU3yPMQnn6OehdQ9QAAAXA"]
[Mon Jul 20 07:07:36.846726 2026] [security2:error] [pid 49578:tid 49810] [client 187.16.64.216:52482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dmLU3yPMQnn6OehdQ9QAAAXA"]
[Mon Jul 20 07:07:36.890187 2026] [security2:error] [pid 45040:tid 45258] [client 114.119.146.109:63291] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karimnawfal.com"] [uri "/Dr-Karim-Nawfal/photo/thumb/2.jpg"] [unique_id "al4dmLEFnm79ltp0SFBh4QAAAFY"], referer: http://karimnawfal.com/Dr-Karim-Nawfal/photo/thumb/2.jpg
[Mon Jul 20 07:07:37.040640 2026] [security2:error] [pid 45040:tid 45214] [client 194.61.41.87:26805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/autoload_classmap.php"] [unique_id "al4dmbEFnm79ltp0SFBh5wAAACo"]
[Mon Jul 20 07:07:37.130304 2026] [security2:error] [pid 49578:tid 49797] [client 14.225.17.146:61639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4dmbU3yPMQnn6OehdQ_QAAAWM"], referer: http://daseighty.net/2023
[Mon Jul 20 07:07:37.152548 2026] [security2:error] [pid 49578:tid 49769] [client 158.173.89.95:38941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dmbU3yPMQnn6OehdRBwAAAUc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:07:37.181806 2026] [security2:error] [pid 49578:tid 49813] [client 14.225.17.146:59669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4dmLU3yPMQnn6OehdQ7AAAAXM"], referer: http://onewingpictures.com/2023
[Mon Jul 20 07:07:37.286534 2026] [security2:error] [pid 45040:tid 45246] [client 204.168.211.95:38272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4dmbEFnm79ltp0SFBh6gAAAEo"], referer: https://www.google.com/search?q=www.saudalsubaie.com
[Mon Jul 20 07:07:37.292065 2026] [security2:error] [pid 49578:tid 49830] [client 204.168.211.95:38254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4dmbU3yPMQnn6OehdRAQAAAYQ"]
[Mon Jul 20 07:07:37.327842 2026] [security2:error] [pid 49578:tid 49729] [client 204.168.211.95:38258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4dmbU3yPMQnn6OehdRCgAAAR8"]
[Mon Jul 20 07:07:37.331931 2026] [security2:error] [pid 45040:tid 45293] [client 43.173.177.223:49464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.177.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4dmbEFnm79ltp0SFBh9AAAAHk"], referer: https://www.savilerowtravel.com/?p=8361
[Mon Jul 20 07:07:37.382949 2026] [security2:error] [pid 49578:tid 49731] [client 104.234.53.49:53861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dmbU3yPMQnn6OehdRHQAAASE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:37.845869 2026] [security2:error] [pid 49578:tid 49794] [client 194.61.41.64:22093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/lock.php"] [unique_id "al4dmbU3yPMQnn6OehdRLgAAAWA"]
[Mon Jul 20 07:07:37.863550 2026] [security2:error] [pid 45040:tid 45174] [client 14.225.17.146:57655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4dmLEFnm79ltp0SFBh3AAAAAI"], referer: http://whiteoutcb.com/2023
[Mon Jul 20 07:07:37.942981 2026] [security2:error] [pid 45040:tid 45217] [client 14.225.17.146:61791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4dmbEFnm79ltp0SFBiBQAAAC0"]
[Mon Jul 20 07:07:38.277762 2026] [security2:error] [pid 45040:tid 45076] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dmrEFnm79ltp0SFBiDgAAZiE"]
[Mon Jul 20 07:07:38.277919 2026] [security2:error] [pid 45040:tid 45274] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dmrEFnm79ltp0SFBiDgAAZiE"]
[Mon Jul 20 07:07:38.359070 2026] [security2:error] [pid 49578:tid 49746] [client 77.110.127.138:63537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dmrU3yPMQnn6OehdRUgAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:38.359174 2026] [security2:error] [pid 49578:tid 49746] [client 77.110.127.138:63537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dmrU3yPMQnn6OehdRUgAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:38.623880 2026] [security2:error] [pid 49578:tid 49726] [client 194.61.41.56:32789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/gold.php"] [unique_id "al4dmrU3yPMQnn6OehdRYAAAARw"]
[Mon Jul 20 07:07:39.034547 2026] [security2:error] [pid 49578:tid 49748] [client 14.225.17.146:61752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4dmrU3yPMQnn6OehdRbAAAATI"], referer: http://falconarrowshop.com/2023
[Mon Jul 20 07:07:39.284400 2026] [access_compat:error] [pid 49578:tid 49725] [client 183.47.107.19:54413] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:07:39.436000 2026] [security2:error] [pid 45040:tid 45245] [client 194.61.41.58:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/atomlib.php"] [unique_id "al4dm7EFnm79ltp0SFBiKQAAAEk"]
[Mon Jul 20 07:07:39.614569 2026] [security2:error] [pid 45040:tid 45296] [client 88.241.67.160:56768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dm7EFnm79ltp0SFBiLAAAAHw"]
[Mon Jul 20 07:07:39.614692 2026] [security2:error] [pid 45040:tid 45296] [client 88.241.67.160:56768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dm7EFnm79ltp0SFBiLAAAAHw"]
[Mon Jul 20 07:07:39.614843 2026] [security2:error] [pid 49578:tid 49817] [client 2a01:4f9:c015:5c7c::1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4dm7U3yPMQnn6OehdRkQAAAXc"]
[Mon Jul 20 07:07:40.272847 2026] [security2:error] [pid 49578:tid 49802] [client 194.61.41.98:43969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/rest-api/index.php"] [unique_id "al4dnLU3yPMQnn6OehdRywAAAWg"]
[Mon Jul 20 07:07:40.534231 2026] [security2:error] [pid 49578:tid 49800] [client 170.64.227.219:52759] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.massagelacey.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4dnLU3yPMQnn6OehdR2QAAAWY"]
[Mon Jul 20 07:07:40.655102 2026] [security2:error] [pid 49578:tid 49680] [remote 47.86.33.52:65252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dnLU3yPMQnn6OehdR5AABXmU"]
[Mon Jul 20 07:07:40.655341 2026] [security2:error] [pid 49578:tid 49792] [client 47.86.33.52:65252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dnLU3yPMQnn6OehdR5AABXmU"]
[Mon Jul 20 07:07:40.658864 2026] [access_compat:error] [pid 45040:tid 45276] [client 157.148.43.236:45279] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:07:40.770968 2026] [security2:error] [pid 49578:tid 49741] [client 103.144.65.217:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dnLU3yPMQnn6OehdR8QAAASs"]
[Mon Jul 20 07:07:40.771105 2026] [security2:error] [pid 49578:tid 49741] [client 103.144.65.217:57374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dnLU3yPMQnn6OehdR8QAAASs"]
[Mon Jul 20 07:07:40.774316 2026] [security2:error] [pid 45040:tid 45261] [client 14.225.17.146:56492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4dnLEFnm79ltp0SFBiQAAAAFk"], referer: http://ivetstrategies.com/2023
[Mon Jul 20 07:07:40.786404 2026] [security2:error] [pid 45040:tid 45067] [remote 173.249.4.11:23246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dnLEFnm79ltp0SFBiRAAAAxg"]
[Mon Jul 20 07:07:40.894036 2026] [security2:error] [pid 49578:tid 49759] [client 213.152.161.101:54652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dnLU3yPMQnn6OehdR-QAAAT0"]
[Mon Jul 20 07:07:40.894141 2026] [security2:error] [pid 49578:tid 49759] [client 213.152.161.101:54652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4dnLU3yPMQnn6OehdR-QAAAT0"]
[Mon Jul 20 07:07:40.924006 2026] [security2:error] [pid 49578:tid 49805] [client 179.61.245.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vtv.zzt.mybluehost.me"] [uri "/index.php"] [unique_id "al4dnLU3yPMQnn6OehdR7wAAAWs"]
[Mon Jul 20 07:07:40.969947 2026] [security2:error] [pid 45040:tid 45132] [remote 173.249.4.11:23246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dnLEFnm79ltp0SFBiSgAALlk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:41.022659 2026] [security2:error] [pid 49578:tid 49835] [client 194.61.41.72:28093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/about.php"] [unique_id "al4dnbU3yPMQnn6OehdR_gAAAYk"]
[Mon Jul 20 07:07:41.267095 2026] [lsapi:warn] [pid 49578:tid 49772] [client 14.225.17.146:56467] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2023
[Mon Jul 20 07:07:41.267124 2026] [lsapi:warn] [pid 49578:tid 49772] [client 14.225.17.146:56467] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2023
[Mon Jul 20 07:07:41.575768 2026] [security2:error] [pid 49578:tid 49818] [client 183.82.98.154:46997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dnbU3yPMQnn6OehdSHwAAAXg"]
[Mon Jul 20 07:07:41.575872 2026] [security2:error] [pid 49578:tid 49818] [client 183.82.98.154:46997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dnbU3yPMQnn6OehdSHwAAAXg"]
[Mon Jul 20 07:07:41.593258 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dnbU3yPMQnn6OehdSFgAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:41.660647 2026] [security2:error] [pid 49578:tid 49596] [remote 188.95.113.76:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4dnbU3yPMQnn6OehdSJAABRBE"]
[Mon Jul 20 07:07:41.729759 2026] [security2:error] [pid 45040:tid 45253] [client 194.61.41.89:27835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/wincust.php"] [unique_id "al4dnbEFnm79ltp0SFBiWAAAAFE"]
[Mon Jul 20 07:07:41.789910 2026] [lsapi:warn] [pid 49578:tid 49726] [client 50.116.65.227:27760] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:07:41.789942 2026] [lsapi:warn] [pid 49578:tid 49726] [client 50.116.65.227:27760] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:07:41.805433 2026] [security2:error] [pid 49578:tid 49772] [client 14.225.17.146:56467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4dnLU3yPMQnn6OehdR8AAAAUo"], referer: http://oswegooperatheater.com/2023
[Mon Jul 20 07:07:41.846368 2026] [security2:error] [pid 49578:tid 49828] [client 14.225.17.146:56587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4dnLU3yPMQnn6OehdR9AAAAYI"], referer: http://headachescarpaltunnelfibromyalgia.com/2023
[Mon Jul 20 07:07:41.883541 2026] [security2:error] [pid 49578:tid 49598] [remote 188.95.113.76:51234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4dnbU3yPMQnn6OehdSNgABKRM"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 07:07:41.963136 2026] [security2:error] [pid 49578:tid 49713] [client 14.225.17.146:56979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4dnLU3yPMQnn6OehdRyQAAAQ8"], referer: http://nomorewetsheets.net/2023
[Mon Jul 20 07:07:41.972405 2026] [security2:error] [pid 49578:tid 49709] [client 14.225.17.146:54138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4dm7U3yPMQnn6OehdRqQAAAQs"], referer: http://latiendadejorge.com.gt/2023
[Mon Jul 20 07:07:42.101942 2026] [security2:error] [pid 45040:tid 45059] [remote 91.142.222.105:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4dnrEFnm79ltp0SFBiYgAAPBE"]
[Mon Jul 20 07:07:42.168995 2026] [security2:error] [pid 49578:tid 49750] [client 14.225.17.146:61740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4dnbU3yPMQnn6OehdSOQAAATQ"], referer: http://securingmemories.com/2023
[Mon Jul 20 07:07:42.282865 2026] [security2:error] [pid 49578:tid 49740] [client 14.225.17.146:56533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4dnLU3yPMQnn6OehdRwQAAASo"], referer: http://webgardensbypaula.com/2023
[Mon Jul 20 07:07:42.344317 2026] [security2:error] [pid 45040:tid 45136] [remote 91.142.222.105:59610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4dnrEFnm79ltp0SFBiagAAL10"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:07:42.477155 2026] [security2:error] [pid 49578:tid 49757] [client 194.61.41.105:40387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/light/alfa-rex.php"] [unique_id "al4dnrU3yPMQnn6OehdSVwAAATs"]
[Mon Jul 20 07:07:42.660825 2026] [lsapi:warn] [pid 49578:tid 49784] [client 14.225.17.146:57152] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2023
[Mon Jul 20 07:07:42.660845 2026] [lsapi:warn] [pid 49578:tid 49784] [client 14.225.17.146:57152] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2023
[Mon Jul 20 07:07:42.723988 2026] [lsapi:warn] [pid 49578:tid 49712] [client 50.116.65.227:27824] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:07:42.724021 2026] [lsapi:warn] [pid 49578:tid 49712] [client 50.116.65.227:27824] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:07:42.733762 2026] [security2:error] [pid 49578:tid 49784] [client 14.225.17.146:57152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4dnrU3yPMQnn6OehdSZAAAAVY"], referer: https://oswegooperatheater.com/2023
[Mon Jul 20 07:07:42.764078 2026] [security2:error] [pid 49578:tid 49767] [client 192.140.149.97:46233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.149.140.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dnrU3yPMQnn6OehdScAAAAUU"]
[Mon Jul 20 07:07:42.764307 2026] [security2:error] [pid 49578:tid 49767] [client 192.140.149.97:46233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samueldcohen.com"] [uri "/xmlrpc.php"] [unique_id "al4dnrU3yPMQnn6OehdScAAAAUU"]
[Mon Jul 20 07:07:42.959914 2026] [security2:error] [pid 45040:tid 45078] [remote 45.90.123.233:41976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dnrEFnm79ltp0SFBigQAAeiM"]
[Mon Jul 20 07:07:43.161345 2026] [security2:error] [pid 45040:tid 45065] [remote 45.90.123.233:41976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dn7EFnm79ltp0SFBiigAAYRY"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:07:43.233225 2026] [security2:error] [pid 49578:tid 49819] [client 194.61.41.66:29715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-good.php"] [unique_id "al4dn7U3yPMQnn6OehdSfQAAAXk"]
[Mon Jul 20 07:07:43.469443 2026] [security2:error] [pid 45040:tid 45211] [client 14.225.17.146:56594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4dnbEFnm79ltp0SFBiWQAAACc"], referer: http://ksands.co.uk/2023
[Mon Jul 20 07:07:43.617346 2026] [security2:error] [pid 45040:tid 45185] [client 14.225.17.146:49931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4dn7EFnm79ltp0SFBikgAAAA0"], referer: http://cheesewithjam.com/2023
[Mon Jul 20 07:07:43.644506 2026] [security2:error] [pid 49578:tid 49695] [remote 188.138.102.156:33640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dn7U3yPMQnn6OehdSmwABO3Q"]
[Mon Jul 20 07:07:43.645444 2026] [security2:error] [pid 49578:tid 49811] [client 57.141.18.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4dn7U3yPMQnn6OehdSjAAAAXE"]
[Mon Jul 20 07:07:43.844932 2026] [security2:error] [pid 49578:tid 49591] [remote 188.138.102.156:33640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dn7U3yPMQnn6OehdSqQABVQw"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:43.958385 2026] [security2:error] [pid 49578:tid 49725] [client 14.225.17.146:63853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4dnrU3yPMQnn6OehdSYgAAARs"], referer: http://momheadquarters.com/2023
[Mon Jul 20 07:07:43.984732 2026] [security2:error] [pid 45040:tid 45290] [client 77.110.127.138:63667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dn7EFnm79ltp0SFBingAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:43.984869 2026] [security2:error] [pid 45040:tid 45290] [client 77.110.127.138:63667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dn7EFnm79ltp0SFBingAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:44.018651 2026] [security2:error] [pid 49578:tid 49763] [client 194.61.41.248:39741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/index.php"] [unique_id "al4doLU3yPMQnn6OehdSuAAAAUE"]
[Mon Jul 20 07:07:44.320612 2026] [security2:error] [pid 45040:tid 45197] [client 14.225.17.146:56847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4dn7EFnm79ltp0SFBikQAAABk"], referer: http://backandneckpainrelieflaceychiropractor.com/2023
[Mon Jul 20 07:07:44.617877 2026] [security2:error] [pid 49578:tid 49739] [client 201.27.111.74:57204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4doLU3yPMQnn6OehdS2wAAASk"]
[Mon Jul 20 07:07:44.617988 2026] [security2:error] [pid 49578:tid 49739] [client 201.27.111.74:57204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4doLU3yPMQnn6OehdS2wAAASk"]
[Mon Jul 20 07:07:44.768439 2026] [security2:error] [pid 49578:tid 49830] [client 194.61.41.105:43147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/wp-conflg.php"] [unique_id "al4doLU3yPMQnn6OehdS5AAAAYQ"]
[Mon Jul 20 07:07:44.830309 2026] [security2:error] [pid 49578:tid 49816] [client 154.208.48.130:63198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4doLU3yPMQnn6OehdS6QAAAXY"]
[Mon Jul 20 07:07:44.830457 2026] [security2:error] [pid 49578:tid 49816] [client 154.208.48.130:63198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4doLU3yPMQnn6OehdS6QAAAXY"]
[Mon Jul 20 07:07:44.858355 2026] [security2:error] [pid 49578:tid 49603] [remote 202.51.202.242:36278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4doLU3yPMQnn6OehdS6wABahg"]
[Mon Jul 20 07:07:44.905124 2026] [security2:error] [pid 49578:tid 49808] [client 77.110.127.138:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4doLU3yPMQnn6OehdS7AAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:44.905222 2026] [security2:error] [pid 49578:tid 49808] [client 77.110.127.138:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4doLU3yPMQnn6OehdS7AAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:45.193674 2026] [security2:error] [pid 49578:tid 49759] [client 14.225.17.146:56891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4dn7U3yPMQnn6OehdSlgAAAT0"], referer: http://bigwormfishing.com/2023
[Mon Jul 20 07:07:45.375106 2026] [security2:error] [pid 45040:tid 45179] [client 117.247.108.24:61437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dobEFnm79ltp0SFBivAAAAAc"]
[Mon Jul 20 07:07:45.375258 2026] [security2:error] [pid 45040:tid 45179] [client 117.247.108.24:61437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dobEFnm79ltp0SFBivAAAAAc"]
[Mon Jul 20 07:07:45.547392 2026] [security2:error] [pid 49578:tid 49726] [client 194.61.41.78:44855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/autoload_classmap.php"] [unique_id "al4dobU3yPMQnn6OehdTFQAAARw"]
[Mon Jul 20 07:07:45.683375 2026] [security2:error] [pid 49578:tid 49746] [client 77.110.127.138:63675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dobU3yPMQnn6OehdTHgAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:45.683476 2026] [security2:error] [pid 49578:tid 49746] [client 77.110.127.138:63675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dobU3yPMQnn6OehdTHgAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:46.086047 2026] [security2:error] [pid 49578:tid 49760] [client 77.110.127.138:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dorU3yPMQnn6OehdTOgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:46.086162 2026] [security2:error] [pid 49578:tid 49760] [client 77.110.127.138:63680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dorU3yPMQnn6OehdTOgAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:46.240480 2026] [security2:error] [pid 49578:tid 49774] [client 14.225.17.146:54700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4dorU3yPMQnn6OehdTPQAAAUw"], referer: https://bigwormfishing.com/2023
[Mon Jul 20 07:07:46.378240 2026] [security2:error] [pid 49578:tid 49722] [client 194.61.41.63:54905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/about.php"] [unique_id "al4dorU3yPMQnn6OehdTSAAAARg"]
[Mon Jul 20 07:07:46.746019 2026] [security2:error] [pid 49578:tid 49788] [client 77.110.127.138:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dorU3yPMQnn6OehdTYAAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:46.746164 2026] [security2:error] [pid 49578:tid 49788] [client 77.110.127.138:63687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dorU3yPMQnn6OehdTYAAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:46.797482 2026] [security2:error] [pid 45040:tid 45124] [remote 188.166.241.141:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dorEFnm79ltp0SFBi7AAAZ1E"]
[Mon Jul 20 07:07:46.797614 2026] [security2:error] [pid 45040:tid 45275] [client 188.166.241.141:35530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dorEFnm79ltp0SFBi7AAAZ1E"]
[Mon Jul 20 07:07:46.801063 2026] [security2:error] [pid 49578:tid 49802] [client 104.234.53.79:61477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dorU3yPMQnn6OehdTXgAAAWg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:47.100379 2026] [security2:error] [pid 49578:tid 49748] [client 77.110.127.138:63688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4do7U3yPMQnn6OehdTdwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:47.100492 2026] [security2:error] [pid 49578:tid 49748] [client 77.110.127.138:63688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4do7U3yPMQnn6OehdTdwAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:47.242960 2026] [security2:error] [pid 49578:tid 49825] [client 104.234.53.79:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4do7U3yPMQnn6OehdTfwAAAX8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:47.370626 2026] [security2:error] [pid 49578:tid 49752] [client 194.61.41.75:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4do7U3yPMQnn6OehdTewAAATY"]
[Mon Jul 20 07:07:47.554682 2026] [security2:error] [pid 45040:tid 45069] [remote 194.164.192.228:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4do7EFnm79ltp0SFBjAAAAUho"]
[Mon Jul 20 07:07:47.574245 2026] [security2:error] [pid 45040:tid 45212] [client 187.16.64.216:53058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4do7EFnm79ltp0SFBjAgAAACg"]
[Mon Jul 20 07:07:47.574355 2026] [security2:error] [pid 45040:tid 45212] [client 187.16.64.216:53058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4do7EFnm79ltp0SFBjAgAAACg"]
[Mon Jul 20 07:07:47.584702 2026] [security2:error] [pid 49578:tid 49762] [client 77.110.127.138:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4do7U3yPMQnn6OehdTiwAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:47.584801 2026] [security2:error] [pid 49578:tid 49762] [client 77.110.127.138:63690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4do7U3yPMQnn6OehdTiwAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:47.848629 2026] [security2:error] [pid 45040:tid 45150] [remote 194.164.192.228:40902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4do7EFnm79ltp0SFBjCQAAJ2s"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:07:48.261703 2026] [security2:error] [pid 49578:tid 49777] [client 194.61.41.75:43309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/about.php"] [unique_id "al4dpLU3yPMQnn6OehdTtwAAAU8"]
[Mon Jul 20 07:07:48.469700 2026] [security2:error] [pid 49578:tid 49753] [client 74.7.241.168:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4dpLU3yPMQnn6OehdTxwAAATc"]
[Mon Jul 20 07:07:48.472884 2026] [security2:error] [pid 49578:tid 49757] [client 74.7.241.168:44714] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nikkidesigns.net"] [uri "/robots.txt"] [unique_id "al4dpLU3yPMQnn6OehdTwwABO3o"]
[Mon Jul 20 07:07:48.497307 2026] [security2:error] [pid 49578:tid 49581] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dpLU3yPMQnn6OehdTzAABJAI"]
[Mon Jul 20 07:07:48.497455 2026] [security2:error] [pid 49578:tid 49734] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dpLU3yPMQnn6OehdTzAABJAI"]
[Mon Jul 20 07:07:48.842918 2026] [security2:error] [pid 49578:tid 49765] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dpLU3yPMQnn6OehdT1wAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:48.871681 2026] [security2:error] [pid 49578:tid 49598] [remote 188.166.241.141:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dpLU3yPMQnn6OehdT5gABGhM"]
[Mon Jul 20 07:07:48.931793 2026] [autoindex:error] [pid 49578:tid 49810] [client 168.144.19.97:54025] AH01276: Cannot serve directory /home4/msdmqzmy/public_html/website_41aebdfc/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:07:49.037503 2026] [security2:error] [pid 49578:tid 49753] [client 194.61.41.60:52565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/fonts/database.php"] [unique_id "al4dpbU3yPMQnn6OehdT7QAAATc"]
[Mon Jul 20 07:07:49.235697 2026] [security2:error] [pid 49578:tid 49687] [remote 188.166.241.141:35538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4dpbU3yPMQnn6OehdT-gABImw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:07:49.846099 2026] [security2:error] [pid 49578:tid 49783] [client 194.61.41.60:41837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ff2.php"] [unique_id "al4dpbU3yPMQnn6OehdUIgAAAVU"]
[Mon Jul 20 07:07:50.047017 2026] [security2:error] [pid 45040:tid 45283] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dpbEFnm79ltp0SFBjKAAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:50.058205 2026] [security2:error] [pid 49578:tid 49800] [client 88.241.67.160:55838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dprU3yPMQnn6OehdUMAAAAWY"]
[Mon Jul 20 07:07:50.058727 2026] [security2:error] [pid 49578:tid 49800] [client 88.241.67.160:55838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dprU3yPMQnn6OehdUMAAAAWY"]
[Mon Jul 20 07:07:50.613070 2026] [security2:error] [pid 45040:tid 45259] [client 194.61.41.108:22291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/Exception-wp.php"] [unique_id "al4dprEFnm79ltp0SFBjNwAAAFc"]
[Mon Jul 20 07:07:50.647340 2026] [security2:error] [pid 49578:tid 49785] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dprU3yPMQnn6OehdUSwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:51.338411 2026] [security2:error] [pid 45040:tid 45203] [client 194.61.41.79:33743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/plugin.php"] [unique_id "al4dp7EFnm79ltp0SFBjWQAAAB8"]
[Mon Jul 20 07:07:51.376452 2026] [security2:error] [pid 49578:tid 49768] [client 103.144.65.217:57830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dp7U3yPMQnn6OehdUfwAAAUY"]
[Mon Jul 20 07:07:51.376566 2026] [security2:error] [pid 49578:tid 49768] [client 103.144.65.217:57830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dp7U3yPMQnn6OehdUfwAAAUY"]
[Mon Jul 20 07:07:51.401040 2026] [security2:error] [pid 45040:tid 45193] [client 104.234.53.54:47093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dp7EFnm79ltp0SFBjWgAAABU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:51.640704 2026] [security2:error] [pid 45040:tid 45185] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dp7EFnm79ltp0SFBjVwAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:51.838820 2026] [proxy:error] [pid 49578:tid 49772] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:07:51.838857 2026] [proxy_http:error] [pid 49578:tid 49772] [client 107.172.180.205:52512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:07:51.839313 2026] [proxy:error] [pid 49578:tid 49772] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:07:51.839347 2026] [proxy_http:error] [pid 49578:tid 49772] [client 107.172.180.205:52512] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:07:52.092571 2026] [security2:error] [pid 49578:tid 49809] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dp7U3yPMQnn6OehdUpwAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:52.154647 2026] [security2:error] [pid 45040:tid 45285] [client 194.61.41.86:23579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/rest-api/autoload_classmap.php"] [unique_id "al4dqLEFnm79ltp0SFBjbwAAAHE"]
[Mon Jul 20 07:07:52.220557 2026] [security2:error] [pid 49578:tid 49782] [client 77.110.127.138:63707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dqLU3yPMQnn6OehdUuwAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:52.220645 2026] [security2:error] [pid 49578:tid 49782] [client 77.110.127.138:63707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dqLU3yPMQnn6OehdUuwAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:52.240988 2026] [security2:error] [pid 45040:tid 45205] [client 183.82.98.154:53807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dqLEFnm79ltp0SFBjcgAAACE"]
[Mon Jul 20 07:07:52.241083 2026] [security2:error] [pid 45040:tid 45205] [client 183.82.98.154:53807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dqLEFnm79ltp0SFBjcgAAACE"]
[Mon Jul 20 07:07:52.278713 2026] [security2:error] [pid 49578:tid 49825] [client 158.173.166.181:65043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dqLU3yPMQnn6OehdUvgAAAX8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:07:52.529010 2026] [security2:error] [pid 49578:tid 49666] [remote 5.252.52.249:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dqLU3yPMQnn6OehdUzAABEVc"]
[Mon Jul 20 07:07:52.589116 2026] [security2:error] [pid 49578:tid 49646] [remote 15.206.251.117:33444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dqLU3yPMQnn6OehdUzwABc0M"]
[Mon Jul 20 07:07:52.688412 2026] [security2:error] [pid 49578:tid 49711] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dqLU3yPMQnn6OehdUwwAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:52.772552 2026] [security2:error] [pid 49578:tid 49643] [remote 5.252.52.249:42916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dqLU3yPMQnn6OehdU3AABOkA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:52.926377 2026] [security2:error] [pid 49578:tid 49735] [client 194.61.41.108:27435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/jp.php"] [unique_id "al4dqLU3yPMQnn6OehdU7QAAASU"]
[Mon Jul 20 07:07:53.030528 2026] [security2:error] [pid 49578:tid 49777] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dqLU3yPMQnn6OehdU4gAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:53.055890 2026] [security2:error] [pid 49578:tid 49677] [remote 15.206.251.117:33444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dqbU3yPMQnn6OehdU-gABS2I"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:53.393535 2026] [security2:error] [pid 49578:tid 49745] [client 57.141.18.11:52762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dqLU3yPMQnn6OehdUuAABLz0"]
[Mon Jul 20 07:07:53.647519 2026] [proxy:error] [pid 45040:tid 45188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:07:53.647580 2026] [proxy_http:error] [pid 45040:tid 45188] [client 107.172.180.205:52536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:07:53.648725 2026] [proxy:error] [pid 45040:tid 45188] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:07:53.648778 2026] [proxy_http:error] [pid 45040:tid 45188] [client 107.172.180.205:52536] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:07:53.675236 2026] [security2:error] [pid 45040:tid 45281] [client 194.61.41.82:23677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-atom.php"] [unique_id "al4dqbEFnm79ltp0SFBjrAAAAG0"]
[Mon Jul 20 07:07:53.782550 2026] [security2:error] [pid 49578:tid 49680] [remote 160.187.68.132:48630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dqbU3yPMQnn6OehdVHwABFGU"]
[Mon Jul 20 07:07:54.179055 2026] [security2:error] [pid 49578:tid 49769] [client 167.114.139.170:16084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4dqrU3yPMQnn6OehdVQAAAAUc"]
[Mon Jul 20 07:07:54.179131 2026] [security2:error] [pid 49578:tid 49769] [client 167.114.139.170:16084] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4dqrU3yPMQnn6OehdVQAAAAUc"]
[Mon Jul 20 07:07:54.194740 2026] [security2:error] [pid 45040:tid 45193] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dqbEFnm79ltp0SFBjrgAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:54.266002 2026] [security2:error] [pid 49578:tid 49616] [remote 160.187.68.132:48630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dqrU3yPMQnn6OehdVRQABgyU"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:54.416849 2026] [security2:error] [pid 49578:tid 49813] [client 136.107.64.51:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/xmlrpc.php"] [unique_id "al4dqrU3yPMQnn6OehdVUQAAAXM"]
[Mon Jul 20 07:07:54.438688 2026] [security2:error] [pid 49578:tid 49717] [client 194.61.41.75:36975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/index.php"] [unique_id "al4dqrU3yPMQnn6OehdVUgAAARM"]
[Mon Jul 20 07:07:54.673915 2026] [security2:error] [pid 49578:tid 49757] [client 136.107.64.51:63416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4dqrU3yPMQnn6OehdVWgAAATs"]
[Mon Jul 20 07:07:54.947374 2026] [security2:error] [pid 49578:tid 49730] [client 136.107.64.51:58397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4dqrU3yPMQnn6OehdVZQAAASA"]
[Mon Jul 20 07:07:55.009878 2026] [security2:error] [pid 45040:tid 45295] [client 191.96.254.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tgs.lfg.mybluehost.me"] [uri "/index.php"] [unique_id "al4dqbEFnm79ltp0SFBjnAAAAHs"]
[Mon Jul 20 07:07:55.121106 2026] [security2:error] [pid 45040:tid 45260] [client 77.110.127.138:63673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dq7EFnm79ltp0SFBj1AAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:55.121297 2026] [security2:error] [pid 45040:tid 45260] [client 77.110.127.138:63673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dq7EFnm79ltp0SFBj1AAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:55.243784 2026] [security2:error] [pid 45040:tid 45187] [client 201.27.111.74:57676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dq7EFnm79ltp0SFBj1wAAAA8"]
[Mon Jul 20 07:07:55.243884 2026] [security2:error] [pid 45040:tid 45187] [client 201.27.111.74:57676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dq7EFnm79ltp0SFBj1wAAAA8"]
[Mon Jul 20 07:07:55.245198 2026] [security2:error] [pid 49578:tid 49744] [client 194.61.41.106:28053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/up.php"] [unique_id "al4dq7U3yPMQnn6OehdVewAAAS4"]
[Mon Jul 20 07:07:55.248577 2026] [security2:error] [pid 49578:tid 49732] [client 136.107.64.51:54664] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4dq7U3yPMQnn6OehdVfAAAASI"]
[Mon Jul 20 07:07:55.334651 2026] [security2:error] [pid 49578:tid 49687] [remote 185.191.171.11:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wraptheupstatesc.com"] [uri "/car-wraps/"] [unique_id "al4dq7U3yPMQnn6OehdVfwABgWw"]
[Mon Jul 20 07:07:55.334830 2026] [security2:error] [pid 49578:tid 49827] [client 185.191.171.11:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wraptheupstatesc.com"] [uri "/car-wraps/"] [unique_id "al4dq7U3yPMQnn6OehdVfwABgWw"]
[Mon Jul 20 07:07:55.554284 2026] [security2:error] [pid 45040:tid 45269] [client 136.107.64.51:63851] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4dq7EFnm79ltp0SFBj4AAAAGE"]
[Mon Jul 20 07:07:55.841032 2026] [security2:error] [pid 49578:tid 49738] [client 136.107.64.51:65508] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4dq7U3yPMQnn6OehdVngAAASg"]
[Mon Jul 20 07:07:56.015666 2026] [security2:error] [pid 49578:tid 49726] [client 194.61.41.88:42031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/bypass.php"] [unique_id "al4drLU3yPMQnn6OehdVrgAAARw"]
[Mon Jul 20 07:07:56.090266 2026] [security2:error] [pid 45040:tid 45243] [client 117.247.108.24:18575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4drLEFnm79ltp0SFBj5wAAAEc"]
[Mon Jul 20 07:07:56.090408 2026] [security2:error] [pid 45040:tid 45243] [client 117.247.108.24:18575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4drLEFnm79ltp0SFBj5wAAAEc"]
[Mon Jul 20 07:07:56.111600 2026] [security2:error] [pid 49578:tid 49722] [client 136.107.64.51:64408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4drLU3yPMQnn6OehdVsQAAARg"]
[Mon Jul 20 07:07:56.205721 2026] [security2:error] [pid 49578:tid 49770] [client 135.148.32.173:59018] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "collectingrealestate.com"] [uri "/"] [unique_id "al4drLU3yPMQnn6OehdVuAAAAUg"]
[Mon Jul 20 07:07:56.277214 2026] [security2:error] [pid 49578:tid 49613] [remote 117.0.21.154:56978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4drLU3yPMQnn6OehdVuwABMyI"]
[Mon Jul 20 07:07:56.389743 2026] [security2:error] [pid 49578:tid 49727] [client 136.107.64.51:49479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4drLU3yPMQnn6OehdVwgAAAR0"]
[Mon Jul 20 07:07:56.415416 2026] [security2:error] [pid 49578:tid 49703] [remote 72.167.132.114:47818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4drLU3yPMQnn6OehdVwwABF3w"]
[Mon Jul 20 07:07:56.620110 2026] [security2:error] [pid 49578:tid 49737] [client 136.107.64.51:65204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4drLU3yPMQnn6OehdVzQAAASc"]
[Mon Jul 20 07:07:56.632209 2026] [security2:error] [pid 49578:tid 49624] [remote 72.167.132.114:47818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4drLU3yPMQnn6OehdVzgABcC0"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:07:56.718907 2026] [security2:error] [pid 49578:tid 49745] [client 104.234.53.67:23347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4drLU3yPMQnn6OehdV0gAAAS8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:56.755642 2026] [security2:error] [pid 49578:tid 49816] [client 194.61.41.57:32233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/images/admin.php"] [unique_id "al4drLU3yPMQnn6OehdV0wAAAXY"]
[Mon Jul 20 07:07:56.892795 2026] [security2:error] [pid 45040:tid 45227] [client 136.107.64.51:59153] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4drLEFnm79ltp0SFBj-AAAADc"]
[Mon Jul 20 07:07:57.133145 2026] [security2:error] [pid 45040:tid 45292] [client 136.107.64.51:52783] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4drbEFnm79ltp0SFBj-wAAAHg"]
[Mon Jul 20 07:07:57.263120 2026] [security2:error] [pid 45040:tid 45167] [remote 81.173.115.7:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4drbEFnm79ltp0SFBj_QAAJHw"]
[Mon Jul 20 07:07:57.389873 2026] [security2:error] [pid 49578:tid 49735] [client 136.107.64.51:59593] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "smithfamilyfoundationsunshine.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4drbU3yPMQnn6OehdV-QAAASU"]
[Mon Jul 20 07:07:57.454557 2026] [security2:error] [pid 45040:tid 45092] [remote 81.173.115.7:35166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4drbEFnm79ltp0SFBkAgAAeTE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:07:57.455583 2026] [security2:error] [pid 45040:tid 45131] [remote 152.228.213.32:44594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4drbEFnm79ltp0SFBkAQAAM1g"]
[Mon Jul 20 07:07:57.455725 2026] [security2:error] [pid 45040:tid 45223] [client 152.228.213.32:44594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4drbEFnm79ltp0SFBkAQAAM1g"]
[Mon Jul 20 07:07:57.517162 2026] [security2:error] [pid 49578:tid 49732] [client 194.61.41.68:28423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/index.php"] [unique_id "al4drbU3yPMQnn6OehdV_QAAASI"]
[Mon Jul 20 07:07:57.724974 2026] [security2:error] [pid 49578:tid 49798] [client 154.208.48.130:63714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4drbU3yPMQnn6OehdWCAAAAWQ"]
[Mon Jul 20 07:07:57.725102 2026] [security2:error] [pid 49578:tid 49798] [client 154.208.48.130:63714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4drbU3yPMQnn6OehdWCAAAAWQ"]
[Mon Jul 20 07:07:58.201363 2026] [security2:error] [pid 49578:tid 49625] [remote 117.0.21.154:56978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4drrU3yPMQnn6OehdWIgABKi4"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:07:58.222278 2026] [security2:error] [pid 49578:tid 49724] [client 187.16.64.216:53633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4drrU3yPMQnn6OehdWJwAAARo"]
[Mon Jul 20 07:07:58.222404 2026] [security2:error] [pid 49578:tid 49724] [client 187.16.64.216:53633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4drrU3yPMQnn6OehdWJwAAARo"]
[Mon Jul 20 07:07:58.286463 2026] [security2:error] [pid 45040:tid 45282] [client 194.61.41.75:21555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/wp-login.php"] [unique_id "al4drrEFnm79ltp0SFBkFAAAAG4"]
[Mon Jul 20 07:07:58.329869 2026] [security2:error] [pid 45040:tid 45165] [remote 45.90.123.233:58806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4drrEFnm79ltp0SFBkGwAAPHo"]
[Mon Jul 20 07:07:58.549854 2026] [security2:error] [pid 45040:tid 45141] [remote 45.90.123.233:58806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4drrEFnm79ltp0SFBkHwAAemI"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:07:58.729464 2026] [security2:error] [pid 49578:tid 49715] [client 104.234.53.75:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4drrU3yPMQnn6OehdWOAAAARE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:07:58.784705 2026] [security2:error] [pid 45040:tid 45254] [client 158.173.241.141:27077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4drrEFnm79ltp0SFBkIAAAUnQ"]
[Mon Jul 20 07:07:59.039028 2026] [security2:error] [pid 49578:tid 49803] [client 194.61.41.250:65331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/simple/function.php"] [unique_id "al4dr7U3yPMQnn6OehdWTAAAAWk"]
[Mon Jul 20 07:07:59.229819 2026] [security2:error] [pid 45040:tid 45161] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dr7EFnm79ltp0SFBkLQAAVXY"]
[Mon Jul 20 07:07:59.229934 2026] [security2:error] [pid 45040:tid 45257] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dr7EFnm79ltp0SFBkLQAAVXY"]
[Mon Jul 20 07:07:59.516098 2026] [security2:error] [pid 45040:tid 45264] [client 77.110.127.138:63748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dr7EFnm79ltp0SFBkNQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:59.516187 2026] [security2:error] [pid 45040:tid 45264] [client 77.110.127.138:63748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dr7EFnm79ltp0SFBkNQAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:07:59.684813 2026] [security2:error] [pid 49578:tid 49793] [client 77.110.127.138:63753] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/feed/"] [unique_id "al4dr7U3yPMQnn6OehdWbAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:00.048215 2026] [security2:error] [pid 49578:tid 49748] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4dr7U3yPMQnn6OehdWdQAAATI"]
[Mon Jul 20 07:08:00.302824 2026] [security2:error] [pid 49578:tid 49811] [client 98.159.234.160:29635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dsLU3yPMQnn6OehdWjwAAAXE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:08:00.559610 2026] [security2:error] [pid 49578:tid 49657] [remote 47.86.33.52:27208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dsLU3yPMQnn6OehdWoAABLU4"]
[Mon Jul 20 07:08:00.707717 2026] [security2:error] [pid 49578:tid 49722] [client 88.241.67.160:56690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dsLU3yPMQnn6OehdWqAAAARg"]
[Mon Jul 20 07:08:00.708826 2026] [security2:error] [pid 49578:tid 49722] [client 88.241.67.160:56690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dsLU3yPMQnn6OehdWqAAAARg"]
[Mon Jul 20 07:08:00.951940 2026] [security2:error] [pid 49578:tid 49802] [client 194.61.41.69:34469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ext.php"] [unique_id "al4dsLU3yPMQnn6OehdWuwAAAWg"]
[Mon Jul 20 07:08:01.166404 2026] [security2:error] [pid 49578:tid 49685] [remote 182.77.62.24:43962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4dsbU3yPMQnn6OehdWzAABL2o"]
[Mon Jul 20 07:08:01.375225 2026] [security2:error] [pid 49578:tid 49606] [remote 162.19.86.63:48924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4dsbU3yPMQnn6OehdW1wABJxs"]
[Mon Jul 20 07:08:01.585545 2026] [security2:error] [pid 45040:tid 45195] [client 14.225.17.146:55170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4dsbEFnm79ltp0SFBktAAAABc"], referer: http://katsklar.com/2024
[Mon Jul 20 07:08:01.590805 2026] [security2:error] [pid 45040:tid 45205] [client 47.128.19.81:34474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4dsbEFnm79ltp0SFBkuQAAACE"]
[Mon Jul 20 07:08:01.608444 2026] [security2:error] [pid 49578:tid 49704] [remote 162.19.86.63:48924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4dsbU3yPMQnn6OehdW4AABf30"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 07:08:01.683393 2026] [security2:error] [pid 49578:tid 49593] [remote 182.77.62.24:43962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4dsbU3yPMQnn6OehdW5gABeQ4"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 07:08:01.741004 2026] [security2:error] [pid 49578:tid 49747] [client 194.61.41.74:52327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/delpaths.php"] [unique_id "al4dsbU3yPMQnn6OehdW7QAAATE"]
[Mon Jul 20 07:08:01.850540 2026] [security2:error] [pid 45040:tid 45206] [client 103.144.65.217:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dsbEFnm79ltp0SFBkvgAAACI"]
[Mon Jul 20 07:08:01.850629 2026] [security2:error] [pid 45040:tid 45206] [client 103.144.65.217:58396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dsbEFnm79ltp0SFBkvgAAACI"]
[Mon Jul 20 07:08:01.874877 2026] [security2:error] [pid 49578:tid 49608] [remote 47.86.33.52:27208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dsbU3yPMQnn6OehdW9AABIx0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:08:02.071429 2026] [security2:error] [pid 49578:tid 49591] [remote 188.166.241.141:34788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dsrU3yPMQnn6OehdXAgABOgw"]
[Mon Jul 20 07:08:02.071575 2026] [security2:error] [pid 49578:tid 49756] [client 188.166.241.141:34788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dsrU3yPMQnn6OehdXAgABOgw"]
[Mon Jul 20 07:08:02.542651 2026] [security2:error] [pid 49578:tid 49821] [client 194.61.41.102:51153] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/1.php"] [unique_id "al4dsrU3yPMQnn6OehdXKAAAAXs"]
[Mon Jul 20 07:08:02.542774 2026] [security2:error] [pid 49578:tid 49821] [client 194.61.41.102:51153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/1.php"] [unique_id "al4dsrU3yPMQnn6OehdXKAAAAXs"]
[Mon Jul 20 07:08:02.729247 2026] [security2:error] [pid 49578:tid 49768] [client 104.234.53.69:62391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dsrU3yPMQnn6OehdXMgAAAUY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:02.829472 2026] [security2:error] [pid 45040:tid 45042] [remote 188.166.241.141:34798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4dsrEFnm79ltp0SFBk3AAAZAE"]
[Mon Jul 20 07:08:02.864799 2026] [security2:error] [pid 45040:tid 45180] [client 183.82.98.154:54353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dsrEFnm79ltp0SFBk3gAAAAg"]
[Mon Jul 20 07:08:02.864896 2026] [security2:error] [pid 45040:tid 45180] [client 183.82.98.154:54353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dsrEFnm79ltp0SFBk3gAAAAg"]
[Mon Jul 20 07:08:03.034431 2026] [security2:error] [pid 49578:tid 49649] [remote 47.128.121.102:43836] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thierry-henry.fr"] [uri "/robots.txt"] [unique_id "al4ds7U3yPMQnn6OehdXPgABc0Y"]
[Mon Jul 20 07:08:03.088204 2026] [security2:error] [pid 49578:tid 49808] [client 77.110.127.138:63772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ds7U3yPMQnn6OehdXQgAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:03.088292 2026] [security2:error] [pid 49578:tid 49808] [client 77.110.127.138:63772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ds7U3yPMQnn6OehdXQgAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:03.225871 2026] [security2:error] [pid 45040:tid 45153] [remote 188.166.241.141:34798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4ds7EFnm79ltp0SFBk6QAAA24"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:08:03.378844 2026] [security2:error] [pid 45040:tid 45240] [client 194.61.41.242:39321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/wp-login.php"] [unique_id "al4ds7EFnm79ltp0SFBk7AAAAEQ"]
[Mon Jul 20 07:08:03.523729 2026] [security2:error] [pid 49578:tid 49774] [client 57.141.18.98:28574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dsbU3yPMQnn6OehdW-AABTHw"]
[Mon Jul 20 07:08:03.883892 2026] [security2:error] [pid 49578:tid 49620] [remote 94.130.22.227:42644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.22.130.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ds7U3yPMQnn6OehdXZAABeyk"]
[Mon Jul 20 07:08:03.884169 2026] [security2:error] [pid 49578:tid 49821] [client 94.130.22.227:42644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ds7U3yPMQnn6OehdXZAABeyk"]
[Mon Jul 20 07:08:03.902566 2026] [security2:error] [pid 45040:tid 45298] [client 77.110.127.138:63775] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/feed/"] [unique_id "al4ds7EFnm79ltp0SFBlCAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:04.116448 2026] [security2:error] [pid 45040:tid 45274] [client 194.61.41.61:24581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/install.php"] [unique_id "al4dtLEFnm79ltp0SFBlEwAAAGY"]
[Mon Jul 20 07:08:04.216403 2026] [security2:error] [pid 49578:tid 49767] [client 172.239.57.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4dtLU3yPMQnn6OehdXawAAAUU"]
[Mon Jul 20 07:08:05.125377 2026] [security2:error] [pid 45040:tid 45284] [client 118.71.135.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4dsrEFnm79ltp0SFBk4QAAAHA"]
[Mon Jul 20 07:08:05.398620 2026] [security2:error] [pid 49578:tid 49823] [client 14.225.17.146:63396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4dtbU3yPMQnn6OehdXyAAAAX0"], referer: http://mourgroup.com/2024
[Mon Jul 20 07:08:05.559626 2026] [security2:error] [pid 49578:tid 49786] [client 14.225.17.146:55804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4dtbU3yPMQnn6OehdXtgAAAVg"], referer: http://alrowad-hub.net/2024
[Mon Jul 20 07:08:05.633038 2026] [security2:error] [pid 45040:tid 45268] [client 104.234.53.82:37477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dtbEFnm79ltp0SFBlPAAAAGA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:05.728920 2026] [security2:error] [pid 45040:tid 45236] [client 201.27.111.74:58145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dtbEFnm79ltp0SFBlPwAAAEA"]
[Mon Jul 20 07:08:05.729058 2026] [security2:error] [pid 45040:tid 45236] [client 201.27.111.74:58145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dtbEFnm79ltp0SFBlPwAAAEA"]
[Mon Jul 20 07:08:05.850296 2026] [security2:error] [pid 45040:tid 45078] [remote 151.158.48.106:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4dtbEFnm79ltp0SFBlQAAAWCM"]
[Mon Jul 20 07:08:05.911835 2026] [security2:error] [pid 45040:tid 45265] [client 138.197.159.250:57119] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.gearwaterproof.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4dtbEFnm79ltp0SFBlQgAAAF0"]
[Mon Jul 20 07:08:05.928126 2026] [security2:error] [pid 49578:tid 49771] [client 14.225.17.146:53352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4dtbU3yPMQnn6OehdX2wAAAUk"], referer: http://latiendadejorge.com.gt/2024
[Mon Jul 20 07:08:05.939713 2026] [security2:error] [pid 45040:tid 45264] [client 14.225.17.146:55052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4dtLEFnm79ltp0SFBlFwAAAFw"]
[Mon Jul 20 07:08:05.947662 2026] [security2:error] [pid 49578:tid 49762] [client 194.61.41.99:65109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/sunrise/admin.php"] [unique_id "al4dtbU3yPMQnn6OehdX8wAAAUA"]
[Mon Jul 20 07:08:06.045062 2026] [security2:error] [pid 49578:tid 49804] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dtbU3yPMQnn6OehdXzgAAAWo"]
[Mon Jul 20 07:08:06.174671 2026] [security2:error] [pid 45040:tid 45079] [remote 81.173.115.7:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4dtrEFnm79ltp0SFBlRgAAQSQ"]
[Mon Jul 20 07:08:06.289731 2026] [security2:error] [pid 45040:tid 45129] [remote 182.77.62.24:37262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dtrEFnm79ltp0SFBlSQAASVY"]
[Mon Jul 20 07:08:06.289957 2026] [security2:error] [pid 45040:tid 45245] [client 182.77.62.24:37262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "vyx.sbv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4dtrEFnm79ltp0SFBlSQAASVY"]
[Mon Jul 20 07:08:06.292762 2026] [security2:error] [pid 45040:tid 45084] [remote 151.158.48.106:42810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.48.158.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4dtrEFnm79ltp0SFBlSgAAUSk"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 07:08:06.369427 2026] [security2:error] [pid 45040:tid 45120] [remote 81.173.115.7:44930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4dtrEFnm79ltp0SFBlTwAAC00"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:08:06.386693 2026] [security2:error] [pid 49578:tid 49769] [client 104.234.53.63:52059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dtrU3yPMQnn6OehdYCgAAAUc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:06.390634 2026] [security2:error] [pid 45040:tid 45186] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4dtbEFnm79ltp0SFBlNQAAAA4"]
[Mon Jul 20 07:08:06.544259 2026] [core:error] [pid 45040:tid 45285] [client 14.225.17.146:63313] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:06.544284 2026] [core:error] [pid 45040:tid 45285] [client 14.225.17.146:63313] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:06.596363 2026] [security2:error] [pid 49578:tid 49788] [client 14.225.17.146:54764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4dtrU3yPMQnn6OehdYDQAAAVo"], referer: http://ironcitywellness.com/2024
[Mon Jul 20 07:08:06.748805 2026] [security2:error] [pid 45040:tid 45213] [client 194.61.41.60:27493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/gifclass.php"] [unique_id "al4dtrEFnm79ltp0SFBlWAAAACk"]
[Mon Jul 20 07:08:06.813289 2026] [security2:error] [pid 49578:tid 49805] [client 117.247.108.24:18620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dtrU3yPMQnn6OehdYIwAAAWs"]
[Mon Jul 20 07:08:06.813426 2026] [security2:error] [pid 49578:tid 49805] [client 117.247.108.24:18620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dtrU3yPMQnn6OehdYIwAAAWs"]
[Mon Jul 20 07:08:07.020355 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dt7EFnm79ltp0SFBlYgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:07.020501 2026] [security2:error] [pid 45040:tid 45220] [client 77.110.127.138:63790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dt7EFnm79ltp0SFBlYgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:07.027501 2026] [security2:error] [pid 49578:tid 49815] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4dtrU3yPMQnn6OehdYLAAAAXU"]
[Mon Jul 20 07:08:07.140201 2026] [security2:error] [pid 49578:tid 49798] [client 34.148.53.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dtbU3yPMQnn6OehdXzAAAAWQ"]
[Mon Jul 20 07:08:07.149852 2026] [security2:error] [pid 49578:tid 49765] [client 104.234.53.88:53557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dt7U3yPMQnn6OehdYMgAAAUM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:07.182201 2026] [security2:error] [pid 49578:tid 49825] [client 77.110.127.138:63792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/feed/"] [unique_id "al4dt7U3yPMQnn6OehdYMwAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:07.474892 2026] [security2:error] [pid 49578:tid 49830] [client 14.225.17.146:55246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4dtrU3yPMQnn6OehdYLQAAAYQ"]
[Mon Jul 20 07:08:07.536725 2026] [security2:error] [pid 45040:tid 45258] [client 194.61.41.84:32787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/plugin.php"] [unique_id "al4dt7EFnm79ltp0SFBlegAAAFY"]
[Mon Jul 20 07:08:07.645349 2026] [security2:error] [pid 49578:tid 49711] [client 57.141.18.104:39826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dtrU3yPMQnn6OehdX-AABDVo"]
[Mon Jul 20 07:08:07.813701 2026] [security2:error] [pid 45040:tid 45173] [client 102.0.25.168:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4dt7EFnm79ltp0SFBlgAAAAQg"]
[Mon Jul 20 07:08:08.000980 2026] [security2:error] [pid 49578:tid 49802] [client 14.225.17.146:54954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4dt7U3yPMQnn6OehdYYQAAAWg"], referer: http://retzkolonglogistics.com/2024
[Mon Jul 20 07:08:08.212775 2026] [security2:error] [pid 45040:tid 45291] [client 14.176.235.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4dtrEFnm79ltp0SFBlWQAAAHc"]
[Mon Jul 20 07:08:08.346357 2026] [security2:error] [pid 45040:tid 45201] [client 194.61.41.84:30455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/bypass.php"] [unique_id "al4duLEFnm79ltp0SFBlkAAAAB0"]
[Mon Jul 20 07:08:08.370873 2026] [security2:error] [pid 49578:tid 49753] [client 104.234.53.72:27053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4duLU3yPMQnn6OehdYcgAAATc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:08.698037 2026] [security2:error] [pid 45040:tid 45249] [client 14.225.17.146:58363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4dt7EFnm79ltp0SFBlhQAAAE0"]
[Mon Jul 20 07:08:08.801896 2026] [security2:error] [pid 49578:tid 49733] [client 187.16.64.216:54210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4duLU3yPMQnn6OehdYiwAAASM"]
[Mon Jul 20 07:08:08.802018 2026] [security2:error] [pid 49578:tid 49733] [client 187.16.64.216:54210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4duLU3yPMQnn6OehdYiwAAASM"]
[Mon Jul 20 07:08:09.064623 2026] [security2:error] [pid 49578:tid 49695] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/.env"] [unique_id "al4dubU3yPMQnn6OehdYlQABNnQ"]
[Mon Jul 20 07:08:09.085600 2026] [security2:error] [pid 49578:tid 49600] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "oauth.jeffjaeger.com"] [uri "/.gitlab-ci.yml"] [unique_id "al4dubU3yPMQnn6OehdYmgABNhU"]
[Mon Jul 20 07:08:09.128709 2026] [security2:error] [pid 49578:tid 49816] [client 194.61.41.99:37803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/update-core.php"] [unique_id "al4dubU3yPMQnn6OehdYnQAAAXY"]
[Mon Jul 20 07:08:09.153287 2026] [security2:error] [pid 49578:tid 49721] [client 14.225.17.146:56708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4duLU3yPMQnn6OehdYkwAAARc"], referer: http://detroitcsc.com/2024
[Mon Jul 20 07:08:09.287838 2026] [security2:error] [pid 49578:tid 49743] [client 104.234.53.59:45871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4dubU3yPMQnn6OehdYngAAAS0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:09.508717 2026] [security2:error] [pid 45040:tid 45244] [client 154.208.48.130:64245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dubEFnm79ltp0SFBlxQAAAEg"]
[Mon Jul 20 07:08:09.508831 2026] [security2:error] [pid 45040:tid 45244] [client 154.208.48.130:64245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dubEFnm79ltp0SFBlxQAAAEg"]
[Mon Jul 20 07:08:09.853778 2026] [security2:error] [pid 49578:tid 49763] [client 194.61.41.89:32113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/about.php"] [unique_id "al4dubU3yPMQnn6OehdYzgAAAUE"]
[Mon Jul 20 07:08:09.963288 2026] [security2:error] [pid 49578:tid 49703] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dubU3yPMQnn6OehdY0wABFXw"]
[Mon Jul 20 07:08:09.963413 2026] [security2:error] [pid 49578:tid 49719] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dubU3yPMQnn6OehdY0wABFXw"]
[Mon Jul 20 07:08:10.075176 2026] [fcgid:warn] [pid 45040:tid 45240] (70014)End of file found: [client 66.132.186.185:24246] mod_fcgid: can't get data from http client
[Mon Jul 20 07:08:10.153656 2026] [security2:error] [pid 49578:tid 49726] [client 104.234.53.59:45871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4durU3yPMQnn6OehdY2QAAARw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:10.162807 2026] [security2:error] [pid 49578:tid 49694] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4durU3yPMQnn6OehdY2wABNnM"]
[Mon Jul 20 07:08:10.344048 2026] [security2:error] [pid 49578:tid 49651] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.old"] [unique_id "al4durU3yPMQnn6OehdY4QABNkg"]
[Mon Jul 20 07:08:10.646015 2026] [security2:error] [pid 49578:tid 49805] [client 194.61.41.69:57353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-mail.php"] [unique_id "al4durU3yPMQnn6OehdY8AAAAWs"]
[Mon Jul 20 07:08:10.741602 2026] [security2:error] [pid 49578:tid 49646] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/api/.env"] [unique_id "al4durU3yPMQnn6OehdY-AABNkM"]
[Mon Jul 20 07:08:10.973317 2026] [security2:error] [pid 49578:tid 49626] [remote 182.77.62.24:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4durU3yPMQnn6OehdZDwABhC8"]
[Mon Jul 20 07:08:11.099472 2026] [security2:error] [pid 49578:tid 49823] [client 77.110.127.138:63816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4du7U3yPMQnn6OehdZIwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:11.099586 2026] [security2:error] [pid 49578:tid 49823] [client 77.110.127.138:63816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4du7U3yPMQnn6OehdZIwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:11.310087 2026] [security2:error] [pid 49578:tid 49640] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oauth.jeffjaeger.com"] [uri "/graphql"] [unique_id "al4du7U3yPMQnn6OehdZLgABNj0"]
[Mon Jul 20 07:08:11.370997 2026] [security2:error] [pid 49578:tid 49667] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/serviceAccountKey.json"] [unique_id "al4du7U3yPMQnn6OehdZNgABVFg"]
[Mon Jul 20 07:08:11.371132 2026] [security2:error] [pid 49578:tid 49782] [client 34.156.104.72:36370] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "oauth.jeffjaeger.com"] [uri "/serviceAccountKey.json"] [unique_id "al4du7U3yPMQnn6OehdZNgABVFg"]
[Mon Jul 20 07:08:11.371563 2026] [security2:error] [pid 49578:tid 49604] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/secrets.yml"] [unique_id "al4du7U3yPMQnn6OehdZOwABVBk"]
[Mon Jul 20 07:08:11.372227 2026] [security2:error] [pid 49578:tid 49680] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/config/.env"] [unique_id "al4du7U3yPMQnn6OehdZOAABVGU"]
[Mon Jul 20 07:08:11.373329 2026] [security2:error] [pid 49578:tid 49661] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/backend/.env"] [unique_id "al4du7U3yPMQnn6OehdZPAABVFI"]
[Mon Jul 20 07:08:11.374134 2026] [security2:error] [pid 45040:tid 45183] [client 88.241.67.160:54170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4du7EFnm79ltp0SFBmCwAAAAs"]
[Mon Jul 20 07:08:11.374419 2026] [security2:error] [pid 45040:tid 45183] [client 88.241.67.160:54170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4du7EFnm79ltp0SFBmCwAAAAs"]
[Mon Jul 20 07:08:11.417909 2026] [security2:error] [pid 45040:tid 45244] [client 66.249.70.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4du7EFnm79ltp0SFBmBwAASG0"]
[Mon Jul 20 07:08:11.470590 2026] [security2:error] [pid 49578:tid 49733] [client 194.61.41.64:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/admin.php"] [unique_id "al4du7U3yPMQnn6OehdZPgAAASM"]
[Mon Jul 20 07:08:11.538280 2026] [security2:error] [pid 49578:tid 49689] [remote 182.77.62.24:37272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4du7U3yPMQnn6OehdZQQABD24"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:08:11.673201 2026] [core:error] [pid 49578:tid 49720] [client 149.202.94.131:63904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:11.673231 2026] [core:error] [pid 49578:tid 49720] [client 149.202.94.131:63904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:11.719481 2026] [security2:error] [pid 49578:tid 49581] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oauth.jeffjaeger.com"] [uri "/api/graphql"] [unique_id "al4du7U3yPMQnn6OehdZUgABdgI"]
[Mon Jul 20 07:08:11.737851 2026] [security2:error] [pid 49578:tid 49596] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4du7U3yPMQnn6OehdZVwABMRE"]
[Mon Jul 20 07:08:11.739299 2026] [security2:error] [pid 49578:tid 49583] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "oauth.jeffjaeger.com"] [uri "/.npmrc"] [unique_id "al4du7U3yPMQnn6OehdZVgABMQQ"]
[Mon Jul 20 07:08:11.873862 2026] [security2:error] [pid 49578:tid 49780] [client 14.225.17.146:65076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4du7U3yPMQnn6OehdZSQAAAVI"], referer: http://maplerespiteservices.com/2024
[Mon Jul 20 07:08:11.893319 2026] [authz_core:error] [pid 49578:tid 49688] [remote 34.156.104.72:36370] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 07:08:11.966452 2026] [security2:error] [pid 49578:tid 49706] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "oauth.jeffjaeger.com"] [uri "/v1/graphql"] [unique_id "al4du7U3yPMQnn6OehdZZAABTH8"]
[Mon Jul 20 07:08:11.984729 2026] [security2:error] [pid 49578:tid 49684] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/docker-compose.yaml"] [unique_id "al4du7U3yPMQnn6OehdZaQABWGk"]
[Mon Jul 20 07:08:11.986043 2026] [security2:error] [pid 49578:tid 49672] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "oauth.jeffjaeger.com"] [uri "/.ssh/id_ed25519"] [unique_id "al4du7U3yPMQnn6OehdZbAABWF0"]
[Mon Jul 20 07:08:11.989376 2026] [security2:error] [pid 49578:tid 49673] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/.ssh/id_dsa"] [unique_id "al4du7U3yPMQnn6OehdZbQABWF4"]
[Mon Jul 20 07:08:12.059597 2026] [security2:error] [pid 49578:tid 49678] [remote 192.241.143.148:59834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4dvLU3yPMQnn6OehdZdQABHmM"]
[Mon Jul 20 07:08:12.059815 2026] [security2:error] [pid 49578:tid 49728] [client 192.241.143.148:59834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4dvLU3yPMQnn6OehdZdQABHmM"]
[Mon Jul 20 07:08:12.216336 2026] [security2:error] [pid 45040:tid 45185] [client 194.61.41.96:64627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/defaults.php"] [unique_id "al4dvLEFnm79ltp0SFBmKAAAAA0"]
[Mon Jul 20 07:08:12.261672 2026] [security2:error] [pid 49578:tid 49587] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.ssh/id_rsa"] [unique_id "al4dvLU3yPMQnn6OehdZsgABVgg"]
[Mon Jul 20 07:08:12.419289 2026] [security2:error] [pid 49578:tid 49629] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4dvLU3yPMQnn6OehdZwgABcDI"]
[Mon Jul 20 07:08:12.419625 2026] [security2:error] [pid 49578:tid 49646] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/id_rsa"] [unique_id "al4dvLU3yPMQnn6OehdZxAABcEM"]
[Mon Jul 20 07:08:12.467005 2026] [security2:error] [pid 49578:tid 49812] [client 103.144.65.217:59075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dvLU3yPMQnn6OehdZyAAAAXI"]
[Mon Jul 20 07:08:12.467153 2026] [security2:error] [pid 49578:tid 49812] [client 103.144.65.217:59075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dvLU3yPMQnn6OehdZyAAAAXI"]
[Mon Jul 20 07:08:12.496527 2026] [core:error] [pid 49578:tid 49731] [client 149.202.94.131:65331] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:12.496552 2026] [core:error] [pid 49578:tid 49731] [client 149.202.94.131:65331] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:12.544425 2026] [security2:error] [pid 49578:tid 49620] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/.ssh/config"] [unique_id "al4dvLU3yPMQnn6OehdZzgABWik"]
[Mon Jul 20 07:08:12.565722 2026] [security2:error] [pid 49578:tid 49815] [client 54.161.25.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4dvLU3yPMQnn6OehdZxwABdUk"]
[Mon Jul 20 07:08:12.788504 2026] [security2:error] [pid 49578:tid 49660] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/privatekey.key"] [unique_id "al4dvLU3yPMQnn6OehdZ3QABQ1E"]
[Mon Jul 20 07:08:12.788556 2026] [security2:error] [pid 49578:tid 49676] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/key.pem"] [unique_id "al4dvLU3yPMQnn6OehdZ4QABQ2E"]
[Mon Jul 20 07:08:12.939426 2026] [security2:error] [pid 45040:tid 45279] [client 104.234.53.60:31579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4dvLEFnm79ltp0SFBmSgAAAGs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:12.946392 2026] [security2:error] [pid 45040:tid 45172] [client 194.61.41.105:24229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/content.php"] [unique_id "al4dvLEFnm79ltp0SFBmSwAAAAA"]
[Mon Jul 20 07:08:12.973902 2026] [security2:error] [pid 49578:tid 49667] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.openclaw/.env"] [unique_id "al4dvLU3yPMQnn6OehdZ6AABR1g"]
[Mon Jul 20 07:08:12.974569 2026] [security2:error] [pid 49578:tid 49604] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/.openclaw/openclaw.json"] [unique_id "al4dvLU3yPMQnn6OehdZ6QABRxk"]
[Mon Jul 20 07:08:13.404850 2026] [security2:error] [pid 45040:tid 45287] [client 183.82.98.154:54903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dvbEFnm79ltp0SFBmYgAAAHM"]
[Mon Jul 20 07:08:13.404953 2026] [security2:error] [pid 45040:tid 45287] [client 183.82.98.154:54903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dvbEFnm79ltp0SFBmYgAAAHM"]
[Mon Jul 20 07:08:13.473373 2026] [security2:error] [pid 49578:tid 49580] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.hermes/.env"] [unique_id "al4dvbU3yPMQnn6OehdZ_gABVgE"]
[Mon Jul 20 07:08:13.748171 2026] [security2:error] [pid 49578:tid 49741] [client 194.61.41.98:46509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/ALFA_DATA/alfacgiapi/bypass.php"] [unique_id "al4dvbU3yPMQnn6OehdaFgAAASs"]
[Mon Jul 20 07:08:13.919781 2026] [security2:error] [pid 49578:tid 49716] [client 14.225.17.146:54543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4dvbU3yPMQnn6OehdaGgAAARI"]
[Mon Jul 20 07:08:14.082829 2026] [security2:error] [pid 49578:tid 49631] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "oauth.jeffjaeger.com"] [uri "/wp-config.php.bak"] [unique_id "al4dvrU3yPMQnn6OehdaNQABRTQ"]
[Mon Jul 20 07:08:14.568720 2026] [security2:error] [pid 49578:tid 49770] [client 194.61.41.77:35197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/about.php"] [unique_id "al4dvrU3yPMQnn6OehdaZgAAAUg"]
[Mon Jul 20 07:08:14.604372 2026] [security2:error] [pid 49578:tid 49757] [client 77.110.127.138:63832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dvrU3yPMQnn6OehdaaQAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:14.604488 2026] [security2:error] [pid 49578:tid 49757] [client 77.110.127.138:63832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dvrU3yPMQnn6OehdaaQAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:14.693042 2026] [security2:error] [pid 49578:tid 49615] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "oauth.jeffjaeger.com"] [uri "/wp-config.php.old"] [unique_id "al4dvrU3yPMQnn6OehdadgABaCQ"]
[Mon Jul 20 07:08:14.693660 2026] [security2:error] [pid 49578:tid 49686] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oauth.jeffjaeger.com"] [uri "/config/.env.php"] [unique_id "al4dvrU3yPMQnn6OehdadwABaGs"]
[Mon Jul 20 07:08:14.693681 2026] [security2:error] [pid 49578:tid 49614] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.php.bak"] [unique_id "al4dvrU3yPMQnn6OehdaeAABaCM"]
[Mon Jul 20 07:08:14.694644 2026] [security2:error] [pid 49578:tid 49591] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/core/.env"] [unique_id "al4dvrU3yPMQnn6OehdaeQABaAw"]
[Mon Jul 20 07:08:14.694711 2026] [security2:error] [pid 49578:tid 49649] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/laravel/.env"] [unique_id "al4dvrU3yPMQnn6OehdadQABaEY"]
[Mon Jul 20 07:08:14.752413 2026] [core:error] [pid 49578:tid 49718] [client 14.225.17.146:55066] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:14.752442 2026] [core:error] [pid 49578:tid 49718] [client 14.225.17.146:55066] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:15.049914 2026] [security2:error] [pid 49578:tid 49756] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dvrU3yPMQnn6OehdajAAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:15.137485 2026] [security2:error] [pid 49578:tid 49590] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oauth.jeffjaeger.com"] [uri "/config.php.bak"] [unique_id "al4dv7U3yPMQnn6OehdarQABPAs"]
[Mon Jul 20 07:08:15.298280 2026] [security2:error] [pid 49578:tid 49658] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.104.156.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "oauth.jeffjaeger.com"] [uri "/configuration.php.bak"] [unique_id "al4dv7U3yPMQnn6OehdawAABSk8"]
[Mon Jul 20 07:08:15.298298 2026] [security2:error] [pid 49578:tid 49646] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/public/.env"] [unique_id "al4dv7U3yPMQnn6OehdavwABSkM"]
[Mon Jul 20 07:08:15.300557 2026] [security2:error] [pid 49578:tid 49653] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.swp"] [unique_id "al4dv7U3yPMQnn6OehdawQABSko"]
[Mon Jul 20 07:08:15.349530 2026] [security2:error] [pid 49578:tid 49757] [client 14.225.17.146:58399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4dv7U3yPMQnn6OehdauwAAATs"], referer: http://whiteoutcb.com/2024
[Mon Jul 20 07:08:15.364132 2026] [security2:error] [pid 49578:tid 49765] [client 194.61.41.60:43273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/about.php"] [unique_id "al4dv7U3yPMQnn6OehdaxwAAAUM"]
[Mon Jul 20 07:08:15.478386 2026] [security2:error] [pid 49578:tid 49778] [client 14.225.17.146:55040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4dvrU3yPMQnn6OehdanQAAAVA"], referer: http://gearwaterproof.com/2024
[Mon Jul 20 07:08:16.026954 2026] [security2:error] [pid 49578:tid 49823] [client 201.27.111.74:58627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dwLU3yPMQnn6Oehda9gAAAX0"]
[Mon Jul 20 07:08:16.027124 2026] [security2:error] [pid 49578:tid 49823] [client 201.27.111.74:58627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dwLU3yPMQnn6Oehda9gAAAX0"]
[Mon Jul 20 07:08:16.145653 2026] [security2:error] [pid 49578:tid 49710] [client 194.61.41.67:27473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/2023/05/404.php"] [unique_id "al4dwLU3yPMQnn6OehdbAAAAAQw"]
[Mon Jul 20 07:08:16.187095 2026] [security2:error] [pid 49578:tid 49827] [client 216.24.212.31:64013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4dwLU3yPMQnn6OehdbAwAAAYE"]
[Mon Jul 20 07:08:16.193521 2026] [security2:error] [pid 49578:tid 49774] [client 216.24.212.11:51141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4dwLU3yPMQnn6OehdbBgAAAUw"]
[Mon Jul 20 07:08:16.260082 2026] [security2:error] [pid 49578:tid 49638] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/web/.env"] [unique_id "al4dwLU3yPMQnn6OehdbEAABcDs"]
[Mon Jul 20 07:08:16.282589 2026] [security2:error] [pid 49578:tid 49616] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/appsettings.json"] [unique_id "al4dwLU3yPMQnn6OehdbHAABOiU"]
[Mon Jul 20 07:08:16.282784 2026] [security2:error] [pid 49578:tid 49756] [client 34.156.104.72:36370] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "oauth.jeffjaeger.com"] [uri "/appsettings.json"] [unique_id "al4dwLU3yPMQnn6OehdbHAABOiU"]
[Mon Jul 20 07:08:16.466453 2026] [security2:error] [pid 49578:tid 49828] [client 50.116.65.227:10184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dwLU3yPMQnn6OehdbKgAAAYI"]
[Mon Jul 20 07:08:16.475585 2026] [security2:error] [pid 49578:tid 49725] [client 50.116.65.227:10200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dwLU3yPMQnn6OehdbKwAAARs"]
[Mon Jul 20 07:08:16.569977 2026] [security2:error] [pid 49578:tid 49712] [client 57.141.18.86:52394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dvrU3yPMQnn6OehdaagABDng"]
[Mon Jul 20 07:08:16.742567 2026] [security2:error] [pid 49578:tid 49822] [client 14.225.17.146:57612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4dv7U3yPMQnn6OehdayQAAAXw"], referer: http://39ishlife.com/2024
[Mon Jul 20 07:08:16.850326 2026] [security2:error] [pid 49578:tid 49683] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/web.config"] [unique_id "al4dwLU3yPMQnn6OehdbVAABOmg"]
[Mon Jul 20 07:08:16.935722 2026] [security2:error] [pid 49578:tid 49808] [client 194.61.41.104:31379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/maint.php"] [unique_id "al4dwLU3yPMQnn6OehdbXQAAAW4"]
[Mon Jul 20 07:08:16.969618 2026] [security2:error] [pid 49578:tid 49722] [client 14.225.17.146:59570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4dwLU3yPMQnn6OehdbNwAAARg"], referer: http://maxenengineering.com/2024
[Mon Jul 20 07:08:17.179709 2026] [security2:error] [pid 49578:tid 49605] [remote 47.86.33.52:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4dwbU3yPMQnn6OehdbaQABZho"]
[Mon Jul 20 07:08:17.392589 2026] [core:error] [pid 49578:tid 49812] [client 205.210.31.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:17.392621 2026] [core:error] [pid 49578:tid 49812] [client 205.210.31.45:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:17.421610 2026] [proxy:warn] [pid 49578:tid 49814] [client 199.45.154.154:38832] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 07:08:17.421641 2026] [proxy:error] [pid 49578:tid 49814] (70014)End of file found: [client 199.45.154.154:38832] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 199.45.154.154 ()
[Mon Jul 20 07:08:17.482429 2026] [security2:error] [pid 49578:tid 49716] [client 117.247.108.24:65332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dwbU3yPMQnn6OehdblQAAARI"]
[Mon Jul 20 07:08:17.482536 2026] [security2:error] [pid 49578:tid 49716] [client 117.247.108.24:65332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dwbU3yPMQnn6OehdblQAAARI"]
[Mon Jul 20 07:08:17.726001 2026] [security2:error] [pid 49578:tid 49714] [client 194.61.41.67:56127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/bypass.php"] [unique_id "al4dwbU3yPMQnn6OehdbrAAAARA"]
[Mon Jul 20 07:08:17.727047 2026] [security2:error] [pid 49578:tid 49786] [client 14.225.17.146:64977] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4dwbU3yPMQnn6OehdbngAAAVg"], referer: https://39ishlife.com/2024
[Mon Jul 20 07:08:17.810929 2026] [security2:error] [pid 49578:tid 49671] [remote 47.86.33.52:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4dwbU3yPMQnn6OehdbsAABXVw"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 07:08:17.869257 2026] [security2:error] [pid 49578:tid 49635] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.test"] [unique_id "al4dwbU3yPMQnn6OehdbvAABMjg"]
[Mon Jul 20 07:08:17.926652 2026] [security2:error] [pid 49578:tid 49801] [client 14.225.17.146:65059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4dwbU3yPMQnn6OehdbsQAAAWc"], referer: https://maxenengineering.com/2024
[Mon Jul 20 07:08:18.076284 2026] [security2:error] [pid 49578:tid 49606] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/server/.env"] [unique_id "al4dwrU3yPMQnn6OehdbzAABMhs"]
[Mon Jul 20 07:08:18.137376 2026] [security2:error] [pid 49578:tid 49653] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/dev/.env"] [unique_id "al4dwrU3yPMQnn6Oehdb0wABMko"]
[Mon Jul 20 07:08:18.137460 2026] [security2:error] [pid 49578:tid 49658] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/src/.env"] [unique_id "al4dwrU3yPMQnn6Oehdb0gABMk8"]
[Mon Jul 20 07:08:18.137517 2026] [security2:error] [pid 49578:tid 49666] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/frontend/.env"] [unique_id "al4dwrU3yPMQnn6Oehdb1AABMlc"]
[Mon Jul 20 07:08:18.137535 2026] [security2:error] [pid 49578:tid 49619] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/app/.env"] [unique_id "al4dwrU3yPMQnn6Oehdb1gABMig"]
[Mon Jul 20 07:08:18.137717 2026] [security2:error] [pid 49578:tid 49646] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/production/.env"] [unique_id "al4dwrU3yPMQnn6Oehdb0QABMkM"]
[Mon Jul 20 07:08:18.137783 2026] [security2:error] [pid 49578:tid 49629] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/docker/.env"] [unique_id "al4dwrU3yPMQnn6Oehdb1wABMjI"]
[Mon Jul 20 07:08:18.181297 2026] [autoindex:error] [pid 49578:tid 49775] [client 199.45.154.154:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:08:18.481537 2026] [security2:error] [pid 49578:tid 49663] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.production.bak"] [unique_id "al4dwrU3yPMQnn6Oehdb_wABZ1Q"]
[Mon Jul 20 07:08:18.481710 2026] [security2:error] [pid 49578:tid 49665] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/@fs/root/.env"] [unique_id "al4dwrU3yPMQnn6OehdcAQABZ1Y"]
[Mon Jul 20 07:08:18.482240 2026] [security2:error] [pid 49578:tid 49667] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/.env.prod.bak"] [unique_id "al4dwrU3yPMQnn6OehdcAAABZ1g"]
[Mon Jul 20 07:08:18.520663 2026] [security2:error] [pid 49578:tid 49643] [remote 34.156.104.72:36370] ModSecurity: Access denied with connection close (phase 1). Pattern match "proc/self/environ" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1161"] [id "999997"] [msg "proc environ"] [hostname "oauth.jeffjaeger.com"] [uri "/@fs/proc/self/environ"] [unique_id "al4dwrU3yPMQnn6OehdcBAABa0A"]
[Mon Jul 20 07:08:18.521363 2026] [security2:error] [pid 49578:tid 49604] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/@fs/.env"] [unique_id "al4dwrU3yPMQnn6OehdcAwABaxk"]
[Mon Jul 20 07:08:18.521723 2026] [security2:error] [pid 49578:tid 49691] [remote 34.156.104.72:36370] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "oauth.jeffjaeger.com"] [uri "/staging/.env"] [unique_id "al4dwrU3yPMQnn6OehdcBQABa3A"]
[Mon Jul 20 07:08:18.528143 2026] [security2:error] [pid 49578:tid 49793] [client 194.61.41.62:37665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/aa.php"] [unique_id "al4dwrU3yPMQnn6OehdcBgAAAV8"]
[Mon Jul 20 07:08:18.762182 2026] [security2:error] [pid 49578:tid 49778] [client 74.7.228.0:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4dwrU3yPMQnn6OehdcDgAAAVA"]
[Mon Jul 20 07:08:18.765212 2026] [security2:error] [pid 49578:tid 49745] [client 74.7.228.0:45262] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "whiteoutcb.com"] [uri "/robots.txt"] [unique_id "al4dwrU3yPMQnn6OehdcDAABL1U"]
[Mon Jul 20 07:08:19.023208 2026] [security2:error] [pid 49578:tid 49698] [remote 47.128.29.205:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tiokubito.cl"] [uri "/robots.txt"] [unique_id "al4dw7U3yPMQnn6OehdcKQABWHc"]
[Mon Jul 20 07:08:19.239977 2026] [security2:error] [pid 49578:tid 49794] [client 194.61.41.94:30891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/index2.php"] [unique_id "al4dw7U3yPMQnn6OehdcPAAAAWA"]
[Mon Jul 20 07:08:19.341466 2026] [security2:error] [pid 49578:tid 49732] [client 14.225.17.146:58068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4dwbU3yPMQnn6OehdbwwAAASI"], referer: http://slutilities.com/2024
[Mon Jul 20 07:08:19.461734 2026] [security2:error] [pid 49578:tid 49756] [client 187.16.64.216:54791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dw7U3yPMQnn6OehdcXAAAATo"]
[Mon Jul 20 07:08:19.461876 2026] [security2:error] [pid 49578:tid 49756] [client 187.16.64.216:54791] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dw7U3yPMQnn6OehdcXAAAATo"]
[Mon Jul 20 07:08:19.484480 2026] [security2:error] [pid 49578:tid 49724] [client 45.157.112.60:51813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dw7U3yPMQnn6OehdcXgAAARo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:08:19.800761 2026] [security2:error] [pid 49578:tid 49749] [client 77.110.127.138:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dw7U3yPMQnn6OehdceQAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:19.800846 2026] [security2:error] [pid 49578:tid 49749] [client 77.110.127.138:63872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dw7U3yPMQnn6OehdceQAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:19.851402 2026] [security2:error] [pid 49578:tid 49697] [remote 34.156.104.72:59124] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/gcp-key.json"] [unique_id "al4dw7U3yPMQnn6OehdchwABTHY"]
[Mon Jul 20 07:08:19.851454 2026] [security2:error] [pid 49578:tid 49602] [remote 34.156.104.72:59124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oauth.jeffjaeger.com"] [uri "/config/firebase-admin.json"] [unique_id "al4dw7U3yPMQnn6OehdcigABTBc"]
[Mon Jul 20 07:08:19.983977 2026] [security2:error] [pid 49578:tid 49600] [remote 152.228.213.32:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4dw7U3yPMQnn6OehdcmQABMBU"]
[Mon Jul 20 07:08:20.025594 2026] [security2:error] [pid 49578:tid 49750] [client 57.141.18.30:35542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dwrU3yPMQnn6Oehdb5AABNDw"]
[Mon Jul 20 07:08:20.028489 2026] [security2:error] [pid 49578:tid 49781] [client 194.61.41.75:56917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/hello-element/footer.php"] [unique_id "al4dxLU3yPMQnn6OehdcpQAAAVM"]
[Mon Jul 20 07:08:20.162933 2026] [security2:error] [pid 49578:tid 49615] [remote 152.228.213.32:53256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/wp-login.php"] [unique_id "al4dxLU3yPMQnn6OehdcrAABCyQ"], referer: https://mail.grndl.com/wp-login.php
[Mon Jul 20 07:08:20.201949 2026] [security2:error] [pid 49578:tid 49803] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dw7U3yPMQnn6OehdcnwAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:20.550993 2026] [security2:error] [pid 49578:tid 49589] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dxLU3yPMQnn6Oehdc2gABHAo"]
[Mon Jul 20 07:08:20.551190 2026] [security2:error] [pid 49578:tid 49726] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dxLU3yPMQnn6Oehdc2gABHAo"]
[Mon Jul 20 07:08:20.559965 2026] [security2:error] [pid 49578:tid 49743] [client 14.225.17.146:58069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4dxLU3yPMQnn6OehdczQAAAS0"], referer: http://samdothan.org/2024
[Mon Jul 20 07:08:20.717296 2026] [security2:error] [pid 49578:tid 49786] [client 14.225.17.146:57660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4dxLU3yPMQnn6OehdcvAAAAVg"], referer: http://areitoproducciones.com/2024
[Mon Jul 20 07:08:20.742128 2026] [security2:error] [pid 49578:tid 49830] [client 194.61.41.243:64813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/admin.php"] [unique_id "al4dxLU3yPMQnn6Oehdc5wAAAYQ"]
[Mon Jul 20 07:08:20.990396 2026] [security2:error] [pid 49578:tid 49725] [client 154.208.48.130:64777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dxLU3yPMQnn6OehddCwAAARs"]
[Mon Jul 20 07:08:20.990537 2026] [security2:error] [pid 49578:tid 49725] [client 154.208.48.130:64777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4dxLU3yPMQnn6OehddCwAAARs"]
[Mon Jul 20 07:08:21.115842 2026] [security2:error] [pid 49578:tid 49733] [client 18.184.179.151:25576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dxbU3yPMQnn6OehddFAAAASM"]
[Mon Jul 20 07:08:21.539162 2026] [security2:error] [pid 49578:tid 49722] [client 213.152.161.101:37368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dxbU3yPMQnn6OehddMQAAARg"]
[Mon Jul 20 07:08:21.539276 2026] [security2:error] [pid 49578:tid 49722] [client 213.152.161.101:37368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dxbU3yPMQnn6OehddMQAAARg"]
[Mon Jul 20 07:08:21.541064 2026] [security2:error] [pid 49578:tid 49821] [client 194.61.41.96:23917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/2index.php"] [unique_id "al4dxbU3yPMQnn6OehddMgAAAXs"]
[Mon Jul 20 07:08:21.665636 2026] [security2:error] [pid 49578:tid 49775] [client 63.179.149.246:43006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4dxbU3yPMQnn6OehddOwAAAU0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:08:21.711886 2026] [authz_core:error] [pid 49578:tid 49696] [remote 35.252.182.126:63221] AH01630: client denied by server configuration: /home1/asliceo1/public_html/jmark/php.ini, referer: http://www.jmark.asliceofleadership.com
[Mon Jul 20 07:08:21.886870 2026] [security2:error] [pid 49578:tid 49749] [client 88.241.67.160:54938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dxbU3yPMQnn6OehddWAAAATM"]
[Mon Jul 20 07:08:21.887051 2026] [security2:error] [pid 49578:tid 49749] [client 88.241.67.160:54938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dxbU3yPMQnn6OehddWAAAATM"]
[Mon Jul 20 07:08:22.297906 2026] [security2:error] [pid 49578:tid 49754] [client 89.167.13.70:23807] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "areitoproducciones.com"] [uri "/"] [unique_id "al4dxrU3yPMQnn6OehddiQAAATg"]
[Mon Jul 20 07:08:22.324261 2026] [security2:error] [pid 49578:tid 49812] [client 194.61.41.242:36525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/plugins.php"] [unique_id "al4dxrU3yPMQnn6OehddjAAAAXI"]
[Mon Jul 20 07:08:22.431949 2026] [security2:error] [pid 49578:tid 49810] [client 74.7.227.179:60804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4dxrU3yPMQnn6OehddiAABcH0"], referer: https://tejasenvironmental.com/p=3497836
[Mon Jul 20 07:08:22.698494 2026] [security2:error] [pid 49578:tid 49764] [client 127.0.0.1:27806] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4dxrU3yPMQnn6OehddrAAAAUI"], referer: https://duckduckgo.com/?q=kit35
[Mon Jul 20 07:08:22.918432 2026] [security2:error] [pid 49578:tid 49770] [client 103.144.65.217:59593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dxrU3yPMQnn6OehdduQAAAUg"]
[Mon Jul 20 07:08:22.918593 2026] [security2:error] [pid 49578:tid 49770] [client 103.144.65.217:59593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4dxrU3yPMQnn6OehdduQAAAUg"]
[Mon Jul 20 07:08:22.945595 2026] [security2:error] [pid 49578:tid 49788] [client 104.234.53.66:59465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4dxrU3yPMQnn6OehddvQAAAVo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:23.051022 2026] [security2:error] [pid 49578:tid 49815] [client 194.61.41.85:22709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/shell.php"] [unique_id "al4dx7U3yPMQnn6OehddyAAAAXU"]
[Mon Jul 20 07:08:23.619182 2026] [security2:error] [pid 49578:tid 49669] [remote 168.138.197.172:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.197.138.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4dx7U3yPMQnn6Oehdd9QABK1o"]
[Mon Jul 20 07:08:23.825598 2026] [security2:error] [pid 49578:tid 49760] [client 183.82.98.154:55454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dx7U3yPMQnn6OehdeAgAAAT4"]
[Mon Jul 20 07:08:23.825692 2026] [security2:error] [pid 49578:tid 49760] [client 183.82.98.154:55454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4dx7U3yPMQnn6OehdeAgAAAT4"]
[Mon Jul 20 07:08:23.836702 2026] [security2:error] [pid 49578:tid 49737] [client 194.61.41.73:62487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/content.php"] [unique_id "al4dx7U3yPMQnn6OehdeBQAAASc"]
[Mon Jul 20 07:08:24.007230 2026] [security2:error] [pid 49578:tid 49645] [remote 168.138.197.172:51496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.197.138.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fansarogroup.com"] [uri "/wp-login.php"] [unique_id "al4dyLU3yPMQnn6OehdeFAABO0I"], referer: https://fansarogroup.com/wp-login.php
[Mon Jul 20 07:08:24.013581 2026] [security2:error] [pid 49578:tid 49811] [client 104.234.53.49:46465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4dyLU3yPMQnn6OehdeEwAAAXE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:24.201587 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:63900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dyLU3yPMQnn6OehdeKAAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:24.201671 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:63900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dyLU3yPMQnn6OehdeKAAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:24.578840 2026] [security2:error] [pid 49578:tid 49737] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dyLU3yPMQnn6OehdeNwAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:24.656664 2026] [security2:error] [pid 49578:tid 49811] [client 194.61.41.81:38945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/about.php"] [unique_id "al4dyLU3yPMQnn6OehdeRQAAAXE"]
[Mon Jul 20 07:08:24.992594 2026] [autoindex:error] [pid 49578:tid 49688] [remote 34.53.14.183:54058] AH01276: Cannot serve directory /home2/oqkxeemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.oqk.xee.mybluehost.me
[Mon Jul 20 07:08:25.054881 2026] [security2:error] [pid 49578:tid 49732] [client 114.119.129.199:24031] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sanifidensolutions.com"] [uri "/"] [unique_id "al4dybU3yPMQnn6OehdeYQAAASI"], referer: https://sidhulawyers.com.au/sitemap_quality_80.xml
[Mon Jul 20 07:08:25.197333 2026] [security2:error] [pid 49578:tid 49580] [remote 72.167.132.114:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dybU3yPMQnn6OehdebwABGAE"]
[Mon Jul 20 07:08:25.198637 2026] [security2:error] [pid 49578:tid 49798] [client 213.152.161.101:37382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dybU3yPMQnn6OehdecQAAAWQ"]
[Mon Jul 20 07:08:25.198718 2026] [security2:error] [pid 49578:tid 49798] [client 213.152.161.101:37382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dybU3yPMQnn6OehdecQAAAWQ"]
[Mon Jul 20 07:08:25.426622 2026] [security2:error] [pid 49578:tid 49664] [remote 72.167.132.114:52006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4dybU3yPMQnn6OehdehQABglU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:08:25.430733 2026] [security2:error] [pid 49578:tid 49822] [client 194.61.41.73:20831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/atomlib.php"] [unique_id "al4dybU3yPMQnn6OehdeiAAAAXw"]
[Mon Jul 20 07:08:25.790192 2026] [security2:error] [pid 49578:tid 49793] [client 158.173.89.95:47147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4dybU3yPMQnn6OehderAAAAV8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:08:26.178787 2026] [security2:error] [pid 49578:tid 49720] [client 194.61.41.66:25251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/install.php"] [unique_id "al4dyrU3yPMQnn6OehdevwAAARY"]
[Mon Jul 20 07:08:26.410805 2026] [security2:error] [pid 49578:tid 49806] [client 159.223.218.25:61811] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.transamericagrid.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4dyrU3yPMQnn6Oehde0wAAAWw"]
[Mon Jul 20 07:08:26.466107 2026] [security2:error] [pid 49578:tid 49739] [client 201.27.111.74:59104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dyrU3yPMQnn6Oehde2QAAASk"]
[Mon Jul 20 07:08:26.466266 2026] [security2:error] [pid 49578:tid 49739] [client 201.27.111.74:59104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4dyrU3yPMQnn6Oehde2QAAASk"]
[Mon Jul 20 07:08:26.673027 2026] [security2:error] [pid 49578:tid 49624] [remote 217.160.133.107:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.133.160.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dyrU3yPMQnn6Oehde4gABYy0"]
[Mon Jul 20 07:08:26.946366 2026] [security2:error] [pid 49578:tid 49773] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dyrU3yPMQnn6Oehde8gAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:26.949593 2026] [security2:error] [pid 49578:tid 49824] [client 194.61.41.88:33323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/hehe.php"] [unique_id "al4dyrU3yPMQnn6OehdfBQAAAX4"]
[Mon Jul 20 07:08:27.040216 2026] [security2:error] [pid 49578:tid 49591] [remote 217.160.133.107:56232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.133.160.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4dy7U3yPMQnn6OehdfCQABIQw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:08:27.176132 2026] [security2:error] [pid 49578:tid 49739] [client 77.110.127.138:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dy7U3yPMQnn6OehdfEQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:27.176233 2026] [security2:error] [pid 49578:tid 49739] [client 77.110.127.138:63912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dy7U3yPMQnn6OehdfEQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:27.657771 2026] [security2:error] [pid 49578:tid 49744] [client 77.110.127.138:63915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dy7U3yPMQnn6OehdfQgAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:27.657918 2026] [security2:error] [pid 49578:tid 49744] [client 77.110.127.138:63915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dy7U3yPMQnn6OehdfQgAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:27.730576 2026] [security2:error] [pid 49578:tid 49770] [client 194.61.41.242:46873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/fonts/autoload_classmap.php"] [unique_id "al4dy7U3yPMQnn6OehdfSQAAAUg"]
[Mon Jul 20 07:08:27.959486 2026] [security2:error] [pid 49578:tid 49729] [client 14.225.17.146:62822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4dyrU3yPMQnn6OehdexgAAAR8"], referer: http://according2plant.com/2024
[Mon Jul 20 07:08:27.960070 2026] [security2:error] [pid 49578:tid 49763] [client 14.225.17.146:64842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4dy7U3yPMQnn6OehdfUgAAAUE"], referer: http://friendlyspreadsheet.com/2024
[Mon Jul 20 07:08:28.140665 2026] [proxy:error] [pid 49578:tid 49740] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:08:28.140702 2026] [proxy_http:error] [pid 49578:tid 49740] [client 195.96.139.69:33123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:08:28.141301 2026] [proxy:error] [pid 49578:tid 49740] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:08:28.141327 2026] [proxy_http:error] [pid 49578:tid 49740] [client 195.96.139.69:33123] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:08:28.187398 2026] [security2:error] [pid 49578:tid 49823] [client 14.225.17.146:64774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4dzLU3yPMQnn6OehdfYAAAAX0"], referer: http://eduardsales.com/2024
[Mon Jul 20 07:08:28.267901 2026] [core:error] [pid 49578:tid 49738] [client 205.210.31.151:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:28.267921 2026] [core:error] [pid 49578:tid 49738] [client 205.210.31.151:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:28.306410 2026] [security2:error] [pid 49578:tid 49803] [client 117.247.108.24:65526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dzLU3yPMQnn6OehdfeQAAAWk"]
[Mon Jul 20 07:08:28.306523 2026] [security2:error] [pid 49578:tid 49803] [client 117.247.108.24:65526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4dzLU3yPMQnn6OehdfeQAAAWk"]
[Mon Jul 20 07:08:28.521888 2026] [security2:error] [pid 49578:tid 49771] [client 194.61.41.76:61825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/slider.php"] [unique_id "al4dzLU3yPMQnn6OehdfjAAAAUk"]
[Mon Jul 20 07:08:28.657866 2026] [security2:error] [pid 49578:tid 49735] [client 57.141.18.40:65176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dy7U3yPMQnn6OehdfEAABJX4"]
[Mon Jul 20 07:08:28.988459 2026] [security2:error] [pid 49578:tid 49779] [client 14.225.17.146:64846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4dzLU3yPMQnn6OehdfqQAAAVE"], referer: https://friendlyspreadsheet.com/2024
[Mon Jul 20 07:08:29.104009 2026] [security2:error] [pid 49578:tid 49797] [client 50.116.65.227:41848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4dzbU3yPMQnn6OehdftQAAAWM"]
[Mon Jul 20 07:08:29.117217 2026] [security2:error] [pid 49578:tid 49759] [client 50.116.65.227:41854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4dzbU3yPMQnn6OehdftgAAAT0"]
[Mon Jul 20 07:08:29.156070 2026] [security2:error] [pid 49578:tid 49812] [client 14.225.17.146:52445] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4dzbU3yPMQnn6OehdfsgAAAXI"], referer: http://momheadquarters.com/2024
[Mon Jul 20 07:08:29.255568 2026] [security2:error] [pid 49578:tid 49799] [client 194.61.41.99:35177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/dir.php"] [unique_id "al4dzbU3yPMQnn6OehdfywAAAWU"]
[Mon Jul 20 07:08:29.533162 2026] [security2:error] [pid 49578:tid 49797] [client 77.110.127.138:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dzbU3yPMQnn6Oehdf4AAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:29.533259 2026] [security2:error] [pid 49578:tid 49797] [client 77.110.127.138:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dzbU3yPMQnn6Oehdf4AAAAWM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:29.565162 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4dzbU3yPMQnn6Oehdf1QAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:29.657499 2026] [security2:error] [pid 49578:tid 49782] [client 50.116.65.227:41874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dzbU3yPMQnn6Oehdf2gAAAVQ"]
[Mon Jul 20 07:08:29.811000 2026] [security2:error] [pid 49578:tid 49767] [client 14.225.17.146:62906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4dzbU3yPMQnn6Oehdf2wAAAUU"], referer: http://hilltopnurseryinc.com/2024
[Mon Jul 20 07:08:29.840835 2026] [security2:error] [pid 49578:tid 49798] [client 50.116.65.227:41882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4dzbU3yPMQnn6Oehdf7gAAAWQ"]
[Mon Jul 20 07:08:29.851447 2026] [ssl:error] [pid 49578:tid 49738] [client 104.48.69.105:55704] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:08:30.028969 2026] [security2:error] [pid 49578:tid 49777] [client 194.61.41.249:25735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/atomlib.php"] [unique_id "al4dzrU3yPMQnn6OehdgCAAAAU8"]
[Mon Jul 20 07:08:30.223589 2026] [security2:error] [pid 49578:tid 49758] [client 187.16.64.216:55368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dzrU3yPMQnn6OehdgEQAAATw"]
[Mon Jul 20 07:08:30.223684 2026] [security2:error] [pid 49578:tid 49758] [client 187.16.64.216:55368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4dzrU3yPMQnn6OehdgEQAAATw"]
[Mon Jul 20 07:08:30.512301 2026] [security2:error] [pid 49578:tid 49714] [client 158.173.241.141:63855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4dzrU3yPMQnn6OehdgHgABEGk"]
[Mon Jul 20 07:08:30.519824 2026] [security2:error] [pid 49578:tid 49716] [client 117.211.236.168:64308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4dzrU3yPMQnn6OehdgJwAAARI"]
[Mon Jul 20 07:08:30.520017 2026] [security2:error] [pid 49578:tid 49716] [client 117.211.236.168:64308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4dzrU3yPMQnn6OehdgJwAAARI"]
[Mon Jul 20 07:08:30.627935 2026] [security2:error] [pid 49578:tid 49602] [remote 8.217.108.67:8440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dzrU3yPMQnn6OehdgMwABXhc"]
[Mon Jul 20 07:08:30.826220 2026] [security2:error] [pid 49578:tid 49802] [client 194.61.41.62:23627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/style.php"] [unique_id "al4dzrU3yPMQnn6OehdgSQAAAWg"]
[Mon Jul 20 07:08:31.128543 2026] [security2:error] [pid 49578:tid 49686] [remote 182.77.62.24:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4dz7U3yPMQnn6OehdgXQABLGs"]
[Mon Jul 20 07:08:31.166325 2026] [security2:error] [pid 49578:tid 49648] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dz7U3yPMQnn6OehdgYgABG0U"]
[Mon Jul 20 07:08:31.166471 2026] [security2:error] [pid 49578:tid 49725] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4dz7U3yPMQnn6OehdgYgABG0U"]
[Mon Jul 20 07:08:31.168149 2026] [security2:error] [pid 49578:tid 49714] [client 74.208.214.194:35730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dz7U3yPMQnn6OehdgYwAAARA"]
[Mon Jul 20 07:08:31.204478 2026] [security2:error] [pid 49578:tid 49804] [client 77.110.127.138:63933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dz7U3yPMQnn6OehdgZQAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:31.204589 2026] [security2:error] [pid 49578:tid 49804] [client 77.110.127.138:63933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4dz7U3yPMQnn6OehdgZQAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:31.216740 2026] [security2:error] [pid 49578:tid 49785] [client 50.116.65.227:39872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4dz7U3yPMQnn6OehdgZgAAAVc"]
[Mon Jul 20 07:08:31.228983 2026] [security2:error] [pid 49578:tid 49715] [client 50.116.65.227:41894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4dz7U3yPMQnn6OehdgagAAAWs"]
[Mon Jul 20 07:08:31.286676 2026] [security2:error] [pid 49578:tid 49767] [client 114.119.159.145:63777] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.crmpfilms.com"] [uri "/%23about"] [unique_id "al4dz7U3yPMQnn6OehdgcgAAAUU"], referer: https://www.crmpfilms.com/%23about
[Mon Jul 20 07:08:31.412247 2026] [security2:error] [pid 49578:tid 49682] [remote 8.217.108.67:8440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4dz7U3yPMQnn6OehdgfAABfGc"], referer: https://mail.fvx.wyy.mybluehost.me/wp-login.php
[Mon Jul 20 07:08:31.476174 2026] [security2:error] [pid 49578:tid 49732] [client 14.225.17.146:52710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4dz7U3yPMQnn6OehdgdgAAASI"], referer: http://bbwipartnerconference.com/2024
[Mon Jul 20 07:08:31.553550 2026] [security2:error] [pid 49578:tid 49835] [client 194.61.41.83:63725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/libraries/phpmailer/updates.php"] [unique_id "al4dz7U3yPMQnn6OehdgiAAAAYk"]
[Mon Jul 20 07:08:31.559285 2026] [security2:error] [pid 49578:tid 49769] [client 74.208.214.194:35732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4dz7U3yPMQnn6OehdgigAAAUc"]
[Mon Jul 20 07:08:31.653869 2026] [security2:error] [pid 49578:tid 49617] [remote 182.77.62.24:46954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4dz7U3yPMQnn6OehdgjwABYiY"], referer: https://rtkenergypartners.com/wp-login.php
[Mon Jul 20 07:08:31.663991 2026] [security2:error] [pid 49578:tid 49814] [client 45.129.228.117:44884] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "giftsurprizo.com"] [uri "/wp-comments-post.php"] [unique_id "al4dz7U3yPMQnn6OehdgjAAAAXQ"]
[Mon Jul 20 07:08:31.913227 2026] [security2:error] [pid 49578:tid 49758] [client 14.225.17.146:64775] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4dz7U3yPMQnn6OehdglwAAATw"], referer: http://sesamegreenbeans.com/2024
[Mon Jul 20 07:08:32.002149 2026] [security2:error] [pid 49578:tid 49803] [client 14.225.17.146:52831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4dzbU3yPMQnn6Oehdf9AAAAWk"], referer: http://talknutritionwithlesley.com/2024
[Mon Jul 20 07:08:32.168262 2026] [security2:error] [pid 49578:tid 49814] [client 45.129.228.117:44884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "giftsurprizo.com"] [uri "/wp-comments-post.php"] [unique_id "al4dz7U3yPMQnn6OehdgjAAAAXQ"]
[Mon Jul 20 07:08:32.344856 2026] [security2:error] [pid 49578:tid 49821] [client 77.110.127.138:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d0LU3yPMQnn6OehdgwgAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:32.345003 2026] [security2:error] [pid 49578:tid 49821] [client 77.110.127.138:63942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d0LU3yPMQnn6OehdgwgAAAXs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:32.353675 2026] [security2:error] [pid 49578:tid 49779] [client 194.61.41.105:47459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/nf_tracking.php"] [unique_id "al4d0LU3yPMQnn6OehdgwwAAAVE"]
[Mon Jul 20 07:08:32.500504 2026] [security2:error] [pid 49578:tid 49786] [client 14.225.17.146:56277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "arunavabanerjee.com"] [uri "/index.php"] [unique_id "al4d0LU3yPMQnn6OehdgxwAAAVg"]
[Mon Jul 20 07:08:32.504115 2026] [security2:error] [pid 49578:tid 49644] [remote 78.46.157.202:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4d0LU3yPMQnn6Oehdg1wABR0E"]
[Mon Jul 20 07:08:32.558199 2026] [security2:error] [pid 49578:tid 49629] [remote 217.61.143.92:44032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4d0LU3yPMQnn6Oehdg2wABXDI"]
[Mon Jul 20 07:08:32.564025 2026] [security2:error] [pid 49578:tid 49801] [client 88.241.67.160:55062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d0LU3yPMQnn6Oehdg3AAAAWc"]
[Mon Jul 20 07:08:32.564624 2026] [security2:error] [pid 49578:tid 49801] [client 88.241.67.160:55062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d0LU3yPMQnn6Oehdg3AAAAWc"]
[Mon Jul 20 07:08:32.601916 2026] [security2:error] [pid 49578:tid 49593] [remote 81.173.115.7:51242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d0LU3yPMQnn6Oehdg4QABTg4"]
[Mon Jul 20 07:08:32.731185 2026] [security2:error] [pid 49578:tid 49650] [remote 78.46.157.202:36688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4d0LU3yPMQnn6Oehdg6wABUkc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:08:32.788575 2026] [security2:error] [pid 49578:tid 49705] [remote 217.61.143.92:44032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4d0LU3yPMQnn6Oehdg9AABGH4"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 07:08:32.883941 2026] [security2:error] [pid 49578:tid 49594] [remote 81.173.115.7:51242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d0LU3yPMQnn6Oehdg9gABSg8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:08:32.979094 2026] [security2:error] [pid 49578:tid 49753] [client 14.225.17.146:56372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4d0LU3yPMQnn6Oehdg9QAAATc"], referer: https://sesamegreenbeans.com/2024
[Mon Jul 20 07:08:33.144141 2026] [security2:error] [pid 49578:tid 49835] [client 194.61.41.104:53913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/about.php7"] [unique_id "al4d0bU3yPMQnn6OehdhCQAAAYk"]
[Mon Jul 20 07:08:33.164393 2026] [security2:error] [pid 49578:tid 49755] [client 114.119.138.154:45081] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nextlevelpressurewashing.com"] [uri "/robots.txt"] [unique_id "al4d0bU3yPMQnn6OehdhCwAAATk"], referer: http://nextlevelpressurewashing.com/robots.txt
[Mon Jul 20 07:08:33.200883 2026] [security2:error] [pid 49578:tid 49777] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d0LU3yPMQnn6Oehdg_gAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:33.462526 2026] [security2:error] [pid 49578:tid 49743] [client 103.144.65.217:60057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d0bU3yPMQnn6OehdhIQAAAS0"]
[Mon Jul 20 07:08:33.462688 2026] [security2:error] [pid 49578:tid 49743] [client 103.144.65.217:60057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d0bU3yPMQnn6OehdhIQAAAS0"]
[Mon Jul 20 07:08:33.746534 2026] [security2:error] [pid 49578:tid 49747] [client 57.141.18.51:64344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4dz7U3yPMQnn6OehdgmgABMSw"]
[Mon Jul 20 07:08:33.844898 2026] [security2:error] [pid 49578:tid 49811] [client 77.110.127.138:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d0bU3yPMQnn6OehdhPwAAAXE"]
[Mon Jul 20 07:08:33.844995 2026] [security2:error] [pid 49578:tid 49811] [client 77.110.127.138:63949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d0bU3yPMQnn6OehdhPwAAAXE"]
[Mon Jul 20 07:08:33.929177 2026] [security2:error] [pid 49578:tid 49745] [client 194.61.41.95:42619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/filefuns.php"] [unique_id "al4d0bU3yPMQnn6OehdhQwAAAS8"]
[Mon Jul 20 07:08:34.329371 2026] [security2:error] [pid 49578:tid 49647] [remote 192.241.143.148:60070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4d0rU3yPMQnn6OehdhYgABg0Q"]
[Mon Jul 20 07:08:34.329531 2026] [security2:error] [pid 49578:tid 49829] [client 192.241.143.148:60070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4d0rU3yPMQnn6OehdhYgABg0Q"]
[Mon Jul 20 07:08:34.407204 2026] [security2:error] [pid 49578:tid 49828] [client 183.82.98.154:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d0rU3yPMQnn6OehdhbQAAAYI"]
[Mon Jul 20 07:08:34.407353 2026] [security2:error] [pid 49578:tid 49828] [client 183.82.98.154:56006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d0rU3yPMQnn6OehdhbQAAAYI"]
[Mon Jul 20 07:08:34.660289 2026] [security2:error] [pid 49578:tid 49802] [client 194.61.41.60:56693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/class_api.php"] [unique_id "al4d0rU3yPMQnn6OehdhgAAAAWg"]
[Mon Jul 20 07:08:35.257331 2026] [security2:error] [pid 49578:tid 49776] [client 77.110.127.138:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d07U3yPMQnn6OehdhvwAAAU4"]
[Mon Jul 20 07:08:35.257413 2026] [security2:error] [pid 49578:tid 49776] [client 77.110.127.138:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d07U3yPMQnn6OehdhvwAAAU4"]
[Mon Jul 20 07:08:35.317442 2026] [security2:error] [pid 49578:tid 49794] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d07U3yPMQnn6OehdhrwAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:35.442104 2026] [security2:error] [pid 49578:tid 49804] [client 194.61.41.250:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/l.php"] [unique_id "al4d07U3yPMQnn6OehdhzgAAAWo"]
[Mon Jul 20 07:08:35.721361 2026] [security2:error] [pid 49578:tid 49775] [client 104.234.53.50:28725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4d07U3yPMQnn6Oehdh3gAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:35.856660 2026] [security2:error] [pid 49578:tid 49597] [remote 45.90.123.233:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4d07U3yPMQnn6Oehdh7gABYhI"]
[Mon Jul 20 07:08:36.042541 2026] [security2:error] [pid 49578:tid 49649] [remote 130.51.180.8:33556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6Oehdh9QABJkY"]
[Mon Jul 20 07:08:36.087887 2026] [security2:error] [pid 49578:tid 49587] [remote 45.90.123.233:51256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6Oehdh_gABeQg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:08:36.111268 2026] [security2:error] [pid 49578:tid 49651] [remote 162.19.86.63:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6Oehdh_wABhUg"]
[Mon Jul 20 07:08:36.192316 2026] [security2:error] [pid 49578:tid 49728] [client 158.173.166.181:27891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4d1LU3yPMQnn6OehdiBwAAAR4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:08:36.196416 2026] [security2:error] [pid 49578:tid 49725] [client 43.173.176.216:50050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4d1LU3yPMQnn6OehdiAgAAARs"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:08:36.210866 2026] [security2:error] [pid 49578:tid 49609] [remote 130.51.180.8:33556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6OehdiCQABWh4"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 07:08:36.254516 2026] [security2:error] [pid 49578:tid 49808] [client 194.61.41.245:50061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/repeater.php"] [unique_id "al4d1LU3yPMQnn6OehdiDwAAAW4"]
[Mon Jul 20 07:08:36.272760 2026] [security2:error] [pid 49578:tid 49694] [remote 160.187.68.132:49510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6OehdiEAABX3M"]
[Mon Jul 20 07:08:36.280730 2026] [security2:error] [pid 49578:tid 49750] [client 43.172.197.104:51004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.197.172.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tour-interests.php"] [unique_id "al4d1LU3yPMQnn6OehdiEQAAATQ"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:08:36.335120 2026] [security2:error] [pid 49578:tid 49633] [remote 162.19.86.63:37330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6OehdiHQABMjY"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 07:08:36.429886 2026] [security2:error] [pid 49578:tid 49799] [client 43.173.176.234:35030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.176.173.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4d1LU3yPMQnn6OehdiKAAAAWU"], referer: https://www.savilerowtravel.com/tours/wines-of-the-douro-valley/
[Mon Jul 20 07:08:36.493993 2026] [security2:error] [pid 49578:tid 49835] [client 14.225.17.146:64567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4d1LU3yPMQnn6OehdiIAAAAYk"], referer: http://colinkeyphotography.com/2024
[Mon Jul 20 07:08:36.759259 2026] [security2:error] [pid 49578:tid 49794] [client 173.252.87.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4d1LU3yPMQnn6OehdiMQAAAWA"]
[Mon Jul 20 07:08:36.775197 2026] [security2:error] [pid 49578:tid 49590] [remote 160.187.68.132:49510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4d1LU3yPMQnn6OehdiPwABVAs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:08:36.924112 2026] [security2:error] [pid 49578:tid 49759] [client 82.102.18.116:45548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "adastra.love"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4d1LU3yPMQnn6OehdiSgAAAT0"]
[Mon Jul 20 07:08:36.995314 2026] [security2:error] [pid 49578:tid 49803] [client 201.27.111.74:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d1LU3yPMQnn6OehdiUQAAAWk"]
[Mon Jul 20 07:08:36.995431 2026] [security2:error] [pid 49578:tid 49803] [client 201.27.111.74:59591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d1LU3yPMQnn6OehdiUQAAAWk"]
[Mon Jul 20 07:08:37.018647 2026] [security2:error] [pid 49578:tid 49817] [client 194.61.41.72:34415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/wso.php"] [unique_id "al4d1bU3yPMQnn6OehdiVwAAAXc"]
[Mon Jul 20 07:08:37.269568 2026] [ssl:error] [pid 49578:tid 49820] [client 104.48.69.105:55720] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:08:37.339164 2026] [security2:error] [pid 49578:tid 49749] [client 14.225.17.146:61296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4d1bU3yPMQnn6OehdiXQAAATM"]
[Mon Jul 20 07:08:37.409003 2026] [security2:error] [pid 49578:tid 49717] [client 57.141.18.53:48858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4d07U3yPMQnn6Oehdh0AABE3w"]
[Mon Jul 20 07:08:37.418839 2026] [security2:error] [pid 49578:tid 49640] [remote 20.153.140.50:46218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4d1bU3yPMQnn6OehdidwABUz0"]
[Mon Jul 20 07:08:37.419154 2026] [security2:error] [pid 49578:tid 49781] [client 20.153.140.50:46218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4d1bU3yPMQnn6OehdidwABUz0"]
[Mon Jul 20 07:08:37.554664 2026] [security2:error] [pid 49578:tid 49785] [client 82.102.18.116:45558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/xmlrpc.php"] [unique_id "al4d1bU3yPMQnn6OehdifgAAAVc"]
[Mon Jul 20 07:08:37.754637 2026] [security2:error] [pid 49578:tid 49731] [client 194.61.41.247:22973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sitemaps/autoload_classmap.php"] [unique_id "al4d1bU3yPMQnn6OehdiiwAAASE"]
[Mon Jul 20 07:08:37.906183 2026] [security2:error] [pid 49578:tid 49804] [client 14.225.17.146:61156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4d1bU3yPMQnn6OehdihgAAAWo"], referer: http://tntcatholic.com/2024
[Mon Jul 20 07:08:38.071920 2026] [security2:error] [pid 49578:tid 49806] [client 68.167.136.251:43596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4d1bU3yPMQnn6OehdilwABbCw"]
[Mon Jul 20 07:08:38.094994 2026] [ssl:error] [pid 49578:tid 49727] [client 104.48.69.105:36348] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:08:38.253762 2026] [security2:error] [pid 49578:tid 49754] [client 14.225.17.146:53039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4d07U3yPMQnn6Oehdh7AAAATg"], referer: http://drewsasburyparkbeachhouse.com/2024
[Mon Jul 20 07:08:38.559941 2026] [security2:error] [pid 49578:tid 49760] [client 194.61.41.246:48815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/contacts.php"] [unique_id "al4d1rU3yPMQnn6OehdiyAAAAT4"]
[Mon Jul 20 07:08:38.985603 2026] [security2:error] [pid 49578:tid 49696] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d1rU3yPMQnn6Oehdi8wABKXU"]
[Mon Jul 20 07:08:38.985927 2026] [security2:error] [pid 49578:tid 49739] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d1rU3yPMQnn6Oehdi8wABKXU"]
[Mon Jul 20 07:08:39.021386 2026] [security2:error] [pid 49578:tid 49801] [client 117.247.108.24:20442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d17U3yPMQnn6Oehdi-AAAAWc"]
[Mon Jul 20 07:08:39.021511 2026] [security2:error] [pid 49578:tid 49801] [client 117.247.108.24:20442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d17U3yPMQnn6Oehdi-AAAAWc"]
[Mon Jul 20 07:08:39.071001 2026] [security2:error] [pid 49578:tid 49783] [client 104.234.53.68:38969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4d17U3yPMQnn6Oehdi-gAAAVU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:39.082654 2026] [security2:error] [pid 49578:tid 49807] [client 14.225.17.146:52481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4d1rU3yPMQnn6Oehdi5gAAAW0"], referer: http://floorsourcestock.com/2024
[Mon Jul 20 07:08:39.348879 2026] [security2:error] [pid 49578:tid 49770] [client 194.61.41.75:54589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wsa.php"] [unique_id "al4d17U3yPMQnn6OehdjEgAAAUg"]
[Mon Jul 20 07:08:39.349384 2026] [security2:error] [pid 49578:tid 49723] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d1rU3yPMQnn6Oehdi5QAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:39.514083 2026] [security2:error] [pid 49578:tid 49773] [client 14.225.17.146:52411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4d17U3yPMQnn6OehdjFwAAAUs"], referer: http://getgarrison.com/2024
[Mon Jul 20 07:08:40.021208 2026] [security2:error] [pid 49578:tid 49758] [client 77.110.127.138:63971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d2LU3yPMQnn6OehdjTgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:40.021287 2026] [security2:error] [pid 49578:tid 49758] [client 77.110.127.138:63971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d2LU3yPMQnn6OehdjTgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:40.125100 2026] [security2:error] [pid 49578:tid 49735] [client 194.61.41.72:21053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/about.php"] [unique_id "al4d2LU3yPMQnn6OehdjVgAAASU"]
[Mon Jul 20 07:08:40.232552 2026] [security2:error] [pid 49578:tid 49671] [remote 173.212.252.15:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4d2LU3yPMQnn6OehdjWgABDVw"]
[Mon Jul 20 07:08:40.453480 2026] [security2:error] [pid 49578:tid 49627] [remote 173.212.252.15:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4d2LU3yPMQnn6OehdjagABgTA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:08:40.587985 2026] [security2:error] [pid 49578:tid 49753] [client 82.102.18.116:45574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/xmlrpc.php"] [unique_id "al4d2LU3yPMQnn6OehdjdwAAATc"]
[Mon Jul 20 07:08:40.588104 2026] [security2:error] [pid 49578:tid 49753] [client 82.102.18.116:45574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adastra.love"] [uri "/xmlrpc.php"] [unique_id "al4d2LU3yPMQnn6OehdjdwAAATc"]
[Mon Jul 20 07:08:40.671196 2026] [security2:error] [pid 49578:tid 49745] [client 165.232.55.228:59607] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.aljosour-alarabia.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d2LU3yPMQnn6OehdjeAAAAS8"]
[Mon Jul 20 07:08:40.717295 2026] [security2:error] [pid 49578:tid 49785] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d2LU3yPMQnn6OehdjbwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:40.847353 2026] [security2:error] [pid 49578:tid 49807] [client 194.61.41.248:44187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/firewall.php7"] [unique_id "al4d2LU3yPMQnn6OehdjiQAAAW0"]
[Mon Jul 20 07:08:40.977896 2026] [security2:error] [pid 49578:tid 49828] [client 187.16.64.216:55969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d2LU3yPMQnn6OehdjkwAAAYI"]
[Mon Jul 20 07:08:40.978022 2026] [security2:error] [pid 49578:tid 49828] [client 187.16.64.216:55969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d2LU3yPMQnn6OehdjkwAAAYI"]
[Mon Jul 20 07:08:40.996306 2026] [security2:error] [pid 49578:tid 49751] [client 57.141.18.23:58986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4d1rU3yPMQnn6Oehdi6gABNV0"]
[Mon Jul 20 07:08:41.405588 2026] [security2:error] [pid 49578:tid 49782] [client 117.211.236.168:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d2bU3yPMQnn6OehdjtgAAAVQ"]
[Mon Jul 20 07:08:41.405683 2026] [security2:error] [pid 49578:tid 49782] [client 117.211.236.168:64962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d2bU3yPMQnn6OehdjtgAAAVQ"]
[Mon Jul 20 07:08:41.488159 2026] [security2:error] [pid 49578:tid 49835] [client 14.225.17.146:61475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4d2bU3yPMQnn6OehdjrgAAAYk"], referer: http://thesoloceos.com/2024
[Mon Jul 20 07:08:41.644138 2026] [security2:error] [pid 49578:tid 49800] [client 194.61.41.83:61537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sodium_compat/index.php"] [unique_id "al4d2bU3yPMQnn6OehdjyQAAAWY"]
[Mon Jul 20 07:08:41.768476 2026] [security2:error] [pid 49578:tid 49718] [client 114.119.136.5:35827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/shadows-mirrors-and-flames-2"] [unique_id "al4d2bU3yPMQnn6Oehdj1AAAARQ"], referer: https://omenana.com/2017/09/17/artist-spotlight-on-olisa-onwualu
[Mon Jul 20 07:08:41.770840 2026] [security2:error] [pid 49578:tid 49808] [client 47.128.46.209:37124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bandsir.com"] [uri "/robots.txt"] [unique_id "al4d2bU3yPMQnn6Oehdj1gAAAW4"]
[Mon Jul 20 07:08:41.810401 2026] [security2:error] [pid 49578:tid 49660] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d2bU3yPMQnn6Oehdj3wABGVE"]
[Mon Jul 20 07:08:41.810550 2026] [security2:error] [pid 49578:tid 49723] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d2bU3yPMQnn6Oehdj3wABGVE"]
[Mon Jul 20 07:08:42.064825 2026] [security2:error] [pid 49578:tid 49730] [client 64.225.43.113:63082] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.espiritualidadmoderna.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d2bU3yPMQnn6Oehdj6QAAASA"]
[Mon Jul 20 07:08:42.424796 2026] [security2:error] [pid 49578:tid 49834] [client 194.61.41.77:56169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/content.php"] [unique_id "al4d2rU3yPMQnn6OehdkBwAAAYg"]
[Mon Jul 20 07:08:42.559151 2026] [security2:error] [pid 49578:tid 49717] [client 104.234.53.58:32981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4d2rU3yPMQnn6OehdkDAAAARM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:42.793853 2026] [security2:error] [pid 49578:tid 49722] [client 77.110.127.138:63984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d2rU3yPMQnn6OehdkJwAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:42.793943 2026] [security2:error] [pid 49578:tid 49722] [client 77.110.127.138:63984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d2rU3yPMQnn6OehdkJwAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:42.878259 2026] [security2:error] [pid 49578:tid 49789] [client 50.116.65.227:14696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4d2rU3yPMQnn6OehdkLQAAAVs"]
[Mon Jul 20 07:08:42.889679 2026] [security2:error] [pid 49578:tid 49772] [client 50.116.65.227:14706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4d2rU3yPMQnn6OehdkLgAAAUo"]
[Mon Jul 20 07:08:43.033865 2026] [security2:error] [pid 49578:tid 49781] [client 14.225.17.146:61240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4d2rU3yPMQnn6OehdkLwAAAVM"], referer: http://effingweirdmuseums.com/2024
[Mon Jul 20 07:08:43.042437 2026] [security2:error] [pid 49578:tid 49659] [remote 188.166.241.141:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4d27U3yPMQnn6OehdkPAABd1A"]
[Mon Jul 20 07:08:43.156583 2026] [security2:error] [pid 49578:tid 49712] [client 194.61.41.98:48275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/lv.php"] [unique_id "al4d27U3yPMQnn6OehdkTQAAAQ4"]
[Mon Jul 20 07:08:43.167177 2026] [security2:error] [pid 49578:tid 49677] [remote 152.228.213.32:39664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4d27U3yPMQnn6OehdkTAABNGI"]
[Mon Jul 20 07:08:43.191315 2026] [security2:error] [pid 49578:tid 49762] [client 88.241.67.160:56239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d27U3yPMQnn6OehdkUgAAAUA"]
[Mon Jul 20 07:08:43.191707 2026] [security2:error] [pid 49578:tid 49762] [client 88.241.67.160:56239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d27U3yPMQnn6OehdkUgAAAUA"]
[Mon Jul 20 07:08:43.340578 2026] [security2:error] [pid 49578:tid 49726] [client 104.234.53.63:39849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4d27U3yPMQnn6OehdkXgAAARw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:43.429529 2026] [security2:error] [pid 49578:tid 49581] [remote 188.166.241.141:46602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4d27U3yPMQnn6OehdkZwABIwI"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:08:43.476042 2026] [security2:error] [pid 49578:tid 49684] [remote 152.228.213.32:39664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4d27U3yPMQnn6OehdkaAABOGk"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:08:43.594433 2026] [security2:error] [pid 49578:tid 49802] [client 14.225.17.146:52454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4d27U3yPMQnn6OehdkawAAAWg"], referer: http://ancestralidadytrance.space/2024
[Mon Jul 20 07:08:43.615966 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:63988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d27U3yPMQnn6OehdkdAAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:43.616065 2026] [security2:error] [pid 49578:tid 49715] [client 77.110.127.138:63988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d27U3yPMQnn6OehdkdAAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:43.915414 2026] [security2:error] [pid 49578:tid 49808] [client 185.238.231.95:27817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4d27U3yPMQnn6OehdkigAAAW4"]
[Mon Jul 20 07:08:43.933621 2026] [security2:error] [pid 49578:tid 49833] [client 194.61.41.58:39839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/js1.php"] [unique_id "al4d27U3yPMQnn6OehdkjAAAAYc"]
[Mon Jul 20 07:08:43.964808 2026] [security2:error] [pid 49578:tid 49776] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d27U3yPMQnn6OehdkgQAAAU4"]
[Mon Jul 20 07:08:43.975379 2026] [security2:error] [pid 49578:tid 49827] [client 155.2.212.12:30363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4d27U3yPMQnn6OehdkjwAAAYE"]
[Mon Jul 20 07:08:44.025515 2026] [security2:error] [pid 49578:tid 49712] [client 14.225.17.146:64078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4d27U3yPMQnn6OehdkjQAAAQ4"], referer: https://effingweirdmuseums.com/2024
[Mon Jul 20 07:08:44.028195 2026] [security2:error] [pid 49578:tid 49794] [client 103.144.65.217:60516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d3LU3yPMQnn6OehdklgAAAWA"]
[Mon Jul 20 07:08:44.028291 2026] [security2:error] [pid 49578:tid 49794] [client 103.144.65.217:60516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d3LU3yPMQnn6OehdklgAAAWA"]
[Mon Jul 20 07:08:44.242019 2026] [security2:error] [pid 49578:tid 49804] [client 98.159.234.160:42387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4d3LU3yPMQnn6OehdkpQAAAWo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:08:44.395948 2026] [security2:error] [pid 49578:tid 49777] [client 104.234.53.75:48745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4d3LU3yPMQnn6OehdksgAAAU8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:44.444166 2026] [security2:error] [pid 49578:tid 49701] [remote 8.217.108.67:16796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4d3LU3yPMQnn6OehdktgABDHo"]
[Mon Jul 20 07:08:44.621891 2026] [autoindex:error] [pid 49578:tid 49754] [client 34.86.31.247:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://varmath.com
[Mon Jul 20 07:08:44.644974 2026] [security2:error] [pid 49578:tid 49757] [client 194.61.41.91:41921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/file.php"] [unique_id "al4d3LU3yPMQnn6OehdkzAAAATs"]
[Mon Jul 20 07:08:44.804994 2026] [security2:error] [pid 49578:tid 49800] [client 14.225.17.146:52553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4d3LU3yPMQnn6Oehdk0gAAAWY"]
[Mon Jul 20 07:08:44.974559 2026] [security2:error] [pid 49578:tid 49730] [client 183.82.98.154:52529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d3LU3yPMQnn6Oehdk7QAAASA"]
[Mon Jul 20 07:08:44.974678 2026] [security2:error] [pid 49578:tid 49730] [client 183.82.98.154:52529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d3LU3yPMQnn6Oehdk7QAAASA"]
[Mon Jul 20 07:08:44.980008 2026] [security2:error] [pid 49578:tid 49763] [client 14.225.17.146:52348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4d3LU3yPMQnn6OehdkuQAAAUE"], referer: http://idigress.group/2024
[Mon Jul 20 07:08:45.041159 2026] [security2:error] [pid 49578:tid 49756] [client 14.225.17.146:52497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4d3LU3yPMQnn6Oehdk4QAAATo"], referer: https://north-woods-engineering.com/2024
[Mon Jul 20 07:08:45.118112 2026] [security2:error] [pid 49578:tid 49733] [client 138.197.159.250:60502] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.generationloveproject.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d3bU3yPMQnn6Oehdk9gAAASM"]
[Mon Jul 20 07:08:45.188532 2026] [security2:error] [pid 49578:tid 49633] [remote 162.19.86.63:44695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4d3bU3yPMQnn6OehdlAAABFzY"]
[Mon Jul 20 07:08:45.373598 2026] [security2:error] [pid 49578:tid 49720] [client 143.110.218.154:54007] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.soundmeditationmiami.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d3bU3yPMQnn6OehdlCwAAARY"]
[Mon Jul 20 07:08:45.380290 2026] [security2:error] [pid 49578:tid 49582] [remote 162.19.86.63:44695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4d3bU3yPMQnn6OehdlDQABfgM"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 07:08:45.419249 2026] [security2:error] [pid 49578:tid 49819] [client 194.61.41.80:34123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/file.php"] [unique_id "al4d3bU3yPMQnn6OehdlEgAAAXk"]
[Mon Jul 20 07:08:45.450040 2026] [security2:error] [pid 49578:tid 49832] [client 143.110.218.154:54040] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.soundmeditationsouthflorida.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d3bU3yPMQnn6OehdlFwAAAYY"]
[Mon Jul 20 07:08:45.502785 2026] [security2:error] [pid 49578:tid 49690] [remote 8.217.108.67:16796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4d3bU3yPMQnn6OehdlHwABPW8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:08:45.696155 2026] [security2:error] [pid 49578:tid 49726] [client 14.225.17.146:61346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4d3LU3yPMQnn6OehdkoQAAARw"], referer: http://guidehunting.com/2024
[Mon Jul 20 07:08:45.714235 2026] [security2:error] [pid 49578:tid 49730] [client 114.119.130.12:25421] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.tmsteamer.com"] [uri "/robots.txt"] [unique_id "al4d3bU3yPMQnn6OehdlMQAAASA"], referer: https://www.tmsteamer.com/robots.txt
[Mon Jul 20 07:08:45.762878 2026] [security2:error] [pid 49578:tid 49829] [client 49.13.164.148:54992] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4d3bU3yPMQnn6OehdlIwAAAYM"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:08:46.100486 2026] [security2:error] [pid 49578:tid 49750] [client 114.119.147.6:29523] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.safe-systems.net"] [uri "/nextbit.mx/portafolio/aviato/pricing.html"] [unique_id "al4d3rU3yPMQnn6OehdlSgAAATQ"], referer: http://www.safe-systems.net/nextbit.mx/portafolio/aviato/contact.html
[Mon Jul 20 07:08:46.154067 2026] [security2:error] [pid 49578:tid 49745] [client 194.61.41.71:46609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/admin.php"] [unique_id "al4d3rU3yPMQnn6OehdlSwAAAS8"]
[Mon Jul 20 07:08:46.350101 2026] [access_compat:error] [pid 49578:tid 49805] [client 183.47.107.102:43389] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:08:46.454117 2026] [security2:error] [pid 49578:tid 49830] [client 179.220.126.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4d3LU3yPMQnn6Oehdk7AAAAYQ"]
[Mon Jul 20 07:08:46.914363 2026] [security2:error] [pid 49578:tid 49722] [client 14.225.17.146:52318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4d3rU3yPMQnn6OehdldQAAARg"], referer: https://guidehunting.com/2024
[Mon Jul 20 07:08:46.939680 2026] [security2:error] [pid 49578:tid 49815] [client 194.61.41.94:54693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/autoload_classmap.php"] [unique_id "al4d3rU3yPMQnn6OehdljwAAAXU"]
[Mon Jul 20 07:08:46.976003 2026] [security2:error] [pid 49578:tid 49739] [client 14.225.17.146:61095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4d3LU3yPMQnn6OehdkwwAAASk"], referer: http://healthylifegourmet.org/2024
[Mon Jul 20 07:08:47.397711 2026] [security2:error] [pid 49578:tid 49832] [client 77.110.127.138:64001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d37U3yPMQnn6OehdlrgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:47.397830 2026] [security2:error] [pid 49578:tid 49832] [client 77.110.127.138:64001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d37U3yPMQnn6OehdlrgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:47.454400 2026] [security2:error] [pid 49578:tid 49778] [client 201.27.111.74:60073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d37U3yPMQnn6OehdltwAAAVA"]
[Mon Jul 20 07:08:47.454557 2026] [security2:error] [pid 49578:tid 49778] [client 201.27.111.74:60073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d37U3yPMQnn6OehdltwAAAVA"]
[Mon Jul 20 07:08:47.671048 2026] [security2:error] [pid 49578:tid 49783] [client 209.38.88.95:60833] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.omegacompass.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d37U3yPMQnn6OehdlvQAAAVU"]
[Mon Jul 20 07:08:47.721795 2026] [security2:error] [pid 49578:tid 49789] [client 194.61.41.249:32473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/wp-conflg.php"] [unique_id "al4d37U3yPMQnn6OehdlxgAAAVs"]
[Mon Jul 20 07:08:47.973535 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d37U3yPMQnn6Oehdl3AAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:47.973662 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:64007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d37U3yPMQnn6Oehdl3AAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:48.069135 2026] [security2:error] [pid 49578:tid 49818] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d37U3yPMQnn6OehdltAAAAXg"]
[Mon Jul 20 07:08:48.407835 2026] [access_compat:error] [pid 49578:tid 49809] [client 112.90.2.147:60623] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:08:48.437860 2026] [security2:error] [pid 49578:tid 49787] [client 34.221.76.50:58842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4d4LU3yPMQnn6OehdmAgAAAVk"]
[Mon Jul 20 07:08:48.457006 2026] [security2:error] [pid 49578:tid 49769] [client 194.61.41.107:58899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/theme-editor.php"] [unique_id "al4d4LU3yPMQnn6OehdmBAAAAUc"]
[Mon Jul 20 07:08:48.458156 2026] [security2:error] [pid 49578:tid 49744] [client 34.73.232.127:8234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "greenport-us.com"] [uri "/wp-json/batch/v1"] [unique_id "al4d4LU3yPMQnn6OehdmAwAAAS4"]
[Mon Jul 20 07:08:48.485930 2026] [security2:error] [pid 49578:tid 49687] [remote 100.42.189.89:38002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4d4LU3yPMQnn6OehdmBgABEGw"]
[Mon Jul 20 07:08:48.593343 2026] [security2:error] [pid 49578:tid 49759] [client 34.73.232.127:8234] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "greenport-us.com"] [uri "/"] [unique_id "al4d4LU3yPMQnn6OehdmEQAAAT0"]
[Mon Jul 20 07:08:48.672528 2026] [security2:error] [pid 49578:tid 49701] [remote 100.42.189.89:38002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4d4LU3yPMQnn6OehdmFQABEXo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:08:48.848920 2026] [security2:error] [pid 49578:tid 49613] [remote 124.55.178.99:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d4LU3yPMQnn6OehdmIwABNSI"]
[Mon Jul 20 07:08:48.855840 2026] [security2:error] [pid 49578:tid 49802] [client 14.225.17.146:49938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4d4LU3yPMQnn6OehdmIAAAAWg"], referer: http://walkingandtalking.net/2024
[Mon Jul 20 07:08:49.227488 2026] [security2:error] [pid 49578:tid 49710] [client 194.61.41.251:57187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/abc.php"] [unique_id "al4d4bU3yPMQnn6OehdmQQAAAQw"]
[Mon Jul 20 07:08:49.235233 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:64022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d4bU3yPMQnn6OehdmQwAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:49.235343 2026] [security2:error] [pid 49578:tid 49729] [client 77.110.127.138:64022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d4bU3yPMQnn6OehdmQwAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:49.247837 2026] [security2:error] [pid 49578:tid 49587] [remote 124.55.178.99:55242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d4bU3yPMQnn6OehdmRAABCwg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:08:49.619544 2026] [security2:error] [pid 49578:tid 49724] [client 117.247.108.24:20540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d4bU3yPMQnn6OehdmbQAAARo"]
[Mon Jul 20 07:08:49.619681 2026] [security2:error] [pid 49578:tid 49724] [client 117.247.108.24:20540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d4bU3yPMQnn6OehdmbQAAARo"]
[Mon Jul 20 07:08:49.691682 2026] [access_compat:error] [pid 49578:tid 49814] [client 183.47.125.177:35435] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:08:49.818597 2026] [security2:error] [pid 49578:tid 49770] [client 14.225.17.146:49922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4d4bU3yPMQnn6OehdmUQAAAUg"], referer: http://onewingpictures.com/2024
[Mon Jul 20 07:08:49.928696 2026] [security2:error] [pid 49578:tid 49809] [client 14.225.17.146:60425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4d4bU3yPMQnn6OehdmfQAAAW8"], referer: https://walkingandtalking.net/2024
[Mon Jul 20 07:08:49.929356 2026] [security2:error] [pid 49578:tid 49773] [client 194.61.41.57:21583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/wonder.php"] [unique_id "al4d4bU3yPMQnn6OehdmgwAAAUs"]
[Mon Jul 20 07:08:49.929496 2026] [security2:error] [pid 49578:tid 49735] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4d4bU3yPMQnn6OehdmVAABJUM"], referer: http://assasalnazaha.com/2024
[Mon Jul 20 07:08:50.350889 2026] [core:error] [pid 49578:tid 49720] [client 14.225.17.146:64129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2024
[Mon Jul 20 07:08:50.350920 2026] [core:error] [pid 49578:tid 49720] [client 14.225.17.146:64129] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2024
[Mon Jul 20 07:08:50.385211 2026] [security2:error] [pid 49578:tid 49635] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d4rU3yPMQnn6OehdmmwABFDg"]
[Mon Jul 20 07:08:50.385342 2026] [security2:error] [pid 49578:tid 49718] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d4rU3yPMQnn6OehdmmwABFDg"]
[Mon Jul 20 07:08:50.656145 2026] [security2:error] [pid 49578:tid 49722] [client 194.61.41.68:38241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/wonder.php"] [unique_id "al4d4rU3yPMQnn6OehdmuAAAARg"]
[Mon Jul 20 07:08:50.709740 2026] [security2:error] [pid 49578:tid 49751] [client 77.110.127.138:64040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d4rU3yPMQnn6OehdmuQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:50.709861 2026] [security2:error] [pid 49578:tid 49751] [client 77.110.127.138:64040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d4rU3yPMQnn6OehdmuQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:50.801906 2026] [security2:error] [pid 49578:tid 49782] [client 173.239.224.20:63229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "genspagroup.com"] [uri "/wp-login.php"] [unique_id "al4d4rU3yPMQnn6OehdmvwAAAVQ"]
[Mon Jul 20 07:08:51.281982 2026] [security2:error] [pid 49578:tid 49661] [remote 8.217.108.67:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4d47U3yPMQnn6Oehdm4gABS1I"]
[Mon Jul 20 07:08:51.439516 2026] [security2:error] [pid 49578:tid 49732] [client 194.61.41.54:53385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/fix/as.php"] [unique_id "al4d47U3yPMQnn6Oehdm8AAAASI"]
[Mon Jul 20 07:08:51.663106 2026] [security2:error] [pid 49578:tid 49784] [client 187.16.64.216:56571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d47U3yPMQnn6OehdnAgAAAVY"]
[Mon Jul 20 07:08:51.663207 2026] [security2:error] [pid 49578:tid 49784] [client 187.16.64.216:56571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d47U3yPMQnn6OehdnAgAAAVY"]
[Mon Jul 20 07:08:51.762174 2026] [security2:error] [pid 49578:tid 49700] [remote 98.156.100.191:43850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4d47U3yPMQnn6OehdnBwABLnk"]
[Mon Jul 20 07:08:51.788733 2026] [security2:error] [pid 49578:tid 49713] [client 114.119.134.106:43091] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.musichaven.info"] [uri "/how-artificial-intelligence-benefits-music-industry/"] [unique_id "al4d47U3yPMQnn6OehdnCwAAAQ8"], referer: https://www.musichaven.info/how-music-therapy-helps-women-suffering-from-domestic-violence/
[Mon Jul 20 07:08:52.015386 2026] [security2:error] [pid 49578:tid 49739] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4d47U3yPMQnn6OehdnFwAAASk"]
[Mon Jul 20 07:08:52.240704 2026] [security2:error] [pid 49578:tid 49791] [client 194.61.41.67:38019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/tox.php"] [unique_id "al4d5LU3yPMQnn6OehdnOAAAAV0"]
[Mon Jul 20 07:08:52.272129 2026] [security2:error] [pid 49578:tid 49817] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d5LU3yPMQnn6OehdnIgAAAXc"], referer: 1'"3000
[Mon Jul 20 07:08:52.310073 2026] [security2:error] [pid 49578:tid 49721] [client 14.225.17.146:64186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4d5LU3yPMQnn6OehdnOQAAARc"], referer: http://grndl.com/2024
[Mon Jul 20 07:08:52.492232 2026] [security2:error] [pid 49578:tid 49657] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d5LU3yPMQnn6OehdnRwABMU4"]
[Mon Jul 20 07:08:52.492458 2026] [security2:error] [pid 49578:tid 49747] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d5LU3yPMQnn6OehdnRwABMU4"]
[Mon Jul 20 07:08:52.549327 2026] [security2:error] [pid 49578:tid 49824] [client 14.225.17.146:64455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4d5LU3yPMQnn6OehdnJgAAAX4"]
[Mon Jul 20 07:08:52.605625 2026] [security2:error] [pid 49578:tid 49715] [client 14.225.17.146:49585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4d47U3yPMQnn6OehdnGgAAARE"], referer: http://bruceledewitz.com/2024
[Mon Jul 20 07:08:52.669360 2026] [security2:error] [pid 49578:tid 49736] [client 77.110.127.138:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d5LU3yPMQnn6OehdnVwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:52.669447 2026] [security2:error] [pid 49578:tid 49736] [client 77.110.127.138:63999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d5LU3yPMQnn6OehdnVwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:52.888908 2026] [security2:error] [pid 49578:tid 49804] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d5LU3yPMQnn6OehdnWgAAAWo"], referer: 1'"3000
[Mon Jul 20 07:08:53.012145 2026] [security2:error] [pid 49578:tid 49739] [client 14.225.17.146:64583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4d5LU3yPMQnn6OehdnbwAAASk"], referer: http://mtlegnews.gov/2024
[Mon Jul 20 07:08:53.028657 2026] [security2:error] [pid 49578:tid 49769] [client 14.225.17.146:64115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4d5LU3yPMQnn6OehdnLAAAAUc"], referer: http://idigress.studio/2024
[Mon Jul 20 07:08:53.040949 2026] [security2:error] [pid 49578:tid 49747] [client 194.61.41.76:21243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/index.php"] [unique_id "al4d5bU3yPMQnn6OehdnfwAAATE"]
[Mon Jul 20 07:08:53.383524 2026] [security2:error] [pid 49578:tid 49830] [client 57.141.18.91:46372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4d47U3yPMQnn6Oehdm3AABhEA"]
[Mon Jul 20 07:08:53.601296 2026] [security2:error] [pid 49578:tid 49651] [remote 98.156.100.191:43850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4d5bU3yPMQnn6OehdnowABZkg"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 07:08:53.664191 2026] [security2:error] [pid 49578:tid 49618] [remote 97.74.93.24:44710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4d5bU3yPMQnn6OehdnqQABHCc"]
[Mon Jul 20 07:08:53.728663 2026] [security2:error] [pid 49578:tid 49835] [client 14.225.17.146:64497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4d47U3yPMQnn6OehdnCAAAAYk"], referer: http://amalia-capital.com/2024
[Mon Jul 20 07:08:53.768103 2026] [security2:error] [pid 49578:tid 49810] [client 117.211.236.168:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d5bU3yPMQnn6OehdnsQAAAXA"]
[Mon Jul 20 07:08:53.768208 2026] [security2:error] [pid 49578:tid 49810] [client 117.211.236.168:65495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d5bU3yPMQnn6OehdnsQAAAXA"]
[Mon Jul 20 07:08:53.826507 2026] [security2:error] [pid 49578:tid 49771] [client 194.61.41.107:20525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/dist/default.php"] [unique_id "al4d5bU3yPMQnn6OehdnuwAAAUk"]
[Mon Jul 20 07:08:53.891983 2026] [security2:error] [pid 49578:tid 49811] [client 88.241.67.160:56322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d5bU3yPMQnn6OehdnvQAAAXE"]
[Mon Jul 20 07:08:53.892096 2026] [security2:error] [pid 49578:tid 49811] [client 88.241.67.160:56322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d5bU3yPMQnn6OehdnvQAAAXE"]
[Mon Jul 20 07:08:54.074776 2026] [security2:error] [pid 49578:tid 49627] [remote 97.74.93.24:44710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4d5rU3yPMQnn6OehdnyQABITA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:08:54.489981 2026] [security2:error] [pid 49578:tid 49812] [client 14.225.17.146:64323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4d5bU3yPMQnn6OehdnhgAAAXI"], referer: http://dadanetnet.net/2024
[Mon Jul 20 07:08:54.515203 2026] [security2:error] [pid 49578:tid 49725] [client 77.110.127.138:64039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/thank-you-for-signing-up/4q3qwro8g130.php"] [unique_id "al4d5rU3yPMQnn6Oehdn5wAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:54.540205 2026] [security2:error] [pid 49578:tid 49822] [client 103.144.65.217:60994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d5rU3yPMQnn6Oehdn7gAAAXw"]
[Mon Jul 20 07:08:54.541140 2026] [security2:error] [pid 49578:tid 49822] [client 103.144.65.217:60994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d5rU3yPMQnn6Oehdn7gAAAXw"]
[Mon Jul 20 07:08:54.563504 2026] [security2:error] [pid 49578:tid 49774] [client 194.61.41.66:38951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/tfileman.php"] [unique_id "al4d5rU3yPMQnn6Oehdn8gAAAUw"]
[Mon Jul 20 07:08:54.777138 2026] [fcgid:warn] [pid 49578:tid 49709] (70014)End of file found: [client 66.132.186.185:2252] mod_fcgid: can't get data from http client
[Mon Jul 20 07:08:54.845402 2026] [security2:error] [pid 49578:tid 49771] [client 14.225.17.146:50499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4d5rU3yPMQnn6Oehdn9wAAAUk"], referer: http://mobilesurvsolutions.com/2024
[Mon Jul 20 07:08:54.897218 2026] [security2:error] [pid 49578:tid 49778] [client 50.116.65.227:30324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4d5rU3yPMQnn6OehdoDAAAAVA"]
[Mon Jul 20 07:08:54.906183 2026] [security2:error] [pid 49578:tid 49756] [client 50.116.65.227:30330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4d5rU3yPMQnn6OehdoDQAAATo"]
[Mon Jul 20 07:08:55.149294 2026] [security2:error] [pid 49578:tid 49731] [client 14.225.17.146:64524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4d5rU3yPMQnn6OehdoCwAAASE"], referer: http://webgardensbypaula.com/2024
[Mon Jul 20 07:08:55.299486 2026] [security2:error] [pid 49578:tid 49815] [client 183.82.98.154:57113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d57U3yPMQnn6OehdoKwAAAXU"]
[Mon Jul 20 07:08:55.299615 2026] [security2:error] [pid 49578:tid 49815] [client 183.82.98.154:57113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d57U3yPMQnn6OehdoKwAAAXU"]
[Mon Jul 20 07:08:55.326439 2026] [security2:error] [pid 49578:tid 49775] [client 194.61.41.56:34627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/tiny.php"] [unique_id "al4d57U3yPMQnn6OehdoMQAAAU0"]
[Mon Jul 20 07:08:55.351358 2026] [security2:error] [pid 49578:tid 49805] [client 14.225.17.146:64201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4d57U3yPMQnn6OehdoIAAAAWs"], referer: http://backandneckpainrelieflaceychiropractor.com/2024
[Mon Jul 20 07:08:55.388429 2026] [security2:error] [pid 49578:tid 49726] [client 104.234.53.82:48135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4d57U3yPMQnn6OehdoNQAAARw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:55.723160 2026] [autoindex:error] [pid 49578:tid 49833] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/uploads/2024/
[Mon Jul 20 07:08:55.875286 2026] [security2:error] [pid 49578:tid 49738] [client 77.110.127.138:64042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d57U3yPMQnn6OehdoRQAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.008897 2026] [security2:error] [pid 49578:tid 49732] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d57U3yPMQnn6OehdoVQAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.026424 2026] [security2:error] [pid 49578:tid 49778] [client 194.61.41.91:54779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/autoload_classmap.php"] [unique_id "al4d6LU3yPMQnn6OehdodAAAAVA"]
[Mon Jul 20 07:08:56.052497 2026] [security2:error] [pid 49578:tid 49642] [remote 8.217.108.67:8400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4d6LU3yPMQnn6OehdodgABZz8"], referer: https://sk-financial.com/wp-login.php
[Mon Jul 20 07:08:56.062980 2026] [security2:error] [pid 49578:tid 49783] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d57U3yPMQnn6OehdoYgAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.122772 2026] [access_compat:error] [pid 49578:tid 49804] [client 183.186.78.181:44455] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:08:56.182390 2026] [security2:error] [pid 49578:tid 49730] [client 77.110.127.138:64052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/3/263gh2j33kbe.php"] [unique_id "al4d6LU3yPMQnn6OehdoigAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.261553 2026] [security2:error] [pid 49578:tid 49813] [client 77.110.127.138:64067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d6LU3yPMQnn6OehdokwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.261670 2026] [security2:error] [pid 49578:tid 49813] [client 77.110.127.138:64067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d6LU3yPMQnn6OehdokwAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.438635 2026] [security2:error] [pid 49578:tid 49689] [remote 5.161.225.162:58120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4d6LU3yPMQnn6OehdorQABKm4"]
[Mon Jul 20 07:08:56.488446 2026] [security2:error] [pid 49578:tid 49721] [client 114.119.129.74:50911] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.californiaperfumecompany.com"] [uri "/robots.txt"] [unique_id "al4d6LU3yPMQnn6OehdosQAAARc"], referer: https://www.californiaperfumecompany.com/robots.txt
[Mon Jul 20 07:08:56.496032 2026] [security2:error] [pid 49578:tid 49677] [remote 20.153.140.50:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4d6LU3yPMQnn6OehdosgABEWI"]
[Mon Jul 20 07:08:56.601827 2026] [security2:error] [pid 49578:tid 49745] [client 77.110.127.138:64070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6LU3yPMQnn6OehdomAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:56.694380 2026] [security2:error] [pid 49578:tid 49598] [remote 5.161.225.162:58120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4d6LU3yPMQnn6OehdouwABTBM"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 07:08:56.773161 2026] [security2:error] [pid 49578:tid 49760] [client 194.61.41.82:21645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/themes.php"] [unique_id "al4d6LU3yPMQnn6OehdowgAAAT4"]
[Mon Jul 20 07:08:56.894509 2026] [security2:error] [pid 49578:tid 49785] [client 165.22.141.39:64434] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.uninursity.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4d6LU3yPMQnn6OehdoygAAAVc"]
[Mon Jul 20 07:08:56.922443 2026] [security2:error] [pid 49578:tid 49678] [remote 20.153.140.50:54946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bigwormfishing.com"] [uri "/wp-login.php"] [unique_id "al4d6LU3yPMQnn6Oehdo0QABeWM"], referer: https://bigwormfishing.com/wp-login.php
[Mon Jul 20 07:08:57.165427 2026] [security2:error] [pid 49578:tid 49771] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6LU3yPMQnn6OehdooQAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:57.184217 2026] [security2:error] [pid 49578:tid 49737] [client 104.234.53.62:47497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4d6bU3yPMQnn6Oehdo4gAAASc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:08:57.202102 2026] [security2:error] [pid 49578:tid 49720] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6LU3yPMQnn6OehdoogAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:57.364089 2026] [security2:error] [pid 49578:tid 49828] [client 77.110.127.138:64042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/pattern/sf6l8oooh8ga.php"] [unique_id "al4d6bU3yPMQnn6Oehdo9QAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:57.401885 2026] [security2:error] [pid 49578:tid 49721] [client 14.225.17.146:50072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4d6bU3yPMQnn6Oehdo8gAAARc"], referer: http://processorstudio.com/2024
[Mon Jul 20 07:08:57.543941 2026] [security2:error] [pid 49578:tid 49798] [client 194.61.41.74:23017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-themes.php"] [unique_id "al4d6bU3yPMQnn6OehdpFQAAAWQ"]
[Mon Jul 20 07:08:57.715492 2026] [security2:error] [pid 49578:tid 49752] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6bU3yPMQnn6Oehdo_gAAATY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:57.717237 2026] [security2:error] [pid 49578:tid 49811] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6bU3yPMQnn6OehdpDgAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:57.851342 2026] [security2:error] [pid 49578:tid 49778] [client 77.110.127.138:64079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6bU3yPMQnn6OehdpEQAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:57.863309 2026] [security2:error] [pid 49578:tid 49793] [client 57.141.18.11:55308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4d57U3yPMQnn6OehdoHQABXxk"]
[Mon Jul 20 07:08:57.920665 2026] [security2:error] [pid 49578:tid 49741] [client 14.225.17.146:50402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4d6bU3yPMQnn6OehdpHQAAASs"], referer: http://fluidtemple.org/2024
[Mon Jul 20 07:08:57.962549 2026] [security2:error] [pid 49578:tid 49802] [client 201.27.111.74:60556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d6bU3yPMQnn6OehdpMwAAAWg"]
[Mon Jul 20 07:08:57.962662 2026] [security2:error] [pid 49578:tid 49802] [client 201.27.111.74:60556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d6bU3yPMQnn6OehdpMwAAAWg"]
[Mon Jul 20 07:08:58.129809 2026] [security2:error] [pid 49578:tid 49731] [client 14.225.17.146:50509] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4d6LU3yPMQnn6OehdoyAAAASE"], referer: http://elitetax-mi.com/2024
[Mon Jul 20 07:08:58.188106 2026] [security2:error] [pid 49578:tid 49742] [client 50.116.65.227:30376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4d6rU3yPMQnn6OehdpQwAAASw"]
[Mon Jul 20 07:08:58.191195 2026] [security2:error] [pid 49578:tid 49757] [client 14.225.17.146:50459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4d6LU3yPMQnn6OehdougAAATs"], referer: http://recruitinginsight.us/2024
[Mon Jul 20 07:08:58.340027 2026] [security2:error] [pid 49578:tid 49831] [client 194.61.41.77:30529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sodium_compat/src/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpWgAAAYU"]
[Mon Jul 20 07:08:58.364650 2026] [security2:error] [pid 49578:tid 49720] [client 14.225.17.146:50055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpWAAAARY"], referer: https://processorstudio.com/2024
[Mon Jul 20 07:08:58.452235 2026] [core:error] [pid 49578:tid 49780] [client 144.126.210.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:58.452268 2026] [core:error] [pid 49578:tid 49780] [client 144.126.210.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:08:58.452744 2026] [security2:error] [pid 49578:tid 49740] [client 77.110.127.138:64085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/mohair/gwpjudqhq6ai.php"] [unique_id "al4d6rU3yPMQnn6OehdpbQAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:58.608417 2026] [security2:error] [pid 49578:tid 49721] [client 77.110.127.138:64051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpYQAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:58.622731 2026] [security2:error] [pid 49578:tid 49771] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpZgAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:58.741896 2026] [security2:error] [pid 49578:tid 49801] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpcQAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:58.849484 2026] [security2:error] [pid 49578:tid 49790] [client 209.203.23.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpQQAAAVw"]
[Mon Jul 20 07:08:58.856058 2026] [security2:error] [pid 49578:tid 49786] [client 77.110.127.138:64074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/2atwmvvian4w.php"] [unique_id "al4d6rU3yPMQnn6OehdpmgAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:58.893891 2026] [security2:error] [pid 49578:tid 49823] [client 77.110.127.138:64063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d6rU3yPMQnn6OehdprAAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:58.893979 2026] [security2:error] [pid 49578:tid 49823] [client 77.110.127.138:64063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d6rU3yPMQnn6OehdprAAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:59.072476 2026] [security2:error] [pid 49578:tid 49589] [remote 182.77.62.24:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4d67U3yPMQnn6OehdptQABPAo"]
[Mon Jul 20 07:08:59.139593 2026] [security2:error] [pid 49578:tid 49718] [client 194.61.41.76:51873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/erinyani/asasx.php"] [unique_id "al4d67U3yPMQnn6OehdpuwAAARQ"]
[Mon Jul 20 07:08:59.349495 2026] [security2:error] [pid 49578:tid 49742] [client 14.225.17.146:50192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4d67U3yPMQnn6OehdpwQAAASw"], referer: http://dasmarque.com/2024
[Mon Jul 20 07:08:59.364292 2026] [security2:error] [pid 49578:tid 49805] [client 77.110.127.138:64047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdpmwAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:59.403849 2026] [security2:error] [pid 49578:tid 49813] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdprQAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:59.446986 2026] [security2:error] [pid 49578:tid 49739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d6rU3yPMQnn6OehdprwAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:59.569796 2026] [security2:error] [pid 49578:tid 49770] [client 77.110.127.138:64066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/kdsp2lg65b66.php"] [unique_id "al4d67U3yPMQnn6Oehdp3QAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:08:59.613246 2026] [autoindex:error] [pid 49578:tid 49725] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpseo-local/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:08:59.664594 2026] [security2:error] [pid 49578:tid 49590] [remote 182.77.62.24:59632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4d67U3yPMQnn6Oehdp8gABVgs"], referer: https://swafforddetailing.com/wp-login.php
[Mon Jul 20 07:08:59.690896 2026] [security2:error] [pid 49578:tid 49769] [client 14.225.17.146:50779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4d67U3yPMQnn6Oehdp2wAAAUc"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2024
[Mon Jul 20 07:08:59.714408 2026] [autoindex:error] [pid 49578:tid 49801] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpseo-local/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:08:59.948715 2026] [security2:error] [pid 49578:tid 49796] [client 194.61.41.97:24337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/mariju.php"] [unique_id "al4d67U3yPMQnn6OehdqCwAAAWI"]
[Mon Jul 20 07:09:00.046291 2026] [security2:error] [pid 49578:tid 49665] [remote 68.178.160.25:43550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4d7LU3yPMQnn6OehdqGAABiFY"]
[Mon Jul 20 07:09:00.046432 2026] [security2:error] [pid 49578:tid 49834] [client 68.178.160.25:43550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4d7LU3yPMQnn6OehdqGAABiFY"]
[Mon Jul 20 07:09:00.196910 2026] [security2:error] [pid 49578:tid 49712] [client 77.110.127.138:64082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d67U3yPMQnn6Oehdp4gAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:00.214222 2026] [security2:error] [pid 49578:tid 49814] [client 117.247.108.24:1522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d7LU3yPMQnn6OehdqJgAAAXQ"]
[Mon Jul 20 07:09:00.214317 2026] [security2:error] [pid 49578:tid 49814] [client 117.247.108.24:1522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d7LU3yPMQnn6OehdqJgAAAXQ"]
[Mon Jul 20 07:09:00.228681 2026] [security2:error] [pid 49578:tid 49758] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d67U3yPMQnn6Oehdp5AAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:00.427392 2026] [autoindex:error] [pid 49578:tid 49795] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpseo-local/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:09:00.427802 2026] [autoindex:error] [pid 49578:tid 49734] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpseo-local/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:09:00.555596 2026] [security2:error] [pid 49578:tid 49787] [client 77.110.127.138:64094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js/dj5245zrfp7o.php"] [unique_id "al4d7LU3yPMQnn6OehdqVgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:00.629879 2026] [security2:error] [pid 49578:tid 49784] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7LU3yPMQnn6OehdqQwAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:00.753312 2026] [security2:error] [pid 49578:tid 49754] [client 194.61.41.92:58191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/waf_defender.php"] [unique_id "al4d7LU3yPMQnn6OehdqYgAAATg"]
[Mon Jul 20 07:09:00.769622 2026] [security2:error] [pid 49578:tid 49713] [client 77.110.127.138:64095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7LU3yPMQnn6OehdqVwAAAQ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:00.959021 2026] [security2:error] [pid 49578:tid 49793] [client 57.141.18.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4d7LU3yPMQnn6OehdqawAAAV8"]
[Mon Jul 20 07:09:00.983950 2026] [autoindex:error] [pid 49578:tid 49720] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpseo-local/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:09:01.074896 2026] [security2:error] [pid 49578:tid 49788] [client 77.110.127.138:64000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js/dist/tznn1nuq5dyf.php"] [unique_id "al4d7bU3yPMQnn6OehdqhQAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:01.116669 2026] [autoindex:error] [pid 49578:tid 49773] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpseo-local/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:09:01.344766 2026] [security2:error] [pid 49578:tid 49806] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7bU3yPMQnn6OehdqkQAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:01.441466 2026] [security2:error] [pid 49578:tid 49799] [client 77.110.127.138:64096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7bU3yPMQnn6OehdqmwAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:01.472464 2026] [security2:error] [pid 49578:tid 49809] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7bU3yPMQnn6OehdqnwAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:01.499092 2026] [security2:error] [pid 49578:tid 49601] [remote 198.46.152.106:33906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d7bU3yPMQnn6OehdqwgABDBY"]
[Mon Jul 20 07:09:01.548382 2026] [security2:error] [pid 49578:tid 49767] [client 194.61.41.79:63013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/cong.php"] [unique_id "al4d7bU3yPMQnn6OehdqzQAAAUU"]
[Mon Jul 20 07:09:01.586446 2026] [autoindex:error] [pid 49578:tid 49771] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2024/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:09:01.702292 2026] [security2:error] [pid 49578:tid 49693] [remote 198.46.152.106:33906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d7bU3yPMQnn6Oehdq6QABYXI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:09:01.739210 2026] [security2:error] [pid 49578:tid 49798] [client 104.234.53.51:52909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4d7bU3yPMQnn6Oehdq7AAAAWQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:01.784659 2026] [security2:error] [pid 49578:tid 49637] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d7bU3yPMQnn6Oehdq7QABQDo"]
[Mon Jul 20 07:09:01.784833 2026] [security2:error] [pid 49578:tid 49762] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d7bU3yPMQnn6Oehdq7QABQDo"]
[Mon Jul 20 07:09:02.065284 2026] [security2:error] [pid 49578:tid 49809] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7bU3yPMQnn6Oehdq9wAAAW8"], referer: 1'"3000
[Mon Jul 20 07:09:02.129055 2026] [security2:error] [pid 49578:tid 49735] [client 77.110.127.138:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d7rU3yPMQnn6OehdrEQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:02.129159 2026] [security2:error] [pid 49578:tid 49735] [client 77.110.127.138:64110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d7rU3yPMQnn6OehdrEQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:02.358141 2026] [security2:error] [pid 49578:tid 49835] [client 194.61.41.62:31071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/av.php"] [unique_id "al4d7rU3yPMQnn6OehdrKAAAAYk"]
[Mon Jul 20 07:09:02.374898 2026] [security2:error] [pid 49578:tid 49784] [client 187.16.64.216:57151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d7rU3yPMQnn6OehdrLQAAAVY"]
[Mon Jul 20 07:09:02.375017 2026] [security2:error] [pid 49578:tid 49784] [client 187.16.64.216:57151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d7rU3yPMQnn6OehdrLQAAAVY"]
[Mon Jul 20 07:09:02.532073 2026] [security2:error] [pid 49578:tid 49834] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d7rU3yPMQnn6OehdrGwAAAYg"], referer: 1'"3000
[Mon Jul 20 07:09:02.833860 2026] [security2:error] [pid 49578:tid 49690] [remote 24.49.231.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4d7rU3yPMQnn6OehdrPwABNG8"]
[Mon Jul 20 07:09:03.149934 2026] [security2:error] [pid 49578:tid 49773] [client 194.61.41.54:41873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/glex.php"] [unique_id "al4d77U3yPMQnn6OehdrZAAAAUs"]
[Mon Jul 20 07:09:03.153782 2026] [security2:error] [pid 49578:tid 49610] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d77U3yPMQnn6OehdrZQABXx8"]
[Mon Jul 20 07:09:03.153922 2026] [security2:error] [pid 49578:tid 49793] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d77U3yPMQnn6OehdrZQABXx8"]
[Mon Jul 20 07:09:03.404574 2026] [security2:error] [pid 49578:tid 49775] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d77U3yPMQnn6OehdrYQAAAU0"], referer: 1'"3000
[Mon Jul 20 07:09:03.470663 2026] [security2:error] [pid 49578:tid 49781] [client 117.211.236.168:49627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d77U3yPMQnn6OehdrfwAAAVM"]
[Mon Jul 20 07:09:03.470779 2026] [security2:error] [pid 49578:tid 49781] [client 117.211.236.168:49627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d77U3yPMQnn6OehdrfwAAAVM"]
[Mon Jul 20 07:09:03.945011 2026] [security2:error] [pid 49578:tid 49769] [client 194.61.41.91:50143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/autoload_classmap.php"] [unique_id "al4d77U3yPMQnn6OehdrrQAAAUc"]
[Mon Jul 20 07:09:04.205058 2026] [security2:error] [pid 49578:tid 49790] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4d7bU3yPMQnn6Oehdq6wAAAVw"]
[Mon Jul 20 07:09:04.468354 2026] [security2:error] [pid 49578:tid 49798] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8LU3yPMQnn6OehdrxAAAAWQ"], referer: 1'"3000
[Mon Jul 20 07:09:04.580283 2026] [security2:error] [pid 49578:tid 49835] [client 88.241.67.160:54017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d8LU3yPMQnn6Oehdr3gAAAYk"]
[Mon Jul 20 07:09:04.580423 2026] [security2:error] [pid 49578:tid 49835] [client 88.241.67.160:54017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d8LU3yPMQnn6Oehdr3gAAAYk"]
[Mon Jul 20 07:09:04.728193 2026] [security2:error] [pid 49578:tid 49785] [client 194.61.41.243:24573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/Parse/about.php"] [unique_id "al4d8LU3yPMQnn6Oehdr7QAAAVc"]
[Mon Jul 20 07:09:04.851502 2026] [security2:error] [pid 49578:tid 49739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8LU3yPMQnn6Oehdr5gAAASk"], referer: 1'"3000
[Mon Jul 20 07:09:04.907973 2026] [security2:error] [pid 49578:tid 49722] [client 104.234.53.57:58623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4d8LU3yPMQnn6Oehdr-QAAARg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:04.941285 2026] [security2:error] [pid 49578:tid 49754] [client 57.141.18.79:30100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4d7rU3yPMQnn6OehdrLAABOAw"]
[Mon Jul 20 07:09:05.238336 2026] [security2:error] [pid 49578:tid 49790] [client 103.144.65.217:61507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d8bU3yPMQnn6OehdsJQAAAVw"]
[Mon Jul 20 07:09:05.238442 2026] [security2:error] [pid 49578:tid 49790] [client 103.144.65.217:61507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d8bU3yPMQnn6OehdsJQAAAVw"]
[Mon Jul 20 07:09:05.418938 2026] [security2:error] [pid 49578:tid 49601] [remote 81.173.115.7:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4d8bU3yPMQnn6OehdsNgABaRY"]
[Mon Jul 20 07:09:05.485035 2026] [security2:error] [pid 49578:tid 49758] [client 77.110.127.138:64083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d8bU3yPMQnn6OehdsPQAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:05.485136 2026] [security2:error] [pid 49578:tid 49758] [client 77.110.127.138:64083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d8bU3yPMQnn6OehdsPQAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:05.559556 2026] [security2:error] [pid 49578:tid 49817] [client 194.61.41.104:26437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/about.php"] [unique_id "al4d8bU3yPMQnn6OehdsQwAAAXc"]
[Mon Jul 20 07:09:05.903650 2026] [security2:error] [pid 49578:tid 49708] [client 183.82.98.154:57666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d8bU3yPMQnn6OehdsXAAAAQo"]
[Mon Jul 20 07:09:05.903794 2026] [security2:error] [pid 49578:tid 49708] [client 183.82.98.154:57666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d8bU3yPMQnn6OehdsXAAAAQo"]
[Mon Jul 20 07:09:05.904118 2026] [security2:error] [pid 49578:tid 49795] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8bU3yPMQnn6OehdsTAAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:06.190094 2026] [security2:error] [pid 49578:tid 49632] [remote 5.161.225.162:36312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4d8rU3yPMQnn6OehdsdQABQTU"]
[Mon Jul 20 07:09:06.204885 2026] [security2:error] [pid 49578:tid 49812] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8bU3yPMQnn6OehdsZAAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:06.315858 2026] [security2:error] [pid 49578:tid 49739] [client 194.61.41.65:61079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/system_cache.php"] [unique_id "al4d8rU3yPMQnn6OehdsgAAAASk"]
[Mon Jul 20 07:09:06.593812 2026] [security2:error] [pid 49578:tid 49686] [remote 5.161.225.162:36312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4d8rU3yPMQnn6OehdsoAABGms"], referer: https://website-19aec4aa.spencersadventures.com/wp-login.php
[Mon Jul 20 07:09:06.649483 2026] [security2:error] [pid 49578:tid 49827] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8rU3yPMQnn6OehdslAAAAYE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:06.693003 2026] [security2:error] [pid 49578:tid 49730] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8rU3yPMQnn6OehdslwAAASA"], referer: 1'"3000
[Mon Jul 20 07:09:06.803511 2026] [security2:error] [pid 49578:tid 49597] [remote 81.173.115.7:45754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4d8rU3yPMQnn6OehdsswABdBI"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:09:06.808540 2026] [fcgid:warn] [pid 49578:tid 49723] (70014)End of file found: [client 66.132.186.185:60180] mod_fcgid: can't get data from http client
[Mon Jul 20 07:09:06.870939 2026] [security2:error] [pid 49578:tid 49760] [client 40.77.167.235:61002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4d8rU3yPMQnn6OehdsrgABPjY"]
[Mon Jul 20 07:09:06.992194 2026] [security2:error] [pid 49578:tid 49800] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d8rU3yPMQnn6OehdsrwAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:07.037936 2026] [security2:error] [pid 49578:tid 49714] [client 194.61.41.95:34507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/sky-pro/js.php"] [unique_id "al4d87U3yPMQnn6OehdswgAAARA"]
[Mon Jul 20 07:09:07.280791 2026] [security2:error] [pid 49578:tid 49805] [client 50.116.65.227:60906] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4d87U3yPMQnn6Oehds3gAAAWs"]
[Mon Jul 20 07:09:07.290664 2026] [security2:error] [pid 49578:tid 49796] [client 50.116.65.227:60922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4d87U3yPMQnn6Oehds3wAAAWI"]
[Mon Jul 20 07:09:07.498639 2026] [security2:error] [pid 49578:tid 49798] [client 14.225.17.146:52150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4d8rU3yPMQnn6OehdsdgAAAWQ"]
[Mon Jul 20 07:09:07.513227 2026] [security2:error] [pid 49578:tid 49719] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d87U3yPMQnn6Oehds5AAAARU"], referer: 1'"3000
[Mon Jul 20 07:09:07.514998 2026] [security2:error] [pid 49578:tid 49721] [client 14.225.17.146:62272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4d87U3yPMQnn6Oehds6gAAARc"], referer: http://phillipbloch.com/2024
[Mon Jul 20 07:09:07.729553 2026] [security2:error] [pid 49578:tid 49711] [client 40.77.167.235:61002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4d87U3yPMQnn6Oehds_gABDVs"]
[Mon Jul 20 07:09:07.865368 2026] [security2:error] [pid 49578:tid 49720] [client 194.61.41.71:43241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/wp-conflg.php"] [unique_id "al4d87U3yPMQnn6OehdtFAAAARY"]
[Mon Jul 20 07:09:08.331527 2026] [security2:error] [pid 49578:tid 49732] [client 45.157.112.60:56671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4d9LU3yPMQnn6OehdtOgAAASI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:09:08.440256 2026] [security2:error] [pid 49578:tid 49754] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d9LU3yPMQnn6OehdtMgAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:08.472300 2026] [security2:error] [pid 49578:tid 49743] [client 201.27.111.74:61046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d9LU3yPMQnn6OehdtRQAAAS0"]
[Mon Jul 20 07:09:08.472393 2026] [security2:error] [pid 49578:tid 49743] [client 201.27.111.74:61046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d9LU3yPMQnn6OehdtRQAAAS0"]
[Mon Jul 20 07:09:08.548131 2026] [security2:error] [pid 49578:tid 49739] [client 14.225.17.146:59550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4d87U3yPMQnn6OehdsyAAAASk"], referer: http://carolinapressurewashers.com/2024
[Mon Jul 20 07:09:08.629418 2026] [security2:error] [pid 49578:tid 49735] [client 194.61.41.87:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/pridmag/waf_defender.php"] [unique_id "al4d9LU3yPMQnn6OehdtTAAAASU"]
[Mon Jul 20 07:09:08.686788 2026] [security2:error] [pid 49578:tid 49595] [remote 217.61.143.92:43672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4d9LU3yPMQnn6OehdtTQABRxA"]
[Mon Jul 20 07:09:08.770817 2026] [security2:error] [pid 49578:tid 49719] [client 77.110.127.138:64144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d9LU3yPMQnn6OehdtVQAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:08.770940 2026] [security2:error] [pid 49578:tid 49719] [client 77.110.127.138:64144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d9LU3yPMQnn6OehdtVQAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:08.938105 2026] [security2:error] [pid 49578:tid 49662] [remote 217.61.143.92:43672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hilltopnurseryinc.com"] [uri "/wp-login.php"] [unique_id "al4d9LU3yPMQnn6OehdtZgABSlM"], referer: https://hilltopnurseryinc.com/wp-login.php
[Mon Jul 20 07:09:09.261150 2026] [security2:error] [pid 49578:tid 49775] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d9bU3yPMQnn6OehdtdQAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:09.267945 2026] [security2:error] [pid 49578:tid 49814] [client 14.225.17.146:52029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4d9bU3yPMQnn6OehdthwAAAXQ"], referer: http://daseighty.net/2024
[Mon Jul 20 07:09:09.356191 2026] [security2:error] [pid 49578:tid 49732] [client 14.225.17.146:51991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4d9bU3yPMQnn6OehdthAAAASI"], referer: http://ivetstrategies.com/2024
[Mon Jul 20 07:09:09.364711 2026] [security2:error] [pid 49578:tid 49784] [client 194.61.41.94:52515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/theme.php"] [unique_id "al4d9bU3yPMQnn6OehdtmgAAAVY"]
[Mon Jul 20 07:09:09.897102 2026] [security2:error] [pid 49578:tid 49770] [client 114.119.129.71:49043] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "verdunestate.com"] [uri "/agent/rima-rimlawi"] [unique_id "al4d9bU3yPMQnn6OehdtvAAAAUg"], referer: https://verdunestate.com/agent/rima-rimlawi
[Mon Jul 20 07:09:10.121965 2026] [security2:error] [pid 49578:tid 49817] [client 194.61.41.102:44811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentytwo/waf_defender.php"] [unique_id "al4d9rU3yPMQnn6OehdtyAAAAXc"]
[Mon Jul 20 07:09:10.743108 2026] [security2:error] [pid 49578:tid 49758] [client 117.247.108.24:1652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d9rU3yPMQnn6Oehdt9AAAATw"]
[Mon Jul 20 07:09:10.743227 2026] [security2:error] [pid 49578:tid 49758] [client 117.247.108.24:1652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4d9rU3yPMQnn6Oehdt9AAAATw"]
[Mon Jul 20 07:09:10.746582 2026] [security2:error] [pid 49578:tid 49778] [client 14.225.17.146:51818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4d9bU3yPMQnn6OehdtlAAAAVA"], referer: http://blaizeaccountingservices.com/2024
[Mon Jul 20 07:09:10.855305 2026] [security2:error] [pid 49578:tid 49818] [client 194.61.41.246:60053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/coffee/index.php"] [unique_id "al4d9rU3yPMQnn6Oehdt_gAAAXg"]
[Mon Jul 20 07:09:11.532315 2026] [security2:error] [pid 49578:tid 49725] [client 14.225.17.146:62284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4d9rU3yPMQnn6OehdtzQAAARs"], referer: http://wathenbartlett.co.uk/2024
[Mon Jul 20 07:09:11.660441 2026] [security2:error] [pid 49578:tid 49808] [client 194.61.41.62:58539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/Simple.php"] [unique_id "al4d97U3yPMQnn6OehduOQAAAW4"]
[Mon Jul 20 07:09:11.718892 2026] [security2:error] [pid 49578:tid 49822] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d97U3yPMQnn6OehduLAAAAXw"]
[Mon Jul 20 07:09:11.892843 2026] [security2:error] [pid 49578:tid 49824] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d97U3yPMQnn6OehduMgAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:11.929030 2026] [security2:error] [pid 49578:tid 49813] [client 14.225.17.146:62287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4d97U3yPMQnn6OehduPwAAAXM"], referer: http://ncsynchro.com/2024
[Mon Jul 20 07:09:12.033359 2026] [security2:error] [pid 49578:tid 49800] [client 74.208.214.194:55168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4d-LU3yPMQnn6OehduWgAAAWY"]
[Mon Jul 20 07:09:12.132236 2026] [security2:error] [pid 49578:tid 49814] [client 57.141.18.113:64518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4d9bU3yPMQnn6OehdtrwABdAk"]
[Mon Jul 20 07:09:12.173302 2026] [security2:error] [pid 49578:tid 49778] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d97U3yPMQnn6OehduVQAAAVA"]
[Mon Jul 20 07:09:12.349947 2026] [security2:error] [pid 49578:tid 49675] [remote 78.46.157.202:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d-LU3yPMQnn6OehdubQABLWA"]
[Mon Jul 20 07:09:12.360597 2026] [security2:error] [pid 49578:tid 49770] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehduYQAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:12.418553 2026] [security2:error] [pid 49578:tid 49752] [client 194.61.41.70:57729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/index.php"] [unique_id "al4d-LU3yPMQnn6OehdudgAAATY"]
[Mon Jul 20 07:09:12.498859 2026] [security2:error] [pid 49578:tid 49806] [client 14.225.17.146:65357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehdueAAAAWw"], referer: https://wathenbartlett.co.uk/2024
[Mon Jul 20 07:09:12.558438 2026] [security2:error] [pid 49578:tid 49650] [remote 78.46.157.202:56872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d-LU3yPMQnn6OehduiQABgUc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:09:12.574500 2026] [security2:error] [pid 49578:tid 49665] [remote 57.141.18.120:20914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4d-LU3yPMQnn6OehduigABC1Y"]
[Mon Jul 20 07:09:12.663615 2026] [security2:error] [pid 49578:tid 49763] [client 23.21.254.26:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehduiAABQQs"]
[Mon Jul 20 07:09:12.700910 2026] [security2:error] [pid 49578:tid 49711] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehduhAAAAQ0"]
[Mon Jul 20 07:09:12.733297 2026] [security2:error] [pid 49578:tid 49705] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d-LU3yPMQnn6OehdukQABD34"]
[Mon Jul 20 07:09:12.733447 2026] [security2:error] [pid 49578:tid 49713] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4d-LU3yPMQnn6OehdukQABD34"]
[Mon Jul 20 07:09:13.024549 2026] [security2:error] [pid 49578:tid 49735] [client 50.116.65.227:53458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4d-bU3yPMQnn6OehdutAAAASU"]
[Mon Jul 20 07:09:13.027845 2026] [security2:error] [pid 49578:tid 49727] [client 14.225.17.146:62411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4d97U3yPMQnn6OehduNQAAAR0"]
[Mon Jul 20 07:09:13.044133 2026] [security2:error] [pid 49578:tid 49595] [remote 100.42.189.89:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4d-bU3yPMQnn6OehdutQABdhA"]
[Mon Jul 20 07:09:13.079346 2026] [security2:error] [pid 49578:tid 49790] [client 54.147.229.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehduqAABXC8"]
[Mon Jul 20 07:09:13.102066 2026] [security2:error] [pid 49578:tid 49712] [client 187.16.64.216:57729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d-bU3yPMQnn6OehduuwAAAQ4"]
[Mon Jul 20 07:09:13.102164 2026] [security2:error] [pid 49578:tid 49712] [client 187.16.64.216:57729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4d-bU3yPMQnn6OehduuwAAAQ4"]
[Mon Jul 20 07:09:13.136592 2026] [security2:error] [pid 49578:tid 49803] [client 194.61.41.94:35807] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/wp-admin/1.php"] [unique_id "al4d-bU3yPMQnn6OehduvAAAAWk"]
[Mon Jul 20 07:09:13.136700 2026] [security2:error] [pid 49578:tid 49803] [client 194.61.41.94:35807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/1.php"] [unique_id "al4d-bU3yPMQnn6OehduvAAAAWk"]
[Mon Jul 20 07:09:13.157104 2026] [security2:error] [pid 49578:tid 49736] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehduqwAAASY"]
[Mon Jul 20 07:09:13.236606 2026] [security2:error] [pid 49578:tid 49642] [remote 100.42.189.89:47440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omrobuildingcenter.com"] [uri "/wp-login.php"] [unique_id "al4d-bU3yPMQnn6OehduxQABRD8"], referer: https://omrobuildingcenter.com/wp-login.php
[Mon Jul 20 07:09:13.355195 2026] [security2:error] [pid 49578:tid 49819] [client 14.225.17.146:51678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4d-bU3yPMQnn6OehduwAAAAXk"], referer: http://ghivs.com/2024
[Mon Jul 20 07:09:13.424021 2026] [autoindex:error] [pid 49578:tid 49620] [remote 34.148.218.153:53466] AH01276: Cannot serve directory /home2/hsdrromy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://hsd.rro.mybluehost.me
[Mon Jul 20 07:09:13.447156 2026] [security2:error] [pid 49578:tid 49769] [client 104.234.53.74:37707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4d-bU3yPMQnn6Oehdu5gAAAUc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:13.649839 2026] [security2:error] [pid 49578:tid 49739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-bU3yPMQnn6Oehdu4wAAASk"]
[Mon Jul 20 07:09:13.898668 2026] [security2:error] [pid 49578:tid 49679] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d-bU3yPMQnn6Oehdu_QABGGQ"]
[Mon Jul 20 07:09:13.898831 2026] [security2:error] [pid 49578:tid 49722] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4d-bU3yPMQnn6Oehdu_QABGGQ"]
[Mon Jul 20 07:09:13.926249 2026] [security2:error] [pid 49578:tid 49798] [client 14.225.17.146:62260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4d-LU3yPMQnn6OehduhgAAAWQ"], referer: http://expertcultures.com/2024
[Mon Jul 20 07:09:14.002565 2026] [security2:error] [pid 49578:tid 49749] [client 194.61.41.244:54481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/ocean/wp-login.php"] [unique_id "al4d-bU3yPMQnn6OehdvAwAAATM"]
[Mon Jul 20 07:09:14.117487 2026] [security2:error] [pid 49578:tid 49734] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-bU3yPMQnn6Oehdu_AAAASQ"]
[Mon Jul 20 07:09:14.237523 2026] [security2:error] [pid 49578:tid 49786] [client 77.110.127.138:64179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d-rU3yPMQnn6OehdvGQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:14.237597 2026] [security2:error] [pid 49578:tid 49786] [client 77.110.127.138:64179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d-rU3yPMQnn6OehdvGQAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:14.584411 2026] [security2:error] [pid 49578:tid 49834] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-rU3yPMQnn6OehdvJwAAAYg"]
[Mon Jul 20 07:09:14.737244 2026] [security2:error] [pid 49578:tid 49746] [client 194.61.41.252:41359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/wp-conflg.php"] [unique_id "al4d-rU3yPMQnn6OehdvQgAAATA"]
[Mon Jul 20 07:09:15.039626 2026] [security2:error] [pid 49578:tid 49825] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d-rU3yPMQnn6OehdvSQAAAX8"]
[Mon Jul 20 07:09:15.044394 2026] [security2:error] [pid 49578:tid 49793] [client 43.205.139.3:47146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvVgAAAV8"]
[Mon Jul 20 07:09:15.052353 2026] [security2:error] [pid 49578:tid 49742] [client 88.241.67.160:55586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvVwAAASw"]
[Mon Jul 20 07:09:15.052552 2026] [security2:error] [pid 49578:tid 49742] [client 88.241.67.160:55586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvVwAAASw"]
[Mon Jul 20 07:09:15.184308 2026] [security2:error] [pid 49578:tid 49773] [client 14.225.17.146:62120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4d-rU3yPMQnn6OehdvEgAAAUs"], referer: http://intelligentengineeringsolutions.com/2024
[Mon Jul 20 07:09:15.205678 2026] [security2:error] [pid 49578:tid 49794] [client 14.225.17.146:62135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4d-bU3yPMQnn6Oehdu6QAAAWA"], referer: http://aandarealtygroup.com/2024
[Mon Jul 20 07:09:15.261037 2026] [security2:error] [pid 49578:tid 49807] [client 52.47.76.32:35644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvZwAAAW0"]
[Mon Jul 20 07:09:15.261159 2026] [security2:error] [pid 49578:tid 49807] [client 52.47.76.32:35644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvZwAAAW0"]
[Mon Jul 20 07:09:15.297338 2026] [security2:error] [pid 49578:tid 49745] [client 117.211.236.168:50165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvbAAAAS8"]
[Mon Jul 20 07:09:15.297449 2026] [security2:error] [pid 49578:tid 49745] [client 117.211.236.168:50165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvbAAAAS8"]
[Mon Jul 20 07:09:15.418708 2026] [security2:error] [pid 49578:tid 49818] [client 104.234.53.64:47379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvdQAAAXg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:15.437262 2026] [security2:error] [pid 49578:tid 49710] [client 194.61.41.99:48137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/classwithtostring.php"] [unique_id "al4d-7U3yPMQnn6OehdvfgAAAQw"]
[Mon Jul 20 07:09:15.527190 2026] [security2:error] [pid 49578:tid 49748] [client 77.110.127.138:64150] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4d-7U3yPMQnn6OehdvgAAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:15.662585 2026] [security2:error] [pid 49578:tid 49822] [client 158.173.89.95:41787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4d-7U3yPMQnn6OehdvjgAAAXw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:09:15.684013 2026] [security2:error] [pid 49578:tid 49671] [remote 72.167.132.114:32820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvjAABG1w"]
[Mon Jul 20 07:09:15.747773 2026] [security2:error] [pid 49578:tid 49618] [remote 217.61.143.92:53726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvkQABeyc"]
[Mon Jul 20 07:09:15.873587 2026] [security2:error] [pid 49578:tid 49747] [client 103.144.65.217:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvmgAAATE"]
[Mon Jul 20 07:09:15.873707 2026] [security2:error] [pid 49578:tid 49747] [client 103.144.65.217:61971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4d-7U3yPMQnn6OehdvmgAAATE"]
[Mon Jul 20 07:09:15.913655 2026] [security2:error] [pid 49578:tid 49615] [remote 72.167.132.114:32820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvpAABQCQ"], referer: https://zlp.omk.mybluehost.me/wp-login.php
[Mon Jul 20 07:09:15.993735 2026] [security2:error] [pid 49578:tid 49589] [remote 217.61.143.92:53726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvsQABEwo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:09:16.013396 2026] [security2:error] [pid 49578:tid 49614] [remote 142.93.10.93:36658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4d-7U3yPMQnn6OehdvsgABZyM"]
[Mon Jul 20 07:09:16.020111 2026] [security2:error] [pid 49578:tid 49736] [client 13.233.207.33:24930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4d_LU3yPMQnn6OehdvtAAAASY"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:09:16.163021 2026] [security2:error] [pid 49578:tid 49757] [client 194.61.41.75:23421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/av.php"] [unique_id "al4d_LU3yPMQnn6OehdvwgAAATs"]
[Mon Jul 20 07:09:16.189531 2026] [security2:error] [pid 49578:tid 49593] [remote 142.93.10.93:36658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4d_LU3yPMQnn6OehdvxAABVA4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:09:16.342108 2026] [security2:error] [pid 49578:tid 49715] [client 14.225.17.146:51484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4d_LU3yPMQnn6OehdvtQAAARE"], referer: http://tacticaltreeoperations.com/2024
[Mon Jul 20 07:09:16.482333 2026] [security2:error] [pid 49578:tid 49734] [client 183.82.98.154:21205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.98.82.183.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d_LU3yPMQnn6Oehdv3AAAASQ"]
[Mon Jul 20 07:09:16.482507 2026] [security2:error] [pid 49578:tid 49734] [client 183.82.98.154:21205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4d_LU3yPMQnn6Oehdv3AAAASQ"]
[Mon Jul 20 07:09:16.588141 2026] [security2:error] [pid 49578:tid 49775] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_LU3yPMQnn6OehdvzgAAAU0"]
[Mon Jul 20 07:09:16.845324 2026] [security2:error] [pid 49578:tid 49741] [client 14.225.17.146:59751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4d_LU3yPMQnn6Oehdv7AAAASs"], referer: http://ksands.co.uk/2024
[Mon Jul 20 07:09:16.919768 2026] [security2:error] [pid 49578:tid 49743] [client 194.61.41.94:44939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/waf_defender.php"] [unique_id "al4d_LU3yPMQnn6OehdwAAAAAS0"]
[Mon Jul 20 07:09:17.064882 2026] [security2:error] [pid 49578:tid 49772] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_LU3yPMQnn6Oehdv9AAAAUo"]
[Mon Jul 20 07:09:17.228738 2026] [autoindex:error] [pid 49578:tid 49663] [remote 34.23.37.181:57900] AH01276: Cannot serve directory /home2/brsjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.brs.jiv.mybluehost.me
[Mon Jul 20 07:09:17.469626 2026] [security2:error] [pid 49578:tid 49826] [client 77.110.127.138:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d_bU3yPMQnn6OehdwMgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:17.469713 2026] [security2:error] [pid 49578:tid 49826] [client 77.110.127.138:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d_bU3yPMQnn6OehdwMgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:17.570604 2026] [security2:error] [pid 49578:tid 49718] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_bU3yPMQnn6OehdwJAAAARQ"]
[Mon Jul 20 07:09:17.637692 2026] [security2:error] [pid 49578:tid 49736] [client 194.61.41.101:60895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/Cache/upfile.php"] [unique_id "al4d_bU3yPMQnn6OehdwRQAAASY"]
[Mon Jul 20 07:09:18.044075 2026] [security2:error] [pid 49578:tid 49741] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_bU3yPMQnn6OehdwXAAAASs"]
[Mon Jul 20 07:09:18.407233 2026] [security2:error] [pid 49578:tid 49742] [client 77.110.127.138:64183] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4d_rU3yPMQnn6OehdwkgAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:18.439700 2026] [security2:error] [pid 49578:tid 49765] [client 194.61.41.105:62829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/small.php"] [unique_id "al4d_rU3yPMQnn6OehdwmgAAAUM"]
[Mon Jul 20 07:09:18.487222 2026] [security2:error] [pid 49578:tid 49732] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_rU3yPMQnn6OehdwhQAAASI"]
[Mon Jul 20 07:09:18.741602 2026] [security2:error] [pid 49578:tid 49684] [remote 81.173.115.7:38524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d_rU3yPMQnn6OehdwsAABYmk"]
[Mon Jul 20 07:09:18.837639 2026] [security2:error] [pid 49578:tid 49721] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_rU3yPMQnn6OehdwpwAAARc"]
[Mon Jul 20 07:09:18.899814 2026] [security2:error] [pid 49578:tid 49736] [client 201.27.111.74:61531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d_rU3yPMQnn6OehdwwgAAASY"]
[Mon Jul 20 07:09:18.899931 2026] [security2:error] [pid 49578:tid 49736] [client 201.27.111.74:61531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4d_rU3yPMQnn6OehdwwgAAASY"]
[Mon Jul 20 07:09:18.960121 2026] [security2:error] [pid 49578:tid 49695] [remote 173.212.252.15:38154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4d_rU3yPMQnn6OehdwygABZHQ"]
[Mon Jul 20 07:09:18.961583 2026] [security2:error] [pid 49578:tid 49674] [remote 81.173.115.7:38524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4d_rU3yPMQnn6OehdwywABL18"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:09:19.061250 2026] [security2:error] [pid 49578:tid 49685] [remote 57.141.18.50:32784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3251155"] [unique_id "al4d_7U3yPMQnn6Oehdw1gABGGo"]
[Mon Jul 20 07:09:19.225891 2026] [security2:error] [pid 49578:tid 49634] [remote 173.212.252.15:38154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4d_7U3yPMQnn6Oehdw4QABHTc"], referer: https://superiorcopywriting.com/wp-login.php
[Mon Jul 20 07:09:19.254271 2026] [security2:error] [pid 49578:tid 49782] [client 194.61.41.55:21795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/tinymce/plugins/fullscreen/about.php"] [unique_id "al4d_7U3yPMQnn6Oehdw5QAAAVQ"]
[Mon Jul 20 07:09:19.259718 2026] [security2:error] [pid 49578:tid 49762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_7U3yPMQnn6Oehdw1AAAAUA"]
[Mon Jul 20 07:09:19.319566 2026] [security2:error] [pid 49578:tid 49787] [client 114.119.155.153:54889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villa-m-medjugorje.com"] [uri "/our-rooms/"] [unique_id "al4d_7U3yPMQnn6Oehdw7QAAAVk"], referer: http://villa-m-medjugorje.com/
[Mon Jul 20 07:09:19.623539 2026] [security2:error] [pid 49578:tid 49752] [client 213.152.186.163:37500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4d_7U3yPMQnn6OehdxCwAAATY"]
[Mon Jul 20 07:09:19.623672 2026] [security2:error] [pid 49578:tid 49752] [client 213.152.186.163:37500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4d_7U3yPMQnn6OehdxCwAAATY"]
[Mon Jul 20 07:09:19.634639 2026] [security2:error] [pid 49578:tid 49824] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4d_7U3yPMQnn6Oehdw9wAAAX4"]
[Mon Jul 20 07:09:19.776746 2026] [security2:error] [pid 49578:tid 49771] [client 14.225.17.146:51296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4d_7U3yPMQnn6OehdxCQAAAUk"], referer: http://vinovinhowine.com/2024
[Mon Jul 20 07:09:19.777461 2026] [security2:error] [pid 49578:tid 49727] [client 77.110.127.138:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d_7U3yPMQnn6OehdxFgAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:19.777556 2026] [security2:error] [pid 49578:tid 49727] [client 77.110.127.138:64211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4d_7U3yPMQnn6OehdxFgAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:20.031950 2026] [security2:error] [pid 49578:tid 49728] [client 194.61.41.61:36399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/NewFile.php"] [unique_id "al4eALU3yPMQnn6OehdxKwAAAR4"]
[Mon Jul 20 07:09:20.259021 2026] [security2:error] [pid 49578:tid 49717] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eALU3yPMQnn6OehdxLAAAARM"]
[Mon Jul 20 07:09:20.675653 2026] [security2:error] [pid 49578:tid 49783] [client 158.173.166.181:22441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eALU3yPMQnn6OehdxfQAAAVU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:09:20.739566 2026] [security2:error] [pid 49578:tid 49777] [client 14.225.17.146:62008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4d_rU3yPMQnn6OehdwxAAAAU8"], referer: http://windowtx.com/2024
[Mon Jul 20 07:09:20.755034 2026] [security2:error] [pid 49578:tid 49808] [client 194.61.41.66:45993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/index.php"] [unique_id "al4eALU3yPMQnn6OehdxggAAAW4"]
[Mon Jul 20 07:09:20.863793 2026] [security2:error] [pid 49578:tid 49626] [remote 5.161.225.162:58140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eALU3yPMQnn6OehdxjgABDi8"]
[Mon Jul 20 07:09:20.864023 2026] [security2:error] [pid 49578:tid 49712] [client 5.161.225.162:58140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eALU3yPMQnn6OehdxjgABDi8"]
[Mon Jul 20 07:09:20.965964 2026] [security2:error] [pid 49578:tid 49761] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eALU3yPMQnn6OehdxbgAAAT8"]
[Mon Jul 20 07:09:21.179406 2026] [security2:error] [pid 49578:tid 49833] [client 43.205.139.3:47162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4eAbU3yPMQnn6OehdxqQAAAYc"]
[Mon Jul 20 07:09:21.179501 2026] [security2:error] [pid 49578:tid 49833] [client 43.205.139.3:47162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4eAbU3yPMQnn6OehdxqQAAAYc"]
[Mon Jul 20 07:09:21.328323 2026] [security2:error] [pid 49578:tid 49744] [client 117.247.108.24:22394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eAbU3yPMQnn6OehdxsgAAAS4"]
[Mon Jul 20 07:09:21.328442 2026] [security2:error] [pid 49578:tid 49744] [client 117.247.108.24:22394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eAbU3yPMQnn6OehdxsgAAAS4"]
[Mon Jul 20 07:09:21.470808 2026] [security2:error] [pid 49578:tid 49799] [client 77.110.127.138:64201] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4eAbU3yPMQnn6Oehdx1AAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:21.519823 2026] [security2:error] [pid 49578:tid 49729] [client 194.61.41.246:57045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/error.php"] [unique_id "al4eAbU3yPMQnn6Oehdx1gAAAR8"]
[Mon Jul 20 07:09:21.564595 2026] [security2:error] [pid 49578:tid 49717] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eAbU3yPMQnn6OehdxswAAARM"]
[Mon Jul 20 07:09:21.853772 2026] [core:error] [pid 49578:tid 49727] [client 14.225.17.146:62030] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:09:21.853793 2026] [core:error] [pid 49578:tid 49727] [client 14.225.17.146:62030] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:09:21.888263 2026] [security2:error] [pid 49578:tid 49720] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eAbU3yPMQnn6Oehdx6AAAARY"]
[Mon Jul 20 07:09:21.944112 2026] [security2:error] [pid 49578:tid 49767] [client 13.233.207.33:24942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eAbU3yPMQnn6OehdyFQAAAUU"]
[Mon Jul 20 07:09:22.211514 2026] [security2:error] [pid 49578:tid 49712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eAbU3yPMQnn6OehdyJAAAAQ4"]
[Mon Jul 20 07:09:22.257918 2026] [security2:error] [pid 49578:tid 49730] [client 194.61.41.83:52679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/admin-footer.php"] [unique_id "al4eArU3yPMQnn6OehdyawAAASA"]
[Mon Jul 20 07:09:22.310797 2026] [security2:error] [pid 49578:tid 49725] [client 77.110.127.138:64207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eArU3yPMQnn6OehdycgAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:22.310929 2026] [security2:error] [pid 49578:tid 49725] [client 77.110.127.138:64207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eArU3yPMQnn6OehdycgAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:22.549460 2026] [security2:error] [pid 49578:tid 49768] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eArU3yPMQnn6OehdydAAAAUY"]
[Mon Jul 20 07:09:23.268394 2026] [http2:info] [pid 78969:tid 78969] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:09:23.285557 2026] [security2:error] [pid 78969:tid 79100] [client 194.61.41.94:28251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-wp-widget-search-function.php"] [unique_id "al4eA3DvNPGtvLGb7O3lBQAAAIY"]
[Mon Jul 20 07:09:23.420391 2026] [security2:error] [pid 49578:tid 49663] [remote 57.141.18.101:45750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eALU3yPMQnn6OehdxbwABiVQ"]
[Mon Jul 20 07:09:23.464190 2026] [security2:error] [pid 78969:tid 78981] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eA3DvNPGtvLGb7O3lJQAAiws"]
[Mon Jul 20 07:09:23.464404 2026] [security2:error] [pid 78969:tid 79105] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eA3DvNPGtvLGb7O3lJQAAiws"]
[Mon Jul 20 07:09:23.549833 2026] [security2:error] [pid 78969:tid 79108] [client 43.205.139.3:17268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eA3DvNPGtvLGb7O3lLAAAAI4"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:09:23.593323 2026] [security2:error] [pid 78969:tid 79130] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eA3DvNPGtvLGb7O3lHAAAAKQ"]
[Mon Jul 20 07:09:23.832106 2026] [security2:error] [pid 78969:tid 79152] [client 187.16.64.216:58309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eA3DvNPGtvLGb7O3lUQAAALo"]
[Mon Jul 20 07:09:23.832221 2026] [security2:error] [pid 78969:tid 79152] [client 187.16.64.216:58309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eA3DvNPGtvLGb7O3lUQAAALo"]
[Mon Jul 20 07:09:24.033834 2026] [security2:error] [pid 78969:tid 79217] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eA3DvNPGtvLGb7O3lUgAAAPs"]
[Mon Jul 20 07:09:24.037125 2026] [security2:error] [pid 78969:tid 79137] [client 194.61.41.63:27629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/themes/index.php"] [unique_id "al4eBHDvNPGtvLGb7O3lXQAAAKs"]
[Mon Jul 20 07:09:24.522352 2026] [security2:error] [pid 78969:tid 79017] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eBHDvNPGtvLGb7O3lgQAA0S8"]
[Mon Jul 20 07:09:24.522521 2026] [security2:error] [pid 78969:tid 79175] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eBHDvNPGtvLGb7O3lgQAA0S8"]
[Mon Jul 20 07:09:24.824326 2026] [security2:error] [pid 78969:tid 79126] [client 194.61.41.253:59013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-files.php"] [unique_id "al4eBHDvNPGtvLGb7O3lnAAAAKA"]
[Mon Jul 20 07:09:24.989072 2026] [security2:error] [pid 78969:tid 79148] [client 77.110.127.138:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBHDvNPGtvLGb7O3logAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:24.989176 2026] [security2:error] [pid 78969:tid 79148] [client 77.110.127.138:64239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBHDvNPGtvLGb7O3logAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:25.038348 2026] [security2:error] [pid 78969:tid 79125] [client 74.7.227.179:44094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4eBHDvNPGtvLGb7O3loAAAnzo"], referer: https://tejasenvironmental.com/p=831147
[Mon Jul 20 07:09:25.227299 2026] [security2:error] [pid 78969:tid 79181] [client 77.110.127.138:64242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBXDvNPGtvLGb7O3ltAAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:25.227448 2026] [security2:error] [pid 78969:tid 79181] [client 77.110.127.138:64242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBXDvNPGtvLGb7O3ltAAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:25.280058 2026] [security2:error] [pid 78969:tid 79101] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eBXDvNPGtvLGb7O3lqAAAAIc"]
[Mon Jul 20 07:09:25.565001 2026] [security2:error] [pid 78969:tid 79207] [client 194.61.41.84:36463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/functions.php"] [unique_id "al4eBXDvNPGtvLGb7O3l1gAAAPE"]
[Mon Jul 20 07:09:25.599008 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:64246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBXDvNPGtvLGb7O3l2QAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:25.599106 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:64246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBXDvNPGtvLGb7O3l2QAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:25.601010 2026] [security2:error] [pid 78969:tid 79112] [client 157.245.179.103:49278] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.technicalseohouse.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4eBXDvNPGtvLGb7O3l1wAAAJI"]
[Mon Jul 20 07:09:25.671693 2026] [security2:error] [pid 78969:tid 79195] [client 88.241.67.160:56694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eBXDvNPGtvLGb7O3l4wAAAOU"]
[Mon Jul 20 07:09:25.672184 2026] [security2:error] [pid 78969:tid 79195] [client 88.241.67.160:56694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eBXDvNPGtvLGb7O3l4wAAAOU"]
[Mon Jul 20 07:09:25.721366 2026] [security2:error] [pid 78969:tid 79137] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eBXDvNPGtvLGb7O3l0wAAAKs"]
[Mon Jul 20 07:09:26.134189 2026] [security2:error] [pid 78969:tid 79121] [client 77.110.127.138:64252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mDAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:26.134284 2026] [security2:error] [pid 78969:tid 79121] [client 77.110.127.138:64252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mDAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:26.329266 2026] [security2:error] [pid 78969:tid 79162] [client 194.61.41.64:25157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/Canonical.php"] [unique_id "al4eBnDvNPGtvLGb7O3mHwAAAMQ"]
[Mon Jul 20 07:09:26.353150 2026] [security2:error] [pid 78969:tid 79225] [client 114.119.145.216:52859] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nevelow.com"] [uri "/robots.txt"] [unique_id "al4eBnDvNPGtvLGb7O3mIgAAAQM"], referer: https://nevelow.com/robots.txt
[Mon Jul 20 07:09:26.367255 2026] [security2:error] [pid 78969:tid 79142] [client 77.110.127.138:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mIwAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:26.367356 2026] [security2:error] [pid 78969:tid 79142] [client 77.110.127.138:64256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mIwAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:26.368270 2026] [security2:error] [pid 78969:tid 79130] [client 103.144.65.217:62420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eBnDvNPGtvLGb7O3mJAAAAKQ"]
[Mon Jul 20 07:09:26.368345 2026] [security2:error] [pid 78969:tid 79130] [client 103.144.65.217:62420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eBnDvNPGtvLGb7O3mJAAAAKQ"]
[Mon Jul 20 07:09:26.440726 2026] [security2:error] [pid 78969:tid 79149] [client 14.225.17.146:57463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4eBnDvNPGtvLGb7O3mAQAAALc"], referer: http://mollycahill.com/2024
[Mon Jul 20 07:09:26.445390 2026] [security2:error] [pid 78969:tid 79143] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eBnDvNPGtvLGb7O3mFQAAALE"]
[Mon Jul 20 07:09:26.717204 2026] [security2:error] [pid 78969:tid 79122] [client 117.211.236.168:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eBnDvNPGtvLGb7O3mQgAAAJw"]
[Mon Jul 20 07:09:26.717325 2026] [security2:error] [pid 78969:tid 79122] [client 117.211.236.168:50680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eBnDvNPGtvLGb7O3mQgAAAJw"]
[Mon Jul 20 07:09:26.737437 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:64261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mRQAAAOg"]
[Mon Jul 20 07:09:26.737546 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:64261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mRQAAAOg"]
[Mon Jul 20 07:09:26.812197 2026] [security2:error] [pid 78969:tid 79169] [client 185.198.240.150:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "leapexinc.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4eBnDvNPGtvLGb7O3mSwAAAMs"]
[Mon Jul 20 07:09:26.926721 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mWAAAAMQ"]
[Mon Jul 20 07:09:26.926824 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:64263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eBnDvNPGtvLGb7O3mWAAAAMQ"]
[Mon Jul 20 07:09:27.039601 2026] [security2:error] [pid 78969:tid 79104] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eBnDvNPGtvLGb7O3mTAAAAIo"]
[Mon Jul 20 07:09:27.108672 2026] [security2:error] [pid 78969:tid 79226] [client 185.198.240.150:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "leapexinc.com"] [uri "/media/system/js/core.js"] [unique_id "al4eB3DvNPGtvLGb7O3maAAAAQQ"]
[Mon Jul 20 07:09:27.133551 2026] [security2:error] [pid 78969:tid 79204] [client 194.61.41.243:27271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/autoload_classmap.php"] [unique_id "al4eB3DvNPGtvLGb7O3maQAAAO4"]
[Mon Jul 20 07:09:27.424984 2026] [security2:error] [pid 78969:tid 79125] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eB3DvNPGtvLGb7O3mdAAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:27.504578 2026] [security2:error] [pid 78969:tid 79180] [client 14.225.17.146:60343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4eB3DvNPGtvLGb7O3magAAANY"], referer: http://grecruit.online/2024
[Mon Jul 20 07:09:27.588626 2026] [security2:error] [pid 78969:tid 79214] [client 14.225.17.146:59580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4eB3DvNPGtvLGb7O3mkgAAAPg"], referer: http://headachescarpaltunnelfibromyalgia.com/2024
[Mon Jul 20 07:09:27.720910 2026] [security2:error] [pid 78969:tid 79208] [client 167.172.52.63:57248] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.asliceofleadership.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4eB3DvNPGtvLGb7O3mogAAAPI"]
[Mon Jul 20 07:09:27.786272 2026] [security2:error] [pid 78969:tid 79103] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eB3DvNPGtvLGb7O3mmgAAAIk"]
[Mon Jul 20 07:09:27.928768 2026] [security2:error] [pid 78969:tid 79216] [client 194.61.41.82:24569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/aks.php"] [unique_id "al4eB3DvNPGtvLGb7O3mvAAAAPo"]
[Mon Jul 20 07:09:28.098338 2026] [security2:error] [pid 78969:tid 79108] [client 130.185.118.215:44766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4eB3DvNPGtvLGb7O3mwQAAjhY"], referer: https://blaizeaccountingservices.com/wp-login.php
[Mon Jul 20 07:09:28.151155 2026] [security2:error] [pid 78969:tid 78996] [remote 173.249.4.11:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eCHDvNPGtvLGb7O3mzQAA2ho"]
[Mon Jul 20 07:09:28.214193 2026] [security2:error] [pid 78969:tid 79137] [client 134.199.153.155:64247] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.fluidtemple.org"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4eCHDvNPGtvLGb7O3mzAAAAKs"]
[Mon Jul 20 07:09:28.257198 2026] [security2:error] [pid 78969:tid 79200] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCHDvNPGtvLGb7O3myQAAAOo"]
[Mon Jul 20 07:09:28.339346 2026] [security2:error] [pid 78969:tid 78999] [remote 173.249.4.11:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eCHDvNPGtvLGb7O3m3QAAsR0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:09:28.629886 2026] [security2:error] [pid 78969:tid 79192] [client 194.61.41.243:37729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/litespeed.php"] [unique_id "al4eCHDvNPGtvLGb7O3nAQAAAOI"]
[Mon Jul 20 07:09:28.963334 2026] [security2:error] [pid 78969:tid 79170] [client 14.225.17.146:60114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4eB3DvNPGtvLGb7O3mpAAAAMw"], referer: http://cloudspacesgroup.com/2024
[Mon Jul 20 07:09:29.137926 2026] [security2:error] [pid 78969:tid 79198] [client 14.225.17.146:57333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4eCHDvNPGtvLGb7O3nGwAAAOg"], referer: http://idigress.agency/2024
[Mon Jul 20 07:09:29.205674 2026] [security2:error] [pid 78969:tid 79181] [client 14.225.17.146:60142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4eCXDvNPGtvLGb7O3nLwAAANc"], referer: http://hammadownenterprises.com/2024
[Mon Jul 20 07:09:29.226599 2026] [security2:error] [pid 78969:tid 79114] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCXDvNPGtvLGb7O3nKQAAAJQ"]
[Mon Jul 20 07:09:29.329605 2026] [security2:error] [pid 78969:tid 79186] [client 14.225.17.146:60183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4eCXDvNPGtvLGb7O3nNAAAANw"], referer: http://cheesewithjam.com/2024
[Mon Jul 20 07:09:29.369455 2026] [security2:error] [pid 78969:tid 79126] [client 194.61.41.240:41591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/img/about.php"] [unique_id "al4eCXDvNPGtvLGb7O3nRAAAAKA"]
[Mon Jul 20 07:09:29.412633 2026] [security2:error] [pid 78969:tid 79194] [client 201.27.111.74:62013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eCXDvNPGtvLGb7O3nSwAAAOQ"]
[Mon Jul 20 07:09:29.412731 2026] [security2:error] [pid 78969:tid 79194] [client 201.27.111.74:62013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eCXDvNPGtvLGb7O3nSwAAAOQ"]
[Mon Jul 20 07:09:29.499646 2026] [security2:error] [pid 78969:tid 79161] [client 57.141.18.107:35810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eBnDvNPGtvLGb7O3mNAAAw2c"]
[Mon Jul 20 07:09:29.560270 2026] [security2:error] [pid 78969:tid 79112] [client 104.234.53.94:27955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4eCXDvNPGtvLGb7O3nXQAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:29.594126 2026] [security2:error] [pid 78969:tid 79148] [client 14.225.17.146:51580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4eCHDvNPGtvLGb7O3m9gAAALY"], referer: http://entuvy.com/2024
[Mon Jul 20 07:09:29.641533 2026] [security2:error] [pid 78969:tid 79124] [client 98.159.234.160:62137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eCXDvNPGtvLGb7O3nYgAAAJ4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:09:29.667730 2026] [security2:error] [pid 78969:tid 79159] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCXDvNPGtvLGb7O3nVwAAAME"]
[Mon Jul 20 07:09:29.799145 2026] [security2:error] [pid 78969:tid 79045] [remote 152.228.213.32:41178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4eCXDvNPGtvLGb7O3nbgAA8Us"]
[Mon Jul 20 07:09:29.936755 2026] [security2:error] [pid 78969:tid 79178] [client 14.225.17.146:59691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4eCXDvNPGtvLGb7O3nZgAAANQ"], referer: http://myspineworld.com/2024
[Mon Jul 20 07:09:29.958118 2026] [security2:error] [pid 78969:tid 79053] [remote 152.228.213.32:36150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eCXDvNPGtvLGb7O3nfwAAlFM"]
[Mon Jul 20 07:09:30.011177 2026] [security2:error] [pid 78969:tid 79052] [remote 152.228.213.32:41178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4eCnDvNPGtvLGb7O3ngwAAqVI"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 07:09:30.076886 2026] [security2:error] [pid 78969:tid 79186] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCXDvNPGtvLGb7O3ndAAAANw"]
[Mon Jul 20 07:09:30.126145 2026] [security2:error] [pid 78969:tid 79197] [client 194.61.41.86:25889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-feed-index.php"] [unique_id "al4eCnDvNPGtvLGb7O3njQAAAOc"]
[Mon Jul 20 07:09:30.166192 2026] [security2:error] [pid 78969:tid 79057] [remote 152.228.213.32:36150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eCnDvNPGtvLGb7O3njgAAu1c"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:09:30.246649 2026] [security2:error] [pid 78969:tid 79107] [client 14.225.17.146:57361] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4eCHDvNPGtvLGb7O3nJAAAAI0"], referer: http://iagdevelopments.com/2024
[Mon Jul 20 07:09:30.703345 2026] [security2:error] [pid 78969:tid 79139] [client 14.225.17.146:58971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4eCnDvNPGtvLGb7O3nqAAAAK0"], referer: http://ccsdifference.com/2024
[Mon Jul 20 07:09:30.794799 2026] [security2:error] [pid 78969:tid 79148] [client 77.110.127.138:64289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/stitch-pattern/ocf8hws79806.php"] [unique_id "al4eCnDvNPGtvLGb7O3nywAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:30.879194 2026] [security2:error] [pid 78969:tid 79106] [client 194.61.41.72:63647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wpn.php"] [unique_id "al4eCnDvNPGtvLGb7O3n2wAAAIw"]
[Mon Jul 20 07:09:30.895431 2026] [security2:error] [pid 78969:tid 79210] [client 77.110.127.138:64237] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCnDvNPGtvLGb7O3ntQAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:31.164718 2026] [security2:error] [pid 78969:tid 79184] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCnDvNPGtvLGb7O3n0wAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:31.228664 2026] [security2:error] [pid 78969:tid 79221] [client 14.225.17.146:58942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4eC3DvNPGtvLGb7O3n-QAAAP8"], referer: https://iagdevelopments.com/2024
[Mon Jul 20 07:09:31.335803 2026] [security2:error] [pid 78969:tid 79104] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eCnDvNPGtvLGb7O3n1AAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:31.534296 2026] [security2:error] [pid 78969:tid 79145] [client 77.110.127.138:64273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eC3DvNPGtvLGb7O3oEgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:31.534402 2026] [security2:error] [pid 78969:tid 79145] [client 77.110.127.138:64273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eC3DvNPGtvLGb7O3oEgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:31.652062 2026] [security2:error] [pid 78969:tid 79153] [client 194.61.41.66:25195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/classwithtostring.php"] [unique_id "al4eC3DvNPGtvLGb7O3oJgAAALs"]
[Mon Jul 20 07:09:31.843776 2026] [security2:error] [pid 78969:tid 78970] [remote 124.55.178.99:56170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eC3DvNPGtvLGb7O3oNQABAwA"]
[Mon Jul 20 07:09:31.900504 2026] [security2:error] [pid 78969:tid 79124] [client 117.247.108.24:22560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eC3DvNPGtvLGb7O3oPAAAAJ4"]
[Mon Jul 20 07:09:31.900596 2026] [security2:error] [pid 78969:tid 79124] [client 117.247.108.24:22560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eC3DvNPGtvLGb7O3oPAAAAJ4"]
[Mon Jul 20 07:09:31.946941 2026] [proxy:error] [pid 78969:tid 79147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:09:31.947000 2026] [proxy_http:error] [pid 78969:tid 79147] [client 93.152.221.21:37504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:09:31.947861 2026] [proxy:error] [pid 78969:tid 79147] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:09:31.947904 2026] [proxy_http:error] [pid 78969:tid 79147] [client 93.152.221.21:37504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:09:32.022199 2026] [security2:error] [pid 78969:tid 79107] [client 77.110.127.138:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/surrey/mrxuf126oz2b.php"] [unique_id "al4eDHDvNPGtvLGb7O3oTAAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:32.030033 2026] [security2:error] [pid 78969:tid 79190] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eC3DvNPGtvLGb7O3oMgAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:32.243111 2026] [security2:error] [pid 78969:tid 79160] [client 77.110.127.138:64281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eDHDvNPGtvLGb7O3oTQAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:32.303504 2026] [security2:error] [pid 78969:tid 78985] [remote 124.55.178.99:56170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eDHDvNPGtvLGb7O3obgAAyw8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:09:32.364120 2026] [security2:error] [pid 78969:tid 79223] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eDHDvNPGtvLGb7O3oXQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:32.453248 2026] [security2:error] [pid 78969:tid 79142] [client 194.61.41.93:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/iR7SzrsOUEP.php"] [unique_id "al4eDHDvNPGtvLGb7O3ofwAAALA"]
[Mon Jul 20 07:09:32.458286 2026] [security2:error] [pid 78969:tid 79161] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eDHDvNPGtvLGb7O3oYAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:32.615011 2026] [security2:error] [pid 78969:tid 79145] [client 50.116.65.227:39732] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eDHDvNPGtvLGb7O3ohwAAALM"]
[Mon Jul 20 07:09:32.625775 2026] [security2:error] [pid 78969:tid 79180] [client 50.116.65.227:39742] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eDHDvNPGtvLGb7O3oiAAAANY"]
[Mon Jul 20 07:09:32.692094 2026] [security2:error] [pid 78969:tid 79178] [client 104.234.53.83:47621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4eDHDvNPGtvLGb7O3oigAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:32.785316 2026] [security2:error] [pid 78969:tid 79203] [client 14.225.17.146:59022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4eC3DvNPGtvLGb7O3oEQAAAO0"], referer: http://betterbonddogtraining.com/2024
[Mon Jul 20 07:09:33.184652 2026] [security2:error] [pid 78969:tid 79215] [client 77.110.127.138:64234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/httksxb4tf06.php"] [unique_id "al4eDXDvNPGtvLGb7O3ovwAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:33.227429 2026] [security2:error] [pid 78969:tid 79131] [client 194.61.41.98:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-section-boolean.php"] [unique_id "al4eDXDvNPGtvLGb7O3o0AAAAKU"]
[Mon Jul 20 07:09:33.347282 2026] [security2:error] [pid 78969:tid 79172] [client 104.234.53.49:30023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4eDXDvNPGtvLGb7O3o2wAAAM4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:33.416044 2026] [security2:error] [pid 78969:tid 79118] [client 34.147.22.160:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.familiaconsciente.com"] [uri "/"] [unique_id "al4eDXDvNPGtvLGb7O3o3wAAAJg"]
[Mon Jul 20 07:09:33.416126 2026] [security2:error] [pid 78969:tid 79118] [client 34.147.22.160:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.familiaconsciente.com"] [uri "/"] [unique_id "al4eDXDvNPGtvLGb7O3o3wAAAJg"]
[Mon Jul 20 07:09:33.634322 2026] [security2:error] [pid 78969:tid 79185] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eDXDvNPGtvLGb7O3oywAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:33.802612 2026] [security2:error] [pid 78969:tid 79167] [client 77.110.127.138:64291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eDXDvNPGtvLGb7O3o8gAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:33.873640 2026] [security2:error] [pid 78969:tid 79141] [client 57.141.18.118:61334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eC3DvNPGtvLGb7O3n_QAAr3I"]
[Mon Jul 20 07:09:33.950558 2026] [security2:error] [pid 78969:tid 79200] [client 194.61.41.54:26805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/functions.php"] [unique_id "al4eDXDvNPGtvLGb7O3pCQAAAOo"]
[Mon Jul 20 07:09:34.076436 2026] [security2:error] [pid 78969:tid 79041] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eDnDvNPGtvLGb7O3pEgAA90c"]
[Mon Jul 20 07:09:34.076593 2026] [security2:error] [pid 78969:tid 79213] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eDnDvNPGtvLGb7O3pEgAA90c"]
[Mon Jul 20 07:09:34.556388 2026] [security2:error] [pid 78969:tid 79107] [client 187.16.64.216:58889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eDnDvNPGtvLGb7O3pKwAAAI0"]
[Mon Jul 20 07:09:34.556500 2026] [security2:error] [pid 78969:tid 79107] [client 187.16.64.216:58889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eDnDvNPGtvLGb7O3pKwAAAI0"]
[Mon Jul 20 07:09:34.833863 2026] [security2:error] [pid 78969:tid 79207] [client 194.61.41.249:53989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/db.php"] [unique_id "al4eDnDvNPGtvLGb7O3pQQAAAPE"]
[Mon Jul 20 07:09:35.155973 2026] [security2:error] [pid 78969:tid 79071] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eD3DvNPGtvLGb7O3pWwAA22U"]
[Mon Jul 20 07:09:35.156681 2026] [security2:error] [pid 78969:tid 79185] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eD3DvNPGtvLGb7O3pWwAA22U"]
[Mon Jul 20 07:09:35.385987 2026] [security2:error] [pid 78969:tid 79078] [remote 152.228.213.32:43220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eD3DvNPGtvLGb7O3paAAAqmw"]
[Mon Jul 20 07:09:35.430687 2026] [security2:error] [pid 78969:tid 79175] [client 74.208.214.194:34988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4eD3DvNPGtvLGb7O3pbgAAANE"]
[Mon Jul 20 07:09:35.513601 2026] [security2:error] [pid 78969:tid 79146] [client 143.244.57.86:57966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4eD3DvNPGtvLGb7O3pcgAAALQ"]
[Mon Jul 20 07:09:35.564746 2026] [security2:error] [pid 78969:tid 79086] [remote 152.228.213.32:43220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eD3DvNPGtvLGb7O3pdQAAnnQ"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:09:35.628617 2026] [security2:error] [pid 78969:tid 79150] [client 194.61.41.252:39927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-dependency-float.php"] [unique_id "al4eD3DvNPGtvLGb7O3peQAAALg"]
[Mon Jul 20 07:09:35.830090 2026] [security2:error] [pid 78969:tid 79164] [client 143.244.57.86:57978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.57.244.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eD3DvNPGtvLGb7O3pjAAAAMY"]
[Mon Jul 20 07:09:35.990530 2026] [security2:error] [pid 78969:tid 79176] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eD3DvNPGtvLGb7O3phAAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:36.265756 2026] [security2:error] [pid 78969:tid 79160] [client 88.241.67.160:53701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eEHDvNPGtvLGb7O3puAAAAMI"]
[Mon Jul 20 07:09:36.266328 2026] [security2:error] [pid 78969:tid 79160] [client 88.241.67.160:53701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eEHDvNPGtvLGb7O3puAAAAMI"]
[Mon Jul 20 07:09:36.352184 2026] [security2:error] [pid 78969:tid 79164] [client 194.61.41.241:59215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/index.php"] [unique_id "al4eEHDvNPGtvLGb7O3pwQAAAMY"]
[Mon Jul 20 07:09:36.438755 2026] [security2:error] [pid 78969:tid 79099] [client 143.244.57.86:57994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4eEHDvNPGtvLGb7O3pyQAAAIU"]
[Mon Jul 20 07:09:36.604646 2026] [security2:error] [pid 78969:tid 79158] [client 115.96.42.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4eEHDvNPGtvLGb7O3ptQAAAMA"], referer: https://aosta.nz/
[Mon Jul 20 07:09:36.644797 2026] [security2:error] [pid 78969:tid 78984] [remote 5.161.225.162:33784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4eEHDvNPGtvLGb7O3p1QAA5w4"]
[Mon Jul 20 07:09:36.708624 2026] [security2:error] [pid 78969:tid 78987] [remote 192.241.143.148:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eEHDvNPGtvLGb7O3p2AAA_hE"]
[Mon Jul 20 07:09:36.744371 2026] [security2:error] [pid 78969:tid 79182] [client 143.244.57.86:58008] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4eEHDvNPGtvLGb7O3p3AAAANg"]
[Mon Jul 20 07:09:36.824492 2026] [security2:error] [pid 78969:tid 79205] [client 77.110.127.138:64237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/student-resource/0pwpp87rxb4a.php"] [unique_id "al4eEHDvNPGtvLGb7O3p5AAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:36.826194 2026] [security2:error] [pid 78969:tid 78985] [remote 5.161.225.162:33784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4eEHDvNPGtvLGb7O3p6AAApw8"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 07:09:36.880745 2026] [security2:error] [pid 78969:tid 79128] [client 103.144.65.217:62881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eEHDvNPGtvLGb7O3p-AAAAKI"]
[Mon Jul 20 07:09:36.880831 2026] [security2:error] [pid 78969:tid 79128] [client 103.144.65.217:62881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eEHDvNPGtvLGb7O3p-AAAAKI"]
[Mon Jul 20 07:09:36.902633 2026] [security2:error] [pid 78969:tid 78999] [remote 192.241.143.148:37588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eEHDvNPGtvLGb7O3p_gAA1h0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:09:37.006115 2026] [autoindex:error] [pid 78969:tid 79146] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/genesis/lib/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/themes/genesis/lib/
[Mon Jul 20 07:09:37.046987 2026] [security2:error] [pid 78969:tid 79197] [client 143.244.57.86:58014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4eEXDvNPGtvLGb7O3qGQAAAOc"]
[Mon Jul 20 07:09:37.047001 2026] [security2:error] [pid 78969:tid 79154] [client 77.110.127.138:64259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEHDvNPGtvLGb7O3p5gAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:37.117543 2026] [security2:error] [pid 78969:tid 79149] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEHDvNPGtvLGb7O3p8gAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:37.125986 2026] [security2:error] [pid 78969:tid 79165] [client 194.61.41.64:51407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/purna.php"] [unique_id "al4eEXDvNPGtvLGb7O3qIgAAAMc"]
[Mon Jul 20 07:09:37.350784 2026] [security2:error] [pid 78969:tid 79139] [client 143.244.57.86:58020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4eEXDvNPGtvLGb7O3qPQAAAK0"]
[Mon Jul 20 07:09:37.385497 2026] [security2:error] [pid 78969:tid 79134] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEHDvNPGtvLGb7O3qDwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:37.416710 2026] [security2:error] [pid 78969:tid 79163] [client 116.179.37.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4eEXDvNPGtvLGb7O3qHwAAAMU"]
[Mon Jul 20 07:09:37.453589 2026] [security2:error] [pid 78969:tid 79143] [client 14.225.17.146:56299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4eD3DvNPGtvLGb7O3phgAAALE"], referer: http://lelandumc.org/2024
[Mon Jul 20 07:09:37.651299 2026] [security2:error] [pid 78969:tid 79192] [client 143.244.57.86:58032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4eEXDvNPGtvLGb7O3qVQAAAOI"]
[Mon Jul 20 07:09:37.694007 2026] [security2:error] [pid 78969:tid 79203] [client 104.234.53.47:65263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eEXDvNPGtvLGb7O3qWAAAAO0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:37.755796 2026] [security2:error] [pid 78969:tid 79133] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEXDvNPGtvLGb7O3qSAAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:37.833457 2026] [security2:error] [pid 78969:tid 79207] [client 194.61.41.67:30599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/interactivity-api/interactivity-api-class.php"] [unique_id "al4eEXDvNPGtvLGb7O3qaQAAAPE"]
[Mon Jul 20 07:09:37.925976 2026] [security2:error] [pid 78969:tid 79206] [client 77.110.127.138:64318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/thread-crochet/sgfqoiwvvwnt.php"] [unique_id "al4eEXDvNPGtvLGb7O3qdwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:37.942324 2026] [security2:error] [pid 78969:tid 79150] [client 143.244.57.86:58046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4eEXDvNPGtvLGb7O3qfQAAALg"]
[Mon Jul 20 07:09:38.236089 2026] [security2:error] [pid 78969:tid 79153] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEXDvNPGtvLGb7O3qfgAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:38.240383 2026] [security2:error] [pid 78969:tid 79215] [client 143.244.57.86:58058] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4eEnDvNPGtvLGb7O3qkQAAAPk"]
[Mon Jul 20 07:09:38.537244 2026] [security2:error] [pid 78969:tid 79223] [client 143.244.57.86:58074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4eEnDvNPGtvLGb7O3qrgAAAQE"]
[Mon Jul 20 07:09:38.635074 2026] [security2:error] [pid 78969:tid 79117] [client 194.61.41.252:56965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/l10n/class-wp-widddget-pages.php"] [unique_id "al4eEnDvNPGtvLGb7O3qtwAAAJc"]
[Mon Jul 20 07:09:38.829518 2026] [security2:error] [pid 78969:tid 79103] [client 20.206.105.145:47374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4eEnDvNPGtvLGb7O3qvwAAAIk"]
[Mon Jul 20 07:09:38.829627 2026] [security2:error] [pid 78969:tid 79103] [client 20.206.105.145:47374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4eEnDvNPGtvLGb7O3qvwAAAIk"]
[Mon Jul 20 07:09:38.838419 2026] [security2:error] [pid 78969:tid 79207] [client 143.244.57.86:58086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4eEnDvNPGtvLGb7O3qwwAAAPE"]
[Mon Jul 20 07:09:38.982397 2026] [security2:error] [pid 78969:tid 79186] [client 104.131.191.63:62343] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.primests.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4eEnDvNPGtvLGb7O3qzwAAANw"]
[Mon Jul 20 07:09:38.998715 2026] [security2:error] [pid 78969:tid 79145] [client 14.225.17.146:55536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEnDvNPGtvLGb7O3qwgAAALM"], referer: http://mezzacraft.com/2024
[Mon Jul 20 07:09:39.142902 2026] [security2:error] [pid 78969:tid 79157] [client 143.244.57.86:58100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4eE3DvNPGtvLGb7O3q7AAAAL8"]
[Mon Jul 20 07:09:39.180039 2026] [security2:error] [pid 78969:tid 79125] [client 77.110.127.138:64322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eEnDvNPGtvLGb7O3q1AAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:39.228871 2026] [security2:error] [pid 78969:tid 79111] [client 117.211.236.168:51226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eE3DvNPGtvLGb7O3q8QAAAJE"]
[Mon Jul 20 07:09:39.229003 2026] [security2:error] [pid 78969:tid 79111] [client 117.211.236.168:51226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eE3DvNPGtvLGb7O3q8QAAAJE"]
[Mon Jul 20 07:09:39.450427 2026] [security2:error] [pid 78969:tid 79145] [client 143.244.57.86:58116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4eE3DvNPGtvLGb7O3q_wAAALM"]
[Mon Jul 20 07:09:39.462313 2026] [security2:error] [pid 78969:tid 79199] [client 194.61.41.242:21023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/tinyfilemanager/tinyfilemanager.php"] [unique_id "al4eE3DvNPGtvLGb7O3rAAAAAOk"]
[Mon Jul 20 07:09:39.758483 2026] [security2:error] [pid 78969:tid 79107] [client 143.244.57.86:58124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4eE3DvNPGtvLGb7O3rGAAAAI0"]
[Mon Jul 20 07:09:39.880025 2026] [security2:error] [pid 78969:tid 79185] [client 77.110.127.138:64324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eE3DvNPGtvLGb7O3rIQAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:39.880111 2026] [security2:error] [pid 78969:tid 79185] [client 77.110.127.138:64324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eE3DvNPGtvLGb7O3rIQAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:39.972717 2026] [security2:error] [pid 78969:tid 79136] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4eE3DvNPGtvLGb7O3q-QAAqmQ"], referer: http://ardhalwafaa.com/2024
[Mon Jul 20 07:09:40.015625 2026] [security2:error] [pid 78969:tid 79117] [client 201.27.111.74:62494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eFHDvNPGtvLGb7O3rLgAAAJc"]
[Mon Jul 20 07:09:40.018634 2026] [security2:error] [pid 78969:tid 79117] [client 201.27.111.74:62494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eFHDvNPGtvLGb7O3rLgAAAJc"]
[Mon Jul 20 07:09:40.052509 2026] [security2:error] [pid 78969:tid 79202] [client 143.244.57.86:58144] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4eFHDvNPGtvLGb7O3rMgAAAOw"]
[Mon Jul 20 07:09:40.135255 2026] [security2:error] [pid 78969:tid 79159] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eE3DvNPGtvLGb7O3rKgAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:40.228223 2026] [security2:error] [pid 78969:tid 79171] [client 194.61.41.73:20535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/light/colors.min.php"] [unique_id "al4eFHDvNPGtvLGb7O3rQAAAAM0"]
[Mon Jul 20 07:09:40.354981 2026] [security2:error] [pid 78969:tid 79205] [client 143.244.57.86:58158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4eFHDvNPGtvLGb7O3rRwAAAO8"]
[Mon Jul 20 07:09:40.654786 2026] [security2:error] [pid 78969:tid 79188] [client 143.244.57.86:58166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.ggb.jiv.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4eFHDvNPGtvLGb7O3rZwAAAN4"]
[Mon Jul 20 07:09:40.736074 2026] [security2:error] [pid 78969:tid 78985] [remote 124.55.178.99:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eFHDvNPGtvLGb7O3raAAAng8"]
[Mon Jul 20 07:09:40.769714 2026] [security2:error] [pid 78969:tid 78983] [remote 74.235.96.117:53940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4eFHDvNPGtvLGb7O3ragAAmg0"]
[Mon Jul 20 07:09:40.918237 2026] [security2:error] [pid 78969:tid 79131] [client 13.233.207.33:31502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eFHDvNPGtvLGb7O3rfgAAAKU"]
[Mon Jul 20 07:09:40.918331 2026] [security2:error] [pid 78969:tid 79131] [client 13.233.207.33:31502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eFHDvNPGtvLGb7O3rfgAAAKU"]
[Mon Jul 20 07:09:40.953089 2026] [security2:error] [pid 78969:tid 79196] [client 194.61.41.252:43141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/class-wp-customize-nav-menu-auto-add-control-repository.php"] [unique_id "al4eFHDvNPGtvLGb7O3rhwAAAOY"]
[Mon Jul 20 07:09:40.965596 2026] [security2:error] [pid 78969:tid 78997] [remote 74.235.96.117:53940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4eFHDvNPGtvLGb7O3riAAAnxs"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:09:41.151468 2026] [security2:error] [pid 78969:tid 79014] [remote 124.55.178.99:59976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eFXDvNPGtvLGb7O3rnQABACw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:09:41.237459 2026] [security2:error] [pid 78969:tid 79173] [client 14.225.17.146:49923] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4eE3DvNPGtvLGb7O3rHAAAAM8"], referer: http://eframiproperties.com/2024
[Mon Jul 20 07:09:41.405942 2026] [security2:error] [pid 78969:tid 79107] [client 14.225.17.146:53760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4eFXDvNPGtvLGb7O3rpgAAAI0"], referer: http://thechancersband.com/2024
[Mon Jul 20 07:09:41.765202 2026] [security2:error] [pid 78969:tid 79211] [client 194.61.41.93:64505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/script-loader-react-refresh-runtime.min-soap.php"] [unique_id "al4eFXDvNPGtvLGb7O3rzAAAAPU"]
[Mon Jul 20 07:09:42.027206 2026] [security2:error] [pid 78969:tid 79208] [client 20.206.105.145:47366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4eFnDvNPGtvLGb7O3r4QAAAPI"]
[Mon Jul 20 07:09:42.027315 2026] [security2:error] [pid 78969:tid 79208] [client 20.206.105.145:47366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4eFnDvNPGtvLGb7O3r4QAAAPI"]
[Mon Jul 20 07:09:42.108634 2026] [security2:error] [pid 78969:tid 79135] [client 104.234.53.72:51801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4eFnDvNPGtvLGb7O3r5wAAAKk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:42.439703 2026] [security2:error] [pid 78969:tid 79164] [client 14.225.17.146:59351] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4eFHDvNPGtvLGb7O3rbwAAAMY"], referer: http://lifeisbetterlakeside.com/2024
[Mon Jul 20 07:09:42.495724 2026] [security2:error] [pid 78969:tid 79226] [client 117.247.108.24:12969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eFnDvNPGtvLGb7O3sDgAAAQQ"]
[Mon Jul 20 07:09:42.495862 2026] [security2:error] [pid 78969:tid 79226] [client 117.247.108.24:12969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eFnDvNPGtvLGb7O3sDgAAAQQ"]
[Mon Jul 20 07:09:42.503860 2026] [security2:error] [pid 78969:tid 79188] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eFnDvNPGtvLGb7O3sAQAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:42.536674 2026] [security2:error] [pid 78969:tid 79099] [client 194.61.41.75:21593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/module.audio-video.riff-set.php"] [unique_id "al4eFnDvNPGtvLGb7O3sEwAAAIU"]
[Mon Jul 20 07:09:42.637452 2026] [autoindex:error] [pid 78969:tid 79048] [remote 34.48.84.195:58147] AH01276: Cannot serve directory /home2/ysslifmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.yss.lif.mybluehost.me
[Mon Jul 20 07:09:42.815399 2026] [security2:error] [pid 78969:tid 79109] [client 14.225.17.146:54113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4eFnDvNPGtvLGb7O3sJwAAAI8"], referer: http://scott-assist.com/2024
[Mon Jul 20 07:09:42.825728 2026] [security2:error] [pid 78969:tid 79202] [client 77.110.127.138:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/amigurumi-crochet-course-surrey/pteot17083c3.php"] [unique_id "al4eFnDvNPGtvLGb7O3sMQAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.067256 2026] [security2:error] [pid 78969:tid 79103] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4eFnDvNPGtvLGb7O3sLgAAAIk"]
[Mon Jul 20 07:09:43.104718 2026] [core:error] [pid 78969:tid 79124] [client 14.225.17.146:56646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2024
[Mon Jul 20 07:09:43.104759 2026] [core:error] [pid 78969:tid 79124] [client 14.225.17.146:56646] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2024
[Mon Jul 20 07:09:43.302120 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3sVwAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.302220 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:64333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3sVwAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.346171 2026] [security2:error] [pid 78969:tid 79218] [client 194.61.41.93:50145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/tinymce/utils/license.php"] [unique_id "al4eF3DvNPGtvLGb7O3sYAAAAPw"]
[Mon Jul 20 07:09:43.382856 2026] [security2:error] [pid 78969:tid 79199] [client 77.110.127.138:64282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3sYgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.382975 2026] [security2:error] [pid 78969:tid 79199] [client 77.110.127.138:64282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3sYgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.437007 2026] [security2:error] [pid 78969:tid 79226] [client 77.110.127.138:64323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3sZwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.437110 2026] [security2:error] [pid 78969:tid 79226] [client 77.110.127.138:64323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3sZwAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.524835 2026] [security2:error] [pid 78969:tid 79176] [client 14.225.17.146:57164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4eF3DvNPGtvLGb7O3sYwAAANI"], referer: http://lutheranphilosopher.com/2024
[Mon Jul 20 07:09:43.592066 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:64339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3scAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.592211 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:64339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eF3DvNPGtvLGb7O3scAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.597117 2026] [security2:error] [pid 78969:tid 79110] [client 77.110.127.138:64334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eF3DvNPGtvLGb7O3sWAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.601260 2026] [security2:error] [pid 78969:tid 79113] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eF3DvNPGtvLGb7O3sXgAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.683049 2026] [security2:error] [pid 78969:tid 79153] [client 14.225.17.146:61801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4eFnDvNPGtvLGb7O3sMgAAALs"], referer: http://nextlevelpressurewashing.com/2024
[Mon Jul 20 07:09:43.844579 2026] [security2:error] [pid 78969:tid 79107] [client 77.110.127.138:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/tabber/czukv1jfq0nl.php"] [unique_id "al4eF3DvNPGtvLGb7O3skgAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:43.901651 2026] [security2:error] [pid 78969:tid 79129] [client 14.225.17.146:61795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4eFnDvNPGtvLGb7O3sLwAAAKM"], referer: http://ravmike.com/2024
[Mon Jul 20 07:09:44.032574 2026] [security2:error] [pid 78969:tid 79138] [client 77.110.127.138:64328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eGHDvNPGtvLGb7O3spgAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.032680 2026] [security2:error] [pid 78969:tid 79138] [client 77.110.127.138:64328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eGHDvNPGtvLGb7O3spgAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.058335 2026] [security2:error] [pid 78969:tid 79170] [client 104.210.140.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4eF3DvNPGtvLGb7O3sngAAAMw"]
[Mon Jul 20 07:09:44.058418 2026] [security2:error] [pid 78969:tid 79163] [client 194.61.41.94:50063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/options.php"] [unique_id "al4eGHDvNPGtvLGb7O3srQAAAMU"]
[Mon Jul 20 07:09:44.218183 2026] [security2:error] [pid 78969:tid 79181] [client 77.110.127.138:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eGHDvNPGtvLGb7O3suwAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.218267 2026] [security2:error] [pid 78969:tid 79181] [client 77.110.127.138:64349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eGHDvNPGtvLGb7O3suwAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.257821 2026] [security2:error] [pid 78969:tid 79194] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eF3DvNPGtvLGb7O3shwAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.457173 2026] [security2:error] [pid 78969:tid 79212] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3srgAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.493181 2026] [security2:error] [pid 78969:tid 79215] [client 77.110.127.138:64345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3spQAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.582410 2026] [security2:error] [pid 78969:tid 79165] [client 88.165.238.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3swwAAxwQ"], referer: https://www.aleishapenny.ca
[Mon Jul 20 07:09:44.656473 2026] [security2:error] [pid 78969:tid 79187] [client 50.116.65.227:45152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eGHDvNPGtvLGb7O3s2gAAAN0"]
[Mon Jul 20 07:09:44.667617 2026] [security2:error] [pid 78969:tid 79149] [client 50.116.65.227:45154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eGHDvNPGtvLGb7O3s3QAAALc"]
[Mon Jul 20 07:09:44.672234 2026] [security2:error] [pid 78969:tid 78981] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eGHDvNPGtvLGb7O3s3wAAvQs"]
[Mon Jul 20 07:09:44.672400 2026] [security2:error] [pid 78969:tid 79155] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eGHDvNPGtvLGb7O3s3wAAvQs"]
[Mon Jul 20 07:09:44.784996 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:64354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/video/xtqirxdjtbk8.php"] [unique_id "al4eGHDvNPGtvLGb7O3s8AAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:44.858308 2026] [security2:error] [pid 78969:tid 79190] [client 194.61.41.83:32561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/wp-load.php"] [unique_id "al4eGHDvNPGtvLGb7O3s_AAAAOA"]
[Mon Jul 20 07:09:44.908780 2026] [security2:error] [pid 78969:tid 79138] [client 14.225.17.146:51630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3s-QAAAKw"], referer: https://ravmike.com/2024
[Mon Jul 20 07:09:45.163770 2026] [security2:error] [pid 78969:tid 79109] [client 14.225.17.146:59417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4eF3DvNPGtvLGb7O3smAAAAI8"]
[Mon Jul 20 07:09:45.176888 2026] [security2:error] [pid 78969:tid 78987] [remote 47.86.33.52:63602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4eGXDvNPGtvLGb7O3tEQAAvxE"]
[Mon Jul 20 07:09:45.224586 2026] [security2:error] [pid 78969:tid 79170] [client 50.116.65.227:45178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tCgAAAMw"]
[Mon Jul 20 07:09:45.291296 2026] [security2:error] [pid 78969:tid 79186] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3s6QAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:45.298491 2026] [security2:error] [pid 78969:tid 79221] [client 187.16.64.216:59473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eGXDvNPGtvLGb7O3tIQAAAP8"]
[Mon Jul 20 07:09:45.298597 2026] [security2:error] [pid 78969:tid 79221] [client 187.16.64.216:59473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eGXDvNPGtvLGb7O3tIQAAAP8"]
[Mon Jul 20 07:09:45.410973 2026] [security2:error] [pid 78969:tid 79126] [client 50.116.65.227:45192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tHAAAAKA"]
[Mon Jul 20 07:09:45.416887 2026] [security2:error] [pid 78969:tid 79180] [client 77.110.127.138:64356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3s8wAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:45.438807 2026] [security2:error] [pid 78969:tid 79198] [client 104.234.53.55:62605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4eGXDvNPGtvLGb7O3tKAAAAOg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:45.461151 2026] [security2:error] [pid 78969:tid 79199] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGHDvNPGtvLGb7O3s_wAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:45.648652 2026] [security2:error] [pid 78969:tid 79120] [client 194.61.41.102:59739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/upgrade/cc.php"] [unique_id "al4eGXDvNPGtvLGb7O3tQwAAAJo"]
[Mon Jul 20 07:09:45.827122 2026] [security2:error] [pid 78969:tid 79013] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eGXDvNPGtvLGb7O3tTwABBCs"]
[Mon Jul 20 07:09:45.827255 2026] [security2:error] [pid 78969:tid 79226] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eGXDvNPGtvLGb7O3tTwABBCs"]
[Mon Jul 20 07:09:45.832511 2026] [security2:error] [pid 78969:tid 79206] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tPAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:45.986894 2026] [security2:error] [pid 78969:tid 79015] [remote 154.0.166.254:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eGXDvNPGtvLGb7O3tbgAA-C0"]
[Mon Jul 20 07:09:46.011019 2026] [security2:error] [pid 78969:tid 79155] [client 77.110.127.138:64359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/amigurumi-owl-crochet-course-farnham/gd2j4jkop4zh.php"] [unique_id "al4eGnDvNPGtvLGb7O3tcAAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:46.170008 2026] [security2:error] [pid 78969:tid 79016] [remote 217.61.143.92:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4eGnDvNPGtvLGb7O3teQAAoS4"]
[Mon Jul 20 07:09:46.193024 2026] [security2:error] [pid 78969:tid 79138] [client 77.110.127.138:64291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tWwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:46.273226 2026] [security2:error] [pid 78969:tid 79200] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tZAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:46.274795 2026] [security2:error] [pid 78969:tid 79158] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tZwAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:46.289233 2026] [security2:error] [pid 78969:tid 79156] [client 20.206.105.145:47383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/x.php"] [unique_id "al4eGnDvNPGtvLGb7O3thQAAAL4"]
[Mon Jul 20 07:09:46.289335 2026] [security2:error] [pid 78969:tid 79156] [client 20.206.105.145:47383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/x.php"] [unique_id "al4eGnDvNPGtvLGb7O3thQAAAL4"]
[Mon Jul 20 07:09:46.416109 2026] [security2:error] [pid 78969:tid 79073] [remote 47.86.33.52:63602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4eGnDvNPGtvLGb7O3tjwAAmWc"], referer: https://thedoctorscuisine.com/wp-login.php
[Mon Jul 20 07:09:46.429838 2026] [security2:error] [pid 78969:tid 79167] [client 194.61.41.57:34465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/aahana/worksec.php"] [unique_id "al4eGnDvNPGtvLGb7O3tkAAAAMk"]
[Mon Jul 20 07:09:46.463397 2026] [security2:error] [pid 78969:tid 79027] [remote 217.61.143.92:52240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4eGnDvNPGtvLGb7O3tlAAAszk"], referer: https://schuttfarms.com/wp-login.php
[Mon Jul 20 07:09:46.476416 2026] [security2:error] [pid 78969:tid 79034] [remote 154.0.166.254:47690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eGnDvNPGtvLGb7O3tlgAAkUA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:09:46.569970 2026] [security2:error] [pid 78969:tid 79217] [client 14.225.17.146:63910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4eGnDvNPGtvLGb7O3tkQAAAPs"], referer: http://aljosour-alarabia.com/2024
[Mon Jul 20 07:09:46.613686 2026] [security2:error] [pid 78969:tid 79195] [client 14.225.17.146:57020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tFAAAAOU"], referer: http://709fx.com/2024
[Mon Jul 20 07:09:46.753540 2026] [security2:error] [pid 78969:tid 79198] [client 14.225.17.146:57206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4eGnDvNPGtvLGb7O3tmwAAAOg"]
[Mon Jul 20 07:09:46.995742 2026] [security2:error] [pid 78969:tid 79201] [client 88.241.67.160:56016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eGnDvNPGtvLGb7O3twQAAAOs"]
[Mon Jul 20 07:09:46.996091 2026] [security2:error] [pid 78969:tid 79201] [client 88.241.67.160:56016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eGnDvNPGtvLGb7O3twQAAAOs"]
[Mon Jul 20 07:09:47.182908 2026] [security2:error] [pid 78969:tid 79172] [client 194.61.41.87:44877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/bltm/wp-login.php"] [unique_id "al4eG3DvNPGtvLGb7O3tzgAAAM4"]
[Mon Jul 20 07:09:47.212970 2026] [security2:error] [pid 78969:tid 79116] [client 77.110.127.138:64351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eG3DvNPGtvLGb7O3t1AAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:47.213053 2026] [security2:error] [pid 78969:tid 79116] [client 77.110.127.138:64351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eG3DvNPGtvLGb7O3t1AAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:47.479732 2026] [security2:error] [pid 78969:tid 79133] [client 103.144.65.217:63340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eG3DvNPGtvLGb7O3t8AAAAKc"]
[Mon Jul 20 07:09:47.479856 2026] [security2:error] [pid 78969:tid 79133] [client 103.144.65.217:63340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eG3DvNPGtvLGb7O3t8AAAAKc"]
[Mon Jul 20 07:09:47.796375 2026] [security2:error] [pid 78969:tid 79191] [client 14.225.17.146:63684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4eG3DvNPGtvLGb7O3t6gAAAOE"], referer: http://securingmemories.com/2024
[Mon Jul 20 07:09:47.943794 2026] [security2:error] [pid 78969:tid 79131] [client 194.61.41.72:61499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/includes/class_api.php"] [unique_id "al4eG3DvNPGtvLGb7O3uEAAAAKU"]
[Mon Jul 20 07:09:48.205170 2026] [security2:error] [pid 78969:tid 79182] [client 57.141.18.24:59784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eGXDvNPGtvLGb7O3tKwAA2Bc"]
[Mon Jul 20 07:09:48.573203 2026] [security2:error] [pid 78969:tid 79161] [client 213.152.186.163:42692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eHHDvNPGtvLGb7O3uUAAAAMM"]
[Mon Jul 20 07:09:48.573294 2026] [security2:error] [pid 78969:tid 79161] [client 213.152.186.163:42692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eHHDvNPGtvLGb7O3uUAAAAMM"]
[Mon Jul 20 07:09:48.683761 2026] [security2:error] [pid 78969:tid 79168] [client 104.234.53.64:47363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4eHHDvNPGtvLGb7O3uVwAAAMo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:48.727128 2026] [security2:error] [pid 78969:tid 79103] [client 194.61.41.87:57383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/plugins/content/apismtp/apismtp.php"] [unique_id "al4eHHDvNPGtvLGb7O3uWgAAAIk"]
[Mon Jul 20 07:09:48.780332 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eHHDvNPGtvLGb7O3uUQAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:48.982741 2026] [security2:error] [pid 78969:tid 79115] [client 13.232.231.177:25056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eHHDvNPGtvLGb7O3udAAAAJU"]
[Mon Jul 20 07:09:48.982859 2026] [security2:error] [pid 78969:tid 79115] [client 13.232.231.177:25056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eHHDvNPGtvLGb7O3udAAAAJU"]
[Mon Jul 20 07:09:49.350632 2026] [security2:error] [pid 78969:tid 79148] [client 104.234.53.85:35779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4eHXDvNPGtvLGb7O3uhQAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:09:49.526931 2026] [security2:error] [pid 78969:tid 79224] [client 194.61.41.95:34837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/includes/class-core-upgrader-first.php"] [unique_id "al4eHXDvNPGtvLGb7O3uoAAAAQI"]
[Mon Jul 20 07:09:49.616582 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:64316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eHXDvNPGtvLGb7O3uqAAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:49.616677 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:64316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eHXDvNPGtvLGb7O3uqAAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:49.779774 2026] [security2:error] [pid 78969:tid 78983] [remote 20.153.140.50:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4eHXDvNPGtvLGb7O3usAAA_A0"]
[Mon Jul 20 07:09:49.836722 2026] [security2:error] [pid 78969:tid 79201] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "janayanarvaez.com"] [uri "/.well-known/about.php"] [unique_id "al4eHXDvNPGtvLGb7O3uuQAAAOs"]
[Mon Jul 20 07:09:49.836932 2026] [security2:error] [pid 78969:tid 79201] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "janayanarvaez.com"] [uri "/.well-known/about.php"] [unique_id "al4eHXDvNPGtvLGb7O3uuQAAAOs"]
[Mon Jul 20 07:09:50.172505 2026] [security2:error] [pid 78969:tid 78997] [remote 20.153.140.50:53096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4eHnDvNPGtvLGb7O3uzwAA2Bs"], referer: https://fbvrealtors.com/wp-login.php
[Mon Jul 20 07:09:50.254946 2026] [security2:error] [pid 78969:tid 79120] [client 194.61.41.106:65437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/wp-css.php"] [unique_id "al4eHnDvNPGtvLGb7O3u0wAAAJo"]
[Mon Jul 20 07:09:50.349144 2026] [security2:error] [pid 78969:tid 79122] [client 201.27.111.74:62989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eHnDvNPGtvLGb7O3u2QAAAJw"]
[Mon Jul 20 07:09:50.349308 2026] [security2:error] [pid 78969:tid 79122] [client 201.27.111.74:62989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eHnDvNPGtvLGb7O3u2QAAAJw"]
[Mon Jul 20 07:09:50.618654 2026] [security2:error] [pid 78969:tid 79012] [remote 173.249.4.11:22879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eHnDvNPGtvLGb7O3u9AAAzCo"]
[Mon Jul 20 07:09:50.618789 2026] [security2:error] [pid 78969:tid 79170] [client 173.249.4.11:22879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eHnDvNPGtvLGb7O3u9AAAzCo"]
[Mon Jul 20 07:09:51.018584 2026] [security2:error] [pid 78969:tid 79196] [client 194.61.41.81:57985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/goto.php"] [unique_id "al4eH3DvNPGtvLGb7O3vFQAAAOY"]
[Mon Jul 20 07:09:51.759159 2026] [security2:error] [pid 78969:tid 79182] [client 194.61.41.243:39735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/xboom.php"] [unique_id "al4eH3DvNPGtvLGb7O3vQgAAANg"]
[Mon Jul 20 07:09:51.923277 2026] [security2:error] [pid 78969:tid 79138] [client 143.198.28.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4eH3DvNPGtvLGb7O3vSwAAAKw"], referer: http://elevator-data.com/
[Mon Jul 20 07:09:52.215208 2026] [security2:error] [pid 78969:tid 79124] [client 77.110.127.138:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eIHDvNPGtvLGb7O3vcQAAAJ4"], referer: https://mezzacraft.com/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/
[Mon Jul 20 07:09:52.431229 2026] [security2:error] [pid 78969:tid 79174] [client 117.211.236.168:51858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eIHDvNPGtvLGb7O3vfgAAANA"]
[Mon Jul 20 07:09:52.431317 2026] [security2:error] [pid 78969:tid 79174] [client 117.211.236.168:51858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eIHDvNPGtvLGb7O3vfgAAANA"]
[Mon Jul 20 07:09:52.541173 2026] [security2:error] [pid 78969:tid 79220] [client 194.61.41.243:56097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/kadence/functions.php"] [unique_id "al4eIHDvNPGtvLGb7O3vjwAAAP4"]
[Mon Jul 20 07:09:52.744254 2026] [security2:error] [pid 78969:tid 79158] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eIHDvNPGtvLGb7O3vjQAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:52.988180 2026] [security2:error] [pid 78969:tid 79156] [client 117.247.108.24:23674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eIHDvNPGtvLGb7O3vvwAAAL4"]
[Mon Jul 20 07:09:52.988300 2026] [security2:error] [pid 78969:tid 79156] [client 117.247.108.24:23674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eIHDvNPGtvLGb7O3vvwAAAL4"]
[Mon Jul 20 07:09:53.223579 2026] [security2:error] [pid 78969:tid 79140] [client 57.141.18.39:63327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eHnDvNPGtvLGb7O3vCAAArnI"]
[Mon Jul 20 07:09:53.253533 2026] [security2:error] [pid 78969:tid 79108] [client 77.110.127.138:64402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eIXDvNPGtvLGb7O3v1wAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:53.253645 2026] [security2:error] [pid 78969:tid 79108] [client 77.110.127.138:64402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eIXDvNPGtvLGb7O3v1wAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:53.344911 2026] [security2:error] [pid 78969:tid 79104] [client 194.61.41.243:25405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/Sanskrit.php"] [unique_id "al4eIXDvNPGtvLGb7O3v4QAAAIo"]
[Mon Jul 20 07:09:53.479447 2026] [security2:error] [pid 78969:tid 79181] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eIXDvNPGtvLGb7O3v2AAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:53.637863 2026] [security2:error] [pid 78969:tid 78975] [remote 20.153.140.50:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4eIXDvNPGtvLGb7O3v7wAA9QU"]
[Mon Jul 20 07:09:54.058073 2026] [security2:error] [pid 78969:tid 78978] [remote 20.153.140.50:53098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4eInDvNPGtvLGb7O3wEgAAnAg"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:09:54.141939 2026] [security2:error] [pid 78969:tid 79137] [client 194.61.41.91:48243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-fmfile.php"] [unique_id "al4eInDvNPGtvLGb7O3wGgAAAKs"]
[Mon Jul 20 07:09:54.256769 2026] [security2:error] [pid 78969:tid 79102] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eInDvNPGtvLGb7O3wEAAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:54.365443 2026] [security2:error] [pid 78969:tid 79131] [client 151.243.11.245:53014] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4eInDvNPGtvLGb7O3wKAAAAKU"]
[Mon Jul 20 07:09:54.587800 2026] [security2:error] [pid 78969:tid 79182] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eInDvNPGtvLGb7O3wLgAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:54.860231 2026] [security2:error] [pid 78969:tid 79013] [remote 188.166.241.141:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eInDvNPGtvLGb7O3wVgAA4ys"]
[Mon Jul 20 07:09:54.944906 2026] [security2:error] [pid 78969:tid 79212] [client 194.61.41.247:27913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.trash7309/index.php"] [unique_id "al4eInDvNPGtvLGb7O3wWgAAAPY"]
[Mon Jul 20 07:09:54.949191 2026] [security2:error] [pid 78969:tid 79009] [remote 188.166.241.141:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eInDvNPGtvLGb7O3wWwAAsCc"]
[Mon Jul 20 07:09:55.019448 2026] [security2:error] [pid 78969:tid 79183] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eInDvNPGtvLGb7O3wUgAAANk"]
[Mon Jul 20 07:09:55.236449 2026] [security2:error] [pid 78969:tid 79051] [remote 188.166.241.141:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eI3DvNPGtvLGb7O3wbQABAlE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:09:55.361915 2026] [security2:error] [pid 78969:tid 79001] [remote 188.166.241.141:49458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eI3DvNPGtvLGb7O3wdgAAyx8"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 07:09:55.409865 2026] [security2:error] [pid 78969:tid 79005] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eI3DvNPGtvLGb7O3weAAAkyM"]
[Mon Jul 20 07:09:55.410076 2026] [security2:error] [pid 78969:tid 79113] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eI3DvNPGtvLGb7O3weAAAkyM"]
[Mon Jul 20 07:09:55.476499 2026] [security2:error] [pid 78969:tid 79187] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eI3DvNPGtvLGb7O3wcQAAAN0"]
[Mon Jul 20 07:09:55.739835 2026] [security2:error] [pid 78969:tid 79218] [client 194.61.41.94:46181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/revslider/includes/external/page/index.php"] [unique_id "al4eI3DvNPGtvLGb7O3wmgAAAPw"]
[Mon Jul 20 07:09:55.801759 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eI3DvNPGtvLGb7O3wjQAAAM4"], referer: 1'"3000
[Mon Jul 20 07:09:55.867790 2026] [security2:error] [pid 78969:tid 79212] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eI3DvNPGtvLGb7O3wkwAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:55.914084 2026] [security2:error] [pid 78969:tid 79126] [client 57.141.18.48:51804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eIXDvNPGtvLGb7O3v6QAAoAA"]
[Mon Jul 20 07:09:55.941589 2026] [security2:error] [pid 78969:tid 79104] [client 187.16.64.216:60042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eI3DvNPGtvLGb7O3wpQAAAIo"]
[Mon Jul 20 07:09:55.941709 2026] [security2:error] [pid 78969:tid 79104] [client 187.16.64.216:60042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eI3DvNPGtvLGb7O3wpQAAAIo"]
[Mon Jul 20 07:09:55.959961 2026] [security2:error] [pid 78969:tid 79023] [remote 173.249.4.11:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4eI3DvNPGtvLGb7O3wqQAAzDU"]
[Mon Jul 20 07:09:56.080525 2026] [security2:error] [pid 78969:tid 79103] [client 77.110.127.138:64413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eJHDvNPGtvLGb7O3wtAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:56.080616 2026] [security2:error] [pid 78969:tid 79103] [client 77.110.127.138:64413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eJHDvNPGtvLGb7O3wtAAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:56.134003 2026] [security2:error] [pid 78969:tid 79043] [remote 173.249.4.11:56725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4eJHDvNPGtvLGb7O3wtwAA8Uk"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 07:09:56.210127 2026] [security2:error] [pid 78969:tid 79109] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eJHDvNPGtvLGb7O3wrwAAAI8"], referer: 1'"3000
[Mon Jul 20 07:09:56.257039 2026] [security2:error] [pid 78969:tid 79216] [client 14.225.17.146:64809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4eI3DvNPGtvLGb7O3wpwAAAPo"]
[Mon Jul 20 07:09:56.385337 2026] [security2:error] [pid 78969:tid 79129] [client 13.233.207.33:15676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eJHDvNPGtvLGb7O3w0gAAAKM"]
[Mon Jul 20 07:09:56.512770 2026] [security2:error] [pid 78969:tid 79055] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eJHDvNPGtvLGb7O3w4AAA1FU"]
[Mon Jul 20 07:09:56.512913 2026] [security2:error] [pid 78969:tid 79178] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eJHDvNPGtvLGb7O3w4AAA1FU"]
[Mon Jul 20 07:09:56.550608 2026] [security2:error] [pid 78969:tid 79169] [client 194.61.41.63:64907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ioxi/ioxi/dropdown.php"] [unique_id "al4eJHDvNPGtvLGb7O3w4gAAAMs"]
[Mon Jul 20 07:09:57.070567 2026] [security2:error] [pid 78969:tid 79211] [client 20.206.105.145:47186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/j260624_13.php"] [unique_id "al4eJXDvNPGtvLGb7O3xCwAAAPU"]
[Mon Jul 20 07:09:57.070669 2026] [security2:error] [pid 78969:tid 79211] [client 20.206.105.145:47186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/j260624_13.php"] [unique_id "al4eJXDvNPGtvLGb7O3xCwAAAPU"]
[Mon Jul 20 07:09:57.087063 2026] [security2:error] [pid 78969:tid 79182] [client 14.225.17.146:64805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4eJHDvNPGtvLGb7O3wvQAAANg"], referer: http://oldracelimited.com/2024
[Mon Jul 20 07:09:57.151607 2026] [security2:error] [pid 78969:tid 79104] [client 50.116.65.227:17050] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eJXDvNPGtvLGb7O3xDwAAAIo"]
[Mon Jul 20 07:09:57.160925 2026] [security2:error] [pid 78969:tid 79170] [client 50.116.65.227:17054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eJXDvNPGtvLGb7O3xEgAAAMw"]
[Mon Jul 20 07:09:57.321222 2026] [security2:error] [pid 78969:tid 79203] [client 194.61.41.70:44371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/memberfuns.php"] [unique_id "al4eJXDvNPGtvLGb7O3xIQAAAO0"]
[Mon Jul 20 07:09:57.409037 2026] [security2:error] [pid 78969:tid 79162] [client 50.116.65.227:17056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4eJXDvNPGtvLGb7O3xFwAAAMQ"]
[Mon Jul 20 07:09:57.434483 2026] [security2:error] [pid 78969:tid 79206] [client 13.233.207.33:15680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eJXDvNPGtvLGb7O3xKQAAAPA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:09:57.479689 2026] [security2:error] [pid 78969:tid 79120] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eJXDvNPGtvLGb7O3xGwAAAJo"], referer: 1'"3000
[Mon Jul 20 07:09:57.523914 2026] [security2:error] [pid 78969:tid 79202] [client 47.82.10.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4eJXDvNPGtvLGb7O3xJQAAAOw"]
[Mon Jul 20 07:09:57.581586 2026] [security2:error] [pid 78969:tid 79225] [client 50.116.65.227:17062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4eJXDvNPGtvLGb7O3xKAAAAQM"]
[Mon Jul 20 07:09:57.593166 2026] [security2:error] [pid 78969:tid 79223] [client 88.241.67.160:54663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eJXDvNPGtvLGb7O3xMwAAAQE"]
[Mon Jul 20 07:09:57.593462 2026] [security2:error] [pid 78969:tid 79223] [client 88.241.67.160:54663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eJXDvNPGtvLGb7O3xMwAAAQE"]
[Mon Jul 20 07:09:57.915046 2026] [security2:error] [pid 78969:tid 79201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eJXDvNPGtvLGb7O3xPwAAAOs"], referer: 1'"3000
[Mon Jul 20 07:09:58.024831 2026] [security2:error] [pid 78969:tid 79138] [client 103.144.65.217:63802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eJnDvNPGtvLGb7O3xZgAAAKw"]
[Mon Jul 20 07:09:58.024985 2026] [security2:error] [pid 78969:tid 79138] [client 103.144.65.217:63802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eJnDvNPGtvLGb7O3xZgAAAKw"]
[Mon Jul 20 07:09:58.041376 2026] [security2:error] [pid 78969:tid 79220] [client 194.61.41.94:28827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/infos.php"] [unique_id "al4eJnDvNPGtvLGb7O3xaAAAAP4"]
[Mon Jul 20 07:09:58.404124 2026] [security2:error] [pid 78969:tid 79144] [client 57.141.18.69:24334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eJHDvNPGtvLGb7O3w1AAAskw"]
[Mon Jul 20 07:09:58.476442 2026] [security2:error] [pid 78969:tid 79178] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eJnDvNPGtvLGb7O3xggAAANQ"]
[Mon Jul 20 07:09:58.678734 2026] [security2:error] [pid 78969:tid 79226] [client 77.110.127.138:64409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eJnDvNPGtvLGb7O3xoQAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:58.678884 2026] [security2:error] [pid 78969:tid 79226] [client 77.110.127.138:64409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eJnDvNPGtvLGb7O3xoQAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:58.736257 2026] [security2:error] [pid 78969:tid 79180] [client 14.225.17.146:65093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4eJHDvNPGtvLGb7O3w8gAAANY"], referer: http://narv.co/2024
[Mon Jul 20 07:09:58.825502 2026] [security2:error] [pid 78969:tid 79104] [client 194.61.41.245:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/modules/file.php"] [unique_id "al4eJnDvNPGtvLGb7O3xpQAAAIo"]
[Mon Jul 20 07:09:58.826851 2026] [security2:error] [pid 78969:tid 79136] [client 45.157.112.60:48191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eJnDvNPGtvLGb7O3xpgAAAKo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:09:58.893059 2026] [security2:error] [pid 78969:tid 79205] [client 13.233.207.33:15692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eJnDvNPGtvLGb7O3xrAAAAO8"]
[Mon Jul 20 07:09:59.193963 2026] [security2:error] [pid 78969:tid 79186] [client 57.141.18.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3xxAAAANw"]
[Mon Jul 20 07:09:59.329903 2026] [security2:error] [pid 78969:tid 79169] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3xygAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:59.548125 2026] [security2:error] [pid 78969:tid 79108] [client 194.61.41.81:35829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/x.php"] [unique_id "al4eJ3DvNPGtvLGb7O3x8gAAAI4"]
[Mon Jul 20 07:09:59.809694 2026] [security2:error] [pid 78969:tid 79158] [client 14.225.17.146:54518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3x_AAAAMA"], referer: https://narv.co/2024
[Mon Jul 20 07:09:59.868242 2026] [security2:error] [pid 78969:tid 79106] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3x_QAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:09:59.898003 2026] [security2:error] [pid 78969:tid 79105] [client 13.232.231.177:14354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eJ3DvNPGtvLGb7O3yEgAAAIs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:09:59.953742 2026] [security2:error] [pid 78969:tid 79223] [client 14.225.17.146:54630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3yEAAAAQE"], referer: http://nextlvlmarketingco.com/2024
[Mon Jul 20 07:10:00.067022 2026] [security2:error] [pid 78969:tid 79119] [client 14.225.17.146:54610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3yDgAAAJk"], referer: http://secretkeynumerology.com/2024
[Mon Jul 20 07:10:00.160060 2026] [security2:error] [pid 78969:tid 79164] [client 20.206.105.145:47408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/d62.php"] [unique_id "al4eKHDvNPGtvLGb7O3yLQAAAMY"]
[Mon Jul 20 07:10:00.160212 2026] [security2:error] [pid 78969:tid 79164] [client 20.206.105.145:47408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/d62.php"] [unique_id "al4eKHDvNPGtvLGb7O3yLQAAAMY"]
[Mon Jul 20 07:10:00.330596 2026] [security2:error] [pid 78969:tid 79132] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eKHDvNPGtvLGb7O3yKwAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:00.342086 2026] [security2:error] [pid 78969:tid 79174] [client 194.61.41.74:53125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/wp.php"] [unique_id "al4eKHDvNPGtvLGb7O3yMwAAANA"]
[Mon Jul 20 07:10:00.822939 2026] [security2:error] [pid 78969:tid 79122] [client 201.27.111.74:63475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eKHDvNPGtvLGb7O3yUgAAAJw"]
[Mon Jul 20 07:10:00.823048 2026] [security2:error] [pid 78969:tid 79122] [client 201.27.111.74:63475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eKHDvNPGtvLGb7O3yUgAAAJw"]
[Mon Jul 20 07:10:00.953694 2026] [security2:error] [pid 78969:tid 79040] [remote 81.173.115.7:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4eKHDvNPGtvLGb7O3yYQAA40Y"]
[Mon Jul 20 07:10:01.135702 2026] [security2:error] [pid 78969:tid 79224] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eKHDvNPGtvLGb7O3yXgAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:01.154973 2026] [security2:error] [pid 78969:tid 79102] [client 194.61.41.241:41801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/options-writing.php"] [unique_id "al4eKXDvNPGtvLGb7O3ydgAAAIg"]
[Mon Jul 20 07:10:01.218463 2026] [security2:error] [pid 78969:tid 79069] [remote 8.217.108.67:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eKXDvNPGtvLGb7O3ygAAAlmM"]
[Mon Jul 20 07:10:01.523118 2026] [security2:error] [pid 78969:tid 79068] [remote 47.86.33.52:27738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4eKXDvNPGtvLGb7O3ymAAAx2I"]
[Mon Jul 20 07:10:01.743733 2026] [security2:error] [pid 78969:tid 79216] [client 57.141.18.117:25024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eJ3DvNPGtvLGb7O3yGAAA-jk"]
[Mon Jul 20 07:10:01.858842 2026] [security2:error] [pid 78969:tid 79196] [client 151.243.11.245:53034] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4eKXDvNPGtvLGb7O3yrgAAAOY"]
[Mon Jul 20 07:10:01.875107 2026] [security2:error] [pid 78969:tid 79149] [client 117.211.236.168:52337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eKXDvNPGtvLGb7O3ysgAAALc"]
[Mon Jul 20 07:10:01.875202 2026] [security2:error] [pid 78969:tid 79149] [client 117.211.236.168:52337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eKXDvNPGtvLGb7O3ysgAAALc"]
[Mon Jul 20 07:10:01.882319 2026] [security2:error] [pid 78969:tid 79058] [remote 91.142.222.105:37214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4eKXDvNPGtvLGb7O3ysQAAwVg"]
[Mon Jul 20 07:10:01.917336 2026] [security2:error] [pid 78969:tid 79071] [remote 47.86.33.52:27738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4eKXDvNPGtvLGb7O3ytgAA22U"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:10:01.918633 2026] [security2:error] [pid 78969:tid 79219] [client 14.225.17.146:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4eKHDvNPGtvLGb7O3yOwAAAP0"], referer: http://alchemygroup.ca/2024
[Mon Jul 20 07:10:01.930435 2026] [security2:error] [pid 78969:tid 79173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eKXDvNPGtvLGb7O3ypQAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:02.128785 2026] [security2:error] [pid 78969:tid 79085] [remote 91.142.222.105:37214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4eKnDvNPGtvLGb7O3yzAAAxHM"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 07:10:02.183654 2026] [security2:error] [pid 78969:tid 79181] [client 194.61.41.82:63899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/options-reading.php"] [unique_id "al4eKnDvNPGtvLGb7O3yzwAAANc"]
[Mon Jul 20 07:10:02.314426 2026] [security2:error] [pid 78969:tid 79168] [client 14.225.17.146:53897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4eKXDvNPGtvLGb7O3ycAAAAMo"], referer: http://mazzucelli.com/2024
[Mon Jul 20 07:10:02.394264 2026] [security2:error] [pid 78969:tid 79189] [client 14.225.17.146:53968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4eKnDvNPGtvLGb7O3y1wAAAN8"], referer: http://christiancountytrumpet.com/2024
[Mon Jul 20 07:10:02.396808 2026] [security2:error] [pid 78969:tid 79190] [client 77.110.127.138:64445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eKnDvNPGtvLGb7O3y5gAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:02.396902 2026] [security2:error] [pid 78969:tid 79190] [client 77.110.127.138:64445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eKnDvNPGtvLGb7O3y5gAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:02.421453 2026] [security2:error] [pid 78969:tid 79093] [remote 8.217.108.67:61202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eKnDvNPGtvLGb7O3y6QAAy3s"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:10:02.508488 2026] [security2:error] [pid 78969:tid 79110] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eKnDvNPGtvLGb7O3y2wAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:02.747703 2026] [security2:error] [pid 78969:tid 79223] [client 14.225.17.146:53430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4eKXDvNPGtvLGb7O3ykQAAAQE"], referer: http://alaraycreative.com/2024
[Mon Jul 20 07:10:02.869271 2026] [security2:error] [pid 78969:tid 79155] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eKnDvNPGtvLGb7O3zAwAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:03.109712 2026] [security2:error] [pid 78969:tid 79221] [client 194.61.41.102:21781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wsad.php"] [unique_id "al4eK3DvNPGtvLGb7O3zJwAAAP8"]
[Mon Jul 20 07:10:03.208287 2026] [security2:error] [pid 78969:tid 78983] [remote 57.141.18.62:34390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3656248"] [unique_id "al4eK3DvNPGtvLGb7O3zMgAA2Q0"]
[Mon Jul 20 07:10:03.211838 2026] [security2:error] [pid 78969:tid 79219] [client 20.206.105.145:47405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/ups.php"] [unique_id "al4eK3DvNPGtvLGb7O3zMwAAAP0"]
[Mon Jul 20 07:10:03.211934 2026] [security2:error] [pid 78969:tid 79219] [client 20.206.105.145:47405] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/ups.php"] [unique_id "al4eK3DvNPGtvLGb7O3zMwAAAP0"]
[Mon Jul 20 07:10:03.440374 2026] [security2:error] [pid 78969:tid 79210] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eK3DvNPGtvLGb7O3zNAAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:03.707439 2026] [security2:error] [pid 78969:tid 79115] [client 117.247.108.24:23944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eK3DvNPGtvLGb7O3zYwAAAJU"]
[Mon Jul 20 07:10:03.707608 2026] [security2:error] [pid 78969:tid 79115] [client 117.247.108.24:23944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eK3DvNPGtvLGb7O3zYwAAAJU"]
[Mon Jul 20 07:10:03.990679 2026] [security2:error] [pid 78969:tid 79141] [client 194.61.41.73:38759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/nation.php"] [unique_id "al4eK3DvNPGtvLGb7O3zgQAAAK8"]
[Mon Jul 20 07:10:04.296957 2026] [security2:error] [pid 78969:tid 79130] [client 57.141.18.94:33056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eKnDvNPGtvLGb7O3y3gAApB4"]
[Mon Jul 20 07:10:04.426755 2026] [security2:error] [pid 78969:tid 79144] [client 196.61.240.62:55832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4eLHDvNPGtvLGb7O3zlAAAALI"]
[Mon Jul 20 07:10:04.439783 2026] [security2:error] [pid 78969:tid 79070] [remote 81.173.115.7:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4eLHDvNPGtvLGb7O3zqgAAxWQ"], referer: https://cathybuffini.com/wp-login.php
[Mon Jul 20 07:10:04.724310 2026] [security2:error] [pid 78969:tid 79225] [client 194.61.41.62:46677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/codemirror/index.php"] [unique_id "al4eLHDvNPGtvLGb7O3zxAAAAQM"]
[Mon Jul 20 07:10:04.829100 2026] [security2:error] [pid 78969:tid 79195] [client 14.225.17.146:55880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eLHDvNPGtvLGb7O3zuwAAAOU"]
[Mon Jul 20 07:10:04.829636 2026] [security2:error] [pid 78969:tid 79201] [client 158.173.89.95:25107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eLHDvNPGtvLGb7O3z0AAAAOs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:05.312522 2026] [security2:error] [pid 78969:tid 79207] [client 104.234.53.58:27685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eLXDvNPGtvLGb7O3z-QAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:05.437855 2026] [security2:error] [pid 78969:tid 79117] [client 194.61.41.61:52913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/wp_class_datlib.php"] [unique_id "al4eLXDvNPGtvLGb7O30AgAAAJc"]
[Mon Jul 20 07:10:05.545389 2026] [security2:error] [pid 78969:tid 79132] [client 14.225.17.146:56805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4eLXDvNPGtvLGb7O3z_wAAAKY"], referer: http://laceycaraccident.com/2024
[Mon Jul 20 07:10:05.687722 2026] [security2:error] [pid 78969:tid 79147] [client 158.173.166.181:39659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eLXDvNPGtvLGb7O30DwAAALU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:05.791885 2026] [security2:error] [pid 78969:tid 79155] [client 20.206.105.145:47389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/k.php"] [unique_id "al4eLXDvNPGtvLGb7O30GAAAAL0"]
[Mon Jul 20 07:10:05.791970 2026] [security2:error] [pid 78969:tid 79155] [client 20.206.105.145:47389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "hedgerow-crafts.com"] [uri "/k.php"] [unique_id "al4eLXDvNPGtvLGb7O30GAAAAL0"]
[Mon Jul 20 07:10:05.843473 2026] [security2:error] [pid 78969:tid 79163] [client 77.110.127.138:64461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eLXDvNPGtvLGb7O30GQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:05.843591 2026] [security2:error] [pid 78969:tid 79163] [client 77.110.127.138:64461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eLXDvNPGtvLGb7O30GQAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:06.085966 2026] [security2:error] [pid 78969:tid 79079] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eLnDvNPGtvLGb7O30LAAA120"]
[Mon Jul 20 07:10:06.086133 2026] [security2:error] [pid 78969:tid 79181] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eLnDvNPGtvLGb7O30LAAA120"]
[Mon Jul 20 07:10:06.219560 2026] [security2:error] [pid 78969:tid 79226] [client 194.61.41.78:56713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/tinymce/langs/about.php"] [unique_id "al4eLnDvNPGtvLGb7O30PQAAAQQ"]
[Mon Jul 20 07:10:06.677959 2026] [security2:error] [pid 78969:tid 79119] [client 187.16.64.216:60630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eLnDvNPGtvLGb7O30XQAAAJk"]
[Mon Jul 20 07:10:06.678059 2026] [security2:error] [pid 78969:tid 79119] [client 187.16.64.216:60630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eLnDvNPGtvLGb7O30XQAAAJk"]
[Mon Jul 20 07:10:06.954358 2026] [security2:error] [pid 78969:tid 79093] [remote 182.77.62.24:36448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4eLnDvNPGtvLGb7O30fAAA53s"]
[Mon Jul 20 07:10:06.958849 2026] [security2:error] [pid 78969:tid 79182] [client 194.61.41.88:38923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/autoload_classmap/wso.php"] [unique_id "al4eLnDvNPGtvLGb7O30fgAAANg"]
[Mon Jul 20 07:10:07.025586 2026] [core:error] [pid 78969:tid 79185] [client 14.225.17.146:55891] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2024
[Mon Jul 20 07:10:07.025615 2026] [core:error] [pid 78969:tid 79185] [client 14.225.17.146:55891] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2024
[Mon Jul 20 07:10:07.076364 2026] [security2:error] [pid 78969:tid 79171] [client 77.110.127.138:64466] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/3/"] [unique_id "al4eL3DvNPGtvLGb7O30hQAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:07.114000 2026] [security2:error] [pid 78969:tid 78984] [remote 154.61.75.100:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eL3DvNPGtvLGb7O30hgAA-w4"]
[Mon Jul 20 07:10:07.179355 2026] [security2:error] [pid 78969:tid 78975] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eL3DvNPGtvLGb7O30igAA0AU"]
[Mon Jul 20 07:10:07.179517 2026] [security2:error] [pid 78969:tid 79174] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eL3DvNPGtvLGb7O30igAA0AU"]
[Mon Jul 20 07:10:07.459690 2026] [security2:error] [pid 78969:tid 78978] [remote 182.77.62.24:36448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4eL3DvNPGtvLGb7O30nQAAjQg"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 07:10:07.603041 2026] [security2:error] [pid 78969:tid 79139] [client 104.234.53.84:52599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4eL3DvNPGtvLGb7O30qgAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:07.659192 2026] [security2:error] [pid 78969:tid 78976] [remote 154.61.75.100:54512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eL3DvNPGtvLGb7O30rQAA6QY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:10:07.733221 2026] [security2:error] [pid 78969:tid 79202] [client 194.61.41.242:46501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-atomx.php"] [unique_id "al4eL3DvNPGtvLGb7O30tAAAAOw"]
[Mon Jul 20 07:10:07.981820 2026] [security2:error] [pid 78969:tid 79137] [client 57.141.18.42:50438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eLXDvNPGtvLGb7O30IwAAq10"]
[Mon Jul 20 07:10:08.056527 2026] [security2:error] [pid 78969:tid 79170] [client 114.119.153.49:26483] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/resource/developing-dimension-state-voluntary-carbon-markets-2012"] [unique_id "al4eMHDvNPGtvLGb7O30zAAAAMw"], referer: http://www.lowemissionsasia.org/resources?qt-resources=1
[Mon Jul 20 07:10:08.194034 2026] [security2:error] [pid 78969:tid 79201] [client 88.241.67.160:53473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O30zwAAAOs"]
[Mon Jul 20 07:10:08.194172 2026] [security2:error] [pid 78969:tid 79201] [client 88.241.67.160:53473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O30zwAAAOs"]
[Mon Jul 20 07:10:08.406193 2026] [security2:error] [pid 78969:tid 79156] [client 3.90.176.61:36490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.176.90.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O302QAAAL4"]
[Mon Jul 20 07:10:08.406296 2026] [security2:error] [pid 78969:tid 79156] [client 3.90.176.61:36490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O302QAAAL4"]
[Mon Jul 20 07:10:08.448825 2026] [security2:error] [pid 78969:tid 79199] [client 194.61.41.242:25603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin-footer.php"] [unique_id "al4eMHDvNPGtvLGb7O304wAAAOk"]
[Mon Jul 20 07:10:08.576320 2026] [security2:error] [pid 78969:tid 79150] [client 103.144.65.217:64260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O309AAAALg"]
[Mon Jul 20 07:10:08.576437 2026] [security2:error] [pid 78969:tid 79150] [client 103.144.65.217:64260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O309AAAALg"]
[Mon Jul 20 07:10:08.797940 2026] [security2:error] [pid 78969:tid 79000] [remote 20.153.140.50:40970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O31BwAAsh4"]
[Mon Jul 20 07:10:08.798153 2026] [security2:error] [pid 78969:tid 79144] [client 20.153.140.50:40970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eMHDvNPGtvLGb7O31BwAAsh4"]
[Mon Jul 20 07:10:09.241616 2026] [security2:error] [pid 78969:tid 79140] [client 194.61.41.67:35795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/wp-conflg.php"] [unique_id "al4eMXDvNPGtvLGb7O31MgAAAK4"]
[Mon Jul 20 07:10:09.838836 2026] [security2:error] [pid 78969:tid 79040] [remote 20.153.140.50:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4eMXDvNPGtvLGb7O31WAAAnUY"]
[Mon Jul 20 07:10:09.889236 2026] [security2:error] [pid 78969:tid 79167] [client 50.116.65.227:36076] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eMXDvNPGtvLGb7O31XAAAAMk"]
[Mon Jul 20 07:10:09.900902 2026] [security2:error] [pid 78969:tid 79146] [client 50.116.65.227:36078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eMXDvNPGtvLGb7O31XQAAALQ"]
[Mon Jul 20 07:10:09.958856 2026] [qos:error] [pid 78969:tid 79149] [client 138.0.244.246:40472] mod_qos(045): access denied, invalid request line: can't parse uri, c=138.0.244.246, id=al4eMXDvNPGtvLGb7O31ZgAAALc
[Mon Jul 20 07:10:10.040512 2026] [security2:error] [pid 78969:tid 79198] [client 14.225.17.146:63642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4eMHDvNPGtvLGb7O305AAAAOg"], referer: http://nurturemarple.co.uk/2024
[Mon Jul 20 07:10:10.050898 2026] [security2:error] [pid 78969:tid 79180] [client 194.61.41.63:44751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/XxX.php"] [unique_id "al4eMnDvNPGtvLGb7O31dwAAANY"]
[Mon Jul 20 07:10:10.056420 2026] [security2:error] [pid 78969:tid 79100] [client 104.234.53.94:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4eMnDvNPGtvLGb7O31eAAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:10.278588 2026] [security2:error] [pid 78969:tid 79060] [remote 20.153.140.50:40978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4eMnDvNPGtvLGb7O31gwAA5Vo"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:10:10.508303 2026] [security2:error] [pid 78969:tid 79138] [client 50.116.65.227:36104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4eMnDvNPGtvLGb7O31fAAAAKw"]
[Mon Jul 20 07:10:10.709255 2026] [security2:error] [pid 78969:tid 79149] [client 50.116.65.227:36120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4eMnDvNPGtvLGb7O31nAAAALc"]
[Mon Jul 20 07:10:10.740563 2026] [security2:error] [pid 78969:tid 79141] [client 57.141.18.70:26630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eMHDvNPGtvLGb7O309QAAryw"]
[Mon Jul 20 07:10:10.817359 2026] [security2:error] [pid 78969:tid 79217] [client 194.61.41.247:51103] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ubh/install.php"] [unique_id "al4eMnDvNPGtvLGb7O31sQAAAPs"]
[Mon Jul 20 07:10:11.082424 2026] [security2:error] [pid 78969:tid 79169] [client 14.225.17.146:53354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4eMnDvNPGtvLGb7O31vQAAAMs"], referer: https://nurturemarple.co.uk/2024
[Mon Jul 20 07:10:11.230814 2026] [security2:error] [pid 78969:tid 79214] [client 14.225.17.146:55041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4eMnDvNPGtvLGb7O31kwAAAPg"], referer: http://overloadcomedy.com/2024
[Mon Jul 20 07:10:11.407152 2026] [security2:error] [pid 78969:tid 79178] [client 104.234.53.91:29617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4eM3DvNPGtvLGb7O314wAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:11.424896 2026] [security2:error] [pid 78969:tid 79122] [client 201.27.111.74:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eM3DvNPGtvLGb7O315QAAAJw"]
[Mon Jul 20 07:10:11.425037 2026] [security2:error] [pid 78969:tid 79122] [client 201.27.111.74:63969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eM3DvNPGtvLGb7O315QAAAJw"]
[Mon Jul 20 07:10:11.436419 2026] [security2:error] [pid 78969:tid 79130] [client 82.135.202.97:42322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.202.135.82.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/mcd/mcd_results.php"] [unique_id "al4eM3DvNPGtvLGb7O316AAAAKQ"]
[Mon Jul 20 07:10:11.528590 2026] [security2:error] [pid 78969:tid 79180] [client 194.61.41.248:51275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/Registry-private.php"] [unique_id "al4eM3DvNPGtvLGb7O319AAAANY"]
[Mon Jul 20 07:10:11.657340 2026] [security2:error] [pid 78969:tid 78976] [remote 162.19.86.63:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4eM3DvNPGtvLGb7O32AAAA1wY"]
[Mon Jul 20 07:10:11.712987 2026] [security2:error] [pid 78969:tid 79184] [client 14.225.17.146:53454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4eM3DvNPGtvLGb7O319wAAANo"], referer: http://adirondackengineering.com/2024
[Mon Jul 20 07:10:11.858703 2026] [security2:error] [pid 78969:tid 78988] [remote 162.19.86.63:56397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4eM3DvNPGtvLGb7O32DwAA-BI"], referer: https://hammadownenterprises.com/wp-login.php
[Mon Jul 20 07:10:12.221835 2026] [security2:error] [pid 78969:tid 79158] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eNHDvNPGtvLGb7O32IgAAwGw"], referer: http://aleishapenny.ca/2024
[Mon Jul 20 07:10:12.264035 2026] [security2:error] [pid 78969:tid 79104] [client 14.225.17.146:56159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4eMnDvNPGtvLGb7O31fgAAAIo"], referer: http://jvcmotorsports.com/2024
[Mon Jul 20 07:10:12.291929 2026] [security2:error] [pid 78969:tid 79156] [client 77.110.127.138:64497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eNHDvNPGtvLGb7O32OgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:12.292094 2026] [security2:error] [pid 78969:tid 79156] [client 77.110.127.138:64497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eNHDvNPGtvLGb7O32OgAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:12.302065 2026] [security2:error] [pid 78969:tid 79141] [client 43.205.139.3:64806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eNHDvNPGtvLGb7O32OwAAAK8"]
[Mon Jul 20 07:10:12.302164 2026] [security2:error] [pid 78969:tid 79141] [client 43.205.139.3:64806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eNHDvNPGtvLGb7O32OwAAAK8"]
[Mon Jul 20 07:10:12.332978 2026] [security2:error] [pid 78969:tid 79226] [client 194.61.41.108:38497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/script-modules-packages.min-meta.php"] [unique_id "al4eNHDvNPGtvLGb7O32PAAAAQQ"]
[Mon Jul 20 07:10:12.406125 2026] [security2:error] [pid 78969:tid 79222] [client 117.211.236.168:52816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eNHDvNPGtvLGb7O32PgAAAQA"]
[Mon Jul 20 07:10:12.406224 2026] [security2:error] [pid 78969:tid 79222] [client 117.211.236.168:52816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eNHDvNPGtvLGb7O32PgAAAQA"]
[Mon Jul 20 07:10:12.443584 2026] [security2:error] [pid 78969:tid 79121] [client 77.110.127.138:64498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/3/"] [unique_id "al4eNHDvNPGtvLGb7O32PwAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:12.846454 2026] [security2:error] [pid 78969:tid 79000] [remote 81.173.115.7:53382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4eNHDvNPGtvLGb7O32ZQAA8x4"]
[Mon Jul 20 07:10:12.871519 2026] [security2:error] [pid 78969:tid 79140] [client 57.141.18.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eNHDvNPGtvLGb7O32YAAAAK4"]
[Mon Jul 20 07:10:13.081626 2026] [security2:error] [pid 78969:tid 79186] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eNHDvNPGtvLGb7O32bAAA3DA"], referer: https://aleishapenny.ca/2024
[Mon Jul 20 07:10:13.093168 2026] [security2:error] [pid 78969:tid 79024] [remote 81.173.115.7:53382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4eNXDvNPGtvLGb7O32ggAAsTY"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 07:10:13.149783 2026] [security2:error] [pid 78969:tid 79149] [client 194.61.41.241:56353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/bypass.php"] [unique_id "al4eNXDvNPGtvLGb7O32iQAAALc"]
[Mon Jul 20 07:10:13.224032 2026] [security2:error] [pid 78969:tid 79212] [client 57.141.18.121:50578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eM3DvNPGtvLGb7O314AAA9gs"]
[Mon Jul 20 07:10:13.840977 2026] [security2:error] [pid 78969:tid 79202] [client 47.129.222.11:46192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eNXDvNPGtvLGb7O32uwAAAOw"]
[Mon Jul 20 07:10:13.841123 2026] [security2:error] [pid 78969:tid 79202] [client 47.129.222.11:46192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eNXDvNPGtvLGb7O32uwAAAOw"]
[Mon Jul 20 07:10:13.914909 2026] [security2:error] [pid 78969:tid 79099] [client 194.61.41.101:22535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/content-index.php"] [unique_id "al4eNXDvNPGtvLGb7O32vwAAAIU"]
[Mon Jul 20 07:10:13.924964 2026] [security2:error] [pid 78969:tid 79103] [client 14.225.17.146:53083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4eNHDvNPGtvLGb7O32QAAAAIk"], referer: http://inspirespublishing.com/2024
[Mon Jul 20 07:10:13.967219 2026] [security2:error] [pid 78969:tid 79161] [client 74.7.228.17:41716] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.asliceofleadership.com"] [uri "/robots.txt"] [unique_id "al4eNXDvNPGtvLGb7O32wgAAAMM"]
[Mon Jul 20 07:10:14.125943 2026] [security2:error] [pid 78969:tid 79109] [client 74.7.228.17:37932] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.asliceofleadership.com"] [uri "/index.php"] [unique_id "al4eNnDvNPGtvLGb7O320QAAj1U"], referer: http://www.asliceofleadership.com/robots.txt
[Mon Jul 20 07:10:14.308588 2026] [security2:error] [pid 78969:tid 79218] [client 98.159.234.160:56151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eNnDvNPGtvLGb7O325gAAAPw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:14.328614 2026] [security2:error] [pid 78969:tid 79121] [client 117.247.108.24:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eNnDvNPGtvLGb7O325wAAAJs"]
[Mon Jul 20 07:10:14.328738 2026] [security2:error] [pid 78969:tid 79121] [client 117.247.108.24:49320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eNnDvNPGtvLGb7O325wAAAJs"]
[Mon Jul 20 07:10:14.464521 2026] [security2:error] [pid 78969:tid 79175] [client 104.234.53.80:32801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4eNnDvNPGtvLGb7O327QAAANE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:14.479524 2026] [security2:error] [pid 78969:tid 79221] [client 51.68.111.219:14667] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.stopfeedingthemonster.com"] [uri "/robots.txt"] [unique_id "al4eNnDvNPGtvLGb7O327wAAAP8"]
[Mon Jul 20 07:10:14.479631 2026] [security2:error] [pid 78969:tid 79221] [client 51.68.111.219:14667] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.stopfeedingthemonster.com"] [uri "/robots.txt"] [unique_id "al4eNnDvNPGtvLGb7O327wAAAP8"]
[Mon Jul 20 07:10:14.747775 2026] [security2:error] [pid 78969:tid 79181] [client 145.239.10.137:53540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wolv.php"] [unique_id "al4eNnDvNPGtvLGb7O33BQAAANc"], referer: http://iagdevelopments.com/wolv.php
[Mon Jul 20 07:10:14.747929 2026] [security2:error] [pid 78969:tid 79220] [client 194.61.41.252:56241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin/controller/extension/extension/alfa.php"] [unique_id "al4eNnDvNPGtvLGb7O33BgAAAP4"]
[Mon Jul 20 07:10:14.899279 2026] [lsapi:warn] [pid 78969:tid 79104] [client 14.225.17.146:53485] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2024
[Mon Jul 20 07:10:14.899306 2026] [lsapi:warn] [pid 78969:tid 79104] [client 14.225.17.146:53485] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2024
[Mon Jul 20 07:10:15.176760 2026] [security2:error] [pid 78969:tid 79175] [client 77.110.127.138:64515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eN3DvNPGtvLGb7O33KwAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:15.176876 2026] [security2:error] [pid 78969:tid 79175] [client 77.110.127.138:64515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eN3DvNPGtvLGb7O33KwAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:15.313914 2026] [security2:error] [pid 78969:tid 78974] [remote 173.249.4.11:22000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eN3DvNPGtvLGb7O33PAAA_wQ"]
[Mon Jul 20 07:10:15.364465 2026] [security2:error] [pid 78969:tid 79205] [client 77.110.127.138:64518] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/3/"] [unique_id "al4eN3DvNPGtvLGb7O33QgAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:15.442165 2026] [lsapi:warn] [pid 78969:tid 79162] [client 50.116.65.227:36200] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:10:15.442187 2026] [lsapi:warn] [pid 78969:tid 79162] [client 50.116.65.227:36200] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:10:15.459529 2026] [security2:error] [pid 78969:tid 79104] [client 14.225.17.146:53485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4eNnDvNPGtvLGb7O326AAAAIo"], referer: http://oswegooperatheater.com/2024
[Mon Jul 20 07:10:15.534985 2026] [security2:error] [pid 78969:tid 79095] [remote 194.164.192.228:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eN3DvNPGtvLGb7O33TgAA830"]
[Mon Jul 20 07:10:15.535319 2026] [security2:error] [pid 78969:tid 79209] [client 194.164.192.228:59178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eN3DvNPGtvLGb7O33TgAA830"]
[Mon Jul 20 07:10:15.554811 2026] [security2:error] [pid 78969:tid 79204] [client 194.61.41.81:48247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/system_cache.php%20"] [unique_id "al4eN3DvNPGtvLGb7O33UgAAAO4"]
[Mon Jul 20 07:10:15.595707 2026] [security2:error] [pid 78969:tid 79084] [remote 173.249.4.11:22000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eN3DvNPGtvLGb7O33VwAAuXI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:10:16.315712 2026] [lsapi:warn] [pid 78969:tid 79200] [client 14.225.17.146:54723] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2024
[Mon Jul 20 07:10:16.315736 2026] [lsapi:warn] [pid 78969:tid 79200] [client 14.225.17.146:54723] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2024
[Mon Jul 20 07:10:16.355788 2026] [security2:error] [pid 78969:tid 79191] [client 194.61.41.252:49981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/modern/colors.css.php"] [unique_id "al4eOHDvNPGtvLGb7O33jgAAAOE"]
[Mon Jul 20 07:10:16.366654 2026] [security2:error] [pid 78969:tid 79200] [client 14.225.17.146:54723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4eOHDvNPGtvLGb7O33igAAAOo"], referer: https://oswegooperatheater.com/2024
[Mon Jul 20 07:10:16.709738 2026] [security2:error] [pid 78969:tid 79015] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eOHDvNPGtvLGb7O33sAAA8S0"]
[Mon Jul 20 07:10:16.709920 2026] [security2:error] [pid 78969:tid 79207] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eOHDvNPGtvLGb7O33sAAA8S0"]
[Mon Jul 20 07:10:17.137325 2026] [security2:error] [pid 78969:tid 79156] [client 194.61.41.81:56719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/adminfus.php"] [unique_id "al4eOXDvNPGtvLGb7O330AAAAL4"]
[Mon Jul 20 07:10:17.225312 2026] [security2:error] [pid 78969:tid 79171] [client 57.141.18.110:30326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eN3DvNPGtvLGb7O33NQAAzXg"]
[Mon Jul 20 07:10:17.244192 2026] [security2:error] [pid 78969:tid 79203] [client 14.225.17.146:54685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4eN3DvNPGtvLGb7O33bgAAAO0"], referer: http://balticsteelmgmt.com/2024
[Mon Jul 20 07:10:17.383664 2026] [security2:error] [pid 78969:tid 79208] [client 187.16.64.216:61212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eOXDvNPGtvLGb7O337wAAAPI"]
[Mon Jul 20 07:10:17.383761 2026] [security2:error] [pid 78969:tid 79208] [client 187.16.64.216:61212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eOXDvNPGtvLGb7O337wAAAPI"]
[Mon Jul 20 07:10:17.460282 2026] [security2:error] [pid 78969:tid 79166] [client 104.234.53.62:56575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eOXDvNPGtvLGb7O33-gAAAMg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:17.788718 2026] [security2:error] [pid 78969:tid 79043] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eOXDvNPGtvLGb7O34CAAAl0k"]
[Mon Jul 20 07:10:17.788869 2026] [security2:error] [pid 78969:tid 79117] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eOXDvNPGtvLGb7O34CAAAl0k"]
[Mon Jul 20 07:10:17.872702 2026] [security2:error] [pid 78969:tid 79139] [client 77.110.127.138:64549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOXDvNPGtvLGb7O34EgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:17.872851 2026] [security2:error] [pid 78969:tid 79139] [client 77.110.127.138:64549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOXDvNPGtvLGb7O34EgAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:17.933724 2026] [security2:error] [pid 78969:tid 79129] [client 194.61.41.66:54783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/media-widget-vide02.php"] [unique_id "al4eOXDvNPGtvLGb7O34GwAAAKM"]
[Mon Jul 20 07:10:18.098979 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:64551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOnDvNPGtvLGb7O34KgAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:18.099101 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:64551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOnDvNPGtvLGb7O34KgAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:18.113878 2026] [security2:error] [pid 78969:tid 79218] [client 14.225.17.146:53264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4eOHDvNPGtvLGb7O33kgAAAPw"], referer: http://nwcarvingacademy.com/2024
[Mon Jul 20 07:10:18.517675 2026] [security2:error] [pid 78969:tid 79188] [client 104.234.53.60:47267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4eOnDvNPGtvLGb7O34WAAAAN4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:18.555045 2026] [security2:error] [pid 78969:tid 79191] [client 14.225.17.146:58349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4eOnDvNPGtvLGb7O34TgAAAOE"], referer: http://koaconsultants.com/2024
[Mon Jul 20 07:10:18.636571 2026] [security2:error] [pid 78969:tid 79159] [client 77.110.127.138:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOnDvNPGtvLGb7O34YwAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:18.636657 2026] [security2:error] [pid 78969:tid 79159] [client 77.110.127.138:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOnDvNPGtvLGb7O34YwAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:18.651899 2026] [security2:error] [pid 78969:tid 79119] [client 194.61.41.108:61525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/blocks/group/wp-style.php"] [unique_id "al4eOnDvNPGtvLGb7O34ZQAAAJk"]
[Mon Jul 20 07:10:18.673333 2026] [security2:error] [pid 78969:tid 79147] [client 47.128.41.217:23072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.chestermonty.com"] [uri "/robots.txt"] [unique_id "al4eOnDvNPGtvLGb7O34ZgAAALU"]
[Mon Jul 20 07:10:18.936774 2026] [security2:error] [pid 78969:tid 79182] [client 77.110.127.138:64556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOnDvNPGtvLGb7O34eAAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:18.936872 2026] [security2:error] [pid 78969:tid 79182] [client 77.110.127.138:64556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eOnDvNPGtvLGb7O34eAAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:19.050159 2026] [security2:error] [pid 78969:tid 79105] [client 88.241.67.160:54536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eO3DvNPGtvLGb7O34hwAAAIs"]
[Mon Jul 20 07:10:19.050552 2026] [security2:error] [pid 78969:tid 79105] [client 88.241.67.160:54536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eO3DvNPGtvLGb7O34hwAAAIs"]
[Mon Jul 20 07:10:19.081194 2026] [security2:error] [pid 78969:tid 79108] [client 103.144.65.217:64727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eO3DvNPGtvLGb7O34iwAAAI4"]
[Mon Jul 20 07:10:19.081322 2026] [security2:error] [pid 78969:tid 79108] [client 103.144.65.217:64727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eO3DvNPGtvLGb7O34iwAAAI4"]
[Mon Jul 20 07:10:19.100777 2026] [security2:error] [pid 78969:tid 79135] [client 77.110.127.138:64557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eO3DvNPGtvLGb7O34jQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:19.102504 2026] [security2:error] [pid 78969:tid 79135] [client 77.110.127.138:64557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eO3DvNPGtvLGb7O34jQAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:19.192901 2026] [security2:error] [pid 78969:tid 79212] [client 14.225.17.146:63159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4eOnDvNPGtvLGb7O34eQAAAPY"], referer: https://nwcarvingacademy.com/2024
[Mon Jul 20 07:10:19.436833 2026] [security2:error] [pid 78969:tid 79220] [client 194.61.41.248:24053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/buy.php"] [unique_id "al4eO3DvNPGtvLGb7O34nwAAAP4"]
[Mon Jul 20 07:10:19.463730 2026] [security2:error] [pid 78969:tid 79149] [client 14.225.17.146:54679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4eOXDvNPGtvLGb7O334QAAALc"], referer: http://younutrition.gr/2024
[Mon Jul 20 07:10:19.523955 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:64561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eO3DvNPGtvLGb7O34pQAAAKM"]
[Mon Jul 20 07:10:19.524040 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:64561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eO3DvNPGtvLGb7O34pQAAAKM"]
[Mon Jul 20 07:10:19.812885 2026] [security2:error] [pid 78969:tid 79108] [client 77.110.127.138:64513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eO3DvNPGtvLGb7O34uQAAAI4"]
[Mon Jul 20 07:10:19.813037 2026] [security2:error] [pid 78969:tid 79108] [client 77.110.127.138:64513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eO3DvNPGtvLGb7O34uQAAAI4"]
[Mon Jul 20 07:10:20.157233 2026] [security2:error] [pid 78969:tid 79113] [client 194.61.41.249:22107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/templates/beez3/av.php"] [unique_id "al4ePHDvNPGtvLGb7O34zQAAAJM"]
[Mon Jul 20 07:10:20.389785 2026] [security2:error] [pid 78969:tid 79220] [client 216.24.212.38:61411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4ePHDvNPGtvLGb7O342gAAAP4"]
[Mon Jul 20 07:10:20.393126 2026] [security2:error] [pid 78969:tid 79175] [client 216.24.212.42:53257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4ePHDvNPGtvLGb7O342wAAANE"]
[Mon Jul 20 07:10:20.679661 2026] [security2:error] [pid 78969:tid 79213] [client 57.141.18.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ePHDvNPGtvLGb7O345wAAAPc"]
[Mon Jul 20 07:10:20.930678 2026] [security2:error] [pid 78969:tid 79198] [client 194.61.41.79:57875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-wp-wolf-widget.php"] [unique_id "al4ePHDvNPGtvLGb7O35CgAAAOg"]
[Mon Jul 20 07:10:21.569141 2026] [security2:error] [pid 78969:tid 79135] [client 74.208.214.194:38994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ePXDvNPGtvLGb7O35OAAAAKk"]
[Mon Jul 20 07:10:21.756508 2026] [security2:error] [pid 78969:tid 79223] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ePXDvNPGtvLGb7O35NQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:21.759022 2026] [security2:error] [pid 78969:tid 79190] [client 194.61.41.93:43125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/install.php"] [unique_id "al4ePXDvNPGtvLGb7O35TAAAAOA"]
[Mon Jul 20 07:10:21.884932 2026] [security2:error] [pid 78969:tid 79200] [client 14.225.17.146:58044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4ePXDvNPGtvLGb7O35SAAAAOo"], referer: http://fineartsfactory.net/2024
[Mon Jul 20 07:10:21.892077 2026] [security2:error] [pid 78969:tid 79121] [client 201.27.111.74:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ePXDvNPGtvLGb7O35VwAAAJs"]
[Mon Jul 20 07:10:21.892183 2026] [security2:error] [pid 78969:tid 79121] [client 201.27.111.74:64473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ePXDvNPGtvLGb7O35VwAAAJs"]
[Mon Jul 20 07:10:22.446810 2026] [security2:error] [pid 78969:tid 79156] [client 57.141.18.16:43866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ePHDvNPGtvLGb7O35BQAAviI"]
[Mon Jul 20 07:10:22.573311 2026] [security2:error] [pid 78969:tid 79172] [client 194.61.41.242:49105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/plugins/function.php"] [unique_id "al4ePnDvNPGtvLGb7O35iwAAAM4"]
[Mon Jul 20 07:10:22.798447 2026] [security2:error] [pid 78969:tid 79158] [client 104.234.53.92:56357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ePnDvNPGtvLGb7O35mAAAAMA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:22.901165 2026] [security2:error] [pid 78969:tid 79061] [remote 182.77.62.24:39800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4ePnDvNPGtvLGb7O35pAAAvVs"]
[Mon Jul 20 07:10:23.263188 2026] [security2:error] [pid 78969:tid 79100] [client 14.225.17.146:57605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4ePnDvNPGtvLGb7O35eQAAAIY"], referer: http://claysharecon.com/2024
[Mon Jul 20 07:10:23.350397 2026] [security2:error] [pid 78969:tid 79128] [client 194.61.41.79:24919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/header.php"] [unique_id "al4eP3DvNPGtvLGb7O35xgAAAKI"]
[Mon Jul 20 07:10:23.436945 2026] [security2:error] [pid 78969:tid 79072] [remote 182.77.62.24:39800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4eP3DvNPGtvLGb7O35ywAAr2Y"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:10:24.110489 2026] [security2:error] [pid 78969:tid 79150] [client 14.225.17.146:63118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4eP3DvNPGtvLGb7O355wAAALg"], referer: http://transparentservices.online/2024
[Mon Jul 20 07:10:24.117127 2026] [security2:error] [pid 78969:tid 79139] [client 194.61.41.87:20425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wordpress/wp-content/uploads/install.php"] [unique_id "al4eQHDvNPGtvLGb7O357wAAAK0"]
[Mon Jul 20 07:10:24.338132 2026] [security2:error] [pid 78969:tid 79178] [client 77.110.127.138:64598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eQHDvNPGtvLGb7O36AgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:24.338239 2026] [security2:error] [pid 78969:tid 79178] [client 77.110.127.138:64598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eQHDvNPGtvLGb7O36AgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:24.843958 2026] [security2:error] [pid 78969:tid 79224] [client 194.61.41.68:41333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/server.php"] [unique_id "al4eQHDvNPGtvLGb7O36MAAAAQI"]
[Mon Jul 20 07:10:24.948734 2026] [security2:error] [pid 78969:tid 79214] [client 117.247.108.24:50034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eQHDvNPGtvLGb7O36NgAAAPg"]
[Mon Jul 20 07:10:24.948832 2026] [security2:error] [pid 78969:tid 79214] [client 117.247.108.24:50034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eQHDvNPGtvLGb7O36NgAAAPg"]
[Mon Jul 20 07:10:24.990028 2026] [security2:error] [pid 78969:tid 79158] [client 57.141.18.110:37122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eP3DvNPGtvLGb7O352AAAwG0"]
[Mon Jul 20 07:10:25.168482 2026] [security2:error] [pid 78969:tid 79121] [client 117.211.236.168:53392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eQXDvNPGtvLGb7O36PQAAAJs"]
[Mon Jul 20 07:10:25.168590 2026] [security2:error] [pid 78969:tid 79121] [client 117.211.236.168:53392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eQXDvNPGtvLGb7O36PQAAAJs"]
[Mon Jul 20 07:10:25.628551 2026] [security2:error] [pid 78969:tid 79200] [client 194.61.41.105:51557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/autoload_classmap/install.php"] [unique_id "al4eQXDvNPGtvLGb7O36YAAAAOo"]
[Mon Jul 20 07:10:25.915471 2026] [security2:error] [pid 78969:tid 79207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eQXDvNPGtvLGb7O36aQAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:26.250795 2026] [security2:error] [pid 78969:tid 79172] [client 112.86.225.158:34830] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mezzacraft.com"] [uri "/newsletter-privacy-policy/"] [unique_id "al4eQnDvNPGtvLGb7O36mAAAAM4"]
[Mon Jul 20 07:10:26.250936 2026] [security2:error] [pid 78969:tid 79172] [client 112.86.225.158:34830] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.mezzacraft.com"] [uri "/newsletter-privacy-policy/"] [unique_id "al4eQnDvNPGtvLGb7O36mAAAAM4"]
[Mon Jul 20 07:10:26.329080 2026] [security2:error] [pid 78969:tid 79139] [client 194.61.41.105:28235] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "al4eQnDvNPGtvLGb7O36nwAAAK0"]
[Mon Jul 20 07:10:26.329191 2026] [security2:error] [pid 78969:tid 79139] [client 194.61.41.105:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/1.php"] [unique_id "al4eQnDvNPGtvLGb7O36nwAAAK0"]
[Mon Jul 20 07:10:26.445010 2026] [security2:error] [pid 78969:tid 79126] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eQnDvNPGtvLGb7O36lgAAAKA"], referer: https://mezzacraft.com/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/
[Mon Jul 20 07:10:26.874147 2026] [security2:error] [pid 78969:tid 79128] [client 14.225.17.146:57866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4eQXDvNPGtvLGb7O36OAAAAKI"], referer: http://longevityperformanceclinic.com/2024
[Mon Jul 20 07:10:27.041016 2026] [security2:error] [pid 78969:tid 79209] [client 194.61.41.100:46293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ubh/av.php"] [unique_id "al4eQ3DvNPGtvLGb7O36zAAAAPM"]
[Mon Jul 20 07:10:27.259952 2026] [security2:error] [pid 78969:tid 79050] [remote 68.178.160.25:60822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4eQ3DvNPGtvLGb7O364QAAr1A"]
[Mon Jul 20 07:10:27.369428 2026] [proxy:error] [pid 78969:tid 79185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:10:27.369492 2026] [proxy_http:error] [pid 78969:tid 79185] [client 205.210.31.53:58406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:10:27.370140 2026] [proxy:error] [pid 78969:tid 79185] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:10:27.370189 2026] [proxy_http:error] [pid 78969:tid 79185] [client 205.210.31.53:58406] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:10:27.500559 2026] [security2:error] [pid 78969:tid 79049] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eQ3DvNPGtvLGb7O369AAAy08"]
[Mon Jul 20 07:10:27.500714 2026] [security2:error] [pid 78969:tid 79169] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eQ3DvNPGtvLGb7O369AAAy08"]
[Mon Jul 20 07:10:27.668190 2026] [security2:error] [pid 78969:tid 79061] [remote 68.178.160.25:60822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4eQ3DvNPGtvLGb7O36-wAAzVs"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 07:10:27.813652 2026] [security2:error] [pid 78969:tid 79199] [client 14.225.17.146:58019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4eQ3DvNPGtvLGb7O369wAAAOk"], referer: http://www.justinagrayman.com/2024
[Mon Jul 20 07:10:27.843884 2026] [security2:error] [pid 78969:tid 79192] [client 194.61.41.244:49609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/anas.php"] [unique_id "al4eQ3DvNPGtvLGb7O37BwAAAOI"]
[Mon Jul 20 07:10:28.035819 2026] [security2:error] [pid 78969:tid 79099] [client 187.16.64.216:61804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eRHDvNPGtvLGb7O37HwAAAIU"]
[Mon Jul 20 07:10:28.035935 2026] [security2:error] [pid 78969:tid 79099] [client 187.16.64.216:61804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eRHDvNPGtvLGb7O37HwAAAIU"]
[Mon Jul 20 07:10:28.400618 2026] [security2:error] [pid 78969:tid 79064] [remote 130.51.180.8:39418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eRHDvNPGtvLGb7O37PAAA7F4"]
[Mon Jul 20 07:10:28.404827 2026] [security2:error] [pid 78969:tid 79062] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eRHDvNPGtvLGb7O37PwAAw1w"]
[Mon Jul 20 07:10:28.404981 2026] [security2:error] [pid 78969:tid 79161] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eRHDvNPGtvLGb7O37PwAAw1w"]
[Mon Jul 20 07:10:28.526924 2026] [security2:error] [pid 78969:tid 79102] [client 3.149.57.90:9654] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4eRHDvNPGtvLGb7O37RwAAAIg"], referer: https://windowtx.com
[Mon Jul 20 07:10:28.543174 2026] [security2:error] [pid 78969:tid 79188] [client 50.116.65.227:18954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eyl.bfk.mybluehost.me"] [uri "/website_70dc46cb/wp-cron.php"] [unique_id "al4eRHDvNPGtvLGb7O37SgAAAN4"]
[Mon Jul 20 07:10:28.594381 2026] [security2:error] [pid 78969:tid 79071] [remote 130.51.180.8:39418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eRHDvNPGtvLGb7O37TwAA9WU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:10:28.638430 2026] [security2:error] [pid 78969:tid 79204] [client 194.61.41.95:62401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/shell.php"] [unique_id "al4eRHDvNPGtvLGb7O37UAAAAO4"]
[Mon Jul 20 07:10:28.684709 2026] [security2:error] [pid 78969:tid 79124] [client 77.110.127.138:64621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRHDvNPGtvLGb7O37UgAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:28.684830 2026] [security2:error] [pid 78969:tid 79124] [client 77.110.127.138:64621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRHDvNPGtvLGb7O37UgAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:28.774499 2026] [security2:error] [pid 78969:tid 79220] [client 13.233.207.33:63356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4eRHDvNPGtvLGb7O37VAAAAP4"]
[Mon Jul 20 07:10:28.846033 2026] [security2:error] [pid 78969:tid 79118] [client 77.110.127.138:64623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRHDvNPGtvLGb7O37YQAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:28.846134 2026] [security2:error] [pid 78969:tid 79118] [client 77.110.127.138:64623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRHDvNPGtvLGb7O37YQAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:29.433994 2026] [security2:error] [pid 78969:tid 79118] [client 194.61.41.73:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/erinyani/default.php"] [unique_id "al4eRXDvNPGtvLGb7O37iwAAAJg"]
[Mon Jul 20 07:10:29.466154 2026] [security2:error] [pid 78969:tid 79147] [client 88.241.67.160:55311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eRXDvNPGtvLGb7O37kAAAALU"]
[Mon Jul 20 07:10:29.466640 2026] [security2:error] [pid 78969:tid 79147] [client 88.241.67.160:55311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eRXDvNPGtvLGb7O37kAAAALU"]
[Mon Jul 20 07:10:29.615155 2026] [security2:error] [pid 78969:tid 79190] [client 103.144.65.217:65182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eRXDvNPGtvLGb7O37mQAAAOA"]
[Mon Jul 20 07:10:29.615275 2026] [security2:error] [pid 78969:tid 79190] [client 103.144.65.217:65182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eRXDvNPGtvLGb7O37mQAAAOA"]
[Mon Jul 20 07:10:29.820161 2026] [security2:error] [pid 78969:tid 79202] [client 13.232.231.177:53950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4eRXDvNPGtvLGb7O37rgAAAOw"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:10:29.879259 2026] [security2:error] [pid 78969:tid 79157] [client 77.110.127.138:64630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRXDvNPGtvLGb7O37sQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:29.879373 2026] [security2:error] [pid 78969:tid 79157] [client 77.110.127.138:64630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRXDvNPGtvLGb7O37sQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:30.193323 2026] [security2:error] [pid 78969:tid 79203] [client 14.225.17.146:62786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4eRnDvNPGtvLGb7O37wgAAAO0"], referer: http://keywayconstructionclt.com/2024
[Mon Jul 20 07:10:30.197822 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:64601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRnDvNPGtvLGb7O37xwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:30.197929 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:64601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRnDvNPGtvLGb7O37xwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:30.227355 2026] [security2:error] [pid 78969:tid 79172] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eRXDvNPGtvLGb7O37uAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:30.230422 2026] [security2:error] [pid 78969:tid 79101] [client 194.61.41.69:29227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/index.php"] [unique_id "al4eRnDvNPGtvLGb7O37ywAAAIc"]
[Mon Jul 20 07:10:30.314470 2026] [security2:error] [pid 78969:tid 79017] [remote 216.73.216.55:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4eRnDvNPGtvLGb7O37zwAA8i8"]
[Mon Jul 20 07:10:30.357514 2026] [security2:error] [pid 78969:tid 79125] [client 77.110.127.138:64633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRnDvNPGtvLGb7O370wAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:30.357610 2026] [security2:error] [pid 78969:tid 79125] [client 77.110.127.138:64633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eRnDvNPGtvLGb7O370wAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:30.840152 2026] [security2:error] [pid 78969:tid 79185] [client 14.225.17.146:63075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4eRXDvNPGtvLGb7O37egAAANs"], referer: http://xp-design.co/2024
[Mon Jul 20 07:10:30.886616 2026] [autoindex:error] [pid 78969:tid 79190] [client 8.234.160.70:61841] AH01276: Cannot serve directory /home4/sbdwidmy/public_html/website_7ca3a27a/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:10:30.948594 2026] [security2:error] [pid 78969:tid 79206] [client 194.61.41.69:48829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/xex.php"] [unique_id "al4eRnDvNPGtvLGb7O38BQAAAPA"]
[Mon Jul 20 07:10:31.014881 2026] [security2:error] [pid 78969:tid 79201] [client 77.110.127.138:64635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eR3DvNPGtvLGb7O38CgAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:31.015033 2026] [security2:error] [pid 78969:tid 79201] [client 77.110.127.138:64635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eR3DvNPGtvLGb7O38CgAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:31.037363 2026] [security2:error] [pid 78969:tid 79186] [client 74.7.227.179:39724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4eRnDvNPGtvLGb7O379wAA3H4"], referer: https://tejasenvironmental.com/p=317764
[Mon Jul 20 07:10:31.199933 2026] [security2:error] [pid 78969:tid 79179] [client 14.225.17.146:64945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4eR3DvNPGtvLGb7O38GgAAANU"], referer: https://keywayconstructionclt.com/2024
[Mon Jul 20 07:10:31.275458 2026] [security2:error] [pid 78969:tid 79183] [client 77.110.127.138:64612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eR3DvNPGtvLGb7O38IwAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:31.275572 2026] [security2:error] [pid 78969:tid 79183] [client 77.110.127.138:64612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eR3DvNPGtvLGb7O38IwAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:31.746428 2026] [security2:error] [pid 78969:tid 79052] [remote 20.233.187.228:3970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4eR3DvNPGtvLGb7O38PAAAr1I"]
[Mon Jul 20 07:10:31.757286 2026] [security2:error] [pid 78969:tid 79179] [client 194.61.41.101:55897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/about.php"] [unique_id "al4eR3DvNPGtvLGb7O38PwAAANU"]
[Mon Jul 20 07:10:31.863724 2026] [security2:error] [pid 78969:tid 79102] [client 207.46.13.64:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.13.46.207.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daseighty.net"] [uri "/gallery/main.php/d/878-1/996seven.jpg"] [unique_id "al4eR3DvNPGtvLGb7O38TAAAAIg"]
[Mon Jul 20 07:10:32.120022 2026] [security2:error] [pid 78969:tid 79061] [remote 20.233.187.228:3970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4eSHDvNPGtvLGb7O38WQAA8ls"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 07:10:32.210419 2026] [security2:error] [pid 78969:tid 79117] [client 201.27.111.74:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eSHDvNPGtvLGb7O38YwAAAJc"]
[Mon Jul 20 07:10:32.210537 2026] [security2:error] [pid 78969:tid 79117] [client 201.27.111.74:64972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eSHDvNPGtvLGb7O38YwAAAJc"]
[Mon Jul 20 07:10:32.295997 2026] [security2:error] [pid 78969:tid 79196] [client 52.47.76.32:22674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eSHDvNPGtvLGb7O38awAAAOY"]
[Mon Jul 20 07:10:32.510523 2026] [security2:error] [pid 78969:tid 79202] [client 14.225.17.146:52779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4eSHDvNPGtvLGb7O38bAAAAOw"], referer: http://soloceos.com/2024
[Mon Jul 20 07:10:32.555460 2026] [security2:error] [pid 78969:tid 79102] [client 194.61.41.76:29311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/install.php"] [unique_id "al4eSHDvNPGtvLGb7O38hQAAAIg"]
[Mon Jul 20 07:10:32.705470 2026] [security2:error] [pid 78969:tid 79176] [client 104.234.53.65:40469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4eSHDvNPGtvLGb7O38kgAAANI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:32.885569 2026] [security2:error] [pid 78969:tid 79203] [client 194.180.48.253:39918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "aviationsynergy.aero"] [uri "/"] [unique_id "al4eSHDvNPGtvLGb7O38oAAAAO0"]
[Mon Jul 20 07:10:32.889276 2026] [security2:error] [pid 78969:tid 79213] [client 52.47.76.32:22690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eSHDvNPGtvLGb7O38oQAAAPc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:10:33.039119 2026] [security2:error] [pid 78969:tid 79134] [client 14.225.17.146:56422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4eSHDvNPGtvLGb7O38ngAAAKg"], referer: http://sarahsnyder.net/2024
[Mon Jul 20 07:10:33.259402 2026] [security2:error] [pid 78969:tid 79082] [remote 74.235.96.117:48020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eSXDvNPGtvLGb7O38uAAAoHA"]
[Mon Jul 20 07:10:33.328051 2026] [security2:error] [pid 78969:tid 79118] [client 194.61.41.66:21615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/upload/install.php"] [unique_id "al4eSXDvNPGtvLGb7O38vgAAAJg"]
[Mon Jul 20 07:10:33.446740 2026] [security2:error] [pid 78969:tid 79076] [remote 74.235.96.117:48020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eSXDvNPGtvLGb7O38xgAAwWo"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:10:33.553978 2026] [security2:error] [pid 78969:tid 79197] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eSXDvNPGtvLGb7O38vwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:33.925578 2026] [security2:error] [pid 78969:tid 79143] [client 14.225.17.146:62607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4eSXDvNPGtvLGb7O388AAAALE"], referer: http://thefriendlyspreadsheet.com/2024
[Mon Jul 20 07:10:34.058527 2026] [security2:error] [pid 78969:tid 79137] [client 194.61.41.247:63361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-head.php"] [unique_id "al4eSnDvNPGtvLGb7O39CQAAAKs"]
[Mon Jul 20 07:10:34.058561 2026] [security2:error] [pid 78969:tid 79133] [client 14.225.17.146:62675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4eSXDvNPGtvLGb7O389gAAAKc"], referer: https://sarahsnyder.net/2024
[Mon Jul 20 07:10:34.230031 2026] [security2:error] [pid 78969:tid 79113] [client 14.225.17.146:62645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4eSHDvNPGtvLGb7O38lwAAAJM"], referer: http://dnsplumbing.com/2024
[Mon Jul 20 07:10:34.658728 2026] [security2:error] [pid 78969:tid 79179] [client 77.110.127.138:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eSnDvNPGtvLGb7O39OAAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:34.658855 2026] [security2:error] [pid 78969:tid 79179] [client 77.110.127.138:64691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eSnDvNPGtvLGb7O39OAAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:34.768772 2026] [autoindex:error] [pid 78969:tid 79113] [client 213.35.113.47:0] AH01276: Cannot serve directory /home3/xpdesig1/amazonservices.xp-design.co/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:10:34.813348 2026] [security2:error] [pid 78969:tid 79168] [client 194.61.41.104:43949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/admin-footer.php"] [unique_id "al4eSnDvNPGtvLGb7O39RwAAAMo"]
[Mon Jul 20 07:10:35.235144 2026] [security2:error] [pid 78969:tid 79172] [client 14.225.17.146:62595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4eSXDvNPGtvLGb7O380gAAAM4"], referer: http://bigwormfishing.com/2024
[Mon Jul 20 07:10:35.450018 2026] [autoindex:error] [pid 78969:tid 79147] [client 213.35.113.47:0] AH01276: Cannot serve directory /home3/xpdesig1/amazonservices.xp-design.co/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:10:35.522603 2026] [security2:error] [pid 78969:tid 79130] [client 194.61.41.67:43827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/upgrade/wp-conflg.php"] [unique_id "al4eS3DvNPGtvLGb7O39gQAAAKQ"]
[Mon Jul 20 07:10:35.536308 2026] [security2:error] [pid 78969:tid 79187] [client 117.247.108.24:50605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.108.247.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eS3DvNPGtvLGb7O39ggAAAN0"]
[Mon Jul 20 07:10:35.536451 2026] [security2:error] [pid 78969:tid 79187] [client 117.247.108.24:50605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "omenana.com"] [uri "/xmlrpc.php"] [unique_id "al4eS3DvNPGtvLGb7O39ggAAAN0"]
[Mon Jul 20 07:10:35.745026 2026] [security2:error] [pid 78969:tid 79044] [remote 124.55.178.99:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eS3DvNPGtvLGb7O39kAAAhko"]
[Mon Jul 20 07:10:36.147596 2026] [security2:error] [pid 78969:tid 79008] [remote 124.55.178.99:46736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eTHDvNPGtvLGb7O39tAAAvSY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:10:36.232844 2026] [security2:error] [pid 78969:tid 79225] [client 194.61.41.76:20091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/makeasmtp.php"] [unique_id "al4eTHDvNPGtvLGb7O39vAAAAQM"]
[Mon Jul 20 07:10:36.236022 2026] [security2:error] [pid 78969:tid 79112] [client 14.225.17.146:58319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4eTHDvNPGtvLGb7O39rwAAAJI"], referer: https://bigwormfishing.com/2024
[Mon Jul 20 07:10:36.272201 2026] [security2:error] [pid 78969:tid 79108] [client 14.225.17.146:62705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4eSnDvNPGtvLGb7O39QgAAAI4"], referer: http://cephasnext.com/2024
[Mon Jul 20 07:10:36.333814 2026] [security2:error] [pid 78969:tid 79164] [client 57.141.18.106:47370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eS3DvNPGtvLGb7O39bAAAxn4"]
[Mon Jul 20 07:10:36.334397 2026] [security2:error] [pid 78969:tid 79067] [remote 216.73.216.55:56799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4eTHDvNPGtvLGb7O39xAAAqWE"]
[Mon Jul 20 07:10:36.406227 2026] [security2:error] [pid 78969:tid 79102] [client 213.35.113.47:65191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.113.35.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amazonservices.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4eTHDvNPGtvLGb7O39yQAAAIg"]
[Mon Jul 20 07:10:36.461321 2026] [security2:error] [pid 78969:tid 79145] [client 50.116.65.227:42892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eTHDvNPGtvLGb7O39zgAAALM"]
[Mon Jul 20 07:10:36.471234 2026] [security2:error] [pid 78969:tid 79207] [client 50.116.65.227:42900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eTHDvNPGtvLGb7O39zwAAAPE"]
[Mon Jul 20 07:10:36.594586 2026] [security2:error] [pid 78969:tid 79103] [client 14.225.17.146:62664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4eS3DvNPGtvLGb7O39WgAAAIk"], referer: http://reosportsboats.com/2024
[Mon Jul 20 07:10:36.993073 2026] [security2:error] [pid 78969:tid 79182] [client 13.233.207.33:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eTHDvNPGtvLGb7O39_QAAANg"]
[Mon Jul 20 07:10:36.993167 2026] [security2:error] [pid 78969:tid 79182] [client 13.233.207.33:58556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4eTHDvNPGtvLGb7O39_QAAANg"]
[Mon Jul 20 07:10:37.046882 2026] [security2:error] [pid 78969:tid 79165] [client 194.61.41.81:35021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/wp-sup.php"] [unique_id "al4eTXDvNPGtvLGb7O39_wAAAMc"]
[Mon Jul 20 07:10:37.256646 2026] [security2:error] [pid 78969:tid 79167] [client 104.234.53.66:51277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4eTXDvNPGtvLGb7O3-DAAAAMk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:37.594834 2026] [security2:error] [pid 78969:tid 79146] [client 14.225.17.146:52990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4eTXDvNPGtvLGb7O3-IAAAALQ"], referer: https://reosportsboats.com/2024
[Mon Jul 20 07:10:37.841560 2026] [security2:error] [pid 78969:tid 79221] [client 194.61.41.104:28161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wordpress/wp-includes/class-wp-http-ixr-client-view.php"] [unique_id "al4eTXDvNPGtvLGb7O3-MwAAAP8"]
[Mon Jul 20 07:10:37.849980 2026] [security2:error] [pid 78969:tid 79111] [client 14.225.17.146:53026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4eTXDvNPGtvLGb7O3-GAAAAJE"], referer: http://partnerselectricalllc.com/2024
[Mon Jul 20 07:10:38.193088 2026] [security2:error] [pid 78969:tid 78975] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eTnDvNPGtvLGb7O3-TAAAsAU"]
[Mon Jul 20 07:10:38.193281 2026] [security2:error] [pid 78969:tid 79142] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eTnDvNPGtvLGb7O3-TAAAsAU"]
[Mon Jul 20 07:10:38.335349 2026] [security2:error] [pid 78969:tid 79139] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eTnDvNPGtvLGb7O3-SAAAAK0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:38.511607 2026] [security2:error] [pid 78969:tid 79210] [client 114.119.150.248:63995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4eTnDvNPGtvLGb7O3-VQAAAPQ"], referer: https://astrollthrulife.com/2023/09/25/699th-inspire-me-tuesday/
[Mon Jul 20 07:10:38.618782 2026] [security2:error] [pid 78969:tid 79115] [client 194.61.41.252:52033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/bypass.php"] [unique_id "al4eTnDvNPGtvLGb7O3-dAAAAJU"]
[Mon Jul 20 07:10:38.828015 2026] [security2:error] [pid 78969:tid 79157] [client 187.16.64.216:62392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eTnDvNPGtvLGb7O3-eQAAAL8"]
[Mon Jul 20 07:10:38.828134 2026] [security2:error] [pid 78969:tid 79157] [client 187.16.64.216:62392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eTnDvNPGtvLGb7O3-eQAAAL8"]
[Mon Jul 20 07:10:39.104366 2026] [security2:error] [pid 78969:tid 78973] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eT3DvNPGtvLGb7O3-lgAA8wM"]
[Mon Jul 20 07:10:39.104520 2026] [security2:error] [pid 78969:tid 79209] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eT3DvNPGtvLGb7O3-lgAA8wM"]
[Mon Jul 20 07:10:39.211744 2026] [security2:error] [pid 78969:tid 79106] [client 77.110.127.138:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eT3DvNPGtvLGb7O3-mgAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:39.211889 2026] [security2:error] [pid 78969:tid 79106] [client 77.110.127.138:64731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eT3DvNPGtvLGb7O3-mgAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:39.327501 2026] [security2:error] [pid 78969:tid 79220] [client 194.61.41.67:36137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-t.api.php"] [unique_id "al4eT3DvNPGtvLGb7O3-pAAAAP4"]
[Mon Jul 20 07:10:39.401658 2026] [security2:error] [pid 78969:tid 79169] [client 117.211.236.168:54093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eT3DvNPGtvLGb7O3-rgAAAMs"]
[Mon Jul 20 07:10:39.401797 2026] [security2:error] [pid 78969:tid 79169] [client 117.211.236.168:54093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eT3DvNPGtvLGb7O3-rgAAAMs"]
[Mon Jul 20 07:10:40.009458 2026] [security2:error] [pid 78969:tid 79225] [client 88.241.67.160:53717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eUHDvNPGtvLGb7O3-3QAAAQM"]
[Mon Jul 20 07:10:40.009825 2026] [security2:error] [pid 78969:tid 79225] [client 88.241.67.160:53717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eUHDvNPGtvLGb7O3-3QAAAQM"]
[Mon Jul 20 07:10:40.032046 2026] [security2:error] [pid 78969:tid 79219] [client 194.61.41.96:21127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/edit.php"] [unique_id "al4eUHDvNPGtvLGb7O3-3wAAAP0"]
[Mon Jul 20 07:10:40.140534 2026] [security2:error] [pid 78969:tid 79164] [client 103.144.65.217:49265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eUHDvNPGtvLGb7O3-6QAAAMY"]
[Mon Jul 20 07:10:40.140663 2026] [security2:error] [pid 78969:tid 79164] [client 103.144.65.217:49265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eUHDvNPGtvLGb7O3-6QAAAMY"]
[Mon Jul 20 07:10:40.275828 2026] [lsapi:warn] [pid 78969:tid 79038] [remote 172.215.218.101:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:10:40.419628 2026] [security2:error] [pid 78969:tid 79096] [remote 57.141.18.50:39172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4eUHDvNPGtvLGb7O3_AwAA5H4"]
[Mon Jul 20 07:10:40.503280 2026] [security2:error] [pid 78969:tid 79068] [remote 220.181.108.146:20367] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4eUHDvNPGtvLGb7O3_CwAAmGI"]
[Mon Jul 20 07:10:40.551594 2026] [security2:error] [pid 78969:tid 79101] [client 74.208.214.194:51834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4eUHDvNPGtvLGb7O3_DgAAAIc"]
[Mon Jul 20 07:10:40.751108 2026] [security2:error] [pid 78969:tid 79148] [client 194.61.41.96:56909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/info.php"] [unique_id "al4eUHDvNPGtvLGb7O3_HQAAALY"]
[Mon Jul 20 07:10:41.502241 2026] [access_compat:error] [pid 78969:tid 79101] [client 183.47.122.213:33477] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:10:41.548360 2026] [security2:error] [pid 78969:tid 79155] [client 194.61.41.242:40833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/autoload_classmap.php"] [unique_id "al4eUXDvNPGtvLGb7O3_WgAAAL0"]
[Mon Jul 20 07:10:41.749007 2026] [security2:error] [pid 78969:tid 79220] [client 208.78.81.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4eUXDvNPGtvLGb7O3_XAAAAP4"]
[Mon Jul 20 07:10:41.759901 2026] [security2:error] [pid 78969:tid 78985] [remote 57.141.18.21:56812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4eUXDvNPGtvLGb7O3_bAAAmA8"]
[Mon Jul 20 07:10:41.849164 2026] [security2:error] [pid 78969:tid 79020] [remote 81.173.115.7:45502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eUXDvNPGtvLGb7O3_cAAAmTI"]
[Mon Jul 20 07:10:41.849349 2026] [security2:error] [pid 78969:tid 79119] [client 81.173.115.7:45502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eUXDvNPGtvLGb7O3_cAAAmTI"]
[Mon Jul 20 07:10:41.920213 2026] [security2:error] [pid 78969:tid 79141] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eUXDvNPGtvLGb7O3_ZwAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:42.007593 2026] [security2:error] [pid 78969:tid 78993] [remote 111.225.214.183:48668] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4eUnDvNPGtvLGb7O3_fgAAqxc"]
[Mon Jul 20 07:10:42.017363 2026] [security2:error] [pid 78969:tid 78975] [remote 5.161.225.162:33428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4eUnDvNPGtvLGb7O3_fwAA3AU"]
[Mon Jul 20 07:10:42.017520 2026] [security2:error] [pid 78969:tid 79186] [client 5.161.225.162:33428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4eUnDvNPGtvLGb7O3_fwAA3AU"]
[Mon Jul 20 07:10:42.151814 2026] [security2:error] [pid 78969:tid 79187] [client 77.110.127.138:64753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eUnDvNPGtvLGb7O3_iAAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:42.151905 2026] [security2:error] [pid 78969:tid 79187] [client 77.110.127.138:64753] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eUnDvNPGtvLGb7O3_iAAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:42.334804 2026] [security2:error] [pid 78969:tid 79133] [client 194.61.41.81:40115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/navi.php"] [unique_id "al4eUnDvNPGtvLGb7O3_mgAAAKc"]
[Mon Jul 20 07:10:42.671650 2026] [security2:error] [pid 78969:tid 79199] [client 201.27.111.74:49307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eUnDvNPGtvLGb7O3_wgAAAOk"]
[Mon Jul 20 07:10:42.671763 2026] [security2:error] [pid 78969:tid 79199] [client 201.27.111.74:49307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eUnDvNPGtvLGb7O3_wgAAAOk"]
[Mon Jul 20 07:10:42.732638 2026] [security2:error] [pid 78969:tid 79195] [client 14.225.17.146:52778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4eUXDvNPGtvLGb7O3_MQAAAOU"], referer: http://margaretspeckogawa.com/2024
[Mon Jul 20 07:10:42.890287 2026] [security2:error] [pid 78969:tid 79212] [client 34.204.82.126:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eUnDvNPGtvLGb7O3_vQAA9hY"]
[Mon Jul 20 07:10:42.925253 2026] [access_compat:error] [pid 78969:tid 79200] [client 112.90.2.141:38889] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php
[Mon Jul 20 07:10:43.023956 2026] [security2:error] [pid 78969:tid 79102] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eUnDvNPGtvLGb7O3_ywAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:43.061985 2026] [security2:error] [pid 78969:tid 79058] [remote 173.212.252.15:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eU3DvNPGtvLGb7O3_5QAArFg"]
[Mon Jul 20 07:10:43.069842 2026] [security2:error] [pid 78969:tid 79176] [client 194.61.41.68:24439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/require-dynamic-blocks.php"] [unique_id "al4eU3DvNPGtvLGb7O3_6QAAANI"]
[Mon Jul 20 07:10:43.256558 2026] [security2:error] [pid 78969:tid 79028] [remote 173.212.252.15:45596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eU3DvNPGtvLGb7O3_8AAA4Do"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:10:43.656648 2026] [security2:error] [pid 78969:tid 79193] [client 14.225.17.146:61636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4eUnDvNPGtvLGb7O3_vwAAAOM"], referer: http://adultdaycarereno.com/2024
[Mon Jul 20 07:10:43.752370 2026] [security2:error] [pid 78969:tid 79004] [remote 160.187.68.132:43038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eU3DvNPGtvLGb7O0AFwAA5SI"]
[Mon Jul 20 07:10:43.795329 2026] [security2:error] [pid 78969:tid 79168] [client 57.141.18.43:55930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eUnDvNPGtvLGb7O3_wAAAyhA"]
[Mon Jul 20 07:10:43.827335 2026] [security2:error] [pid 78969:tid 79154] [client 194.61.41.242:34715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/xp.php%20"] [unique_id "al4eU3DvNPGtvLGb7O0AIwAAALw"]
[Mon Jul 20 07:10:43.855483 2026] [security2:error] [pid 78969:tid 79131] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eU3DvNPGtvLGb7O0ACQAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:44.005581 2026] [security2:error] [pid 78969:tid 79160] [client 14.225.17.146:53042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4eUXDvNPGtvLGb7O3_bgAAAMI"], referer: http://nomorewetsheets.net/2024
[Mon Jul 20 07:10:44.192147 2026] [security2:error] [pid 78969:tid 79203] [client 14.225.17.146:61205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4eVHDvNPGtvLGb7O0ALQAAAO0"], referer: http://superiorcopywriting.com/2024
[Mon Jul 20 07:10:44.216736 2026] [security2:error] [pid 78969:tid 79021] [remote 160.187.68.132:43038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eVHDvNPGtvLGb7O0APgAA5TM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:10:44.264166 2026] [security2:error] [pid 78969:tid 79173] [client 14.225.17.146:61391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4eUnDvNPGtvLGb7O3_kAAAAM8"], referer: http://itdynamix.com/2024
[Mon Jul 20 07:10:44.534058 2026] [security2:error] [pid 78969:tid 79101] [client 194.61.41.242:37045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/bypass.php"] [unique_id "al4eVHDvNPGtvLGb7O0AVwAAAIc"]
[Mon Jul 20 07:10:44.592539 2026] [security2:error] [pid 78969:tid 79224] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eVHDvNPGtvLGb7O0ATQAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:44.644033 2026] [security2:error] [pid 78969:tid 79130] [client 14.225.17.146:60957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4eVHDvNPGtvLGb7O0AXgAAAKQ"], referer: https://adultdaycarereno.com/2024
[Mon Jul 20 07:10:44.896058 2026] [security2:error] [pid 78969:tid 79222] [client 77.110.127.138:64766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eVHDvNPGtvLGb7O0AdgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:44.896226 2026] [security2:error] [pid 78969:tid 79222] [client 77.110.127.138:64766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eVHDvNPGtvLGb7O0AdgAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:44.915419 2026] [core:error] [pid 78969:tid 79169] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:10:44.915440 2026] [core:error] [pid 78969:tid 79169] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:10:45.040868 2026] [security2:error] [pid 78969:tid 79143] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eVHDvNPGtvLGb7O0AcAAAALE"]
[Mon Jul 20 07:10:45.261891 2026] [security2:error] [pid 78969:tid 79148] [client 47.128.21.146:20366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.vfcthomasville.org"] [uri "/robots.txt"] [unique_id "al4eVXDvNPGtvLGb7O0AjwAAALY"]
[Mon Jul 20 07:10:45.312014 2026] [security2:error] [pid 78969:tid 79219] [client 14.225.17.146:61183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4eVXDvNPGtvLGb7O0AhwAAAP0"], referer: https://itdynamix.com/2024
[Mon Jul 20 07:10:45.327357 2026] [security2:error] [pid 78969:tid 79220] [client 194.61.41.78:32785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/bypass_1.php"] [unique_id "al4eVXDvNPGtvLGb7O0AlwAAAP4"]
[Mon Jul 20 07:10:45.395363 2026] [security2:error] [pid 78969:tid 79046] [remote 117.0.21.154:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eVXDvNPGtvLGb7O0AnAAAlUw"]
[Mon Jul 20 07:10:45.553967 2026] [security2:error] [pid 78969:tid 79205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eVXDvNPGtvLGb7O0AkwAAAO8"]
[Mon Jul 20 07:10:45.941453 2026] [security2:error] [pid 78969:tid 78984] [remote 117.0.21.154:42260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eVXDvNPGtvLGb7O0A2AAAzw4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:10:46.021836 2026] [security2:error] [pid 78969:tid 79135] [client 43.159.135.203:55364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4eVXDvNPGtvLGb7O0A1QAAAKk"]
[Mon Jul 20 07:10:46.030739 2026] [security2:error] [pid 78969:tid 79108] [client 194.61.41.80:23003] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/elementskit.php"] [unique_id "al4eVnDvNPGtvLGb7O0A3AAAAI4"]
[Mon Jul 20 07:10:46.148986 2026] [security2:error] [pid 78969:tid 79092] [remote 124.55.178.99:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4eVnDvNPGtvLGb7O0A5QAAmHo"]
[Mon Jul 20 07:10:46.591905 2026] [security2:error] [pid 78969:tid 79072] [remote 124.55.178.99:45690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4eVnDvNPGtvLGb7O0BDgAAzGY"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 07:10:46.752152 2026] [security2:error] [pid 78969:tid 79121] [client 194.61.41.85:51635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-wp-widget-rss-database.php"] [unique_id "al4eVnDvNPGtvLGb7O0BFQAAAJs"]
[Mon Jul 20 07:10:46.875616 2026] [security2:error] [pid 78969:tid 78987] [remote 154.0.166.254:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4eVnDvNPGtvLGb7O0BHwAAxxE"]
[Mon Jul 20 07:10:46.978041 2026] [security2:error] [pid 78969:tid 79127] [client 57.141.18.72:63054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eVXDvNPGtvLGb7O0AnwAAoQQ"]
[Mon Jul 20 07:10:47.120192 2026] [security2:error] [pid 78969:tid 79116] [client 37.139.53.11:58056] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "37.139.53.11" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4eV3DvNPGtvLGb7O0BMQAAAJY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 07:10:47.120302 2026] [security2:error] [pid 78969:tid 79116] [client 37.139.53.11:58056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4eV3DvNPGtvLGb7O0BMQAAAJY"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 07:10:47.133703 2026] [security2:error] [pid 78969:tid 79197] [client 14.225.17.146:61169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4eVXDvNPGtvLGb7O0AqgAAAOc"], referer: http://careysheatingandcooling.com/2024
[Mon Jul 20 07:10:47.402206 2026] [core:error] [pid 78969:tid 79126] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:10:47.402225 2026] [core:error] [pid 78969:tid 79126] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:10:47.404111 2026] [security2:error] [pid 78969:tid 79115] [client 14.225.17.146:52582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4eV3DvNPGtvLGb7O0BNAAAAJU"]
[Mon Jul 20 07:10:47.443727 2026] [security2:error] [pid 78969:tid 78978] [remote 154.0.166.254:45002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4eV3DvNPGtvLGb7O0BVQAA1wg"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 07:10:47.549225 2026] [security2:error] [pid 78969:tid 79154] [client 194.61.41.81:37857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/kur.php"] [unique_id "al4eV3DvNPGtvLGb7O0BWgAAALw"]
[Mon Jul 20 07:10:47.867008 2026] [security2:error] [pid 78969:tid 79206] [client 14.225.17.146:52573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4eVnDvNPGtvLGb7O0A4QAAAPA"]
[Mon Jul 20 07:10:47.947250 2026] [security2:error] [pid 78969:tid 79118] [client 47.128.54.32:19490] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/robots.txt"] [unique_id "al4eV3DvNPGtvLGb7O0BhQAAAJg"]
[Mon Jul 20 07:10:47.954746 2026] [security2:error] [pid 78969:tid 79198] [client 57.141.18.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eV3DvNPGtvLGb7O0BdAAAAOg"]
[Mon Jul 20 07:10:48.130830 2026] [security2:error] [pid 78969:tid 79035] [remote 47.86.33.52:29924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eWHDvNPGtvLGb7O0BkgAA9EE"]
[Mon Jul 20 07:10:48.230999 2026] [security2:error] [pid 78969:tid 79195] [client 14.225.17.146:52493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4eVnDvNPGtvLGb7O0BFwAAAOU"], referer: http://chestermonty.com/2024
[Mon Jul 20 07:10:48.280083 2026] [security2:error] [pid 78969:tid 79167] [client 149.20.244.37:35039] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4eWHDvNPGtvLGb7O0BmAAAAMk"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 07:10:48.310476 2026] [security2:error] [pid 78969:tid 79052] [remote 119.249.100.177:8327] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4eWHDvNPGtvLGb7O0BpAAAxFI"]
[Mon Jul 20 07:10:48.327127 2026] [security2:error] [pid 78969:tid 79194] [client 194.61.41.102:37021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/click.php"] [unique_id "al4eWHDvNPGtvLGb7O0BqAAAAOQ"]
[Mon Jul 20 07:10:48.340982 2026] [security2:error] [pid 78969:tid 79116] [client 77.110.127.138:64784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eWHDvNPGtvLGb7O0BqQAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:48.341091 2026] [security2:error] [pid 78969:tid 79116] [client 77.110.127.138:64784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eWHDvNPGtvLGb7O0BqQAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:48.370080 2026] [security2:error] [pid 78969:tid 79212] [client 82.102.18.116:49746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "mail.fic.zzt.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4eWHDvNPGtvLGb7O0BrgAAAPY"]
[Mon Jul 20 07:10:48.486347 2026] [security2:error] [pid 78969:tid 79163] [client 14.225.17.146:52575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4eWHDvNPGtvLGb7O0BoAAAAMU"], referer: http://falconarrowshop.com/2024
[Mon Jul 20 07:10:48.740275 2026] [security2:error] [pid 78969:tid 79142] [client 82.102.18.116:60820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eWHDvNPGtvLGb7O0BwQAAALA"]
[Mon Jul 20 07:10:48.766182 2026] [security2:error] [pid 78969:tid 79122] [client 50.116.65.227:59534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eWHDvNPGtvLGb7O0BwgAAAJw"]
[Mon Jul 20 07:10:48.776903 2026] [security2:error] [pid 78969:tid 79196] [client 50.116.65.227:59538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eWHDvNPGtvLGb7O0BxAAAAOY"]
[Mon Jul 20 07:10:48.829536 2026] [security2:error] [pid 78969:tid 79061] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eWHDvNPGtvLGb7O0ByAAA01s"]
[Mon Jul 20 07:10:48.829727 2026] [security2:error] [pid 78969:tid 79177] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eWHDvNPGtvLGb7O0ByAAA01s"]
[Mon Jul 20 07:10:48.841608 2026] [security2:error] [pid 78969:tid 79166] [client 45.157.112.60:24291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eWHDvNPGtvLGb7O0ByQAAAMg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:49.057906 2026] [security2:error] [pid 78969:tid 79204] [client 194.61.41.248:32113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-customize-manager-client.php"] [unique_id "al4eWXDvNPGtvLGb7O0B5QAAAO4"]
[Mon Jul 20 07:10:49.079377 2026] [security2:error] [pid 78969:tid 79222] [client 66.249.88.232:54392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.rvprintfactory.com"] [uri "/index.php"] [unique_id "al4eV3DvNPGtvLGb7O0BbwAAAQA"]
[Mon Jul 20 07:10:49.275380 2026] [security2:error] [pid 78969:tid 79106] [client 14.225.17.146:52677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4eWXDvNPGtvLGb7O0B7QAAAIw"], referer: http://swafforddetailing.com/2024
[Mon Jul 20 07:10:49.369623 2026] [security2:error] [pid 78969:tid 79100] [client 14.225.17.146:61145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4eWXDvNPGtvLGb7O0B9AAAAIY"], referer: https://chestermonty.com/2024
[Mon Jul 20 07:10:49.484857 2026] [security2:error] [pid 78969:tid 79203] [client 187.16.64.216:62980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eWXDvNPGtvLGb7O0CEgAAAO0"]
[Mon Jul 20 07:10:49.484986 2026] [security2:error] [pid 78969:tid 79203] [client 187.16.64.216:62980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eWXDvNPGtvLGb7O0CEgAAAO0"]
[Mon Jul 20 07:10:49.509522 2026] [security2:error] [pid 78969:tid 79187] [client 35.173.141.237:24619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4eV3DvNPGtvLGb7O0BLgAA3Xw"]
[Mon Jul 20 07:10:49.866404 2026] [security2:error] [pid 78969:tid 79224] [client 194.61.41.78:24673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/script-modules-packages.min-boolean.php"] [unique_id "al4eWXDvNPGtvLGb7O0CMQAAAQI"]
[Mon Jul 20 07:10:49.874297 2026] [security2:error] [pid 78969:tid 78984] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eWXDvNPGtvLGb7O0CNQABAw4"]
[Mon Jul 20 07:10:49.874475 2026] [security2:error] [pid 78969:tid 79225] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eWXDvNPGtvLGb7O0CNQABAw4"]
[Mon Jul 20 07:10:49.875783 2026] [security2:error] [pid 78969:tid 79020] [remote 91.142.222.105:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eWXDvNPGtvLGb7O0CNAAAzjI"]
[Mon Jul 20 07:10:50.000933 2026] [security2:error] [pid 78969:tid 79102] [client 14.225.17.146:52555] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4eWHDvNPGtvLGb7O0BuAAAAIg"], referer: http://alexsandbergmusic.com/2024
[Mon Jul 20 07:10:50.054831 2026] [security2:error] [pid 78969:tid 79179] [client 54.204.158.117:59046] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4eWnDvNPGtvLGb7O0CSwAAANU"]
[Mon Jul 20 07:10:50.068782 2026] [security2:error] [pid 78969:tid 79212] [client 35.173.141.237:24619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4eWXDvNPGtvLGb7O0CKQAA9lw"], referer: http://hilltopnurseryinc.com/robots.txt
[Mon Jul 20 07:10:50.137555 2026] [security2:error] [pid 78969:tid 79003] [remote 91.142.222.105:36818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eWnDvNPGtvLGb7O0CUQAA9CE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:10:50.142512 2026] [security2:error] [pid 78969:tid 79144] [client 14.225.17.146:60486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4eWHDvNPGtvLGb7O0BygAAALI"], referer: http://collectingrealestate.com/2024
[Mon Jul 20 07:10:50.343260 2026] [security2:error] [pid 78969:tid 79211] [client 82.102.18.116:60824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eWnDvNPGtvLGb7O0CaQAAAPU"]
[Mon Jul 20 07:10:50.343405 2026] [security2:error] [pid 78969:tid 79211] [client 82.102.18.116:60824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eWnDvNPGtvLGb7O0CaQAAAPU"]
[Mon Jul 20 07:10:50.511318 2026] [security2:error] [pid 78969:tid 79057] [remote 182.77.62.24:45614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4eWnDvNPGtvLGb7O0CdwAA0Fc"]
[Mon Jul 20 07:10:50.605792 2026] [security2:error] [pid 78969:tid 79109] [client 50.116.65.227:54662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4eWnDvNPGtvLGb7O0CgAAAAI8"]
[Mon Jul 20 07:10:50.607638 2026] [security2:error] [pid 78969:tid 79079] [remote 84.247.172.23:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eWnDvNPGtvLGb7O0CfwAAwW0"]
[Mon Jul 20 07:10:50.611061 2026] [security2:error] [pid 78969:tid 79193] [client 34.52.240.235:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4eWXDvNPGtvLGb7O0B8gAAAOM"]
[Mon Jul 20 07:10:50.648597 2026] [security2:error] [pid 78969:tid 79116] [client 88.241.67.160:54811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eWnDvNPGtvLGb7O0ChQAAAJY"]
[Mon Jul 20 07:10:50.649315 2026] [security2:error] [pid 78969:tid 79116] [client 88.241.67.160:54811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eWnDvNPGtvLGb7O0ChQAAAJY"]
[Mon Jul 20 07:10:50.659068 2026] [security2:error] [pid 78969:tid 79126] [client 194.61.41.253:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/error.php"] [unique_id "al4eWnDvNPGtvLGb7O0ChwAAAKA"]
[Mon Jul 20 07:10:50.727061 2026] [security2:error] [pid 78969:tid 79162] [client 103.144.65.217:49722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eWnDvNPGtvLGb7O0CjAAAAMQ"]
[Mon Jul 20 07:10:50.727165 2026] [security2:error] [pid 78969:tid 79162] [client 103.144.65.217:49722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eWnDvNPGtvLGb7O0CjAAAAMQ"]
[Mon Jul 20 07:10:51.033451 2026] [security2:error] [pid 78969:tid 79173] [client 158.173.166.181:20759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eW3DvNPGtvLGb7O0CpwAAAM8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:51.303074 2026] [security2:error] [pid 78969:tid 79167] [client 149.20.244.37:35039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4eWHDvNPGtvLGb7O0BmAAAAMk"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 07:10:51.303138 2026] [security2:error] [pid 78969:tid 79167] [client 149.20.244.37:35039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "innspace.ca"] [uri "/wp-comments-post.php"] [unique_id "al4eWHDvNPGtvLGb7O0BmAAAAMk"], referer: https://innspace.ca/theres-room-at-the-inn/
[Mon Jul 20 07:10:51.305432 2026] [security2:error] [pid 78969:tid 79177] [client 44.245.170.32:61924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4eW3DvNPGtvLGb7O0CvwAAANM"]
[Mon Jul 20 07:10:51.354603 2026] [security2:error] [pid 78969:tid 79158] [client 98.85.250.161:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4eWnDvNPGtvLGb7O0CcwAAAMA"]
[Mon Jul 20 07:10:51.376514 2026] [security2:error] [pid 78969:tid 79200] [client 98.85.250.161:63586] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink"] [unique_id "al4eWnDvNPGtvLGb7O0CcAAAAOo"]
[Mon Jul 20 07:10:51.413379 2026] [security2:error] [pid 78969:tid 79193] [client 194.61.41.251:52467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ALFA_DATA/alfacgiapi/all.php"] [unique_id "al4eW3DvNPGtvLGb7O0CxQAAAOM"]
[Mon Jul 20 07:10:51.422490 2026] [security2:error] [pid 78969:tid 78973] [remote 182.77.62.24:45614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4eW3DvNPGtvLGb7O0CxgAAjwM"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 07:10:51.641118 2026] [security2:error] [pid 78969:tid 78996] [remote 47.86.33.52:48024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eW3DvNPGtvLGb7O0C2AAA9ho"]
[Mon Jul 20 07:10:51.993899 2026] [security2:error] [pid 78969:tid 79159] [client 117.211.236.168:54606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eW3DvNPGtvLGb7O0C7gAAAME"]
[Mon Jul 20 07:10:51.994055 2026] [security2:error] [pid 78969:tid 79159] [client 117.211.236.168:54606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eW3DvNPGtvLGb7O0C7gAAAME"]
[Mon Jul 20 07:10:52.098537 2026] [security2:error] [pid 78969:tid 79187] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4eW3DvNPGtvLGb7O0C5gAA3Uk"], referer: http://ali-alghanim.net/2024
[Mon Jul 20 07:10:52.144893 2026] [security2:error] [pid 78969:tid 79151] [client 194.61.41.71:60949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/autoload_classmap.php"] [unique_id "al4eXHDvNPGtvLGb7O0DAwAAALk"]
[Mon Jul 20 07:10:52.175977 2026] [security2:error] [pid 78969:tid 79090] [remote 84.247.172.23:60934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eXHDvNPGtvLGb7O0DCAAArXg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:10:52.213114 2026] [security2:error] [pid 78969:tid 79135] [client 114.119.148.163:23103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/getting-chickens-picking-out-baby-chicks/"] [unique_id "al4eXHDvNPGtvLGb7O0DCQAAAKk"], referer: https://tweetoflove.com/supplies-youll-need-for-baby-chicks-the-well-oiled-life/
[Mon Jul 20 07:10:52.360308 2026] [security2:error] [pid 78969:tid 79108] [client 98.85.250.161:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4eW3DvNPGtvLGb7O0C0wAAAI4"]
[Mon Jul 20 07:10:52.375149 2026] [security2:error] [pid 78969:tid 79218] [client 98.85.250.161:63600] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4eW3DvNPGtvLGb7O0CzgAAAPw"]
[Mon Jul 20 07:10:52.722135 2026] [security2:error] [pid 78969:tid 79144] [client 14.225.17.146:60564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4eW3DvNPGtvLGb7O0C1gAAALI"], referer: http://nikkidesigns.net/2024
[Mon Jul 20 07:10:52.811684 2026] [security2:error] [pid 78969:tid 79167] [client 77.110.127.138:64804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eXHDvNPGtvLGb7O0DOwAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:52.811806 2026] [security2:error] [pid 78969:tid 79167] [client 77.110.127.138:64804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eXHDvNPGtvLGb7O0DOwAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:52.925995 2026] [security2:error] [pid 78969:tid 79069] [remote 47.86.33.52:29924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eXHDvNPGtvLGb7O0DRAAAmmM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:10:52.955073 2026] [security2:error] [pid 78969:tid 79137] [client 194.61.41.77:28335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/xmrlpc.php"] [unique_id "al4eXHDvNPGtvLGb7O0DRQAAAKs"]
[Mon Jul 20 07:10:53.147654 2026] [security2:error] [pid 78969:tid 79226] [client 98.158.230.246:57830] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ccsdifference.com"] [uri "/wp-content/themes/ccs/dist/fonts/ArialRegular.715e0c52.woff2"] [unique_id "al4eXXDvNPGtvLGb7O0DVAABBGE"]
[Mon Jul 20 07:10:53.183677 2026] [security2:error] [pid 78969:tid 79143] [client 201.27.111.74:49993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eXXDvNPGtvLGb7O0DWgAAALE"]
[Mon Jul 20 07:10:53.183842 2026] [security2:error] [pid 78969:tid 79143] [client 201.27.111.74:49993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eXXDvNPGtvLGb7O0DWgAAALE"]
[Mon Jul 20 07:10:53.376166 2026] [security2:error] [pid 78969:tid 79206] [client 98.158.230.246:53884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.ccsdifference.com"] [uri "/wp-content/themes/ccs/dist/fonts/Arial-Bold.aba93faf.woff2"] [unique_id "al4eXXDvNPGtvLGb7O0DaAAA8Ew"]
[Mon Jul 20 07:10:53.456557 2026] [security2:error] [pid 78969:tid 79064] [remote 47.86.33.52:48024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eXXDvNPGtvLGb7O0DcQAA5F4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:10:53.636815 2026] [security2:error] [pid 78969:tid 79195] [client 158.173.89.95:47789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eXXDvNPGtvLGb7O0DfAAAAOU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:53.720487 2026] [security2:error] [pid 78969:tid 79173] [client 194.61.41.71:37479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/repairs.php"] [unique_id "al4eXXDvNPGtvLGb7O0DiAAAAM8"]
[Mon Jul 20 07:10:54.181385 2026] [security2:error] [pid 78969:tid 79183] [client 77.110.127.138:64808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eXnDvNPGtvLGb7O0DqAAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:54.181491 2026] [security2:error] [pid 78969:tid 79183] [client 77.110.127.138:64808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eXnDvNPGtvLGb7O0DqAAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:54.432939 2026] [security2:error] [pid 78969:tid 79168] [client 194.61.41.79:64247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/smilies/simi.php"] [unique_id "al4eXnDvNPGtvLGb7O0DvgAAAMo"]
[Mon Jul 20 07:10:54.475073 2026] [security2:error] [pid 78969:tid 79154] [client 104.234.53.93:58359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eXnDvNPGtvLGb7O0DwAAAALw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:54.516580 2026] [security2:error] [pid 78969:tid 79176] [client 116.179.33.142:8114] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4eXnDvNPGtvLGb7O0DxgAAANI"]
[Mon Jul 20 07:10:55.233700 2026] [security2:error] [pid 78969:tid 79216] [client 194.61.41.76:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin.php"] [unique_id "al4eX3DvNPGtvLGb7O0D-gAAAPo"]
[Mon Jul 20 07:10:55.730387 2026] [security2:error] [pid 78969:tid 79202] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eX3DvNPGtvLGb7O0EGQAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:55.866093 2026] [security2:error] [pid 78969:tid 79180] [client 17.246.15.37:40458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4eX3DvNPGtvLGb7O0ECgAA1nc"], referer: https://betterbonddogtraining.com/
[Mon Jul 20 07:10:56.030667 2026] [security2:error] [pid 78969:tid 79207] [client 14.225.17.146:60769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4eXnDvNPGtvLGb7O0D3gAAAPE"], referer: http://northbrookcpa.ca/2024
[Mon Jul 20 07:10:56.039829 2026] [security2:error] [pid 78969:tid 79168] [client 194.61.41.91:22847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-header.php%20"] [unique_id "al4eYHDvNPGtvLGb7O0EQQAAAMo"]
[Mon Jul 20 07:10:56.141530 2026] [security2:error] [pid 78969:tid 79026] [remote 68.178.160.25:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eYHDvNPGtvLGb7O0ERwAA9Tg"]
[Mon Jul 20 07:10:56.280197 2026] [security2:error] [pid 78969:tid 79115] [client 104.234.53.55:28039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4eYHDvNPGtvLGb7O0EVAAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:10:56.558880 2026] [security2:error] [pid 78969:tid 79052] [remote 68.178.160.25:52336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eYHDvNPGtvLGb7O0EbAAAmFI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:10:56.824913 2026] [security2:error] [pid 78969:tid 79038] [remote 124.55.178.99:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eYHDvNPGtvLGb7O0EfAAAtEQ"]
[Mon Jul 20 07:10:56.840433 2026] [security2:error] [pid 78969:tid 79196] [client 194.61.41.73:56681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/file.php%20"] [unique_id "al4eYHDvNPGtvLGb7O0EfgAAAOY"]
[Mon Jul 20 07:10:56.967825 2026] [security2:error] [pid 78969:tid 79160] [client 17.246.15.37:40458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4eYHDvNPGtvLGb7O0EegAAwls"], referer: https://betterbonddogtraining.com/
[Mon Jul 20 07:10:57.063807 2026] [security2:error] [pid 78969:tid 79137] [client 77.110.127.138:64819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eYXDvNPGtvLGb7O0EkAAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:57.063984 2026] [security2:error] [pid 78969:tid 79137] [client 77.110.127.138:64819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eYXDvNPGtvLGb7O0EkAAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:57.180537 2026] [security2:error] [pid 78969:tid 79210] [client 14.225.17.146:60786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4eYHDvNPGtvLGb7O0EdwAAAPQ"], referer: http://fkconstructionfunding.com/2024
[Mon Jul 20 07:10:57.255820 2026] [security2:error] [pid 78969:tid 79059] [remote 124.55.178.99:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eYXDvNPGtvLGb7O0ElgAAlVk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:10:57.440266 2026] [security2:error] [pid 78969:tid 79224] [client 14.225.17.146:49426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4eX3DvNPGtvLGb7O0ECAAAAQI"], referer: http://dollpassionista.com/2024
[Mon Jul 20 07:10:57.574495 2026] [security2:error] [pid 78969:tid 79162] [client 50.116.65.227:49164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4eYXDvNPGtvLGb7O0EoAAAAMQ"]
[Mon Jul 20 07:10:57.659266 2026] [security2:error] [pid 78969:tid 79217] [client 194.61.41.247:55779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.tmb/doc.php"] [unique_id "al4eYXDvNPGtvLGb7O0EwQAAAPs"]
[Mon Jul 20 07:10:57.664934 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eYXDvNPGtvLGb7O0ErwAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:57.787377 2026] [security2:error] [pid 78969:tid 79177] [client 50.116.65.227:49184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4eYXDvNPGtvLGb7O0EvAAAANM"]
[Mon Jul 20 07:10:58.237672 2026] [proxy:error] [pid 78969:tid 79214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:10:58.237775 2026] [proxy_http:error] [pid 78969:tid 79214] [client 205.210.31.24:62896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:10:58.238434 2026] [proxy:error] [pid 78969:tid 79214] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:10:58.238462 2026] [proxy_http:error] [pid 78969:tid 79214] [client 205.210.31.24:62896] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:10:58.284968 2026] [security2:error] [pid 78969:tid 79201] [client 14.225.17.146:50844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4eYnDvNPGtvLGb7O0E5gAAAOs"], referer: http://uritems.net/2024
[Mon Jul 20 07:10:58.353565 2026] [security2:error] [pid 78969:tid 79148] [client 14.225.17.146:64541] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4eYHDvNPGtvLGb7O0EUgAAALY"], referer: http://savilerowtravel.com/2024
[Mon Jul 20 07:10:58.451922 2026] [security2:error] [pid 78969:tid 79141] [client 194.61.41.249:43125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-editor.php"] [unique_id "al4eYnDvNPGtvLGb7O0FDQAAAK8"]
[Mon Jul 20 07:10:58.551028 2026] [security2:error] [pid 78969:tid 78993] [remote 86.107.77.57:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.77.107.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4eYnDvNPGtvLGb7O0FFQABABc"]
[Mon Jul 20 07:10:58.632634 2026] [security2:error] [pid 78969:tid 79221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eYnDvNPGtvLGb7O0FBwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:58.664393 2026] [security2:error] [pid 78969:tid 79216] [client 14.225.17.146:50068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4eYnDvNPGtvLGb7O0FEAAAAPo"], referer: https://dollpassionista.com/2024
[Mon Jul 20 07:10:58.689288 2026] [security2:error] [pid 78969:tid 79205] [client 57.141.18.20:30164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eYXDvNPGtvLGb7O0EuwAA73k"]
[Mon Jul 20 07:10:58.708950 2026] [security2:error] [pid 78969:tid 79127] [client 194.180.48.253:33844] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "ccgranvillecorp.org"] [uri "/"] [unique_id "al4eYnDvNPGtvLGb7O0FIQAAAKE"]
[Mon Jul 20 07:10:58.727249 2026] [security2:error] [pid 78969:tid 78990] [remote 86.107.77.57:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.77.107.86.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4eYnDvNPGtvLGb7O0FJAAAkBQ"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 07:10:58.756885 2026] [security2:error] [pid 78969:tid 79135] [client 14.225.17.146:50557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4eYXDvNPGtvLGb7O0EwAAAAKk"], referer: http://travelbyfire.com/2024
[Mon Jul 20 07:10:58.872989 2026] [core:error] [pid 78969:tid 79158] [client 198.235.24.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:10:58.873008 2026] [core:error] [pid 78969:tid 79158] [client 198.235.24.136:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:10:59.237363 2026] [security2:error] [pid 78969:tid 79135] [client 194.61.41.75:33947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine-session.php"] [unique_id "al4eY3DvNPGtvLGb7O0FVAAAAKk"]
[Mon Jul 20 07:10:59.324118 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eY3DvNPGtvLGb7O0FSwAAAOg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:59.345999 2026] [security2:error] [pid 78969:tid 79146] [client 98.159.234.160:44819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eY3DvNPGtvLGb7O0FWwAAALQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:10:59.403525 2026] [security2:error] [pid 78969:tid 79186] [client 77.110.127.138:64832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eY3DvNPGtvLGb7O0FXQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:59.403622 2026] [security2:error] [pid 78969:tid 79186] [client 77.110.127.138:64832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eY3DvNPGtvLGb7O0FXQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:10:59.497603 2026] [security2:error] [pid 78969:tid 79006] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eY3DvNPGtvLGb7O0FaQAAkSQ"]
[Mon Jul 20 07:10:59.497816 2026] [security2:error] [pid 78969:tid 79111] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eY3DvNPGtvLGb7O0FaQAAkSQ"]
[Mon Jul 20 07:10:59.569496 2026] [security2:error] [pid 78969:tid 79164] [client 116.62.81.204:42426] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eY3DvNPGtvLGb7O0FagAAAMY"]
[Mon Jul 20 07:10:59.666199 2026] [security2:error] [pid 78969:tid 79165] [client 192.178.6.105:51925] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.astoryunwritten.com"] [uri "/robots.txt"] [unique_id "al4eY3DvNPGtvLGb7O0FdwAAAMc"]
[Mon Jul 20 07:10:59.717029 2026] [security2:error] [pid 78969:tid 79194] [client 14.225.17.146:50652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4eY3DvNPGtvLGb7O0FdgAAAOQ"], referer: https://travelbyfire.com/2024
[Mon Jul 20 07:10:59.717392 2026] [security2:error] [pid 78969:tid 79164] [client 116.62.81.204:42426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eY3DvNPGtvLGb7O0FagAAAMY"]
[Mon Jul 20 07:10:59.980834 2026] [security2:error] [pid 78969:tid 79171] [client 14.225.17.146:50991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4eY3DvNPGtvLGb7O0FggAAAM0"], referer: http://taskidsvirginia.com/2024
[Mon Jul 20 07:11:00.026934 2026] [security2:error] [pid 78969:tid 79114] [client 194.61.41.79:47337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/install.php"] [unique_id "al4eZHDvNPGtvLGb7O0FmQAAAJQ"]
[Mon Jul 20 07:11:00.056910 2026] [security2:error] [pid 78969:tid 79135] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eY3DvNPGtvLGb7O0FgwAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:00.152004 2026] [security2:error] [pid 78969:tid 79202] [client 187.16.64.216:63561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eZHDvNPGtvLGb7O0FqQAAAOw"]
[Mon Jul 20 07:11:00.152113 2026] [security2:error] [pid 78969:tid 79202] [client 187.16.64.216:63561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eZHDvNPGtvLGb7O0FqQAAAOw"]
[Mon Jul 20 07:11:00.248234 2026] [security2:error] [pid 78969:tid 79133] [client 14.225.17.146:50983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4eY3DvNPGtvLGb7O0FPgAAAKc"], referer: http://sarahholyfield.com/2024
[Mon Jul 20 07:11:00.508466 2026] [security2:error] [pid 78969:tid 79044] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eZHDvNPGtvLGb7O0FxQAA3Eo"]
[Mon Jul 20 07:11:00.508649 2026] [security2:error] [pid 78969:tid 79186] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eZHDvNPGtvLGb7O0FxQAA3Eo"]
[Mon Jul 20 07:11:00.570253 2026] [security2:error] [pid 78969:tid 79035] [remote 20.233.187.228:2439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4eZHDvNPGtvLGb7O0FyQAAyUE"]
[Mon Jul 20 07:11:00.758918 2026] [security2:error] [pid 78969:tid 79146] [client 194.61.41.66:65505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/adminfusm.php"] [unique_id "al4eZHDvNPGtvLGb7O0F1wAAALQ"]
[Mon Jul 20 07:11:00.953581 2026] [security2:error] [pid 78969:tid 79021] [remote 20.233.187.228:2439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.187.233.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4eZHDvNPGtvLGb7O0F5wABBDM"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 07:11:01.004831 2026] [security2:error] [pid 78969:tid 79158] [client 117.211.236.168:55083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eZXDvNPGtvLGb7O0F7QAAAMA"]
[Mon Jul 20 07:11:01.004965 2026] [security2:error] [pid 78969:tid 79158] [client 117.211.236.168:55083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eZXDvNPGtvLGb7O0F7QAAAMA"]
[Mon Jul 20 07:11:01.082819 2026] [security2:error] [pid 78969:tid 79166] [client 14.225.17.146:49250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4eZHDvNPGtvLGb7O0F1gAAAMg"], referer: http://mcg.homes/2024
[Mon Jul 20 07:11:01.144798 2026] [security2:error] [pid 78969:tid 79049] [remote 162.19.86.63:59393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eZXDvNPGtvLGb7O0F9gABA08"]
[Mon Jul 20 07:11:01.153755 2026] [security2:error] [pid 78969:tid 79160] [client 14.225.17.146:50531] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4eYnDvNPGtvLGb7O0FIAAAAMI"], referer: http://adastra.love/2024
[Mon Jul 20 07:11:01.316086 2026] [security2:error] [pid 78969:tid 79196] [client 88.241.67.160:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eZXDvNPGtvLGb7O0GCgAAAOY"]
[Mon Jul 20 07:11:01.316875 2026] [security2:error] [pid 78969:tid 79196] [client 88.241.67.160:53534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eZXDvNPGtvLGb7O0GCgAAAOY"]
[Mon Jul 20 07:11:01.333217 2026] [security2:error] [pid 78969:tid 79101] [client 52.187.75.220:8960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4eZXDvNPGtvLGb7O0GCwAAAIc"]
[Mon Jul 20 07:11:01.360045 2026] [security2:error] [pid 78969:tid 79068] [remote 162.19.86.63:59393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eZXDvNPGtvLGb7O0GFAAAjGI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:11:01.402098 2026] [security2:error] [pid 78969:tid 79139] [client 103.144.65.217:50184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eZXDvNPGtvLGb7O0GGgAAAK0"]
[Mon Jul 20 07:11:01.402984 2026] [security2:error] [pid 78969:tid 79139] [client 103.144.65.217:50184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eZXDvNPGtvLGb7O0GGgAAAK0"]
[Mon Jul 20 07:11:01.434608 2026] [security2:error] [pid 78969:tid 79195] [client 14.225.17.146:50746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4eY3DvNPGtvLGb7O0FjAAAAOU"], referer: http://kromosenergy.com/2024
[Mon Jul 20 07:11:01.489501 2026] [security2:error] [pid 78969:tid 79211] [client 50.116.65.227:16470] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eZXDvNPGtvLGb7O0GJAAAAPU"]
[Mon Jul 20 07:11:01.502649 2026] [security2:error] [pid 78969:tid 79160] [client 50.116.65.227:16484] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eZXDvNPGtvLGb7O0GKAAAAMI"]
[Mon Jul 20 07:11:01.534254 2026] [security2:error] [pid 78969:tid 79189] [client 52.187.75.220:8960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4eZXDvNPGtvLGb7O0GLwAAAN8"]
[Mon Jul 20 07:11:01.549821 2026] [security2:error] [pid 78969:tid 79145] [client 194.61.41.97:62091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/adminfusm.php"] [unique_id "al4eZXDvNPGtvLGb7O0GMQAAALM"]
[Mon Jul 20 07:11:01.741414 2026] [security2:error] [pid 78969:tid 79216] [client 57.141.18.82:20782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eZHDvNPGtvLGb7O0FxwAA-kM"]
[Mon Jul 20 07:11:01.763676 2026] [autoindex:error] [pid 78969:tid 79074] [remote 35.245.189.88:60518] AH01276: Cannot serve directory /home2/tsbjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://tsb.jiv.mybluehost.me
[Mon Jul 20 07:11:01.771972 2026] [security2:error] [pid 78969:tid 79163] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eZXDvNPGtvLGb7O0GMAAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:02.041475 2026] [security2:error] [pid 78969:tid 79162] [client 185.238.231.75:24583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4eZnDvNPGtvLGb7O0GSgAAAMQ"]
[Mon Jul 20 07:11:02.046368 2026] [security2:error] [pid 78969:tid 79121] [client 185.238.231.234:44841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4eZnDvNPGtvLGb7O0GSwAAAJs"]
[Mon Jul 20 07:11:02.102020 2026] [security2:error] [pid 78969:tid 79128] [client 18.142.226.106:59158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eZnDvNPGtvLGb7O0GUwAAAKI"]
[Mon Jul 20 07:11:02.116218 2026] [security2:error] [pid 78969:tid 79053] [remote 81.173.115.7:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4eZnDvNPGtvLGb7O0GVgAAhVM"]
[Mon Jul 20 07:11:02.338140 2026] [security2:error] [pid 78969:tid 79154] [client 194.61.41.85:60957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/js1.php"] [unique_id "al4eZnDvNPGtvLGb7O0GawAAALw"]
[Mon Jul 20 07:11:02.351175 2026] [security2:error] [pid 78969:tid 79014] [remote 81.173.115.7:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4eZnDvNPGtvLGb7O0GbwAAmiw"], referer: https://royalart-lb.com/wp-login.php
[Mon Jul 20 07:11:02.699612 2026] [security2:error] [pid 78969:tid 79192] [client 52.237.147.83:4486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4eZnDvNPGtvLGb7O0GjwAAAOI"]
[Mon Jul 20 07:11:02.753017 2026] [security2:error] [pid 78969:tid 79186] [client 52.237.147.83:4486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4eZnDvNPGtvLGb7O0GkgAAANw"]
[Mon Jul 20 07:11:02.824896 2026] [security2:error] [pid 78969:tid 79223] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eZnDvNPGtvLGb7O0GhQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:02.983483 2026] [security2:error] [pid 78969:tid 78988] [remote 217.113.60.80:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eZnDvNPGtvLGb7O0GngABABI"]
[Mon Jul 20 07:11:03.052743 2026] [security2:error] [pid 78969:tid 79203] [client 194.61.41.97:42391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/wp-includes/assets/script-loader-packages.min.php"] [unique_id "al4eZ3DvNPGtvLGb7O0GogAAAO0"]
[Mon Jul 20 07:11:03.206918 2026] [security2:error] [pid 78969:tid 78983] [remote 217.113.60.80:58420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eZ3DvNPGtvLGb7O0GsgAA2A0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:11:03.338494 2026] [security2:error] [pid 78969:tid 79121] [client 13.215.47.127:18886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eZ3DvNPGtvLGb7O0GvwAAAJs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:11:03.414325 2026] [security2:error] [pid 78969:tid 79141] [client 77.110.127.138:64849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eZ3DvNPGtvLGb7O0GyAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:03.414423 2026] [security2:error] [pid 78969:tid 79141] [client 77.110.127.138:64849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eZ3DvNPGtvLGb7O0GyAAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:03.434394 2026] [security2:error] [pid 78969:tid 79151] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eZ3DvNPGtvLGb7O0GtAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:03.622873 2026] [security2:error] [pid 78969:tid 79226] [client 201.27.111.74:50495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eZ3DvNPGtvLGb7O0G3wAAAQQ"]
[Mon Jul 20 07:11:03.623008 2026] [security2:error] [pid 78969:tid 79226] [client 201.27.111.74:50495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eZ3DvNPGtvLGb7O0G3wAAAQQ"]
[Mon Jul 20 07:11:03.824327 2026] [security2:error] [pid 78969:tid 79224] [client 194.61.41.249:48105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/blocks/file/wp-style.php"] [unique_id "al4eZ3DvNPGtvLGb7O0G7wAAAQI"]
[Mon Jul 20 07:11:03.845956 2026] [security2:error] [pid 78969:tid 79197] [client 13.233.207.33:10386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eZ3DvNPGtvLGb7O0G8wAAAOc"]
[Mon Jul 20 07:11:04.209391 2026] [security2:error] [pid 78969:tid 79173] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eaHDvNPGtvLGb7O0G_AAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:04.226713 2026] [security2:error] [pid 78969:tid 79104] [client 14.225.17.146:50367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4eZnDvNPGtvLGb7O0GjgAAAIo"], referer: http://olearyplumbingllc.com/2024
[Mon Jul 20 07:11:04.563955 2026] [security2:error] [pid 78969:tid 79222] [client 194.61.41.80:62919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/mu-plugins/admin.php"] [unique_id "al4eaHDvNPGtvLGb7O0HJAAAAQA"]
[Mon Jul 20 07:11:04.682920 2026] [autoindex:error] [pid 78969:tid 79173] [client 8.234.160.70:52021] AH01276: Cannot serve directory /home1/heidimo2/public_html/website_ba575a2e/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:11:04.786663 2026] [security2:error] [pid 78969:tid 79157] [client 13.233.207.33:50208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4eaHDvNPGtvLGb7O0HQQAAAL8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:11:04.964984 2026] [security2:error] [pid 78969:tid 79199] [client 77.110.127.138:64864] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/3/"] [unique_id "al4eaHDvNPGtvLGb7O0HVQAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:05.341283 2026] [security2:error] [pid 78969:tid 79022] [remote 130.185.118.215:43512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eaXDvNPGtvLGb7O0HZwAA-DQ"]
[Mon Jul 20 07:11:05.341587 2026] [security2:error] [pid 78969:tid 79214] [client 130.185.118.215:43512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eaXDvNPGtvLGb7O0HZwAA-DQ"]
[Mon Jul 20 07:11:05.351979 2026] [security2:error] [pid 78969:tid 79108] [client 194.61.41.61:30803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/class-IXR-cilent.php"] [unique_id "al4eaXDvNPGtvLGb7O0HagAAAI4"]
[Mon Jul 20 07:11:05.626275 2026] [security2:error] [pid 78969:tid 79144] [client 77.110.127.138:64867] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/3/"] [unique_id "al4eaXDvNPGtvLGb7O0HegAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:05.722905 2026] [security2:error] [pid 78969:tid 79197] [client 77.110.127.138:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eaXDvNPGtvLGb7O0HhQAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:05.723035 2026] [security2:error] [pid 78969:tid 79197] [client 77.110.127.138:64868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eaXDvNPGtvLGb7O0HhQAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:05.889016 2026] [security2:error] [pid 78969:tid 79174] [client 116.62.81.204:43776] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eaXDvNPGtvLGb7O0HlQAAANA"]
[Mon Jul 20 07:11:06.023610 2026] [security2:error] [pid 78969:tid 79174] [client 116.62.81.204:43776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eaXDvNPGtvLGb7O0HlQAAANA"]
[Mon Jul 20 07:11:06.409558 2026] [security2:error] [pid 78969:tid 79192] [client 194.61.41.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4eanDvNPGtvLGb7O0HqwAAAOI"]
[Mon Jul 20 07:11:07.268459 2026] [security2:error] [pid 78969:tid 79147] [client 194.61.41.88:61813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/about/function.php%20"] [unique_id "al4ea3DvNPGtvLGb7O0IBwAAALU"]
[Mon Jul 20 07:11:07.473495 2026] [security2:error] [pid 78969:tid 79194] [client 104.234.53.90:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ea3DvNPGtvLGb7O0IGwAAAOQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:07.728455 2026] [security2:error] [pid 78969:tid 78997] [remote 68.178.160.25:39924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4ea3DvNPGtvLGb7O0IKwAAlRs"]
[Mon Jul 20 07:11:07.768802 2026] [security2:error] [pid 78969:tid 79205] [client 114.119.158.50:57275] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/product/home-pro-paint-roller-cover"] [unique_id "al4ea3DvNPGtvLGb7O0IMAAAAO8"], referer: https://www.liquidationteam.com/product/home-pro-paint-roller-cover
[Mon Jul 20 07:11:08.052969 2026] [security2:error] [pid 78969:tid 79123] [client 194.61.41.241:30315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/install.php"] [unique_id "al4ebHDvNPGtvLGb7O0ISQAAAJ0"]
[Mon Jul 20 07:11:08.147309 2026] [security2:error] [pid 78969:tid 78991] [remote 68.178.160.25:39924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4ebHDvNPGtvLGb7O0ITAAAqRU"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:11:08.187895 2026] [security2:error] [pid 78969:tid 79137] [client 136.107.64.51:65399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ebHDvNPGtvLGb7O0IUgAAAKs"]
[Mon Jul 20 07:11:08.188013 2026] [security2:error] [pid 78969:tid 79137] [client 136.107.64.51:65399] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ebHDvNPGtvLGb7O0IUgAAAKs"]
[Mon Jul 20 07:11:08.457021 2026] [autoindex:error] [pid 78969:tid 79099] [client 198.235.24.155:61466] AH01276: Cannot serve directory /home1/wgsdoqmy/public_html/website_9df15244/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:11:08.461537 2026] [security2:error] [pid 78969:tid 79118] [client 136.107.64.51:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.64.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ebHDvNPGtvLGb7O0IdwAAAJg"]
[Mon Jul 20 07:11:08.461710 2026] [security2:error] [pid 78969:tid 79118] [client 136.107.64.51:62815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "snctaxgroup.com"] [uri "/xmlrpc.php"] [unique_id "al4ebHDvNPGtvLGb7O0IdwAAAJg"]
[Mon Jul 20 07:11:08.576661 2026] [security2:error] [pid 78969:tid 79089] [remote 57.141.18.45:45862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3042932"] [unique_id "al4ebHDvNPGtvLGb7O0IfAAA8nc"]
[Mon Jul 20 07:11:08.659462 2026] [security2:error] [pid 78969:tid 79191] [client 57.141.18.25:22068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ea3DvNPGtvLGb7O0IAAAA4Vc"]
[Mon Jul 20 07:11:08.842367 2026] [security2:error] [pid 78969:tid 79169] [client 194.61.41.97:46243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/PHPMailer/xleet.php"] [unique_id "al4ebHDvNPGtvLGb7O0IiwAAAMs"]
[Mon Jul 20 07:11:09.096160 2026] [security2:error] [pid 78969:tid 79043] [remote 152.228.213.32:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4ebXDvNPGtvLGb7O0InwAAn0k"]
[Mon Jul 20 07:11:09.308178 2026] [security2:error] [pid 78969:tid 79032] [remote 152.228.213.32:38020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4ebXDvNPGtvLGb7O0IywAAyz4"], referer: https://lutheranphilosopher.com/wp-login.php
[Mon Jul 20 07:11:09.389878 2026] [http2:info] [pid 85094:tid 85094] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:11:09.434306 2026] [security2:error] [pid 78969:tid 79178] [client 114.119.155.252:28743] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/thorazine-cvs-772a.pdf"] [unique_id "al4ebXDvNPGtvLGb7O0I3AAAANQ"], referer: http://www.lnt.com.tw/jklink/listuser.asp?page=9290
[Mon Jul 20 07:11:09.439915 2026] [security2:error] [pid 78969:tid 79120] [client 82.157.210.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ebXDvNPGtvLGb7O0IxgAAmlE"], referer: https://www.aleishapenny.ca/listing/page/1145?paged=1&view=grid&posts_per_page=48
[Mon Jul 20 07:11:09.655802 2026] [security2:error] [pid 78969:tid 79146] [client 194.61.41.65:40367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/doc.php"] [unique_id "al4ebXDvNPGtvLGb7O0I8QAAALQ"]
[Mon Jul 20 07:11:10.075857 2026] [security2:error] [pid 85094:tid 85253] [client 50.116.65.227:55584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4ebq_nUl59BcEkkgFhnQAAASY"]
[Mon Jul 20 07:11:10.087706 2026] [security2:error] [pid 85094:tid 85256] [client 50.116.65.227:38160] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-9-Feature-Image.jpg"] [unique_id "al4ebq_nUl59BcEkkgFhnwAAASk"]
[Mon Jul 20 07:11:10.147254 2026] [security2:error] [pid 85094:tid 85097] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ebq_nUl59BcEkkgFhowABIgE"]
[Mon Jul 20 07:11:10.147529 2026] [security2:error] [pid 85094:tid 85249] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ebq_nUl59BcEkkgFhowABIgE"]
[Mon Jul 20 07:11:10.175796 2026] [security2:error] [pid 85094:tid 85269] [client 50.116.65.227:55600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ipl.ysa.mybluehost.me"] [uri "/website_bb9e8c9e/wp-cron.php"] [unique_id "al4ebq_nUl59BcEkkgFhpgAAATY"]
[Mon Jul 20 07:11:10.385280 2026] [security2:error] [pid 78969:tid 79134] [client 189.115.214.172:37718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4ebnDvNPGtvLGb7O0JEwAAAKg"]
[Mon Jul 20 07:11:10.422769 2026] [security2:error] [pid 78969:tid 79125] [client 194.61.41.250:52675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/f35_SpaceTn.php"] [unique_id "al4ebnDvNPGtvLGb7O0JHgAAAJ8"]
[Mon Jul 20 07:11:10.553986 2026] [security2:error] [pid 78969:tid 79085] [remote 152.228.213.32:38026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4ebnDvNPGtvLGb7O0JKgAA7XM"]
[Mon Jul 20 07:11:10.589667 2026] [security2:error] [pid 78969:tid 79168] [client 77.110.127.138:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ebnDvNPGtvLGb7O0JKwAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:10.589782 2026] [security2:error] [pid 78969:tid 79168] [client 77.110.127.138:64880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ebnDvNPGtvLGb7O0JKwAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:10.593433 2026] [security2:error] [pid 85094:tid 85299] [client 77.110.127.138:64884] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/3/"] [unique_id "al4ebq_nUl59BcEkkgFhtwAAAVM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:10.763281 2026] [security2:error] [pid 78969:tid 78975] [remote 152.228.213.32:38026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4ebnDvNPGtvLGb7O0JLwAA9AU"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 07:11:10.815441 2026] [security2:error] [pid 78969:tid 79182] [client 187.16.64.216:64142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ebnDvNPGtvLGb7O0JMgAAANg"]
[Mon Jul 20 07:11:10.815586 2026] [security2:error] [pid 78969:tid 79182] [client 187.16.64.216:64142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ebnDvNPGtvLGb7O0JMgAAANg"]
[Mon Jul 20 07:11:10.938735 2026] [security2:error] [pid 78969:tid 79125] [client 3.67.192.83:11100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ebnDvNPGtvLGb7O0JPgAAAJ8"]
[Mon Jul 20 07:11:10.938863 2026] [security2:error] [pid 78969:tid 79125] [client 3.67.192.83:11100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ebnDvNPGtvLGb7O0JPgAAAJ8"]
[Mon Jul 20 07:11:10.958823 2026] [security2:error] [pid 85094:tid 85246] [client 104.234.53.51:20159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ebq_nUl59BcEkkgFhvwAAAR8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:11.117325 2026] [security2:error] [pid 78969:tid 79048] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eb3DvNPGtvLGb7O0JRwAAyE4"]
[Mon Jul 20 07:11:11.117498 2026] [security2:error] [pid 78969:tid 79166] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eb3DvNPGtvLGb7O0JRwAAyE4"]
[Mon Jul 20 07:11:11.147335 2026] [security2:error] [pid 78969:tid 79100] [client 194.61.41.56:31189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/sunrise/bypass.php"] [unique_id "al4eb3DvNPGtvLGb7O0JSAAAAIY"]
[Mon Jul 20 07:11:11.523075 2026] [security2:error] [pid 78969:tid 79127] [client 66.228.36.223:5870] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5936.bluehost.com"] [uri "/"] [unique_id "al4eb3DvNPGtvLGb7O0JYQAAAKE"]
[Mon Jul 20 07:11:11.532277 2026] [security2:error] [pid 78969:tid 79127] [client 66.228.36.223:5870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4eb3DvNPGtvLGb7O0JYQAAAKE"]
[Mon Jul 20 07:11:11.828181 2026] [security2:error] [pid 85094:tid 85348] [client 66.228.36.223:5896] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5033.bluehost.com"] [uri "/sdk"] [unique_id "al4eb6_nUl59BcEkkgFh1gAAAYQ"]
[Mon Jul 20 07:11:11.932189 2026] [security2:error] [pid 78969:tid 79161] [client 88.241.67.160:56483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eb3DvNPGtvLGb7O0JdwAAAMM"]
[Mon Jul 20 07:11:11.932333 2026] [security2:error] [pid 78969:tid 79161] [client 88.241.67.160:56483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eb3DvNPGtvLGb7O0JdwAAAMM"]
[Mon Jul 20 07:11:11.942364 2026] [security2:error] [pid 85094:tid 85331] [client 103.144.65.217:50648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eb6_nUl59BcEkkgFh2gAAAXM"]
[Mon Jul 20 07:11:11.942546 2026] [security2:error] [pid 85094:tid 85331] [client 103.144.65.217:50648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eb6_nUl59BcEkkgFh2gAAAXM"]
[Mon Jul 20 07:11:11.959723 2026] [security2:error] [pid 85094:tid 85263] [client 194.61.41.57:47713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/fixed.php"] [unique_id "al4eb6_nUl59BcEkkgFh3AAAATA"]
[Mon Jul 20 07:11:12.070660 2026] [security2:error] [pid 85094:tid 85265] [client 52.109.52.84:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ecK_nUl59BcEkkgFh3gAAATI"]
[Mon Jul 20 07:11:12.088454 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:64892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ecHDvNPGtvLGb7O0JfAAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:12.088542 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:64892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ecHDvNPGtvLGb7O0JfAAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:12.185334 2026] [security2:error] [pid 85094:tid 85286] [client 52.109.52.84:12162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ecK_nUl59BcEkkgFh5wAAAUY"]
[Mon Jul 20 07:11:12.246919 2026] [security2:error] [pid 78969:tid 79148] [client 20.199.97.14:1472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ecHDvNPGtvLGb7O0JiAAAALY"]
[Mon Jul 20 07:11:12.403375 2026] [security2:error] [pid 78969:tid 79154] [client 20.199.97.14:1472] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ecHDvNPGtvLGb7O0JjgAAALw"]
[Mon Jul 20 07:11:12.503178 2026] [security2:error] [pid 78969:tid 79130] [client 117.211.236.168:55634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ecHDvNPGtvLGb7O0JkwAAAKQ"]
[Mon Jul 20 07:11:12.503263 2026] [security2:error] [pid 78969:tid 79130] [client 117.211.236.168:55634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ecHDvNPGtvLGb7O0JkwAAAKQ"]
[Mon Jul 20 07:11:12.694417 2026] [security2:error] [pid 85094:tid 85111] [remote 15.206.251.117:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4ecK_nUl59BcEkkgFh8gABQg8"]
[Mon Jul 20 07:11:12.733254 2026] [security2:error] [pid 78969:tid 79192] [client 194.61.41.253:25971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/themes.php"] [unique_id "al4ecHDvNPGtvLGb7O0JnQAAAOI"]
[Mon Jul 20 07:11:12.776390 2026] [security2:error] [pid 85094:tid 85309] [client 66.228.36.223:5926] ModSecurity: Warning. Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "82"] [id "331030"] [rev "2"] [msg "Atomicorp.com WAF Rules: Suspicious activity detected - HTTP Request Missing a Host Header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5936.bluehost.com"] [uri "/"] [unique_id "al4ecK_nUl59BcEkkgFh9gAAAV0"]
[Mon Jul 20 07:11:12.785228 2026] [security2:error] [pid 85094:tid 85309] [client 66.228.36.223:5926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4ecK_nUl59BcEkkgFh9gAAAV0"]
[Mon Jul 20 07:11:12.785300 2026] [autoindex:error] [pid 78969:tid 79149] [client 144.172.114.51:58372] AH01276: Cannot serve directory /home1/wcnktkmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:11:13.054818 2026] [security2:error] [pid 85094:tid 85337] [client 57.141.18.73:49080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eb6_nUl59BcEkkgFhywABeQY"]
[Mon Jul 20 07:11:13.079372 2026] [security2:error] [pid 85094:tid 85336] [client 66.228.36.223:6008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "box5033.bluehost.com"] [uri "/cgi-sys/404.html"] [unique_id "al4eca_nUl59BcEkkgFh_QAAAXg"]
[Mon Jul 20 07:11:13.137769 2026] [security2:error] [pid 85094:tid 85112] [remote 15.206.251.117:48754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4eca_nUl59BcEkkgFiAAABehA"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 07:11:13.195332 2026] [security2:error] [pid 78969:tid 79004] [remote 8.217.108.67:14882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ecXDvNPGtvLGb7O0JqwAAiiI"]
[Mon Jul 20 07:11:13.195967 2026] [security2:error] [pid 78969:tid 79104] [client 8.217.108.67:14882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ecXDvNPGtvLGb7O0JqwAAiiI"]
[Mon Jul 20 07:11:13.249311 2026] [security2:error] [pid 85094:tid 85237] [client 50.116.65.227:55612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4eca_nUl59BcEkkgFiBAAAARY"]
[Mon Jul 20 07:11:13.261550 2026] [security2:error] [pid 85094:tid 85233] [client 50.116.65.227:38192] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/RWC-Feature-Image.jpg"] [unique_id "al4eca_nUl59BcEkkgFiBQAAARI"]
[Mon Jul 20 07:11:13.401019 2026] [security2:error] [pid 85094:tid 85116] [remote 49.12.216.176:35852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eca_nUl59BcEkkgFiDQABDhQ"]
[Mon Jul 20 07:11:13.401186 2026] [security2:error] [pid 85094:tid 85229] [client 49.12.216.176:35852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eca_nUl59BcEkkgFiDQABDhQ"]
[Mon Jul 20 07:11:13.460416 2026] [security2:error] [pid 78969:tid 79168] [client 194.61.41.97:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/fix/bypass.php"] [unique_id "al4ecXDvNPGtvLGb7O0JuwAAAMo"]
[Mon Jul 20 07:11:13.586497 2026] [security2:error] [pid 78969:tid 79155] [client 104.234.53.47:21575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ecXDvNPGtvLGb7O0JwQAAAL0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:13.599100 2026] [security2:error] [pid 85094:tid 85274] [client 50.116.65.227:38204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eca_nUl59BcEkkgFiEAAAATs"]
[Mon Jul 20 07:11:13.608313 2026] [security2:error] [pid 85094:tid 85283] [client 50.116.65.227:38210] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eca_nUl59BcEkkgFiEgAAAUM"]
[Mon Jul 20 07:11:13.838650 2026] [security2:error] [pid 78969:tid 79032] [remote 45.90.123.233:41574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ecXDvNPGtvLGb7O0JzgAAvz4"]
[Mon Jul 20 07:11:14.037089 2026] [security2:error] [pid 85094:tid 85313] [client 77.110.127.138:64906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ecq_nUl59BcEkkgFiKQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:14.037205 2026] [security2:error] [pid 85094:tid 85313] [client 77.110.127.138:64906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ecq_nUl59BcEkkgFiKQAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:14.117835 2026] [security2:error] [pid 85094:tid 85292] [client 201.27.111.74:50991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ecq_nUl59BcEkkgFiKwAAAUw"]
[Mon Jul 20 07:11:14.118047 2026] [security2:error] [pid 85094:tid 85292] [client 201.27.111.74:50991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ecq_nUl59BcEkkgFiKwAAAUw"]
[Mon Jul 20 07:11:14.253839 2026] [security2:error] [pid 78969:tid 79203] [client 194.61.41.72:40289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/category-double.php"] [unique_id "al4ecnDvNPGtvLGb7O0J3gAAAO0"]
[Mon Jul 20 07:11:14.537427 2026] [security2:error] [pid 78969:tid 79189] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ecnDvNPGtvLGb7O0J3AAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:14.920371 2026] [security2:error] [pid 85094:tid 85302] [client 104.234.53.80:54883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ecq_nUl59BcEkkgFiRAAAAVY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:15.049328 2026] [security2:error] [pid 78969:tid 79145] [client 194.61.41.65:48099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/admin.php"] [unique_id "al4ec3DvNPGtvLGb7O0J_AAAALM"]
[Mon Jul 20 07:11:15.704096 2026] [security2:error] [pid 85094:tid 85332] [client 116.62.81.204:45248] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ec6_nUl59BcEkkgFiVwAAAXQ"]
[Mon Jul 20 07:11:15.859656 2026] [security2:error] [pid 85094:tid 85312] [client 194.61.41.82:43223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/blog/signatur.php"] [unique_id "al4ec6_nUl59BcEkkgFiXAAAAWA"]
[Mon Jul 20 07:11:15.864366 2026] [security2:error] [pid 85094:tid 85332] [client 116.62.81.204:45248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ec6_nUl59BcEkkgFiVwAAAXQ"]
[Mon Jul 20 07:11:16.266698 2026] [security2:error] [pid 78969:tid 79221] [client 77.110.127.138:64914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4edHDvNPGtvLGb7O0KNwAAAP8"]
[Mon Jul 20 07:11:16.266830 2026] [security2:error] [pid 78969:tid 79221] [client 77.110.127.138:64914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4edHDvNPGtvLGb7O0KNwAAAP8"]
[Mon Jul 20 07:11:16.552885 2026] [security2:error] [pid 85094:tid 85129] [remote 160.187.68.132:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4edK_nUl59BcEkkgFiawABeSE"]
[Mon Jul 20 07:11:16.640245 2026] [security2:error] [pid 85094:tid 85328] [client 194.61.41.102:28483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/db.php"] [unique_id "al4edK_nUl59BcEkkgFibQAAAXA"]
[Mon Jul 20 07:11:16.701760 2026] [security2:error] [pid 78969:tid 79065] [remote 173.212.252.15:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4edHDvNPGtvLGb7O0KSwAAqV8"]
[Mon Jul 20 07:11:16.820160 2026] [security2:error] [pid 78969:tid 79072] [remote 78.46.157.202:33488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4edHDvNPGtvLGb7O0KVQAA72Y"]
[Mon Jul 20 07:11:16.820385 2026] [security2:error] [pid 78969:tid 79205] [client 78.46.157.202:33488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4edHDvNPGtvLGb7O0KVQAA72Y"]
[Mon Jul 20 07:11:16.843829 2026] [security2:error] [pid 85094:tid 85330] [client 104.234.53.71:41063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4edK_nUl59BcEkkgFicQAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:16.909259 2026] [security2:error] [pid 78969:tid 79081] [remote 173.212.252.15:44198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4edHDvNPGtvLGb7O0KXgAA928"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 07:11:17.039038 2026] [security2:error] [pid 78969:tid 78976] [remote 182.77.62.24:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4edXDvNPGtvLGb7O0KZQAA8gY"]
[Mon Jul 20 07:11:17.043007 2026] [security2:error] [pid 85094:tid 85132] [remote 160.187.68.132:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4eda_nUl59BcEkkgFiewABXiQ"], referer: https://guidehunting.com/wp-login.php
[Mon Jul 20 07:11:17.222898 2026] [security2:error] [pid 85094:tid 85248] [client 14.225.17.146:62207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4edK_nUl59BcEkkgFidwAAASE"]
[Mon Jul 20 07:11:17.237370 2026] [security2:error] [pid 85094:tid 85335] [client 14.225.17.146:52315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4edK_nUl59BcEkkgFidgAAAXc"]
[Mon Jul 20 07:11:17.272847 2026] [security2:error] [pid 85094:tid 85312] [client 104.234.53.71:41063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eda_nUl59BcEkkgFihAAAAWA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:17.328559 2026] [security2:error] [pid 78969:tid 79009] [remote 45.90.123.233:41574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4edXDvNPGtvLGb7O0KcgAA0yc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:17.430727 2026] [security2:error] [pid 85094:tid 85233] [client 194.61.41.76:32335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/security.php"] [unique_id "al4eda_nUl59BcEkkgFijQAAARI"]
[Mon Jul 20 07:11:17.625446 2026] [security2:error] [pid 78969:tid 79036] [remote 182.77.62.24:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4edXDvNPGtvLGb7O0KfQAAhkI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:17.975706 2026] [security2:error] [pid 78969:tid 79125] [client 14.225.17.146:50047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4edXDvNPGtvLGb7O0KgwAAAJ8"], referer: http://blaizeaccountingservices.com/2017
[Mon Jul 20 07:11:18.174513 2026] [security2:error] [pid 78969:tid 79200] [client 194.61.41.82:21633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/include/install.php"] [unique_id "al4ednDvNPGtvLGb7O0KnQAAAOo"]
[Mon Jul 20 07:11:18.388140 2026] [security2:error] [pid 85094:tid 85138] [remote 209.42.18.223:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4edq_nUl59BcEkkgFipQABhio"]
[Mon Jul 20 07:11:18.568017 2026] [security2:error] [pid 85094:tid 85139] [remote 209.42.18.223:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4edq_nUl59BcEkkgFirQABKis"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:11:18.705632 2026] [security2:error] [pid 78969:tid 79225] [client 213.152.161.101:42522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.161.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ednDvNPGtvLGb7O0KrgAAAQM"]
[Mon Jul 20 07:11:18.705740 2026] [security2:error] [pid 78969:tid 79225] [client 213.152.161.101:42522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ednDvNPGtvLGb7O0KrgAAAQM"]
[Mon Jul 20 07:11:18.786466 2026] [security2:error] [pid 85094:tid 85329] [client 14.225.17.146:51871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4edq_nUl59BcEkkgFirwAAAXE"], referer: https://north-woods-engineering.com/2017
[Mon Jul 20 07:11:18.956399 2026] [security2:error] [pid 78969:tid 79108] [client 194.61.41.78:21627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/gm.php"] [unique_id "al4ednDvNPGtvLGb7O0KtgAAAI4"]
[Mon Jul 20 07:11:19.177778 2026] [security2:error] [pid 85094:tid 85242] [client 77.110.127.138:64927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ed6_nUl59BcEkkgFizgAAARs"]
[Mon Jul 20 07:11:19.178023 2026] [security2:error] [pid 85094:tid 85242] [client 77.110.127.138:64927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ed6_nUl59BcEkkgFizgAAARs"]
[Mon Jul 20 07:11:19.415808 2026] [security2:error] [pid 85094:tid 85245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ed6_nUl59BcEkkgFiyQAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:19.743544 2026] [security2:error] [pid 78969:tid 79217] [client 194.61.41.54:60911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-language-pack.php"] [unique_id "al4ed3DvNPGtvLGb7O0K2QAAAPs"]
[Mon Jul 20 07:11:19.830869 2026] [security2:error] [pid 78969:tid 79222] [client 104.234.53.68:40417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ed3DvNPGtvLGb7O0K2wAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:20.041757 2026] [security2:error] [pid 85094:tid 85345] [client 14.225.17.146:50038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4eda_nUl59BcEkkgFikQAAAYE"], referer: http://floorsourcestock.com/2017
[Mon Jul 20 07:11:20.161327 2026] [security2:error] [pid 85094:tid 85146] [remote 8.217.108.67:14886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4eeK_nUl59BcEkkgFi8QABLDI"]
[Mon Jul 20 07:11:20.507060 2026] [security2:error] [pid 85094:tid 85285] [client 74.208.214.194:41946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4eeK_nUl59BcEkkgFjAAAAAUU"]
[Mon Jul 20 07:11:20.543213 2026] [security2:error] [pid 78969:tid 79147] [client 194.61.41.249:50829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/content-type.php"] [unique_id "al4eeHDvNPGtvLGb7O0LCAAAALU"]
[Mon Jul 20 07:11:20.844874 2026] [security2:error] [pid 85094:tid 85151] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eeK_nUl59BcEkkgFjFgABCjc"]
[Mon Jul 20 07:11:20.845128 2026] [security2:error] [pid 85094:tid 85225] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eeK_nUl59BcEkkgFjFgABCjc"]
[Mon Jul 20 07:11:20.996577 2026] [security2:error] [pid 85094:tid 85252] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eeK_nUl59BcEkkgFjDwAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:21.005398 2026] [security2:error] [pid 78969:tid 79092] [remote 182.77.62.24:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4eeHDvNPGtvLGb7O0LGgAA2Ho"]
[Mon Jul 20 07:11:21.049370 2026] [security2:error] [pid 85094:tid 85330] [client 14.225.17.146:62151] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4ed6_nUl59BcEkkgFi0QAAAXI"], referer: http://areitoproducciones.com/2017
[Mon Jul 20 07:11:21.196997 2026] [security2:error] [pid 85094:tid 85251] [client 14.225.17.146:51168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4eea_nUl59BcEkkgFjHwAAASQ"], referer: http://phillipbloch.com/2017
[Mon Jul 20 07:11:21.209260 2026] [security2:error] [pid 78969:tid 79123] [client 77.110.127.138:64957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eeXDvNPGtvLGb7O0LJQAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:21.209356 2026] [security2:error] [pid 78969:tid 79123] [client 77.110.127.138:64957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eeXDvNPGtvLGb7O0LJQAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:21.352238 2026] [security2:error] [pid 85094:tid 85232] [client 194.61.41.100:51119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-walker-comment-client.php"] [unique_id "al4eea_nUl59BcEkkgFjJwAAARE"]
[Mon Jul 20 07:11:21.390517 2026] [security2:error] [pid 85094:tid 85153] [remote 57.141.18.99:45648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3656248"] [unique_id "al4eea_nUl59BcEkkgFjKgABGDk"]
[Mon Jul 20 07:11:21.441975 2026] [security2:error] [pid 85094:tid 85263] [client 187.16.64.216:64724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eea_nUl59BcEkkgFjLgAAATA"]
[Mon Jul 20 07:11:21.442141 2026] [security2:error] [pid 85094:tid 85263] [client 187.16.64.216:64724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4eea_nUl59BcEkkgFjLgAAATA"]
[Mon Jul 20 07:11:21.553637 2026] [security2:error] [pid 78969:tid 79110] [client 116.62.81.204:46612] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eeXDvNPGtvLGb7O0LMAAAAJA"]
[Mon Jul 20 07:11:21.696936 2026] [security2:error] [pid 78969:tid 79110] [client 116.62.81.204:46612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eeXDvNPGtvLGb7O0LMAAAAJA"]
[Mon Jul 20 07:11:21.766400 2026] [security2:error] [pid 85094:tid 85156] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eea_nUl59BcEkkgFjOwABFjw"]
[Mon Jul 20 07:11:21.766659 2026] [security2:error] [pid 85094:tid 85237] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eea_nUl59BcEkkgFjOwABFjw"]
[Mon Jul 20 07:11:22.003484 2026] [security2:error] [pid 85094:tid 85327] [client 13.233.207.33:15974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4eeq_nUl59BcEkkgFjQgAAAW8"]
[Mon Jul 20 07:11:22.033845 2026] [security2:error] [pid 85094:tid 85305] [client 14.225.17.146:62262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4eea_nUl59BcEkkgFjPAAAAVk"], referer: http://oldracelimited.com/2017
[Mon Jul 20 07:11:22.073544 2026] [security2:error] [pid 85094:tid 85252] [client 50.116.65.227:20148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ait.afz.mybluehost.me"] [uri "/website_d78e7740/wp-cron.php"] [unique_id "al4eeq_nUl59BcEkkgFjSAAAASU"]
[Mon Jul 20 07:11:22.140248 2026] [security2:error] [pid 85094:tid 85233] [client 194.61.41.88:48771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/about/goods.php"] [unique_id "al4eeq_nUl59BcEkkgFjSgAAARI"]
[Mon Jul 20 07:11:22.348700 2026] [security2:error] [pid 85094:tid 85234] [client 14.225.17.146:59872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4eeK_nUl59BcEkkgFjAgAAARM"], referer: http://fluidtemple.org/2017
[Mon Jul 20 07:11:22.371206 2026] [security2:error] [pid 85094:tid 85163] [remote 8.217.108.67:14886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4eeq_nUl59BcEkkgFjWQABMUM"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 07:11:22.392563 2026] [security2:error] [pid 78969:tid 79000] [remote 182.77.62.24:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4eenDvNPGtvLGb7O0LTAAAph4"], referer: https://spencersadventures.com/wp-login.php
[Mon Jul 20 07:11:22.553546 2026] [security2:error] [pid 78969:tid 79150] [client 103.144.65.217:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eenDvNPGtvLGb7O0LUQAAALg"]
[Mon Jul 20 07:11:22.553632 2026] [security2:error] [pid 78969:tid 79150] [client 103.144.65.217:51107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4eenDvNPGtvLGb7O0LUQAAALg"]
[Mon Jul 20 07:11:22.593242 2026] [security2:error] [pid 85094:tid 85321] [client 88.241.67.160:56090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eeq_nUl59BcEkkgFjYwAAAWk"]
[Mon Jul 20 07:11:22.593458 2026] [security2:error] [pid 85094:tid 85321] [client 88.241.67.160:56090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eeq_nUl59BcEkkgFjYwAAAWk"]
[Mon Jul 20 07:11:22.613223 2026] [security2:error] [pid 78969:tid 78981] [remote 8.217.108.67:8804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eenDvNPGtvLGb7O0LVAAAows"]
[Mon Jul 20 07:11:22.652443 2026] [security2:error] [pid 85094:tid 85243] [client 54.84.71.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eeq_nUl59BcEkkgFjXQABHEQ"]
[Mon Jul 20 07:11:22.809007 2026] [security2:error] [pid 85094:tid 85266] [client 14.225.17.146:50245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4eea_nUl59BcEkkgFjNwAAATM"], referer: http://intelligentengineeringsolutions.com/2017
[Mon Jul 20 07:11:22.915712 2026] [security2:error] [pid 78969:tid 79122] [client 194.61.41.60:27035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/file/function.php"] [unique_id "al4eenDvNPGtvLGb7O0LXAAAAJw"]
[Mon Jul 20 07:11:22.942524 2026] [security2:error] [pid 85094:tid 85245] [client 43.205.139.3:63736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4eeq_nUl59BcEkkgFjbgAAAR4"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:11:22.999158 2026] [security2:error] [pid 78969:tid 79028] [remote 8.217.108.67:8804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eenDvNPGtvLGb7O0LXgAA7zo"], referer: https://rcq.nst.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:23.047129 2026] [security2:error] [pid 78969:tid 79164] [client 104.234.53.63:39895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ee3DvNPGtvLGb7O0LYgAAAMY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:23.181470 2026] [security2:error] [pid 78969:tid 79097] [remote 162.19.86.63:53966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ee3DvNPGtvLGb7O0LagAA1H8"]
[Mon Jul 20 07:11:23.281366 2026] [security2:error] [pid 78969:tid 78990] [remote 81.173.115.7:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ee3DvNPGtvLGb7O0LcAAAlBQ"]
[Mon Jul 20 07:11:23.384267 2026] [security2:error] [pid 78969:tid 79019] [remote 162.19.86.63:53966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ee3DvNPGtvLGb7O0LcgAAnzE"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:11:23.543786 2026] [security2:error] [pid 78969:tid 79025] [remote 81.173.115.7:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ee3DvNPGtvLGb7O0LewAA_zc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:11:23.595528 2026] [security2:error] [pid 85094:tid 85168] [remote 51.68.236.114:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aleishapenny.ca"] [uri "/robots.txt"] [unique_id "al4ee6_nUl59BcEkkgFjiQABOUg"]
[Mon Jul 20 07:11:23.595660 2026] [security2:error] [pid 85094:tid 85272] [client 51.68.236.114:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aleishapenny.ca"] [uri "/robots.txt"] [unique_id "al4ee6_nUl59BcEkkgFjiQABOUg"]
[Mon Jul 20 07:11:23.622697 2026] [security2:error] [pid 78969:tid 79200] [client 57.141.18.95:35532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eenDvNPGtvLGb7O0LRgAA6m0"]
[Mon Jul 20 07:11:23.640713 2026] [security2:error] [pid 78969:tid 79153] [client 194.61.41.249:48911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/function/goods.php"] [unique_id "al4ee3DvNPGtvLGb7O0LhgAAALs"]
[Mon Jul 20 07:11:24.119294 2026] [security2:error] [pid 85094:tid 85172] [remote 51.68.236.114:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "aleishapenny.ca"] [uri "/"] [unique_id "al4efK_nUl59BcEkkgFjlgABgkw"]
[Mon Jul 20 07:11:24.119475 2026] [security2:error] [pid 85094:tid 85346] [client 51.68.236.114:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "aleishapenny.ca"] [uri "/"] [unique_id "al4efK_nUl59BcEkkgFjlgABgkw"]
[Mon Jul 20 07:11:24.422105 2026] [security2:error] [pid 85094:tid 85252] [client 194.61.41.241:36995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/bypass.php"] [unique_id "al4efK_nUl59BcEkkgFjqQAAASU"]
[Mon Jul 20 07:11:24.434912 2026] [security2:error] [pid 78969:tid 79162] [client 117.211.236.168:56126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4efHDvNPGtvLGb7O0LowAAAMQ"]
[Mon Jul 20 07:11:24.435007 2026] [security2:error] [pid 78969:tid 79162] [client 117.211.236.168:56126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4efHDvNPGtvLGb7O0LowAAAMQ"]
[Mon Jul 20 07:11:24.485077 2026] [security2:error] [pid 85094:tid 85309] [client 116.62.81.204:47318] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4efK_nUl59BcEkkgFjsQAAAV0"]
[Mon Jul 20 07:11:24.568696 2026] [security2:error] [pid 85094:tid 85326] [client 201.27.111.74:51489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4efK_nUl59BcEkkgFjuAAAAW4"]
[Mon Jul 20 07:11:24.568828 2026] [security2:error] [pid 85094:tid 85326] [client 201.27.111.74:51489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4efK_nUl59BcEkkgFjuAAAAW4"]
[Mon Jul 20 07:11:24.616223 2026] [security2:error] [pid 85094:tid 85309] [client 116.62.81.204:47318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4efK_nUl59BcEkkgFjsQAAAV0"]
[Mon Jul 20 07:11:24.714987 2026] [security2:error] [pid 85094:tid 85282] [client 104.234.53.72:55751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4efK_nUl59BcEkkgFjwAAAAUI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:24.920941 2026] [security2:error] [pid 85094:tid 85279] [client 13.233.207.33:43824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4efK_nUl59BcEkkgFjyAAAAUA"]
[Mon Jul 20 07:11:24.927643 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4efHDvNPGtvLGb7O0LqgAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:25.140513 2026] [security2:error] [pid 78969:tid 79154] [client 194.61.41.56:32529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/upgrade/index.php"] [unique_id "al4efXDvNPGtvLGb7O0LugAAALw"]
[Mon Jul 20 07:11:25.141724 2026] [security2:error] [pid 85094:tid 85349] [client 77.110.127.138:64978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efa_nUl59BcEkkgFjygAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:25.141808 2026] [security2:error] [pid 85094:tid 85349] [client 77.110.127.138:64978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efa_nUl59BcEkkgFjygAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:25.415831 2026] [security2:error] [pid 85094:tid 85293] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4efK_nUl59BcEkkgFjsAAAAU0"]
[Mon Jul 20 07:11:25.419406 2026] [security2:error] [pid 85094:tid 85250] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4efK_nUl59BcEkkgFjqAAAASM"]
[Mon Jul 20 07:11:25.584670 2026] [security2:error] [pid 85094:tid 85238] [client 14.225.17.146:60245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4efa_nUl59BcEkkgFj0gAAARc"], referer: http://lifeisbetterlakeside.com/2017
[Mon Jul 20 07:11:25.642359 2026] [security2:error] [pid 78969:tid 79037] [remote 124.55.178.99:56610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4efXDvNPGtvLGb7O0LzgAA6kM"]
[Mon Jul 20 07:11:25.642534 2026] [security2:error] [pid 78969:tid 79200] [client 124.55.178.99:56610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4efXDvNPGtvLGb7O0LzgAA6kM"]
[Mon Jul 20 07:11:25.819124 2026] [security2:error] [pid 85094:tid 85246] [client 77.110.127.138:64982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efa_nUl59BcEkkgFj3gAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:25.819232 2026] [security2:error] [pid 85094:tid 85246] [client 77.110.127.138:64982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efa_nUl59BcEkkgFj3gAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:25.919649 2026] [security2:error] [pid 78969:tid 79195] [client 194.61.41.105:63165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-network-query-stat.php"] [unique_id "al4efXDvNPGtvLGb7O0L4wAAAOU"]
[Mon Jul 20 07:11:26.135277 2026] [security2:error] [pid 85094:tid 85264] [client 13.233.207.33:43832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4efq_nUl59BcEkkgFj6QAAATE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:11:26.139955 2026] [security2:error] [pid 85094:tid 85183] [remote 94.184.4.240:1678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.4.184.94.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4efq_nUl59BcEkkgFj6AABe1c"]
[Mon Jul 20 07:11:26.157776 2026] [security2:error] [pid 78969:tid 79144] [client 77.110.127.138:64984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efnDvNPGtvLGb7O0L6gAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:26.157879 2026] [security2:error] [pid 78969:tid 79144] [client 77.110.127.138:64984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efnDvNPGtvLGb7O0L6gAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:26.277387 2026] [security2:error] [pid 78969:tid 79156] [client 14.225.17.146:58735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4efnDvNPGtvLGb7O0L5gAAAL4"], referer: http://fineartsfactory.net/2017
[Mon Jul 20 07:11:26.422229 2026] [security2:error] [pid 85094:tid 85237] [client 77.110.127.138:64989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efq_nUl59BcEkkgFj9AAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:26.422348 2026] [security2:error] [pid 85094:tid 85237] [client 77.110.127.138:64989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4efq_nUl59BcEkkgFj9AAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:26.440846 2026] [security2:error] [pid 78969:tid 79046] [remote 100.42.189.89:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4efnDvNPGtvLGb7O0L-wAA8Uw"]
[Mon Jul 20 07:11:26.638208 2026] [security2:error] [pid 85094:tid 85271] [client 194.61.41.89:46929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/pridmag/db.php"] [unique_id "al4efq_nUl59BcEkkgFj-gAAATg"]
[Mon Jul 20 07:11:26.671999 2026] [security2:error] [pid 78969:tid 79048] [remote 100.42.189.89:48812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4efnDvNPGtvLGb7O0MBQAAok4"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 07:11:26.846139 2026] [security2:error] [pid 78969:tid 79214] [client 14.225.17.146:57514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4efnDvNPGtvLGb7O0MCQAAAPg"], referer: http://olearyplumbingllc.com/2017
[Mon Jul 20 07:11:27.206200 2026] [security2:error] [pid 78969:tid 79120] [client 57.141.18.73:50828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4efXDvNPGtvLGb7O0L1AAAmjM"]
[Mon Jul 20 07:11:27.207879 2026] [security2:error] [pid 78969:tid 79101] [client 77.110.127.138:64993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef3DvNPGtvLGb7O0MIAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:27.207984 2026] [security2:error] [pid 78969:tid 79101] [client 77.110.127.138:64993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef3DvNPGtvLGb7O0MIAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:27.262794 2026] [security2:error] [pid 85094:tid 85348] [client 116.62.81.204:47864] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef6_nUl59BcEkkgFkFgAAAYQ"]
[Mon Jul 20 07:11:27.289709 2026] [security2:error] [pid 85094:tid 85189] [remote 72.167.132.114:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4ef6_nUl59BcEkkgFkGAABNl0"]
[Mon Jul 20 07:11:27.386772 2026] [security2:error] [pid 85094:tid 85348] [client 116.62.81.204:47864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef6_nUl59BcEkkgFkFgAAAYQ"]
[Mon Jul 20 07:11:27.419623 2026] [security2:error] [pid 78969:tid 79138] [client 194.61.41.247:54459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/plugin-install.php"] [unique_id "al4ef3DvNPGtvLGb7O0MKwAAAKw"]
[Mon Jul 20 07:11:27.516828 2026] [security2:error] [pid 85094:tid 85191] [remote 72.167.132.114:57648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4ef6_nUl59BcEkkgFkIgABDl8"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 07:11:27.621630 2026] [security2:error] [pid 78969:tid 79127] [client 77.110.127.138:64997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef3DvNPGtvLGb7O0MMwAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:27.621771 2026] [security2:error] [pid 78969:tid 79127] [client 77.110.127.138:64997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef3DvNPGtvLGb7O0MMwAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:27.929182 2026] [security2:error] [pid 85094:tid 85323] [client 14.225.17.146:57300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4ef6_nUl59BcEkkgFkKQAAAWs"], referer: http://hilltopnurseryinc.com/2017
[Mon Jul 20 07:11:27.970101 2026] [security2:error] [pid 85094:tid 85193] [remote 20.153.140.50:57554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ef6_nUl59BcEkkgFkLAABWWE"]
[Mon Jul 20 07:11:27.988785 2026] [security2:error] [pid 78969:tid 79122] [client 77.110.127.138:64967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef3DvNPGtvLGb7O0MTQAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:27.988887 2026] [security2:error] [pid 78969:tid 79122] [client 77.110.127.138:64967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ef3DvNPGtvLGb7O0MTQAAAJw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:28.152923 2026] [security2:error] [pid 78969:tid 79159] [client 194.61.41.105:24833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-session-tokens-https.php"] [unique_id "al4egHDvNPGtvLGb7O0MVAAAAME"]
[Mon Jul 20 07:11:28.153919 2026] [security2:error] [pid 78969:tid 79205] [client 200.6.17.55:59148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4egHDvNPGtvLGb7O0MUAAAAO8"]
[Mon Jul 20 07:11:28.186514 2026] [security2:error] [pid 85094:tid 85259] [client 104.234.53.67:30705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4egK_nUl59BcEkkgFkOQAAASw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:28.196619 2026] [security2:error] [pid 78969:tid 79158] [client 154.58.229.20:55896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "steadfastwolfproductions.com"] [uri "/secrets.json"] [unique_id "al4egHDvNPGtvLGb7O0MWQAAAMA"]
[Mon Jul 20 07:11:28.196741 2026] [security2:error] [pid 78969:tid 79158] [client 154.58.229.20:55896] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "steadfastwolfproductions.com"] [uri "/secrets.json"] [unique_id "al4egHDvNPGtvLGb7O0MWQAAAMA"]
[Mon Jul 20 07:11:28.362200 2026] [security2:error] [pid 78969:tid 79114] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egHDvNPGtvLGb7O0MXAAAAJQ"]
[Mon Jul 20 07:11:28.407128 2026] [security2:error] [pid 85094:tid 85197] [remote 20.153.140.50:57554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4egK_nUl59BcEkkgFkQwABP2U"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:11:28.539880 2026] [security2:error] [pid 85094:tid 85344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4egK_nUl59BcEkkgFkOAAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:28.576236 2026] [security2:error] [pid 85094:tid 85251] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egK_nUl59BcEkkgFkRwAAASQ"]
[Mon Jul 20 07:11:28.724893 2026] [security2:error] [pid 85094:tid 85308] [client 14.225.17.146:57465] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4egK_nUl59BcEkkgFkSAAAAVw"], referer: http://bigwormfishing.com/2017
[Mon Jul 20 07:11:28.797223 2026] [security2:error] [pid 85094:tid 85273] [client 52.140.101.203:21954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4egK_nUl59BcEkkgFkSgAAATo"]
[Mon Jul 20 07:11:28.924720 2026] [security2:error] [pid 85094:tid 85271] [client 194.61.41.104:49173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/load.php"] [unique_id "al4egK_nUl59BcEkkgFkVQAAATg"]
[Mon Jul 20 07:11:29.025359 2026] [security2:error] [pid 85094:tid 85330] [client 52.140.101.203:21954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ega_nUl59BcEkkgFkXQAAAXI"]
[Mon Jul 20 07:11:29.178231 2026] [security2:error] [pid 85094:tid 85299] [client 57.141.18.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkYQAAAVM"]
[Mon Jul 20 07:11:29.187938 2026] [security2:error] [pid 78969:tid 79129] [client 154.58.229.20:55132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "steadfastwolfproductions.com"] [uri "/wp-config.php.bak"] [unique_id "al4egXDvNPGtvLGb7O0MjgAAAKM"]
[Mon Jul 20 07:11:29.189017 2026] [security2:error] [pid 78969:tid 79151] [client 154.58.229.20:55170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "steadfastwolfproductions.com"] [uri "/serverless.yml"] [unique_id "al4egXDvNPGtvLGb7O0MlAAAALk"]
[Mon Jul 20 07:11:29.189150 2026] [security2:error] [pid 78969:tid 79151] [client 154.58.229.20:55170] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "steadfastwolfproductions.com"] [uri "/serverless.yml"] [unique_id "al4egXDvNPGtvLGb7O0MlAAAALk"]
[Mon Jul 20 07:11:29.191308 2026] [security2:error] [pid 85094:tid 85237] [client 154.58.229.20:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/web.config"] [unique_id "al4ega_nUl59BcEkkgFkbQAAARY"]
[Mon Jul 20 07:11:29.193119 2026] [security2:error] [pid 78969:tid 79212] [client 154.58.229.20:55218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "steadfastwolfproductions.com"] [uri "/.aws/config"] [unique_id "al4egXDvNPGtvLGb7O0MnwAAAPY"]
[Mon Jul 20 07:11:29.193218 2026] [security2:error] [pid 78969:tid 79212] [client 154.58.229.20:55218] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "steadfastwolfproductions.com"] [uri "/.aws/config"] [unique_id "al4egXDvNPGtvLGb7O0MnwAAAPY"]
[Mon Jul 20 07:11:29.195078 2026] [security2:error] [pid 78969:tid 79170] [client 154.58.229.20:55028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/.env"] [unique_id "al4egXDvNPGtvLGb7O0MnAAAAMw"]
[Mon Jul 20 07:11:29.202492 2026] [security2:error] [pid 78969:tid 79217] [client 154.58.229.20:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.229.58.154.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "steadfastwolfproductions.com"] [uri "/wp-config.php"] [unique_id "al4egXDvNPGtvLGb7O0MkQAAAPs"]
[Mon Jul 20 07:11:29.225017 2026] [security2:error] [pid 78969:tid 79104] [client 50.116.65.227:41342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4egXDvNPGtvLGb7O0MpgAAAIo"]
[Mon Jul 20 07:11:29.235519 2026] [security2:error] [pid 85094:tid 85338] [client 50.116.65.227:41354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ega_nUl59BcEkkgFkhQAAAXo"]
[Mon Jul 20 07:11:29.247015 2026] [security2:error] [pid 85094:tid 85227] [client 57.141.18.16:60230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ef6_nUl59BcEkkgFkKwABDGA"]
[Mon Jul 20 07:11:29.308575 2026] [security2:error] [pid 85094:tid 85271] [client 213.152.186.163:46332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ega_nUl59BcEkkgFkkQAAATg"]
[Mon Jul 20 07:11:29.308784 2026] [security2:error] [pid 85094:tid 85271] [client 213.152.186.163:46332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ega_nUl59BcEkkgFkkQAAATg"]
[Mon Jul 20 07:11:29.417328 2026] [security2:error] [pid 78969:tid 79155] [client 14.225.17.146:57500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MhwAAAL0"], referer: http://narv.co/2017
[Mon Jul 20 07:11:29.473655 2026] [security2:error] [pid 85094:tid 85244] [client 14.225.17.146:60053] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkkgAAAR0"], referer: http://lutheranphilosopher.com/2017
[Mon Jul 20 07:11:29.475667 2026] [security2:error] [pid 85094:tid 85293] [client 154.58.229.20:55498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/app/.env"] [unique_id "al4ega_nUl59BcEkkgFkoQAAAU0"]
[Mon Jul 20 07:11:29.475987 2026] [security2:error] [pid 78969:tid 79133] [client 154.58.229.20:55052] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/.env.backup"] [unique_id "al4egXDvNPGtvLGb7O0MxQAAAKc"]
[Mon Jul 20 07:11:29.476040 2026] [security2:error] [pid 85094:tid 85307] [client 154.58.229.20:55246] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/.env.old"] [unique_id "al4ega_nUl59BcEkkgFkpAAAAVs"]
[Mon Jul 20 07:11:29.476576 2026] [security2:error] [pid 85094:tid 85330] [client 154.58.229.20:55088] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/.env.bak"] [unique_id "al4ega_nUl59BcEkkgFkowAAAXI"]
[Mon Jul 20 07:11:29.496033 2026] [security2:error] [pid 78969:tid 79215] [client 154.58.229.20:55042] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/api/.env"] [unique_id "al4egXDvNPGtvLGb7O0MywAAAPk"]
[Mon Jul 20 07:11:29.506880 2026] [security2:error] [pid 85094:tid 85260] [client 154.58.229.20:55598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/backend/.env"] [unique_id "al4ega_nUl59BcEkkgFkqQAAAS0"]
[Mon Jul 20 07:11:29.644005 2026] [security2:error] [pid 78969:tid 79110] [client 194.61.41.252:61291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/firewall.php7"] [unique_id "al4egXDvNPGtvLGb7O0M2QAAAJA"]
[Mon Jul 20 07:11:29.655074 2026] [security2:error] [pid 78969:tid 79222] [client 154.58.229.20:55028] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/laravel/.env"] [unique_id "al4egXDvNPGtvLGb7O0M3QAAAQA"]
[Mon Jul 20 07:11:29.655077 2026] [security2:error] [pid 85094:tid 85285] [client 154.58.229.20:55506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/public/.env"] [unique_id "al4ega_nUl59BcEkkgFkrwAAAUU"]
[Mon Jul 20 07:11:29.656145 2026] [security2:error] [pid 85094:tid 85344] [client 154.58.229.20:55386] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "steadfastwolfproductions.com"] [uri "/wp/.env"] [unique_id "al4ega_nUl59BcEkkgFksAAAAYA"]
[Mon Jul 20 07:11:29.671320 2026] [security2:error] [pid 78969:tid 79169] [client 14.225.17.146:60444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MiAAAAMs"], referer: http://alrowad-hub.net/2017
[Mon Jul 20 07:11:29.767840 2026] [security2:error] [pid 78969:tid 79117] [client 14.225.17.146:57606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0M2AAAAJc"], referer: https://bigwormfishing.com/2017
[Mon Jul 20 07:11:29.767990 2026] [security2:error] [pid 85094:tid 85313] [client 154.58.229.20:55908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "steadfastwolfproductions.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/view.min.js.map"] [unique_id "al4ega_nUl59BcEkkgFkuAAAAWE"]
[Mon Jul 20 07:11:29.768105 2026] [security2:error] [pid 85094:tid 85313] [client 154.58.229.20:55908] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "steadfastwolfproductions.com"] [uri "/wp-includes/js/dist/script-modules/block-library/navigation/view.min.js.map"] [unique_id "al4ega_nUl59BcEkkgFkuAAAAWE"]
[Mon Jul 20 07:11:29.788537 2026] [security2:error] [pid 85094:tid 85205] [remote 15.206.251.117:51002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ega_nUl59BcEkkgFkuQABT20"]
[Mon Jul 20 07:11:29.815677 2026] [security2:error] [pid 85094:tid 85338] [client 52.233.165.60:1603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ega_nUl59BcEkkgFkugAAAXo"]
[Mon Jul 20 07:11:29.964968 2026] [security2:error] [pid 85094:tid 85268] [client 52.233.165.60:1603] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ega_nUl59BcEkkgFkwgAAATU"]
[Mon Jul 20 07:11:29.996634 2026] [security2:error] [pid 85094:tid 85343] [client 191.96.254.24:50763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4ega_nUl59BcEkkgFkwAAAAX8"]
[Mon Jul 20 07:11:30.173242 2026] [security2:error] [pid 85094:tid 85283] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkhgAAAUM"]
[Mon Jul 20 07:11:30.191191 2026] [security2:error] [pid 85094:tid 85339] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkiAAAAXs"]
[Mon Jul 20 07:11:30.193811 2026] [security2:error] [pid 78969:tid 79173] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MpwAAAM8"]
[Mon Jul 20 07:11:30.194562 2026] [security2:error] [pid 85094:tid 85231] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkiQAAARA"]
[Mon Jul 20 07:11:30.194723 2026] [security2:error] [pid 78969:tid 79211] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MqQAAAPU"]
[Mon Jul 20 07:11:30.196548 2026] [security2:error] [pid 85094:tid 85294] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkigAAAU4"]
[Mon Jul 20 07:11:30.196782 2026] [security2:error] [pid 85094:tid 85262] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkjAAAAS8"]
[Mon Jul 20 07:11:30.198686 2026] [security2:error] [pid 85094:tid 85243] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkiwAAARw"]
[Mon Jul 20 07:11:30.201402 2026] [security2:error] [pid 85094:tid 85265] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkjwAAATI"]
[Mon Jul 20 07:11:30.202335 2026] [security2:error] [pid 85094:tid 85241] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkkAAAARo"]
[Mon Jul 20 07:11:30.203665 2026] [security2:error] [pid 78969:tid 79201] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MqwAAAOs"]
[Mon Jul 20 07:11:30.206629 2026] [security2:error] [pid 85094:tid 85209] [remote 15.206.251.117:51002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4egq_nUl59BcEkkgFkyQABFnE"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:11:30.207541 2026] [security2:error] [pid 85094:tid 85332] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkjQAAAXQ"]
[Mon Jul 20 07:11:30.209876 2026] [security2:error] [pid 85094:tid 85346] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkhwAAAYI"]
[Mon Jul 20 07:11:30.241139 2026] [security2:error] [pid 78969:tid 79225] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MrAAAAQM"]
[Mon Jul 20 07:11:30.242191 2026] [security2:error] [pid 78969:tid 79138] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MqAAAAKw"]
[Mon Jul 20 07:11:30.341600 2026] [security2:error] [pid 78969:tid 79051] [remote 217.113.60.80:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4egnDvNPGtvLGb7O0NAQAAsFE"]
[Mon Jul 20 07:11:30.347305 2026] [security2:error] [pid 85094:tid 85210] [remote 173.249.4.11:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4egq_nUl59BcEkkgFk0AABH3I"]
[Mon Jul 20 07:11:30.434743 2026] [security2:error] [pid 85094:tid 85329] [client 194.61.41.78:27385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/crystal/lrs_dage.php"] [unique_id "al4egq_nUl59BcEkkgFk1wAAAXE"]
[Mon Jul 20 07:11:30.561033 2026] [security2:error] [pid 85094:tid 85213] [remote 173.249.4.11:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4egq_nUl59BcEkkgFk3gABTHU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:30.572354 2026] [security2:error] [pid 78969:tid 79083] [remote 217.113.60.80:50028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4egnDvNPGtvLGb7O0NDAAAzHE"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:11:30.726307 2026] [security2:error] [pid 85094:tid 85233] [client 77.110.127.138:65007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4egq_nUl59BcEkkgFk5wAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:30.726443 2026] [security2:error] [pid 85094:tid 85233] [client 77.110.127.138:65007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4egq_nUl59BcEkkgFk5wAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:30.792992 2026] [security2:error] [pid 85094:tid 85227] [client 34.201.171.57:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkvQAAAQw"]
[Mon Jul 20 07:11:30.833860 2026] [security2:error] [pid 78969:tid 79106] [client 34.201.171.57:28532] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/refresco-de-avena-cold-oatmeal-drink/"] [unique_id "al4egXDvNPGtvLGb7O0M6wAAAIw"]
[Mon Jul 20 07:11:31.127396 2026] [security2:error] [pid 78969:tid 79107] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MqgAAAI0"]
[Mon Jul 20 07:11:31.158851 2026] [security2:error] [pid 85094:tid 85341] [client 194.61.41.244:23151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/upgrade/pdf.php"] [unique_id "al4eg6_nUl59BcEkkgFk-AAAAX0"]
[Mon Jul 20 07:11:31.161382 2026] [security2:error] [pid 85094:tid 85251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4egq_nUl59BcEkkgFk7AAAASQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:31.186295 2026] [security2:error] [pid 85094:tid 85352] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFktwAAAYg"]
[Mon Jul 20 07:11:31.222559 2026] [security2:error] [pid 78969:tid 79196] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MzQAAAOY"]
[Mon Jul 20 07:11:31.230333 2026] [security2:error] [pid 78969:tid 79139] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0M0AAAAK0"]
[Mon Jul 20 07:11:31.233071 2026] [security2:error] [pid 85094:tid 85314] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFktgAAAWI"]
[Mon Jul 20 07:11:31.235670 2026] [security2:error] [pid 78969:tid 79208] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MuQAAAPI"]
[Mon Jul 20 07:11:31.236638 2026] [security2:error] [pid 85094:tid 85298] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkngAAAVI"]
[Mon Jul 20 07:11:31.237459 2026] [security2:error] [pid 78969:tid 79123] [client 154.58.229.20:55626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MzwAAAJ0"]
[Mon Jul 20 07:11:31.239604 2026] [security2:error] [pid 78969:tid 79144] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MuAAAALI"]
[Mon Jul 20 07:11:31.239619 2026] [security2:error] [pid 78969:tid 79194] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MuwAAAOQ"]
[Mon Jul 20 07:11:31.248007 2026] [security2:error] [pid 85094:tid 85328] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4ega_nUl59BcEkkgFkswAAAXA"]
[Mon Jul 20 07:11:31.253232 2026] [security2:error] [pid 78969:tid 79168] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MvAAAAMo"]
[Mon Jul 20 07:11:31.257074 2026] [security2:error] [pid 78969:tid 79154] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MzgAAALw"]
[Mon Jul 20 07:11:31.261509 2026] [security2:error] [pid 78969:tid 79189] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egXDvNPGtvLGb7O0MvgAAAN8"]
[Mon Jul 20 07:11:31.284008 2026] [security2:error] [pid 85094:tid 85330] [client 154.58.229.20:55110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4egq_nUl59BcEkkgFk0gAAAXI"]
[Mon Jul 20 07:11:31.441928 2026] [security2:error] [pid 85094:tid 85321] [client 191.96.254.24:33291] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4eg6_nUl59BcEkkgFlBQAAAWk"]
[Mon Jul 20 07:11:31.501242 2026] [security2:error] [pid 78969:tid 79064] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eg3DvNPGtvLGb7O0NLgAA4l4"]
[Mon Jul 20 07:11:31.501440 2026] [security2:error] [pid 78969:tid 79192] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4eg3DvNPGtvLGb7O0NLgAA4l4"]
[Mon Jul 20 07:11:31.515823 2026] [security2:error] [pid 78969:tid 79216] [client 85.208.96.205:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/wp-admin/admin/dibujos-de-caballos/vicks-vapor-rub-on-infants.html"] [unique_id "al4eg3DvNPGtvLGb7O0NMAAAAPo"]
[Mon Jul 20 07:11:31.515931 2026] [security2:error] [pid 78969:tid 79216] [client 85.208.96.205:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lakelopezonline.com"] [uri "/wp-admin/admin/dibujos-de-caballos/vicks-vapor-rub-on-infants.html"] [unique_id "al4eg3DvNPGtvLGb7O0NMAAAAPo"]
[Mon Jul 20 07:11:31.523807 2026] [security2:error] [pid 78969:tid 79203] [client 54.204.158.117:24020] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/sopa-de-pollo-con-fideos-puerto-rican-chicken-noodle-soup"] [unique_id "al4eg3DvNPGtvLGb7O0NMQAAAO0"]
[Mon Jul 20 07:11:31.581901 2026] [security2:error] [pid 85094:tid 85293] [client 57.141.18.46:61296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4egq_nUl59BcEkkgFkwwABTW8"]
[Mon Jul 20 07:11:31.689059 2026] [security2:error] [pid 78969:tid 79046] [remote 72.167.132.114:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eg3DvNPGtvLGb7O0NQQAAtUw"]
[Mon Jul 20 07:11:31.744030 2026] [security2:error] [pid 85094:tid 85347] [client 89.124.113.107:63203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4eg6_nUl59BcEkkgFlDQAAAYM"], referer: https://sesamegreenbeans.com/nine-days-south-africa-ii/
[Mon Jul 20 07:11:31.904936 2026] [security2:error] [pid 85094:tid 85277] [client 104.234.53.65:25045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4eg6_nUl59BcEkkgFlIwAAAT4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:31.914640 2026] [security2:error] [pid 78969:tid 79038] [remote 72.167.132.114:57662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eg3DvNPGtvLGb7O0NTwAA8kQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:31.934760 2026] [security2:error] [pid 85094:tid 85300] [client 194.61.41.243:33777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/as.php"] [unique_id "al4eg6_nUl59BcEkkgFlJgAAAVQ"]
[Mon Jul 20 07:11:32.012710 2026] [security2:error] [pid 85094:tid 85317] [client 74.7.227.179:50236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4eg6_nUl59BcEkkgFlIgABZQ8"], referer: https://tejasenvironmental.com/p=845650
[Mon Jul 20 07:11:32.020229 2026] [security2:error] [pid 78969:tid 79127] [client 14.225.17.146:57599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4eg3DvNPGtvLGb7O0NRgAAAKE"], referer: http://according2plant.com/2017
[Mon Jul 20 07:11:32.115820 2026] [security2:error] [pid 85094:tid 85305] [client 187.16.64.216:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ehK_nUl59BcEkkgFlLQAAAVk"]
[Mon Jul 20 07:11:32.116011 2026] [security2:error] [pid 85094:tid 85305] [client 187.16.64.216:65304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ehK_nUl59BcEkkgFlLQAAAVk"]
[Mon Jul 20 07:11:32.135624 2026] [security2:error] [pid 78969:tid 79123] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eg3DvNPGtvLGb7O0NUAAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:32.384935 2026] [security2:error] [pid 85094:tid 85244] [client 54.166.194.245:53148] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4eg6_nUl59BcEkkgFlIAAAAR0"]
[Mon Jul 20 07:11:32.423070 2026] [security2:error] [pid 85094:tid 85116] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ehK_nUl59BcEkkgFlPgABiRQ"]
[Mon Jul 20 07:11:32.423213 2026] [security2:error] [pid 85094:tid 85353] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ehK_nUl59BcEkkgFlPgABiRQ"]
[Mon Jul 20 07:11:32.483984 2026] [security2:error] [pid 78969:tid 79216] [client 50.116.65.227:57534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ehHDvNPGtvLGb7O0NZwAAAPo"]
[Mon Jul 20 07:11:32.496921 2026] [security2:error] [pid 78969:tid 79163] [client 50.116.65.227:41444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ehHDvNPGtvLGb7O0NaQAAAMU"]
[Mon Jul 20 07:11:32.511482 2026] [security2:error] [pid 78969:tid 79138] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ehHDvNPGtvLGb7O0NXgAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:32.549660 2026] [security2:error] [pid 85094:tid 85115] [remote 8.217.108.67:6442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ehK_nUl59BcEkkgFlQgABeRM"]
[Mon Jul 20 07:11:32.662296 2026] [security2:error] [pid 85094:tid 85257] [client 116.62.81.204:48722] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ehK_nUl59BcEkkgFlTAAAASo"]
[Mon Jul 20 07:11:32.670242 2026] [security2:error] [pid 85094:tid 85347] [client 194.61.41.84:55497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/item.php"] [unique_id "al4ehK_nUl59BcEkkgFlTQAAAYM"]
[Mon Jul 20 07:11:32.687159 2026] [security2:error] [pid 85094:tid 85119] [remote 50.28.1.50:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4ehK_nUl59BcEkkgFlTgABXRc"]
[Mon Jul 20 07:11:32.687380 2026] [security2:error] [pid 85094:tid 85309] [client 50.28.1.50:43554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4ehK_nUl59BcEkkgFlTgABXRc"]
[Mon Jul 20 07:11:32.832447 2026] [security2:error] [pid 85094:tid 85257] [client 116.62.81.204:48722] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ehK_nUl59BcEkkgFlTAAAASo"]
[Mon Jul 20 07:11:33.022496 2026] [security2:error] [pid 78969:tid 79184] [client 188.236.60.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4ehHDvNPGtvLGb7O0NewAA2mY"]
[Mon Jul 20 07:11:33.024527 2026] [security2:error] [pid 78969:tid 79157] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ehHDvNPGtvLGb7O0NfwAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:33.091582 2026] [security2:error] [pid 78969:tid 79201] [client 103.144.65.217:51538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ehXDvNPGtvLGb7O0NiAAAAOs"]
[Mon Jul 20 07:11:33.091775 2026] [security2:error] [pid 78969:tid 79201] [client 103.144.65.217:51538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ehXDvNPGtvLGb7O0NiAAAAOs"]
[Mon Jul 20 07:11:33.404467 2026] [security2:error] [pid 78969:tid 79142] [client 88.241.67.160:53965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ehXDvNPGtvLGb7O0NmQAAALA"]
[Mon Jul 20 07:11:33.404634 2026] [security2:error] [pid 78969:tid 79142] [client 88.241.67.160:53965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ehXDvNPGtvLGb7O0NmQAAALA"]
[Mon Jul 20 07:11:33.416108 2026] [security2:error] [pid 85094:tid 85349] [client 100.31.58.60:46172] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4ehK_nUl59BcEkkgFlSAAAAYU"]
[Mon Jul 20 07:11:33.438374 2026] [security2:error] [pid 85094:tid 85350] [client 14.225.17.146:60185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4eha_nUl59BcEkkgFlXgAAAYY"]
[Mon Jul 20 07:11:33.453169 2026] [security2:error] [pid 85094:tid 85225] [client 194.61.41.94:37423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/wp-conflg.php"] [unique_id "al4eha_nUl59BcEkkgFlbwAAAQo"]
[Mon Jul 20 07:11:33.477660 2026] [security2:error] [pid 85094:tid 85305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eha_nUl59BcEkkgFlXAAAAVk"]
[Mon Jul 20 07:11:33.631179 2026] [security2:error] [pid 85094:tid 85132] [remote 95.217.78.234:47098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eha_nUl59BcEkkgFldAABHSQ"]
[Mon Jul 20 07:11:33.671542 2026] [security2:error] [pid 85094:tid 85233] [client 89.124.113.107:63330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4eha_nUl59BcEkkgFldQAAARI"], referer: https://www.sesamegreenbeans.com/nine-days-south-africa-ii/
[Mon Jul 20 07:11:33.671660 2026] [security2:error] [pid 85094:tid 85233] [client 89.124.113.107:63330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4eha_nUl59BcEkkgFldQAAARI"], referer: https://www.sesamegreenbeans.com/nine-days-south-africa-ii/
[Mon Jul 20 07:11:33.750312 2026] [security2:error] [pid 85094:tid 85133] [remote 8.217.108.67:6442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eha_nUl59BcEkkgFlfAABeCU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:11:33.759224 2026] [security2:error] [pid 85094:tid 85343] [client 74.208.214.194:47804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4eha_nUl59BcEkkgFlfgAAAX8"]
[Mon Jul 20 07:11:33.766456 2026] [security2:error] [pid 85094:tid 85254] [client 98.88.240.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eha_nUl59BcEkkgFlcwABJyI"]
[Mon Jul 20 07:11:33.874725 2026] [security2:error] [pid 85094:tid 85138] [remote 95.217.78.234:47098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eha_nUl59BcEkkgFliwABUio"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:33.943652 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ehXDvNPGtvLGb7O0NpAAAAMw"]
[Mon Jul 20 07:11:34.232958 2026] [security2:error] [pid 85094:tid 85323] [client 194.61.41.249:63871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/install.php"] [unique_id "al4ehq_nUl59BcEkkgFllAAAAWs"]
[Mon Jul 20 07:11:34.288123 2026] [security2:error] [pid 85094:tid 85284] [client 157.66.67.132:55970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mochawavepublishing.com"] [uri "/index.php"] [unique_id "al4ehK_nUl59BcEkkgFlLgAAAUQ"]
[Mon Jul 20 07:11:34.453420 2026] [security2:error] [pid 78969:tid 79137] [client 50.116.65.227:57548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ehnDvNPGtvLGb7O0NvAAAAKs"]
[Mon Jul 20 07:11:34.465111 2026] [security2:error] [pid 85094:tid 85309] [client 50.116.65.227:41494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-2-Feature-Image.jpg"] [unique_id "al4ehq_nUl59BcEkkgFloQAAAV0"]
[Mon Jul 20 07:11:34.468891 2026] [security2:error] [pid 85094:tid 85235] [client 77.110.127.138:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ehq_nUl59BcEkkgFlogAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:34.469016 2026] [security2:error] [pid 85094:tid 85235] [client 77.110.127.138:64987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ehq_nUl59BcEkkgFlogAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:34.478860 2026] [security2:error] [pid 78969:tid 78970] [remote 103.187.169.251:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ehnDvNPGtvLGb7O0NvQAAkgA"]
[Mon Jul 20 07:11:34.497646 2026] [security2:error] [pid 85094:tid 85290] [client 57.141.18.70:61600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ehK_nUl59BcEkkgFlRgABShU"]
[Mon Jul 20 07:11:34.509211 2026] [security2:error] [pid 85094:tid 85314] [client 14.225.17.146:60148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4eha_nUl59BcEkkgFlWQAAAWI"], referer: http://iagdevelopments.com/2017
[Mon Jul 20 07:11:34.748785 2026] [security2:error] [pid 78969:tid 79044] [remote 95.217.78.234:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ehnDvNPGtvLGb7O0NxQAArUo"]
[Mon Jul 20 07:11:34.986573 2026] [security2:error] [pid 78969:tid 79001] [remote 95.217.78.234:47104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ehnDvNPGtvLGb7O0N1QAAsR8"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:11:35.018892 2026] [security2:error] [pid 78969:tid 79150] [client 194.61.41.66:42963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/db.php"] [unique_id "al4eh3DvNPGtvLGb7O0N1wAAALg"]
[Mon Jul 20 07:11:35.093074 2026] [security2:error] [pid 78969:tid 79090] [remote 103.187.169.251:46168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4eh3DvNPGtvLGb7O0N2gAA03g"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:11:35.221518 2026] [security2:error] [pid 78969:tid 79193] [client 154.58.229.20:55252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.229.58.154.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "steadfastwolfproductions.com"] [uri "/xmlrpc.php"] [unique_id "al4eh3DvNPGtvLGb7O0N3gAAAOM"]
[Mon Jul 20 07:11:35.237903 2026] [security2:error] [pid 85094:tid 85301] [client 104.234.53.78:27965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4eh6_nUl59BcEkkgFlxwAAAVU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:35.248615 2026] [security2:error] [pid 85094:tid 85274] [client 14.225.17.146:60373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFlugAAATs"], referer: http://mazzucelli.com/2017
[Mon Jul 20 07:11:35.294109 2026] [security2:error] [pid 85094:tid 85276] [client 201.27.111.74:51995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eh6_nUl59BcEkkgFlygAAAT0"]
[Mon Jul 20 07:11:35.294235 2026] [security2:error] [pid 85094:tid 85276] [client 201.27.111.74:51995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eh6_nUl59BcEkkgFlygAAAT0"]
[Mon Jul 20 07:11:35.310776 2026] [security2:error] [pid 85094:tid 85251] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFlxgAAASQ"]
[Mon Jul 20 07:11:35.317060 2026] [security2:error] [pid 78969:tid 79199] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eh3DvNPGtvLGb7O0N4gAAAOk"]
[Mon Jul 20 07:11:35.322195 2026] [security2:error] [pid 85094:tid 85235] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFlxAAAARQ"]
[Mon Jul 20 07:11:35.331448 2026] [security2:error] [pid 85094:tid 85336] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFlwwAAAXg"]
[Mon Jul 20 07:11:35.339501 2026] [security2:error] [pid 85094:tid 85327] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFlxQAAAW8"]
[Mon Jul 20 07:11:35.440555 2026] [security2:error] [pid 85094:tid 85337] [client 14.225.17.146:56304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFlywAAAXk"], referer: https://iagdevelopments.com/2017
[Mon Jul 20 07:11:35.621890 2026] [security2:error] [pid 85094:tid 85302] [client 154.58.229.20:55324] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "steadfastwolfproductions.com"] [uri "/feed"] [unique_id "al4eh6_nUl59BcEkkgFl5wAAAVY"]
[Mon Jul 20 07:11:35.622014 2026] [security2:error] [pid 85094:tid 85302] [client 154.58.229.20:55324] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "steadfastwolfproductions.com"] [uri "/feed"] [unique_id "al4eh6_nUl59BcEkkgFl5wAAAVY"]
[Mon Jul 20 07:11:35.663197 2026] [security2:error] [pid 85094:tid 85264] [client 14.225.17.146:58734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4eh6_nUl59BcEkkgFl5gAAATE"], referer: http://balticsteelmgmt.com/2017
[Mon Jul 20 07:11:35.747889 2026] [security2:error] [pid 78969:tid 79210] [client 194.61.41.68:22829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/fan.php"] [unique_id "al4eh3DvNPGtvLGb7O0N_AAAAPQ"]
[Mon Jul 20 07:11:36.137811 2026] [security2:error] [pid 78969:tid 79163] [client 158.173.166.181:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eiHDvNPGtvLGb7O0ODQAAAMU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:11:36.241385 2026] [security2:error] [pid 85094:tid 85150] [remote 100.42.189.89:48890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eiK_nUl59BcEkkgFl9QABJDY"]
[Mon Jul 20 07:11:36.343905 2026] [security2:error] [pid 78969:tid 79177] [client 14.225.17.146:64268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4eiHDvNPGtvLGb7O0OFwAAANM"], referer: http://keywayconstructionclt.com/2017
[Mon Jul 20 07:11:36.464655 2026] [security2:error] [pid 85094:tid 85152] [remote 100.42.189.89:48890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4eiK_nUl59BcEkkgFmAQABDDg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:11:36.498218 2026] [security2:error] [pid 78969:tid 79160] [client 14.168.214.232:60331] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4eiHDvNPGtvLGb7O0OGwAAAMI"]
[Mon Jul 20 07:11:36.548574 2026] [security2:error] [pid 85094:tid 85263] [client 194.61.41.66:51255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/colors.php"] [unique_id "al4eiK_nUl59BcEkkgFmBwAAATA"]
[Mon Jul 20 07:11:36.759618 2026] [security2:error] [pid 85094:tid 85317] [client 116.62.81.204:49528] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eiK_nUl59BcEkkgFmDAAAAWU"]
[Mon Jul 20 07:11:36.885328 2026] [security2:error] [pid 85094:tid 85317] [client 116.62.81.204:49528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4eiK_nUl59BcEkkgFmDAAAAWU"]
[Mon Jul 20 07:11:37.243333 2026] [security2:error] [pid 85094:tid 85241] [client 14.225.17.146:55739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4eia_nUl59BcEkkgFmLAAAARo"], referer: https://keywayconstructionclt.com/2017
[Mon Jul 20 07:11:37.304807 2026] [security2:error] [pid 85094:tid 85227] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eia_nUl59BcEkkgFmMgAAAQw"]
[Mon Jul 20 07:11:37.335011 2026] [security2:error] [pid 85094:tid 85310] [client 194.61.41.57:50233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/mah.php"] [unique_id "al4eia_nUl59BcEkkgFmMwAAAV4"]
[Mon Jul 20 07:11:37.344080 2026] [security2:error] [pid 78969:tid 79106] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eiXDvNPGtvLGb7O0OPgAAAIw"]
[Mon Jul 20 07:11:37.361637 2026] [security2:error] [pid 78969:tid 79163] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eiXDvNPGtvLGb7O0OPwAAAMU"]
[Mon Jul 20 07:11:37.563591 2026] [security2:error] [pid 85094:tid 85276] [client 104.234.53.52:36877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4eia_nUl59BcEkkgFmQgAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:37.690246 2026] [security2:error] [pid 78969:tid 79187] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eiXDvNPGtvLGb7O0OTwAA3TI"], referer: http://aleishapenny.ca/2017
[Mon Jul 20 07:11:37.928737 2026] [security2:error] [pid 78969:tid 79143] [client 57.141.18.55:43696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eh3DvNPGtvLGb7O0OAQAAsXc"]
[Mon Jul 20 07:11:38.090577 2026] [security2:error] [pid 85094:tid 85280] [client 154.58.229.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4eia_nUl59BcEkkgFmYgAAAUE"]
[Mon Jul 20 07:11:38.125898 2026] [security2:error] [pid 85094:tid 85340] [client 194.61.41.62:20747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/waf_defender.php"] [unique_id "al4eiq_nUl59BcEkkgFmZgAAAXw"]
[Mon Jul 20 07:11:38.363897 2026] [security2:error] [pid 85094:tid 85257] [client 50.116.65.227:41560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4eiq_nUl59BcEkkgFmbgAAASo"]
[Mon Jul 20 07:11:38.373827 2026] [security2:error] [pid 85094:tid 85267] [client 50.116.65.227:41570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4eiq_nUl59BcEkkgFmcQAAATQ"]
[Mon Jul 20 07:11:38.451572 2026] [security2:error] [pid 85094:tid 85248] [client 77.110.127.138:65046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eiq_nUl59BcEkkgFmegAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:38.451685 2026] [security2:error] [pid 85094:tid 85248] [client 77.110.127.138:65046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eiq_nUl59BcEkkgFmegAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:38.454215 2026] [security2:error] [pid 85094:tid 85243] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eiq_nUl59BcEkkgFmbQABHEc"], referer: https://aleishapenny.ca/2017
[Mon Jul 20 07:11:38.864608 2026] [security2:error] [pid 78969:tid 79197] [client 194.61.41.61:59817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/ectoplasm/content.php"] [unique_id "al4einDvNPGtvLGb7O0OfwAAAOc"]
[Mon Jul 20 07:11:38.908883 2026] [security2:error] [pid 85094:tid 85329] [client 14.225.17.146:60004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4eiq_nUl59BcEkkgFmhAAAAXE"], referer: http://koaconsultants.com/2017
[Mon Jul 20 07:11:39.020509 2026] [security2:error] [pid 85094:tid 85237] [client 14.225.17.146:58981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4eiq_nUl59BcEkkgFmgAAAARY"], referer: http://adastra.love/2017
[Mon Jul 20 07:11:39.257337 2026] [security2:error] [pid 85094:tid 85315] [client 14.225.17.146:60307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4eiq_nUl59BcEkkgFmagAAAWM"], referer: http://ncsynchro.com/2017
[Mon Jul 20 07:11:39.637216 2026] [security2:error] [pid 85094:tid 85283] [client 194.61.41.68:56183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/install.php"] [unique_id "al4ei6_nUl59BcEkkgFmoQAAAUM"]
[Mon Jul 20 07:11:39.827722 2026] [security2:error] [pid 85094:tid 85339] [client 57.141.18.34:53506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eia_nUl59BcEkkgFmUAABez8"]
[Mon Jul 20 07:11:39.875103 2026] [security2:error] [pid 85094:tid 85248] [client 117.211.236.168:56895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ei6_nUl59BcEkkgFmqgAAASE"]
[Mon Jul 20 07:11:39.875197 2026] [security2:error] [pid 85094:tid 85248] [client 117.211.236.168:56895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ei6_nUl59BcEkkgFmqgAAASE"]
[Mon Jul 20 07:11:40.014348 2026] [security2:error] [pid 85094:tid 85262] [client 14.225.17.146:55654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ei6_nUl59BcEkkgFmpQAAAS8"]
[Mon Jul 20 07:11:40.061100 2026] [security2:error] [pid 78969:tid 79166] [client 14.225.17.146:59000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4ei3DvNPGtvLGb7O0OsAAAAMg"], referer: http://younutrition.gr/2017
[Mon Jul 20 07:11:40.179552 2026] [security2:error] [pid 85094:tid 85301] [client 45.157.112.60:28151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ejK_nUl59BcEkkgFmvAAAAVU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:11:40.426530 2026] [security2:error] [pid 78969:tid 79137] [client 194.61.41.79:56861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/thickbox/about.php"] [unique_id "al4ejHDvNPGtvLGb7O0O0gAAAKs"]
[Mon Jul 20 07:11:40.520137 2026] [security2:error] [pid 78969:tid 79190] [client 104.234.53.66:23499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ejHDvNPGtvLGb7O0O1gAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:41.149997 2026] [security2:error] [pid 78969:tid 79148] [client 194.61.41.61:39611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/content.php"] [unique_id "al4ejXDvNPGtvLGb7O0O8QAAALY"]
[Mon Jul 20 07:11:41.686356 2026] [security2:error] [pid 85094:tid 85188] [remote 160.187.68.132:38858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eja_nUl59BcEkkgFm_gABM1w"]
[Mon Jul 20 07:11:41.928565 2026] [security2:error] [pid 85094:tid 85345] [client 57.141.18.15:48996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ei6_nUl59BcEkkgFmpwABgVE"]
[Mon Jul 20 07:11:41.945062 2026] [security2:error] [pid 85094:tid 85254] [client 194.61.41.75:32093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/icascreenshots.php"] [unique_id "al4eja_nUl59BcEkkgFnCgAAASc"]
[Mon Jul 20 07:11:42.161694 2026] [security2:error] [pid 85094:tid 85190] [remote 160.187.68.132:38858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ejq_nUl59BcEkkgFnEgABhl4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:11:42.228571 2026] [security2:error] [pid 78969:tid 79069] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ejnDvNPGtvLGb7O0PIAAA_2M"]
[Mon Jul 20 07:11:42.228700 2026] [security2:error] [pid 78969:tid 79221] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ejnDvNPGtvLGb7O0PIAAA_2M"]
[Mon Jul 20 07:11:42.360870 2026] [security2:error] [pid 85094:tid 85308] [client 14.225.17.146:59497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4eja_nUl59BcEkkgFm7QAAAVw"], referer: http://walkingandtalking.net/2017
[Mon Jul 20 07:11:42.436794 2026] [security2:error] [pid 85094:tid 85193] [remote 124.55.178.99:59216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ejq_nUl59BcEkkgFnGAABVGE"]
[Mon Jul 20 07:11:42.504869 2026] [security2:error] [pid 78969:tid 79181] [client 104.234.53.75:54045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ejnDvNPGtvLGb7O0PKgAAANc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:42.746698 2026] [security2:error] [pid 85094:tid 85326] [client 187.16.64.216:49508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ejq_nUl59BcEkkgFnIAAAAW4"]
[Mon Jul 20 07:11:42.746826 2026] [security2:error] [pid 85094:tid 85326] [client 187.16.64.216:49508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ejq_nUl59BcEkkgFnIAAAAW4"]
[Mon Jul 20 07:11:42.747388 2026] [security2:error] [pid 78969:tid 79202] [client 194.61.41.79:55945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/upgrade/bypass.php"] [unique_id "al4ejnDvNPGtvLGb7O0PPAAAAOw"]
[Mon Jul 20 07:11:42.756628 2026] [security2:error] [pid 78969:tid 79166] [client 14.225.17.146:52070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4ejXDvNPGtvLGb7O0PBwAAAMg"], referer: http://getgarrison.com/2017
[Mon Jul 20 07:11:42.818845 2026] [security2:error] [pid 85094:tid 85230] [client 98.84.242.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ejq_nUl59BcEkkgFnHQABD2U"]
[Mon Jul 20 07:11:42.869375 2026] [security2:error] [pid 85094:tid 85201] [remote 124.55.178.99:59216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ejq_nUl59BcEkkgFnJgABaWk"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:42.929571 2026] [security2:error] [pid 85094:tid 85347] [client 14.225.17.146:59566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4ejq_nUl59BcEkkgFnJwAAAYM"], referer: http://travelbyfire.com/2017
[Mon Jul 20 07:11:42.932082 2026] [security2:error] [pid 78969:tid 79113] [client 77.110.127.138:65068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ejnDvNPGtvLGb7O0PRAAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:42.932168 2026] [security2:error] [pid 78969:tid 79113] [client 77.110.127.138:65068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ejnDvNPGtvLGb7O0PRAAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:43.061170 2026] [security2:error] [pid 85094:tid 85229] [client 14.225.17.146:59536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ejq_nUl59BcEkkgFnIQAAAQ4"], referer: http://fkconstructionfunding.com/2017
[Mon Jul 20 07:11:43.188988 2026] [security2:error] [pid 78969:tid 79084] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ej3DvNPGtvLGb7O0PUwAA_nI"]
[Mon Jul 20 07:11:43.189192 2026] [security2:error] [pid 78969:tid 79220] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ej3DvNPGtvLGb7O0PUwAA_nI"]
[Mon Jul 20 07:11:43.245148 2026] [security2:error] [pid 78969:tid 79172] [client 158.173.89.95:29105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ej3DvNPGtvLGb7O0PWQAAAM4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:11:43.252389 2026] [security2:error] [pid 85094:tid 85228] [client 14.225.17.146:56246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4ej6_nUl59BcEkkgFnMAAAAQ0"], referer: https://walkingandtalking.net/2017
[Mon Jul 20 07:11:43.308455 2026] [security2:error] [pid 85094:tid 85251] [client 14.225.17.146:56199] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ej6_nUl59BcEkkgFnKgAAASQ"], referer: http://sesamegreenbeans.com/2017
[Mon Jul 20 07:11:43.431213 2026] [security2:error] [pid 78969:tid 79177] [client 14.225.17.146:56240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4ej3DvNPGtvLGb7O0PVAAAANM"], referer: http://itdynamix.com/2017
[Mon Jul 20 07:11:43.527780 2026] [security2:error] [pid 85094:tid 85302] [client 194.61.41.96:54761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/rk2.php"] [unique_id "al4ej6_nUl59BcEkkgFnPgAAAVY"]
[Mon Jul 20 07:11:43.575106 2026] [security2:error] [pid 85094:tid 85257] [client 103.144.65.217:52001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ej6_nUl59BcEkkgFnQQAAASo"]
[Mon Jul 20 07:11:43.575217 2026] [security2:error] [pid 85094:tid 85257] [client 103.144.65.217:52001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ej6_nUl59BcEkkgFnQQAAASo"]
[Mon Jul 20 07:11:43.682255 2026] [security2:error] [pid 85094:tid 85262] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4ej6_nUl59BcEkkgFnSgAAAS8"]
[Mon Jul 20 07:11:43.682380 2026] [security2:error] [pid 85094:tid 85262] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4ej6_nUl59BcEkkgFnSgAAAS8"]
[Mon Jul 20 07:11:43.702912 2026] [security2:error] [pid 85094:tid 85245] [client 116.62.81.204:50510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ej6_nUl59BcEkkgFnSwAAAR4"]
[Mon Jul 20 07:11:43.828589 2026] [security2:error] [pid 85094:tid 85245] [client 116.62.81.204:50510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4ej6_nUl59BcEkkgFnSwAAAR4"]
[Mon Jul 20 07:11:43.862398 2026] [security2:error] [pid 78969:tid 79131] [client 50.116.65.227:35520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dbn.vkf.mybluehost.me"] [uri "/website_91469382/wp-cron.php"] [unique_id "al4ej3DvNPGtvLGb7O0PeAAAAKU"]
[Mon Jul 20 07:11:44.005566 2026] [security2:error] [pid 85094:tid 85298] [client 88.241.67.160:57007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ekK_nUl59BcEkkgFnVQAAAVI"]
[Mon Jul 20 07:11:44.005686 2026] [security2:error] [pid 85094:tid 85298] [client 88.241.67.160:57007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ekK_nUl59BcEkkgFnVQAAAVI"]
[Mon Jul 20 07:11:44.031960 2026] [security2:error] [pid 78969:tid 78982] [remote 130.51.180.8:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ekHDvNPGtvLGb7O0PfgAAsww"]
[Mon Jul 20 07:11:44.060346 2026] [security2:error] [pid 78969:tid 79158] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4ekHDvNPGtvLGb7O0PggAAAMA"]
[Mon Jul 20 07:11:44.060496 2026] [security2:error] [pid 78969:tid 79158] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4ekHDvNPGtvLGb7O0PggAAAMA"]
[Mon Jul 20 07:11:44.181212 2026] [security2:error] [pid 78969:tid 78979] [remote 130.51.180.8:37338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ekHDvNPGtvLGb7O0PjgAAkgk"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:11:44.238422 2026] [security2:error] [pid 78969:tid 79201] [client 194.61.41.105:40039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/ocean/alam.php"] [unique_id "al4ekHDvNPGtvLGb7O0PlAAAAOs"]
[Mon Jul 20 07:11:44.355305 2026] [security2:error] [pid 78969:tid 79125] [client 14.225.17.146:61725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4ekHDvNPGtvLGb7O0PjAAAAJ8"], referer: https://sesamegreenbeans.com/2017
[Mon Jul 20 07:11:44.368449 2026] [security2:error] [pid 78969:tid 79117] [client 82.102.18.116:39244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-91469382.dbn.vkf.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4ekHDvNPGtvLGb7O0PnQAAAJc"]
[Mon Jul 20 07:11:44.416365 2026] [security2:error] [pid 78969:tid 79169] [client 104.234.53.82:37129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ekHDvNPGtvLGb7O0PngAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:44.432333 2026] [security2:error] [pid 78969:tid 79118] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/x.php"] [unique_id "al4ekHDvNPGtvLGb7O0PoQAAAJg"]
[Mon Jul 20 07:11:44.432422 2026] [security2:error] [pid 78969:tid 79118] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/x.php"] [unique_id "al4ekHDvNPGtvLGb7O0PoQAAAJg"]
[Mon Jul 20 07:11:44.457396 2026] [security2:error] [pid 85094:tid 85273] [client 14.225.17.146:61935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4ekK_nUl59BcEkkgFnWwAAATo"], referer: https://itdynamix.com/2017
[Mon Jul 20 07:11:44.687341 2026] [security2:error] [pid 78969:tid 79224] [client 82.102.18.116:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-91469382.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ekHDvNPGtvLGb7O0PrgAAAQI"]
[Mon Jul 20 07:11:44.729171 2026] [security2:error] [pid 78969:tid 79192] [client 110.249.202.44:19050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.itdynamix.com"] [uri "/robots.txt"] [unique_id "al4ekHDvNPGtvLGb7O0PsAAAAOI"]
[Mon Jul 20 07:11:44.775876 2026] [security2:error] [pid 85094:tid 85243] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ekK_nUl59BcEkkgFnbQAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:44.788041 2026] [security2:error] [pid 85094:tid 85290] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/j260624_13.php"] [unique_id "al4ekK_nUl59BcEkkgFndAAAAUo"]
[Mon Jul 20 07:11:44.788159 2026] [security2:error] [pid 85094:tid 85290] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/j260624_13.php"] [unique_id "al4ekK_nUl59BcEkkgFndAAAAUo"]
[Mon Jul 20 07:11:44.837403 2026] [proxy:error] [pid 85094:tid 85275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:11:44.837438 2026] [proxy_http:error] [pid 85094:tid 85275] [client 205.210.31.8:64138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:11:44.837957 2026] [proxy:error] [pid 85094:tid 85275] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:11:44.837991 2026] [proxy_http:error] [pid 85094:tid 85275] [client 205.210.31.8:64138] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:11:44.839242 2026] [proxy:error] [pid 85094:tid 85327] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:11:44.839344 2026] [proxy_http:error] [pid 85094:tid 85327] [client 205.210.31.8:64152] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:11:44.840433 2026] [proxy:error] [pid 85094:tid 85327] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:11:44.840465 2026] [proxy_http:error] [pid 85094:tid 85327] [client 205.210.31.8:64152] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:11:45.028183 2026] [security2:error] [pid 85094:tid 85316] [client 194.61.41.88:65421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/b.php"] [unique_id "al4eka_nUl59BcEkkgFnhAAAAWQ"]
[Mon Jul 20 07:11:45.187278 2026] [security2:error] [pid 85094:tid 85235] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/d62.php"] [unique_id "al4eka_nUl59BcEkkgFniwAAARQ"]
[Mon Jul 20 07:11:45.187418 2026] [security2:error] [pid 85094:tid 85235] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/d62.php"] [unique_id "al4eka_nUl59BcEkkgFniwAAARQ"]
[Mon Jul 20 07:11:45.287960 2026] [security2:error] [pid 85094:tid 85227] [client 14.225.17.146:59529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4eka_nUl59BcEkkgFnjgAAAQw"], referer: http://adultdaycarereno.com/2017
[Mon Jul 20 07:11:45.438134 2026] [security2:error] [pid 85094:tid 85216] [remote 91.142.222.105:46978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eka_nUl59BcEkkgFnmwABXng"]
[Mon Jul 20 07:11:45.456168 2026] [security2:error] [pid 85094:tid 85307] [client 201.27.111.74:52501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eka_nUl59BcEkkgFnnAAAAVs"]
[Mon Jul 20 07:11:45.456296 2026] [security2:error] [pid 85094:tid 85307] [client 201.27.111.74:52501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eka_nUl59BcEkkgFnnAAAAVs"]
[Mon Jul 20 07:11:45.532546 2026] [security2:error] [pid 85094:tid 85265] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ups.php"] [unique_id "al4eka_nUl59BcEkkgFnowAAATI"]
[Mon Jul 20 07:11:45.532652 2026] [security2:error] [pid 85094:tid 85265] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ups.php"] [unique_id "al4eka_nUl59BcEkkgFnowAAATI"]
[Mon Jul 20 07:11:45.570635 2026] [security2:error] [pid 85094:tid 85222] [remote 192.241.143.148:45784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4eka_nUl59BcEkkgFnpAABX34"]
[Mon Jul 20 07:11:45.702506 2026] [security2:error] [pid 85094:tid 85223] [remote 91.142.222.105:46978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eka_nUl59BcEkkgFnqAABDX8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:11:45.735676 2026] [security2:error] [pid 85094:tid 85255] [client 194.61.41.77:59457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/past.php"] [unique_id "al4eka_nUl59BcEkkgFnqQAAASg"]
[Mon Jul 20 07:11:45.752935 2026] [security2:error] [pid 85094:tid 85220] [remote 192.241.143.148:45784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4eka_nUl59BcEkkgFnqwABHHw"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 07:11:45.890844 2026] [security2:error] [pid 85094:tid 85325] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/k.php"] [unique_id "al4eka_nUl59BcEkkgFnuAAAAW0"]
[Mon Jul 20 07:11:45.890958 2026] [security2:error] [pid 85094:tid 85325] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/k.php"] [unique_id "al4eka_nUl59BcEkkgFnuAAAAW0"]
[Mon Jul 20 07:11:45.961210 2026] [security2:error] [pid 85094:tid 85287] [client 98.159.234.160:28715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4eka_nUl59BcEkkgFnugAAAUc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:11:45.971796 2026] [security2:error] [pid 78969:tid 79209] [client 77.110.127.138:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ekXDvNPGtvLGb7O0P6gAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:45.971880 2026] [security2:error] [pid 78969:tid 79209] [client 77.110.127.138:65089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ekXDvNPGtvLGb7O0P6gAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:46.089222 2026] [security2:error] [pid 85094:tid 85321] [client 14.225.17.146:56588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4ekK_nUl59BcEkkgFnZQAAAWk"], referer: http://maplerespiteservices.com/2017
[Mon Jul 20 07:11:46.239742 2026] [core:error] [pid 78969:tid 79131] [client 82.102.18.116:39268] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:11:46.239789 2026] [core:error] [pid 78969:tid 79131] [client 82.102.18.116:39268] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:11:46.241404 2026] [security2:error] [pid 85094:tid 85263] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/k2.php"] [unique_id "al4ekq_nUl59BcEkkgFnvwAAATA"]
[Mon Jul 20 07:11:46.241499 2026] [security2:error] [pid 85094:tid 85263] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/k2.php"] [unique_id "al4ekq_nUl59BcEkkgFnvwAAATA"]
[Mon Jul 20 07:11:46.420731 2026] [security2:error] [pid 85094:tid 85226] [client 14.225.17.146:65287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eduardsales.com"] [uri "/index.php"] [unique_id "al4ekK_nUl59BcEkkgFnfwAAAQs"], referer: http://eduardsales.com/2017
[Mon Jul 20 07:11:46.496743 2026] [security2:error] [pid 85094:tid 85283] [client 14.225.17.146:59487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4eka_nUl59BcEkkgFnjAAAAUM"], referer: http://whiteoutcb.com/2017
[Mon Jul 20 07:11:46.521073 2026] [security2:error] [pid 78969:tid 79147] [client 194.61.41.55:28933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/as.php"] [unique_id "al4eknDvNPGtvLGb7O0P_gAAALU"]
[Mon Jul 20 07:11:46.584862 2026] [core:error] [pid 78969:tid 79190] [client 82.102.18.116:39282] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:11:46.584884 2026] [core:error] [pid 78969:tid 79190] [client 82.102.18.116:39282] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:11:46.599897 2026] [security2:error] [pid 78969:tid 79151] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/k3.php"] [unique_id "al4eknDvNPGtvLGb7O0QAwAAALk"]
[Mon Jul 20 07:11:46.599994 2026] [security2:error] [pid 78969:tid 79151] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/k3.php"] [unique_id "al4eknDvNPGtvLGb7O0QAwAAALk"]
[Mon Jul 20 07:11:46.727973 2026] [security2:error] [pid 78969:tid 79035] [remote 100.42.189.89:49014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4eknDvNPGtvLGb7O0QCAAA5UE"]
[Mon Jul 20 07:11:46.921885 2026] [security2:error] [pid 85094:tid 85301] [client 82.102.18.116:39296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-91469382.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ekq_nUl59BcEkkgFn3AAAAVU"]
[Mon Jul 20 07:11:46.921967 2026] [security2:error] [pid 85094:tid 85301] [client 82.102.18.116:39296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-91469382.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ekq_nUl59BcEkkgFn3AAAAVU"]
[Mon Jul 20 07:11:46.969524 2026] [security2:error] [pid 78969:tid 79018] [remote 100.42.189.89:49014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4eknDvNPGtvLGb7O0QEgAA6zA"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 07:11:46.986729 2026] [security2:error] [pid 85094:tid 85262] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/k4.php"] [unique_id "al4ekq_nUl59BcEkkgFn4gAAAS8"]
[Mon Jul 20 07:11:46.986821 2026] [security2:error] [pid 85094:tid 85262] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/k4.php"] [unique_id "al4ekq_nUl59BcEkkgFn4gAAAS8"]
[Mon Jul 20 07:11:47.018559 2026] [security2:error] [pid 78969:tid 79049] [remote 89.42.136.2:41538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4ek3DvNPGtvLGb7O0QFAAA5k8"]
[Mon Jul 20 07:11:47.232175 2026] [security2:error] [pid 78969:tid 79194] [client 194.61.41.63:42283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/sst.php"] [unique_id "al4ek3DvNPGtvLGb7O0QHgAAAOQ"]
[Mon Jul 20 07:11:47.265790 2026] [security2:error] [pid 85094:tid 85261] [client 57.141.18.56:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ek6_nUl59BcEkkgFn6QAAAS4"]
[Mon Jul 20 07:11:47.333420 2026] [security2:error] [pid 78969:tid 79222] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/k5.php"] [unique_id "al4ek3DvNPGtvLGb7O0QJAAAAQA"]
[Mon Jul 20 07:11:47.333569 2026] [security2:error] [pid 78969:tid 79222] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/k5.php"] [unique_id "al4ek3DvNPGtvLGb7O0QJAAAAQA"]
[Mon Jul 20 07:11:47.347833 2026] [security2:error] [pid 78969:tid 79082] [remote 89.42.136.2:41538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.136.42.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4ek3DvNPGtvLGb7O0QJgAAi3A"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:11:47.429771 2026] [security2:error] [pid 85094:tid 85336] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4ek6_nUl59BcEkkgFn7AAAAXg"]
[Mon Jul 20 07:11:47.637668 2026] [security2:error] [pid 85094:tid 85324] [client 57.141.18.107:44974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eka_nUl59BcEkkgFnoAABbGc"]
[Mon Jul 20 07:11:47.747279 2026] [security2:error] [pid 78969:tid 79218] [client 14.225.17.146:56927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4ek3DvNPGtvLGb7O0QMAAAAPw"]
[Mon Jul 20 07:11:47.899122 2026] [security2:error] [pid 85094:tid 85347] [client 14.225.17.146:56873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4ek6_nUl59BcEkkgFn-AAAAYM"], referer: http://nomorewetsheets.net/2017
[Mon Jul 20 07:11:47.916766 2026] [security2:error] [pid 78969:tid 79224] [client 14.225.17.146:63816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4eknDvNPGtvLGb7O0P-gAAAQI"], referer: http://guidehunting.com/2017
[Mon Jul 20 07:11:47.963062 2026] [security2:error] [pid 78969:tid 79213] [client 194.61.41.83:21551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/edit-tags.php"] [unique_id "al4ek3DvNPGtvLGb7O0QSwAAAPc"]
[Mon Jul 20 07:11:47.966335 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/w.php"] [unique_id "al4ek3DvNPGtvLGb7O0QTAAAAJM"]
[Mon Jul 20 07:11:47.966451 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/w.php"] [unique_id "al4ek3DvNPGtvLGb7O0QTAAAAJM"]
[Mon Jul 20 07:11:48.081613 2026] [security2:error] [pid 85094:tid 85313] [client 157.245.179.103:56356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.terrapro.marketing"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4elK_nUl59BcEkkgFn_AAAAWE"]
[Mon Jul 20 07:11:48.131886 2026] [security2:error] [pid 85094:tid 85104] [remote 103.28.36.200:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4elK_nUl59BcEkkgFn_wABUQg"]
[Mon Jul 20 07:11:48.345240 2026] [security2:error] [pid 85094:tid 85285] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/fpwch.php"] [unique_id "al4elK_nUl59BcEkkgFoAQAAAUU"]
[Mon Jul 20 07:11:48.345344 2026] [security2:error] [pid 85094:tid 85285] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/fpwch.php"] [unique_id "al4elK_nUl59BcEkkgFoAQAAAUU"]
[Mon Jul 20 07:11:48.388981 2026] [security2:error] [pid 85094:tid 85342] [client 46.110.96.34:32855] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4elK_nUl59BcEkkgFoBAAAAX4"]
[Mon Jul 20 07:11:48.525312 2026] [security2:error] [pid 78969:tid 79177] [client 117.211.236.168:57300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4elHDvNPGtvLGb7O0QcQAAANM"]
[Mon Jul 20 07:11:48.525449 2026] [security2:error] [pid 78969:tid 79177] [client 117.211.236.168:57300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4elHDvNPGtvLGb7O0QcQAAANM"]
[Mon Jul 20 07:11:48.698625 2026] [security2:error] [pid 78969:tid 79162] [client 14.225.17.146:56842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4ek3DvNPGtvLGb7O0QIAAAAMQ"], referer: http://bbwipartnerconference.com/2017
[Mon Jul 20 07:11:48.729387 2026] [security2:error] [pid 78969:tid 79142] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/w2025.php"] [unique_id "al4elHDvNPGtvLGb7O0QewAAALA"]
[Mon Jul 20 07:11:48.729486 2026] [security2:error] [pid 78969:tid 79142] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/w2025.php"] [unique_id "al4elHDvNPGtvLGb7O0QewAAALA"]
[Mon Jul 20 07:11:48.741171 2026] [security2:error] [pid 78969:tid 79183] [client 194.61.41.60:27861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wsax.php"] [unique_id "al4elHDvNPGtvLGb7O0QfQAAANk"]
[Mon Jul 20 07:11:48.799743 2026] [security2:error] [pid 85094:tid 85350] [client 104.234.53.66:49735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4elK_nUl59BcEkkgFoGQAAAYY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:49.041245 2026] [security2:error] [pid 85094:tid 85270] [client 14.225.17.146:57122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4elK_nUl59BcEkkgFoFgAAATc"], referer: https://guidehunting.com/2017
[Mon Jul 20 07:11:49.119441 2026] [security2:error] [pid 85094:tid 85116] [remote 103.28.36.200:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4ela_nUl59BcEkkgFoKgABbBQ"], referer: https://dnsplumbing.com/wp-login.php
[Mon Jul 20 07:11:49.197055 2026] [security2:error] [pid 85094:tid 85279] [client 14.225.17.146:63904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4ela_nUl59BcEkkgFoKAAAAUA"], referer: http://carolinapressurewashers.com/2017
[Mon Jul 20 07:11:49.219513 2026] [security2:error] [pid 78969:tid 79148] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/scxy.php"] [unique_id "al4elXDvNPGtvLGb7O0QlwAAALY"]
[Mon Jul 20 07:11:49.219621 2026] [security2:error] [pid 78969:tid 79148] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/scxy.php"] [unique_id "al4elXDvNPGtvLGb7O0QlwAAALY"]
[Mon Jul 20 07:11:49.366359 2026] [security2:error] [pid 78969:tid 79156] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4elXDvNPGtvLGb7O0QlQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:49.373633 2026] [security2:error] [pid 78969:tid 79226] [client 14.225.17.146:56917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4ek3DvNPGtvLGb7O0QQwAAAQQ"], referer: http://tntcatholic.com/2017
[Mon Jul 20 07:11:49.501544 2026] [security2:error] [pid 85094:tid 85335] [client 14.225.17.146:57178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4ela_nUl59BcEkkgFoLgAAAXc"], referer: http://margaretspeckogawa.com/2017
[Mon Jul 20 07:11:49.522201 2026] [security2:error] [pid 85094:tid 85286] [client 194.61.41.105:36955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/bless.php%20"] [unique_id "al4ela_nUl59BcEkkgFoMwAAAUY"]
[Mon Jul 20 07:11:49.568907 2026] [security2:error] [pid 85094:tid 85305] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/FWAZ.php"] [unique_id "al4ela_nUl59BcEkkgFoNwAAAVk"]
[Mon Jul 20 07:11:49.569007 2026] [security2:error] [pid 85094:tid 85305] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/FWAZ.php"] [unique_id "al4ela_nUl59BcEkkgFoNwAAAVk"]
[Mon Jul 20 07:11:49.627469 2026] [security2:error] [pid 85094:tid 85114] [remote 217.61.143.92:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ela_nUl59BcEkkgFoOwABXxI"]
[Mon Jul 20 07:11:49.627660 2026] [security2:error] [pid 85094:tid 85311] [client 217.61.143.92:53906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ela_nUl59BcEkkgFoOwABXxI"]
[Mon Jul 20 07:11:49.806759 2026] [security2:error] [pid 78969:tid 79147] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4elXDvNPGtvLGb7O0QrgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:49.938587 2026] [security2:error] [pid 78969:tid 79172] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/qterm.php"] [unique_id "al4elXDvNPGtvLGb7O0QtgAAAM4"]
[Mon Jul 20 07:11:49.938720 2026] [security2:error] [pid 78969:tid 79172] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/qterm.php"] [unique_id "al4elXDvNPGtvLGb7O0QtgAAAM4"]
[Mon Jul 20 07:11:49.993013 2026] [security2:error] [pid 85094:tid 85255] [client 114.119.146.195:39273] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4ela_nUl59BcEkkgFoQQAAASg"], referer: https://www.nandansons.com/ola20142017/
[Mon Jul 20 07:11:50.027523 2026] [security2:error] [pid 78969:tid 79207] [client 104.234.53.57:24937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4elnDvNPGtvLGb7O0QvwAAAPE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:50.242785 2026] [security2:error] [pid 85094:tid 85227] [client 194.61.41.73:45021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/system_cache.php"] [unique_id "al4elq_nUl59BcEkkgFoVgAAAQw"]
[Mon Jul 20 07:11:50.282399 2026] [security2:error] [pid 78969:tid 79196] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4elnDvNPGtvLGb7O0QwAAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:50.437808 2026] [security2:error] [pid 85094:tid 85283] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/blurbs.php"] [unique_id "al4elq_nUl59BcEkkgFoXAAAAUM"]
[Mon Jul 20 07:11:50.437899 2026] [security2:error] [pid 85094:tid 85283] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/blurbs.php"] [unique_id "al4elq_nUl59BcEkkgFoXAAAAUM"]
[Mon Jul 20 07:11:50.518262 2026] [security2:error] [pid 85094:tid 85278] [client 77.110.127.138:65117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4elq_nUl59BcEkkgFoYwAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:50.518357 2026] [security2:error] [pid 85094:tid 85278] [client 77.110.127.138:65117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4elq_nUl59BcEkkgFoYwAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:50.817021 2026] [security2:error] [pid 85094:tid 85333] [client 14.224.227.113:58636] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4elq_nUl59BcEkkgFobgAAAXU"]
[Mon Jul 20 07:11:50.821128 2026] [security2:error] [pid 85094:tid 85255] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/v543.php"] [unique_id "al4elq_nUl59BcEkkgFobwAAASg"]
[Mon Jul 20 07:11:50.821219 2026] [security2:error] [pid 85094:tid 85255] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/v543.php"] [unique_id "al4elq_nUl59BcEkkgFobwAAASg"]
[Mon Jul 20 07:11:51.016512 2026] [security2:error] [pid 85094:tid 85275] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4elq_nUl59BcEkkgFobQAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:51.038786 2026] [security2:error] [pid 78969:tid 79103] [client 194.61.41.250:30865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/files.php"] [unique_id "al4el3DvNPGtvLGb7O0Q4wAAAIk"]
[Mon Jul 20 07:11:51.167018 2026] [security2:error] [pid 78969:tid 79129] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/w3lls.php"] [unique_id "al4el3DvNPGtvLGb7O0Q7gAAAKM"]
[Mon Jul 20 07:11:51.167125 2026] [security2:error] [pid 78969:tid 79129] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/w3lls.php"] [unique_id "al4el3DvNPGtvLGb7O0Q7gAAAKM"]
[Mon Jul 20 07:11:51.182564 2026] [security2:error] [pid 78969:tid 78990] [remote 57.141.18.113:65340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5083626"] [unique_id "al4el3DvNPGtvLGb7O0Q7wAAtBQ"]
[Mon Jul 20 07:11:51.247591 2026] [security2:error] [pid 85094:tid 85349] [client 57.141.18.16:58402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4elK_nUl59BcEkkgFoHQABhQY"]
[Mon Jul 20 07:11:51.528635 2026] [security2:error] [pid 78969:tid 79178] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4el3DvNPGtvLGb7O0Q9gAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:51.571806 2026] [security2:error] [pid 78969:tid 79168] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-ws68.php"] [unique_id "al4el3DvNPGtvLGb7O0RAQAAAMo"]
[Mon Jul 20 07:11:51.571889 2026] [security2:error] [pid 78969:tid 79168] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-ws68.php"] [unique_id "al4el3DvNPGtvLGb7O0RAQAAAMo"]
[Mon Jul 20 07:11:51.601210 2026] [security2:error] [pid 78969:tid 79044] [remote 72.167.132.114:34036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4el3DvNPGtvLGb7O0RAgAAnEo"]
[Mon Jul 20 07:11:51.807459 2026] [security2:error] [pid 85094:tid 85272] [client 50.116.65.227:43994] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4el6_nUl59BcEkkgFolAAAATk"]
[Mon Jul 20 07:11:51.816250 2026] [security2:error] [pid 78969:tid 79029] [remote 72.167.132.114:34036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4el3DvNPGtvLGb7O0RDAAA_Ts"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:11:51.817668 2026] [security2:error] [pid 78969:tid 79184] [client 50.116.65.227:44002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4el3DvNPGtvLGb7O0RDQAAANo"]
[Mon Jul 20 07:11:51.832798 2026] [security2:error] [pid 85094:tid 85278] [client 194.61.41.107:45179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/tflow/admin-footer.php"] [unique_id "al4el6_nUl59BcEkkgFolQAAAT8"]
[Mon Jul 20 07:11:51.844791 2026] [security2:error] [pid 85094:tid 85348] [client 66.132.195.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cathybuffini.com"] [uri "/index.php"] [unique_id "al4el6_nUl59BcEkkgFokgAAAYQ"]
[Mon Jul 20 07:11:51.943456 2026] [security2:error] [pid 85094:tid 85303] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xyn.php"] [unique_id "al4el6_nUl59BcEkkgFolwAAAVc"]
[Mon Jul 20 07:11:51.943594 2026] [security2:error] [pid 85094:tid 85303] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/xyn.php"] [unique_id "al4el6_nUl59BcEkkgFolwAAAVc"]
[Mon Jul 20 07:11:52.089359 2026] [security2:error] [pid 85094:tid 85263] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4el6_nUl59BcEkkgFokQAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:52.292878 2026] [security2:error] [pid 78969:tid 79102] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/green3.php"] [unique_id "al4emHDvNPGtvLGb7O0RIAAAAIg"]
[Mon Jul 20 07:11:52.292969 2026] [security2:error] [pid 78969:tid 79102] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/green3.php"] [unique_id "al4emHDvNPGtvLGb7O0RIAAAAIg"]
[Mon Jul 20 07:11:52.632362 2026] [security2:error] [pid 85094:tid 85270] [client 44.210.225.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4emK_nUl59BcEkkgFouwABNyo"]
[Mon Jul 20 07:11:52.635494 2026] [security2:error] [pid 78969:tid 79101] [client 194.61.41.82:58759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/footer-default.php"] [unique_id "al4emHDvNPGtvLGb7O0RLgAAAIc"]
[Mon Jul 20 07:11:52.666542 2026] [security2:error] [pid 85094:tid 85234] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ccs.php"] [unique_id "al4emK_nUl59BcEkkgFoxQAAARM"]
[Mon Jul 20 07:11:52.666632 2026] [security2:error] [pid 85094:tid 85234] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ccs.php"] [unique_id "al4emK_nUl59BcEkkgFoxQAAARM"]
[Mon Jul 20 07:11:52.813337 2026] [security2:error] [pid 85094:tid 85307] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4emK_nUl59BcEkkgFowgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:52.970173 2026] [security2:error] [pid 85094:tid 85311] [client 34.199.2.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4emK_nUl59BcEkkgFozgABXy0"]
[Mon Jul 20 07:11:53.000557 2026] [security2:error] [pid 85094:tid 85142] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ema_nUl59BcEkkgFo2AABdC4"]
[Mon Jul 20 07:11:53.000677 2026] [security2:error] [pid 85094:tid 85332] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ema_nUl59BcEkkgFo2AABdC4"]
[Mon Jul 20 07:11:53.017078 2026] [security2:error] [pid 78969:tid 79185] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ccc.php"] [unique_id "al4emXDvNPGtvLGb7O0RPgAAANs"]
[Mon Jul 20 07:11:53.017159 2026] [security2:error] [pid 78969:tid 79185] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ccc.php"] [unique_id "al4emXDvNPGtvLGb7O0RPgAAANs"]
[Mon Jul 20 07:11:53.074164 2026] [security2:error] [pid 85094:tid 85235] [client 104.234.53.75:53871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ema_nUl59BcEkkgFo3wAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:53.081207 2026] [security2:error] [pid 85094:tid 85146] [remote 160.187.68.132:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ema_nUl59BcEkkgFo4QABOTI"]
[Mon Jul 20 07:11:53.390915 2026] [security2:error] [pid 78969:tid 79156] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4emXDvNPGtvLGb7O0RRQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:53.416735 2026] [security2:error] [pid 78969:tid 79148] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/get.php"] [unique_id "al4emXDvNPGtvLGb7O0RUQAAALY"]
[Mon Jul 20 07:11:53.416833 2026] [security2:error] [pid 78969:tid 79148] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/get.php"] [unique_id "al4emXDvNPGtvLGb7O0RUQAAALY"]
[Mon Jul 20 07:11:53.435954 2026] [security2:error] [pid 78969:tid 79179] [client 187.16.64.216:50097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4emXDvNPGtvLGb7O0RUwAAANU"]
[Mon Jul 20 07:11:53.436066 2026] [security2:error] [pid 78969:tid 79179] [client 187.16.64.216:50097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4emXDvNPGtvLGb7O0RUwAAANU"]
[Mon Jul 20 07:11:53.444893 2026] [security2:error] [pid 85094:tid 85274] [client 194.61.41.72:24689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/about.php"] [unique_id "al4ema_nUl59BcEkkgFo8AAAATs"]
[Mon Jul 20 07:11:53.585783 2026] [security2:error] [pid 85094:tid 85147] [remote 160.187.68.132:48854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ema_nUl59BcEkkgFo9AABVjM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:11:53.610968 2026] [security2:error] [pid 85094:tid 85242] [client 14.225.17.146:63580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4ema_nUl59BcEkkgFo8QAAARs"], referer: http://chestermonty.com/2017
[Mon Jul 20 07:11:53.774287 2026] [security2:error] [pid 78969:tid 79123] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/images.php"] [unique_id "al4emXDvNPGtvLGb7O0RYAAAAJ0"]
[Mon Jul 20 07:11:53.774385 2026] [security2:error] [pid 78969:tid 79123] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/images.php"] [unique_id "al4emXDvNPGtvLGb7O0RYAAAAJ0"]
[Mon Jul 20 07:11:53.783138 2026] [security2:error] [pid 85094:tid 85144] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ema_nUl59BcEkkgFpAwABIzA"]
[Mon Jul 20 07:11:53.783353 2026] [security2:error] [pid 85094:tid 85250] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ema_nUl59BcEkkgFpAwABIzA"]
[Mon Jul 20 07:11:53.784937 2026] [security2:error] [pid 85094:tid 85255] [client 14.225.17.146:63823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4ema_nUl59BcEkkgFo-wAAASg"], referer: http://christiancountytrumpet.com/2017
[Mon Jul 20 07:11:53.853026 2026] [security2:error] [pid 85094:tid 85310] [client 14.225.17.146:63417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4ema_nUl59BcEkkgFo7gAAAV4"], referer: http://partnerselectricalllc.com/2017
[Mon Jul 20 07:11:54.090815 2026] [security2:error] [pid 78969:tid 79216] [client 116.62.81.204:52866] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4emnDvNPGtvLGb7O0RbwAAAPo"]
[Mon Jul 20 07:11:54.101221 2026] [security2:error] [pid 78969:tid 79220] [client 103.144.65.217:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4emnDvNPGtvLGb7O0RcAAAAP4"]
[Mon Jul 20 07:11:54.101354 2026] [security2:error] [pid 78969:tid 79220] [client 103.144.65.217:52454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4emnDvNPGtvLGb7O0RcAAAAP4"]
[Mon Jul 20 07:11:54.106162 2026] [security2:error] [pid 85094:tid 85337] [client 57.141.18.4:44562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4el6_nUl59BcEkkgFogwABeRg"]
[Mon Jul 20 07:11:54.152746 2026] [security2:error] [pid 85094:tid 85332] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/alls.php"] [unique_id "al4emq_nUl59BcEkkgFpEAAAAXQ"]
[Mon Jul 20 07:11:54.152879 2026] [security2:error] [pid 85094:tid 85332] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/alls.php"] [unique_id "al4emq_nUl59BcEkkgFpEAAAAXQ"]
[Mon Jul 20 07:11:54.239865 2026] [security2:error] [pid 78969:tid 79215] [client 194.61.41.253:20969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-wp-widget-meta-request.php"] [unique_id "al4emnDvNPGtvLGb7O0RfAAAAPk"]
[Mon Jul 20 07:11:54.257723 2026] [security2:error] [pid 78969:tid 79216] [client 116.62.81.204:52866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "rentorangegrove.com"] [uri "/wp-comments-post.php"] [unique_id "al4emnDvNPGtvLGb7O0RbwAAAPo"]
[Mon Jul 20 07:11:54.271400 2026] [security2:error] [pid 78969:tid 79087] [remote 91.142.222.105:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4emnDvNPGtvLGb7O0RfQAA13U"]
[Mon Jul 20 07:11:54.359150 2026] [security2:error] [pid 85094:tid 85318] [client 14.225.17.146:54318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4emq_nUl59BcEkkgFpEQAAAWY"], referer: http://xp-design.co/2017
[Mon Jul 20 07:11:54.407293 2026] [security2:error] [pid 78969:tid 79085] [remote 45.90.123.233:43566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4emnDvNPGtvLGb7O0RhAAA8HM"]
[Mon Jul 20 07:11:54.503784 2026] [security2:error] [pid 85094:tid 85321] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/yyu.php"] [unique_id "al4emq_nUl59BcEkkgFpIAAAAWk"]
[Mon Jul 20 07:11:54.503883 2026] [security2:error] [pid 85094:tid 85321] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/yyu.php"] [unique_id "al4emq_nUl59BcEkkgFpIAAAAWk"]
[Mon Jul 20 07:11:54.532733 2026] [security2:error] [pid 78969:tid 79075] [remote 91.142.222.105:59550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4emnDvNPGtvLGb7O0RhgAAjmk"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 07:11:54.539778 2026] [security2:error] [pid 85094:tid 85236] [client 14.225.17.146:64089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4emq_nUl59BcEkkgFpHwAAARU"], referer: https://chestermonty.com/2017
[Mon Jul 20 07:11:54.580067 2026] [security2:error] [pid 85094:tid 85154] [remote 68.178.160.25:51364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4emq_nUl59BcEkkgFpJAABOTo"]
[Mon Jul 20 07:11:54.594974 2026] [security2:error] [pid 78969:tid 79020] [remote 45.90.123.233:43566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4emnDvNPGtvLGb7O0RiQAAqjI"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 07:11:54.638695 2026] [security2:error] [pid 78969:tid 79115] [client 88.241.67.160:56511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4emnDvNPGtvLGb7O0RiwAAAJU"]
[Mon Jul 20 07:11:54.638977 2026] [security2:error] [pid 78969:tid 79115] [client 88.241.67.160:56511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4emnDvNPGtvLGb7O0RiwAAAJU"]
[Mon Jul 20 07:11:54.752122 2026] [security2:error] [pid 78969:tid 79168] [client 14.225.17.146:63403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4emXDvNPGtvLGb7O0RTgAAAMo"], referer: http://expertcultures.com/2017
[Mon Jul 20 07:11:54.809975 2026] [security2:error] [pid 85094:tid 85252] [client 77.110.127.138:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4emq_nUl59BcEkkgFpMwAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:54.810103 2026] [security2:error] [pid 85094:tid 85252] [client 77.110.127.138:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4emq_nUl59BcEkkgFpMwAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:54.849284 2026] [security2:error] [pid 85094:tid 85280] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/by.php"] [unique_id "al4emq_nUl59BcEkkgFpNQAAAUE"]
[Mon Jul 20 07:11:54.849396 2026] [security2:error] [pid 85094:tid 85280] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/by.php"] [unique_id "al4emq_nUl59BcEkkgFpNQAAAUE"]
[Mon Jul 20 07:11:54.984314 2026] [security2:error] [pid 85094:tid 85158] [remote 68.178.160.25:51364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4emq_nUl59BcEkkgFpOAABWT4"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 07:11:55.046270 2026] [security2:error] [pid 85094:tid 85307] [client 194.61.41.55:37035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/cloud.php"] [unique_id "al4em6_nUl59BcEkkgFpPAAAAVs"]
[Mon Jul 20 07:11:55.217519 2026] [security2:error] [pid 85094:tid 85352] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/FAQ.php"] [unique_id "al4em6_nUl59BcEkkgFpSQAAAYg"]
[Mon Jul 20 07:11:55.217609 2026] [security2:error] [pid 85094:tid 85352] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/FAQ.php"] [unique_id "al4em6_nUl59BcEkkgFpSQAAAYg"]
[Mon Jul 20 07:11:55.448119 2026] [security2:error] [pid 78969:tid 79105] [client 14.225.17.146:63825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4emXDvNPGtvLGb7O0RWgAAAIs"], referer: http://ccsdifference.com/2017
[Mon Jul 20 07:11:55.600108 2026] [security2:error] [pid 85094:tid 85276] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/coffexium.php"] [unique_id "al4em6_nUl59BcEkkgFpWQAAAT0"]
[Mon Jul 20 07:11:55.600216 2026] [security2:error] [pid 85094:tid 85276] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/coffexium.php"] [unique_id "al4em6_nUl59BcEkkgFpWQAAAT0"]
[Mon Jul 20 07:11:55.956193 2026] [security2:error] [pid 85094:tid 85305] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/red.php"] [unique_id "al4em6_nUl59BcEkkgFpZwAAAVk"]
[Mon Jul 20 07:11:55.956271 2026] [security2:error] [pid 85094:tid 85305] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/red.php"] [unique_id "al4em6_nUl59BcEkkgFpZwAAAVk"]
[Mon Jul 20 07:11:56.016096 2026] [security2:error] [pid 85094:tid 85240] [client 201.27.111.74:53005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4enK_nUl59BcEkkgFpagAAARk"]
[Mon Jul 20 07:11:56.016215 2026] [security2:error] [pid 85094:tid 85240] [client 201.27.111.74:53005] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4enK_nUl59BcEkkgFpagAAARk"]
[Mon Jul 20 07:11:56.019488 2026] [security2:error] [pid 85094:tid 85288] [client 194.61.41.246:30999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/edit-widgets/bypass.php"] [unique_id "al4enK_nUl59BcEkkgFpawAAAUg"]
[Mon Jul 20 07:11:56.201537 2026] [core:error] [pid 85094:tid 85259] [client 14.225.17.146:64890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:11:56.201560 2026] [core:error] [pid 85094:tid 85259] [client 14.225.17.146:64890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:11:56.311675 2026] [security2:error] [pid 85094:tid 85287] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4enK_nUl59BcEkkgFpdwAAAUc"]
[Mon Jul 20 07:11:56.456341 2026] [security2:error] [pid 78969:tid 79210] [client 14.225.17.146:64155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4enHDvNPGtvLGb7O0RyQAAAPQ"], referer: https://ccsdifference.com/2017
[Mon Jul 20 07:11:56.502183 2026] [security2:error] [pid 85094:tid 85321] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4enK_nUl59BcEkkgFpgQAAAWk"]
[Mon Jul 20 07:11:56.679906 2026] [security2:error] [pid 85094:tid 85276] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4enK_nUl59BcEkkgFpiQAAAT0"]
[Mon Jul 20 07:11:56.679987 2026] [security2:error] [pid 85094:tid 85276] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4enK_nUl59BcEkkgFpiQAAAT0"]
[Mon Jul 20 07:11:56.738586 2026] [security2:error] [pid 85094:tid 85228] [client 194.61.41.92:51107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/ubh/adminfus.php"] [unique_id "al4enK_nUl59BcEkkgFpiwAAAQ0"]
[Mon Jul 20 07:11:56.976870 2026] [security2:error] [pid 78969:tid 79017] [remote 45.119.213.111:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.213.119.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4enHDvNPGtvLGb7O0R3wAA6y8"]
[Mon Jul 20 07:11:57.079463 2026] [security2:error] [pid 85094:tid 85350] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4ena_nUl59BcEkkgFpmwAAAYY"]
[Mon Jul 20 07:11:57.280576 2026] [security2:error] [pid 85094:tid 85273] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ena_nUl59BcEkkgFppAAAATo"]
[Mon Jul 20 07:11:57.290876 2026] [security2:error] [pid 78969:tid 79197] [client 14.225.17.146:64640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4enXDvNPGtvLGb7O0R4gAAAOc"], referer: http://709fx.com/2017
[Mon Jul 20 07:11:57.339092 2026] [security2:error] [pid 85094:tid 85183] [remote 192.241.143.148:40146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fiq.jjc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ena_nUl59BcEkkgFpqQABUFc"]
[Mon Jul 20 07:11:57.339225 2026] [security2:error] [pid 85094:tid 85296] [client 192.241.143.148:40146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fiq.jjc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ena_nUl59BcEkkgFpqQABUFc"]
[Mon Jul 20 07:11:57.411200 2026] [security2:error] [pid 85094:tid 85291] [client 77.110.127.138:65176] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/if(now()=sysdate(),sleep(15),0)/3/"] [unique_id "al4ena_nUl59BcEkkgFpqgAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:57.411435 2026] [security2:error] [pid 78969:tid 78970] [remote 45.119.213.111:51730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.213.119.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4enXDvNPGtvLGb7O0R6wAAwAA"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 07:11:57.477453 2026] [security2:error] [pid 85094:tid 85278] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/footer.php"] [unique_id "al4ena_nUl59BcEkkgFprQAAAT8"]
[Mon Jul 20 07:11:57.477535 2026] [security2:error] [pid 85094:tid 85278] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/footer.php"] [unique_id "al4ena_nUl59BcEkkgFprQAAAT8"]
[Mon Jul 20 07:11:57.510092 2026] [security2:error] [pid 85094:tid 85181] [remote 5.252.52.249:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ena_nUl59BcEkkgFpsAABQFU"]
[Mon Jul 20 07:11:57.545963 2026] [security2:error] [pid 85094:tid 85264] [client 194.61.41.63:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/pki-validation/webdb.php"] [unique_id "al4ena_nUl59BcEkkgFpsgAAATE"]
[Mon Jul 20 07:11:57.627080 2026] [security2:error] [pid 85094:tid 85239] [client 104.234.53.75:24555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ena_nUl59BcEkkgFptAAAARg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:57.751222 2026] [security2:error] [pid 85094:tid 85184] [remote 5.252.52.249:59150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ena_nUl59BcEkkgFpuAABIlg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:11:57.866854 2026] [security2:error] [pid 78969:tid 79172] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4enXDvNPGtvLGb7O0R9QAAAM4"]
[Mon Jul 20 07:11:58.066702 2026] [security2:error] [pid 78969:tid 79118] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ennDvNPGtvLGb7O0R_QAAAJg"]
[Mon Jul 20 07:11:58.263356 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/index.php"] [unique_id "al4ennDvNPGtvLGb7O0SAAAAAJM"]
[Mon Jul 20 07:11:58.263447 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/index.php"] [unique_id "al4ennDvNPGtvLGb7O0SAAAAAJM"]
[Mon Jul 20 07:11:58.329457 2026] [security2:error] [pid 85094:tid 85342] [client 104.234.53.83:27183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4enq_nUl59BcEkkgFp3gAAAX4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:58.357520 2026] [security2:error] [pid 85094:tid 85300] [client 194.61.41.60:33173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/l10n/wp-login.php"] [unique_id "al4enq_nUl59BcEkkgFp3AAAAVQ"]
[Mon Jul 20 07:11:58.620430 2026] [security2:error] [pid 85094:tid 85341] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/zoro.php"] [unique_id "al4enq_nUl59BcEkkgFp7AAAAX0"]
[Mon Jul 20 07:11:58.620530 2026] [security2:error] [pid 85094:tid 85341] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/zoro.php"] [unique_id "al4enq_nUl59BcEkkgFp7AAAAX0"]
[Mon Jul 20 07:11:58.738678 2026] [security2:error] [pid 85094:tid 85238] [client 117.211.236.168:57825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4enq_nUl59BcEkkgFp9AAAARc"]
[Mon Jul 20 07:11:58.738796 2026] [security2:error] [pid 85094:tid 85238] [client 117.211.236.168:57825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4enq_nUl59BcEkkgFp9AAAARc"]
[Mon Jul 20 07:11:58.808655 2026] [security2:error] [pid 85094:tid 85301] [client 14.225.17.146:64899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4enq_nUl59BcEkkgFp6wAAAVU"], referer: http://mezzacraft.com/2017
[Mon Jul 20 07:11:58.972711 2026] [security2:error] [pid 78969:tid 79182] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/admin.php"] [unique_id "al4ennDvNPGtvLGb7O0SGgAAANg"]
[Mon Jul 20 07:11:58.972861 2026] [security2:error] [pid 78969:tid 79182] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/admin.php"] [unique_id "al4ennDvNPGtvLGb7O0SGgAAANg"]
[Mon Jul 20 07:11:59.076746 2026] [security2:error] [pid 78969:tid 79066] [remote 100.42.189.89:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4en3DvNPGtvLGb7O0SJQAAvmA"]
[Mon Jul 20 07:11:59.124126 2026] [security2:error] [pid 85094:tid 85278] [client 194.61.41.58:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/admin.php"] [unique_id "al4en6_nUl59BcEkkgFqAgAAAT8"]
[Mon Jul 20 07:11:59.281691 2026] [security2:error] [pid 78969:tid 79045] [remote 100.42.189.89:51644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4en3DvNPGtvLGb7O0SLwAA50s"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:11:59.323694 2026] [security2:error] [pid 85094:tid 85331] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/greap.php"] [unique_id "al4en6_nUl59BcEkkgFqCwAAAXM"]
[Mon Jul 20 07:11:59.323784 2026] [security2:error] [pid 85094:tid 85331] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/greap.php"] [unique_id "al4en6_nUl59BcEkkgFqCwAAAXM"]
[Mon Jul 20 07:11:59.674218 2026] [security2:error] [pid 78969:tid 79135] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/177.php"] [unique_id "al4en3DvNPGtvLGb7O0SSQAAAKk"]
[Mon Jul 20 07:11:59.674340 2026] [security2:error] [pid 78969:tid 79135] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/177.php"] [unique_id "al4en3DvNPGtvLGb7O0SSQAAAKk"]
[Mon Jul 20 07:11:59.736515 2026] [security2:error] [pid 78969:tid 79219] [client 14.225.17.146:53966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4en3DvNPGtvLGb7O0SRgAAAP0"], referer: http://alaraycreative.com/2017
[Mon Jul 20 07:11:59.742738 2026] [security2:error] [pid 78969:tid 79180] [client 203.83.11.13:52650] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.acaiandcitystreets.com"] [uri "/"] [unique_id "al4en3DvNPGtvLGb7O0STQAAANY"]
[Mon Jul 20 07:11:59.843072 2026] [security2:error] [pid 85094:tid 85302] [client 194.61.41.75:40009] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/item.php"] [unique_id "al4en6_nUl59BcEkkgFqHAAAAVY"]
[Mon Jul 20 07:11:59.856564 2026] [security2:error] [pid 78969:tid 79061] [remote 173.249.4.11:2861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4en3DvNPGtvLGb7O0SUQAAl1s"]
[Mon Jul 20 07:11:59.937290 2026] [security2:error] [pid 85094:tid 85339] [client 104.234.53.69:60805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4en6_nUl59BcEkkgFqHgAAAXs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:11:59.968476 2026] [security2:error] [pid 85094:tid 85295] [client 77.110.127.138:65196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4en6_nUl59BcEkkgFqHwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:11:59.968565 2026] [security2:error] [pid 85094:tid 85295] [client 77.110.127.138:65196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4en6_nUl59BcEkkgFqHwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:00.023087 2026] [security2:error] [pid 85094:tid 85233] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/199.php"] [unique_id "al4eoK_nUl59BcEkkgFqIwAAARI"]
[Mon Jul 20 07:12:00.023210 2026] [security2:error] [pid 85094:tid 85233] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/199.php"] [unique_id "al4eoK_nUl59BcEkkgFqIwAAARI"]
[Mon Jul 20 07:12:00.040488 2026] [security2:error] [pid 78969:tid 79062] [remote 173.249.4.11:2861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4eoHDvNPGtvLGb7O0SWQAAsVw"], referer: https://according2plant.com/wp-login.php
[Mon Jul 20 07:12:00.369117 2026] [security2:error] [pid 85094:tid 85328] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file52.php"] [unique_id "al4eoK_nUl59BcEkkgFqKwAAAXA"]
[Mon Jul 20 07:12:00.369219 2026] [security2:error] [pid 85094:tid 85328] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file52.php"] [unique_id "al4eoK_nUl59BcEkkgFqKwAAAXA"]
[Mon Jul 20 07:12:00.378984 2026] [security2:error] [pid 78969:tid 79033] [remote 182.77.62.24:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eoHDvNPGtvLGb7O0SZAAA6j8"]
[Mon Jul 20 07:12:00.379148 2026] [security2:error] [pid 78969:tid 79200] [client 182.77.62.24:50980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eoHDvNPGtvLGb7O0SZAAA6j8"]
[Mon Jul 20 07:12:00.648191 2026] [security2:error] [pid 85094:tid 85265] [client 194.61.41.86:45041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/uploads/xsec.php"] [unique_id "al4eoK_nUl59BcEkkgFqNgAAATI"]
[Mon Jul 20 07:12:00.742901 2026] [autoindex:error] [pid 85094:tid 85100] [remote 104.196.128.222:53693] AH01276: Cannot serve directory /home2/tbdlhomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://tbd.lho.mybluehost.me
[Mon Jul 20 07:12:00.749929 2026] [security2:error] [pid 78969:tid 79224] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/122.php"] [unique_id "al4eoHDvNPGtvLGb7O0SewAAAQI"]
[Mon Jul 20 07:12:00.750030 2026] [security2:error] [pid 78969:tid 79224] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/122.php"] [unique_id "al4eoHDvNPGtvLGb7O0SewAAAQI"]
[Mon Jul 20 07:12:00.766906 2026] [security2:error] [pid 85094:tid 85225] [client 14.225.17.146:54081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4eoK_nUl59BcEkkgFqNQAAAQo"], referer: http://alchemygroup.ca/2017
[Mon Jul 20 07:12:00.802846 2026] [security2:error] [pid 78969:tid 79091] [remote 132.148.72.88:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eoHDvNPGtvLGb7O0SfAAArXk"]
[Mon Jul 20 07:12:00.965253 2026] [security2:error] [pid 78969:tid 79195] [client 14.225.17.146:54112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4eoHDvNPGtvLGb7O0SfQAAAOU"]
[Mon Jul 20 07:12:01.027600 2026] [security2:error] [pid 78969:tid 79065] [remote 132.148.72.88:44816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eoXDvNPGtvLGb7O0SiQAA6V8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:12:01.120453 2026] [security2:error] [pid 78969:tid 79108] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/green1.php"] [unique_id "al4eoXDvNPGtvLGb7O0SlQAAAI4"]
[Mon Jul 20 07:12:01.120553 2026] [security2:error] [pid 78969:tid 79108] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/green1.php"] [unique_id "al4eoXDvNPGtvLGb7O0SlQAAAI4"]
[Mon Jul 20 07:12:01.447330 2026] [security2:error] [pid 78969:tid 79217] [client 66.249.89.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4ennDvNPGtvLGb7O0SGwAA-yY"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91yolo-studio-escala-1-6-ayanami-rei/
[Mon Jul 20 07:12:01.450519 2026] [security2:error] [pid 78969:tid 79124] [client 194.61.41.57:50995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/Marvins.php"] [unique_id "al4eoXDvNPGtvLGb7O0SoQAAAJ4"]
[Mon Jul 20 07:12:01.533434 2026] [security2:error] [pid 85094:tid 85295] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/biufile.php"] [unique_id "al4eoa_nUl59BcEkkgFqYQAAAU8"]
[Mon Jul 20 07:12:01.533520 2026] [security2:error] [pid 85094:tid 85295] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/biufile.php"] [unique_id "al4eoa_nUl59BcEkkgFqYQAAAU8"]
[Mon Jul 20 07:12:01.560457 2026] [security2:error] [pid 85094:tid 85353] [client 57.141.18.115:56100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ena_nUl59BcEkkgFpvQABiV0"]
[Mon Jul 20 07:12:01.896517 2026] [security2:error] [pid 85094:tid 85333] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wpconf.php"] [unique_id "al4eoa_nUl59BcEkkgFqdgAAAXU"]
[Mon Jul 20 07:12:01.896630 2026] [security2:error] [pid 85094:tid 85333] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wpconf.php"] [unique_id "al4eoa_nUl59BcEkkgFqdgAAAXU"]
[Mon Jul 20 07:12:02.249837 2026] [security2:error] [pid 78969:tid 79107] [client 194.61.41.108:38049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd-1/kurd.php"] [unique_id "al4eonDvNPGtvLGb7O0SxQAAAI0"]
[Mon Jul 20 07:12:02.266564 2026] [security2:error] [pid 78969:tid 79103] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/mosty.php"] [unique_id "al4eonDvNPGtvLGb7O0SxgAAAIk"]
[Mon Jul 20 07:12:02.266719 2026] [security2:error] [pid 78969:tid 79103] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/mosty.php"] [unique_id "al4eonDvNPGtvLGb7O0SxgAAAIk"]
[Mon Jul 20 07:12:02.504800 2026] [security2:error] [pid 78969:tid 79157] [client 13.71.159.57:28352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4eonDvNPGtvLGb7O0S0AAAAL8"]
[Mon Jul 20 07:12:02.619113 2026] [security2:error] [pid 85094:tid 85268] [client 44.215.99.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eoq_nUl59BcEkkgFqiQABNSY"]
[Mon Jul 20 07:12:02.623831 2026] [security2:error] [pid 78969:tid 79213] [client 13.71.159.57:28352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4eonDvNPGtvLGb7O0S1gAAAPc"]
[Mon Jul 20 07:12:02.657905 2026] [security2:error] [pid 78969:tid 79200] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/dejavu.php"] [unique_id "al4eonDvNPGtvLGb7O0S2QAAAOo"]
[Mon Jul 20 07:12:02.658050 2026] [security2:error] [pid 78969:tid 79200] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/dejavu.php"] [unique_id "al4eonDvNPGtvLGb7O0S2QAAAOo"]
[Mon Jul 20 07:12:02.669445 2026] [security2:error] [pid 85094:tid 85306] [client 14.225.17.146:54632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4eoq_nUl59BcEkkgFqiwAAAVo"], referer: http://processorstudio.com/2017
[Mon Jul 20 07:12:02.895377 2026] [security2:error] [pid 78969:tid 79226] [client 14.225.17.146:54074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4eonDvNPGtvLGb7O0S4gAAAQQ"], referer: http://cephasnext.com/2017
[Mon Jul 20 07:12:03.006311 2026] [security2:error] [pid 78969:tid 79181] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/aaf.php"] [unique_id "al4eo3DvNPGtvLGb7O0S6AAAANc"]
[Mon Jul 20 07:12:03.006455 2026] [security2:error] [pid 78969:tid 79181] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/aaf.php"] [unique_id "al4eo3DvNPGtvLGb7O0S6AAAANc"]
[Mon Jul 20 07:12:03.028079 2026] [security2:error] [pid 85094:tid 85351] [client 194.61.41.55:34921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/tflow/install.php"] [unique_id "al4eo6_nUl59BcEkkgFqlwAAAYc"]
[Mon Jul 20 07:12:03.084109 2026] [security2:error] [pid 85094:tid 85323] [client 77.110.127.138:65216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/3/"] [unique_id "al4eo6_nUl59BcEkkgFqmwAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:03.379455 2026] [security2:error] [pid 85094:tid 85259] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/term.php"] [unique_id "al4eo6_nUl59BcEkkgFqrQAAASw"]
[Mon Jul 20 07:12:03.379597 2026] [security2:error] [pid 85094:tid 85259] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/term.php"] [unique_id "al4eo6_nUl59BcEkkgFqrQAAASw"]
[Mon Jul 20 07:12:03.487789 2026] [core:error] [pid 85094:tid 85320] [client 14.225.17.146:55287] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2017
[Mon Jul 20 07:12:03.487809 2026] [core:error] [pid 85094:tid 85320] [client 14.225.17.146:55287] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2017
[Mon Jul 20 07:12:03.559592 2026] [security2:error] [pid 78969:tid 79180] [client 14.225.17.146:64009] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4eo3DvNPGtvLGb7O0TAQAAANY"], referer: https://processorstudio.com/2017
[Mon Jul 20 07:12:03.740409 2026] [security2:error] [pid 85094:tid 85242] [client 77.110.127.138:65221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eo6_nUl59BcEkkgFqvgAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:03.740533 2026] [security2:error] [pid 85094:tid 85242] [client 77.110.127.138:65221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eo6_nUl59BcEkkgFqvgAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:03.748658 2026] [security2:error] [pid 85094:tid 85290] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ha.php"] [unique_id "al4eo6_nUl59BcEkkgFqwAAAAUo"]
[Mon Jul 20 07:12:03.748743 2026] [security2:error] [pid 85094:tid 85290] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ha.php"] [unique_id "al4eo6_nUl59BcEkkgFqwAAAAUo"]
[Mon Jul 20 07:12:03.758164 2026] [security2:error] [pid 85094:tid 85338] [client 194.61.41.83:31569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/languages/radio.php"] [unique_id "al4eo6_nUl59BcEkkgFqwwAAAXo"]
[Mon Jul 20 07:12:04.056461 2026] [security2:error] [pid 85094:tid 85323] [client 4.201.176.24:45632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4epK_nUl59BcEkkgFqzwAAAWs"]
[Mon Jul 20 07:12:04.098254 2026] [security2:error] [pid 85094:tid 85322] [client 187.16.64.216:50933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4epK_nUl59BcEkkgFq0AAAAWo"]
[Mon Jul 20 07:12:04.098347 2026] [security2:error] [pid 85094:tid 85322] [client 187.16.64.216:50933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4epK_nUl59BcEkkgFq0AAAAWo"]
[Mon Jul 20 07:12:04.122599 2026] [security2:error] [pid 85094:tid 85230] [client 13.232.231.177:22330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4epK_nUl59BcEkkgFq0QAAAQ8"]
[Mon Jul 20 07:12:04.136107 2026] [security2:error] [pid 78969:tid 79090] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4epHDvNPGtvLGb7O0TEgAA5Hg"]
[Mon Jul 20 07:12:04.136262 2026] [security2:error] [pid 78969:tid 79194] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4epHDvNPGtvLGb7O0TEgAA5Hg"]
[Mon Jul 20 07:12:04.151764 2026] [security2:error] [pid 85094:tid 85235] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/hur.php"] [unique_id "al4epK_nUl59BcEkkgFq1QAAARQ"]
[Mon Jul 20 07:12:04.151853 2026] [security2:error] [pid 85094:tid 85235] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/hur.php"] [unique_id "al4epK_nUl59BcEkkgFq1QAAARQ"]
[Mon Jul 20 07:12:04.188017 2026] [security2:error] [pid 78969:tid 79108] [client 14.225.17.146:53723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4epHDvNPGtvLGb7O0TDwAAAI4"], referer: http://colinkeyphotography.com/2017
[Mon Jul 20 07:12:04.216114 2026] [security2:error] [pid 85094:tid 85236] [client 4.201.176.24:45632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4epK_nUl59BcEkkgFq3gAAARU"]
[Mon Jul 20 07:12:04.221089 2026] [security2:error] [pid 85094:tid 85147] [remote 5.161.225.162:35210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4epK_nUl59BcEkkgFq3QABTzM"]
[Mon Jul 20 07:12:04.311769 2026] [security2:error] [pid 85094:tid 85245] [client 66.249.69.36:62104] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.luxuria-properties.net"] [uri "/robots.txt"] [unique_id "al4epK_nUl59BcEkkgFq5gAAAR4"]
[Mon Jul 20 07:12:04.401236 2026] [security2:error] [pid 85094:tid 85145] [remote 5.161.225.162:35210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4epK_nUl59BcEkkgFq6wABGzE"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 07:12:04.472668 2026] [security2:error] [pid 85094:tid 85151] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4epK_nUl59BcEkkgFq7wABSzc"]
[Mon Jul 20 07:12:04.472806 2026] [security2:error] [pid 85094:tid 85291] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4epK_nUl59BcEkkgFq7wABSzc"]
[Mon Jul 20 07:12:04.500634 2026] [security2:error] [pid 85094:tid 85265] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/h02ugyh.php"] [unique_id "al4epK_nUl59BcEkkgFq8gAAATI"]
[Mon Jul 20 07:12:04.500709 2026] [security2:error] [pid 85094:tid 85265] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/h02ugyh.php"] [unique_id "al4epK_nUl59BcEkkgFq8gAAATI"]
[Mon Jul 20 07:12:04.545625 2026] [security2:error] [pid 78969:tid 79112] [client 194.61.41.86:31015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/fileman.php"] [unique_id "al4epHDvNPGtvLGb7O0THAAAAJI"]
[Mon Jul 20 07:12:04.748516 2026] [security2:error] [pid 85094:tid 85262] [client 14.225.17.146:54068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4eoq_nUl59BcEkkgFqkQAAAS8"], referer: http://webgardensbypaula.com/2017
[Mon Jul 20 07:12:04.757818 2026] [security2:error] [pid 85094:tid 85349] [client 103.144.65.217:52914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4epK_nUl59BcEkkgFrBQAAAYU"]
[Mon Jul 20 07:12:04.757911 2026] [security2:error] [pid 85094:tid 85349] [client 103.144.65.217:52914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4epK_nUl59BcEkkgFrBQAAAYU"]
[Mon Jul 20 07:12:04.849336 2026] [security2:error] [pid 78969:tid 79222] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/seiso.php"] [unique_id "al4epHDvNPGtvLGb7O0TKAAAAQA"]
[Mon Jul 20 07:12:04.849465 2026] [security2:error] [pid 78969:tid 79222] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/seiso.php"] [unique_id "al4epHDvNPGtvLGb7O0TKAAAAQA"]
[Mon Jul 20 07:12:05.055764 2026] [security2:error] [pid 85094:tid 85275] [client 14.225.17.146:53996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4epK_nUl59BcEkkgFrCQAAATw"], referer: http://inspirespublishing.com/2017
[Mon Jul 20 07:12:05.238202 2026] [security2:error] [pid 78969:tid 79169] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/155.php"] [unique_id "al4epXDvNPGtvLGb7O0TQgAAAMs"]
[Mon Jul 20 07:12:05.238303 2026] [security2:error] [pid 78969:tid 79169] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/155.php"] [unique_id "al4epXDvNPGtvLGb7O0TQgAAAMs"]
[Mon Jul 20 07:12:05.290540 2026] [security2:error] [pid 85094:tid 85293] [client 57.141.18.112:21664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eoa_nUl59BcEkkgFqcQABTQ4"]
[Mon Jul 20 07:12:05.316019 2026] [security2:error] [pid 78969:tid 79099] [client 194.61.41.69:43377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/wp-ss.php"] [unique_id "al4epXDvNPGtvLGb7O0TSwAAAIU"]
[Mon Jul 20 07:12:05.352976 2026] [security2:error] [pid 78969:tid 79105] [client 13.233.207.33:52412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4epXDvNPGtvLGb7O0TTQAAAIs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:12:05.511810 2026] [security2:error] [pid 85094:tid 85335] [client 88.241.67.160:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4epa_nUl59BcEkkgFrHgAAAXc"]
[Mon Jul 20 07:12:05.512042 2026] [security2:error] [pid 85094:tid 85335] [client 88.241.67.160:53799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4epa_nUl59BcEkkgFrHgAAAXc"]
[Mon Jul 20 07:12:05.588213 2026] [security2:error] [pid 78969:tid 79207] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ppp.php"] [unique_id "al4epXDvNPGtvLGb7O0TWgAAAPE"]
[Mon Jul 20 07:12:05.588305 2026] [security2:error] [pid 78969:tid 79207] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ppp.php"] [unique_id "al4epXDvNPGtvLGb7O0TWgAAAPE"]
[Mon Jul 20 07:12:05.588464 2026] [security2:error] [pid 78969:tid 79112] [client 50.116.65.227:55310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4epXDvNPGtvLGb7O0TWQAAAJI"]
[Mon Jul 20 07:12:05.598819 2026] [security2:error] [pid 85094:tid 85291] [client 50.116.65.227:55314] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4epa_nUl59BcEkkgFrIwAAAUs"]
[Mon Jul 20 07:12:05.936777 2026] [security2:error] [pid 78969:tid 79167] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/201.php"] [unique_id "al4epXDvNPGtvLGb7O0TbgAAAMk"]
[Mon Jul 20 07:12:05.936910 2026] [security2:error] [pid 78969:tid 79167] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/201.php"] [unique_id "al4epXDvNPGtvLGb7O0TbgAAAMk"]
[Mon Jul 20 07:12:06.049188 2026] [security2:error] [pid 85094:tid 85352] [client 194.61.41.84:20535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/xsec1.php"] [unique_id "al4epq_nUl59BcEkkgFrMwAAAYg"]
[Mon Jul 20 07:12:06.152634 2026] [security2:error] [pid 78969:tid 79114] [client 50.116.65.227:55330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4epXDvNPGtvLGb7O0TcgAAAJQ"]
[Mon Jul 20 07:12:06.301412 2026] [security2:error] [pid 85094:tid 85246] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ops.php"] [unique_id "al4epq_nUl59BcEkkgFrOwAAAR8"]
[Mon Jul 20 07:12:06.301511 2026] [security2:error] [pid 85094:tid 85246] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ops.php"] [unique_id "al4epq_nUl59BcEkkgFrOwAAAR8"]
[Mon Jul 20 07:12:06.339978 2026] [security2:error] [pid 78969:tid 79160] [client 50.116.65.227:55346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4epnDvNPGtvLGb7O0TfAAAAMI"]
[Mon Jul 20 07:12:06.674020 2026] [security2:error] [pid 78969:tid 79225] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ingfo.php"] [unique_id "al4epnDvNPGtvLGb7O0TkAAAAQM"]
[Mon Jul 20 07:12:06.674123 2026] [security2:error] [pid 78969:tid 79225] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ingfo.php"] [unique_id "al4epnDvNPGtvLGb7O0TkAAAAQM"]
[Mon Jul 20 07:12:06.843476 2026] [security2:error] [pid 85094:tid 85325] [client 194.61.41.246:25899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin.php%20"] [unique_id "al4epq_nUl59BcEkkgFrUgAAAW0"]
[Mon Jul 20 07:12:06.870645 2026] [security2:error] [pid 78969:tid 79210] [client 14.225.17.146:53903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4epXDvNPGtvLGb7O0TbQAAAPQ"], referer: http://retzkolonglogistics.com/2017
[Mon Jul 20 07:12:06.929303 2026] [security2:error] [pid 85094:tid 85318] [client 201.27.111.74:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4epq_nUl59BcEkkgFrVwAAAWY"]
[Mon Jul 20 07:12:06.929437 2026] [security2:error] [pid 85094:tid 85318] [client 201.27.111.74:53506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4epq_nUl59BcEkkgFrVwAAAWY"]
[Mon Jul 20 07:12:07.024186 2026] [security2:error] [pid 78969:tid 79203] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/error_log.php"] [unique_id "al4ep3DvNPGtvLGb7O0TmgAAAO0"]
[Mon Jul 20 07:12:07.024323 2026] [security2:error] [pid 78969:tid 79203] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/error_log.php"] [unique_id "al4ep3DvNPGtvLGb7O0TmgAAAO0"]
[Mon Jul 20 07:12:07.238708 2026] [security2:error] [pid 85094:tid 85279] [client 77.110.127.138:65249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/3/"] [unique_id "al4ep6_nUl59BcEkkgFrZQAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:07.263423 2026] [security2:error] [pid 85094:tid 85238] [client 14.225.17.146:55830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4epa_nUl59BcEkkgFrGwAAARc"], referer: http://mollycahill.com/2017
[Mon Jul 20 07:12:07.407358 2026] [security2:error] [pid 78969:tid 79118] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4epXDvNPGtvLGb7O0TcQAAAJg"]
[Mon Jul 20 07:12:07.485904 2026] [security2:error] [pid 85094:tid 85240] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xenon1337.php"] [unique_id "al4ep6_nUl59BcEkkgFrdQAAARk"]
[Mon Jul 20 07:12:07.486018 2026] [security2:error] [pid 85094:tid 85240] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/xenon1337.php"] [unique_id "al4ep6_nUl59BcEkkgFrdQAAARk"]
[Mon Jul 20 07:12:07.610771 2026] [security2:error] [pid 85094:tid 85182] [remote 117.0.21.154:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4ep6_nUl59BcEkkgFregABRlY"]
[Mon Jul 20 07:12:07.645327 2026] [security2:error] [pid 85094:tid 85259] [client 194.61.41.56:31455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/hong1.php"] [unique_id "al4ep6_nUl59BcEkkgFrfQAAASw"]
[Mon Jul 20 07:12:07.714297 2026] [security2:error] [pid 78969:tid 79058] [remote 148.153.193.99:41514] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "omegaecho.com"] [uri "/"] [unique_id "al4ep3DvNPGtvLGb7O0TrQAAw1g"]
[Mon Jul 20 07:12:07.729818 2026] [security2:error] [pid 78969:tid 79116] [client 14.225.17.146:56070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4ep3DvNPGtvLGb7O0TqgAAAJY"], referer: http://scott-assist.com/2017
[Mon Jul 20 07:12:07.823916 2026] [security2:error] [pid 78969:tid 78997] [remote 160.187.68.132:33884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ep3DvNPGtvLGb7O0TrwAA9xs"]
[Mon Jul 20 07:12:07.877260 2026] [security2:error] [pid 78969:tid 79158] [client 77.110.127.138:65252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ep3DvNPGtvLGb7O0TsgAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:07.877374 2026] [security2:error] [pid 78969:tid 79158] [client 77.110.127.138:65252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ep3DvNPGtvLGb7O0TsgAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:07.885322 2026] [security2:error] [pid 78969:tid 79199] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/test11.php"] [unique_id "al4ep3DvNPGtvLGb7O0TtAAAAOk"]
[Mon Jul 20 07:12:07.885399 2026] [security2:error] [pid 78969:tid 79199] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/test11.php"] [unique_id "al4ep3DvNPGtvLGb7O0TtAAAAOk"]
[Mon Jul 20 07:12:07.959212 2026] [security2:error] [pid 78969:tid 79218] [client 14.225.17.146:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4epXDvNPGtvLGb7O0TbwAAAPw"], referer: http://securingmemories.com/2017
[Mon Jul 20 07:12:08.034644 2026] [security2:error] [pid 85094:tid 85233] [client 77.110.127.138:65255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqK_nUl59BcEkkgFrjwAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:08.034780 2026] [security2:error] [pid 85094:tid 85233] [client 77.110.127.138:65255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqK_nUl59BcEkkgFrjwAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:08.165256 2026] [security2:error] [pid 85094:tid 85327] [client 144.172.91.227:59196] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cathybuffini.com"] [uri "/kickstart.php"] [unique_id "al4eqK_nUl59BcEkkgFrkQAAAW8"]
[Mon Jul 20 07:12:08.264279 2026] [security2:error] [pid 85094:tid 85184] [remote 117.0.21.154:55864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4eqK_nUl59BcEkkgFrmAABW1g"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 07:12:08.269659 2026] [security2:error] [pid 85094:tid 85288] [client 77.110.127.138:65256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqK_nUl59BcEkkgFrmgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:08.269744 2026] [security2:error] [pid 85094:tid 85288] [client 77.110.127.138:65256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqK_nUl59BcEkkgFrmgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:08.276965 2026] [security2:error] [pid 78969:tid 79165] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/koala.php"] [unique_id "al4eqHDvNPGtvLGb7O0TxAAAAMc"]
[Mon Jul 20 07:12:08.277048 2026] [security2:error] [pid 78969:tid 79165] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/koala.php"] [unique_id "al4eqHDvNPGtvLGb7O0TxAAAAMc"]
[Mon Jul 20 07:12:08.337667 2026] [security2:error] [pid 78969:tid 78976] [remote 20.153.140.50:40150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eqHDvNPGtvLGb7O0TxgAA3AY"]
[Mon Jul 20 07:12:08.340593 2026] [security2:error] [pid 78969:tid 78981] [remote 160.187.68.132:33884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4eqHDvNPGtvLGb7O0TxQAA0ws"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:12:08.426585 2026] [security2:error] [pid 78969:tid 79149] [client 194.61.41.64:21879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/byps.php"] [unique_id "al4eqHDvNPGtvLGb7O0TzwAAALc"]
[Mon Jul 20 07:12:08.602551 2026] [security2:error] [pid 85094:tid 85278] [client 37.27.59.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4eqK_nUl59BcEkkgFrngAAAT8"]
[Mon Jul 20 07:12:08.672029 2026] [security2:error] [pid 78969:tid 79163] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/mac.php"] [unique_id "al4eqHDvNPGtvLGb7O0T2wAAAMU"]
[Mon Jul 20 07:12:08.672128 2026] [security2:error] [pid 78969:tid 79163] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/mac.php"] [unique_id "al4eqHDvNPGtvLGb7O0T2wAAAMU"]
[Mon Jul 20 07:12:08.721606 2026] [security2:error] [pid 78969:tid 79138] [client 77.110.127.138:65265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqHDvNPGtvLGb7O0T4AAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:08.721708 2026] [security2:error] [pid 78969:tid 79138] [client 77.110.127.138:65265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqHDvNPGtvLGb7O0T4AAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:08.740357 2026] [security2:error] [pid 78969:tid 79017] [remote 20.153.140.50:40150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eqHDvNPGtvLGb7O0T4QAAqy8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:12:08.937810 2026] [security2:error] [pid 85094:tid 85190] [remote 117.0.21.154:39128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eqK_nUl59BcEkkgFrrgABg14"]
[Mon Jul 20 07:12:08.937974 2026] [security2:error] [pid 85094:tid 85347] [client 117.0.21.154:39128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eqK_nUl59BcEkkgFrrgABg14"]
[Mon Jul 20 07:12:09.050713 2026] [security2:error] [pid 78969:tid 79169] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/25d653587fdfd1.php"] [unique_id "al4eqXDvNPGtvLGb7O0T8gAAAMs"]
[Mon Jul 20 07:12:09.050795 2026] [security2:error] [pid 78969:tid 79169] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/25d653587fdfd1.php"] [unique_id "al4eqXDvNPGtvLGb7O0T8gAAAMs"]
[Mon Jul 20 07:12:09.146325 2026] [security2:error] [pid 85094:tid 85227] [client 14.225.17.146:53387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4ep6_nUl59BcEkkgFrhgAAAQw"]
[Mon Jul 20 07:12:09.187044 2026] [security2:error] [pid 78969:tid 79105] [client 194.61.41.54:48755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/crystal/sad.php"] [unique_id "al4eqXDvNPGtvLGb7O0T-AAAAIs"]
[Mon Jul 20 07:12:09.231854 2026] [security2:error] [pid 85094:tid 85245] [client 57.141.18.12:58856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4epa_nUl59BcEkkgFrFgABHj4"]
[Mon Jul 20 07:12:09.428471 2026] [security2:error] [pid 85094:tid 85327] [client 77.110.127.138:65270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqa_nUl59BcEkkgFrwQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:09.432307 2026] [security2:error] [pid 85094:tid 85327] [client 77.110.127.138:65270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqa_nUl59BcEkkgFrwQAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:09.496824 2026] [security2:error] [pid 85094:tid 85307] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wefile.php"] [unique_id "al4eqa_nUl59BcEkkgFrxAAAAVs"]
[Mon Jul 20 07:12:09.496908 2026] [security2:error] [pid 85094:tid 85307] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wefile.php"] [unique_id "al4eqa_nUl59BcEkkgFrxAAAAVs"]
[Mon Jul 20 07:12:09.594540 2026] [security2:error] [pid 85094:tid 85263] [client 104.234.53.47:34259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4eqa_nUl59BcEkkgFrxwAAATA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:09.910149 2026] [security2:error] [pid 78969:tid 79201] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4eqXDvNPGtvLGb7O0UDgAAAOs"]
[Mon Jul 20 07:12:09.924184 2026] [security2:error] [pid 78969:tid 79226] [client 194.61.41.107:60529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/script-loader-packages.min.php"] [unique_id "al4eqXDvNPGtvLGb7O0UEAAAAQQ"]
[Mon Jul 20 07:12:09.942019 2026] [security2:error] [pid 78969:tid 79208] [client 77.110.127.138:65276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqXDvNPGtvLGb7O0UEQAAAPI"]
[Mon Jul 20 07:12:09.942102 2026] [security2:error] [pid 78969:tid 79208] [client 77.110.127.138:65276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqXDvNPGtvLGb7O0UEQAAAPI"]
[Mon Jul 20 07:12:10.093144 2026] [security2:error] [pid 78969:tid 79192] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4eqnDvNPGtvLGb7O0UGwAAAOI"]
[Mon Jul 20 07:12:10.161567 2026] [security2:error] [pid 78969:tid 79013] [remote 192.241.143.148:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eqnDvNPGtvLGb7O0UHwAAnys"]
[Mon Jul 20 07:12:10.177114 2026] [security2:error] [pid 78969:tid 79202] [client 77.110.127.138:65279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqnDvNPGtvLGb7O0UIAAAAOw"]
[Mon Jul 20 07:12:10.177230 2026] [security2:error] [pid 78969:tid 79202] [client 77.110.127.138:65279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eqnDvNPGtvLGb7O0UIAAAAOw"]
[Mon Jul 20 07:12:10.279225 2026] [security2:error] [pid 78969:tid 79213] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/js/"] [unique_id "al4eqnDvNPGtvLGb7O0UKgAAAPc"]
[Mon Jul 20 07:12:10.334428 2026] [security2:error] [pid 78969:tid 79018] [remote 192.241.143.148:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4eqnDvNPGtvLGb7O0ULAAAojA"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:12:10.663171 2026] [security2:error] [pid 78969:tid 79165] [client 194.61.41.63:45811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/patterns/content-type.php"] [unique_id "al4eqnDvNPGtvLGb7O0UPgAAAMc"]
[Mon Jul 20 07:12:10.714221 2026] [security2:error] [pid 85094:tid 85228] [client 52.109.108.111:38017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4eqq_nUl59BcEkkgFr6gAAAQ0"]
[Mon Jul 20 07:12:10.882055 2026] [security2:error] [pid 85094:tid 85341] [client 52.109.108.111:38017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4eqq_nUl59BcEkkgFr8gAAAX0"]
[Mon Jul 20 07:12:10.950424 2026] [security2:error] [pid 78969:tid 79143] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al4eqnDvNPGtvLGb7O0URwAAALE"]
[Mon Jul 20 07:12:10.950514 2026] [security2:error] [pid 78969:tid 79143] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/css/colour.php"] [unique_id "al4eqnDvNPGtvLGb7O0URwAAALE"]
[Mon Jul 20 07:12:10.999454 2026] [security2:error] [pid 78969:tid 79074] [remote 182.77.62.24:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4eqnDvNPGtvLGb7O0USAAAp2g"]
[Mon Jul 20 07:12:11.076644 2026] [security2:error] [pid 85094:tid 85264] [client 117.211.236.168:58415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eq6_nUl59BcEkkgFr-QAAATE"]
[Mon Jul 20 07:12:11.076794 2026] [security2:error] [pid 85094:tid 85264] [client 117.211.236.168:58415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4eq6_nUl59BcEkkgFr-QAAATE"]
[Mon Jul 20 07:12:11.129325 2026] [autoindex:error] [pid 78969:tid 79193] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/genesis/lib/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:12:11.306080 2026] [security2:error] [pid 85094:tid 85257] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/2P.php"] [unique_id "al4eq6_nUl59BcEkkgFsDgAAASo"]
[Mon Jul 20 07:12:11.306183 2026] [security2:error] [pid 85094:tid 85257] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/2P.php"] [unique_id "al4eq6_nUl59BcEkkgFsDgAAASo"]
[Mon Jul 20 07:12:11.376922 2026] [security2:error] [pid 85094:tid 85254] [client 32.220.229.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lovedbynee.com"] [uri "/index.php"] [unique_id "al4eqq_nUl59BcEkkgFr9gABJ3M"], referer: https://lovedbynee.com/
[Mon Jul 20 07:12:11.419728 2026] [security2:error] [pid 85094:tid 85300] [client 194.61.41.55:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/class.php"] [unique_id "al4eq6_nUl59BcEkkgFsEwAAAVQ"]
[Mon Jul 20 07:12:11.558412 2026] [security2:error] [pid 85094:tid 85222] [remote 182.77.62.24:56932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eq6_nUl59BcEkkgFsGAABEn4"]
[Mon Jul 20 07:12:11.558558 2026] [security2:error] [pid 85094:tid 85233] [client 182.77.62.24:56932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eq6_nUl59BcEkkgFsGAABEn4"]
[Mon Jul 20 07:12:11.578563 2026] [security2:error] [pid 78969:tid 79206] [client 51.143.183.75:13313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4eq3DvNPGtvLGb7O0UWQAAAPA"]
[Mon Jul 20 07:12:11.610807 2026] [security2:error] [pid 78969:tid 79101] [client 14.225.17.146:55143] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4eqnDvNPGtvLGb7O0UIQAAAIc"], referer: http://thechancersband.com/2017
[Mon Jul 20 07:12:11.654913 2026] [security2:error] [pid 78969:tid 79052] [remote 182.77.62.24:56930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4eq3DvNPGtvLGb7O0UXwAArFI"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:12:11.708180 2026] [security2:error] [pid 85094:tid 85344] [client 104.234.53.51:48541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eq6_nUl59BcEkkgFsIQAAAYA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:11.720287 2026] [security2:error] [pid 78969:tid 79172] [client 51.143.183.75:13313] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4eq3DvNPGtvLGb7O0UZgAAAM4"]
[Mon Jul 20 07:12:11.757862 2026] [security2:error] [pid 78969:tid 79005] [remote 162.19.86.63:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4eq3DvNPGtvLGb7O0UbAAAmCM"]
[Mon Jul 20 07:12:11.831887 2026] [security2:error] [pid 78969:tid 79188] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/.well-known/about.php"] [unique_id "al4eq3DvNPGtvLGb7O0UbQAAAN4"]
[Mon Jul 20 07:12:11.832047 2026] [security2:error] [pid 78969:tid 79188] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/.well-known/about.php"] [unique_id "al4eq3DvNPGtvLGb7O0UbQAAAN4"]
[Mon Jul 20 07:12:11.965642 2026] [security2:error] [pid 78969:tid 79084] [remote 162.19.86.63:38454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4eq3DvNPGtvLGb7O0UcQAAu3I"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 07:12:12.155495 2026] [security2:error] [pid 85094:tid 85251] [client 194.61.41.96:28673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-phpmailer-beta.php"] [unique_id "al4erK_nUl59BcEkkgFsRQAAASQ"]
[Mon Jul 20 07:12:12.272716 2026] [security2:error] [pid 78969:tid 79151] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4erHDvNPGtvLGb7O0UgwAAALk"]
[Mon Jul 20 07:12:12.272865 2026] [security2:error] [pid 78969:tid 79151] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4erHDvNPGtvLGb7O0UgwAAALk"]
[Mon Jul 20 07:12:12.660105 2026] [security2:error] [pid 85094:tid 85331] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/bob.php"] [unique_id "al4erK_nUl59BcEkkgFsWwAAAXM"]
[Mon Jul 20 07:12:12.660196 2026] [security2:error] [pid 85094:tid 85331] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/bob.php"] [unique_id "al4erK_nUl59BcEkkgFsWwAAAXM"]
[Mon Jul 20 07:12:12.675451 2026] [security2:error] [pid 85094:tid 85284] [client 14.225.17.146:55871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4erK_nUl59BcEkkgFsVgAAAUQ"], referer: http://superiorcopywriting.com/2017
[Mon Jul 20 07:12:12.940876 2026] [security2:error] [pid 85094:tid 85249] [client 194.61.41.88:59501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ms-file.php"] [unique_id "al4erK_nUl59BcEkkgFsXgAAASI"]
[Mon Jul 20 07:12:13.058408 2026] [security2:error] [pid 78969:tid 79171] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4erXDvNPGtvLGb7O0UogAAAM0"]
[Mon Jul 20 07:12:13.109889 2026] [security2:error] [pid 78969:tid 79009] [remote 100.42.189.89:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4erXDvNPGtvLGb7O0UqQAA1yc"]
[Mon Jul 20 07:12:13.220711 2026] [security2:error] [pid 78969:tid 79218] [client 98.95.100.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4erXDvNPGtvLGb7O0UpAAA_AM"]
[Mon Jul 20 07:12:13.260178 2026] [security2:error] [pid 78969:tid 79184] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4erXDvNPGtvLGb7O0UsgAAANo"]
[Mon Jul 20 07:12:13.322560 2026] [security2:error] [pid 78969:tid 79055] [remote 100.42.189.89:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4erXDvNPGtvLGb7O0UtwAAylU"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 07:12:13.471724 2026] [security2:error] [pid 78969:tid 79103] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4erXDvNPGtvLGb7O0UuwAAAIk"]
[Mon Jul 20 07:12:13.496883 2026] [security2:error] [pid 85094:tid 85277] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4era_nUl59BcEkkgFsbQAAAT4"], referer: 1'"3000
[Mon Jul 20 07:12:13.607645 2026] [security2:error] [pid 78969:tid 79036] [remote 130.51.180.8:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4erXDvNPGtvLGb7O0UxAAAx0I"]
[Mon Jul 20 07:12:13.766308 2026] [security2:error] [pid 78969:tid 79017] [remote 130.51.180.8:42748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4erXDvNPGtvLGb7O0UzQAA7S8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:12:13.793027 2026] [security2:error] [pid 85094:tid 85352] [client 194.61.41.71:49407] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "655"] [id "900155"] [msg "WP Brute UA block"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/wp-login.php"] [unique_id "al4era_nUl59BcEkkgFsdwAAAYg"]
[Mon Jul 20 07:12:13.911048 2026] [security2:error] [pid 78969:tid 79154] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4erXDvNPGtvLGb7O0U0wAAALw"]
[Mon Jul 20 07:12:14.155624 2026] [security2:error] [pid 78969:tid 79202] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/crgio.php"] [unique_id "al4ernDvNPGtvLGb7O0U2gAAAOw"]
[Mon Jul 20 07:12:14.155721 2026] [security2:error] [pid 78969:tid 79202] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/crgio.php"] [unique_id "al4ernDvNPGtvLGb7O0U2gAAAOw"]
[Mon Jul 20 07:12:14.197297 2026] [security2:error] [pid 78969:tid 79104] [client 14.225.17.146:55334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4erHDvNPGtvLGb7O0UkgAAAIo"], referer: http://amalia-capital.com/2017
[Mon Jul 20 07:12:14.430712 2026] [security2:error] [pid 85094:tid 85307] [client 14.225.17.146:53386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4erq_nUl59BcEkkgFslQAAAVs"], referer: http://aljosour-alarabia.com/2017
[Mon Jul 20 07:12:14.454158 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ernDvNPGtvLGb7O0U3gAAAOg"], referer: 1'"3000
[Mon Jul 20 07:12:14.530369 2026] [security2:error] [pid 85094:tid 85135] [remote 95.217.78.234:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4erq_nUl59BcEkkgFsmwABLCc"]
[Mon Jul 20 07:12:14.535631 2026] [security2:error] [pid 85094:tid 85243] [client 194.61.41.96:42531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/av.php"] [unique_id "al4erq_nUl59BcEkkgFsnAAAARw"]
[Mon Jul 20 07:12:14.540960 2026] [security2:error] [pid 85094:tid 85335] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/pucci.php"] [unique_id "al4erq_nUl59BcEkkgFsngAAAXc"]
[Mon Jul 20 07:12:14.541062 2026] [security2:error] [pid 85094:tid 85335] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/pucci.php"] [unique_id "al4erq_nUl59BcEkkgFsngAAAXc"]
[Mon Jul 20 07:12:14.614689 2026] [core:error] [pid 78969:tid 79222] [client 14.225.17.146:55934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2017
[Mon Jul 20 07:12:14.614710 2026] [core:error] [pid 78969:tid 79222] [client 14.225.17.146:55934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2017
[Mon Jul 20 07:12:14.774743 2026] [security2:error] [pid 85094:tid 85141] [remote 95.217.78.234:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4erq_nUl59BcEkkgFsqQABNi0"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:12:14.803030 2026] [security2:error] [pid 85094:tid 85146] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4erq_nUl59BcEkkgFsrAABgzI"]
[Mon Jul 20 07:12:14.803174 2026] [security2:error] [pid 85094:tid 85347] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4erq_nUl59BcEkkgFsrAABgzI"]
[Mon Jul 20 07:12:14.829418 2026] [security2:error] [pid 78969:tid 79150] [client 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4ernDvNPGtvLGb7O0U9wAAALg"]
[Mon Jul 20 07:12:14.921017 2026] [security2:error] [pid 85094:tid 85298] [client 3.75.183.99:50604] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4erq_nUl59BcEkkgFstAAAAVI"]
[Mon Jul 20 07:12:15.023513 2026] [security2:error] [pid 78969:tid 79075] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4er3DvNPGtvLGb7O0VAwAAumk"]
[Mon Jul 20 07:12:15.023620 2026] [security2:error] [pid 78969:tid 79152] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4er3DvNPGtvLGb7O0VAwAAumk"]
[Mon Jul 20 07:12:15.083243 2026] [security2:error] [pid 85094:tid 85238] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4er6_nUl59BcEkkgFsuAAAARc"]
[Mon Jul 20 07:12:15.240594 2026] [security2:error] [pid 85094:tid 85314] [client 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4er6_nUl59BcEkkgFswwAAAWI"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 07:12:15.261882 2026] [security2:error] [pid 85094:tid 85282] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4er6_nUl59BcEkkgFsxgAAAUI"]
[Mon Jul 20 07:12:15.319333 2026] [security2:error] [pid 85094:tid 85265] [client 103.144.65.217:53368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4er6_nUl59BcEkkgFsywAAATI"]
[Mon Jul 20 07:12:15.319444 2026] [security2:error] [pid 85094:tid 85265] [client 103.144.65.217:53368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4er6_nUl59BcEkkgFsywAAATI"]
[Mon Jul 20 07:12:15.358064 2026] [security2:error] [pid 85094:tid 85234] [client 194.61.41.91:51343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/chosen.php%20"] [unique_id "al4er6_nUl59BcEkkgFszQAAARM"]
[Mon Jul 20 07:12:15.420794 2026] [security2:error] [pid 85094:tid 85137] [remote 57.141.18.63:61650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5356874"] [unique_id "al4er6_nUl59BcEkkgFszgABPyk"]
[Mon Jul 20 07:12:15.447734 2026] [security2:error] [pid 85094:tid 85336] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4er6_nUl59BcEkkgFszwAAAXg"]
[Mon Jul 20 07:12:15.666065 2026] [security2:error] [pid 85094:tid 85335] [client 57.141.18.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4er6_nUl59BcEkkgFs1QAAAXc"]
[Mon Jul 20 07:12:15.743015 2026] [security2:error] [pid 85094:tid 85342] [client 57.141.18.28:53118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eq6_nUl59BcEkkgFsJQABfn8"]
[Mon Jul 20 07:12:15.805308 2026] [security2:error] [pid 85094:tid 85323] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4er6_nUl59BcEkkgFs4gAAAWs"]
[Mon Jul 20 07:12:15.944994 2026] [security2:error] [pid 85094:tid 85294] [client 187.16.64.216:51648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4er6_nUl59BcEkkgFs6wAAAU4"]
[Mon Jul 20 07:12:15.945093 2026] [security2:error] [pid 85094:tid 85294] [client 187.16.64.216:51648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4er6_nUl59BcEkkgFs6wAAAU4"]
[Mon Jul 20 07:12:15.970898 2026] [security2:error] [pid 78969:tid 79053] [remote 188.166.241.141:41100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4er3DvNPGtvLGb7O0VLwAA8FM"]
[Mon Jul 20 07:12:15.971077 2026] [security2:error] [pid 78969:tid 79206] [client 188.166.241.141:41100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4er3DvNPGtvLGb7O0VLwAA8FM"]
[Mon Jul 20 07:12:15.981250 2026] [security2:error] [pid 85094:tid 85256] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-temp.php"] [unique_id "al4er6_nUl59BcEkkgFs7AAAASk"]
[Mon Jul 20 07:12:15.981350 2026] [security2:error] [pid 85094:tid 85256] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-temp.php"] [unique_id "al4er6_nUl59BcEkkgFs7AAAASk"]
[Mon Jul 20 07:12:15.985803 2026] [security2:error] [pid 85094:tid 85347] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4er6_nUl59BcEkkgFs3gAAAYM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:16.134664 2026] [security2:error] [pid 78969:tid 79114] [client 194.61.41.64:62171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/bs1.php"] [unique_id "al4esHDvNPGtvLGb7O0VOAAAAJQ"]
[Mon Jul 20 07:12:16.270130 2026] [security2:error] [pid 85094:tid 85226] [client 88.241.67.160:56822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4esK_nUl59BcEkkgFs-QAAAQs"]
[Mon Jul 20 07:12:16.270354 2026] [security2:error] [pid 85094:tid 85226] [client 88.241.67.160:56822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4esK_nUl59BcEkkgFs-QAAAQs"]
[Mon Jul 20 07:12:16.378346 2026] [security2:error] [pid 85094:tid 85306] [client 14.225.17.146:53408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4esK_nUl59BcEkkgFs7gAAAVo"], referer: http://transparentservices.online/2017
[Mon Jul 20 07:12:16.393654 2026] [security2:error] [pid 78969:tid 79203] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4esHDvNPGtvLGb7O0VRQAAAO0"]
[Mon Jul 20 07:12:16.584146 2026] [security2:error] [pid 78969:tid 79174] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4esHDvNPGtvLGb7O0VSgAAANA"]
[Mon Jul 20 07:12:16.674176 2026] [security2:error] [pid 85094:tid 85259] [client 63.179.149.246:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4er6_nUl59BcEkkgFs0wAAASw"]
[Mon Jul 20 07:12:16.773527 2026] [security2:error] [pid 85094:tid 85247] [client 63.179.149.246:21020] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4er6_nUl59BcEkkgFs0AAAASA"]
[Mon Jul 20 07:12:16.933256 2026] [security2:error] [pid 78969:tid 79226] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4esHDvNPGtvLGb7O0VXwAAAQQ"]
[Mon Jul 20 07:12:16.933358 2026] [security2:error] [pid 78969:tid 79226] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4esHDvNPGtvLGb7O0VXwAAAQQ"]
[Mon Jul 20 07:12:16.960229 2026] [security2:error] [pid 78969:tid 79109] [client 194.61.41.242:26073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/autoload_classmap.php"] [unique_id "al4esHDvNPGtvLGb7O0VYwAAAI8"]
[Mon Jul 20 07:12:17.012287 2026] [security2:error] [pid 85094:tid 85110] [remote 68.178.160.25:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4esa_nUl59BcEkkgFtOQABSw4"]
[Mon Jul 20 07:12:17.102640 2026] [security2:error] [pid 85094:tid 85298] [client 201.27.111.74:54001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4esa_nUl59BcEkkgFtPQAAAVI"]
[Mon Jul 20 07:12:17.102796 2026] [security2:error] [pid 85094:tid 85298] [client 201.27.111.74:54001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4esa_nUl59BcEkkgFtPQAAAVI"]
[Mon Jul 20 07:12:17.323846 2026] [security2:error] [pid 85094:tid 85164] [remote 95.217.78.234:48196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4esa_nUl59BcEkkgFtUAABD0Q"]
[Mon Jul 20 07:12:17.502079 2026] [security2:error] [pid 85094:tid 85169] [remote 68.178.160.25:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4esa_nUl59BcEkkgFtVgABUEk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:12:17.546796 2026] [security2:error] [pid 85094:tid 85170] [remote 95.217.78.234:48196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4esa_nUl59BcEkkgFtXQABTUo"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 07:12:17.630023 2026] [security2:error] [pid 85094:tid 85301] [client 50.116.65.227:51376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4esa_nUl59BcEkkgFtYQAAAVU"]
[Mon Jul 20 07:12:17.642370 2026] [security2:error] [pid 85094:tid 85282] [client 50.116.65.227:51392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4esa_nUl59BcEkkgFtYwAAAUI"]
[Mon Jul 20 07:12:17.708618 2026] [security2:error] [pid 78969:tid 79207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4esXDvNPGtvLGb7O0VdgAAAPE"], referer: 1'"3000
[Mon Jul 20 07:12:17.734317 2026] [security2:error] [pid 85094:tid 85240] [client 194.61.41.105:58547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/network.php"] [unique_id "al4esa_nUl59BcEkkgFtagAAARk"]
[Mon Jul 20 07:12:18.055973 2026] [security2:error] [pid 78969:tid 79165] [client 152.42.185.27:62177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itekphonerepair.com"] [uri "/xmlrpc.php"] [unique_id "al4esnDvNPGtvLGb7O0VjwAAAMc"], referer: https://itcompaniesdirectory.net//blog//wp-login.php
[Mon Jul 20 07:12:18.072324 2026] [security2:error] [pid 78969:tid 79103] [client 84.32.245.178:19160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4esXDvNPGtvLGb7O0VgwAAiXw"]
[Mon Jul 20 07:12:18.450244 2026] [security2:error] [pid 85094:tid 85323] [client 194.61.41.78:35755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/page.php"] [unique_id "al4esq_nUl59BcEkkgFtkAAAAWs"]
[Mon Jul 20 07:12:18.458165 2026] [security2:error] [pid 78969:tid 79201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4esnDvNPGtvLGb7O0VkAAAAOs"], referer: 1'"3000
[Mon Jul 20 07:12:18.732985 2026] [security2:error] [pid 85094:tid 85181] [remote 152.228.213.32:48488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4esq_nUl59BcEkkgFtmQABaVU"]
[Mon Jul 20 07:12:18.913313 2026] [security2:error] [pid 85094:tid 85177] [remote 152.228.213.32:48488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4esq_nUl59BcEkkgFtowABc1E"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:12:18.951517 2026] [security2:error] [pid 78969:tid 79195] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4esnDvNPGtvLGb7O0VqwAAAOU"]
[Mon Jul 20 07:12:19.084020 2026] [security2:error] [pid 85094:tid 85249] [client 14.225.17.146:55744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4esq_nUl59BcEkkgFtggAAASI"], referer: http://entuvy.com/2017
[Mon Jul 20 07:12:19.229199 2026] [security2:error] [pid 85094:tid 85346] [client 194.61.41.91:38175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/includes/index.php"] [unique_id "al4es6_nUl59BcEkkgFtsAAAAYI"]
[Mon Jul 20 07:12:19.276890 2026] [security2:error] [pid 85094:tid 85304] [client 57.141.18.19:30924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4er6_nUl59BcEkkgFs2AABWCw"]
[Mon Jul 20 07:12:19.337831 2026] [security2:error] [pid 85094:tid 85190] [remote 104.248.157.6:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.157.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4es6_nUl59BcEkkgFtuAABXV4"]
[Mon Jul 20 07:12:19.470292 2026] [security2:error] [pid 78969:tid 79104] [client 82.102.18.116:35714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4es3DvNPGtvLGb7O0V3wAAAIo"]
[Mon Jul 20 07:12:19.532846 2026] [security2:error] [pid 85094:tid 85245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4es6_nUl59BcEkkgFtqwAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:19.676009 2026] [security2:error] [pid 78969:tid 79138] [client 14.225.17.146:55112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4es3DvNPGtvLGb7O0V5AAAAKw"], referer: http://mourgroup.com/2017
[Mon Jul 20 07:12:19.723881 2026] [security2:error] [pid 85094:tid 85158] [remote 104.248.157.6:35354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.157.248.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4es6_nUl59BcEkkgFtxwABEz4"], referer: https://fineartsfactory.net/wp-login.php
[Mon Jul 20 07:12:19.743204 2026] [security2:error] [pid 85094:tid 85292] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4es6_nUl59BcEkkgFtvAAAAUw"]
[Mon Jul 20 07:12:19.746769 2026] [security2:error] [pid 85094:tid 85330] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/puc.php"] [unique_id "al4es6_nUl59BcEkkgFtygAAAXI"]
[Mon Jul 20 07:12:19.746861 2026] [security2:error] [pid 85094:tid 85330] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/puc.php"] [unique_id "al4es6_nUl59BcEkkgFtygAAAXI"]
[Mon Jul 20 07:12:19.954125 2026] [security2:error] [pid 78969:tid 79133] [client 194.61.41.56:43971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/chosen.php"] [unique_id "al4es3DvNPGtvLGb7O0V8gAAAKc"]
[Mon Jul 20 07:12:20.102808 2026] [security2:error] [pid 85094:tid 85229] [client 207.46.13.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4es6_nUl59BcEkkgFt0AAAAQ4"]
[Mon Jul 20 07:12:20.123675 2026] [security2:error] [pid 78969:tid 79122] [client 152.42.185.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4esnDvNPGtvLGb7O0VsAAAAJw"], referer: https://itcompaniesdirectory.net//blog//wp-login.php
[Mon Jul 20 07:12:20.130044 2026] [security2:error] [pid 85094:tid 85344] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/themes.php"] [unique_id "al4etK_nUl59BcEkkgFt5QAAAYA"]
[Mon Jul 20 07:12:20.130251 2026] [security2:error] [pid 85094:tid 85344] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/themes.php"] [unique_id "al4etK_nUl59BcEkkgFt5QAAAYA"]
[Mon Jul 20 07:12:20.152143 2026] [security2:error] [pid 85094:tid 85321] [client 82.102.18.116:35730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4etK_nUl59BcEkkgFt5wAAAWk"]
[Mon Jul 20 07:12:20.465687 2026] [security2:error] [pid 78969:tid 79043] [remote 212.95.34.85:25342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4etHDvNPGtvLGb7O0WBgAAx0k"]
[Mon Jul 20 07:12:20.478179 2026] [security2:error] [pid 85094:tid 85266] [client 82.102.18.116:35740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4etK_nUl59BcEkkgFt9gAAATM"]
[Mon Jul 20 07:12:20.512729 2026] [security2:error] [pid 78969:tid 79110] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/dx.php"] [unique_id "al4etHDvNPGtvLGb7O0WDgAAAJA"]
[Mon Jul 20 07:12:20.512835 2026] [security2:error] [pid 78969:tid 79110] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/dx.php"] [unique_id "al4etHDvNPGtvLGb7O0WDgAAAJA"]
[Mon Jul 20 07:12:20.635107 2026] [security2:error] [pid 78969:tid 79198] [client 57.141.18.0:53596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4esXDvNPGtvLGb7O0VZwAA6HI"]
[Mon Jul 20 07:12:20.678812 2026] [security2:error] [pid 78969:tid 79090] [remote 212.95.34.85:25342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.34.95.212.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4etHDvNPGtvLGb7O0WFwAA3Xg"], referer: https://sarakety.com/wp-login.php
[Mon Jul 20 07:12:20.715039 2026] [security2:error] [pid 85094:tid 85278] [client 194.61.41.250:25665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/WordPressCore/include.php"] [unique_id "al4etK_nUl59BcEkkgFuAgAAAT8"]
[Mon Jul 20 07:12:20.773735 2026] [security2:error] [pid 85094:tid 85312] [client 152.42.185.27:55608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4etK_nUl59BcEkkgFuAAAAAWA"], referer: https://itcompaniesdirectory.net//blog//wp-login.php
[Mon Jul 20 07:12:20.791683 2026] [security2:error] [pid 78969:tid 79120] [client 82.102.18.116:35742] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4etHDvNPGtvLGb7O0WHgAAAJo"]
[Mon Jul 20 07:12:20.876325 2026] [security2:error] [pid 78969:tid 79128] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/p.php"] [unique_id "al4etHDvNPGtvLGb7O0WIAAAAKI"]
[Mon Jul 20 07:12:20.876456 2026] [security2:error] [pid 78969:tid 79128] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/p.php"] [unique_id "al4etHDvNPGtvLGb7O0WIAAAAKI"]
[Mon Jul 20 07:12:20.958997 2026] [security2:error] [pid 85094:tid 85299] [client 66.249.74.36:35659] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.colliersgroup.com"] [uri "/robots.txt"] [unique_id "al4etK_nUl59BcEkkgFuDwAAAVM"]
[Mon Jul 20 07:12:20.965278 2026] [core:error] [pid 78969:tid 79133] [client 205.210.31.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:12:20.965298 2026] [core:error] [pid 78969:tid 79133] [client 205.210.31.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:12:21.001813 2026] [security2:error] [pid 78969:tid 79158] [client 158.173.166.181:31901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4etXDvNPGtvLGb7O0WKgAAAMA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:12:21.124203 2026] [security2:error] [pid 78969:tid 79145] [client 82.102.18.116:35756] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4etXDvNPGtvLGb7O0WMgAAALM"]
[Mon Jul 20 07:12:21.301696 2026] [security2:error] [pid 85094:tid 85348] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4eta_nUl59BcEkkgFuIQAAAYQ"]
[Mon Jul 20 07:12:21.384166 2026] [security2:error] [pid 85094:tid 85344] [client 152.42.185.27:55608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itekphonerepair.com"] [uri "/index.php"] [unique_id "al4eta_nUl59BcEkkgFuHgAAAYA"], referer: https://itcompaniesdirectory.net//blog//wp-login.php
[Mon Jul 20 07:12:21.432170 2026] [security2:error] [pid 85094:tid 85322] [client 194.61.41.106:31599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/admin-footer.php"] [unique_id "al4eta_nUl59BcEkkgFuJgAAAWo"]
[Mon Jul 20 07:12:21.443063 2026] [security2:error] [pid 85094:tid 85235] [client 104.234.53.51:63567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4eta_nUl59BcEkkgFuKAAAARQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:21.450671 2026] [security2:error] [pid 85094:tid 85342] [client 82.102.18.116:35766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4eta_nUl59BcEkkgFuKQAAAX4"]
[Mon Jul 20 07:12:21.479381 2026] [security2:error] [pid 78969:tid 79207] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4etHDvNPGtvLGb7O0WIQAA8UE"], referer: http://assasalnazaha.com/2017
[Mon Jul 20 07:12:21.499087 2026] [security2:error] [pid 85094:tid 85261] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4eta_nUl59BcEkkgFuKwAAAS4"]
[Mon Jul 20 07:12:21.536219 2026] [security2:error] [pid 85094:tid 85349] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eta_nUl59BcEkkgFuJAAAAYU"], referer: 1'"3000
[Mon Jul 20 07:12:21.573693 2026] [security2:error] [pid 85094:tid 85282] [client 152.42.185.27:55608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itekphonerepair.com"] [uri "/blog//xmlrpc.php"] [unique_id "al4eta_nUl59BcEkkgFuLgAAAUI"]
[Mon Jul 20 07:12:21.573798 2026] [security2:error] [pid 85094:tid 85282] [client 152.42.185.27:55608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "itekphonerepair.com"] [uri "/blog//xmlrpc.php"] [unique_id "al4eta_nUl59BcEkkgFuLgAAAUI"]
[Mon Jul 20 07:12:21.696721 2026] [security2:error] [pid 85094:tid 85296] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/bthil.php"] [unique_id "al4eta_nUl59BcEkkgFuMAAAAVA"]
[Mon Jul 20 07:12:21.696823 2026] [security2:error] [pid 85094:tid 85296] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/bthil.php"] [unique_id "al4eta_nUl59BcEkkgFuMAAAAVA"]
[Mon Jul 20 07:12:21.774579 2026] [security2:error] [pid 85094:tid 85299] [client 82.102.18.116:35774] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4eta_nUl59BcEkkgFuOAAAAVM"]
[Mon Jul 20 07:12:22.065099 2026] [security2:error] [pid 78969:tid 79203] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/7.php"] [unique_id "al4etnDvNPGtvLGb7O0WYAAAAO0"]
[Mon Jul 20 07:12:22.065198 2026] [security2:error] [pid 78969:tid 79203] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/7.php"] [unique_id "al4etnDvNPGtvLGb7O0WYAAAAO0"]
[Mon Jul 20 07:12:22.109733 2026] [security2:error] [pid 78969:tid 79156] [client 82.102.18.116:35786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4etnDvNPGtvLGb7O0WYgAAAL4"]
[Mon Jul 20 07:12:22.142789 2026] [security2:error] [pid 85094:tid 85342] [client 194.61.41.82:40801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/modules/mod_simplefileuploadv1.3/elements/admin-footer.php"] [unique_id "al4etq_nUl59BcEkkgFuTAAAAX4"]
[Mon Jul 20 07:12:22.174915 2026] [security2:error] [pid 85094:tid 85205] [remote 124.55.178.99:56994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4etq_nUl59BcEkkgFuUAABcm0"]
[Mon Jul 20 07:12:22.275737 2026] [security2:error] [pid 78969:tid 79222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4etXDvNPGtvLGb7O0WXAAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:22.319118 2026] [security2:error] [pid 78969:tid 79137] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4etnDvNPGtvLGb7O0WYQAAAKs"], referer: 1'"3000
[Mon Jul 20 07:12:22.355998 2026] [security2:error] [pid 78969:tid 79213] [client 152.42.185.27:57570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.185.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "itekphonerepair.com"] [uri "/blog//wp-login.php"] [unique_id "al4etnDvNPGtvLGb7O0WbAAAAPc"], referer: https://itekphonerepair.com//blog//wp-login.php
[Mon Jul 20 07:12:22.374717 2026] [security2:error] [pid 85094:tid 85259] [client 57.141.18.72:36024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4esq_nUl59BcEkkgFtmAABLFg"]
[Mon Jul 20 07:12:22.415668 2026] [security2:error] [pid 85094:tid 85309] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/8.php"] [unique_id "al4etq_nUl59BcEkkgFuYAAAAV0"]
[Mon Jul 20 07:12:22.415739 2026] [security2:error] [pid 85094:tid 85309] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/8.php"] [unique_id "al4etq_nUl59BcEkkgFuYAAAAV0"]
[Mon Jul 20 07:12:22.430825 2026] [security2:error] [pid 85094:tid 85306] [client 82.102.18.116:35792] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4etq_nUl59BcEkkgFuYQAAAVo"]
[Mon Jul 20 07:12:22.609263 2026] [security2:error] [pid 85094:tid 85217] [remote 124.55.178.99:56994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4etq_nUl59BcEkkgFuagABF3k"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 07:12:22.767611 2026] [security2:error] [pid 78969:tid 79116] [client 98.95.161.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4etnDvNPGtvLGb7O0WfAAAlgU"]
[Mon Jul 20 07:12:22.770602 2026] [security2:error] [pid 78969:tid 79189] [client 82.102.18.116:35798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4etnDvNPGtvLGb7O0WjQAAAN8"]
[Mon Jul 20 07:12:22.794342 2026] [security2:error] [pid 85094:tid 85244] [client 191.237.250.106:0] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/1.php"] [unique_id "al4etq_nUl59BcEkkgFucwAAAR0"]
[Mon Jul 20 07:12:22.794455 2026] [security2:error] [pid 85094:tid 85244] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/1.php"] [unique_id "al4etq_nUl59BcEkkgFucwAAAR0"]
[Mon Jul 20 07:12:22.794558 2026] [security2:error] [pid 85094:tid 85244] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/1.php"] [unique_id "al4etq_nUl59BcEkkgFucwAAAR0"]
[Mon Jul 20 07:12:22.940827 2026] [security2:error] [pid 78969:tid 79142] [client 194.61.41.102:50545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/info.php"] [unique_id "al4etnDvNPGtvLGb7O0WlgAAALA"]
[Mon Jul 20 07:12:23.111816 2026] [security2:error] [pid 85094:tid 85259] [client 82.102.18.116:35814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4et6_nUl59BcEkkgFuggAAASw"]
[Mon Jul 20 07:12:23.172511 2026] [security2:error] [pid 78969:tid 79111] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/100.php"] [unique_id "al4et3DvNPGtvLGb7O0WoAAAAJE"]
[Mon Jul 20 07:12:23.172651 2026] [security2:error] [pid 78969:tid 79111] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/100.php"] [unique_id "al4et3DvNPGtvLGb7O0WoAAAAJE"]
[Mon Jul 20 07:12:23.435029 2026] [security2:error] [pid 85094:tid 85230] [client 82.102.18.116:35820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4et6_nUl59BcEkkgFumAAAAQ8"]
[Mon Jul 20 07:12:23.527776 2026] [security2:error] [pid 85094:tid 85239] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/about.php"] [unique_id "al4et6_nUl59BcEkkgFumwAAARg"]
[Mon Jul 20 07:12:23.527890 2026] [security2:error] [pid 85094:tid 85239] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/about.php"] [unique_id "al4et6_nUl59BcEkkgFumwAAARg"]
[Mon Jul 20 07:12:23.589864 2026] [security2:error] [pid 85094:tid 85231] [client 117.211.236.168:58982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4et6_nUl59BcEkkgFuogAAARA"]
[Mon Jul 20 07:12:23.589956 2026] [security2:error] [pid 85094:tid 85231] [client 117.211.236.168:58982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4et6_nUl59BcEkkgFuogAAARA"]
[Mon Jul 20 07:12:23.657352 2026] [security2:error] [pid 78969:tid 79200] [client 159.89.114.44:56936] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.thslogistics.net"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4et3DvNPGtvLGb7O0WrwAAAOo"]
[Mon Jul 20 07:12:23.736142 2026] [security2:error] [pid 78969:tid 79171] [client 194.61.41.94:57997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/XML/content.php"] [unique_id "al4et3DvNPGtvLGb7O0WuwAAAM0"]
[Mon Jul 20 07:12:23.745872 2026] [security2:error] [pid 78969:tid 79209] [client 82.102.18.116:35836] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4et3DvNPGtvLGb7O0WvAAAAPM"]
[Mon Jul 20 07:12:23.880423 2026] [security2:error] [pid 85094:tid 85234] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/admin.php"] [unique_id "al4et6_nUl59BcEkkgFutAAAARM"]
[Mon Jul 20 07:12:23.880541 2026] [security2:error] [pid 85094:tid 85234] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/admin.php"] [unique_id "al4et6_nUl59BcEkkgFutAAAARM"]
[Mon Jul 20 07:12:23.897674 2026] [security2:error] [pid 85094:tid 85298] [client 14.225.17.146:58411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4et6_nUl59BcEkkgFurAAAAVI"], referer: http://careysheatingandcooling.com/2017
[Mon Jul 20 07:12:24.082405 2026] [security2:error] [pid 85094:tid 85230] [client 82.102.18.116:35848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4euK_nUl59BcEkkgFuvAAAAQ8"]
[Mon Jul 20 07:12:24.101398 2026] [ssl:error] [pid 78969:tid 79112] [client 66.132.195.39:59744] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname cathybuffini.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:12:24.111414 2026] [security2:error] [pid 78969:tid 79198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4et3DvNPGtvLGb7O0WwwAAAOg"], referer: 1'"3000
[Mon Jul 20 07:12:24.226697 2026] [security2:error] [pid 85094:tid 85345] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/edit.php"] [unique_id "al4euK_nUl59BcEkkgFuxAAAAYE"]
[Mon Jul 20 07:12:24.226807 2026] [security2:error] [pid 85094:tid 85345] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/edit.php"] [unique_id "al4euK_nUl59BcEkkgFuxAAAAYE"]
[Mon Jul 20 07:12:24.429142 2026] [security2:error] [pid 78969:tid 79152] [client 82.102.18.116:35854] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4euHDvNPGtvLGb7O0W5AAAALo"]
[Mon Jul 20 07:12:24.497542 2026] [security2:error] [pid 78969:tid 79153] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4euHDvNPGtvLGb7O0W3wAAALs"], referer: 1'"3000
[Mon Jul 20 07:12:24.552869 2026] [security2:error] [pid 85094:tid 85242] [client 194.61.41.82:31999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/item.php"] [unique_id "al4euK_nUl59BcEkkgFu0QAAARs"]
[Mon Jul 20 07:12:24.590786 2026] [security2:error] [pid 85094:tid 85261] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/admin.php"] [unique_id "al4euK_nUl59BcEkkgFu0gAAAS4"]
[Mon Jul 20 07:12:24.590912 2026] [security2:error] [pid 85094:tid 85261] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/admin.php"] [unique_id "al4euK_nUl59BcEkkgFu0gAAAS4"]
[Mon Jul 20 07:12:24.767965 2026] [security2:error] [pid 78969:tid 79174] [client 82.102.18.116:35866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.msd.mqz.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4euHDvNPGtvLGb7O0W7QAAANA"]
[Mon Jul 20 07:12:24.968709 2026] [security2:error] [pid 78969:tid 79175] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/f6.php"] [unique_id "al4euHDvNPGtvLGb7O0W-wAAANE"]
[Mon Jul 20 07:12:24.968828 2026] [security2:error] [pid 78969:tid 79175] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/f6.php"] [unique_id "al4euHDvNPGtvLGb7O0W-wAAANE"]
[Mon Jul 20 07:12:25.008922 2026] [security2:error] [pid 78969:tid 79194] [client 14.225.17.146:53209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4euHDvNPGtvLGb7O0W9AAAAOQ"], referer: http://uritems.net/2017
[Mon Jul 20 07:12:25.032591 2026] [autoindex:error] [pid 78969:tid 78990] [remote 34.48.84.195:64659] AH01276: Cannot serve directory /home2/brsjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.brs.jiv.mybluehost.me
[Mon Jul 20 07:12:25.085068 2026] [security2:error] [pid 85094:tid 85107] [remote 160.187.68.132:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eua_nUl59BcEkkgFu5gABIQs"]
[Mon Jul 20 07:12:25.328048 2026] [security2:error] [pid 78969:tid 79179] [client 194.61.41.78:51911] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/wp-content/1.php%20"] [unique_id "al4euXDvNPGtvLGb7O0XDgAAANU"]
[Mon Jul 20 07:12:25.328146 2026] [security2:error] [pid 78969:tid 79179] [client 194.61.41.78:51911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/1.php%20"] [unique_id "al4euXDvNPGtvLGb7O0XDgAAANU"]
[Mon Jul 20 07:12:25.334360 2026] [security2:error] [pid 78969:tid 79207] [client 47.129.222.11:56866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4euXDvNPGtvLGb7O0XDQAAAPE"]
[Mon Jul 20 07:12:25.334458 2026] [security2:error] [pid 78969:tid 79207] [client 47.129.222.11:56866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4euXDvNPGtvLGb7O0XDQAAAPE"]
[Mon Jul 20 07:12:25.336173 2026] [security2:error] [pid 78969:tid 79127] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/inputs.php"] [unique_id "al4euXDvNPGtvLGb7O0XEAAAAKE"]
[Mon Jul 20 07:12:25.336328 2026] [security2:error] [pid 78969:tid 79127] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/inputs.php"] [unique_id "al4euXDvNPGtvLGb7O0XEAAAAKE"]
[Mon Jul 20 07:12:25.413086 2026] [security2:error] [pid 85094:tid 85256] [client 14.225.17.146:58288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4euK_nUl59BcEkkgFutwAAASk"], referer: http://ghivs.com/2017
[Mon Jul 20 07:12:25.443867 2026] [security2:error] [pid 78969:tid 79044] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4euXDvNPGtvLGb7O0XEwAA_Uo"]
[Mon Jul 20 07:12:25.444042 2026] [security2:error] [pid 78969:tid 79219] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4euXDvNPGtvLGb7O0XEwAA_Uo"]
[Mon Jul 20 07:12:25.494921 2026] [security2:error] [pid 85094:tid 85268] [client 104.234.53.85:63629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4eua_nUl59BcEkkgFu-gAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:25.563710 2026] [security2:error] [pid 85094:tid 85189] [remote 160.187.68.132:57588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4eua_nUl59BcEkkgFu_QABU10"], referer: https://ouw.egd.mybluehost.me/wp-login.php
[Mon Jul 20 07:12:25.698689 2026] [security2:error] [pid 85094:tid 85114] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eua_nUl59BcEkkgFvBAABWRI"]
[Mon Jul 20 07:12:25.698916 2026] [security2:error] [pid 85094:tid 85305] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eua_nUl59BcEkkgFvBAABWRI"]
[Mon Jul 20 07:12:25.713549 2026] [security2:error] [pid 85094:tid 85351] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/av.php"] [unique_id "al4eua_nUl59BcEkkgFvBgAAAYc"]
[Mon Jul 20 07:12:25.713641 2026] [security2:error] [pid 85094:tid 85351] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/av.php"] [unique_id "al4eua_nUl59BcEkkgFvBgAAAYc"]
[Mon Jul 20 07:12:25.850207 2026] [security2:error] [pid 78969:tid 79157] [client 103.144.65.217:53823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4euXDvNPGtvLGb7O0XJgAAAL8"]
[Mon Jul 20 07:12:25.850353 2026] [security2:error] [pid 78969:tid 79157] [client 103.144.65.217:53823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4euXDvNPGtvLGb7O0XJgAAAL8"]
[Mon Jul 20 07:12:26.023097 2026] [security2:error] [pid 85094:tid 85247] [client 57.141.18.78:46720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eta_nUl59BcEkkgFuOwABIHE"]
[Mon Jul 20 07:12:26.034002 2026] [security2:error] [pid 78969:tid 79141] [client 194.61.41.81:37883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/wp-atom.php"] [unique_id "al4eunDvNPGtvLGb7O0XMQAAAK8"]
[Mon Jul 20 07:12:26.046927 2026] [security2:error] [pid 78969:tid 79095] [remote 81.173.115.7:37996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eunDvNPGtvLGb7O0XMgAAon0"]
[Mon Jul 20 07:12:26.047094 2026] [security2:error] [pid 78969:tid 79128] [client 81.173.115.7:37996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4eunDvNPGtvLGb7O0XMgAAon0"]
[Mon Jul 20 07:12:26.070857 2026] [security2:error] [pid 78969:tid 79167] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/classwithtostring.php"] [unique_id "al4eunDvNPGtvLGb7O0XNAAAAMk"]
[Mon Jul 20 07:12:26.070983 2026] [security2:error] [pid 78969:tid 79167] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/classwithtostring.php"] [unique_id "al4eunDvNPGtvLGb7O0XNAAAAMk"]
[Mon Jul 20 07:12:26.103527 2026] [security2:error] [pid 85094:tid 85121] [remote 100.42.189.89:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4euq_nUl59BcEkkgFvIgABfxk"]
[Mon Jul 20 07:12:26.109871 2026] [security2:error] [pid 78969:tid 79109] [client 4.201.176.24:20130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4eunDvNPGtvLGb7O0XNwAAAI8"]
[Mon Jul 20 07:12:26.113603 2026] [security2:error] [pid 85094:tid 85123] [remote 57.141.18.62:59432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6327541"] [unique_id "al4euq_nUl59BcEkkgFvIwABNxs"]
[Mon Jul 20 07:12:26.224147 2026] [security2:error] [pid 85094:tid 85260] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eua_nUl59BcEkkgFvGwAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:26.267630 2026] [security2:error] [pid 78969:tid 79178] [client 4.201.176.24:20130] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4eunDvNPGtvLGb7O0XQQAAANQ"]
[Mon Jul 20 07:12:26.381908 2026] [security2:error] [pid 85094:tid 85347] [client 216.24.212.12:37885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4euq_nUl59BcEkkgFvMwAAAYM"]
[Mon Jul 20 07:12:26.382482 2026] [security2:error] [pid 85094:tid 85227] [client 216.24.212.40:41213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4euq_nUl59BcEkkgFvNgAAAQw"]
[Mon Jul 20 07:12:26.383707 2026] [security2:error] [pid 85094:tid 85298] [client 14.225.17.146:57786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4euq_nUl59BcEkkgFvHQAAAVI"], referer: http://healthylifegourmet.org/2017
[Mon Jul 20 07:12:26.386657 2026] [security2:error] [pid 85094:tid 85124] [remote 100.42.189.89:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4euq_nUl59BcEkkgFvNwABhxw"], referer: https://gertoger.org/wp-login.php
[Mon Jul 20 07:12:26.406179 2026] [security2:error] [pid 85094:tid 85265] [client 187.16.64.216:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4euq_nUl59BcEkkgFvOAAAATI"]
[Mon Jul 20 07:12:26.406326 2026] [security2:error] [pid 85094:tid 85265] [client 187.16.64.216:52236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4euq_nUl59BcEkkgFvOAAAATI"]
[Mon Jul 20 07:12:26.452931 2026] [security2:error] [pid 85094:tid 85282] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4euq_nUl59BcEkkgFvOgAAAUI"]
[Mon Jul 20 07:12:26.453018 2026] [security2:error] [pid 85094:tid 85282] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4euq_nUl59BcEkkgFvOgAAAUI"]
[Mon Jul 20 07:12:26.496359 2026] [security2:error] [pid 85094:tid 85289] [client 172.200.24.58:44417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4euq_nUl59BcEkkgFvPAAAAUk"]
[Mon Jul 20 07:12:26.557499 2026] [security2:error] [pid 85094:tid 85243] [client 172.200.24.58:44417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4euq_nUl59BcEkkgFvQAAAARw"]
[Mon Jul 20 07:12:26.623316 2026] [security2:error] [pid 78969:tid 79103] [client 88.241.67.160:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eunDvNPGtvLGb7O0XTgAAAIk"]
[Mon Jul 20 07:12:26.623834 2026] [security2:error] [pid 78969:tid 79103] [client 88.241.67.160:55830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4eunDvNPGtvLGb7O0XTgAAAIk"]
[Mon Jul 20 07:12:26.824963 2026] [security2:error] [pid 78969:tid 79213] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-blog.php"] [unique_id "al4eunDvNPGtvLGb7O0XVwAAAPc"]
[Mon Jul 20 07:12:26.825064 2026] [security2:error] [pid 78969:tid 79213] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-blog.php"] [unique_id "al4eunDvNPGtvLGb7O0XVwAAAPc"]
[Mon Jul 20 07:12:26.841422 2026] [security2:error] [pid 85094:tid 85236] [client 194.61.41.91:44517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/plugins.php"] [unique_id "al4euq_nUl59BcEkkgFvUAAAARU"]
[Mon Jul 20 07:12:27.092921 2026] [security2:error] [pid 78969:tid 79101] [client 57.141.18.125:27650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4etnDvNPGtvLGb7O0WjwAAh18"]
[Mon Jul 20 07:12:27.399921 2026] [security2:error] [pid 85094:tid 85283] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4eu6_nUl59BcEkkgFvbQAAAUM"]
[Mon Jul 20 07:12:27.440225 2026] [security2:error] [pid 85094:tid 85337] [client 201.27.111.74:54503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eu6_nUl59BcEkkgFvbwAAAXk"]
[Mon Jul 20 07:12:27.440371 2026] [security2:error] [pid 85094:tid 85337] [client 201.27.111.74:54503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4eu6_nUl59BcEkkgFvbwAAAXk"]
[Mon Jul 20 07:12:27.584923 2026] [security2:error] [pid 85094:tid 85250] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4eu6_nUl59BcEkkgFvdAAAASM"]
[Mon Jul 20 07:12:27.636619 2026] [security2:error] [pid 78969:tid 79185] [client 194.61.41.104:27623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/install.php"] [unique_id "al4eu3DvNPGtvLGb7O0XdAAAANs"]
[Mon Jul 20 07:12:27.685138 2026] [security2:error] [pid 85094:tid 85228] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eu6_nUl59BcEkkgFvcgAAAQ0"], referer: 1'"3000
[Mon Jul 20 07:12:27.747384 2026] [security2:error] [pid 78969:tid 79064] [remote 124.55.178.99:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4eu3DvNPGtvLGb7O0XewAAtl4"]
[Mon Jul 20 07:12:27.774847 2026] [security2:error] [pid 85094:tid 85232] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/admin.php"] [unique_id "al4eu6_nUl59BcEkkgFvfAAAARE"]
[Mon Jul 20 07:12:27.774951 2026] [security2:error] [pid 85094:tid 85232] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-content/admin.php"] [unique_id "al4eu6_nUl59BcEkkgFvfAAAARE"]
[Mon Jul 20 07:12:27.943314 2026] [security2:error] [pid 85094:tid 85318] [client 14.225.17.146:57938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4eu6_nUl59BcEkkgFvWQAAAWY"], referer: http://cheesewithjam.com/2017
[Mon Jul 20 07:12:27.954865 2026] [security2:error] [pid 85094:tid 85315] [client 14.225.17.146:57990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4euq_nUl59BcEkkgFvPgAAAWM"], referer: http://dadanetnet.net/2017
[Mon Jul 20 07:12:28.053558 2026] [security2:error] [pid 78969:tid 79156] [client 77.110.127.138:49180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/if(now()=sysdate(),sleep(15),0)/js/dist/wp-seo-local-frontend-1390.js"] [unique_id "al4evHDvNPGtvLGb7O0XiQAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:28.132421 2026] [security2:error] [pid 78969:tid 79131] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/adminfuns.php"] [unique_id "al4evHDvNPGtvLGb7O0XjAAAAKU"]
[Mon Jul 20 07:12:28.132505 2026] [security2:error] [pid 78969:tid 79131] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/adminfuns.php"] [unique_id "al4evHDvNPGtvLGb7O0XjAAAAKU"]
[Mon Jul 20 07:12:28.196186 2026] [security2:error] [pid 78969:tid 79033] [remote 124.55.178.99:57010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4evHDvNPGtvLGb7O0XjgAA7j8"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 07:12:28.219307 2026] [security2:error] [pid 85094:tid 85325] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eu6_nUl59BcEkkgFvgwAAAW0"], referer: 1'"3000
[Mon Jul 20 07:12:28.351295 2026] [security2:error] [pid 78969:tid 79111] [client 194.61.41.92:65211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/gecko-old.php"] [unique_id "al4evHDvNPGtvLGb7O0XkwAAAJE"]
[Mon Jul 20 07:12:28.510860 2026] [security2:error] [pid 85094:tid 85230] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/goods.php"] [unique_id "al4evK_nUl59BcEkkgFvqgAAAQ8"]
[Mon Jul 20 07:12:28.510966 2026] [security2:error] [pid 85094:tid 85230] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/goods.php"] [unique_id "al4evK_nUl59BcEkkgFvqgAAAQ8"]
[Mon Jul 20 07:12:28.688427 2026] [security2:error] [pid 85094:tid 85312] [client 57.141.18.26:23250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4euK_nUl59BcEkkgFuywABYAg"]
[Mon Jul 20 07:12:28.864544 2026] [security2:error] [pid 78969:tid 79193] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ms-edit.php"] [unique_id "al4evHDvNPGtvLGb7O0XrAAAAOM"]
[Mon Jul 20 07:12:28.864670 2026] [security2:error] [pid 78969:tid 79193] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ms-edit.php"] [unique_id "al4evHDvNPGtvLGb7O0XrAAAAOM"]
[Mon Jul 20 07:12:29.182134 2026] [security2:error] [pid 85094:tid 85324] [client 194.61.41.106:51717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/wp-login.php"] [unique_id "al4eva_nUl59BcEkkgFv0AAAAWw"]
[Mon Jul 20 07:12:29.191605 2026] [security2:error] [pid 78969:tid 79169] [client 14.225.17.146:58150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4evHDvNPGtvLGb7O0XpQAAAMs"], referer: http://bruceledewitz.com/2017
[Mon Jul 20 07:12:29.241623 2026] [security2:error] [pid 85094:tid 85254] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/222.php"] [unique_id "al4eva_nUl59BcEkkgFv2AAAASc"]
[Mon Jul 20 07:12:29.241714 2026] [security2:error] [pid 85094:tid 85254] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/222.php"] [unique_id "al4eva_nUl59BcEkkgFv2AAAASc"]
[Mon Jul 20 07:12:29.297222 2026] [security2:error] [pid 78969:tid 79088] [remote 5.161.225.162:40730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4evXDvNPGtvLGb7O0XvQAA_HY"]
[Mon Jul 20 07:12:29.451059 2026] [security2:error] [pid 78969:tid 79128] [client 104.234.53.83:65339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4evXDvNPGtvLGb7O0XxgAAAKI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:29.509604 2026] [security2:error] [pid 78969:tid 79034] [remote 5.161.225.162:40730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4evXDvNPGtvLGb7O0XzgAA5UA"], referer: https://lmgorman.com/wp-login.php
[Mon Jul 20 07:12:29.596997 2026] [security2:error] [pid 85094:tid 85321] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/cgi-bin/index.php"] [unique_id "al4eva_nUl59BcEkkgFv6AAAAWk"]
[Mon Jul 20 07:12:29.597107 2026] [security2:error] [pid 85094:tid 85321] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/cgi-bin/index.php"] [unique_id "al4eva_nUl59BcEkkgFv6AAAAWk"]
[Mon Jul 20 07:12:29.668842 2026] [security2:error] [pid 85094:tid 85241] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eva_nUl59BcEkkgFv4wAAARo"]
[Mon Jul 20 07:12:29.749987 2026] [security2:error] [pid 78969:tid 79148] [client 47.128.43.142:18728] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.qualitycoatingsinspection.com"] [uri "/robots.txt"] [unique_id "al4evXDvNPGtvLGb7O0X2gAAALY"]
[Mon Jul 20 07:12:29.815469 2026] [security2:error] [pid 85094:tid 85312] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eva_nUl59BcEkkgFv6QAAAWA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:29.943694 2026] [security2:error] [pid 78969:tid 79113] [client 194.61.41.67:23521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/autoload_classmap.php"] [unique_id "al4evXDvNPGtvLGb7O0X5gAAAJM"]
[Mon Jul 20 07:12:29.966615 2026] [security2:error] [pid 78969:tid 79135] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4evXDvNPGtvLGb7O0X5wAAAKk"]
[Mon Jul 20 07:12:29.989659 2026] [security2:error] [pid 85094:tid 85295] [client 14.225.17.146:58173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4eva_nUl59BcEkkgFv8QAAAU8"], referer: http://myspineworld.com/2017
[Mon Jul 20 07:12:30.025187 2026] [lsapi:warn] [pid 78969:tid 79189] [client 14.225.17.146:62785] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2017
[Mon Jul 20 07:12:30.025217 2026] [lsapi:warn] [pid 78969:tid 79189] [client 14.225.17.146:62785] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2017
[Mon Jul 20 07:12:30.153129 2026] [security2:error] [pid 85094:tid 85307] [client 45.157.112.60:61449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4evq_nUl59BcEkkgFwCAAAAVs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:12:30.175176 2026] [security2:error] [pid 78969:tid 79112] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4evnDvNPGtvLGb7O0X8QAAAJI"]
[Mon Jul 20 07:12:30.219182 2026] [security2:error] [pid 85094:tid 85261] [client 50.116.65.227:53524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4evq_nUl59BcEkkgFwDAAAAS4"]
[Mon Jul 20 07:12:30.229976 2026] [security2:error] [pid 85094:tid 85319] [client 50.116.65.227:53526] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4evq_nUl59BcEkkgFwDQAAAWc"]
[Mon Jul 20 07:12:30.278933 2026] [security2:error] [pid 85094:tid 85288] [client 14.225.17.146:58119] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4evq_nUl59BcEkkgFwBwAAAUg"], referer: http://backandneckpainrelieflaceychiropractor.com/2017
[Mon Jul 20 07:12:30.378257 2026] [security2:error] [pid 78969:tid 79122] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/BDKR28WP.php"] [unique_id "al4evnDvNPGtvLGb7O0X9gAAAJw"]
[Mon Jul 20 07:12:30.378383 2026] [security2:error] [pid 78969:tid 79122] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/BDKR28WP.php"] [unique_id "al4evnDvNPGtvLGb7O0X9gAAAJw"]
[Mon Jul 20 07:12:30.461444 2026] [security2:error] [pid 78969:tid 79200] [client 14.225.17.146:63327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4evHDvNPGtvLGb7O0XswAAAOo"], referer: http://momheadquarters.com/2017
[Mon Jul 20 07:12:30.478539 2026] [security2:error] [pid 85094:tid 85226] [client 77.110.127.138:49393] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/js/dist/wp-seo-local-frontend-1390.js"] [unique_id "al4evq_nUl59BcEkkgFwGQAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:30.537947 2026] [lsapi:warn] [pid 85094:tid 85228] [client 50.116.65.227:53548] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:12:30.537974 2026] [lsapi:warn] [pid 85094:tid 85228] [client 50.116.65.227:53548] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:12:30.558541 2026] [security2:error] [pid 78969:tid 79189] [client 14.225.17.146:62785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4evXDvNPGtvLGb7O0XzwAAAN8"], referer: http://oswegooperatheater.com/2017
[Mon Jul 20 07:12:30.718283 2026] [security2:error] [pid 85094:tid 85227] [client 14.225.17.146:58253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4eva_nUl59BcEkkgFv2wAAAQw"], referer: http://elitetax-mi.com/2017
[Mon Jul 20 07:12:30.739477 2026] [security2:error] [pid 85094:tid 85266] [client 194.61.41.240:39703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-wp-nav-widgets.php"] [unique_id "al4evq_nUl59BcEkkgFwKwAAATM"]
[Mon Jul 20 07:12:30.768698 2026] [security2:error] [pid 78969:tid 79106] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4evnDvNPGtvLGb7O0YBgAAAIw"]
[Mon Jul 20 07:12:30.953697 2026] [security2:error] [pid 85094:tid 85229] [client 14.225.17.146:62812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4evq_nUl59BcEkkgFwMAAAAQ4"], referer: https://myspineworld.com/2017
[Mon Jul 20 07:12:30.957514 2026] [security2:error] [pid 85094:tid 85170] [remote 192.241.143.148:58822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4evq_nUl59BcEkkgFwOwABO0o"]
[Mon Jul 20 07:12:30.987027 2026] [security2:error] [pid 85094:tid 85350] [client 14.225.17.146:63115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4evK_nUl59BcEkkgFvwQAAAYY"], referer: http://idigress.agency/2017
[Mon Jul 20 07:12:31.030771 2026] [security2:error] [pid 78969:tid 79118] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ev3DvNPGtvLGb7O0YGgAAAJg"]
[Mon Jul 20 07:12:31.128145 2026] [security2:error] [pid 85094:tid 85343] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4evq_nUl59BcEkkgFwNQAAAX8"], referer: 1'"3000
[Mon Jul 20 07:12:31.214799 2026] [security2:error] [pid 78969:tid 79183] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4ev3DvNPGtvLGb7O0YJAAAANk"]
[Mon Jul 20 07:12:31.255494 2026] [security2:error] [pid 85094:tid 85316] [client 157.20.138.62:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ev6_nUl59BcEkkgFwPwAAAWQ"]
[Mon Jul 20 07:12:31.255641 2026] [security2:error] [pid 85094:tid 85316] [client 157.20.138.62:61561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ev6_nUl59BcEkkgFwPwAAAWQ"]
[Mon Jul 20 07:12:31.287282 2026] [security2:error] [pid 85094:tid 85168] [remote 192.241.143.148:58822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ev6_nUl59BcEkkgFwRQABaUg"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:12:31.379702 2026] [lsapi:warn] [pid 78969:tid 79148] [client 14.225.17.146:65133] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2017
[Mon Jul 20 07:12:31.379723 2026] [lsapi:warn] [pid 78969:tid 79148] [client 14.225.17.146:65133] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2017
[Mon Jul 20 07:12:31.416885 2026] [security2:error] [pid 78969:tid 79208] [client 14.225.17.146:52890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4ev3DvNPGtvLGb7O0YKQAAAPI"], referer: http://dnsplumbing.com/2017
[Mon Jul 20 07:12:31.433428 2026] [security2:error] [pid 78969:tid 79148] [client 14.225.17.146:65133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4ev3DvNPGtvLGb7O0YLQAAALY"], referer: https://oswegooperatheater.com/2017
[Mon Jul 20 07:12:31.491064 2026] [security2:error] [pid 85094:tid 85268] [client 14.225.17.146:63049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4evq_nUl59BcEkkgFwAwAAATU"], referer: http://eframiproperties.com/2017
[Mon Jul 20 07:12:31.524138 2026] [security2:error] [pid 85094:tid 85338] [client 194.61.41.64:32425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/wp-pridmag/init.php"] [unique_id "al4ev6_nUl59BcEkkgFwTgAAAXo"]
[Mon Jul 20 07:12:31.580492 2026] [security2:error] [pid 78969:tid 79131] [client 104.234.53.67:32205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ev3DvNPGtvLGb7O0YNgAAAKU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:31.711441 2026] [security2:error] [pid 78969:tid 79108] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ev3DvNPGtvLGb7O0YOwAAAI4"]
[Mon Jul 20 07:12:31.889886 2026] [security2:error] [pid 78969:tid 79191] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp.php"] [unique_id "al4ev3DvNPGtvLGb7O0YSgAAAOE"]
[Mon Jul 20 07:12:31.890036 2026] [security2:error] [pid 78969:tid 79191] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp.php"] [unique_id "al4ev3DvNPGtvLGb7O0YSgAAAOE"]
[Mon Jul 20 07:12:31.926570 2026] [security2:error] [pid 78969:tid 79172] [client 14.225.17.146:52904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4ev3DvNPGtvLGb7O0YOQAAAM4"], referer: http://talknutritionwithlesley.com/2017
[Mon Jul 20 07:12:32.080950 2026] [security2:error] [pid 78969:tid 79132] [client 57.141.18.112:35870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eu3DvNPGtvLGb7O0XfgAApnU"]
[Mon Jul 20 07:12:32.148247 2026] [security2:error] [pid 78969:tid 79144] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ev3DvNPGtvLGb7O0YSwAAALI"], referer: 1'"3000
[Mon Jul 20 07:12:32.223357 2026] [security2:error] [pid 78969:tid 79204] [client 194.61.41.105:63809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/install.php"] [unique_id "al4ewHDvNPGtvLGb7O0YXQAAAO4"]
[Mon Jul 20 07:12:32.268399 2026] [security2:error] [pid 85094:tid 85313] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/abcd.php"] [unique_id "al4ewK_nUl59BcEkkgFwcAAAAWE"]
[Mon Jul 20 07:12:32.268505 2026] [security2:error] [pid 85094:tid 85313] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/abcd.php"] [unique_id "al4ewK_nUl59BcEkkgFwcAAAAWE"]
[Mon Jul 20 07:12:32.511159 2026] [security2:error] [pid 85094:tid 85264] [client 98.159.234.160:27005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ewK_nUl59BcEkkgFwgQAAATE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:12:32.625143 2026] [security2:error] [pid 78969:tid 79174] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/a1.php"] [unique_id "al4ewHDvNPGtvLGb7O0YbAAAANA"]
[Mon Jul 20 07:12:32.625270 2026] [security2:error] [pid 78969:tid 79174] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/a1.php"] [unique_id "al4ewHDvNPGtvLGb7O0YbAAAANA"]
[Mon Jul 20 07:12:32.757698 2026] [security2:error] [pid 85094:tid 85237] [client 52.201.77.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ewK_nUl59BcEkkgFwigABFl4"]
[Mon Jul 20 07:12:32.790069 2026] [security2:error] [pid 85094:tid 85185] [remote 173.212.252.15:50692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4ewK_nUl59BcEkkgFwjwABeVk"]
[Mon Jul 20 07:12:32.790219 2026] [security2:error] [pid 85094:tid 85337] [client 173.212.252.15:50692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4ewK_nUl59BcEkkgFwjwABeVk"]
[Mon Jul 20 07:12:32.798032 2026] [security2:error] [pid 78969:tid 79145] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ewHDvNPGtvLGb7O0YZQAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:32.832847 2026] [security2:error] [pid 85094:tid 85270] [client 158.173.89.95:62729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ewK_nUl59BcEkkgFwkwAAATc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:12:32.936472 2026] [security2:error] [pid 78969:tid 79205] [client 194.61.41.94:52775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/install.php"] [unique_id "al4ewHDvNPGtvLGb7O0YeQAAAO8"]
[Mon Jul 20 07:12:32.991549 2026] [security2:error] [pid 85094:tid 85343] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4ewK_nUl59BcEkkgFwlgAAAX8"]
[Mon Jul 20 07:12:32.991696 2026] [security2:error] [pid 85094:tid 85343] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4ewK_nUl59BcEkkgFwlgAAAX8"]
[Mon Jul 20 07:12:33.090475 2026] [security2:error] [pid 85094:tid 85318] [client 14.225.17.146:53018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4ev6_nUl59BcEkkgFwUwAAAWY"], referer: http://slutilities.com/2017
[Mon Jul 20 07:12:33.230732 2026] [security2:error] [pid 78969:tid 79191] [client 148.255.40.157:64072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/xmlrpc.php"] [unique_id "al4ewXDvNPGtvLGb7O0YigAAAOE"]
[Mon Jul 20 07:12:33.230872 2026] [security2:error] [pid 78969:tid 79191] [client 148.255.40.157:64072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/xmlrpc.php"] [unique_id "al4ewXDvNPGtvLGb7O0YigAAAOE"]
[Mon Jul 20 07:12:33.351902 2026] [security2:error] [pid 85094:tid 85277] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4ewa_nUl59BcEkkgFwqQAAAT4"]
[Mon Jul 20 07:12:33.531899 2026] [security2:error] [pid 85094:tid 85261] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ewa_nUl59BcEkkgFwvwAAAS4"]
[Mon Jul 20 07:12:33.669005 2026] [security2:error] [pid 85094:tid 85242] [client 54.169.146.187:23964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ewa_nUl59BcEkkgFwygAAARs"]
[Mon Jul 20 07:12:33.669125 2026] [security2:error] [pid 85094:tid 85242] [client 54.169.146.187:23964] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ewa_nUl59BcEkkgFwygAAARs"]
[Mon Jul 20 07:12:33.718774 2026] [security2:error] [pid 85094:tid 85321] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4ewa_nUl59BcEkkgFw0gAAAWk"]
[Mon Jul 20 07:12:33.726919 2026] [security2:error] [pid 85094:tid 85241] [client 194.61.41.74:24653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sitemaps/providers/doc.php"] [unique_id "al4ewa_nUl59BcEkkgFw0wAAARo"]
[Mon Jul 20 07:12:33.743649 2026] [security2:error] [pid 85094:tid 85262] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ewa_nUl59BcEkkgFwvgAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:33.874320 2026] [security2:error] [pid 85094:tid 85326] [client 114.119.132.202:25309] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jenfarley.com"] [uri "/guinness-cooper/"] [unique_id "al4ewa_nUl59BcEkkgFw3AAAAW4"], referer: https://jenfarley.com/lets-keep-reading-childrens-books-ireland-campaign/
[Mon Jul 20 07:12:33.898666 2026] [security2:error] [pid 85094:tid 85234] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ewa_nUl59BcEkkgFw3QAAARM"]
[Mon Jul 20 07:12:34.097769 2026] [security2:error] [pid 85094:tid 85317] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4ewq_nUl59BcEkkgFw6AAAAWU"]
[Mon Jul 20 07:12:34.180197 2026] [security2:error] [pid 85094:tid 85300] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ewa_nUl59BcEkkgFw5gAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:34.233189 2026] [security2:error] [pid 85094:tid 85277] [client 14.225.17.146:62777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4ewq_nUl59BcEkkgFw7gAAAT4"], referer: http://dasmarque.com/2017
[Mon Jul 20 07:12:34.323724 2026] [security2:error] [pid 85094:tid 85342] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ewq_nUl59BcEkkgFw8wAAAX4"]
[Mon Jul 20 07:12:34.349650 2026] [security2:error] [pid 85094:tid 85294] [client 77.110.127.138:49516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/js/dist/wp-seo-local-frontend-1390.js"] [unique_id "al4ewq_nUl59BcEkkgFw9AAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:34.427981 2026] [security2:error] [pid 78969:tid 79046] [remote 188.166.241.141:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ewnDvNPGtvLGb7O0YuQAAnUw"]
[Mon Jul 20 07:12:34.515354 2026] [security2:error] [pid 78969:tid 79122] [client 194.61.41.64:48595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ws.php"] [unique_id "al4ewnDvNPGtvLGb7O0YvQAAAJw"]
[Mon Jul 20 07:12:34.537584 2026] [security2:error] [pid 85094:tid 85250] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4ewq_nUl59BcEkkgFw_wAAASM"]
[Mon Jul 20 07:12:34.537687 2026] [security2:error] [pid 85094:tid 85250] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4ewq_nUl59BcEkkgFw_wAAASM"]
[Mon Jul 20 07:12:34.824464 2026] [security2:error] [pid 85094:tid 85352] [client 14.225.17.146:58068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4ewa_nUl59BcEkkgFwnAAAAYg"], referer: http://aandarealtygroup.com/2017
[Mon Jul 20 07:12:34.832566 2026] [security2:error] [pid 78969:tid 79094] [remote 188.166.241.141:34924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ewnDvNPGtvLGb7O0YxwAAkHw"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:12:34.910905 2026] [security2:error] [pid 85094:tid 85277] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/gettest.php"] [unique_id "al4ewq_nUl59BcEkkgFxHwAAAT4"]
[Mon Jul 20 07:12:34.911015 2026] [security2:error] [pid 85094:tid 85277] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/gettest.php"] [unique_id "al4ewq_nUl59BcEkkgFxHwAAAT4"]
[Mon Jul 20 07:12:34.948523 2026] [security2:error] [pid 85094:tid 85228] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ewq_nUl59BcEkkgFw_AAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:35.237868 2026] [security2:error] [pid 78969:tid 79186] [client 194.61.41.80:28903] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/wp-includes/rest-api/1.php"] [unique_id "al4ew3DvNPGtvLGb7O0Y3AAAANw"]
[Mon Jul 20 07:12:35.238011 2026] [security2:error] [pid 78969:tid 79186] [client 194.61.41.80:28903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/rest-api/1.php"] [unique_id "al4ew3DvNPGtvLGb7O0Y3AAAANw"]
[Mon Jul 20 07:12:35.397300 2026] [security2:error] [pid 85094:tid 85247] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4ew6_nUl59BcEkkgFxPAAAASA"]
[Mon Jul 20 07:12:35.407163 2026] [security2:error] [pid 78969:tid 79129] [client 57.141.18.27:58454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4evnDvNPGtvLGb7O0YEQAAowA"]
[Mon Jul 20 07:12:35.432288 2026] [autoindex:error] [pid 78969:tid 79213] [client 198.235.24.132:57756] AH01276: Cannot serve directory /home3/alpchxmy/public_html/noisepacks/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://noisepacks.noisepacks.com/
[Mon Jul 20 07:12:35.461719 2026] [security2:error] [pid 85094:tid 85328] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ew6_nUl59BcEkkgFxMgAAAXA"]
[Mon Jul 20 07:12:35.627671 2026] [security2:error] [pid 85094:tid 85271] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4ew6_nUl59BcEkkgFxRQAAATg"]
[Mon Jul 20 07:12:35.858358 2026] [security2:error] [pid 85094:tid 85279] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/simple.php"] [unique_id "al4ew6_nUl59BcEkkgFxXAAAAUA"]
[Mon Jul 20 07:12:35.858530 2026] [security2:error] [pid 85094:tid 85279] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/simple.php"] [unique_id "al4ew6_nUl59BcEkkgFxXAAAAUA"]
[Mon Jul 20 07:12:36.040568 2026] [security2:error] [pid 85094:tid 85267] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ew6_nUl59BcEkkgFxTQAAATQ"]
[Mon Jul 20 07:12:36.049171 2026] [security2:error] [pid 85094:tid 85111] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4exK_nUl59BcEkkgFxXwABWQ8"]
[Mon Jul 20 07:12:36.049309 2026] [security2:error] [pid 85094:tid 85305] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4exK_nUl59BcEkkgFxXwABWQ8"]
[Mon Jul 20 07:12:36.061721 2026] [security2:error] [pid 85094:tid 85341] [client 194.61.41.99:50601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/fonts/class_api.php"] [unique_id "al4exK_nUl59BcEkkgFxYAAAAX0"]
[Mon Jul 20 07:12:36.072579 2026] [security2:error] [pid 85094:tid 85326] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ew6_nUl59BcEkkgFxWgABbgQ"]
[Mon Jul 20 07:12:36.100724 2026] [security2:error] [pid 85094:tid 85326] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ew6_nUl59BcEkkgFxWwABbmw"]
[Mon Jul 20 07:12:36.146569 2026] [security2:error] [pid 85094:tid 85262] [client 74.7.227.179:58378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4exK_nUl59BcEkkgFxXQABLw0"], referer: https://tejasenvironmental.com/p=451621
[Mon Jul 20 07:12:36.178143 2026] [autoindex:error] [pid 85094:tid 85283] [client 87.236.176.102:40207] AH01276: Cannot serve directory /home2/dsyjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:12:36.214067 2026] [security2:error] [pid 85094:tid 85238] [client 57.141.18.71:32686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ev6_nUl59BcEkkgFwYQABF1Y"]
[Mon Jul 20 07:12:36.250623 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:49393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4exK_nUl59BcEkkgFxZAAAAVU"], referer: https://mezzacraft.com/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/
[Mon Jul 20 07:12:36.250746 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:49393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4exK_nUl59BcEkkgFxZAAAAVU"], referer: https://mezzacraft.com/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/
[Mon Jul 20 07:12:36.261339 2026] [security2:error] [pid 78969:tid 79017] [remote 173.249.4.11:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4exHDvNPGtvLGb7O0ZCwAAjS8"]
[Mon Jul 20 07:12:36.264918 2026] [security2:error] [pid 78969:tid 79125] [client 77.110.127.138:49425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4exHDvNPGtvLGb7O0ZBAAAAJ8"], referer: https://mezzacraft.com/category/student-resource/
[Mon Jul 20 07:12:36.264917 2026] [security2:error] [pid 85094:tid 85334] [client 77.110.127.138:49516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4exK_nUl59BcEkkgFxZQAAAXY"], referer: https://mezzacraft.com/category/student-resource/
[Mon Jul 20 07:12:36.265435 2026] [security2:error] [pid 78969:tid 79155] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xxx.php"] [unique_id "al4exHDvNPGtvLGb7O0ZDAAAAL0"]
[Mon Jul 20 07:12:36.265502 2026] [security2:error] [pid 78969:tid 79155] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/xxx.php"] [unique_id "al4exHDvNPGtvLGb7O0ZDAAAAL0"]
[Mon Jul 20 07:12:36.305865 2026] [security2:error] [pid 85094:tid 85118] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4exK_nUl59BcEkkgFxawABTRY"]
[Mon Jul 20 07:12:36.306004 2026] [security2:error] [pid 85094:tid 85293] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4exK_nUl59BcEkkgFxawABTRY"]
[Mon Jul 20 07:12:36.344201 2026] [autoindex:error] [pid 78969:tid 79128] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/uploads/
[Mon Jul 20 07:12:36.449354 2026] [security2:error] [pid 85094:tid 85321] [client 187.198.212.64:57158] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4exK_nUl59BcEkkgFxegAAAWk"]
[Mon Jul 20 07:12:36.453375 2026] [security2:error] [pid 78969:tid 79036] [remote 173.249.4.11:52256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4exHDvNPGtvLGb7O0ZFwAA7EI"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 07:12:36.465999 2026] [security2:error] [pid 85094:tid 85330] [client 103.144.65.217:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4exK_nUl59BcEkkgFxewAAAXI"]
[Mon Jul 20 07:12:36.466100 2026] [security2:error] [pid 85094:tid 85330] [client 103.144.65.217:54278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4exK_nUl59BcEkkgFxewAAAXI"]
[Mon Jul 20 07:12:36.512141 2026] [security2:error] [pid 85094:tid 85134] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-json"] [unique_id "al4exK_nUl59BcEkkgFxhgABhyY"]
[Mon Jul 20 07:12:36.512249 2026] [security2:error] [pid 85094:tid 85351] [client 34.107.127.176:35446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/wp-json"] [unique_id "al4exK_nUl59BcEkkgFxhgABhyY"]
[Mon Jul 20 07:12:36.578157 2026] [security2:error] [pid 85094:tid 85321] [client 187.198.212.64:57158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4exK_nUl59BcEkkgFxegAAAWk"]
[Mon Jul 20 07:12:36.613576 2026] [security2:error] [pid 85094:tid 85264] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4exK_nUl59BcEkkgFxeQAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:36.645465 2026] [security2:error] [pid 78969:tid 79213] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/hypo.php"] [unique_id "al4exHDvNPGtvLGb7O0ZIgAAAPc"]
[Mon Jul 20 07:12:36.645544 2026] [security2:error] [pid 78969:tid 79213] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/hypo.php"] [unique_id "al4exHDvNPGtvLGb7O0ZIgAAAPc"]
[Mon Jul 20 07:12:36.728720 2026] [security2:error] [pid 85094:tid 85351] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exK_nUl59BcEkkgFxggABhxc"]
[Mon Jul 20 07:12:36.741512 2026] [security2:error] [pid 85094:tid 85277] [client 74.208.214.194:33900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4exK_nUl59BcEkkgFxnwAAAT4"]
[Mon Jul 20 07:12:36.742567 2026] [security2:error] [pid 85094:tid 85351] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exK_nUl59BcEkkgFxhAABhyQ"]
[Mon Jul 20 07:12:36.834099 2026] [security2:error] [pid 78969:tid 79164] [client 194.61.41.243:39197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/shop.php"] [unique_id "al4exHDvNPGtvLGb7O0ZKAAAAMY"]
[Mon Jul 20 07:12:36.987173 2026] [security2:error] [pid 78969:tid 79133] [client 187.16.64.216:52819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4exHDvNPGtvLGb7O0ZNgAAAKc"]
[Mon Jul 20 07:12:36.987357 2026] [security2:error] [pid 78969:tid 79133] [client 187.16.64.216:52819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4exHDvNPGtvLGb7O0ZNgAAAKc"]
[Mon Jul 20 07:12:37.025163 2026] [security2:error] [pid 78969:tid 79193] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4exXDvNPGtvLGb7O0ZOQAAAOM"]
[Mon Jul 20 07:12:37.118222 2026] [security2:error] [pid 85094:tid 85144] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/terraform.tfstate"] [unique_id "al4exa_nUl59BcEkkgFxsQABIzA"]
[Mon Jul 20 07:12:37.119194 2026] [authz_core:error] [pid 85094:tid 85147] [remote 34.107.127.176:35446] AH01630: client denied by server configuration: /home3/exycgcmy/public_html/mtredistricting/.htpasswd
[Mon Jul 20 07:12:37.181450 2026] [security2:error] [pid 78969:tid 79206] [client 88.241.67.160:54914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4exXDvNPGtvLGb7O0ZQgAAAPA"]
[Mon Jul 20 07:12:37.181565 2026] [security2:error] [pid 78969:tid 79206] [client 88.241.67.160:54914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4exXDvNPGtvLGb7O0ZQgAAAPA"]
[Mon Jul 20 07:12:37.346613 2026] [security2:error] [pid 85094:tid 85250] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exa_nUl59BcEkkgFxsAABIxg"]
[Mon Jul 20 07:12:37.396767 2026] [security2:error] [pid 78969:tid 79111] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4exXDvNPGtvLGb7O0ZSQAAAJE"]
[Mon Jul 20 07:12:37.557897 2026] [security2:error] [pid 78969:tid 79215] [client 194.61.41.62:49053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd-1/dedi1.php"] [unique_id "al4exXDvNPGtvLGb7O0ZTgAAAPk"]
[Mon Jul 20 07:12:37.561008 2026] [security2:error] [pid 85094:tid 85155] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_rsa"] [unique_id "al4exa_nUl59BcEkkgFx0QABeDs"]
[Mon Jul 20 07:12:37.564552 2026] [security2:error] [pid 85094:tid 85157] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/docker-compose.yaml"] [unique_id "al4exa_nUl59BcEkkgFx0gABZj0"]
[Mon Jul 20 07:12:37.564702 2026] [security2:error] [pid 85094:tid 85318] [client 34.107.127.176:35446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/docker-compose.yaml"] [unique_id "al4exa_nUl59BcEkkgFx0gABZj0"]
[Mon Jul 20 07:12:37.577840 2026] [security2:error] [pid 78969:tid 79192] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/chosen.php"] [unique_id "al4exXDvNPGtvLGb7O0ZTwAAAOI"]
[Mon Jul 20 07:12:37.577935 2026] [security2:error] [pid 78969:tid 79192] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/chosen.php"] [unique_id "al4exXDvNPGtvLGb7O0ZTwAAAOI"]
[Mon Jul 20 07:12:37.596801 2026] [security2:error] [pid 78969:tid 79223] [client 77.110.127.138:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/4/hpg8ilv10q0t.php"] [unique_id "al4exXDvNPGtvLGb7O0ZUAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:37.609098 2026] [security2:error] [pid 78969:tid 79189] [client 77.110.127.138:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4exXDvNPGtvLGb7O0ZUgAAAN8"], referer: https://mezzacraft.com/amigurumi-crochet-course-surrey/
[Mon Jul 20 07:12:37.609210 2026] [security2:error] [pid 78969:tid 79189] [client 77.110.127.138:49595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4exXDvNPGtvLGb7O0ZUgAAAN8"], referer: https://mezzacraft.com/amigurumi-crochet-course-surrey/
[Mon Jul 20 07:12:37.618899 2026] [security2:error] [pid 85094:tid 85263] [client 187.198.212.64:57352] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4exa_nUl59BcEkkgFx3wAAATA"]
[Mon Jul 20 07:12:37.676483 2026] [security2:error] [pid 85094:tid 85171] [remote 103.187.169.251:44294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4exa_nUl59BcEkkgFx4wABFUs"]
[Mon Jul 20 07:12:37.692476 2026] [security2:error] [pid 85094:tid 85160] [remote 124.55.178.99:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4exa_nUl59BcEkkgFx5QABIEA"]
[Mon Jul 20 07:12:37.755384 2026] [security2:error] [pid 85094:tid 85263] [client 187.198.212.64:57352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4exa_nUl59BcEkkgFx3wAAATA"]
[Mon Jul 20 07:12:37.758236 2026] [security2:error] [pid 85094:tid 85229] [client 74.208.214.194:33906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4exa_nUl59BcEkkgFx5gAAAQ4"]
[Mon Jul 20 07:12:37.845638 2026] [security2:error] [pid 85094:tid 85309] [client 201.27.111.74:55007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4exa_nUl59BcEkkgFx_wAAAV0"]
[Mon Jul 20 07:12:37.845762 2026] [security2:error] [pid 85094:tid 85309] [client 201.27.111.74:55007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4exa_nUl59BcEkkgFx_wAAAV0"]
[Mon Jul 20 07:12:37.876412 2026] [security2:error] [pid 85094:tid 85261] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exa_nUl59BcEkkgFx4QABLkg"]
[Mon Jul 20 07:12:37.893362 2026] [security2:error] [pid 85094:tid 85261] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exa_nUl59BcEkkgFx4AABLiI"]
[Mon Jul 20 07:12:37.978727 2026] [security2:error] [pid 85094:tid 85183] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.ssh/config"] [unique_id "al4exa_nUl59BcEkkgFyAgABRlc"]
[Mon Jul 20 07:12:37.984524 2026] [security2:error] [pid 85094:tid 85187] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/id_ecdsa"] [unique_id "al4exa_nUl59BcEkkgFyAwABiFs"]
[Mon Jul 20 07:12:38.001350 2026] [security2:error] [pid 85094:tid 85350] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4exa_nUl59BcEkkgFyBQAAAYY"]
[Mon Jul 20 07:12:38.147237 2026] [security2:error] [pid 85094:tid 85190] [remote 103.187.169.251:44294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4exq_nUl59BcEkkgFyCgABhF4"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:12:38.150872 2026] [security2:error] [pid 85094:tid 85185] [remote 124.55.178.99:46158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4exq_nUl59BcEkkgFyCwABQlk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:12:38.197484 2026] [security2:error] [pid 85094:tid 85290] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4exq_nUl59BcEkkgFyDgAAAUo"]
[Mon Jul 20 07:12:38.224088 2026] [security2:error] [pid 85094:tid 85188] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.ssh/id_dsa"] [unique_id "al4exq_nUl59BcEkkgFyFgABiFw"]
[Mon Jul 20 07:12:38.235508 2026] [security2:error] [pid 78969:tid 79221] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4exXDvNPGtvLGb7O0ZZQAA_z0"], referer: http://ali-alghanim.net/2017
[Mon Jul 20 07:12:38.237286 2026] [security2:error] [pid 85094:tid 85352] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exa_nUl59BcEkkgFyBAABiFE"]
[Mon Jul 20 07:12:38.292869 2026] [security2:error] [pid 85094:tid 85342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4exa_nUl59BcEkkgFx-wAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:38.345697 2026] [security2:error] [pid 85094:tid 85263] [client 194.61.41.242:47787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/setting.php"] [unique_id "al4exq_nUl59BcEkkgFyJwAAATA"]
[Mon Jul 20 07:12:38.370115 2026] [security2:error] [pid 85094:tid 85230] [client 14.225.17.146:56408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4exa_nUl59BcEkkgFx9gAAAQ8"], referer: http://onewingpictures.com/2017
[Mon Jul 20 07:12:38.415108 2026] [security2:error] [pid 85094:tid 85198] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/key.pem"] [unique_id "al4exq_nUl59BcEkkgFyKwABiGY"]
[Mon Jul 20 07:12:38.415522 2026] [security2:error] [pid 85094:tid 85195] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/privatekey.key"] [unique_id "al4exq_nUl59BcEkkgFyLAABiGM"]
[Mon Jul 20 07:12:38.430091 2026] [security2:error] [pid 85094:tid 85352] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyEQABiH8"]
[Mon Jul 20 07:12:38.441452 2026] [security2:error] [pid 85094:tid 85352] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyEAABiDg"]
[Mon Jul 20 07:12:38.482983 2026] [security2:error] [pid 78969:tid 79212] [client 117.211.236.168:59667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4exnDvNPGtvLGb7O0ZdQAAAPY"]
[Mon Jul 20 07:12:38.483090 2026] [security2:error] [pid 78969:tid 79212] [client 117.211.236.168:59667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4exnDvNPGtvLGb7O0ZdQAAAPY"]
[Mon Jul 20 07:12:38.484497 2026] [security2:error] [pid 85094:tid 85352] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyFQABiGQ"]
[Mon Jul 20 07:12:38.621552 2026] [security2:error] [pid 78969:tid 79129] [client 77.110.127.138:49629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4exnDvNPGtvLGb7O0ZaQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:38.660284 2026] [security2:error] [pid 85094:tid 85352] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyKQABiGA"]
[Mon Jul 20 07:12:38.673886 2026] [security2:error] [pid 85094:tid 85352] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyKgABiE0"]
[Mon Jul 20 07:12:38.685202 2026] [security2:error] [pid 85094:tid 85237] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/als.php"] [unique_id "al4exq_nUl59BcEkkgFyQwAAARY"]
[Mon Jul 20 07:12:38.685280 2026] [security2:error] [pid 85094:tid 85237] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/als.php"] [unique_id "al4exq_nUl59BcEkkgFyQwAAARY"]
[Mon Jul 20 07:12:38.791490 2026] [security2:error] [pid 85094:tid 85216] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.ssh/known_hosts"] [unique_id "al4exq_nUl59BcEkkgFySAABNXg"]
[Mon Jul 20 07:12:38.793718 2026] [security2:error] [pid 85094:tid 85208] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/id_rsa"] [unique_id "al4exq_nUl59BcEkkgFyRwABNXA"]
[Mon Jul 20 07:12:38.837161 2026] [security2:error] [pid 78969:tid 79120] [client 187.198.212.64:57484] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4exnDvNPGtvLGb7O0ZggAAAJo"]
[Mon Jul 20 07:12:38.967603 2026] [security2:error] [pid 78969:tid 79120] [client 187.198.212.64:57484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4exnDvNPGtvLGb7O0ZggAAAJo"]
[Mon Jul 20 07:12:39.087582 2026] [security2:error] [pid 78969:tid 79192] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/pol.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZkAAAAOI"]
[Mon Jul 20 07:12:39.087682 2026] [security2:error] [pid 78969:tid 79192] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/pol.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZkAAAAOI"]
[Mon Jul 20 07:12:39.111577 2026] [security2:error] [pid 78969:tid 79208] [client 176.31.139.0:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "guau-pet-rrimos.com"] [uri "/robots.txt"] [unique_id "al4ex3DvNPGtvLGb7O0ZkQAAAPI"]
[Mon Jul 20 07:12:39.111672 2026] [security2:error] [pid 78969:tid 79208] [client 176.31.139.0:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guau-pet-rrimos.com"] [uri "/robots.txt"] [unique_id "al4ex3DvNPGtvLGb7O0ZkQAAAPI"]
[Mon Jul 20 07:12:39.136354 2026] [security2:error] [pid 78969:tid 79224] [client 194.61.41.58:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/smilies/admin.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZkgAAAQI"]
[Mon Jul 20 07:12:39.150641 2026] [security2:error] [pid 85094:tid 85247] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyUgABIHc"]
[Mon Jul 20 07:12:39.185619 2026] [security2:error] [pid 85094:tid 85212] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.hermes/.env"] [unique_id "al4ex6_nUl59BcEkkgFyVwABC3Q"]
[Mon Jul 20 07:12:39.195597 2026] [security2:error] [pid 85094:tid 85311] [client 135.181.166.38:21128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.166.181.135.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyWgAAAV8"]
[Mon Jul 20 07:12:39.209831 2026] [security2:error] [pid 85094:tid 85217] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/id_dsa"] [unique_id "al4ex6_nUl59BcEkkgFyXAABC3k"]
[Mon Jul 20 07:12:39.269300 2026] [security2:error] [pid 85094:tid 85214] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/graphql"] [unique_id "al4ex6_nUl59BcEkkgFyXQABC3Y"]
[Mon Jul 20 07:12:39.274205 2026] [security2:error] [pid 85094:tid 85221] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.openclaw/.env"] [unique_id "al4ex6_nUl59BcEkkgFyYAABC30"]
[Mon Jul 20 07:12:39.274316 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.openclaw/.env"] [unique_id "al4ex6_nUl59BcEkkgFyYAABC30"]
[Mon Jul 20 07:12:39.394689 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyVgABC20"]
[Mon Jul 20 07:12:39.403891 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyWAABCwA"]
[Mon Jul 20 07:12:39.474533 2026] [security2:error] [pid 78969:tid 79199] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file5.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZngAAAOk"]
[Mon Jul 20 07:12:39.474705 2026] [security2:error] [pid 78969:tid 79199] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file5.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZngAAAOk"]
[Mon Jul 20 07:12:39.478608 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyYgABC3o"]
[Mon Jul 20 07:12:39.481078 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyYwABC2c"]
[Mon Jul 20 07:12:39.497120 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyXgABCwE"]
[Mon Jul 20 07:12:39.571307 2026] [security2:error] [pid 85094:tid 85219] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/api/graphql"] [unique_id "al4ex6_nUl59BcEkkgFyawABbHs"]
[Mon Jul 20 07:12:39.571411 2026] [security2:error] [pid 85094:tid 85349] [client 57.141.18.60:24412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ew6_nUl59BcEkkgFxOgABhQM"]
[Mon Jul 20 07:12:39.617634 2026] [security2:error] [pid 78969:tid 79056] [remote 47.86.33.52:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZpwAAvVY"]
[Mon Jul 20 07:12:39.751836 2026] [security2:error] [pid 85094:tid 85241] [client 14.225.17.146:62558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4exq_nUl59BcEkkgFyBgAAARo"], referer: http://ironcitywellness.com/2017
[Mon Jul 20 07:12:39.856630 2026] [security2:error] [pid 78969:tid 79135] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZswAAAKk"]
[Mon Jul 20 07:12:39.856738 2026] [security2:error] [pid 78969:tid 79135] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/4PJcpMFsD8B.php"] [unique_id "al4ex3DvNPGtvLGb7O0ZswAAAKk"]
[Mon Jul 20 07:12:39.927075 2026] [security2:error] [pid 85094:tid 85348] [client 194.61.41.78:27251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/light/as.php"] [unique_id "al4ex6_nUl59BcEkkgFyhwAAAYQ"]
[Mon Jul 20 07:12:40.051421 2026] [security2:error] [pid 85094:tid 85257] [client 187.198.212.64:57686] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4eyK_nUl59BcEkkgFylAAAASo"]
[Mon Jul 20 07:12:40.136523 2026] [security2:error] [pid 85094:tid 85118] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mtredistricting.gov"] [uri "/wp-config.php.bak"] [unique_id "al4eyK_nUl59BcEkkgFynAABCxY"]
[Mon Jul 20 07:12:40.136564 2026] [security2:error] [pid 85094:tid 85121] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "mtredistricting.gov"] [uri "/wp-config.php.old"] [unique_id "al4eyK_nUl59BcEkkgFypgABCxk"]
[Mon Jul 20 07:12:40.136981 2026] [security2:error] [pid 85094:tid 85113] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "mtredistricting.gov"] [uri "/v1/graphql"] [unique_id "al4eyK_nUl59BcEkkgFyoAABCxE"]
[Mon Jul 20 07:12:40.166809 2026] [security2:error] [pid 78969:tid 79048] [remote 47.86.33.52:4556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4eyHDvNPGtvLGb7O0ZuwAAo04"], referer: https://sbinframx.com/wp-login.php
[Mon Jul 20 07:12:40.197186 2026] [security2:error] [pid 85094:tid 85257] [client 187.198.212.64:57686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4eyK_nUl59BcEkkgFylAAAASo"]
[Mon Jul 20 07:12:40.219769 2026] [security2:error] [pid 78969:tid 79046] [remote 38.242.157.30:39950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eyHDvNPGtvLGb7O0ZvwAAh0w"]
[Mon Jul 20 07:12:40.351222 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFyoQABC1A"]
[Mon Jul 20 07:12:40.351707 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFyngABC10"]
[Mon Jul 20 07:12:40.362786 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFynwABCws"]
[Mon Jul 20 07:12:40.365875 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFyogABC3E"]
[Mon Jul 20 07:12:40.377191 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFynQABCxM"]
[Mon Jul 20 07:12:40.405900 2026] [security2:error] [pid 85094:tid 85268] [client 15.235.98.192:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "guau-pet-rrimos.com"] [uri "/"] [unique_id "al4eyK_nUl59BcEkkgFysQAAATU"]
[Mon Jul 20 07:12:40.406016 2026] [security2:error] [pid 85094:tid 85268] [client 15.235.98.192:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guau-pet-rrimos.com"] [uri "/"] [unique_id "al4eyK_nUl59BcEkkgFysQAAATU"]
[Mon Jul 20 07:12:40.411846 2026] [security2:error] [pid 85094:tid 85226] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFymgABCwc"]
[Mon Jul 20 07:12:40.419553 2026] [security2:error] [pid 78969:tid 78972] [remote 38.242.157.30:39950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4eyHDvNPGtvLGb7O0ZywAA1gI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:12:40.505257 2026] [security2:error] [pid 85094:tid 85320] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file.php"] [unique_id "al4eyK_nUl59BcEkkgFytwAAAWg"]
[Mon Jul 20 07:12:40.505362 2026] [security2:error] [pid 85094:tid 85320] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file.php"] [unique_id "al4eyK_nUl59BcEkkgFytwAAAWg"]
[Mon Jul 20 07:12:40.643621 2026] [security2:error] [pid 85094:tid 85230] [client 194.61.41.243:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/user/header.php"] [unique_id "al4eyK_nUl59BcEkkgFyuwAAAQ8"]
[Mon Jul 20 07:12:40.676518 2026] [security2:error] [pid 85094:tid 85284] [client 14.225.17.146:62722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4eyK_nUl59BcEkkgFytAAAAUQ"], referer: http://laceycaraccident.com/2017
[Mon Jul 20 07:12:40.881597 2026] [security2:error] [pid 78969:tid 79181] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/cfile.php"] [unique_id "al4eyHDvNPGtvLGb7O0Z2gAAANc"]
[Mon Jul 20 07:12:40.881740 2026] [security2:error] [pid 78969:tid 79181] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/cfile.php"] [unique_id "al4eyHDvNPGtvLGb7O0Z2gAAANc"]
[Mon Jul 20 07:12:41.224413 2026] [security2:error] [pid 78969:tid 79217] [client 157.20.138.62:62187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4eyXDvNPGtvLGb7O0Z6AAAAPs"]
[Mon Jul 20 07:12:41.224538 2026] [security2:error] [pid 78969:tid 79217] [client 157.20.138.62:62187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4eyXDvNPGtvLGb7O0Z6AAAAPs"]
[Mon Jul 20 07:12:41.256310 2026] [security2:error] [pid 78969:tid 79186] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/class-wp.php"] [unique_id "al4eyXDvNPGtvLGb7O0Z6gAAANw"]
[Mon Jul 20 07:12:41.256404 2026] [security2:error] [pid 78969:tid 79186] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/class-wp.php"] [unique_id "al4eyXDvNPGtvLGb7O0Z6gAAANw"]
[Mon Jul 20 07:12:41.315781 2026] [security2:error] [pid 85094:tid 85279] [client 57.141.18.57:59608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4exK_nUl59BcEkkgFxpAABQDE"]
[Mon Jul 20 07:12:41.393684 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eyXDvNPGtvLGb7O0Z8QAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:41.393849 2026] [security2:error] [pid 78969:tid 79162] [client 77.110.127.138:49629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4eyXDvNPGtvLGb7O0Z8QAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:41.425439 2026] [security2:error] [pid 85094:tid 85344] [client 194.61.41.67:29733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/about.php"] [unique_id "al4eya_nUl59BcEkkgFy7QAAAYA"]
[Mon Jul 20 07:12:41.653196 2026] [security2:error] [pid 85094:tid 85286] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/admin.php"] [unique_id "al4eya_nUl59BcEkkgFzBwAAAUY"]
[Mon Jul 20 07:12:41.653299 2026] [security2:error] [pid 85094:tid 85286] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/admin.php"] [unique_id "al4eya_nUl59BcEkkgFzBwAAAUY"]
[Mon Jul 20 07:12:41.772289 2026] [security2:error] [pid 85094:tid 85287] [client 57.141.18.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eya_nUl59BcEkkgFzBQAAAUc"]
[Mon Jul 20 07:12:41.808916 2026] [security2:error] [pid 78969:tid 79103] [client 14.225.17.146:64703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4eyHDvNPGtvLGb7O0Z0AAAAIk"], referer: http://effingweirdmuseums.com/2017
[Mon Jul 20 07:12:41.918746 2026] [security2:error] [pid 85094:tid 85151] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/laravel/.env"] [unique_id "al4eya_nUl59BcEkkgFzFQABNTc"]
[Mon Jul 20 07:12:41.953704 2026] [security2:error] [pid 85094:tid 85155] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/web/.env"] [unique_id "al4eya_nUl59BcEkkgFzGQABdzs"]
[Mon Jul 20 07:12:41.955677 2026] [security2:error] [pid 85094:tid 85154] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/core/.env"] [unique_id "al4eya_nUl59BcEkkgFzHAABaTo"]
[Mon Jul 20 07:12:41.955827 2026] [security2:error] [pid 85094:tid 85163] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.swp"] [unique_id "al4eya_nUl59BcEkkgFzHgABaUM"]
[Mon Jul 20 07:12:41.957252 2026] [security2:error] [pid 85094:tid 85149] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/public/.env"] [unique_id "al4eya_nUl59BcEkkgFzHwABaTU"]
[Mon Jul 20 07:12:41.965229 2026] [security2:error] [pid 85094:tid 85170] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/.env.php.bak"] [unique_id "al4eya_nUl59BcEkkgFzHQABaUo"]
[Mon Jul 20 07:12:42.041557 2026] [security2:error] [pid 78969:tid 79205] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/aa2.php"] [unique_id "al4eynDvNPGtvLGb7O0aCQAAAO8"]
[Mon Jul 20 07:12:42.041681 2026] [security2:error] [pid 78969:tid 79205] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/aa2.php"] [unique_id "al4eynDvNPGtvLGb7O0aCQAAAO8"]
[Mon Jul 20 07:12:42.151995 2026] [security2:error] [pid 85094:tid 85249] [client 194.61.41.252:62077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-api.php"] [unique_id "al4eyq_nUl59BcEkkgFzJAAAASI"]
[Mon Jul 20 07:12:42.160462 2026] [security2:error] [pid 85094:tid 85321] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eya_nUl59BcEkkgFzGwABaTY"]
[Mon Jul 20 07:12:42.376991 2026] [security2:error] [pid 85094:tid 85348] [client 187.198.212.64:58024] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4eyq_nUl59BcEkkgFzMwAAAYQ"]
[Mon Jul 20 07:12:42.518592 2026] [security2:error] [pid 85094:tid 85348] [client 187.198.212.64:58024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4eyq_nUl59BcEkkgFzMwAAAYQ"]
[Mon Jul 20 07:12:42.647958 2026] [security2:error] [pid 78969:tid 79184] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/ccou.php"] [unique_id "al4eynDvNPGtvLGb7O0aKQAAANo"]
[Mon Jul 20 07:12:42.648084 2026] [security2:error] [pid 78969:tid 79184] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/ccou.php"] [unique_id "al4eynDvNPGtvLGb7O0aKQAAANo"]
[Mon Jul 20 07:12:42.712849 2026] [security2:error] [pid 85094:tid 85241] [client 57.141.18.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4eyq_nUl59BcEkkgFzQQAAARo"]
[Mon Jul 20 07:12:42.713206 2026] [security2:error] [pid 78969:tid 79156] [client 98.95.56.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4eynDvNPGtvLGb7O0aHwAAvhQ"]
[Mon Jul 20 07:12:42.790308 2026] [security2:error] [pid 85094:tid 85142] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/config.js"] [unique_id "al4eyq_nUl59BcEkkgFzWgABOy4"]
[Mon Jul 20 07:12:42.884667 2026] [security2:error] [pid 78969:tid 79182] [client 14.225.17.146:56517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4eynDvNPGtvLGb7O0aKwAAANg"], referer: http://nextlvlmarketingco.com/2017
[Mon Jul 20 07:12:42.960104 2026] [security2:error] [pid 78969:tid 79213] [client 194.61.41.253:22019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/install.php"] [unique_id "al4eynDvNPGtvLGb7O0aOAAAAPc"]
[Mon Jul 20 07:12:43.014193 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:49785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ey3DvNPGtvLGb7O0aPAAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:43.014351 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:49785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ey3DvNPGtvLGb7O0aPAAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:43.033495 2026] [security2:error] [pid 78969:tid 79174] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/dr.php"] [unique_id "al4ey3DvNPGtvLGb7O0aPQAAANA"]
[Mon Jul 20 07:12:43.033687 2026] [security2:error] [pid 78969:tid 79174] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/dr.php"] [unique_id "al4ey3DvNPGtvLGb7O0aPQAAANA"]
[Mon Jul 20 07:12:43.063344 2026] [security2:error] [pid 85094:tid 85343] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyq_nUl59BcEkkgFzXgABfyI"]
[Mon Jul 20 07:12:43.116704 2026] [security2:error] [pid 85094:tid 85343] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyq_nUl59BcEkkgFzXQABf0g"]
[Mon Jul 20 07:12:43.168479 2026] [security2:error] [pid 85094:tid 85343] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4eyq_nUl59BcEkkgFzZgABf14"]
[Mon Jul 20 07:12:43.177638 2026] [security2:error] [pid 85094:tid 85195] [remote 124.55.178.99:36570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4ey6_nUl59BcEkkgFzhAABX2M"]
[Mon Jul 20 07:12:43.397522 2026] [security2:error] [pid 85094:tid 85201] [remote 91.142.222.105:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ey6_nUl59BcEkkgFzmQABC2k"]
[Mon Jul 20 07:12:43.401821 2026] [security2:error] [pid 85094:tid 85319] [client 14.225.17.146:53235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4eya_nUl59BcEkkgFzDgAAAWc"], referer: http://headachescarpaltunnelfibromyalgia.com/2017
[Mon Jul 20 07:12:43.475312 2026] [security2:error] [pid 85094:tid 85341] [client 14.225.17.146:53130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4eya_nUl59BcEkkgFzEgAAAX0"], referer: http://reosportsboats.com/2017
[Mon Jul 20 07:12:43.491681 2026] [security2:error] [pid 78969:tid 79133] [client 14.225.17.146:64728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4eynDvNPGtvLGb7O0aNwAAAKc"]
[Mon Jul 20 07:12:43.634407 2026] [security2:error] [pid 85094:tid 85344] [client 14.225.17.146:49648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4ey6_nUl59BcEkkgFzmwAAAYA"], referer: http://nextlevelpressurewashing.com/2017
[Mon Jul 20 07:12:43.634853 2026] [security2:error] [pid 85094:tid 85210] [remote 124.55.178.99:36570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4ey6_nUl59BcEkkgFzqwABX3I"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:12:43.640259 2026] [security2:error] [pid 85094:tid 85277] [client 102.41.172.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "icemarc.org"] [uri "/index.php"] [unique_id "al4eyq_nUl59BcEkkgFzOgAAAT4"]
[Mon Jul 20 07:12:43.666957 2026] [security2:error] [pid 85094:tid 85172] [remote 91.142.222.105:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ey6_nUl59BcEkkgFzrwABgUw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:12:43.705560 2026] [security2:error] [pid 85094:tid 85240] [client 66.249.93.224:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.lakelopezonline.com"] [uri "/index.php"] [unique_id "al4ey6_nUl59BcEkkgFzqgAAARk"]
[Mon Jul 20 07:12:43.707601 2026] [lsapi:warn] [pid 78969:tid 79004] [remote 196.251.121.187:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:12:43.728274 2026] [security2:error] [pid 85094:tid 85255] [client 14.225.17.146:62739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4eya_nUl59BcEkkgFzDwAAASg"], referer: http://longevityperformanceclinic.com/2017
[Mon Jul 20 07:12:43.761794 2026] [security2:error] [pid 85094:tid 85203] [remote 47.128.99.254:39298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/3330.pdf"] [unique_id "al4ey6_nUl59BcEkkgFztAABU2s"]
[Mon Jul 20 07:12:43.762344 2026] [security2:error] [pid 78969:tid 79169] [client 194.61.41.249:56109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css.php"] [unique_id "al4ey3DvNPGtvLGb7O0aWAAAAMs"]
[Mon Jul 20 07:12:43.781120 2026] [security2:error] [pid 85094:tid 85254] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xamp.php"] [unique_id "al4ey6_nUl59BcEkkgFztwAAASc"]
[Mon Jul 20 07:12:43.781240 2026] [security2:error] [pid 85094:tid 85254] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/xamp.php"] [unique_id "al4ey6_nUl59BcEkkgFztwAAASc"]
[Mon Jul 20 07:12:43.794317 2026] [security2:error] [pid 85094:tid 85184] [remote 57.141.18.0:21998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2896560"] [unique_id "al4ey6_nUl59BcEkkgFzuAABE1g"]
[Mon Jul 20 07:12:44.148220 2026] [security2:error] [pid 85094:tid 85245] [client 77.110.127.138:50006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ey6_nUl59BcEkkgFzvQAAAR4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:44.162884 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/bless.php"] [unique_id "al4ezHDvNPGtvLGb7O0aagAAAJM"]
[Mon Jul 20 07:12:44.162981 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/bless.php"] [unique_id "al4ezHDvNPGtvLGb7O0aagAAAJM"]
[Mon Jul 20 07:12:44.207169 2026] [security2:error] [pid 85094:tid 85329] [client 107.152.32.177:61407] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "107.152.32.177" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezK_nUl59BcEkkgFzzwAAAXE"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.207270 2026] [security2:error] [pid 85094:tid 85329] [client 107.152.32.177:61407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezK_nUl59BcEkkgFzzwAAAXE"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.241865 2026] [security2:error] [pid 85094:tid 85215] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/config/.env.php"] [unique_id "al4ezK_nUl59BcEkkgFz1AABGnc"]
[Mon Jul 20 07:12:44.241922 2026] [security2:error] [pid 85094:tid 85191] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/configuration.php.bak"] [unique_id "al4ezK_nUl59BcEkkgFz0gABGl8"]
[Mon Jul 20 07:12:44.241922 2026] [security2:error] [pid 85094:tid 85222] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/config.php.bak"] [unique_id "al4ezK_nUl59BcEkkgFz0QABGn4"]
[Mon Jul 20 07:12:44.264383 2026] [security2:error] [pid 85094:tid 85217] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/.well-known/jwks.json"] [unique_id "al4ezK_nUl59BcEkkgFz1wABGnk"]
[Mon Jul 20 07:12:44.264562 2026] [security2:error] [pid 85094:tid 85241] [client 34.107.127.176:35446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/.well-known/jwks.json"] [unique_id "al4ezK_nUl59BcEkkgFz1wABGnk"]
[Mon Jul 20 07:12:44.409318 2026] [security2:error] [pid 85094:tid 85352] [client 107.152.32.177:61439] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "107.152.32.177" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezK_nUl59BcEkkgFz5QAAAYg"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.409450 2026] [security2:error] [pid 85094:tid 85352] [client 107.152.32.177:61439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezK_nUl59BcEkkgFz5QAAAYg"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.491079 2026] [security2:error] [pid 85094:tid 85241] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgFz0wABGnM"]
[Mon Jul 20 07:12:44.523926 2026] [security2:error] [pid 85094:tid 85241] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgFz2QABGnY"]
[Mon Jul 20 07:12:44.526396 2026] [security2:error] [pid 85094:tid 85241] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgFz1gABGnQ"]
[Mon Jul 20 07:12:44.539125 2026] [security2:error] [pid 85094:tid 85299] [client 194.61.41.72:54759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/db.php"] [unique_id "al4ezK_nUl59BcEkkgFz5wAAAVM"]
[Mon Jul 20 07:12:44.544634 2026] [security2:error] [pid 85094:tid 85228] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file46.php"] [unique_id "al4ezK_nUl59BcEkkgFz6AAAAQ0"]
[Mon Jul 20 07:12:44.544731 2026] [security2:error] [pid 85094:tid 85228] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file46.php"] [unique_id "al4ezK_nUl59BcEkkgFz6AAAAQ0"]
[Mon Jul 20 07:12:44.547920 2026] [security2:error] [pid 85094:tid 85241] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgFz2wABGhQ"]
[Mon Jul 20 07:12:44.571549 2026] [security2:error] [pid 85094:tid 85241] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgFz3AABGnw"]
[Mon Jul 20 07:12:44.574880 2026] [security2:error] [pid 85094:tid 85315] [client 57.141.18.5:34284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ex6_nUl59BcEkkgFyggABYw8"]
[Mon Jul 20 07:12:44.610185 2026] [security2:error] [pid 78969:tid 79200] [client 107.152.32.177:61468] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "107.152.32.177" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezHDvNPGtvLGb7O0afwAAAOo"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.610312 2026] [security2:error] [pid 78969:tid 79200] [client 107.152.32.177:61468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezHDvNPGtvLGb7O0afwAAAOo"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.761661 2026] [security2:error] [pid 78969:tid 79112] [client 77.110.127.138:50011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ezHDvNPGtvLGb7O0aeAAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:44.842884 2026] [security2:error] [pid 85094:tid 85266] [client 107.152.32.177:61487] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "107.152.32.177" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezK_nUl59BcEkkgFz-AAAATM"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.842983 2026] [security2:error] [pid 85094:tid 85266] [client 107.152.32.177:61487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.secretkeynumerology.com"] [uri "/wp-comments-post.php"] [unique_id "al4ezK_nUl59BcEkkgFz-AAAATM"], referer: https://www.secretkeynumerology.com/about-this-blog/
[Mon Jul 20 07:12:44.914527 2026] [security2:error] [pid 85094:tid 85318] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/eee.php"] [unique_id "al4ezK_nUl59BcEkkgF0AAAAAWY"]
[Mon Jul 20 07:12:44.914617 2026] [security2:error] [pid 85094:tid 85318] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/eee.php"] [unique_id "al4ezK_nUl59BcEkkgF0AAAAAWY"]
[Mon Jul 20 07:12:45.129047 2026] [security2:error] [pid 78969:tid 79199] [client 14.225.17.146:57649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4ezHDvNPGtvLGb7O0adgAAAOk"], referer: http://idigress.group/2017
[Mon Jul 20 07:12:45.144816 2026] [security2:error] [pid 85094:tid 85319] [client 14.225.17.146:61558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgF0AgAAAWc"], referer: http://ivetstrategies.com/2017
[Mon Jul 20 07:12:45.224962 2026] [security2:error] [pid 85094:tid 85317] [client 138.197.143.74:55052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4ezK_nUl59BcEkkgFz1QAAAWU"]
[Mon Jul 20 07:12:45.251557 2026] [security2:error] [pid 78969:tid 79117] [client 77.110.127.138:50013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ezXDvNPGtvLGb7O0ajAAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:45.264884 2026] [security2:error] [pid 78969:tid 79108] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file25.php"] [unique_id "al4ezXDvNPGtvLGb7O0amwAAAI4"]
[Mon Jul 20 07:12:45.265007 2026] [security2:error] [pid 78969:tid 79108] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file25.php"] [unique_id "al4ezXDvNPGtvLGb7O0amwAAAI4"]
[Mon Jul 20 07:12:45.338623 2026] [security2:error] [pid 85094:tid 85278] [client 194.61.41.98:35851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-customize-manager-interpreter.php"] [unique_id "al4eza_nUl59BcEkkgF0FgAAAT8"]
[Mon Jul 20 07:12:45.610486 2026] [security2:error] [pid 85094:tid 85239] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file48.php"] [unique_id "al4eza_nUl59BcEkkgF0IgAAARg"]
[Mon Jul 20 07:12:45.610575 2026] [security2:error] [pid 85094:tid 85239] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file48.php"] [unique_id "al4eza_nUl59BcEkkgF0IgAAARg"]
[Mon Jul 20 07:12:45.645964 2026] [security2:error] [pid 85094:tid 85346] [client 77.110.127.138:49965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eza_nUl59BcEkkgF0GAAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:45.864565 2026] [security2:error] [pid 78969:tid 79137] [client 34.162.230.222:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4ezXDvNPGtvLGb7O0argAAAKs"]
[Mon Jul 20 07:12:45.991638 2026] [security2:error] [pid 85094:tid 85296] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file6.php"] [unique_id "al4eza_nUl59BcEkkgF0OgAAAVA"]
[Mon Jul 20 07:12:45.991721 2026] [security2:error] [pid 85094:tid 85296] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file6.php"] [unique_id "al4eza_nUl59BcEkkgF0OgAAAVA"]
[Mon Jul 20 07:12:46.001570 2026] [security2:error] [pid 85094:tid 85283] [client 104.234.53.78:31655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4eza_nUl59BcEkkgF0OAAAAUM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:46.041397 2026] [security2:error] [pid 78969:tid 79118] [client 77.110.127.138:49563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ezXDvNPGtvLGb7O0asAAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:46.138804 2026] [security2:error] [pid 78969:tid 79174] [client 194.61.41.243:63695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/bypass.php"] [unique_id "al4eznDvNPGtvLGb7O0awwAAANA"]
[Mon Jul 20 07:12:46.277586 2026] [security2:error] [pid 85094:tid 85293] [client 14.225.17.146:61517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0PwAAAU0"], referer: http://39ishlife.com/2017
[Mon Jul 20 07:12:46.314767 2026] [security2:error] [pid 78969:tid 79123] [client 77.110.127.138:49994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eznDvNPGtvLGb7O0avwAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:46.342429 2026] [security2:error] [pid 78969:tid 79107] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/a2.php"] [unique_id "al4eznDvNPGtvLGb7O0a2QAAAI0"]
[Mon Jul 20 07:12:46.342523 2026] [security2:error] [pid 78969:tid 79107] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/a2.php"] [unique_id "al4eznDvNPGtvLGb7O0a2QAAAI0"]
[Mon Jul 20 07:12:46.669597 2026] [security2:error] [pid 85094:tid 85100] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ezq_nUl59BcEkkgF0UAABRwQ"]
[Mon Jul 20 07:12:46.669792 2026] [security2:error] [pid 85094:tid 85287] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ezq_nUl59BcEkkgF0UAABRwQ"]
[Mon Jul 20 07:12:46.681879 2026] [security2:error] [pid 85094:tid 85234] [client 104.234.53.80:34139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0UQAAARM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:46.683108 2026] [security2:error] [pid 85094:tid 85275] [client 57.141.18.59:56728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eyq_nUl59BcEkkgFzKwABPEY"]
[Mon Jul 20 07:12:46.689017 2026] [security2:error] [pid 78969:tid 79102] [client 77.110.127.138:50023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4eznDvNPGtvLGb7O0a4QAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:46.696082 2026] [security2:error] [pid 78969:tid 79188] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/file15.php"] [unique_id "al4eznDvNPGtvLGb7O0a7gAAAN4"]
[Mon Jul 20 07:12:46.696175 2026] [security2:error] [pid 78969:tid 79188] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/file15.php"] [unique_id "al4eznDvNPGtvLGb7O0a7gAAAN4"]
[Mon Jul 20 07:12:46.788104 2026] [security2:error] [pid 85094:tid 85235] [client 14.225.17.146:61270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4eza_nUl59BcEkkgF0DwAAARQ"], referer: http://nurturemarple.co.uk/2017
[Mon Jul 20 07:12:46.847447 2026] [security2:error] [pid 78969:tid 79179] [client 45.166.182.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4eznDvNPGtvLGb7O0a5gAAANU"]
[Mon Jul 20 07:12:46.922464 2026] [security2:error] [pid 78969:tid 79097] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eznDvNPGtvLGb7O0a-QAA-X8"]
[Mon Jul 20 07:12:46.922635 2026] [security2:error] [pid 78969:tid 79215] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4eznDvNPGtvLGb7O0a-QAA-X8"]
[Mon Jul 20 07:12:46.934276 2026] [security2:error] [pid 85094:tid 85334] [client 194.61.41.63:54333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/fm.php7"] [unique_id "al4ezq_nUl59BcEkkgF0WgAAAXY"]
[Mon Jul 20 07:12:46.971032 2026] [security2:error] [pid 85094:tid 85209] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/service-worker.js"] [unique_id "al4ezq_nUl59BcEkkgF0YAABT3E"]
[Mon Jul 20 07:12:46.982468 2026] [security2:error] [pid 85094:tid 85122] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/__env.js"] [unique_id "al4ezq_nUl59BcEkkgF0ZAABTxo"]
[Mon Jul 20 07:12:46.982660 2026] [security2:error] [pid 85094:tid 85295] [client 34.107.127.176:35446] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mtredistricting.gov"] [uri "/__env.js"] [unique_id "al4ezq_nUl59BcEkkgF0ZAABTxo"]
[Mon Jul 20 07:12:47.019293 2026] [security2:error] [pid 85094:tid 85312] [client 103.144.65.217:54736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0aQAAAWA"]
[Mon Jul 20 07:12:47.019443 2026] [security2:error] [pid 85094:tid 85312] [client 103.144.65.217:54736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0aQAAAWA"]
[Mon Jul 20 07:12:47.057310 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/jp.php"] [unique_id "al4ez3DvNPGtvLGb7O0a_wAAAJM"]
[Mon Jul 20 07:12:47.057429 2026] [security2:error] [pid 78969:tid 79113] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/jp.php"] [unique_id "al4ez3DvNPGtvLGb7O0a_wAAAJM"]
[Mon Jul 20 07:12:47.114817 2026] [security2:error] [pid 85094:tid 85252] [client 77.110.127.138:49781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0VAAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:47.212364 2026] [security2:error] [pid 85094:tid 85295] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0XgABTws"]
[Mon Jul 20 07:12:47.213657 2026] [security2:error] [pid 85094:tid 85295] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0XAABTwY"]
[Mon Jul 20 07:12:47.213883 2026] [security2:error] [pid 85094:tid 85295] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0XwABT1Y"]
[Mon Jul 20 07:12:47.229963 2026] [security2:error] [pid 85094:tid 85295] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0ZgABTyo"]
[Mon Jul 20 07:12:47.238227 2026] [security2:error] [pid 85094:tid 85295] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ezq_nUl59BcEkkgF0ZQABTyY"]
[Mon Jul 20 07:12:47.238235 2026] [security2:error] [pid 78969:tid 79147] [client 187.198.212.64:58480] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4ez3DvNPGtvLGb7O0bBwAAALU"]
[Mon Jul 20 07:12:47.276014 2026] [security2:error] [pid 78969:tid 79177] [client 50.116.65.227:12228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4eznDvNPGtvLGb7O0a-AAAANM"]
[Mon Jul 20 07:12:47.376008 2026] [security2:error] [pid 78969:tid 79147] [client 187.198.212.64:58480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "sbinframx.com"] [uri "/wp-comments-post.php"] [unique_id "al4ez3DvNPGtvLGb7O0bBwAAALU"]
[Mon Jul 20 07:12:47.400233 2026] [security2:error] [pid 85094:tid 85319] [client 77.110.127.138:49347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0cAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:47.403666 2026] [security2:error] [pid 85094:tid 85299] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/f35.php"] [unique_id "al4ez6_nUl59BcEkkgF0iwAAAVM"]
[Mon Jul 20 07:12:47.403791 2026] [security2:error] [pid 85094:tid 85299] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/f35.php"] [unique_id "al4ez6_nUl59BcEkkgF0iwAAAVM"]
[Mon Jul 20 07:12:47.409351 2026] [security2:error] [pid 85094:tid 85301] [client 117.211.236.168:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0jAAAAVU"]
[Mon Jul 20 07:12:47.409488 2026] [security2:error] [pid 85094:tid 85301] [client 117.211.236.168:60175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0jAAAAVU"]
[Mon Jul 20 07:12:47.422641 2026] [security2:error] [pid 78969:tid 79201] [client 14.225.17.146:53075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4ez3DvNPGtvLGb7O0bDwAAAOs"]
[Mon Jul 20 07:12:47.459948 2026] [security2:error] [pid 85094:tid 85233] [client 14.225.17.146:60826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0hwAAARI"], referer: http://collectingrealestate.com/2017
[Mon Jul 20 07:12:47.477169 2026] [security2:error] [pid 85094:tid 85297] [client 50.116.65.227:12234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0dgAAAVE"]
[Mon Jul 20 07:12:47.587081 2026] [security2:error] [pid 85094:tid 85154] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/actuator/mappings"] [unique_id "al4ez6_nUl59BcEkkgF0nQABKjo"]
[Mon Jul 20 07:12:47.587085 2026] [security2:error] [pid 85094:tid 85143] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mtredistricting.gov"] [uri "/info.php"] [unique_id "al4ez6_nUl59BcEkkgF0lQABKi8"]
[Mon Jul 20 07:12:47.587378 2026] [security2:error] [pid 85094:tid 85120] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/test.php"] [unique_id "al4ez6_nUl59BcEkkgF0lgABKhg"]
[Mon Jul 20 07:12:47.587541 2026] [security2:error] [pid 85094:tid 85148] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/phpinfo.php"] [unique_id "al4ez6_nUl59BcEkkgF0mwABKjQ"]
[Mon Jul 20 07:12:47.587566 2026] [security2:error] [pid 85094:tid 85163] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.127.107.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/pi.php"] [unique_id "al4ez6_nUl59BcEkkgF0ngABKkM"]
[Mon Jul 20 07:12:47.733983 2026] [security2:error] [pid 85094:tid 85245] [client 194.61.41.87:47117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/count.php"] [unique_id "al4ez6_nUl59BcEkkgF0rQAAAR4"]
[Mon Jul 20 07:12:47.749129 2026] [security2:error] [pid 85094:tid 85349] [client 187.16.64.216:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0rwAAAYU"]
[Mon Jul 20 07:12:47.749249 2026] [security2:error] [pid 85094:tid 85349] [client 187.16.64.216:53408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0rwAAAYU"]
[Mon Jul 20 07:12:47.770176 2026] [security2:error] [pid 78969:tid 79212] [client 14.225.17.146:53070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4ez3DvNPGtvLGb7O0bIQAAAPY"], referer: https://nurturemarple.co.uk/2017
[Mon Jul 20 07:12:47.790548 2026] [security2:error] [pid 78969:tid 79150] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-load.php"] [unique_id "al4ez3DvNPGtvLGb7O0bKgAAALg"]
[Mon Jul 20 07:12:47.790668 2026] [security2:error] [pid 78969:tid 79150] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-load.php"] [unique_id "al4ez3DvNPGtvLGb7O0bKgAAALg"]
[Mon Jul 20 07:12:47.812073 2026] [security2:error] [pid 85094:tid 85266] [client 77.110.127.138:50027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0kQAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:47.813118 2026] [security2:error] [pid 85094:tid 85257] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0kwABKjM"]
[Mon Jul 20 07:12:47.816900 2026] [security2:error] [pid 85094:tid 85165] [remote 154.0.166.254:37848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ez6_nUl59BcEkkgF0tAABYUU"]
[Mon Jul 20 07:12:47.827839 2026] [security2:error] [pid 85094:tid 85257] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0mAABKiM"]
[Mon Jul 20 07:12:47.832465 2026] [security2:error] [pid 85094:tid 85257] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0nAABKjs"]
[Mon Jul 20 07:12:47.837282 2026] [security2:error] [pid 85094:tid 85257] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0mgABKjc"]
[Mon Jul 20 07:12:47.840767 2026] [security2:error] [pid 85094:tid 85309] [client 88.241.67.160:54525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0tgAAAV0"]
[Mon Jul 20 07:12:47.840995 2026] [security2:error] [pid 85094:tid 85309] [client 88.241.67.160:54525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ez6_nUl59BcEkkgF0tgAAAV0"]
[Mon Jul 20 07:12:47.850626 2026] [security2:error] [pid 85094:tid 85257] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0mQABKhc"]
[Mon Jul 20 07:12:47.855126 2026] [security2:error] [pid 85094:tid 85257] [client 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0lwABKiE"]
[Mon Jul 20 07:12:48.037124 2026] [security2:error] [pid 85094:tid 85178] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env"] [unique_id "al4e0K_nUl59BcEkkgF0xAABflI"]
[Mon Jul 20 07:12:48.088293 2026] [security2:error] [pid 85094:tid 85200] [remote 34.107.127.176:35446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mtredistricting.gov"] [uri "/.env.bak"] [unique_id "al4e0K_nUl59BcEkkgF0ygABfmg"]
[Mon Jul 20 07:12:48.143727 2026] [security2:error] [pid 85094:tid 85183] [remote 81.173.115.7:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4e0K_nUl59BcEkkgF00AABIlc"]
[Mon Jul 20 07:12:48.168122 2026] [security2:error] [pid 85094:tid 85238] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xwpg.php"] [unique_id "al4e0K_nUl59BcEkkgF00gAAARc"]
[Mon Jul 20 07:12:48.168268 2026] [security2:error] [pid 85094:tid 85238] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/xwpg.php"] [unique_id "al4e0K_nUl59BcEkkgF00gAAARc"]
[Mon Jul 20 07:12:48.307716 2026] [security2:error] [pid 85094:tid 85169] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0uAABfkk"]
[Mon Jul 20 07:12:48.309527 2026] [security2:error] [pid 85094:tid 85125] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4ez6_nUl59BcEkkgF0uQABfh0"]
[Mon Jul 20 07:12:48.318382 2026] [security2:error] [pid 85094:tid 85240] [client 77.110.127.138:50031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0yAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:48.356197 2026] [security2:error] [pid 85094:tid 85142] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0wwABfi4"]
[Mon Jul 20 07:12:48.359099 2026] [security2:error] [pid 85094:tid 85293] [client 201.27.111.74:55509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e0K_nUl59BcEkkgF02gAAAU0"]
[Mon Jul 20 07:12:48.359208 2026] [security2:error] [pid 85094:tid 85293] [client 201.27.111.74:55509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e0K_nUl59BcEkkgF02gAAAU0"]
[Mon Jul 20 07:12:48.443669 2026] [security2:error] [pid 85094:tid 85239] [client 194.61.41.56:49311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-error_log.php"] [unique_id "al4e0K_nUl59BcEkkgF03gAAARg"]
[Mon Jul 20 07:12:48.558461 2026] [security2:error] [pid 85094:tid 85343] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4e0K_nUl59BcEkkgF04gAAAX8"]
[Mon Jul 20 07:12:48.632633 2026] [security2:error] [pid 85094:tid 85294] [client 77.110.127.138:50015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF03QAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:48.766985 2026] [security2:error] [pid 85094:tid 85335] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4e0K_nUl59BcEkkgF07QAAAXc"]
[Mon Jul 20 07:12:48.819863 2026] [security2:error] [pid 78969:tid 79132] [client 14.225.17.146:52450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4ez3DvNPGtvLGb7O0bDQAAAKY"], referer: http://sarahsnyder.net/2017
[Mon Jul 20 07:12:48.857960 2026] [security2:error] [pid 85094:tid 85168] [remote 81.173.115.7:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4e0K_nUl59BcEkkgF08AABPUg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:12:48.956933 2026] [security2:error] [pid 85094:tid 85194] [remote 154.0.166.254:37848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.166.0.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4e0K_nUl59BcEkkgF0_AABU2I"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:12:48.984595 2026] [security2:error] [pid 85094:tid 85262] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "cdn-0.sustaintheart.com"] [uri "/index.cgi"] [unique_id "al4e0K_nUl59BcEkkgF0_gAAAS8"]
[Mon Jul 20 07:12:49.013493 2026] [security2:error] [pid 78969:tid 79112] [client 104.234.53.63:40685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4e0XDvNPGtvLGb7O0bXQAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:49.130566 2026] [security2:error] [pid 85094:tid 85153] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0xgABfjk"]
[Mon Jul 20 07:12:49.137200 2026] [security2:error] [pid 85094:tid 85159] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0xwABfj8"]
[Mon Jul 20 07:12:49.139146 2026] [security2:error] [pid 85094:tid 85175] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0wAABfk8"]
[Mon Jul 20 07:12:49.140264 2026] [security2:error] [pid 85094:tid 85160] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0vwABfkA"]
[Mon Jul 20 07:12:49.145415 2026] [security2:error] [pid 85094:tid 85162] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0vgABfkI"]
[Mon Jul 20 07:12:49.175425 2026] [security2:error] [pid 85094:tid 85180] [remote 34.107.127.176:35446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4e0K_nUl59BcEkkgF0wgABflQ"]
[Mon Jul 20 07:12:49.178948 2026] [security2:error] [pid 85094:tid 85330] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "cdn-0.sustaintheart.com"] [uri "/404.html"] [unique_id "al4e0a_nUl59BcEkkgF1BQAAAXI"]
[Mon Jul 20 07:12:49.241345 2026] [security2:error] [pid 78969:tid 79173] [client 194.61.41.97:56183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/class_update_plugins.php"] [unique_id "al4e0XDvNPGtvLGb7O0bYgAAAM8"]
[Mon Jul 20 07:12:49.371564 2026] [security2:error] [pid 85094:tid 85274] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/waf.php"] [unique_id "al4e0a_nUl59BcEkkgF1DAAAATs"]
[Mon Jul 20 07:12:49.371668 2026] [security2:error] [pid 85094:tid 85274] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/waf.php"] [unique_id "al4e0a_nUl59BcEkkgF1DAAAATs"]
[Mon Jul 20 07:12:49.585270 2026] [security2:error] [pid 85094:tid 85339] [client 14.225.17.146:52669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4e0a_nUl59BcEkkgF1DQAAAXs"], referer: http://swafforddetailing.com/2017
[Mon Jul 20 07:12:49.743944 2026] [security2:error] [pid 85094:tid 85318] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xstelth.php"] [unique_id "al4e0a_nUl59BcEkkgF1GQAAAWY"]
[Mon Jul 20 07:12:49.744025 2026] [security2:error] [pid 85094:tid 85318] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/xstelth.php"] [unique_id "al4e0a_nUl59BcEkkgF1GQAAAWY"]
[Mon Jul 20 07:12:49.767412 2026] [security2:error] [pid 85094:tid 85256] [client 14.225.17.146:52458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4e0a_nUl59BcEkkgF1EgAAASk"], referer: https://sarahsnyder.net/2017
[Mon Jul 20 07:12:49.863832 2026] [security2:error] [pid 85094:tid 85341] [client 57.141.18.25:48160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4eza_nUl59BcEkkgF0JgABfQU"]
[Mon Jul 20 07:12:50.015512 2026] [security2:error] [pid 78969:tid 79124] [client 194.61.41.68:41861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/av.php"] [unique_id "al4e0nDvNPGtvLGb7O0bhQAAAJ4"]
[Mon Jul 20 07:12:50.096106 2026] [security2:error] [pid 85094:tid 85285] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-links.php"] [unique_id "al4e0q_nUl59BcEkkgF1IgAAAUU"]
[Mon Jul 20 07:12:50.096188 2026] [security2:error] [pid 85094:tid 85285] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-links.php"] [unique_id "al4e0q_nUl59BcEkkgF1IgAAAUU"]
[Mon Jul 20 07:12:50.454398 2026] [security2:error] [pid 85094:tid 85337] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4e0q_nUl59BcEkkgF1LwAAAXk"]
[Mon Jul 20 07:12:50.454493 2026] [security2:error] [pid 85094:tid 85337] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4e0q_nUl59BcEkkgF1LwAAAXk"]
[Mon Jul 20 07:12:50.483492 2026] [security2:error] [pid 78969:tid 79122] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4e0nDvNPGtvLGb7O0blgAAAJw"]
[Mon Jul 20 07:12:50.727737 2026] [security2:error] [pid 78969:tid 79188] [client 194.61.41.74:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/templates/beez5/error.php"] [unique_id "al4e0nDvNPGtvLGb7O0bpQAAAN4"]
[Mon Jul 20 07:12:50.832947 2026] [security2:error] [pid 78969:tid 79208] [client 191.237.250.106:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.250.237.191.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/aaa.php"] [unique_id "al4e0nDvNPGtvLGb7O0brQAAAPI"]
[Mon Jul 20 07:12:50.833087 2026] [security2:error] [pid 78969:tid 79208] [client 191.237.250.106:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cdn-0.sustaintheart.com"] [uri "/aaa.php"] [unique_id "al4e0nDvNPGtvLGb7O0brQAAAPI"]
[Mon Jul 20 07:12:51.125660 2026] [security2:error] [pid 78969:tid 79143] [client 104.234.53.72:47559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4e03DvNPGtvLGb7O0buwAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:51.327926 2026] [security2:error] [pid 78969:tid 79085] [remote 173.212.252.15:37534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4e03DvNPGtvLGb7O0bwAAAvnM"]
[Mon Jul 20 07:12:51.328051 2026] [security2:error] [pid 78969:tid 79156] [client 173.212.252.15:37534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4e03DvNPGtvLGb7O0bwAAAvnM"]
[Mon Jul 20 07:12:51.463758 2026] [security2:error] [pid 78969:tid 79099] [client 194.61.41.247:55261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/admin-footer.php"] [unique_id "al4e03DvNPGtvLGb7O0bxwAAAIU"]
[Mon Jul 20 07:12:51.782311 2026] [security2:error] [pid 78969:tid 79133] [client 157.20.138.62:62837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e03DvNPGtvLGb7O0b3wAAAKc"]
[Mon Jul 20 07:12:51.782445 2026] [security2:error] [pid 78969:tid 79133] [client 157.20.138.62:62837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e03DvNPGtvLGb7O0b3wAAAKc"]
[Mon Jul 20 07:12:51.798663 2026] [security2:error] [pid 85094:tid 85268] [client 14.225.17.146:60865] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4e06_nUl59BcEkkgF1bQAAATU"], referer: http://thefriendlyspreadsheet.com/2017
[Mon Jul 20 07:12:52.116036 2026] [core:error] [pid 78969:tid 79165] [client 14.225.17.146:61095] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:12:52.116059 2026] [core:error] [pid 78969:tid 79165] [client 14.225.17.146:61095] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:12:52.232082 2026] [security2:error] [pid 78969:tid 79143] [client 194.61.41.244:54521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/firewall.php7"] [unique_id "al4e1HDvNPGtvLGb7O0b9QAAALE"]
[Mon Jul 20 07:12:52.252730 2026] [security2:error] [pid 78969:tid 79170] [client 77.110.127.138:50050] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4e1HDvNPGtvLGb7O0b-AAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:52.525903 2026] [security2:error] [pid 85094:tid 85098] [remote 57.141.18.105:41504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4710513"] [unique_id "al4e1K_nUl59BcEkkgF1lAABIQI"]
[Mon Jul 20 07:12:52.603636 2026] [security2:error] [pid 85094:tid 85233] [client 44.221.129.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4e1K_nUl59BcEkkgF1kAABEn0"]
[Mon Jul 20 07:12:52.632776 2026] [security2:error] [pid 85094:tid 85235] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4e1K_nUl59BcEkkgF1fwAAARQ"]
[Mon Jul 20 07:12:52.693971 2026] [security2:error] [pid 78969:tid 79113] [client 104.234.53.87:53119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4e1HDvNPGtvLGb7O0cDQAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:52.832703 2026] [security2:error] [pid 78969:tid 79223] [client 57.141.18.33:48448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e0HDvNPGtvLGb7O0bRAABATc"]
[Mon Jul 20 07:12:52.833519 2026] [security2:error] [pid 85094:tid 85280] [client 14.225.17.146:61197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4e0q_nUl59BcEkkgF1KgAAAUE"], referer: http://overloadcomedy.com/2017
[Mon Jul 20 07:12:52.950690 2026] [security2:error] [pid 78969:tid 79221] [client 194.61.41.65:28699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/certificates/chosen.php"] [unique_id "al4e1HDvNPGtvLGb7O0cGwAAAP8"]
[Mon Jul 20 07:12:53.028058 2026] [security2:error] [pid 85094:tid 85279] [client 44.223.253.120:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4e1K_nUl59BcEkkgF1pAABQA8"]
[Mon Jul 20 07:12:53.161525 2026] [security2:error] [pid 85094:tid 85270] [client 14.225.17.146:61382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4e1a_nUl59BcEkkgF1qwAAATc"], referer: http://grecruit.online/2017
[Mon Jul 20 07:12:53.464219 2026] [security2:error] [pid 85094:tid 85104] [remote 57.141.18.38:32164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5138828"] [unique_id "al4e1a_nUl59BcEkkgF1zQABZgg"]
[Mon Jul 20 07:12:53.532671 2026] [security2:error] [pid 85094:tid 85351] [client 14.225.17.146:49949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4e1a_nUl59BcEkkgF1ugAAAYc"], referer: http://mcg.homes/2017
[Mon Jul 20 07:12:53.673232 2026] [security2:error] [pid 85094:tid 85292] [client 13.233.207.33:34478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4e1a_nUl59BcEkkgF14QAAAUw"]
[Mon Jul 20 07:12:53.673340 2026] [security2:error] [pid 85094:tid 85292] [client 13.233.207.33:34478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4e1a_nUl59BcEkkgF14QAAAUw"]
[Mon Jul 20 07:12:53.717183 2026] [security2:error] [pid 85094:tid 85232] [client 14.225.17.146:52425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4e1a_nUl59BcEkkgF1xwAAARE"], referer: http://tacticaltreeoperations.com/2017
[Mon Jul 20 07:12:53.728620 2026] [security2:error] [pid 85094:tid 85287] [client 194.61.41.69:58417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/about.php"] [unique_id "al4e1a_nUl59BcEkkgF15AAAAUc"]
[Mon Jul 20 07:12:53.806004 2026] [security2:error] [pid 85094:tid 85282] [client 104.234.53.61:49579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4e1a_nUl59BcEkkgF16AAAAUI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:54.082027 2026] [security2:error] [pid 78969:tid 79100] [client 57.141.18.18:59558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e0XDvNPGtvLGb7O0bewAAhj0"]
[Mon Jul 20 07:12:54.177022 2026] [security2:error] [pid 78969:tid 79220] [client 77.110.127.138:50244] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e1nDvNPGtvLGb7O0cTQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:54.230019 2026] [security2:error] [pid 85094:tid 85288] [client 77.110.127.138:50057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4e1q_nUl59BcEkkgF18QAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:54.434084 2026] [security2:error] [pid 85094:tid 85229] [client 194.61.41.102:42169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/file/incpb.php"] [unique_id "al4e1q_nUl59BcEkkgF19gAAAQ4"]
[Mon Jul 20 07:12:54.893941 2026] [security2:error] [pid 85094:tid 85265] [client 50.116.65.227:10640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4e1q_nUl59BcEkkgF2DgAAATI"]
[Mon Jul 20 07:12:54.907282 2026] [security2:error] [pid 78969:tid 79155] [client 50.116.65.227:10654] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4e1nDvNPGtvLGb7O0cbwAAAL0"]
[Mon Jul 20 07:12:55.155969 2026] [security2:error] [pid 78969:tid 79105] [client 194.61.41.66:54591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/stories/themes.php"] [unique_id "al4e13DvNPGtvLGb7O0cfwAAAIs"]
[Mon Jul 20 07:12:55.641556 2026] [security2:error] [pid 78969:tid 79106] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4e13DvNPGtvLGb7O0chwAAAIw"]
[Mon Jul 20 07:12:55.684626 2026] [security2:error] [pid 78969:tid 79128] [client 14.225.17.146:61032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4e1nDvNPGtvLGb7O0caAAAAKI"], referer: http://detroitcsc.com/2017
[Mon Jul 20 07:12:55.925454 2026] [security2:error] [pid 85094:tid 85314] [client 194.61.41.82:45565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/theme-compat/footer-embed-function.php"] [unique_id "al4e16_nUl59BcEkkgF2KwAAAWI"]
[Mon Jul 20 07:12:56.100876 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:50367] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e2K_nUl59BcEkkgF2OQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:12:56.231527 2026] [security2:error] [pid 78969:tid 79135] [client 35.90.38.209:36400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4e2HDvNPGtvLGb7O0cqwAAAKk"]
[Mon Jul 20 07:12:56.658007 2026] [security2:error] [pid 85094:tid 85346] [client 194.61.41.102:22655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/firewall.php7"] [unique_id "al4e2K_nUl59BcEkkgF2TgAAAYI"]
[Mon Jul 20 07:12:56.758379 2026] [security2:error] [pid 85094:tid 85298] [client 104.234.53.58:49019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4e2K_nUl59BcEkkgF2UAAAAVI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:56.860103 2026] [security2:error] [pid 85094:tid 85339] [client 14.225.17.146:60947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4e2K_nUl59BcEkkgF2UQAAAXs"], referer: http://friendlyspreadsheet.com/2017
[Mon Jul 20 07:12:56.907572 2026] [security2:error] [pid 78969:tid 79194] [client 114.119.150.95:23239] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sergioraya.com"] [uri "/robots.txt"] [unique_id "al4e2HDvNPGtvLGb7O0cxwAAAOQ"], referer: https://sergioraya.com/robots.txt
[Mon Jul 20 07:12:57.394170 2026] [security2:error] [pid 85094:tid 85137] [remote 74.235.96.117:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4e2a_nUl59BcEkkgF2bwABfik"]
[Mon Jul 20 07:12:57.420842 2026] [security2:error] [pid 85094:tid 85296] [client 194.61.41.253:39577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/home/O-Simple.php"] [unique_id "al4e2a_nUl59BcEkkgF2cQAAAVA"]
[Mon Jul 20 07:12:57.559452 2026] [security2:error] [pid 78969:tid 78982] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e2XDvNPGtvLGb7O0c4gAA-gw"]
[Mon Jul 20 07:12:57.559616 2026] [security2:error] [pid 78969:tid 79216] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e2XDvNPGtvLGb7O0c4gAA-gw"]
[Mon Jul 20 07:12:57.562317 2026] [security2:error] [pid 78969:tid 79093] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e2XDvNPGtvLGb7O0c4wAA7Hs"]
[Mon Jul 20 07:12:57.562435 2026] [security2:error] [pid 78969:tid 79202] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e2XDvNPGtvLGb7O0c4wAA7Hs"]
[Mon Jul 20 07:12:57.565583 2026] [security2:error] [pid 85094:tid 85277] [client 103.144.65.217:55188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e2a_nUl59BcEkkgF2dAAAAT4"]
[Mon Jul 20 07:12:57.565708 2026] [security2:error] [pid 85094:tid 85277] [client 103.144.65.217:55188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e2a_nUl59BcEkkgF2dAAAAT4"]
[Mon Jul 20 07:12:57.582609 2026] [security2:error] [pid 85094:tid 85145] [remote 74.235.96.117:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4e2a_nUl59BcEkkgF2dQABTDE"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 07:12:57.651785 2026] [security2:error] [pid 78969:tid 79162] [client 104.234.53.73:34669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4e2XDvNPGtvLGb7O0c5gAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:12:57.741985 2026] [security2:error] [pid 85094:tid 85279] [client 14.225.17.146:64552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4e2a_nUl59BcEkkgF2egAAAUA"], referer: https://friendlyspreadsheet.com/2017
[Mon Jul 20 07:12:57.911875 2026] [security2:error] [pid 85094:tid 85297] [client 14.225.17.146:52364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4e16_nUl59BcEkkgF2LAAAAVE"], referer: http://www.justinagrayman.com/2017
[Mon Jul 20 07:12:58.001834 2026] [security2:error] [pid 78969:tid 79157] [client 57.141.18.76:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4e2XDvNPGtvLGb7O0c8QAAAL8"]
[Mon Jul 20 07:12:58.099894 2026] [autoindex:error] [pid 85094:tid 85312] [client 64.23.221.228:0] AH01276: Cannot serve directory /home3/elemeqg5/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:12:58.131194 2026] [security2:error] [pid 85094:tid 85246] [client 194.61.41.82:38389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/l10n/class-wp-translation-file-mo-event.php"] [unique_id "al4e2q_nUl59BcEkkgF2lQAAAR8"]
[Mon Jul 20 07:12:58.243126 2026] [security2:error] [pid 85094:tid 85254] [client 52.233.165.60:19456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4e2q_nUl59BcEkkgF2nAAAASc"]
[Mon Jul 20 07:12:58.341511 2026] [security2:error] [pid 85094:tid 85337] [client 187.16.64.216:53991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e2q_nUl59BcEkkgF2pwAAAXk"]
[Mon Jul 20 07:12:58.341637 2026] [security2:error] [pid 85094:tid 85337] [client 187.16.64.216:53991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e2q_nUl59BcEkkgF2pwAAAXk"]
[Mon Jul 20 07:12:58.391332 2026] [security2:error] [pid 85094:tid 85233] [client 52.233.165.60:19456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4e2q_nUl59BcEkkgF2qwAAARI"]
[Mon Jul 20 07:12:58.524982 2026] [security2:error] [pid 85094:tid 85245] [client 88.241.67.160:54400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e2q_nUl59BcEkkgF2sAAAAR4"]
[Mon Jul 20 07:12:58.525315 2026] [security2:error] [pid 85094:tid 85245] [client 88.241.67.160:54400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e2q_nUl59BcEkkgF2sAAAAR4"]
[Mon Jul 20 07:12:58.565519 2026] [security2:error] [pid 85094:tid 85260] [client 52.183.195.200:10630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4e2q_nUl59BcEkkgF2sQAAAS0"]
[Mon Jul 20 07:12:58.594629 2026] [security2:error] [pid 85094:tid 85318] [client 52.183.195.200:10630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4e2q_nUl59BcEkkgF2twAAAWY"]
[Mon Jul 20 07:12:58.919510 2026] [security2:error] [pid 78969:tid 79221] [client 194.61.41.242:51327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/vars-soap.php"] [unique_id "al4e2nDvNPGtvLGb7O0dFAAAAP8"]
[Mon Jul 20 07:12:58.941980 2026] [security2:error] [pid 78969:tid 79136] [client 57.141.18.34:26768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e1nDvNPGtvLGb7O0cSgAAqhQ"]
[Mon Jul 20 07:12:58.955333 2026] [security2:error] [pid 85094:tid 85344] [client 201.27.111.74:56009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e2q_nUl59BcEkkgF2yAAAAYA"]
[Mon Jul 20 07:12:58.957125 2026] [security2:error] [pid 85094:tid 85344] [client 201.27.111.74:56009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e2q_nUl59BcEkkgF2yAAAAYA"]
[Mon Jul 20 07:12:59.063592 2026] [security2:error] [pid 85094:tid 85282] [client 46.110.96.34:13689] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4e26_nUl59BcEkkgF20wAAAUI"]
[Mon Jul 20 07:12:59.074680 2026] [security2:error] [pid 85094:tid 85258] [client 46.110.96.34:41283] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4e26_nUl59BcEkkgF21QAAASs"]
[Mon Jul 20 07:12:59.515524 2026] [autoindex:error] [pid 85094:tid 85275] [client 136.66.235.77:0] AH01276: Cannot serve directory /home1/heidimo2/strongtowerpodcast.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:12:59.518785 2026] [security2:error] [pid 85094:tid 85274] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4e26_nUl59BcEkkgF24QAAATs"]
[Mon Jul 20 07:12:59.531452 2026] [security2:error] [pid 85094:tid 85318] [client 117.211.236.168:60724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e26_nUl59BcEkkgF29AAAAWY"]
[Mon Jul 20 07:12:59.531537 2026] [security2:error] [pid 85094:tid 85318] [client 117.211.236.168:60724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e26_nUl59BcEkkgF29AAAAWY"]
[Mon Jul 20 07:12:59.635874 2026] [security2:error] [pid 85094:tid 85337] [client 194.61.41.64:24831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentytwo/av.php"] [unique_id "al4e26_nUl59BcEkkgF2-wAAAXk"]
[Mon Jul 20 07:13:00.128318 2026] [security2:error] [pid 85094:tid 85317] [client 77.110.127.138:50620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4e3K_nUl59BcEkkgF3DgAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:00.440549 2026] [security2:error] [pid 78969:tid 79221] [client 194.61.41.82:64089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/style.php%20"] [unique_id "al4e3HDvNPGtvLGb7O0dVAAAAP8"]
[Mon Jul 20 07:13:00.654846 2026] [security2:error] [pid 85094:tid 85225] [client 14.225.17.146:50767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4e3K_nUl59BcEkkgF3GgAAAQo"], referer: http://sarahholyfield.com/2017
[Mon Jul 20 07:13:01.245215 2026] [security2:error] [pid 78969:tid 79210] [client 194.61.41.108:41569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/files.php"] [unique_id "al4e3XDvNPGtvLGb7O0deQAAAPQ"]
[Mon Jul 20 07:13:01.522065 2026] [autoindex:error] [pid 78969:tid 79124] [client 136.109.15.43:56448] AH01276: Cannot serve directory /home1/heidimo2/public_html/website_ba575a2e/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:13:01.765685 2026] [security2:error] [pid 85094:tid 85315] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mezzacraft.com"] [uri "/index.php"] [unique_id "al4e3a_nUl59BcEkkgF3PwAAAWM"]
[Mon Jul 20 07:13:02.026279 2026] [security2:error] [pid 85094:tid 85260] [client 194.61.41.108:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/av.php"] [unique_id "al4e3q_nUl59BcEkkgF3UgAAAS0"]
[Mon Jul 20 07:13:02.167560 2026] [security2:error] [pid 85094:tid 85269] [client 14.225.17.146:50480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4e3K_nUl59BcEkkgF3HQAAATY"]
[Mon Jul 20 07:13:02.346603 2026] [security2:error] [pid 85094:tid 85250] [client 77.110.127.138:50650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4e3q_nUl59BcEkkgF3aQAAASM"], referer: https://mezzacraft.com/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/
[Mon Jul 20 07:13:02.379916 2026] [security2:error] [pid 78969:tid 79199] [client 157.20.138.62:63351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e3nDvNPGtvLGb7O0dqgAAAOk"]
[Mon Jul 20 07:13:02.380014 2026] [security2:error] [pid 78969:tid 79199] [client 157.20.138.62:63351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e3nDvNPGtvLGb7O0dqgAAAOk"]
[Mon Jul 20 07:13:02.681519 2026] [security2:error] [pid 85094:tid 85290] [client 18.140.64.130:42352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4e3q_nUl59BcEkkgF3egAAAUo"]
[Mon Jul 20 07:13:02.726731 2026] [security2:error] [pid 85094:tid 85314] [client 18.209.142.234:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4e3q_nUl59BcEkkgF3eAABYh0"]
[Mon Jul 20 07:13:02.782506 2026] [security2:error] [pid 85094:tid 85326] [client 14.225.17.146:49293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4e3q_nUl59BcEkkgF3ewAAAW4"], referer: http://daseighty.net/2017
[Mon Jul 20 07:13:02.784143 2026] [security2:error] [pid 85094:tid 85275] [client 194.61.41.99:60175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/about.php"] [unique_id "al4e3q_nUl59BcEkkgF3fQAAATw"]
[Mon Jul 20 07:13:02.901121 2026] [security2:error] [pid 85094:tid 85260] [client 46.110.96.34:58322] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4e3q_nUl59BcEkkgF3ggAAAS0"]
[Mon Jul 20 07:13:02.949169 2026] [security2:error] [pid 85094:tid 85332] [client 57.141.18.42:47666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e2q_nUl59BcEkkgF2rQABdC8"]
[Mon Jul 20 07:13:02.953527 2026] [security2:error] [pid 85094:tid 85333] [client 104.234.53.85:22587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4e3q_nUl59BcEkkgF3hwAAAXU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:03.528983 2026] [lsapi:warn] [pid 85094:tid 85168] [remote 104.210.140.132:42090] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:13:03.529021 2026] [lsapi:warn] [pid 85094:tid 85168] [remote 104.210.140.132:42090] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:13:03.622806 2026] [lsapi:warn] [pid 85094:tid 85283] [client 50.116.65.227:37850] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:13:03.622826 2026] [lsapi:warn] [pid 85094:tid 85283] [client 50.116.65.227:37850] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:13:03.636293 2026] [security2:error] [pid 85094:tid 85248] [client 104.210.140.132:42090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4e36_nUl59BcEkkgF3pAABIUg"]
[Mon Jul 20 07:13:03.716196 2026] [security2:error] [pid 78969:tid 79118] [client 104.234.53.79:31425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4e33DvNPGtvLGb7O0d3wAAAJg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:03.785869 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:50655] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e36_nUl59BcEkkgF3rAAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:03.805856 2026] [security2:error] [pid 78969:tid 79213] [client 194.61.41.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4e33DvNPGtvLGb7O0d2gAAAPc"]
[Mon Jul 20 07:13:03.859715 2026] [security2:error] [pid 85094:tid 85246] [client 18.142.226.106:58182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4e36_nUl59BcEkkgF3rQAAAR8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:13:03.927530 2026] [security2:error] [pid 85094:tid 85254] [client 14.225.17.146:64504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4e3q_nUl59BcEkkgF3gwAAASc"], referer: http://claysharecon.com/2017
[Mon Jul 20 07:13:03.979004 2026] [security2:error] [pid 78969:tid 79225] [client 104.234.53.79:31425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4e33DvNPGtvLGb7O0d7AAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:04.034114 2026] [security2:error] [pid 85094:tid 85261] [client 57.141.18.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4e36_nUl59BcEkkgF3pgAAAS4"]
[Mon Jul 20 07:13:04.258241 2026] [security2:error] [pid 78969:tid 79170] [client 57.141.18.91:24214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e23DvNPGtvLGb7O0dNQAAzDU"]
[Mon Jul 20 07:13:04.637464 2026] [security2:error] [pid 78969:tid 79018] [remote 57.141.18.1:38730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4752481"] [unique_id "al4e4HDvNPGtvLGb7O0eDgAA1jA"]
[Mon Jul 20 07:13:04.664452 2026] [security2:error] [pid 85094:tid 85253] [client 194.61.41.61:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/id3/wp-work.php"] [unique_id "al4e4K_nUl59BcEkkgF3ygAAASY"]
[Mon Jul 20 07:13:05.113163 2026] [security2:error] [pid 78969:tid 79147] [client 14.225.17.146:51028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4e33DvNPGtvLGb7O0dygAAALU"], referer: http://windowtx.com/2017
[Mon Jul 20 07:13:05.407551 2026] [security2:error] [pid 85094:tid 85317] [client 14.225.17.146:49876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4e4K_nUl59BcEkkgF3zAAAAWU"]
[Mon Jul 20 07:13:05.437967 2026] [security2:error] [pid 85094:tid 85314] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4e4a_nUl59BcEkkgF33gAAAWI"]
[Mon Jul 20 07:13:05.469957 2026] [security2:error] [pid 85094:tid 85294] [client 194.61.41.251:45673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/WordPressCore/gecko.php"] [unique_id "al4e4a_nUl59BcEkkgF38gAAAU4"]
[Mon Jul 20 07:13:05.696481 2026] [security2:error] [pid 85094:tid 85261] [client 158.173.166.181:34875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4e4a_nUl59BcEkkgF4AAAAAS4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:13:06.004996 2026] [security2:error] [pid 85094:tid 85244] [client 166.88.169.130:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4e4a_nUl59BcEkkgF3_gAAAR0"]
[Mon Jul 20 07:13:06.229499 2026] [security2:error] [pid 78969:tid 79126] [client 23.17.215.161:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4e4nDvNPGtvLGb7O0ePQAAoC4"], referer: https://www.google.com/
[Mon Jul 20 07:13:06.233103 2026] [security2:error] [pid 85094:tid 85339] [client 194.61.41.101:30099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/baxa1.php7"] [unique_id "al4e4q_nUl59BcEkkgF4FQAAAXs"]
[Mon Jul 20 07:13:06.273309 2026] [lsapi:warn] [pid 85094:tid 85174] [remote 104.210.140.137:61585] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:13:06.273332 2026] [lsapi:warn] [pid 85094:tid 85174] [remote 104.210.140.137:61585] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:13:06.347489 2026] [security2:error] [pid 85094:tid 85315] [client 104.234.53.73:39439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4e4q_nUl59BcEkkgF4GgAAAWM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:06.586942 2026] [security2:error] [pid 78969:tid 79215] [client 14.225.17.146:50215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4e4nDvNPGtvLGb7O0eRwAAAPk"], referer: http://adirondackengineering.com/2017
[Mon Jul 20 07:13:06.606061 2026] [security2:error] [pid 78969:tid 79164] [client 14.225.17.146:50213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4e4nDvNPGtvLGb7O0eRgAAAMY"], referer: http://falconarrowshop.com/2017
[Mon Jul 20 07:13:06.620364 2026] [security2:error] [pid 85094:tid 85232] [client 52.187.213.117:45154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4e4q_nUl59BcEkkgF4JwAAARE"]
[Mon Jul 20 07:13:06.777251 2026] [security2:error] [pid 85094:tid 85322] [client 52.187.213.117:45154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4e4q_nUl59BcEkkgF4LgAAAWo"]
[Mon Jul 20 07:13:07.023414 2026] [security2:error] [pid 85094:tid 85266] [client 194.61.41.240:51905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-taxonomy.editor.php"] [unique_id "al4e46_nUl59BcEkkgF4NQAAATM"]
[Mon Jul 20 07:13:07.052121 2026] [security2:error] [pid 85094:tid 85350] [client 77.110.127.138:50819] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e46_nUl59BcEkkgF4OAAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:07.611957 2026] [security2:error] [pid 85094:tid 85098] [remote 57.141.18.2:31510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4529487"] [unique_id "al4e46_nUl59BcEkkgF4WwABNwI"]
[Mon Jul 20 07:13:07.729186 2026] [security2:error] [pid 85094:tid 85327] [client 194.61.41.105:47105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/dedi1.php"] [unique_id "al4e46_nUl59BcEkkgF4aAAAAW8"]
[Mon Jul 20 07:13:07.895286 2026] [security2:error] [pid 85094:tid 85323] [client 57.141.18.22:46030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e36_nUl59BcEkkgF3qwABa2I"]
[Mon Jul 20 07:13:07.995355 2026] [security2:error] [pid 85094:tid 85298] [client 103.144.65.217:55631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e46_nUl59BcEkkgF4fAAAAVI"]
[Mon Jul 20 07:13:07.997066 2026] [security2:error] [pid 85094:tid 85298] [client 103.144.65.217:55631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e46_nUl59BcEkkgF4fAAAAVI"]
[Mon Jul 20 07:13:08.144231 2026] [security2:error] [pid 85094:tid 85263] [client 52.109.4.7:22083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4e5K_nUl59BcEkkgF4hgAAATA"]
[Mon Jul 20 07:13:08.204879 2026] [security2:error] [pid 85094:tid 85337] [client 52.109.4.7:22083] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4e5K_nUl59BcEkkgF4jAAAAXk"]
[Mon Jul 20 07:13:08.214029 2026] [security2:error] [pid 85094:tid 85116] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e5K_nUl59BcEkkgF4jQABThQ"]
[Mon Jul 20 07:13:08.214170 2026] [security2:error] [pid 85094:tid 85294] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e5K_nUl59BcEkkgF4jQABThQ"]
[Mon Jul 20 07:13:08.277221 2026] [security2:error] [pid 85094:tid 85218] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e5K_nUl59BcEkkgF4lwABPXo"]
[Mon Jul 20 07:13:08.277381 2026] [security2:error] [pid 85094:tid 85276] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e5K_nUl59BcEkkgF4lwABPXo"]
[Mon Jul 20 07:13:08.291994 2026] [security2:error] [pid 85094:tid 85261] [client 77.110.127.138:50951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4e5K_nUl59BcEkkgF4mQAAAS4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:08.453297 2026] [security2:error] [pid 85094:tid 85260] [client 194.61.41.74:38629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/wp-conflg.php"] [unique_id "al4e5K_nUl59BcEkkgF4nwAAAS0"]
[Mon Jul 20 07:13:09.057293 2026] [security2:error] [pid 85094:tid 85325] [client 64.227.49.194:53050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.alexsandbergmusic.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4e5a_nUl59BcEkkgF40wAAAW0"]
[Mon Jul 20 07:13:09.110581 2026] [security2:error] [pid 85094:tid 85327] [client 104.234.53.85:43563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4e5a_nUl59BcEkkgF43QAAAW8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:09.113606 2026] [security2:error] [pid 85094:tid 85323] [client 88.241.67.160:53452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e5a_nUl59BcEkkgF43gAAAWs"]
[Mon Jul 20 07:13:09.114239 2026] [security2:error] [pid 85094:tid 85323] [client 88.241.67.160:53452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e5a_nUl59BcEkkgF43gAAAWs"]
[Mon Jul 20 07:13:09.240868 2026] [security2:error] [pid 85094:tid 85303] [client 194.61.41.102:56615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/blog.php"] [unique_id "al4e5a_nUl59BcEkkgF45gAAAVc"]
[Mon Jul 20 07:13:09.402067 2026] [security2:error] [pid 85094:tid 85338] [client 187.16.64.216:54588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e5a_nUl59BcEkkgF49gAAAXo"]
[Mon Jul 20 07:13:09.402160 2026] [security2:error] [pid 85094:tid 85338] [client 187.16.64.216:54588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e5a_nUl59BcEkkgF49gAAAXo"]
[Mon Jul 20 07:13:09.513140 2026] [security2:error] [pid 85094:tid 85228] [client 201.27.111.74:56509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e5a_nUl59BcEkkgF4_QAAAQ0"]
[Mon Jul 20 07:13:09.513259 2026] [security2:error] [pid 85094:tid 85228] [client 201.27.111.74:56509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e5a_nUl59BcEkkgF4_QAAAQ0"]
[Mon Jul 20 07:13:09.895663 2026] [security2:error] [pid 85094:tid 85270] [client 46.110.96.34:40115] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4e5a_nUl59BcEkkgF5KwAAATc"]
[Mon Jul 20 07:13:10.030421 2026] [security2:error] [pid 85094:tid 85285] [client 194.61.41.89:60081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/about/install.php"] [unique_id "al4e5q_nUl59BcEkkgF5PgAAAUU"]
[Mon Jul 20 07:13:10.367837 2026] [security2:error] [pid 85094:tid 85246] [client 92.252.162.147:20490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4e5q_nUl59BcEkkgF5RwAAAR8"]
[Mon Jul 20 07:13:10.444021 2026] [security2:error] [pid 85094:tid 85255] [client 57.141.18.88:34106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e4q_nUl59BcEkkgF4EAABKGE"]
[Mon Jul 20 07:13:10.488719 2026] [security2:error] [pid 85094:tid 85175] [remote 173.249.4.11:31818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4e5q_nUl59BcEkkgF5bQABFU8"]
[Mon Jul 20 07:13:10.575171 2026] [security2:error] [pid 85094:tid 85303] [client 117.211.236.168:61277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e5q_nUl59BcEkkgF5eAAAAVc"]
[Mon Jul 20 07:13:10.575288 2026] [security2:error] [pid 85094:tid 85303] [client 117.211.236.168:61277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e5q_nUl59BcEkkgF5eAAAAVc"]
[Mon Jul 20 07:13:10.685342 2026] [security2:error] [pid 85094:tid 85101] [remote 173.249.4.11:31818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4e5q_nUl59BcEkkgF5fgABcgU"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:13:10.821461 2026] [security2:error] [pid 85094:tid 85230] [client 194.61.41.241:46283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/pridmag/bypass.php"] [unique_id "al4e5q_nUl59BcEkkgF5hgAAAQ8"]
[Mon Jul 20 07:13:10.922619 2026] [security2:error] [pid 85094:tid 85312] [client 14.225.17.146:50073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4e5a_nUl59BcEkkgF48AAAAWA"], referer: http://vinovinhowine.com/2017
[Mon Jul 20 07:13:11.398039 2026] [security2:error] [pid 85094:tid 85336] [client 14.225.17.146:50414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4e5q_nUl59BcEkkgF5RQAAAXg"], referer: http://wathenbartlett.co.uk/2017
[Mon Jul 20 07:13:11.531234 2026] [security2:error] [pid 85094:tid 85306] [client 194.61.41.92:51451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/chosen.php"] [unique_id "al4e56_nUl59BcEkkgF5vgAAAVo"]
[Mon Jul 20 07:13:11.818991 2026] [security2:error] [pid 85094:tid 85240] [client 182.8.226.25:18522] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "circafabrication.com"] [uri "/wp-json/batch/v1"] [unique_id "al4e56_nUl59BcEkkgF5zwAAARk"]
[Mon Jul 20 07:13:12.185036 2026] [security2:error] [pid 85094:tid 85334] [client 77.110.127.138:51264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpui1csZXJ'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4e6K_nUl59BcEkkgF56QAAAXY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:12.247721 2026] [security2:error] [pid 85094:tid 85344] [client 194.61.41.254:46365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/av.php"] [unique_id "al4e6K_nUl59BcEkkgF57gAAAYA"]
[Mon Jul 20 07:13:12.286462 2026] [security2:error] [pid 85094:tid 85318] [client 14.225.17.146:52688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4e6K_nUl59BcEkkgF57AAAAWY"], referer: https://wathenbartlett.co.uk/2017
[Mon Jul 20 07:13:12.489578 2026] [fcgid:warn] [pid 85094:tid 85314] (70014)End of file found: [client 103.168.67.159:46748] mod_fcgid: can't get data from http client
[Mon Jul 20 07:13:12.535685 2026] [security2:error] [pid 85094:tid 85123] [remote 217.61.143.92:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4e6K_nUl59BcEkkgF6FgABRxs"]
[Mon Jul 20 07:13:12.557276 2026] [security2:error] [pid 85094:tid 85260] [client 104.234.53.66:61347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4e6K_nUl59BcEkkgF6HQAAAS0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:12.773573 2026] [security2:error] [pid 85094:tid 85100] [remote 217.61.143.92:45044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4e6K_nUl59BcEkkgF6KAABYwQ"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 07:13:12.910335 2026] [security2:error] [pid 85094:tid 85253] [client 157.20.138.62:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e6K_nUl59BcEkkgF6LgAAASY"]
[Mon Jul 20 07:13:12.910476 2026] [security2:error] [pid 85094:tid 85253] [client 157.20.138.62:63876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e6K_nUl59BcEkkgF6LgAAASY"]
[Mon Jul 20 07:13:13.012407 2026] [security2:error] [pid 85094:tid 85318] [client 182.8.226.25:18512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "circafabrication.com"] [uri "/"] [unique_id "al4e6a_nUl59BcEkkgF6PAAAAWY"]
[Mon Jul 20 07:13:13.017907 2026] [security2:error] [pid 85094:tid 85262] [client 57.141.18.16:34088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e5K_nUl59BcEkkgF4zQABLyY"]
[Mon Jul 20 07:13:13.036121 2026] [security2:error] [pid 85094:tid 85305] [client 194.61.41.98:48395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/interactivity-api/interactivity-api-xml.php"] [unique_id "al4e6a_nUl59BcEkkgF6QwAAAVk"]
[Mon Jul 20 07:13:13.290677 2026] [security2:error] [pid 85094:tid 85312] [client 14.225.17.146:52725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4e6K_nUl59BcEkkgF6BAAAAWA"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2017
[Mon Jul 20 07:13:13.308203 2026] [security2:error] [pid 85094:tid 85237] [client 14.225.17.146:50644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4e6K_nUl59BcEkkgF54wAAARY"], referer: http://cloudspacesgroup.com/2017
[Mon Jul 20 07:13:13.694004 2026] [security2:error] [pid 85094:tid 85132] [remote 20.153.140.50:59826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4e6a_nUl59BcEkkgF6dQABRCQ"]
[Mon Jul 20 07:13:13.694234 2026] [security2:error] [pid 85094:tid 85284] [client 20.153.140.50:59826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4e6a_nUl59BcEkkgF6dQABRCQ"]
[Mon Jul 20 07:13:13.707551 2026] [security2:error] [pid 85094:tid 85164] [remote 132.148.72.88:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4e6a_nUl59BcEkkgF6dgABW0Q"]
[Mon Jul 20 07:13:13.852723 2026] [security2:error] [pid 85094:tid 85316] [client 182.8.226.25:29231] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "circafabrication.com"] [uri "/wp-json/batch/v1"] [unique_id "al4e6a_nUl59BcEkkgF6eQAAAWQ"]
[Mon Jul 20 07:13:13.975168 2026] [security2:error] [pid 85094:tid 85155] [remote 132.148.72.88:53184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4e6a_nUl59BcEkkgF6ggABKzs"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:13:13.975923 2026] [security2:error] [pid 85094:tid 85231] [client 194.61.41.66:64301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/colour.php"] [unique_id "al4e6a_nUl59BcEkkgF6gwAAARA"]
[Mon Jul 20 07:13:14.096219 2026] [security2:error] [pid 85094:tid 85321] [client 154.192.123.127:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4e6q_nUl59BcEkkgF6jQAAAWk"]
[Mon Jul 20 07:13:14.096374 2026] [security2:error] [pid 85094:tid 85321] [client 154.192.123.127:18408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4e6q_nUl59BcEkkgF6jQAAAWk"]
[Mon Jul 20 07:13:14.247911 2026] [security2:error] [pid 85094:tid 85298] [client 57.141.18.10:49332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e5q_nUl59BcEkkgF5TQABUi4"]
[Mon Jul 20 07:13:14.321802 2026] [security2:error] [pid 85094:tid 85300] [client 14.225.17.146:50312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4e6K_nUl59BcEkkgF6JAAAAVQ"], referer: http://lelandumc.org/2017
[Mon Jul 20 07:13:14.396658 2026] [security2:error] [pid 85094:tid 85193] [remote 194.164.192.228:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4e6q_nUl59BcEkkgF6oQABG2E"]
[Mon Jul 20 07:13:14.429438 2026] [security2:error] [pid 85094:tid 85245] [client 114.119.146.40:63055] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.fkconstructionfunding.com"] [uri "/los-angeles-iconic-6th-street-viaduct-project-reaches-engineering-milestone/"] [unique_id "al4e6q_nUl59BcEkkgF6pgAAAR4"], referer: https://www.fkconstructionfunding.com/los-angeles-iconic-6th-street-viaduct-project-reaches-engineering-milestone/
[Mon Jul 20 07:13:14.578087 2026] [security2:error] [pid 85094:tid 85198] [remote 194.164.192.228:48498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4e6q_nUl59BcEkkgF6uQABYGY"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 07:13:14.710620 2026] [autoindex:error] [pid 85094:tid 85229] [client 159.203.126.234:55150] AH01276: Cannot serve directory /home2/saintrhu/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:13:14.754386 2026] [security2:error] [pid 85094:tid 85323] [client 194.61.41.80:53361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/elp.php"] [unique_id "al4e6q_nUl59BcEkkgF6yAAAAWs"]
[Mon Jul 20 07:13:15.063595 2026] [security2:error] [pid 85094:tid 85240] [client 144.172.114.51:60500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/.env.backup"] [unique_id "al4e66_nUl59BcEkkgF64QAAARk"]
[Mon Jul 20 07:13:15.229079 2026] [security2:error] [pid 85094:tid 85265] [client 98.159.234.160:38461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4e66_nUl59BcEkkgF67gAAATI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:13:15.527408 2026] [security2:error] [pid 85094:tid 85316] [client 194.61.41.63:35233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/class-wp-customize-background-position-control-variable.php"] [unique_id "al4e66_nUl59BcEkkgF7AgAAAWQ"]
[Mon Jul 20 07:13:15.674404 2026] [security2:error] [pid 85094:tid 85239] [client 77.110.127.138:51621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpqhgUSVw7'%20OR%20584=(SELECT%20584%20FROM%20PG_SLEEP(15))--"] [unique_id "al4e66_nUl59BcEkkgF7EgAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:16.013781 2026] [security2:error] [pid 85094:tid 85240] [client 213.152.186.163:52042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.186.152.213.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e7K_nUl59BcEkkgF7KgAAARk"]
[Mon Jul 20 07:13:16.013877 2026] [security2:error] [pid 85094:tid 85240] [client 213.152.186.163:52042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e7K_nUl59BcEkkgF7KgAAARk"]
[Mon Jul 20 07:13:16.101490 2026] [security2:error] [pid 85094:tid 85284] [client 49.37.242.14:56844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4e6q_nUl59BcEkkgF62AAAAUQ"]
[Mon Jul 20 07:13:16.316801 2026] [security2:error] [pid 85094:tid 85278] [client 194.61.41.63:63625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/images/include.php"] [unique_id "al4e7K_nUl59BcEkkgF7YwAAAT8"]
[Mon Jul 20 07:13:16.730534 2026] [security2:error] [pid 85094:tid 85274] [client 74.208.214.194:42166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4e7K_nUl59BcEkkgF7gwAAATs"]
[Mon Jul 20 07:13:16.801256 2026] [security2:error] [pid 85094:tid 85228] [client 14.225.17.146:51991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4e7K_nUl59BcEkkgF7dwAAAQ0"], referer: http://samdothan.org/2017
[Mon Jul 20 07:13:17.029247 2026] [security2:error] [pid 85094:tid 85245] [client 208.96.241.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4e7K_nUl59BcEkkgF7ZwABHmc"], referer: https://packerjanitorial.com
[Mon Jul 20 07:13:17.056022 2026] [security2:error] [pid 85094:tid 85352] [client 194.61.41.91:46051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/av.php.php"] [unique_id "al4e7a_nUl59BcEkkgF7nwAAAYg"]
[Mon Jul 20 07:13:17.300712 2026] [security2:error] [pid 85094:tid 85294] [client 57.141.18.37:31220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e6a_nUl59BcEkkgF6TAABTiU"]
[Mon Jul 20 07:13:17.607916 2026] [security2:error] [pid 85094:tid 85310] [client 155.2.212.1:30965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4e7a_nUl59BcEkkgF72gAAAV4"]
[Mon Jul 20 07:13:17.609885 2026] [security2:error] [pid 85094:tid 85318] [client 155.2.212.15:44571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4e7a_nUl59BcEkkgF72wAAAWY"]
[Mon Jul 20 07:13:17.682384 2026] [security2:error] [pid 85094:tid 85260] [client 15.237.209.113:47850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.209.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4e7a_nUl59BcEkkgF75wAAAS0"]
[Mon Jul 20 07:13:17.682482 2026] [security2:error] [pid 85094:tid 85260] [client 15.237.209.113:47850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4e7a_nUl59BcEkkgF75wAAAS0"]
[Mon Jul 20 07:13:17.686051 2026] [security2:error] [pid 85094:tid 85158] [remote 182.77.62.24:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4e7a_nUl59BcEkkgF74gABfj4"]
[Mon Jul 20 07:13:17.848883 2026] [security2:error] [pid 85094:tid 85259] [client 194.61.41.92:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd-1/install.php"] [unique_id "al4e7a_nUl59BcEkkgF78wAAASw"]
[Mon Jul 20 07:13:17.913159 2026] [security2:error] [pid 85094:tid 85347] [client 45.157.112.60:36513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4e7a_nUl59BcEkkgF79wAAAYM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:13:18.092711 2026] [security2:error] [pid 85094:tid 85273] [client 14.225.17.146:52185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4e7a_nUl59BcEkkgF7ogAAATo"], referer: http://ancestralidadytrance.space/2017
[Mon Jul 20 07:13:18.314926 2026] [security2:error] [pid 85094:tid 85167] [remote 57.141.18.85:63310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3818564"] [unique_id "al4e7q_nUl59BcEkkgF8JAABWEc"]
[Mon Jul 20 07:13:18.384263 2026] [security2:error] [pid 85094:tid 85215] [remote 182.77.62.24:38662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4e7q_nUl59BcEkkgF8KAABhnc"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 07:13:18.423532 2026] [security2:error] [pid 85094:tid 85242] [client 14.225.17.146:52255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4e7a_nUl59BcEkkgF7owAAARs"], referer: http://hammadownenterprises.com/2017
[Mon Jul 20 07:13:18.656206 2026] [security2:error] [pid 85094:tid 85111] [remote 57.141.18.91:20744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4409190"] [unique_id "al4e7q_nUl59BcEkkgF8PAABcg8"]
[Mon Jul 20 07:13:18.668186 2026] [security2:error] [pid 85094:tid 85117] [remote 84.247.172.23:45974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4e7q_nUl59BcEkkgF8PgABHRU"]
[Mon Jul 20 07:13:18.673998 2026] [security2:error] [pid 85094:tid 85296] [client 104.234.53.87:57773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4e7q_nUl59BcEkkgF8QQAAAVA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:18.711499 2026] [security2:error] [pid 85094:tid 85337] [client 194.61.41.54:58801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/imgareaselect/wp-login.php"] [unique_id "al4e7q_nUl59BcEkkgF8PwAAAXk"]
[Mon Jul 20 07:13:18.722972 2026] [security2:error] [pid 85094:tid 85267] [client 103.144.65.217:56088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e7q_nUl59BcEkkgF8RAAAATQ"]
[Mon Jul 20 07:13:18.723104 2026] [security2:error] [pid 85094:tid 85267] [client 103.144.65.217:56088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e7q_nUl59BcEkkgF8RAAAATQ"]
[Mon Jul 20 07:13:18.818118 2026] [security2:error] [pid 85094:tid 85222] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e7q_nUl59BcEkkgF8SwABDX4"]
[Mon Jul 20 07:13:18.818270 2026] [security2:error] [pid 85094:tid 85228] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e7q_nUl59BcEkkgF8SwABDX4"]
[Mon Jul 20 07:13:18.819251 2026] [security2:error] [pid 85094:tid 85282] [client 77.110.127.138:51914] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 818 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e7q_nUl59BcEkkgF8SgAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:18.842839 2026] [security2:error] [pid 85094:tid 85213] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e7q_nUl59BcEkkgF8TwABYHU"]
[Mon Jul 20 07:13:18.843003 2026] [security2:error] [pid 85094:tid 85312] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e7q_nUl59BcEkkgF8TwABYHU"]
[Mon Jul 20 07:13:19.228653 2026] [security2:error] [pid 85094:tid 85207] [remote 188.40.28.4:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4e76_nUl59BcEkkgF8agABeG8"]
[Mon Jul 20 07:13:19.324232 2026] [security2:error] [pid 85094:tid 85232] [client 104.234.53.49:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4e76_nUl59BcEkkgF8eAAAARE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:19.387758 2026] [security2:error] [pid 85094:tid 85298] [client 77.110.127.138:51950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phplOjtHRjc')%20OR%20482=(SELECT%20482%20FROM%20PG_SLEEP(15))--"] [unique_id "al4e76_nUl59BcEkkgF8fgAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:19.422828 2026] [security2:error] [pid 85094:tid 85106] [remote 188.40.28.4:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4e76_nUl59BcEkkgF8gQABEAo"], referer: https://thechancersband.com/wp-login.php
[Mon Jul 20 07:13:19.423099 2026] [security2:error] [pid 85094:tid 85233] [client 194.61.41.251:43499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/upload/bilder/cong.php"] [unique_id "al4e76_nUl59BcEkkgF8gAAAARI"]
[Mon Jul 20 07:13:19.648475 2026] [security2:error] [pid 85094:tid 85228] [client 88.241.67.160:54805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e76_nUl59BcEkkgF8lwAAAQ0"]
[Mon Jul 20 07:13:19.649130 2026] [security2:error] [pid 85094:tid 85228] [client 88.241.67.160:54805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e76_nUl59BcEkkgF8lwAAAQ0"]
[Mon Jul 20 07:13:20.013489 2026] [security2:error] [pid 85094:tid 85324] [client 187.16.64.216:55166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e8K_nUl59BcEkkgF8tgAAAWw"]
[Mon Jul 20 07:13:20.013635 2026] [security2:error] [pid 85094:tid 85324] [client 187.16.64.216:55166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e8K_nUl59BcEkkgF8tgAAAWw"]
[Mon Jul 20 07:13:20.153307 2026] [security2:error] [pid 85094:tid 85330] [client 194.61.41.107:46371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/pass.php"] [unique_id "al4e8K_nUl59BcEkkgF8wAAAAXI"]
[Mon Jul 20 07:13:20.202692 2026] [security2:error] [pid 85094:tid 85265] [client 201.27.111.74:57015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e8K_nUl59BcEkkgF8wgAAATI"]
[Mon Jul 20 07:13:20.204744 2026] [security2:error] [pid 85094:tid 85265] [client 201.27.111.74:57015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e8K_nUl59BcEkkgF8wgAAATI"]
[Mon Jul 20 07:13:20.233831 2026] [security2:error] [pid 85094:tid 85321] [client 50.116.65.227:43456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4e8K_nUl59BcEkkgF8yQAAAWk"]
[Mon Jul 20 07:13:20.242777 2026] [security2:error] [pid 85094:tid 85260] [client 50.116.65.227:43460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4e8K_nUl59BcEkkgF8ywAAAS0"]
[Mon Jul 20 07:13:20.321341 2026] [security2:error] [pid 85094:tid 85283] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4e8K_nUl59BcEkkgF8ugAAAUM"]
[Mon Jul 20 07:13:20.795342 2026] [security2:error] [pid 85094:tid 85337] [client 50.116.65.227:43478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4e8K_nUl59BcEkkgF86gAAAXk"]
[Mon Jul 20 07:13:20.868678 2026] [security2:error] [pid 85094:tid 85325] [client 57.141.18.8:21984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e7a_nUl59BcEkkgF70wABbVw"]
[Mon Jul 20 07:13:20.944527 2026] [security2:error] [pid 85094:tid 85253] [client 194.61.41.86:28159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/l10n/class-wp-translations-interface.php"] [unique_id "al4e8K_nUl59BcEkkgF9BgAAASY"]
[Mon Jul 20 07:13:20.984046 2026] [security2:error] [pid 85094:tid 85295] [client 50.116.65.227:43482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4e8K_nUl59BcEkkgF8-gAAAU8"]
[Mon Jul 20 07:13:21.041642 2026] [security2:error] [pid 85094:tid 85169] [remote 124.55.178.99:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4e8a_nUl59BcEkkgF9DQABhUk"]
[Mon Jul 20 07:13:21.355042 2026] [security2:error] [pid 85094:tid 85228] [client 14.225.17.146:51905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4e8K_nUl59BcEkkgF85QAAAQ0"]
[Mon Jul 20 07:13:21.467611 2026] [security2:error] [pid 85094:tid 85319] [client 45.131.194.165:49657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.194.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4e8a_nUl59BcEkkgF9KwAAAWc"]
[Mon Jul 20 07:13:21.486641 2026] [security2:error] [pid 85094:tid 85158] [remote 124.55.178.99:60998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4e8a_nUl59BcEkkgF9NAABEj4"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:13:21.730373 2026] [security2:error] [pid 85094:tid 85327] [client 194.61.41.94:38903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/about5.php"] [unique_id "al4e8a_nUl59BcEkkgF9RAAAAW8"]
[Mon Jul 20 07:13:21.922588 2026] [security2:error] [pid 85094:tid 85232] [client 104.234.53.80:33761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4e8a_nUl59BcEkkgF9VgAAARE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:21.984606 2026] [security2:error] [pid 85094:tid 85292] [client 158.173.89.95:26417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4e8a_nUl59BcEkkgF9WgAAAUw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:13:22.006197 2026] [security2:error] [pid 85094:tid 85267] [client 13.74.155.112:14020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4e8a_nUl59BcEkkgF9WwAAATQ"]
[Mon Jul 20 07:13:22.096211 2026] [security2:error] [pid 85094:tid 85186] [remote 188.138.102.156:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4e8q_nUl59BcEkkgF9YAABFFo"]
[Mon Jul 20 07:13:22.138461 2026] [security2:error] [pid 85094:tid 85262] [client 13.74.155.112:14020] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4e8q_nUl59BcEkkgF9ZQAAAS8"]
[Mon Jul 20 07:13:22.297939 2026] [security2:error] [pid 85094:tid 85240] [client 77.110.127.138:52243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 182 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e8q_nUl59BcEkkgF9eAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:22.437718 2026] [security2:error] [pid 85094:tid 85277] [client 194.61.41.100:60581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/maint/lint-branch.php"] [unique_id "al4e8q_nUl59BcEkkgF9gQAAAT4"]
[Mon Jul 20 07:13:22.498065 2026] [security2:error] [pid 85094:tid 85157] [remote 188.138.102.156:58472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.102.138.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4e8q_nUl59BcEkkgF9hQABVD0"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:13:22.701707 2026] [security2:error] [pid 85094:tid 85250] [client 52.233.165.60:7362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4e8q_nUl59BcEkkgF9jwAAASM"]
[Mon Jul 20 07:13:22.797114 2026] [security2:error] [pid 85094:tid 85294] [client 50.116.65.227:43502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4e8q_nUl59BcEkkgF9ZAAAAU4"]
[Mon Jul 20 07:13:22.849848 2026] [security2:error] [pid 85094:tid 85286] [client 52.233.165.60:7362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4e8q_nUl59BcEkkgF9ngAAAUY"]
[Mon Jul 20 07:13:23.094136 2026] [security2:error] [pid 85094:tid 85260] [client 117.211.236.168:61811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e86_nUl59BcEkkgF9tQAAAS0"]
[Mon Jul 20 07:13:23.094266 2026] [security2:error] [pid 85094:tid 85260] [client 117.211.236.168:61811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e86_nUl59BcEkkgF9tQAAAS0"]
[Mon Jul 20 07:13:23.164028 2026] [security2:error] [pid 85094:tid 85273] [client 194.61.41.240:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/cong.php"] [unique_id "al4e86_nUl59BcEkkgF9wAAAATo"]
[Mon Jul 20 07:13:23.315265 2026] [security2:error] [pid 85094:tid 85299] [client 144.172.114.51:41430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/.env.bak"] [unique_id "al4e86_nUl59BcEkkgF9zQAAAVM"]
[Mon Jul 20 07:13:23.366059 2026] [security2:error] [pid 85094:tid 85306] [client 157.20.138.62:64398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e86_nUl59BcEkkgF92AAAAVo"]
[Mon Jul 20 07:13:23.366166 2026] [security2:error] [pid 85094:tid 85306] [client 157.20.138.62:64398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e86_nUl59BcEkkgF92AAAAVo"]
[Mon Jul 20 07:13:23.507351 2026] [security2:error] [pid 85094:tid 85338] [client 50.116.65.227:43506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4e8q_nUl59BcEkkgF9mgAAAXo"]
[Mon Jul 20 07:13:23.520145 2026] [security2:error] [pid 85094:tid 85260] [client 77.110.127.138:52386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpQU5DBWhK'))%20OR%20419=(SELECT%20419%20FROM%20PG_SLEEP(15))--"] [unique_id "al4e86_nUl59BcEkkgF95QAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:23.547623 2026] [security2:error] [pid 85094:tid 85323] [client 57.141.18.51:62130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e76_nUl59BcEkkgF8qQABawM"]
[Mon Jul 20 07:13:23.725724 2026] [autoindex:error] [pid 85094:tid 85244] [client 172.237.128.200:51460] AH01276: Cannot serve directory /home1/thesums1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:13:23.844059 2026] [security2:error] [pid 85094:tid 85348] [client 104.234.53.75:26851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4e86_nUl59BcEkkgF9_AAAAYQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:23.926610 2026] [security2:error] [pid 85094:tid 85300] [client 194.61.41.79:57131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/db.php"] [unique_id "al4e86_nUl59BcEkkgF-AgAAAVQ"]
[Mon Jul 20 07:13:23.979641 2026] [security2:error] [pid 85094:tid 85313] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4e86_nUl59BcEkkgF90wABYRI"], referer: http://ardhalwafaa.com/2017
[Mon Jul 20 07:13:24.009108 2026] [security2:error] [pid 85094:tid 85255] [client 154.192.123.127:18816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4e9K_nUl59BcEkkgF-CAAAASg"]
[Mon Jul 20 07:13:24.009218 2026] [security2:error] [pid 85094:tid 85255] [client 154.192.123.127:18816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4e9K_nUl59BcEkkgF-CAAAASg"]
[Mon Jul 20 07:13:24.064271 2026] [security2:error] [pid 85094:tid 85137] [remote 152.228.213.32:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4e9K_nUl59BcEkkgF-CwABWCk"]
[Mon Jul 20 07:13:24.160445 2026] [security2:error] [pid 85094:tid 85257] [client 14.225.17.146:52001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4e86_nUl59BcEkkgF94AAAASo"], referer: http://idigress.studio/2017
[Mon Jul 20 07:13:24.263050 2026] [security2:error] [pid 85094:tid 85138] [remote 152.228.213.32:50772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4e9K_nUl59BcEkkgF-HgABYyo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:13:24.324916 2026] [autoindex:error] [pid 85094:tid 85289] [client 172.238.172.176:34034] AH01276: Cannot serve directory /home1/thesums1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://thesummercampstore.com/
[Mon Jul 20 07:13:24.564125 2026] [security2:error] [pid 85094:tid 85282] [client 57.141.18.11:56034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e8a_nUl59BcEkkgF9DwABQhg"]
[Mon Jul 20 07:13:24.632888 2026] [security2:error] [pid 85094:tid 85325] [client 194.61.41.249:31191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/buy.php"] [unique_id "al4e9K_nUl59BcEkkgF-OAAAAW0"]
[Mon Jul 20 07:13:24.750690 2026] [security2:error] [pid 85094:tid 85336] [client 104.234.53.62:55735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4e9K_nUl59BcEkkgF-QAAAAXg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:24.928961 2026] [core:error] [pid 85094:tid 85265] [client 14.225.17.146:59974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2017
[Mon Jul 20 07:13:24.928987 2026] [core:error] [pid 85094:tid 85265] [client 14.225.17.146:59974] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2017
[Mon Jul 20 07:13:25.242860 2026] [security2:error] [pid 85094:tid 85325] [client 77.110.127.138:52564] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 987 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e9a_nUl59BcEkkgF-bAAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:25.286302 2026] [security2:error] [pid 85094:tid 85337] [client 57.141.18.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4e9K_nUl59BcEkkgF-UwAAAXk"]
[Mon Jul 20 07:13:25.432524 2026] [security2:error] [pid 85094:tid 85258] [client 194.61.41.85:60837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/db.php"] [unique_id "al4e9a_nUl59BcEkkgF-ggAAASs"]
[Mon Jul 20 07:13:25.595744 2026] [security2:error] [pid 85094:tid 85268] [client 14.225.17.146:51705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4e9K_nUl59BcEkkgF-GAAAATU"], referer: http://alexsandbergmusic.com/2017
[Mon Jul 20 07:13:25.740299 2026] [security2:error] [pid 85094:tid 85156] [remote 20.153.140.50:46460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4e9a_nUl59BcEkkgF-kwABXjw"]
[Mon Jul 20 07:13:25.740437 2026] [security2:error] [pid 85094:tid 85310] [client 20.153.140.50:46460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4e9a_nUl59BcEkkgF-kwABXjw"]
[Mon Jul 20 07:13:26.200035 2026] [security2:error] [pid 85094:tid 85252] [client 170.64.227.219:51900] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.meditacionmiami.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4e9q_nUl59BcEkkgF-swAAASU"]
[Mon Jul 20 07:13:26.234351 2026] [security2:error] [pid 85094:tid 85232] [client 194.61.41.86:24381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/function/install.php"] [unique_id "al4e9q_nUl59BcEkkgF-tgAAARE"]
[Mon Jul 20 07:13:26.700819 2026] [security2:error] [pid 85094:tid 85333] [client 77.110.127.138:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4e9q_nUl59BcEkkgF-4wAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:26.766432 2026] [security2:error] [pid 85094:tid 85308] [client 104.234.53.59:41369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4e9q_nUl59BcEkkgF-2wAAAVw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:26.901476 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e9q_nUl59BcEkkgF-9wAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:26.901637 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:52770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e9q_nUl59BcEkkgF-9wAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:26.952128 2026] [security2:error] [pid 85094:tid 85260] [client 194.61.41.242:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/tflow/av.php"] [unique_id "al4e9q_nUl59BcEkkgF--QAAAS0"]
[Mon Jul 20 07:13:26.960772 2026] [security2:error] [pid 85094:tid 85271] [client 57.141.18.28:64928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e86_nUl59BcEkkgF9vAABOG0"]
[Mon Jul 20 07:13:27.033889 2026] [security2:error] [pid 85094:tid 85291] [client 104.234.53.59:41369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4e9q_nUl59BcEkkgF--wAAAUs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:27.047393 2026] [security2:error] [pid 85094:tid 85245] [client 14.182.195.220:52591] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4e96_nUl59BcEkkgF_AwAAAR4"]
[Mon Jul 20 07:13:27.090365 2026] [security2:error] [pid 85094:tid 85338] [client 77.110.127.138:52798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4e96_nUl59BcEkkgF_CgAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:27.147742 2026] [security2:error] [pid 85094:tid 85244] [client 77.110.127.138:52233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4e96_nUl59BcEkkgF_DAAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:27.239340 2026] [security2:error] [pid 85094:tid 85318] [client 77.110.127.138:52243] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/if(now()=sysdate(),sleep(15),0)/dist/wp-seo-local-frontend-1390.js"] [unique_id "al4e96_nUl59BcEkkgF_EQAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:27.542200 2026] [security2:error] [pid 85094:tid 85116] [remote 81.173.115.7:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4e96_nUl59BcEkkgF_JwABYxQ"]
[Mon Jul 20 07:13:27.553213 2026] [security2:error] [pid 85094:tid 85292] [client 77.110.127.138:52816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4e96_nUl59BcEkkgF_GQAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:27.732579 2026] [security2:error] [pid 85094:tid 85259] [client 194.61.41.62:59137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/dist/bypass.php"] [unique_id "al4e96_nUl59BcEkkgF_OAAAASw"]
[Mon Jul 20 07:13:27.956022 2026] [security2:error] [pid 85094:tid 85235] [client 77.110.127.138:52360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4e96_nUl59BcEkkgF_OwAAARQ"]
[Mon Jul 20 07:13:28.160161 2026] [security2:error] [pid 85094:tid 85231] [client 50.116.65.227:43562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4e-K_nUl59BcEkkgF_VgAAARA"]
[Mon Jul 20 07:13:28.163563 2026] [security2:error] [pid 85094:tid 85229] [client 14.225.17.146:59868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4e9q_nUl59BcEkkgF-2gAAAQ4"], referer: http://recruitinginsight.us/2017
[Mon Jul 20 07:13:28.271880 2026] [security2:error] [pid 85094:tid 85289] [client 77.110.127.138:52401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4e-K_nUl59BcEkkgF_TwAAAUk"]
[Mon Jul 20 07:13:28.300572 2026] [security2:error] [pid 85094:tid 85256] [client 144.172.114.51:41440] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/.env.old"] [unique_id "al4e-K_nUl59BcEkkgF_YwAAASk"]
[Mon Jul 20 07:13:28.424249 2026] [security2:error] [pid 85094:tid 85310] [client 43.205.139.3:65202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4e-K_nUl59BcEkkgF_aAAAAV4"]
[Mon Jul 20 07:13:28.461011 2026] [security2:error] [pid 85094:tid 85315] [client 104.234.53.91:22783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4e-K_nUl59BcEkkgF_awAAAWM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:28.551044 2026] [security2:error] [pid 85094:tid 85235] [client 194.61.41.56:22905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/testt.php"] [unique_id "al4e-K_nUl59BcEkkgF_cAAAARQ"]
[Mon Jul 20 07:13:28.642588 2026] [security2:error] [pid 85094:tid 85135] [remote 81.173.115.7:33978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4e-K_nUl59BcEkkgF_fAABZyc"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:13:28.795420 2026] [security2:error] [pid 85094:tid 85228] [client 77.110.127.138:52964] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e-K_nUl59BcEkkgF_gQAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:29.173566 2026] [security2:error] [pid 85094:tid 85199] [remote 182.77.62.24:35742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4e-a_nUl59BcEkkgF_nAABOGc"]
[Mon Jul 20 07:13:29.324025 2026] [security2:error] [pid 85094:tid 85345] [client 57.141.18.120:47924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e9a_nUl59BcEkkgF-fwABgS8"]
[Mon Jul 20 07:13:29.355012 2026] [security2:error] [pid 85094:tid 85308] [client 194.61.41.95:28473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/goods.php"] [unique_id "al4e-a_nUl59BcEkkgF_qQAAAVw"]
[Mon Jul 20 07:13:29.473541 2026] [security2:error] [pid 85094:tid 85349] [client 103.144.65.217:56549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e-a_nUl59BcEkkgF_tAAAAYU"]
[Mon Jul 20 07:13:29.473675 2026] [security2:error] [pid 85094:tid 85349] [client 103.144.65.217:56549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4e-a_nUl59BcEkkgF_tAAAAYU"]
[Mon Jul 20 07:13:29.478775 2026] [security2:error] [pid 85094:tid 85147] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e-a_nUl59BcEkkgF_tQABFzM"]
[Mon Jul 20 07:13:29.478923 2026] [security2:error] [pid 85094:tid 85238] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4e-a_nUl59BcEkkgF_tQABFzM"]
[Mon Jul 20 07:13:29.488829 2026] [security2:error] [pid 85094:tid 85179] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e-a_nUl59BcEkkgF_tgABHlM"]
[Mon Jul 20 07:13:29.489041 2026] [security2:error] [pid 85094:tid 85245] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4e-a_nUl59BcEkkgF_tgABHlM"]
[Mon Jul 20 07:13:29.929514 2026] [security2:error] [pid 85094:tid 85246] [client 104.234.53.87:64605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4e-a_nUl59BcEkkgF_0QAAAR8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:29.931759 2026] [security2:error] [pid 85094:tid 85125] [remote 182.77.62.24:35742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4e-a_nUl59BcEkkgF_1gABhB0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:13:30.101156 2026] [core:error] [pid 85094:tid 85349] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:30.101180 2026] [core:error] [pid 85094:tid 85349] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:30.136206 2026] [security2:error] [pid 85094:tid 85257] [client 194.61.41.55:46995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/sad.php"] [unique_id "al4e-q_nUl59BcEkkgF_7AAAASo"]
[Mon Jul 20 07:13:30.176239 2026] [security2:error] [pid 85094:tid 85171] [remote 57.141.18.89:45034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4459097"] [unique_id "al4e-q_nUl59BcEkkgF_7wABYEs"]
[Mon Jul 20 07:13:30.196471 2026] [security2:error] [pid 85094:tid 85315] [client 13.232.231.177:48408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4e-q_nUl59BcEkkgF_8gAAAWM"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:13:30.257481 2026] [ssl:error] [pid 85094:tid 85228] [client 104.48.69.105:34168] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:13:30.334007 2026] [security2:error] [pid 85094:tid 85342] [client 88.241.67.160:53485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e-q_nUl59BcEkkgGAAAAAAX4"]
[Mon Jul 20 07:13:30.334425 2026] [security2:error] [pid 85094:tid 85342] [client 88.241.67.160:53485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4e-q_nUl59BcEkkgGAAAAAAX4"]
[Mon Jul 20 07:13:30.433233 2026] [security2:error] [pid 85094:tid 85336] [client 201.27.111.74:57516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e-q_nUl59BcEkkgGACAAAAXg"]
[Mon Jul 20 07:13:30.433343 2026] [security2:error] [pid 85094:tid 85336] [client 201.27.111.74:57516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4e-q_nUl59BcEkkgGACAAAAXg"]
[Mon Jul 20 07:13:30.442810 2026] [security2:error] [pid 85094:tid 85301] [client 77.110.127.138:53142] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/dist/wp-seo-local-frontend-1390.js"] [unique_id "al4e-q_nUl59BcEkkgGACgAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:30.446840 2026] [security2:error] [pid 85094:tid 85317] [client 57.141.18.94:20246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e9q_nUl59BcEkkgF-2QABZVk"]
[Mon Jul 20 07:13:30.458192 2026] [security2:error] [pid 85094:tid 85289] [client 114.119.133.89:61479] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/thank-you"] [unique_id "al4e-q_nUl59BcEkkgGADQAAAUk"], referer: https://mourgroup.com/thank-you
[Mon Jul 20 07:13:30.546332 2026] [security2:error] [pid 85094:tid 85263] [client 57.141.18.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4e-q_nUl59BcEkkgGABgAAATA"]
[Mon Jul 20 07:13:30.706149 2026] [security2:error] [pid 85094:tid 85341] [client 187.16.64.216:55748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e-q_nUl59BcEkkgGAJgAAAX0"]
[Mon Jul 20 07:13:30.706322 2026] [security2:error] [pid 85094:tid 85341] [client 187.16.64.216:55748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4e-q_nUl59BcEkkgGAJgAAAX0"]
[Mon Jul 20 07:13:30.710667 2026] [security2:error] [pid 85094:tid 85309] [client 14.225.17.146:58875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4e-a_nUl59BcEkkgF_wAAAAV0"], referer: http://nikkidesigns.net/2017
[Mon Jul 20 07:13:30.946683 2026] [security2:error] [pid 85094:tid 85301] [client 194.61.41.253:20027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sitemaps/wp-conflg.php"] [unique_id "al4e-q_nUl59BcEkkgGASQAAAVU"]
[Mon Jul 20 07:13:31.155772 2026] [security2:error] [pid 85094:tid 85323] [client 77.110.127.138:53226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e-6_nUl59BcEkkgGAWAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:31.155863 2026] [security2:error] [pid 85094:tid 85323] [client 77.110.127.138:53226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e-6_nUl59BcEkkgGAWAAAAWs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:31.726381 2026] [security2:error] [pid 85094:tid 85326] [client 57.141.18.55:34754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e96_nUl59BcEkkgF_QQABbg0"]
[Mon Jul 20 07:13:31.730711 2026] [security2:error] [pid 85094:tid 85275] [client 194.61.41.78:50149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/wp-includes/assets/script-loader-packages.php"] [unique_id "al4e-6_nUl59BcEkkgGAiQAAATw"]
[Mon Jul 20 07:13:31.876745 2026] [security2:error] [pid 85094:tid 85231] [client 14.225.17.146:50709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4e-6_nUl59BcEkkgGAaAAAARA"], referer: http://drewsasburyparkbeachhouse.com/2017
[Mon Jul 20 07:13:31.919084 2026] [security2:error] [pid 85094:tid 85267] [client 216.73.216.123:44450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techexecutive.me"] [uri "/index.php"] [unique_id "al4e-q_nUl59BcEkkgGAKAABNGA"]
[Mon Jul 20 07:13:32.073235 2026] [security2:error] [pid 85094:tid 85265] [client 57.141.18.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4e-6_nUl59BcEkkgGAkAAAATI"]
[Mon Jul 20 07:13:32.384826 2026] [security2:error] [pid 85094:tid 85275] [client 216.73.216.123:44450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techexecutive.me"] [uri "/index.php"] [unique_id "al4e_K_nUl59BcEkkgGAuAABPEM"]
[Mon Jul 20 07:13:32.416065 2026] [security2:error] [pid 85094:tid 85169] [remote 84.247.172.23:54792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4e_K_nUl59BcEkkgGAywABekk"], referer: https://thslogistics.net/wp-login.php
[Mon Jul 20 07:13:32.544179 2026] [security2:error] [pid 85094:tid 85342] [client 194.61.41.73:43719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/login.php"] [unique_id "al4e_K_nUl59BcEkkgGA3gAAAX4"]
[Mon Jul 20 07:13:32.694845 2026] [security2:error] [pid 85094:tid 85278] [client 14.225.17.146:59701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4e_K_nUl59BcEkkgGA4AAAAT8"]
[Mon Jul 20 07:13:32.721880 2026] [security2:error] [pid 85094:tid 85283] [client 77.110.127.138:53411] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4e_K_nUl59BcEkkgGA6wAAAUM"]
[Mon Jul 20 07:13:32.730484 2026] [security2:error] [pid 85094:tid 85253] [client 50.116.65.227:18168] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4e_K_nUl59BcEkkgGA7QAAASY"]
[Mon Jul 20 07:13:32.739474 2026] [security2:error] [pid 85094:tid 85340] [client 50.116.65.227:18172] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4e_K_nUl59BcEkkgGA7wAAAXw"]
[Mon Jul 20 07:13:32.824727 2026] [security2:error] [pid 85094:tid 85325] [client 74.208.214.194:56868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4e_K_nUl59BcEkkgGA9gAAAW0"]
[Mon Jul 20 07:13:32.855070 2026] [security2:error] [pid 85094:tid 85232] [client 104.234.53.61:22201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4e_K_nUl59BcEkkgGA-QAAARE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:32.942547 2026] [security2:error] [pid 85094:tid 85350] [client 77.110.127.138:53429] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/dist/wp-seo-local-frontend-1390.js"] [unique_id "al4e_K_nUl59BcEkkgGBBAAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:33.335624 2026] [security2:error] [pid 85094:tid 85249] [client 194.61.41.107:33849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/network.php"] [unique_id "al4e_a_nUl59BcEkkgGBGAAAASI"]
[Mon Jul 20 07:13:33.531000 2026] [security2:error] [pid 85094:tid 85231] [client 117.211.236.168:62404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e_a_nUl59BcEkkgGBKAAAARA"]
[Mon Jul 20 07:13:33.531091 2026] [security2:error] [pid 85094:tid 85231] [client 117.211.236.168:62404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4e_a_nUl59BcEkkgGBKAAAARA"]
[Mon Jul 20 07:13:33.543091 2026] [security2:error] [pid 85094:tid 85225] [client 14.225.17.146:51406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4e_K_nUl59BcEkkgGAugAAAQo"], referer: http://northbrookcpa.ca/2017
[Mon Jul 20 07:13:33.626140 2026] [security2:error] [pid 85094:tid 85348] [client 77.110.127.138:53500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_a_nUl59BcEkkgGBMwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:33.626243 2026] [security2:error] [pid 85094:tid 85348] [client 77.110.127.138:53500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_a_nUl59BcEkkgGBMwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:33.806523 2026] [security2:error] [pid 85094:tid 85332] [client 14.225.17.146:57477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4e_a_nUl59BcEkkgGBNwAAAXQ"], referer: http://ravmike.com/2017
[Mon Jul 20 07:13:33.900360 2026] [security2:error] [pid 85094:tid 85246] [client 77.110.127.138:53530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_a_nUl59BcEkkgGBRQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:33.900458 2026] [security2:error] [pid 85094:tid 85246] [client 77.110.127.138:53530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_a_nUl59BcEkkgGBRQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:33.994929 2026] [security2:error] [pid 85094:tid 85232] [client 157.20.138.62:64914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e_a_nUl59BcEkkgGBTAAAARE"]
[Mon Jul 20 07:13:33.995034 2026] [security2:error] [pid 85094:tid 85232] [client 157.20.138.62:64914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4e_a_nUl59BcEkkgGBTAAAARE"]
[Mon Jul 20 07:13:33.995465 2026] [security2:error] [pid 85094:tid 85181] [remote 173.212.252.15:35484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4e_a_nUl59BcEkkgGBTQABMVU"]
[Mon Jul 20 07:13:34.119152 2026] [security2:error] [pid 85094:tid 85295] [client 77.110.127.138:53555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBWwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.119152 2026] [security2:error] [pid 85094:tid 85336] [client 194.61.41.68:41919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/alfa.php"] [unique_id "al4e_q_nUl59BcEkkgGBXAAAAXg"]
[Mon Jul 20 07:13:34.119248 2026] [security2:error] [pid 85094:tid 85295] [client 77.110.127.138:53555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBWwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.206024 2026] [security2:error] [pid 85094:tid 85178] [remote 173.212.252.15:35484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4e_q_nUl59BcEkkgGBZQABhlI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:13:34.211787 2026] [security2:error] [pid 85094:tid 85233] [client 57.141.18.46:25846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e-q_nUl59BcEkkgGAFAABEho"]
[Mon Jul 20 07:13:34.290707 2026] [security2:error] [pid 85094:tid 85333] [client 77.110.127.138:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBbwAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.290817 2026] [security2:error] [pid 85094:tid 85333] [client 77.110.127.138:53570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBbwAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.524877 2026] [security2:error] [pid 85094:tid 85259] [client 77.110.127.138:53578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBhgAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.525051 2026] [security2:error] [pid 85094:tid 85259] [client 77.110.127.138:53578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBhgAAASw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.635598 2026] [security2:error] [pid 85094:tid 85348] [client 77.110.127.138:52822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBjwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.635692 2026] [security2:error] [pid 85094:tid 85348] [client 77.110.127.138:52822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBjwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.664432 2026] [security2:error] [pid 85094:tid 85309] [client 154.192.123.127:17137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4e_q_nUl59BcEkkgGBlQAAAV0"]
[Mon Jul 20 07:13:34.664554 2026] [security2:error] [pid 85094:tid 85309] [client 154.192.123.127:17137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4e_q_nUl59BcEkkgGBlQAAAV0"]
[Mon Jul 20 07:13:34.714989 2026] [security2:error] [pid 85094:tid 85245] [client 77.75.79.17:23972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mollycahill.com"] [uri "/instagram-reels-music/"] [unique_id "al4e_q_nUl59BcEkkgGBlwAAAR4"]
[Mon Jul 20 07:13:34.715081 2026] [security2:error] [pid 85094:tid 85245] [client 77.75.79.17:23972] ModSecurity: Warning. Matched phrase "Seznam" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mollycahill.com"] [uri "/instagram-reels-music/"] [unique_id "al4e_q_nUl59BcEkkgGBlwAAAR4"]
[Mon Jul 20 07:13:34.733350 2026] [security2:error] [pid 85094:tid 85307] [client 104.234.53.57:55107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4e_q_nUl59BcEkkgGBmgAAAVs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:34.794051 2026] [security2:error] [pid 85094:tid 85337] [client 77.110.127.138:53587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBnwAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.794165 2026] [security2:error] [pid 85094:tid 85337] [client 77.110.127.138:53587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4e_q_nUl59BcEkkgGBnwAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:34.854126 2026] [security2:error] [pid 85094:tid 85274] [client 194.61.41.78:57149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sitemaps/chosen.php"] [unique_id "al4e_q_nUl59BcEkkgGBpgAAATs"]
[Mon Jul 20 07:13:35.209134 2026] [core:error] [pid 85094:tid 85250] [client 14.225.17.146:59183] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:35.209153 2026] [core:error] [pid 85094:tid 85250] [client 14.225.17.146:59183] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:35.225607 2026] [security2:error] [pid 85094:tid 85226] [client 57.141.18.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4e_6_nUl59BcEkkgGBugAAAQs"]
[Mon Jul 20 07:13:35.261216 2026] [security2:error] [pid 85094:tid 85240] [client 57.141.18.25:35586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e-6_nUl59BcEkkgGAbwABGWU"]
[Mon Jul 20 07:13:35.363911 2026] [security2:error] [pid 85094:tid 85244] [client 176.78.179.156:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4e_q_nUl59BcEkkgGBrQABHXE"], referer: https://packerjanitorial.com
[Mon Jul 20 07:13:35.588658 2026] [security2:error] [pid 85094:tid 85283] [client 14.225.17.146:60464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4e_a_nUl59BcEkkgGBHgAAAUM"], referer: http://latiendadejorge.com.gt/2017
[Mon Jul 20 07:13:35.641281 2026] [security2:error] [pid 85094:tid 85294] [client 194.61.41.102:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wikindex.php"] [unique_id "al4e_6_nUl59BcEkkgGB6wAAAU4"]
[Mon Jul 20 07:13:36.095595 2026] [security2:error] [pid 85094:tid 85290] [client 144.172.114.51:42806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/.env"] [unique_id "al4fAK_nUl59BcEkkgGCDAAAAUo"]
[Mon Jul 20 07:13:36.295075 2026] [security2:error] [pid 85094:tid 85259] [client 3.84.173.24:59984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.173.84.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fAK_nUl59BcEkkgGCFgAAASw"]
[Mon Jul 20 07:13:36.295155 2026] [security2:error] [pid 85094:tid 85259] [client 3.84.173.24:59984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fAK_nUl59BcEkkgGCFgAAASw"]
[Mon Jul 20 07:13:36.433991 2026] [security2:error] [pid 85094:tid 85252] [client 194.61.41.243:31879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/seoo/alfa.php"] [unique_id "al4fAK_nUl59BcEkkgGCLwAAASU"]
[Mon Jul 20 07:13:36.669790 2026] [ssl:error] [pid 85094:tid 85256] [client 104.48.69.105:34176] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:13:37.242115 2026] [security2:error] [pid 85094:tid 85250] [client 194.61.41.88:47383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/Cache/index.php"] [unique_id "al4fAa_nUl59BcEkkgGCbwAAASM"]
[Mon Jul 20 07:13:37.355517 2026] [security2:error] [pid 85094:tid 85342] [client 66.249.65.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rentorangegrove.com"] [uri "/index.php"] [unique_id "al4fAa_nUl59BcEkkgGCbQAAAX4"]
[Mon Jul 20 07:13:37.450010 2026] [ssl:error] [pid 85094:tid 85230] [client 104.48.69.105:34190] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:13:37.987348 2026] [security2:error] [pid 85094:tid 85273] [client 14.225.17.146:58973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4fAa_nUl59BcEkkgGCpAAAATo"], referer: http://taskidsvirginia.com/2017
[Mon Jul 20 07:13:38.025890 2026] [security2:error] [pid 85094:tid 85253] [client 194.61.41.76:39459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/about.php"] [unique_id "al4fAq_nUl59BcEkkgGCswAAASY"]
[Mon Jul 20 07:13:38.027184 2026] [security2:error] [pid 85094:tid 85328] [client 57.141.18.19:26660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e_q_nUl59BcEkkgGBZAABcAc"]
[Mon Jul 20 07:13:38.045394 2026] [security2:error] [pid 85094:tid 85181] [remote 72.167.132.114:41048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fAq_nUl59BcEkkgGCtAABVVU"]
[Mon Jul 20 07:13:38.078295 2026] [security2:error] [pid 85094:tid 85321] [client 77.110.127.138:53833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fAq_nUl59BcEkkgGCvQAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:38.078378 2026] [security2:error] [pid 85094:tid 85321] [client 77.110.127.138:53833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fAq_nUl59BcEkkgGCvQAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:38.211828 2026] [security2:error] [pid 85094:tid 85256] [client 144.172.114.51:38386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-config.php"] [unique_id "al4fAq_nUl59BcEkkgGCyAAAASk"]
[Mon Jul 20 07:13:38.244457 2026] [security2:error] [pid 85094:tid 85270] [client 14.225.17.146:58636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4fAK_nUl59BcEkkgGCNgAAATc"], referer: http://nwcarvingacademy.com/2017
[Mon Jul 20 07:13:38.272261 2026] [security2:error] [pid 85094:tid 85140] [remote 72.167.132.114:41048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fAq_nUl59BcEkkgGC0gABOyw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:13:38.724487 2026] [security2:error] [pid 85094:tid 85240] [client 194.61.41.252:45345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/as.php"] [unique_id "al4fAq_nUl59BcEkkgGC-wAAARk"]
[Mon Jul 20 07:13:38.929493 2026] [security2:error] [pid 85094:tid 85211] [remote 188.166.241.141:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fAq_nUl59BcEkkgGDCQABcHM"]
[Mon Jul 20 07:13:39.029449 2026] [security2:error] [pid 85094:tid 85311] [client 57.141.18.90:23720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4e_6_nUl59BcEkkgGBzgABXzI"]
[Mon Jul 20 07:13:39.277852 2026] [security2:error] [pid 85094:tid 85238] [client 14.225.17.146:60298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4fA6_nUl59BcEkkgGDFgAAARc"], referer: https://nwcarvingacademy.com/2017
[Mon Jul 20 07:13:39.328190 2026] [security2:error] [pid 85094:tid 85197] [remote 188.166.241.141:57814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fA6_nUl59BcEkkgGDKgABfmU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:13:39.437928 2026] [security2:error] [pid 85094:tid 85343] [client 14.225.17.146:59208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4fA6_nUl59BcEkkgGDJgAAAX8"], referer: http://mobilesurvsolutions.com/2017
[Mon Jul 20 07:13:39.455719 2026] [security2:error] [pid 85094:tid 85269] [client 194.61.41.91:64617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/about.php"] [unique_id "al4fA6_nUl59BcEkkgGDNQAAATY"]
[Mon Jul 20 07:13:39.628207 2026] [security2:error] [pid 85094:tid 85206] [remote 192.241.143.148:35338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fA6_nUl59BcEkkgGDQwABb24"]
[Mon Jul 20 07:13:39.801917 2026] [security2:error] [pid 85094:tid 85118] [remote 192.241.143.148:35338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fA6_nUl59BcEkkgGDUQABGRY"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:13:39.966335 2026] [security2:error] [pid 85094:tid 85283] [client 103.144.65.217:57003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fA6_nUl59BcEkkgGDZgAAAUM"]
[Mon Jul 20 07:13:39.966439 2026] [security2:error] [pid 85094:tid 85283] [client 103.144.65.217:57003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fA6_nUl59BcEkkgGDZgAAAUM"]
[Mon Jul 20 07:13:40.001861 2026] [security2:error] [pid 85094:tid 85199] [remote 47.86.33.52:60722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4fA6_nUl59BcEkkgGDawABFmc"]
[Mon Jul 20 07:13:40.038883 2026] [security2:error] [pid 85094:tid 85346] [client 14.225.17.146:55610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4fA6_nUl59BcEkkgGDXwAAAYI"], referer: http://betterbonddogtraining.com/2017
[Mon Jul 20 07:13:40.053667 2026] [security2:error] [pid 85094:tid 85163] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fBK_nUl59BcEkkgGDcAABZUM"]
[Mon Jul 20 07:13:40.053836 2026] [security2:error] [pid 85094:tid 85317] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fBK_nUl59BcEkkgGDcAABZUM"]
[Mon Jul 20 07:13:40.185534 2026] [security2:error] [pid 85094:tid 85147] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fBK_nUl59BcEkkgGDgAABKDM"]
[Mon Jul 20 07:13:40.185663 2026] [security2:error] [pid 85094:tid 85255] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fBK_nUl59BcEkkgGDgAABKDM"]
[Mon Jul 20 07:13:40.248731 2026] [security2:error] [pid 85094:tid 85240] [client 194.61.41.69:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/simi.php"] [unique_id "al4fBK_nUl59BcEkkgGDigAAARk"]
[Mon Jul 20 07:13:40.500505 2026] [security2:error] [pid 85094:tid 85273] [client 144.172.114.51:40848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-config.php.bak"] [unique_id "al4fBK_nUl59BcEkkgGDnwAAATo"]
[Mon Jul 20 07:13:40.741841 2026] [security2:error] [pid 85094:tid 85233] [client 77.110.127.138:54014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fBK_nUl59BcEkkgGDtgAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:40.741944 2026] [security2:error] [pid 85094:tid 85233] [client 77.110.127.138:54014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fBK_nUl59BcEkkgGDtgAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:40.839250 2026] [security2:error] [pid 85094:tid 85258] [client 14.225.17.146:60129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4fBK_nUl59BcEkkgGDqwAAASs"], referer: http://soloceos.com/2017
[Mon Jul 20 07:13:40.936789 2026] [security2:error] [pid 85094:tid 85237] [client 88.241.67.160:56202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fBK_nUl59BcEkkgGDwgAAARY"]
[Mon Jul 20 07:13:40.936973 2026] [security2:error] [pid 85094:tid 85237] [client 88.241.67.160:56202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fBK_nUl59BcEkkgGDwgAAARY"]
[Mon Jul 20 07:13:41.058682 2026] [security2:error] [pid 85094:tid 85309] [client 194.61.41.83:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/images/chosen.php"] [unique_id "al4fBa_nUl59BcEkkgGDzAAAAV0"]
[Mon Jul 20 07:13:41.197099 2026] [security2:error] [pid 85094:tid 85270] [client 201.27.111.74:58023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fBa_nUl59BcEkkgGD3gAAATc"]
[Mon Jul 20 07:13:41.197314 2026] [security2:error] [pid 85094:tid 85270] [client 201.27.111.74:58023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fBa_nUl59BcEkkgGD3gAAATc"]
[Mon Jul 20 07:13:41.204959 2026] [security2:error] [pid 85094:tid 85256] [client 74.7.227.179:59412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4fBa_nUl59BcEkkgGDygABKTY"], referer: https://tejasenvironmental.com/p=1405409
[Mon Jul 20 07:13:41.349538 2026] [security2:error] [pid 85094:tid 85299] [client 187.16.64.216:56325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fBa_nUl59BcEkkgGD5gAAAVM"]
[Mon Jul 20 07:13:41.349720 2026] [security2:error] [pid 85094:tid 85299] [client 187.16.64.216:56325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fBa_nUl59BcEkkgGD5gAAAVM"]
[Mon Jul 20 07:13:41.383457 2026] [security2:error] [pid 85094:tid 85253] [client 113.160.97.242:57986] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4fBa_nUl59BcEkkgGD6AAAASY"]
[Mon Jul 20 07:13:41.432418 2026] [security2:error] [pid 85094:tid 85229] [client 50.116.65.227:23230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4fBa_nUl59BcEkkgGD8gAAAQ4"]
[Mon Jul 20 07:13:41.435730 2026] [security2:error] [pid 85094:tid 85262] [client 14.225.17.146:55798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4fA6_nUl59BcEkkgGDYgAAAS8"]
[Mon Jul 20 07:13:41.788182 2026] [security2:error] [pid 85094:tid 85289] [client 57.141.18.26:55842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fAq_nUl59BcEkkgGCtQABSU4"]
[Mon Jul 20 07:13:41.804944 2026] [security2:error] [pid 85094:tid 85283] [client 49.37.242.14:57381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fBa_nUl59BcEkkgGD1QAAAUM"]
[Mon Jul 20 07:13:41.852496 2026] [security2:error] [pid 85094:tid 85277] [client 194.61.41.245:49681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/gold.php"] [unique_id "al4fBa_nUl59BcEkkgGEEgAAAT4"]
[Mon Jul 20 07:13:41.902219 2026] [security2:error] [pid 85094:tid 85318] [client 14.225.17.146:62013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4fBa_nUl59BcEkkgGEDgAAAWY"], referer: http://thesoloceos.com/2017
[Mon Jul 20 07:13:41.904306 2026] [security2:error] [pid 85094:tid 85267] [client 14.225.17.146:55595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4fBa_nUl59BcEkkgGEEQAAATQ"], referer: http://grndl.com/2017
[Mon Jul 20 07:13:42.112796 2026] [security2:error] [pid 85094:tid 85294] [client 14.225.17.146:59126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4fBq_nUl59BcEkkgGEIAAAAU4"], referer: http://katsklar.com/2017
[Mon Jul 20 07:13:42.154729 2026] [security2:error] [pid 85094:tid 85352] [client 14.225.17.146:60243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4fBK_nUl59BcEkkgGDlAAAAYg"], referer: http://secretkeynumerology.com/2017
[Mon Jul 20 07:13:42.167290 2026] [security2:error] [pid 85094:tid 85340] [client 74.7.244.30:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jqq.cyv.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4fBq_nUl59BcEkkgGENwAAAXw"]
[Mon Jul 20 07:13:42.172498 2026] [security2:error] [pid 85094:tid 85253] [client 74.7.244.30:34046] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.jqq.cyv.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4fBq_nUl59BcEkkgGELwABJlI"]
[Mon Jul 20 07:13:42.354022 2026] [security2:error] [pid 85094:tid 85201] [remote 103.75.185.95:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fBq_nUl59BcEkkgGEQwABNWk"]
[Mon Jul 20 07:13:42.627049 2026] [security2:error] [pid 85094:tid 85315] [client 194.61.41.62:28585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/Text/index.php"] [unique_id "al4fBq_nUl59BcEkkgGEXQAAAWM"]
[Mon Jul 20 07:13:42.851841 2026] [security2:error] [pid 85094:tid 85106] [remote 103.75.185.95:35252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fBq_nUl59BcEkkgGEbwABVwo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:13:42.887449 2026] [security2:error] [pid 85094:tid 85247] [client 14.225.17.146:58994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4fBq_nUl59BcEkkgGEaQAAASA"], referer: https://thesoloceos.com/2017
[Mon Jul 20 07:13:43.208250 2026] [security2:error] [pid 85094:tid 85278] [client 14.225.17.146:60175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4fB6_nUl59BcEkkgGEewAAAT8"], referer: https://secretkeynumerology.com/2017
[Mon Jul 20 07:13:43.373196 2026] [security2:error] [pid 85094:tid 85272] [client 144.172.114.51:40850] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-config.php.old"] [unique_id "al4fB6_nUl59BcEkkgGEkQAAATk"]
[Mon Jul 20 07:13:43.430624 2026] [security2:error] [pid 85094:tid 85249] [client 194.61.41.83:63747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/mu-plugins/index.php"] [unique_id "al4fB6_nUl59BcEkkgGElQAAASI"]
[Mon Jul 20 07:13:43.480954 2026] [security2:error] [pid 85094:tid 85100] [remote 154.66.198.148:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4fB6_nUl59BcEkkgGElwABfQQ"]
[Mon Jul 20 07:13:43.553512 2026] [security2:error] [pid 85094:tid 85182] [remote 47.86.33.52:60722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4fB6_nUl59BcEkkgGEmgABIFY"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:13:44.096629 2026] [security2:error] [pid 85094:tid 85169] [remote 154.66.198.148:48096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4fCK_nUl59BcEkkgGExgABOUk"], referer: https://guidehunting.com/wp-login.php
[Mon Jul 20 07:13:44.141997 2026] [security2:error] [pid 85094:tid 85283] [client 194.61.41.88:35621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sitemaps/abcd.php"] [unique_id "al4fCK_nUl59BcEkkgGEywAAAUM"]
[Mon Jul 20 07:13:44.177942 2026] [security2:error] [pid 85094:tid 85334] [client 57.141.18.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4fCK_nUl59BcEkkgGExAAAAXY"]
[Mon Jul 20 07:13:44.222353 2026] [security2:error] [pid 85094:tid 85257] [client 77.110.127.138:54405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fCK_nUl59BcEkkgGE0gAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:44.222442 2026] [security2:error] [pid 85094:tid 85257] [client 77.110.127.138:54405] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fCK_nUl59BcEkkgGE0gAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:44.259205 2026] [security2:error] [pid 85094:tid 85180] [remote 47.128.54.21:20034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gescontrols.com"] [uri "/sm/contact.htm"] [unique_id "al4fCK_nUl59BcEkkgGE2AABElQ"]
[Mon Jul 20 07:13:44.552344 2026] [security2:error] [pid 85094:tid 85287] [client 157.20.138.62:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fCK_nUl59BcEkkgGE7AAAAUc"]
[Mon Jul 20 07:13:44.552456 2026] [security2:error] [pid 85094:tid 85287] [client 157.20.138.62:65442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fCK_nUl59BcEkkgGE7AAAAUc"]
[Mon Jul 20 07:13:44.738278 2026] [security2:error] [pid 85094:tid 85241] [client 57.141.18.58:37216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fBK_nUl59BcEkkgGDwwABGg4"]
[Mon Jul 20 07:13:44.773844 2026] [security2:error] [pid 85094:tid 85277] [client 134.209.6.81:54415] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.asliceofleadership.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4fCK_nUl59BcEkkgGE9QAAAT4"]
[Mon Jul 20 07:13:44.915590 2026] [security2:error] [pid 85094:tid 85245] [client 194.61.41.247:59067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/rk2.php"] [unique_id "al4fCK_nUl59BcEkkgGFBQAAAR4"]
[Mon Jul 20 07:13:45.045154 2026] [security2:error] [pid 85094:tid 85350] [client 14.225.17.146:58965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4fBq_nUl59BcEkkgGEYAAAAYY"], referer: http://gearwaterproof.com/2017
[Mon Jul 20 07:13:45.169813 2026] [security2:error] [pid 85094:tid 85289] [client 154.192.123.127:17434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fCa_nUl59BcEkkgGFFwAAAUk"]
[Mon Jul 20 07:13:45.169922 2026] [security2:error] [pid 85094:tid 85289] [client 154.192.123.127:17434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fCa_nUl59BcEkkgGFFwAAAUk"]
[Mon Jul 20 07:13:45.630939 2026] [security2:error] [pid 85094:tid 85279] [client 194.61.41.245:26935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/widgets/class-wp-widget-search-interpreter.php"] [unique_id "al4fCa_nUl59BcEkkgGFQgAAAUA"]
[Mon Jul 20 07:13:45.674660 2026] [security2:error] [pid 85094:tid 85328] [client 50.116.65.227:17090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fCa_nUl59BcEkkgGFSQAAAXA"]
[Mon Jul 20 07:13:45.685931 2026] [security2:error] [pid 85094:tid 85317] [client 50.116.65.227:17104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fCa_nUl59BcEkkgGFTAAAAWU"]
[Mon Jul 20 07:13:45.837298 2026] [security2:error] [pid 85094:tid 85264] [client 144.172.114.51:40860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-config.php~"] [unique_id "al4fCa_nUl59BcEkkgGFWwAAATE"]
[Mon Jul 20 07:13:45.899927 2026] [security2:error] [pid 85094:tid 85339] [client 117.211.236.168:63008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fCa_nUl59BcEkkgGFXwAAAXs"]
[Mon Jul 20 07:13:45.900054 2026] [security2:error] [pid 85094:tid 85339] [client 117.211.236.168:63008] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fCa_nUl59BcEkkgGFXwAAAXs"]
[Mon Jul 20 07:13:45.996165 2026] [security2:error] [pid 85094:tid 85276] [client 57.141.18.49:64866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fBq_nUl59BcEkkgGEUAABPXM"]
[Mon Jul 20 07:13:46.353611 2026] [security2:error] [pid 85094:tid 85352] [client 194.61.41.98:42549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/chosen.php"] [unique_id "al4fCq_nUl59BcEkkgGFhwAAAYg"]
[Mon Jul 20 07:13:46.725243 2026] [security2:error] [pid 85094:tid 85264] [client 104.234.53.79:24129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fCq_nUl59BcEkkgGFmgAAATE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:46.828320 2026] [security2:error] [pid 85094:tid 85295] [client 77.110.127.138:54689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fCq_nUl59BcEkkgGFqQAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:46.828394 2026] [security2:error] [pid 85094:tid 85295] [client 77.110.127.138:54689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fCq_nUl59BcEkkgGFqQAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:47.020398 2026] [security2:error] [pid 85094:tid 85313] [client 104.234.53.79:24129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fC6_nUl59BcEkkgGFugAAAWE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:13:47.137904 2026] [security2:error] [pid 85094:tid 85231] [client 194.61.41.65:45731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/autoload_classmap.php"] [unique_id "al4fC6_nUl59BcEkkgGFxwAAARA"]
[Mon Jul 20 07:13:47.949096 2026] [security2:error] [pid 85094:tid 85346] [client 194.61.41.98:33901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/block-template-utils-other.php"] [unique_id "al4fC6_nUl59BcEkkgGGCAAAAYI"]
[Mon Jul 20 07:13:48.133506 2026] [security2:error] [pid 85094:tid 85169] [remote 100.42.189.89:41740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4fDK_nUl59BcEkkgGGFwABEUk"]
[Mon Jul 20 07:13:48.188714 2026] [security2:error] [pid 85094:tid 85107] [remote 95.217.78.234:37436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4fDK_nUl59BcEkkgGGGgABdgs"]
[Mon Jul 20 07:13:48.317432 2026] [security2:error] [pid 85094:tid 85291] [client 170.239.213.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4fC6_nUl59BcEkkgGF_wABS2c"], referer: https://packerjanitorial.com
[Mon Jul 20 07:13:48.323188 2026] [security2:error] [pid 85094:tid 85138] [remote 100.42.189.89:41740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4fDK_nUl59BcEkkgGGHwABEio"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:13:48.418420 2026] [security2:error] [pid 85094:tid 85322] [client 57.141.18.92:33468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fCK_nUl59BcEkkgGE9gABaiE"]
[Mon Jul 20 07:13:48.420018 2026] [security2:error] [pid 85094:tid 85221] [remote 95.217.78.234:37436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4fDK_nUl59BcEkkgGGUgABTn0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:13:48.450908 2026] [security2:error] [pid 85094:tid 85183] [remote 72.167.132.114:47176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4fDK_nUl59BcEkkgGGVQABT1c"]
[Mon Jul 20 07:13:48.682473 2026] [security2:error] [pid 85094:tid 85333] [client 144.172.114.51:40874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/config.php"] [unique_id "al4fDK_nUl59BcEkkgGGcQAAAXU"]
[Mon Jul 20 07:13:48.741454 2026] [security2:error] [pid 85094:tid 85310] [client 194.61.41.63:50833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/alam.php"] [unique_id "al4fDK_nUl59BcEkkgGGhgAAAV4"]
[Mon Jul 20 07:13:49.213420 2026] [security2:error] [pid 85094:tid 85182] [remote 72.167.132.114:47176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4fDa_nUl59BcEkkgGGuAABW1Y"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 07:13:49.291273 2026] [security2:error] [pid 85094:tid 85243] [client 57.141.18.22:37686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fCa_nUl59BcEkkgGFTQABHH8"]
[Mon Jul 20 07:13:49.518200 2026] [security2:error] [pid 85094:tid 85340] [client 194.61.41.249:20629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/adminfusm.php"] [unique_id "al4fDa_nUl59BcEkkgGG0AAAAXw"]
[Mon Jul 20 07:13:49.825048 2026] [security2:error] [pid 85094:tid 85309] [client 14.225.17.146:55664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4fC6_nUl59BcEkkgGF-wAAAV0"], referer: http://dollpassionista.com/2017
[Mon Jul 20 07:13:49.963013 2026] [proxy:warn] [pid 85094:tid 85288] [client 94.102.49.155:57854] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 07:13:49.996891 2026] [core:error] [pid 85094:tid 85289] [client 94.102.49.155:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:49.996910 2026] [core:error] [pid 85094:tid 85289] [client 94.102.49.155:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:49.997007 2026] [security2:error] [pid 85094:tid 85289] [client 94.102.49.155:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4fDa_nUl59BcEkkgGG-gAAAUk"]
[Mon Jul 20 07:13:50.220457 2026] [security2:error] [pid 85094:tid 85244] [client 194.61.41.74:31199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/sodium_compat/lib/widget-group.php"] [unique_id "al4fDq_nUl59BcEkkgGHDQAAAR0"]
[Mon Jul 20 07:13:50.356633 2026] [security2:error] [pid 85094:tid 85322] [client 158.173.166.181:47187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fDq_nUl59BcEkkgGHEgAAAWo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:13:50.435603 2026] [security2:error] [pid 85094:tid 85255] [client 57.141.18.12:36160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fCq_nUl59BcEkkgGFqgABKBU"]
[Mon Jul 20 07:13:50.625302 2026] [security2:error] [pid 85094:tid 85286] [client 103.144.65.217:57462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fDq_nUl59BcEkkgGHJgAAAUY"]
[Mon Jul 20 07:13:50.625382 2026] [security2:error] [pid 85094:tid 85286] [client 103.144.65.217:57462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fDq_nUl59BcEkkgGHJgAAAUY"]
[Mon Jul 20 07:13:50.729594 2026] [security2:error] [pid 85094:tid 85284] [client 14.225.17.146:59615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4fDq_nUl59BcEkkgGHGAAAAUQ"], referer: http://savilerowtravel.com/2017
[Mon Jul 20 07:13:50.770339 2026] [security2:error] [pid 85094:tid 85256] [client 3.77.67.4:18642] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4fDq_nUl59BcEkkgGHKQAAASk"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:13:50.797372 2026] [security2:error] [pid 85094:tid 85272] [client 14.225.17.146:61956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4fDq_nUl59BcEkkgGHKAAAATk"], referer: https://dollpassionista.com/2017
[Mon Jul 20 07:13:50.821701 2026] [security2:error] [pid 85094:tid 85203] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fDq_nUl59BcEkkgGHOgABLms"]
[Mon Jul 20 07:13:50.821905 2026] [security2:error] [pid 85094:tid 85261] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fDq_nUl59BcEkkgGHOgABLms"]
[Mon Jul 20 07:13:50.826704 2026] [security2:error] [pid 85094:tid 85152] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fDq_nUl59BcEkkgGHPAABbTg"]
[Mon Jul 20 07:13:50.826837 2026] [security2:error] [pid 85094:tid 85325] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fDq_nUl59BcEkkgGHPAABbTg"]
[Mon Jul 20 07:13:50.925927 2026] [security2:error] [pid 85094:tid 85323] [client 194.61.41.75:21895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/raw.php"] [unique_id "al4fDq_nUl59BcEkkgGHPgAAAWs"]
[Mon Jul 20 07:13:51.207826 2026] [security2:error] [pid 85094:tid 85330] [client 201.27.111.74:58526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fD6_nUl59BcEkkgGHWgAAAXI"]
[Mon Jul 20 07:13:51.207926 2026] [security2:error] [pid 85094:tid 85330] [client 201.27.111.74:58526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fD6_nUl59BcEkkgGHWgAAAXI"]
[Mon Jul 20 07:13:51.533976 2026] [security2:error] [pid 85094:tid 85325] [client 64.227.49.194:60613] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.aljosour-alarabia.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4fD6_nUl59BcEkkgGHbgAAAW0"]
[Mon Jul 20 07:13:51.547002 2026] [security2:error] [pid 85094:tid 85296] [client 88.241.67.160:55648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fD6_nUl59BcEkkgGHcAAAAVA"]
[Mon Jul 20 07:13:51.547108 2026] [security2:error] [pid 85094:tid 85296] [client 88.241.67.160:55648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fD6_nUl59BcEkkgGHcAAAAVA"]
[Mon Jul 20 07:13:51.633214 2026] [security2:error] [pid 85094:tid 85233] [client 194.61.41.76:51239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/js/jcrop/about.php"] [unique_id "al4fD6_nUl59BcEkkgGHfwAAARI"]
[Mon Jul 20 07:13:51.737107 2026] [security2:error] [pid 85094:tid 85306] [client 14.225.17.146:59687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4fD6_nUl59BcEkkgGHcQAAAVo"], referer: https://savilerowtravel.com/2017
[Mon Jul 20 07:13:52.136011 2026] [security2:error] [pid 85094:tid 85318] [client 187.16.64.216:56920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fEK_nUl59BcEkkgGHpwAAAWY"]
[Mon Jul 20 07:13:52.136117 2026] [security2:error] [pid 85094:tid 85318] [client 187.16.64.216:56920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fEK_nUl59BcEkkgGHpwAAAWY"]
[Mon Jul 20 07:13:52.419985 2026] [security2:error] [pid 85094:tid 85311] [client 194.61.41.58:25619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/includes/admin.php"] [unique_id "al4fEK_nUl59BcEkkgGHygAAAV8"]
[Mon Jul 20 07:13:52.495081 2026] [security2:error] [pid 85094:tid 85333] [client 52.109.124.141:14370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fEK_nUl59BcEkkgGHzwAAAXU"]
[Mon Jul 20 07:13:52.676568 2026] [security2:error] [pid 85094:tid 85250] [client 52.109.124.141:14370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fEK_nUl59BcEkkgGH5gAAASM"]
[Mon Jul 20 07:13:52.864666 2026] [security2:error] [pid 85094:tid 85242] [client 4.218.23.144:40134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fEK_nUl59BcEkkgGH-AAAARs"]
[Mon Jul 20 07:13:53.001610 2026] [security2:error] [pid 85094:tid 85273] [client 4.218.23.144:40134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fEK_nUl59BcEkkgGICgAAATo"]
[Mon Jul 20 07:13:53.032013 2026] [security2:error] [pid 85094:tid 85291] [client 14.225.17.146:61791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4fEK_nUl59BcEkkgGH0wAAAUs"]
[Mon Jul 20 07:13:53.060645 2026] [security2:error] [pid 85094:tid 85259] [client 57.141.18.99:43528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fDa_nUl59BcEkkgGGwwABLBg"]
[Mon Jul 20 07:13:53.149127 2026] [security2:error] [pid 85094:tid 85109] [remote 173.212.252.15:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4fEa_nUl59BcEkkgGIFAABTw0"]
[Mon Jul 20 07:13:53.162055 2026] [security2:error] [pid 85094:tid 85319] [client 194.61.41.65:59171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/chosen.php"] [unique_id "al4fEa_nUl59BcEkkgGIFQAAAWc"]
[Mon Jul 20 07:13:53.344504 2026] [security2:error] [pid 85094:tid 85189] [remote 173.212.252.15:56762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4fEa_nUl59BcEkkgGILQABOl0"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 07:13:53.823096 2026] [security2:error] [pid 85094:tid 85248] [client 14.225.17.146:63770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4fEK_nUl59BcEkkgGHoAAAASE"], referer: http://maxenengineering.com/2017
[Mon Jul 20 07:13:53.952496 2026] [security2:error] [pid 85094:tid 85273] [client 194.61.41.80:51131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/2021/wp-works.php"] [unique_id "al4fEa_nUl59BcEkkgGIXwAAATo"]
[Mon Jul 20 07:13:54.188035 2026] [security2:error] [pid 85094:tid 85328] [client 57.141.18.120:63732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fDq_nUl59BcEkkgGHIAABcGQ"]
[Mon Jul 20 07:13:54.530964 2026] [security2:error] [pid 85094:tid 85345] [client 14.225.17.146:57347] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4fEq_nUl59BcEkkgGIggAAAYE"], referer: http://kromosenergy.com/2017
[Mon Jul 20 07:13:54.747537 2026] [security2:error] [pid 85094:tid 85332] [client 14.225.17.146:59500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4fEa_nUl59BcEkkgGIEgAAAXQ"], referer: http://ksands.co.uk/2017
[Mon Jul 20 07:13:54.772916 2026] [security2:error] [pid 85094:tid 85337] [client 194.61.41.74:32377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/media-new.php"] [unique_id "al4fEq_nUl59BcEkkgGIkgAAAXk"]
[Mon Jul 20 07:13:55.017744 2026] [security2:error] [pid 85094:tid 85269] [client 50.116.65.227:49102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_d9d7fe47/wp-cron.php"] [unique_id "al4fE6_nUl59BcEkkgGIpgAAATY"]
[Mon Jul 20 07:13:55.147932 2026] [security2:error] [pid 85094:tid 85338] [client 157.20.138.62:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fE6_nUl59BcEkkgGIrQAAAXo"]
[Mon Jul 20 07:13:55.148042 2026] [security2:error] [pid 85094:tid 85338] [client 157.20.138.62:49629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fE6_nUl59BcEkkgGIrQAAAXo"]
[Mon Jul 20 07:13:55.329885 2026] [security2:error] [pid 85094:tid 85289] [client 57.141.18.78:47470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fD6_nUl59BcEkkgGHhgABSVM"]
[Mon Jul 20 07:13:55.448640 2026] [security2:error] [pid 85094:tid 85282] [client 77.110.127.138:55651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fE6_nUl59BcEkkgGIwgAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:55.448762 2026] [security2:error] [pid 85094:tid 85282] [client 77.110.127.138:55651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fE6_nUl59BcEkkgGIwgAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:55.521809 2026] [security2:error] [pid 85094:tid 85269] [client 194.61.41.56:56883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/media-new.php"] [unique_id "al4fE6_nUl59BcEkkgGI0AAAATY"]
[Mon Jul 20 07:13:55.563890 2026] [security2:error] [pid 85094:tid 85298] [client 82.102.27.163:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fE6_nUl59BcEkkgGI2AAAAVI"]
[Mon Jul 20 07:13:55.564059 2026] [security2:error] [pid 85094:tid 85298] [client 82.102.27.163:56286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fE6_nUl59BcEkkgGI2AAAAVI"]
[Mon Jul 20 07:13:55.691972 2026] [security2:error] [pid 85094:tid 85276] [client 154.192.123.127:17732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fE6_nUl59BcEkkgGI5AAAAT0"]
[Mon Jul 20 07:13:55.692096 2026] [security2:error] [pid 85094:tid 85276] [client 154.192.123.127:17732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fE6_nUl59BcEkkgGI5AAAAT0"]
[Mon Jul 20 07:13:55.762238 2026] [security2:error] [pid 85094:tid 85322] [client 14.225.17.146:57070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4fEa_nUl59BcEkkgGISwAAAWo"], referer: http://jvcmotorsports.com/2017
[Mon Jul 20 07:13:56.074215 2026] [security2:error] [pid 85094:tid 85348] [client 144.172.114.51:59580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/phpinfo.php"] [unique_id "al4fFK_nUl59BcEkkgGI_wAAAYQ"]
[Mon Jul 20 07:13:56.245894 2026] [security2:error] [pid 85094:tid 85284] [client 194.61.41.99:35915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/class_api.php"] [unique_id "al4fFK_nUl59BcEkkgGJDQAAAUQ"]
[Mon Jul 20 07:13:56.515646 2026] [security2:error] [pid 85094:tid 85327] [client 144.172.114.51:47640] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/.env.backup"] [unique_id "al4fFK_nUl59BcEkkgGJKAAAAW8"]
[Mon Jul 20 07:13:56.814789 2026] [security2:error] [pid 85094:tid 85273] [client 144.172.114.51:59590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/info.php"] [unique_id "al4fFK_nUl59BcEkkgGJRgAAATo"]
[Mon Jul 20 07:13:57.052663 2026] [security2:error] [pid 85094:tid 85237] [client 194.61.41.56:51633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/2021/themes.php"] [unique_id "al4fFa_nUl59BcEkkgGJWAAAARY"]
[Mon Jul 20 07:13:57.330107 2026] [security2:error] [pid 85094:tid 85246] [client 77.110.127.138:55296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fFa_nUl59BcEkkgGJbgAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:57.330217 2026] [security2:error] [pid 85094:tid 85246] [client 77.110.127.138:55296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fFa_nUl59BcEkkgGJbgAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:57.849232 2026] [security2:error] [pid 85094:tid 85320] [client 194.61.41.58:46641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/admin/install.php"] [unique_id "al4fFa_nUl59BcEkkgGJngAAAWg"]
[Mon Jul 20 07:13:58.291969 2026] [security2:error] [pid 85094:tid 85321] [client 117.211.236.168:63611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fFq_nUl59BcEkkgGJwgAAAWk"]
[Mon Jul 20 07:13:58.292064 2026] [security2:error] [pid 85094:tid 85321] [client 117.211.236.168:63611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fFq_nUl59BcEkkgGJwgAAAWk"]
[Mon Jul 20 07:13:58.556454 2026] [security2:error] [pid 85094:tid 85228] [client 57.141.18.84:50840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fE6_nUl59BcEkkgGIuQABDV4"]
[Mon Jul 20 07:13:58.616017 2026] [security2:error] [pid 85094:tid 85306] [client 194.61.41.91:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/plugin.php"] [unique_id "al4fFq_nUl59BcEkkgGJ6gAAAVo"]
[Mon Jul 20 07:13:58.644293 2026] [security2:error] [pid 85094:tid 85246] [client 98.159.234.160:21365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fFq_nUl59BcEkkgGJ7gAAAR8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:13:59.205633 2026] [security2:error] [pid 85094:tid 85291] [client 50.116.65.227:54926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fF6_nUl59BcEkkgGKQQAAAUs"]
[Mon Jul 20 07:13:59.215886 2026] [security2:error] [pid 85094:tid 85306] [client 50.116.65.227:54940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fF6_nUl59BcEkkgGKQgAAAVo"]
[Mon Jul 20 07:13:59.284639 2026] [security2:error] [pid 85094:tid 85342] [client 144.172.114.51:59576] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/.env"] [unique_id "al4fF6_nUl59BcEkkgGKTQAAAX4"]
[Mon Jul 20 07:13:59.325588 2026] [security2:error] [pid 85094:tid 85321] [client 194.61.41.85:64727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-scripts-query.php"] [unique_id "al4fF6_nUl59BcEkkgGKUQAAAWk"]
[Mon Jul 20 07:13:59.430454 2026] [core:error] [pid 85094:tid 85256] [client 126.209.16.133:45140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:59.430472 2026] [core:error] [pid 85094:tid 85256] [client 126.209.16.133:45140] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:13:59.606704 2026] [security2:error] [pid 85094:tid 85341] [client 77.110.127.138:55648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fF6_nUl59BcEkkgGKzwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:59.606817 2026] [security2:error] [pid 85094:tid 85341] [client 77.110.127.138:55648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fF6_nUl59BcEkkgGKzwAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:13:59.758910 2026] [security2:error] [pid 85094:tid 85096] [remote 152.228.213.32:39128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fF6_nUl59BcEkkgGK4AABFAA"]
[Mon Jul 20 07:13:59.759080 2026] [security2:error] [pid 85094:tid 85235] [client 152.228.213.32:39128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fF6_nUl59BcEkkgGK4AABFAA"]
[Mon Jul 20 07:14:00.031050 2026] [security2:error] [pid 85094:tid 85308] [client 194.61.41.79:48567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/item.php"] [unique_id "al4fGK_nUl59BcEkkgGLDAAAAVw"]
[Mon Jul 20 07:14:00.033390 2026] [security2:error] [pid 85094:tid 85322] [client 57.141.18.56:43734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fFK_nUl59BcEkkgGJQwABago"]
[Mon Jul 20 07:14:00.483373 2026] [security2:error] [pid 85094:tid 85288] [client 49.37.242.14:58087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fF6_nUl59BcEkkgGK7AAAAUg"]
[Mon Jul 20 07:14:00.750644 2026] [security2:error] [pid 85094:tid 85303] [client 77.110.127.138:56159] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fGK_nUl59BcEkkgGLhwAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:00.771445 2026] [security2:error] [pid 85094:tid 85293] [client 194.61.41.85:50747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/pages.php"] [unique_id "al4fGK_nUl59BcEkkgGLigAAAU0"]
[Mon Jul 20 07:14:01.173799 2026] [security2:error] [pid 85094:tid 85336] [client 57.141.18.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4fF6_nUl59BcEkkgGKTgAAAXg"]
[Mon Jul 20 07:14:01.205389 2026] [security2:error] [pid 85094:tid 85307] [client 103.144.65.217:57907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fGa_nUl59BcEkkgGLsAAAAVs"]
[Mon Jul 20 07:14:01.206178 2026] [security2:error] [pid 85094:tid 85307] [client 103.144.65.217:57907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fGa_nUl59BcEkkgGLsAAAAVs"]
[Mon Jul 20 07:14:01.269363 2026] [security2:error] [pid 85094:tid 85219] [remote 95.217.78.234:47218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4fGa_nUl59BcEkkgGLuwABdns"]
[Mon Jul 20 07:14:01.427183 2026] [security2:error] [pid 85094:tid 85115] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fGa_nUl59BcEkkgGLzAABhxM"]
[Mon Jul 20 07:14:01.427385 2026] [security2:error] [pid 85094:tid 85351] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fGa_nUl59BcEkkgGLzAABhxM"]
[Mon Jul 20 07:14:01.502189 2026] [security2:error] [pid 85094:tid 85170] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fGa_nUl59BcEkkgGL2QABa0o"]
[Mon Jul 20 07:14:01.502330 2026] [security2:error] [pid 85094:tid 85323] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fGa_nUl59BcEkkgGL2QABa0o"]
[Mon Jul 20 07:14:01.515972 2026] [security2:error] [pid 85094:tid 85166] [remote 95.217.78.234:47218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4fGa_nUl59BcEkkgGL3AABJ0Y"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 07:14:01.517122 2026] [security2:error] [pid 85094:tid 85310] [client 194.61.41.74:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/module.audio-license.php"] [unique_id "al4fGa_nUl59BcEkkgGL3QAAAV4"]
[Mon Jul 20 07:14:01.809098 2026] [security2:error] [pid 85094:tid 85242] [client 52.140.101.203:23689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fGa_nUl59BcEkkgGL-AAAARs"]
[Mon Jul 20 07:14:01.960275 2026] [security2:error] [pid 85094:tid 85299] [client 52.109.76.144:29699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fGa_nUl59BcEkkgGMBQAAAVM"]
[Mon Jul 20 07:14:02.026088 2026] [security2:error] [pid 85094:tid 85262] [client 201.27.111.74:59033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fGq_nUl59BcEkkgGMCwAAAS8"]
[Mon Jul 20 07:14:02.031246 2026] [security2:error] [pid 85094:tid 85262] [client 201.27.111.74:59033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fGq_nUl59BcEkkgGMCwAAAS8"]
[Mon Jul 20 07:14:02.043875 2026] [security2:error] [pid 85094:tid 85329] [client 52.140.101.203:23689] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fGq_nUl59BcEkkgGMDQAAAXE"]
[Mon Jul 20 07:14:02.100668 2026] [security2:error] [pid 85094:tid 85288] [client 52.109.76.144:29699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fGq_nUl59BcEkkgGMEgAAAUg"]
[Mon Jul 20 07:14:02.165725 2026] [security2:error] [pid 85094:tid 85307] [client 88.241.67.160:55571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fGq_nUl59BcEkkgGMFgAAAVs"]
[Mon Jul 20 07:14:02.165848 2026] [security2:error] [pid 85094:tid 85307] [client 88.241.67.160:55571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fGq_nUl59BcEkkgGMFgAAAVs"]
[Mon Jul 20 07:14:02.255412 2026] [security2:error] [pid 85094:tid 85260] [client 194.61.41.252:29969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/classwithtostring.php%20"] [unique_id "al4fGq_nUl59BcEkkgGMHwAAAS0"]
[Mon Jul 20 07:14:02.271401 2026] [core:error] [pid 85094:tid 85334] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:02.271432 2026] [core:error] [pid 85094:tid 85334] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:02.573340 2026] [security2:error] [pid 85094:tid 85330] [client 77.110.127.138:55917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fGq_nUl59BcEkkgGMQAAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:02.573473 2026] [security2:error] [pid 85094:tid 85330] [client 77.110.127.138:55917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fGq_nUl59BcEkkgGMQAAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:02.739677 2026] [security2:error] [pid 85094:tid 85239] [client 52.3.251.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fGq_nUl59BcEkkgGMQgABGE8"]
[Mon Jul 20 07:14:03.046301 2026] [security2:error] [pid 85094:tid 85344] [client 194.61.41.242:24057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/uploads/function.php"] [unique_id "al4fG6_nUl59BcEkkgGMYgAAAYA"]
[Mon Jul 20 07:14:03.080383 2026] [security2:error] [pid 85094:tid 85316] [client 187.16.64.216:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fG6_nUl59BcEkkgGMZAAAAWQ"]
[Mon Jul 20 07:14:03.080512 2026] [security2:error] [pid 85094:tid 85316] [client 187.16.64.216:57498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fG6_nUl59BcEkkgGMZAAAAWQ"]
[Mon Jul 20 07:14:03.120884 2026] [security2:error] [pid 85094:tid 85183] [remote 20.153.140.50:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fG6_nUl59BcEkkgGMZgABcFc"]
[Mon Jul 20 07:14:03.335442 2026] [security2:error] [pid 85094:tid 85131] [remote 182.77.62.24:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4fG6_nUl59BcEkkgGMdAABUCM"]
[Mon Jul 20 07:14:03.525281 2026] [security2:error] [pid 85094:tid 85149] [remote 20.153.140.50:41506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fG6_nUl59BcEkkgGMiAABFjU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:03.619072 2026] [security2:error] [pid 85094:tid 85316] [client 50.116.65.227:37406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "eyl.bfk.mybluehost.me"] [uri "/website_70dc46cb/wp-cron.php"] [unique_id "al4fG6_nUl59BcEkkgGMkQAAAWQ"]
[Mon Jul 20 07:14:03.861420 2026] [security2:error] [pid 85094:tid 85222] [remote 182.77.62.24:48588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4fG6_nUl59BcEkkgGMpQABCn4"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 07:14:03.865979 2026] [security2:error] [pid 85094:tid 85336] [client 194.61.41.101:36637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/js/doc.php"] [unique_id "al4fG6_nUl59BcEkkgGMqQAAAXg"]
[Mon Jul 20 07:14:04.226032 2026] [security2:error] [pid 85094:tid 85194] [remote 20.153.140.50:41516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fHK_nUl59BcEkkgGMxgABg2I"]
[Mon Jul 20 07:14:04.299767 2026] [security2:error] [pid 85094:tid 85127] [remote 160.187.68.132:58006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fHK_nUl59BcEkkgGMyAABiR8"]
[Mon Jul 20 07:14:04.299919 2026] [security2:error] [pid 85094:tid 85353] [client 160.187.68.132:58006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fHK_nUl59BcEkkgGMyAABiR8"]
[Mon Jul 20 07:14:04.307755 2026] [security2:error] [pid 85094:tid 85228] [client 57.141.18.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4fHK_nUl59BcEkkgGMvwAAAQ0"]
[Mon Jul 20 07:14:04.327189 2026] [security2:error] [pid 85094:tid 85267] [client 77.110.127.138:56377] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fHK_nUl59BcEkkgGMzgAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:04.401339 2026] [security2:error] [pid 85094:tid 85233] [client 54.184.226.94:61663] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thecreole.com"] [uri "/"] [unique_id "al4fHK_nUl59BcEkkgGM0wAAARI"]
[Mon Jul 20 07:14:04.413063 2026] [core:error] [pid 85094:tid 85241] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:04.413083 2026] [core:error] [pid 85094:tid 85241] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:04.454305 2026] [security2:error] [pid 85094:tid 85346] [client 216.144.249.201:47010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/.git/HEAD"] [unique_id "al4fHK_nUl59BcEkkgGM2wAAAYI"]
[Mon Jul 20 07:14:04.454404 2026] [security2:error] [pid 85094:tid 85346] [client 216.144.249.201:47010] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/.git/HEAD"] [unique_id "al4fHK_nUl59BcEkkgGM2wAAAYI"]
[Mon Jul 20 07:14:04.510063 2026] [security2:error] [pid 85094:tid 85249] [client 54.184.226.94:59377] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "TRACE" at REQUEST_METHOD. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "52"] [id "340002"] [rev "3"] [msg "Atomicorp.com WAF Rules: TRACE/TRACK method denied"] [severity "CRITICAL"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4fHK_nUl59BcEkkgGM5AAAASI"]
[Mon Jul 20 07:14:04.626559 2026] [security2:error] [pid 85094:tid 85236] [client 194.61.41.102:41641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/comfunctions.php"] [unique_id "al4fHK_nUl59BcEkkgGM7gAAARU"]
[Mon Jul 20 07:14:04.663665 2026] [security2:error] [pid 85094:tid 85219] [remote 20.153.140.50:41516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fHK_nUl59BcEkkgGM9AABfXs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:14:05.195465 2026] [security2:error] [pid 85094:tid 85297] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fHK_nUl59BcEkkgGM6gAAAVE"]
[Mon Jul 20 07:14:05.296511 2026] [security2:error] [pid 85094:tid 85242] [client 77.110.127.138:56161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fHa_nUl59BcEkkgGNbQAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:05.296652 2026] [security2:error] [pid 85094:tid 85242] [client 77.110.127.138:56161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fHa_nUl59BcEkkgGNbQAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:05.351950 2026] [security2:error] [pid 85094:tid 85347] [client 103.176.215.66:56389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fHa_nUl59BcEkkgGNbwAAAYM"]
[Mon Jul 20 07:14:05.352124 2026] [security2:error] [pid 85094:tid 85347] [client 103.176.215.66:56389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fHa_nUl59BcEkkgGNbwAAAYM"]
[Mon Jul 20 07:14:05.399083 2026] [security2:error] [pid 85094:tid 85296] [client 194.61.41.89:26877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-error-module.php"] [unique_id "al4fHa_nUl59BcEkkgGNdgAAAVA"]
[Mon Jul 20 07:14:05.423116 2026] [security2:error] [pid 85094:tid 85248] [client 104.234.53.86:49109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fHa_nUl59BcEkkgGNdAAAASE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:05.628544 2026] [security2:error] [pid 85094:tid 85332] [client 144.172.114.51:36784] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/.env.old"] [unique_id "al4fHa_nUl59BcEkkgGNtwAAAXQ"]
[Mon Jul 20 07:14:05.685452 2026] [security2:error] [pid 85094:tid 85308] [client 157.20.138.62:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fHa_nUl59BcEkkgGNvgAAAVw"]
[Mon Jul 20 07:14:05.685548 2026] [security2:error] [pid 85094:tid 85308] [client 157.20.138.62:50198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fHa_nUl59BcEkkgGNvgAAAVw"]
[Mon Jul 20 07:14:05.743851 2026] [security2:error] [pid 85094:tid 85242] [client 54.184.226.94:28476] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4fHa_nUl59BcEkkgGNxAAAARs"], referer: https://www.google.com/images/url
[Mon Jul 20 07:14:06.028987 2026] [security2:error] [pid 85094:tid 85282] [client 45.157.112.60:31725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fHq_nUl59BcEkkgGN7gAAAUI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:14:06.147915 2026] [security2:error] [pid 85094:tid 85254] [client 194.61.41.101:25233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/adminfus.php"] [unique_id "al4fHq_nUl59BcEkkgGN-gAAASc"]
[Mon Jul 20 07:14:06.282672 2026] [security2:error] [pid 85094:tid 85261] [client 154.192.123.127:18190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fHq_nUl59BcEkkgGOCgAAAS4"]
[Mon Jul 20 07:14:06.282786 2026] [security2:error] [pid 85094:tid 85261] [client 154.192.123.127:18190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fHq_nUl59BcEkkgGOCgAAAS4"]
[Mon Jul 20 07:14:06.284816 2026] [security2:error] [pid 85094:tid 85237] [client 57.141.18.31:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4fHq_nUl59BcEkkgGN-QAAARY"]
[Mon Jul 20 07:14:06.298916 2026] [security2:error] [pid 85094:tid 85306] [client 77.110.127.138:56593] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fHq_nUl59BcEkkgGODAAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:06.303786 2026] [security2:error] [pid 85094:tid 85342] [client 57.141.18.68:32286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fGq_nUl59BcEkkgGMTQABfho"]
[Mon Jul 20 07:14:06.999930 2026] [security2:error] [pid 85094:tid 85317] [client 216.144.249.201:47732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/.aws/config"] [unique_id "al4fHq_nUl59BcEkkgGOQgAAAWU"]
[Mon Jul 20 07:14:07.000032 2026] [security2:error] [pid 85094:tid 85317] [client 216.144.249.201:47732] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/.aws/config"] [unique_id "al4fHq_nUl59BcEkkgGOQgAAAWU"]
[Mon Jul 20 07:14:07.002185 2026] [security2:error] [pid 85094:tid 85341] [client 194.61.41.81:28633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/adminfus.php"] [unique_id "al4fH6_nUl59BcEkkgGORAAAAX0"]
[Mon Jul 20 07:14:07.016966 2026] [security2:error] [pid 85094:tid 85237] [client 216.144.249.201:47688] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/.netrc"] [unique_id "al4fH6_nUl59BcEkkgGOSwAAARY"]
[Mon Jul 20 07:14:07.017068 2026] [security2:error] [pid 85094:tid 85237] [client 216.144.249.201:47688] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/.netrc"] [unique_id "al4fH6_nUl59BcEkkgGOSwAAARY"]
[Mon Jul 20 07:14:07.017084 2026] [security2:error] [pid 85094:tid 85313] [client 216.144.249.201:47606] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/openapi.json"] [unique_id "al4fH6_nUl59BcEkkgGOUgAAAWE"]
[Mon Jul 20 07:14:07.017148 2026] [security2:error] [pid 85094:tid 85337] [client 216.144.249.201:47820] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/vercel.json"] [unique_id "al4fH6_nUl59BcEkkgGOVAAAAXk"]
[Mon Jul 20 07:14:07.017168 2026] [security2:error] [pid 85094:tid 85313] [client 216.144.249.201:47606] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/openapi.json"] [unique_id "al4fH6_nUl59BcEkkgGOUgAAAWE"]
[Mon Jul 20 07:14:07.017227 2026] [security2:error] [pid 85094:tid 85298] [client 216.144.249.201:47766] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/amplifyconfiguration.json"] [unique_id "al4fH6_nUl59BcEkkgGOVgAAAVI"]
[Mon Jul 20 07:14:07.017268 2026] [security2:error] [pid 85094:tid 85337] [client 216.144.249.201:47820] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/vercel.json"] [unique_id "al4fH6_nUl59BcEkkgGOVAAAAXk"]
[Mon Jul 20 07:14:07.017315 2026] [security2:error] [pid 85094:tid 85298] [client 216.144.249.201:47766] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/amplifyconfiguration.json"] [unique_id "al4fH6_nUl59BcEkkgGOVgAAAVI"]
[Mon Jul 20 07:14:07.018561 2026] [security2:error] [pid 85094:tid 85233] [client 216.144.249.201:47660] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/web.config"] [unique_id "al4fH6_nUl59BcEkkgGOYQAAARI"]
[Mon Jul 20 07:14:07.018842 2026] [security2:error] [pid 85094:tid 85227] [client 216.144.249.201:47442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/wp/.env"] [unique_id "al4fH6_nUl59BcEkkgGOXAAAAQw"]
[Mon Jul 20 07:14:07.018884 2026] [security2:error] [pid 85094:tid 85340] [client 216.144.249.201:47348] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/.env.bak"] [unique_id "al4fH6_nUl59BcEkkgGOTQAAAXw"]
[Mon Jul 20 07:14:07.020896 2026] [security2:error] [pid 85094:tid 85292] [client 216.144.249.201:47254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/wp-includes/js/dist/vendor/react-jsx-runtime.min.js"] [unique_id "al4fH6_nUl59BcEkkgGOdAAAAUw"]
[Mon Jul 20 07:14:07.020993 2026] [security2:error] [pid 85094:tid 85292] [client 216.144.249.201:47254] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/wp-includes/js/dist/vendor/react-jsx-runtime.min.js"] [unique_id "al4fH6_nUl59BcEkkgGOdAAAAUw"]
[Mon Jul 20 07:14:07.020995 2026] [security2:error] [pid 85094:tid 85288] [client 216.144.249.201:47320] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/.env"] [unique_id "al4fH6_nUl59BcEkkgGOagAAAUg"]
[Mon Jul 20 07:14:07.021628 2026] [security2:error] [pid 85094:tid 85238] [client 216.144.249.201:47212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/wp-content/themes/storefront/assets/js/footer.min.js"] [unique_id "al4fH6_nUl59BcEkkgGOgQAAARc"]
[Mon Jul 20 07:14:07.021736 2026] [security2:error] [pid 85094:tid 85238] [client 216.144.249.201:47212] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/wp-content/themes/storefront/assets/js/footer.min.js"] [unique_id "al4fH6_nUl59BcEkkgGOgQAAARc"]
[Mon Jul 20 07:14:07.022186 2026] [security2:error] [pid 85094:tid 85342] [client 216.144.249.201:47400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/backend/.env"] [unique_id "al4fH6_nUl59BcEkkgGOgAAAAX4"]
[Mon Jul 20 07:14:07.022226 2026] [security2:error] [pid 85094:tid 85316] [client 216.144.249.201:47428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/public/.env"] [unique_id "al4fH6_nUl59BcEkkgGOewAAAWQ"]
[Mon Jul 20 07:14:07.022352 2026] [security2:error] [pid 85094:tid 85325] [client 216.144.249.201:47362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/.env.backup"] [unique_id "al4fH6_nUl59BcEkkgGOeAAAAW0"]
[Mon Jul 20 07:14:07.022519 2026] [security2:error] [pid 85094:tid 85306] [client 216.144.249.201:47434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/laravel/.env"] [unique_id "al4fH6_nUl59BcEkkgGOhQAAAVo"]
[Mon Jul 20 07:14:07.029598 2026] [security2:error] [pid 85094:tid 85262] [client 216.144.249.201:47644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.249.144.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-config.php"] [unique_id "al4fH6_nUl59BcEkkgGOWQAAAS8"]
[Mon Jul 20 07:14:07.032026 2026] [security2:error] [pid 85094:tid 85167] [remote 45.90.123.233:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4fH6_nUl59BcEkkgGOjgABW0c"]
[Mon Jul 20 07:14:07.062814 2026] [security2:error] [pid 85094:tid 85255] [client 216.144.249.201:47650] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "schuttfarms.com"] [uri "/wp-config.php.bak"] [unique_id "al4fH6_nUl59BcEkkgGOlAAAASg"]
[Mon Jul 20 07:14:07.572009 2026] [http2:info] [pid 94831:tid 94831] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:14:07.731243 2026] [security2:error] [pid 85094:tid 85307] [client 77.110.127.138:56004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fH6_nUl59BcEkkgGOtgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:07.731419 2026] [security2:error] [pid 85094:tid 85307] [client 77.110.127.138:56004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fH6_nUl59BcEkkgGOtgAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:07.756475 2026] [security2:error] [pid 85094:tid 85290] [client 194.61.41.92:47113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/litespeed.php"] [unique_id "al4fH6_nUl59BcEkkgGOuwAAAUo"]
[Mon Jul 20 07:14:07.935309 2026] [security2:error] [pid 85094:tid 85255] [client 216.144.249.201:47150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/app/.env"] [unique_id "al4fH6_nUl59BcEkkgGOywAAASg"]
[Mon Jul 20 07:14:07.935420 2026] [security2:error] [pid 85094:tid 85255] [client 216.144.249.201:47150] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/app/.env"] [unique_id "al4fH6_nUl59BcEkkgGOywAAASg"]
[Mon Jul 20 07:14:07.941675 2026] [security2:error] [pid 85094:tid 85234] [client 216.144.249.201:47554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/key.json"] [unique_id "al4fH6_nUl59BcEkkgGOzQAAARM"]
[Mon Jul 20 07:14:07.941803 2026] [security2:error] [pid 85094:tid 85234] [client 216.144.249.201:47554] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/key.json"] [unique_id "al4fH6_nUl59BcEkkgGOzQAAARM"]
[Mon Jul 20 07:14:07.945759 2026] [security2:error] [pid 85094:tid 85262] [client 216.144.249.201:47460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/api/.env"] [unique_id "al4fH6_nUl59BcEkkgGO0QAAAS8"]
[Mon Jul 20 07:14:07.945855 2026] [security2:error] [pid 85094:tid 85262] [client 216.144.249.201:47460] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/api/.env"] [unique_id "al4fH6_nUl59BcEkkgGO0QAAAS8"]
[Mon Jul 20 07:14:07.946489 2026] [security2:error] [pid 85094:tid 85240] [client 216.144.249.201:47476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "schuttfarms.com"] [uri "/.env.old"] [unique_id "al4fH6_nUl59BcEkkgGO0AAAARk"]
[Mon Jul 20 07:14:07.951481 2026] [security2:error] [pid 85094:tid 85308] [client 216.144.249.201:47400] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/wp-includes/js/jquery/jquery.min.js.map"] [unique_id "al4fH6_nUl59BcEkkgGO1gAAAVw"]
[Mon Jul 20 07:14:07.951552 2026] [security2:error] [pid 85094:tid 85308] [client 216.144.249.201:47400] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/wp-includes/js/jquery/jquery.min.js.map"] [unique_id "al4fH6_nUl59BcEkkgGO1gAAAVw"]
[Mon Jul 20 07:14:07.972640 2026] [security2:error] [pid 94831:tid 95010] [client 104.234.53.89:26527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fH406NaEKF1g_MW2mKwAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:08.020873 2026] [security2:error] [pid 94831:tid 94838] [remote 124.55.178.99:41050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4fII06NaEKF1g_MW2mMgAALwY"]
[Mon Jul 20 07:14:08.068351 2026] [security2:error] [pid 94831:tid 94839] [remote 160.187.68.132:58016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fII06NaEKF1g_MW2mNwAANQc"]
[Mon Jul 20 07:14:08.068530 2026] [security2:error] [pid 94831:tid 95014] [client 160.187.68.132:58016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fII06NaEKF1g_MW2mNwAANQc"]
[Mon Jul 20 07:14:08.107201 2026] [security2:error] [pid 85094:tid 85291] [client 57.141.18.34:47278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fHK_nUl59BcEkkgGM_AABS1Y"]
[Mon Jul 20 07:14:08.263891 2026] [security2:error] [pid 85094:tid 85298] [client 216.144.249.201:47022] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/wp-content/themes/storefront/assets/js/woocommerce/extensions/brands.min.js.map"] [unique_id "al4fIK_nUl59BcEkkgGO-gAAAVI"]
[Mon Jul 20 07:14:08.264061 2026] [security2:error] [pid 85094:tid 85298] [client 216.144.249.201:47022] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/wp-content/themes/storefront/assets/js/woocommerce/extensions/brands.min.js.map"] [unique_id "al4fIK_nUl59BcEkkgGO-gAAAVI"]
[Mon Jul 20 07:14:08.431112 2026] [security2:error] [pid 94831:tid 94841] [remote 124.55.178.99:41050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4fII06NaEKF1g_MW2mRQAAAwk"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 07:14:08.462356 2026] [autoindex:error] [pid 94831:tid 95032] [client 35.199.26.21:62505] AH01276: Cannot serve directory /home4/sbdwidmy/public_html/website_7ca3a27a/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:14:08.542434 2026] [security2:error] [pid 94831:tid 95077] [client 194.61.41.246:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/images/as.php"] [unique_id "al4fII06NaEKF1g_MW2mSwAAAHQ"]
[Mon Jul 20 07:14:08.627887 2026] [http2:info] [pid 95126:tid 95126] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:14:08.634903 2026] [http2:info] [pid 95128:tid 95128] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:14:08.743669 2026] [autoindex:error] [pid 94831:tid 95063] [client 144.172.114.51:55116] AH01276: Cannot serve directory /home4/mgjpswmy/public_html/website_ea3fe34b/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:14:09.139794 2026] [security2:error] [pid 94831:tid 94999] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mAQAAACY"]
[Mon Jul 20 07:14:09.194243 2026] [security2:error] [pid 94831:tid 94981] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l8QAAABQ"]
[Mon Jul 20 07:14:09.195869 2026] [security2:error] [pid 94831:tid 94993] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l-QAAACA"]
[Mon Jul 20 07:14:09.220074 2026] [security2:error] [pid 94831:tid 94990] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l9gAAAB0"]
[Mon Jul 20 07:14:09.228050 2026] [security2:error] [pid 94831:tid 94977] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l6wAAABA"]
[Mon Jul 20 07:14:09.230539 2026] [security2:error] [pid 94831:tid 94983] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l8AAAABY"]
[Mon Jul 20 07:14:09.235724 2026] [security2:error] [pid 94831:tid 95013] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mAgAAADQ"]
[Mon Jul 20 07:14:09.240296 2026] [security2:error] [pid 94831:tid 94997] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mAAAAACQ"]
[Mon Jul 20 07:14:09.243853 2026] [security2:error] [pid 94831:tid 95022] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mDwAAAD0"]
[Mon Jul 20 07:14:09.247593 2026] [security2:error] [pid 94831:tid 95018] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mBwAAADk"]
[Mon Jul 20 07:14:09.251579 2026] [security2:error] [pid 94831:tid 94985] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l9AAAABg"]
[Mon Jul 20 07:14:09.256975 2026] [security2:error] [pid 85094:tid 85133] [remote 45.90.123.233:54754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4fIa_nUl59BcEkkgGPHQABTyU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:14:09.341671 2026] [security2:error] [pid 95126:tid 95277] [client 194.61.41.57:21027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/setup-config.php"] [unique_id "al4fIQpx5ks9joCJTKWrdAAAAaI"]
[Mon Jul 20 07:14:09.430045 2026] [security2:error] [pid 85094:tid 85353] [client 50.116.65.227:48876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4fIa_nUl59BcEkkgGPGwAAAYk"]
[Mon Jul 20 07:14:09.580072 2026] [security2:error] [pid 85094:tid 85113] [remote 209.42.21.221:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4fIa_nUl59BcEkkgGPLQABPhE"]
[Mon Jul 20 07:14:09.618780 2026] [security2:error] [pid 85094:tid 85289] [client 50.116.65.227:48878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4fIa_nUl59BcEkkgGPJgAAAUk"]
[Mon Jul 20 07:14:09.622842 2026] [security2:error] [pid 95126:tid 95130] [remote 103.187.169.251:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4fIQpx5ks9joCJTKWrdgABjwE"]
[Mon Jul 20 07:14:09.662134 2026] [security2:error] [pid 85094:tid 85284] [client 57.141.18.78:45246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fHq_nUl59BcEkkgGODQABRAc"]
[Mon Jul 20 07:14:09.751014 2026] [security2:error] [pid 85094:tid 85227] [client 50.116.65.227:48884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2026/04/IMG_2998.jpeg"] [unique_id "al4fIa_nUl59BcEkkgGPPQAAAXM"]
[Mon Jul 20 07:14:09.752942 2026] [security2:error] [pid 85094:tid 85212] [remote 209.42.21.221:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4fIa_nUl59BcEkkgGPPAABR3Q"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 07:14:09.881134 2026] [security2:error] [pid 85094:tid 85289] [client 77.110.127.138:56973] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fIa_nUl59BcEkkgGPQAAAAUk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:10.022574 2026] [security2:error] [pid 95126:tid 95131] [remote 103.187.169.251:46680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4fIgpx5ks9joCJTKWrdwABqQI"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 07:14:10.030711 2026] [security2:error] [pid 95128:tid 95548] [client 77.110.127.138:56994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fIueSd8WoG-6-XpCjVwAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:10.030799 2026] [security2:error] [pid 95128:tid 95548] [client 77.110.127.138:56994] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fIueSd8WoG-6-XpCjVwAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:10.128298 2026] [security2:error] [pid 85094:tid 85286] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH6_nUl59BcEkkgGOrwAAAUY"]
[Mon Jul 20 07:14:10.139536 2026] [security2:error] [pid 94831:tid 94987] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l9QAAABo"]
[Mon Jul 20 07:14:10.144993 2026] [security2:error] [pid 94831:tid 95009] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mAwAAADA"]
[Mon Jul 20 07:14:10.146023 2026] [security2:error] [pid 85094:tid 85353] [client 194.61.41.240:36397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/alam.php"] [unique_id "al4fIq_nUl59BcEkkgGPUgAAAYk"]
[Mon Jul 20 07:14:10.149620 2026] [security2:error] [pid 94831:tid 95016] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mCAAAADc"]
[Mon Jul 20 07:14:10.159291 2026] [security2:error] [pid 94831:tid 95017] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mBgAAADg"]
[Mon Jul 20 07:14:10.174745 2026] [security2:error] [pid 94831:tid 94994] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2l_QAAACE"]
[Mon Jul 20 07:14:10.189941 2026] [security2:error] [pid 94831:tid 95029] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4fIo06NaEKF1g_MW2mXwAAAEQ"]
[Mon Jul 20 07:14:10.199229 2026] [security2:error] [pid 94831:tid 95023] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mEQAAAD4"]
[Mon Jul 20 07:14:10.199522 2026] [security2:error] [pid 94831:tid 95030] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mGQAAAEU"]
[Mon Jul 20 07:14:10.199970 2026] [security2:error] [pid 94831:tid 95015] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mCQAAADY"]
[Mon Jul 20 07:14:10.201268 2026] [security2:error] [pid 85094:tid 85293] [client 104.234.53.90:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fIq_nUl59BcEkkgGPWAAAAU0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:10.216284 2026] [security2:error] [pid 94831:tid 95026] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mEwAAAEE"]
[Mon Jul 20 07:14:10.384931 2026] [security2:error] [pid 85094:tid 85332] [client 57.141.18.118:34372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fH6_nUl59BcEkkgGOmQABdCs"]
[Mon Jul 20 07:14:10.903921 2026] [security2:error] [pid 95128:tid 95565] [client 158.173.89.95:30617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fIueSd8WoG-6-XpCjcQAAAkU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:14:10.928165 2026] [security2:error] [pid 95128:tid 95601] [client 194.61.41.100:25977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/cong.php"] [unique_id "al4fIueSd8WoG-6-XpCjdgAAAmk"]
[Mon Jul 20 07:14:10.946891 2026] [core:error] [pid 95126:tid 95315] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:10.946911 2026] [core:error] [pid 95126:tid 95315] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:10.969227 2026] [security2:error] [pid 95128:tid 95580] [client 117.211.236.168:64506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fIueSd8WoG-6-XpCjfAAAAlQ"]
[Mon Jul 20 07:14:10.969319 2026] [security2:error] [pid 95128:tid 95580] [client 117.211.236.168:64506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fIueSd8WoG-6-XpCjfAAAAlQ"]
[Mon Jul 20 07:14:10.975061 2026] [core:error] [pid 95128:tid 95606] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:10.975098 2026] [core:error] [pid 95128:tid 95606] [client 94.154.43.183:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:11.048016 2026] [security2:error] [pid 94831:tid 94973] [client 144.172.114.51:43920] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/.env"] [unique_id "al4fI406NaEKF1g_MW2mZgAAAAw"]
[Mon Jul 20 07:14:11.061242 2026] [security2:error] [pid 94831:tid 94971] [client 34.21.41.254:52301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.lho.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fI406NaEKF1g_MW2mZwAAAAo"]
[Mon Jul 20 07:14:11.125903 2026] [security2:error] [pid 94831:tid 95031] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mHwAAAEY"]
[Mon Jul 20 07:14:11.190091 2026] [security2:error] [pid 94831:tid 95028] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mFgAAAEM"]
[Mon Jul 20 07:14:11.206191 2026] [security2:error] [pid 94831:tid 95025] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mEgAAAEA"]
[Mon Jul 20 07:14:11.239649 2026] [security2:error] [pid 94831:tid 95033] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mJAAAAEg"]
[Mon Jul 20 07:14:11.280343 2026] [security2:error] [pid 95128:tid 95404] [remote 162.19.86.63:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fI-eSd8WoG-6-XpCjhQACdRE"]
[Mon Jul 20 07:14:11.325762 2026] [security2:error] [pid 95126:tid 95340] [client 34.21.41.254:55729] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4fIwpx5ks9joCJTKWrlAAAAeE"]
[Mon Jul 20 07:14:11.478673 2026] [security2:error] [pid 95128:tid 95410] [remote 162.19.86.63:54148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fI-eSd8WoG-6-XpCjkAACkxc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:11.542905 2026] [security2:error] [pid 95128:tid 95411] [remote 160.187.68.132:52736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4fI-eSd8WoG-6-XpCjkwACchg"]
[Mon Jul 20 07:14:11.555742 2026] [security2:error] [pid 95126:tid 95348] [client 34.21.41.254:62526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4fIwpx5ks9joCJTKWrmgAAAek"]
[Mon Jul 20 07:14:11.604499 2026] [security2:error] [pid 95128:tid 95537] [client 50.116.65.227:48908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fI-eSd8WoG-6-XpCjmQAAAik"]
[Mon Jul 20 07:14:11.618615 2026] [security2:error] [pid 95128:tid 95539] [client 50.116.65.227:48910] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fI-eSd8WoG-6-XpCjmgAAAis"]
[Mon Jul 20 07:14:11.671561 2026] [security2:error] [pid 95128:tid 95551] [client 194.61.41.107:36091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/block-bindings/imagess.php"] [unique_id "al4fI-eSd8WoG-6-XpCjogAAAjc"]
[Mon Jul 20 07:14:11.769902 2026] [security2:error] [pid 85094:tid 85247] [client 14.225.17.146:53613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4fIq_nUl59BcEkkgGPUwAAASA"], referer: http://olearyplumbingllc.com/2020
[Mon Jul 20 07:14:11.815764 2026] [security2:error] [pid 95126:tid 95364] [client 34.21.41.254:64521] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4fIwpx5ks9joCJTKWroAAAAfk"]
[Mon Jul 20 07:14:11.834642 2026] [security2:error] [pid 95128:tid 95571] [client 49.37.242.14:58697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fI-eSd8WoG-6-XpCjfwAAAks"]
[Mon Jul 20 07:14:11.841606 2026] [security2:error] [pid 95126:tid 95338] [client 154.208.48.130:56455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fIwpx5ks9joCJTKWroQAAAd8"]
[Mon Jul 20 07:14:11.841723 2026] [security2:error] [pid 95126:tid 95338] [client 154.208.48.130:56455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fIwpx5ks9joCJTKWroQAAAd8"]
[Mon Jul 20 07:14:11.921016 2026] [security2:error] [pid 95128:tid 95583] [client 135.148.32.173:38356] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "colt-innovate.com"] [uri "/"] [unique_id "al4fI-eSd8WoG-6-XpCjtAAAAlc"]
[Mon Jul 20 07:14:11.927437 2026] [security2:error] [pid 95128:tid 95604] [client 135.148.32.173:38368] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "colt-in.com"] [uri "/"] [unique_id "al4fI-eSd8WoG-6-XpCjtQAAAmw"]
[Mon Jul 20 07:14:11.959793 2026] [security2:error] [pid 95128:tid 95518] [client 103.144.65.217:58527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fI-eSd8WoG-6-XpCjuQAAAhY"]
[Mon Jul 20 07:14:11.959980 2026] [security2:error] [pid 95128:tid 95518] [client 103.144.65.217:58527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fI-eSd8WoG-6-XpCjuQAAAhY"]
[Mon Jul 20 07:14:11.975997 2026] [security2:error] [pid 95126:tid 95334] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4fIwpx5ks9joCJTKWrlQAB2wk"], referer: http://assasalnazaha.com/2020
[Mon Jul 20 07:14:12.052841 2026] [security2:error] [pid 95128:tid 95588] [client 34.21.41.254:50362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4fJOeSd8WoG-6-XpCjvQAAAlw"]
[Mon Jul 20 07:14:12.052955 2026] [security2:error] [pid 95128:tid 95424] [remote 160.187.68.132:52736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4fJOeSd8WoG-6-XpCjvAACeiU"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:14:12.062728 2026] [security2:error] [pid 95128:tid 95425] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fJOeSd8WoG-6-XpCjvwACaCY"]
[Mon Jul 20 07:14:12.062957 2026] [security2:error] [pid 95128:tid 95600] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fJOeSd8WoG-6-XpCjvwACaCY"]
[Mon Jul 20 07:14:12.120832 2026] [security2:error] [pid 94831:tid 94997] [client 104.234.53.76:51661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fJI06NaEKF1g_MW2mdgAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:12.149071 2026] [security2:error] [pid 94831:tid 95077] [client 201.27.111.74:59553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fJI06NaEKF1g_MW2megAAAHQ"]
[Mon Jul 20 07:14:12.149308 2026] [security2:error] [pid 94831:tid 95077] [client 201.27.111.74:59553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fJI06NaEKF1g_MW2megAAAHQ"]
[Mon Jul 20 07:14:12.170699 2026] [security2:error] [pid 85094:tid 85255] [client 216.144.249.201:47660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO5gAAASg"]
[Mon Jul 20 07:14:12.172779 2026] [security2:error] [pid 85094:tid 85290] [client 216.144.249.201:47068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO6QAAAUo"]
[Mon Jul 20 07:14:12.193503 2026] [security2:error] [pid 85094:tid 85249] [client 216.144.249.201:47748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO5QAAASI"]
[Mon Jul 20 07:14:12.194105 2026] [security2:error] [pid 85094:tid 85312] [client 216.144.249.201:47244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO5wAAAWA"]
[Mon Jul 20 07:14:12.200071 2026] [security2:error] [pid 95128:tid 95430] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fJOeSd8WoG-6-XpCjyAACeCs"]
[Mon Jul 20 07:14:12.201468 2026] [security2:error] [pid 95128:tid 95616] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fJOeSd8WoG-6-XpCjyAACeCs"]
[Mon Jul 20 07:14:12.201620 2026] [security2:error] [pid 85094:tid 85318] [client 216.144.249.201:47602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO5AAAAWY"]
[Mon Jul 20 07:14:12.224920 2026] [security2:error] [pid 85094:tid 85313] [client 216.144.249.201:47082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO4wAAAWE"]
[Mon Jul 20 07:14:12.255612 2026] [security2:error] [pid 95126:tid 95259] [client 77.110.127.138:57269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fJApx5ks9joCJTKWrrQAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:12.255852 2026] [security2:error] [pid 95126:tid 95259] [client 77.110.127.138:57269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fJApx5ks9joCJTKWrrQAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:12.279632 2026] [security2:error] [pid 94831:tid 95075] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fII06NaEKF1g_MW2mNAAAAHI"]
[Mon Jul 20 07:14:12.282043 2026] [security2:error] [pid 85094:tid 85307] [client 216.144.249.201:47236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO7AAAAVs"]
[Mon Jul 20 07:14:12.314203 2026] [security2:error] [pid 95128:tid 95557] [client 14.225.17.146:55443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4fI-eSd8WoG-6-XpCjugAAAj0"], referer: http://superiorcopywriting.com/2020
[Mon Jul 20 07:14:12.326478 2026] [security2:error] [pid 94831:tid 95061] [client 34.21.41.254:57740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4fJI06NaEKF1g_MW2mgwAAAGQ"]
[Mon Jul 20 07:14:12.351308 2026] [core:error] [pid 95126:tid 95275] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:12.351337 2026] [core:error] [pid 95126:tid 95275] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:12.367647 2026] [security2:error] [pid 95128:tid 95607] [client 14.225.17.146:56891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4fJOeSd8WoG-6-XpCjywAAAm8"], referer: http://mourgroup.com/2020
[Mon Jul 20 07:14:12.407054 2026] [security2:error] [pid 85094:tid 85145] [remote 57.141.18.90:39412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fIa_nUl59BcEkkgGPFgABPDE"]
[Mon Jul 20 07:14:12.423595 2026] [security2:error] [pid 95128:tid 95534] [client 194.61.41.61:59243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/pwnd/adminfus.php"] [unique_id "al4fJOeSd8WoG-6-XpCj0gAAAiY"]
[Mon Jul 20 07:14:12.585185 2026] [security2:error] [pid 95126:tid 95268] [client 34.21.41.254:52040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4fJApx5ks9joCJTKWrsAAAAZk"]
[Mon Jul 20 07:14:12.720465 2026] [security2:error] [pid 95128:tid 95544] [client 57.141.18.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4fJOeSd8WoG-6-XpCj1gAAAjA"]
[Mon Jul 20 07:14:12.721047 2026] [security2:error] [pid 94831:tid 95085] [client 88.241.67.160:56573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fJI06NaEKF1g_MW2miwAAAHw"]
[Mon Jul 20 07:14:12.721225 2026] [security2:error] [pid 94831:tid 95085] [client 88.241.67.160:56573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fJI06NaEKF1g_MW2miwAAAHw"]
[Mon Jul 20 07:14:12.831017 2026] [security2:error] [pid 95128:tid 95536] [client 34.21.41.254:63947] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4fJOeSd8WoG-6-XpCj4AAAAig"]
[Mon Jul 20 07:14:12.935213 2026] [security2:error] [pid 95128:tid 95602] [client 14.225.17.146:64360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4fJOeSd8WoG-6-XpCjzwAAAmo"], referer: http://onewingpictures.com/2020
[Mon Jul 20 07:14:13.127024 2026] [security2:error] [pid 94831:tid 95066] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mLgAAAGk"]
[Mon Jul 20 07:14:13.127759 2026] [security2:error] [pid 95128:tid 95615] [client 34.21.41.254:53642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4fJeeSd8WoG-6-XpCj-QAAAnc"]
[Mon Jul 20 07:14:13.135643 2026] [security2:error] [pid 94831:tid 95080] [client 104.234.53.76:51661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fJY06NaEKF1g_MW2mkwAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:13.143618 2026] [security2:error] [pid 94831:tid 95048] [client 194.61.41.73:21087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/default-filters-edit.php"] [unique_id "al4fJY06NaEKF1g_MW2mlgAAAFc"]
[Mon Jul 20 07:14:13.149377 2026] [security2:error] [pid 85094:tid 85239] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH6_nUl59BcEkkgGO3wAAARg"]
[Mon Jul 20 07:14:13.154473 2026] [security2:error] [pid 94831:tid 95074] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fII06NaEKF1g_MW2mNQAAAHE"]
[Mon Jul 20 07:14:13.174872 2026] [security2:error] [pid 85094:tid 85316] [client 216.144.249.201:47532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH6_nUl59BcEkkgGO4QAAAWQ"]
[Mon Jul 20 07:14:13.179869 2026] [security2:error] [pid 85094:tid 85253] [client 216.144.249.201:47294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO6wAAASY"]
[Mon Jul 20 07:14:13.181535 2026] [security2:error] [pid 94831:tid 95068] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fH406NaEKF1g_MW2mMAAAAGs"]
[Mon Jul 20 07:14:13.199055 2026] [security2:error] [pid 85094:tid 85276] [client 216.144.249.201:47310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO7wAAAT0"]
[Mon Jul 20 07:14:13.200683 2026] [security2:error] [pid 85094:tid 85238] [client 216.144.249.201:47228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO9gAAARc"]
[Mon Jul 20 07:14:13.204093 2026] [security2:error] [pid 85094:tid 85262] [client 216.144.249.201:47442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO6AAAAS8"]
[Mon Jul 20 07:14:13.212180 2026] [security2:error] [pid 85094:tid 85265] [client 216.144.249.201:47118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO8AAAATI"]
[Mon Jul 20 07:14:13.231880 2026] [security2:error] [pid 85094:tid 85273] [client 216.144.249.201:47204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO7gAAATo"]
[Mon Jul 20 07:14:13.238132 2026] [security2:error] [pid 85094:tid 85292] [client 216.144.249.201:47080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO7QAAAUw"]
[Mon Jul 20 07:14:13.245230 2026] [security2:error] [pid 85094:tid 85308] [client 216.144.249.201:47126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO6gAAAVw"]
[Mon Jul 20 07:14:13.258007 2026] [security2:error] [pid 85094:tid 85233] [client 216.144.249.201:47582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO-QAAARI"]
[Mon Jul 20 07:14:13.275701 2026] [security2:error] [pid 85094:tid 85317] [client 216.144.249.201:47160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO9AAAAWU"]
[Mon Jul 20 07:14:13.427845 2026] [security2:error] [pid 95128:tid 95572] [client 34.21.41.254:61276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4fJeeSd8WoG-6-XpCkDAAAAkw"]
[Mon Jul 20 07:14:13.683405 2026] [security2:error] [pid 95128:tid 95546] [client 34.21.41.254:49542] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4fJeeSd8WoG-6-XpCkGQAAAjI"]
[Mon Jul 20 07:14:13.887343 2026] [security2:error] [pid 95128:tid 95555] [client 187.16.64.216:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fJeeSd8WoG-6-XpCkKQAAAjs"]
[Mon Jul 20 07:14:13.887490 2026] [security2:error] [pid 95128:tid 95555] [client 187.16.64.216:58085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fJeeSd8WoG-6-XpCkKQAAAjs"]
[Mon Jul 20 07:14:13.929893 2026] [security2:error] [pid 94831:tid 95057] [client 34.21.41.254:52224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tbd.lho.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4fJY06NaEKF1g_MW2moQAAAGA"]
[Mon Jul 20 07:14:13.968526 2026] [security2:error] [pid 95128:tid 95608] [client 194.61.41.107:43965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/install.php"] [unique_id "al4fJeeSd8WoG-6-XpCkMQAAAnA"]
[Mon Jul 20 07:14:14.132536 2026] [security2:error] [pid 85094:tid 85300] [client 216.144.249.201:47188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO8QAAAVQ"]
[Mon Jul 20 07:14:14.138869 2026] [security2:error] [pid 94831:tid 95011] [client 216.144.249.201:47956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fII06NaEKF1g_MW2mVAAAADI"]
[Mon Jul 20 07:14:14.139772 2026] [security2:error] [pid 94831:tid 94975] [client 216.144.249.201:47910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fII06NaEKF1g_MW2mRAAAAA4"]
[Mon Jul 20 07:14:14.159816 2026] [security2:error] [pid 85094:tid 85315] [client 216.144.249.201:47886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO-AAAAWM"]
[Mon Jul 20 07:14:14.160727 2026] [security2:error] [pid 85094:tid 85269] [client 216.144.249.201:47518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO_AAAATY"]
[Mon Jul 20 07:14:14.171180 2026] [security2:error] [pid 85094:tid 85306] [client 216.144.249.201:47112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fIK_nUl59BcEkkgGO_wAAAVo"]
[Mon Jul 20 07:14:14.221763 2026] [security2:error] [pid 94831:tid 95055] [client 216.144.249.201:47930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fJI06NaEKF1g_MW2mjAAAAF4"]
[Mon Jul 20 07:14:14.395494 2026] [security2:error] [pid 95126:tid 95331] [client 57.141.18.13:49518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fIwpx5ks9joCJTKWrjgAB2Ac"]
[Mon Jul 20 07:14:14.630328 2026] [security2:error] [pid 95128:tid 95580] [client 14.225.17.146:56089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4fJueSd8WoG-6-XpCkSQAAAlQ"], referer: http://effingweirdmuseums.com/2020
[Mon Jul 20 07:14:14.691639 2026] [security2:error] [pid 95128:tid 95545] [client 114.119.131.28:34687] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "muafaces.org"] [uri "/media/"] [unique_id "al4fJueSd8WoG-6-XpCkUgAAAjE"], referer: http://muafaces.org/home-magazine-style-2
[Mon Jul 20 07:14:14.726649 2026] [security2:error] [pid 95128:tid 95549] [client 194.61.41.87:43623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/av.php"] [unique_id "al4fJueSd8WoG-6-XpCkVAAAAjU"]
[Mon Jul 20 07:14:14.753083 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:57525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fJgpx5ks9joCJTKWr3wAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:14.753195 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:57525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fJgpx5ks9joCJTKWr3wAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:15.035629 2026] [core:alert] [pid 95128:tid 95633] [client 44.220.233.148:29538] /home3/princfv3/public_html/.htaccess: php_value takes two arguments, PHP Value
[Mon Jul 20 07:14:15.379236 2026] [security2:error] [pid 95128:tid 95542] [client 14.225.17.146:55379] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4fJ-eSd8WoG-6-XpCkcAAAAi4"], referer: http://amalia-capital.com/2020
[Mon Jul 20 07:14:15.432782 2026] [security2:error] [pid 94831:tid 95008] [client 57.141.18.117:21236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fJI06NaEKF1g_MW2mhwAALxc"]
[Mon Jul 20 07:14:15.449163 2026] [security2:error] [pid 95128:tid 95573] [client 194.61.41.66:43695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/autoload_classmap/about.php"] [unique_id "al4fJ-eSd8WoG-6-XpCkhgAAAk0"]
[Mon Jul 20 07:14:15.602923 2026] [security2:error] [pid 95128:tid 95518] [client 14.225.17.146:56072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4fJ-eSd8WoG-6-XpCkiQAAAhY"], referer: https://effingweirdmuseums.com/2020
[Mon Jul 20 07:14:15.719438 2026] [security2:error] [pid 95126:tid 95274] [client 160.176.31.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4fJwpx5ks9joCJTKWr5gAAAZ8"]
[Mon Jul 20 07:14:15.732613 2026] [security2:error] [pid 95128:tid 95510] [remote 5.161.225.162:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4fJ-eSd8WoG-6-XpCklwACkHs"]
[Mon Jul 20 07:14:15.793907 2026] [security2:error] [pid 95128:tid 95530] [client 135.148.32.173:44050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "coltinnovate.com"] [uri "/"] [unique_id "al4fJ-eSd8WoG-6-XpCkoAAAAiI"]
[Mon Jul 20 07:14:15.794932 2026] [security2:error] [pid 95128:tid 95619] [client 103.176.215.66:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fJ-eSd8WoG-6-XpCkoQAAAns"]
[Mon Jul 20 07:14:15.795370 2026] [security2:error] [pid 95128:tid 95619] [client 103.176.215.66:57101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fJ-eSd8WoG-6-XpCkoQAAAns"]
[Mon Jul 20 07:14:15.817672 2026] [security2:error] [pid 95126:tid 95365] [client 104.234.53.55:35123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4fJwpx5ks9joCJTKWr6AAAAfo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:15.949929 2026] [security2:error] [pid 95128:tid 95390] [remote 5.161.225.162:42180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4fJ-eSd8WoG-6-XpCksQACSgM"], referer: https://samueldcohen.com/wp-login.php
[Mon Jul 20 07:14:16.146778 2026] [security2:error] [pid 94831:tid 94964] [client 216.144.249.201:47930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.249.144.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/xmlrpc.php"] [unique_id "al4fKI06NaEKF1g_MW2mrwAAAAM"]
[Mon Jul 20 07:14:16.203474 2026] [security2:error] [pid 95128:tid 95599] [client 157.20.138.62:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fKOeSd8WoG-6-XpCkvQAAAmc"]
[Mon Jul 20 07:14:16.203647 2026] [security2:error] [pid 95128:tid 95599] [client 157.20.138.62:50750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fKOeSd8WoG-6-XpCkvQAAAmc"]
[Mon Jul 20 07:14:16.221924 2026] [security2:error] [pid 95128:tid 95399] [remote 97.74.87.194:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fKOeSd8WoG-6-XpCkwAACWQw"]
[Mon Jul 20 07:14:16.242961 2026] [security2:error] [pid 95128:tid 95629] [client 194.61.41.84:30149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-configs.php"] [unique_id "al4fKOeSd8WoG-6-XpCkxAAAAoU"]
[Mon Jul 20 07:14:16.293293 2026] [security2:error] [pid 95128:tid 95639] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCkuQAAAo8"]
[Mon Jul 20 07:14:16.501295 2026] [security2:error] [pid 95126:tid 95381] [client 14.225.17.146:63447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKApx5ks9joCJTKWr6wAAAgo"]
[Mon Jul 20 07:14:16.501461 2026] [security2:error] [pid 94831:tid 94995] [client 50.116.65.227:48972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fKI06NaEKF1g_MW2mtAAAACI"]
[Mon Jul 20 07:14:16.511121 2026] [security2:error] [pid 94831:tid 95086] [client 50.116.65.227:48984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fKI06NaEKF1g_MW2mtQAAAH0"]
[Mon Jul 20 07:14:16.583408 2026] [security2:error] [pid 95128:tid 95412] [remote 97.74.87.194:39328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fKOeSd8WoG-6-XpCk3QACMRk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:16.599433 2026] [security2:error] [pid 95128:tid 95414] [remote 8.217.108.67:22230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fKOeSd8WoG-6-XpCk3gACKBs"]
[Mon Jul 20 07:14:16.727580 2026] [security2:error] [pid 95128:tid 95590] [client 49.13.135.18:10197] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCkwgAAAl4"]
[Mon Jul 20 07:14:16.734484 2026] [security2:error] [pid 94831:tid 95087] [client 77.110.127.138:57740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKI06NaEKF1g_MW2muAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:16.734600 2026] [security2:error] [pid 94831:tid 95087] [client 77.110.127.138:57740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKI06NaEKF1g_MW2muAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:16.835005 2026] [security2:error] [pid 95128:tid 95572] [client 154.192.123.127:18676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fKOeSd8WoG-6-XpCk5AAAAkw"]
[Mon Jul 20 07:14:16.835138 2026] [security2:error] [pid 95128:tid 95572] [client 154.192.123.127:18676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fKOeSd8WoG-6-XpCk5AAAAkw"]
[Mon Jul 20 07:14:16.848047 2026] [security2:error] [pid 94831:tid 95062] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKI06NaEKF1g_MW2mtwAAAGU"]
[Mon Jul 20 07:14:16.959312 2026] [security2:error] [pid 95128:tid 95553] [client 216.144.249.201:34924] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/schutt-farms-the-studio"] [unique_id "al4fKOeSd8WoG-6-XpCk9QAAAjk"]
[Mon Jul 20 07:14:16.959437 2026] [security2:error] [pid 95128:tid 95553] [client 216.144.249.201:34924] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/schutt-farms-the-studio"] [unique_id "al4fKOeSd8WoG-6-XpCk9QAAAjk"]
[Mon Jul 20 07:14:16.977234 2026] [security2:error] [pid 95128:tid 95631] [client 63.179.149.246:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCkvwAAAoc"]
[Mon Jul 20 07:14:16.990280 2026] [security2:error] [pid 95128:tid 95638] [client 114.119.132.42:22931] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mezzacraft.com"] [uri "/category/crochet-tips-tutorials-category"] [unique_id "al4fKOeSd8WoG-6-XpCk_QAAAo4"], referer: https://mezzacraft.com/2019/08
[Mon Jul 20 07:14:17.010847 2026] [security2:error] [pid 95128:tid 95616] [client 194.61.41.249:27617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/Auth/index.php"] [unique_id "al4fKeeSd8WoG-6-XpCk_gAAAng"]
[Mon Jul 20 07:14:17.046690 2026] [security2:error] [pid 94831:tid 95023] [client 63.179.149.246:25834] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4fKI06NaEKF1g_MW2msQAAAD4"]
[Mon Jul 20 07:14:17.105769 2026] [security2:error] [pid 95126:tid 95375] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKApx5ks9joCJTKWr-AAAAgQ"]
[Mon Jul 20 07:14:17.155884 2026] [security2:error] [pid 95128:tid 95605] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCk9gAAAm0"]
[Mon Jul 20 07:14:17.172644 2026] [security2:error] [pid 95128:tid 95522] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCk-gAAAho"]
[Mon Jul 20 07:14:17.194919 2026] [security2:error] [pid 95128:tid 95554] [client 52.109.112.174:13057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fKeeSd8WoG-6-XpClDAAAAjo"]
[Mon Jul 20 07:14:17.223646 2026] [security2:error] [pid 95128:tid 95561] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCk-AAAAkE"]
[Mon Jul 20 07:14:17.240719 2026] [security2:error] [pid 95128:tid 95624] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKeeSd8WoG-6-XpClAgAAAoA"]
[Mon Jul 20 07:14:17.249579 2026] [security2:error] [pid 95128:tid 95604] [client 64.225.179.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4fKOeSd8WoG-6-XpCk4AACbBw"], referer: https://packerjanitorial.com
[Mon Jul 20 07:14:17.251585 2026] [security2:error] [pid 94831:tid 95046] [client 77.110.127.138:57809] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 788 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fKY06NaEKF1g_MW2mxwAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:17.274358 2026] [security2:error] [pid 94831:tid 95048] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKY06NaEKF1g_MW2mxgAAAFc"]
[Mon Jul 20 07:14:17.326404 2026] [security2:error] [pid 95128:tid 95430] [remote 162.19.86.63:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4fKeeSd8WoG-6-XpClEwACLCs"]
[Mon Jul 20 07:14:17.351379 2026] [security2:error] [pid 95128:tid 95636] [client 52.109.112.174:13057] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fKeeSd8WoG-6-XpClFgAAAow"]
[Mon Jul 20 07:14:17.539577 2026] [security2:error] [pid 95128:tid 95427] [remote 162.19.86.63:46594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4fKeeSd8WoG-6-XpClIQACeCg"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 07:14:17.590766 2026] [security2:error] [pid 95128:tid 95566] [client 77.110.127.138:57444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKeeSd8WoG-6-XpClJQAAAkY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:17.590863 2026] [security2:error] [pid 95128:tid 95566] [client 77.110.127.138:57444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKeeSd8WoG-6-XpClJQAAAkY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:17.708626 2026] [security2:error] [pid 95126:tid 95280] [client 104.234.53.78:41995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fKQpx5ks9joCJTKWsEAAAAaU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:17.710058 2026] [security2:error] [pid 95128:tid 95584] [client 57.141.18.112:50204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fJueSd8WoG-6-XpCkagACWGk"]
[Mon Jul 20 07:14:17.750185 2026] [security2:error] [pid 95128:tid 95554] [client 194.61.41.100:63501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/widgets/bless2.php"] [unique_id "al4fKeeSd8WoG-6-XpClLgAAAjo"]
[Mon Jul 20 07:14:17.804298 2026] [security2:error] [pid 95126:tid 95338] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKQpx5ks9joCJTKWsDwAAAd8"]
[Mon Jul 20 07:14:17.996146 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKQpx5ks9joCJTKWsGAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:17.996249 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:57874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKQpx5ks9joCJTKWsGAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.224466 2026] [security2:error] [pid 95128:tid 95587] [client 77.110.127.138:57896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKueSd8WoG-6-XpClSQAAAls"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.224564 2026] [security2:error] [pid 95128:tid 95587] [client 77.110.127.138:57896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKueSd8WoG-6-XpClSQAAAls"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.281977 2026] [security2:error] [pid 95126:tid 95355] [client 14.225.17.146:55124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4fKgpx5ks9joCJTKWsHAAAAfA"], referer: http://maxenengineering.com/2020
[Mon Jul 20 07:14:18.287143 2026] [security2:error] [pid 95128:tid 95628] [client 77.110.127.138:57513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKueSd8WoG-6-XpClUgAAAoQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.287247 2026] [security2:error] [pid 95128:tid 95628] [client 77.110.127.138:57513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKueSd8WoG-6-XpClUgAAAoQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.339406 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:57071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKgpx5ks9joCJTKWsIwAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.339524 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:57071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKgpx5ks9joCJTKWsIwAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.407842 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:57129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKgpx5ks9joCJTKWsJQAAAaQ"]
[Mon Jul 20 07:14:18.407965 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:57129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKgpx5ks9joCJTKWsJQAAAaQ"]
[Mon Jul 20 07:14:18.516960 2026] [security2:error] [pid 95128:tid 95524] [client 194.61.41.99:46727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/network/about.php"] [unique_id "al4fKueSd8WoG-6-XpClZAAAAhw"]
[Mon Jul 20 07:14:18.575370 2026] [security2:error] [pid 95128:tid 95535] [client 77.110.127.138:57946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKueSd8WoG-6-XpClaAAAAic"]
[Mon Jul 20 07:14:18.575476 2026] [security2:error] [pid 95128:tid 95535] [client 77.110.127.138:57946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fKueSd8WoG-6-XpClaAAAAic"]
[Mon Jul 20 07:14:18.645040 2026] [security2:error] [pid 95128:tid 95541] [client 181.63.150.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4fKueSd8WoG-6-XpClSAAAAi0"]
[Mon Jul 20 07:14:18.795079 2026] [security2:error] [pid 95128:tid 95461] [remote 162.19.86.63:51544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4fKueSd8WoG-6-XpCldwACc0o"]
[Mon Jul 20 07:14:18.918362 2026] [security2:error] [pid 95128:tid 95604] [client 216.244.66.203:60060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4fKueSd8WoG-6-XpClfAAAAmw"]
[Mon Jul 20 07:14:18.918499 2026] [security2:error] [pid 95128:tid 95604] [client 216.244.66.203:60060] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.savilerowtravel.com"] [uri "/robots.txt"] [unique_id "al4fKueSd8WoG-6-XpClfAAAAmw"]
[Mon Jul 20 07:14:18.945725 2026] [security2:error] [pid 94831:tid 95076] [client 77.110.127.138:57992] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 280 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fKo06NaEKF1g_MW2m3AAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:18.960974 2026] [security2:error] [pid 95128:tid 95464] [remote 156.59.198.135:13348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "kingsafety.ca"] [uri "/wp-content/uploads/2025/08/KSS-Equality-Diversity-Anti-Discrimination-Policy.docx-1.pdf"] [unique_id "al4fKueSd8WoG-6-XpClgwACVk0"]
[Mon Jul 20 07:14:18.993130 2026] [security2:error] [pid 95128:tid 95469] [remote 162.19.86.63:51544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4fKueSd8WoG-6-XpCliAACW1I"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 07:14:19.022646 2026] [security2:error] [pid 95128:tid 95516] [client 4.201.176.24:1474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fK-eSd8WoG-6-XpCliQAAAhQ"]
[Mon Jul 20 07:14:19.034496 2026] [security2:error] [pid 95128:tid 95539] [client 216.144.249.201:34958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/product-category/knit-sweater"] [unique_id "al4fK-eSd8WoG-6-XpCljAAAAis"]
[Mon Jul 20 07:14:19.034583 2026] [security2:error] [pid 95128:tid 95539] [client 216.144.249.201:34958] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/product-category/knit-sweater"] [unique_id "al4fK-eSd8WoG-6-XpCljAAAAis"]
[Mon Jul 20 07:14:19.036480 2026] [security2:error] [pid 95126:tid 95309] [client 216.144.249.201:35000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "schuttfarms.com"] [uri "/product-category/personalized-product"] [unique_id "al4fKwpx5ks9joCJTKWsLwAAAcI"]
[Mon Jul 20 07:14:19.036565 2026] [security2:error] [pid 95126:tid 95309] [client 216.144.249.201:35000] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "schuttfarms.com"] [uri "/product-category/personalized-product"] [unique_id "al4fKwpx5ks9joCJTKWsLwAAAcI"]
[Mon Jul 20 07:14:19.106007 2026] [security2:error] [pid 95128:tid 95636] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKueSd8WoG-6-XpClhAAAAow"]
[Mon Jul 20 07:14:19.114972 2026] [security2:error] [pid 95128:tid 95615] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKueSd8WoG-6-XpClhgAAAnc"]
[Mon Jul 20 07:14:19.183726 2026] [security2:error] [pid 95128:tid 95635] [client 4.201.176.24:1474] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fK-eSd8WoG-6-XpClmAAAAos"]
[Mon Jul 20 07:14:19.225557 2026] [security2:error] [pid 95126:tid 95384] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKwpx5ks9joCJTKWsMQAAAg0"]
[Mon Jul 20 07:14:19.228854 2026] [security2:error] [pid 95126:tid 95285] [client 216.144.249.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4fKwpx5ks9joCJTKWsMgAAAao"]
[Mon Jul 20 07:14:19.247640 2026] [security2:error] [pid 95128:tid 95524] [client 194.61.41.107:30441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/item.php"] [unique_id "al4fK-eSd8WoG-6-XpClmwAAAhw"]
[Mon Jul 20 07:14:19.401986 2026] [security2:error] [pid 95128:tid 95475] [remote 162.19.86.63:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fK-eSd8WoG-6-XpCloQACR1g"]
[Mon Jul 20 07:14:19.486963 2026] [security2:error] [pid 95128:tid 95530] [client 77.110.127.138:57672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fK-eSd8WoG-6-XpClqgAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:19.487046 2026] [security2:error] [pid 95128:tid 95530] [client 77.110.127.138:57672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fK-eSd8WoG-6-XpClqgAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:19.578219 2026] [security2:error] [pid 95128:tid 95608] [client 14.225.17.146:58566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4fK-eSd8WoG-6-XpClrgAAAnA"], referer: http://katsklar.com/2020
[Mon Jul 20 07:14:19.597243 2026] [security2:error] [pid 95128:tid 95482] [remote 162.19.86.63:53963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fK-eSd8WoG-6-XpCltgACO18"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:14:20.040991 2026] [security2:error] [pid 95128:tid 95585] [client 194.61.41.249:23143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Text/Diff/Engine/theme.php"] [unique_id "al4fLOeSd8WoG-6-XpCl1wAAAlk"]
[Mon Jul 20 07:14:20.126381 2026] [security2:error] [pid 95128:tid 95520] [client 14.225.17.146:58638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4fK-eSd8WoG-6-XpClzwAAAhg"], referer: http://swafforddetailing.com/2020
[Mon Jul 20 07:14:20.503524 2026] [security2:error] [pid 95128:tid 95567] [client 14.225.17.146:54956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4fLOeSd8WoG-6-XpCl9AAAAkc"], referer: http://dasmarque.com/2020
[Mon Jul 20 07:14:20.817514 2026] [security2:error] [pid 95128:tid 95591] [client 194.61.41.100:30797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/.well-known/acme-challenge/mah.php"] [unique_id "al4fLOeSd8WoG-6-XpCmCwAAAl8"]
[Mon Jul 20 07:14:21.383225 2026] [security2:error] [pid 95126:tid 95171] [remote 20.153.140.50:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4fLQpx5ks9joCJTKWsQgABvCo"]
[Mon Jul 20 07:14:21.531191 2026] [security2:error] [pid 94831:tid 95061] [client 194.61.41.69:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/shell.php"] [unique_id "al4fLY06NaEKF1g_MW2m7gAAAGQ"]
[Mon Jul 20 07:14:21.777655 2026] [security2:error] [pid 95126:tid 95173] [remote 20.153.140.50:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4fLQpx5ks9joCJTKWsSAAB6yw"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 07:14:22.247422 2026] [security2:error] [pid 95126:tid 95271] [client 194.61.41.251:29303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/customize/class-wp-customize-selective-refresh-library.php"] [unique_id "al4fLgpx5ks9joCJTKWsVgAAAZw"]
[Mon Jul 20 07:14:22.559120 2026] [security2:error] [pid 95126:tid 95374] [client 14.225.17.146:63552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4fLgpx5ks9joCJTKWsWgAAAgM"], referer: http://hammadownenterprises.com/2020
[Mon Jul 20 07:14:22.610956 2026] [security2:error] [pid 95128:tid 95632] [client 103.144.65.217:59155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fLueSd8WoG-6-XpCmXwAAAog"]
[Mon Jul 20 07:14:22.611067 2026] [security2:error] [pid 95128:tid 95632] [client 103.144.65.217:59155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fLueSd8WoG-6-XpCmXwAAAog"]
[Mon Jul 20 07:14:22.611635 2026] [security2:error] [pid 95126:tid 95269] [client 201.27.111.74:60059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fLgpx5ks9joCJTKWsXQAAAZo"]
[Mon Jul 20 07:14:22.611728 2026] [security2:error] [pid 95126:tid 95269] [client 201.27.111.74:60059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fLgpx5ks9joCJTKWsXQAAAZo"]
[Mon Jul 20 07:14:22.624558 2026] [security2:error] [pid 95126:tid 95279] [client 52.167.144.209:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fLgpx5ks9joCJTKWsWAABpC4"]
[Mon Jul 20 07:14:22.682730 2026] [security2:error] [pid 95126:tid 95287] [client 77.110.127.138:58418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fLgpx5ks9joCJTKWsYQAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:22.682829 2026] [security2:error] [pid 95126:tid 95287] [client 77.110.127.138:58418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fLgpx5ks9joCJTKWsYQAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:22.685720 2026] [security2:error] [pid 95128:tid 95420] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fLueSd8WoG-6-XpCmZQACRCE"]
[Mon Jul 20 07:14:22.685897 2026] [security2:error] [pid 95128:tid 95564] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fLueSd8WoG-6-XpCmZQACRCE"]
[Mon Jul 20 07:14:22.844672 2026] [security2:error] [pid 95128:tid 95586] [client 77.110.127.138:58438] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 956 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fLueSd8WoG-6-XpCmbAAAAlo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:22.851933 2026] [security2:error] [pid 95128:tid 95549] [client 77.110.127.138:58439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fLueSd8WoG-6-XpCmbQAAAjU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:22.852031 2026] [security2:error] [pid 95128:tid 95549] [client 77.110.127.138:58439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fLueSd8WoG-6-XpCmbQAAAjU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:22.975704 2026] [security2:error] [pid 95126:tid 95179] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fLgpx5ks9joCJTKWsaAABuzI"]
[Mon Jul 20 07:14:22.975879 2026] [security2:error] [pid 95126:tid 95302] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fLgpx5ks9joCJTKWsaAABuzI"]
[Mon Jul 20 07:14:23.036570 2026] [security2:error] [pid 95128:tid 95523] [client 194.61.41.102:57891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/ms-users.php"] [unique_id "al4fL-eSd8WoG-6-XpCmdAAAAhs"]
[Mon Jul 20 07:14:23.055064 2026] [security2:error] [pid 95128:tid 95623] [client 77.110.127.138:58468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmdgAAAn8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.055172 2026] [security2:error] [pid 95128:tid 95623] [client 77.110.127.138:58468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmdgAAAn8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.209257 2026] [security2:error] [pid 95126:tid 95325] [client 77.110.127.138:58490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fLwpx5ks9joCJTKWsbQAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.209347 2026] [security2:error] [pid 95126:tid 95325] [client 77.110.127.138:58490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fLwpx5ks9joCJTKWsbQAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.405890 2026] [security2:error] [pid 95128:tid 95531] [client 88.241.67.160:55198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fL-eSd8WoG-6-XpCmkgAAAiM"]
[Mon Jul 20 07:14:23.406212 2026] [security2:error] [pid 95128:tid 95531] [client 88.241.67.160:55198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fL-eSd8WoG-6-XpCmkgAAAiM"]
[Mon Jul 20 07:14:23.435611 2026] [security2:error] [pid 95128:tid 95551] [client 77.110.127.138:58504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmlgAAAjc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.435738 2026] [security2:error] [pid 95128:tid 95551] [client 77.110.127.138:58504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmlgAAAjc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.599786 2026] [security2:error] [pid 95128:tid 95564] [client 77.110.127.138:58522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmqAAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.599874 2026] [security2:error] [pid 95128:tid 95564] [client 77.110.127.138:58522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmqAAAAkQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.751260 2026] [security2:error] [pid 95128:tid 95563] [client 77.110.127.138:58538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmuAAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.751350 2026] [security2:error] [pid 95128:tid 95563] [client 77.110.127.138:58538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fL-eSd8WoG-6-XpCmuAAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:23.772145 2026] [security2:error] [pid 95128:tid 95449] [remote 117.0.21.154:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fL-eSd8WoG-6-XpCmtQACgT4"]
[Mon Jul 20 07:14:23.847395 2026] [security2:error] [pid 95128:tid 95552] [client 194.61.41.60:60777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/js/cc.php"] [unique_id "al4fL-eSd8WoG-6-XpCmvwAAAjg"]
[Mon Jul 20 07:14:24.086234 2026] [security2:error] [pid 95128:tid 95562] [client 50.116.65.227:21582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fMOeSd8WoG-6-XpCmxwAAAkI"]
[Mon Jul 20 07:14:24.095181 2026] [security2:error] [pid 95128:tid 95531] [client 50.116.65.227:21592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fMOeSd8WoG-6-XpCmyAAAAiM"]
[Mon Jul 20 07:14:24.152331 2026] [security2:error] [pid 95128:tid 95638] [client 57.141.18.119:59820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fLOeSd8WoG-6-XpCmEwACjn8"]
[Mon Jul 20 07:14:24.231842 2026] [security2:error] [pid 95128:tid 95472] [remote 117.0.21.154:53412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fMOeSd8WoG-6-XpCm0AACFFU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:14:24.390918 2026] [security2:error] [pid 95126:tid 95353] [client 117.211.236.168:65247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fMApx5ks9joCJTKWsewAAAe4"]
[Mon Jul 20 07:14:24.391026 2026] [security2:error] [pid 95126:tid 95353] [client 117.211.236.168:65247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fMApx5ks9joCJTKWsewAAAe4"]
[Mon Jul 20 07:14:24.606500 2026] [security2:error] [pid 95126:tid 95322] [client 38.226.206.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4fMApx5ks9joCJTKWsegAAAc8"]
[Mon Jul 20 07:14:24.612427 2026] [security2:error] [pid 95126:tid 95357] [client 14.225.17.146:63602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4fMApx5ks9joCJTKWsdAAAAfI"], referer: http://gearwaterproof.com/2020
[Mon Jul 20 07:14:24.701386 2026] [security2:error] [pid 95128:tid 95590] [client 194.61.41.250:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/Requests/library/wp-login.php"] [unique_id "al4fMOeSd8WoG-6-XpCm5QAAAl4"]
[Mon Jul 20 07:14:24.811548 2026] [security2:error] [pid 94831:tid 95046] [client 66.249.82.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4fMI06NaEKF1g_MW2nAQAAAFU"]
[Mon Jul 20 07:14:24.845110 2026] [security2:error] [pid 95128:tid 95631] [client 154.208.48.130:57385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fMOeSd8WoG-6-XpCm9gAAAoc"]
[Mon Jul 20 07:14:24.845197 2026] [security2:error] [pid 95128:tid 95631] [client 154.208.48.130:57385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fMOeSd8WoG-6-XpCm9gAAAoc"]
[Mon Jul 20 07:14:24.902431 2026] [security2:error] [pid 95128:tid 95540] [client 187.16.64.216:58662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fMOeSd8WoG-6-XpCm-gAAAiw"]
[Mon Jul 20 07:14:24.902581 2026] [security2:error] [pid 95128:tid 95540] [client 187.16.64.216:58662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fMOeSd8WoG-6-XpCm-gAAAiw"]
[Mon Jul 20 07:14:25.025158 2026] [security2:error] [pid 95126:tid 95280] [client 1.92.216.129:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4fMApx5ks9joCJTKWsdwABpTQ"]
[Mon Jul 20 07:14:25.333016 2026] [security2:error] [pid 95128:tid 95524] [client 136.144.33.17:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "northplating.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4fMeeSd8WoG-6-XpCnCwAAAhw"]
[Mon Jul 20 07:14:25.448057 2026] [core:error] [pid 95128:tid 95553] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:25.448082 2026] [core:error] [pid 95128:tid 95553] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:25.454576 2026] [security2:error] [pid 95128:tid 95566] [client 194.61.41.95:65215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/interactivity-api/about.php"] [unique_id "al4fMeeSd8WoG-6-XpCnFgAAAkY"]
[Mon Jul 20 07:14:25.589091 2026] [security2:error] [pid 95128:tid 95596] [client 49.37.242.14:59219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fMOeSd8WoG-6-XpCm-AAAAmQ"]
[Mon Jul 20 07:14:25.675160 2026] [security2:error] [pid 95128:tid 95639] [client 57.141.18.44:48744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fLueSd8WoG-6-XpCmUQACjyQ"]
[Mon Jul 20 07:14:26.057497 2026] [security2:error] [pid 94831:tid 95007] [client 14.225.17.146:55559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4fMY06NaEKF1g_MW2nDwAAAC4"], referer: http://soloceos.com/2020
[Mon Jul 20 07:14:26.087177 2026] [security2:error] [pid 95128:tid 95540] [client 77.110.127.138:58693] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:na"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fMueSd8WoG-6-XpCnOAAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:26.234176 2026] [security2:error] [pid 95128:tid 95629] [client 194.61.41.108:62409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/css/file.php"] [unique_id "al4fMueSd8WoG-6-XpCnQAAAAoU"]
[Mon Jul 20 07:14:26.292402 2026] [security2:error] [pid 95128:tid 95574] [client 103.176.215.66:57659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fMueSd8WoG-6-XpCnSAAAAk4"]
[Mon Jul 20 07:14:26.293042 2026] [security2:error] [pid 95128:tid 95574] [client 103.176.215.66:57659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fMueSd8WoG-6-XpCnSAAAAk4"]
[Mon Jul 20 07:14:26.675505 2026] [security2:error] [pid 95128:tid 95584] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4fMueSd8WoG-6-XpCnNgACWH4"], referer: http://ardhalwafaa.com/2020
[Mon Jul 20 07:14:26.742665 2026] [security2:error] [pid 95126:tid 95375] [client 157.20.138.62:51308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fMgpx5ks9joCJTKWslQAAAgQ"]
[Mon Jul 20 07:14:26.742795 2026] [security2:error] [pid 95126:tid 95375] [client 157.20.138.62:51308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fMgpx5ks9joCJTKWslQAAAgQ"]
[Mon Jul 20 07:14:26.931581 2026] [security2:error] [pid 95126:tid 95282] [client 77.110.127.138:58286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fMgpx5ks9joCJTKWslgAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:26.931682 2026] [security2:error] [pid 95126:tid 95282] [client 77.110.127.138:58286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fMgpx5ks9joCJTKWslgAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:27.028195 2026] [security2:error] [pid 95128:tid 95567] [client 194.61.41.62:49525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/classic-editor/alam.php"] [unique_id "al4fM-eSd8WoG-6-XpCncwAAAkc"]
[Mon Jul 20 07:14:27.131364 2026] [security2:error] [pid 95128:tid 95634] [client 14.225.17.146:56026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4fM-eSd8WoG-6-XpCncgAAAoo"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2020
[Mon Jul 20 07:14:27.206925 2026] [security2:error] [pid 95126:tid 95338] [client 104.234.53.74:23893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fMwpx5ks9joCJTKWsmQAAAd8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:27.262002 2026] [security2:error] [pid 95126:tid 95283] [client 144.172.114.51:42260] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/.env.bak"] [unique_id "al4fMwpx5ks9joCJTKWsmwAAAag"]
[Mon Jul 20 07:14:27.377657 2026] [security2:error] [pid 95128:tid 95527] [client 154.192.123.127:17054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fM-eSd8WoG-6-XpCnjAAAAh8"]
[Mon Jul 20 07:14:27.377785 2026] [security2:error] [pid 95128:tid 95527] [client 154.192.123.127:17054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fM-eSd8WoG-6-XpCnjAAAAh8"]
[Mon Jul 20 07:14:27.690789 2026] [security2:error] [pid 95126:tid 95310] [client 3.75.183.99:31118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fMwpx5ks9joCJTKWsoAAAAcM"]
[Mon Jul 20 07:14:27.690907 2026] [security2:error] [pid 95126:tid 95310] [client 3.75.183.99:31118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fMwpx5ks9joCJTKWsoAAAAcM"]
[Mon Jul 20 07:14:27.756502 2026] [security2:error] [pid 95128:tid 95540] [client 194.61.41.83:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wordpress/wp-admin/includes/admin-filters.php"] [unique_id "al4fM-eSd8WoG-6-XpCnqQAAAiw"]
[Mon Jul 20 07:14:28.514622 2026] [security2:error] [pid 95128:tid 95637] [client 194.61.41.245:52797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/content.php"] [unique_id "al4fNOeSd8WoG-6-XpCn1AAAAo0"]
[Mon Jul 20 07:14:28.723700 2026] [security2:error] [pid 95126:tid 95352] [client 14.225.17.146:57912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4fNApx5ks9joCJTKWsqgAAAe0"], referer: http://myspineworld.com/2020
[Mon Jul 20 07:14:28.796957 2026] [security2:error] [pid 95128:tid 95549] [client 77.110.127.138:58953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fNOeSd8WoG-6-XpCn5QAAAjU"], referer: https://mezzacraft.com/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/
[Mon Jul 20 07:14:28.847875 2026] [security2:error] [pid 95128:tid 95532] [client 57.141.18.68:45848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fMeeSd8WoG-6-XpCnDQACJGI"]
[Mon Jul 20 07:14:28.918582 2026] [security2:error] [pid 95126:tid 95191] [remote 1.92.216.129:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "< ?[?%] ?|\\\\[ ?php" at REQUEST_HEADERS:Referer. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "805"] [id "340133"] [rev "5"] [msg "Atomicorp.com WAF Rules: HTTP header PHP code injection attack"] [data "<?"] [severity "CRITICAL"] [hostname "paultoursafari.com"] [uri "/wp-content/plugins/elementor/assets/js/shared-frontend-handlers.3b079824c37a5fe2bdaa.bundle.js"] [unique_id "al4fNApx5ks9joCJTKWsrQAB7j4"], referer: https://paultoursafari.com/author/paultoursafari/page/2/%3C?php+echo+wc_get_cart_url()+?%3E
[Mon Jul 20 07:14:28.977389 2026] [security2:error] [pid 95128:tid 95621] [client 144.172.114.51:42298] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/.env.old"] [unique_id "al4fNOeSd8WoG-6-XpCn8AAAAn0"]
[Mon Jul 20 07:14:29.252479 2026] [security2:error] [pid 95128:tid 95624] [client 194.61.41.250:54989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/fm.php%20"] [unique_id "al4fNeeSd8WoG-6-XpCn_wAAAoA"]
[Mon Jul 20 07:14:29.732237 2026] [security2:error] [pid 95128:tid 95612] [client 14.225.17.146:63306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4fNeeSd8WoG-6-XpCoGgAAAnQ"], referer: https://myspineworld.com/2020
[Mon Jul 20 07:14:29.873351 2026] [security2:error] [pid 95128:tid 95588] [client 3.136.111.218:7247] ModSecurity: Warning. Matched phrase "Siteimprove" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.adirondackengineering.com"] [uri "/"] [unique_id "al4fNeeSd8WoG-6-XpCoIAAAAlw"]
[Mon Jul 20 07:14:29.957896 2026] [security2:error] [pid 95126:tid 95274] [client 144.172.114.51:38030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/wp-config.php~"] [unique_id "al4fNQpx5ks9joCJTKWstAAAAZ8"]
[Mon Jul 20 07:14:30.018920 2026] [security2:error] [pid 95128:tid 95583] [client 194.61.41.107:55111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/goods.php"] [unique_id "al4fNueSd8WoG-6-XpCoKAAAAlc"]
[Mon Jul 20 07:14:30.158827 2026] [security2:error] [pid 95126:tid 95366] [client 14.225.17.146:54664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4fNgpx5ks9joCJTKWsuwAAAfs"], referer: http://nikkidesigns.net/2020
[Mon Jul 20 07:14:30.198296 2026] [security2:error] [pid 95128:tid 95531] [client 144.172.114.51:54584] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/.env.backup"] [unique_id "al4fNueSd8WoG-6-XpCoNwAAAiM"]
[Mon Jul 20 07:14:30.231063 2026] [security2:error] [pid 95126:tid 95270] [client 14.225.17.146:54665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4fNgpx5ks9joCJTKWsuQAAAZs"], referer: http://dadanetnet.net/2020
[Mon Jul 20 07:14:30.333994 2026] [security2:error] [pid 95128:tid 95550] [client 3.136.111.218:0] ModSecurity: Warning. Matched phrase "Siteimprove" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.adirondackengineering.com"] [uri "/index.php"] [unique_id "al4fNueSd8WoG-6-XpCoNAAAAjY"]
[Mon Jul 20 07:14:30.335483 2026] [security2:error] [pid 95128:tid 95598] [client 3.136.111.218:4192] ModSecurity: Warning. Matched phrase "Siteimprove" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "www.adirondackengineering.com"] [uri "/"] [unique_id "al4fNueSd8WoG-6-XpCoLwAAAmY"]
[Mon Jul 20 07:14:30.337889 2026] [core:error] [pid 95128:tid 95607] [client 14.225.17.146:58362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:30.337905 2026] [core:error] [pid 95128:tid 95607] [client 14.225.17.146:58362] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:30.484532 2026] [security2:error] [pid 95128:tid 95603] [client 77.110.127.138:59068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:na. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4fNueSd8WoG-6-XpCoRgAAAms"]
[Mon Jul 20 07:14:30.613141 2026] [security2:error] [pid 95128:tid 95488] [remote 57.141.18.38:48676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4fNueSd8WoG-6-XpCoTwACFmU"]
[Mon Jul 20 07:14:30.705479 2026] [security2:error] [pid 95128:tid 95562] [client 77.110.127.138:58693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fNueSd8WoG-6-XpCoUgAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:30.705580 2026] [security2:error] [pid 95128:tid 95562] [client 77.110.127.138:58693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fNueSd8WoG-6-XpCoUgAAAkI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:30.782558 2026] [security2:error] [pid 95128:tid 95592] [client 57.141.18.55:49728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fM-eSd8WoG-6-XpCnpAACYCs"]
[Mon Jul 20 07:14:30.838529 2026] [security2:error] [pid 95128:tid 95523] [client 194.61.41.69:23563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/wp-2019.php"] [unique_id "al4fNueSd8WoG-6-XpCoVgAAAhs"]
[Mon Jul 20 07:14:30.847449 2026] [security2:error] [pid 95126:tid 95375] [client 3.136.111.218:0] ModSecurity: Warning. Matched phrase "Siteimprove" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4fNgpx5ks9joCJTKWsywAAAgQ"]
[Mon Jul 20 07:14:30.849977 2026] [security2:error] [pid 95128:tid 95578] [client 3.136.111.218:44471] ModSecurity: Warning. Matched phrase "Siteimprove" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adirondackengineering.com"] [uri "/"] [unique_id "al4fNueSd8WoG-6-XpCoTgAAAlI"]
[Mon Jul 20 07:14:31.178552 2026] [security2:error] [pid 95128:tid 95516] [client 74.208.214.194:43362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4fN-eSd8WoG-6-XpCoaQAAAhQ"]
[Mon Jul 20 07:14:31.377051 2026] [security2:error] [pid 95128:tid 95624] [client 144.172.114.51:54600] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/private/.env"] [unique_id "al4fN-eSd8WoG-6-XpCocQAAAoA"]
[Mon Jul 20 07:14:31.625612 2026] [security2:error] [pid 95128:tid 95577] [client 194.61.41.107:39035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/SimplePie/info.php"] [unique_id "al4fN-eSd8WoG-6-XpCofgAAAlE"]
[Mon Jul 20 07:14:31.845894 2026] [security2:error] [pid 95126:tid 95326] [client 14.225.17.146:63533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4fNwpx5ks9joCJTKWs0AAAAdM"], referer: http://ravmike.com/2020
[Mon Jul 20 07:14:32.291666 2026] [security2:error] [pid 95126:tid 95299] [client 20.226.66.230:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amagicbutton.com"] [uri "/.well-known/about.php"] [unique_id "al4fOApx5ks9joCJTKWs1AAAAbg"]
[Mon Jul 20 07:14:32.291737 2026] [security2:error] [pid 95126:tid 95299] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "amagicbutton.com"] [uri "/.well-known/about.php"] [unique_id "al4fOApx5ks9joCJTKWs1AAAAbg"]
[Mon Jul 20 07:14:32.344259 2026] [security2:error] [pid 95126:tid 95337] [client 194.61.41.253:42195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/assets/images/cloud.php"] [unique_id "al4fOApx5ks9joCJTKWs1gAAAd4"]
[Mon Jul 20 07:14:32.585635 2026] [security2:error] [pid 95126:tid 95277] [client 74.208.214.194:43368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4fOApx5ks9joCJTKWs2gAAAaI"]
[Mon Jul 20 07:14:32.591419 2026] [security2:error] [pid 94831:tid 95000] [client 3.222.127.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fOI06NaEKF1g_MW2nLwAAJ1A"]
[Mon Jul 20 07:14:32.750416 2026] [security2:error] [pid 95128:tid 95569] [client 14.225.17.146:62815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4fOOeSd8WoG-6-XpCotQAAAkk"], referer: https://ravmike.com/2020
[Mon Jul 20 07:14:32.878501 2026] [security2:error] [pid 95128:tid 95555] [client 77.110.127.138:58910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fOOeSd8WoG-6-XpCouwAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:33.042532 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:59085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fOeeSd8WoG-6-XpCoyAAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:33.042615 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:59085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fOeeSd8WoG-6-XpCoyAAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:33.117890 2026] [security2:error] [pid 95128:tid 95617] [client 194.61.41.62:50721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/log.php"] [unique_id "al4fOeeSd8WoG-6-XpCoywAAAnk"]
[Mon Jul 20 07:14:33.233038 2026] [security2:error] [pid 95128:tid 95616] [client 201.27.111.74:60568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fOeeSd8WoG-6-XpCo1AAAAng"]
[Mon Jul 20 07:14:33.233134 2026] [security2:error] [pid 95128:tid 95616] [client 201.27.111.74:60568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fOeeSd8WoG-6-XpCo1AAAAng"]
[Mon Jul 20 07:14:33.262416 2026] [security2:error] [pid 95128:tid 95637] [client 103.144.65.217:59647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fOeeSd8WoG-6-XpCo1gAAAo0"]
[Mon Jul 20 07:14:33.264139 2026] [security2:error] [pid 95128:tid 95637] [client 103.144.65.217:59647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fOeeSd8WoG-6-XpCo1gAAAo0"]
[Mon Jul 20 07:14:33.412029 2026] [security2:error] [pid 95128:tid 95421] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fOeeSd8WoG-6-XpCo4AACICI"]
[Mon Jul 20 07:14:33.412158 2026] [security2:error] [pid 95128:tid 95528] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fOeeSd8WoG-6-XpCo4AACICI"]
[Mon Jul 20 07:14:33.445342 2026] [security2:error] [pid 95128:tid 95594] [client 144.172.114.51:54612] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/backup/.env"] [unique_id "al4fOeeSd8WoG-6-XpCo4wAAAmI"]
[Mon Jul 20 07:14:33.451978 2026] [security2:error] [pid 94831:tid 95030] [client 117.211.236.168:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fOY06NaEKF1g_MW2nNAAAAEU"]
[Mon Jul 20 07:14:33.452106 2026] [security2:error] [pid 94831:tid 95030] [client 117.211.236.168:49324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fOY06NaEKF1g_MW2nNAAAAEU"]
[Mon Jul 20 07:14:33.482229 2026] [security2:error] [pid 95128:tid 95641] [client 74.7.241.147:55072] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "1ilyn9.com"] [uri "/robots.txt"] [unique_id "al4fOeeSd8WoG-6-XpCo5gAAApE"]
[Mon Jul 20 07:14:33.537658 2026] [security2:error] [pid 95126:tid 95204] [remote 209.42.18.223:41068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fOQpx5ks9joCJTKWs8AABmUs"]
[Mon Jul 20 07:14:33.665059 2026] [security2:error] [pid 95126:tid 95205] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fOQpx5ks9joCJTKWs8wACA0w"]
[Mon Jul 20 07:14:33.665228 2026] [security2:error] [pid 95126:tid 95374] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fOQpx5ks9joCJTKWs8wACA0w"]
[Mon Jul 20 07:14:33.720629 2026] [security2:error] [pid 95126:tid 95206] [remote 209.42.18.223:41068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fOQpx5ks9joCJTKWs9AABsU0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:33.810452 2026] [security2:error] [pid 95126:tid 95275] [client 57.141.18.113:62160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fNgpx5ks9joCJTKWsvAABoEA"]
[Mon Jul 20 07:14:33.857506 2026] [security2:error] [pid 95128:tid 95606] [client 194.61.41.101:32047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/script-loader-react-refresh-runtime-num.php"] [unique_id "al4fOeeSd8WoG-6-XpCo-QAAAm4"]
[Mon Jul 20 07:14:34.038539 2026] [security2:error] [pid 95126:tid 95287] [client 88.241.67.160:55819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fOgpx5ks9joCJTKWtAAAAAaw"]
[Mon Jul 20 07:14:34.038741 2026] [security2:error] [pid 95126:tid 95287] [client 88.241.67.160:55819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fOgpx5ks9joCJTKWtAAAAAaw"]
[Mon Jul 20 07:14:34.219613 2026] [security2:error] [pid 95128:tid 95585] [client 14.225.17.146:63110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4fOueSd8WoG-6-XpCpCwAAAlk"], referer: http://momheadquarters.com/2020
[Mon Jul 20 07:14:34.637193 2026] [security2:error] [pid 95128:tid 95605] [client 104.234.53.92:37111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fOueSd8WoG-6-XpCpIgAAAm0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:34.640705 2026] [security2:error] [pid 95128:tid 95586] [client 194.61.41.244:58739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/script-loader-react-refresh-entry.min-object.php"] [unique_id "al4fOueSd8WoG-6-XpCpIwAAAlo"]
[Mon Jul 20 07:14:34.681726 2026] [autoindex:error] [pid 95128:tid 95446] [remote 35.185.95.129:62048] AH01276: Cannot serve directory /home2/fscxcsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.fsc.xcs.mybluehost.me
[Mon Jul 20 07:14:34.687818 2026] [security2:error] [pid 95128:tid 95633] [client 57.141.18.54:55638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fN-eSd8WoG-6-XpCoYQACiSQ"]
[Mon Jul 20 07:14:34.885982 2026] [security2:error] [pid 95128:tid 95536] [client 13.232.231.177:17672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4fOueSd8WoG-6-XpCpMgAAAig"]
[Mon Jul 20 07:14:34.886108 2026] [security2:error] [pid 95128:tid 95536] [client 13.232.231.177:17672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4fOueSd8WoG-6-XpCpMgAAAig"]
[Mon Jul 20 07:14:35.067612 2026] [security2:error] [pid 95128:tid 95573] [client 4.194.217.15:11444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/nine2code.php"] [unique_id "al4fO-eSd8WoG-6-XpCpQAAAAk0"]
[Mon Jul 20 07:14:35.072373 2026] [security2:error] [pid 95126:tid 95328] [client 13.232.231.177:17676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4fOwpx5ks9joCJTKWtIAAAAdU"]
[Mon Jul 20 07:14:35.419806 2026] [security2:error] [pid 95128:tid 95520] [client 194.61.41.61:33793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/aw.php"] [unique_id "al4fO-eSd8WoG-6-XpCpVAAAAhg"]
[Mon Jul 20 07:14:35.496988 2026] [security2:error] [pid 95128:tid 95521] [client 77.110.127.138:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fO-eSd8WoG-6-XpCpWwAAAhk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:35.534419 2026] [core:error] [pid 95128:tid 95534] [client 14.225.17.146:62888] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:35.534439 2026] [core:error] [pid 95128:tid 95534] [client 14.225.17.146:62888] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:14:35.613044 2026] [security2:error] [pid 94831:tid 94965] [client 158.173.166.181:24225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fO406NaEKF1g_MW2nQgAAAAQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:14:35.641162 2026] [security2:error] [pid 95128:tid 95565] [client 4.194.217.15:5908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/num.php"] [unique_id "al4fO-eSd8WoG-6-XpCpdgAAAkU"]
[Mon Jul 20 07:14:35.653248 2026] [security2:error] [pid 95128:tid 95602] [client 77.110.127.138:59100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fO-eSd8WoG-6-XpCpeQAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:35.653355 2026] [security2:error] [pid 95128:tid 95602] [client 77.110.127.138:59100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fO-eSd8WoG-6-XpCpeQAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:35.808865 2026] [security2:error] [pid 95128:tid 95618] [client 187.16.64.216:59255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fO-eSd8WoG-6-XpCpkQAAAno"]
[Mon Jul 20 07:14:35.808976 2026] [security2:error] [pid 95128:tid 95618] [client 187.16.64.216:59255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fO-eSd8WoG-6-XpCpkQAAAno"]
[Mon Jul 20 07:14:35.982800 2026] [security2:error] [pid 95128:tid 95579] [client 77.110.127.138:59101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fO-eSd8WoG-6-XpCpjAAAAlM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:36.062853 2026] [security2:error] [pid 95128:tid 95523] [client 13.232.231.177:17686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4fPOeSd8WoG-6-XpCpqAAAAhs"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:14:36.137386 2026] [security2:error] [pid 95126:tid 95335] [client 194.61.41.99:45827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/update/gely.php"] [unique_id "al4fPApx5ks9joCJTKWtLwAAAdw"]
[Mon Jul 20 07:14:36.245659 2026] [security2:error] [pid 95126:tid 95268] [client 4.194.217.15:3501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4fPApx5ks9joCJTKWtMAAAAZk"]
[Mon Jul 20 07:14:36.270961 2026] [security2:error] [pid 95126:tid 95280] [client 154.208.48.130:57901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fPApx5ks9joCJTKWtMQAAAaU"]
[Mon Jul 20 07:14:36.271118 2026] [security2:error] [pid 95126:tid 95280] [client 154.208.48.130:57901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fPApx5ks9joCJTKWtMQAAAaU"]
[Mon Jul 20 07:14:36.543970 2026] [security2:error] [pid 95128:tid 95552] [client 50.116.65.227:26908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fPOeSd8WoG-6-XpCpxQAAAjg"]
[Mon Jul 20 07:14:36.553624 2026] [security2:error] [pid 95128:tid 95637] [client 50.116.65.227:26912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fPOeSd8WoG-6-XpCpxgAAAo0"]
[Mon Jul 20 07:14:36.724802 2026] [security2:error] [pid 95128:tid 95590] [client 116.204.44.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fPOeSd8WoG-6-XpCpxwACXg4"], referer: https://www.aleishapenny.ca/listing/page/1343?paged=1&view=grid&posts_per_page=24
[Mon Jul 20 07:14:36.800370 2026] [security2:error] [pid 95128:tid 95524] [client 4.194.217.15:5750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/option.php"] [unique_id "al4fPOeSd8WoG-6-XpCp4QAAAhw"]
[Mon Jul 20 07:14:36.844198 2026] [security2:error] [pid 95128:tid 95604] [client 77.110.127.138:59086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fPOeSd8WoG-6-XpCp0AAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:36.905547 2026] [security2:error] [pid 95128:tid 95534] [client 103.176.215.66:58171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fPOeSd8WoG-6-XpCp7wAAAiY"]
[Mon Jul 20 07:14:36.905946 2026] [security2:error] [pid 95128:tid 95534] [client 103.176.215.66:58171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fPOeSd8WoG-6-XpCp7wAAAiY"]
[Mon Jul 20 07:14:36.933521 2026] [security2:error] [pid 94831:tid 94980] [client 194.61.41.105:31397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/uploads/c99shell.php"] [unique_id "al4fPI06NaEKF1g_MW2nUAAAABM"]
[Mon Jul 20 07:14:37.012145 2026] [security2:error] [pid 95126:tid 95341] [client 49.37.242.14:59665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fPApx5ks9joCJTKWtMwAAAeI"]
[Mon Jul 20 07:14:37.036429 2026] [security2:error] [pid 95126:tid 95285] [client 144.172.114.51:54618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-config.php"] [unique_id "al4fPQpx5ks9joCJTKWtQQAAAao"]
[Mon Jul 20 07:14:37.124923 2026] [security2:error] [pid 95128:tid 95592] [client 50.116.65.227:26918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4fPOeSd8WoG-6-XpCp8wAAAmA"]
[Mon Jul 20 07:14:37.304301 2026] [security2:error] [pid 95128:tid 95607] [client 50.116.65.227:26924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4fPeeSd8WoG-6-XpCp-wAAAm8"]
[Mon Jul 20 07:14:37.308437 2026] [security2:error] [pid 95126:tid 95375] [client 157.20.138.62:51866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fPQpx5ks9joCJTKWtQwAAAgQ"]
[Mon Jul 20 07:14:37.308536 2026] [security2:error] [pid 95126:tid 95375] [client 157.20.138.62:51866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fPQpx5ks9joCJTKWtQwAAAgQ"]
[Mon Jul 20 07:14:37.346075 2026] [security2:error] [pid 95128:tid 95518] [client 4.194.217.15:4841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/p.php"] [unique_id "al4fPeeSd8WoG-6-XpCqCgAAAhY"]
[Mon Jul 20 07:14:37.733091 2026] [security2:error] [pid 95128:tid 95561] [client 77.110.127.138:59118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fPeeSd8WoG-6-XpCqGwAAAkE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:37.735631 2026] [security2:error] [pid 95126:tid 95329] [client 194.61.41.242:20185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/pridmag/admin-footer.php"] [unique_id "al4fPQpx5ks9joCJTKWtSQAAAdY"]
[Mon Jul 20 07:14:37.745779 2026] [security2:error] [pid 95126:tid 95307] [client 14.225.17.146:62550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4fPApx5ks9joCJTKWtNQAAAcA"], referer: http://lutheranphilosopher.com/2020
[Mon Jul 20 07:14:37.890069 2026] [security2:error] [pid 95128:tid 95562] [client 4.194.217.15:10592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/past.php"] [unique_id "al4fPeeSd8WoG-6-XpCqMwAAAkI"]
[Mon Jul 20 07:14:37.955365 2026] [security2:error] [pid 95126:tid 95299] [client 154.192.123.127:17389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fPQpx5ks9joCJTKWtTwAAAbg"]
[Mon Jul 20 07:14:37.955450 2026] [security2:error] [pid 95126:tid 95299] [client 154.192.123.127:17389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fPQpx5ks9joCJTKWtTwAAAbg"]
[Mon Jul 20 07:14:38.059962 2026] [security2:error] [pid 95128:tid 95541] [client 77.110.127.138:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fPueSd8WoG-6-XpCqPgAAAi0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:38.060046 2026] [security2:error] [pid 95128:tid 95541] [client 77.110.127.138:59120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fPueSd8WoG-6-XpCqPgAAAi0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:38.434355 2026] [security2:error] [pid 95126:tid 95325] [client 4.194.217.15:10621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/php.php"] [unique_id "al4fPgpx5ks9joCJTKWtUQAAAdI"]
[Mon Jul 20 07:14:38.520346 2026] [security2:error] [pid 95128:tid 95604] [client 194.61.41.254:41941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/uploads/lala.php"] [unique_id "al4fPueSd8WoG-6-XpCqXgAAAmw"]
[Mon Jul 20 07:14:38.579244 2026] [security2:error] [pid 95128:tid 95587] [client 14.225.17.146:58161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4fPeeSd8WoG-6-XpCp_AAAAls"], referer: http://colinkeyphotography.com/2020
[Mon Jul 20 07:14:38.645903 2026] [security2:error] [pid 95128:tid 95524] [client 185.93.182.171:51854] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fPueSd8WoG-6-XpCqZQAAAhw"]
[Mon Jul 20 07:14:38.646005 2026] [security2:error] [pid 95128:tid 95524] [client 185.93.182.171:51854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fPueSd8WoG-6-XpCqZQAAAhw"]
[Mon Jul 20 07:14:38.716700 2026] [security2:error] [pid 95128:tid 95521] [client 144.172.114.51:54626] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/.env.bak"] [unique_id "al4fPueSd8WoG-6-XpCqaAAAAhk"]
[Mon Jul 20 07:14:38.727492 2026] [security2:error] [pid 95126:tid 95353] [client 77.110.127.138:59090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fPgpx5ks9joCJTKWtUgAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:38.761701 2026] [security2:error] [pid 95128:tid 95473] [remote 173.212.252.15:55800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fPueSd8WoG-6-XpCqbQACNVY"]
[Mon Jul 20 07:14:38.761918 2026] [security2:error] [pid 95128:tid 95549] [client 173.212.252.15:55800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fPueSd8WoG-6-XpCqbQACNVY"]
[Mon Jul 20 07:14:39.055626 2026] [security2:error] [pid 95128:tid 95641] [client 4.194.217.15:12357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/php8.php"] [unique_id "al4fP-eSd8WoG-6-XpCqhgAAApE"]
[Mon Jul 20 07:14:39.228351 2026] [security2:error] [pid 95126:tid 95377] [client 144.172.114.51:54628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-config.php.bak"] [unique_id "al4fPwpx5ks9joCJTKWtYAAAAgY"]
[Mon Jul 20 07:14:39.256411 2026] [security2:error] [pid 95126:tid 95382] [client 194.61.41.92:25741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/IXR/db.php"] [unique_id "al4fPwpx5ks9joCJTKWtYQAAAgs"]
[Mon Jul 20 07:14:39.273760 2026] [security2:error] [pid 95128:tid 95609] [client 57.141.18.95:61512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fO-eSd8WoG-6-XpCpcwACcWM"]
[Mon Jul 20 07:14:39.428286 2026] [security2:error] [pid 95128:tid 95599] [client 77.110.127.138:59127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fP-eSd8WoG-6-XpCqlAAAAmc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:39.428369 2026] [security2:error] [pid 95128:tid 95599] [client 77.110.127.138:59127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fP-eSd8WoG-6-XpCqlAAAAmc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:39.478459 2026] [security2:error] [pid 95126:tid 95358] [client 14.225.17.146:56378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4fPwpx5ks9joCJTKWtYgAAAfM"], referer: http://detroitcsc.com/2020
[Mon Jul 20 07:14:39.639090 2026] [security2:error] [pid 95128:tid 95627] [client 4.194.217.15:10566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/phpinfo.php"] [unique_id "al4fP-eSd8WoG-6-XpCqqwAAAoM"]
[Mon Jul 20 07:14:39.655044 2026] [security2:error] [pid 95128:tid 95577] [client 77.110.127.138:59128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fP-eSd8WoG-6-XpCqnAAAAlE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:39.762488 2026] [security2:error] [pid 95128:tid 95587] [client 14.225.17.146:53030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4fP-eSd8WoG-6-XpCqoAAAAls"], referer: http://jvcmotorsports.com/2020
[Mon Jul 20 07:14:40.029133 2026] [security2:error] [pid 95126:tid 95262] [client 194.61.41.80:47923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/install.php"] [unique_id "al4fQApx5ks9joCJTKWtaQAAAZM"]
[Mon Jul 20 07:14:40.275649 2026] [security2:error] [pid 95128:tid 95389] [remote 95.217.78.234:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4fQOeSd8WoG-6-XpCqzQAChwI"]
[Mon Jul 20 07:14:40.386981 2026] [security2:error] [pid 95128:tid 95395] [remote 8.217.108.67:26104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fQOeSd8WoG-6-XpCqzwACTAg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:14:40.498669 2026] [security2:error] [pid 95128:tid 95509] [remote 95.217.78.234:44638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4fQOeSd8WoG-6-XpCq3AACJ3o"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 07:14:40.502877 2026] [security2:error] [pid 95126:tid 95343] [client 4.194.217.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4fQApx5ks9joCJTKWtbQAAAeQ"]
[Mon Jul 20 07:14:40.675731 2026] [security2:error] [pid 95128:tid 95569] [client 114.119.153.237:56857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "securingmemories.com"] [uri "/index.php/our-story/"] [unique_id "al4fQOeSd8WoG-6-XpCq6AAAAkk"], referer: https://securingmemories.com/index.php/2020/11/02/i-know-what-youre-thinking
[Mon Jul 20 07:14:40.751822 2026] [security2:error] [pid 95126:tid 95281] [client 194.61.41.88:44967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/plugins/wp-theme-editor/include.php%20"] [unique_id "al4fQApx5ks9joCJTKWtdgAAAaY"]
[Mon Jul 20 07:14:40.861648 2026] [security2:error] [pid 95126:tid 95296] [client 4.194.217.15:9655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/post.php"] [unique_id "al4fQApx5ks9joCJTKWtdwAAAbU"]
[Mon Jul 20 07:14:41.030868 2026] [security2:error] [pid 95126:tid 95362] [client 57.141.18.53:30936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fPQpx5ks9joCJTKWtRAAB914"]
[Mon Jul 20 07:14:41.439869 2026] [security2:error] [pid 95128:tid 95598] [client 4.194.217.15:11037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4fQeeSd8WoG-6-XpCrCQAAAmY"]
[Mon Jul 20 07:14:41.514493 2026] [security2:error] [pid 95126:tid 95259] [client 14.225.17.146:63032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4fPwpx5ks9joCJTKWtZwAAAZA"], referer: http://fineartsfactory.net/2020
[Mon Jul 20 07:14:41.521175 2026] [security2:error] [pid 95126:tid 95338] [client 194.61.41.105:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/top.php"] [unique_id "al4fQQpx5ks9joCJTKWtewAAAd8"]
[Mon Jul 20 07:14:42.031236 2026] [security2:error] [pid 95128:tid 95629] [client 4.194.217.15:10560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/public/css.php"] [unique_id "al4fQueSd8WoG-6-XpCrLAAAAoU"]
[Mon Jul 20 07:14:42.240605 2026] [security2:error] [pid 95126:tid 95294] [client 194.61.41.253:48995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/css/dist/install.php"] [unique_id "al4fQgpx5ks9joCJTKWtgQAAAbM"]
[Mon Jul 20 07:14:42.468594 2026] [security2:error] [pid 95128:tid 95617] [client 77.110.127.138:59138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fQueSd8WoG-6-XpCrPQAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:42.498652 2026] [autoindex:error] [pid 95128:tid 95543] [client 35.199.26.21:55486] AH01276: Cannot serve directory /home1/heidimo2/public_html/website_ba575a2e/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:14:42.619702 2026] [security2:error] [pid 94831:tid 95011] [client 4.194.217.15:10577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/r.php"] [unique_id "al4fQo06NaEKF1g_MW2naQAAADI"]
[Mon Jul 20 07:14:42.753088 2026] [security2:error] [pid 95128:tid 95641] [client 195.170.172.102:54260] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; bingbot\\\\/2\\\\.0; \\\\+http:\\\\/\\\\/www\\\\.bing\\\\.com\\\\/bingbot\\\\.htm\\\\)" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/bing.conf"] [line "3"] [id "901006"] [msg "Bing Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.2sweetchicks.com"] [uri "/"] [unique_id "al4fQueSd8WoG-6-XpCrXAAAApE"]
[Mon Jul 20 07:14:42.798610 2026] [security2:error] [pid 95126:tid 95357] [client 144.172.114.51:51446] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/dev/.env"] [unique_id "al4fQgpx5ks9joCJTKWtjAAAAfI"]
[Mon Jul 20 07:14:43.019469 2026] [security2:error] [pid 95126:tid 95366] [client 194.61.41.83:50759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/style-engine/dedi1.php"] [unique_id "al4fQwpx5ks9joCJTKWtkQAAAfs"]
[Mon Jul 20 07:14:43.223247 2026] [security2:error] [pid 95128:tid 95529] [client 4.194.217.15:9301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/radio.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrgQAAAiE"]
[Mon Jul 20 07:14:43.324679 2026] [security2:error] [pid 95128:tid 95574] [client 77.110.127.138:59140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrjgAAAk4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:43.324776 2026] [security2:error] [pid 95128:tid 95574] [client 77.110.127.138:59140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrjgAAAk4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:43.325954 2026] [security2:error] [pid 95128:tid 95603] [client 57.141.18.0:41660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fP-eSd8WoG-6-XpCquAACa28"]
[Mon Jul 20 07:14:43.388820 2026] [security2:error] [pid 95128:tid 95535] [client 98.159.234.160:20239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrkQAAAic"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:14:43.413815 2026] [security2:error] [pid 95128:tid 95568] [client 50.116.65.227:43026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ipl.ysa.mybluehost.me"] [uri "/website_bb9e8c9e/wp-cron.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrkwAAAkg"]
[Mon Jul 20 07:14:43.459356 2026] [security2:error] [pid 95126:tid 95278] [client 144.172.114.51:51460] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/.env.old"] [unique_id "al4fQwpx5ks9joCJTKWtlgAAAaM"]
[Mon Jul 20 07:14:43.568514 2026] [security2:error] [pid 95126:tid 95265] [client 74.7.227.179:60058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4fQwpx5ks9joCJTKWtlQABlmk"], referer: https://tejasenvironmental.com/p=680823
[Mon Jul 20 07:14:43.579820 2026] [security2:error] [pid 95128:tid 95599] [client 14.225.17.146:62956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4fQeeSd8WoG-6-XpCrGgAAAmc"], referer: http://sesamegreenbeans.com/2020
[Mon Jul 20 07:14:43.647143 2026] [security2:error] [pid 95126:tid 95305] [client 201.27.111.74:61080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fQwpx5ks9joCJTKWtmgAAAb4"]
[Mon Jul 20 07:14:43.647278 2026] [security2:error] [pid 95126:tid 95305] [client 201.27.111.74:61080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fQwpx5ks9joCJTKWtmgAAAb4"]
[Mon Jul 20 07:14:43.715756 2026] [security2:error] [pid 94831:tid 95045] [client 14.225.17.146:62875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4fQ406NaEKF1g_MW2nbAAAAFQ"]
[Mon Jul 20 07:14:43.758708 2026] [security2:error] [pid 94831:tid 95055] [client 194.61.41.68:56813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/adminfusm.php"] [unique_id "al4fQ406NaEKF1g_MW2nbgAAAF4"]
[Mon Jul 20 07:14:43.818506 2026] [security2:error] [pid 95128:tid 95548] [client 4.194.217.15:4520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/randkeyword.php7"] [unique_id "al4fQ-eSd8WoG-6-XpCrrwAAAjQ"]
[Mon Jul 20 07:14:43.941113 2026] [security2:error] [pid 95128:tid 95516] [client 103.144.65.217:60101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrtQAAAhQ"]
[Mon Jul 20 07:14:43.941259 2026] [security2:error] [pid 95128:tid 95516] [client 103.144.65.217:60101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrtQAAAhQ"]
[Mon Jul 20 07:14:44.138492 2026] [security2:error] [pid 95128:tid 95469] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fROeSd8WoG-6-XpCrvQACP1I"]
[Mon Jul 20 07:14:44.138613 2026] [security2:error] [pid 95128:tid 95559] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fROeSd8WoG-6-XpCrvQACP1I"]
[Mon Jul 20 07:14:44.318214 2026] [security2:error] [pid 95128:tid 95517] [client 57.141.18.62:37416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fQOeSd8WoG-6-XpCq7gACFRE"]
[Mon Jul 20 07:14:44.336508 2026] [security2:error] [pid 95128:tid 95476] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fROeSd8WoG-6-XpCrzgACcVk"]
[Mon Jul 20 07:14:44.336687 2026] [security2:error] [pid 95128:tid 95609] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fROeSd8WoG-6-XpCrzgACcVk"]
[Mon Jul 20 07:14:44.443328 2026] [security2:error] [pid 95128:tid 95582] [client 4.194.217.15:9318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/readme.php"] [unique_id "al4fROeSd8WoG-6-XpCr1QAAAlY"]
[Mon Jul 20 07:14:44.530587 2026] [security2:error] [pid 95128:tid 95621] [client 194.61.41.78:33817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/click.php"] [unique_id "al4fROeSd8WoG-6-XpCr2AAAAn0"]
[Mon Jul 20 07:14:44.613095 2026] [security2:error] [pid 95128:tid 95547] [client 144.172.114.51:50044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/phpinfo.php"] [unique_id "al4fROeSd8WoG-6-XpCr2wAAAjM"]
[Mon Jul 20 07:14:44.752213 2026] [security2:error] [pid 95128:tid 95615] [client 88.241.67.160:57272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fROeSd8WoG-6-XpCr5wAAAnc"]
[Mon Jul 20 07:14:44.752553 2026] [security2:error] [pid 95128:tid 95615] [client 88.241.67.160:57272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fROeSd8WoG-6-XpCr5wAAAnc"]
[Mon Jul 20 07:14:44.973907 2026] [security2:error] [pid 95128:tid 95490] [remote 182.77.62.24:44670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fROeSd8WoG-6-XpCr-QACLmc"]
[Mon Jul 20 07:14:45.025626 2026] [security2:error] [pid 95128:tid 95593] [client 4.194.217.15:4804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/reze.php"] [unique_id "al4fReeSd8WoG-6-XpCsAAAAAmE"]
[Mon Jul 20 07:14:45.075474 2026] [security2:error] [pid 95126:tid 95370] [client 14.225.17.146:52897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4fRApx5ks9joCJTKWtrwAAAf8"], referer: http://thesoloceos.com/2020
[Mon Jul 20 07:14:45.288539 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:59152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fROeSd8WoG-6-XpCr_gAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:45.344202 2026] [security2:error] [pid 95128:tid 95531] [client 194.61.41.252:47035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/template-less.php"] [unique_id "al4fReeSd8WoG-6-XpCsDwAAAiM"]
[Mon Jul 20 07:14:45.472435 2026] [security2:error] [pid 95128:tid 95607] [client 23.251.146.115:45824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4fReeSd8WoG-6-XpCsEAACb3E"]
[Mon Jul 20 07:14:45.567039 2026] [security2:error] [pid 95128:tid 95395] [remote 182.77.62.24:44670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fReeSd8WoG-6-XpCsIwACRAg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:14:45.587697 2026] [security2:error] [pid 95128:tid 95536] [client 23.251.146.115:45824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4fReeSd8WoG-6-XpCsIAACKHU"]
[Mon Jul 20 07:14:45.590825 2026] [security2:error] [pid 94831:tid 95032] [client 4.194.217.15:12384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/rh.php"] [unique_id "al4fRY06NaEKF1g_MW2ndQAAAEc"]
[Mon Jul 20 07:14:45.794247 2026] [security2:error] [pid 95128:tid 95526] [client 57.141.18.107:60496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fQueSd8WoG-6-XpCrWQACHjU"]
[Mon Jul 20 07:14:45.840657 2026] [security2:error] [pid 95128:tid 95517] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4fReeSd8WoG-6-XpCsMgAAAhU"]
[Mon Jul 20 07:14:45.880199 2026] [security2:error] [pid 95128:tid 95530] [client 117.211.236.168:49908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fReeSd8WoG-6-XpCsOQAAAiI"]
[Mon Jul 20 07:14:45.880302 2026] [security2:error] [pid 95128:tid 95530] [client 117.211.236.168:49908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fReeSd8WoG-6-XpCsOQAAAiI"]
[Mon Jul 20 07:14:46.128349 2026] [security2:error] [pid 95128:tid 95567] [client 194.61.41.99:53307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/pomo/alfa-rex.php"] [unique_id "al4fRueSd8WoG-6-XpCsUwAAAkc"]
[Mon Jul 20 07:14:46.148815 2026] [security2:error] [pid 95126:tid 95336] [client 77.110.127.138:59159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fRgpx5ks9joCJTKWtwwAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:46.148913 2026] [security2:error] [pid 95126:tid 95336] [client 77.110.127.138:59159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fRgpx5ks9joCJTKWtwwAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:46.218337 2026] [security2:error] [pid 95128:tid 95613] [client 4.194.217.15:4517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/rip.php"] [unique_id "al4fRueSd8WoG-6-XpCsWgAAAnU"]
[Mon Jul 20 07:14:46.265424 2026] [security2:error] [pid 95128:tid 95564] [client 144.172.114.51:50054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/info.php"] [unique_id "al4fRueSd8WoG-6-XpCsXwAAAkQ"]
[Mon Jul 20 07:14:46.340946 2026] [security2:error] [pid 95128:tid 95525] [client 52.109.68.130:25537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fRueSd8WoG-6-XpCsagAAAh0"]
[Mon Jul 20 07:14:46.344495 2026] [security2:error] [pid 95128:tid 95519] [client 77.110.127.138:59158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fRueSd8WoG-6-XpCsUgAAAhc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:46.498671 2026] [security2:error] [pid 95128:tid 95521] [client 52.109.68.130:25537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fRueSd8WoG-6-XpCsfAAAAhk"]
[Mon Jul 20 07:14:46.752169 2026] [security2:error] [pid 95126:tid 95364] [client 104.234.53.75:45577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fRgpx5ks9joCJTKWtxwAAAfk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:46.806987 2026] [security2:error] [pid 95128:tid 95541] [client 4.194.217.15:4806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/root.php"] [unique_id "al4fRueSd8WoG-6-XpCsjwAAAi0"]
[Mon Jul 20 07:14:46.817688 2026] [security2:error] [pid 95128:tid 95611] [client 187.16.64.216:59851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fRueSd8WoG-6-XpCskAAAAnM"]
[Mon Jul 20 07:14:46.817820 2026] [security2:error] [pid 95128:tid 95611] [client 187.16.64.216:59851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fRueSd8WoG-6-XpCskAAAAnM"]
[Mon Jul 20 07:14:46.839350 2026] [security2:error] [pid 95128:tid 95600] [client 194.61.41.62:49745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/abcd.php"] [unique_id "al4fRueSd8WoG-6-XpCskwAAAmg"]
[Mon Jul 20 07:14:46.975466 2026] [security2:error] [pid 95128:tid 95551] [client 57.141.18.90:21282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fQ-eSd8WoG-6-XpCrswACN1E"]
[Mon Jul 20 07:14:46.996930 2026] [security2:error] [pid 95128:tid 95604] [client 52.109.0.142:19393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fRueSd8WoG-6-XpCspgAAAmw"]
[Mon Jul 20 07:14:47.017854 2026] [security2:error] [pid 95128:tid 95547] [client 52.109.0.142:19393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fR-eSd8WoG-6-XpCsqgAAAjM"]
[Mon Jul 20 07:14:47.158438 2026] [security2:error] [pid 95128:tid 95619] [client 154.208.48.130:58413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fR-eSd8WoG-6-XpCstwAAAns"]
[Mon Jul 20 07:14:47.158543 2026] [security2:error] [pid 95128:tid 95619] [client 154.208.48.130:58413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fR-eSd8WoG-6-XpCstwAAAns"]
[Mon Jul 20 07:14:47.166062 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:59167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fRueSd8WoG-6-XpCsogAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:47.180182 2026] [security2:error] [pid 95128:tid 95453] [remote 57.141.18.96:34890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4085058"] [unique_id "al4fR-eSd8WoG-6-XpCstgACTUI"]
[Mon Jul 20 07:14:47.368959 2026] [security2:error] [pid 95126:tid 95343] [client 4.194.217.15:11403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/s.php"] [unique_id "al4fRwpx5ks9joCJTKWt0AAAAeQ"]
[Mon Jul 20 07:14:47.396269 2026] [security2:error] [pid 95126:tid 95278] [client 103.176.215.66:58675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fRwpx5ks9joCJTKWt0QAAAaM"]
[Mon Jul 20 07:14:47.396847 2026] [security2:error] [pid 95126:tid 95278] [client 103.176.215.66:58675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fRwpx5ks9joCJTKWt0QAAAaM"]
[Mon Jul 20 07:14:47.654078 2026] [security2:error] [pid 95128:tid 95525] [client 194.61.41.79:56999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/colors/blue/admin-footer.php"] [unique_id "al4fR-eSd8WoG-6-XpCtAwAAAh0"]
[Mon Jul 20 07:14:47.925480 2026] [security2:error] [pid 95128:tid 95587] [client 4.194.217.15:4812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sang.php"] [unique_id "al4fR-eSd8WoG-6-XpCtKgAAAls"]
[Mon Jul 20 07:14:47.947691 2026] [security2:error] [pid 95126:tid 95320] [client 157.20.138.62:52423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fRwpx5ks9joCJTKWt4wAAAc0"]
[Mon Jul 20 07:14:47.947787 2026] [security2:error] [pid 95126:tid 95320] [client 157.20.138.62:52423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fRwpx5ks9joCJTKWt4wAAAc0"]
[Mon Jul 20 07:14:48.067028 2026] [security2:error] [pid 95128:tid 95575] [client 77.110.127.138:59178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fR-eSd8WoG-6-XpCtHQAAAk8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:48.101785 2026] [security2:error] [pid 95128:tid 95569] [client 57.141.18.76:49096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fROeSd8WoG-6-XpCr-AACSWA"]
[Mon Jul 20 07:14:48.298472 2026] [security2:error] [pid 95128:tid 95554] [client 14.225.17.146:49721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4fSOeSd8WoG-6-XpCtSgAAAjo"], referer: http://alaraycreative.com/2020
[Mon Jul 20 07:14:48.470934 2026] [security2:error] [pid 95128:tid 95481] [remote 72.167.132.114:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fSOeSd8WoG-6-XpCtZwACKl4"]
[Mon Jul 20 07:14:48.505570 2026] [security2:error] [pid 95128:tid 95627] [client 4.194.217.15:12365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/scxy.php"] [unique_id "al4fSOeSd8WoG-6-XpCtcQAAAoM"]
[Mon Jul 20 07:14:48.648128 2026] [security2:error] [pid 94831:tid 94979] [client 144.172.114.51:51480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-config.php~"] [unique_id "al4fSI06NaEKF1g_MW2ngQAAABI"]
[Mon Jul 20 07:14:48.690082 2026] [security2:error] [pid 95128:tid 95400] [remote 72.167.132.114:38972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fSOeSd8WoG-6-XpCteQACKw0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:14:48.694261 2026] [security2:error] [pid 95128:tid 95603] [client 194.61.41.62:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fSOeSd8WoG-6-XpCtaQAAAms"]
[Mon Jul 20 07:14:48.856592 2026] [security2:error] [pid 95128:tid 95531] [client 182.253.110.82:35812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4fSOeSd8WoG-6-XpCtYgAAAiM"]
[Mon Jul 20 07:14:48.957075 2026] [security2:error] [pid 95128:tid 95517] [client 104.234.53.55:31477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4fSOeSd8WoG-6-XpCtjAAAAhU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:49.017370 2026] [security2:error] [pid 95128:tid 95546] [client 77.110.127.138:59182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fSOeSd8WoG-6-XpCtgQAAAjI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:49.055507 2026] [security2:error] [pid 95128:tid 95527] [client 50.116.65.227:15530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fSeeSd8WoG-6-XpCtlQAAAh8"]
[Mon Jul 20 07:14:49.065567 2026] [security2:error] [pid 95126:tid 95319] [client 50.116.65.227:15532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fSQpx5ks9joCJTKWt7wAAAcw"]
[Mon Jul 20 07:14:49.108096 2026] [security2:error] [pid 95128:tid 95521] [client 4.194.217.15:5675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sd.php"] [unique_id "al4fSeeSd8WoG-6-XpCtngAAAhk"]
[Mon Jul 20 07:14:49.158739 2026] [security2:error] [pid 95128:tid 95591] [client 154.192.123.127:17712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fSeeSd8WoG-6-XpCtogAAAl8"]
[Mon Jul 20 07:14:49.158881 2026] [security2:error] [pid 95128:tid 95591] [client 154.192.123.127:17712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fSeeSd8WoG-6-XpCtogAAAl8"]
[Mon Jul 20 07:14:49.580193 2026] [security2:error] [pid 95128:tid 95567] [client 194.61.41.62:59293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentytwo/bypass.php"] [unique_id "al4fSeeSd8WoG-6-XpCtugAAAkc"]
[Mon Jul 20 07:14:49.627515 2026] [security2:error] [pid 95128:tid 95579] [client 77.110.127.138:59187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fSeeSd8WoG-6-XpCtvgAAAlM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:49.627592 2026] [security2:error] [pid 95128:tid 95579] [client 77.110.127.138:59187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fSeeSd8WoG-6-XpCtvgAAAlM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:49.697563 2026] [security2:error] [pid 95126:tid 95366] [client 4.194.217.15:9663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sf.php"] [unique_id "al4fSQpx5ks9joCJTKWt-AAAAfs"]
[Mon Jul 20 07:14:49.723325 2026] [security2:error] [pid 95128:tid 95559] [client 77.110.127.138:59154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fSeeSd8WoG-6-XpCtxAAAAj8"], referer: https://mezzacraft.com/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/
[Mon Jul 20 07:14:49.723463 2026] [security2:error] [pid 95128:tid 95559] [client 77.110.127.138:59154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fSeeSd8WoG-6-XpCtxAAAAj8"], referer: https://mezzacraft.com/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/
[Mon Jul 20 07:14:49.809606 2026] [security2:error] [pid 95128:tid 95516] [client 77.110.127.138:59152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fSeeSd8WoG-6-XpCtuwAAAhQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:50.239475 2026] [lsapi:warn] [pid 95128:tid 95619] [client 213.111.158.220:42702] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: http://oldracelimited.com/
[Mon Jul 20 07:14:50.242862 2026] [lsapi:warn] [pid 95128:tid 95619] [client 213.111.158.220:42702] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: http://oldracelimited.com/
[Mon Jul 20 07:14:50.306259 2026] [security2:error] [pid 95126:tid 95372] [client 4.194.217.15:5689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/shell.php"] [unique_id "al4fSgpx5ks9joCJTKWuBgAAAgE"]
[Mon Jul 20 07:14:50.322373 2026] [security2:error] [pid 95128:tid 95620] [client 194.61.41.83:41323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-admin/css/elementskit.php"] [unique_id "al4fSueSd8WoG-6-XpCt6AAAAnw"]
[Mon Jul 20 07:14:50.404083 2026] [security2:error] [pid 95128:tid 95621] [client 57.141.18.41:42826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fR-eSd8WoG-6-XpCs0QACfX8"]
[Mon Jul 20 07:14:50.450120 2026] [security2:error] [pid 95126:tid 95267] [client 47.128.115.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4fSgpx5ks9joCJTKWuAwAAAZg"]
[Mon Jul 20 07:14:50.457600 2026] [security2:error] [pid 95128:tid 95469] [remote 188.40.28.4:44950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fSueSd8WoG-6-XpCt8gACgFI"]
[Mon Jul 20 07:14:50.476232 2026] [security2:error] [pid 95126:tid 95285] [client 144.172.114.51:59808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/config.php"] [unique_id "al4fSgpx5ks9joCJTKWuDgAAAao"]
[Mon Jul 20 07:14:50.662546 2026] [security2:error] [pid 95128:tid 95561] [client 50.116.65.227:15568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4fSueSd8WoG-6-XpCt9QAAAkE"]
[Mon Jul 20 07:14:50.678533 2026] [security2:error] [pid 95128:tid 95528] [client 49.37.242.14:60137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fSeeSd8WoG-6-XpCt0gAAAiA"]
[Mon Jul 20 07:14:50.744667 2026] [security2:error] [pid 95128:tid 95626] [client 213.111.158.220:19756] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "oldracelimited.com"] [uri "/"] [unique_id "al4fSueSd8WoG-6-XpCuDAAAAoI"]
[Mon Jul 20 07:14:50.846580 2026] [security2:error] [pid 95128:tid 95605] [client 50.116.65.227:15592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4fSueSd8WoG-6-XpCuCgAAAm0"]
[Mon Jul 20 07:14:50.902721 2026] [security2:error] [pid 95128:tid 95478] [remote 188.40.28.4:44950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fSueSd8WoG-6-XpCuEwACfFs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:14:51.038064 2026] [security2:error] [pid 95126:tid 95294] [client 194.61.41.69:33233] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "littleaosta.nz"] [uri "/js/1.php7"] [unique_id "al4fSwpx5ks9joCJTKWuJAAAAbM"]
[Mon Jul 20 07:14:51.038172 2026] [security2:error] [pid 95126:tid 95294] [client 194.61.41.69:33233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/js/1.php7"] [unique_id "al4fSwpx5ks9joCJTKWuJAAAAbM"]
[Mon Jul 20 07:14:51.113989 2026] [security2:error] [pid 95126:tid 95352] [client 4.194.217.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4fSgpx5ks9joCJTKWuHQAAAe0"]
[Mon Jul 20 07:14:51.284641 2026] [security2:error] [pid 95126:tid 95361] [client 104.234.53.83:35683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fSwpx5ks9joCJTKWuLAAAAfY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:51.389040 2026] [security2:error] [pid 95128:tid 95621] [client 14.225.17.146:61282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4fS-eSd8WoG-6-XpCuIgAAAn0"], referer: http://ncsynchro.com/2020
[Mon Jul 20 07:14:51.506029 2026] [security2:error] [pid 95126:tid 95368] [client 4.194.217.15:9327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sid3.php"] [unique_id "al4fSwpx5ks9joCJTKWuMwAAAf0"]
[Mon Jul 20 07:14:51.638337 2026] [security2:error] [pid 94831:tid 94994] [client 91.92.42.58:33260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/wp-login.php"] [unique_id "al4fS406NaEKF1g_MW2njwAAACE"]
[Mon Jul 20 07:14:51.847550 2026] [security2:error] [pid 95126:tid 95350] [client 194.61.41.62:59921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes/twentytwentyfour/install.php"] [unique_id "al4fSwpx5ks9joCJTKWuPwAAAes"]
[Mon Jul 20 07:14:52.004713 2026] [security2:error] [pid 95128:tid 95598] [client 143.110.218.154:55249] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.aula.cimahmo.pro"] [uri "/wp-login.php"] [unique_id "al4fS-eSd8WoG-6-XpCuRQAAAmY"]
[Mon Jul 20 07:14:52.014261 2026] [security2:error] [pid 95128:tid 95624] [client 77.110.127.138:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fTOeSd8WoG-6-XpCuSwAAAoA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:52.014348 2026] [security2:error] [pid 95128:tid 95624] [client 77.110.127.138:59177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fTOeSd8WoG-6-XpCuSwAAAoA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:52.084036 2026] [security2:error] [pid 95128:tid 95620] [client 4.194.217.15:9660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/simple.php"] [unique_id "al4fTOeSd8WoG-6-XpCuUQAAAnw"]
[Mon Jul 20 07:14:52.177459 2026] [security2:error] [pid 95128:tid 95582] [client 14.225.17.146:57798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4fSeeSd8WoG-6-XpCtxwAAAlY"], referer: http://healthylifegourmet.org/2020
[Mon Jul 20 07:14:52.645462 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:59202] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4fTOeSd8WoG-6-XpCuhQAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:52.647679 2026] [security2:error] [pid 95126:tid 95358] [client 194.61.41.99:37759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/assets/min.php"] [unique_id "al4fTApx5ks9joCJTKWuTQAAAfM"]
[Mon Jul 20 07:14:52.652983 2026] [security2:error] [pid 95128:tid 95579] [client 144.172.114.51:59822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/wp-config.php"] [unique_id "al4fTOeSd8WoG-6-XpCuhgAAAlM"]
[Mon Jul 20 07:14:52.683369 2026] [security2:error] [pid 95128:tid 95560] [client 4.194.217.15:10595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sitemap.php"] [unique_id "al4fTOeSd8WoG-6-XpCuhwAAAkA"]
[Mon Jul 20 07:14:52.945993 2026] [security2:error] [pid 94831:tid 94840] [remote 57.141.18.50:50048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2637480"] [unique_id "al4fTI06NaEKF1g_MW2nlQAAawg"]
[Mon Jul 20 07:14:53.229876 2026] [security2:error] [pid 95128:tid 95561] [client 4.194.217.15:5680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/size.php"] [unique_id "al4fTeeSd8WoG-6-XpCuqAAAAkE"]
[Mon Jul 20 07:14:53.440076 2026] [security2:error] [pid 95128:tid 95576] [client 194.61.41.86:54753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/wp-conflg.php"] [unique_id "al4fTeeSd8WoG-6-XpCutgAAAlA"]
[Mon Jul 20 07:14:53.623780 2026] [security2:error] [pid 95128:tid 95529] [client 77.110.127.138:59193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fTeeSd8WoG-6-XpCuwwAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:53.623857 2026] [security2:error] [pid 95128:tid 95529] [client 77.110.127.138:59193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fTeeSd8WoG-6-XpCuwwAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:53.787599 2026] [security2:error] [pid 95126:tid 95331] [client 4.194.217.15:5692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sm.php"] [unique_id "al4fTQpx5ks9joCJTKWuaAAAAdg"]
[Mon Jul 20 07:14:54.061325 2026] [security2:error] [pid 95128:tid 95585] [client 201.27.111.74:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fTueSd8WoG-6-XpCu4QAAAlk"]
[Mon Jul 20 07:14:54.061424 2026] [security2:error] [pid 95128:tid 95585] [client 201.27.111.74:61559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fTueSd8WoG-6-XpCu4QAAAlk"]
[Mon Jul 20 07:14:54.088818 2026] [security2:error] [pid 95126:tid 95377] [client 104.234.53.93:34309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fTgpx5ks9joCJTKWuaQAAAgY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:54.195302 2026] [security2:error] [pid 95128:tid 95417] [remote 72.167.132.114:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4fTueSd8WoG-6-XpCu6gACbh4"]
[Mon Jul 20 07:14:54.224810 2026] [security2:error] [pid 95126:tid 95277] [client 194.61.41.240:49843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/backup/autoload_classmap.php"] [unique_id "al4fTgpx5ks9joCJTKWubAAAAaI"]
[Mon Jul 20 07:14:54.350299 2026] [security2:error] [pid 95126:tid 95340] [client 14.225.17.146:61266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4fTgpx5ks9joCJTKWubQAAAeE"]
[Mon Jul 20 07:14:54.369960 2026] [security2:error] [pid 95126:tid 95290] [client 4.194.217.15:5662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sql.php"] [unique_id "al4fTgpx5ks9joCJTKWudAAAAa8"]
[Mon Jul 20 07:14:54.418233 2026] [security2:error] [pid 95128:tid 95444] [remote 72.167.132.114:33622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4fTueSd8WoG-6-XpCu-QACJjk"], referer: https://mail.innspace.ca/wp-login.php
[Mon Jul 20 07:14:54.423663 2026] [security2:error] [pid 95128:tid 95634] [client 45.157.112.60:35303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fTueSd8WoG-6-XpCu-gAAAoo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:14:54.429978 2026] [security2:error] [pid 95128:tid 95559] [client 14.225.17.146:61478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4fTeeSd8WoG-6-XpCunAAAAj8"], referer: http://blaizeaccountingservices.com/2020
[Mon Jul 20 07:14:54.496039 2026] [security2:error] [pid 95128:tid 95600] [client 103.144.65.217:60556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fTueSd8WoG-6-XpCvAAAAAmg"]
[Mon Jul 20 07:14:54.496123 2026] [security2:error] [pid 95128:tid 95600] [client 103.144.65.217:60556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fTueSd8WoG-6-XpCvAAAAAmg"]
[Mon Jul 20 07:14:54.752593 2026] [security2:error] [pid 95128:tid 95447] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fTueSd8WoG-6-XpCvDAACeDw"]
[Mon Jul 20 07:14:54.752773 2026] [security2:error] [pid 95128:tid 95616] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fTueSd8WoG-6-XpCvDAACeDw"]
[Mon Jul 20 07:14:54.774175 2026] [security2:error] [pid 95128:tid 95544] [client 57.141.18.52:30926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fS-eSd8WoG-6-XpCuQwACMHg"]
[Mon Jul 20 07:14:54.904378 2026] [security2:error] [pid 95126:tid 95372] [client 77.110.127.138:59179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4fTgpx5ks9joCJTKWugQAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:54.953518 2026] [security2:error] [pid 94831:tid 94972] [client 4.194.217.15:4849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/ss.php"] [unique_id "al4fTo06NaEKF1g_MW2npgAAAAs"]
[Mon Jul 20 07:14:54.966089 2026] [security2:error] [pid 95128:tid 95603] [client 194.61.41.105:49829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/uploads/uploads.php"] [unique_id "al4fTueSd8WoG-6-XpCvFgAAAms"]
[Mon Jul 20 07:14:55.070507 2026] [security2:error] [pid 95126:tid 95169] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fTwpx5ks9joCJTKWugwACByg"]
[Mon Jul 20 07:14:55.070702 2026] [security2:error] [pid 95126:tid 95378] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fTwpx5ks9joCJTKWugwACByg"]
[Mon Jul 20 07:14:55.114767 2026] [security2:error] [pid 95128:tid 95453] [remote 103.74.123.7:23122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.123.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fT-eSd8WoG-6-XpCvGAACfUI"]
[Mon Jul 20 07:14:55.449526 2026] [security2:error] [pid 95126:tid 95341] [client 88.241.67.160:54395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fTwpx5ks9joCJTKWuhwAAAeI"]
[Mon Jul 20 07:14:55.449885 2026] [security2:error] [pid 95126:tid 95341] [client 88.241.67.160:54395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fTwpx5ks9joCJTKWuhwAAAeI"]
[Mon Jul 20 07:14:55.512817 2026] [security2:error] [pid 95128:tid 95592] [client 4.194.217.15:9088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/stats.php"] [unique_id "al4fT-eSd8WoG-6-XpCvNQAAAmA"]
[Mon Jul 20 07:14:55.547013 2026] [security2:error] [pid 95128:tid 95518] [client 57.141.18.39:48487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fTOeSd8WoG-6-XpCugAACFgc"]
[Mon Jul 20 07:14:55.637575 2026] [fcgid:warn] [pid 95128:tid 95564] (70014)End of file found: [client 66.132.195.114:63472] mod_fcgid: can't get data from http client
[Mon Jul 20 07:14:55.682465 2026] [security2:error] [pid 95128:tid 95443] [remote 45.90.123.233:44974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fT-eSd8WoG-6-XpCvQgACJTg"]
[Mon Jul 20 07:14:55.716109 2026] [security2:error] [pid 94831:tid 95071] [client 194.61.41.69:37417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/file.php"] [unique_id "al4fT406NaEKF1g_MW2nqgAAAG4"]
[Mon Jul 20 07:14:55.806827 2026] [security2:error] [pid 95128:tid 95567] [client 14.225.17.146:53272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4fT-eSd8WoG-6-XpCvQAAAAkc"], referer: http://fluidtemple.org/2020
[Mon Jul 20 07:14:55.883465 2026] [security2:error] [pid 95128:tid 95474] [remote 45.90.123.233:44974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fT-eSd8WoG-6-XpCvVQACL1c"], referer: https://mail.idf.ldc.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:55.892873 2026] [security2:error] [pid 95128:tid 95589] [client 77.110.127.138:59203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fT-eSd8WoG-6-XpCvWwAAAl0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:55.893005 2026] [security2:error] [pid 95128:tid 95589] [client 77.110.127.138:59203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fT-eSd8WoG-6-XpCvWwAAAl0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:55.972956 2026] [security2:error] [pid 95128:tid 95478] [remote 103.74.123.7:23122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.123.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fT-eSd8WoG-6-XpCvZAACWls"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:56.000180 2026] [security2:error] [pid 95128:tid 95551] [client 14.225.17.146:61461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4fT-eSd8WoG-6-XpCvYQAAAjc"], referer: http://aljosour-alarabia.com/2020
[Mon Jul 20 07:14:56.104096 2026] [security2:error] [pid 95128:tid 95571] [client 4.194.217.15:5653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/sump1.php"] [unique_id "al4fUOeSd8WoG-6-XpCvaAAAAks"]
[Mon Jul 20 07:14:56.426369 2026] [security2:error] [pid 95128:tid 95535] [client 194.61.41.95:43453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-content/themes.php"] [unique_id "al4fUOeSd8WoG-6-XpCvhAAAAic"]
[Mon Jul 20 07:14:56.505297 2026] [security2:error] [pid 95128:tid 95496] [remote 47.128.42.255:14786] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sarahholyfield.com"] [uri "/moral-compass/"] [unique_id "al4fUOeSd8WoG-6-XpCviQACe20"]
[Mon Jul 20 07:14:56.674002 2026] [security2:error] [pid 95128:tid 95639] [client 4.194.217.15:3598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/system.php"] [unique_id "al4fUOeSd8WoG-6-XpCvmQAAAo8"]
[Mon Jul 20 07:14:56.871492 2026] [security2:error] [pid 95126:tid 95283] [client 77.110.127.138:59204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4fUApx5ks9joCJTKWukAAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:57.106185 2026] [security2:error] [pid 94831:tid 95028] [client 54.244.177.189:54006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4fUY06NaEKF1g_MW2nsAAAAEM"]
[Mon Jul 20 07:14:57.195685 2026] [security2:error] [pid 95128:tid 95387] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.github/workflows/deploy.yml"] [unique_id "al4fUeeSd8WoG-6-XpCvuwACewA"]
[Mon Jul 20 07:14:57.195761 2026] [security2:error] [pid 95128:tid 95508] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.areitoproducciones.com"] [uri "/z9x8c7v6b5-debug-trigger-api.areitoproducciones.com"] [unique_id "al4fUeeSd8WoG-6-XpCvvAACe3k"]
[Mon Jul 20 07:14:57.196834 2026] [security2:error] [pid 95128:tid 95495] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.git-credentials"] [unique_id "al4fUeeSd8WoG-6-XpCvvQACe2w"]
[Mon Jul 20 07:14:57.196981 2026] [security2:error] [pid 95128:tid 95619] [client 34.39.87.128:58894] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "api.areitoproducciones.com"] [uri "/.git-credentials"] [unique_id "al4fUeeSd8WoG-6-XpCvvQACe2w"]
[Mon Jul 20 07:14:57.197060 2026] [security2:error] [pid 95128:tid 95510] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.env"] [unique_id "al4fUeeSd8WoG-6-XpCvvwACe3s"]
[Mon Jul 20 07:14:57.215220 2026] [security2:error] [pid 95128:tid 95567] [client 4.194.217.15:4975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4fUeeSd8WoG-6-XpCvwQAAAkc"]
[Mon Jul 20 07:14:57.254971 2026] [security2:error] [pid 95128:tid 95590] [client 194.61.41.77:48283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/block-patterns/about.php"] [unique_id "al4fUeeSd8WoG-6-XpCvxAAAAl4"]
[Mon Jul 20 07:14:57.417517 2026] [security2:error] [pid 95128:tid 95440] [remote 217.61.143.92:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fUeeSd8WoG-6-XpCv1QACeDU"]
[Mon Jul 20 07:14:57.417839 2026] [security2:error] [pid 95126:tid 95352] [client 14.251.3.155:55950] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4fUQpx5ks9joCJTKWumAAAAe0"]
[Mon Jul 20 07:14:57.630911 2026] [security2:error] [pid 95128:tid 95552] [client 187.16.64.216:60426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fUeeSd8WoG-6-XpCv5wAAAjg"]
[Mon Jul 20 07:14:57.631046 2026] [security2:error] [pid 95128:tid 95552] [client 187.16.64.216:60426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fUeeSd8WoG-6-XpCv5wAAAjg"]
[Mon Jul 20 07:14:57.641249 2026] [security2:error] [pid 95128:tid 95628] [client 104.234.53.88:64817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fUeeSd8WoG-6-XpCv6AAAAoQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:14:57.649481 2026] [security2:error] [pid 95128:tid 95401] [remote 217.61.143.92:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fUeeSd8WoG-6-XpCv6QACdA4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:14:57.730166 2026] [security2:error] [pid 95128:tid 95608] [client 52.140.101.203:29956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fUeeSd8WoG-6-XpCv7QAAAnA"]
[Mon Jul 20 07:14:57.770692 2026] [security2:error] [pid 95126:tid 95325] [client 4.194.217.15:9115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4fUQpx5ks9joCJTKWuoAAAAdI"]
[Mon Jul 20 07:14:57.854712 2026] [security2:error] [pid 95128:tid 95392] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "api.areitoproducciones.com"] [uri "/graphql"] [unique_id "al4fUeeSd8WoG-6-XpCv8wACewU"]
[Mon Jul 20 07:14:57.856873 2026] [security2:error] [pid 95128:tid 95425] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "api.areitoproducciones.com"] [uri "/.env.local"] [unique_id "al4fUeeSd8WoG-6-XpCv-AACeyY"]
[Mon Jul 20 07:14:57.857611 2026] [security2:error] [pid 95128:tid 95424] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.env.backup"] [unique_id "al4fUeeSd8WoG-6-XpCv-QACeyU"]
[Mon Jul 20 07:14:57.879428 2026] [security2:error] [pid 95126:tid 95259] [client 117.211.236.168:50489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fUQpx5ks9joCJTKWuowAAAZA"]
[Mon Jul 20 07:14:57.879502 2026] [security2:error] [pid 95126:tid 95259] [client 117.211.236.168:50489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fUQpx5ks9joCJTKWuowAAAZA"]
[Mon Jul 20 07:14:57.894662 2026] [security2:error] [pid 95128:tid 95606] [client 144.172.114.51:59846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/admin/phpinfo.php"] [unique_id "al4fUeeSd8WoG-6-XpCv_gAAAm4"]
[Mon Jul 20 07:14:57.936593 2026] [security2:error] [pid 95128:tid 95537] [client 154.208.48.130:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fUeeSd8WoG-6-XpCwAwAAAik"]
[Mon Jul 20 07:14:57.937352 2026] [security2:error] [pid 95128:tid 95537] [client 154.208.48.130:58922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fUeeSd8WoG-6-XpCwAwAAAik"]
[Mon Jul 20 07:14:57.962321 2026] [security2:error] [pid 95128:tid 95551] [client 52.140.101.203:29956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fUeeSd8WoG-6-XpCwBQAAAjc"]
[Mon Jul 20 07:14:58.007821 2026] [security2:error] [pid 95128:tid 95557] [client 103.176.215.66:59181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fUueSd8WoG-6-XpCwDgAAAj0"]
[Mon Jul 20 07:14:58.007917 2026] [security2:error] [pid 95128:tid 95557] [client 103.176.215.66:59181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fUueSd8WoG-6-XpCwDgAAAj0"]
[Mon Jul 20 07:14:58.021338 2026] [security2:error] [pid 95128:tid 95577] [client 57.141.18.1:20030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fTueSd8WoG-6-XpCvCwACUTA"]
[Mon Jul 20 07:14:58.071126 2026] [security2:error] [pid 95128:tid 95581] [client 14.225.17.146:52490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4fUeeSd8WoG-6-XpCv7wAAAlU"], referer: http://lifeisbetterlakeside.com/2020
[Mon Jul 20 07:14:58.079016 2026] [security2:error] [pid 95126:tid 95174] [remote 95.217.78.234:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4fUgpx5ks9joCJTKWupwAB2C0"]
[Mon Jul 20 07:14:58.264488 2026] [security2:error] [pid 95128:tid 95613] [client 20.199.97.14:24288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fUueSd8WoG-6-XpCwIAAAAnU"]
[Mon Jul 20 07:14:58.293564 2026] [security2:error] [pid 95128:tid 95618] [client 194.61.41.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fUueSd8WoG-6-XpCwFQAAAno"]
[Mon Jul 20 07:14:58.310657 2026] [security2:error] [pid 95126:tid 95176] [remote 95.217.78.234:46822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4fUgpx5ks9joCJTKWuqQABny8"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 07:14:58.315075 2026] [security2:error] [pid 95128:tid 95634] [client 4.194.217.15:2783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/system_log.php"] [unique_id "al4fUueSd8WoG-6-XpCwIgAAAoo"]
[Mon Jul 20 07:14:58.335265 2026] [security2:error] [pid 94831:tid 95009] [client 77.110.127.138:59212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fUo06NaEKF1g_MW2nvQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:58.335366 2026] [security2:error] [pid 94831:tid 95009] [client 77.110.127.138:59212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fUo06NaEKF1g_MW2nvQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:14:58.399481 2026] [security2:error] [pid 95126:tid 95277] [client 157.20.138.62:52976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fUgpx5ks9joCJTKWuqgAAAaI"]
[Mon Jul 20 07:14:58.399630 2026] [security2:error] [pid 95126:tid 95277] [client 157.20.138.62:52976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fUgpx5ks9joCJTKWuqgAAAaI"]
[Mon Jul 20 07:14:58.421850 2026] [security2:error] [pid 95128:tid 95568] [client 20.199.97.14:24288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fUueSd8WoG-6-XpCwKgAAAkg"]
[Mon Jul 20 07:14:58.499555 2026] [security2:error] [pid 95128:tid 95438] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "api.areitoproducciones.com"] [uri "/api/graphql"] [unique_id "al4fUueSd8WoG-6-XpCwMQACOzM"]
[Mon Jul 20 07:14:58.833492 2026] [security2:error] [pid 95128:tid 95567] [client 57.141.18.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fUueSd8WoG-6-XpCwQwAAAkc"]
[Mon Jul 20 07:14:58.854011 2026] [security2:error] [pid 95128:tid 95519] [client 14.225.17.146:61275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4fUeeSd8WoG-6-XpCvxgAAAhc"], referer: http://careysheatingandcooling.com/2020
[Mon Jul 20 07:14:58.860696 2026] [security2:error] [pid 94831:tid 95082] [client 4.194.217.15:9358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/t.php"] [unique_id "al4fUo06NaEKF1g_MW2nwwAAAHk"]
[Mon Jul 20 07:14:58.978503 2026] [security2:error] [pid 95128:tid 95514] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/api/.env"] [unique_id "al4fUueSd8WoG-6-XpCwWwACRX8"]
[Mon Jul 20 07:14:58.979422 2026] [security2:error] [pid 95128:tid 95457] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/config/.env"] [unique_id "al4fUueSd8WoG-6-XpCwXQACRUY"]
[Mon Jul 20 07:14:58.993344 2026] [security2:error] [pid 95128:tid 95458] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/backend/.env"] [unique_id "al4fUueSd8WoG-6-XpCwXwACQUc"]
[Mon Jul 20 07:14:58.993596 2026] [security2:error] [pid 95128:tid 95511] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.env.old"] [unique_id "al4fUueSd8WoG-6-XpCwYAACQXw"]
[Mon Jul 20 07:14:58.995653 2026] [security2:error] [pid 95128:tid 95448] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.env.bak"] [unique_id "al4fUueSd8WoG-6-XpCwYQACQT0"]
[Mon Jul 20 07:14:59.057334 2026] [security2:error] [pid 95128:tid 95638] [client 158.173.89.95:58743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fU-eSd8WoG-6-XpCwZgAAAo4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:14:59.172601 2026] [security2:error] [pid 95128:tid 95633] [client 194.61.41.96:43511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/load.php"] [unique_id "al4fU-eSd8WoG-6-XpCwcQAAAok"]
[Mon Jul 20 07:14:59.262150 2026] [security2:error] [pid 95126:tid 95371] [client 50.116.65.227:29248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ait.afz.mybluehost.me"] [uri "/website_d78e7740/wp-cron.php"] [unique_id "al4fUwpx5ks9joCJTKWuuwAAAgA"]
[Mon Jul 20 07:14:59.328925 2026] [security2:error] [pid 95128:tid 95474] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "api.areitoproducciones.com"] [uri "/v1/graphql"] [unique_id "al4fU-eSd8WoG-6-XpCwdwACa1c"]
[Mon Jul 20 07:14:59.428825 2026] [security2:error] [pid 95126:tid 95261] [client 4.194.217.15:10574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/term.php"] [unique_id "al4fUwpx5ks9joCJTKWuvAAAAZI"]
[Mon Jul 20 07:14:59.487924 2026] [security2:error] [pid 95128:tid 95634] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4fU-eSd8WoG-6-XpCwjAAAAoo"]
[Mon Jul 20 07:14:59.585715 2026] [security2:error] [pid 95126:tid 95340] [client 14.225.17.146:60897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4fUgpx5ks9joCJTKWuqAAAAeE"], referer: http://39ishlife.com/2020
[Mon Jul 20 07:14:59.597498 2026] [security2:error] [pid 95128:tid 95528] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4fU-eSd8WoG-6-XpCwkQAAAiA"]
[Mon Jul 20 07:14:59.708727 2026] [security2:error] [pid 95128:tid 95517] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4fU-eSd8WoG-6-XpCwlwAAAhU"]
[Mon Jul 20 07:14:59.800407 2026] [security2:error] [pid 95128:tid 95529] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4fU-eSd8WoG-6-XpCwngAAAiE"]
[Mon Jul 20 07:14:59.807162 2026] [security2:error] [pid 95128:tid 95641] [client 154.192.123.127:18165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fU-eSd8WoG-6-XpCwnwAAApE"]
[Mon Jul 20 07:14:59.807381 2026] [security2:error] [pid 95128:tid 95641] [client 154.192.123.127:18165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fU-eSd8WoG-6-XpCwnwAAApE"]
[Mon Jul 20 07:14:59.895437 2026] [security2:error] [pid 95128:tid 95526] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4fU-eSd8WoG-6-XpCwowAAAh4"]
[Mon Jul 20 07:14:59.954900 2026] [security2:error] [pid 95128:tid 95603] [client 194.61.41.102:44859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/ID3/chosen.php"] [unique_id "al4fU-eSd8WoG-6-XpCwsQAAAms"]
[Mon Jul 20 07:14:59.989966 2026] [security2:error] [pid 95128:tid 95550] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4fU-eSd8WoG-6-XpCwtQAAAjY"]
[Mon Jul 20 07:15:00.019087 2026] [security2:error] [pid 95128:tid 95629] [client 4.194.217.15:5636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/test.php"] [unique_id "al4fVOeSd8WoG-6-XpCwvAAAAoU"]
[Mon Jul 20 07:15:00.081087 2026] [security2:error] [pid 95128:tid 95387] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.areitoproducciones.com"] [uri "/serviceAccountKey.json"] [unique_id "al4fVOeSd8WoG-6-XpCwxAACVQA"]
[Mon Jul 20 07:15:00.086095 2026] [security2:error] [pid 95128:tid 95576] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4fVOeSd8WoG-6-XpCwxQAAAlA"]
[Mon Jul 20 07:15:00.187017 2026] [security2:error] [pid 95126:tid 95288] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4fVApx5ks9joCJTKWuwQAAAa0"]
[Mon Jul 20 07:15:00.364910 2026] [security2:error] [pid 95126:tid 95338] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4fVApx5ks9joCJTKWuxQAAAd8"]
[Mon Jul 20 07:15:00.504374 2026] [security2:error] [pid 95128:tid 95605] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4fVOeSd8WoG-6-XpCw5wAAAm0"]
[Mon Jul 20 07:15:00.538699 2026] [security2:error] [pid 95126:tid 95329] [client 144.172.114.51:40900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/test/phpinfo.php"] [unique_id "al4fVApx5ks9joCJTKWuxwAAAdY"]
[Mon Jul 20 07:15:00.585521 2026] [security2:error] [pid 95128:tid 95620] [client 4.194.217.15:2788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/test1.php"] [unique_id "al4fVOeSd8WoG-6-XpCw9AAAAnw"]
[Mon Jul 20 07:15:00.688647 2026] [security2:error] [pid 95128:tid 95572] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4fVOeSd8WoG-6-XpCxAQAAAkw"]
[Mon Jul 20 07:15:00.728807 2026] [security2:error] [pid 95126:tid 95306] [client 194.61.41.247:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.41.61.194.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "littleaosta.nz"] [uri "/wp-includes/class-wp-theme-float.php"] [unique_id "al4fVApx5ks9joCJTKWuywAAAb8"]
[Mon Jul 20 07:15:00.839125 2026] [security2:error] [pid 95128:tid 95522] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "poopatrol608.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4fVOeSd8WoG-6-XpCxCgAAAho"]
[Mon Jul 20 07:15:00.919310 2026] [security2:error] [pid 95128:tid 95607] [client 57.141.18.59:51198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fUeeSd8WoG-6-XpCv3wACbyA"]
[Mon Jul 20 07:15:00.927635 2026] [security2:error] [pid 95128:tid 95538] [client 114.119.134.207:40585] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "floorsourcestock.com"] [uri "/product/flagstaff-cypress-5-by-sunstone-tile/"] [unique_id "al4fVOeSd8WoG-6-XpCxEgAAAio"], referer: https://floorsourcestock.com/product-category/tile
[Mon Jul 20 07:15:00.996462 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:59259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fVOeSd8WoG-6-XpCxHgAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:00.996559 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:59259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fVOeSd8WoG-6-XpCxHgAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:01.179719 2026] [security2:error] [pid 95128:tid 95528] [client 4.194.217.15:5635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/tfm.php"] [unique_id "al4fVeeSd8WoG-6-XpCxLAAAAiA"]
[Mon Jul 20 07:15:01.197141 2026] [security2:error] [pid 95126:tid 95332] [client 144.172.114.51:40914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/info.php"] [unique_id "al4fVQpx5ks9joCJTKWuzAAAAdk"]
[Mon Jul 20 07:15:01.228198 2026] [security2:error] [pid 95128:tid 95451] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.ssh/id_ed25519"] [unique_id "al4fVeeSd8WoG-6-XpCxNwACREA"]
[Mon Jul 20 07:15:01.228977 2026] [authz_core:error] [pid 95128:tid 95414] [remote 34.39.87.128:58894] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 07:15:01.229455 2026] [security2:error] [pid 95128:tid 95438] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.ssh/id_rsa"] [unique_id "al4fVeeSd8WoG-6-XpCxNAACRDM"]
[Mon Jul 20 07:15:01.361903 2026] [security2:error] [pid 95128:tid 95642] [client 77.110.127.138:59262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fVeeSd8WoG-6-XpCxJwAAApI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:01.448431 2026] [security2:error] [pid 95128:tid 95518] [client 14.225.17.146:60746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4fVeeSd8WoG-6-XpCxPQAAAhY"], referer: http://headachescarpaltunnelfibromyalgia.com/2020
[Mon Jul 20 07:15:01.454840 2026] [cgid:error] [pid 95128:tid 95590] [client 66.132.195.114:52656] AH01265: stderr from /home1/threetj3/public_html/website_fa490990/cgi-bin/: attempt to invoke directory as script, referer: http://website-fa490990.threethirds.co:80/cgi-bin
[Mon Jul 20 07:15:01.538690 2026] [security2:error] [pid 95128:tid 95640] [client 194.61.41.77:35161] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "littleaosta.nz"] [uri "/images/c99.php"] [unique_id "al4fVeeSd8WoG-6-XpCxVAAAApA"]
[Mon Jul 20 07:15:01.560854 2026] [security2:error] [pid 95128:tid 95434] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/id_rsa"] [unique_id "al4fVeeSd8WoG-6-XpCxXQACii8"]
[Mon Jul 20 07:15:01.717813 2026] [security2:error] [pid 95126:tid 95310] [client 50.116.65.227:45722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fVQpx5ks9joCJTKWu1QAAAcM"]
[Mon Jul 20 07:15:01.722374 2026] [security2:error] [pid 95128:tid 95556] [client 4.194.217.15:6389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/thebe.php"] [unique_id "al4fVeeSd8WoG-6-XpCxbQAAAjw"]
[Mon Jul 20 07:15:01.730369 2026] [security2:error] [pid 95128:tid 95599] [client 50.116.65.227:45736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fVeeSd8WoG-6-XpCxbgAAAmc"]
[Mon Jul 20 07:15:01.737552 2026] [security2:error] [pid 95128:tid 95443] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/id_dsa"] [unique_id "al4fVeeSd8WoG-6-XpCxcgACgzg"]
[Mon Jul 20 07:15:01.738166 2026] [security2:error] [pid 95128:tid 95460] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.ssh/id_dsa"] [unique_id "al4fVeeSd8WoG-6-XpCxcQACg0k"]
[Mon Jul 20 07:15:02.267881 2026] [security2:error] [pid 95126:tid 95274] [client 4.194.217.15:6364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/themes.php"] [unique_id "al4fVgpx5ks9joCJTKWu3AAAAZ8"]
[Mon Jul 20 07:15:02.279028 2026] [security2:error] [pid 95126:tid 95316] [client 194.61.41.241:32563] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "littleaosta.nz"] [uri "/images/c99.php"] [unique_id "al4fVgpx5ks9joCJTKWu3QAAAck"]
[Mon Jul 20 07:15:02.302487 2026] [security2:error] [pid 94831:tid 94869] [remote 57.141.18.10:59718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4319861"] [unique_id "al4fVo06NaEKF1g_MW2n0wAAOCU"]
[Mon Jul 20 07:15:02.362223 2026] [security2:error] [pid 95128:tid 95636] [client 49.37.242.14:60620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fVeeSd8WoG-6-XpCxagAAAow"]
[Mon Jul 20 07:15:02.488071 2026] [security2:error] [pid 94831:tid 95042] [client 14.225.17.146:64506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4fVo06NaEKF1g_MW2n1AAAAFE"], referer: http://maplerespiteservices.com/2020
[Mon Jul 20 07:15:02.710211 2026] [security2:error] [pid 95128:tid 95404] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/key.pem"] [unique_id "al4fVueSd8WoG-6-XpCxuwACSRE"]
[Mon Jul 20 07:15:02.711676 2026] [security2:error] [pid 95128:tid 95430] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/privatekey.key"] [unique_id "al4fVueSd8WoG-6-XpCxvgACSSs"]
[Mon Jul 20 07:15:02.937042 2026] [security2:error] [pid 95128:tid 95536] [client 77.110.127.138:59214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4fVueSd8WoG-6-XpCx0AAAAig"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:03.012597 2026] [security2:error] [pid 95126:tid 95371] [client 4.194.217.15:5646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/tiny.php"] [unique_id "al4fVwpx5ks9joCJTKWu5QAAAgA"]
[Mon Jul 20 07:15:03.046040 2026] [security2:error] [pid 95128:tid 95606] [client 194.61.41.69:35989] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "littleaosta.nz"] [uri "/images/c99.php"] [unique_id "al4fV-eSd8WoG-6-XpCx3gAAAm4"]
[Mon Jul 20 07:15:03.202114 2026] [security2:error] [pid 95126:tid 95185] [remote 182.77.62.24:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4fVwpx5ks9joCJTKWu5wABqTg"]
[Mon Jul 20 07:15:03.567405 2026] [security2:error] [pid 95126:tid 95302] [client 4.194.217.15:4949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.217.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/tmp/byp.php"] [unique_id "al4fVwpx5ks9joCJTKWu6gAAAbs"]
[Mon Jul 20 07:15:03.692777 2026] [security2:error] [pid 95128:tid 95630] [client 47.128.42.61:29930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sarahholyfield.com"] [uri "/robots.txt"] [unique_id "al4fV-eSd8WoG-6-XpCyAwAAAoY"]
[Mon Jul 20 07:15:03.745140 2026] [security2:error] [pid 95128:tid 95615] [client 77.110.127.138:59277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fV-eSd8WoG-6-XpCyBgAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:03.745260 2026] [security2:error] [pid 95128:tid 95615] [client 77.110.127.138:59277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fV-eSd8WoG-6-XpCyBgAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:03.756705 2026] [security2:error] [pid 95128:tid 95581] [client 194.61.41.81:26887] ModSecurity: Access denied with connection close (phase 1). Pattern match "c99\\\\.php|r57shell\\\\.php|r57\\\\.php|c99\\\\.txt" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1164"] [id "900010"] [rev "1"] [msg "c99 variant "] [severity "CRITICAL"] [hostname "littleaosta.nz"] [uri "/images/c99.php"] [unique_id "al4fV-eSd8WoG-6-XpCyCwAAAlU"]
[Mon Jul 20 07:15:03.799795 2026] [security2:error] [pid 95126:tid 95186] [remote 182.77.62.24:45016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4fVwpx5ks9joCJTKWu7gACDTk"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 07:15:04.358759 2026] [security2:error] [pid 94831:tid 94996] [client 164.52.120.5:4286] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4fWI06NaEKF1g_MW2n3gAAACM"]
[Mon Jul 20 07:15:04.476117 2026] [security2:error] [pid 95128:tid 95421] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.openclaw/.env"] [unique_id "al4fWOeSd8WoG-6-XpCyPAACjiI"]
[Mon Jul 20 07:15:04.554911 2026] [security2:error] [pid 95128:tid 95525] [client 201.27.111.74:62090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fWOeSd8WoG-6-XpCySAAAAh0"]
[Mon Jul 20 07:15:04.555037 2026] [security2:error] [pid 95128:tid 95525] [client 201.27.111.74:62090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fWOeSd8WoG-6-XpCySAAAAh0"]
[Mon Jul 20 07:15:04.567761 2026] [security2:error] [pid 95128:tid 95594] [client 57.141.18.74:59264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fVeeSd8WoG-6-XpCxQwACYkU"]
[Mon Jul 20 07:15:04.579519 2026] [security2:error] [pid 95128:tid 95507] [remote 8.217.108.67:32500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fWOeSd8WoG-6-XpCySgACRXg"]
[Mon Jul 20 07:15:04.658789 2026] [security2:error] [pid 95128:tid 95564] [client 52.167.144.147:49527] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4fWOeSd8WoG-6-XpCyNQACRAo"]
[Mon Jul 20 07:15:04.666702 2026] [security2:error] [pid 95126:tid 95347] [client 179.247.228.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4fWApx5ks9joCJTKWu9gAAAeg"], referer: https://kromosenergy.com/
[Mon Jul 20 07:15:04.740836 2026] [security2:error] [pid 95128:tid 95439] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/.hermes/.env"] [unique_id "al4fWOeSd8WoG-6-XpCyVQACjjQ"]
[Mon Jul 20 07:15:04.750592 2026] [security2:error] [pid 95128:tid 95551] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fWOeSd8WoG-6-XpCyRwAAAjc"]
[Mon Jul 20 07:15:04.837998 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:59289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fWApx5ks9joCJTKWu9wAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:05.111465 2026] [security2:error] [pid 95128:tid 95535] [client 103.144.65.217:61036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fWeeSd8WoG-6-XpCybAAAAic"]
[Mon Jul 20 07:15:05.111559 2026] [security2:error] [pid 95128:tid 95535] [client 103.144.65.217:61036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fWeeSd8WoG-6-XpCybAAAAic"]
[Mon Jul 20 07:15:05.237326 2026] [security2:error] [pid 95128:tid 95448] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.hermes/config.yaml"] [unique_id "al4fWeeSd8WoG-6-XpCydQACjj0"]
[Mon Jul 20 07:15:05.237381 2026] [security2:error] [pid 95128:tid 95443] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.codex/config.toml"] [unique_id "al4fWeeSd8WoG-6-XpCydgACjjg"]
[Mon Jul 20 07:15:05.265696 2026] [core:error] [pid 95128:tid 95619] [client 14.225.17.146:49326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2020
[Mon Jul 20 07:15:05.265719 2026] [core:error] [pid 95128:tid 95619] [client 14.225.17.146:49326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2020
[Mon Jul 20 07:15:05.350085 2026] [security2:error] [pid 95126:tid 95283] [client 14.225.17.146:49590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4fWQpx5ks9joCJTKWu-wAAAag"], referer: http://transparentservices.online/2020
[Mon Jul 20 07:15:05.413912 2026] [security2:error] [pid 95128:tid 95466] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fWeeSd8WoG-6-XpCyhgACWE8"]
[Mon Jul 20 07:15:05.414074 2026] [security2:error] [pid 95128:tid 95584] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fWeeSd8WoG-6-XpCyhgACWE8"]
[Mon Jul 20 07:15:05.432128 2026] [security2:error] [pid 95126:tid 95312] [client 77.110.127.138:59293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fWQpx5ks9joCJTKWu_AAAAcU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:05.468970 2026] [security2:error] [pid 95128:tid 95532] [client 47.128.55.16:39754] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mollycahill.com"] [uri "/robots.txt"] [unique_id "al4fWeeSd8WoG-6-XpCyjQAAAiQ"]
[Mon Jul 20 07:15:05.511579 2026] [security2:error] [pid 95128:tid 95572] [client 14.225.17.146:64729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4fWOeSd8WoG-6-XpCyJwAAAkw"], referer: http://balticsteelmgmt.com/2020
[Mon Jul 20 07:15:05.564069 2026] [security2:error] [pid 95128:tid 95477] [remote 192.241.143.148:53126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4fWeeSd8WoG-6-XpCylQACHlo"]
[Mon Jul 20 07:15:05.595090 2026] [security2:error] [pid 95128:tid 95573] [client 179.247.228.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4fWeeSd8WoG-6-XpCykQAAAk0"], referer: https://kromosenergy.com/
[Mon Jul 20 07:15:05.702233 2026] [security2:error] [pid 95128:tid 95489] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fWeeSd8WoG-6-XpCyqwACGmY"]
[Mon Jul 20 07:15:05.702347 2026] [security2:error] [pid 95128:tid 95522] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fWeeSd8WoG-6-XpCyqwACGmY"]
[Mon Jul 20 07:15:05.726253 2026] [security2:error] [pid 95128:tid 95484] [remote 8.217.108.67:32500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fWeeSd8WoG-6-XpCyrAACPGE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:15:05.813580 2026] [security2:error] [pid 95128:tid 95503] [remote 192.241.143.148:53126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4fWeeSd8WoG-6-XpCytAACb3Q"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:15:05.931207 2026] [security2:error] [pid 95128:tid 95501] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "api.areitoproducciones.com"] [uri "/wp-config.php.bak"] [unique_id "al4fWeeSd8WoG-6-XpCywQACZnI"]
[Mon Jul 20 07:15:06.025070 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:59299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fWQpx5ks9joCJTKWvBQAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:06.033429 2026] [security2:error] [pid 95128:tid 95500] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "api.areitoproducciones.com"] [uri "/.claude.json"] [unique_id "al4fWueSd8WoG-6-XpCyzQACZnE"]
[Mon Jul 20 07:15:06.095112 2026] [security2:error] [pid 95128:tid 95568] [client 88.241.67.160:53432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fWueSd8WoG-6-XpCy0AAAAkg"]
[Mon Jul 20 07:15:06.095269 2026] [security2:error] [pid 95128:tid 95568] [client 88.241.67.160:53432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fWueSd8WoG-6-XpCy0AAAAkg"]
[Mon Jul 20 07:15:06.107672 2026] [security2:error] [pid 95128:tid 95599] [client 14.225.17.146:64658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4fWeeSd8WoG-6-XpCyygAAAmc"], referer: http://ksands.co.uk/2020
[Mon Jul 20 07:15:06.123523 2026] [autoindex:error] [pid 95128:tid 95622] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/maint/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:06.654112 2026] [security2:error] [pid 95128:tid 95590] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fWueSd8WoG-6-XpCy6QAAAl4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:06.681077 2026] [security2:error] [pid 95128:tid 95632] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fWueSd8WoG-6-XpCy8QAAAog"]
[Mon Jul 20 07:15:06.912518 2026] [security2:error] [pid 95126:tid 95362] [client 14.225.17.146:64684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4fWgpx5ks9joCJTKWvCgAAAfc"], referer: http://friendlyspreadsheet.com/2020
[Mon Jul 20 07:15:07.106143 2026] [security2:error] [pid 95128:tid 95540] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fWueSd8WoG-6-XpCzBwAAAiw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:07.251650 2026] [security2:error] [pid 95126:tid 95328] [client 14.225.17.146:50735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4fWwpx5ks9joCJTKWvEAAAAdU"], referer: http://thefriendlyspreadsheet.com/2020
[Mon Jul 20 07:15:07.385567 2026] [security2:error] [pid 95128:tid 95606] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fW-eSd8WoG-6-XpCzFQAAAm4"]
[Mon Jul 20 07:15:07.566239 2026] [security2:error] [pid 95126:tid 95363] [client 57.141.18.95:36844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fWApx5ks9joCJTKWu8AAB-DU"]
[Mon Jul 20 07:15:07.712745 2026] [security2:error] [pid 95128:tid 95435] [remote 5.161.225.162:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4fW-eSd8WoG-6-XpCzPwACFjA"]
[Mon Jul 20 07:15:07.724666 2026] [security2:error] [pid 95128:tid 95502] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "api.areitoproducciones.com"] [uri "/wp-config.php.old"] [unique_id "al4fW-eSd8WoG-6-XpCzSgAChHM"]
[Mon Jul 20 07:15:07.725353 2026] [security2:error] [pid 95128:tid 95428] [remote 34.39.87.128:58894] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "api.areitoproducciones.com"] [uri "/laravel/.env"] [unique_id "al4fW-eSd8WoG-6-XpCzSQAChCk"]
[Mon Jul 20 07:15:07.822131 2026] [security2:error] [pid 95128:tid 95416] [remote 72.167.132.114:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fW-eSd8WoG-6-XpCzTgACiB0"]
[Mon Jul 20 07:15:07.925760 2026] [security2:error] [pid 95128:tid 95639] [client 14.225.17.146:51270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4fW-eSd8WoG-6-XpCzUAAAAo8"], referer: https://friendlyspreadsheet.com/2020
[Mon Jul 20 07:15:07.930066 2026] [autoindex:error] [pid 95128:tid 95540] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:07.992256 2026] [security2:error] [pid 95126:tid 95321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fWwpx5ks9joCJTKWvFAAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.016958 2026] [security2:error] [pid 95128:tid 95507] [remote 5.161.225.162:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4fXOeSd8WoG-6-XpCzXQACRng"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:15:08.019634 2026] [security2:error] [pid 95128:tid 95521] [client 14.225.17.146:51327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4fW-eSd8WoG-6-XpCzVQAAAhk"], referer: http://sarahholyfield.com/2020
[Mon Jul 20 07:15:08.023364 2026] [security2:error] [pid 95128:tid 95608] [client 77.110.127.138:59317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpKbeyF46u'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4fXOeSd8WoG-6-XpCzXgAAAnA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.066050 2026] [security2:error] [pid 95128:tid 95397] [remote 18.61.192.253:42134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fXOeSd8WoG-6-XpCzYQACKgo"]
[Mon Jul 20 07:15:08.089348 2026] [security2:error] [pid 95128:tid 95468] [remote 72.167.132.114:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fXOeSd8WoG-6-XpCzYwACbFE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:08.124837 2026] [security2:error] [pid 95128:tid 95589] [client 57.141.18.54:27350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fWOeSd8WoG-6-XpCyTwACXTw"]
[Mon Jul 20 07:15:08.455911 2026] [security2:error] [pid 95128:tid 95593] [client 103.176.215.66:59689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCziQAAAmE"]
[Mon Jul 20 07:15:08.456020 2026] [security2:error] [pid 95128:tid 95593] [client 103.176.215.66:59689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCziQAAAmE"]
[Mon Jul 20 07:15:08.487596 2026] [security2:error] [pid 95126:tid 95371] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fXApx5ks9joCJTKWvHAAAAgA"]
[Mon Jul 20 07:15:08.521113 2026] [security2:error] [pid 95128:tid 95581] [client 187.16.64.216:61006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCzjQAAAlU"]
[Mon Jul 20 07:15:08.521220 2026] [security2:error] [pid 95128:tid 95581] [client 187.16.64.216:61006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCzjQAAAlU"]
[Mon Jul 20 07:15:08.531460 2026] [security2:error] [pid 95128:tid 95469] [remote 18.61.192.253:42134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fXOeSd8WoG-6-XpCzjwACcFI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:15:08.582330 2026] [security2:error] [pid 95128:tid 95524] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fXOeSd8WoG-6-XpCzgQAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.822289 2026] [security2:error] [pid 95128:tid 95625] [client 77.110.127.138:59322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXOeSd8WoG-6-XpCzngAAAoE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.822380 2026] [security2:error] [pid 95128:tid 95625] [client 77.110.127.138:59322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXOeSd8WoG-6-XpCzngAAAoE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.900216 2026] [security2:error] [pid 95128:tid 95592] [client 157.20.138.62:53537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCzogAAAmA"]
[Mon Jul 20 07:15:08.900307 2026] [security2:error] [pid 95128:tid 95592] [client 157.20.138.62:53537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCzogAAAmA"]
[Mon Jul 20 07:15:08.925299 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:59289] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fXApx5ks9joCJTKWvJwAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.933681 2026] [security2:error] [pid 95128:tid 95518] [client 154.208.48.130:59429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCzpAAAAhY"]
[Mon Jul 20 07:15:08.933783 2026] [security2:error] [pid 95128:tid 95518] [client 154.208.48.130:59429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fXOeSd8WoG-6-XpCzpAAAAhY"]
[Mon Jul 20 07:15:08.983924 2026] [security2:error] [pid 95128:tid 95563] [client 77.110.127.138:59323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXOeSd8WoG-6-XpCzqQAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:08.984022 2026] [security2:error] [pid 95128:tid 95563] [client 77.110.127.138:59323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXOeSd8WoG-6-XpCzqQAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.152412 2026] [security2:error] [pid 95128:tid 95557] [client 77.110.127.138:59324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzuQAAAj0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.152507 2026] [security2:error] [pid 95128:tid 95557] [client 77.110.127.138:59324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzuQAAAj0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.214585 2026] [security2:error] [pid 95128:tid 95643] [client 77.110.127.138:59306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzuwAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.214686 2026] [security2:error] [pid 95128:tid 95643] [client 77.110.127.138:59306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzuwAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.294140 2026] [security2:error] [pid 95128:tid 95616] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fXeeSd8WoG-6-XpCztgAAAng"]
[Mon Jul 20 07:15:09.366957 2026] [security2:error] [pid 95128:tid 95578] [client 77.110.127.138:59327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzwgAAAlI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.367049 2026] [security2:error] [pid 95128:tid 95578] [client 77.110.127.138:59327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzwgAAAlI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:09.419461 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:59308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzxgAAAjM"]
[Mon Jul 20 07:15:09.419579 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:59308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXeeSd8WoG-6-XpCzxgAAAjM"]
[Mon Jul 20 07:15:09.610329 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:59330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXY06NaEKF1g_MW2n9QAAAEM"]
[Mon Jul 20 07:15:09.610449 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:59330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fXY06NaEKF1g_MW2n9QAAAEM"]
[Mon Jul 20 07:15:09.977873 2026] [security2:error] [pid 94831:tid 94975] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fXY06NaEKF1g_MW2n-AAAAA4"]
[Mon Jul 20 07:15:09.986312 2026] [security2:error] [pid 95126:tid 95285] [client 144.172.114.51:40930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/private/config.php"] [unique_id "al4fXQpx5ks9joCJTKWvPQAAAao"]
[Mon Jul 20 07:15:10.197833 2026] [security2:error] [pid 95128:tid 95493] [remote 74.235.96.117:39520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4fXueSd8WoG-6-XpCz7AACJGo"]
[Mon Jul 20 07:15:10.289606 2026] [security2:error] [pid 95126:tid 95331] [client 154.192.123.127:18660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fXgpx5ks9joCJTKWvQQAAAdg"]
[Mon Jul 20 07:15:10.289733 2026] [security2:error] [pid 95126:tid 95331] [client 154.192.123.127:18660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fXgpx5ks9joCJTKWvQQAAAdg"]
[Mon Jul 20 07:15:10.367138 2026] [security2:error] [pid 95128:tid 95432] [remote 74.235.96.117:39520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4fXueSd8WoG-6-XpCz-AACQi0"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:15:10.620947 2026] [security2:error] [pid 95128:tid 95570] [client 14.225.17.146:49957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4fXeeSd8WoG-6-XpCzsgAAAko"], referer: http://laceycaraccident.com/2020
[Mon Jul 20 07:15:10.672440 2026] [security2:error] [pid 95128:tid 95576] [client 77.110.127.138:59334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpUVNpnkPM'%20OR%20887=(SELECT%20887%20FROM%20PG_SLEEP(15))--"] [unique_id "al4fXueSd8WoG-6-XpC0HwAAAlA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:10.696319 2026] [security2:error] [pid 95128:tid 95548] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fXueSd8WoG-6-XpC0DQAAAjQ"]
[Mon Jul 20 07:15:10.718879 2026] [security2:error] [pid 95128:tid 95543] [client 117.211.236.168:51075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fXueSd8WoG-6-XpC0IwAAAi8"]
[Mon Jul 20 07:15:10.719010 2026] [security2:error] [pid 95128:tid 95543] [client 117.211.236.168:51075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fXueSd8WoG-6-XpC0IwAAAi8"]
[Mon Jul 20 07:15:10.719702 2026] [security2:error] [pid 95128:tid 95522] [client 104.234.53.71:52051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4fXueSd8WoG-6-XpC0FgAAAho"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:10.720985 2026] [security2:error] [pid 95128:tid 95575] [client 14.225.17.146:49879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4fXeeSd8WoG-6-XpCzrQAAAk8"], referer: http://koaconsultants.com/2020
[Mon Jul 20 07:15:10.751446 2026] [security2:error] [pid 95128:tid 95612] [client 14.225.17.146:51264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4fXeeSd8WoG-6-XpCzugAAAnQ"], referer: http://margaretspeckogawa.com/2020
[Mon Jul 20 07:15:10.941047 2026] [security2:error] [pid 95128:tid 95538] [client 144.172.114.51:46456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/config.php"] [unique_id "al4fXueSd8WoG-6-XpC0LwAAAio"]
[Mon Jul 20 07:15:10.941457 2026] [security2:error] [pid 95128:tid 95588] [client 104.234.53.71:52051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fXueSd8WoG-6-XpC0LAAAAlw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:11.361657 2026] [security2:error] [pid 95128:tid 95591] [client 144.172.114.51:46468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/settings.php"] [unique_id "al4fX-eSd8WoG-6-XpC0SQAAAl8"]
[Mon Jul 20 07:15:11.376253 2026] [security2:error] [pid 95128:tid 95592] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fX-eSd8WoG-6-XpC0RAAAAmA"]
[Mon Jul 20 07:15:11.770841 2026] [security2:error] [pid 95128:tid 95524] [client 104.234.53.72:30089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fX-eSd8WoG-6-XpC0ZwAAAhw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:12.054893 2026] [security2:error] [pid 95126:tid 95369] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fXwpx5ks9joCJTKWvUQAAAf4"]
[Mon Jul 20 07:15:12.060062 2026] [security2:error] [pid 95128:tid 95558] [client 14.225.17.146:50670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4fXueSd8WoG-6-XpC0GQAAAj4"], referer: http://thechancersband.com/2020
[Mon Jul 20 07:15:12.099338 2026] [security2:error] [pid 95128:tid 95527] [client 14.225.17.146:51108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4fX-eSd8WoG-6-XpC0aQAAAh8"], referer: http://guidehunting.com/2020
[Mon Jul 20 07:15:12.808235 2026] [autoindex:error] [pid 95128:tid 95535] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/midnight/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:12.975324 2026] [security2:error] [pid 94831:tid 95064] [client 77.110.127.138:59340] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js/dist/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4fYI06NaEKF1g_MW2oDgAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:13.038155 2026] [security2:error] [pid 95128:tid 95551] [client 144.172.114.51:46478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/config/settings.php"] [unique_id "al4fYeeSd8WoG-6-XpC0ugAAAjc"]
[Mon Jul 20 07:15:13.134491 2026] [security2:error] [pid 95128:tid 95436] [remote 100.42.189.89:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4fYeeSd8WoG-6-XpC0wAACKjE"]
[Mon Jul 20 07:15:13.231134 2026] [security2:error] [pid 95126:tid 95335] [client 14.225.17.146:52524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4fYQpx5ks9joCJTKWvaAAAAdw"], referer: http://daseighty.net/2020
[Mon Jul 20 07:15:13.235441 2026] [security2:error] [pid 95128:tid 95622] [client 14.225.17.146:50657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4fYOeSd8WoG-6-XpC0swAAAn4"], referer: https://guidehunting.com/2020
[Mon Jul 20 07:15:13.366107 2026] [security2:error] [pid 95128:tid 95447] [remote 100.42.189.89:42876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4fYeeSd8WoG-6-XpC00AACiDw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:15:13.401319 2026] [security2:error] [pid 95128:tid 95599] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fYeeSd8WoG-6-XpC0wwAAAmc"]
[Mon Jul 20 07:15:13.445435 2026] [security2:error] [pid 95128:tid 95566] [client 52.109.4.7:17345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fYeeSd8WoG-6-XpC02AAAAkY"]
[Mon Jul 20 07:15:13.474912 2026] [security2:error] [pid 95128:tid 95614] [client 82.102.27.163:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fYeeSd8WoG-6-XpC03AAAAnY"]
[Mon Jul 20 07:15:13.475057 2026] [security2:error] [pid 95128:tid 95614] [client 82.102.27.163:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fYeeSd8WoG-6-XpC03AAAAnY"]
[Mon Jul 20 07:15:13.514450 2026] [security2:error] [pid 95128:tid 95516] [client 52.109.4.7:17345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fYeeSd8WoG-6-XpC03gAAAhQ"]
[Mon Jul 20 07:15:13.523115 2026] [core:error] [pid 95128:tid 95547] [client 223.84.239.151:55390] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Mon Jul 20 07:15:13.554815 2026] [security2:error] [pid 95128:tid 95539] [client 77.110.127.138:59341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fYeeSd8WoG-6-XpC04wAAAis"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:13.554919 2026] [security2:error] [pid 95128:tid 95539] [client 77.110.127.138:59341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fYeeSd8WoG-6-XpC04wAAAis"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:13.601151 2026] [security2:error] [pid 95128:tid 95540] [client 57.141.18.65:51090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fXueSd8WoG-6-XpCz-wACLHc"]
[Mon Jul 20 07:15:13.608952 2026] [security2:error] [pid 95126:tid 95344] [client 20.245.75.247:26944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fYQpx5ks9joCJTKWvcgAAAeU"]
[Mon Jul 20 07:15:13.629602 2026] [security2:error] [pid 95126:tid 95385] [client 20.245.75.247:26944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fYQpx5ks9joCJTKWvcwAAAg4"]
[Mon Jul 20 07:15:13.876087 2026] [autoindex:error] [pid 95126:tid 95350] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/style-engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:13.887667 2026] [security2:error] [pid 95126:tid 95212] [remote 57.141.18.91:21686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/6127551"] [unique_id "al4fYQpx5ks9joCJTKWvggABr1M"]
[Mon Jul 20 07:15:13.924608 2026] [security2:error] [pid 95126:tid 95349] [client 14.225.17.146:52649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4fYQpx5ks9joCJTKWvegAAAeo"], referer: http://kromosenergy.com/2020
[Mon Jul 20 07:15:14.102897 2026] [security2:error] [pid 95126:tid 95379] [client 77.83.1.143:11661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "302"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4fYQpx5ks9joCJTKWvdAAAAgg"]
[Mon Jul 20 07:15:14.102950 2026] [security2:error] [pid 95126:tid 95379] [client 77.83.1.143:11661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4fYQpx5ks9joCJTKWvdAAAAgg"]
[Mon Jul 20 07:15:14.377457 2026] [security2:error] [pid 95126:tid 95314] [client 14.225.17.146:51148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4fYQpx5ks9joCJTKWvagAAAcc"], referer: http://christiancountytrumpet.com/2020
[Mon Jul 20 07:15:14.453908 2026] [security2:error] [pid 95128:tid 95603] [client 104.234.53.51:57831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fYueSd8WoG-6-XpC1CgAAAms"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:14.512961 2026] [security2:error] [pid 95128:tid 95526] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fYueSd8WoG-6-XpC1AQAAAh4"]
[Mon Jul 20 07:15:14.685444 2026] [security2:error] [pid 95128:tid 95643] [client 77.110.127.138:59345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpi8OMPgfI')%20OR%20985=(SELECT%20985%20FROM%20PG_SLEEP(15))--"] [unique_id "al4fYueSd8WoG-6-XpC1GAAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:14.926711 2026] [security2:error] [pid 95128:tid 95558] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4fYueSd8WoG-6-XpC1EgAAAj4"]
[Mon Jul 20 07:15:15.292079 2026] [security2:error] [pid 94831:tid 95061] [client 5.102.173.71:41792] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4fYI06NaEKF1g_MW2oCwAAAGQ"]
[Mon Jul 20 07:15:15.399096 2026] [security2:error] [pid 95128:tid 95606] [client 57.141.18.79:57822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fYOeSd8WoG-6-XpC0gwACbic"]
[Mon Jul 20 07:15:15.453563 2026] [security2:error] [pid 95128:tid 95519] [client 49.37.242.14:61077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fYueSd8WoG-6-XpC1IQAAAhc"]
[Mon Jul 20 07:15:15.517758 2026] [security2:error] [pid 95128:tid 95538] [client 201.27.111.74:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fY-eSd8WoG-6-XpC1WAAAAio"]
[Mon Jul 20 07:15:15.517867 2026] [security2:error] [pid 95128:tid 95538] [client 201.27.111.74:62602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fY-eSd8WoG-6-XpC1WAAAAio"]
[Mon Jul 20 07:15:15.615781 2026] [security2:error] [pid 95128:tid 95603] [client 103.144.65.217:61537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fY-eSd8WoG-6-XpC1XQAAAms"]
[Mon Jul 20 07:15:15.615967 2026] [security2:error] [pid 95128:tid 95603] [client 103.144.65.217:61537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fY-eSd8WoG-6-XpC1XQAAAms"]
[Mon Jul 20 07:15:15.722730 2026] [security2:error] [pid 95128:tid 95572] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fY-eSd8WoG-6-XpC1VAAAAkw"]
[Mon Jul 20 07:15:15.806855 2026] [security2:error] [pid 95128:tid 95620] [client 14.225.17.146:52508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4fYueSd8WoG-6-XpC1GQAAAnw"], referer: http://intelligentengineeringsolutions.com/2020
[Mon Jul 20 07:15:15.880889 2026] [security2:error] [pid 95126:tid 95213] [remote 20.153.140.50:41054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fYwpx5ks9joCJTKWvogABvFQ"]
[Mon Jul 20 07:15:15.881077 2026] [security2:error] [pid 95126:tid 95303] [client 20.153.140.50:41054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fYwpx5ks9joCJTKWvogABvFQ"]
[Mon Jul 20 07:15:16.029442 2026] [security2:error] [pid 95128:tid 95490] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fZOeSd8WoG-6-XpC1eQACU2c"]
[Mon Jul 20 07:15:16.029575 2026] [security2:error] [pid 95128:tid 95579] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fZOeSd8WoG-6-XpC1eQACU2c"]
[Mon Jul 20 07:15:16.150836 2026] [security2:error] [pid 94831:tid 95027] [client 5.102.173.71:41792] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4fY406NaEKF1g_MW2oIAAAAEI"]
[Mon Jul 20 07:15:16.441095 2026] [security2:error] [pid 95128:tid 95615] [client 104.234.53.50:28785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fZOeSd8WoG-6-XpC1kAAAAnc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:16.570106 2026] [security2:error] [pid 95128:tid 95509] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fZOeSd8WoG-6-XpC1owACGno"]
[Mon Jul 20 07:15:16.570250 2026] [security2:error] [pid 95128:tid 95522] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fZOeSd8WoG-6-XpC1owACGno"]
[Mon Jul 20 07:15:16.595567 2026] [autoindex:error] [pid 95128:tid 95638] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:16.727594 2026] [security2:error] [pid 95126:tid 95215] [remote 162.19.86.63:36788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4fZApx5ks9joCJTKWvsgABr1Y"]
[Mon Jul 20 07:15:16.776341 2026] [security2:error] [pid 95128:tid 95527] [client 104.234.53.50:28785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fZOeSd8WoG-6-XpC1qwAAAh8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:16.788551 2026] [security2:error] [pid 95128:tid 95564] [client 88.241.67.160:53843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fZOeSd8WoG-6-XpC1rAAAAkQ"]
[Mon Jul 20 07:15:16.788821 2026] [security2:error] [pid 95128:tid 95564] [client 88.241.67.160:53843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fZOeSd8WoG-6-XpC1rAAAAkQ"]
[Mon Jul 20 07:15:16.926934 2026] [security2:error] [pid 95126:tid 95218] [remote 162.19.86.63:36788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4fZApx5ks9joCJTKWvvwAB51k"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:15:16.993952 2026] [autoindex:error] [pid 95128:tid 95536] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/upgrade/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:17.386668 2026] [autoindex:error] [pid 95128:tid 95615] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/languages/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:17.445827 2026] [security2:error] [pid 94831:tid 94998] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4fZY06NaEKF1g_MW2oKwAAACU"]
[Mon Jul 20 07:15:17.526185 2026] [security2:error] [pid 95126:tid 95365] [client 57.141.18.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4fZQpx5ks9joCJTKWvyQAAAfo"]
[Mon Jul 20 07:15:17.602389 2026] [core:error] [pid 95128:tid 95526] [client 14.225.17.146:51999] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2020
[Mon Jul 20 07:15:17.602411 2026] [core:error] [pid 95128:tid 95526] [client 14.225.17.146:51999] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2020
[Mon Jul 20 07:15:17.718666 2026] [security2:error] [pid 95126:tid 95326] [client 66.249.73.164:57454] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "miaimminiatures.com"] [uri "/robots.txt"] [unique_id "al4fZQpx5ks9joCJTKWv0QAAAdM"]
[Mon Jul 20 07:15:17.752863 2026] [security2:error] [pid 95126:tid 95340] [client 66.249.73.164:57454] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "miaimminiatures.com"] [uri "/robots.txt"] [unique_id "al4fZQpx5ks9joCJTKWv0gAAAeE"]
[Mon Jul 20 07:15:18.186476 2026] [security2:error] [pid 95128:tid 95635] [client 114.119.139.86:51573] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "recruitinginsight.us"] [uri "/category/uncategorized/page/36"] [unique_id "al4fZueSd8WoG-6-XpC2HwAAAos"], referer: https://recruitinginsight.us/category/uncategorized/page/35?et_blog
[Mon Jul 20 07:15:18.189854 2026] [security2:error] [pid 95128:tid 95607] [client 14.225.17.146:51698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4fZOeSd8WoG-6-XpC1sgAAAm8"]
[Mon Jul 20 07:15:18.275532 2026] [autoindex:error] [pid 95126:tid 95376] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/plugins/elementor/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:18.416317 2026] [security2:error] [pid 95128:tid 95549] [client 57.141.18.86:30758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fY-eSd8WoG-6-XpC1OQACNVs"]
[Mon Jul 20 07:15:18.436761 2026] [security2:error] [pid 95128:tid 95574] [client 14.225.17.146:51557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4fZueSd8WoG-6-XpC2IwAAAk4"], referer: http://vinovinhowine.com/2020
[Mon Jul 20 07:15:18.672344 2026] [autoindex:error] [pid 95128:tid 95635] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/IXR/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:18.753275 2026] [security2:error] [pid 94831:tid 94913] [remote 57.141.18.124:32920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600005"] [unique_id "al4fZo06NaEKF1g_MW2oNQAAfFE"]
[Mon Jul 20 07:15:18.813774 2026] [security2:error] [pid 95128:tid 95581] [client 144.172.114.51:46534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/administrator/.env"] [unique_id "al4fZueSd8WoG-6-XpC2VAAAAlU"]
[Mon Jul 20 07:15:18.912860 2026] [security2:error] [pid 95128:tid 95569] [client 57.141.18.17:50042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fY-eSd8WoG-6-XpC1XgACSQQ"]
[Mon Jul 20 07:15:19.070033 2026] [autoindex:error] [pid 95128:tid 95617] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:19.085871 2026] [security2:error] [pid 95126:tid 95327] [client 103.176.215.66:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fZwpx5ks9joCJTKWv4QAAAdQ"]
[Mon Jul 20 07:15:19.086118 2026] [security2:error] [pid 95126:tid 95327] [client 103.176.215.66:60199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fZwpx5ks9joCJTKWv4QAAAdQ"]
[Mon Jul 20 07:15:19.108605 2026] [security2:error] [pid 95128:tid 95582] [client 14.225.17.146:52021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4fZueSd8WoG-6-XpC2VwAAAlY"], referer: http://nwcarvingacademy.com/2020
[Mon Jul 20 07:15:19.114730 2026] [security2:error] [pid 95128:tid 95535] [client 187.16.64.216:61582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2bgAAAic"]
[Mon Jul 20 07:15:19.114836 2026] [security2:error] [pid 95128:tid 95535] [client 187.16.64.216:61582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2bgAAAic"]
[Mon Jul 20 07:15:19.196190 2026] [security2:error] [pid 94831:tid 95038] [client 104.234.53.70:34097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fZ406NaEKF1g_MW2oOAAAAE0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:19.338203 2026] [security2:error] [pid 95128:tid 95559] [client 14.225.17.146:51967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4fZueSd8WoG-6-XpC2FQAAAj8"], referer: http://mazzucelli.com/2020
[Mon Jul 20 07:15:19.386033 2026] [security2:error] [pid 95128:tid 95621] [client 158.173.241.141:28589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2bwAAAn0"], referer: http://sesamegreenbeans.com/nine-days-south-africa-iii/
[Mon Jul 20 07:15:19.484260 2026] [autoindex:error] [pid 95128:tid 95638] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/images/smilies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:19.541084 2026] [security2:error] [pid 95128:tid 95523] [client 157.20.138.62:54097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2jQAAAhs"]
[Mon Jul 20 07:15:19.541186 2026] [security2:error] [pid 95128:tid 95523] [client 157.20.138.62:54097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2jQAAAhs"]
[Mon Jul 20 07:15:19.624059 2026] [security2:error] [pid 95128:tid 95453] [remote 182.77.62.24:56760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2kgACIkI"]
[Mon Jul 20 07:15:19.653369 2026] [security2:error] [pid 95128:tid 95552] [client 14.225.17.146:52277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4fZeeSd8WoG-6-XpC1_wAAAjg"], referer: http://narv.co/2020
[Mon Jul 20 07:15:19.695375 2026] [security2:error] [pid 95128:tid 95568] [client 159.26.101.22:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.101.26.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ashleystrain.com"] [uri "/xmlrpc.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2lgAAAkg"]
[Mon Jul 20 07:15:19.737407 2026] [security2:error] [pid 95128:tid 95526] [client 94.158.20.22:10119] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "idigress.group"] [uri "/wp-signup.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2fQAAAh4"]
[Mon Jul 20 07:15:19.849308 2026] [security2:error] [pid 95128:tid 95466] [remote 57.141.18.13:59536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4fZ-eSd8WoG-6-XpC2mgACR08"]
[Mon Jul 20 07:15:19.880845 2026] [autoindex:error] [pid 95128:tid 95518] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/crop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:19.955214 2026] [security2:error] [pid 95128:tid 95498] [remote 152.228.213.32:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2owACLm8"]
[Mon Jul 20 07:15:19.955505 2026] [security2:error] [pid 95128:tid 95609] [client 14.225.17.146:52201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4fZueSd8WoG-6-XpC2XQAAAnE"], referer: http://entuvy.com/2020
[Mon Jul 20 07:15:20.008798 2026] [security2:error] [pid 95128:tid 95566] [client 104.234.53.76:24995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2nwAAAkY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:20.054978 2026] [security2:error] [pid 95128:tid 95565] [client 50.116.65.227:13382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4faOeSd8WoG-6-XpC2rgAAAkU"]
[Mon Jul 20 07:15:20.067103 2026] [security2:error] [pid 95128:tid 95562] [client 50.116.65.227:52152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Trip-Report-Day-3-Feature-Image.jpg"] [unique_id "al4faOeSd8WoG-6-XpC2sAAAAkI"]
[Mon Jul 20 07:15:20.110048 2026] [security2:error] [pid 95128:tid 95564] [client 82.102.18.116:39898] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "al4faOeSd8WoG-6-XpC2sgAAAkQ"]
[Mon Jul 20 07:15:20.136192 2026] [security2:error] [pid 95128:tid 95471] [remote 182.77.62.24:56760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4faOeSd8WoG-6-XpC2tQACN1Q"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:20.145004 2026] [security2:error] [pid 95128:tid 95472] [remote 152.228.213.32:57364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4faOeSd8WoG-6-XpC2uAACj1U"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:15:20.206102 2026] [security2:error] [pid 95128:tid 95575] [client 14.225.17.146:52805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4fZ-eSd8WoG-6-XpC2qAAAAk8"], referer: https://nwcarvingacademy.com/2020
[Mon Jul 20 07:15:20.209637 2026] [security2:error] [pid 95128:tid 95620] [client 104.234.53.76:24995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4faOeSd8WoG-6-XpC2vgAAAnw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:20.281635 2026] [autoindex:error] [pid 95128:tid 95552] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/PHPMailer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:20.611965 2026] [security2:error] [pid 95128:tid 95537] [client 154.208.48.130:59958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4faOeSd8WoG-6-XpC22QAAAik"]
[Mon Jul 20 07:15:20.612084 2026] [security2:error] [pid 95128:tid 95537] [client 154.208.48.130:59958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4faOeSd8WoG-6-XpC22QAAAik"]
[Mon Jul 20 07:15:20.663923 2026] [security2:error] [pid 95128:tid 95525] [client 14.225.17.146:59438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4faOeSd8WoG-6-XpC2zwAAAh0"], referer: https://narv.co/2020
[Mon Jul 20 07:15:20.688737 2026] [cgid:error] [pid 95128:tid 95540] [client 194.61.41.69:0] AH01265: stderr from /home3/dbnvkfmy/public_html/website_3ab692aa/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 07:15:20.752388 2026] [security2:error] [pid 95128:tid 95488] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4faOeSd8WoG-6-XpC24gACQWU"]
[Mon Jul 20 07:15:20.789348 2026] [security2:error] [pid 95128:tid 95632] [client 82.102.18.116:44178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4faOeSd8WoG-6-XpC24wAAAog"]
[Mon Jul 20 07:15:21.144565 2026] [autoindex:error] [pid 95128:tid 95578] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:21.283250 2026] [security2:error] [pid 95128:tid 95640] [client 154.192.123.127:17055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4faeeSd8WoG-6-XpC2_wAAApA"]
[Mon Jul 20 07:15:21.283395 2026] [security2:error] [pid 95128:tid 95640] [client 154.192.123.127:17055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4faeeSd8WoG-6-XpC2_wAAApA"]
[Mon Jul 20 07:15:21.501744 2026] [security2:error] [pid 95128:tid 95501] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4faeeSd8WoG-6-XpC3EwACQXI"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 07:15:21.502362 2026] [security2:error] [pid 95126:tid 95300] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4faQpx5ks9joCJTKWwAwAAAbk"]
[Mon Jul 20 07:15:21.565952 2026] [autoindex:error] [pid 95128:tid 95614] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:21.598282 2026] [security2:error] [pid 95126:tid 95271] [client 144.172.114.51:33028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/info.php"] [unique_id "al4faQpx5ks9joCJTKWwBAAAAZw"]
[Mon Jul 20 07:15:21.736814 2026] [security2:error] [pid 95126:tid 95326] [client 94.158.20.22:54447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4faQpx5ks9joCJTKWv_wAAAdM"]
[Mon Jul 20 07:15:21.940724 2026] [security2:error] [pid 95128:tid 95554] [client 158.173.166.181:36743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4faeeSd8WoG-6-XpC3OgAAAjo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:15:21.980515 2026] [security2:error] [pid 95126:tid 95328] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4faQpx5ks9joCJTKWwBwAAAdU"]
[Mon Jul 20 07:15:21.994625 2026] [autoindex:error] [pid 95128:tid 95621] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/block-supports/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:22.101003 2026] [security2:error] [pid 95128:tid 95530] [client 82.102.18.116:44184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4faueSd8WoG-6-XpC3RwAAAiI"]
[Mon Jul 20 07:15:22.178987 2026] [security2:error] [pid 95128:tid 95574] [client 57.141.18.2:56886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fZueSd8WoG-6-XpC2XwACTig"]
[Mon Jul 20 07:15:22.731014 2026] [security2:error] [pid 95128:tid 95582] [client 82.102.18.116:44200] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4faueSd8WoG-6-XpC3bwAAAlY"]
[Mon Jul 20 07:15:22.763424 2026] [security2:error] [pid 95128:tid 95529] [client 43.205.139.3:22944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4faueSd8WoG-6-XpC3cQAAAiE"]
[Mon Jul 20 07:15:22.763544 2026] [security2:error] [pid 95128:tid 95529] [client 43.205.139.3:22944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4faueSd8WoG-6-XpC3cQAAAiE"]
[Mon Jul 20 07:15:23.186901 2026] [security2:error] [pid 95128:tid 95626] [client 144.172.114.51:48118] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/backup/.env"] [unique_id "al4fa-eSd8WoG-6-XpC3kgAAAoI"]
[Mon Jul 20 07:15:23.239176 2026] [security2:error] [pid 95128:tid 95549] [client 14.225.17.146:52369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4faeeSd8WoG-6-XpC3MgAAAjU"], referer: http://expertcultures.com/2020
[Mon Jul 20 07:15:23.397639 2026] [security2:error] [pid 95128:tid 95642] [client 82.102.18.116:44210] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4fa-eSd8WoG-6-XpC3ogAAApI"]
[Mon Jul 20 07:15:23.518209 2026] [security2:error] [pid 95128:tid 95639] [client 104.234.53.76:34603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fa-eSd8WoG-6-XpC3qgAAAo8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:23.637108 2026] [security2:error] [pid 95128:tid 95525] [client 74.208.214.194:37486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4fa-eSd8WoG-6-XpC3rgAAAh0"]
[Mon Jul 20 07:15:23.767091 2026] [security2:error] [pid 95128:tid 95643] [client 178.20.45.159:59739] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "178.20.45.159" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4fa-eSd8WoG-6-XpC3ugAAApM"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 07:15:23.767181 2026] [security2:error] [pid 95128:tid 95643] [client 178.20.45.159:59739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4fa-eSd8WoG-6-XpC3ugAAApM"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 07:15:23.850082 2026] [security2:error] [pid 95128:tid 95569] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4fa-eSd8WoG-6-XpC3wAAAAkk"]
[Mon Jul 20 07:15:23.923934 2026] [security2:error] [pid 95126:tid 95274] [client 57.141.18.57:36450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4faApx5ks9joCJTKWv9wABn2I"]
[Mon Jul 20 07:15:23.938239 2026] [security2:error] [pid 95128:tid 95593] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fa-eSd8WoG-6-XpC3tgAAAmE"]
[Mon Jul 20 07:15:24.017321 2026] [security2:error] [pid 95126:tid 95331] [client 14.225.17.146:49158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4fawpx5ks9joCJTKWwGQAAAdg"]
[Mon Jul 20 07:15:24.071151 2026] [security2:error] [pid 95128:tid 95628] [client 82.102.18.116:44212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "al4fbOeSd8WoG-6-XpC3ywAAAoQ"]
[Mon Jul 20 07:15:24.185583 2026] [security2:error] [pid 95128:tid 95581] [client 14.225.17.146:62507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4fa-eSd8WoG-6-XpC3xAAAAlU"], referer: http://fkconstructionfunding.com/2020
[Mon Jul 20 07:15:24.365184 2026] [autoindex:error] [pid 95128:tid 95512] [remote 34.75.132.13:52404] AH01276: Cannot serve directory /home2/cssgdzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.css.gdz.mybluehost.me
[Mon Jul 20 07:15:24.561459 2026] [security2:error] [pid 95126:tid 95366] [client 117.211.236.168:51713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fbApx5ks9joCJTKWwKgAAAfs"]
[Mon Jul 20 07:15:24.561568 2026] [security2:error] [pid 95126:tid 95366] [client 117.211.236.168:51713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fbApx5ks9joCJTKWwKgAAAfs"]
[Mon Jul 20 07:15:24.703707 2026] [autoindex:error] [pid 95126:tid 95275] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:24.747672 2026] [security2:error] [pid 95126:tid 95354] [client 82.102.18.116:44216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4fbApx5ks9joCJTKWwLgAAAe8"]
[Mon Jul 20 07:15:24.794567 2026] [security2:error] [pid 95126:tid 95290] [client 14.225.17.146:59789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4fbApx5ks9joCJTKWwKwAAAa8"], referer: http://taskidsvirginia.com/2020
[Mon Jul 20 07:15:25.098016 2026] [autoindex:error] [pid 95126:tid 95296] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/customize/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:25.363854 2026] [security2:error] [pid 95128:tid 95521] [client 104.234.53.91:38083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fbeeSd8WoG-6-XpC4CAAAAhk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:25.384688 2026] [security2:error] [pid 95126:tid 95325] [client 82.102.18.116:44222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "al4fbQpx5ks9joCJTKWwOAAAAdI"]
[Mon Jul 20 07:15:25.481741 2026] [autoindex:error] [pid 95128:tid 95561] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/SimplePie/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:25.501580 2026] [security2:error] [pid 95128:tid 95524] [client 77.110.127.138:59363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbeeSd8WoG-6-XpC4GgAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:25.501681 2026] [security2:error] [pid 95128:tid 95524] [client 77.110.127.138:59363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbeeSd8WoG-6-XpC4GgAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:25.664243 2026] [security2:error] [pid 95128:tid 95560] [client 77.110.127.138:59366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbeeSd8WoG-6-XpC4IgAAAkA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:25.664336 2026] [security2:error] [pid 95128:tid 95560] [client 77.110.127.138:59366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbeeSd8WoG-6-XpC4IgAAAkA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:25.704638 2026] [security2:error] [pid 94831:tid 95082] [client 201.27.111.74:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fbY06NaEKF1g_MW2oVAAAAHk"]
[Mon Jul 20 07:15:25.704776 2026] [security2:error] [pid 94831:tid 95082] [client 201.27.111.74:63116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fbY06NaEKF1g_MW2oVAAAAHk"]
[Mon Jul 20 07:15:25.755367 2026] [security2:error] [pid 95128:tid 95570] [client 14.225.17.146:65502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4fa-eSd8WoG-6-XpC3rwAAAko"], referer: http://younutrition.gr/2020
[Mon Jul 20 07:15:25.814136 2026] [security2:error] [pid 95128:tid 95601] [client 77.110.127.138:59367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbeeSd8WoG-6-XpC4LQAAAmk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:25.814272 2026] [security2:error] [pid 95128:tid 95601] [client 77.110.127.138:59367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbeeSd8WoG-6-XpC4LQAAAmk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:25.890776 2026] [security2:error] [pid 95128:tid 95598] [client 212.107.27.47:48889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fbeeSd8WoG-6-XpC4CQAAAmY"]
[Mon Jul 20 07:15:25.890828 2026] [security2:error] [pid 95128:tid 95598] [client 212.107.27.47:48889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fbeeSd8WoG-6-XpC4CQAAAmY"]
[Mon Jul 20 07:15:25.892321 2026] [autoindex:error] [pid 95126:tid 95359] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/theme-compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:25.938657 2026] [security2:error] [pid 94831:tid 95058] [client 57.141.18.42:25592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fao06NaEKF1g_MW2oRQAAYV4"]
[Mon Jul 20 07:15:26.027009 2026] [security2:error] [pid 95128:tid 95582] [client 77.110.127.138:59370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbueSd8WoG-6-XpC4SwAAAlY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.027098 2026] [security2:error] [pid 95128:tid 95582] [client 77.110.127.138:59370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbueSd8WoG-6-XpC4SwAAAlY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.046420 2026] [security2:error] [pid 95128:tid 95618] [client 82.102.18.116:44234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4fbueSd8WoG-6-XpC4TQAAAno"]
[Mon Jul 20 07:15:26.060949 2026] [security2:error] [pid 95128:tid 95519] [client 144.172.114.51:48132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/test/.env"] [unique_id "al4fbueSd8WoG-6-XpC4TgAAAhc"]
[Mon Jul 20 07:15:26.225012 2026] [security2:error] [pid 95128:tid 95584] [client 103.144.65.217:61987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fbueSd8WoG-6-XpC4VAAAAlg"]
[Mon Jul 20 07:15:26.225124 2026] [security2:error] [pid 95128:tid 95584] [client 103.144.65.217:61987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fbueSd8WoG-6-XpC4VAAAAlg"]
[Mon Jul 20 07:15:26.225842 2026] [security2:error] [pid 95128:tid 95614] [client 77.110.127.138:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbueSd8WoG-6-XpC4VwAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.225960 2026] [security2:error] [pid 95128:tid 95614] [client 77.110.127.138:59374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbueSd8WoG-6-XpC4VwAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.270283 2026] [security2:error] [pid 94831:tid 95064] [client 144.172.114.51:33034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/portal/.env"] [unique_id "al4fbo06NaEKF1g_MW2oWAAAAGc"]
[Mon Jul 20 07:15:26.285166 2026] [autoindex:error] [pid 95128:tid 95635] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:26.394814 2026] [security2:error] [pid 94831:tid 94963] [client 77.110.127.138:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbo06NaEKF1g_MW2oWQAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.394980 2026] [security2:error] [pid 94831:tid 94963] [client 77.110.127.138:59375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbo06NaEKF1g_MW2oWQAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.404945 2026] [security2:error] [pid 94831:tid 95070] [client 202.28.194.139:50787] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4fbo06NaEKF1g_MW2oWgAAAG0"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 07:15:26.405064 2026] [security2:error] [pid 94831:tid 95070] [client 202.28.194.139:50787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/wp-comments-post.php"] [unique_id "al4fbo06NaEKF1g_MW2oWgAAAG0"], referer: https://blog.danwolfe.us/on-the-closure-of-valley-forge-military-academy/
[Mon Jul 20 07:15:26.551739 2026] [security2:error] [pid 95128:tid 95534] [client 77.110.127.138:59379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbueSd8WoG-6-XpC4bAAAAiY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.551855 2026] [security2:error] [pid 95128:tid 95534] [client 77.110.127.138:59379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fbueSd8WoG-6-XpC4bAAAAiY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:26.598636 2026] [security2:error] [pid 94831:tid 94927] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fbo06NaEKF1g_MW2oXQAADV8"]
[Mon Jul 20 07:15:26.598769 2026] [security2:error] [pid 94831:tid 94974] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fbo06NaEKF1g_MW2oXQAADV8"]
[Mon Jul 20 07:15:26.676566 2026] [autoindex:error] [pid 95128:tid 95599] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/ID3/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:26.690165 2026] [security2:error] [pid 95126:tid 95327] [client 57.141.18.101:36248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fawpx5ks9joCJTKWwFQAB1GM"]
[Mon Jul 20 07:15:26.715973 2026] [security2:error] [pid 95128:tid 95573] [client 82.102.18.116:44246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4fbueSd8WoG-6-XpC4eQAAAk0"]
[Mon Jul 20 07:15:26.750381 2026] [security2:error] [pid 95128:tid 95608] [client 77.110.127.138:59380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0uToVW9z'))%20OR%20166=(SELECT%20166%20FROM%20PG_SLEEP(15))--"] [unique_id "al4fbueSd8WoG-6-XpC4fQAAAnA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:27.183248 2026] [security2:error] [pid 95128:tid 95539] [client 57.141.18.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fbueSd8WoG-6-XpC4kQAAAis"]
[Mon Jul 20 07:15:27.203924 2026] [security2:error] [pid 95128:tid 95547] [client 144.172.114.51:48144] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/dev/.env"] [unique_id "al4fb-eSd8WoG-6-XpC4ogAAAjM"]
[Mon Jul 20 07:15:27.226890 2026] [security2:error] [pid 95128:tid 95627] [client 14.225.17.146:51899] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4fbeeSd8WoG-6-XpC4QgAAAoM"], referer: http://wathenbartlett.co.uk/2020
[Mon Jul 20 07:15:27.265044 2026] [security2:error] [pid 95128:tid 95413] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fb-eSd8WoG-6-XpC4rAACFRo"]
[Mon Jul 20 07:15:27.265279 2026] [security2:error] [pid 95128:tid 95517] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fb-eSd8WoG-6-XpC4rAACFRo"]
[Mon Jul 20 07:15:27.278091 2026] [security2:error] [pid 95128:tid 95521] [client 50.116.65.227:52256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fb-eSd8WoG-6-XpC4rgAAAhk"]
[Mon Jul 20 07:15:27.291213 2026] [security2:error] [pid 95126:tid 95339] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fbwpx5ks9joCJTKWwRwAAAeA"]
[Mon Jul 20 07:15:27.293020 2026] [security2:error] [pid 95128:tid 95642] [client 50.116.65.227:52272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fb-eSd8WoG-6-XpC4sAAAApI"]
[Mon Jul 20 07:15:27.314369 2026] [security2:error] [pid 95128:tid 95641] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fb-eSd8WoG-6-XpC4oQACkRQ"], referer: http://aleishapenny.ca/2020
[Mon Jul 20 07:15:27.341359 2026] [security2:error] [pid 95128:tid 95560] [client 82.102.18.116:44256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4fb-eSd8WoG-6-XpC4swAAAkA"]
[Mon Jul 20 07:15:27.358309 2026] [security2:error] [pid 95128:tid 95481] [remote 72.167.132.114:43480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fb-eSd8WoG-6-XpC4tQACJV4"]
[Mon Jul 20 07:15:27.401891 2026] [security2:error] [pid 95128:tid 95577] [client 144.172.114.51:33048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/dashboard/.env"] [unique_id "al4fb-eSd8WoG-6-XpC4vAAAAlE"]
[Mon Jul 20 07:15:27.426969 2026] [security2:error] [pid 95128:tid 95549] [client 94.21.88.188:50172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "cephasnext.com"] [uri "/"] [unique_id "al4fb-eSd8WoG-6-XpC4wgAAAjU"]
[Mon Jul 20 07:15:27.432643 2026] [security2:error] [pid 95126:tid 95351] [client 88.241.67.160:55623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fbwpx5ks9joCJTKWwTQAAAew"]
[Mon Jul 20 07:15:27.432916 2026] [security2:error] [pid 95126:tid 95351] [client 88.241.67.160:55623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fbwpx5ks9joCJTKWwTQAAAew"]
[Mon Jul 20 07:15:27.525775 2026] [security2:error] [pid 95128:tid 95607] [client 14.225.17.146:65471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4fbueSd8WoG-6-XpC4SgAAAm8"], referer: http://inspirespublishing.com/2020
[Mon Jul 20 07:15:27.527186 2026] [security2:error] [pid 95128:tid 95621] [client 23.226.219.135:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4fb-eSd8WoG-6-XpC4uwAAAn0"]
[Mon Jul 20 07:15:27.574886 2026] [security2:error] [pid 95128:tid 95435] [remote 72.167.132.114:43480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fb-eSd8WoG-6-XpC40QACFDA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:27.639391 2026] [security2:error] [pid 95128:tid 95611] [client 100.26.198.54:28188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.198.26.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fb-eSd8WoG-6-XpC41gAAAnM"], referer: https://curlsnpearlsss.com/es/jamon-con-pina-glazed-ham-with-pineapples/
[Mon Jul 20 07:15:27.751131 2026] [security2:error] [pid 95128:tid 95627] [client 77.110.127.138:59385] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js/dist/wp-seo-local-frontend-1390.js0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4fb-eSd8WoG-6-XpC42AAAAoM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:27.797370 2026] [autoindex:error] [pid 95128:tid 95599] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/assets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:27.943439 2026] [security2:error] [pid 95128:tid 95546] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4fb-eSd8WoG-6-XpC47gAAAjI"]
[Mon Jul 20 07:15:27.972212 2026] [security2:error] [pid 95128:tid 95553] [client 82.102.18.116:44260] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/test/wp-includes/wlwmanifest.xml"] [unique_id "al4fb-eSd8WoG-6-XpC48QAAAjk"]
[Mon Jul 20 07:15:28.040727 2026] [security2:error] [pid 95128:tid 95547] [client 14.225.17.146:60005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4fb-eSd8WoG-6-XpC44wAAAjM"], referer: http://scott-assist.com/2020
[Mon Jul 20 07:15:28.118788 2026] [security2:error] [pid 95128:tid 95537] [client 77.83.1.16:34599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fb-eSd8WoG-6-XpC41QAAAik"]
[Mon Jul 20 07:15:28.118848 2026] [security2:error] [pid 95128:tid 95537] [client 77.83.1.16:34599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fb-eSd8WoG-6-XpC41QAAAik"]
[Mon Jul 20 07:15:28.175949 2026] [security2:error] [pid 94831:tid 94989] [client 14.225.17.146:60108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4fcI06NaEKF1g_MW2obgAAABw"], referer: https://wathenbartlett.co.uk/2020
[Mon Jul 20 07:15:28.181104 2026] [security2:error] [pid 95128:tid 95631] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fcOeSd8WoG-6-XpC49wAChyI"], referer: https://aleishapenny.ca/2020
[Mon Jul 20 07:15:28.280191 2026] [autoindex:error] [pid 95128:tid 95561] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/fonts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:28.295238 2026] [security2:error] [pid 95128:tid 95620] [client 14.225.17.146:60107] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4fcOeSd8WoG-6-XpC4_AAAAnw"], referer: http://tacticaltreeoperations.com/2020
[Mon Jul 20 07:15:28.302409 2026] [security2:error] [pid 95128:tid 95567] [client 14.225.17.146:50964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4fb-eSd8WoG-6-XpC4wAAAAkc"], referer: http://processorstudio.com/2020
[Mon Jul 20 07:15:28.441782 2026] [security2:error] [pid 95128:tid 95595] [client 159.89.114.44:61197] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.tntcatholic.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4fcOeSd8WoG-6-XpC5EAAAAmM"]
[Mon Jul 20 07:15:28.601091 2026] [security2:error] [pid 95128:tid 95600] [client 82.102.18.116:47438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "al4fcOeSd8WoG-6-XpC5IAAAAmg"]
[Mon Jul 20 07:15:28.834409 2026] [security2:error] [pid 95128:tid 95617] [client 114.119.145.115:61399] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4fcOeSd8WoG-6-XpC5MQAAAnk"], referer: http://www.new-menus.com/index.php?page=28
[Mon Jul 20 07:15:28.846683 2026] [security2:error] [pid 95128:tid 95526] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fcOeSd8WoG-6-XpC5JwAAAh4"]
[Mon Jul 20 07:15:29.169831 2026] [security2:error] [pid 95126:tid 95323] [client 14.225.17.146:50929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4fcQpx5ks9joCJTKWwYwAAAdA"], referer: https://processorstudio.com/2020
[Mon Jul 20 07:15:29.230370 2026] [security2:error] [pid 95126:tid 95289] [client 82.102.18.116:47446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4fcQpx5ks9joCJTKWwZgAAAa4"]
[Mon Jul 20 07:15:29.340803 2026] [autoindex:error] [pid 95126:tid 95333] [client 167.86.117.252:57190] AH01276: Cannot serve directory /home1/aberball/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:15:29.360994 2026] [security2:error] [pid 95128:tid 95575] [client 98.159.234.160:28977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fceeSd8WoG-6-XpC5TwAAAk8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:15:29.396688 2026] [security2:error] [pid 95126:tid 95381] [client 77.110.127.138:59356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fcQpx5ks9joCJTKWwaAAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:29.396808 2026] [security2:error] [pid 95126:tid 95381] [client 77.110.127.138:59356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fcQpx5ks9joCJTKWwaAAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:29.500338 2026] [security2:error] [pid 95128:tid 95627] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fceeSd8WoG-6-XpC5TQAAAoM"]
[Mon Jul 20 07:15:29.640017 2026] [security2:error] [pid 95126:tid 95369] [client 103.176.215.66:60707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fcQpx5ks9joCJTKWwcAAAAf4"]
[Mon Jul 20 07:15:29.640307 2026] [security2:error] [pid 95126:tid 95369] [client 103.176.215.66:60707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fcQpx5ks9joCJTKWwcAAAAf4"]
[Mon Jul 20 07:15:29.719384 2026] [security2:error] [pid 95128:tid 95637] [client 187.16.64.216:62147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fceeSd8WoG-6-XpC5aQAAAo0"]
[Mon Jul 20 07:15:29.719584 2026] [security2:error] [pid 95128:tid 95637] [client 187.16.64.216:62147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fceeSd8WoG-6-XpC5aQAAAo0"]
[Mon Jul 20 07:15:29.885842 2026] [security2:error] [pid 94831:tid 95001] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4fcY06NaEKF1g_MW2oegAAACg"]
[Mon Jul 20 07:15:29.910207 2026] [security2:error] [pid 95128:tid 95597] [client 82.102.18.116:47454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/site/wp-includes/wlwmanifest.xml"] [unique_id "al4fceeSd8WoG-6-XpC5dwAAAmU"]
[Mon Jul 20 07:15:30.042255 2026] [security2:error] [pid 95126:tid 95365] [client 157.20.138.62:54653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fcgpx5ks9joCJTKWwdwAAAfo"]
[Mon Jul 20 07:15:30.042424 2026] [security2:error] [pid 95126:tid 95365] [client 157.20.138.62:54653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fcgpx5ks9joCJTKWwdwAAAfo"]
[Mon Jul 20 07:15:30.095835 2026] [security2:error] [pid 95128:tid 95579] [client 57.141.18.48:64676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fbueSd8WoG-6-XpC4gAACUzc"]
[Mon Jul 20 07:15:30.129461 2026] [security2:error] [pid 95128:tid 95484] [remote 124.55.178.99:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fcueSd8WoG-6-XpC5jwACiGE"]
[Mon Jul 20 07:15:30.188685 2026] [security2:error] [pid 94831:tid 95049] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fcY06NaEKF1g_MW2ofgAAAFg"]
[Mon Jul 20 07:15:30.533571 2026] [security2:error] [pid 95128:tid 95489] [remote 124.55.178.99:53042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fcueSd8WoG-6-XpC5pAACNWY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:15:30.585375 2026] [security2:error] [pid 95128:tid 95601] [client 82.102.18.116:47456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4fcueSd8WoG-6-XpC5qQAAAmk"]
[Mon Jul 20 07:15:30.586737 2026] [autoindex:error] [pid 95128:tid 95500] [remote 8.229.41.77:58133] AH01276: Cannot serve directory /home2/oqkxeemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.oqk.xee.mybluehost.me
[Mon Jul 20 07:15:30.705055 2026] [autoindex:error] [pid 95128:tid 95562] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:30.734133 2026] [security2:error] [pid 95128:tid 95523] [client 14.225.17.146:57571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4fceeSd8WoG-6-XpC5bAAAAhs"], referer: http://ancestralidadytrance.space/2020
[Mon Jul 20 07:15:30.748272 2026] [security2:error] [pid 95128:tid 95558] [client 49.37.242.14:61564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fcueSd8WoG-6-XpC5iAAAAj4"]
[Mon Jul 20 07:15:30.801420 2026] [security2:error] [pid 95126:tid 95238] [remote 54.39.0.198:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-post-1.xml"] [unique_id "al4fcgpx5ks9joCJTKWwfAABwm0"]
[Mon Jul 20 07:15:30.801606 2026] [security2:error] [pid 95126:tid 95309] [client 54.39.0.198:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-post-1.xml"] [unique_id "al4fcgpx5ks9joCJTKWwfAABwm0"]
[Mon Jul 20 07:15:30.988035 2026] [security2:error] [pid 95128:tid 95563] [client 77.110.127.138:59371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4fcueSd8WoG-6-XpC5vgAAAkM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:31.053182 2026] [security2:error] [pid 95128:tid 95551] [client 77.110.127.138:59373] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js/dist/wp-seo-local-frontend-1390.js0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4fc-eSd8WoG-6-XpC5xAAAAjc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:31.209786 2026] [security2:error] [pid 95128:tid 95547] [client 82.102.18.116:47472] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.kpb.qlr.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4fc-eSd8WoG-6-XpC50gAAAjM"]
[Mon Jul 20 07:15:31.305669 2026] [security2:error] [pid 95128:tid 95560] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fc-eSd8WoG-6-XpC5zQAAAkA"]
[Mon Jul 20 07:15:31.328011 2026] [security2:error] [pid 95128:tid 95522] [client 57.141.18.89:28308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fcOeSd8WoG-6-XpC49gACGg0"]
[Mon Jul 20 07:15:31.495836 2026] [security2:error] [pid 95128:tid 95569] [client 14.225.17.146:62088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4fcueSd8WoG-6-XpC5ugAAAkk"], referer: http://partnerselectricalllc.com/2020
[Mon Jul 20 07:15:31.501898 2026] [security2:error] [pid 95126:tid 95240] [remote 160.187.68.132:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fcwpx5ks9joCJTKWwhgAB128"]
[Mon Jul 20 07:15:31.634475 2026] [security2:error] [pid 95128:tid 95625] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4fc-eSd8WoG-6-XpC57QAAAoE"]
[Mon Jul 20 07:15:31.810688 2026] [security2:error] [pid 95128:tid 95556] [client 77.110.127.138:59378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fc-eSd8WoG-6-XpC58wAAAjw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:31.810803 2026] [security2:error] [pid 95128:tid 95556] [client 77.110.127.138:59378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fc-eSd8WoG-6-XpC58wAAAjw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:31.890464 2026] [security2:error] [pid 95128:tid 95563] [client 144.172.114.51:35616] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/staging/.env"] [unique_id "al4fc-eSd8WoG-6-XpC59QAAAkM"]
[Mon Jul 20 07:15:31.956918 2026] [security2:error] [pid 95126:tid 95245] [remote 160.187.68.132:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fcwpx5ks9joCJTKWwkAAB3XQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:15:31.970344 2026] [security2:error] [pid 95128:tid 95604] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fc-eSd8WoG-6-XpC58gAAAmw"]
[Mon Jul 20 07:15:31.981886 2026] [security2:error] [pid 95128:tid 95555] [client 77.110.127.138:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fc-eSd8WoG-6-XpC5-wAAAjs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:32.145803 2026] [security2:error] [pid 95128:tid 95633] [client 77.110.127.138:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php'\\""] [unique_id "al4fdOeSd8WoG-6-XpC6BwAAAok"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:32.225174 2026] [security2:error] [pid 95126:tid 95247] [remote 54.39.210.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-page-1.xml"] [unique_id "al4fdApx5ks9joCJTKWwlAABrXY"]
[Mon Jul 20 07:15:32.225309 2026] [security2:error] [pid 95126:tid 95288] [client 54.39.210.36:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-page-1.xml"] [unique_id "al4fdApx5ks9joCJTKWwlAABrXY"]
[Mon Jul 20 07:15:32.514687 2026] [autoindex:error] [pid 95128:tid 95606] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/light/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:32.558109 2026] [security2:error] [pid 95128:tid 95588] [client 154.192.123.127:17413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fdOeSd8WoG-6-XpC6KwAAAlw"]
[Mon Jul 20 07:15:32.558217 2026] [security2:error] [pid 95128:tid 95588] [client 154.192.123.127:17413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fdOeSd8WoG-6-XpC6KwAAAlw"]
[Mon Jul 20 07:15:32.691124 2026] [security2:error] [pid 95128:tid 95417] [remote 97.74.93.24:38050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fdOeSd8WoG-6-XpC6MQACNR4"]
[Mon Jul 20 07:15:32.740370 2026] [security2:error] [pid 95128:tid 95563] [client 3.211.100.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fdOeSd8WoG-6-XpC6LQACQyA"]
[Mon Jul 20 07:15:32.764647 2026] [security2:error] [pid 95128:tid 95571] [client 154.208.48.130:60498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fdOeSd8WoG-6-XpC6OQAAAks"]
[Mon Jul 20 07:15:32.764793 2026] [security2:error] [pid 95128:tid 95571] [client 154.208.48.130:60498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fdOeSd8WoG-6-XpC6OQAAAks"]
[Mon Jul 20 07:15:32.902291 2026] [autoindex:error] [pid 95128:tid 95631] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:32.954233 2026] [security2:error] [pid 95126:tid 95307] [client 77.110.127.138:59406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fdApx5ks9joCJTKWwqQAAAcA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:32.954320 2026] [security2:error] [pid 95126:tid 95307] [client 77.110.127.138:59406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fdApx5ks9joCJTKWwqQAAAcA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:32.996096 2026] [security2:error] [pid 95126:tid 95357] [client 77.110.127.138:59408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4fdApx5ks9joCJTKWwqgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:33.014899 2026] [security2:error] [pid 95126:tid 95286] [client 50.116.65.227:22990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4fdQpx5ks9joCJTKWwrAAAAas"]
[Mon Jul 20 07:15:33.026997 2026] [security2:error] [pid 95126:tid 95315] [client 50.116.65.227:55042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2021/03/Aroy-Thai.jpg"] [unique_id "al4fdQpx5ks9joCJTKWwrgAAAZ4"]
[Mon Jul 20 07:15:33.059296 2026] [security2:error] [pid 95126:tid 95308] [client 117.211.236.168:52154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fdQpx5ks9joCJTKWwrwAAAcE"]
[Mon Jul 20 07:15:33.059418 2026] [security2:error] [pid 95126:tid 95308] [client 117.211.236.168:52154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fdQpx5ks9joCJTKWwrwAAAcE"]
[Mon Jul 20 07:15:33.105494 2026] [security2:error] [pid 95128:tid 95471] [remote 97.74.93.24:38050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fdeeSd8WoG-6-XpC6SAAChVQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:15:33.230666 2026] [security2:error] [pid 95128:tid 95630] [client 57.141.18.107:21246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fceeSd8WoG-6-XpC5cwAChkQ"]
[Mon Jul 20 07:15:33.329504 2026] [autoindex:error] [pid 95128:tid 95626] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/rest-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:33.359203 2026] [security2:error] [pid 95128:tid 95574] [client 176.98.215.133:14467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "jqq.cyv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fdeeSd8WoG-6-XpC6TwACTlE"]
[Mon Jul 20 07:15:33.410200 2026] [security2:error] [pid 94831:tid 95032] [client 14.225.17.146:57823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4fdY06NaEKF1g_MW2omQAAAEc"], referer: http://latiendadejorge.com.gt/2020
[Mon Jul 20 07:15:33.596117 2026] [security2:error] [pid 95126:tid 95253] [remote 54.39.210.203:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-product-1.xml"] [unique_id "al4fdQpx5ks9joCJTKWwuQABvHw"]
[Mon Jul 20 07:15:33.596312 2026] [security2:error] [pid 95126:tid 95303] [client 54.39.210.203:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-product-1.xml"] [unique_id "al4fdQpx5ks9joCJTKWwuQABvHw"]
[Mon Jul 20 07:15:33.654304 2026] [security2:error] [pid 95128:tid 95553] [client 94.158.20.53:16417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "160"] [id "900408"] [msg "register POST logging"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fdeeSd8WoG-6-XpC6SQAAAjk"]
[Mon Jul 20 07:15:33.654363 2026] [security2:error] [pid 95128:tid 95553] [client 94.158.20.53:16417] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fdeeSd8WoG-6-XpC6SQAAAjk"]
[Mon Jul 20 07:15:33.742565 2026] [security2:error] [pid 95128:tid 95571] [client 77.110.127.138:59392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fdeeSd8WoG-6-XpC6ZgAAAks"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:33.976104 2026] [security2:error] [pid 95128:tid 95564] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fdeeSd8WoG-6-XpC6dwAAAkQ"]
[Mon Jul 20 07:15:34.085536 2026] [security2:error] [pid 95126:tid 95254] [remote 173.249.4.11:22810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fdgpx5ks9joCJTKWwvwAB2X0"]
[Mon Jul 20 07:15:34.175700 2026] [security2:error] [pid 95128:tid 95531] [client 77.110.127.138:59393] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fdeeSd8WoG-6-XpC6jgAAAiM"]
[Mon Jul 20 07:15:34.177605 2026] [security2:error] [pid 95128:tid 95548] [client 77.110.127.138:59396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fdueSd8WoG-6-XpC6ngAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:34.177744 2026] [security2:error] [pid 95128:tid 95548] [client 77.110.127.138:59396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fdueSd8WoG-6-XpC6ngAAAjQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:34.284099 2026] [security2:error] [pid 95126:tid 95256] [remote 173.249.4.11:22810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fdgpx5ks9joCJTKWwxgABvX8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:15:34.304067 2026] [security2:error] [pid 95128:tid 95584] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4fdueSd8WoG-6-XpC61AAAAlg"]
[Mon Jul 20 07:15:34.306638 2026] [proxy:error] [pid 95128:tid 95599] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:15:34.306676 2026] [proxy_http:error] [pid 95128:tid 95599] [client 3.139.242.79:47600] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:15:34.307306 2026] [proxy:error] [pid 95128:tid 95599] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:15:34.307331 2026] [proxy_http:error] [pid 95128:tid 95599] [client 3.139.242.79:47600] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:15:34.348304 2026] [core:error] [pid 94831:tid 94974] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:34.348339 2026] [core:error] [pid 94831:tid 94974] [client 3.139.242.79:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:34.375151 2026] [security2:error] [pid 95128:tid 95538] [client 178.156.184.20:36794] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4fdeeSd8WoG-6-XpC6hQAAAio"], referer: https://windowtx.com
[Mon Jul 20 07:15:34.504168 2026] [security2:error] [pid 95128:tid 95546] [client 144.172.114.51:34956] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/mail/.env"] [unique_id "al4fdueSd8WoG-6-XpC65QAAAjI"]
[Mon Jul 20 07:15:34.617362 2026] [security2:error] [pid 95128:tid 95568] [client 77.110.127.138:59414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fdueSd8WoG-6-XpC63gAAAkg"]
[Mon Jul 20 07:15:34.777252 2026] [security2:error] [pid 94831:tid 95014] [client 157.180.2.168:41110] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "windowtx.com"] [uri "/"] [unique_id "al4fdo06NaEKF1g_MW2opQAAADU"]
[Mon Jul 20 07:15:34.926065 2026] [access_compat:error] [pid 95128:tid 95504] [remote 82.159.45.33:5278] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 07:15:34.982436 2026] [security2:error] [pid 95126:tid 95130] [remote 167.114.139.38:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-mailpoet_page-1.xml"] [unique_id "al4fdgpx5ks9joCJTKWw0AABqQE"]
[Mon Jul 20 07:15:34.982677 2026] [security2:error] [pid 95126:tid 95284] [client 167.114.139.38:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-posts-mailpoet_page-1.xml"] [unique_id "al4fdgpx5ks9joCJTKWw0AABqQE"]
[Mon Jul 20 07:15:34.996841 2026] [security2:error] [pid 95128:tid 95635] [client 14.225.17.146:57607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4fdueSd8WoG-6-XpC6lgAAAos"], referer: http://retzkolonglogistics.com/2020
[Mon Jul 20 07:15:35.017787 2026] [security2:error] [pid 95128:tid 95552] [client 185.238.231.75:36631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4fd-eSd8WoG-6-XpC7FwAAAjg"]
[Mon Jul 20 07:15:35.030464 2026] [security2:error] [pid 95128:tid 95569] [client 185.238.231.242:27471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4fd-eSd8WoG-6-XpC7FgAAAkk"]
[Mon Jul 20 07:15:35.143915 2026] [security2:error] [pid 95126:tid 95294] [client 57.141.18.53:20732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fcwpx5ks9joCJTKWwjgABs3E"]
[Mon Jul 20 07:15:35.163015 2026] [security2:error] [pid 95128:tid 95631] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fdueSd8WoG-6-XpC7FQAAAoc"]
[Mon Jul 20 07:15:35.267164 2026] [security2:error] [pid 95128:tid 95577] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4fd-eSd8WoG-6-XpC7HwAAAlE"]
[Mon Jul 20 07:15:35.340877 2026] [security2:error] [pid 95128:tid 95436] [remote 202.51.202.242:34052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fd-eSd8WoG-6-XpC7IgACGTE"]
[Mon Jul 20 07:15:35.646332 2026] [security2:error] [pid 95126:tid 95315] [client 205.185.117.197:60793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.117.185.205.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.betterbonddogtraining.com"] [uri "/wp-login.php"] [unique_id "al4fdwpx5ks9joCJTKWw3wAAAcg"]
[Mon Jul 20 07:15:35.691324 2026] [autoindex:error] [pid 95128:tid 95548] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:35.876817 2026] [security2:error] [pid 95128:tid 95609] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4fd-eSd8WoG-6-XpC7RgAAAnE"]
[Mon Jul 20 07:15:36.074180 2026] [autoindex:error] [pid 95128:tid 95569] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/rest-api/endpoints/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:36.137307 2026] [security2:error] [pid 95126:tid 95347] [client 201.27.111.74:63632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4feApx5ks9joCJTKWw6AAAAeg"]
[Mon Jul 20 07:15:36.137399 2026] [security2:error] [pid 95126:tid 95347] [client 201.27.111.74:63632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4feApx5ks9joCJTKWw6AAAAeg"]
[Mon Jul 20 07:15:36.235346 2026] [security2:error] [pid 95128:tid 95514] [remote 202.51.202.242:34052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4feOeSd8WoG-6-XpC7XgACXH8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:15:36.303636 2026] [security2:error] [pid 95128:tid 95638] [client 77.110.127.138:59402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4feOeSd8WoG-6-XpC7WAAAAo4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:36.413499 2026] [security2:error] [pid 95126:tid 95137] [remote 54.39.89.179:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-taxonomies-category-1.xml"] [unique_id "al4feApx5ks9joCJTKWw8QABkAg"]
[Mon Jul 20 07:15:36.413706 2026] [security2:error] [pid 95126:tid 95259] [client 54.39.89.179:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-taxonomies-category-1.xml"] [unique_id "al4feApx5ks9joCJTKWw8QABkAg"]
[Mon Jul 20 07:15:36.517898 2026] [security2:error] [pid 95126:tid 95264] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4feApx5ks9joCJTKWw7AABlQU"], referer: http://ali-alghanim.net/2020
[Mon Jul 20 07:15:36.668502 2026] [security2:error] [pid 95128:tid 95546] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4feOeSd8WoG-6-XpC7bwAAAjI"]
[Mon Jul 20 07:15:36.729838 2026] [security2:error] [pid 95126:tid 95139] [remote 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4feApx5ks9joCJTKWw9gAB-Ao"]
[Mon Jul 20 07:15:36.754067 2026] [security2:error] [pid 95128:tid 95522] [client 14.225.17.146:57679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4fd-eSd8WoG-6-XpC7HQAAAho"], referer: http://tntcatholic.com/2020
[Mon Jul 20 07:15:36.760296 2026] [security2:error] [pid 95126:tid 95309] [client 103.144.65.217:62438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4feApx5ks9joCJTKWw-AAAAcI"]
[Mon Jul 20 07:15:36.760383 2026] [security2:error] [pid 95126:tid 95309] [client 103.144.65.217:62438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4feApx5ks9joCJTKWw-AAAAcI"]
[Mon Jul 20 07:15:36.912147 2026] [security2:error] [pid 95128:tid 95566] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4feOeSd8WoG-6-XpC7hAAAAkY"]
[Mon Jul 20 07:15:37.208775 2026] [security2:error] [pid 95126:tid 95142] [remote 152.228.213.32:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4feQpx5ks9joCJTKWw_gABvQ0"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 07:15:37.235656 2026] [security2:error] [pid 95128:tid 95483] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4feeeSd8WoG-6-XpC7mgACbWA"]
[Mon Jul 20 07:15:37.235836 2026] [security2:error] [pid 95128:tid 95605] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4feeeSd8WoG-6-XpC7mgACbWA"]
[Mon Jul 20 07:15:37.374690 2026] [security2:error] [pid 95128:tid 95604] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4feeeSd8WoG-6-XpC7mQAAAmw"]
[Mon Jul 20 07:15:37.491135 2026] [lsapi:warn] [pid 94831:tid 95042] [client 14.225.17.146:57807] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2020
[Mon Jul 20 07:15:37.491183 2026] [lsapi:warn] [pid 94831:tid 95042] [client 14.225.17.146:57807] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2020
[Mon Jul 20 07:15:37.546606 2026] [core:error] [pid 95126:tid 95366] [client 14.225.17.146:59813] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2020
[Mon Jul 20 07:15:37.546630 2026] [core:error] [pid 95126:tid 95366] [client 14.225.17.146:59813] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2020
[Mon Jul 20 07:15:37.784754 2026] [security2:error] [pid 95126:tid 95141] [remote 142.44.220.73:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-taxonomies-post_tag-1.xml"] [unique_id "al4feQpx5ks9joCJTKWxBQACAAw"]
[Mon Jul 20 07:15:37.784951 2026] [security2:error] [pid 95126:tid 95371] [client 142.44.220.73:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-taxonomies-post_tag-1.xml"] [unique_id "al4feQpx5ks9joCJTKWxBQACAAw"]
[Mon Jul 20 07:15:37.803352 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:59445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4feeeSd8WoG-6-XpC7xAAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:37.803449 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:59445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4feeeSd8WoG-6-XpC7xAAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:37.978859 2026] [security2:error] [pid 95128:tid 95405] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4feeeSd8WoG-6-XpC70QACUBI"]
[Mon Jul 20 07:15:37.979030 2026] [security2:error] [pid 95128:tid 95576] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4feeeSd8WoG-6-XpC70QACUBI"]
[Mon Jul 20 07:15:37.992768 2026] [lsapi:warn] [pid 95128:tid 95561] [client 50.116.65.227:55108] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:15:37.992783 2026] [lsapi:warn] [pid 95128:tid 95561] [client 50.116.65.227:55108] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:15:38.008541 2026] [security2:error] [pid 94831:tid 95042] [client 14.225.17.146:57807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4feI06NaEKF1g_MW2osAAAAFE"], referer: http://oswegooperatheater.com/2020
[Mon Jul 20 07:15:38.020186 2026] [security2:error] [pid 95128:tid 95535] [client 14.225.17.146:57802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4feeeSd8WoG-6-XpC7xQAAAic"], referer: https://north-woods-engineering.com/2020
[Mon Jul 20 07:15:38.054292 2026] [security2:error] [pid 94831:tid 94973] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4feY06NaEKF1g_MW2otgAAAAw"]
[Mon Jul 20 07:15:38.181982 2026] [security2:error] [pid 95128:tid 95537] [client 88.241.67.160:54681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4feueSd8WoG-6-XpC74gAAAik"]
[Mon Jul 20 07:15:38.182141 2026] [security2:error] [pid 95128:tid 95537] [client 88.241.67.160:54681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4feueSd8WoG-6-XpC74gAAAik"]
[Mon Jul 20 07:15:38.389024 2026] [security2:error] [pid 95128:tid 95564] [client 144.172.114.51:35634] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/laravel/.env"] [unique_id "al4feueSd8WoG-6-XpC76gAAAkQ"]
[Mon Jul 20 07:15:38.396845 2026] [security2:error] [pid 95126:tid 95382] [client 77.110.127.138:59453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fegpx5ks9joCJTKWxDAAAAgs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:38.409529 2026] [security2:error] [pid 95128:tid 95587] [client 104.234.53.70:44333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4feueSd8WoG-6-XpC76wAAAls"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:38.597959 2026] [autoindex:error] [pid 95128:tid 95529] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/includes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:38.852777 2026] [lsapi:warn] [pid 95128:tid 95608] [client 14.225.17.146:58806] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2020
[Mon Jul 20 07:15:38.852796 2026] [lsapi:warn] [pid 95128:tid 95608] [client 14.225.17.146:58806] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2020
[Mon Jul 20 07:15:38.907049 2026] [security2:error] [pid 95128:tid 95608] [client 14.225.17.146:58806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4feueSd8WoG-6-XpC8BwAAAnA"], referer: https://oswegooperatheater.com/2020
[Mon Jul 20 07:15:38.917116 2026] [security2:error] [pid 95128:tid 95586] [client 66.249.73.96:55406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "suretybonds-california.com"] [uri "/index.php"] [unique_id "al4feueSd8WoG-6-XpC8BAAAAlo"], referer: https://suretybonds-california.com/surety-bonds-blog/
[Mon Jul 20 07:15:38.955848 2026] [security2:error] [pid 95128:tid 95543] [client 14.225.17.146:58929] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4feueSd8WoG-6-XpC8BQAAAi8"], referer: http://grecruit.online/2020
[Mon Jul 20 07:15:39.074029 2026] [security2:error] [pid 95126:tid 95147] [remote 54.39.0.189:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-taxonomies-product_cat-1.xml"] [unique_id "al4fewpx5ks9joCJTKWxFQAByBI"]
[Mon Jul 20 07:15:39.074273 2026] [security2:error] [pid 95126:tid 95315] [client 54.39.0.189:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-taxonomies-product_cat-1.xml"] [unique_id "al4fewpx5ks9joCJTKWxFQAByBI"]
[Mon Jul 20 07:15:39.160953 2026] [security2:error] [pid 95126:tid 95357] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fegpx5ks9joCJTKWxEAAAAfI"]
[Mon Jul 20 07:15:39.325437 2026] [security2:error] [pid 95128:tid 95398] [remote 182.77.62.24:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fe-eSd8WoG-6-XpC8FwACKws"]
[Mon Jul 20 07:15:39.844166 2026] [security2:error] [pid 95128:tid 95504] [remote 188.166.241.141:44328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fe-eSd8WoG-6-XpC8NAACRHU"]
[Mon Jul 20 07:15:39.884529 2026] [security2:error] [pid 95128:tid 95636] [client 14.225.17.146:58891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4fe-eSd8WoG-6-XpC8KwAAAow"], referer: http://mobilesurvsolutions.com/2020
[Mon Jul 20 07:15:39.897647 2026] [autoindex:error] [pid 95128:tid 95575] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/ocean/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:39.925943 2026] [security2:error] [pid 95128:tid 95424] [remote 182.77.62.24:44784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fe-eSd8WoG-6-XpC8OQACZiU"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:40.173800 2026] [security2:error] [pid 95126:tid 95270] [client 103.176.215.66:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ffApx5ks9joCJTKWxIQAAAZs"]
[Mon Jul 20 07:15:40.174417 2026] [security2:error] [pid 95126:tid 95270] [client 103.176.215.66:61222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ffApx5ks9joCJTKWxIQAAAZs"]
[Mon Jul 20 07:15:40.178283 2026] [security2:error] [pid 95128:tid 95537] [client 144.172.114.51:35622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/admin/phpinfo.php"] [unique_id "al4ffOeSd8WoG-6-XpC8SAAAAik"]
[Mon Jul 20 07:15:40.253781 2026] [security2:error] [pid 95128:tid 95435] [remote 188.166.241.141:44328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ffOeSd8WoG-6-XpC8SwACPTA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:15:40.293219 2026] [security2:error] [pid 95128:tid 95588] [client 50.116.65.227:12346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ffOeSd8WoG-6-XpC8TwAAAlw"]
[Mon Jul 20 07:15:40.303401 2026] [security2:error] [pid 95126:tid 95332] [client 50.116.65.227:12356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ffApx5ks9joCJTKWxKAAAAdk"]
[Mon Jul 20 07:15:40.334819 2026] [security2:error] [pid 95126:tid 95301] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4ffApx5ks9joCJTKWxKgAAAbo"]
[Mon Jul 20 07:15:40.370641 2026] [security2:error] [pid 95126:tid 95384] [client 187.16.64.216:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ffApx5ks9joCJTKWxLQAAAg0"]
[Mon Jul 20 07:15:40.370774 2026] [security2:error] [pid 95126:tid 95384] [client 187.16.64.216:62704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ffApx5ks9joCJTKWxLQAAAg0"]
[Mon Jul 20 07:15:40.456607 2026] [security2:error] [pid 95128:tid 95562] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4ffOeSd8WoG-6-XpC8TQAAAkI"]
[Mon Jul 20 07:15:40.511759 2026] [security2:error] [pid 95128:tid 95577] [client 157.20.138.62:55211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ffOeSd8WoG-6-XpC8UgAAAlE"]
[Mon Jul 20 07:15:40.511911 2026] [security2:error] [pid 95128:tid 95577] [client 157.20.138.62:55211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ffOeSd8WoG-6-XpC8UgAAAlE"]
[Mon Jul 20 07:15:40.524996 2026] [security2:error] [pid 95128:tid 95631] [client 57.141.18.72:64746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4feeeSd8WoG-6-XpC7nAAChwI"]
[Mon Jul 20 07:15:40.525457 2026] [security2:error] [pid 95126:tid 95155] [remote 15.235.27.236:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-users-1.xml"] [unique_id "al4ffApx5ks9joCJTKWxLwABsho"]
[Mon Jul 20 07:15:40.525684 2026] [security2:error] [pid 95126:tid 95293] [client 15.235.27.236:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "beauacoustics.com"] [uri "/wp-sitemap-users-1.xml"] [unique_id "al4ffApx5ks9joCJTKWxLwABsho"]
[Mon Jul 20 07:15:40.583873 2026] [security2:error] [pid 95126:tid 95306] [client 77.110.127.138:59462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ffApx5ks9joCJTKWxLgAAAb8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:40.600353 2026] [autoindex:error] [pid 95126:tid 95336] [client 198.235.24.13:0] AH01276: Cannot serve directory /home1/tgdhcnmy/public_html/upstatecarolinafrenchies/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:40.796049 2026] [security2:error] [pid 95128:tid 95633] [client 18.142.226.106:17550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ffOeSd8WoG-6-XpC8ZwAAAok"]
[Mon Jul 20 07:15:40.893135 2026] [security2:error] [pid 94831:tid 94860] [remote 188.166.241.141:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4ffI06NaEKF1g_MW2o1gAACxw"]
[Mon Jul 20 07:15:41.111793 2026] [autoindex:error] [pid 95126:tid 95322] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/pomo/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:41.173103 2026] [security2:error] [pid 95128:tid 95636] [client 14.225.17.146:59162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4ffOeSd8WoG-6-XpC8awAAAow"]
[Mon Jul 20 07:15:41.337190 2026] [proxy:error] [pid 95128:tid 95535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:15:41.337240 2026] [proxy_http:error] [pid 95128:tid 95535] [client 107.172.180.205:41582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:15:41.338588 2026] [proxy:error] [pid 95128:tid 95535] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:15:41.338624 2026] [proxy_http:error] [pid 95128:tid 95535] [client 107.172.180.205:41582] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:15:41.345541 2026] [security2:error] [pid 95128:tid 95605] [client 57.141.18.44:53504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4feueSd8WoG-6-XpC72wACbV8"]
[Mon Jul 20 07:15:41.383291 2026] [security2:error] [pid 95126:tid 95358] [client 57.141.18.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ffQpx5ks9joCJTKWxPwAAAfM"]
[Mon Jul 20 07:15:41.504494 2026] [autoindex:error] [pid 95128:tid 95635] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/themes/twentytwentythree/patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:41.619473 2026] [security2:error] [pid 94831:tid 94854] [remote 188.166.241.141:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4ffY06NaEKF1g_MW2o4AAAbxY"], referer: https://mail.indiraskitchenllc.com/wp-login.php
[Mon Jul 20 07:15:41.660538 2026] [security2:error] [pid 95128:tid 95618] [client 18.142.226.106:17562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ffeeSd8WoG-6-XpC8sgAAAno"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:15:41.835004 2026] [security2:error] [pid 95128:tid 95489] [remote 124.55.178.99:43094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ffeeSd8WoG-6-XpC8vgACiWY"]
[Mon Jul 20 07:15:41.914570 2026] [security2:error] [pid 95128:tid 95589] [client 77.110.127.138:59471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ffeeSd8WoG-6-XpC8yQAAAl0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:41.914677 2026] [security2:error] [pid 95128:tid 95589] [client 77.110.127.138:59471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ffeeSd8WoG-6-XpC8yQAAAl0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:41.915115 2026] [autoindex:error] [pid 95128:tid 95547] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:41.970043 2026] [security2:error] [pid 95128:tid 95536] [client 66.249.73.96:55406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "suretybonds-california.com"] [uri "/forms.php"] [unique_id "al4ffeeSd8WoG-6-XpC8ygAAAig"], referer: https://suretybonds-california.com/surety-bonds-blog/
[Mon Jul 20 07:15:42.045266 2026] [security2:error] [pid 94831:tid 95055] [client 14.225.17.146:59012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4ffY06NaEKF1g_MW2o2gAAAF4"], referer: http://adultdaycarereno.com/2020
[Mon Jul 20 07:15:42.093780 2026] [security2:error] [pid 95128:tid 95533] [client 144.172.114.51:42946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/test/phpinfo.php"] [unique_id "al4ffueSd8WoG-6-XpC81AAAAiU"]
[Mon Jul 20 07:15:42.321198 2026] [security2:error] [pid 95128:tid 95498] [remote 124.55.178.99:43094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ffueSd8WoG-6-XpC86QAChW8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:42.324317 2026] [autoindex:error] [pid 95128:tid 95578] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/block-patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:42.511986 2026] [security2:error] [pid 95128:tid 95524] [client 66.249.73.96:55406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "suretybonds-california.com"] [uri "/howtoobtainbonds.php"] [unique_id "al4ffueSd8WoG-6-XpC89wAAAhw"], referer: https://suretybonds-california.com/surety-bonds-blog/
[Mon Jul 20 07:15:42.717576 2026] [autoindex:error] [pid 95128:tid 95575] [client 194.61.41.69:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/certificates/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:42.729430 2026] [security2:error] [pid 95128:tid 95530] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4ffueSd8WoG-6-XpC9CAAAAiI"]
[Mon Jul 20 07:15:42.763227 2026] [proxy:error] [pid 95128:tid 95521] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:15:42.763301 2026] [proxy_http:error] [pid 95128:tid 95521] [client 107.172.180.205:41606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:15:42.763998 2026] [proxy:error] [pid 95128:tid 95521] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:15:42.764043 2026] [proxy_http:error] [pid 95128:tid 95521] [client 107.172.180.205:41606] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:15:42.810340 2026] [security2:error] [pid 94831:tid 94997] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4ffo06NaEKF1g_MW2o7QAAACQ"]
[Mon Jul 20 07:15:42.973030 2026] [security2:error] [pid 95128:tid 95603] [client 52.109.76.144:10370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ffueSd8WoG-6-XpC9GAAAAms"]
[Mon Jul 20 07:15:42.988399 2026] [security2:error] [pid 95128:tid 95523] [client 85.204.70.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdn.sustaintheart.com"] [uri "/xmlrpc.php"] [unique_id "al4ffueSd8WoG-6-XpC9GwAAAhs"]
[Mon Jul 20 07:15:43.020725 2026] [security2:error] [pid 94831:tid 95088] [client 63.179.149.246:12752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ffo06NaEKF1g_MW2o8AAAAH8"]
[Mon Jul 20 07:15:43.079745 2026] [security2:error] [pid 94831:tid 94988] [client 49.37.242.14:62003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ffo06NaEKF1g_MW2o6wAAABs"]
[Mon Jul 20 07:15:43.114892 2026] [security2:error] [pid 95128:tid 95586] [client 52.109.76.144:10370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ff-eSd8WoG-6-XpC9JQAAAlo"]
[Mon Jul 20 07:15:43.248928 2026] [security2:error] [pid 95128:tid 95588] [client 154.192.123.127:17760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ff-eSd8WoG-6-XpC9MQAAAlw"]
[Mon Jul 20 07:15:43.249053 2026] [security2:error] [pid 95128:tid 95588] [client 154.192.123.127:17760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ff-eSd8WoG-6-XpC9MQAAAlw"]
[Mon Jul 20 07:15:43.344674 2026] [security2:error] [pid 95128:tid 95570] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4ff-eSd8WoG-6-XpC9KwAAAko"]
[Mon Jul 20 07:15:43.536522 2026] [security2:error] [pid 95128:tid 95615] [client 77.110.127.138:59477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ff-eSd8WoG-6-XpC9OgAAAnc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:43.580899 2026] [security2:error] [pid 95128:tid 95444] [remote 95.217.78.234:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ff-eSd8WoG-6-XpC9PQACizk"]
[Mon Jul 20 07:15:43.581136 2026] [security2:error] [pid 95128:tid 95598] [client 3.67.192.83:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ff-eSd8WoG-6-XpC9PgAAAmY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:15:43.624075 2026] [security2:error] [pid 95128:tid 95561] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4ff-eSd8WoG-6-XpC9SQAAAkE"]
[Mon Jul 20 07:15:43.673167 2026] [security2:error] [pid 95128:tid 95552] [client 4.201.176.24:41024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ff-eSd8WoG-6-XpC9TQAAAjg"]
[Mon Jul 20 07:15:43.728513 2026] [security2:error] [pid 95128:tid 95544] [client 77.110.127.138:59479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ff-eSd8WoG-6-XpC9UwAAAjA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:43.787412 2026] [security2:error] [pid 95128:tid 95558] [client 104.234.53.91:38455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ff-eSd8WoG-6-XpC9XwAAAj4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:43.800658 2026] [security2:error] [pid 95128:tid 95481] [remote 95.217.78.234:54862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ff-eSd8WoG-6-XpC9YwACjF4"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:15:43.832891 2026] [security2:error] [pid 95128:tid 95562] [client 4.201.176.24:41024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ff-eSd8WoG-6-XpC9ZwAAAkI"]
[Mon Jul 20 07:15:43.837081 2026] [security2:error] [pid 95126:tid 95259] [client 57.141.18.110:58096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ffApx5ks9joCJTKWxJQABkAc"]
[Mon Jul 20 07:15:43.875455 2026] [security2:error] [pid 95128:tid 95538] [client 154.208.48.130:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ff-eSd8WoG-6-XpC9bAAAAio"]
[Mon Jul 20 07:15:43.875569 2026] [security2:error] [pid 95128:tid 95538] [client 154.208.48.130:61019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ff-eSd8WoG-6-XpC9bAAAAio"]
[Mon Jul 20 07:15:43.936602 2026] [security2:error] [pid 95128:tid 95521] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4ff-eSd8WoG-6-XpC9cAAAAhk"]
[Mon Jul 20 07:15:43.988164 2026] [security2:error] [pid 95128:tid 95546] [client 74.208.214.194:43656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ff-eSd8WoG-6-XpC9dAAAAjI"]
[Mon Jul 20 07:15:43.999774 2026] [security2:error] [pid 95126:tid 95280] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4ffwpx5ks9joCJTKWxYwAAAaU"]
[Mon Jul 20 07:15:44.097824 2026] [security2:error] [pid 95126:tid 95372] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4fgApx5ks9joCJTKWxaAAAAgE"]
[Mon Jul 20 07:15:44.144360 2026] [security2:error] [pid 95128:tid 95591] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4fgOeSd8WoG-6-XpC9fgAAAl8"]
[Mon Jul 20 07:15:44.282377 2026] [security2:error] [pid 95128:tid 95541] [client 77.110.127.138:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fgOeSd8WoG-6-XpC9hgAAAi0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:44.406495 2026] [security2:error] [pid 95128:tid 95524] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4fgOeSd8WoG-6-XpC9jwAAAhw"]
[Mon Jul 20 07:15:44.420947 2026] [security2:error] [pid 95128:tid 95563] [client 57.141.18.29:30930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ffOeSd8WoG-6-XpC8cwACQ1Y"]
[Mon Jul 20 07:15:44.522229 2026] [autoindex:error] [pid 95128:tid 95572] [client 194.61.41.69:60199] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/js/widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:44.651162 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:59481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fgApx5ks9joCJTKWxbQAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:44.652328 2026] [security2:error] [pid 95128:tid 95633] [client 117.211.236.168:52695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fgOeSd8WoG-6-XpC9ngAAAok"]
[Mon Jul 20 07:15:44.652438 2026] [security2:error] [pid 95128:tid 95633] [client 117.211.236.168:52695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fgOeSd8WoG-6-XpC9ngAAAok"]
[Mon Jul 20 07:15:44.718013 2026] [security2:error] [pid 95128:tid 95615] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4fgOeSd8WoG-6-XpC9owAAAnc"]
[Mon Jul 20 07:15:44.718657 2026] [security2:error] [pid 95128:tid 95594] [client 45.157.112.60:63447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fgOeSd8WoG-6-XpC9pAAAAmI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:15:44.768476 2026] [core:error] [pid 95128:tid 95628] [client 205.210.31.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:44.768506 2026] [core:error] [pid 95128:tid 95628] [client 205.210.31.129:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:44.780951 2026] [security2:error] [pid 95126:tid 95332] [client 14.225.17.146:59358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4ffwpx5ks9joCJTKWxYQAAAdk"], referer: http://cloudspacesgroup.com/2020
[Mon Jul 20 07:15:44.840275 2026] [security2:error] [pid 95128:tid 95576] [client 14.225.17.146:59334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4ff-eSd8WoG-6-XpC9NwAAAlA"], referer: http://bbwipartnerconference.com/2020
[Mon Jul 20 07:15:45.039564 2026] [security2:error] [pid 94831:tid 94981] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4fgY06NaEKF1g_MW2o_wAAABQ"]
[Mon Jul 20 07:15:45.082586 2026] [security2:error] [pid 95128:tid 95544] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fgOeSd8WoG-6-XpC9sQAAAjA"]
[Mon Jul 20 07:15:45.193054 2026] [security2:error] [pid 95128:tid 95642] [client 57.141.18.63:22088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ffeeSd8WoG-6-XpC8wAACkiY"]
[Mon Jul 20 07:15:45.340897 2026] [security2:error] [pid 95128:tid 95540] [client 144.172.114.51:46004] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/private/.env"] [unique_id "al4fgeeSd8WoG-6-XpC9ygAAAiw"]
[Mon Jul 20 07:15:45.346414 2026] [security2:error] [pid 95128:tid 95597] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4fgeeSd8WoG-6-XpC9zAAAAmU"]
[Mon Jul 20 07:15:45.356076 2026] [security2:error] [pid 95128:tid 95522] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4fgeeSd8WoG-6-XpC9zgAAAho"]
[Mon Jul 20 07:15:45.375309 2026] [security2:error] [pid 95128:tid 95546] [client 77.110.127.138:59484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fgeeSd8WoG-6-XpC9zwAAAjI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:45.555549 2026] [security2:error] [pid 95128:tid 95565] [client 77.110.127.138:59485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fgeeSd8WoG-6-XpC95wAAAkU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:45.649361 2026] [security2:error] [pid 95128:tid 95541] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4fgeeSd8WoG-6-XpC9-AAAAi0"]
[Mon Jul 20 07:15:45.654429 2026] [security2:error] [pid 95128:tid 95553] [client 77.110.127.138:59486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fgeeSd8WoG-6-XpC9-QAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:45.654537 2026] [security2:error] [pid 95128:tid 95553] [client 77.110.127.138:59486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fgeeSd8WoG-6-XpC9-QAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:45.777092 2026] [security2:error] [pid 95128:tid 95632] [client 194.61.41.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fgeeSd8WoG-6-XpC96wAAAog"]
[Mon Jul 20 07:15:45.783397 2026] [security2:error] [pid 95128:tid 95570] [client 14.225.17.146:59249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4fgeeSd8WoG-6-XpC94QAAAko"], referer: http://securingmemories.com/2020
[Mon Jul 20 07:15:45.801229 2026] [security2:error] [pid 95126:tid 95364] [client 77.110.127.138:59488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fgQpx5ks9joCJTKWxggAAAfk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:45.977604 2026] [security2:error] [pid 95128:tid 95611] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4fgeeSd8WoG-6-XpC-DAAAAnM"]
[Mon Jul 20 07:15:46.300496 2026] [security2:error] [pid 95126:tid 95279] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4fggpx5ks9joCJTKWxigAAAaQ"]
[Mon Jul 20 07:15:46.424113 2026] [security2:error] [pid 95128:tid 95642] [client 77.110.127.138:59491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fgueSd8WoG-6-XpC-KgAAApI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:46.425200 2026] [security2:error] [pid 95128:tid 95600] [client 158.173.241.141:25469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4fgueSd8WoG-6-XpC-GwACaFs"]
[Mon Jul 20 07:15:46.490948 2026] [security2:error] [pid 95128:tid 95607] [client 201.27.111.74:64143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fgueSd8WoG-6-XpC-MQAAAm8"]
[Mon Jul 20 07:15:46.491050 2026] [security2:error] [pid 95128:tid 95607] [client 201.27.111.74:64143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fgueSd8WoG-6-XpC-MQAAAm8"]
[Mon Jul 20 07:15:46.626674 2026] [security2:error] [pid 95128:tid 95526] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4fgueSd8WoG-6-XpC-QgAAAh4"]
[Mon Jul 20 07:15:46.646519 2026] [autoindex:error] [pid 95128:tid 95573] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/images/media/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:46.710253 2026] [security2:error] [pid 95128:tid 95531] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4fgueSd8WoG-6-XpC-SAAAAiM"]
[Mon Jul 20 07:15:46.738163 2026] [security2:error] [pid 95128:tid 95599] [client 57.141.18.103:46654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ff-eSd8WoG-6-XpC9QwACZww"]
[Mon Jul 20 07:15:46.940973 2026] [security2:error] [pid 94831:tid 95005] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4fgo06NaEKF1g_MW2pBwAAACw"]
[Mon Jul 20 07:15:47.062493 2026] [autoindex:error] [pid 95128:tid 95561] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:47.080468 2026] [security2:error] [pid 95128:tid 95553] [client 50.116.65.227:16982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4fg-eSd8WoG-6-XpC-ZgAAAjk"]
[Mon Jul 20 07:15:47.094068 2026] [security2:error] [pid 95128:tid 95597] [client 50.116.65.227:12544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-7-Feature-Image.jpg"] [unique_id "al4fg-eSd8WoG-6-XpC-ZwAAAmU"]
[Mon Jul 20 07:15:47.246299 2026] [security2:error] [pid 95128:tid 95523] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4fg-eSd8WoG-6-XpC-cwAAAhs"]
[Mon Jul 20 07:15:47.313159 2026] [security2:error] [pid 95128:tid 95598] [client 103.144.65.217:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fg-eSd8WoG-6-XpC-dwAAAmY"]
[Mon Jul 20 07:15:47.313301 2026] [security2:error] [pid 95128:tid 95598] [client 103.144.65.217:62883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fg-eSd8WoG-6-XpC-dwAAAmY"]
[Mon Jul 20 07:15:47.483569 2026] [security2:error] [pid 95128:tid 95628] [client 74.7.227.179:56972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4fg-eSd8WoG-6-XpC-eAAChDQ"], referer: https://tejasenvironmental.com/p=1770891
[Mon Jul 20 07:15:47.496181 2026] [security2:error] [pid 95128:tid 95534] [client 14.225.17.146:56475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4fgueSd8WoG-6-XpC-NgAAAiY"], referer: http://uritems.net/2020
[Mon Jul 20 07:15:47.496438 2026] [security2:error] [pid 95126:tid 95266] [client 144.172.114.51:46008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/backup/.env"] [unique_id "al4fgwpx5ks9joCJTKWxoAAAAZc"]
[Mon Jul 20 07:15:47.552948 2026] [security2:error] [pid 95128:tid 95575] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4fg-eSd8WoG-6-XpC-ggAAAk8"]
[Mon Jul 20 07:15:47.648872 2026] [security2:error] [pid 95128:tid 95629] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fg-eSd8WoG-6-XpC-fQAAAoU"]
[Mon Jul 20 07:15:47.865273 2026] [security2:error] [pid 95128:tid 95559] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4fg-eSd8WoG-6-XpC-lwAAAj8"]
[Mon Jul 20 07:15:47.884054 2026] [security2:error] [pid 95128:tid 95452] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fg-eSd8WoG-6-XpC-mQAChkE"]
[Mon Jul 20 07:15:47.884182 2026] [security2:error] [pid 95128:tid 95630] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fg-eSd8WoG-6-XpC-mQAChkE"]
[Mon Jul 20 07:15:47.890713 2026] [security2:error] [pid 95128:tid 95640] [client 77.110.127.138:59495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fg-eSd8WoG-6-XpC-kAAAApA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:48.024363 2026] [security2:error] [pid 95128:tid 95613] [client 144.172.114.51:46020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/docker/.env"] [unique_id "al4fhOeSd8WoG-6-XpC-nwAAAnU"]
[Mon Jul 20 07:15:48.155821 2026] [security2:error] [pid 95128:tid 95567] [client 14.225.17.146:65273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4fhOeSd8WoG-6-XpC-ngAAAkc"], referer: http://ivetstrategies.com/2020
[Mon Jul 20 07:15:48.175048 2026] [security2:error] [pid 95128:tid 95584] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn.sustaintheart.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4fhOeSd8WoG-6-XpC-qQAAAlg"]
[Mon Jul 20 07:15:48.295145 2026] [security2:error] [pid 95128:tid 95525] [client 143.44.185.218:38482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fhOeSd8WoG-6-XpC-rAAAAh0"]
[Mon Jul 20 07:15:48.295301 2026] [security2:error] [pid 95128:tid 95525] [client 143.44.185.218:38482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fhOeSd8WoG-6-XpC-rAAAAh0"]
[Mon Jul 20 07:15:48.331027 2026] [security2:error] [pid 95128:tid 95537] [client 14.225.17.146:60305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4fg-eSd8WoG-6-XpC-WQAAAik"], referer: http://whiteoutcb.com/2020
[Mon Jul 20 07:15:48.331417 2026] [security2:error] [pid 95126:tid 95284] [client 158.173.89.95:29375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fhApx5ks9joCJTKWxsAAAAak"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:15:48.591875 2026] [security2:error] [pid 95126:tid 95330] [client 144.172.114.51:46032] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/test/.env"] [unique_id "al4fhApx5ks9joCJTKWxswAAAdc"]
[Mon Jul 20 07:15:48.598102 2026] [autoindex:error] [pid 95128:tid 95595] [client 104.196.202.31:0] AH01276: Cannot serve directory /home1/heidimo2/strongtowerpodcast.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:48.716048 2026] [security2:error] [pid 95128:tid 95622] [client 104.234.53.74:38627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4fhOeSd8WoG-6-XpC-0AAAAn4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:48.731984 2026] [security2:error] [pid 95128:tid 95581] [client 57.141.18.45:31106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fgeeSd8WoG-6-XpC90AACVQI"]
[Mon Jul 20 07:15:48.749186 2026] [security2:error] [pid 95128:tid 95495] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fhOeSd8WoG-6-XpC-0QACW2w"]
[Mon Jul 20 07:15:48.749326 2026] [security2:error] [pid 95128:tid 95587] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fhOeSd8WoG-6-XpC-0QACW2w"]
[Mon Jul 20 07:15:48.775983 2026] [security2:error] [pid 95128:tid 95543] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fhOeSd8WoG-6-XpC-vQAAAi8"]
[Mon Jul 20 07:15:48.895413 2026] [security2:error] [pid 95126:tid 95326] [client 77.110.127.138:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fhApx5ks9joCJTKWxvwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:48.895508 2026] [security2:error] [pid 95126:tid 95326] [client 77.110.127.138:59505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fhApx5ks9joCJTKWxvwAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:48.914770 2026] [security2:error] [pid 95128:tid 95558] [client 88.241.67.160:55174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fhOeSd8WoG-6-XpC-2wAAAj4"]
[Mon Jul 20 07:15:48.915163 2026] [security2:error] [pid 95128:tid 95558] [client 88.241.67.160:55174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fhOeSd8WoG-6-XpC-2wAAAj4"]
[Mon Jul 20 07:15:49.330568 2026] [security2:error] [pid 95126:tid 95283] [client 31.59.27.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4fhQpx5ks9joCJTKWxyQAAAag"], referer: http://www.elementconstruction.co.uk/robots.txt
[Mon Jul 20 07:15:49.491378 2026] [security2:error] [pid 95126:tid 95363] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fhQpx5ks9joCJTKWxygAAAfg"]
[Mon Jul 20 07:15:49.855821 2026] [security2:error] [pid 95128:tid 95555] [client 57.141.18.106:34096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fgueSd8WoG-6-XpC-QAACO1o"]
[Mon Jul 20 07:15:49.999873 2026] [autoindex:error] [pid 95128:tid 95519] [client 194.61.41.241:33789] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:50.326941 2026] [security2:error] [pid 95126:tid 95321] [client 159.26.101.22:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "ashleystrain.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4fhgpx5ks9joCJTKWx6gAAAc4"]
[Mon Jul 20 07:15:50.530818 2026] [security2:error] [pid 95128:tid 95617] [client 77.110.127.138:59513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fhueSd8WoG-6-XpC_IAAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:50.550286 2026] [security2:error] [pid 95128:tid 95630] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fhueSd8WoG-6-XpC_GQAAAoY"]
[Mon Jul 20 07:15:50.636561 2026] [security2:error] [pid 95126:tid 95336] [client 57.141.18.48:58020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fgwpx5ks9joCJTKWxnQAB3SE"]
[Mon Jul 20 07:15:50.659728 2026] [core:error] [pid 94831:tid 95017] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:50.659762 2026] [core:error] [pid 94831:tid 95017] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:50.715562 2026] [security2:error] [pid 95128:tid 95604] [client 14.225.17.146:56333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4fheeSd8WoG-6-XpC_AQAAAmw"], referer: http://claysharecon.com/2020
[Mon Jul 20 07:15:50.770010 2026] [security2:error] [pid 95126:tid 95358] [client 103.176.215.66:61741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fhgpx5ks9joCJTKWx8wAAAfM"]
[Mon Jul 20 07:15:50.770380 2026] [security2:error] [pid 95126:tid 95358] [client 103.176.215.66:61741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fhgpx5ks9joCJTKWx8wAAAfM"]
[Mon Jul 20 07:15:50.830609 2026] [security2:error] [pid 95126:tid 95377] [client 57.141.18.97:48968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fgwpx5ks9joCJTKWxogACBiY"]
[Mon Jul 20 07:15:50.920606 2026] [security2:error] [pid 95126:tid 95369] [client 187.16.64.216:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fhgpx5ks9joCJTKWx9AAAAf4"]
[Mon Jul 20 07:15:50.920796 2026] [security2:error] [pid 95126:tid 95369] [client 187.16.64.216:63261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fhgpx5ks9joCJTKWx9AAAAf4"]
[Mon Jul 20 07:15:50.999474 2026] [security2:error] [pid 95126:tid 95278] [client 144.172.114.51:33750] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/k8s/.env"] [unique_id "al4fhgpx5ks9joCJTKWx9gAAAaM"]
[Mon Jul 20 07:15:51.060881 2026] [autoindex:error] [pid 95126:tid 95365] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/images/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:51.163644 2026] [security2:error] [pid 95128:tid 95637] [client 157.20.138.62:55772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fh-eSd8WoG-6-XpC_QgAAAo0"]
[Mon Jul 20 07:15:51.163767 2026] [security2:error] [pid 95128:tid 95637] [client 157.20.138.62:55772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fh-eSd8WoG-6-XpC_QgAAAo0"]
[Mon Jul 20 07:15:51.667539 2026] [security2:error] [pid 95128:tid 95573] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fh-eSd8WoG-6-XpC_UAAAAk0"]
[Mon Jul 20 07:15:51.777402 2026] [security2:error] [pid 95126:tid 95349] [client 52.109.52.84:27848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fhwpx5ks9joCJTKWyCQAAAeo"]
[Mon Jul 20 07:15:51.839015 2026] [security2:error] [pid 95126:tid 95259] [client 77.110.127.138:59525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fhwpx5ks9joCJTKWyCAAAAZA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:51.889648 2026] [security2:error] [pid 95126:tid 95289] [client 52.109.52.84:27848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fhwpx5ks9joCJTKWyDgAAAa4"]
[Mon Jul 20 07:15:51.947379 2026] [security2:error] [pid 95128:tid 95538] [client 77.110.127.138:59492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fh-eSd8WoG-6-XpC_egAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:51.947510 2026] [security2:error] [pid 95128:tid 95538] [client 77.110.127.138:59492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fh-eSd8WoG-6-XpC_egAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:51.957582 2026] [security2:error] [pid 95128:tid 95530] [client 144.172.114.51:54972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/private/config.php"] [unique_id "al4fh-eSd8WoG-6-XpC_ewAAAiI"]
[Mon Jul 20 07:15:52.001650 2026] [security2:error] [pid 95126:tid 95332] [client 52.109.68.130:22978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fhwpx5ks9joCJTKWyDwAAAdk"]
[Mon Jul 20 07:15:52.159642 2026] [security2:error] [pid 95126:tid 95322] [client 52.109.68.130:22978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fiApx5ks9joCJTKWyEgAAAc8"]
[Mon Jul 20 07:15:52.296538 2026] [security2:error] [pid 95126:tid 95364] [client 57.141.18.64:34850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fhApx5ks9joCJTKWxvQAB-S8"]
[Mon Jul 20 07:15:52.407888 2026] [security2:error] [pid 95128:tid 95540] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fiOeSd8WoG-6-XpC_iAAAAiw"]
[Mon Jul 20 07:15:52.700505 2026] [security2:error] [pid 94831:tid 95033] [client 82.102.27.163:38660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fiI06NaEKF1g_MW2paQAAAEg"]
[Mon Jul 20 07:15:52.700640 2026] [security2:error] [pid 94831:tid 95033] [client 82.102.27.163:38660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fiI06NaEKF1g_MW2paQAAAEg"]
[Mon Jul 20 07:15:52.885848 2026] [autoindex:error] [pid 95128:tid 95629] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/.well-known/acme-challenge/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:53.175170 2026] [security2:error] [pid 95128:tid 95573] [client 144.172.114.51:54988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/settings.php"] [unique_id "al4fieeSd8WoG-6-XpC_xgAAAk0"]
[Mon Jul 20 07:15:53.299861 2026] [security2:error] [pid 95126:tid 95261] [client 104.234.53.93:35849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fiQpx5ks9joCJTKWyJAAAAZI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:53.369833 2026] [security2:error] [pid 95126:tid 95272] [client 14.225.17.146:56543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4fhwpx5ks9joCJTKWyAgAAAZ0"], referer: http://webgardensbypaula.com/2020
[Mon Jul 20 07:15:53.407559 2026] [core:error] [pid 95128:tid 95625] [client 195.182.16.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:53.407589 2026] [core:error] [pid 95128:tid 95625] [client 195.182.16.23:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:15:53.499004 2026] [security2:error] [pid 95128:tid 95600] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fieeSd8WoG-6-XpC_0AAAAmg"]
[Mon Jul 20 07:15:53.758033 2026] [security2:error] [pid 95128:tid 95574] [client 50.116.65.227:12542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fieeSd8WoG-6-XpC_3gAAAk4"]
[Mon Jul 20 07:15:53.769558 2026] [security2:error] [pid 95126:tid 95331] [client 50.116.65.227:12552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fiQpx5ks9joCJTKWyMAAAAdg"]
[Mon Jul 20 07:15:53.878589 2026] [security2:error] [pid 95126:tid 95358] [client 154.192.123.127:18230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fiQpx5ks9joCJTKWyMwAAAfM"]
[Mon Jul 20 07:15:53.878723 2026] [security2:error] [pid 95126:tid 95358] [client 154.192.123.127:18230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fiQpx5ks9joCJTKWyMwAAAfM"]
[Mon Jul 20 07:15:53.880055 2026] [security2:error] [pid 95128:tid 95598] [client 77.110.127.138:59538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fieeSd8WoG-6-XpC_5QAAAmY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:54.148619 2026] [security2:error] [pid 95126:tid 95285] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fiQpx5ks9joCJTKWyNgAAAao"]
[Mon Jul 20 07:15:54.343078 2026] [security2:error] [pid 95126:tid 95346] [client 50.116.65.227:12586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4figpx5ks9joCJTKWyOQAAAec"]
[Mon Jul 20 07:15:54.371259 2026] [security2:error] [pid 95128:tid 95434] [remote 72.167.132.114:47536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fiueSd8WoG-6-XpC_-wACFS8"]
[Mon Jul 20 07:15:54.482450 2026] [security2:error] [pid 95126:tid 95270] [client 57.141.18.78:22076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fhgpx5ks9joCJTKWx9QABmzo"]
[Mon Jul 20 07:15:54.539106 2026] [security2:error] [pid 95128:tid 95627] [client 50.116.65.227:12614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4fiueSd8WoG-6-XpC_-QAAAoM"]
[Mon Jul 20 07:15:54.584038 2026] [security2:error] [pid 95128:tid 95500] [remote 72.167.132.114:47536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fiueSd8WoG-6-XpDABwACH3E"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:54.599009 2026] [security2:error] [pid 95128:tid 95458] [remote 8.217.108.67:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fiueSd8WoG-6-XpDACAACMkc"]
[Mon Jul 20 07:15:54.669391 2026] [autoindex:error] [pid 95128:tid 95534] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/css/dist/edit-widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:54.683722 2026] [security2:error] [pid 95126:tid 95287] [client 154.208.48.130:61543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4figpx5ks9joCJTKWyQgAAAaw"]
[Mon Jul 20 07:15:54.683850 2026] [security2:error] [pid 95126:tid 95287] [client 154.208.48.130:61543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4figpx5ks9joCJTKWyQgAAAaw"]
[Mon Jul 20 07:15:54.745917 2026] [security2:error] [pid 95128:tid 95476] [remote 103.28.36.220:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4fiueSd8WoG-6-XpDAEAACKVk"]
[Mon Jul 20 07:15:54.840654 2026] [security2:error] [pid 95128:tid 95631] [client 14.225.17.146:59807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4fieeSd8WoG-6-XpC_wgAAAoc"], referer: http://according2plant.com/2020
[Mon Jul 20 07:15:55.034165 2026] [security2:error] [pid 95128:tid 95443] [remote 182.77.62.24:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fi-eSd8WoG-6-XpDAIAACUTg"]
[Mon Jul 20 07:15:55.083870 2026] [autoindex:error] [pid 95128:tid 95573] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Requests/src/Exception/Http/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:55.221981 2026] [security2:error] [pid 95128:tid 95506] [remote 103.28.36.220:32838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4fi-eSd8WoG-6-XpDAKwACJHc"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:15:55.480500 2026] [autoindex:error] [pid 95128:tid 95576] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:55.564012 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:59708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fiwpx5ks9joCJTKWyWAAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.564162 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:59708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fiwpx5ks9joCJTKWyWAAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.568591 2026] [autoindex:error] [pid 95128:tid 95603] [client 35.222.199.138:57421] AH01276: Cannot serve directory /home1/heidimo2/rootedandwholecoaching.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:55.601004 2026] [security2:error] [pid 95128:tid 95498] [remote 182.77.62.24:49678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fi-eSd8WoG-6-XpDARgACR28"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 07:15:55.611288 2026] [security2:error] [pid 95128:tid 95571] [client 178.128.233.140:50964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.genesismbs.com"] [uri "/wp-login.php"] [unique_id "al4fi-eSd8WoG-6-XpDAQQAAAks"]
[Mon Jul 20 07:15:55.740730 2026] [security2:error] [pid 95128:tid 95586] [client 77.110.127.138:59729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fi-eSd8WoG-6-XpDAVAAAAlo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.740841 2026] [security2:error] [pid 95128:tid 95586] [client 77.110.127.138:59729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fi-eSd8WoG-6-XpDAVAAAAlo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.874522 2026] [autoindex:error] [pid 95128:tid 95548] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Text/Diff/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:55.897989 2026] [security2:error] [pid 94831:tid 94984] [client 77.110.127.138:59756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fi406NaEKF1g_MW2pngAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.898087 2026] [security2:error] [pid 94831:tid 94984] [client 77.110.127.138:59756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fi406NaEKF1g_MW2pngAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.905188 2026] [security2:error] [pid 95128:tid 95543] [client 77.110.127.138:59728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fi-eSd8WoG-6-XpDAUwAAAi8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:55.907116 2026] [security2:error] [pid 95126:tid 95293] [client 178.128.233.140:53909] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.genesismedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4fiwpx5ks9joCJTKWyXgAAAbI"]
[Mon Jul 20 07:15:55.919495 2026] [security2:error] [pid 95128:tid 95536] [client 178.128.233.140:51050] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.genesismbs.com"] [uri "/wp-login.php"] [unique_id "al4fi-eSd8WoG-6-XpDAYAAAAig"]
[Mon Jul 20 07:15:56.065502 2026] [security2:error] [pid 95128:tid 95523] [client 14.225.17.146:56987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4fiOeSd8WoG-6-XpC_lgAAAhs"], referer: http://areitoproducciones.com/2020
[Mon Jul 20 07:15:56.093108 2026] [security2:error] [pid 95126:tid 95352] [client 77.110.127.138:59774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjApx5ks9joCJTKWyYQAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:56.093195 2026] [security2:error] [pid 95126:tid 95352] [client 77.110.127.138:59774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjApx5ks9joCJTKWyYQAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:56.158809 2026] [security2:error] [pid 95128:tid 95618] [client 117.211.236.168:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fjOeSd8WoG-6-XpDAdAAAAno"]
[Mon Jul 20 07:15:56.158924 2026] [security2:error] [pid 95128:tid 95618] [client 117.211.236.168:53246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fjOeSd8WoG-6-XpDAdAAAAno"]
[Mon Jul 20 07:15:56.265194 2026] [security2:error] [pid 95128:tid 95570] [client 77.110.127.138:59796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjOeSd8WoG-6-XpDAeAAAAko"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:56.265280 2026] [security2:error] [pid 95128:tid 95570] [client 77.110.127.138:59796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjOeSd8WoG-6-XpDAeAAAAko"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:56.288652 2026] [autoindex:error] [pid 94831:tid 94994] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/skins/lightgray/img/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:15:56.437004 2026] [security2:error] [pid 95128:tid 95567] [client 77.110.127.138:59827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjOeSd8WoG-6-XpDAggAAAkc"]
[Mon Jul 20 07:15:56.437100 2026] [security2:error] [pid 95128:tid 95567] [client 77.110.127.138:59827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjOeSd8WoG-6-XpDAggAAAkc"]
[Mon Jul 20 07:15:56.452812 2026] [security2:error] [pid 94831:tid 94989] [client 77.110.127.138:59802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fjI06NaEKF1g_MW2pqAAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:56.527168 2026] [security2:error] [pid 95126:tid 95289] [client 77.110.127.138:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjApx5ks9joCJTKWyZwAAAa4"]
[Mon Jul 20 07:15:56.527291 2026] [security2:error] [pid 95126:tid 95289] [client 77.110.127.138:59525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fjApx5ks9joCJTKWyZwAAAa4"]
[Mon Jul 20 07:15:56.614768 2026] [security2:error] [pid 95126:tid 95300] [client 57.141.18.7:50444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fiApx5ks9joCJTKWyHAABuTU"]
[Mon Jul 20 07:15:56.684641 2026] [security2:error] [pid 95126:tid 95304] [client 94.72.110.190:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4fjApx5ks9joCJTKWyaQAAAb0"]
[Mon Jul 20 07:15:56.838619 2026] [security2:error] [pid 95128:tid 95594] [client 49.37.242.14:62485] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fjOeSd8WoG-6-XpDAmQAAAmI"]
[Mon Jul 20 07:15:56.838771 2026] [security2:error] [pid 95128:tid 95594] [client 49.37.242.14:62485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fjOeSd8WoG-6-XpDAmQAAAmI"]
[Mon Jul 20 07:15:56.894728 2026] [security2:error] [pid 95128:tid 95581] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fjOeSd8WoG-6-XpDAkgAAAlU"]
[Mon Jul 20 07:15:56.973329 2026] [security2:error] [pid 95128:tid 95553] [client 77.110.127.138:59873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fjOeSd8WoG-6-XpDAlAAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:57.058621 2026] [security2:error] [pid 95128:tid 95519] [client 201.27.111.74:64655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fjeeSd8WoG-6-XpDApQAAAhc"]
[Mon Jul 20 07:15:57.058738 2026] [security2:error] [pid 95128:tid 95519] [client 201.27.111.74:64655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fjeeSd8WoG-6-XpDApQAAAhc"]
[Mon Jul 20 07:15:57.186260 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:59920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fjeeSd8WoG-6-XpDAqwAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:57.507231 2026] [security2:error] [pid 95126:tid 95347] [client 104.234.53.89:42457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fjQpx5ks9joCJTKWyfAAAAeg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:15:57.561964 2026] [security2:error] [pid 95128:tid 95572] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fjeeSd8WoG-6-XpDAtAAAAkw"]
[Mon Jul 20 07:15:57.752310 2026] [security2:error] [pid 94831:tid 94900] [remote 173.249.4.11:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4fjY06NaEKF1g_MW2pxgAAH0Q"]
[Mon Jul 20 07:15:57.797949 2026] [security2:error] [pid 95128:tid 95556] [client 103.144.65.217:63333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fjeeSd8WoG-6-XpDAzwAAAjw"]
[Mon Jul 20 07:15:57.798066 2026] [security2:error] [pid 95128:tid 95556] [client 103.144.65.217:63333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fjeeSd8WoG-6-XpDAzwAAAjw"]
[Mon Jul 20 07:15:57.849910 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fjQpx5ks9joCJTKWygAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:58.106718 2026] [security2:error] [pid 94831:tid 94908] [remote 173.249.4.11:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4fjo06NaEKF1g_MW2pzQAAaEw"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:15:58.250034 2026] [security2:error] [pid 95128:tid 95595] [client 194.61.41.241:33789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fjueSd8WoG-6-XpDA2QAAAmM"]
[Mon Jul 20 07:15:58.337057 2026] [security2:error] [pid 95128:tid 95601] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fjueSd8WoG-6-XpDA5QAAAmk"]
[Mon Jul 20 07:15:58.366291 2026] [security2:error] [pid 95128:tid 95520] [client 57.141.18.33:58754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fiueSd8WoG-6-XpC__QACGDY"]
[Mon Jul 20 07:15:58.389825 2026] [security2:error] [pid 95128:tid 95614] [client 34.67.218.220:63572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "dasmarque.com"] [uri "/wp-json/batch/v1"] [unique_id "al4fjueSd8WoG-6-XpDA9AAAAnY"]
[Mon Jul 20 07:15:58.445101 2026] [security2:error] [pid 95128:tid 95395] [remote 45.90.123.233:32816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fjueSd8WoG-6-XpDA9QACiAg"]
[Mon Jul 20 07:15:58.508367 2026] [security2:error] [pid 95128:tid 95396] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fjueSd8WoG-6-XpDA_AACKwk"]
[Mon Jul 20 07:15:58.508516 2026] [security2:error] [pid 95128:tid 95539] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fjueSd8WoG-6-XpDA_AACKwk"]
[Mon Jul 20 07:15:58.577366 2026] [security2:error] [pid 94831:tid 94990] [client 188.87.6.213:46592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "jqq.cyv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fjo06NaEKF1g_MW2p0wAAHU8"]
[Mon Jul 20 07:15:58.610560 2026] [autoindex:error] [pid 95128:tid 95633] [client 167.86.107.171:58788] AH01276: Cannot serve directory /home3/suppouk2/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:15:58.639443 2026] [security2:error] [pid 95128:tid 95420] [remote 45.90.123.233:32816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fjueSd8WoG-6-XpDBDAACJiE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:15:58.668807 2026] [security2:error] [pid 95126:tid 95298] [client 14.225.17.146:63889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hilltopnurseryinc.com"] [uri "/index.php"] [unique_id "al4fjApx5ks9joCJTKWyYwAAAbc"], referer: http://hilltopnurseryinc.com/2020
[Mon Jul 20 07:15:58.715096 2026] [security2:error] [pid 95126:tid 95319] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fjgpx5ks9joCJTKWyiAAAAcw"]
[Mon Jul 20 07:15:58.744278 2026] [security2:error] [pid 95128:tid 95521] [client 143.44.185.218:39834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fjueSd8WoG-6-XpDBGAAAAhk"]
[Mon Jul 20 07:15:58.744381 2026] [security2:error] [pid 95128:tid 95521] [client 143.44.185.218:39834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fjueSd8WoG-6-XpDBGAAAAhk"]
[Mon Jul 20 07:15:58.767306 2026] [security2:error] [pid 95128:tid 95554] [client 34.67.218.220:63572] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "dasmarque.com"] [uri "/"] [unique_id "al4fjueSd8WoG-6-XpDBGgAAAjo"]
[Mon Jul 20 07:15:58.942082 2026] [security2:error] [pid 95126:tid 95331] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fjgpx5ks9joCJTKWyiwAAAdg"]
[Mon Jul 20 07:15:59.110208 2026] [security2:error] [pid 95128:tid 95634] [client 57.141.18.50:33288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fi-eSd8WoG-6-XpDAIgACimE"]
[Mon Jul 20 07:15:59.299705 2026] [security2:error] [pid 94831:tid 94991] [client 194.187.171.135:58093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4fj406NaEKF1g_MW2p4QAAHlo"]
[Mon Jul 20 07:15:59.358185 2026] [security2:error] [pid 95128:tid 95599] [client 77.110.127.138:60169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fj-eSd8WoG-6-XpDBKgAAAmc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:59.358303 2026] [security2:error] [pid 95128:tid 95599] [client 77.110.127.138:60169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fj-eSd8WoG-6-XpDBKgAAAmc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:15:59.379987 2026] [access_compat:error] [pid 95128:tid 95446] [remote 84.203.174.37:63167] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 07:15:59.450134 2026] [security2:error] [pid 95128:tid 95473] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fj-eSd8WoG-6-XpDBMAACdFY"]
[Mon Jul 20 07:15:59.450260 2026] [security2:error] [pid 95128:tid 95612] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fj-eSd8WoG-6-XpDBMAACdFY"]
[Mon Jul 20 07:15:59.578445 2026] [security2:error] [pid 95126:tid 95375] [client 88.241.67.160:56603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fjwpx5ks9joCJTKWyoQAAAgQ"]
[Mon Jul 20 07:15:59.578605 2026] [security2:error] [pid 95126:tid 95375] [client 88.241.67.160:56603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fjwpx5ks9joCJTKWyoQAAAgQ"]
[Mon Jul 20 07:15:59.969118 2026] [security2:error] [pid 95128:tid 95620] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fj-eSd8WoG-6-XpDBSgAAAnw"]
[Mon Jul 20 07:16:00.091079 2026] [security2:error] [pid 95128:tid 95502] [remote 34.21.244.199:32026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fkOeSd8WoG-6-XpDBVgACY3M"]
[Mon Jul 20 07:16:00.091293 2026] [security2:error] [pid 95128:tid 95595] [client 34.21.244.199:32026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fkOeSd8WoG-6-XpDBVgACY3M"]
[Mon Jul 20 07:16:00.133514 2026] [security2:error] [pid 95126:tid 95219] [remote 193.70.112.205:38206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4fkApx5ks9joCJTKWypgACClo"]
[Mon Jul 20 07:16:00.225604 2026] [security2:error] [pid 95128:tid 95618] [client 104.234.53.86:50069] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fkOeSd8WoG-6-XpDBZgAAAno"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:00.320474 2026] [security2:error] [pid 95128:tid 95637] [client 34.67.218.220:63572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4fkOeSd8WoG-6-XpDBZQAAAo0"], referer: http://dasmarque.com/wp-json/batch/v1
[Mon Jul 20 07:16:00.338533 2026] [security2:error] [pid 95126:tid 95220] [remote 193.70.112.205:38206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4fkApx5ks9joCJTKWyqAABqVs"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 07:16:00.356965 2026] [security2:error] [pid 95128:tid 95578] [client 14.225.17.146:59882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4fkOeSd8WoG-6-XpDBYQAAAlI"], referer: http://samdothan.org/2020
[Mon Jul 20 07:16:00.655122 2026] [security2:error] [pid 95128:tid 95543] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fkOeSd8WoG-6-XpDBcAAAAi8"]
[Mon Jul 20 07:16:00.721010 2026] [security2:error] [pid 95128:tid 95641] [client 144.172.114.51:49606] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/backup/.env"] [unique_id "al4fkOeSd8WoG-6-XpDBfQAAApE"]
[Mon Jul 20 07:16:01.016103 2026] [security2:error] [pid 95128:tid 95524] [client 14.225.17.146:64137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4fkOeSd8WoG-6-XpDBgAAAAhw"], referer: http://adirondackengineering.com/2020
[Mon Jul 20 07:16:01.119786 2026] [security2:error] [pid 95128:tid 95552] [client 57.141.18.22:41888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fjeeSd8WoG-6-XpDAqgACOHQ"]
[Mon Jul 20 07:16:01.165534 2026] [autoindex:error] [pid 95128:tid 95582] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/html-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:01.269951 2026] [security2:error] [pid 95128:tid 95614] [client 77.110.127.138:60323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fkeeSd8WoG-6-XpDBpwAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:01.372677 2026] [security2:error] [pid 95128:tid 95616] [client 103.176.215.66:62258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fkeeSd8WoG-6-XpDBrgAAAng"]
[Mon Jul 20 07:16:01.373007 2026] [security2:error] [pid 95128:tid 95616] [client 103.176.215.66:62258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fkeeSd8WoG-6-XpDBrgAAAng"]
[Mon Jul 20 07:16:01.576006 2026] [autoindex:error] [pid 95128:tid 95573] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/sitemaps/providers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:01.690851 2026] [security2:error] [pid 95128:tid 95591] [client 187.16.64.216:63825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fkeeSd8WoG-6-XpDBzAAAAl8"]
[Mon Jul 20 07:16:01.690997 2026] [security2:error] [pid 95128:tid 95591] [client 187.16.64.216:63825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fkeeSd8WoG-6-XpDBzAAAAl8"]
[Mon Jul 20 07:16:01.709797 2026] [security2:error] [pid 95128:tid 95554] [client 157.20.138.62:56328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fkeeSd8WoG-6-XpDBzQAAAjo"]
[Mon Jul 20 07:16:01.709968 2026] [security2:error] [pid 95128:tid 95554] [client 157.20.138.62:56328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fkeeSd8WoG-6-XpDBzQAAAjo"]
[Mon Jul 20 07:16:01.798136 2026] [security2:error] [pid 95128:tid 95519] [client 104.234.53.90:58579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fkeeSd8WoG-6-XpDB0gAAAhc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:01.979476 2026] [autoindex:error] [pid 95128:tid 95601] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Text/Diff/Engine/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:02.317339 2026] [security2:error] [pid 95126:tid 95226] [remote 57.141.18.63:46470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5979734"] [unique_id "al4fkgpx5ks9joCJTKWyyQAB82E"]
[Mon Jul 20 07:16:02.414263 2026] [autoindex:error] [pid 95128:tid 95578] [client 194.61.41.241:33789] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/coffee/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:02.468808 2026] [security2:error] [pid 95128:tid 95546] [client 14.225.17.146:64584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4fkueSd8WoG-6-XpDB5AAAAjI"], referer: http://idigress.agency/2020
[Mon Jul 20 07:16:02.607078 2026] [security2:error] [pid 95128:tid 95577] [client 54.87.255.90:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fkueSd8WoG-6-XpDB-AACUTM"]
[Mon Jul 20 07:16:02.680537 2026] [security2:error] [pid 95128:tid 95611] [client 14.225.17.146:64598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4fkueSd8WoG-6-XpDB5QAAAnM"], referer: http://idigress.group/2020
[Mon Jul 20 07:16:02.792794 2026] [autoindex:error] [pid 95128:tid 95533] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/calendar/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:02.970041 2026] [security2:error] [pid 95128:tid 95605] [client 14.225.17.146:64023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4fkueSd8WoG-6-XpDCAQAAAm0"], referer: http://mcg.homes/2020
[Mon Jul 20 07:16:03.033332 2026] [security2:error] [pid 95126:tid 95377] [client 77.110.127.138:60472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fkwpx5ks9joCJTKWy1gAAAgY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:03.185038 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:60491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fk-eSd8WoG-6-XpDCIQAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:03.185164 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:60491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fk-eSd8WoG-6-XpDCIQAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:03.273351 2026] [security2:error] [pid 95128:tid 95400] [remote 217.61.143.92:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4fk-eSd8WoG-6-XpDCKQAChw0"]
[Mon Jul 20 07:16:03.344455 2026] [security2:error] [pid 95126:tid 95301] [client 57.141.18.75:48172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fjwpx5ks9joCJTKWykwABulQ"]
[Mon Jul 20 07:16:03.419014 2026] [security2:error] [pid 95128:tid 95581] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fk-eSd8WoG-6-XpDCIAAAAlU"]
[Mon Jul 20 07:16:03.574524 2026] [security2:error] [pid 95128:tid 95501] [remote 217.61.143.92:57106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4fk-eSd8WoG-6-XpDCNwACIXI"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:16:03.590602 2026] [security2:error] [pid 95126:tid 95356] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4fkwpx5ks9joCJTKWy2gAAAfE"]
[Mon Jul 20 07:16:03.666900 2026] [security2:error] [pid 94831:tid 94862] [remote 72.167.132.114:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fk406NaEKF1g_MW2qLQAATR4"]
[Mon Jul 20 07:16:03.847289 2026] [security2:error] [pid 95128:tid 95528] [client 14.225.17.146:64008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4fkueSd8WoG-6-XpDCAAAAAiA"], referer: http://northbrookcpa.ca/2020
[Mon Jul 20 07:16:03.910869 2026] [autoindex:error] [pid 95128:tid 95578] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/themes/twentytwentyfour/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:03.914850 2026] [security2:error] [pid 94831:tid 94855] [remote 72.167.132.114:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fk406NaEKF1g_MW2qNQAACxc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:16:03.964269 2026] [security2:error] [pid 95126:tid 95353] [client 14.225.17.146:64854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4fkwpx5ks9joCJTKWy3QAAAe4"]
[Mon Jul 20 07:16:04.117718 2026] [security2:error] [pid 95128:tid 95523] [client 77.110.127.138:60570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flOeSd8WoG-6-XpDCYgAAAhs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:04.117826 2026] [security2:error] [pid 95128:tid 95523] [client 77.110.127.138:60570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flOeSd8WoG-6-XpDCYgAAAhs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:04.204824 2026] [security2:error] [pid 95128:tid 95537] [client 144.172.114.51:50634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/administrator/.env"] [unique_id "al4flOeSd8WoG-6-XpDCZgAAAik"]
[Mon Jul 20 07:16:04.441648 2026] [security2:error] [pid 94831:tid 95002] [client 154.192.123.127:18690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4flI06NaEKF1g_MW2qPQAAACk"]
[Mon Jul 20 07:16:04.441790 2026] [security2:error] [pid 94831:tid 95002] [client 154.192.123.127:18690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4flI06NaEKF1g_MW2qPQAAACk"]
[Mon Jul 20 07:16:04.471477 2026] [security2:error] [pid 95128:tid 95518] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4flOeSd8WoG-6-XpDCbwAAAhY"]
[Mon Jul 20 07:16:04.712298 2026] [security2:error] [pid 94831:tid 95058] [client 77.110.127.138:60617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flI06NaEKF1g_MW2qRAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:04.712402 2026] [security2:error] [pid 94831:tid 95058] [client 77.110.127.138:60617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flI06NaEKF1g_MW2qRAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:04.816227 2026] [security2:error] [pid 95128:tid 95395] [remote 100.42.189.89:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4flOeSd8WoG-6-XpDChgACggg"]
[Mon Jul 20 07:16:04.821725 2026] [security2:error] [pid 95126:tid 95323] [client 14.225.17.146:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4fkwpx5ks9joCJTKWy2QAAAdA"], referer: http://alexsandbergmusic.com/2020
[Mon Jul 20 07:16:04.866903 2026] [security2:error] [pid 95128:tid 95525] [client 77.110.127.138:60622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flOeSd8WoG-6-XpDCjQAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:04.867003 2026] [security2:error] [pid 95128:tid 95525] [client 77.110.127.138:60622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flOeSd8WoG-6-XpDCjQAAAh0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.034993 2026] [autoindex:error] [pid 95128:tid 95540] [client 194.233.85.87:58717] AH01276: Cannot serve directory /home1/tgdhcnmy/public_html/mcg/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:16:05.072074 2026] [security2:error] [pid 95128:tid 95420] [remote 100.42.189.89:43482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4fleeSd8WoG-6-XpDCngACSiE"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 07:16:05.209355 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:60637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flQpx5ks9joCJTKWy-gAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.209457 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:60637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flQpx5ks9joCJTKWy-gAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.266222 2026] [security2:error] [pid 95128:tid 95516] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fleeSd8WoG-6-XpDCnwAAAhQ"]
[Mon Jul 20 07:16:05.278476 2026] [security2:error] [pid 95128:tid 95569] [client 14.225.17.146:65495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fleeSd8WoG-6-XpDCoQAAAkk"], referer: http://mezzacraft.com/2020
[Mon Jul 20 07:16:05.360151 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:60643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flQpx5ks9joCJTKWzAQAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.360244 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:60643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4flQpx5ks9joCJTKWzAQAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.469209 2026] [security2:error] [pid 95128:tid 95568] [client 144.172.114.51:50644] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/cms/.env"] [unique_id "al4fleeSd8WoG-6-XpDCswAAAkg"]
[Mon Jul 20 07:16:05.503687 2026] [security2:error] [pid 95128:tid 95542] [client 14.225.17.146:64971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4flOeSd8WoG-6-XpDCYAAAAi4"], referer: http://dnsplumbing.com/2020
[Mon Jul 20 07:16:05.548349 2026] [security2:error] [pid 95126:tid 95357] [client 57.141.18.12:63746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fkQpx5ks9joCJTKWysQAB8lg"]
[Mon Jul 20 07:16:05.618482 2026] [security2:error] [pid 95128:tid 95524] [client 77.110.127.138:60654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fleeSd8WoG-6-XpDCugAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.618573 2026] [security2:error] [pid 95128:tid 95524] [client 77.110.127.138:60654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fleeSd8WoG-6-XpDCugAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:05.629642 2026] [security2:error] [pid 95126:tid 95258] [client 154.208.48.130:62062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4flQpx5ks9joCJTKWzBwAAAY8"]
[Mon Jul 20 07:16:05.630359 2026] [security2:error] [pid 95126:tid 95258] [client 154.208.48.130:62062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4flQpx5ks9joCJTKWzBwAAAY8"]
[Mon Jul 20 07:16:05.656663 2026] [security2:error] [pid 94831:tid 95081] [client 104.234.53.65:25139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4flY06NaEKF1g_MW2qVgAAAHg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:05.821738 2026] [security2:error] [pid 95128:tid 95613] [client 77.110.127.138:60660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fleeSd8WoG-6-XpDCxQAAAnU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:06.107659 2026] [security2:error] [pid 95126:tid 95289] [client 49.37.242.14:62900] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4flgpx5ks9joCJTKWzDAAAAa4"]
[Mon Jul 20 07:16:06.107835 2026] [security2:error] [pid 95126:tid 95289] [client 49.37.242.14:62900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4flgpx5ks9joCJTKWzDAAAAa4"]
[Mon Jul 20 07:16:06.118183 2026] [security2:error] [pid 95128:tid 95410] [remote 100.42.189.89:51502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4flueSd8WoG-6-XpDC2AACcRc"]
[Mon Jul 20 07:16:06.131561 2026] [security2:error] [pid 95128:tid 95533] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fleeSd8WoG-6-XpDC0AAAAiU"]
[Mon Jul 20 07:16:06.238785 2026] [security2:error] [pid 95128:tid 95557] [client 144.172.114.51:50652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/portal/.env"] [unique_id "al4flueSd8WoG-6-XpDC2wAAAj0"]
[Mon Jul 20 07:16:06.326532 2026] [security2:error] [pid 95128:tid 95555] [client 50.116.65.227:36700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4flueSd8WoG-6-XpDC3wAAAjs"]
[Mon Jul 20 07:16:06.336078 2026] [security2:error] [pid 95128:tid 95632] [client 50.116.65.227:36712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4flueSd8WoG-6-XpDC4AAAAog"]
[Mon Jul 20 07:16:06.362705 2026] [security2:error] [pid 95126:tid 95322] [client 158.173.166.181:43209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4flgpx5ks9joCJTKWzFgAAAc8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:16:06.402404 2026] [security2:error] [pid 95128:tid 95473] [remote 100.42.189.89:51502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4flueSd8WoG-6-XpDC5gACSFY"], referer: https://zbj.ahr.mybluehost.me/wp-login.php
[Mon Jul 20 07:16:06.560092 2026] [security2:error] [pid 95126:tid 95354] [client 52.140.101.203:6024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4flgpx5ks9joCJTKWzHAAAAe8"]
[Mon Jul 20 07:16:06.771474 2026] [security2:error] [pid 95128:tid 95583] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4flueSd8WoG-6-XpDC9AAAAlc"]
[Mon Jul 20 07:16:06.789955 2026] [security2:error] [pid 95126:tid 95329] [client 52.140.101.203:6024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4flgpx5ks9joCJTKWzIgAAAdY"]
[Mon Jul 20 07:16:06.893141 2026] [security2:error] [pid 95128:tid 95504] [remote 195.191.25.51:9794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.191.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4flueSd8WoG-6-XpDC-QACZXU"]
[Mon Jul 20 07:16:06.953555 2026] [security2:error] [pid 94831:tid 95044] [client 104.234.53.91:24489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4flo06NaEKF1g_MW2qdQAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:06.972768 2026] [security2:error] [pid 95128:tid 95428] [remote 41.186.86.12:2179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4flueSd8WoG-6-XpDC_gACNSk"]
[Mon Jul 20 07:16:07.146482 2026] [security2:error] [pid 95128:tid 95517] [client 14.225.17.146:49302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4fleeSd8WoG-6-XpDCuQAAAhU"], referer: http://cephasnext.com/2020
[Mon Jul 20 07:16:07.170657 2026] [security2:error] [pid 95128:tid 95472] [remote 195.191.25.51:9794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.25.191.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4fl-eSd8WoG-6-XpDDCAACX1U"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:16:07.225017 2026] [security2:error] [pid 95128:tid 95610] [client 57.141.18.2:37024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fk-eSd8WoG-6-XpDCJwACcjc"]
[Mon Jul 20 07:16:07.281641 2026] [autoindex:error] [pid 95126:tid 95302] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:07.477412 2026] [security2:error] [pid 95128:tid 95435] [remote 41.186.86.12:2179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fl-eSd8WoG-6-XpDDIAACHDA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:16:07.511664 2026] [security2:error] [pid 95126:tid 95252] [remote 154.66.198.148:35878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4flwpx5ks9joCJTKWzNgACDXs"]
[Mon Jul 20 07:16:07.559389 2026] [security2:error] [pid 95128:tid 95638] [client 77.110.127.138:60703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fl-eSd8WoG-6-XpDDIgAAAo4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:07.651094 2026] [security2:error] [pid 95128:tid 95554] [client 201.27.111.74:65167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fl-eSd8WoG-6-XpDDJAAAAjo"]
[Mon Jul 20 07:16:07.651238 2026] [security2:error] [pid 95128:tid 95554] [client 201.27.111.74:65167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fl-eSd8WoG-6-XpDDJAAAAjo"]
[Mon Jul 20 07:16:07.678228 2026] [autoindex:error] [pid 95128:tid 95633] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/sitemaps/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:07.703969 2026] [security2:error] [pid 95128:tid 95566] [client 51.143.183.75:11120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fl-eSd8WoG-6-XpDDKQAAAkY"]
[Mon Jul 20 07:16:07.791018 2026] [security2:error] [pid 95126:tid 95298] [client 14.225.17.146:50125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4flwpx5ks9joCJTKWzNwAAAbc"], referer: http://talknutritionwithlesley.com/2020
[Mon Jul 20 07:16:07.837986 2026] [security2:error] [pid 95128:tid 95563] [client 51.143.183.75:11120] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fl-eSd8WoG-6-XpDDMgAAAkM"]
[Mon Jul 20 07:16:07.966742 2026] [security2:error] [pid 95128:tid 95520] [client 14.225.17.146:49440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4fleeSd8WoG-6-XpDC0gAAAhg"], referer: http://dollpassionista.com/2020
[Mon Jul 20 07:16:07.982048 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:60708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4flwpx5ks9joCJTKWzOQAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:08.046168 2026] [security2:error] [pid 95126:tid 95255] [remote 154.66.198.148:35878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fmApx5ks9joCJTKWzQgABkn4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:16:08.078767 2026] [autoindex:error] [pid 95128:tid 95535] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:08.242166 2026] [security2:error] [pid 95128:tid 95588] [client 103.144.65.217:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fmOeSd8WoG-6-XpDDTAAAAlw"]
[Mon Jul 20 07:16:08.242820 2026] [security2:error] [pid 95128:tid 95588] [client 103.144.65.217:63790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fmOeSd8WoG-6-XpDDTAAAAlw"]
[Mon Jul 20 07:16:08.368367 2026] [security2:error] [pid 95126:tid 95343] [client 57.141.18.107:44576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4flApx5ks9joCJTKWy7AAB5Gw"]
[Mon Jul 20 07:16:08.370895 2026] [security2:error] [pid 95128:tid 95617] [client 57.141.18.59:47800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4flOeSd8WoG-6-XpDCegACeV4"]
[Mon Jul 20 07:16:08.451613 2026] [security2:error] [pid 94831:tid 95045] [client 77.110.127.138:60722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fmI06NaEKF1g_MW2qkwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:08.474094 2026] [security2:error] [pid 95128:tid 95574] [client 14.225.17.146:49830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4flueSd8WoG-6-XpDC9wAAAk4"], referer: http://ironcitywellness.com/2020
[Mon Jul 20 07:16:08.503103 2026] [autoindex:error] [pid 95126:tid 95309] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:08.538240 2026] [security2:error] [pid 95128:tid 95453] [remote 95.217.78.234:35514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4fmOeSd8WoG-6-XpDDWgACWEI"]
[Mon Jul 20 07:16:08.717172 2026] [security2:error] [pid 95128:tid 95641] [client 117.211.236.168:53805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fmOeSd8WoG-6-XpDDYgAAApE"]
[Mon Jul 20 07:16:08.717285 2026] [security2:error] [pid 95128:tid 95641] [client 117.211.236.168:53805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fmOeSd8WoG-6-XpDDYgAAApE"]
[Mon Jul 20 07:16:08.788325 2026] [security2:error] [pid 95128:tid 95468] [remote 95.217.78.234:35514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4fmOeSd8WoG-6-XpDDZAACQ1E"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 07:16:08.895833 2026] [autoindex:error] [pid 95128:tid 95532] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/sodium_compat/src/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:08.932599 2026] [security2:error] [pid 95128:tid 95605] [client 13.232.231.177:14592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fmOeSd8WoG-6-XpDDbQAAAm0"]
[Mon Jul 20 07:16:08.932844 2026] [security2:error] [pid 95128:tid 95605] [client 13.232.231.177:14592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fmOeSd8WoG-6-XpDDbQAAAm0"]
[Mon Jul 20 07:16:09.010499 2026] [security2:error] [pid 95128:tid 95620] [client 14.225.17.146:50711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4fmOeSd8WoG-6-XpDDZQAAAnw"], referer: https://dollpassionista.com/2020
[Mon Jul 20 07:16:09.026425 2026] [security2:error] [pid 95126:tid 95306] [client 77.110.127.138:60738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fmApx5ks9joCJTKWzTgAAAb8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:09.139812 2026] [security2:error] [pid 95126:tid 95135] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fmQpx5ks9joCJTKWzVwABugY"]
[Mon Jul 20 07:16:09.140015 2026] [security2:error] [pid 95126:tid 95301] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fmQpx5ks9joCJTKWzVwABugY"]
[Mon Jul 20 07:16:09.258071 2026] [security2:error] [pid 95128:tid 95639] [client 77.110.127.138:60752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fmeeSd8WoG-6-XpDDfwAAAo8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:09.258222 2026] [security2:error] [pid 95128:tid 95639] [client 77.110.127.138:60752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fmeeSd8WoG-6-XpDDfwAAAo8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:09.346430 2026] [security2:error] [pid 95126:tid 95379] [client 104.234.53.64:39227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fmQpx5ks9joCJTKWzWQAAAgg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:09.410625 2026] [security2:error] [pid 95128:tid 95634] [client 143.44.185.218:41144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fmeeSd8WoG-6-XpDDjAAAAoo"]
[Mon Jul 20 07:16:09.410726 2026] [security2:error] [pid 95128:tid 95634] [client 143.44.185.218:41144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fmeeSd8WoG-6-XpDDjAAAAoo"]
[Mon Jul 20 07:16:09.469802 2026] [security2:error] [pid 95128:tid 95557] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fmeeSd8WoG-6-XpDDggAAAj0"]
[Mon Jul 20 07:16:09.513475 2026] [security2:error] [pid 95128:tid 95575] [client 77.110.127.138:60754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fmeeSd8WoG-6-XpDDgwAAAk8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:09.917918 2026] [security2:error] [pid 94831:tid 94905] [remote 182.77.62.24:47004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fmY06NaEKF1g_MW2qrgAAZ0k"]
[Mon Jul 20 07:16:10.049906 2026] [security2:error] [pid 95126:tid 95283] [client 77.110.127.138:60772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fmQpx5ks9joCJTKWzYAAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:10.055629 2026] [security2:error] [pid 94831:tid 95015] [client 77.110.127.138:60780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fmo06NaEKF1g_MW2qswAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:10.078898 2026] [security2:error] [pid 95128:tid 95476] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fmueSd8WoG-6-XpDDqgACRVk"]
[Mon Jul 20 07:16:10.079064 2026] [security2:error] [pid 95128:tid 95565] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fmueSd8WoG-6-XpDDqgACRVk"]
[Mon Jul 20 07:16:10.288325 2026] [security2:error] [pid 95128:tid 95615] [client 88.241.67.160:54031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fmueSd8WoG-6-XpDDsgAAAnc"]
[Mon Jul 20 07:16:10.288483 2026] [security2:error] [pid 95128:tid 95615] [client 88.241.67.160:54031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fmueSd8WoG-6-XpDDsgAAAnc"]
[Mon Jul 20 07:16:10.379766 2026] [security2:error] [pid 95126:tid 95352] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fmgpx5ks9joCJTKWzawAAAe0"]
[Mon Jul 20 07:16:10.433835 2026] [security2:error] [pid 94831:tid 94841] [remote 182.77.62.24:47004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fmo06NaEKF1g_MW2quwAAAwk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:16:10.490576 2026] [security2:error] [pid 95128:tid 95516] [client 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4fmueSd8WoG-6-XpDDuwAAAhQ"]
[Mon Jul 20 07:16:10.588674 2026] [security2:error] [pid 95128:tid 95618] [client 77.110.127.138:60791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fmueSd8WoG-6-XpDDtwAAAno"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:10.739079 2026] [security2:error] [pid 95128:tid 95631] [client 173.212.252.15:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4fmueSd8WoG-6-XpDDxAAAAoc"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 07:16:11.061948 2026] [security2:error] [pid 94831:tid 94848] [remote 199.189.225.40:44449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fm406NaEKF1g_MW2qzgAAdxA"]
[Mon Jul 20 07:16:11.111093 2026] [security2:error] [pid 94831:tid 95068] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fmo06NaEKF1g_MW2qyAAAAGs"]
[Mon Jul 20 07:16:11.171448 2026] [security2:error] [pid 95126:tid 95145] [remote 8.217.108.67:41462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fmwpx5ks9joCJTKWzgAABshA"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:16:11.231439 2026] [security2:error] [pid 95128:tid 95597] [client 50.116.65.227:32170] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "longevityperformanceclinic.com"] [uri "/wp-cron.php"] [unique_id "al4fm-eSd8WoG-6-XpDD1QAAAmU"]
[Mon Jul 20 07:16:11.235444 2026] [security2:error] [pid 95128:tid 95561] [client 14.225.17.146:63870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4fmeeSd8WoG-6-XpDDiQAAAkE"], referer: http://longevityperformanceclinic.com/2020
[Mon Jul 20 07:16:11.271024 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:60807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fmo06NaEKF1g_MW2qywAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:11.312942 2026] [security2:error] [pid 95128:tid 95579] [client 14.225.17.146:64164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4fmeeSd8WoG-6-XpDDpQAAAlM"], referer: http://elitetax-mi.com/2020
[Mon Jul 20 07:16:11.362446 2026] [security2:error] [pid 94831:tid 95055] [client 14.225.17.146:64008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4fmY06NaEKF1g_MW2qqwAAAF4"], referer: http://lelandumc.org/2020
[Mon Jul 20 07:16:11.367238 2026] [security2:error] [pid 95126:tid 95343] [client 104.234.53.68:38883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fmwpx5ks9joCJTKWzgQAAAeQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:11.460046 2026] [security2:error] [pid 95128:tid 95642] [client 57.141.18.101:59912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fl-eSd8WoG-6-XpDDLwACkjE"]
[Mon Jul 20 07:16:11.552680 2026] [security2:error] [pid 94831:tid 94849] [remote 199.189.225.40:44449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fm406NaEKF1g_MW2q2QAAZhE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:16:11.784546 2026] [security2:error] [pid 94831:tid 95012] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fm406NaEKF1g_MW2q2wAAADM"]
[Mon Jul 20 07:16:11.919217 2026] [security2:error] [pid 95128:tid 95583] [client 103.176.215.66:62785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fm-eSd8WoG-6-XpDEAwAAAlc"]
[Mon Jul 20 07:16:11.920016 2026] [security2:error] [pid 95128:tid 95583] [client 103.176.215.66:62785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fm-eSd8WoG-6-XpDEAwAAAlc"]
[Mon Jul 20 07:16:11.965414 2026] [security2:error] [pid 95126:tid 95336] [client 57.141.18.106:27474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fmApx5ks9joCJTKWzRAAB3XE"]
[Mon Jul 20 07:16:12.233136 2026] [security2:error] [pid 94831:tid 94962] [client 187.16.64.216:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fnI06NaEKF1g_MW2q6QAAAAE"]
[Mon Jul 20 07:16:12.233256 2026] [security2:error] [pid 94831:tid 94962] [client 187.16.64.216:64388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fnI06NaEKF1g_MW2q6QAAAAE"]
[Mon Jul 20 07:16:12.266727 2026] [security2:error] [pid 95128:tid 95439] [remote 57.141.18.16:62080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6073798"] [unique_id "al4fnOeSd8WoG-6-XpDEEQACPzQ"]
[Mon Jul 20 07:16:12.304358 2026] [autoindex:error] [pid 95128:tid 95565] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/plugins/fullscreen/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:12.349125 2026] [security2:error] [pid 95128:tid 95566] [client 157.20.138.62:56890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fnOeSd8WoG-6-XpDEGQAAAkY"]
[Mon Jul 20 07:16:12.349287 2026] [security2:error] [pid 95128:tid 95566] [client 157.20.138.62:56890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fnOeSd8WoG-6-XpDEGQAAAkY"]
[Mon Jul 20 07:16:12.360485 2026] [security2:error] [pid 95128:tid 95591] [client 77.110.127.138:60707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fnOeSd8WoG-6-XpDECwAAAl8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:12.534064 2026] [security2:error] [pid 94831:tid 94978] [client 57.141.18.2:37038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fmI06NaEKF1g_MW2qngAAEXA"]
[Mon Jul 20 07:16:12.557773 2026] [security2:error] [pid 95126:tid 95360] [client 14.225.17.146:64209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4fmwpx5ks9joCJTKWzfwAAAfU"], referer: http://slutilities.com/2020
[Mon Jul 20 07:16:12.558208 2026] [security2:error] [pid 95128:tid 95404] [remote 209.42.18.223:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fnOeSd8WoG-6-XpDEJQACRBE"]
[Mon Jul 20 07:16:12.669058 2026] [security2:error] [pid 95128:tid 95634] [client 104.234.53.85:43749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fnOeSd8WoG-6-XpDEKgAAAoo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:12.694460 2026] [autoindex:error] [pid 95126:tid 95341] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/languages/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:12.718706 2026] [security2:error] [pid 95126:tid 95354] [client 18.209.178.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4fnApx5ks9joCJTKWzkgAB7xo"]
[Mon Jul 20 07:16:12.733149 2026] [security2:error] [pid 95128:tid 95494] [remote 209.42.18.223:37240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4fnOeSd8WoG-6-XpDELgACHms"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:16:13.179016 2026] [security2:error] [pid 95128:tid 95543] [client 14.225.17.146:65038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4fm-eSd8WoG-6-XpDD_QAAAi8"], referer: http://alchemygroup.ca/2020
[Mon Jul 20 07:16:13.183423 2026] [security2:error] [pid 95128:tid 95541] [client 57.141.18.85:33058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fmeeSd8WoG-6-XpDDlgACLX8"]
[Mon Jul 20 07:16:13.261185 2026] [security2:error] [pid 94831:tid 95086] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fnY06NaEKF1g_MW2q_gAAAH0"]
[Mon Jul 20 07:16:13.876604 2026] [autoindex:error] [pid 95128:tid 95557] [client 94.154.43.187:41504] AH01276: Cannot serve directory /home2/oldracel/list.learnthissecret.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:13.950992 2026] [security2:error] [pid 95126:tid 95339] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fnQpx5ks9joCJTKWzpQAAAeA"]
[Mon Jul 20 07:16:14.048373 2026] [security2:error] [pid 95128:tid 95615] [client 14.225.17.146:53885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4fneeSd8WoG-6-XpDEVAAAAnc"]
[Mon Jul 20 07:16:14.416670 2026] [security2:error] [pid 94831:tid 95026] [client 98.159.234.160:55155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fno06NaEKF1g_MW2rHAAAAEE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:16:14.466307 2026] [autoindex:error] [pid 95128:tid 95591] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/interactivity-api/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:14.559023 2026] [security2:error] [pid 95128:tid 95396] [remote 45.84.107.182:54663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fnueSd8WoG-6-XpDEigACkAk"], referer: https://verdunestate.com/
[Mon Jul 20 07:16:14.681582 2026] [security2:error] [pid 94831:tid 94907] [remote 173.249.4.11:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fno06NaEKF1g_MW2rIgAAd0s"]
[Mon Jul 20 07:16:14.702505 2026] [security2:error] [pid 95128:tid 95619] [client 57.141.18.48:53436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fm-eSd8WoG-6-XpDD0wACe1c"]
[Mon Jul 20 07:16:14.876072 2026] [autoindex:error] [pid 95128:tid 95624] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:14.876373 2026] [security2:error] [pid 94831:tid 94906] [remote 173.249.4.11:49947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fno06NaEKF1g_MW2rJQAAXko"], referer: https://maa.hws.mybluehost.me/wp-login.php
[Mon Jul 20 07:16:14.902336 2026] [security2:error] [pid 95128:tid 95571] [client 57.141.18.55:40492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fm-eSd8WoG-6-XpDD7gACSy0"]
[Mon Jul 20 07:16:15.012100 2026] [security2:error] [pid 95126:tid 95320] [client 154.192.123.127:17077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fnwpx5ks9joCJTKWztQAAAc0"]
[Mon Jul 20 07:16:15.012254 2026] [security2:error] [pid 95126:tid 95320] [client 154.192.123.127:17077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fnwpx5ks9joCJTKWztQAAAc0"]
[Mon Jul 20 07:16:15.323110 2026] [security2:error] [pid 95128:tid 95513] [remote 217.61.143.92:45482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4fn-eSd8WoG-6-XpDEqgACLH4"]
[Mon Jul 20 07:16:15.360262 2026] [security2:error] [pid 95128:tid 95417] [remote 95.217.78.234:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4fn-eSd8WoG-6-XpDEqwACWx4"]
[Mon Jul 20 07:16:15.468172 2026] [security2:error] [pid 95126:tid 95321] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fnwpx5ks9joCJTKWzvgAAAc4"]
[Mon Jul 20 07:16:15.557703 2026] [security2:error] [pid 95128:tid 95473] [remote 217.61.143.92:45482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4fn-eSd8WoG-6-XpDErwACRVY"], referer: https://pscmedicalbilling.com/wp-login.php
[Mon Jul 20 07:16:15.608342 2026] [security2:error] [pid 95128:tid 95470] [remote 45.84.107.182:54663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fn-eSd8WoG-6-XpDEsgACQ1M"], referer: https://verdunestate.com/
[Mon Jul 20 07:16:15.610962 2026] [security2:error] [pid 95128:tid 95418] [remote 95.217.78.234:35530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.78.217.95.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4fn-eSd8WoG-6-XpDEtAACUB8"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 07:16:15.904288 2026] [security2:error] [pid 95126:tid 95179] [remote 47.128.54.76:38340] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "recruitinginsight.us"] [uri "/2022/03/01/how-to-interview-an-entrepreneur/"] [unique_id "al4fnwpx5ks9joCJTKWz2QAB1DI"]
[Mon Jul 20 07:16:15.989992 2026] [autoindex:error] [pid 95126:tid 95279] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/utils/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:15.999106 2026] [security2:error] [pid 95128:tid 95584] [client 57.141.18.107:55020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fnOeSd8WoG-6-XpDELAACWDo"]
[Mon Jul 20 07:16:16.014736 2026] [security2:error] [pid 95128:tid 95626] [client 52.167.144.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4fn-eSd8WoG-6-XpDEwwAAAoI"]
[Mon Jul 20 07:16:16.040041 2026] [security2:error] [pid 95128:tid 95559] [client 91.73.64.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4fneeSd8WoG-6-XpDERgAAAj8"]
[Mon Jul 20 07:16:16.144074 2026] [security2:error] [pid 95128:tid 95598] [client 14.225.17.146:56197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4fnueSd8WoG-6-XpDEkAAAAmY"], referer: http://eframiproperties.com/2020
[Mon Jul 20 07:16:16.247420 2026] [security2:error] [pid 95126:tid 95276] [client 77.110.127.138:60923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4foApx5ks9joCJTKWz3gAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:16.247515 2026] [security2:error] [pid 95126:tid 95276] [client 77.110.127.138:60923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4foApx5ks9joCJTKWz3gAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:16.396675 2026] [security2:error] [pid 94831:tid 95060] [client 77.110.127.138:60927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4foI06NaEKF1g_MW2rQAAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:16.518520 2026] [security2:error] [pid 95128:tid 95635] [client 77.110.127.138:60892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4foOeSd8WoG-6-XpDE0QAAAos"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:16.545407 2026] [security2:error] [pid 95126:tid 95348] [client 154.208.48.130:62584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4foApx5ks9joCJTKWz5AAAAek"]
[Mon Jul 20 07:16:16.545503 2026] [security2:error] [pid 95126:tid 95348] [client 154.208.48.130:62584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4foApx5ks9joCJTKWz5AAAAek"]
[Mon Jul 20 07:16:16.546588 2026] [security2:error] [pid 95128:tid 95636] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4foOeSd8WoG-6-XpDE1wAAAow"]
[Mon Jul 20 07:16:16.641363 2026] [security2:error] [pid 95128:tid 95543] [client 14.225.17.146:54284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4fn-eSd8WoG-6-XpDEsQAAAi8"], referer: http://travelbyfire.com/2020
[Mon Jul 20 07:16:16.746517 2026] [security2:error] [pid 94831:tid 94977] [client 104.234.53.59:26565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4foI06NaEKF1g_MW2rRgAAABA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:16.830527 2026] [security2:error] [pid 94831:tid 94978] [client 49.51.52.250:59102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.52.51.49.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/kwmenus/index.php"] [unique_id "al4foI06NaEKF1g_MW2rSQAAABE"]
[Mon Jul 20 07:16:16.934528 2026] [security2:error] [pid 94831:tid 95058] [client 104.234.53.59:26565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4foI06NaEKF1g_MW2rSwAAAGE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:17.188119 2026] [security2:error] [pid 95128:tid 95613] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4foOeSd8WoG-6-XpDFAgAAAnU"]
[Mon Jul 20 07:16:17.223035 2026] [security2:error] [pid 95128:tid 95588] [client 49.37.242.14:63347] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4foeeSd8WoG-6-XpDFEgAAAlw"]
[Mon Jul 20 07:16:17.223154 2026] [security2:error] [pid 95128:tid 95588] [client 49.37.242.14:63347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4foeeSd8WoG-6-XpDFEgAAAlw"]
[Mon Jul 20 07:16:17.271391 2026] [security2:error] [pid 94831:tid 95027] [client 57.141.18.101:25612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fnY06NaEKF1g_MW2rFAAAQjw"]
[Mon Jul 20 07:16:17.523222 2026] [security2:error] [pid 95128:tid 95576] [client 14.225.17.146:55395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4foeeSd8WoG-6-XpDFIgAAAlA"], referer: https://travelbyfire.com/2020
[Mon Jul 20 07:16:17.620456 2026] [security2:error] [pid 94831:tid 94997] [client 14.225.17.146:55433] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4foY06NaEKF1g_MW2rWAAAACQ"], referer: http://betterbonddogtraining.com/2020
[Mon Jul 20 07:16:17.686052 2026] [security2:error] [pid 95128:tid 95503] [remote 152.228.213.32:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4foeeSd8WoG-6-XpDFLgACIHQ"]
[Mon Jul 20 07:16:17.822633 2026] [security2:error] [pid 95128:tid 95582] [client 14.225.17.146:53907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4foeeSd8WoG-6-XpDFLwAAAlY"], referer: http://keywayconstructionclt.com/2020
[Mon Jul 20 07:16:17.847283 2026] [security2:error] [pid 95126:tid 95293] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4foQpx5ks9joCJTKWz9AAAAbI"]
[Mon Jul 20 07:16:17.880704 2026] [security2:error] [pid 95128:tid 95431] [remote 152.228.213.32:54438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4foeeSd8WoG-6-XpDFMgACQCw"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:16:17.989616 2026] [security2:error] [pid 95128:tid 95526] [client 201.27.111.74:49564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4foeeSd8WoG-6-XpDFPAAAAh4"]
[Mon Jul 20 07:16:17.989726 2026] [security2:error] [pid 95128:tid 95526] [client 201.27.111.74:49564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4foeeSd8WoG-6-XpDFPAAAAh4"]
[Mon Jul 20 07:16:18.365873 2026] [security2:error] [pid 95126:tid 95341] [client 117.211.236.168:54404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fogpx5ks9joCJTKW0AAAAAeI"]
[Mon Jul 20 07:16:18.365987 2026] [security2:error] [pid 95126:tid 95341] [client 117.211.236.168:54404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fogpx5ks9joCJTKW0AAAAAeI"]
[Mon Jul 20 07:16:18.482740 2026] [security2:error] [pid 95128:tid 95468] [remote 57.141.18.59:24286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6113361"] [unique_id "al4foueSd8WoG-6-XpDFWAACUlE"]
[Mon Jul 20 07:16:18.641154 2026] [core:error] [pid 94831:tid 94989] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:18.641183 2026] [core:error] [pid 94831:tid 94989] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:18.660227 2026] [security2:error] [pid 95128:tid 95546] [client 50.116.65.227:32280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4foueSd8WoG-6-XpDFZQAAAjI"]
[Mon Jul 20 07:16:18.662607 2026] [security2:error] [pid 95128:tid 95562] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4foueSd8WoG-6-XpDFWQAAAkI"]
[Mon Jul 20 07:16:18.670400 2026] [security2:error] [pid 95128:tid 95530] [client 50.116.65.227:32288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4foueSd8WoG-6-XpDFZgAAAiI"]
[Mon Jul 20 07:16:18.725338 2026] [security2:error] [pid 95126:tid 95316] [client 14.225.17.146:54455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4fogpx5ks9joCJTKW0BQAAAck"], referer: https://keywayconstructionclt.com/2020
[Mon Jul 20 07:16:18.735084 2026] [security2:error] [pid 94831:tid 94994] [client 77.110.127.138:61002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4foo06NaEKF1g_MW2rbAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:18.775054 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:61009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4foueSd8WoG-6-XpDFawAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:18.775170 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:61009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4foueSd8WoG-6-XpDFawAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:18.835012 2026] [security2:error] [pid 95126:tid 95278] [client 103.144.65.217:64245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fogpx5ks9joCJTKW0CgAAAaM"]
[Mon Jul 20 07:16:18.835107 2026] [security2:error] [pid 95126:tid 95278] [client 103.144.65.217:64245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fogpx5ks9joCJTKW0CgAAAaM"]
[Mon Jul 20 07:16:18.858189 2026] [security2:error] [pid 95128:tid 95463] [remote 154.66.198.148:46210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4foueSd8WoG-6-XpDFcAACLkw"]
[Mon Jul 20 07:16:18.858300 2026] [security2:error] [pid 95128:tid 95542] [client 154.66.198.148:46210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4foueSd8WoG-6-XpDFcAACLkw"]
[Mon Jul 20 07:16:18.927431 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:61020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fogpx5ks9joCJTKW0DgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:18.960770 2026] [security2:error] [pid 94831:tid 95026] [client 14.225.17.146:53768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4foo06NaEKF1g_MW2rdwAAAEE"], referer: http://walkingandtalking.net/2020
[Mon Jul 20 07:16:19.118252 2026] [security2:error] [pid 94831:tid 95018] [client 57.141.18.4:40848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fn406NaEKF1g_MW2rOQAAOWM"]
[Mon Jul 20 07:16:19.362356 2026] [security2:error] [pid 95128:tid 95604] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fo-eSd8WoG-6-XpDFigAAAmw"]
[Mon Jul 20 07:16:19.442012 2026] [security2:error] [pid 95128:tid 95622] [client 144.172.114.51:49344] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/mailer/.env"] [unique_id "al4fo-eSd8WoG-6-XpDFkwAAAn4"]
[Mon Jul 20 07:16:19.546448 2026] [security2:error] [pid 95128:tid 95632] [client 14.225.17.146:56137] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4foueSd8WoG-6-XpDFYQAAAog"]
[Mon Jul 20 07:16:19.671055 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:61036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fo406NaEKF1g_MW2rfwAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:19.754337 2026] [security2:error] [pid 95128:tid 95620] [client 14.225.17.146:56910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4foueSd8WoG-6-XpDFZAAAAnw"], referer: http://getgarrison.com/2020
[Mon Jul 20 07:16:19.811118 2026] [security2:error] [pid 95128:tid 95426] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fo-eSd8WoG-6-XpDFrAACPCc"]
[Mon Jul 20 07:16:19.811346 2026] [security2:error] [pid 95128:tid 95556] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fo-eSd8WoG-6-XpDFrAACPCc"]
[Mon Jul 20 07:16:19.831533 2026] [security2:error] [pid 95128:tid 95616] [client 14.225.17.146:56262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4fo-eSd8WoG-6-XpDFqwAAAng"], referer: https://walkingandtalking.net/2020
[Mon Jul 20 07:16:19.979957 2026] [autoindex:error] [pid 95126:tid 95326] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/codemirror/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:20.193046 2026] [security2:error] [pid 95126:tid 95330] [client 143.44.185.218:42462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fpApx5ks9joCJTKW0IwAAAdc"]
[Mon Jul 20 07:16:20.193192 2026] [security2:error] [pid 95126:tid 95330] [client 143.44.185.218:42462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fpApx5ks9joCJTKW0IwAAAdc"]
[Mon Jul 20 07:16:20.220546 2026] [security2:error] [pid 95126:tid 95297] [client 104.234.53.84:20415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fpApx5ks9joCJTKW0JAAAAbY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:20.344876 2026] [security2:error] [pid 95128:tid 95592] [client 57.141.18.61:43844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4foeeSd8WoG-6-XpDFDQACYB0"]
[Mon Jul 20 07:16:20.395239 2026] [autoindex:error] [pid 95128:tid 95617] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/langs/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:20.424672 2026] [security2:error] [pid 95126:tid 95284] [client 14.225.17.146:53769] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4fogpx5ks9joCJTKW0DwAAAak"], referer: http://709fx.com/2020
[Mon Jul 20 07:16:20.493565 2026] [security2:error] [pid 95128:tid 95538] [client 77.110.127.138:60924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fpOeSd8WoG-6-XpDFyAAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:20.666834 2026] [security2:error] [pid 95128:tid 95636] [client 14.225.17.146:54407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4fpOeSd8WoG-6-XpDFwwAAAow"], referer: http://bruceledewitz.com/2020
[Mon Jul 20 07:16:20.714333 2026] [security2:error] [pid 95128:tid 95568] [client 77.110.127.138:61071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fpOeSd8WoG-6-XpDF3QAAAkg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:20.714413 2026] [security2:error] [pid 95128:tid 95568] [client 77.110.127.138:61071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fpOeSd8WoG-6-XpDF3QAAAkg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:20.802380 2026] [autoindex:error] [pid 95128:tid 95528] [client 194.61.41.241:33789] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:20.862151 2026] [security2:error] [pid 95128:tid 95584] [client 216.121.255.198:42548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "jqq.cyv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fpOeSd8WoG-6-XpDF3gACWHA"]
[Mon Jul 20 07:16:20.866584 2026] [security2:error] [pid 95128:tid 95628] [client 77.110.127.138:61076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fpOeSd8WoG-6-XpDF6wAAAoQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:20.976541 2026] [security2:error] [pid 95128:tid 95610] [client 88.241.67.160:55213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fpOeSd8WoG-6-XpDF9AAAAnI"]
[Mon Jul 20 07:16:20.976649 2026] [security2:error] [pid 95128:tid 95610] [client 88.241.67.160:55213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fpOeSd8WoG-6-XpDF9AAAAnI"]
[Mon Jul 20 07:16:21.005720 2026] [security2:error] [pid 95126:tid 95198] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fpQpx5ks9joCJTKW0LwABsUU"]
[Mon Jul 20 07:16:21.005874 2026] [security2:error] [pid 95126:tid 95292] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fpQpx5ks9joCJTKW0LwABsUU"]
[Mon Jul 20 07:16:21.181778 2026] [autoindex:error] [pid 95128:tid 95632] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/group/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:21.478246 2026] [security2:error] [pid 95128:tid 95520] [client 57.141.18.32:46228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4foueSd8WoG-6-XpDFUQACGF8"]
[Mon Jul 20 07:16:21.748394 2026] [security2:error] [pid 95128:tid 95607] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fpeeSd8WoG-6-XpDGGgAAAm8"]
[Mon Jul 20 07:16:22.086531 2026] [security2:error] [pid 95126:tid 95321] [client 104.234.53.75:57931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fpgpx5ks9joCJTKW0OQAAAc4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:22.121149 2026] [access_compat:error] [pid 95126:tid 95204] [remote 181.24.190.20:49008] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/xmlrpc.php
[Mon Jul 20 07:16:22.474075 2026] [security2:error] [pid 95128:tid 95629] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fpueSd8WoG-6-XpDGQQAAAoU"]
[Mon Jul 20 07:16:22.481322 2026] [security2:error] [pid 95128:tid 95632] [client 103.176.215.66:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fpueSd8WoG-6-XpDGVQAAAog"]
[Mon Jul 20 07:16:22.481468 2026] [security2:error] [pid 95128:tid 95632] [client 103.176.215.66:63309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fpueSd8WoG-6-XpDGVQAAAog"]
[Mon Jul 20 07:16:22.507536 2026] [security2:error] [pid 95128:tid 95560] [client 14.225.17.146:55548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4fpueSd8WoG-6-XpDGRgAAAkA"], referer: http://carolinapressurewashers.com/2020
[Mon Jul 20 07:16:22.712849 2026] [security2:error] [pid 95126:tid 95205] [remote 220.181.108.81:47758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.108.181.220.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4fpgpx5ks9joCJTKW0QwAB0Ew"]
[Mon Jul 20 07:16:22.734166 2026] [security2:error] [pid 95128:tid 95639] [client 57.141.18.43:44182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fo-eSd8WoG-6-XpDFoQACj2A"]
[Mon Jul 20 07:16:22.772687 2026] [proxy:warn] [pid 95128:tid 95559] [client 93.174.93.12:60000] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 07:16:22.772726 2026] [proxy:error] [pid 95128:tid 95559] (70014)End of file found: [client 93.174.93.12:60000] AH01095: prefetch request body failed to 127.0.0.1:8080 (127.0.0.1) from 93.174.93.12 ()
[Mon Jul 20 07:16:22.827354 2026] [security2:error] [pid 95128:tid 95627] [client 187.16.64.216:64957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fpueSd8WoG-6-XpDGYwAAAoM"]
[Mon Jul 20 07:16:22.827544 2026] [security2:error] [pid 95128:tid 95627] [client 187.16.64.216:64957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fpueSd8WoG-6-XpDGYwAAAoM"]
[Mon Jul 20 07:16:22.930141 2026] [security2:error] [pid 95126:tid 95346] [client 157.20.138.62:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fpgpx5ks9joCJTKW0TAAAAec"]
[Mon Jul 20 07:16:22.930314 2026] [security2:error] [pid 95126:tid 95346] [client 157.20.138.62:57454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fpgpx5ks9joCJTKW0TAAAAec"]
[Mon Jul 20 07:16:23.060552 2026] [security2:error] [pid 95128:tid 95508] [remote 47.86.33.52:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fp-eSd8WoG-6-XpDGbQACT3k"]
[Mon Jul 20 07:16:23.169519 2026] [security2:error] [pid 95128:tid 95541] [client 77.110.127.138:61137] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4fp-eSd8WoG-6-XpDGdQAAAi0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:23.239615 2026] [core:error] [pid 95128:tid 95617] [client 14.225.17.146:58574] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:23.239635 2026] [core:error] [pid 95128:tid 95617] [client 14.225.17.146:58574] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:23.276495 2026] [security2:error] [pid 95128:tid 95566] [client 57.141.18.118:29176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fpOeSd8WoG-6-XpDFwgACRm8"]
[Mon Jul 20 07:16:23.342247 2026] [security2:error] [pid 95128:tid 95604] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fp-eSd8WoG-6-XpDGdAAAAmw"]
[Mon Jul 20 07:16:23.407054 2026] [security2:error] [pid 95128:tid 95615] [client 14.225.17.146:53720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4fpueSd8WoG-6-XpDGOQAAAnc"], referer: http://iagdevelopments.com/2020
[Mon Jul 20 07:16:23.414605 2026] [security2:error] [pid 95128:tid 95411] [remote 217.61.143.92:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4fp-eSd8WoG-6-XpDGgQACSxg"]
[Mon Jul 20 07:16:23.661665 2026] [security2:error] [pid 95126:tid 95336] [client 77.110.127.138:61019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fpwpx5ks9joCJTKW0WgAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:23.661841 2026] [security2:error] [pid 95126:tid 95336] [client 77.110.127.138:61019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fpwpx5ks9joCJTKW0WgAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:23.815068 2026] [security2:error] [pid 95128:tid 95522] [client 77.110.127.138:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fp-eSd8WoG-6-XpDGkQAAAho"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:23.936976 2026] [security2:error] [pid 95128:tid 95509] [remote 217.61.143.92:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4fp-eSd8WoG-6-XpDGlQACbno"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 07:16:23.961768 2026] [security2:error] [pid 95128:tid 95427] [remote 182.77.62.24:40480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fp-eSd8WoG-6-XpDGlgACbyg"]
[Mon Jul 20 07:16:23.977162 2026] [security2:error] [pid 95128:tid 95625] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fp-eSd8WoG-6-XpDGjwAAAoE"]
[Mon Jul 20 07:16:24.066431 2026] [security2:error] [pid 95128:tid 95485] [remote 47.86.33.52:4152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4fqOeSd8WoG-6-XpDGmwACG2I"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:16:24.114571 2026] [security2:error] [pid 95128:tid 95538] [client 77.110.127.138:61162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fqOeSd8WoG-6-XpDGngAAAio"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:24.296543 2026] [security2:error] [pid 95126:tid 95313] [client 14.225.17.146:53594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4fqApx5ks9joCJTKW0YQAAAcY"], referer: https://iagdevelopments.com/2020
[Mon Jul 20 07:16:24.462402 2026] [security2:error] [pid 95128:tid 95582] [client 57.141.18.39:27595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fpeeSd8WoG-6-XpDF_gACVk0"]
[Mon Jul 20 07:16:24.468228 2026] [security2:error] [pid 95126:tid 95328] [client 104.234.53.57:29475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fqApx5ks9joCJTKW0agAAAdU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:24.679185 2026] [autoindex:error] [pid 95126:tid 95338] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:24.753644 2026] [security2:error] [pid 95128:tid 95410] [remote 103.82.22.235:40884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4fqOeSd8WoG-6-XpDGuwACORc"]
[Mon Jul 20 07:16:24.753875 2026] [security2:error] [pid 95128:tid 95553] [client 103.82.22.235:40884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4fqOeSd8WoG-6-XpDGuwACORc"]
[Mon Jul 20 07:16:24.754611 2026] [security2:error] [pid 95128:tid 95418] [remote 188.166.241.141:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4fqOeSd8WoG-6-XpDGwQACIx8"]
[Mon Jul 20 07:16:24.828453 2026] [security2:error] [pid 95128:tid 95561] [client 14.225.17.146:63695] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4fqOeSd8WoG-6-XpDGuAAAAkE"], referer: http://xp-design.co/2020
[Mon Jul 20 07:16:24.848316 2026] [security2:error] [pid 95126:tid 95270] [client 77.110.127.138:61175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fqApx5ks9joCJTKW0cwAAAZs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:24.887532 2026] [security2:error] [pid 95126:tid 95360] [client 14.225.17.146:53429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4fqApx5ks9joCJTKW0bgAAAfU"], referer: http://savilerowtravel.com/2020
[Mon Jul 20 07:16:24.941546 2026] [security2:error] [pid 95128:tid 95446] [remote 182.77.62.24:40480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fqOeSd8WoG-6-XpDGxwACcDs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:16:24.984732 2026] [security2:error] [pid 94831:tid 95021] [client 144.172.114.51:49102] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/deployment/.env"] [unique_id "al4fqI06NaEKF1g_MW2r5wAAADw"]
[Mon Jul 20 07:16:25.139049 2026] [security2:error] [pid 95128:tid 95459] [remote 188.166.241.141:36010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4fqeeSd8WoG-6-XpDG1AACMkg"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 07:16:25.198627 2026] [security2:error] [pid 95128:tid 95629] [client 77.110.127.138:61190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fqeeSd8WoG-6-XpDG2AAAAoU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:25.247302 2026] [security2:error] [pid 95128:tid 95610] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fqeeSd8WoG-6-XpDG0AAAAnI"]
[Mon Jul 20 07:16:25.485487 2026] [security2:error] [pid 95126:tid 95381] [client 77.110.127.138:61199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fqQpx5ks9joCJTKW0gAAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:25.599362 2026] [security2:error] [pid 95128:tid 95616] [client 154.192.123.127:17428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fqeeSd8WoG-6-XpDG8AAAAng"]
[Mon Jul 20 07:16:25.599478 2026] [security2:error] [pid 95128:tid 95616] [client 154.192.123.127:17428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fqeeSd8WoG-6-XpDG8AAAAng"]
[Mon Jul 20 07:16:25.887929 2026] [security2:error] [pid 95128:tid 95577] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fqeeSd8WoG-6-XpDG8wAAAlE"]
[Mon Jul 20 07:16:25.904836 2026] [security2:error] [pid 95126:tid 95352] [client 77.110.127.138:60985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fqQpx5ks9joCJTKW0hQAAAe0"]
[Mon Jul 20 07:16:25.953040 2026] [security2:error] [pid 95128:tid 95624] [client 57.141.18.99:50228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fpueSd8WoG-6-XpDGWwACgC4"]
[Mon Jul 20 07:16:25.955150 2026] [security2:error] [pid 94831:tid 95076] [client 77.110.127.138:61100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fqY06NaEKF1g_MW2r9wAAAHM"]
[Mon Jul 20 07:16:26.032086 2026] [security2:error] [pid 95128:tid 95530] [client 77.110.127.138:61216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4fqueSd8WoG-6-XpDHBAAAAiI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:26.143510 2026] [security2:error] [pid 95128:tid 95534] [client 50.116.65.227:53572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4fqueSd8WoG-6-XpDHBgAAAiY"]
[Mon Jul 20 07:16:26.147743 2026] [security2:error] [pid 95128:tid 95562] [client 14.225.17.146:55197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4fqueSd8WoG-6-XpDHAwAAAkI"], referer: http://recruitinginsight.us/2020
[Mon Jul 20 07:16:26.181222 2026] [security2:error] [pid 95128:tid 95642] [client 77.110.127.138:61220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fqueSd8WoG-6-XpDHBwAAApI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:26.181312 2026] [security2:error] [pid 95128:tid 95642] [client 77.110.127.138:61220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fqueSd8WoG-6-XpDHBwAAApI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:26.521358 2026] [security2:error] [pid 95128:tid 95520] [client 14.225.17.146:53624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4fqOeSd8WoG-6-XpDGpwAAAhg"], referer: http://adastra.love/2020
[Mon Jul 20 07:16:26.635825 2026] [security2:error] [pid 95128:tid 95587] [client 14.225.17.146:54784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4fqueSd8WoG-6-XpDHHwAAAls"], referer: http://nextlvlmarketingco.com/2020
[Mon Jul 20 07:16:26.746499 2026] [security2:error] [pid 95128:tid 95527] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fqueSd8WoG-6-XpDHIgAAAh8"]
[Mon Jul 20 07:16:27.149869 2026] [security2:error] [pid 95126:tid 95344] [client 57.141.18.56:60132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fpwpx5ks9joCJTKW0XAAB5VI"]
[Mon Jul 20 07:16:27.376852 2026] [autoindex:error] [pid 95128:tid 95605] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/file/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:27.640997 2026] [security2:error] [pid 95128:tid 95601] [client 154.208.48.130:63093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fq-eSd8WoG-6-XpDHZQAAAmk"]
[Mon Jul 20 07:16:27.641092 2026] [security2:error] [pid 95128:tid 95601] [client 154.208.48.130:63093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fq-eSd8WoG-6-XpDHZQAAAmk"]
[Mon Jul 20 07:16:27.775778 2026] [autoindex:error] [pid 95128:tid 95575] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/mu-plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:28.215223 2026] [security2:error] [pid 95128:tid 95609] [client 14.225.17.146:54740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4fqueSd8WoG-6-XpDHLwAAAnE"], referer: http://phillipbloch.com/2020
[Mon Jul 20 07:16:28.361961 2026] [security2:error] [pid 94831:tid 95042] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4frI06NaEKF1g_MW2sIQAAAFE"]
[Mon Jul 20 07:16:28.385523 2026] [security2:error] [pid 94831:tid 94986] [client 201.27.111.74:50198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4frI06NaEKF1g_MW2sJgAAABk"]
[Mon Jul 20 07:16:28.387102 2026] [security2:error] [pid 94831:tid 94986] [client 201.27.111.74:50198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4frI06NaEKF1g_MW2sJgAAABk"]
[Mon Jul 20 07:16:28.418489 2026] [security2:error] [pid 95128:tid 95539] [client 14.225.17.146:63664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4frOeSd8WoG-6-XpDHfwAAAis"], referer: http://secretkeynumerology.com/2020
[Mon Jul 20 07:16:28.448531 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:61343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4frApx5ks9joCJTKW0pgAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:28.499814 2026] [security2:error] [pid 95126:tid 95334] [client 77.110.127.138:61058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4frApx5ks9joCJTKW0qAAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:28.549441 2026] [security2:error] [pid 95128:tid 95528] [client 14.225.17.146:54920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4fq-eSd8WoG-6-XpDHbQAAAiA"], referer: http://idigress.studio/2020
[Mon Jul 20 07:16:28.651399 2026] [security2:error] [pid 95128:tid 95527] [client 77.110.127.138:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4frOeSd8WoG-6-XpDHkQAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:28.651534 2026] [security2:error] [pid 95128:tid 95527] [client 77.110.127.138:61352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4frOeSd8WoG-6-XpDHkQAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:28.697640 2026] [security2:error] [pid 95128:tid 95541] [client 104.234.53.75:40623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4frOeSd8WoG-6-XpDHlgAAAi0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:28.707515 2026] [security2:error] [pid 95128:tid 95553] [client 144.172.114.51:35174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/private/config.php"] [unique_id "al4frOeSd8WoG-6-XpDHlwAAAjk"]
[Mon Jul 20 07:16:29.022109 2026] [security2:error] [pid 95126:tid 95363] [client 47.128.123.6:41434] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/robots.txt"] [unique_id "al4frQpx5ks9joCJTKW0swAAAfg"]
[Mon Jul 20 07:16:29.137976 2026] [security2:error] [pid 94831:tid 95085] [client 144.172.114.51:49116] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/docker/.env"] [unique_id "al4frY06NaEKF1g_MW2sNQAAAHw"]
[Mon Jul 20 07:16:29.184337 2026] [security2:error] [pid 95128:tid 95538] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4frOeSd8WoG-6-XpDHrQAAAio"]
[Mon Jul 20 07:16:29.188740 2026] [security2:error] [pid 95126:tid 95349] [client 14.225.17.146:63716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4frApx5ks9joCJTKW0sAAAAeo"], referer: http://mollycahill.com/2020
[Mon Jul 20 07:16:29.213984 2026] [security2:error] [pid 95126:tid 95260] [client 57.141.18.106:53066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fqQpx5ks9joCJTKW0gQABkV4"]
[Mon Jul 20 07:16:29.275202 2026] [security2:error] [pid 95126:tid 95311] [client 14.225.17.146:54993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4fqwpx5ks9joCJTKW0kwAAAcQ"], referer: http://aandarealtygroup.com/2020
[Mon Jul 20 07:16:29.410633 2026] [security2:error] [pid 95126:tid 95374] [client 14.225.17.146:63828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4frQpx5ks9joCJTKW0uwAAAgM"], referer: https://secretkeynumerology.com/2020
[Mon Jul 20 07:16:29.429002 2026] [security2:error] [pid 95128:tid 95573] [client 103.144.65.217:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4freeSd8WoG-6-XpDHvwAAAk0"]
[Mon Jul 20 07:16:29.429150 2026] [security2:error] [pid 95128:tid 95573] [client 103.144.65.217:64704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4freeSd8WoG-6-XpDHvwAAAk0"]
[Mon Jul 20 07:16:29.521863 2026] [security2:error] [pid 94831:tid 95071] [client 104.234.53.50:60877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4frY06NaEKF1g_MW2sOAAAAG4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:29.783804 2026] [security2:error] [pid 94831:tid 94981] [client 104.234.53.50:60877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4frY06NaEKF1g_MW2sQAAAABQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:29.930233 2026] [security2:error] [pid 95128:tid 95575] [client 117.211.236.168:54968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4freeSd8WoG-6-XpDH2AAAAk8"]
[Mon Jul 20 07:16:29.930318 2026] [security2:error] [pid 95128:tid 95575] [client 117.211.236.168:54968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4freeSd8WoG-6-XpDH2AAAAk8"]
[Mon Jul 20 07:16:30.016285 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:61036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fro06NaEKF1g_MW2sRAAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.031042 2026] [security2:error] [pid 95128:tid 95562] [client 194.61.41.241:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4freeSd8WoG-6-XpDH0wAAAkI"]
[Mon Jul 20 07:16:30.088275 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:61048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4frgpx5ks9joCJTKW0xwAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.245507 2026] [security2:error] [pid 94831:tid 94992] [client 77.110.127.138:61395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fro06NaEKF1g_MW2sSAAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.484090 2026] [security2:error] [pid 95128:tid 95457] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4frueSd8WoG-6-XpDH9AACIEY"]
[Mon Jul 20 07:16:30.484335 2026] [security2:error] [pid 95128:tid 95528] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4frueSd8WoG-6-XpDH9AACIEY"]
[Mon Jul 20 07:16:30.569856 2026] [security2:error] [pid 95128:tid 95595] [client 77.110.127.138:61404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4frueSd8WoG-6-XpDH-AAAAmM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.587118 2026] [security2:error] [pid 95128:tid 95576] [client 49.37.242.14:63839] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4frueSd8WoG-6-XpDH-wAAAlA"]
[Mon Jul 20 07:16:30.587258 2026] [security2:error] [pid 95128:tid 95576] [client 49.37.242.14:63839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4frueSd8WoG-6-XpDH-wAAAlA"]
[Mon Jul 20 07:16:30.639391 2026] [security2:error] [pid 95128:tid 95578] [client 57.141.18.122:65142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fqueSd8WoG-6-XpDHNAACUhA"]
[Mon Jul 20 07:16:30.675694 2026] [autoindex:error] [pid 95128:tid 95579] [client 194.61.41.241:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/themes/twentytwentyfour/patterns/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:30.707721 2026] [security2:error] [pid 95128:tid 95624] [client 77.110.127.138:61407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4frueSd8WoG-6-XpDIBQAAAoA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.707859 2026] [security2:error] [pid 95128:tid 95624] [client 77.110.127.138:61407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4frueSd8WoG-6-XpDIBQAAAoA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.823280 2026] [security2:error] [pid 95128:tid 95581] [client 77.110.127.138:61357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4frueSd8WoG-6-XpDIEgAAAlU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.871447 2026] [security2:error] [pid 95128:tid 95573] [client 143.44.185.218:44321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4frueSd8WoG-6-XpDIFAAAAk0"]
[Mon Jul 20 07:16:30.871575 2026] [security2:error] [pid 95128:tid 95573] [client 143.44.185.218:44321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4frueSd8WoG-6-XpDIFAAAAk0"]
[Mon Jul 20 07:16:30.921889 2026] [security2:error] [pid 95128:tid 95587] [client 77.110.127.138:61368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4frueSd8WoG-6-XpDIFgAAAls"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:30.973889 2026] [security2:error] [pid 95128:tid 95554] [client 77.110.127.138:61142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4frueSd8WoG-6-XpDIGAAAAjo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:31.113610 2026] [security2:error] [pid 95126:tid 95265] [client 144.172.114.51:49690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/k8s/.env"] [unique_id "al4frwpx5ks9joCJTKW04AAAAZY"]
[Mon Jul 20 07:16:31.168109 2026] [security2:error] [pid 95126:tid 95261] [client 14.225.17.146:54662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4frgpx5ks9joCJTKW00wAAAZI"], referer: http://alrowad-hub.net/2020
[Mon Jul 20 07:16:31.169212 2026] [security2:error] [pid 95128:tid 95572] [client 14.225.17.146:63494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4freeSd8WoG-6-XpDHxwAAAkw"], referer: http://sarahsnyder.net/2020
[Mon Jul 20 07:16:31.191346 2026] [security2:error] [pid 95128:tid 95548] [client 14.225.17.146:63663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4freeSd8WoG-6-XpDH1AAAAjQ"], referer: http://collectingrealestate.com/2020
[Mon Jul 20 07:16:31.433108 2026] [security2:error] [pid 95126:tid 95277] [client 77.110.127.138:61372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4frwpx5ks9joCJTKW05AAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:31.587256 2026] [security2:error] [pid 94831:tid 95024] [client 57.141.18.17:47646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fq406NaEKF1g_MW2sGwAAPwg"]
[Mon Jul 20 07:16:31.625058 2026] [security2:error] [pid 95128:tid 95536] [client 88.241.67.160:54804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fr-eSd8WoG-6-XpDIQAAAAig"]
[Mon Jul 20 07:16:31.625417 2026] [security2:error] [pid 95128:tid 95536] [client 88.241.67.160:54804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fr-eSd8WoG-6-XpDIQAAAAig"]
[Mon Jul 20 07:16:31.786436 2026] [security2:error] [pid 95128:tid 95486] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fr-eSd8WoG-6-XpDIRQACk2M"]
[Mon Jul 20 07:16:31.786577 2026] [security2:error] [pid 95128:tid 95643] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fr-eSd8WoG-6-XpDIRQACk2M"]
[Mon Jul 20 07:16:31.812036 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:61271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fr-eSd8WoG-6-XpDIRgAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:31.812134 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:61271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fr-eSd8WoG-6-XpDIRgAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:31.928801 2026] [security2:error] [pid 95128:tid 95615] [client 57.141.18.105:35090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4frOeSd8WoG-6-XpDHggACd3g"]
[Mon Jul 20 07:16:31.966568 2026] [security2:error] [pid 95128:tid 95602] [client 77.110.127.138:61437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fr-eSd8WoG-6-XpDIUgAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:32.016511 2026] [security2:error] [pid 95128:tid 95622] [client 77.110.127.138:61330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpN1gRrLm7'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4fsOeSd8WoG-6-XpDIWgAAAn4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:32.131264 2026] [security2:error] [pid 95126:tid 95380] [client 14.225.17.146:58059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4frwpx5ks9joCJTKW07wAAAgk"], referer: https://sarahsnyder.net/2020
[Mon Jul 20 07:16:32.170142 2026] [security2:error] [pid 95128:tid 95530] [client 74.208.214.194:41236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4fsOeSd8WoG-6-XpDIYQAAAiI"]
[Mon Jul 20 07:16:32.235962 2026] [security2:error] [pid 95128:tid 95582] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fsOeSd8WoG-6-XpDIWQAAAlY"]
[Mon Jul 20 07:16:32.284561 2026] [security2:error] [pid 95128:tid 95563] [client 13.233.207.33:13684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fsOeSd8WoG-6-XpDIZgAAAkM"]
[Mon Jul 20 07:16:32.284639 2026] [security2:error] [pid 95128:tid 95563] [client 13.233.207.33:13684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fsOeSd8WoG-6-XpDIZgAAAkM"]
[Mon Jul 20 07:16:32.610175 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:61451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fsOeSd8WoG-6-XpDIewAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:32.610283 2026] [security2:error] [pid 95128:tid 95631] [client 77.110.127.138:61451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fsOeSd8WoG-6-XpDIewAAAoc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:32.722126 2026] [security2:error] [pid 95128:tid 95469] [remote 15.206.251.117:56904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fsOeSd8WoG-6-XpDIhQACM1I"]
[Mon Jul 20 07:16:32.722360 2026] [security2:error] [pid 95128:tid 95547] [client 15.206.251.117:56904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fsOeSd8WoG-6-XpDIhQACM1I"]
[Mon Jul 20 07:16:32.957762 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:61459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fsApx5ks9joCJTKW1AgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:32.957880 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:61459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fsApx5ks9joCJTKW1AgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:32.960126 2026] [security2:error] [pid 95126:tid 95311] [client 14.225.17.146:58349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4fsApx5ks9joCJTKW0_gAAAcQ"], referer: http://oldracelimited.com/2020
[Mon Jul 20 07:16:33.029207 2026] [security2:error] [pid 95128:tid 95531] [client 77.110.127.138:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIngAAAiM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.029347 2026] [security2:error] [pid 95128:tid 95531] [client 77.110.127.138:61349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIngAAAiM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.044837 2026] [security2:error] [pid 95128:tid 95567] [client 14.225.17.146:58063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4fr-eSd8WoG-6-XpDIOAAAAkc"], referer: http://reosportsboats.com/2020
[Mon Jul 20 07:16:33.050546 2026] [security2:error] [pid 95126:tid 95352] [client 103.176.215.66:63831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fsQpx5ks9joCJTKW1CAAAAe0"]
[Mon Jul 20 07:16:33.050675 2026] [security2:error] [pid 95126:tid 95352] [client 103.176.215.66:63831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fsQpx5ks9joCJTKW1CAAAAe0"]
[Mon Jul 20 07:16:33.179731 2026] [security2:error] [pid 95128:tid 95608] [client 77.110.127.138:61467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIqAAAAnA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.179893 2026] [security2:error] [pid 95128:tid 95608] [client 77.110.127.138:61467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIqAAAAnA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.347112 2026] [security2:error] [pid 95128:tid 95625] [client 77.110.127.138:61473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIrwAAAoE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.347203 2026] [security2:error] [pid 95128:tid 95625] [client 77.110.127.138:61473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIrwAAAoE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.351727 2026] [security2:error] [pid 95128:tid 95599] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fseeSd8WoG-6-XpDIowAAAmc"]
[Mon Jul 20 07:16:33.409416 2026] [security2:error] [pid 95128:tid 95564] [client 104.234.53.80:54219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fseeSd8WoG-6-XpDIswAAAkQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:33.410100 2026] [security2:error] [pid 95128:tid 95633] [client 77.110.127.138:61384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDItAAAAok"]
[Mon Jul 20 07:16:33.410195 2026] [security2:error] [pid 95128:tid 95633] [client 77.110.127.138:61384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDItAAAAok"]
[Mon Jul 20 07:16:33.477965 2026] [security2:error] [pid 95128:tid 95626] [client 77.110.127.138:61380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIuwAAAoI"]
[Mon Jul 20 07:16:33.478065 2026] [security2:error] [pid 95128:tid 95626] [client 77.110.127.138:61380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fseeSd8WoG-6-XpDIuwAAAoI"]
[Mon Jul 20 07:16:33.494505 2026] [security2:error] [pid 95128:tid 95613] [client 187.16.64.216:65532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fseeSd8WoG-6-XpDIvgAAAnU"]
[Mon Jul 20 07:16:33.494628 2026] [security2:error] [pid 95128:tid 95613] [client 187.16.64.216:65532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fseeSd8WoG-6-XpDIvgAAAnU"]
[Mon Jul 20 07:16:33.553951 2026] [security2:error] [pid 95128:tid 95544] [client 14.225.17.146:56085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4fsOeSd8WoG-6-XpDIYgAAAjA"], referer: http://ghivs.com/2020
[Mon Jul 20 07:16:33.559198 2026] [security2:error] [pid 95128:tid 95592] [client 157.20.138.62:58017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fseeSd8WoG-6-XpDIwwAAAmA"]
[Mon Jul 20 07:16:33.559287 2026] [security2:error] [pid 95128:tid 95592] [client 157.20.138.62:58017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fseeSd8WoG-6-XpDIwwAAAmA"]
[Mon Jul 20 07:16:33.636421 2026] [security2:error] [pid 95126:tid 95334] [client 77.110.127.138:61482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fsQpx5ks9joCJTKW1HgAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.804008 2026] [security2:error] [pid 95126:tid 95260] [client 14.225.17.146:58135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4fsApx5ks9joCJTKW08wAAAZE"]
[Mon Jul 20 07:16:33.813373 2026] [security2:error] [pid 95128:tid 95536] [client 77.110.127.138:61487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phptyvgVNfF'%20OR%20402=(SELECT%20402%20FROM%20PG_SLEEP(15))--"] [unique_id "al4fseeSd8WoG-6-XpDIzwAAAig"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:33.850096 2026] [security2:error] [pid 95128:tid 95561] [client 45.157.112.60:61439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fseeSd8WoG-6-XpDI0AAAAkE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:16:34.085092 2026] [security2:error] [pid 95128:tid 95575] [client 14.225.17.146:53227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4fseeSd8WoG-6-XpDI2AAAAk8"], referer: https://reosportsboats.com/2020
[Mon Jul 20 07:16:34.086102 2026] [security2:error] [pid 95128:tid 95526] [client 144.172.114.51:59194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/test/phpinfo.php"] [unique_id "al4fsueSd8WoG-6-XpDI3QAAAh4"]
[Mon Jul 20 07:16:34.086113 2026] [security2:error] [pid 95128:tid 95577] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fseeSd8WoG-6-XpDI1AAAAlE"]
[Mon Jul 20 07:16:34.568653 2026] [security2:error] [pid 95128:tid 95544] [client 184.154.139.41:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4fsueSd8WoG-6-XpDI8wAAAjA"]
[Mon Jul 20 07:16:34.568697 2026] [security2:error] [pid 95128:tid 95544] [client 184.154.139.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4fsueSd8WoG-6-XpDI8wAAAjA"]
[Mon Jul 20 07:16:34.584980 2026] [security2:error] [pid 95126:tid 95372] [client 184.154.139.41:50864] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/th1s_1s_a_4o4.html"] [unique_id "al4fsgpx5ks9joCJTKW1MAAAAgE"]
[Mon Jul 20 07:16:34.660229 2026] [security2:error] [pid 95128:tid 95612] [client 14.225.17.146:56006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4fsOeSd8WoG-6-XpDIlgAAAnQ"], referer: http://ccsdifference.com/2020
[Mon Jul 20 07:16:34.677046 2026] [security2:error] [pid 94831:tid 94986] [client 14.225.17.146:55979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4fso06NaEKF1g_MW2sjwAAABk"], referer: http://bigwormfishing.com/2020
[Mon Jul 20 07:16:34.804093 2026] [security2:error] [pid 95128:tid 95534] [client 194.61.41.64:42001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fsueSd8WoG-6-XpDI9gAAAiY"]
[Mon Jul 20 07:16:35.003669 2026] [security2:error] [pid 95128:tid 95504] [remote 97.74.87.194:55982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fsueSd8WoG-6-XpDJGAACI3U"]
[Mon Jul 20 07:16:35.236821 2026] [security2:error] [pid 95128:tid 95562] [client 14.225.17.146:53380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4fseeSd8WoG-6-XpDInQAAAkI"]
[Mon Jul 20 07:16:35.446185 2026] [security2:error] [pid 95128:tid 95424] [remote 97.74.87.194:55982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fs-eSd8WoG-6-XpDJMQACaSU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:16:35.458841 2026] [security2:error] [pid 95128:tid 95553] [client 77.110.127.138:61396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fs-eSd8WoG-6-XpDJMgAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:35.458991 2026] [security2:error] [pid 95128:tid 95553] [client 77.110.127.138:61396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fs-eSd8WoG-6-XpDJMgAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:35.488643 2026] [security2:error] [pid 95128:tid 95569] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fs-eSd8WoG-6-XpDJIwAAAkk"]
[Mon Jul 20 07:16:35.672919 2026] [security2:error] [pid 95128:tid 95560] [client 14.225.17.146:63313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4fs-eSd8WoG-6-XpDJOAAAAkA"], referer: https://ccsdifference.com/2020
[Mon Jul 20 07:16:35.724189 2026] [security2:error] [pid 95126:tid 95308] [client 98.124.43.70:51854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "jqq.cyv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fswpx5ks9joCJTKW1RwABwQw"]
[Mon Jul 20 07:16:35.927739 2026] [security2:error] [pid 95128:tid 95613] [client 144.172.114.51:59210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/config/settings.php"] [unique_id "al4fs-eSd8WoG-6-XpDJSQAAAnU"]
[Mon Jul 20 07:16:35.973754 2026] [autoindex:error] [pid 95128:tid 95615] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/imgareaselect/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:36.066918 2026] [security2:error] [pid 95126:tid 95343] [client 77.110.127.138:60989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ftApx5ks9joCJTKW1UgAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:36.229502 2026] [security2:error] [pid 95128:tid 95639] [client 77.110.127.138:61561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.phpomvvgjGG')%20OR%20233=(SELECT%20233%20FROM%20PG_SLEEP(15))--"] [unique_id "al4ftOeSd8WoG-6-XpDJYQAAAo8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:36.325131 2026] [security2:error] [pid 95126:tid 95366] [client 14.225.17.146:53066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ftApx5ks9joCJTKW1VAAAAfs"], referer: http://falconarrowshop.com/2020
[Mon Jul 20 07:16:36.402266 2026] [security2:error] [pid 95128:tid 95548] [client 154.192.123.127:17774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ftOeSd8WoG-6-XpDJdQAAAjQ"]
[Mon Jul 20 07:16:36.402388 2026] [security2:error] [pid 95128:tid 95548] [client 154.192.123.127:17774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ftOeSd8WoG-6-XpDJdQAAAjQ"]
[Mon Jul 20 07:16:36.498040 2026] [security2:error] [pid 95128:tid 95619] [client 158.173.89.95:59709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ftOeSd8WoG-6-XpDJfQAAAns"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:16:36.570383 2026] [security2:error] [pid 95128:tid 95543] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4ftOeSd8WoG-6-XpDJcgAAAi8"]
[Mon Jul 20 07:16:36.575389 2026] [security2:error] [pid 95126:tid 95327] [client 14.225.17.146:63286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4fsgpx5ks9joCJTKW1MgAAAdQ"], referer: http://itdynamix.com/2020
[Mon Jul 20 07:16:36.598676 2026] [security2:error] [pid 95126:tid 95339] [client 57.141.18.92:22338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fsApx5ks9joCJTKW0-wAB4H0"]
[Mon Jul 20 07:16:36.812289 2026] [security2:error] [pid 95128:tid 95571] [client 104.234.53.53:21107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ftOeSd8WoG-6-XpDJiQAAAks"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:37.027602 2026] [security2:error] [pid 95128:tid 95408] [remote 173.212.252.15:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4fteeSd8WoG-6-XpDJmAACPRU"]
[Mon Jul 20 07:16:37.079267 2026] [security2:error] [pid 95126:tid 95278] [client 159.195.201.212:46410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4ftApx5ks9joCJTKW1YgABoxU"]
[Mon Jul 20 07:16:37.080680 2026] [security2:error] [pid 95126:tid 95278] [client 159.195.201.212:46410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4ftApx5ks9joCJTKW1YQABoxo"]
[Mon Jul 20 07:16:37.232694 2026] [security2:error] [pid 95128:tid 95401] [remote 173.212.252.15:52810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4fteeSd8WoG-6-XpDJpAACXA4"], referer: https://allergyantidotes.com/wp-login.php
[Mon Jul 20 07:16:37.274934 2026] [security2:error] [pid 95128:tid 95530] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fteeSd8WoG-6-XpDJnQAAAiI"]
[Mon Jul 20 07:16:37.500280 2026] [security2:error] [pid 95126:tid 95314] [client 159.195.201.212:46410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4ftQpx5ks9joCJTKW1agABxx0"]
[Mon Jul 20 07:16:37.504486 2026] [security2:error] [pid 95126:tid 95314] [client 159.195.201.212:46410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4ftQpx5ks9joCJTKW1awABxxg"]
[Mon Jul 20 07:16:37.514173 2026] [security2:error] [pid 95126:tid 95280] [client 52.109.56.130:14473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ftQpx5ks9joCJTKW1bwAAAaU"]
[Mon Jul 20 07:16:37.570297 2026] [security2:error] [pid 95128:tid 95639] [client 14.225.17.146:65155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4fteeSd8WoG-6-XpDJqgAAAo8"], referer: https://itdynamix.com/2020
[Mon Jul 20 07:16:37.630717 2026] [security2:error] [pid 95128:tid 95584] [client 144.172.114.51:59220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/backup/config.php"] [unique_id "al4fteeSd8WoG-6-XpDJvgAAAlg"]
[Mon Jul 20 07:16:37.688453 2026] [security2:error] [pid 95128:tid 95633] [client 184.154.139.41:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "405"] [hostname "www.travelbyfire.com"] [uri "/xmlrpc.php"] [unique_id "al4fteeSd8WoG-6-XpDJvQAAAok"]
[Mon Jul 20 07:16:37.719396 2026] [security2:error] [pid 95128:tid 95568] [client 184.154.139.41:52688] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "405"] [hostname "www.travelbyfire.com"] [uri "/xmlrpc.php"] [unique_id "al4fteeSd8WoG-6-XpDJrQAAAkg"]
[Mon Jul 20 07:16:37.747187 2026] [security2:error] [pid 95126:tid 95384] [client 52.109.56.130:14473] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ftQpx5ks9joCJTKW1cgAAAg0"]
[Mon Jul 20 07:16:37.771842 2026] [autoindex:error] [pid 95126:tid 95348] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/sodium_compat/lib/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:37.911679 2026] [security2:error] [pid 94831:tid 94863] [remote 100.42.189.89:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ftY06NaEKF1g_MW2s3wAAFx8"]
[Mon Jul 20 07:16:37.975003 2026] [security2:error] [pid 95126:tid 95349] [client 57.141.18.50:21822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fsgpx5ks9joCJTKW1LQAB6gM"]
[Mon Jul 20 07:16:37.994836 2026] [security2:error] [pid 95128:tid 95604] [client 77.110.127.138:61613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fteeSd8WoG-6-XpDJ2gAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:37.994944 2026] [security2:error] [pid 95128:tid 95604] [client 77.110.127.138:61613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fteeSd8WoG-6-XpDJ2gAAAmw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:37.996170 2026] [security2:error] [pid 95126:tid 95326] [client 74.208.214.194:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ftQpx5ks9joCJTKW1egAAAdM"]
[Mon Jul 20 07:16:38.012823 2026] [security2:error] [pid 95128:tid 95399] [remote 45.84.107.182:10435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ftueSd8WoG-6-XpDJ2wACZgw"], referer: https://verdunestate.com/contact/
[Mon Jul 20 07:16:38.100827 2026] [security2:error] [pid 94831:tid 94855] [remote 100.42.189.89:51814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4fto06NaEKF1g_MW2s5QAAehc"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:16:38.146731 2026] [security2:error] [pid 95126:tid 95170] [remote 173.249.4.11:12829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4ftgpx5ks9joCJTKW1ewABtik"]
[Mon Jul 20 07:16:38.166304 2026] [security2:error] [pid 95128:tid 95641] [client 77.110.127.138:61620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftueSd8WoG-6-XpDJ6QAAApE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.166421 2026] [security2:error] [pid 95128:tid 95641] [client 77.110.127.138:61620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftueSd8WoG-6-XpDJ6QAAApE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.196254 2026] [autoindex:error] [pid 95128:tid 95563] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/jcrop/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:38.199594 2026] [security2:error] [pid 95126:tid 95357] [client 57.141.18.91:23424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fsgpx5ks9joCJTKW1MwAB8ng"]
[Mon Jul 20 07:16:38.341801 2026] [security2:error] [pid 95126:tid 95160] [remote 173.249.4.11:12829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4ftgpx5ks9joCJTKW1ggABux8"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 07:16:38.356538 2026] [security2:error] [pid 95126:tid 95324] [client 52.111.227.28:13408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ftgpx5ks9joCJTKW1hAAAAdE"]
[Mon Jul 20 07:16:38.399773 2026] [security2:error] [pid 95126:tid 95282] [client 14.225.17.146:52868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4ftgpx5ks9joCJTKW1fAAAAac"]
[Mon Jul 20 07:16:38.410106 2026] [security2:error] [pid 95126:tid 95370] [client 52.111.227.28:13408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ftgpx5ks9joCJTKW1hgAAAf8"]
[Mon Jul 20 07:16:38.477258 2026] [security2:error] [pid 95128:tid 95617] [client 77.110.127.138:61398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4ftueSd8WoG-6-XpDJ-AAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.541317 2026] [security2:error] [pid 95128:tid 95609] [client 77.110.127.138:61519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php4jwWWs8D'))%20OR%20447=(SELECT%20447%20FROM%20PG_SLEEP(15))--"] [unique_id "al4ftueSd8WoG-6-XpDKAQAAAnE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.542213 2026] [security2:error] [pid 95128:tid 95610] [client 77.110.127.138:61625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftueSd8WoG-6-XpDKAgAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.542295 2026] [security2:error] [pid 95128:tid 95610] [client 77.110.127.138:61625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftueSd8WoG-6-XpDKAgAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.553657 2026] [core:error] [pid 95128:tid 95530] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:38.553675 2026] [core:error] [pid 95128:tid 95530] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:38.569339 2026] [security2:error] [pid 95128:tid 95543] [client 154.208.48.130:63617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ftueSd8WoG-6-XpDKBgAAAi8"]
[Mon Jul 20 07:16:38.569490 2026] [security2:error] [pid 95128:tid 95543] [client 154.208.48.130:63617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ftueSd8WoG-6-XpDKBgAAAi8"]
[Mon Jul 20 07:16:38.720400 2026] [security2:error] [pid 95126:tid 95374] [client 77.110.127.138:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftgpx5ks9joCJTKW1kAAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.720497 2026] [security2:error] [pid 95126:tid 95374] [client 77.110.127.138:61631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftgpx5ks9joCJTKW1kAAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.726691 2026] [security2:error] [pid 94831:tid 95061] [client 57.141.18.61:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4fto06NaEKF1g_MW2s7gAAAGQ"]
[Mon Jul 20 07:16:38.758657 2026] [security2:error] [pid 95128:tid 95621] [client 34.201.171.57:26598] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4ftueSd8WoG-6-XpDKFAAAAn0"]
[Mon Jul 20 07:16:38.799546 2026] [security2:error] [pid 95128:tid 95611] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4ftueSd8WoG-6-XpDKDAAAAnM"]
[Mon Jul 20 07:16:38.854920 2026] [security2:error] [pid 95128:tid 95540] [client 201.27.111.74:50707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ftueSd8WoG-6-XpDKGgAAAiw"]
[Mon Jul 20 07:16:38.855090 2026] [security2:error] [pid 95128:tid 95540] [client 201.27.111.74:50707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ftueSd8WoG-6-XpDKGgAAAiw"]
[Mon Jul 20 07:16:38.872018 2026] [security2:error] [pid 95128:tid 95560] [client 77.110.127.138:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftueSd8WoG-6-XpDKGwAAAkA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:38.872112 2026] [security2:error] [pid 95128:tid 95560] [client 77.110.127.138:61636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftueSd8WoG-6-XpDKGwAAAkA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:39.024424 2026] [security2:error] [pid 95128:tid 95636] [client 77.110.127.138:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ft-eSd8WoG-6-XpDKIQAAAow"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:39.024522 2026] [security2:error] [pid 95128:tid 95636] [client 77.110.127.138:61642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ft-eSd8WoG-6-XpDKIQAAAow"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:39.097800 2026] [core:error] [pid 95128:tid 95602] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:39.097827 2026] [core:error] [pid 95128:tid 95602] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:39.110865 2026] [security2:error] [pid 95126:tid 95284] [client 144.172.114.51:49704] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/terraform/.env"] [unique_id "al4ftwpx5ks9joCJTKW1lgAAAak"]
[Mon Jul 20 07:16:39.155382 2026] [security2:error] [pid 95126:tid 95266] [client 57.141.18.8:57276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fswpx5ks9joCJTKW1TwABlxE"]
[Mon Jul 20 07:16:39.230665 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:61647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftwpx5ks9joCJTKW1mgAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:39.230794 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:61647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ftwpx5ks9joCJTKW1mgAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:39.471467 2026] [security2:error] [pid 95128:tid 95628] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4ft-eSd8WoG-6-XpDKPQAAAoQ"]
[Mon Jul 20 07:16:39.732124 2026] [security2:error] [pid 95128:tid 95520] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4ft-eSd8WoG-6-XpDKJgAAAhg"]
[Mon Jul 20 07:16:39.788202 2026] [security2:error] [pid 95128:tid 95563] [client 3.85.28.216:31376] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4ftueSd8WoG-6-XpDKHAAAAkM"]
[Mon Jul 20 07:16:39.855812 2026] [security2:error] [pid 95128:tid 95578] [client 144.172.114.51:59228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/private/config.php"] [unique_id "al4ft-eSd8WoG-6-XpDKTwAAAlI"]
[Mon Jul 20 07:16:39.974632 2026] [autoindex:error] [pid 95128:tid 95567] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:39.987655 2026] [security2:error] [pid 95128:tid 95533] [client 103.144.65.217:65159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ft-eSd8WoG-6-XpDKXQAAAiU"]
[Mon Jul 20 07:16:39.987786 2026] [security2:error] [pid 95128:tid 95533] [client 103.144.65.217:65159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ft-eSd8WoG-6-XpDKXQAAAiU"]
[Mon Jul 20 07:16:40.562925 2026] [security2:error] [pid 95128:tid 95615] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fuOeSd8WoG-6-XpDKfgAAAnc"]
[Mon Jul 20 07:16:40.738106 2026] [security2:error] [pid 95126:tid 95366] [client 14.225.17.146:62591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4ftwpx5ks9joCJTKW1ngAAAfs"], referer: http://windowtx.com/2020
[Mon Jul 20 07:16:40.824032 2026] [security2:error] [pid 95128:tid 95542] [client 14.225.17.146:56885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4fuOeSd8WoG-6-XpDKigAAAi4"]
[Mon Jul 20 07:16:40.895094 2026] [security2:error] [pid 95126:tid 95369] [client 14.225.17.146:56893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4fuApx5ks9joCJTKW1uAAAAf4"], referer: http://grndl.com/2020
[Mon Jul 20 07:16:40.948236 2026] [security2:error] [pid 95126:tid 95300] [client 104.234.53.77:35263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4fuApx5ks9joCJTKW1twAAAbk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:40.998418 2026] [security2:error] [pid 95126:tid 95370] [client 144.172.114.51:40700] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-abc5f05b.vfcthomasville.org"] [uri "/ansible/.env"] [unique_id "al4fuApx5ks9joCJTKW1vgAAAf8"]
[Mon Jul 20 07:16:41.046308 2026] [security2:error] [pid 95128:tid 95574] [client 77.110.127.138:61607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fueeSd8WoG-6-XpDKoQAAAk4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.072301 2026] [autoindex:error] [pid 95128:tid 95584] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/Requests/library/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:41.099924 2026] [security2:error] [pid 95128:tid 95582] [client 77.110.127.138:61619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4fueeSd8WoG-6-XpDKpwAAAlY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.168313 2026] [security2:error] [pid 95128:tid 95509] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fueeSd8WoG-6-XpDKrQACIXo"]
[Mon Jul 20 07:16:41.168520 2026] [security2:error] [pid 95128:tid 95529] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fueeSd8WoG-6-XpDKrQACIXo"]
[Mon Jul 20 07:16:41.229106 2026] [security2:error] [pid 95126:tid 95378] [client 104.234.53.77:35263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fuQpx5ks9joCJTKW1xwAAAgc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:41.326270 2026] [security2:error] [pid 95126:tid 95321] [client 77.110.127.138:61711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fuQpx5ks9joCJTKW1ywAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.346908 2026] [security2:error] [pid 95128:tid 95464] [remote 47.86.33.52:4112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4fueeSd8WoG-6-XpDKugACZU0"]
[Mon Jul 20 07:16:41.396730 2026] [security2:error] [pid 95126:tid 95374] [client 117.211.236.168:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fuQpx5ks9joCJTKW1zAAAAgM"]
[Mon Jul 20 07:16:41.396859 2026] [security2:error] [pid 95126:tid 95374] [client 117.211.236.168:55540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fuQpx5ks9joCJTKW1zAAAAgM"]
[Mon Jul 20 07:16:41.397324 2026] [security2:error] [pid 95128:tid 95516] [client 49.37.242.14:64272] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fueeSd8WoG-6-XpDKvgAAAhQ"]
[Mon Jul 20 07:16:41.397408 2026] [security2:error] [pid 95128:tid 95516] [client 49.37.242.14:64272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fueeSd8WoG-6-XpDKvgAAAhQ"]
[Mon Jul 20 07:16:41.422421 2026] [security2:error] [pid 95126:tid 95330] [client 14.225.17.146:63371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4ftwpx5ks9joCJTKW1nAAAAdc"], referer: http://floorsourcestock.com/2020
[Mon Jul 20 07:16:41.500290 2026] [security2:error] [pid 95126:tid 95313] [client 77.110.127.138:61720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php'\\""] [unique_id "al4fuQpx5ks9joCJTKW10gAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.506845 2026] [security2:error] [pid 95126:tid 95308] [client 143.44.185.218:45718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fuQpx5ks9joCJTKW11AAAAcE"]
[Mon Jul 20 07:16:41.507031 2026] [security2:error] [pid 95126:tid 95308] [client 143.44.185.218:45718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fuQpx5ks9joCJTKW11AAAAcE"]
[Mon Jul 20 07:16:41.624811 2026] [security2:error] [pid 95128:tid 95613] [client 77.110.127.138:61629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fueeSd8WoG-6-XpDKxwAAAnU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.624906 2026] [security2:error] [pid 95128:tid 95613] [client 77.110.127.138:61629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fueeSd8WoG-6-XpDKxwAAAnU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.663374 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:61727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4fuY06NaEKF1g_MW2s-gAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:41.664562 2026] [security2:error] [pid 95126:tid 95266] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fuQpx5ks9joCJTKW1zwAAAZc"]
[Mon Jul 20 07:16:41.804607 2026] [security2:error] [pid 95128:tid 95549] [client 57.141.18.7:38312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fteeSd8WoG-6-XpDJ1wACNWc"]
[Mon Jul 20 07:16:41.900512 2026] [security2:error] [pid 95128:tid 95590] [client 206.135.24.10:49362] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.229"] [uri "/"] [unique_id "al4fueeSd8WoG-6-XpDK3AAAAl4"]
[Mon Jul 20 07:16:41.946674 2026] [security2:error] [pid 95126:tid 95347] [client 144.172.114.51:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/settings.php"] [unique_id "al4fuQpx5ks9joCJTKW14wAAAeg"]
[Mon Jul 20 07:16:41.958378 2026] [security2:error] [pid 95128:tid 95529] [client 206.135.24.10:44190] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.229"] [uri "/"] [unique_id "al4fueeSd8WoG-6-XpDK3wAAAiE"]
[Mon Jul 20 07:16:42.015891 2026] [security2:error] [pid 95128:tid 95610] [client 77.110.127.138:61643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fueeSd8WoG-6-XpDKzgAAAnI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:42.145834 2026] [security2:error] [pid 95128:tid 95534] [client 14.225.17.146:63042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4fuOeSd8WoG-6-XpDKZQAAAiY"], referer: http://cheesewithjam.com/2020
[Mon Jul 20 07:16:42.168793 2026] [security2:error] [pid 95128:tid 95589] [client 14.225.17.146:63092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4fuOeSd8WoG-6-XpDKawAAAl0"], referer: http://www.justinagrayman.com/2020
[Mon Jul 20 07:16:42.187089 2026] [security2:error] [pid 95126:tid 95200] [remote 154.66.198.148:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4fugpx5ks9joCJTKW18AABnEc"]
[Mon Jul 20 07:16:42.241192 2026] [security2:error] [pid 95126:tid 95345] [client 134.199.169.16:61168] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webdisk.sanifidensolutions.com"] [uri "/___proxy_subdomain_webdisk/wp-login.php"] [unique_id "al4fugpx5ks9joCJTKW1-wAAAeY"]
[Mon Jul 20 07:16:42.273187 2026] [security2:error] [pid 95128:tid 95582] [client 88.241.67.160:53909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fuueSd8WoG-6-XpDK_gAAAlY"]
[Mon Jul 20 07:16:42.273299 2026] [security2:error] [pid 95128:tid 95582] [client 88.241.67.160:53909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fuueSd8WoG-6-XpDK_gAAAlY"]
[Mon Jul 20 07:16:42.330567 2026] [security2:error] [pid 95128:tid 95536] [client 77.110.127.138:61644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fuueSd8WoG-6-XpDK5QAAAig"]
[Mon Jul 20 07:16:42.376256 2026] [security2:error] [pid 95128:tid 95578] [client 194.61.41.64:42001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fuueSd8WoG-6-XpDK7AAAAlI"]
[Mon Jul 20 07:16:42.441386 2026] [security2:error] [pid 95128:tid 95454] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fuueSd8WoG-6-XpDLDwACRkM"]
[Mon Jul 20 07:16:42.441554 2026] [security2:error] [pid 95128:tid 95566] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fuueSd8WoG-6-XpDLDwACRkM"]
[Mon Jul 20 07:16:42.544620 2026] [security2:error] [pid 95126:tid 95382] [client 50.116.65.227:37324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4fugpx5ks9joCJTKW2BAAAAgs"]
[Mon Jul 20 07:16:42.557345 2026] [security2:error] [pid 95128:tid 95557] [client 50.116.65.227:37340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4fuueSd8WoG-6-XpDLFgAAAj0"]
[Mon Jul 20 07:16:42.625887 2026] [security2:error] [pid 95128:tid 95625] [client 77.110.127.138:61564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4fuueSd8WoG-6-XpDLDQAAAoE"]
[Mon Jul 20 07:16:42.737080 2026] [security2:error] [pid 95126:tid 95204] [remote 154.66.198.148:42718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4fugpx5ks9joCJTKW2CwABzks"], referer: https://peoplestrategies.us/wp-login.php
[Mon Jul 20 07:16:43.281511 2026] [security2:error] [pid 94831:tid 95034] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fu406NaEKF1g_MW2tDwAAAEk"]
[Mon Jul 20 07:16:43.588074 2026] [security2:error] [pid 94831:tid 95032] [client 103.176.215.66:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fu406NaEKF1g_MW2tFgAAAEc"]
[Mon Jul 20 07:16:43.588421 2026] [security2:error] [pid 94831:tid 95032] [client 103.176.215.66:64350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fu406NaEKF1g_MW2tFgAAAEc"]
[Mon Jul 20 07:16:43.643268 2026] [security2:error] [pid 95126:tid 95362] [client 144.172.114.51:51548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/administrator/.env"] [unique_id "al4fuwpx5ks9joCJTKW2FwAAAfc"]
[Mon Jul 20 07:16:43.792190 2026] [security2:error] [pid 95128:tid 95547] [client 14.225.17.146:56773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4fuueSd8WoG-6-XpDK8gAAAjM"]
[Mon Jul 20 07:16:43.948836 2026] [security2:error] [pid 95128:tid 95522] [client 14.225.17.146:62652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4fuueSd8WoG-6-XpDLCQAAAho"], referer: http://nurturemarple.co.uk/2020
[Mon Jul 20 07:16:43.954206 2026] [security2:error] [pid 95128:tid 95584] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fu-eSd8WoG-6-XpDLYgAAAlg"]
[Mon Jul 20 07:16:44.021039 2026] [security2:error] [pid 95128:tid 95478] [remote 152.228.213.32:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fvOeSd8WoG-6-XpDLcgACils"]
[Mon Jul 20 07:16:44.085404 2026] [security2:error] [pid 95128:tid 95624] [client 157.20.138.62:58577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fvOeSd8WoG-6-XpDLeQAAAoA"]
[Mon Jul 20 07:16:44.085587 2026] [security2:error] [pid 95128:tid 95624] [client 157.20.138.62:58577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fvOeSd8WoG-6-XpDLeQAAAoA"]
[Mon Jul 20 07:16:44.109463 2026] [security2:error] [pid 95128:tid 95557] [client 77.110.127.138:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fvOeSd8WoG-6-XpDLfAAAAj0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:44.120029 2026] [security2:error] [pid 95128:tid 95430] [remote 57.141.18.88:41016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2887329"] [unique_id "al4fvOeSd8WoG-6-XpDLewACiys"]
[Mon Jul 20 07:16:44.179722 2026] [security2:error] [pid 95128:tid 95643] [client 187.16.64.216:49725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fvOeSd8WoG-6-XpDLfgAAApM"]
[Mon Jul 20 07:16:44.179848 2026] [security2:error] [pid 95128:tid 95643] [client 187.16.64.216:49725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fvOeSd8WoG-6-XpDLfgAAApM"]
[Mon Jul 20 07:16:44.208103 2026] [security2:error] [pid 95128:tid 95574] [client 13.232.231.177:35744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fvOeSd8WoG-6-XpDLggAAAk4"]
[Mon Jul 20 07:16:44.208196 2026] [security2:error] [pid 95128:tid 95574] [client 13.232.231.177:35744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4fvOeSd8WoG-6-XpDLggAAAk4"]
[Mon Jul 20 07:16:44.210375 2026] [security2:error] [pid 95128:tid 95458] [remote 152.228.213.32:49360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4fvOeSd8WoG-6-XpDLgAACUEc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:16:44.238100 2026] [security2:error] [pid 94831:tid 94891] [remote 45.84.107.182:62685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fvI06NaEKF1g_MW2tHAAAUDs"], referer: https://verdunestate.com/contact/
[Mon Jul 20 07:16:44.417969 2026] [security2:error] [pid 95128:tid 95626] [client 50.116.65.227:37370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4fvOeSd8WoG-6-XpDLdQAAAoI"]
[Mon Jul 20 07:16:44.497395 2026] [security2:error] [pid 95126:tid 95285] [client 14.225.17.146:63152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4fugpx5ks9joCJTKW15wAAAao"], referer: http://drewsasburyparkbeachhouse.com/2020
[Mon Jul 20 07:16:44.578328 2026] [core:error] [pid 95128:tid 95639] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:44.578353 2026] [core:error] [pid 95128:tid 95639] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:44.579073 2026] [security2:error] [pid 95128:tid 95543] [client 57.141.18.39:62873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fueeSd8WoG-6-XpDKrwACL3w"]
[Mon Jul 20 07:16:44.624927 2026] [security2:error] [pid 94831:tid 95064] [client 50.116.65.227:37372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4fvI06NaEKF1g_MW2tHQAAAGc"]
[Mon Jul 20 07:16:44.652361 2026] [security2:error] [pid 95126:tid 95351] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fvApx5ks9joCJTKW2JAAAAew"]
[Mon Jul 20 07:16:44.902451 2026] [security2:error] [pid 95128:tid 95559] [client 14.225.17.146:58539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4fu-eSd8WoG-6-XpDLTAAAAj8"], referer: http://chestermonty.com/2020
[Mon Jul 20 07:16:44.914407 2026] [security2:error] [pid 95128:tid 95592] [client 14.225.17.146:62907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4fvOeSd8WoG-6-XpDLpwAAAmA"], referer: https://nurturemarple.co.uk/2020
[Mon Jul 20 07:16:44.946913 2026] [security2:error] [pid 95126:tid 95369] [client 77.110.127.138:61786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fvApx5ks9joCJTKW2KwAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:44.947007 2026] [security2:error] [pid 95126:tid 95369] [client 77.110.127.138:61786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fvApx5ks9joCJTKW2KwAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:45.105211 2026] [security2:error] [pid 95128:tid 95507] [remote 5.161.225.162:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fveeSd8WoG-6-XpDLuQACi3g"]
[Mon Jul 20 07:16:45.345292 2026] [security2:error] [pid 95128:tid 95630] [client 14.225.17.146:56746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4fvOeSd8WoG-6-XpDLrgAAAoY"], referer: http://overloadcomedy.com/2020
[Mon Jul 20 07:16:45.369087 2026] [security2:error] [pid 95126:tid 95377] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fvQpx5ks9joCJTKW2MwAAAgY"]
[Mon Jul 20 07:16:45.417370 2026] [security2:error] [pid 95128:tid 95419] [remote 5.161.225.162:60034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4fveeSd8WoG-6-XpDLxAACjSA"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 07:16:45.448202 2026] [security2:error] [pid 95128:tid 95604] [client 14.225.17.146:56817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4fu-eSd8WoG-6-XpDLXAAAAmw"], referer: http://nomorewetsheets.net/2020
[Mon Jul 20 07:16:45.599914 2026] [security2:error] [pid 95128:tid 95552] [client 34.90.235.227:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "antiquickpick.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4fveeSd8WoG-6-XpDLzQAAAjg"]
[Mon Jul 20 07:16:45.600014 2026] [security2:error] [pid 95128:tid 95552] [client 34.90.235.227:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "antiquickpick.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4fveeSd8WoG-6-XpDLzQAAAjg"]
[Mon Jul 20 07:16:45.811173 2026] [security2:error] [pid 95126:tid 95259] [client 82.102.27.163:57334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4fvQpx5ks9joCJTKW2QgAAAZA"]
[Mon Jul 20 07:16:45.811294 2026] [security2:error] [pid 95126:tid 95259] [client 82.102.27.163:57334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4fvQpx5ks9joCJTKW2QgAAAZA"]
[Mon Jul 20 07:16:45.829806 2026] [security2:error] [pid 95128:tid 95631] [client 14.225.17.146:62620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4fveeSd8WoG-6-XpDL1gAAAoc"], referer: https://chestermonty.com/2020
[Mon Jul 20 07:16:45.856409 2026] [security2:error] [pid 95126:tid 95262] [client 14.225.17.146:62939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4fvApx5ks9joCJTKW2KAAAAZM"], referer: http://backandneckpainrelieflaceychiropractor.com/2020
[Mon Jul 20 07:16:46.082857 2026] [security2:error] [pid 94831:tid 95044] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fvY06NaEKF1g_MW2tKwAAAFM"]
[Mon Jul 20 07:16:46.162232 2026] [security2:error] [pid 94831:tid 95059] [client 184.154.139.41:58490] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/divi-builder/includes/builder/scripts/jquery.mobile.custom.min.js"] [unique_id "al4fvo06NaEKF1g_MW2tLgAAAGI"]
[Mon Jul 20 07:16:46.347839 2026] [security2:error] [pid 95126:tid 95334] [client 77.110.127.138:61815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fvgpx5ks9joCJTKW2SgAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:46.742484 2026] [security2:error] [pid 95128:tid 95642] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fvueSd8WoG-6-XpDMIwAAApI"]
[Mon Jul 20 07:16:47.027792 2026] [security2:error] [pid 95128:tid 95638] [client 154.192.123.127:18252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fv-eSd8WoG-6-XpDMPAAAAo4"]
[Mon Jul 20 07:16:47.027888 2026] [security2:error] [pid 95128:tid 95638] [client 154.192.123.127:18252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fv-eSd8WoG-6-XpDMPAAAAo4"]
[Mon Jul 20 07:16:47.045312 2026] [security2:error] [pid 95128:tid 95635] [client 77.110.127.138:61837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fv-eSd8WoG-6-XpDMPgAAAos"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:47.561645 2026] [security2:error] [pid 95126:tid 95267] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fvwpx5ks9joCJTKW2UwAAAZg"]
[Mon Jul 20 07:16:47.695542 2026] [proxy:error] [pid 95128:tid 95524] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:16:47.695579 2026] [proxy_http:error] [pid 95128:tid 95524] [client 94.154.43.186:48390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:16:47.696249 2026] [proxy:error] [pid 95128:tid 95524] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:16:47.696274 2026] [proxy_http:error] [pid 95128:tid 95524] [client 94.154.43.186:48390] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:16:47.723867 2026] [security2:error] [pid 95128:tid 95630] [client 34.84.221.1:7435] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.savilerowtravel.com"] [uri "/wp-content/uploads/2016/12/Myanmar-country-image-450x253.jpg"] [unique_id "al4fv-eSd8WoG-6-XpDMXgAAAoY"]
[Mon Jul 20 07:16:47.838011 2026] [security2:error] [pid 95128:tid 95571] [client 201.49.69.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4fvueSd8WoG-6-XpDMFwAAAks"]
[Mon Jul 20 07:16:47.964468 2026] [security2:error] [pid 95126:tid 95288] [client 142.250.32.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.benbayly.co.nz"] [uri "/index.php"] [unique_id "al4fvwpx5ks9joCJTKW2YwABrWU"]
[Mon Jul 20 07:16:48.282776 2026] [security2:error] [pid 95128:tid 95603] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fwOeSd8WoG-6-XpDMegAAAms"]
[Mon Jul 20 07:16:48.634961 2026] [security2:error] [pid 95126:tid 95335] [client 104.234.53.83:29373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4fwApx5ks9joCJTKW2cwAAAdw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:48.840415 2026] [security2:error] [pid 95128:tid 95617] [client 77.110.127.138:61881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fwOeSd8WoG-6-XpDMrAAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:48.840518 2026] [security2:error] [pid 95128:tid 95617] [client 77.110.127.138:61881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fwOeSd8WoG-6-XpDMrAAAAnk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:48.974584 2026] [security2:error] [pid 95128:tid 95548] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fwOeSd8WoG-6-XpDMqQAAAjQ"]
[Mon Jul 20 07:16:49.268371 2026] [security2:error] [pid 95128:tid 95478] [remote 91.142.222.105:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4fweeSd8WoG-6-XpDMxQACgVs"]
[Mon Jul 20 07:16:49.319496 2026] [security2:error] [pid 95128:tid 95536] [client 201.27.111.74:51214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fweeSd8WoG-6-XpDMyAAAAig"]
[Mon Jul 20 07:16:49.319630 2026] [security2:error] [pid 95128:tid 95536] [client 201.27.111.74:51214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fweeSd8WoG-6-XpDMyAAAAig"]
[Mon Jul 20 07:16:49.422735 2026] [security2:error] [pid 95126:tid 95364] [client 184.154.139.41:60952] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/divi-builder/includes/builder/scripts/waypoints.min.js"] [unique_id "al4fwQpx5ks9joCJTKW2gAAAAfk"]
[Mon Jul 20 07:16:49.481332 2026] [security2:error] [pid 95128:tid 95633] [client 154.208.48.130:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fweeSd8WoG-6-XpDM1AAAAok"]
[Mon Jul 20 07:16:49.481443 2026] [security2:error] [pid 95128:tid 95633] [client 154.208.48.130:64139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fweeSd8WoG-6-XpDM1AAAAok"]
[Mon Jul 20 07:16:49.523888 2026] [security2:error] [pid 95128:tid 95394] [remote 91.142.222.105:40026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4fweeSd8WoG-6-XpDM2wACIgc"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:16:49.673308 2026] [security2:error] [pid 95128:tid 95517] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fweeSd8WoG-6-XpDM1gAAAhU"]
[Mon Jul 20 07:16:49.878448 2026] [security2:error] [pid 95128:tid 95642] [client 57.141.18.42:56666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fv-eSd8WoG-6-XpDMWAACkho"]
[Mon Jul 20 07:16:50.356638 2026] [security2:error] [pid 95126:tid 95271] [client 158.173.166.181:55437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fwgpx5ks9joCJTKW2jwAAAZw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:16:50.362505 2026] [security2:error] [pid 95128:tid 95572] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fwueSd8WoG-6-XpDNAAAAAkw"]
[Mon Jul 20 07:16:50.365999 2026] [security2:error] [pid 95126:tid 95285] [client 52.109.76.144:26946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fwgpx5ks9joCJTKW2kAAAAao"]
[Mon Jul 20 07:16:50.403046 2026] [security2:error] [pid 95126:tid 95290] [client 172.200.24.58:11361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fwgpx5ks9joCJTKW2kQAAAa8"]
[Mon Jul 20 07:16:50.474810 2026] [security2:error] [pid 95126:tid 95314] [client 103.144.65.217:49231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fwgpx5ks9joCJTKW2lQAAAcc"]
[Mon Jul 20 07:16:50.474964 2026] [security2:error] [pid 95126:tid 95314] [client 103.144.65.217:49231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fwgpx5ks9joCJTKW2lQAAAcc"]
[Mon Jul 20 07:16:50.479235 2026] [security2:error] [pid 95126:tid 95267] [client 172.200.24.58:11361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fwgpx5ks9joCJTKW2lgAAAZg"]
[Mon Jul 20 07:16:50.507434 2026] [security2:error] [pid 95126:tid 95315] [client 52.109.76.144:26946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fwgpx5ks9joCJTKW2lwAAAcg"]
[Mon Jul 20 07:16:50.594577 2026] [security2:error] [pid 95128:tid 95573] [client 45.162.72.208:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4fwueSd8WoG-6-XpDNDQAAAk0"]
[Mon Jul 20 07:16:50.829698 2026] [security2:error] [pid 95126:tid 95240] [remote 152.228.213.32:58088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fwgpx5ks9joCJTKW2nAAB9m8"]
[Mon Jul 20 07:16:50.829916 2026] [security2:error] [pid 95126:tid 95361] [client 152.228.213.32:58088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4fwgpx5ks9joCJTKW2nAAB9m8"]
[Mon Jul 20 07:16:50.857318 2026] [security2:error] [pid 95126:tid 95308] [client 57.141.18.73:61430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fwApx5ks9joCJTKW2cgABwWk"]
[Mon Jul 20 07:16:50.878022 2026] [autoindex:error] [pid 95128:tid 95557] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/languages/plugins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:50.913067 2026] [security2:error] [pid 95128:tid 95624] [client 57.141.18.85:51116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fwOeSd8WoG-6-XpDMnQACgAo"]
[Mon Jul 20 07:16:51.086628 2026] [security2:error] [pid 95128:tid 95497] [remote 41.185.8.252:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4fw-eSd8WoG-6-XpDNMQACLG4"]
[Mon Jul 20 07:16:51.287809 2026] [autoindex:error] [pid 95126:tid 95281] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/skins/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:51.289563 2026] [security2:error] [pid 95128:tid 95525] [client 57.141.18.32:61260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fweeSd8WoG-6-XpDMvQACHQ4"]
[Mon Jul 20 07:16:51.495534 2026] [security2:error] [pid 95128:tid 95588] [client 77.110.127.138:61945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fw-eSd8WoG-6-XpDNTAAAAlw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:51.727419 2026] [security2:error] [pid 95128:tid 95391] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fw-eSd8WoG-6-XpDNZwACTgQ"]
[Mon Jul 20 07:16:51.727560 2026] [security2:error] [pid 95128:tid 95574] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fw-eSd8WoG-6-XpDNZwACTgQ"]
[Mon Jul 20 07:16:51.730768 2026] [security2:error] [pid 94831:tid 95013] [client 185.93.182.171:54374] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4fw406NaEKF1g_MW2tSAAAADQ"]
[Mon Jul 20 07:16:51.730864 2026] [security2:error] [pid 94831:tid 95013] [client 185.93.182.171:54374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4fw406NaEKF1g_MW2tSAAAADQ"]
[Mon Jul 20 07:16:51.795017 2026] [security2:error] [pid 95128:tid 95516] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fw-eSd8WoG-6-XpDNZgAAAhQ"]
[Mon Jul 20 07:16:52.180741 2026] [security2:error] [pid 95128:tid 95546] [client 143.44.185.218:47218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fxOeSd8WoG-6-XpDNfwAAAjI"]
[Mon Jul 20 07:16:52.180836 2026] [security2:error] [pid 95128:tid 95546] [client 143.44.185.218:47218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fxOeSd8WoG-6-XpDNfwAAAjI"]
[Mon Jul 20 07:16:52.233275 2026] [security2:error] [pid 95128:tid 95405] [remote 41.185.8.252:36128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4fxOeSd8WoG-6-XpDNgAACQRI"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 07:16:52.275359 2026] [security2:error] [pid 95128:tid 95465] [remote 5.252.52.249:41226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4fxOeSd8WoG-6-XpDNgwACS04"]
[Mon Jul 20 07:16:52.289411 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:61973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fxApx5ks9joCJTKW2twAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:52.353715 2026] [security2:error] [pid 95128:tid 95518] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fxOeSd8WoG-6-XpDNfQAAAhY"]
[Mon Jul 20 07:16:52.375853 2026] [security2:error] [pid 95128:tid 95591] [client 74.7.227.179:38582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4fxOeSd8WoG-6-XpDNgQACX2c"], referer: https://tejasenvironmental.com/p=966995
[Mon Jul 20 07:16:52.409979 2026] [security2:error] [pid 95128:tid 95560] [client 57.141.18.53:48598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fwueSd8WoG-6-XpDNBQACQDQ"]
[Mon Jul 20 07:16:52.485513 2026] [security2:error] [pid 95128:tid 95504] [remote 5.252.52.249:41226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4fxOeSd8WoG-6-XpDNjwACLnU"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:16:52.585455 2026] [security2:error] [pid 95128:tid 95563] [client 57.141.18.75:37502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fwueSd8WoG-6-XpDNFgACQ10"]
[Mon Jul 20 07:16:52.689378 2026] [security2:error] [pid 95126:tid 95345] [client 77.110.127.138:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fxApx5ks9joCJTKW2wgAAAeY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:52.689487 2026] [security2:error] [pid 95126:tid 95345] [client 77.110.127.138:61976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fxApx5ks9joCJTKW2wgAAAeY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:52.833265 2026] [security2:error] [pid 95128:tid 95630] [client 88.241.67.160:55187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fxOeSd8WoG-6-XpDNowAAAoY"]
[Mon Jul 20 07:16:52.834093 2026] [security2:error] [pid 95128:tid 95630] [client 88.241.67.160:55187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fxOeSd8WoG-6-XpDNowAAAoY"]
[Mon Jul 20 07:16:52.866931 2026] [autoindex:error] [pid 95128:tid 95554] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/jquery/ui/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:52.960534 2026] [security2:error] [pid 95128:tid 95438] [remote 51.195.39.149:35952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "holistichealthmassagenz.com"] [uri "/"] [unique_id "al4fxOeSd8WoG-6-XpDNqwACMDM"]
[Mon Jul 20 07:16:53.029573 2026] [security2:error] [pid 95128:tid 95421] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fxeeSd8WoG-6-XpDNrQACKSI"]
[Mon Jul 20 07:16:53.029852 2026] [security2:error] [pid 95128:tid 95537] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fxeeSd8WoG-6-XpDNrQACKSI"]
[Mon Jul 20 07:16:53.052562 2026] [security2:error] [pid 95126:tid 95357] [client 184.154.139.41:35318] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/divi-builder/includes/builder/scripts/jquery.fitvids.js"] [unique_id "al4fxQpx5ks9joCJTKW2xwAAAfI"]
[Mon Jul 20 07:16:53.297020 2026] [security2:error] [pid 95128:tid 95598] [client 49.37.242.14:64744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fxeeSd8WoG-6-XpDNvAAAAmY"]
[Mon Jul 20 07:16:53.297189 2026] [security2:error] [pid 95128:tid 95598] [client 49.37.242.14:64744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4fxeeSd8WoG-6-XpDNvAAAAmY"]
[Mon Jul 20 07:16:53.298724 2026] [security2:error] [pid 95128:tid 95595] [client 184.154.139.41:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al4fxeeSd8WoG-6-XpDNwQAAAmM"]
[Mon Jul 20 07:16:53.302733 2026] [security2:error] [pid 95126:tid 95302] [client 184.154.139.41:35460] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/jetpack/readme.txt"] [unique_id "al4fxQpx5ks9joCJTKW2yAAAAbs"]
[Mon Jul 20 07:16:53.353834 2026] [security2:error] [pid 95128:tid 95526] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fxeeSd8WoG-6-XpDNwAAAAh4"]
[Mon Jul 20 07:16:53.478131 2026] [security2:error] [pid 95128:tid 95583] [client 77.110.127.138:61993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fxeeSd8WoG-6-XpDNyAAAAlc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:53.563691 2026] [security2:error] [pid 94831:tid 95038] [client 184.154.139.41:0] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/divi-builder/changelog.txt"] [unique_id "al4fxY06NaEKF1g_MW2tUgAAAE0"]
[Mon Jul 20 07:16:53.568479 2026] [security2:error] [pid 95128:tid 95613] [client 184.154.139.41:35620] ModSecurity: Warning. Matched phrase "SiteLockSpider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/wp-content/plugins/divi-builder/changelog.txt"] [unique_id "al4fxeeSd8WoG-6-XpDNywAAAnU"]
[Mon Jul 20 07:16:53.942776 2026] [security2:error] [pid 95128:tid 95556] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fxeeSd8WoG-6-XpDN2wAAAjw"]
[Mon Jul 20 07:16:54.026546 2026] [security2:error] [pid 95128:tid 95546] [client 77.110.127.138:62035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fxueSd8WoG-6-XpDN7gAAAjI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:54.094626 2026] [security2:error] [pid 95126:tid 95288] [client 103.176.215.66:64868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fxgpx5ks9joCJTKW2zwAAAa0"]
[Mon Jul 20 07:16:54.094803 2026] [security2:error] [pid 95126:tid 95288] [client 103.176.215.66:64868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4fxgpx5ks9joCJTKW2zwAAAa0"]
[Mon Jul 20 07:16:54.145021 2026] [core:error] [pid 95128:tid 95533] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:54.145044 2026] [core:error] [pid 95128:tid 95533] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:16:54.168993 2026] [security2:error] [pid 95126:tid 95339] [client 57.141.18.26:40214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fxApx5ks9joCJTKW2tgAB4Hs"]
[Mon Jul 20 07:16:54.446637 2026] [security2:error] [pid 95128:tid 95576] [client 57.141.18.97:21112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fxOeSd8WoG-6-XpDNkQACUA8"]
[Mon Jul 20 07:16:54.471876 2026] [security2:error] [pid 95128:tid 95563] [client 117.211.236.168:56133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fxueSd8WoG-6-XpDOCgAAAkM"]
[Mon Jul 20 07:16:54.471965 2026] [security2:error] [pid 95128:tid 95563] [client 117.211.236.168:56133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4fxueSd8WoG-6-XpDOCgAAAkM"]
[Mon Jul 20 07:16:54.474550 2026] [autoindex:error] [pid 95126:tid 95365] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/themes/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:54.770603 2026] [proxy:error] [pid 95128:tid 95590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:16:54.770657 2026] [proxy_http:error] [pid 95128:tid 95590] [client 94.154.43.186:48404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:16:54.771090 2026] [proxy:error] [pid 95128:tid 95590] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:16:54.771117 2026] [proxy_http:error] [pid 95128:tid 95590] [client 94.154.43.186:48404] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:16:54.782082 2026] [security2:error] [pid 95126:tid 95381] [client 187.16.64.216:50385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fxgpx5ks9joCJTKW23QAAAgo"]
[Mon Jul 20 07:16:54.782200 2026] [security2:error] [pid 95126:tid 95381] [client 187.16.64.216:50385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4fxgpx5ks9joCJTKW23QAAAgo"]
[Mon Jul 20 07:16:54.804094 2026] [security2:error] [pid 95128:tid 95564] [client 157.20.138.62:59138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fxueSd8WoG-6-XpDOJAAAAkQ"]
[Mon Jul 20 07:16:54.804480 2026] [security2:error] [pid 95128:tid 95564] [client 157.20.138.62:59138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4fxueSd8WoG-6-XpDOJAAAAkQ"]
[Mon Jul 20 07:16:55.104496 2026] [security2:error] [pid 95128:tid 95617] [client 194.61.41.64:42001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fxueSd8WoG-6-XpDOJQAAAnk"]
[Mon Jul 20 07:16:55.288331 2026] [security2:error] [pid 95126:tid 95267] [client 104.234.53.54:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4fxwpx5ks9joCJTKW27gAAAZg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:55.433158 2026] [security2:error] [pid 95128:tid 95635] [client 57.141.18.12:32542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fxeeSd8WoG-6-XpDNzQACi18"]
[Mon Jul 20 07:16:55.665303 2026] [security2:error] [pid 95128:tid 95565] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fx-eSd8WoG-6-XpDOPQAAAkU"]
[Mon Jul 20 07:16:55.694988 2026] [security2:error] [pid 95128:tid 95572] [client 34.147.91.161:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.antiquickpick.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4fx-eSd8WoG-6-XpDORwAAAkw"]
[Mon Jul 20 07:16:55.695097 2026] [security2:error] [pid 95128:tid 95572] [client 34.147.91.161:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.antiquickpick.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4fx-eSd8WoG-6-XpDORwAAAkw"]
[Mon Jul 20 07:16:56.205802 2026] [autoindex:error] [pid 94831:tid 95041] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/themes/inlite/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:56.390456 2026] [security2:error] [pid 95126:tid 95359] [client 57.141.18.104:59888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fxgpx5ks9joCJTKW21gAB9HU"]
[Mon Jul 20 07:16:56.793593 2026] [security2:error] [pid 95126:tid 95320] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fyApx5ks9joCJTKW3EwAAAc0"]
[Mon Jul 20 07:16:56.828082 2026] [security2:error] [pid 94831:tid 94965] [client 18.140.64.130:11348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4fyI06NaEKF1g_MW2taAAAAAQ"]
[Mon Jul 20 07:16:57.487877 2026] [autoindex:error] [pid 95128:tid 95519] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/plupload/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:57.562864 2026] [security2:error] [pid 95128:tid 95630] [client 154.192.123.127:18726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fyeeSd8WoG-6-XpDOqAAAAoY"]
[Mon Jul 20 07:16:57.563015 2026] [security2:error] [pid 95128:tid 95630] [client 154.192.123.127:18726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4fyeeSd8WoG-6-XpDOqAAAAoY"]
[Mon Jul 20 07:16:57.737490 2026] [security2:error] [pid 95128:tid 95542] [client 104.234.53.53:35699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4fyeeSd8WoG-6-XpDOrgAAAi4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:16:57.802625 2026] [security2:error] [pid 95128:tid 95583] [client 18.142.226.106:64962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4fyeeSd8WoG-6-XpDOuAAAAlc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:16:57.878556 2026] [autoindex:error] [pid 95128:tid 95584] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/rest-api/fields/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:58.013773 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:62120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fygpx5ks9joCJTKW3KAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:58.021155 2026] [security2:error] [pid 95126:tid 95311] [client 77.110.127.138:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fygpx5ks9joCJTKW3KQAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:58.021350 2026] [security2:error] [pid 95126:tid 95311] [client 77.110.127.138:62122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fygpx5ks9joCJTKW3KQAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:58.189984 2026] [security2:error] [pid 95128:tid 95585] [client 77.110.127.138:62126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fyueSd8WoG-6-XpDO1wAAAlk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:58.475104 2026] [security2:error] [pid 95128:tid 95591] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fyueSd8WoG-6-XpDO3QAAAl8"]
[Mon Jul 20 07:16:58.600477 2026] [security2:error] [pid 95128:tid 95425] [remote 57.141.18.20:42086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3359665"] [unique_id "al4fyueSd8WoG-6-XpDO9QACMiY"]
[Mon Jul 20 07:16:58.753947 2026] [security2:error] [pid 95128:tid 95428] [remote 45.84.107.182:61251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fyueSd8WoG-6-XpDO_AACHCk"], referer: https://verdunestate.com/building-for-sale-geitawi-beirut/
[Mon Jul 20 07:16:58.848792 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:62148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fygpx5ks9joCJTKW3NAAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:58.979094 2026] [autoindex:error] [pid 95128:tid 95538] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/code/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:59.009014 2026] [security2:error] [pid 95126:tid 95313] [client 98.159.234.160:42975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fywpx5ks9joCJTKW3OgAAAcY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:16:59.380924 2026] [autoindex:error] [pid 95128:tid 95624] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/archives/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:59.668043 2026] [security2:error] [pid 95128:tid 95524] [client 77.110.127.138:62166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fy-eSd8WoG-6-XpDPPAAAAhw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:16:59.780757 2026] [autoindex:error] [pid 95128:tid 95541] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/css/dist/components/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:16:59.792454 2026] [security2:error] [pid 95128:tid 95618] [client 201.27.111.74:51724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fy-eSd8WoG-6-XpDPSAAAAno"]
[Mon Jul 20 07:16:59.792559 2026] [security2:error] [pid 95128:tid 95618] [client 201.27.111.74:51724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4fy-eSd8WoG-6-XpDPSAAAAno"]
[Mon Jul 20 07:17:00.138227 2026] [security2:error] [pid 95128:tid 95595] [client 14.225.17.146:49697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4fzOeSd8WoG-6-XpDPUQAAAmM"], referer: http://headachescarpaltunnelfibromyalgia.com/2019
[Mon Jul 20 07:17:00.188456 2026] [security2:error] [pid 95128:tid 95637] [client 57.141.18.12:32592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fyueSd8WoG-6-XpDO2gACjTo"]
[Mon Jul 20 07:17:00.341878 2026] [security2:error] [pid 95128:tid 95521] [client 14.225.17.146:53329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4fzOeSd8WoG-6-XpDPZAAAAhk"], referer: http://alaraycreative.com/2019
[Mon Jul 20 07:17:00.353311 2026] [security2:error] [pid 94831:tid 95037] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fzI06NaEKF1g_MW2tewAAAEw"]
[Mon Jul 20 07:17:00.372604 2026] [security2:error] [pid 95128:tid 95548] [client 144.172.114.51:33400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.website-fa490990.threethirds.co"] [uri "/administrator/.env"] [unique_id "al4fzOeSd8WoG-6-XpDPawAAAjQ"]
[Mon Jul 20 07:17:00.416010 2026] [security2:error] [pid 95126:tid 95280] [client 104.234.53.88:41657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4fzApx5ks9joCJTKW3RwAAAaU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:00.578663 2026] [security2:error] [pid 95128:tid 95600] [client 154.208.48.130:64651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fzOeSd8WoG-6-XpDPgQAAAmg"]
[Mon Jul 20 07:17:00.579444 2026] [security2:error] [pid 95128:tid 95600] [client 154.208.48.130:64651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4fzOeSd8WoG-6-XpDPgQAAAmg"]
[Mon Jul 20 07:17:01.013258 2026] [security2:error] [pid 95128:tid 95585] [client 14.225.17.146:61732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4fzOeSd8WoG-6-XpDPmAAAAlk"], referer: http://cheesewithjam.com/2019
[Mon Jul 20 07:17:01.013267 2026] [security2:error] [pid 95128:tid 95570] [client 57.141.18.115:51130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fy-eSd8WoG-6-XpDPKAACSkE"]
[Mon Jul 20 07:17:01.063682 2026] [security2:error] [pid 95128:tid 95615] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fzOeSd8WoG-6-XpDPlwAAAnc"]
[Mon Jul 20 07:17:01.142575 2026] [security2:error] [pid 95128:tid 95562] [client 103.144.65.217:49687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fzeeSd8WoG-6-XpDPqwAAAkI"]
[Mon Jul 20 07:17:01.143591 2026] [security2:error] [pid 95128:tid 95562] [client 103.144.65.217:49687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4fzeeSd8WoG-6-XpDPqwAAAkI"]
[Mon Jul 20 07:17:01.174657 2026] [security2:error] [pid 94831:tid 95065] [client 34.91.36.231:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.cheaterreader.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4fzY06NaEKF1g_MW2tfwAAAGg"]
[Mon Jul 20 07:17:01.174812 2026] [security2:error] [pid 94831:tid 95065] [client 34.91.36.231:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.cheaterreader.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4fzY06NaEKF1g_MW2tfwAAAGg"]
[Mon Jul 20 07:17:01.562928 2026] [security2:error] [pid 95128:tid 95561] [client 14.225.17.146:61265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4fzeeSd8WoG-6-XpDPxwAAAkE"], referer: http://koaconsultants.com/2019
[Mon Jul 20 07:17:01.601259 2026] [security2:error] [pid 95128:tid 95604] [client 14.225.17.146:52933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4fzeeSd8WoG-6-XpDPygAAAmw"]
[Mon Jul 20 07:17:01.711232 2026] [security2:error] [pid 95128:tid 95543] [client 57.141.18.77:62882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fzOeSd8WoG-6-XpDPXAACLys"]
[Mon Jul 20 07:17:01.761452 2026] [security2:error] [pid 95128:tid 95628] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fzeeSd8WoG-6-XpDP0QAAAoQ"]
[Mon Jul 20 07:17:01.792141 2026] [security2:error] [pid 95128:tid 95401] [remote 57.141.18.116:34960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4197835"] [unique_id "al4fzeeSd8WoG-6-XpDP4wAChw4"]
[Mon Jul 20 07:17:01.964660 2026] [security2:error] [pid 95128:tid 95566] [client 77.110.127.138:62197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fzeeSd8WoG-6-XpDP-AAAAkY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:02.075861 2026] [security2:error] [pid 95126:tid 95276] [client 47.128.118.221:35258] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.willowbranchequines.org"] [uri "/cPanel_magic_revision_1648610195/unprotected/cpanel/fonts/open_sans/OpenSans-Regular-webfont.woff"] [unique_id "al4fzgpx5ks9joCJTKW3UgAAAaE"]
[Mon Jul 20 07:17:02.094929 2026] [security2:error] [pid 95126:tid 95311] [client 52.35.20.1:8936] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "liquidationteam.com"] [uri "/"] [unique_id "al4fzgpx5ks9joCJTKW3VAAAAcQ"]
[Mon Jul 20 07:17:02.281706 2026] [security2:error] [pid 94831:tid 94939] [remote 100.42.189.89:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4fzo06NaEKF1g_MW2thQAAHWs"]
[Mon Jul 20 07:17:02.306163 2026] [autoindex:error] [pid 95128:tid 95604] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/pullquote/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:02.433151 2026] [security2:error] [pid 95126:tid 95249] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fzgpx5ks9joCJTKW3WgABz3g"]
[Mon Jul 20 07:17:02.433277 2026] [security2:error] [pid 95126:tid 95322] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4fzgpx5ks9joCJTKW3WgABz3g"]
[Mon Jul 20 07:17:02.462862 2026] [security2:error] [pid 95126:tid 95356] [client 114.119.135.120:37191] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ferrellroofing.com"] [uri "/011_11"] [unique_id "al4fzgpx5ks9joCJTKW3WwAAAfE"], referer: https://www.ferrellroofing.com/011_11/
[Mon Jul 20 07:17:02.480683 2026] [security2:error] [pid 94831:tid 94945] [remote 100.42.189.89:52102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4fzo06NaEKF1g_MW2thwAAV3E"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:17:02.780833 2026] [security2:error] [pid 95126:tid 95359] [client 77.110.127.138:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fzgpx5ks9joCJTKW3aQAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:02.780959 2026] [security2:error] [pid 95126:tid 95359] [client 77.110.127.138:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4fzgpx5ks9joCJTKW3aQAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:02.800855 2026] [autoindex:error] [pid 95128:tid 95530] [client 34.11.82.158:57219] AH01276: Cannot serve directory /home4/sbdwidmy/public_html/website_7ca3a27a/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:02.851068 2026] [security2:error] [pid 95128:tid 95575] [client 143.44.185.218:48690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fzueSd8WoG-6-XpDQMgAAAk8"]
[Mon Jul 20 07:17:02.851196 2026] [security2:error] [pid 95128:tid 95575] [client 143.44.185.218:48690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4fzueSd8WoG-6-XpDQMgAAAk8"]
[Mon Jul 20 07:17:02.894695 2026] [security2:error] [pid 95126:tid 95340] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fzgpx5ks9joCJTKW3ZgAAAeE"]
[Mon Jul 20 07:17:02.965052 2026] [security2:error] [pid 95128:tid 95591] [client 14.225.17.146:49703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4fzeeSd8WoG-6-XpDPtwAAAl8"], referer: http://superiorcopywriting.com/2019
[Mon Jul 20 07:17:03.052348 2026] [security2:error] [pid 95128:tid 95524] [client 144.172.114.51:33414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/cms/.env"] [unique_id "al4fz-eSd8WoG-6-XpDQPwAAAhw"]
[Mon Jul 20 07:17:03.084151 2026] [security2:error] [pid 95128:tid 95567] [client 14.225.17.146:53360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4fzueSd8WoG-6-XpDQNgAAAkc"], referer: http://cephasnext.com/2019
[Mon Jul 20 07:17:03.367818 2026] [security2:error] [pid 94831:tid 95013] [client 172.200.24.58:8896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fz406NaEKF1g_MW2tjQAAADQ"]
[Mon Jul 20 07:17:03.423010 2026] [security2:error] [pid 94831:tid 94972] [client 172.200.24.58:8896] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fz406NaEKF1g_MW2tjwAAAAs"]
[Mon Jul 20 07:17:03.449459 2026] [security2:error] [pid 95126:tid 95171] [remote 188.166.241.141:48286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4fzwpx5ks9joCJTKW3egABnCo"]
[Mon Jul 20 07:17:03.476600 2026] [security2:error] [pid 95128:tid 95589] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4fz-eSd8WoG-6-XpDQQQAAAl0"]
[Mon Jul 20 07:17:03.485595 2026] [security2:error] [pid 95126:tid 95269] [client 88.241.67.160:54059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fzwpx5ks9joCJTKW3fAAAAZo"]
[Mon Jul 20 07:17:03.486345 2026] [security2:error] [pid 95126:tid 95269] [client 88.241.67.160:54059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4fzwpx5ks9joCJTKW3fAAAAZo"]
[Mon Jul 20 07:17:03.524526 2026] [security2:error] [pid 95126:tid 95280] [client 77.110.127.138:62258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fzwpx5ks9joCJTKW3ewAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:03.563628 2026] [security2:error] [pid 95128:tid 95585] [client 194.61.41.64:42001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4fz-eSd8WoG-6-XpDQVAAAAlk"]
[Mon Jul 20 07:17:03.686860 2026] [security2:error] [pid 95126:tid 95382] [client 52.109.16.52:25734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4fzwpx5ks9joCJTKW3ggAAAgs"]
[Mon Jul 20 07:17:03.735278 2026] [security2:error] [pid 95126:tid 95318] [client 52.109.16.52:25734] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4fzwpx5ks9joCJTKW3hAAAAcs"]
[Mon Jul 20 07:17:03.796058 2026] [security2:error] [pid 95126:tid 95178] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fzwpx5ks9joCJTKW3hgABkTE"]
[Mon Jul 20 07:17:03.796204 2026] [security2:error] [pid 95126:tid 95260] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4fzwpx5ks9joCJTKW3hgABkTE"]
[Mon Jul 20 07:17:03.864613 2026] [security2:error] [pid 94831:tid 94991] [client 77.110.127.138:62266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4fz406NaEKF1g_MW2tlAAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:03.892676 2026] [security2:error] [pid 95126:tid 95179] [remote 45.84.107.182:61253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4fzwpx5ks9joCJTKW3jAAB1DI"], referer: https://verdunestate.com/5903-2/
[Mon Jul 20 07:17:03.924115 2026] [security2:error] [pid 95128:tid 95591] [client 82.102.18.116:39424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4fz-eSd8WoG-6-XpDQbQAAAl8"]
[Mon Jul 20 07:17:04.046523 2026] [security2:error] [pid 95128:tid 95583] [client 57.141.18.11:54924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fzueSd8WoG-6-XpDQHgACV04"]
[Mon Jul 20 07:17:04.063954 2026] [autoindex:error] [pid 95128:tid 95598] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/comments-pagination-numbers/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:04.147612 2026] [core:error] [pid 95126:tid 95264] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:04.147643 2026] [core:error] [pid 95126:tid 95264] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:04.153675 2026] [security2:error] [pid 95126:tid 95307] [client 14.225.17.146:61215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4fzwpx5ks9joCJTKW3jQAAAcA"], referer: http://sesamegreenbeans.com/2019
[Mon Jul 20 07:17:04.257306 2026] [security2:error] [pid 95126:tid 95174] [remote 188.166.241.141:48286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4f0Apx5ks9joCJTKW3ogABjy0"], referer: https://709fx.com/wp-login.php
[Mon Jul 20 07:17:04.258526 2026] [security2:error] [pid 94831:tid 95056] [client 82.102.18.116:39436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.fineartsfactory.net"] [uri "/xmlrpc.php"] [unique_id "al4f0I06NaEKF1g_MW2tlgAAAF8"]
[Mon Jul 20 07:17:04.401661 2026] [security2:error] [pid 94831:tid 94977] [client 49.37.242.14:65182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f0I06NaEKF1g_MW2tmQAAABA"]
[Mon Jul 20 07:17:04.401801 2026] [security2:error] [pid 94831:tid 94977] [client 49.37.242.14:65182] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f0I06NaEKF1g_MW2tmQAAABA"]
[Mon Jul 20 07:17:04.634123 2026] [security2:error] [pid 95128:tid 95540] [client 194.61.41.64:42001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f0OeSd8WoG-6-XpDQoQAAAiw"]
[Mon Jul 20 07:17:04.725328 2026] [security2:error] [pid 95126:tid 95275] [client 103.176.215.66:65395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f0Apx5ks9joCJTKW3rQAAAaA"]
[Mon Jul 20 07:17:04.725945 2026] [security2:error] [pid 95126:tid 95275] [client 103.176.215.66:65395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f0Apx5ks9joCJTKW3rQAAAaA"]
[Mon Jul 20 07:17:04.948637 2026] [security2:error] [pid 95128:tid 95553] [client 82.102.18.116:39444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4f0OeSd8WoG-6-XpDQvQAAAjk"]
[Mon Jul 20 07:17:05.143302 2026] [security2:error] [pid 94831:tid 95046] [client 57.141.18.29:21174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fz406NaEKF1g_MW2tkgAAVXg"]
[Mon Jul 20 07:17:05.192082 2026] [security2:error] [pid 95128:tid 95575] [client 14.225.17.146:60952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4f0eeSd8WoG-6-XpDQwwAAAk8"], referer: https://sesamegreenbeans.com/2019
[Mon Jul 20 07:17:05.208650 2026] [security2:error] [pid 94831:tid 95029] [client 77.110.127.138:62281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f0Y06NaEKF1g_MW2tnQAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:05.258672 2026] [security2:error] [pid 94831:tid 94987] [client 82.102.18.116:39446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4f0Y06NaEKF1g_MW2tngAAABo"]
[Mon Jul 20 07:17:05.283584 2026] [security2:error] [pid 95128:tid 95521] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f0eeSd8WoG-6-XpDQywAAAhk"]
[Mon Jul 20 07:17:05.313201 2026] [security2:error] [pid 95128:tid 95531] [client 157.20.138.62:59701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f0eeSd8WoG-6-XpDQ1AAAAiM"]
[Mon Jul 20 07:17:05.313294 2026] [security2:error] [pid 95128:tid 95531] [client 157.20.138.62:59701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f0eeSd8WoG-6-XpDQ1AAAAiM"]
[Mon Jul 20 07:17:05.463991 2026] [security2:error] [pid 95128:tid 95639] [client 14.225.17.146:60809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4f0eeSd8WoG-6-XpDQ0QAAAo8"], referer: http://sarahsnyder.net/2019
[Mon Jul 20 07:17:05.517112 2026] [security2:error] [pid 94831:tid 94979] [client 187.16.64.216:51142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f0Y06NaEKF1g_MW2towAAABI"]
[Mon Jul 20 07:17:05.517201 2026] [security2:error] [pid 94831:tid 94979] [client 187.16.64.216:51142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f0Y06NaEKF1g_MW2towAAABI"]
[Mon Jul 20 07:17:05.571091 2026] [security2:error] [pid 95128:tid 95573] [client 82.102.18.116:39450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4f0eeSd8WoG-6-XpDQ6AAAAk0"]
[Mon Jul 20 07:17:05.622387 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:62296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f0eeSd8WoG-6-XpDQ6gAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:05.672946 2026] [security2:error] [pid 95128:tid 95413] [remote 57.141.18.12:37296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2898939"] [unique_id "al4f0eeSd8WoG-6-XpDQ7AACeBo"]
[Mon Jul 20 07:17:05.689716 2026] [security2:error] [pid 95128:tid 95565] [client 57.141.18.26:42734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4fz-eSd8WoG-6-XpDQfQACRUQ"]
[Mon Jul 20 07:17:05.907224 2026] [security2:error] [pid 94831:tid 95032] [client 82.102.18.116:39464] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4f0Y06NaEKF1g_MW2tqgAAAEc"]
[Mon Jul 20 07:17:05.976435 2026] [security2:error] [pid 95126:tid 95260] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f0Qpx5ks9joCJTKW3vQAAAZE"]
[Mon Jul 20 07:17:06.210328 2026] [security2:error] [pid 95128:tid 95531] [client 77.110.127.138:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f0ueSd8WoG-6-XpDRCwAAAiM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:06.210408 2026] [security2:error] [pid 95128:tid 95531] [client 77.110.127.138:62325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f0ueSd8WoG-6-XpDRCwAAAiM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:06.245883 2026] [security2:error] [pid 95128:tid 95637] [client 82.102.18.116:39476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4f0ueSd8WoG-6-XpDRDgAAAo0"]
[Mon Jul 20 07:17:06.262339 2026] [security2:error] [pid 95128:tid 95630] [client 77.110.127.138:62327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f0ueSd8WoG-6-XpDREAAAAoY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:06.426873 2026] [security2:error] [pid 95128:tid 95570] [client 144.172.114.51:33428] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/portal/.env"] [unique_id "al4f0ueSd8WoG-6-XpDRFgAAAko"]
[Mon Jul 20 07:17:06.503925 2026] [security2:error] [pid 94831:tid 94984] [client 14.225.17.146:49589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4f0o06NaEKF1g_MW2tsAAAABc"], referer: https://sarahsnyder.net/2019
[Mon Jul 20 07:17:06.580628 2026] [security2:error] [pid 95128:tid 95591] [client 82.102.18.116:39478] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4f0ueSd8WoG-6-XpDRIQAAAl8"]
[Mon Jul 20 07:17:06.663173 2026] [security2:error] [pid 95126:tid 95310] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f0gpx5ks9joCJTKW3ywAAAcM"]
[Mon Jul 20 07:17:06.752602 2026] [security2:error] [pid 95128:tid 95579] [client 57.141.18.86:58082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f0eeSd8WoG-6-XpDQ1wACU1A"]
[Mon Jul 20 07:17:06.905035 2026] [security2:error] [pid 95126:tid 95262] [client 82.102.18.116:39488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4f0gpx5ks9joCJTKW31AAAAZM"]
[Mon Jul 20 07:17:07.051694 2026] [security2:error] [pid 95126:tid 95305] [client 195.2.78.191:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.78.2.195.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f0wpx5ks9joCJTKW31wAAAb4"], referer: https://swafforddetailing.com/
[Mon Jul 20 07:17:07.216602 2026] [security2:error] [pid 95128:tid 95609] [client 82.102.18.116:39498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4f0-eSd8WoG-6-XpDRRgAAAnE"]
[Mon Jul 20 07:17:07.348298 2026] [security2:error] [pid 95128:tid 95631] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f0-eSd8WoG-6-XpDRQAAAAoc"]
[Mon Jul 20 07:17:07.434413 2026] [security2:error] [pid 95126:tid 95181] [remote 24.122.67.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4f0wpx5ks9joCJTKW32wAB0DQ"], referer: https://www.aleishapenny.ca/
[Mon Jul 20 07:17:07.540846 2026] [security2:error] [pid 95128:tid 95565] [client 82.102.18.116:39504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4f0-eSd8WoG-6-XpDRUwAAAkU"]
[Mon Jul 20 07:17:07.553832 2026] [core:error] [pid 95126:tid 95275] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:07.553856 2026] [core:error] [pid 95126:tid 95275] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:07.593800 2026] [security2:error] [pid 95128:tid 95581] [client 47.128.40.146:26808] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "securingmemories.com"] [uri "/robots.txt"] [unique_id "al4f0-eSd8WoG-6-XpDRVQAAAlU"]
[Mon Jul 20 07:17:07.760890 2026] [security2:error] [pid 95126:tid 95269] [client 77.110.127.138:62363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f0wpx5ks9joCJTKW35wAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:07.780447 2026] [security2:error] [pid 95128:tid 95546] [client 57.141.18.12:33070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f0ueSd8WoG-6-XpDRDAACMj0"]
[Mon Jul 20 07:17:07.827183 2026] [access_compat:error] [pid 95126:tid 95190] [remote 2.211.145.78:17408] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 07:17:07.872474 2026] [security2:error] [pid 95126:tid 95365] [client 82.102.18.116:39512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4f0wpx5ks9joCJTKW36QAAAfo"]
[Mon Jul 20 07:17:08.100577 2026] [security2:error] [pid 95126:tid 95267] [client 14.225.17.146:49597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4f0gpx5ks9joCJTKW3zQAAAZg"], referer: http://myspineworld.com/2019
[Mon Jul 20 07:17:08.145328 2026] [security2:error] [pid 95128:tid 95643] [client 154.192.123.127:17133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f1OeSd8WoG-6-XpDRcgAAApM"]
[Mon Jul 20 07:17:08.145475 2026] [security2:error] [pid 95128:tid 95643] [client 154.192.123.127:17133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f1OeSd8WoG-6-XpDRcgAAApM"]
[Mon Jul 20 07:17:08.151744 2026] [security2:error] [pid 95128:tid 95577] [client 144.172.114.51:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/dashboard/.env"] [unique_id "al4f1OeSd8WoG-6-XpDRcwAAAlE"]
[Mon Jul 20 07:17:08.195433 2026] [security2:error] [pid 95128:tid 95563] [client 82.102.18.116:51686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4f1OeSd8WoG-6-XpDRdwAAAkM"]
[Mon Jul 20 07:17:08.201633 2026] [security2:error] [pid 95128:tid 95418] [remote 100.42.189.89:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4f1OeSd8WoG-6-XpDReAACIB8"]
[Mon Jul 20 07:17:08.240791 2026] [security2:error] [pid 95126:tid 95299] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f1Apx5ks9joCJTKW38QAAAbg"]
[Mon Jul 20 07:17:08.343966 2026] [security2:error] [pid 95128:tid 95567] [client 57.141.18.4:60208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f0ueSd8WoG-6-XpDRKwACRwA"]
[Mon Jul 20 07:17:08.421344 2026] [security2:error] [pid 95128:tid 95410] [remote 100.42.189.89:52156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4f1OeSd8WoG-6-XpDRggACOhc"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:17:08.515694 2026] [security2:error] [pid 94831:tid 95085] [client 82.102.18.116:51690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4f1I06NaEKF1g_MW2tuAAAAHw"]
[Mon Jul 20 07:17:08.527456 2026] [security2:error] [pid 95126:tid 95195] [remote 173.249.4.11:33403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4f1Apx5ks9joCJTKW3-QABqUI"]
[Mon Jul 20 07:17:08.688743 2026] [security2:error] [pid 95126:tid 95302] [client 50.116.65.227:22018] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4f1Apx5ks9joCJTKW3_AAAAbs"]
[Mon Jul 20 07:17:08.697048 2026] [security2:error] [pid 95128:tid 95522] [client 50.116.65.227:22024] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4f1OeSd8WoG-6-XpDRkAAAAho"]
[Mon Jul 20 07:17:08.721897 2026] [security2:error] [pid 95126:tid 95197] [remote 173.249.4.11:33403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4f1Apx5ks9joCJTKW3_QAB_kQ"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 07:17:08.784335 2026] [security2:error] [pid 95128:tid 95564] [client 117.211.236.168:56803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f1OeSd8WoG-6-XpDRlQAAAkQ"]
[Mon Jul 20 07:17:08.784534 2026] [security2:error] [pid 95128:tid 95564] [client 117.211.236.168:56803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f1OeSd8WoG-6-XpDRlQAAAkQ"]
[Mon Jul 20 07:17:08.838124 2026] [security2:error] [pid 95126:tid 95307] [client 82.102.18.116:51698] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4f1Apx5ks9joCJTKW4AwAAAcA"]
[Mon Jul 20 07:17:08.949454 2026] [security2:error] [pid 95128:tid 95521] [client 194.61.41.64:42001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f1OeSd8WoG-6-XpDRkgAAAhk"]
[Mon Jul 20 07:17:09.067659 2026] [security2:error] [pid 95128:tid 95530] [client 57.141.18.93:54202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f0-eSd8WoG-6-XpDRUgACIgQ"]
[Mon Jul 20 07:17:09.106899 2026] [security2:error] [pid 95126:tid 95334] [client 14.225.17.146:64870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4f1Apx5ks9joCJTKW4BQAAAds"], referer: https://myspineworld.com/2019
[Mon Jul 20 07:17:09.144965 2026] [security2:error] [pid 95126:tid 95319] [client 57.141.18.81:32016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f0wpx5ks9joCJTKW35AABzD8"]
[Mon Jul 20 07:17:09.206022 2026] [security2:error] [pid 95128:tid 95570] [client 82.102.18.116:51704] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.fineartsfactory.net"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4f1eeSd8WoG-6-XpDRqQAAAko"]
[Mon Jul 20 07:17:09.222079 2026] [security2:error] [pid 95128:tid 95586] [client 50.116.65.227:30112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4f1eeSd8WoG-6-XpDRngAAAlo"]
[Mon Jul 20 07:17:09.410513 2026] [security2:error] [pid 95128:tid 95555] [client 50.116.65.227:30128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4f1eeSd8WoG-6-XpDRrAAAAjs"]
[Mon Jul 20 07:17:09.486301 2026] [autoindex:error] [pid 95128:tid 95542] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:09.755193 2026] [security2:error] [pid 95126:tid 95285] [client 57.141.18.100:57400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f1Apx5ks9joCJTKW39wABqkM"]
[Mon Jul 20 07:17:09.885549 2026] [autoindex:error] [pid 95128:tid 95633] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/post-terms/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:10.081706 2026] [security2:error] [pid 95128:tid 95559] [client 104.234.53.79:53339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4f1eeSd8WoG-6-XpDR3QAAAj8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:10.161779 2026] [security2:error] [pid 95128:tid 95589] [client 14.225.17.146:64890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4f1ueSd8WoG-6-XpDR3wAAAl0"], referer: http://vinovinhowine.com/2019
[Mon Jul 20 07:17:10.201621 2026] [security2:error] [pid 95128:tid 95540] [client 14.225.17.146:64960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4f1ueSd8WoG-6-XpDR5AAAAiw"], referer: http://reosportsboats.com/2019
[Mon Jul 20 07:17:10.254801 2026] [security2:error] [pid 95128:tid 95612] [client 201.27.111.74:52236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f1ueSd8WoG-6-XpDR7wAAAnQ"]
[Mon Jul 20 07:17:10.254947 2026] [security2:error] [pid 95128:tid 95612] [client 201.27.111.74:52236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f1ueSd8WoG-6-XpDR7wAAAnQ"]
[Mon Jul 20 07:17:10.336218 2026] [security2:error] [pid 95128:tid 95568] [client 34.48.79.16:58282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.79.48.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tsb.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f1ueSd8WoG-6-XpDR9gAAAkg"]
[Mon Jul 20 07:17:10.452681 2026] [security2:error] [pid 95128:tid 95565] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f1ueSd8WoG-6-XpDR8gAAAkU"]
[Mon Jul 20 07:17:10.515019 2026] [security2:error] [pid 95128:tid 95556] [client 43.205.139.3:53208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4f1ueSd8WoG-6-XpDR_AAAAjw"]
[Mon Jul 20 07:17:10.620465 2026] [security2:error] [pid 95128:tid 95518] [client 14.225.17.146:64582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4f1ueSd8WoG-6-XpDR-wAAAhY"], referer: https://north-woods-engineering.com/2019
[Mon Jul 20 07:17:10.668783 2026] [security2:error] [pid 95128:tid 95603] [client 34.48.79.16:50155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4f1ueSd8WoG-6-XpDSCQAAAms"]
[Mon Jul 20 07:17:10.809131 2026] [security2:error] [pid 95128:tid 95445] [remote 91.142.222.105:34328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f1ueSd8WoG-6-XpDSEAACZjo"]
[Mon Jul 20 07:17:10.977576 2026] [autoindex:error] [pid 95128:tid 95622] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/dist/development/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:11.064729 2026] [security2:error] [pid 95128:tid 95458] [remote 91.142.222.105:34328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f1-eSd8WoG-6-XpDSHQACG0c"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:17:11.174697 2026] [security2:error] [pid 95126:tid 95276] [client 34.48.79.16:61809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4f1wpx5ks9joCJTKW4KAAAAaE"]
[Mon Jul 20 07:17:11.432406 2026] [security2:error] [pid 95128:tid 95585] [client 154.208.48.130:65171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f1-eSd8WoG-6-XpDSMQAAAlk"]
[Mon Jul 20 07:17:11.432555 2026] [security2:error] [pid 95128:tid 95585] [client 154.208.48.130:65171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f1-eSd8WoG-6-XpDSMQAAAlk"]
[Mon Jul 20 07:17:11.453656 2026] [security2:error] [pid 95126:tid 95278] [client 34.48.79.16:59557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4f1wpx5ks9joCJTKW4LgAAAaM"]
[Mon Jul 20 07:17:11.455990 2026] [security2:error] [pid 95128:tid 95528] [client 57.141.18.7:23490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f1eeSd8WoG-6-XpDR1gACID8"]
[Mon Jul 20 07:17:11.535603 2026] [security2:error] [pid 95128:tid 95612] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f1-eSd8WoG-6-XpDSLwAAAnQ"]
[Mon Jul 20 07:17:11.637446 2026] [security2:error] [pid 95126:tid 95371] [client 43.205.139.3:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4f1wpx5ks9joCJTKW4MAAAAgA"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:17:11.651993 2026] [security2:error] [pid 94831:tid 95037] [client 103.144.65.217:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f1406NaEKF1g_MW2tyAAAAEw"]
[Mon Jul 20 07:17:11.652091 2026] [security2:error] [pid 94831:tid 95037] [client 103.144.65.217:50148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f1406NaEKF1g_MW2tyAAAAEw"]
[Mon Jul 20 07:17:11.726823 2026] [security2:error] [pid 94831:tid 95055] [client 14.225.17.146:64673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4f1406NaEKF1g_MW2txQAAAF4"], referer: http://tntcatholic.com/2019
[Mon Jul 20 07:17:11.729802 2026] [security2:error] [pid 95128:tid 95583] [client 57.141.18.97:42266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f1ueSd8WoG-6-XpDR5wACV1k"]
[Mon Jul 20 07:17:11.746295 2026] [security2:error] [pid 95126:tid 95368] [client 34.48.79.16:53613] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4f1wpx5ks9joCJTKW4MwAAAf0"]
[Mon Jul 20 07:17:11.815233 2026] [security2:error] [pid 95128:tid 95539] [client 20.220.9.199:64188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4f1-eSd8WoG-6-XpDSRAAAAis"]
[Mon Jul 20 07:17:11.815317 2026] [security2:error] [pid 95128:tid 95539] [client 20.220.9.199:64188] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4f1-eSd8WoG-6-XpDSRAAAAis"]
[Mon Jul 20 07:17:11.889998 2026] [security2:error] [pid 95126:tid 95338] [client 57.141.18.12:33084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f1gpx5ks9joCJTKW4DwAB30Y"]
[Mon Jul 20 07:17:12.003871 2026] [autoindex:error] [pid 95126:tid 95309] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/sodium_compat/namespaced/Core/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:12.067390 2026] [security2:error] [pid 95128:tid 95521] [client 20.220.9.199:64406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4f2OeSd8WoG-6-XpDSUQAAAhk"]
[Mon Jul 20 07:17:12.067518 2026] [security2:error] [pid 95128:tid 95521] [client 20.220.9.199:64406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4f2OeSd8WoG-6-XpDSUQAAAhk"]
[Mon Jul 20 07:17:12.092178 2026] [security2:error] [pid 95128:tid 95588] [client 34.48.79.16:56139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4f2OeSd8WoG-6-XpDSUgAAAlw"]
[Mon Jul 20 07:17:12.116653 2026] [security2:error] [pid 95128:tid 95605] [client 57.141.18.29:30592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f1ueSd8WoG-6-XpDSBAACbRU"]
[Mon Jul 20 07:17:12.297552 2026] [security2:error] [pid 95128:tid 95563] [client 14.225.17.146:51867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4f2OeSd8WoG-6-XpDSUAAAAkM"]
[Mon Jul 20 07:17:12.337782 2026] [security2:error] [pid 95128:tid 95537] [client 146.103.110.4:50437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.110.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f2OeSd8WoG-6-XpDSYAAAAik"], referer: https://entuvy.com/
[Mon Jul 20 07:17:12.367224 2026] [security2:error] [pid 95128:tid 95636] [client 34.48.79.16:54203] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4f2OeSd8WoG-6-XpDSYwAAAow"]
[Mon Jul 20 07:17:12.395706 2026] [security2:error] [pid 95128:tid 95585] [client 20.220.9.199:60395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/x.php"] [unique_id "al4f2OeSd8WoG-6-XpDSaQAAAlk"]
[Mon Jul 20 07:17:12.395796 2026] [security2:error] [pid 95128:tid 95585] [client 20.220.9.199:60395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/x.php"] [unique_id "al4f2OeSd8WoG-6-XpDSaQAAAlk"]
[Mon Jul 20 07:17:12.433815 2026] [security2:error] [pid 95126:tid 95193] [remote 20.153.140.50:39326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4f2Apx5ks9joCJTKW4OwABvkA"]
[Mon Jul 20 07:17:12.465642 2026] [security2:error] [pid 95128:tid 95577] [client 114.119.146.215:22903] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "oswegooperatheater.com"] [uri "/nny360-oswego-opera-theater-announces-board-elections-of"] [unique_id "al4f2OeSd8WoG-6-XpDSbgAAAlE"], referer: https://oswegooperatheater.com/a-night-at-the-opera-virtual-performance
[Mon Jul 20 07:17:12.561797 2026] [security2:error] [pid 95128:tid 95628] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f2OeSd8WoG-6-XpDSZQAAAoQ"]
[Mon Jul 20 07:17:12.616838 2026] [security2:error] [pid 94831:tid 95079] [client 34.48.79.16:58511] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4f2I06NaEKF1g_MW2tzAAAAHY"]
[Mon Jul 20 07:17:12.832425 2026] [security2:error] [pid 95126:tid 95210] [remote 20.153.140.50:39326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.legallyknownaszacharyhoy999.com"] [uri "/wp-login.php"] [unique_id "al4f2Apx5ks9joCJTKW4QwABn1E"], referer: https://mail.legallyknownaszacharyhoy999.com/wp-login.php
[Mon Jul 20 07:17:12.899049 2026] [security2:error] [pid 95128:tid 95550] [client 34.48.79.16:58122] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4f2OeSd8WoG-6-XpDShgAAAjY"]
[Mon Jul 20 07:17:12.996551 2026] [security2:error] [pid 95128:tid 95399] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f2OeSd8WoG-6-XpDSjwACjQw"]
[Mon Jul 20 07:17:12.996733 2026] [security2:error] [pid 95128:tid 95637] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f2OeSd8WoG-6-XpDSjwACjQw"]
[Mon Jul 20 07:17:13.044845 2026] [security2:error] [pid 95128:tid 95609] [client 20.220.9.199:59941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/mgrr.php"] [unique_id "al4f2eeSd8WoG-6-XpDSlgAAAnE"]
[Mon Jul 20 07:17:13.044974 2026] [security2:error] [pid 95128:tid 95609] [client 20.220.9.199:59941] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/mgrr.php"] [unique_id "al4f2eeSd8WoG-6-XpDSlgAAAnE"]
[Mon Jul 20 07:17:13.045402 2026] [core:error] [pid 95128:tid 95584] [client 14.225.17.146:52281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:13.045418 2026] [core:error] [pid 95128:tid 95584] [client 14.225.17.146:52281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:13.048676 2026] [security2:error] [pid 95128:tid 95523] [client 77.110.127.138:62443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f2eeSd8WoG-6-XpDSlwAAAhs"]
[Mon Jul 20 07:17:13.077366 2026] [security2:error] [pid 95126:tid 95363] [client 14.225.17.146:49410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4f1wpx5ks9joCJTKW4LQAAAfg"], referer: http://thesoloceos.com/2019
[Mon Jul 20 07:17:13.097639 2026] [security2:error] [pid 95128:tid 95543] [client 77.110.127.138:62445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f2eeSd8WoG-6-XpDSoAAAAi8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:13.168625 2026] [security2:error] [pid 94831:tid 95035] [client 57.141.18.12:51540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f1406NaEKF1g_MW2txwAASmM"]
[Mon Jul 20 07:17:13.251553 2026] [security2:error] [pid 95128:tid 95529] [client 77.110.127.138:62447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f2eeSd8WoG-6-XpDSrgAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:13.251653 2026] [security2:error] [pid 95128:tid 95529] [client 77.110.127.138:62447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f2eeSd8WoG-6-XpDSrgAAAiE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:13.281866 2026] [security2:error] [pid 95128:tid 95544] [client 34.48.79.16:63963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4f2eeSd8WoG-6-XpDStAAAAjA"]
[Mon Jul 20 07:17:13.295089 2026] [security2:error] [pid 95128:tid 95562] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f2eeSd8WoG-6-XpDSnAAAAkI"]
[Mon Jul 20 07:17:13.413899 2026] [security2:error] [pid 95128:tid 95520] [client 14.225.17.146:51161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4f2eeSd8WoG-6-XpDSowAAAhg"], referer: http://falconarrowshop.com/2019
[Mon Jul 20 07:17:13.428351 2026] [security2:error] [pid 95128:tid 95582] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4f2eeSd8WoG-6-XpDSnQAAAlY"]
[Mon Jul 20 07:17:13.486015 2026] [security2:error] [pid 95126:tid 95277] [client 143.44.185.218:49843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f2Qpx5ks9joCJTKW4UQAAAaI"]
[Mon Jul 20 07:17:13.486167 2026] [security2:error] [pid 95126:tid 95277] [client 143.44.185.218:49843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f2Qpx5ks9joCJTKW4UQAAAaI"]
[Mon Jul 20 07:17:13.579242 2026] [security2:error] [pid 95126:tid 95289] [client 34.48.79.16:51422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tsb.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4f2Qpx5ks9joCJTKW4UwAAAa4"]
[Mon Jul 20 07:17:13.591062 2026] [security2:error] [pid 95126:tid 95295] [client 77.110.127.138:62456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f2Qpx5ks9joCJTKW4VAAAAbQ"]
[Mon Jul 20 07:17:13.796650 2026] [security2:error] [pid 95126:tid 95344] [client 20.220.9.199:64395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/stdin.php"] [unique_id "al4f2Qpx5ks9joCJTKW4VwAAAeU"]
[Mon Jul 20 07:17:13.796805 2026] [security2:error] [pid 95126:tid 95344] [client 20.220.9.199:64395] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/stdin.php"] [unique_id "al4f2Qpx5ks9joCJTKW4VwAAAeU"]
[Mon Jul 20 07:17:13.947897 2026] [security2:error] [pid 95126:tid 95343] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f2Qpx5ks9joCJTKW4VgAAAeQ"]
[Mon Jul 20 07:17:13.996377 2026] [security2:error] [pid 95128:tid 95625] [client 57.141.18.115:34284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f2OeSd8WoG-6-XpDSZgACgVA"]
[Mon Jul 20 07:17:14.061189 2026] [security2:error] [pid 94831:tid 94993] [client 14.225.17.146:51144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4f2Y06NaEKF1g_MW2t0gAAACA"], referer: https://thesoloceos.com/2019
[Mon Jul 20 07:17:14.184577 2026] [security2:error] [pid 95128:tid 95425] [remote 45.84.107.182:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f2ueSd8WoG-6-XpDS1AACfiY"], referer: https://verdunestate.com/furnished-apartment-for-rent-ashrafieh-fassouh-2/
[Mon Jul 20 07:17:14.202807 2026] [security2:error] [pid 95128:tid 95521] [client 20.197.192.193:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.192.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "gaantuition.co.uk"] [uri "/.well-known/about.php"] [unique_id "al4f2ueSd8WoG-6-XpDS1QAAAhk"]
[Mon Jul 20 07:17:14.202897 2026] [security2:error] [pid 95128:tid 95521] [client 20.197.192.193:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "gaantuition.co.uk"] [uri "/.well-known/about.php"] [unique_id "al4f2ueSd8WoG-6-XpDS1QAAAhk"]
[Mon Jul 20 07:17:14.251305 2026] [security2:error] [pid 95126:tid 95317] [client 88.241.67.160:53497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f2gpx5ks9joCJTKW4YQAAAco"]
[Mon Jul 20 07:17:14.251530 2026] [security2:error] [pid 95126:tid 95317] [client 88.241.67.160:53497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f2gpx5ks9joCJTKW4YQAAAco"]
[Mon Jul 20 07:17:14.364315 2026] [security2:error] [pid 95128:tid 95594] [client 20.220.9.199:56269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/BDKR28.php"] [unique_id "al4f2ueSd8WoG-6-XpDS5QAAAmI"]
[Mon Jul 20 07:17:14.364405 2026] [security2:error] [pid 95128:tid 95594] [client 20.220.9.199:56269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/BDKR28.php"] [unique_id "al4f2ueSd8WoG-6-XpDS5QAAAmI"]
[Mon Jul 20 07:17:14.455655 2026] [security2:error] [pid 95128:tid 95438] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f2ueSd8WoG-6-XpDS7AACijM"]
[Mon Jul 20 07:17:14.455789 2026] [security2:error] [pid 95128:tid 95634] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f2ueSd8WoG-6-XpDS7AACijM"]
[Mon Jul 20 07:17:14.521581 2026] [security2:error] [pid 95128:tid 95584] [client 14.225.17.146:51254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4f2ueSd8WoG-6-XpDS1gAAAlg"], referer: http://guidehunting.com/2019
[Mon Jul 20 07:17:14.640318 2026] [security2:error] [pid 95128:tid 95630] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f2ueSd8WoG-6-XpDS6wAAAoY"]
[Mon Jul 20 07:17:14.684776 2026] [security2:error] [pid 95128:tid 95525] [client 20.220.9.199:64167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/001.php"] [unique_id "al4f2ueSd8WoG-6-XpDS9wAAAh0"]
[Mon Jul 20 07:17:14.684897 2026] [security2:error] [pid 95128:tid 95525] [client 20.220.9.199:64167] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/001.php"] [unique_id "al4f2ueSd8WoG-6-XpDS9wAAAh0"]
[Mon Jul 20 07:17:14.967712 2026] [security2:error] [pid 95126:tid 95334] [client 20.220.9.199:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/dZ3wP5.php"] [unique_id "al4f2gpx5ks9joCJTKW4bwAAAds"]
[Mon Jul 20 07:17:14.967803 2026] [security2:error] [pid 95126:tid 95334] [client 20.220.9.199:56274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/dZ3wP5.php"] [unique_id "al4f2gpx5ks9joCJTKW4bwAAAds"]
[Mon Jul 20 07:17:14.970264 2026] [security2:error] [pid 95128:tid 95633] [client 14.225.17.146:51580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4f2ueSd8WoG-6-XpDS_gAAAok"], referer: http://kromosenergy.com/2019
[Mon Jul 20 07:17:15.285463 2026] [security2:error] [pid 95128:tid 95576] [client 103.176.215.66:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f2-eSd8WoG-6-XpDTFQAAAlA"]
[Mon Jul 20 07:17:15.285588 2026] [security2:error] [pid 95128:tid 95576] [client 103.176.215.66:49533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f2-eSd8WoG-6-XpDTFQAAAlA"]
[Mon Jul 20 07:17:15.291676 2026] [security2:error] [pid 95128:tid 95610] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f2-eSd8WoG-6-XpDTCgAAAnI"]
[Mon Jul 20 07:17:15.358309 2026] [security2:error] [pid 95128:tid 95577] [client 20.220.9.199:64394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/yup.php"] [unique_id "al4f2-eSd8WoG-6-XpDTGgAAAlE"]
[Mon Jul 20 07:17:15.358425 2026] [security2:error] [pid 95128:tid 95577] [client 20.220.9.199:64394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/yup.php"] [unique_id "al4f2-eSd8WoG-6-XpDTGgAAAlE"]
[Mon Jul 20 07:17:15.643422 2026] [security2:error] [pid 94831:tid 95058] [client 14.225.17.146:52269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4f2406NaEKF1g_MW2t2AAAAGE"], referer: https://guidehunting.com/2019
[Mon Jul 20 07:17:15.800361 2026] [security2:error] [pid 95128:tid 95519] [client 77.110.127.138:62481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f2-eSd8WoG-6-XpDTLwAAAhc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:15.800460 2026] [security2:error] [pid 95128:tid 95519] [client 77.110.127.138:62481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f2-eSd8WoG-6-XpDTLwAAAhc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:15.879653 2026] [security2:error] [pid 95128:tid 95522] [client 20.220.9.199:60352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/X.php"] [unique_id "al4f2-eSd8WoG-6-XpDTMwAAAho"]
[Mon Jul 20 07:17:15.879798 2026] [security2:error] [pid 95128:tid 95522] [client 20.220.9.199:60352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/X.php"] [unique_id "al4f2-eSd8WoG-6-XpDTMwAAAho"]
[Mon Jul 20 07:17:15.904366 2026] [security2:error] [pid 95128:tid 95618] [client 157.20.138.62:60263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f2-eSd8WoG-6-XpDTNAAAAno"]
[Mon Jul 20 07:17:15.904490 2026] [security2:error] [pid 95128:tid 95618] [client 157.20.138.62:60263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f2-eSd8WoG-6-XpDTNAAAAno"]
[Mon Jul 20 07:17:15.938260 2026] [security2:error] [pid 95128:tid 95574] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f2-eSd8WoG-6-XpDTKwAAAk4"]
[Mon Jul 20 07:17:15.950512 2026] [security2:error] [pid 95128:tid 95573] [client 77.110.127.138:62483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f2-eSd8WoG-6-XpDTNwAAAk0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:15.993607 2026] [security2:error] [pid 95128:tid 95526] [client 57.141.18.95:56248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f2ueSd8WoG-6-XpDS2gACHkM"]
[Mon Jul 20 07:17:16.088660 2026] [security2:error] [pid 95128:tid 95460] [remote 154.66.198.148:36284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f3OeSd8WoG-6-XpDTQgACW0k"]
[Mon Jul 20 07:17:16.088781 2026] [security2:error] [pid 95128:tid 95587] [client 154.66.198.148:36284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f3OeSd8WoG-6-XpDTQgACW0k"]
[Mon Jul 20 07:17:16.170532 2026] [security2:error] [pid 95128:tid 95520] [client 187.16.64.216:51771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f3OeSd8WoG-6-XpDTSgAAAhg"]
[Mon Jul 20 07:17:16.170656 2026] [security2:error] [pid 95128:tid 95520] [client 187.16.64.216:51771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f3OeSd8WoG-6-XpDTSgAAAhg"]
[Mon Jul 20 07:17:16.173539 2026] [security2:error] [pid 95126:tid 95271] [client 20.220.9.199:64397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/1polka.php"] [unique_id "al4f3Apx5ks9joCJTKW4fwAAAZw"]
[Mon Jul 20 07:17:16.173643 2026] [security2:error] [pid 95126:tid 95271] [client 20.220.9.199:64397] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/1polka.php"] [unique_id "al4f3Apx5ks9joCJTKW4fwAAAZw"]
[Mon Jul 20 07:17:16.442107 2026] [security2:error] [pid 95126:tid 95339] [client 20.220.9.199:56293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/gec.php"] [unique_id "al4f3Apx5ks9joCJTKW4hgAAAeA"]
[Mon Jul 20 07:17:16.442222 2026] [security2:error] [pid 95126:tid 95339] [client 20.220.9.199:56293] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/gec.php"] [unique_id "al4f3Apx5ks9joCJTKW4hgAAAeA"]
[Mon Jul 20 07:17:16.555733 2026] [security2:error] [pid 95126:tid 95385] [client 34.147.84.84:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.zastrow.com"] [uri "/"] [unique_id "al4f3Apx5ks9joCJTKW4iQAAAg4"]
[Mon Jul 20 07:17:16.555859 2026] [security2:error] [pid 95126:tid 95385] [client 34.147.84.84:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.zastrow.com"] [uri "/"] [unique_id "al4f3Apx5ks9joCJTKW4iQAAAg4"]
[Mon Jul 20 07:17:16.572551 2026] [security2:error] [pid 95128:tid 95599] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f3OeSd8WoG-6-XpDTVAAAAmc"]
[Mon Jul 20 07:17:16.619386 2026] [security2:error] [pid 95128:tid 95542] [client 49.37.242.14:49237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f3OeSd8WoG-6-XpDTXgAAAi4"]
[Mon Jul 20 07:17:16.619475 2026] [security2:error] [pid 95128:tid 95542] [client 49.37.242.14:49237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f3OeSd8WoG-6-XpDTXgAAAi4"]
[Mon Jul 20 07:17:16.712438 2026] [security2:error] [pid 95128:tid 95625] [client 14.225.17.146:52548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4f3OeSd8WoG-6-XpDTXAAAAoE"], referer: http://bbwipartnerconference.com/2019
[Mon Jul 20 07:17:16.716478 2026] [security2:error] [pid 95128:tid 95527] [client 77.110.127.138:62489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f3OeSd8WoG-6-XpDTaAAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:16.716545 2026] [security2:error] [pid 95128:tid 95527] [client 77.110.127.138:62489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f3OeSd8WoG-6-XpDTaAAAAh8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:16.967335 2026] [security2:error] [pid 95128:tid 95626] [client 20.220.9.199:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/sky.php"] [unique_id "al4f3OeSd8WoG-6-XpDTdAAAAoI"]
[Mon Jul 20 07:17:16.967428 2026] [security2:error] [pid 95128:tid 95626] [client 20.220.9.199:64429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/sky.php"] [unique_id "al4f3OeSd8WoG-6-XpDTdAAAAoI"]
[Mon Jul 20 07:17:17.247484 2026] [security2:error] [pid 95128:tid 95639] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f3eeSd8WoG-6-XpDTfwAAAo8"]
[Mon Jul 20 07:17:17.248631 2026] [security2:error] [pid 95128:tid 95443] [remote 45.84.107.182:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f3eeSd8WoG-6-XpDTigACfjg"], referer: https://verdunestate.com/
[Mon Jul 20 07:17:17.645123 2026] [security2:error] [pid 95128:tid 95566] [client 57.141.18.43:44968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f2-eSd8WoG-6-XpDTOAACRlg"]
[Mon Jul 20 07:17:17.680628 2026] [security2:error] [pid 95128:tid 95595] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4f3eeSd8WoG-6-XpDTjwAAAmM"]
[Mon Jul 20 07:17:17.687189 2026] [security2:error] [pid 94831:tid 94861] [remote 103.187.169.251:56574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f3Y06NaEKF1g_MW2t4AAAVR0"]
[Mon Jul 20 07:17:17.687384 2026] [security2:error] [pid 94831:tid 95046] [client 103.187.169.251:56574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f3Y06NaEKF1g_MW2t4AAAVR0"]
[Mon Jul 20 07:17:17.771381 2026] [autoindex:error] [pid 95128:tid 95527] [client 194.61.41.64:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/blocks/site-title/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:17.776469 2026] [security2:error] [pid 95128:tid 95574] [client 20.220.9.199:60399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/fffm.php"] [unique_id "al4f3eeSd8WoG-6-XpDTpQAAAk4"]
[Mon Jul 20 07:17:17.776610 2026] [security2:error] [pid 95128:tid 95574] [client 20.220.9.199:60399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/fffm.php"] [unique_id "al4f3eeSd8WoG-6-XpDTpQAAAk4"]
[Mon Jul 20 07:17:17.793922 2026] [security2:error] [pid 95126:tid 95268] [client 117.211.236.168:57359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f3Qpx5ks9joCJTKW4pgAAAZk"]
[Mon Jul 20 07:17:17.794018 2026] [security2:error] [pid 95126:tid 95268] [client 117.211.236.168:57359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f3Qpx5ks9joCJTKW4pgAAAZk"]
[Mon Jul 20 07:17:17.814932 2026] [security2:error] [pid 95128:tid 95553] [client 191.202.66.27:63587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f3eeSd8WoG-6-XpDTowAAAjk"]
[Mon Jul 20 07:17:17.815022 2026] [security2:error] [pid 95128:tid 95553] [client 191.202.66.27:63587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f3eeSd8WoG-6-XpDTowAAAjk"]
[Mon Jul 20 07:17:17.944779 2026] [security2:error] [pid 95128:tid 95632] [client 77.110.127.138:62501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f3eeSd8WoG-6-XpDTrAAAAog"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:18.024436 2026] [security2:error] [pid 95126:tid 95381] [client 57.141.18.33:64762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f3Apx5ks9joCJTKW4ggACCmA"]
[Mon Jul 20 07:17:18.047161 2026] [security2:error] [pid 95128:tid 95616] [client 54.244.177.189:11288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4f3ueSd8WoG-6-XpDTtwAAAng"]
[Mon Jul 20 07:17:18.242162 2026] [security2:error] [pid 95128:tid 95436] [remote 162.19.86.63:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4f3ueSd8WoG-6-XpDTwwACSzE"]
[Mon Jul 20 07:17:18.338094 2026] [security2:error] [pid 95128:tid 95586] [client 194.61.41.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f3ueSd8WoG-6-XpDTvwAAAlo"]
[Mon Jul 20 07:17:18.440097 2026] [security2:error] [pid 95128:tid 95390] [remote 162.19.86.63:56856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4f3ueSd8WoG-6-XpDTygACigM"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 07:17:18.733335 2026] [security2:error] [pid 95126:tid 95351] [client 154.192.123.127:17504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f3gpx5ks9joCJTKW4tQAAAew"]
[Mon Jul 20 07:17:18.733473 2026] [security2:error] [pid 95126:tid 95351] [client 154.192.123.127:17504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f3gpx5ks9joCJTKW4tQAAAew"]
[Mon Jul 20 07:17:18.760732 2026] [core:error] [pid 95128:tid 95557] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:18.760769 2026] [core:error] [pid 95128:tid 95557] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:18.789556 2026] [security2:error] [pid 95126:tid 95282] [client 144.172.114.51:57666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/docker/.env"] [unique_id "al4f3gpx5ks9joCJTKW4tgAAAac"]
[Mon Jul 20 07:17:18.838906 2026] [security2:error] [pid 95128:tid 95610] [client 57.141.18.46:27614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f3eeSd8WoG-6-XpDTiAACchU"]
[Mon Jul 20 07:17:18.849947 2026] [security2:error] [pid 95128:tid 95560] [client 20.220.9.199:55891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/sixxis.php"] [unique_id "al4f3ueSd8WoG-6-XpDT7wAAAkA"]
[Mon Jul 20 07:17:18.850026 2026] [security2:error] [pid 95128:tid 95560] [client 20.220.9.199:55891] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/sixxis.php"] [unique_id "al4f3ueSd8WoG-6-XpDT7wAAAkA"]
[Mon Jul 20 07:17:18.923857 2026] [security2:error] [pid 95128:tid 95618] [client 54.184.226.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4f3eeSd8WoG-6-XpDTpAAAAno"]
[Mon Jul 20 07:17:18.926409 2026] [security2:error] [pid 95126:tid 95278] [client 54.184.226.94:61909] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "youpositive.co"] [uri "/"] [unique_id "al4f3Qpx5ks9joCJTKW4pAAAAaM"]
[Mon Jul 20 07:17:19.091866 2026] [security2:error] [pid 95128:tid 95559] [client 77.110.127.138:62508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f3-eSd8WoG-6-XpDUBAAAAj8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:19.242662 2026] [security2:error] [pid 95126:tid 95292] [client 77.110.127.138:62509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f3wpx5ks9joCJTKW4wQAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:19.242801 2026] [security2:error] [pid 95126:tid 95292] [client 77.110.127.138:62509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f3wpx5ks9joCJTKW4wQAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:19.438779 2026] [security2:error] [pid 95128:tid 95421] [remote 57.141.18.107:29920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4f3-eSd8WoG-6-XpDUGgACNiI"]
[Mon Jul 20 07:17:19.638351 2026] [security2:error] [pid 95126:tid 95281] [client 194.61.41.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f3wpx5ks9joCJTKW4xAAAAaY"]
[Mon Jul 20 07:17:19.692083 2026] [security2:error] [pid 95128:tid 95622] [client 54.184.226.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4f3ueSd8WoG-6-XpDT_QAAAn4"], referer: https://youpositive.co/?rnd=1784553437533
[Mon Jul 20 07:17:19.714946 2026] [security2:error] [pid 95126:tid 95271] [client 54.184.226.94:61909] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "youpositive.co"] [uri "/ar/"] [unique_id "al4f3gpx5ks9joCJTKW4uwAAAZw"], referer: https://youpositive.co/?rnd=1784553437533
[Mon Jul 20 07:17:19.734457 2026] [security2:error] [pid 95128:tid 95442] [remote 45.90.123.233:56078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f3-eSd8WoG-6-XpDUMAACJDc"]
[Mon Jul 20 07:17:19.734658 2026] [security2:error] [pid 95128:tid 95532] [client 45.90.123.233:56078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f3-eSd8WoG-6-XpDUMAACJDc"]
[Mon Jul 20 07:17:19.799857 2026] [core:error] [pid 95128:tid 95560] [client 14.225.17.146:52549] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2019
[Mon Jul 20 07:17:19.799875 2026] [core:error] [pid 95128:tid 95560] [client 14.225.17.146:52549] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://belavistatile.com/2019
[Mon Jul 20 07:17:19.837802 2026] [security2:error] [pid 95128:tid 95590] [client 20.220.9.199:64154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/yj09.php"] [unique_id "al4f3-eSd8WoG-6-XpDUOgAAAl4"]
[Mon Jul 20 07:17:19.837890 2026] [security2:error] [pid 95128:tid 95590] [client 20.220.9.199:64154] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/yj09.php"] [unique_id "al4f3-eSd8WoG-6-XpDUOgAAAl4"]
[Mon Jul 20 07:17:19.861569 2026] [security2:error] [pid 94831:tid 94855] [remote 57.141.18.12:47158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4f3406NaEKF1g_MW2t7wAAcBc"]
[Mon Jul 20 07:17:19.905563 2026] [access_compat:error] [pid 95128:tid 95451] [remote 124.244.102.199:58048] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 07:17:20.080528 2026] [security2:error] [pid 95126:tid 95228] [remote 8.217.108.67:38056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4f4Apx5ks9joCJTKW4zgACDWM"]
[Mon Jul 20 07:17:20.167295 2026] [security2:error] [pid 95128:tid 95521] [client 57.141.18.29:36412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f3ueSd8WoG-6-XpDT0QACGUU"]
[Mon Jul 20 07:17:20.564450 2026] [security2:error] [pid 95126:tid 95235] [remote 152.228.213.32:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4f4Apx5ks9joCJTKW41QACAWo"]
[Mon Jul 20 07:17:20.582719 2026] [security2:error] [pid 95128:tid 95639] [client 20.220.9.199:60380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/f900.php"] [unique_id "al4f4OeSd8WoG-6-XpDUYQAAAo8"]
[Mon Jul 20 07:17:20.582829 2026] [security2:error] [pid 95128:tid 95639] [client 20.220.9.199:60380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/f900.php"] [unique_id "al4f4OeSd8WoG-6-XpDUYQAAAo8"]
[Mon Jul 20 07:17:20.639281 2026] [core:error] [pid 95126:tid 95311] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:20.639302 2026] [core:error] [pid 95126:tid 95311] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:20.660538 2026] [security2:error] [pid 95126:tid 95354] [client 194.61.41.79:37487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f4Apx5ks9joCJTKW41AAAAe8"]
[Mon Jul 20 07:17:20.690256 2026] [security2:error] [pid 95126:tid 95236] [remote 8.217.108.67:38056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4f4Apx5ks9joCJTKW42AABmWs"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:17:20.743643 2026] [security2:error] [pid 95126:tid 95264] [client 77.110.127.138:62519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f4Apx5ks9joCJTKW43AAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:20.743716 2026] [security2:error] [pid 95126:tid 95264] [client 77.110.127.138:62519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f4Apx5ks9joCJTKW43AAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:20.746703 2026] [security2:error] [pid 95126:tid 95234] [remote 152.228.213.32:36090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4f4Apx5ks9joCJTKW43QABmmk"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 07:17:20.825123 2026] [security2:error] [pid 95128:tid 95529] [client 201.27.111.74:52752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f4OeSd8WoG-6-XpDUeAAAAiE"]
[Mon Jul 20 07:17:20.825231 2026] [security2:error] [pid 95128:tid 95529] [client 201.27.111.74:52752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f4OeSd8WoG-6-XpDUeAAAAiE"]
[Mon Jul 20 07:17:20.867636 2026] [security2:error] [pid 95128:tid 95553] [client 144.172.114.51:44002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/k8s/.env"] [unique_id "al4f4OeSd8WoG-6-XpDUegAAAjk"]
[Mon Jul 20 07:17:20.883481 2026] [security2:error] [pid 95128:tid 95558] [client 20.220.9.199:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ups.php"] [unique_id "al4f4OeSd8WoG-6-XpDUewAAAj4"]
[Mon Jul 20 07:17:20.883585 2026] [security2:error] [pid 95128:tid 95558] [client 20.220.9.199:64169] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ups.php"] [unique_id "al4f4OeSd8WoG-6-XpDUewAAAj4"]
[Mon Jul 20 07:17:21.046046 2026] [core:error] [pid 95128:tid 95556] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:21.046066 2026] [core:error] [pid 95128:tid 95556] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:21.237828 2026] [security2:error] [pid 95126:tid 95241] [remote 57.141.18.4:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4f4Qpx5ks9joCJTKW45wAB0nA"]
[Mon Jul 20 07:17:21.237950 2026] [security2:error] [pid 95128:tid 95547] [client 113.160.97.242:50747] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4f4eeSd8WoG-6-XpDUlQAAAjM"]
[Mon Jul 20 07:17:21.242633 2026] [security2:error] [pid 95128:tid 95518] [client 194.61.41.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f4eeSd8WoG-6-XpDUhgAAAhY"]
[Mon Jul 20 07:17:21.394952 2026] [security2:error] [pid 95128:tid 95610] [client 104.234.53.57:38461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4f4eeSd8WoG-6-XpDUnwAAAnI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:21.576531 2026] [security2:error] [pid 95128:tid 95614] [client 77.110.127.138:62523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f4eeSd8WoG-6-XpDUowAAAnY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:21.594311 2026] [security2:error] [pid 95128:tid 95450] [remote 57.141.18.67:27782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4f4eeSd8WoG-6-XpDUrQACVj8"]
[Mon Jul 20 07:17:21.660302 2026] [security2:error] [pid 95128:tid 95558] [client 77.110.127.138:62525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4eeSd8WoG-6-XpDUtgAAAj4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:21.851926 2026] [security2:error] [pid 95128:tid 95531] [client 20.220.9.199:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/k.php"] [unique_id "al4f4eeSd8WoG-6-XpDUywAAAiM"]
[Mon Jul 20 07:17:21.852021 2026] [security2:error] [pid 95128:tid 95531] [client 20.220.9.199:64134] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/k.php"] [unique_id "al4f4eeSd8WoG-6-XpDUywAAAiM"]
[Mon Jul 20 07:17:21.852620 2026] [security2:error] [pid 95128:tid 95544] [client 77.110.127.138:62528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4eeSd8WoG-6-XpDUzAAAAjA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:21.960127 2026] [security2:error] [pid 95126:tid 95285] [client 194.61.41.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f4Qpx5ks9joCJTKW47AAAAao"]
[Mon Jul 20 07:17:22.172025 2026] [security2:error] [pid 94831:tid 95083] [client 45.157.112.60:51181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f4o06NaEKF1g_MW2t9wAAAHo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:17:22.233466 2026] [security2:error] [pid 95128:tid 95607] [client 14.225.17.146:59504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDU1QAAAm8"], referer: http://ccsdifference.com/2019
[Mon Jul 20 07:17:22.234117 2026] [security2:error] [pid 95126:tid 95260] [client 77.110.127.138:62529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f4gpx5ks9joCJTKW49AAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:22.234851 2026] [security2:error] [pid 95128:tid 95637] [client 20.220.9.199:56279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/k2.php"] [unique_id "al4f4ueSd8WoG-6-XpDU5gAAAo0"]
[Mon Jul 20 07:17:22.234960 2026] [security2:error] [pid 95128:tid 95637] [client 20.220.9.199:56279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/k2.php"] [unique_id "al4f4ueSd8WoG-6-XpDU5gAAAo0"]
[Mon Jul 20 07:17:22.308590 2026] [security2:error] [pid 95128:tid 95567] [client 57.141.18.117:43488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f4OeSd8WoG-6-XpDUZgACRy8"]
[Mon Jul 20 07:17:22.333107 2026] [security2:error] [pid 94831:tid 94999] [client 103.144.65.217:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f4o06NaEKF1g_MW2t-gAAACY"]
[Mon Jul 20 07:17:22.333249 2026] [security2:error] [pid 94831:tid 94999] [client 103.144.65.217:50602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f4o06NaEKF1g_MW2t-gAAACY"]
[Mon Jul 20 07:17:22.337052 2026] [security2:error] [pid 95126:tid 95274] [client 154.208.48.130:49299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f4gpx5ks9joCJTKW4_AAAAZ8"]
[Mon Jul 20 07:17:22.337173 2026] [security2:error] [pid 95126:tid 95274] [client 154.208.48.130:49299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f4gpx5ks9joCJTKW4_AAAAZ8"]
[Mon Jul 20 07:17:22.435375 2026] [security2:error] [pid 95128:tid 95437] [remote 74.235.96.117:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4f4ueSd8WoG-6-XpDU8AACkDI"]
[Mon Jul 20 07:17:22.446614 2026] [security2:error] [pid 95128:tid 95419] [remote 57.141.18.61:23874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4f4ueSd8WoG-6-XpDU8QACeSA"]
[Mon Jul 20 07:17:22.480828 2026] [autoindex:error] [pid 95126:tid 95312] [client 194.61.41.79:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-includes/js/tinymce/plugins/compat3x/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:22.505392 2026] [security2:error] [pid 95128:tid 95634] [client 77.110.127.138:62531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4ueSd8WoG-6-XpDU9QAAAoo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:22.609035 2026] [security2:error] [pid 95128:tid 95487] [remote 74.235.96.117:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4f4ueSd8WoG-6-XpDU-gACO2Q"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:17:22.639281 2026] [security2:error] [pid 95128:tid 95597] [client 14.225.17.146:52528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDU9AAAAmU"], referer: http://nurturemarple.co.uk/2019
[Mon Jul 20 07:17:22.650587 2026] [security2:error] [pid 95126:tid 95272] [client 144.172.114.51:44026] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/helm/.env"] [unique_id "al4f4gpx5ks9joCJTKW5AgAAAZ0"]
[Mon Jul 20 07:17:22.744704 2026] [security2:error] [pid 95128:tid 95628] [client 77.110.127.138:62533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4ueSd8WoG-6-XpDVCAAAAoQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:22.885275 2026] [security2:error] [pid 95128:tid 95552] [client 77.110.127.138:62532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDU_wAAAjg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:22.887559 2026] [security2:error] [pid 94831:tid 95049] [client 20.220.9.199:56311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/w.php"] [unique_id "al4f4o06NaEKF1g_MW2t_QAAAFg"]
[Mon Jul 20 07:17:22.887689 2026] [security2:error] [pid 94831:tid 95049] [client 20.220.9.199:56311] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/w.php"] [unique_id "al4f4o06NaEKF1g_MW2t_QAAAFg"]
[Mon Jul 20 07:17:22.895814 2026] [security2:error] [pid 95128:tid 95602] [client 77.110.127.138:62539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f4ueSd8WoG-6-XpDVGwAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:22.895928 2026] [security2:error] [pid 95128:tid 95602] [client 77.110.127.138:62539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f4ueSd8WoG-6-XpDVGwAAAmo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:23.030644 2026] [security2:error] [pid 95128:tid 95390] [remote 45.84.107.182:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f4-eSd8WoG-6-XpDVIwACiAM"], referer: https://verdunestate.com/property-type/residential/
[Mon Jul 20 07:17:23.091040 2026] [security2:error] [pid 95128:tid 95584] [client 194.61.41.79:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDVGgAAAlg"]
[Mon Jul 20 07:17:23.155619 2026] [security2:error] [pid 95126:tid 95264] [client 77.110.127.138:62541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4wpx5ks9joCJTKW5EQAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:23.250383 2026] [security2:error] [pid 95128:tid 95589] [client 14.225.17.146:50688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4f4-eSd8WoG-6-XpDVKgAAAl0"], referer: https://ccsdifference.com/2019
[Mon Jul 20 07:17:23.311278 2026] [security2:error] [pid 95126:tid 95255] [remote 152.228.213.32:36106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4f4wpx5ks9joCJTKW5FgAB6n4"]
[Mon Jul 20 07:17:23.329531 2026] [security2:error] [pid 95126:tid 95284] [client 77.110.127.138:62503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f4wpx5ks9joCJTKW5EAAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:23.363000 2026] [security2:error] [pid 95128:tid 95572] [client 57.141.18.43:44978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f4eeSd8WoG-6-XpDUuwACTCc"]
[Mon Jul 20 07:17:23.428150 2026] [security2:error] [pid 94831:tid 94876] [remote 124.55.178.99:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4f4406NaEKF1g_MW2uAAAAYiw"]
[Mon Jul 20 07:17:23.451608 2026] [security2:error] [pid 95128:tid 95605] [client 77.110.127.138:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4-eSd8WoG-6-XpDVOwAAAm0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:23.524301 2026] [security2:error] [pid 95126:tid 95131] [remote 152.228.213.32:36106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4f4wpx5ks9joCJTKW5HQABtQI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:17:23.543868 2026] [security2:error] [pid 95126:tid 95256] [remote 45.76.153.27:44552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4f4wpx5ks9joCJTKW5HgABp38"]
[Mon Jul 20 07:17:23.636522 2026] [security2:error] [pid 95126:tid 95258] [client 14.225.17.146:52419] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4f4wpx5ks9joCJTKW5HAAAAY8"], referer: https://nurturemarple.co.uk/2019
[Mon Jul 20 07:17:23.641479 2026] [security2:error] [pid 95128:tid 95613] [client 20.220.9.199:55887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/fpwch.php"] [unique_id "al4f4-eSd8WoG-6-XpDVSQAAAnU"]
[Mon Jul 20 07:17:23.641607 2026] [security2:error] [pid 95128:tid 95613] [client 20.220.9.199:55887] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/fpwch.php"] [unique_id "al4f4-eSd8WoG-6-XpDVSQAAAnU"]
[Mon Jul 20 07:17:23.712181 2026] [security2:error] [pid 95128:tid 95509] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f4-eSd8WoG-6-XpDVTAACNXo"]
[Mon Jul 20 07:17:23.712350 2026] [security2:error] [pid 95128:tid 95549] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f4-eSd8WoG-6-XpDVTAACNXo"]
[Mon Jul 20 07:17:23.717165 2026] [security2:error] [pid 95128:tid 95547] [client 77.110.127.138:62543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f4-eSd8WoG-6-XpDVQAAAAjM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:23.815852 2026] [security2:error] [pid 95128:tid 95600] [client 57.141.18.60:24748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDU7gACaGs"]
[Mon Jul 20 07:17:23.830142 2026] [security2:error] [pid 95126:tid 95375] [client 14.225.17.146:50479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4f4gpx5ks9joCJTKW49QAAAgQ"], referer: http://fineartsfactory.net/2019
[Mon Jul 20 07:17:23.941171 2026] [security2:error] [pid 94831:tid 94875] [remote 124.55.178.99:38494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4f4406NaEKF1g_MW2uAwAAXSs"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:17:23.948426 2026] [security2:error] [pid 95128:tid 95632] [client 77.110.127.138:62545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f4-eSd8WoG-6-XpDVXgAAAog"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:24.070464 2026] [security2:error] [pid 95128:tid 95626] [client 57.141.18.4:35078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDU_AACggI"]
[Mon Jul 20 07:17:24.099799 2026] [proxy:error] [pid 95128:tid 95572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:24.099841 2026] [proxy_http:error] [pid 95128:tid 95572] [client 158.173.77.209:32645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:24.100492 2026] [proxy:error] [pid 95128:tid 95572] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:24.100521 2026] [proxy_http:error] [pid 95128:tid 95572] [client 158.173.77.209:32645] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:24.102296 2026] [security2:error] [pid 95128:tid 95601] [client 77.110.127.138:62510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f4-eSd8WoG-6-XpDVWgAAAmk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:24.191954 2026] [security2:error] [pid 95126:tid 95333] [client 143.44.185.218:51027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f5Apx5ks9joCJTKW5JgAAAdo"]
[Mon Jul 20 07:17:24.192051 2026] [security2:error] [pid 95126:tid 95333] [client 143.44.185.218:51027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f5Apx5ks9joCJTKW5JgAAAdo"]
[Mon Jul 20 07:17:24.268331 2026] [security2:error] [pid 94831:tid 94874] [remote 5.252.52.249:41850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f5I06NaEKF1g_MW2uBgAAaio"]
[Mon Jul 20 07:17:24.290647 2026] [security2:error] [pid 95128:tid 95554] [client 57.141.18.60:24754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f4ueSd8WoG-6-XpDVEQACOjE"]
[Mon Jul 20 07:17:24.423513 2026] [security2:error] [pid 95126:tid 95271] [client 20.220.9.199:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/w2025.php"] [unique_id "al4f5Apx5ks9joCJTKW5KwAAAZw"]
[Mon Jul 20 07:17:24.423603 2026] [security2:error] [pid 95126:tid 95271] [client 20.220.9.199:64190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/w2025.php"] [unique_id "al4f5Apx5ks9joCJTKW5KwAAAZw"]
[Mon Jul 20 07:17:24.624195 2026] [security2:error] [pid 95128:tid 95607] [client 144.172.114.51:44034] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/terraform/.env"] [unique_id "al4f5OeSd8WoG-6-XpDVigAAAm8"]
[Mon Jul 20 07:17:24.792446 2026] [security2:error] [pid 95126:tid 95379] [client 158.173.89.95:54027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f5Apx5ks9joCJTKW5NgAAAgg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:17:24.809428 2026] [security2:error] [pid 95128:tid 95531] [client 20.220.9.199:64447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/FWAZ.php"] [unique_id "al4f5OeSd8WoG-6-XpDVnQAAAiM"]
[Mon Jul 20 07:17:24.809522 2026] [security2:error] [pid 95128:tid 95531] [client 20.220.9.199:64447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/FWAZ.php"] [unique_id "al4f5OeSd8WoG-6-XpDVnQAAAiM"]
[Mon Jul 20 07:17:24.829556 2026] [security2:error] [pid 95126:tid 95385] [client 77.110.127.138:62547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f5Apx5ks9joCJTKW5OAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:24.843101 2026] [security2:error] [pid 95126:tid 95134] [remote 45.76.153.27:44552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4f5Apx5ks9joCJTKW5OwABrgU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:17:24.887360 2026] [security2:error] [pid 95128:tid 95579] [client 88.241.67.160:56058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f5OeSd8WoG-6-XpDVowAAAlM"]
[Mon Jul 20 07:17:24.888069 2026] [security2:error] [pid 95128:tid 95579] [client 88.241.67.160:56058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f5OeSd8WoG-6-XpDVowAAAlM"]
[Mon Jul 20 07:17:24.898449 2026] [security2:error] [pid 95128:tid 95589] [client 57.141.18.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4f5OeSd8WoG-6-XpDVlAAAAl0"]
[Mon Jul 20 07:17:25.054896 2026] [security2:error] [pid 95128:tid 95600] [client 20.220.9.199:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/qterm.php"] [unique_id "al4f5eeSd8WoG-6-XpDVtAAAAmg"]
[Mon Jul 20 07:17:25.054973 2026] [security2:error] [pid 95128:tid 95600] [client 20.220.9.199:64152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/qterm.php"] [unique_id "al4f5eeSd8WoG-6-XpDVtAAAAmg"]
[Mon Jul 20 07:17:25.066903 2026] [security2:error] [pid 94831:tid 94872] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f5Y06NaEKF1g_MW2uCgAAaCg"]
[Mon Jul 20 07:17:25.067109 2026] [security2:error] [pid 94831:tid 95065] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f5Y06NaEKF1g_MW2uCgAAaCg"]
[Mon Jul 20 07:17:25.175308 2026] [security2:error] [pid 95126:tid 95372] [client 77.110.127.138:62550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f5Apx5ks9joCJTKW5PQAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:25.229224 2026] [security2:error] [pid 94831:tid 94983] [client 20.220.9.199:55898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/blurbs.php"] [unique_id "al4f5Y06NaEKF1g_MW2uCwAAABY"]
[Mon Jul 20 07:17:25.229329 2026] [security2:error] [pid 94831:tid 94983] [client 20.220.9.199:55898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/blurbs.php"] [unique_id "al4f5Y06NaEKF1g_MW2uCwAAABY"]
[Mon Jul 20 07:17:25.275004 2026] [autoindex:error] [pid 95128:tid 95526] [client 194.61.41.79:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/uploads/2025/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:25.276863 2026] [security2:error] [pid 95126:tid 95139] [remote 152.228.213.32:48544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4f5Qpx5ks9joCJTKW5QwABlgo"]
[Mon Jul 20 07:17:25.475229 2026] [security2:error] [pid 95126:tid 95138] [remote 152.228.213.32:48544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4f5Qpx5ks9joCJTKW5UAAB5wk"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 07:17:25.519309 2026] [security2:error] [pid 94831:tid 95079] [client 20.220.9.199:64412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/v543.php"] [unique_id "al4f5Y06NaEKF1g_MW2uEwAAAHY"]
[Mon Jul 20 07:17:25.519398 2026] [security2:error] [pid 94831:tid 95079] [client 20.220.9.199:64412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/v543.php"] [unique_id "al4f5Y06NaEKF1g_MW2uEwAAAHY"]
[Mon Jul 20 07:17:25.612357 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:62553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f5Qpx5ks9joCJTKW5SgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:25.681100 2026] [autoindex:error] [pid 95126:tid 95324] [client 194.61.41.79:0] AH01276: Cannot serve directory /home3/dbnvkfmy/public_html/website_3ab692aa/wp-content/uploads/2026/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:25.732586 2026] [security2:error] [pid 95128:tid 95525] [client 20.220.9.199:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/w3lls.php"] [unique_id "al4f5eeSd8WoG-6-XpDV0QAAAh0"]
[Mon Jul 20 07:17:25.732698 2026] [security2:error] [pid 95128:tid 95525] [client 20.220.9.199:59933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/w3lls.php"] [unique_id "al4f5eeSd8WoG-6-XpDV0QAAAh0"]
[Mon Jul 20 07:17:25.781618 2026] [security2:error] [pid 94831:tid 94880] [remote 5.252.52.249:41850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f5Y06NaEKF1g_MW2uFQAANzA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:17:25.788457 2026] [security2:error] [pid 95128:tid 95619] [client 14.225.17.146:62550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4f5eeSd8WoG-6-XpDVzAAAAns"], referer: http://according2plant.com/2019
[Mon Jul 20 07:17:25.886446 2026] [security2:error] [pid 95126:tid 95311] [client 103.176.215.66:50064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f5Qpx5ks9joCJTKW5YQAAAcQ"]
[Mon Jul 20 07:17:25.886785 2026] [security2:error] [pid 95126:tid 95311] [client 103.176.215.66:50064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f5Qpx5ks9joCJTKW5YQAAAcQ"]
[Mon Jul 20 07:17:25.913971 2026] [security2:error] [pid 95128:tid 95586] [client 20.220.9.199:59919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-ws68.php"] [unique_id "al4f5eeSd8WoG-6-XpDV4QAAAlo"]
[Mon Jul 20 07:17:25.914082 2026] [security2:error] [pid 95128:tid 95586] [client 20.220.9.199:59919] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-ws68.php"] [unique_id "al4f5eeSd8WoG-6-XpDV4QAAAlo"]
[Mon Jul 20 07:17:26.126133 2026] [security2:error] [pid 95128:tid 95519] [client 20.220.9.199:64174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xyn.php"] [unique_id "al4f5ueSd8WoG-6-XpDV8AAAAhc"]
[Mon Jul 20 07:17:26.126239 2026] [security2:error] [pid 95128:tid 95519] [client 20.220.9.199:64174] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xyn.php"] [unique_id "al4f5ueSd8WoG-6-XpDV8AAAAhc"]
[Mon Jul 20 07:17:26.169375 2026] [security2:error] [pid 95128:tid 95520] [client 77.110.127.138:62560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f5eeSd8WoG-6-XpDV4wAAAhg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:26.229745 2026] [security2:error] [pid 95128:tid 95536] [client 57.141.18.112:32364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f5OeSd8WoG-6-XpDVnwACKDY"]
[Mon Jul 20 07:17:26.286044 2026] [security2:error] [pid 95128:tid 95618] [client 20.220.9.199:59943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/green3.php"] [unique_id "al4f5ueSd8WoG-6-XpDV-wAAAno"]
[Mon Jul 20 07:17:26.286176 2026] [security2:error] [pid 95128:tid 95618] [client 20.220.9.199:59943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/green3.php"] [unique_id "al4f5ueSd8WoG-6-XpDV-wAAAno"]
[Mon Jul 20 07:17:26.393268 2026] [security2:error] [pid 95128:tid 95538] [client 157.20.138.62:60867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f5ueSd8WoG-6-XpDWAgAAAio"]
[Mon Jul 20 07:17:26.393366 2026] [security2:error] [pid 95128:tid 95538] [client 157.20.138.62:60867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f5ueSd8WoG-6-XpDWAgAAAio"]
[Mon Jul 20 07:17:26.443330 2026] [security2:error] [pid 95128:tid 95589] [client 20.220.9.199:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ccc.php"] [unique_id "al4f5ueSd8WoG-6-XpDWCQAAAl0"]
[Mon Jul 20 07:17:26.443419 2026] [security2:error] [pid 95128:tid 95589] [client 20.220.9.199:64150] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ccc.php"] [unique_id "al4f5ueSd8WoG-6-XpDWCQAAAl0"]
[Mon Jul 20 07:17:26.577801 2026] [security2:error] [pid 95128:tid 95605] [client 20.220.9.199:55904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/get.php"] [unique_id "al4f5ueSd8WoG-6-XpDWEgAAAm0"]
[Mon Jul 20 07:17:26.577887 2026] [security2:error] [pid 95128:tid 95605] [client 20.220.9.199:55904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/get.php"] [unique_id "al4f5ueSd8WoG-6-XpDWEgAAAm0"]
[Mon Jul 20 07:17:26.608162 2026] [security2:error] [pid 95128:tid 95563] [client 57.141.18.117:32186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f5eeSd8WoG-6-XpDVtgACQyQ"]
[Mon Jul 20 07:17:26.655863 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f5o06NaEKF1g_MW2uGAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:26.655971 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:62562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f5o06NaEKF1g_MW2uGAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:26.670737 2026] [security2:error] [pid 95126:tid 95271] [client 194.61.41.79:37487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4f5gpx5ks9joCJTKW5ZAAAAZw"]
[Mon Jul 20 07:17:26.750807 2026] [security2:error] [pid 94831:tid 95021] [client 187.16.64.216:52334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f5o06NaEKF1g_MW2uGQAAADw"]
[Mon Jul 20 07:17:26.750898 2026] [security2:error] [pid 94831:tid 95021] [client 187.16.64.216:52334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f5o06NaEKF1g_MW2uGQAAADw"]
[Mon Jul 20 07:17:26.778305 2026] [security2:error] [pid 95128:tid 95611] [client 20.220.9.199:60367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/images.php"] [unique_id "al4f5ueSd8WoG-6-XpDWHQAAAnM"]
[Mon Jul 20 07:17:26.778388 2026] [security2:error] [pid 95128:tid 95611] [client 20.220.9.199:60367] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/images.php"] [unique_id "al4f5ueSd8WoG-6-XpDWHQAAAnM"]
[Mon Jul 20 07:17:26.805914 2026] [security2:error] [pid 95128:tid 95559] [client 77.110.127.138:62563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f5ueSd8WoG-6-XpDWHgAAAj8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:26.934506 2026] [security2:error] [pid 94831:tid 94985] [client 20.220.9.199:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/alls.php"] [unique_id "al4f5o06NaEKF1g_MW2uGwAAABg"]
[Mon Jul 20 07:17:26.934620 2026] [security2:error] [pid 94831:tid 94985] [client 20.220.9.199:59950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/alls.php"] [unique_id "al4f5o06NaEKF1g_MW2uGwAAABg"]
[Mon Jul 20 07:17:27.070273 2026] [security2:error] [pid 95128:tid 95570] [client 14.225.17.146:49213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4f5ueSd8WoG-6-XpDWAAAAAko"], referer: http://idigress.studio/2019
[Mon Jul 20 07:17:27.209941 2026] [security2:error] [pid 95126:tid 95312] [client 20.220.9.199:56309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/coffexium.php"] [unique_id "al4f5wpx5ks9joCJTKW5agAAAcU"]
[Mon Jul 20 07:17:27.210058 2026] [security2:error] [pid 95126:tid 95312] [client 20.220.9.199:56309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/coffexium.php"] [unique_id "al4f5wpx5ks9joCJTKW5agAAAcU"]
[Mon Jul 20 07:17:27.327018 2026] [security2:error] [pid 95128:tid 95533] [client 77.110.127.138:62565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f5ueSd8WoG-6-XpDWJgAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:27.451564 2026] [security2:error] [pid 95128:tid 95563] [client 20.220.9.199:60392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/red.php"] [unique_id "al4f5-eSd8WoG-6-XpDWQwAAAkM"]
[Mon Jul 20 07:17:27.451669 2026] [security2:error] [pid 95128:tid 95563] [client 20.220.9.199:60392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/red.php"] [unique_id "al4f5-eSd8WoG-6-XpDWQwAAAkM"]
[Mon Jul 20 07:17:27.592572 2026] [security2:error] [pid 95128:tid 95594] [client 49.37.242.14:49704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f5-eSd8WoG-6-XpDWSQAAAmI"]
[Mon Jul 20 07:17:27.592682 2026] [security2:error] [pid 95128:tid 95594] [client 49.37.242.14:49704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f5-eSd8WoG-6-XpDWSQAAAmI"]
[Mon Jul 20 07:17:27.649709 2026] [security2:error] [pid 95128:tid 95616] [client 144.172.114.51:44038] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/deployment/.env"] [unique_id "al4f5-eSd8WoG-6-XpDWTAAAAng"]
[Mon Jul 20 07:17:27.677390 2026] [proxy:error] [pid 95126:tid 95357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:27.677426 2026] [proxy_http:error] [pid 95126:tid 95357] [client 20.220.9.199:60392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:27.678063 2026] [proxy:error] [pid 95126:tid 95357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:27.678087 2026] [proxy_http:error] [pid 95126:tid 95357] [client 20.220.9.199:60392] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:27.678164 2026] [security2:error] [pid 95126:tid 95357] [client 20.220.9.199:60392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f5wpx5ks9joCJTKW5eAAAAfI"]
[Mon Jul 20 07:17:27.687170 2026] [security2:error] [pid 95128:tid 95617] [client 14.225.17.146:52181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bruceledewitz.com"] [uri "/index.php"] [unique_id "al4f5-eSd8WoG-6-XpDWPAAAAnk"], referer: http://bruceledewitz.com/2019
[Mon Jul 20 07:17:27.740868 2026] [security2:error] [pid 94831:tid 95034] [client 144.172.114.51:44048] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/ansible/.env"] [unique_id "al4f5406NaEKF1g_MW2uIwAAAEk"]
[Mon Jul 20 07:17:27.810180 2026] [security2:error] [pid 95126:tid 95275] [client 191.202.66.27:64234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f5wpx5ks9joCJTKW5eQAAAaA"]
[Mon Jul 20 07:17:27.810298 2026] [security2:error] [pid 95126:tid 95275] [client 191.202.66.27:64234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f5wpx5ks9joCJTKW5eQAAAaA"]
[Mon Jul 20 07:17:27.942813 2026] [security2:error] [pid 95128:tid 95553] [client 77.110.127.138:62575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f5-eSd8WoG-6-XpDWUwAAAjk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:28.023919 2026] [security2:error] [pid 95128:tid 95626] [client 20.220.9.199:60383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4f6OeSd8WoG-6-XpDWYgAAAoI"]
[Mon Jul 20 07:17:28.024015 2026] [security2:error] [pid 95128:tid 95626] [client 20.220.9.199:60383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4f6OeSd8WoG-6-XpDWYgAAAoI"]
[Mon Jul 20 07:17:28.116560 2026] [security2:error] [pid 95128:tid 95398] [remote 45.84.107.182:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f6OeSd8WoG-6-XpDWagACfgs"], referer: https://verdunestate.com/compare-properties/
[Mon Jul 20 07:17:28.142852 2026] [security2:error] [pid 95128:tid 95518] [client 77.110.127.138:62581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f6OeSd8WoG-6-XpDWbAAAAhY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:28.264797 2026] [proxy:error] [pid 95128:tid 95555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:28.264903 2026] [proxy_http:error] [pid 95128:tid 95555] [client 20.220.9.199:56307] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:28.266017 2026] [proxy:error] [pid 95128:tid 95555] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:28.266062 2026] [proxy_http:error] [pid 95128:tid 95555] [client 20.220.9.199:56307] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:28.266191 2026] [security2:error] [pid 95128:tid 95555] [client 20.220.9.199:56307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f6OeSd8WoG-6-XpDWdAAAAjs"]
[Mon Jul 20 07:17:28.469376 2026] [core:error] [pid 95128:tid 95611] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:28.469393 2026] [core:error] [pid 95128:tid 95611] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:28.536815 2026] [proxy:error] [pid 95128:tid 95577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:28.536888 2026] [proxy_http:error] [pid 95128:tid 95577] [client 20.220.9.199:59944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:28.537313 2026] [proxy:error] [pid 95128:tid 95577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:28.537337 2026] [proxy_http:error] [pid 95128:tid 95577] [client 20.220.9.199:59944] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:28.537411 2026] [security2:error] [pid 95128:tid 95577] [client 20.220.9.199:59944] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f6OeSd8WoG-6-XpDWigAAAlE"]
[Mon Jul 20 07:17:28.678848 2026] [security2:error] [pid 95126:tid 95298] [client 77.110.127.138:62550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f6Apx5ks9joCJTKW5fgAAAbc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:28.747062 2026] [security2:error] [pid 95128:tid 95641] [client 20.220.9.199:59961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/index.php"] [unique_id "al4f6OeSd8WoG-6-XpDWmQAAApE"]
[Mon Jul 20 07:17:28.747163 2026] [security2:error] [pid 95128:tid 95641] [client 20.220.9.199:59961] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/index.php"] [unique_id "al4f6OeSd8WoG-6-XpDWmQAAApE"]
[Mon Jul 20 07:17:28.914086 2026] [security2:error] [pid 95126:tid 95360] [client 57.141.18.34:41330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f5wpx5ks9joCJTKW5bgAB9RM"]
[Mon Jul 20 07:17:28.977362 2026] [security2:error] [pid 95126:tid 95306] [client 57.141.18.25:59526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f5wpx5ks9joCJTKW5cgABvxA"]
[Mon Jul 20 07:17:29.002959 2026] [security2:error] [pid 95128:tid 95558] [client 77.110.127.138:62589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f6eeSd8WoG-6-XpDWqAAAAj4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:29.003054 2026] [security2:error] [pid 95128:tid 95558] [client 77.110.127.138:62589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f6eeSd8WoG-6-XpDWqAAAAj4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:29.054299 2026] [security2:error] [pid 95128:tid 95606] [client 77.110.127.138:62558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f6eeSd8WoG-6-XpDWqwAAAm4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:29.164552 2026] [security2:error] [pid 95128:tid 95633] [client 20.220.9.199:64140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/admin.php"] [unique_id "al4f6eeSd8WoG-6-XpDWsgAAAok"]
[Mon Jul 20 07:17:29.164639 2026] [security2:error] [pid 95128:tid 95633] [client 20.220.9.199:64140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/admin.php"] [unique_id "al4f6eeSd8WoG-6-XpDWsgAAAok"]
[Mon Jul 20 07:17:29.282718 2026] [security2:error] [pid 95128:tid 95575] [client 74.208.214.194:43070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4f6eeSd8WoG-6-XpDWuwAAAk8"]
[Mon Jul 20 07:17:29.308131 2026] [security2:error] [pid 95128:tid 95538] [client 154.192.123.127:17870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f6eeSd8WoG-6-XpDWvgAAAio"]
[Mon Jul 20 07:17:29.308238 2026] [security2:error] [pid 95128:tid 95538] [client 154.192.123.127:17870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f6eeSd8WoG-6-XpDWvgAAAio"]
[Mon Jul 20 07:17:29.352792 2026] [security2:error] [pid 95128:tid 95577] [client 20.220.9.199:59936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/177.php"] [unique_id "al4f6eeSd8WoG-6-XpDWwAAAAlE"]
[Mon Jul 20 07:17:29.352892 2026] [security2:error] [pid 95128:tid 95577] [client 20.220.9.199:59936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/177.php"] [unique_id "al4f6eeSd8WoG-6-XpDWwAAAAlE"]
[Mon Jul 20 07:17:29.379247 2026] [security2:error] [pid 95128:tid 95594] [client 117.211.236.168:57947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f6eeSd8WoG-6-XpDWwgAAAmI"]
[Mon Jul 20 07:17:29.379324 2026] [security2:error] [pid 95128:tid 95594] [client 117.211.236.168:57947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f6eeSd8WoG-6-XpDWwgAAAmI"]
[Mon Jul 20 07:17:29.673346 2026] [security2:error] [pid 95126:tid 95341] [client 77.110.127.138:62591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f6Qpx5ks9joCJTKW5kAAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:29.677514 2026] [security2:error] [pid 95128:tid 95417] [remote 188.166.241.141:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f6eeSd8WoG-6-XpDW0gACcx4"]
[Mon Jul 20 07:17:29.824259 2026] [security2:error] [pid 95126:tid 95297] [client 14.225.17.146:54247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4f6Qpx5ks9joCJTKW5iAAAAbY"], referer: http://talknutritionwithlesley.com/2019
[Mon Jul 20 07:17:29.824710 2026] [security2:error] [pid 95126:tid 95287] [client 77.110.127.138:62593] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4f6Qpx5ks9joCJTKW5lAAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:29.957551 2026] [security2:error] [pid 94831:tid 95010] [client 20.220.9.199:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/199.php"] [unique_id "al4f6Y06NaEKF1g_MW2uMwAAADE"]
[Mon Jul 20 07:17:29.957712 2026] [security2:error] [pid 94831:tid 95010] [client 20.220.9.199:64387] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/199.php"] [unique_id "al4f6Y06NaEKF1g_MW2uMwAAADE"]
[Mon Jul 20 07:17:30.049689 2026] [security2:error] [pid 95128:tid 95640] [client 57.141.18.68:38064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f6OeSd8WoG-6-XpDWjQACkHo"]
[Mon Jul 20 07:17:30.052006 2026] [security2:error] [pid 95128:tid 95451] [remote 57.141.18.45:34494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4695448"] [unique_id "al4f6ueSd8WoG-6-XpDW4wAChEA"]
[Mon Jul 20 07:17:30.065665 2026] [security2:error] [pid 95128:tid 95442] [remote 188.166.241.141:36024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f6ueSd8WoG-6-XpDW5AACLjc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:17:30.325323 2026] [security2:error] [pid 95126:tid 95365] [client 14.225.17.146:62699] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4f6Qpx5ks9joCJTKW5lwAAAfo"], referer: http://overloadcomedy.com/2019
[Mon Jul 20 07:17:30.353990 2026] [security2:error] [pid 95128:tid 95604] [client 14.225.17.146:62366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4f6ueSd8WoG-6-XpDW8gAAAmw"], referer: http://39ishlife.com/2019
[Mon Jul 20 07:17:30.685270 2026] [security2:error] [pid 95128:tid 95626] [client 52.109.68.130:10609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4f6ueSd8WoG-6-XpDXCwAAAoI"]
[Mon Jul 20 07:17:30.735593 2026] [security2:error] [pid 95126:tid 95384] [client 57.141.18.120:56610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f6Qpx5ks9joCJTKW5iQACDX0"]
[Mon Jul 20 07:17:30.843171 2026] [security2:error] [pid 95128:tid 95555] [client 52.109.68.130:10609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4f6ueSd8WoG-6-XpDXFgAAAjs"]
[Mon Jul 20 07:17:30.910209 2026] [security2:error] [pid 95128:tid 95602] [client 50.116.65.227:43226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/Comida-Mexicana-Feature-Image.jpg"] [unique_id "al4f6ueSd8WoG-6-XpDXGgAAAmo"]
[Mon Jul 20 07:17:30.924169 2026] [security2:error] [pid 95128:tid 95635] [client 50.116.65.227:42426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/Comida-Mexicana-Feature-Image.jpg"] [unique_id "al4f6ueSd8WoG-6-XpDXHQAAAos"]
[Mon Jul 20 07:17:30.925688 2026] [security2:error] [pid 95128:tid 95575] [client 20.220.9.199:60414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file52.php"] [unique_id "al4f6ueSd8WoG-6-XpDXIAAAAk8"]
[Mon Jul 20 07:17:30.925837 2026] [security2:error] [pid 95128:tid 95575] [client 20.220.9.199:60414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file52.php"] [unique_id "al4f6ueSd8WoG-6-XpDXIAAAAk8"]
[Mon Jul 20 07:17:31.112398 2026] [security2:error] [pid 95128:tid 95517] [client 20.220.9.199:59955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/geck.php"] [unique_id "al4f6-eSd8WoG-6-XpDXLwAAAhU"]
[Mon Jul 20 07:17:31.112498 2026] [security2:error] [pid 95128:tid 95517] [client 20.220.9.199:59955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/geck.php"] [unique_id "al4f6-eSd8WoG-6-XpDXLwAAAhU"]
[Mon Jul 20 07:17:31.135421 2026] [autoindex:error] [pid 95128:tid 95524] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:31.143360 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:62582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f6wpx5ks9joCJTKW5pgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:31.143498 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:62582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f6wpx5ks9joCJTKW5pgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:31.177080 2026] [security2:error] [pid 95128:tid 95617] [client 136.116.39.53:36778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4f6-eSd8WoG-6-XpDXLQACeTs"], referer: http://adultdaycarereno.com/robots.txt
[Mon Jul 20 07:17:31.194149 2026] [security2:error] [pid 95126:tid 95264] [client 77.110.127.138:62550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f6wpx5ks9joCJTKW5qgAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:31.314549 2026] [security2:error] [pid 95128:tid 95533] [client 52.109.52.84:30017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4f6-eSd8WoG-6-XpDXPgAAAiU"]
[Mon Jul 20 07:17:31.323255 2026] [security2:error] [pid 94831:tid 95018] [client 20.220.9.199:59960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/biufile.php"] [unique_id "al4f6406NaEKF1g_MW2uQQAAADk"]
[Mon Jul 20 07:17:31.323373 2026] [security2:error] [pid 94831:tid 95018] [client 20.220.9.199:59960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/biufile.php"] [unique_id "al4f6406NaEKF1g_MW2uQQAAADk"]
[Mon Jul 20 07:17:31.358905 2026] [security2:error] [pid 95128:tid 95609] [client 77.110.127.138:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f6-eSd8WoG-6-XpDXQAAAAnE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:31.395692 2026] [security2:error] [pid 95128:tid 95583] [client 201.27.111.74:53273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f6-eSd8WoG-6-XpDXQgAAAlc"]
[Mon Jul 20 07:17:31.395788 2026] [security2:error] [pid 95128:tid 95583] [client 201.27.111.74:53273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f6-eSd8WoG-6-XpDXQgAAAlc"]
[Mon Jul 20 07:17:31.427810 2026] [security2:error] [pid 95128:tid 95593] [client 52.109.52.84:30017] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4f6-eSd8WoG-6-XpDXRQAAAmE"]
[Mon Jul 20 07:17:31.507961 2026] [security2:error] [pid 95128:tid 95629] [client 77.110.127.138:62602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4f6-eSd8WoG-6-XpDXTgAAAoU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:31.586043 2026] [access_compat:error] [pid 95128:tid 95500] [remote 152.202.229.107:51254] AH01797: client denied by server configuration: /home3/aviatjd3/public_html/.website_a62aee27/wp-login.php
[Mon Jul 20 07:17:31.616773 2026] [security2:error] [pid 95126:tid 95351] [client 20.220.9.199:60366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/mosty.php"] [unique_id "al4f6wpx5ks9joCJTKW5rQAAAew"]
[Mon Jul 20 07:17:31.616860 2026] [security2:error] [pid 95126:tid 95351] [client 20.220.9.199:60366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/mosty.php"] [unique_id "al4f6wpx5ks9joCJTKW5rQAAAew"]
[Mon Jul 20 07:17:31.777607 2026] [security2:error] [pid 95126:tid 95261] [client 14.225.17.146:50111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4f6wpx5ks9joCJTKW5rgAAAZI"], referer: http://carolinapressurewashers.com/2019
[Mon Jul 20 07:17:31.787710 2026] [security2:error] [pid 95128:tid 95547] [client 74.208.214.194:43074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4f6-eSd8WoG-6-XpDXYQAAAjM"]
[Mon Jul 20 07:17:31.857208 2026] [security2:error] [pid 94831:tid 95067] [client 20.220.9.199:56272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/dejavu.php"] [unique_id "al4f6406NaEKF1g_MW2uRwAAAGo"]
[Mon Jul 20 07:17:31.857362 2026] [security2:error] [pid 94831:tid 95067] [client 20.220.9.199:56272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/dejavu.php"] [unique_id "al4f6406NaEKF1g_MW2uRwAAAGo"]
[Mon Jul 20 07:17:31.879413 2026] [security2:error] [pid 95128:tid 95561] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f6-eSd8WoG-6-XpDXVAAAAkE"], referer: 1'"3000
[Mon Jul 20 07:17:31.922479 2026] [security2:error] [pid 95128:tid 95589] [client 14.225.17.146:50139] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4f6-eSd8WoG-6-XpDXWwAAAl0"], referer: http://longevityperformanceclinic.com/2019
[Mon Jul 20 07:17:32.110698 2026] [security2:error] [pid 95126:tid 95359] [client 57.141.18.21:20094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f6gpx5ks9joCJTKW5owAB9Bs"]
[Mon Jul 20 07:17:32.270293 2026] [security2:error] [pid 95126:tid 95281] [client 104.234.53.71:24683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4f7Apx5ks9joCJTKW5wgAAAaY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:32.391005 2026] [security2:error] [pid 95128:tid 95606] [client 14.225.17.146:52167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4f6ueSd8WoG-6-XpDXIQAAAm4"], referer: http://detroitcsc.com/2019
[Mon Jul 20 07:17:32.467704 2026] [security2:error] [pid 95128:tid 95571] [client 57.141.18.107:49488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f6-eSd8WoG-6-XpDXMQACS0k"]
[Mon Jul 20 07:17:32.473108 2026] [security2:error] [pid 95128:tid 95579] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f7OeSd8WoG-6-XpDXdwAAAlM"], referer: 1'"3000
[Mon Jul 20 07:17:32.594704 2026] [security2:error] [pid 95128:tid 95613] [client 20.220.9.199:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/aaf.php"] [unique_id "al4f7OeSd8WoG-6-XpDXigAAAnU"]
[Mon Jul 20 07:17:32.594799 2026] [security2:error] [pid 95128:tid 95613] [client 20.220.9.199:64137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/aaf.php"] [unique_id "al4f7OeSd8WoG-6-XpDXigAAAnU"]
[Mon Jul 20 07:17:32.830477 2026] [security2:error] [pid 95128:tid 95546] [client 20.220.9.199:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ha.php"] [unique_id "al4f7OeSd8WoG-6-XpDXnQAAAjI"]
[Mon Jul 20 07:17:32.830576 2026] [security2:error] [pid 95128:tid 95546] [client 20.220.9.199:55884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ha.php"] [unique_id "al4f7OeSd8WoG-6-XpDXnQAAAjI"]
[Mon Jul 20 07:17:32.882959 2026] [security2:error] [pid 95128:tid 95565] [client 103.144.65.217:51054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f7OeSd8WoG-6-XpDXnwAAAkU"]
[Mon Jul 20 07:17:32.883091 2026] [security2:error] [pid 95128:tid 95565] [client 103.144.65.217:51054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f7OeSd8WoG-6-XpDXnwAAAkU"]
[Mon Jul 20 07:17:32.927350 2026] [security2:error] [pid 95128:tid 95620] [client 77.110.127.138:62608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f7OeSd8WoG-6-XpDXoAAAAnw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:32.927472 2026] [security2:error] [pid 95128:tid 95620] [client 77.110.127.138:62608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f7OeSd8WoG-6-XpDXoAAAAnw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:32.956454 2026] [security2:error] [pid 95128:tid 95604] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f7OeSd8WoG-6-XpDXlQAAAmw"], referer: 1'"3000
[Mon Jul 20 07:17:33.006478 2026] [security2:error] [pid 95126:tid 95171] [remote 142.93.10.93:52984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4f7Apx5ks9joCJTKW50AABvio"]
[Mon Jul 20 07:17:33.115986 2026] [security2:error] [pid 95128:tid 95593] [client 20.220.9.199:64389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/hur.php"] [unique_id "al4f7eeSd8WoG-6-XpDXqwAAAmE"]
[Mon Jul 20 07:17:33.116088 2026] [security2:error] [pid 95128:tid 95593] [client 20.220.9.199:64389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/hur.php"] [unique_id "al4f7eeSd8WoG-6-XpDXqwAAAmE"]
[Mon Jul 20 07:17:33.147002 2026] [security2:error] [pid 95126:tid 95160] [remote 68.178.160.25:39362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4f7Qpx5ks9joCJTKW51AABnR8"]
[Mon Jul 20 07:17:33.150281 2026] [security2:error] [pid 95128:tid 95397] [remote 45.84.107.182:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f7eeSd8WoG-6-XpDXrQACSgo"], referer: https://verdunestate.com/property-listing/
[Mon Jul 20 07:17:33.178776 2026] [security2:error] [pid 95126:tid 95178] [remote 142.93.10.93:52984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4f7Qpx5ks9joCJTKW51gABjzE"], referer: https://alaraycreative.com/wp-login.php
[Mon Jul 20 07:17:33.324224 2026] [security2:error] [pid 95128:tid 95537] [client 20.220.9.199:56302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/h02ugyh.php"] [unique_id "al4f7eeSd8WoG-6-XpDXuwAAAik"]
[Mon Jul 20 07:17:33.324327 2026] [security2:error] [pid 95128:tid 95537] [client 20.220.9.199:56302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/h02ugyh.php"] [unique_id "al4f7eeSd8WoG-6-XpDXuwAAAik"]
[Mon Jul 20 07:17:33.366119 2026] [security2:error] [pid 95126:tid 95293] [client 104.234.53.71:24683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4f7Qpx5ks9joCJTKW52gAAAbI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:33.419185 2026] [security2:error] [pid 95128:tid 95544] [client 154.217.204.171:35731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hedgerow-crafts.com"] [uri "/index.php"] [unique_id "al4f7eeSd8WoG-6-XpDXpwAAAjA"]
[Mon Jul 20 07:17:33.429172 2026] [security2:error] [pid 95128:tid 95553] [client 154.208.48.130:49815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f7eeSd8WoG-6-XpDXwQAAAjk"]
[Mon Jul 20 07:17:33.429284 2026] [security2:error] [pid 95128:tid 95553] [client 154.208.48.130:49815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f7eeSd8WoG-6-XpDXwQAAAjk"]
[Mon Jul 20 07:17:33.451108 2026] [security2:error] [pid 95126:tid 95319] [client 50.116.65.227:42502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4f7Qpx5ks9joCJTKW53AAAAcw"]
[Mon Jul 20 07:17:33.462554 2026] [security2:error] [pid 95128:tid 95585] [client 50.116.65.227:42518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4f7eeSd8WoG-6-XpDXwgAAAlk"]
[Mon Jul 20 07:17:33.510548 2026] [security2:error] [pid 95128:tid 95555] [client 20.220.9.199:56317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/155.php"] [unique_id "al4f7eeSd8WoG-6-XpDXxQAAAjs"]
[Mon Jul 20 07:17:33.510645 2026] [security2:error] [pid 95128:tid 95555] [client 20.220.9.199:56317] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/155.php"] [unique_id "al4f7eeSd8WoG-6-XpDXxQAAAjs"]
[Mon Jul 20 07:17:33.584150 2026] [security2:error] [pid 95126:tid 95173] [remote 68.178.160.25:39362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4f7Qpx5ks9joCJTKW53QACDiw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:17:33.652818 2026] [security2:error] [pid 95126:tid 95340] [client 77.110.127.138:62610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f7Qpx5ks9joCJTKW54AAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:33.675001 2026] [security2:error] [pid 94831:tid 94909] [remote 173.212.252.15:42172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f7Y06NaEKF1g_MW2uXwAAYk0"]
[Mon Jul 20 07:17:33.675210 2026] [security2:error] [pid 94831:tid 95059] [client 173.212.252.15:42172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f7Y06NaEKF1g_MW2uXwAAYk0"]
[Mon Jul 20 07:17:33.678384 2026] [security2:error] [pid 95126:tid 95333] [client 20.220.9.199:64191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/pp.php"] [unique_id "al4f7Qpx5ks9joCJTKW54wAAAdo"]
[Mon Jul 20 07:17:33.678485 2026] [security2:error] [pid 95126:tid 95333] [client 20.220.9.199:64191] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/pp.php"] [unique_id "al4f7Qpx5ks9joCJTKW54wAAAdo"]
[Mon Jul 20 07:17:33.703929 2026] [security2:error] [pid 95128:tid 95605] [client 77.110.127.138:62575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f7eeSd8WoG-6-XpDXzQAAAm0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:33.756287 2026] [security2:error] [pid 95128:tid 95565] [client 77.110.127.138:62598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4f7eeSd8WoG-6-XpDX1QAAAkU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:33.999455 2026] [security2:error] [pid 95128:tid 95573] [client 20.220.9.199:64145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ops.php"] [unique_id "al4f7eeSd8WoG-6-XpDX5gAAAk0"]
[Mon Jul 20 07:17:33.999558 2026] [security2:error] [pid 95128:tid 95573] [client 20.220.9.199:64145] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ops.php"] [unique_id "al4f7eeSd8WoG-6-XpDX5gAAAk0"]
[Mon Jul 20 07:17:34.129284 2026] [security2:error] [pid 95128:tid 95588] [client 20.220.9.199:55889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ingfo.php"] [unique_id "al4f7ueSd8WoG-6-XpDX7wAAAlw"]
[Mon Jul 20 07:17:34.129376 2026] [security2:error] [pid 95128:tid 95588] [client 20.220.9.199:55889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ingfo.php"] [unique_id "al4f7ueSd8WoG-6-XpDX7wAAAlw"]
[Mon Jul 20 07:17:34.177446 2026] [security2:error] [pid 95128:tid 95538] [client 57.141.18.45:51022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f7OeSd8WoG-6-XpDXjwACKjg"]
[Mon Jul 20 07:17:34.295431 2026] [security2:error] [pid 95126:tid 95359] [client 20.220.9.199:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/error_log.php"] [unique_id "al4f7gpx5ks9joCJTKW55gAAAfQ"]
[Mon Jul 20 07:17:34.295528 2026] [security2:error] [pid 95126:tid 95359] [client 20.220.9.199:59962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/error_log.php"] [unique_id "al4f7gpx5ks9joCJTKW55gAAAfQ"]
[Mon Jul 20 07:17:34.386240 2026] [security2:error] [pid 95128:tid 95405] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f7ueSd8WoG-6-XpDYBwACihI"]
[Mon Jul 20 07:17:34.386496 2026] [security2:error] [pid 95128:tid 95634] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f7ueSd8WoG-6-XpDYBwACihI"]
[Mon Jul 20 07:17:34.580010 2026] [security2:error] [pid 95128:tid 95562] [client 20.220.9.199:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/test10.php"] [unique_id "al4f7ueSd8WoG-6-XpDYFQAAAkI"]
[Mon Jul 20 07:17:34.580101 2026] [security2:error] [pid 95128:tid 95562] [client 20.220.9.199:56262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/test10.php"] [unique_id "al4f7ueSd8WoG-6-XpDYFQAAAkI"]
[Mon Jul 20 07:17:34.595014 2026] [security2:error] [pid 95128:tid 95424] [remote 15.206.251.117:48486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4f7ueSd8WoG-6-XpDYFwACZSU"]
[Mon Jul 20 07:17:34.647992 2026] [security2:error] [pid 95128:tid 95559] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4f7ueSd8WoG-6-XpDYFAACP1E"], referer: http://aleishapenny.ca/2019
[Mon Jul 20 07:17:34.788438 2026] [security2:error] [pid 95128:tid 95592] [client 20.220.9.199:64163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/koala.php"] [unique_id "al4f7ueSd8WoG-6-XpDYJQAAAmA"]
[Mon Jul 20 07:17:34.788527 2026] [security2:error] [pid 95128:tid 95592] [client 20.220.9.199:64163] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/koala.php"] [unique_id "al4f7ueSd8WoG-6-XpDYJQAAAmA"]
[Mon Jul 20 07:17:34.915270 2026] [security2:error] [pid 95128:tid 95576] [client 143.44.185.218:52595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f7ueSd8WoG-6-XpDYLgAAAlA"]
[Mon Jul 20 07:17:34.915438 2026] [security2:error] [pid 95128:tid 95576] [client 143.44.185.218:52595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f7ueSd8WoG-6-XpDYLgAAAlA"]
[Mon Jul 20 07:17:35.021884 2026] [security2:error] [pid 95128:tid 95465] [remote 15.206.251.117:48486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4f7-eSd8WoG-6-XpDYNwACik4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:17:35.048984 2026] [security2:error] [pid 95126:tid 95368] [client 158.173.166.181:52811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f7wpx5ks9joCJTKW59AAAAf0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:17:35.169832 2026] [autoindex:error] [pid 95128:tid 95573] [client 147.93.171.185:62728] AH01276: Cannot serve directory /home3/anastbi7/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:17:35.279884 2026] [security2:error] [pid 95128:tid 95567] [client 20.220.9.199:64165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/mac.php"] [unique_id "al4f7-eSd8WoG-6-XpDYSwAAAkc"]
[Mon Jul 20 07:17:35.280010 2026] [security2:error] [pid 95128:tid 95567] [client 20.220.9.199:64165] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/mac.php"] [unique_id "al4f7-eSd8WoG-6-XpDYSwAAAkc"]
[Mon Jul 20 07:17:35.344549 2026] [security2:error] [pid 95128:tid 95586] [client 57.141.18.14:21762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f7eeSd8WoG-6-XpDX0gACWic"]
[Mon Jul 20 07:17:35.430549 2026] [security2:error] [pid 94831:tid 95082] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4f7406NaEKF1g_MW2uZwAAeUo"], referer: https://aleishapenny.ca/2019
[Mon Jul 20 07:17:35.524096 2026] [security2:error] [pid 95128:tid 95604] [client 88.241.67.160:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f7-eSd8WoG-6-XpDYYQAAAmw"]
[Mon Jul 20 07:17:35.524301 2026] [security2:error] [pid 95128:tid 95604] [client 88.241.67.160:56274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f7-eSd8WoG-6-XpDYYQAAAmw"]
[Mon Jul 20 07:17:35.649560 2026] [security2:error] [pid 95128:tid 95631] [client 57.141.18.20:21160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f7ueSd8WoG-6-XpDX5wACh1o"]
[Mon Jul 20 07:17:35.679997 2026] [security2:error] [pid 95128:tid 95568] [client 20.220.9.199:59923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wefile.php"] [unique_id "al4f7-eSd8WoG-6-XpDYaAAAAkg"]
[Mon Jul 20 07:17:35.680100 2026] [security2:error] [pid 95128:tid 95568] [client 20.220.9.199:59923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wefile.php"] [unique_id "al4f7-eSd8WoG-6-XpDYaAAAAkg"]
[Mon Jul 20 07:17:35.820297 2026] [security2:error] [pid 95128:tid 95498] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f7-eSd8WoG-6-XpDYbwACIG8"]
[Mon Jul 20 07:17:35.820470 2026] [security2:error] [pid 95128:tid 95528] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f7-eSd8WoG-6-XpDYbwACIG8"]
[Mon Jul 20 07:17:35.896145 2026] [security2:error] [pid 95128:tid 95600] [client 57.141.18.67:62152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f7ueSd8WoG-6-XpDYBgACaHA"]
[Mon Jul 20 07:17:35.899877 2026] [security2:error] [pid 95128:tid 95567] [client 77.110.127.138:62615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f7-eSd8WoG-6-XpDYfQAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:35.899981 2026] [security2:error] [pid 95128:tid 95567] [client 77.110.127.138:62615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f7-eSd8WoG-6-XpDYfQAAAkc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:35.915433 2026] [proxy:error] [pid 95126:tid 95308] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:35.915498 2026] [proxy_http:error] [pid 95126:tid 95308] [client 20.220.9.199:50909] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:35.915971 2026] [proxy:error] [pid 95126:tid 95308] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:35.916000 2026] [proxy_http:error] [pid 95126:tid 95308] [client 20.220.9.199:50909] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:35.916085 2026] [security2:error] [pid 95126:tid 95308] [client 20.220.9.199:50909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f7wpx5ks9joCJTKW5-wAAAcE"]
[Mon Jul 20 07:17:35.954200 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:62583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f7-eSd8WoG-6-XpDYhQAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:35.954298 2026] [security2:error] [pid 95128:tid 95537] [client 77.110.127.138:62583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f7-eSd8WoG-6-XpDYhQAAAik"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.019125 2026] [security2:error] [pid 95126:tid 95373] [client 14.225.17.146:60117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4f7wpx5ks9joCJTKW5-QAAAgI"], referer: http://soloceos.com/2019
[Mon Jul 20 07:17:36.102968 2026] [proxy:error] [pid 95128:tid 95570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:36.103048 2026] [proxy_http:error] [pid 95128:tid 95570] [client 20.220.9.199:56316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:36.103662 2026] [proxy:error] [pid 95128:tid 95570] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:36.103704 2026] [proxy_http:error] [pid 95128:tid 95570] [client 20.220.9.199:56316] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:36.103799 2026] [security2:error] [pid 95128:tid 95570] [client 20.220.9.199:56316] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f8OeSd8WoG-6-XpDYiwAAAko"]
[Mon Jul 20 07:17:36.109790 2026] [security2:error] [pid 95126:tid 95298] [client 77.110.127.138:62618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8Apx5ks9joCJTKW6AgAAAbc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.109869 2026] [security2:error] [pid 95126:tid 95298] [client 77.110.127.138:62618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8Apx5ks9joCJTKW6AgAAAbc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.203801 2026] [security2:error] [pid 94831:tid 95041] [client 104.234.53.80:55459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4f8I06NaEKF1g_MW2uawAAAFA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:36.237479 2026] [security2:error] [pid 95128:tid 95643] [client 77.110.127.138:62586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYlAAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.237623 2026] [security2:error] [pid 95128:tid 95643] [client 77.110.127.138:62586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYlAAAApM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.289655 2026] [security2:error] [pid 95128:tid 95533] [client 77.110.127.138:62604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYmAAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.290021 2026] [security2:error] [pid 95128:tid 95533] [client 77.110.127.138:62604] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYmAAAAiU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:36.311757 2026] [security2:error] [pid 95128:tid 95616] [client 20.220.9.199:50973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/makeasmtp.php"] [unique_id "al4f8OeSd8WoG-6-XpDYmQAAAng"]
[Mon Jul 20 07:17:36.311875 2026] [security2:error] [pid 95128:tid 95616] [client 20.220.9.199:50973] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/makeasmtp.php"] [unique_id "al4f8OeSd8WoG-6-XpDYmQAAAng"]
[Mon Jul 20 07:17:36.341137 2026] [security2:error] [pid 95128:tid 95517] [client 77.110.127.138:62561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYngAAAhU"]
[Mon Jul 20 07:17:36.341252 2026] [security2:error] [pid 95128:tid 95517] [client 77.110.127.138:62561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYngAAAhU"]
[Mon Jul 20 07:17:36.362138 2026] [security2:error] [pid 95128:tid 95409] [remote 149.88.64.125:48656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.64.88.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4f8OeSd8WoG-6-XpDYoAACaRY"]
[Mon Jul 20 07:17:36.370741 2026] [security2:error] [pid 95128:tid 95549] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hwa.hne.mybluehost.me"] [uri "/index.php"] [unique_id "al4f7ueSd8WoG-6-XpDYIgAAAjU"]
[Mon Jul 20 07:17:36.373183 2026] [security2:error] [pid 95128:tid 95550] [client 74.7.241.155:37664] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hwa.hne.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4f7ueSd8WoG-6-XpDYHgAAAjY"]
[Mon Jul 20 07:17:36.459009 2026] [security2:error] [pid 95128:tid 95449] [remote 160.187.68.132:33230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4f8OeSd8WoG-6-XpDYrAACfD4"]
[Mon Jul 20 07:17:36.460324 2026] [security2:error] [pid 95126:tid 95260] [client 20.220.9.199:64410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/2P.php"] [unique_id "al4f8Apx5ks9joCJTKW6BQAAAZE"]
[Mon Jul 20 07:17:36.460396 2026] [security2:error] [pid 95126:tid 95260] [client 20.220.9.199:64410] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/2P.php"] [unique_id "al4f8Apx5ks9joCJTKW6BQAAAZE"]
[Mon Jul 20 07:17:36.495131 2026] [security2:error] [pid 95128:tid 95540] [client 103.176.215.66:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f8OeSd8WoG-6-XpDYswAAAiw"]
[Mon Jul 20 07:17:36.495550 2026] [security2:error] [pid 95128:tid 95518] [client 77.110.127.138:62620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYsgAAAhY"]
[Mon Jul 20 07:17:36.495660 2026] [security2:error] [pid 95128:tid 95518] [client 77.110.127.138:62620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8OeSd8WoG-6-XpDYsgAAAhY"]
[Mon Jul 20 07:17:36.495805 2026] [security2:error] [pid 95128:tid 95540] [client 103.176.215.66:50585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f8OeSd8WoG-6-XpDYswAAAiw"]
[Mon Jul 20 07:17:36.628681 2026] [security2:error] [pid 95128:tid 95628] [client 57.141.18.107:49500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f7-eSd8WoG-6-XpDYTAAChHM"]
[Mon Jul 20 07:17:36.672096 2026] [security2:error] [pid 95128:tid 95538] [client 20.220.9.199:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/.well-known/about.php"] [unique_id "al4f8OeSd8WoG-6-XpDYugAAAio"]
[Mon Jul 20 07:17:36.672243 2026] [security2:error] [pid 95128:tid 95538] [client 20.220.9.199:60390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/.well-known/about.php"] [unique_id "al4f8OeSd8WoG-6-XpDYugAAAio"]
[Mon Jul 20 07:17:36.703695 2026] [core:alert] [pid 95128:tid 95539] [client 124.156.225.181:51620] /home3/princfv3/public_html/.htaccess: php_value takes two arguments, PHP Value, referer: http://www.pathwaypuppetproductions.com
[Mon Jul 20 07:17:36.868952 2026] [security2:error] [pid 95128:tid 95614] [client 57.141.18.105:64006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f7-eSd8WoG-6-XpDYZQACdhk"]
[Mon Jul 20 07:17:36.972718 2026] [security2:error] [pid 95128:tid 95562] [client 157.20.138.62:61514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f8OeSd8WoG-6-XpDY0AAAAkI"]
[Mon Jul 20 07:17:36.972843 2026] [security2:error] [pid 95128:tid 95562] [client 157.20.138.62:61514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f8OeSd8WoG-6-XpDY0AAAAkI"]
[Mon Jul 20 07:17:36.976723 2026] [security2:error] [pid 95128:tid 95486] [remote 160.187.68.132:33230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4f8OeSd8WoG-6-XpDYzwACimM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:17:37.087571 2026] [security2:error] [pid 95128:tid 95437] [remote 117.0.21.154:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4f8eeSd8WoG-6-XpDY1gACZzI"]
[Mon Jul 20 07:17:37.212915 2026] [security2:error] [pid 95128:tid 95588] [client 20.220.9.199:56257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4f8eeSd8WoG-6-XpDY4QAAAlw"]
[Mon Jul 20 07:17:37.213020 2026] [security2:error] [pid 95128:tid 95588] [client 20.220.9.199:56257] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4f8eeSd8WoG-6-XpDY4QAAAlw"]
[Mon Jul 20 07:17:37.446355 2026] [security2:error] [pid 95126:tid 95339] [client 187.16.64.216:52906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f8Qpx5ks9joCJTKW6DwAAAeA"]
[Mon Jul 20 07:17:37.446472 2026] [security2:error] [pid 95126:tid 95339] [client 187.16.64.216:52906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f8Qpx5ks9joCJTKW6DwAAAeA"]
[Mon Jul 20 07:17:37.507129 2026] [security2:error] [pid 95128:tid 95529] [client 20.220.9.199:64399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/system_log.php"] [unique_id "al4f8eeSd8WoG-6-XpDY_gAAAiE"]
[Mon Jul 20 07:17:37.507220 2026] [security2:error] [pid 95128:tid 95529] [client 20.220.9.199:64399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/system_log.php"] [unique_id "al4f8eeSd8WoG-6-XpDY_gAAAiE"]
[Mon Jul 20 07:17:37.594734 2026] [security2:error] [pid 95128:tid 95466] [remote 117.0.21.154:41992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4f8eeSd8WoG-6-XpDZAAACdE8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:17:37.611612 2026] [security2:error] [pid 95128:tid 95591] [client 77.110.127.138:62629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8eeSd8WoG-6-XpDZBgAAAl8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:37.661236 2026] [security2:error] [pid 94831:tid 95000] [client 77.110.127.138:62592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8Y06NaEKF1g_MW2ucwAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:37.797843 2026] [proxy:error] [pid 95128:tid 95626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:37.797913 2026] [proxy_http:error] [pid 95128:tid 95626] [client 20.220.9.199:56256] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:37.798328 2026] [proxy:error] [pid 95128:tid 95626] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:37.798351 2026] [proxy_http:error] [pid 95128:tid 95626] [client 20.220.9.199:56256] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:37.798418 2026] [security2:error] [pid 95128:tid 95626] [client 20.220.9.199:56256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f8eeSd8WoG-6-XpDZDgAAAoI"]
[Mon Jul 20 07:17:37.955926 2026] [security2:error] [pid 95128:tid 95390] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4f8eeSd8WoG-6-XpDZGQACbgM"]
[Mon Jul 20 07:17:37.964257 2026] [security2:error] [pid 95128:tid 95544] [client 14.225.17.146:51549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4f8eeSd8WoG-6-XpDZDQAAAjA"]
[Mon Jul 20 07:17:38.151711 2026] [security2:error] [pid 95128:tid 95484] [remote 45.84.107.182:2753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.107.84.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f8ueSd8WoG-6-XpDZIwACU2E"], referer: https://verdunestate.com/luxury-apartment-for-sale-bay-tower-downtown-beirut/
[Mon Jul 20 07:17:38.171796 2026] [security2:error] [pid 95128:tid 95632] [client 191.202.66.27:64708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f8ueSd8WoG-6-XpDZJAAAAog"]
[Mon Jul 20 07:17:38.171920 2026] [security2:error] [pid 95128:tid 95632] [client 191.202.66.27:64708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f8ueSd8WoG-6-XpDZJAAAAog"]
[Mon Jul 20 07:17:38.178625 2026] [core:error] [pid 95126:tid 95341] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:38.178644 2026] [core:error] [pid 95126:tid 95341] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:38.335314 2026] [proxy:error] [pid 95126:tid 95294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:38.335394 2026] [proxy_http:error] [pid 95126:tid 95294] [client 20.220.9.199:64425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:38.336232 2026] [proxy:error] [pid 95126:tid 95294] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:38.336266 2026] [proxy_http:error] [pid 95126:tid 95294] [client 20.220.9.199:64425] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:38.336341 2026] [security2:error] [pid 95128:tid 95627] [client 77.110.127.138:62632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8ueSd8WoG-6-XpDZKwAAAoM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:38.336354 2026] [security2:error] [pid 95126:tid 95294] [client 20.220.9.199:64425] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f8gpx5ks9joCJTKW6HgAAAbM"]
[Mon Jul 20 07:17:38.409481 2026] [security2:error] [pid 95126:tid 95334] [client 14.225.17.146:50996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4f8gpx5ks9joCJTKW6GwAAAds"], referer: http://laceycaraccident.com/2019
[Mon Jul 20 07:17:38.431059 2026] [security2:error] [pid 95126:tid 95186] [remote 162.19.86.63:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4f8gpx5ks9joCJTKW6IgABrDk"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 07:17:38.639281 2026] [security2:error] [pid 95126:tid 95337] [client 20.220.9.199:60370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/crgio.php"] [unique_id "al4f8gpx5ks9joCJTKW6JwAAAd4"]
[Mon Jul 20 07:17:38.639359 2026] [security2:error] [pid 95126:tid 95337] [client 20.220.9.199:60370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/crgio.php"] [unique_id "al4f8gpx5ks9joCJTKW6JwAAAd4"]
[Mon Jul 20 07:17:38.661051 2026] [security2:error] [pid 95128:tid 95528] [client 77.110.127.138:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8ueSd8WoG-6-XpDZQwAAAiA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:38.720701 2026] [security2:error] [pid 95128:tid 95573] [client 77.110.127.138:62599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8ueSd8WoG-6-XpDZSwAAAk0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:38.749147 2026] [security2:error] [pid 95128:tid 95522] [client 49.37.242.14:50169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f8ueSd8WoG-6-XpDZTgAAAho"]
[Mon Jul 20 07:17:38.749281 2026] [security2:error] [pid 95128:tid 95522] [client 49.37.242.14:50169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f8ueSd8WoG-6-XpDZTgAAAho"]
[Mon Jul 20 07:17:38.777513 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:62613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8gpx5ks9joCJTKW6LQAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:38.828245 2026] [security2:error] [pid 95128:tid 95590] [client 20.220.9.199:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/pucci.php"] [unique_id "al4f8ueSd8WoG-6-XpDZVQAAAl4"]
[Mon Jul 20 07:17:38.828345 2026] [security2:error] [pid 95128:tid 95590] [client 20.220.9.199:64149] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/pucci.php"] [unique_id "al4f8ueSd8WoG-6-XpDZVQAAAl4"]
[Mon Jul 20 07:17:38.836242 2026] [security2:error] [pid 95128:tid 95591] [client 77.110.127.138:62614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8ueSd8WoG-6-XpDZWAAAAl8"]
[Mon Jul 20 07:17:38.986999 2026] [security2:error] [pid 95128:tid 95567] [client 77.110.127.138:62638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8ueSd8WoG-6-XpDZbQAAAkc"]
[Mon Jul 20 07:17:39.110929 2026] [proxy:error] [pid 95126:tid 95259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:39.111202 2026] [proxy_http:error] [pid 95126:tid 95259] [client 20.220.9.199:64135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:39.111848 2026] [proxy:error] [pid 95126:tid 95259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:39.111875 2026] [proxy_http:error] [pid 95126:tid 95259] [client 20.220.9.199:64135] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:39.111968 2026] [security2:error] [pid 95126:tid 95259] [client 20.220.9.199:64135] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f8wpx5ks9joCJTKW6LgAAAZA"]
[Mon Jul 20 07:17:39.183125 2026] [security2:error] [pid 95128:tid 95539] [client 14.225.17.146:60074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4f8-eSd8WoG-6-XpDZcwAAAis"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2019
[Mon Jul 20 07:17:39.197048 2026] [security2:error] [pid 95126:tid 95359] [client 57.141.18.114:51746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f8gpx5ks9joCJTKW6GQAB9CU"]
[Mon Jul 20 07:17:39.235249 2026] [security2:error] [pid 95126:tid 95266] [client 77.110.127.138:62639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8wpx5ks9joCJTKW6MwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:39.235345 2026] [security2:error] [pid 95126:tid 95266] [client 77.110.127.138:62639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f8wpx5ks9joCJTKW6MwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:39.440890 2026] [security2:error] [pid 95126:tid 95258] [client 77.110.127.138:62640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f8wpx5ks9joCJTKW6PAAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:39.483183 2026] [proxy:error] [pid 94831:tid 95026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:39.483227 2026] [proxy_http:error] [pid 94831:tid 95026] [client 20.220.9.199:55907] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:39.483829 2026] [proxy:error] [pid 94831:tid 95026] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:39.483865 2026] [proxy_http:error] [pid 94831:tid 95026] [client 20.220.9.199:55907] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:39.483955 2026] [security2:error] [pid 94831:tid 95026] [client 20.220.9.199:55907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f8406NaEKF1g_MW2ufgAAAEE"]
[Mon Jul 20 07:17:39.510334 2026] [security2:error] [pid 95128:tid 95422] [remote 57.141.18.5:47268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f8ueSd8WoG-6-XpDZOAACYiM"]
[Mon Jul 20 07:17:39.590737 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:62641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4f8wpx5ks9joCJTKW6RQAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:39.644182 2026] [security2:error] [pid 95126:tid 95339] [client 20.220.9.199:64415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-temp.php"] [unique_id "al4f8wpx5ks9joCJTKW6SAAAAeA"]
[Mon Jul 20 07:17:39.644277 2026] [security2:error] [pid 95126:tid 95339] [client 20.220.9.199:64415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-temp.php"] [unique_id "al4f8wpx5ks9joCJTKW6SAAAAeA"]
[Mon Jul 20 07:17:39.760927 2026] [security2:error] [pid 95126:tid 95194] [remote 57.141.18.99:29764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4f8wpx5ks9joCJTKW6TgAB2kE"]
[Mon Jul 20 07:17:39.806662 2026] [security2:error] [pid 94831:tid 95012] [client 20.220.9.199:64428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4f8406NaEKF1g_MW2uigAAADM"]
[Mon Jul 20 07:17:39.806983 2026] [security2:error] [pid 94831:tid 95012] [client 20.220.9.199:64428] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4f8406NaEKF1g_MW2uigAAADM"]
[Mon Jul 20 07:17:39.834178 2026] [security2:error] [pid 95126:tid 95346] [client 154.192.123.127:18366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f8wpx5ks9joCJTKW6VwAAAec"]
[Mon Jul 20 07:17:39.834616 2026] [security2:error] [pid 95126:tid 95346] [client 154.192.123.127:18366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f8wpx5ks9joCJTKW6VwAAAec"]
[Mon Jul 20 07:17:40.220135 2026] [security2:error] [pid 95126:tid 95266] [client 20.220.9.199:56294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/puc.php"] [unique_id "al4f9Apx5ks9joCJTKW6dQAAAZc"]
[Mon Jul 20 07:17:40.220219 2026] [security2:error] [pid 95126:tid 95266] [client 20.220.9.199:56294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/puc.php"] [unique_id "al4f9Apx5ks9joCJTKW6dQAAAZc"]
[Mon Jul 20 07:17:40.353261 2026] [security2:error] [pid 95126:tid 95263] [client 54.152.11.32:57768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4f8wpx5ks9joCJTKW6QwAAAZQ"]
[Mon Jul 20 07:17:40.354167 2026] [security2:error] [pid 95126:tid 95261] [client 14.225.17.146:59964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4f8wpx5ks9joCJTKW6VgAAAZI"], referer: http://partnerselectricalllc.com/2019
[Mon Jul 20 07:17:40.850358 2026] [security2:error] [pid 95126:tid 95319] [client 57.141.18.9:64878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f8wpx5ks9joCJTKW6QgABzEI"]
[Mon Jul 20 07:17:40.994572 2026] [security2:error] [pid 95126:tid 95367] [client 20.220.9.199:64178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/dx.php"] [unique_id "al4f9Apx5ks9joCJTKW6ngAAAfw"]
[Mon Jul 20 07:17:40.994674 2026] [security2:error] [pid 95126:tid 95367] [client 20.220.9.199:64178] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/dx.php"] [unique_id "al4f9Apx5ks9joCJTKW6ngAAAfw"]
[Mon Jul 20 07:17:41.180518 2026] [proxy:error] [pid 95126:tid 95351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:41.180595 2026] [proxy_http:error] [pid 95126:tid 95351] [client 20.220.9.199:59911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:41.181262 2026] [proxy:error] [pid 95126:tid 95351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:41.181296 2026] [proxy_http:error] [pid 95126:tid 95351] [client 20.220.9.199:59911] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:41.181393 2026] [security2:error] [pid 95126:tid 95351] [client 20.220.9.199:59911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f9Qpx5ks9joCJTKW6swAAAew"]
[Mon Jul 20 07:17:41.222208 2026] [security2:error] [pid 94831:tid 94981] [client 57.141.18.34:63524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9I06NaEKF1g_MW2ujwAAFFo"]
[Mon Jul 20 07:17:41.310610 2026] [security2:error] [pid 94831:tid 95075] [client 117.211.236.168:58520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f9Y06NaEKF1g_MW2upgAAAHI"]
[Mon Jul 20 07:17:41.310717 2026] [security2:error] [pid 94831:tid 95075] [client 117.211.236.168:58520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4f9Y06NaEKF1g_MW2upgAAAHI"]
[Mon Jul 20 07:17:41.315551 2026] [security2:error] [pid 95126:tid 95282] [client 15.237.209.113:15322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cryptomeaning.com"] [uri "/robots.txt"] [unique_id "al4f9Qpx5ks9joCJTKW6tgAAAac"]
[Mon Jul 20 07:17:41.315641 2026] [security2:error] [pid 95126:tid 95282] [client 15.237.209.113:15322] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cryptomeaning.com"] [uri "/robots.txt"] [unique_id "al4f9Qpx5ks9joCJTKW6tgAAAac"]
[Mon Jul 20 07:17:41.418359 2026] [security2:error] [pid 95126:tid 95326] [client 20.220.9.199:64441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/bthil.php"] [unique_id "al4f9Qpx5ks9joCJTKW6vgAAAdM"]
[Mon Jul 20 07:17:41.418428 2026] [security2:error] [pid 95126:tid 95326] [client 20.220.9.199:64441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/bthil.php"] [unique_id "al4f9Qpx5ks9joCJTKW6vgAAAdM"]
[Mon Jul 20 07:17:41.475418 2026] [security2:error] [pid 95126:tid 95380] [client 57.141.18.119:57388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9Apx5ks9joCJTKW6dAACCUo"]
[Mon Jul 20 07:17:41.703916 2026] [security2:error] [pid 95126:tid 95259] [client 104.234.53.53:39447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4f9Qpx5ks9joCJTKW61gAAAZA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:41.727986 2026] [security2:error] [pid 95126:tid 95274] [client 20.220.9.199:59939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/7.php"] [unique_id "al4f9Qpx5ks9joCJTKW62wAAAZ8"]
[Mon Jul 20 07:17:41.728105 2026] [security2:error] [pid 95126:tid 95274] [client 20.220.9.199:59939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/7.php"] [unique_id "al4f9Qpx5ks9joCJTKW62wAAAZ8"]
[Mon Jul 20 07:17:41.747188 2026] [security2:error] [pid 95126:tid 95339] [client 201.27.111.74:53776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f9Qpx5ks9joCJTKW63AAAAeA"]
[Mon Jul 20 07:17:41.750942 2026] [security2:error] [pid 95126:tid 95339] [client 201.27.111.74:53776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4f9Qpx5ks9joCJTKW63AAAAeA"]
[Mon Jul 20 07:17:42.013769 2026] [security2:error] [pid 95126:tid 95263] [client 20.220.9.199:56277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/8.php"] [unique_id "al4f9gpx5ks9joCJTKW65QAAAZQ"]
[Mon Jul 20 07:17:42.013844 2026] [security2:error] [pid 95126:tid 95263] [client 20.220.9.199:56277] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/8.php"] [unique_id "al4f9gpx5ks9joCJTKW65QAAAZQ"]
[Mon Jul 20 07:17:42.066177 2026] [security2:error] [pid 95126:tid 95271] [client 57.141.18.112:31202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9Apx5ks9joCJTKW6iwABnF8"]
[Mon Jul 20 07:17:42.273842 2026] [security2:error] [pid 95126:tid 95325] [client 20.220.9.199:55916] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "cpcontacts.mzsassy.com"] [uri "/1.php"] [unique_id "al4f9gpx5ks9joCJTKW6_AAAAdI"]
[Mon Jul 20 07:17:42.273957 2026] [security2:error] [pid 95126:tid 95325] [client 20.220.9.199:55916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/1.php"] [unique_id "al4f9gpx5ks9joCJTKW6_AAAAdI"]
[Mon Jul 20 07:17:42.274025 2026] [security2:error] [pid 95126:tid 95325] [client 20.220.9.199:55916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/1.php"] [unique_id "al4f9gpx5ks9joCJTKW6_AAAAdI"]
[Mon Jul 20 07:17:42.279077 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:62653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9o06NaEKF1g_MW2uswAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.279161 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:62653] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9o06NaEKF1g_MW2uswAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.294063 2026] [security2:error] [pid 95126:tid 95276] [client 52.140.101.203:14727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4f9gpx5ks9joCJTKW6_gAAAaE"]
[Mon Jul 20 07:17:42.299449 2026] [security2:error] [pid 95126:tid 95237] [remote 57.141.18.56:64684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4f9gpx5ks9joCJTKW7AAAB52w"]
[Mon Jul 20 07:17:42.336575 2026] [security2:error] [pid 94831:tid 95003] [client 144.172.114.51:34184] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/helm/.env"] [unique_id "al4f9o06NaEKF1g_MW2utgAAACo"]
[Mon Jul 20 07:17:42.418196 2026] [security2:error] [pid 94831:tid 95064] [client 20.220.9.199:56287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/100.php"] [unique_id "al4f9o06NaEKF1g_MW2uuQAAAGc"]
[Mon Jul 20 07:17:42.418290 2026] [security2:error] [pid 94831:tid 95064] [client 20.220.9.199:56287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/100.php"] [unique_id "al4f9o06NaEKF1g_MW2uuQAAAGc"]
[Mon Jul 20 07:17:42.447421 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:62654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f9o06NaEKF1g_MW2uugAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.450613 2026] [security2:error] [pid 95126:tid 95356] [client 57.141.18.48:64762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9Apx5ks9joCJTKW6nAAB8WA"]
[Mon Jul 20 07:17:42.530332 2026] [security2:error] [pid 95126:tid 95385] [client 52.140.101.203:14727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4f9gpx5ks9joCJTKW7EgAAAg4"]
[Mon Jul 20 07:17:42.533065 2026] [security2:error] [pid 95126:tid 95286] [client 77.110.127.138:62655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9gpx5ks9joCJTKW7EwAAAas"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.533191 2026] [security2:error] [pid 95126:tid 95286] [client 77.110.127.138:62655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9gpx5ks9joCJTKW7EwAAAas"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.605441 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f9gpx5ks9joCJTKW7HAAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.719428 2026] [security2:error] [pid 95126:tid 95271] [client 20.220.9.199:10393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/about.php"] [unique_id "al4f9gpx5ks9joCJTKW7JgAAAZw"]
[Mon Jul 20 07:17:42.719509 2026] [security2:error] [pid 95126:tid 95271] [client 20.220.9.199:10393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/about.php"] [unique_id "al4f9gpx5ks9joCJTKW7JgAAAZw"]
[Mon Jul 20 07:17:42.742096 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:62657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9o06NaEKF1g_MW2uwwAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.742201 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:62657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9o06NaEKF1g_MW2uwwAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.808267 2026] [security2:error] [pid 94831:tid 95025] [client 77.110.127.138:62658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpfybuYyox'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4f9o06NaEKF1g_MW2uxQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.849032 2026] [security2:error] [pid 95126:tid 95336] [client 14.225.17.146:59259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4f9gpx5ks9joCJTKW7GwAAAd0"], referer: http://securingmemories.com/2019
[Mon Jul 20 07:17:42.892164 2026] [security2:error] [pid 94831:tid 95083] [client 77.110.127.138:62661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9o06NaEKF1g_MW2uyAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.892269 2026] [security2:error] [pid 94831:tid 95083] [client 77.110.127.138:62661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9o06NaEKF1g_MW2uyAAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.928106 2026] [security2:error] [pid 95126:tid 95272] [client 14.225.17.146:60697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4f9Apx5ks9joCJTKW6mAAAAZ0"], referer: http://margaretspeckogawa.com/2019
[Mon Jul 20 07:17:42.978640 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:62643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9gpx5ks9joCJTKW7KwAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:42.978783 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:62643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9gpx5ks9joCJTKW7KwAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:43.008593 2026] [security2:error] [pid 95126:tid 95296] [client 14.225.17.146:58935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4f9gpx5ks9joCJTKW7JAAAAbU"], referer: http://lifeisbetterlakeside.com/2019
[Mon Jul 20 07:17:43.069792 2026] [security2:error] [pid 95126:tid 95340] [client 77.110.127.138:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9wpx5ks9joCJTKW7MgAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:43.069865 2026] [security2:error] [pid 95126:tid 95148] [remote 152.228.213.32:46770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f9wpx5ks9joCJTKW7LwABmRM"]
[Mon Jul 20 07:17:43.069958 2026] [security2:error] [pid 95126:tid 95340] [client 77.110.127.138:62644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9wpx5ks9joCJTKW7MgAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:43.070064 2026] [security2:error] [pid 95126:tid 95268] [client 152.228.213.32:46770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f9wpx5ks9joCJTKW7LwABmRM"]
[Mon Jul 20 07:17:43.074702 2026] [security2:error] [pid 95126:tid 95327] [client 57.141.18.3:24274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9Qpx5ks9joCJTKW6xgAB1Fg"]
[Mon Jul 20 07:17:43.104906 2026] [security2:error] [pid 94831:tid 95035] [client 20.220.9.199:56284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/admin.php"] [unique_id "al4f9406NaEKF1g_MW2u2wAAAEo"]
[Mon Jul 20 07:17:43.105028 2026] [security2:error] [pid 94831:tid 95035] [client 20.220.9.199:56284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/admin.php"] [unique_id "al4f9406NaEKF1g_MW2u2wAAAEo"]
[Mon Jul 20 07:17:43.212991 2026] [security2:error] [pid 95126:tid 95365] [client 57.141.18.102:61180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9Qpx5ks9joCJTKW60wAB-nc"]
[Mon Jul 20 07:17:43.234146 2026] [core:error] [pid 95126:tid 95259] [client 14.225.17.146:55904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:43.234174 2026] [core:error] [pid 95126:tid 95259] [client 14.225.17.146:55904] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:17:43.237502 2026] [security2:error] [pid 95126:tid 95307] [client 77.110.127.138:62664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9wpx5ks9joCJTKW7QgAAAcA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:43.237631 2026] [security2:error] [pid 95126:tid 95307] [client 77.110.127.138:62664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f9wpx5ks9joCJTKW7QgAAAcA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:43.495570 2026] [security2:error] [pid 95126:tid 95373] [client 103.144.65.217:51505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f9wpx5ks9joCJTKW7VAAAAgI"]
[Mon Jul 20 07:17:43.495655 2026] [security2:error] [pid 95126:tid 95373] [client 103.144.65.217:51505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4f9wpx5ks9joCJTKW7VAAAAgI"]
[Mon Jul 20 07:17:43.574445 2026] [security2:error] [pid 95126:tid 95306] [client 202.141.11.99:22216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4f9wpx5ks9joCJTKW7WQAAAb8"]
[Mon Jul 20 07:17:43.574554 2026] [security2:error] [pid 95126:tid 95306] [client 202.141.11.99:22216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4f9wpx5ks9joCJTKW7WQAAAb8"]
[Mon Jul 20 07:17:43.611441 2026] [security2:error] [pid 95126:tid 95264] [client 20.220.9.199:44374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/edit.php"] [unique_id "al4f9wpx5ks9joCJTKW7XAAAAZU"]
[Mon Jul 20 07:17:43.611518 2026] [security2:error] [pid 95126:tid 95264] [client 20.220.9.199:44374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/edit.php"] [unique_id "al4f9wpx5ks9joCJTKW7XAAAAZU"]
[Mon Jul 20 07:17:43.673699 2026] [security2:error] [pid 95126:tid 95362] [client 52.109.76.144:14963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4f9wpx5ks9joCJTKW7YQAAAfc"]
[Mon Jul 20 07:17:43.674979 2026] [security2:error] [pid 94831:tid 94982] [client 98.159.234.160:33035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f9406NaEKF1g_MW2u5wAAABU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:17:43.812875 2026] [security2:error] [pid 95126:tid 95334] [client 52.109.76.144:14963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4f9wpx5ks9joCJTKW7bgAAAds"]
[Mon Jul 20 07:17:43.889350 2026] [security2:error] [pid 95126:tid 95259] [client 144.172.114.51:34212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/api/index.php/v1/config/application"] [unique_id "al4f9wpx5ks9joCJTKW7cgAAAZA"]
[Mon Jul 20 07:17:44.233502 2026] [security2:error] [pid 95126:tid 95273] [client 14.225.17.146:59127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4f-Apx5ks9joCJTKW7fAAAAZ4"], referer: http://floorsourcestock.com/2019
[Mon Jul 20 07:17:44.257150 2026] [security2:error] [pid 95126:tid 95338] [client 20.220.9.199:55877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/admin.php"] [unique_id "al4f-Apx5ks9joCJTKW7kgAAAd8"]
[Mon Jul 20 07:17:44.257229 2026] [security2:error] [pid 95126:tid 95338] [client 20.220.9.199:55877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/admin.php"] [unique_id "al4f-Apx5ks9joCJTKW7kgAAAd8"]
[Mon Jul 20 07:17:44.274735 2026] [security2:error] [pid 95126:tid 95289] [client 154.208.48.130:50315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f-Apx5ks9joCJTKW7kwAAAa4"]
[Mon Jul 20 07:17:44.275225 2026] [security2:error] [pid 95126:tid 95289] [client 154.208.48.130:50315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4f-Apx5ks9joCJTKW7kwAAAa4"]
[Mon Jul 20 07:17:44.489237 2026] [security2:error] [pid 95126:tid 95268] [client 77.110.127.138:62649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-Apx5ks9joCJTKW7pgAAAZk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:44.501103 2026] [security2:error] [pid 95126:tid 95326] [client 20.220.9.199:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ss.php"] [unique_id "al4f-Apx5ks9joCJTKW7qAAAAdM"]
[Mon Jul 20 07:17:44.501183 2026] [security2:error] [pid 95126:tid 95326] [client 20.220.9.199:64181] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ss.php"] [unique_id "al4f-Apx5ks9joCJTKW7qAAAAdM"]
[Mon Jul 20 07:17:44.545599 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:62650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-Apx5ks9joCJTKW7qgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:44.582160 2026] [security2:error] [pid 95126:tid 95197] [remote 185.220.100.243:60936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.100.220.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4f-Apx5ks9joCJTKW7qQAB4UQ"], referer: https://verdunestate.com/property-type/apartment/
[Mon Jul 20 07:17:44.708971 2026] [security2:error] [pid 95126:tid 95330] [client 77.110.127.138:62670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php82tfcDBg'%20OR%20145=(SELECT%20145%20FROM%20PG_SLEEP(15))--"] [unique_id "al4f-Apx5ks9joCJTKW7wgAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:44.859624 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:62671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-Apx5ks9joCJTKW7ygAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:44.859730 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:62671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-Apx5ks9joCJTKW7ygAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.026438 2026] [security2:error] [pid 95126:tid 95286] [client 20.220.9.199:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/inputs.php"] [unique_id "al4f-Qpx5ks9joCJTKW71gAAAas"]
[Mon Jul 20 07:17:45.026541 2026] [security2:error] [pid 95126:tid 95286] [client 20.220.9.199:64418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/inputs.php"] [unique_id "al4f-Qpx5ks9joCJTKW71gAAAas"]
[Mon Jul 20 07:17:45.056831 2026] [security2:error] [pid 94831:tid 94837] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f-Y06NaEKF1g_MW2u-QAADQU"]
[Mon Jul 20 07:17:45.056974 2026] [security2:error] [pid 94831:tid 94974] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4f-Y06NaEKF1g_MW2u-QAADQU"]
[Mon Jul 20 07:17:45.091166 2026] [security2:error] [pid 95126:tid 95378] [client 57.141.18.62:44852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f9wpx5ks9joCJTKW7WwACByo"]
[Mon Jul 20 07:17:45.171819 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:62675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-Qpx5ks9joCJTKW76QAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.618215 2026] [security2:error] [pid 95126:tid 95308] [client 143.44.185.218:53907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f-Qpx5ks9joCJTKW8CwAAAcE"]
[Mon Jul 20 07:17:45.620013 2026] [security2:error] [pid 95126:tid 95308] [client 143.44.185.218:53907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4f-Qpx5ks9joCJTKW8CwAAAcE"]
[Mon Jul 20 07:17:45.635483 2026] [security2:error] [pid 94831:tid 95026] [client 20.220.9.199:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/av.php"] [unique_id "al4f-Y06NaEKF1g_MW2vCwAAAEE"]
[Mon Jul 20 07:17:45.635565 2026] [security2:error] [pid 94831:tid 95026] [client 20.220.9.199:64184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/av.php"] [unique_id "al4f-Y06NaEKF1g_MW2vCwAAAEE"]
[Mon Jul 20 07:17:45.904675 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:62659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-Qpx5ks9joCJTKW8IQAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.911618 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-Qpx5ks9joCJTKW8IwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.929800 2026] [security2:error] [pid 94831:tid 95004] [client 14.225.17.146:59190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4f-Y06NaEKF1g_MW2vDgAAACs"], referer: http://samdothan.org/2019
[Mon Jul 20 07:17:45.956035 2026] [security2:error] [pid 94831:tid 94968] [client 77.110.127.138:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-Y06NaEKF1g_MW2vFAAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.956136 2026] [security2:error] [pid 94831:tid 94968] [client 77.110.127.138:62663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-Y06NaEKF1g_MW2vFAAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.959404 2026] [security2:error] [pid 95126:tid 95300] [client 50.116.65.227:57114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4f-Qpx5ks9joCJTKW8KAAAAbk"]
[Mon Jul 20 07:17:45.962672 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-Y06NaEKF1g_MW2vFQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:45.969993 2026] [security2:error] [pid 95126:tid 95325] [client 50.116.65.227:57128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4f-Qpx5ks9joCJTKW8KQAAAdI"]
[Mon Jul 20 07:17:46.009072 2026] [security2:error] [pid 95126:tid 95293] [client 14.225.17.146:59066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4f-Apx5ks9joCJTKW7rwAAAbI"], referer: http://expertcultures.com/2019
[Mon Jul 20 07:17:46.019291 2026] [security2:error] [pid 95126:tid 95275] [client 77.110.127.138:62647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-gpx5ks9joCJTKW8LwAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:46.070268 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:62648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-gpx5ks9joCJTKW8MwAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:46.085434 2026] [security2:error] [pid 95126:tid 95297] [client 57.141.18.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4f-Qpx5ks9joCJTKW8JQAAAbY"]
[Mon Jul 20 07:17:46.113097 2026] [security2:error] [pid 95126:tid 95328] [client 77.110.127.138:62683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpBtZbRUPi')%20OR%20847=(SELECT%20847%20FROM%20PG_SLEEP(15))--"] [unique_id "al4f-gpx5ks9joCJTKW8NAAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:46.234727 2026] [security2:error] [pid 94831:tid 95066] [client 77.110.127.138:62684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-o06NaEKF1g_MW2vIwAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:46.244027 2026] [security2:error] [pid 95126:tid 95370] [client 20.220.9.199:44418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/classwithtostring.php"] [unique_id "al4f-gpx5ks9joCJTKW8OwAAAf8"]
[Mon Jul 20 07:17:46.244151 2026] [security2:error] [pid 95126:tid 95370] [client 20.220.9.199:44418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/classwithtostring.php"] [unique_id "al4f-gpx5ks9joCJTKW8OwAAAf8"]
[Mon Jul 20 07:17:46.261145 2026] [security2:error] [pid 95126:tid 95307] [client 88.241.67.160:56879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f-gpx5ks9joCJTKW8PgAAAcA"]
[Mon Jul 20 07:17:46.261453 2026] [security2:error] [pid 95126:tid 95307] [client 88.241.67.160:56879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4f-gpx5ks9joCJTKW8PgAAAcA"]
[Mon Jul 20 07:17:46.280047 2026] [security2:error] [pid 95126:tid 95260] [client 57.141.18.38:57806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f-Apx5ks9joCJTKW7zQABkT0"]
[Mon Jul 20 07:17:46.292581 2026] [autoindex:error] [pid 95126:tid 95324] [client 147.93.171.188:65467] AH01276: Cannot serve directory /home4/elemeph8/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:17:46.484086 2026] [security2:error] [pid 94831:tid 94862] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f-o06NaEKF1g_MW2vNQAAGB4"]
[Mon Jul 20 07:17:46.484219 2026] [security2:error] [pid 94831:tid 94985] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4f-o06NaEKF1g_MW2vNQAAGB4"]
[Mon Jul 20 07:17:46.567220 2026] [security2:error] [pid 94831:tid 94984] [client 95.158.43.9:57308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4f-o06NaEKF1g_MW2vNgAAABc"], referer: https://new-menus.com
[Mon Jul 20 07:17:46.640928 2026] [security2:error] [pid 95126:tid 95338] [client 104.234.53.91:65245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4f-gpx5ks9joCJTKW8WgAAAd8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:46.680043 2026] [security2:error] [pid 95126:tid 95352] [client 14.225.17.146:60432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4f-gpx5ks9joCJTKW8WAAAAe0"], referer: http://claysharecon.com/2019
[Mon Jul 20 07:17:46.772215 2026] [security2:error] [pid 94831:tid 95005] [client 57.141.18.58:53110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f-Y06NaEKF1g_MW2vAQAALAc"]
[Mon Jul 20 07:17:46.852667 2026] [security2:error] [pid 95126:tid 95383] [client 20.220.9.199:60365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4f-gpx5ks9joCJTKW8awAAAgw"]
[Mon Jul 20 07:17:46.852768 2026] [security2:error] [pid 95126:tid 95383] [client 20.220.9.199:60365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4f-gpx5ks9joCJTKW8awAAAgw"]
[Mon Jul 20 07:17:46.955362 2026] [security2:error] [pid 95126:tid 95261] [client 103.176.215.66:51102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f-gpx5ks9joCJTKW8cwAAAZI"]
[Mon Jul 20 07:17:46.955491 2026] [security2:error] [pid 95126:tid 95261] [client 103.176.215.66:51102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4f-gpx5ks9joCJTKW8cwAAAZI"]
[Mon Jul 20 07:17:47.238635 2026] [security2:error] [pid 95126:tid 95378] [client 77.110.127.138:62691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-wpx5ks9joCJTKW8ggAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.323339 2026] [security2:error] [pid 94831:tid 95077] [client 77.110.127.138:62676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-406NaEKF1g_MW2vSAAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.323449 2026] [security2:error] [pid 94831:tid 95077] [client 77.110.127.138:62676] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-406NaEKF1g_MW2vSAAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.426929 2026] [security2:error] [pid 95126:tid 95300] [client 20.220.9.199:55900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-blog.php"] [unique_id "al4f-wpx5ks9joCJTKW8kgAAAbk"]
[Mon Jul 20 07:17:47.427058 2026] [security2:error] [pid 95126:tid 95300] [client 20.220.9.199:55900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-blog.php"] [unique_id "al4f-wpx5ks9joCJTKW8kgAAAbk"]
[Mon Jul 20 07:17:47.428501 2026] [security2:error] [pid 94831:tid 95040] [client 77.110.127.138:62692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-406NaEKF1g_MW2vSwAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.476614 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:62693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpFj6R5NCt'))%20OR%20178=(SELECT%20178%20FROM%20PG_SLEEP(15))--"] [unique_id "al4f-wpx5ks9joCJTKW8lQAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.508523 2026] [security2:error] [pid 94831:tid 95034] [client 157.20.138.62:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f-406NaEKF1g_MW2vTwAAAEk"]
[Mon Jul 20 07:17:47.508655 2026] [security2:error] [pid 94831:tid 95034] [client 157.20.138.62:62284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4f-406NaEKF1g_MW2vTwAAAEk"]
[Mon Jul 20 07:17:47.527207 2026] [security2:error] [pid 94831:tid 95015] [client 77.110.127.138:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-406NaEKF1g_MW2vUAAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.577704 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:62646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-wpx5ks9joCJTKW8oAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.577866 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:62646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f-wpx5ks9joCJTKW8oAAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:47.634081 2026] [proxy:error] [pid 95126:tid 95343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:47.634159 2026] [proxy_http:error] [pid 95126:tid 95343] [client 20.220.9.199:64403] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:47.634838 2026] [proxy:error] [pid 95126:tid 95343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:47.634868 2026] [proxy_http:error] [pid 95126:tid 95343] [client 20.220.9.199:64403] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:47.634962 2026] [security2:error] [pid 95126:tid 95343] [client 20.220.9.199:64403] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f-wpx5ks9joCJTKW8owAAAeQ"]
[Mon Jul 20 07:17:47.868785 2026] [security2:error] [pid 95126:tid 95365] [client 14.225.17.146:59269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4f-wpx5ks9joCJTKW8pgAAAfo"], referer: http://lelandumc.org/2019
[Mon Jul 20 07:17:47.896003 2026] [security2:error] [pid 95126:tid 95359] [client 20.220.9.199:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/admin.php"] [unique_id "al4f-wpx5ks9joCJTKW8tgAAAfQ"]
[Mon Jul 20 07:17:47.896126 2026] [security2:error] [pid 95126:tid 95359] [client 20.220.9.199:64416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-content/admin.php"] [unique_id "al4f-wpx5ks9joCJTKW8tgAAAfQ"]
[Mon Jul 20 07:17:47.924185 2026] [security2:error] [pid 95126:tid 95268] [client 77.110.127.138:62701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f-wpx5ks9joCJTKW8uAAAAZk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:48.056973 2026] [security2:error] [pid 94831:tid 94988] [client 14.225.17.146:59209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4f-406NaEKF1g_MW2vUgAAABs"], referer: http://onewingpictures.com/2019
[Mon Jul 20 07:17:48.085316 2026] [security2:error] [pid 95126:tid 95354] [client 47.128.58.29:41216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/robots.txt"] [unique_id "al4f_Apx5ks9joCJTKW8wgAAAe8"]
[Mon Jul 20 07:17:48.101654 2026] [security2:error] [pid 95126:tid 95279] [client 187.16.64.216:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f_Apx5ks9joCJTKW8xQAAAaQ"]
[Mon Jul 20 07:17:48.101778 2026] [security2:error] [pid 95126:tid 95279] [client 187.16.64.216:53477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4f_Apx5ks9joCJTKW8xQAAAaQ"]
[Mon Jul 20 07:17:48.447948 2026] [security2:error] [pid 95126:tid 95305] [client 20.220.9.199:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/adminfuns.php"] [unique_id "al4f_Apx5ks9joCJTKW81AAAAb4"]
[Mon Jul 20 07:17:48.448085 2026] [security2:error] [pid 95126:tid 95305] [client 20.220.9.199:64156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/adminfuns.php"] [unique_id "al4f_Apx5ks9joCJTKW81AAAAb4"]
[Mon Jul 20 07:17:48.655419 2026] [security2:error] [pid 95126:tid 95343] [client 191.202.66.27:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f_Apx5ks9joCJTKW83gAAAeQ"]
[Mon Jul 20 07:17:48.655524 2026] [security2:error] [pid 95126:tid 95343] [client 191.202.66.27:65152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4f_Apx5ks9joCJTKW83gAAAeQ"]
[Mon Jul 20 07:17:48.679059 2026] [security2:error] [pid 95126:tid 95378] [client 20.220.9.199:44457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/goods.php"] [unique_id "al4f_Apx5ks9joCJTKW83wAAAgc"]
[Mon Jul 20 07:17:48.679136 2026] [security2:error] [pid 95126:tid 95378] [client 20.220.9.199:44457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/goods.php"] [unique_id "al4f_Apx5ks9joCJTKW83wAAAgc"]
[Mon Jul 20 07:17:48.852630 2026] [security2:error] [pid 95126:tid 95351] [client 77.110.127.138:62669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f_Apx5ks9joCJTKW86wAAAew"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:48.852733 2026] [security2:error] [pid 95126:tid 95351] [client 77.110.127.138:62669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f_Apx5ks9joCJTKW86wAAAew"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:48.915970 2026] [security2:error] [pid 95126:tid 95381] [client 57.141.18.81:27424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f-wpx5ks9joCJTKW8nwACChI"]
[Mon Jul 20 07:17:48.958334 2026] [security2:error] [pid 95126:tid 95284] [client 20.220.9.199:56286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ms-edit.php"] [unique_id "al4f_Apx5ks9joCJTKW88QAAAak"]
[Mon Jul 20 07:17:48.958446 2026] [security2:error] [pid 95126:tid 95284] [client 20.220.9.199:56286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ms-edit.php"] [unique_id "al4f_Apx5ks9joCJTKW88QAAAak"]
[Mon Jul 20 07:17:49.119837 2026] [security2:error] [pid 95126:tid 95300] [client 77.110.127.138:62686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4f_Qpx5ks9joCJTKW8-wAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.169141 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:62712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f_Y06NaEKF1g_MW2vcQAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.170499 2026] [security2:error] [pid 95126:tid 95345] [client 77.110.127.138:62668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f_Qpx5ks9joCJTKW9AAAAAeY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.201148 2026] [security2:error] [pid 95126:tid 95342] [client 20.220.9.199:64420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/222.php"] [unique_id "al4f_Qpx5ks9joCJTKW9AQAAAeM"]
[Mon Jul 20 07:17:49.201261 2026] [security2:error] [pid 95126:tid 95342] [client 20.220.9.199:64420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/222.php"] [unique_id "al4f_Qpx5ks9joCJTKW9AQAAAeM"]
[Mon Jul 20 07:17:49.316198 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:62689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f_Qpx5ks9joCJTKW9BgAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.316294 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:62689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f_Qpx5ks9joCJTKW9BgAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.361411 2026] [security2:error] [pid 95126:tid 95309] [client 57.141.18.34:33028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_Apx5ks9joCJTKW8wQABwhE"]
[Mon Jul 20 07:17:49.368115 2026] [security2:error] [pid 95126:tid 95264] [client 77.110.127.138:62674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4f_Qpx5ks9joCJTKW9DwAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.420555 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:62678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4f_Qpx5ks9joCJTKW9FQAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.458925 2026] [security2:error] [pid 95126:tid 95281] [client 14.225.17.146:60284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4f-wpx5ks9joCJTKW8iAAAAaY"], referer: http://latiendadejorge.com.gt/2019
[Mon Jul 20 07:17:49.521805 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:62715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f_Qpx5ks9joCJTKW9GAAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:49.631386 2026] [security2:error] [pid 95126:tid 95261] [client 104.234.53.57:30481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4f_Qpx5ks9joCJTKW9JwAAAZI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:49.682398 2026] [security2:error] [pid 95126:tid 95300] [client 20.220.9.199:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/cgi-bin/index.php"] [unique_id "al4f_Qpx5ks9joCJTKW9LQAAAbk"]
[Mon Jul 20 07:17:49.682514 2026] [security2:error] [pid 95126:tid 95300] [client 20.220.9.199:64189] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/cgi-bin/index.php"] [unique_id "al4f_Qpx5ks9joCJTKW9LQAAAbk"]
[Mon Jul 20 07:17:49.689064 2026] [security2:error] [pid 95126:tid 95219] [remote 103.75.185.95:34286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.185.75.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f_Qpx5ks9joCJTKW9LAACDVo"]
[Mon Jul 20 07:17:49.689222 2026] [security2:error] [pid 95126:tid 95384] [client 103.75.185.95:34286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4f_Qpx5ks9joCJTKW9LAACDVo"]
[Mon Jul 20 07:17:49.818519 2026] [security2:error] [pid 95126:tid 95289] [client 57.141.18.65:59378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_Apx5ks9joCJTKW81gABrkU"]
[Mon Jul 20 07:17:49.861367 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:62717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f_Y06NaEKF1g_MW2veQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:50.000993 2026] [proxy:error] [pid 94831:tid 95081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:50.001067 2026] [proxy_http:error] [pid 94831:tid 95081] [client 20.220.9.199:64386] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:50.001678 2026] [proxy:error] [pid 94831:tid 95081] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:50.001711 2026] [proxy_http:error] [pid 94831:tid 95081] [client 20.220.9.199:64386] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:50.001819 2026] [security2:error] [pid 94831:tid 95081] [client 20.220.9.199:64386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f_Y06NaEKF1g_MW2vfwAAAHg"]
[Mon Jul 20 07:17:50.067226 2026] [security2:error] [pid 94831:tid 94994] [client 14.225.17.146:60343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4f_Y06NaEKF1g_MW2vfAAAACE"], referer: http://fkconstructionfunding.com/2019
[Mon Jul 20 07:17:50.142446 2026] [security2:error] [pid 95126:tid 95308] [client 77.110.127.138:62720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f_gpx5ks9joCJTKW9SQAAAcE"]
[Mon Jul 20 07:17:50.234440 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:62695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f_gpx5ks9joCJTKW9SwAAAbw"]
[Mon Jul 20 07:17:50.292423 2026] [security2:error] [pid 95126:tid 95297] [client 57.141.18.110:62892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_Qpx5ks9joCJTKW8-AABti8"]
[Mon Jul 20 07:17:50.413560 2026] [security2:error] [pid 94831:tid 95059] [client 154.192.123.127:18827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f_o06NaEKF1g_MW2vhgAAAGI"]
[Mon Jul 20 07:17:50.413656 2026] [security2:error] [pid 94831:tid 95059] [client 154.192.123.127:18827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4f_o06NaEKF1g_MW2vhgAAAGI"]
[Mon Jul 20 07:17:50.465705 2026] [security2:error] [pid 95126:tid 95272] [client 20.220.9.199:44412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/BDKR28WP.php"] [unique_id "al4f_gpx5ks9joCJTKW9VgAAAZ0"]
[Mon Jul 20 07:17:50.465802 2026] [security2:error] [pid 95126:tid 95272] [client 20.220.9.199:44412] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/BDKR28WP.php"] [unique_id "al4f_gpx5ks9joCJTKW9VgAAAZ0"]
[Mon Jul 20 07:17:50.467957 2026] [security2:error] [pid 95126:tid 95330] [client 77.110.127.138:62694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9RwAAAdc"]
[Mon Jul 20 07:17:50.648123 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:62682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f_o06NaEKF1g_MW2vjgAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:50.648207 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:62682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4f_o06NaEKF1g_MW2vjgAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:50.700158 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:62679] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4f_gpx5ks9joCJTKW9ZAAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:50.751702 2026] [security2:error] [pid 95126:tid 95269] [client 77.110.127.138:62696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9WgAAAZo"]
[Mon Jul 20 07:17:50.807886 2026] [security2:error] [pid 95126:tid 95312] [client 14.225.17.146:56474] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9ZQAAAcU"], referer: http://keywayconstructionclt.com/2019
[Mon Jul 20 07:17:50.815188 2026] [security2:error] [pid 95126:tid 95360] [client 49.37.242.14:50661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f_gpx5ks9joCJTKW9aAAAAfU"]
[Mon Jul 20 07:17:50.815291 2026] [security2:error] [pid 95126:tid 95360] [client 49.37.242.14:50661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4f_gpx5ks9joCJTKW9aAAAAfU"]
[Mon Jul 20 07:17:50.912935 2026] [security2:error] [pid 95126:tid 95302] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9XwAAAbs"]
[Mon Jul 20 07:17:50.952613 2026] [proxy:error] [pid 95126:tid 95343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:50.952694 2026] [proxy_http:error] [pid 95126:tid 95343] [client 20.220.9.199:60385] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:50.953243 2026] [proxy:error] [pid 95126:tid 95343] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:50.953269 2026] [proxy_http:error] [pid 95126:tid 95343] [client 20.220.9.199:60385] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:50.953339 2026] [security2:error] [pid 95126:tid 95343] [client 20.220.9.199:60385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f_gpx5ks9joCJTKW9bwAAAeQ"]
[Mon Jul 20 07:17:51.248799 2026] [proxy:error] [pid 95126:tid 95297] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:51.248872 2026] [proxy_http:error] [pid 95126:tid 95297] [client 20.220.9.199:55894] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:51.249279 2026] [proxy:error] [pid 95126:tid 95297] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:51.249301 2026] [proxy_http:error] [pid 95126:tid 95297] [client 20.220.9.199:55894] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:51.249365 2026] [security2:error] [pid 95126:tid 95297] [client 20.220.9.199:55894] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4f_wpx5ks9joCJTKW9gAAAAbY"]
[Mon Jul 20 07:17:51.301687 2026] [security2:error] [pid 94831:tid 94896] [remote 113.160.142.119:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4f_406NaEKF1g_MW2voQAAXEA"]
[Mon Jul 20 07:17:51.409271 2026] [autoindex:error] [pid 94831:tid 95071] [client 164.163.151.142:0] AH01276: Cannot serve directory /home1/acaiandc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:51.470678 2026] [security2:error] [pid 95126:tid 95272] [client 77.110.127.138:62726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4f_wpx5ks9joCJTKW9iQAAAZ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:51.488923 2026] [security2:error] [pid 95126:tid 95277] [client 20.220.9.199:59926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp.php"] [unique_id "al4f_wpx5ks9joCJTKW9igAAAaI"]
[Mon Jul 20 07:17:51.489021 2026] [security2:error] [pid 95126:tid 95277] [client 20.220.9.199:59926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp.php"] [unique_id "al4f_wpx5ks9joCJTKW9igAAAaI"]
[Mon Jul 20 07:17:51.621148 2026] [security2:error] [pid 95126:tid 95312] [client 20.220.9.199:60406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/abcd.php"] [unique_id "al4f_wpx5ks9joCJTKW9mQAAAcU"]
[Mon Jul 20 07:17:51.621263 2026] [security2:error] [pid 95126:tid 95312] [client 20.220.9.199:60406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/abcd.php"] [unique_id "al4f_wpx5ks9joCJTKW9mQAAAcU"]
[Mon Jul 20 07:17:51.831428 2026] [security2:error] [pid 95126:tid 95287] [client 20.220.9.199:50949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/a1.php"] [unique_id "al4f_wpx5ks9joCJTKW9qAAAAaw"]
[Mon Jul 20 07:17:51.831537 2026] [security2:error] [pid 95126:tid 95287] [client 20.220.9.199:50949] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/a1.php"] [unique_id "al4f_wpx5ks9joCJTKW9qAAAAaw"]
[Mon Jul 20 07:17:51.862357 2026] [security2:error] [pid 95126:tid 95379] [client 14.225.17.146:55802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4f_wpx5ks9joCJTKW9pgAAAgg"], referer: https://keywayconstructionclt.com/2019
[Mon Jul 20 07:17:51.894320 2026] [security2:error] [pid 95126:tid 95310] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9UgABw2o"], referer: http://assasalnazaha.com/2019
[Mon Jul 20 07:17:51.910178 2026] [security2:error] [pid 95126:tid 95299] [client 14.225.17.146:55820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4f_wpx5ks9joCJTKW9pwAAAbg"], referer: http://chestermonty.com/2019
[Mon Jul 20 07:17:51.935739 2026] [security2:error] [pid 94831:tid 94911] [remote 113.160.142.119:53496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4f_406NaEKF1g_MW2vtAAAF08"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 07:17:52.041317 2026] [security2:error] [pid 94831:tid 95066] [client 104.234.53.53:22545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gAI06NaEKF1g_MW2vvAAAAGk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:52.054397 2026] [security2:error] [pid 95126:tid 95358] [client 57.141.18.68:27696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9WAAB82s"]
[Mon Jul 20 07:17:52.124311 2026] [security2:error] [pid 94831:tid 95079] [client 201.27.111.74:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gAI06NaEKF1g_MW2vwwAAAHY"]
[Mon Jul 20 07:17:52.124413 2026] [security2:error] [pid 94831:tid 95079] [client 201.27.111.74:54286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gAI06NaEKF1g_MW2vwwAAAHY"]
[Mon Jul 20 07:17:52.258654 2026] [security2:error] [pid 95126:tid 95269] [client 20.220.9.199:56310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4gAApx5ks9joCJTKW9wAAAAZo"]
[Mon Jul 20 07:17:52.258727 2026] [security2:error] [pid 95126:tid 95269] [client 20.220.9.199:56310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4gAApx5ks9joCJTKW9wAAAAZo"]
[Mon Jul 20 07:17:52.321900 2026] [security2:error] [pid 95126:tid 95344] [client 144.172.114.51:47220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.website-fa490990.threethirds.co"] [uri "/ansible/.env"] [unique_id "al4gAApx5ks9joCJTKW9xwAAAeU"]
[Mon Jul 20 07:17:52.325538 2026] [security2:error] [pid 95126:tid 95312] [client 77.110.127.138:62736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/test-knitting/3qqmfuxpu0ig.php"] [unique_id "al4gAApx5ks9joCJTKW9yQAAAcU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:52.488549 2026] [security2:error] [pid 95126:tid 95262] [client 57.141.18.24:29520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_gpx5ks9joCJTKW9agABk08"]
[Mon Jul 20 07:17:52.593238 2026] [security2:error] [pid 95126:tid 95384] [client 77.110.127.138:62738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAApx5ks9joCJTKW91QAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:52.621505 2026] [security2:error] [pid 94831:tid 94989] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAI06NaEKF1g_MW2vyQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:52.705209 2026] [security2:error] [pid 95126:tid 95299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAApx5ks9joCJTKW93AAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:52.849898 2026] [security2:error] [pid 95126:tid 95381] [client 14.225.17.146:62091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4gAApx5ks9joCJTKW98wAAAgo"], referer: https://chestermonty.com/2019
[Mon Jul 20 07:17:52.936816 2026] [autoindex:error] [pid 95126:tid 95380] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/modules/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:53.032866 2026] [security2:error] [pid 94831:tid 95047] [client 74.7.227.179:49500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4gAI06NaEKF1g_MW2v3QAAVl0"], referer: https://tejasenvironmental.com/p=2298277
[Mon Jul 20 07:17:53.099039 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:62679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gAQpx5ks9joCJTKW-DgAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.099166 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:62679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gAQpx5ks9joCJTKW-DgAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.107235 2026] [security2:error] [pid 94831:tid 95039] [client 57.141.18.123:20566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_406NaEKF1g_MW2vqQAATkQ"]
[Mon Jul 20 07:17:53.125770 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:62727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/dfolscmx6owf.php"] [unique_id "al4gAQpx5ks9joCJTKW-EAAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.160073 2026] [security2:error] [pid 95126:tid 95342] [client 57.141.18.42:38004] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4f_wpx5ks9joCJTKW9lQAB438"]
[Mon Jul 20 07:17:53.168773 2026] [autoindex:error] [pid 94831:tid 94969] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/modules/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.217418 2026] [security2:error] [pid 94831:tid 95062] [client 20.220.9.199:44359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4gAY06NaEKF1g_MW2v5wAAAGU"]
[Mon Jul 20 07:17:53.217513 2026] [security2:error] [pid 94831:tid 95062] [client 20.220.9.199:44359] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4gAY06NaEKF1g_MW2v5wAAAGU"]
[Mon Jul 20 07:17:53.469197 2026] [security2:error] [pid 94831:tid 95045] [client 20.220.9.199:60373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/gettest.php"] [unique_id "al4gAY06NaEKF1g_MW2v7gAAAFQ"]
[Mon Jul 20 07:17:53.469332 2026] [security2:error] [pid 94831:tid 95045] [client 20.220.9.199:60373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/gettest.php"] [unique_id "al4gAY06NaEKF1g_MW2v7gAAAFQ"]
[Mon Jul 20 07:17:53.532410 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:62744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-GQAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.565054 2026] [security2:error] [pid 95126:tid 95266] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-HwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.578844 2026] [security2:error] [pid 95126:tid 95384] [client 14.225.17.146:62072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-JAAAAg0"], referer: http://eframiproperties.com/2019
[Mon Jul 20 07:17:53.654617 2026] [security2:error] [pid 94831:tid 94994] [client 77.110.127.138:62717] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gAY06NaEKF1g_MW2v9QAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.720385 2026] [security2:error] [pid 94831:tid 94922] [remote 57.141.18.104:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5356874"] [unique_id "al4gAY06NaEKF1g_MW2v-gAARFo"]
[Mon Jul 20 07:17:53.730840 2026] [proxy:error] [pid 95126:tid 95373] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:53.730890 2026] [proxy_http:error] [pid 95126:tid 95373] [client 20.220.9.199:64393] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:53.731355 2026] [proxy:error] [pid 95126:tid 95373] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:53.731382 2026] [proxy_http:error] [pid 95126:tid 95373] [client 20.220.9.199:64393] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:53.731455 2026] [security2:error] [pid 95126:tid 95373] [client 20.220.9.199:64393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4gAQpx5ks9joCJTKW-OgAAAgI"]
[Mon Jul 20 07:17:53.809232 2026] [security2:error] [pid 95126:tid 95325] [client 77.110.127.138:62750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gAQpx5ks9joCJTKW-PwAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.809329 2026] [security2:error] [pid 95126:tid 95325] [client 77.110.127.138:62750] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gAQpx5ks9joCJTKW-PwAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.816292 2026] [security2:error] [pid 95126:tid 95278] [client 77.110.127.138:62734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/related-posts/qhs8m15iup00.php"] [unique_id "al4gAQpx5ks9joCJTKW-QgAAAaM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.860833 2026] [autoindex:error] [pid 95126:tid 95313] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/modules/related-posts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:17:53.867800 2026] [security2:error] [pid 94831:tid 94995] [client 117.211.236.168:59108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gAY06NaEKF1g_MW2v_gAAACI"]
[Mon Jul 20 07:17:53.867879 2026] [security2:error] [pid 94831:tid 94995] [client 117.211.236.168:59108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gAY06NaEKF1g_MW2v_gAAACI"]
[Mon Jul 20 07:17:53.873649 2026] [autoindex:error] [pid 95126:tid 95274] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/modules/related-posts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:17:53.901656 2026] [security2:error] [pid 94831:tid 94985] [client 103.144.65.217:51960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gAY06NaEKF1g_MW2v_wAAABg"]
[Mon Jul 20 07:17:53.901881 2026] [security2:error] [pid 94831:tid 94985] [client 103.144.65.217:51960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gAY06NaEKF1g_MW2v_wAAABg"]
[Mon Jul 20 07:17:54.044540 2026] [security2:error] [pid 94831:tid 95075] [client 20.220.9.199:55882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/simple.php"] [unique_id "al4gAo06NaEKF1g_MW2wBwAAAHI"]
[Mon Jul 20 07:17:54.044646 2026] [security2:error] [pid 94831:tid 95075] [client 20.220.9.199:55882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/simple.php"] [unique_id "al4gAo06NaEKF1g_MW2wBwAAAHI"]
[Mon Jul 20 07:17:54.054798 2026] [security2:error] [pid 95126:tid 95371] [client 57.141.18.44:30550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gAApx5ks9joCJTKW94gACAHE"]
[Mon Jul 20 07:17:54.061885 2026] [security2:error] [pid 95126:tid 95331] [client 14.225.17.146:57148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-QQAAAdg"], referer: http://www.justinagrayman.com/2019
[Mon Jul 20 07:17:54.067921 2026] [security2:error] [pid 94831:tid 95002] [client 57.141.0.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gAI06NaEKF1g_MW2v1QAAACk"]
[Mon Jul 20 07:17:54.106319 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-TwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:54.266539 2026] [security2:error] [pid 94831:tid 94970] [client 20.220.9.199:44355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xxx.php"] [unique_id "al4gAo06NaEKF1g_MW2wCwAAAAk"]
[Mon Jul 20 07:17:54.266679 2026] [security2:error] [pid 94831:tid 94970] [client 20.220.9.199:44355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xxx.php"] [unique_id "al4gAo06NaEKF1g_MW2wCwAAAAk"]
[Mon Jul 20 07:17:54.275777 2026] [security2:error] [pid 95126:tid 95378] [client 77.110.127.138:62751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-VwAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:54.318141 2026] [proxy:error] [pid 95126:tid 95258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:54.318180 2026] [proxy_http:error] [pid 95126:tid 95258] [client 8.229.28.226:37268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:54.318622 2026] [proxy:error] [pid 95126:tid 95258] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:54.318647 2026] [proxy_http:error] [pid 95126:tid 95258] [client 8.229.28.226:37268] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:54.361522 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:62739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gAgpx5ks9joCJTKW-cwAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:54.369884 2026] [security2:error] [pid 95126:tid 95318] [client 3.67.192.83:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4gAQpx5ks9joCJTKW-LQAAAcs"]
[Mon Jul 20 07:17:54.398609 2026] [security2:error] [pid 95126:tid 95359] [client 20.220.9.199:55899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/hypo.php"] [unique_id "al4gAgpx5ks9joCJTKW-dwAAAfQ"]
[Mon Jul 20 07:17:54.398690 2026] [security2:error] [pid 95126:tid 95359] [client 20.220.9.199:55899] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/hypo.php"] [unique_id "al4gAgpx5ks9joCJTKW-dwAAAfQ"]
[Mon Jul 20 07:17:54.448060 2026] [security2:error] [pid 95126:tid 95187] [remote 45.90.123.233:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4gAgpx5ks9joCJTKW-ewAB4jo"]
[Mon Jul 20 07:17:54.453770 2026] [security2:error] [pid 94831:tid 94982] [client 3.67.192.83:43682] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4gAY06NaEKF1g_MW2v8gAAABU"]
[Mon Jul 20 07:17:54.529379 2026] [security2:error] [pid 94831:tid 95076] [client 14.225.17.146:59784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4gAo06NaEKF1g_MW2wCgAAAHM"]
[Mon Jul 20 07:17:54.573858 2026] [proxy:error] [pid 95126:tid 95345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:54.573924 2026] [proxy_http:error] [pid 95126:tid 95345] [client 20.220.9.199:60361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:54.574413 2026] [proxy:error] [pid 95126:tid 95345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:54.574441 2026] [proxy_http:error] [pid 95126:tid 95345] [client 20.220.9.199:60361] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:54.574510 2026] [security2:error] [pid 95126:tid 95345] [client 20.220.9.199:60361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4gAgpx5ks9joCJTKW-hwAAAeY"]
[Mon Jul 20 07:17:54.660352 2026] [security2:error] [pid 95126:tid 95300] [client 185.238.231.131:56213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4gAgpx5ks9joCJTKW-iwAAAbk"]
[Mon Jul 20 07:17:54.676885 2026] [security2:error] [pid 95126:tid 95189] [remote 45.90.123.233:54898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4gAgpx5ks9joCJTKW-jgABqTw"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:17:54.688095 2026] [security2:error] [pid 95126:tid 95269] [client 155.2.212.10:40663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4gAgpx5ks9joCJTKW-jQAAAZo"]
[Mon Jul 20 07:17:54.732230 2026] [security2:error] [pid 95126:tid 95266] [client 20.220.9.199:56281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/chosen.php"] [unique_id "al4gAgpx5ks9joCJTKW-kAAAAZc"]
[Mon Jul 20 07:17:54.732296 2026] [security2:error] [pid 95126:tid 95266] [client 20.220.9.199:56281] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/chosen.php"] [unique_id "al4gAgpx5ks9joCJTKW-kAAAAZc"]
[Mon Jul 20 07:17:54.921771 2026] [proxy:error] [pid 95126:tid 95344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:54.921867 2026] [proxy_http:error] [pid 95126:tid 95344] [client 20.220.9.199:44424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:54.922537 2026] [proxy:error] [pid 95126:tid 95344] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:54.922565 2026] [proxy_http:error] [pid 95126:tid 95344] [client 20.220.9.199:44424] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:54.922687 2026] [security2:error] [pid 95126:tid 95344] [client 20.220.9.199:44424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4gAgpx5ks9joCJTKW-owAAAeU"]
[Mon Jul 20 07:17:55.048196 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:62755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gAwpx5ks9joCJTKW-sAAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:55.048311 2026] [security2:error] [pid 95126:tid 95349] [client 77.110.127.138:62755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gAwpx5ks9joCJTKW-sAAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:55.112948 2026] [security2:error] [pid 94831:tid 95049] [client 20.220.9.199:44363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/als.php"] [unique_id "al4gA406NaEKF1g_MW2wHAAAAFg"]
[Mon Jul 20 07:17:55.113040 2026] [security2:error] [pid 94831:tid 95049] [client 20.220.9.199:44363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/als.php"] [unique_id "al4gA406NaEKF1g_MW2wHAAAAFg"]
[Mon Jul 20 07:17:55.179265 2026] [security2:error] [pid 95126:tid 95296] [client 154.208.48.130:50819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gAwpx5ks9joCJTKW-ugAAAbU"]
[Mon Jul 20 07:17:55.179396 2026] [security2:error] [pid 95126:tid 95296] [client 154.208.48.130:50819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gAwpx5ks9joCJTKW-ugAAAbU"]
[Mon Jul 20 07:17:55.246448 2026] [security2:error] [pid 95126:tid 95315] [client 20.220.9.199:64432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/pol.php"] [unique_id "al4gAwpx5ks9joCJTKW-xAAAAcg"]
[Mon Jul 20 07:17:55.246545 2026] [security2:error] [pid 95126:tid 95315] [client 20.220.9.199:64432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/pol.php"] [unique_id "al4gAwpx5ks9joCJTKW-xAAAAcg"]
[Mon Jul 20 07:17:55.404092 2026] [security2:error] [pid 95126:tid 95362] [client 47.128.54.153:47558] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gescontrols.com"] [uri "/robots.txt"] [unique_id "al4gAwpx5ks9joCJTKW-ywAAAfc"]
[Mon Jul 20 07:17:55.446541 2026] [security2:error] [pid 95126:tid 95366] [client 20.220.9.199:64158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file5.php"] [unique_id "al4gAwpx5ks9joCJTKW-zQAAAfs"]
[Mon Jul 20 07:17:55.446634 2026] [security2:error] [pid 95126:tid 95366] [client 20.220.9.199:64158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file5.php"] [unique_id "al4gAwpx5ks9joCJTKW-zQAAAfs"]
[Mon Jul 20 07:17:55.603012 2026] [security2:error] [pid 95126:tid 95323] [client 20.220.9.199:59909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file.php"] [unique_id "al4gAwpx5ks9joCJTKW-1AAAAdA"]
[Mon Jul 20 07:17:55.603100 2026] [security2:error] [pid 95126:tid 95323] [client 20.220.9.199:59909] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file.php"] [unique_id "al4gAwpx5ks9joCJTKW-1AAAAdA"]
[Mon Jul 20 07:17:55.680575 2026] [security2:error] [pid 95126:tid 95219] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gAwpx5ks9joCJTKW-1wABllo"]
[Mon Jul 20 07:17:55.680701 2026] [security2:error] [pid 95126:tid 95265] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gAwpx5ks9joCJTKW-1wABllo"]
[Mon Jul 20 07:17:55.753227 2026] [security2:error] [pid 95126:tid 95340] [client 14.225.17.146:59782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4gAwpx5ks9joCJTKW-0gAAAeE"], referer: http://adirondackengineering.com/2019
[Mon Jul 20 07:17:55.792041 2026] [security2:error] [pid 95126:tid 95277] [client 57.141.18.11:51048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gAgpx5ks9joCJTKW-hQABoj4"]
[Mon Jul 20 07:17:55.844080 2026] [security2:error] [pid 95126:tid 95303] [client 13.232.231.177:18094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gAwpx5ks9joCJTKW-3QAAAbw"]
[Mon Jul 20 07:17:55.844198 2026] [security2:error] [pid 95126:tid 95303] [client 13.232.231.177:18094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gAwpx5ks9joCJTKW-3QAAAbw"]
[Mon Jul 20 07:17:55.849116 2026] [security2:error] [pid 95126:tid 95268] [client 20.220.9.199:64404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/cfile.php"] [unique_id "al4gAwpx5ks9joCJTKW-3gAAAZk"]
[Mon Jul 20 07:17:55.849212 2026] [security2:error] [pid 95126:tid 95268] [client 20.220.9.199:64404] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/cfile.php"] [unique_id "al4gAwpx5ks9joCJTKW-3gAAAZk"]
[Mon Jul 20 07:17:55.950890 2026] [security2:error] [pid 94831:tid 94947] [remote 152.228.213.32:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gA406NaEKF1g_MW2wKQAAMXM"]
[Mon Jul 20 07:17:56.071648 2026] [security2:error] [pid 95126:tid 95375] [client 20.220.9.199:10424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/admin.php"] [unique_id "al4gBApx5ks9joCJTKW-7QAAAgQ"]
[Mon Jul 20 07:17:56.071728 2026] [security2:error] [pid 95126:tid 95375] [client 20.220.9.199:10424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/admin.php"] [unique_id "al4gBApx5ks9joCJTKW-7QAAAgQ"]
[Mon Jul 20 07:17:56.222412 2026] [security2:error] [pid 95126:tid 95334] [client 20.220.9.199:60415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/aa2.php"] [unique_id "al4gBApx5ks9joCJTKW--wAAAds"]
[Mon Jul 20 07:17:56.222520 2026] [security2:error] [pid 95126:tid 95334] [client 20.220.9.199:60415] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/aa2.php"] [unique_id "al4gBApx5ks9joCJTKW--wAAAds"]
[Mon Jul 20 07:17:56.266058 2026] [security2:error] [pid 94831:tid 95043] [client 143.44.185.218:55170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gBI06NaEKF1g_MW2wLAAAAFI"]
[Mon Jul 20 07:17:56.266520 2026] [security2:error] [pid 94831:tid 95043] [client 143.44.185.218:55170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gBI06NaEKF1g_MW2wLAAAAFI"]
[Mon Jul 20 07:17:56.284239 2026] [security2:error] [pid 94831:tid 94956] [remote 152.228.213.32:47572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gBI06NaEKF1g_MW2wLgAAfnw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:17:56.440652 2026] [security2:error] [pid 95126:tid 95313] [client 20.220.9.199:44373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ccou.php"] [unique_id "al4gBApx5ks9joCJTKW_CAAAAcY"]
[Mon Jul 20 07:17:56.440818 2026] [security2:error] [pid 95126:tid 95313] [client 20.220.9.199:44373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ccou.php"] [unique_id "al4gBApx5ks9joCJTKW_CAAAAcY"]
[Mon Jul 20 07:17:56.475609 2026] [security2:error] [pid 95126:tid 95380] [client 104.234.53.50:31835] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gBApx5ks9joCJTKW_AgAAAgk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:17:56.498526 2026] [security2:error] [pid 95126:tid 95273] [client 57.141.18.87:27968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gAwpx5ks9joCJTKW-uAABnkQ"]
[Mon Jul 20 07:17:56.626823 2026] [security2:error] [pid 95126:tid 95383] [client 77.110.127.138:62761] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gBApx5ks9joCJTKW_DwAAAgw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:56.679757 2026] [security2:error] [pid 95126:tid 95358] [client 77.110.127.138:62730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBApx5ks9joCJTKW_EwAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:56.679876 2026] [security2:error] [pid 95126:tid 95358] [client 77.110.127.138:62730] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBApx5ks9joCJTKW_EwAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:56.767507 2026] [security2:error] [pid 95126:tid 95342] [client 20.220.9.199:64445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/dr.php"] [unique_id "al4gBApx5ks9joCJTKW_GQAAAeM"]
[Mon Jul 20 07:17:56.767576 2026] [security2:error] [pid 95126:tid 95342] [client 20.220.9.199:64445] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/dr.php"] [unique_id "al4gBApx5ks9joCJTKW_GQAAAeM"]
[Mon Jul 20 07:17:56.832736 2026] [security2:error] [pid 95126:tid 95264] [client 88.241.67.160:54527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gBApx5ks9joCJTKW_HgAAAZU"]
[Mon Jul 20 07:17:56.832839 2026] [security2:error] [pid 95126:tid 95264] [client 88.241.67.160:54527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gBApx5ks9joCJTKW_HgAAAZU"]
[Mon Jul 20 07:17:56.833633 2026] [security2:error] [pid 94831:tid 95066] [client 52.140.101.203:13312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gBI06NaEKF1g_MW2wNwAAAGk"]
[Mon Jul 20 07:17:56.929836 2026] [security2:error] [pid 95126:tid 95299] [client 82.102.18.116:45074] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4gBApx5ks9joCJTKW_IQAAAbg"]
[Mon Jul 20 07:17:56.989535 2026] [security2:error] [pid 95126:tid 95362] [client 20.220.9.199:55902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xamp.php"] [unique_id "al4gBApx5ks9joCJTKW_JgAAAfc"]
[Mon Jul 20 07:17:56.989635 2026] [security2:error] [pid 95126:tid 95362] [client 20.220.9.199:55902] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xamp.php"] [unique_id "al4gBApx5ks9joCJTKW_JgAAAfc"]
[Mon Jul 20 07:17:57.058049 2026] [security2:error] [pid 95126:tid 95334] [client 77.110.127.138:62738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_KAAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.058157 2026] [security2:error] [pid 95126:tid 95334] [client 77.110.127.138:62738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_KAAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.064629 2026] [security2:error] [pid 94831:tid 95003] [client 52.140.101.203:13312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gBY06NaEKF1g_MW2wPAAAACo"]
[Mon Jul 20 07:17:57.100746 2026] [security2:error] [pid 94831:tid 94971] [client 52.183.195.200:7298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gBY06NaEKF1g_MW2wQQAAAAo"]
[Mon Jul 20 07:17:57.129531 2026] [security2:error] [pid 94831:tid 95002] [client 52.183.195.200:7298] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gBY06NaEKF1g_MW2wQwAAACk"]
[Mon Jul 20 07:17:57.130514 2026] [security2:error] [pid 94831:tid 95052] [client 20.220.9.199:55876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/bless.php"] [unique_id "al4gBY06NaEKF1g_MW2wRAAAAFs"]
[Mon Jul 20 07:17:57.130588 2026] [security2:error] [pid 94831:tid 95052] [client 20.220.9.199:55876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/bless.php"] [unique_id "al4gBY06NaEKF1g_MW2wRAAAAFs"]
[Mon Jul 20 07:17:57.208834 2026] [security2:error] [pid 95126:tid 95272] [client 77.110.127.138:62763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_OAAAAZ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.208954 2026] [security2:error] [pid 95126:tid 95272] [client 77.110.127.138:62763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_OAAAAZ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.250123 2026] [security2:error] [pid 94831:tid 95016] [client 13.232.231.177:50216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gBY06NaEKF1g_MW2wRgAAADc"]
[Mon Jul 20 07:17:57.254980 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:62764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gBQpx5ks9joCJTKW_OgAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.271846 2026] [security2:error] [pid 95126:tid 95261] [client 20.220.9.199:56282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file25.php"] [unique_id "al4gBQpx5ks9joCJTKW_OwAAAZI"]
[Mon Jul 20 07:17:57.271918 2026] [security2:error] [pid 95126:tid 95261] [client 20.220.9.199:56282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file25.php"] [unique_id "al4gBQpx5ks9joCJTKW_OwAAAZI"]
[Mon Jul 20 07:17:57.277300 2026] [security2:error] [pid 94831:tid 95065] [client 82.102.18.116:45076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.recalibratemed.com"] [uri "/xmlrpc.php"] [unique_id "al4gBY06NaEKF1g_MW2wRwAAAGg"]
[Mon Jul 20 07:17:57.277739 2026] [security2:error] [pid 94831:tid 94837] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gBY06NaEKF1g_MW2wSAAAHAU"]
[Mon Jul 20 07:17:57.277858 2026] [security2:error] [pid 94831:tid 94989] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gBY06NaEKF1g_MW2wSAAAHAU"]
[Mon Jul 20 07:17:57.402131 2026] [security2:error] [pid 95126:tid 95346] [client 77.110.127.138:62688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_QAAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.402249 2026] [security2:error] [pid 95126:tid 95346] [client 77.110.127.138:62688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_QAAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.453038 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:62731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_RgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.453188 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:62731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBQpx5ks9joCJTKW_RgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.469053 2026] [security2:error] [pid 95126:tid 95360] [client 20.220.9.199:50881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file6.php"] [unique_id "al4gBQpx5ks9joCJTKW_SAAAAfU"]
[Mon Jul 20 07:17:57.469130 2026] [security2:error] [pid 95126:tid 95360] [client 20.220.9.199:50881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file6.php"] [unique_id "al4gBQpx5ks9joCJTKW_SAAAAfU"]
[Mon Jul 20 07:17:57.485848 2026] [security2:error] [pid 95126:tid 95307] [client 66.249.74.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mollycahill.com"] [uri "/index.php"] [unique_id "al4gBQpx5ks9joCJTKW_MAAAAcA"]
[Mon Jul 20 07:17:57.502557 2026] [security2:error] [pid 95126:tid 95379] [client 103.176.215.66:51619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gBQpx5ks9joCJTKW_SQAAAgg"]
[Mon Jul 20 07:17:57.502680 2026] [security2:error] [pid 95126:tid 95379] [client 103.176.215.66:51619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gBQpx5ks9joCJTKW_SQAAAgg"]
[Mon Jul 20 07:17:57.504687 2026] [security2:error] [pid 94831:tid 95084] [client 77.110.127.138:62740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBY06NaEKF1g_MW2wTAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.504791 2026] [security2:error] [pid 94831:tid 95084] [client 77.110.127.138:62740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBY06NaEKF1g_MW2wTAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:57.594874 2026] [security2:error] [pid 95126:tid 95232] [remote 117.0.21.154:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4gBQpx5ks9joCJTKW_TQAB_2c"]
[Mon Jul 20 07:17:57.631328 2026] [security2:error] [pid 95126:tid 95351] [client 20.220.9.199:64141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/a2.php"] [unique_id "al4gBQpx5ks9joCJTKW_UwAAAew"]
[Mon Jul 20 07:17:57.631427 2026] [security2:error] [pid 95126:tid 95351] [client 20.220.9.199:64141] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/a2.php"] [unique_id "al4gBQpx5ks9joCJTKW_UwAAAew"]
[Mon Jul 20 07:17:57.671687 2026] [security2:error] [pid 95126:tid 95225] [remote 162.19.86.63:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gBQpx5ks9joCJTKW_WAABqWA"]
[Mon Jul 20 07:17:57.769618 2026] [security2:error] [pid 94831:tid 95067] [client 77.83.36.161:47522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4gBY06NaEKF1g_MW2wUwAAAGo"]
[Mon Jul 20 07:17:57.780491 2026] [security2:error] [pid 95126:tid 95343] [client 20.220.9.199:64128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file15.php"] [unique_id "al4gBQpx5ks9joCJTKW_XQAAAeQ"]
[Mon Jul 20 07:17:57.780582 2026] [security2:error] [pid 95126:tid 95343] [client 20.220.9.199:64128] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file15.php"] [unique_id "al4gBQpx5ks9joCJTKW_XQAAAeQ"]
[Mon Jul 20 07:17:57.880221 2026] [security2:error] [pid 95126:tid 95216] [remote 162.19.86.63:53838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gBQpx5ks9joCJTKW_aAABkVc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:17:57.919230 2026] [security2:error] [pid 95126:tid 95372] [client 82.102.18.116:45078] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4gBQpx5ks9joCJTKW_awAAAgE"]
[Mon Jul 20 07:17:57.927557 2026] [security2:error] [pid 95126:tid 95357] [client 20.220.9.199:59930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/f35.php"] [unique_id "al4gBQpx5ks9joCJTKW_bAAAAfI"]
[Mon Jul 20 07:17:57.927636 2026] [security2:error] [pid 95126:tid 95357] [client 20.220.9.199:59930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/f35.php"] [unique_id "al4gBQpx5ks9joCJTKW_bAAAAfI"]
[Mon Jul 20 07:17:57.970126 2026] [security2:error] [pid 95126:tid 95326] [client 157.20.138.62:62905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gBQpx5ks9joCJTKW_bgAAAdM"]
[Mon Jul 20 07:17:57.970244 2026] [security2:error] [pid 95126:tid 95326] [client 157.20.138.62:62905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gBQpx5ks9joCJTKW_bgAAAdM"]
[Mon Jul 20 07:17:58.080372 2026] [security2:error] [pid 95126:tid 95296] [client 20.220.9.199:55904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-load.php"] [unique_id "al4gBgpx5ks9joCJTKW_dwAAAbU"]
[Mon Jul 20 07:17:58.080447 2026] [security2:error] [pid 95126:tid 95296] [client 20.220.9.199:55904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-load.php"] [unique_id "al4gBgpx5ks9joCJTKW_dwAAAbU"]
[Mon Jul 20 07:17:58.246456 2026] [security2:error] [pid 95126:tid 95252] [remote 160.187.68.132:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4gBgpx5ks9joCJTKW_fQACDXs"]
[Mon Jul 20 07:17:58.247013 2026] [security2:error] [pid 95126:tid 95259] [client 82.102.18.116:38950] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4gBgpx5ks9joCJTKW_fwAAAZA"]
[Mon Jul 20 07:17:58.297487 2026] [security2:error] [pid 95126:tid 95278] [client 20.220.9.199:56295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xwpg.php"] [unique_id "al4gBgpx5ks9joCJTKW_ggAAAaM"]
[Mon Jul 20 07:17:58.297581 2026] [security2:error] [pid 95126:tid 95278] [client 20.220.9.199:56295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xwpg.php"] [unique_id "al4gBgpx5ks9joCJTKW_ggAAAaM"]
[Mon Jul 20 07:17:58.335050 2026] [security2:error] [pid 95126:tid 95279] [client 57.141.18.25:35118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gBApx5ks9joCJTKW_GgABpCg"]
[Mon Jul 20 07:17:58.347523 2026] [security2:error] [pid 95126:tid 95309] [client 13.233.207.33:51656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gBgpx5ks9joCJTKW_iAAAAcI"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:17:58.422718 2026] [security2:error] [pid 95126:tid 95377] [client 77.83.36.161:47926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4gBgpx5ks9joCJTKW_iwAAAgY"]
[Mon Jul 20 07:17:58.430011 2026] [security2:error] [pid 94831:tid 94979] [client 50.116.65.227:21058] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gBo06NaEKF1g_MW2wYAAAABI"]
[Mon Jul 20 07:17:58.439467 2026] [security2:error] [pid 94831:tid 95039] [client 50.116.65.227:21066] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gBo06NaEKF1g_MW2wYQAAAE4"]
[Mon Jul 20 07:17:58.448889 2026] [security2:error] [pid 94831:tid 95012] [client 77.110.127.138:62767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBo06NaEKF1g_MW2wYgAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:58.449010 2026] [security2:error] [pid 94831:tid 95012] [client 77.110.127.138:62767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBo06NaEKF1g_MW2wYgAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:58.492091 2026] [security2:error] [pid 94831:tid 95014] [client 57.141.18.6:25564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gBI06NaEKF1g_MW2wOAAANQA"]
[Mon Jul 20 07:17:58.496132 2026] [security2:error] [pid 94831:tid 95061] [client 77.110.127.138:62771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBo06NaEKF1g_MW2wYwAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:58.496206 2026] [security2:error] [pid 94831:tid 95061] [client 77.110.127.138:62771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBo06NaEKF1g_MW2wYwAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:58.551990 2026] [security2:error] [pid 95126:tid 95273] [client 77.110.127.138:62754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBgpx5ks9joCJTKW_kAAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:58.552110 2026] [security2:error] [pid 95126:tid 95273] [client 77.110.127.138:62754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gBgpx5ks9joCJTKW_kAAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:17:58.568239 2026] [security2:error] [pid 94831:tid 94983] [client 82.102.18.116:38964] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4gBo06NaEKF1g_MW2wZwAAABY"]
[Mon Jul 20 07:17:58.671569 2026] [security2:error] [pid 95126:tid 95248] [remote 117.0.21.154:53484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4gBgpx5ks9joCJTKW_nQAB1Hc"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:17:58.748491 2026] [security2:error] [pid 95126:tid 95154] [remote 160.187.68.132:38844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4gBgpx5ks9joCJTKW_ogAB_hk"], referer: https://adultdaycarereno.com/wp-login.php
[Mon Jul 20 07:17:58.911130 2026] [security2:error] [pid 95126:tid 95351] [client 82.102.18.116:38966] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4gBgpx5ks9joCJTKW_rQAAAew"]
[Mon Jul 20 07:17:58.915146 2026] [security2:error] [pid 95126:tid 95318] [client 187.16.64.216:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gBgpx5ks9joCJTKW_rgAAAcs"]
[Mon Jul 20 07:17:58.915256 2026] [security2:error] [pid 95126:tid 95318] [client 187.16.64.216:54048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gBgpx5ks9joCJTKW_rgAAAcs"]
[Mon Jul 20 07:17:59.079006 2026] [security2:error] [pid 95126:tid 95341] [client 77.83.36.161:48284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.36.83.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "amberhillstyle.com"] [uri "/administrator/index.php"] [unique_id "al4gBwpx5ks9joCJTKW_vAAAAeI"]
[Mon Jul 20 07:17:59.096051 2026] [security2:error] [pid 95126:tid 95310] [client 14.225.17.146:54683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4gBgpx5ks9joCJTKW_swAAAcM"], referer: http://whiteoutcb.com/2019
[Mon Jul 20 07:17:59.147372 2026] [security2:error] [pid 95126:tid 95323] [client 191.202.66.27:49218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gBwpx5ks9joCJTKW_vwAAAdA"]
[Mon Jul 20 07:17:59.147477 2026] [security2:error] [pid 95126:tid 95323] [client 191.202.66.27:49218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gBwpx5ks9joCJTKW_vwAAAdA"]
[Mon Jul 20 07:17:59.254279 2026] [security2:error] [pid 94831:tid 95019] [client 82.102.18.116:38972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4gB406NaEKF1g_MW2wfAAAADo"]
[Mon Jul 20 07:17:59.333082 2026] [fcgid:warn] [pid 95126:tid 95296] (70014)End of file found: [client 144.172.114.51:47276] mod_fcgid: can't get data from http client
[Mon Jul 20 07:17:59.351435 2026] [security2:error] [pid 95126:tid 95266] [client 57.141.18.54:21562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gBQpx5ks9joCJTKW_ZAABl2o"]
[Mon Jul 20 07:17:59.445439 2026] [proxy:error] [pid 95126:tid 95357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:59.445527 2026] [proxy_http:error] [pid 95126:tid 95357] [client 20.220.9.199:50983] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:59.446756 2026] [proxy:error] [pid 95126:tid 95357] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:59.446795 2026] [proxy_http:error] [pid 95126:tid 95357] [client 20.220.9.199:50983] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:59.446888 2026] [security2:error] [pid 95126:tid 95357] [client 20.220.9.199:50983] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4gBwpx5ks9joCJTKW_0gAAAfI"]
[Mon Jul 20 07:17:59.571657 2026] [security2:error] [pid 95126:tid 95375] [client 82.102.18.116:38988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4gBwpx5ks9joCJTKW_2QAAAgQ"]
[Mon Jul 20 07:17:59.657828 2026] [security2:error] [pid 95126:tid 95336] [client 14.225.17.146:57318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gBwpx5ks9joCJTKW_0wAAAd0"], referer: http://mezzacraft.com/2019
[Mon Jul 20 07:17:59.670925 2026] [proxy:error] [pid 94831:tid 94967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:59.671027 2026] [proxy_http:error] [pid 94831:tid 94967] [client 20.220.9.199:64400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:59.671734 2026] [proxy:error] [pid 94831:tid 94967] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:17:59.671772 2026] [proxy_http:error] [pid 94831:tid 94967] [client 20.220.9.199:64400] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:17:59.671859 2026] [security2:error] [pid 94831:tid 94967] [client 20.220.9.199:64400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cpcontacts.mzsassy.com"] [uri "/___proxy_subdomain_cpcontacts/cgi-sys/503.html"] [unique_id "al4gB406NaEKF1g_MW2wgwAAAAY"]
[Mon Jul 20 07:17:59.721808 2026] [security2:error] [pid 95126:tid 95370] [client 43.205.139.3:42570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gBwpx5ks9joCJTKW_4AAAAf8"]
[Mon Jul 20 07:17:59.721930 2026] [security2:error] [pid 95126:tid 95370] [client 43.205.139.3:42570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gBwpx5ks9joCJTKW_4AAAAf8"]
[Mon Jul 20 07:17:59.819990 2026] [security2:error] [pid 95126:tid 95361] [client 20.220.9.199:56312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xstelth.php"] [unique_id "al4gBwpx5ks9joCJTKW_5gAAAfY"]
[Mon Jul 20 07:17:59.820086 2026] [security2:error] [pid 95126:tid 95361] [client 20.220.9.199:56312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xstelth.php"] [unique_id "al4gBwpx5ks9joCJTKW_5gAAAfY"]
[Mon Jul 20 07:17:59.888073 2026] [security2:error] [pid 95126:tid 95283] [client 82.102.18.116:38994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4gBwpx5ks9joCJTKW_6gAAAag"]
[Mon Jul 20 07:17:59.992453 2026] [security2:error] [pid 95126:tid 95308] [client 77.110.127.138:62774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gBwpx5ks9joCJTKW_8QAAAcE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:00.055314 2026] [security2:error] [pid 95126:tid 95277] [client 20.220.9.199:55926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4gCApx5ks9joCJTKW_8gAAAaI"]
[Mon Jul 20 07:18:00.055433 2026] [security2:error] [pid 95126:tid 95277] [client 20.220.9.199:55926] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4gCApx5ks9joCJTKW_8gAAAaI"]
[Mon Jul 20 07:18:00.206052 2026] [security2:error] [pid 95126:tid 95324] [client 20.220.9.199:55918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/aaa.php"] [unique_id "al4gCApx5ks9joCJTKW__QAAAdE"]
[Mon Jul 20 07:18:00.206136 2026] [security2:error] [pid 95126:tid 95324] [client 20.220.9.199:55918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/aaa.php"] [unique_id "al4gCApx5ks9joCJTKW__QAAAdE"]
[Mon Jul 20 07:18:00.245109 2026] [security2:error] [pid 95126:tid 95357] [client 82.102.18.116:39000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4gCApx5ks9joCJTKXAAAAAAfI"]
[Mon Jul 20 07:18:00.337330 2026] [security2:error] [pid 95126:tid 95325] [client 14.225.17.146:59637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4gCApx5ks9joCJTKXAAQAAAdI"], referer: http://friendlyspreadsheet.com/2019
[Mon Jul 20 07:18:00.395511 2026] [security2:error] [pid 95126:tid 95375] [client 20.220.9.199:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/gecko.php"] [unique_id "al4gCApx5ks9joCJTKXACQAAAgQ"]
[Mon Jul 20 07:18:00.395589 2026] [security2:error] [pid 95126:tid 95375] [client 20.220.9.199:64161] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/gecko.php"] [unique_id "al4gCApx5ks9joCJTKXACQAAAgQ"]
[Mon Jul 20 07:18:00.449623 2026] [security2:error] [pid 95126:tid 95290] [client 57.141.18.0:50520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gBwpx5ks9joCJTKW_vQABrxA"]
[Mon Jul 20 07:18:00.527967 2026] [security2:error] [pid 95126:tid 95265] [client 20.220.9.199:55888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/sh3ll.php"] [unique_id "al4gCApx5ks9joCJTKXAEgAAAZY"]
[Mon Jul 20 07:18:00.528063 2026] [security2:error] [pid 95126:tid 95265] [client 20.220.9.199:55888] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/sh3ll.php"] [unique_id "al4gCApx5ks9joCJTKXAEgAAAZY"]
[Mon Jul 20 07:18:00.569229 2026] [security2:error] [pid 94831:tid 95013] [client 82.102.18.116:39012] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4gCI06NaEKF1g_MW2wqwAAADQ"]
[Mon Jul 20 07:18:00.692988 2026] [security2:error] [pid 94831:tid 94972] [client 20.220.9.199:56290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/pbck.php"] [unique_id "al4gCI06NaEKF1g_MW2wsAAAAAs"]
[Mon Jul 20 07:18:00.693071 2026] [security2:error] [pid 94831:tid 94972] [client 20.220.9.199:56290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/pbck.php"] [unique_id "al4gCI06NaEKF1g_MW2wsAAAAAs"]
[Mon Jul 20 07:18:00.836958 2026] [security2:error] [pid 94831:tid 95023] [client 20.220.9.199:56306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xiugai.php"] [unique_id "al4gCI06NaEKF1g_MW2wsgAAAD4"]
[Mon Jul 20 07:18:00.837052 2026] [security2:error] [pid 94831:tid 95023] [client 20.220.9.199:56306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xiugai.php"] [unique_id "al4gCI06NaEKF1g_MW2wsgAAAD4"]
[Mon Jul 20 07:18:00.843277 2026] [security2:error] [pid 95126:tid 95175] [remote 160.187.68.132:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gCApx5ks9joCJTKXAIwAB7C4"]
[Mon Jul 20 07:18:00.880445 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:62776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gCI06NaEKF1g_MW2wtgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:00.895773 2026] [lsapi:warn] [pid 95126:tid 95156] [remote 104.223.65.148:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:18:00.913283 2026] [security2:error] [pid 95126:tid 95299] [client 82.102.18.116:39024] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4gCApx5ks9joCJTKXAKQAAAbg"]
[Mon Jul 20 07:18:00.932606 2026] [security2:error] [pid 95126:tid 95335] [client 57.141.18.98:30062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gBwpx5ks9joCJTKW_2AAB3HE"]
[Mon Jul 20 07:18:00.949715 2026] [security2:error] [pid 94831:tid 95057] [client 154.192.123.127:17214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gCI06NaEKF1g_MW2wuQAAAGA"]
[Mon Jul 20 07:18:00.950208 2026] [security2:error] [pid 94831:tid 95057] [client 154.192.123.127:17214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gCI06NaEKF1g_MW2wuQAAAGA"]
[Mon Jul 20 07:18:01.071864 2026] [security2:error] [pid 95126:tid 95324] [client 104.234.53.50:31835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gCQpx5ks9joCJTKXAOQAAAdE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:01.102282 2026] [security2:error] [pid 95126:tid 95380] [client 14.225.17.146:57345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4gCQpx5ks9joCJTKXAMwAAAgk"], referer: http://momheadquarters.com/2019
[Mon Jul 20 07:18:01.128374 2026] [security2:error] [pid 95126:tid 95263] [client 139.28.219.68:48616] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4gCQpx5ks9joCJTKXAPgAAAZQ"]
[Mon Jul 20 07:18:01.135042 2026] [security2:error] [pid 95126:tid 95311] [client 20.220.9.199:50963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/e.php"] [unique_id "al4gCQpx5ks9joCJTKXAPwAAAcQ"]
[Mon Jul 20 07:18:01.135113 2026] [security2:error] [pid 95126:tid 95311] [client 20.220.9.199:50963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/e.php"] [unique_id "al4gCQpx5ks9joCJTKXAPwAAAcQ"]
[Mon Jul 20 07:18:01.160878 2026] [core:error] [pid 95126:tid 95309] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:01.160909 2026] [core:error] [pid 95126:tid 95309] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:01.233917 2026] [security2:error] [pid 95126:tid 95281] [client 82.102.18.116:39030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4gCQpx5ks9joCJTKXATAAAAaY"]
[Mon Jul 20 07:18:01.263932 2026] [security2:error] [pid 94831:tid 95056] [client 20.220.9.199:50989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/for.php"] [unique_id "al4gCY06NaEKF1g_MW2wvQAAAF8"]
[Mon Jul 20 07:18:01.264039 2026] [security2:error] [pid 94831:tid 95056] [client 20.220.9.199:50989] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/for.php"] [unique_id "al4gCY06NaEKF1g_MW2wvQAAAF8"]
[Mon Jul 20 07:18:01.291001 2026] [security2:error] [pid 95126:tid 95317] [client 14.225.17.146:65286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4gCQpx5ks9joCJTKXASwAAAco"], referer: https://friendlyspreadsheet.com/2019
[Mon Jul 20 07:18:01.328274 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:62777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gCY06NaEKF1g_MW2wvwAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.328376 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:62777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gCY06NaEKF1g_MW2wvwAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.402372 2026] [security2:error] [pid 95126:tid 95261] [client 20.220.9.199:44447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/ssh3ll.php"] [unique_id "al4gCQpx5ks9joCJTKXAVwAAAZI"]
[Mon Jul 20 07:18:01.402475 2026] [security2:error] [pid 95126:tid 95261] [client 20.220.9.199:44447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/ssh3ll.php"] [unique_id "al4gCQpx5ks9joCJTKXAVwAAAZI"]
[Mon Jul 20 07:18:01.476027 2026] [security2:error] [pid 95126:tid 95327] [client 139.28.219.68:48624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "footstompproductions.com"] [uri "/xmlrpc.php"] [unique_id "al4gCQpx5ks9joCJTKXAXgAAAdQ"]
[Mon Jul 20 07:18:01.479632 2026] [security2:error] [pid 95126:tid 95280] [client 77.110.127.138:62778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gCQpx5ks9joCJTKXAYAAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.479784 2026] [security2:error] [pid 95126:tid 95280] [client 77.110.127.138:62778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gCQpx5ks9joCJTKXAYAAAAaU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.496994 2026] [security2:error] [pid 95126:tid 95207] [remote 160.187.68.132:38846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gCQpx5ks9joCJTKXAYgABnE4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:18:01.549567 2026] [security2:error] [pid 95126:tid 95296] [client 82.102.18.116:39034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4gCQpx5ks9joCJTKXAZAAAAbU"]
[Mon Jul 20 07:18:01.597608 2026] [security2:error] [pid 95126:tid 95279] [client 14.225.17.146:54609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4gBwpx5ks9joCJTKW_6AAAAaQ"], referer: http://fluidtemple.org/2019
[Mon Jul 20 07:18:01.633196 2026] [security2:error] [pid 95126:tid 95328] [client 77.110.127.138:62780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gCQpx5ks9joCJTKXAaAAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.633305 2026] [security2:error] [pid 95126:tid 95328] [client 77.110.127.138:62780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gCQpx5ks9joCJTKXAaAAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.641177 2026] [security2:error] [pid 94831:tid 95075] [client 20.220.9.199:56318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/adminner.php"] [unique_id "al4gCY06NaEKF1g_MW2wygAAAHI"]
[Mon Jul 20 07:18:01.641273 2026] [security2:error] [pid 94831:tid 95075] [client 20.220.9.199:56318] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/adminner.php"] [unique_id "al4gCY06NaEKF1g_MW2wygAAAHI"]
[Mon Jul 20 07:18:01.679372 2026] [security2:error] [pid 95126:tid 95229] [remote 20.173.88.122:35642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gCQpx5ks9joCJTKXAagABoWQ"]
[Mon Jul 20 07:18:01.679577 2026] [security2:error] [pid 95126:tid 95276] [client 20.173.88.122:35642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gCQpx5ks9joCJTKXAagABoWQ"]
[Mon Jul 20 07:18:01.786934 2026] [security2:error] [pid 95126:tid 95313] [client 20.220.9.199:55923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/82.php"] [unique_id "al4gCQpx5ks9joCJTKXAegAAAcY"]
[Mon Jul 20 07:18:01.787049 2026] [security2:error] [pid 95126:tid 95313] [client 20.220.9.199:55923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/82.php"] [unique_id "al4gCQpx5ks9joCJTKXAegAAAcY"]
[Mon Jul 20 07:18:01.871281 2026] [security2:error] [pid 94831:tid 95026] [client 82.102.18.116:39038] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4gCY06NaEKF1g_MW2w0QAAAEE"]
[Mon Jul 20 07:18:01.898401 2026] [security2:error] [pid 95126:tid 95203] [remote 202.51.202.242:37360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4gCQpx5ks9joCJTKXAggABtEo"]
[Mon Jul 20 07:18:01.898614 2026] [security2:error] [pid 95126:tid 95295] [client 202.51.202.242:37360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4gCQpx5ks9joCJTKXAggABtEo"]
[Mon Jul 20 07:18:01.959879 2026] [security2:error] [pid 95126:tid 95268] [client 77.110.127.138:62729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gCQpx5ks9joCJTKXAdAAAAZk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:01.967556 2026] [security2:error] [pid 95126:tid 95317] [client 139.28.219.68:48626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4gCQpx5ks9joCJTKXAhQAAAco"]
[Mon Jul 20 07:18:02.093130 2026] [security2:error] [pid 95126:tid 95336] [client 20.220.9.199:59959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/kir.php"] [unique_id "al4gCgpx5ks9joCJTKXAiwAAAd0"]
[Mon Jul 20 07:18:02.093255 2026] [security2:error] [pid 95126:tid 95336] [client 20.220.9.199:59959] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/kir.php"] [unique_id "al4gCgpx5ks9joCJTKXAiwAAAd0"]
[Mon Jul 20 07:18:02.148636 2026] [security2:error] [pid 94831:tid 94977] [client 49.37.242.14:51113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gCo06NaEKF1g_MW2w0wAAABA"]
[Mon Jul 20 07:18:02.148871 2026] [security2:error] [pid 94831:tid 94977] [client 49.37.242.14:51113] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gCo06NaEKF1g_MW2w0wAAABA"]
[Mon Jul 20 07:18:02.212435 2026] [security2:error] [pid 94831:tid 95082] [client 82.102.18.116:39050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4gCo06NaEKF1g_MW2w1gAAAHk"]
[Mon Jul 20 07:18:02.283706 2026] [security2:error] [pid 94831:tid 94974] [client 139.28.219.68:48628] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4gCo06NaEKF1g_MW2w2gAAAA0"]
[Mon Jul 20 07:18:02.333796 2026] [security2:error] [pid 94831:tid 94978] [client 20.220.9.199:56261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/up4.php"] [unique_id "al4gCo06NaEKF1g_MW2w3QAAABE"]
[Mon Jul 20 07:18:02.333930 2026] [security2:error] [pid 94831:tid 94978] [client 20.220.9.199:56261] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/up4.php"] [unique_id "al4gCo06NaEKF1g_MW2w3QAAABE"]
[Mon Jul 20 07:18:02.481203 2026] [security2:error] [pid 95126:tid 95276] [client 20.220.9.199:55881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/xhar.php"] [unique_id "al4gCgpx5ks9joCJTKXAnAAAAaE"]
[Mon Jul 20 07:18:02.481282 2026] [security2:error] [pid 95126:tid 95276] [client 20.220.9.199:55881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/xhar.php"] [unique_id "al4gCgpx5ks9joCJTKXAnAAAAaE"]
[Mon Jul 20 07:18:02.555386 2026] [security2:error] [pid 95126:tid 95348] [client 82.102.18.116:39060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4gCgpx5ks9joCJTKXAogAAAek"]
[Mon Jul 20 07:18:02.561901 2026] [security2:error] [pid 95126:tid 95323] [client 57.141.18.30:28628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gCApx5ks9joCJTKXAIQAB0EM"]
[Mon Jul 20 07:18:02.573672 2026] [security2:error] [pid 95126:tid 95334] [client 139.28.219.68:48642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4gCgpx5ks9joCJTKXApAAAAds"]
[Mon Jul 20 07:18:02.592083 2026] [security2:error] [pid 95126:tid 95340] [client 201.27.111.74:54799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gCgpx5ks9joCJTKXApgAAAeE"]
[Mon Jul 20 07:18:02.592251 2026] [security2:error] [pid 95126:tid 95340] [client 201.27.111.74:54799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gCgpx5ks9joCJTKXApgAAAeE"]
[Mon Jul 20 07:18:02.704278 2026] [security2:error] [pid 94831:tid 95083] [client 14.225.17.146:59663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4gCo06NaEKF1g_MW2w4wAAAHo"], referer: http://iagdevelopments.com/2019
[Mon Jul 20 07:18:02.711657 2026] [security2:error] [pid 95126:tid 95268] [client 20.220.9.199:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/file1221.php"] [unique_id "al4gCgpx5ks9joCJTKXAsQAAAZk"]
[Mon Jul 20 07:18:02.711775 2026] [security2:error] [pid 95126:tid 95268] [client 20.220.9.199:50976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/file1221.php"] [unique_id "al4gCgpx5ks9joCJTKXAsQAAAZk"]
[Mon Jul 20 07:18:02.713676 2026] [security2:error] [pid 94831:tid 94966] [client 114.119.155.126:40611] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elespecialista.mx"] [uri "/&sa=U"] [unique_id "al4gCo06NaEKF1g_MW2w5AAAAAU"], referer: http://www.google.co.il/maps/search/6050/C%20Burke%20commons%20Rd,Burke%20VA%2022015
[Mon Jul 20 07:18:02.853187 2026] [security2:error] [pid 95126:tid 95266] [client 57.141.18.0:64860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gCApx5ks9joCJTKXAMgABl3g"]
[Mon Jul 20 07:18:02.872077 2026] [security2:error] [pid 95126:tid 95331] [client 82.102.18.116:39070] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.recalibratemed.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4gCgpx5ks9joCJTKXAvAAAAdg"]
[Mon Jul 20 07:18:02.881243 2026] [security2:error] [pid 95126:tid 95278] [client 20.220.9.199:50985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/inx.php"] [unique_id "al4gCgpx5ks9joCJTKXAvQAAAaM"]
[Mon Jul 20 07:18:02.881325 2026] [security2:error] [pid 95126:tid 95278] [client 20.220.9.199:50985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/inx.php"] [unique_id "al4gCgpx5ks9joCJTKXAvQAAAaM"]
[Mon Jul 20 07:18:02.902508 2026] [security2:error] [pid 95126:tid 95371] [client 139.28.219.68:48658] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4gCgpx5ks9joCJTKXAwwAAAgA"]
[Mon Jul 20 07:18:03.086660 2026] [security2:error] [pid 95126:tid 95385] [client 77.110.127.138:62785] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gCgpx5ks9joCJTKXAvwAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:03.148826 2026] [security2:error] [pid 95126:tid 95259] [client 20.220.9.199:44452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/qqqa.php"] [unique_id "al4gCwpx5ks9joCJTKXA1QAAAZA"]
[Mon Jul 20 07:18:03.148951 2026] [security2:error] [pid 95126:tid 95259] [client 20.220.9.199:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/qqqa.php"] [unique_id "al4gCwpx5ks9joCJTKXA1QAAAZA"]
[Mon Jul 20 07:18:03.216232 2026] [security2:error] [pid 95126:tid 95292] [client 139.28.219.68:48670] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4gCwpx5ks9joCJTKXA2QAAAbE"]
[Mon Jul 20 07:18:03.256967 2026] [core:error] [pid 95126:tid 95286] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:03.256994 2026] [core:error] [pid 95126:tid 95286] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:03.295948 2026] [security2:error] [pid 95126:tid 95290] [client 20.220.9.199:64144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/gk.php"] [unique_id "al4gCwpx5ks9joCJTKXA4gAAAa8"]
[Mon Jul 20 07:18:03.296063 2026] [security2:error] [pid 95126:tid 95290] [client 20.220.9.199:64144] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/gk.php"] [unique_id "al4gCwpx5ks9joCJTKXA4gAAAa8"]
[Mon Jul 20 07:18:03.446467 2026] [security2:error] [pid 95126:tid 95347] [client 20.220.9.199:50975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/005.php"] [unique_id "al4gCwpx5ks9joCJTKXA7gAAAeg"]
[Mon Jul 20 07:18:03.446568 2026] [security2:error] [pid 95126:tid 95347] [client 20.220.9.199:50975] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/005.php"] [unique_id "al4gCwpx5ks9joCJTKXA7gAAAeg"]
[Mon Jul 20 07:18:03.529287 2026] [security2:error] [pid 95126:tid 95287] [client 139.28.219.68:48676] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4gCwpx5ks9joCJTKXA8gAAAaw"]
[Mon Jul 20 07:18:03.590891 2026] [security2:error] [pid 95126:tid 95280] [client 20.220.9.199:55919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/norn.php"] [unique_id "al4gCwpx5ks9joCJTKXA9wAAAaU"]
[Mon Jul 20 07:18:03.591023 2026] [security2:error] [pid 95126:tid 95280] [client 20.220.9.199:55919] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/norn.php"] [unique_id "al4gCwpx5ks9joCJTKXA9wAAAaU"]
[Mon Jul 20 07:18:03.726532 2026] [security2:error] [pid 95126:tid 95385] [client 50.116.65.227:44818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gCwpx5ks9joCJTKXBAAAAAg4"]
[Mon Jul 20 07:18:03.736362 2026] [security2:error] [pid 95126:tid 95334] [client 50.116.65.227:44826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gCwpx5ks9joCJTKXBBAAAAds"]
[Mon Jul 20 07:18:03.764315 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:62788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gCwpx5ks9joCJTKXA9QAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:03.806493 2026] [security2:error] [pid 95126:tid 95375] [client 23.251.146.115:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4gCwpx5ks9joCJTKXA_QACBAk"]
[Mon Jul 20 07:18:03.815916 2026] [security2:error] [pid 95126:tid 95309] [client 14.225.17.146:57436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4gCwpx5ks9joCJTKXBAgAAAcI"], referer: https://iagdevelopments.com/2019
[Mon Jul 20 07:18:03.848882 2026] [security2:error] [pid 95126:tid 95304] [client 139.28.219.68:48686] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4gCwpx5ks9joCJTKXBDQAAAb0"]
[Mon Jul 20 07:18:03.924100 2026] [security2:error] [pid 95126:tid 95313] [client 23.251.146.115:1024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4gCwpx5ks9joCJTKXBDAABxho"]
[Mon Jul 20 07:18:03.932954 2026] [security2:error] [pid 95126:tid 95274] [client 20.220.9.199:64388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.mzsassy.com"] [uri "/dmin.php"] [unique_id "al4gCwpx5ks9joCJTKXBFQAAAZ8"]
[Mon Jul 20 07:18:03.933066 2026] [security2:error] [pid 95126:tid 95274] [client 20.220.9.199:64388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpcontacts.mzsassy.com"] [uri "/dmin.php"] [unique_id "al4gCwpx5ks9joCJTKXBFQAAAZ8"]
[Mon Jul 20 07:18:03.944186 2026] [security2:error] [pid 95126:tid 95354] [client 14.225.17.146:57236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4gCgpx5ks9joCJTKXAtAAAAe8"], referer: http://mourgroup.com/2019
[Mon Jul 20 07:18:04.162993 2026] [security2:error] [pid 95126:tid 95310] [client 139.28.219.68:48702] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4gDApx5ks9joCJTKXBJwAAAcM"]
[Mon Jul 20 07:18:04.213642 2026] [security2:error] [pid 95126:tid 95345] [client 23.251.146.115:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4gDApx5ks9joCJTKXBJAAAAeY"]
[Mon Jul 20 07:18:04.296264 2026] [security2:error] [pid 95126:tid 95299] [client 77.110.127.138:62790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDApx5ks9joCJTKXBHQAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:04.406276 2026] [security2:error] [pid 94831:tid 95019] [client 103.144.65.217:52419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gDI06NaEKF1g_MW2xDAAAADo"]
[Mon Jul 20 07:18:04.406379 2026] [security2:error] [pid 94831:tid 95019] [client 103.144.65.217:52419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gDI06NaEKF1g_MW2xDAAAADo"]
[Mon Jul 20 07:18:04.468342 2026] [security2:error] [pid 94831:tid 94989] [client 139.28.219.68:48718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4gDI06NaEKF1g_MW2xEAAAABw"]
[Mon Jul 20 07:18:04.470982 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:62791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gDI06NaEKF1g_MW2xEQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:04.778555 2026] [security2:error] [pid 95126:tid 95294] [client 139.28.219.68:48726] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4gDApx5ks9joCJTKXBSAAAAbM"]
[Mon Jul 20 07:18:05.011274 2026] [security2:error] [pid 94831:tid 94987] [client 77.110.127.138:62793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDI06NaEKF1g_MW2xHQAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:05.068047 2026] [security2:error] [pid 95126:tid 95297] [client 139.28.219.68:48734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4gDQpx5ks9joCJTKXBWQAAAbY"]
[Mon Jul 20 07:18:05.102800 2026] [security2:error] [pid 95126:tid 95277] [client 77.110.127.138:62794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gDQpx5ks9joCJTKXBXAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:05.102899 2026] [security2:error] [pid 95126:tid 95277] [client 77.110.127.138:62794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gDQpx5ks9joCJTKXBXAAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:05.152247 2026] [security2:error] [pid 94831:tid 94980] [client 77.110.127.138:62757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gDY06NaEKF1g_MW2xKQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:05.152336 2026] [security2:error] [pid 94831:tid 94980] [client 77.110.127.138:62757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gDY06NaEKF1g_MW2xKQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:05.212521 2026] [security2:error] [pid 95126:tid 95310] [client 34.90.222.110:16384] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gDQpx5ks9joCJTKXBaAAAAcM"]
[Mon Jul 20 07:18:05.212648 2026] [security2:error] [pid 95126:tid 95310] [client 34.90.222.110:16384] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gDQpx5ks9joCJTKXBaAAAAcM"]
[Mon Jul 20 07:18:05.366922 2026] [security2:error] [pid 95126:tid 95323] [client 139.28.219.68:48738] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4gDQpx5ks9joCJTKXBcgAAAdA"]
[Mon Jul 20 07:18:05.439261 2026] [security2:error] [pid 95126:tid 95343] [client 77.110.127.138:62795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDQpx5ks9joCJTKXBaQAAAeQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:05.535200 2026] [core:error] [pid 94831:tid 95062] [client 14.225.17.146:49483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2019
[Mon Jul 20 07:18:05.535224 2026] [core:error] [pid 94831:tid 95062] [client 14.225.17.146:49483] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2019
[Mon Jul 20 07:18:05.688839 2026] [security2:error] [pid 94831:tid 95021] [client 139.28.219.68:55928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4gDY06NaEKF1g_MW2xNQAAADw"]
[Mon Jul 20 07:18:05.957566 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:62742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDY06NaEKF1g_MW2xNwAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:06.012990 2026] [security2:error] [pid 95126:tid 95301] [client 139.28.219.68:55930] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4gDgpx5ks9joCJTKXBkAAAAbo"]
[Mon Jul 20 07:18:06.127493 2026] [security2:error] [pid 95126:tid 95286] [client 154.208.48.130:51326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gDgpx5ks9joCJTKXBlwAAAas"]
[Mon Jul 20 07:18:06.127620 2026] [security2:error] [pid 95126:tid 95286] [client 154.208.48.130:51326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gDgpx5ks9joCJTKXBlwAAAas"]
[Mon Jul 20 07:18:06.140797 2026] [security2:error] [pid 95126:tid 95292] [client 14.225.17.146:59722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4gDApx5ks9joCJTKXBRQAAAbE"], referer: http://dadanetnet.net/2019
[Mon Jul 20 07:18:06.223473 2026] [security2:error] [pid 94831:tid 95081] [client 14.225.17.146:59916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4gDo06NaEKF1g_MW2xRQAAAHg"], referer: http://oldracelimited.com/2019
[Mon Jul 20 07:18:06.320974 2026] [security2:error] [pid 94831:tid 95019] [client 139.28.219.68:55944] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "footstompproductions.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4gDo06NaEKF1g_MW2xSAAAADo"]
[Mon Jul 20 07:18:06.331962 2026] [security2:error] [pid 95126:tid 95307] [client 77.110.127.138:62798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDgpx5ks9joCJTKXBlgAAAcA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:06.338682 2026] [security2:error] [pid 95126:tid 95215] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gDgpx5ks9joCJTKXBqQAB0FY"]
[Mon Jul 20 07:18:06.338835 2026] [security2:error] [pid 95126:tid 95323] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gDgpx5ks9joCJTKXBqQAB0FY"]
[Mon Jul 20 07:18:06.376995 2026] [security2:error] [pid 94831:tid 94993] [client 57.141.18.72:45318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gDI06NaEKF1g_MW2xEgAAIFE"]
[Mon Jul 20 07:18:06.589160 2026] [security2:error] [pid 95126:tid 95305] [client 50.116.65.227:44868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4gDgpx5ks9joCJTKXBrQAAAb4"]
[Mon Jul 20 07:18:06.755248 2026] [security2:error] [pid 95126:tid 95359] [client 50.116.65.227:44882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4gDgpx5ks9joCJTKXBwQAAAfQ"]
[Mon Jul 20 07:18:06.991185 2026] [security2:error] [pid 95126:tid 95261] [client 143.44.185.218:56359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gDgpx5ks9joCJTKXB4AAAAZI"]
[Mon Jul 20 07:18:06.991327 2026] [security2:error] [pid 95126:tid 95261] [client 143.44.185.218:56359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gDgpx5ks9joCJTKXB4AAAAZI"]
[Mon Jul 20 07:18:07.012776 2026] [security2:error] [pid 95126:tid 95263] [client 77.110.127.138:62805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDgpx5ks9joCJTKXB0AAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:07.033584 2026] [security2:error] [pid 94831:tid 95070] [client 117.211.236.168:59760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xVQAAAG0"]
[Mon Jul 20 07:18:07.033720 2026] [security2:error] [pid 94831:tid 95070] [client 117.211.236.168:59760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xVQAAAG0"]
[Mon Jul 20 07:18:07.232143 2026] [access_compat:error] [pid 95126:tid 95308] [client 144.172.114.51:45288] AH01797: client denied by server configuration: /home4/vfcthoma/public_html/website_abc5f05b/server-status
[Mon Jul 20 07:18:07.366660 2026] [security2:error] [pid 94831:tid 94892] [remote 188.95.113.76:49902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xXgAAdjw"]
[Mon Jul 20 07:18:07.366843 2026] [security2:error] [pid 94831:tid 95079] [client 188.95.113.76:49902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xXgAAdjw"]
[Mon Jul 20 07:18:07.472789 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:62812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXB7QAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:07.514115 2026] [security2:error] [pid 94831:tid 94962] [client 77.110.127.138:62814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gD406NaEKF1g_MW2xZAAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:07.602703 2026] [security2:error] [pid 94831:tid 95008] [client 88.241.67.160:56583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xbQAAAC8"]
[Mon Jul 20 07:18:07.602880 2026] [security2:error] [pid 94831:tid 95008] [client 88.241.67.160:56583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xbQAAAC8"]
[Mon Jul 20 07:18:07.784264 2026] [security2:error] [pid 94831:tid 94951] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xdwAAH3c"]
[Mon Jul 20 07:18:07.784422 2026] [security2:error] [pid 94831:tid 94992] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gD406NaEKF1g_MW2xdwAAH3c"]
[Mon Jul 20 07:18:07.800708 2026] [security2:error] [pid 94831:tid 95060] [client 77.110.127.138:62786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gD406NaEKF1g_MW2xawAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:07.948349 2026] [security2:error] [pid 95126:tid 95193] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.openclaw/.env"] [unique_id "al4gDwpx5ks9joCJTKXCEQABmEA"]
[Mon Jul 20 07:18:08.027030 2026] [security2:error] [pid 94831:tid 95083] [client 103.176.215.66:52134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gEI06NaEKF1g_MW2xfAAAAHo"]
[Mon Jul 20 07:18:08.027172 2026] [security2:error] [pid 94831:tid 95083] [client 103.176.215.66:52134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gEI06NaEKF1g_MW2xfAAAAHo"]
[Mon Jul 20 07:18:08.071242 2026] [security2:error] [pid 95126:tid 95367] [client 34.90.254.162:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gEApx5ks9joCJTKXCGwAAAfw"]
[Mon Jul 20 07:18:08.071385 2026] [security2:error] [pid 95126:tid 95367] [client 34.90.254.162:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gEApx5ks9joCJTKXCGwAAAfw"]
[Mon Jul 20 07:18:08.124121 2026] [security2:error] [pid 95126:tid 95321] [client 57.141.18.71:38244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gDgpx5ks9joCJTKXBsAABzhs"]
[Mon Jul 20 07:18:08.142373 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCBAABmFI"]
[Mon Jul 20 07:18:08.200235 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCCQABmG4"]
[Mon Jul 20 07:18:08.200412 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCCAABmHg"]
[Mon Jul 20 07:18:08.201395 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCBwABmGc"]
[Mon Jul 20 07:18:08.202007 2026] [security2:error] [pid 94831:tid 95010] [client 77.110.127.138:62822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gD406NaEKF1g_MW2xeQAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:08.215847 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCBgABmHw"]
[Mon Jul 20 07:18:08.217197 2026] [security2:error] [pid 95126:tid 95171] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCCwABmCo"]
[Mon Jul 20 07:18:08.233141 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCDgABmHQ"]
[Mon Jul 20 07:18:08.233272 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCDwABmFc"]
[Mon Jul 20 07:18:08.239383 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXCDQABmAI"]
[Mon Jul 20 07:18:08.262572 2026] [security2:error] [pid 95126:tid 95252] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/.continue/config.json"] [unique_id "al4gEApx5ks9joCJTKXCKAABmHs"]
[Mon Jul 20 07:18:08.262720 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/.continue/config.json"] [unique_id "al4gEApx5ks9joCJTKXCKAABmHs"]
[Mon Jul 20 07:18:08.392740 2026] [security2:error] [pid 95126:tid 95363] [client 57.141.18.112:35182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gDgpx5ks9joCJTKXBwgAB-FE"]
[Mon Jul 20 07:18:08.405000 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gEApx5ks9joCJTKXCMQAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:08.405083 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:62840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gEApx5ks9joCJTKXCMQAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:08.442667 2026] [core:error] [pid 95126:tid 95261] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:08.442686 2026] [core:error] [pid 95126:tid 95261] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:08.459824 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCIQABmA4"]
[Mon Jul 20 07:18:08.464691 2026] [security2:error] [pid 95126:tid 95336] [client 20.63.100.92:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.100.63.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "chadoldfather.com"] [uri "/.well-known/about.php"] [unique_id "al4gEApx5ks9joCJTKXCNgAAAd0"]
[Mon Jul 20 07:18:08.464799 2026] [security2:error] [pid 95126:tid 95336] [client 20.63.100.92:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "chadoldfather.com"] [uri "/.well-known/about.php"] [unique_id "al4gEApx5ks9joCJTKXCNgAAAd0"]
[Mon Jul 20 07:18:08.544907 2026] [core:error] [pid 95126:tid 95289] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:08.544947 2026] [core:error] [pid 95126:tid 95289] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:08.565593 2026] [security2:error] [pid 95126:tid 95294] [client 77.110.127.138:62841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gEApx5ks9joCJTKXCQgAAAbM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:08.565696 2026] [security2:error] [pid 95126:tid 95294] [client 77.110.127.138:62841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gEApx5ks9joCJTKXCQgAAAbM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:08.597320 2026] [security2:error] [pid 94831:tid 94968] [client 57.141.18.64:65080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gDo06NaEKF1g_MW2xTgAAB18"]
[Mon Jul 20 07:18:08.607476 2026] [security2:error] [pid 95126:tid 95258] [client 157.20.138.62:63474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gEApx5ks9joCJTKXCRwAAAY8"]
[Mon Jul 20 07:18:08.608744 2026] [security2:error] [pid 95126:tid 95258] [client 157.20.138.62:63474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gEApx5ks9joCJTKXCRwAAAY8"]
[Mon Jul 20 07:18:08.663497 2026] [security2:error] [pid 95126:tid 95283] [client 14.225.17.146:59901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXB4wAAAag"], referer: http://gearwaterproof.com/2019
[Mon Jul 20 07:18:08.802884 2026] [security2:error] [pid 95126:tid 95337] [client 57.141.18.56:51078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gDwpx5ks9joCJTKXB4QAB3i8"]
[Mon Jul 20 07:18:09.106397 2026] [security2:error] [pid 95126:tid 95183] [remote 72.167.132.114:56896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4gEQpx5ks9joCJTKXCdgACBjY"]
[Mon Jul 20 07:18:09.106581 2026] [security2:error] [pid 95126:tid 95377] [client 72.167.132.114:56896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4gEQpx5ks9joCJTKXCdgACBjY"]
[Mon Jul 20 07:18:09.182195 2026] [security2:error] [pid 95126:tid 95327] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCVgAB1Bw"]
[Mon Jul 20 07:18:09.211592 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCUgAB6Sc"], referer: https://guidehunting.com/rclone.conf
[Mon Jul 20 07:18:09.211929 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCUQAB6Q0"], referer: https://guidehunting.com/z9x8c7v6b5-debug-trigger-guidehunting.com
[Mon Jul 20 07:18:09.212025 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCVQAB6R8"], referer: https://guidehunting.com/.openclaw/openclaw.json
[Mon Jul 20 07:18:09.212448 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCVAAB6Rg"], referer: https://guidehunting.com/.cursor/mcp.json
[Mon Jul 20 07:18:09.255836 2026] [proxy:error] [pid 95126:tid 95259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:09.255894 2026] [proxy_http:error] [pid 95126:tid 95259] [client 23.180.120.148:51918] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:09.257006 2026] [proxy:error] [pid 95126:tid 95259] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:09.257057 2026] [proxy_http:error] [pid 95126:tid 95259] [client 23.180.120.148:51918] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:09.332242 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCagAB6TI"], referer: https://guidehunting.com/_next/build-manifest.json
[Mon Jul 20 07:18:09.332560 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCaQAB6Ss"], referer: https://guidehunting.com/webpack-stats.json
[Mon Jul 20 07:18:09.332665 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCaAAB6X0"], referer: https://guidehunting.com/build-manifest.json
[Mon Jul 20 07:18:09.335321 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCbAAB6Sw"], referer: https://guidehunting.com/manifest.json
[Mon Jul 20 07:18:09.335408 2026] [security2:error] [pid 95126:tid 95348] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCZwAB6Rc"], referer: https://guidehunting.com/asset-manifest.json
[Mon Jul 20 07:18:09.335703 2026] [security2:error] [pid 95126:tid 95250] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCawAB6Xk"], referer: https://guidehunting.com/_next/static/buildManifest.js
[Mon Jul 20 07:18:09.381374 2026] [security2:error] [pid 95126:tid 95327] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEApx5ks9joCJTKXCbgAB1Dk"]
[Mon Jul 20 07:18:09.406240 2026] [security2:error] [pid 95126:tid 95341] [client 104.234.53.58:34897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gEQpx5ks9joCJTKXCjgAAAeI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:09.561715 2026] [security2:error] [pid 95126:tid 95188] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.hermes/.env"] [unique_id "al4gEQpx5ks9joCJTKXCmgAB-Ds"]
[Mon Jul 20 07:18:09.569524 2026] [core:error] [pid 94831:tid 94997] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:09.569547 2026] [core:error] [pid 94831:tid 94997] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:09.706174 2026] [security2:error] [pid 94831:tid 95032] [client 191.202.66.27:49696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gEY06NaEKF1g_MW2xoAAAAEc"]
[Mon Jul 20 07:18:09.706279 2026] [security2:error] [pid 94831:tid 95032] [client 191.202.66.27:49696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gEY06NaEKF1g_MW2xoAAAAEc"]
[Mon Jul 20 07:18:09.809674 2026] [security2:error] [pid 94831:tid 95000] [client 187.16.64.216:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gEY06NaEKF1g_MW2xogAAACc"]
[Mon Jul 20 07:18:09.809830 2026] [security2:error] [pid 94831:tid 95000] [client 187.16.64.216:54622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gEY06NaEKF1g_MW2xogAAACc"]
[Mon Jul 20 07:18:09.827455 2026] [security2:error] [pid 95126:tid 95305] [client 50.116.65.227:35002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gEQpx5ks9joCJTKXCsQAAAb4"]
[Mon Jul 20 07:18:09.837651 2026] [security2:error] [pid 95126:tid 95298] [client 50.116.65.227:35012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gEQpx5ks9joCJTKXCswAAAbc"]
[Mon Jul 20 07:18:09.847279 2026] [security2:error] [pid 95126:tid 95182] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/graphql"] [unique_id "al4gEQpx5ks9joCJTKXCtgAB4jU"]
[Mon Jul 20 07:18:09.909219 2026] [security2:error] [pid 95126:tid 95166] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/.bashrc"] [unique_id "al4gEQpx5ks9joCJTKXCwAAB2CU"]
[Mon Jul 20 07:18:10.097870 2026] [security2:error] [pid 94831:tid 95013] [client 14.225.17.146:50286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4gEY06NaEKF1g_MW2xpQAAADQ"], referer: http://savilerowtravel.com/2019
[Mon Jul 20 07:18:10.183034 2026] [security2:error] [pid 95126:tid 95230] [remote 182.77.62.24:35706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4gEgpx5ks9joCJTKXC1AAB5GU"]
[Mon Jul 20 07:18:10.239951 2026] [security2:error] [pid 94831:tid 94841] [remote 152.228.213.32:59432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4gEo06NaEKF1g_MW2xqwAAVwk"]
[Mon Jul 20 07:18:10.257467 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCugAB2BE"]
[Mon Jul 20 07:18:10.257594 2026] [security2:error] [pid 95126:tid 95205] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/api/graphql"] [unique_id "al4gEgpx5ks9joCJTKXC1wAB2Ew"]
[Mon Jul 20 07:18:10.257869 2026] [security2:error] [pid 95126:tid 95234] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "guidehunting.com"] [uri "/wp-config.php.bak"] [unique_id "al4gEgpx5ks9joCJTKXC2AAB2Gk"]
[Mon Jul 20 07:18:10.259272 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCuQAB2FU"]
[Mon Jul 20 07:18:10.297779 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCxQAB2E0"]
[Mon Jul 20 07:18:10.298168 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCwQAB2DA"]
[Mon Jul 20 07:18:10.298282 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCvwAB2Aw"]
[Mon Jul 20 07:18:10.298395 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCuwAB5SA"], referer: https://guidehunting.com/.codex/config.toml
[Mon Jul 20 07:18:10.298706 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCxwAB2D4"]
[Mon Jul 20 07:18:10.319925 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCwwAB2GY"]
[Mon Jul 20 07:18:10.320897 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCxgAB5Vk"], referer: https://guidehunting.com/.aider.conf.yml
[Mon Jul 20 07:18:10.361446 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEQpx5ks9joCJTKXCyQAB2CI"]
[Mon Jul 20 07:18:10.399056 2026] [security2:error] [pid 95126:tid 95331] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXCzgAB2G0"]
[Mon Jul 20 07:18:10.453212 2026] [security2:error] [pid 94831:tid 94835] [remote 152.228.213.32:59432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4gEo06NaEKF1g_MW2xsQAADwM"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:18:10.749849 2026] [security2:error] [pid 95126:tid 95133] [remote 182.77.62.24:35706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4gEgpx5ks9joCJTKXC-QAB_gQ"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 07:18:10.751477 2026] [security2:error] [pid 95126:tid 95156] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guidehunting.com"] [uri "/v1/graphql"] [unique_id "al4gEgpx5ks9joCJTKXC-wABshs"]
[Mon Jul 20 07:18:10.753992 2026] [security2:error] [pid 95126:tid 95171] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "guidehunting.com"] [uri "/wp-config.php.old"] [unique_id "al4gEgpx5ks9joCJTKXDBAABtio"]
[Mon Jul 20 07:18:10.878550 2026] [security2:error] [pid 95126:tid 95139] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/laravel/.env"] [unique_id "al4gEgpx5ks9joCJTKXDFQABkwo"]
[Mon Jul 20 07:18:10.982011 2026] [security2:error] [pid 95126:tid 95296] [client 77.110.127.138:62878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gEgpx5ks9joCJTKXDIQAAAbU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:11.152891 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXC1QAB5VQ"]
[Mon Jul 20 07:18:11.223380 2026] [security2:error] [pid 95126:tid 95248] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/config/.env.php"] [unique_id "al4gEwpx5ks9joCJTKXDMAABk3c"]
[Mon Jul 20 07:18:11.223723 2026] [security2:error] [pid 95126:tid 95159] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/.env.php.bak"] [unique_id "al4gEwpx5ks9joCJTKXDMQABkx4"]
[Mon Jul 20 07:18:11.334947 2026] [security2:error] [pid 94831:tid 95049] [client 57.141.18.53:34662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gEY06NaEKF1g_MW2xlAAAWH0"]
[Mon Jul 20 07:18:11.412524 2026] [security2:error] [pid 95126:tid 95262] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXDFgABk1E"]
[Mon Jul 20 07:18:11.430560 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXC-gAB5Ws"], referer: https://guidehunting.com/.hermes/auth.json
[Mon Jul 20 07:18:11.484521 2026] [security2:error] [pid 94831:tid 95069] [client 154.192.123.127:17578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gE406NaEKF1g_MW2xwAAAAGw"]
[Mon Jul 20 07:18:11.484675 2026] [security2:error] [pid 94831:tid 95069] [client 154.192.123.127:17578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gE406NaEKF1g_MW2xwAAAAGw"]
[Mon Jul 20 07:18:11.650056 2026] [security2:error] [pid 95126:tid 95334] [client 77.110.127.138:62880] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4gEwpx5ks9joCJTKXDRwAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:11.654250 2026] [security2:error] [pid 95126:tid 95200] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/core/.env"] [unique_id "al4gEwpx5ks9joCJTKXDSAAB00c"]
[Mon Jul 20 07:18:11.776892 2026] [security2:error] [pid 95126:tid 95255] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/config.php.bak"] [unique_id "al4gEwpx5ks9joCJTKXDTgAB034"]
[Mon Jul 20 07:18:11.987237 2026] [security2:error] [pid 95126:tid 95303] [client 45.157.112.60:25153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gEwpx5ks9joCJTKXDWQAAAbw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:18:12.130697 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXC_AAB5QY"], referer: https://guidehunting.com/.config/anthropic/credentials/default.json
[Mon Jul 20 07:18:12.132189 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXDAgAB5QU"], referer: https://guidehunting.com/.claude/settings.json
[Mon Jul 20 07:18:12.133322 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXDAQAB5Rs"], referer: https://guidehunting.com/.bash_profile
[Mon Jul 20 07:18:12.133498 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXDBwAB5UI"], referer: https://guidehunting.com/.profile
[Mon Jul 20 07:18:12.133725 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXDAAAB5Xg"], referer: https://guidehunting.com/.hermes/config.yaml
[Mon Jul 20 07:18:12.136152 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXC_wAB5W4"], referer: https://guidehunting.com/.mcp.json
[Mon Jul 20 07:18:12.136730 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXC_QAB5T0"], referer: https://guidehunting.com/.claude.json
[Mon Jul 20 07:18:12.139102 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEgpx5ks9joCJTKXC_gAB5VI"], referer: https://guidehunting.com/.zshrc
[Mon Jul 20 07:18:12.185499 2026] [security2:error] [pid 95126:tid 95187] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/configuration.php.bak"] [unique_id "al4gFApx5ks9joCJTKXDawAB0zo"]
[Mon Jul 20 07:18:12.292464 2026] [security2:error] [pid 94831:tid 95070] [client 14.225.17.146:64196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "royalart-lb.com"] [uri "/index.php"] [unique_id "al4gFI06NaEKF1g_MW2xyAAAAG0"]
[Mon Jul 20 07:18:12.319722 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:62883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gFApx5ks9joCJTKXDdgAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:12.319852 2026] [security2:error] [pid 95126:tid 95373] [client 77.110.127.138:62883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gFApx5ks9joCJTKXDdgAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:12.323226 2026] [core:error] [pid 94831:tid 94962] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:12.323268 2026] [core:error] [pid 94831:tid 94962] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:12.411636 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gEwpx5ks9joCJTKXDRgAB0yY"]
[Mon Jul 20 07:18:12.437321 2026] [security2:error] [pid 95126:tid 95344] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gEwpx5ks9joCJTKXDUwAB5SQ"], referer: https://guidehunting.com/storage/logs/laravel.log
[Mon Jul 20 07:18:12.456862 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDbAAB0zI"]
[Mon Jul 20 07:18:12.475201 2026] [security2:error] [pid 95126:tid 95384] [client 77.110.127.138:62884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gFApx5ks9joCJTKXDiQAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:12.475336 2026] [security2:error] [pid 95126:tid 95384] [client 77.110.127.138:62884] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gFApx5ks9joCJTKXDiQAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:12.519976 2026] [security2:error] [pid 95126:tid 95181] [remote 192.241.143.148:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4gFApx5ks9joCJTKXDjAAB6DQ"]
[Mon Jul 20 07:18:12.554109 2026] [security2:error] [pid 95126:tid 95151] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/public/.env"] [unique_id "al4gFApx5ks9joCJTKXDkAAB0xY"]
[Mon Jul 20 07:18:12.555576 2026] [security2:error] [pid 95126:tid 95242] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/web/.env"] [unique_id "al4gFApx5ks9joCJTKXDkgAB03E"]
[Mon Jul 20 07:18:12.593732 2026] [security2:error] [pid 95126:tid 95215] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/api/settings"] [unique_id "al4gFApx5ks9joCJTKXDlQAB01Y"]
[Mon Jul 20 07:18:12.665365 2026] [security2:error] [pid 95126:tid 95166] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.env.swp"] [unique_id "al4gFApx5ks9joCJTKXDmAAB0yU"]
[Mon Jul 20 07:18:12.697746 2026] [security2:error] [pid 95126:tid 95202] [remote 192.241.143.148:53892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4gFApx5ks9joCJTKXDngABykk"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 07:18:12.728503 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDhAAB0zc"]
[Mon Jul 20 07:18:12.728642 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDhgAB0z8"]
[Mon Jul 20 07:18:12.777858 2026] [security2:error] [pid 95126:tid 95305] [client 104.234.53.91:49209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gFApx5ks9joCJTKXDpgAAAb4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:12.815150 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDkQAB0y0"]
[Mon Jul 20 07:18:12.815689 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDjwAB0zw"]
[Mon Jul 20 07:18:12.834829 2026] [security2:error] [pid 95126:tid 95229] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/settings.json"] [unique_id "al4gFApx5ks9joCJTKXDqAAB02Q"]
[Mon Jul 20 07:18:12.835487 2026] [security2:error] [pid 95126:tid 95175] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/env.json"] [unique_id "al4gFApx5ks9joCJTKXDqQAB0y4"]
[Mon Jul 20 07:18:12.963109 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDlwAB0zg"]
[Mon Jul 20 07:18:12.995052 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDoQACAUU"], referer: https://guidehunting.com/auth.json
[Mon Jul 20 07:18:12.995272 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDogACASE"], referer: https://guidehunting.com/.env.dev
[Mon Jul 20 07:18:13.185992 2026] [security2:error] [pid 95126:tid 95287] [client 201.27.111.74:55318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gFQpx5ks9joCJTKXDxAAAAaw"]
[Mon Jul 20 07:18:13.186300 2026] [security2:error] [pid 95126:tid 95287] [client 201.27.111.74:55318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gFQpx5ks9joCJTKXDxAAAAaw"]
[Mon Jul 20 07:18:13.254483 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDqgAB00Y"]
[Mon Jul 20 07:18:13.255014 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDqwAB01w"]
[Mon Jul 20 07:18:13.355804 2026] [security2:error] [pid 94831:tid 94979] [client 158.173.89.95:52115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gFY06NaEKF1g_MW2x7QAAABI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:18:13.369796 2026] [security2:error] [pid 95126:tid 95331] [client 49.37.242.14:51542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gFQpx5ks9joCJTKXD0AAAAdg"]
[Mon Jul 20 07:18:13.369965 2026] [security2:error] [pid 95126:tid 95331] [client 49.37.242.14:51542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gFQpx5ks9joCJTKXD0AAAAdg"]
[Mon Jul 20 07:18:13.415736 2026] [security2:error] [pid 94831:tid 94985] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gFY06NaEKF1g_MW2x6gAAABg"]
[Mon Jul 20 07:18:13.416963 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDuAAB00w"]
[Mon Jul 20 07:18:13.449718 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDwwAB0ww"]
[Mon Jul 20 07:18:13.470824 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDwQABryA"], referer: https://guidehunting.com/__/firebase/init.json
[Mon Jul 20 07:18:13.471043 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDwAABr00"], referer: https://guidehunting.com/api/config
[Mon Jul 20 07:18:13.471492 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDvwABr1U"], referer: https://guidehunting.com/config.json
[Mon Jul 20 07:18:13.472066 2026] [security2:error] [pid 95126:tid 95223] [remote 149.88.64.125:51488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.64.88.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gFQpx5ks9joCJTKXD4AAB314"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:18:13.490676 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDwgABrzA"], referer: https://guidehunting.com/config.js
[Mon Jul 20 07:18:13.526928 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDxgAB02E"]
[Mon Jul 20 07:18:13.609209 2026] [security2:error] [pid 95126:tid 95356] [client 57.141.18.95:50840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gEwpx5ks9joCJTKXDQQAB8Qc"]
[Mon Jul 20 07:18:13.646508 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXDzgABr1k"], referer: https://guidehunting.com/values.yaml
[Mon Jul 20 07:18:13.670098 2026] [security2:error] [pid 95126:tid 95374] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4gFApx5ks9joCJTKXDrAACA0o"], referer: http://ardhalwafaa.com/2019
[Mon Jul 20 07:18:14.045899 2026] [autoindex:error] [pid 95126:tid 95155] [remote 34.23.167.213:49160] AH01276: Cannot serve directory /home2/fjyyvsmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://fjy.yvs.mybluehost.me
[Mon Jul 20 07:18:14.258462 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD6QAB03M"]
[Mon Jul 20 07:18:14.261757 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD5wAB010"]
[Mon Jul 20 07:18:14.319785 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD8QABr18"], referer: https://guidehunting.com/api/v1/settings
[Mon Jul 20 07:18:14.328740 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD7wABr0M"], referer: https://guidehunting.com/env.js
[Mon Jul 20 07:18:14.330790 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD8AABr0A"], referer: https://guidehunting.com/firebase-config.json
[Mon Jul 20 07:18:14.396489 2026] [security2:error] [pid 94831:tid 95036] [client 57.141.18.1:61486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gFI06NaEKF1g_MW2x0wAASxU"]
[Mon Jul 20 07:18:14.984282 2026] [security2:error] [pid 95126:tid 95332] [client 14.225.17.146:55511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEQwAAAdk"], referer: http://getgarrison.com/2019
[Mon Jul 20 07:18:15.015541 2026] [security2:error] [pid 94831:tid 95063] [client 202.141.11.99:22143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gF406NaEKF1g_MW2yCwAAAGY"]
[Mon Jul 20 07:18:15.015672 2026] [security2:error] [pid 94831:tid 95063] [client 202.141.11.99:22143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gF406NaEKF1g_MW2yCwAAAGY"]
[Mon Jul 20 07:18:15.035136 2026] [security2:error] [pid 94831:tid 95034] [client 103.144.65.217:52876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gF406NaEKF1g_MW2yDAAAAEk"]
[Mon Jul 20 07:18:15.035279 2026] [security2:error] [pid 94831:tid 95034] [client 103.144.65.217:52876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gF406NaEKF1g_MW2yDAAAAEk"]
[Mon Jul 20 07:18:15.040710 2026] [security2:error] [pid 95126:tid 95135] [remote 162.19.86.63:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gFwpx5ks9joCJTKXETAABoQY"]
[Mon Jul 20 07:18:15.082711 2026] [security2:error] [pid 95126:tid 95323] [client 77.110.127.138:62892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gFwpx5ks9joCJTKXEUAAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:15.166061 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXEAgAB03A"]
[Mon Jul 20 07:18:15.166171 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEFgAB0wk"]
[Mon Jul 20 07:18:15.166295 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEEAAB01g"]
[Mon Jul 20 07:18:15.167239 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXEAAAB01c"]
[Mon Jul 20 07:18:15.174656 2026] [core:error] [pid 95126:tid 95298] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:15.174682 2026] [core:error] [pid 95126:tid 95298] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:15.176819 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEEQAB0w8"]
[Mon Jul 20 07:18:15.188337 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXECQABryg"], referer: https://guidehunting.com/.well-known/jwks.json
[Mon Jul 20 07:18:15.188444 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXEDQABrxM"], referer: https://guidehunting.com/api/v2/config
[Mon Jul 20 07:18:15.263025 2026] [security2:error] [pid 94831:tid 95022] [client 57.141.18.77:47930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gFY06NaEKF1g_MW2x6AAAPSA"]
[Mon Jul 20 07:18:15.283310 2026] [security2:error] [pid 95126:tid 95211] [remote 162.19.86.63:36450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gFwpx5ks9joCJTKXEYgACAlI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:18:15.314291 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:62894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gFwpx5ks9joCJTKXEYwAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:15.396956 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEPwAB034"]
[Mon Jul 20 07:18:15.397877 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEQAAB0wg"]
[Mon Jul 20 07:18:15.415350 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEOgABrzM"], referer: https://guidehunting.com/api/v1/config
[Mon Jul 20 07:18:15.415615 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEOQABrwE"], referer: https://guidehunting.com/api/env
[Mon Jul 20 07:18:15.415947 2026] [security2:error] [pid 95126:tid 95326] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFgpx5ks9joCJTKXEQQAB00Q"]
[Mon Jul 20 07:18:15.545449 2026] [security2:error] [pid 95126:tid 95333] [client 14.225.17.146:50751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD-AAAAdo"], referer: http://grecruit.online/2019
[Mon Jul 20 07:18:15.580979 2026] [security2:error] [pid 95126:tid 95305] [client 14.225.17.146:50755] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4gFQpx5ks9joCJTKXD9wAAAb4"], referer: http://tacticaltreeoperations.com/2019
[Mon Jul 20 07:18:15.708576 2026] [security2:error] [pid 94831:tid 95064] [client 77.110.127.138:62895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4gF406NaEKF1g_MW2yGgAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:15.900928 2026] [security2:error] [pid 95126:tid 95363] [client 14.225.17.146:56343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEgAAAAfg"], referer: http://jvcmotorsports.com/2019
[Mon Jul 20 07:18:16.173923 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEeQABsDI"], referer: https://guidehunting.com/api/v2/settings
[Mon Jul 20 07:18:16.176189 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEfAABsDQ"], referer: https://guidehunting.com/manifest.webmanifest
[Mon Jul 20 07:18:16.179126 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEewABsDs"], referer: https://guidehunting.com/openapi.json
[Mon Jul 20 07:18:16.180726 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEeAABsDk"], referer: https://guidehunting.com/runtime-config.js
[Mon Jul 20 07:18:16.190741 2026] [security2:error] [pid 94831:tid 95021] [client 77.110.127.138:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gGI06NaEKF1g_MW2yLAAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:16.201372 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEegABsCQ"], referer: https://guidehunting.com/api/openapi.json
[Mon Jul 20 07:18:16.210023 2026] [security2:error] [pid 95126:tid 95313] [client 117.211.236.168:60329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gGApx5ks9joCJTKXEnQAAAcY"]
[Mon Jul 20 07:18:16.210118 2026] [security2:error] [pid 95126:tid 95313] [client 117.211.236.168:60329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gGApx5ks9joCJTKXEnQAAAcY"]
[Mon Jul 20 07:18:16.290775 2026] [security2:error] [pid 95126:tid 95373] [client 34.147.91.161:32769] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gGApx5ks9joCJTKXEpQAAAgI"]
[Mon Jul 20 07:18:16.290881 2026] [security2:error] [pid 95126:tid 95373] [client 34.147.91.161:32769] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpanel.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gGApx5ks9joCJTKXEpQAAAgI"]
[Mon Jul 20 07:18:16.295500 2026] [security2:error] [pid 95126:tid 95258] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEhwABjzU"]
[Mon Jul 20 07:18:16.300600 2026] [security2:error] [pid 95126:tid 95258] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEhQABj1Y"]
[Mon Jul 20 07:18:16.321422 2026] [security2:error] [pid 95126:tid 95185] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/__env.js"] [unique_id "al4gGApx5ks9joCJTKXEqAAB4zg"]
[Mon Jul 20 07:18:16.331345 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEigABsCU"], referer: https://guidehunting.com/api/health
[Mon Jul 20 07:18:16.332655 2026] [security2:error] [pid 95126:tid 95349] [client 165.227.239.47:62427] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.familiaconsciente.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4gGApx5ks9joCJTKXEpgAAAeo"]
[Mon Jul 20 07:18:16.352515 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEiQABsCw"], referer: https://guidehunting.com/app-config.json
[Mon Jul 20 07:18:16.352657 2026] [security2:error] [pid 95126:tid 95291] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEiwABsFA"], referer: https://guidehunting.com/api/account
[Mon Jul 20 07:18:16.353022 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGApx5ks9joCJTKXErAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:16.353111 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:62898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGApx5ks9joCJTKXErAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:16.518090 2026] [security2:error] [pid 95126:tid 95352] [client 77.110.127.138:62899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGApx5ks9joCJTKXEswAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:16.518219 2026] [security2:error] [pid 95126:tid 95352] [client 77.110.127.138:62899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGApx5ks9joCJTKXEswAAAe0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:16.602460 2026] [security2:error] [pid 95126:tid 95377] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEqgACBlo"]
[Mon Jul 20 07:18:16.620333 2026] [security2:error] [pid 95126:tid 95234] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/api/graphql"] [unique_id "al4gGApx5ks9joCJTKXEtgABnGk"]
[Mon Jul 20 07:18:16.707659 2026] [security2:error] [pid 95126:tid 95238] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "guidehunting.com"] [uri "/service-worker.js"] [unique_id "al4gGApx5ks9joCJTKXExQACAW0"]
[Mon Jul 20 07:18:16.833432 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gGApx5ks9joCJTKXE0wAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:17.011966 2026] [security2:error] [pid 94831:tid 94968] [client 14.225.17.146:54059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4gGI06NaEKF1g_MW2yNwAAAAc"]
[Mon Jul 20 07:18:17.044515 2026] [security2:error] [pid 95126:tid 95232] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/phpinfo.php"] [unique_id "al4gGQpx5ks9joCJTKXE4AACAWc"]
[Mon Jul 20 07:18:17.074225 2026] [security2:error] [pid 95126:tid 95171] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gGQpx5ks9joCJTKXE4gABtSo"]
[Mon Jul 20 07:18:17.074358 2026] [security2:error] [pid 95126:tid 95296] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gGQpx5ks9joCJTKXE4gABtSo"]
[Mon Jul 20 07:18:17.186768 2026] [security2:error] [pid 95126:tid 95276] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEugABoWY"], referer: https://guidehunting.com/swagger.json
[Mon Jul 20 07:18:17.187709 2026] [security2:error] [pid 94831:tid 95077] [client 14.225.17.146:54116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4gGI06NaEKF1g_MW2yJAAAAHQ"], referer: http://ancestralidadytrance.space/2019
[Mon Jul 20 07:18:17.188168 2026] [security2:error] [pid 95126:tid 95365] [client 57.141.18.71:55582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gFwpx5ks9joCJTKXEXgAB-j0"]
[Mon Jul 20 07:18:17.190662 2026] [security2:error] [pid 95126:tid 95276] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEuQABoVw"], referer: https://guidehunting.com/health
[Mon Jul 20 07:18:17.220428 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXExAACAT4"]
[Mon Jul 20 07:18:17.223043 2026] [security2:error] [pid 95126:tid 95274] [client 154.208.48.130:51835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gGQpx5ks9joCJTKXE6gAAAZ8"]
[Mon Jul 20 07:18:17.224406 2026] [security2:error] [pid 95126:tid 95274] [client 154.208.48.130:51835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gGQpx5ks9joCJTKXE6gAAAZ8"]
[Mon Jul 20 07:18:17.229447 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEwwACAUw"]
[Mon Jul 20 07:18:17.239784 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEwgACARQ"]
[Mon Jul 20 07:18:17.267957 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEywACAU0"]
[Mon Jul 20 07:18:17.268092 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEzQACAV4"]
[Mon Jul 20 07:18:17.269170 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEzAACAVU"]
[Mon Jul 20 07:18:17.303551 2026] [security2:error] [pid 94831:tid 95036] [client 180.153.197.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4gGY06NaEKF1g_MW2yPQAASy4"], referer: https://www.aleishapenny.ca/listing/page/614?paged=614&view=map
[Mon Jul 20 07:18:17.322836 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXE0QACAWE"]
[Mon Jul 20 07:18:17.382818 2026] [security2:error] [pid 95126:tid 95372] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXE3wACAVk"]
[Mon Jul 20 07:18:17.400240 2026] [security2:error] [pid 95126:tid 95276] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXE3QABoQM"], referer: https://guidehunting.com/api/v1/env
[Mon Jul 20 07:18:17.414145 2026] [security2:error] [pid 94831:tid 95009] [client 77.110.127.138:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gGY06NaEKF1g_MW2yRAAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:17.502960 2026] [core:error] [pid 95126:tid 95360] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:17.502988 2026] [core:error] [pid 95126:tid 95360] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:17.629279 2026] [security2:error] [pid 95126:tid 95275] [client 143.44.185.218:57570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gGQpx5ks9joCJTKXFBAAAAaA"]
[Mon Jul 20 07:18:17.629376 2026] [security2:error] [pid 95126:tid 95275] [client 143.44.185.218:57570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gGQpx5ks9joCJTKXFBAAAAaA"]
[Mon Jul 20 07:18:17.639684 2026] [security2:error] [pid 94831:tid 94881] [remote 100.42.189.89:52936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4gGY06NaEKF1g_MW2ySgAAZjE"]
[Mon Jul 20 07:18:17.669089 2026] [security2:error] [pid 95126:tid 95256] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/info.php"] [unique_id "al4gGQpx5ks9joCJTKXFDAABkH8"]
[Mon Jul 20 07:18:17.669613 2026] [security2:error] [pid 95126:tid 95236] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "guidehunting.com"] [uri "/pi.php"] [unique_id "al4gGQpx5ks9joCJTKXFDQABpGs"]
[Mon Jul 20 07:18:17.669725 2026] [security2:error] [pid 95126:tid 95279] [client 34.178.33.65:47978] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "guidehunting.com"] [uri "/pi.php"] [unique_id "al4gGQpx5ks9joCJTKXFDQABpGs"]
[Mon Jul 20 07:18:17.694218 2026] [security2:error] [pid 95126:tid 95286] [client 77.110.127.138:62910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gGQpx5ks9joCJTKXFEAAAAas"]
[Mon Jul 20 07:18:17.761521 2026] [security2:error] [pid 95126:tid 95129] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/test.php"] [unique_id "al4gGQpx5ks9joCJTKXFGwAB1gA"]
[Mon Jul 20 07:18:17.828303 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:62912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1 OR 465. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 465 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gGY06NaEKF1g_MW2yUwAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:17.830042 2026] [security2:error] [pid 94831:tid 94882] [remote 100.42.189.89:52936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4gGY06NaEKF1g_MW2yVAAANDI"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:18:17.883546 2026] [security2:error] [pid 95126:tid 95142] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/i.php"] [unique_id "al4gGQpx5ks9joCJTKXFJQAB7Q0"]
[Mon Jul 20 07:18:18.059670 2026] [security2:error] [pid 95126:tid 95333] [client 14.225.17.146:55561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4gGApx5ks9joCJTKXEzgAAAdo"], referer: http://wathenbartlett.co.uk/2019
[Mon Jul 20 07:18:18.122830 2026] [security2:error] [pid 95126:tid 95217] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/app_dev.php"] [unique_id "al4gGgpx5ks9joCJTKXFMwABrFg"]
[Mon Jul 20 07:18:18.143443 2026] [security2:error] [pid 95126:tid 95325] [client 77.110.127.138:62917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gGgpx5ks9joCJTKXFLwAAAdI"]
[Mon Jul 20 07:18:18.150544 2026] [core:error] [pid 95126:tid 95378] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:18.150564 2026] [core:error] [pid 95126:tid 95378] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:18.222077 2026] [security2:error] [pid 95126:tid 95148] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/app_dev.php/_profiler"] [unique_id "al4gGgpx5ks9joCJTKXFOQABrBM"]
[Mon Jul 20 07:18:18.238070 2026] [security2:error] [pid 94831:tid 95041] [client 34.141.215.197:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.tipcruncher.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gGo06NaEKF1g_MW2yYgAAAFA"]
[Mon Jul 20 07:18:18.238219 2026] [security2:error] [pid 94831:tid 95041] [client 34.141.215.197:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.tipcruncher.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gGo06NaEKF1g_MW2yYgAAAFA"]
[Mon Jul 20 07:18:18.240506 2026] [security2:error] [pid 95126:tid 95334] [client 88.241.67.160:55081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gGgpx5ks9joCJTKXFPAAAAds"]
[Mon Jul 20 07:18:18.240955 2026] [security2:error] [pid 95126:tid 95334] [client 88.241.67.160:55081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gGgpx5ks9joCJTKXFPAAAAds"]
[Mon Jul 20 07:18:18.246234 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFHQABoiM"], referer: https://guidehunting.com/graphql
[Mon Jul 20 07:18:18.246484 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFIwABomg"], referer: https://guidehunting.com/actuator/mappings
[Mon Jul 20 07:18:18.246951 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFHgABohk"], referer: https://guidehunting.com/ngsw.json
[Mon Jul 20 07:18:18.247163 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFIQABoic"], referer: https://guidehunting.com/actuator/configprops
[Mon Jul 20 07:18:18.250094 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFHwABokc"], referer: https://guidehunting.com/actuator
[Mon Jul 20 07:18:18.250258 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFIAABojY"], referer: https://guidehunting.com/v1/graphql
[Mon Jul 20 07:18:18.250676 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFJAABoks"], referer: https://guidehunting.com/sw.js
[Mon Jul 20 07:18:18.252683 2026] [security2:error] [pid 95126:tid 95277] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFIgABohg"], referer: https://guidehunting.com/graphql/console
[Mon Jul 20 07:18:18.386871 2026] [security2:error] [pid 95126:tid 95287] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFNAABrFc"]
[Mon Jul 20 07:18:18.386985 2026] [security2:error] [pid 95126:tid 95287] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFNQABrHg"]
[Mon Jul 20 07:18:18.476818 2026] [security2:error] [pid 94831:tid 94891] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gGo06NaEKF1g_MW2yZgAAejs"]
[Mon Jul 20 07:18:18.476974 2026] [security2:error] [pid 94831:tid 95083] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gGo06NaEKF1g_MW2yZgAAejs"]
[Mon Jul 20 07:18:18.547574 2026] [security2:error] [pid 94831:tid 95040] [client 103.176.215.66:52654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gGo06NaEKF1g_MW2yaAAAAE8"]
[Mon Jul 20 07:18:18.547706 2026] [security2:error] [pid 94831:tid 95040] [client 103.176.215.66:52654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gGo06NaEKF1g_MW2yaAAAAE8"]
[Mon Jul 20 07:18:18.650551 2026] [security2:error] [pid 95126:tid 95150] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/server-info"] [unique_id "al4gGgpx5ks9joCJTKXFWAAB4RU"]
[Mon Jul 20 07:18:18.703246 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFSgAB4R0"]
[Mon Jul 20 07:18:18.876981 2026] [lsapi:warn] [pid 94831:tid 94879] [remote 8.234.173.158:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim-com.aasgroup.online/
[Mon Jul 20 07:18:18.894121 2026] [security2:error] [pid 94831:tid 95046] [client 104.234.53.59:31269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gGo06NaEKF1g_MW2ybQAAAFU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:18.959264 2026] [access_compat:error] [pid 95126:tid 95170] [remote 34.178.33.65:47978] AH01797: client denied by server configuration: /home4/guidehun/public_html/server-status
[Mon Jul 20 07:18:19.059986 2026] [security2:error] [pid 95126:tid 95346] [client 14.225.17.146:54602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFegAAAec"], referer: https://wathenbartlett.co.uk/2019
[Mon Jul 20 07:18:19.165421 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:62921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4gG406NaEKF1g_MW2ycwAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:19.177055 2026] [security2:error] [pid 95126:tid 95362] [client 157.20.138.62:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gGwpx5ks9joCJTKXFhAAAAfc"]
[Mon Jul 20 07:18:19.177217 2026] [security2:error] [pid 95126:tid 95362] [client 157.20.138.62:64041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gGwpx5ks9joCJTKXFhAAAAfc"]
[Mon Jul 20 07:18:19.230868 2026] [security2:error] [pid 95126:tid 95343] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFVQAB5AE"], referer: https://guidehunting.com/_profiler/latest
[Mon Jul 20 07:18:19.231176 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFXQAB4RY"]
[Mon Jul 20 07:18:19.231687 2026] [security2:error] [pid 95126:tid 95343] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFVgAB5EQ"], referer: https://guidehunting.com/_profiler/open
[Mon Jul 20 07:18:19.231847 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFWgAB4VM"]
[Mon Jul 20 07:18:19.232191 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFVwAB4Rc"]
[Mon Jul 20 07:18:19.232272 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFWwAB4X0"]
[Mon Jul 20 07:18:19.237628 2026] [security2:error] [pid 95126:tid 95379] [client 57.141.18.19:63950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXE_AACCFQ"]
[Mon Jul 20 07:18:19.255490 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFWQAB4Rs"]
[Mon Jul 20 07:18:19.286095 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFXAAB4Xk"]
[Mon Jul 20 07:18:19.318672 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:62923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGwpx5ks9joCJTKXFkAAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:19.318798 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:62923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGwpx5ks9joCJTKXFkAAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:19.365471 2026] [security2:error] [pid 95126:tid 95261] [client 57.141.18.82:52980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gGQpx5ks9joCJTKXFBwABkl8"]
[Mon Jul 20 07:18:19.393382 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGgpx5ks9joCJTKXFbAAB4R4"]
[Mon Jul 20 07:18:19.467978 2026] [security2:error] [pid 95126:tid 95311] [client 77.110.127.138:62925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGwpx5ks9joCJTKXFnQAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:19.468065 2026] [security2:error] [pid 95126:tid 95311] [client 77.110.127.138:62925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gGwpx5ks9joCJTKXFnQAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:19.528851 2026] [security2:error] [pid 95126:tid 95267] [client 14.225.17.146:53777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFmQAAAZg"], referer: http://ghivs.com/2019
[Mon Jul 20 07:18:19.533055 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFiAAB4Tw"]
[Mon Jul 20 07:18:19.533207 2026] [security2:error] [pid 95126:tid 95340] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFiQAB4S4"]
[Mon Jul 20 07:18:19.554521 2026] [security2:error] [pid 95126:tid 95278] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFigABozU"], referer: https://guidehunting.com/_ignition/health-check
[Mon Jul 20 07:18:19.664997 2026] [security2:error] [pid 94831:tid 94902] [remote 57.141.18.99:50364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2931408"] [unique_id "al4gG406NaEKF1g_MW2ygwAABUY"]
[Mon Jul 20 07:18:19.864644 2026] [security2:error] [pid 95126:tid 95279] [client 49.47.218.174:64670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gGwpx5ks9joCJTKXFqAAAAaQ"]
[Mon Jul 20 07:18:19.864815 2026] [security2:error] [pid 95126:tid 95279] [client 49.47.218.174:64670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gGwpx5ks9joCJTKXFqAAAAaQ"]
[Mon Jul 20 07:18:19.915663 2026] [security2:error] [pid 95126:tid 95136] [remote 34.178.33.65:47978] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "guidehunting.com"] [uri "/.env"] [unique_id "al4gGwpx5ks9joCJTKXFtQABtgc"]
[Mon Jul 20 07:18:20.192415 2026] [core:error] [pid 94831:tid 94965] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:20.192448 2026] [core:error] [pid 94831:tid 94965] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:20.221419 2026] [security2:error] [pid 95126:tid 95265] [client 65.109.162.42:59428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXFwQAAAZY"]
[Mon Jul 20 07:18:20.234131 2026] [security2:error] [pid 95126:tid 95385] [client 77.110.127.138:62928] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1) OR 464. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 464 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gHApx5ks9joCJTKXFzQAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:20.295055 2026] [security2:error] [pid 95126:tid 95375] [client 191.202.66.27:50152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gHApx5ks9joCJTKXF0gAAAgQ"]
[Mon Jul 20 07:18:20.295232 2026] [security2:error] [pid 95126:tid 95375] [client 191.202.66.27:50152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gHApx5ks9joCJTKXF0gAAAgQ"]
[Mon Jul 20 07:18:20.446467 2026] [security2:error] [pid 95126:tid 95308] [client 187.16.64.216:55191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gHApx5ks9joCJTKXF4gAAAcE"]
[Mon Jul 20 07:18:20.446610 2026] [security2:error] [pid 95126:tid 95308] [client 187.16.64.216:55191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gHApx5ks9joCJTKXF4gAAAcE"]
[Mon Jul 20 07:18:20.484947 2026] [security2:error] [pid 95126:tid 95285] [client 14.225.17.146:55156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXF1wAAAao"], referer: http://xp-design.co/2019
[Mon Jul 20 07:18:20.507519 2026] [security2:error] [pid 95126:tid 95336] [client 14.225.17.146:54370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFgAAAAd0"], referer: http://balticsteelmgmt.com/2019
[Mon Jul 20 07:18:20.550189 2026] [security2:error] [pid 95126:tid 95356] [client 50.116.65.227:13038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXF2AAAAfE"]
[Mon Jul 20 07:18:20.695198 2026] [security2:error] [pid 95126:tid 95274] [client 158.173.166.181:54611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gHApx5ks9joCJTKXF8QAAAZ8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:18:20.753505 2026] [security2:error] [pid 95126:tid 95339] [client 50.116.65.227:13054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXF6gAAAeA"]
[Mon Jul 20 07:18:20.849172 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:62931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gHI06NaEKF1g_MW2ynwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:20.854086 2026] [autoindex:error] [pid 95126:tid 95155] [remote 34.75.194.172:62486] AH01276: Cannot serve directory /home2/cssgdzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.css.gdz.mybluehost.me
[Mon Jul 20 07:18:21.163963 2026] [security2:error] [pid 95126:tid 95176] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFsQABti8"]
[Mon Jul 20 07:18:21.167086 2026] [security2:error] [pid 95126:tid 95234] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFqgAB_Wk"], referer: https://guidehunting.com/_debugbar/open
[Mon Jul 20 07:18:21.169695 2026] [security2:error] [pid 95126:tid 95199] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFqwAB_UY"], referer: https://guidehunting.com/elmah.axd
[Mon Jul 20 07:18:21.169716 2026] [security2:error] [pid 95126:tid 95157] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFrQAB_Rw"], referer: https://guidehunting.com/.aws/credentials
[Mon Jul 20 07:18:21.170146 2026] [security2:error] [pid 95126:tid 95219] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFqQAB_Vo"], referer: https://guidehunting.com/__debug__/
[Mon Jul 20 07:18:21.172261 2026] [security2:error] [pid 95126:tid 95238] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFrgAB_W0"], referer: https://guidehunting.com/trace.axd
[Mon Jul 20 07:18:21.175026 2026] [security2:error] [pid 95126:tid 95203] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFuAABtko"]
[Mon Jul 20 07:18:21.175034 2026] [security2:error] [pid 95126:tid 95133] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFtgABtgQ"]
[Mon Jul 20 07:18:21.175043 2026] [security2:error] [pid 95126:tid 95232] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFtwABtmc"]
[Mon Jul 20 07:18:21.176560 2026] [security2:error] [pid 95126:tid 95230] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFsgABtmU"]
[Mon Jul 20 07:18:21.179051 2026] [security2:error] [pid 95126:tid 95163] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFugABtiI"]
[Mon Jul 20 07:18:21.193138 2026] [security2:error] [pid 95126:tid 95171] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFuQABtio"]
[Mon Jul 20 07:18:21.195134 2026] [security2:error] [pid 95126:tid 95253] [remote 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFvAABtnw"]
[Mon Jul 20 07:18:21.211609 2026] [security2:error] [pid 95126:tid 95162] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gGwpx5ks9joCJTKXFrAAB_SE"], referer: https://guidehunting.com/nginx_status
[Mon Jul 20 07:18:21.337196 2026] [security2:error] [pid 95126:tid 95190] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXFvwAB_T0"], referer: https://guidehunting.com/.aws/config
[Mon Jul 20 07:18:21.337623 2026] [security2:error] [pid 95126:tid 95227] [remote 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXFwAAB_WI"], referer: https://guidehunting.com/.git/config
[Mon Jul 20 07:18:21.390311 2026] [security2:error] [pid 95126:tid 95277] [client 14.225.17.146:55412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXFygAAAaI"], referer: http://effingweirdmuseums.com/2019
[Mon Jul 20 07:18:21.419822 2026] [security2:error] [pid 95126:tid 95267] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXF5QABmGE"]
[Mon Jul 20 07:18:21.598159 2026] [security2:error] [pid 94831:tid 95079] [client 57.141.18.34:61898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gG406NaEKF1g_MW2yggAAdkg"]
[Mon Jul 20 07:18:21.604328 2026] [security2:error] [pid 95126:tid 95340] [client 34.34.21.42:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webmail.joulecommunications.com"] [uri "/"] [unique_id "al4gHQpx5ks9joCJTKXGNAAAAeE"]
[Mon Jul 20 07:18:21.604402 2026] [security2:error] [pid 95126:tid 95340] [client 34.34.21.42:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webmail.joulecommunications.com"] [uri "/"] [unique_id "al4gHQpx5ks9joCJTKXGNAAAAeE"]
[Mon Jul 20 07:18:21.679604 2026] [security2:error] [pid 95126:tid 95332] [client 65.109.162.42:59432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4gHQpx5ks9joCJTKXGHgAAAdg"]
[Mon Jul 20 07:18:21.777814 2026] [security2:error] [pid 95126:tid 95200] [remote 20.173.88.122:36740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.com"] [uri "/wp-login.php"] [unique_id "al4gHQpx5ks9joCJTKXGRwABxUc"]
[Mon Jul 20 07:18:21.872205 2026] [security2:error] [pid 95126:tid 95204] [remote 188.166.241.141:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gHQpx5ks9joCJTKXGSwAB50s"]
[Mon Jul 20 07:18:21.876762 2026] [security2:error] [pid 95126:tid 95153] [remote 81.173.115.7:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gHQpx5ks9joCJTKXGTAABnBg"]
[Mon Jul 20 07:18:21.941574 2026] [security2:error] [pid 95126:tid 95335] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gHQpx5ks9joCJTKXGOQAB3CM"], referer: https://guidehunting.com/ssilko3
[Mon Jul 20 07:18:21.995690 2026] [security2:error] [pid 94831:tid 94925] [remote 57.141.18.92:61074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6058180"] [unique_id "al4gHY06NaEKF1g_MW2ytAAAFl0"]
[Mon Jul 20 07:18:22.005214 2026] [security2:error] [pid 95126:tid 95363] [client 50.116.65.227:13090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gHgpx5ks9joCJTKXGWQAAAfg"]
[Mon Jul 20 07:18:22.014878 2026] [security2:error] [pid 94831:tid 95065] [client 50.116.65.227:13098] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gHo06NaEKF1g_MW2ytQAAAGg"]
[Mon Jul 20 07:18:22.027709 2026] [security2:error] [pid 95126:tid 95341] [client 104.234.53.74:21575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gHgpx5ks9joCJTKXGWwAAAeI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:22.038215 2026] [security2:error] [pid 94831:tid 95013] [client 57.141.18.79:40666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gG406NaEKF1g_MW2yiAAANEw"]
[Mon Jul 20 07:18:22.078164 2026] [security2:error] [pid 95126:tid 95160] [remote 81.173.115.7:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gHgpx5ks9joCJTKXGYAACCB8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:18:22.088759 2026] [security2:error] [pid 94831:tid 95003] [client 154.192.123.127:18014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gHo06NaEKF1g_MW2yuQAAACo"]
[Mon Jul 20 07:18:22.088898 2026] [security2:error] [pid 94831:tid 95003] [client 154.192.123.127:18014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gHo06NaEKF1g_MW2yuQAAACo"]
[Mon Jul 20 07:18:22.135592 2026] [security2:error] [pid 95126:tid 95150] [remote 20.173.88.122:36740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.com"] [uri "/wp-login.php"] [unique_id "al4gHgpx5ks9joCJTKXGbAAB5RU"], referer: https://fkconstructionfunding.com/wp-login.php
[Mon Jul 20 07:18:22.151102 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:62962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHgpx5ks9joCJTKXGbQAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.151228 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:62962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHgpx5ks9joCJTKXGbQAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.202627 2026] [security2:error] [pid 94831:tid 95027] [client 77.110.127.138:62926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHo06NaEKF1g_MW2yugAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.202724 2026] [security2:error] [pid 94831:tid 95027] [client 77.110.127.138:62926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHo06NaEKF1g_MW2yugAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.203421 2026] [fcgid:warn] [pid 95126:tid 95291] (70014)End of file found: [client 144.172.114.51:46986] mod_fcgid: can't get data from http client
[Mon Jul 20 07:18:22.207975 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:62928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHgpx5ks9joCJTKXGdAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.208099 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:62928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHgpx5ks9joCJTKXGdAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.247950 2026] [security2:error] [pid 95126:tid 95211] [remote 188.166.241.141:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gHgpx5ks9joCJTKXGeAABplI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:18:22.345873 2026] [security2:error] [pid 95126:tid 95372] [client 14.225.17.146:55173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4gHgpx5ks9joCJTKXGdgAAAgE"], referer: https://effingweirdmuseums.com/2019
[Mon Jul 20 07:18:22.360420 2026] [security2:error] [pid 94831:tid 94966] [client 77.110.127.138:62966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHo06NaEKF1g_MW2ywAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.360514 2026] [security2:error] [pid 94831:tid 94966] [client 77.110.127.138:62966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHo06NaEKF1g_MW2ywAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.383680 2026] [security2:error] [pid 95126:tid 95167] [remote 47.86.33.52:18758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gHgpx5ks9joCJTKXGgAAB9CY"]
[Mon Jul 20 07:18:22.453483 2026] [security2:error] [pid 95126:tid 95314] [client 57.141.18.95:34196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gHApx5ks9joCJTKXF2gABx14"]
[Mon Jul 20 07:18:22.514739 2026] [security2:error] [pid 95126:tid 95283] [client 77.110.127.138:62968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHgpx5ks9joCJTKXGigAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.514850 2026] [security2:error] [pid 95126:tid 95283] [client 77.110.127.138:62968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHgpx5ks9joCJTKXGigAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:22.631119 2026] [core:error] [pid 94831:tid 95072] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:22.631139 2026] [core:error] [pid 94831:tid 95072] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:22.739386 2026] [lsapi:warn] [pid 95126:tid 95360] [client 14.225.17.146:55152] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2019
[Mon Jul 20 07:18:22.739406 2026] [lsapi:warn] [pid 95126:tid 95360] [client 14.225.17.146:55152] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2019
[Mon Jul 20 07:18:22.744501 2026] [security2:error] [pid 95126:tid 95339] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gHgpx5ks9joCJTKXGhQAB4D8"]
[Mon Jul 20 07:18:22.856494 2026] [core:error] [pid 95126:tid 95273] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:22.856513 2026] [core:error] [pid 95126:tid 95273] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:23.030214 2026] [security2:error] [pid 95126:tid 95152] [remote 47.86.33.52:18758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gHwpx5ks9joCJTKXGoAACBhc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:18:23.089388 2026] [security2:error] [pid 95126:tid 95313] [client 57.141.18.14:64424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gHQpx5ks9joCJTKXGCQABxgA"]
[Mon Jul 20 07:18:23.108794 2026] [security2:error] [pid 95126:tid 95378] [client 14.225.17.146:56201] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4gHgpx5ks9joCJTKXGXQAAAgc"], referer: http://ravmike.com/2019
[Mon Jul 20 07:18:23.220563 2026] [security2:error] [pid 95126:tid 95290] [client 57.141.18.79:40668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gHQpx5ks9joCJTKXGEQABrwo"]
[Mon Jul 20 07:18:23.245419 2026] [lsapi:warn] [pid 95126:tid 95330] [client 50.116.65.227:13108] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:18:23.245446 2026] [lsapi:warn] [pid 95126:tid 95330] [client 50.116.65.227:13108] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:18:23.262014 2026] [security2:error] [pid 95126:tid 95360] [client 14.225.17.146:55152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4gHgpx5ks9joCJTKXGdQAAAfU"], referer: http://oswegooperatheater.com/2019
[Mon Jul 20 07:18:23.374656 2026] [security2:error] [pid 95126:tid 95384] [client 127.0.0.1:57720] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4gHwpx5ks9joCJTKXGugAAAg0"], referer: https://www.bing.com/search?q=gsip8l
[Mon Jul 20 07:18:23.517547 2026] [security2:error] [pid 94831:tid 95028] [client 201.27.111.74:55828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gH406NaEKF1g_MW2y5wAAAEM"]
[Mon Jul 20 07:18:23.517682 2026] [security2:error] [pid 94831:tid 95028] [client 201.27.111.74:55828] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gH406NaEKF1g_MW2y5wAAAEM"]
[Mon Jul 20 07:18:23.759415 2026] [security2:error] [pid 95126:tid 95246] [remote 72.167.132.114:35184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gHwpx5ks9joCJTKXG0wABnnU"]
[Mon Jul 20 07:18:23.761516 2026] [security2:error] [pid 94831:tid 95046] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4gH406NaEKF1g_MW2y6AAAAFU"]
[Mon Jul 20 07:18:23.818378 2026] [security2:error] [pid 95126:tid 95345] [client 77.110.127.138:62977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHwpx5ks9joCJTKXG2AAAAeY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:23.818478 2026] [security2:error] [pid 95126:tid 95345] [client 77.110.127.138:62977] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHwpx5ks9joCJTKXG2AAAAeY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:23.874599 2026] [security2:error] [pid 94831:tid 95070] [client 77.110.127.138:62912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gH406NaEKF1g_MW2y-wAAAG0"]
[Mon Jul 20 07:18:23.874734 2026] [security2:error] [pid 94831:tid 95070] [client 77.110.127.138:62912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gH406NaEKF1g_MW2y-wAAAG0"]
[Mon Jul 20 07:18:23.896743 2026] [security2:error] [pid 95126:tid 95271] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gHwpx5ks9joCJTKXGzgABnEU"], referer: https://guidehunting.com/ssilko4
[Mon Jul 20 07:18:23.928696 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:62918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHwpx5ks9joCJTKXG3AAAAZI"]
[Mon Jul 20 07:18:23.928871 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:62918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gHwpx5ks9joCJTKXG3AAAAZI"]
[Mon Jul 20 07:18:24.068820 2026] [security2:error] [pid 95126:tid 95334] [client 14.225.17.146:54454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4gHwpx5ks9joCJTKXG3gAAAds"], referer: https://ravmike.com/2019
[Mon Jul 20 07:18:24.163745 2026] [security2:error] [pid 94831:tid 94991] [client 103.168.67.159:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/assets/config.json%00.php"] [unique_id "al4gII06NaEKF1g_MW2zAwAAAB4"], referer: https://news.ycombinator.com/
[Mon Jul 20 07:18:24.185567 2026] [security2:error] [pid 95126:tid 95205] [remote 72.167.132.114:35184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gIApx5ks9joCJTKXG6QACDkw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:18:24.271743 2026] [lsapi:warn] [pid 94831:tid 95013] [client 14.225.17.146:55238] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2019
[Mon Jul 20 07:18:24.271773 2026] [lsapi:warn] [pid 94831:tid 95013] [client 14.225.17.146:55238] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2019
[Mon Jul 20 07:18:24.274949 2026] [security2:error] [pid 94831:tid 94992] [client 77.110.127.138:62904] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1-1)) OR 673. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 673 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gII06NaEKF1g_MW2zCQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:24.322556 2026] [security2:error] [pid 94831:tid 95013] [client 14.225.17.146:55238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4gII06NaEKF1g_MW2zCAAAADQ"], referer: https://oswegooperatheater.com/2019
[Mon Jul 20 07:18:24.569415 2026] [fcgid:warn] [pid 95126:tid 95322] (70014)End of file found: [client 66.132.224.237:36252] mod_fcgid: can't get data from http client
[Mon Jul 20 07:18:24.702678 2026] [security2:error] [pid 95126:tid 95345] [client 77.110.127.138:62958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIApx5ks9joCJTKXHCwAAAeY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:24.739874 2026] [security2:error] [pid 95126:tid 95263] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gIApx5ks9joCJTKXG-gABlHs"]
[Mon Jul 20 07:18:24.742408 2026] [security2:error] [pid 95126:tid 95326] [client 49.37.242.14:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gIApx5ks9joCJTKXHDQAAAdM"]
[Mon Jul 20 07:18:24.742546 2026] [security2:error] [pid 95126:tid 95326] [client 49.37.242.14:52027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gIApx5ks9joCJTKXHDQAAAdM"]
[Mon Jul 20 07:18:24.859491 2026] [security2:error] [pid 94831:tid 94963] [client 40.77.167.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bandsir.com"] [uri "/index.php"] [unique_id "al4gII06NaEKF1g_MW2zFwAAAAI"]
[Mon Jul 20 07:18:24.860409 2026] [security2:error] [pid 94831:tid 94964] [client 57.141.18.37:20156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gHo06NaEKF1g_MW2ywwAAA0Q"]
[Mon Jul 20 07:18:24.932951 2026] [security2:error] [pid 94831:tid 94993] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gII06NaEKF1g_MW2zFQAAACA"]
[Mon Jul 20 07:18:24.943671 2026] [security2:error] [pid 95126:tid 95379] [client 77.110.127.138:62991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIApx5ks9joCJTKXHGQAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.197421 2026] [security2:error] [pid 95126:tid 95339] [client 77.110.127.138:62994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php-1%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4gIQpx5ks9joCJTKXHKwAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.290612 2026] [security2:error] [pid 95126:tid 95336] [client 77.110.127.138:62997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIQpx5ks9joCJTKXHLQAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.332410 2026] [security2:error] [pid 95126:tid 95288] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gIQpx5ks9joCJTKXHGwABrWM"], referer: https://guidehunting.com/ssilko5
[Mon Jul 20 07:18:25.356043 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:62998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIY06NaEKF1g_MW2zKQAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.356142 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:62998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIY06NaEKF1g_MW2zKQAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.406746 2026] [security2:error] [pid 95126:tid 95323] [client 77.110.127.138:62900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIQpx5ks9joCJTKXHOQAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.406877 2026] [security2:error] [pid 95126:tid 95323] [client 77.110.127.138:62900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIQpx5ks9joCJTKXHOQAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.521054 2026] [security2:error] [pid 95126:tid 95332] [client 103.144.65.217:53333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gIQpx5ks9joCJTKXHPwAAAdk"]
[Mon Jul 20 07:18:25.521165 2026] [security2:error] [pid 95126:tid 95332] [client 103.144.65.217:53333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gIQpx5ks9joCJTKXHPwAAAdk"]
[Mon Jul 20 07:18:25.580857 2026] [security2:error] [pid 95126:tid 95326] [client 77.110.127.138:62950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIQpx5ks9joCJTKXHRAAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.632325 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:62911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIQpx5ks9joCJTKXHSQAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.683414 2026] [security2:error] [pid 95126:tid 95283] [client 77.110.127.138:62973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIQpx5ks9joCJTKXHTQAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.710246 2026] [security2:error] [pid 94831:tid 95060] [client 14.225.17.146:56309] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4gII06NaEKF1g_MW2zAgAAAGM"], referer: http://amalia-capital.com/2019
[Mon Jul 20 07:18:25.755146 2026] [security2:error] [pid 94831:tid 95041] [client 77.110.127.138:62974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIY06NaEKF1g_MW2zLwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:25.767863 2026] [security2:error] [pid 94831:tid 95067] [client 14.225.17.146:55273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4gII06NaEKF1g_MW2zEwAAAGo"], referer: http://lutheranphilosopher.com/2019
[Mon Jul 20 07:18:25.922531 2026] [security2:error] [pid 95126:tid 95289] [client 149.118.58.82:53624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-login.php"] [unique_id "al4gIQpx5ks9joCJTKXHVwAAAa4"]
[Mon Jul 20 07:18:26.222346 2026] [security2:error] [pid 95126:tid 95290] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gIQpx5ks9joCJTKXHWgABr3A"]
[Mon Jul 20 07:18:26.429512 2026] [security2:error] [pid 94831:tid 94983] [client 14.225.17.146:55352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4gIY06NaEKF1g_MW2zLQAAABY"]
[Mon Jul 20 07:18:26.503533 2026] [security2:error] [pid 94831:tid 95030] [client 77.110.127.138:62913] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1QxDwbbgt' OR 871. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 871 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gIo06NaEKF1g_MW2zTgAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:26.712639 2026] [security2:error] [pid 94831:tid 94989] [client 14.225.17.146:55244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4gII06NaEKF1g_MW2zGwAAABw"], referer: http://nwcarvingacademy.com/2019
[Mon Jul 20 07:18:26.817444 2026] [security2:error] [pid 95126:tid 95383] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gIgpx5ks9joCJTKXHcgACDBg"], referer: https://guidehunting.com/ssilko6
[Mon Jul 20 07:18:26.983946 2026] [security2:error] [pid 95126:tid 95381] [client 57.141.18.56:29712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gIApx5ks9joCJTKXG7AACCk0"]
[Mon Jul 20 07:18:27.001636 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:62959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpGrF6ZSwp'%3b%20waitfor%20delay%20'0:0:15'%20--%20"] [unique_id "al4gIwpx5ks9joCJTKXHkAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.154972 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gI406NaEKF1g_MW2zWwAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.155116 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gI406NaEKF1g_MW2zWwAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.214375 2026] [security2:error] [pid 95126:tid 95351] [client 57.141.18.48:51988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gIApx5ks9joCJTKXHBwAB7HM"]
[Mon Jul 20 07:18:27.314354 2026] [security2:error] [pid 94831:tid 95034] [client 77.110.127.138:63013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gI406NaEKF1g_MW2zYAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.314489 2026] [security2:error] [pid 94831:tid 95034] [client 77.110.127.138:63013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gI406NaEKF1g_MW2zYAAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.388403 2026] [security2:error] [pid 95126:tid 95335] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4gIwpx5ks9joCJTKXHoAAB3Do"], referer: http://ali-alghanim.net/2019
[Mon Jul 20 07:18:27.467017 2026] [security2:error] [pid 95126:tid 95327] [client 77.110.127.138:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gIwpx5ks9joCJTKXHsAAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.544577 2026] [security2:error] [pid 95126:tid 95261] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gIwpx5ks9joCJTKXHowABkkk"]
[Mon Jul 20 07:18:27.599066 2026] [security2:error] [pid 95126:tid 95355] [client 77.110.127.138:63018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIwpx5ks9joCJTKXHtwAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.599176 2026] [security2:error] [pid 95126:tid 95355] [client 77.110.127.138:63018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIwpx5ks9joCJTKXHtwAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.615186 2026] [security2:error] [pid 94831:tid 94987] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gI406NaEKF1g_MW2zXwAAABo"]
[Mon Jul 20 07:18:27.621757 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:63019] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1m3uqliIb') OR 412. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 412 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gIwpx5ks9joCJTKXHuAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.644713 2026] [security2:error] [pid 95126:tid 95188] [remote 45.90.123.233:36680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gIwpx5ks9joCJTKXHuwABsDs"]
[Mon Jul 20 07:18:27.725870 2026] [security2:error] [pid 95126:tid 95343] [client 149.118.58.82:54729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gIwpx5ks9joCJTKXHwAAAAeQ"]
[Mon Jul 20 07:18:27.761121 2026] [security2:error] [pid 95126:tid 95192] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gIwpx5ks9joCJTKXHxAABlz8"]
[Mon Jul 20 07:18:27.761286 2026] [security2:error] [pid 95126:tid 95266] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gIwpx5ks9joCJTKXHxAABlz8"]
[Mon Jul 20 07:18:27.779771 2026] [security2:error] [pid 95126:tid 95360] [client 77.110.127.138:63023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIwpx5ks9joCJTKXHyAAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.779894 2026] [security2:error] [pid 95126:tid 95360] [client 77.110.127.138:63023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gIwpx5ks9joCJTKXHyAAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:27.874690 2026] [security2:error] [pid 95126:tid 95186] [remote 45.90.123.233:36680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gIwpx5ks9joCJTKXHywAB0Tk"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:18:27.877126 2026] [security2:error] [pid 95126:tid 95334] [client 14.225.17.146:58705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4gIwpx5ks9joCJTKXHuQAAAds"], referer: https://nwcarvingacademy.com/2019
[Mon Jul 20 07:18:27.918101 2026] [security2:error] [pid 94831:tid 95054] [client 43.205.139.3:45740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gI406NaEKF1g_MW2zcAAAAF0"]
[Mon Jul 20 07:18:27.918235 2026] [security2:error] [pid 94831:tid 95054] [client 43.205.139.3:45740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gI406NaEKF1g_MW2zcAAAAF0"]
[Mon Jul 20 07:18:28.096527 2026] [security2:error] [pid 94831:tid 95038] [client 50.116.65.227:13142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4gI406NaEKF1g_MW2zYwAAAE0"]
[Mon Jul 20 07:18:28.206974 2026] [security2:error] [pid 95126:tid 95305] [client 154.208.48.130:52344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gJApx5ks9joCJTKXH3AAAAb4"]
[Mon Jul 20 07:18:28.207124 2026] [security2:error] [pid 95126:tid 95305] [client 154.208.48.130:52344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gJApx5ks9joCJTKXH3AAAAb4"]
[Mon Jul 20 07:18:28.276658 2026] [security2:error] [pid 94831:tid 94967] [client 143.44.185.218:59141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gJI06NaEKF1g_MW2zegAAAAY"]
[Mon Jul 20 07:18:28.276818 2026] [security2:error] [pid 94831:tid 94967] [client 143.44.185.218:59141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gJI06NaEKF1g_MW2zegAAAAY"]
[Mon Jul 20 07:18:28.296528 2026] [security2:error] [pid 94831:tid 95042] [client 149.118.58.82:55094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4gJI06NaEKF1g_MW2zfAAAAFE"]
[Mon Jul 20 07:18:28.304290 2026] [security2:error] [pid 95126:tid 95351] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gIwpx5ks9joCJTKXHzgAB7FM"], referer: https://guidehunting.com/ssilko7
[Mon Jul 20 07:18:28.329316 2026] [security2:error] [pid 95126:tid 95271] [client 66.249.93.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4gIApx5ks9joCJTKXHEQAAAZw"]
[Mon Jul 20 07:18:28.358529 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJApx5ks9joCJTKXH6QAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.358672 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJApx5ks9joCJTKXH6QAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.378300 2026] [security2:error] [pid 95126:tid 95287] [client 57.141.18.83:49600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gIQpx5ks9joCJTKXHPAABrCI"]
[Mon Jul 20 07:18:28.390070 2026] [security2:error] [pid 94831:tid 95058] [client 14.225.17.146:53547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4gIo06NaEKF1g_MW2zQQAAAGE"], referer: http://younutrition.gr/2019
[Mon Jul 20 07:18:28.429866 2026] [security2:error] [pid 95126:tid 95341] [client 57.141.18.122:26866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gIQpx5ks9joCJTKXHPgAB4mo"]
[Mon Jul 20 07:18:28.532923 2026] [security2:error] [pid 95126:tid 95331] [client 77.110.127.138:62999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJApx5ks9joCJTKXH9QAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.533088 2026] [security2:error] [pid 95126:tid 95331] [client 77.110.127.138:62999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJApx5ks9joCJTKXH9QAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.687077 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJI06NaEKF1g_MW2zigAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.687173 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJI06NaEKF1g_MW2zigAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.751092 2026] [security2:error] [pid 94831:tid 95009] [client 77.110.127.138:62913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJI06NaEKF1g_MW2zjgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.751209 2026] [security2:error] [pid 94831:tid 95009] [client 77.110.127.138:62913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJI06NaEKF1g_MW2zjgAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.813308 2026] [security2:error] [pid 95126:tid 95363] [client 50.116.65.227:13144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4gJApx5ks9joCJTKXH2AAAAfg"]
[Mon Jul 20 07:18:28.842533 2026] [security2:error] [pid 94831:tid 95026] [client 88.241.67.160:56921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gJI06NaEKF1g_MW2zkAAAAEE"]
[Mon Jul 20 07:18:28.842682 2026] [security2:error] [pid 94831:tid 95026] [client 88.241.67.160:56921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gJI06NaEKF1g_MW2zkAAAAEE"]
[Mon Jul 20 07:18:28.860153 2026] [security2:error] [pid 94831:tid 95000] [client 117.211.236.168:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gJI06NaEKF1g_MW2zkQAAACc"]
[Mon Jul 20 07:18:28.860288 2026] [security2:error] [pid 94831:tid 95000] [client 117.211.236.168:60976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gJI06NaEKF1g_MW2zkQAAACc"]
[Mon Jul 20 07:18:28.865764 2026] [security2:error] [pid 95126:tid 95346] [client 149.118.58.82:55427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4gJApx5ks9joCJTKXICwAAAec"]
[Mon Jul 20 07:18:28.880193 2026] [security2:error] [pid 95126:tid 95279] [client 77.110.127.138:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php897h8xAe'%20OR%20519=(SELECT%20519%20FROM%20PG_SLEEP(15))--"] [unique_id "al4gJApx5ks9joCJTKXIDAAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.898485 2026] [security2:error] [pid 94831:tid 95019] [client 172.232.181.107:2232] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5023.bluehost.com"] [uri "/"] [unique_id "al4gJI06NaEKF1g_MW2zkgAAADo"]
[Mon Jul 20 07:18:28.930423 2026] [security2:error] [pid 95126:tid 95358] [client 50.116.65.227:42390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gJApx5ks9joCJTKXIDQAAAfM"]
[Mon Jul 20 07:18:28.935923 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:62957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJApx5ks9joCJTKXIDwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.936090 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:62957] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJApx5ks9joCJTKXIDwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:28.943474 2026] [security2:error] [pid 95126:tid 95304] [client 50.116.65.227:42402] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gJApx5ks9joCJTKXIEAAAAb0"]
[Mon Jul 20 07:18:29.054419 2026] [security2:error] [pid 95126:tid 95274] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gJApx5ks9joCJTKXH_wABn2g"]
[Mon Jul 20 07:18:29.069242 2026] [security2:error] [pid 95126:tid 95360] [client 103.176.215.66:53167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gJQpx5ks9joCJTKXIFAAAAfU"]
[Mon Jul 20 07:18:29.069358 2026] [security2:error] [pid 95126:tid 95360] [client 103.176.215.66:53167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gJQpx5ks9joCJTKXIFAAAAfU"]
[Mon Jul 20 07:18:29.086659 2026] [security2:error] [pid 95126:tid 95287] [client 77.110.127.138:63033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gJQpx5ks9joCJTKXIFgAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:29.099836 2026] [security2:error] [pid 95126:tid 95274] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gJApx5ks9joCJTKXIBQABnxE"]
[Mon Jul 20 07:18:29.099958 2026] [security2:error] [pid 95126:tid 95274] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gJApx5ks9joCJTKXIBwABnww"]
[Mon Jul 20 07:18:29.100066 2026] [security2:error] [pid 95126:tid 95274] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gJApx5ks9joCJTKXICAABn3o"]
[Mon Jul 20 07:18:29.100154 2026] [security2:error] [pid 95126:tid 95274] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gJApx5ks9joCJTKXIBgABnzA"]
[Mon Jul 20 07:18:29.138374 2026] [security2:error] [pid 94831:tid 94839] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gJY06NaEKF1g_MW2zlwAAWAc"]
[Mon Jul 20 07:18:29.138530 2026] [security2:error] [pid 94831:tid 95049] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gJY06NaEKF1g_MW2zlwAAWAc"]
[Mon Jul 20 07:18:29.170745 2026] [security2:error] [pid 95126:tid 95368] [client 52.187.213.117:5570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gJQpx5ks9joCJTKXIGQAAAf0"]
[Mon Jul 20 07:18:29.249968 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63036] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:1xnBuPXPl')) OR 43. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 43 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gJY06NaEKF1g_MW2zmwAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:29.325170 2026] [security2:error] [pid 94831:tid 94996] [client 57.141.18.20:28878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gIo06NaEKF1g_MW2zSgAAIww"]
[Mon Jul 20 07:18:29.327510 2026] [security2:error] [pid 95126:tid 95383] [client 52.187.213.117:5570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gJQpx5ks9joCJTKXIMwAAAgw"]
[Mon Jul 20 07:18:29.424619 2026] [security2:error] [pid 95126:tid 95352] [client 14.225.17.146:53735] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIJAAAAe0"], referer: http://bigwormfishing.com/2019
[Mon Jul 20 07:18:29.550400 2026] [security2:error] [pid 94831:tid 94973] [client 50.116.65.227:42426] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gJY06NaEKF1g_MW2zowAAAAw"]
[Mon Jul 20 07:18:29.555667 2026] [security2:error] [pid 95126:tid 95367] [client 34.178.33.65:47978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIJgAB_HI"]
[Mon Jul 20 07:18:29.565825 2026] [security2:error] [pid 94831:tid 95052] [client 50.116.65.227:42432] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gJY06NaEKF1g_MW2zpAAAAFs"]
[Mon Jul 20 07:18:29.594127 2026] [security2:error] [pid 95126:tid 95330] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIKgAB1w4"], referer: https://guidehunting.com/login
[Mon Jul 20 07:18:29.603025 2026] [security2:error] [pid 95126:tid 95330] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIKwAB11U"], referer: https://guidehunting.com/dashboard
[Mon Jul 20 07:18:29.606805 2026] [security2:error] [pid 95126:tid 95335] [client 34.147.91.161:32770] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gJQpx5ks9joCJTKXITgAAAdw"]
[Mon Jul 20 07:18:29.606886 2026] [security2:error] [pid 95126:tid 95335] [client 34.147.91.161:32770] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mail.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gJQpx5ks9joCJTKXITgAAAdw"]
[Mon Jul 20 07:18:29.618426 2026] [security2:error] [pid 95126:tid 95330] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXILAAB11E"], referer: https://guidehunting.com/settings
[Mon Jul 20 07:18:29.620977 2026] [security2:error] [pid 95126:tid 95330] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIKQAB12A"], referer: https://guidehunting.com/console
[Mon Jul 20 07:18:29.638839 2026] [security2:error] [pid 95126:tid 95330] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXILQAB10g"], referer: https://guidehunting.com/app
[Mon Jul 20 07:18:29.677691 2026] [ssl:error] [pid 94831:tid 95013] [client 104.48.69.105:34772] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:18:29.679198 2026] [security2:error] [pid 95126:tid 95274] [client 50.116.65.227:54116] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gJQpx5ks9joCJTKXIUQAAAZ8"]
[Mon Jul 20 07:18:29.694138 2026] [security2:error] [pid 95126:tid 95380] [client 50.116.65.227:42446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gJQpx5ks9joCJTKXIUgAAAfQ"]
[Mon Jul 20 07:18:29.721367 2026] [security2:error] [pid 95126:tid 95348] [client 157.20.138.62:64605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gJQpx5ks9joCJTKXIUwAAAek"]
[Mon Jul 20 07:18:29.721505 2026] [security2:error] [pid 95126:tid 95348] [client 157.20.138.62:64605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gJQpx5ks9joCJTKXIUwAAAek"]
[Mon Jul 20 07:18:29.894954 2026] [security2:error] [pid 95126:tid 95219] [remote 34.178.33.65:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4gJQpx5ks9joCJTKXIWwABqlo"], referer: https://www.guidehunting.com/login
[Mon Jul 20 07:18:30.024843 2026] [security2:error] [pid 94831:tid 95025] [client 77.110.127.138:63042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJo06NaEKF1g_MW2zsQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:30.024987 2026] [security2:error] [pid 94831:tid 95025] [client 77.110.127.138:63042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJo06NaEKF1g_MW2zsQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:30.079093 2026] [security2:error] [pid 95126:tid 95295] [client 77.110.127.138:63019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpG8VEE6mo')%20OR%20642=(SELECT%20642%20FROM%20PG_SLEEP(15))--"] [unique_id "al4gJgpx5ks9joCJTKXIbgAAAbQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:30.153893 2026] [security2:error] [pid 94831:tid 95021] [client 52.109.4.7:35008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gJo06NaEKF1g_MW2ztgAAADw"]
[Mon Jul 20 07:18:30.209684 2026] [security2:error] [pid 95126:tid 95285] [client 34.178.33.65:33320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIYwABqmc"], referer: https://guidehunting.com/admin
[Mon Jul 20 07:18:30.210000 2026] [security2:error] [pid 94831:tid 95079] [client 52.109.4.7:35008] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gJo06NaEKF1g_MW2zugAAAHY"]
[Mon Jul 20 07:18:30.233791 2026] [security2:error] [pid 95126:tid 95322] [client 49.47.218.174:65322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gJgpx5ks9joCJTKXIegAAAc8"]
[Mon Jul 20 07:18:30.233943 2026] [security2:error] [pid 95126:tid 95322] [client 49.47.218.174:65322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gJgpx5ks9joCJTKXIegAAAc8"]
[Mon Jul 20 07:18:30.371023 2026] [security2:error] [pid 94831:tid 95071] [client 14.225.17.146:63882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4gJo06NaEKF1g_MW2ztwAAAG4"], referer: http://windowtx.com/2019
[Mon Jul 20 07:18:30.443457 2026] [security2:error] [pid 95126:tid 95301] [client 14.225.17.146:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4gJgpx5ks9joCJTKXIfgAAAbo"], referer: https://bigwormfishing.com/2019
[Mon Jul 20 07:18:30.473270 2026] [security2:error] [pid 95126:tid 95314] [client 57.141.18.97:44112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gIwpx5ks9joCJTKXHyQABxwE"]
[Mon Jul 20 07:18:30.526385 2026] [security2:error] [pid 94831:tid 94867] [remote 57.141.18.101:32686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5017581"] [unique_id "al4gJo06NaEKF1g_MW2zwgAARSM"]
[Mon Jul 20 07:18:30.603108 2026] [security2:error] [pid 94831:tid 94978] [client 98.159.234.160:48785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gJo06NaEKF1g_MW2zxQAAABE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:18:30.633532 2026] [security2:error] [pid 94831:tid 95032] [client 34.55.163.65:27438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "keyq8.com"] [uri "/wp-json/batch/v1"] [unique_id "al4gJo06NaEKF1g_MW2zyAAAAEc"]
[Mon Jul 20 07:18:30.691683 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:63047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJgpx5ks9joCJTKXIlwAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:30.691787 2026] [security2:error] [pid 95126:tid 95318] [client 77.110.127.138:63047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gJgpx5ks9joCJTKXIlwAAAcs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:30.701688 2026] [security2:error] [pid 94831:tid 94984] [client 34.55.163.65:27438] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "keyq8.com"] [uri "/"] [unique_id "al4gJo06NaEKF1g_MW2zzAAAABc"]
[Mon Jul 20 07:18:30.841474 2026] [security2:error] [pid 95126:tid 95278] [client 191.202.66.27:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gJgpx5ks9joCJTKXInwAAAaM"]
[Mon Jul 20 07:18:30.841573 2026] [security2:error] [pid 95126:tid 95278] [client 191.202.66.27:50612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gJgpx5ks9joCJTKXInwAAAaM"]
[Mon Jul 20 07:18:30.843228 2026] [security2:error] [pid 95126:tid 95298] [client 77.110.127.138:63048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gJgpx5ks9joCJTKXIoAAAAbc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:31.002961 2026] [security2:error] [pid 94831:tid 94874] [remote 81.173.115.7:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4gJ406NaEKF1g_MW2z1gAAUyo"]
[Mon Jul 20 07:18:31.143547 2026] [security2:error] [pid 94831:tid 94990] [client 57.141.18.114:46996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJI06NaEKF1g_MW2zfwAAHRs"]
[Mon Jul 20 07:18:31.297362 2026] [security2:error] [pid 94831:tid 94966] [client 187.16.64.216:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gJ406NaEKF1g_MW2z4gAAAAU"]
[Mon Jul 20 07:18:31.297504 2026] [security2:error] [pid 94831:tid 94966] [client 187.16.64.216:55758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gJ406NaEKF1g_MW2z4gAAAAU"]
[Mon Jul 20 07:18:31.362309 2026] [security2:error] [pid 95126:tid 95244] [remote 34.178.33.65:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4gJwpx5ks9joCJTKXIyAABp3M"], referer: https://www.guidehunting.com/wp-admin/
[Mon Jul 20 07:18:31.682689 2026] [security2:error] [pid 94831:tid 94970] [client 34.90.222.110:16385] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "partythingy.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gJ406NaEKF1g_MW2z5wAAAAk"]
[Mon Jul 20 07:18:31.682807 2026] [security2:error] [pid 94831:tid 94970] [client 34.90.222.110:16385] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "partythingy.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gJ406NaEKF1g_MW2z5wAAAAk"]
[Mon Jul 20 07:18:31.710910 2026] [security2:error] [pid 94831:tid 95050] [client 66.249.73.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4gJ406NaEKF1g_MW2z3wAAAFk"]
[Mon Jul 20 07:18:31.881131 2026] [security2:error] [pid 95126:tid 95240] [remote 34.178.33.65:33320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.33.178.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4gJwpx5ks9joCJTKXI8QAB8G8"], referer: https://www.guidehunting.com/wp-admin/
[Mon Jul 20 07:18:31.901673 2026] [security2:error] [pid 95126:tid 95263] [client 57.141.18.8:63668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIGgABlGY"]
[Mon Jul 20 07:18:31.906583 2026] [security2:error] [pid 95126:tid 95300] [client 149.118.58.82:57229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-includes/version.php"] [unique_id "al4gJwpx5ks9joCJTKXI9QAAAbk"]
[Mon Jul 20 07:18:32.124680 2026] [security2:error] [pid 95126:tid 95330] [client 14.225.17.146:58367] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4gJwpx5ks9joCJTKXI_AAAAdc"], referer: http://mobilesurvsolutions.com/2019
[Mon Jul 20 07:18:32.481193 2026] [security2:error] [pid 95126:tid 95274] [client 149.118.58.82:57607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-includes/functions.php"] [unique_id "al4gKApx5ks9joCJTKXJHgAAAZ8"]
[Mon Jul 20 07:18:32.568374 2026] [security2:error] [pid 95126:tid 95322] [client 14.225.17.146:57922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4gKApx5ks9joCJTKXJHAAAAc8"], referer: http://scott-assist.com/2019
[Mon Jul 20 07:18:32.585237 2026] [security2:error] [pid 95126:tid 95365] [client 57.141.18.46:27666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJQpx5ks9joCJTKXIYQAB-m0"]
[Mon Jul 20 07:18:32.681553 2026] [security2:error] [pid 95126:tid 95346] [client 154.192.123.127:18555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gKApx5ks9joCJTKXJLAAAAec"]
[Mon Jul 20 07:18:32.681657 2026] [security2:error] [pid 95126:tid 95346] [client 154.192.123.127:18555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gKApx5ks9joCJTKXJLAAAAec"]
[Mon Jul 20 07:18:32.783551 2026] [security2:error] [pid 95126:tid 95249] [remote 104.131.116.82:60052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gKApx5ks9joCJTKXJMgAB23g"]
[Mon Jul 20 07:18:32.783779 2026] [security2:error] [pid 95126:tid 95334] [client 104.131.116.82:60052] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gKApx5ks9joCJTKXJMgAB23g"]
[Mon Jul 20 07:18:32.925742 2026] [autoindex:error] [pid 95126:tid 95358] [client 104.236.249.14:52762] AH01276: Cannot serve directory /home4/gpmvvomy/funnels.allandbeckson.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:18:33.013496 2026] [security2:error] [pid 95126:tid 95380] [client 57.141.18.24:36492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJgpx5ks9joCJTKXIgQACCVg"]
[Mon Jul 20 07:18:33.023684 2026] [security2:error] [pid 95126:tid 95354] [client 14.225.17.146:58285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4gJwpx5ks9joCJTKXI6AAAAe8"], referer: http://northbrookcpa.ca/2019
[Mon Jul 20 07:18:33.053954 2026] [security2:error] [pid 95126:tid 95384] [client 149.118.58.82:57990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4gKQpx5ks9joCJTKXJQgAAAg0"]
[Mon Jul 20 07:18:33.182098 2026] [security2:error] [pid 94831:tid 94984] [client 14.225.17.146:54943] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4gKY06NaEKF1g_MW20CQAAABc"], referer: http://katsklar.com/2019
[Mon Jul 20 07:18:33.220604 2026] [security2:error] [pid 95126:tid 95331] [client 172.232.181.107:26024] ModSecurity: Rule 564f98687970 [id "340157"][file "/etc/httpd/modsecurity.d/10_asl_rules.conf"][line "395"] - Execution error - PCRE limits exceeded (-47): (null). [hostname "box5023.bluehost.com"] [uri "/"] [unique_id "al4gKQpx5ks9joCJTKXJSwAAAdg"]
[Mon Jul 20 07:18:33.305564 2026] [security2:error] [pid 95126:tid 95335] [client 77.110.127.138:63028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gKQpx5ks9joCJTKXJUgAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:33.305664 2026] [security2:error] [pid 95126:tid 95335] [client 77.110.127.138:63028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gKQpx5ks9joCJTKXJUgAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:33.316913 2026] [security2:error] [pid 94831:tid 94975] [client 13.232.231.177:21976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gKY06NaEKF1g_MW20DwAAAA4"]
[Mon Jul 20 07:18:33.344679 2026] [autoindex:error] [pid 95126:tid 95263] [client 104.236.249.14:36748] AH01276: Cannot serve directory /home4/gpmvvomy/funnels.allandbeckson.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:18:33.621370 2026] [security2:error] [pid 94831:tid 95044] [client 149.118.58.82:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-includes/option.php"] [unique_id "al4gKY06NaEKF1g_MW20FQAAAFM"]
[Mon Jul 20 07:18:33.649194 2026] [security2:error] [pid 95126:tid 95155] [remote 167.114.139.119:43576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4gKQpx5ks9joCJTKXJawABlxo"]
[Mon Jul 20 07:18:33.649387 2026] [security2:error] [pid 95126:tid 95266] [client 167.114.139.119:43576] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4gKQpx5ks9joCJTKXJawABlxo"]
[Mon Jul 20 07:18:33.738577 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.phpdEVZZA5E'))%20OR%20353=(SELECT%20353%20FROM%20PG_SLEEP(15))--"] [unique_id "al4gKQpx5ks9joCJTKXJdQAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:33.910027 2026] [security2:error] [pid 95126:tid 95362] [client 57.141.18.61:41986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJwpx5ks9joCJTKXIrwAB9xg"]
[Mon Jul 20 07:18:34.008059 2026] [security2:error] [pid 95126:tid 95374] [client 201.27.111.74:56342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gKQpx5ks9joCJTKXJiAAAAgM"]
[Mon Jul 20 07:18:34.008211 2026] [security2:error] [pid 95126:tid 95374] [client 201.27.111.74:56342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gKQpx5ks9joCJTKXJiAAAAgM"]
[Mon Jul 20 07:18:34.109243 2026] [security2:error] [pid 94831:tid 95014] [client 57.141.18.12:59330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJ406NaEKF1g_MW2z5AAANRM"]
[Mon Jul 20 07:18:34.137967 2026] [security2:error] [pid 95126:tid 95361] [client 74.208.214.194:57638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4gKgpx5ks9joCJTKXJjgAAAfY"]
[Mon Jul 20 07:18:34.189731 2026] [security2:error] [pid 95126:tid 95329] [client 149.118.58.82:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-includes/post.php"] [unique_id "al4gKgpx5ks9joCJTKXJkAAAAdY"]
[Mon Jul 20 07:18:34.294326 2026] [security2:error] [pid 95126:tid 95319] [client 13.233.207.33:59418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gKgpx5ks9joCJTKXJlQAAAcw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:18:34.356323 2026] [security2:error] [pid 94831:tid 94990] [client 14.225.17.146:54823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4gKo06NaEKF1g_MW20HAAAAB0"], referer: http://adastra.love/2019
[Mon Jul 20 07:18:34.360427 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gKo06NaEKF1g_MW20HwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:34.360511 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gKo06NaEKF1g_MW20HwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:34.365610 2026] [security2:error] [pid 95126:tid 95379] [client 57.141.18.65:20338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gJwpx5ks9joCJTKXI2AACCCA"]
[Mon Jul 20 07:18:34.511943 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:63071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gKgpx5ks9joCJTKXJoAAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:34.731263 2026] [security2:error] [pid 94831:tid 94989] [client 50.116.65.227:42532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gKo06NaEKF1g_MW20KgAAABw"]
[Mon Jul 20 07:18:34.741241 2026] [security2:error] [pid 95126:tid 95381] [client 50.116.65.227:42544] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gKgpx5ks9joCJTKXJrQAAAgo"]
[Mon Jul 20 07:18:34.767104 2026] [security2:error] [pid 94831:tid 95012] [client 149.118.58.82:59227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-includes/user.php"] [unique_id "al4gKo06NaEKF1g_MW20LgAAADM"]
[Mon Jul 20 07:18:35.046928 2026] [core:error] [pid 95126:tid 95369] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:35.046956 2026] [core:error] [pid 95126:tid 95369] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:35.272561 2026] [security2:error] [pid 95126:tid 95305] [client 50.116.65.227:42554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gKwpx5ks9joCJTKXJ1AAAAb4"]
[Mon Jul 20 07:18:35.288078 2026] [security2:error] [pid 95126:tid 95272] [client 14.225.17.146:63556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4gKwpx5ks9joCJTKXJ2wAAAZ0"]
[Mon Jul 20 07:18:35.403487 2026] [security2:error] [pid 94831:tid 94991] [client 57.141.18.10:37134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gKI06NaEKF1g_MW20AwAAHjs"]
[Mon Jul 20 07:18:35.452812 2026] [security2:error] [pid 95126:tid 95283] [client 57.141.18.122:58738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gKApx5ks9joCJTKXJNQABqDw"]
[Mon Jul 20 07:18:35.455011 2026] [security2:error] [pid 95126:tid 95276] [client 50.116.65.227:42562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gKwpx5ks9joCJTKXJ4gAAAaE"]
[Mon Jul 20 07:18:36.050150 2026] [security2:error] [pid 94831:tid 95022] [client 103.144.65.217:53789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gLI06NaEKF1g_MW20SwAAAD0"]
[Mon Jul 20 07:18:36.050235 2026] [security2:error] [pid 94831:tid 95022] [client 103.144.65.217:53789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gLI06NaEKF1g_MW20SwAAAD0"]
[Mon Jul 20 07:18:36.310736 2026] [security2:error] [pid 94831:tid 94986] [client 57.141.18.17:41448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gKY06NaEKF1g_MW20FwAAGTc"]
[Mon Jul 20 07:18:36.625597 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:63075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLApx5ks9joCJTKXKNgAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:36.625704 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:63075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLApx5ks9joCJTKXKNgAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:36.748580 2026] [security2:error] [pid 94831:tid 94904] [remote 81.173.115.7:37438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4gLI06NaEKF1g_MW20ZQAAEEg"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 07:18:36.866700 2026] [security2:error] [pid 95126:tid 95314] [client 114.119.143.214:48041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mollycahill.com"] [uri "/s/IGTV-Swipe-Up-Hack.pdf"] [unique_id "al4gLApx5ks9joCJTKXKRQAAAcc"], referer: https://www.mollycahill.com/facebook-downloads
[Mon Jul 20 07:18:36.977349 2026] [security2:error] [pid 94831:tid 95000] [client 52.109.28.48:11264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gLI06NaEKF1g_MW20bAAAACc"]
[Mon Jul 20 07:18:37.052337 2026] [security2:error] [pid 94831:tid 94994] [client 77.110.127.138:63060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'||DBMS_PIPE.RECEIVE_MESSAGE(CHR(98)||CHR(98)||CHR(98),15)||'"] [unique_id "al4gLY06NaEKF1g_MW20cAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:37.058316 2026] [ssl:error] [pid 94831:tid 94982] [client 104.48.69.105:34778] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:18:37.120879 2026] [security2:error] [pid 94831:tid 95067] [client 52.109.28.48:11264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gLY06NaEKF1g_MW20dAAAAGo"]
[Mon Jul 20 07:18:37.177017 2026] [security2:error] [pid 94831:tid 95004] [client 14.225.17.146:54812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4gLI06NaEKF1g_MW20ZwAAACs"], referer: http://mollycahill.com/2019
[Mon Jul 20 07:18:37.254923 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:63116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLQpx5ks9joCJTKXKZgAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:37.255030 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:63116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLQpx5ks9joCJTKXKZgAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:37.436231 2026] [security2:error] [pid 95126:tid 95258] [client 57.141.18.72:60552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gKgpx5ks9joCJTKXJuQABjwU"]
[Mon Jul 20 07:18:37.546458 2026] [security2:error] [pid 95126:tid 95349] [client 52.109.28.48:19824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gLQpx5ks9joCJTKXKdQAAAeo"]
[Mon Jul 20 07:18:37.611932 2026] [security2:error] [pid 95126:tid 95260] [client 74.208.214.194:39802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4gLQpx5ks9joCJTKXKfgAAAZE"]
[Mon Jul 20 07:18:37.612699 2026] [security2:error] [pid 95126:tid 95162] [remote 167.71.218.184:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gLQpx5ks9joCJTKXKewABmCE"]
[Mon Jul 20 07:18:37.683574 2026] [security2:error] [pid 95126:tid 95329] [client 52.109.28.48:19824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gLQpx5ks9joCJTKXKhwAAAdY"]
[Mon Jul 20 07:18:37.752953 2026] [core:error] [pid 95126:tid 95332] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:37.752976 2026] [core:error] [pid 95126:tid 95332] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:37.801702 2026] [ssl:error] [pid 95126:tid 95357] [client 104.48.69.105:34780] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:18:37.906829 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:63105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLQpx5ks9joCJTKXKmAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:37.906964 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:63105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLQpx5ks9joCJTKXKmAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:37.959673 2026] [security2:error] [pid 94831:tid 95025] [client 77.110.127.138:63102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gLY06NaEKF1g_MW20iQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.009847 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLgpx5ks9joCJTKXKnwAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.009957 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLgpx5ks9joCJTKXKnwAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.067324 2026] [security2:error] [pid 95126:tid 95289] [client 77.110.127.138:63076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php'\\""] [unique_id "al4gLgpx5ks9joCJTKXKpAAAAa4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.165168 2026] [security2:error] [pid 95126:tid 95217] [remote 167.71.218.184:59942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gLgpx5ks9joCJTKXKrAABolg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:18:38.222224 2026] [security2:error] [pid 95126:tid 95362] [client 77.110.127.138:63119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php%c0%a7%c0%a2%252527%252522\\\\'\\\\\\""] [unique_id "al4gLgpx5ks9joCJTKXKsQAAAfc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.341933 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLgpx5ks9joCJTKXKuAAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.342076 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLgpx5ks9joCJTKXKuAAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.346607 2026] [security2:error] [pid 95126:tid 95368] [client 57.141.18.67:40040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gKwpx5ks9joCJTKXKEQAB_Ss"]
[Mon Jul 20 07:18:38.382140 2026] [security2:error] [pid 95126:tid 95146] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gLgpx5ks9joCJTKXKvgAB5xE"]
[Mon Jul 20 07:18:38.382305 2026] [security2:error] [pid 95126:tid 95346] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gLgpx5ks9joCJTKXKvgAB5xE"]
[Mon Jul 20 07:18:38.391866 2026] [security2:error] [pid 95126:tid 95306] [client 77.110.127.138:63079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLgpx5ks9joCJTKXKvwAAAb8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.391976 2026] [security2:error] [pid 95126:tid 95306] [client 77.110.127.138:63079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLgpx5ks9joCJTKXKvwAAAb8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.453598 2026] [security2:error] [pid 95126:tid 95331] [client 77.110.127.138:63050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gLgpx5ks9joCJTKXKyQAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:38.587197 2026] [security2:error] [pid 95126:tid 95275] [client 57.141.18.109:43948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gLApx5ks9joCJTKXKIQABoBI"]
[Mon Jul 20 07:18:38.612777 2026] [security2:error] [pid 94831:tid 94978] [client 34.84.221.1:6501] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "omenana.com"] [uri "/wp-content/uploads/2015/03/omenana-issue-2-final-cover.jpg"] [unique_id "al4gLo06NaEKF1g_MW20kQAAABE"]
[Mon Jul 20 07:18:38.968047 2026] [security2:error] [pid 95126:tid 95366] [client 143.44.185.218:60904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gLgpx5ks9joCJTKXK7QAAAfs"]
[Mon Jul 20 07:18:38.968131 2026] [security2:error] [pid 95126:tid 95366] [client 143.44.185.218:60904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gLgpx5ks9joCJTKXK7QAAAfs"]
[Mon Jul 20 07:18:39.092562 2026] [security2:error] [pid 95126:tid 95339] [client 154.208.48.130:52847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gLwpx5ks9joCJTKXK9gAAAeA"]
[Mon Jul 20 07:18:39.093018 2026] [security2:error] [pid 95126:tid 95339] [client 154.208.48.130:52847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gLwpx5ks9joCJTKXK9gAAAeA"]
[Mon Jul 20 07:18:39.356366 2026] [access_compat:error] [pid 95126:tid 95384] [client 144.172.114.51:56986] AH01797: client denied by server configuration: proxy:http://127.0.0.1:8080/server-status
[Mon Jul 20 07:18:39.448087 2026] [security2:error] [pid 94831:tid 95071] [client 88.241.67.160:54265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gL406NaEKF1g_MW20owAAAG4"]
[Mon Jul 20 07:18:39.448714 2026] [security2:error] [pid 94831:tid 95071] [client 88.241.67.160:54265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gL406NaEKF1g_MW20owAAAG4"]
[Mon Jul 20 07:18:39.704100 2026] [security2:error] [pid 94831:tid 95023] [client 103.176.215.66:53687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gL406NaEKF1g_MW20qQAAAD4"]
[Mon Jul 20 07:18:39.704597 2026] [security2:error] [pid 94831:tid 95023] [client 103.176.215.66:53687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gL406NaEKF1g_MW20qQAAAD4"]
[Mon Jul 20 07:18:39.756739 2026] [security2:error] [pid 95126:tid 95219] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gLwpx5ks9joCJTKXLIwAB11o"]
[Mon Jul 20 07:18:39.756883 2026] [security2:error] [pid 95126:tid 95330] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gLwpx5ks9joCJTKXLIwAB11o"]
[Mon Jul 20 07:18:39.931226 2026] [security2:error] [pid 94831:tid 94996] [client 57.141.18.78:54374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gLY06NaEKF1g_MW20fgAAIyI"]
[Mon Jul 20 07:18:39.950082 2026] [security2:error] [pid 95126:tid 95377] [client 77.110.127.138:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLwpx5ks9joCJTKXLOwAAAgY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:39.950194 2026] [security2:error] [pid 95126:tid 95377] [client 77.110.127.138:63127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gLwpx5ks9joCJTKXLOwAAAgY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:40.185304 2026] [security2:error] [pid 95126:tid 95382] [client 57.141.18.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gMApx5ks9joCJTKXLQwAAAgs"]
[Mon Jul 20 07:18:40.276348 2026] [security2:error] [pid 95126:tid 95328] [client 77.110.127.138:63123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gLwpx5ks9joCJTKXLOgAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:40.367933 2026] [security2:error] [pid 95126:tid 95190] [remote 117.0.21.154:42066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gMApx5ks9joCJTKXLWwAB7z0"]
[Mon Jul 20 07:18:40.389578 2026] [security2:error] [pid 94831:tid 94962] [client 157.20.138.62:65171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gMI06NaEKF1g_MW20twAAAAE"]
[Mon Jul 20 07:18:40.389762 2026] [security2:error] [pid 94831:tid 94962] [client 157.20.138.62:65171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gMI06NaEKF1g_MW20twAAAAE"]
[Mon Jul 20 07:18:40.478521 2026] [security2:error] [pid 95126:tid 95326] [client 104.234.53.48:64793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gMApx5ks9joCJTKXLYAAAAdM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:40.648281 2026] [security2:error] [pid 95126:tid 95263] [client 49.47.218.174:49438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gMApx5ks9joCJTKXLbQAAAZQ"]
[Mon Jul 20 07:18:40.648493 2026] [security2:error] [pid 95126:tid 95263] [client 49.47.218.174:49438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gMApx5ks9joCJTKXLbQAAAZQ"]
[Mon Jul 20 07:18:40.684261 2026] [security2:error] [pid 94831:tid 94970] [client 49.37.242.14:52510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gMI06NaEKF1g_MW20uQAAAAk"]
[Mon Jul 20 07:18:40.684457 2026] [security2:error] [pid 94831:tid 94970] [client 49.37.242.14:52510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gMI06NaEKF1g_MW20uQAAAAk"]
[Mon Jul 20 07:18:40.710256 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gMApx5ks9joCJTKXLbgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:40.710350 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gMApx5ks9joCJTKXLbgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:40.760438 2026] [security2:error] [pid 95126:tid 95301] [client 77.110.127.138:63108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gMApx5ks9joCJTKXLcQAAAbo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:40.840246 2026] [security2:error] [pid 95126:tid 95164] [remote 117.0.21.154:42066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gMApx5ks9joCJTKXLegABmSM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:18:40.907548 2026] [security2:error] [pid 95126:tid 95278] [client 57.141.18.67:40044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gLgpx5ks9joCJTKXKtgABo2g"]
[Mon Jul 20 07:18:40.951283 2026] [security2:error] [pid 95126:tid 95169] [remote 120.46.94.180:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.94.46.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gMApx5ks9joCJTKXLgAABqyg"]
[Mon Jul 20 07:18:41.305226 2026] [core:error] [pid 95126:tid 95343] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:41.305246 2026] [core:error] [pid 95126:tid 95343] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:41.349120 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gMY06NaEKF1g_MW20zAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:41.349216 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:63136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gMY06NaEKF1g_MW20zAAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:41.495952 2026] [security2:error] [pid 95126:tid 95362] [client 57.141.18.105:61536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gLgpx5ks9joCJTKXK6QAB92Q"]
[Mon Jul 20 07:18:41.499661 2026] [security2:error] [pid 94831:tid 95085] [client 191.202.66.27:51071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gMY06NaEKF1g_MW201QAAAHw"]
[Mon Jul 20 07:18:41.499790 2026] [security2:error] [pid 94831:tid 95085] [client 191.202.66.27:51071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gMY06NaEKF1g_MW201QAAAHw"]
[Mon Jul 20 07:18:41.620387 2026] [proxy:error] [pid 95126:tid 95285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:41.620428 2026] [proxy_http:error] [pid 95126:tid 95285] [client 8.229.28.226:56698] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:41.621230 2026] [proxy:error] [pid 95126:tid 95285] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:41.621273 2026] [proxy_http:error] [pid 95126:tid 95285] [client 8.229.28.226:56698] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:41.696075 2026] [security2:error] [pid 95126:tid 95231] [remote 154.66.198.148:1710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4gMQpx5ks9joCJTKXLqwAB8mY"]
[Mon Jul 20 07:18:41.699492 2026] [security2:error] [pid 94831:tid 95005] [client 77.110.127.138:63138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gMY06NaEKF1g_MW200wAAACw"]
[Mon Jul 20 07:18:41.917223 2026] [security2:error] [pid 94831:tid 94959] [remote 192.241.143.148:35992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gMY06NaEKF1g_MW206QAAXn8"]
[Mon Jul 20 07:18:41.917393 2026] [security2:error] [pid 94831:tid 95055] [client 192.241.143.148:35992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gMY06NaEKF1g_MW206QAAXn8"]
[Mon Jul 20 07:18:41.958136 2026] [security2:error] [pid 94831:tid 94971] [client 57.141.18.77:41808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gL406NaEKF1g_MW20ogAACm0"]
[Mon Jul 20 07:18:42.054806 2026] [security2:error] [pid 94831:tid 94982] [client 187.16.64.216:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gMo06NaEKF1g_MW208AAAABU"]
[Mon Jul 20 07:18:42.054932 2026] [security2:error] [pid 94831:tid 94982] [client 187.16.64.216:56327] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gMo06NaEKF1g_MW208AAAABU"]
[Mon Jul 20 07:18:42.114504 2026] [security2:error] [pid 95126:tid 95311] [client 104.234.53.92:21551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gMgpx5ks9joCJTKXLvQAAAcQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:42.258132 2026] [security2:error] [pid 95126:tid 95179] [remote 154.66.198.148:1710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4gMgpx5ks9joCJTKXLxgAB1zI"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 07:18:42.631404 2026] [security2:error] [pid 95126:tid 95181] [remote 120.46.94.180:60612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.94.46.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gMgpx5ks9joCJTKXL2wABwTQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:18:42.652704 2026] [security2:error] [pid 94831:tid 94989] [client 144.172.114.51:40796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/api/index.php/v1/config/application"] [unique_id "al4gMo06NaEKF1g_MW21BgAAABw"]
[Mon Jul 20 07:18:42.657854 2026] [security2:error] [pid 95126:tid 95335] [client 57.141.18.83:49714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMApx5ks9joCJTKXLRAAB3CQ"]
[Mon Jul 20 07:18:42.836050 2026] [security2:error] [pid 94831:tid 94834] [remote 103.82.22.235:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4gMo06NaEKF1g_MW21BwAAWQI"]
[Mon Jul 20 07:18:42.984739 2026] [security2:error] [pid 95126:tid 95280] [client 50.116.65.227:39788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gMgpx5ks9joCJTKXL_QAAAaU"]
[Mon Jul 20 07:18:42.995911 2026] [security2:error] [pid 95126:tid 95312] [client 50.116.65.227:18040] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gMgpx5ks9joCJTKXL_wAAAfs"]
[Mon Jul 20 07:18:43.044061 2026] [security2:error] [pid 95126:tid 95360] [client 117.211.236.168:61594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gMwpx5ks9joCJTKXMBAAAAfU"]
[Mon Jul 20 07:18:43.044173 2026] [security2:error] [pid 95126:tid 95360] [client 117.211.236.168:61594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gMwpx5ks9joCJTKXMBAAAAfU"]
[Mon Jul 20 07:18:43.238511 2026] [security2:error] [pid 95126:tid 95268] [client 154.192.123.127:17016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gMwpx5ks9joCJTKXMDwAAAZk"]
[Mon Jul 20 07:18:43.238607 2026] [security2:error] [pid 95126:tid 95268] [client 154.192.123.127:17016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gMwpx5ks9joCJTKXMDwAAAZk"]
[Mon Jul 20 07:18:43.310356 2026] [security2:error] [pid 94831:tid 94858] [remote 103.82.22.235:51962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4gM406NaEKF1g_MW21EwAAIho"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:18:43.392324 2026] [security2:error] [pid 95126:tid 95308] [client 104.234.53.47:63127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gMwpx5ks9joCJTKXMFwAAAcE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:43.622332 2026] [security2:error] [pid 95126:tid 95285] [client 77.110.127.138:63111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gMwpx5ks9joCJTKXMIwAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:43.622442 2026] [security2:error] [pid 95126:tid 95285] [client 77.110.127.138:63111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gMwpx5ks9joCJTKXMIwAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:43.774460 2026] [security2:error] [pid 94831:tid 95066] [client 57.141.18.63:30440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMY06NaEKF1g_MW20wwAAaXk"]
[Mon Jul 20 07:18:43.799073 2026] [security2:error] [pid 94831:tid 95080] [client 57.141.18.105:61538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMY06NaEKF1g_MW20xQAAdxg"]
[Mon Jul 20 07:18:43.823774 2026] [security2:error] [pid 95126:tid 95292] [client 14.225.17.146:65136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4gMgpx5ks9joCJTKXLygAAAbE"], referer: http://inspirespublishing.com/2019
[Mon Jul 20 07:18:43.839377 2026] [security2:error] [pid 95126:tid 95307] [client 77.110.127.138:63110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gMwpx5ks9joCJTKXMIgAAAcA"]
[Mon Jul 20 07:18:44.242109 2026] [security2:error] [pid 95126:tid 95365] [client 54.255.146.241:54132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cryptomeaning.com"] [uri "/best-cpu-for-mining"] [unique_id "al4gNApx5ks9joCJTKXMSwAAAfo"], referer: https://setht.com/unlocking-the-secrets-of-seo-how-to-effectively-use-keyword-for-search-engine-success
[Mon Jul 20 07:18:44.381042 2026] [security2:error] [pid 95126:tid 95357] [client 14.225.17.146:63125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4gMgpx5ks9joCJTKXL-QAAAfI"], referer: http://thechancersband.com/2019
[Mon Jul 20 07:18:44.454334 2026] [security2:error] [pid 94831:tid 94853] [remote 57.141.18.8:39692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gNI06NaEKF1g_MW21LwAABhU"]
[Mon Jul 20 07:18:44.580793 2026] [security2:error] [pid 94831:tid 95006] [client 149.118.58.82:49768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.58.118.149.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.memarion.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4gNI06NaEKF1g_MW21NAAAAC0"]
[Mon Jul 20 07:18:44.581857 2026] [security2:error] [pid 95126:tid 95269] [client 201.27.111.74:56858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gNApx5ks9joCJTKXMWwAAAZo"]
[Mon Jul 20 07:18:44.581972 2026] [security2:error] [pid 95126:tid 95269] [client 201.27.111.74:56858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gNApx5ks9joCJTKXMWwAAAZo"]
[Mon Jul 20 07:18:44.600163 2026] [security2:error] [pid 94831:tid 95047] [client 57.141.18.79:62270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMo06NaEKF1g_MW208QAAVnE"]
[Mon Jul 20 07:18:44.755260 2026] [security2:error] [pid 94831:tid 94855] [remote 113.160.142.119:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gNI06NaEKF1g_MW21NgAATxc"]
[Mon Jul 20 07:18:44.809655 2026] [security2:error] [pid 94831:tid 95063] [client 57.141.18.4:22018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMo06NaEKF1g_MW20_gAAZns"]
[Mon Jul 20 07:18:44.894578 2026] [security2:error] [pid 95126:tid 95157] [remote 47.86.33.52:30036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gNApx5ks9joCJTKXMbQAB1hw"]
[Mon Jul 20 07:18:44.925420 2026] [security2:error] [pid 95126:tid 95378] [client 14.225.17.146:65157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4gMwpx5ks9joCJTKXMMgAAAgc"], referer: http://intelligentengineeringsolutions.com/2019
[Mon Jul 20 07:18:45.129117 2026] [core:error] [pid 95126:tid 95344] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:45.129137 2026] [core:error] [pid 95126:tid 95344] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:45.280959 2026] [security2:error] [pid 94831:tid 94864] [remote 113.160.142.119:59162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gNY06NaEKF1g_MW21QAAADSA"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:18:45.377892 2026] [security2:error] [pid 94831:tid 94838] [remote 41.186.86.12:46625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4gNY06NaEKF1g_MW21QQAAWQY"]
[Mon Jul 20 07:18:45.401805 2026] [security2:error] [pid 95126:tid 95248] [remote 57.141.18.84:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gNQpx5ks9joCJTKXMlQABsnc"]
[Mon Jul 20 07:18:45.411713 2026] [security2:error] [pid 95126:tid 95335] [client 14.225.17.146:58597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4gNApx5ks9joCJTKXMQwAAAdw"], referer: http://mazzucelli.com/2019
[Mon Jul 20 07:18:45.680327 2026] [core:error] [pid 94831:tid 94984] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:45.680353 2026] [core:error] [pid 94831:tid 94984] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:45.714045 2026] [security2:error] [pid 95126:tid 95241] [remote 47.86.33.52:30050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4gNQpx5ks9joCJTKXMtQABx3A"]
[Mon Jul 20 07:18:45.736556 2026] [security2:error] [pid 95126:tid 95359] [client 57.141.18.28:56610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMwpx5ks9joCJTKXMEQAB9Bs"]
[Mon Jul 20 07:18:45.739302 2026] [security2:error] [pid 95126:tid 95196] [remote 47.86.33.52:30036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gNQpx5ks9joCJTKXMuAABs0M"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:18:45.934982 2026] [security2:error] [pid 95126:tid 95278] [client 57.141.18.84:22748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMwpx5ks9joCJTKXMFgABoyw"]
[Mon Jul 20 07:18:45.980365 2026] [security2:error] [pid 94831:tid 94873] [remote 41.186.86.12:46625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4gNY06NaEKF1g_MW21UQAAFSk"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:18:46.007126 2026] [security2:error] [pid 95126:tid 95285] [client 104.234.53.61:33369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gNgpx5ks9joCJTKXMxgAAAao"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:46.104031 2026] [security2:error] [pid 95126:tid 95204] [remote 47.86.33.52:30050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4gNgpx5ks9joCJTKXM0AAB6Us"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:18:46.218507 2026] [security2:error] [pid 95126:tid 95358] [client 57.141.18.27:58390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gMwpx5ks9joCJTKXMLAAB8xE"]
[Mon Jul 20 07:18:46.389101 2026] [security2:error] [pid 95126:tid 95338] [client 34.147.84.84:32769] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "rumjungle.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gNgpx5ks9joCJTKXM6gAAAd8"]
[Mon Jul 20 07:18:46.389191 2026] [security2:error] [pid 95126:tid 95338] [client 34.147.84.84:32769] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rumjungle.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gNgpx5ks9joCJTKXM6gAAAd8"]
[Mon Jul 20 07:18:46.645804 2026] [core:error] [pid 95126:tid 95314] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:46.645835 2026] [core:error] [pid 95126:tid 95314] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:46.694061 2026] [security2:error] [pid 95126:tid 95286] [client 57.141.18.60:47270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNApx5ks9joCJTKXMRwABqzA"]
[Mon Jul 20 07:18:46.788522 2026] [security2:error] [pid 95126:tid 95346] [client 77.110.127.138:63162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gNgpx5ks9joCJTKXNBQAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:46.793517 2026] [security2:error] [pid 95126:tid 95259] [client 14.225.17.146:53039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4gNQpx5ks9joCJTKXMiwAAAZA"], referer: http://careysheatingandcooling.com/2019
[Mon Jul 20 07:18:46.797771 2026] [security2:error] [pid 95126:tid 95311] [client 103.144.65.217:54245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gNgpx5ks9joCJTKXNBgAAAcQ"]
[Mon Jul 20 07:18:46.799122 2026] [security2:error] [pid 95126:tid 95311] [client 103.144.65.217:54245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gNgpx5ks9joCJTKXNBgAAAcQ"]
[Mon Jul 20 07:18:46.889524 2026] [security2:error] [pid 94831:tid 95017] [client 57.141.18.44:65356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNI06NaEKF1g_MW21KAAAOAo"]
[Mon Jul 20 07:18:46.939633 2026] [security2:error] [pid 95126:tid 95360] [client 77.110.127.138:63167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gNgpx5ks9joCJTKXNDgAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:46.939799 2026] [security2:error] [pid 95126:tid 95360] [client 77.110.127.138:63167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gNgpx5ks9joCJTKXNDgAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:46.960625 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gNo06NaEKF1g_MW21YAAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:46.960718 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gNo06NaEKF1g_MW21YAAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:47.017451 2026] [security2:error] [pid 95126:tid 95312] [client 202.141.11.99:36017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gNwpx5ks9joCJTKXNFQAAAcU"]
[Mon Jul 20 07:18:47.017875 2026] [security2:error] [pid 95126:tid 95312] [client 202.141.11.99:36017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gNwpx5ks9joCJTKXNFQAAAcU"]
[Mon Jul 20 07:18:47.065309 2026] [core:error] [pid 95126:tid 95305] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:47.065330 2026] [core:error] [pid 95126:tid 95305] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:47.101863 2026] [security2:error] [pid 95126:tid 95327] [client 14.225.17.146:62910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4gNQpx5ks9joCJTKXMoQAAAdQ"], referer: http://ironcitywellness.com/2019
[Mon Jul 20 07:18:47.350374 2026] [security2:error] [pid 94831:tid 94997] [client 50.116.65.227:18112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gN406NaEKF1g_MW21aQAAACQ"]
[Mon Jul 20 07:18:47.352859 2026] [core:error] [pid 94831:tid 94983] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:47.352882 2026] [core:error] [pid 94831:tid 94983] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:47.360242 2026] [security2:error] [pid 94831:tid 95053] [client 50.116.65.227:18122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gN406NaEKF1g_MW21bQAAAFw"]
[Mon Jul 20 07:18:47.472965 2026] [security2:error] [pid 95126:tid 95379] [client 57.141.18.66:51110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNApx5ks9joCJTKXMdgACCCA"]
[Mon Jul 20 07:18:47.473718 2026] [security2:error] [pid 94831:tid 95026] [client 50.116.65.227:39802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4gN406NaEKF1g_MW21cAAAAEE"]
[Mon Jul 20 07:18:47.476683 2026] [security2:error] [pid 95126:tid 95292] [client 14.225.17.146:62826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4gNgpx5ks9joCJTKXMzgAAAbE"]
[Mon Jul 20 07:18:47.789141 2026] [security2:error] [pid 95126:tid 95383] [client 57.141.18.112:35756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNQpx5ks9joCJTKXMjwACDGI"]
[Mon Jul 20 07:18:47.914841 2026] [security2:error] [pid 95126:tid 95368] [client 77.110.127.138:63173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gNwpx5ks9joCJTKXNUAAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:47.915004 2026] [security2:error] [pid 95126:tid 95368] [client 77.110.127.138:63173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gNwpx5ks9joCJTKXNUAAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:48.175202 2026] [security2:error] [pid 95126:tid 95319] [client 57.141.18.54:20514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNQpx5ks9joCJTKXMtAABzDw"]
[Mon Jul 20 07:18:48.187725 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:63175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOApx5ks9joCJTKXNZwAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:48.187827 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:63175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOApx5ks9joCJTKXNZwAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:48.351672 2026] [security2:error] [pid 95126:tid 95331] [client 77.110.127.138:63177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gOApx5ks9joCJTKXNdAAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:48.482931 2026] [security2:error] [pid 94831:tid 94883] [remote 57.141.18.86:30544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gOI06NaEKF1g_MW21hQAAITM"]
[Mon Jul 20 07:18:48.515620 2026] [security2:error] [pid 95126:tid 95294] [client 77.110.127.138:63178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOApx5ks9joCJTKXNfwAAAbM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:48.515731 2026] [security2:error] [pid 95126:tid 95294] [client 77.110.127.138:63178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOApx5ks9joCJTKXNfwAAAbM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:48.991901 2026] [security2:error] [pid 95126:tid 95239] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gOApx5ks9joCJTKXNpQAB0W4"]
[Mon Jul 20 07:18:48.992077 2026] [security2:error] [pid 95126:tid 95324] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gOApx5ks9joCJTKXNpQAB0W4"]
[Mon Jul 20 07:18:49.047130 2026] [security2:error] [pid 95126:tid 95365] [client 192.109.139.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "terrapro.marketing"] [uri "/index.php"] [unique_id "al4gOApx5ks9joCJTKXNnQAAAfo"]
[Mon Jul 20 07:18:49.342800 2026] [core:error] [pid 94831:tid 95085] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:49.342824 2026] [core:error] [pid 94831:tid 95085] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:49.444007 2026] [security2:error] [pid 94831:tid 95013] [client 57.141.18.29:32050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNo06NaEKF1g_MW21WgAANCo"]
[Mon Jul 20 07:18:49.515731 2026] [security2:error] [pid 95126:tid 95367] [client 104.234.53.90:20419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gOQpx5ks9joCJTKXNxQAAAfw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:49.640578 2026] [security2:error] [pid 95126:tid 95307] [client 34.34.21.42:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "vundaball.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gOQpx5ks9joCJTKXNygAAAcA"]
[Mon Jul 20 07:18:49.640707 2026] [security2:error] [pid 95126:tid 95307] [client 34.34.21.42:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vundaball.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gOQpx5ks9joCJTKXNygAAAcA"]
[Mon Jul 20 07:18:49.693722 2026] [security2:error] [pid 94831:tid 95008] [client 143.44.185.218:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gOY06NaEKF1g_MW21oQAAAC8"]
[Mon Jul 20 07:18:49.693823 2026] [security2:error] [pid 94831:tid 95008] [client 143.44.185.218:62165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gOY06NaEKF1g_MW21oQAAAC8"]
[Mon Jul 20 07:18:50.069102 2026] [security2:error] [pid 95126:tid 95267] [client 88.241.67.160:56860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXN4QAAAZg"]
[Mon Jul 20 07:18:50.069253 2026] [security2:error] [pid 95126:tid 95267] [client 88.241.67.160:56860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXN4QAAAZg"]
[Mon Jul 20 07:18:50.097128 2026] [security2:error] [pid 95126:tid 95287] [client 34.147.91.161:32771] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.hypnorem.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gOgpx5ks9joCJTKXN5QAAAaw"]
[Mon Jul 20 07:18:50.097216 2026] [security2:error] [pid 95126:tid 95287] [client 34.147.91.161:32771] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.hypnorem.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gOgpx5ks9joCJTKXN5QAAAaw"]
[Mon Jul 20 07:18:50.149385 2026] [security2:error] [pid 95126:tid 95171] [remote 57.141.18.108:40596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gOgpx5ks9joCJTKXN7gAB4io"]
[Mon Jul 20 07:18:50.188255 2026] [security2:error] [pid 94831:tid 95047] [client 103.176.215.66:54205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gOo06NaEKF1g_MW21pAAAAFY"]
[Mon Jul 20 07:18:50.188829 2026] [security2:error] [pid 94831:tid 95047] [client 103.176.215.66:54205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gOo06NaEKF1g_MW21pAAAAFY"]
[Mon Jul 20 07:18:50.258083 2026] [security2:error] [pid 95126:tid 95275] [client 77.110.127.138:63190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOgpx5ks9joCJTKXOAQAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.258190 2026] [security2:error] [pid 95126:tid 95275] [client 77.110.127.138:63190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOgpx5ks9joCJTKXOAQAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.277708 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOo06NaEKF1g_MW21pwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.277826 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOo06NaEKF1g_MW21pwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.294136 2026] [security2:error] [pid 94831:tid 95021] [client 154.208.48.130:53357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gOo06NaEKF1g_MW21qAAAADw"]
[Mon Jul 20 07:18:50.294251 2026] [security2:error] [pid 94831:tid 95021] [client 154.208.48.130:53357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gOo06NaEKF1g_MW21qAAAADw"]
[Mon Jul 20 07:18:50.308584 2026] [security2:error] [pid 95126:tid 95340] [client 49.37.242.14:53024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXOCwAAAeE"]
[Mon Jul 20 07:18:50.308688 2026] [security2:error] [pid 95126:tid 95340] [client 49.37.242.14:53024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXOCwAAAeE"]
[Mon Jul 20 07:18:50.351061 2026] [security2:error] [pid 95126:tid 95207] [remote 57.141.18.81:50782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gOgpx5ks9joCJTKXODgAB0U4"]
[Mon Jul 20 07:18:50.380489 2026] [security2:error] [pid 95126:tid 95154] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXODwAB1Bk"]
[Mon Jul 20 07:18:50.380599 2026] [security2:error] [pid 95126:tid 95327] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXODwAB1Bk"]
[Mon Jul 20 07:18:50.456287 2026] [security2:error] [pid 95126:tid 95276] [client 57.141.18.20:63918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gNwpx5ks9joCJTKXNVwABoRc"]
[Mon Jul 20 07:18:50.610837 2026] [security2:error] [pid 95126:tid 95233] [remote 57.141.18.81:50792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gOgpx5ks9joCJTKXOHQABpWg"]
[Mon Jul 20 07:18:50.893159 2026] [security2:error] [pid 95126:tid 95375] [client 77.110.127.138:63199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOgpx5ks9joCJTKXOLQAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.893282 2026] [security2:error] [pid 95126:tid 95375] [client 77.110.127.138:63199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOgpx5ks9joCJTKXOLQAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.901508 2026] [security2:error] [pid 95126:tid 95366] [client 157.20.138.62:49369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXOLgAAAfs"]
[Mon Jul 20 07:18:50.901643 2026] [security2:error] [pid 95126:tid 95366] [client 157.20.138.62:49369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gOgpx5ks9joCJTKXOLgAAAfs"]
[Mon Jul 20 07:18:50.906863 2026] [security2:error] [pid 95126:tid 95276] [client 77.110.127.138:63200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOgpx5ks9joCJTKXOLwAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.906954 2026] [security2:error] [pid 95126:tid 95276] [client 77.110.127.138:63200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOgpx5ks9joCJTKXOLwAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:50.945242 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gOgpx5ks9joCJTKXOMAAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.012630 2026] [security2:error] [pid 94831:tid 95056] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gOo06NaEKF1g_MW21swAAAF8"]
[Mon Jul 20 07:18:51.112560 2026] [security2:error] [pid 95126:tid 95335] [client 77.110.127.138:63201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOwpx5ks9joCJTKXOOgAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.112641 2026] [security2:error] [pid 95126:tid 95335] [client 77.110.127.138:63201] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOwpx5ks9joCJTKXOOgAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.114122 2026] [security2:error] [pid 95126:tid 95336] [client 77.110.127.138:63202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gOwpx5ks9joCJTKXOOwAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.114547 2026] [security2:error] [pid 94831:tid 95038] [client 57.141.18.38:65408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gOI06NaEKF1g_MW21iQAATTk"]
[Mon Jul 20 07:18:51.286148 2026] [security2:error] [pid 95126:tid 95292] [client 49.47.218.174:49967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gOwpx5ks9joCJTKXOVAAAAbE"]
[Mon Jul 20 07:18:51.286246 2026] [security2:error] [pid 95126:tid 95292] [client 49.47.218.174:49967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gOwpx5ks9joCJTKXOVAAAAbE"]
[Mon Jul 20 07:18:51.399137 2026] [security2:error] [pid 95126:tid 95286] [client 57.141.18.97:38584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gOApx5ks9joCJTKXNpAABq0A"]
[Mon Jul 20 07:18:51.468825 2026] [security2:error] [pid 95126:tid 95223] [remote 57.141.18.66:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gOwpx5ks9joCJTKXOXwAB9F4"]
[Mon Jul 20 07:18:51.549903 2026] [security2:error] [pid 95126:tid 95333] [client 57.141.18.95:56386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gOQpx5ks9joCJTKXNsAAB2gw"]
[Mon Jul 20 07:18:51.552222 2026] [security2:error] [pid 95126:tid 95214] [remote 57.141.18.94:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3376637"] [unique_id "al4gOwpx5ks9joCJTKXOYQABwVU"]
[Mon Jul 20 07:18:51.668274 2026] [security2:error] [pid 95126:tid 95314] [client 52.237.147.83:23747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gOwpx5ks9joCJTKXOaAAAAcc"]
[Mon Jul 20 07:18:51.720032 2026] [security2:error] [pid 95126:tid 95280] [client 52.237.147.83:23747] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gOwpx5ks9joCJTKXObQAAAaU"]
[Mon Jul 20 07:18:51.860114 2026] [security2:error] [pid 95126:tid 95289] [client 191.202.66.27:51530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gOwpx5ks9joCJTKXOeAAAAa4"]
[Mon Jul 20 07:18:51.860292 2026] [security2:error] [pid 95126:tid 95289] [client 191.202.66.27:51530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gOwpx5ks9joCJTKXOeAAAAa4"]
[Mon Jul 20 07:18:51.890497 2026] [security2:error] [pid 95126:tid 95266] [client 77.110.127.138:63182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gOwpx5ks9joCJTKXOewAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.890497 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOwpx5ks9joCJTKXOegAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.890593 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOwpx5ks9joCJTKXOegAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:51.902628 2026] [security2:error] [pid 95126:tid 95179] [remote 45.90.123.233:49310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4gOwpx5ks9joCJTKXOfAACBjI"]
[Mon Jul 20 07:18:51.988928 2026] [security2:error] [pid 95126:tid 95302] [client 77.110.127.138:63209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOwpx5ks9joCJTKXOgAAAAbs"]
[Mon Jul 20 07:18:51.989080 2026] [security2:error] [pid 95126:tid 95302] [client 77.110.127.138:63209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gOwpx5ks9joCJTKXOgAAAAbs"]
[Mon Jul 20 07:18:52.051568 2026] [security2:error] [pid 95126:tid 95263] [client 34.90.254.162:24577] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gPApx5ks9joCJTKXOhgAAAZQ"]
[Mon Jul 20 07:18:52.051693 2026] [security2:error] [pid 95126:tid 95263] [client 34.90.254.162:24577] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcalendars.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gPApx5ks9joCJTKXOhgAAAZQ"]
[Mon Jul 20 07:18:52.121480 2026] [security2:error] [pid 95126:tid 95135] [remote 45.90.123.233:49310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4gPApx5ks9joCJTKXOiwABwgY"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 07:18:52.363098 2026] [security2:error] [pid 95126:tid 95258] [client 57.141.18.95:56394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gOgpx5ks9joCJTKXN3gABjy8"]
[Mon Jul 20 07:18:52.386376 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPI06NaEKF1g_MW21ygAAAGg"]
[Mon Jul 20 07:18:52.386462 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63215] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPI06NaEKF1g_MW21ygAAAGg"]
[Mon Jul 20 07:18:52.431021 2026] [autoindex:error] [pid 95126:tid 95306] [client 147.93.171.188:63005] AH01276: Cannot serve directory /home4/tgslfgmy/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:18:52.455959 2026] [security2:error] [pid 95126:tid 95263] [client 77.110.127.138:63194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gPApx5ks9joCJTKXOrwAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:52.520282 2026] [security2:error] [pid 95126:tid 95328] [client 77.110.127.138:63217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPApx5ks9joCJTKXOsgAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:52.520369 2026] [security2:error] [pid 95126:tid 95328] [client 77.110.127.138:63217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPApx5ks9joCJTKXOsgAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:52.552743 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:63219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPApx5ks9joCJTKXOuAAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:52.552854 2026] [security2:error] [pid 95126:tid 95310] [client 77.110.127.138:63219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPApx5ks9joCJTKXOuAAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:52.621969 2026] [security2:error] [pid 95126:tid 95331] [client 77.110.127.138:63221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gPApx5ks9joCJTKXOvgAAAdg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:52.670078 2026] [security2:error] [pid 94831:tid 95077] [client 13.74.155.112:35137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gPI06NaEKF1g_MW210gAAAHQ"]
[Mon Jul 20 07:18:52.746561 2026] [security2:error] [pid 95126:tid 95288] [client 187.16.64.216:56902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gPApx5ks9joCJTKXOygAAAa0"]
[Mon Jul 20 07:18:52.746657 2026] [security2:error] [pid 95126:tid 95288] [client 187.16.64.216:56902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gPApx5ks9joCJTKXOygAAAa0"]
[Mon Jul 20 07:18:52.809880 2026] [security2:error] [pid 94831:tid 95081] [client 13.74.155.112:35137] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gPI06NaEKF1g_MW212AAAAHg"]
[Mon Jul 20 07:18:52.870178 2026] [security2:error] [pid 95126:tid 95317] [client 216.73.163.88:38181] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "onewingpictures.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4gPApx5ks9joCJTKXO0gAAAco"]
[Mon Jul 20 07:18:52.936771 2026] [security2:error] [pid 95126:tid 95365] [client 14.225.17.146:58019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4gOwpx5ks9joCJTKXOYwAAAfo"], referer: http://hammadownenterprises.com/2019
[Mon Jul 20 07:18:53.076876 2026] [security2:error] [pid 95126:tid 95262] [client 77.110.127.138:63227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPQpx5ks9joCJTKXO4AAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:53.076962 2026] [security2:error] [pid 95126:tid 95262] [client 77.110.127.138:63227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPQpx5ks9joCJTKXO4AAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:53.083853 2026] [security2:error] [pid 94831:tid 94999] [client 77.110.127.138:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gPY06NaEKF1g_MW212QAAACY"]
[Mon Jul 20 07:18:53.104375 2026] [security2:error] [pid 95126:tid 95322] [client 57.141.18.114:55040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gOgpx5ks9joCJTKXOJgABzyg"]
[Mon Jul 20 07:18:53.406925 2026] [security2:error] [pid 94831:tid 95088] [client 104.234.53.86:31571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gPY06NaEKF1g_MW213QAAAH8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:53.411230 2026] [security2:error] [pid 95126:tid 95338] [client 77.110.127.138:63169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gPQpx5ks9joCJTKXPIAAAAd8"]
[Mon Jul 20 07:18:53.488828 2026] [security2:error] [pid 95126:tid 95300] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gPQpx5ks9joCJTKXO9wAAAbk"]
[Mon Jul 20 07:18:53.526331 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPQpx5ks9joCJTKXPJwAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:53.526417 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPQpx5ks9joCJTKXPJwAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:53.644766 2026] [security2:error] [pid 95126:tid 95266] [client 77.110.127.138:63172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPQpx5ks9joCJTKXPMgAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:53.644874 2026] [security2:error] [pid 95126:tid 95266] [client 77.110.127.138:63172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPQpx5ks9joCJTKXPMgAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:53.684549 2026] [security2:error] [pid 95126:tid 95358] [client 103.106.165.44:55171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gPQpx5ks9joCJTKXPLwAAAfM"]
[Mon Jul 20 07:18:53.684648 2026] [security2:error] [pid 95126:tid 95358] [client 103.106.165.44:55171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gPQpx5ks9joCJTKXPLwAAAfM"]
[Mon Jul 20 07:18:53.823391 2026] [security2:error] [pid 95126:tid 95347] [client 154.192.123.127:17410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gPQpx5ks9joCJTKXPQAAAAeg"]
[Mon Jul 20 07:18:53.823513 2026] [security2:error] [pid 95126:tid 95347] [client 154.192.123.127:17410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gPQpx5ks9joCJTKXPQAAAAeg"]
[Mon Jul 20 07:18:54.044985 2026] [security2:error] [pid 94831:tid 94971] [client 84.247.167.104:34208] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5016.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW215QAAAAo"]
[Mon Jul 20 07:18:54.091543 2026] [security2:error] [pid 95126:tid 95264] [client 57.141.18.92:29192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gOwpx5ks9joCJTKXOXgABlWY"]
[Mon Jul 20 07:18:54.123172 2026] [security2:error] [pid 94831:tid 94977] [client 77.110.127.138:63241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPo06NaEKF1g_MW215gAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:54.123273 2026] [security2:error] [pid 94831:tid 94977] [client 77.110.127.138:63241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPo06NaEKF1g_MW215gAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:54.155881 2026] [security2:error] [pid 94831:tid 94915] [remote 91.142.222.105:37576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4gPo06NaEKF1g_MW215wAAVlM"]
[Mon Jul 20 07:18:54.156045 2026] [security2:error] [pid 94831:tid 95047] [client 91.142.222.105:37576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4gPo06NaEKF1g_MW215wAAVlM"]
[Mon Jul 20 07:18:54.218158 2026] [proxy:error] [pid 94831:tid 95021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:54.218199 2026] [proxy_http:error] [pid 94831:tid 95021] [client 8.229.28.226:58516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:54.218612 2026] [security2:error] [pid 94831:tid 95064] [client 84.247.167.104:50620] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5020.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW216wAAAGc"]
[Mon Jul 20 07:18:54.218944 2026] [proxy:error] [pid 94831:tid 95021] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:54.218980 2026] [proxy_http:error] [pid 94831:tid 95021] [client 8.229.28.226:58516] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:54.286773 2026] [security2:error] [pid 94831:tid 95026] [client 77.110.127.138:63243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPo06NaEKF1g_MW218QAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:54.286921 2026] [security2:error] [pid 94831:tid 95026] [client 77.110.127.138:63243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPo06NaEKF1g_MW218QAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:54.333884 2026] [security2:error] [pid 94831:tid 94969] [client 84.247.167.104:33120] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5023.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW218gAAAAg"]
[Mon Jul 20 07:18:54.433872 2026] [security2:error] [pid 95126:tid 95324] [client 64.233.173.201:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4gPgpx5ks9joCJTKXPVgAAAdE"]
[Mon Jul 20 07:18:54.480157 2026] [security2:error] [pid 94831:tid 95074] [client 84.247.167.104:49576] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5028.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW219wAAAHE"]
[Mon Jul 20 07:18:54.485348 2026] [security2:error] [pid 94831:tid 95071] [client 84.247.167.104:34210] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW21-AAAAG4"]
[Mon Jul 20 07:18:54.560236 2026] [security2:error] [pid 95126:tid 95331] [client 104.234.53.59:51153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gPgpx5ks9joCJTKXPdwAAAdg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:54.612828 2026] [security2:error] [pid 95126:tid 95293] [client 84.247.167.104:56044] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5033.bluehost.com"] [uri "/news/"] [unique_id "al4gPgpx5ks9joCJTKXPewAAAbI"]
[Mon Jul 20 07:18:54.651296 2026] [security2:error] [pid 95126:tid 95357] [client 57.141.18.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gPgpx5ks9joCJTKXPcQAAAfI"]
[Mon Jul 20 07:18:54.671438 2026] [security2:error] [pid 95126:tid 95326] [client 84.247.167.104:50622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5020.bluehost.com"] [uri "/news/"] [unique_id "al4gPgpx5ks9joCJTKXPfQAAAdM"]
[Mon Jul 20 07:18:54.768010 2026] [security2:error] [pid 94831:tid 95005] [client 84.247.167.104:33126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW22BQAAACw"]
[Mon Jul 20 07:18:54.924113 2026] [security2:error] [pid 94831:tid 94982] [client 84.247.167.104:34212] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW22CwAAABU"]
[Mon Jul 20 07:18:54.927911 2026] [security2:error] [pid 94831:tid 94962] [client 84.247.167.104:49578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/news/"] [unique_id "al4gPo06NaEKF1g_MW22DAAAAAE"]
[Mon Jul 20 07:18:54.927944 2026] [security2:error] [pid 95126:tid 95325] [client 201.27.111.74:57374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gPgpx5ks9joCJTKXPiAAAAdI"]
[Mon Jul 20 07:18:54.928027 2026] [security2:error] [pid 95126:tid 95325] [client 201.27.111.74:57374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gPgpx5ks9joCJTKXPiAAAAdI"]
[Mon Jul 20 07:18:55.049771 2026] [security2:error] [pid 94831:tid 95054] [client 84.247.167.104:56046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5033.bluehost.com"] [uri "/news/"] [unique_id "al4gP406NaEKF1g_MW22DwAAAF0"]
[Mon Jul 20 07:18:55.118879 2026] [security2:error] [pid 94831:tid 94967] [client 84.247.167.104:50624] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/news/"] [unique_id "al4gP406NaEKF1g_MW22EwAAAAY"]
[Mon Jul 20 07:18:55.192515 2026] [security2:error] [pid 94831:tid 94965] [client 84.247.167.104:33130] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/news/"] [unique_id "al4gP406NaEKF1g_MW22GQAAAAQ"]
[Mon Jul 20 07:18:55.201957 2026] [security2:error] [pid 94831:tid 94939] [remote 162.19.86.63:42163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4gP406NaEKF1g_MW22GAAAeGs"]
[Mon Jul 20 07:18:55.339705 2026] [security2:error] [pid 94831:tid 94999] [client 117.211.236.168:62189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gP406NaEKF1g_MW22IAAAACY"]
[Mon Jul 20 07:18:55.339794 2026] [security2:error] [pid 94831:tid 94999] [client 117.211.236.168:62189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gP406NaEKF1g_MW22IAAAACY"]
[Mon Jul 20 07:18:55.375819 2026] [security2:error] [pid 94831:tid 94975] [client 84.247.167.104:49580] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/news/"] [unique_id "al4gP406NaEKF1g_MW22IQAAAA4"]
[Mon Jul 20 07:18:55.403168 2026] [proxy:error] [pid 94831:tid 95008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:55.403202 2026] [proxy_http:error] [pid 94831:tid 95008] [client 8.229.28.226:59158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:55.403608 2026] [proxy:error] [pid 94831:tid 95008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:55.403631 2026] [proxy_http:error] [pid 94831:tid 95008] [client 8.229.28.226:59158] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:55.494915 2026] [security2:error] [pid 94831:tid 94979] [client 84.247.167.104:56048] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5033.bluehost.com"] [uri "/news/"] [unique_id "al4gP406NaEKF1g_MW22LAAAABI"]
[Mon Jul 20 07:18:55.525807 2026] [security2:error] [pid 94831:tid 94943] [remote 162.19.86.63:42163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4gP406NaEKF1g_MW22LQAAbm8"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 07:18:55.592426 2026] [security2:error] [pid 94831:tid 95021] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gP406NaEKF1g_MW22HgAAADw"]
[Mon Jul 20 07:18:55.648368 2026] [security2:error] [pid 95126:tid 95263] [client 57.141.18.90:53676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gPApx5ks9joCJTKXO2QABlEU"]
[Mon Jul 20 07:18:55.764347 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:63247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPwpx5ks9joCJTKXPsgAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:55.764472 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:63247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gPwpx5ks9joCJTKXPsgAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:55.851387 2026] [security2:error] [pid 94831:tid 95016] [client 74.7.227.179:42156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4gP406NaEKF1g_MW22MAAAN3U"], referer: https://tejasenvironmental.com/p=168752
[Mon Jul 20 07:18:56.372968 2026] [security2:error] [pid 95126:tid 95272] [client 50.116.65.227:56420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gQApx5ks9joCJTKXP1AAAAZ0"]
[Mon Jul 20 07:18:56.384337 2026] [security2:error] [pid 94831:tid 94998] [client 50.116.65.227:52406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gQI06NaEKF1g_MW22PQAAAHo"]
[Mon Jul 20 07:18:56.746633 2026] [security2:error] [pid 94831:tid 94996] [client 77.110.127.138:63218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQI06NaEKF1g_MW22UAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:56.746725 2026] [security2:error] [pid 94831:tid 94996] [client 77.110.127.138:63218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQI06NaEKF1g_MW22UAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:56.932151 2026] [security2:error] [pid 94831:tid 95026] [client 77.110.127.138:63256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQI06NaEKF1g_MW22UwAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:56.932279 2026] [security2:error] [pid 94831:tid 95026] [client 77.110.127.138:63256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQI06NaEKF1g_MW22UwAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.209577 2026] [security2:error] [pid 95126:tid 95286] [client 104.234.53.61:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gQQpx5ks9joCJTKXQGQAAAas"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:18:57.235235 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:63261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQGgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.235338 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:63261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQGgAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.310986 2026] [autoindex:error] [pid 95126:tid 95178] [remote 34.169.253.58:51550] AH01276: Cannot serve directory /home2/elvxwymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://elv.xwy.mybluehost.me
[Mon Jul 20 07:18:57.317339 2026] [security2:error] [pid 95126:tid 95312] [client 18.193.252.127:40586] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4gQApx5ks9joCJTKXP1gAAAcU"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:18:57.380135 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQIwAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.380258 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQIwAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.393983 2026] [security2:error] [pid 95126:tid 95290] [client 103.144.65.217:54705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gQQpx5ks9joCJTKXQJAAAAa8"]
[Mon Jul 20 07:18:57.395601 2026] [security2:error] [pid 95126:tid 95290] [client 103.144.65.217:54705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gQQpx5ks9joCJTKXQJAAAAa8"]
[Mon Jul 20 07:18:57.432584 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:63236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQJgAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.432685 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:63236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQJgAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.530278 2026] [security2:error] [pid 95126:tid 95324] [client 14.225.17.146:63561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4gQApx5ks9joCJTKXPyQAAAdE"], referer: http://dnsplumbing.com/2019
[Mon Jul 20 07:18:57.589438 2026] [security2:error] [pid 95126:tid 95285] [client 77.110.127.138:63267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQMgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.589554 2026] [security2:error] [pid 95126:tid 95285] [client 77.110.127.138:63267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQMgAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.677662 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:63204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQPwAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.677788 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:63204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQPwAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.905955 2026] [security2:error] [pid 95126:tid 95303] [client 85.204.70.112:58376] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4gQQpx5ks9joCJTKXQSQAAAbw"]
[Mon Jul 20 07:18:57.945623 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQSgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:57.945761 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQQpx5ks9joCJTKXQSgAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:58.019459 2026] [security2:error] [pid 94831:tid 95034] [client 14.225.17.146:64113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4gQY06NaEKF1g_MW22ZAAAAEk"]
[Mon Jul 20 07:18:58.381185 2026] [security2:error] [pid 95126:tid 95317] [client 57.141.18.51:47460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gPwpx5ks9joCJTKXPvQAByjU"]
[Mon Jul 20 07:18:58.429278 2026] [security2:error] [pid 94831:tid 95077] [client 85.204.70.112:47404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gQo06NaEKF1g_MW22bwAAAHQ"]
[Mon Jul 20 07:18:58.523929 2026] [proxy:error] [pid 95126:tid 95283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:58.523977 2026] [proxy_http:error] [pid 95126:tid 95283] [client 8.229.28.226:42348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:58.524558 2026] [proxy:error] [pid 95126:tid 95283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:18:58.524585 2026] [proxy_http:error] [pid 95126:tid 95283] [client 8.229.28.226:42348] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:18:58.730789 2026] [security2:error] [pid 94831:tid 95067] [client 14.225.17.146:64321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4gQo06NaEKF1g_MW22bQAAAGo"]
[Mon Jul 20 07:18:58.772235 2026] [security2:error] [pid 95126:tid 95379] [client 77.110.127.138:63248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQgpx5ks9joCJTKXQhAAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:58.772358 2026] [security2:error] [pid 95126:tid 95379] [client 77.110.127.138:63248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQgpx5ks9joCJTKXQhAAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:58.830533 2026] [security2:error] [pid 94831:tid 95055] [client 57.141.18.103:27344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gQI06NaEKF1g_MW22PAAAXl8"]
[Mon Jul 20 07:18:58.847486 2026] [core:error] [pid 95126:tid 95306] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:58.847506 2026] [core:error] [pid 95126:tid 95306] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:18:59.032687 2026] [security2:error] [pid 95126:tid 95266] [client 50.116.65.227:19624] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gQwpx5ks9joCJTKXQlwAAAZc"]
[Mon Jul 20 07:18:59.045777 2026] [security2:error] [pid 95126:tid 95282] [client 50.116.65.227:19628] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gQwpx5ks9joCJTKXQmgAAAac"]
[Mon Jul 20 07:18:59.105760 2026] [security2:error] [pid 95126:tid 95371] [client 57.141.18.4:39418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gQApx5ks9joCJTKXP4wACAFY"]
[Mon Jul 20 07:18:59.492314 2026] [security2:error] [pid 94831:tid 95013] [client 14.225.17.146:57905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4gQ406NaEKF1g_MW22fwAAADQ"], referer: http://daseighty.net/2019
[Mon Jul 20 07:18:59.675510 2026] [security2:error] [pid 94831:tid 94834] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gQ406NaEKF1g_MW22hgAAfAI"]
[Mon Jul 20 07:18:59.675633 2026] [security2:error] [pid 94831:tid 95085] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gQ406NaEKF1g_MW22hgAAfAI"]
[Mon Jul 20 07:18:59.700797 2026] [security2:error] [pid 95126:tid 95359] [client 77.110.127.138:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQwpx5ks9joCJTKXQxQAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:59.700908 2026] [security2:error] [pid 95126:tid 95359] [client 77.110.127.138:63254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQwpx5ks9joCJTKXQxQAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:59.769492 2026] [security2:error] [pid 94831:tid 94860] [remote 47.86.33.52:13882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4gQ406NaEKF1g_MW22iQAAJRw"]
[Mon Jul 20 07:18:59.850745 2026] [security2:error] [pid 95126:tid 95330] [client 77.110.127.138:63281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQwpx5ks9joCJTKXQzQAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:18:59.850865 2026] [security2:error] [pid 95126:tid 95330] [client 77.110.127.138:63281] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gQwpx5ks9joCJTKXQzQAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:00.001455 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:63282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRApx5ks9joCJTKXQ2AAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:00.001542 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:63282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRApx5ks9joCJTKXQ2AAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:00.032778 2026] [security2:error] [pid 94831:tid 95048] [client 57.141.18.47:27986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gQY06NaEKF1g_MW22WQAAV2g"]
[Mon Jul 20 07:19:00.064201 2026] [security2:error] [pid 95126:tid 95324] [client 77.110.127.138:63258] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gRApx5ks9joCJTKXQ3AAAAdE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:00.099904 2026] [security2:error] [pid 95126:tid 95307] [client 85.204.70.112:47408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4gRApx5ks9joCJTKXQ4AAAAcA"]
[Mon Jul 20 07:19:00.178850 2026] [security2:error] [pid 94831:tid 94953] [remote 47.86.33.52:13882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4gRI06NaEKF1g_MW22lgAAJnk"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:19:00.219492 2026] [proxy:error] [pid 94831:tid 95024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:00.219537 2026] [proxy_http:error] [pid 94831:tid 95024] [client 8.229.28.226:55714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:00.220155 2026] [proxy:error] [pid 94831:tid 95024] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:00.220182 2026] [proxy_http:error] [pid 94831:tid 95024] [client 8.229.28.226:55714] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:00.489731 2026] [security2:error] [pid 95126:tid 95267] [client 143.44.185.218:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gRApx5ks9joCJTKXQ-AAAAZg"]
[Mon Jul 20 07:19:00.492605 2026] [security2:error] [pid 95126:tid 95267] [client 143.44.185.218:63790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gRApx5ks9joCJTKXQ-AAAAZg"]
[Mon Jul 20 07:19:00.540908 2026] [security2:error] [pid 95126:tid 95286] [client 85.204.70.112:47418] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4gRApx5ks9joCJTKXQ_AAAAas"]
[Mon Jul 20 07:19:00.777092 2026] [security2:error] [pid 95126:tid 95332] [client 88.241.67.160:53570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gRApx5ks9joCJTKXRDAAAAdk"]
[Mon Jul 20 07:19:00.777431 2026] [security2:error] [pid 95126:tid 95332] [client 88.241.67.160:53570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gRApx5ks9joCJTKXRDAAAAdk"]
[Mon Jul 20 07:19:00.927029 2026] [security2:error] [pid 95126:tid 95266] [client 103.176.215.66:54733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gRApx5ks9joCJTKXRFgAAAZc"]
[Mon Jul 20 07:19:00.927414 2026] [security2:error] [pid 95126:tid 95266] [client 103.176.215.66:54733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gRApx5ks9joCJTKXRFgAAAZc"]
[Mon Jul 20 07:19:01.011146 2026] [security2:error] [pid 94831:tid 95057] [client 85.204.70.112:47420] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4gRY06NaEKF1g_MW22rgAAAGA"]
[Mon Jul 20 07:19:01.020687 2026] [security2:error] [pid 95126:tid 95321] [client 45.157.112.60:25427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gRQpx5ks9joCJTKXRGwAAAc4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:01.035819 2026] [security2:error] [pid 94831:tid 94975] [client 82.23.206.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gRI06NaEKF1g_MW22lAAAAA4"]
[Mon Jul 20 07:19:01.040742 2026] [security2:error] [pid 95126:tid 95183] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRHwABpjY"]
[Mon Jul 20 07:19:01.040919 2026] [security2:error] [pid 95126:tid 95281] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRHwABpjY"]
[Mon Jul 20 07:19:01.157273 2026] [security2:error] [pid 95126:tid 95289] [client 57.141.18.62:33840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gQgpx5ks9joCJTKXQeQABrg0"]
[Mon Jul 20 07:19:01.193385 2026] [security2:error] [pid 95126:tid 95314] [client 104.234.53.56:64775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gRQpx5ks9joCJTKXRLwAAAcc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:01.193872 2026] [security2:error] [pid 95126:tid 95342] [client 57.141.18.87:61218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gQgpx5ks9joCJTKXQfgAB400"]
[Mon Jul 20 07:19:01.289415 2026] [security2:error] [pid 95126:tid 95304] [client 154.208.48.130:53867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRPgAAAb0"]
[Mon Jul 20 07:19:01.289594 2026] [security2:error] [pid 95126:tid 95304] [client 154.208.48.130:53867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRPgAAAb0"]
[Mon Jul 20 07:19:01.354345 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRQpx5ks9joCJTKXRQgAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:01.354453 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRQpx5ks9joCJTKXRQgAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:01.395703 2026] [security2:error] [pid 95126:tid 95299] [client 14.225.17.146:61602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4gQwpx5ks9joCJTKXQxwAAAbg"], referer: http://nomorewetsheets.net/2019
[Mon Jul 20 07:19:01.405769 2026] [security2:error] [pid 95126:tid 95366] [client 77.110.127.138:63297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gRQpx5ks9joCJTKXRRQAAAfs"], referer: https://mezzacraft.com/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/?action=pys_get_gdpr_filters_values
[Mon Jul 20 07:19:01.470952 2026] [security2:error] [pid 95126:tid 95279] [client 157.20.138.62:49949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRRwAAAaQ"]
[Mon Jul 20 07:19:01.471129 2026] [security2:error] [pid 95126:tid 95279] [client 157.20.138.62:49949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRRwAAAaQ"]
[Mon Jul 20 07:19:01.574854 2026] [security2:error] [pid 94831:tid 95013] [client 50.116.65.227:15912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gRY06NaEKF1g_MW22vQAAADQ"]
[Mon Jul 20 07:19:01.586495 2026] [security2:error] [pid 94831:tid 94978] [client 50.116.65.227:19632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4gRY06NaEKF1g_MW22vgAAAAM"]
[Mon Jul 20 07:19:01.624069 2026] [security2:error] [pid 94831:tid 95039] [client 85.204.70.112:47424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4gRY06NaEKF1g_MW22vwAAAE4"]
[Mon Jul 20 07:19:01.662425 2026] [security2:error] [pid 95126:tid 95264] [client 49.47.218.174:50469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRTAAAAZU"]
[Mon Jul 20 07:19:01.662601 2026] [security2:error] [pid 95126:tid 95264] [client 49.47.218.174:50469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRTAAAAZU"]
[Mon Jul 20 07:19:01.813434 2026] [autoindex:error] [pid 95126:tid 95357] [client 136.66.235.77:0] AH01276: Cannot serve directory /home2/bluestm2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.suq.iks.mybluehost.me
[Mon Jul 20 07:19:01.966409 2026] [security2:error] [pid 94831:tid 94965] [client 158.173.241.141:21223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4gRY06NaEKF1g_MW22wQAAAAQ"], referer: http://sesamegreenbeans.com/category/travel/
[Mon Jul 20 07:19:01.981526 2026] [security2:error] [pid 95126:tid 95280] [client 49.37.242.14:53505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRcwAAAaU"]
[Mon Jul 20 07:19:01.981664 2026] [security2:error] [pid 95126:tid 95280] [client 49.37.242.14:53505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gRQpx5ks9joCJTKXRcwAAAaU"]
[Mon Jul 20 07:19:02.007364 2026] [security2:error] [pid 95126:tid 95248] [remote 103.118.29.185:33388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gRQpx5ks9joCJTKXRdAABl3c"]
[Mon Jul 20 07:19:02.042190 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:63303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRdwAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.042285 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:63303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRdwAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.106835 2026] [security2:error] [pid 94831:tid 94969] [client 85.204.70.112:47436] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4gRo06NaEKF1g_MW22xwAAAAg"]
[Mon Jul 20 07:19:02.153957 2026] [security2:error] [pid 95126:tid 95344] [client 77.110.127.138:63251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRfgAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.154082 2026] [security2:error] [pid 95126:tid 95344] [client 77.110.127.138:63251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRfgAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.207041 2026] [security2:error] [pid 95126:tid 95272] [client 77.110.127.138:63249] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gRgpx5ks9joCJTKXRhAAAAZ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.229093 2026] [security2:error] [pid 95126:tid 95368] [client 77.110.127.138:63274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRhgAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.229256 2026] [security2:error] [pid 95126:tid 95368] [client 77.110.127.138:63274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRhgAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.378738 2026] [security2:error] [pid 95126:tid 95357] [client 77.110.127.138:63305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRkgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.378829 2026] [security2:error] [pid 95126:tid 95357] [client 77.110.127.138:63305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRkgAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.431987 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:63277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRlwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.432111 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:63277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRlwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.433417 2026] [security2:error] [pid 95126:tid 95191] [remote 103.118.29.185:33388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gRgpx5ks9joCJTKXRmAABpT4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:19:02.450673 2026] [security2:error] [pid 94831:tid 94993] [client 158.173.89.95:49379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gRo06NaEKF1g_MW22zgAAACA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:02.452863 2026] [security2:error] [pid 95126:tid 95262] [client 191.202.66.27:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gRgpx5ks9joCJTKXRmwAAAZM"]
[Mon Jul 20 07:19:02.452967 2026] [security2:error] [pid 95126:tid 95262] [client 191.202.66.27:51991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gRgpx5ks9joCJTKXRmwAAAZM"]
[Mon Jul 20 07:19:02.555908 2026] [security2:error] [pid 94831:tid 94864] [remote 81.173.115.7:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gRo06NaEKF1g_MW220QAAJiA"]
[Mon Jul 20 07:19:02.590308 2026] [security2:error] [pid 95126:tid 95347] [client 77.110.127.138:63306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRrQAAAeg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.590451 2026] [security2:error] [pid 95126:tid 95347] [client 77.110.127.138:63306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRrQAAAeg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:02.625369 2026] [security2:error] [pid 95126:tid 95258] [client 85.204.70.112:47440] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4gRgpx5ks9joCJTKXRsQAAAY8"]
[Mon Jul 20 07:19:02.650371 2026] [security2:error] [pid 95126:tid 95348] [client 34.90.66.217:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "vergotek.com.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gRgpx5ks9joCJTKXRtAAAAek"]
[Mon Jul 20 07:19:02.650457 2026] [security2:error] [pid 95126:tid 95348] [client 34.90.66.217:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "vergotek.com.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gRgpx5ks9joCJTKXRtAAAAek"]
[Mon Jul 20 07:19:02.662757 2026] [security2:error] [pid 95126:tid 95329] [client 50.116.65.227:15920] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4gRgpx5ks9joCJTKXRtgAAAdY"]
[Mon Jul 20 07:19:02.677099 2026] [security2:error] [pid 95126:tid 95283] [client 50.116.65.227:19674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4gRgpx5ks9joCJTKXRtwAAAag"]
[Mon Jul 20 07:19:02.776990 2026] [security2:error] [pid 95126:tid 95346] [client 77.110.127.138:63309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRwwAAAec"]
[Mon Jul 20 07:19:02.777113 2026] [security2:error] [pid 95126:tid 95346] [client 77.110.127.138:63309] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRgpx5ks9joCJTKXRwwAAAec"]
[Mon Jul 20 07:19:02.817696 2026] [security2:error] [pid 94831:tid 94854] [remote 81.173.115.7:45040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gRo06NaEKF1g_MW222AAASBY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:19:03.021011 2026] [security2:error] [pid 94831:tid 95036] [client 57.141.18.64:39574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gRI06NaEKF1g_MW22ngAAS3w"]
[Mon Jul 20 07:19:03.199218 2026] [security2:error] [pid 95126:tid 95309] [client 14.225.17.146:61423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4gRgpx5ks9joCJTKXRdgAAAcI"], referer: http://sarahholyfield.com/2019
[Mon Jul 20 07:19:03.218119 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:63310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRwpx5ks9joCJTKXR5QAAAZI"]
[Mon Jul 20 07:19:03.218222 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:63310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gRwpx5ks9joCJTKXR5QAAAZI"]
[Mon Jul 20 07:19:03.348905 2026] [core:error] [pid 94831:tid 95016] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:03.348927 2026] [core:error] [pid 94831:tid 95016] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:03.361869 2026] [security2:error] [pid 95126:tid 95357] [client 187.16.64.216:57493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gRwpx5ks9joCJTKXR9QAAAfI"]
[Mon Jul 20 07:19:03.361961 2026] [security2:error] [pid 95126:tid 95357] [client 187.16.64.216:57493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gRwpx5ks9joCJTKXR9QAAAfI"]
[Mon Jul 20 07:19:03.604090 2026] [security2:error] [pid 95126:tid 95259] [client 85.204.70.112:47448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4gRwpx5ks9joCJTKXSBQAAAZA"]
[Mon Jul 20 07:19:03.629314 2026] [security2:error] [pid 95126:tid 95319] [client 57.141.18.69:54386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gRQpx5ks9joCJTKXRMQABzHo"]
[Mon Jul 20 07:19:03.652075 2026] [security2:error] [pid 95126:tid 95138] [remote 182.77.62.24:45272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4gRwpx5ks9joCJTKXSCgABuQk"]
[Mon Jul 20 07:19:03.652221 2026] [security2:error] [pid 95126:tid 95300] [client 182.77.62.24:45272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4gRwpx5ks9joCJTKXSCgABuQk"]
[Mon Jul 20 07:19:03.907983 2026] [security2:error] [pid 94831:tid 94962] [client 158.173.166.181:56053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gR406NaEKF1g_MW228QAAAAE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:03.908782 2026] [security2:error] [pid 95126:tid 95313] [client 103.106.165.44:55802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gRwpx5ks9joCJTKXSJAAAAcY"]
[Mon Jul 20 07:19:03.908867 2026] [security2:error] [pid 95126:tid 95313] [client 103.106.165.44:55802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gRwpx5ks9joCJTKXSJAAAAcY"]
[Mon Jul 20 07:19:03.979824 2026] [security2:error] [pid 95126:tid 95304] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gRwpx5ks9joCJTKXSCwAAAb0"]
[Mon Jul 20 07:19:04.108508 2026] [security2:error] [pid 95126:tid 95291] [client 85.204.70.112:47456] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4gSApx5ks9joCJTKXSOAAAAbA"]
[Mon Jul 20 07:19:04.233915 2026] [security2:error] [pid 95126:tid 95258] [client 54.184.226.94:54799] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thecreole.com"] [uri "/"] [unique_id "al4gSApx5ks9joCJTKXSRAAAAY8"]
[Mon Jul 20 07:19:04.235216 2026] [security2:error] [pid 95126:tid 95278] [client 54.184.226.94:4219] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "TRACE" at REQUEST_METHOD. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "52"] [id "340002"] [rev "3"] [msg "Atomicorp.com WAF Rules: TRACE/TRACK method denied"] [severity "CRITICAL"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4gSApx5ks9joCJTKXSRwAAAaM"]
[Mon Jul 20 07:19:04.241797 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:63284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gSI06NaEKF1g_MW22_AAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:04.241900 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:63284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gSI06NaEKF1g_MW22_AAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:04.338644 2026] [security2:error] [pid 95126:tid 95368] [client 54.184.226.94:35943] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4gSApx5ks9joCJTKXSSwAAAf0"], referer: https://www.google.com/images/url
[Mon Jul 20 07:19:04.366037 2026] [security2:error] [pid 94831:tid 95017] [client 154.192.123.127:17812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gSI06NaEKF1g_MW23AAAAADg"]
[Mon Jul 20 07:19:04.366143 2026] [security2:error] [pid 94831:tid 95017] [client 154.192.123.127:17812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gSI06NaEKF1g_MW23AAAAADg"]
[Mon Jul 20 07:19:04.416922 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63315] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gSApx5ks9joCJTKXSVwAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:04.533080 2026] [security2:error] [pid 95126:tid 95293] [client 85.204.70.112:47468] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4gSApx5ks9joCJTKXSXgAAAbI"]
[Mon Jul 20 07:19:04.570912 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gSApx5ks9joCJTKXSYAAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:04.571022 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gSApx5ks9joCJTKXSYAAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:04.690846 2026] [security2:error] [pid 95126:tid 95372] [client 14.225.17.146:61759] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4gRwpx5ks9joCJTKXSDAAAAgE"], referer: http://nikkidesigns.net/2019
[Mon Jul 20 07:19:04.692322 2026] [security2:error] [pid 95126:tid 95311] [client 57.141.18.12:38144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gRgpx5ks9joCJTKXRfAABxCw"]
[Mon Jul 20 07:19:04.862168 2026] [security2:error] [pid 94831:tid 95064] [client 14.225.17.146:61475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4gSI06NaEKF1g_MW23BwAAAGc"], referer: http://adultdaycarereno.com/2019
[Mon Jul 20 07:19:04.950454 2026] [security2:error] [pid 95126:tid 95375] [client 85.204.70.112:47484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4gSApx5ks9joCJTKXSeQAAAgQ"]
[Mon Jul 20 07:19:05.046227 2026] [security2:error] [pid 95126:tid 95373] [client 57.141.18.40:34546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gRgpx5ks9joCJTKXRmgACAjQ"]
[Mon Jul 20 07:19:05.246080 2026] [security2:error] [pid 95126:tid 95222] [remote 217.61.143.92:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4gSQpx5ks9joCJTKXSigAB010"]
[Mon Jul 20 07:19:05.390613 2026] [security2:error] [pid 94831:tid 95059] [client 201.27.111.74:57879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gSY06NaEKF1g_MW23HAAAAGI"]
[Mon Jul 20 07:19:05.390785 2026] [security2:error] [pid 94831:tid 95059] [client 201.27.111.74:57879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gSY06NaEKF1g_MW23HAAAAGI"]
[Mon Jul 20 07:19:05.468075 2026] [security2:error] [pid 95126:tid 95196] [remote 217.61.143.92:56660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4gSQpx5ks9joCJTKXSlAAB4UM"], referer: https://detroitcsc.com/wp-login.php
[Mon Jul 20 07:19:05.638862 2026] [security2:error] [pid 94831:tid 94961] [client 14.225.17.146:53328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4gSY06NaEKF1g_MW23IAAAAAA"], referer: http://alchemygroup.ca/2019
[Mon Jul 20 07:19:05.728028 2026] [security2:error] [pid 95126:tid 95333] [client 85.204.70.112:47488] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4gSQpx5ks9joCJTKXSrQAAAdo"]
[Mon Jul 20 07:19:05.889057 2026] [security2:error] [pid 95126:tid 95295] [client 14.225.17.146:61777] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4gSQpx5ks9joCJTKXSswAAAbQ"], referer: https://adultdaycarereno.com/2019
[Mon Jul 20 07:19:05.985089 2026] [security2:error] [pid 95126:tid 95319] [client 14.225.17.146:60814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4gSQpx5ks9joCJTKXSmgAAAcw"], referer: http://idigress.group/2019
[Mon Jul 20 07:19:06.088842 2026] [security2:error] [pid 95126:tid 95267] [client 57.141.18.43:34952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gRwpx5ks9joCJTKXSDQABmCE"]
[Mon Jul 20 07:19:06.230057 2026] [core:error] [pid 94831:tid 95017] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:06.230083 2026] [core:error] [pid 94831:tid 95017] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:06.271035 2026] [security2:error] [pid 95126:tid 95272] [client 57.141.18.125:62012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gRwpx5ks9joCJTKXSJwABnW8"]
[Mon Jul 20 07:19:06.341383 2026] [security2:error] [pid 95126:tid 95151] [remote 182.77.62.24:45288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4gSgpx5ks9joCJTKXS0wABsxY"]
[Mon Jul 20 07:19:06.345102 2026] [core:error] [pid 95126:tid 95300] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:06.345128 2026] [core:error] [pid 95126:tid 95300] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:06.378189 2026] [security2:error] [pid 95126:tid 95352] [client 216.73.216.156:27083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4gSgpx5ks9joCJTKXSxwAB7XU"]
[Mon Jul 20 07:19:06.445063 2026] [security2:error] [pid 95126:tid 95286] [client 57.141.18.96:22962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gSApx5ks9joCJTKXSNQABq2o"]
[Mon Jul 20 07:19:06.568681 2026] [security2:error] [pid 95126:tid 95280] [client 104.234.53.81:50905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gSgpx5ks9joCJTKXS4QAAAaU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:06.589099 2026] [fcgid:warn] [pid 95126:tid 95343] (70014)End of file found: [client 103.168.67.159:22710] mod_fcgid: can't get data from http client
[Mon Jul 20 07:19:06.590665 2026] [proxy:error] [pid 94831:tid 95054] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:06.590700 2026] [proxy_http:error] [pid 94831:tid 95054] [client 107.172.180.205:44876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:06.591345 2026] [proxy:error] [pid 94831:tid 95054] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:06.591369 2026] [proxy_http:error] [pid 94831:tid 95054] [client 107.172.180.205:44876] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:06.704235 2026] [security2:error] [pid 95126:tid 95304] [client 85.204.70.112:47504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4gSgpx5ks9joCJTKXTDAAAAb0"]
[Mon Jul 20 07:19:06.830348 2026] [security2:error] [pid 95126:tid 95142] [remote 182.77.62.24:45288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4gSgpx5ks9joCJTKXTGQABrw0"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 07:19:07.002425 2026] [security2:error] [pid 95126:tid 95137] [remote 20.173.88.122:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4gSgpx5ks9joCJTKXTIAABqgg"]
[Mon Jul 20 07:19:07.227744 2026] [security2:error] [pid 95126:tid 95377] [client 85.204.70.112:47506] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4gSwpx5ks9joCJTKXTPQAAAgY"]
[Mon Jul 20 07:19:07.248742 2026] [security2:error] [pid 94831:tid 95079] [client 172.245.102.64:47927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4gSY06NaEKF1g_MW23LQAAAHY"]
[Mon Jul 20 07:19:07.271440 2026] [security2:error] [pid 95126:tid 95278] [client 193.36.225.9:27729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4gSQpx5ks9joCJTKXStgAAAaM"]
[Mon Jul 20 07:19:07.342590 2026] [security2:error] [pid 95126:tid 95207] [remote 20.173.88.122:38512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4gSwpx5ks9joCJTKXTQwAB3k4"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:19:07.496930 2026] [security2:error] [pid 94831:tid 94995] [client 57.141.18.117:43220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gSY06NaEKF1g_MW23HgAAIjM"]
[Mon Jul 20 07:19:07.585727 2026] [security2:error] [pid 94831:tid 94984] [client 77.110.127.138:63336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gS406NaEKF1g_MW23TwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:07.585847 2026] [security2:error] [pid 94831:tid 94984] [client 77.110.127.138:63336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gS406NaEKF1g_MW23TwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:07.604051 2026] [security2:error] [pid 94831:tid 94982] [client 57.141.18.85:25466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gSY06NaEKF1g_MW23IQAAFTI"]
[Mon Jul 20 07:19:07.722867 2026] [security2:error] [pid 94831:tid 94981] [client 85.204.70.112:47512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4gS406NaEKF1g_MW23UgAAABQ"]
[Mon Jul 20 07:19:07.827731 2026] [security2:error] [pid 95126:tid 95133] [remote 57.141.18.122:41938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5138828"] [unique_id "al4gSwpx5ks9joCJTKXTYgABuAQ"]
[Mon Jul 20 07:19:07.858304 2026] [proxy:error] [pid 95126:tid 95324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:07.858348 2026] [proxy_http:error] [pid 95126:tid 95324] [client 107.172.180.205:44900] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:07.858992 2026] [proxy:error] [pid 95126:tid 95324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:07.859019 2026] [proxy_http:error] [pid 95126:tid 95324] [client 107.172.180.205:44900] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:07.922330 2026] [security2:error] [pid 95126:tid 95280] [client 216.73.216.156:27083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4gSwpx5ks9joCJTKXTXgABpWk"]
[Mon Jul 20 07:19:07.974501 2026] [security2:error] [pid 95126:tid 95302] [client 103.144.65.217:55178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gSwpx5ks9joCJTKXTcAAAAbs"]
[Mon Jul 20 07:19:07.974658 2026] [security2:error] [pid 95126:tid 95302] [client 103.144.65.217:55178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gSwpx5ks9joCJTKXTcAAAAbs"]
[Mon Jul 20 07:19:08.172930 2026] [security2:error] [pid 95126:tid 95346] [client 216.73.216.156:33810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4gTApx5ks9joCJTKXTdwAB53g"], referer: https://sarahsnyder.net/sitemap.xml
[Mon Jul 20 07:19:08.209637 2026] [security2:error] [pid 94831:tid 95013] [client 85.204.70.112:43498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4gTI06NaEKF1g_MW23YgAAADQ"]
[Mon Jul 20 07:19:08.519114 2026] [security2:error] [pid 95126:tid 95267] [client 104.234.53.92:64239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gTApx5ks9joCJTKXTjQAAAZg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:08.617407 2026] [security2:error] [pid 95126:tid 95283] [client 57.141.18.12:38154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gSgpx5ks9joCJTKXS2QABqBc"]
[Mon Jul 20 07:19:08.728010 2026] [security2:error] [pid 95126:tid 95264] [client 85.204.70.112:43502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.gns.xyp.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4gTApx5ks9joCJTKXTnAAAAZU"]
[Mon Jul 20 07:19:08.891023 2026] [security2:error] [pid 95126:tid 95229] [remote 192.241.143.148:42526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4gTApx5ks9joCJTKXTrQAB-mQ"]
[Mon Jul 20 07:19:09.090731 2026] [security2:error] [pid 95126:tid 95177] [remote 192.241.143.148:42526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4gTQpx5ks9joCJTKXTvgACDTA"], referer: https://mail.cathybuffini.com/wp-login.php
[Mon Jul 20 07:19:09.103138 2026] [security2:error] [pid 95126:tid 95187] [remote 8.217.108.67:39346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gTQpx5ks9joCJTKXTvQABkTo"]
[Mon Jul 20 07:19:09.103311 2026] [security2:error] [pid 95126:tid 95260] [client 8.217.108.67:39346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gTQpx5ks9joCJTKXTvQABkTo"]
[Mon Jul 20 07:19:09.161198 2026] [core:error] [pid 95126:tid 95341] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:09.161223 2026] [core:error] [pid 95126:tid 95341] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:09.220929 2026] [security2:error] [pid 95126:tid 95359] [client 47.129.222.11:51246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gTQpx5ks9joCJTKXTzAAAAfQ"]
[Mon Jul 20 07:19:09.305128 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:63344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTQpx5ks9joCJTKXT0AAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.305223 2026] [security2:error] [pid 95126:tid 95332] [client 77.110.127.138:63344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTQpx5ks9joCJTKXT0AAAAdk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.459472 2026] [security2:error] [pid 95126:tid 95365] [client 77.110.127.138:63347] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gTQpx5ks9joCJTKXT2gAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.612528 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTQpx5ks9joCJTKXT3wAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.612640 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTQpx5ks9joCJTKXT3wAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.766288 2026] [security2:error] [pid 94831:tid 95066] [client 77.110.127.138:63350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTY06NaEKF1g_MW23lAAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.766384 2026] [security2:error] [pid 94831:tid 95066] [client 77.110.127.138:63350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTY06NaEKF1g_MW23lAAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.794166 2026] [security2:error] [pid 94831:tid 95068] [client 117.211.236.168:62881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gTY06NaEKF1g_MW23lQAAAGs"]
[Mon Jul 20 07:19:09.794266 2026] [security2:error] [pid 94831:tid 95068] [client 117.211.236.168:62881] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gTY06NaEKF1g_MW23lQAAAGs"]
[Mon Jul 20 07:19:09.802255 2026] [proxy:error] [pid 95126:tid 95313] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:09.802329 2026] [proxy_http:error] [pid 95126:tid 95313] [client 193.47.62.167:36882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:09.803128 2026] [proxy:error] [pid 95126:tid 95313] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:09.803167 2026] [proxy_http:error] [pid 95126:tid 95313] [client 193.47.62.167:36882] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:09.804987 2026] [proxy:error] [pid 95126:tid 95370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:09.805029 2026] [proxy_http:error] [pid 95126:tid 95370] [client 193.47.62.167:36884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:09.805436 2026] [proxy:error] [pid 95126:tid 95370] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:09.805459 2026] [proxy_http:error] [pid 95126:tid 95370] [client 193.47.62.167:36884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:09.883063 2026] [security2:error] [pid 95126:tid 95325] [client 57.141.18.78:52300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gSwpx5ks9joCJTKXTVQAB0kM"]
[Mon Jul 20 07:19:09.923112 2026] [security2:error] [pid 95126:tid 95359] [client 77.110.127.138:63352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTQpx5ks9joCJTKXT_AAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:09.923221 2026] [security2:error] [pid 95126:tid 95359] [client 77.110.127.138:63352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTQpx5ks9joCJTKXT_AAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.013637 2026] [security2:error] [pid 95126:tid 95289] [client 34.147.91.161:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "tipcruncher.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gTgpx5ks9joCJTKXUAgAAAa4"]
[Mon Jul 20 07:19:10.013757 2026] [security2:error] [pid 95126:tid 95289] [client 34.147.91.161:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "tipcruncher.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gTgpx5ks9joCJTKXUAgAAAa4"]
[Mon Jul 20 07:19:10.169503 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:63354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUCgAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.169603 2026] [security2:error] [pid 95126:tid 95291] [client 77.110.127.138:63354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUCgAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.251413 2026] [security2:error] [pid 95126:tid 95310] [client 185.93.182.171:49146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.182.93.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gTgpx5ks9joCJTKXUEAAAAcM"]
[Mon Jul 20 07:19:10.251551 2026] [security2:error] [pid 95126:tid 95310] [client 185.93.182.171:49146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gTgpx5ks9joCJTKXUEAAAAcM"]
[Mon Jul 20 07:19:10.306311 2026] [security2:error] [pid 94831:tid 95027] [client 104.234.53.85:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gTo06NaEKF1g_MW23nwAAAEI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:10.344365 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:63356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUGwAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.344499 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:63356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUGwAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.347395 2026] [security2:error] [pid 95126:tid 95276] [client 18.141.57.241:51122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gTgpx5ks9joCJTKXUGQAAAaE"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:19:10.402334 2026] [security2:error] [pid 94831:tid 95020] [client 193.47.62.167:36890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.almaz-aura.com"] [uri "/index.php"] [unique_id "al4gTY06NaEKF1g_MW23lgAAADs"]
[Mon Jul 20 07:19:10.409653 2026] [security2:error] [pid 94831:tid 94914] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gTo06NaEKF1g_MW23oAAAUlI"]
[Mon Jul 20 07:19:10.409873 2026] [security2:error] [pid 94831:tid 95043] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gTo06NaEKF1g_MW23oAAAUlI"]
[Mon Jul 20 07:19:10.547302 2026] [security2:error] [pid 95126:tid 95341] [client 77.110.127.138:63358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUKQAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.547423 2026] [security2:error] [pid 95126:tid 95341] [client 77.110.127.138:63358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUKQAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.662581 2026] [security2:error] [pid 94831:tid 95061] [client 57.141.18.12:38168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gTI06NaEKF1g_MW23ZwAAZE0"]
[Mon Jul 20 07:19:10.673393 2026] [security2:error] [pid 95126:tid 95175] [remote 162.19.86.63:41540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4gTgpx5ks9joCJTKXUMwAB0y4"]
[Mon Jul 20 07:19:10.790038 2026] [security2:error] [pid 95126:tid 95380] [client 34.147.91.161:32772] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "zastrow.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gTgpx5ks9joCJTKXUPQAAAgk"]
[Mon Jul 20 07:19:10.790137 2026] [security2:error] [pid 95126:tid 95380] [client 34.147.91.161:32772] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "zastrow.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gTgpx5ks9joCJTKXUPQAAAgk"]
[Mon Jul 20 07:19:10.895294 2026] [security2:error] [pid 95126:tid 95150] [remote 162.19.86.63:41540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lapietramedjugorje.com"] [uri "/wp-login.php"] [unique_id "al4gTgpx5ks9joCJTKXUQQABpRU"], referer: https://lapietramedjugorje.com/wp-login.php
[Mon Jul 20 07:19:10.900685 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:63333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUQgAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.900814 2026] [security2:error] [pid 95126:tid 95261] [client 77.110.127.138:63333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXUQgAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.952162 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:63359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXURAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.952253 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:63359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTgpx5ks9joCJTKXURAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:10.993816 2026] [security2:error] [pid 95126:tid 95272] [client 57.141.18.9:60414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gTApx5ks9joCJTKXTogABnUs"]
[Mon Jul 20 07:19:11.040466 2026] [security2:error] [pid 94831:tid 94961] [client 14.225.17.146:64930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4gTo06NaEKF1g_MW23sQAAAAA"], referer: http://transparentservices.online/2019
[Mon Jul 20 07:19:11.198113 2026] [security2:error] [pid 94831:tid 95080] [client 143.44.185.218:65297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gT406NaEKF1g_MW23tgAAAHc"]
[Mon Jul 20 07:19:11.198215 2026] [security2:error] [pid 94831:tid 95080] [client 143.44.185.218:65297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gT406NaEKF1g_MW23tgAAAHc"]
[Mon Jul 20 07:19:11.391726 2026] [security2:error] [pid 94831:tid 95082] [client 14.225.17.146:60893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gT406NaEKF1g_MW23uQAAAHk"], referer: http://nextlvlmarketingco.com/2019
[Mon Jul 20 07:19:11.401383 2026] [security2:error] [pid 95126:tid 95340] [client 103.176.215.66:55245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gTwpx5ks9joCJTKXUYgAAAeE"]
[Mon Jul 20 07:19:11.401549 2026] [security2:error] [pid 95126:tid 95340] [client 103.176.215.66:55245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gTwpx5ks9joCJTKXUYgAAAeE"]
[Mon Jul 20 07:19:11.417368 2026] [security2:error] [pid 94831:tid 95033] [client 88.241.67.160:54145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gT406NaEKF1g_MW23wAAAAEg"]
[Mon Jul 20 07:19:11.417869 2026] [security2:error] [pid 94831:tid 95033] [client 88.241.67.160:54145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gT406NaEKF1g_MW23wAAAAEg"]
[Mon Jul 20 07:19:11.452793 2026] [security2:error] [pid 95126:tid 95342] [client 14.225.17.146:64948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4gTgpx5ks9joCJTKXUHgAAAeM"], referer: http://travelbyfire.com/2019
[Mon Jul 20 07:19:11.463187 2026] [security2:error] [pid 95126:tid 95284] [client 77.110.127.138:63360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTwpx5ks9joCJTKXUZQAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:11.463290 2026] [security2:error] [pid 95126:tid 95284] [client 77.110.127.138:63360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTwpx5ks9joCJTKXUZQAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:11.531031 2026] [security2:error] [pid 95126:tid 95171] [remote 209.42.18.223:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gTwpx5ks9joCJTKXUbQABmCo"]
[Mon Jul 20 07:19:11.706211 2026] [security2:error] [pid 95126:tid 95226] [remote 209.42.18.223:36858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gTwpx5ks9joCJTKXUdwAB0mE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:19:11.741503 2026] [security2:error] [pid 95126:tid 95135] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gTwpx5ks9joCJTKXUfQAB_wY"]
[Mon Jul 20 07:19:11.741674 2026] [security2:error] [pid 95126:tid 95370] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gTwpx5ks9joCJTKXUfQAB_wY"]
[Mon Jul 20 07:19:11.742161 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTwpx5ks9joCJTKXUfgAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:11.742257 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:63362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gTwpx5ks9joCJTKXUfgAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:11.911823 2026] [security2:error] [pid 94831:tid 94965] [client 166.199.141.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4gT406NaEKF1g_MW23ugAAAAQ"], referer: https://liquidationteam.com/
[Mon Jul 20 07:19:11.918498 2026] [security2:error] [pid 95126:tid 95355] [client 14.225.17.146:50931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4gTQpx5ks9joCJTKXT8wAAAfA"], referer: http://dollpassionista.com/2019
[Mon Jul 20 07:19:11.946573 2026] [security2:error] [pid 94831:tid 94988] [client 14.225.17.146:51903] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4gT406NaEKF1g_MW23wwAAABs"], referer: http://mcg.homes/2019
[Mon Jul 20 07:19:12.029426 2026] [security2:error] [pid 95126:tid 95280] [client 157.20.138.62:50524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gUApx5ks9joCJTKXUjwAAAaU"]
[Mon Jul 20 07:19:12.030652 2026] [security2:error] [pid 95126:tid 95280] [client 157.20.138.62:50524] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gUApx5ks9joCJTKXUjwAAAaU"]
[Mon Jul 20 07:19:12.078424 2026] [security2:error] [pid 95126:tid 95283] [client 57.141.18.73:20156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gTQpx5ks9joCJTKXT8AABqAU"]
[Mon Jul 20 07:19:12.191777 2026] [security2:error] [pid 95126:tid 95289] [client 49.47.218.174:50976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gUApx5ks9joCJTKXUkwAAAa4"]
[Mon Jul 20 07:19:12.191911 2026] [security2:error] [pid 95126:tid 95289] [client 49.47.218.174:50976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gUApx5ks9joCJTKXUkwAAAa4"]
[Mon Jul 20 07:19:12.401629 2026] [security2:error] [pid 95126:tid 95263] [client 14.225.17.146:51523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4gUApx5ks9joCJTKXUoAAAAZQ"], referer: https://travelbyfire.com/2019
[Mon Jul 20 07:19:12.598223 2026] [security2:error] [pid 95126:tid 95308] [client 14.225.17.146:64716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4gUApx5ks9joCJTKXUqgAAAcE"], referer: http://uritems.net/2019
[Mon Jul 20 07:19:12.647961 2026] [access_compat:error] [pid 95126:tid 95303] [client 144.172.114.51:33216] AH01797: client denied by server configuration: /home1/threetj3/public_html/website_fa490990/server-status
[Mon Jul 20 07:19:12.991379 2026] [security2:error] [pid 95126:tid 95273] [client 14.225.17.146:61316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4gTwpx5ks9joCJTKXUigAAAZ4"], referer: http://ncsynchro.com/2019
[Mon Jul 20 07:19:13.068732 2026] [security2:error] [pid 95126:tid 95310] [client 191.202.66.27:52473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gUQpx5ks9joCJTKXU0gAAAcM"]
[Mon Jul 20 07:19:13.068865 2026] [security2:error] [pid 95126:tid 95310] [client 191.202.66.27:52473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gUQpx5ks9joCJTKXU0gAAAcM"]
[Mon Jul 20 07:19:13.076713 2026] [security2:error] [pid 95126:tid 95368] [client 154.208.48.130:54404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gUQpx5ks9joCJTKXU0QAAAf0"]
[Mon Jul 20 07:19:13.076864 2026] [security2:error] [pid 95126:tid 95368] [client 154.208.48.130:54404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gUQpx5ks9joCJTKXU0QAAAf0"]
[Mon Jul 20 07:19:13.152119 2026] [security2:error] [pid 95126:tid 95384] [client 14.225.17.146:64792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4gUApx5ks9joCJTKXUzwAAAg0"], referer: https://dollpassionista.com/2019
[Mon Jul 20 07:19:13.156982 2026] [security2:error] [pid 95126:tid 95365] [client 57.141.18.0:33238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gTgpx5ks9joCJTKXUQAAB-ig"]
[Mon Jul 20 07:19:13.463587 2026] [security2:error] [pid 95126:tid 95337] [client 57.141.18.5:32690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gTwpx5ks9joCJTKXUUwAB3iw"]
[Mon Jul 20 07:19:13.638838 2026] [security2:error] [pid 95126:tid 95235] [remote 8.217.108.67:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gUQpx5ks9joCJTKXU8QACBGo"]
[Mon Jul 20 07:19:13.712282 2026] [security2:error] [pid 95126:tid 95383] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gUQpx5ks9joCJTKXU8AAAAgw"]
[Mon Jul 20 07:19:13.923745 2026] [security2:error] [pid 95126:tid 95348] [client 187.16.64.216:58065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gUQpx5ks9joCJTKXU_wAAAek"]
[Mon Jul 20 07:19:13.923848 2026] [security2:error] [pid 95126:tid 95348] [client 187.16.64.216:58065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gUQpx5ks9joCJTKXU_wAAAek"]
[Mon Jul 20 07:19:13.970000 2026] [security2:error] [pid 94831:tid 95083] [client 57.141.18.104:26272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gT406NaEKF1g_MW23yAAAemA"]
[Mon Jul 20 07:19:14.019111 2026] [security2:error] [pid 94831:tid 95032] [client 13.233.207.33:18624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gUo06NaEKF1g_MW23_QAAAEc"]
[Mon Jul 20 07:19:14.019203 2026] [security2:error] [pid 94831:tid 95032] [client 13.233.207.33:18624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gUo06NaEKF1g_MW23_QAAAEc"]
[Mon Jul 20 07:19:14.038567 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gUo06NaEKF1g_MW23_gAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:14.038656 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gUo06NaEKF1g_MW23_gAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:14.193635 2026] [security2:error] [pid 94831:tid 94954] [remote 154.61.75.100:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gUo06NaEKF1g_MW24AAAAOHo"]
[Mon Jul 20 07:19:14.239464 2026] [security2:error] [pid 94831:tid 95077] [client 77.110.127.138:63374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gUo06NaEKF1g_MW24AQAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:14.239588 2026] [security2:error] [pid 94831:tid 95077] [client 77.110.127.138:63374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gUo06NaEKF1g_MW24AQAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:14.458055 2026] [security2:error] [pid 95126:tid 95340] [client 103.106.165.44:56343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gUgpx5ks9joCJTKXVFQAAAeE"]
[Mon Jul 20 07:19:14.458212 2026] [security2:error] [pid 95126:tid 95340] [client 103.106.165.44:56343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gUgpx5ks9joCJTKXVFQAAAeE"]
[Mon Jul 20 07:19:14.514708 2026] [security2:error] [pid 95126:tid 95250] [remote 8.217.108.67:53918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gUgpx5ks9joCJTKXVGAAB8Hk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:19:14.684425 2026] [security2:error] [pid 94831:tid 94950] [remote 154.61.75.100:57014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gUo06NaEKF1g_MW24EAAAUnY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:19:14.918095 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:63377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gUgpx5ks9joCJTKXVKQAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:14.918281 2026] [security2:error] [pid 95126:tid 95342] [client 77.110.127.138:63377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gUgpx5ks9joCJTKXVKQAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:15.027653 2026] [security2:error] [pid 95126:tid 95333] [client 154.192.123.127:18339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gUwpx5ks9joCJTKXVOQAAAdo"]
[Mon Jul 20 07:19:15.027820 2026] [security2:error] [pid 95126:tid 95333] [client 154.192.123.127:18339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gUwpx5ks9joCJTKXVOQAAAdo"]
[Mon Jul 20 07:19:15.114139 2026] [security2:error] [pid 94831:tid 94982] [client 14.225.17.146:64822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4gUo06NaEKF1g_MW23_wAAABU"], referer: http://walkingandtalking.net/2019
[Mon Jul 20 07:19:15.138264 2026] [security2:error] [pid 94831:tid 95051] [client 98.159.234.160:44439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gU406NaEKF1g_MW24GAAAAFo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:15.258850 2026] [security2:error] [pid 95126:tid 95332] [client 74.208.214.194:55208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4gUwpx5ks9joCJTKXVRgAAAdk"]
[Mon Jul 20 07:19:15.423119 2026] [security2:error] [pid 95126:tid 95259] [client 57.141.18.45:48308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUQpx5ks9joCJTKXU2wABkFs"]
[Mon Jul 20 07:19:15.539192 2026] [security2:error] [pid 94831:tid 94969] [client 77.110.127.138:63378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gU406NaEKF1g_MW24IQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:15.539299 2026] [security2:error] [pid 94831:tid 94969] [client 77.110.127.138:63378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gU406NaEKF1g_MW24IQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:15.858726 2026] [security2:error] [pid 95126:tid 95321] [client 201.27.111.74:58396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gUwpx5ks9joCJTKXVaQAAAc4"]
[Mon Jul 20 07:19:15.858840 2026] [security2:error] [pid 95126:tid 95321] [client 201.27.111.74:58396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gUwpx5ks9joCJTKXVaQAAAc4"]
[Mon Jul 20 07:19:15.949481 2026] [security2:error] [pid 95126:tid 95285] [client 57.141.18.52:57796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUQpx5ks9joCJTKXU-QABqnU"]
[Mon Jul 20 07:19:15.952506 2026] [security2:error] [pid 94831:tid 95036] [client 57.141.18.66:31670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUY06NaEKF1g_MW23-QAASzw"]
[Mon Jul 20 07:19:15.956145 2026] [security2:error] [pid 95126:tid 95363] [client 114.119.146.255:35535] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "ksands.co.uk"] [uri "/kss-policies"] [unique_id "al4gUwpx5ks9joCJTKXVcgAAAfg"], referer: https://ksands.co.uk/news/secure-ground-transportation-in-london/
[Mon Jul 20 07:19:16.170414 2026] [security2:error] [pid 95126:tid 95370] [client 14.225.17.146:51441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4gVApx5ks9joCJTKXVfwAAAf8"], referer: https://walkingandtalking.net/2019
[Mon Jul 20 07:19:16.254423 2026] [security2:error] [pid 95126:tid 95264] [client 77.110.127.138:63382] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 645 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gVApx5ks9joCJTKXVhQAAAZU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:16.289395 2026] [security2:error] [pid 95126:tid 95368] [client 57.141.18.108:41942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUgpx5ks9joCJTKXVBQAB_T8"]
[Mon Jul 20 07:19:16.416862 2026] [security2:error] [pid 95126:tid 95341] [client 77.110.127.138:63384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVApx5ks9joCJTKXVkwAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:16.416971 2026] [security2:error] [pid 95126:tid 95341] [client 77.110.127.138:63384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVApx5ks9joCJTKXVkwAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:16.776065 2026] [security2:error] [pid 95126:tid 95330] [client 104.234.53.73:54769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gVApx5ks9joCJTKXVqAAAAdc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:16.908235 2026] [security2:error] [pid 95126:tid 95375] [client 57.141.18.111:64158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUgpx5ks9joCJTKXVJAACBHs"]
[Mon Jul 20 07:19:16.963885 2026] [security2:error] [pid 95126:tid 95140] [remote 124.55.178.99:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gVApx5ks9joCJTKXVtgAB3As"]
[Mon Jul 20 07:19:16.980882 2026] [security2:error] [pid 95126:tid 95320] [client 57.141.18.38:51294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUgpx5ks9joCJTKXVJQABzWM"]
[Mon Jul 20 07:19:17.255465 2026] [security2:error] [pid 95126:tid 95358] [client 77.110.127.138:63389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVQpx5ks9joCJTKXV1QAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:17.255548 2026] [security2:error] [pid 95126:tid 95358] [client 77.110.127.138:63389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVQpx5ks9joCJTKXV1QAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:17.333788 2026] [security2:error] [pid 95126:tid 95338] [client 57.141.18.31:58134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gUwpx5ks9joCJTKXVPgAB3y4"]
[Mon Jul 20 07:19:17.374647 2026] [security2:error] [pid 95126:tid 95190] [remote 124.55.178.99:53462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gVQpx5ks9joCJTKXV3QABkz0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:19:17.593100 2026] [security2:error] [pid 95126:tid 95289] [client 144.172.114.51:33228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gVQpx5ks9joCJTKXVzgAAAas"]
[Mon Jul 20 07:19:18.043392 2026] [security2:error] [pid 95126:tid 95368] [client 186.243.171.86:58343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.171.243.186.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.maxenengineering.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVQpx5ks9joCJTKXV9wAAAf0"], referer: https://www.maxenengineering.com/complete-construction-equipment-under-one-roof/#comment-10557
[Mon Jul 20 07:19:18.043519 2026] [security2:error] [pid 95126:tid 95368] [client 186.243.171.86:58343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.maxenengineering.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVQpx5ks9joCJTKXV9wAAAf0"], referer: https://www.maxenengineering.com/complete-construction-equipment-under-one-roof/#comment-10557
[Mon Jul 20 07:19:18.151553 2026] [security2:error] [pid 95126:tid 95299] [client 14.225.17.146:50778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4gVgpx5ks9joCJTKXWAAAAAbg"], referer: http://grndl.com/2019
[Mon Jul 20 07:19:18.195269 2026] [security2:error] [pid 95126:tid 95347] [client 57.141.18.12:38222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gVApx5ks9joCJTKXVegAB6FA"]
[Mon Jul 20 07:19:18.326309 2026] [security2:error] [pid 95126:tid 95326] [client 14.225.17.146:51249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4gVApx5ks9joCJTKXVmgAAAdM"], referer: http://areitoproducciones.com/2019
[Mon Jul 20 07:19:18.661322 2026] [security2:error] [pid 95126:tid 95336] [client 103.144.65.217:55639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gVgpx5ks9joCJTKXWJwAAAd0"]
[Mon Jul 20 07:19:18.661449 2026] [security2:error] [pid 95126:tid 95336] [client 103.144.65.217:55639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gVgpx5ks9joCJTKXWJwAAAd0"]
[Mon Jul 20 07:19:18.675250 2026] [security2:error] [pid 95126:tid 95332] [client 57.141.18.93:37300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gVApx5ks9joCJTKXVmwAB2XI"]
[Mon Jul 20 07:19:18.732904 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:63393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVgpx5ks9joCJTKXWKwAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:18.733018 2026] [security2:error] [pid 95126:tid 95271] [client 77.110.127.138:63393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVgpx5ks9joCJTKXWKwAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:18.744577 2026] [security2:error] [pid 95126:tid 95371] [client 36.250.220.161:31898] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "jndsupport.com"] [uri "/"] [unique_id "al4gVgpx5ks9joCJTKXWLAAAAgA"]
[Mon Jul 20 07:19:18.773118 2026] [security2:error] [pid 94831:tid 94955] [remote 57.141.18.51:47004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6472956"] [unique_id "al4gVo06NaEKF1g_MW24WwAAJXs"]
[Mon Jul 20 07:19:18.932661 2026] [security2:error] [pid 95126:tid 95354] [client 77.110.127.138:63394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVgpx5ks9joCJTKXWNgAAAe8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:18.932778 2026] [security2:error] [pid 95126:tid 95354] [client 77.110.127.138:63394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gVgpx5ks9joCJTKXWNgAAAe8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:18.985297 2026] [security2:error] [pid 95126:tid 95351] [client 57.141.18.86:55838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gVApx5ks9joCJTKXVrQAB7AQ"]
[Mon Jul 20 07:19:19.086053 2026] [security2:error] [pid 95126:tid 95304] [client 116.179.37.61:33100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4gVQpx5ks9joCJTKXVyQAAAb0"], referer: https://innspace.ca/entrepreneurial-journal-weekly/
[Mon Jul 20 07:19:19.125085 2026] [proxy:error] [pid 95126:tid 95283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:19.125149 2026] [proxy_http:error] [pid 95126:tid 95283] [client 8.229.28.226:58918] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:19.125640 2026] [proxy:error] [pid 95126:tid 95283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:19.125667 2026] [proxy_http:error] [pid 95126:tid 95283] [client 8.229.28.226:58918] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:19.423044 2026] [security2:error] [pid 95126:tid 95342] [client 14.225.17.146:52945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4gVQpx5ks9joCJTKXV-AAAAeM"], referer: http://blaizeaccountingservices.com/2019
[Mon Jul 20 07:19:19.655035 2026] [core:error] [pid 95126:tid 95354] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:19.655063 2026] [core:error] [pid 95126:tid 95354] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:19.703054 2026] [security2:error] [pid 94831:tid 94970] [client 104.234.53.47:52975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gV406NaEKF1g_MW24cQAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:19.706556 2026] [security2:error] [pid 95126:tid 95385] [client 77.110.127.138:63396] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 645 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gVwpx5ks9joCJTKXWZQAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:19.761585 2026] [security2:error] [pid 94831:tid 94867] [remote 51.158.61.221:52368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4gV406NaEKF1g_MW24dAAAUCM"]
[Mon Jul 20 07:19:19.761856 2026] [security2:error] [pid 94831:tid 95041] [client 51.158.61.221:52368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4gV406NaEKF1g_MW24dAAAUCM"]
[Mon Jul 20 07:19:19.821092 2026] [security2:error] [pid 94831:tid 95051] [client 57.141.18.8:23850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gVY06NaEKF1g_MW24QQAAWhE"]
[Mon Jul 20 07:19:20.077435 2026] [security2:error] [pid 95126:tid 95319] [client 57.141.18.63:32586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gVQpx5ks9joCJTKXV9AABzBE"]
[Mon Jul 20 07:19:20.260172 2026] [security2:error] [pid 95126:tid 95275] [client 14.225.17.146:51442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4gVgpx5ks9joCJTKXWNAAAAaA"], referer: http://elitetax-mi.com/2019
[Mon Jul 20 07:19:20.444715 2026] [security2:error] [pid 94831:tid 94870] [remote 57.141.18.47:62008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4040476"] [unique_id "al4gWI06NaEKF1g_MW24iwAAfCY"]
[Mon Jul 20 07:19:20.504818 2026] [security2:error] [pid 94831:tid 94974] [client 57.141.18.96:65504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gVo06NaEKF1g_MW24TwAADX4"]
[Mon Jul 20 07:19:20.537681 2026] [security2:error] [pid 95126:tid 95261] [client 34.91.36.231:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gWApx5ks9joCJTKXWngAAAZI"]
[Mon Jul 20 07:19:20.537804 2026] [security2:error] [pid 95126:tid 95261] [client 34.91.36.231:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gWApx5ks9joCJTKXWngAAAZI"]
[Mon Jul 20 07:19:20.566720 2026] [security2:error] [pid 95126:tid 95311] [client 52.47.76.32:59438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gWApx5ks9joCJTKXWoQAAAcQ"]
[Mon Jul 20 07:19:20.572552 2026] [security2:error] [pid 95126:tid 95355] [client 77.110.127.138:63400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWApx5ks9joCJTKXWpAAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:20.572640 2026] [security2:error] [pid 95126:tid 95355] [client 77.110.127.138:63400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWApx5ks9joCJTKXWpAAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:20.743506 2026] [security2:error] [pid 95126:tid 95319] [client 77.110.127.138:63401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWApx5ks9joCJTKXWqwAAAcw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:20.743603 2026] [security2:error] [pid 95126:tid 95319] [client 77.110.127.138:63401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWApx5ks9joCJTKXWqwAAAcw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:21.054377 2026] [security2:error] [pid 95126:tid 95302] [client 14.225.17.146:50896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4gWApx5ks9joCJTKXWjgAAAbs"], referer: http://processorstudio.com/2019
[Mon Jul 20 07:19:21.093962 2026] [security2:error] [pid 95126:tid 95171] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gWQpx5ks9joCJTKXWvQAB-Co"]
[Mon Jul 20 07:19:21.094177 2026] [security2:error] [pid 95126:tid 95363] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gWQpx5ks9joCJTKXWvQAB-Co"]
[Mon Jul 20 07:19:21.148139 2026] [security2:error] [pid 94831:tid 95028] [client 35.180.166.19:17444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gWY06NaEKF1g_MW24ogAAAEM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:19:21.237832 2026] [security2:error] [pid 94831:tid 95043] [client 84.247.167.104:48530] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5936.bluehost.com"] [uri "/news/"] [unique_id "al4gWY06NaEKF1g_MW24qwAAAFI"]
[Mon Jul 20 07:19:21.288450 2026] [security2:error] [pid 94831:tid 94888] [remote 20.153.140.50:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gWY06NaEKF1g_MW24sAAAczg"]
[Mon Jul 20 07:19:21.367954 2026] [security2:error] [pid 94831:tid 95014] [client 158.173.241.141:28533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4gWY06NaEKF1g_MW24pwAAADU"], referer: http://sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:21.518404 2026] [security2:error] [pid 94831:tid 95077] [client 14.225.17.146:51314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4gV406NaEKF1g_MW24cwAAAHQ"], referer: http://maplerespiteservices.com/2019
[Mon Jul 20 07:19:21.676901 2026] [security2:error] [pid 95126:tid 95340] [client 84.247.167.104:48532] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/news/"] [unique_id "al4gWQpx5ks9joCJTKXW3wAAAeE"]
[Mon Jul 20 07:19:21.681528 2026] [security2:error] [pid 94831:tid 94883] [remote 20.153.140.50:43046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gWY06NaEKF1g_MW24ugAAGjM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:19:21.840471 2026] [security2:error] [pid 94831:tid 94983] [client 117.211.236.168:63449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gWY06NaEKF1g_MW24vgAAABY"]
[Mon Jul 20 07:19:21.840568 2026] [security2:error] [pid 94831:tid 94983] [client 117.211.236.168:63449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gWY06NaEKF1g_MW24vgAAABY"]
[Mon Jul 20 07:19:21.842142 2026] [security2:error] [pid 95126:tid 95263] [client 143.44.185.218:1326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gWQpx5ks9joCJTKXW5wAAAZQ"]
[Mon Jul 20 07:19:21.842233 2026] [security2:error] [pid 95126:tid 95263] [client 143.44.185.218:1326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gWQpx5ks9joCJTKXW5wAAAZQ"]
[Mon Jul 20 07:19:21.954482 2026] [security2:error] [pid 94831:tid 95007] [client 103.176.215.66:55769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gWY06NaEKF1g_MW24xAAAAC4"]
[Mon Jul 20 07:19:21.954599 2026] [security2:error] [pid 94831:tid 95007] [client 103.176.215.66:55769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gWY06NaEKF1g_MW24xAAAAC4"]
[Mon Jul 20 07:19:21.966487 2026] [security2:error] [pid 94831:tid 95085] [client 14.225.17.146:52850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4gWY06NaEKF1g_MW24wQAAAHw"], referer: https://processorstudio.com/2019
[Mon Jul 20 07:19:22.041239 2026] [security2:error] [pid 95126:tid 95304] [client 50.116.65.227:50558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gWgpx5ks9joCJTKXW9QAAAb0"]
[Mon Jul 20 07:19:22.052219 2026] [security2:error] [pid 95126:tid 95343] [client 50.116.65.227:37114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gWgpx5ks9joCJTKXW9wAAAeQ"]
[Mon Jul 20 07:19:22.127491 2026] [security2:error] [pid 95126:tid 95320] [client 84.247.167.104:48536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/news/"] [unique_id "al4gWgpx5ks9joCJTKXW_AAAAc0"]
[Mon Jul 20 07:19:22.204227 2026] [security2:error] [pid 95126:tid 95321] [client 88.241.67.160:54976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gWgpx5ks9joCJTKXW_wAAAc4"]
[Mon Jul 20 07:19:22.204441 2026] [security2:error] [pid 95126:tid 95321] [client 88.241.67.160:54976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gWgpx5ks9joCJTKXW_wAAAc4"]
[Mon Jul 20 07:19:22.371267 2026] [security2:error] [pid 94831:tid 94902] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gWo06NaEKF1g_MW24zAAAfUY"]
[Mon Jul 20 07:19:22.371408 2026] [security2:error] [pid 94831:tid 95086] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gWo06NaEKF1g_MW24zAAAfUY"]
[Mon Jul 20 07:19:22.396504 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:63406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWgpx5ks9joCJTKXXDQAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:22.396600 2026] [security2:error] [pid 95126:tid 95314] [client 77.110.127.138:63406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWgpx5ks9joCJTKXXDQAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:22.476541 2026] [security2:error] [pid 95126:tid 95156] [remote 156.67.31.167:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gWgpx5ks9joCJTKXXFwAB_Bs"]
[Mon Jul 20 07:19:22.503349 2026] [security2:error] [pid 95126:tid 95347] [client 157.20.138.62:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gWgpx5ks9joCJTKXXGAAAAeg"]
[Mon Jul 20 07:19:22.503461 2026] [security2:error] [pid 95126:tid 95347] [client 157.20.138.62:51090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gWgpx5ks9joCJTKXXGAAAAeg"]
[Mon Jul 20 07:19:22.573426 2026] [security2:error] [pid 95126:tid 95340] [client 98.94.228.253:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4gWgpx5ks9joCJTKXXDgAB4Qs"]
[Mon Jul 20 07:19:22.644120 2026] [security2:error] [pid 95126:tid 95300] [client 14.225.17.146:59497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4gWgpx5ks9joCJTKXXGQAAAbk"], referer: http://ivetstrategies.com/2019
[Mon Jul 20 07:19:22.671501 2026] [security2:error] [pid 95126:tid 95371] [client 49.47.218.174:37512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gWgpx5ks9joCJTKXXHQAAAgA"]
[Mon Jul 20 07:19:22.671623 2026] [security2:error] [pid 95126:tid 95371] [client 49.47.218.174:37512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gWgpx5ks9joCJTKXXHQAAAgA"]
[Mon Jul 20 07:19:22.673497 2026] [security2:error] [pid 95126:tid 95175] [remote 156.67.31.167:42304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gWgpx5ks9joCJTKXXHgAB2i4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:19:22.958855 2026] [security2:error] [pid 95126:tid 95342] [client 47.128.62.100:23422] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "xp-design.co"] [uri "/robots.txt"] [unique_id "al4gWgpx5ks9joCJTKXXNQAAAeM"]
[Mon Jul 20 07:19:22.959162 2026] [security2:error] [pid 95126:tid 95280] [client 34.147.91.161:32773] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.vergotek.com.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gWgpx5ks9joCJTKXXNgAAAaU"]
[Mon Jul 20 07:19:22.959259 2026] [security2:error] [pid 95126:tid 95280] [client 34.147.91.161:32773] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.vergotek.com.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gWgpx5ks9joCJTKXXNgAAAaU"]
[Mon Jul 20 07:19:23.033672 2026] [security2:error] [pid 95126:tid 95335] [client 77.110.127.138:63408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWwpx5ks9joCJTKXXPwAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:23.033782 2026] [security2:error] [pid 95126:tid 95335] [client 77.110.127.138:63408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gWwpx5ks9joCJTKXXPwAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:23.198453 2026] [security2:error] [pid 94831:tid 95054] [client 77.110.127.138:63409] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 423 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gW406NaEKF1g_MW245QAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:23.257642 2026] [security2:error] [pid 95126:tid 95286] [client 52.109.89.119:8516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gWwpx5ks9joCJTKXXRAAAAas"]
[Mon Jul 20 07:19:23.266263 2026] [security2:error] [pid 94831:tid 95083] [client 14.225.17.146:52856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4gWY06NaEKF1g_MW24wAAAAHo"]
[Mon Jul 20 07:19:23.384522 2026] [security2:error] [pid 94831:tid 95014] [client 179.25.105.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4gW406NaEKF1g_MW244AAAADU"]
[Mon Jul 20 07:19:23.387449 2026] [security2:error] [pid 94831:tid 95031] [client 57.141.18.121:32900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gWY06NaEKF1g_MW24nwAARjE"]
[Mon Jul 20 07:19:23.392782 2026] [security2:error] [pid 94831:tid 94971] [client 14.225.17.146:50603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4gW406NaEKF1g_MW246QAAAAo"], referer: http://collectingrealestate.com/2019
[Mon Jul 20 07:19:23.406444 2026] [security2:error] [pid 95126:tid 95275] [client 52.109.89.119:8516] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gWwpx5ks9joCJTKXXTQAAAaA"]
[Mon Jul 20 07:19:23.431144 2026] [security2:error] [pid 94831:tid 94964] [client 191.202.66.27:52943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gW406NaEKF1g_MW247gAAAAM"]
[Mon Jul 20 07:19:23.431236 2026] [security2:error] [pid 94831:tid 94964] [client 191.202.66.27:52943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gW406NaEKF1g_MW247gAAAAM"]
[Mon Jul 20 07:19:23.598177 2026] [security2:error] [pid 94831:tid 94980] [client 154.208.48.130:54891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gW406NaEKF1g_MW24-QAAABM"]
[Mon Jul 20 07:19:23.598270 2026] [security2:error] [pid 94831:tid 94980] [client 154.208.48.130:54891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gW406NaEKF1g_MW24-QAAABM"]
[Mon Jul 20 07:19:23.910444 2026] [security2:error] [pid 95126:tid 95336] [client 14.225.17.146:59496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4gWgpx5ks9joCJTKXXEAAAAd0"], referer: http://709fx.com/2019
[Mon Jul 20 07:19:23.939461 2026] [security2:error] [pid 95126:tid 95355] [client 104.234.53.88:37569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gWwpx5ks9joCJTKXXYQAAAfA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:23.976410 2026] [security2:error] [pid 94831:tid 95002] [client 77.110.127.138:63412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gW406NaEKF1g_MW25CAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:23.976502 2026] [security2:error] [pid 94831:tid 95002] [client 77.110.127.138:63412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gW406NaEKF1g_MW25CAAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:24.455762 2026] [security2:error] [pid 95126:tid 95368] [client 57.141.18.4:65392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gWQpx5ks9joCJTKXW6gAB_SI"]
[Mon Jul 20 07:19:24.502819 2026] [security2:error] [pid 94831:tid 95028] [client 207.175.80.208:61740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.80.175.207.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/xmlrpc.php"] [unique_id "al4gXI06NaEKF1g_MW25FAAAAEM"]
[Mon Jul 20 07:19:24.556443 2026] [security2:error] [pid 95126:tid 95353] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gXApx5ks9joCJTKXXdwAAAe4"]
[Mon Jul 20 07:19:24.556669 2026] [security2:error] [pid 95126:tid 95380] [client 187.16.64.216:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gXApx5ks9joCJTKXXgwAAAgk"]
[Mon Jul 20 07:19:24.556769 2026] [security2:error] [pid 95126:tid 95380] [client 187.16.64.216:58638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gXApx5ks9joCJTKXXgwAAAgk"]
[Mon Jul 20 07:19:24.590654 2026] [security2:error] [pid 95126:tid 95338] [client 57.141.18.47:25420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gWQpx5ks9joCJTKXW8AAB3zk"]
[Mon Jul 20 07:19:24.601693 2026] [security2:error] [pid 94831:tid 95042] [client 77.110.127.138:63417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXI06NaEKF1g_MW25FgAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:24.601810 2026] [security2:error] [pid 94831:tid 95042] [client 77.110.127.138:63417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXI06NaEKF1g_MW25FgAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:24.834809 2026] [security2:error] [pid 95126:tid 95345] [client 52.109.108.111:23201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gXApx5ks9joCJTKXXkQAAAeY"]
[Mon Jul 20 07:19:24.878258 2026] [security2:error] [pid 94831:tid 95039] [client 103.106.165.44:56776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gXI06NaEKF1g_MW25GQAAAE4"]
[Mon Jul 20 07:19:24.878398 2026] [security2:error] [pid 94831:tid 95039] [client 103.106.165.44:56776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gXI06NaEKF1g_MW25GQAAAE4"]
[Mon Jul 20 07:19:24.993679 2026] [security2:error] [pid 95126:tid 95289] [client 52.109.108.111:23201] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gXApx5ks9joCJTKXXowAAAa4"]
[Mon Jul 20 07:19:25.182403 2026] [security2:error] [pid 95126:tid 95283] [client 207.175.80.208:54225] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4gXQpx5ks9joCJTKXXsQAAAag"]
[Mon Jul 20 07:19:25.227128 2026] [security2:error] [pid 95126:tid 95189] [remote 100.42.189.89:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gXQpx5ks9joCJTKXXtAABmDw"]
[Mon Jul 20 07:19:25.254109 2026] [security2:error] [pid 94831:tid 95077] [client 50.116.65.227:37200] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gXY06NaEKF1g_MW25IQAAAHQ"]
[Mon Jul 20 07:19:25.265786 2026] [security2:error] [pid 95126:tid 95262] [client 50.116.65.227:37212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gXQpx5ks9joCJTKXXtwAAAZM"]
[Mon Jul 20 07:19:25.348711 2026] [security2:error] [pid 95126:tid 95384] [client 77.110.127.138:63431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXQpx5ks9joCJTKXXvwAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:25.348813 2026] [security2:error] [pid 95126:tid 95384] [client 77.110.127.138:63431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXQpx5ks9joCJTKXXvwAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:25.443797 2026] [security2:error] [pid 95126:tid 95238] [remote 100.42.189.89:45904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gXQpx5ks9joCJTKXXzAAB2G0"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:19:25.602511 2026] [security2:error] [pid 95126:tid 95294] [client 154.192.123.127:18831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gXQpx5ks9joCJTKXX1QAAAbM"]
[Mon Jul 20 07:19:25.602763 2026] [security2:error] [pid 95126:tid 95294] [client 154.192.123.127:18831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gXQpx5ks9joCJTKXX1QAAAbM"]
[Mon Jul 20 07:19:25.787330 2026] [security2:error] [pid 95126:tid 95312] [client 207.175.80.208:49780] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4gXQpx5ks9joCJTKXX4AAAAcU"]
[Mon Jul 20 07:19:25.838667 2026] [security2:error] [pid 95126:tid 95255] [remote 5.161.225.162:48970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4gXQpx5ks9joCJTKXX4gACAX4"]
[Mon Jul 20 07:19:25.974881 2026] [security2:error] [pid 94831:tid 94973] [client 57.141.18.120:64570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gW406NaEKF1g_MW246wAADEc"]
[Mon Jul 20 07:19:26.010358 2026] [core:error] [pid 94831:tid 94995] [client 14.225.17.146:59575] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2019
[Mon Jul 20 07:19:26.010379 2026] [core:error] [pid 94831:tid 94995] [client 14.225.17.146:59575] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2019
[Mon Jul 20 07:19:26.017855 2026] [security2:error] [pid 95126:tid 95322] [client 77.110.127.138:63434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gXgpx5ks9joCJTKXX-QAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:26.077487 2026] [security2:error] [pid 95126:tid 95246] [remote 5.161.225.162:48970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4gXgpx5ks9joCJTKXX_wABonU"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:19:26.205305 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:63435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXo06NaEKF1g_MW25NwAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:26.205444 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:63435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXo06NaEKF1g_MW25NwAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:26.226400 2026] [security2:error] [pid 94831:tid 95063] [client 104.28.251.199:45126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/.env"] [unique_id "al4gXo06NaEKF1g_MW25OAAAAGY"]
[Mon Jul 20 07:19:26.321107 2026] [security2:error] [pid 94831:tid 95068] [client 104.28.219.199:37364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXo06NaEKF1g_MW25NgAAAGs"]
[Mon Jul 20 07:19:26.327460 2026] [security2:error] [pid 95126:tid 95320] [client 201.27.111.74:58901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gXgpx5ks9joCJTKXYCAAAAc0"]
[Mon Jul 20 07:19:26.332273 2026] [security2:error] [pid 95126:tid 95320] [client 201.27.111.74:58901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gXgpx5ks9joCJTKXYCAAAAc0"]
[Mon Jul 20 07:19:26.357504 2026] [security2:error] [pid 94831:tid 95035] [client 104.28.251.199:45122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXo06NaEKF1g_MW25OQAAAEo"]
[Mon Jul 20 07:19:26.385329 2026] [security2:error] [pid 95126:tid 95383] [client 104.28.251.199:45146] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/wp-config.php.old"] [unique_id "al4gXgpx5ks9joCJTKXYCgAAAgw"]
[Mon Jul 20 07:19:26.385853 2026] [security2:error] [pid 94831:tid 95037] [client 104.28.251.199:45139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/wp-config.php~"] [unique_id "al4gXo06NaEKF1g_MW25OwAAAEw"]
[Mon Jul 20 07:19:26.394044 2026] [security2:error] [pid 95126:tid 95326] [client 104.28.251.199:16091] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXgpx5ks9joCJTKXYBgAAAdM"]
[Mon Jul 20 07:19:26.418260 2026] [security2:error] [pid 95126:tid 95311] [client 104.28.251.199:45135] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/wp-config.php.bak"] [unique_id "al4gXgpx5ks9joCJTKXYDQAAAcQ"]
[Mon Jul 20 07:19:26.424738 2026] [security2:error] [pid 95126:tid 95284] [client 207.175.80.208:52876] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4gXgpx5ks9joCJTKXYEAAAAak"]
[Mon Jul 20 07:19:26.456223 2026] [security2:error] [pid 95126:tid 95283] [client 104.28.251.199:45127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/wp-config.php"] [unique_id "al4gXgpx5ks9joCJTKXYEwAAAag"]
[Mon Jul 20 07:19:26.460508 2026] [security2:error] [pid 94831:tid 94975] [client 104.28.251.199:45126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXo06NaEKF1g_MW25OgAAAA4"]
[Mon Jul 20 07:19:26.543660 2026] [core:error] [pid 95126:tid 95289] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:26.543680 2026] [core:error] [pid 95126:tid 95289] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:26.631710 2026] [security2:error] [pid 94831:tid 94965] [client 23.137.105.2:25040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXo06NaEKF1g_MW25QAAAAAQ"]
[Mon Jul 20 07:19:26.687504 2026] [security2:error] [pid 94831:tid 94943] [remote 5.161.225.162:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4gXo06NaEKF1g_MW25SQAAWG8"]
[Mon Jul 20 07:19:26.711499 2026] [security2:error] [pid 95126:tid 95347] [client 104.28.219.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXgpx5ks9joCJTKXYKQAAAeg"]
[Mon Jul 20 07:19:26.737022 2026] [security2:error] [pid 94831:tid 95055] [client 104.28.251.199:45122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXo06NaEKF1g_MW25RQAAAF4"]
[Mon Jul 20 07:19:26.774393 2026] [security2:error] [pid 94831:tid 95044] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXo06NaEKF1g_MW25RwAAAFM"]
[Mon Jul 20 07:19:26.871400 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXo06NaEKF1g_MW25TQAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:26.871496 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXo06NaEKF1g_MW25TQAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:26.874000 2026] [security2:error] [pid 95126:tid 95359] [client 104.28.251.199:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4gXgpx5ks9joCJTKXYNAAAAfQ"]
[Mon Jul 20 07:19:26.904906 2026] [security2:error] [pid 95126:tid 95263] [client 57.141.18.59:28446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gXApx5ks9joCJTKXXbQABlDs"]
[Mon Jul 20 07:19:26.980387 2026] [core:error] [pid 95126:tid 95372] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:26.980404 2026] [core:error] [pid 95126:tid 95372] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:26.983256 2026] [security2:error] [pid 95126:tid 95377] [client 207.175.80.208:49408] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4gXgpx5ks9joCJTKXYQQAAAgY"]
[Mon Jul 20 07:19:27.270347 2026] [security2:error] [pid 94831:tid 94938] [remote 5.161.225.162:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4gX406NaEKF1g_MW25XQAANGo"], referer: https://solkeetw.com/wp-login.php
[Mon Jul 20 07:19:27.307521 2026] [security2:error] [pid 94831:tid 94985] [client 116.179.32.157:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gX406NaEKF1g_MW25WQAAABg"]
[Mon Jul 20 07:19:27.410152 2026] [security2:error] [pid 95126:tid 95314] [client 104.234.53.55:39993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gXwpx5ks9joCJTKXYWwAAAcc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:27.459866 2026] [security2:error] [pid 95126:tid 95327] [client 77.110.127.138:63441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXwpx5ks9joCJTKXYXwAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:27.459983 2026] [security2:error] [pid 95126:tid 95327] [client 77.110.127.138:63441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gXwpx5ks9joCJTKXYXwAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:27.579259 2026] [security2:error] [pid 95126:tid 95354] [client 207.175.80.208:51962] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4gXwpx5ks9joCJTKXYaAAAAe8"]
[Mon Jul 20 07:19:27.906516 2026] [security2:error] [pid 95126:tid 95358] [client 14.225.17.146:52411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4gXwpx5ks9joCJTKXYdAAAAfM"], referer: http://christiancountytrumpet.com/2019
[Mon Jul 20 07:19:27.922627 2026] [security2:error] [pid 95126:tid 95291] [client 57.141.18.125:49472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gXQpx5ks9joCJTKXXpgABsCY"]
[Mon Jul 20 07:19:28.112213 2026] [security2:error] [pid 95126:tid 95306] [client 14.225.17.146:49214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4gXwpx5ks9joCJTKXYfgAAAb8"], referer: http://itdynamix.com/2019
[Mon Jul 20 07:19:28.168366 2026] [security2:error] [pid 94831:tid 95001] [client 207.175.80.208:54224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4gYI06NaEKF1g_MW25cgAAACg"]
[Mon Jul 20 07:19:28.289041 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:63445] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gYI06NaEKF1g_MW25dwAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:28.360926 2026] [security2:error] [pid 94831:tid 95050] [client 34.221.76.50:10114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4gYI06NaEKF1g_MW25eQAAAFk"]
[Mon Jul 20 07:19:28.754093 2026] [security2:error] [pid 94831:tid 95012] [client 207.175.80.208:58061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4gYI06NaEKF1g_MW25iQAAADM"]
[Mon Jul 20 07:19:28.769771 2026] [security2:error] [pid 95126:tid 95383] [client 14.225.17.146:51231] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4gXwpx5ks9joCJTKXYVgAAAgw"], referer: http://olearyplumbingllc.com/2019
[Mon Jul 20 07:19:28.779244 2026] [security2:error] [pid 95126:tid 95358] [client 34.91.36.231:24577] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cheaterreader.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gYApx5ks9joCJTKXYqwAAAfM"]
[Mon Jul 20 07:19:28.779315 2026] [security2:error] [pid 95126:tid 95358] [client 34.91.36.231:24577] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cheaterreader.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gYApx5ks9joCJTKXYqwAAAfM"]
[Mon Jul 20 07:19:29.070812 2026] [core:error] [pid 95126:tid 95338] [client 14.225.17.146:52083] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:29.070845 2026] [core:error] [pid 95126:tid 95338] [client 14.225.17.146:52083] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:29.142933 2026] [security2:error] [pid 95126:tid 95313] [client 15.237.142.234:32502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gYQpx5ks9joCJTKXYyAAAAcY"]
[Mon Jul 20 07:19:29.143070 2026] [security2:error] [pid 95126:tid 95313] [client 15.237.142.234:32502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gYQpx5ks9joCJTKXYyAAAAcY"]
[Mon Jul 20 07:19:29.167375 2026] [security2:error] [pid 95126:tid 95289] [client 14.225.17.146:52558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4gYQpx5ks9joCJTKXYuQAAAa4"], referer: https://itdynamix.com/2019
[Mon Jul 20 07:19:29.203784 2026] [security2:error] [pid 95126:tid 95320] [client 77.110.127.138:63456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYQpx5ks9joCJTKXY0AAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:29.203891 2026] [security2:error] [pid 95126:tid 95320] [client 77.110.127.138:63456] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYQpx5ks9joCJTKXY0AAAAc0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:29.209737 2026] [security2:error] [pid 94831:tid 95005] [client 103.144.65.217:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gYY06NaEKF1g_MW25jQAAACw"]
[Mon Jul 20 07:19:29.209844 2026] [security2:error] [pid 94831:tid 95005] [client 103.144.65.217:56100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gYY06NaEKF1g_MW25jQAAACw"]
[Mon Jul 20 07:19:29.257591 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:63424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYQpx5ks9joCJTKXY1wAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:29.257682 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:63424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYQpx5ks9joCJTKXY1wAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:29.428871 2026] [security2:error] [pid 95126:tid 95369] [client 207.175.80.208:56155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4gYQpx5ks9joCJTKXY4QAAAf4"]
[Mon Jul 20 07:19:29.440086 2026] [security2:error] [pid 95126:tid 95367] [client 117.211.236.168:64121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gYQpx5ks9joCJTKXY4wAAAfw"]
[Mon Jul 20 07:19:29.440229 2026] [security2:error] [pid 95126:tid 95367] [client 117.211.236.168:64121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gYQpx5ks9joCJTKXY4wAAAfw"]
[Mon Jul 20 07:19:29.447531 2026] [security2:error] [pid 95126:tid 95296] [client 57.141.18.66:24388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gXgpx5ks9joCJTKXYFwABtSs"]
[Mon Jul 20 07:19:29.841081 2026] [security2:error] [pid 95126:tid 95300] [client 57.141.18.55:30658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gXgpx5ks9joCJTKXYNgABuRw"]
[Mon Jul 20 07:19:29.902028 2026] [security2:error] [pid 95126:tid 95281] [client 13.233.207.33:61126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gYQpx5ks9joCJTKXZAQAAAaY"]
[Mon Jul 20 07:19:29.902126 2026] [security2:error] [pid 95126:tid 95281] [client 13.233.207.33:61126] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gYQpx5ks9joCJTKXZAQAAAaY"]
[Mon Jul 20 07:19:30.049809 2026] [security2:error] [pid 95126:tid 95339] [client 207.175.80.208:56889] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4gYgpx5ks9joCJTKXZCgAAAeA"]
[Mon Jul 20 07:19:30.189956 2026] [security2:error] [pid 95126:tid 95290] [client 77.110.127.138:63461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYgpx5ks9joCJTKXZFgAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:30.197067 2026] [security2:error] [pid 95126:tid 95290] [client 77.110.127.138:63461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYgpx5ks9joCJTKXZFgAAAa8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:30.266412 2026] [core:error] [pid 95126:tid 95311] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:30.266436 2026] [core:error] [pid 95126:tid 95311] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:30.269735 2026] [core:error] [pid 95126:tid 95342] [client 87.236.176.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:30.269757 2026] [core:error] [pid 95126:tid 95342] [client 87.236.176.37:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:30.508252 2026] [security2:error] [pid 95126:tid 95307] [client 14.225.17.146:52104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4gYApx5ks9joCJTKXYrAAAAcA"], referer: http://aandarealtygroup.com/2019
[Mon Jul 20 07:19:30.549219 2026] [security2:error] [pid 95126:tid 95360] [client 77.110.127.138:63433] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gYgpx5ks9joCJTKXZLwAAAfU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:30.563711 2026] [core:error] [pid 95126:tid 95383] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:30.563737 2026] [core:error] [pid 95126:tid 95383] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:30.637996 2026] [security2:error] [pid 95126:tid 95265] [client 207.175.80.208:57304] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4gYgpx5ks9joCJTKXZOgAAAZY"]
[Mon Jul 20 07:19:30.778782 2026] [security2:error] [pid 95126:tid 95300] [client 14.225.17.146:52050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4gYgpx5ks9joCJTKXZNwAAAbk"], referer: http://swafforddetailing.com/2019
[Mon Jul 20 07:19:30.910448 2026] [security2:error] [pid 95126:tid 95322] [client 34.147.91.161:32774] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.partythingy.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gYgpx5ks9joCJTKXZRwAAAc8"]
[Mon Jul 20 07:19:30.910541 2026] [security2:error] [pid 95126:tid 95322] [client 34.147.91.161:32774] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.partythingy.gns.xyp.mybluehost.me"] [uri "/"] [unique_id "al4gYgpx5ks9joCJTKXZRwAAAc8"]
[Mon Jul 20 07:19:31.121322 2026] [security2:error] [pid 95126:tid 95319] [client 57.141.18.118:39694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gXwpx5ks9joCJTKXYdgABzHg"]
[Mon Jul 20 07:19:31.121691 2026] [security2:error] [pid 94831:tid 94979] [client 57.141.18.123:64738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gX406NaEKF1g_MW25bQAAEls"]
[Mon Jul 20 07:19:31.224997 2026] [security2:error] [pid 95126:tid 95382] [client 207.175.80.208:62994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4gYwpx5ks9joCJTKXZXAAAAgs"]
[Mon Jul 20 07:19:31.250045 2026] [security2:error] [pid 94831:tid 95014] [client 77.110.127.138:63439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gY406NaEKF1g_MW25vwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.250153 2026] [security2:error] [pid 94831:tid 95014] [client 77.110.127.138:63439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gY406NaEKF1g_MW25vwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.309274 2026] [security2:error] [pid 95126:tid 95351] [client 57.141.18.94:48450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gXwpx5ks9joCJTKXYfQAB7G8"]
[Mon Jul 20 07:19:31.405106 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYwpx5ks9joCJTKXZZAAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.405236 2026] [security2:error] [pid 95126:tid 95304] [client 77.110.127.138:63465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYwpx5ks9joCJTKXZZAAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.547131 2026] [core:error] [pid 94831:tid 94969] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:31.547160 2026] [core:error] [pid 94831:tid 94969] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:31.633214 2026] [security2:error] [pid 95126:tid 95263] [client 57.141.18.21:58148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gYApx5ks9joCJTKXYlgABlBc"]
[Mon Jul 20 07:19:31.649261 2026] [security2:error] [pid 95126:tid 95207] [remote 57.141.18.97:32744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4gYwpx5ks9joCJTKXZegAB404"]
[Mon Jul 20 07:19:31.723179 2026] [security2:error] [pid 95126:tid 95198] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gYwpx5ks9joCJTKXZggABk0U"]
[Mon Jul 20 07:19:31.723304 2026] [security2:error] [pid 95126:tid 95262] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gYwpx5ks9joCJTKXZggABk0U"]
[Mon Jul 20 07:19:31.737088 2026] [security2:error] [pid 95126:tid 95371] [client 77.110.127.138:63442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYwpx5ks9joCJTKXZgwAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.737184 2026] [security2:error] [pid 95126:tid 95371] [client 77.110.127.138:63442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYwpx5ks9joCJTKXZgwAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.788743 2026] [security2:error] [pid 94831:tid 95056] [client 77.110.127.138:63445] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gY406NaEKF1g_MW25yQAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.790802 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYwpx5ks9joCJTKXZhwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.790888 2026] [security2:error] [pid 95126:tid 95293] [client 77.110.127.138:63468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gYwpx5ks9joCJTKXZhwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:31.794637 2026] [security2:error] [pid 94831:tid 95082] [client 207.175.80.208:58730] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "northmaineadventures.crmpfilms.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4gY406NaEKF1g_MW25ywAAAHk"]
[Mon Jul 20 07:19:31.801184 2026] [security2:error] [pid 95126:tid 95370] [client 14.225.17.146:52344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4gYgpx5ks9joCJTKXZQwAAAf8"]
[Mon Jul 20 07:19:31.939645 2026] [security2:error] [pid 95126:tid 95363] [client 13.233.207.33:61128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gYwpx5ks9joCJTKXZjgAAAfg"]
[Mon Jul 20 07:19:31.939723 2026] [security2:error] [pid 95126:tid 95363] [client 13.233.207.33:61128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4gYwpx5ks9joCJTKXZjgAAAfg"]
[Mon Jul 20 07:19:32.050330 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZlwAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:32.050436 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZlwAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:32.214669 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:63470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZnAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:32.214767 2026] [security2:error] [pid 95126:tid 95274] [client 77.110.127.138:63470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZnAAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:32.320986 2026] [security2:error] [pid 95126:tid 95279] [client 52.109.124.141:23553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gZApx5ks9joCJTKXZrAAAAaQ"]
[Mon Jul 20 07:19:32.335928 2026] [security2:error] [pid 95126:tid 95272] [client 77.110.127.138:63458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZsQAAAZ0"]
[Mon Jul 20 07:19:32.336038 2026] [security2:error] [pid 95126:tid 95272] [client 77.110.127.138:63458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZsQAAAZ0"]
[Mon Jul 20 07:19:32.400519 2026] [security2:error] [pid 95126:tid 95324] [client 57.141.18.75:30550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gYQpx5ks9joCJTKXYuwAB0Sg"]
[Mon Jul 20 07:19:32.502354 2026] [security2:error] [pid 95126:tid 95299] [client 52.109.124.141:23553] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gZApx5ks9joCJTKXZwgAAAbg"]
[Mon Jul 20 07:19:32.510977 2026] [security2:error] [pid 95126:tid 95369] [client 77.110.127.138:63473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZxAAAAf4"]
[Mon Jul 20 07:19:32.511072 2026] [security2:error] [pid 95126:tid 95369] [client 77.110.127.138:63473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZxAAAAf4"]
[Mon Jul 20 07:19:32.538321 2026] [security2:error] [pid 94831:tid 95002] [client 103.176.215.66:56520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gZI06NaEKF1g_MW252wAAACk"]
[Mon Jul 20 07:19:32.538957 2026] [security2:error] [pid 94831:tid 95002] [client 103.176.215.66:56520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gZI06NaEKF1g_MW252wAAACk"]
[Mon Jul 20 07:19:32.572274 2026] [security2:error] [pid 95126:tid 95344] [client 77.110.127.138:63432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZxgAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:32.572401 2026] [security2:error] [pid 95126:tid 95344] [client 77.110.127.138:63432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZApx5ks9joCJTKXZxgAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:32.581625 2026] [security2:error] [pid 95126:tid 95297] [client 143.44.185.218:2948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gZApx5ks9joCJTKXZxwAAAbY"]
[Mon Jul 20 07:19:32.581721 2026] [security2:error] [pid 95126:tid 95297] [client 143.44.185.218:2948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gZApx5ks9joCJTKXZxwAAAbY"]
[Mon Jul 20 07:19:32.644974 2026] [security2:error] [pid 95126:tid 95337] [client 88.241.67.160:53843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gZApx5ks9joCJTKXZzQAAAd4"]
[Mon Jul 20 07:19:32.645096 2026] [security2:error] [pid 95126:tid 95337] [client 88.241.67.160:53843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gZApx5ks9joCJTKXZzQAAAd4"]
[Mon Jul 20 07:19:32.856220 2026] [security2:error] [pid 95126:tid 95321] [client 52.109.52.84:7104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gZApx5ks9joCJTKXZ2wAAAc4"]
[Mon Jul 20 07:19:32.968627 2026] [security2:error] [pid 95126:tid 95306] [client 52.109.52.84:7104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gZApx5ks9joCJTKXZ4wAAAb8"]
[Mon Jul 20 07:19:33.017692 2026] [security2:error] [pid 95126:tid 95187] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXZ6QABwjo"]
[Mon Jul 20 07:19:33.017842 2026] [security2:error] [pid 95126:tid 95309] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXZ6QABwjo"]
[Mon Jul 20 07:19:33.094596 2026] [security2:error] [pid 95126:tid 95358] [client 157.20.138.62:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXZ7gAAAfM"]
[Mon Jul 20 07:19:33.095347 2026] [security2:error] [pid 95126:tid 95358] [client 157.20.138.62:51655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXZ7gAAAfM"]
[Mon Jul 20 07:19:33.132507 2026] [security2:error] [pid 95126:tid 95269] [client 57.141.18.48:46820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gYQpx5ks9joCJTKXY7QABmkk"]
[Mon Jul 20 07:19:33.205589 2026] [security2:error] [pid 95126:tid 95335] [client 50.116.65.227:12130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4gZQpx5ks9joCJTKXZ8QAAAdw"]
[Mon Jul 20 07:19:33.209506 2026] [security2:error] [pid 95126:tid 95336] [client 14.225.17.146:62570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4gZQpx5ks9joCJTKXZ7AAAAd0"], referer: http://recruitinginsight.us/2019
[Mon Jul 20 07:19:33.220431 2026] [security2:error] [pid 95126:tid 95282] [client 49.47.218.174:51984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXZ8gAAAac"]
[Mon Jul 20 07:19:33.220569 2026] [security2:error] [pid 95126:tid 95282] [client 49.47.218.174:51984] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXZ8gAAAac"]
[Mon Jul 20 07:19:33.289341 2026] [security2:error] [pid 95126:tid 95366] [client 77.110.127.138:63463] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4gZQpx5ks9joCJTKXZ9gAAAfs"]
[Mon Jul 20 07:19:33.312478 2026] [security2:error] [pid 95126:tid 95260] [client 14.225.17.146:60135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4gZApx5ks9joCJTKXZuQAAAZE"], referer: http://retzkolonglogistics.com/2019
[Mon Jul 20 07:19:33.314304 2026] [proxy:error] [pid 95126:tid 95307] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:33.314336 2026] [proxy_http:error] [pid 95126:tid 95307] [client 8.229.28.226:55388] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:33.315031 2026] [proxy:error] [pid 95126:tid 95307] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:33.315055 2026] [proxy_http:error] [pid 95126:tid 95307] [client 8.229.28.226:55388] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:33.372709 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63479] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gZQpx5ks9joCJTKXZ_QAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:33.423040 2026] [security2:error] [pid 95126:tid 95367] [client 77.110.127.138:63464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZQpx5ks9joCJTKXaAAAAAfw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:33.423174 2026] [security2:error] [pid 95126:tid 95367] [client 77.110.127.138:63464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZQpx5ks9joCJTKXaAAAAAfw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:33.544767 2026] [security2:error] [pid 94831:tid 95031] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4gZY06NaEKF1g_MW258AAAAEY"]
[Mon Jul 20 07:19:33.848542 2026] [security2:error] [pid 95126:tid 95233] [remote 113.160.142.119:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gZQpx5ks9joCJTKXaJwAB_2g"]
[Mon Jul 20 07:19:33.873097 2026] [security2:error] [pid 95126:tid 95375] [client 104.234.53.57:42513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gZQpx5ks9joCJTKXaKwAAAgQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:33.953392 2026] [security2:error] [pid 95126:tid 95295] [client 191.202.66.27:53410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXaLgAAAbQ"]
[Mon Jul 20 07:19:33.954796 2026] [security2:error] [pid 95126:tid 95295] [client 191.202.66.27:53410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gZQpx5ks9joCJTKXaLgAAAbQ"]
[Mon Jul 20 07:19:33.981031 2026] [security2:error] [pid 94831:tid 95020] [client 14.225.17.146:52466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4gZI06NaEKF1g_MW251gAAADs"], referer: http://ksands.co.uk/2019
[Mon Jul 20 07:19:33.998583 2026] [security2:error] [pid 94831:tid 95019] [client 57.141.18.115:52362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gYo06NaEKF1g_MW25rgAAOg4"]
[Mon Jul 20 07:19:34.039949 2026] [core:error] [pid 94831:tid 95032] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:34.039974 2026] [core:error] [pid 94831:tid 95032] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:34.168727 2026] [security2:error] [pid 94831:tid 95036] [client 14.225.17.146:52471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4gZo06NaEKF1g_MW26BQAAAEs"], referer: http://entuvy.com/2019
[Mon Jul 20 07:19:34.297444 2026] [security2:error] [pid 95126:tid 95302] [client 57.141.18.13:44426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gYgpx5ks9joCJTKXZQAABuxE"]
[Mon Jul 20 07:19:34.346558 2026] [security2:error] [pid 95126:tid 95249] [remote 113.160.142.119:34856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gZgpx5ks9joCJTKXaVAABkng"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:19:34.367019 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:63484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZgpx5ks9joCJTKXadwAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:34.367099 2026] [security2:error] [pid 95126:tid 95297] [client 77.110.127.138:63484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZgpx5ks9joCJTKXadwAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:34.421284 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZo06NaEKF1g_MW26QQAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:34.421380 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZo06NaEKF1g_MW26QQAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:34.548030 2026] [security2:error] [pid 94831:tid 95055] [client 57.141.18.64:34574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gY406NaEKF1g_MW25uQAAXh8"]
[Mon Jul 20 07:19:34.628978 2026] [security2:error] [pid 95126:tid 95372] [client 154.208.48.130:55406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gZgpx5ks9joCJTKXamgAAAgE"]
[Mon Jul 20 07:19:34.629076 2026] [security2:error] [pid 95126:tid 95372] [client 154.208.48.130:55406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gZgpx5ks9joCJTKXamgAAAgE"]
[Mon Jul 20 07:19:35.044931 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:63488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXaxwAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.046632 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:63488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXaxwAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.058055 2026] [security2:error] [pid 95126:tid 95261] [client 104.234.53.67:45475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gZwpx5ks9joCJTKXaxgAAAZI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:35.151418 2026] [security2:error] [pid 95126:tid 95283] [client 187.16.64.216:59203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gZwpx5ks9joCJTKXa1gAAAag"]
[Mon Jul 20 07:19:35.151565 2026] [security2:error] [pid 95126:tid 95283] [client 187.16.64.216:59203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gZwpx5ks9joCJTKXa1gAAAag"]
[Mon Jul 20 07:19:35.231574 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZ406NaEKF1g_MW26VQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.231654 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZ406NaEKF1g_MW26VQAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.376949 2026] [security2:error] [pid 95126:tid 95358] [client 49.37.242.14:54547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gZwpx5ks9joCJTKXa_QAAAfM"]
[Mon Jul 20 07:19:35.377074 2026] [security2:error] [pid 95126:tid 95358] [client 49.37.242.14:54547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gZwpx5ks9joCJTKXa_QAAAfM"]
[Mon Jul 20 07:19:35.447564 2026] [security2:error] [pid 95126:tid 95368] [client 103.106.165.44:57217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gZwpx5ks9joCJTKXbBgAAAf0"]
[Mon Jul 20 07:19:35.447659 2026] [security2:error] [pid 95126:tid 95368] [client 103.106.165.44:57217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gZwpx5ks9joCJTKXbBgAAAf0"]
[Mon Jul 20 07:19:35.453617 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:63494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZ406NaEKF1g_MW26YQAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.453717 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:63494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZ406NaEKF1g_MW26YQAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.542407 2026] [security2:error] [pid 95126:tid 95262] [client 14.225.17.146:51088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4gZwpx5ks9joCJTKXbAAAAAZM"], referer: http://slutilities.com/2019
[Mon Jul 20 07:19:35.601788 2026] [core:error] [pid 95126:tid 95345] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:35.601812 2026] [core:error] [pid 95126:tid 95345] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:35.688872 2026] [security2:error] [pid 95126:tid 95373] [client 57.141.18.29:63444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gYwpx5ks9joCJTKXZlAACAlc"]
[Mon Jul 20 07:19:35.706198 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXbFgAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.706337 2026] [security2:error] [pid 95126:tid 95329] [client 77.110.127.138:63496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXbFgAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.710670 2026] [security2:error] [pid 95126:tid 95308] [client 104.234.53.88:42049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gZwpx5ks9joCJTKXbFwAAAcE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:35.733191 2026] [security2:error] [pid 95126:tid 95309] [client 77.110.127.138:63497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXbGAAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.733289 2026] [security2:error] [pid 95126:tid 95309] [client 77.110.127.138:63497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXbGAAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.778057 2026] [security2:error] [pid 95126:tid 95343] [client 57.141.18.76:24078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZApx5ks9joCJTKXZlgAB5Fo"]
[Mon Jul 20 07:19:35.788613 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZ406NaEKF1g_MW26bAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.788701 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZ406NaEKF1g_MW26bAAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.833862 2026] [security2:error] [pid 95126:tid 95171] [remote 97.74.93.24:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gZwpx5ks9joCJTKXbIgABxSo"]
[Mon Jul 20 07:19:35.947493 2026] [security2:error] [pid 95126:tid 95246] [remote 194.164.192.228:46306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gZwpx5ks9joCJTKXbLQABonU"]
[Mon Jul 20 07:19:35.950603 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:63499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXbNAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:35.950674 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:63499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gZwpx5ks9joCJTKXbNAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:36.020526 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:63463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gaApx5ks9joCJTKXbPgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:36.020607 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:63463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gaApx5ks9joCJTKXbPgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:36.078771 2026] [security2:error] [pid 95126:tid 95326] [client 154.192.123.127:17234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gaApx5ks9joCJTKXbQQAAAdM"]
[Mon Jul 20 07:19:36.078975 2026] [security2:error] [pid 95126:tid 95326] [client 154.192.123.127:17234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gaApx5ks9joCJTKXbQQAAAdM"]
[Mon Jul 20 07:19:36.150609 2026] [security2:error] [pid 95126:tid 95188] [remote 194.164.192.228:46306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gaApx5ks9joCJTKXbQwABpDs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:19:36.214928 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gaApx5ks9joCJTKXbSgAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:36.215016 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gaApx5ks9joCJTKXbSgAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:36.231279 2026] [security2:error] [pid 95126:tid 95248] [remote 97.74.93.24:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gaApx5ks9joCJTKXbSwAB7nc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:19:36.260556 2026] [security2:error] [pid 95126:tid 95284] [client 144.172.114.51:58792] ModSecurity: Access denied with code 406 (phase 2). Pattern match "[$]{[\\\\w{}\\\\-:$]*j[\\\\w{}\\\\-:$]*n[\\\\w{}\\\\-:$]*d[\\\\w{}\\\\-:$]*i[\\\\w{}\\\\-:$]*:.*}" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1535"] [id "345117"] [rev "2"] [msg "Atomicorp.com WAF Rules - Virtual Just In Time Patch: log4j CVE-2021-44228 broad scope obfuscated attack blocked"] [severity "CRITICAL"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/"] [unique_id "al4gaApx5ks9joCJTKXbTAAAAak"]
[Mon Jul 20 07:19:36.573062 2026] [security2:error] [pid 95126:tid 95276] [client 14.225.17.146:52011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4gZwpx5ks9joCJTKXazQAAAaE"], referer: http://alexsandbergmusic.com/2019
[Mon Jul 20 07:19:36.692784 2026] [security2:error] [pid 95126:tid 95322] [client 82.102.18.116:42424] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4gaApx5ks9joCJTKXbbAAAAc8"]
[Mon Jul 20 07:19:36.718388 2026] [security2:error] [pid 95126:tid 95377] [client 57.141.18.77:50850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZApx5ks9joCJTKXZ0QACBmY"]
[Mon Jul 20 07:19:36.944190 2026] [security2:error] [pid 95126:tid 95259] [client 201.27.111.74:59425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gaApx5ks9joCJTKXbeQAAAZA"]
[Mon Jul 20 07:19:36.944288 2026] [security2:error] [pid 95126:tid 95259] [client 201.27.111.74:59425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gaApx5ks9joCJTKXbeQAAAZA"]
[Mon Jul 20 07:19:37.209027 2026] [security2:error] [pid 95126:tid 95228] [remote 124.55.178.99:39982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gaQpx5ks9joCJTKXbjQABuGM"]
[Mon Jul 20 07:19:37.243660 2026] [security2:error] [pid 95126:tid 95324] [client 32.198.12.77:44458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gaQpx5ks9joCJTKXbjgAAAdE"]
[Mon Jul 20 07:19:37.338175 2026] [security2:error] [pid 95126:tid 95277] [client 82.102.18.116:42432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/xmlrpc.php"] [unique_id "al4gaQpx5ks9joCJTKXbmQAAAaI"]
[Mon Jul 20 07:19:37.429378 2026] [security2:error] [pid 95126:tid 95182] [remote 159.65.81.207:53930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gaQpx5ks9joCJTKXboAABvzU"]
[Mon Jul 20 07:19:37.501373 2026] [security2:error] [pid 95126:tid 95365] [client 57.141.18.91:59324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZQpx5ks9joCJTKXaDwAB-gQ"]
[Mon Jul 20 07:19:37.578028 2026] [security2:error] [pid 95126:tid 95289] [client 57.141.18.108:62818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZQpx5ks9joCJTKXaGQABri0"]
[Mon Jul 20 07:19:37.601485 2026] [security2:error] [pid 95126:tid 95369] [client 104.234.53.92:48107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gaQpx5ks9joCJTKXbtQAAAf4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:37.638977 2026] [security2:error] [pid 95126:tid 95166] [remote 124.55.178.99:39982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gaQpx5ks9joCJTKXbuAAB3CU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:19:37.642541 2026] [security2:error] [pid 95126:tid 95199] [remote 159.65.81.207:53930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gaQpx5ks9joCJTKXbtwAB1UY"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:19:37.763331 2026] [security2:error] [pid 95126:tid 95366] [client 57.141.18.99:51850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZQpx5ks9joCJTKXaKgAB-wI"]
[Mon Jul 20 07:19:37.904797 2026] [security2:error] [pid 95126:tid 95363] [client 98.85.250.161:18518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.250.85.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gaQpx5ks9joCJTKXbwgAAAfg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:19:38.248392 2026] [security2:error] [pid 95126:tid 95313] [client 158.173.241.141:52045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4gagpx5ks9joCJTKXbzQABxnI"]
[Mon Jul 20 07:19:38.285720 2026] [security2:error] [pid 95126:tid 95320] [client 82.102.18.116:42442] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4gagpx5ks9joCJTKXb1QAAAc0"]
[Mon Jul 20 07:19:38.291090 2026] [security2:error] [pid 95126:tid 95274] [client 50.116.65.227:12212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gagpx5ks9joCJTKXb1wAAAZ8"]
[Mon Jul 20 07:19:38.300887 2026] [security2:error] [pid 95126:tid 95267] [client 50.116.65.227:12224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gagpx5ks9joCJTKXb2gAAAZg"]
[Mon Jul 20 07:19:38.328409 2026] [security2:error] [pid 95126:tid 95348] [client 57.141.18.51:21938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZgpx5ks9joCJTKXahAAB6XY"]
[Mon Jul 20 07:19:38.463004 2026] [security2:error] [pid 95126:tid 95297] [client 82.102.27.163:46764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gagpx5ks9joCJTKXb5QAAAbY"]
[Mon Jul 20 07:19:38.463110 2026] [security2:error] [pid 95126:tid 95297] [client 82.102.27.163:46764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gagpx5ks9joCJTKXb5QAAAbY"]
[Mon Jul 20 07:19:38.648430 2026] [security2:error] [pid 94831:tid 95070] [client 14.225.17.146:57607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4gao06NaEKF1g_MW26mgAAAG0"]
[Mon Jul 20 07:19:38.669078 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gao06NaEKF1g_MW26rQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:38.669184 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gao06NaEKF1g_MW26rQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:38.679077 2026] [security2:error] [pid 94831:tid 94962] [client 74.208.214.194:32806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4gao06NaEKF1g_MW26rwAAAAE"]
[Mon Jul 20 07:19:38.680552 2026] [security2:error] [pid 95126:tid 95318] [client 57.141.18.8:56154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZgpx5ks9joCJTKXanAABywM"]
[Mon Jul 20 07:19:38.924815 2026] [security2:error] [pid 95126:tid 95280] [client 82.102.18.116:46414] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4gagpx5ks9joCJTKXcAwAAAaU"]
[Mon Jul 20 07:19:38.928089 2026] [security2:error] [pid 95126:tid 95344] [client 50.116.65.227:12568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4gagpx5ks9joCJTKXcBQAAAeU"]
[Mon Jul 20 07:19:38.942884 2026] [security2:error] [pid 95126:tid 95348] [client 50.116.65.227:43136] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4gagpx5ks9joCJTKXcBwAAAek"]
[Mon Jul 20 07:19:39.271264 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gawpx5ks9joCJTKXcHwAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:39.271357 2026] [security2:error] [pid 95126:tid 95337] [client 77.110.127.138:63522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gawpx5ks9joCJTKXcHwAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:39.351514 2026] [security2:error] [pid 95126:tid 95333] [client 77.110.127.138:63523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gawpx5ks9joCJTKXcKgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:39.351617 2026] [security2:error] [pid 95126:tid 95333] [client 77.110.127.138:63523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gawpx5ks9joCJTKXcKgAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:39.658406 2026] [security2:error] [pid 95126:tid 95280] [client 82.102.18.116:46416] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4gawpx5ks9joCJTKXcOwAAAaU"]
[Mon Jul 20 07:19:39.791141 2026] [security2:error] [pid 95126:tid 95269] [client 144.172.114.51:49432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-content/plugins/ultra/admin/options.php"] [unique_id "al4gawpx5ks9joCJTKXcQwAAAZo"]
[Mon Jul 20 07:19:39.796659 2026] [security2:error] [pid 95126:tid 95341] [client 103.144.65.217:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gawpx5ks9joCJTKXcRQAAAeI"]
[Mon Jul 20 07:19:39.796792 2026] [security2:error] [pid 95126:tid 95341] [client 103.144.65.217:56558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gawpx5ks9joCJTKXcRQAAAeI"]
[Mon Jul 20 07:19:39.866392 2026] [security2:error] [pid 95126:tid 95379] [client 57.141.18.121:64530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gZwpx5ks9joCJTKXbOQACCE4"]
[Mon Jul 20 07:19:39.893297 2026] [security2:error] [pid 95126:tid 95310] [client 14.225.17.146:51015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4gawpx5ks9joCJTKXcLwAAAcM"], referer: http://alrowad-hub.net/2019
[Mon Jul 20 07:19:40.091131 2026] [security2:error] [pid 94831:tid 94832] [remote 20.173.88.122:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gbI06NaEKF1g_MW26zAAAVAA"]
[Mon Jul 20 07:19:40.203117 2026] [security2:error] [pid 95126:tid 95236] [remote 20.153.140.50:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gbApx5ks9joCJTKXcXwAB1Ws"]
[Mon Jul 20 07:19:40.236347 2026] [security2:error] [pid 95126:tid 95367] [client 37.239.72.135:64868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4gbApx5ks9joCJTKXcXAAAAfw"]
[Mon Jul 20 07:19:40.287111 2026] [security2:error] [pid 95126:tid 95360] [client 82.102.18.116:46432] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4gbApx5ks9joCJTKXcYgAAAfU"]
[Mon Jul 20 07:19:40.364687 2026] [security2:error] [pid 95126:tid 95262] [client 77.110.127.138:63536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXcbwAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:40.364852 2026] [security2:error] [pid 95126:tid 95262] [client 77.110.127.138:63536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXcbwAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:40.369114 2026] [security2:error] [pid 95126:tid 95308] [client 202.141.11.99:27533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gbApx5ks9joCJTKXcbQAAAcE"]
[Mon Jul 20 07:19:40.369251 2026] [security2:error] [pid 95126:tid 95308] [client 202.141.11.99:27533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gbApx5ks9joCJTKXcbQAAAcE"]
[Mon Jul 20 07:19:40.408157 2026] [security2:error] [pid 95126:tid 95383] [client 158.173.241.141:61117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXcbAAAAgw"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:40.408287 2026] [security2:error] [pid 95126:tid 95383] [client 158.173.241.141:61117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXcbAAAAgw"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:40.424278 2026] [security2:error] [pid 94831:tid 94844] [remote 20.173.88.122:52276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gbI06NaEKF1g_MW262AAATww"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:19:40.451083 2026] [core:error] [pid 95126:tid 95277] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:40.451110 2026] [core:error] [pid 95126:tid 95277] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:40.583551 2026] [security2:error] [pid 94831:tid 95042] [client 117.211.236.168:64901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gbI06NaEKF1g_MW262wAAAFE"]
[Mon Jul 20 07:19:40.583712 2026] [security2:error] [pid 94831:tid 95042] [client 117.211.236.168:64901] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gbI06NaEKF1g_MW262wAAAFE"]
[Mon Jul 20 07:19:40.614910 2026] [security2:error] [pid 95126:tid 95135] [remote 20.153.140.50:38702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gbApx5ks9joCJTKXcewAB-gY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:19:40.718495 2026] [security2:error] [pid 95126:tid 95330] [client 14.225.17.146:62627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4gagpx5ks9joCJTKXb2QAAAdc"], referer: http://healthylifegourmet.org/2019
[Mon Jul 20 07:19:40.894994 2026] [security2:error] [pid 95126:tid 95284] [client 158.173.241.141:42919] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXclAAAAak"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:40.900477 2026] [security2:error] [pid 95126:tid 95306] [client 14.225.17.146:60221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4gagpx5ks9joCJTKXcBAAAAb8"], referer: http://webgardensbypaula.com/2019
[Mon Jul 20 07:19:40.915228 2026] [security2:error] [pid 95126:tid 95276] [client 57.141.18.107:27324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gaQpx5ks9joCJTKXbhwABoS8"]
[Mon Jul 20 07:19:40.964335 2026] [security2:error] [pid 95126:tid 95348] [client 82.102.18.116:46438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4gbApx5ks9joCJTKXcmQAAAek"]
[Mon Jul 20 07:19:41.145445 2026] [security2:error] [pid 95126:tid 95337] [client 181.120.160.97:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4gawpx5ks9joCJTKXcQAAAAd4"]
[Mon Jul 20 07:19:41.222610 2026] [security2:error] [pid 95126:tid 95331] [client 57.141.18.47:20434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gaQpx5ks9joCJTKXbmwAB2As"]
[Mon Jul 20 07:19:41.264693 2026] [security2:error] [pid 94831:tid 95035] [client 77.110.127.138:63540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbY06NaEKF1g_MW267AAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:41.264802 2026] [security2:error] [pid 94831:tid 95035] [client 77.110.127.138:63540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbY06NaEKF1g_MW267AAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:41.438421 2026] [security2:error] [pid 95126:tid 95332] [client 57.141.18.69:41432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gaQpx5ks9joCJTKXbtgAB2Uc"]
[Mon Jul 20 07:19:41.606181 2026] [security2:error] [pid 95126:tid 95318] [client 57.141.0.52:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gbQpx5ks9joCJTKXcngAAAcs"]
[Mon Jul 20 07:19:41.628725 2026] [security2:error] [pid 94831:tid 94970] [client 82.102.18.116:46448] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4gbY06NaEKF1g_MW26-QAAAAk"]
[Mon Jul 20 07:19:41.866114 2026] [security2:error] [pid 95126:tid 95336] [client 57.141.18.7:35334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gagpx5ks9joCJTKXbxgAB3Uk"]
[Mon Jul 20 07:19:42.050927 2026] [security2:error] [pid 95126:tid 95131] [remote 4.205.168.44:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4gbgpx5ks9joCJTKXc1gAB3AI"]
[Mon Jul 20 07:19:42.087639 2026] [security2:error] [pid 95126:tid 95284] [client 158.173.241.141:42919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXclAAAAak"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:42.087713 2026] [security2:error] [pid 95126:tid 95284] [client 158.173.241.141:42919] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbApx5ks9joCJTKXclAAAAak"], referer: https://www.sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:42.214520 2026] [security2:error] [pid 95126:tid 95291] [client 14.225.17.146:57846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4gbgpx5ks9joCJTKXc1wAAAbA"], referer: http://backandneckpainrelieflaceychiropractor.com/2019
[Mon Jul 20 07:19:42.232294 2026] [security2:error] [pid 95126:tid 95229] [remote 4.205.168.44:58922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4gbgpx5ks9joCJTKXc7AABmmQ"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 07:19:42.259849 2026] [security2:error] [pid 95126:tid 95275] [client 82.102.18.116:46460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4gbgpx5ks9joCJTKXc7QAAAaA"]
[Mon Jul 20 07:19:42.284332 2026] [security2:error] [pid 95126:tid 95327] [client 57.141.18.75:50100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gagpx5ks9joCJTKXb5AAB1Gk"]
[Mon Jul 20 07:19:42.357048 2026] [security2:error] [pid 95126:tid 95278] [client 66.249.73.64:52636] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "logandelehanty.org"] [uri "/robots.txt"] [unique_id "al4gbgpx5ks9joCJTKXc9wAAAaM"]
[Mon Jul 20 07:19:42.411175 2026] [security2:error] [pid 95126:tid 95193] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gbgpx5ks9joCJTKXdAQACB0A"]
[Mon Jul 20 07:19:42.411298 2026] [security2:error] [pid 95126:tid 95378] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gbgpx5ks9joCJTKXdAQACB0A"]
[Mon Jul 20 07:19:42.433372 2026] [security2:error] [pid 95126:tid 95358] [client 77.110.127.138:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbgpx5ks9joCJTKXdCAAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:42.433489 2026] [security2:error] [pid 95126:tid 95358] [client 77.110.127.138:63546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbgpx5ks9joCJTKXdCAAAAfM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:42.465373 2026] [security2:error] [pid 95126:tid 95318] [client 144.172.114.51:49450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-content/plugins/ultra/admin/options.php"] [unique_id "al4gbgpx5ks9joCJTKXdCwAAAcs"]
[Mon Jul 20 07:19:42.488161 2026] [security2:error] [pid 95126:tid 95153] [remote 152.228.213.32:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4gbgpx5ks9joCJTKXdDAAB4Rg"]
[Mon Jul 20 07:19:42.602538 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:63548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbgpx5ks9joCJTKXdFgAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:42.602676 2026] [security2:error] [pid 95126:tid 95303] [client 77.110.127.138:63548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbgpx5ks9joCJTKXdFgAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:42.688330 2026] [security2:error] [pid 95126:tid 95180] [remote 152.228.213.32:38842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4gbgpx5ks9joCJTKXdHAACCTM"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:19:42.770926 2026] [security2:error] [pid 95126:tid 95384] [client 50.116.65.227:12574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gbgpx5ks9joCJTKXdIwAAAg0"]
[Mon Jul 20 07:19:42.782637 2026] [security2:error] [pid 95126:tid 95358] [client 50.116.65.227:43230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gbgpx5ks9joCJTKXdJAAAAek"]
[Mon Jul 20 07:19:42.815973 2026] [security2:error] [pid 95126:tid 95258] [client 14.225.17.146:60711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4gbgpx5ks9joCJTKXdHgAAAY8"], referer: http://betterbonddogtraining.com/2019
[Mon Jul 20 07:19:42.870663 2026] [security2:error] [pid 95126:tid 95322] [client 57.141.18.40:24056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gawpx5ks9joCJTKXcDQABzyQ"]
[Mon Jul 20 07:19:42.892899 2026] [security2:error] [pid 95126:tid 95281] [client 82.102.18.116:46476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4gbgpx5ks9joCJTKXdLAAAAaY"]
[Mon Jul 20 07:19:43.153302 2026] [security2:error] [pid 95126:tid 95385] [client 103.176.215.66:57243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdNwAAAg4"]
[Mon Jul 20 07:19:43.153409 2026] [security2:error] [pid 95126:tid 95385] [client 103.176.215.66:57243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdNwAAAg4"]
[Mon Jul 20 07:19:43.157643 2026] [security2:error] [pid 94831:tid 95043] [client 104.234.53.72:22645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gb406NaEKF1g_MW27EQAAAFI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:43.206551 2026] [security2:error] [pid 95126:tid 95354] [client 143.44.185.218:4385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdOgAAAe8"]
[Mon Jul 20 07:19:43.206660 2026] [security2:error] [pid 95126:tid 95354] [client 143.44.185.218:4385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdOgAAAe8"]
[Mon Jul 20 07:19:43.488230 2026] [security2:error] [pid 95126:tid 95306] [client 88.241.67.160:55217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdUwAAAb8"]
[Mon Jul 20 07:19:43.488395 2026] [security2:error] [pid 95126:tid 95306] [client 88.241.67.160:55217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdUwAAAb8"]
[Mon Jul 20 07:19:43.505477 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:63551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbwpx5ks9joCJTKXdVAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:43.505592 2026] [security2:error] [pid 95126:tid 95348] [client 77.110.127.138:63551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbwpx5ks9joCJTKXdVAAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:43.557562 2026] [security2:error] [pid 95126:tid 95292] [client 82.102.18.116:46486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4gbwpx5ks9joCJTKXdVQAAAbE"]
[Mon Jul 20 07:19:43.665775 2026] [security2:error] [pid 95126:tid 95168] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdYgAB-ic"]
[Mon Jul 20 07:19:43.665965 2026] [security2:error] [pid 95126:tid 95365] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdYgAB-ic"]
[Mon Jul 20 07:19:43.676447 2026] [security2:error] [pid 95126:tid 95274] [client 49.47.218.174:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdYwAAAZ8"]
[Mon Jul 20 07:19:43.676810 2026] [security2:error] [pid 95126:tid 95274] [client 49.47.218.174:52494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gbwpx5ks9joCJTKXdYwAAAZ8"]
[Mon Jul 20 07:19:43.714189 2026] [security2:error] [pid 95126:tid 95355] [client 57.141.18.12:48196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gawpx5ks9joCJTKXcPQAB8Fc"]
[Mon Jul 20 07:19:43.759110 2026] [security2:error] [pid 94831:tid 95032] [client 157.20.138.62:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gb406NaEKF1g_MW27GgAAAEc"]
[Mon Jul 20 07:19:43.759221 2026] [security2:error] [pid 94831:tid 95032] [client 157.20.138.62:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gb406NaEKF1g_MW27GgAAAEc"]
[Mon Jul 20 07:19:43.770785 2026] [security2:error] [pid 95126:tid 95378] [client 77.110.127.138:63552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbwpx5ks9joCJTKXdcAAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:43.770889 2026] [security2:error] [pid 95126:tid 95378] [client 77.110.127.138:63552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gbwpx5ks9joCJTKXdcAAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:44.017025 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:63555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcI06NaEKF1g_MW27IgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:44.017150 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:63555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcI06NaEKF1g_MW27IgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:44.075933 2026] [security2:error] [pid 95126:tid 95290] [client 174.138.64.189:65364] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.fluidtemple.org"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4gcApx5ks9joCJTKXdhAAAAa8"]
[Mon Jul 20 07:19:44.106921 2026] [security2:error] [pid 95126:tid 95321] [client 57.141.18.88:49644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gbApx5ks9joCJTKXcUgABzg8"]
[Mon Jul 20 07:19:44.140868 2026] [security2:error] [pid 95126:tid 95358] [client 158.173.241.141:45987] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4gbwpx5ks9joCJTKXdgQAAAfM"], referer: http://sesamegreenbeans.com/flying-vietnam-airlines-a321/
[Mon Jul 20 07:19:44.230958 2026] [security2:error] [pid 95126:tid 95271] [client 82.102.18.116:46496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4gcApx5ks9joCJTKXdiwAAAZw"]
[Mon Jul 20 07:19:44.451416 2026] [security2:error] [pid 95126:tid 95352] [client 191.202.66.27:53876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gcApx5ks9joCJTKXdlwAAAe0"]
[Mon Jul 20 07:19:44.451539 2026] [security2:error] [pid 95126:tid 95352] [client 191.202.66.27:53876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gcApx5ks9joCJTKXdlwAAAe0"]
[Mon Jul 20 07:19:44.808696 2026] [security2:error] [pid 95126:tid 95272] [client 50.116.65.227:12588] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gcApx5ks9joCJTKXdqQAAAZ0"]
[Mon Jul 20 07:19:44.818784 2026] [security2:error] [pid 95126:tid 95309] [client 50.116.65.227:43232] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gcApx5ks9joCJTKXdqwAAAgE"]
[Mon Jul 20 07:19:44.862097 2026] [security2:error] [pid 95126:tid 95278] [client 82.102.18.116:46510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4gcApx5ks9joCJTKXdsAAAAaM"]
[Mon Jul 20 07:19:44.949851 2026] [security2:error] [pid 94831:tid 94974] [client 57.141.18.16:61766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gbI06NaEKF1g_MW263wAADRw"]
[Mon Jul 20 07:19:44.971623 2026] [security2:error] [pid 95126:tid 95344] [client 14.225.17.146:57845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4gcApx5ks9joCJTKXdrwAAAeU"], referer: http://aljosour-alarabia.com/2019
[Mon Jul 20 07:19:44.983053 2026] [security2:error] [pid 94831:tid 95010] [client 77.110.127.138:63561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcI06NaEKF1g_MW27OwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:44.983131 2026] [security2:error] [pid 94831:tid 95010] [client 77.110.127.138:63561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcI06NaEKF1g_MW27OwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:45.009597 2026] [security2:error] [pid 94831:tid 94869] [remote 62.193.192.29:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4gcI06NaEKF1g_MW27PQAABSU"]
[Mon Jul 20 07:19:45.054785 2026] [security2:error] [pid 94831:tid 95054] [client 77.110.127.138:63538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcY06NaEKF1g_MW27QgAAAF0"]
[Mon Jul 20 07:19:45.054897 2026] [security2:error] [pid 94831:tid 95054] [client 77.110.127.138:63538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcY06NaEKF1g_MW27QgAAAF0"]
[Mon Jul 20 07:19:45.184506 2026] [security2:error] [pid 94831:tid 94901] [remote 62.193.192.29:36200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4gcY06NaEKF1g_MW27RQAAT0U"], referer: https://joulecommunications.com/wp-login.php
[Mon Jul 20 07:19:45.212163 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcQpx5ks9joCJTKXdywAAAfg"]
[Mon Jul 20 07:19:45.212254 2026] [security2:error] [pid 95126:tid 95363] [client 77.110.127.138:63566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcQpx5ks9joCJTKXdywAAAfg"]
[Mon Jul 20 07:19:45.214430 2026] [security2:error] [pid 95126:tid 95379] [client 77.110.127.138:63539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcQpx5ks9joCJTKXdzAAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:45.214538 2026] [security2:error] [pid 95126:tid 95379] [client 77.110.127.138:63539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcQpx5ks9joCJTKXdzAAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:45.359121 2026] [security2:error] [pid 95126:tid 95380] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gcQpx5ks9joCJTKXdyAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:45.494391 2026] [security2:error] [pid 94831:tid 95034] [client 82.102.18.116:46518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4gcY06NaEKF1g_MW27VQAAAEk"]
[Mon Jul 20 07:19:45.553756 2026] [security2:error] [pid 95126:tid 95288] [client 185.93.182.171:51418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.182.93.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gcQpx5ks9joCJTKXd3QAAAa0"]
[Mon Jul 20 07:19:45.553873 2026] [security2:error] [pid 95126:tid 95288] [client 185.93.182.171:51418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gcQpx5ks9joCJTKXd3QAAAa0"]
[Mon Jul 20 07:19:45.630459 2026] [security2:error] [pid 94831:tid 95055] [client 154.208.48.130:55912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gcY06NaEKF1g_MW27XQAAAF4"]
[Mon Jul 20 07:19:45.630600 2026] [security2:error] [pid 94831:tid 95055] [client 154.208.48.130:55912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gcY06NaEKF1g_MW27XQAAAF4"]
[Mon Jul 20 07:19:45.753375 2026] [security2:error] [pid 95126:tid 95145] [remote 5.161.225.162:47086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4gcQpx5ks9joCJTKXd5AABvhA"]
[Mon Jul 20 07:19:45.819561 2026] [proxy:error] [pid 95126:tid 95351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:45.819623 2026] [proxy_http:error] [pid 95126:tid 95351] [client 8.229.28.226:55194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:45.820802 2026] [proxy:error] [pid 95126:tid 95351] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:45.820852 2026] [proxy_http:error] [pid 95126:tid 95351] [client 8.229.28.226:55194] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:45.902949 2026] [security2:error] [pid 94831:tid 95006] [client 187.16.64.216:59779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gcY06NaEKF1g_MW27aAAAAC0"]
[Mon Jul 20 07:19:45.903118 2026] [security2:error] [pid 94831:tid 95006] [client 187.16.64.216:59779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gcY06NaEKF1g_MW27aAAAAC0"]
[Mon Jul 20 07:19:45.938459 2026] [security2:error] [pid 95126:tid 95296] [client 103.106.165.44:57655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gcQpx5ks9joCJTKXd7gAAAbU"]
[Mon Jul 20 07:19:45.938622 2026] [security2:error] [pid 95126:tid 95296] [client 103.106.165.44:57655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gcQpx5ks9joCJTKXd7gAAAbU"]
[Mon Jul 20 07:19:45.968648 2026] [security2:error] [pid 95126:tid 95346] [client 14.225.17.146:59293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4gbwpx5ks9joCJTKXdVgAAAec"], referer: http://drewsasburyparkbeachhouse.com/2019
[Mon Jul 20 07:19:45.978735 2026] [security2:error] [pid 95126:tid 95225] [remote 5.161.225.162:47086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4gcQpx5ks9joCJTKXd8AAB42A"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:19:46.118031 2026] [security2:error] [pid 94831:tid 95033] [client 82.102.18.116:46520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4gco06NaEKF1g_MW27eAAAAEg"]
[Mon Jul 20 07:19:46.185557 2026] [security2:error] [pid 94831:tid 95075] [client 50.116.65.227:12594] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gco06NaEKF1g_MW27eQAAAHI"]
[Mon Jul 20 07:19:46.197212 2026] [security2:error] [pid 95126:tid 95274] [client 50.116.65.227:43296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/VN-Feature-Image.jpg"] [unique_id "al4gcgpx5ks9joCJTKXd_QAAAZ8"]
[Mon Jul 20 07:19:46.306626 2026] [proxy:error] [pid 94831:tid 95037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:46.306672 2026] [proxy_http:error] [pid 94831:tid 95037] [client 8.229.28.226:43504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:46.307395 2026] [proxy:error] [pid 94831:tid 95037] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:19:46.307423 2026] [proxy_http:error] [pid 94831:tid 95037] [client 8.229.28.226:43504] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:19:46.439858 2026] [security2:error] [pid 95126:tid 95270] [client 54.158.124.211:10514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.124.158.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4gcgpx5ks9joCJTKXeCwAAAZs"], referer: https://curlsnpearlsss.com/es/tag/cook-the-bacalao-guisado/
[Mon Jul 20 07:19:46.565296 2026] [security2:error] [pid 95126:tid 95276] [client 77.110.127.138:63572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcgpx5ks9joCJTKXeGwAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:46.565414 2026] [security2:error] [pid 95126:tid 95276] [client 77.110.127.138:63572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcgpx5ks9joCJTKXeGwAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:46.600900 2026] [security2:error] [pid 94831:tid 94972] [client 154.192.123.127:17617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gco06NaEKF1g_MW27hQAAAAs"]
[Mon Jul 20 07:19:46.601012 2026] [security2:error] [pid 94831:tid 94972] [client 154.192.123.127:17617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gco06NaEKF1g_MW27hQAAAAs"]
[Mon Jul 20 07:19:46.691480 2026] [security2:error] [pid 94831:tid 94986] [client 57.141.18.62:45084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gbo06NaEKF1g_MW27CAAAGSw"]
[Mon Jul 20 07:19:46.712563 2026] [security2:error] [pid 95126:tid 95296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gcgpx5ks9joCJTKXeFgAAAbU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:46.747431 2026] [security2:error] [pid 95126:tid 95305] [client 82.102.18.116:46534] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4gcgpx5ks9joCJTKXeJgAAAb4"]
[Mon Jul 20 07:19:47.032611 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcwpx5ks9joCJTKXeOQAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:47.032707 2026] [security2:error] [pid 95126:tid 95265] [client 77.110.127.138:63576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcwpx5ks9joCJTKXeOQAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:47.086681 2026] [security2:error] [pid 95126:tid 95321] [client 52.140.101.203:25475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gcwpx5ks9joCJTKXeQAAAAc4"]
[Mon Jul 20 07:19:47.132398 2026] [security2:error] [pid 95126:tid 95385] [client 14.225.17.146:59161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4gcQpx5ks9joCJTKXd1AAAAg4"], referer: http://narv.co/2019
[Mon Jul 20 07:19:47.184309 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:63578] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 469 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gc406NaEKF1g_MW27kgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:47.202684 2026] [security2:error] [pid 94831:tid 94967] [client 57.141.18.81:43976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gbo06NaEKF1g_MW27DQAABiY"]
[Mon Jul 20 07:19:47.245863 2026] [security2:error] [pid 94831:tid 95029] [client 52.207.32.99:51888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gc406NaEKF1g_MW27lQAAAEQ"], referer: https://curlsnpearlsss.com/es/tag/cook-the-bacalao-guisado/
[Mon Jul 20 07:19:47.266275 2026] [security2:error] [pid 95126:tid 95258] [client 14.225.17.146:59218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4gcwpx5ks9joCJTKXeNQAAAY8"], referer: http://idigress.agency/2019
[Mon Jul 20 07:19:47.294770 2026] [security2:error] [pid 95126:tid 95344] [client 185.209.229.78:40622] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXeTAAAAeU"]
[Mon Jul 20 07:19:47.304230 2026] [security2:error] [pid 94831:tid 95082] [client 201.27.111.74:59935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gc406NaEKF1g_MW27mAAAAHk"]
[Mon Jul 20 07:19:47.304323 2026] [security2:error] [pid 94831:tid 95082] [client 201.27.111.74:59935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gc406NaEKF1g_MW27mAAAAHk"]
[Mon Jul 20 07:19:47.318897 2026] [security2:error] [pid 95126:tid 95263] [client 52.140.101.203:25475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gcwpx5ks9joCJTKXeTQAAAZQ"]
[Mon Jul 20 07:19:47.369293 2026] [security2:error] [pid 95126:tid 95270] [client 82.102.18.116:58401] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "thierry-henry.fr"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4gcwpx5ks9joCJTKXeVgAAAZs"]
[Mon Jul 20 07:19:47.384935 2026] [security2:error] [pid 95126:tid 95276] [client 185.209.229.78:42680] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXeVwAAAaE"]
[Mon Jul 20 07:19:47.391113 2026] [security2:error] [pid 95126:tid 95357] [client 185.209.229.78:34814] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXeWQAAAfI"]
[Mon Jul 20 07:19:47.414237 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:63579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcwpx5ks9joCJTKXeXAAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:47.414324 2026] [security2:error] [pid 95126:tid 95305] [client 77.110.127.138:63579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gcwpx5ks9joCJTKXeXAAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:47.605875 2026] [security2:error] [pid 95126:tid 95380] [client 185.209.229.78:34442] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXeaQAAAgk"]
[Mon Jul 20 07:19:47.631379 2026] [security2:error] [pid 95126:tid 95367] [client 14.225.17.146:58848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4gcwpx5ks9joCJTKXeaAAAAfw"], referer: http://dasmarque.com/2019
[Mon Jul 20 07:19:47.649377 2026] [security2:error] [pid 95126:tid 95366] [client 123.18.146.67:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4gcwpx5ks9joCJTKXeOgAAAfs"]
[Mon Jul 20 07:19:47.835344 2026] [security2:error] [pid 95126:tid 95348] [client 158.173.166.181:51655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gcwpx5ks9joCJTKXedQAAAek"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:47.897134 2026] [security2:error] [pid 95126:tid 95302] [client 185.209.229.78:40636] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXeewAAAbs"]
[Mon Jul 20 07:19:47.986622 2026] [security2:error] [pid 95126:tid 95263] [client 185.209.229.78:42694] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXeggAAAZQ"]
[Mon Jul 20 07:19:47.994651 2026] [security2:error] [pid 95126:tid 95270] [client 185.209.229.78:59478] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4gcwpx5ks9joCJTKXegwAAAZs"]
[Mon Jul 20 07:19:48.005465 2026] [security2:error] [pid 95126:tid 95355] [client 34.207.130.29:44158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4gdApx5ks9joCJTKXehQAAAfA"], referer: https://curlsnpearlsss.com/es/tag/cook-the-bacalao-guisado/
[Mon Jul 20 07:19:48.038506 2026] [security2:error] [pid 95126:tid 95329] [client 57.141.18.4:60282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gbwpx5ks9joCJTKXdZwAB1hU"]
[Mon Jul 20 07:19:48.086404 2026] [security2:error] [pid 95126:tid 95314] [client 185.209.229.78:34818] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4gdApx5ks9joCJTKXeiQAAAcc"]
[Mon Jul 20 07:19:48.120239 2026] [security2:error] [pid 95126:tid 95328] [client 57.141.18.30:23800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gbwpx5ks9joCJTKXdbAAB1QE"]
[Mon Jul 20 07:19:48.192491 2026] [security2:error] [pid 95126:tid 95280] [client 185.209.229.78:34456] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4gdApx5ks9joCJTKXejwAAAaU"]
[Mon Jul 20 07:19:48.258892 2026] [security2:error] [pid 95126:tid 95276] [client 14.225.17.146:59158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4gdApx5ks9joCJTKXeiAAAAaE"], referer: https://narv.co/2019
[Mon Jul 20 07:19:48.395432 2026] [security2:error] [pid 94831:tid 94980] [client 57.141.18.22:28580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gcI06NaEKF1g_MW27IwAAEx4"]
[Mon Jul 20 07:19:48.501304 2026] [security2:error] [pid 95126:tid 95382] [client 185.209.229.78:40652] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5016.bluehost.com"] [uri "/blog/"] [unique_id "al4gdApx5ks9joCJTKXeoQAAAgs"]
[Mon Jul 20 07:19:48.604127 2026] [security2:error] [pid 94831:tid 94978] [client 185.209.229.78:59490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4gdI06NaEKF1g_MW27rAAAABE"]
[Mon Jul 20 07:19:48.604129 2026] [security2:error] [pid 94831:tid 95086] [client 185.209.229.78:42698] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4gdI06NaEKF1g_MW27qwAAAH0"]
[Mon Jul 20 07:19:48.671499 2026] [security2:error] [pid 95126:tid 95321] [client 49.37.242.14:55053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gdApx5ks9joCJTKXeqQAAAc4"]
[Mon Jul 20 07:19:48.671615 2026] [security2:error] [pid 95126:tid 95321] [client 49.37.242.14:55053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gdApx5ks9joCJTKXeqQAAAc4"]
[Mon Jul 20 07:19:48.698796 2026] [security2:error] [pid 94831:tid 95040] [client 185.209.229.78:34832] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4gdI06NaEKF1g_MW27rgAAAE8"]
[Mon Jul 20 07:19:48.800708 2026] [security2:error] [pid 95126:tid 95355] [client 185.209.229.78:34468] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4gdApx5ks9joCJTKXeswAAAfA"]
[Mon Jul 20 07:19:48.845883 2026] [security2:error] [pid 95126:tid 95141] [remote 188.166.241.141:38466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gdApx5ks9joCJTKXeuAABmAw"]
[Mon Jul 20 07:19:48.846097 2026] [security2:error] [pid 95126:tid 95267] [client 188.166.241.141:38466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gdApx5ks9joCJTKXeuAABmAw"]
[Mon Jul 20 07:19:48.870328 2026] [security2:error] [pid 95126:tid 95371] [client 82.102.27.163:53408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gdApx5ks9joCJTKXeugAAAgA"]
[Mon Jul 20 07:19:48.870435 2026] [security2:error] [pid 95126:tid 95371] [client 82.102.27.163:53408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gdApx5ks9joCJTKXeugAAAgA"]
[Mon Jul 20 07:19:49.022662 2026] [security2:error] [pid 94831:tid 95071] [client 57.141.18.29:22246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gcI06NaEKF1g_MW27NAAAbj4"]
[Mon Jul 20 07:19:49.195698 2026] [security2:error] [pid 94831:tid 95081] [client 185.209.229.78:59494] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5033.bluehost.com"] [uri "/blog/"] [unique_id "al4gdY06NaEKF1g_MW27tAAAAHg"]
[Mon Jul 20 07:19:49.311181 2026] [security2:error] [pid 95126:tid 95306] [client 104.234.53.78:42867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gdQpx5ks9joCJTKXezAAAAb8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:49.524111 2026] [security2:error] [pid 95126:tid 95294] [client 203.76.222.182:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4gdApx5ks9joCJTKXelAAAAbM"]
[Mon Jul 20 07:19:49.668834 2026] [security2:error] [pid 94831:tid 95038] [client 54.166.194.245:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 245.194.166.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gdY06NaEKF1g_MW27vAAAAE0"], referer: https://curlsnpearlsss.com/es/tag/cook-the-bacalao-guisado/
[Mon Jul 20 07:19:49.765373 2026] [security2:error] [pid 95126:tid 95370] [client 45.157.112.60:26757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gdQpx5ks9joCJTKXe4QAAAf8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:50.130375 2026] [security2:error] [pid 95126:tid 95325] [client 14.225.17.146:59022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4gdgpx5ks9joCJTKXe5AAAAdI"], referer: http://thefriendlyspreadsheet.com/2019
[Mon Jul 20 07:19:50.376807 2026] [security2:error] [pid 94831:tid 94981] [client 103.144.65.217:57018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gdo06NaEKF1g_MW279gAAABQ"]
[Mon Jul 20 07:19:50.376926 2026] [security2:error] [pid 94831:tid 94981] [client 103.144.65.217:57018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gdo06NaEKF1g_MW279gAAABQ"]
[Mon Jul 20 07:19:50.393827 2026] [security2:error] [pid 94831:tid 95063] [client 144.172.114.51:40410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gdo06NaEKF1g_MW27-AAAAGY"]
[Mon Jul 20 07:19:50.489489 2026] [security2:error] [pid 94831:tid 95079] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gdo06NaEKF1g_MW276AAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:50.514327 2026] [security2:error] [pid 95126:tid 95202] [remote 57.141.18.45:30838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gcgpx5ks9joCJTKXd-gABqUk"]
[Mon Jul 20 07:19:50.705894 2026] [security2:error] [pid 94831:tid 95037] [client 50.116.65.227:52448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gdo06NaEKF1g_MW28EQAAAEw"]
[Mon Jul 20 07:19:50.715198 2026] [security2:error] [pid 94831:tid 95006] [client 50.116.65.227:52462] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gdo06NaEKF1g_MW28EwAAAC0"]
[Mon Jul 20 07:19:50.933896 2026] [security2:error] [pid 94831:tid 95055] [client 202.141.11.99:24410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gdo06NaEKF1g_MW28IQAAAF4"]
[Mon Jul 20 07:19:50.934003 2026] [security2:error] [pid 94831:tid 95055] [client 202.141.11.99:24410] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gdo06NaEKF1g_MW28IQAAAF4"]
[Mon Jul 20 07:19:51.086929 2026] [security2:error] [pid 94831:tid 95045] [client 158.173.89.95:42937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gd406NaEKF1g_MW28MAAAAFQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:19:51.229504 2026] [security2:error] [pid 94831:tid 95086] [client 14.225.17.146:59236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4gd406NaEKF1g_MW28KwAAAH0"], referer: http://taskidsvirginia.com/2019
[Mon Jul 20 07:19:51.246444 2026] [security2:error] [pid 94831:tid 95008] [client 50.116.65.227:52484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gd406NaEKF1g_MW28LgAAAC8"]
[Mon Jul 20 07:19:51.272670 2026] [security2:error] [pid 94831:tid 95074] [client 57.141.18.99:27908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gco06NaEKF1g_MW27iwAAcWE"]
[Mon Jul 20 07:19:51.331761 2026] [security2:error] [pid 94831:tid 94981] [client 14.225.17.146:60485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4gd406NaEKF1g_MW28NAAAABQ"], referer: http://maxenengineering.com/2019
[Mon Jul 20 07:19:51.397230 2026] [security2:error] [pid 94831:tid 94997] [client 77.110.127.138:63586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gd406NaEKF1g_MW28QAAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:51.397328 2026] [security2:error] [pid 94831:tid 94997] [client 77.110.127.138:63586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gd406NaEKF1g_MW28QAAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:51.433704 2026] [security2:error] [pid 94831:tid 94977] [client 50.116.65.227:52510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gd406NaEKF1g_MW28NQAAABA"]
[Mon Jul 20 07:19:51.470411 2026] [security2:error] [pid 94831:tid 94963] [client 14.225.17.146:59125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4gdo06NaEKF1g_MW275QAAAAI"], referer: http://cloudspacesgroup.com/2019
[Mon Jul 20 07:19:51.506435 2026] [security2:error] [pid 94831:tid 94971] [client 114.119.133.158:27355] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/grantees"] [unique_id "al4gd406NaEKF1g_MW28SQAAAAo"], referer: https://adambergeron.com/grantees?topic%5B0%5D=118&topic%5B1%5D=121&year%5B0%5D=129&year%5B1%5D=132
[Mon Jul 20 07:19:51.791484 2026] [security2:error] [pid 94831:tid 95014] [client 77.110.127.138:63588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gd406NaEKF1g_MW28YwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:51.795808 2026] [security2:error] [pid 94831:tid 95014] [client 77.110.127.138:63588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gd406NaEKF1g_MW28YwAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:51.843102 2026] [security2:error] [pid 94831:tid 95059] [client 57.141.18.112:60078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gc406NaEKF1g_MW27mgAAYlo"]
[Mon Jul 20 07:19:51.853482 2026] [security2:error] [pid 95126:tid 95180] [remote 57.141.18.108:58294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gcwpx5ks9joCJTKXeYwABwjM"]
[Mon Jul 20 07:19:52.168060 2026] [security2:error] [pid 94831:tid 95050] [client 144.172.114.51:40428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4geI06NaEKF1g_MW28jAAAAFk"]
[Mon Jul 20 07:19:52.173188 2026] [security2:error] [pid 95126:tid 95165] [remote 57.141.18.58:59916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gcwpx5ks9joCJTKXebAAB7yQ"]
[Mon Jul 20 07:19:52.181796 2026] [security2:error] [pid 94831:tid 94883] [remote 152.53.111.131:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4geI06NaEKF1g_MW28jQAAMDM"]
[Mon Jul 20 07:19:52.268896 2026] [security2:error] [pid 94831:tid 94994] [client 104.234.53.47:35705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4geI06NaEKF1g_MW28kwAAACE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:52.311457 2026] [security2:error] [pid 94831:tid 95062] [client 14.225.17.146:60414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4geI06NaEKF1g_MW28jwAAAGU"], referer: https://maxenengineering.com/2019
[Mon Jul 20 07:19:52.398385 2026] [security2:error] [pid 94831:tid 94878] [remote 152.53.111.131:45426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.111.53.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4geI06NaEKF1g_MW28nwAAbC4"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:19:52.764721 2026] [security2:error] [pid 94831:tid 95012] [client 14.225.17.146:55826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4gd406NaEKF1g_MW28OQAAADM"], referer: http://colinkeyphotography.com/2019
[Mon Jul 20 07:19:52.868240 2026] [security2:error] [pid 94831:tid 94974] [client 77.110.127.138:63598] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 97 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4geI06NaEKF1g_MW28wAAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:53.036947 2026] [security2:error] [pid 94831:tid 95079] [client 77.110.127.138:63605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geY06NaEKF1g_MW281AAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:53.037043 2026] [security2:error] [pid 94831:tid 95079] [client 77.110.127.138:63605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geY06NaEKF1g_MW281AAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:53.100495 2026] [security2:error] [pid 95126:tid 95159] [remote 57.141.18.27:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gdApx5ks9joCJTKXerwAB0x4"]
[Mon Jul 20 07:19:53.127010 2026] [security2:error] [pid 95126:tid 95201] [remote 57.141.18.38:36724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gdApx5ks9joCJTKXesgABrUg"]
[Mon Jul 20 07:19:53.130358 2026] [security2:error] [pid 94831:tid 95046] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4geI06NaEKF1g_MW28xgAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:53.134017 2026] [security2:error] [pid 94831:tid 94934] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW283AAAImY"]
[Mon Jul 20 07:19:53.134145 2026] [security2:error] [pid 94831:tid 94995] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW283AAAImY"]
[Mon Jul 20 07:19:53.220084 2026] [security2:error] [pid 94831:tid 95033] [client 117.211.236.168:65496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW285wAAAEg"]
[Mon Jul 20 07:19:53.220181 2026] [security2:error] [pid 94831:tid 95033] [client 117.211.236.168:65496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW285wAAAEg"]
[Mon Jul 20 07:19:53.340110 2026] [security2:error] [pid 94831:tid 95030] [client 77.110.127.138:63608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geY06NaEKF1g_MW288AAAAEU"]
[Mon Jul 20 07:19:53.340209 2026] [security2:error] [pid 94831:tid 95030] [client 77.110.127.138:63608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geY06NaEKF1g_MW288AAAAEU"]
[Mon Jul 20 07:19:53.698956 2026] [security2:error] [pid 94831:tid 95029] [client 103.176.215.66:57783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW29BAAAAEQ"]
[Mon Jul 20 07:19:53.699363 2026] [security2:error] [pid 94831:tid 95029] [client 103.176.215.66:57783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW29BAAAAEQ"]
[Mon Jul 20 07:19:53.802325 2026] [security2:error] [pid 94831:tid 95019] [client 88.241.67.160:56990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW29CQAAADo"]
[Mon Jul 20 07:19:53.802428 2026] [security2:error] [pid 94831:tid 95019] [client 88.241.67.160:56990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4geY06NaEKF1g_MW29CQAAADo"]
[Mon Jul 20 07:19:53.935672 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geY06NaEKF1g_MW29FAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:53.935777 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geY06NaEKF1g_MW29FAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:53.946912 2026] [core:error] [pid 94831:tid 95088] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:53.946931 2026] [core:error] [pid 94831:tid 95088] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:19:54.085550 2026] [security2:error] [pid 94831:tid 94988] [client 143.44.185.218:5816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29IQAAABs"]
[Mon Jul 20 07:19:54.085867 2026] [security2:error] [pid 94831:tid 94988] [client 143.44.185.218:5816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29IQAAABs"]
[Mon Jul 20 07:19:54.126856 2026] [security2:error] [pid 94831:tid 94978] [client 49.47.218.174:53001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29KgAAABE"]
[Mon Jul 20 07:19:54.126950 2026] [security2:error] [pid 94831:tid 94978] [client 49.47.218.174:53001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29KgAAABE"]
[Mon Jul 20 07:19:54.135316 2026] [security2:error] [pid 94831:tid 94999] [client 114.119.137.193:22827] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.secretkeynumerology.com"] [uri "/part-ii-brackets/"] [unique_id "al4geo06NaEKF1g_MW29LQAAACY"], referer: https://www.secretkeynumerology.com/oppositions/
[Mon Jul 20 07:19:54.138781 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4geY06NaEKF1g_MW29GgAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:54.241696 2026] [security2:error] [pid 94831:tid 95068] [client 157.20.138.62:52790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29NgAAAGs"]
[Mon Jul 20 07:19:54.241848 2026] [security2:error] [pid 94831:tid 95068] [client 157.20.138.62:52790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29NgAAAGs"]
[Mon Jul 20 07:19:54.267758 2026] [security2:error] [pid 94831:tid 95040] [client 77.110.127.138:63613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geo06NaEKF1g_MW29NwAAAE8"]
[Mon Jul 20 07:19:54.267867 2026] [security2:error] [pid 94831:tid 95040] [client 77.110.127.138:63613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geo06NaEKF1g_MW29NwAAAE8"]
[Mon Jul 20 07:19:54.301925 2026] [security2:error] [pid 94831:tid 94834] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29OwAAWwI"]
[Mon Jul 20 07:19:54.302164 2026] [security2:error] [pid 94831:tid 95052] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29OwAAWwI"]
[Mon Jul 20 07:19:54.382354 2026] [security2:error] [pid 94831:tid 94848] [remote 81.173.115.7:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4geo06NaEKF1g_MW29QAAARhA"]
[Mon Jul 20 07:19:54.506426 2026] [security2:error] [pid 94831:tid 95078] [client 104.234.53.59:59269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4geo06NaEKF1g_MW29TwAAAHU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:54.691920 2026] [security2:error] [pid 94831:tid 94956] [remote 81.173.115.7:40178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4geo06NaEKF1g_MW29ZQAACHw"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:19:54.853807 2026] [security2:error] [pid 94831:tid 94992] [client 77.110.127.138:63618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geo06NaEKF1g_MW29cQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:54.853925 2026] [security2:error] [pid 94831:tid 94992] [client 77.110.127.138:63618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4geo06NaEKF1g_MW29cQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:54.854840 2026] [security2:error] [pid 94831:tid 95007] [client 36.93.152.155:49487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29bQAAAC4"]
[Mon Jul 20 07:19:54.854934 2026] [security2:error] [pid 94831:tid 95007] [client 36.93.152.155:49487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4geo06NaEKF1g_MW29bQAAAC4"]
[Mon Jul 20 07:19:55.003958 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63619] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 221 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4ge406NaEKF1g_MW29fQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:55.060838 2026] [security2:error] [pid 94831:tid 94972] [client 191.202.66.27:54343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ge406NaEKF1g_MW29gQAAAAs"]
[Mon Jul 20 07:19:55.060972 2026] [security2:error] [pid 94831:tid 94972] [client 191.202.66.27:54343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ge406NaEKF1g_MW29gQAAAAs"]
[Mon Jul 20 07:19:55.146344 2026] [security2:error] [pid 94831:tid 95068] [client 77.110.127.138:63621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ge406NaEKF1g_MW29hwAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:55.146443 2026] [security2:error] [pid 94831:tid 95068] [client 77.110.127.138:63621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ge406NaEKF1g_MW29hwAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:55.249588 2026] [security2:error] [pid 94831:tid 95018] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ge406NaEKF1g_MW29hQAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:55.301509 2026] [security2:error] [pid 94831:tid 95011] [client 57.141.18.79:47430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gd406NaEKF1g_MW28JQAAMnQ"]
[Mon Jul 20 07:19:55.629084 2026] [security2:error] [pid 94831:tid 94911] [remote 182.77.62.24:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4ge406NaEKF1g_MW29qAAAT08"]
[Mon Jul 20 07:19:55.932167 2026] [security2:error] [pid 94831:tid 95081] [client 57.141.18.11:26872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gd406NaEKF1g_MW28VgAAeH4"]
[Mon Jul 20 07:19:55.983998 2026] [security2:error] [pid 94831:tid 95018] [client 57.141.0.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4ge406NaEKF1g_MW29vQAAADk"]
[Mon Jul 20 07:19:56.097271 2026] [security2:error] [pid 94831:tid 94909] [remote 182.77.62.24:35320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4gfI06NaEKF1g_MW291QAAUE0"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 07:19:56.256706 2026] [security2:error] [pid 94831:tid 95086] [client 77.110.127.138:63626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfI06NaEKF1g_MW296QAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.256840 2026] [security2:error] [pid 94831:tid 95086] [client 77.110.127.138:63626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfI06NaEKF1g_MW296QAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.347091 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:63627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfI06NaEKF1g_MW297wAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.347196 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:63627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfI06NaEKF1g_MW297wAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.351152 2026] [security2:error] [pid 94831:tid 95003] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gfI06NaEKF1g_MW295gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.508730 2026] [security2:error] [pid 94831:tid 94998] [client 77.110.127.138:63628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 162 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gfI06NaEKF1g_MW2-AgAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.540994 2026] [security2:error] [pid 94831:tid 94981] [client 103.106.165.44:58107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gfI06NaEKF1g_MW2-BAAAABQ"]
[Mon Jul 20 07:19:56.541085 2026] [security2:error] [pid 94831:tid 94981] [client 103.106.165.44:58107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gfI06NaEKF1g_MW2-BAAAABQ"]
[Mon Jul 20 07:19:56.586743 2026] [security2:error] [pid 94831:tid 94972] [client 187.16.64.216:60346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gfI06NaEKF1g_MW2-CgAAAAs"]
[Mon Jul 20 07:19:56.586866 2026] [security2:error] [pid 94831:tid 94972] [client 187.16.64.216:60346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gfI06NaEKF1g_MW2-CgAAAAs"]
[Mon Jul 20 07:19:56.666859 2026] [security2:error] [pid 94831:tid 95086] [client 77.110.127.138:63629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfI06NaEKF1g_MW2-EAAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.666935 2026] [security2:error] [pid 94831:tid 95086] [client 77.110.127.138:63629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfI06NaEKF1g_MW2-EAAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:56.761475 2026] [security2:error] [pid 94831:tid 94986] [client 154.208.48.130:56571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gfI06NaEKF1g_MW2-GwAAABk"]
[Mon Jul 20 07:19:56.761588 2026] [security2:error] [pid 94831:tid 94986] [client 154.208.48.130:56571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gfI06NaEKF1g_MW2-GwAAABk"]
[Mon Jul 20 07:19:57.096523 2026] [security2:error] [pid 94831:tid 95059] [client 66.249.79.32:58858] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "bestenergydeals.com"] [uri "/robots.txt"] [unique_id "al4gfY06NaEKF1g_MW2-MgAAAGI"]
[Mon Jul 20 07:19:57.152465 2026] [security2:error] [pid 94831:tid 95040] [client 154.192.123.127:18043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gfY06NaEKF1g_MW2-PAAAAE8"]
[Mon Jul 20 07:19:57.152547 2026] [security2:error] [pid 94831:tid 95040] [client 154.192.123.127:18043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gfY06NaEKF1g_MW2-PAAAAE8"]
[Mon Jul 20 07:19:57.211403 2026] [security2:error] [pid 94831:tid 94963] [client 57.141.18.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gfY06NaEKF1g_MW2-LwAAAAI"]
[Mon Jul 20 07:19:57.484459 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:63633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfY06NaEKF1g_MW2-UgAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:57.484588 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:63633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfY06NaEKF1g_MW2-UgAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:57.590230 2026] [security2:error] [pid 94831:tid 94991] [client 104.234.53.91:40579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gfY06NaEKF1g_MW2-WAAAAB4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:19:57.605684 2026] [security2:error] [pid 94831:tid 94969] [client 144.172.114.51:40438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gfY06NaEKF1g_MW2-XQAAAAg"]
[Mon Jul 20 07:19:57.694296 2026] [security2:error] [pid 94831:tid 95068] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gfY06NaEKF1g_MW2-VgAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:57.715066 2026] [security2:error] [pid 94831:tid 95025] [client 57.141.18.64:40506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4geY06NaEKF1g_MW285gAAQF4"]
[Mon Jul 20 07:19:57.717057 2026] [security2:error] [pid 94831:tid 95015] [client 82.102.27.163:53422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gfY06NaEKF1g_MW2-ZgAAADY"]
[Mon Jul 20 07:19:57.717125 2026] [security2:error] [pid 94831:tid 95015] [client 82.102.27.163:53422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4gfY06NaEKF1g_MW2-ZgAAADY"]
[Mon Jul 20 07:19:57.742100 2026] [security2:error] [pid 94831:tid 95038] [client 201.27.111.74:60446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gfY06NaEKF1g_MW2-aQAAAE0"]
[Mon Jul 20 07:19:57.742192 2026] [security2:error] [pid 94831:tid 95038] [client 201.27.111.74:60446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gfY06NaEKF1g_MW2-aQAAAE0"]
[Mon Jul 20 07:19:57.981216 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:63636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfY06NaEKF1g_MW2-gwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:57.981336 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:63636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfY06NaEKF1g_MW2-gwAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.510852 2026] [security2:error] [pid 94831:tid 94887] [remote 98.156.100.191:41328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gfo06NaEKF1g_MW2-rwAAWzc"]
[Mon Jul 20 07:19:58.616670 2026] [security2:error] [pid 94831:tid 95059] [client 77.110.127.138:63639] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 546 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gfo06NaEKF1g_MW2-tgAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.649964 2026] [security2:error] [pid 94831:tid 95083] [client 77.110.127.138:63581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-twAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.650057 2026] [security2:error] [pid 94831:tid 95083] [client 77.110.127.138:63581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-twAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.666680 2026] [security2:error] [pid 94831:tid 95058] [client 77.110.127.138:63623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-uAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.666824 2026] [security2:error] [pid 94831:tid 95058] [client 77.110.127.138:63623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-uAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.688412 2026] [security2:error] [pid 94831:tid 94997] [client 57.141.18.25:25920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4geo06NaEKF1g_MW29HwAAJAs"]
[Mon Jul 20 07:19:58.799882 2026] [security2:error] [pid 94831:tid 95084] [client 77.110.127.138:63641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-zQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.799982 2026] [security2:error] [pid 94831:tid 95084] [client 77.110.127.138:63641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-zQAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.882950 2026] [security2:error] [pid 94831:tid 94870] [remote 100.42.189.89:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gfo06NaEKF1g_MW2-2wAAayY"]
[Mon Jul 20 07:19:58.898660 2026] [security2:error] [pid 94831:tid 94972] [client 77.110.127.138:63643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-3AAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.898787 2026] [security2:error] [pid 94831:tid 94972] [client 77.110.127.138:63643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gfo06NaEKF1g_MW2-3AAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:58.912209 2026] [security2:error] [pid 94831:tid 94966] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gfo06NaEKF1g_MW2-yQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.081387 2026] [security2:error] [pid 94831:tid 94935] [remote 100.42.189.89:53912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gf406NaEKF1g_MW2-5QAACGc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:19:59.145326 2026] [security2:error] [pid 94831:tid 94982] [client 57.141.18.62:55424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4geo06NaEKF1g_MW29WgAAFQ8"]
[Mon Jul 20 07:19:59.203742 2026] [security2:error] [pid 94831:tid 95006] [client 57.141.18.76:50046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4geo06NaEKF1g_MW29WAAALRY"]
[Mon Jul 20 07:19:59.262024 2026] [security2:error] [pid 94831:tid 95019] [client 77.110.127.138:63630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2--AAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.262157 2026] [security2:error] [pid 94831:tid 95019] [client 77.110.127.138:63630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2--AAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.282469 2026] [security2:error] [pid 94831:tid 94995] [client 77.110.127.138:63648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2--gAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.282553 2026] [security2:error] [pid 94831:tid 94995] [client 77.110.127.138:63648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2--gAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.315185 2026] [security2:error] [pid 94831:tid 95074] [client 77.110.127.138:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2-_gAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.315311 2026] [security2:error] [pid 94831:tid 95074] [client 77.110.127.138:63614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2-_gAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.316396 2026] [security2:error] [pid 94831:tid 94852] [remote 98.156.100.191:41328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gf406NaEKF1g_MW2-_AAAahQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:19:59.367199 2026] [security2:error] [pid 94831:tid 95044] [client 77.110.127.138:63631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2_DAAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.367307 2026] [security2:error] [pid 94831:tid 95044] [client 77.110.127.138:63631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2_DAAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.396002 2026] [security2:error] [pid 94831:tid 94963] [client 15.204.114.164:11530] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "oohlovely.com"] [uri "/"] [unique_id "al4gf406NaEKF1g_MW2_FAAAAAI"]
[Mon Jul 20 07:19:59.418860 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:63619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2_FwAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.418969 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:63619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2_FwAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.436544 2026] [security2:error] [pid 94831:tid 94964] [client 77.110.127.138:63650] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 546 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gf406NaEKF1g_MW2_GgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.448027 2026] [security2:error] [pid 94831:tid 95072] [client 57.141.18.58:59932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4geo06NaEKF1g_MW29eAAAb0Y"]
[Mon Jul 20 07:19:59.539918 2026] [security2:error] [pid 94831:tid 95021] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gf406NaEKF1g_MW2_BgAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.648822 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2_KgAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:19:59.648924 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gf406NaEKF1g_MW2_KgAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:00.018045 2026] [security2:error] [pid 94831:tid 95057] [client 57.141.18.67:61100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ge406NaEKF1g_MW29mgAAYDM"]
[Mon Jul 20 07:20:00.099733 2026] [security2:error] [pid 94831:tid 95072] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4gf406NaEKF1g_MW2_SQAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:00.358130 2026] [security2:error] [pid 94831:tid 95034] [client 98.159.234.160:31915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ggI06NaEKF1g_MW2_cgAAAEk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:20:00.374866 2026] [security2:error] [pid 94831:tid 94969] [client 114.119.141.100:53429] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4ggI06NaEKF1g_MW2_egAAAAg"], referer: https://www.hammerandrails.com/2016/7/27/12300790/2016-purdue-football-preview-quarterbacks
[Mon Jul 20 07:20:00.545986 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:63659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggI06NaEKF1g_MW2_kgAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:00.546104 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:63659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggI06NaEKF1g_MW2_kgAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:00.621885 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ggI06NaEKF1g_MW2_iQAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:00.753875 2026] [security2:error] [pid 94831:tid 95023] [client 3.67.192.83:16654] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.curlsnpearlsss.com"] [uri "/"] [unique_id "al4ggI06NaEKF1g_MW2_mAAAAD4"]
[Mon Jul 20 07:20:00.753981 2026] [security2:error] [pid 94831:tid 95023] [client 3.67.192.83:16654] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.curlsnpearlsss.com"] [uri "/"] [unique_id "al4ggI06NaEKF1g_MW2_mAAAAD4"]
[Mon Jul 20 07:20:00.770505 2026] [security2:error] [pid 94831:tid 95054] [client 49.37.242.14:55550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ggI06NaEKF1g_MW2_nQAAAF0"]
[Mon Jul 20 07:20:00.770602 2026] [security2:error] [pid 94831:tid 95054] [client 49.37.242.14:55550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ggI06NaEKF1g_MW2_nQAAAF0"]
[Mon Jul 20 07:20:00.805199 2026] [proxy:error] [pid 94831:tid 94991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:00.805245 2026] [proxy_http:error] [pid 94831:tid 94991] [client 8.229.28.226:46366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:00.805915 2026] [proxy:error] [pid 94831:tid 94991] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:00.805969 2026] [proxy_http:error] [pid 94831:tid 94991] [client 8.229.28.226:46366] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:00.883566 2026] [proxy:error] [pid 94831:tid 95064] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:00.883644 2026] [proxy_http:error] [pid 94831:tid 95064] [client 207.241.173.154:44980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:00.884302 2026] [proxy:error] [pid 94831:tid 95064] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:00.884334 2026] [proxy_http:error] [pid 94831:tid 95064] [client 207.241.173.154:44980] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:00.885912 2026] [security2:error] [pid 94831:tid 95082] [client 103.144.65.217:57479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ggI06NaEKF1g_MW2_swAAAHk"]
[Mon Jul 20 07:20:00.886036 2026] [security2:error] [pid 94831:tid 95082] [client 103.144.65.217:57479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4ggI06NaEKF1g_MW2_swAAAHk"]
[Mon Jul 20 07:20:01.013195 2026] [security2:error] [pid 94831:tid 94838] [remote 147.50.252.213:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4ggY06NaEKF1g_MW2_wAAASgY"]
[Mon Jul 20 07:20:01.231228 2026] [core:error] [pid 94831:tid 95001] [client 207.241.173.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:01.231258 2026] [core:error] [pid 94831:tid 95001] [client 207.241.173.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:01.419593 2026] [security2:error] [pid 94831:tid 94898] [remote 47.86.33.52:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4ggY06NaEKF1g_MW2_5gAAQUI"]
[Mon Jul 20 07:20:01.437965 2026] [security2:error] [pid 94831:tid 94916] [remote 147.50.252.213:45008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4ggY06NaEKF1g_MW2_6wAAM1Q"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:20:01.561775 2026] [security2:error] [pid 94831:tid 94992] [client 138.197.165.173:60252] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4ggY06NaEKF1g_MW2_9AAAAB8"]
[Mon Jul 20 07:20:01.701780 2026] [security2:error] [pid 94831:tid 94994] [client 202.141.11.99:22044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ggY06NaEKF1g_MW2_-wAAACE"]
[Mon Jul 20 07:20:01.701883 2026] [security2:error] [pid 94831:tid 94994] [client 202.141.11.99:22044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ggY06NaEKF1g_MW2_-wAAACE"]
[Mon Jul 20 07:20:01.762753 2026] [security2:error] [pid 94831:tid 95061] [client 74.7.227.179:53706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ggY06NaEKF1g_MW2_-QAAZE4"], referer: https://tejasenvironmental.com/p=139914
[Mon Jul 20 07:20:01.835860 2026] [security2:error] [pid 94831:tid 94930] [remote 47.86.33.52:53294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4ggY06NaEKF1g_MW3AAwAALWI"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:20:02.141435 2026] [security2:error] [pid 94831:tid 95070] [client 104.234.53.72:22211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ggo06NaEKF1g_MW3AKwAAAG0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:02.183487 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3ANgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.183638 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3ANgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.236377 2026] [security2:error] [pid 94831:tid 95082] [client 77.110.127.138:63635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(99),ARGS:relatedposts"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4ggo06NaEKF1g_MW3APAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.532452 2026] [security2:error] [pid 94831:tid 95031] [client 77.110.127.138:63664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3AWAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.532573 2026] [security2:error] [pid 94831:tid 95031] [client 77.110.127.138:63664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3AWAAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.617731 2026] [security2:error] [pid 94831:tid 94986] [client 50.116.65.227:27524] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ggo06NaEKF1g_MW3AXAAAABk"]
[Mon Jul 20 07:20:02.629274 2026] [security2:error] [pid 94831:tid 94962] [client 50.116.65.227:27528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ggo06NaEKF1g_MW3AXQAAAAE"]
[Mon Jul 20 07:20:02.686661 2026] [security2:error] [pid 94831:tid 95013] [client 77.110.127.138:63650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3AZAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.686803 2026] [security2:error] [pid 94831:tid 95013] [client 77.110.127.138:63650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3AZAAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.713043 2026] [core:error] [pid 94831:tid 95077] [client 207.241.173.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:02.713076 2026] [core:error] [pid 94831:tid 95077] [client 207.241.173.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:02.718460 2026] [core:error] [pid 94831:tid 95084] [client 207.241.173.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:02.718491 2026] [core:error] [pid 94831:tid 95084] [client 207.241.173.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:02.816003 2026] [security2:error] [pid 94831:tid 95003] [client 77.110.127.138:63646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3AawAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.816177 2026] [security2:error] [pid 94831:tid 95003] [client 77.110.127.138:63646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ggo06NaEKF1g_MW3AawAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:02.911159 2026] [security2:error] [pid 94831:tid 95085] [client 104.28.251.193:26839] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.almaz-aura.net"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al4ggo06NaEKF1g_MW3AfQAAAHw"]
[Mon Jul 20 07:20:03.839808 2026] [security2:error] [pid 94831:tid 94833] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gg406NaEKF1g_MW3AuAAAFwE"]
[Mon Jul 20 07:20:03.839980 2026] [security2:error] [pid 94831:tid 94984] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gg406NaEKF1g_MW3AuAAAFwE"]
[Mon Jul 20 07:20:03.952371 2026] [security2:error] [pid 94831:tid 95058] [client 77.110.127.138:63669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gg406NaEKF1g_MW3AyAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:03.952457 2026] [security2:error] [pid 94831:tid 95058] [client 77.110.127.138:63669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gg406NaEKF1g_MW3AyAAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.000770 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:63671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gg406NaEKF1g_MW3A0QAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.000859 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:63671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gg406NaEKF1g_MW3A0QAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.133159 2026] [proxy:error] [pid 94831:tid 94978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:04.133198 2026] [proxy_http:error] [pid 94831:tid 94978] [client 8.229.28.226:52784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:04.133919 2026] [proxy:error] [pid 94831:tid 94978] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:04.133966 2026] [proxy_http:error] [pid 94831:tid 94978] [client 8.229.28.226:52784] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:04.151960 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4ghI06NaEKF1g_MW3A3wAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.190792 2026] [security2:error] [pid 94831:tid 94997] [client 103.176.215.66:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3A5wAAACQ"]
[Mon Jul 20 07:20:04.190890 2026] [security2:error] [pid 94831:tid 94997] [client 103.176.215.66:58313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3A5wAAACQ"]
[Mon Jul 20 07:20:04.320272 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghI06NaEKF1g_MW3A7QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.320358 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghI06NaEKF1g_MW3A7QAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.353201 2026] [security2:error] [pid 94831:tid 95029] [client 77.110.127.138:63675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghI06NaEKF1g_MW3A7wAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.353289 2026] [security2:error] [pid 94831:tid 95029] [client 77.110.127.138:63675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghI06NaEKF1g_MW3A7wAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.371365 2026] [security2:error] [pid 94831:tid 95086] [client 77.110.127.138:63656] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:relatedposts"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4ghI06NaEKF1g_MW3A9QAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:04.512801 2026] [security2:error] [pid 94831:tid 95016] [client 88.241.67.160:53459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BAQAAADc"]
[Mon Jul 20 07:20:04.512951 2026] [security2:error] [pid 94831:tid 95016] [client 88.241.67.160:53459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BAQAAADc"]
[Mon Jul 20 07:20:04.635012 2026] [security2:error] [pid 94831:tid 95054] [client 49.47.218.174:53511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BDgAAAF0"]
[Mon Jul 20 07:20:04.635447 2026] [security2:error] [pid 94831:tid 95054] [client 49.47.218.174:53511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BDgAAAF0"]
[Mon Jul 20 07:20:04.717598 2026] [security2:error] [pid 94831:tid 95065] [client 157.20.138.62:53358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BFgAAAGg"]
[Mon Jul 20 07:20:04.718033 2026] [security2:error] [pid 94831:tid 95065] [client 157.20.138.62:53358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BFgAAAGg"]
[Mon Jul 20 07:20:04.826656 2026] [security2:error] [pid 94831:tid 94995] [client 143.44.185.218:7091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BHAAAACI"]
[Mon Jul 20 07:20:04.826776 2026] [security2:error] [pid 94831:tid 94995] [client 143.44.185.218:7091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BHAAAACI"]
[Mon Jul 20 07:20:04.976340 2026] [security2:error] [pid 94831:tid 94873] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BMAAARCk"]
[Mon Jul 20 07:20:04.976484 2026] [security2:error] [pid 94831:tid 95029] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ghI06NaEKF1g_MW3BMAAARCk"]
[Mon Jul 20 07:20:05.019779 2026] [security2:error] [pid 94831:tid 95079] [client 77.110.127.138:63679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BMwAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:05.019885 2026] [security2:error] [pid 94831:tid 95079] [client 77.110.127.138:63679] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BMwAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:05.023824 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:63678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BNAAAAGY"]
[Mon Jul 20 07:20:05.023922 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:63678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BNAAAAGY"]
[Mon Jul 20 07:20:05.199172 2026] [security2:error] [pid 94831:tid 94902] [remote 100.42.189.89:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4ghY06NaEKF1g_MW3BRwAAN0Y"]
[Mon Jul 20 07:20:05.305918 2026] [security2:error] [pid 94831:tid 95006] [client 144.172.114.51:39036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-content/plugins/ultra/includes/ajax.php"] [unique_id "al4ghY06NaEKF1g_MW3BTQAAAC0"]
[Mon Jul 20 07:20:05.321896 2026] [security2:error] [pid 94831:tid 94991] [client 36.93.152.155:50077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ghY06NaEKF1g_MW3BUQAAAB4"]
[Mon Jul 20 07:20:05.321996 2026] [security2:error] [pid 94831:tid 94991] [client 36.93.152.155:50077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ghY06NaEKF1g_MW3BUQAAAB4"]
[Mon Jul 20 07:20:05.455133 2026] [security2:error] [pid 94831:tid 94900] [remote 100.42.189.89:53994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4ghY06NaEKF1g_MW3BXgAAJEQ"], referer: https://thesoloceos.com/wp-login.php
[Mon Jul 20 07:20:05.486647 2026] [security2:error] [pid 94831:tid 95028] [client 191.202.66.27:54810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ghY06NaEKF1g_MW3BXwAAAEM"]
[Mon Jul 20 07:20:05.488023 2026] [security2:error] [pid 94831:tid 95028] [client 191.202.66.27:54810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ghY06NaEKF1g_MW3BXwAAAEM"]
[Mon Jul 20 07:20:05.542347 2026] [core:error] [pid 94831:tid 95075] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:05.542375 2026] [core:error] [pid 94831:tid 95075] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:05.578012 2026] [security2:error] [pid 94831:tid 95010] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ghY06NaEKF1g_MW3BXAAAADE"]
[Mon Jul 20 07:20:05.589663 2026] [security2:error] [pid 94831:tid 95055] [client 13.215.47.127:49988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ghY06NaEKF1g_MW3BagAAAF4"]
[Mon Jul 20 07:20:05.765185 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BhgAAAHU"]
[Mon Jul 20 07:20:05.765294 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BhgAAAHU"]
[Mon Jul 20 07:20:05.790855 2026] [security2:error] [pid 94831:tid 94998] [client 104.234.53.54:48649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ghY06NaEKF1g_MW3BigAAACU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:05.989742 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BlAAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:05.989877 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ghY06NaEKF1g_MW3BlAAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.105970 2026] [security2:error] [pid 94831:tid 95046] [client 51.68.111.212:13857] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gertoger.org"] [uri "/robots.txt"] [unique_id "al4gho06NaEKF1g_MW3BnwAAAFU"]
[Mon Jul 20 07:20:06.106110 2026] [security2:error] [pid 94831:tid 95046] [client 51.68.111.212:13857] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "gertoger.org"] [uri "/robots.txt"] [unique_id "al4gho06NaEKF1g_MW3BnwAAAFU"]
[Mon Jul 20 07:20:06.263529 2026] [security2:error] [pid 94831:tid 95042] [client 2a03:2880:10ff:53:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "benbayly.co.nz"] [uri "/index.php"] [unique_id "al4gho06NaEKF1g_MW3BlQAAUUw"]
[Mon Jul 20 07:20:06.558671 2026] [security2:error] [pid 94831:tid 95070] [client 18.142.226.106:30066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gho06NaEKF1g_MW3BwwAAAG0"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:20:06.720531 2026] [security2:error] [pid 94831:tid 95072] [client 77.110.127.138:63687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B3wAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.720630 2026] [security2:error] [pid 94831:tid 95072] [client 77.110.127.138:63687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B3wAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.771021 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:63672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B4gAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.771134 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:63672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B4gAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.887883 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B7gAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.887985 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:63689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B7gAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.973284 2026] [security2:error] [pid 94831:tid 95068] [client 77.110.127.138:63690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B-AAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:06.973362 2026] [security2:error] [pid 94831:tid 95068] [client 77.110.127.138:63690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gho06NaEKF1g_MW3B-AAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.010401 2026] [security2:error] [pid 94831:tid 95067] [client 103.106.165.44:58550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gho06NaEKF1g_MW3B-wAAAGo"]
[Mon Jul 20 07:20:07.010501 2026] [security2:error] [pid 94831:tid 95067] [client 103.106.165.44:58550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gho06NaEKF1g_MW3B-wAAAGo"]
[Mon Jul 20 07:20:07.082060 2026] [security2:error] [pid 94831:tid 95087] [client 77.110.127.138:63691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CAQAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.082138 2026] [security2:error] [pid 94831:tid 95087] [client 77.110.127.138:63691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CAQAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.082878 2026] [security2:error] [pid 94831:tid 94997] [client 117.211.236.168:49798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3CAgAAACQ"]
[Mon Jul 20 07:20:07.082954 2026] [security2:error] [pid 94831:tid 94997] [client 117.211.236.168:49798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3CAgAAACQ"]
[Mon Jul 20 07:20:07.231785 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CFAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.231876 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:63693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CFAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.233548 2026] [security2:error] [pid 94831:tid 95002] [client 187.16.64.216:60914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3CFQAAACk"]
[Mon Jul 20 07:20:07.233622 2026] [security2:error] [pid 94831:tid 95002] [client 187.16.64.216:60914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3CFQAAACk"]
[Mon Jul 20 07:20:07.288643 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:63680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CGgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.288742 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:63680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CGgAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.341147 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:63661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CIAAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.341297 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:63661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CIAAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.496931 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:63697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CLgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.497155 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:63697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gh406NaEKF1g_MW3CLgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:07.596010 2026] [security2:error] [pid 94831:tid 94986] [client 154.208.48.130:57363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3COAAAABk"]
[Mon Jul 20 07:20:07.596141 2026] [security2:error] [pid 94831:tid 94986] [client 154.208.48.130:57363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3COAAAABk"]
[Mon Jul 20 07:20:07.710391 2026] [security2:error] [pid 94831:tid 94994] [client 154.192.123.127:18589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3CRQAAACE"]
[Mon Jul 20 07:20:07.710487 2026] [security2:error] [pid 94831:tid 94994] [client 154.192.123.127:18589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gh406NaEKF1g_MW3CRQAAACE"]
[Mon Jul 20 07:20:08.075083 2026] [security2:error] [pid 94831:tid 95050] [client 216.73.217.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mail.robiem.com"] [uri "/index.php"] [unique_id "al4gho06NaEKF1g_MW3BzQAAAFk"]
[Mon Jul 20 07:20:08.210981 2026] [security2:error] [pid 94831:tid 95088] [client 201.27.111.74:60966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4giI06NaEKF1g_MW3CZgAAAH8"]
[Mon Jul 20 07:20:08.211089 2026] [security2:error] [pid 94831:tid 95088] [client 201.27.111.74:60966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4giI06NaEKF1g_MW3CZgAAAH8"]
[Mon Jul 20 07:20:08.338722 2026] [security2:error] [pid 94831:tid 95074] [client 57.141.18.93:65240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gg406NaEKF1g_MW3AuQAAcS0"]
[Mon Jul 20 07:20:08.418395 2026] [core:error] [pid 94831:tid 95058] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:08.418413 2026] [core:error] [pid 94831:tid 95058] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:08.555785 2026] [security2:error] [pid 94831:tid 95052] [client 57.141.18.39:61869] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ghI06NaEKF1g_MW3A1AAAWwY"]
[Mon Jul 20 07:20:08.944033 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4giI06NaEKF1g_MW3CpgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:08.944122 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4giI06NaEKF1g_MW3CpgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:08.986299 2026] [security2:error] [pid 94831:tid 95001] [client 14.225.17.146:65377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4giI06NaEKF1g_MW3CiAAAACg"]
[Mon Jul 20 07:20:08.994823 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:63656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4giI06NaEKF1g_MW3CrQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:08.994923 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:63656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4giI06NaEKF1g_MW3CrQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:09.005095 2026] [proxy:error] [pid 94831:tid 94982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:09.005125 2026] [proxy_http:error] [pid 94831:tid 94982] [client 8.229.28.226:48340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:09.005662 2026] [proxy:error] [pid 94831:tid 94982] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:09.005684 2026] [proxy_http:error] [pid 94831:tid 94982] [client 8.229.28.226:48340] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:09.180330 2026] [security2:error] [pid 94831:tid 95016] [client 77.110.127.138:63692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4giY06NaEKF1g_MW3CvgAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:09.180441 2026] [security2:error] [pid 94831:tid 95016] [client 77.110.127.138:63692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4giY06NaEKF1g_MW3CvgAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:09.413456 2026] [proxy:error] [pid 94831:tid 95008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:09.413492 2026] [proxy_http:error] [pid 94831:tid 95008] [client 8.229.28.226:44338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:09.413985 2026] [proxy:error] [pid 94831:tid 95008] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:09.414006 2026] [proxy_http:error] [pid 94831:tid 95008] [client 8.229.28.226:44338] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:09.542687 2026] [core:error] [pid 94831:tid 95011] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:09.542714 2026] [core:error] [pid 94831:tid 95011] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:09.558298 2026] [security2:error] [pid 94831:tid 94999] [client 57.141.18.34:22830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ghY06NaEKF1g_MW3BNQAAJj0"]
[Mon Jul 20 07:20:09.834182 2026] [security2:error] [pid 94831:tid 95064] [client 121.229.156.28:44362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-readartny-com/"] [unique_id "al4giY06NaEKF1g_MW3C8QAAAGc"]
[Mon Jul 20 07:20:09.834279 2026] [security2:error] [pid 94831:tid 95064] [client 121.229.156.28:44362] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-readartny-com/"] [unique_id "al4giY06NaEKF1g_MW3C8QAAAGc"]
[Mon Jul 20 07:20:09.875241 2026] [core:error] [pid 94831:tid 95046] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:09.875267 2026] [core:error] [pid 94831:tid 95046] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:10.392043 2026] [security2:error] [pid 94831:tid 94970] [client 114.119.146.179:54887] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.zonemist.com"] [uri "/technology/eco-h2o-water-disinfecting-system-schematic"] [unique_id "al4gio06NaEKF1g_MW3DHwAAAAk"], referer: https://www.zonemist.com/technology/eco-h2o-water-disinfecting-system-schematic/
[Mon Jul 20 07:20:10.538334 2026] [security2:error] [pid 94831:tid 95018] [client 35.162.140.124:11373] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4gio06NaEKF1g_MW3DIQAAADk"]
[Mon Jul 20 07:20:10.837044 2026] [security2:error] [pid 94831:tid 94874] [remote 20.153.140.50:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gio06NaEKF1g_MW3DVAAAOio"]
[Mon Jul 20 07:20:10.881018 2026] [security2:error] [pid 94831:tid 95081] [client 14.225.17.146:50255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4gio06NaEKF1g_MW3DIAAAAHg"]
[Mon Jul 20 07:20:11.237352 2026] [security2:error] [pid 94831:tid 94869] [remote 20.153.140.50:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gi406NaEKF1g_MW3DbQAAPyU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:20:11.452266 2026] [security2:error] [pid 94831:tid 94967] [client 103.144.65.217:57943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gi406NaEKF1g_MW3DiQAAAAY"]
[Mon Jul 20 07:20:11.452419 2026] [security2:error] [pid 94831:tid 94967] [client 103.144.65.217:57943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gi406NaEKF1g_MW3DiQAAAAY"]
[Mon Jul 20 07:20:11.484011 2026] [security2:error] [pid 94831:tid 95073] [client 14.225.17.146:55922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gi406NaEKF1g_MW3DZwAAAHA"], referer: http://fkconstructionfunding.com/2018
[Mon Jul 20 07:20:11.505975 2026] [security2:error] [pid 94831:tid 95069] [client 57.141.18.71:60344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gho06NaEKF1g_MW3B7wAAbHs"]
[Mon Jul 20 07:20:11.714510 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gi406NaEKF1g_MW3DlgAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:11.714628 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gi406NaEKF1g_MW3DlgAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:11.770479 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:63694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gi406NaEKF1g_MW3DnQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:11.770576 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:63694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gi406NaEKF1g_MW3DnQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:11.774990 2026] [security2:error] [pid 94831:tid 95064] [client 77.110.127.138:63716] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:relatedposts. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gi406NaEKF1g_MW3DngAAAGc"]
[Mon Jul 20 07:20:11.920410 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:63717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gi406NaEKF1g_MW3DrAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:11.920548 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:63717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gi406NaEKF1g_MW3DrAAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:12.326986 2026] [security2:error] [pid 94831:tid 95072] [client 202.141.11.99:22072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gjI06NaEKF1g_MW3DzAAAAG8"]
[Mon Jul 20 07:20:12.327126 2026] [security2:error] [pid 94831:tid 95072] [client 202.141.11.99:22072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gjI06NaEKF1g_MW3DzAAAAG8"]
[Mon Jul 20 07:20:12.455975 2026] [security2:error] [pid 94831:tid 95084] [client 14.225.17.146:54576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4gjI06NaEKF1g_MW3DvwAAAHs"], referer: http://longevityperformanceclinic.com/2018
[Mon Jul 20 07:20:12.472641 2026] [security2:error] [pid 94831:tid 95082] [client 141.94.95.178:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4gjI06NaEKF1g_MW3DzgAAAHk"]
[Mon Jul 20 07:20:12.628016 2026] [security2:error] [pid 94831:tid 94933] [remote 8.217.108.67:10884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/wp-login.php"] [unique_id "al4gjI06NaEKF1g_MW3D7AAAaWU"]
[Mon Jul 20 07:20:12.726918 2026] [security2:error] [pid 94831:tid 95043] [client 49.37.242.14:56057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gjI06NaEKF1g_MW3D8AAAAFI"]
[Mon Jul 20 07:20:12.727029 2026] [security2:error] [pid 94831:tid 95043] [client 49.37.242.14:56057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gjI06NaEKF1g_MW3D8AAAAFI"]
[Mon Jul 20 07:20:13.041736 2026] [security2:error] [pid 94831:tid 94986] [client 2a03:2880:f800:14:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "benbayly.co.nz"] [uri "/index.php"] [unique_id "al4gjI06NaEKF1g_MW3ECgAAGWk"]
[Mon Jul 20 07:20:13.243281 2026] [security2:error] [pid 94831:tid 95031] [client 77.110.127.138:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gjY06NaEKF1g_MW3EFgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:13.243371 2026] [security2:error] [pid 94831:tid 95031] [client 77.110.127.138:63727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gjY06NaEKF1g_MW3EFgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:13.288420 2026] [security2:error] [pid 94831:tid 94900] [remote 8.217.108.67:10884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/wp-login.php"] [unique_id "al4gjY06NaEKF1g_MW3EGAAAOkQ"], referer: https://elementconstruction.co.uk/wp-login.php
[Mon Jul 20 07:20:13.618310 2026] [security2:error] [pid 94831:tid 94970] [client 14.225.17.146:49511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4gjY06NaEKF1g_MW3EDwAAAAk"], referer: http://partnerselectricalllc.com/2018
[Mon Jul 20 07:20:13.971349 2026] [security2:error] [pid 94831:tid 95034] [client 166.199.141.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4gjY06NaEKF1g_MW3EPAAAAEk"], referer: https://liquidationteam.com/our-products/
[Mon Jul 20 07:20:13.977449 2026] [security2:error] [pid 94831:tid 94927] [remote 5.161.225.162:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4gjY06NaEKF1g_MW3EWgAAD18"]
[Mon Jul 20 07:20:14.213467 2026] [security2:error] [pid 94831:tid 94841] [remote 5.161.225.162:54080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4gjo06NaEKF1g_MW3EagAAGQk"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:20:14.357020 2026] [security2:error] [pid 94831:tid 95054] [client 77.110.127.138:63737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gjo06NaEKF1g_MW3EewAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:14.357118 2026] [security2:error] [pid 94831:tid 95054] [client 77.110.127.138:63737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gjo06NaEKF1g_MW3EewAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:14.390092 2026] [security2:error] [pid 94831:tid 95062] [client 57.141.18.123:28690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gio06NaEKF1g_MW3DAQAAZWE"]
[Mon Jul 20 07:20:14.485912 2026] [security2:error] [pid 94831:tid 94884] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gjo06NaEKF1g_MW3EiQAALzQ"]
[Mon Jul 20 07:20:14.486072 2026] [security2:error] [pid 94831:tid 95008] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gjo06NaEKF1g_MW3EiQAALzQ"]
[Mon Jul 20 07:20:14.766699 2026] [security2:error] [pid 94831:tid 95026] [client 103.176.215.66:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gjo06NaEKF1g_MW3EngAAAEE"]
[Mon Jul 20 07:20:14.766852 2026] [security2:error] [pid 94831:tid 95026] [client 103.176.215.66:58850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gjo06NaEKF1g_MW3EngAAAEE"]
[Mon Jul 20 07:20:14.891563 2026] [security2:error] [pid 94831:tid 95083] [client 14.225.17.146:50342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4gjo06NaEKF1g_MW3EoAAAAHo"], referer: http://friendlyspreadsheet.com/2018
[Mon Jul 20 07:20:15.122651 2026] [security2:error] [pid 94831:tid 95073] [client 49.47.218.174:54024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3EwgAAAHA"]
[Mon Jul 20 07:20:15.122776 2026] [security2:error] [pid 94831:tid 95073] [client 49.47.218.174:54024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3EwgAAAHA"]
[Mon Jul 20 07:20:15.143602 2026] [security2:error] [pid 94831:tid 95035] [client 88.241.67.160:55341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3ExAAAAEo"]
[Mon Jul 20 07:20:15.143876 2026] [security2:error] [pid 94831:tid 95035] [client 88.241.67.160:55341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3ExAAAAEo"]
[Mon Jul 20 07:20:15.151958 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:63741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gj406NaEKF1g_MW3ExgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:15.152043 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:63741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gj406NaEKF1g_MW3ExgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:15.214188 2026] [security2:error] [pid 94831:tid 94867] [remote 100.42.189.89:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gj406NaEKF1g_MW3EzQAACSM"]
[Mon Jul 20 07:20:15.315066 2026] [security2:error] [pid 94831:tid 95016] [client 50.116.65.227:59406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4gj406NaEKF1g_MW3EwwAAADc"]
[Mon Jul 20 07:20:15.393335 2026] [security2:error] [pid 94831:tid 95030] [client 157.20.138.62:53931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E5gAAAEU"]
[Mon Jul 20 07:20:15.393503 2026] [security2:error] [pid 94831:tid 95030] [client 157.20.138.62:53931] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E5gAAAEU"]
[Mon Jul 20 07:20:15.471835 2026] [security2:error] [pid 94831:tid 94896] [remote 100.42.189.89:54070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gj406NaEKF1g_MW3E6QAAbEA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:20:15.496019 2026] [security2:error] [pid 94831:tid 95083] [client 50.116.65.227:59408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4gj406NaEKF1g_MW3E2QAAAHo"]
[Mon Jul 20 07:20:15.555228 2026] [lsapi:warn] [pid 94831:tid 95071] [client 134.122.8.24:51675] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:15.558268 2026] [lsapi:warn] [pid 94831:tid 95071] [client 134.122.8.24:51675] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:15.582432 2026] [security2:error] [pid 94831:tid 95078] [client 143.44.185.218:8180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E8QAAAHU"]
[Mon Jul 20 07:20:15.582530 2026] [security2:error] [pid 94831:tid 95078] [client 143.44.185.218:8180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E8QAAAHU"]
[Mon Jul 20 07:20:15.611534 2026] [security2:error] [pid 94831:tid 94881] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E9QAASzE"]
[Mon Jul 20 07:20:15.611657 2026] [security2:error] [pid 94831:tid 95036] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E9QAASzE"]
[Mon Jul 20 07:20:15.770861 2026] [security2:error] [pid 94831:tid 95062] [client 216.24.212.24:43817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4gj406NaEKF1g_MW3E-gAAAGU"]
[Mon Jul 20 07:20:15.773551 2026] [security2:error] [pid 94831:tid 95031] [client 36.93.152.155:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E_gAAAEY"]
[Mon Jul 20 07:20:15.773627 2026] [security2:error] [pid 94831:tid 95031] [client 36.93.152.155:50697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gj406NaEKF1g_MW3E_gAAAEY"]
[Mon Jul 20 07:20:15.773766 2026] [security2:error] [pid 94831:tid 95019] [client 216.24.212.22:47973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4gj406NaEKF1g_MW3E-wAAADo"]
[Mon Jul 20 07:20:15.871263 2026] [security2:error] [pid 94831:tid 94967] [client 14.225.17.146:59841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4gj406NaEKF1g_MW3FAgAAAAY"], referer: https://friendlyspreadsheet.com/2018
[Mon Jul 20 07:20:16.001222 2026] [security2:error] [pid 94831:tid 95001] [client 57.141.18.103:25744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gi406NaEKF1g_MW3DiwAAKEg"]
[Mon Jul 20 07:20:16.036556 2026] [security2:error] [pid 94831:tid 94988] [client 191.202.66.27:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gkI06NaEKF1g_MW3FFAAAABs"]
[Mon Jul 20 07:20:16.036660 2026] [security2:error] [pid 94831:tid 94988] [client 191.202.66.27:55283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gkI06NaEKF1g_MW3FFAAAABs"]
[Mon Jul 20 07:20:16.057928 2026] [security2:error] [pid 94831:tid 94991] [client 14.225.17.146:64212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4gjo06NaEKF1g_MW3EhQAAAB4"], referer: http://lelandumc.org/2018
[Mon Jul 20 07:20:16.615716 2026] [security2:error] [pid 94831:tid 95079] [client 117.211.236.168:50403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gkI06NaEKF1g_MW3FQAAAAHY"]
[Mon Jul 20 07:20:16.615851 2026] [security2:error] [pid 94831:tid 95079] [client 117.211.236.168:50403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gkI06NaEKF1g_MW3FQAAAAHY"]
[Mon Jul 20 07:20:16.686445 2026] [security2:error] [pid 94831:tid 95047] [client 52.183.195.200:9988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gkI06NaEKF1g_MW3FQwAAAFY"]
[Mon Jul 20 07:20:16.716527 2026] [security2:error] [pid 94831:tid 95073] [client 52.183.195.200:9988] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gkI06NaEKF1g_MW3FSAAAAHA"]
[Mon Jul 20 07:20:16.893512 2026] [security2:error] [pid 94831:tid 94978] [client 14.225.17.146:50676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4gkI06NaEKF1g_MW3FRwAAABE"], referer: http://swafforddetailing.com/2018
[Mon Jul 20 07:20:17.027351 2026] [core:error] [pid 94831:tid 95038] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:17.027370 2026] [core:error] [pid 94831:tid 95038] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:17.177161 2026] [security2:error] [pid 94831:tid 94998] [client 57.141.18.26:47734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gjI06NaEKF1g_MW3D9gAAJRQ"]
[Mon Jul 20 07:20:17.311890 2026] [security2:error] [pid 94831:tid 94913] [remote 57.141.18.63:33812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6500809"] [unique_id "al4gkY06NaEKF1g_MW3FkQAAalE"]
[Mon Jul 20 07:20:17.477303 2026] [security2:error] [pid 94831:tid 95065] [client 103.106.165.44:59004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gkY06NaEKF1g_MW3FnAAAAGg"]
[Mon Jul 20 07:20:17.477420 2026] [security2:error] [pid 94831:tid 95065] [client 103.106.165.44:59004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gkY06NaEKF1g_MW3FnAAAAGg"]
[Mon Jul 20 07:20:17.517077 2026] [security2:error] [pid 94831:tid 94961] [client 50.116.65.227:59444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gkY06NaEKF1g_MW3FowAAAAA"]
[Mon Jul 20 07:20:17.526669 2026] [security2:error] [pid 94831:tid 95025] [client 50.116.65.227:59458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gkY06NaEKF1g_MW3FpQAAAEA"]
[Mon Jul 20 07:20:17.701207 2026] [security2:error] [pid 94831:tid 95006] [client 144.172.114.51:56818] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/wp-config.php.old"] [unique_id "al4gkY06NaEKF1g_MW3FrwAAAC0"]
[Mon Jul 20 07:20:17.777340 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:63757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gkY06NaEKF1g_MW3FtgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:17.777425 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:63757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gkY06NaEKF1g_MW3FtgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:17.941531 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gkY06NaEKF1g_MW3FvgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:17.941641 2026] [security2:error] [pid 94831:tid 95051] [client 77.110.127.138:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gkY06NaEKF1g_MW3FvgAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:17.985216 2026] [security2:error] [pid 94831:tid 95031] [client 187.16.64.216:61492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gkY06NaEKF1g_MW3FwAAAAEY"]
[Mon Jul 20 07:20:17.985328 2026] [security2:error] [pid 94831:tid 95031] [client 187.16.64.216:61492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gkY06NaEKF1g_MW3FwAAAAEY"]
[Mon Jul 20 07:20:18.021292 2026] [security2:error] [pid 94831:tid 94996] [client 57.141.18.102:64530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gjY06NaEKF1g_MW3EQwAAIyE"]
[Mon Jul 20 07:20:18.227823 2026] [proxy:error] [pid 94831:tid 95070] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:18.227895 2026] [proxy_http:error] [pid 94831:tid 95070] [client 8.229.28.226:39382] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:18.229061 2026] [proxy:error] [pid 94831:tid 95070] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:18.229117 2026] [proxy_http:error] [pid 94831:tid 95070] [client 8.229.28.226:39382] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:18.336091 2026] [core:error] [pid 94831:tid 95062] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:18.336114 2026] [core:error] [pid 94831:tid 95062] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:18.336231 2026] [security2:error] [pid 94831:tid 95047] [client 154.192.123.127:17070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gko06NaEKF1g_MW3F7QAAAFY"]
[Mon Jul 20 07:20:18.336851 2026] [security2:error] [pid 94831:tid 95047] [client 154.192.123.127:17070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gko06NaEKF1g_MW3F7QAAAFY"]
[Mon Jul 20 07:20:18.418421 2026] [security2:error] [pid 94831:tid 95019] [client 40.77.178.36:43844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4gko06NaEKF1g_MW3F6gAAOho"]
[Mon Jul 20 07:20:18.440988 2026] [security2:error] [pid 94831:tid 95015] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4gko06NaEKF1g_MW3F6wAAADY"]
[Mon Jul 20 07:20:18.501417 2026] [security2:error] [pid 94831:tid 95086] [client 154.208.48.130:57875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gko06NaEKF1g_MW3F-wAAAH0"]
[Mon Jul 20 07:20:18.501541 2026] [security2:error] [pid 94831:tid 95086] [client 154.208.48.130:57875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gko06NaEKF1g_MW3F-wAAAH0"]
[Mon Jul 20 07:20:18.569985 2026] [security2:error] [pid 94831:tid 94984] [client 14.225.17.146:64215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4gkY06NaEKF1g_MW3FeAAAABc"], referer: http://kromosenergy.com/2018
[Mon Jul 20 07:20:18.823538 2026] [security2:error] [pid 94831:tid 94916] [remote 18.61.192.253:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gko06NaEKF1g_MW3GHQAAb1Q"]
[Mon Jul 20 07:20:18.823737 2026] [security2:error] [pid 94831:tid 95072] [client 18.61.192.253:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gko06NaEKF1g_MW3GHQAAb1Q"]
[Mon Jul 20 07:20:18.918343 2026] [security2:error] [pid 94831:tid 94980] [client 57.141.18.42:39232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gjo06NaEKF1g_MW3EkQAAE0M"]
[Mon Jul 20 07:20:19.451662 2026] [security2:error] [pid 94831:tid 95045] [client 77.110.127.138:63764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gk406NaEKF1g_MW3GRgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:19.451741 2026] [security2:error] [pid 94831:tid 95045] [client 77.110.127.138:63764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gk406NaEKF1g_MW3GRgAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:19.455544 2026] [security2:error] [pid 94831:tid 95043] [client 201.27.111.74:61480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gk406NaEKF1g_MW3GSAAAAFI"]
[Mon Jul 20 07:20:19.455614 2026] [security2:error] [pid 94831:tid 95043] [client 201.27.111.74:61480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gk406NaEKF1g_MW3GSAAAAFI"]
[Mon Jul 20 07:20:19.803348 2026] [security2:error] [pid 94831:tid 94987] [client 14.225.17.146:53954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4gk406NaEKF1g_MW3GYAAAABo"], referer: http://ancestralidadytrance.space/2018
[Mon Jul 20 07:20:19.976365 2026] [security2:error] [pid 94831:tid 95046] [client 104.234.53.83:56413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gk406NaEKF1g_MW3GcgAAAFU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:20.158312 2026] [security2:error] [pid 94831:tid 95007] [client 14.225.17.146:54148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4gk406NaEKF1g_MW3GWQAAAC4"], referer: http://onewingpictures.com/2018
[Mon Jul 20 07:20:20.288098 2026] [security2:error] [pid 94831:tid 95031] [client 14.225.17.146:64146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4gk406NaEKF1g_MW3GdAAAAEY"], referer: http://transparentservices.online/2018
[Mon Jul 20 07:20:20.323266 2026] [security2:error] [pid 94831:tid 95004] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GigAAACs"]
[Mon Jul 20 07:20:20.332392 2026] [security2:error] [pid 94831:tid 94964] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GjgAAAAM"]
[Mon Jul 20 07:20:20.355808 2026] [security2:error] [pid 94831:tid 94971] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GjwAAAAo"]
[Mon Jul 20 07:20:20.497137 2026] [security2:error] [pid 94831:tid 94979] [client 57.141.18.73:58126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gkI06NaEKF1g_MW3FGgAAEmY"]
[Mon Jul 20 07:20:20.739686 2026] [security2:error] [pid 94831:tid 95012] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GrgAAADM"]
[Mon Jul 20 07:20:20.741096 2026] [security2:error] [pid 94831:tid 95007] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GrwAAAC4"]
[Mon Jul 20 07:20:20.822525 2026] [security2:error] [pid 94831:tid 95063] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GtQAAAGY"]
[Mon Jul 20 07:20:20.909808 2026] [security2:error] [pid 94831:tid 94964] [client 74.7.175.170:37580] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.marscafe.com"] [uri "/robots.txt"] [unique_id "al4glI06NaEKF1g_MW3GzwAAAxc"]
[Mon Jul 20 07:20:21.021346 2026] [security2:error] [pid 94831:tid 94999] [client 35.252.248.221:38086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4gk406NaEKF1g_MW3GNgAAACY"]
[Mon Jul 20 07:20:21.305545 2026] [security2:error] [pid 94831:tid 95010] [client 104.234.53.47:24285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4glY06NaEKF1g_MW3G8AAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:21.411133 2026] [security2:error] [pid 94831:tid 94978] [client 14.225.17.146:54117] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4glY06NaEKF1g_MW3G7QAAABE"], referer: http://sarahsnyder.net/2018
[Mon Jul 20 07:20:21.839398 2026] [security2:error] [pid 94831:tid 95031] [client 50.116.65.227:34890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4glY06NaEKF1g_MW3HFAAAAEY"]
[Mon Jul 20 07:20:21.848699 2026] [security2:error] [pid 94831:tid 95062] [client 50.116.65.227:34904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4glY06NaEKF1g_MW3HFQAAAGU"]
[Mon Jul 20 07:20:21.987566 2026] [security2:error] [pid 94831:tid 94945] [remote 152.228.213.32:42194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4glY06NaEKF1g_MW3HHAAAGXE"]
[Mon Jul 20 07:20:21.987729 2026] [security2:error] [pid 94831:tid 94986] [client 152.228.213.32:42194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4glY06NaEKF1g_MW3HHAAAGXE"]
[Mon Jul 20 07:20:22.024703 2026] [security2:error] [pid 94831:tid 95054] [client 14.225.17.146:54341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GpwAAAF0"], referer: http://adirondackengineering.com/2018
[Mon Jul 20 07:20:22.052771 2026] [security2:error] [pid 94831:tid 95075] [client 103.144.65.217:58561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4glo06NaEKF1g_MW3HHgAAAHI"]
[Mon Jul 20 07:20:22.052896 2026] [security2:error] [pid 94831:tid 95075] [client 103.144.65.217:58561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4glo06NaEKF1g_MW3HHgAAAHI"]
[Mon Jul 20 07:20:22.060394 2026] [security2:error] [pid 94831:tid 95066] [client 77.110.127.138:63770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4glo06NaEKF1g_MW3HIAAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:22.060525 2026] [security2:error] [pid 94831:tid 95066] [client 77.110.127.138:63770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4glo06NaEKF1g_MW3HIAAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:22.210790 2026] [security2:error] [pid 94831:tid 95032] [client 77.110.127.138:63771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4glo06NaEKF1g_MW3HLAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:22.210884 2026] [security2:error] [pid 94831:tid 95032] [client 77.110.127.138:63771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4glo06NaEKF1g_MW3HLAAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:22.322509 2026] [proxy:error] [pid 94831:tid 95014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:22.322598 2026] [proxy_http:error] [pid 94831:tid 95014] [client 8.229.28.226:34766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:22.323233 2026] [proxy:error] [pid 94831:tid 95014] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:22.323263 2026] [proxy_http:error] [pid 94831:tid 95014] [client 8.229.28.226:34766] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:22.639398 2026] [security2:error] [pid 94831:tid 95070] [client 14.225.17.146:56333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4glo06NaEKF1g_MW3HPwAAAG0"], referer: http://inspirespublishing.com/2018
[Mon Jul 20 07:20:22.794088 2026] [security2:error] [pid 94831:tid 95053] [client 47.82.124.204:59886] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.mezzacraft.com"] [uri "/wp-content/uploads/2018/02/Tunisian-entrelac_mezzacraft_classes-1-320x320.jpg"] [unique_id "al4glo06NaEKF1g_MW3HUgAAAFw"]
[Mon Jul 20 07:20:22.986851 2026] [security2:error] [pid 94831:tid 95050] [client 202.141.11.99:37003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4glo06NaEKF1g_MW3HaQAAAFk"]
[Mon Jul 20 07:20:22.986998 2026] [security2:error] [pid 94831:tid 95050] [client 202.141.11.99:37003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4glo06NaEKF1g_MW3HaQAAAFk"]
[Mon Jul 20 07:20:23.077209 2026] [security2:error] [pid 94831:tid 94878] [remote 13.232.189.155:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4gl406NaEKF1g_MW3HcAAAOC4"]
[Mon Jul 20 07:20:23.157379 2026] [security2:error] [pid 94831:tid 95076] [client 77.110.127.138:63774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gl406NaEKF1g_MW3HdwAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:23.157464 2026] [security2:error] [pid 94831:tid 95076] [client 77.110.127.138:63774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gl406NaEKF1g_MW3HdwAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:23.180825 2026] [security2:error] [pid 94831:tid 95083] [client 15.235.184.192:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4gl406NaEKF1g_MW3HbgAAAHo"]
[Mon Jul 20 07:20:23.400001 2026] [security2:error] [pid 94831:tid 94889] [remote 57.141.18.74:47252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/5127862"] [unique_id "al4gl406NaEKF1g_MW3HigAAVDk"]
[Mon Jul 20 07:20:23.476354 2026] [security2:error] [pid 94831:tid 94854] [remote 13.232.189.155:40160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4gl406NaEKF1g_MW3HmAAAchY"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:20:23.603890 2026] [proxy:error] [pid 94831:tid 95015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:23.603972 2026] [proxy_http:error] [pid 94831:tid 95015] [client 94.154.43.188:19966] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:23.604900 2026] [proxy:error] [pid 94831:tid 95015] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:23.604933 2026] [proxy_http:error] [pid 94831:tid 95015] [client 94.154.43.188:19966] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:23.685185 2026] [security2:error] [pid 94831:tid 94964] [client 14.225.17.146:56360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4gl406NaEKF1g_MW3HkAAAAAM"], referer: http://dollpassionista.com/2018
[Mon Jul 20 07:20:23.830886 2026] [proxy:error] [pid 94831:tid 94972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:23.830972 2026] [proxy_http:error] [pid 94831:tid 94972] [client 94.154.43.185:53074] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:23.831600 2026] [proxy:error] [pid 94831:tid 94972] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:23.831645 2026] [proxy_http:error] [pid 94831:tid 94972] [client 94.154.43.185:53074] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:24.056535 2026] [lsapi:warn] [pid 94831:tid 95061] [client 134.122.8.24:51824] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:24.059565 2026] [lsapi:warn] [pid 94831:tid 95061] [client 134.122.8.24:51824] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:24.249647 2026] [security2:error] [pid 94831:tid 95036] [client 49.37.242.14:56545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gmI06NaEKF1g_MW3H2wAAAEs"]
[Mon Jul 20 07:20:24.249735 2026] [security2:error] [pid 94831:tid 95036] [client 49.37.242.14:56545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gmI06NaEKF1g_MW3H2wAAAEs"]
[Mon Jul 20 07:20:24.302441 2026] [security2:error] [pid 94831:tid 95010] [client 47.82.10.12:50530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4glo06NaEKF1g_MW3HUAAAADE"], referer: https://lifeisbetterlakeside.com/
[Mon Jul 20 07:20:24.690721 2026] [security2:error] [pid 94831:tid 95028] [client 14.225.17.146:56370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4gmI06NaEKF1g_MW3H6QAAAEM"], referer: https://dollpassionista.com/2018
[Mon Jul 20 07:20:24.990256 2026] [security2:error] [pid 94831:tid 95029] [client 14.225.17.146:55133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4gl406NaEKF1g_MW3HjwAAAEQ"], referer: http://vinovinhowine.com/2018
[Mon Jul 20 07:20:25.031200 2026] [security2:error] [pid 94831:tid 94970] [client 57.141.18.64:58968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GrQAACQU"]
[Mon Jul 20 07:20:25.136246 2026] [security2:error] [pid 94831:tid 95016] [client 57.141.18.12:27400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4glI06NaEKF1g_MW3GtwAANxQ"]
[Mon Jul 20 07:20:25.157766 2026] [security2:error] [pid 94831:tid 94845] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IIQAAUA0"]
[Mon Jul 20 07:20:25.157918 2026] [security2:error] [pid 94831:tid 95041] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IIQAAUA0"]
[Mon Jul 20 07:20:25.331717 2026] [security2:error] [pid 94831:tid 95024] [client 103.176.215.66:59383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IKwAAAD8"]
[Mon Jul 20 07:20:25.331845 2026] [security2:error] [pid 94831:tid 95024] [client 103.176.215.66:59383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IKwAAAD8"]
[Mon Jul 20 07:20:25.364149 2026] [security2:error] [pid 94831:tid 95038] [client 77.110.127.138:63786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gmY06NaEKF1g_MW3ILAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:25.364263 2026] [security2:error] [pid 94831:tid 95038] [client 77.110.127.138:63786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gmY06NaEKF1g_MW3ILAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:25.520172 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:63787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gmY06NaEKF1g_MW3IMQAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:25.520258 2026] [security2:error] [pid 94831:tid 95007] [client 77.110.127.138:63787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gmY06NaEKF1g_MW3IMQAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:25.639088 2026] [security2:error] [pid 94831:tid 94987] [client 49.47.218.174:54539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IPQAAABo"]
[Mon Jul 20 07:20:25.639239 2026] [security2:error] [pid 94831:tid 94987] [client 49.47.218.174:54539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IPQAAABo"]
[Mon Jul 20 07:20:25.663775 2026] [security2:error] [pid 94831:tid 95020] [client 88.241.67.160:56264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IQwAAADs"]
[Mon Jul 20 07:20:25.664078 2026] [security2:error] [pid 94831:tid 95020] [client 88.241.67.160:56264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IQwAAADs"]
[Mon Jul 20 07:20:25.865021 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:63793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gmY06NaEKF1g_MW3IXgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:25.865116 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:63793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gmY06NaEKF1g_MW3IXgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:25.875891 2026] [lsapi:warn] [pid 94831:tid 95048] [client 134.122.8.24:51863] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:25.878880 2026] [lsapi:warn] [pid 94831:tid 95048] [client 134.122.8.24:51863] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:25.893583 2026] [security2:error] [pid 94831:tid 95076] [client 157.20.138.62:54497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IYwAAAHM"]
[Mon Jul 20 07:20:25.893667 2026] [security2:error] [pid 94831:tid 95076] [client 157.20.138.62:54497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gmY06NaEKF1g_MW3IYwAAAHM"]
[Mon Jul 20 07:20:26.158010 2026] [security2:error] [pid 94831:tid 95072] [client 143.44.185.218:9509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IcwAAAG8"]
[Mon Jul 20 07:20:26.158097 2026] [security2:error] [pid 94831:tid 95072] [client 143.44.185.218:9509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IcwAAAG8"]
[Mon Jul 20 07:20:26.179364 2026] [security2:error] [pid 94831:tid 94995] [client 50.116.65.227:29748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4gmo06NaEKF1g_MW3IdgAAACI"]
[Mon Jul 20 07:20:26.184126 2026] [security2:error] [pid 94831:tid 94986] [client 141.94.194.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.locketsandcharms.com"] [uri "/index.php"] [unique_id "al4gmI06NaEKF1g_MW3IAwAAABk"]
[Mon Jul 20 07:20:26.311806 2026] [security2:error] [pid 94831:tid 95006] [client 36.93.152.155:51194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IhAAAAC0"]
[Mon Jul 20 07:20:26.311886 2026] [security2:error] [pid 94831:tid 95006] [client 36.93.152.155:51194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IhAAAAC0"]
[Mon Jul 20 07:20:26.327152 2026] [security2:error] [pid 94831:tid 94912] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IhwAAeFA"]
[Mon Jul 20 07:20:26.327267 2026] [security2:error] [pid 94831:tid 95081] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IhwAAeFA"]
[Mon Jul 20 07:20:26.470859 2026] [security2:error] [pid 94831:tid 95075] [client 191.202.66.27:55748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IlAAAAHI"]
[Mon Jul 20 07:20:26.470965 2026] [security2:error] [pid 94831:tid 95075] [client 191.202.66.27:55748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gmo06NaEKF1g_MW3IlAAAAHI"]
[Mon Jul 20 07:20:26.712658 2026] [security2:error] [pid 94831:tid 95003] [client 57.141.18.71:32346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4glo06NaEKF1g_MW3HHwAAKgw"]
[Mon Jul 20 07:20:26.746242 2026] [security2:error] [pid 94831:tid 94981] [client 50.116.65.227:34950] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gmo06NaEKF1g_MW3IqAAAABQ"]
[Mon Jul 20 07:20:26.755142 2026] [security2:error] [pid 94831:tid 95067] [client 50.116.65.227:34960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gmo06NaEKF1g_MW3IqgAAAGo"]
[Mon Jul 20 07:20:26.780202 2026] [security2:error] [pid 94831:tid 95069] [client 185.209.229.78:41532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4gmo06NaEKF1g_MW3IrAAAAGw"]
[Mon Jul 20 07:20:27.291576 2026] [security2:error] [pid 94831:tid 94983] [client 185.209.229.78:41536] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4gm406NaEKF1g_MW3IxQAAABY"]
[Mon Jul 20 07:20:27.431075 2026] [security2:error] [pid 94831:tid 94906] [remote 69.57.160.88:40988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.160.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4gm406NaEKF1g_MW3I0gAAO0o"]
[Mon Jul 20 07:20:27.444857 2026] [core:error] [pid 94831:tid 95053] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:27.444870 2026] [core:error] [pid 94831:tid 95053] [client 8.229.28.226:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:27.512700 2026] [security2:error] [pid 94831:tid 95066] [client 52.109.28.48:9025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gm406NaEKF1g_MW3I3gAAAGk"]
[Mon Jul 20 07:20:27.591974 2026] [security2:error] [pid 94831:tid 94916] [remote 69.57.160.88:40988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.160.57.69.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4gm406NaEKF1g_MW3I4wAAa1Q"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 07:20:27.651850 2026] [security2:error] [pid 94831:tid 95044] [client 52.109.28.48:9025] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gm406NaEKF1g_MW3I6wAAAFM"]
[Mon Jul 20 07:20:27.729284 2026] [security2:error] [pid 94831:tid 95080] [client 185.209.229.78:41552] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4gm406NaEKF1g_MW3I9QAAAHc"]
[Mon Jul 20 07:20:27.767411 2026] [security2:error] [pid 94831:tid 95022] [client 57.141.18.56:43100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4glo06NaEKF1g_MW3HZQAAPUA"]
[Mon Jul 20 07:20:28.026598 2026] [security2:error] [pid 94831:tid 95055] [client 103.106.165.44:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gnI06NaEKF1g_MW3JBwAAAF4"]
[Mon Jul 20 07:20:28.026699 2026] [security2:error] [pid 94831:tid 95055] [client 103.106.165.44:59447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gnI06NaEKF1g_MW3JBwAAAF4"]
[Mon Jul 20 07:20:28.048617 2026] [security2:error] [pid 94831:tid 94973] [client 47.82.124.120:38698] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.mezzacraft.com"] [uri "/wp-content/uploads/2018/02/Tunisian-entrelac_mezzacraft_classes-1-320x320.jpg"] [unique_id "al4gnI06NaEKF1g_MW3JCQAAAAw"]
[Mon Jul 20 07:20:28.250412 2026] [security2:error] [pid 94831:tid 94980] [client 52.109.89.119:7170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gnI06NaEKF1g_MW3JGAAAABM"]
[Mon Jul 20 07:20:28.396034 2026] [security2:error] [pid 94831:tid 94996] [client 57.141.18.12:27308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gl406NaEKF1g_MW3HowAAI2c"]
[Mon Jul 20 07:20:28.398684 2026] [security2:error] [pid 94831:tid 95045] [client 52.109.89.119:7170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gnI06NaEKF1g_MW3JJgAAAFQ"]
[Mon Jul 20 07:20:28.441203 2026] [security2:error] [pid 94831:tid 95080] [client 57.141.18.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gnI06NaEKF1g_MW3JIQAAAHc"]
[Mon Jul 20 07:20:28.475254 2026] [lsapi:warn] [pid 94831:tid 95066] [client 134.122.8.24:51905] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:28.478185 2026] [lsapi:warn] [pid 94831:tid 95066] [client 134.122.8.24:51905] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:28.537851 2026] [security2:error] [pid 94831:tid 94961] [client 47.82.124.45:4914] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.mezzacraft.com"] [uri "/wp-content/uploads/2018/02/Tunisian-entrelac_mezzacraft_classes-1-320x320.jpg"] [unique_id "al4gnI06NaEKF1g_MW3JLAAAAAA"]
[Mon Jul 20 07:20:28.659031 2026] [security2:error] [pid 94831:tid 95022] [client 187.16.64.216:62070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gnI06NaEKF1g_MW3JNwAAAD0"]
[Mon Jul 20 07:20:28.659185 2026] [security2:error] [pid 94831:tid 95022] [client 187.16.64.216:62070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gnI06NaEKF1g_MW3JNwAAAD0"]
[Mon Jul 20 07:20:28.791355 2026] [security2:error] [pid 94831:tid 95017] [client 104.234.53.70:46983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gnI06NaEKF1g_MW3JRAAAADg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:28.971594 2026] [security2:error] [pid 94831:tid 95006] [client 117.211.236.168:50987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gnI06NaEKF1g_MW3JTgAAAC0"]
[Mon Jul 20 07:20:28.971699 2026] [security2:error] [pid 94831:tid 95006] [client 117.211.236.168:50987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gnI06NaEKF1g_MW3JTgAAAC0"]
[Mon Jul 20 07:20:29.015719 2026] [security2:error] [pid 94831:tid 95036] [client 14.225.17.146:53668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4gnI06NaEKF1g_MW3JSAAAAEs"]
[Mon Jul 20 07:20:29.053590 2026] [security2:error] [pid 94831:tid 94999] [client 154.192.123.127:17459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gnY06NaEKF1g_MW3JUQAAACY"]
[Mon Jul 20 07:20:29.053710 2026] [security2:error] [pid 94831:tid 94999] [client 154.192.123.127:17459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gnY06NaEKF1g_MW3JUQAAACY"]
[Mon Jul 20 07:20:29.122908 2026] [security2:error] [pid 94831:tid 94928] [remote 188.166.241.141:41394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gnY06NaEKF1g_MW3JWQAARWA"]
[Mon Jul 20 07:20:29.213463 2026] [security2:error] [pid 94831:tid 95064] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4gm406NaEKF1g_MW3I_wAAAGc"]
[Mon Jul 20 07:20:29.301375 2026] [security2:error] [pid 94831:tid 95052] [client 20.220.225.223:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "rdcramer3.com"] [uri "/.well-known/about.php"] [unique_id "al4gnY06NaEKF1g_MW3JaQAAAFs"]
[Mon Jul 20 07:20:29.301490 2026] [security2:error] [pid 94831:tid 95052] [client 20.220.225.223:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "rdcramer3.com"] [uri "/.well-known/about.php"] [unique_id "al4gnY06NaEKF1g_MW3JaQAAAFs"]
[Mon Jul 20 07:20:29.303667 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:63816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gnY06NaEKF1g_MW3JbAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:29.303786 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:63816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gnY06NaEKF1g_MW3JbAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:29.409213 2026] [security2:error] [pid 94831:tid 95007] [client 47.82.124.196:42601] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.mezzacraft.com"] [uri "/wp-content/uploads/2018/02/Tunisian-entrelac_mezzacraft_classes-1-320x320.jpg"] [unique_id "al4gnY06NaEKF1g_MW3JcQAAAC4"]
[Mon Jul 20 07:20:29.490096 2026] [security2:error] [pid 94831:tid 94954] [remote 188.166.241.141:41394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gnY06NaEKF1g_MW3JeQAAUHo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:20:29.501871 2026] [security2:error] [pid 94831:tid 95077] [client 201.27.111.74:61990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gnY06NaEKF1g_MW3JegAAAHQ"]
[Mon Jul 20 07:20:29.502029 2026] [security2:error] [pid 94831:tid 95077] [client 201.27.111.74:61990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gnY06NaEKF1g_MW3JegAAAHQ"]
[Mon Jul 20 07:20:29.710462 2026] [security2:error] [pid 94831:tid 95005] [client 77.110.127.138:63820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gnY06NaEKF1g_MW3JjAAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:29.710550 2026] [security2:error] [pid 94831:tid 95005] [client 77.110.127.138:63820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gnY06NaEKF1g_MW3JjAAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:29.796617 2026] [core:error] [pid 94831:tid 95081] [client 14.225.17.146:53724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:29.796637 2026] [core:error] [pid 94831:tid 95081] [client 14.225.17.146:53724] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:29.994643 2026] [security2:error] [pid 94831:tid 94984] [client 57.141.18.56:52290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gmY06NaEKF1g_MW3IGQAAF0w"]
[Mon Jul 20 07:20:30.000910 2026] [security2:error] [pid 94831:tid 95000] [client 154.208.48.130:58401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gno06NaEKF1g_MW3JsgAAACc"]
[Mon Jul 20 07:20:30.001025 2026] [security2:error] [pid 94831:tid 95000] [client 154.208.48.130:58401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gno06NaEKF1g_MW3JsgAAACc"]
[Mon Jul 20 07:20:30.007398 2026] [security2:error] [pid 94831:tid 95045] [client 47.82.124.205:34486] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.mezzacraft.com"] [uri "/wp-content/uploads/2018/02/Tunisian-entrelac_mezzacraft_classes-1-320x320.jpg"] [unique_id "al4gno06NaEKF1g_MW3JswAAAFQ"]
[Mon Jul 20 07:20:30.243676 2026] [security2:error] [pid 94831:tid 95030] [client 104.234.53.47:22239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gno06NaEKF1g_MW3JwAAAAEU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:30.289111 2026] [security2:error] [pid 94831:tid 94940] [remote 72.167.132.114:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gno06NaEKF1g_MW3JyQAALGw"]
[Mon Jul 20 07:20:30.341423 2026] [security2:error] [pid 94831:tid 95023] [client 77.110.127.138:63832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gno06NaEKF1g_MW3JzQAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:30.341510 2026] [security2:error] [pid 94831:tid 95023] [client 77.110.127.138:63832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gno06NaEKF1g_MW3JzQAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:30.497315 2026] [security2:error] [pid 94831:tid 95043] [client 77.110.127.138:63833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gno06NaEKF1g_MW3J3wAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:30.497412 2026] [security2:error] [pid 94831:tid 95043] [client 77.110.127.138:63833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gno06NaEKF1g_MW3J3wAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:30.505172 2026] [security2:error] [pid 94831:tid 94912] [remote 72.167.132.114:50854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4gno06NaEKF1g_MW3J3QAAblA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:20:30.564412 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gno06NaEKF1g_MW3J5QAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:30.564538 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gno06NaEKF1g_MW3J5QAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:30.691946 2026] [security2:error] [pid 94831:tid 95044] [client 14.225.17.146:63938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4gno06NaEKF1g_MW3J4QAAAFM"], referer: http://taskidsvirginia.com/2018
[Mon Jul 20 07:20:31.085349 2026] [security2:error] [pid 94831:tid 95021] [client 77.110.127.138:63794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gn406NaEKF1g_MW3KDwAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:31.085462 2026] [security2:error] [pid 94831:tid 95021] [client 77.110.127.138:63794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gn406NaEKF1g_MW3KDwAAADw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:31.156779 2026] [security2:error] [pid 94831:tid 95073] [client 14.225.17.146:55116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4gn406NaEKF1g_MW3KDQAAAHA"], referer: http://blaizeaccountingservices.com/2018
[Mon Jul 20 07:20:31.419550 2026] [security2:error] [pid 94831:tid 95003] [client 47.82.124.195:54441] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.mezzacraft.com"] [uri "/wp-content/uploads/2018/02/Tunisian-entrelac_mezzacraft_classes-1-320x320.jpg"] [unique_id "al4gn406NaEKF1g_MW3KLwAAACo"]
[Mon Jul 20 07:20:31.521531 2026] [security2:error] [pid 94831:tid 95016] [client 104.234.53.56:64119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gn406NaEKF1g_MW3KOQAAADc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:31.537261 2026] [security2:error] [pid 94831:tid 95061] [client 114.119.131.46:53431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.gescontrols.com"] [uri "/robots.txt"] [unique_id "al4gn406NaEKF1g_MW3KOgAAAGQ"], referer: https://www.gescontrols.com/robots.txt
[Mon Jul 20 07:20:31.569645 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gn406NaEKF1g_MW3KPAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:31.569761 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gn406NaEKF1g_MW3KPAAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:31.704148 2026] [security2:error] [pid 94831:tid 95013] [client 14.225.17.146:53694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4gno06NaEKF1g_MW3JzAAAADQ"], referer: http://eframiproperties.com/2018
[Mon Jul 20 07:20:31.725116 2026] [security2:error] [pid 94831:tid 95081] [client 77.110.127.138:63839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gn406NaEKF1g_MW3KRwAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:31.725198 2026] [security2:error] [pid 94831:tid 95081] [client 77.110.127.138:63839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gn406NaEKF1g_MW3KRwAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.014157 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:63840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KXQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.014259 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:63840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KXQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.056613 2026] [lsapi:warn] [pid 94831:tid 95074] [client 134.122.8.24:51996] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:32.059720 2026] [lsapi:warn] [pid 94831:tid 95074] [client 134.122.8.24:51996] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n
[Mon Jul 20 07:20:32.249673 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KbgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.249823 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KbgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.314521 2026] [security2:error] [pid 94831:tid 95053] [client 77.110.127.138:63842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KfAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.314617 2026] [security2:error] [pid 94831:tid 95053] [client 77.110.127.138:63842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KfAAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.317640 2026] [security2:error] [pid 94831:tid 94965] [client 77.110.127.138:63818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KfgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.317738 2026] [security2:error] [pid 94831:tid 94965] [client 77.110.127.138:63818] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KfgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.372883 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:63827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KhgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.372991 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:63827] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KhgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.529446 2026] [security2:error] [pid 94831:tid 95011] [client 104.234.53.72:39713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4goI06NaEKF1g_MW3KmwAAADI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:32.545933 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KngAAAHc"]
[Mon Jul 20 07:20:32.546027 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KngAAAHc"]
[Mon Jul 20 07:20:32.549671 2026] [security2:error] [pid 94831:tid 95018] [client 158.173.166.181:29267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4goI06NaEKF1g_MW3KnwAAADk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:20:32.586696 2026] [security2:error] [pid 94831:tid 95028] [client 103.144.65.217:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4goI06NaEKF1g_MW3KpgAAAEM"]
[Mon Jul 20 07:20:32.586835 2026] [security2:error] [pid 94831:tid 95028] [client 103.144.65.217:59178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4goI06NaEKF1g_MW3KpgAAAEM"]
[Mon Jul 20 07:20:32.613882 2026] [security2:error] [pid 94831:tid 94998] [client 45.66.35.37:50392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4goI06NaEKF1g_MW3KogAAACU"]
[Mon Jul 20 07:20:32.755519 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:63846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KrgAAACg"]
[Mon Jul 20 07:20:32.755620 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:63846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KrgAAACg"]
[Mon Jul 20 07:20:32.812137 2026] [security2:error] [pid 94831:tid 95073] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4goI06NaEKF1g_MW3KpQAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.872011 2026] [security2:error] [pid 94831:tid 95082] [client 57.141.18.78:43558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gnI06NaEKF1g_MW3JCAAAeRI"]
[Mon Jul 20 07:20:32.923420 2026] [security2:error] [pid 94831:tid 94988] [client 152.58.191.142:51224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4goI06NaEKF1g_MW3KuwAAABs"]
[Mon Jul 20 07:20:32.923555 2026] [security2:error] [pid 94831:tid 94988] [client 152.58.191.142:51224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4goI06NaEKF1g_MW3KuwAAABs"]
[Mon Jul 20 07:20:32.936040 2026] [security2:error] [pid 94831:tid 94984] [client 77.110.127.138:63838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KwwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:32.936158 2026] [security2:error] [pid 94831:tid 94984] [client 77.110.127.138:63838] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goI06NaEKF1g_MW3KwwAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:33.429802 2026] [security2:error] [pid 94831:tid 94957] [remote 57.141.18.53:40386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4goY06NaEKF1g_MW3K7AAAcH0"]
[Mon Jul 20 07:20:33.591462 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:63850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goY06NaEKF1g_MW3K-gAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:33.591545 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:63850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goY06NaEKF1g_MW3K-gAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:33.596943 2026] [security2:error] [pid 94831:tid 95041] [client 202.141.11.99:58297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4goY06NaEKF1g_MW3K-wAAAFA"]
[Mon Jul 20 07:20:33.597053 2026] [security2:error] [pid 94831:tid 95041] [client 202.141.11.99:58297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4goY06NaEKF1g_MW3K-wAAAFA"]
[Mon Jul 20 07:20:33.626344 2026] [security2:error] [pid 94831:tid 94987] [client 57.141.18.54:61280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gnI06NaEKF1g_MW3JSgAAGmo"]
[Mon Jul 20 07:20:33.690118 2026] [security2:error] [pid 94831:tid 95004] [client 77.110.127.138:63851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goY06NaEKF1g_MW3LBQAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:33.690203 2026] [security2:error] [pid 94831:tid 95004] [client 77.110.127.138:63851] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goY06NaEKF1g_MW3LBQAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:33.863595 2026] [security2:error] [pid 94831:tid 94988] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "rootsofwisdom.ca"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4goY06NaEKF1g_MW3LEwAAABs"]
[Mon Jul 20 07:20:34.038870 2026] [security2:error] [pid 94831:tid 94839] [remote 57.141.18.32:41930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4goo06NaEKF1g_MW3LHwAASwc"]
[Mon Jul 20 07:20:34.162602 2026] [security2:error] [pid 94831:tid 95076] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4goY06NaEKF1g_MW3LGgAAAHM"]
[Mon Jul 20 07:20:34.248641 2026] [security2:error] [pid 94831:tid 95031] [client 77.110.127.138:63817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goo06NaEKF1g_MW3LLgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:34.248739 2026] [security2:error] [pid 94831:tid 95031] [client 77.110.127.138:63817] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goo06NaEKF1g_MW3LLgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:34.447985 2026] [security2:error] [pid 94831:tid 95066] [client 57.141.18.30:45996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gnY06NaEKF1g_MW3JlAAAaQE"]
[Mon Jul 20 07:20:34.579398 2026] [security2:error] [pid 94831:tid 94948] [remote 57.141.18.51:24358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4goo06NaEKF1g_MW3LSQAAfnQ"]
[Mon Jul 20 07:20:34.581876 2026] [security2:error] [pid 94831:tid 95012] [client 77.110.127.138:63859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goo06NaEKF1g_MW3LSgAAADM"]
[Mon Jul 20 07:20:34.581958 2026] [security2:error] [pid 94831:tid 95012] [client 77.110.127.138:63859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goo06NaEKF1g_MW3LSgAAADM"]
[Mon Jul 20 07:20:34.717265 2026] [security2:error] [pid 94831:tid 95037] [client 57.141.18.109:51964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gno06NaEKF1g_MW3JvAAATBA"]
[Mon Jul 20 07:20:34.873073 2026] [security2:error] [pid 94831:tid 95049] [client 77.110.127.138:63860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goo06NaEKF1g_MW3LXQAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:34.873156 2026] [security2:error] [pid 94831:tid 95049] [client 77.110.127.138:63860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4goo06NaEKF1g_MW3LXQAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:34.950779 2026] [security2:error] [pid 94831:tid 94909] [remote 173.249.4.11:26174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4goo06NaEKF1g_MW3LZAAAOE0"]
[Mon Jul 20 07:20:35.043453 2026] [security2:error] [pid 94831:tid 94991] [client 77.110.127.138:63862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4go406NaEKF1g_MW3LcQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:35.043536 2026] [security2:error] [pid 94831:tid 94991] [client 77.110.127.138:63862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4go406NaEKF1g_MW3LcQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:35.161150 2026] [security2:error] [pid 94831:tid 94876] [remote 173.249.4.11:26174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4go406NaEKF1g_MW3LhQAAVyw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:20:35.273270 2026] [security2:error] [pid 94831:tid 95055] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4goo06NaEKF1g_MW3LagAAAF4"]
[Mon Jul 20 07:20:35.331436 2026] [security2:error] [pid 94831:tid 95008] [client 14.225.17.146:58314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4go406NaEKF1g_MW3LiwAAAC8"]
[Mon Jul 20 07:20:35.681314 2026] [security2:error] [pid 94831:tid 95072] [client 45.66.35.37:52122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4go406NaEKF1g_MW3LogAAAG8"]
[Mon Jul 20 07:20:35.686616 2026] [security2:error] [pid 94831:tid 94988] [client 49.37.242.14:57108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4go406NaEKF1g_MW3LowAAABs"]
[Mon Jul 20 07:20:35.686706 2026] [security2:error] [pid 94831:tid 94988] [client 49.37.242.14:57108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4go406NaEKF1g_MW3LowAAABs"]
[Mon Jul 20 07:20:35.759037 2026] [security2:error] [pid 94831:tid 95064] [client 57.141.18.68:54862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gn406NaEKF1g_MW3KDgAAZ0s"]
[Mon Jul 20 07:20:35.813302 2026] [security2:error] [pid 94831:tid 94871] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4go406NaEKF1g_MW3LqgAANyc"]
[Mon Jul 20 07:20:35.813422 2026] [security2:error] [pid 94831:tid 95016] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4go406NaEKF1g_MW3LqgAANyc"]
[Mon Jul 20 07:20:35.872863 2026] [security2:error] [pid 94831:tid 94990] [client 103.176.215.66:59905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4go406NaEKF1g_MW3LsAAAAB0"]
[Mon Jul 20 07:20:35.873222 2026] [security2:error] [pid 94831:tid 94990] [client 103.176.215.66:59905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4go406NaEKF1g_MW3LsAAAAB0"]
[Mon Jul 20 07:20:36.062853 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3LvQAAABQ"]
[Mon Jul 20 07:20:36.062967 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3LvQAAABQ"]
[Mon Jul 20 07:20:36.158916 2026] [security2:error] [pid 94831:tid 94994] [client 49.47.218.174:55058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3LygAAACE"]
[Mon Jul 20 07:20:36.159208 2026] [security2:error] [pid 94831:tid 94994] [client 49.47.218.174:55058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3LygAAACE"]
[Mon Jul 20 07:20:36.206281 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3LzwAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.206372 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3LzwAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.248492 2026] [security2:error] [pid 94831:tid 94951] [remote 57.141.18.9:20374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4gpI06NaEKF1g_MW3L0QAADHc"]
[Mon Jul 20 07:20:36.307089 2026] [security2:error] [pid 94831:tid 95038] [client 88.241.67.160:54158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3L1AAAAE0"]
[Mon Jul 20 07:20:36.307266 2026] [security2:error] [pid 94831:tid 95038] [client 88.241.67.160:54158] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3L1AAAAE0"]
[Mon Jul 20 07:20:36.355692 2026] [security2:error] [pid 94831:tid 95041] [client 74.208.214.194:44894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4gpI06NaEKF1g_MW3L2gAAAFA"]
[Mon Jul 20 07:20:36.389934 2026] [security2:error] [pid 94831:tid 95016] [client 77.110.127.138:63867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3L3AAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.390030 2026] [security2:error] [pid 94831:tid 95016] [client 77.110.127.138:63867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3L3AAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.473908 2026] [security2:error] [pid 94831:tid 95067] [client 157.20.138.62:55063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3L4gAAAGo"]
[Mon Jul 20 07:20:36.474062 2026] [security2:error] [pid 94831:tid 95067] [client 157.20.138.62:55063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3L4gAAAGo"]
[Mon Jul 20 07:20:36.647178 2026] [security2:error] [pid 94831:tid 95013] [client 77.110.127.138:63854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3L7QAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.647344 2026] [security2:error] [pid 94831:tid 95013] [client 77.110.127.138:63854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3L7QAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.680702 2026] [security2:error] [pid 94831:tid 95084] [client 143.44.185.218:10655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3L8wAAAHs"]
[Mon Jul 20 07:20:36.680826 2026] [security2:error] [pid 94831:tid 95084] [client 143.44.185.218:10655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3L8wAAAHs"]
[Mon Jul 20 07:20:36.770977 2026] [security2:error] [pid 94831:tid 95075] [client 36.93.152.155:51683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3MAAAAAHI"]
[Mon Jul 20 07:20:36.771111 2026] [security2:error] [pid 94831:tid 95075] [client 36.93.152.155:51683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3MAAAAAHI"]
[Mon Jul 20 07:20:36.809149 2026] [security2:error] [pid 94831:tid 94963] [client 14.225.17.146:55159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4goo06NaEKF1g_MW3LXAAAAAI"], referer: http://savilerowtravel.com/2018
[Mon Jul 20 07:20:36.815467 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3MCAAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.815562 2026] [security2:error] [pid 94831:tid 95080] [client 77.110.127.138:63872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpI06NaEKF1g_MW3MCAAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:36.883185 2026] [security2:error] [pid 94831:tid 95068] [client 14.225.17.146:56947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4gpI06NaEKF1g_MW3L9gAAAGs"], referer: http://careysheatingandcooling.com/2018
[Mon Jul 20 07:20:36.958577 2026] [security2:error] [pid 94831:tid 94981] [client 191.202.66.27:56209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3MEAAAABQ"]
[Mon Jul 20 07:20:36.958702 2026] [security2:error] [pid 94831:tid 94981] [client 191.202.66.27:56209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gpI06NaEKF1g_MW3MEAAAABQ"]
[Mon Jul 20 07:20:37.062422 2026] [security2:error] [pid 94831:tid 94949] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gpY06NaEKF1g_MW3MGwAAHXU"]
[Mon Jul 20 07:20:37.062580 2026] [security2:error] [pid 94831:tid 94990] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gpY06NaEKF1g_MW3MGwAAHXU"]
[Mon Jul 20 07:20:37.291796 2026] [security2:error] [pid 94831:tid 95021] [client 74.208.214.194:44902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4gpY06NaEKF1g_MW3MLQAAADw"]
[Mon Jul 20 07:20:37.612514 2026] [security2:error] [pid 94831:tid 94967] [client 77.110.127.138:63873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpY06NaEKF1g_MW3MQgAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:37.612604 2026] [security2:error] [pid 94831:tid 94967] [client 77.110.127.138:63873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpY06NaEKF1g_MW3MQgAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:37.614526 2026] [security2:error] [pid 94831:tid 94872] [remote 182.77.62.24:42312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4gpY06NaEKF1g_MW3MQAAAJCg"]
[Mon Jul 20 07:20:37.687117 2026] [security2:error] [pid 94831:tid 95002] [client 57.141.18.44:43178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4goI06NaEKF1g_MW3KrAAAKVw"]
[Mon Jul 20 07:20:37.734562 2026] [security2:error] [pid 94831:tid 94929] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4gpY06NaEKF1g_MW3MUQAAGGE"]
[Mon Jul 20 07:20:37.767360 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpY06NaEKF1g_MW3MVQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:37.767490 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:63857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpY06NaEKF1g_MW3MVQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.072688 2026] [security2:error] [pid 94831:tid 94977] [client 45.157.112.60:28705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gpo06NaEKF1g_MW3MawAAABA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:20:38.102401 2026] [security2:error] [pid 94831:tid 95024] [client 77.110.127.138:63877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MbAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.102495 2026] [security2:error] [pid 94831:tid 95024] [client 77.110.127.138:63877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MbAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.117894 2026] [security2:error] [pid 94831:tid 94884] [remote 182.77.62.24:42312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4gpo06NaEKF1g_MW3MbQAAZjQ"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:20:38.251859 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:63879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MeQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.251999 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:63879] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MeQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.297204 2026] [security2:error] [pid 94831:tid 94833] [remote 57.141.18.87:57290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4gpo06NaEKF1g_MW3MfQAARgE"]
[Mon Jul 20 07:20:38.496307 2026] [security2:error] [pid 94831:tid 94975] [client 103.106.165.44:59896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gpo06NaEKF1g_MW3MjwAAAA4"]
[Mon Jul 20 07:20:38.496462 2026] [security2:error] [pid 94831:tid 94975] [client 103.106.165.44:59896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gpo06NaEKF1g_MW3MjwAAAA4"]
[Mon Jul 20 07:20:38.501543 2026] [security2:error] [pid 94831:tid 95038] [client 77.110.127.138:63880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MkAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.501638 2026] [security2:error] [pid 94831:tid 95038] [client 77.110.127.138:63880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MkAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.535107 2026] [security2:error] [pid 94831:tid 94869] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4gpo06NaEKF1g_MW3MlAAAYiU"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 07:20:38.632040 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:63847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MnwAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.632151 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:63847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MnwAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.718860 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MqgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.718970 2026] [security2:error] [pid 94831:tid 95057] [client 77.110.127.138:63810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MqgAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.772353 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MrwAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.772545 2026] [security2:error] [pid 94831:tid 95065] [client 77.110.127.138:63865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MrwAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.839081 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MuAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.839204 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:63853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gpo06NaEKF1g_MW3MuAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:38.966140 2026] [security2:error] [pid 94831:tid 95050] [client 45.66.35.37:52802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gpo06NaEKF1g_MW3MwQAAAFk"]
[Mon Jul 20 07:20:39.035136 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:63883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3MxAAAACg"]
[Mon Jul 20 07:20:39.035229 2026] [security2:error] [pid 94831:tid 95001] [client 77.110.127.138:63883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3MxAAAACg"]
[Mon Jul 20 07:20:39.056583 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3MxwAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.056690 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3MxwAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.140723 2026] [security2:error] [pid 94831:tid 95027] [client 216.73.216.223:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "makeupyourskin.com"] [uri "/index.php"] [unique_id "al4go406NaEKF1g_MW3LrAAAQhs"]
[Mon Jul 20 07:20:39.207768 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:63886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3M0AAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.207860 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:63886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3M0AAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.324978 2026] [core:error] [pid 94831:tid 95080] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:39.324998 2026] [core:error] [pid 94831:tid 95080] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:39.404767 2026] [security2:error] [pid 94831:tid 95034] [client 187.16.64.216:62644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gp406NaEKF1g_MW3M5wAAAEk"]
[Mon Jul 20 07:20:39.404876 2026] [security2:error] [pid 94831:tid 95034] [client 187.16.64.216:62644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gp406NaEKF1g_MW3M5wAAAEk"]
[Mon Jul 20 07:20:39.417193 2026] [security2:error] [pid 94831:tid 94984] [client 57.141.18.115:47210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4goo06NaEKF1g_MW3LPgAAFxw"]
[Mon Jul 20 07:20:39.597043 2026] [security2:error] [pid 94831:tid 95005] [client 178.156.185.231:21732] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4gp406NaEKF1g_MW3M8gAAACw"], referer: https://windowtx.com
[Mon Jul 20 07:20:39.601396 2026] [security2:error] [pid 94831:tid 95045] [client 77.110.127.138:63876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3M8wAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.601533 2026] [security2:error] [pid 94831:tid 95045] [client 77.110.127.138:63876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3M8wAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.642695 2026] [security2:error] [pid 94831:tid 94976] [client 154.192.123.127:17866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gp406NaEKF1g_MW3M9wAAAA8"]
[Mon Jul 20 07:20:39.642832 2026] [security2:error] [pid 94831:tid 94976] [client 154.192.123.127:17866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gp406NaEKF1g_MW3M9wAAAA8"]
[Mon Jul 20 07:20:39.760050 2026] [security2:error] [pid 94831:tid 95043] [client 213.111.158.220:49226] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "omegacompass.com"] [uri "/"] [unique_id "al4gp406NaEKF1g_MW3NAwAAAFI"]
[Mon Jul 20 07:20:39.760657 2026] [security2:error] [pid 94831:tid 94973] [client 77.110.127.138:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3NBQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.760757 2026] [security2:error] [pid 94831:tid 94973] [client 77.110.127.138:63890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3NBQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.833228 2026] [security2:error] [pid 94831:tid 94877] [remote 57.141.18.8:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4gp406NaEKF1g_MW3NDQAAAS0"]
[Mon Jul 20 07:20:39.845363 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:63878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3NDgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.845475 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:63878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gp406NaEKF1g_MW3NDgAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:39.935816 2026] [security2:error] [pid 94831:tid 95003] [client 201.27.111.74:62502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gp406NaEKF1g_MW3NEwAAACo"]
[Mon Jul 20 07:20:39.939846 2026] [security2:error] [pid 94831:tid 95003] [client 201.27.111.74:62502] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gp406NaEKF1g_MW3NEwAAACo"]
[Mon Jul 20 07:20:39.961148 2026] [security2:error] [pid 94831:tid 95032] [client 57.141.18.55:44548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4go406NaEKF1g_MW3LbAAAR0I"]
[Mon Jul 20 07:20:40.013926 2026] [security2:error] [pid 94831:tid 94975] [client 77.110.127.138:63891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqI06NaEKF1g_MW3NGQAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:40.014024 2026] [security2:error] [pid 94831:tid 94975] [client 77.110.127.138:63891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqI06NaEKF1g_MW3NGQAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:40.156648 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqI06NaEKF1g_MW3NIAAAAAk"]
[Mon Jul 20 07:20:40.156745 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63892] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqI06NaEKF1g_MW3NIAAAAAk"]
[Mon Jul 20 07:20:40.164943 2026] [security2:error] [pid 94831:tid 94902] [remote 57.141.18.3:22534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4gqI06NaEKF1g_MW3NHwAALEY"]
[Mon Jul 20 07:20:40.181847 2026] [security2:error] [pid 94831:tid 95057] [client 158.173.89.95:33411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gqI06NaEKF1g_MW3NIwAAAGA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:20:40.199515 2026] [security2:error] [pid 94831:tid 95074] [client 14.225.17.146:58158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4gpo06NaEKF1g_MW3MkwAAAHE"], referer: http://according2plant.com/2018
[Mon Jul 20 07:20:40.317337 2026] [security2:error] [pid 94831:tid 94873] [remote 20.153.140.50:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4gqI06NaEKF1g_MW3NLgAAEik"]
[Mon Jul 20 07:20:40.629801 2026] [security2:error] [pid 94831:tid 95052] [client 77.110.127.138:63893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqI06NaEKF1g_MW3NQAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:40.629893 2026] [security2:error] [pid 94831:tid 95052] [client 77.110.127.138:63893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqI06NaEKF1g_MW3NQAAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:40.847708 2026] [security2:error] [pid 94831:tid 94837] [remote 20.153.140.50:48494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4gqI06NaEKF1g_MW3NWwAADwU"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:20:41.037227 2026] [security2:error] [pid 94831:tid 95053] [client 77.110.127.138:63882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqY06NaEKF1g_MW3NZgAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:41.037357 2026] [security2:error] [pid 94831:tid 95053] [client 77.110.127.138:63882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gqY06NaEKF1g_MW3NZgAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:41.092676 2026] [security2:error] [pid 94831:tid 95030] [client 154.208.48.130:58916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gqY06NaEKF1g_MW3NaAAAAEU"]
[Mon Jul 20 07:20:41.093499 2026] [security2:error] [pid 94831:tid 95030] [client 154.208.48.130:58916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gqY06NaEKF1g_MW3NaAAAAEU"]
[Mon Jul 20 07:20:41.403323 2026] [security2:error] [pid 94831:tid 95023] [client 57.141.18.67:59870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gpI06NaEKF1g_MW3MDQAAPl0"]
[Mon Jul 20 07:20:41.744766 2026] [core:error] [pid 94831:tid 95031] [client 23.137.105.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:41.744789 2026] [core:error] [pid 94831:tid 95031] [client 23.137.105.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:41.837157 2026] [security2:error] [pid 94831:tid 94990] [client 14.225.17.146:58159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4gqY06NaEKF1g_MW3NnAAAAB0"], referer: http://bbwipartnerconference.com/2018
[Mon Jul 20 07:20:41.880332 2026] [security2:error] [pid 94831:tid 95008] [client 117.211.236.168:51587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gqY06NaEKF1g_MW3NrgAAAC8"]
[Mon Jul 20 07:20:41.880409 2026] [security2:error] [pid 94831:tid 95008] [client 117.211.236.168:51587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gqY06NaEKF1g_MW3NrgAAAC8"]
[Mon Jul 20 07:20:42.079737 2026] [security2:error] [pid 94831:tid 94996] [client 52.109.0.142:2753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gqo06NaEKF1g_MW3NuwAAACM"]
[Mon Jul 20 07:20:42.099402 2026] [security2:error] [pid 94831:tid 95014] [client 52.109.0.142:2753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gqo06NaEKF1g_MW3NvQAAADU"]
[Mon Jul 20 07:20:42.150839 2026] [security2:error] [pid 94831:tid 94940] [remote 45.90.123.233:44972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gqo06NaEKF1g_MW3NvwAACWw"]
[Mon Jul 20 07:20:42.396575 2026] [security2:error] [pid 94831:tid 94846] [remote 45.90.123.233:44972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gqo06NaEKF1g_MW3NzQAAAg4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:20:42.741458 2026] [security2:error] [pid 94831:tid 95087] [client 57.141.18.54:41256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gpo06NaEKF1g_MW3MiAAAflA"]
[Mon Jul 20 07:20:42.910887 2026] [security2:error] [pid 94831:tid 95059] [client 34.239.87.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4gqo06NaEKF1g_MW3N5gAAYio"]
[Mon Jul 20 07:20:43.018304 2026] [security2:error] [pid 94831:tid 94980] [client 57.141.18.89:23692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gpo06NaEKF1g_MW3MmwAAEzc"]
[Mon Jul 20 07:20:43.135577 2026] [core:error] [pid 94831:tid 95064] [client 23.137.105.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:43.135599 2026] [core:error] [pid 94831:tid 95064] [client 23.137.105.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:43.144284 2026] [core:error] [pid 94831:tid 95010] [client 23.137.105.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:43.144305 2026] [core:error] [pid 94831:tid 95010] [client 23.137.105.171:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:43.170721 2026] [security2:error] [pid 94831:tid 95057] [client 103.144.65.217:59657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gq406NaEKF1g_MW3OFwAAAGA"]
[Mon Jul 20 07:20:43.171075 2026] [security2:error] [pid 94831:tid 95057] [client 103.144.65.217:59657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gq406NaEKF1g_MW3OFwAAAGA"]
[Mon Jul 20 07:20:43.400165 2026] [security2:error] [pid 94831:tid 95001] [client 121.229.156.117:50386] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cira.org"] [uri "/"] [unique_id "al4gq406NaEKF1g_MW3OKgAAACg"]
[Mon Jul 20 07:20:43.400262 2026] [security2:error] [pid 94831:tid 95001] [client 121.229.156.117:50386] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cira.org"] [uri "/"] [unique_id "al4gq406NaEKF1g_MW3OKgAAACg"]
[Mon Jul 20 07:20:43.694899 2026] [security2:error] [pid 94831:tid 94885] [remote 188.166.241.141:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4gq406NaEKF1g_MW3ONgAAEDU"]
[Mon Jul 20 07:20:43.957233 2026] [security2:error] [pid 94831:tid 94970] [client 152.58.191.142:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.191.58.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4gq406NaEKF1g_MW3OTQAAAAk"]
[Mon Jul 20 07:20:43.957319 2026] [security2:error] [pid 94831:tid 94970] [client 152.58.191.142:52062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ncsynchro.com"] [uri "/xmlrpc.php"] [unique_id "al4gq406NaEKF1g_MW3OTQAAAAk"]
[Mon Jul 20 07:20:44.056580 2026] [security2:error] [pid 94831:tid 94895] [remote 188.166.241.141:39258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4grI06NaEKF1g_MW3OVwAART8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:20:44.058728 2026] [security2:error] [pid 94831:tid 95082] [client 202.141.11.99:22134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4grI06NaEKF1g_MW3OWAAAAHk"]
[Mon Jul 20 07:20:44.058827 2026] [security2:error] [pid 94831:tid 95082] [client 202.141.11.99:22134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4grI06NaEKF1g_MW3OWAAAAHk"]
[Mon Jul 20 07:20:44.137357 2026] [security2:error] [pid 94831:tid 94973] [client 172.200.24.58:16995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4grI06NaEKF1g_MW3OXQAAAAw"]
[Mon Jul 20 07:20:44.198112 2026] [security2:error] [pid 94831:tid 95012] [client 172.200.24.58:16995] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4grI06NaEKF1g_MW3OYgAAADM"]
[Mon Jul 20 07:20:44.855191 2026] [security2:error] [pid 94831:tid 95010] [client 77.110.127.138:63902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grI06NaEKF1g_MW3OtwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:44.855272 2026] [security2:error] [pid 94831:tid 95010] [client 77.110.127.138:63902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grI06NaEKF1g_MW3OtwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:44.862021 2026] [security2:error] [pid 94831:tid 94991] [client 77.110.127.138:63905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grI06NaEKF1g_MW3OuQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:44.862096 2026] [security2:error] [pid 94831:tid 94991] [client 77.110.127.138:63905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grI06NaEKF1g_MW3OuQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:44.963130 2026] [security2:error] [pid 94831:tid 95005] [client 57.141.18.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4grI06NaEKF1g_MW3OsQAAACw"]
[Mon Jul 20 07:20:45.047405 2026] [security2:error] [pid 94831:tid 95013] [client 77.110.127.138:63910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grY06NaEKF1g_MW3OzgAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:45.047533 2026] [security2:error] [pid 94831:tid 95013] [client 77.110.127.138:63910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grY06NaEKF1g_MW3OzgAAADQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:45.084984 2026] [security2:error] [pid 94831:tid 95064] [client 77.110.127.138:63911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grY06NaEKF1g_MW3O1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:45.085079 2026] [security2:error] [pid 94831:tid 95064] [client 77.110.127.138:63911] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4grY06NaEKF1g_MW3O1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:45.125554 2026] [security2:error] [pid 94831:tid 95054] [client 14.182.195.220:52663] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4grY06NaEKF1g_MW3O2wAAAF0"]
[Mon Jul 20 07:20:45.127500 2026] [security2:error] [pid 94831:tid 95053] [client 14.182.195.220:52664] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4grY06NaEKF1g_MW3O3AAAAFw"]
[Mon Jul 20 07:20:45.130802 2026] [security2:error] [pid 94831:tid 95018] [client 14.182.195.220:52662] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4grY06NaEKF1g_MW3O3QAAADk"]
[Mon Jul 20 07:20:45.258530 2026] [security2:error] [pid 94831:tid 95026] [client 14.225.17.146:54847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4grY06NaEKF1g_MW3O1wAAAEE"], referer: http://ironcitywellness.com/2018
[Mon Jul 20 07:20:45.264499 2026] [security2:error] [pid 94831:tid 94905] [remote 188.166.241.141:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4grY06NaEKF1g_MW3O6QAAOkk"]
[Mon Jul 20 07:20:45.429569 2026] [security2:error] [pid 94831:tid 95076] [client 104.234.53.78:33075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4grY06NaEKF1g_MW3O9gAAAHM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:45.736603 2026] [security2:error] [pid 94831:tid 94909] [remote 188.166.241.141:38316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4grY06NaEKF1g_MW3PGAAARU0"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 07:20:45.886865 2026] [fcgid:warn] [pid 94831:tid 94974] (70014)End of file found: [client 152.42.185.27:56324] mod_fcgid: can't get data from http client
[Mon Jul 20 07:20:46.021406 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:63919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gro06NaEKF1g_MW3PMgAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:46.021495 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:63919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gro06NaEKF1g_MW3PMgAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:46.032233 2026] [security2:error] [pid 94831:tid 94867] [remote 31.42.184.154:36774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.184.42.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4gro06NaEKF1g_MW3PMAAAeiM"]
[Mon Jul 20 07:20:46.214258 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:63920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gro06NaEKF1g_MW3PUAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:46.214369 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:63920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gro06NaEKF1g_MW3PUAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:46.265453 2026] [security2:error] [pid 94831:tid 94860] [remote 31.42.184.154:36774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.184.42.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4gro06NaEKF1g_MW3PUQAANxw"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 07:20:46.313217 2026] [security2:error] [pid 94831:tid 95022] [client 57.141.18.55:45164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gqY06NaEKF1g_MW3NoQAAPWg"]
[Mon Jul 20 07:20:46.368357 2026] [security2:error] [pid 94831:tid 94973] [client 98.159.234.160:25525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gro06NaEKF1g_MW3PWAAAAAw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:20:46.379115 2026] [security2:error] [pid 94831:tid 94985] [client 103.176.215.66:60436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gro06NaEKF1g_MW3PWgAAABg"]
[Mon Jul 20 07:20:46.379234 2026] [security2:error] [pid 94831:tid 94985] [client 103.176.215.66:60436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gro06NaEKF1g_MW3PWgAAABg"]
[Mon Jul 20 07:20:46.456785 2026] [security2:error] [pid 94831:tid 95078] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gro06NaEKF1g_MW3PRQAAAHU"]
[Mon Jul 20 07:20:46.459809 2026] [security2:error] [pid 94831:tid 94906] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gro06NaEKF1g_MW3PXgAAWEo"]
[Mon Jul 20 07:20:46.459983 2026] [security2:error] [pid 94831:tid 95049] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gro06NaEKF1g_MW3PXgAAWEo"]
[Mon Jul 20 07:20:46.519996 2026] [security2:error] [pid 94831:tid 94962] [client 13.232.231.177:16648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gro06NaEKF1g_MW3PYAAAAAE"]
[Mon Jul 20 07:20:46.664612 2026] [security2:error] [pid 94831:tid 95071] [client 49.47.218.174:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gro06NaEKF1g_MW3PfAAAAG4"]
[Mon Jul 20 07:20:46.665159 2026] [security2:error] [pid 94831:tid 95071] [client 49.47.218.174:55576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gro06NaEKF1g_MW3PfAAAAG4"]
[Mon Jul 20 07:20:46.831091 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gro06NaEKF1g_MW3PgAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:46.831184 2026] [security2:error] [pid 94831:tid 94982] [client 77.110.127.138:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gro06NaEKF1g_MW3PgAAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.022046 2026] [security2:error] [pid 94831:tid 95081] [client 88.241.67.160:54802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PhwAAAHg"]
[Mon Jul 20 07:20:47.022649 2026] [security2:error] [pid 94831:tid 95081] [client 88.241.67.160:54802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PhwAAAHg"]
[Mon Jul 20 07:20:47.062933 2026] [security2:error] [pid 94831:tid 95055] [client 157.20.138.62:55632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PjwAAAF4"]
[Mon Jul 20 07:20:47.063036 2026] [security2:error] [pid 94831:tid 95055] [client 157.20.138.62:55632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PjwAAAF4"]
[Mon Jul 20 07:20:47.080922 2026] [security2:error] [pid 94831:tid 94987] [client 77.110.127.138:63928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3PkgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.081010 2026] [security2:error] [pid 94831:tid 94987] [client 77.110.127.138:63928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3PkgAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.284001 2026] [security2:error] [pid 94831:tid 95045] [client 14.225.17.146:53429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4gro06NaEKF1g_MW3PNgAAAFQ"], referer: http://wathenbartlett.co.uk/2018
[Mon Jul 20 07:20:47.286471 2026] [security2:error] [pid 94831:tid 94901] [remote 57.141.18.27:45034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4297331"] [unique_id "al4gr406NaEKF1g_MW3PqAAAZ0U"]
[Mon Jul 20 07:20:47.301263 2026] [security2:error] [pid 94831:tid 94998] [client 36.93.152.155:52179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PqgAAACU"]
[Mon Jul 20 07:20:47.301340 2026] [security2:error] [pid 94831:tid 94998] [client 36.93.152.155:52179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PqgAAACU"]
[Mon Jul 20 07:20:47.323411 2026] [security2:error] [pid 94831:tid 94966] [client 49.37.242.14:57710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PrQAAAAU"]
[Mon Jul 20 07:20:47.323485 2026] [security2:error] [pid 94831:tid 94966] [client 49.37.242.14:57710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PrQAAAAU"]
[Mon Jul 20 07:20:47.333710 2026] [proxy:error] [pid 94831:tid 94981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:47.333801 2026] [proxy_http:error] [pid 94831:tid 94981] [client 205.210.31.58:58342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:47.334364 2026] [proxy:error] [pid 94831:tid 94981] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:20:47.334396 2026] [proxy_http:error] [pid 94831:tid 94981] [client 205.210.31.58:58342] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:20:47.398971 2026] [security2:error] [pid 94831:tid 94975] [client 143.44.185.218:11882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PtQAAAA4"]
[Mon Jul 20 07:20:47.399115 2026] [security2:error] [pid 94831:tid 94975] [client 143.44.185.218:11882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PtQAAAA4"]
[Mon Jul 20 07:20:47.525897 2026] [security2:error] [pid 94831:tid 95023] [client 52.109.0.142:30401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gr406NaEKF1g_MW3PwAAAAD4"]
[Mon Jul 20 07:20:47.545738 2026] [security2:error] [pid 94831:tid 95074] [client 52.109.0.142:30401] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gr406NaEKF1g_MW3PxAAAAHE"]
[Mon Jul 20 07:20:47.552004 2026] [security2:error] [pid 94831:tid 94996] [client 77.110.127.138:63934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3PxQAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.552088 2026] [security2:error] [pid 94831:tid 94996] [client 77.110.127.138:63934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3PxQAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.582575 2026] [security2:error] [pid 94831:tid 94964] [client 191.202.66.27:56680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PxwAAAAM"]
[Mon Jul 20 07:20:47.582693 2026] [security2:error] [pid 94831:tid 94964] [client 191.202.66.27:56680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3PxwAAAAM"]
[Mon Jul 20 07:20:47.632906 2026] [security2:error] [pid 94831:tid 94967] [client 43.205.139.3:19880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gr406NaEKF1g_MW3PzwAAAAY"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:20:47.651673 2026] [security2:error] [pid 94831:tid 94864] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3P0QAAYCA"]
[Mon Jul 20 07:20:47.651899 2026] [security2:error] [pid 94831:tid 95057] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gr406NaEKF1g_MW3P0QAAYCA"]
[Mon Jul 20 07:20:47.671842 2026] [security2:error] [pid 94831:tid 95042] [client 77.110.127.138:63900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P1AAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.671972 2026] [security2:error] [pid 94831:tid 95042] [client 77.110.127.138:63900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P1AAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.825708 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P4wAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.825807 2026] [security2:error] [pid 94831:tid 94981] [client 77.110.127.138:63914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P4wAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.830784 2026] [security2:error] [pid 94831:tid 95004] [client 77.110.127.138:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P5AAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.830881 2026] [security2:error] [pid 94831:tid 95004] [client 77.110.127.138:63936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P5AAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.998056 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:63937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P9QAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:47.998144 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:63937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gr406NaEKF1g_MW3P9QAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.053180 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3P-AAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.053286 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3P-AAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.116374 2026] [core:error] [pid 94831:tid 94961] [client 14.225.17.146:56762] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2018
[Mon Jul 20 07:20:48.116404 2026] [core:error] [pid 94831:tid 94961] [client 14.225.17.146:56762] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/2018
[Mon Jul 20 07:20:48.190471 2026] [security2:error] [pid 94831:tid 94975] [client 14.225.17.146:56763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4gsI06NaEKF1g_MW3QBwAAAA4"], referer: https://wathenbartlett.co.uk/2018
[Mon Jul 20 07:20:48.203651 2026] [security2:error] [pid 94831:tid 94977] [client 77.110.127.138:63941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3QEQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.203788 2026] [security2:error] [pid 94831:tid 94977] [client 77.110.127.138:63941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3QEQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.280426 2026] [security2:error] [pid 94831:tid 95059] [client 200.104.71.234:45738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4gro06NaEKF1g_MW3PgwAAYkI"]
[Mon Jul 20 07:20:48.288060 2026] [security2:error] [pid 94831:tid 95017] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gr406NaEKF1g_MW3P9AAAADg"]
[Mon Jul 20 07:20:48.364505 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:63943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3QIAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.364607 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:63943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3QIAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.637983 2026] [security2:error] [pid 94831:tid 95002] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gsI06NaEKF1g_MW3QLAAAACk"]
[Mon Jul 20 07:20:48.837190 2026] [security2:error] [pid 94831:tid 95082] [client 77.110.127.138:63944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3QRQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.837271 2026] [security2:error] [pid 94831:tid 95082] [client 77.110.127.138:63944] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsI06NaEKF1g_MW3QRQAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:48.933717 2026] [security2:error] [pid 94831:tid 94963] [client 34.208.80.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4gr406NaEKF1g_MW3PlQAAAAI"]
[Mon Jul 20 07:20:48.936032 2026] [security2:error] [pid 94831:tid 95052] [client 34.208.80.94:37166] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/"] [unique_id "al4gr406NaEKF1g_MW3PkAAAAFs"]
[Mon Jul 20 07:20:48.987259 2026] [security2:error] [pid 94831:tid 94983] [client 103.106.165.44:60348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gsI06NaEKF1g_MW3QUgAAABY"]
[Mon Jul 20 07:20:48.987345 2026] [security2:error] [pid 94831:tid 94983] [client 103.106.165.44:60348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gsI06NaEKF1g_MW3QUgAAABY"]
[Mon Jul 20 07:20:49.125917 2026] [security2:error] [pid 94831:tid 95038] [client 14.225.17.146:54810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4gsI06NaEKF1g_MW3QTAAAAE0"], referer: http://maplerespiteservices.com/2018
[Mon Jul 20 07:20:49.212601 2026] [security2:error] [pid 94831:tid 95027] [client 77.110.127.138:63929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QXgAAAEI"]
[Mon Jul 20 07:20:49.212686 2026] [security2:error] [pid 94831:tid 95027] [client 77.110.127.138:63929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QXgAAAEI"]
[Mon Jul 20 07:20:49.375094 2026] [security2:error] [pid 94831:tid 95083] [client 34.208.80.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4gsY06NaEKF1g_MW3QWwAAAHo"]
[Mon Jul 20 07:20:49.378716 2026] [security2:error] [pid 94831:tid 95023] [client 34.208.80.94:55568] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4gsY06NaEKF1g_MW3QVwAAAD4"]
[Mon Jul 20 07:20:49.383829 2026] [security2:error] [pid 94831:tid 94973] [client 77.110.127.138:63949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QbwAAAAw"]
[Mon Jul 20 07:20:49.383958 2026] [security2:error] [pid 94831:tid 94973] [client 77.110.127.138:63949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QbwAAAAw"]
[Mon Jul 20 07:20:49.469091 2026] [security2:error] [pid 94831:tid 95084] [client 77.110.127.138:63950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QdAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:49.469220 2026] [security2:error] [pid 94831:tid 95084] [client 77.110.127.138:63950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QdAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:49.478356 2026] [security2:error] [pid 94831:tid 95003] [client 182.253.110.82:59308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.hedgerow-crafts.com"] [uri "/index.php"] [unique_id "al4gsY06NaEKF1g_MW3QVQAAACo"]
[Mon Jul 20 07:20:49.581589 2026] [security2:error] [pid 94831:tid 95025] [client 77.110.127.138:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QeQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:49.581711 2026] [security2:error] [pid 94831:tid 95025] [client 77.110.127.138:63951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gsY06NaEKF1g_MW3QeQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:49.683347 2026] [security2:error] [pid 94831:tid 95061] [client 14.225.17.146:56767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4gsI06NaEKF1g_MW3QCgAAAGQ"], referer: http://xp-design.co/2018
[Mon Jul 20 07:20:49.801014 2026] [security2:error] [pid 94831:tid 95044] [client 52.109.0.142:30912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gsY06NaEKF1g_MW3QjwAAAFM"]
[Mon Jul 20 07:20:49.821477 2026] [security2:error] [pid 94831:tid 95057] [client 52.109.0.142:30912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gsY06NaEKF1g_MW3QkwAAAGA"]
[Mon Jul 20 07:20:50.102512 2026] [security2:error] [pid 94831:tid 95058] [client 57.141.18.96:56798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4grY06NaEKF1g_MW3PJgAAYTA"]
[Mon Jul 20 07:20:50.117458 2026] [security2:error] [pid 94831:tid 94995] [client 187.16.64.216:63214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gso06NaEKF1g_MW3QqwAAACI"]
[Mon Jul 20 07:20:50.117607 2026] [security2:error] [pid 94831:tid 94995] [client 187.16.64.216:63214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gso06NaEKF1g_MW3QqwAAACI"]
[Mon Jul 20 07:20:50.159546 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gso06NaEKF1g_MW3QrgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:50.159663 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gso06NaEKF1g_MW3QrgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:50.167155 2026] [security2:error] [pid 94831:tid 95087] [client 154.192.123.127:18415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gso06NaEKF1g_MW3QrwAAAH4"]
[Mon Jul 20 07:20:50.167258 2026] [security2:error] [pid 94831:tid 95087] [client 154.192.123.127:18415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gso06NaEKF1g_MW3QrwAAAH4"]
[Mon Jul 20 07:20:50.264122 2026] [security2:error] [pid 94831:tid 94978] [client 201.27.111.74:63007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gso06NaEKF1g_MW3QugAAABE"]
[Mon Jul 20 07:20:50.264247 2026] [security2:error] [pid 94831:tid 94978] [client 201.27.111.74:63007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gso06NaEKF1g_MW3QugAAABE"]
[Mon Jul 20 07:20:50.471020 2026] [security2:error] [pid 94831:tid 95030] [client 142.93.64.197:34878] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4gso06NaEKF1g_MW3QyAAAAEU"]
[Mon Jul 20 07:20:50.551522 2026] [security2:error] [pid 94831:tid 94985] [client 142.93.64.197:54140] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4gso06NaEKF1g_MW3Q0gAAABg"]
[Mon Jul 20 07:20:50.587541 2026] [security2:error] [pid 94831:tid 94899] [remote 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4gso06NaEKF1g_MW3Q1AAAP0M"]
[Mon Jul 20 07:20:50.626539 2026] [security2:error] [pid 94831:tid 95083] [client 44.225.73.253:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4gso06NaEKF1g_MW3QxgAAAHo"]
[Mon Jul 20 07:20:50.627898 2026] [security2:error] [pid 94831:tid 95027] [client 44.225.73.253:45106] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "cira.org"] [uri "/"] [unique_id "al4gso06NaEKF1g_MW3QxAAAAEI"]
[Mon Jul 20 07:20:50.790554 2026] [security2:error] [pid 94831:tid 94935] [remote 5.161.225.162:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "benbayly.co.nz"] [uri "/wp-login.php"] [unique_id "al4gso06NaEKF1g_MW3Q4QAAV2c"], referer: https://benbayly.co.nz/wp-login.php
[Mon Jul 20 07:20:50.820198 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gso06NaEKF1g_MW3Q5gAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:50.820320 2026] [security2:error] [pid 94831:tid 95088] [client 77.110.127.138:63958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gso06NaEKF1g_MW3Q5gAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:50.901556 2026] [security2:error] [pid 94831:tid 95002] [client 192.236.168.43:60886] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "website-aa114cb7.iwv.oao.mybluehost.me"] [uri "/"] [unique_id "al4gso06NaEKF1g_MW3Q8gAAACk"]
[Mon Jul 20 07:20:50.975383 2026] [security2:error] [pid 94831:tid 95068] [client 57.141.18.14:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gso06NaEKF1g_MW3Q4wAAAGs"]
[Mon Jul 20 07:20:51.143834 2026] [security2:error] [pid 94831:tid 95007] [client 45.66.35.37:52510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.35.66.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gs406NaEKF1g_MW3RCQAAAC4"]
[Mon Jul 20 07:20:51.148180 2026] [security2:error] [pid 94831:tid 94983] [client 44.225.73.253:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4gso06NaEKF1g_MW3Q8wAAABY"]
[Mon Jul 20 07:20:51.178775 2026] [security2:error] [pid 94831:tid 95044] [client 44.225.73.253:34402] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4gso06NaEKF1g_MW3Q7gAAAFM"]
[Mon Jul 20 07:20:51.351593 2026] [security2:error] [pid 94831:tid 95032] [client 14.225.17.146:63132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4gsY06NaEKF1g_MW3QdgAAAEc"], referer: http://fluidtemple.org/2018
[Mon Jul 20 07:20:51.539306 2026] [security2:error] [pid 94831:tid 95022] [client 50.116.65.227:32228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gs406NaEKF1g_MW3RLgAAAD0"]
[Mon Jul 20 07:20:51.550582 2026] [security2:error] [pid 94831:tid 94971] [client 50.116.65.227:32234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gs406NaEKF1g_MW3RLwAAAAo"]
[Mon Jul 20 07:20:52.053697 2026] [security2:error] [pid 94831:tid 95029] [client 154.208.48.130:59439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gtI06NaEKF1g_MW3RWQAAAEQ"]
[Mon Jul 20 07:20:52.053829 2026] [security2:error] [pid 94831:tid 95029] [client 154.208.48.130:59439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gtI06NaEKF1g_MW3RWQAAAEQ"]
[Mon Jul 20 07:20:52.306284 2026] [security2:error] [pid 94831:tid 95069] [client 57.141.18.19:41688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gsI06NaEKF1g_MW3QAwAAbD0"]
[Mon Jul 20 07:20:52.344094 2026] [security2:error] [pid 94831:tid 94898] [remote 160.187.68.132:56060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gtI06NaEKF1g_MW3RcQAAVkI"]
[Mon Jul 20 07:20:52.446232 2026] [security2:error] [pid 94831:tid 94980] [client 77.110.127.138:63924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RggAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.446335 2026] [security2:error] [pid 94831:tid 94980] [client 77.110.127.138:63924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RggAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.501442 2026] [security2:error] [pid 94831:tid 95036] [client 171.25.193.45:34282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.193.25.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gtI06NaEKF1g_MW3RhAAAAEs"]
[Mon Jul 20 07:20:52.528301 2026] [security2:error] [pid 94831:tid 94972] [client 14.225.17.146:54891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4gtI06NaEKF1g_MW3RgAAAAAs"], referer: http://grndl.com/2018
[Mon Jul 20 07:20:52.534883 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:63942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RjgAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.534980 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:63942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RjgAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.598427 2026] [security2:error] [pid 94831:tid 94966] [client 77.110.127.138:63970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RkQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.598530 2026] [security2:error] [pid 94831:tid 94966] [client 77.110.127.138:63970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RkQAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.678279 2026] [security2:error] [pid 94831:tid 95073] [client 77.110.127.138:63913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RlAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.678404 2026] [security2:error] [pid 94831:tid 95073] [client 77.110.127.138:63913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RlAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.700474 2026] [security2:error] [pid 94831:tid 95051] [client 57.141.18.100:36774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gsI06NaEKF1g_MW3QKwAAWnI"]
[Mon Jul 20 07:20:52.831815 2026] [security2:error] [pid 94831:tid 94886] [remote 160.187.68.132:56060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4gtI06NaEKF1g_MW3RogAARzY"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:20:52.865055 2026] [security2:error] [pid 94831:tid 94980] [client 77.110.127.138:63974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RpwAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.865134 2026] [security2:error] [pid 94831:tid 94980] [client 77.110.127.138:63974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RpwAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.869827 2026] [security2:error] [pid 94831:tid 94996] [client 77.110.127.138:63973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RqAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.869891 2026] [security2:error] [pid 94831:tid 94996] [client 77.110.127.138:63973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RqAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.950019 2026] [security2:error] [pid 94831:tid 94972] [client 77.110.127.138:63952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RrwAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:52.950115 2026] [security2:error] [pid 94831:tid 94972] [client 77.110.127.138:63952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtI06NaEKF1g_MW3RrwAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:53.103339 2026] [security2:error] [pid 94831:tid 95003] [client 77.110.127.138:63978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtY06NaEKF1g_MW3RuAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:53.103476 2026] [security2:error] [pid 94831:tid 95003] [client 77.110.127.138:63978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gtY06NaEKF1g_MW3RuAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:53.186446 2026] [security2:error] [pid 94831:tid 94983] [client 14.225.17.146:63215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4gs406NaEKF1g_MW3RUgAAABY"], referer: http://whiteoutcb.com/2018
[Mon Jul 20 07:20:53.557682 2026] [security2:error] [pid 94831:tid 95043] [client 14.182.195.220:52666] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4gtY06NaEKF1g_MW3R2wAAAFI"]
[Mon Jul 20 07:20:53.570202 2026] [security2:error] [pid 94831:tid 94988] [client 57.141.18.66:24152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gsY06NaEKF1g_MW3QagAAGwE"]
[Mon Jul 20 07:20:53.595189 2026] [security2:error] [pid 94831:tid 95022] [client 14.182.195.220:52668] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4gtY06NaEKF1g_MW3R4AAAAD0"]
[Mon Jul 20 07:20:53.597536 2026] [security2:error] [pid 94831:tid 95028] [client 14.182.195.220:52667] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4gtY06NaEKF1g_MW3R4QAAAEM"]
[Mon Jul 20 07:20:53.745043 2026] [security2:error] [pid 94831:tid 95040] [client 103.144.65.217:60119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gtY06NaEKF1g_MW3R6wAAAE8"]
[Mon Jul 20 07:20:53.745172 2026] [security2:error] [pid 94831:tid 95040] [client 103.144.65.217:60119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gtY06NaEKF1g_MW3R6wAAAE8"]
[Mon Jul 20 07:20:53.968950 2026] [security2:error] [pid 94831:tid 95042] [client 57.141.18.60:27890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gsY06NaEKF1g_MW3QjAAAUQQ"]
[Mon Jul 20 07:20:53.987961 2026] [security2:error] [pid 94831:tid 95083] [client 14.225.17.146:49372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4gtY06NaEKF1g_MW3R7gAAAHo"], referer: https://north-woods-engineering.com/2018
[Mon Jul 20 07:20:54.122098 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:63982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gto06NaEKF1g_MW3SEAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.122193 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:63982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gto06NaEKF1g_MW3SEAAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.193318 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gto06NaEKF1g_MW3SFgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.193417 2026] [security2:error] [pid 94831:tid 94970] [client 77.110.127.138:63983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gto06NaEKF1g_MW3SFgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.635678 2026] [security2:error] [pid 94831:tid 95016] [client 77.110.127.138:63988] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gto06NaEKF1g_MW3SLwAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.727740 2026] [security2:error] [pid 94831:tid 95050] [client 20.104.96.117:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.104.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "makeupyourskin.online"] [uri "/.well-known/about.php"] [unique_id "al4gto06NaEKF1g_MW3SNwAAAFk"]
[Mon Jul 20 07:20:54.727863 2026] [security2:error] [pid 94831:tid 95050] [client 20.104.96.117:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "makeupyourskin.online"] [uri "/.well-known/about.php"] [unique_id "al4gto06NaEKF1g_MW3SNwAAAFk"]
[Mon Jul 20 07:20:54.776461 2026] [security2:error] [pid 94831:tid 95011] [client 57.141.18.28:29932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gso06NaEKF1g_MW3Q0QAAMko"]
[Mon Jul 20 07:20:54.847139 2026] [security2:error] [pid 94831:tid 95088] [client 202.141.11.99:55380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gto06NaEKF1g_MW3SQgAAAH8"]
[Mon Jul 20 07:20:54.847232 2026] [security2:error] [pid 94831:tid 95088] [client 202.141.11.99:55380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4gto06NaEKF1g_MW3SQgAAAH8"]
[Mon Jul 20 07:20:54.870570 2026] [security2:error] [pid 94831:tid 95082] [client 77.110.127.138:63989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gto06NaEKF1g_MW3SRgAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.870645 2026] [security2:error] [pid 94831:tid 95082] [client 77.110.127.138:63989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gto06NaEKF1g_MW3SRgAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:54.904658 2026] [core:error] [pid 94831:tid 95085] [client 198.235.24.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:54.904682 2026] [core:error] [pid 94831:tid 95085] [client 198.235.24.161:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:20:54.963791 2026] [security2:error] [pid 94831:tid 94877] [remote 57.141.18.87:46754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4gto06NaEKF1g_MW3SUQAAdy0"]
[Mon Jul 20 07:20:55.039219 2026] [security2:error] [pid 94831:tid 95068] [client 117.211.236.168:52176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gt406NaEKF1g_MW3SWQAAAGs"]
[Mon Jul 20 07:20:55.039343 2026] [security2:error] [pid 94831:tid 95068] [client 117.211.236.168:52176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gt406NaEKF1g_MW3SWQAAAGs"]
[Mon Jul 20 07:20:55.214091 2026] [security2:error] [pid 94831:tid 95020] [client 114.119.154.82:62325] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.almadisplay.ca"] [uri "/robots.txt"] [unique_id "al4gt406NaEKF1g_MW3SZwAAADs"], referer: https://www.almadisplay.ca/robots.txt
[Mon Jul 20 07:20:55.391538 2026] [security2:error] [pid 94831:tid 95052] [client 77.110.127.138:63939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gt406NaEKF1g_MW3ScgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:55.391634 2026] [security2:error] [pid 94831:tid 95052] [client 77.110.127.138:63939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gt406NaEKF1g_MW3ScgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:55.727706 2026] [security2:error] [pid 94831:tid 94861] [remote 45.90.123.233:53788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gt406NaEKF1g_MW3SjgAALR0"]
[Mon Jul 20 07:20:55.734652 2026] [security2:error] [pid 94831:tid 94999] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4gto06NaEKF1g_MW3SEQAAJho"], referer: http://ali-alghanim.net/2018
[Mon Jul 20 07:20:55.940064 2026] [security2:error] [pid 94831:tid 94868] [remote 45.90.123.233:53788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gt406NaEKF1g_MW3SnwAALyQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:20:55.988859 2026] [security2:error] [pid 94831:tid 94981] [client 57.141.18.61:31378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gs406NaEKF1g_MW3RQAAAFGY"]
[Mon Jul 20 07:20:56.060116 2026] [security2:error] [pid 94831:tid 95016] [client 14.225.17.146:54974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4gt406NaEKF1g_MW3SmQAAADc"], referer: http://carolinapressurewashers.com/2018
[Mon Jul 20 07:20:56.175908 2026] [security2:error] [pid 94831:tid 95020] [client 104.234.53.51:30087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4guI06NaEKF1g_MW3SsQAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:56.375800 2026] [security2:error] [pid 94831:tid 94907] [remote 154.66.198.148:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4guI06NaEKF1g_MW3SvwAAS0s"]
[Mon Jul 20 07:20:56.778103 2026] [security2:error] [pid 94831:tid 95061] [client 77.110.127.138:63976] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4guI06NaEKF1g_MW3S2AAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:56.928048 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4guI06NaEKF1g_MW3S4gAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:56.928169 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4guI06NaEKF1g_MW3S4gAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:56.973722 2026] [security2:error] [pid 94831:tid 95029] [client 103.176.215.66:60961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4guI06NaEKF1g_MW3S6QAAAEQ"]
[Mon Jul 20 07:20:56.974604 2026] [security2:error] [pid 94831:tid 95029] [client 103.176.215.66:60961] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4guI06NaEKF1g_MW3S6QAAAEQ"]
[Mon Jul 20 07:20:57.030667 2026] [security2:error] [pid 94831:tid 94862] [remote 154.66.198.148:48244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4guY06NaEKF1g_MW3S7QAAJx4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:20:57.091469 2026] [security2:error] [pid 94831:tid 94964] [client 49.47.218.174:56094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3S8QAAAAM"]
[Mon Jul 20 07:20:57.091575 2026] [security2:error] [pid 94831:tid 94964] [client 49.47.218.174:56094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3S8QAAAAM"]
[Mon Jul 20 07:20:57.118837 2026] [security2:error] [pid 94831:tid 95069] [client 77.110.127.138:64004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4guY06NaEKF1g_MW3S9AAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:57.118924 2026] [security2:error] [pid 94831:tid 95069] [client 77.110.127.138:64004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4guY06NaEKF1g_MW3S9AAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:57.143853 2026] [security2:error] [pid 94831:tid 94940] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3S9wAASmw"]
[Mon Jul 20 07:20:57.144034 2026] [security2:error] [pid 94831:tid 95035] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3S9wAASmw"]
[Mon Jul 20 07:20:57.170073 2026] [security2:error] [pid 94831:tid 95038] [client 14.225.17.146:54997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4gt406NaEKF1g_MW3SmAAAAE0"], referer: http://alaraycreative.com/2018
[Mon Jul 20 07:20:57.277282 2026] [security2:error] [pid 94831:tid 94985] [client 77.110.127.138:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4guY06NaEKF1g_MW3TBwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:57.277431 2026] [security2:error] [pid 94831:tid 94985] [client 77.110.127.138:64007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4guY06NaEKF1g_MW3TBwAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:20:57.279705 2026] [security2:error] [pid 94831:tid 94995] [client 57.141.18.91:58804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gtY06NaEKF1g_MW3RtwAAIjM"]
[Mon Jul 20 07:20:57.324581 2026] [security2:error] [pid 94831:tid 94990] [client 104.234.53.57:60435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4guY06NaEKF1g_MW3TCQAAAB0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:20:57.516744 2026] [security2:error] [pid 94831:tid 95063] [client 157.20.138.62:56198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3TFgAAAGY"]
[Mon Jul 20 07:20:57.516848 2026] [security2:error] [pid 94831:tid 95063] [client 157.20.138.62:56198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3TFgAAAGY"]
[Mon Jul 20 07:20:57.600951 2026] [security2:error] [pid 94831:tid 95025] [client 88.241.67.160:53809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3TGgAAAEA"]
[Mon Jul 20 07:20:57.601402 2026] [security2:error] [pid 94831:tid 95025] [client 88.241.67.160:53809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3TGgAAAEA"]
[Mon Jul 20 07:20:57.837410 2026] [security2:error] [pid 94831:tid 95014] [client 36.93.152.155:52710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3TKwAAADU"]
[Mon Jul 20 07:20:57.837506 2026] [security2:error] [pid 94831:tid 95014] [client 36.93.152.155:52710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4guY06NaEKF1g_MW3TKwAAADU"]
[Mon Jul 20 07:20:57.952036 2026] [security2:error] [pid 94831:tid 94978] [client 14.225.17.146:57246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4guI06NaEKF1g_MW3SqgAAABE"], referer: http://samdothan.org/2018
[Mon Jul 20 07:20:58.062453 2026] [security2:error] [pid 94831:tid 95067] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4guY06NaEKF1g_MW3TNgAAAGo"]
[Mon Jul 20 07:20:58.129273 2026] [security2:error] [pid 94831:tid 95070] [client 191.202.66.27:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4guo06NaEKF1g_MW3TSgAAAG0"]
[Mon Jul 20 07:20:58.129388 2026] [security2:error] [pid 94831:tid 95070] [client 191.202.66.27:57156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4guo06NaEKF1g_MW3TSgAAAG0"]
[Mon Jul 20 07:20:58.169427 2026] [security2:error] [pid 94831:tid 95085] [client 143.44.185.218:13129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4guo06NaEKF1g_MW3TSwAAAHw"]
[Mon Jul 20 07:20:58.169607 2026] [security2:error] [pid 94831:tid 95085] [client 143.44.185.218:13129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4guo06NaEKF1g_MW3TSwAAAHw"]
[Mon Jul 20 07:20:58.320322 2026] [security2:error] [pid 94831:tid 94857] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4guo06NaEKF1g_MW3TXAAAMBk"]
[Mon Jul 20 07:20:58.320459 2026] [security2:error] [pid 94831:tid 95009] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4guo06NaEKF1g_MW3TXAAAMBk"]
[Mon Jul 20 07:20:58.431714 2026] [security2:error] [pid 94831:tid 95058] [client 15.204.254.129:52478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.254.204.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jennylouraya.com"] [uri "/wp-login.php"] [unique_id "al4guo06NaEKF1g_MW3TYgAAAGE"]
[Mon Jul 20 07:20:58.557164 2026] [security2:error] [pid 94831:tid 95002] [client 171.25.193.45:42928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.193.25.171.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4guo06NaEKF1g_MW3TagAAACk"]
[Mon Jul 20 07:20:58.673623 2026] [security2:error] [pid 94831:tid 95049] [client 15.204.254.129:52492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.254.204.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jennylouraya.com"] [uri "/administrator/index.php"] [unique_id "al4guo06NaEKF1g_MW3TbQAAAFg"]
[Mon Jul 20 07:20:58.828220 2026] [security2:error] [pid 94831:tid 95020] [client 15.204.254.129:52506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.254.204.15.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jennylouraya.com"] [uri "/api/index.php/v1/config/application"] [unique_id "al4guo06NaEKF1g_MW3TewAAADs"]
[Mon Jul 20 07:20:58.845613 2026] [security2:error] [pid 94831:tid 95044] [client 57.141.18.14:51836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gto06NaEKF1g_MW3SLgAAU1U"]
[Mon Jul 20 07:20:58.985642 2026] [security2:error] [pid 94831:tid 95056] [client 15.204.254.129:52520] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "jennylouraya.com"] [uri "/"] [unique_id "al4guo06NaEKF1g_MW3TgwAAAF8"]
[Mon Jul 20 07:20:59.306063 2026] [security2:error] [pid 94831:tid 95001] [client 14.225.17.146:63520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4guY06NaEKF1g_MW3TBQAAACg"], referer: http://latiendadejorge.com.gt/2018
[Mon Jul 20 07:20:59.629411 2026] [security2:error] [pid 94831:tid 95000] [client 103.106.165.44:60813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gu406NaEKF1g_MW3TxgAAACc"]
[Mon Jul 20 07:20:59.629557 2026] [security2:error] [pid 94831:tid 95000] [client 103.106.165.44:60813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gu406NaEKF1g_MW3TxgAAACc"]
[Mon Jul 20 07:20:59.788639 2026] [security2:error] [pid 94831:tid 95074] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4gu406NaEKF1g_MW3TqwAAAHE"], referer: http://thescarystory.com/phpinfo
[Mon Jul 20 07:21:00.130283 2026] [security2:error] [pid 94831:tid 94926] [remote 81.173.115.7:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4gvI06NaEKF1g_MW3T5wAAHV4"]
[Mon Jul 20 07:21:00.328167 2026] [security2:error] [pid 94831:tid 94898] [remote 81.173.115.7:54016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4gvI06NaEKF1g_MW3T-AAAM0I"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 07:21:00.341049 2026] [security2:error] [pid 94831:tid 95048] [client 104.234.53.90:61391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gvI06NaEKF1g_MW3T-QAAAFc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:00.384245 2026] [security2:error] [pid 94831:tid 95085] [client 185.209.196.216:53414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.196.209.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "waterproofgoods.com"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UAQAAAHw"]
[Mon Jul 20 07:21:00.416351 2026] [security2:error] [pid 94831:tid 95067] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gvI06NaEKF1g_MW3T9AAAAGo"], referer: https://thescarystory.com/phpinfo
[Mon Jul 20 07:21:00.622756 2026] [security2:error] [pid 94831:tid 94992] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/phpinfo.php"] [unique_id "al4gvI06NaEKF1g_MW3UDQAAAB8"]
[Mon Jul 20 07:21:00.743544 2026] [security2:error] [pid 94831:tid 95010] [client 154.192.123.127:16910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UGQAAADE"]
[Mon Jul 20 07:21:00.743657 2026] [security2:error] [pid 94831:tid 95010] [client 154.192.123.127:16910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UGQAAADE"]
[Mon Jul 20 07:21:00.772061 2026] [security2:error] [pid 94831:tid 94996] [client 194.105.111.14:21050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4gvI06NaEKF1g_MW3UDgAAACM"]
[Mon Jul 20 07:21:00.820984 2026] [security2:error] [pid 94831:tid 95028] [client 14.225.17.146:64632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4gvI06NaEKF1g_MW3UEwAAAEM"], referer: http://headachescarpaltunnelfibromyalgia.com/2018
[Mon Jul 20 07:21:00.870733 2026] [security2:error] [pid 94831:tid 95003] [client 187.16.64.216:63786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UJgAAACo"]
[Mon Jul 20 07:21:00.870856 2026] [security2:error] [pid 94831:tid 95003] [client 187.16.64.216:63786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UJgAAACo"]
[Mon Jul 20 07:21:00.931223 2026] [security2:error] [pid 94831:tid 95079] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/test.php"] [unique_id "al4gvI06NaEKF1g_MW3UNQAAAHY"]
[Mon Jul 20 07:21:00.943566 2026] [security2:error] [pid 94831:tid 95050] [client 201.27.111.74:63516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UNwAAAFk"]
[Mon Jul 20 07:21:00.946054 2026] [security2:error] [pid 94831:tid 95050] [client 201.27.111.74:63516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gvI06NaEKF1g_MW3UNwAAAFk"]
[Mon Jul 20 07:21:01.114285 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64029] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gvY06NaEKF1g_MW3UPQAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.172826 2026] [security2:error] [pid 94831:tid 94979] [client 57.141.18.75:35458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4guY06NaEKF1g_MW3S8AAAEmE"]
[Mon Jul 20 07:21:01.289039 2026] [security2:error] [pid 94831:tid 95038] [client 77.110.127.138:64030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gvY06NaEKF1g_MW3UQwAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.289162 2026] [security2:error] [pid 94831:tid 95038] [client 77.110.127.138:64030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gvY06NaEKF1g_MW3UQwAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.297333 2026] [security2:error] [pid 94831:tid 94834] [remote 45.90.123.233:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gvY06NaEKF1g_MW3URAAASgI"]
[Mon Jul 20 07:21:01.442778 2026] [security2:error] [pid 94831:tid 95022] [client 108.174.8.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "paultoursafari.com"] [uri "/index.php"] [unique_id "al4gvI06NaEKF1g_MW3UFwAAPQ8"]
[Mon Jul 20 07:21:01.447727 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:64031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gvY06NaEKF1g_MW3UXQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.447841 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:64031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gvY06NaEKF1g_MW3UXQAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.558660 2026] [security2:error] [pid 94831:tid 95015] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4gvY06NaEKF1g_MW3UXgAAADY"], referer: http://thescarystory.com/_profiler/phpinfo
[Mon Jul 20 07:21:01.612384 2026] [security2:error] [pid 94831:tid 94998] [client 77.110.127.138:64032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gvY06NaEKF1g_MW3UagAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.612468 2026] [security2:error] [pid 94831:tid 94998] [client 77.110.127.138:64032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gvY06NaEKF1g_MW3UagAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:01.721325 2026] [security2:error] [pid 94831:tid 95064] [client 49.37.242.14:58368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gvY06NaEKF1g_MW3UbwAAAGc"]
[Mon Jul 20 07:21:01.721456 2026] [security2:error] [pid 94831:tid 95064] [client 49.37.242.14:58368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gvY06NaEKF1g_MW3UbwAAAGc"]
[Mon Jul 20 07:21:01.860480 2026] [security2:error] [pid 94831:tid 95012] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gvY06NaEKF1g_MW3UcgAAADM"], referer: https://thescarystory.com/_profiler/phpinfo
[Mon Jul 20 07:21:01.958561 2026] [core:error] [pid 94831:tid 95079] [client 14.225.17.146:49900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:01.958586 2026] [core:error] [pid 94831:tid 95079] [client 14.225.17.146:49900] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:02.189211 2026] [security2:error] [pid 94831:tid 95063] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/info.php"] [unique_id "al4gvo06NaEKF1g_MW3UmQAAAGY"]
[Mon Jul 20 07:21:02.509226 2026] [security2:error] [pid 94831:tid 95051] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/php.php"] [unique_id "al4gvo06NaEKF1g_MW3UtgAAAFo"]
[Mon Jul 20 07:21:02.621619 2026] [security2:error] [pid 94831:tid 95064] [client 136.158.60.21:54592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4gvo06NaEKF1g_MW3UuAAAAGc"]
[Mon Jul 20 07:21:02.621738 2026] [security2:error] [pid 94831:tid 95064] [client 136.158.60.21:54592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4gvo06NaEKF1g_MW3UuAAAAGc"]
[Mon Jul 20 07:21:02.823884 2026] [security2:error] [pid 94831:tid 95035] [client 144.172.114.51:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-0a92102d.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4gvo06NaEKF1g_MW3UrgAAAEo"]
[Mon Jul 20 07:21:02.857877 2026] [security2:error] [pid 94831:tid 95076] [client 196.189.144.127:29343] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4gvo06NaEKF1g_MW3UwwAAc2I"]
[Mon Jul 20 07:21:03.060866 2026] [security2:error] [pid 94831:tid 95083] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/php_info.php"] [unique_id "al4gv406NaEKF1g_MW3U4wAAAHo"]
[Mon Jul 20 07:21:03.066967 2026] [security2:error] [pid 94831:tid 95024] [client 154.208.48.130:59950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gv406NaEKF1g_MW3U5AAAAD8"]
[Mon Jul 20 07:21:03.067080 2026] [security2:error] [pid 94831:tid 95024] [client 154.208.48.130:59950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gv406NaEKF1g_MW3U5AAAAD8"]
[Mon Jul 20 07:21:03.097573 2026] [security2:error] [pid 94831:tid 95057] [client 195.2.84.198:55589] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.84.198" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "bandsir.com"] [uri "/wp-comments-post.php"] [unique_id "al4gv406NaEKF1g_MW3U6AAAAGA"], referer: http://bandsir.com/1973-1974/1973-1974-fall-concert/
[Mon Jul 20 07:21:03.275930 2026] [security2:error] [pid 94831:tid 95057] [client 195.2.84.198:55589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "bandsir.com"] [uri "/wp-comments-post.php"] [unique_id "al4gv406NaEKF1g_MW3U6AAAAGA"], referer: http://bandsir.com/1973-1974/1973-1974-fall-concert/
[Mon Jul 20 07:21:03.287802 2026] [autoindex:error] [pid 94831:tid 95025] [client 64.227.143.21:58315] AH01276: Cannot serve directory /home2/willoxv8/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:21:03.316169 2026] [security2:error] [pid 94831:tid 95074] [client 14.225.17.146:61752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4gv406NaEKF1g_MW3U6wAAAHE"], referer: http://mobilesurvsolutions.com/2018
[Mon Jul 20 07:21:03.424723 2026] [security2:error] [pid 94831:tid 95039] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/i.php"] [unique_id "al4gv406NaEKF1g_MW3VBgAAAE4"]
[Mon Jul 20 07:21:03.642100 2026] [security2:error] [pid 94831:tid 94998] [client 14.225.17.146:49806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4gv406NaEKF1g_MW3VAwAAACU"], referer: http://oldracelimited.com/2018
[Mon Jul 20 07:21:03.681582 2026] [security2:error] [pid 94831:tid 95066] [client 57.141.18.61:53646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gu406NaEKF1g_MW3TwQAAaXc"]
[Mon Jul 20 07:21:03.757639 2026] [security2:error] [pid 94831:tid 94977] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/pi.php"] [unique_id "al4gv406NaEKF1g_MW3VLAAAABA"]
[Mon Jul 20 07:21:03.780710 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:64045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gv406NaEKF1g_MW3VMQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:03.780801 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:64045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gv406NaEKF1g_MW3VMQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:03.810241 2026] [security2:error] [pid 94831:tid 95082] [client 57.141.18.24:33050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gu406NaEKF1g_MW3TwwAAeXY"]
[Mon Jul 20 07:21:03.948013 2026] [security2:error] [pid 94831:tid 95004] [client 77.110.127.138:64046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gv406NaEKF1g_MW3VRwAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:03.948119 2026] [security2:error] [pid 94831:tid 95004] [client 77.110.127.138:64046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gv406NaEKF1g_MW3VRwAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:04.010789 2026] [security2:error] [pid 94831:tid 94978] [client 14.225.17.146:49838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4gvo06NaEKF1g_MW3U1AAAABE"], referer: http://claysharecon.com/2018
[Mon Jul 20 07:21:04.141584 2026] [security2:error] [pid 94831:tid 95008] [client 2.78.60.10:44448] ModSecurity: Access denied with code 406 (phase 1). RBL lookup of 10.60.78.2.csi.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1548"] [id "900927"] [msg "contact-form RBL block: csi.websitewelcome.com"] [hostname "bandsir.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwI06NaEKF1g_MW3VWgAAAC8"], referer: http://bandsir.com/1973-1974/1973-1974-fall-concert/
[Mon Jul 20 07:21:04.141693 2026] [security2:error] [pid 94831:tid 95008] [client 2.78.60.10:44448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "bandsir.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwI06NaEKF1g_MW3VWgAAAC8"], referer: http://bandsir.com/1973-1974/1973-1974-fall-concert/
[Mon Jul 20 07:21:04.151006 2026] [security2:error] [pid 94831:tid 95070] [client 14.225.17.146:64446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4gwI06NaEKF1g_MW3VTgAAAG0"], referer: http://cloudspacesgroup.com/2018
[Mon Jul 20 07:21:04.163397 2026] [security2:error] [pid 94831:tid 94946] [remote 45.90.123.233:46054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4gwI06NaEKF1g_MW3VZAAAMXI"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 07:21:04.215567 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gwI06NaEKF1g_MW3VaAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:04.266533 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:64029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwI06NaEKF1g_MW3VcQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:04.266647 2026] [security2:error] [pid 94831:tid 94990] [client 77.110.127.138:64029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwI06NaEKF1g_MW3VcQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:04.343718 2026] [security2:error] [pid 94831:tid 95039] [client 103.144.65.217:60580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gwI06NaEKF1g_MW3VfAAAAE4"]
[Mon Jul 20 07:21:04.343832 2026] [security2:error] [pid 94831:tid 95039] [client 103.144.65.217:60580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gwI06NaEKF1g_MW3VfAAAAE4"]
[Mon Jul 20 07:21:04.389021 2026] [core:error] [pid 94831:tid 95064] [client 104.28.214.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:04.389040 2026] [core:error] [pid 94831:tid 95064] [client 104.28.214.112:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:04.841035 2026] [security2:error] [pid 94831:tid 95078] [client 57.141.18.3:52974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gvI06NaEKF1g_MW3UGgAAdVw"]
[Mon Jul 20 07:21:04.849187 2026] [security2:error] [pid 94831:tid 95041] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/admin/phpinfo.php"] [unique_id "al4gwI06NaEKF1g_MW3V6AAAAFA"]
[Mon Jul 20 07:21:04.887633 2026] [security2:error] [pid 94831:tid 95056] [client 77.110.127.138:64050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwI06NaEKF1g_MW3V7QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:04.887728 2026] [security2:error] [pid 94831:tid 95056] [client 77.110.127.138:64050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwI06NaEKF1g_MW3V7QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:05.044283 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwY06NaEKF1g_MW3V-AAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:05.044390 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwY06NaEKF1g_MW3V-AAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:05.111947 2026] [security2:error] [pid 94831:tid 95068] [client 85.204.70.92:40570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "www.thewelloiledlife.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4gwY06NaEKF1g_MW3WCwAAAGs"]
[Mon Jul 20 07:21:05.273275 2026] [security2:error] [pid 94831:tid 94893] [remote 152.228.213.32:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gwY06NaEKF1g_MW3WIgAAGz0"]
[Mon Jul 20 07:21:05.297774 2026] [security2:error] [pid 94831:tid 95003] [client 57.141.18.95:34258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gvY06NaEKF1g_MW3USAAAKjo"]
[Mon Jul 20 07:21:05.420501 2026] [security2:error] [pid 94831:tid 95054] [client 50.116.65.227:33672] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gwY06NaEKF1g_MW3WOAAAAF0"]
[Mon Jul 20 07:21:05.421297 2026] [security2:error] [pid 94831:tid 95022] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/pinfo.php"] [unique_id "al4gwY06NaEKF1g_MW3WOQAAAD0"]
[Mon Jul 20 07:21:05.431104 2026] [security2:error] [pid 94831:tid 95039] [client 50.116.65.227:33678] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gwY06NaEKF1g_MW3WOgAAAE4"]
[Mon Jul 20 07:21:05.490877 2026] [security2:error] [pid 94831:tid 94903] [remote 152.228.213.32:56344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gwY06NaEKF1g_MW3WOwAAXEc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:21:05.642967 2026] [security2:error] [pid 94831:tid 94983] [client 85.204.70.92:40580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/xmlrpc.php"] [unique_id "al4gwY06NaEKF1g_MW3WSgAAABY"]
[Mon Jul 20 07:21:05.752691 2026] [security2:error] [pid 94831:tid 95013] [client 93.152.221.13:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/php_version.php"] [unique_id "al4gwY06NaEKF1g_MW3WUgAAADQ"]
[Mon Jul 20 07:21:05.754259 2026] [security2:error] [pid 94831:tid 94875] [remote 173.249.4.11:38839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4gwY06NaEKF1g_MW3WUwAALys"]
[Mon Jul 20 07:21:05.907172 2026] [security2:error] [pid 94831:tid 95043] [client 57.141.18.14:34600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gvY06NaEKF1g_MW3UhwAAUn8"]
[Mon Jul 20 07:21:05.964900 2026] [security2:error] [pid 94831:tid 95085] [client 50.116.65.227:33700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gwY06NaEKF1g_MW3WWQAAAHw"]
[Mon Jul 20 07:21:06.056931 2026] [security2:error] [pid 94831:tid 95053] [client 116.179.32.49:27680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WbAAAXFs"]
[Mon Jul 20 07:21:06.066849 2026] [security2:error] [pid 94831:tid 94834] [remote 173.249.4.11:38839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4gwo06NaEKF1g_MW3WdQAAeQI"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:21:06.152624 2026] [security2:error] [pid 94831:tid 94990] [client 50.116.65.227:33714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4gwY06NaEKF1g_MW3WaQAAAB0"]
[Mon Jul 20 07:21:06.263516 2026] [security2:error] [pid 94831:tid 95066] [client 14.225.17.146:61621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4gwI06NaEKF1g_MW3VvwAAAGk"], referer: http://tntcatholic.com/2018
[Mon Jul 20 07:21:06.432640 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:64065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwo06NaEKF1g_MW3WjwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:06.432774 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:64065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gwo06NaEKF1g_MW3WjwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:06.691860 2026] [security2:error] [pid 94831:tid 94964] [client 40.77.179.160:42884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WnQAAA0M"]
[Mon Jul 20 07:21:06.756276 2026] [security2:error] [pid 94831:tid 94994] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WqQAAACE"], referer: http://thescarystory.com/.env.example
[Mon Jul 20 07:21:06.921827 2026] [security2:error] [pid 94831:tid 95001] [client 14.225.17.146:61669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WvwAAACg"], referer: http://retzkolonglogistics.com/2018
[Mon Jul 20 07:21:07.064132 2026] [security2:error] [pid 94831:tid 95081] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WygAAAHg"], referer: https://thescarystory.com/.env.example
[Mon Jul 20 07:21:07.219532 2026] [security2:error] [pid 94831:tid 94979] [client 77.110.127.138:64075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gw406NaEKF1g_MW3W2AAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:07.219630 2026] [security2:error] [pid 94831:tid 94979] [client 77.110.127.138:64075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gw406NaEKF1g_MW3W2AAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:07.317326 2026] [security2:error] [pid 94831:tid 95028] [client 144.172.114.51:51852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gw406NaEKF1g_MW3W5AAAAEM"]
[Mon Jul 20 07:21:07.371613 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:64077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gw406NaEKF1g_MW3W7QAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:07.372143 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:64077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gw406NaEKF1g_MW3W7QAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:07.465857 2026] [security2:error] [pid 94831:tid 95009] [client 74.7.227.179:33292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4gw406NaEKF1g_MW3W4gAAMDE"], referer: https://tejasenvironmental.com/p=2236816
[Mon Jul 20 07:21:07.529028 2026] [security2:error] [pid 94831:tid 94964] [client 85.204.70.92:40588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XAwAAAAM"]
[Mon Jul 20 07:21:07.529155 2026] [security2:error] [pid 94831:tid 94964] [client 85.204.70.92:40588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.thewelloiledlife.com"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XAwAAAAM"]
[Mon Jul 20 07:21:07.531225 2026] [security2:error] [pid 94831:tid 95040] [client 103.176.215.66:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XBQAAAE8"]
[Mon Jul 20 07:21:07.531874 2026] [security2:error] [pid 94831:tid 95040] [client 103.176.215.66:61490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XBQAAAE8"]
[Mon Jul 20 07:21:07.545516 2026] [security2:error] [pid 94831:tid 94906] [remote 91.142.222.105:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4gw406NaEKF1g_MW3XBwAADko"]
[Mon Jul 20 07:21:07.571965 2026] [security2:error] [pid 94831:tid 94990] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4gw406NaEKF1g_MW3W_wAAAB0"], referer: http://thescarystory.com/.env.local
[Mon Jul 20 07:21:07.572604 2026] [security2:error] [pid 94831:tid 95087] [client 57.141.18.12:38652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gv406NaEKF1g_MW3VIwAAfgY"]
[Mon Jul 20 07:21:07.650031 2026] [security2:error] [pid 94831:tid 95030] [client 49.47.218.174:56613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XEAAAAEU"]
[Mon Jul 20 07:21:07.650205 2026] [security2:error] [pid 94831:tid 95030] [client 49.47.218.174:56613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XEAAAAEU"]
[Mon Jul 20 07:21:07.749174 2026] [security2:error] [pid 94831:tid 95064] [client 14.225.17.146:53006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WrgAAAGc"], referer: http://intelligentengineeringsolutions.com/2018
[Mon Jul 20 07:21:07.781919 2026] [security2:error] [pid 94831:tid 94902] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XHgAAXkY"]
[Mon Jul 20 07:21:07.782053 2026] [security2:error] [pid 94831:tid 95055] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gw406NaEKF1g_MW3XHgAAXkY"]
[Mon Jul 20 07:21:07.794995 2026] [security2:error] [pid 94831:tid 94832] [remote 91.142.222.105:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4gw406NaEKF1g_MW3XHwAAagA"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 07:21:07.907380 2026] [security2:error] [pid 94831:tid 95003] [client 93.152.221.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4gw406NaEKF1g_MW3XJQAAACo"], referer: https://thescarystory.com/.env.local
[Mon Jul 20 07:21:07.935834 2026] [security2:error] [pid 94831:tid 94982] [client 104.234.53.57:30205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gw406NaEKF1g_MW3XLwAAABU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:08.077530 2026] [security2:error] [pid 94831:tid 95020] [client 93.152.221.13:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "thescarystory.com"] [uri "/.env.backup"] [unique_id "al4gxI06NaEKF1g_MW3XOgAAADs"]
[Mon Jul 20 07:21:08.083292 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:64048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxI06NaEKF1g_MW3XOwAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:08.083375 2026] [security2:error] [pid 94831:tid 95022] [client 77.110.127.138:64048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxI06NaEKF1g_MW3XOwAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:08.089854 2026] [security2:error] [pid 94831:tid 95050] [client 157.20.138.62:56771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XOQAAAFk"]
[Mon Jul 20 07:21:08.089934 2026] [security2:error] [pid 94831:tid 95050] [client 157.20.138.62:56771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XOQAAAFk"]
[Mon Jul 20 07:21:08.154456 2026] [security2:error] [pid 94831:tid 95059] [client 14.225.17.146:61487] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4gw406NaEKF1g_MW3XJwAAAGI"], referer: http://healthylifegourmet.org/2018
[Mon Jul 20 07:21:08.176728 2026] [security2:error] [pid 94831:tid 95010] [client 88.241.67.160:57338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XQwAAADE"]
[Mon Jul 20 07:21:08.176953 2026] [security2:error] [pid 94831:tid 95010] [client 88.241.67.160:57338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XQwAAADE"]
[Mon Jul 20 07:21:08.187674 2026] [security2:error] [pid 94831:tid 94976] [client 14.225.17.146:53045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4gxI06NaEKF1g_MW3XNgAAAA8"], referer: http://aljosour-alarabia.com/2018
[Mon Jul 20 07:21:08.340787 2026] [security2:error] [pid 94831:tid 95024] [client 36.93.152.155:53228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XWQAAAD8"]
[Mon Jul 20 07:21:08.340863 2026] [security2:error] [pid 94831:tid 95024] [client 36.93.152.155:53228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XWQAAAD8"]
[Mon Jul 20 07:21:08.395773 2026] [security2:error] [pid 94831:tid 95001] [client 117.211.236.168:52781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XYwAAACg"]
[Mon Jul 20 07:21:08.395855 2026] [security2:error] [pid 94831:tid 95001] [client 117.211.236.168:52781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XYwAAACg"]
[Mon Jul 20 07:21:08.540546 2026] [security2:error] [pid 94831:tid 95005] [client 14.225.17.146:61228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4gxI06NaEKF1g_MW3XYAAAACw"], referer: http://elitetax-mi.com/2018
[Mon Jul 20 07:21:08.571053 2026] [security2:error] [pid 94831:tid 95014] [client 57.141.18.107:52424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gwI06NaEKF1g_MW3VkAAANW8"]
[Mon Jul 20 07:21:08.662034 2026] [security2:error] [pid 94831:tid 94994] [client 191.202.66.27:57624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XcwAAACE"]
[Mon Jul 20 07:21:08.662177 2026] [security2:error] [pid 94831:tid 94994] [client 191.202.66.27:57624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XcwAAACE"]
[Mon Jul 20 07:21:08.726622 2026] [security2:error] [pid 94831:tid 95039] [client 104.234.53.71:33843] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gxI06NaEKF1g_MW3XcgAAAE4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:08.774043 2026] [security2:error] [pid 94831:tid 95007] [client 143.44.185.218:14445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XfAAAAC4"]
[Mon Jul 20 07:21:08.774205 2026] [security2:error] [pid 94831:tid 95007] [client 143.44.185.218:14445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gxI06NaEKF1g_MW3XfAAAAC4"]
[Mon Jul 20 07:21:09.228191 2026] [security2:error] [pid 94831:tid 95077] [client 57.141.18.21:36734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gwY06NaEKF1g_MW3WDQAAdFc"]
[Mon Jul 20 07:21:09.277445 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:64091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxY06NaEKF1g_MW3XoQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:09.277526 2026] [security2:error] [pid 94831:tid 95078] [client 77.110.127.138:64091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxY06NaEKF1g_MW3XoQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:09.318050 2026] [security2:error] [pid 94831:tid 94953] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gxY06NaEKF1g_MW3XpQAAM3k"]
[Mon Jul 20 07:21:09.318296 2026] [security2:error] [pid 94831:tid 95012] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4gxY06NaEKF1g_MW3XpQAAM3k"]
[Mon Jul 20 07:21:09.345470 2026] [security2:error] [pid 94831:tid 95047] [client 104.234.53.71:33843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gxY06NaEKF1g_MW3XqwAAAFY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:10.013083 2026] [security2:error] [pid 94831:tid 94973] [client 103.106.165.44:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gxo06NaEKF1g_MW3X5gAAAAw"]
[Mon Jul 20 07:21:10.013186 2026] [security2:error] [pid 94831:tid 94973] [client 103.106.165.44:61260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4gxo06NaEKF1g_MW3X5gAAAAw"]
[Mon Jul 20 07:21:10.064352 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxo06NaEKF1g_MW3X7QAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:10.064428 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxo06NaEKF1g_MW3X7QAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:10.076050 2026] [security2:error] [pid 94831:tid 95086] [client 14.225.17.146:49549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4gxo06NaEKF1g_MW3X5QAAAH0"], referer: http://thefriendlyspreadsheet.com/2018
[Mon Jul 20 07:21:10.087612 2026] [security2:error] [pid 94831:tid 94886] [remote 117.0.21.154:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gxo06NaEKF1g_MW3X7gAAWTY"]
[Mon Jul 20 07:21:10.166587 2026] [security2:error] [pid 94831:tid 94965] [client 77.110.127.138:64024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxo06NaEKF1g_MW3X9QAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:10.166678 2026] [security2:error] [pid 94831:tid 94965] [client 77.110.127.138:64024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gxo06NaEKF1g_MW3X9QAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:10.330110 2026] [security2:error] [pid 94831:tid 94991] [client 57.141.18.35:50042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gwo06NaEKF1g_MW3WjAAAHlA"]
[Mon Jul 20 07:21:10.571041 2026] [security2:error] [pid 94831:tid 94860] [remote 78.46.157.202:34308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gxo06NaEKF1g_MW3YFQAARBw"]
[Mon Jul 20 07:21:10.571220 2026] [security2:error] [pid 94831:tid 95029] [client 78.46.157.202:34308] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4gxo06NaEKF1g_MW3YFQAARBw"]
[Mon Jul 20 07:21:10.598695 2026] [security2:error] [pid 94831:tid 95038] [client 93.93.168.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4gxI06NaEKF1g_MW3XagAAAE0"]
[Mon Jul 20 07:21:10.682919 2026] [security2:error] [pid 94831:tid 95056] [client 31.25.11.143:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gxo06NaEKF1g_MW3YGgAAAF8"]
[Mon Jul 20 07:21:10.837326 2026] [security2:error] [pid 94831:tid 95034] [client 14.225.17.146:61380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4gxI06NaEKF1g_MW3XggAAAEk"], referer: http://www.justinagrayman.com/2018
[Mon Jul 20 07:21:11.008598 2026] [security2:error] [pid 94831:tid 94939] [remote 117.0.21.154:60164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gxo06NaEKF1g_MW3YQwAAA2s"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:21:11.167226 2026] [security2:error] [pid 94831:tid 95059] [client 201.27.111.74:64021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YUwAAAGI"]
[Mon Jul 20 07:21:11.167426 2026] [security2:error] [pid 94831:tid 95059] [client 201.27.111.74:64021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YUwAAAGI"]
[Mon Jul 20 07:21:11.261601 2026] [security2:error] [pid 94831:tid 95010] [client 154.192.123.127:17301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YVwAAADE"]
[Mon Jul 20 07:21:11.261725 2026] [security2:error] [pid 94831:tid 95010] [client 154.192.123.127:17301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YVwAAADE"]
[Mon Jul 20 07:21:11.405391 2026] [security2:error] [pid 94831:tid 95077] [client 14.225.17.146:60981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4gx406NaEKF1g_MW3YYAAAAHQ"], referer: http://processorstudio.com/2018
[Mon Jul 20 07:21:11.422318 2026] [security2:error] [pid 94831:tid 95023] [client 57.141.18.24:49284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gw406NaEKF1g_MW3W-QAAPn4"]
[Mon Jul 20 07:21:11.666267 2026] [security2:error] [pid 94831:tid 95082] [client 192.227.131.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4gxY06NaEKF1g_MW3X3gAAAHk"], referer: https://omenanadotcom.files.wordpress.com/sitemap.xml
[Mon Jul 20 07:21:11.669150 2026] [security2:error] [pid 94831:tid 95080] [client 187.16.64.216:64360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YiQAAAHc"]
[Mon Jul 20 07:21:11.669240 2026] [security2:error] [pid 94831:tid 95080] [client 187.16.64.216:64360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YiQAAAHc"]
[Mon Jul 20 07:21:11.735121 2026] [security2:error] [pid 94831:tid 95063] [client 14.225.17.146:60990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4gx406NaEKF1g_MW3YiAAAAGY"], referer: http://entuvy.com/2018
[Mon Jul 20 07:21:11.906293 2026] [security2:error] [pid 94831:tid 95064] [client 49.37.242.14:58815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YngAAAGc"]
[Mon Jul 20 07:21:11.906412 2026] [security2:error] [pid 94831:tid 95064] [client 49.37.242.14:58815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4gx406NaEKF1g_MW3YngAAAGc"]
[Mon Jul 20 07:21:12.060053 2026] [security2:error] [pid 94831:tid 95014] [client 31.25.11.143:53864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gyI06NaEKF1g_MW3YrwAAADU"]
[Mon Jul 20 07:21:12.292030 2026] [security2:error] [pid 94831:tid 95038] [client 14.225.17.146:49624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4gyI06NaEKF1g_MW3YtwAAAE0"], referer: https://processorstudio.com/2018
[Mon Jul 20 07:21:12.489316 2026] [security2:error] [pid 94831:tid 95080] [client 31.25.11.143:59838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gyI06NaEKF1g_MW3YzwAAAHc"]
[Mon Jul 20 07:21:12.590317 2026] [security2:error] [pid 94831:tid 95070] [client 14.225.17.146:60959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4gx406NaEKF1g_MW3YVgAAAG0"], referer: http://hammadownenterprises.com/2018
[Mon Jul 20 07:21:12.593343 2026] [security2:error] [pid 94831:tid 95071] [client 14.225.17.146:61287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4gyI06NaEKF1g_MW3Y0gAAAG4"], referer: http://keywayconstructionclt.com/2018
[Mon Jul 20 07:21:12.652572 2026] [security2:error] [pid 94831:tid 95058] [client 57.141.18.12:38664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gxI06NaEKF1g_MW3XbwAAYV4"]
[Mon Jul 20 07:21:12.725934 2026] [security2:error] [pid 94831:tid 95003] [client 104.234.53.87:21247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4gyI06NaEKF1g_MW3Y5QAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:12.829124 2026] [security2:error] [pid 94831:tid 95053] [client 77.110.127.138:64105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyI06NaEKF1g_MW3Y9wAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:12.829246 2026] [security2:error] [pid 94831:tid 95053] [client 77.110.127.138:64105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyI06NaEKF1g_MW3Y9wAAAFw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:12.982102 2026] [security2:error] [pid 94831:tid 94974] [client 77.110.127.138:64106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyI06NaEKF1g_MW3ZBgAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:12.982215 2026] [security2:error] [pid 94831:tid 94974] [client 77.110.127.138:64106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyI06NaEKF1g_MW3ZBgAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.021873 2026] [security2:error] [pid 94831:tid 94976] [client 136.158.60.21:56064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4gyY06NaEKF1g_MW3ZCgAAAA8"]
[Mon Jul 20 07:21:13.022036 2026] [security2:error] [pid 94831:tid 94976] [client 136.158.60.21:56064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4gyY06NaEKF1g_MW3ZCgAAAA8"]
[Mon Jul 20 07:21:13.038214 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:64087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZDQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.038390 2026] [security2:error] [pid 94831:tid 95063] [client 77.110.127.138:64087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZDQAAAGY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.136987 2026] [security2:error] [pid 94831:tid 95000] [client 77.110.127.138:64107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZFwAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.137108 2026] [security2:error] [pid 94831:tid 95000] [client 77.110.127.138:64107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZFwAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.195367 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZHwAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.195466 2026] [security2:error] [pid 94831:tid 95075] [client 77.110.127.138:64109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZHwAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.373709 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:64110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZMAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.373853 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:64110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZMAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.442016 2026] [security2:error] [pid 94831:tid 94990] [client 14.225.17.146:61070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4gyY06NaEKF1g_MW3ZMQAAAB0"], referer: https://keywayconstructionclt.com/2018
[Mon Jul 20 07:21:13.483003 2026] [security2:error] [pid 94831:tid 95088] [client 57.141.18.105:30964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gxY06NaEKF1g_MW3XrAAAf1M"]
[Mon Jul 20 07:21:13.532137 2026] [security2:error] [pid 94831:tid 95059] [client 77.110.127.138:64111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZNwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.532251 2026] [security2:error] [pid 94831:tid 95059] [client 77.110.127.138:64111] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyY06NaEKF1g_MW3ZNwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:13.579488 2026] [security2:error] [pid 94831:tid 95043] [client 14.225.17.146:61825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4gyI06NaEKF1g_MW3YuAAAAFI"], referer: http://effingweirdmuseums.com/2018
[Mon Jul 20 07:21:13.786312 2026] [security2:error] [pid 94831:tid 94999] [client 31.25.11.143:53878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gyY06NaEKF1g_MW3ZTgAAACY"]
[Mon Jul 20 07:21:14.053568 2026] [security2:error] [pid 94831:tid 94869] [remote 57.141.18.42:58118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3802589"] [unique_id "al4gyo06NaEKF1g_MW3ZbAAACyU"]
[Mon Jul 20 07:21:14.080830 2026] [security2:error] [pid 94831:tid 95009] [client 154.208.48.130:60459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gyo06NaEKF1g_MW3ZbgAAADA"]
[Mon Jul 20 07:21:14.081288 2026] [security2:error] [pid 94831:tid 95009] [client 154.208.48.130:60459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4gyo06NaEKF1g_MW3ZbgAAADA"]
[Mon Jul 20 07:21:14.100734 2026] [security2:error] [pid 94831:tid 95057] [client 14.225.17.146:61081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4gyY06NaEKF1g_MW3ZYQAAAGA"], referer: http://uritems.net/2018
[Mon Jul 20 07:21:14.194606 2026] [security2:error] [pid 94831:tid 95049] [client 31.25.11.143:59854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gyo06NaEKF1g_MW3ZewAAAFg"]
[Mon Jul 20 07:21:14.251345 2026] [security2:error] [pid 94831:tid 95044] [client 77.110.127.138:64113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 113 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gyo06NaEKF1g_MW3ZggAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:14.443438 2026] [security2:error] [pid 94831:tid 95005] [client 77.110.127.138:64115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyo06NaEKF1g_MW3ZjgAAACw"]
[Mon Jul 20 07:21:14.443546 2026] [security2:error] [pid 94831:tid 95005] [client 77.110.127.138:64115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyo06NaEKF1g_MW3ZjgAAACw"]
[Mon Jul 20 07:21:14.622442 2026] [security2:error] [pid 94831:tid 95023] [client 104.234.53.70:41605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4gyo06NaEKF1g_MW3ZoAAAAD4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:14.638333 2026] [security2:error] [pid 94831:tid 95002] [client 77.110.127.138:64116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyo06NaEKF1g_MW3ZowAAACk"]
[Mon Jul 20 07:21:14.638477 2026] [security2:error] [pid 94831:tid 95002] [client 77.110.127.138:64116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gyo06NaEKF1g_MW3ZowAAACk"]
[Mon Jul 20 07:21:14.773513 2026] [security2:error] [pid 94831:tid 94836] [remote 124.55.178.99:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gyo06NaEKF1g_MW3ZsAAAdgQ"]
[Mon Jul 20 07:21:14.846857 2026] [security2:error] [pid 94831:tid 95025] [client 14.225.17.146:65097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4gyo06NaEKF1g_MW3ZrwAAAEA"], referer: http://collectingrealestate.com/2018
[Mon Jul 20 07:21:14.915334 2026] [security2:error] [pid 94831:tid 95084] [client 103.144.65.217:61086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gyo06NaEKF1g_MW3ZugAAAHs"]
[Mon Jul 20 07:21:14.915512 2026] [security2:error] [pid 94831:tid 95084] [client 103.144.65.217:61086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4gyo06NaEKF1g_MW3ZugAAAHs"]
[Mon Jul 20 07:21:15.087309 2026] [security2:error] [pid 94831:tid 95075] [client 216.244.66.244:34320] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4gy406NaEKF1g_MW3ZwwAAAHI"]
[Mon Jul 20 07:21:15.087393 2026] [security2:error] [pid 94831:tid 95075] [client 216.244.66.244:34320] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4gy406NaEKF1g_MW3ZwwAAAHI"]
[Mon Jul 20 07:21:15.180641 2026] [security2:error] [pid 94831:tid 94895] [remote 124.55.178.99:60208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4gy406NaEKF1g_MW3ZywAAKT8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:21:15.320237 2026] [security2:error] [pid 94831:tid 95064] [client 52.109.16.52:3780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gy406NaEKF1g_MW3Z2AAAAGc"]
[Mon Jul 20 07:21:15.375185 2026] [security2:error] [pid 94831:tid 95079] [client 52.109.16.52:3780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gy406NaEKF1g_MW3Z4QAAAHY"]
[Mon Jul 20 07:21:15.555892 2026] [security2:error] [pid 94831:tid 95035] [client 14.225.17.146:49638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4gyY06NaEKF1g_MW3ZQgAAAEo"], referer: http://areitoproducciones.com/2018
[Mon Jul 20 07:21:15.568845 2026] [security2:error] [pid 94831:tid 95010] [client 31.25.11.143:53888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gy406NaEKF1g_MW3Z7AAAADE"]
[Mon Jul 20 07:21:15.605885 2026] [security2:error] [pid 94831:tid 94924] [remote 162.19.86.63:37341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4gy406NaEKF1g_MW3Z8AAAT1w"]
[Mon Jul 20 07:21:15.611583 2026] [core:error] [pid 94831:tid 95070] [client 14.225.17.146:65168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:15.611620 2026] [core:error] [pid 94831:tid 95070] [client 14.225.17.146:65168] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:15.619400 2026] [security2:error] [pid 94831:tid 95007] [client 52.187.75.220:32848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4gy406NaEKF1g_MW3Z8wAAAC4"]
[Mon Jul 20 07:21:15.662957 2026] [security2:error] [pid 94831:tid 95061] [client 57.141.18.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4gy406NaEKF1g_MW3Z6AAAAGQ"]
[Mon Jul 20 07:21:15.734534 2026] [security2:error] [pid 94831:tid 94962] [client 77.110.127.138:64124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gy406NaEKF1g_MW3aAQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:15.734664 2026] [security2:error] [pid 94831:tid 94962] [client 77.110.127.138:64124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gy406NaEKF1g_MW3aAQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:15.804070 2026] [security2:error] [pid 94831:tid 94863] [remote 162.19.86.63:37341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4gy406NaEKF1g_MW3aCgAAYh8"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:21:15.811059 2026] [security2:error] [pid 94831:tid 94983] [client 52.187.75.220:32848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4gy406NaEKF1g_MW3aCwAAABY"]
[Mon Jul 20 07:21:15.932256 2026] [security2:error] [pid 94831:tid 94980] [client 14.225.17.146:49684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4gyo06NaEKF1g_MW3ZiwAAABM"], referer: http://detroitcsc.com/2018
[Mon Jul 20 07:21:15.945002 2026] [security2:error] [pid 94831:tid 95040] [client 77.110.127.138:64126] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 204 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gy406NaEKF1g_MW3aHwAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:15.975315 2026] [security2:error] [pid 94831:tid 95038] [client 14.225.17.146:62851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4gy406NaEKF1g_MW3aGAAAAE0"], referer: http://adultdaycarereno.com/2018
[Mon Jul 20 07:21:15.978850 2026] [ssl:error] [pid 94831:tid 95066] [client 66.132.172.187:54020] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bridgeamazon.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:21:16.013793 2026] [security2:error] [pid 94831:tid 95020] [client 31.25.11.143:59860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gy406NaEKF1g_MW3aIgAAADs"]
[Mon Jul 20 07:21:16.054385 2026] [security2:error] [pid 94831:tid 94990] [client 104.234.53.83:26293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4gzI06NaEKF1g_MW3aJgAAAB0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:16.115495 2026] [security2:error] [pid 94831:tid 95009] [client 144.172.114.51:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gzI06NaEKF1g_MW3aKgAAADA"]
[Mon Jul 20 07:21:16.209760 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:64127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzI06NaEKF1g_MW3aNQAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:16.209858 2026] [security2:error] [pid 94831:tid 95011] [client 77.110.127.138:64127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzI06NaEKF1g_MW3aNQAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:16.227362 2026] [security2:error] [pid 94831:tid 95085] [client 57.141.18.12:48298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gyI06NaEKF1g_MW3YwwAAfC8"]
[Mon Jul 20 07:21:16.234726 2026] [security2:error] [pid 94831:tid 95015] [client 47.128.118.239:50100] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.willowbranchequines.org"] [uri "/robots.txt"] [unique_id "al4gzI06NaEKF1g_MW3aOQAAADY"]
[Mon Jul 20 07:21:16.334373 2026] [security2:error] [pid 94831:tid 95069] [client 14.225.17.146:61050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4gyI06NaEKF1g_MW3Y-QAAAGw"], referer: http://gearwaterproof.com/2018
[Mon Jul 20 07:21:16.350958 2026] [security2:error] [pid 94831:tid 95076] [client 57.141.18.89:33718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gyI06NaEKF1g_MW3YxwAAc3U"]
[Mon Jul 20 07:21:16.720088 2026] [access_compat:error] [pid 94831:tid 94888] [remote 165.227.39.235:0] AH01797: client denied by server configuration: /home4/sustalj1/public_html/server-status
[Mon Jul 20 07:21:16.770321 2026] [security2:error] [pid 94831:tid 94964] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4gzI06NaEKF1g_MW3aUQAAAAM"]
[Mon Jul 20 07:21:16.841462 2026] [security2:error] [pid 94831:tid 94996] [client 14.225.17.146:50039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "younutrition.gr"] [uri "/index.php"] [unique_id "al4gyo06NaEKF1g_MW3ZogAAACM"], referer: http://younutrition.gr/2018
[Mon Jul 20 07:21:16.896399 2026] [security2:error] [pid 94831:tid 94975] [client 14.225.17.146:61229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4gyo06NaEKF1g_MW3ZngAAAA4"]
[Mon Jul 20 07:21:17.041332 2026] [security2:error] [pid 94831:tid 95017] [client 14.225.17.146:65128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4gy406NaEKF1g_MW3aDgAAADg"], referer: http://getgarrison.com/2018
[Mon Jul 20 07:21:17.192026 2026] [security2:error] [pid 94831:tid 94977] [client 77.110.127.138:64096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzY06NaEKF1g_MW3aiQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:17.192167 2026] [security2:error] [pid 94831:tid 94977] [client 77.110.127.138:64096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzY06NaEKF1g_MW3aiQAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:17.197297 2026] [security2:error] [pid 94831:tid 95070] [client 158.173.166.181:23603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4gzY06NaEKF1g_MW3aiwAAAG0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:21:17.260140 2026] [security2:error] [pid 94831:tid 94984] [client 31.25.11.143:53894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gzY06NaEKF1g_MW3ajgAAABc"]
[Mon Jul 20 07:21:17.307365 2026] [security2:error] [pid 94831:tid 95081] [client 14.225.17.146:62868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4gy406NaEKF1g_MW3aHQAAAHg"], referer: http://iagdevelopments.com/2018
[Mon Jul 20 07:21:17.320460 2026] [security2:error] [pid 94831:tid 95030] [client 136.144.33.207:48325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4gzY06NaEKF1g_MW3aegAAAEU"]
[Mon Jul 20 07:21:17.337097 2026] [security2:error] [pid 94831:tid 94976] [client 37.140.223.99:29413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4gzY06NaEKF1g_MW3adgAAAA8"]
[Mon Jul 20 07:21:17.416637 2026] [security2:error] [pid 94831:tid 94972] [client 77.110.127.138:64132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzY06NaEKF1g_MW3apQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:17.416811 2026] [security2:error] [pid 94831:tid 94972] [client 77.110.127.138:64132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzY06NaEKF1g_MW3apQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:17.607494 2026] [security2:error] [pid 94831:tid 95076] [client 50.116.65.227:37080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4gzY06NaEKF1g_MW3atgAAAHM"]
[Mon Jul 20 07:21:17.619352 2026] [security2:error] [pid 94831:tid 95056] [client 50.116.65.227:37090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4gzY06NaEKF1g_MW3auAAAAF8"]
[Mon Jul 20 07:21:17.747177 2026] [security2:error] [pid 94831:tid 95016] [client 31.25.11.143:59872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gzY06NaEKF1g_MW3avgAAADc"]
[Mon Jul 20 07:21:17.867513 2026] [security2:error] [pid 94831:tid 95035] [client 104.234.53.52:50395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4gzY06NaEKF1g_MW3azwAAAEo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:18.001101 2026] [security2:error] [pid 94831:tid 95042] [client 14.225.17.146:64945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4gzY06NaEKF1g_MW3awgAAAFE"], referer: http://falconarrowshop.com/2018
[Mon Jul 20 07:21:18.006809 2026] [security2:error] [pid 94831:tid 94908] [remote 192.241.143.148:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4gzY06NaEKF1g_MW3a3AAAZEw"]
[Mon Jul 20 07:21:18.034285 2026] [security2:error] [pid 94831:tid 94990] [client 103.176.215.66:62021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3a4gAAAB0"]
[Mon Jul 20 07:21:18.034919 2026] [security2:error] [pid 94831:tid 94990] [client 103.176.215.66:62021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3a4gAAAB0"]
[Mon Jul 20 07:21:18.049268 2026] [security2:error] [pid 94831:tid 94961] [client 117.211.236.168:53323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3a5AAAAAA"]
[Mon Jul 20 07:21:18.049381 2026] [security2:error] [pid 94831:tid 94961] [client 117.211.236.168:53323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3a5AAAAAA"]
[Mon Jul 20 07:21:18.056359 2026] [security2:error] [pid 94831:tid 95047] [client 77.110.127.138:64138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzo06NaEKF1g_MW3a3wAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:18.056492 2026] [security2:error] [pid 94831:tid 95047] [client 77.110.127.138:64138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gzo06NaEKF1g_MW3a3wAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:18.096116 2026] [security2:error] [pid 94831:tid 95057] [client 49.47.218.174:57133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3a6gAAAGA"]
[Mon Jul 20 07:21:18.096255 2026] [security2:error] [pid 94831:tid 95057] [client 49.47.218.174:57133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3a6gAAAGA"]
[Mon Jul 20 07:21:18.166411 2026] [fcgid:warn] [pid 94831:tid 94991] (70014)End of file found: [client 65.49.20.69:24856] mod_fcgid: can't get data from http client
[Mon Jul 20 07:21:18.212887 2026] [security2:error] [pid 94831:tid 94992] [client 14.225.17.146:51460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4gzo06NaEKF1g_MW3a7AAAAB8"], referer: https://iagdevelopments.com/2018
[Mon Jul 20 07:21:18.219035 2026] [security2:error] [pid 94831:tid 95019] [client 14.225.17.146:51940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4gzI06NaEKF1g_MW3aSwAAADo"], referer: http://thesoloceos.com/2018
[Mon Jul 20 07:21:18.222002 2026] [security2:error] [pid 94831:tid 94936] [remote 192.241.143.148:58264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4gzo06NaEKF1g_MW3a8QAAeWg"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 07:21:18.314010 2026] [security2:error] [pid 94831:tid 95020] [client 13.232.231.177:50896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gzo06NaEKF1g_MW3a-QAAADs"]
[Mon Jul 20 07:21:18.523619 2026] [security2:error] [pid 94831:tid 94956] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bCQAAcHw"]
[Mon Jul 20 07:21:18.523781 2026] [security2:error] [pid 94831:tid 95073] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bCQAAcHw"]
[Mon Jul 20 07:21:18.586696 2026] [security2:error] [pid 94831:tid 95055] [client 144.172.114.51:50074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.114.172.144.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-content/plugins/ultra/includes/ajax.php"] [unique_id "al4gzo06NaEKF1g_MW3bEgAAAF4"]
[Mon Jul 20 07:21:18.598645 2026] [security2:error] [pid 94831:tid 95001] [client 157.20.138.62:57337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bFQAAACg"]
[Mon Jul 20 07:21:18.598800 2026] [security2:error] [pid 94831:tid 95001] [client 157.20.138.62:57337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bFQAAACg"]
[Mon Jul 20 07:21:18.851383 2026] [security2:error] [pid 94831:tid 94982] [client 36.93.152.155:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bKwAAABU"]
[Mon Jul 20 07:21:18.851462 2026] [security2:error] [pid 94831:tid 94982] [client 36.93.152.155:53724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bKwAAABU"]
[Mon Jul 20 07:21:18.875335 2026] [security2:error] [pid 94831:tid 94997] [client 57.141.18.97:48648] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gyo06NaEKF1g_MW3ZtgAAJHs"]
[Mon Jul 20 07:21:18.893873 2026] [security2:error] [pid 94831:tid 95061] [client 88.241.67.160:55801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bLQAAAGQ"]
[Mon Jul 20 07:21:18.893989 2026] [security2:error] [pid 94831:tid 95061] [client 88.241.67.160:55801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4gzo06NaEKF1g_MW3bLQAAAGQ"]
[Mon Jul 20 07:21:18.975041 2026] [security2:error] [pid 94831:tid 94948] [remote 57.141.18.12:48858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5276127"] [unique_id "al4gzo06NaEKF1g_MW3bMgAAa3Q"]
[Mon Jul 20 07:21:19.085723 2026] [security2:error] [pid 94831:tid 94978] [client 191.202.66.27:58099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gz406NaEKF1g_MW3bNwAAABE"]
[Mon Jul 20 07:21:19.085857 2026] [security2:error] [pid 94831:tid 94978] [client 191.202.66.27:58099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4gz406NaEKF1g_MW3bNwAAABE"]
[Mon Jul 20 07:21:19.094112 2026] [security2:error] [pid 94831:tid 95085] [client 77.110.127.138:64142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bOQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.094181 2026] [security2:error] [pid 94831:tid 95085] [client 77.110.127.138:64142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bOQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.122054 2026] [security2:error] [pid 94831:tid 95034] [client 31.25.11.143:58658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gz406NaEKF1g_MW3bOwAAAEk"]
[Mon Jul 20 07:21:19.146031 2026] [security2:error] [pid 94831:tid 95006] [client 77.110.127.138:64122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at REQUEST_HEADERS:X-Requested-With. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 507 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4gz406NaEKF1g_MW3bPQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.162129 2026] [security2:error] [pid 94831:tid 94987] [client 77.110.127.138:64123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bQAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.162251 2026] [security2:error] [pid 94831:tid 94987] [client 77.110.127.138:64123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bQAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.213165 2026] [security2:error] [pid 94831:tid 95053] [client 14.225.17.146:64889] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4gz406NaEKF1g_MW3bNAAAAFw"], referer: https://thesoloceos.com/2018
[Mon Jul 20 07:21:19.291767 2026] [security2:error] [pid 94831:tid 94866] [remote 216.73.216.55:65292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4gz406NaEKF1g_MW3bTQAAPyI"]
[Mon Jul 20 07:21:19.315961 2026] [security2:error] [pid 94831:tid 95035] [client 77.110.127.138:64147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bTwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.316075 2026] [security2:error] [pid 94831:tid 95035] [client 77.110.127.138:64147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bTwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.358262 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:64148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bUwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.358357 2026] [security2:error] [pid 94831:tid 95062] [client 77.110.127.138:64148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bUwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.428463 2026] [security2:error] [pid 94831:tid 95054] [client 143.44.185.218:15675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gz406NaEKF1g_MW3bXAAAAF0"]
[Mon Jul 20 07:21:19.428557 2026] [security2:error] [pid 94831:tid 95054] [client 143.44.185.218:15675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4gz406NaEKF1g_MW3bXAAAAF0"]
[Mon Jul 20 07:21:19.455691 2026] [security2:error] [pid 94831:tid 95018] [client 13.232.231.177:50900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4gz406NaEKF1g_MW3bYQAAADk"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:21:19.466342 2026] [security2:error] [pid 94831:tid 95059] [client 77.110.127.138:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bZQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.466432 2026] [security2:error] [pid 94831:tid 95059] [client 77.110.127.138:64149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bZQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.563076 2026] [security2:error] [pid 94831:tid 95066] [client 31.25.11.143:57660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.11.25.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4gz406NaEKF1g_MW3bawAAAGk"]
[Mon Jul 20 07:21:19.660370 2026] [security2:error] [pid 94831:tid 95017] [client 77.110.127.138:64150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bcQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.660488 2026] [security2:error] [pid 94831:tid 95017] [client 77.110.127.138:64150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bcQAAADg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.703804 2026] [security2:error] [pid 94831:tid 94863] [remote 5.161.225.162:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gz406NaEKF1g_MW3bcgAACR8"]
[Mon Jul 20 07:21:19.794973 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:64151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bewAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.795070 2026] [security2:error] [pid 94831:tid 95050] [client 77.110.127.138:64151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4gz406NaEKF1g_MW3bewAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:19.862772 2026] [security2:error] [pid 94831:tid 95020] [client 104.234.53.83:36873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4gz406NaEKF1g_MW3bgwAAADs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:19.928703 2026] [security2:error] [pid 94831:tid 94878] [remote 5.161.225.162:49658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4gz406NaEKF1g_MW3biQAAUC4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:21:20.061594 2026] [security2:error] [pid 94831:tid 94943] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g0I06NaEKF1g_MW3blAAAf28"]
[Mon Jul 20 07:21:20.061726 2026] [security2:error] [pid 94831:tid 95088] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g0I06NaEKF1g_MW3blAAAf28"]
[Mon Jul 20 07:21:20.106409 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:64136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0I06NaEKF1g_MW3blgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:20.106485 2026] [security2:error] [pid 94831:tid 95067] [client 77.110.127.138:64136] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0I06NaEKF1g_MW3blgAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:20.148875 2026] [security2:error] [pid 94831:tid 94841] [remote 162.19.86.63:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4g0I06NaEKF1g_MW3bmAAAOQk"]
[Mon Jul 20 07:21:20.240502 2026] [security2:error] [pid 94831:tid 94983] [client 14.225.17.146:51471] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4gzo06NaEKF1g_MW3a-AAAABY"], referer: http://mollycahill.com/2018
[Mon Jul 20 07:21:20.261494 2026] [security2:error] [pid 94831:tid 94979] [client 77.110.127.138:64155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0I06NaEKF1g_MW3bnwAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:20.261569 2026] [security2:error] [pid 94831:tid 94979] [client 77.110.127.138:64155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0I06NaEKF1g_MW3bnwAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:20.371219 2026] [security2:error] [pid 94831:tid 94926] [remote 162.19.86.63:55212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4g0I06NaEKF1g_MW3brwAAGV4"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 07:21:20.498603 2026] [security2:error] [pid 94831:tid 95063] [client 57.141.18.48:31314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gzI06NaEKF1g_MW3aSgAAZiQ"]
[Mon Jul 20 07:21:20.572131 2026] [security2:error] [pid 94831:tid 95061] [client 103.106.165.44:61725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g0I06NaEKF1g_MW3bvwAAAGQ"]
[Mon Jul 20 07:21:20.572256 2026] [security2:error] [pid 94831:tid 95061] [client 103.106.165.44:61725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g0I06NaEKF1g_MW3bvwAAAGQ"]
[Mon Jul 20 07:21:20.749592 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:64161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0I06NaEKF1g_MW3b0QAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:20.749716 2026] [security2:error] [pid 94831:tid 95028] [client 77.110.127.138:64161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0I06NaEKF1g_MW3b0QAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:20.928324 2026] [security2:error] [pid 94831:tid 95055] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4gz406NaEKF1g_MW3bfwAAXho"], referer: http://ardhalwafaa.com/2018
[Mon Jul 20 07:21:21.283396 2026] [core:error] [pid 94831:tid 95039] [client 103.102.247.241:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:21.283429 2026] [core:error] [pid 94831:tid 95039] [client 103.102.247.241:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:21.585216 2026] [security2:error] [pid 94831:tid 95073] [client 201.27.111.74:64527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g0Y06NaEKF1g_MW3cGQAAAHA"]
[Mon Jul 20 07:21:21.585356 2026] [security2:error] [pid 94831:tid 95073] [client 201.27.111.74:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g0Y06NaEKF1g_MW3cGQAAAHA"]
[Mon Jul 20 07:21:21.706777 2026] [security2:error] [pid 94831:tid 95029] [client 104.234.53.49:23715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g0Y06NaEKF1g_MW3cHQAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:21.745404 2026] [security2:error] [pid 94831:tid 94980] [client 49.37.242.14:59331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g0Y06NaEKF1g_MW3cIgAAABM"]
[Mon Jul 20 07:21:21.745500 2026] [security2:error] [pid 94831:tid 94980] [client 49.37.242.14:59331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g0Y06NaEKF1g_MW3cIgAAABM"]
[Mon Jul 20 07:21:21.790957 2026] [security2:error] [pid 94831:tid 95069] [client 14.225.17.146:51612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4g0Y06NaEKF1g_MW3cGgAAAGw"], referer: http://aandarealtygroup.com/2018
[Mon Jul 20 07:21:21.878791 2026] [security2:error] [pid 94831:tid 95053] [client 154.192.123.127:17697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g0Y06NaEKF1g_MW3cMQAAAFw"]
[Mon Jul 20 07:21:21.878925 2026] [security2:error] [pid 94831:tid 95053] [client 154.192.123.127:17697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g0Y06NaEKF1g_MW3cMQAAAFw"]
[Mon Jul 20 07:21:22.359263 2026] [security2:error] [pid 94831:tid 95044] [client 187.16.64.216:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g0o06NaEKF1g_MW3cVgAAAFM"]
[Mon Jul 20 07:21:22.359383 2026] [security2:error] [pid 94831:tid 95044] [client 187.16.64.216:64943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g0o06NaEKF1g_MW3cVgAAAFM"]
[Mon Jul 20 07:21:22.424260 2026] [security2:error] [pid 94831:tid 94973] [client 14.225.17.146:52547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4g0o06NaEKF1g_MW3cUgAAAAw"], referer: http://ravmike.com/2018
[Mon Jul 20 07:21:22.473275 2026] [security2:error] [pid 94831:tid 94977] [client 57.141.18.9:45284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gzo06NaEKF1g_MW3bFwAAEDc"]
[Mon Jul 20 07:21:22.602547 2026] [security2:error] [pid 94831:tid 94897] [remote 165.227.39.235:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.sustaintheart.com"] [uri "/.env"] [unique_id "al4g0o06NaEKF1g_MW3cagAAAkE"]
[Mon Jul 20 07:21:22.829430 2026] [security2:error] [pid 94831:tid 94976] [client 77.110.127.138:64146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0o06NaEKF1g_MW3cfgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:22.829531 2026] [security2:error] [pid 94831:tid 94976] [client 77.110.127.138:64146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0o06NaEKF1g_MW3cfgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:22.856511 2026] [security2:error] [pid 94831:tid 94958] [remote 72.167.132.114:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4g0o06NaEKF1g_MW3cgAAAK34"]
[Mon Jul 20 07:21:22.907922 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:64169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0o06NaEKF1g_MW3chgAAAE4"]
[Mon Jul 20 07:21:22.908015 2026] [security2:error] [pid 94831:tid 95039] [client 77.110.127.138:64169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0o06NaEKF1g_MW3chgAAAE4"]
[Mon Jul 20 07:21:22.980266 2026] [security2:error] [pid 94831:tid 95046] [client 77.110.127.138:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0o06NaEKF1g_MW3cjwAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:22.980434 2026] [security2:error] [pid 94831:tid 95046] [client 77.110.127.138:64173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0o06NaEKF1g_MW3cjwAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.069885 2026] [security2:error] [pid 94831:tid 95043] [client 77.110.127.138:64174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3cmgAAAFI"]
[Mon Jul 20 07:21:23.069989 2026] [security2:error] [pid 94831:tid 95043] [client 77.110.127.138:64174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3cmgAAAFI"]
[Mon Jul 20 07:21:23.123584 2026] [security2:error] [pid 94831:tid 94944] [remote 72.167.132.114:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4g0406NaEKF1g_MW3cogAAPnA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:21:23.230442 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:64152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3crQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.230539 2026] [security2:error] [pid 94831:tid 95036] [client 77.110.127.138:64152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3crQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.295724 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:64139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3csAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.295881 2026] [security2:error] [pid 94831:tid 94988] [client 77.110.127.138:64139] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3csAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.350128 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:64157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3ctwAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.350255 2026] [security2:error] [pid 94831:tid 95048] [client 77.110.127.138:64157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3ctwAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.373730 2026] [security2:error] [pid 94831:tid 94969] [client 14.225.17.146:60821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4g0406NaEKF1g_MW3csgAAAAg"], referer: https://ravmike.com/2018
[Mon Jul 20 07:21:23.504768 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:64176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3cyQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.504884 2026] [security2:error] [pid 94831:tid 94971] [client 77.110.127.138:64176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g0406NaEKF1g_MW3cyQAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:23.512180 2026] [security2:error] [pid 94831:tid 95062] [client 14.225.17.146:51337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4g0406NaEKF1g_MW3cugAAAGU"], referer: http://ncsynchro.com/2018
[Mon Jul 20 07:21:23.728003 2026] [security2:error] [pid 94831:tid 94972] [client 136.158.60.21:57826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g0406NaEKF1g_MW3c4gAAAAs"]
[Mon Jul 20 07:21:23.728094 2026] [security2:error] [pid 94831:tid 94972] [client 136.158.60.21:57826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g0406NaEKF1g_MW3c4gAAAAs"]
[Mon Jul 20 07:21:23.845390 2026] [security2:error] [pid 94831:tid 95030] [client 57.141.18.88:54694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4gz406NaEKF1g_MW3bhgAARRg"]
[Mon Jul 20 07:21:24.865045 2026] [security2:error] [pid 94831:tid 95043] [client 74.249.226.166:21185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4g1I06NaEKF1g_MW3dOwAAAFI"]
[Mon Jul 20 07:21:24.865857 2026] [security2:error] [pid 94831:tid 94920] [remote 209.42.21.221:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4g1I06NaEKF1g_MW3dOgAAR1g"]
[Mon Jul 20 07:21:24.918345 2026] [security2:error] [pid 94831:tid 95025] [client 74.249.226.166:21185] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4g1I06NaEKF1g_MW3dPAAAAEA"]
[Mon Jul 20 07:21:25.019997 2026] [security2:error] [pid 94831:tid 95076] [client 57.141.18.116:56384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g0Y06NaEKF1g_MW3b6gAAc38"]
[Mon Jul 20 07:21:25.041968 2026] [security2:error] [pid 94831:tid 94845] [remote 209.42.21.221:54272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4g1Y06NaEKF1g_MW3dRAAAbA0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:21:25.081960 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:64181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1Y06NaEKF1g_MW3dSQAAADs"]
[Mon Jul 20 07:21:25.082069 2026] [security2:error] [pid 94831:tid 95020] [client 77.110.127.138:64181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1Y06NaEKF1g_MW3dSQAAADs"]
[Mon Jul 20 07:21:25.097065 2026] [security2:error] [pid 94831:tid 94984] [client 154.208.48.130:60965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g1Y06NaEKF1g_MW3dSwAAABc"]
[Mon Jul 20 07:21:25.097722 2026] [security2:error] [pid 94831:tid 94984] [client 154.208.48.130:60965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g1Y06NaEKF1g_MW3dSwAAABc"]
[Mon Jul 20 07:21:25.141376 2026] [security2:error] [pid 94831:tid 95049] [client 104.234.53.85:46375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4g1Y06NaEKF1g_MW3dUQAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:25.319396 2026] [security2:error] [pid 94831:tid 95081] [client 52.109.28.48:18241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4g1Y06NaEKF1g_MW3daAAAAHg"]
[Mon Jul 20 07:21:25.459884 2026] [security2:error] [pid 94831:tid 94984] [client 52.109.28.48:18241] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4g1Y06NaEKF1g_MW3ddwAAABc"]
[Mon Jul 20 07:21:25.544743 2026] [security2:error] [pid 94831:tid 94968] [client 14.225.17.146:52763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4g0406NaEKF1g_MW3c8wAAAAc"], referer: http://bigwormfishing.com/2018
[Mon Jul 20 07:21:25.544948 2026] [security2:error] [pid 94831:tid 95030] [client 103.144.65.217:61590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4g1Y06NaEKF1g_MW3dfgAAAEU"]
[Mon Jul 20 07:21:25.545047 2026] [security2:error] [pid 94831:tid 95030] [client 103.144.65.217:61590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4g1Y06NaEKF1g_MW3dfgAAAEU"]
[Mon Jul 20 07:21:25.644249 2026] [security2:error] [pid 94831:tid 94964] [client 77.110.127.138:64183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1Y06NaEKF1g_MW3dhgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:25.644354 2026] [security2:error] [pid 94831:tid 94964] [client 77.110.127.138:64183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1Y06NaEKF1g_MW3dhgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:25.668003 2026] [security2:error] [pid 94831:tid 94848] [remote 160.187.68.132:59736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4g1Y06NaEKF1g_MW3diAAAbRA"]
[Mon Jul 20 07:21:25.735851 2026] [security2:error] [pid 94831:tid 94833] [remote 57.141.18.64:29110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g0Y06NaEKF1g_MW3cIAAALwE"]
[Mon Jul 20 07:21:26.018703 2026] [http2:info] [pid 110058:tid 110058] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:21:26.091784 2026] [security2:error] [pid 110058:tid 110204] [client 77.110.127.138:64184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1hJHADqs2gAgBs-ERgAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:26.091923 2026] [security2:error] [pid 110058:tid 110204] [client 77.110.127.138:64184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1hJHADqs2gAgBs-ERgAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:26.378263 2026] [security2:error] [pid 110058:tid 110205] [client 87.199.199.98:64699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-comments-post.php"] [unique_id "al4g1hJHADqs2gAgBs-EbgAAAJU"], referer: https://fluidtemple.org/namaste-course/yin-class/
[Mon Jul 20 07:21:26.378446 2026] [security2:error] [pid 110058:tid 110205] [client 87.199.199.98:64699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "fluidtemple.org"] [uri "/wp-comments-post.php"] [unique_id "al4g1hJHADqs2gAgBs-EbgAAAJU"], referer: https://fluidtemple.org/namaste-course/yin-class/
[Mon Jul 20 07:21:26.396374 2026] [security2:error] [pid 110058:tid 110219] [client 37.27.51.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "innspace.ca"] [uri "/index.php"] [unique_id "al4g1hJHADqs2gAgBs-EOQAAAKM"]
[Mon Jul 20 07:21:26.419167 2026] [security2:error] [pid 110058:tid 110282] [client 77.110.127.138:64188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1hJHADqs2gAgBs-EcgAAAOI"]
[Mon Jul 20 07:21:26.419267 2026] [security2:error] [pid 110058:tid 110282] [client 77.110.127.138:64188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1hJHADqs2gAgBs-EcgAAAOI"]
[Mon Jul 20 07:21:26.571287 2026] [security2:error] [pid 110058:tid 110198] [client 202.141.11.99:22148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4g1hJHADqs2gAgBs-EfQAAAI4"]
[Mon Jul 20 07:21:26.571674 2026] [security2:error] [pid 110058:tid 110198] [client 202.141.11.99:22148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4g1hJHADqs2gAgBs-EfQAAAI4"]
[Mon Jul 20 07:21:26.620734 2026] [security2:error] [pid 110058:tid 110247] [client 14.225.17.146:59498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4g1hJHADqs2gAgBs-EewAAAL8"], referer: https://bigwormfishing.com/2018
[Mon Jul 20 07:21:26.700512 2026] [security2:error] [pid 110058:tid 110261] [client 193.37.33.47:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4g1hJHADqs2gAgBs-EhQAAAM0"]
[Mon Jul 20 07:21:26.720415 2026] [security2:error] [pid 110058:tid 110260] [client 193.37.33.21:59035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4g1hJHADqs2gAgBs-EgwAAAMw"]
[Mon Jul 20 07:21:27.131802 2026] [security2:error] [pid 110058:tid 110099] [remote 160.187.68.132:59750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4g1xJHADqs2gAgBs-ErgAAlCg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:21:27.177949 2026] [security2:error] [pid 110058:tid 110228] [client 45.157.112.60:47049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4g1xJHADqs2gAgBs-EsAAAAKw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:21:27.544217 2026] [security2:error] [pid 94831:tid 94884] [remote 57.141.18.17:40950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g0406NaEKF1g_MW3czAAADTQ"]
[Mon Jul 20 07:21:27.825761 2026] [security2:error] [pid 110058:tid 110121] [remote 182.77.62.24:38154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g1xJHADqs2gAgBs-E2wAA-j0"]
[Mon Jul 20 07:21:27.825816 2026] [security2:error] [pid 110058:tid 110234] [client 77.110.127.138:64192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1xJHADqs2gAgBs-E3AAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:27.825888 2026] [security2:error] [pid 110058:tid 110234] [client 77.110.127.138:64192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g1xJHADqs2gAgBs-E3AAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:27.825966 2026] [security2:error] [pid 110058:tid 110306] [client 182.77.62.24:38154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g1xJHADqs2gAgBs-E2wAA-j0"]
[Mon Jul 20 07:21:27.913113 2026] [security2:error] [pid 110058:tid 110125] [remote 176.56.118.182:43956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g1xJHADqs2gAgBs-E5QAAmkE"]
[Mon Jul 20 07:21:27.913255 2026] [security2:error] [pid 110058:tid 110210] [client 176.56.118.182:43956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g1xJHADqs2gAgBs-E5QAAmkE"]
[Mon Jul 20 07:21:28.000977 2026] [security2:error] [pid 110058:tid 110281] [client 74.208.214.194:60754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4g2BJHADqs2gAgBs-E7gAAAOE"]
[Mon Jul 20 07:21:28.263590 2026] [security2:error] [pid 110058:tid 110200] [client 104.234.53.53:64037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4g2BJHADqs2gAgBs-FCwAAAJA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:28.302372 2026] [security2:error] [pid 110058:tid 110244] [client 114.119.135.120:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.toddnielsen.com"] [uri "/leadership-scripting/effective-leadership-personal-success-through-scripting/"] [unique_id "al4g2BJHADqs2gAgBs-FDgAAALw"], referer: https://links.kannan-subbiah.com/2013/01/?m=0
[Mon Jul 20 07:21:28.495109 2026] [security2:error] [pid 110058:tid 110219] [client 77.110.127.138:64195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2BJHADqs2gAgBs-FHQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:28.495184 2026] [security2:error] [pid 110058:tid 110219] [client 77.110.127.138:64195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2BJHADqs2gAgBs-FHQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:28.594594 2026] [security2:error] [pid 110058:tid 110198] [client 49.47.218.174:32721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g2BJHADqs2gAgBs-FIwAAAI4"]
[Mon Jul 20 07:21:28.594704 2026] [security2:error] [pid 110058:tid 110198] [client 49.47.218.174:32721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g2BJHADqs2gAgBs-FIwAAAI4"]
[Mon Jul 20 07:21:28.611947 2026] [security2:error] [pid 110058:tid 110279] [client 103.176.215.66:62562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g2BJHADqs2gAgBs-FJgAAAN8"]
[Mon Jul 20 07:21:28.612055 2026] [security2:error] [pid 110058:tid 110279] [client 103.176.215.66:62562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g2BJHADqs2gAgBs-FJgAAAN8"]
[Mon Jul 20 07:21:28.770934 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2BJHADqs2gAgBs-FMgAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:28.771082 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2BJHADqs2gAgBs-FMgAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:28.797112 2026] [security2:error] [pid 110058:tid 110155] [remote 192.241.143.148:47694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4g2BJHADqs2gAgBs-FNAAA218"]
[Mon Jul 20 07:21:28.959980 2026] [security2:error] [pid 110058:tid 110160] [remote 192.241.143.148:47694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4g2BJHADqs2gAgBs-FPQAAmGQ"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:21:29.063144 2026] [security2:error] [pid 110058:tid 110313] [client 157.20.138.62:57897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FRQAAAQE"]
[Mon Jul 20 07:21:29.063239 2026] [security2:error] [pid 110058:tid 110313] [client 157.20.138.62:57897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FRQAAAQE"]
[Mon Jul 20 07:21:29.140165 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2RJHADqs2gAgBs-FUAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:29.140252 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2RJHADqs2gAgBs-FUAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:29.253431 2026] [security2:error] [pid 110058:tid 110170] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FUwAAo24"]
[Mon Jul 20 07:21:29.253547 2026] [security2:error] [pid 110058:tid 110219] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FUwAAo24"]
[Mon Jul 20 07:21:29.324825 2026] [security2:error] [pid 110058:tid 110173] [remote 103.74.123.7:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.123.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4g2RJHADqs2gAgBs-FWgAAtnE"]
[Mon Jul 20 07:21:29.388229 2026] [security2:error] [pid 110058:tid 110244] [client 88.241.67.160:56853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FYQAAALw"]
[Mon Jul 20 07:21:29.388817 2026] [security2:error] [pid 110058:tid 110244] [client 88.241.67.160:56853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FYQAAALw"]
[Mon Jul 20 07:21:29.431569 2026] [security2:error] [pid 110058:tid 110232] [client 36.93.152.155:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FZgAAALA"]
[Mon Jul 20 07:21:29.431658 2026] [security2:error] [pid 110058:tid 110232] [client 36.93.152.155:54227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FZgAAALA"]
[Mon Jul 20 07:21:29.571165 2026] [security2:error] [pid 110058:tid 110278] [client 191.202.66.27:58571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FdQAAAN4"]
[Mon Jul 20 07:21:29.571334 2026] [security2:error] [pid 110058:tid 110278] [client 191.202.66.27:58571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g2RJHADqs2gAgBs-FdQAAAN4"]
[Mon Jul 20 07:21:29.613025 2026] [security2:error] [pid 110058:tid 110210] [client 158.173.89.95:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4g2RJHADqs2gAgBs-FewAAAJo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:21:29.762040 2026] [security2:error] [pid 110058:tid 110068] [remote 103.74.123.7:64786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.123.74.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4g2RJHADqs2gAgBs-FggAAhwk"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 07:21:29.939432 2026] [security2:error] [pid 110058:tid 110314] [client 104.234.53.70:64689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4g2RJHADqs2gAgBs-FkAAAAQI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:29.946140 2026] [security2:error] [pid 110058:tid 110273] [client 165.227.111.134:59325] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.espiritualidadmoderna.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4g2RJHADqs2gAgBs-FiQAAANk"]
[Mon Jul 20 07:21:30.005074 2026] [security2:error] [pid 110058:tid 110222] [client 143.44.185.218:16787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g2hJHADqs2gAgBs-FnQAAAKY"]
[Mon Jul 20 07:21:30.005172 2026] [security2:error] [pid 110058:tid 110222] [client 143.44.185.218:16787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g2hJHADqs2gAgBs-FnQAAAKY"]
[Mon Jul 20 07:21:30.011044 2026] [security2:error] [pid 110058:tid 110231] [client 192.178.4.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.puppoopatrol.com"] [uri "/index.php"] [unique_id "al4g2RJHADqs2gAgBs-FiwAAAK8"]
[Mon Jul 20 07:21:30.125848 2026] [security2:error] [pid 110058:tid 110289] [client 77.110.127.138:64187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2hJHADqs2gAgBs-FrAAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:30.125975 2026] [security2:error] [pid 110058:tid 110289] [client 77.110.127.138:64187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2hJHADqs2gAgBs-FrAAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:30.166441 2026] [security2:error] [pid 110058:tid 110239] [client 57.141.18.12:38212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g1hJHADqs2gAgBs-EWgAAtww"]
[Mon Jul 20 07:21:30.177444 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2hJHADqs2gAgBs-FrgAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:30.177535 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2hJHADqs2gAgBs-FrgAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:30.332275 2026] [security2:error] [pid 110058:tid 110255] [client 77.110.127.138:64203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2hJHADqs2gAgBs-FuQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:30.332361 2026] [security2:error] [pid 110058:tid 110255] [client 77.110.127.138:64203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2hJHADqs2gAgBs-FuQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:30.503095 2026] [security2:error] [pid 110058:tid 110206] [client 104.234.53.49:64665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4g2hJHADqs2gAgBs-FywAAAJY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:30.576308 2026] [security2:error] [pid 110058:tid 110314] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4g2hJHADqs2gAgBs-FyQABAhg"], referer: http://aleishapenny.ca/2018
[Mon Jul 20 07:21:30.773929 2026] [security2:error] [pid 110058:tid 110222] [client 117.211.236.168:53873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4g2hJHADqs2gAgBs-F4gAAAKY"]
[Mon Jul 20 07:21:30.774028 2026] [security2:error] [pid 110058:tid 110222] [client 117.211.236.168:53873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4g2hJHADqs2gAgBs-F4gAAAKY"]
[Mon Jul 20 07:21:30.787541 2026] [security2:error] [pid 110058:tid 110094] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g2hJHADqs2gAgBs-F5AAA6CM"]
[Mon Jul 20 07:21:30.787705 2026] [security2:error] [pid 110058:tid 110288] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g2hJHADqs2gAgBs-F5AAA6CM"]
[Mon Jul 20 07:21:31.044860 2026] [security2:error] [pid 110058:tid 110272] [client 103.106.165.44:62176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g2xJHADqs2gAgBs-F9AAAANg"]
[Mon Jul 20 07:21:31.045013 2026] [security2:error] [pid 110058:tid 110272] [client 103.106.165.44:62176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g2xJHADqs2gAgBs-F9AAAANg"]
[Mon Jul 20 07:21:31.096102 2026] [fcgid:warn] [pid 110058:tid 110281] (70014)End of file found: [client 80.87.206.20:34248] mod_fcgid: can't get data from http client
[Mon Jul 20 07:21:31.098408 2026] [fcgid:warn] [pid 110058:tid 110271] (70014)End of file found: [client 80.87.206.20:34242] mod_fcgid: can't get data from http client
[Mon Jul 20 07:21:31.108482 2026] [fcgid:warn] [pid 110058:tid 110226] (70014)End of file found: [client 80.87.206.20:34244] mod_fcgid: can't get data from http client
[Mon Jul 20 07:21:31.111898 2026] [fcgid:warn] [pid 110058:tid 110200] (70014)End of file found: [client 80.87.206.20:34246] mod_fcgid: can't get data from http client
[Mon Jul 20 07:21:31.136232 2026] [security2:error] [pid 110058:tid 110196] [client 57.141.18.104:32260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g1xJHADqs2gAgBs-EsQAAjCo"]
[Mon Jul 20 07:21:31.225326 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2xJHADqs2gAgBs-GCAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:31.225437 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2xJHADqs2gAgBs-GCAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:31.296799 2026] [security2:error] [pid 110058:tid 110283] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4g2xJHADqs2gAgBs-GBwAA4zE"], referer: https://aleishapenny.ca/2018
[Mon Jul 20 07:21:31.577995 2026] [security2:error] [pid 110058:tid 110285] [client 77.110.127.138:64211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2xJHADqs2gAgBs-GHgAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:31.578159 2026] [security2:error] [pid 110058:tid 110285] [client 77.110.127.138:64211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g2xJHADqs2gAgBs-GHgAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:31.625330 2026] [security2:error] [pid 110058:tid 110117] [remote 165.227.39.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.39.227.165.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sustaintheart.com"] [uri "/info.php"] [unique_id "al4g2xJHADqs2gAgBs-GIQAA0Do"]
[Mon Jul 20 07:21:31.781798 2026] [security2:error] [pid 110058:tid 110237] [client 104.234.53.57:37803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g2xJHADqs2gAgBs-GLAAAALU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:31.882640 2026] [security2:error] [pid 110058:tid 110126] [remote 154.66.198.148:2882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g2xJHADqs2gAgBs-GMwAAzEI"]
[Mon Jul 20 07:21:31.882829 2026] [security2:error] [pid 110058:tid 110260] [client 154.66.198.148:2882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g2xJHADqs2gAgBs-GMwAAzEI"]
[Mon Jul 20 07:21:32.041389 2026] [security2:error] [pid 110058:tid 110307] [client 77.110.127.138:64218] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at REQUEST_HEADERS:x-requested-with. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/6-tips-for-a-perfect-starting-ring-for-crochet-motifs/"] [unique_id "al4g3BJHADqs2gAgBs-GOwAAAPs"]
[Mon Jul 20 07:21:32.043631 2026] [security2:error] [pid 110058:tid 110272] [client 201.27.111.74:65027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g3BJHADqs2gAgBs-GPAAAANg"]
[Mon Jul 20 07:21:32.047160 2026] [security2:error] [pid 110058:tid 110272] [client 201.27.111.74:65027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g3BJHADqs2gAgBs-GPAAAANg"]
[Mon Jul 20 07:21:32.329308 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3BJHADqs2gAgBs-GXAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:32.329429 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3BJHADqs2gAgBs-GXAAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:32.408123 2026] [security2:error] [pid 110058:tid 110246] [client 57.141.18.59:38704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g2BJHADqs2gAgBs-FDAAAvlA"]
[Mon Jul 20 07:21:32.455199 2026] [security2:error] [pid 110058:tid 110196] [client 154.192.123.127:18198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g3BJHADqs2gAgBs-GZgAAAIw"]
[Mon Jul 20 07:21:32.455381 2026] [security2:error] [pid 110058:tid 110196] [client 154.192.123.127:18198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g3BJHADqs2gAgBs-GZgAAAIw"]
[Mon Jul 20 07:21:32.463164 2026] [security2:error] [pid 110058:tid 110229] [client 104.234.53.73:62411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4g3BJHADqs2gAgBs-GZwAAAK0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:32.506436 2026] [security2:error] [pid 110058:tid 110239] [client 98.159.234.160:38441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4g3BJHADqs2gAgBs-GagAAALc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:21:32.594693 2026] [security2:error] [pid 110058:tid 110247] [client 77.110.127.138:64229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3BJHADqs2gAgBs-GcQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:32.594810 2026] [security2:error] [pid 110058:tid 110247] [client 77.110.127.138:64229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3BJHADqs2gAgBs-GcQAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:33.077527 2026] [security2:error] [pid 110058:tid 110213] [client 187.16.64.216:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g3RJHADqs2gAgBs-GjwAAAJ0"]
[Mon Jul 20 07:21:33.077672 2026] [security2:error] [pid 110058:tid 110213] [client 187.16.64.216:65519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g3RJHADqs2gAgBs-GjwAAAJ0"]
[Mon Jul 20 07:21:33.106079 2026] [security2:error] [pid 110058:tid 110268] [client 104.234.53.70:63951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4g3RJHADqs2gAgBs-GkQAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:33.162140 2026] [security2:error] [pid 110058:tid 110209] [client 49.37.242.14:59811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g3RJHADqs2gAgBs-GmQAAAJk"]
[Mon Jul 20 07:21:33.162249 2026] [security2:error] [pid 110058:tid 110209] [client 49.37.242.14:59811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g3RJHADqs2gAgBs-GmQAAAJk"]
[Mon Jul 20 07:21:33.230985 2026] [security2:error] [pid 110058:tid 110310] [client 57.141.18.46:63536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g2RJHADqs2gAgBs-FRAAA_mg"]
[Mon Jul 20 07:21:34.078412 2026] [security2:error] [pid 110058:tid 110289] [client 14.225.17.146:62399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4g3BJHADqs2gAgBs-GiAAAAOk"], referer: http://sarahholyfield.com/2018
[Mon Jul 20 07:21:34.256152 2026] [security2:error] [pid 110058:tid 110207] [client 77.110.127.138:64240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3hJHADqs2gAgBs-G9wAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:34.256247 2026] [security2:error] [pid 110058:tid 110207] [client 77.110.127.138:64240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3hJHADqs2gAgBs-G9wAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:34.323423 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3hJHADqs2gAgBs-G-wAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:34.323557 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3hJHADqs2gAgBs-G-wAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:34.449105 2026] [security2:error] [pid 110058:tid 110260] [client 77.110.127.138:64241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3hJHADqs2gAgBs-HBQAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:34.449203 2026] [security2:error] [pid 110058:tid 110260] [client 77.110.127.138:64241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3hJHADqs2gAgBs-HBQAAAMw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:34.558486 2026] [security2:error] [pid 110058:tid 110226] [client 136.158.60.21:59375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g3hJHADqs2gAgBs-HCgAAAKo"]
[Mon Jul 20 07:21:34.558643 2026] [security2:error] [pid 110058:tid 110226] [client 136.158.60.21:59375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g3hJHADqs2gAgBs-HCgAAAKo"]
[Mon Jul 20 07:21:34.751928 2026] [security2:error] [pid 110058:tid 110250] [client 14.225.17.146:52429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4g3hJHADqs2gAgBs-HAAAAAMI"], referer: http://idigress.group/2018
[Mon Jul 20 07:21:34.763806 2026] [security2:error] [pid 110058:tid 110302] [client 57.141.18.45:59994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g2hJHADqs2gAgBs-FzQAA9hk"]
[Mon Jul 20 07:21:34.779983 2026] [security2:error] [pid 110058:tid 110205] [client 104.234.53.67:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4g3hJHADqs2gAgBs-HJAAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:34.783804 2026] [security2:error] [pid 110058:tid 110198] [client 57.141.18.30:56278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g2hJHADqs2gAgBs-F2AAAjh8"]
[Mon Jul 20 07:21:34.794207 2026] [security2:error] [pid 110058:tid 110224] [client 14.225.17.146:52049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4g3RJHADqs2gAgBs-G3QAAAKg"], referer: http://walkingandtalking.net/2018
[Mon Jul 20 07:21:35.210710 2026] [security2:error] [pid 110058:tid 110103] [remote 152.228.213.32:37038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g3xJHADqs2gAgBs-HPQAAmSw"]
[Mon Jul 20 07:21:35.210891 2026] [security2:error] [pid 110058:tid 110209] [client 152.228.213.32:37038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4g3xJHADqs2gAgBs-HPQAAmSw"]
[Mon Jul 20 07:21:35.391859 2026] [security2:error] [pid 110058:tid 110218] [client 74.208.214.194:49364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4g3xJHADqs2gAgBs-HUAAAAKI"]
[Mon Jul 20 07:21:35.438958 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:60241] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4g3xJHADqs2gAgBs-HQwAAAME"]
[Mon Jul 20 07:21:35.455086 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3xJHADqs2gAgBs-HVgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:35.455187 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3xJHADqs2gAgBs-HVgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:35.516859 2026] [security2:error] [pid 110058:tid 110239] [client 57.141.18.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "uninursity.com"] [uri "/index.php"] [unique_id "al4g3RJHADqs2gAgBs-GpgAAALc"]
[Mon Jul 20 07:21:35.573532 2026] [autoindex:error] [pid 110058:tid 110302] [client 167.71.3.243:41512] AH01276: Cannot serve directory /home2/pukjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:21:35.606184 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3xJHADqs2gAgBs-HYAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:35.606282 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3xJHADqs2gAgBs-HYAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:35.665092 2026] [security2:error] [pid 110058:tid 110206] [client 14.225.17.146:60302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4g3xJHADqs2gAgBs-HZQAAAJY"], referer: https://walkingandtalking.net/2018
[Mon Jul 20 07:21:35.743105 2026] [security2:error] [pid 110058:tid 110254] [client 77.110.127.138:64249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3xJHADqs2gAgBs-HawAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:35.743205 2026] [security2:error] [pid 110058:tid 110254] [client 77.110.127.138:64249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g3xJHADqs2gAgBs-HawAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:36.160253 2026] [security2:error] [pid 110058:tid 110278] [client 103.144.65.217:62018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.65.144.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4g4BJHADqs2gAgBs-HkgAAAN4"]
[Mon Jul 20 07:21:36.160396 2026] [security2:error] [pid 110058:tid 110278] [client 103.144.65.217:62018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "codykkline.com"] [uri "/xmlrpc.php"] [unique_id "al4g4BJHADqs2gAgBs-HkgAAAN4"]
[Mon Jul 20 07:21:36.224019 2026] [security2:error] [pid 110058:tid 110190] [client 154.208.48.130:61488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g4BJHADqs2gAgBs-HlQAAAIY"]
[Mon Jul 20 07:21:36.224156 2026] [security2:error] [pid 110058:tid 110190] [client 154.208.48.130:61488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g4BJHADqs2gAgBs-HlQAAAIY"]
[Mon Jul 20 07:21:36.243885 2026] [security2:error] [pid 110058:tid 110256] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g4BJHADqs2gAgBs-HhgAAAMg"], referer: 1'"3000
[Mon Jul 20 07:21:36.557209 2026] [security2:error] [pid 110058:tid 110313] [client 77.110.127.138:64256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4BJHADqs2gAgBs-HtAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:36.557317 2026] [security2:error] [pid 110058:tid 110313] [client 77.110.127.138:64256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4BJHADqs2gAgBs-HtAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:36.825696 2026] [security2:error] [pid 110058:tid 110203] [client 202.141.11.99:24550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4g4BJHADqs2gAgBs-HxQAAAJM"]
[Mon Jul 20 07:21:36.825822 2026] [security2:error] [pid 110058:tid 110203] [client 202.141.11.99:24550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4g4BJHADqs2gAgBs-HxQAAAJM"]
[Mon Jul 20 07:21:37.183232 2026] [security2:error] [pid 110058:tid 110294] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g4BJHADqs2gAgBs-H1wAAAO4"], referer: 1'"3000
[Mon Jul 20 07:21:37.390259 2026] [security2:error] [pid 110058:tid 110236] [client 77.110.127.138:64263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4RJHADqs2gAgBs-H8gAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:37.390340 2026] [security2:error] [pid 110058:tid 110236] [client 77.110.127.138:64263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4RJHADqs2gAgBs-H8gAAALQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:37.414830 2026] [security2:error] [pid 110058:tid 110214] [client 52.233.165.60:25153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4g4RJHADqs2gAgBs-H8wAAAJ4"]
[Mon Jul 20 07:21:37.552794 2026] [security2:error] [pid 110058:tid 110192] [client 20.245.75.247:1537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4g4RJHADqs2gAgBs-IAAAAAIg"]
[Mon Jul 20 07:21:37.571845 2026] [security2:error] [pid 110058:tid 110280] [client 52.233.165.60:25153] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4g4RJHADqs2gAgBs-IAQAAAOA"]
[Mon Jul 20 07:21:37.572849 2026] [security2:error] [pid 110058:tid 110190] [client 20.245.75.247:1537] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4g4RJHADqs2gAgBs-IAgAAAIY"]
[Mon Jul 20 07:21:37.891594 2026] [security2:error] [pid 110058:tid 110226] [client 14.225.17.146:51183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4g4BJHADqs2gAgBs-HvgAAAKo"], referer: http://mourgroup.com/2018
[Mon Jul 20 07:21:37.921931 2026] [security2:error] [pid 110058:tid 110238] [client 77.110.127.138:64235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4RJHADqs2gAgBs-IHQAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:37.922039 2026] [security2:error] [pid 110058:tid 110238] [client 77.110.127.138:64235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4RJHADqs2gAgBs-IHQAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:37.976478 2026] [security2:error] [pid 110058:tid 110218] [client 77.110.127.138:64248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4RJHADqs2gAgBs-IJAAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:37.976593 2026] [security2:error] [pid 110058:tid 110218] [client 77.110.127.138:64248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4RJHADqs2gAgBs-IJAAAAKI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.090364 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:64202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IJwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.090467 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:64202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IJwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.160526 2026] [security2:error] [pid 110058:tid 110248] [client 77.110.127.138:64251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-ILAAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.160642 2026] [security2:error] [pid 110058:tid 110248] [client 77.110.127.138:64251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-ILAAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.280109 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-INwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.280229 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-INwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.316765 2026] [security2:error] [pid 110058:tid 110305] [client 77.110.127.138:64270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IPAAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.316852 2026] [security2:error] [pid 110058:tid 110305] [client 77.110.127.138:64270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IPAAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.330264 2026] [security2:error] [pid 110058:tid 110195] [client 77.110.127.138:64243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IPwAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.330397 2026] [security2:error] [pid 110058:tid 110195] [client 77.110.127.138:64243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IPwAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.396252 2026] [security2:error] [pid 110058:tid 110279] [client 14.225.17.146:52488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4g4BJHADqs2gAgBs-HrQAAAN8"], referer: http://securingmemories.com/2018
[Mon Jul 20 07:21:38.433972 2026] [security2:error] [pid 110058:tid 110069] [remote 103.118.29.185:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4g4hJHADqs2gAgBs-ISwAAqQo"]
[Mon Jul 20 07:21:38.483512 2026] [security2:error] [pid 110058:tid 110299] [client 77.110.127.138:64271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IUAAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.483642 2026] [security2:error] [pid 110058:tid 110299] [client 77.110.127.138:64271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g4hJHADqs2gAgBs-IUAAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:38.564312 2026] [security2:error] [pid 110058:tid 110316] [client 14.225.17.146:52184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4g4BJHADqs2gAgBs-H0AAAAQQ"], referer: http://cheesewithjam.com/2018
[Mon Jul 20 07:21:38.867043 2026] [security2:error] [pid 110058:tid 110088] [remote 103.118.29.185:43924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4g4hJHADqs2gAgBs-IbwAAuh0"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:21:39.121608 2026] [security2:error] [pid 110058:tid 110267] [client 49.47.218.174:58165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IiAAAANM"]
[Mon Jul 20 07:21:39.121777 2026] [security2:error] [pid 110058:tid 110267] [client 49.47.218.174:58165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IiAAAANM"]
[Mon Jul 20 07:21:39.163357 2026] [security2:error] [pid 110058:tid 110215] [client 57.141.18.40:22828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g3hJHADqs2gAgBs-HEwAAnyI"]
[Mon Jul 20 07:21:39.256472 2026] [security2:error] [pid 110058:tid 110213] [client 103.176.215.66:63091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IjgAAAJ0"]
[Mon Jul 20 07:21:39.256665 2026] [security2:error] [pid 110058:tid 110213] [client 103.176.215.66:63091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IjgAAAJ0"]
[Mon Jul 20 07:21:39.312424 2026] [security2:error] [pid 110058:tid 110239] [client 14.225.17.146:62444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4g4RJHADqs2gAgBs-IIwAAALc"], referer: http://momheadquarters.com/2018
[Mon Jul 20 07:21:39.476118 2026] [security2:error] [pid 110058:tid 110299] [client 14.225.17.146:62435] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4g4xJHADqs2gAgBs-IewAAAPM"]
[Mon Jul 20 07:21:39.492678 2026] [security2:error] [pid 110058:tid 110263] [client 14.225.17.146:52148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4g4hJHADqs2gAgBs-IKAAAAM8"], referer: http://balticsteelmgmt.com/2018
[Mon Jul 20 07:21:39.689891 2026] [security2:error] [pid 110058:tid 110275] [client 157.20.138.62:58463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IsAAAANs"]
[Mon Jul 20 07:21:39.690053 2026] [security2:error] [pid 110058:tid 110275] [client 157.20.138.62:58463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IsAAAANs"]
[Mon Jul 20 07:21:39.751097 2026] [security2:error] [pid 110058:tid 110251] [client 14.225.17.146:51154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4g4hJHADqs2gAgBs-IdQAAAMM"]
[Mon Jul 20 07:21:39.794597 2026] [security2:error] [pid 110058:tid 110261] [client 104.234.53.52:36953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4g4xJHADqs2gAgBs-IuAAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:39.891065 2026] [security2:error] [pid 110058:tid 110123] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IwQAAnz8"]
[Mon Jul 20 07:21:39.891235 2026] [security2:error] [pid 110058:tid 110215] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IwQAAnz8"]
[Mon Jul 20 07:21:39.932294 2026] [security2:error] [pid 110058:tid 110314] [client 36.93.152.155:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IxQAAAQI"]
[Mon Jul 20 07:21:39.932389 2026] [security2:error] [pid 110058:tid 110314] [client 36.93.152.155:54726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g4xJHADqs2gAgBs-IxQAAAQI"]
[Mon Jul 20 07:21:39.940404 2026] [security2:error] [pid 110058:tid 110250] [client 223.109.252.215:36690] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "timespans.org"] [uri "/"] [unique_id "al4g4xJHADqs2gAgBs-IxgAAAMI"]
[Mon Jul 20 07:21:39.940485 2026] [security2:error] [pid 110058:tid 110250] [client 223.109.252.215:36690] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "timespans.org"] [uri "/"] [unique_id "al4g4xJHADqs2gAgBs-IxgAAAMI"]
[Mon Jul 20 07:21:39.989178 2026] [proxy:error] [pid 110058:tid 110266] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:21:39.989224 2026] [proxy_http:error] [pid 110058:tid 110266] [client 205.210.31.51:64412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:21:39.989874 2026] [proxy:error] [pid 110058:tid 110266] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:21:39.989901 2026] [proxy_http:error] [pid 110058:tid 110266] [client 205.210.31.51:64412] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:21:40.031487 2026] [security2:error] [pid 110058:tid 110296] [client 88.241.67.160:54353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g5BJHADqs2gAgBs-IzQAAAPA"]
[Mon Jul 20 07:21:40.031797 2026] [security2:error] [pid 110058:tid 110296] [client 88.241.67.160:54353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g5BJHADqs2gAgBs-IzQAAAPA"]
[Mon Jul 20 07:21:40.219433 2026] [security2:error] [pid 110058:tid 110118] [remote 100.42.189.89:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4g5BJHADqs2gAgBs-I1QABADs"]
[Mon Jul 20 07:21:40.233153 2026] [security2:error] [pid 110058:tid 110302] [client 191.202.66.27:59059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g5BJHADqs2gAgBs-I1gAAAPY"]
[Mon Jul 20 07:21:40.233277 2026] [security2:error] [pid 110058:tid 110302] [client 191.202.66.27:59059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g5BJHADqs2gAgBs-I1gAAAPY"]
[Mon Jul 20 07:21:40.418158 2026] [security2:error] [pid 110058:tid 110131] [remote 100.42.189.89:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4g5BJHADqs2gAgBs-I6QAAw0c"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:21:40.700701 2026] [security2:error] [pid 110058:tid 110203] [client 143.44.185.218:18003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g5BJHADqs2gAgBs-JBAAAAJM"]
[Mon Jul 20 07:21:40.700834 2026] [security2:error] [pid 110058:tid 110203] [client 143.44.185.218:18003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g5BJHADqs2gAgBs-JBAAAAJM"]
[Mon Jul 20 07:21:40.788091 2026] [security2:error] [pid 110058:tid 110215] [client 104.234.53.64:35867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g5BJHADqs2gAgBs-JBQAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:40.868600 2026] [security2:error] [pid 110058:tid 110127] [remote 173.249.4.11:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4g5BJHADqs2gAgBs-JDwAA80M"]
[Mon Jul 20 07:21:40.902287 2026] [security2:error] [pid 110058:tid 110276] [client 77.110.127.138:64275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5BJHADqs2gAgBs-JEwAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:40.902673 2026] [security2:error] [pid 110058:tid 110276] [client 77.110.127.138:64275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5BJHADqs2gAgBs-JEwAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.060857 2026] [security2:error] [pid 110058:tid 110153] [remote 173.249.4.11:52482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4g5RJHADqs2gAgBs-JJAAAlF0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:21:41.111543 2026] [security2:error] [pid 110058:tid 110201] [client 77.110.127.138:64279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JKAAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.111636 2026] [security2:error] [pid 110058:tid 110201] [client 77.110.127.138:64279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JKAAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.218778 2026] [security2:error] [pid 110058:tid 110254] [client 50.116.65.227:58390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4g5BJHADqs2gAgBs-I9AAAAMY"]
[Mon Jul 20 07:21:41.402413 2026] [security2:error] [pid 110058:tid 110218] [client 50.116.65.227:58406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4g5RJHADqs2gAgBs-JPQAAAKI"]
[Mon Jul 20 07:21:41.413273 2026] [security2:error] [pid 110058:tid 110300] [client 50.116.65.227:58418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4g5RJHADqs2gAgBs-JPgAAAPQ"]
[Mon Jul 20 07:21:41.464239 2026] [security2:error] [pid 110058:tid 110151] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g5RJHADqs2gAgBs-JQgAAmVs"]
[Mon Jul 20 07:21:41.464383 2026] [security2:error] [pid 110058:tid 110209] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g5RJHADqs2gAgBs-JQgAAmVs"]
[Mon Jul 20 07:21:41.470042 2026] [security2:error] [pid 110058:tid 110291] [client 77.110.127.138:64282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JQwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.470124 2026] [security2:error] [pid 110058:tid 110291] [client 77.110.127.138:64282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JQwAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.520523 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JRwAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.520661 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JRwAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:41.532322 2026] [security2:error] [pid 110058:tid 110303] [client 14.225.17.146:59971] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4g5RJHADqs2gAgBs-JOgAAAPc"], referer: http://laceycaraccident.com/2018
[Mon Jul 20 07:21:41.588946 2026] [security2:error] [pid 110058:tid 110233] [client 77.110.127.138:64284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JTwAAALE"]
[Mon Jul 20 07:21:41.589053 2026] [security2:error] [pid 110058:tid 110233] [client 77.110.127.138:64284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5RJHADqs2gAgBs-JTwAAALE"]
[Mon Jul 20 07:21:41.620376 2026] [security2:error] [pid 110058:tid 110306] [client 103.106.165.44:62633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g5RJHADqs2gAgBs-JUQAAAPo"]
[Mon Jul 20 07:21:41.620513 2026] [security2:error] [pid 110058:tid 110306] [client 103.106.165.44:62633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g5RJHADqs2gAgBs-JUQAAAPo"]
[Mon Jul 20 07:21:41.901721 2026] [security2:error] [pid 110058:tid 110178] [remote 57.141.18.39:40743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3637375"] [unique_id "al4g5RJHADqs2gAgBs-JZwAA1XY"]
[Mon Jul 20 07:21:41.907155 2026] [security2:error] [pid 110058:tid 110240] [client 50.116.65.227:58396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4g5RJHADqs2gAgBs-JLwAAALg"]
[Mon Jul 20 07:21:41.993893 2026] [security2:error] [pid 110058:tid 110197] [client 57.141.18.39:32907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g4RJHADqs2gAgBs-H5QAAjWs"]
[Mon Jul 20 07:21:42.243302 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5hJHADqs2gAgBs-JhQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:42.243418 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5hJHADqs2gAgBs-JhQAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:42.625206 2026] [security2:error] [pid 110058:tid 110275] [client 14.225.17.146:57651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4g5BJHADqs2gAgBs-I_QAAANs"], referer: http://floorsourcestock.com/2018
[Mon Jul 20 07:21:42.775260 2026] [security2:error] [pid 110058:tid 110306] [client 201.27.111.74:49358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g5hJHADqs2gAgBs-JqgAAAPo"]
[Mon Jul 20 07:21:42.775398 2026] [security2:error] [pid 110058:tid 110306] [client 201.27.111.74:49358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g5hJHADqs2gAgBs-JqgAAAPo"]
[Mon Jul 20 07:21:42.842230 2026] [security2:error] [pid 110058:tid 110197] [client 77.110.127.138:64272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5hJHADqs2gAgBs-JsQAAAI0"]
[Mon Jul 20 07:21:42.842355 2026] [security2:error] [pid 110058:tid 110197] [client 77.110.127.138:64272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g5hJHADqs2gAgBs-JsQAAAI0"]
[Mon Jul 20 07:21:42.944948 2026] [security2:error] [pid 110058:tid 110212] [client 154.192.123.127:18720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g5hJHADqs2gAgBs-JtwAAAJw"]
[Mon Jul 20 07:21:42.945052 2026] [security2:error] [pid 110058:tid 110212] [client 154.192.123.127:18720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g5hJHADqs2gAgBs-JtwAAAJw"]
[Mon Jul 20 07:21:43.011562 2026] [security2:error] [pid 110058:tid 110247] [client 14.225.17.146:51600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4g5RJHADqs2gAgBs-JZQAAAL8"], referer: http://lutheranphilosopher.com/2018
[Mon Jul 20 07:21:43.382455 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g5hJHADqs2gAgBs-JwgAAAP8"]
[Mon Jul 20 07:21:43.771929 2026] [security2:error] [pid 110058:tid 110198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g5xJHADqs2gAgBs-J-QAAAI4"]
[Mon Jul 20 07:21:43.828574 2026] [security2:error] [pid 110058:tid 110302] [client 187.16.64.216:49724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g5xJHADqs2gAgBs-KFAAAAPY"]
[Mon Jul 20 07:21:43.828672 2026] [security2:error] [pid 110058:tid 110302] [client 187.16.64.216:49724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g5xJHADqs2gAgBs-KFAAAAPY"]
[Mon Jul 20 07:21:43.856641 2026] [security2:error] [pid 110058:tid 110272] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g5xJHADqs2gAgBs-KAAAAANg"]
[Mon Jul 20 07:21:44.450962 2026] [security2:error] [pid 110058:tid 110230] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g6BJHADqs2gAgBs-KOAAAAK4"]
[Mon Jul 20 07:21:44.704664 2026] [security2:error] [pid 110058:tid 110267] [client 77.110.127.138:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g6BJHADqs2gAgBs-KXAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:44.704829 2026] [security2:error] [pid 110058:tid 110267] [client 77.110.127.138:64269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g6BJHADqs2gAgBs-KXAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:44.755826 2026] [security2:error] [pid 110058:tid 110242] [client 77.110.127.138:64277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g6BJHADqs2gAgBs-KXwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:44.755918 2026] [security2:error] [pid 110058:tid 110242] [client 77.110.127.138:64277] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g6BJHADqs2gAgBs-KXwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:44.862242 2026] [security2:error] [pid 110058:tid 110280] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g6BJHADqs2gAgBs-KWwAAAOA"]
[Mon Jul 20 07:21:44.922363 2026] [security2:error] [pid 110058:tid 110316] [client 14.182.195.220:52673] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4g6BJHADqs2gAgBs-KcwAAAQQ"]
[Mon Jul 20 07:21:45.147013 2026] [security2:error] [pid 110058:tid 110238] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g6BJHADqs2gAgBs-KbgAAALY"]
[Mon Jul 20 07:21:45.263723 2026] [security2:error] [pid 110058:tid 110294] [client 136.158.60.21:61105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g6RJHADqs2gAgBs-KhgAAAO4"]
[Mon Jul 20 07:21:45.263846 2026] [security2:error] [pid 110058:tid 110294] [client 136.158.60.21:61105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g6RJHADqs2gAgBs-KhgAAAO4"]
[Mon Jul 20 07:21:45.911776 2026] [security2:error] [pid 110058:tid 110230] [client 49.37.242.14:60297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g6RJHADqs2gAgBs-KzAAAAK4"]
[Mon Jul 20 07:21:45.911903 2026] [security2:error] [pid 110058:tid 110230] [client 49.37.242.14:60297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g6RJHADqs2gAgBs-KzAAAAK4"]
[Mon Jul 20 07:21:46.116896 2026] [security2:error] [pid 110058:tid 110219] [client 57.141.18.117:36812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g5RJHADqs2gAgBs-JXgAAo3E"]
[Mon Jul 20 07:21:46.242849 2026] [security2:error] [pid 110058:tid 110283] [client 14.225.17.146:57934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4g6hJHADqs2gAgBs-K1QAAAOM"], referer: http://expertcultures.com/2018
[Mon Jul 20 07:21:46.273492 2026] [security2:error] [pid 110058:tid 110245] [client 14.191.166.100:32717] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4g6hJHADqs2gAgBs-K2AAAAL0"]
[Mon Jul 20 07:21:46.459935 2026] [security2:error] [pid 110058:tid 110241] [client 57.141.18.116:43276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g5hJHADqs2gAgBs-JgQAAuQY"]
[Mon Jul 20 07:21:47.712986 2026] [security2:error] [pid 110058:tid 110259] [client 154.208.48.130:62016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g6xJHADqs2gAgBs-LTQAAAMs"]
[Mon Jul 20 07:21:47.714602 2026] [security2:error] [pid 110058:tid 110259] [client 154.208.48.130:62016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g6xJHADqs2gAgBs-LTQAAAMs"]
[Mon Jul 20 07:21:47.751064 2026] [security2:error] [pid 110058:tid 110096] [remote 157.66.26.183:55338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g6xJHADqs2gAgBs-LUAAAhyU"]
[Mon Jul 20 07:21:47.751493 2026] [autoindex:error] [pid 110058:tid 110101] [remote 34.75.194.172:64724] AH01276: Cannot serve directory /home2/cxrmhtmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.cxr.mht.mybluehost.me
[Mon Jul 20 07:21:48.012828 2026] [security2:error] [pid 110058:tid 110225] [client 57.141.18.117:36818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g5xJHADqs2gAgBs-KEQAAqS0"]
[Mon Jul 20 07:21:48.160090 2026] [security2:error] [pid 110058:tid 110114] [remote 157.66.26.183:55338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g7BJHADqs2gAgBs-LcwAA8jc"], referer: https://friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:48.325602 2026] [security2:error] [pid 110058:tid 110243] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7BJHADqs2gAgBs-LcQAAALs"]
[Mon Jul 20 07:21:48.362267 2026] [security2:error] [pid 110058:tid 110251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7BJHADqs2gAgBs-LcgAAAMM"]
[Mon Jul 20 07:21:48.539065 2026] [security2:error] [pid 110058:tid 110208] [client 46.110.96.34:34723] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4g7BJHADqs2gAgBs-LnwAAAJg"]
[Mon Jul 20 07:21:48.742337 2026] [security2:error] [pid 110058:tid 110191] [client 14.225.17.146:58863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4g7BJHADqs2gAgBs-LlgAAAIc"], referer: http://maxenengineering.com/2018
[Mon Jul 20 07:21:48.769734 2026] [security2:error] [pid 110058:tid 110222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7BJHADqs2gAgBs-LngAAAKY"]
[Mon Jul 20 07:21:48.848332 2026] [security2:error] [pid 110058:tid 110304] [client 13.233.207.33:30292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4g7BJHADqs2gAgBs-LrgAAAPg"]
[Mon Jul 20 07:21:48.848444 2026] [security2:error] [pid 110058:tid 110304] [client 13.233.207.33:30292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4g7BJHADqs2gAgBs-LrgAAAPg"]
[Mon Jul 20 07:21:48.870049 2026] [security2:error] [pid 110058:tid 110280] [client 14.225.17.146:60523] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4g6xJHADqs2gAgBs-LNQAAAOA"], referer: http://guidehunting.com/2018
[Mon Jul 20 07:21:49.177710 2026] [security2:error] [pid 110058:tid 110316] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7BJHADqs2gAgBs-LvwAAAQQ"]
[Mon Jul 20 07:21:49.259734 2026] [security2:error] [pid 110058:tid 110208] [client 77.110.127.138:64314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g7RJHADqs2gAgBs-LzgAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:49.259870 2026] [security2:error] [pid 110058:tid 110208] [client 77.110.127.138:64314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g7RJHADqs2gAgBs-LzgAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:49.348573 2026] [security2:error] [pid 110058:tid 110215] [client 14.225.17.146:57928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4g6xJHADqs2gAgBs-LTAAAAJ8"], referer: http://ksands.co.uk/2018
[Mon Jul 20 07:21:49.558638 2026] [security2:error] [pid 110058:tid 110258] [client 49.47.218.174:58680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g7RJHADqs2gAgBs-L8AAAAMo"]
[Mon Jul 20 07:21:49.558985 2026] [security2:error] [pid 110058:tid 110258] [client 49.47.218.174:58680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g7RJHADqs2gAgBs-L8AAAAMo"]
[Mon Jul 20 07:21:49.561478 2026] [security2:error] [pid 110058:tid 110196] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7RJHADqs2gAgBs-L1wAAAIw"]
[Mon Jul 20 07:21:49.659031 2026] [security2:error] [pid 110058:tid 110299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7RJHADqs2gAgBs-L6QAAAPM"]
[Mon Jul 20 07:21:49.707115 2026] [security2:error] [pid 110058:tid 110227] [client 14.225.17.146:58989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4g7RJHADqs2gAgBs-L9gAAAKs"], referer: https://maxenengineering.com/2018
[Mon Jul 20 07:21:49.812977 2026] [security2:error] [pid 110058:tid 110269] [client 103.176.215.66:63625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g7RJHADqs2gAgBs-MCAAAANU"]
[Mon Jul 20 07:21:49.813458 2026] [security2:error] [pid 110058:tid 110269] [client 103.176.215.66:63625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g7RJHADqs2gAgBs-MCAAAANU"]
[Mon Jul 20 07:21:50.081404 2026] [security2:error] [pid 110058:tid 110221] [client 14.225.17.146:58905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4g7RJHADqs2gAgBs-MBwAAAKU"], referer: https://guidehunting.com/2018
[Mon Jul 20 07:21:50.193447 2026] [security2:error] [pid 110058:tid 110202] [client 157.20.138.62:59023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MLAAAAJI"]
[Mon Jul 20 07:21:50.193557 2026] [security2:error] [pid 110058:tid 110202] [client 157.20.138.62:59023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MLAAAAJI"]
[Mon Jul 20 07:21:50.393045 2026] [security2:error] [pid 110058:tid 110198] [client 14.225.17.146:60497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4g7RJHADqs2gAgBs-LzQAAAI4"], referer: http://northbrookcpa.ca/2018
[Mon Jul 20 07:21:50.449499 2026] [security2:error] [pid 110058:tid 110219] [client 36.93.152.155:55231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MPgAAAKM"]
[Mon Jul 20 07:21:50.449576 2026] [security2:error] [pid 110058:tid 110219] [client 36.93.152.155:55231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MPgAAAKM"]
[Mon Jul 20 07:21:50.546507 2026] [security2:error] [pid 110058:tid 110183] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MRgAAsHs"]
[Mon Jul 20 07:21:50.546629 2026] [security2:error] [pid 110058:tid 110232] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MRgAAsHs"]
[Mon Jul 20 07:21:50.582767 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:64321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g7hJHADqs2gAgBs-MSQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:50.582847 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:64321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g7hJHADqs2gAgBs-MSQAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:50.584572 2026] [security2:error] [pid 110058:tid 110269] [client 88.241.67.160:57179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MSgAAANU"]
[Mon Jul 20 07:21:50.585191 2026] [security2:error] [pid 110058:tid 110269] [client 88.241.67.160:57179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MSgAAANU"]
[Mon Jul 20 07:21:50.660556 2026] [security2:error] [pid 110058:tid 110307] [client 191.202.66.27:59539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MVwAAAPs"]
[Mon Jul 20 07:21:50.660730 2026] [security2:error] [pid 110058:tid 110307] [client 191.202.66.27:59539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g7hJHADqs2gAgBs-MVwAAAPs"]
[Mon Jul 20 07:21:50.759890 2026] [core:error] [pid 110058:tid 110202] [client 185.247.137.126:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:50.759917 2026] [core:error] [pid 110058:tid 110202] [client 185.247.137.126:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:21:50.770471 2026] [security2:error] [pid 110058:tid 110068] [remote 217.61.143.92:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4g7hJHADqs2gAgBs-MXgAA6Ak"]
[Mon Jul 20 07:21:50.878799 2026] [security2:error] [pid 110058:tid 110237] [client 57.141.18.64:43720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g6hJHADqs2gAgBs-LDQAAtR0"]
[Mon Jul 20 07:21:50.901214 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7hJHADqs2gAgBs-MWAAAAIc"]
[Mon Jul 20 07:21:50.998972 2026] [security2:error] [pid 110058:tid 110066] [remote 217.61.143.92:52228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4g7hJHADqs2gAgBs-MfQAA0gc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:21:51.101851 2026] [security2:error] [pid 110058:tid 110063] [remote 8.217.108.67:19020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4g7xJHADqs2gAgBs-MhQAA5AQ"]
[Mon Jul 20 07:21:51.220448 2026] [security2:error] [pid 110058:tid 110207] [client 14.251.3.155:58652] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4g7xJHADqs2gAgBs-MkQAAAJc"]
[Mon Jul 20 07:21:51.267012 2026] [security2:error] [pid 110058:tid 110221] [client 66.249.72.65:38940] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.2sweetchicks.com"] [uri "/robots.txt"] [unique_id "al4g7xJHADqs2gAgBs-MlAAAAKU"]
[Mon Jul 20 07:21:51.384170 2026] [security2:error] [pid 110058:tid 110215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7xJHADqs2gAgBs-MjAAAAJ8"]
[Mon Jul 20 07:21:51.411136 2026] [security2:error] [pid 110058:tid 110080] [remote 45.90.123.233:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g7xJHADqs2gAgBs-MoAAApxU"]
[Mon Jul 20 07:21:51.411316 2026] [security2:error] [pid 110058:tid 110223] [client 45.90.123.233:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g7xJHADqs2gAgBs-MoAAApxU"]
[Mon Jul 20 07:21:51.469564 2026] [security2:error] [pid 110058:tid 110090] [remote 8.217.108.67:19020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "amalia-capital.com"] [uri "/wp-login.php"] [unique_id "al4g7xJHADqs2gAgBs-MpgAAwx8"], referer: https://amalia-capital.com/wp-login.php
[Mon Jul 20 07:21:51.509238 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g7xJHADqs2gAgBs-MqwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:51.509339 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g7xJHADqs2gAgBs-MqwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:51.550799 2026] [security2:error] [pid 110058:tid 110220] [client 14.225.17.146:59443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4g7xJHADqs2gAgBs-MowAAAKQ"], referer: http://slutilities.com/2018
[Mon Jul 20 07:21:51.569014 2026] [security2:error] [pid 110058:tid 110315] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7xJHADqs2gAgBs-MnQAAAQM"]
[Mon Jul 20 07:21:51.646303 2026] [security2:error] [pid 110058:tid 110308] [client 14.225.17.146:59061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4g7hJHADqs2gAgBs-MHwAAAPw"], referer: http://nwcarvingacademy.com/2018
[Mon Jul 20 07:21:51.782993 2026] [security2:error] [pid 110058:tid 110235] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g7xJHADqs2gAgBs-MsAAAALM"]
[Mon Jul 20 07:21:52.051898 2026] [security2:error] [pid 110058:tid 110278] [client 103.106.165.44:63087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g8BJHADqs2gAgBs-MzwAAAN4"]
[Mon Jul 20 07:21:52.052066 2026] [security2:error] [pid 110058:tid 110278] [client 103.106.165.44:63087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g8BJHADqs2gAgBs-MzwAAAN4"]
[Mon Jul 20 07:21:52.208922 2026] [security2:error] [pid 110058:tid 110169] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g8BJHADqs2gAgBs-M3gAArG0"]
[Mon Jul 20 07:21:52.209110 2026] [security2:error] [pid 110058:tid 110228] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g8BJHADqs2gAgBs-M3gAArG0"]
[Mon Jul 20 07:21:52.314901 2026] [security2:error] [pid 110058:tid 110211] [client 77.110.127.138:64322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/tunisian-crochet/v1sc3ipcg3ak.php"] [unique_id "al4g8BJHADqs2gAgBs-M7wAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:52.329093 2026] [security2:error] [pid 110058:tid 110235] [client 50.116.65.227:39942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4g8BJHADqs2gAgBs-M9gAAALM"]
[Mon Jul 20 07:21:52.334130 2026] [security2:error] [pid 110058:tid 110204] [client 14.225.17.146:59216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-M2gAAAJQ"], referer: http://recruitinginsight.us/2018
[Mon Jul 20 07:21:52.362270 2026] [security2:error] [pid 110058:tid 110196] [client 143.44.185.218:19318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g8BJHADqs2gAgBs-M_AAAAIw"]
[Mon Jul 20 07:21:52.362408 2026] [security2:error] [pid 110058:tid 110196] [client 143.44.185.218:19318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g8BJHADqs2gAgBs-M_AAAAIw"]
[Mon Jul 20 07:21:52.452313 2026] [security2:error] [pid 110058:tid 110288] [client 66.249.74.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4g8BJHADqs2gAgBs-M8QAAAOg"]
[Mon Jul 20 07:21:52.566736 2026] [security2:error] [pid 110058:tid 110248] [client 57.141.18.4:22880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g7BJHADqs2gAgBs-LkwAAwEc"]
[Mon Jul 20 07:21:52.628706 2026] [security2:error] [pid 110058:tid 110309] [client 14.225.17.146:60560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4g7hJHADqs2gAgBs-MaAAAAP0"], referer: http://ccsdifference.com/2018
[Mon Jul 20 07:21:52.667488 2026] [security2:error] [pid 110058:tid 110292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-M-AAAAOw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:52.672344 2026] [security2:error] [pid 110058:tid 110201] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-M-QAAAJE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:52.714547 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64333] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-NAQAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:52.728058 2026] [security2:error] [pid 110058:tid 110276] [client 14.225.17.146:60041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-NCwAAANw"], referer: https://nwcarvingacademy.com/2018
[Mon Jul 20 07:21:53.017150 2026] [security2:error] [pid 110058:tid 110261] [client 77.110.127.138:64335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8RJHADqs2gAgBs-NNAAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.017247 2026] [security2:error] [pid 110058:tid 110261] [client 77.110.127.138:64335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8RJHADqs2gAgBs-NNAAAAM0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.088331 2026] [security2:error] [pid 110058:tid 110307] [client 201.27.111.74:50009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g8RJHADqs2gAgBs-NOgAAAPs"]
[Mon Jul 20 07:21:53.088432 2026] [security2:error] [pid 110058:tid 110307] [client 201.27.111.74:50009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g8RJHADqs2gAgBs-NOgAAAPs"]
[Mon Jul 20 07:21:53.150641 2026] [security2:error] [pid 110058:tid 110202] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-NEQAAAJI"]
[Mon Jul 20 07:21:53.196348 2026] [security2:error] [pid 110058:tid 110214] [client 77.110.127.138:64292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/walton-on-thames/qjsmhgd8w987.php"] [unique_id "al4g8RJHADqs2gAgBs-NQgAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.238563 2026] [security2:error] [pid 110058:tid 110270] [client 50.116.65.227:39962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4g8RJHADqs2gAgBs-NTwAAANY"]
[Mon Jul 20 07:21:53.250235 2026] [security2:error] [pid 110058:tid 110287] [client 50.116.65.227:39970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4g8RJHADqs2gAgBs-NUQAAAOc"]
[Mon Jul 20 07:21:53.458038 2026] [security2:error] [pid 110058:tid 110273] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8RJHADqs2gAgBs-NTAAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.461299 2026] [security2:error] [pid 110058:tid 110312] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8RJHADqs2gAgBs-NTQAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.496496 2026] [security2:error] [pid 110058:tid 110207] [client 14.225.17.146:56558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-M0wAAAJc"], referer: http://dadanetnet.net/2018
[Mon Jul 20 07:21:53.527425 2026] [security2:error] [pid 110058:tid 110316] [client 77.110.127.138:64338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8RJHADqs2gAgBs-NVAAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.547168 2026] [security2:error] [pid 110058:tid 110274] [client 154.192.123.127:17196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g8RJHADqs2gAgBs-NcAAAANo"]
[Mon Jul 20 07:21:53.547294 2026] [security2:error] [pid 110058:tid 110274] [client 154.192.123.127:17196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g8RJHADqs2gAgBs-NcAAAANo"]
[Mon Jul 20 07:21:53.640065 2026] [security2:error] [pid 110058:tid 110231] [client 57.141.18.4:22896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g7RJHADqs2gAgBs-MCgAAr2I"]
[Mon Jul 20 07:21:53.672167 2026] [security2:error] [pid 110058:tid 110197] [client 14.225.17.146:56611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4g8RJHADqs2gAgBs-NbQAAAI0"], referer: https://ccsdifference.com/2018
[Mon Jul 20 07:21:53.760516 2026] [security2:error] [pid 110058:tid 110215] [client 77.110.127.138:64333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8RJHADqs2gAgBs-NfwAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.760634 2026] [security2:error] [pid 110058:tid 110215] [client 77.110.127.138:64333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8RJHADqs2gAgBs-NfwAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:53.877320 2026] [security2:error] [pid 110058:tid 110250] [client 14.225.17.146:56554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4g8BJHADqs2gAgBs-NHwAAAMI"], referer: http://mazzucelli.com/2018
[Mon Jul 20 07:21:54.021927 2026] [security2:error] [pid 110058:tid 110262] [client 114.119.156.232:32041] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "itekphonerepair.com"] [uri "/"] [unique_id "al4g8hJHADqs2gAgBs-NkwAAAM4"], referer: https://ads-yd.top/zigva/%E6%9F%AC%E5%9F%94%E5%AF%A8%E6%9C%80%E5%A4%A7%E8%B3%AD%E5%A0%B4-0d5a295154/
[Mon Jul 20 07:21:54.179790 2026] [security2:error] [pid 110058:tid 110242] [client 77.110.127.138:64325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8hJHADqs2gAgBs-NqwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:54.179927 2026] [security2:error] [pid 110058:tid 110242] [client 77.110.127.138:64325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8hJHADqs2gAgBs-NqwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:54.404394 2026] [security2:error] [pid 110058:tid 110168] [remote 47.128.54.188:17732] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gescontrols.com"] [uri "/sm/contact.htm"] [unique_id "al4g8hJHADqs2gAgBs-NvgAAwmw"]
[Mon Jul 20 07:21:54.422578 2026] [security2:error] [pid 110058:tid 110294] [client 57.141.18.97:23632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g7hJHADqs2gAgBs-MZQAA7gY"]
[Mon Jul 20 07:21:54.423428 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8hJHADqs2gAgBs-NsAAAAME"]
[Mon Jul 20 07:21:54.556329 2026] [security2:error] [pid 110058:tid 110243] [client 187.16.64.216:50388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g8hJHADqs2gAgBs-NywAAALs"]
[Mon Jul 20 07:21:54.556436 2026] [security2:error] [pid 110058:tid 110243] [client 187.16.64.216:50388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g8hJHADqs2gAgBs-NywAAALs"]
[Mon Jul 20 07:21:54.587890 2026] [security2:error] [pid 110058:tid 110306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g8hJHADqs2gAgBs-NuAAAAPo"], referer: 1'"3000
[Mon Jul 20 07:21:54.881537 2026] [security2:error] [pid 110058:tid 110266] [client 117.211.236.168:55148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4g8hJHADqs2gAgBs-N6QAAANI"]
[Mon Jul 20 07:21:54.881626 2026] [security2:error] [pid 110058:tid 110266] [client 117.211.236.168:55148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4g8hJHADqs2gAgBs-N6QAAANI"]
[Mon Jul 20 07:21:55.051517 2026] [security2:error] [pid 110058:tid 110267] [client 14.225.17.146:56563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4g8hJHADqs2gAgBs-NmQAAANM"]
[Mon Jul 20 07:21:55.083377 2026] [security2:error] [pid 110058:tid 110199] [client 94.154.43.178:39276] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "www.crimargroup.com"] [uri "/.env"] [unique_id "al4g8xJHADqs2gAgBs-OAAAAAI8"]
[Mon Jul 20 07:21:55.136244 2026] [security2:error] [pid 110058:tid 110271] [client 77.110.127.138:64330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8xJHADqs2gAgBs-OCAAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:55.136371 2026] [security2:error] [pid 110058:tid 110271] [client 77.110.127.138:64330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g8xJHADqs2gAgBs-OCAAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:55.185663 2026] [security2:error] [pid 110058:tid 110286] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4g8xJHADqs2gAgBs-ODAAAAOY"]
[Mon Jul 20 07:21:55.190236 2026] [security2:error] [pid 110058:tid 110276] [client 14.225.17.146:56040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4g8xJHADqs2gAgBs-N-AAAANw"], referer: http://ivetstrategies.com/2018
[Mon Jul 20 07:21:55.909717 2026] [security2:error] [pid 110058:tid 110209] [client 14.225.17.146:59345] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4g8xJHADqs2gAgBs-OMgAAAJk"], referer: http://sesamegreenbeans.com/2018
[Mon Jul 20 07:21:56.024580 2026] [security2:error] [pid 110058:tid 110316] [client 136.158.60.21:62634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g9BJHADqs2gAgBs-OSAAAAQQ"]
[Mon Jul 20 07:21:56.024740 2026] [security2:error] [pid 110058:tid 110316] [client 136.158.60.21:62634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g9BJHADqs2gAgBs-OSAAAAQQ"]
[Mon Jul 20 07:21:56.286031 2026] [security2:error] [pid 110058:tid 110270] [client 104.234.53.47:24555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4g9BJHADqs2gAgBs-OXAAAANY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:56.498677 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:56086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4g8hJHADqs2gAgBs-N5gAAAME"]
[Mon Jul 20 07:21:56.522994 2026] [security2:error] [pid 110058:tid 110292] [client 14.225.17.146:56076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4g8xJHADqs2gAgBs-N_wAAAOw"], referer: http://cephasnext.com/2018
[Mon Jul 20 07:21:56.564259 2026] [security2:error] [pid 110058:tid 110096] [remote 144.79.133.30:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4g9BJHADqs2gAgBs-OcQAAqiU"]
[Mon Jul 20 07:21:56.592067 2026] [security2:error] [pid 110058:tid 110223] [client 49.37.242.14:60819] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g9BJHADqs2gAgBs-OeQAAAKc"]
[Mon Jul 20 07:21:56.592170 2026] [security2:error] [pid 110058:tid 110223] [client 49.37.242.14:60819] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4g9BJHADqs2gAgBs-OeQAAAKc"]
[Mon Jul 20 07:21:56.658417 2026] [security2:error] [pid 110058:tid 110295] [client 77.110.127.138:64350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g9BJHADqs2gAgBs-OiAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:56.658510 2026] [security2:error] [pid 110058:tid 110295] [client 77.110.127.138:64350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g9BJHADqs2gAgBs-OiAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:56.722431 2026] [security2:error] [pid 110058:tid 110279] [client 185.93.182.171:35260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.182.93.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g9BJHADqs2gAgBs-OkQAAAN8"]
[Mon Jul 20 07:21:56.722555 2026] [security2:error] [pid 110058:tid 110279] [client 185.93.182.171:35260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g9BJHADqs2gAgBs-OkQAAAN8"]
[Mon Jul 20 07:21:56.753787 2026] [security2:error] [pid 110058:tid 110258] [client 81.70.216.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4g9BJHADqs2gAgBs-OegAAyiE"], referer: https://www.aleishapenny.ca/listing/page/1127?paged=1&view=grid&posts_per_page=24
[Mon Jul 20 07:21:57.034424 2026] [security2:error] [pid 110058:tid 110243] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g9BJHADqs2gAgBs-OigAAALs"], referer: 1'"3000
[Mon Jul 20 07:21:57.163484 2026] [security2:error] [pid 110058:tid 110227] [client 14.225.17.146:60626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4g9BJHADqs2gAgBs-OpQAAAKs"], referer: https://sesamegreenbeans.com/2018
[Mon Jul 20 07:21:57.233031 2026] [security2:error] [pid 110058:tid 110270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g9BJHADqs2gAgBs-OiwAAANY"]
[Mon Jul 20 07:21:57.477312 2026] [security2:error] [pid 110058:tid 110242] [client 114.119.145.110:30277] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "emsbodystorm.com"] [uri "/robots.txt"] [unique_id "al4g9RJHADqs2gAgBs-OxwAAALo"], referer: https://emsbodystorm.com/robots.txt
[Mon Jul 20 07:21:57.477873 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g9RJHADqs2gAgBs-OyAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:57.477960 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g9RJHADqs2gAgBs-OyAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:57.816191 2026] [security2:error] [pid 110058:tid 110119] [remote 144.79.133.30:35272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bruceledewitz.com"] [uri "/wp-login.php"] [unique_id "al4g9RJHADqs2gAgBs-O5gAAhzw"], referer: https://bruceledewitz.com/wp-login.php
[Mon Jul 20 07:21:57.853202 2026] [security2:error] [pid 110058:tid 110257] [client 202.141.11.99:12207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4g9RJHADqs2gAgBs-O6QAAAMk"]
[Mon Jul 20 07:21:57.853648 2026] [security2:error] [pid 110058:tid 110257] [client 202.141.11.99:12207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4g9RJHADqs2gAgBs-O6QAAAMk"]
[Mon Jul 20 07:21:57.910615 2026] [security2:error] [pid 110058:tid 110201] [client 14.225.17.146:59039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4g9BJHADqs2gAgBs-OUwAAAJE"], referer: http://koaconsultants.com/2018
[Mon Jul 20 07:21:57.975602 2026] [security2:error] [pid 110058:tid 110308] [client 77.110.127.138:64355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g9RJHADqs2gAgBs-O9gAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:57.975764 2026] [security2:error] [pid 110058:tid 110308] [client 77.110.127.138:64355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g9RJHADqs2gAgBs-O9gAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:21:58.050538 2026] [security2:error] [pid 110058:tid 110263] [client 14.225.17.146:60507] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4g9BJHADqs2gAgBs-OnAAAAM8"], referer: http://christiancountytrumpet.com/2018
[Mon Jul 20 07:21:58.432284 2026] [security2:error] [pid 110058:tid 110195] [client 57.141.18.20:38992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g8hJHADqs2gAgBs-N5wAAi3k"]
[Mon Jul 20 07:21:58.518868 2026] [security2:error] [pid 110058:tid 110292] [client 144.172.114.51:54280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "www.website-d9d7fe47.balticsteelmgmt.com"] [uri "/wp-config.php.txt"] [unique_id "al4g9hJHADqs2gAgBs-PLgAAAOw"]
[Mon Jul 20 07:21:58.664818 2026] [security2:error] [pid 110058:tid 110065] [remote 47.86.33.52:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4g9hJHADqs2gAgBs-PNAAAxAY"]
[Mon Jul 20 07:21:58.938202 2026] [security2:error] [pid 110058:tid 110160] [remote 8.217.108.67:19026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4g9hJHADqs2gAgBs-PSQAAzWQ"]
[Mon Jul 20 07:21:58.938321 2026] [security2:error] [pid 110058:tid 110261] [client 8.217.108.67:19026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4g9hJHADqs2gAgBs-PSQAAzWQ"]
[Mon Jul 20 07:21:59.014295 2026] [security2:error] [pid 110058:tid 110220] [client 154.208.48.130:62540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g9xJHADqs2gAgBs-PTwAAAKQ"]
[Mon Jul 20 07:21:59.014435 2026] [security2:error] [pid 110058:tid 110220] [client 154.208.48.130:62540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4g9xJHADqs2gAgBs-PTwAAAKQ"]
[Mon Jul 20 07:21:59.085515 2026] [security2:error] [pid 110058:tid 110310] [client 14.225.17.146:59095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4g9RJHADqs2gAgBs-OzwAAAP4"], referer: http://alexsandbergmusic.com/2018
[Mon Jul 20 07:21:59.161614 2026] [security2:error] [pid 110058:tid 110201] [client 50.116.65.227:49316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4g9xJHADqs2gAgBs-PXAAAAJE"]
[Mon Jul 20 07:21:59.164484 2026] [security2:error] [pid 110058:tid 110288] [client 14.225.17.146:60680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4g9RJHADqs2gAgBs-O3wAAAOg"]
[Mon Jul 20 07:21:59.364077 2026] [security2:error] [pid 110058:tid 110306] [client 104.234.53.63:31023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4g9xJHADqs2gAgBs-PZwAAAPo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:21:59.441398 2026] [security2:error] [pid 110058:tid 110216] [client 82.102.27.163:34900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g9xJHADqs2gAgBs-PbAAAAKA"]
[Mon Jul 20 07:21:59.441475 2026] [security2:error] [pid 110058:tid 110216] [client 82.102.27.163:34900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g9xJHADqs2gAgBs-PbAAAAKA"]
[Mon Jul 20 07:21:59.627792 2026] [security2:error] [pid 110058:tid 110091] [remote 47.86.33.52:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4g9xJHADqs2gAgBs-PhgAAjiA"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 07:21:59.939325 2026] [security2:error] [pid 110058:tid 110191] [client 14.225.17.146:62561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4g9xJHADqs2gAgBs-PmgAAAIc"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/2018
[Mon Jul 20 07:22:00.040172 2026] [security2:error] [pid 110058:tid 110245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g9xJHADqs2gAgBs-PiQAAAL0"], referer: 1'"3000
[Mon Jul 20 07:22:00.055602 2026] [security2:error] [pid 110058:tid 110212] [client 49.47.218.174:59195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-PsgAAAJw"]
[Mon Jul 20 07:22:00.055983 2026] [security2:error] [pid 110058:tid 110212] [client 49.47.218.174:59195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-PsgAAAJw"]
[Mon Jul 20 07:22:00.072670 2026] [security2:error] [pid 110058:tid 110195] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g9xJHADqs2gAgBs-PiAAAAIs"]
[Mon Jul 20 07:22:00.121597 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-BJHADqs2gAgBs-PtwAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:00.121705 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-BJHADqs2gAgBs-PtwAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:00.121873 2026] [security2:error] [pid 110058:tid 110251] [client 14.225.17.146:62494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4g9xJHADqs2gAgBs-PiwAAAMM"], referer: http://alrowad-hub.net/2018
[Mon Jul 20 07:22:00.174369 2026] [security2:error] [pid 110058:tid 110299] [client 57.141.18.48:62514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g9RJHADqs2gAgBs-OrAAA8zk"]
[Mon Jul 20 07:22:00.449512 2026] [security2:error] [pid 110058:tid 110235] [client 103.176.215.66:64156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-P1QAAALM"]
[Mon Jul 20 07:22:00.450168 2026] [security2:error] [pid 110058:tid 110235] [client 103.176.215.66:64156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-P1QAAALM"]
[Mon Jul 20 07:22:00.572301 2026] [security2:error] [pid 110058:tid 110302] [client 77.110.127.138:64366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-BJHADqs2gAgBs-P3QAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:00.572385 2026] [security2:error] [pid 110058:tid 110302] [client 77.110.127.138:64366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-BJHADqs2gAgBs-P3QAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:00.795801 2026] [security2:error] [pid 110058:tid 110292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-BJHADqs2gAgBs-P4QAAAOw"], referer: 1'"3000
[Mon Jul 20 07:22:00.842924 2026] [security2:error] [pid 110058:tid 110256] [client 157.20.138.62:59588] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-P-wAAAMg"]
[Mon Jul 20 07:22:00.843019 2026] [security2:error] [pid 110058:tid 110256] [client 157.20.138.62:59588] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-P-wAAAMg"]
[Mon Jul 20 07:22:00.934792 2026] [security2:error] [pid 110058:tid 110250] [client 36.93.152.155:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-QCwAAAMI"]
[Mon Jul 20 07:22:00.934906 2026] [security2:error] [pid 110058:tid 110250] [client 36.93.152.155:55732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g-BJHADqs2gAgBs-QCwAAAMI"]
[Mon Jul 20 07:22:01.176824 2026] [security2:error] [pid 110058:tid 110237] [client 57.141.18.43:49836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g9hJHADqs2gAgBs-PCwAAtVU"]
[Mon Jul 20 07:22:01.179560 2026] [security2:error] [pid 110058:tid 110311] [client 191.202.66.27:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QHwAAAP8"]
[Mon Jul 20 07:22:01.179686 2026] [security2:error] [pid 110058:tid 110311] [client 191.202.66.27:60017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QHwAAAP8"]
[Mon Jul 20 07:22:01.189159 2026] [security2:error] [pid 110058:tid 110109] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QIQAAuTI"]
[Mon Jul 20 07:22:01.189270 2026] [security2:error] [pid 110058:tid 110241] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QIQAAuTI"]
[Mon Jul 20 07:22:01.214353 2026] [security2:error] [pid 110058:tid 110207] [client 88.241.67.160:55978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QIwAAAJc"]
[Mon Jul 20 07:22:01.214569 2026] [security2:error] [pid 110058:tid 110207] [client 88.241.67.160:55978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QIwAAAJc"]
[Mon Jul 20 07:22:01.229313 2026] [security2:error] [pid 110058:tid 110231] [client 139.28.219.68:49804] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "tntcatholic.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4g-RJHADqs2gAgBs-QJAAAAK8"]
[Mon Jul 20 07:22:01.235078 2026] [security2:error] [pid 110058:tid 110203] [client 57.141.18.66:55116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g9hJHADqs2gAgBs-PEgAAk2E"]
[Mon Jul 20 07:22:01.249274 2026] [security2:error] [pid 110058:tid 110270] [client 77.110.127.138:64342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-RJHADqs2gAgBs-QKQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:01.249386 2026] [security2:error] [pid 110058:tid 110270] [client 77.110.127.138:64342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-RJHADqs2gAgBs-QKQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:01.299727 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-RJHADqs2gAgBs-QLgAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:01.299879 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4g-RJHADqs2gAgBs-QLgAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:01.302416 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-BJHADqs2gAgBs-QCQAAAIc"]
[Mon Jul 20 07:22:01.334650 2026] [security2:error] [pid 110058:tid 110235] [client 14.225.17.146:63270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QIgAAALM"], referer: http://scott-assist.com/2018
[Mon Jul 20 07:22:01.371389 2026] [security2:error] [pid 110058:tid 110286] [client 77.110.127.138:64367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/tutorial/oobkmvn5kc4e.php"] [unique_id "al4g-RJHADqs2gAgBs-QPQAAAOY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:01.382293 2026] [autoindex:error] [pid 110058:tid 110287] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/mai-lifestyle-pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/themes/mai-lifestyle-pro/
[Mon Jul 20 07:22:01.540180 2026] [security2:error] [pid 110058:tid 110129] [remote 8.217.108.67:42928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4g-RJHADqs2gAgBs-QWgAApUU"]
[Mon Jul 20 07:22:01.588618 2026] [security2:error] [pid 110058:tid 110112] [remote 192.241.143.148:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4g-RJHADqs2gAgBs-QYQAAnDU"]
[Mon Jul 20 07:22:01.745030 2026] [security2:error] [pid 110058:tid 110303] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QQgAAAPc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:01.773956 2026] [security2:error] [pid 110058:tid 110119] [remote 192.241.143.148:45484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4g-RJHADqs2gAgBs-QcAAAxjw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:22:01.811475 2026] [security2:error] [pid 110058:tid 110288] [client 14.225.17.146:63520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QaAAAAOg"], referer: http://nextlvlmarketingco.com/2018
[Mon Jul 20 07:22:01.822784 2026] [security2:error] [pid 110058:tid 110222] [client 139.28.219.68:49814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/xmlrpc.php"] [unique_id "al4g-RJHADqs2gAgBs-QdwAAAKY"]
[Mon Jul 20 07:22:01.924860 2026] [security2:error] [pid 110058:tid 110240] [client 14.225.17.146:63518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QZwAAALg"], referer: http://amalia-capital.com/2018
[Mon Jul 20 07:22:01.948019 2026] [security2:error] [pid 110058:tid 110144] [remote 8.217.108.67:42928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/wp-login.php"] [unique_id "al4g-RJHADqs2gAgBs-QiwAArVQ"], referer: https://adambergeron.com/wp-login.php
[Mon Jul 20 07:22:02.079575 2026] [security2:error] [pid 110058:tid 110278] [client 57.141.18.113:62972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g9xJHADqs2gAgBs-PXQAA3no"]
[Mon Jul 20 07:22:02.161519 2026] [security2:error] [pid 110058:tid 110237] [client 77.110.127.138:64368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QSgAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:02.224239 2026] [security2:error] [pid 110058:tid 110295] [client 104.234.53.81:38429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4g-hJHADqs2gAgBs-QsAAAAO8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:02.345249 2026] [security2:error] [pid 110058:tid 110287] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QaQAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:02.390720 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-hJHADqs2gAgBs-QnQAAAIc"]
[Mon Jul 20 07:22:02.408304 2026] [security2:error] [pid 110058:tid 110206] [client 14.225.17.146:63092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4g-BJHADqs2gAgBs-P_QAAAJY"], referer: http://dnsplumbing.com/2018
[Mon Jul 20 07:22:02.484809 2026] [security2:error] [pid 110058:tid 110198] [client 103.106.165.44:63546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g-hJHADqs2gAgBs-QywAAAI4"]
[Mon Jul 20 07:22:02.484971 2026] [security2:error] [pid 110058:tid 110198] [client 103.106.165.44:63546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4g-hJHADqs2gAgBs-QywAAAI4"]
[Mon Jul 20 07:22:02.960611 2026] [security2:error] [pid 110058:tid 110068] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g-hJHADqs2gAgBs-Q8gAAkwk"]
[Mon Jul 20 07:22:02.960781 2026] [security2:error] [pid 110058:tid 110203] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4g-hJHADqs2gAgBs-Q8gAAkwk"]
[Mon Jul 20 07:22:03.165423 2026] [security2:error] [pid 110058:tid 110293] [client 57.141.18.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-Q-wAAAO0"]
[Mon Jul 20 07:22:03.189630 2026] [security2:error] [pid 110058:tid 110222] [client 158.173.166.181:44669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4g-xJHADqs2gAgBs-RBQAAAKY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:22:03.238655 2026] [security2:error] [pid 110058:tid 110221] [client 15.237.209.113:38430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.209.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4g-xJHADqs2gAgBs-RBgAAAKU"]
[Mon Jul 20 07:22:03.245739 2026] [security2:error] [pid 110058:tid 110265] [client 14.225.17.146:62905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4g-BJHADqs2gAgBs-P1gAAANE"], referer: http://tacticaltreeoperations.com/2018
[Mon Jul 20 07:22:03.246211 2026] [security2:error] [pid 110058:tid 110190] [client 66.249.65.170:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QKwAAAIY"]
[Mon Jul 20 07:22:03.368970 2026] [security2:error] [pid 110058:tid 110204] [client 57.141.18.118:32404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g-BJHADqs2gAgBs-P6AAAlCU"]
[Mon Jul 20 07:22:03.455143 2026] [security2:error] [pid 110058:tid 110304] [client 201.27.111.74:50511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g-xJHADqs2gAgBs-RIwAAAPg"]
[Mon Jul 20 07:22:03.455289 2026] [security2:error] [pid 110058:tid 110304] [client 201.27.111.74:50511] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4g-xJHADqs2gAgBs-RIwAAAPg"]
[Mon Jul 20 07:22:03.588733 2026] [security2:error] [pid 110058:tid 110314] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-RJwABAh0"]
[Mon Jul 20 07:22:03.626724 2026] [security2:error] [pid 110058:tid 110211] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-RLgAAAJs"]
[Mon Jul 20 07:22:03.626922 2026] [security2:error] [pid 110058:tid 110224] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-RLQAAAKg"]
[Mon Jul 20 07:22:03.685443 2026] [security2:error] [pid 110058:tid 110276] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-RHgAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:03.726683 2026] [security2:error] [pid 110058:tid 110095] [remote 100.42.189.89:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g-xJHADqs2gAgBs-RRwAA-yQ"]
[Mon Jul 20 07:22:03.748218 2026] [security2:error] [pid 110058:tid 110255] [client 15.237.142.234:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4g-xJHADqs2gAgBs-RSgAAAMc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:22:03.886645 2026] [security2:error] [pid 110058:tid 110300] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-RUAAAAPQ"]
[Mon Jul 20 07:22:03.939829 2026] [security2:error] [pid 110058:tid 110078] [remote 100.42.189.89:55254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4g-xJHADqs2gAgBs-RWgAA3hM"], referer: https://thefriendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:03.987469 2026] [security2:error] [pid 110058:tid 110203] [client 13.233.207.33:25424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4g-xJHADqs2gAgBs-RYQAAAJM"]
[Mon Jul 20 07:22:04.024771 2026] [security2:error] [pid 110058:tid 110225] [client 154.192.123.127:17597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g_BJHADqs2gAgBs-RaQAAAKk"]
[Mon Jul 20 07:22:04.024877 2026] [security2:error] [pid 110058:tid 110191] [client 172.212.190.89:6015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4g_BJHADqs2gAgBs-RaAAAAIc"]
[Mon Jul 20 07:22:04.024897 2026] [security2:error] [pid 110058:tid 110225] [client 154.192.123.127:17597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4g_BJHADqs2gAgBs-RaQAAAKk"]
[Mon Jul 20 07:22:04.024962 2026] [security2:error] [pid 110058:tid 110191] [client 172.212.190.89:6015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4g_BJHADqs2gAgBs-RaAAAAIc"]
[Mon Jul 20 07:22:04.303768 2026] [security2:error] [pid 110058:tid 110271] [client 77.110.127.138:64378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g_BJHADqs2gAgBs-RcgAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:04.316153 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g_BJHADqs2gAgBs-RdgAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:04.387293 2026] [security2:error] [pid 110058:tid 110261] [client 57.141.18.91:27270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QbQAAzU0"]
[Mon Jul 20 07:22:04.440381 2026] [security2:error] [pid 110058:tid 110195] [client 57.141.18.25:50846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g-RJHADqs2gAgBs-QeAAAix4"]
[Mon Jul 20 07:22:04.441049 2026] [security2:error] [pid 110058:tid 110249] [client 139.28.219.68:49816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/xmlrpc.php"] [unique_id "al4g_BJHADqs2gAgBs-RiAAAAME"]
[Mon Jul 20 07:22:04.441175 2026] [security2:error] [pid 110058:tid 110249] [client 139.28.219.68:49816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tntcatholic.com"] [uri "/xmlrpc.php"] [unique_id "al4g_BJHADqs2gAgBs-RiAAAAME"]
[Mon Jul 20 07:22:04.607124 2026] [security2:error] [pid 110058:tid 110292] [client 172.212.190.89:14848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4g_BJHADqs2gAgBs-RmAAAAOw"]
[Mon Jul 20 07:22:04.607241 2026] [security2:error] [pid 110058:tid 110292] [client 172.212.190.89:14848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4g_BJHADqs2gAgBs-RmAAAAOw"]
[Mon Jul 20 07:22:04.637133 2026] [autoindex:error] [pid 110058:tid 110131] [remote 34.10.22.13:50298] AH01276: Cannot serve directory /home2/hsdrromy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.hsd.rro.mybluehost.me
[Mon Jul 20 07:22:05.022840 2026] [security2:error] [pid 110058:tid 110196] [client 139.28.219.68:49832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/xmlrpc.php"] [unique_id "al4g_RJHADqs2gAgBs-RugAAAIw"]
[Mon Jul 20 07:22:05.022967 2026] [security2:error] [pid 110058:tid 110196] [client 139.28.219.68:49832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tntcatholic.com"] [uri "/xmlrpc.php"] [unique_id "al4g_RJHADqs2gAgBs-RugAAAIw"]
[Mon Jul 20 07:22:05.086538 2026] [security2:error] [pid 110058:tid 110211] [client 172.212.190.89:4933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/wp.php"] [unique_id "al4g_RJHADqs2gAgBs-RwgAAAJs"]
[Mon Jul 20 07:22:05.086675 2026] [security2:error] [pid 110058:tid 110211] [client 172.212.190.89:4933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/wp.php"] [unique_id "al4g_RJHADqs2gAgBs-RwgAAAJs"]
[Mon Jul 20 07:22:05.164443 2026] [security2:error] [pid 110058:tid 110202] [client 13.233.207.33:22302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4g_RJHADqs2gAgBs-RzwAAAJI"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:22:05.186740 2026] [security2:error] [pid 110058:tid 110296] [client 187.16.64.216:51151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g_RJHADqs2gAgBs-R0QAAAPA"]
[Mon Jul 20 07:22:05.186867 2026] [security2:error] [pid 110058:tid 110296] [client 187.16.64.216:51151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4g_RJHADqs2gAgBs-R0QAAAPA"]
[Mon Jul 20 07:22:05.230007 2026] [security2:error] [pid 110058:tid 110193] [client 14.225.17.146:60834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4g-hJHADqs2gAgBs-Q7AAAAIk"], referer: http://adastra.love/2018
[Mon Jul 20 07:22:05.525205 2026] [security2:error] [pid 110058:tid 110191] [client 172.212.190.89:10378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/new.php"] [unique_id "al4g_RJHADqs2gAgBs-R6AAAAIc"]
[Mon Jul 20 07:22:05.525298 2026] [security2:error] [pid 110058:tid 110191] [client 172.212.190.89:10378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/new.php"] [unique_id "al4g_RJHADqs2gAgBs-R6AAAAIc"]
[Mon Jul 20 07:22:05.660179 2026] [security2:error] [pid 110058:tid 110299] [client 143.44.185.218:20835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g_RJHADqs2gAgBs-R9QAAAPM"]
[Mon Jul 20 07:22:05.660288 2026] [security2:error] [pid 110058:tid 110299] [client 143.44.185.218:20835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4g_RJHADqs2gAgBs-R9QAAAPM"]
[Mon Jul 20 07:22:05.722472 2026] [security2:error] [pid 110058:tid 110296] [client 50.116.65.227:33772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4g_RJHADqs2gAgBs-R-QAAAPA"]
[Mon Jul 20 07:22:05.730930 2026] [security2:error] [pid 110058:tid 110206] [client 50.116.65.227:33780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4g_RJHADqs2gAgBs-R-gAAAJY"]
[Mon Jul 20 07:22:05.980959 2026] [security2:error] [pid 110058:tid 110208] [client 14.225.17.146:61637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4g_RJHADqs2gAgBs-R7QAAAJg"], referer: http://grecruit.online/2018
[Mon Jul 20 07:22:06.114157 2026] [security2:error] [pid 110058:tid 110232] [client 57.141.18.64:65354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g-xJHADqs2gAgBs-RMgAAsH8"]
[Mon Jul 20 07:22:06.154593 2026] [security2:error] [pid 110058:tid 110276] [client 172.212.190.89:1576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/wpls.php"] [unique_id "al4g_hJHADqs2gAgBs-SHgAAANw"]
[Mon Jul 20 07:22:06.154697 2026] [security2:error] [pid 110058:tid 110276] [client 172.212.190.89:1576] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/wpls.php"] [unique_id "al4g_hJHADqs2gAgBs-SHgAAANw"]
[Mon Jul 20 07:22:06.362802 2026] [security2:error] [pid 110058:tid 110273] [client 77.110.127.138:64386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-2/2j7nqzbqiox7.php"] [unique_id "al4g_hJHADqs2gAgBs-SMgAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:06.387405 2026] [security2:error] [pid 110058:tid 110151] [remote 17.22.253.199:39722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.253.22.17.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4g_hJHADqs2gAgBs-SLwAAj1s"], referer: https://massagelacey.com/hindsight-in-2020/
[Mon Jul 20 07:22:06.397240 2026] [security2:error] [pid 110058:tid 110277] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-SLAAAAN0"]
[Mon Jul 20 07:22:06.441628 2026] [security2:error] [pid 110058:tid 110065] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/.gitconfig"] [unique_id "al4g_hJHADqs2gAgBs-SRAAAlwY"]
[Mon Jul 20 07:22:06.548168 2026] [security2:error] [pid 110058:tid 110248] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-STgAAAMA"]
[Mon Jul 20 07:22:06.553382 2026] [security2:error] [pid 110058:tid 110292] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-STQAAAOw"]
[Mon Jul 20 07:22:06.563301 2026] [security2:error] [pid 110058:tid 110216] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-STAAAAKA"]
[Mon Jul 20 07:22:06.581017 2026] [security2:error] [pid 110058:tid 110286] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-SUQAAAOY"]
[Mon Jul 20 07:22:06.581079 2026] [security2:error] [pid 110058:tid 110314] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-STwAAAQI"]
[Mon Jul 20 07:22:06.619489 2026] [security2:error] [pid 110058:tid 110269] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-SPgAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:06.681914 2026] [security2:error] [pid 110058:tid 110268] [client 172.212.190.89:14873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/mjq.php"] [unique_id "al4g_hJHADqs2gAgBs-SZQAAANQ"]
[Mon Jul 20 07:22:06.682004 2026] [security2:error] [pid 110058:tid 110268] [client 172.212.190.89:14873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/mjq.php"] [unique_id "al4g_hJHADqs2gAgBs-SZQAAANQ"]
[Mon Jul 20 07:22:06.836400 2026] [security2:error] [pid 110058:tid 110211] [client 136.158.60.21:64164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g_hJHADqs2gAgBs-SbQAAAJs"]
[Mon Jul 20 07:22:06.836519 2026] [security2:error] [pid 110058:tid 110211] [client 136.158.60.21:64164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4g_hJHADqs2gAgBs-SbQAAAJs"]
[Mon Jul 20 07:22:06.915052 2026] [security2:error] [pid 110058:tid 110282] [client 14.225.17.146:61449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4g_RJHADqs2gAgBs-R2QAAAOI"], referer: http://superiorcopywriting.com/2018
[Mon Jul 20 07:22:07.008979 2026] [security2:error] [pid 110058:tid 110274] [client 117.211.236.168:55758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4g_hJHADqs2gAgBs-SegAAANo"]
[Mon Jul 20 07:22:07.009108 2026] [security2:error] [pid 110058:tid 110274] [client 117.211.236.168:55758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4g_hJHADqs2gAgBs-SegAAANo"]
[Mon Jul 20 07:22:07.018071 2026] [security2:error] [pid 110058:tid 110307] [client 57.141.18.60:20266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g_BJHADqs2gAgBs-RfwAA-zE"]
[Mon Jul 20 07:22:07.122383 2026] [lsapi:warn] [pid 110058:tid 110316] [client 14.225.17.146:62142] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2018
[Mon Jul 20 07:22:07.122407 2026] [lsapi:warn] [pid 110058:tid 110316] [client 14.225.17.146:62142] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/2018
[Mon Jul 20 07:22:07.144155 2026] [security2:error] [pid 110058:tid 110219] [client 172.212.190.89:14879] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/class-t.api.php"] [unique_id "al4g_xJHADqs2gAgBs-SiAAAAKM"]
[Mon Jul 20 07:22:07.144246 2026] [security2:error] [pid 110058:tid 110219] [client 172.212.190.89:14879] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/class-t.api.php"] [unique_id "al4g_xJHADqs2gAgBs-SiAAAAKM"]
[Mon Jul 20 07:22:07.481034 2026] [core:error] [pid 110058:tid 110220] [client 14.225.17.146:57204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2018
[Mon Jul 20 07:22:07.481070 2026] [core:error] [pid 110058:tid 110220] [client 14.225.17.146:57204] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/2018
[Mon Jul 20 07:22:07.492994 2026] [security2:error] [pid 110058:tid 110203] [client 172.212.190.89:9653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/plugins.php"] [unique_id "al4g_xJHADqs2gAgBs-SoAAAAJM"]
[Mon Jul 20 07:22:07.493119 2026] [security2:error] [pid 110058:tid 110203] [client 172.212.190.89:9653] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/plugins.php"] [unique_id "al4g_xJHADqs2gAgBs-SoAAAAJM"]
[Mon Jul 20 07:22:07.637801 2026] [lsapi:warn] [pid 110058:tid 110194] [client 50.116.65.227:33822] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:22:07.637823 2026] [lsapi:warn] [pid 110058:tid 110194] [client 50.116.65.227:33822] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:22:07.652274 2026] [security2:error] [pid 110058:tid 110316] [client 14.225.17.146:62142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4g_hJHADqs2gAgBs-SXgAAAQQ"], referer: http://oswegooperatheater.com/2018
[Mon Jul 20 07:22:07.747229 2026] [security2:error] [pid 110058:tid 110199] [client 34.221.76.50:53696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4g_xJHADqs2gAgBs-StwAAAI8"]
[Mon Jul 20 07:22:07.764011 2026] [security2:error] [pid 110058:tid 110254] [client 44.245.170.32:13240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4g_xJHADqs2gAgBs-SugAAAMY"]
[Mon Jul 20 07:22:07.849120 2026] [security2:error] [pid 110058:tid 110247] [client 57.141.18.20:55318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4g_RJHADqs2gAgBs-R1QAAvzU"]
[Mon Jul 20 07:22:07.956262 2026] [security2:error] [pid 110058:tid 110300] [client 172.212.190.89:6012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/jp.php"] [unique_id "al4g_xJHADqs2gAgBs-SxAAAAPQ"]
[Mon Jul 20 07:22:07.956380 2026] [security2:error] [pid 110058:tid 110300] [client 172.212.190.89:6012] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/jp.php"] [unique_id "al4g_xJHADqs2gAgBs-SxAAAAPQ"]
[Mon Jul 20 07:22:08.073796 2026] [security2:error] [pid 110058:tid 110098] [remote 173.212.252.15:50932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hABJHADqs2gAgBs-S1QAAmyc"]
[Mon Jul 20 07:22:08.073948 2026] [security2:error] [pid 110058:tid 110211] [client 173.212.252.15:50932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hABJHADqs2gAgBs-S1QAAmyc"]
[Mon Jul 20 07:22:08.103919 2026] [core:error] [pid 110058:tid 110286] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:08.103934 2026] [core:error] [pid 110058:tid 110286] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:08.274070 2026] [security2:error] [pid 110058:tid 110216] [client 49.37.242.14:61325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hABJHADqs2gAgBs-S7AAAAKA"]
[Mon Jul 20 07:22:08.274267 2026] [security2:error] [pid 110058:tid 110216] [client 49.37.242.14:61325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hABJHADqs2gAgBs-S7AAAAKA"]
[Mon Jul 20 07:22:08.402923 2026] [security2:error] [pid 110058:tid 110279] [client 172.212.190.89:14878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/pu9.php"] [unique_id "al4hABJHADqs2gAgBs-S-AAAAN8"]
[Mon Jul 20 07:22:08.403061 2026] [security2:error] [pid 110058:tid 110279] [client 172.212.190.89:14878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/pu9.php"] [unique_id "al4hABJHADqs2gAgBs-S-AAAAN8"]
[Mon Jul 20 07:22:08.512965 2026] [lsapi:warn] [pid 110058:tid 110309] [client 14.225.17.146:57459] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2018
[Mon Jul 20 07:22:08.512986 2026] [lsapi:warn] [pid 110058:tid 110309] [client 14.225.17.146:57459] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/2018
[Mon Jul 20 07:22:08.550676 2026] [security2:error] [pid 110058:tid 110102] [remote 45.150.79.142:43516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hABJHADqs2gAgBs-TAQAAuis"]
[Mon Jul 20 07:22:08.550836 2026] [security2:error] [pid 110058:tid 110242] [client 45.150.79.142:43516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hABJHADqs2gAgBs-TAQAAuis"]
[Mon Jul 20 07:22:08.562075 2026] [security2:error] [pid 110058:tid 110309] [client 14.225.17.146:57459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4hABJHADqs2gAgBs-TAAAAAP0"], referer: https://oswegooperatheater.com/2018
[Mon Jul 20 07:22:08.888670 2026] [security2:error] [pid 110058:tid 110122] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/.env"] [unique_id "al4hABJHADqs2gAgBs-TFAAAuT4"]
[Mon Jul 20 07:22:08.888823 2026] [security2:error] [pid 110058:tid 110241] [client 104.28.211.187:57863] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "retzkolonglogistics.com"] [uri "/.env"] [unique_id "al4hABJHADqs2gAgBs-TFAAAuT4"]
[Mon Jul 20 07:22:08.949180 2026] [security2:error] [pid 110058:tid 110129] [remote 124.55.178.99:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4hABJHADqs2gAgBs-THAAAu0U"]
[Mon Jul 20 07:22:08.987737 2026] [security2:error] [pid 110058:tid 110130] [remote 47.86.33.52:50364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4hABJHADqs2gAgBs-THwAAzkY"]
[Mon Jul 20 07:22:08.992821 2026] [security2:error] [pid 110058:tid 110279] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hABJHADqs2gAgBs-TGgAAAN8"]
[Mon Jul 20 07:22:08.992897 2026] [security2:error] [pid 110058:tid 110203] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hABJHADqs2gAgBs-TGQAAAJM"]
[Mon Jul 20 07:22:09.036776 2026] [security2:error] [pid 110058:tid 110313] [client 172.212.190.89:5630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/error.php"] [unique_id "al4hARJHADqs2gAgBs-TIgAAAQE"]
[Mon Jul 20 07:22:09.036878 2026] [security2:error] [pid 110058:tid 110313] [client 172.212.190.89:5630] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/error.php"] [unique_id "al4hARJHADqs2gAgBs-TIgAAAQE"]
[Mon Jul 20 07:22:09.044350 2026] [security2:error] [pid 110058:tid 110171] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/.env.old"] [unique_id "al4hARJHADqs2gAgBs-TJAAAt28"]
[Mon Jul 20 07:22:09.145775 2026] [security2:error] [pid 110058:tid 110208] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hARJHADqs2gAgBs-TJgAAAJg"]
[Mon Jul 20 07:22:09.380686 2026] [security2:error] [pid 110058:tid 110125] [remote 124.55.178.99:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "north-woods-engineering.com"] [uri "/wp-login.php"] [unique_id "al4hARJHADqs2gAgBs-TOAAA8kE"], referer: https://north-woods-engineering.com/wp-login.php
[Mon Jul 20 07:22:09.482679 2026] [security2:error] [pid 110058:tid 110304] [client 172.212.190.89:9615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/bdshell.php"] [unique_id "al4hARJHADqs2gAgBs-TPwAAAPg"]
[Mon Jul 20 07:22:09.482787 2026] [security2:error] [pid 110058:tid 110304] [client 172.212.190.89:9615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/bdshell.php"] [unique_id "al4hARJHADqs2gAgBs-TPwAAAPg"]
[Mon Jul 20 07:22:09.530531 2026] [security2:error] [pid 110058:tid 110283] [client 74.7.227.179:35226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4hARJHADqs2gAgBs-TOgAA40M"], referer: https://tejasenvironmental.com/p=3083827
[Mon Jul 20 07:22:09.537610 2026] [security2:error] [pid 110058:tid 110287] [client 77.110.127.138:64390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hARJHADqs2gAgBs-TRwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:09.537697 2026] [security2:error] [pid 110058:tid 110287] [client 77.110.127.138:64390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hARJHADqs2gAgBs-TRwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:09.570522 2026] [security2:error] [pid 110058:tid 110144] [remote 47.86.33.52:50364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/wp-login.php"] [unique_id "al4hARJHADqs2gAgBs-TSAAA4FQ"], referer: https://narv.co/wp-login.php
[Mon Jul 20 07:22:09.778101 2026] [security2:error] [pid 110058:tid 110229] [client 14.225.17.146:56519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4hABJHADqs2gAgBs-S9wAAAK0"], referer: http://chestermonty.com/2018
[Mon Jul 20 07:22:10.046660 2026] [security2:error] [pid 110058:tid 110201] [client 194.180.48.253:43466] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "lizrichter.com.au"] [uri "/"] [unique_id "al4hAhJHADqs2gAgBs-TfAAAAJE"]
[Mon Jul 20 07:22:10.246724 2026] [security2:error] [pid 110058:tid 110253] [client 154.208.48.130:63071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hAhJHADqs2gAgBs-ThwAAAMU"]
[Mon Jul 20 07:22:10.246852 2026] [security2:error] [pid 110058:tid 110253] [client 154.208.48.130:63071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hAhJHADqs2gAgBs-ThwAAAMU"]
[Mon Jul 20 07:22:10.396076 2026] [security2:error] [pid 110058:tid 110231] [client 172.212.190.89:10370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/bitwise.php"] [unique_id "al4hAhJHADqs2gAgBs-TjwAAAK8"]
[Mon Jul 20 07:22:10.396165 2026] [security2:error] [pid 110058:tid 110231] [client 172.212.190.89:10370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/bitwise.php"] [unique_id "al4hAhJHADqs2gAgBs-TjwAAAK8"]
[Mon Jul 20 07:22:10.435051 2026] [security2:error] [pid 110058:tid 110178] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/backend/.env"] [unique_id "al4hAhJHADqs2gAgBs-TkQAA0HY"]
[Mon Jul 20 07:22:10.435202 2026] [security2:error] [pid 110058:tid 110152] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/config/.env"] [unique_id "al4hAhJHADqs2gAgBs-TkgAA0Fw"]
[Mon Jul 20 07:22:10.465027 2026] [security2:error] [pid 110058:tid 110162] [remote 160.187.68.132:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4hAhJHADqs2gAgBs-TkwAAmmY"]
[Mon Jul 20 07:22:10.522336 2026] [security2:error] [pid 110058:tid 110284] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hAhJHADqs2gAgBs-TlAAA5FY"]
[Mon Jul 20 07:22:10.578589 2026] [security2:error] [pid 110058:tid 110228] [client 49.47.218.174:59715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hAhJHADqs2gAgBs-TnwAAAKw"]
[Mon Jul 20 07:22:10.578690 2026] [security2:error] [pid 110058:tid 110228] [client 49.47.218.174:59715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hAhJHADqs2gAgBs-TnwAAAKw"]
[Mon Jul 20 07:22:10.597692 2026] [security2:error] [pid 110058:tid 110167] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/api/.env"] [unique_id "al4hAhJHADqs2gAgBs-TowAAnms"]
[Mon Jul 20 07:22:10.598812 2026] [security2:error] [pid 110058:tid 110108] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/.env.backup"] [unique_id "al4hAhJHADqs2gAgBs-ToQAAnjE"]
[Mon Jul 20 07:22:10.599389 2026] [security2:error] [pid 110058:tid 110183] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/.env.bak"] [unique_id "al4hAhJHADqs2gAgBs-TogAAnns"]
[Mon Jul 20 07:22:10.701975 2026] [security2:error] [pid 110058:tid 110289] [client 14.225.17.146:62274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4hAhJHADqs2gAgBs-TpAAAAOk"], referer: https://chestermonty.com/2018
[Mon Jul 20 07:22:10.806946 2026] [security2:error] [pid 110058:tid 110252] [client 103.176.215.66:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hAhJHADqs2gAgBs-TrwAAAMQ"]
[Mon Jul 20 07:22:10.807403 2026] [security2:error] [pid 110058:tid 110252] [client 103.176.215.66:64688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hAhJHADqs2gAgBs-TrwAAAMQ"]
[Mon Jul 20 07:22:11.029514 2026] [security2:error] [pid 110058:tid 110184] [remote 160.187.68.132:39618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4hAxJHADqs2gAgBs-TxAAAp3w"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 07:22:11.146609 2026] [security2:error] [pid 110058:tid 110276] [client 14.225.17.146:57547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4hARJHADqs2gAgBs-TLgAAANw"], referer: http://webgardensbypaula.com/2018
[Mon Jul 20 07:22:11.186403 2026] [security2:error] [pid 110058:tid 110278] [client 172.212.190.89:14905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/BLaSTER.php"] [unique_id "al4hAxJHADqs2gAgBs-T1AAAAN4"]
[Mon Jul 20 07:22:11.186507 2026] [security2:error] [pid 110058:tid 110278] [client 172.212.190.89:14905] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/BLaSTER.php"] [unique_id "al4hAxJHADqs2gAgBs-T1AAAAN4"]
[Mon Jul 20 07:22:11.357260 2026] [security2:error] [pid 110058:tid 110191] [client 36.93.152.155:56230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-T5AAAAIc"]
[Mon Jul 20 07:22:11.357354 2026] [security2:error] [pid 110058:tid 110191] [client 36.93.152.155:56230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-T5AAAAIc"]
[Mon Jul 20 07:22:11.425791 2026] [security2:error] [pid 110058:tid 110250] [client 157.20.138.62:60155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-T6wAAAMI"]
[Mon Jul 20 07:22:11.425912 2026] [security2:error] [pid 110058:tid 110250] [client 157.20.138.62:60155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-T6wAAAMI"]
[Mon Jul 20 07:22:11.576126 2026] [security2:error] [pid 110058:tid 110094] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4hAxJHADqs2gAgBs-T9AAA-iM"]
[Mon Jul 20 07:22:11.659922 2026] [security2:error] [pid 110058:tid 110306] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hAxJHADqs2gAgBs-T9QAA-hQ"]
[Mon Jul 20 07:22:11.684873 2026] [security2:error] [pid 110058:tid 110295] [client 57.141.18.95:22872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hARJHADqs2gAgBs-TOwAA70o"]
[Mon Jul 20 07:22:11.727392 2026] [security2:error] [pid 110058:tid 110265] [client 191.202.66.27:60499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-T-wAAANE"]
[Mon Jul 20 07:22:11.727476 2026] [security2:error] [pid 110058:tid 110265] [client 191.202.66.27:60499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-T-wAAANE"]
[Mon Jul 20 07:22:11.781399 2026] [autoindex:error] [pid 110058:tid 110089] [remote 93.152.221.21:58236] AH01276: Cannot serve directory /home1/ikrsycmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.ikr.syc.mybluehost.me
[Mon Jul 20 07:22:11.863863 2026] [security2:error] [pid 110058:tid 110235] [client 88.241.67.160:56110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-UDgAAALM"]
[Mon Jul 20 07:22:11.864386 2026] [security2:error] [pid 110058:tid 110235] [client 88.241.67.160:56110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-UDgAAALM"]
[Mon Jul 20 07:22:11.958555 2026] [security2:error] [pid 110058:tid 110311] [client 172.212.190.89:14858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/bloodsecv4.php"] [unique_id "al4hAxJHADqs2gAgBs-UEgAAAP8"]
[Mon Jul 20 07:22:11.958664 2026] [security2:error] [pid 110058:tid 110311] [client 172.212.190.89:14858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/bloodsecv4.php"] [unique_id "al4hAxJHADqs2gAgBs-UEgAAAP8"]
[Mon Jul 20 07:22:11.960857 2026] [security2:error] [pid 110058:tid 110076] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-UEwAA2RE"]
[Mon Jul 20 07:22:11.960995 2026] [security2:error] [pid 110058:tid 110273] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hAxJHADqs2gAgBs-UEwAA2RE"]
[Mon Jul 20 07:22:12.368269 2026] [security2:error] [pid 110058:tid 110304] [client 77.110.127.138:64401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/uncategorized/dwl1vbn6kmq1.php"] [unique_id "al4hBBJHADqs2gAgBs-UKwAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:12.443844 2026] [security2:error] [pid 110058:tid 110288] [client 140.245.46.64:51885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4hBBJHADqs2gAgBs-UOwAAAOg"]
[Mon Jul 20 07:22:12.444358 2026] [security2:error] [pid 110058:tid 110169] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/.docker/config.json"] [unique_id "al4hBBJHADqs2gAgBs-URQAA920"]
[Mon Jul 20 07:22:12.519948 2026] [autoindex:error] [pid 110058:tid 110197] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/
[Mon Jul 20 07:22:12.546782 2026] [security2:error] [pid 110058:tid 110303] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-URAAA9z0"]
[Mon Jul 20 07:22:12.550997 2026] [security2:error] [pid 110058:tid 110303] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UQwAA92E"]
[Mon Jul 20 07:22:12.572815 2026] [security2:error] [pid 110058:tid 110303] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UQQAA9y0"]
[Mon Jul 20 07:22:12.588076 2026] [security2:error] [pid 110058:tid 110273] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UUwAAANk"]
[Mon Jul 20 07:22:12.594908 2026] [security2:error] [pid 110058:tid 110207] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UUgAAAJc"]
[Mon Jul 20 07:22:12.649223 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UKgAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:12.726963 2026] [security2:error] [pid 110058:tid 110290] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UbAAAAOo"]
[Mon Jul 20 07:22:12.734768 2026] [security2:error] [pid 110058:tid 110215] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UawAAAJ8"]
[Mon Jul 20 07:22:12.786433 2026] [security2:error] [pid 110058:tid 110218] [client 172.212.190.89:9288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/Bnkqbakq.php"] [unique_id "al4hBBJHADqs2gAgBs-UcwAAAKI"]
[Mon Jul 20 07:22:12.786542 2026] [security2:error] [pid 110058:tid 110218] [client 172.212.190.89:9288] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/Bnkqbakq.php"] [unique_id "al4hBBJHADqs2gAgBs-UcwAAAKI"]
[Mon Jul 20 07:22:12.916243 2026] [security2:error] [pid 110058:tid 110254] [client 77.110.127.138:64424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBBJHADqs2gAgBs-UegAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:12.916409 2026] [security2:error] [pid 110058:tid 110254] [client 77.110.127.138:64424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBBJHADqs2gAgBs-UegAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:12.962877 2026] [security2:error] [pid 110058:tid 110287] [client 103.106.165.44:63999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hBBJHADqs2gAgBs-UgAAAAOc"]
[Mon Jul 20 07:22:12.962978 2026] [security2:error] [pid 110058:tid 110287] [client 103.106.165.44:63999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hBBJHADqs2gAgBs-UgAAAAOc"]
[Mon Jul 20 07:22:13.020790 2026] [security2:error] [pid 110058:tid 110273] [client 77.110.127.138:64427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/knitting/2fezeskobd6w.php"] [unique_id "al4hBRJHADqs2gAgBs-UiQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.058430 2026] [security2:error] [pid 110058:tid 110315] [client 172.212.190.89:9623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/haha.php"] [unique_id "al4hBRJHADqs2gAgBs-UkQAAAQM"]
[Mon Jul 20 07:22:13.058544 2026] [security2:error] [pid 110058:tid 110315] [client 172.212.190.89:9623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/haha.php"] [unique_id "al4hBRJHADqs2gAgBs-UkQAAAQM"]
[Mon Jul 20 07:22:13.284701 2026] [security2:error] [pid 110058:tid 110245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UPwAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.367814 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UXwAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.369846 2026] [security2:error] [pid 110058:tid 110222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UggAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.398258 2026] [security2:error] [pid 110058:tid 110187] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "retzkolonglogistics.com"] [uri "/graphql"] [unique_id "al4hBRJHADqs2gAgBs-UqgAA2H8"]
[Mon Jul 20 07:22:13.403374 2026] [security2:error] [pid 110058:tid 110310] [client 77.110.127.138:64423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UeQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.423649 2026] [authz_core:error] [pid 110058:tid 110280] [client 104.28.211.187:0] AH01630: client denied by server configuration: /home4/retzkolo/public_html/.htpasswd
[Mon Jul 20 07:22:13.503804 2026] [security2:error] [pid 110058:tid 110290] [client 172.212.190.89:13104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/classwithtostring.php"] [unique_id "al4hBRJHADqs2gAgBs-UwAAAAOo"]
[Mon Jul 20 07:22:13.503922 2026] [security2:error] [pid 110058:tid 110290] [client 172.212.190.89:13104] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/classwithtostring.php"] [unique_id "al4hBRJHADqs2gAgBs-UwAAAAOo"]
[Mon Jul 20 07:22:13.507547 2026] [security2:error] [pid 110058:tid 110211] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-UtAAAAJs"]
[Mon Jul 20 07:22:13.535270 2026] [security2:error] [pid 110058:tid 110209] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-UtwAAAJk"]
[Mon Jul 20 07:22:13.596836 2026] [security2:error] [pid 110058:tid 110213] [client 77.110.127.138:64428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/19/hzyb4iqw6hju.php"] [unique_id "al4hBRJHADqs2gAgBs-UzAAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.743836 2026] [security2:error] [pid 110058:tid 110235] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-U1AAAALM"]
[Mon Jul 20 07:22:13.786203 2026] [security2:error] [pid 110058:tid 110224] [client 172.212.190.89:1590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/bless.php"] [unique_id "al4hBRJHADqs2gAgBs-U8QAAAKg"]
[Mon Jul 20 07:22:13.786325 2026] [security2:error] [pid 110058:tid 110224] [client 172.212.190.89:1590] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/bless.php"] [unique_id "al4hBRJHADqs2gAgBs-U8QAAAKg"]
[Mon Jul 20 07:22:13.794342 2026] [security2:error] [pid 110058:tid 110198] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-UzQAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:13.829443 2026] [security2:error] [pid 110058:tid 110156] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "retzkolonglogistics.com"] [uri "/api/graphql"] [unique_id "al4hBRJHADqs2gAgBs-U8wAAvmA"]
[Mon Jul 20 07:22:13.856813 2026] [security2:error] [pid 110058:tid 110180] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hBRJHADqs2gAgBs-U9gAA_ng"]
[Mon Jul 20 07:22:13.857013 2026] [security2:error] [pid 110058:tid 110310] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hBRJHADqs2gAgBs-U9gAA_ng"]
[Mon Jul 20 07:22:13.882710 2026] [security2:error] [pid 110058:tid 110191] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-U8gAAAIc"]
[Mon Jul 20 07:22:13.914399 2026] [security2:error] [pid 110058:tid 110225] [client 201.27.111.74:51019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hBRJHADqs2gAgBs-U-gAAAKk"]
[Mon Jul 20 07:22:13.914493 2026] [security2:error] [pid 110058:tid 110225] [client 201.27.111.74:51019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hBRJHADqs2gAgBs-U-gAAAKk"]
[Mon Jul 20 07:22:13.933986 2026] [security2:error] [pid 110058:tid 110146] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/.ssh/id_dsa"] [unique_id "al4hBRJHADqs2gAgBs-VBAAAhlY"]
[Mon Jul 20 07:22:13.934013 2026] [security2:error] [pid 110058:tid 110164] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "retzkolonglogistics.com"] [uri "/.ssh/config"] [unique_id "al4hBRJHADqs2gAgBs-VAAAAhmg"]
[Mon Jul 20 07:22:13.935369 2026] [security2:error] [pid 110058:tid 110152] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/.ssh/id_rsa"] [unique_id "al4hBRJHADqs2gAgBs-VAQAAhlw"]
[Mon Jul 20 07:22:14.015777 2026] [security2:error] [pid 110058:tid 110190] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-U_wAAhnY"]
[Mon Jul 20 07:22:14.041293 2026] [security2:error] [pid 110058:tid 110271] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-VDwAAANc"]
[Mon Jul 20 07:22:14.045806 2026] [security2:error] [pid 110058:tid 110303] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-VEQAAAPc"]
[Mon Jul 20 07:22:14.048305 2026] [security2:error] [pid 110058:tid 110243] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-VDgAAALs"]
[Mon Jul 20 07:22:14.050888 2026] [security2:error] [pid 110058:tid 110220] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-VEAAAAKQ"]
[Mon Jul 20 07:22:14.186131 2026] [security2:error] [pid 110058:tid 110203] [client 172.212.190.89:4985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/storage/index.php"] [unique_id "al4hBhJHADqs2gAgBs-VJwAAAJM"]
[Mon Jul 20 07:22:14.186262 2026] [security2:error] [pid 110058:tid 110203] [client 172.212.190.89:4985] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/storage/index.php"] [unique_id "al4hBhJHADqs2gAgBs-VJwAAAJM"]
[Mon Jul 20 07:22:14.241671 2026] [security2:error] [pid 110058:tid 110239] [client 140.245.46.64:52735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hBhJHADqs2gAgBs-VKQAAALc"]
[Mon Jul 20 07:22:14.285231 2026] [security2:error] [pid 110058:tid 110277] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-U5wAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:14.288250 2026] [security2:error] [pid 110058:tid 110077] [remote 57.141.18.59:45296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2896560"] [unique_id "al4hBhJHADqs2gAgBs-VKwAAiBI"]
[Mon Jul 20 07:22:14.317686 2026] [security2:error] [pid 110058:tid 110240] [client 77.110.127.138:64436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hBRJHADqs2gAgBs-U4gAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:14.520271 2026] [security2:error] [pid 110058:tid 110275] [client 154.192.123.127:18076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hBhJHADqs2gAgBs-VPwAAANs"]
[Mon Jul 20 07:22:14.520393 2026] [security2:error] [pid 110058:tid 110275] [client 154.192.123.127:18076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hBhJHADqs2gAgBs-VPwAAANs"]
[Mon Jul 20 07:22:14.564737 2026] [security2:error] [pid 110058:tid 110295] [client 172.212.190.89:6504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/g.php"] [unique_id "al4hBhJHADqs2gAgBs-VRQAAAO8"]
[Mon Jul 20 07:22:14.564836 2026] [security2:error] [pid 110058:tid 110295] [client 172.212.190.89:6504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/g.php"] [unique_id "al4hBhJHADqs2gAgBs-VRQAAAO8"]
[Mon Jul 20 07:22:14.810892 2026] [security2:error] [pid 110058:tid 110245] [client 140.245.46.64:53036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4hBhJHADqs2gAgBs-VVQAAAL0"]
[Mon Jul 20 07:22:14.922186 2026] [security2:error] [pid 110058:tid 110310] [client 77.110.127.138:64438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBhJHADqs2gAgBs-VWAAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:14.922284 2026] [security2:error] [pid 110058:tid 110310] [client 77.110.127.138:64438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBhJHADqs2gAgBs-VWAAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.001856 2026] [security2:error] [pid 110058:tid 110300] [client 52.109.28.48:25345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hBhJHADqs2gAgBs-VYwAAAPQ"]
[Mon Jul 20 07:22:15.038426 2026] [security2:error] [pid 110058:tid 110134] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "retzkolonglogistics.com"] [uri "/id_rsa"] [unique_id "al4hBxJHADqs2gAgBs-VaAAAxEo"]
[Mon Jul 20 07:22:15.038591 2026] [security2:error] [pid 110058:tid 110252] [client 104.28.211.187:57863] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "retzkolonglogistics.com"] [uri "/id_rsa"] [unique_id "al4hBxJHADqs2gAgBs-VaAAAxEo"]
[Mon Jul 20 07:22:15.047703 2026] [security2:error] [pid 110058:tid 110295] [client 77.110.127.138:64400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VawAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.047844 2026] [security2:error] [pid 110058:tid 110295] [client 77.110.127.138:64400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VawAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.077273 2026] [security2:error] [pid 110058:tid 110313] [client 172.212.190.89:13087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/nf.php"] [unique_id "al4hBxJHADqs2gAgBs-VbwAAAQE"]
[Mon Jul 20 07:22:15.077378 2026] [security2:error] [pid 110058:tid 110313] [client 172.212.190.89:13087] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/nf.php"] [unique_id "al4hBxJHADqs2gAgBs-VbwAAAQE"]
[Mon Jul 20 07:22:15.140770 2026] [security2:error] [pid 110058:tid 110200] [client 52.109.28.48:25345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hBxJHADqs2gAgBs-VeAAAAJA"]
[Mon Jul 20 07:22:15.143421 2026] [security2:error] [pid 110058:tid 110231] [client 57.141.18.94:53604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hBBJHADqs2gAgBs-UdQAAr1M"]
[Mon Jul 20 07:22:15.195064 2026] [security2:error] [pid 110058:tid 110098] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "retzkolonglogistics.com"] [uri "/id_dsa"] [unique_id "al4hBxJHADqs2gAgBs-VfAAAkyc"]
[Mon Jul 20 07:22:15.240313 2026] [security2:error] [pid 110058:tid 110084] [remote 5.161.225.162:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hBxJHADqs2gAgBs-VfwAAmRk"]
[Mon Jul 20 07:22:15.284245 2026] [security2:error] [pid 110058:tid 110275] [client 104.234.53.74:47993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hBxJHADqs2gAgBs-VfgAAANs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:15.365386 2026] [security2:error] [pid 110058:tid 110316] [client 77.110.127.138:64431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VjgAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.365494 2026] [security2:error] [pid 110058:tid 110316] [client 77.110.127.138:64431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VjgAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.382335 2026] [security2:error] [pid 110058:tid 110272] [client 140.245.46.64:53303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4hBxJHADqs2gAgBs-VkAAAANg"]
[Mon Jul 20 07:22:15.387458 2026] [security2:error] [pid 110058:tid 110252] [client 172.212.190.89:1564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/xda.php"] [unique_id "al4hBxJHADqs2gAgBs-VkwAAAMQ"]
[Mon Jul 20 07:22:15.387541 2026] [security2:error] [pid 110058:tid 110252] [client 172.212.190.89:1564] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/xda.php"] [unique_id "al4hBxJHADqs2gAgBs-VkwAAAMQ"]
[Mon Jul 20 07:22:15.443697 2026] [security2:error] [pid 110058:tid 110241] [client 14.225.17.146:49164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4hBxJHADqs2gAgBs-VgAAAALk"], referer: http://windowtx.com/2018
[Mon Jul 20 07:22:15.488508 2026] [security2:error] [pid 110058:tid 110147] [remote 5.161.225.162:60362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hBxJHADqs2gAgBs-VmwAArVc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:22:15.490090 2026] [security2:error] [pid 110058:tid 110208] [client 14.225.17.146:50752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4hBxJHADqs2gAgBs-VigAAAJg"]
[Mon Jul 20 07:22:15.510507 2026] [security2:error] [pid 110058:tid 110227] [client 77.110.127.138:64416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VnwAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.510643 2026] [security2:error] [pid 110058:tid 110227] [client 77.110.127.138:64416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VnwAAAKs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.626727 2026] [security2:error] [pid 110058:tid 110192] [client 45.157.112.60:48179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hBxJHADqs2gAgBs-VqwAAAIg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:22:15.631517 2026] [security2:error] [pid 110058:tid 110287] [client 185.55.243.121:56351] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "superiorcopywriting.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4hBxJHADqs2gAgBs-VrAAAAOc"]
[Mon Jul 20 07:22:15.642788 2026] [security2:error] [pid 110058:tid 110299] [client 82.102.18.116:47466] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4hBxJHADqs2gAgBs-VrgAAAPM"]
[Mon Jul 20 07:22:15.653452 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VrwAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.653559 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hBxJHADqs2gAgBs-VrwAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:15.684671 2026] [security2:error] [pid 110058:tid 110100] [remote 104.28.211.187:57863] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "retzkolonglogistics.com"] [uri "/v1/graphql"] [unique_id "al4hBxJHADqs2gAgBs-VsQAAtik"]
[Mon Jul 20 07:22:15.714824 2026] [security2:error] [pid 110058:tid 110239] [client 14.225.17.146:50227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4hBxJHADqs2gAgBs-VowAAALc"], referer: http://fineartsfactory.net/2018
[Mon Jul 20 07:22:15.827461 2026] [security2:error] [pid 110058:tid 110225] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBxJHADqs2gAgBs-VuQAAAKk"]
[Mon Jul 20 07:22:15.918846 2026] [security2:error] [pid 110058:tid 110259] [client 187.16.64.216:51773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hBxJHADqs2gAgBs-VxgAAAMs"]
[Mon Jul 20 07:22:15.918968 2026] [security2:error] [pid 110058:tid 110259] [client 187.16.64.216:51773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hBxJHADqs2gAgBs-VxgAAAMs"]
[Mon Jul 20 07:22:15.936585 2026] [security2:error] [pid 110058:tid 110255] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hBxJHADqs2gAgBs-VwgAAAMc"]
[Mon Jul 20 07:22:15.947068 2026] [security2:error] [pid 110058:tid 110205] [client 172.212.190.89:6467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/shell.php"] [unique_id "al4hBxJHADqs2gAgBs-VyAAAAJU"]
[Mon Jul 20 07:22:15.947172 2026] [security2:error] [pid 110058:tid 110205] [client 172.212.190.89:6467] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/shell.php"] [unique_id "al4hBxJHADqs2gAgBs-VyAAAAJU"]
[Mon Jul 20 07:22:15.976596 2026] [security2:error] [pid 110058:tid 110195] [client 82.102.18.116:47480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hBxJHADqs2gAgBs-VzQAAAIs"]
[Mon Jul 20 07:22:16.182365 2026] [security2:error] [pid 110058:tid 110238] [client 77.110.127.138:64418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCBJHADqs2gAgBs-V5AAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:16.182454 2026] [security2:error] [pid 110058:tid 110238] [client 77.110.127.138:64418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCBJHADqs2gAgBs-V5AAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:16.276722 2026] [security2:error] [pid 110058:tid 110275] [client 77.110.127.138:64445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCBJHADqs2gAgBs-V6wAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:16.276840 2026] [security2:error] [pid 110058:tid 110275] [client 77.110.127.138:64445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCBJHADqs2gAgBs-V6wAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:16.278770 2026] [security2:error] [pid 110058:tid 110249] [client 185.55.243.121:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.243.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/xmlrpc.php"] [unique_id "al4hCBJHADqs2gAgBs-V6gAAAME"]
[Mon Jul 20 07:22:16.300016 2026] [security2:error] [pid 110058:tid 110219] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V5gAAo28"]
[Mon Jul 20 07:22:16.442166 2026] [security2:error] [pid 110058:tid 110276] [client 172.212.190.89:6494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/3.php"] [unique_id "al4hCBJHADqs2gAgBs-V_QAAANw"]
[Mon Jul 20 07:22:16.442344 2026] [security2:error] [pid 110058:tid 110276] [client 172.212.190.89:6494] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/3.php"] [unique_id "al4hCBJHADqs2gAgBs-V_QAAANw"]
[Mon Jul 20 07:22:16.456611 2026] [security2:error] [pid 110058:tid 110263] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V9AAAzzo"]
[Mon Jul 20 07:22:16.462658 2026] [security2:error] [pid 110058:tid 110263] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V9QAAz0Q"]
[Mon Jul 20 07:22:16.464803 2026] [security2:error] [pid 110058:tid 110263] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V8wAAzxs"]
[Mon Jul 20 07:22:16.474804 2026] [security2:error] [pid 110058:tid 110263] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V-QAAz1k"]
[Mon Jul 20 07:22:16.479801 2026] [security2:error] [pid 110058:tid 110263] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V-AAAz0E"]
[Mon Jul 20 07:22:16.483005 2026] [security2:error] [pid 110058:tid 110216] [client 82.102.18.116:47484] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4hCBJHADqs2gAgBs-V_gAAAKA"]
[Mon Jul 20 07:22:16.491776 2026] [security2:error] [pid 110058:tid 110263] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V9wAAzzw"]
[Mon Jul 20 07:22:16.506213 2026] [security2:error] [pid 110058:tid 110197] [client 104.28.211.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V-wAAAI0"]
[Mon Jul 20 07:22:16.698991 2026] [security2:error] [pid 110058:tid 110307] [client 104.234.53.47:27607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hCBJHADqs2gAgBs-WGgAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:16.830520 2026] [security2:error] [pid 110058:tid 110207] [client 82.102.18.116:47486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4hCBJHADqs2gAgBs-WJwAAAJc"]
[Mon Jul 20 07:22:16.969508 2026] [security2:error] [pid 110058:tid 110200] [client 14.225.17.146:59792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-WKQAAAJA"], referer: http://betterbonddogtraining.com/2018
[Mon Jul 20 07:22:17.165703 2026] [security2:error] [pid 110058:tid 110225] [client 172.212.190.89:5606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.190.212.172.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.trinacria.ca"] [uri "/mds.php"] [unique_id "al4hCRJHADqs2gAgBs-WQwAAAKk"]
[Mon Jul 20 07:22:17.165833 2026] [security2:error] [pid 110058:tid 110225] [client 172.212.190.89:5606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.trinacria.ca"] [uri "/mds.php"] [unique_id "al4hCRJHADqs2gAgBs-WQwAAAKk"]
[Mon Jul 20 07:22:17.170985 2026] [security2:error] [pid 110058:tid 110295] [client 14.225.17.146:50900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4hCBJHADqs2gAgBs-V2AAAAO8"], referer: http://travelbyfire.com/2018
[Mon Jul 20 07:22:17.176805 2026] [security2:error] [pid 110058:tid 110309] [client 82.102.18.116:47494] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4hCRJHADqs2gAgBs-WRwAAAP0"]
[Mon Jul 20 07:22:17.224520 2026] [security2:error] [pid 110058:tid 110195] [client 77.110.127.138:64449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WTAAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:17.224611 2026] [security2:error] [pid 110058:tid 110195] [client 77.110.127.138:64449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WTAAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:17.237382 2026] [security2:error] [pid 110058:tid 110290] [client 77.110.127.138:64432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WUAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:17.237467 2026] [security2:error] [pid 110058:tid 110290] [client 77.110.127.138:64432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WUAAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:17.240196 2026] [security2:error] [pid 110058:tid 110216] [client 34.208.80.94:59788] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4hCRJHADqs2gAgBs-WNQAAAKA"]
[Mon Jul 20 07:22:17.255496 2026] [autoindex:error] [pid 110058:tid 110196] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/themes/mai-lifestyle-pro/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:22:17.289317 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:64435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WVAAAAP8"]
[Mon Jul 20 07:22:17.289437 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:64435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WVAAAAP8"]
[Mon Jul 20 07:22:17.342290 2026] [security2:error] [pid 110058:tid 110222] [client 77.110.127.138:64433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WVgAAAKY"]
[Mon Jul 20 07:22:17.342445 2026] [security2:error] [pid 110058:tid 110222] [client 77.110.127.138:64433] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hCRJHADqs2gAgBs-WVgAAAKY"]
[Mon Jul 20 07:22:17.498997 2026] [security2:error] [pid 110058:tid 110276] [client 82.102.18.116:47504] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4hCRJHADqs2gAgBs-WZQAAANw"]
[Mon Jul 20 07:22:17.499702 2026] [security2:error] [pid 110058:tid 110248] [client 98.159.234.160:33073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hCRJHADqs2gAgBs-WZgAAAMA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:22:17.590825 2026] [security2:error] [pid 110058:tid 110289] [client 136.158.60.21:44] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hCRJHADqs2gAgBs-WawAAAOk"]
[Mon Jul 20 07:22:17.590947 2026] [security2:error] [pid 110058:tid 110289] [client 136.158.60.21:44] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hCRJHADqs2gAgBs-WawAAAOk"]
[Mon Jul 20 07:22:17.825703 2026] [security2:error] [pid 110058:tid 110253] [client 82.102.18.116:47512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4hCRJHADqs2gAgBs-WiQAAAMU"]
[Mon Jul 20 07:22:17.917496 2026] [security2:error] [pid 110058:tid 110216] [client 72.14.187.58:50662] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4hCRJHADqs2gAgBs-WgAAAAKA"]
[Mon Jul 20 07:22:18.110738 2026] [security2:error] [pid 110058:tid 110251] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hChJHADqs2gAgBs-WogAAwws"]
[Mon Jul 20 07:22:18.138520 2026] [security2:error] [pid 110058:tid 110283] [client 82.102.18.116:44232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4hChJHADqs2gAgBs-WsQAAAOM"]
[Mon Jul 20 07:22:18.147958 2026] [proxy:error] [pid 110058:tid 110291] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:18.148046 2026] [proxy_http:error] [pid 110058:tid 110291] [client 87.236.176.164:51849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:18.148616 2026] [proxy:error] [pid 110058:tid 110291] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:18.148660 2026] [proxy_http:error] [pid 110058:tid 110291] [client 87.236.176.164:51849] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:18.198197 2026] [security2:error] [pid 110058:tid 110193] [client 14.225.17.146:49339] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4hChJHADqs2gAgBs-WsgAAAIk"], referer: https://travelbyfire.com/2018
[Mon Jul 20 07:22:18.330932 2026] [security2:error] [pid 110058:tid 110249] [client 143.44.185.218:22079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hChJHADqs2gAgBs-WyQAAAME"]
[Mon Jul 20 07:22:18.331107 2026] [security2:error] [pid 110058:tid 110249] [client 143.44.185.218:22079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hChJHADqs2gAgBs-WyQAAAME"]
[Mon Jul 20 07:22:18.350662 2026] [security2:error] [pid 110058:tid 110273] [client 50.116.65.227:11818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hChJHADqs2gAgBs-WtwAAANk"]
[Mon Jul 20 07:22:18.411221 2026] [security2:error] [pid 110058:tid 110302] [client 104.28.211.187:57863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hChJHADqs2gAgBs-WxwAA9hA"]
[Mon Jul 20 07:22:18.412188 2026] [security2:error] [pid 110058:tid 110311] [client 140.245.46.64:54635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-includes/version.php"] [unique_id "al4hChJHADqs2gAgBs-W0AAAAP8"]
[Mon Jul 20 07:22:18.460528 2026] [core:error] [pid 110058:tid 110221] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:18.460548 2026] [core:error] [pid 110058:tid 110221] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:18.483397 2026] [security2:error] [pid 110058:tid 110200] [client 77.110.127.138:64448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W1gAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:18.483574 2026] [security2:error] [pid 110058:tid 110200] [client 77.110.127.138:64448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W1gAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:18.493975 2026] [security2:error] [pid 110058:tid 110251] [client 82.102.18.116:44244] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4hChJHADqs2gAgBs-W1wAAAMM"]
[Mon Jul 20 07:22:18.538427 2026] [security2:error] [pid 110058:tid 110308] [client 77.110.127.138:64413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W3AAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:18.538572 2026] [security2:error] [pid 110058:tid 110308] [client 77.110.127.138:64413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W3AAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:18.554190 2026] [security2:error] [pid 110058:tid 110267] [client 50.116.65.227:11830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hChJHADqs2gAgBs-WzQAAANM"]
[Mon Jul 20 07:22:18.594216 2026] [security2:error] [pid 110058:tid 110190] [client 104.234.53.87:45167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hChJHADqs2gAgBs-W4AAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:18.669668 2026] [security2:error] [pid 110058:tid 110254] [client 77.110.127.138:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W5wAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:18.669760 2026] [security2:error] [pid 110058:tid 110254] [client 77.110.127.138:64452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W5wAAAMY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:18.715821 2026] [security2:error] [pid 110058:tid 110306] [client 77.110.127.138:64453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W7QAAAPo"]
[Mon Jul 20 07:22:18.715922 2026] [security2:error] [pid 110058:tid 110306] [client 77.110.127.138:64453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hChJHADqs2gAgBs-W7QAAAPo"]
[Mon Jul 20 07:22:18.828591 2026] [security2:error] [pid 110058:tid 110302] [client 82.102.18.116:44254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4hChJHADqs2gAgBs-W9QAAAPY"]
[Mon Jul 20 07:22:18.958458 2026] [security2:error] [pid 110058:tid 110240] [client 202.141.11.99:35952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hChJHADqs2gAgBs-W-wAAALg"]
[Mon Jul 20 07:22:18.958569 2026] [security2:error] [pid 110058:tid 110240] [client 202.141.11.99:35952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hChJHADqs2gAgBs-W-wAAALg"]
[Mon Jul 20 07:22:18.973044 2026] [security2:error] [pid 110058:tid 110243] [client 158.173.89.95:20839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hChJHADqs2gAgBs-XAQAAALs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:22:18.984347 2026] [security2:error] [pid 110058:tid 110196] [client 140.245.46.64:54909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-includes/functions.php"] [unique_id "al4hChJHADqs2gAgBs-XAgAAAIw"]
[Mon Jul 20 07:22:19.167479 2026] [security2:error] [pid 110058:tid 110194] [client 82.102.18.116:44264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4hCxJHADqs2gAgBs-XEwAAAIo"]
[Mon Jul 20 07:22:19.177263 2026] [security2:error] [pid 110058:tid 110241] [client 117.211.236.168:56369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hCxJHADqs2gAgBs-XFAAAALk"]
[Mon Jul 20 07:22:19.177371 2026] [security2:error] [pid 110058:tid 110241] [client 117.211.236.168:56369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hCxJHADqs2gAgBs-XFAAAALk"]
[Mon Jul 20 07:22:19.295701 2026] [security2:error] [pid 110058:tid 110316] [client 57.141.18.29:20784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hCRJHADqs2gAgBs-WMQABBFo"]
[Mon Jul 20 07:22:19.494503 2026] [security2:error] [pid 110058:tid 110290] [client 82.102.18.116:44280] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4hCxJHADqs2gAgBs-XOAAAAOo"]
[Mon Jul 20 07:22:19.536434 2026] [security2:error] [pid 110058:tid 110257] [client 185.55.243.121:57054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.243.55.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/xmlrpc.php"] [unique_id "al4hCxJHADqs2gAgBs-XOgAAAMk"]
[Mon Jul 20 07:22:19.536586 2026] [security2:error] [pid 110058:tid 110257] [client 185.55.243.121:57054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "superiorcopywriting.com"] [uri "/xmlrpc.php"] [unique_id "al4hCxJHADqs2gAgBs-XOgAAAMk"]
[Mon Jul 20 07:22:19.554113 2026] [security2:error] [pid 110058:tid 110230] [client 140.245.46.64:55193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4hCxJHADqs2gAgBs-XPQAAAK4"]
[Mon Jul 20 07:22:19.804659 2026] [security2:error] [pid 110058:tid 110193] [client 14.225.17.146:55626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4hCxJHADqs2gAgBs-XJAAAAIk"], referer: http://talknutritionwithlesley.com/2018
[Mon Jul 20 07:22:19.828717 2026] [security2:error] [pid 110058:tid 110208] [client 82.102.18.116:44284] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4hCxJHADqs2gAgBs-XUAAAAJg"]
[Mon Jul 20 07:22:19.938979 2026] [security2:error] [pid 110058:tid 110231] [client 14.225.17.146:64287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4hChJHADqs2gAgBs-W3gAAAK8"], referer: http://alchemygroup.ca/2018
[Mon Jul 20 07:22:20.095735 2026] [security2:error] [pid 110058:tid 110228] [client 77.110.127.138:64437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDBJHADqs2gAgBs-XaAAAAKw"]
[Mon Jul 20 07:22:20.095899 2026] [security2:error] [pid 110058:tid 110228] [client 77.110.127.138:64437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDBJHADqs2gAgBs-XaAAAAKw"]
[Mon Jul 20 07:22:20.103247 2026] [security2:error] [pid 110058:tid 110194] [client 49.37.242.14:61782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hDBJHADqs2gAgBs-XaQAAAIo"]
[Mon Jul 20 07:22:20.103360 2026] [security2:error] [pid 110058:tid 110194] [client 49.37.242.14:61782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hDBJHADqs2gAgBs-XaQAAAIo"]
[Mon Jul 20 07:22:20.122722 2026] [security2:error] [pid 110058:tid 110270] [client 140.245.46.64:55415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-includes/option.php"] [unique_id "al4hDBJHADqs2gAgBs-XagAAANY"]
[Mon Jul 20 07:22:20.152119 2026] [security2:error] [pid 110058:tid 110200] [client 82.102.18.116:44292] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4hDBJHADqs2gAgBs-XbgAAAJA"]
[Mon Jul 20 07:22:20.407470 2026] [security2:error] [pid 110058:tid 110313] [client 104.234.53.48:20367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hDBJHADqs2gAgBs-XiAAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:20.481644 2026] [security2:error] [pid 110058:tid 110290] [client 82.102.18.116:44306] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4hDBJHADqs2gAgBs-XjgAAAOo"]
[Mon Jul 20 07:22:20.582871 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDBJHADqs2gAgBs-XlAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:20.582969 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDBJHADqs2gAgBs-XlAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:20.594821 2026] [security2:error] [pid 110058:tid 110289] [client 14.225.17.146:54250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4hDBJHADqs2gAgBs-XggAAAOk"], referer: http://idigress.agency/2018
[Mon Jul 20 07:22:20.692510 2026] [security2:error] [pid 110058:tid 110292] [client 140.245.46.64:55659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-includes/post.php"] [unique_id "al4hDBJHADqs2gAgBs-XqwAAAOw"]
[Mon Jul 20 07:22:20.817570 2026] [security2:error] [pid 110058:tid 110199] [client 82.102.18.116:44310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4hDBJHADqs2gAgBs-XvQAAAI8"]
[Mon Jul 20 07:22:21.077122 2026] [security2:error] [pid 110058:tid 110300] [client 49.47.218.174:50006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-X0wAAAPQ"]
[Mon Jul 20 07:22:21.077223 2026] [security2:error] [pid 110058:tid 110300] [client 49.47.218.174:50006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-X0wAAAPQ"]
[Mon Jul 20 07:22:21.136780 2026] [security2:error] [pid 110058:tid 110254] [client 82.102.18.116:44316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4hDRJHADqs2gAgBs-X1QAAAMY"]
[Mon Jul 20 07:22:21.240305 2026] [security2:error] [pid 110058:tid 110210] [client 14.225.17.146:50370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4hDRJHADqs2gAgBs-X1AAAAJo"]
[Mon Jul 20 07:22:21.264678 2026] [security2:error] [pid 110058:tid 110220] [client 140.245.46.64:55887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-includes/user.php"] [unique_id "al4hDRJHADqs2gAgBs-X3QAAAKQ"]
[Mon Jul 20 07:22:21.456527 2026] [security2:error] [pid 110058:tid 110245] [client 82.102.18.116:44332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.fvx.wyy.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4hDRJHADqs2gAgBs-X8wAAAL0"]
[Mon Jul 20 07:22:21.463327 2026] [security2:error] [pid 110058:tid 110244] [client 103.176.215.66:65227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-X9AAAALw"]
[Mon Jul 20 07:22:21.463479 2026] [security2:error] [pid 110058:tid 110244] [client 103.176.215.66:65227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-X9AAAALw"]
[Mon Jul 20 07:22:21.522225 2026] [security2:error] [pid 110058:tid 110295] [client 77.110.127.138:64465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDRJHADqs2gAgBs-X-QAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:21.522322 2026] [security2:error] [pid 110058:tid 110295] [client 77.110.127.138:64465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDRJHADqs2gAgBs-X-QAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:21.551705 2026] [security2:error] [pid 110058:tid 110249] [client 114.119.136.150:47397] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.bandsir.com"] [uri "/es_template/hello-world-newsletter/page/9/"] [unique_id "al4hDRJHADqs2gAgBs-X-wAAAME"], referer: https://www.bandsir.com/es_template/hello-world-newsletter/page/11/
[Mon Jul 20 07:22:21.670317 2026] [security2:error] [pid 110058:tid 110215] [client 154.208.48.130:63597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-YAQAAAJ8"]
[Mon Jul 20 07:22:21.670482 2026] [security2:error] [pid 110058:tid 110215] [client 154.208.48.130:63597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-YAQAAAJ8"]
[Mon Jul 20 07:22:21.687964 2026] [security2:error] [pid 110058:tid 110296] [client 52.59.238.198:45582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4hDRJHADqs2gAgBs-YAAAAAPA"], referer: https://curlsnpearlsss.com/es/budin-de-pan-puerto-rican-style-bread-pudding/
[Mon Jul 20 07:22:21.948910 2026] [security2:error] [pid 110058:tid 110254] [client 216.24.212.78:52995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4hDRJHADqs2gAgBs-YKAAAAMY"]
[Mon Jul 20 07:22:21.954024 2026] [security2:error] [pid 110058:tid 110211] [client 36.93.152.155:56732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-YKQAAAJs"]
[Mon Jul 20 07:22:21.954187 2026] [security2:error] [pid 110058:tid 110211] [client 36.93.152.155:56732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-YKQAAAJs"]
[Mon Jul 20 07:22:21.956877 2026] [security2:error] [pid 110058:tid 110300] [client 216.24.212.44:30691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4hDRJHADqs2gAgBs-YJwAAAPQ"]
[Mon Jul 20 07:22:21.980746 2026] [security2:error] [pid 110058:tid 110262] [client 157.20.138.62:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-YKgAAAM4"]
[Mon Jul 20 07:22:21.980903 2026] [security2:error] [pid 110058:tid 110262] [client 157.20.138.62:60755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hDRJHADqs2gAgBs-YKgAAAM4"]
[Mon Jul 20 07:22:22.170822 2026] [security2:error] [pid 110058:tid 110190] [client 57.141.18.91:43682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hDBJHADqs2gAgBs-XYAAAhiw"]
[Mon Jul 20 07:22:22.206974 2026] [security2:error] [pid 110058:tid 110291] [client 104.234.53.55:35775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hDhJHADqs2gAgBs-YMwAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:22.239700 2026] [security2:error] [pid 110058:tid 110246] [client 191.202.66.27:60975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hDhJHADqs2gAgBs-YNAAAAL4"]
[Mon Jul 20 07:22:22.239833 2026] [security2:error] [pid 110058:tid 110246] [client 191.202.66.27:60975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hDhJHADqs2gAgBs-YNAAAAL4"]
[Mon Jul 20 07:22:22.308482 2026] [security2:error] [pid 110058:tid 110238] [client 14.225.17.146:55600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4hDBJHADqs2gAgBs-XgwAAALY"], referer: http://narv.co/2018
[Mon Jul 20 07:22:22.312402 2026] [security2:error] [pid 110058:tid 110207] [client 3.67.192.83:57954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4hDhJHADqs2gAgBs-YQAAAAJc"], referer: https://curlsnpearlsss.com/es/budin-de-pan-puerto-rican-style-bread-pudding/
[Mon Jul 20 07:22:22.418441 2026] [security2:error] [pid 110058:tid 110243] [client 88.241.67.160:53745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hDhJHADqs2gAgBs-YTQAAALs"]
[Mon Jul 20 07:22:22.418556 2026] [security2:error] [pid 110058:tid 110243] [client 88.241.67.160:53745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hDhJHADqs2gAgBs-YTQAAALs"]
[Mon Jul 20 07:22:22.559821 2026] [security2:error] [pid 110058:tid 110280] [client 77.110.127.138:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDhJHADqs2gAgBs-YWAAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:22.559933 2026] [security2:error] [pid 110058:tid 110280] [client 77.110.127.138:64471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDhJHADqs2gAgBs-YWAAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:22.570349 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDhJHADqs2gAgBs-YWQAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:22.570424 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDhJHADqs2gAgBs-YWQAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:22.586712 2026] [security2:error] [pid 110058:tid 110185] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hDhJHADqs2gAgBs-YWgAApH0"]
[Mon Jul 20 07:22:22.586908 2026] [security2:error] [pid 110058:tid 110220] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hDhJHADqs2gAgBs-YWgAApH0"]
[Mon Jul 20 07:22:22.802979 2026] [security2:error] [pid 110058:tid 110271] [client 52.111.227.28:10881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hDhJHADqs2gAgBs-YagAAANc"]
[Mon Jul 20 07:22:22.857260 2026] [security2:error] [pid 110058:tid 110237] [client 52.111.227.28:10881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hDhJHADqs2gAgBs-YcQAAALU"]
[Mon Jul 20 07:22:22.911554 2026] [security2:error] [pid 110058:tid 110312] [client 54.236.251.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4hDhJHADqs2gAgBs-YYgABAF8"]
[Mon Jul 20 07:22:23.043201 2026] [security2:error] [pid 110058:tid 110309] [client 52.109.76.144:38529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hDxJHADqs2gAgBs-YfgAAAP0"]
[Mon Jul 20 07:22:23.156111 2026] [security2:error] [pid 110058:tid 110258] [client 3.67.192.83:57956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hDxJHADqs2gAgBs-YjQAAAMo"], referer: https://curlsnpearlsss.com/es/budin-de-pan-puerto-rican-style-bread-pudding/
[Mon Jul 20 07:22:23.164266 2026] [security2:error] [pid 110058:tid 110304] [client 3.67.192.83:57964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hDxJHADqs2gAgBs-YjwAAAPg"], referer: https://curlsnpearlsss.com/es/budin-de-pan-puerto-rican-style-bread-pudding/
[Mon Jul 20 07:22:23.166724 2026] [security2:error] [pid 110058:tid 110268] [client 63.177.52.239:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4hDxJHADqs2gAgBs-YjAAAANQ"], referer: https://curlsnpearlsss.com/es/budin-de-pan-puerto-rican-style-bread-pudding/
[Mon Jul 20 07:22:23.178061 2026] [security2:error] [pid 110058:tid 110261] [client 52.109.76.144:38529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hDxJHADqs2gAgBs-YkAAAAM0"]
[Mon Jul 20 07:22:23.289988 2026] [security2:error] [pid 110058:tid 110316] [client 14.225.17.146:64135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4hDRJHADqs2gAgBs-YDwAAAQQ"], referer: http://709fx.com/2018
[Mon Jul 20 07:22:23.315296 2026] [security2:error] [pid 110058:tid 110256] [client 57.141.18.84:48744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hDRJHADqs2gAgBs-X4wAAyGc"]
[Mon Jul 20 07:22:23.446070 2026] [security2:error] [pid 110058:tid 110213] [client 77.110.127.138:64458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDxJHADqs2gAgBs-YtQAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:23.446222 2026] [security2:error] [pid 110058:tid 110213] [client 77.110.127.138:64458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDxJHADqs2gAgBs-YtQAAAJ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:23.458725 2026] [security2:error] [pid 110058:tid 110307] [client 104.234.53.60:46105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hDxJHADqs2gAgBs-YtAAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:23.471369 2026] [security2:error] [pid 110058:tid 110243] [client 14.225.17.146:55623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4hDxJHADqs2gAgBs-YoAAAALs"], referer: https://narv.co/2018
[Mon Jul 20 07:22:23.491556 2026] [security2:error] [pid 110058:tid 110287] [client 103.106.165.44:64466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hDxJHADqs2gAgBs-YugAAAOc"]
[Mon Jul 20 07:22:23.491658 2026] [security2:error] [pid 110058:tid 110287] [client 103.106.165.44:64466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hDxJHADqs2gAgBs-YugAAAOc"]
[Mon Jul 20 07:22:23.602242 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDxJHADqs2gAgBs-YxQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:23.602401 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDxJHADqs2gAgBs-YxQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:23.697828 2026] [security2:error] [pid 110058:tid 110223] [client 14.225.17.146:54303] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4hDRJHADqs2gAgBs-YLQAAAKc"], referer: http://nomorewetsheets.net/2018
[Mon Jul 20 07:22:23.906208 2026] [security2:error] [pid 110058:tid 110307] [client 77.110.127.138:64480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDxJHADqs2gAgBs-Y4AAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:23.906340 2026] [security2:error] [pid 110058:tid 110307] [client 77.110.127.138:64480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hDxJHADqs2gAgBs-Y4AAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.043860 2026] [security2:error] [pid 110058:tid 110193] [client 14.225.17.146:64016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4hDxJHADqs2gAgBs-Y1wAAAIk"], referer: http://jvcmotorsports.com/2018
[Mon Jul 20 07:22:24.062985 2026] [security2:error] [pid 110058:tid 110221] [client 14.225.17.146:55554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4hDRJHADqs2gAgBs-X_QAAAKU"], referer: http://drewsasburyparkbeachhouse.com/2018
[Mon Jul 20 07:22:24.091787 2026] [security2:error] [pid 110058:tid 110215] [client 57.141.18.117:51338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hDhJHADqs2gAgBs-YMQAAnww"]
[Mon Jul 20 07:22:24.093977 2026] [security2:error] [pid 110058:tid 110216] [client 63.177.52.239:13668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hEBJHADqs2gAgBs-Y7gAAAKA"], referer: https://curlsnpearlsss.com/es/budin-de-pan-puerto-rican-style-bread-pudding/
[Mon Jul 20 07:22:24.372899 2026] [security2:error] [pid 110058:tid 110278] [client 77.110.127.138:64429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZBgAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.373027 2026] [security2:error] [pid 110058:tid 110278] [client 77.110.127.138:64429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZBgAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.441808 2026] [security2:error] [pid 110058:tid 110237] [client 77.110.127.138:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZEwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.441923 2026] [security2:error] [pid 110058:tid 110237] [client 77.110.127.138:64451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZEwAAALU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.488225 2026] [security2:error] [pid 110058:tid 110265] [client 77.110.127.138:64477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZHQAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.488404 2026] [security2:error] [pid 110058:tid 110265] [client 77.110.127.138:64477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZHQAAANE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.505397 2026] [security2:error] [pid 110058:tid 110298] [client 14.225.17.146:54647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4hDxJHADqs2gAgBs-YiAAAAPI"], referer: http://thechancersband.com/2018
[Mon Jul 20 07:22:24.538776 2026] [security2:error] [pid 110058:tid 110138] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hEBJHADqs2gAgBs-ZIwAA8E4"]
[Mon Jul 20 07:22:24.538981 2026] [security2:error] [pid 110058:tid 110296] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hEBJHADqs2gAgBs-ZIwAA8E4"]
[Mon Jul 20 07:22:24.540525 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZJQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.540614 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZJQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.593369 2026] [security2:error] [pid 110058:tid 110219] [client 77.110.127.138:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZLQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.593512 2026] [security2:error] [pid 110058:tid 110219] [client 77.110.127.138:64483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEBJHADqs2gAgBs-ZLQAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:24.797796 2026] [security2:error] [pid 110058:tid 110256] [client 20.55.35.128:55536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4hEBJHADqs2gAgBs-ZMAAAAMg"]
[Mon Jul 20 07:22:24.888865 2026] [security2:error] [pid 110058:tid 110307] [client 201.27.111.74:51525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hEBJHADqs2gAgBs-ZQAAAAPs"]
[Mon Jul 20 07:22:24.888977 2026] [security2:error] [pid 110058:tid 110307] [client 201.27.111.74:51525] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hEBJHADqs2gAgBs-ZQAAAAPs"]
[Mon Jul 20 07:22:25.087479 2026] [security2:error] [pid 110058:tid 110262] [client 154.192.123.127:18606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hERJHADqs2gAgBs-ZVAAAAM4"]
[Mon Jul 20 07:22:25.087626 2026] [security2:error] [pid 110058:tid 110262] [client 154.192.123.127:18606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hERJHADqs2gAgBs-ZVAAAAM4"]
[Mon Jul 20 07:22:25.100021 2026] [security2:error] [pid 110058:tid 110085] [remote 45.90.123.233:47010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4hERJHADqs2gAgBs-ZVQAA0Bo"]
[Mon Jul 20 07:22:25.159333 2026] [security2:error] [pid 110058:tid 110222] [client 77.110.127.138:64487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hERJHADqs2gAgBs-ZWgAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:25.159440 2026] [security2:error] [pid 110058:tid 110222] [client 77.110.127.138:64487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hERJHADqs2gAgBs-ZWgAAAKY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:25.171791 2026] [security2:error] [pid 110058:tid 110168] [remote 72.167.132.114:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4hERJHADqs2gAgBs-ZWQAA5mw"]
[Mon Jul 20 07:22:25.371002 2026] [security2:error] [pid 110058:tid 110177] [remote 72.167.132.114:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4hERJHADqs2gAgBs-ZcgAA93U"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 07:22:25.874416 2026] [security2:error] [pid 110058:tid 110108] [remote 68.178.160.25:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4hERJHADqs2gAgBs-ZnQAA-zE"]
[Mon Jul 20 07:22:25.878660 2026] [security2:error] [pid 110058:tid 110234] [client 77.110.127.138:64417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hERJHADqs2gAgBs-ZngAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:25.878794 2026] [security2:error] [pid 110058:tid 110234] [client 77.110.127.138:64417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hERJHADqs2gAgBs-ZngAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:26.090930 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:54277] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4hERJHADqs2gAgBs-ZlwAAAME"], referer: http://mcg.homes/2018
[Mon Jul 20 07:22:26.267186 2026] [security2:error] [pid 110058:tid 110124] [remote 68.178.160.25:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4hEhJHADqs2gAgBs-ZxQAAy0A"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:22:26.335171 2026] [security2:error] [pid 110058:tid 110231] [client 77.110.127.138:64473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEhJHADqs2gAgBs-Z0gAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:26.335299 2026] [security2:error] [pid 110058:tid 110231] [client 77.110.127.138:64473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEhJHADqs2gAgBs-Z0gAAAK8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:26.384831 2026] [security2:error] [pid 110058:tid 110059] [remote 195.26.244.42:47672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4hEhJHADqs2gAgBs-Z1gAAxgA"]
[Mon Jul 20 07:22:26.400788 2026] [security2:error] [pid 110058:tid 110293] [client 57.141.18.48:30130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hEBJHADqs2gAgBs-ZAQAA7XM"]
[Mon Jul 20 07:22:26.485603 2026] [security2:error] [pid 110058:tid 110095] [remote 45.90.123.233:47010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4hEhJHADqs2gAgBs-Z4QAA9CQ"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 07:22:26.552983 2026] [security2:error] [pid 110058:tid 110198] [client 187.16.64.216:52356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hEhJHADqs2gAgBs-Z8AAAAI4"]
[Mon Jul 20 07:22:26.553125 2026] [security2:error] [pid 110058:tid 110198] [client 187.16.64.216:52356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hEhJHADqs2gAgBs-Z8AAAAI4"]
[Mon Jul 20 07:22:26.741316 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEhJHADqs2gAgBs-aBgAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:26.741472 2026] [security2:error] [pid 110058:tid 110203] [client 77.110.127.138:64463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEhJHADqs2gAgBs-aBgAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:26.894736 2026] [security2:error] [pid 110058:tid 110300] [client 77.110.127.138:64496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEhJHADqs2gAgBs-aFgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:26.894840 2026] [security2:error] [pid 110058:tid 110300] [client 77.110.127.138:64496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hEhJHADqs2gAgBs-aFgAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:27.021891 2026] [security2:error] [pid 110058:tid 110194] [client 77.110.127.138:64476] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/if(now()=sysdate(),sleep(15),0)/modules/related-posts/related-posts.css"] [unique_id "al4hExJHADqs2gAgBs-aGwAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:27.071586 2026] [security2:error] [pid 110058:tid 110277] [client 77.110.127.138:64482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hExJHADqs2gAgBs-aHwAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:27.071697 2026] [security2:error] [pid 110058:tid 110277] [client 77.110.127.138:64482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hExJHADqs2gAgBs-aHwAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:27.121391 2026] [security2:error] [pid 110058:tid 110094] [remote 195.26.244.42:47672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4hExJHADqs2gAgBs-aJAAAzyM"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 07:22:27.315692 2026] [security2:error] [pid 110058:tid 110291] [client 57.141.18.102:44236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hERJHADqs2gAgBs-ZagAA61Q"]
[Mon Jul 20 07:22:27.770123 2026] [core:error] [pid 110058:tid 110254] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:27.770145 2026] [core:error] [pid 110058:tid 110254] [client 144.172.114.51:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:28.318394 2026] [security2:error] [pid 110058:tid 110181] [remote 5.161.225.162:45600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4hFBJHADqs2gAgBs-anQAA03k"]
[Mon Jul 20 07:22:28.339104 2026] [security2:error] [pid 110058:tid 110242] [client 136.158.60.21:1526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hFBJHADqs2gAgBs-anwAAALo"]
[Mon Jul 20 07:22:28.339265 2026] [security2:error] [pid 110058:tid 110242] [client 136.158.60.21:1526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hFBJHADqs2gAgBs-anwAAALo"]
[Mon Jul 20 07:22:28.494966 2026] [security2:error] [pid 110058:tid 110205] [client 57.141.18.48:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hFBJHADqs2gAgBs-amgAAAJU"]
[Mon Jul 20 07:22:28.550574 2026] [security2:error] [pid 110058:tid 110142] [remote 5.161.225.162:45600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4hFBJHADqs2gAgBs-asgAA2FI"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:22:28.552180 2026] [security2:error] [pid 110058:tid 110203] [client 14.225.17.146:54568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4hExJHADqs2gAgBs-aPgAAAJM"], referer: http://nikkidesigns.net/2018
[Mon Jul 20 07:22:28.675092 2026] [security2:error] [pid 110058:tid 110313] [client 104.234.53.57:37849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hFBJHADqs2gAgBs-avgAAAQE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:28.854901 2026] [security2:error] [pid 110058:tid 110310] [client 77.110.127.138:64488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/modules/related-posts/related-posts.css"] [unique_id "al4hFBJHADqs2gAgBs-a1gAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:28.972794 2026] [security2:error] [pid 110058:tid 110243] [client 57.141.18.59:54884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hEhJHADqs2gAgBs-aAgAAuw4"]
[Mon Jul 20 07:22:29.008064 2026] [security2:error] [pid 110058:tid 110279] [client 77.110.127.138:64503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hFRJHADqs2gAgBs-a8AAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:29.008174 2026] [security2:error] [pid 110058:tid 110279] [client 77.110.127.138:64503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hFRJHADqs2gAgBs-a8AAAAN8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:29.084460 2026] [security2:error] [pid 110058:tid 110061] [remote 5.161.225.162:47826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hFRJHADqs2gAgBs-a9wAA_QI"]
[Mon Jul 20 07:22:29.084646 2026] [security2:error] [pid 110058:tid 110309] [client 5.161.225.162:47826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hFRJHADqs2gAgBs-a9wAA_QI"]
[Mon Jul 20 07:22:29.101071 2026] [proxy:error] [pid 110058:tid 110283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:29.101161 2026] [proxy_http:error] [pid 110058:tid 110283] [client 198.235.24.158:62044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:29.102327 2026] [proxy:error] [pid 110058:tid 110283] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:29.102373 2026] [proxy_http:error] [pid 110058:tid 110283] [client 198.235.24.158:62044] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:29.386900 2026] [security2:error] [pid 110058:tid 110079] [remote 194.164.192.228:48818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4hFRJHADqs2gAgBs-bIgAAlRQ"]
[Mon Jul 20 07:22:29.402823 2026] [security2:error] [pid 110058:tid 110303] [client 57.141.18.68:57240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hExJHADqs2gAgBs-aJQAA9xw"]
[Mon Jul 20 07:22:29.410019 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hFRJHADqs2gAgBs-bKAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:29.410119 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hFRJHADqs2gAgBs-bKAAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:29.461221 2026] [security2:error] [pid 110058:tid 110211] [client 66.249.93.38:47636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4hFBJHADqs2gAgBs-a7gAAAJs"]
[Mon Jul 20 07:22:29.509036 2026] [security2:error] [pid 110058:tid 110253] [client 14.225.17.146:55282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4hExJHADqs2gAgBs-aPQAAAMU"], referer: http://itdynamix.com/2018
[Mon Jul 20 07:22:29.573693 2026] [security2:error] [pid 110058:tid 110143] [remote 194.164.192.228:48818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4hFRJHADqs2gAgBs-bNwAArVM"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:22:29.749746 2026] [security2:error] [pid 110058:tid 110287] [client 57.141.18.10:37006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hExJHADqs2gAgBs-aUwAA5zI"]
[Mon Jul 20 07:22:29.854191 2026] [core:error] [pid 110058:tid 110275] [client 144.172.114.51:43594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:29.854215 2026] [core:error] [pid 110058:tid 110275] [client 144.172.114.51:43594] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:30.018160 2026] [security2:error] [pid 110058:tid 110298] [client 50.116.65.227:24880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hFhJHADqs2gAgBs-bZgAAAPI"]
[Mon Jul 20 07:22:30.032314 2026] [security2:error] [pid 110058:tid 110199] [client 50.116.65.227:24882] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hFhJHADqs2gAgBs-bZwAAAI8"]
[Mon Jul 20 07:22:30.055210 2026] [security2:error] [pid 110058:tid 110076] [remote 167.172.73.193:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.73.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4hFhJHADqs2gAgBs-baQAAyhE"]
[Mon Jul 20 07:22:30.458115 2026] [security2:error] [pid 110058:tid 110075] [remote 167.172.73.193:59594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.73.172.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4hFhJHADqs2gAgBs-bkAAAzRA"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 07:22:30.487627 2026] [security2:error] [pid 110058:tid 110301] [client 77.110.127.138:64464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/modules/related-posts/related-posts.css"] [unique_id "al4hFhJHADqs2gAgBs-bmQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:30.527101 2026] [security2:error] [pid 110058:tid 110191] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4hFRJHADqs2gAgBs-bZQAAhxM"], referer: http://assasalnazaha.com/2018
[Mon Jul 20 07:22:30.562383 2026] [security2:error] [pid 110058:tid 110302] [client 14.225.17.146:55416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4hFhJHADqs2gAgBs-biQAAAPY"], referer: https://itdynamix.com/2018
[Mon Jul 20 07:22:30.711927 2026] [security2:error] [pid 110058:tid 110090] [remote 182.77.62.24:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4hFhJHADqs2gAgBs-bqAAAlB8"]
[Mon Jul 20 07:22:30.756577 2026] [security2:error] [pid 110058:tid 110215] [client 14.225.17.146:63669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4hFhJHADqs2gAgBs-boAAAAJ8"], referer: http://soloceos.com/2018
[Mon Jul 20 07:22:30.885671 2026] [security2:error] [pid 110058:tid 110260] [client 109.105.209.12:26758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4hFhJHADqs2gAgBs-bhAAAzDA"]
[Mon Jul 20 07:22:30.977832 2026] [security2:error] [pid 110058:tid 110284] [client 57.141.18.68:36900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hFBJHADqs2gAgBs-awgAA5Fs"]
[Mon Jul 20 07:22:31.059411 2026] [security2:error] [pid 110058:tid 110268] [client 140.245.46.64:60420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4hFxJHADqs2gAgBs-bzQAAANQ"]
[Mon Jul 20 07:22:31.233624 2026] [security2:error] [pid 110058:tid 110152] [remote 182.77.62.24:59412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4hFxJHADqs2gAgBs-b1QAAmVw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:22:31.291957 2026] [security2:error] [pid 110058:tid 110248] [client 117.211.236.168:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-b3wAAAMA"]
[Mon Jul 20 07:22:31.292065 2026] [security2:error] [pid 110058:tid 110248] [client 117.211.236.168:56914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-b3wAAAMA"]
[Mon Jul 20 07:22:31.387920 2026] [security2:error] [pid 110058:tid 110223] [client 109.105.209.12:26758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4hFhJHADqs2gAgBs-bxAAAp3o"]
[Mon Jul 20 07:22:31.531918 2026] [security2:error] [pid 110058:tid 110316] [client 49.47.218.174:60751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-b-gAAAQQ"]
[Mon Jul 20 07:22:31.532063 2026] [security2:error] [pid 110058:tid 110316] [client 49.47.218.174:60751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-b-gAAAQQ"]
[Mon Jul 20 07:22:31.703848 2026] [security2:error] [pid 110058:tid 110247] [client 143.44.185.218:23651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-cBAAAAL8"]
[Mon Jul 20 07:22:31.705904 2026] [security2:error] [pid 110058:tid 110247] [client 143.44.185.218:23651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-cBAAAAL8"]
[Mon Jul 20 07:22:31.717247 2026] [security2:error] [pid 110058:tid 110203] [client 54.216.131.115:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "secoaches.co"] [uri "/index.php"] [unique_id "al4hFxJHADqs2gAgBs-b9AAAAJM"]
[Mon Jul 20 07:22:31.721716 2026] [security2:error] [pid 110058:tid 110218] [client 54.216.131.115:58798] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "secoaches.co"] [uri "/contact-us-2/"] [unique_id "al4hFxJHADqs2gAgBs-b8QAAAKI"]
[Mon Jul 20 07:22:31.821074 2026] [security2:error] [pid 110058:tid 110294] [client 77.110.127.138:64513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hFxJHADqs2gAgBs-cEQAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:31.821180 2026] [security2:error] [pid 110058:tid 110294] [client 77.110.127.138:64513] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hFxJHADqs2gAgBs-cEQAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:31.953582 2026] [security2:error] [pid 110058:tid 110225] [client 103.176.215.66:49378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-cGAAAAKk"]
[Mon Jul 20 07:22:31.954048 2026] [security2:error] [pid 110058:tid 110225] [client 103.176.215.66:49378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hFxJHADqs2gAgBs-cGAAAAKk"]
[Mon Jul 20 07:22:32.017212 2026] [security2:error] [pid 110058:tid 110239] [client 57.141.18.112:53560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hFRJHADqs2gAgBs-bWAAAtys"]
[Mon Jul 20 07:22:32.221335 2026] [security2:error] [pid 110058:tid 110204] [client 77.110.127.138:64500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGBJHADqs2gAgBs-cKwAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:32.221437 2026] [security2:error] [pid 110058:tid 110204] [client 77.110.127.138:64500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGBJHADqs2gAgBs-cKwAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:32.302684 2026] [security2:error] [pid 110058:tid 110282] [client 14.225.17.146:53663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4hFhJHADqs2gAgBs-btQAAAOI"], referer: http://olearyplumbingllc.com/2018
[Mon Jul 20 07:22:32.339819 2026] [security2:error] [pid 110058:tid 110309] [client 49.37.242.14:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cQwAAAP0"]
[Mon Jul 20 07:22:32.339932 2026] [security2:error] [pid 110058:tid 110309] [client 49.37.242.14:62304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cQwAAAP0"]
[Mon Jul 20 07:22:32.356167 2026] [security2:error] [pid 110058:tid 110274] [client 36.93.152.155:57238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cRgAAANo"]
[Mon Jul 20 07:22:32.356259 2026] [security2:error] [pid 110058:tid 110274] [client 36.93.152.155:57238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cRgAAANo"]
[Mon Jul 20 07:22:32.409718 2026] [security2:error] [pid 110058:tid 110124] [remote 8.217.108.67:20242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cRwAApUA"]
[Mon Jul 20 07:22:32.409934 2026] [security2:error] [pid 110058:tid 110221] [client 8.217.108.67:20242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cRwAApUA"]
[Mon Jul 20 07:22:32.599118 2026] [security2:error] [pid 110058:tid 110302] [client 157.20.138.62:61344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cVgAAAPY"]
[Mon Jul 20 07:22:32.599246 2026] [security2:error] [pid 110058:tid 110302] [client 157.20.138.62:61344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cVgAAAPY"]
[Mon Jul 20 07:22:32.791691 2026] [security2:error] [pid 110058:tid 110196] [client 96.44.154.224:42622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hGBJHADqs2gAgBs-cWgAAAIw"]
[Mon Jul 20 07:22:32.869966 2026] [security2:error] [pid 110058:tid 110230] [client 191.202.66.27:61461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cbgAAAK4"]
[Mon Jul 20 07:22:32.870052 2026] [security2:error] [pid 110058:tid 110230] [client 191.202.66.27:61461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-cbgAAAK4"]
[Mon Jul 20 07:22:32.883263 2026] [security2:error] [pid 110058:tid 110247] [client 154.208.48.130:64132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-ccQAAAL8"]
[Mon Jul 20 07:22:32.885059 2026] [security2:error] [pid 110058:tid 110247] [client 154.208.48.130:64132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hGBJHADqs2gAgBs-ccQAAAL8"]
[Mon Jul 20 07:22:33.100440 2026] [security2:error] [pid 110058:tid 110268] [client 14.225.17.146:53550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4hFxJHADqs2gAgBs-cEgAAANQ"], referer: http://39ishlife.com/2018
[Mon Jul 20 07:22:33.128085 2026] [security2:error] [pid 110058:tid 110279] [client 88.241.67.160:56786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hGRJHADqs2gAgBs-cfAAAAN8"]
[Mon Jul 20 07:22:33.128213 2026] [security2:error] [pid 110058:tid 110279] [client 88.241.67.160:56786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hGRJHADqs2gAgBs-cfAAAAN8"]
[Mon Jul 20 07:22:33.331923 2026] [security2:error] [pid 110058:tid 110084] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hGRJHADqs2gAgBs-cjgAApxk"]
[Mon Jul 20 07:22:33.332131 2026] [security2:error] [pid 110058:tid 110223] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hGRJHADqs2gAgBs-cjgAApxk"]
[Mon Jul 20 07:22:33.432420 2026] [security2:error] [pid 110058:tid 110292] [client 74.208.214.194:50950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hGRJHADqs2gAgBs-cmgAAAOw"]
[Mon Jul 20 07:22:33.756532 2026] [security2:error] [pid 110058:tid 110206] [client 77.110.127.138:64434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGRJHADqs2gAgBs-ctgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:33.756705 2026] [security2:error] [pid 110058:tid 110206] [client 77.110.127.138:64434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGRJHADqs2gAgBs-ctgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:34.028587 2026] [security2:error] [pid 110058:tid 110219] [client 103.106.165.44:64928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hGhJHADqs2gAgBs-c0gAAAKM"]
[Mon Jul 20 07:22:34.028712 2026] [security2:error] [pid 110058:tid 110219] [client 103.106.165.44:64928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hGhJHADqs2gAgBs-c0gAAAKM"]
[Mon Jul 20 07:22:34.036296 2026] [security2:error] [pid 110058:tid 110104] [remote 103.28.36.106:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hGhJHADqs2gAgBs-c0wAAiS0"]
[Mon Jul 20 07:22:34.048521 2026] [security2:error] [pid 110058:tid 110304] [client 77.110.127.138:64520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGhJHADqs2gAgBs-c1AAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:34.048624 2026] [security2:error] [pid 110058:tid 110304] [client 77.110.127.138:64520] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGhJHADqs2gAgBs-c1AAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:34.453704 2026] [security2:error] [pid 110058:tid 110123] [remote 103.28.36.106:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hGhJHADqs2gAgBs-c8AAAlj8"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:22:34.673347 2026] [security2:error] [pid 110058:tid 110270] [client 96.44.154.224:42414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hGhJHADqs2gAgBs-dAAAAANY"]
[Mon Jul 20 07:22:34.839987 2026] [security2:error] [pid 110058:tid 110223] [client 201.27.111.74:52031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hGhJHADqs2gAgBs-dEwAAAKc"]
[Mon Jul 20 07:22:34.840088 2026] [security2:error] [pid 110058:tid 110223] [client 201.27.111.74:52031] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hGhJHADqs2gAgBs-dEwAAAKc"]
[Mon Jul 20 07:22:34.874568 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGhJHADqs2gAgBs-dFwAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:34.874654 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGhJHADqs2gAgBs-dFwAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:35.005521 2026] [security2:error] [pid 110058:tid 110266] [client 14.225.17.146:55243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hGhJHADqs2gAgBs-dDwAAANI"], referer: http://mezzacraft.com/2018
[Mon Jul 20 07:22:35.121109 2026] [security2:error] [pid 110058:tid 110107] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hGxJHADqs2gAgBs-dJgAAuzA"]
[Mon Jul 20 07:22:35.121279 2026] [security2:error] [pid 110058:tid 110243] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hGxJHADqs2gAgBs-dJgAAuzA"]
[Mon Jul 20 07:22:35.577296 2026] [security2:error] [pid 110058:tid 110228] [client 104.234.53.47:49275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hGxJHADqs2gAgBs-dVgAAAKw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:35.641368 2026] [security2:error] [pid 110058:tid 110239] [client 77.110.127.138:64481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGxJHADqs2gAgBs-dXAAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:35.641473 2026] [security2:error] [pid 110058:tid 110239] [client 77.110.127.138:64481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hGxJHADqs2gAgBs-dXAAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:35.692066 2026] [security2:error] [pid 110058:tid 110259] [client 154.192.123.127:17085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hGxJHADqs2gAgBs-dXgAAAMs"]
[Mon Jul 20 07:22:35.692199 2026] [security2:error] [pid 110058:tid 110259] [client 154.192.123.127:17085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hGxJHADqs2gAgBs-dXgAAAMs"]
[Mon Jul 20 07:22:35.704698 2026] [security2:error] [pid 110058:tid 110242] [client 14.225.17.146:58681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4hGxJHADqs2gAgBs-dTAAAALo"], referer: http://lifeisbetterlakeside.com/2018
[Mon Jul 20 07:22:35.925563 2026] [security2:error] [pid 110058:tid 110126] [remote 124.55.178.99:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4hGxJHADqs2gAgBs-deAAA8kI"]
[Mon Jul 20 07:22:36.341116 2026] [security2:error] [pid 110058:tid 110175] [remote 124.55.178.99:46628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4hHBJHADqs2gAgBs-dmQAAo3M"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 07:22:36.428363 2026] [security2:error] [pid 110058:tid 110218] [client 52.109.44.112:31114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hHBJHADqs2gAgBs-dpAAAAKI"]
[Mon Jul 20 07:22:36.537437 2026] [security2:error] [pid 110058:tid 110255] [client 104.234.53.49:43313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hHBJHADqs2gAgBs-dqQAAAMc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:36.567353 2026] [security2:error] [pid 110058:tid 110264] [client 57.141.18.115:20878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hGhJHADqs2gAgBs-c6QAA0A0"]
[Mon Jul 20 07:22:36.568383 2026] [security2:error] [pid 110058:tid 110265] [client 52.109.44.112:31114] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hHBJHADqs2gAgBs-drgAAANE"]
[Mon Jul 20 07:22:36.629506 2026] [security2:error] [pid 110058:tid 110267] [client 77.110.127.138:64519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hHBJHADqs2gAgBs-dtQAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:36.629600 2026] [security2:error] [pid 110058:tid 110267] [client 77.110.127.138:64519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hHBJHADqs2gAgBs-dtQAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:36.741829 2026] [security2:error] [pid 110058:tid 110306] [client 74.208.214.194:60146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hHBJHADqs2gAgBs-dvwAAAPo"]
[Mon Jul 20 07:22:37.276851 2026] [security2:error] [pid 110058:tid 110237] [client 187.16.64.216:52941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hHRJHADqs2gAgBs-d8AAAALU"]
[Mon Jul 20 07:22:37.276976 2026] [security2:error] [pid 110058:tid 110237] [client 187.16.64.216:52941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hHRJHADqs2gAgBs-d8AAAALU"]
[Mon Jul 20 07:22:37.379757 2026] [security2:error] [pid 110058:tid 110241] [client 96.44.154.224:42636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hHRJHADqs2gAgBs-d-QAAALk"]
[Mon Jul 20 07:22:37.861078 2026] [security2:error] [pid 110058:tid 110266] [client 14.225.17.146:55088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hHBJHADqs2gAgBs-dlwAAANI"], referer: http://nurturemarple.co.uk/2018
[Mon Jul 20 07:22:38.315260 2026] [security2:error] [pid 110058:tid 110292] [client 104.234.53.70:28043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hHhJHADqs2gAgBs-eQAAAAOw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:38.318058 2026] [security2:error] [pid 110058:tid 110238] [client 50.116.65.227:24986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hHRJHADqs2gAgBs-eLgAAALY"]
[Mon Jul 20 07:22:38.508459 2026] [security2:error] [pid 110058:tid 110224] [client 50.116.65.227:24988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hHhJHADqs2gAgBs-eQgAAAKg"]
[Mon Jul 20 07:22:38.526600 2026] [security2:error] [pid 110058:tid 110205] [client 14.225.17.146:58337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4hHhJHADqs2gAgBs-eTwAAAJU"], referer: http://backandneckpainrelieflaceychiropractor.com/2018
[Mon Jul 20 07:22:38.893880 2026] [security2:error] [pid 110058:tid 110219] [client 14.225.17.146:63601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hHhJHADqs2gAgBs-eYwAAAKM"], referer: https://nurturemarple.co.uk/2018
[Mon Jul 20 07:22:38.983055 2026] [security2:error] [pid 110058:tid 110276] [client 136.158.60.21:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hHhJHADqs2gAgBs-ecAAAANw"]
[Mon Jul 20 07:22:38.983169 2026] [security2:error] [pid 110058:tid 110276] [client 136.158.60.21:3079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hHhJHADqs2gAgBs-ecAAAANw"]
[Mon Jul 20 07:22:39.029840 2026] [security2:error] [pid 110058:tid 110263] [client 57.141.18.14:33060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hHBJHADqs2gAgBs-dwwAAzwU"]
[Mon Jul 20 07:22:39.223339 2026] [security2:error] [pid 110058:tid 110230] [client 96.44.154.224:32526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hHxJHADqs2gAgBs-efAAAAK4"]
[Mon Jul 20 07:22:39.859307 2026] [security2:error] [pid 110058:tid 110300] [client 57.141.18.32:29882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hHRJHADqs2gAgBs-eBAAA9GM"]
[Mon Jul 20 07:22:39.946930 2026] [security2:error] [pid 110058:tid 110160] [remote 188.166.241.141:40784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4hHxJHADqs2gAgBs-exwAA_mQ"]
[Mon Jul 20 07:22:40.718159 2026] [security2:error] [pid 110058:tid 110216] [client 57.141.18.44:44444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hHhJHADqs2gAgBs-eSQAAoCA"]
[Mon Jul 20 07:22:40.742790 2026] [security2:error] [pid 110058:tid 110078] [remote 8.217.108.67:20246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4hIBJHADqs2gAgBs-e_QAA6hM"]
[Mon Jul 20 07:22:40.776662 2026] [security2:error] [pid 110058:tid 110095] [remote 188.166.241.141:40784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4hIBJHADqs2gAgBs-fAAAAwyQ"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:22:40.872183 2026] [security2:error] [pid 110058:tid 110295] [client 3.84.173.24:61610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.173.84.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hIBJHADqs2gAgBs-fDAAAAO8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:22:41.736932 2026] [security2:error] [pid 110058:tid 110232] [client 14.225.17.146:58466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4hIBJHADqs2gAgBs-e4AAAALA"], referer: http://ghivs.com/2018
[Mon Jul 20 07:22:41.965499 2026] [security2:error] [pid 110058:tid 110253] [client 49.47.218.174:25987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hIRJHADqs2gAgBs-fUQAAAMU"]
[Mon Jul 20 07:22:41.965622 2026] [security2:error] [pid 110058:tid 110253] [client 49.47.218.174:25987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hIRJHADqs2gAgBs-fUQAAAMU"]
[Mon Jul 20 07:22:42.006343 2026] [security2:error] [pid 110058:tid 110211] [client 66.249.93.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4hIRJHADqs2gAgBs-fRgAAAJs"]
[Mon Jul 20 07:22:42.337822 2026] [security2:error] [pid 110058:tid 110258] [client 13.221.132.12:34140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.132.221.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hIhJHADqs2gAgBs-fdQAAAMo"]
[Mon Jul 20 07:22:42.452063 2026] [security2:error] [pid 110058:tid 110215] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hIhJHADqs2gAgBs-fegAAAJ8"]
[Mon Jul 20 07:22:42.478136 2026] [security2:error] [pid 110058:tid 110128] [remote 124.55.178.99:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4hIhJHADqs2gAgBs-fjQAA6kQ"]
[Mon Jul 20 07:22:42.522536 2026] [security2:error] [pid 110058:tid 110264] [client 103.176.215.66:49924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hIhJHADqs2gAgBs-fjwAAANA"]
[Mon Jul 20 07:22:42.522655 2026] [security2:error] [pid 110058:tid 110264] [client 103.176.215.66:49924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hIhJHADqs2gAgBs-fjwAAANA"]
[Mon Jul 20 07:22:42.641267 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hIhJHADqs2gAgBs-flgAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:42.641359 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hIhJHADqs2gAgBs-flgAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:42.749693 2026] [security2:error] [pid 110058:tid 110300] [client 3.90.176.61:21298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.176.90.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hIhJHADqs2gAgBs-fmwAAAPQ"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:22:42.902836 2026] [security2:error] [pid 110058:tid 110153] [remote 124.55.178.99:51380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4hIhJHADqs2gAgBs-fqwAA-F0"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:22:42.950150 2026] [security2:error] [pid 110058:tid 110316] [client 36.93.152.155:57743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hIhJHADqs2gAgBs-frQAAAQQ"]
[Mon Jul 20 07:22:42.950241 2026] [security2:error] [pid 110058:tid 110316] [client 36.93.152.155:57743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hIhJHADqs2gAgBs-frQAAAQQ"]
[Mon Jul 20 07:22:43.118074 2026] [security2:error] [pid 110058:tid 110113] [remote 8.217.108.67:23816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hIxJHADqs2gAgBs-fvAAA6DY"]
[Mon Jul 20 07:22:43.164298 2026] [security2:error] [pid 110058:tid 110249] [client 49.37.242.14:62789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-fvgAAAME"]
[Mon Jul 20 07:22:43.164431 2026] [security2:error] [pid 110058:tid 110249] [client 49.37.242.14:62789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-fvgAAAME"]
[Mon Jul 20 07:22:43.205788 2026] [security2:error] [pid 110058:tid 110092] [remote 20.153.140.50:41704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4hIxJHADqs2gAgBs-fwAAAiSE"]
[Mon Jul 20 07:22:43.226739 2026] [security2:error] [pid 110058:tid 110282] [client 157.20.138.62:62122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-fxAAAAOI"]
[Mon Jul 20 07:22:43.226859 2026] [security2:error] [pid 110058:tid 110282] [client 157.20.138.62:62122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-fxAAAAOI"]
[Mon Jul 20 07:22:43.311126 2026] [security2:error] [pid 110058:tid 110218] [client 191.202.66.27:61941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-fygAAAKI"]
[Mon Jul 20 07:22:43.311258 2026] [security2:error] [pid 110058:tid 110218] [client 191.202.66.27:61941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-fygAAAKI"]
[Mon Jul 20 07:22:43.531037 2026] [security2:error] [pid 110058:tid 110169] [remote 8.217.108.67:23816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hIxJHADqs2gAgBs-f3wAA_20"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:22:43.547601 2026] [security2:error] [pid 110058:tid 110279] [client 96.44.154.224:21634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hIxJHADqs2gAgBs-f4wAAAN8"]
[Mon Jul 20 07:22:43.594244 2026] [security2:error] [pid 110058:tid 110080] [remote 20.153.140.50:41704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4hIxJHADqs2gAgBs-f5gAA0RU"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:22:43.657413 2026] [security2:error] [pid 110058:tid 110271] [client 57.141.18.94:48652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hIRJHADqs2gAgBs-fLwAA1yc"]
[Mon Jul 20 07:22:43.745479 2026] [security2:error] [pid 110058:tid 110226] [client 104.234.53.91:24997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hIxJHADqs2gAgBs-f7wAAAKo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:43.812233 2026] [security2:error] [pid 110058:tid 110286] [client 88.241.67.160:53932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-f-QAAAOY"]
[Mon Jul 20 07:22:43.813067 2026] [security2:error] [pid 110058:tid 110286] [client 88.241.67.160:53932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-f-QAAAOY"]
[Mon Jul 20 07:22:43.887011 2026] [security2:error] [pid 110058:tid 110310] [client 154.208.48.130:64662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-gAAAAAP4"]
[Mon Jul 20 07:22:43.887189 2026] [security2:error] [pid 110058:tid 110310] [client 154.208.48.130:64662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-gAAAAAP4"]
[Mon Jul 20 07:22:43.959065 2026] [security2:error] [pid 110058:tid 110242] [client 112.86.225.157:50938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.littleaosta.nz"] [uri "/"] [unique_id "al4hIxJHADqs2gAgBs-gAgAAALo"]
[Mon Jul 20 07:22:43.959216 2026] [security2:error] [pid 110058:tid 110242] [client 112.86.225.157:50938] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.littleaosta.nz"] [uri "/"] [unique_id "al4hIxJHADqs2gAgBs-gAgAAALo"]
[Mon Jul 20 07:22:43.978473 2026] [security2:error] [pid 110058:tid 110182] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-gBAAAyHo"]
[Mon Jul 20 07:22:43.978642 2026] [security2:error] [pid 110058:tid 110256] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hIxJHADqs2gAgBs-gBAAAyHo"]
[Mon Jul 20 07:22:44.038108 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:64537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hJBJHADqs2gAgBs-gEQAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:44.038193 2026] [security2:error] [pid 110058:tid 110191] [client 77.110.127.138:64537] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hJBJHADqs2gAgBs-gEQAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:44.114610 2026] [security2:error] [pid 110058:tid 110218] [client 14.225.17.146:58388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4hJBJHADqs2gAgBs-gDAAAAKI"], referer: http://daseighty.net/2018
[Mon Jul 20 07:22:44.424441 2026] [security2:error] [pid 110058:tid 110078] [remote 100.42.189.89:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hJBJHADqs2gAgBs-gJgAA8xM"]
[Mon Jul 20 07:22:44.506181 2026] [security2:error] [pid 110058:tid 110283] [client 57.141.18.122:46140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hIhJHADqs2gAgBs-fjgAA4xA"]
[Mon Jul 20 07:22:44.536448 2026] [security2:error] [pid 110058:tid 110270] [client 103.106.165.44:65391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hJBJHADqs2gAgBs-gLQAAANY"]
[Mon Jul 20 07:22:44.536729 2026] [security2:error] [pid 110058:tid 110270] [client 103.106.165.44:65391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hJBJHADqs2gAgBs-gLQAAANY"]
[Mon Jul 20 07:22:44.637591 2026] [security2:error] [pid 110058:tid 110164] [remote 100.42.189.89:55732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hJBJHADqs2gAgBs-gNwAAyWg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:22:44.764264 2026] [security2:error] [pid 110058:tid 110099] [remote 8.217.108.67:28444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hJBJHADqs2gAgBs-gUAAAxig"]
[Mon Jul 20 07:22:44.764429 2026] [security2:error] [pid 110058:tid 110254] [client 8.217.108.67:28444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hJBJHADqs2gAgBs-gUAAAxig"]
[Mon Jul 20 07:22:44.839191 2026] [security2:error] [pid 110058:tid 110299] [client 96.44.154.224:32536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hJBJHADqs2gAgBs-gXQAAAPM"]
[Mon Jul 20 07:22:44.916308 2026] [security2:error] [pid 110058:tid 110242] [client 104.234.53.77:64619] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hJBJHADqs2gAgBs-gTwAAALo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:44.976638 2026] [security2:error] [pid 110058:tid 110227] [client 50.116.65.227:16394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hJBJHADqs2gAgBs-gbQAAAKs"]
[Mon Jul 20 07:22:44.988071 2026] [security2:error] [pid 110058:tid 110303] [client 50.116.65.227:16396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hJBJHADqs2gAgBs-gbwAAAPc"]
[Mon Jul 20 07:22:45.030204 2026] [security2:error] [pid 110058:tid 110256] [client 143.44.185.218:25187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-gcgAAAMg"]
[Mon Jul 20 07:22:45.032275 2026] [security2:error] [pid 110058:tid 110256] [client 143.44.185.218:25187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-gcgAAAMg"]
[Mon Jul 20 07:22:45.379499 2026] [security2:error] [pid 110058:tid 110117] [remote 182.77.62.24:49516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hJRJHADqs2gAgBs-gkQAA4Do"]
[Mon Jul 20 07:22:45.423602 2026] [security2:error] [pid 110058:tid 110301] [client 201.27.111.74:52540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-glgAAAPU"]
[Mon Jul 20 07:22:45.423696 2026] [security2:error] [pid 110058:tid 110301] [client 201.27.111.74:52540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-glgAAAPU"]
[Mon Jul 20 07:22:45.609278 2026] [security2:error] [pid 110058:tid 110202] [client 104.234.53.77:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hJRJHADqs2gAgBs-gpAAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:45.738914 2026] [security2:error] [pid 110058:tid 110125] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-gsgAAqkE"]
[Mon Jul 20 07:22:45.739125 2026] [security2:error] [pid 110058:tid 110226] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-gsgAAqkE"]
[Mon Jul 20 07:22:45.878868 2026] [security2:error] [pid 110058:tid 110148] [remote 182.77.62.24:49516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hJRJHADqs2gAgBs-guQAAiVg"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 07:22:45.880763 2026] [security2:error] [pid 110058:tid 110290] [client 117.211.236.168:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-gugAAAOo"]
[Mon Jul 20 07:22:45.880893 2026] [security2:error] [pid 110058:tid 110290] [client 117.211.236.168:57547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hJRJHADqs2gAgBs-gugAAAOo"]
[Mon Jul 20 07:22:45.895506 2026] [security2:error] [pid 110058:tid 110138] [remote 209.42.18.223:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4hJRJHADqs2gAgBs-guwAA0E4"]
[Mon Jul 20 07:22:46.075501 2026] [security2:error] [pid 110058:tid 110071] [remote 209.42.18.223:52792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4hJhJHADqs2gAgBs-gxwAAlAw"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:22:46.151122 2026] [security2:error] [pid 110058:tid 110240] [client 14.225.17.146:53453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4hJBJHADqs2gAgBs-gSgAAALg"], referer: http://colinkeyphotography.com/2018
[Mon Jul 20 07:22:46.218038 2026] [security2:error] [pid 110058:tid 110275] [client 154.192.123.127:17485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hJhJHADqs2gAgBs-g1AAAANs"]
[Mon Jul 20 07:22:46.218180 2026] [security2:error] [pid 110058:tid 110275] [client 154.192.123.127:17485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hJhJHADqs2gAgBs-g1AAAANs"]
[Mon Jul 20 07:22:46.453172 2026] [security2:error] [pid 110058:tid 110177] [remote 154.61.75.100:40686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4hJhJHADqs2gAgBs-g6AAAsnU"]
[Mon Jul 20 07:22:46.459086 2026] [core:error] [pid 110058:tid 110300] [client 144.172.114.51:58186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:46.459119 2026] [core:error] [pid 110058:tid 110300] [client 144.172.114.51:58186] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:46.543904 2026] [security2:error] [pid 110058:tid 110314] [client 14.225.17.146:54872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4hJhJHADqs2gAgBs-g8wAAAQI"], referer: http://dasmarque.com/2018
[Mon Jul 20 07:22:46.601138 2026] [security2:error] [pid 110058:tid 110289] [client 14.225.17.146:63302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4hJRJHADqs2gAgBs-gdgAAAOk"], referer: http://reosportsboats.com/2018
[Mon Jul 20 07:22:46.658020 2026] [security2:error] [pid 110058:tid 110060] [remote 57.141.18.34:43400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600005"] [unique_id "al4hJhJHADqs2gAgBs-g_gAAxAE"]
[Mon Jul 20 07:22:46.923368 2026] [security2:error] [pid 110058:tid 110242] [client 14.225.17.146:65375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4hJhJHADqs2gAgBs-g1QAAALo"], referer: http://idigress.studio/2018
[Mon Jul 20 07:22:46.957042 2026] [security2:error] [pid 110058:tid 110105] [remote 154.61.75.100:40686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4hJhJHADqs2gAgBs-hRwAA7S4"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 07:22:47.037703 2026] [security2:error] [pid 110058:tid 110292] [client 14.225.17.146:54732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4hJhJHADqs2gAgBs-hQQAAAOw"], referer: http://myspineworld.com/2018
[Mon Jul 20 07:22:47.055200 2026] [security2:error] [pid 110058:tid 110230] [client 14.225.17.146:54779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4hJhJHADqs2gAgBs-hSwAAAK4"], referer: http://katsklar.com/2018
[Mon Jul 20 07:22:47.396808 2026] [security2:error] [pid 110058:tid 110151] [remote 20.153.140.50:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4hJxJHADqs2gAgBs-hiwAA2ls"]
[Mon Jul 20 07:22:47.617777 2026] [security2:error] [pid 110058:tid 110237] [client 14.225.17.146:54740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4hJxJHADqs2gAgBs-hlwAAALU"], referer: https://reosportsboats.com/2018
[Mon Jul 20 07:22:47.822838 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:64553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hJxJHADqs2gAgBs-hrwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:47.823182 2026] [security2:error] [pid 110058:tid 110311] [client 77.110.127.138:64553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hJxJHADqs2gAgBs-hrwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:47.826693 2026] [security2:error] [pid 110058:tid 110149] [remote 20.153.140.50:44742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4hJxJHADqs2gAgBs-hrAAAlFk"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:22:47.943608 2026] [security2:error] [pid 110058:tid 110234] [client 187.16.64.216:53528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hJxJHADqs2gAgBs-hvAAAALI"]
[Mon Jul 20 07:22:47.943705 2026] [security2:error] [pid 110058:tid 110234] [client 187.16.64.216:53528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hJxJHADqs2gAgBs-hvAAAALI"]
[Mon Jul 20 07:22:48.044759 2026] [security2:error] [pid 110058:tid 110230] [client 14.225.17.146:56179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4hJxJHADqs2gAgBs-huwAAAK4"], referer: https://myspineworld.com/2018
[Mon Jul 20 07:22:48.124033 2026] [security2:error] [pid 110058:tid 110210] [client 57.141.18.13:53828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hJRJHADqs2gAgBs-gvwAAmnQ"]
[Mon Jul 20 07:22:48.222625 2026] [security2:error] [pid 110058:tid 110280] [client 104.234.53.84:47125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hKBJHADqs2gAgBs-h2gAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:48.257811 2026] [security2:error] [pid 110058:tid 110258] [client 158.173.166.181:52771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hKBJHADqs2gAgBs-h3AAAAMo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:22:49.056277 2026] [security2:error] [pid 110058:tid 110059] [remote 192.241.143.148:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4hKRJHADqs2gAgBs-iEQAAhgA"]
[Mon Jul 20 07:22:49.123947 2026] [security2:error] [pid 110058:tid 110203] [client 14.225.17.146:65285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4hJxJHADqs2gAgBs-hmwAAAJM"], referer: http://margaretspeckogawa.com/2018
[Mon Jul 20 07:22:49.127685 2026] [security2:error] [pid 110058:tid 110307] [client 57.141.18.12:23296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hJhJHADqs2gAgBs-hJwAA-w0"]
[Mon Jul 20 07:22:49.301915 2026] [security2:error] [pid 110058:tid 110155] [remote 192.241.143.148:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4hKRJHADqs2gAgBs-iJQAAn18"], referer: https://fluidtemple.org/wp-login.php
[Mon Jul 20 07:22:49.362795 2026] [security2:error] [pid 110058:tid 110206] [client 145.239.10.137:41642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/file4.php"] [unique_id "al4hKRJHADqs2gAgBs-iLQAAAJY"], referer: http://iagdevelopments.com/file4.php
[Mon Jul 20 07:22:49.509466 2026] [security2:error] [pid 110058:tid 110292] [client 14.225.17.146:65232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4hKRJHADqs2gAgBs-iEgAAAOw"], referer: http://overloadcomedy.com/2018
[Mon Jul 20 07:22:49.660678 2026] [security2:error] [pid 110058:tid 110234] [client 136.158.60.21:4668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hKRJHADqs2gAgBs-iVgAAALI"]
[Mon Jul 20 07:22:49.660814 2026] [security2:error] [pid 110058:tid 110234] [client 136.158.60.21:4668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hKRJHADqs2gAgBs-iVgAAALI"]
[Mon Jul 20 07:22:50.094366 2026] [security2:error] [pid 110058:tid 110271] [client 96.44.154.224:26104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.154.44.96.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hKhJHADqs2gAgBs-idwAAANc"]
[Mon Jul 20 07:22:50.398482 2026] [security2:error] [pid 110058:tid 110171] [remote 103.187.169.251:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hKhJHADqs2gAgBs-ijgAAwm8"]
[Mon Jul 20 07:22:50.788986 2026] [security2:error] [pid 110058:tid 110163] [remote 103.187.169.251:41010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hKhJHADqs2gAgBs-iqQAAyWc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:22:51.387052 2026] [autoindex:error] [pid 110058:tid 110202] [client 198.235.24.143:60848] AH01276: Cannot serve directory /home2/tmjybcmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://tmj.ybc.mybluehost.me/
[Mon Jul 20 07:22:51.486594 2026] [security2:error] [pid 110058:tid 110312] [client 57.141.18.37:31380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hKRJHADqs2gAgBs-iLgABAH0"]
[Mon Jul 20 07:22:51.621761 2026] [security2:error] [pid 110058:tid 110229] [client 34.23.246.146:57602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "maxenengineering.com"] [uri "/wp-json/batch/v1"] [unique_id "al4hKxJHADqs2gAgBs-i4wAAAK0"]
[Mon Jul 20 07:22:51.894236 2026] [security2:error] [pid 110058:tid 110201] [client 57.141.18.98:46234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hKRJHADqs2gAgBs-iXAAAkTA"]
[Mon Jul 20 07:22:51.947328 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hKxJHADqs2gAgBs-jAgAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:51.947413 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hKxJHADqs2gAgBs-jAgAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:52.065025 2026] [core:error] [pid 110058:tid 110282] [client 144.172.114.51:51326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:52.065054 2026] [core:error] [pid 110058:tid 110282] [client 144.172.114.51:51326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:52.396619 2026] [fcgid:warn] [pid 110058:tid 110314] (70014)End of file found: [client 66.132.172.140:39724] mod_fcgid: can't get data from http client
[Mon Jul 20 07:22:52.573289 2026] [security2:error] [pid 110058:tid 110095] [remote 98.156.100.191:46382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4hLBJHADqs2gAgBs-jMAAA6SQ"]
[Mon Jul 20 07:22:52.680909 2026] [security2:error] [pid 110058:tid 110206] [client 52.71.205.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4hLBJHADqs2gAgBs-jLgAAlnA"]
[Mon Jul 20 07:22:52.735661 2026] [security2:error] [pid 110058:tid 110286] [client 57.141.18.124:55040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hKhJHADqs2gAgBs-ikwAA5kA"]
[Mon Jul 20 07:22:52.860183 2026] [security2:error] [pid 110058:tid 110223] [client 104.234.53.60:33511] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hLBJHADqs2gAgBs-jPwAAAKc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:52.881681 2026] [security2:error] [pid 110058:tid 110219] [client 49.47.218.174:61792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hLBJHADqs2gAgBs-jQwAAAKM"]
[Mon Jul 20 07:22:52.881784 2026] [security2:error] [pid 110058:tid 110219] [client 49.47.218.174:61792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hLBJHADqs2gAgBs-jQwAAAKM"]
[Mon Jul 20 07:22:52.912343 2026] [security2:error] [pid 110058:tid 110164] [remote 154.66.198.148:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4hLBJHADqs2gAgBs-jRQAA72g"]
[Mon Jul 20 07:22:53.123983 2026] [security2:error] [pid 110058:tid 110196] [client 103.176.215.66:50463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jUwAAAIw"]
[Mon Jul 20 07:22:53.124100 2026] [security2:error] [pid 110058:tid 110196] [client 103.176.215.66:50463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jUwAAAIw"]
[Mon Jul 20 07:22:53.126496 2026] [proxy:error] [pid 110058:tid 110099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.126558 2026] [proxy_http:error] [pid 110058:tid 110099] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.127236 2026] [proxy:error] [pid 110058:tid 110099] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.127277 2026] [proxy_http:error] [pid 110058:tid 110099] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.149816 2026] [security2:error] [pid 110058:tid 110269] [client 57.141.18.12:41996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hKxJHADqs2gAgBs-iuwAA1Vs"]
[Mon Jul 20 07:22:53.297470 2026] [proxy:error] [pid 110058:tid 110096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.297525 2026] [proxy_http:error] [pid 110058:tid 110096] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.297976 2026] [proxy:error] [pid 110058:tid 110096] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.298000 2026] [proxy_http:error] [pid 110058:tid 110096] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.389120 2026] [security2:error] [pid 110058:tid 110197] [client 36.93.152.155:58243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jZgAAAI0"]
[Mon Jul 20 07:22:53.389209 2026] [security2:error] [pid 110058:tid 110197] [client 36.93.152.155:58243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jZgAAAI0"]
[Mon Jul 20 07:22:53.454541 2026] [security2:error] [pid 110058:tid 110178] [remote 154.66.198.148:51464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4hLRJHADqs2gAgBs-jaQAA2XY"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 07:22:53.470402 2026] [proxy:error] [pid 110058:tid 110132] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.470453 2026] [proxy_http:error] [pid 110058:tid 110132] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.470900 2026] [proxy:error] [pid 110058:tid 110132] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.470924 2026] [proxy_http:error] [pid 110058:tid 110132] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.642223 2026] [proxy:error] [pid 110058:tid 110087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.642294 2026] [proxy_http:error] [pid 110058:tid 110087] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.642733 2026] [proxy:error] [pid 110058:tid 110087] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.642775 2026] [proxy_http:error] [pid 110058:tid 110087] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.744412 2026] [security2:error] [pid 110058:tid 110101] [remote 98.156.100.191:46382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fbvrealtors.com"] [uri "/wp-login.php"] [unique_id "al4hLRJHADqs2gAgBs-jdwAA6io"], referer: https://fbvrealtors.com/wp-login.php
[Mon Jul 20 07:22:53.758167 2026] [security2:error] [pid 110058:tid 110230] [client 157.20.138.62:62759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jeQAAAK4"]
[Mon Jul 20 07:22:53.758278 2026] [security2:error] [pid 110058:tid 110230] [client 157.20.138.62:62759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jeQAAAK4"]
[Mon Jul 20 07:22:53.815166 2026] [proxy:error] [pid 110058:tid 110082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.815245 2026] [proxy_http:error] [pid 110058:tid 110082] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.815846 2026] [proxy:error] [pid 110058:tid 110082] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.815886 2026] [proxy_http:error] [pid 110058:tid 110082] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.841565 2026] [security2:error] [pid 110058:tid 110311] [client 191.202.66.27:62424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jgwAAAP8"]
[Mon Jul 20 07:22:53.841665 2026] [security2:error] [pid 110058:tid 110311] [client 191.202.66.27:62424] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hLRJHADqs2gAgBs-jgwAAAP8"]
[Mon Jul 20 07:22:53.926081 2026] [security2:error] [pid 110058:tid 110251] [client 57.141.18.40:52788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hKxJHADqs2gAgBs-i_wAAw3g"]
[Mon Jul 20 07:22:53.995242 2026] [proxy:error] [pid 110058:tid 110123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.995330 2026] [proxy_http:error] [pid 110058:tid 110123] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:53.995734 2026] [proxy:error] [pid 110058:tid 110123] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:53.995775 2026] [proxy_http:error] [pid 110058:tid 110123] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.183457 2026] [proxy:error] [pid 110058:tid 110141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.183824 2026] [proxy_http:error] [pid 110058:tid 110141] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.184782 2026] [proxy:error] [pid 110058:tid 110141] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.184817 2026] [proxy_http:error] [pid 110058:tid 110141] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.356194 2026] [proxy:error] [pid 110058:tid 110183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.356262 2026] [proxy_http:error] [pid 110058:tid 110183] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.356668 2026] [proxy:error] [pid 110058:tid 110183] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.356693 2026] [proxy_http:error] [pid 110058:tid 110183] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.392102 2026] [security2:error] [pid 110058:tid 110287] [client 88.241.67.160:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-jugAAAOc"]
[Mon Jul 20 07:22:54.392429 2026] [security2:error] [pid 110058:tid 110287] [client 88.241.67.160:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-jugAAAOc"]
[Mon Jul 20 07:22:54.430300 2026] [security2:error] [pid 110058:tid 110250] [client 77.110.127.138:64573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hLhJHADqs2gAgBs-jvAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:54.430384 2026] [security2:error] [pid 110058:tid 110250] [client 77.110.127.138:64573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hLhJHADqs2gAgBs-jvAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:54.500685 2026] [security2:error] [pid 110058:tid 110138] [remote 57.141.18.117:62902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2950356"] [unique_id "al4hLhJHADqs2gAgBs-jwwAA2E4"]
[Mon Jul 20 07:22:54.527002 2026] [proxy:error] [pid 110058:tid 110065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.527049 2026] [proxy_http:error] [pid 110058:tid 110065] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.527490 2026] [proxy:error] [pid 110058:tid 110065] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.527512 2026] [proxy_http:error] [pid 110058:tid 110065] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.614214 2026] [security2:error] [pid 110058:tid 110083] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-j1AAAphg"]
[Mon Jul 20 07:22:54.614355 2026] [security2:error] [pid 110058:tid 110222] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-j1AAAphg"]
[Mon Jul 20 07:22:54.692547 2026] [security2:error] [pid 110058:tid 110315] [client 34.141.229.34:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "webdisk.gmk.tqd.mybluehost.me"] [uri "/"] [unique_id "al4hLhJHADqs2gAgBs-j2QAAAQM"]
[Mon Jul 20 07:22:54.692624 2026] [security2:error] [pid 110058:tid 110315] [client 34.141.229.34:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "webdisk.gmk.tqd.mybluehost.me"] [uri "/"] [unique_id "al4hLhJHADqs2gAgBs-j2QAAAQM"]
[Mon Jul 20 07:22:54.702182 2026] [proxy:error] [pid 110058:tid 110186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.702254 2026] [proxy_http:error] [pid 110058:tid 110186] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.702703 2026] [proxy:error] [pid 110058:tid 110186] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.702727 2026] [proxy_http:error] [pid 110058:tid 110186] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.758518 2026] [security2:error] [pid 110058:tid 110264] [client 154.208.48.130:65180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-j3QAAANA"]
[Mon Jul 20 07:22:54.758610 2026] [security2:error] [pid 110058:tid 110264] [client 154.208.48.130:65180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-j3QAAANA"]
[Mon Jul 20 07:22:54.812383 2026] [security2:error] [pid 110058:tid 110284] [client 49.37.242.14:63291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-j5wAAAOQ"]
[Mon Jul 20 07:22:54.812492 2026] [security2:error] [pid 110058:tid 110284] [client 49.37.242.14:63291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-j5wAAAOQ"]
[Mon Jul 20 07:22:54.821681 2026] [security2:error] [pid 110058:tid 110274] [client 66.249.74.7:49283] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.bitesofwealth.com"] [uri "/robots.txt"] [unique_id "al4hLhJHADqs2gAgBs-j6AAAANo"]
[Mon Jul 20 07:22:54.873106 2026] [proxy:error] [pid 110058:tid 110152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.873177 2026] [proxy_http:error] [pid 110058:tid 110152] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.873621 2026] [proxy:error] [pid 110058:tid 110152] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:54.873650 2026] [proxy_http:error] [pid 110058:tid 110152] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:54.988353 2026] [security2:error] [pid 110058:tid 110205] [client 57.141.18.71:52586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hLRJHADqs2gAgBs-jUgAAlWo"]
[Mon Jul 20 07:22:54.996822 2026] [security2:error] [pid 110058:tid 110254] [client 117.211.236.168:58144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-kGwAAAMY"]
[Mon Jul 20 07:22:54.996916 2026] [security2:error] [pid 110058:tid 110254] [client 117.211.236.168:58144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hLhJHADqs2gAgBs-kGwAAAMY"]
[Mon Jul 20 07:22:55.045543 2026] [proxy:error] [pid 110058:tid 110075] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:55.045630 2026] [proxy_http:error] [pid 110058:tid 110075] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:55.046154 2026] [proxy:error] [pid 110058:tid 110075] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:22:55.046180 2026] [proxy_http:error] [pid 110058:tid 110075] [remote 157.143.3.35:50242] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:22:55.062580 2026] [security2:error] [pid 110058:tid 110296] [client 103.106.165.44:49474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hLxJHADqs2gAgBs-kIwAAAPA"]
[Mon Jul 20 07:22:55.062745 2026] [security2:error] [pid 110058:tid 110296] [client 103.106.165.44:49474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hLxJHADqs2gAgBs-kIwAAAPA"]
[Mon Jul 20 07:22:55.659336 2026] [security2:error] [pid 110058:tid 110193] [client 138.197.16.64:60388] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.besoundful.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4hLxJHADqs2gAgBs-kYwAAAIk"]
[Mon Jul 20 07:22:55.731618 2026] [security2:error] [pid 110058:tid 110203] [client 104.234.53.47:50949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hLxJHADqs2gAgBs-kbAAAAJM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:22:55.839913 2026] [security2:error] [pid 110058:tid 110267] [client 201.27.111.74:53046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hLxJHADqs2gAgBs-kcAAAANM"]
[Mon Jul 20 07:22:55.840016 2026] [security2:error] [pid 110058:tid 110267] [client 201.27.111.74:53046] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hLxJHADqs2gAgBs-kcAAAANM"]
[Mon Jul 20 07:22:55.902647 2026] [core:alert] [pid 110058:tid 110194] [client 8.229.41.77:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:22:55.941606 2026] [security2:error] [pid 110058:tid 110220] [client 34.84.221.1:14607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "thewelloiledlife.com"] [uri "/wp-content/uploads/2015/09/September-ER.png"] [unique_id "al4hLxJHADqs2gAgBs-kewAAAKQ"]
[Mon Jul 20 07:22:56.053658 2026] [security2:error] [pid 110058:tid 110316] [client 34.23.246.146:57602] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "maxenengineering.com"] [uri "/"] [unique_id "al4hMBJHADqs2gAgBs-khQAAAQQ"]
[Mon Jul 20 07:22:56.078371 2026] [security2:error] [pid 110058:tid 110093] [remote 147.50.252.213:53658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4hMBJHADqs2gAgBs-kiAAA3CI"]
[Mon Jul 20 07:22:56.181034 2026] [core:error] [pid 110058:tid 110193] [client 144.172.114.51:51330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:56.181062 2026] [core:error] [pid 110058:tid 110193] [client 144.172.114.51:51330] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:56.350459 2026] [security2:error] [pid 110058:tid 110254] [client 158.173.241.141:50223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4hMBJHADqs2gAgBs-kkgAAAMY"], referer: http://sesamegreenbeans.com/nine-days-south-africa-i/
[Mon Jul 20 07:22:56.411610 2026] [security2:error] [pid 110058:tid 110165] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hMBJHADqs2gAgBs-kpAAAk2k"]
[Mon Jul 20 07:22:56.411736 2026] [security2:error] [pid 110058:tid 110203] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hMBJHADqs2gAgBs-kpAAAk2k"]
[Mon Jul 20 07:22:56.584130 2026] [security2:error] [pid 110058:tid 110181] [remote 147.50.252.213:53658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 213.252.50.147.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4hMBJHADqs2gAgBs-kugAAkHk"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 07:22:56.611325 2026] [proxy:warn] [pid 110058:tid 110245] [client 20.171.9.108:58722] AH01092: no HTTP 0.9 request (with no host line) on incoming request and preserve host set forcing hostname to be upositive-co.youpositive.co for uri /400.shtml
[Mon Jul 20 07:22:56.632014 2026] [core:error] [pid 110058:tid 110218] [client 20.171.9.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:56.632033 2026] [core:error] [pid 110058:tid 110218] [client 20.171.9.108:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:22:56.632115 2026] [security2:error] [pid 110058:tid 110218] [client 20.171.9.108:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/index.php"] [unique_id "al4hMBJHADqs2gAgBs-kxQAAAKI"]
[Mon Jul 20 07:22:56.634528 2026] [security2:error] [pid 110058:tid 110245] [client 20.171.9.108:58722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "upositive-co.youpositive.co"] [uri "/400.shtml"] [unique_id "al4hMBJHADqs2gAgBs-kvwAAAL0"]
[Mon Jul 20 07:22:56.634600 2026] [security2:error] [pid 110058:tid 110137] [remote 8.217.108.67:37352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4hMBJHADqs2gAgBs-kxAAA9k0"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 07:22:56.723132 2026] [security2:error] [pid 110058:tid 110239] [client 154.192.123.127:17908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hMBJHADqs2gAgBs-kyQAAALc"]
[Mon Jul 20 07:22:56.723232 2026] [security2:error] [pid 110058:tid 110239] [client 154.192.123.127:17908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hMBJHADqs2gAgBs-kyQAAALc"]
[Mon Jul 20 07:22:57.019906 2026] [security2:error] [pid 110058:tid 110202] [client 50.116.65.227:21984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4hMRJHADqs2gAgBs-k2wAAAJI"]
[Mon Jul 20 07:22:57.035507 2026] [security2:error] [pid 110058:tid 110216] [client 50.116.65.227:29370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4hMRJHADqs2gAgBs-k3AAAAKA"]
[Mon Jul 20 07:22:57.077190 2026] [security2:error] [pid 110058:tid 110266] [client 77.110.127.138:64586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hMRJHADqs2gAgBs-k4AAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:57.077292 2026] [security2:error] [pid 110058:tid 110266] [client 77.110.127.138:64586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hMRJHADqs2gAgBs-k4AAAANI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:57.127472 2026] [security2:error] [pid 110058:tid 110280] [client 77.110.127.138:64572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hMRJHADqs2gAgBs-k5AAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:57.127567 2026] [security2:error] [pid 110058:tid 110280] [client 77.110.127.138:64572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hMRJHADqs2gAgBs-k5AAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:57.199868 2026] [security2:error] [pid 110058:tid 110222] [client 143.44.185.218:26468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hMRJHADqs2gAgBs-k7QAAAKY"]
[Mon Jul 20 07:22:57.199992 2026] [security2:error] [pid 110058:tid 110222] [client 143.44.185.218:26468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hMRJHADqs2gAgBs-k7QAAAKY"]
[Mon Jul 20 07:22:57.469323 2026] [security2:error] [pid 110058:tid 110239] [client 50.116.65.227:29386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hMRJHADqs2gAgBs-k_AAAALc"]
[Mon Jul 20 07:22:57.481199 2026] [security2:error] [pid 110058:tid 110229] [client 50.116.65.227:29398] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hMRJHADqs2gAgBs-k_gAAAK0"]
[Mon Jul 20 07:22:57.973222 2026] [security2:error] [pid 110058:tid 110248] [client 35.162.140.124:19286] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.thecreole.com"] [uri "/index.cgi"] [unique_id "al4hMRJHADqs2gAgBs-lHgAAAMA"]
[Mon Jul 20 07:22:58.491257 2026] [security2:error] [pid 110058:tid 110271] [client 104.28.163.235:47325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "709fx.com"] [uri "/wp-login.php"] [unique_id "al4hMhJHADqs2gAgBs-lRAAAANc"]
[Mon Jul 20 07:22:58.761062 2026] [security2:error] [pid 110058:tid 110295] [client 187.16.64.216:54121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hMhJHADqs2gAgBs-lWAAAAO8"]
[Mon Jul 20 07:22:58.761158 2026] [security2:error] [pid 110058:tid 110295] [client 187.16.64.216:54121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hMhJHADqs2gAgBs-lWAAAAO8"]
[Mon Jul 20 07:22:58.802810 2026] [security2:error] [pid 110058:tid 110164] [remote 57.141.18.44:27546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5680545"] [unique_id "al4hMhJHADqs2gAgBs-lWgAA1Wg"]
[Mon Jul 20 07:22:59.177906 2026] [security2:error] [pid 110058:tid 110289] [client 77.110.127.138:64590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hMxJHADqs2gAgBs-lfgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:59.178035 2026] [security2:error] [pid 110058:tid 110289] [client 77.110.127.138:64590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hMxJHADqs2gAgBs-lfgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:22:59.253881 2026] [security2:error] [pid 110058:tid 110310] [client 46.110.96.34:43992] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4hMxJHADqs2gAgBs-lggAAAP4"]
[Mon Jul 20 07:22:59.254865 2026] [security2:error] [pid 110058:tid 110225] [client 46.110.96.34:47242] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4hMxJHADqs2gAgBs-lgwAAAKk"]
[Mon Jul 20 07:22:59.643977 2026] [security2:error] [pid 110058:tid 110192] [client 57.141.18.46:56546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hMRJHADqs2gAgBs-lEAAAiEc"]
[Mon Jul 20 07:22:59.877423 2026] [security2:error] [pid 110058:tid 110262] [client 57.141.18.73:21870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hMRJHADqs2gAgBs-lIQAAzic"]
[Mon Jul 20 07:23:00.529303 2026] [security2:error] [pid 110058:tid 110190] [client 136.158.60.21:6199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hNBJHADqs2gAgBs-lygAAAIY"]
[Mon Jul 20 07:23:00.529476 2026] [security2:error] [pid 110058:tid 110190] [client 136.158.60.21:6199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hNBJHADqs2gAgBs-lygAAAIY"]
[Mon Jul 20 07:23:01.052366 2026] [security2:error] [pid 110058:tid 110239] [client 202.141.11.99:27497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hNRJHADqs2gAgBs-l7wAAALc"]
[Mon Jul 20 07:23:01.052516 2026] [security2:error] [pid 110058:tid 110239] [client 202.141.11.99:27497] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hNRJHADqs2gAgBs-l7wAAALc"]
[Mon Jul 20 07:23:01.261003 2026] [security2:error] [pid 110058:tid 110271] [client 57.141.18.103:56902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hMxJHADqs2gAgBs-legAA13w"]
[Mon Jul 20 07:23:01.580534 2026] [security2:error] [pid 110058:tid 110275] [client 109.70.100.6:60088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.100.70.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hNRJHADqs2gAgBs-mHgAAANs"]
[Mon Jul 20 07:23:01.947666 2026] [security2:error] [pid 110058:tid 110220] [client 57.141.18.115:54890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hMxJHADqs2gAgBs-lrgAApFM"]
[Mon Jul 20 07:23:02.279009 2026] [security2:error] [pid 110058:tid 110304] [client 98.159.234.160:43057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hNhJHADqs2gAgBs-mUgAAAPg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:02.602016 2026] [security2:error] [pid 110058:tid 110266] [client 213.111.158.220:18772] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "omrobuildingcenter.com"] [uri "/"] [unique_id "al4hNhJHADqs2gAgBs-maQAAANI"]
[Mon Jul 20 07:23:02.805741 2026] [security2:error] [pid 110058:tid 110265] [client 14.225.17.146:65189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4hNhJHADqs2gAgBs-mawAAANE"], referer: http://superiorcopywriting.com/backup
[Mon Jul 20 07:23:02.966448 2026] [fcgid:warn] [pid 110058:tid 110275] (70014)End of file found: [client 66.132.195.124:61752] mod_fcgid: can't get data from http client
[Mon Jul 20 07:23:03.007257 2026] [security2:error] [pid 110058:tid 110209] [client 49.47.218.174:62314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hNxJHADqs2gAgBs-mjgAAAJk"]
[Mon Jul 20 07:23:03.007386 2026] [security2:error] [pid 110058:tid 110209] [client 49.47.218.174:62314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hNxJHADqs2gAgBs-mjgAAAJk"]
[Mon Jul 20 07:23:03.355115 2026] [security2:error] [pid 110058:tid 110277] [client 57.141.18.18:31582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hNRJHADqs2gAgBs-mCQAA3U8"]
[Mon Jul 20 07:23:03.366485 2026] [security2:error] [pid 110058:tid 110302] [client 14.225.17.146:54972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4hNxJHADqs2gAgBs-mnwAAAPY"], referer: http://grecruit.online/backup
[Mon Jul 20 07:23:03.391233 2026] [security2:error] [pid 110058:tid 110310] [client 104.234.53.51:61477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hNxJHADqs2gAgBs-msAAAAP4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:03.446103 2026] [security2:error] [pid 110058:tid 110274] [client 77.110.127.138:64600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hNxJHADqs2gAgBs-mugAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:03.446194 2026] [security2:error] [pid 110058:tid 110274] [client 77.110.127.138:64600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hNxJHADqs2gAgBs-mugAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:03.595356 2026] [security2:error] [pid 110058:tid 110192] [client 103.176.215.66:50997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hNxJHADqs2gAgBs-mxgAAAIg"]
[Mon Jul 20 07:23:03.595868 2026] [security2:error] [pid 110058:tid 110192] [client 103.176.215.66:50997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hNxJHADqs2gAgBs-mxgAAAIg"]
[Mon Jul 20 07:23:03.946322 2026] [security2:error] [pid 110058:tid 110314] [client 36.93.152.155:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hNxJHADqs2gAgBs-m6gAAAQI"]
[Mon Jul 20 07:23:03.946444 2026] [security2:error] [pid 110058:tid 110314] [client 36.93.152.155:58744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hNxJHADqs2gAgBs-m6gAAAQI"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 07:23:04.334482 2026] [security2:error] [pid 110058:tid 110197] [client 57.141.18.82:56772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hNRJHADqs2gAgBs-mQAAAjWM"]
[Mon Jul 20 07:23:04.356369 2026] [security2:error] [pid 110058:tid 110262] [client 77.110.127.138:64606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hOBJHADqs2gAgBs-nHQAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:04.356467 2026] [security2:error] [pid 110058:tid 110262] [client 77.110.127.138:64606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hOBJHADqs2gAgBs-nHQAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:04.420153 2026] [security2:error] [pid 110058:tid 110220] [client 157.20.138.62:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hOBJHADqs2gAgBs-nJAAAAKQ"]
[Mon Jul 20 07:23:04.420254 2026] [security2:error] [pid 110058:tid 110220] [client 157.20.138.62:63329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hOBJHADqs2gAgBs-nJAAAAKQ"]
[Mon Jul 20 07:23:04.456537 2026] [security2:error] [pid 110058:tid 110265] [client 191.202.66.27:62916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hOBJHADqs2gAgBs-nKwAAANE"]
[Mon Jul 20 07:23:04.456653 2026] [security2:error] [pid 110058:tid 110265] [client 191.202.66.27:62916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hOBJHADqs2gAgBs-nKwAAANE"]
[Mon Jul 20 07:23:04.480153 2026] [security2:error] [pid 110058:tid 110279] [client 45.157.112.60:34781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hOBJHADqs2gAgBs-nLAAAAN8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:04.668801 2026] [security2:error] [pid 110058:tid 110264] [client 15.204.80.170:42162] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "steadfastwolfproductions.com"] [uri "/"] [unique_id "al4hOBJHADqs2gAgBs-nOgAAANA"]
[Mon Jul 20 07:23:05.031582 2026] [security2:error] [pid 110058:tid 110289] [client 88.241.67.160:57268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nYwAAAOk"]
[Mon Jul 20 07:23:05.031837 2026] [security2:error] [pid 110058:tid 110289] [client 88.241.67.160:57268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nYwAAAOk"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 07:23:05.187446 2026] [security2:error] [pid 110058:tid 110306] [client 179.127.84.238:64471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nagAAAPo"]
[Mon Jul 20 07:23:05.187573 2026] [security2:error] [pid 110058:tid 110306] [client 179.127.84.238:64471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nagAAAPo"]
[Mon Jul 20 07:23:05.198403 2026] [security2:error] [pid 110058:tid 110193] [client 14.225.17.146:65269] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4hORJHADqs2gAgBs-nZAAAAIk"], referer: http://ivetstrategies.com/backup
[Mon Jul 20 07:23:05.218659 2026] [security2:error] [pid 110058:tid 110144] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-ncwAAk1Q"]
[Mon Jul 20 07:23:05.218850 2026] [security2:error] [pid 110058:tid 110203] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-ncwAAk1Q"]
[Mon Jul 20 07:23:05.392329 2026] [security2:error] [pid 110058:tid 110110] [remote 8.217.108.67:41318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hORJHADqs2gAgBs-newAAvDM"]
[Mon Jul 20 07:23:05.563782 2026] [security2:error] [pid 110058:tid 110202] [client 103.106.165.44:49950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nigAAAJI"]
[Mon Jul 20 07:23:05.563881 2026] [security2:error] [pid 110058:tid 110202] [client 103.106.165.44:49950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nigAAAJI"]
[Mon Jul 20 07:23:05.685630 2026] [security2:error] [pid 110058:tid 110309] [client 77.110.127.138:64576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hORJHADqs2gAgBs-nkwAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:05.685739 2026] [security2:error] [pid 110058:tid 110309] [client 77.110.127.138:64576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hORJHADqs2gAgBs-nkwAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:05.777721 2026] [security2:error] [pid 110058:tid 110314] [client 154.208.48.130:49320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nmQAAAQI"]
[Mon Jul 20 07:23:05.777853 2026] [security2:error] [pid 110058:tid 110314] [client 154.208.48.130:49320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hORJHADqs2gAgBs-nmQAAAQI"]
[Mon Jul 20 07:23:05.802173 2026] [security2:error] [pid 110058:tid 110295] [client 4.218.23.144:17667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hORJHADqs2gAgBs-nmwAAAO8"]
[Mon Jul 20 07:23:05.940163 2026] [security2:error] [pid 110058:tid 110311] [client 4.218.23.144:17667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hORJHADqs2gAgBs-nqAAAAP8"]
[Mon Jul 20 07:23:06.125016 2026] [security2:error] [pid 110058:tid 110197] [client 14.225.17.146:58077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4hORJHADqs2gAgBs-ngwAAAI0"], referer: http://idigress.studio/backup
[Mon Jul 20 07:23:06.159205 2026] [security2:error] [pid 110058:tid 110229] [client 46.110.96.34:3132] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4hOhJHADqs2gAgBs-nuAAAAK0"]
[Mon Jul 20 07:23:06.418860 2026] [security2:error] [pid 110058:tid 110102] [remote 8.217.108.67:41318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hOhJHADqs2gAgBs-n0AAAkys"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:23:06.448038 2026] [security2:error] [pid 110058:tid 110242] [client 49.37.242.14:63790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hOhJHADqs2gAgBs-n0wAAALo"]
[Mon Jul 20 07:23:06.448131 2026] [security2:error] [pid 110058:tid 110242] [client 49.37.242.14:63790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hOhJHADqs2gAgBs-n0wAAALo"]
[Mon Jul 20 07:23:06.695718 2026] [security2:error] [pid 110058:tid 110279] [client 201.27.111.74:53541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hOhJHADqs2gAgBs-n7AAAAN8"]
[Mon Jul 20 07:23:06.701743 2026] [security2:error] [pid 110058:tid 110279] [client 201.27.111.74:53541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hOhJHADqs2gAgBs-n7AAAAN8"]
[Mon Jul 20 07:23:07.018498 2026] [security2:error] [pid 110058:tid 110164] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hOxJHADqs2gAgBs-n_QAA0Gg"]
[Mon Jul 20 07:23:07.018661 2026] [security2:error] [pid 110058:tid 110264] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hOxJHADqs2gAgBs-n_QAA0Gg"]
[Mon Jul 20 07:23:07.243198 2026] [security2:error] [pid 110058:tid 110199] [client 52.109.20.47:19072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hOxJHADqs2gAgBs-oEgAAAI8"]
[Mon Jul 20 07:23:07.267727 2026] [security2:error] [pid 110058:tid 110218] [client 154.192.123.127:18455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hOxJHADqs2gAgBs-oEwAAAKI"]
[Mon Jul 20 07:23:07.267867 2026] [security2:error] [pid 110058:tid 110218] [client 154.192.123.127:18455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hOxJHADqs2gAgBs-oEwAAAKI"]
[Mon Jul 20 07:23:07.277225 2026] [security2:error] [pid 110058:tid 110262] [client 52.109.20.47:19072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hOxJHADqs2gAgBs-oFwAAAM4"]
[Mon Jul 20 07:23:07.391874 2026] [security2:error] [pid 110058:tid 110304] [client 14.225.17.146:64454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4hOxJHADqs2gAgBs-oFAAAAPg"], referer: http://cephasnext.com/backup
[Mon Jul 20 07:23:07.881496 2026] [security2:error] [pid 110058:tid 110264] [client 14.225.17.146:64543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4hOxJHADqs2gAgBs-oOgAAANA"], referer: http://collectingrealestate.com/backup
[Mon Jul 20 07:23:08.041844 2026] [security2:error] [pid 110058:tid 110249] [client 158.173.89.95:47355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hPBJHADqs2gAgBs-oTQAAAME"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:08.249950 2026] [security2:error] [pid 110058:tid 110305] [client 77.110.127.138:64620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPBJHADqs2gAgBs-oXgAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:08.250036 2026] [security2:error] [pid 110058:tid 110305] [client 77.110.127.138:64620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPBJHADqs2gAgBs-oXgAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:08.703078 2026] [security2:error] [pid 110058:tid 110246] [client 77.110.127.138:64611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPBJHADqs2gAgBs-ogAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:08.703233 2026] [security2:error] [pid 110058:tid 110246] [client 77.110.127.138:64611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPBJHADqs2gAgBs-ogAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:08.858201 2026] [security2:error] [pid 110058:tid 110247] [client 77.110.127.138:64622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPBJHADqs2gAgBs-ojgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:08.858277 2026] [security2:error] [pid 110058:tid 110247] [client 77.110.127.138:64622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPBJHADqs2gAgBs-ojgAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:09.007229 2026] [security2:error] [pid 110058:tid 110193] [client 3.78.190.80:50610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hPBJHADqs2gAgBs-oYAAAAIk"]
[Mon Jul 20 07:23:09.011471 2026] [security2:error] [pid 110058:tid 110194] [client 57.141.18.51:44212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hOhJHADqs2gAgBs-n5AAAimY"]
[Mon Jul 20 07:23:09.045570 2026] [security2:error] [pid 110058:tid 110238] [client 34.23.246.146:62306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4hPBJHADqs2gAgBs-obQAAALY"], referer: http://maxenengineering.com/wp-json/batch/v1
[Mon Jul 20 07:23:09.206854 2026] [security2:error] [pid 110058:tid 110253] [client 213.32.68.86:34138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.68.32.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/edu-dl/edu-dl.php"] [unique_id "al4hPRJHADqs2gAgBs-oswAAAMU"]
[Mon Jul 20 07:23:09.341213 2026] [security2:error] [pid 110058:tid 110227] [client 14.225.17.146:53245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4hPRJHADqs2gAgBs-ouAAAAKs"], referer: http://whiteoutcb.com/backup
[Mon Jul 20 07:23:09.452982 2026] [security2:error] [pid 110058:tid 110307] [client 187.16.64.216:54701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hPRJHADqs2gAgBs-oxwAAAPs"]
[Mon Jul 20 07:23:09.453124 2026] [security2:error] [pid 110058:tid 110307] [client 187.16.64.216:54701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hPRJHADqs2gAgBs-oxwAAAPs"]
[Mon Jul 20 07:23:09.536392 2026] [security2:error] [pid 110058:tid 110238] [client 50.116.65.227:31004] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hPRJHADqs2gAgBs-o0gAAALY"]
[Mon Jul 20 07:23:09.546680 2026] [security2:error] [pid 110058:tid 110218] [client 50.116.65.227:31006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hPRJHADqs2gAgBs-o0wAAAKI"]
[Mon Jul 20 07:23:09.595970 2026] [security2:error] [pid 110058:tid 110231] [client 14.225.17.146:61485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4hPRJHADqs2gAgBs-oyAAAAK8"], referer: http://olearyplumbingllc.com/backup
[Mon Jul 20 07:23:09.635665 2026] [security2:error] [pid 110058:tid 110157] [remote 4.205.168.44:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hPRJHADqs2gAgBs-o1gAA52E"]
[Mon Jul 20 07:23:09.829157 2026] [security2:error] [pid 110058:tid 110185] [remote 4.205.168.44:44922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hPRJHADqs2gAgBs-o7AAArH0"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:23:09.886055 2026] [security2:error] [pid 110058:tid 110246] [client 57.129.81.224:52040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/edu-dl/edu-dl.php"] [unique_id "al4hPRJHADqs2gAgBs-o8gAAAL4"]
[Mon Jul 20 07:23:10.190651 2026] [security2:error] [pid 110058:tid 110279] [client 117.211.236.168:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hPhJHADqs2gAgBs-pCwAAAN8"]
[Mon Jul 20 07:23:10.190775 2026] [security2:error] [pid 110058:tid 110279] [client 117.211.236.168:58776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hPhJHADqs2gAgBs-pCwAAAN8"]
[Mon Jul 20 07:23:10.475701 2026] [security2:error] [pid 110058:tid 110243] [client 143.44.185.218:27924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hPhJHADqs2gAgBs-pIAAAALs"]
[Mon Jul 20 07:23:10.475847 2026] [security2:error] [pid 110058:tid 110243] [client 143.44.185.218:27924] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hPhJHADqs2gAgBs-pIAAAALs"]
[Mon Jul 20 07:23:10.513232 2026] [security2:error] [pid 110058:tid 110265] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPhJHADqs2gAgBs-pHgAAANE"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:10.606501 2026] [security2:error] [pid 110058:tid 110265] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPhJHADqs2gAgBs-pHgAAANE"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:10.711768 2026] [security2:error] [pid 110058:tid 110304] [client 104.234.53.58:24699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hPhJHADqs2gAgBs-pNgAAAPg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:10.759478 2026] [security2:error] [pid 110058:tid 110213] [client 57.141.18.28:44734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hPBJHADqs2gAgBs-onAAAnU4"]
[Mon Jul 20 07:23:10.798226 2026] [security2:error] [pid 110058:tid 110206] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPhJHADqs2gAgBs-pPQAAAJY"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:10.894426 2026] [security2:error] [pid 110058:tid 110206] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPhJHADqs2gAgBs-pPQAAAJY"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.028025 2026] [security2:error] [pid 110058:tid 110191] [client 121.229.156.95:54128] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.qualitycoatingsinspection.com"] [uri "/"] [unique_id "al4hPxJHADqs2gAgBs-pSgAAAIc"]
[Mon Jul 20 07:23:11.028094 2026] [security2:error] [pid 110058:tid 110191] [client 121.229.156.95:54128] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.qualitycoatingsinspection.com"] [uri "/"] [unique_id "al4hPxJHADqs2gAgBs-pSgAAAIc"]
[Mon Jul 20 07:23:11.083584 2026] [security2:error] [pid 110058:tid 110265] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pTwAAANE"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.174409 2026] [security2:error] [pid 110058:tid 110265] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pTwAAANE"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.231887 2026] [security2:error] [pid 110058:tid 110207] [client 136.158.60.21:7603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hPxJHADqs2gAgBs-pYgAAAJc"]
[Mon Jul 20 07:23:11.231983 2026] [security2:error] [pid 110058:tid 110207] [client 136.158.60.21:7603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hPxJHADqs2gAgBs-pYgAAAJc"]
[Mon Jul 20 07:23:11.332061 2026] [security2:error] [pid 110058:tid 110280] [client 104.234.53.57:46031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hPxJHADqs2gAgBs-pawAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:11.364080 2026] [security2:error] [pid 110058:tid 110294] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pbQAAAO4"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.399101 2026] [security2:error] [pid 110058:tid 110206] [client 77.110.127.138:64615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pdgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.399187 2026] [security2:error] [pid 110058:tid 110206] [client 77.110.127.138:64615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pdgAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.436346 2026] [autoindex:error] [pid 110058:tid 110155] [remote 35.196.3.178:50706] AH01276: Cannot serve directory /home2/elvxwymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.elv.xwy.mybluehost.me
[Mon Jul 20 07:23:11.451583 2026] [security2:error] [pid 110058:tid 110217] [client 77.110.127.138:64617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pewAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.451698 2026] [security2:error] [pid 110058:tid 110217] [client 77.110.127.138:64617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pewAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.461786 2026] [security2:error] [pid 110058:tid 110294] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pbQAAAO4"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.604523 2026] [security2:error] [pid 110058:tid 110289] [client 77.110.127.138:64619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pgwAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.604614 2026] [security2:error] [pid 110058:tid 110289] [client 77.110.127.138:64619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pgwAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.651174 2026] [security2:error] [pid 110058:tid 110235] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-piwAAALM"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.655269 2026] [security2:error] [pid 110058:tid 110223] [client 77.110.127.138:64624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pjgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.655360 2026] [security2:error] [pid 110058:tid 110223] [client 77.110.127.138:64624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pjgAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.739694 2026] [security2:error] [pid 110058:tid 110235] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-piwAAALM"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:11.752324 2026] [security2:error] [pid 110058:tid 110304] [client 77.110.127.138:64609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-plgAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.752418 2026] [security2:error] [pid 110058:tid 110304] [client 77.110.127.138:64609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-plgAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.904760 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-poAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.904857 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-poAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:11.930711 2026] [security2:error] [pid 110058:tid 110196] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pogAAAIw"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.028844 2026] [security2:error] [pid 110058:tid 110196] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hPxJHADqs2gAgBs-pogAAAIw"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.220195 2026] [security2:error] [pid 110058:tid 110211] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-puwAAAJs"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.307021 2026] [security2:error] [pid 110058:tid 110211] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-puwAAAJs"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.364449 2026] [security2:error] [pid 110058:tid 110213] [client 141.94.94.121:47860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/nav-toppers/stickies.php"] [unique_id "al4hQBJHADqs2gAgBs-pvgAAAJ0"]
[Mon Jul 20 07:23:12.497213 2026] [security2:error] [pid 110058:tid 110245] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-p0gAAAL0"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.563354 2026] [security2:error] [pid 110058:tid 110300] [client 74.208.214.194:59634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hQBJHADqs2gAgBs-p1wAAAPQ"]
[Mon Jul 20 07:23:12.587022 2026] [security2:error] [pid 110058:tid 110245] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-p0gAAAL0"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.612757 2026] [security2:error] [pid 110058:tid 110254] [client 57.141.18.80:23714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hPhJHADqs2gAgBs-pOQAAxjA"]
[Mon Jul 20 07:23:12.613663 2026] [security2:error] [pid 110058:tid 110315] [client 104.234.53.91:57285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hQBJHADqs2gAgBs-p2gAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:12.778484 2026] [security2:error] [pid 110058:tid 110266] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-p5gAAANI"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.857609 2026] [security2:error] [pid 110058:tid 110287] [client 14.225.17.146:61603] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4hPxJHADqs2gAgBs-pbwAAAOc"], referer: http://xp-design.co/backup
[Mon Jul 20 07:23:12.862549 2026] [security2:error] [pid 110058:tid 110266] [client 69.165.67.17:59510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "403"] [hostname "mail.lapietramedjugorje.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-p5gAAANI"], referer: https://mail.lapietramedjugorje.com
[Mon Jul 20 07:23:12.907816 2026] [security2:error] [pid 110058:tid 110296] [client 57.129.81.225:50972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.81.129.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/nav-toppers/stickies.php"] [unique_id "al4hQBJHADqs2gAgBs-p7wAAAPA"]
[Mon Jul 20 07:23:12.978464 2026] [security2:error] [pid 110058:tid 110265] [client 77.110.127.138:64603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-p9wAAANE"]
[Mon Jul 20 07:23:12.978557 2026] [security2:error] [pid 110058:tid 110265] [client 77.110.127.138:64603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQBJHADqs2gAgBs-p9wAAANE"]
[Mon Jul 20 07:23:12.998667 2026] [security2:error] [pid 110058:tid 110289] [client 74.7.227.179:52680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4hQBJHADqs2gAgBs-p6wAA6Xs"], referer: https://tejasenvironmental.com/p=965166
[Mon Jul 20 07:23:13.030122 2026] [security2:error] [pid 110058:tid 110269] [client 77.110.127.138:64626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQRJHADqs2gAgBs-qBgAAANU"]
[Mon Jul 20 07:23:13.030220 2026] [security2:error] [pid 110058:tid 110269] [client 77.110.127.138:64626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQRJHADqs2gAgBs-qBgAAANU"]
[Mon Jul 20 07:23:13.143233 2026] [security2:error] [pid 110058:tid 110222] [client 14.225.17.146:61498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4hQBJHADqs2gAgBs-p-QAAAKY"], referer: http://uritems.net/backup
[Mon Jul 20 07:23:13.190169 2026] [security2:error] [pid 110058:tid 110248] [client 57.141.18.29:40940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hPxJHADqs2gAgBs-paAAAwGg"]
[Mon Jul 20 07:23:13.201683 2026] [security2:error] [pid 110058:tid 110141] [remote 57.141.18.113:50124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2729187"] [unique_id "al4hQRJHADqs2gAgBs-qDwAAwlE"]
[Mon Jul 20 07:23:13.549762 2026] [security2:error] [pid 110058:tid 110238] [client 49.47.218.174:62840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hQRJHADqs2gAgBs-qJQAAALY"]
[Mon Jul 20 07:23:13.549872 2026] [security2:error] [pid 110058:tid 110238] [client 49.47.218.174:62840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hQRJHADqs2gAgBs-qJQAAALY"]
[Mon Jul 20 07:23:13.573346 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQRJHADqs2gAgBs-qJwAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:13.573426 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQRJHADqs2gAgBs-qJwAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:13.922225 2026] [security2:error] [pid 110058:tid 110134] [remote 100.42.189.89:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hQRJHADqs2gAgBs-qTAAAlUo"]
[Mon Jul 20 07:23:13.922395 2026] [security2:error] [pid 110058:tid 110205] [client 100.42.189.89:56080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hQRJHADqs2gAgBs-qTAAAlUo"]
[Mon Jul 20 07:23:14.154986 2026] [security2:error] [pid 110058:tid 110234] [client 103.176.215.66:51534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qXwAAALI"]
[Mon Jul 20 07:23:14.155471 2026] [security2:error] [pid 110058:tid 110234] [client 103.176.215.66:51534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qXwAAALI"]
[Mon Jul 20 07:23:14.312028 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQhJHADqs2gAgBs-qZQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:14.312148 2026] [security2:error] [pid 110058:tid 110258] [client 77.110.127.138:64637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hQhJHADqs2gAgBs-qZQAAAMo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:14.430012 2026] [security2:error] [pid 110058:tid 110274] [client 36.93.152.155:59245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qbgAAANo"]
[Mon Jul 20 07:23:14.430096 2026] [security2:error] [pid 110058:tid 110274] [client 36.93.152.155:59245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qbgAAANo"]
[Mon Jul 20 07:23:14.508848 2026] [security2:error] [pid 110058:tid 110294] [client 57.141.18.18:50176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hQBJHADqs2gAgBs-p3wAA7lg"]
[Mon Jul 20 07:23:14.528795 2026] [security2:error] [pid 110058:tid 110198] [client 20.151.205.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "maxcom.net"] [uri "/.well-known/about.php"] [unique_id "al4hQhJHADqs2gAgBs-qdwAAAI4"]
[Mon Jul 20 07:23:14.528944 2026] [security2:error] [pid 110058:tid 110198] [client 20.151.205.204:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "maxcom.net"] [uri "/.well-known/about.php"] [unique_id "al4hQhJHADqs2gAgBs-qdwAAAI4"]
[Mon Jul 20 07:23:14.597235 2026] [security2:error] [pid 110058:tid 110250] [client 52.109.28.48:3904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hQhJHADqs2gAgBs-qfQAAAMI"]
[Mon Jul 20 07:23:14.607058 2026] [core:error] [pid 110058:tid 110207] [client 14.225.17.146:60958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:14.607088 2026] [core:error] [pid 110058:tid 110207] [client 14.225.17.146:60958] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:14.741453 2026] [security2:error] [pid 110058:tid 110239] [client 52.109.28.48:3904] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hQhJHADqs2gAgBs-qhgAAALc"]
[Mon Jul 20 07:23:14.890214 2026] [security2:error] [pid 110058:tid 110217] [client 157.20.138.62:63897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qnQAAAKE"]
[Mon Jul 20 07:23:14.890986 2026] [security2:error] [pid 110058:tid 110217] [client 157.20.138.62:63897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qnQAAAKE"]
[Mon Jul 20 07:23:14.937621 2026] [security2:error] [pid 110058:tid 110307] [client 191.202.66.27:63662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qpQAAAPs"]
[Mon Jul 20 07:23:14.937785 2026] [security2:error] [pid 110058:tid 110307] [client 191.202.66.27:63662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hQhJHADqs2gAgBs-qpQAAAPs"]
[Mon Jul 20 07:23:15.007983 2026] [security2:error] [pid 110058:tid 110175] [remote 117.0.21.154:49316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4hQhJHADqs2gAgBs-qpgAA_3M"]
[Mon Jul 20 07:23:15.075506 2026] [core:error] [pid 110058:tid 110299] [client 14.225.17.146:49679] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/backup
[Mon Jul 20 07:23:15.075528 2026] [core:error] [pid 110058:tid 110299] [client 14.225.17.146:49679] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/backup
[Mon Jul 20 07:23:15.280997 2026] [security2:error] [pid 110058:tid 110265] [client 52.109.68.130:26049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hQxJHADqs2gAgBs-quwAAANE"]
[Mon Jul 20 07:23:15.324581 2026] [security2:error] [pid 110058:tid 110232] [client 14.225.17.146:49678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4hQxJHADqs2gAgBs-qqgAAALA"], referer: http://adastra.love/backup
[Mon Jul 20 07:23:15.437156 2026] [security2:error] [pid 110058:tid 110252] [client 52.109.68.130:26049] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hQxJHADqs2gAgBs-qzwAAAMQ"]
[Mon Jul 20 07:23:15.493070 2026] [security2:error] [pid 110058:tid 110278] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thescarystory.com"] [uri "/index.php"] [unique_id "al4hQhJHADqs2gAgBs-qkAAAAN4"]
[Mon Jul 20 07:23:15.510733 2026] [security2:error] [pid 110058:tid 110266] [client 14.225.17.146:61441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hQxJHADqs2gAgBs-qwgAAANI"], referer: http://fkconstructionfunding.com/backup
[Mon Jul 20 07:23:15.563563 2026] [security2:error] [pid 110058:tid 110202] [client 57.141.18.90:49558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hQRJHADqs2gAgBs-qRwAAkkE"]
[Mon Jul 20 07:23:15.594203 2026] [security2:error] [pid 110058:tid 110315] [client 104.234.53.81:59887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hQxJHADqs2gAgBs-q1wAAAQM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:15.619070 2026] [security2:error] [pid 110058:tid 110214] [client 179.127.84.238:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hQxJHADqs2gAgBs-q2AAAAJ4"]
[Mon Jul 20 07:23:15.619171 2026] [security2:error] [pid 110058:tid 110214] [client 179.127.84.238:65121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hQxJHADqs2gAgBs-q2AAAAJ4"]
[Mon Jul 20 07:23:15.686945 2026] [security2:error] [pid 110058:tid 110300] [client 88.241.67.160:56114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hQxJHADqs2gAgBs-q2wAAAPQ"]
[Mon Jul 20 07:23:15.687401 2026] [security2:error] [pid 110058:tid 110300] [client 88.241.67.160:56114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hQxJHADqs2gAgBs-q2wAAAPQ"]
[Mon Jul 20 07:23:15.793996 2026] [security2:error] [pid 110058:tid 110081] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hQxJHADqs2gAgBs-q4AAApBY"]
[Mon Jul 20 07:23:15.794116 2026] [security2:error] [pid 110058:tid 110220] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hQxJHADqs2gAgBs-q4AAApBY"]
[Mon Jul 20 07:23:15.876322 2026] [security2:error] [pid 110058:tid 110283] [client 14.225.17.146:49697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4hQxJHADqs2gAgBs-q3QAAAOM"], referer: http://ksands.co.uk/backup
[Mon Jul 20 07:23:16.123372 2026] [security2:error] [pid 110058:tid 110242] [client 103.106.165.44:50409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hRBJHADqs2gAgBs-q_QAAALo"]
[Mon Jul 20 07:23:16.123565 2026] [security2:error] [pid 110058:tid 110242] [client 103.106.165.44:50409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hRBJHADqs2gAgBs-q_QAAALo"]
[Mon Jul 20 07:23:16.151492 2026] [security2:error] [pid 110058:tid 110072] [remote 117.0.21.154:49316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4hRBJHADqs2gAgBs-rAAAA-w0"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 07:23:16.244522 2026] [security2:error] [pid 110058:tid 110306] [client 34.55.163.65:21986] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "keywayconstructionclt.com"] [uri "/"] [unique_id "al4hRBJHADqs2gAgBs-rCAAAAPo"]
[Mon Jul 20 07:23:16.276023 2026] [security2:error] [pid 110058:tid 110202] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4hRBJHADqs2gAgBs-rBAAAAJI"]
[Mon Jul 20 07:23:16.280562 2026] [security2:error] [pid 110058:tid 110272] [client 57.141.18.97:22240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hQhJHADqs2gAgBs-qfwAA2Ho"]
[Mon Jul 20 07:23:16.370138 2026] [core:error] [pid 110058:tid 110225] [client 144.172.114.51:41640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:16.370162 2026] [core:error] [pid 110058:tid 110225] [client 144.172.114.51:41640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:16.562527 2026] [security2:error] [pid 110058:tid 110263] [client 14.225.17.146:65059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hRBJHADqs2gAgBs-rFAAAAM8"], referer: https://fkconstructionfunding.com/backup
[Mon Jul 20 07:23:16.642211 2026] [security2:error] [pid 110058:tid 110207] [client 141.94.94.61:51460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/fats/fat_quiz.php"] [unique_id "al4hRBJHADqs2gAgBs-rIgAAAJc"]
[Mon Jul 20 07:23:16.715166 2026] [security2:error] [pid 110058:tid 110282] [client 57.141.18.27:20788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hQhJHADqs2gAgBs-qpAAA4gs"]
[Mon Jul 20 07:23:16.818449 2026] [security2:error] [pid 110058:tid 110204] [client 154.208.48.130:49857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hRBJHADqs2gAgBs-rLwAAAJQ"]
[Mon Jul 20 07:23:16.818574 2026] [security2:error] [pid 110058:tid 110204] [client 154.208.48.130:49857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hRBJHADqs2gAgBs-rLwAAAJQ"]
[Mon Jul 20 07:23:16.858947 2026] [security2:error] [pid 110058:tid 110279] [client 14.225.17.146:53165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4hRBJHADqs2gAgBs-rKwAAAN8"], referer: http://39ishlife.com/backup
[Mon Jul 20 07:23:16.924863 2026] [security2:error] [pid 110058:tid 110276] [client 201.27.111.74:54048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hRBJHADqs2gAgBs-rOwAAANw"]
[Mon Jul 20 07:23:16.928157 2026] [security2:error] [pid 110058:tid 110276] [client 201.27.111.74:54048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hRBJHADqs2gAgBs-rOwAAANw"]
[Mon Jul 20 07:23:17.294509 2026] [security2:error] [pid 110058:tid 110245] [client 57.141.18.96:53638] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hQxJHADqs2gAgBs-q3gAAvSg"]
[Mon Jul 20 07:23:17.294989 2026] [security2:error] [pid 110058:tid 110274] [client 141.94.94.40:58542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.94.94.141.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/fats/fat_quiz.php"] [unique_id "al4hRRJHADqs2gAgBs-rVAAAANo"]
[Mon Jul 20 07:23:17.658819 2026] [security2:error] [pid 110058:tid 110208] [client 34.55.163.65:21986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4hRRJHADqs2gAgBs-rZwAAAJg"], referer: http://keywayconstructionclt.com/wp-json/batch/v1
[Mon Jul 20 07:23:17.750100 2026] [security2:error] [pid 110058:tid 110123] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hRRJHADqs2gAgBs-rdQAAqD8"]
[Mon Jul 20 07:23:17.750246 2026] [security2:error] [pid 110058:tid 110224] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hRRJHADqs2gAgBs-rdQAAqD8"]
[Mon Jul 20 07:23:17.808025 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRRJHADqs2gAgBs-rdwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:17.808116 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRRJHADqs2gAgBs-rdwAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:17.812247 2026] [security2:error] [pid 110058:tid 110204] [client 14.225.17.146:65112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4hRRJHADqs2gAgBs-rdAAAAJQ"], referer: https://39ishlife.com/backup
[Mon Jul 20 07:23:17.828155 2026] [security2:error] [pid 110058:tid 110250] [client 57.141.18.87:26674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hRBJHADqs2gAgBs-rCwAAwh8"]
[Mon Jul 20 07:23:17.862367 2026] [security2:error] [pid 110058:tid 110244] [client 77.110.127.138:64635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRRJHADqs2gAgBs-regAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:17.862437 2026] [security2:error] [pid 110058:tid 110244] [client 77.110.127.138:64635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRRJHADqs2gAgBs-regAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:17.914852 2026] [security2:error] [pid 110058:tid 110293] [client 49.37.242.14:64269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hRRJHADqs2gAgBs-rgAAAAO0"]
[Mon Jul 20 07:23:17.914994 2026] [security2:error] [pid 110058:tid 110293] [client 49.37.242.14:64269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hRRJHADqs2gAgBs-rgAAAAO0"]
[Mon Jul 20 07:23:17.997415 2026] [security2:error] [pid 110058:tid 110190] [client 154.192.123.127:16975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hRRJHADqs2gAgBs-riAAAAIY"]
[Mon Jul 20 07:23:17.997513 2026] [security2:error] [pid 110058:tid 110190] [client 154.192.123.127:16975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hRRJHADqs2gAgBs-riAAAAIY"]
[Mon Jul 20 07:23:18.368480 2026] [security2:error] [pid 110058:tid 110269] [client 14.225.17.146:61232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4hRhJHADqs2gAgBs-rmwAAANU"]
[Mon Jul 20 07:23:18.422035 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRhJHADqs2gAgBs-rrwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:18.422155 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRhJHADqs2gAgBs-rrwAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:18.856302 2026] [security2:error] [pid 110058:tid 110259] [client 57.141.18.45:22196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hRRJHADqs2gAgBs-rUwAAy3k"]
[Mon Jul 20 07:23:19.250821 2026] [security2:error] [pid 110058:tid 110245] [client 77.110.127.138:64664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRxJHADqs2gAgBs-r8AAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:19.250898 2026] [security2:error] [pid 110058:tid 110245] [client 77.110.127.138:64664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hRxJHADqs2gAgBs-r8AAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:19.502745 2026] [security2:error] [pid 110058:tid 110062] [remote 217.182.128.41:41266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hRxJHADqs2gAgBs-sCgAAiQM"]
[Mon Jul 20 07:23:19.502961 2026] [security2:error] [pid 110058:tid 110193] [client 217.182.128.41:41266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hRxJHADqs2gAgBs-sCgAAiQM"]
[Mon Jul 20 07:23:19.873889 2026] [security2:error] [pid 110058:tid 110254] [client 14.225.17.146:65082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4hRxJHADqs2gAgBs-sFwAAAMY"], referer: http://itdynamix.com/backup
[Mon Jul 20 07:23:19.920089 2026] [lsapi:warn] [pid 110058:tid 110262] [client 14.225.17.146:65106] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/backup
[Mon Jul 20 07:23:19.920114 2026] [lsapi:warn] [pid 110058:tid 110262] [client 14.225.17.146:65106] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/backup
[Mon Jul 20 07:23:20.001503 2026] [lsapi:warn] [pid 110058:tid 110193] [client 50.116.65.227:17722] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:23:20.001532 2026] [lsapi:warn] [pid 110058:tid 110193] [client 50.116.65.227:17722] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:23:20.016090 2026] [security2:error] [pid 110058:tid 110262] [client 14.225.17.146:65106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4hRxJHADqs2gAgBs-sJQAAAM4"], referer: http://oswegooperatheater.com/backup
[Mon Jul 20 07:23:20.213008 2026] [security2:error] [pid 110058:tid 110294] [client 187.16.64.216:55255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hSBJHADqs2gAgBs-sRgAAAO4"]
[Mon Jul 20 07:23:20.213122 2026] [security2:error] [pid 110058:tid 110294] [client 187.16.64.216:55255] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hSBJHADqs2gAgBs-sRgAAAO4"]
[Mon Jul 20 07:23:20.241830 2026] [security2:error] [pid 110058:tid 110198] [client 57.141.18.32:23030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hRhJHADqs2gAgBs-rpQAAjn8"]
[Mon Jul 20 07:23:20.842474 2026] [security2:error] [pid 110058:tid 110228] [client 77.110.127.138:64668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSBJHADqs2gAgBs-scwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:20.843464 2026] [security2:error] [pid 110058:tid 110228] [client 77.110.127.138:64668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSBJHADqs2gAgBs-scwAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:20.881183 2026] [lsapi:warn] [pid 110058:tid 110269] [client 14.225.17.146:65039] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/backup
[Mon Jul 20 07:23:20.881205 2026] [lsapi:warn] [pid 110058:tid 110269] [client 14.225.17.146:65039] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/backup
[Mon Jul 20 07:23:20.931838 2026] [security2:error] [pid 110058:tid 110269] [client 14.225.17.146:65039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4hSBJHADqs2gAgBs-sdQAAANU"], referer: https://oswegooperatheater.com/backup
[Mon Jul 20 07:23:21.001701 2026] [security2:error] [pid 110058:tid 110287] [client 14.225.17.146:60941] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4hSBJHADqs2gAgBs-scgAAAOc"], referer: https://itdynamix.com/backup
[Mon Jul 20 07:23:21.426982 2026] [security2:error] [pid 110058:tid 110237] [client 57.141.18.16:57980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hRxJHADqs2gAgBs-sAQAAtRU"]
[Mon Jul 20 07:23:21.530873 2026] [security2:error] [pid 110058:tid 110256] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4hSRJHADqs2gAgBs-sjgAAyDA"], referer: http://ali-alghanim.net/backup
[Mon Jul 20 07:23:21.562170 2026] [security2:error] [pid 110058:tid 110289] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aosta.nz"] [uri "/index.php"] [unique_id "al4hSBJHADqs2gAgBs-sQAAAAOk"]
[Mon Jul 20 07:23:21.719237 2026] [security2:error] [pid 110058:tid 110226] [client 57.141.18.58:54238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hRxJHADqs2gAgBs-sGAAAqk8"]
[Mon Jul 20 07:23:21.723824 2026] [security2:error] [pid 110058:tid 110211] [client 77.110.127.138:64616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSRJHADqs2gAgBs-svAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:21.723931 2026] [security2:error] [pid 110058:tid 110211] [client 77.110.127.138:64616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSRJHADqs2gAgBs-svAAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:21.804667 2026] [security2:error] [pid 110058:tid 110150] [remote 188.40.28.4:33368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hSRJHADqs2gAgBs-swQAAoFo"]
[Mon Jul 20 07:23:21.804811 2026] [security2:error] [pid 110058:tid 110216] [client 188.40.28.4:33368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hSRJHADqs2gAgBs-swQAAoFo"]
[Mon Jul 20 07:23:21.848730 2026] [security2:error] [pid 110058:tid 110274] [client 14.225.17.146:49999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4hSBJHADqs2gAgBs-sSgAAANo"], referer: http://lelandumc.org/backup
[Mon Jul 20 07:23:21.887743 2026] [security2:error] [pid 110058:tid 110246] [client 77.110.127.138:64672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSRJHADqs2gAgBs-syAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:21.887843 2026] [security2:error] [pid 110058:tid 110246] [client 77.110.127.138:64672] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSRJHADqs2gAgBs-syAAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:21.930519 2026] [security2:error] [pid 110058:tid 110235] [client 136.158.60.21:9149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hSRJHADqs2gAgBs-s0AAAALM"]
[Mon Jul 20 07:23:21.930659 2026] [security2:error] [pid 110058:tid 110235] [client 136.158.60.21:9149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hSRJHADqs2gAgBs-s0AAAALM"]
[Mon Jul 20 07:23:22.246542 2026] [security2:error] [pid 110058:tid 110305] [client 57.141.18.28:52690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hSBJHADqs2gAgBs-sSQAA-W4"]
[Mon Jul 20 07:23:22.329257 2026] [security2:error] [pid 110058:tid 110226] [client 50.116.65.227:17748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hShJHADqs2gAgBs-s5QAAAKo"]
[Mon Jul 20 07:23:22.337838 2026] [security2:error] [pid 110058:tid 110199] [client 50.116.65.227:17760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hShJHADqs2gAgBs-s5wAAAI8"]
[Mon Jul 20 07:23:22.740364 2026] [security2:error] [pid 110058:tid 110296] [client 57.141.18.107:60196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hSBJHADqs2gAgBs-scQAA8HU"]
[Mon Jul 20 07:23:22.760314 2026] [security2:error] [pid 110058:tid 110309] [client 117.211.236.168:59326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hShJHADqs2gAgBs-tFgAAAP0"]
[Mon Jul 20 07:23:22.760450 2026] [security2:error] [pid 110058:tid 110309] [client 117.211.236.168:59326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hShJHADqs2gAgBs-tFgAAAP0"]
[Mon Jul 20 07:23:22.992502 2026] [security2:error] [pid 110058:tid 110275] [client 77.110.127.138:64660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hShJHADqs2gAgBs-tMAAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:22.992629 2026] [security2:error] [pid 110058:tid 110275] [client 77.110.127.138:64660] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hShJHADqs2gAgBs-tMAAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:22.998725 2026] [security2:error] [pid 110058:tid 110270] [client 14.225.17.146:52887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4hShJHADqs2gAgBs-tGQAAANY"], referer: http://myspineworld.com/backup
[Mon Jul 20 07:23:23.048660 2026] [security2:error] [pid 110058:tid 110268] [client 77.110.127.138:64669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tMgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.048761 2026] [security2:error] [pid 110058:tid 110268] [client 77.110.127.138:64669] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tMgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.221419 2026] [security2:error] [pid 110058:tid 110264] [client 143.44.185.218:29268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hSxJHADqs2gAgBs-tPQAAANA"]
[Mon Jul 20 07:23:23.221530 2026] [security2:error] [pid 110058:tid 110264] [client 143.44.185.218:29268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hSxJHADqs2gAgBs-tPQAAANA"]
[Mon Jul 20 07:23:23.276335 2026] [security2:error] [pid 110058:tid 110315] [client 14.225.17.146:52575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4hSxJHADqs2gAgBs-tOAAAAQM"], referer: http://momheadquarters.com/backup
[Mon Jul 20 07:23:23.354430 2026] [security2:error] [pid 110058:tid 110223] [client 77.110.127.138:64691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tRwAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.354520 2026] [security2:error] [pid 110058:tid 110223] [client 77.110.127.138:64691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tRwAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.405614 2026] [security2:error] [pid 110058:tid 110278] [client 77.110.127.138:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tTAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.405690 2026] [security2:error] [pid 110058:tid 110278] [client 77.110.127.138:64671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tTAAAAN4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.455982 2026] [security2:error] [pid 110058:tid 110235] [client 77.110.127.138:64673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tUgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.456083 2026] [security2:error] [pid 110058:tid 110235] [client 77.110.127.138:64673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tUgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.547872 2026] [security2:error] [pid 110058:tid 110314] [client 77.110.127.138:64688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tWwAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.547967 2026] [security2:error] [pid 110058:tid 110314] [client 77.110.127.138:64688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tWwAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.721721 2026] [security2:error] [pid 110058:tid 110251] [client 77.110.127.138:64694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tZAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.721853 2026] [security2:error] [pid 110058:tid 110251] [client 77.110.127.138:64694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hSxJHADqs2gAgBs-tZAAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:23.934563 2026] [security2:error] [pid 110058:tid 110282] [client 49.47.218.174:64387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hSxJHADqs2gAgBs-tdAAAAOI"]
[Mon Jul 20 07:23:23.934729 2026] [security2:error] [pid 110058:tid 110282] [client 49.47.218.174:64387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hSxJHADqs2gAgBs-tdAAAAOI"]
[Mon Jul 20 07:23:24.031457 2026] [security2:error] [pid 110058:tid 110078] [remote 45.90.123.233:42016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hTBJHADqs2gAgBs-tegABABM"]
[Mon Jul 20 07:23:24.046094 2026] [security2:error] [pid 110058:tid 110232] [client 14.225.17.146:51995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4hSxJHADqs2gAgBs-tcQAAALA"], referer: https://myspineworld.com/backup
[Mon Jul 20 07:23:24.106341 2026] [core:error] [pid 110058:tid 110225] [client 14.225.17.146:51011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:24.106362 2026] [core:error] [pid 110058:tid 110225] [client 14.225.17.146:51011] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:24.198870 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hTBJHADqs2gAgBs-tgQAAAKg"]
[Mon Jul 20 07:23:24.198993 2026] [security2:error] [pid 110058:tid 110224] [client 77.110.127.138:64658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hTBJHADqs2gAgBs-tgQAAAKg"]
[Mon Jul 20 07:23:24.257784 2026] [security2:error] [pid 110058:tid 110200] [client 77.110.127.138:64639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hTBJHADqs2gAgBs-thwAAAJA"]
[Mon Jul 20 07:23:24.257920 2026] [security2:error] [pid 110058:tid 110200] [client 77.110.127.138:64639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hTBJHADqs2gAgBs-thwAAAJA"]
[Mon Jul 20 07:23:24.348992 2026] [security2:error] [pid 110058:tid 110084] [remote 45.90.123.233:42016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hTBJHADqs2gAgBs-tkQAAlhk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:23:24.368421 2026] [security2:error] [pid 110058:tid 110251] [client 77.110.127.138:64642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hTBJHADqs2gAgBs-tlQAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:24.368496 2026] [security2:error] [pid 110058:tid 110251] [client 77.110.127.138:64642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hTBJHADqs2gAgBs-tlQAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:24.738485 2026] [security2:error] [pid 110058:tid 110193] [client 103.176.215.66:52077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hTBJHADqs2gAgBs-trwAAAIk"]
[Mon Jul 20 07:23:24.738953 2026] [security2:error] [pid 110058:tid 110193] [client 103.176.215.66:52077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hTBJHADqs2gAgBs-trwAAAIk"]
[Mon Jul 20 07:23:24.894292 2026] [security2:error] [pid 110058:tid 110267] [client 36.93.152.155:59747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hTBJHADqs2gAgBs-twAAAANM"]
[Mon Jul 20 07:23:24.894388 2026] [security2:error] [pid 110058:tid 110267] [client 36.93.152.155:59747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hTBJHADqs2gAgBs-twAAAANM"]
[Mon Jul 20 07:23:24.926042 2026] [security2:error] [pid 110058:tid 110201] [client 14.225.17.146:50964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4hTBJHADqs2gAgBs-tqwAAAJE"], referer: http://talknutritionwithlesley.com/backup
[Mon Jul 20 07:23:25.035472 2026] [security2:error] [pid 110058:tid 110285] [client 14.225.17.146:50997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4hTBJHADqs2gAgBs-trQAAAOU"], referer: http://transparentservices.online/backup
[Mon Jul 20 07:23:25.051578 2026] [security2:error] [pid 110058:tid 110295] [client 104.234.53.76:20517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hTBJHADqs2gAgBs-txAAAAO8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:25.274591 2026] [security2:error] [pid 110058:tid 110294] [client 104.234.53.76:20517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hTRJHADqs2gAgBs-t2wAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:25.581281 2026] [security2:error] [pid 110058:tid 110197] [client 191.202.66.27:64360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hTRJHADqs2gAgBs-uAQAAAI0"]
[Mon Jul 20 07:23:25.581379 2026] [security2:error] [pid 110058:tid 110197] [client 191.202.66.27:64360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hTRJHADqs2gAgBs-uAQAAAI0"]
[Mon Jul 20 07:23:25.601304 2026] [security2:error] [pid 110058:tid 110304] [client 157.20.138.62:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hTRJHADqs2gAgBs-uAwAAAPg"]
[Mon Jul 20 07:23:25.601413 2026] [security2:error] [pid 110058:tid 110304] [client 157.20.138.62:64474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hTRJHADqs2gAgBs-uAwAAAPg"]
[Mon Jul 20 07:23:25.666072 2026] [security2:error] [pid 110058:tid 110270] [client 52.167.144.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.floorsourcestock.com"] [uri "/index.php"] [unique_id "al4hTRJHADqs2gAgBs-t9AAAANY"]
[Mon Jul 20 07:23:25.904744 2026] [security2:error] [pid 110058:tid 110310] [client 14.225.17.146:51349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4hTRJHADqs2gAgBs-uDQAAAP4"], referer: http://ccsdifference.com/backup
[Mon Jul 20 07:23:26.097200 2026] [security2:error] [pid 110058:tid 110253] [client 77.110.127.138:64705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hThJHADqs2gAgBs-uLgAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:26.097285 2026] [security2:error] [pid 110058:tid 110253] [client 77.110.127.138:64705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hThJHADqs2gAgBs-uLgAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:26.291247 2026] [security2:error] [pid 110058:tid 110298] [client 179.127.84.238:49264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uOAAAAPI"]
[Mon Jul 20 07:23:26.291364 2026] [security2:error] [pid 110058:tid 110298] [client 179.127.84.238:49264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uOAAAAPI"]
[Mon Jul 20 07:23:26.292858 2026] [security2:error] [pid 110058:tid 110280] [client 88.241.67.160:53775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uOQAAAOA"]
[Mon Jul 20 07:23:26.293701 2026] [security2:error] [pid 110058:tid 110280] [client 88.241.67.160:53775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uOQAAAOA"]
[Mon Jul 20 07:23:26.346173 2026] [security2:error] [pid 110058:tid 110309] [client 57.141.18.31:37332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hTBJHADqs2gAgBs-towAA_Sw"]
[Mon Jul 20 07:23:26.453432 2026] [security2:error] [pid 110058:tid 110198] [client 103.106.165.44:50878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uXAAAAI4"]
[Mon Jul 20 07:23:26.453547 2026] [security2:error] [pid 110058:tid 110198] [client 103.106.165.44:50878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uXAAAAI4"]
[Mon Jul 20 07:23:26.466875 2026] [security2:error] [pid 110058:tid 110110] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uXQAAjDM"]
[Mon Jul 20 07:23:26.467060 2026] [security2:error] [pid 110058:tid 110196] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uXQAAjDM"]
[Mon Jul 20 07:23:26.525992 2026] [security2:error] [pid 110058:tid 110186] [remote 162.19.86.63:60928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uYgAA9n4"]
[Mon Jul 20 07:23:26.526107 2026] [security2:error] [pid 110058:tid 110302] [client 162.19.86.63:60928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hThJHADqs2gAgBs-uYgAA9n4"]
[Mon Jul 20 07:23:26.873613 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:52743] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4hThJHADqs2gAgBs-uaQAAAME"], referer: http://maplerespiteservices.com/backup
[Mon Jul 20 07:23:26.879361 2026] [security2:error] [pid 110058:tid 110298] [client 77.110.127.138:64711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hThJHADqs2gAgBs-ucgAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:26.879444 2026] [security2:error] [pid 110058:tid 110298] [client 77.110.127.138:64711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hThJHADqs2gAgBs-ucgAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:26.932890 2026] [security2:error] [pid 110058:tid 110276] [client 14.225.17.146:52842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4hThJHADqs2gAgBs-uagAAANw"], referer: https://ccsdifference.com/backup
[Mon Jul 20 07:23:27.130450 2026] [security2:error] [pid 110058:tid 110285] [client 104.234.53.51:43065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hTxJHADqs2gAgBs-uiQAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:27.251001 2026] [security2:error] [pid 110058:tid 110274] [client 201.27.111.74:54548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hTxJHADqs2gAgBs-ujwAAANo"]
[Mon Jul 20 07:23:27.251093 2026] [security2:error] [pid 110058:tid 110274] [client 201.27.111.74:54548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hTxJHADqs2gAgBs-ujwAAANo"]
[Mon Jul 20 07:23:27.357988 2026] [security2:error] [pid 110058:tid 110254] [client 14.225.17.146:64760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4hTxJHADqs2gAgBs-ujAAAAMY"], referer: http://windowtx.com/backup
[Mon Jul 20 07:23:27.740038 2026] [security2:error] [pid 110058:tid 110211] [client 14.182.195.220:52691] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4hTxJHADqs2gAgBs-urwAAAJs"]
[Mon Jul 20 07:23:27.748531 2026] [security2:error] [pid 110058:tid 110271] [client 14.225.17.146:64779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4hTxJHADqs2gAgBs-upwAAANc"], referer: http://soloceos.com/backup
[Mon Jul 20 07:23:27.759902 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64702] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/if(now()=sysdate(),sleep(15),0)/related-posts/related-posts.css"] [unique_id "al4hTxJHADqs2gAgBs-usAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:27.868918 2026] [security2:error] [pid 110058:tid 110314] [client 154.208.48.130:50386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hTxJHADqs2gAgBs-uvAAAAQI"]
[Mon Jul 20 07:23:27.869074 2026] [security2:error] [pid 110058:tid 110314] [client 154.208.48.130:50386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hTxJHADqs2gAgBs-uvAAAAQI"]
[Mon Jul 20 07:23:27.971561 2026] [security2:error] [pid 110058:tid 110176] [remote 188.95.113.76:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4hTxJHADqs2gAgBs-uzAAAiHQ"]
[Mon Jul 20 07:23:28.239093 2026] [security2:error] [pid 110058:tid 110179] [remote 188.95.113.76:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.113.95.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4hUBJHADqs2gAgBs-u4wAAqnc"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:23:28.458617 2026] [security2:error] [pid 110058:tid 110300] [client 52.109.68.130:26593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hUBJHADqs2gAgBs-u7QAAAPQ"]
[Mon Jul 20 07:23:28.463188 2026] [security2:error] [pid 110058:tid 110081] [remote 182.77.62.24:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hUBJHADqs2gAgBs-u7wAAuxY"]
[Mon Jul 20 07:23:28.506075 2026] [security2:error] [pid 110058:tid 110283] [client 57.141.18.12:21584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hThJHADqs2gAgBs-uWQAA428"]
[Mon Jul 20 07:23:28.545279 2026] [security2:error] [pid 110058:tid 110084] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hUBJHADqs2gAgBs-u9AAA7xk"]
[Mon Jul 20 07:23:28.545389 2026] [security2:error] [pid 110058:tid 110295] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hUBJHADqs2gAgBs-u9AAA7xk"]
[Mon Jul 20 07:23:28.559878 2026] [security2:error] [pid 110058:tid 110316] [client 154.192.123.127:17381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hUBJHADqs2gAgBs-u9QAAAQQ"]
[Mon Jul 20 07:23:28.559957 2026] [security2:error] [pid 110058:tid 110316] [client 154.192.123.127:17381] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hUBJHADqs2gAgBs-u9QAAAQQ"]
[Mon Jul 20 07:23:28.615202 2026] [security2:error] [pid 110058:tid 110312] [client 52.109.68.130:26593] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hUBJHADqs2gAgBs-u-gAAAQA"]
[Mon Jul 20 07:23:28.627320 2026] [security2:error] [pid 110058:tid 110189] [client 77.110.127.138:64712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hUBJHADqs2gAgBs-u-wAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:28.627399 2026] [security2:error] [pid 110058:tid 110189] [client 77.110.127.138:64712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hUBJHADqs2gAgBs-u-wAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:28.710431 2026] [security2:error] [pid 110058:tid 110266] [client 52.109.68.130:15744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hUBJHADqs2gAgBs-vBAAAANI"]
[Mon Jul 20 07:23:28.745888 2026] [security2:error] [pid 110058:tid 110301] [client 104.234.53.50:35625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hUBJHADqs2gAgBs-vBwAAAPU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:28.864643 2026] [security2:error] [pid 110058:tid 110260] [client 52.109.68.130:15744] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hUBJHADqs2gAgBs-vDgAAAMw"]
[Mon Jul 20 07:23:28.919528 2026] [security2:error] [pid 110058:tid 110068] [remote 182.77.62.24:60296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hUBJHADqs2gAgBs-vFgAAzgk"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:23:28.972412 2026] [security2:error] [pid 110058:tid 110210] [client 49.37.242.14:64760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hUBJHADqs2gAgBs-vIQAAAJo"]
[Mon Jul 20 07:23:28.972523 2026] [security2:error] [pid 110058:tid 110210] [client 49.37.242.14:64760] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hUBJHADqs2gAgBs-vIQAAAJo"]
[Mon Jul 20 07:23:29.087341 2026] [proxy:error] [pid 110058:tid 110215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:23:29.087444 2026] [proxy_http:error] [pid 110058:tid 110215] [client 64.23.153.25:39716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:23:29.088826 2026] [proxy:error] [pid 110058:tid 110215] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:23:29.088874 2026] [proxy_http:error] [pid 110058:tid 110215] [client 64.23.153.25:39716] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:23:29.129592 2026] [proxy:error] [pid 110058:tid 110208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:23:29.129693 2026] [proxy_http:error] [pid 110058:tid 110208] [client 64.23.153.25:39728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.mzsassy.com/
[Mon Jul 20 07:23:29.131037 2026] [proxy:error] [pid 110058:tid 110208] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:23:29.131109 2026] [proxy_http:error] [pid 110058:tid 110208] [client 64.23.153.25:39728] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.mzsassy.com/
[Mon Jul 20 07:23:29.191226 2026] [security2:error] [pid 110058:tid 110202] [client 77.110.127.138:64707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hURJHADqs2gAgBs-vPgAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:29.191332 2026] [security2:error] [pid 110058:tid 110202] [client 77.110.127.138:64707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hURJHADqs2gAgBs-vPgAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:29.213432 2026] [security2:error] [pid 110058:tid 110106] [remote 72.167.132.114:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4hURJHADqs2gAgBs-vQAAAvC8"]
[Mon Jul 20 07:23:29.235762 2026] [core:error] [pid 110058:tid 110279] [client 64.23.153.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:29.235782 2026] [core:error] [pid 110058:tid 110279] [client 64.23.153.25:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:29.299991 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hURJHADqs2gAgBs-vSAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:29.300092 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hURJHADqs2gAgBs-vSAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:29.440769 2026] [security2:error] [pid 110058:tid 110180] [remote 72.167.132.114:47640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4hURJHADqs2gAgBs-vVgAA7ng"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 07:23:29.714099 2026] [security2:error] [pid 110058:tid 110203] [client 57.141.18.15:27152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hTxJHADqs2gAgBs-urQAAk0Q"]
[Mon Jul 20 07:23:29.969669 2026] [security2:error] [pid 110058:tid 110196] [client 77.110.127.138:64717] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/related-posts/related-posts.css"] [unique_id "al4hURJHADqs2gAgBs-veAAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:30.020846 2026] [security2:error] [pid 110058:tid 110297] [client 77.110.127.138:64718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hUhJHADqs2gAgBs-vewAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:30.020933 2026] [security2:error] [pid 110058:tid 110297] [client 77.110.127.138:64718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hUhJHADqs2gAgBs-vewAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:30.026567 2026] [ssl:error] [pid 110058:tid 110289] [client 104.48.69.105:40126] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:23:30.140912 2026] [security2:error] [pid 110058:tid 110246] [client 207.46.13.92:7682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4hUBJHADqs2gAgBs-u3AAAvnw"]
[Mon Jul 20 07:23:30.817032 2026] [security2:error] [pid 110058:tid 110223] [client 57.141.18.69:43354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hUBJHADqs2gAgBs-vFQAAp3o"]
[Mon Jul 20 07:23:30.915513 2026] [security2:error] [pid 110058:tid 110264] [client 187.16.64.216:55576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.64.16.187.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hUhJHADqs2gAgBs-vvgAAANA"]
[Mon Jul 20 07:23:30.915658 2026] [security2:error] [pid 110058:tid 110264] [client 187.16.64.216:55576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hUhJHADqs2gAgBs-vvgAAANA"]
[Mon Jul 20 07:23:31.287636 2026] [security2:error] [pid 110058:tid 110247] [client 77.110.127.138:64725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hUxJHADqs2gAgBs-v2QAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:31.287732 2026] [security2:error] [pid 110058:tid 110247] [client 77.110.127.138:64725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hUxJHADqs2gAgBs-v2QAAAL8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:31.303784 2026] [security2:error] [pid 110058:tid 110221] [client 207.46.13.92:7682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4hUxJHADqs2gAgBs-vwwAApRc"]
[Mon Jul 20 07:23:31.358293 2026] [security2:error] [pid 110058:tid 110255] [client 136.144.33.204:61349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4hURJHADqs2gAgBs-vdgAAAMc"]
[Mon Jul 20 07:23:31.358677 2026] [security2:error] [pid 110058:tid 110268] [client 193.36.225.8:58541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4hURJHADqs2gAgBs-vdwAAANQ"]
[Mon Jul 20 07:23:31.508058 2026] [security2:error] [pid 110058:tid 110218] [client 57.141.18.87:32770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hURJHADqs2gAgBs-vbwAAolE"]
[Mon Jul 20 07:23:31.754197 2026] [security2:error] [pid 110058:tid 110263] [client 57.141.18.116:59166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hURJHADqs2gAgBs-vcgAAzxE"]
[Mon Jul 20 07:23:31.993654 2026] [security2:error] [pid 110058:tid 110209] [client 117.211.236.168:59899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hUxJHADqs2gAgBs-wEQAAAJk"]
[Mon Jul 20 07:23:31.993757 2026] [security2:error] [pid 110058:tid 110209] [client 117.211.236.168:59899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hUxJHADqs2gAgBs-wEQAAAJk"]
[Mon Jul 20 07:23:32.135920 2026] [security2:error] [pid 110058:tid 110229] [client 14.225.17.146:59812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4hVBJHADqs2gAgBs-wGAAAAK0"], referer: http://northbrookcpa.ca/backup
[Mon Jul 20 07:23:32.326921 2026] [security2:error] [pid 110058:tid 110230] [client 77.110.127.138:64698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wPgAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.327026 2026] [security2:error] [pid 110058:tid 110230] [client 77.110.127.138:64698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wPgAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.410563 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wRgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.410659 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wRgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.571022 2026] [security2:error] [pid 110058:tid 110207] [client 104.234.53.74:60225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hVBJHADqs2gAgBs-wTgAAAJc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:32.581397 2026] [security2:error] [pid 110058:tid 110289] [client 57.141.18.77:37454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hUhJHADqs2gAgBs-vrgAA6Vw"]
[Mon Jul 20 07:23:32.728496 2026] [security2:error] [pid 110058:tid 110253] [client 136.158.60.21:10647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hVBJHADqs2gAgBs-wXQAAAMU"]
[Mon Jul 20 07:23:32.728625 2026] [security2:error] [pid 110058:tid 110253] [client 136.158.60.21:10647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hVBJHADqs2gAgBs-wXQAAAMU"]
[Mon Jul 20 07:23:32.736025 2026] [security2:error] [pid 110058:tid 110293] [client 77.110.127.138:64704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wXgAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.736127 2026] [security2:error] [pid 110058:tid 110293] [client 77.110.127.138:64704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wXgAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.787450 2026] [security2:error] [pid 110058:tid 110244] [client 77.110.127.138:64716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wYAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:32.787543 2026] [security2:error] [pid 110058:tid 110244] [client 77.110.127.138:64716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVBJHADqs2gAgBs-wYAAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:33.175091 2026] [security2:error] [pid 110058:tid 110297] [client 14.225.17.146:52552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4hUxJHADqs2gAgBs-v_AAAAPE"], referer: http://samdothan.org/backup
[Mon Jul 20 07:23:33.424011 2026] [security2:error] [pid 110058:tid 110070] [remote 102.220.160.176:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "innovativecleaningsvs.com"] [uri "/.env"] [unique_id "al4hVRJHADqs2gAgBs-wlgAA6Qs"]
[Mon Jul 20 07:23:33.462694 2026] [security2:error] [pid 110058:tid 110230] [client 77.110.127.138:64731] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/related-posts/related-posts.css"] [unique_id "al4hVRJHADqs2gAgBs-wmQAAAK4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:33.764457 2026] [security2:error] [pid 110058:tid 110107] [remote 18.61.192.253:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4hVRJHADqs2gAgBs-wsgAA5zA"]
[Mon Jul 20 07:23:33.865742 2026] [security2:error] [pid 110058:tid 110244] [client 158.173.166.181:60433] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hVRJHADqs2gAgBs-wugAAALw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:33.963900 2026] [security2:error] [pid 110058:tid 110219] [client 57.141.18.26:32808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hUxJHADqs2gAgBs-wAwAAozY"]
[Mon Jul 20 07:23:34.105626 2026] [security2:error] [pid 110058:tid 110293] [client 14.225.17.146:51200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4hVhJHADqs2gAgBs-wyAAAAO0"], referer: http://retzkolonglogistics.com/backup
[Mon Jul 20 07:23:34.234539 2026] [security2:error] [pid 110058:tid 110104] [remote 18.61.192.253:51568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4hVhJHADqs2gAgBs-w3wAArS0"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:23:34.302979 2026] [security2:error] [pid 110058:tid 110167] [remote 102.220.160.176:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "innovativecleaningsvs.com"] [uri "/.git/HEAD"] [unique_id "al4hVhJHADqs2gAgBs-w5AAAxGs"]
[Mon Jul 20 07:23:34.419299 2026] [security2:error] [pid 110058:tid 110242] [client 49.47.218.174:63936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hVhJHADqs2gAgBs-w6QAAALo"]
[Mon Jul 20 07:23:34.419395 2026] [security2:error] [pid 110058:tid 110242] [client 49.47.218.174:63936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hVhJHADqs2gAgBs-w6QAAALo"]
[Mon Jul 20 07:23:34.553378 2026] [security2:error] [pid 110058:tid 110253] [client 74.208.214.194:46754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hVhJHADqs2gAgBs-w-QAAAMU"]
[Mon Jul 20 07:23:34.556031 2026] [security2:error] [pid 110058:tid 110192] [client 14.225.17.146:52506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4hVhJHADqs2gAgBs-w0gAAAIg"], referer: http://idigress.group/backup
[Mon Jul 20 07:23:34.684687 2026] [security2:error] [pid 110058:tid 110316] [client 13.233.207.33:31120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hVhJHADqs2gAgBs-xAwAAAQQ"]
[Mon Jul 20 07:23:34.684846 2026] [security2:error] [pid 110058:tid 110316] [client 13.233.207.33:31120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hVhJHADqs2gAgBs-xAwAAAQQ"]
[Mon Jul 20 07:23:34.708522 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVhJHADqs2gAgBs-xBgAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:34.708621 2026] [security2:error] [pid 110058:tid 110296] [client 77.110.127.138:64736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hVhJHADqs2gAgBs-xBgAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:34.862563 2026] [security2:error] [pid 110058:tid 110170] [remote 120.72.98.5:24490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hVhJHADqs2gAgBs-xEgAA1m4"]
[Mon Jul 20 07:23:34.895944 2026] [security2:error] [pid 110058:tid 110196] [client 50.116.65.227:52422] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hVhJHADqs2gAgBs-xFgAAAIw"]
[Mon Jul 20 07:23:34.905778 2026] [security2:error] [pid 110058:tid 110254] [client 50.116.65.227:52436] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hVhJHADqs2gAgBs-xFwAAAMY"]
[Mon Jul 20 07:23:35.226434 2026] [security2:error] [pid 110058:tid 110269] [client 57.141.18.71:29840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hVRJHADqs2gAgBs-wdQAA1Ug"]
[Mon Jul 20 07:23:35.290021 2026] [security2:error] [pid 110058:tid 110286] [client 103.176.215.66:52620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hVxJHADqs2gAgBs-xPQAAAOY"]
[Mon Jul 20 07:23:35.290141 2026] [security2:error] [pid 110058:tid 110286] [client 103.176.215.66:52620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hVxJHADqs2gAgBs-xPQAAAOY"]
[Mon Jul 20 07:23:35.314288 2026] [security2:error] [pid 110058:tid 110268] [client 14.225.17.146:52550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4hVhJHADqs2gAgBs-w5gAAANQ"], referer: http://claysharecon.com/backup
[Mon Jul 20 07:23:35.335689 2026] [security2:error] [pid 110058:tid 110082] [remote 120.72.98.5:24490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hVxJHADqs2gAgBs-xQgAAmxc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:23:35.431689 2026] [security2:error] [pid 110058:tid 110292] [client 36.93.152.155:60250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hVxJHADqs2gAgBs-xTwAAAOw"]
[Mon Jul 20 07:23:35.431857 2026] [security2:error] [pid 110058:tid 110292] [client 36.93.152.155:60250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hVxJHADqs2gAgBs-xTwAAAOw"]
[Mon Jul 20 07:23:35.468204 2026] [security2:error] [pid 110058:tid 110303] [client 14.225.17.146:50600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xLgAAAPc"], referer: http://mcg.homes/backup
[Mon Jul 20 07:23:35.478647 2026] [security2:error] [pid 110058:tid 110287] [client 50.116.65.227:52446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xNwAAAOc"]
[Mon Jul 20 07:23:35.500611 2026] [security2:error] [pid 110058:tid 110316] [client 14.225.17.146:52257] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xUAAAAQQ"], referer: http://dasmarque.com/backup
[Mon Jul 20 07:23:35.550241 2026] [security2:error] [pid 110058:tid 110115] [remote 45.90.123.233:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4hVxJHADqs2gAgBs-xYQAA-Dg"]
[Mon Jul 20 07:23:35.666137 2026] [security2:error] [pid 110058:tid 110257] [client 50.116.65.227:52462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xXAAAAMk"]
[Mon Jul 20 07:23:35.737376 2026] [security2:error] [pid 110058:tid 110209] [client 14.225.17.146:52500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4hVhJHADqs2gAgBs-w5QAAAJk"], referer: http://detroitcsc.com/backup
[Mon Jul 20 07:23:35.824764 2026] [security2:error] [pid 110058:tid 110226] [client 57.141.18.0:40278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hVRJHADqs2gAgBs-wqwAAqkw"]
[Mon Jul 20 07:23:36.024262 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hWBJHADqs2gAgBs-xhAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:36.024361 2026] [security2:error] [pid 110058:tid 110263] [client 77.110.127.138:64731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hWBJHADqs2gAgBs-xhAAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:36.151481 2026] [security2:error] [pid 110058:tid 110191] [client 157.20.138.62:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xjAAAAIc"]
[Mon Jul 20 07:23:36.151643 2026] [security2:error] [pid 110058:tid 110191] [client 157.20.138.62:65038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xjAAAAIc"]
[Mon Jul 20 07:23:36.155138 2026] [security2:error] [pid 110058:tid 110207] [client 104.234.53.92:49503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hWBJHADqs2gAgBs-xjQAAAJc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:36.260537 2026] [security2:error] [pid 110058:tid 110196] [client 143.44.185.218:30837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xlwAAAIw"]
[Mon Jul 20 07:23:36.261777 2026] [security2:error] [pid 110058:tid 110196] [client 143.44.185.218:30837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xlwAAAIw"]
[Mon Jul 20 07:23:36.285295 2026] [security2:error] [pid 110058:tid 110200] [client 191.202.66.27:64846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xmAAAAJA"]
[Mon Jul 20 07:23:36.285460 2026] [security2:error] [pid 110058:tid 110200] [client 191.202.66.27:64846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xmAAAAJA"]
[Mon Jul 20 07:23:36.364602 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:52213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hWBJHADqs2gAgBs-xjgAAAME"], referer: http://mezzacraft.com/backup
[Mon Jul 20 07:23:36.478664 2026] [ssl:error] [pid 110058:tid 110267] [client 104.48.69.105:40136] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:23:36.649827 2026] [security2:error] [pid 110058:tid 110152] [remote 45.90.123.233:53644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4hWBJHADqs2gAgBs-xtQAAs1w"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 07:23:36.856737 2026] [security2:error] [pid 110058:tid 110281] [client 88.241.67.160:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xyAAAAOE"]
[Mon Jul 20 07:23:36.856969 2026] [security2:error] [pid 110058:tid 110281] [client 88.241.67.160:56417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-xyAAAAOE"]
[Mon Jul 20 07:23:36.877471 2026] [security2:error] [pid 110058:tid 110243] [client 14.225.17.146:52271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xLQAAALs"], referer: http://aandarealtygroup.com/backup
[Mon Jul 20 07:23:36.893626 2026] [security2:error] [pid 110058:tid 110075] [remote 8.217.108.67:16506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4hWBJHADqs2gAgBs-xygAA9RA"]
[Mon Jul 20 07:23:36.935492 2026] [security2:error] [pid 110058:tid 110242] [client 103.106.165.44:51342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-x0gAAALo"]
[Mon Jul 20 07:23:36.935625 2026] [security2:error] [pid 110058:tid 110242] [client 103.106.165.44:51342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hWBJHADqs2gAgBs-x0gAAALo"]
[Mon Jul 20 07:23:37.049023 2026] [security2:error] [pid 110058:tid 110218] [client 40.77.167.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xLAAAAKI"]
[Mon Jul 20 07:23:37.054102 2026] [security2:error] [pid 110058:tid 110244] [client 179.127.84.238:49746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hWRJHADqs2gAgBs-x3AAAALw"]
[Mon Jul 20 07:23:37.054199 2026] [security2:error] [pid 110058:tid 110244] [client 179.127.84.238:49746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hWRJHADqs2gAgBs-x3AAAALw"]
[Mon Jul 20 07:23:37.145185 2026] [security2:error] [pid 110058:tid 110279] [client 104.234.53.78:45821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hWRJHADqs2gAgBs-x4AAAAN8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:37.381967 2026] [security2:error] [pid 110058:tid 110073] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hWRJHADqs2gAgBs-x8wAAtw4"]
[Mon Jul 20 07:23:37.382143 2026] [security2:error] [pid 110058:tid 110239] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hWRJHADqs2gAgBs-x8wAAtw4"]
[Mon Jul 20 07:23:37.816889 2026] [security2:error] [pid 110058:tid 110283] [client 201.27.111.74:55049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hWRJHADqs2gAgBs-yFgAAAOM"]
[Mon Jul 20 07:23:37.817002 2026] [security2:error] [pid 110058:tid 110283] [client 201.27.111.74:55049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hWRJHADqs2gAgBs-yFgAAAOM"]
[Mon Jul 20 07:23:38.016431 2026] [security2:error] [pid 110058:tid 110311] [client 57.141.18.20:52150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hVxJHADqs2gAgBs-xbwAA_wo"]
[Mon Jul 20 07:23:38.167113 2026] [ssl:error] [pid 110058:tid 110307] [client 104.48.69.105:42454] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:23:38.270964 2026] [security2:error] [pid 110058:tid 110235] [client 77.110.127.138:64737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hWhJHADqs2gAgBs-yRgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:38.271134 2026] [security2:error] [pid 110058:tid 110235] [client 77.110.127.138:64737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hWhJHADqs2gAgBs-yRgAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:38.313528 2026] [security2:error] [pid 110058:tid 110259] [client 104.234.53.55:23399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hWhJHADqs2gAgBs-ySAAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:38.478550 2026] [security2:error] [pid 110058:tid 110270] [client 57.141.18.38:28454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hWBJHADqs2gAgBs-xlgAA1kI"]
[Mon Jul 20 07:23:38.592225 2026] [security2:error] [pid 110058:tid 110224] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "coachpops.org"] [uri "/.well-known/about.php"] [unique_id "al4hWhJHADqs2gAgBs-yZgAAAKg"]
[Mon Jul 20 07:23:38.592330 2026] [security2:error] [pid 110058:tid 110224] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "coachpops.org"] [uri "/.well-known/about.php"] [unique_id "al4hWhJHADqs2gAgBs-yZgAAAKg"]
[Mon Jul 20 07:23:38.815523 2026] [security2:error] [pid 110058:tid 110309] [client 154.208.48.130:50922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hWhJHADqs2gAgBs-ydwAAAP0"]
[Mon Jul 20 07:23:38.815638 2026] [security2:error] [pid 110058:tid 110309] [client 154.208.48.130:50922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hWhJHADqs2gAgBs-ydwAAAP0"]
[Mon Jul 20 07:23:38.907635 2026] [security2:error] [pid 110058:tid 110256] [client 57.141.18.8:62272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hWBJHADqs2gAgBs-xuQAAyBY"]
[Mon Jul 20 07:23:38.979025 2026] [security2:error] [pid 110058:tid 110192] [client 154.192.123.127:17782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hWhJHADqs2gAgBs-yhgAAAIg"]
[Mon Jul 20 07:23:38.979131 2026] [security2:error] [pid 110058:tid 110192] [client 154.192.123.127:17782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hWhJHADqs2gAgBs-yhgAAAIg"]
[Mon Jul 20 07:23:39.338350 2026] [security2:error] [pid 110058:tid 110132] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hWxJHADqs2gAgBs-yngAA8Eg"]
[Mon Jul 20 07:23:39.338585 2026] [security2:error] [pid 110058:tid 110296] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hWxJHADqs2gAgBs-yngAA8Eg"]
[Mon Jul 20 07:23:39.554355 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hWxJHADqs2gAgBs-ytgAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:39.554457 2026] [security2:error] [pid 110058:tid 110241] [client 77.110.127.138:64751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hWxJHADqs2gAgBs-ytgAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:39.583954 2026] [security2:error] [pid 110058:tid 110209] [client 57.141.18.12:58024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hWRJHADqs2gAgBs-x5wAAmXY"]
[Mon Jul 20 07:23:39.710711 2026] [security2:error] [pid 110058:tid 110238] [client 14.225.17.146:60259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4hWhJHADqs2gAgBs-yOAAAALY"], referer: http://vinovinhowine.com/backup
[Mon Jul 20 07:23:40.234169 2026] [security2:error] [pid 110058:tid 110213] [client 49.37.242.14:65261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hXBJHADqs2gAgBs-y8wAAAJ0"]
[Mon Jul 20 07:23:40.234300 2026] [security2:error] [pid 110058:tid 110213] [client 49.37.242.14:65261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hXBJHADqs2gAgBs-y8wAAAJ0"]
[Mon Jul 20 07:23:40.557712 2026] [security2:error] [pid 110058:tid 110125] [remote 8.217.108.67:16506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4hXBJHADqs2gAgBs-zDgAAq0E"], referer: https://ncsynchro.com/wp-login.php
[Mon Jul 20 07:23:40.709654 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hXBJHADqs2gAgBs-zFgAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:40.709773 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hXBJHADqs2gAgBs-zFgAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:40.785926 2026] [core:error] [pid 110058:tid 110216] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:40.785959 2026] [core:error] [pid 110058:tid 110216] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:41.181230 2026] [security2:error] [pid 110058:tid 110073] [remote 20.153.140.50:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hXRJHADqs2gAgBs-zQQAAlg4"]
[Mon Jul 20 07:23:41.311811 2026] [security2:error] [pid 110058:tid 110100] [remote 100.42.189.89:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hXRJHADqs2gAgBs-zUgAA3Sk"]
[Mon Jul 20 07:23:41.426011 2026] [security2:error] [pid 110058:tid 110275] [client 57.141.18.88:21160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hWxJHADqs2gAgBs-yjwAA2zM"]
[Mon Jul 20 07:23:41.503483 2026] [security2:error] [pid 110058:tid 110299] [client 34.147.22.160:49152] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "rootedandwholecoaching.com.heidimortenson.com"] [uri "/"] [unique_id "al4hXRJHADqs2gAgBs-zXwAAAPM"]
[Mon Jul 20 07:23:41.503563 2026] [security2:error] [pid 110058:tid 110299] [client 34.147.22.160:49152] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "rootedandwholecoaching.com.heidimortenson.com"] [uri "/"] [unique_id "al4hXRJHADqs2gAgBs-zXwAAAPM"]
[Mon Jul 20 07:23:41.522446 2026] [security2:error] [pid 110058:tid 110116] [remote 100.42.189.89:56340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hXRJHADqs2gAgBs-zYwAA8jk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:23:41.571153 2026] [security2:error] [pid 110058:tid 110180] [remote 20.153.140.50:58672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hXRJHADqs2gAgBs-zZwAAzHg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:23:41.667036 2026] [security2:error] [pid 110058:tid 110205] [client 77.110.127.138:64749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hXRJHADqs2gAgBs-zcAAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:41.667128 2026] [security2:error] [pid 110058:tid 110205] [client 77.110.127.138:64749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hXRJHADqs2gAgBs-zcAAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:41.865814 2026] [security2:error] [pid 110058:tid 110263] [client 113.160.97.242:58041] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4hXRJHADqs2gAgBs-zfAAAAM8"]
[Mon Jul 20 07:23:42.032552 2026] [security2:error] [pid 110058:tid 110257] [client 57.141.18.108:21908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hWxJHADqs2gAgBs-yvgAAyQU"]
[Mon Jul 20 07:23:42.738770 2026] [security2:error] [pid 110058:tid 110157] [remote 192.241.143.148:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hXhJHADqs2gAgBs-zxAAAnWE"]
[Mon Jul 20 07:23:42.920985 2026] [security2:error] [pid 110058:tid 110090] [remote 192.241.143.148:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hXhJHADqs2gAgBs-z1AAA8x8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:23:43.047337 2026] [security2:error] [pid 110058:tid 110060] [remote 113.160.142.119:55096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4hXxJHADqs2gAgBs-z4QAAowE"]
[Mon Jul 20 07:23:43.177090 2026] [security2:error] [pid 110058:tid 110181] [remote 8.217.108.67:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hXxJHADqs2gAgBs-z7AAAp3k"]
[Mon Jul 20 07:23:43.264321 2026] [security2:error] [pid 110058:tid 110280] [client 202.141.11.99:24349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hXxJHADqs2gAgBs-z8gAAAOA"]
[Mon Jul 20 07:23:43.264436 2026] [security2:error] [pid 110058:tid 110280] [client 202.141.11.99:24349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hXxJHADqs2gAgBs-z8gAAAOA"]
[Mon Jul 20 07:23:43.286705 2026] [security2:error] [pid 110058:tid 110270] [client 77.110.127.138:64738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hXxJHADqs2gAgBs-z9wAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:43.286856 2026] [security2:error] [pid 110058:tid 110270] [client 77.110.127.138:64738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hXxJHADqs2gAgBs-z9wAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:43.310409 2026] [security2:error] [pid 110058:tid 110243] [client 57.141.18.121:47342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hXBJHADqs2gAgBs-zJgAAuyM"]
[Mon Jul 20 07:23:43.345461 2026] [security2:error] [pid 110058:tid 110195] [client 57.141.18.118:53722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hXBJHADqs2gAgBs-zLAAAixk"]
[Mon Jul 20 07:23:43.463614 2026] [security2:error] [pid 110058:tid 110205] [client 136.158.60.21:11998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hXxJHADqs2gAgBs-0DgAAAJU"]
[Mon Jul 20 07:23:43.463769 2026] [security2:error] [pid 110058:tid 110205] [client 136.158.60.21:11998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hXxJHADqs2gAgBs-0DgAAAJU"]
[Mon Jul 20 07:23:43.543429 2026] [security2:error] [pid 110058:tid 110149] [remote 113.160.142.119:55096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4hXxJHADqs2gAgBs-0FgAAwVk"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:23:43.687961 2026] [security2:error] [pid 110058:tid 110141] [remote 8.217.108.67:56030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hXxJHADqs2gAgBs-0HwAA4FE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:23:43.924585 2026] [security2:error] [pid 110058:tid 110218] [client 14.225.17.146:51767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4hXxJHADqs2gAgBs-0JgAAAKI"], referer: http://backandneckpainrelieflaceychiropractor.com/backup
[Mon Jul 20 07:23:44.911049 2026] [security2:error] [pid 110058:tid 110210] [client 14.225.17.146:57628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4hXxJHADqs2gAgBs-0DQAAAJo"], referer: http://kromosenergy.com/backup
[Mon Jul 20 07:23:44.917172 2026] [security2:error] [pid 110058:tid 110314] [client 57.141.18.111:45668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hXhJHADqs2gAgBs-znAABAnw"]
[Mon Jul 20 07:23:44.933980 2026] [security2:error] [pid 110058:tid 110268] [client 77.110.127.138:64798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hYBJHADqs2gAgBs-0pgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:44.934093 2026] [security2:error] [pid 110058:tid 110268] [client 77.110.127.138:64798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hYBJHADqs2gAgBs-0pgAAANQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:45.014234 2026] [security2:error] [pid 110058:tid 110316] [client 49.47.218.174:64748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-0rQAAAQQ"]
[Mon Jul 20 07:23:45.014402 2026] [security2:error] [pid 110058:tid 110316] [client 49.47.218.174:64748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-0rQAAAQQ"]
[Mon Jul 20 07:23:45.109608 2026] [security2:error] [pid 110058:tid 110259] [client 117.211.236.168:60526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-0ugAAAMs"]
[Mon Jul 20 07:23:45.109728 2026] [security2:error] [pid 110058:tid 110259] [client 117.211.236.168:60526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-0ugAAAMs"]
[Mon Jul 20 07:23:45.132764 2026] [security2:error] [pid 110058:tid 110137] [remote 152.228.213.32:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4hYRJHADqs2gAgBs-0uwAAjU0"]
[Mon Jul 20 07:23:45.140959 2026] [security2:error] [pid 110058:tid 110196] [client 14.225.17.146:57528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4hYRJHADqs2gAgBs-0rAAAAIw"]
[Mon Jul 20 07:23:45.157224 2026] [security2:error] [pid 110058:tid 110294] [client 57.141.18.46:32508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hXhJHADqs2gAgBs-zwwAA7iE"]
[Mon Jul 20 07:23:45.233953 2026] [security2:error] [pid 110058:tid 110194] [client 14.225.17.146:51747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4hXxJHADqs2gAgBs-0BwAAAIo"], referer: http://mobilesurvsolutions.com/backup
[Mon Jul 20 07:23:45.239953 2026] [security2:error] [pid 110058:tid 110240] [client 14.225.17.146:57552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4hXxJHADqs2gAgBs-0CwAAALg"], referer: http://fluidtemple.org/backup
[Mon Jul 20 07:23:45.264493 2026] [security2:error] [pid 110058:tid 110203] [client 14.225.17.146:57623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4hYRJHADqs2gAgBs-0tgAAAJM"], referer: http://ghivs.com/backup
[Mon Jul 20 07:23:45.346644 2026] [security2:error] [pid 110058:tid 110099] [remote 152.228.213.32:35136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4hYRJHADqs2gAgBs-00AAA4Sg"], referer: https://superiorcopywriting.com/wp-login.php
[Mon Jul 20 07:23:45.844884 2026] [security2:error] [pid 110058:tid 110256] [client 103.176.215.66:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-1CAAAAMg"]
[Mon Jul 20 07:23:45.844979 2026] [security2:error] [pid 110058:tid 110256] [client 103.176.215.66:53162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-1CAAAAMg"]
[Mon Jul 20 07:23:45.909258 2026] [security2:error] [pid 110058:tid 110200] [client 36.93.152.155:60755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-1DQAAAJA"]
[Mon Jul 20 07:23:45.909346 2026] [security2:error] [pid 110058:tid 110200] [client 36.93.152.155:60755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hYRJHADqs2gAgBs-1DQAAAJA"]
[Mon Jul 20 07:23:46.032855 2026] [security2:error] [pid 110058:tid 110247] [client 23.180.120.147:40802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "mail.secretkeynumerology.com"] [uri "/"] [unique_id "al4hYhJHADqs2gAgBs-1IAAAAL8"]
[Mon Jul 20 07:23:46.090534 2026] [security2:error] [pid 110058:tid 110154] [remote 173.212.252.15:37202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hYhJHADqs2gAgBs-1IgAA7F4"]
[Mon Jul 20 07:23:46.090719 2026] [security2:error] [pid 110058:tid 110292] [client 173.212.252.15:37202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hYhJHADqs2gAgBs-1IgAA7F4"]
[Mon Jul 20 07:23:46.399597 2026] [security2:error] [pid 110058:tid 110249] [client 57.141.18.68:45250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hXxJHADqs2gAgBs-0OQAAwWQ"]
[Mon Jul 20 07:23:46.414638 2026] [security2:error] [pid 110058:tid 110274] [client 14.225.17.146:58133] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4hYRJHADqs2gAgBs-1GAAAANo"]
[Mon Jul 20 07:23:46.549423 2026] [core:error] [pid 110058:tid 110222] [client 144.172.114.51:41934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:46.549455 2026] [core:error] [pid 110058:tid 110222] [client 144.172.114.51:41934] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:46.568576 2026] [security2:error] [pid 110058:tid 110210] [client 23.180.120.147:40812] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "mail.secretkeynumerology.com"] [uri "/wp-json/batch/v1"] [unique_id "al4hYhJHADqs2gAgBs-1SwAAAJo"]
[Mon Jul 20 07:23:46.625189 2026] [security2:error] [pid 110058:tid 110224] [client 98.159.234.160:23053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hYhJHADqs2gAgBs-1UwAAAKg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:46.702307 2026] [security2:error] [pid 110058:tid 110311] [client 104.234.53.70:56987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hYhJHADqs2gAgBs-1VwAAAP8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:46.862199 2026] [security2:error] [pid 110058:tid 110242] [client 191.202.66.27:65324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hYhJHADqs2gAgBs-1XgAAALo"]
[Mon Jul 20 07:23:46.862329 2026] [security2:error] [pid 110058:tid 110242] [client 191.202.66.27:65324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hYhJHADqs2gAgBs-1XgAAALo"]
[Mon Jul 20 07:23:46.981578 2026] [security2:error] [pid 110058:tid 110200] [client 157.20.138.62:49227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hYhJHADqs2gAgBs-1agAAAJA"]
[Mon Jul 20 07:23:46.982816 2026] [security2:error] [pid 110058:tid 110200] [client 157.20.138.62:49227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hYhJHADqs2gAgBs-1agAAAJA"]
[Mon Jul 20 07:23:47.152084 2026] [security2:error] [pid 110058:tid 110238] [client 20.220.9.199:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.9.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wesmclucas.com"] [uri "/.well-known/about.php"] [unique_id "al4hYxJHADqs2gAgBs-1gAAAALY"]
[Mon Jul 20 07:23:47.152193 2026] [security2:error] [pid 110058:tid 110238] [client 20.220.9.199:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "wesmclucas.com"] [uri "/.well-known/about.php"] [unique_id "al4hYxJHADqs2gAgBs-1gAAAALY"]
[Mon Jul 20 07:23:47.218055 2026] [security2:error] [pid 110058:tid 110256] [client 77.110.127.138:64812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hYxJHADqs2gAgBs-1hAAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:47.218188 2026] [security2:error] [pid 110058:tid 110256] [client 77.110.127.138:64812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hYxJHADqs2gAgBs-1hAAAAMg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:47.397571 2026] [security2:error] [pid 110058:tid 110272] [client 57.141.18.33:30788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hYBJHADqs2gAgBs-0qAAA2CA"]
[Mon Jul 20 07:23:47.444902 2026] [security2:error] [pid 110058:tid 110290] [client 103.106.165.44:51812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1lAAAAOo"]
[Mon Jul 20 07:23:47.445049 2026] [security2:error] [pid 110058:tid 110290] [client 103.106.165.44:51812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1lAAAAOo"]
[Mon Jul 20 07:23:47.506530 2026] [security2:error] [pid 110058:tid 110227] [client 88.241.67.160:53794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1mwAAAKs"]
[Mon Jul 20 07:23:47.507616 2026] [security2:error] [pid 110058:tid 110227] [client 88.241.67.160:53794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1mwAAAKs"]
[Mon Jul 20 07:23:47.571764 2026] [security2:error] [pid 110058:tid 110247] [client 50.116.65.227:16546] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hYxJHADqs2gAgBs-1oQAAAL8"]
[Mon Jul 20 07:23:47.581895 2026] [security2:error] [pid 110058:tid 110238] [client 50.116.65.227:16548] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hYxJHADqs2gAgBs-1owAAALY"]
[Mon Jul 20 07:23:47.666650 2026] [security2:error] [pid 110058:tid 110127] [remote 162.19.86.63:53394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1rQAAm0M"]
[Mon Jul 20 07:23:47.666777 2026] [security2:error] [pid 110058:tid 110211] [client 162.19.86.63:53394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1rQAAm0M"]
[Mon Jul 20 07:23:47.675878 2026] [security2:error] [pid 110058:tid 110235] [client 179.127.84.238:50220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1rgAAALM"]
[Mon Jul 20 07:23:47.676083 2026] [security2:error] [pid 110058:tid 110235] [client 179.127.84.238:50220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hYxJHADqs2gAgBs-1rgAAALM"]
[Mon Jul 20 07:23:48.195639 2026] [security2:error] [pid 110058:tid 110134] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hZBJHADqs2gAgBs-1xwAAsko"]
[Mon Jul 20 07:23:48.195803 2026] [security2:error] [pid 110058:tid 110234] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hZBJHADqs2gAgBs-1xwAAsko"]
[Mon Jul 20 07:23:48.261139 2026] [security2:error] [pid 110058:tid 110281] [client 77.110.127.138:64805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZBJHADqs2gAgBs-1ywAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:48.261245 2026] [security2:error] [pid 110058:tid 110281] [client 77.110.127.138:64805] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZBJHADqs2gAgBs-1ywAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:48.458797 2026] [security2:error] [pid 110058:tid 110224] [client 201.27.111.74:55553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hZBJHADqs2gAgBs-13wAAAKg"]
[Mon Jul 20 07:23:48.458897 2026] [security2:error] [pid 110058:tid 110224] [client 201.27.111.74:55553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hZBJHADqs2gAgBs-13wAAAKg"]
[Mon Jul 20 07:23:48.946951 2026] [security2:error] [pid 110058:tid 110239] [client 77.110.127.138:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZBJHADqs2gAgBs-2CQAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:48.947055 2026] [security2:error] [pid 110058:tid 110239] [client 77.110.127.138:64811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZBJHADqs2gAgBs-2CQAAALc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:48.998300 2026] [security2:error] [pid 110058:tid 110307] [client 77.110.127.138:64801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZBJHADqs2gAgBs-2DAAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:48.998412 2026] [security2:error] [pid 110058:tid 110307] [client 77.110.127.138:64801] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZBJHADqs2gAgBs-2DAAAAPs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:49.539490 2026] [security2:error] [pid 110058:tid 110278] [client 154.192.123.127:18283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hZRJHADqs2gAgBs-2MAAAAN4"]
[Mon Jul 20 07:23:49.539586 2026] [security2:error] [pid 110058:tid 110278] [client 154.192.123.127:18283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hZRJHADqs2gAgBs-2MAAAAN4"]
[Mon Jul 20 07:23:49.568890 2026] [security2:error] [pid 110058:tid 110262] [client 143.44.185.218:32289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hZRJHADqs2gAgBs-2NAAAAM4"]
[Mon Jul 20 07:23:49.569024 2026] [security2:error] [pid 110058:tid 110262] [client 143.44.185.218:32289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hZRJHADqs2gAgBs-2NAAAAM4"]
[Mon Jul 20 07:23:49.865603 2026] [security2:error] [pid 110058:tid 110185] [remote 18.61.192.253:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hZRJHADqs2gAgBs-2SQAAmH0"]
[Mon Jul 20 07:23:49.900417 2026] [security2:error] [pid 110058:tid 110227] [client 14.225.17.146:55924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4hZRJHADqs2gAgBs-2QQAAAKs"], referer: http://sesamegreenbeans.com/backup
[Mon Jul 20 07:23:50.020058 2026] [security2:error] [pid 110058:tid 110168] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hZhJHADqs2gAgBs-2XAAA5Ww"]
[Mon Jul 20 07:23:50.020220 2026] [security2:error] [pid 110058:tid 110285] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hZhJHADqs2gAgBs-2XAAA5Ww"]
[Mon Jul 20 07:23:50.068867 2026] [security2:error] [pid 110058:tid 110248] [client 154.208.48.130:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hZhJHADqs2gAgBs-2YAAAAMA"]
[Mon Jul 20 07:23:50.069015 2026] [security2:error] [pid 110058:tid 110248] [client 154.208.48.130:51450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hZhJHADqs2gAgBs-2YAAAAMA"]
[Mon Jul 20 07:23:50.104517 2026] [security2:error] [pid 110058:tid 110232] [client 168.199.101.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hZRJHADqs2gAgBs-2UQAAALA"]
[Mon Jul 20 07:23:50.233155 2026] [security2:error] [pid 110058:tid 110276] [client 77.110.127.138:64832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZhJHADqs2gAgBs-2eQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:50.233225 2026] [security2:error] [pid 110058:tid 110276] [client 77.110.127.138:64832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZhJHADqs2gAgBs-2eQAAANw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:50.283148 2026] [security2:error] [pid 110058:tid 110298] [client 77.110.127.138:64808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZhJHADqs2gAgBs-2fQAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:50.283261 2026] [security2:error] [pid 110058:tid 110298] [client 77.110.127.138:64808] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hZhJHADqs2gAgBs-2fQAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:50.337831 2026] [security2:error] [pid 110058:tid 110061] [remote 18.61.192.253:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hZhJHADqs2gAgBs-2gQAAyQI"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 07:23:50.585284 2026] [security2:error] [pid 110058:tid 110247] [client 57.141.18.83:41992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hZBJHADqs2gAgBs-1xgAAvws"]
[Mon Jul 20 07:23:50.941096 2026] [security2:error] [pid 110058:tid 110277] [client 14.225.17.146:57822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4hZhJHADqs2gAgBs-2pAAAAN0"], referer: https://sesamegreenbeans.com/backup
[Mon Jul 20 07:23:51.500777 2026] [security2:error] [pid 110058:tid 110252] [client 57.141.18.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hZxJHADqs2gAgBs-2zgAAAMQ"]
[Mon Jul 20 07:23:51.572541 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:55804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4hZhJHADqs2gAgBs-2fwAAAME"], referer: http://cloudspacesgroup.com/backup
[Mon Jul 20 07:23:51.779728 2026] [security2:error] [pid 110058:tid 110222] [client 14.225.17.146:57808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4hZxJHADqs2gAgBs-22wAAAKY"], referer: http://laceycaraccident.com/backup
[Mon Jul 20 07:23:51.912767 2026] [security2:error] [pid 110058:tid 110211] [client 45.157.112.60:56575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hZxJHADqs2gAgBs-29wAAAJs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:52.035565 2026] [security2:error] [pid 110058:tid 110229] [client 57.141.18.81:63608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hZRJHADqs2gAgBs-2HAAArTU"]
[Mon Jul 20 07:23:52.226317 2026] [security2:error] [pid 110058:tid 110206] [client 103.168.67.159:7930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/var/run/secrets/kubernetes.io/serviceaccount/token%00.php"] [unique_id "al4haBJHADqs2gAgBs-3GgAAAJY"], referer: https://www.google.com/
[Mon Jul 20 07:23:52.352450 2026] [security2:error] [pid 110058:tid 110272] [client 14.225.17.146:58033] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4haBJHADqs2gAgBs-3IAAAANg"], referer: http://travelbyfire.com/backup
[Mon Jul 20 07:23:52.639264 2026] [security2:error] [pid 110058:tid 110184] [remote 81.173.115.7:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4haBJHADqs2gAgBs-3OAAA23w"]
[Mon Jul 20 07:23:52.805803 2026] [security2:error] [pid 110058:tid 110278] [client 57.141.18.98:62978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hZRJHADqs2gAgBs-2VQAA3h8"]
[Mon Jul 20 07:23:52.823399 2026] [security2:error] [pid 110058:tid 110255] [client 14.225.17.146:57912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4hZxJHADqs2gAgBs-29QAAAMc"], referer: http://entuvy.com/backup
[Mon Jul 20 07:23:52.850947 2026] [security2:error] [pid 110058:tid 110111] [remote 81.173.115.7:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/wp-login.php"] [unique_id "al4haBJHADqs2gAgBs-3RwAAvzQ"], referer: https://uninursity.com/wp-login.php
[Mon Jul 20 07:23:53.097157 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4haRJHADqs2gAgBs-3XwAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:53.097247 2026] [security2:error] [pid 110058:tid 110249] [client 77.110.127.138:64860] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4haRJHADqs2gAgBs-3XwAAAME"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:53.151073 2026] [security2:error] [pid 110058:tid 110271] [client 77.110.127.138:64800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4haRJHADqs2gAgBs-3YgAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:53.151203 2026] [security2:error] [pid 110058:tid 110271] [client 77.110.127.138:64800] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4haRJHADqs2gAgBs-3YgAAANc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:53.220778 2026] [core:error] [pid 110058:tid 110220] [client 14.225.17.146:60614] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/backup
[Mon Jul 20 07:23:53.220798 2026] [core:error] [pid 110058:tid 110220] [client 14.225.17.146:60614] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/backup
[Mon Jul 20 07:23:53.248149 2026] [security2:error] [pid 110058:tid 110244] [client 14.225.17.146:60612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4haRJHADqs2gAgBs-3bAAAALw"], referer: https://travelbyfire.com/backup
[Mon Jul 20 07:23:53.685330 2026] [core:error] [pid 110058:tid 110207] [client 144.172.114.51:48468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:53.685349 2026] [core:error] [pid 110058:tid 110207] [client 144.172.114.51:48468] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:53.739321 2026] [security2:error] [pid 110058:tid 110198] [client 57.141.18.48:27680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hZhJHADqs2gAgBs-2oAAAjgg"]
[Mon Jul 20 07:23:53.787350 2026] [security2:error] [pid 110058:tid 110081] [remote 188.166.241.141:50822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4haRJHADqs2gAgBs-3nAAArRY"]
[Mon Jul 20 07:23:53.884145 2026] [security2:error] [pid 110058:tid 110278] [client 57.141.18.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4haRJHADqs2gAgBs-3mgAAAN4"]
[Mon Jul 20 07:23:53.964063 2026] [security2:error] [pid 110058:tid 110226] [client 57.141.18.95:51690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hZxJHADqs2gAgBs-2uwAAqkE"]
[Mon Jul 20 07:23:53.987300 2026] [security2:error] [pid 110058:tid 110249] [client 14.225.17.146:59296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4haRJHADqs2gAgBs-3oQAAAME"], referer: http://mazzucelli.com/backup
[Mon Jul 20 07:23:54.119417 2026] [security2:error] [pid 110058:tid 110301] [client 49.37.242.14:49428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hahJHADqs2gAgBs-3twAAAPU"]
[Mon Jul 20 07:23:54.119513 2026] [security2:error] [pid 110058:tid 110301] [client 49.37.242.14:49428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hahJHADqs2gAgBs-3twAAAPU"]
[Mon Jul 20 07:23:54.159377 2026] [security2:error] [pid 110058:tid 110255] [client 136.158.60.21:13605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hahJHADqs2gAgBs-3ugAAAMc"]
[Mon Jul 20 07:23:54.159473 2026] [security2:error] [pid 110058:tid 110255] [client 136.158.60.21:13605] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hahJHADqs2gAgBs-3ugAAAMc"]
[Mon Jul 20 07:23:54.259851 2026] [security2:error] [pid 110058:tid 110160] [remote 188.166.241.141:50822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-3vwAAu2Q"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:23:54.683380 2026] [security2:error] [pid 110058:tid 110298] [client 104.234.53.74:26013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-33gAAAPI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:54.715692 2026] [security2:error] [pid 110058:tid 110083] [remote 152.228.213.32:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-33wAAqhg"]
[Mon Jul 20 07:23:54.734040 2026] [security2:error] [pid 110058:tid 110136] [remote 91.212.174.124:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.174.212.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-34QAAoUw"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:23:54.786640 2026] [security2:error] [pid 110058:tid 110270] [client 193.37.33.30:33167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-35wAAANY"]
[Mon Jul 20 07:23:54.789375 2026] [security2:error] [pid 110058:tid 110303] [client 57.141.18.6:28398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4haBJHADqs2gAgBs-2_QAA9xU"]
[Mon Jul 20 07:23:54.833004 2026] [security2:error] [pid 110058:tid 110239] [client 193.37.33.51:58807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-36gAAALc"]
[Mon Jul 20 07:23:54.908592 2026] [security2:error] [pid 110058:tid 110165] [remote 152.228.213.32:58900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4hahJHADqs2gAgBs-3-QAAjWk"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:23:55.220326 2026] [security2:error] [pid 110058:tid 110148] [remote 57.141.18.94:59730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3313804"] [unique_id "al4haxJHADqs2gAgBs-4EgAAkVg"]
[Mon Jul 20 07:23:55.304357 2026] [security2:error] [pid 110058:tid 110091] [remote 157.66.26.183:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4haxJHADqs2gAgBs-4HAAAySA"]
[Mon Jul 20 07:23:55.341099 2026] [security2:error] [pid 110058:tid 110102] [remote 91.212.174.124:56606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.174.212.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4haxJHADqs2gAgBs-4IgAA4is"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:23:55.386138 2026] [security2:error] [pid 110058:tid 110228] [client 57.141.18.90:40282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4haBJHADqs2gAgBs-3OQAArDs"]
[Mon Jul 20 07:23:55.506098 2026] [security2:error] [pid 110058:tid 110276] [client 49.47.218.174:65382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4haxJHADqs2gAgBs-4NgAAANw"]
[Mon Jul 20 07:23:55.506259 2026] [security2:error] [pid 110058:tid 110276] [client 49.47.218.174:65382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4haxJHADqs2gAgBs-4NgAAANw"]
[Mon Jul 20 07:23:55.544401 2026] [security2:error] [pid 110058:tid 110302] [client 57.141.18.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4haxJHADqs2gAgBs-4KwAAAPY"]
[Mon Jul 20 07:23:55.628320 2026] [security2:error] [pid 110058:tid 110203] [client 14.225.17.146:59086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4haxJHADqs2gAgBs-4MgAAAJM"], referer: http://bbwipartnerconference.com/backup
[Mon Jul 20 07:23:55.715568 2026] [security2:error] [pid 110058:tid 110075] [remote 157.66.26.183:47232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.26.66.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4haxJHADqs2gAgBs-4RQAAyRA"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 07:23:55.837097 2026] [security2:error] [pid 110058:tid 110218] [client 57.141.18.71:29520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4haRJHADqs2gAgBs-3WwAAoiI"]
[Mon Jul 20 07:23:56.109884 2026] [security2:error] [pid 110058:tid 110251] [client 57.141.18.120:50222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4haRJHADqs2gAgBs-3eQAAw1c"]
[Mon Jul 20 07:23:56.447816 2026] [security2:error] [pid 110058:tid 110275] [client 103.176.215.66:53699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hbBJHADqs2gAgBs-4hAAAANs"]
[Mon Jul 20 07:23:56.448161 2026] [security2:error] [pid 110058:tid 110275] [client 103.176.215.66:53699] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hbBJHADqs2gAgBs-4hAAAANs"]
[Mon Jul 20 07:23:56.455963 2026] [security2:error] [pid 110058:tid 110304] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4hbBJHADqs2gAgBs-4hgAAAPg"]
[Mon Jul 20 07:23:56.474246 2026] [security2:error] [pid 110058:tid 110301] [client 36.93.152.155:61260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hbBJHADqs2gAgBs-4iwAAAPU"]
[Mon Jul 20 07:23:56.474325 2026] [security2:error] [pid 110058:tid 110301] [client 36.93.152.155:61260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hbBJHADqs2gAgBs-4iwAAAPU"]
[Mon Jul 20 07:23:56.563502 2026] [security2:error] [pid 110058:tid 110251] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4hbBJHADqs2gAgBs-4lAAAAMM"]
[Mon Jul 20 07:23:56.627125 2026] [security2:error] [pid 110058:tid 110242] [client 117.211.236.168:61090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hbBJHADqs2gAgBs-4lwAAALo"]
[Mon Jul 20 07:23:56.627216 2026] [security2:error] [pid 110058:tid 110242] [client 117.211.236.168:61090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hbBJHADqs2gAgBs-4lwAAALo"]
[Mon Jul 20 07:23:56.643523 2026] [security2:error] [pid 110058:tid 110310] [client 158.173.89.95:30985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hbBJHADqs2gAgBs-4mQAAAP4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:23:56.665511 2026] [security2:error] [pid 110058:tid 110211] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4hbBJHADqs2gAgBs-4mgAAAJs"]
[Mon Jul 20 07:23:56.771114 2026] [security2:error] [pid 110058:tid 110256] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4hbBJHADqs2gAgBs-4owAAAMg"]
[Mon Jul 20 07:23:56.932451 2026] [security2:error] [pid 110058:tid 110313] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4hbBJHADqs2gAgBs-4uQAAAQE"]
[Mon Jul 20 07:23:57.033095 2026] [security2:error] [pid 110058:tid 110267] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4hbRJHADqs2gAgBs-4wgAAANM"]
[Mon Jul 20 07:23:57.057515 2026] [security2:error] [pid 110058:tid 110170] [remote 173.249.4.11:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hbRJHADqs2gAgBs-4xAAA824"]
[Mon Jul 20 07:23:57.122112 2026] [security2:error] [pid 110058:tid 110209] [client 14.225.17.146:56185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4hbBJHADqs2gAgBs-4qQAAAJk"], referer: http://healthylifegourmet.org/backup
[Mon Jul 20 07:23:57.147258 2026] [security2:error] [pid 110058:tid 110301] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4hbRJHADqs2gAgBs-4ywAAAPU"]
[Mon Jul 20 07:23:57.243303 2026] [security2:error] [pid 110058:tid 110123] [remote 173.249.4.11:49050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hbRJHADqs2gAgBs-41QAA9z8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:23:57.254816 2026] [security2:error] [pid 110058:tid 110212] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4hbRJHADqs2gAgBs-42wAAAJw"]
[Mon Jul 20 07:23:57.355741 2026] [security2:error] [pid 110058:tid 110276] [client 104.28.214.112:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "undefeatedthe.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4hbRJHADqs2gAgBs-44wAAANw"]
[Mon Jul 20 07:23:57.397234 2026] [core:error] [pid 110058:tid 110267] [client 144.172.114.51:48476] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:57.397260 2026] [core:error] [pid 110058:tid 110267] [client 144.172.114.51:48476] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:23:57.580358 2026] [security2:error] [pid 110058:tid 110290] [client 191.202.66.27:49455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hbRJHADqs2gAgBs-5AQAAAOo"]
[Mon Jul 20 07:23:57.580462 2026] [security2:error] [pid 110058:tid 110290] [client 191.202.66.27:49455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hbRJHADqs2gAgBs-5AQAAAOo"]
[Mon Jul 20 07:23:57.637709 2026] [security2:error] [pid 110058:tid 110301] [client 14.225.17.146:59683] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4hbRJHADqs2gAgBs-4_wAAAPU"]
[Mon Jul 20 07:23:57.657982 2026] [security2:error] [pid 110058:tid 110228] [client 157.20.138.62:49806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hbRJHADqs2gAgBs-5DQAAAKw"]
[Mon Jul 20 07:23:57.658119 2026] [security2:error] [pid 110058:tid 110228] [client 157.20.138.62:49806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hbRJHADqs2gAgBs-5DQAAAKw"]
[Mon Jul 20 07:23:57.755194 2026] [security2:error] [pid 110058:tid 110277] [client 57.141.18.112:38832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4haxJHADqs2gAgBs-4DwAA3XA"]
[Mon Jul 20 07:23:58.043765 2026] [security2:error] [pid 110058:tid 110211] [client 103.106.165.44:52290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5KAAAAJs"]
[Mon Jul 20 07:23:58.043866 2026] [security2:error] [pid 110058:tid 110211] [client 103.106.165.44:52290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5KAAAAJs"]
[Mon Jul 20 07:23:58.105031 2026] [security2:error] [pid 110058:tid 110314] [client 88.241.67.160:56315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5MAAAAQI"]
[Mon Jul 20 07:23:58.105184 2026] [security2:error] [pid 110058:tid 110314] [client 88.241.67.160:56315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5MAAAAQI"]
[Mon Jul 20 07:23:58.123962 2026] [security2:error] [pid 110058:tid 110250] [client 57.141.18.60:29664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4haxJHADqs2gAgBs-4JwAAwg0"]
[Mon Jul 20 07:23:58.291087 2026] [security2:error] [pid 110058:tid 110296] [client 179.127.84.238:50709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5QAAAAPA"]
[Mon Jul 20 07:23:58.291198 2026] [security2:error] [pid 110058:tid 110296] [client 179.127.84.238:50709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5QAAAAPA"]
[Mon Jul 20 07:23:58.420005 2026] [security2:error] [pid 110058:tid 110061] [remote 158.180.33.171:42554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.33.180.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4hbhJHADqs2gAgBs-5RwAAqwI"]
[Mon Jul 20 07:23:58.809186 2026] [security2:error] [pid 110058:tid 110220] [client 52.140.101.203:27845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hbhJHADqs2gAgBs-5dgAAAKQ"]
[Mon Jul 20 07:23:58.816021 2026] [security2:error] [pid 110058:tid 110245] [client 201.27.111.74:56053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5eQAAAL0"]
[Mon Jul 20 07:23:58.816112 2026] [security2:error] [pid 110058:tid 110245] [client 201.27.111.74:56053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5eQAAAL0"]
[Mon Jul 20 07:23:58.876233 2026] [security2:error] [pid 110058:tid 110108] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5gQAA9DE"]
[Mon Jul 20 07:23:58.876412 2026] [security2:error] [pid 110058:tid 110300] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hbhJHADqs2gAgBs-5gQAA9DE"]
[Mon Jul 20 07:23:59.049707 2026] [security2:error] [pid 110058:tid 110102] [remote 158.180.33.171:42554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.33.180.158.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4hbxJHADqs2gAgBs-5jwAA7Cs"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 07:23:59.059802 2026] [security2:error] [pid 110058:tid 110251] [client 52.140.101.203:27845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hbxJHADqs2gAgBs-5lAAAAMM"]
[Mon Jul 20 07:23:59.060467 2026] [security2:error] [pid 110058:tid 110194] [client 77.110.127.138:64913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hbxJHADqs2gAgBs-5lQAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:59.060601 2026] [security2:error] [pid 110058:tid 110194] [client 77.110.127.138:64913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hbxJHADqs2gAgBs-5lQAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:59.107066 2026] [security2:error] [pid 110058:tid 110268] [client 104.234.53.87:64223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hbxJHADqs2gAgBs-5mgAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:23:59.110421 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hbxJHADqs2gAgBs-5nAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:59.110549 2026] [security2:error] [pid 110058:tid 110232] [client 77.110.127.138:64802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hbxJHADqs2gAgBs-5nAAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:23:59.242145 2026] [security2:error] [pid 110058:tid 110218] [client 52.233.165.60:20930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hbxJHADqs2gAgBs-5pgAAAKI"]
[Mon Jul 20 07:23:59.389104 2026] [security2:error] [pid 110058:tid 110290] [client 52.233.165.60:20930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hbxJHADqs2gAgBs-5sQAAAOo"]
[Mon Jul 20 07:23:59.803009 2026] [security2:error] [pid 110058:tid 110247] [client 57.141.18.25:56148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hbRJHADqs2gAgBs-4zAAAv1Y"]
[Mon Jul 20 07:23:59.813557 2026] [security2:error] [pid 110058:tid 110214] [client 57.141.18.120:50238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hbRJHADqs2gAgBs-4xwAAnms"]
[Mon Jul 20 07:24:00.333470 2026] [security2:error] [pid 110058:tid 110278] [client 14.225.17.146:59233] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4hbxJHADqs2gAgBs-53AAAAN4"], referer: http://mollycahill.com/backup
[Mon Jul 20 07:24:00.437155 2026] [security2:error] [pid 110058:tid 110292] [client 154.192.123.127:18803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hcBJHADqs2gAgBs-6BQAAAOw"]
[Mon Jul 20 07:24:00.437255 2026] [security2:error] [pid 110058:tid 110292] [client 154.192.123.127:18803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hcBJHADqs2gAgBs-6BQAAAOw"]
[Mon Jul 20 07:24:00.498955 2026] [security2:error] [pid 110058:tid 110126] [remote 192.241.143.148:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hcBJHADqs2gAgBs-6CAAA70I"]
[Mon Jul 20 07:24:00.667687 2026] [security2:error] [pid 110058:tid 110170] [remote 192.241.143.148:53942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hcBJHADqs2gAgBs-6FwAAk24"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:24:00.762025 2026] [security2:error] [pid 110058:tid 110123] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hcBJHADqs2gAgBs-6IgAA5D8"]
[Mon Jul 20 07:24:00.762210 2026] [security2:error] [pid 110058:tid 110284] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hcBJHADqs2gAgBs-6IgAA5D8"]
[Mon Jul 20 07:24:00.784202 2026] [security2:error] [pid 110058:tid 110257] [client 57.141.18.84:34914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hbhJHADqs2gAgBs-5KwAAyQE"]
[Mon Jul 20 07:24:00.790766 2026] [security2:error] [pid 110058:tid 110241] [client 43.157.180.116:35286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4hcBJHADqs2gAgBs-6FQAAALk"]
[Mon Jul 20 07:24:00.929823 2026] [security2:error] [pid 110058:tid 110313] [client 77.110.127.138:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hcBJHADqs2gAgBs-6NQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:00.929958 2026] [security2:error] [pid 110058:tid 110313] [client 77.110.127.138:64887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hcBJHADqs2gAgBs-6NQAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:00.980670 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hcBJHADqs2gAgBs-6OQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:00.981087 2026] [security2:error] [pid 110058:tid 110259] [client 77.110.127.138:64864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hcBJHADqs2gAgBs-6OQAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:01.141992 2026] [security2:error] [pid 110058:tid 110199] [client 14.225.17.146:62519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4hcRJHADqs2gAgBs-6QAAAAI8"]
[Mon Jul 20 07:24:01.485432 2026] [security2:error] [pid 110058:tid 110189] [client 14.225.17.146:62469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4hcRJHADqs2gAgBs-6aAAAAIU"], referer: http://idigress.agency/backup
[Mon Jul 20 07:24:01.649257 2026] [security2:error] [pid 110058:tid 110256] [client 154.208.48.130:51986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hcRJHADqs2gAgBs-6gQAAAMg"]
[Mon Jul 20 07:24:01.649367 2026] [security2:error] [pid 110058:tid 110256] [client 154.208.48.130:51986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hcRJHADqs2gAgBs-6gQAAAMg"]
[Mon Jul 20 07:24:01.813663 2026] [security2:error] [pid 110058:tid 110199] [client 14.225.17.146:62787] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4hcRJHADqs2gAgBs-6iQAAAI8"], referer: http://katsklar.com/backup
[Mon Jul 20 07:24:02.184590 2026] [http2:info] [pid 116718:tid 116718] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:24:02.318807 2026] [security2:error] [pid 110058:tid 110308] [client 143.44.185.218:33662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hchJHADqs2gAgBs-6kwAAAPw"]
[Mon Jul 20 07:24:02.318901 2026] [security2:error] [pid 110058:tid 110308] [client 143.44.185.218:33662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hchJHADqs2gAgBs-6kwAAAPw"]
[Mon Jul 20 07:24:02.532829 2026] [security2:error] [pid 116718:tid 116915] [client 18.225.9.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4hcpPWlhYV5NwZ9vUqEQAAADM"]
[Mon Jul 20 07:24:02.618431 2026] [security2:error] [pid 110058:tid 110268] [client 14.225.17.146:60685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4hcRJHADqs2gAgBs-6iwAAANQ"], referer: http://processorstudio.com/backup
[Mon Jul 20 07:24:02.618599 2026] [security2:error] [pid 116718:tid 116876] [client 49.13.24.81:40024] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4hcpPWlhYV5NwZ9vUqBwAAAAw"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:24:02.634336 2026] [security2:error] [pid 116718:tid 116752] [remote 20.153.140.50:44160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hcpPWlhYV5NwZ9vUqHAAAAxE"]
[Mon Jul 20 07:24:02.749383 2026] [security2:error] [pid 110058:tid 110155] [remote 57.141.18.83:64220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hbxJHADqs2gAgBs-5zwAAuF8"]
[Mon Jul 20 07:24:03.033771 2026] [security2:error] [pid 116718:tid 116769] [remote 20.153.140.50:44160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqQwAAKyI"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:24:03.363862 2026] [security2:error] [pid 116718:tid 116882] [client 104.234.53.51:31189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqVwAAABI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:03.460779 2026] [security2:error] [pid 116718:tid 116922] [client 14.225.17.146:63438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqXQAAADo"], referer: https://processorstudio.com/backup
[Mon Jul 20 07:24:03.733827 2026] [security2:error] [pid 116718:tid 116942] [client 77.110.127.138:64936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqdQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:03.733945 2026] [security2:error] [pid 116718:tid 116942] [client 77.110.127.138:64936] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqdQAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:03.810079 2026] [security2:error] [pid 110058:tid 110177] [remote 57.141.18.19:45888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hcBJHADqs2gAgBs-6GwAAonU"]
[Mon Jul 20 07:24:03.884863 2026] [security2:error] [pid 116718:tid 116906] [client 77.110.127.138:64937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqfAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:03.886099 2026] [security2:error] [pid 116718:tid 116906] [client 77.110.127.138:64937] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqfAAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:04.119830 2026] [security2:error] [pid 116718:tid 116896] [client 66.249.89.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4hc5PWlhYV5NwZ9vUqggAAID0"], referer: https://tiokubito.cl/producto/%E3%80%90preventa%E3%80%91kawaii-studio-escala-1-6-fern-2/
[Mon Jul 20 07:24:04.877403 2026] [security2:error] [pid 116718:tid 116900] [client 104.234.53.92:28209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hdJPWlhYV5NwZ9vUrCAAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:04.902935 2026] [security2:error] [pid 116718:tid 116956] [client 136.158.60.21:15160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hdJPWlhYV5NwZ9vUrCwAAAFw"]
[Mon Jul 20 07:24:04.903051 2026] [security2:error] [pid 116718:tid 116956] [client 136.158.60.21:15160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hdJPWlhYV5NwZ9vUrCwAAAFw"]
[Mon Jul 20 07:24:04.918762 2026] [security2:error] [pid 116718:tid 116933] [client 49.37.242.14:49907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hdJPWlhYV5NwZ9vUrEQAAAEU"]
[Mon Jul 20 07:24:04.918859 2026] [security2:error] [pid 116718:tid 116933] [client 49.37.242.14:49907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hdJPWlhYV5NwZ9vUrEQAAAEU"]
[Mon Jul 20 07:24:04.947050 2026] [security2:error] [pid 116718:tid 116919] [client 216.244.66.203:54316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/hotels/greece/elounda-peninsula-suite-hotel/"] [unique_id "al4hdJPWlhYV5NwZ9vUrFAAAADc"]
[Mon Jul 20 07:24:04.947148 2026] [security2:error] [pid 116718:tid 116919] [client 216.244.66.203:54316] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.savilerowtravel.com"] [uri "/hotels/greece/elounda-peninsula-suite-hotel/"] [unique_id "al4hdJPWlhYV5NwZ9vUrFAAAADc"]
[Mon Jul 20 07:24:05.080699 2026] [security2:error] [pid 110058:tid 110079] [remote 57.141.18.64:35398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hcRJHADqs2gAgBs-6kAAAqxQ"]
[Mon Jul 20 07:24:05.580321 2026] [security2:error] [pid 116718:tid 116795] [remote 45.90.123.233:42108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4hdZPWlhYV5NwZ9vUrVAAAJzw"]
[Mon Jul 20 07:24:05.836861 2026] [security2:error] [pid 116718:tid 116919] [client 14.225.17.146:60912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4hdZPWlhYV5NwZ9vUrWQAAADc"]
[Mon Jul 20 07:24:05.873300 2026] [security2:error] [pid 116718:tid 116952] [client 77.110.127.138:64928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hdZPWlhYV5NwZ9vUrbwAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:05.873459 2026] [security2:error] [pid 116718:tid 116952] [client 77.110.127.138:64928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hdZPWlhYV5NwZ9vUrbwAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:06.024387 2026] [security2:error] [pid 116718:tid 116973] [client 49.47.218.174:49533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hdpPWlhYV5NwZ9vUregAAAG0"]
[Mon Jul 20 07:24:06.024528 2026] [security2:error] [pid 116718:tid 116973] [client 49.47.218.174:49533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hdpPWlhYV5NwZ9vUregAAAG0"]
[Mon Jul 20 07:24:06.028631 2026] [security2:error] [pid 116718:tid 116870] [client 77.110.127.138:64945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrewAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:06.028745 2026] [security2:error] [pid 116718:tid 116870] [client 77.110.127.138:64945] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrewAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:06.441906 2026] [security2:error] [pid 116718:tid 116800] [remote 72.167.132.114:54120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrnAAAGUE"]
[Mon Jul 20 07:24:06.605000 2026] [security2:error] [pid 116718:tid 116898] [client 57.141.18.123:54434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hcpPWlhYV5NwZ9vUqPgAAIh8"]
[Mon Jul 20 07:24:06.647363 2026] [security2:error] [pid 116718:tid 116812] [remote 72.167.132.114:54120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrpwAAfE0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:24:06.677492 2026] [security2:error] [pid 116718:tid 116871] [client 14.225.17.146:60690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4hdZPWlhYV5NwZ9vUrHAAAAAc"], referer: http://ironcitywellness.com/backup
[Mon Jul 20 07:24:06.943630 2026] [security2:error] [pid 116718:tid 116939] [client 36.93.152.155:61764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hdpPWlhYV5NwZ9vUryAAAAEs"]
[Mon Jul 20 07:24:06.943770 2026] [security2:error] [pid 116718:tid 116939] [client 36.93.152.155:61764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hdpPWlhYV5NwZ9vUryAAAAEs"]
[Mon Jul 20 07:24:06.989676 2026] [security2:error] [pid 116718:tid 116929] [client 103.176.215.66:54226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrzQAAAEE"]
[Mon Jul 20 07:24:06.989818 2026] [security2:error] [pid 116718:tid 116929] [client 103.176.215.66:54226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrzQAAAEE"]
[Mon Jul 20 07:24:07.178179 2026] [security2:error] [pid 116718:tid 116847] [remote 100.42.189.89:56550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr5AAAAHA"]
[Mon Jul 20 07:24:07.200622 2026] [security2:error] [pid 116718:tid 116913] [client 188.166.91.169:65420] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.gearwaterproof.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr2gAAADE"]
[Mon Jul 20 07:24:07.388744 2026] [security2:error] [pid 116718:tid 116861] [remote 100.42.189.89:56550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr7QAAYn4"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:24:07.522048 2026] [security2:error] [pid 116718:tid 116902] [client 77.110.127.138:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr_AAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:07.522174 2026] [security2:error] [pid 116718:tid 116902] [client 77.110.127.138:64949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr_AAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:07.644240 2026] [security2:error] [pid 116718:tid 116975] [client 14.225.17.146:62429] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr9AAAAG8"], referer: http://swafforddetailing.com/backup
[Mon Jul 20 07:24:07.836685 2026] [security2:error] [pid 116718:tid 116877] [client 14.225.17.146:61415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrjgAAAA0"], referer: https://north-woods-engineering.com/backup
[Mon Jul 20 07:24:07.898178 2026] [security2:error] [pid 116718:tid 116929] [client 14.225.17.146:62115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4hd5PWlhYV5NwZ9vUsGAAAAEE"], referer: http://grndl.com/backup
[Mon Jul 20 07:24:08.017413 2026] [security2:error] [pid 116718:tid 116930] [client 57.141.18.60:37750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hdJPWlhYV5NwZ9vUqjwAAQkU"]
[Mon Jul 20 07:24:08.140184 2026] [security2:error] [pid 116718:tid 116936] [client 77.110.127.138:64954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heJPWlhYV5NwZ9vUsKgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:08.140269 2026] [security2:error] [pid 116718:tid 116936] [client 77.110.127.138:64954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heJPWlhYV5NwZ9vUsKgAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:08.203844 2026] [security2:error] [pid 116718:tid 116964] [client 191.202.66.27:49956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsMQAAAGQ"]
[Mon Jul 20 07:24:08.204068 2026] [security2:error] [pid 116718:tid 116964] [client 191.202.66.27:49956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsMQAAAGQ"]
[Mon Jul 20 07:24:08.257342 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:64943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heJPWlhYV5NwZ9vUsNQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:08.257527 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:64943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heJPWlhYV5NwZ9vUsNQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:08.409392 2026] [security2:error] [pid 116718:tid 116773] [remote 45.90.123.233:42108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4heJPWlhYV5NwZ9vUsPwAAKyY"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:24:08.420839 2026] [security2:error] [pid 116718:tid 116913] [client 77.110.127.138:64958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heJPWlhYV5NwZ9vUsQAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:08.420949 2026] [security2:error] [pid 116718:tid 116913] [client 77.110.127.138:64958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heJPWlhYV5NwZ9vUsQAAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:08.528745 2026] [security2:error] [pid 116718:tid 116896] [client 57.141.18.93:37810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hdJPWlhYV5NwZ9vUq9QAAIAQ"]
[Mon Jul 20 07:24:08.528947 2026] [security2:error] [pid 116718:tid 116925] [client 103.106.165.44:52767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsSwAAAD0"]
[Mon Jul 20 07:24:08.529053 2026] [security2:error] [pid 116718:tid 116925] [client 103.106.165.44:52767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsSwAAAD0"]
[Mon Jul 20 07:24:08.575713 2026] [security2:error] [pid 116718:tid 116885] [client 157.20.138.62:50379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsUQAAABU"]
[Mon Jul 20 07:24:08.575871 2026] [security2:error] [pid 116718:tid 116885] [client 157.20.138.62:50379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsUQAAABU"]
[Mon Jul 20 07:24:08.709063 2026] [security2:error] [pid 116718:tid 116892] [client 88.241.67.160:55057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsXAAAABw"]
[Mon Jul 20 07:24:08.709320 2026] [security2:error] [pid 116718:tid 116892] [client 88.241.67.160:55057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsXAAAABw"]
[Mon Jul 20 07:24:08.737293 2026] [security2:error] [pid 116718:tid 116879] [client 117.211.236.168:61671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsYAAAAA8"]
[Mon Jul 20 07:24:08.737430 2026] [security2:error] [pid 116718:tid 116879] [client 117.211.236.168:61671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4heJPWlhYV5NwZ9vUsYAAAAA8"]
[Mon Jul 20 07:24:08.859408 2026] [security2:error] [pid 116718:tid 116989] [client 14.225.17.146:62479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4heJPWlhYV5NwZ9vUsWwAAAH0"], referer: http://thechancersband.com/backup
[Mon Jul 20 07:24:09.005141 2026] [security2:error] [pid 116718:tid 116985] [client 57.141.18.125:24364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hdZPWlhYV5NwZ9vUrGwAAeRU"]
[Mon Jul 20 07:24:09.061544 2026] [security2:error] [pid 116718:tid 116987] [client 179.127.84.238:51206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4heZPWlhYV5NwZ9vUsfgAAAHs"]
[Mon Jul 20 07:24:09.061713 2026] [security2:error] [pid 116718:tid 116987] [client 179.127.84.238:51206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4heZPWlhYV5NwZ9vUsfgAAAHs"]
[Mon Jul 20 07:24:09.241158 2026] [security2:error] [pid 116718:tid 116883] [client 201.27.111.74:56558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4heZPWlhYV5NwZ9vUsnQAAABM"]
[Mon Jul 20 07:24:09.241265 2026] [security2:error] [pid 116718:tid 116883] [client 201.27.111.74:56558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4heZPWlhYV5NwZ9vUsnQAAABM"]
[Mon Jul 20 07:24:09.431885 2026] [security2:error] [pid 116718:tid 116932] [client 104.234.53.47:60933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4heZPWlhYV5NwZ9vUsrwAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:09.522289 2026] [security2:error] [pid 116718:tid 116819] [remote 57.141.18.5:56942] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/3671901"] [unique_id "al4heZPWlhYV5NwZ9vUsuAAAbVQ"]
[Mon Jul 20 07:24:09.616790 2026] [security2:error] [pid 116718:tid 116822] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4heZPWlhYV5NwZ9vUsvgAAKlc"]
[Mon Jul 20 07:24:09.616952 2026] [security2:error] [pid 116718:tid 116906] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4heZPWlhYV5NwZ9vUsvgAAKlc"]
[Mon Jul 20 07:24:09.676868 2026] [security2:error] [pid 116718:tid 116975] [client 77.110.127.138:64971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heZPWlhYV5NwZ9vUsxQAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:09.676975 2026] [security2:error] [pid 116718:tid 116975] [client 77.110.127.138:64971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4heZPWlhYV5NwZ9vUsxQAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:10.065484 2026] [security2:error] [pid 116718:tid 116926] [client 121.229.156.95:37848] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/product/dsi-7-led-light-chandelier/"] [unique_id "al4hepPWlhYV5NwZ9vUs6gAAAD4"]
[Mon Jul 20 07:24:10.065614 2026] [security2:error] [pid 116718:tid 116926] [client 121.229.156.95:37848] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.liquidationteam.com"] [uri "/product/dsi-7-led-light-chandelier/"] [unique_id "al4hepPWlhYV5NwZ9vUs6gAAAD4"]
[Mon Jul 20 07:24:10.269378 2026] [security2:error] [pid 116718:tid 116919] [client 77.110.127.138:64942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hepPWlhYV5NwZ9vUtAgAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:10.269535 2026] [security2:error] [pid 116718:tid 116919] [client 77.110.127.138:64942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hepPWlhYV5NwZ9vUtAgAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:10.278790 2026] [security2:error] [pid 116718:tid 116894] [client 66.249.64.8:59670] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.immigrationlawyers.me.uk"] [uri "/robots.txt"] [unique_id "al4hepPWlhYV5NwZ9vUtBAAAAB4"]
[Mon Jul 20 07:24:10.312721 2026] [security2:error] [pid 116718:tid 116900] [client 20.245.75.247:32641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hepPWlhYV5NwZ9vUtBwAAACQ"]
[Mon Jul 20 07:24:10.331860 2026] [security2:error] [pid 116718:tid 116987] [client 20.245.75.247:32641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hepPWlhYV5NwZ9vUtCgAAAHs"]
[Mon Jul 20 07:24:10.512194 2026] [security2:error] [pid 116718:tid 116877] [client 13.71.159.57:3849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hepPWlhYV5NwZ9vUtEQAAAA0"]
[Mon Jul 20 07:24:10.623865 2026] [security2:error] [pid 116718:tid 116951] [client 13.71.159.57:3849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hepPWlhYV5NwZ9vUtHwAAAFc"]
[Mon Jul 20 07:24:10.742058 2026] [security2:error] [pid 116718:tid 116872] [client 14.225.17.146:49319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4hepPWlhYV5NwZ9vUtGQAAAAg"], referer: http://adirondackengineering.com/backup
[Mon Jul 20 07:24:10.778451 2026] [security2:error] [pid 116718:tid 116870] [client 57.141.18.92:47994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hdpPWlhYV5NwZ9vUrvAAABmU"]
[Mon Jul 20 07:24:10.957007 2026] [security2:error] [pid 116718:tid 116860] [remote 57.141.18.45:31022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4198967"] [unique_id "al4hepPWlhYV5NwZ9vUtOQAAVH0"]
[Mon Jul 20 07:24:11.016169 2026] [security2:error] [pid 116718:tid 116923] [client 77.110.127.138:64946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4he5PWlhYV5NwZ9vUtQQAAADs"]
[Mon Jul 20 07:24:11.016275 2026] [security2:error] [pid 116718:tid 116923] [client 77.110.127.138:64946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4he5PWlhYV5NwZ9vUtQQAAADs"]
[Mon Jul 20 07:24:11.077583 2026] [security2:error] [pid 116718:tid 116959] [client 77.110.127.138:64969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4he5PWlhYV5NwZ9vUtSAAAAF8"]
[Mon Jul 20 07:24:11.077717 2026] [security2:error] [pid 116718:tid 116959] [client 77.110.127.138:64969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4he5PWlhYV5NwZ9vUtSAAAAF8"]
[Mon Jul 20 07:24:11.148171 2026] [security2:error] [pid 116718:tid 116957] [client 14.225.17.146:60081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4he5PWlhYV5NwZ9vUtQAAAAF0"]
[Mon Jul 20 07:24:11.180047 2026] [security2:error] [pid 116718:tid 116874] [client 154.192.123.127:17243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4he5PWlhYV5NwZ9vUtWQAAAAo"]
[Mon Jul 20 07:24:11.180178 2026] [security2:error] [pid 116718:tid 116874] [client 154.192.123.127:17243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4he5PWlhYV5NwZ9vUtWQAAAAo"]
[Mon Jul 20 07:24:11.277245 2026] [security2:error] [pid 116718:tid 116952] [client 57.141.18.89:59416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hd5PWlhYV5NwZ9vUr5gAAWHo"]
[Mon Jul 20 07:24:11.400344 2026] [security2:error] [pid 116718:tid 116760] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4he5PWlhYV5NwZ9vUtbwAAKRk"]
[Mon Jul 20 07:24:11.400550 2026] [security2:error] [pid 116718:tid 116905] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4he5PWlhYV5NwZ9vUtbwAAKRk"]
[Mon Jul 20 07:24:11.588220 2026] [security2:error] [pid 116718:tid 116916] [client 14.225.17.146:62399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4heZPWlhYV5NwZ9vUswQAAADQ"], referer: http://oldracelimited.com/backup
[Mon Jul 20 07:24:11.761342 2026] [proxy:error] [pid 116718:tid 116963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:24:11.761395 2026] [proxy_http:error] [pid 116718:tid 116963] [client 107.172.180.205:37264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:24:11.762178 2026] [proxy:error] [pid 116718:tid 116963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:24:11.762210 2026] [proxy_http:error] [pid 116718:tid 116963] [client 107.172.180.205:37264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:24:11.957016 2026] [security2:error] [pid 116718:tid 116893] [client 50.116.65.227:51088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4he5PWlhYV5NwZ9vUtkAAAAB0"]
[Mon Jul 20 07:24:12.029886 2026] [security2:error] [pid 116718:tid 116906] [client 77.110.127.138:64980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfJPWlhYV5NwZ9vUtuQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:12.030001 2026] [security2:error] [pid 116718:tid 116906] [client 77.110.127.138:64980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfJPWlhYV5NwZ9vUtuQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:12.133470 2026] [security2:error] [pid 116718:tid 116919] [client 50.116.65.227:51092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4he5PWlhYV5NwZ9vUtsAAAADc"]
[Mon Jul 20 07:24:12.319891 2026] [security2:error] [pid 116718:tid 116931] [client 112.86.225.100:49598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nwcarvingacademy.com"] [uri "/"] [unique_id "al4hfJPWlhYV5NwZ9vUt8QAAAEM"]
[Mon Jul 20 07:24:12.320037 2026] [security2:error] [pid 116718:tid 116931] [client 112.86.225.100:49598] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nwcarvingacademy.com"] [uri "/"] [unique_id "al4hfJPWlhYV5NwZ9vUt8QAAAEM"]
[Mon Jul 20 07:24:12.428647 2026] [security2:error] [pid 116718:tid 116967] [client 54.244.177.189:65360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4hfJPWlhYV5NwZ9vUt9gAAAGc"]
[Mon Jul 20 07:24:12.448222 2026] [security2:error] [pid 116718:tid 116986] [client 104.234.53.69:25503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hfJPWlhYV5NwZ9vUt9QAAAHo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:12.467983 2026] [security2:error] [pid 116718:tid 116959] [client 14.225.17.146:61931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4hfJPWlhYV5NwZ9vUt8wAAAF8"], referer: http://sarahholyfield.com/backup
[Mon Jul 20 07:24:12.500730 2026] [security2:error] [pid 116718:tid 116905] [client 154.208.48.130:52509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hfJPWlhYV5NwZ9vUuAAAAACk"]
[Mon Jul 20 07:24:12.501010 2026] [security2:error] [pid 116718:tid 116905] [client 154.208.48.130:52509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hfJPWlhYV5NwZ9vUuAAAAACk"]
[Mon Jul 20 07:24:12.618291 2026] [core:error] [pid 116718:tid 116980] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:12.618321 2026] [core:error] [pid 116718:tid 116980] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:12.716844 2026] [security2:error] [pid 116718:tid 116923] [client 77.110.127.138:64983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfJPWlhYV5NwZ9vUuGQAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:12.716945 2026] [security2:error] [pid 116718:tid 116923] [client 77.110.127.138:64983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfJPWlhYV5NwZ9vUuGQAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:12.772841 2026] [core:error] [pid 116718:tid 116941] [client 144.172.114.51:43232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:12.772871 2026] [core:error] [pid 116718:tid 116941] [client 144.172.114.51:43232] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:12.782431 2026] [security2:error] [pid 116718:tid 116835] [remote 182.77.62.24:40662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4hfJPWlhYV5NwZ9vUuHQAAImQ"]
[Mon Jul 20 07:24:12.795868 2026] [security2:error] [pid 116718:tid 116906] [client 50.116.65.227:51112] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hfJPWlhYV5NwZ9vUuIQAAACo"]
[Mon Jul 20 07:24:12.805679 2026] [security2:error] [pid 116718:tid 116986] [client 50.116.65.227:51122] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hfJPWlhYV5NwZ9vUuIgAAAHo"]
[Mon Jul 20 07:24:12.955008 2026] [security2:error] [pid 116718:tid 116869] [client 192.178.4.99:35407] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "emil.manasyan.uk"] [uri "/robots.txt"] [unique_id "al4hfJPWlhYV5NwZ9vUuPAAAAAU"]
[Mon Jul 20 07:24:13.210319 2026] [security2:error] [pid 116718:tid 116957] [client 14.225.17.146:56613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuRAAAAF0"], referer: http://colinkeyphotography.com/backup
[Mon Jul 20 07:24:13.229839 2026] [security2:error] [pid 116718:tid 116913] [client 14.225.17.146:62499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4hfJPWlhYV5NwZ9vUuOwAAADE"], referer: http://webgardensbypaula.com/backup
[Mon Jul 20 07:24:13.358249 2026] [security2:error] [pid 116718:tid 116804] [remote 182.77.62.24:40662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4hfZPWlhYV5NwZ9vUubwAAIEU"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 07:24:13.452497 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:64989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUudQAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.452625 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:64989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUudQAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.513059 2026] [proxy:error] [pid 116718:tid 116963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:24:13.513138 2026] [proxy_http:error] [pid 116718:tid 116963] [client 107.172.180.205:37306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:24:13.513660 2026] [proxy:error] [pid 116718:tid 116963] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:24:13.513703 2026] [proxy_http:error] [pid 116718:tid 116963] [client 107.172.180.205:37306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:24:13.540727 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:64948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUufQAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.540886 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:64948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUufQAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.592977 2026] [security2:error] [pid 116718:tid 116928] [client 77.110.127.138:64968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUufwAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.593136 2026] [security2:error] [pid 116718:tid 116928] [client 77.110.127.138:64968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUufwAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.643819 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:64953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuggAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.643971 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:64953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuggAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.694074 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:64955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuigAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.694201 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:64955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuigAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.843443 2026] [security2:error] [pid 116718:tid 116919] [client 77.110.127.138:64992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUunQAAADc"]
[Mon Jul 20 07:24:13.843547 2026] [security2:error] [pid 116718:tid 116919] [client 77.110.127.138:64992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUunQAAADc"]
[Mon Jul 20 07:24:13.920022 2026] [security2:error] [pid 116718:tid 116984] [client 77.110.127.138:64985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuowAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:13.920143 2026] [security2:error] [pid 116718:tid 116984] [client 77.110.127.138:64985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuowAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.086301 2026] [security2:error] [pid 116718:tid 116926] [client 77.110.127.138:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUuuQAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.086397 2026] [security2:error] [pid 116718:tid 116926] [client 77.110.127.138:64995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUuuQAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.141387 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:64996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUuvAAAAGI"]
[Mon Jul 20 07:24:14.141538 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:64996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUuvAAAAGI"]
[Mon Jul 20 07:24:14.330537 2026] [core:error] [pid 116718:tid 116877] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:14.330569 2026] [core:error] [pid 116718:tid 116877] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:14.380590 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:64974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu3wAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.380830 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:64974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu3wAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.451557 2026] [security2:error] [pid 116718:tid 116928] [client 77.110.127.138:64972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu4QAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.451655 2026] [security2:error] [pid 116718:tid 116928] [client 77.110.127.138:64972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu4QAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.503257 2026] [security2:error] [pid 116718:tid 116967] [client 77.110.127.138:64978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu6AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.503387 2026] [security2:error] [pid 116718:tid 116967] [client 77.110.127.138:64978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu6AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.555195 2026] [security2:error] [pid 116718:tid 116960] [client 77.110.127.138:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu7AAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.555327 2026] [security2:error] [pid 116718:tid 116960] [client 77.110.127.138:64987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu7AAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.605683 2026] [security2:error] [pid 116718:tid 116983] [client 77.110.127.138:64988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu7wAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.605818 2026] [security2:error] [pid 116718:tid 116983] [client 77.110.127.138:64988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu7wAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.676657 2026] [security2:error] [pid 116718:tid 116969] [client 14.225.17.146:56674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4hfZPWlhYV5NwZ9vUuRgAAAGk"], referer: http://blaizeaccountingservices.com/backup
[Mon Jul 20 07:24:14.883477 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:64935] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/if(now()=sysdate(),sleep(15),0)/related-posts.css"] [unique_id "al4hfpPWlhYV5NwZ9vUvAQAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:14.986016 2026] [security2:error] [pid 116718:tid 116879] [client 57.141.18.20:46224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hepPWlhYV5NwZ9vUtKgAADwc"]
[Mon Jul 20 07:24:15.184694 2026] [security2:error] [pid 116718:tid 116906] [client 143.44.185.218:35176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvFAAAACo"]
[Mon Jul 20 07:24:15.184809 2026] [security2:error] [pid 116718:tid 116906] [client 143.44.185.218:35176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvFAAAACo"]
[Mon Jul 20 07:24:15.354683 2026] [security2:error] [pid 116718:tid 116799] [remote 91.142.222.105:56028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvIgAAZ0A"]
[Mon Jul 20 07:24:15.521621 2026] [security2:error] [pid 116718:tid 116895] [client 77.110.127.138:65002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvLQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:15.521715 2026] [security2:error] [pid 116718:tid 116895] [client 77.110.127.138:65002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvLQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:15.535510 2026] [security2:error] [pid 116718:tid 116933] [client 136.158.60.21:16654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvLwAAAEU"]
[Mon Jul 20 07:24:15.535637 2026] [security2:error] [pid 116718:tid 116933] [client 136.158.60.21:16654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvLwAAAEU"]
[Mon Jul 20 07:24:15.578173 2026] [security2:error] [pid 116718:tid 116807] [remote 91.142.222.105:56028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvMAAAHUg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:24:15.672833 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvNAAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:15.672933 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvNAAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:15.912117 2026] [security2:error] [pid 116718:tid 116832] [remote 98.156.100.191:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvQwAAdGE"]
[Mon Jul 20 07:24:16.076833 2026] [security2:error] [pid 116718:tid 116970] [client 74.7.227.179:44084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvSwAAai8"], referer: https://tejasenvironmental.com/p=652533
[Mon Jul 20 07:24:16.132026 2026] [security2:error] [pid 116718:tid 116828] [remote 98.156.100.191:39488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvWwAAVV0"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:24:16.163682 2026] [security2:error] [pid 116718:tid 116839] [remote 47.86.33.52:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvXQAABGg"]
[Mon Jul 20 07:24:16.245599 2026] [security2:error] [pid 116718:tid 116865] [client 14.225.17.146:50317] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu6gAAAAE"], referer: http://nwcarvingacademy.com/backup
[Mon Jul 20 07:24:16.259948 2026] [security2:error] [pid 116718:tid 116947] [client 104.234.53.47:44201] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvZgAAAFM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:16.392319 2026] [security2:error] [pid 116718:tid 116900] [client 14.225.17.146:57473] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4hfpPWlhYV5NwZ9vUu1gAAACQ"], referer: http://securingmemories.com/backup
[Mon Jul 20 07:24:16.452383 2026] [security2:error] [pid 116718:tid 116916] [client 49.47.218.174:50079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvdwAAADQ"]
[Mon Jul 20 07:24:16.452494 2026] [security2:error] [pid 116718:tid 116916] [client 49.47.218.174:50079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvdwAAADQ"]
[Mon Jul 20 07:24:16.552654 2026] [security2:error] [pid 116718:tid 116845] [remote 47.86.33.52:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvewAAFG4"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 07:24:16.788730 2026] [security2:error] [pid 116718:tid 116976] [client 14.225.17.146:50368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4hf5PWlhYV5NwZ9vUvOwAAAHA"], referer: http://ancestralidadytrance.space/backup
[Mon Jul 20 07:24:16.810497 2026] [security2:error] [pid 116718:tid 116957] [client 14.224.227.113:55980] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hgJPWlhYV5NwZ9vUvjwAAAF0"]
[Mon Jul 20 07:24:16.811776 2026] [security2:error] [pid 116718:tid 116958] [client 14.224.227.113:55976] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hgJPWlhYV5NwZ9vUvkQAAAF4"]
[Mon Jul 20 07:24:16.813806 2026] [security2:error] [pid 116718:tid 116893] [client 14.251.3.155:55975] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hgJPWlhYV5NwZ9vUvkgAAAB0"]
[Mon Jul 20 07:24:17.031330 2026] [security2:error] [pid 116718:tid 116754] [remote 167.71.218.184:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4hgZPWlhYV5NwZ9vUvqwAAWRM"]
[Mon Jul 20 07:24:17.121002 2026] [security2:error] [pid 116718:tid 116936] [client 40.77.167.5:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4hgJPWlhYV5NwZ9vUviAAAAEg"]
[Mon Jul 20 07:24:17.409499 2026] [security2:error] [pid 116718:tid 116895] [client 14.225.17.146:62305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4hgZPWlhYV5NwZ9vUvsQAAAB8"], referer: https://nwcarvingacademy.com/backup
[Mon Jul 20 07:24:17.425091 2026] [security2:error] [pid 116718:tid 116836] [remote 167.71.218.184:39406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.218.71.167.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4hgZPWlhYV5NwZ9vUvzgAAYmU"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 07:24:17.468057 2026] [security2:error] [pid 116718:tid 116892] [client 36.93.152.155:62268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv1QAAABw"]
[Mon Jul 20 07:24:17.468161 2026] [security2:error] [pid 116718:tid 116892] [client 36.93.152.155:62268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv1QAAABw"]
[Mon Jul 20 07:24:17.509054 2026] [security2:error] [pid 116718:tid 116878] [client 103.176.215.66:54777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv2QAAAA4"]
[Mon Jul 20 07:24:17.509595 2026] [security2:error] [pid 116718:tid 116878] [client 103.176.215.66:54777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv2QAAAA4"]
[Mon Jul 20 07:24:17.849494 2026] [security2:error] [pid 116718:tid 116884] [client 173.252.69.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv2gAAFCE"]
[Mon Jul 20 07:24:17.854911 2026] [security2:error] [pid 116718:tid 116871] [client 57.141.18.68:35042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hfZPWlhYV5NwZ9vUujgAABwE"]
[Mon Jul 20 07:24:18.183153 2026] [security2:error] [pid 116718:tid 116868] [client 14.225.17.146:57564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv-wAAAAQ"], referer: http://lifeisbetterlakeside.com/backup
[Mon Jul 20 07:24:18.577093 2026] [security2:error] [pid 116718:tid 116929] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwHQAAAEE"], referer: 1'"3000
[Mon Jul 20 07:24:18.688967 2026] [security2:error] [pid 116718:tid 116957] [client 77.110.127.138:64998] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/related-posts0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/related-posts.css"] [unique_id "al4hgpPWlhYV5NwZ9vUwOQAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:18.696656 2026] [security2:error] [pid 116718:tid 116747] [remote 216.73.216.55:64134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training/"] [unique_id "al4hgpPWlhYV5NwZ9vUwPAAANww"]
[Mon Jul 20 07:24:18.843866 2026] [security2:error] [pid 116718:tid 116927] [client 77.110.127.138:65015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwQwAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:18.843981 2026] [security2:error] [pid 116718:tid 116927] [client 77.110.127.138:65015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwQwAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:18.846701 2026] [security2:error] [pid 116718:tid 116954] [client 14.225.17.146:57563] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4hgZPWlhYV5NwZ9vUv9wAAAFo"], referer: http://partnerselectricalllc.com/backup
[Mon Jul 20 07:24:18.962244 2026] [security2:error] [pid 116718:tid 116874] [client 191.202.66.27:50448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwSQAAAAo"]
[Mon Jul 20 07:24:18.962386 2026] [security2:error] [pid 116718:tid 116874] [client 191.202.66.27:50448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwSQAAAAo"]
[Mon Jul 20 07:24:18.993949 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwTQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:18.994087 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:65016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwTQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:18.999879 2026] [security2:error] [pid 116718:tid 116890] [client 158.173.166.181:24481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hgpPWlhYV5NwZ9vUwTwAAABo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:24:19.003844 2026] [security2:error] [pid 116718:tid 116905] [client 49.37.242.14:50385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwUgAAACk"]
[Mon Jul 20 07:24:19.003931 2026] [security2:error] [pid 116718:tid 116905] [client 49.37.242.14:50385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwUgAAACk"]
[Mon Jul 20 07:24:19.154816 2026] [security2:error] [pid 116718:tid 116962] [client 57.141.18.92:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwUAAAAGI"]
[Mon Jul 20 07:24:19.175286 2026] [security2:error] [pid 116718:tid 116928] [client 103.106.165.44:53246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwYQAAAEA"]
[Mon Jul 20 07:24:19.175381 2026] [security2:error] [pid 116718:tid 116928] [client 103.106.165.44:53246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwYQAAAEA"]
[Mon Jul 20 07:24:19.252793 2026] [security2:error] [pid 116718:tid 116927] [client 77.110.127.138:64979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwawAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.252881 2026] [security2:error] [pid 116718:tid 116927] [client 77.110.127.138:64979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwawAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.401400 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwdQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.401511 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwdQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.465339 2026] [security2:error] [pid 116718:tid 116976] [client 157.20.138.62:50948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwhAAAAHA"]
[Mon Jul 20 07:24:19.465458 2026] [security2:error] [pid 116718:tid 116976] [client 157.20.138.62:50948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwhAAAAHA"]
[Mon Jul 20 07:24:19.473362 2026] [security2:error] [pid 116718:tid 116936] [client 88.241.67.160:56955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwhQAAAEg"]
[Mon Jul 20 07:24:19.473890 2026] [security2:error] [pid 116718:tid 116936] [client 88.241.67.160:56955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwhQAAAEg"]
[Mon Jul 20 07:24:19.493280 2026] [security2:error] [pid 116718:tid 116887] [client 104.234.53.63:36249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwiAAAABc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:19.679156 2026] [security2:error] [pid 116718:tid 116952] [client 201.27.111.74:57073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwkgAAAFg"]
[Mon Jul 20 07:24:19.679306 2026] [security2:error] [pid 116718:tid 116952] [client 201.27.111.74:57073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwkgAAAFg"]
[Mon Jul 20 07:24:19.702441 2026] [security2:error] [pid 116718:tid 116866] [client 179.127.84.238:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwkwAAAAI"]
[Mon Jul 20 07:24:19.702611 2026] [security2:error] [pid 116718:tid 116866] [client 179.127.84.238:51701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwkwAAAAI"]
[Mon Jul 20 07:24:19.704383 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwcwAAAHU"], referer: 1'"3000
[Mon Jul 20 07:24:19.711314 2026] [security2:error] [pid 116718:tid 116918] [client 77.110.127.138:64998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwlwAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.711414 2026] [security2:error] [pid 116718:tid 116918] [client 77.110.127.138:64998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwlwAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.871951 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:65023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwowAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:19.872090 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:65023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwowAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:20.068883 2026] [security2:error] [pid 116718:tid 116895] [client 77.110.127.138:65024] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/related-posts0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/related-posts.css"] [unique_id "al4hhJPWlhYV5NwZ9vUwuQAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:20.112815 2026] [security2:error] [pid 116718:tid 116917] [client 14.225.17.146:49426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwtAAAADU"]
[Mon Jul 20 07:24:20.118521 2026] [security2:error] [pid 116718:tid 116949] [client 77.110.127.138:64981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhJPWlhYV5NwZ9vUwvgAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:20.118612 2026] [security2:error] [pid 116718:tid 116949] [client 77.110.127.138:64981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhJPWlhYV5NwZ9vUwvgAAAFU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:20.303497 2026] [security2:error] [pid 116718:tid 116954] [client 77.110.127.138:65028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhJPWlhYV5NwZ9vUw2AAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:20.303616 2026] [security2:error] [pid 116718:tid 116954] [client 77.110.127.138:65028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhJPWlhYV5NwZ9vUw2AAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:20.340566 2026] [security2:error] [pid 116718:tid 116778] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hhJPWlhYV5NwZ9vUw2wAAHCs"]
[Mon Jul 20 07:24:20.340735 2026] [security2:error] [pid 116718:tid 116892] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hhJPWlhYV5NwZ9vUw2wAAHCs"]
[Mon Jul 20 07:24:20.588351 2026] [security2:error] [pid 116718:tid 116870] [client 57.141.18.31:38528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hgJPWlhYV5NwZ9vUvbAAABmQ"]
[Mon Jul 20 07:24:20.662245 2026] [security2:error] [pid 116718:tid 116951] [client 14.225.17.146:50273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4hg5PWlhYV5NwZ9vUwbAAAAFc"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/backup
[Mon Jul 20 07:24:20.987564 2026] [autoindex:error] [pid 116718:tid 116935] [client 34.73.253.87:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://eyl.bfk.mybluehost.me
[Mon Jul 20 07:24:21.003453 2026] [core:error] [pid 116718:tid 116906] [client 133.167.125.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:21.003474 2026] [core:error] [pid 116718:tid 116906] [client 133.167.125.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:21.007608 2026] [core:error] [pid 116718:tid 116967] [client 133.167.125.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:21.007625 2026] [core:error] [pid 116718:tid 116967] [client 133.167.125.159:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:21.180687 2026] [security2:error] [pid 116718:tid 116983] [client 77.110.127.138:65033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxIQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:21.180802 2026] [security2:error] [pid 116718:tid 116983] [client 77.110.127.138:65033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxIQAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:21.190364 2026] [security2:error] [pid 116718:tid 116803] [remote 162.19.86.63:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxIwAANkQ"]
[Mon Jul 20 07:24:21.263428 2026] [security2:error] [pid 116718:tid 116985] [client 77.110.127.138:65024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxKwAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:21.263532 2026] [security2:error] [pid 116718:tid 116985] [client 77.110.127.138:65024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxKwAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:21.456800 2026] [security2:error] [pid 116718:tid 116738] [remote 162.19.86.63:57050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxPQAAVAM"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:24:21.511428 2026] [security2:error] [pid 116718:tid 116933] [client 14.225.17.146:50810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxNwAAAEU"], referer: http://betterbonddogtraining.com/backup
[Mon Jul 20 07:24:21.680413 2026] [security2:error] [pid 116718:tid 116968] [client 14.225.17.146:50841] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4hhJPWlhYV5NwZ9vUwtwAAAGg"], referer: http://koaconsultants.com/backup
[Mon Jul 20 07:24:21.748433 2026] [security2:error] [pid 116718:tid 116929] [client 154.192.123.127:17639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxXQAAAEE"]
[Mon Jul 20 07:24:21.748628 2026] [security2:error] [pid 116718:tid 116929] [client 154.192.123.127:17639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxXQAAAEE"]
[Mon Jul 20 07:24:21.766909 2026] [security2:error] [pid 116718:tid 116916] [client 104.234.53.66:54447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxYQAAADQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:21.776509 2026] [security2:error] [pid 116718:tid 116745] [remote 154.61.75.100:48382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxXwAAWAo"]
[Mon Jul 20 07:24:21.788654 2026] [security2:error] [pid 116718:tid 116990] [client 14.225.17.146:49159] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4hhJPWlhYV5NwZ9vUw-gAAAH4"], referer: http://headachescarpaltunnelfibromyalgia.com/backup
[Mon Jul 20 07:24:21.890992 2026] [security2:error] [pid 116718:tid 116905] [client 216.131.76.241:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.jennylouraya.com"] [uri "/index.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxEQAAACk"]
[Mon Jul 20 07:24:21.894903 2026] [security2:error] [pid 116718:tid 116936] [client 216.131.76.241:51592] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.jennylouraya.com"] [uri "/feed/"] [unique_id "al4hhJPWlhYV5NwZ9vUxCAAAAEg"]
[Mon Jul 20 07:24:22.127921 2026] [security2:error] [pid 116718:tid 116977] [client 66.249.89.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxawAAcS4"], referer: https://tiokubito.cl/producto/preventa-happy-life-one-piece-monkey-d-luffy/
[Mon Jul 20 07:24:22.136099 2026] [security2:error] [pid 116718:tid 116949] [client 14.225.17.146:50828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4hhZPWlhYV5NwZ9vUxbAAAAFU"], referer: http://longevityperformanceclinic.com/backup
[Mon Jul 20 07:24:22.146662 2026] [security2:error] [pid 116718:tid 116770] [remote 130.51.180.8:54410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxdwAAXiM"]
[Mon Jul 20 07:24:22.192376 2026] [security2:error] [pid 116718:tid 116907] [client 77.110.127.138:65011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxfwAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:22.192474 2026] [security2:error] [pid 116718:tid 116907] [client 77.110.127.138:65011] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxfwAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:22.258473 2026] [security2:error] [pid 116718:tid 116772] [remote 154.61.75.100:48382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxhwAAIyU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:24:22.301909 2026] [security2:error] [pid 116718:tid 116791] [remote 130.51.180.8:54410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxkwAALDg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:24:22.323175 2026] [security2:error] [pid 116718:tid 116862] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxlgAAWX8"]
[Mon Jul 20 07:24:22.323354 2026] [security2:error] [pid 116718:tid 116953] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxlgAAWX8"]
[Mon Jul 20 07:24:22.381151 2026] [security2:error] [pid 116718:tid 116982] [client 158.51.126.91:41952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "qualitycoatingsinspection.com"] [uri "/.env.bak"] [unique_id "al4hhpPWlhYV5NwZ9vUxqQAAAHY"]
[Mon Jul 20 07:24:22.406410 2026] [security2:error] [pid 116718:tid 116893] [client 158.51.126.91:41952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "qualitycoatingsinspection.com"] [uri "/.env.backup"] [unique_id "al4hhpPWlhYV5NwZ9vUxqwAAAB0"]
[Mon Jul 20 07:24:22.431168 2026] [security2:error] [pid 116718:tid 116904] [client 158.51.126.91:41952] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "qualitycoatingsinspection.com"] [uri "/.env"] [unique_id "al4hhpPWlhYV5NwZ9vUxrQAAACg"]
[Mon Jul 20 07:24:22.444645 2026] [security2:error] [pid 116718:tid 116889] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxlAAAABk"]
[Mon Jul 20 07:24:22.553173 2026] [security2:error] [pid 116718:tid 116914] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxqAAAADI"]
[Mon Jul 20 07:24:22.627082 2026] [security2:error] [pid 116718:tid 116901] [client 158.51.126.91:41942] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "qualitycoatingsinspection.com"] [uri "/.env.production"] [unique_id "al4hhpPWlhYV5NwZ9vUxwAAAACU"]
[Mon Jul 20 07:24:22.659812 2026] [security2:error] [pid 116718:tid 116958] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxuAAAAF4"]
[Mon Jul 20 07:24:22.661800 2026] [security2:error] [pid 116718:tid 116975] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxtwAAAG8"]
[Mon Jul 20 07:24:22.663464 2026] [security2:error] [pid 116718:tid 116933] [client 117.211.236.168:62335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxxAAAAEU"]
[Mon Jul 20 07:24:22.663552 2026] [security2:error] [pid 116718:tid 116933] [client 117.211.236.168:62335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxxAAAAEU"]
[Mon Jul 20 07:24:22.780147 2026] [security2:error] [pid 116718:tid 116892] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxugAAABw"], referer: https://qualitycoatingsinspection.com/api/env
[Mon Jul 20 07:24:22.979359 2026] [security2:error] [pid 116718:tid 116960] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUx0wAAAGA"], referer: https://qualitycoatingsinspection.com/api/config
[Mon Jul 20 07:24:22.991265 2026] [security2:error] [pid 116718:tid 116923] [client 14.225.17.146:64046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxdQAAADs"], referer: http://careysheatingandcooling.com/backup
[Mon Jul 20 07:24:23.259096 2026] [security2:error] [pid 116718:tid 116986] [client 216.131.76.241:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.jennylouraya.com"] [uri "/index.php"] [unique_id "al4hh5PWlhYV5NwZ9vUx-QAAAHo"]
[Mon Jul 20 07:24:23.262093 2026] [security2:error] [pid 116718:tid 116885] [client 216.131.76.241:51673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "500"] [hostname "www.jennylouraya.com"] [uri "/feed/"] [unique_id "al4hh5PWlhYV5NwZ9vUx9AAAABU"]
[Mon Jul 20 07:24:23.601301 2026] [security2:error] [pid 116718:tid 116821] [remote 152.228.213.32:35872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyDAAAaVY"]
[Mon Jul 20 07:24:23.601455 2026] [security2:error] [pid 116718:tid 116969] [client 152.228.213.32:35872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyDAAAaVY"]
[Mon Jul 20 07:24:23.877617 2026] [security2:error] [pid 116718:tid 116934] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyFgAAAEY"], referer: https://qualitycoatingsinspection.com/.env.local
[Mon Jul 20 07:24:23.943118 2026] [security2:error] [pid 116718:tid 116991] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyHwAAAH8"], referer: https://qualitycoatingsinspection.com/actuator/env
[Mon Jul 20 07:24:23.964479 2026] [security2:error] [pid 116718:tid 116983] [client 154.208.48.130:53056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyMQAAAHc"]
[Mon Jul 20 07:24:23.964582 2026] [security2:error] [pid 116718:tid 116983] [client 154.208.48.130:53056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyMQAAAHc"]
[Mon Jul 20 07:24:24.130914 2026] [security2:error] [pid 116718:tid 116938] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hh5PWlhYV5NwZ9vUyNgAAAEo"]
[Mon Jul 20 07:24:24.288303 2026] [security2:error] [pid 116718:tid 116897] [client 57.141.18.111:30980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hhJPWlhYV5NwZ9vUwxQAAIV0"]
[Mon Jul 20 07:24:24.420897 2026] [security2:error] [pid 116718:tid 116958] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiJPWlhYV5NwZ9vUySQAAAF4"], referer: https://qualitycoatingsinspection.com/.git/HEAD
[Mon Jul 20 07:24:24.625704 2026] [security2:error] [pid 116718:tid 116979] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiJPWlhYV5NwZ9vUyZQAAAHM"]
[Mon Jul 20 07:24:24.695847 2026] [security2:error] [pid 116718:tid 116937] [client 50.116.65.227:27234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hiJPWlhYV5NwZ9vUybwAAAEk"]
[Mon Jul 20 07:24:24.705426 2026] [security2:error] [pid 116718:tid 116965] [client 50.116.65.227:27248] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hiJPWlhYV5NwZ9vUycQAAAGU"]
[Mon Jul 20 07:24:24.903556 2026] [security2:error] [pid 116718:tid 116865] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiJPWlhYV5NwZ9vUydgAAAAE"], referer: https://qualitycoatingsinspection.com/app/.git/HEAD
[Mon Jul 20 07:24:24.983191 2026] [security2:error] [pid 116718:tid 116909] [client 52.109.28.48:5377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hiJPWlhYV5NwZ9vUykAAAAC0"]
[Mon Jul 20 07:24:25.117292 2026] [security2:error] [pid 116718:tid 116964] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiJPWlhYV5NwZ9vUyjQAAAGQ"]
[Mon Jul 20 07:24:25.120271 2026] [security2:error] [pid 116718:tid 116935] [client 52.109.28.48:5377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hiZPWlhYV5NwZ9vUyngAAAEc"]
[Mon Jul 20 07:24:25.140738 2026] [security2:error] [pid 116718:tid 116972] [client 57.141.18.37:24266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hhJPWlhYV5NwZ9vUw_gAAbGo"]
[Mon Jul 20 07:24:25.205903 2026] [security2:error] [pid 116718:tid 116878] [client 14.224.227.113:56013] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hiZPWlhYV5NwZ9vUypgAAAA4"]
[Mon Jul 20 07:24:25.216998 2026] [security2:error] [pid 116718:tid 116903] [client 14.224.227.113:56011] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hiZPWlhYV5NwZ9vUyrQAAACc"]
[Mon Jul 20 07:24:25.243128 2026] [security2:error] [pid 116718:tid 116931] [client 14.251.3.155:56012] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hiZPWlhYV5NwZ9vUysAAAAEM"]
[Mon Jul 20 07:24:25.262546 2026] [security2:error] [pid 116718:tid 116875] [client 14.225.17.146:50278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUynwAAAAs"], referer: http://chestermonty.com/backup
[Mon Jul 20 07:24:25.393420 2026] [security2:error] [pid 116718:tid 116962] [client 202.141.11.99:37057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyuAAAAGI"]
[Mon Jul 20 07:24:25.393522 2026] [security2:error] [pid 116718:tid 116962] [client 202.141.11.99:37057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyuAAAAGI"]
[Mon Jul 20 07:24:25.401884 2026] [security2:error] [pid 116718:tid 116985] [client 14.225.17.146:55662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyqAAAAHk"], referer: http://margaretspeckogawa.com/backup
[Mon Jul 20 07:24:25.413398 2026] [security2:error] [pid 116718:tid 116873] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyqgAAAAk"], referer: https://qualitycoatingsinspection.com/public/.git/HEAD
[Mon Jul 20 07:24:25.611571 2026] [security2:error] [pid 116718:tid 116980] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUywQAAAHQ"]
[Mon Jul 20 07:24:25.623408 2026] [security2:error] [pid 116718:tid 116762] [remote 100.42.189.89:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyzQAAWRs"]
[Mon Jul 20 07:24:25.657473 2026] [security2:error] [pid 116718:tid 116915] [client 77.110.127.138:65054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyzwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:25.657597 2026] [security2:error] [pid 116718:tid 116915] [client 77.110.127.138:65054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyzwAAADM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:25.813761 2026] [security2:error] [pid 116718:tid 116759] [remote 100.42.189.89:56714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4hiZPWlhYV5NwZ9vUy5QAAahg"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:24:25.909577 2026] [security2:error] [pid 116718:tid 116973] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUy0wAAAG0"], referer: https://qualitycoatingsinspection.com/src/.git/HEAD
[Mon Jul 20 07:24:25.964722 2026] [security2:error] [pid 116718:tid 116969] [client 77.110.127.138:65057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hiZPWlhYV5NwZ9vUy8AAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:25.964866 2026] [security2:error] [pid 116718:tid 116969] [client 77.110.127.138:65057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hiZPWlhYV5NwZ9vUy8AAAAGk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:26.099175 2026] [security2:error] [pid 116718:tid 116976] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUy8QAAAHA"]
[Mon Jul 20 07:24:26.229916 2026] [security2:error] [pid 116718:tid 116962] [client 136.158.60.21:18049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hipPWlhYV5NwZ9vUzBgAAAGI"]
[Mon Jul 20 07:24:26.230036 2026] [security2:error] [pid 116718:tid 116962] [client 136.158.60.21:18049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hipPWlhYV5NwZ9vUzBgAAAGI"]
[Mon Jul 20 07:24:26.306306 2026] [security2:error] [pid 116718:tid 116917] [client 14.225.17.146:54015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4hipPWlhYV5NwZ9vUzAgAAADU"], referer: https://chestermonty.com/backup
[Mon Jul 20 07:24:26.400332 2026] [security2:error] [pid 116718:tid 116918] [client 158.51.126.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.qualitycoatingsinspection.com"] [uri "/index.php"] [unique_id "al4hipPWlhYV5NwZ9vUzAAAAADY"], referer: https://qualitycoatingsinspection.com/backend/.git/HEAD
[Mon Jul 20 07:24:26.556669 2026] [security2:error] [pid 116718:tid 116941] [client 57.141.18.16:51284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hhpPWlhYV5NwZ9vUxgAAATRU"]
[Mon Jul 20 07:24:26.593950 2026] [security2:error] [pid 116718:tid 116878] [client 195.96.139.187:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.benbayly.co.nz"] [uri "/index.php"] [unique_id "al4hipPWlhYV5NwZ9vUzGQAADgg"]
[Mon Jul 20 07:24:26.713094 2026] [security2:error] [pid 116718:tid 116871] [client 104.234.53.74:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hipPWlhYV5NwZ9vUzJAAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:26.854193 2026] [security2:error] [pid 116718:tid 116739] [remote 103.187.169.251:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hipPWlhYV5NwZ9vUzNQAAOAQ"]
[Mon Jul 20 07:24:27.022412 2026] [security2:error] [pid 116718:tid 116948] [client 49.47.218.174:50623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzQQAAAFQ"]
[Mon Jul 20 07:24:27.022544 2026] [security2:error] [pid 116718:tid 116948] [client 49.47.218.174:50623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzQQAAAFQ"]
[Mon Jul 20 07:24:27.053445 2026] [security2:error] [pid 116718:tid 116913] [client 77.110.127.138:65022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzQgAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:27.053595 2026] [security2:error] [pid 116718:tid 116913] [client 77.110.127.138:65022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzQgAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:27.248275 2026] [security2:error] [pid 116718:tid 116955] [client 14.225.17.146:53888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzSwAAAFs"], referer: http://friendlyspreadsheet.com/backup
[Mon Jul 20 07:24:27.262667 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzUQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:27.262772 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzUQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:27.269920 2026] [security2:error] [pid 116718:tid 116793] [remote 103.187.169.251:50934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzUwAAZTo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:24:27.319517 2026] [security2:error] [pid 116718:tid 116983] [client 14.225.17.146:64402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzSAAAAHc"], referer: http://floorsourcestock.com/backup
[Mon Jul 20 07:24:27.332109 2026] [security2:error] [pid 116718:tid 116892] [client 50.116.65.227:27304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzXwAAABw"]
[Mon Jul 20 07:24:27.335029 2026] [security2:error] [pid 116718:tid 116880] [client 14.225.17.146:50359] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUy5wAAABA"], referer: http://recruitinginsight.us/backup
[Mon Jul 20 07:24:27.470548 2026] [security2:error] [pid 116718:tid 116824] [remote 20.153.140.50:39550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzawAAQ1k"]
[Mon Jul 20 07:24:27.615796 2026] [security2:error] [pid 116718:tid 116986] [client 66.249.72.229:63958] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.bundleofjoyandpoop.com"] [uri "/robots.txt"] [unique_id "al4hi5PWlhYV5NwZ9vUzcwAAAHo"]
[Mon Jul 20 07:24:27.822437 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzhgAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:27.822574 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzhgAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:27.859561 2026] [security2:error] [pid 116718:tid 116814] [remote 20.153.140.50:39550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzjAAAZE8"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 07:24:27.900035 2026] [security2:error] [pid 116718:tid 116829] [remote 91.142.222.105:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzkQAAWl4"]
[Mon Jul 20 07:24:27.963191 2026] [security2:error] [pid 116718:tid 116869] [client 36.93.152.155:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzmwAAAAU"]
[Mon Jul 20 07:24:27.963289 2026] [security2:error] [pid 116718:tid 116869] [client 36.93.152.155:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzmwAAAAU"]
[Mon Jul 20 07:24:28.064794 2026] [security2:error] [pid 116718:tid 116920] [client 103.176.215.66:55315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzowAAADg"]
[Mon Jul 20 07:24:28.065342 2026] [security2:error] [pid 116718:tid 116920] [client 103.176.215.66:55315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzowAAADg"]
[Mon Jul 20 07:24:28.079328 2026] [security2:error] [pid 116718:tid 116888] [client 104.234.53.85:50455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzogAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:28.142741 2026] [security2:error] [pid 116718:tid 116859] [remote 91.142.222.105:49232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzrQAAZXw"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:24:28.152853 2026] [security2:error] [pid 116718:tid 116873] [client 14.225.17.146:55608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzpgAAAAk"], referer: https://friendlyspreadsheet.com/backup
[Mon Jul 20 07:24:28.154491 2026] [security2:error] [pid 116718:tid 116932] [client 14.225.17.146:55819] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4hipPWlhYV5NwZ9vUzNwAAAEQ"], referer: http://elitetax-mi.com/backup
[Mon Jul 20 07:24:28.197458 2026] [security2:error] [pid 116718:tid 116990] [client 148.251.126.195:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ferrellroofing.com"] [uri "/index.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzqQAAAH4"]
[Mon Jul 20 07:24:28.277534 2026] [security2:error] [pid 116718:tid 116903] [client 77.110.127.138:65035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzvQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:28.277678 2026] [security2:error] [pid 116718:tid 116903] [client 77.110.127.138:65035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzvQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:28.453134 2026] [security2:error] [pid 116718:tid 116875] [client 14.225.17.146:55670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzugAAAAs"], referer: http://narv.co/backup
[Mon Jul 20 07:24:28.478547 2026] [security2:error] [pid 116718:tid 116965] [client 50.116.65.227:27328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hjJPWlhYV5NwZ9vUz0QAAAGU"]
[Mon Jul 20 07:24:28.489042 2026] [security2:error] [pid 116718:tid 116874] [client 143.44.185.218:37058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hjJPWlhYV5NwZ9vUz0gAAAAo"]
[Mon Jul 20 07:24:28.489149 2026] [security2:error] [pid 116718:tid 116874] [client 143.44.185.218:37058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hjJPWlhYV5NwZ9vUz0gAAAAo"]
[Mon Jul 20 07:24:28.491957 2026] [security2:error] [pid 116718:tid 116891] [client 50.116.65.227:27332] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hjJPWlhYV5NwZ9vUz0wAAABs"]
[Mon Jul 20 07:24:28.711396 2026] [security2:error] [pid 116718:tid 116985] [client 14.225.17.146:54118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4hjJPWlhYV5NwZ9vUzvwAAAHk"], referer: http://overloadcomedy.com/backup
[Mon Jul 20 07:24:28.712093 2026] [security2:error] [pid 116718:tid 116974] [client 57.141.18.95:51742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hiJPWlhYV5NwZ9vUyWAAAbkI"]
[Mon Jul 20 07:24:29.373071 2026] [security2:error] [pid 116718:tid 116939] [client 77.110.127.138:65074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0DwAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:29.373229 2026] [security2:error] [pid 116718:tid 116939] [client 77.110.127.138:65074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0DwAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:29.446252 2026] [security2:error] [pid 116718:tid 116914] [client 216.24.212.27:22871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0GQAAADI"]
[Mon Jul 20 07:24:29.452051 2026] [security2:error] [pid 116718:tid 116888] [client 14.225.17.146:54172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0DQAAABg"], referer: https://narv.co/backup
[Mon Jul 20 07:24:29.455255 2026] [security2:error] [pid 116718:tid 116899] [client 216.24.212.79:53617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0FwAAACM"]
[Mon Jul 20 07:24:29.569293 2026] [security2:error] [pid 116718:tid 116932] [client 191.202.66.27:50938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0JgAAAEQ"]
[Mon Jul 20 07:24:29.569416 2026] [security2:error] [pid 116718:tid 116932] [client 191.202.66.27:50938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0JgAAAEQ"]
[Mon Jul 20 07:24:29.705093 2026] [security2:error] [pid 116718:tid 116946] [client 103.106.165.44:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0LgAAAFI"]
[Mon Jul 20 07:24:29.705202 2026] [security2:error] [pid 116718:tid 116946] [client 103.106.165.44:53724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0LgAAAFI"]
[Mon Jul 20 07:24:29.933918 2026] [security2:error] [pid 116718:tid 116968] [client 57.141.18.69:20134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hiZPWlhYV5NwZ9vUyzAAAaCA"]
[Mon Jul 20 07:24:29.942779 2026] [security2:error] [pid 116718:tid 116823] [remote 64.225.121.94:42246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hjZPWlhYV5NwZ9vU0OgAAPVg"]
[Mon Jul 20 07:24:29.964785 2026] [security2:error] [pid 116718:tid 116966] [client 14.225.17.146:54645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4hjJPWlhYV5NwZ9vUz2gAAAGY"], referer: http://balticsteelmgmt.com/backup
[Mon Jul 20 07:24:30.126910 2026] [security2:error] [pid 116718:tid 116955] [client 201.27.111.74:57573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0SwAAAFs"]
[Mon Jul 20 07:24:30.127065 2026] [security2:error] [pid 116718:tid 116955] [client 201.27.111.74:57573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0SwAAAFs"]
[Mon Jul 20 07:24:30.153923 2026] [security2:error] [pid 116718:tid 116759] [remote 64.225.121.94:42246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0TAAAYBg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:24:30.259212 2026] [security2:error] [pid 116718:tid 116944] [client 157.20.138.62:51512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0WwAAAFA"]
[Mon Jul 20 07:24:30.259363 2026] [security2:error] [pid 116718:tid 116944] [client 157.20.138.62:51512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0WwAAAFA"]
[Mon Jul 20 07:24:30.310919 2026] [security2:error] [pid 116718:tid 116901] [client 88.241.67.160:56093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0XwAAACU"]
[Mon Jul 20 07:24:30.311299 2026] [security2:error] [pid 116718:tid 116901] [client 88.241.67.160:56093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0XwAAACU"]
[Mon Jul 20 07:24:30.377031 2026] [security2:error] [pid 116718:tid 116903] [client 179.127.84.238:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0ZwAAACc"]
[Mon Jul 20 07:24:30.377160 2026] [security2:error] [pid 116718:tid 116903] [client 179.127.84.238:52206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0ZwAAACc"]
[Mon Jul 20 07:24:30.426466 2026] [security2:error] [pid 116718:tid 116991] [client 82.102.18.116:50498] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4hjpPWlhYV5NwZ9vU0agAAAH8"]
[Mon Jul 20 07:24:30.787952 2026] [security2:error] [pid 116718:tid 116911] [client 77.110.127.138:65056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0fgAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:30.788063 2026] [security2:error] [pid 116718:tid 116911] [client 77.110.127.138:65056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0fgAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:30.801621 2026] [security2:error] [pid 116718:tid 116868] [client 82.102.18.116:50514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.theablesea.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0gAAAAAQ"]
[Mon Jul 20 07:24:30.807639 2026] [security2:error] [pid 116718:tid 116986] [client 20.199.97.14:4929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4hjpPWlhYV5NwZ9vU0gQAAAHo"]
[Mon Jul 20 07:24:30.889874 2026] [security2:error] [pid 116718:tid 116786] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0jAAAHjM"]
[Mon Jul 20 07:24:30.889998 2026] [security2:error] [pid 116718:tid 116894] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0jAAAHjM"]
[Mon Jul 20 07:24:30.966266 2026] [security2:error] [pid 116718:tid 116891] [client 20.199.97.14:4929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4hjpPWlhYV5NwZ9vU0jwAAABs"]
[Mon Jul 20 07:24:31.047242 2026] [security2:error] [pid 116718:tid 116906] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0jgAAKgg"], referer: http://aleishapenny.ca/backup
[Mon Jul 20 07:24:31.210962 2026] [security2:error] [pid 116718:tid 116747] [remote 15.206.251.117:46786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4hj5PWlhYV5NwZ9vU0nwAAfQw"]
[Mon Jul 20 07:24:31.281016 2026] [security2:error] [pid 116718:tid 116943] [client 82.102.18.116:50520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4hj5PWlhYV5NwZ9vU0qwAAAE8"]
[Mon Jul 20 07:24:31.452247 2026] [security2:error] [pid 116718:tid 116927] [client 104.234.53.80:56595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hj5PWlhYV5NwZ9vU0tAAAAD8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:31.547104 2026] [security2:error] [pid 116718:tid 116889] [client 57.141.18.29:49068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hi5PWlhYV5NwZ9vUzRQAAGRY"]
[Mon Jul 20 07:24:31.614687 2026] [security2:error] [pid 116718:tid 116950] [client 77.110.127.138:65081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hj5PWlhYV5NwZ9vU0wwAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:31.614824 2026] [security2:error] [pid 116718:tid 116950] [client 77.110.127.138:65081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hj5PWlhYV5NwZ9vU0wwAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:31.620983 2026] [security2:error] [pid 116718:tid 116940] [client 82.102.18.116:50530] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4hj5PWlhYV5NwZ9vU0xAAAAEw"]
[Mon Jul 20 07:24:31.627207 2026] [security2:error] [pid 116718:tid 116820] [remote 15.206.251.117:46786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4hj5PWlhYV5NwZ9vU0xwAAJFU"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:24:31.664816 2026] [security2:error] [pid 116718:tid 116902] [client 49.37.242.14:50891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hj5PWlhYV5NwZ9vU00AAAACY"]
[Mon Jul 20 07:24:31.664904 2026] [security2:error] [pid 116718:tid 116902] [client 49.37.242.14:50891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hj5PWlhYV5NwZ9vU00AAAACY"]
[Mon Jul 20 07:24:31.933150 2026] [security2:error] [pid 116718:tid 116934] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4hj5PWlhYV5NwZ9vU03AAARlQ"], referer: https://aleishapenny.ca/backup
[Mon Jul 20 07:24:31.956474 2026] [security2:error] [pid 116718:tid 116902] [client 82.102.18.116:50538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4hj5PWlhYV5NwZ9vU07wAAACY"]
[Mon Jul 20 07:24:31.995958 2026] [security2:error] [pid 116718:tid 116821] [remote 72.167.132.114:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hj5PWlhYV5NwZ9vU08QAAPVY"]
[Mon Jul 20 07:24:32.022629 2026] [security2:error] [pid 116718:tid 116888] [client 117.211.236.168:62927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hkJPWlhYV5NwZ9vU08gAAABg"]
[Mon Jul 20 07:24:32.022743 2026] [security2:error] [pid 116718:tid 116888] [client 117.211.236.168:62927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hkJPWlhYV5NwZ9vU08gAAABg"]
[Mon Jul 20 07:24:32.236045 2026] [security2:error] [pid 116718:tid 116779] [remote 72.167.132.114:38428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hkJPWlhYV5NwZ9vU1BAAANyw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:24:32.263659 2026] [security2:error] [pid 116718:tid 116990] [client 154.192.123.127:18097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hkJPWlhYV5NwZ9vU1CQAAAH4"]
[Mon Jul 20 07:24:32.263776 2026] [security2:error] [pid 116718:tid 116990] [client 154.192.123.127:18097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hkJPWlhYV5NwZ9vU1CQAAAH4"]
[Mon Jul 20 07:24:32.300543 2026] [security2:error] [pid 116718:tid 116883] [client 82.102.18.116:50554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4hkJPWlhYV5NwZ9vU1DQAAABM"]
[Mon Jul 20 07:24:32.644377 2026] [security2:error] [pid 116718:tid 116929] [client 82.102.18.116:50556] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4hkJPWlhYV5NwZ9vU1JQAAAEE"]
[Mon Jul 20 07:24:32.932822 2026] [security2:error] [pid 116718:tid 116843] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hkJPWlhYV5NwZ9vU1QwAAb2w"]
[Mon Jul 20 07:24:32.932958 2026] [security2:error] [pid 116718:tid 116975] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hkJPWlhYV5NwZ9vU1QwAAb2w"]
[Mon Jul 20 07:24:32.969017 2026] [security2:error] [pid 116718:tid 116890] [client 82.102.18.116:50570] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4hkJPWlhYV5NwZ9vU1RgAAABo"]
[Mon Jul 20 07:24:33.129552 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1TwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:33.129669 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1TwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:33.168129 2026] [security2:error] [pid 116718:tid 116899] [client 98.159.234.160:41325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1VgAAACM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:24:33.233844 2026] [security2:error] [pid 116718:tid 116912] [client 14.225.17.146:53704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1TAAAADA"], referer: http://nurturemarple.co.uk/backup
[Mon Jul 20 07:24:33.309198 2026] [security2:error] [pid 116718:tid 116961] [client 82.102.18.116:2298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4hkZPWlhYV5NwZ9vU1ZgAAAGE"]
[Mon Jul 20 07:24:33.433631 2026] [security2:error] [pid 116718:tid 116868] [client 77.110.127.138:65055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1agAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:33.433721 2026] [security2:error] [pid 116718:tid 116868] [client 77.110.127.138:65055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1agAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:33.536313 2026] [security2:error] [pid 116718:tid 116990] [client 50.116.65.227:31194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1aAAAAH4"]
[Mon Jul 20 07:24:33.590847 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1fQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:33.590948 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1fQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:33.622485 2026] [security2:error] [pid 116718:tid 116893] [client 82.102.18.116:50592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4hkZPWlhYV5NwZ9vU1fwAAAB0"]
[Mon Jul 20 07:24:33.751478 2026] [security2:error] [pid 116718:tid 116952] [client 50.116.65.227:31196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1cwAAAFg"]
[Mon Jul 20 07:24:33.947105 2026] [security2:error] [pid 116718:tid 116897] [client 82.102.18.116:50598] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4hkZPWlhYV5NwZ9vU1pwAAACE"]
[Mon Jul 20 07:24:34.192191 2026] [security2:error] [pid 116718:tid 116881] [client 14.225.17.146:58948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4hkpPWlhYV5NwZ9vU1rQAAABE"], referer: https://nurturemarple.co.uk/backup
[Mon Jul 20 07:24:34.285425 2026] [security2:error] [pid 116718:tid 116964] [client 82.102.18.116:50610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4hkpPWlhYV5NwZ9vU1vgAAAGQ"]
[Mon Jul 20 07:24:34.366100 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:65027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU1wAAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.366193 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:65027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU1wAAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.628223 2026] [security2:error] [pid 116718:tid 116935] [client 154.208.48.130:53569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hkpPWlhYV5NwZ9vU10AAAAEc"]
[Mon Jul 20 07:24:34.628319 2026] [security2:error] [pid 116718:tid 116935] [client 154.208.48.130:53569] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hkpPWlhYV5NwZ9vU10AAAAEc"]
[Mon Jul 20 07:24:34.630624 2026] [security2:error] [pid 116718:tid 116980] [client 82.102.18.116:1046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4hkpPWlhYV5NwZ9vU10QAAAHQ"]
[Mon Jul 20 07:24:34.807517 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU13QAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.807602 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU13QAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.865587 2026] [security2:error] [pid 116718:tid 116901] [client 77.110.127.138:65045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU13wAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.865679 2026] [security2:error] [pid 116718:tid 116901] [client 77.110.127.138:65045] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU13wAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.919372 2026] [security2:error] [pid 116718:tid 116975] [client 77.110.127.138:65069] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hkpPWlhYV5NwZ9vU14gAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:34.921228 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU14wAAAAs"]
[Mon Jul 20 07:24:34.921323 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hkpPWlhYV5NwZ9vU14wAAAAs"]
[Mon Jul 20 07:24:35.052346 2026] [security2:error] [pid 116718:tid 116972] [client 57.141.18.95:31480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hjpPWlhYV5NwZ9vU0aAAAbB4"]
[Mon Jul 20 07:24:35.074439 2026] [security2:error] [pid 116718:tid 116891] [client 77.110.127.138:65092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hk5PWlhYV5NwZ9vU18QAAABs"]
[Mon Jul 20 07:24:35.074531 2026] [security2:error] [pid 116718:tid 116891] [client 77.110.127.138:65092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hk5PWlhYV5NwZ9vU18QAAABs"]
[Mon Jul 20 07:24:35.084976 2026] [security2:error] [pid 116718:tid 116837] [remote 8.217.108.67:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4hk5PWlhYV5NwZ9vU17QAABGY"]
[Mon Jul 20 07:24:35.208778 2026] [security2:error] [pid 116718:tid 116864] [client 82.102.18.116:50626] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4hk5PWlhYV5NwZ9vU1_gAAAAA"]
[Mon Jul 20 07:24:35.536443 2026] [security2:error] [pid 116718:tid 116923] [client 82.102.18.116:50632] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4hk5PWlhYV5NwZ9vU2HwAAADs"]
[Mon Jul 20 07:24:35.579492 2026] [security2:error] [pid 116718:tid 116888] [client 3.75.183.99:29164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hk5PWlhYV5NwZ9vU2IwAAABg"]
[Mon Jul 20 07:24:35.579611 2026] [security2:error] [pid 116718:tid 116888] [client 3.75.183.99:29164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hk5PWlhYV5NwZ9vU2IwAAABg"]
[Mon Jul 20 07:24:35.877502 2026] [security2:error] [pid 116718:tid 116970] [client 82.102.18.116:50636] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4hk5PWlhYV5NwZ9vU2OQAAAGo"]
[Mon Jul 20 07:24:36.019792 2026] [security2:error] [pid 116718:tid 116819] [remote 217.61.143.92:52414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4hlJPWlhYV5NwZ9vU2QQAAP1Q"]
[Mon Jul 20 07:24:36.226589 2026] [security2:error] [pid 116718:tid 116948] [client 82.102.18.116:50638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4hlJPWlhYV5NwZ9vU2TwAAAFQ"]
[Mon Jul 20 07:24:36.263476 2026] [security2:error] [pid 116718:tid 116833] [remote 217.61.143.92:52414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4hlJPWlhYV5NwZ9vU2VgAAM2I"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 07:24:36.530879 2026] [security2:error] [pid 116718:tid 116922] [client 74.208.214.194:37632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hlJPWlhYV5NwZ9vU2bgAAADo"]
[Mon Jul 20 07:24:36.569458 2026] [security2:error] [pid 116718:tid 116980] [client 82.102.18.116:50646] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webdisk.theablesea.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4hlJPWlhYV5NwZ9vU2cAAAAHQ"]
[Mon Jul 20 07:24:36.775613 2026] [security2:error] [pid 116718:tid 116951] [client 57.141.18.117:38698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hj5PWlhYV5NwZ9vU03QAAV0A"]
[Mon Jul 20 07:24:36.878643 2026] [security2:error] [pid 116718:tid 116856] [remote 57.141.18.124:60984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4hlJPWlhYV5NwZ9vU2lQAAZXk"]
[Mon Jul 20 07:24:37.046006 2026] [security2:error] [pid 116718:tid 116894] [client 136.158.60.21:19667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2pQAAAB4"]
[Mon Jul 20 07:24:37.046097 2026] [security2:error] [pid 116718:tid 116894] [client 136.158.60.21:19667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2pQAAAB4"]
[Mon Jul 20 07:24:37.203380 2026] [security2:error] [pid 116718:tid 116871] [client 216.73.217.19:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2qQAAAAc"]
[Mon Jul 20 07:24:37.278468 2026] [security2:error] [pid 116718:tid 116911] [client 77.110.127.138:65100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2twAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:37.278544 2026] [security2:error] [pid 116718:tid 116911] [client 77.110.127.138:65100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2twAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:37.438225 2026] [security2:error] [pid 116718:tid 116892] [client 173.239.254.57:40007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hoomanr.com"] [uri "/wp-login.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2xAAAABw"]
[Mon Jul 20 07:24:37.494306 2026] [security2:error] [pid 116718:tid 116967] [client 49.47.218.174:51153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2zgAAAGc"]
[Mon Jul 20 07:24:37.494429 2026] [security2:error] [pid 116718:tid 116967] [client 49.47.218.174:51153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hlZPWlhYV5NwZ9vU2zgAAAGc"]
[Mon Jul 20 07:24:37.571032 2026] [security2:error] [pid 116718:tid 116922] [client 74.208.214.194:37634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hlZPWlhYV5NwZ9vU21QAAADo"]
[Mon Jul 20 07:24:37.725243 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:65103] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hlZPWlhYV5NwZ9vU21wAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:38.047996 2026] [security2:error] [pid 116718:tid 116910] [client 57.141.18.99:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hlZPWlhYV5NwZ9vU27AAAAC4"]
[Mon Jul 20 07:24:38.164078 2026] [security2:error] [pid 116718:tid 116935] [client 14.225.17.146:55346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4hlpPWlhYV5NwZ9vU2-AAAAEc"], referer: http://carolinapressurewashers.com/backup
[Mon Jul 20 07:24:38.245740 2026] [security2:error] [pid 116718:tid 116978] [client 14.225.17.146:55354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4hlZPWlhYV5NwZ9vU29QAAAHI"], referer: http://www.justinagrayman.com/backup
[Mon Jul 20 07:24:38.378552 2026] [security2:error] [pid 116718:tid 116965] [client 50.116.65.227:31224] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hlpPWlhYV5NwZ9vU3GwAAAGU"]
[Mon Jul 20 07:24:38.388211 2026] [security2:error] [pid 116718:tid 116914] [client 50.116.65.227:31226] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hlpPWlhYV5NwZ9vU3HQAAADI"]
[Mon Jul 20 07:24:38.410071 2026] [security2:error] [pid 116718:tid 116985] [client 57.141.18.1:22806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hkZPWlhYV5NwZ9vU1cAAAeUU"]
[Mon Jul 20 07:24:38.490338 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:64935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3JgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:38.490425 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:64935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3JgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:38.525915 2026] [security2:error] [pid 116718:tid 116989] [client 36.93.152.155:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3MQAAAH0"]
[Mon Jul 20 07:24:38.526032 2026] [security2:error] [pid 116718:tid 116989] [client 36.93.152.155:63288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3MQAAAH0"]
[Mon Jul 20 07:24:38.637503 2026] [security2:error] [pid 116718:tid 116947] [client 103.176.215.66:55857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3NwAAAFM"]
[Mon Jul 20 07:24:38.637619 2026] [security2:error] [pid 116718:tid 116947] [client 103.176.215.66:55857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3NwAAAFM"]
[Mon Jul 20 07:24:38.641708 2026] [security2:error] [pid 116718:tid 116896] [client 14.225.17.146:63764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4hlJPWlhYV5NwZ9vU2lwAAACA"], referer: http://according2plant.com/backup
[Mon Jul 20 07:24:38.697567 2026] [security2:error] [pid 116718:tid 116791] [remote 8.217.108.67:59762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3OwAAIjg"], referer: https://mail.transamericagrid.com/wp-login.php
[Mon Jul 20 07:24:39.082833 2026] [security2:error] [pid 116718:tid 116988] [client 57.141.18.14:62608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hkpPWlhYV5NwZ9vU1sgAAfDE"]
[Mon Jul 20 07:24:39.195399 2026] [security2:error] [pid 116718:tid 116969] [client 57.141.18.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3UQAAAGk"]
[Mon Jul 20 07:24:39.200283 2026] [security2:error] [pid 116718:tid 116901] [client 20.220.225.223:19458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3WwAAACU"]
[Mon Jul 20 07:24:39.200405 2026] [security2:error] [pid 116718:tid 116901] [client 20.220.225.223:19458] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3WwAAACU"]
[Mon Jul 20 07:24:39.736537 2026] [security2:error] [pid 116718:tid 116865] [client 57.141.18.71:43988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hkpPWlhYV5NwZ9vU14QAAAQg"]
[Mon Jul 20 07:24:39.808512 2026] [security2:error] [pid 116718:tid 116879] [client 77.110.127.138:65098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3hwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:39.808609 2026] [security2:error] [pid 116718:tid 116879] [client 77.110.127.138:65098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3hwAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:39.926602 2026] [security2:error] [pid 116718:tid 116918] [client 104.234.53.57:49299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3jAAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:39.984468 2026] [security2:error] [pid 116718:tid 116818] [remote 188.40.28.4:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3jQAAEVM"]
[Mon Jul 20 07:24:40.043355 2026] [security2:error] [pid 116718:tid 116825] [remote 173.249.4.11:35089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3lQAAM1o"]
[Mon Jul 20 07:24:40.189441 2026] [security2:error] [pid 116718:tid 116815] [remote 188.40.28.4:44146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3pQAAZVA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:24:40.227214 2026] [security2:error] [pid 116718:tid 116832] [remote 173.249.4.11:35089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3qgAAV2E"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 07:24:40.247009 2026] [security2:error] [pid 116718:tid 116944] [client 103.106.165.44:54205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3rAAAAFA"]
[Mon Jul 20 07:24:40.247124 2026] [security2:error] [pid 116718:tid 116944] [client 103.106.165.44:54205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3rAAAAFA"]
[Mon Jul 20 07:24:40.254130 2026] [security2:error] [pid 116718:tid 116987] [client 57.141.18.31:27614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hk5PWlhYV5NwZ9vU2DQAAezA"]
[Mon Jul 20 07:24:40.255475 2026] [security2:error] [pid 116718:tid 116914] [client 77.110.127.138:65110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hmJPWlhYV5NwZ9vU3rgAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:40.291978 2026] [security2:error] [pid 116718:tid 116938] [client 191.202.66.27:51426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3tQAAAEo"]
[Mon Jul 20 07:24:40.292058 2026] [security2:error] [pid 116718:tid 116938] [client 191.202.66.27:51426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3tQAAAEo"]
[Mon Jul 20 07:24:40.606870 2026] [security2:error] [pid 116718:tid 116920] [client 201.27.111.74:58074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3wwAAADg"]
[Mon Jul 20 07:24:40.606996 2026] [security2:error] [pid 116718:tid 116920] [client 201.27.111.74:58074] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU3wwAAADg"]
[Mon Jul 20 07:24:40.759588 2026] [security2:error] [pid 116718:tid 116988] [client 88.241.67.160:54836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU30AAAAHw"]
[Mon Jul 20 07:24:40.759992 2026] [security2:error] [pid 116718:tid 116988] [client 88.241.67.160:54836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU30AAAAHw"]
[Mon Jul 20 07:24:40.888851 2026] [security2:error] [pid 116718:tid 116874] [client 43.157.22.109:39900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.22.157.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/downloads/tutorials/presentations/yield_test_info/index.php"] [unique_id "al4hmJPWlhYV5NwZ9vU31wAAAAo"]
[Mon Jul 20 07:24:40.978423 2026] [security2:error] [pid 116718:tid 116895] [client 157.20.138.62:52075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU33wAAAB8"]
[Mon Jul 20 07:24:40.978574 2026] [security2:error] [pid 116718:tid 116895] [client 157.20.138.62:52075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hmJPWlhYV5NwZ9vU33wAAAB8"]
[Mon Jul 20 07:24:41.037569 2026] [security2:error] [pid 116718:tid 116967] [client 179.127.84.238:52701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hmZPWlhYV5NwZ9vU35AAAAGc"]
[Mon Jul 20 07:24:41.037668 2026] [security2:error] [pid 116718:tid 116967] [client 179.127.84.238:52701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hmZPWlhYV5NwZ9vU35AAAAGc"]
[Mon Jul 20 07:24:41.141860 2026] [security2:error] [pid 116718:tid 116868] [client 77.110.127.138:65105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU39QAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.141970 2026] [security2:error] [pid 116718:tid 116868] [client 77.110.127.138:65105] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU39QAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.252619 2026] [core:error] [pid 116718:tid 116985] [client 101.47.15.119:39114] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Mon Jul 20 07:24:41.273405 2026] [security2:error] [pid 116718:tid 116943] [client 143.44.185.218:39124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hmZPWlhYV5NwZ9vU3_gAAAE8"]
[Mon Jul 20 07:24:41.273512 2026] [security2:error] [pid 116718:tid 116943] [client 143.44.185.218:39124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hmZPWlhYV5NwZ9vU3_gAAAE8"]
[Mon Jul 20 07:24:41.274214 2026] [security2:error] [pid 116718:tid 116928] [client 57.141.18.34:45168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hlJPWlhYV5NwZ9vU2ZwAAQGg"]
[Mon Jul 20 07:24:41.322457 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:65107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4AwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.322556 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:65107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4AwAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.403281 2026] [security2:error] [pid 116718:tid 116960] [client 45.157.112.60:27307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4CAAAAGA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:24:41.482660 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:65116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4DwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.482768 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:65116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4DwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.484972 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:65114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4AAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.530137 2026] [security2:error] [pid 116718:tid 116752] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4EAAAchE"]
[Mon Jul 20 07:24:41.530270 2026] [security2:error] [pid 116718:tid 116978] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4EAAAchE"]
[Mon Jul 20 07:24:41.711395 2026] [security2:error] [pid 116718:tid 116961] [client 14.225.17.146:57263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4GwAAAGE"], referer: http://ravmike.com/backup
[Mon Jul 20 07:24:41.924312 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65117] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4KQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:41.924399 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65117] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmZPWlhYV5NwZ9vU4KQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.375542 2026] [security2:error] [pid 116718:tid 116781] [remote 182.77.62.24:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4SwAAai4"]
[Mon Jul 20 07:24:42.411193 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4UAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.411276 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4UAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.521592 2026] [security2:error] [pid 116718:tid 116862] [remote 103.28.36.200:47882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4VwAAGn8"]
[Mon Jul 20 07:24:42.521884 2026] [security2:error] [pid 116718:tid 116914] [client 104.234.53.69:36649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4WAAAADI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:42.616214 2026] [security2:error] [pid 116718:tid 116969] [client 14.225.17.146:58650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4WwAAAGk"], referer: https://ravmike.com/backup
[Mon Jul 20 07:24:42.687009 2026] [security2:error] [pid 116718:tid 116866] [client 77.110.127.138:65120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4ZwAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.687098 2026] [security2:error] [pid 116718:tid 116866] [client 77.110.127.138:65120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4ZwAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.743875 2026] [security2:error] [pid 116718:tid 116919] [client 77.110.127.138:65121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4awAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.743987 2026] [security2:error] [pid 116718:tid 116919] [client 77.110.127.138:65121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4awAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:42.797903 2026] [security2:error] [pid 116718:tid 116936] [client 154.192.123.127:18608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4cAAAAEg"]
[Mon Jul 20 07:24:42.798011 2026] [security2:error] [pid 116718:tid 116936] [client 154.192.123.127:18608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4cAAAAEg"]
[Mon Jul 20 07:24:42.876806 2026] [security2:error] [pid 116718:tid 116792] [remote 182.77.62.24:43910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4dwAAKDk"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:24:42.961221 2026] [security2:error] [pid 116718:tid 116769] [remote 103.28.36.200:47882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4gwAAMyI"], referer: https://iagdevelopments.com/wp-login.php
[Mon Jul 20 07:24:42.974513 2026] [security2:error] [pid 116718:tid 116739] [remote 57.141.18.77:51420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3928178"] [unique_id "al4hmpPWlhYV5NwZ9vU4hAAAYgQ"]
[Mon Jul 20 07:24:43.069039 2026] [security2:error] [pid 116718:tid 116928] [client 77.110.127.138:65124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4jQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:43.069132 2026] [security2:error] [pid 116718:tid 116928] [client 77.110.127.138:65124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4jQAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:43.133638 2026] [security2:error] [pid 116718:tid 116889] [client 20.220.225.223:19974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4lQAAABk"]
[Mon Jul 20 07:24:43.133724 2026] [security2:error] [pid 116718:tid 116889] [client 20.220.225.223:19974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4lQAAABk"]
[Mon Jul 20 07:24:43.320618 2026] [security2:error] [pid 116718:tid 116904] [client 144.126.229.46:64247] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.jmfinnfilms.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4ogAAACg"]
[Mon Jul 20 07:24:43.483278 2026] [security2:error] [pid 116718:tid 116885] [client 57.141.18.12:46456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hlpPWlhYV5NwZ9vU3KwAAFUM"]
[Mon Jul 20 07:24:43.577332 2026] [security2:error] [pid 116718:tid 116816] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4uwAAVVE"]
[Mon Jul 20 07:24:43.577483 2026] [security2:error] [pid 116718:tid 116949] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4uwAAVVE"]
[Mon Jul 20 07:24:43.596689 2026] [security2:error] [pid 116718:tid 116931] [client 117.211.236.168:63532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4vAAAAEM"]
[Mon Jul 20 07:24:43.596793 2026] [security2:error] [pid 116718:tid 116931] [client 117.211.236.168:63532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hm5PWlhYV5NwZ9vU4vAAAAEM"]
[Mon Jul 20 07:24:43.841104 2026] [security2:error] [pid 116718:tid 116876] [client 49.37.242.14:51400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hm5PWlhYV5NwZ9vU40wAAAAw"]
[Mon Jul 20 07:24:43.841220 2026] [security2:error] [pid 116718:tid 116876] [client 49.37.242.14:51400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hm5PWlhYV5NwZ9vU40wAAAAw"]
[Mon Jul 20 07:24:43.904720 2026] [security2:error] [pid 116718:tid 116990] [client 77.110.127.138:65127] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hm5PWlhYV5NwZ9vU43QAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:43.909300 2026] [security2:error] [pid 116718:tid 116946] [client 66.249.73.198:57614] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.topspot.com.pk"] [uri "/robots.txt"] [unique_id "al4hm5PWlhYV5NwZ9vU43gAAAFI"]
[Mon Jul 20 07:24:44.007799 2026] [security2:error] [pid 116718:tid 116899] [client 14.225.17.146:55083] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4hm5PWlhYV5NwZ9vU44gAAACM"], referer: http://adultdaycarereno.com/backup
[Mon Jul 20 07:24:44.213556 2026] [security2:error] [pid 116718:tid 116916] [client 14.225.17.146:58546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4hm5PWlhYV5NwZ9vU45QAAADQ"], referer: http://latiendadejorge.com.gt/backup
[Mon Jul 20 07:24:44.266769 2026] [security2:error] [pid 116718:tid 116871] [client 14.225.17.146:53781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4eAAAAAc"], referer: http://dadanetnet.net/backup
[Mon Jul 20 07:24:44.425857 2026] [security2:error] [pid 116718:tid 116903] [client 40.77.167.4:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4hnJPWlhYV5NwZ9vU45gAAACc"]
[Mon Jul 20 07:24:44.547221 2026] [security2:error] [pid 116718:tid 116892] [client 57.141.18.39:43631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3egAAHGA"]
[Mon Jul 20 07:24:44.712912 2026] [security2:error] [pid 116718:tid 116937] [client 13.233.207.33:23152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hnJPWlhYV5NwZ9vU5FAAAAEk"]
[Mon Jul 20 07:24:44.713022 2026] [security2:error] [pid 116718:tid 116937] [client 13.233.207.33:23152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hnJPWlhYV5NwZ9vU5FAAAAEk"]
[Mon Jul 20 07:24:44.752216 2026] [security2:error] [pid 116718:tid 116880] [client 114.119.149.218:36675] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bitesofwealth.com"] [uri "/robots.txt"] [unique_id "al4hnJPWlhYV5NwZ9vU5GAAAABA"], referer: https://bitesofwealth.com/robots.txt
[Mon Jul 20 07:24:44.894947 2026] [security2:error] [pid 116718:tid 116874] [client 14.225.17.146:55162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4hnJPWlhYV5NwZ9vU5JQAAAAo"], referer: https://adultdaycarereno.com/backup
[Mon Jul 20 07:24:44.924086 2026] [security2:error] [pid 116718:tid 116981] [client 57.141.18.30:33450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hl5PWlhYV5NwZ9vU3iwAAdSw"]
[Mon Jul 20 07:24:45.122686 2026] [security2:error] [pid 116718:tid 116851] [remote 78.46.157.202:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5OAAALHQ"]
[Mon Jul 20 07:24:45.327148 2026] [security2:error] [pid 116718:tid 116850] [remote 78.46.157.202:39304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5RAAAC3M"], referer: https://mail.walkingandtalking.net/wp-login.php
[Mon Jul 20 07:24:45.338086 2026] [security2:error] [pid 116718:tid 116746] [remote 57.141.18.107:50058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4hnZPWlhYV5NwZ9vU5RQAAEAs"]
[Mon Jul 20 07:24:45.596574 2026] [security2:error] [pid 116718:tid 116879] [client 154.208.48.130:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5YAAAAA8"]
[Mon Jul 20 07:24:45.596887 2026] [security2:error] [pid 116718:tid 116879] [client 154.208.48.130:54102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5YAAAAA8"]
[Mon Jul 20 07:24:45.597906 2026] [security2:error] [pid 116718:tid 116760] [remote 5.161.225.162:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5XwAAJhk"]
[Mon Jul 20 07:24:45.829129 2026] [security2:error] [pid 116718:tid 116857] [remote 5.161.225.162:37442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5bQAAVXo"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:24:45.853897 2026] [security2:error] [pid 116718:tid 116983] [client 14.225.17.146:57019] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4hnJPWlhYV5NwZ9vU46wAAAHc"], referer: http://fineartsfactory.net/backup
[Mon Jul 20 07:24:45.897123 2026] [security2:error] [pid 116718:tid 116909] [client 77.110.127.138:65136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5XgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.164308 2026] [security2:error] [pid 116718:tid 116959] [client 77.110.127.138:65140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5igAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.164382 2026] [security2:error] [pid 116718:tid 116959] [client 77.110.127.138:65140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5igAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.173500 2026] [security2:error] [pid 116718:tid 116935] [client 57.141.18.61:59506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hmZPWlhYV5NwZ9vU39wAAR0Q"]
[Mon Jul 20 07:24:46.312827 2026] [security2:error] [pid 116718:tid 116989] [client 77.110.127.138:65142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5nwAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.312987 2026] [security2:error] [pid 116718:tid 116989] [client 77.110.127.138:65142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5nwAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.315824 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:65143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5oQAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.315915 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:65143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5oQAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.348914 2026] [security2:error] [pid 116718:tid 116905] [client 104.234.53.75:55899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5ogAAACk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:46.438565 2026] [security2:error] [pid 116718:tid 116960] [client 77.110.127.138:65141] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5lQAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.452775 2026] [security2:error] [pid 116718:tid 116920] [client 202.141.11.99:24496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5pwAAADg"]
[Mon Jul 20 07:24:46.452957 2026] [security2:error] [pid 116718:tid 116920] [client 202.141.11.99:24496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5pwAAADg"]
[Mon Jul 20 07:24:46.584845 2026] [security2:error] [pid 116718:tid 116934] [client 158.173.89.95:57407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5rwAAAEY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:24:46.644155 2026] [security2:error] [pid 116718:tid 116975] [client 14.225.17.146:52936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5YQAAAG8"], referer: http://ncsynchro.com/backup
[Mon Jul 20 07:24:46.735472 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:65146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5uQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.735566 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:65146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5uQAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:46.836732 2026] [security2:error] [pid 116718:tid 116770] [remote 192.241.143.148:48972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5wQAAeiM"]
[Mon Jul 20 07:24:46.836898 2026] [security2:error] [pid 116718:tid 116986] [client 192.241.143.148:48972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5wQAAeiM"]
[Mon Jul 20 07:24:46.844512 2026] [security2:error] [pid 116718:tid 116912] [client 14.225.17.146:55192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4hnJPWlhYV5NwZ9vU5KAAAADA"], referer: http://jvcmotorsports.com/backup
[Mon Jul 20 07:24:47.001087 2026] [security2:error] [pid 116718:tid 116957] [client 57.141.18.29:57748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4NQAAXVg"]
[Mon Jul 20 07:24:47.120960 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hn5PWlhYV5NwZ9vU54AAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:47.121054 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hn5PWlhYV5NwZ9vU54AAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:47.234900 2026] [security2:error] [pid 116718:tid 116914] [client 77.110.127.138:65147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hn5PWlhYV5NwZ9vU50QAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:47.330005 2026] [security2:error] [pid 116718:tid 116867] [client 77.110.127.138:65151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hn5PWlhYV5NwZ9vU59AAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:47.330117 2026] [security2:error] [pid 116718:tid 116867] [client 77.110.127.138:65151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hn5PWlhYV5NwZ9vU59AAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:47.421812 2026] [security2:error] [pid 116718:tid 116951] [client 20.220.225.223:19505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/asd67.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6AAAAAFc"]
[Mon Jul 20 07:24:47.421903 2026] [security2:error] [pid 116718:tid 116951] [client 20.220.225.223:19505] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/asd67.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6AAAAAFc"]
[Mon Jul 20 07:24:47.564787 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:65153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6DwAAAEY"]
[Mon Jul 20 07:24:47.564893 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:65153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6DwAAAEY"]
[Mon Jul 20 07:24:47.616967 2026] [security2:error] [pid 116718:tid 116932] [client 57.141.18.12:28378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hmpPWlhYV5NwZ9vU4cQAARDI"]
[Mon Jul 20 07:24:47.676383 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6CgAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:47.827987 2026] [security2:error] [pid 116718:tid 116871] [client 136.158.60.21:21150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6JwAAAAc"]
[Mon Jul 20 07:24:47.828145 2026] [security2:error] [pid 116718:tid 116871] [client 136.158.60.21:21150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6JwAAAAc"]
[Mon Jul 20 07:24:47.899031 2026] [security2:error] [pid 116718:tid 116876] [client 14.225.17.146:58566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4hnpPWlhYV5NwZ9vU5xwAAAAw"]
[Mon Jul 20 07:24:47.951791 2026] [security2:error] [pid 116718:tid 116866] [client 104.234.53.88:62663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hn5PWlhYV5NwZ9vU6NQAAAAI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:48.004640 2026] [security2:error] [pid 116718:tid 116903] [client 77.110.127.138:65157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6OwAAACc"]
[Mon Jul 20 07:24:48.004720 2026] [security2:error] [pid 116718:tid 116903] [client 77.110.127.138:65157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6OwAAACc"]
[Mon Jul 20 07:24:48.028380 2026] [security2:error] [pid 116718:tid 116953] [client 3.67.192.83:41584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6PAAAAFk"]
[Mon Jul 20 07:24:48.050069 2026] [security2:error] [pid 116718:tid 116975] [client 49.47.218.174:51685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6QgAAAG8"]
[Mon Jul 20 07:24:48.050165 2026] [security2:error] [pid 116718:tid 116975] [client 49.47.218.174:51685] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6QgAAAG8"]
[Mon Jul 20 07:24:48.215591 2026] [security2:error] [pid 116718:tid 116817] [remote 154.66.198.148:39746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6VAAAIlI"]
[Mon Jul 20 07:24:48.295212 2026] [security2:error] [pid 116718:tid 116904] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6TgAAACg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:48.354149 2026] [security2:error] [pid 116718:tid 116897] [client 57.141.18.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6VgAAACE"]
[Mon Jul 20 07:24:48.456421 2026] [security2:error] [pid 116718:tid 116971] [client 57.141.18.123:27116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hm5PWlhYV5NwZ9vU40QAAa14"]
[Mon Jul 20 07:24:48.567007 2026] [security2:error] [pid 116718:tid 116921] [client 52.59.238.198:20248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6cAAAADk"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:24:48.721150 2026] [security2:error] [pid 116718:tid 116874] [client 20.220.225.223:19500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/csa.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6fQAAAAo"]
[Mon Jul 20 07:24:48.721242 2026] [security2:error] [pid 116718:tid 116874] [client 20.220.225.223:19500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/csa.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6fQAAAAo"]
[Mon Jul 20 07:24:48.774454 2026] [security2:error] [pid 116718:tid 116844] [remote 154.66.198.148:39746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6gQAAKG0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:24:48.970869 2026] [security2:error] [pid 116718:tid 116888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6fgAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:49.054863 2026] [security2:error] [pid 116718:tid 116963] [client 36.93.152.155:63792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6ngAAAGM"]
[Mon Jul 20 07:24:49.054979 2026] [security2:error] [pid 116718:tid 116963] [client 36.93.152.155:63792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6ngAAAGM"]
[Mon Jul 20 07:24:49.156492 2026] [security2:error] [pid 116718:tid 116868] [client 103.176.215.66:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6qAAAAAQ"]
[Mon Jul 20 07:24:49.156602 2026] [security2:error] [pid 116718:tid 116868] [client 103.176.215.66:56644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6qAAAAAQ"]
[Mon Jul 20 07:24:49.250743 2026] [security2:error] [pid 116718:tid 116872] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6nwAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:49.302167 2026] [security2:error] [pid 116718:tid 116964] [client 57.141.18.8:24462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hnJPWlhYV5NwZ9vU5AwAAZEA"]
[Mon Jul 20 07:24:49.327461 2026] [security2:error] [pid 116718:tid 116910] [client 20.220.225.223:19491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/2.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6sAAAAC4"]
[Mon Jul 20 07:24:49.327544 2026] [security2:error] [pid 116718:tid 116910] [client 20.220.225.223:19491] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/2.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6sAAAAC4"]
[Mon Jul 20 07:24:49.505009 2026] [security2:error] [pid 116718:tid 116962] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/cgi-sys/404.html"] [unique_id "al4hoZPWlhYV5NwZ9vU6wAAAAGI"]
[Mon Jul 20 07:24:49.529541 2026] [security2:error] [pid 116718:tid 116974] [client 77.110.127.138:65086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6tgAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:49.541214 2026] [security2:error] [pid 116718:tid 116847] [remote 199.189.225.40:63259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6xgAAB3A"]
[Mon Jul 20 07:24:49.541365 2026] [security2:error] [pid 116718:tid 116871] [client 199.189.225.40:63259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6xgAAB3A"]
[Mon Jul 20 07:24:49.575471 2026] [security2:error] [pid 116718:tid 116981] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6yAAAAHU"]
[Mon Jul 20 07:24:49.575504 2026] [security2:error] [pid 116718:tid 116981] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6yAAAAHU"]
[Mon Jul 20 07:24:49.626851 2026] [security2:error] [pid 116718:tid 116991] [client 77.110.127.138:65148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6ygAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:49.626948 2026] [security2:error] [pid 116718:tid 116991] [client 77.110.127.138:65148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6ygAAAH8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:49.646804 2026] [security2:error] [pid 116718:tid 116896] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sql.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6ywAAACA"]
[Mon Jul 20 07:24:49.646825 2026] [security2:error] [pid 116718:tid 116896] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sql.php"] [unique_id "al4hoZPWlhYV5NwZ9vU6ywAAACA"]
[Mon Jul 20 07:24:49.670779 2026] [security2:error] [pid 116718:tid 116990] [client 14.225.17.146:54763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4hn5PWlhYV5NwZ9vU53AAAAH4"]
[Mon Jul 20 07:24:49.782185 2026] [security2:error] [pid 116718:tid 116929] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/1index.php"] [unique_id "al4hoZPWlhYV5NwZ9vU62QAAAEE"]
[Mon Jul 20 07:24:49.782212 2026] [security2:error] [pid 116718:tid 116929] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/1index.php"] [unique_id "al4hoZPWlhYV5NwZ9vU62QAAAEE"]
[Mon Jul 20 07:24:49.885421 2026] [security2:error] [pid 116718:tid 116965] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/reop1.php"] [unique_id "al4hoZPWlhYV5NwZ9vU64AAAAGU"]
[Mon Jul 20 07:24:49.885443 2026] [security2:error] [pid 116718:tid 116965] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/reop1.php"] [unique_id "al4hoZPWlhYV5NwZ9vU64AAAAGU"]
[Mon Jul 20 07:24:49.951826 2026] [security2:error] [pid 116718:tid 116959] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/trusj18.php"] [unique_id "al4hoZPWlhYV5NwZ9vU64gAAAF8"]
[Mon Jul 20 07:24:49.951848 2026] [security2:error] [pid 116718:tid 116959] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/trusj18.php"] [unique_id "al4hoZPWlhYV5NwZ9vU64gAAAF8"]
[Mon Jul 20 07:24:50.160285 2026] [security2:error] [pid 116718:tid 116931] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/trusj15.php"] [unique_id "al4hopPWlhYV5NwZ9vU67wAAAEM"]
[Mon Jul 20 07:24:50.160313 2026] [security2:error] [pid 116718:tid 116931] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/trusj15.php"] [unique_id "al4hopPWlhYV5NwZ9vU67wAAAEM"]
[Mon Jul 20 07:24:50.225695 2026] [security2:error] [pid 116718:tid 116903] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/rft8.php"] [unique_id "al4hopPWlhYV5NwZ9vU6-QAAACc"]
[Mon Jul 20 07:24:50.225714 2026] [security2:error] [pid 116718:tid 116903] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/rft8.php"] [unique_id "al4hopPWlhYV5NwZ9vU6-QAAACc"]
[Mon Jul 20 07:24:50.293034 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ai.php"] [unique_id "al4hopPWlhYV5NwZ9vU7AAAAAHk"]
[Mon Jul 20 07:24:50.293054 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ai.php"] [unique_id "al4hopPWlhYV5NwZ9vU7AAAAAHk"]
[Mon Jul 20 07:24:50.295400 2026] [security2:error] [pid 116718:tid 116909] [client 114.119.158.28:56659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/tours/malaysia-discover"] [unique_id "al4hopPWlhYV5NwZ9vU7AQAAAC0"], referer: https://www.savilerowtravel.com/destinations/malaysia
[Mon Jul 20 07:24:50.301070 2026] [security2:error] [pid 116718:tid 116893] [client 104.234.53.55:57905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hopPWlhYV5NwZ9vU7AgAAAB0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:50.332553 2026] [security2:error] [pid 116718:tid 116900] [client 57.141.18.67:37318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hnZPWlhYV5NwZ9vU5YgAAJAI"]
[Mon Jul 20 07:24:50.364756 2026] [security2:error] [pid 116718:tid 116865] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-rdf.php"] [unique_id "al4hopPWlhYV5NwZ9vU7BwAAAAE"]
[Mon Jul 20 07:24:50.364775 2026] [security2:error] [pid 116718:tid 116865] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-rdf.php"] [unique_id "al4hopPWlhYV5NwZ9vU7BwAAAAE"]
[Mon Jul 20 07:24:50.643931 2026] [security2:error] [pid 116718:tid 116876] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fx.php"] [unique_id "al4hopPWlhYV5NwZ9vU7JgAAAAw"]
[Mon Jul 20 07:24:50.643966 2026] [security2:error] [pid 116718:tid 116876] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fx.php"] [unique_id "al4hopPWlhYV5NwZ9vU7JgAAAAw"]
[Mon Jul 20 07:24:50.659485 2026] [security2:error] [pid 116718:tid 116878] [client 14.225.17.146:63420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4hoJPWlhYV5NwZ9vU6egAAAA4"], referer: http://dollpassionista.com/backup
[Mon Jul 20 07:24:50.709638 2026] [security2:error] [pid 116718:tid 116946] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xxx.php"] [unique_id "al4hopPWlhYV5NwZ9vU7LgAAAFI"]
[Mon Jul 20 07:24:50.709667 2026] [security2:error] [pid 116718:tid 116946] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xxx.php"] [unique_id "al4hopPWlhYV5NwZ9vU7LgAAAFI"]
[Mon Jul 20 07:24:50.709782 2026] [security2:error] [pid 116718:tid 116942] [client 103.106.165.44:54680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hopPWlhYV5NwZ9vU7LwAAAE4"]
[Mon Jul 20 07:24:50.709915 2026] [security2:error] [pid 116718:tid 116942] [client 103.106.165.44:54680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hopPWlhYV5NwZ9vU7LwAAAE4"]
[Mon Jul 20 07:24:50.732879 2026] [security2:error] [pid 116718:tid 116900] [client 20.220.225.223:19512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.225.220.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/667.php"] [unique_id "al4hopPWlhYV5NwZ9vU7MgAAACQ"]
[Mon Jul 20 07:24:50.732981 2026] [security2:error] [pid 116718:tid 116900] [client 20.220.225.223:19512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fwg.ags.mybluehost.me"] [uri "/667.php"] [unique_id "al4hopPWlhYV5NwZ9vU7MgAAACQ"]
[Mon Jul 20 07:24:50.757062 2026] [security2:error] [pid 116718:tid 116982] [client 14.225.17.146:63551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4hopPWlhYV5NwZ9vU7FAAAAHY"], referer: http://falconarrowshop.com/backup
[Mon Jul 20 07:24:50.791871 2026] [security2:error] [pid 116718:tid 116805] [remote 159.65.81.207:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4hopPWlhYV5NwZ9vU7NgAAa0Y"]
[Mon Jul 20 07:24:50.833906 2026] [security2:error] [pid 116718:tid 116902] [client 50.116.65.227:55080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hopPWlhYV5NwZ9vU7JwAAACY"]
[Mon Jul 20 07:24:50.937932 2026] [security2:error] [pid 116718:tid 116885] [client 191.202.66.27:51913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hopPWlhYV5NwZ9vU7PgAAABU"]
[Mon Jul 20 07:24:50.938117 2026] [security2:error] [pid 116718:tid 116885] [client 191.202.66.27:51913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hopPWlhYV5NwZ9vU7PgAAABU"]
[Mon Jul 20 07:24:50.967346 2026] [security2:error] [pid 116718:tid 116765] [remote 159.65.81.207:57388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4hopPWlhYV5NwZ9vU7QwAAKh4"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 07:24:51.021256 2026] [security2:error] [pid 116718:tid 116904] [client 50.116.65.227:55094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4hopPWlhYV5NwZ9vU7OgAAACg"]
[Mon Jul 20 07:24:51.095385 2026] [security2:error] [pid 116718:tid 116991] [client 201.27.111.74:58556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7UgAAAH8"]
[Mon Jul 20 07:24:51.095515 2026] [security2:error] [pid 116718:tid 116991] [client 201.27.111.74:58556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7UgAAAH8"]
[Mon Jul 20 07:24:51.400211 2026] [security2:error] [pid 116718:tid 116916] [client 88.241.67.160:54656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7aAAAADQ"]
[Mon Jul 20 07:24:51.401469 2026] [security2:error] [pid 116718:tid 116916] [client 88.241.67.160:54656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7aAAAADQ"]
[Mon Jul 20 07:24:51.421122 2026] [security2:error] [pid 116718:tid 116958] [client 77.110.127.138:65155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7aQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:51.421199 2026] [security2:error] [pid 116718:tid 116958] [client 77.110.127.138:65155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7aQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:51.637389 2026] [security2:error] [pid 116718:tid 116896] [client 14.225.17.146:65195] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7awAAACA"], referer: https://dollpassionista.com/backup
[Mon Jul 20 07:24:51.668470 2026] [security2:error] [pid 116718:tid 116991] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/dropdown.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7hQAAAH8"]
[Mon Jul 20 07:24:51.668497 2026] [security2:error] [pid 116718:tid 116991] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/dropdown.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7hQAAAH8"]
[Mon Jul 20 07:24:51.670184 2026] [core:error] [pid 116718:tid 116927] [client 14.225.17.146:63451] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:51.670203 2026] [core:error] [pid 116718:tid 116927] [client 14.225.17.146:63451] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:24:51.710556 2026] [security2:error] [pid 116718:tid 116864] [client 179.127.84.238:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7iAAAAAA"]
[Mon Jul 20 07:24:51.710699 2026] [security2:error] [pid 116718:tid 116864] [client 179.127.84.238:53212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7iAAAAAA"]
[Mon Jul 20 07:24:51.719398 2026] [security2:error] [pid 116718:tid 116950] [client 157.20.138.62:52643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7igAAAFY"]
[Mon Jul 20 07:24:51.719527 2026] [security2:error] [pid 116718:tid 116950] [client 157.20.138.62:52643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7igAAAFY"]
[Mon Jul 20 07:24:51.733964 2026] [security2:error] [pid 116718:tid 116957] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file11.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7jAAAAF0"]
[Mon Jul 20 07:24:51.733993 2026] [security2:error] [pid 116718:tid 116957] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file11.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7jAAAAF0"]
[Mon Jul 20 07:24:51.748519 2026] [security2:error] [pid 116718:tid 116867] [client 14.225.17.146:58737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4hopPWlhYV5NwZ9vU7BQAAAAM"], referer: http://eframiproperties.com/backup
[Mon Jul 20 07:24:51.769768 2026] [security2:error] [pid 116718:tid 116919] [client 104.234.53.79:21443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7gQAAADc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:51.801336 2026] [security2:error] [pid 116718:tid 116909] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/png.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7lgAAAC0"]
[Mon Jul 20 07:24:51.801366 2026] [security2:error] [pid 116718:tid 116909] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/png.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7lgAAAC0"]
[Mon Jul 20 07:24:51.891238 2026] [security2:error] [pid 116718:tid 116917] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-slss.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7ngAAADU"]
[Mon Jul 20 07:24:51.891265 2026] [security2:error] [pid 116718:tid 116917] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-slss.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7ngAAADU"]
[Mon Jul 20 07:24:51.972517 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ah25.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7qAAAAHo"]
[Mon Jul 20 07:24:51.972539 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ah25.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7qAAAAHo"]
[Mon Jul 20 07:24:52.253222 2026] [security2:error] [pid 116718:tid 116987] [client 57.141.18.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hpJPWlhYV5NwZ9vU7sQAAAHs"]
[Mon Jul 20 07:24:52.278842 2026] [security2:error] [pid 116718:tid 116833] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hpJPWlhYV5NwZ9vU7vgAAa2I"]
[Mon Jul 20 07:24:52.278997 2026] [security2:error] [pid 116718:tid 116971] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hpJPWlhYV5NwZ9vU7vgAAa2I"]
[Mon Jul 20 07:24:52.376428 2026] [security2:error] [pid 116718:tid 116913] [client 77.110.127.138:65086] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/related-posts/if(now()=sysdate(),sleep(15),0)"] [unique_id "al4hpJPWlhYV5NwZ9vU7ywAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:52.415733 2026] [security2:error] [pid 116718:tid 116937] [client 14.225.17.146:56886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4hopPWlhYV5NwZ9vU7QAAAAEk"]
[Mon Jul 20 07:24:52.572122 2026] [security2:error] [pid 116718:tid 116907] [client 104.234.53.79:21443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hpJPWlhYV5NwZ9vU71wAAACs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:24:52.641201 2026] [security2:error] [pid 116718:tid 116960] [client 14.225.17.146:56874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4ho5PWlhYV5NwZ9vU7WAAAAGA"], referer: http://alexsandbergmusic.com/backup
[Mon Jul 20 07:24:52.694366 2026] [security2:error] [pid 116718:tid 116864] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ccou.php"] [unique_id "al4hpJPWlhYV5NwZ9vU75QAAAAA"]
[Mon Jul 20 07:24:52.694390 2026] [security2:error] [pid 116718:tid 116864] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ccou.php"] [unique_id "al4hpJPWlhYV5NwZ9vU75QAAAAA"]
[Mon Jul 20 07:24:52.759991 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.espiritualidadmoderna.com"] [uri "/1.php"] [unique_id "al4hpJPWlhYV5NwZ9vU76AAAADY"]
[Mon Jul 20 07:24:52.762678 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/1.php"] [unique_id "al4hpJPWlhYV5NwZ9vU76AAAADY"]
[Mon Jul 20 07:24:52.762694 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/1.php"] [unique_id "al4hpJPWlhYV5NwZ9vU76AAAADY"]
[Mon Jul 20 07:24:52.915697 2026] [security2:error] [pid 116718:tid 116886] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/900.php"] [unique_id "al4hpJPWlhYV5NwZ9vU7_QAAABY"]
[Mon Jul 20 07:24:52.915718 2026] [security2:error] [pid 116718:tid 116886] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/900.php"] [unique_id "al4hpJPWlhYV5NwZ9vU7_QAAABY"]
[Mon Jul 20 07:24:53.003483 2026] [security2:error] [pid 116718:tid 116926] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file59.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8AAAAAD4"]
[Mon Jul 20 07:24:53.003517 2026] [security2:error] [pid 116718:tid 116926] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file59.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8AAAAAD4"]
[Mon Jul 20 07:24:53.015989 2026] [security2:error] [pid 116718:tid 116977] [client 82.102.27.163:45468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8AQAAAHE"]
[Mon Jul 20 07:24:53.016098 2026] [security2:error] [pid 116718:tid 116977] [client 82.102.27.163:45468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8AQAAAHE"]
[Mon Jul 20 07:24:53.092129 2026] [security2:error] [pid 116718:tid 116976] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/amxloxxr.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8BAAAAHA"]
[Mon Jul 20 07:24:53.092152 2026] [security2:error] [pid 116718:tid 116976] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/amxloxxr.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8BAAAAHA"]
[Mon Jul 20 07:24:53.158536 2026] [security2:error] [pid 116718:tid 116964] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/aboutc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8CAAAAGQ"]
[Mon Jul 20 07:24:53.158567 2026] [security2:error] [pid 116718:tid 116964] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/aboutc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8CAAAAGQ"]
[Mon Jul 20 07:24:53.229656 2026] [security2:error] [pid 116718:tid 116947] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless18.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8DwAAAFM"]
[Mon Jul 20 07:24:53.229684 2026] [security2:error] [pid 116718:tid 116947] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless18.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8DwAAAFM"]
[Mon Jul 20 07:24:53.324012 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8HQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:53.324105 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8HQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:53.467793 2026] [security2:error] [pid 116718:tid 116865] [client 154.192.123.127:17077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8LAAAAAE"]
[Mon Jul 20 07:24:53.467992 2026] [security2:error] [pid 116718:tid 116865] [client 154.192.123.127:17077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8LAAAAAE"]
[Mon Jul 20 07:24:53.492323 2026] [security2:error] [pid 116718:tid 116959] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/crgio.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8LwAAAF8"]
[Mon Jul 20 07:24:53.492349 2026] [security2:error] [pid 116718:tid 116959] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/crgio.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8LwAAAF8"]
[Mon Jul 20 07:24:53.521962 2026] [security2:error] [pid 116718:tid 116890] [client 93.152.221.13:63307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8MAAAABo"]
[Mon Jul 20 07:24:53.585843 2026] [security2:error] [pid 116718:tid 116979] [client 57.141.18.24:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8KQAAAHM"]
[Mon Jul 20 07:24:53.594837 2026] [security2:error] [pid 116718:tid 116929] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-act.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8NAAAAEE"]
[Mon Jul 20 07:24:53.594862 2026] [security2:error] [pid 116718:tid 116929] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-act.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8NAAAAEE"]
[Mon Jul 20 07:24:53.661275 2026] [security2:error] [pid 116718:tid 116917] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/new4.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8OgAAADU"]
[Mon Jul 20 07:24:53.661314 2026] [security2:error] [pid 116718:tid 116917] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/new4.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8OgAAADU"]
[Mon Jul 20 07:24:53.767983 2026] [security2:error] [pid 116718:tid 116896] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-the.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8QwAAACA"]
[Mon Jul 20 07:24:53.768014 2026] [security2:error] [pid 116718:tid 116896] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-the.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8QwAAACA"]
[Mon Jul 20 07:24:53.796433 2026] [security2:error] [pid 116718:tid 116877] [client 93.152.221.13:59220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/test.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8SgAAAA0"]
[Mon Jul 20 07:24:53.841813 2026] [security2:error] [pid 116718:tid 116958] [client 143.44.185.218:40821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8TgAAAF4"]
[Mon Jul 20 07:24:53.841948 2026] [security2:error] [pid 116718:tid 116958] [client 143.44.185.218:40821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8TgAAAF4"]
[Mon Jul 20 07:24:53.915674 2026] [security2:error] [pid 116718:tid 116932] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/atkno.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8UwAAAEQ"]
[Mon Jul 20 07:24:53.915697 2026] [security2:error] [pid 116718:tid 116932] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/atkno.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8UwAAAEQ"]
[Mon Jul 20 07:24:53.983233 2026] [security2:error] [pid 116718:tid 116974] [client 52.139.36.144:6272] ModSecurity: Access denied with code 403 (phase 2). Pattern match "/mass.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1280"] [id "999110"] [rev "1"] [msg "Possible Mass Defacer Request"] [severity "CRITICAL"] [hostname "mail.espiritualidadmoderna.com"] [uri "/mass.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8WgAAAG4"]
[Mon Jul 20 07:24:53.983832 2026] [security2:error] [pid 116718:tid 116974] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.espiritualidadmoderna.com"] [uri "/mass.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8WgAAAG4"]
[Mon Jul 20 07:24:54.048977 2026] [security2:error] [pid 116718:tid 116872] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wefile.php"] [unique_id "al4hppPWlhYV5NwZ9vU8YAAAAAg"]
[Mon Jul 20 07:24:54.049021 2026] [security2:error] [pid 116718:tid 116872] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wefile.php"] [unique_id "al4hppPWlhYV5NwZ9vU8YAAAAAg"]
[Mon Jul 20 07:24:54.307744 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/min.php"] [unique_id "al4hppPWlhYV5NwZ9vU8gQAAADY"]
[Mon Jul 20 07:24:54.307775 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/min.php"] [unique_id "al4hppPWlhYV5NwZ9vU8gQAAADY"]
[Mon Jul 20 07:24:54.326729 2026] [security2:error] [pid 116718:tid 116761] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hppPWlhYV5NwZ9vU8hgAASho"]
[Mon Jul 20 07:24:54.326914 2026] [security2:error] [pid 116718:tid 116938] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hppPWlhYV5NwZ9vU8hgAASho"]
[Mon Jul 20 07:24:54.374275 2026] [security2:error] [pid 116718:tid 116879] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sid3.php"] [unique_id "al4hppPWlhYV5NwZ9vU8iQAAAA8"]
[Mon Jul 20 07:24:54.374301 2026] [security2:error] [pid 116718:tid 116879] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sid3.php"] [unique_id "al4hppPWlhYV5NwZ9vU8iQAAAA8"]
[Mon Jul 20 07:24:54.434380 2026] [security2:error] [pid 116718:tid 116957] [client 14.225.17.146:55067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4hpZPWlhYV5NwZ9vU8AgAAAF0"], referer: http://slutilities.com/backup
[Mon Jul 20 07:24:54.445158 2026] [security2:error] [pid 116718:tid 116970] [client 93.152.221.13:61678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/info.php"] [unique_id "al4hppPWlhYV5NwZ9vU8lQAAAGo"]
[Mon Jul 20 07:24:54.475967 2026] [security2:error] [pid 116718:tid 116953] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fileas.php"] [unique_id "al4hppPWlhYV5NwZ9vU8mAAAAFk"]
[Mon Jul 20 07:24:54.476003 2026] [security2:error] [pid 116718:tid 116953] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fileas.php"] [unique_id "al4hppPWlhYV5NwZ9vU8mAAAAFk"]
[Mon Jul 20 07:24:54.543452 2026] [security2:error] [pid 116718:tid 116967] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless24.php"] [unique_id "al4hppPWlhYV5NwZ9vU8nAAAAGc"]
[Mon Jul 20 07:24:54.543483 2026] [security2:error] [pid 116718:tid 116967] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless24.php"] [unique_id "al4hppPWlhYV5NwZ9vU8nAAAAGc"]
[Mon Jul 20 07:24:54.718857 2026] [security2:error] [pid 116718:tid 116955] [client 93.152.221.13:57934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/php.php"] [unique_id "al4hppPWlhYV5NwZ9vU8pwAAAFs"]
[Mon Jul 20 07:24:54.723158 2026] [security2:error] [pid 116718:tid 116921] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fun.php"] [unique_id "al4hppPWlhYV5NwZ9vU8qAAAADk"]
[Mon Jul 20 07:24:54.723174 2026] [security2:error] [pid 116718:tid 116921] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fun.php"] [unique_id "al4hppPWlhYV5NwZ9vU8qAAAADk"]
[Mon Jul 20 07:24:54.851926 2026] [security2:error] [pid 116718:tid 116897] [client 77.110.127.138:65214] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 169 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hppPWlhYV5NwZ9vU8twAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:54.882489 2026] [security2:error] [pid 116718:tid 116935] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/drykl.php"] [unique_id "al4hppPWlhYV5NwZ9vU8uwAAAEc"]
[Mon Jul 20 07:24:54.882516 2026] [security2:error] [pid 116718:tid 116935] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/drykl.php"] [unique_id "al4hppPWlhYV5NwZ9vU8uwAAAEc"]
[Mon Jul 20 07:24:54.902843 2026] [security2:error] [pid 116718:tid 116952] [client 77.110.127.138:65122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hppPWlhYV5NwZ9vU8vQAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:54.902958 2026] [security2:error] [pid 116718:tid 116952] [client 77.110.127.138:65122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hppPWlhYV5NwZ9vU8vQAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:54.956326 2026] [security2:error] [pid 116718:tid 116970] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4hppPWlhYV5NwZ9vU8wAAAAGo"]
[Mon Jul 20 07:24:54.956354 2026] [security2:error] [pid 116718:tid 116970] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-admin/css/colors/blue/file.php"] [unique_id "al4hppPWlhYV5NwZ9vU8wAAAAGo"]
[Mon Jul 20 07:24:54.957142 2026] [security2:error] [pid 116718:tid 116941] [client 57.141.18.65:57650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hoZPWlhYV5NwZ9vU65QAATRg"]
[Mon Jul 20 07:24:54.994326 2026] [security2:error] [pid 116718:tid 116911] [client 93.152.221.13:64517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/php_info.php"] [unique_id "al4hppPWlhYV5NwZ9vU8wgAAAC8"]
[Mon Jul 20 07:24:55.021526 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/mifta.php"] [unique_id "al4hp5PWlhYV5NwZ9vU8xAAAABA"]
[Mon Jul 20 07:24:55.021544 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/mifta.php"] [unique_id "al4hp5PWlhYV5NwZ9vU8xAAAABA"]
[Mon Jul 20 07:24:55.030947 2026] [security2:error] [pid 116718:tid 116796] [remote 41.185.8.149:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hp5PWlhYV5NwZ9vU8wwAAWj0"]
[Mon Jul 20 07:24:55.246102 2026] [security2:error] [pid 116718:tid 116886] [client 14.225.17.146:54925] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4hp5PWlhYV5NwZ9vU8yAAAABY"], referer: http://reosportsboats.com/backup
[Mon Jul 20 07:24:55.276036 2026] [security2:error] [pid 116718:tid 116975] [client 93.152.221.13:49550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/i.php"] [unique_id "al4hp5PWlhYV5NwZ9vU80wAAAG8"]
[Mon Jul 20 07:24:55.370464 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/class-t.api.php"] [unique_id "al4hp5PWlhYV5NwZ9vU85gAAACo"]
[Mon Jul 20 07:24:55.370487 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/class-t.api.php"] [unique_id "al4hp5PWlhYV5NwZ9vU85gAAACo"]
[Mon Jul 20 07:24:55.438349 2026] [security2:error] [pid 116718:tid 116988] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/vgtyu.php"] [unique_id "al4hp5PWlhYV5NwZ9vU87AAAAHw"]
[Mon Jul 20 07:24:55.438373 2026] [security2:error] [pid 116718:tid 116988] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/vgtyu.php"] [unique_id "al4hp5PWlhYV5NwZ9vU87AAAAHw"]
[Mon Jul 20 07:24:55.491151 2026] [security2:error] [pid 116718:tid 116824] [remote 41.185.8.149:35156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4hp5PWlhYV5NwZ9vU87QAAcFk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:24:55.539491 2026] [security2:error] [pid 116718:tid 116922] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/atomlib.php"] [unique_id "al4hp5PWlhYV5NwZ9vU88QAAADo"]
[Mon Jul 20 07:24:55.539519 2026] [security2:error] [pid 116718:tid 116922] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/atomlib.php"] [unique_id "al4hp5PWlhYV5NwZ9vU88QAAADo"]
[Mon Jul 20 07:24:55.550417 2026] [security2:error] [pid 116718:tid 116904] [client 93.152.221.13:59177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/pi.php"] [unique_id "al4hp5PWlhYV5NwZ9vU88wAAACg"]
[Mon Jul 20 07:24:55.644132 2026] [security2:error] [pid 116718:tid 116980] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-access.php"] [unique_id "al4hp5PWlhYV5NwZ9vU89gAAAHQ"]
[Mon Jul 20 07:24:55.644157 2026] [security2:error] [pid 116718:tid 116980] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-access.php"] [unique_id "al4hp5PWlhYV5NwZ9vU89gAAAHQ"]
[Mon Jul 20 07:24:55.734255 2026] [security2:error] [pid 116718:tid 116826] [remote 57.141.18.68:26640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4391056"] [unique_id "al4hp5PWlhYV5NwZ9vU8-gAAAls"]
[Mon Jul 20 07:24:55.759824 2026] [security2:error] [pid 116718:tid 116914] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-update.php"] [unique_id "al4hp5PWlhYV5NwZ9vU9AAAAADI"]
[Mon Jul 20 07:24:55.759848 2026] [security2:error] [pid 116718:tid 116914] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-update.php"] [unique_id "al4hp5PWlhYV5NwZ9vU9AAAAADI"]
[Mon Jul 20 07:24:55.768029 2026] [security2:error] [pid 116718:tid 116902] [client 77.110.127.138:65172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/related-posts/related-posts.css0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4hp5PWlhYV5NwZ9vU9AgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:55.923624 2026] [security2:error] [pid 116718:tid 116864] [client 14.225.17.146:58561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4hp5PWlhYV5NwZ9vU8-AAAAAA"], referer: http://tacticaltreeoperations.com/backup
[Mon Jul 20 07:24:55.946009 2026] [security2:error] [pid 116718:tid 116806] [remote 47.128.126.230:37588] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mrbambooplus.com"] [uri "/product/bamboo-mat/"] [unique_id "al4hp5PWlhYV5NwZ9vU9FQAAD0c"]
[Mon Jul 20 07:24:56.178556 2026] [security2:error] [pid 116718:tid 116900] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/erty.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9JQAAACQ"]
[Mon Jul 20 07:24:56.178595 2026] [security2:error] [pid 116718:tid 116900] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/erty.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9JQAAACQ"]
[Mon Jul 20 07:24:56.188734 2026] [security2:error] [pid 116718:tid 116924] [client 14.225.17.146:53142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9HwAAADw"], referer: https://reosportsboats.com/backup
[Mon Jul 20 07:24:56.196567 2026] [security2:error] [pid 116718:tid 116876] [client 15.237.142.234:39222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9KQAAAAw"]
[Mon Jul 20 07:24:56.196693 2026] [security2:error] [pid 116718:tid 116876] [client 15.237.142.234:39222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9KQAAAAw"]
[Mon Jul 20 07:24:56.228606 2026] [security2:error] [pid 116718:tid 116937] [client 93.152.221.13:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9LQAAAEk"]
[Mon Jul 20 07:24:56.244990 2026] [security2:error] [pid 116718:tid 116954] [client 77.110.127.138:65129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9LwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:56.245086 2026] [security2:error] [pid 116718:tid 116954] [client 77.110.127.138:65129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9LwAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:56.253425 2026] [security2:error] [pid 116718:tid 116933] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9MAAAAEU"]
[Mon Jul 20 07:24:56.253443 2026] [security2:error] [pid 116718:tid 116933] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-admin/maint/wp-is.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9MAAAAEU"]
[Mon Jul 20 07:24:56.320113 2026] [security2:error] [pid 116718:tid 116942] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/like.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9OgAAAE4"]
[Mon Jul 20 07:24:56.320135 2026] [security2:error] [pid 116718:tid 116942] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/like.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9OgAAAE4"]
[Mon Jul 20 07:24:56.422061 2026] [security2:error] [pid 116718:tid 116953] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless5.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9RgAAAFk"]
[Mon Jul 20 07:24:56.422082 2026] [security2:error] [pid 116718:tid 116953] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless5.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9RgAAAFk"]
[Mon Jul 20 07:24:56.439457 2026] [security2:error] [pid 116718:tid 116888] [client 154.208.48.130:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9SAAAABg"]
[Mon Jul 20 07:24:56.439571 2026] [security2:error] [pid 116718:tid 116888] [client 154.208.48.130:54628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9SAAAABg"]
[Mon Jul 20 07:24:56.502242 2026] [security2:error] [pid 116718:tid 116926] [client 93.152.221.13:63415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9SgAAAD4"]
[Mon Jul 20 07:24:56.509376 2026] [security2:error] [pid 116718:tid 116850] [remote 47.128.126.226:50974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mrbambooplus.com"] [uri "/"] [unique_id "al4hqJPWlhYV5NwZ9vU9SwAAeHM"]
[Mon Jul 20 07:24:56.682604 2026] [security2:error] [pid 116718:tid 116975] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/t.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9WgAAAG8"]
[Mon Jul 20 07:24:56.682644 2026] [security2:error] [pid 116718:tid 116975] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/t.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9WgAAAG8"]
[Mon Jul 20 07:24:56.770971 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xoot.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9XAAAACo"]
[Mon Jul 20 07:24:56.770999 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xoot.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9XAAAACo"]
[Mon Jul 20 07:24:56.777688 2026] [security2:error] [pid 116718:tid 116909] [client 93.152.221.13:55397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.musichaven.info"] [uri "/php_version.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9XgAAAC0"]
[Mon Jul 20 07:24:56.837234 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xqq.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9bgAAAHk"]
[Mon Jul 20 07:24:56.837262 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xqq.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9bgAAAHk"]
[Mon Jul 20 07:24:56.902229 2026] [security2:error] [pid 116718:tid 116895] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-load.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9dAAAAB8"]
[Mon Jul 20 07:24:56.902247 2026] [security2:error] [pid 116718:tid 116895] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-load.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9dAAAAB8"]
[Mon Jul 20 07:24:56.968281 2026] [security2:error] [pid 116718:tid 116966] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/x.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9ewAAAGY"]
[Mon Jul 20 07:24:56.968307 2026] [security2:error] [pid 116718:tid 116966] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/x.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9ewAAAGY"]
[Mon Jul 20 07:24:56.983403 2026] [security2:error] [pid 116718:tid 116976] [client 202.141.11.99:35872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9fQAAAHA"]
[Mon Jul 20 07:24:56.983563 2026] [security2:error] [pid 116718:tid 116976] [client 202.141.11.99:35872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9fQAAAHA"]
[Mon Jul 20 07:24:57.057720 2026] [security2:error] [pid 116718:tid 116958] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/i.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9hQAAAF4"]
[Mon Jul 20 07:24:57.057738 2026] [security2:error] [pid 116718:tid 116958] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/i.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9hQAAAF4"]
[Mon Jul 20 07:24:57.123693 2026] [security2:error] [pid 116718:tid 116933] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ms-edit.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9hwAAAEU"]
[Mon Jul 20 07:24:57.123711 2026] [security2:error] [pid 116718:tid 116933] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ms-edit.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9hwAAAEU"]
[Mon Jul 20 07:24:57.227602 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/v2.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9jgAAABA"]
[Mon Jul 20 07:24:57.227622 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/v2.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9jgAAABA"]
[Mon Jul 20 07:24:57.292875 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/new.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9kQAAACo"]
[Mon Jul 20 07:24:57.292893 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/new.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9kQAAACo"]
[Mon Jul 20 07:24:57.360002 2026] [security2:error] [pid 116718:tid 116877] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-admin/network/edit.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9mgAAAA0"]
[Mon Jul 20 07:24:57.360043 2026] [security2:error] [pid 116718:tid 116877] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-admin/network/edit.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9mgAAAA0"]
[Mon Jul 20 07:24:57.366867 2026] [security2:error] [pid 116718:tid 116989] [client 77.110.127.138:65198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9nAAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.367005 2026] [security2:error] [pid 116718:tid 116989] [client 77.110.127.138:65198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9nAAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.418403 2026] [security2:error] [pid 116718:tid 116905] [client 77.110.127.138:65204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9pQAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.418501 2026] [security2:error] [pid 116718:tid 116905] [client 77.110.127.138:65204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9pQAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.432397 2026] [security2:error] [pid 116718:tid 116885] [client 93.152.221.13:57963] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.musichaven.info"] [uri "/.env"] [unique_id "al4hqZPWlhYV5NwZ9vU9pgAAABU"]
[Mon Jul 20 07:24:57.572735 2026] [security2:error] [pid 116718:tid 116966] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/pouhg.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9sgAAAGY"]
[Mon Jul 20 07:24:57.572784 2026] [security2:error] [pid 116718:tid 116966] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/pouhg.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9sgAAAGY"]
[Mon Jul 20 07:24:57.597618 2026] [security2:error] [pid 116718:tid 116879] [client 77.110.127.138:65223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9tgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.597708 2026] [security2:error] [pid 116718:tid 116879] [client 77.110.127.138:65223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9tgAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.626401 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9uQAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.626491 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9uQAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:57.695156 2026] [security2:error] [pid 116718:tid 116872] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/cilus.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9vQAAAAg"]
[Mon Jul 20 07:24:57.696253 2026] [security2:error] [pid 116718:tid 116872] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/cilus.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9vQAAAAg"]
[Mon Jul 20 07:24:57.714289 2026] [security2:error] [pid 116718:tid 116804] [remote 45.90.123.233:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9vgAAA0U"]
[Mon Jul 20 07:24:57.760022 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file4.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9wQAAAHo"]
[Mon Jul 20 07:24:57.760049 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file4.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9wQAAAHo"]
[Mon Jul 20 07:24:57.825710 2026] [security2:error] [pid 116718:tid 116917] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/samll.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9ygAAADU"]
[Mon Jul 20 07:24:57.825728 2026] [security2:error] [pid 116718:tid 116917] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/samll.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9ygAAADU"]
[Mon Jul 20 07:24:57.872298 2026] [security2:error] [pid 116718:tid 116926] [client 117.211.236.168:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hqZPWlhYV5NwZ9vU90AAAAD4"]
[Mon Jul 20 07:24:57.872382 2026] [security2:error] [pid 116718:tid 116926] [client 117.211.236.168:64331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hqZPWlhYV5NwZ9vU90AAAAD4"]
[Mon Jul 20 07:24:57.911619 2026] [security2:error] [pid 116718:tid 116955] [client 14.251.3.155:56025] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4hqZPWlhYV5NwZ9vU91gAAAFs"]
[Mon Jul 20 07:24:57.918716 2026] [security2:error] [pid 116718:tid 116883] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/Okxob.php"] [unique_id "al4hqZPWlhYV5NwZ9vU92gAAABM"]
[Mon Jul 20 07:24:57.918736 2026] [security2:error] [pid 116718:tid 116883] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/Okxob.php"] [unique_id "al4hqZPWlhYV5NwZ9vU92gAAABM"]
[Mon Jul 20 07:24:57.921399 2026] [security2:error] [pid 116718:tid 116763] [remote 45.90.123.233:59662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4hqZPWlhYV5NwZ9vU92wAANxw"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 07:24:57.981110 2026] [security2:error] [pid 116718:tid 116912] [client 14.251.3.155:56026] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4hqZPWlhYV5NwZ9vU94AAAADA"]
[Mon Jul 20 07:24:58.025064 2026] [security2:error] [pid 116718:tid 116889] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ok.php"] [unique_id "al4hqpPWlhYV5NwZ9vU95AAAABk"]
[Mon Jul 20 07:24:58.025090 2026] [security2:error] [pid 116718:tid 116889] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ok.php"] [unique_id "al4hqpPWlhYV5NwZ9vU95AAAABk"]
[Mon Jul 20 07:24:58.097817 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wuasr.php"] [unique_id "al4hqpPWlhYV5NwZ9vU97AAAAHk"]
[Mon Jul 20 07:24:58.097846 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wuasr.php"] [unique_id "al4hqpPWlhYV5NwZ9vU97AAAAHk"]
[Mon Jul 20 07:24:58.162981 2026] [security2:error] [pid 116718:tid 116941] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless11.php"] [unique_id "al4hqpPWlhYV5NwZ9vU99QAAAE0"]
[Mon Jul 20 07:24:58.163001 2026] [security2:error] [pid 116718:tid 116941] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bless11.php"] [unique_id "al4hqpPWlhYV5NwZ9vU99QAAAE0"]
[Mon Jul 20 07:24:58.229294 2026] [security2:error] [pid 116718:tid 116979] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-block.php"] [unique_id "al4hqpPWlhYV5NwZ9vU9_AAAAHM"]
[Mon Jul 20 07:24:58.229319 2026] [security2:error] [pid 116718:tid 116979] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-block.php"] [unique_id "al4hqpPWlhYV5NwZ9vU9_AAAAHM"]
[Mon Jul 20 07:24:58.294402 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/aevly.php"] [unique_id "al4hqpPWlhYV5NwZ9vU9_wAAACo"]
[Mon Jul 20 07:24:58.294422 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/aevly.php"] [unique_id "al4hqpPWlhYV5NwZ9vU9_wAAACo"]
[Mon Jul 20 07:24:58.329589 2026] [security2:error] [pid 116718:tid 116892] [client 93.152.221.13:57963] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "autodiscover.musichaven.info"] [uri "/.env.backup"] [unique_id "al4hqpPWlhYV5NwZ9vU-CgAAABw"]
[Mon Jul 20 07:24:58.365104 2026] [security2:error] [pid 116718:tid 116919] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/hello.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-DQAAADc"]
[Mon Jul 20 07:24:58.365130 2026] [security2:error] [pid 116718:tid 116919] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/hello.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-DQAAADc"]
[Mon Jul 20 07:24:58.432680 2026] [security2:error] [pid 116718:tid 116969] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-links-opml.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-EgAAAGk"]
[Mon Jul 20 07:24:58.432707 2026] [security2:error] [pid 116718:tid 116969] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-links-opml.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-EgAAAGk"]
[Mon Jul 20 07:24:58.465723 2026] [security2:error] [pid 116718:tid 116953] [client 93.152.221.13:57963] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.musichaven.info"] [uri "/config/.env"] [unique_id "al4hqpPWlhYV5NwZ9vU-FAAAAFk"]
[Mon Jul 20 07:24:58.489573 2026] [security2:error] [pid 116718:tid 116890] [client 14.225.17.146:53586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9iAAAABo"], referer: http://expertcultures.com/backup
[Mon Jul 20 07:24:58.494010 2026] [security2:error] [pid 116718:tid 116895] [client 185.93.182.171:39180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.182.93.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-FwAAAB8"]
[Mon Jul 20 07:24:58.494111 2026] [security2:error] [pid 116718:tid 116895] [client 185.93.182.171:39180] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-FwAAAB8"]
[Mon Jul 20 07:24:58.495407 2026] [security2:error] [pid 116718:tid 116968] [client 49.47.218.174:52223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-GQAAAGg"]
[Mon Jul 20 07:24:58.495510 2026] [security2:error] [pid 116718:tid 116968] [client 49.47.218.174:52223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-GQAAAGg"]
[Mon Jul 20 07:24:58.553824 2026] [security2:error] [pid 116718:tid 116917] [client 136.158.60.21:22614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-IAAAADU"]
[Mon Jul 20 07:24:58.553958 2026] [security2:error] [pid 116718:tid 116917] [client 136.158.60.21:22614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-IAAAADU"]
[Mon Jul 20 07:24:58.605429 2026] [security2:error] [pid 116718:tid 116917] [client 77.110.127.138:65232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-MQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:58.605518 2026] [security2:error] [pid 116718:tid 116917] [client 77.110.127.138:65232] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-MQAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:58.674663 2026] [security2:error] [pid 116718:tid 116949] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/forbidals.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-MwAAAFU"]
[Mon Jul 20 07:24:58.674695 2026] [security2:error] [pid 116718:tid 116949] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/forbidals.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-MwAAAFU"]
[Mon Jul 20 07:24:58.761201 2026] [security2:error] [pid 116718:tid 116969] [client 93.152.221.13:61226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-OwAAAGk"]
[Mon Jul 20 07:24:58.761782 2026] [security2:error] [pid 116718:tid 116914] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file30.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-OgAAADI"]
[Mon Jul 20 07:24:58.761803 2026] [security2:error] [pid 116718:tid 116914] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file30.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-OgAAADI"]
[Mon Jul 20 07:24:58.827351 2026] [security2:error] [pid 116718:tid 116976] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xda.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-QgAAAHA"]
[Mon Jul 20 07:24:58.827373 2026] [security2:error] [pid 116718:tid 116976] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xda.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-QgAAAHA"]
[Mon Jul 20 07:24:58.893792 2026] [security2:error] [pid 116718:tid 116865] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/z.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-RAAAAAE"]
[Mon Jul 20 07:24:58.893817 2026] [security2:error] [pid 116718:tid 116865] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/z.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-RAAAAAE"]
[Mon Jul 20 07:24:58.952415 2026] [security2:error] [pid 116718:tid 116740] [remote 97.74.93.24:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-SQAANgU"]
[Mon Jul 20 07:24:58.958600 2026] [security2:error] [pid 116718:tid 116989] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/b.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-TQAAAH0"]
[Mon Jul 20 07:24:58.958622 2026] [security2:error] [pid 116718:tid 116989] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/b.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-TQAAAH0"]
[Mon Jul 20 07:24:59.025812 2026] [security2:error] [pid 116718:tid 116939] [client 52.139.36.144:6272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/edit.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-UgAAAEs"]
[Mon Jul 20 07:24:59.025837 2026] [security2:error] [pid 116718:tid 116939] [client 52.139.36.144:6272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/edit.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-UgAAAEs"]
[Mon Jul 20 07:24:59.036180 2026] [security2:error] [pid 116718:tid 116988] [client 93.152.221.13:65346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/test.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-UwAAAHw"]
[Mon Jul 20 07:24:59.055322 2026] [security2:error] [pid 116718:tid 116978] [client 77.110.127.138:65234] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/jetpack/modules/related-posts/related-posts.css0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4hq5PWlhYV5NwZ9vU-VwAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:59.249490 2026] [security2:error] [pid 116718:tid 116985] [client 77.110.127.138:65236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 277 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hq5PWlhYV5NwZ9vU-ZAAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:24:59.395437 2026] [security2:error] [pid 116718:tid 116826] [remote 97.74.93.24:55218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-bgAAMls"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:24:59.442031 2026] [security2:error] [pid 116718:tid 116909] [client 112.86.225.154:59222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/"] [unique_id "al4hq5PWlhYV5NwZ9vU-cgAAAC0"]
[Mon Jul 20 07:24:59.442172 2026] [security2:error] [pid 116718:tid 116909] [client 112.86.225.154:59222] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.liquidationteam.com"] [uri "/"] [unique_id "al4hq5PWlhYV5NwZ9vU-cgAAAC0"]
[Mon Jul 20 07:24:59.483818 2026] [security2:error] [pid 116718:tid 116976] [client 93.152.221.13:58938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/info.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-dwAAAHA"]
[Mon Jul 20 07:24:59.544062 2026] [security2:error] [pid 116718:tid 116922] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/cgi-sys/404.html"] [unique_id "al4hq5PWlhYV5NwZ9vU-fAAAADo"]
[Mon Jul 20 07:24:59.580534 2026] [security2:error] [pid 116718:tid 116945] [client 14.225.17.146:53212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-JAAAAFE"], referer: http://nikkidesigns.net/backup
[Mon Jul 20 07:24:59.584022 2026] [security2:error] [pid 116718:tid 116910] [client 36.93.152.155:64296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-gQAAAC4"]
[Mon Jul 20 07:24:59.584132 2026] [security2:error] [pid 116718:tid 116910] [client 36.93.152.155:64296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-gQAAAC4"]
[Mon Jul 20 07:24:59.611124 2026] [security2:error] [pid 116718:tid 116886] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-png.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-hQAAABY"]
[Mon Jul 20 07:24:59.611151 2026] [security2:error] [pid 116718:tid 116886] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-png.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-hQAAABY"]
[Mon Jul 20 07:24:59.643651 2026] [security2:error] [pid 116718:tid 116969] [client 13.232.231.177:28280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-iQAAAGk"]
[Mon Jul 20 07:24:59.691160 2026] [security2:error] [pid 116718:tid 116869] [client 14.225.17.146:54150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-AQAAAAU"], referer: http://alchemygroup.ca/backup
[Mon Jul 20 07:24:59.760866 2026] [security2:error] [pid 116718:tid 116956] [client 93.152.221.13:51518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/php.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-lQAAAFw"]
[Mon Jul 20 07:24:59.782106 2026] [security2:error] [pid 116718:tid 116963] [client 103.176.215.66:57321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-mgAAAGM"]
[Mon Jul 20 07:24:59.782606 2026] [security2:error] [pid 116718:tid 116963] [client 103.176.215.66:57321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-mgAAAGM"]
[Mon Jul 20 07:24:59.950054 2026] [security2:error] [pid 116718:tid 116884] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/lib.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-pwAAABQ"]
[Mon Jul 20 07:24:59.950087 2026] [security2:error] [pid 116718:tid 116884] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/lib.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-pwAAABQ"]
[Mon Jul 20 07:25:00.023445 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sys.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-rwAAAHo"]
[Mon Jul 20 07:25:00.023468 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sys.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-rwAAAHo"]
[Mon Jul 20 07:25:00.035511 2026] [security2:error] [pid 116718:tid 116964] [client 93.152.221.13:52008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/php_info.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-sQAAAGQ"]
[Mon Jul 20 07:25:00.092807 2026] [security2:error] [pid 116718:tid 116864] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/la.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-twAAAAA"]
[Mon Jul 20 07:25:00.092837 2026] [security2:error] [pid 116718:tid 116864] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/la.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-twAAAAA"]
[Mon Jul 20 07:25:00.163026 2026] [security2:error] [pid 116718:tid 116951] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/tires.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-vQAAAFc"]
[Mon Jul 20 07:25:00.163051 2026] [security2:error] [pid 116718:tid 116951] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/tires.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-vQAAAFc"]
[Mon Jul 20 07:25:00.226968 2026] [security2:error] [pid 116718:tid 116939] [client 116.179.37.136:27208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 136.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotels.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-vwAAAEs"], referer: https://www.savilerowtravel.com/captivating-caribbean-for-ultimate-luxe/
[Mon Jul 20 07:25:00.230294 2026] [security2:error] [pid 116718:tid 116866] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/lv.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-wAAAAAI"]
[Mon Jul 20 07:25:00.230332 2026] [security2:error] [pid 116718:tid 116866] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/lv.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-wAAAAAI"]
[Mon Jul 20 07:25:00.258190 2026] [security2:error] [pid 116718:tid 116972] [client 116.179.37.80:21249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-hotel-interests.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-wwAAAGw"], referer: https://www.savilerowtravel.com/captivating-caribbean-for-ultimate-luxe/
[Mon Jul 20 07:25:00.268622 2026] [security2:error] [pid 116718:tid 116921] [client 14.225.17.146:53936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-tAAAADk"], referer: http://thesoloceos.com/backup
[Mon Jul 20 07:25:00.280698 2026] [security2:error] [pid 116718:tid 116927] [client 14.225.17.146:53366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4hqpPWlhYV5NwZ9vU-TgAAAD8"], referer: http://iagdevelopments.com/backup
[Mon Jul 20 07:25:00.286122 2026] [security2:error] [pid 116718:tid 116978] [client 116.179.37.57:33343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/~saviler1/wp-content/themes/sfmedia/page-templates/inc-tours.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-yQAAAHI"], referer: https://www.savilerowtravel.com/captivating-caribbean-for-ultimate-luxe/
[Mon Jul 20 07:25:00.306013 2026] [security2:error] [pid 116718:tid 116908] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/myfile.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-ygAAACw"]
[Mon Jul 20 07:25:00.306037 2026] [security2:error] [pid 116718:tid 116908] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/myfile.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-ygAAACw"]
[Mon Jul 20 07:25:00.313592 2026] [security2:error] [pid 116718:tid 116955] [client 93.152.221.13:49901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/i.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-zQAAAFs"]
[Mon Jul 20 07:25:00.371384 2026] [security2:error] [pid 116718:tid 116884] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/06.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-1AAAABQ"]
[Mon Jul 20 07:25:00.371437 2026] [security2:error] [pid 116718:tid 116884] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/06.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-1AAAABQ"]
[Mon Jul 20 07:25:00.437743 2026] [security2:error] [pid 116718:tid 116969] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fs.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-1wAAAGk"]
[Mon Jul 20 07:25:00.437776 2026] [security2:error] [pid 116718:tid 116969] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fs.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-1wAAAGk"]
[Mon Jul 20 07:25:00.504348 2026] [security2:error] [pid 116718:tid 116869] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/asasx.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-3gAAAAU"]
[Mon Jul 20 07:25:00.504374 2026] [security2:error] [pid 116718:tid 116869] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/asasx.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-3gAAAAU"]
[Mon Jul 20 07:25:00.571036 2026] [security2:error] [pid 116718:tid 116913] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-5AAAADE"]
[Mon Jul 20 07:25:00.571059 2026] [security2:error] [pid 116718:tid 116913] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-kd4xalrg7m.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-5AAAADE"]
[Mon Jul 20 07:25:00.584523 2026] [security2:error] [pid 116718:tid 116795] [remote 154.120.133.86:14965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.133.120.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-4wAARTw"]
[Mon Jul 20 07:25:00.591650 2026] [security2:error] [pid 116718:tid 116971] [client 93.152.221.13:65472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/pi.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-6AAAAGs"]
[Mon Jul 20 07:25:00.594625 2026] [security2:error] [pid 116718:tid 116882] [client 156.223.234.242:15397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4hq5PWlhYV5NwZ9vU-XQAAABI"]
[Mon Jul 20 07:25:00.661414 2026] [security2:error] [pid 116718:tid 116968] [client 13.232.231.177:28294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-7QAAAGg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:25:00.806679 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-good.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-_gAAADY"]
[Mon Jul 20 07:25:00.806710 2026] [security2:error] [pid 116718:tid 116918] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-good.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-_gAAADY"]
[Mon Jul 20 07:25:00.807430 2026] [security2:error] [pid 116718:tid 116891] [client 57.141.18.15:29316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hp5PWlhYV5NwZ9vU89QAAG2M"]
[Mon Jul 20 07:25:00.810462 2026] [security2:error] [pid 116718:tid 116922] [client 14.225.17.146:53073] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-7AAAADo"], referer: http://dnsplumbing.com/backup
[Mon Jul 20 07:25:00.871166 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/scxy.php"] [unique_id "al4hrJPWlhYV5NwZ9vU_CQAAAHo"]
[Mon Jul 20 07:25:00.871189 2026] [security2:error] [pid 116718:tid 116986] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/scxy.php"] [unique_id "al4hrJPWlhYV5NwZ9vU_CQAAAHo"]
[Mon Jul 20 07:25:00.937634 2026] [security2:error] [pid 116718:tid 116864] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wmore1.php"] [unique_id "al4hrJPWlhYV5NwZ9vU_DAAAAAA"]
[Mon Jul 20 07:25:00.937662 2026] [security2:error] [pid 116718:tid 116864] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wmore1.php"] [unique_id "al4hrJPWlhYV5NwZ9vU_DAAAAAA"]
[Mon Jul 20 07:25:01.003597 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/like.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_DwAAABA"]
[Mon Jul 20 07:25:01.003619 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/like.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_DwAAABA"]
[Mon Jul 20 07:25:01.027054 2026] [security2:error] [pid 116718:tid 116873] [client 93.152.221.13:56085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_EgAAAAk"]
[Mon Jul 20 07:25:01.077215 2026] [security2:error] [pid 116718:tid 116881] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/x.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_FQAAABE"]
[Mon Jul 20 07:25:01.077241 2026] [security2:error] [pid 116718:tid 116881] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/x.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_FQAAABE"]
[Mon Jul 20 07:25:01.114346 2026] [security2:error] [pid 116718:tid 116808] [remote 154.120.133.86:14965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.133.120.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_GAAAdEk"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 07:25:01.142187 2026] [security2:error] [pid 116718:tid 116897] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xa.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_HwAAACE"]
[Mon Jul 20 07:25:01.142208 2026] [security2:error] [pid 116718:tid 116897] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xa.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_HwAAACE"]
[Mon Jul 20 07:25:01.207120 2026] [security2:error] [pid 116718:tid 116876] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/kolda.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_KAAAAAw"]
[Mon Jul 20 07:25:01.207141 2026] [security2:error] [pid 116718:tid 116876] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/kolda.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_KAAAAAw"]
[Mon Jul 20 07:25:01.218204 2026] [security2:error] [pid 116718:tid 116874] [client 14.225.17.146:54007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-vgAAAAo"], referer: http://intelligentengineeringsolutions.com/backup
[Mon Jul 20 07:25:01.240237 2026] [security2:error] [pid 116718:tid 116942] [client 103.106.165.44:55407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_KgAAAE4"]
[Mon Jul 20 07:25:01.240438 2026] [security2:error] [pid 116718:tid 116942] [client 103.106.165.44:55407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_KgAAAE4"]
[Mon Jul 20 07:25:01.257967 2026] [security2:error] [pid 116718:tid 116886] [client 14.225.17.146:53314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_GQAAABY"], referer: https://thesoloceos.com/backup
[Mon Jul 20 07:25:01.269805 2026] [security2:error] [pid 116718:tid 116958] [client 14.225.17.146:53349] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_JgAAAF4"], referer: https://iagdevelopments.com/backup
[Mon Jul 20 07:25:01.302647 2026] [security2:error] [pid 116718:tid 116885] [client 93.152.221.13:60041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_LgAAABU"]
[Mon Jul 20 07:25:01.355571 2026] [security2:error] [pid 116718:tid 116947] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-aothait.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_NQAAAFM"]
[Mon Jul 20 07:25:01.355596 2026] [security2:error] [pid 116718:tid 116947] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-aothait.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_NQAAAFM"]
[Mon Jul 20 07:25:01.569956 2026] [security2:error] [pid 116718:tid 116897] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ftde.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_TAAAACE"]
[Mon Jul 20 07:25:01.569983 2026] [security2:error] [pid 116718:tid 116897] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ftde.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_TAAAACE"]
[Mon Jul 20 07:25:01.575968 2026] [security2:error] [pid 116718:tid 116916] [client 93.152.221.13:62897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.musichaven.info"] [uri "/php_version.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_TQAAADQ"]
[Mon Jul 20 07:25:01.626614 2026] [security2:error] [pid 116718:tid 116990] [client 201.27.111.74:59072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_UwAAAH4"]
[Mon Jul 20 07:25:01.626798 2026] [security2:error] [pid 116718:tid 116990] [client 201.27.111.74:59072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_UwAAAH4"]
[Mon Jul 20 07:25:01.642008 2026] [security2:error] [pid 116718:tid 116942] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/vx.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_VAAAAE4"]
[Mon Jul 20 07:25:01.642033 2026] [security2:error] [pid 116718:tid 116942] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/vx.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_VAAAAE4"]
[Mon Jul 20 07:25:01.648743 2026] [security2:error] [pid 116718:tid 116926] [client 191.202.66.27:52420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_VQAAAD4"]
[Mon Jul 20 07:25:01.648884 2026] [security2:error] [pid 116718:tid 116926] [client 191.202.66.27:52420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_VQAAAD4"]
[Mon Jul 20 07:25:01.724736 2026] [security2:error] [pid 116718:tid 116869] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/a5.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_YQAAAAU"]
[Mon Jul 20 07:25:01.724776 2026] [security2:error] [pid 116718:tid 116869] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/a5.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_YQAAAAU"]
[Mon Jul 20 07:25:01.757348 2026] [security2:error] [pid 116718:tid 116938] [client 188.166.91.169:59404] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.generationloveproject.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_ZQAAAEo"]
[Mon Jul 20 07:25:01.871763 2026] [security2:error] [pid 116718:tid 116889] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-sing.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_cwAAABk"]
[Mon Jul 20 07:25:01.871795 2026] [security2:error] [pid 116718:tid 116889] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-sing.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_cwAAABk"]
[Mon Jul 20 07:25:01.926083 2026] [security2:error] [pid 116718:tid 116942] [client 15.204.80.170:51238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "giftofgiving-usa.org"] [uri "/"] [unique_id "al4hrZPWlhYV5NwZ9vU_dwAAAE4"]
[Mon Jul 20 07:25:01.939291 2026] [security2:error] [pid 116718:tid 116978] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/database.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_eAAAAHI"]
[Mon Jul 20 07:25:01.939321 2026] [security2:error] [pid 116718:tid 116978] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/database.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_eAAAAHI"]
[Mon Jul 20 07:25:02.005694 2026] [security2:error] [pid 116718:tid 116919] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/explorer/index_.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_fQAAADc"]
[Mon Jul 20 07:25:02.005722 2026] [security2:error] [pid 116718:tid 116919] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/explorer/index_.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_fQAAADc"]
[Mon Jul 20 07:25:02.017917 2026] [security2:error] [pid 116718:tid 116903] [client 57.141.18.105:42042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hqJPWlhYV5NwZ9vU9WwAAJ1w"]
[Mon Jul 20 07:25:02.028996 2026] [security2:error] [pid 116718:tid 116932] [client 93.152.221.13:54793] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.musichaven.info"] [uri "/___proxy_subdomain_cpanel/.env"] [unique_id "al4hrpPWlhYV5NwZ9vU_gQAAAEQ"]
[Mon Jul 20 07:25:02.096312 2026] [security2:error] [pid 116718:tid 116870] [client 50.116.65.227:35954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hrpPWlhYV5NwZ9vU_iQAAAAY"]
[Mon Jul 20 07:25:02.106419 2026] [security2:error] [pid 116718:tid 116881] [client 50.116.65.227:35962] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hrpPWlhYV5NwZ9vU_igAAABE"]
[Mon Jul 20 07:25:02.116808 2026] [security2:error] [pid 116718:tid 116882] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-at.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_jAAAABI"]
[Mon Jul 20 07:25:02.116827 2026] [security2:error] [pid 116718:tid 116882] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-at.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_jAAAABI"]
[Mon Jul 20 07:25:02.217541 2026] [security2:error] [pid 116718:tid 116968] [client 88.241.67.160:55834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_mAAAAGg"]
[Mon Jul 20 07:25:02.218968 2026] [security2:error] [pid 116718:tid 116968] [client 88.241.67.160:55834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_mAAAAGg"]
[Mon Jul 20 07:25:02.369243 2026] [security2:error] [pid 116718:tid 116927] [client 110.249.201.217:40028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mrbambooplus.com"] [uri "/robots.txt"] [unique_id "al4hrpPWlhYV5NwZ9vU_qgAAAD8"]
[Mon Jul 20 07:25:02.379465 2026] [security2:error] [pid 116718:tid 116945] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-wz.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_rAAAAFE"]
[Mon Jul 20 07:25:02.379486 2026] [security2:error] [pid 116718:tid 116945] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-wz.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_rAAAAFE"]
[Mon Jul 20 07:25:02.449345 2026] [security2:error] [pid 116718:tid 116896] [client 157.20.138.62:53211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_rwAAACA"]
[Mon Jul 20 07:25:02.449437 2026] [security2:error] [pid 116718:tid 116896] [client 157.20.138.62:53211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_rwAAACA"]
[Mon Jul 20 07:25:02.515185 2026] [security2:error] [pid 116718:tid 116971] [client 93.152.221.13:54793] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpanel.musichaven.info"] [uri "/___proxy_subdomain_cpanel/.env.backup"] [unique_id "al4hrpPWlhYV5NwZ9vU_tgAAAGs"]
[Mon Jul 20 07:25:02.529585 2026] [security2:error] [pid 116718:tid 116989] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-ver.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_uQAAAH0"]
[Mon Jul 20 07:25:02.529613 2026] [security2:error] [pid 116718:tid 116989] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-ver.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_uQAAAH0"]
[Mon Jul 20 07:25:02.581809 2026] [security2:error] [pid 116718:tid 116905] [client 179.127.84.238:53721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_vQAAACk"]
[Mon Jul 20 07:25:02.581913 2026] [security2:error] [pid 116718:tid 116905] [client 179.127.84.238:53721] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_vQAAACk"]
[Mon Jul 20 07:25:02.594787 2026] [security2:error] [pid 116718:tid 116980] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp5.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_vgAAAHQ"]
[Mon Jul 20 07:25:02.594804 2026] [security2:error] [pid 116718:tid 116980] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp5.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_vgAAAHQ"]
[Mon Jul 20 07:25:02.655015 2026] [security2:error] [pid 116718:tid 116913] [client 93.152.221.13:54793] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpanel.musichaven.info"] [uri "/___proxy_subdomain_cpanel/config/.env"] [unique_id "al4hrpPWlhYV5NwZ9vU_wwAAADE"]
[Mon Jul 20 07:25:02.660671 2026] [security2:error] [pid 116718:tid 116874] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-pp.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_xQAAAAo"]
[Mon Jul 20 07:25:02.660699 2026] [security2:error] [pid 116718:tid 116874] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-pp.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_xQAAAAo"]
[Mon Jul 20 07:25:02.767213 2026] [security2:error] [pid 116718:tid 116895] [client 14.225.17.146:57048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_SwAAAB8"], referer: http://christiancountytrumpet.com/backup
[Mon Jul 20 07:25:02.825254 2026] [security2:error] [pid 116718:tid 116903] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/w3lls.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_1gAAACc"]
[Mon Jul 20 07:25:02.825275 2026] [security2:error] [pid 116718:tid 116903] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/w3lls.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_1gAAACc"]
[Mon Jul 20 07:25:02.895499 2026] [security2:error] [pid 116718:tid 116740] [remote 173.249.4.11:11666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_4AAAJgU"]
[Mon Jul 20 07:25:02.905026 2026] [security2:error] [pid 116718:tid 116984] [client 57.141.18.3:61384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hqZPWlhYV5NwZ9vU9vwAAeAY"]
[Mon Jul 20 07:25:02.911349 2026] [security2:error] [pid 116718:tid 116748] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_4QAAeQ0"]
[Mon Jul 20 07:25:02.911524 2026] [security2:error] [pid 116718:tid 116985] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_4QAAeQ0"]
[Mon Jul 20 07:25:02.938982 2026] [security2:error] [pid 116718:tid 116929] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sbhu.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_5AAAAEE"]
[Mon Jul 20 07:25:02.939011 2026] [security2:error] [pid 116718:tid 116929] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sbhu.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_5AAAAEE"]
[Mon Jul 20 07:25:02.964056 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_4wAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:02.964178 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:65246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hrpPWlhYV5NwZ9vU_4wAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:03.011509 2026] [security2:error] [pid 116718:tid 116777] [remote 124.55.178.99:43378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_5wAAFio"]
[Mon Jul 20 07:25:03.014582 2026] [security2:error] [pid 116718:tid 116908] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_5gAAACw"]
[Mon Jul 20 07:25:03.014609 2026] [security2:error] [pid 116718:tid 116908] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-content/uploads/admin.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_5gAAACw"]
[Mon Jul 20 07:25:03.082040 2026] [security2:error] [pid 116718:tid 116890] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/favicon.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_6wAAABo"]
[Mon Jul 20 07:25:03.082064 2026] [security2:error] [pid 116718:tid 116890] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/favicon.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_6wAAABo"]
[Mon Jul 20 07:25:03.083003 2026] [security2:error] [pid 116718:tid 116788] [remote 173.249.4.11:11666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_7AAAQzU"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 07:25:03.147531 2026] [security2:error] [pid 116718:tid 116939] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/txets.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_9AAAAEs"]
[Mon Jul 20 07:25:03.147553 2026] [security2:error] [pid 116718:tid 116939] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/txets.php"] [unique_id "al4hr5PWlhYV5NwZ9vU_9AAAAEs"]
[Mon Jul 20 07:25:03.170149 2026] [security2:error] [pid 116718:tid 116911] [client 57.141.18.25:31440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hqpPWlhYV5NwZ9vU94wAALwQ"]
[Mon Jul 20 07:25:03.239594 2026] [security2:error] [pid 116718:tid 116963] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-su.php"] [unique_id "al4hr5PWlhYV5NwZ9vU__AAAAGM"]
[Mon Jul 20 07:25:03.239619 2026] [security2:error] [pid 116718:tid 116963] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-su.php"] [unique_id "al4hr5PWlhYV5NwZ9vU__AAAAGM"]
[Mon Jul 20 07:25:03.286019 2026] [security2:error] [pid 116718:tid 116868] [client 57.141.18.54:37062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hqpPWlhYV5NwZ9vU97QAABAA"]
[Mon Jul 20 07:25:03.332597 2026] [proxy:error] [pid 116718:tid 116906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:03.332631 2026] [proxy_http:error] [pid 116718:tid 116906] [client 93.152.221.13:60698] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:03.333374 2026] [proxy:error] [pid 116718:tid 116906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:03.333400 2026] [proxy_http:error] [pid 116718:tid 116906] [client 93.152.221.13:60698] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:03.441084 2026] [security2:error] [pid 116718:tid 116757] [remote 124.55.178.99:43378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4hr5PWlhYV5NwZ9vVADQAABRY"], referer: https://lmgorman.com/wp-login.php
[Mon Jul 20 07:25:03.525623 2026] [security2:error] [pid 116718:tid 116941] [client 158.173.166.181:31961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAGQAAAE0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:25:03.586217 2026] [security2:error] [pid 116718:tid 116931] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAEwAAAEM"]
[Mon Jul 20 07:25:03.586254 2026] [security2:error] [pid 116718:tid 116931] [client 74.7.228.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAEwAAAEM"]
[Mon Jul 20 07:25:03.589154 2026] [security2:error] [pid 116718:tid 116882] [client 74.7.228.2:32902] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/robots.txt"] [unique_id "al4hr5PWlhYV5NwZ9vVADwAAElA"]
[Mon Jul 20 07:25:03.620449 2026] [security2:error] [pid 116718:tid 116978] [client 93.152.221.13:55647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAHQAAAHI"]
[Mon Jul 20 07:25:03.851959 2026] [security2:error] [pid 116718:tid 116928] [client 14.225.17.146:57003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_QQAAAEA"], referer: http://drewsasburyparkbeachhouse.com/backup
[Mon Jul 20 07:25:03.897845 2026] [security2:error] [pid 116718:tid 116867] [client 74.7.228.2:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAMAAAAAM"], referer: https://travelbyfire.com/robots.txt
[Mon Jul 20 07:25:03.898498 2026] [security2:error] [pid 116718:tid 116908] [client 93.152.221.13:56793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/test.php"] [unique_id "al4hr5PWlhYV5NwZ9vVANwAAACw"]
[Mon Jul 20 07:25:03.905394 2026] [security2:error] [pid 116718:tid 116933] [client 74.7.228.2:32910] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/robots.txt"] [unique_id "al4hr5PWlhYV5NwZ9vVAJgAARWA"], referer: https://travelbyfire.com/robots.txt
[Mon Jul 20 07:25:03.929835 2026] [security2:error] [pid 116718:tid 116970] [client 34.147.91.161:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "www.rootedandwholecoaching.com.heidimortenson.com"] [uri "/"] [unique_id "al4hr5PWlhYV5NwZ9vVAOgAAAGo"]
[Mon Jul 20 07:25:03.929920 2026] [security2:error] [pid 116718:tid 116970] [client 34.147.91.161:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.rootedandwholecoaching.com.heidimortenson.com"] [uri "/"] [unique_id "al4hr5PWlhYV5NwZ9vVAOgAAAGo"]
[Mon Jul 20 07:25:03.989077 2026] [security2:error] [pid 116718:tid 116929] [client 154.192.123.127:17481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAPgAAAEE"]
[Mon Jul 20 07:25:03.989373 2026] [security2:error] [pid 116718:tid 116929] [client 154.192.123.127:17481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hr5PWlhYV5NwZ9vVAPgAAAEE"]
[Mon Jul 20 07:25:04.177492 2026] [proxy:error] [pid 116718:tid 116871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:04.177570 2026] [proxy_http:error] [pid 116718:tid 116871] [client 93.152.221.13:59053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:04.178224 2026] [proxy:error] [pid 116718:tid 116871] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:04.178256 2026] [proxy_http:error] [pid 116718:tid 116871] [client 93.152.221.13:59053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:04.250420 2026] [security2:error] [pid 116718:tid 116902] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ff.php"] [unique_id "al4hsJPWlhYV5NwZ9vVATAAAACY"]
[Mon Jul 20 07:25:04.250448 2026] [security2:error] [pid 116718:tid 116902] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ff.php"] [unique_id "al4hsJPWlhYV5NwZ9vVATAAAACY"]
[Mon Jul 20 07:25:04.318221 2026] [security2:error] [pid 116718:tid 116958] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/reze.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAWgAAAF4"]
[Mon Jul 20 07:25:04.318249 2026] [security2:error] [pid 116718:tid 116958] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/reze.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAWgAAAF4"]
[Mon Jul 20 07:25:04.328642 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:65269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAYAAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:04.328742 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:65269] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAYAAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:04.333216 2026] [security2:error] [pid 116718:tid 116801] [remote 97.74.93.24:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.think-islam.com"] [uri "/wp-login.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAWwAAD0I"]
[Mon Jul 20 07:25:04.384576 2026] [security2:error] [pid 116718:tid 116924] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/666.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAZwAAADw"]
[Mon Jul 20 07:25:04.384612 2026] [security2:error] [pid 116718:tid 116924] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/666.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAZwAAADw"]
[Mon Jul 20 07:25:04.460235 2026] [security2:error] [pid 116718:tid 116944] [client 93.152.221.13:56081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/info.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAawAAAFA"]
[Mon Jul 20 07:25:04.473880 2026] [security2:error] [pid 116718:tid 116940] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wehrman.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAbAAAAEw"]
[Mon Jul 20 07:25:04.473902 2026] [security2:error] [pid 116718:tid 116940] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wehrman.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAbAAAAEw"]
[Mon Jul 20 07:25:04.540451 2026] [security2:error] [pid 116718:tid 116921] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-conflg.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAdQAAADk"]
[Mon Jul 20 07:25:04.540476 2026] [security2:error] [pid 116718:tid 116921] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-conflg.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAdQAAADk"]
[Mon Jul 20 07:25:04.605998 2026] [security2:error] [pid 116718:tid 116943] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ff1.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAfAAAAE8"]
[Mon Jul 20 07:25:04.606020 2026] [security2:error] [pid 116718:tid 116943] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ff1.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAfAAAAE8"]
[Mon Jul 20 07:25:04.695021 2026] [security2:error] [pid 116718:tid 116967] [client 81.152.56.199:65266] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAfgAAAGc"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 07:25:04.699791 2026] [security2:error] [pid 116718:tid 116928] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fff.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAgwAAAEA"]
[Mon Jul 20 07:25:04.699838 2026] [security2:error] [pid 116718:tid 116928] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/fff.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAgwAAAEA"]
[Mon Jul 20 07:25:04.723500 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:65275] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAhwAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:04.723591 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:65275] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAhwAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:04.764719 2026] [security2:error] [pid 116718:tid 116799] [remote 97.74.93.24:59830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.think-islam.com"] [uri "/wp-login.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAiwAAOkA"], referer: https://mail.think-islam.com/wp-login.php
[Mon Jul 20 07:25:04.882142 2026] [security2:error] [pid 116718:tid 116898] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAUQAAInQ"], referer: http://ardhalwafaa.com/backup
[Mon Jul 20 07:25:04.913138 2026] [security2:error] [pid 116718:tid 116944] [client 93.152.221.13:61996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/php.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAnwAAAFA"]
[Mon Jul 20 07:25:04.972202 2026] [security2:error] [pid 116718:tid 116967] [client 81.152.56.199:65266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAfgAAAGc"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 07:25:04.972253 2026] [security2:error] [pid 116718:tid 116967] [client 81.152.56.199:65266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAfgAAAGc"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/
[Mon Jul 20 07:25:05.018663 2026] [security2:error] [pid 116718:tid 116968] [client 14.225.17.146:64696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAiAAAAGg"], referer: http://guidehunting.com/backup
[Mon Jul 20 07:25:05.037524 2026] [security2:error] [pid 116718:tid 116842] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hsZPWlhYV5NwZ9vVAqgAAVWs"]
[Mon Jul 20 07:25:05.037691 2026] [security2:error] [pid 116718:tid 116949] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hsZPWlhYV5NwZ9vVAqgAAVWs"]
[Mon Jul 20 07:25:05.046121 2026] [security2:error] [pid 116718:tid 116917] [client 57.141.18.11:32754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hrJPWlhYV5NwZ9vU-uwAANWE"]
[Mon Jul 20 07:25:05.102192 2026] [security2:error] [pid 116718:tid 116803] [remote 18.61.192.253:48360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hsZPWlhYV5NwZ9vVArwAAb0Q"]
[Mon Jul 20 07:25:05.102390 2026] [security2:error] [pid 116718:tid 116975] [client 18.61.192.253:48360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4hsZPWlhYV5NwZ9vVArwAAb0Q"]
[Mon Jul 20 07:25:05.187913 2026] [security2:error] [pid 116718:tid 116988] [client 93.152.221.13:59363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/php_info.php"] [unique_id "al4hsZPWlhYV5NwZ9vVAtgAAAHw"]
[Mon Jul 20 07:25:05.212577 2026] [security2:error] [pid 116718:tid 116936] [client 77.110.127.138:65279] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 314 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4hsZPWlhYV5NwZ9vVAugAAAEg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:05.460994 2026] [security2:error] [pid 116718:tid 116968] [client 93.152.221.13:56519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/i.php"] [unique_id "al4hsZPWlhYV5NwZ9vVA2gAAAGg"]
[Mon Jul 20 07:25:05.484788 2026] [security2:error] [pid 116718:tid 116745] [remote 57.141.18.125:33014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4hsZPWlhYV5NwZ9vVA3QAALgo"]
[Mon Jul 20 07:25:05.665425 2026] [security2:error] [pid 116718:tid 116934] [client 42.113.60.89:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4hsZPWlhYV5NwZ9vVA5wAAAEY"]
[Mon Jul 20 07:25:05.735428 2026] [security2:error] [pid 116718:tid 116935] [client 93.152.221.13:50221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/pi.php"] [unique_id "al4hsZPWlhYV5NwZ9vVA-AAAAEc"]
[Mon Jul 20 07:25:06.010871 2026] [proxy:error] [pid 116718:tid 116883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:06.010956 2026] [proxy_http:error] [pid 116718:tid 116883] [client 93.152.221.13:57267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:06.011625 2026] [proxy:error] [pid 116718:tid 116883] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:06.011667 2026] [proxy_http:error] [pid 116718:tid 116883] [client 93.152.221.13:57267] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:06.150036 2026] [security2:error] [pid 116718:tid 116956] [client 14.225.17.146:54789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4hsZPWlhYV5NwZ9vVBBwAAAFw"], referer: https://guidehunting.com/backup
[Mon Jul 20 07:25:06.160335 2026] [security2:error] [pid 116718:tid 116907] [client 57.141.18.78:24148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hrZPWlhYV5NwZ9vU_PAAAK3U"]
[Mon Jul 20 07:25:06.289093 2026] [security2:error] [pid 116718:tid 116987] [client 93.152.221.13:56057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hspPWlhYV5NwZ9vVBKQAAAHs"]
[Mon Jul 20 07:25:06.327108 2026] [security2:error] [pid 116718:tid 116944] [client 14.225.17.146:64146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4hsZPWlhYV5NwZ9vVBFwAAAFA"]
[Mon Jul 20 07:25:06.565692 2026] [security2:error] [pid 116718:tid 116925] [client 93.152.221.13:65303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hspPWlhYV5NwZ9vVBVgAAAD0"]
[Mon Jul 20 07:25:06.593725 2026] [security2:error] [pid 116718:tid 116735] [remote 47.86.33.52:43884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4hspPWlhYV5NwZ9vVBWAAACAA"]
[Mon Jul 20 07:25:06.731182 2026] [security2:error] [pid 116718:tid 116871] [client 14.225.17.146:63072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4hsZPWlhYV5NwZ9vVAvwAAAAc"], referer: http://sarahsnyder.net/backup
[Mon Jul 20 07:25:06.843234 2026] [security2:error] [pid 116718:tid 116984] [client 93.152.221.13:55424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcalendars.musichaven.info"] [uri "/php_version.php"] [unique_id "al4hspPWlhYV5NwZ9vVBaAAAAHg"]
[Mon Jul 20 07:25:07.007283 2026] [security2:error] [pid 116718:tid 116753] [remote 57.141.18.95:38612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4hspPWlhYV5NwZ9vVBqQAASxI"]
[Mon Jul 20 07:25:07.018358 2026] [security2:error] [pid 116718:tid 116937] [client 24.200.64.150:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4hspPWlhYV5NwZ9vVBYAAASVs"]
[Mon Jul 20 07:25:07.046386 2026] [security2:error] [pid 116718:tid 116968] [client 143.44.185.218:42527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBsQAAAGg"]
[Mon Jul 20 07:25:07.046485 2026] [security2:error] [pid 116718:tid 116968] [client 143.44.185.218:42527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBsQAAAGg"]
[Mon Jul 20 07:25:07.062222 2026] [security2:error] [pid 116718:tid 116971] [client 185.93.182.171:39188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.182.93.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBswAAAGs"]
[Mon Jul 20 07:25:07.062366 2026] [security2:error] [pid 116718:tid 116971] [client 185.93.182.171:39188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBswAAAGs"]
[Mon Jul 20 07:25:07.127855 2026] [proxy:error] [pid 116718:tid 116987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.127967 2026] [proxy_http:error] [pid 116718:tid 116987] [client 93.152.221.13:56899] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.129396 2026] [proxy:error] [pid 116718:tid 116987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.129434 2026] [proxy_http:error] [pid 116718:tid 116987] [client 93.152.221.13:56899] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.139628 2026] [security2:error] [pid 116718:tid 116762] [remote 47.86.33.52:43884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBuAAAOhs"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:25:07.143202 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:65300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBuQAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:07.143295 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:65300] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBuQAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:07.194020 2026] [security2:error] [pid 116718:tid 116986] [client 77.110.127.138:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBvwAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:07.194141 2026] [security2:error] [pid 116718:tid 116986] [client 77.110.127.138:65274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBvwAAAHo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:07.309115 2026] [security2:error] [pid 116718:tid 116917] [client 154.208.48.130:55157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBxgAAADU"]
[Mon Jul 20 07:25:07.309783 2026] [security2:error] [pid 116718:tid 116917] [client 154.208.48.130:55157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBxgAAADU"]
[Mon Jul 20 07:25:07.404834 2026] [security2:error] [pid 116718:tid 116891] [client 93.152.221.13:57901] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/.env"] [unique_id "al4hs5PWlhYV5NwZ9vVB0QAAABs"]
[Mon Jul 20 07:25:07.450352 2026] [security2:error] [pid 116718:tid 116871] [client 104.234.53.47:23501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hs5PWlhYV5NwZ9vVB3wAAAAc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:07.512950 2026] [security2:error] [pid 116718:tid 116869] [client 202.141.11.99:36039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVB7AAAAAU"]
[Mon Jul 20 07:25:07.513064 2026] [security2:error] [pid 116718:tid 116869] [client 202.141.11.99:36039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4hs5PWlhYV5NwZ9vVB7AAAAAU"]
[Mon Jul 20 07:25:07.541982 2026] [proxy:error] [pid 116718:tid 116965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.542079 2026] [proxy_http:error] [pid 116718:tid 116965] [client 93.152.221.13:57901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.542920 2026] [proxy:error] [pid 116718:tid 116965] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.542980 2026] [proxy_http:error] [pid 116718:tid 116965] [client 93.152.221.13:57901] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.702725 2026] [security2:error] [pid 116718:tid 116929] [client 14.225.17.146:52982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4hs5PWlhYV5NwZ9vVB9gAAAEE"], referer: https://sarahsnyder.net/backup
[Mon Jul 20 07:25:07.824341 2026] [proxy:error] [pid 116718:tid 116960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.824415 2026] [proxy_http:error] [pid 116718:tid 116960] [client 93.152.221.13:51130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.824994 2026] [proxy:error] [pid 116718:tid 116960] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.825021 2026] [proxy_http:error] [pid 116718:tid 116960] [client 93.152.221.13:51130] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.896139 2026] [security2:error] [pid 116718:tid 116982] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/amax.php"] [unique_id "al4hs5PWlhYV5NwZ9vVCEgAAAHY"]
[Mon Jul 20 07:25:07.896159 2026] [security2:error] [pid 116718:tid 116982] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/amax.php"] [unique_id "al4hs5PWlhYV5NwZ9vVCEgAAAHY"]
[Mon Jul 20 07:25:07.961259 2026] [security2:error] [pid 116718:tid 116897] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-firewall.php"] [unique_id "al4hs5PWlhYV5NwZ9vVCHAAAACE"]
[Mon Jul 20 07:25:07.961286 2026] [security2:error] [pid 116718:tid 116897] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-firewall.php"] [unique_id "al4hs5PWlhYV5NwZ9vVCHAAAACE"]
[Mon Jul 20 07:25:07.995613 2026] [proxy:error] [pid 116718:tid 116938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.995685 2026] [proxy_http:error] [pid 116718:tid 116938] [client 93.152.221.13:50664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:07.996120 2026] [proxy:error] [pid 116718:tid 116938] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:07.996143 2026] [proxy_http:error] [pid 116718:tid 116938] [client 93.152.221.13:50664] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:08.056231 2026] [security2:error] [pid 116718:tid 116898] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/appt.php"] [unique_id "al4htJPWlhYV5NwZ9vVCJwAAACI"]
[Mon Jul 20 07:25:08.056257 2026] [security2:error] [pid 116718:tid 116898] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/appt.php"] [unique_id "al4htJPWlhYV5NwZ9vVCJwAAACI"]
[Mon Jul 20 07:25:08.100980 2026] [security2:error] [pid 116718:tid 116906] [client 93.152.221.13:51114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/.env.backup"] [unique_id "al4htJPWlhYV5NwZ9vVCKwAAACo"]
[Mon Jul 20 07:25:08.122423 2026] [security2:error] [pid 116718:tid 116954] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-thi.php"] [unique_id "al4htJPWlhYV5NwZ9vVCMQAAAFo"]
[Mon Jul 20 07:25:08.122447 2026] [security2:error] [pid 116718:tid 116954] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-thi.php"] [unique_id "al4htJPWlhYV5NwZ9vVCMQAAAFo"]
[Mon Jul 20 07:25:08.193352 2026] [security2:error] [pid 116718:tid 116911] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/jj.php"] [unique_id "al4htJPWlhYV5NwZ9vVCNgAAAC8"]
[Mon Jul 20 07:25:08.193392 2026] [security2:error] [pid 116718:tid 116911] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/jj.php"] [unique_id "al4htJPWlhYV5NwZ9vVCNgAAAC8"]
[Mon Jul 20 07:25:08.203530 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4htJPWlhYV5NwZ9vVCIgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:08.240273 2026] [security2:error] [pid 116718:tid 116990] [client 93.152.221.13:51114] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcalendars.musichaven.info"] [uri "/___proxy_subdomain_cpcalendars/config/.env"] [unique_id "al4htJPWlhYV5NwZ9vVCOAAAAH4"]
[Mon Jul 20 07:25:08.249378 2026] [security2:error] [pid 116718:tid 116970] [client 49.37.242.14:51987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4htJPWlhYV5NwZ9vVCOwAAAGo"]
[Mon Jul 20 07:25:08.249462 2026] [security2:error] [pid 116718:tid 116970] [client 49.37.242.14:51987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4htJPWlhYV5NwZ9vVCOwAAAGo"]
[Mon Jul 20 07:25:08.257634 2026] [security2:error] [pid 116718:tid 116822] [remote 72.167.132.114:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4htJPWlhYV5NwZ9vVCOgAAWFc"]
[Mon Jul 20 07:25:08.265267 2026] [security2:error] [pid 116718:tid 116794] [remote 192.241.143.148:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4htJPWlhYV5NwZ9vVCPAAAQTs"]
[Mon Jul 20 07:25:08.270679 2026] [security2:error] [pid 116718:tid 116960] [client 93.152.221.13:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4htJPWlhYV5NwZ9vVCPQAAAGA"]
[Mon Jul 20 07:25:08.377581 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:65308] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4htJPWlhYV5NwZ9vVCSQAAAEk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:08.437994 2026] [security2:error] [pid 116718:tid 116807] [remote 192.241.143.148:55336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4htJPWlhYV5NwZ9vVCTgAALkg"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 07:25:08.465682 2026] [security2:error] [pid 116718:tid 116956] [client 14.225.17.146:63890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBxAAAAFw"], referer: http://wathenbartlett.co.uk/backup
[Mon Jul 20 07:25:08.541950 2026] [security2:error] [pid 116718:tid 116785] [remote 72.167.132.114:43536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4htJPWlhYV5NwZ9vVCVAAAezI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:25:08.543000 2026] [security2:error] [pid 116718:tid 116875] [client 93.152.221.13:59507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/test.php"] [unique_id "al4htJPWlhYV5NwZ9vVCVgAAAAs"]
[Mon Jul 20 07:25:08.822860 2026] [proxy:error] [pid 116718:tid 116929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:08.822916 2026] [proxy_http:error] [pid 116718:tid 116929] [client 93.152.221.13:59310] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:08.823513 2026] [proxy:error] [pid 116718:tid 116929] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:08.823537 2026] [proxy_http:error] [pid 116718:tid 116929] [client 93.152.221.13:59310] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:08.833030 2026] [security2:error] [pid 116718:tid 116877] [client 104.234.53.61:54737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4htJPWlhYV5NwZ9vVCagAAAA0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:08.849476 2026] [security2:error] [pid 116718:tid 116948] [client 57.141.18.45:60782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hsJPWlhYV5NwZ9vVAUwAAVDw"]
[Mon Jul 20 07:25:08.975392 2026] [security2:error] [pid 116718:tid 116883] [client 49.47.218.174:52755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4htJPWlhYV5NwZ9vVCeQAAABM"]
[Mon Jul 20 07:25:08.975507 2026] [security2:error] [pid 116718:tid 116883] [client 49.47.218.174:52755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4htJPWlhYV5NwZ9vVCeQAAABM"]
[Mon Jul 20 07:25:09.095736 2026] [security2:error] [pid 116718:tid 116949] [client 93.152.221.13:50587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/info.php"] [unique_id "al4htZPWlhYV5NwZ9vVCigAAAFU"]
[Mon Jul 20 07:25:09.137622 2026] [security2:error] [pid 116718:tid 116879] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/333.php"] [unique_id "al4htZPWlhYV5NwZ9vVCjQAAAA8"]
[Mon Jul 20 07:25:09.137647 2026] [security2:error] [pid 116718:tid 116879] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/333.php"] [unique_id "al4htZPWlhYV5NwZ9vVCjQAAAA8"]
[Mon Jul 20 07:25:09.217455 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/albin.php"] [unique_id "al4htZPWlhYV5NwZ9vVCkAAAABA"]
[Mon Jul 20 07:25:09.217475 2026] [security2:error] [pid 116718:tid 116880] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/albin.php"] [unique_id "al4htZPWlhYV5NwZ9vVCkAAAABA"]
[Mon Jul 20 07:25:09.266810 2026] [security2:error] [pid 116718:tid 116864] [client 136.158.60.21:24160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4htZPWlhYV5NwZ9vVClQAAAAA"]
[Mon Jul 20 07:25:09.266948 2026] [security2:error] [pid 116718:tid 116864] [client 136.158.60.21:24160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4htZPWlhYV5NwZ9vVClQAAAAA"]
[Mon Jul 20 07:25:09.340848 2026] [security2:error] [pid 116718:tid 116850] [remote 57.141.18.125:33030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 125.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4htZPWlhYV5NwZ9vVCmQAAMXM"]
[Mon Jul 20 07:25:09.369571 2026] [security2:error] [pid 116718:tid 116948] [client 93.152.221.13:59567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/php.php"] [unique_id "al4htZPWlhYV5NwZ9vVCnAAAAFQ"]
[Mon Jul 20 07:25:09.430030 2026] [security2:error] [pid 116718:tid 116958] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/66.php"] [unique_id "al4htZPWlhYV5NwZ9vVCowAAAF4"]
[Mon Jul 20 07:25:09.430059 2026] [security2:error] [pid 116718:tid 116958] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/66.php"] [unique_id "al4htZPWlhYV5NwZ9vVCowAAAF4"]
[Mon Jul 20 07:25:09.432872 2026] [security2:error] [pid 116718:tid 116906] [client 14.225.17.146:64544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4htZPWlhYV5NwZ9vVCmwAAACo"], referer: https://wathenbartlett.co.uk/backup
[Mon Jul 20 07:25:09.539036 2026] [security2:error] [pid 116718:tid 116956] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/motu.php"] [unique_id "al4htZPWlhYV5NwZ9vVCsQAAAFw"]
[Mon Jul 20 07:25:09.539067 2026] [security2:error] [pid 116718:tid 116956] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/motu.php"] [unique_id "al4htZPWlhYV5NwZ9vVCsQAAAFw"]
[Mon Jul 20 07:25:09.595947 2026] [security2:error] [pid 116718:tid 116925] [client 104.168.114.154:41306] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.indisphotobooth.com"] [uri "/"] [unique_id "al4htZPWlhYV5NwZ9vVCtgAAAD0"]
[Mon Jul 20 07:25:09.654889 2026] [security2:error] [pid 116718:tid 116927] [client 93.152.221.13:49756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/php_info.php"] [unique_id "al4htZPWlhYV5NwZ9vVCvQAAAD8"]
[Mon Jul 20 07:25:09.926011 2026] [security2:error] [pid 116718:tid 116778] [remote 57.141.18.68:33764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4htZPWlhYV5NwZ9vVC0AAAZis"]
[Mon Jul 20 07:25:09.926868 2026] [security2:error] [pid 116718:tid 116948] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/kj.php"] [unique_id "al4htZPWlhYV5NwZ9vVCzwAAAFQ"]
[Mon Jul 20 07:25:09.926890 2026] [security2:error] [pid 116718:tid 116948] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/kj.php"] [unique_id "al4htZPWlhYV5NwZ9vVCzwAAAFQ"]
[Mon Jul 20 07:25:09.930463 2026] [security2:error] [pid 116718:tid 116940] [client 93.152.221.13:62114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/i.php"] [unique_id "al4htZPWlhYV5NwZ9vVC0QAAAEw"]
[Mon Jul 20 07:25:09.986388 2026] [security2:error] [pid 116718:tid 116754] [remote 57.141.18.12:27960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4htZPWlhYV5NwZ9vVC0wAAZxM"]
[Mon Jul 20 07:25:10.003532 2026] [security2:error] [pid 116718:tid 116951] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp4.php"] [unique_id "al4htpPWlhYV5NwZ9vVC1AAAAFc"]
[Mon Jul 20 07:25:10.003558 2026] [security2:error] [pid 116718:tid 116951] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp4.php"] [unique_id "al4htpPWlhYV5NwZ9vVC1AAAAFc"]
[Mon Jul 20 07:25:10.042848 2026] [security2:error] [pid 116718:tid 116753] [remote 115.74.105.156:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4htpPWlhYV5NwZ9vVC1wAAchI"]
[Mon Jul 20 07:25:10.067084 2026] [security2:error] [pid 116718:tid 116893] [client 77.110.127.138:65315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4htpPWlhYV5NwZ9vVC3QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:10.067181 2026] [security2:error] [pid 116718:tid 116893] [client 77.110.127.138:65315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4htpPWlhYV5NwZ9vVC3QAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:10.081077 2026] [security2:error] [pid 116718:tid 116962] [client 36.93.152.155:64811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4htpPWlhYV5NwZ9vVC3gAAAGI"]
[Mon Jul 20 07:25:10.081150 2026] [security2:error] [pid 116718:tid 116962] [client 36.93.152.155:64811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4htpPWlhYV5NwZ9vVC3gAAAGI"]
[Mon Jul 20 07:25:10.092473 2026] [security2:error] [pid 116718:tid 116981] [client 57.141.18.58:24090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hsZPWlhYV5NwZ9vVA6AAAdSI"]
[Mon Jul 20 07:25:10.093305 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file61.php"] [unique_id "al4htpPWlhYV5NwZ9vVC4AAAAHk"]
[Mon Jul 20 07:25:10.093321 2026] [security2:error] [pid 116718:tid 116985] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/file61.php"] [unique_id "al4htpPWlhYV5NwZ9vVC4AAAAHk"]
[Mon Jul 20 07:25:10.126007 2026] [security2:error] [pid 116718:tid 116891] [client 77.110.127.138:65283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4htpPWlhYV5NwZ9vVC5QAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:10.126092 2026] [security2:error] [pid 116718:tid 116891] [client 77.110.127.138:65283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4htpPWlhYV5NwZ9vVC5QAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:10.205861 2026] [security2:error] [pid 116718:tid 116941] [client 93.152.221.13:49193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/pi.php"] [unique_id "al4htpPWlhYV5NwZ9vVC8AAAAE0"]
[Mon Jul 20 07:25:10.214388 2026] [autoindex:error] [pid 116718:tid 116762] [remote 8.229.41.77:62817] AH01276: Cannot serve directory /home2/shnhbfmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.shn.hbf.mybluehost.me
[Mon Jul 20 07:25:10.268045 2026] [security2:error] [pid 116718:tid 116915] [client 103.176.215.66:57865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4htpPWlhYV5NwZ9vVC-QAAADM"]
[Mon Jul 20 07:25:10.268234 2026] [security2:error] [pid 116718:tid 116915] [client 103.176.215.66:57865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4htpPWlhYV5NwZ9vVC-QAAADM"]
[Mon Jul 20 07:25:10.343086 2026] [security2:error] [pid 116718:tid 116744] [remote 57.141.18.93:24474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4htpPWlhYV5NwZ9vVC_AAAEAk"]
[Mon Jul 20 07:25:10.369786 2026] [security2:error] [pid 116718:tid 116932] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp.php"] [unique_id "al4htpPWlhYV5NwZ9vVDAAAAAEQ"]
[Mon Jul 20 07:25:10.369809 2026] [security2:error] [pid 116718:tid 116932] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp.php"] [unique_id "al4htpPWlhYV5NwZ9vVDAAAAAEQ"]
[Mon Jul 20 07:25:10.376617 2026] [security2:error] [pid 116718:tid 116869] [client 117.211.236.168:65034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4htpPWlhYV5NwZ9vVDAgAAAAU"]
[Mon Jul 20 07:25:10.376706 2026] [security2:error] [pid 116718:tid 116869] [client 117.211.236.168:65034] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4htpPWlhYV5NwZ9vVDAgAAAAU"]
[Mon Jul 20 07:25:10.409132 2026] [security2:error] [pid 116718:tid 116857] [remote 182.77.62.24:50884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4htpPWlhYV5NwZ9vVDBQAAA3o"]
[Mon Jul 20 07:25:10.434571 2026] [security2:error] [pid 116718:tid 116988] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-trackback.php"] [unique_id "al4htpPWlhYV5NwZ9vVDCAAAAHw"]
[Mon Jul 20 07:25:10.434598 2026] [security2:error] [pid 116718:tid 116988] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/wp-trackback.php"] [unique_id "al4htpPWlhYV5NwZ9vVDCAAAAHw"]
[Mon Jul 20 07:25:10.487706 2026] [proxy:error] [pid 116718:tid 116983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:10.487800 2026] [proxy_http:error] [pid 116718:tid 116983] [client 93.152.221.13:49676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:10.488409 2026] [proxy:error] [pid 116718:tid 116983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:10.488437 2026] [proxy_http:error] [pid 116718:tid 116983] [client 93.152.221.13:49676] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:10.531511 2026] [security2:error] [pid 116718:tid 116960] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/db.php"] [unique_id "al4htpPWlhYV5NwZ9vVDDgAAAGA"]
[Mon Jul 20 07:25:10.531542 2026] [security2:error] [pid 116718:tid 116960] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/db.php"] [unique_id "al4htpPWlhYV5NwZ9vVDDgAAAGA"]
[Mon Jul 20 07:25:10.601328 2026] [security2:error] [pid 116718:tid 116893] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/NewFile.php"] [unique_id "al4htpPWlhYV5NwZ9vVDEwAAAB0"]
[Mon Jul 20 07:25:10.601365 2026] [security2:error] [pid 116718:tid 116893] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/NewFile.php"] [unique_id "al4htpPWlhYV5NwZ9vVDEwAAAB0"]
[Mon Jul 20 07:25:10.676406 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xxx.php"] [unique_id "al4htpPWlhYV5NwZ9vVDHQAAACo"]
[Mon Jul 20 07:25:10.676426 2026] [security2:error] [pid 116718:tid 116906] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/xxx.php"] [unique_id "al4htpPWlhYV5NwZ9vVDHQAAACo"]
[Mon Jul 20 07:25:10.729503 2026] [security2:error] [pid 116718:tid 116985] [client 138.197.117.171:58525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4htpPWlhYV5NwZ9vVDFwAAAHk"]
[Mon Jul 20 07:25:10.767716 2026] [security2:error] [pid 116718:tid 116933] [client 93.152.221.13:61559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4htpPWlhYV5NwZ9vVDIgAAAEU"]
[Mon Jul 20 07:25:10.771265 2026] [security2:error] [pid 116718:tid 116738] [remote 57.141.18.84:49522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4htpPWlhYV5NwZ9vVDIwAADwM"]
[Mon Jul 20 07:25:10.863162 2026] [security2:error] [pid 116718:tid 116874] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ms.php"] [unique_id "al4htpPWlhYV5NwZ9vVDKgAAAAo"]
[Mon Jul 20 07:25:10.863181 2026] [security2:error] [pid 116718:tid 116874] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/ms.php"] [unique_id "al4htpPWlhYV5NwZ9vVDKgAAAAo"]
[Mon Jul 20 07:25:10.865473 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:65242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4htpPWlhYV5NwZ9vVDIQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:10.920435 2026] [security2:error] [pid 116718:tid 116836] [remote 182.77.62.24:50884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4htpPWlhYV5NwZ9vVDMAAAbmU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:25:11.014127 2026] [security2:error] [pid 116718:tid 116788] [remote 57.141.18.115:59420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4ht5PWlhYV5NwZ9vVDNQAAajU"]
[Mon Jul 20 07:25:11.042554 2026] [security2:error] [pid 116718:tid 116967] [client 93.152.221.13:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDNgAAAGc"]
[Mon Jul 20 07:25:11.183568 2026] [security2:error] [pid 116718:tid 116958] [client 138.197.117.171:58773] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDQwAAAF4"]
[Mon Jul 20 07:25:11.237372 2026] [security2:error] [pid 116718:tid 116868] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/mini.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDSgAAAAQ"]
[Mon Jul 20 07:25:11.237403 2026] [security2:error] [pid 116718:tid 116868] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/mini.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDSgAAAAQ"]
[Mon Jul 20 07:25:11.313637 2026] [security2:error] [pid 116718:tid 116827] [remote 57.141.18.42:38116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4ht5PWlhYV5NwZ9vVDTgAAe1w"]
[Mon Jul 20 07:25:11.315669 2026] [security2:error] [pid 116718:tid 116909] [client 93.152.221.13:61174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpcontacts.musichaven.info"] [uri "/php_version.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDTwAAAC0"]
[Mon Jul 20 07:25:11.336824 2026] [security2:error] [pid 116718:tid 116989] [client 57.141.18.35:54566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hs5PWlhYV5NwZ9vVBqwAAfTY"]
[Mon Jul 20 07:25:11.468484 2026] [security2:error] [pid 116718:tid 116972] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/first.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDWQAAAGw"]
[Mon Jul 20 07:25:11.468506 2026] [security2:error] [pid 116718:tid 116972] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/first.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDWQAAAGw"]
[Mon Jul 20 07:25:11.590884 2026] [proxy:error] [pid 116718:tid 116944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:11.590982 2026] [proxy_http:error] [pid 116718:tid 116944] [client 93.152.221.13:51057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:11.592142 2026] [proxy:error] [pid 116718:tid 116944] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:11.592188 2026] [proxy_http:error] [pid 116718:tid 116944] [client 93.152.221.13:51057] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:11.617472 2026] [security2:error] [pid 116718:tid 116956] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/0okj.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDZgAAAFw"]
[Mon Jul 20 07:25:11.617490 2026] [security2:error] [pid 116718:tid 116956] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/0okj.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDZgAAAFw"]
[Mon Jul 20 07:25:11.672579 2026] [security2:error] [pid 116718:tid 116893] [client 77.110.127.138:65301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDcAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:11.672707 2026] [security2:error] [pid 116718:tid 116893] [client 77.110.127.138:65301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDcAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:11.684070 2026] [security2:error] [pid 116718:tid 116904] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/grsiuk.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDcgAAACg"]
[Mon Jul 20 07:25:11.684103 2026] [security2:error] [pid 116718:tid 116904] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/grsiuk.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDcgAAACg"]
[Mon Jul 20 07:25:11.731303 2026] [security2:error] [pid 116718:tid 116979] [client 103.106.165.44:56071] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDeAAAAHM"]
[Mon Jul 20 07:25:11.731428 2026] [security2:error] [pid 116718:tid 116979] [client 103.106.165.44:56071] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDeAAAAHM"]
[Mon Jul 20 07:25:11.846448 2026] [security2:error] [pid 116718:tid 116876] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/shell20211028.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDhAAAAAw"]
[Mon Jul 20 07:25:11.846478 2026] [security2:error] [pid 116718:tid 116876] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/shell20211028.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDhAAAAAw"]
[Mon Jul 20 07:25:11.870225 2026] [security2:error] [pid 116718:tid 116949] [client 93.152.221.13:57414] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.musichaven.info"] [uri "/___proxy_subdomain_cpcontacts/.env"] [unique_id "al4ht5PWlhYV5NwZ9vVDiQAAAFU"]
[Mon Jul 20 07:25:11.881628 2026] [security2:error] [pid 116718:tid 116802] [remote 45.90.123.233:46274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDjAAAX0M"]
[Mon Jul 20 07:25:11.912534 2026] [security2:error] [pid 116718:tid 116955] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/revealability.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDjgAAAFs"]
[Mon Jul 20 07:25:11.912559 2026] [security2:error] [pid 116718:tid 116955] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/revealability.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDjgAAAFs"]
[Mon Jul 20 07:25:12.018000 2026] [proxy:error] [pid 116718:tid 116983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:12.018075 2026] [proxy_http:error] [pid 116718:tid 116983] [client 93.152.221.13:57414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:12.018631 2026] [proxy:error] [pid 116718:tid 116983] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:12.018658 2026] [proxy_http:error] [pid 116718:tid 116983] [client 93.152.221.13:57414] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:12.025338 2026] [security2:error] [pid 116718:tid 116958] [client 201.27.111.74:59591] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4huJPWlhYV5NwZ9vVDkQAAAF4"]
[Mon Jul 20 07:25:12.025450 2026] [security2:error] [pid 116718:tid 116958] [client 201.27.111.74:59591] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4huJPWlhYV5NwZ9vVDkQAAAF4"]
[Mon Jul 20 07:25:12.044668 2026] [security2:error] [pid 116718:tid 116935] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/btx25.php"] [unique_id "al4huJPWlhYV5NwZ9vVDkgAAAEc"]
[Mon Jul 20 07:25:12.044684 2026] [security2:error] [pid 116718:tid 116935] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/btx25.php"] [unique_id "al4huJPWlhYV5NwZ9vVDkgAAAEc"]
[Mon Jul 20 07:25:12.048166 2026] [security2:error] [pid 116718:tid 116807] [remote 57.141.18.37:22980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4huJPWlhYV5NwZ9vVDkwAAakg"]
[Mon Jul 20 07:25:12.175250 2026] [security2:error] [pid 116718:tid 116953] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bthil.php"] [unique_id "al4huJPWlhYV5NwZ9vVDoAAAAFk"]
[Mon Jul 20 07:25:12.175278 2026] [security2:error] [pid 116718:tid 116953] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bthil.php"] [unique_id "al4huJPWlhYV5NwZ9vVDoAAAAFk"]
[Mon Jul 20 07:25:12.217247 2026] [security2:error] [pid 116718:tid 116872] [client 77.110.127.138:65333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4huJPWlhYV5NwZ9vVDqQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:12.217330 2026] [security2:error] [pid 116718:tid 116872] [client 77.110.127.138:65333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4huJPWlhYV5NwZ9vVDqQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:12.294879 2026] [proxy:error] [pid 116718:tid 116897] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:12.294958 2026] [proxy_http:error] [pid 116718:tid 116897] [client 93.152.221.13:52264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:12.295681 2026] [proxy:error] [pid 116718:tid 116897] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:12.295712 2026] [proxy_http:error] [pid 116718:tid 116897] [client 93.152.221.13:52264] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:12.360894 2026] [security2:error] [pid 116718:tid 116955] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/hplfuns.php"] [unique_id "al4huJPWlhYV5NwZ9vVDuwAAAFs"]
[Mon Jul 20 07:25:12.360921 2026] [security2:error] [pid 116718:tid 116955] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/hplfuns.php"] [unique_id "al4huJPWlhYV5NwZ9vVDuwAAAFs"]
[Mon Jul 20 07:25:12.484431 2026] [security2:error] [pid 116718:tid 116854] [remote 217.61.143.92:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4huJPWlhYV5NwZ9vVDwwAAVnc"]
[Mon Jul 20 07:25:12.485622 2026] [security2:error] [pid 116718:tid 116967] [client 191.202.66.27:52918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4huJPWlhYV5NwZ9vVDxAAAAGc"]
[Mon Jul 20 07:25:12.485767 2026] [security2:error] [pid 116718:tid 116967] [client 191.202.66.27:52918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4huJPWlhYV5NwZ9vVDxAAAAGc"]
[Mon Jul 20 07:25:12.491548 2026] [security2:error] [pid 116718:tid 116914] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/error.php"] [unique_id "al4huJPWlhYV5NwZ9vVDxQAAADI"]
[Mon Jul 20 07:25:12.491576 2026] [security2:error] [pid 116718:tid 116914] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/error.php"] [unique_id "al4huJPWlhYV5NwZ9vVDxQAAADI"]
[Mon Jul 20 07:25:12.569830 2026] [security2:error] [pid 116718:tid 116968] [client 93.152.221.13:59281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "cpcontacts.musichaven.info"] [uri "/___proxy_subdomain_cpcontacts/.env.backup"] [unique_id "al4huJPWlhYV5NwZ9vVDygAAAGg"]
[Mon Jul 20 07:25:12.597026 2026] [security2:error] [pid 116718:tid 116783] [remote 57.141.18.41:46414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4huJPWlhYV5NwZ9vVDywAAYDA"]
[Mon Jul 20 07:25:12.707021 2026] [security2:error] [pid 116718:tid 116984] [client 93.152.221.13:59281] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "cpcontacts.musichaven.info"] [uri "/___proxy_subdomain_cpcontacts/config/.env"] [unique_id "al4huJPWlhYV5NwZ9vVD2AAAAHg"]
[Mon Jul 20 07:25:12.729080 2026] [security2:error] [pid 116718:tid 116855] [remote 217.61.143.92:44088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4huJPWlhYV5NwZ9vVD3QAAE3g"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:25:12.841190 2026] [security2:error] [pid 116718:tid 116915] [client 88.241.67.160:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4huJPWlhYV5NwZ9vVD5gAAADM"]
[Mon Jul 20 07:25:12.841333 2026] [security2:error] [pid 116718:tid 116915] [client 88.241.67.160:54334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4huJPWlhYV5NwZ9vVD5gAAADM"]
[Mon Jul 20 07:25:12.841677 2026] [security2:error] [pid 116718:tid 116896] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/edit.php"] [unique_id "al4huJPWlhYV5NwZ9vVD6QAAACA"]
[Mon Jul 20 07:25:12.841714 2026] [security2:error] [pid 116718:tid 116896] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/edit.php"] [unique_id "al4huJPWlhYV5NwZ9vVD6QAAACA"]
[Mon Jul 20 07:25:12.950102 2026] [security2:error] [pid 116718:tid 116961] [client 14.225.17.146:53158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4ht5PWlhYV5NwZ9vVDTAAAAGE"], referer: http://nomorewetsheets.net/backup
[Mon Jul 20 07:25:13.007267 2026] [security2:error] [pid 116718:tid 116968] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/pass4.php"] [unique_id "al4huZPWlhYV5NwZ9vVD_QAAAGg"]
[Mon Jul 20 07:25:13.007289 2026] [security2:error] [pid 116718:tid 116968] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/pass4.php"] [unique_id "al4huZPWlhYV5NwZ9vVD_QAAAGg"]
[Mon Jul 20 07:25:13.015809 2026] [security2:error] [pid 116718:tid 116902] [client 57.141.18.49:42096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4htZPWlhYV5NwZ9vVCgQAAJiw"]
[Mon Jul 20 07:25:13.024506 2026] [security2:error] [pid 116718:tid 116927] [client 77.110.127.138:65304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4huJPWlhYV5NwZ9vVD5AAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:13.072617 2026] [security2:error] [pid 116718:tid 116932] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sadcut1.php"] [unique_id "al4huZPWlhYV5NwZ9vVD_wAAAEQ"]
[Mon Jul 20 07:25:13.072644 2026] [security2:error] [pid 116718:tid 116932] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/sadcut1.php"] [unique_id "al4huZPWlhYV5NwZ9vVD_wAAAEQ"]
[Mon Jul 20 07:25:13.138914 2026] [security2:error] [pid 116718:tid 116900] [client 52.139.36.144:6545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bgymj.php"] [unique_id "al4huZPWlhYV5NwZ9vVEAwAAACQ"]
[Mon Jul 20 07:25:13.138935 2026] [security2:error] [pid 116718:tid 116900] [client 52.139.36.144:6545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.espiritualidadmoderna.com"] [uri "/bgymj.php"] [unique_id "al4huZPWlhYV5NwZ9vVEAwAAACQ"]
[Mon Jul 20 07:25:13.142584 2026] [security2:error] [pid 116718:tid 116895] [client 157.20.138.62:53794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4huZPWlhYV5NwZ9vVEBgAAAB8"]
[Mon Jul 20 07:25:13.142688 2026] [security2:error] [pid 116718:tid 116895] [client 157.20.138.62:53794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4huZPWlhYV5NwZ9vVEBgAAAB8"]
[Mon Jul 20 07:25:13.176884 2026] [security2:error] [pid 116718:tid 116867] [client 179.127.84.238:54217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4huZPWlhYV5NwZ9vVECQAAAAM"]
[Mon Jul 20 07:25:13.176994 2026] [security2:error] [pid 116718:tid 116867] [client 179.127.84.238:54217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4huZPWlhYV5NwZ9vVECQAAAAM"]
[Mon Jul 20 07:25:13.203255 2026] [autoindex:error] [pid 116718:tid 116937] [client 170.106.37.134:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:25:13.286794 2026] [security2:error] [pid 116718:tid 116934] [client 14.225.17.146:49705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4huZPWlhYV5NwZ9vVEEAAAAEY"], referer: http://daseighty.net/backup
[Mon Jul 20 07:25:13.399471 2026] [security2:error] [pid 116718:tid 116888] [client 77.110.127.138:65264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4huZPWlhYV5NwZ9vVEKAAAABg"]
[Mon Jul 20 07:25:13.599361 2026] [security2:error] [pid 116718:tid 116753] [remote 57.141.18.64:57266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4huZPWlhYV5NwZ9vVEMwAAEBI"]
[Mon Jul 20 07:25:13.666195 2026] [security2:error] [pid 116718:tid 116803] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4huZPWlhYV5NwZ9vVEOQAAdkQ"]
[Mon Jul 20 07:25:13.666332 2026] [security2:error] [pid 116718:tid 116982] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4huZPWlhYV5NwZ9vVEOQAAdkQ"]
[Mon Jul 20 07:25:13.908371 2026] [security2:error] [pid 116718:tid 116914] [client 14.224.227.113:56028] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4huZPWlhYV5NwZ9vVEUQAAADI"]
[Mon Jul 20 07:25:14.114485 2026] [security2:error] [pid 116718:tid 116970] [client 93.152.221.13:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.musichaven.info"] [uri "/index.php"] [unique_id "al4huZPWlhYV5NwZ9vVEAAAAags"], referer: http://mail.musichaven.info/phpinfo
[Mon Jul 20 07:25:14.292926 2026] [security2:error] [pid 116718:tid 116886] [client 50.116.65.227:58978] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hupPWlhYV5NwZ9vVEeAAAABY"]
[Mon Jul 20 07:25:14.302952 2026] [security2:error] [pid 116718:tid 116923] [client 50.116.65.227:58984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hupPWlhYV5NwZ9vVEegAAADs"]
[Mon Jul 20 07:25:14.359894 2026] [security2:error] [pid 116718:tid 116949] [client 93.152.221.13:52164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hupPWlhYV5NwZ9vVEgwAAAFU"]
[Mon Jul 20 07:25:14.394604 2026] [security2:error] [pid 116718:tid 116770] [remote 115.74.105.156:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.105.74.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4hupPWlhYV5NwZ9vVEhwAAZCM"], referer: https://mrbambooplus.com/wp-login.php
[Mon Jul 20 07:25:14.462652 2026] [security2:error] [pid 116718:tid 116979] [client 154.192.123.127:17878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hupPWlhYV5NwZ9vVEiQAAAHM"]
[Mon Jul 20 07:25:14.462787 2026] [security2:error] [pid 116718:tid 116979] [client 154.192.123.127:17878] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hupPWlhYV5NwZ9vVEiQAAAHM"]
[Mon Jul 20 07:25:14.610095 2026] [security2:error] [pid 116718:tid 116823] [remote 57.141.18.85:29616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4hupPWlhYV5NwZ9vVElgAAeFg"]
[Mon Jul 20 07:25:14.612485 2026] [security2:error] [pid 116718:tid 116950] [client 14.225.17.146:57513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4hupPWlhYV5NwZ9vVEYQAAAFY"], referer: http://onewingpictures.com/backup
[Mon Jul 20 07:25:14.634153 2026] [security2:error] [pid 116718:tid 116963] [client 93.152.221.13:63585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/test.php"] [unique_id "al4hupPWlhYV5NwZ9vVElwAAAGM"]
[Mon Jul 20 07:25:14.877571 2026] [security2:error] [pid 116718:tid 116897] [client 14.225.17.146:63968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4hupPWlhYV5NwZ9vVEnAAAACE"], referer: http://taskidsvirginia.com/backup
[Mon Jul 20 07:25:15.023064 2026] [security2:error] [pid 116718:tid 116891] [client 14.225.17.146:65205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4hupPWlhYV5NwZ9vVExwAAABs"], referer: http://thefriendlyspreadsheet.com/backup
[Mon Jul 20 07:25:15.113387 2026] [security2:error] [pid 116718:tid 116950] [client 93.152.221.13:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.musichaven.info"] [uri "/index.php"] [unique_id "al4hu5PWlhYV5NwZ9vVE0QAAVlQ"], referer: http://mail.musichaven.info/_profiler/phpinfo
[Mon Jul 20 07:25:15.156164 2026] [security2:error] [pid 116718:tid 116884] [client 77.110.127.138:65345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hu5PWlhYV5NwZ9vVE7AAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:15.156247 2026] [security2:error] [pid 116718:tid 116884] [client 77.110.127.138:65345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hu5PWlhYV5NwZ9vVE7AAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:15.251820 2026] [security2:error] [pid 116718:tid 116877] [client 93.152.221.13:59449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/info.php"] [unique_id "al4hu5PWlhYV5NwZ9vVE_AAAAA0"]
[Mon Jul 20 07:25:15.465660 2026] [security2:error] [pid 116718:tid 116893] [client 47.128.118.230:51568] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cpanel.willowbranchequines.org"] [uri "/cPanel_magic_revision_1648610195/unprotected/cpanel/fonts/open_sans/OpenSans-Regular-webfont.woff"] [unique_id "al4hu5PWlhYV5NwZ9vVFQwAAAB0"]
[Mon Jul 20 07:25:15.529981 2026] [security2:error] [pid 116718:tid 116962] [client 93.152.221.13:56468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/php.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFRwAAAGI"]
[Mon Jul 20 07:25:15.593196 2026] [security2:error] [pid 116718:tid 116938] [client 77.110.127.138:65242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFUgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:15.593327 2026] [security2:error] [pid 116718:tid 116938] [client 77.110.127.138:65242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFUgAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:15.597885 2026] [security2:error] [pid 116718:tid 116764] [remote 57.141.18.24:48654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4hu5PWlhYV5NwZ9vVFTgAAcR0"]
[Mon Jul 20 07:25:15.801437 2026] [security2:error] [pid 116718:tid 116948] [client 93.152.221.13:58212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/php_info.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFXAAAAFQ"]
[Mon Jul 20 07:25:15.894951 2026] [security2:error] [pid 116718:tid 116892] [client 14.225.17.146:57575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4hupPWlhYV5NwZ9vVEbgAAABw"], referer: http://bigwormfishing.com/backup
[Mon Jul 20 07:25:15.972724 2026] [security2:error] [pid 116718:tid 116807] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFewAAOkg"]
[Mon Jul 20 07:25:15.972897 2026] [security2:error] [pid 116718:tid 116922] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFewAAOkg"]
[Mon Jul 20 07:25:16.075047 2026] [security2:error] [pid 116718:tid 116979] [client 93.152.221.13:59405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/i.php"] [unique_id "al4hvJPWlhYV5NwZ9vVFgQAAAHM"]
[Mon Jul 20 07:25:16.280080 2026] [security2:error] [pid 116718:tid 116870] [client 57.141.18.93:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hvJPWlhYV5NwZ9vVFhAAAAAY"]
[Mon Jul 20 07:25:16.351172 2026] [security2:error] [pid 116718:tid 116893] [client 93.152.221.13:54986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/pi.php"] [unique_id "al4hvJPWlhYV5NwZ9vVFmgAAAB0"]
[Mon Jul 20 07:25:16.480660 2026] [security2:error] [pid 116718:tid 116817] [remote 57.141.18.12:26682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4hvJPWlhYV5NwZ9vVFrQAAfFI"]
[Mon Jul 20 07:25:16.559565 2026] [security2:error] [pid 116718:tid 116943] [client 77.110.127.138:65296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hvJPWlhYV5NwZ9vVFmQAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:16.845912 2026] [security2:error] [pid 116718:tid 116964] [client 14.225.17.146:61378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4hvJPWlhYV5NwZ9vVFuQAAAGQ"], referer: https://bigwormfishing.com/backup
[Mon Jul 20 07:25:16.945651 2026] [security2:error] [pid 116718:tid 116847] [remote 57.141.18.30:24800] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4hvJPWlhYV5NwZ9vVF1wAAaXA"]
[Mon Jul 20 07:25:17.025800 2026] [security2:error] [pid 116718:tid 116913] [client 93.152.221.13:61846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF3QAAADE"]
[Mon Jul 20 07:25:17.055036 2026] [security2:error] [pid 116718:tid 116907] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hvJPWlhYV5NwZ9vVFvQAAACs"], referer: 1'"3000
[Mon Jul 20 07:25:17.110870 2026] [security2:error] [pid 116718:tid 116834] [remote 51.68.107.150:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4hvZPWlhYV5NwZ9vVF4gAAP2M"]
[Mon Jul 20 07:25:17.111011 2026] [security2:error] [pid 116718:tid 116927] [client 51.68.107.150:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "benbayly.co.nz"] [uri "/"] [unique_id "al4hvZPWlhYV5NwZ9vVF4gAAP2M"]
[Mon Jul 20 07:25:17.129338 2026] [security2:error] [pid 116718:tid 116795] [remote 78.46.157.202:40082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF5AAAJDw"]
[Mon Jul 20 07:25:17.166665 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF5gAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:17.166793 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65280] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF5gAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:17.187305 2026] [security2:error] [pid 116718:tid 116760] [remote 57.141.18.88:57038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2887329"] [unique_id "al4hvZPWlhYV5NwZ9vVF5wAAahk"]
[Mon Jul 20 07:25:17.244951 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:65304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF8wAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:17.245051 2026] [security2:error] [pid 116718:tid 116881] [client 77.110.127.138:65304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF8wAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:17.249088 2026] [security2:error] [pid 116718:tid 116800] [remote 20.153.140.50:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF8gAAN0E"]
[Mon Jul 20 07:25:17.271398 2026] [security2:error] [pid 116718:tid 116809] [remote 57.141.18.25:45798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2963812"] [unique_id "al4hvZPWlhYV5NwZ9vVF9gAAYEo"]
[Mon Jul 20 07:25:17.302123 2026] [security2:error] [pid 116718:tid 116976] [client 93.152.221.13:62774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF-QAAAHA"]
[Mon Jul 20 07:25:17.333270 2026] [security2:error] [pid 116718:tid 116953] [client 14.225.17.146:61511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4hu5PWlhYV5NwZ9vVFcAAAAFk"], referer: http://inspirespublishing.com/backup
[Mon Jul 20 07:25:17.350491 2026] [security2:error] [pid 116718:tid 116754] [remote 78.46.157.202:40082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF_gAAYxM"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:25:17.434576 2026] [security2:error] [pid 116718:tid 116893] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hvZPWlhYV5NwZ9vVF8QAAAB0"], referer: 1'"3000
[Mon Jul 20 07:25:17.522807 2026] [security2:error] [pid 116718:tid 116904] [client 51.68.111.208:24029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "elevator-data.com"] [uri "/robots.txt"] [unique_id "al4hvZPWlhYV5NwZ9vVGGAAAACg"]
[Mon Jul 20 07:25:17.522912 2026] [security2:error] [pid 116718:tid 116904] [client 51.68.111.208:24029] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "elevator-data.com"] [uri "/robots.txt"] [unique_id "al4hvZPWlhYV5NwZ9vVGGAAAACg"]
[Mon Jul 20 07:25:17.575806 2026] [security2:error] [pid 116718:tid 116877] [client 93.152.221.13:65001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.musichaven.info"] [uri "/php_version.php"] [unique_id "al4hvZPWlhYV5NwZ9vVGHAAAAA0"]
[Mon Jul 20 07:25:17.616691 2026] [security2:error] [pid 116718:tid 116961] [client 43.155.29.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4hvZPWlhYV5NwZ9vVGEgAAYRY"], referer: https://www.aleishapenny.ca/listing/page/1117?paged=1117&view=grid
[Mon Jul 20 07:25:17.660691 2026] [security2:error] [pid 116718:tid 116736] [remote 20.153.140.50:59700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hvZPWlhYV5NwZ9vVGJAAAVgE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:25:17.869903 2026] [security2:error] [pid 116718:tid 116975] [client 57.141.18.122:26708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hupPWlhYV5NwZ9vVEYwAAbwI"]
[Mon Jul 20 07:25:18.517316 2026] [security2:error] [pid 116718:tid 116890] [client 93.152.221.13:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.musichaven.info"] [uri "/index.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGYAAAGiE"], referer: http://mail.musichaven.info/.aws/credentials
[Mon Jul 20 07:25:18.559648 2026] [security2:error] [pid 116718:tid 116981] [client 154.208.48.130:55687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGawAAAHU"]
[Mon Jul 20 07:25:18.559786 2026] [security2:error] [pid 116718:tid 116981] [client 154.208.48.130:55687] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGawAAAHU"]
[Mon Jul 20 07:25:18.608160 2026] [security2:error] [pid 116718:tid 116864] [client 43.205.139.3:39476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGbgAAAAA"]
[Mon Jul 20 07:25:18.631376 2026] [security2:error] [pid 116718:tid 116952] [client 77.110.127.138:65372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGXwAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:18.796567 2026] [security2:error] [pid 116718:tid 116858] [remote 93.152.221.13:59490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.musichaven.info"] [uri "/.env"] [unique_id "al4hvpPWlhYV5NwZ9vVGewAAans"], referer: http://mail.musichaven.info/.env
[Mon Jul 20 07:25:18.860510 2026] [security2:error] [pid 116718:tid 116947] [client 14.225.17.146:61659] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGcAAAAFM"], referer: http://hammadownenterprises.com/backup
[Mon Jul 20 07:25:19.138339 2026] [security2:error] [pid 116718:tid 116904] [client 93.152.221.13:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.musichaven.info"] [uri "/index.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGkAAAKAQ"], referer: http://mail.musichaven.info/.env.example
[Mon Jul 20 07:25:19.358236 2026] [security2:error] [pid 116718:tid 116975] [client 98.159.234.160:61705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGqAAAAG8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:25:19.489336 2026] [security2:error] [pid 116718:tid 116988] [client 93.152.221.13:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.musichaven.info"] [uri "/index.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGrwAAfEg"], referer: http://mail.musichaven.info/.env.local
[Mon Jul 20 07:25:19.549828 2026] [security2:error] [pid 116718:tid 116964] [client 143.44.185.218:44134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGxQAAAGQ"]
[Mon Jul 20 07:25:19.549944 2026] [security2:error] [pid 116718:tid 116964] [client 143.44.185.218:44134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGxQAAAGQ"]
[Mon Jul 20 07:25:19.622503 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGzQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:19.622595 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGzQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:19.642141 2026] [security2:error] [pid 116718:tid 116989] [client 49.47.218.174:53296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG0AAAAH0"]
[Mon Jul 20 07:25:19.642374 2026] [security2:error] [pid 116718:tid 116989] [client 49.47.218.174:53296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG0AAAAH0"]
[Mon Jul 20 07:25:19.676705 2026] [security2:error] [pid 116718:tid 116975] [client 77.110.127.138:65318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG0gAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:19.676814 2026] [security2:error] [pid 116718:tid 116975] [client 77.110.127.138:65318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG0gAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:19.728897 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hv5PWlhYV5NwZ9vVGwAAAABY"], referer: 1'"3000
[Mon Jul 20 07:25:19.764809 2026] [security2:error] [pid 116718:tid 116824] [remote 93.152.221.13:59490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.musichaven.info"] [uri "/.env.backup"] [unique_id "al4hv5PWlhYV5NwZ9vVG2QAAClk"], referer: http://mail.musichaven.info/.env.backup
[Mon Jul 20 07:25:19.795286 2026] [security2:error] [pid 116718:tid 116940] [client 43.205.139.3:39478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG2gAAAEw"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:25:19.844091 2026] [security2:error] [pid 116718:tid 116827] [remote 57.141.18.7:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4hv5PWlhYV5NwZ9vVG2wAAYlw"]
[Mon Jul 20 07:25:19.960366 2026] [security2:error] [pid 116718:tid 116868] [client 136.158.60.21:25716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG7QAAAAQ"]
[Mon Jul 20 07:25:19.960476 2026] [security2:error] [pid 116718:tid 116868] [client 136.158.60.21:25716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hv5PWlhYV5NwZ9vVG7QAAAAQ"]
[Mon Jul 20 07:25:20.039529 2026] [security2:error] [pid 116718:tid 116846] [remote 93.152.221.13:59490] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.musichaven.info"] [uri "/config/.env"] [unique_id "al4hwJPWlhYV5NwZ9vVG8wAAfW8"], referer: http://mail.musichaven.info/config/.env
[Mon Jul 20 07:25:20.104579 2026] [security2:error] [pid 116718:tid 116829] [remote 45.90.123.233:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "momheadquarters.com"] [uri "/wp-login.php"] [unique_id "al4hwJPWlhYV5NwZ9vVG_wAARl4"], referer: https://momheadquarters.com/wp-login.php
[Mon Jul 20 07:25:20.218744 2026] [security2:error] [pid 116718:tid 116957] [client 74.7.227.179:36252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4hwJPWlhYV5NwZ9vVG-wAAXWk"], referer: https://tejasenvironmental.com/p=3724586
[Mon Jul 20 07:25:20.603336 2026] [security2:error] [pid 116718:tid 116870] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHHwAAAAY"], referer: 1'"3000
[Mon Jul 20 07:25:20.612269 2026] [security2:error] [pid 116718:tid 116923] [client 36.93.152.155:65352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHMwAAADs"]
[Mon Jul 20 07:25:20.612344 2026] [security2:error] [pid 116718:tid 116923] [client 36.93.152.155:65352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHMwAAADs"]
[Mon Jul 20 07:25:20.849277 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:65386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHPgAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:20.853992 2026] [security2:error] [pid 116718:tid 116877] [client 103.176.215.66:58404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHRgAAAA0"]
[Mon Jul 20 07:25:20.854089 2026] [security2:error] [pid 116718:tid 116877] [client 103.176.215.66:58404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHRgAAAA0"]
[Mon Jul 20 07:25:20.899146 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:65344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHUQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:20.899253 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:65344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHUQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:20.949391 2026] [security2:error] [pid 116718:tid 116961] [client 77.110.127.138:65353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHUgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:20.949511 2026] [security2:error] [pid 116718:tid 116961] [client 77.110.127.138:65353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hwJPWlhYV5NwZ9vVHUgAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:21.186761 2026] [security2:error] [pid 116718:tid 116910] [client 57.141.18.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHWgAAAC4"]
[Mon Jul 20 07:25:21.495062 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:65342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHbwAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:21.729979 2026] [security2:error] [pid 116718:tid 116890] [client 14.225.17.146:64908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHjAAAABo"], referer: http://nextlvlmarketingco.com/backup
[Mon Jul 20 07:25:21.860442 2026] [security2:error] [pid 116718:tid 116853] [remote 124.55.178.99:36626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHngAAMHY"]
[Mon Jul 20 07:25:22.033897 2026] [security2:error] [pid 116718:tid 116881] [client 93.152.221.13:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHrAAAEX8"], referer: http://musichaven.info/phpinfo
[Mon Jul 20 07:25:22.094446 2026] [security2:error] [pid 116718:tid 116948] [client 57.141.18.62:59318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hvpPWlhYV5NwZ9vVGZAAAVBo"]
[Mon Jul 20 07:25:22.277121 2026] [security2:error] [pid 116718:tid 116884] [client 77.110.127.138:65386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHogAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:22.323232 2026] [security2:error] [pid 116718:tid 116972] [client 103.106.165.44:56557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hwpPWlhYV5NwZ9vVHzAAAAGw"]
[Mon Jul 20 07:25:22.323336 2026] [security2:error] [pid 116718:tid 116972] [client 103.106.165.44:56557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hwpPWlhYV5NwZ9vVHzAAAAGw"]
[Mon Jul 20 07:25:22.511954 2026] [security2:error] [pid 116718:tid 116970] [client 201.27.111.74:60094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH3gAAAGo"]
[Mon Jul 20 07:25:22.512058 2026] [security2:error] [pid 116718:tid 116970] [client 201.27.111.74:60094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH3gAAAGo"]
[Mon Jul 20 07:25:22.515001 2026] [security2:error] [pid 116718:tid 116955] [client 15.204.80.170:50046] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "giftsurprizo.com"] [uri "/"] [unique_id "al4hwpPWlhYV5NwZ9vVH3QAAAFs"]
[Mon Jul 20 07:25:22.544545 2026] [security2:error] [pid 116718:tid 116979] [client 93.152.221.13:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH3AAAcwM"], referer: https://musichaven.info/phpinfo
[Mon Jul 20 07:25:22.562160 2026] [security2:error] [pid 116718:tid 116791] [remote 124.55.178.99:36626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH4QAATDg"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:25:22.639061 2026] [security2:error] [pid 116718:tid 116888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH1wAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:22.814228 2026] [security2:error] [pid 116718:tid 116949] [client 93.152.221.13:63394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH_gAAAFU"]
[Mon Jul 20 07:25:22.888811 2026] [security2:error] [pid 116718:tid 116964] [client 77.110.127.138:65409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hwpPWlhYV5NwZ9vVIAAAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:22.888892 2026] [security2:error] [pid 116718:tid 116964] [client 77.110.127.138:65409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hwpPWlhYV5NwZ9vVIAAAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:22.981844 2026] [security2:error] [pid 116718:tid 116892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hwpPWlhYV5NwZ9vVH_QAAABw"]
[Mon Jul 20 07:25:23.037290 2026] [security2:error] [pid 116718:tid 116890] [client 191.202.66.27:53411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIEAAAABo"]
[Mon Jul 20 07:25:23.037402 2026] [security2:error] [pid 116718:tid 116890] [client 191.202.66.27:53411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIEAAAABo"]
[Mon Jul 20 07:25:23.089500 2026] [security2:error] [pid 116718:tid 116941] [client 93.152.221.13:60287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/test.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIGwAAAE0"]
[Mon Jul 20 07:25:23.384250 2026] [security2:error] [pid 116718:tid 116897] [client 77.110.127.138:65397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hw5PWlhYV5NwZ9vVINgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:23.384333 2026] [security2:error] [pid 116718:tid 116897] [client 77.110.127.138:65397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hw5PWlhYV5NwZ9vVINgAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:23.529066 2026] [security2:error] [pid 116718:tid 116876] [client 88.241.67.160:56222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVISAAAAAw"]
[Mon Jul 20 07:25:23.529342 2026] [security2:error] [pid 116718:tid 116876] [client 88.241.67.160:56222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVISAAAAAw"]
[Mon Jul 20 07:25:23.554493 2026] [security2:error] [pid 116718:tid 116914] [client 93.152.221.13:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIQwAAMjI"], referer: http://musichaven.info/_profiler/phpinfo
[Mon Jul 20 07:25:23.600992 2026] [security2:error] [pid 116718:tid 116953] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIOQAAAFk"]
[Mon Jul 20 07:25:23.747962 2026] [security2:error] [pid 116718:tid 116932] [client 157.20.138.62:54361] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIVwAAAEQ"]
[Mon Jul 20 07:25:23.748068 2026] [security2:error] [pid 116718:tid 116932] [client 157.20.138.62:54361] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIVwAAAEQ"]
[Mon Jul 20 07:25:23.760538 2026] [security2:error] [pid 116718:tid 116943] [client 93.152.221.13:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIUQAAT14"], referer: https://musichaven.info/_profiler/phpinfo
[Mon Jul 20 07:25:23.868416 2026] [security2:error] [pid 116718:tid 116879] [client 117.211.236.168:49222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIYwAAAA8"]
[Mon Jul 20 07:25:23.868544 2026] [security2:error] [pid 116718:tid 116879] [client 117.211.236.168:49222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIYwAAAA8"]
[Mon Jul 20 07:25:23.878233 2026] [security2:error] [pid 116718:tid 116895] [client 179.127.84.238:54716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIZQAAAB8"]
[Mon Jul 20 07:25:23.878367 2026] [security2:error] [pid 116718:tid 116895] [client 179.127.84.238:54716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIZQAAAB8"]
[Mon Jul 20 07:25:23.898868 2026] [security2:error] [pid 116718:tid 116968] [client 93.152.221.13:65005] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/info.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIaAAAAGg"]
[Mon Jul 20 07:25:24.175583 2026] [security2:error] [pid 116718:tid 116934] [client 93.152.221.13:56677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/php.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIcwAAAEY"]
[Mon Jul 20 07:25:24.269211 2026] [autoindex:error] [pid 116718:tid 116984] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/bluehost-wordpress-plugin/vendor/newfold-labs/wp-module-performance/build/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:25:24.322822 2026] [security2:error] [pid 116718:tid 116751] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIgQAAdBA"]
[Mon Jul 20 07:25:24.323009 2026] [security2:error] [pid 116718:tid 116980] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIgQAAdBA"]
[Mon Jul 20 07:25:24.427322 2026] [security2:error] [pid 116718:tid 116957] [client 14.225.17.146:65058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIJwAAAF0"], referer: http://mourgroup.com/backup
[Mon Jul 20 07:25:24.453325 2026] [security2:error] [pid 116718:tid 116882] [client 93.152.221.13:60974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/php_info.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIiQAAABI"]
[Mon Jul 20 07:25:24.730785 2026] [security2:error] [pid 116718:tid 116985] [client 93.152.221.13:60061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/i.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIowAAAHk"]
[Mon Jul 20 07:25:24.778927 2026] [security2:error] [pid 116718:tid 116959] [client 14.225.17.146:65113] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIKAAAAF8"], referer: http://tntcatholic.com/backup
[Mon Jul 20 07:25:24.872815 2026] [security2:error] [pid 116718:tid 116903] [client 199.45.154.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4hxJPWlhYV5NwZ9vVInAAAACc"]
[Mon Jul 20 07:25:24.962511 2026] [security2:error] [pid 116718:tid 116965] [client 154.192.123.127:18409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hxJPWlhYV5NwZ9vVItQAAAGU"]
[Mon Jul 20 07:25:24.962629 2026] [security2:error] [pid 116718:tid 116965] [client 154.192.123.127:18409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hxJPWlhYV5NwZ9vVItQAAAGU"]
[Mon Jul 20 07:25:24.970200 2026] [security2:error] [pid 116718:tid 116859] [remote 47.86.33.52:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hxJPWlhYV5NwZ9vVItAAAIHw"]
[Mon Jul 20 07:25:25.005706 2026] [security2:error] [pid 116718:tid 116882] [client 93.152.221.13:56260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/pi.php"] [unique_id "al4hxZPWlhYV5NwZ9vVIuAAAABI"]
[Mon Jul 20 07:25:25.239323 2026] [security2:error] [pid 116718:tid 116868] [client 14.225.17.146:64909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4hwZPWlhYV5NwZ9vVHjQAAAAQ"], referer: http://areitoproducciones.com/backup
[Mon Jul 20 07:25:25.241592 2026] [security2:error] [pid 116718:tid 116872] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hxZPWlhYV5NwZ9vVIwAAAAAg"], referer: 1'"3000
[Mon Jul 20 07:25:25.475648 2026] [security2:error] [pid 116718:tid 116950] [client 14.225.17.146:50114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIZgAAAFY"], referer: http://amalia-capital.com/backup
[Mon Jul 20 07:25:25.482350 2026] [security2:error] [pid 116718:tid 116961] [client 54.169.146.187:56514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hxZPWlhYV5NwZ9vVI5AAAAGE"]
[Mon Jul 20 07:25:25.579543 2026] [security2:error] [pid 116718:tid 116937] [client 57.141.18.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hxZPWlhYV5NwZ9vVI3QAAAEk"]
[Mon Jul 20 07:25:25.670429 2026] [security2:error] [pid 116718:tid 116897] [client 14.225.17.146:65092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIpQAAACE"], referer: http://walkingandtalking.net/backup
[Mon Jul 20 07:25:25.740772 2026] [security2:error] [pid 116718:tid 116934] [client 104.234.53.73:60279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hxZPWlhYV5NwZ9vVI9wAAAEY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:25.832292 2026] [security2:error] [pid 116718:tid 116987] [client 93.152.221.13:64014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hxZPWlhYV5NwZ9vVJAgAAAHs"]
[Mon Jul 20 07:25:25.836433 2026] [security2:error] [pid 116718:tid 116870] [client 74.7.175.148:34114] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.travelbyfire.com"] [uri "/robots.txt"] [unique_id "al4hxZPWlhYV5NwZ9vVI_gAABnI"]
[Mon Jul 20 07:25:25.863542 2026] [security2:error] [pid 116718:tid 116967] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hxZPWlhYV5NwZ9vVI8wAAAGc"], referer: 1'"3000
[Mon Jul 20 07:25:25.927416 2026] [security2:error] [pid 116718:tid 116776] [remote 47.86.33.52:9120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4hxZPWlhYV5NwZ9vVJBgAAYSk"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:25:26.104235 2026] [security2:error] [pid 116718:tid 116891] [client 93.152.221.13:59263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJGgAAABs"]
[Mon Jul 20 07:25:26.147616 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:65298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJIAAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:26.147733 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:65298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJIAAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:26.302634 2026] [security2:error] [pid 116718:tid 116910] [client 77.110.127.138:65418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJLgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:26.302776 2026] [security2:error] [pid 116718:tid 116910] [client 77.110.127.138:65418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJLgAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:26.385280 2026] [security2:error] [pid 116718:tid 116967] [client 93.152.221.13:62656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "musichaven.info"] [uri "/php_version.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJNAAAAGc"]
[Mon Jul 20 07:25:26.458951 2026] [security2:error] [pid 116718:tid 116882] [client 50.116.65.227:41520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4hxpPWlhYV5NwZ9vVJOwAAABI"]
[Mon Jul 20 07:25:26.472868 2026] [security2:error] [pid 116718:tid 116906] [client 50.116.65.227:41528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4hxpPWlhYV5NwZ9vVJPQAAACo"]
[Mon Jul 20 07:25:26.521912 2026] [security2:error] [pid 116718:tid 116954] [client 18.141.57.241:30062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJPwAAAFo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:25:26.539052 2026] [security2:error] [pid 116718:tid 116878] [client 14.225.17.146:64939] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJQQAAAA4"], referer: https://walkingandtalking.net/backup
[Mon Jul 20 07:25:26.761314 2026] [security2:error] [pid 116718:tid 116913] [client 57.141.18.76:25966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIHAAAMQ0"]
[Mon Jul 20 07:25:26.780177 2026] [security2:error] [pid 116718:tid 116885] [client 14.225.17.146:52007] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4hxZPWlhYV5NwZ9vVI4gAAABU"], referer: http://effingweirdmuseums.com/backup
[Mon Jul 20 07:25:26.851602 2026] [security2:error] [pid 116718:tid 116921] [client 93.152.221.13:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJVQAAOQw"], referer: http://musichaven.info/.aws/credentials
[Mon Jul 20 07:25:26.869661 2026] [security2:error] [pid 116718:tid 116869] [client 93.152.221.13:55514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJWgAAAAU"]
[Mon Jul 20 07:25:27.056259 2026] [security2:error] [pid 116718:tid 116902] [client 93.152.221.13:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJZgAAJjY"], referer: https://musichaven.info/.aws/credentials
[Mon Jul 20 07:25:27.151865 2026] [security2:error] [pid 116718:tid 116947] [client 93.152.221.13:56724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/test.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJegAAAFM"]
[Mon Jul 20 07:25:27.153950 2026] [security2:error] [pid 116718:tid 116763] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJewAAIhw"]
[Mon Jul 20 07:25:27.154108 2026] [security2:error] [pid 116718:tid 116898] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJewAAIhw"]
[Mon Jul 20 07:25:27.258168 2026] [security2:error] [pid 116718:tid 116875] [client 14.225.17.146:65062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJUgAAAAs"]
[Mon Jul 20 07:25:27.331837 2026] [security2:error] [pid 116718:tid 116827] [remote 93.152.221.13:54994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "musichaven.info"] [uri "/.env"] [unique_id "al4hx5PWlhYV5NwZ9vVJhwAAOVw"], referer: http://musichaven.info/.env
[Mon Jul 20 07:25:27.479498 2026] [security2:error] [pid 116718:tid 116872] [client 104.234.53.50:51749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJkgAAAAg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:27.573518 2026] [security2:error] [pid 116718:tid 116866] [client 93.152.221.13:57498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/info.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJnQAAAAI"]
[Mon Jul 20 07:25:27.654236 2026] [security2:error] [pid 116718:tid 116951] [client 14.225.17.146:51475] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4hxZPWlhYV5NwZ9vVJDgAAAFc"], referer: http://cheesewithjam.com/backup
[Mon Jul 20 07:25:27.673047 2026] [security2:error] [pid 116718:tid 116953] [client 93.152.221.13:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJogAAWTc"], referer: http://musichaven.info/.env.example
[Mon Jul 20 07:25:27.760763 2026] [security2:error] [pid 116718:tid 116829] [remote 51.158.61.221:58688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJqwAAJl4"]
[Mon Jul 20 07:25:27.761016 2026] [security2:error] [pid 116718:tid 116902] [client 51.158.61.221:58688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJqwAAJl4"]
[Mon Jul 20 07:25:27.770467 2026] [security2:error] [pid 116718:tid 116970] [client 57.141.18.125:38094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hw5PWlhYV5NwZ9vVIawAAajA"]
[Mon Jul 20 07:25:27.775376 2026] [security2:error] [pid 116718:tid 116870] [client 14.225.17.146:52804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJqQAAAAY"], referer: https://effingweirdmuseums.com/backup
[Mon Jul 20 07:25:27.913803 2026] [security2:error] [pid 116718:tid 116916] [client 93.152.221.13:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJsQAANGk"], referer: https://musichaven.info/.env.example
[Mon Jul 20 07:25:27.935823 2026] [security2:error] [pid 116718:tid 116864] [client 14.225.17.146:52826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJqgAAAAA"], referer: http://savilerowtravel.com/backup
[Mon Jul 20 07:25:28.054816 2026] [security2:error] [pid 116718:tid 116835] [remote 8.217.108.67:8960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJxAAAPWQ"]
[Mon Jul 20 07:25:28.236022 2026] [security2:error] [pid 116718:tid 116934] [client 93.152.221.13:51741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/php.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ1wAAAEY"]
[Mon Jul 20 07:25:28.371194 2026] [security2:error] [pid 116718:tid 116919] [client 93.152.221.13:54994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "musichaven.info"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ4AAAN10"], referer: http://musichaven.info/.env.local
[Mon Jul 20 07:25:28.403003 2026] [security2:error] [pid 116718:tid 116880] [client 57.141.18.44:36378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hxJPWlhYV5NwZ9vVIoAAAEE0"]
[Mon Jul 20 07:25:28.539706 2026] [security2:error] [pid 116718:tid 116966] [client 93.152.221.13:57805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/php_info.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ8wAAAGY"]
[Mon Jul 20 07:25:28.563670 2026] [security2:error] [pid 116718:tid 116809] [remote 8.217.108.67:8960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ9gAAT0o"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:25:28.573364 2026] [security2:error] [pid 116718:tid 116952] [client 93.152.221.13:64596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.musichaven.info"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ7wAAWFY"], referer: https://musichaven.info/.env.local
[Mon Jul 20 07:25:28.595592 2026] [security2:error] [pid 116718:tid 116953] [client 14.225.17.146:52686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ6AAAAFk"], referer: http://scott-assist.com/backup
[Mon Jul 20 07:25:28.759146 2026] [security2:error] [pid 116718:tid 116907] [client 14.225.17.146:64965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJZwAAACs"], referer: http://maxenengineering.com/backup
[Mon Jul 20 07:25:28.818093 2026] [security2:error] [pid 116718:tid 116951] [client 93.152.221.13:60040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/i.php"] [unique_id "al4hyJPWlhYV5NwZ9vVKCwAAAFc"]
[Mon Jul 20 07:25:28.849136 2026] [security2:error] [pid 116718:tid 116758] [remote 93.152.221.13:54994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "musichaven.info"] [uri "/.env.backup"] [unique_id "al4hyJPWlhYV5NwZ9vVKDgAACxc"], referer: http://musichaven.info/.env.backup
[Mon Jul 20 07:25:28.939684 2026] [security2:error] [pid 116718:tid 116944] [client 14.225.17.146:51362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVKCQAAAFA"], referer: https://savilerowtravel.com/backup
[Mon Jul 20 07:25:29.090452 2026] [security2:error] [pid 116718:tid 116873] [client 93.152.221.13:58802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/pi.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKHwAAAAk"]
[Mon Jul 20 07:25:29.122486 2026] [security2:error] [pid 116718:tid 116778] [remote 93.152.221.13:54994] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "musichaven.info"] [uri "/config/.env"] [unique_id "al4hyZPWlhYV5NwZ9vVKIwAATSs"], referer: http://musichaven.info/config/.env
[Mon Jul 20 07:25:29.175595 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVKFwAAAFQ"], referer: 1'"3000
[Mon Jul 20 07:25:29.211534 2026] [security2:error] [pid 116718:tid 116883] [client 14.225.17.146:52774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4hx5PWlhYV5NwZ9vVJnwAAABM"], referer: http://alrowad-hub.net/backup
[Mon Jul 20 07:25:29.224948 2026] [security2:error] [pid 116718:tid 116980] [client 77.110.127.138:65425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKLgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.225059 2026] [security2:error] [pid 116718:tid 116980] [client 77.110.127.138:65425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKLgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.325268 2026] [security2:error] [pid 116718:tid 116884] [client 77.110.127.138:65417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKMwAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.325378 2026] [security2:error] [pid 116718:tid 116884] [client 77.110.127.138:65417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKMwAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.381308 2026] [security2:error] [pid 116718:tid 116871] [client 77.110.127.138:65429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKOwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.381403 2026] [security2:error] [pid 116718:tid 116871] [client 77.110.127.138:65429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKOwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.503563 2026] [security2:error] [pid 116718:tid 116944] [client 77.110.127.138:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKRAAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.503659 2026] [security2:error] [pid 116718:tid 116944] [client 77.110.127.138:65430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKRAAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.512024 2026] [security2:error] [pid 116718:tid 116929] [client 14.225.17.146:51403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVKDQAAAEE"], referer: http://aljosour-alarabia.com/backup
[Mon Jul 20 07:25:29.515656 2026] [security2:error] [pid 116718:tid 116966] [client 93.152.221.13:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKRQAAAGY"]
[Mon Jul 20 07:25:29.524871 2026] [security2:error] [pid 116718:tid 116984] [client 154.208.48.130:56223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKRwAAAHg"]
[Mon Jul 20 07:25:29.524962 2026] [security2:error] [pid 116718:tid 116984] [client 154.208.48.130:56223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKRwAAAHg"]
[Mon Jul 20 07:25:29.540773 2026] [security2:error] [pid 116718:tid 116965] [client 77.110.127.138:65419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKSQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.540931 2026] [security2:error] [pid 116718:tid 116965] [client 77.110.127.138:65419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKSQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.621983 2026] [security2:error] [pid 116718:tid 116909] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKPgAAAC0"], referer: 1'"3000
[Mon Jul 20 07:25:29.655919 2026] [security2:error] [pid 116718:tid 116931] [client 185.238.231.65:41613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKWAAAAEM"]
[Mon Jul 20 07:25:29.660231 2026] [security2:error] [pid 116718:tid 116963] [client 185.238.231.220:43529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKVwAAAGM"]
[Mon Jul 20 07:25:29.695463 2026] [security2:error] [pid 116718:tid 116885] [client 77.110.127.138:65431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKYQAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.695568 2026] [security2:error] [pid 116718:tid 116885] [client 77.110.127.138:65431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKYQAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.721502 2026] [security2:error] [pid 116718:tid 116919] [client 14.225.17.146:64859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKTQAAADc"], referer: https://maxenengineering.com/backup
[Mon Jul 20 07:25:29.753050 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKZgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.753177 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKZgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.795446 2026] [security2:error] [pid 116718:tid 116871] [client 93.152.221.13:53420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKaQAAAAc"]
[Mon Jul 20 07:25:29.807281 2026] [security2:error] [pid 116718:tid 116866] [client 77.110.127.138:65413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKawAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.807401 2026] [security2:error] [pid 116718:tid 116866] [client 77.110.127.138:65413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKawAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.859637 2026] [security2:error] [pid 116718:tid 116873] [client 77.110.127.138:65391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKbwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.859741 2026] [security2:error] [pid 116718:tid 116873] [client 77.110.127.138:65391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKbwAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.876878 2026] [security2:error] [pid 116718:tid 116893] [client 104.234.53.59:22403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKcAAAAB0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:29.956446 2026] [security2:error] [pid 116718:tid 116962] [client 49.47.218.174:17349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKeAAAAGI"]
[Mon Jul 20 07:25:29.956573 2026] [security2:error] [pid 116718:tid 116962] [client 49.47.218.174:17349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKeAAAAGI"]
[Mon Jul 20 07:25:29.969221 2026] [security2:error] [pid 116718:tid 116984] [client 77.110.127.138:65438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKeQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:29.969342 2026] [security2:error] [pid 116718:tid 116984] [client 77.110.127.138:65438] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKeQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:30.014308 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKewAAAFQ"]
[Mon Jul 20 07:25:30.014423 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKewAAAFQ"]
[Mon Jul 20 07:25:30.067853 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:65282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKhgAAABo"]
[Mon Jul 20 07:25:30.068016 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:65282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKhgAAABo"]
[Mon Jul 20 07:25:30.074095 2026] [security2:error] [pid 116718:tid 116921] [client 93.152.221.13:54603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webdisk.musichaven.info"] [uri "/php_version.php"] [unique_id "al4hypPWlhYV5NwZ9vVKhwAAADk"]
[Mon Jul 20 07:25:30.146605 2026] [security2:error] [pid 116718:tid 116964] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKdgAAAGQ"], referer: 1'"3000
[Mon Jul 20 07:25:30.158671 2026] [security2:error] [pid 116718:tid 116885] [client 77.110.127.138:65442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKkwAAABU"]
[Mon Jul 20 07:25:30.158798 2026] [security2:error] [pid 116718:tid 116885] [client 77.110.127.138:65442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKkwAAABU"]
[Mon Jul 20 07:25:30.191397 2026] [security2:error] [pid 116718:tid 116968] [client 14.225.17.146:65089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4hypPWlhYV5NwZ9vVKgQAAAGg"], referer: http://709fx.com/backup
[Mon Jul 20 07:25:30.251885 2026] [security2:error] [pid 116718:tid 116944] [client 77.110.127.138:65406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKmgAAAFA"]
[Mon Jul 20 07:25:30.252063 2026] [security2:error] [pid 116718:tid 116944] [client 77.110.127.138:65406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hypPWlhYV5NwZ9vVKmgAAAFA"]
[Mon Jul 20 07:25:30.480345 2026] [security2:error] [pid 116718:tid 116938] [client 45.157.112.60:42651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4hypPWlhYV5NwZ9vVKqwAAAEo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:25:30.508927 2026] [security2:error] [pid 116718:tid 116890] [client 93.152.221.13:59515] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.musichaven.info"] [uri "/___proxy_subdomain_webdisk/.env"] [unique_id "al4hypPWlhYV5NwZ9vVKrAAAABo"]
[Mon Jul 20 07:25:30.733094 2026] [security2:error] [pid 116718:tid 116950] [client 57.141.18.108:39028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hxpPWlhYV5NwZ9vVJZQAAVj0"]
[Mon Jul 20 07:25:30.786562 2026] [security2:error] [pid 116718:tid 116948] [client 136.158.60.21:27223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hypPWlhYV5NwZ9vVKwwAAAFQ"]
[Mon Jul 20 07:25:30.786657 2026] [security2:error] [pid 116718:tid 116948] [client 136.158.60.21:27223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4hypPWlhYV5NwZ9vVKwwAAAFQ"]
[Mon Jul 20 07:25:30.797259 2026] [security2:error] [pid 116718:tid 116939] [client 104.234.53.65:36313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4hypPWlhYV5NwZ9vVKwgAAAEs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:30.969822 2026] [security2:error] [pid 116718:tid 116988] [client 93.152.221.13:59515] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webdisk.musichaven.info"] [uri "/___proxy_subdomain_webdisk/.env.backup"] [unique_id "al4hypPWlhYV5NwZ9vVKzAAAAHw"]
[Mon Jul 20 07:25:31.074380 2026] [security2:error] [pid 116718:tid 116983] [client 49.37.242.14:52487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hy5PWlhYV5NwZ9vVK1QAAAHc"]
[Mon Jul 20 07:25:31.074483 2026] [security2:error] [pid 116718:tid 116983] [client 49.37.242.14:52487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4hy5PWlhYV5NwZ9vVK1QAAAHc"]
[Mon Jul 20 07:25:31.099619 2026] [security2:error] [pid 116718:tid 116961] [client 74.208.214.194:59178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hy5PWlhYV5NwZ9vVK2gAAAGE"]
[Mon Jul 20 07:25:31.108450 2026] [security2:error] [pid 116718:tid 116893] [client 93.152.221.13:59515] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webdisk.musichaven.info"] [uri "/___proxy_subdomain_webdisk/config/.env"] [unique_id "al4hy5PWlhYV5NwZ9vVK3QAAAB0"]
[Mon Jul 20 07:25:31.124217 2026] [security2:error] [pid 116718:tid 116937] [client 36.93.152.155:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hy5PWlhYV5NwZ9vVK4AAAAEk"]
[Mon Jul 20 07:25:31.124367 2026] [security2:error] [pid 116718:tid 116937] [client 36.93.152.155:49595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hy5PWlhYV5NwZ9vVK4AAAAEk"]
[Mon Jul 20 07:25:31.414652 2026] [security2:error] [pid 116718:tid 116891] [client 103.176.215.66:58946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hy5PWlhYV5NwZ9vVLBAAAABs"]
[Mon Jul 20 07:25:31.414820 2026] [security2:error] [pid 116718:tid 116891] [client 103.176.215.66:58946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4hy5PWlhYV5NwZ9vVLBAAAABs"]
[Mon Jul 20 07:25:31.694814 2026] [security2:error] [pid 116718:tid 116909] [client 77.110.127.138:65453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/amigurumi-owl-crochet-course-tuesday-mornings-cheam/vc7vsc9w5pfg.php"] [unique_id "al4hy5PWlhYV5NwZ9vVLLwAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:31.998947 2026] [security2:error] [pid 116718:tid 116900] [client 57.141.18.12:39480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hyJPWlhYV5NwZ9vVJ6gAAJBM"]
[Mon Jul 20 07:25:32.118858 2026] [security2:error] [pid 116718:tid 116948] [client 114.119.138.220:52579] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lutheranphilosopher.com"] [uri "/apps/members/membersList%3Bjsessionid=FD41821940519CD32454C6D943DD332C"] [unique_id "al4hzJPWlhYV5NwZ9vVLUQAAAFQ"], referer: https://www.lutheranphilosopher.com/apps/members/membersList%3Bjsessionid=C36E66781D186B83FE173551BBA4C931?offset=2&q&sort=DISPLAY_NAME&view=grid
[Mon Jul 20 07:25:32.452416 2026] [security2:error] [pid 116718:tid 116944] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hy5PWlhYV5NwZ9vVLGQAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:32.573231 2026] [security2:error] [pid 116718:tid 116888] [client 77.110.127.138:65377] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hy5PWlhYV5NwZ9vVLNAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:32.576092 2026] [security2:error] [pid 116718:tid 116980] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hy5PWlhYV5NwZ9vVLQgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:32.711420 2026] [security2:error] [pid 116718:tid 116903] [client 77.110.127.138:65436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/20/1awgrer4m8u3.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLjQAAACc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:32.767667 2026] [security2:error] [pid 116718:tid 116876] [client 103.106.165.44:57036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLngAAAAw"]
[Mon Jul 20 07:25:32.767817 2026] [security2:error] [pid 116718:tid 116876] [client 103.106.165.44:57036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLngAAAAw"]
[Mon Jul 20 07:25:32.967351 2026] [security2:error] [pid 116718:tid 116880] [client 201.27.111.74:60590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLswAAABA"]
[Mon Jul 20 07:25:32.967444 2026] [security2:error] [pid 116718:tid 116880] [client 201.27.111.74:60590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLswAAABA"]
[Mon Jul 20 07:25:33.037632 2026] [security2:error] [pid 116718:tid 116874] [client 143.44.185.218:45789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hzZPWlhYV5NwZ9vVLuAAAAAo"]
[Mon Jul 20 07:25:33.037724 2026] [security2:error] [pid 116718:tid 116874] [client 143.44.185.218:45789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4hzZPWlhYV5NwZ9vVLuAAAAAo"]
[Mon Jul 20 07:25:33.098699 2026] [proxy:error] [pid 116718:tid 116941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:33.098757 2026] [proxy_http:error] [pid 116718:tid 116941] [client 107.172.180.205:60872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:33.099642 2026] [proxy:error] [pid 116718:tid 116941] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:33.099686 2026] [proxy_http:error] [pid 116718:tid 116941] [client 107.172.180.205:60872] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:33.231342 2026] [security2:error] [pid 116718:tid 116929] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLiQAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:33.296716 2026] [security2:error] [pid 116718:tid 116947] [client 93.152.221.13:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/phpinfo.php"] [unique_id "al4hzZPWlhYV5NwZ9vVL0QAAAFM"]
[Mon Jul 20 07:25:33.330766 2026] [security2:error] [pid 116718:tid 116865] [client 57.141.18.104:57300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hyZPWlhYV5NwZ9vVKZQAAAS8"]
[Mon Jul 20 07:25:33.497718 2026] [proxy:error] [pid 116718:tid 116987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:33.497767 2026] [proxy_http:error] [pid 116718:tid 116987] [client 198.235.24.175:59938] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:33.498202 2026] [proxy:error] [pid 116718:tid 116987] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:33.498224 2026] [proxy_http:error] [pid 116718:tid 116987] [client 198.235.24.175:59938] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:33.524448 2026] [security2:error] [pid 116718:tid 116959] [client 112.86.225.90:49958] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-readartny-com/"] [unique_id "al4hzZPWlhYV5NwZ9vVL5QAAAF8"]
[Mon Jul 20 07:25:33.524593 2026] [security2:error] [pid 116718:tid 116959] [client 112.86.225.90:49958] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-readartny-com/"] [unique_id "al4hzZPWlhYV5NwZ9vVL5QAAAF8"]
[Mon Jul 20 07:25:33.544171 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLtQAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:33.570705 2026] [security2:error] [pid 116718:tid 116976] [client 93.152.221.13:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/test.php"] [unique_id "al4hzZPWlhYV5NwZ9vVL5wAAAHA"]
[Mon Jul 20 07:25:33.573572 2026] [security2:error] [pid 116718:tid 116911] [client 77.110.127.138:65449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLqgAAAC8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:33.663119 2026] [security2:error] [pid 116718:tid 116896] [client 191.202.66.27:53895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hzZPWlhYV5NwZ9vVL6QAAACA"]
[Mon Jul 20 07:25:33.663241 2026] [security2:error] [pid 116718:tid 116896] [client 191.202.66.27:53895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4hzZPWlhYV5NwZ9vVL6QAAACA"]
[Mon Jul 20 07:25:33.776368 2026] [proxy:error] [pid 116718:tid 116892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:33.776448 2026] [proxy_http:error] [pid 116718:tid 116892] [client 107.172.180.205:60892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:33.777034 2026] [proxy:error] [pid 116718:tid 116892] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:33.777062 2026] [proxy_http:error] [pid 116718:tid 116892] [client 107.172.180.205:60892] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:33.834820 2026] [security2:error] [pid 116718:tid 116877] [client 104.234.53.69:52415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4hzZPWlhYV5NwZ9vVL_AAAAA0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:33.866646 2026] [security2:error] [pid 116718:tid 116934] [client 77.110.127.138:65460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2016/08/31u2353rtjyr.php"] [unique_id "al4hzZPWlhYV5NwZ9vVMDgAAAEY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:33.938707 2026] [autoindex:error] [pid 116718:tid 116883] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/08/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:25:33.945245 2026] [autoindex:error] [pid 116718:tid 116922] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/08/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:25:33.954789 2026] [security2:error] [pid 116718:tid 116814] [remote 182.77.62.24:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4hzZPWlhYV5NwZ9vVMKwAAHU8"]
[Mon Jul 20 07:25:34.000646 2026] [security2:error] [pid 116718:tid 116971] [client 93.152.221.13:50183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/info.php"] [unique_id "al4hzZPWlhYV5NwZ9vVMMgAAAGs"]
[Mon Jul 20 07:25:34.137848 2026] [security2:error] [pid 116718:tid 116891] [client 88.241.67.160:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMPQAAABs"]
[Mon Jul 20 07:25:34.138075 2026] [security2:error] [pid 116718:tid 116891] [client 88.241.67.160:55742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMPQAAABs"]
[Mon Jul 20 07:25:34.258086 2026] [security2:error] [pid 116718:tid 116944] [client 77.110.127.138:65428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzZPWlhYV5NwZ9vVMEAAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.276670 2026] [security2:error] [pid 116718:tid 116937] [client 93.152.221.13:61163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/php.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMSwAAAEk"]
[Mon Jul 20 07:25:34.300694 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzZPWlhYV5NwZ9vVMHAAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.452447 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:65441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMXQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.452574 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:65441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMXQAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.469577 2026] [security2:error] [pid 116718:tid 116956] [client 157.20.138.62:54925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMYAAAAFw"]
[Mon Jul 20 07:25:34.469695 2026] [security2:error] [pid 116718:tid 116956] [client 157.20.138.62:54925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMYAAAAFw"]
[Mon Jul 20 07:25:34.470163 2026] [security2:error] [pid 116718:tid 116803] [remote 182.77.62.24:51638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/wp-login.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMXgAAAUQ"], referer: https://grndl.com/wp-login.php
[Mon Jul 20 07:25:34.507708 2026] [security2:error] [pid 116718:tid 116871] [client 57.141.18.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMWgAAAAc"]
[Mon Jul 20 07:25:34.553818 2026] [security2:error] [pid 116718:tid 116910] [client 93.152.221.13:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/php_info.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMmQAAAC4"]
[Mon Jul 20 07:25:34.569035 2026] [security2:error] [pid 116718:tid 116988] [client 104.234.53.93:52677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMmwAAAHw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:34.597147 2026] [security2:error] [pid 116718:tid 116907] [client 179.127.84.238:55220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMnQAAACs"]
[Mon Jul 20 07:25:34.597244 2026] [security2:error] [pid 116718:tid 116907] [client 179.127.84.238:55220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMnQAAACs"]
[Mon Jul 20 07:25:34.603779 2026] [security2:error] [pid 116718:tid 116932] [client 77.110.127.138:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMoAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.603846 2026] [security2:error] [pid 116718:tid 116932] [client 77.110.127.138:65468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMoAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.637880 2026] [security2:error] [pid 116718:tid 116964] [client 57.141.18.121:49152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hy5PWlhYV5NwZ9vVK6AAAZA4"]
[Mon Jul 20 07:25:34.648005 2026] [security2:error] [pid 116718:tid 116893] [client 77.110.127.138:65444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-blanket/5fkt5ic4ydmf.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMpAAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.676504 2026] [autoindex:error] [pid 116718:tid 116900] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/08/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/tag/crochet-classes/page/2/
[Mon Jul 20 07:25:34.833653 2026] [security2:error] [pid 116718:tid 116956] [client 93.152.221.13:63976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/i.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMxAAAAFw"]
[Mon Jul 20 07:25:34.850703 2026] [security2:error] [pid 116718:tid 116885] [client 77.110.127.138:65459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMpwAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.853124 2026] [security2:error] [pid 116718:tid 116869] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMsAAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:34.882500 2026] [security2:error] [pid 116718:tid 116780] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMyQAACS0"]
[Mon Jul 20 07:25:34.882648 2026] [security2:error] [pid 116718:tid 116873] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMyQAACS0"]
[Mon Jul 20 07:25:34.885001 2026] [security2:error] [pid 116718:tid 116866] [client 57.141.18.111:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMtwAAAAI"]
[Mon Jul 20 07:25:35.060922 2026] [security2:error] [pid 116718:tid 116969] [client 14.225.17.146:51915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4hzZPWlhYV5NwZ9vVMFgAAAGk"], referer: http://lutheranphilosopher.com/backup
[Mon Jul 20 07:25:35.110334 2026] [security2:error] [pid 116718:tid 116885] [client 93.152.221.13:52546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/pi.php"] [unique_id "al4hz5PWlhYV5NwZ9vVM8QAAABU"]
[Mon Jul 20 07:25:35.118465 2026] [security2:error] [pid 116718:tid 116806] [remote 47.86.33.52:37454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hz5PWlhYV5NwZ9vVM8gAAYUc"]
[Mon Jul 20 07:25:35.122618 2026] [security2:error] [pid 116718:tid 116881] [client 104.234.53.82:34251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4hz5PWlhYV5NwZ9vVM8wAAABE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:35.282021 2026] [security2:error] [pid 116718:tid 116902] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hzpPWlhYV5NwZ9vVMwgAAACY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:35.399023 2026] [security2:error] [pid 116718:tid 116987] [client 77.110.127.138:65462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/pattern/qmz9yq134v1a.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNHAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:35.473594 2026] [security2:error] [pid 116718:tid 116805] [remote 57.141.18.47:36230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5484005"] [unique_id "al4hz5PWlhYV5NwZ9vVNMgAALEY"]
[Mon Jul 20 07:25:35.535369 2026] [security2:error] [pid 116718:tid 116774] [remote 47.86.33.52:37454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNOgAAfSc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:25:35.549780 2026] [security2:error] [pid 116718:tid 116932] [client 93.152.221.13:55312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/admin/phpinfo.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNPAAAAEQ"]
[Mon Jul 20 07:25:35.586901 2026] [security2:error] [pid 116718:tid 116914] [client 74.208.214.194:37788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNPQAAADI"]
[Mon Jul 20 07:25:35.599134 2026] [security2:error] [pid 116718:tid 116953] [client 57.141.18.35:37902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLSQAAWQA"]
[Mon Jul 20 07:25:35.629446 2026] [security2:error] [pid 116718:tid 116952] [client 77.110.127.138:65449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNHgAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:35.683471 2026] [security2:error] [pid 116718:tid 116871] [client 14.225.17.146:64936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4hz5PWlhYV5NwZ9vVM-QAAAAc"], referer: http://gearwaterproof.com/backup
[Mon Jul 20 07:25:35.683500 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNKgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:35.713493 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNLAAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:35.792466 2026] [security2:error] [pid 116718:tid 116985] [client 57.141.18.8:40758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hzJPWlhYV5NwZ9vVLWwAAeSg"]
[Mon Jul 20 07:25:35.831936 2026] [security2:error] [pid 116718:tid 116935] [client 93.152.221.13:51759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/pinfo.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNSgAAAEc"]
[Mon Jul 20 07:25:35.833664 2026] [security2:error] [pid 116718:tid 116907] [client 154.192.123.127:18873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNSQAAACs"]
[Mon Jul 20 07:25:35.833802 2026] [security2:error] [pid 116718:tid 116907] [client 154.192.123.127:18873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNSQAAACs"]
[Mon Jul 20 07:25:36.057345 2026] [security2:error] [pid 116718:tid 116923] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNOAAAOyk"], referer: http://assasalnazaha.com/backup
[Mon Jul 20 07:25:36.072360 2026] [security2:error] [pid 116718:tid 116880] [client 158.173.89.95:58581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4h0JPWlhYV5NwZ9vVNZwAAABA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:25:36.108541 2026] [security2:error] [pid 116718:tid 116976] [client 93.152.221.13:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.221.152.93.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.musichaven.info"] [uri "/php_version.php"] [unique_id "al4h0JPWlhYV5NwZ9vVNbAAAAHA"]
[Mon Jul 20 07:25:36.203106 2026] [security2:error] [pid 116718:tid 116937] [client 104.234.53.59:41089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4h0JPWlhYV5NwZ9vVNdQAAAEk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:36.553404 2026] [security2:error] [pid 116718:tid 116933] [client 93.152.221.13:61020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.musichaven.info"] [uri "/___proxy_subdomain_webmail/.env"] [unique_id "al4h0JPWlhYV5NwZ9vVNmgAAAEU"]
[Mon Jul 20 07:25:36.605290 2026] [security2:error] [pid 116718:tid 116941] [client 41.75.92.228:58219] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4h0JPWlhYV5NwZ9vVNagAAAE0"]
[Mon Jul 20 07:25:37.018137 2026] [security2:error] [pid 116718:tid 116952] [client 93.152.221.13:61020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "webmail.musichaven.info"] [uri "/___proxy_subdomain_webmail/.env.backup"] [unique_id "al4h0ZPWlhYV5NwZ9vVNvQAAAFg"]
[Mon Jul 20 07:25:37.157917 2026] [security2:error] [pid 116718:tid 116920] [client 93.152.221.13:61020] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "webmail.musichaven.info"] [uri "/___proxy_subdomain_webmail/config/.env"] [unique_id "al4h0ZPWlhYV5NwZ9vVNywAAADg"]
[Mon Jul 20 07:25:37.171780 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVNzAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.171875 2026] [security2:error] [pid 116718:tid 116976] [client 77.110.127.138:65480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVNzAAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.224899 2026] [security2:error] [pid 116718:tid 116906] [client 77.110.127.138:65377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN0gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.225005 2026] [security2:error] [pid 116718:tid 116906] [client 77.110.127.138:65377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN0gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.355456 2026] [security2:error] [pid 116718:tid 116869] [client 77.110.127.138:65449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN2wAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.355559 2026] [security2:error] [pid 116718:tid 116869] [client 77.110.127.138:65449] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN2wAAAAU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.407478 2026] [security2:error] [pid 116718:tid 116970] [client 77.110.127.138:65461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN4QAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.407574 2026] [security2:error] [pid 116718:tid 116970] [client 77.110.127.138:65461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN4QAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.431167 2026] [security2:error] [pid 116718:tid 116961] [client 77.110.127.138:65451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN5QAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.431273 2026] [security2:error] [pid 116718:tid 116961] [client 77.110.127.138:65451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN5QAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.466810 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:65428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN5wAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.466934 2026] [security2:error] [pid 116718:tid 116890] [client 77.110.127.138:65428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN5wAAABo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.491707 2026] [security2:error] [pid 116718:tid 116921] [client 77.110.127.138:65440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN6wAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.491831 2026] [security2:error] [pid 116718:tid 116921] [client 77.110.127.138:65440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN6wAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.578457 2026] [security2:error] [pid 116718:tid 116787] [remote 103.28.36.106:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN8gAALjQ"]
[Mon Jul 20 07:25:37.608041 2026] [security2:error] [pid 116718:tid 116987] [client 77.110.127.138:65474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN9gAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.608044 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:65469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN9QAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.608132 2026] [security2:error] [pid 116718:tid 116987] [client 77.110.127.138:65474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN9gAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.608135 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:65469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN9QAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.658103 2026] [security2:error] [pid 116718:tid 116914] [client 77.110.127.138:65407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN_gAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.658218 2026] [security2:error] [pid 116718:tid 116914] [client 77.110.127.138:65407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVN_gAAADI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.719050 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVOAwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.719157 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:65452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVOAwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.768901 2026] [security2:error] [pid 116718:tid 116872] [client 77.110.127.138:65445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVODAAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.769016 2026] [security2:error] [pid 116718:tid 116872] [client 77.110.127.138:65445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVODAAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.771416 2026] [security2:error] [pid 116718:tid 116870] [client 77.110.127.138:65482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVODQAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.771495 2026] [security2:error] [pid 116718:tid 116870] [client 77.110.127.138:65482] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVODQAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:37.898086 2026] [security2:error] [pid 116718:tid 116888] [client 14.225.17.146:51376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVODwAAABg"], referer: http://keywayconstructionclt.com/backup
[Mon Jul 20 07:25:38.036287 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:65465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOHQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:38.036413 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:65465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOHQAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:38.113465 2026] [security2:error] [pid 116718:tid 116833] [remote 103.28.36.106:37582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOJgAAIGI"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 07:25:38.121237 2026] [security2:error] [pid 116718:tid 116815] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOLQAAD1A"]
[Mon Jul 20 07:25:38.121363 2026] [security2:error] [pid 116718:tid 116879] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOLQAAD1A"]
[Mon Jul 20 07:25:38.479712 2026] [security2:error] [pid 116718:tid 116782] [remote 20.153.140.50:52464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4h0pPWlhYV5NwZ9vVORwAAey8"]
[Mon Jul 20 07:25:38.479963 2026] [security2:error] [pid 116718:tid 116987] [client 20.153.140.50:52464] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4h0pPWlhYV5NwZ9vVORwAAey8"]
[Mon Jul 20 07:25:38.725934 2026] [security2:error] [pid 116718:tid 116784] [remote 188.166.241.141:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOZAAAbjE"]
[Mon Jul 20 07:25:38.793858 2026] [security2:error] [pid 116718:tid 116980] [client 14.225.17.146:60036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOZwAAAHQ"], referer: https://keywayconstructionclt.com/backup
[Mon Jul 20 07:25:38.813192 2026] [security2:error] [pid 116718:tid 116965] [client 57.141.18.113:50666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4hz5PWlhYV5NwZ9vVNBQAAZUs"]
[Mon Jul 20 07:25:38.815285 2026] [security2:error] [pid 116718:tid 116921] [client 50.116.65.227:48916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4h0pPWlhYV5NwZ9vVObgAAADk"]
[Mon Jul 20 07:25:38.825060 2026] [security2:error] [pid 116718:tid 116958] [client 50.116.65.227:48918] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4h0pPWlhYV5NwZ9vVObwAAAF4"]
[Mon Jul 20 07:25:39.026889 2026] [security2:error] [pid 116718:tid 116952] [client 104.234.53.54:36685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOewAAAFg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:39.125776 2026] [security2:error] [pid 116718:tid 116792] [remote 188.166.241.141:57932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4h05PWlhYV5NwZ9vVOjQAAdzk"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:25:39.153311 2026] [security2:error] [pid 116718:tid 116964] [client 14.225.17.146:60000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4h0ZPWlhYV5NwZ9vVOFwAAAGQ"], referer: http://getgarrison.com/backup
[Mon Jul 20 07:25:39.726846 2026] [security2:error] [pid 116718:tid 116865] [client 57.141.18.108:64830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h0JPWlhYV5NwZ9vVNeAAAAQw"]
[Mon Jul 20 07:25:40.280189 2026] [security2:error] [pid 116718:tid 116917] [client 37.27.55.110:35720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.55.27.37.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "jedalilly.com"] [uri "/ssv3_directory.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO5AAAADU"]
[Mon Jul 20 07:25:40.319198 2026] [security2:error] [pid 116718:tid 116963] [client 154.208.48.130:57023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO5wAAAGM"]
[Mon Jul 20 07:25:40.319958 2026] [security2:error] [pid 116718:tid 116963] [client 154.208.48.130:57023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO5wAAAGM"]
[Mon Jul 20 07:25:40.441307 2026] [security2:error] [pid 116718:tid 116958] [client 49.47.218.174:54366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO-AAAAF4"]
[Mon Jul 20 07:25:40.441404 2026] [security2:error] [pid 116718:tid 116958] [client 49.47.218.174:54366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO-AAAAF4"]
[Mon Jul 20 07:25:40.497818 2026] [security2:error] [pid 116718:tid 116880] [client 104.234.53.63:26895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO_AAAABA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:40.513172 2026] [security2:error] [pid 116718:tid 116979] [client 50.116.65.227:14722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2022/09/IMG_8303-table-with-salad-plates-on-side--scaled.jpeg"] [unique_id "al4h1JPWlhYV5NwZ9vVO_QAAAHM"]
[Mon Jul 20 07:25:40.612868 2026] [security2:error] [pid 116718:tid 116964] [client 158.173.241.141:36135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO7gAAZHc"]
[Mon Jul 20 07:25:40.674715 2026] [security2:error] [pid 116718:tid 116824] [remote 57.141.18.118:59168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5610164"] [unique_id "al4h1JPWlhYV5NwZ9vVPBQAAK1k"]
[Mon Jul 20 07:25:40.685869 2026] [security2:error] [pid 116718:tid 116892] [client 77.110.127.138:65484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h1JPWlhYV5NwZ9vVPBgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:40.685976 2026] [security2:error] [pid 116718:tid 116892] [client 77.110.127.138:65484] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h1JPWlhYV5NwZ9vVPBgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:40.744463 2026] [security2:error] [pid 116718:tid 116818] [remote 188.166.241.141:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4h1JPWlhYV5NwZ9vVPEgAAcVM"]
[Mon Jul 20 07:25:40.834776 2026] [security2:error] [pid 116718:tid 116975] [client 14.225.17.146:52283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4h05PWlhYV5NwZ9vVOnwAAAG8"], referer: http://alaraycreative.com/backup
[Mon Jul 20 07:25:41.284422 2026] [security2:error] [pid 116718:tid 116890] [client 50.116.65.227:44102] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4h1ZPWlhYV5NwZ9vVPQAAAABo"]
[Mon Jul 20 07:25:41.295977 2026] [security2:error] [pid 116718:tid 116942] [client 50.116.65.227:14754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/07/South-Africa-Day-1-Feature-Image.jpg"] [unique_id "al4h1ZPWlhYV5NwZ9vVPQwAAAE4"]
[Mon Jul 20 07:25:41.373775 2026] [security2:error] [pid 116718:tid 116794] [remote 188.166.241.141:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPSAAAVTs"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 07:25:41.429353 2026] [security2:error] [pid 116718:tid 116909] [client 77.110.127.138:65476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPSgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:41.429446 2026] [security2:error] [pid 116718:tid 116909] [client 77.110.127.138:65476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPSgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:41.568409 2026] [security2:error] [pid 116718:tid 116864] [client 136.158.60.21:28783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPTwAAAAA"]
[Mon Jul 20 07:25:41.568567 2026] [security2:error] [pid 116718:tid 116864] [client 136.158.60.21:28783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPTwAAAAA"]
[Mon Jul 20 07:25:41.659055 2026] [security2:error] [pid 116718:tid 116880] [client 36.93.152.155:50346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPVwAAABA"]
[Mon Jul 20 07:25:41.659162 2026] [security2:error] [pid 116718:tid 116880] [client 36.93.152.155:50346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPVwAAABA"]
[Mon Jul 20 07:25:41.962811 2026] [security2:error] [pid 116718:tid 116976] [client 103.176.215.66:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPdAAAAHA"]
[Mon Jul 20 07:25:41.963230 2026] [security2:error] [pid 116718:tid 116976] [client 103.176.215.66:59480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPdAAAAHA"]
[Mon Jul 20 07:25:41.990412 2026] [security2:error] [pid 116718:tid 116749] [remote 91.142.222.105:44494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPdQAANA4"]
[Mon Jul 20 07:25:42.188083 2026] [security2:error] [pid 116718:tid 116984] [client 57.141.18.34:29090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOPgAAeB4"]
[Mon Jul 20 07:25:42.250006 2026] [security2:error] [pid 116718:tid 116758] [remote 91.142.222.105:44494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4h1pPWlhYV5NwZ9vVPjgAAbhc"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 07:25:42.479446 2026] [security2:error] [pid 116718:tid 116885] [client 57.141.18.98:39404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h0pPWlhYV5NwZ9vVOYwAAFTM"]
[Mon Jul 20 07:25:42.481182 2026] [security2:error] [pid 116718:tid 116906] [client 104.234.53.72:41461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4h1pPWlhYV5NwZ9vVPqAAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:43.050992 2026] [security2:error] [pid 116718:tid 116762] [remote 182.77.62.24:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h15PWlhYV5NwZ9vVP2wAAaBs"]
[Mon Jul 20 07:25:43.190011 2026] [security2:error] [pid 116718:tid 116851] [remote 91.142.222.105:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4h15PWlhYV5NwZ9vVP5gAAenQ"]
[Mon Jul 20 07:25:43.201112 2026] [security2:error] [pid 116718:tid 116908] [client 77.110.127.138:65495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h15PWlhYV5NwZ9vVP5wAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:43.201242 2026] [security2:error] [pid 116718:tid 116908] [client 77.110.127.138:65495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h15PWlhYV5NwZ9vVP5wAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:43.262355 2026] [security2:error] [pid 116718:tid 116897] [client 103.106.165.44:57507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h15PWlhYV5NwZ9vVP7wAAACE"]
[Mon Jul 20 07:25:43.262453 2026] [security2:error] [pid 116718:tid 116897] [client 103.106.165.44:57507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h15PWlhYV5NwZ9vVP7wAAACE"]
[Mon Jul 20 07:25:43.408602 2026] [security2:error] [pid 116718:tid 116892] [client 201.27.111.74:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h15PWlhYV5NwZ9vVQAgAAABw"]
[Mon Jul 20 07:25:43.408713 2026] [security2:error] [pid 116718:tid 116892] [client 201.27.111.74:61095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h15PWlhYV5NwZ9vVQAgAAABw"]
[Mon Jul 20 07:25:43.431352 2026] [security2:error] [pid 116718:tid 116764] [remote 91.142.222.105:45952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4h15PWlhYV5NwZ9vVQBQAABh0"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 07:25:43.613777 2026] [security2:error] [pid 116718:tid 116823] [remote 182.77.62.24:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h15PWlhYV5NwZ9vVQCgAAUlg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:25:43.649352 2026] [security2:error] [pid 116718:tid 116868] [client 57.141.18.21:48168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h05PWlhYV5NwZ9vVOwgAABDg"]
[Mon Jul 20 07:25:43.733622 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:65509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h15PWlhYV5NwZ9vVQFQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:43.733702 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:65509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h15PWlhYV5NwZ9vVQFQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:44.016105 2026] [security2:error] [pid 116718:tid 116980] [client 57.141.18.119:20850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h1JPWlhYV5NwZ9vVO7wAAdAo"]
[Mon Jul 20 07:25:44.317281 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:65506] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h2JPWlhYV5NwZ9vVQQAAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:44.381440 2026] [security2:error] [pid 116718:tid 116945] [client 191.202.66.27:54384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQSQAAAFE"]
[Mon Jul 20 07:25:44.381599 2026] [security2:error] [pid 116718:tid 116945] [client 191.202.66.27:54384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQSQAAAFE"]
[Mon Jul 20 07:25:44.504421 2026] [security2:error] [pid 116718:tid 116919] [client 173.252.70.37:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.greenvillemoving.com"] [uri "/index.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQUQAAADc"]
[Mon Jul 20 07:25:44.574608 2026] [security2:error] [pid 116718:tid 116882] [client 114.119.157.132:35635] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/robots.txt"] [unique_id "al4h2JPWlhYV5NwZ9vVQVAAAABI"], referer: https://backandneckpainrelieflaceychiropractor.com/robots.txt
[Mon Jul 20 07:25:44.768119 2026] [security2:error] [pid 116718:tid 116963] [client 88.241.67.160:53949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQWwAAAGM"]
[Mon Jul 20 07:25:44.768284 2026] [security2:error] [pid 116718:tid 116963] [client 88.241.67.160:53949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQWwAAAGM"]
[Mon Jul 20 07:25:44.786680 2026] [security2:error] [pid 116718:tid 116941] [client 178.156.189.113:4804] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQOgAAAE0"], referer: https://windowtx.com
[Mon Jul 20 07:25:44.912200 2026] [security2:error] [pid 116718:tid 116918] [client 77.110.127.138:65512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQcwAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:44.912290 2026] [security2:error] [pid 116718:tid 116918] [client 77.110.127.138:65512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h2JPWlhYV5NwZ9vVQcwAAADY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:45.303156 2026] [security2:error] [pid 116718:tid 116987] [client 57.141.18.65:50780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h1ZPWlhYV5NwZ9vVPVAAAe1o"]
[Mon Jul 20 07:25:45.324241 2026] [security2:error] [pid 116718:tid 116945] [client 179.127.84.238:55719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQjwAAAFE"]
[Mon Jul 20 07:25:45.324347 2026] [security2:error] [pid 116718:tid 116945] [client 179.127.84.238:55719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQjwAAAFE"]
[Mon Jul 20 07:25:45.370471 2026] [security2:error] [pid 116718:tid 116944] [client 157.20.138.62:55492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQkgAAAFA"]
[Mon Jul 20 07:25:45.370578 2026] [security2:error] [pid 116718:tid 116944] [client 157.20.138.62:55492] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQkgAAAFA"]
[Mon Jul 20 07:25:45.466171 2026] [security2:error] [pid 116718:tid 116937] [client 143.44.185.218:47164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQnAAAAEk"]
[Mon Jul 20 07:25:45.466280 2026] [security2:error] [pid 116718:tid 116937] [client 143.44.185.218:47164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQnAAAAEk"]
[Mon Jul 20 07:25:45.596692 2026] [security2:error] [pid 116718:tid 116864] [client 77.110.127.138:65515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQswAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:45.596789 2026] [security2:error] [pid 116718:tid 116864] [client 77.110.127.138:65515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQswAAAAA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:45.621056 2026] [security2:error] [pid 116718:tid 116780] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQtwAATi0"]
[Mon Jul 20 07:25:45.621225 2026] [security2:error] [pid 116718:tid 116942] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQtwAATi0"]
[Mon Jul 20 07:25:45.850535 2026] [security2:error] [pid 116718:tid 116988] [client 57.141.18.65:50796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h1pPWlhYV5NwZ9vVPiAAAfE0"]
[Mon Jul 20 07:25:45.941227 2026] [security2:error] [pid 116718:tid 116898] [client 77.110.127.138:65502] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h2ZPWlhYV5NwZ9vVQ1AAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:46.015897 2026] [security2:error] [pid 116718:tid 116927] [client 49.37.242.14:53095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4h2pPWlhYV5NwZ9vVQ3QAAAD8"]
[Mon Jul 20 07:25:46.023461 2026] [security2:error] [pid 116718:tid 116927] [client 49.37.242.14:53095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4h2pPWlhYV5NwZ9vVQ3QAAAD8"]
[Mon Jul 20 07:25:46.511177 2026] [security2:error] [pid 116718:tid 116977] [client 154.192.123.127:17316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h2pPWlhYV5NwZ9vVQ-AAAAHE"]
[Mon Jul 20 07:25:46.511319 2026] [security2:error] [pid 116718:tid 116977] [client 154.192.123.127:17316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h2pPWlhYV5NwZ9vVQ-AAAAHE"]
[Mon Jul 20 07:25:46.694328 2026] [security2:error] [pid 116718:tid 116892] [client 104.234.53.52:25427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4h2pPWlhYV5NwZ9vVRAQAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:47.008495 2026] [security2:error] [pid 116718:tid 116953] [client 117.211.236.168:50483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4h25PWlhYV5NwZ9vVRHwAAAFk"]
[Mon Jul 20 07:25:47.008625 2026] [security2:error] [pid 116718:tid 116953] [client 117.211.236.168:50483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4h25PWlhYV5NwZ9vVRHwAAAFk"]
[Mon Jul 20 07:25:47.043699 2026] [security2:error] [pid 116718:tid 116978] [client 57.141.18.86:32792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h15PWlhYV5NwZ9vVQAwAAcgA"]
[Mon Jul 20 07:25:47.100781 2026] [security2:error] [pid 116718:tid 116958] [client 77.110.127.138:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h25PWlhYV5NwZ9vVRJgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:47.100877 2026] [security2:error] [pid 116718:tid 116958] [client 77.110.127.138:65519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h25PWlhYV5NwZ9vVRJgAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:47.104801 2026] [security2:error] [pid 116718:tid 116876] [client 57.141.18.25:26072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h15PWlhYV5NwZ9vVQBgAADBI"]
[Mon Jul 20 07:25:47.343507 2026] [security2:error] [pid 116718:tid 116767] [remote 199.189.225.40:34195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4h25PWlhYV5NwZ9vVRNQAAYSA"]
[Mon Jul 20 07:25:47.756194 2026] [security2:error] [pid 116718:tid 116802] [remote 199.189.225.40:34195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thechancersband.com"] [uri "/wp-login.php"] [unique_id "al4h25PWlhYV5NwZ9vVRWwAAU0M"], referer: https://thechancersband.com/wp-login.php
[Mon Jul 20 07:25:47.827916 2026] [security2:error] [pid 116718:tid 116939] [client 57.141.18.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4h25PWlhYV5NwZ9vVRVAAAAEs"]
[Mon Jul 20 07:25:47.943687 2026] [security2:error] [pid 116718:tid 116898] [client 193.36.225.1:63835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4h25PWlhYV5NwZ9vVRTwAAACI"]
[Mon Jul 20 07:25:47.943990 2026] [security2:error] [pid 116718:tid 116922] [client 193.36.225.90:34581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4h25PWlhYV5NwZ9vVRUAAAADo"]
[Mon Jul 20 07:25:48.030105 2026] [security2:error] [pid 116718:tid 116925] [client 77.110.127.138:65457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h3JPWlhYV5NwZ9vVReAAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:48.030213 2026] [security2:error] [pid 116718:tid 116925] [client 77.110.127.138:65457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h3JPWlhYV5NwZ9vVReAAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:48.519962 2026] [security2:error] [pid 116718:tid 116898] [client 77.110.127.138:65523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h3JPWlhYV5NwZ9vVRoQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:48.579736 2026] [security2:error] [pid 116718:tid 116950] [client 170.64.229.59:49843] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.meditacionmiami.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4h3JPWlhYV5NwZ9vVRoAAAAFY"]
[Mon Jul 20 07:25:48.933031 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h3JPWlhYV5NwZ9vVRugAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:48.933147 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h3JPWlhYV5NwZ9vVRugAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:49.153921 2026] [security2:error] [pid 116718:tid 116962] [client 57.141.18.48:38822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQmAAAYjs"]
[Mon Jul 20 07:25:49.191523 2026] [security2:error] [pid 116718:tid 116949] [client 57.141.18.24:59738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQqgAAVRg"]
[Mon Jul 20 07:25:49.302961 2026] [security2:error] [pid 116718:tid 116780] [remote 154.66.198.148:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVR4QAAIS0"]
[Mon Jul 20 07:25:49.447041 2026] [security2:error] [pid 116718:tid 116865] [client 158.173.166.181:42761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVR6wAAAAE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:25:49.470283 2026] [security2:error] [pid 116718:tid 116833] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVR7QAAH2I"]
[Mon Jul 20 07:25:49.470441 2026] [security2:error] [pid 116718:tid 116895] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVR7QAAH2I"]
[Mon Jul 20 07:25:49.541090 2026] [security2:error] [pid 116718:tid 116935] [client 57.141.18.116:36014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h2ZPWlhYV5NwZ9vVQ1wAARzY"]
[Mon Jul 20 07:25:49.644344 2026] [security2:error] [pid 116718:tid 116874] [client 202.141.11.99:12038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVSAwAAAAo"]
[Mon Jul 20 07:25:49.644443 2026] [security2:error] [pid 116718:tid 116874] [client 202.141.11.99:12038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVSAwAAAAo"]
[Mon Jul 20 07:25:49.851800 2026] [security2:error] [pid 116718:tid 116839] [remote 154.66.198.148:39910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVSDwAAZmg"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:25:50.047129 2026] [security2:error] [pid 116718:tid 116971] [client 52.167.144.191:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4h3ZPWlhYV5NwZ9vVSBAAAa10"]
[Mon Jul 20 07:25:50.351070 2026] [security2:error] [pid 116718:tid 116784] [remote 124.55.178.99:41442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSPAAAEzE"]
[Mon Jul 20 07:25:50.555643 2026] [security2:error] [pid 116718:tid 116871] [client 15.237.142.234:16048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSRwAAAAc"]
[Mon Jul 20 07:25:50.555761 2026] [security2:error] [pid 116718:tid 116871] [client 15.237.142.234:16048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSRwAAAAc"]
[Mon Jul 20 07:25:50.665659 2026] [security2:error] [pid 116718:tid 116932] [client 50.116.65.227:24568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4h3pPWlhYV5NwZ9vVSUgAAAEQ"]
[Mon Jul 20 07:25:50.675437 2026] [security2:error] [pid 116718:tid 116929] [client 50.116.65.227:24578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4h3pPWlhYV5NwZ9vVSUwAAAEE"]
[Mon Jul 20 07:25:50.717205 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSWAAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:50.717291 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:65530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSWAAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:50.756135 2026] [security2:error] [pid 116718:tid 116792] [remote 124.55.178.99:41442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSXAAAIjk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:25:50.854784 2026] [security2:error] [pid 116718:tid 116916] [client 57.141.18.75:46684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h25PWlhYV5NwZ9vVRMAAANCM"]
[Mon Jul 20 07:25:50.968892 2026] [security2:error] [pid 116718:tid 116920] [client 49.47.218.174:23107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSdwAAADg"]
[Mon Jul 20 07:25:50.969035 2026] [security2:error] [pid 116718:tid 116920] [client 49.47.218.174:23107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSdwAAADg"]
[Mon Jul 20 07:25:51.047078 2026] [security2:error] [pid 116718:tid 116788] [remote 124.55.178.99:41458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4h35PWlhYV5NwZ9vVSewAASjU"]
[Mon Jul 20 07:25:51.047203 2026] [security2:error] [pid 116718:tid 116938] [client 124.55.178.99:41458] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4h35PWlhYV5NwZ9vVSewAASjU"]
[Mon Jul 20 07:25:51.104278 2026] [security2:error] [pid 116718:tid 116979] [client 77.110.127.138:65523] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h35PWlhYV5NwZ9vVSfwAAAHM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:51.156265 2026] [security2:error] [pid 116718:tid 116740] [remote 114.119.128.14:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "packerjanitorial.com"] [uri "/robots.txt"] [unique_id "al4h35PWlhYV5NwZ9vVShAAAVAU"], referer: https://packerjanitorial.com/robots.txt
[Mon Jul 20 07:25:51.159897 2026] [security2:error] [pid 116718:tid 116965] [client 77.110.127.138:65508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h35PWlhYV5NwZ9vVShQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:51.160014 2026] [security2:error] [pid 116718:tid 116965] [client 77.110.127.138:65508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h35PWlhYV5NwZ9vVShQAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:51.177452 2026] [security2:error] [pid 116718:tid 116972] [client 154.208.48.130:57645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h35PWlhYV5NwZ9vVSiQAAAGw"]
[Mon Jul 20 07:25:51.178265 2026] [security2:error] [pid 116718:tid 116972] [client 154.208.48.130:57645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h35PWlhYV5NwZ9vVSiQAAAGw"]
[Mon Jul 20 07:25:51.493505 2026] [fcgid:warn] [pid 116718:tid 116890] (70014)End of file found: [client 66.132.195.61:35826] mod_fcgid: can't get data from http client
[Mon Jul 20 07:25:51.500009 2026] [security2:error] [pid 116718:tid 116976] [client 13.233.207.33:12278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4h35PWlhYV5NwZ9vVSowAAAHA"]
[Mon Jul 20 07:25:52.159273 2026] [security2:error] [pid 116718:tid 116912] [client 36.93.152.155:50908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS1QAAADA"]
[Mon Jul 20 07:25:52.159382 2026] [security2:error] [pid 116718:tid 116912] [client 36.93.152.155:50908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS1QAAADA"]
[Mon Jul 20 07:25:52.288840 2026] [security2:error] [pid 116718:tid 116855] [remote 103.187.169.251:36578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS4AAAYng"]
[Mon Jul 20 07:25:52.290029 2026] [security2:error] [pid 116718:tid 116891] [client 136.158.60.21:30454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS4wAAABs"]
[Mon Jul 20 07:25:52.290117 2026] [security2:error] [pid 116718:tid 116891] [client 136.158.60.21:30454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS4wAAABs"]
[Mon Jul 20 07:25:52.398177 2026] [security2:error] [pid 116718:tid 116888] [client 13.233.207.33:12288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS9wAAABg"]
[Mon Jul 20 07:25:52.535222 2026] [security2:error] [pid 116718:tid 116967] [client 103.176.215.66:60017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h4JPWlhYV5NwZ9vVTAQAAAGc"]
[Mon Jul 20 07:25:52.535684 2026] [security2:error] [pid 116718:tid 116967] [client 103.176.215.66:60017] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h4JPWlhYV5NwZ9vVTAQAAAGc"]
[Mon Jul 20 07:25:52.639051 2026] [security2:error] [pid 116718:tid 116922] [client 13.233.207.33:12302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4h4JPWlhYV5NwZ9vVTBgAAADo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:25:52.729168 2026] [security2:error] [pid 116718:tid 116822] [remote 103.187.169.251:36578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4h4JPWlhYV5NwZ9vVTEQAAb1c"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 07:25:53.046779 2026] [security2:error] [pid 116718:tid 116989] [client 82.102.18.116:40222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp-includes/wlwmanifest.xml"] [unique_id "al4h4ZPWlhYV5NwZ9vVTMAAAAH0"]
[Mon Jul 20 07:25:53.276739 2026] [security2:error] [pid 116718:tid 116812] [remote 47.86.33.52:44668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTQQAASk0"]
[Mon Jul 20 07:25:53.611379 2026] [security2:error] [pid 116718:tid 116746] [remote 103.235.199.20:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.199.235.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTWgAALQs"]
[Mon Jul 20 07:25:53.644364 2026] [security2:error] [pid 116718:tid 116968] [client 43.205.139.3:51954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTYQAAAGg"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:25:53.746059 2026] [security2:error] [pid 116718:tid 116936] [client 82.102.18.116:47571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/xmlrpc.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTbgAAAEg"]
[Mon Jul 20 07:25:53.766293 2026] [security2:error] [pid 116718:tid 116900] [client 103.106.165.44:57990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTcQAAACQ"]
[Mon Jul 20 07:25:53.766454 2026] [security2:error] [pid 116718:tid 116900] [client 103.106.165.44:57990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTcQAAACQ"]
[Mon Jul 20 07:25:53.852766 2026] [security2:error] [pid 116718:tid 116784] [remote 47.86.33.52:44668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTeQAASjE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:25:53.980250 2026] [security2:error] [pid 116718:tid 116948] [client 201.27.111.74:61600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTiQAAAFQ"]
[Mon Jul 20 07:25:53.985185 2026] [security2:error] [pid 116718:tid 116948] [client 201.27.111.74:61600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTiQAAAFQ"]
[Mon Jul 20 07:25:54.022178 2026] [security2:error] [pid 116718:tid 116878] [client 116.179.32.30:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTfQAAAA4"]
[Mon Jul 20 07:25:54.145214 2026] [security2:error] [pid 116718:tid 116735] [remote 103.235.199.20:57428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.199.235.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4h4pPWlhYV5NwZ9vVTkQAAIAA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:25:54.364387 2026] [autoindex:error] [pid 116718:tid 116849] [remote 8.229.41.77:64297] AH01276: Cannot serve directory /home2/skujivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.sku.jiv.mybluehost.me
[Mon Jul 20 07:25:54.406556 2026] [security2:error] [pid 116718:tid 116889] [client 57.141.18.45:56028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSVAAAGXQ"]
[Mon Jul 20 07:25:54.477883 2026] [security2:error] [pid 116718:tid 116896] [client 167.99.161.127:58798] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.maplerespiteservices.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4h4pPWlhYV5NwZ9vVTtAAAACA"]
[Mon Jul 20 07:25:54.582828 2026] [security2:error] [pid 116718:tid 116961] [client 77.110.127.138:49167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h4pPWlhYV5NwZ9vVTwQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:54.582919 2026] [security2:error] [pid 116718:tid 116961] [client 77.110.127.138:49167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h4pPWlhYV5NwZ9vVTwQAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:54.756035 2026] [security2:error] [pid 116718:tid 116879] [client 57.141.18.52:60882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h3pPWlhYV5NwZ9vVSdgAADzg"]
[Mon Jul 20 07:25:54.959687 2026] [security2:error] [pid 116718:tid 116896] [client 77.110.127.138:49153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h4pPWlhYV5NwZ9vVT5QAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:54.959803 2026] [security2:error] [pid 116718:tid 116896] [client 77.110.127.138:49153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h4pPWlhYV5NwZ9vVT5QAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:55.114605 2026] [security2:error] [pid 116718:tid 116916] [client 57.141.18.51:24422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h35PWlhYV5NwZ9vVSlQAANHU"]
[Mon Jul 20 07:25:55.134138 2026] [security2:error] [pid 116718:tid 116985] [client 191.202.66.27:54874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h45PWlhYV5NwZ9vVT9AAAAHk"]
[Mon Jul 20 07:25:55.134313 2026] [security2:error] [pid 116718:tid 116985] [client 191.202.66.27:54874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h45PWlhYV5NwZ9vVT9AAAAHk"]
[Mon Jul 20 07:25:55.158643 2026] [security2:error] [pid 116718:tid 116892] [client 82.102.18.116:40252] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4h45PWlhYV5NwZ9vVT9QAAABw"]
[Mon Jul 20 07:25:55.212864 2026] [security2:error] [pid 116718:tid 116918] [client 14.225.17.146:57871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4h45PWlhYV5NwZ9vVT7QAAADY"], referer: http://according2plant.com/test
[Mon Jul 20 07:25:55.342427 2026] [security2:error] [pid 116718:tid 116824] [remote 38.242.157.30:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4h45PWlhYV5NwZ9vVUBwAAZVk"]
[Mon Jul 20 07:25:55.371772 2026] [security2:error] [pid 116718:tid 116936] [client 88.241.67.160:55016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h45PWlhYV5NwZ9vVUDAAAAEg"]
[Mon Jul 20 07:25:55.371889 2026] [security2:error] [pid 116718:tid 116936] [client 88.241.67.160:55016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h45PWlhYV5NwZ9vVUDAAAAEg"]
[Mon Jul 20 07:25:55.404140 2026] [security2:error] [pid 116718:tid 116954] [client 104.234.53.50:30439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4h45PWlhYV5NwZ9vVUEgAAAFo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:55.443553 2026] [security2:error] [pid 116718:tid 116902] [client 14.225.17.146:57892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4h45PWlhYV5NwZ9vVT8wAAACY"], referer: http://guidehunting.com/test
[Mon Jul 20 07:25:55.488512 2026] [security2:error] [pid 116718:tid 116911] [client 14.225.17.146:57888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4h45PWlhYV5NwZ9vVT8AAAAC8"], referer: http://mollycahill.com/test
[Mon Jul 20 07:25:55.535145 2026] [security2:error] [pid 116718:tid 116987] [client 57.141.18.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4h45PWlhYV5NwZ9vVUDwAAAHs"]
[Mon Jul 20 07:25:55.565498 2026] [security2:error] [pid 116718:tid 116739] [remote 38.242.157.30:56314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4h45PWlhYV5NwZ9vVUHQAAMgQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:25:56.009864 2026] [security2:error] [pid 116718:tid 116936] [client 179.127.84.238:56213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUSAAAAEg"]
[Mon Jul 20 07:25:56.009977 2026] [security2:error] [pid 116718:tid 116936] [client 179.127.84.238:56213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUSAAAAEg"]
[Mon Jul 20 07:25:56.063837 2026] [security2:error] [pid 116718:tid 116922] [client 82.102.18.116:40264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/web/wp-includes/wlwmanifest.xml"] [unique_id "al4h5JPWlhYV5NwZ9vVUTQAAADo"]
[Mon Jul 20 07:25:56.257175 2026] [security2:error] [pid 116718:tid 116937] [client 157.20.138.62:56063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUVwAAAEk"]
[Mon Jul 20 07:25:56.257285 2026] [security2:error] [pid 116718:tid 116937] [client 157.20.138.62:56063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUVwAAAEk"]
[Mon Jul 20 07:25:56.296934 2026] [security2:error] [pid 116718:tid 116840] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUYAAAImk"]
[Mon Jul 20 07:25:56.297155 2026] [security2:error] [pid 116718:tid 116898] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUYAAAImk"]
[Mon Jul 20 07:25:56.396716 2026] [security2:error] [pid 116718:tid 116877] [client 57.141.18.85:26290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h4JPWlhYV5NwZ9vVS-AAADVo"]
[Mon Jul 20 07:25:56.536782 2026] [security2:error] [pid 116718:tid 116949] [client 14.225.17.146:51302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUWAAAAFU"], referer: https://guidehunting.com/test
[Mon Jul 20 07:25:56.637671 2026] [security2:error] [pid 116718:tid 116947] [client 14.225.17.146:57910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4h45PWlhYV5NwZ9vVT8QAAAFM"], referer: http://xp-design.co/test
[Mon Jul 20 07:25:56.736615 2026] [security2:error] [pid 116718:tid 116936] [client 82.102.18.116:40272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/website/wp-includes/wlwmanifest.xml"] [unique_id "al4h5JPWlhYV5NwZ9vVUjwAAAEg"]
[Mon Jul 20 07:25:56.857778 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:49177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUnwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:56.857886 2026] [security2:error] [pid 116718:tid 116865] [client 77.110.127.138:49177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUnwAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:56.869060 2026] [security2:error] [pid 116718:tid 116945] [client 143.44.185.218:48411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUoQAAAFE"]
[Mon Jul 20 07:25:56.869158 2026] [security2:error] [pid 116718:tid 116945] [client 143.44.185.218:48411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUoQAAAFE"]
[Mon Jul 20 07:25:56.938608 2026] [security2:error] [pid 116718:tid 116921] [client 14.225.17.146:56090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUngAAADk"]
[Mon Jul 20 07:25:56.943318 2026] [security2:error] [pid 116718:tid 116918] [client 43.155.125.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "timespans.org"] [uri "/index.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUmgAAADY"]
[Mon Jul 20 07:25:56.986301 2026] [security2:error] [pid 116718:tid 116903] [client 154.192.123.127:17717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUrwAAACc"]
[Mon Jul 20 07:25:56.986459 2026] [security2:error] [pid 116718:tid 116903] [client 154.192.123.127:17717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUrwAAACc"]
[Mon Jul 20 07:25:56.994342 2026] [security2:error] [pid 116718:tid 116765] [remote 47.86.33.52:44666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUrQAAER4"]
[Mon Jul 20 07:25:57.007725 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:49178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h5ZPWlhYV5NwZ9vVUswAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:57.007816 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:49178] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h5ZPWlhYV5NwZ9vVUswAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:25:57.245154 2026] [security2:error] [pid 116718:tid 116966] [client 57.141.18.7:29822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h4ZPWlhYV5NwZ9vVTTAAAZnk"]
[Mon Jul 20 07:25:57.390822 2026] [security2:error] [pid 116718:tid 116907] [client 82.102.18.116:40282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/news/wp-includes/wlwmanifest.xml"] [unique_id "al4h5ZPWlhYV5NwZ9vVU5QAAACs"]
[Mon Jul 20 07:25:57.443467 2026] [security2:error] [pid 116718:tid 116897] [client 14.225.17.146:62784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4h5ZPWlhYV5NwZ9vVU0gAAACE"], referer: http://aandarealtygroup.com/test
[Mon Jul 20 07:25:57.724160 2026] [security2:error] [pid 116718:tid 116895] [client 57.141.18.120:38246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h4pPWlhYV5NwZ9vVTkwAAH0s"]
[Mon Jul 20 07:25:57.934955 2026] [security2:error] [pid 116718:tid 116778] [remote 20.153.140.50:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4h5ZPWlhYV5NwZ9vVVBwAAJis"]
[Mon Jul 20 07:25:58.061413 2026] [security2:error] [pid 116718:tid 116918] [client 82.102.18.116:5050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4h5pPWlhYV5NwZ9vVVHAAAADY"]
[Mon Jul 20 07:25:58.130351 2026] [security2:error] [pid 116718:tid 116959] [client 117.211.236.168:51090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4h5pPWlhYV5NwZ9vVVIgAAAF8"]
[Mon Jul 20 07:25:58.130531 2026] [security2:error] [pid 116718:tid 116959] [client 117.211.236.168:51090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4h5pPWlhYV5NwZ9vVVIgAAAF8"]
[Mon Jul 20 07:25:58.352118 2026] [security2:error] [pid 116718:tid 116742] [remote 20.153.140.50:52062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4h5pPWlhYV5NwZ9vVVMwAALQc"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 07:25:58.679880 2026] [security2:error] [pid 116718:tid 116902] [client 82.102.18.116:58272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4h5pPWlhYV5NwZ9vVVTgAAACY"]
[Mon Jul 20 07:25:58.827689 2026] [core:error] [pid 116718:tid 116977] [client 14.225.17.146:56398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/test
[Mon Jul 20 07:25:58.827708 2026] [core:error] [pid 116718:tid 116977] [client 14.225.17.146:56398] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/test
[Mon Jul 20 07:25:58.912166 2026] [security2:error] [pid 116718:tid 116896] [client 104.234.53.92:37607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4h5pPWlhYV5NwZ9vVVWwAAACA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:25:58.939443 2026] [security2:error] [pid 116718:tid 116910] [client 14.225.17.146:56290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4h5pPWlhYV5NwZ9vVVSgAAAC4"], referer: http://webgardensbypaula.com/test
[Mon Jul 20 07:25:58.980646 2026] [proxy:error] [pid 116718:tid 116911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:58.980681 2026] [proxy_http:error] [pid 116718:tid 116911] [client 87.236.176.110:37053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:58.981145 2026] [proxy:error] [pid 116718:tid 116911] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:25:58.981168 2026] [proxy_http:error] [pid 116718:tid 116911] [client 87.236.176.110:37053] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:25:59.210776 2026] [security2:error] [pid 116718:tid 116861] [remote 162.19.86.63:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4h55PWlhYV5NwZ9vVVdwAAD34"]
[Mon Jul 20 07:25:59.340081 2026] [security2:error] [pid 116718:tid 116962] [client 82.102.18.116:58288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4h55PWlhYV5NwZ9vVVfQAAAGI"]
[Mon Jul 20 07:25:59.443257 2026] [security2:error] [pid 116718:tid 116827] [remote 162.19.86.63:46610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4h55PWlhYV5NwZ9vVVhgAAT1w"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 07:25:59.961113 2026] [security2:error] [pid 116718:tid 116921] [client 82.102.18.116:58294] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/media/wp-includes/wlwmanifest.xml"] [unique_id "al4h55PWlhYV5NwZ9vVVqQAAADk"]
[Mon Jul 20 07:26:00.031587 2026] [security2:error] [pid 116718:tid 116868] [client 104.234.53.51:32989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4h6JPWlhYV5NwZ9vVVsAAAAAQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:00.281188 2026] [security2:error] [pid 116718:tid 116789] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h6JPWlhYV5NwZ9vVVvwAATjY"]
[Mon Jul 20 07:26:00.281303 2026] [security2:error] [pid 116718:tid 116942] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h6JPWlhYV5NwZ9vVVvwAATjY"]
[Mon Jul 20 07:26:00.322252 2026] [security2:error] [pid 116718:tid 116867] [client 57.141.18.20:41522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUkgAAAxc"]
[Mon Jul 20 07:26:00.438576 2026] [security2:error] [pid 116718:tid 116898] [client 77.110.127.138:49186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h6JPWlhYV5NwZ9vVVyQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:00.438675 2026] [security2:error] [pid 116718:tid 116898] [client 77.110.127.138:49186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h6JPWlhYV5NwZ9vVVyQAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:00.451250 2026] [security2:error] [pid 116718:tid 116956] [client 57.141.18.66:38146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h5JPWlhYV5NwZ9vVUqwAAXEA"]
[Mon Jul 20 07:26:00.591050 2026] [security2:error] [pid 116718:tid 116971] [client 82.102.18.116:58302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4h6JPWlhYV5NwZ9vVV2AAAAGs"]
[Mon Jul 20 07:26:00.612437 2026] [security2:error] [pid 116718:tid 116954] [client 77.110.127.138:49194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h6JPWlhYV5NwZ9vVV2gAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:00.612514 2026] [security2:error] [pid 116718:tid 116954] [client 77.110.127.138:49194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h6JPWlhYV5NwZ9vVV2gAAAFo"], referer: https://mezzacraft.com/
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 07:26:01.239673 2026] [security2:error] [pid 116718:tid 116877] [client 77.110.127.138:49196] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 316 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h6ZPWlhYV5NwZ9vVWGQAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:01.254082 2026] [security2:error] [pid 116718:tid 116898] [client 82.102.18.116:58310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4h6ZPWlhYV5NwZ9vVWHQAAACI"]
[Mon Jul 20 07:26:01.315879 2026] [security2:error] [pid 116718:tid 116779] [remote 216.73.216.55:20760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4h6ZPWlhYV5NwZ9vVWHgAAGyw"]
[Mon Jul 20 07:26:01.507090 2026] [security2:error] [pid 116718:tid 116899] [client 49.47.218.174:55445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWJQAAACM"]
[Mon Jul 20 07:26:01.507232 2026] [security2:error] [pid 116718:tid 116899] [client 49.47.218.174:55445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWJQAAACM"]
[Mon Jul 20 07:26:01.544913 2026] [security2:error] [pid 116718:tid 116866] [client 185.93.182.171:42736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.182.93.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWKwAAAAI"]
[Mon Jul 20 07:26:01.545023 2026] [security2:error] [pid 116718:tid 116866] [client 185.93.182.171:42736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWKwAAAAI"]
[Mon Jul 20 07:26:01.750524 2026] [security2:error] [pid 116718:tid 116973] [client 57.141.18.5:29276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h5pPWlhYV5NwZ9vVVDwAAbU8"]
[Mon Jul 20 07:26:01.936899 2026] [security2:error] [pid 116718:tid 116963] [client 82.102.18.116:58322] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "autodiscover.msd.mqz.mybluehost.me"] [uri "/autodiscover/autodiscover.xml/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4h6ZPWlhYV5NwZ9vVWRgAAAGM"]
[Mon Jul 20 07:26:01.942195 2026] [security2:error] [pid 116718:tid 116985] [client 14.225.17.146:59252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWKAAAAHk"], referer: http://overloadcomedy.com/test
[Mon Jul 20 07:26:02.121159 2026] [security2:error] [pid 116718:tid 116969] [client 154.208.48.130:58171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWWwAAAGk"]
[Mon Jul 20 07:26:02.121331 2026] [security2:error] [pid 116718:tid 116969] [client 154.208.48.130:58171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWWwAAAGk"]
[Mon Jul 20 07:26:02.414840 2026] [security2:error] [pid 116718:tid 116937] [client 14.225.17.146:60948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWSwAAAEk"]
[Mon Jul 20 07:26:02.577633 2026] [security2:error] [pid 116718:tid 116745] [remote 102.134.101.35:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWeQAACQo"]
[Mon Jul 20 07:26:02.736953 2026] [security2:error] [pid 116718:tid 116985] [client 36.93.152.155:51422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWiwAAAHk"]
[Mon Jul 20 07:26:02.737087 2026] [security2:error] [pid 116718:tid 116985] [client 36.93.152.155:51422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWiwAAAHk"]
[Mon Jul 20 07:26:02.976621 2026] [security2:error] [pid 116718:tid 116919] [client 136.158.60.21:31968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWpwAAADc"]
[Mon Jul 20 07:26:02.976731 2026] [security2:error] [pid 116718:tid 116919] [client 136.158.60.21:31968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWpwAAADc"]
[Mon Jul 20 07:26:03.041563 2026] [security2:error] [pid 116718:tid 116970] [client 103.176.215.66:60554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h65PWlhYV5NwZ9vVWqwAAAGo"]
[Mon Jul 20 07:26:03.041835 2026] [security2:error] [pid 116718:tid 116970] [client 103.176.215.66:60554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h65PWlhYV5NwZ9vVWqwAAAGo"]
[Mon Jul 20 07:26:03.050728 2026] [security2:error] [pid 116718:tid 116910] [client 50.116.65.227:11336] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4h65PWlhYV5NwZ9vVWrAAAAC4"]
[Mon Jul 20 07:26:03.063902 2026] [security2:error] [pid 116718:tid 116921] [client 50.116.65.227:11344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4h65PWlhYV5NwZ9vVWrgAAADk"]
[Mon Jul 20 07:26:03.220478 2026] [security2:error] [pid 116718:tid 116912] [client 77.110.127.138:49185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h65PWlhYV5NwZ9vVWtQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:03.220567 2026] [security2:error] [pid 116718:tid 116912] [client 77.110.127.138:49185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h65PWlhYV5NwZ9vVWtQAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:03.280597 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:49161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h65PWlhYV5NwZ9vVWwwAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:03.280715 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:49161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h65PWlhYV5NwZ9vVWwwAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:03.450963 2026] [security2:error] [pid 116718:tid 116890] [client 57.141.18.115:22886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h55PWlhYV5NwZ9vVVigAAGk4"]
[Mon Jul 20 07:26:03.472288 2026] [core:error] [pid 116718:tid 116896] [client 14.225.17.146:63065] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:03.472307 2026] [core:error] [pid 116718:tid 116896] [client 14.225.17.146:63065] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:03.488460 2026] [security2:error] [pid 116718:tid 116818] [remote 102.134.101.35:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.101.134.102.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4h65PWlhYV5NwZ9vVW2AAAA1M"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:26:03.521694 2026] [security2:error] [pid 116718:tid 116754] [remote 152.228.213.32:38150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h65PWlhYV5NwZ9vVW2gAALBM"]
[Mon Jul 20 07:26:03.611987 2026] [security2:error] [pid 116718:tid 116892] [client 50.116.65.227:11372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4h65PWlhYV5NwZ9vVW1gAAABw"]
[Mon Jul 20 07:26:03.703263 2026] [security2:error] [pid 116718:tid 116750] [remote 152.228.213.32:38150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h65PWlhYV5NwZ9vVW5QAAAA8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:26:03.805230 2026] [security2:error] [pid 116718:tid 116976] [client 50.116.65.227:11378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4h65PWlhYV5NwZ9vVW3gAAAHA"]
[Mon Jul 20 07:26:03.875292 2026] [security2:error] [pid 116718:tid 116763] [remote 124.55.178.99:60074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h65PWlhYV5NwZ9vVW_QAAehw"]
[Mon Jul 20 07:26:03.986136 2026] [security2:error] [pid 116718:tid 116982] [client 14.225.17.146:59714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4h65PWlhYV5NwZ9vVW-gAAAHY"], referer: http://christiancountytrumpet.com/test
[Mon Jul 20 07:26:04.191486 2026] [security2:error] [pid 116718:tid 116892] [client 77.110.127.138:49201] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 731 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h7JPWlhYV5NwZ9vVXDgAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:04.260258 2026] [security2:error] [pid 116718:tid 116940] [client 57.141.18.88:23974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h6JPWlhYV5NwZ9vVV0AAATG8"]
[Mon Jul 20 07:26:04.412555 2026] [security2:error] [pid 116718:tid 116977] [client 201.27.111.74:62093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXKgAAAHE"]
[Mon Jul 20 07:26:04.412692 2026] [security2:error] [pid 116718:tid 116977] [client 201.27.111.74:62093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXKgAAAHE"]
[Mon Jul 20 07:26:04.453926 2026] [security2:error] [pid 116718:tid 116815] [remote 124.55.178.99:60074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXLAAAL1A"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:26:04.470279 2026] [security2:error] [pid 116718:tid 116933] [client 57.141.18.74:48550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h6JPWlhYV5NwZ9vVVwQAARWI"]
[Mon Jul 20 07:26:04.528869 2026] [security2:error] [pid 116718:tid 116937] [client 14.225.17.146:59602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXBQAAAEk"], referer: http://onewingpictures.com/test
[Mon Jul 20 07:26:04.603157 2026] [security2:error] [pid 116718:tid 116883] [client 103.106.165.44:58469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXPQAAABM"]
[Mon Jul 20 07:26:04.603272 2026] [security2:error] [pid 116718:tid 116883] [client 103.106.165.44:58469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXPQAAABM"]
[Mon Jul 20 07:26:04.675467 2026] [security2:error] [pid 116718:tid 116751] [remote 209.42.18.223:34378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXRgAAHRA"]
[Mon Jul 20 07:26:04.852633 2026] [security2:error] [pid 116718:tid 116973] [client 98.159.234.160:34299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXVwAAAG0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:26:04.890270 2026] [security2:error] [pid 116718:tid 116774] [remote 209.42.18.223:34378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXWgAAeyc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:05.234257 2026] [security2:error] [pid 116718:tid 116914] [client 57.141.18.121:54248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h6ZPWlhYV5NwZ9vVWJgAAMjE"]
[Mon Jul 20 07:26:05.674219 2026] [security2:error] [pid 116718:tid 116889] [client 77.110.127.138:49197] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXmQAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:05.674308 2026] [security2:error] [pid 116718:tid 116889] [client 77.110.127.138:49197] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXmQAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:05.724679 2026] [security2:error] [pid 116718:tid 116867] [client 77.110.127.138:49198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXmgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:05.724815 2026] [security2:error] [pid 116718:tid 116867] [client 77.110.127.138:49198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXmgAAAAM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:05.757928 2026] [security2:error] [pid 116718:tid 116956] [client 191.202.66.27:55359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXngAAAFw"]
[Mon Jul 20 07:26:05.758061 2026] [security2:error] [pid 116718:tid 116956] [client 191.202.66.27:55359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXngAAAFw"]
[Mon Jul 20 07:26:05.844353 2026] [security2:error] [pid 116718:tid 116931] [client 77.110.127.138:49207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXpQAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:05.844443 2026] [security2:error] [pid 116718:tid 116931] [client 77.110.127.138:49207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXpQAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:05.952419 2026] [security2:error] [pid 116718:tid 116891] [client 88.241.67.160:56493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXtAAAABs"]
[Mon Jul 20 07:26:05.952691 2026] [security2:error] [pid 116718:tid 116891] [client 88.241.67.160:56493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXtAAAABs"]
[Mon Jul 20 07:26:06.265174 2026] [security2:error] [pid 116718:tid 116965] [client 57.141.18.114:26908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWaAAAZWU"]
[Mon Jul 20 07:26:06.299555 2026] [security2:error] [pid 116718:tid 116875] [client 14.225.17.146:62701] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXRQAAAAs"], referer: http://myspineworld.com/test
[Mon Jul 20 07:26:06.473833 2026] [security2:error] [pid 116718:tid 116931] [client 77.110.127.138:49211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7pPWlhYV5NwZ9vVX1wAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:06.473967 2026] [security2:error] [pid 116718:tid 116931] [client 77.110.127.138:49211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h7pPWlhYV5NwZ9vVX1wAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:06.621560 2026] [security2:error] [pid 116718:tid 116948] [client 14.225.17.146:60810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4h7pPWlhYV5NwZ9vVXzAAAAFQ"], referer: http://talknutritionwithlesley.com/test
[Mon Jul 20 07:26:06.651616 2026] [security2:error] [pid 116718:tid 116989] [client 57.141.18.124:48056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWgQAAfQY"]
[Mon Jul 20 07:26:06.669605 2026] [fcgid:warn] [pid 116718:tid 116882] (70014)End of file found: [client 103.168.67.159:53912] mod_fcgid: can't get data from http client
[Mon Jul 20 07:26:06.686435 2026] [security2:error] [pid 116718:tid 116979] [client 179.127.84.238:56708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h7pPWlhYV5NwZ9vVX7AAAAHM"]
[Mon Jul 20 07:26:06.686588 2026] [security2:error] [pid 116718:tid 116979] [client 179.127.84.238:56708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h7pPWlhYV5NwZ9vVX7AAAAHM"]
[Mon Jul 20 07:26:06.953068 2026] [security2:error] [pid 116718:tid 116983] [client 57.141.18.30:58168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h6pPWlhYV5NwZ9vVWmQAAdxU"]
[Mon Jul 20 07:26:07.016696 2026] [security2:error] [pid 116718:tid 116739] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h75PWlhYV5NwZ9vVYBwAABgQ"]
[Mon Jul 20 07:26:07.016864 2026] [security2:error] [pid 116718:tid 116870] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h75PWlhYV5NwZ9vVYBwAABgQ"]
[Mon Jul 20 07:26:07.028563 2026] [security2:error] [pid 116718:tid 116908] [client 104.234.53.94:36207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4h75PWlhYV5NwZ9vVYCgAAACw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:07.067968 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:49164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h75PWlhYV5NwZ9vVYCwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:07.068068 2026] [security2:error] [pid 116718:tid 116948] [client 77.110.127.138:49164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h75PWlhYV5NwZ9vVYCwAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:07.093963 2026] [security2:error] [pid 116718:tid 116977] [client 14.225.17.146:63234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4h75PWlhYV5NwZ9vVYBAAAAHE"], referer: http://friendlyspreadsheet.com/test
[Mon Jul 20 07:26:07.115363 2026] [security2:error] [pid 116718:tid 116968] [client 157.20.138.62:56636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h75PWlhYV5NwZ9vVYEAAAAGg"]
[Mon Jul 20 07:26:07.115500 2026] [security2:error] [pid 116718:tid 116968] [client 157.20.138.62:56636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h75PWlhYV5NwZ9vVYEAAAAGg"]
[Mon Jul 20 07:26:07.268273 2026] [security2:error] [pid 116718:tid 116932] [client 14.225.17.146:59602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4h75PWlhYV5NwZ9vVYEQAAAEQ"], referer: https://myspineworld.com/test
[Mon Jul 20 07:26:07.485857 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:49195] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 262 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h75PWlhYV5NwZ9vVYKwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:07.534170 2026] [security2:error] [pid 116718:tid 116923] [client 77.110.127.138:49196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h75PWlhYV5NwZ9vVYNAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:07.534284 2026] [security2:error] [pid 116718:tid 116923] [client 77.110.127.138:49196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h75PWlhYV5NwZ9vVYNAAAADs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:07.562381 2026] [security2:error] [pid 116718:tid 116868] [client 154.192.123.127:18198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h75PWlhYV5NwZ9vVYNQAAAAQ"]
[Mon Jul 20 07:26:07.562494 2026] [security2:error] [pid 116718:tid 116868] [client 154.192.123.127:18198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h75PWlhYV5NwZ9vVYNQAAAAQ"]
[Mon Jul 20 07:26:07.578639 2026] [security2:error] [pid 116718:tid 116750] [remote 160.187.68.132:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4h75PWlhYV5NwZ9vVYNgAAHQ8"]
[Mon Jul 20 07:26:07.694584 2026] [security2:error] [pid 116718:tid 116982] [client 77.110.127.138:49216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h75PWlhYV5NwZ9vVYPAAAAHY"]
[Mon Jul 20 07:26:07.695349 2026] [security2:error] [pid 116718:tid 116982] [client 77.110.127.138:49216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h75PWlhYV5NwZ9vVYPAAAAHY"]
[Mon Jul 20 07:26:07.925728 2026] [security2:error] [pid 116718:tid 116910] [client 57.141.18.116:36358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h65PWlhYV5NwZ9vVW_AAALjA"]
[Mon Jul 20 07:26:07.983301 2026] [security2:error] [pid 116718:tid 116945] [client 14.225.17.146:63256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4h75PWlhYV5NwZ9vVYUgAAAFE"], referer: https://friendlyspreadsheet.com/test
[Mon Jul 20 07:26:08.049361 2026] [security2:error] [pid 116718:tid 116820] [remote 160.187.68.132:43554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYWgAABFU"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 07:26:08.297347 2026] [security2:error] [pid 116718:tid 116937] [client 143.44.185.218:50092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYeQAAAEk"]
[Mon Jul 20 07:26:08.297452 2026] [security2:error] [pid 116718:tid 116937] [client 143.44.185.218:50092] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYeQAAAEk"]
[Mon Jul 20 07:26:08.370919 2026] [security2:error] [pid 116718:tid 116969] [client 77.110.127.138:49218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYfgAAAGk"]
[Mon Jul 20 07:26:08.371009 2026] [security2:error] [pid 116718:tid 116969] [client 77.110.127.138:49218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYfgAAAGk"]
[Mon Jul 20 07:26:08.703819 2026] [security2:error] [pid 116718:tid 116765] [remote 162.19.86.63:50446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYmAAATB4"]
[Mon Jul 20 07:26:08.705217 2026] [security2:error] [pid 116718:tid 116942] [client 14.225.17.146:62723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYXgAAAE4"]
[Mon Jul 20 07:26:08.782320 2026] [security2:error] [pid 116718:tid 116897] [client 57.141.18.56:25146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h7JPWlhYV5NwZ9vVXSQAAITw"]
[Mon Jul 20 07:26:08.787478 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:49219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYmgAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:08.787598 2026] [security2:error] [pid 116718:tid 116886] [client 77.110.127.138:49219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYmgAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:08.899021 2026] [security2:error] [pid 116718:tid 116774] [remote 162.19.86.63:50446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYpAAAWic"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:09.487009 2026] [security2:error] [pid 116718:tid 116961] [client 57.141.18.83:40912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h7ZPWlhYV5NwZ9vVXcwAAYRk"]
[Mon Jul 20 07:26:09.787713 2026] [security2:error] [pid 116718:tid 116957] [client 2a05:45c2:6100:c400:44b4:d5c7:9a94:31de:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4h8ZPWlhYV5NwZ9vVY2wAAXXo"], referer: https://www.aleishapenny.ca
[Mon Jul 20 07:26:10.154257 2026] [security2:error] [pid 116718:tid 116878] [client 117.211.236.168:51642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4h8pPWlhYV5NwZ9vVY-QAAAA4"]
[Mon Jul 20 07:26:10.154352 2026] [security2:error] [pid 116718:tid 116878] [client 117.211.236.168:51642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4h8pPWlhYV5NwZ9vVY-QAAAA4"]
[Mon Jul 20 07:26:10.369646 2026] [security2:error] [pid 116718:tid 116898] [client 14.225.17.146:63513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4h8ZPWlhYV5NwZ9vVYwwAAACI"], referer: http://entuvy.com/test
[Mon Jul 20 07:26:10.511810 2026] [security2:error] [pid 116718:tid 116958] [client 57.141.18.5:57162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h7pPWlhYV5NwZ9vVXvwAAXnU"]
[Mon Jul 20 07:26:10.645335 2026] [security2:error] [pid 116718:tid 116956] [client 14.225.17.146:63263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4h8pPWlhYV5NwZ9vVZCAAAAFw"], referer: http://swafforddetailing.com/test
[Mon Jul 20 07:26:10.645345 2026] [security2:error] [pid 116718:tid 116914] [client 57.141.18.55:36752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h7pPWlhYV5NwZ9vVXxgAAMjg"]
[Mon Jul 20 07:26:10.679248 2026] [security2:error] [pid 116718:tid 116834] [remote 5.161.225.162:47000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h8pPWlhYV5NwZ9vVZFgAAU2M"]
[Mon Jul 20 07:26:10.870545 2026] [security2:error] [pid 116718:tid 116756] [remote 5.161.225.162:47000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4h8pPWlhYV5NwZ9vVZIwAAHBU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:10.948308 2026] [security2:error] [pid 116718:tid 116831] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h8pPWlhYV5NwZ9vVZKwAAQ2A"]
[Mon Jul 20 07:26:10.948435 2026] [security2:error] [pid 116718:tid 116931] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h8pPWlhYV5NwZ9vVZKwAAQ2A"]
[Mon Jul 20 07:26:11.023760 2026] [security2:error] [pid 116718:tid 116739] [remote 81.173.115.7:52420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4h85PWlhYV5NwZ9vVZLgAAbQQ"]
[Mon Jul 20 07:26:11.024012 2026] [security2:error] [pid 116718:tid 116973] [client 81.173.115.7:52420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4h85PWlhYV5NwZ9vVZLgAAbQQ"]
[Mon Jul 20 07:26:11.024089 2026] [security2:error] [pid 116718:tid 116876] [client 77.110.127.138:49229] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:action"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h85PWlhYV5NwZ9vVZLwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:11.268507 2026] [security2:error] [pid 116718:tid 116968] [client 14.225.17.146:61652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4h8ZPWlhYV5NwZ9vVY3gAAAGg"], referer: http://maplerespiteservices.com/test
[Mon Jul 20 07:26:11.914134 2026] [security2:error] [pid 116718:tid 116884] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4h85PWlhYV5NwZ9vVZagAAABQ"]
[Mon Jul 20 07:26:12.002950 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:49220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZdgAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:12.003055 2026] [security2:error] [pid 116718:tid 116981] [client 77.110.127.138:49220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZdgAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:12.055390 2026] [security2:error] [pid 116718:tid 116957] [client 77.110.127.138:49223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZeAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:12.055538 2026] [security2:error] [pid 116718:tid 116957] [client 77.110.127.138:49223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZeAAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:12.093912 2026] [security2:error] [pid 116718:tid 116946] [client 49.47.218.174:55982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZgAAAAFI"]
[Mon Jul 20 07:26:12.094032 2026] [security2:error] [pid 116718:tid 116946] [client 49.47.218.174:55982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZgAAAAFI"]
[Mon Jul 20 07:26:12.204318 2026] [security2:error] [pid 116718:tid 116917] [client 14.225.17.146:60803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZhQAAADU"], referer: http://ravmike.com/test
[Mon Jul 20 07:26:12.223872 2026] [security2:error] [pid 116718:tid 116921] [client 14.225.17.146:63271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZhAAAADk"], referer: http://sarahholyfield.com/test
[Mon Jul 20 07:26:12.655492 2026] [security2:error] [pid 116718:tid 116950] [client 57.141.18.59:54132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h8JPWlhYV5NwZ9vVYewAAVhY"]
[Mon Jul 20 07:26:12.698856 2026] [security2:error] [pid 116718:tid 116970] [client 34.79.255.97:54437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.255.79.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "puk.jiv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZvQAAAGo"]
[Mon Jul 20 07:26:13.095999 2026] [security2:error] [pid 116718:tid 116971] [client 14.225.17.146:62700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVZ4QAAAGs"], referer: https://ravmike.com/test
[Mon Jul 20 07:26:13.198548 2026] [autoindex:error] [pid 116718:tid 116862] [remote 34.48.215.173:65525] AH01276: Cannot serve directory /home2/tsbjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.tsb.jiv.mybluehost.me
[Mon Jul 20 07:26:13.219631 2026] [security2:error] [pid 116718:tid 116911] [client 114.119.155.13:58923] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "latiendadejorge.com.gt"] [uri "/wp-content/uploads/2025/02/photoroom_20250723_71213-p.-m-300x300.png"] [unique_id "al4h9ZPWlhYV5NwZ9vVZ9AAAAC8"], referer: https://latiendadejorge.com.gt/product-category/vitaminas-y-salud/
[Mon Jul 20 07:26:13.229105 2026] [security2:error] [pid 116718:tid 116883] [client 36.93.152.155:51986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVZ8gAAABM"]
[Mon Jul 20 07:26:13.229232 2026] [security2:error] [pid 116718:tid 116883] [client 36.93.152.155:51986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVZ8gAAABM"]
[Mon Jul 20 07:26:13.329112 2026] [security2:error] [pid 116718:tid 116909] [client 34.79.255.97:54411] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4h9ZPWlhYV5NwZ9vVZ-QAAAC0"]
[Mon Jul 20 07:26:13.333621 2026] [security2:error] [pid 116718:tid 116908] [client 14.225.17.146:63204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVZ7wAAACw"], referer: http://slutilities.com/test
[Mon Jul 20 07:26:13.592283 2026] [security2:error] [pid 116718:tid 116943] [client 103.176.215.66:61089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVaFgAAAE8"]
[Mon Jul 20 07:26:13.592428 2026] [security2:error] [pid 116718:tid 116943] [client 103.176.215.66:61089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVaFgAAAE8"]
[Mon Jul 20 07:26:13.734450 2026] [security2:error] [pid 116718:tid 116933] [client 57.141.18.42:52714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h8ZPWlhYV5NwZ9vVYxQAARSA"]
[Mon Jul 20 07:26:13.760130 2026] [security2:error] [pid 116718:tid 116880] [client 136.158.60.21:33475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVaKgAAABA"]
[Mon Jul 20 07:26:13.760273 2026] [security2:error] [pid 116718:tid 116880] [client 136.158.60.21:33475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVaKgAAABA"]
[Mon Jul 20 07:26:13.863580 2026] [security2:error] [pid 116718:tid 116738] [remote 152.228.213.32:45192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVaLgAACgM"]
[Mon Jul 20 07:26:14.062214 2026] [security2:error] [pid 116718:tid 116777] [remote 152.228.213.32:45192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "supportinghands22.org"] [uri "/wp-login.php"] [unique_id "al4h9pPWlhYV5NwZ9vVaUQAAISo"], referer: https://supportinghands22.org/wp-login.php
[Mon Jul 20 07:26:14.291473 2026] [security2:error] [pid 116718:tid 116952] [client 34.79.255.97:50984] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4h9pPWlhYV5NwZ9vVaaQAAAFg"]
[Mon Jul 20 07:26:14.549917 2026] [security2:error] [pid 116718:tid 116902] [client 194.180.48.253:36624] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "alexsandbergmusic.com"] [uri "/"] [unique_id "al4h9pPWlhYV5NwZ9vVagQAAACY"]
[Mon Jul 20 07:26:14.761033 2026] [security2:error] [pid 116718:tid 116905] [client 77.110.127.138:49224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9pPWlhYV5NwZ9vValwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:14.761136 2026] [security2:error] [pid 116718:tid 116905] [client 77.110.127.138:49224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9pPWlhYV5NwZ9vValwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:14.798471 2026] [security2:error] [pid 116718:tid 116917] [client 103.106.165.44:58948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h9pPWlhYV5NwZ9vVanAAAADU"]
[Mon Jul 20 07:26:14.798619 2026] [security2:error] [pid 116718:tid 116917] [client 103.106.165.44:58948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h9pPWlhYV5NwZ9vVanAAAADU"]
[Mon Jul 20 07:26:14.812793 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:49237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9pPWlhYV5NwZ9vVangAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:14.812975 2026] [security2:error] [pid 116718:tid 116875] [client 77.110.127.138:49237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h9pPWlhYV5NwZ9vVangAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:14.872286 2026] [security2:error] [pid 116718:tid 116947] [client 201.27.111.74:62594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h9pPWlhYV5NwZ9vVapQAAAFM"]
[Mon Jul 20 07:26:14.872393 2026] [security2:error] [pid 116718:tid 116947] [client 201.27.111.74:62594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4h9pPWlhYV5NwZ9vVapQAAAFM"]
[Mon Jul 20 07:26:14.955178 2026] [security2:error] [pid 116718:tid 116935] [client 77.110.127.138:49238] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:action. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/users-mezza-onedrive-aa20riverhouse20hookers-parent2020child20taster-creature20bowls20full20pattern20us20newsletter20subs-pdf/"] [unique_id "al4h9pPWlhYV5NwZ9vVasgAAAEc"]
[Mon Jul 20 07:26:14.967195 2026] [security2:error] [pid 116718:tid 116950] [client 34.79.255.97:55444] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4h9pPWlhYV5NwZ9vVatQAAAFY"]
[Mon Jul 20 07:26:15.074807 2026] [security2:error] [pid 116718:tid 116984] [client 14.225.17.146:62307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4h9pPWlhYV5NwZ9vVanQAAAHg"], referer: http://tacticaltreeoperations.com/test
[Mon Jul 20 07:26:15.156252 2026] [security2:error] [pid 116718:tid 116925] [client 77.110.127.138:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVayQAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.156395 2026] [security2:error] [pid 116718:tid 116925] [client 77.110.127.138:49240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVayQAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.156798 2026] [fcgid:warn] [pid 116718:tid 116963] (70014)End of file found: [client 66.132.195.96:18992] mod_fcgid: can't get data from http client
[Mon Jul 20 07:26:15.207831 2026] [security2:error] [pid 116718:tid 116942] [client 77.110.127.138:49241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVa0gAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.208031 2026] [security2:error] [pid 116718:tid 116942] [client 77.110.127.138:49241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVa0gAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.259182 2026] [security2:error] [pid 116718:tid 116967] [client 77.110.127.138:49217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVa1gAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.259288 2026] [security2:error] [pid 116718:tid 116967] [client 77.110.127.138:49217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVa1gAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.288405 2026] [security2:error] [pid 116718:tid 116889] [client 14.225.17.146:62285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4h9pPWlhYV5NwZ9vVajwAAABk"], referer: http://alexsandbergmusic.com/test
[Mon Jul 20 07:26:15.389068 2026] [security2:error] [pid 116718:tid 116943] [client 50.116.65.227:55730] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4h95PWlhYV5NwZ9vVa3QAAAE8"]
[Mon Jul 20 07:26:15.401197 2026] [security2:error] [pid 116718:tid 116957] [client 50.116.65.227:55746] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4h95PWlhYV5NwZ9vVa3gAAAF0"]
[Mon Jul 20 07:26:15.410999 2026] [security2:error] [pid 116718:tid 116892] [client 77.110.127.138:49247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVa3wAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.411097 2026] [security2:error] [pid 116718:tid 116892] [client 77.110.127.138:49247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVa3wAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.536311 2026] [security2:error] [pid 116718:tid 116931] [client 34.79.255.97:65519] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4h95PWlhYV5NwZ9vVa5wAAAEM"]
[Mon Jul 20 07:26:15.614571 2026] [security2:error] [pid 116718:tid 116982] [client 66.249.70.4:54649] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.zonemist.com"] [uri "/robots.txt"] [unique_id "al4h95PWlhYV5NwZ9vVa7AAAAHY"]
[Mon Jul 20 07:26:15.657805 2026] [security2:error] [pid 116718:tid 116946] [client 154.208.48.130:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h95PWlhYV5NwZ9vVa7wAAAFI"]
[Mon Jul 20 07:26:15.657973 2026] [security2:error] [pid 116718:tid 116946] [client 154.208.48.130:58694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4h95PWlhYV5NwZ9vVa7wAAAFI"]
[Mon Jul 20 07:26:15.711417 2026] [security2:error] [pid 116718:tid 116873] [client 14.225.17.146:57617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4h95PWlhYV5NwZ9vVa5QAAAAk"], referer: http://fineartsfactory.net/test
[Mon Jul 20 07:26:15.816618 2026] [security2:error] [pid 116718:tid 116912] [client 66.249.70.3:59278] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.zonemist.com"] [uri "/wp-content/uploads/2021/04/Group-626.png"] [unique_id "al4h95PWlhYV5NwZ9vVbBwAAADA"]
[Mon Jul 20 07:26:15.867639 2026] [security2:error] [pid 116718:tid 116897] [client 77.110.127.138:49244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVbCwAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.867728 2026] [security2:error] [pid 116718:tid 116897] [client 77.110.127.138:49244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h95PWlhYV5NwZ9vVbCwAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:15.871102 2026] [security2:error] [pid 116718:tid 116878] [client 82.205.57.84:51060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4h9pPWlhYV5NwZ9vVahAAAAA4"]
[Mon Jul 20 07:26:16.022102 2026] [security2:error] [pid 116718:tid 116950] [client 77.110.127.138:49250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbEgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:16.022192 2026] [security2:error] [pid 116718:tid 116950] [client 77.110.127.138:49250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbEgAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:16.185674 2026] [security2:error] [pid 116718:tid 116991] [client 34.79.255.97:53075] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4h-JPWlhYV5NwZ9vVbIwAAAH8"]
[Mon Jul 20 07:26:16.262925 2026] [security2:error] [pid 116718:tid 116899] [client 121.229.156.113:53926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.danwolfe.us"] [uri "/"] [unique_id "al4h-JPWlhYV5NwZ9vVbLAAAACM"]
[Mon Jul 20 07:26:16.263032 2026] [security2:error] [pid 116718:tid 116899] [client 121.229.156.113:53926] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "blog.danwolfe.us"] [uri "/"] [unique_id "al4h-JPWlhYV5NwZ9vVbLAAAACM"]
[Mon Jul 20 07:26:16.389504 2026] [security2:error] [pid 116718:tid 116957] [client 191.202.66.27:55847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbOgAAAF0"]
[Mon Jul 20 07:26:16.389618 2026] [security2:error] [pid 116718:tid 116957] [client 191.202.66.27:55847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbOgAAAF0"]
[Mon Jul 20 07:26:16.629515 2026] [security2:error] [pid 116718:tid 116864] [client 88.241.67.160:56388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbTwAAAAA"]
[Mon Jul 20 07:26:16.630147 2026] [security2:error] [pid 116718:tid 116864] [client 88.241.67.160:56388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbTwAAAAA"]
[Mon Jul 20 07:26:16.758568 2026] [security2:error] [pid 116718:tid 116988] [client 34.79.255.97:52272] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4h-JPWlhYV5NwZ9vVbVwAAAHw"]
[Mon Jul 20 07:26:16.817445 2026] [security2:error] [pid 116718:tid 116967] [client 66.249.70.2:43041] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.zonemist.com"] [uri "/wp-content/uploads/2021/04/Group-626.png"] [unique_id "al4h-JPWlhYV5NwZ9vVbXgAAAGc"]
[Mon Jul 20 07:26:16.851920 2026] [security2:error] [pid 116718:tid 116900] [client 57.141.18.49:51538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h9JPWlhYV5NwZ9vVZmAAAJD8"]
[Mon Jul 20 07:26:17.303786 2026] [security2:error] [pid 116718:tid 116988] [client 77.110.127.138:49253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbgwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:17.303886 2026] [security2:error] [pid 116718:tid 116988] [client 77.110.127.138:49253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbgwAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:17.316620 2026] [security2:error] [pid 116718:tid 116898] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbdQAAACI"]
[Mon Jul 20 07:26:17.359794 2026] [security2:error] [pid 116718:tid 116968] [client 179.127.84.238:57203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbhwAAAGg"]
[Mon Jul 20 07:26:17.359899 2026] [security2:error] [pid 116718:tid 116968] [client 179.127.84.238:57203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbhwAAAGg"]
[Mon Jul 20 07:26:17.360506 2026] [security2:error] [pid 116718:tid 116867] [client 34.79.255.97:50694] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4h-ZPWlhYV5NwZ9vVbiAAAAAM"]
[Mon Jul 20 07:26:17.430226 2026] [security2:error] [pid 116718:tid 116932] [client 14.225.17.146:50493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4h95PWlhYV5NwZ9vVa2wAAAEQ"], referer: http://idigress.studio/test
[Mon Jul 20 07:26:17.652169 2026] [security2:error] [pid 116718:tid 116811] [remote 47.86.33.52:24464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbnQAAd0w"], referer: https://str.cly.mybluehost.me/wp-login.php
[Mon Jul 20 07:26:17.697157 2026] [security2:error] [pid 116718:tid 116860] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbpQAAB30"]
[Mon Jul 20 07:26:17.697329 2026] [security2:error] [pid 116718:tid 116871] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbpQAAB30"]
[Mon Jul 20 07:26:17.952736 2026] [security2:error] [pid 116718:tid 116923] [client 34.79.255.97:51088] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4h-ZPWlhYV5NwZ9vVbtwAAADs"]
[Mon Jul 20 07:26:18.076408 2026] [security2:error] [pid 116718:tid 116969] [client 157.20.138.62:57207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h-pPWlhYV5NwZ9vVbxQAAAGk"]
[Mon Jul 20 07:26:18.076621 2026] [security2:error] [pid 116718:tid 116969] [client 157.20.138.62:57207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4h-pPWlhYV5NwZ9vVbxQAAAGk"]
[Mon Jul 20 07:26:18.128668 2026] [security2:error] [pid 116718:tid 116912] [client 154.192.123.127:18706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h-pPWlhYV5NwZ9vVbzQAAADA"]
[Mon Jul 20 07:26:18.128826 2026] [security2:error] [pid 116718:tid 116912] [client 154.192.123.127:18706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4h-pPWlhYV5NwZ9vVbzQAAADA"]
[Mon Jul 20 07:26:18.171150 2026] [security2:error] [pid 116718:tid 116929] [client 14.225.17.146:50450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4h-pPWlhYV5NwZ9vVbxgAAAEE"], referer: http://collectingrealestate.com/test
[Mon Jul 20 07:26:18.243324 2026] [security2:error] [pid 116718:tid 116903] [client 14.225.17.146:61958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbmAAAACc"], referer: http://drewsasburyparkbeachhouse.com/test
[Mon Jul 20 07:26:18.270287 2026] [security2:error] [pid 116718:tid 116989] [client 45.157.112.60:62621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4h-pPWlhYV5NwZ9vVb2AAAAH0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:26:18.282985 2026] [core:error] [pid 116718:tid 116897] [client 14.225.17.146:51144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:18.283005 2026] [core:error] [pid 116718:tid 116897] [client 14.225.17.146:51144] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:18.548114 2026] [security2:error] [pid 116718:tid 116900] [client 34.79.255.97:59431] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4h-pPWlhYV5NwZ9vVb8wAAACQ"]
[Mon Jul 20 07:26:18.774627 2026] [security2:error] [pid 116718:tid 116914] [client 57.141.18.6:52180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h9ZPWlhYV5NwZ9vVaNwAAMgo"]
[Mon Jul 20 07:26:18.797755 2026] [security2:error] [pid 116718:tid 116871] [client 14.225.17.146:64710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4h-pPWlhYV5NwZ9vVcAQAAAAc"], referer: http://39ishlife.com/test
[Mon Jul 20 07:26:19.040732 2026] [security2:error] [pid 116718:tid 116904] [client 57.141.18.12:22854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h9pPWlhYV5NwZ9vVaUgAAKCk"]
[Mon Jul 20 07:26:19.098848 2026] [security2:error] [pid 116718:tid 116879] [client 34.79.255.97:59053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4h-5PWlhYV5NwZ9vVcJgAAAA8"]
[Mon Jul 20 07:26:19.223903 2026] [security2:error] [pid 116718:tid 116757] [remote 15.206.251.117:37292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcNAAAMRY"]
[Mon Jul 20 07:26:19.443279 2026] [security2:error] [pid 116718:tid 116963] [client 23.180.120.148:38130] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "jqq.cyv.mybluehost.me"] [uri "/"] [unique_id "al4h-5PWlhYV5NwZ9vVcTwAAAGM"]
[Mon Jul 20 07:26:19.564039 2026] [security2:error] [pid 116718:tid 116784] [remote 114.119.154.9:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.flowmetersupply.com"] [uri "/robots.txt"] [unique_id "al4h-5PWlhYV5NwZ9vVcWAAAVzE"], referer: https://www.flowmetersupply.com/robots.txt
[Mon Jul 20 07:26:19.635398 2026] [security2:error] [pid 116718:tid 116841] [remote 15.206.251.117:37292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcXAAAD2o"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 07:26:19.668359 2026] [security2:error] [pid 116718:tid 116940] [client 34.79.255.97:60838] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4h-5PWlhYV5NwZ9vVcZAAAAEw"]
[Mon Jul 20 07:26:19.796929 2026] [security2:error] [pid 116718:tid 116872] [client 14.225.17.146:51098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcZgAAAAg"], referer: https://39ishlife.com/test
[Mon Jul 20 07:26:19.826739 2026] [security2:error] [pid 116718:tid 116965] [client 14.225.17.146:51324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcaAAAAGU"], referer: http://betterbonddogtraining.com/test
[Mon Jul 20 07:26:19.903677 2026] [security2:error] [pid 116718:tid 116969] [client 23.180.120.148:38144] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "jqq.cyv.mybluehost.me"] [uri "/wp-json/batch/v1"] [unique_id "al4h-5PWlhYV5NwZ9vVcdgAAAGk"]
[Mon Jul 20 07:26:20.019541 2026] [security2:error] [pid 116718:tid 116891] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcPgAAGxA"], referer: http://ardhalwafaa.com/test
[Mon Jul 20 07:26:20.038154 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:49261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcgwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:20.038286 2026] [security2:error] [pid 116718:tid 116962] [client 77.110.127.138:49261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcgwAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:20.122160 2026] [security2:error] [pid 116718:tid 116977] [client 5.9.147.23:41734] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "secoaches.co"] [uri "/contact-us-2/"] [unique_id "al4h_JPWlhYV5NwZ9vVckAAAAHE"]
[Mon Jul 20 07:26:20.270921 2026] [security2:error] [pid 116718:tid 116957] [client 34.79.255.97:55986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "puk.jiv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4h_JPWlhYV5NwZ9vVcpQAAAF0"]
[Mon Jul 20 07:26:20.324980 2026] [http2:info] [pid 145170:tid 145170] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:26:20.437944 2026] [security2:error] [pid 116718:tid 116962] [client 54.244.177.189:51034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4h_JPWlhYV5NwZ9vVcsgAAAGI"]
[Mon Jul 20 07:26:20.447889 2026] [security2:error] [pid 116718:tid 116966] [client 143.44.185.218:51916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h_JPWlhYV5NwZ9vVctQAAAGY"]
[Mon Jul 20 07:26:20.448039 2026] [security2:error] [pid 116718:tid 116966] [client 143.44.185.218:51916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4h_JPWlhYV5NwZ9vVctQAAAGY"]
[Mon Jul 20 07:26:20.628859 2026] [security2:error] [pid 145170:tid 145307] [client 54.244.177.189:51036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4h_Djs5KUa9I09SwTI6wAAAIk"]
[Mon Jul 20 07:26:20.643887 2026] [security2:error] [pid 116718:tid 116978] [client 44.245.170.32:60088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4h_JPWlhYV5NwZ9vVcwAAAAHI"]
[Mon Jul 20 07:26:20.652298 2026] [security2:error] [pid 116718:tid 116906] [client 44.245.170.32:60096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4h_JPWlhYV5NwZ9vVcwQAAACo"]
[Mon Jul 20 07:26:20.813120 2026] [security2:error] [pid 116718:tid 116899] [client 14.225.17.146:64709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4h-pPWlhYV5NwZ9vVcAgAAACM"], referer: http://itdynamix.com/test
[Mon Jul 20 07:26:20.876425 2026] [security2:error] [pid 145170:tid 145312] [client 63.177.52.239:46666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4h_Djs5KUa9I09SwTI8AAAAI4"]
[Mon Jul 20 07:26:21.038062 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:49249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc1wAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.038162 2026] [security2:error] [pid 116718:tid 116977] [client 77.110.127.138:49249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc1wAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.216537 2026] [security2:error] [pid 116718:tid 116902] [client 14.225.17.146:51097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcbAAAACY"], referer: http://detroitcsc.com/test
[Mon Jul 20 07:26:21.233351 2026] [security2:error] [pid 116718:tid 116962] [client 202.141.11.99:55357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc4AAAAGI"]
[Mon Jul 20 07:26:21.233453 2026] [security2:error] [pid 116718:tid 116962] [client 202.141.11.99:55357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc4AAAAGI"]
[Mon Jul 20 07:26:21.278509 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:49225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc4wAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.278612 2026] [security2:error] [pid 116718:tid 116940] [client 77.110.127.138:49225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc4wAAAEw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.383420 2026] [security2:error] [pid 145170:tid 145335] [client 74.7.227.179:45590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4h_Tjs5KUa9I09SwTI-wAApQA"], referer: https://tejasenvironmental.com/p=303199
[Mon Jul 20 07:26:21.434786 2026] [security2:error] [pid 116718:tid 116927] [client 14.225.17.146:55961] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4h_JPWlhYV5NwZ9vVcjwAAAD8"], referer: http://backandneckpainrelieflaceychiropractor.com/test
[Mon Jul 20 07:26:21.620233 2026] [security2:error] [pid 145170:tid 145177] [remote 193.70.112.205:32960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4h_Tjs5KUa9I09SwTJCAAAtwM"]
[Mon Jul 20 07:26:21.643584 2026] [security2:error] [pid 116718:tid 116937] [client 57.141.18.11:32868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h-JPWlhYV5NwZ9vVbTAAASWU"]
[Mon Jul 20 07:26:21.686245 2026] [security2:error] [pid 116718:tid 116941] [client 77.110.127.138:49254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc-wAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.686383 2026] [security2:error] [pid 116718:tid 116941] [client 77.110.127.138:49254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVc-wAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.762664 2026] [security2:error] [pid 116718:tid 116922] [client 77.110.127.138:49256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVdAAAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.762770 2026] [security2:error] [pid 116718:tid 116922] [client 77.110.127.138:49256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_ZPWlhYV5NwZ9vVdAAAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.768188 2026] [security2:error] [pid 145170:tid 145179] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h_Tjs5KUa9I09SwTJDQAAyAU"]
[Mon Jul 20 07:26:21.768360 2026] [security2:error] [pid 145170:tid 145370] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4h_Tjs5KUa9I09SwTJDQAAyAU"]
[Mon Jul 20 07:26:21.828852 2026] [security2:error] [pid 145170:tid 145181] [remote 193.70.112.205:32960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.112.70.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4h_Tjs5KUa9I09SwTJDwAA1Ac"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:26:21.856973 2026] [security2:error] [pid 145170:tid 145361] [client 14.225.17.146:51082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4h_Tjs5KUa9I09SwTJCwAAAL8"], referer: https://itdynamix.com/test
[Mon Jul 20 07:26:21.915043 2026] [security2:error] [pid 145170:tid 145384] [client 77.110.127.138:49265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_Tjs5KUa9I09SwTJFAAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:21.915145 2026] [security2:error] [pid 145170:tid 145384] [client 77.110.127.138:49265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_Tjs5KUa9I09SwTJFAAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:22.144086 2026] [security2:error] [pid 116718:tid 116940] [client 18.141.57.241:27212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/uploads/2023/05/watermelon-fries-blog.jpg"] [unique_id "al4h_pPWlhYV5NwZ9vVdFAAAAEw"], referer: https://curlsnpearlsss.com/watermelon-fries-with-coconut-lime-dip/
[Mon Jul 20 07:26:22.162236 2026] [security2:error] [pid 145170:tid 145341] [client 3.78.190.80:30212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4h_Tjs5KUa9I09SwTJAgAAAKs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:26:22.424368 2026] [security2:error] [pid 145170:tid 145392] [client 49.47.218.174:56526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h_jjs5KUa9I09SwTJMQAAAN4"]
[Mon Jul 20 07:26:22.424491 2026] [security2:error] [pid 145170:tid 145392] [client 49.47.218.174:56526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4h_jjs5KUa9I09SwTJMQAAAN4"]
[Mon Jul 20 07:26:22.437044 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:49268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_pPWlhYV5NwZ9vVdHwAAAEk"]
[Mon Jul 20 07:26:22.437213 2026] [security2:error] [pid 116718:tid 116937] [client 77.110.127.138:49268] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_pPWlhYV5NwZ9vVdHwAAAEk"]
[Mon Jul 20 07:26:22.542674 2026] [security2:error] [pid 116718:tid 116947] [client 57.141.18.120:59320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h-ZPWlhYV5NwZ9vVbkQAAUyo"]
[Mon Jul 20 07:26:22.667829 2026] [security2:error] [pid 145170:tid 145316] [client 14.225.17.146:51129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4h_Tjs5KUa9I09SwTI8wAAAJI"], referer: http://vinovinhowine.com/test
[Mon Jul 20 07:26:22.719483 2026] [security2:error] [pid 116718:tid 116817] [remote 173.212.252.15:60194] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4h_pPWlhYV5NwZ9vVdMgAAblI"]
[Mon Jul 20 07:26:22.719677 2026] [security2:error] [pid 116718:tid 116974] [client 173.212.252.15:60194] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ccsdifference.com"] [uri "/xmlrpc.php"] [unique_id "al4h_pPWlhYV5NwZ9vVdMgAAblI"]
[Mon Jul 20 07:26:22.724151 2026] [security2:error] [pid 145170:tid 145344] [client 77.110.127.138:49270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_jjs5KUa9I09SwTJNAAAAK4"]
[Mon Jul 20 07:26:22.724261 2026] [security2:error] [pid 145170:tid 145344] [client 77.110.127.138:49270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4h_jjs5KUa9I09SwTJNAAAAK4"]
[Mon Jul 20 07:26:22.986404 2026] [security2:error] [pid 145170:tid 145339] [client 14.225.17.146:60629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4h_jjs5KUa9I09SwTJOgAAAKk"], referer: http://thefriendlyspreadsheet.com/test
[Mon Jul 20 07:26:22.997272 2026] [security2:error] [pid 116718:tid 116911] [client 14.225.17.146:50862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4h_pPWlhYV5NwZ9vVdNgAAAC8"], referer: http://travelbyfire.com/test
[Mon Jul 20 07:26:23.090265 2026] [security2:error] [pid 116718:tid 116973] [client 57.141.18.111:53372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h-pPWlhYV5NwZ9vVbygAAbUQ"]
[Mon Jul 20 07:26:23.332877 2026] [core:error] [pid 145170:tid 145379] [client 94.154.43.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.332906 2026] [core:error] [pid 145170:tid 145379] [client 94.154.43.185:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.515386 2026] [security2:error] [pid 145170:tid 145393] [client 57.141.18.80:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4h_zjs5KUa9I09SwTJTAAAAN8"]
[Mon Jul 20 07:26:23.798807 2026] [security2:error] [pid 116718:tid 116974] [client 36.93.152.155:52499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h_5PWlhYV5NwZ9vVdbQAAAG4"]
[Mon Jul 20 07:26:23.798908 2026] [security2:error] [pid 116718:tid 116974] [client 36.93.152.155:52499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4h_5PWlhYV5NwZ9vVdbQAAAG4"]
[Mon Jul 20 07:26:23.896699 2026] [security2:error] [pid 116718:tid 116965] [client 14.225.17.146:62363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4h_5PWlhYV5NwZ9vVdbgAAAGU"], referer: https://travelbyfire.com/test
[Mon Jul 20 07:26:23.972930 2026] [core:error] [pid 145170:tid 145428] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.972957 2026] [core:error] [pid 145170:tid 145428] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.975240 2026] [core:error] [pid 116718:tid 116977] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.975257 2026] [core:error] [pid 116718:tid 116977] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.975296 2026] [core:error] [pid 145170:tid 145429] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.975311 2026] [core:error] [pid 145170:tid 145429] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.985193 2026] [core:error] [pid 145170:tid 145306] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:23.985210 2026] [core:error] [pid 145170:tid 145306] [client 52.59.47.42:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:24.020116 2026] [security2:error] [pid 116718:tid 116942] [client 154.208.48.130:59227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iAJPWlhYV5NwZ9vVdhgAAAE4"]
[Mon Jul 20 07:26:24.020242 2026] [security2:error] [pid 116718:tid 116942] [client 154.208.48.130:59227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iAJPWlhYV5NwZ9vVdhgAAAE4"]
[Mon Jul 20 07:26:24.112539 2026] [security2:error] [pid 145170:tid 145312] [client 77.110.127.138:49278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iADjs5KUa9I09SwTJaQAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:24.112649 2026] [security2:error] [pid 145170:tid 145312] [client 77.110.127.138:49278] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iADjs5KUa9I09SwTJaQAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:24.176540 2026] [security2:error] [pid 145170:tid 145399] [client 103.176.215.66:61624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iADjs5KUa9I09SwTJbQAAAOU"]
[Mon Jul 20 07:26:24.176661 2026] [security2:error] [pid 145170:tid 145399] [client 103.176.215.66:61624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iADjs5KUa9I09SwTJbQAAAOU"]
[Mon Jul 20 07:26:24.179483 2026] [security2:error] [pid 116718:tid 116979] [client 57.141.18.37:51216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h-5PWlhYV5NwZ9vVcJAAAc2Y"]
[Mon Jul 20 07:26:24.209400 2026] [core:error] [pid 145170:tid 145356] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:24.209429 2026] [core:error] [pid 145170:tid 145356] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:24.323604 2026] [security2:error] [pid 145170:tid 145195] [remote 5.161.225.162:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4iADjs5KUa9I09SwTJcgAAmxU"]
[Mon Jul 20 07:26:24.490529 2026] [security2:error] [pid 116718:tid 116922] [client 136.158.60.21:35029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iAJPWlhYV5NwZ9vVdnAAAADo"]
[Mon Jul 20 07:26:24.490672 2026] [security2:error] [pid 116718:tid 116922] [client 136.158.60.21:35029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iAJPWlhYV5NwZ9vVdnAAAADo"]
[Mon Jul 20 07:26:24.512739 2026] [security2:error] [pid 145170:tid 145196] [remote 5.161.225.162:43468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftsurprizo.com"] [uri "/wp-login.php"] [unique_id "al4iADjs5KUa9I09SwTJfQAAzRY"], referer: https://giftsurprizo.com/wp-login.php
[Mon Jul 20 07:26:24.756506 2026] [security2:error] [pid 145170:tid 145359] [client 14.225.17.146:51246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4h_zjs5KUa9I09SwTJRwAAAL0"], referer: http://kromosenergy.com/test
[Mon Jul 20 07:26:24.775505 2026] [security2:error] [pid 116718:tid 116958] [client 117.211.236.168:52324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iAJPWlhYV5NwZ9vVdqwAAAF4"]
[Mon Jul 20 07:26:24.775620 2026] [security2:error] [pid 116718:tid 116958] [client 117.211.236.168:52324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iAJPWlhYV5NwZ9vVdqwAAAF4"]
[Mon Jul 20 07:26:24.973043 2026] [security2:error] [pid 116718:tid 116823] [remote 57.141.18.88:61490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3924907"] [unique_id "al4iAJPWlhYV5NwZ9vVdtwAAYlg"]
[Mon Jul 20 07:26:25.006323 2026] [security2:error] [pid 145170:tid 145203] [remote 50.28.1.50:34734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.1.28.50.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iADjs5KUa9I09SwTJjAAAvx0"]
[Mon Jul 20 07:26:25.006467 2026] [security2:error] [pid 145170:tid 145361] [client 50.28.1.50:34734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iADjs5KUa9I09SwTJjAAAvx0"]
[Mon Jul 20 07:26:25.278892 2026] [security2:error] [pid 145170:tid 145362] [client 103.106.165.44:59434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iATjs5KUa9I09SwTJlQAAAMA"]
[Mon Jul 20 07:26:25.279003 2026] [security2:error] [pid 145170:tid 145362] [client 103.106.165.44:59434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iATjs5KUa9I09SwTJlQAAAMA"]
[Mon Jul 20 07:26:25.356458 2026] [security2:error] [pid 116718:tid 116981] [client 201.27.111.74:63090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iAZPWlhYV5NwZ9vVdzAAAAHU"]
[Mon Jul 20 07:26:25.356564 2026] [security2:error] [pid 116718:tid 116981] [client 201.27.111.74:63090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iAZPWlhYV5NwZ9vVdzAAAAHU"]
[Mon Jul 20 07:26:25.898052 2026] [security2:error] [pid 116718:tid 116918] [client 158.173.89.95:31481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iAZPWlhYV5NwZ9vVd4gAAADY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:26:26.025189 2026] [security2:error] [pid 145170:tid 145347] [client 114.119.158.220:62283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sk-financial.com"] [uri "/testimonials/francis-2/"] [unique_id "al4iAjjs5KUa9I09SwTJuQAAALE"], referer: https://sk-financial.com/testimonials/
[Mon Jul 20 07:26:26.290814 2026] [security2:error] [pid 145170:tid 145367] [client 57.141.18.15:64954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h_Tjs5KUa9I09SwTJBgAAxQQ"]
[Mon Jul 20 07:26:26.611899 2026] [security2:error] [pid 145170:tid 145210] [remote 117.0.21.154:34950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4iAjjs5KUa9I09SwTJxwAAtCQ"]
[Mon Jul 20 07:26:26.644026 2026] [security2:error] [pid 145170:tid 145313] [client 136.0.207.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4iAjjs5KUa9I09SwTJwwAAAI8"]
[Mon Jul 20 07:26:26.648832 2026] [security2:error] [pid 145170:tid 145390] [client 104.234.53.56:50969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iAjjs5KUa9I09SwTJyAAAANw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:26.740248 2026] [security2:error] [pid 145170:tid 145211] [remote 217.113.60.80:35804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iAjjs5KUa9I09SwTJzAABBCU"]
[Mon Jul 20 07:26:26.740454 2026] [security2:error] [pid 145170:tid 145430] [client 217.113.60.80:35804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iAjjs5KUa9I09SwTJzAABBCU"]
[Mon Jul 20 07:26:26.897543 2026] [security2:error] [pid 145170:tid 145401] [client 57.141.18.94:35520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h_jjs5KUa9I09SwTJGgAA5wo"]
[Mon Jul 20 07:26:27.083529 2026] [security2:error] [pid 145170:tid 145411] [client 191.202.66.27:56335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iAzjs5KUa9I09SwTJ3gAAAPE"]
[Mon Jul 20 07:26:27.083653 2026] [security2:error] [pid 145170:tid 145411] [client 191.202.66.27:56335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iAzjs5KUa9I09SwTJ3gAAAPE"]
[Mon Jul 20 07:26:27.211042 2026] [security2:error] [pid 145170:tid 145218] [remote 117.0.21.154:34950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4iAzjs5KUa9I09SwTJ5gAA5iw"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:26:27.262505 2026] [security2:error] [pid 145170:tid 145325] [client 88.241.67.160:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iAzjs5KUa9I09SwTJ7QAAAJs"]
[Mon Jul 20 07:26:27.262625 2026] [security2:error] [pid 145170:tid 145325] [client 88.241.67.160:57057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iAzjs5KUa9I09SwTJ7QAAAJs"]
[Mon Jul 20 07:26:27.775217 2026] [security2:error] [pid 145170:tid 145423] [client 193.37.33.18:62549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4iAzjs5KUa9I09SwTKAAAAAP0"]
[Mon Jul 20 07:26:27.783549 2026] [security2:error] [pid 145170:tid 145425] [client 193.37.33.9:33873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4iAzjs5KUa9I09SwTJ_wAAAP8"]
[Mon Jul 20 07:26:27.843970 2026] [security2:error] [pid 145170:tid 145414] [client 77.110.127.138:49295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iAzjs5KUa9I09SwTKBQAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:27.844065 2026] [security2:error] [pid 145170:tid 145414] [client 77.110.127.138:49295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iAzjs5KUa9I09SwTKBQAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:27.868220 2026] [security2:error] [pid 116718:tid 116947] [client 173.239.224.31:55263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4iA5PWlhYV5NwZ9vVeNQAAAFM"]
[Mon Jul 20 07:26:28.058365 2026] [security2:error] [pid 116718:tid 116906] [client 104.234.53.70:52175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iBJPWlhYV5NwZ9vVeOgAAACo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:28.058783 2026] [security2:error] [pid 116718:tid 116933] [client 179.127.84.238:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iBJPWlhYV5NwZ9vVeOwAAAEU"]
[Mon Jul 20 07:26:28.058870 2026] [security2:error] [pid 116718:tid 116933] [client 179.127.84.238:57702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iBJPWlhYV5NwZ9vVeOwAAAEU"]
[Mon Jul 20 07:26:28.115672 2026] [security2:error] [pid 145170:tid 145412] [client 114.119.149.222:44301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.elevator-data.com"] [uri "/robots.txt"] [unique_id "al4iBDjs5KUa9I09SwTKDAAAAPI"], referer: https://www.elevator-data.com/robots.txt
[Mon Jul 20 07:26:28.324152 2026] [security2:error] [pid 116718:tid 116916] [client 57.141.18.102:57292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h_5PWlhYV5NwZ9vVdQwAANDY"]
[Mon Jul 20 07:26:28.399298 2026] [security2:error] [pid 116718:tid 116913] [client 66.249.65.42:59709] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "zimzelen.com"] [uri "/robots.txt"] [unique_id "al4iBJPWlhYV5NwZ9vVeSQAAADE"]
[Mon Jul 20 07:26:28.404800 2026] [security2:error] [pid 116718:tid 116941] [client 57.141.18.32:41460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4h_5PWlhYV5NwZ9vVdSAAATUE"]
[Mon Jul 20 07:26:28.439739 2026] [security2:error] [pid 145170:tid 145228] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iBDjs5KUa9I09SwTKFgABADY"]
[Mon Jul 20 07:26:28.439918 2026] [security2:error] [pid 145170:tid 145426] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iBDjs5KUa9I09SwTKFgABADY"]
[Mon Jul 20 07:26:28.617381 2026] [security2:error] [pid 145170:tid 145386] [client 154.192.123.127:17134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iBDjs5KUa9I09SwTKIAAAANg"]
[Mon Jul 20 07:26:28.617491 2026] [security2:error] [pid 145170:tid 145386] [client 154.192.123.127:17134] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iBDjs5KUa9I09SwTKIAAAANg"]
[Mon Jul 20 07:26:29.091575 2026] [security2:error] [pid 145170:tid 145415] [client 157.20.138.62:57784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iBTjs5KUa9I09SwTKPAAAAPU"]
[Mon Jul 20 07:26:29.091671 2026] [security2:error] [pid 145170:tid 145415] [client 157.20.138.62:57784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iBTjs5KUa9I09SwTKPAAAAPU"]
[Mon Jul 20 07:26:29.336084 2026] [security2:error] [pid 116718:tid 116873] [client 57.141.18.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iBZPWlhYV5NwZ9vVeZQAAAAk"]
[Mon Jul 20 07:26:29.593011 2026] [security2:error] [pid 145170:tid 145325] [client 50.116.65.227:28086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iBTjs5KUa9I09SwTKWAAAAJs"]
[Mon Jul 20 07:26:29.603233 2026] [security2:error] [pid 145170:tid 145321] [client 50.116.65.227:28090] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iBTjs5KUa9I09SwTKWQAAAJc"]
[Mon Jul 20 07:26:29.697239 2026] [security2:error] [pid 145170:tid 145241] [remote 103.118.29.185:55446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4iBTjs5KUa9I09SwTKXAAA10M"]
[Mon Jul 20 07:26:29.959307 2026] [security2:error] [pid 145170:tid 145311] [client 14.225.17.146:54412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4iBTjs5KUa9I09SwTKXQAAAI0"], referer: http://mourgroup.com/test
[Mon Jul 20 07:26:30.114408 2026] [security2:error] [pid 145170:tid 145246] [remote 103.118.29.185:55446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "entuvy.com"] [uri "/wp-login.php"] [unique_id "al4iBjjs5KUa9I09SwTKaAAArUg"], referer: https://entuvy.com/wp-login.php
[Mon Jul 20 07:26:30.613805 2026] [security2:error] [pid 145170:tid 145334] [client 14.225.17.146:55711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4iBjjs5KUa9I09SwTKcAAAAKQ"], referer: http://bigwormfishing.com/test
[Mon Jul 20 07:26:30.637646 2026] [security2:error] [pid 145170:tid 145423] [client 14.225.17.146:54664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4iBjjs5KUa9I09SwTKbwAAAP0"], referer: http://thechancersband.com/test
[Mon Jul 20 07:26:30.767434 2026] [security2:error] [pid 145170:tid 145348] [client 77.110.127.138:49315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iBjjs5KUa9I09SwTKewAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:30.767544 2026] [security2:error] [pid 145170:tid 145348] [client 77.110.127.138:49315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iBjjs5KUa9I09SwTKewAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:30.988082 2026] [security2:error] [pid 145170:tid 145361] [client 57.141.18.3:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iAjjs5KUa9I09SwTJugAAvyI"]
[Mon Jul 20 07:26:31.023389 2026] [security2:error] [pid 145170:tid 145377] [client 14.225.17.146:55647] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4iBjjs5KUa9I09SwTKgAAAAM8"], referer: http://effingweirdmuseums.com/test
[Mon Jul 20 07:26:31.594110 2026] [security2:error] [pid 116718:tid 116943] [client 14.225.17.146:64069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4iB5PWlhYV5NwZ9vVezgAAAE8"], referer: https://bigwormfishing.com/test
[Mon Jul 20 07:26:31.759832 2026] [security2:error] [pid 145170:tid 145420] [client 57.141.18.87:64140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iAjjs5KUa9I09SwTJ0AAA-ic"]
[Mon Jul 20 07:26:31.767019 2026] [security2:error] [pid 145170:tid 145401] [client 202.141.11.99:36865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iBzjs5KUa9I09SwTKpgAAAOc"]
[Mon Jul 20 07:26:31.768400 2026] [security2:error] [pid 145170:tid 145401] [client 202.141.11.99:36865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iBzjs5KUa9I09SwTKpgAAAOc"]
[Mon Jul 20 07:26:31.870319 2026] [security2:error] [pid 145170:tid 145305] [client 74.208.214.194:55032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4iBzjs5KUa9I09SwTKpwAAAIc"]
[Mon Jul 20 07:26:31.971149 2026] [security2:error] [pid 145170:tid 145314] [client 14.225.17.146:54300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4iBzjs5KUa9I09SwTKqAAAAJA"], referer: https://effingweirdmuseums.com/test
[Mon Jul 20 07:26:31.983967 2026] [security2:error] [pid 145170:tid 145252] [remote 57.141.18.123:56402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4iBzjs5KUa9I09SwTKrAAAs04"]
[Mon Jul 20 07:26:32.130933 2026] [security2:error] [pid 145170:tid 145254] [remote 5.161.225.162:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4iCDjs5KUa9I09SwTKtwAAxFA"]
[Mon Jul 20 07:26:32.256209 2026] [security2:error] [pid 145170:tid 145398] [client 143.44.185.218:53988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iCDjs5KUa9I09SwTKvgAAAOQ"]
[Mon Jul 20 07:26:32.256365 2026] [security2:error] [pid 145170:tid 145398] [client 143.44.185.218:53988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iCDjs5KUa9I09SwTKvgAAAOQ"]
[Mon Jul 20 07:26:32.341342 2026] [security2:error] [pid 145170:tid 145257] [remote 5.161.225.162:44610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4iCDjs5KUa9I09SwTKwAAAplM"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:26:32.492971 2026] [security2:error] [pid 145170:tid 145354] [client 57.141.18.125:42602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iAzjs5KUa9I09SwTJ-gAAuDE"]
[Mon Jul 20 07:26:32.569917 2026] [security2:error] [pid 145170:tid 145328] [client 57.141.18.98:63818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iAzjs5KUa9I09SwTJ_QAAnjM"]
[Mon Jul 20 07:26:32.575678 2026] [security2:error] [pid 145170:tid 145258] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iCDjs5KUa9I09SwTKygAA0VQ"]
[Mon Jul 20 07:26:32.575854 2026] [security2:error] [pid 145170:tid 145379] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iCDjs5KUa9I09SwTKygAA0VQ"]
[Mon Jul 20 07:26:32.628025 2026] [security2:error] [pid 145170:tid 145259] [remote 20.153.140.50:36730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iCDjs5KUa9I09SwTKzAAAqlU"]
[Mon Jul 20 07:26:32.802349 2026] [security2:error] [pid 145170:tid 145418] [client 112.86.225.217:51502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/"] [unique_id "al4iCDjs5KUa9I09SwTK1AAAAPg"]
[Mon Jul 20 07:26:32.802454 2026] [security2:error] [pid 145170:tid 145418] [client 112.86.225.217:51502] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/"] [unique_id "al4iCDjs5KUa9I09SwTK1AAAAPg"]
[Mon Jul 20 07:26:32.916218 2026] [security2:error] [pid 145170:tid 145414] [client 49.47.218.174:57067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iCDjs5KUa9I09SwTK1wAAAPQ"]
[Mon Jul 20 07:26:32.916304 2026] [security2:error] [pid 145170:tid 145414] [client 49.47.218.174:57067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iCDjs5KUa9I09SwTK1wAAAPQ"]
[Mon Jul 20 07:26:32.975347 2026] [security2:error] [pid 145170:tid 145378] [client 57.141.18.73:38366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iBDjs5KUa9I09SwTKCwAA0DU"]
[Mon Jul 20 07:26:33.028926 2026] [security2:error] [pid 145170:tid 145262] [remote 20.153.140.50:36730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iCTjs5KUa9I09SwTK2wAA1Vg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:33.467084 2026] [security2:error] [pid 145170:tid 145267] [remote 42.200.84.61:40516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iCTjs5KUa9I09SwTK8gAAmF0"]
[Mon Jul 20 07:26:33.605426 2026] [security2:error] [pid 145170:tid 145411] [client 216.24.212.22:20947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4iCTjs5KUa9I09SwTK-QAAAPE"]
[Mon Jul 20 07:26:33.616882 2026] [security2:error] [pid 116718:tid 116906] [client 216.24.212.27:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfRQAAACo"]
[Mon Jul 20 07:26:33.662394 2026] [security2:error] [pid 116718:tid 116990] [client 108.31.198.202:59795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfKgAAfmI"]
[Mon Jul 20 07:26:33.673484 2026] [security2:error] [pid 116718:tid 116951] [client 108.31.198.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfMwAAAFc"]
[Mon Jul 20 07:26:33.677708 2026] [security2:error] [pid 116718:tid 116990] [client 108.31.198.202:59795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfKwAAfkQ"]
[Mon Jul 20 07:26:33.733201 2026] [security2:error] [pid 116718:tid 116980] [client 104.234.53.65:29037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfTgAAAHQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:33.826115 2026] [security2:error] [pid 145170:tid 145334] [client 14.225.17.146:55789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4iCDjs5KUa9I09SwTKswAAAKQ"], referer: http://fluidtemple.org/test
[Mon Jul 20 07:26:33.834099 2026] [security2:error] [pid 116718:tid 116977] [client 117.211.236.168:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfVgAAAHE"]
[Mon Jul 20 07:26:33.834241 2026] [security2:error] [pid 116718:tid 116977] [client 117.211.236.168:52823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfVgAAAHE"]
[Mon Jul 20 07:26:33.883557 2026] [security2:error] [pid 145170:tid 145272] [remote 42.200.84.61:40516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iCTjs5KUa9I09SwTLBAAAsmI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:26:33.894912 2026] [security2:error] [pid 116718:tid 116918] [client 35.236.255.199:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.255.236.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/xmlrpc.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfWAAAADY"]
[Mon Jul 20 07:26:33.895094 2026] [security2:error] [pid 116718:tid 116918] [client 35.236.255.199:59400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samdothan.org"] [uri "/xmlrpc.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfWAAAADY"]
[Mon Jul 20 07:26:34.109673 2026] [security2:error] [pid 145170:tid 145409] [client 14.225.17.146:56627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4iCDjs5KUa9I09SwTKxwAAAO8"], referer: http://olearyplumbingllc.com/test
[Mon Jul 20 07:26:34.303884 2026] [security2:error] [pid 145170:tid 145383] [client 36.93.152.155:53021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iCjjs5KUa9I09SwTLFQAAANU"]
[Mon Jul 20 07:26:34.304001 2026] [security2:error] [pid 145170:tid 145383] [client 36.93.152.155:53021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iCjjs5KUa9I09SwTLFQAAANU"]
[Mon Jul 20 07:26:34.353702 2026] [security2:error] [pid 145170:tid 145364] [client 74.208.214.194:55034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4iCjjs5KUa9I09SwTLGAAAAMI"]
[Mon Jul 20 07:26:34.455724 2026] [security2:error] [pid 145170:tid 145379] [client 82.102.18.116:45880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4iCjjs5KUa9I09SwTLHQAAANE"]
[Mon Jul 20 07:26:34.462448 2026] [security2:error] [pid 145170:tid 145377] [client 158.173.166.181:26909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iCjjs5KUa9I09SwTLHgAAAM8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:26:34.491420 2026] [security2:error] [pid 145170:tid 145386] [client 57.141.18.50:25530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iBTjs5KUa9I09SwTKVgAA2EI"]
[Mon Jul 20 07:26:34.542538 2026] [security2:error] [pid 116718:tid 116981] [client 14.225.17.146:55714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4iCJPWlhYV5NwZ9vVfEQAAAHU"], referer: http://adirondackengineering.com/test
[Mon Jul 20 07:26:34.690446 2026] [security2:error] [pid 145170:tid 145349] [client 103.176.215.66:62159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iCjjs5KUa9I09SwTLJgAAALM"]
[Mon Jul 20 07:26:34.690577 2026] [security2:error] [pid 145170:tid 145349] [client 103.176.215.66:62159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iCjjs5KUa9I09SwTLJgAAALM"]
[Mon Jul 20 07:26:34.777486 2026] [security2:error] [pid 116718:tid 116867] [client 82.102.18.116:45896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.robertpierson.net"] [uri "/xmlrpc.php"] [unique_id "al4iCpPWlhYV5NwZ9vVfdgAAAAM"]
[Mon Jul 20 07:26:34.808364 2026] [security2:error] [pid 145170:tid 145308] [client 47.128.52.170:54296] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.californiaperfumecompany.com"] [uri "/robots.txt"] [unique_id "al4iCjjs5KUa9I09SwTLLQAAAIo"]
[Mon Jul 20 07:26:34.940039 2026] [security2:error] [pid 145170:tid 145417] [client 57.141.18.44:22276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iBTjs5KUa9I09SwTKXgAA90Q"]
[Mon Jul 20 07:26:34.954870 2026] [security2:error] [pid 145170:tid 145395] [client 14.225.17.146:55649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4iCjjs5KUa9I09SwTLKgAAAOE"], referer: http://www.justinagrayman.com/test
[Mon Jul 20 07:26:35.114925 2026] [security2:error] [pid 145170:tid 145342] [client 154.208.48.130:59761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iCzjs5KUa9I09SwTLOgAAAKw"]
[Mon Jul 20 07:26:35.115062 2026] [security2:error] [pid 145170:tid 145342] [client 154.208.48.130:59761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iCzjs5KUa9I09SwTLOgAAAKw"]
[Mon Jul 20 07:26:35.275615 2026] [security2:error] [pid 116718:tid 116947] [client 136.158.60.21:36598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iC5PWlhYV5NwZ9vVfkgAAAFM"]
[Mon Jul 20 07:26:35.275771 2026] [security2:error] [pid 116718:tid 116947] [client 136.158.60.21:36598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iC5PWlhYV5NwZ9vVfkgAAAFM"]
[Mon Jul 20 07:26:35.455775 2026] [security2:error] [pid 145170:tid 145398] [client 82.102.18.116:45904] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4iCzjs5KUa9I09SwTLUwAAAOQ"]
[Mon Jul 20 07:26:35.487760 2026] [security2:error] [pid 145170:tid 145370] [client 14.225.17.146:56637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4iCjjs5KUa9I09SwTLDwAAAMg"], referer: http://momheadquarters.com/test
[Mon Jul 20 07:26:35.808128 2026] [security2:error] [pid 145170:tid 145368] [client 201.27.111.74:63592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iCzjs5KUa9I09SwTLbAAAAMY"]
[Mon Jul 20 07:26:35.812262 2026] [security2:error] [pid 145170:tid 145368] [client 201.27.111.74:63592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iCzjs5KUa9I09SwTLbAAAAMY"]
[Mon Jul 20 07:26:35.818829 2026] [security2:error] [pid 145170:tid 145356] [client 82.102.18.116:45906] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4iCzjs5KUa9I09SwTLbQAAALo"]
[Mon Jul 20 07:26:35.821754 2026] [security2:error] [pid 116718:tid 116864] [client 103.106.165.44:59918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iC5PWlhYV5NwZ9vVfqQAAAAA"]
[Mon Jul 20 07:26:35.821842 2026] [security2:error] [pid 116718:tid 116864] [client 103.106.165.44:59918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iC5PWlhYV5NwZ9vVfqQAAAAA"]
[Mon Jul 20 07:26:35.874212 2026] [security2:error] [pid 145170:tid 145288] [remote 173.249.4.11:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iCzjs5KUa9I09SwTLcAAA93I"]
[Mon Jul 20 07:26:35.957248 2026] [security2:error] [pid 116718:tid 116907] [client 14.180.248.135:40054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4iC5PWlhYV5NwZ9vVfrAAAK1g"]
[Mon Jul 20 07:26:36.000404 2026] [security2:error] [pid 145170:tid 145325] [client 14.225.17.146:55602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4iCzjs5KUa9I09SwTLawAAAJs"], referer: http://oldracelimited.com/test
[Mon Jul 20 07:26:36.075818 2026] [security2:error] [pid 116718:tid 116983] [client 104.234.53.94:44449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iDJPWlhYV5NwZ9vVftgAAAHc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:36.140039 2026] [security2:error] [pid 116718:tid 116930] [client 82.102.18.116:45914] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4iDJPWlhYV5NwZ9vVfvQAAAEI"]
[Mon Jul 20 07:26:36.294812 2026] [security2:error] [pid 145170:tid 145295] [remote 173.249.4.11:49690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iDDjs5KUa9I09SwTLigABAnk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:26:36.365909 2026] [security2:error] [pid 145170:tid 145332] [client 103.87.212.240:58980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.212.87.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/xmlrpc.php"] [unique_id "al4iDDjs5KUa9I09SwTLjAAAAKI"]
[Mon Jul 20 07:26:36.366029 2026] [security2:error] [pid 145170:tid 145332] [client 103.87.212.240:58980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "musichaven.info"] [uri "/xmlrpc.php"] [unique_id "al4iDDjs5KUa9I09SwTLjAAAAKI"]
[Mon Jul 20 07:26:36.449166 2026] [security2:error] [pid 145170:tid 145343] [client 57.141.18.24:46550] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iBzjs5KUa9I09SwTKmgAArUw"]
[Mon Jul 20 07:26:36.486444 2026] [security2:error] [pid 145170:tid 145345] [client 82.102.18.116:45916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4iDDjs5KUa9I09SwTLlgAAAK8"]
[Mon Jul 20 07:26:36.506958 2026] [security2:error] [pid 145170:tid 145399] [client 57.141.18.62:59614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iBzjs5KUa9I09SwTKmwAA5U0"]
[Mon Jul 20 07:26:36.732719 2026] [security2:error] [pid 145170:tid 145398] [client 38.3.142.177:4764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "sustaintheart.com"] [uri "/wp-content/plugins/aawp/public/image.php"] [unique_id "al4iDDjs5KUa9I09SwTLogAA5H0"]
[Mon Jul 20 07:26:36.760072 2026] [security2:error] [pid 116718:tid 116952] [client 57.141.18.104:25214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iB5PWlhYV5NwZ9vVe5wAAWEU"]
[Mon Jul 20 07:26:36.801620 2026] [security2:error] [pid 116718:tid 116978] [client 66.132.224.94:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cathybuffini.com"] [uri "/index.php"] [unique_id "al4iDJPWlhYV5NwZ9vVf0AAAAHI"]
[Mon Jul 20 07:26:36.821218 2026] [security2:error] [pid 145170:tid 145411] [client 82.102.18.116:50586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4iDDjs5KUa9I09SwTLqgAAAPE"]
[Mon Jul 20 07:26:36.923289 2026] [security2:error] [pid 145170:tid 145309] [client 14.225.17.146:56407] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4iDDjs5KUa9I09SwTLsAAAAIs"], referer: http://adultdaycarereno.com/test
[Mon Jul 20 07:26:36.938775 2026] [security2:error] [pid 145170:tid 145301] [remote 47.86.33.52:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4iDDjs5KUa9I09SwTLsQAAun8"]
[Mon Jul 20 07:26:36.982901 2026] [security2:error] [pid 145170:tid 145369] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iDDjs5KUa9I09SwTLrAAAAMc"]
[Mon Jul 20 07:26:37.004495 2026] [security2:error] [pid 116718:tid 116805] [remote 173.212.252.15:36662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iDZPWlhYV5NwZ9vVf3gAADUY"]
[Mon Jul 20 07:26:37.004794 2026] [security2:error] [pid 116718:tid 116877] [client 173.212.252.15:36662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iDZPWlhYV5NwZ9vVf3gAADUY"]
[Mon Jul 20 07:26:37.093947 2026] [security2:error] [pid 116718:tid 116988] [client 14.225.17.146:55503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4iDJPWlhYV5NwZ9vVf3QAAAHw"], referer: http://aljosour-alarabia.com/test
[Mon Jul 20 07:26:37.141213 2026] [security2:error] [pid 116718:tid 116916] [client 82.102.18.116:33835] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4iDZPWlhYV5NwZ9vVf5gAAADQ"]
[Mon Jul 20 07:26:37.358167 2026] [security2:error] [pid 116718:tid 116941] [client 77.110.127.138:49314] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iDZPWlhYV5NwZ9vVf8gAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:37.358281 2026] [security2:error] [pid 116718:tid 116941] [client 77.110.127.138:49314] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iDZPWlhYV5NwZ9vVf8gAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:37.478229 2026] [security2:error] [pid 116718:tid 116980] [client 82.102.18.116:45952] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4iDZPWlhYV5NwZ9vVgAQAAAHQ"]
[Mon Jul 20 07:26:37.720319 2026] [security2:error] [pid 116718:tid 116814] [remote 81.173.115.7:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgCgAAY08"]
[Mon Jul 20 07:26:37.788442 2026] [security2:error] [pid 145170:tid 145347] [client 82.102.18.116:45956] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4iDTjs5KUa9I09SwTL5QAAALE"]
[Mon Jul 20 07:26:37.799139 2026] [security2:error] [pid 116718:tid 116912] [client 191.202.66.27:56832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgDgAAADA"]
[Mon Jul 20 07:26:37.799342 2026] [security2:error] [pid 116718:tid 116912] [client 191.202.66.27:56832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgDgAAADA"]
[Mon Jul 20 07:26:37.841169 2026] [security2:error] [pid 116718:tid 116864] [client 14.225.17.146:63762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgAAAAAAA"], referer: http://mcg.homes/test
[Mon Jul 20 07:26:37.874332 2026] [security2:error] [pid 116718:tid 116972] [client 14.225.17.146:55511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgDwAAAGw"], referer: https://adultdaycarereno.com/test
[Mon Jul 20 07:26:37.912788 2026] [security2:error] [pid 116718:tid 116777] [remote 81.173.115.7:49694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgFgAALyo"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 07:26:37.912822 2026] [security2:error] [pid 116718:tid 116957] [client 88.241.67.160:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgFwAAAF0"]
[Mon Jul 20 07:26:37.912960 2026] [security2:error] [pid 116718:tid 116957] [client 88.241.67.160:56006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iDZPWlhYV5NwZ9vVgFwAAAF0"]
[Mon Jul 20 07:26:38.099004 2026] [security2:error] [pid 145170:tid 145375] [client 82.102.18.116:52084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4iDjjs5KUa9I09SwTL7wAAAM0"]
[Mon Jul 20 07:26:38.231875 2026] [security2:error] [pid 116718:tid 116962] [client 57.141.18.80:27748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iCZPWlhYV5NwZ9vVfGAAAYhM"]
[Mon Jul 20 07:26:38.422418 2026] [security2:error] [pid 145170:tid 145189] [remote 47.86.33.52:4634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-login.php"] [unique_id "al4iDjjs5KUa9I09SwTL_gAAmg8"], referer: https://massagelacey.com/wp-login.php
[Mon Jul 20 07:26:38.440923 2026] [security2:error] [pid 116718:tid 116941] [client 82.102.18.116:52086] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4iDpPWlhYV5NwZ9vVgKgAAAE0"]
[Mon Jul 20 07:26:38.535718 2026] [security2:error] [pid 145170:tid 145192] [remote 103.82.22.235:57178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iDjjs5KUa9I09SwTMBAAA1hI"]
[Mon Jul 20 07:26:38.557243 2026] [security2:error] [pid 145170:tid 145416] [client 57.141.18.31:37894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iCTjs5KUa9I09SwTK7AAA9lw"]
[Mon Jul 20 07:26:38.646724 2026] [security2:error] [pid 145170:tid 145402] [client 179.127.84.238:58199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iDjjs5KUa9I09SwTMDAAAAOg"]
[Mon Jul 20 07:26:38.646917 2026] [security2:error] [pid 145170:tid 145402] [client 179.127.84.238:58199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iDjjs5KUa9I09SwTMDAAAAOg"]
[Mon Jul 20 07:26:38.743359 2026] [security2:error] [pid 145170:tid 145335] [client 14.225.17.146:55463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4iDDjs5KUa9I09SwTLsgAAAKU"], referer: http://transparentservices.online/test
[Mon Jul 20 07:26:38.777958 2026] [security2:error] [pid 116718:tid 116896] [client 82.102.18.116:52090] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4iDpPWlhYV5NwZ9vVgPAAAACA"]
[Mon Jul 20 07:26:38.989315 2026] [security2:error] [pid 145170:tid 145430] [client 14.225.17.146:59043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4iDjjs5KUa9I09SwTMEAAAAQQ"]
[Mon Jul 20 07:26:39.014179 2026] [security2:error] [pid 145170:tid 145195] [remote 103.82.22.235:57178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iDzjs5KUa9I09SwTMGwAAzhU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:26:39.060249 2026] [security2:error] [pid 116718:tid 116850] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iD5PWlhYV5NwZ9vVgTwAAcXM"]
[Mon Jul 20 07:26:39.060406 2026] [security2:error] [pid 116718:tid 116977] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iD5PWlhYV5NwZ9vVgTwAAcXM"]
[Mon Jul 20 07:26:39.107217 2026] [security2:error] [pid 145170:tid 145307] [client 82.102.18.116:52096] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4iDzjs5KUa9I09SwTMHgAAAIk"]
[Mon Jul 20 07:26:39.213859 2026] [security2:error] [pid 116718:tid 116981] [client 14.225.17.146:59030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4iD5PWlhYV5NwZ9vVgSwAAAHU"], referer: http://fkconstructionfunding.com/test
[Mon Jul 20 07:26:39.226134 2026] [core:error] [pid 116718:tid 116937] [client 41.75.114.30:48102] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
[Mon Jul 20 07:26:39.422242 2026] [security2:error] [pid 116718:tid 116943] [client 82.102.18.116:52104] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.robertpierson.net"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4iD5PWlhYV5NwZ9vVgYgAAAE8"]
[Mon Jul 20 07:26:39.582834 2026] [security2:error] [pid 145170:tid 145394] [client 49.37.242.14:54622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iDzjs5KUa9I09SwTMMAAAAOA"]
[Mon Jul 20 07:26:39.582991 2026] [security2:error] [pid 145170:tid 145394] [client 49.37.242.14:54622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iDzjs5KUa9I09SwTMMAAAAOA"]
[Mon Jul 20 07:26:39.855101 2026] [security2:error] [pid 145170:tid 145382] [client 154.192.123.127:17543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iDzjs5KUa9I09SwTMQgAAANQ"]
[Mon Jul 20 07:26:39.855226 2026] [security2:error] [pid 145170:tid 145382] [client 154.192.123.127:17543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iDzjs5KUa9I09SwTMQgAAANQ"]
[Mon Jul 20 07:26:39.898836 2026] [security2:error] [pid 145170:tid 145388] [client 169.224.16.246:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4iDDjs5KUa9I09SwTLtgAAANo"]
[Mon Jul 20 07:26:39.935417 2026] [security2:error] [pid 145170:tid 145305] [client 14.225.17.146:58933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4iDzjs5KUa9I09SwTMPAAAAIc"], referer: http://tntcatholic.com/test
[Mon Jul 20 07:26:39.964690 2026] [security2:error] [pid 116718:tid 116770] [remote 8.217.108.67:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iD5PWlhYV5NwZ9vVgeAAARCM"]
[Mon Jul 20 07:26:40.014872 2026] [security2:error] [pid 116718:tid 116986] [client 157.20.138.62:58350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iEJPWlhYV5NwZ9vVgfwAAAHo"]
[Mon Jul 20 07:26:40.015725 2026] [security2:error] [pid 116718:tid 116986] [client 157.20.138.62:58350] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iEJPWlhYV5NwZ9vVgfwAAAHo"]
[Mon Jul 20 07:26:40.038398 2026] [security2:error] [pid 145170:tid 145325] [client 77.110.127.138:49373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iEDjs5KUa9I09SwTMSQAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:40.038498 2026] [security2:error] [pid 145170:tid 145325] [client 77.110.127.138:49373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iEDjs5KUa9I09SwTMSQAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:40.838836 2026] [security2:error] [pid 145170:tid 145426] [client 104.234.53.64:54203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iEDjs5KUa9I09SwTMcwAAAQA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:41.107572 2026] [security2:error] [pid 145170:tid 145428] [client 62.150.67.110:50255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4iEDjs5KUa9I09SwTMcAAAAQI"]
[Mon Jul 20 07:26:41.226104 2026] [security2:error] [pid 145170:tid 145314] [client 50.116.65.227:55802] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iETjs5KUa9I09SwTMiwAAAJA"]
[Mon Jul 20 07:26:41.235499 2026] [security2:error] [pid 145170:tid 145352] [client 50.116.65.227:55812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iETjs5KUa9I09SwTMjQAAALY"]
[Mon Jul 20 07:26:41.305876 2026] [security2:error] [pid 145170:tid 145407] [client 14.225.17.146:63691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4iEDjs5KUa9I09SwTMSgAAAO0"], referer: http://mazzucelli.com/test
[Mon Jul 20 07:26:41.430556 2026] [proxy:error] [pid 145170:tid 145324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:41.430593 2026] [proxy_http:error] [pid 145170:tid 145324] [client 107.172.180.205:54554] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:41.431029 2026] [proxy:error] [pid 145170:tid 145324] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:41.431055 2026] [proxy_http:error] [pid 145170:tid 145324] [client 107.172.180.205:54554] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:42.090196 2026] [security2:error] [pid 145170:tid 145400] [client 14.225.17.146:63732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4iETjs5KUa9I09SwTMjgAAAOY"], referer: http://idigress.agency/test
[Mon Jul 20 07:26:42.280706 2026] [security2:error] [pid 116718:tid 116931] [client 57.141.18.6:40462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iDZPWlhYV5NwZ9vVf_wAAQxw"]
[Mon Jul 20 07:26:42.463117 2026] [security2:error] [pid 145170:tid 145220] [remote 5.161.225.162:38174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4iEjjs5KUa9I09SwTMtgAAqi4"]
[Mon Jul 20 07:26:42.637518 2026] [security2:error] [pid 145170:tid 145222] [remote 8.217.108.67:61948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iEjjs5KUa9I09SwTMuwAA1DA"]
[Mon Jul 20 07:26:42.651544 2026] [security2:error] [pid 145170:tid 145226] [remote 5.161.225.162:38174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4iEjjs5KUa9I09SwTMvAAA1jQ"], referer: https://bbwipartnerconference.com/wp-login.php
[Mon Jul 20 07:26:42.781650 2026] [proxy:error] [pid 145170:tid 145346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:42.781732 2026] [proxy_http:error] [pid 145170:tid 145346] [client 107.172.180.205:54580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:42.782151 2026] [proxy:error] [pid 145170:tid 145346] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:42.782177 2026] [proxy_http:error] [pid 145170:tid 145346] [client 107.172.180.205:54580] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:42.823350 2026] [security2:error] [pid 116718:tid 116921] [client 104.234.53.77:23945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iEpPWlhYV5NwZ9vVg6QAAADk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:43.183382 2026] [security2:error] [pid 116718:tid 116790] [remote 8.217.108.67:61932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iE5PWlhYV5NwZ9vVg9gAAJjc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:26:43.200176 2026] [security2:error] [pid 145170:tid 145231] [remote 8.217.108.67:61948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iEzjs5KUa9I09SwTM2AAA6zk"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:26:43.273720 2026] [security2:error] [pid 145170:tid 145232] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iEzjs5KUa9I09SwTM4QAAjTo"]
[Mon Jul 20 07:26:43.273867 2026] [security2:error] [pid 145170:tid 145311] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iEzjs5KUa9I09SwTM4QAAjTo"]
[Mon Jul 20 07:26:43.284685 2026] [security2:error] [pid 145170:tid 145348] [client 57.141.18.16:47492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iDjjs5KUa9I09SwTMBwAAshM"]
[Mon Jul 20 07:26:43.373070 2026] [security2:error] [pid 116718:tid 116881] [client 57.141.18.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iE5PWlhYV5NwZ9vVg-QAAABE"]
[Mon Jul 20 07:26:43.391943 2026] [security2:error] [pid 116718:tid 116966] [client 57.141.18.104:38364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iDpPWlhYV5NwZ9vVgOgAAZns"]
[Mon Jul 20 07:26:43.476443 2026] [security2:error] [pid 145170:tid 145388] [client 49.47.218.174:61504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iEzjs5KUa9I09SwTM6AAAANo"]
[Mon Jul 20 07:26:43.476591 2026] [security2:error] [pid 145170:tid 145388] [client 49.47.218.174:61504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iEzjs5KUa9I09SwTM6AAAANo"]
[Mon Jul 20 07:26:43.724720 2026] [security2:error] [pid 116718:tid 116812] [remote 124.55.178.99:57668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4iE5PWlhYV5NwZ9vVhDAAABU0"]
[Mon Jul 20 07:26:43.738024 2026] [security2:error] [pid 145170:tid 145309] [client 77.110.127.138:49380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iEzjs5KUa9I09SwTM9QAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:43.738146 2026] [security2:error] [pid 145170:tid 145309] [client 77.110.127.138:49380] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iEzjs5KUa9I09SwTM9QAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:43.772452 2026] [security2:error] [pid 145170:tid 145409] [client 14.225.17.146:55371] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4iEzjs5KUa9I09SwTM8AAAAO8"], referer: http://katsklar.com/test
[Mon Jul 20 07:26:43.843337 2026] [security2:error] [pid 116718:tid 116982] [client 14.225.17.146:58751] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4iEpPWlhYV5NwZ9vVg0gAAAHY"], referer: http://superiorcopywriting.com/test
[Mon Jul 20 07:26:44.145878 2026] [security2:error] [pid 116718:tid 116758] [remote 124.55.178.99:57668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oldracelimited.com"] [uri "/wp-login.php"] [unique_id "al4iFJPWlhYV5NwZ9vVhFgAAShc"], referer: https://oldracelimited.com/wp-login.php
[Mon Jul 20 07:26:44.437274 2026] [security2:error] [pid 116718:tid 116951] [client 57.141.18.121:26868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iD5PWlhYV5NwZ9vVgbwAAVyw"]
[Mon Jul 20 07:26:44.593330 2026] [security2:error] [pid 145170:tid 145400] [client 143.44.185.218:55572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iFDjs5KUa9I09SwTNHwAAAOY"]
[Mon Jul 20 07:26:44.595480 2026] [security2:error] [pid 145170:tid 145400] [client 143.44.185.218:55572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iFDjs5KUa9I09SwTNHwAAAOY"]
[Mon Jul 20 07:26:44.682282 2026] [security2:error] [pid 116718:tid 116950] [client 117.211.236.168:53369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iFJPWlhYV5NwZ9vVhKwAAAFY"]
[Mon Jul 20 07:26:44.682378 2026] [security2:error] [pid 116718:tid 116950] [client 117.211.236.168:53369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iFJPWlhYV5NwZ9vVhKwAAAFY"]
[Mon Jul 20 07:26:44.808672 2026] [security2:error] [pid 145170:tid 145408] [client 36.93.152.155:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iFDjs5KUa9I09SwTNLgAAAO4"]
[Mon Jul 20 07:26:44.808813 2026] [security2:error] [pid 145170:tid 145408] [client 36.93.152.155:53532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iFDjs5KUa9I09SwTNLgAAAO4"]
[Mon Jul 20 07:26:45.281057 2026] [security2:error] [pid 145170:tid 145357] [client 103.176.215.66:62702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iFTjs5KUa9I09SwTNSwAAALs"]
[Mon Jul 20 07:26:45.281458 2026] [security2:error] [pid 145170:tid 145357] [client 103.176.215.66:62702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iFTjs5KUa9I09SwTNSwAAALs"]
[Mon Jul 20 07:26:45.318178 2026] [security2:error] [pid 145170:tid 145327] [client 57.141.18.85:38124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iEDjs5KUa9I09SwTMZgAAnSE"]
[Mon Jul 20 07:26:45.990462 2026] [security2:error] [pid 145170:tid 145430] [client 136.158.60.21:38187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iFTjs5KUa9I09SwTNagAAAQQ"]
[Mon Jul 20 07:26:45.990609 2026] [security2:error] [pid 145170:tid 145430] [client 136.158.60.21:38187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iFTjs5KUa9I09SwTNagAAAQQ"]
[Mon Jul 20 07:26:46.214774 2026] [security2:error] [pid 145170:tid 145397] [client 154.208.48.130:60306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iFjjs5KUa9I09SwTNeAAAAOM"]
[Mon Jul 20 07:26:46.214868 2026] [security2:error] [pid 145170:tid 145397] [client 154.208.48.130:60306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iFjjs5KUa9I09SwTNeAAAAOM"]
[Mon Jul 20 07:26:46.293772 2026] [security2:error] [pid 145170:tid 145307] [client 103.106.165.44:60403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iFjjs5KUa9I09SwTNfAAAAIk"]
[Mon Jul 20 07:26:46.293907 2026] [security2:error] [pid 145170:tid 145307] [client 103.106.165.44:60403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iFjjs5KUa9I09SwTNfAAAAIk"]
[Mon Jul 20 07:26:46.352065 2026] [security2:error] [pid 145170:tid 145424] [client 201.27.111.74:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iFjjs5KUa9I09SwTNfgAAAP4"]
[Mon Jul 20 07:26:46.352189 2026] [security2:error] [pid 145170:tid 145424] [client 201.27.111.74:64093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iFjjs5KUa9I09SwTNfgAAAP4"]
[Mon Jul 20 07:26:46.406586 2026] [security2:error] [pid 116718:tid 116903] [client 104.234.53.54:54487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iFpPWlhYV5NwZ9vVhaAAAACc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:46.447478 2026] [security2:error] [pid 145170:tid 145429] [client 14.225.17.146:55337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4iFjjs5KUa9I09SwTNgQAAAQM"], referer: http://nikkidesigns.net/test
[Mon Jul 20 07:26:46.510842 2026] [security2:error] [pid 145170:tid 145381] [client 77.110.127.138:49375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iFjjs5KUa9I09SwTNjAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:46.511027 2026] [security2:error] [pid 145170:tid 145381] [client 77.110.127.138:49375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iFjjs5KUa9I09SwTNjAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:46.531467 2026] [security2:error] [pid 145170:tid 145270] [remote 72.167.132.114:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iFjjs5KUa9I09SwTNiwABAGA"]
[Mon Jul 20 07:26:46.580990 2026] [security2:error] [pid 145170:tid 145315] [client 14.225.17.146:55222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4iFjjs5KUa9I09SwTNcAAAAJE"], referer: http://gearwaterproof.com/test
[Mon Jul 20 07:26:46.743179 2026] [security2:error] [pid 145170:tid 145271] [remote 72.167.132.114:39862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iFjjs5KUa9I09SwTNlAAA4GE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:46.906234 2026] [security2:error] [pid 116718:tid 116867] [client 57.141.18.2:30670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iEZPWlhYV5NwZ9vVgwQAAAws"]
[Mon Jul 20 07:26:47.073503 2026] [security2:error] [pid 145170:tid 145344] [client 74.7.230.46:42092] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "pscmedicalbilling.com"] [uri "/robots.txt"] [unique_id "al4iFzjs5KUa9I09SwTNvQAArgE"]
[Mon Jul 20 07:26:48.000291 2026] [security2:error] [pid 145170:tid 145345] [client 13.233.207.33:40420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4iFzjs5KUa9I09SwTN7wAAAK8"]
[Mon Jul 20 07:26:48.473041 2026] [security2:error] [pid 145170:tid 145419] [client 191.202.66.27:57328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iGDjs5KUa9I09SwTOBwAAAPk"]
[Mon Jul 20 07:26:48.473138 2026] [security2:error] [pid 145170:tid 145419] [client 191.202.66.27:57328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iGDjs5KUa9I09SwTOBwAAAPk"]
[Mon Jul 20 07:26:48.547863 2026] [security2:error] [pid 116718:tid 116783] [remote 173.249.4.11:33972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iGJPWlhYV5NwZ9vVhuwAAbDA"]
[Mon Jul 20 07:26:48.654829 2026] [security2:error] [pid 145170:tid 145352] [client 88.241.67.160:56888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iGDjs5KUa9I09SwTODAAAALY"]
[Mon Jul 20 07:26:48.655085 2026] [security2:error] [pid 145170:tid 145352] [client 88.241.67.160:56888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iGDjs5KUa9I09SwTODAAAALY"]
[Mon Jul 20 07:26:48.983471 2026] [security2:error] [pid 116718:tid 116962] [client 43.205.139.3:21552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4iGJPWlhYV5NwZ9vVhyQAAAGI"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:26:49.102795 2026] [security2:error] [pid 116718:tid 116793] [remote 173.249.4.11:33972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iGZPWlhYV5NwZ9vVh1AAAcDo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:49.323709 2026] [security2:error] [pid 145170:tid 145340] [client 179.127.84.238:58706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iGTjs5KUa9I09SwTOWQAAAKo"]
[Mon Jul 20 07:26:49.323813 2026] [security2:error] [pid 145170:tid 145340] [client 179.127.84.238:58706] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iGTjs5KUa9I09SwTOWQAAAKo"]
[Mon Jul 20 07:26:49.344332 2026] [proxy:error] [pid 116718:tid 116906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:49.344393 2026] [proxy_http:error] [pid 116718:tid 116906] [client 198.235.24.35:61046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:49.345005 2026] [proxy:error] [pid 116718:tid 116906] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:49.345032 2026] [proxy_http:error] [pid 116718:tid 116906] [client 198.235.24.35:61046] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:49.398769 2026] [security2:error] [pid 145170:tid 145408] [client 14.225.17.146:49167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4iGDjs5KUa9I09SwTOGAAAAO4"]
[Mon Jul 20 07:26:49.711772 2026] [security2:error] [pid 145170:tid 145341] [client 57.141.18.102:44152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iFDjs5KUa9I09SwTNGQAAq0g"]
[Mon Jul 20 07:26:49.751002 2026] [security2:error] [pid 116718:tid 116749] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iGZPWlhYV5NwZ9vVh8AAAVQ4"]
[Mon Jul 20 07:26:49.751156 2026] [security2:error] [pid 116718:tid 116949] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iGZPWlhYV5NwZ9vVh8AAAVQ4"]
[Mon Jul 20 07:26:49.774019 2026] [security2:error] [pid 145170:tid 145355] [client 57.141.18.79:45286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iFDjs5KUa9I09SwTNHQAAuUY"]
[Mon Jul 20 07:26:49.898473 2026] [security2:error] [pid 116718:tid 116963] [client 77.110.127.138:49397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iGZPWlhYV5NwZ9vVh-QAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:49.898618 2026] [security2:error] [pid 116718:tid 116963] [client 77.110.127.138:49397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iGZPWlhYV5NwZ9vVh-QAAAGM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:49.958493 2026] [security2:error] [pid 116718:tid 116870] [client 98.159.234.160:50601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iGZPWlhYV5NwZ9vViAAAAAAY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:26:50.105875 2026] [core:error] [pid 116718:tid 116900] [client 14.225.17.146:63474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:50.105899 2026] [core:error] [pid 116718:tid 116900] [client 14.225.17.146:63474] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:50.242490 2026] [security2:error] [pid 145170:tid 145251] [remote 57.141.18.12:61422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4014294"] [unique_id "al4iGjjs5KUa9I09SwTOjgAA5k0"]
[Mon Jul 20 07:26:50.307367 2026] [security2:error] [pid 145170:tid 145253] [remote 68.178.160.25:42196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4iGjjs5KUa9I09SwTOkgAAkU8"]
[Mon Jul 20 07:26:50.310617 2026] [security2:error] [pid 116718:tid 116971] [client 74.7.241.155:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hwa.hne.mybluehost.me"] [uri "/index.php"] [unique_id "al4iGJPWlhYV5NwZ9vVhsQAAAGs"]
[Mon Jul 20 07:26:50.315252 2026] [security2:error] [pid 145170:tid 145325] [client 74.7.241.155:54682] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "hwa.hne.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4iGDjs5KUa9I09SwTN9QAAm2k"]
[Mon Jul 20 07:26:50.400880 2026] [security2:error] [pid 145170:tid 145344] [client 14.225.17.146:55204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4iGjjs5KUa9I09SwTOjwAAAK4"]
[Mon Jul 20 07:26:50.440034 2026] [security2:error] [pid 116718:tid 116933] [client 57.141.18.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iGpPWlhYV5NwZ9vViGQAAAEU"]
[Mon Jul 20 07:26:50.579203 2026] [security2:error] [pid 145170:tid 145388] [client 173.239.254.14:43261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4iGjjs5KUa9I09SwTOmQAAANo"]
[Mon Jul 20 07:26:50.739285 2026] [security2:error] [pid 145170:tid 145177] [remote 68.178.160.25:42196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.160.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4iGjjs5KUa9I09SwTOoQAA3wM"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:26:50.816305 2026] [security2:error] [pid 145170:tid 145382] [client 157.20.138.62:58917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iGjjs5KUa9I09SwTOqQAAANQ"]
[Mon Jul 20 07:26:50.816450 2026] [security2:error] [pid 145170:tid 145382] [client 157.20.138.62:58917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iGjjs5KUa9I09SwTOqQAAANQ"]
[Mon Jul 20 07:26:50.917472 2026] [security2:error] [pid 145170:tid 145376] [client 14.225.17.146:63477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4iGTjs5KUa9I09SwTOcAAAAM4"], referer: http://blaizeaccountingservices.com/test
[Mon Jul 20 07:26:51.368551 2026] [security2:error] [pid 116718:tid 116928] [client 154.192.123.127:17971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iG5PWlhYV5NwZ9vViTAAAAEA"]
[Mon Jul 20 07:26:51.368719 2026] [security2:error] [pid 116718:tid 116928] [client 154.192.123.127:17971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iG5PWlhYV5NwZ9vViTAAAAEA"]
[Mon Jul 20 07:26:51.460689 2026] [security2:error] [pid 145170:tid 145310] [client 57.141.18.4:54046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iFjjs5KUa9I09SwTNcgAAjFc"]
[Mon Jul 20 07:26:51.484478 2026] [security2:error] [pid 145170:tid 145198] [remote 81.173.115.7:38620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iGzjs5KUa9I09SwTO0wAA-Rg"]
[Mon Jul 20 07:26:51.484604 2026] [security2:error] [pid 145170:tid 145419] [client 81.173.115.7:38620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iGzjs5KUa9I09SwTO0wAA-Rg"]
[Mon Jul 20 07:26:51.766040 2026] [security2:error] [pid 116718:tid 116950] [client 57.141.18.85:38130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iFpPWlhYV5NwZ9vVhbAAAVgE"]
[Mon Jul 20 07:26:52.237374 2026] [security2:error] [pid 116718:tid 116859] [remote 45.150.79.142:34496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iHJPWlhYV5NwZ9vVicAAAMnw"]
[Mon Jul 20 07:26:52.263462 2026] [security2:error] [pid 145170:tid 145326] [client 57.141.18.76:25536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iFzjs5KUa9I09SwTNzwAAnBI"]
[Mon Jul 20 07:26:52.410865 2026] [security2:error] [pid 116718:tid 116756] [remote 45.150.79.142:34496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vyx.sbv.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iHJPWlhYV5NwZ9vVifAAAXRU"], referer: https://vyx.sbv.mybluehost.me/wp-login.php
[Mon Jul 20 07:26:52.564007 2026] [security2:error] [pid 116718:tid 116901] [client 149.202.52.184:58664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4iHJPWlhYV5NwZ9vViewAAACU"]
[Mon Jul 20 07:26:52.977611 2026] [security2:error] [pid 145170:tid 145413] [client 50.116.65.227:58656] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iHDjs5KUa9I09SwTPHgAAAPM"]
[Mon Jul 20 07:26:52.987480 2026] [security2:error] [pid 145170:tid 145341] [client 50.116.65.227:58670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iHDjs5KUa9I09SwTPHwAAAKs"]
[Mon Jul 20 07:26:53.055257 2026] [security2:error] [pid 145170:tid 145418] [client 3.67.192.83:56556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4iHTjs5KUa9I09SwTPIQAAAPg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:26:53.188950 2026] [security2:error] [pid 145170:tid 145359] [client 104.234.53.59:20085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iHTjs5KUa9I09SwTPLQAAAL0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:53.343806 2026] [security2:error] [pid 145170:tid 145409] [client 77.110.127.138:49413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPNAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.343893 2026] [security2:error] [pid 145170:tid 145409] [client 77.110.127.138:49413] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPNAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.394297 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:49339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHZPWlhYV5NwZ9vVinQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.394395 2026] [security2:error] [pid 116718:tid 116883] [client 77.110.127.138:49339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHZPWlhYV5NwZ9vVinQAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.440508 2026] [security2:error] [pid 145170:tid 145389] [client 149.202.48.220:46962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4iHTjs5KUa9I09SwTPMwAAANs"]
[Mon Jul 20 07:26:53.444815 2026] [security2:error] [pid 145170:tid 145425] [client 77.110.127.138:49407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPPwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.444958 2026] [security2:error] [pid 145170:tid 145425] [client 77.110.127.138:49407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPPwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.502892 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:49330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHZPWlhYV5NwZ9vVipQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.503011 2026] [security2:error] [pid 116718:tid 116933] [client 77.110.127.138:49330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHZPWlhYV5NwZ9vVipQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.515891 2026] [security2:error] [pid 116718:tid 116747] [remote 117.0.21.154:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iHZPWlhYV5NwZ9vVipwAAUgw"]
[Mon Jul 20 07:26:53.557230 2026] [security2:error] [pid 145170:tid 145415] [client 77.110.127.138:49382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPRQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.557354 2026] [security2:error] [pid 145170:tid 145415] [client 77.110.127.138:49382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPRQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:53.610831 2026] [security2:error] [pid 145170:tid 145430] [client 77.110.127.138:49384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPSQAAAQQ"]
[Mon Jul 20 07:26:53.610949 2026] [security2:error] [pid 145170:tid 145430] [client 77.110.127.138:49384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPSQAAAQQ"]
[Mon Jul 20 07:26:53.661018 2026] [security2:error] [pid 145170:tid 145351] [client 77.110.127.138:49304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPTwAAALU"]
[Mon Jul 20 07:26:53.661125 2026] [security2:error] [pid 145170:tid 145351] [client 77.110.127.138:49304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iHTjs5KUa9I09SwTPTwAAALU"]
[Mon Jul 20 07:26:53.813023 2026] [cgid:error] [pid 145170:tid 145359] [client 185.147.157.29:54164] AH01265: stderr from /home4/safesys1/public_html/sitioweb/cgi-bin/: attempt to invoke directory as script
[Mon Jul 20 07:26:53.914519 2026] [security2:error] [pid 145170:tid 145377] [client 49.47.218.174:58138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iHTjs5KUa9I09SwTPXAAAAM8"]
[Mon Jul 20 07:26:53.914655 2026] [security2:error] [pid 145170:tid 145377] [client 49.47.218.174:58138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iHTjs5KUa9I09SwTPXAAAAM8"]
[Mon Jul 20 07:26:53.954093 2026] [security2:error] [pid 116718:tid 116871] [client 51.89.167.163:57306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4iHZPWlhYV5NwZ9vVitQAAAAc"]
[Mon Jul 20 07:26:54.028976 2026] [security2:error] [pid 116718:tid 116764] [remote 117.0.21.154:59028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.21.0.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iHpPWlhYV5NwZ9vViuwAAMR0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:26:54.077242 2026] [security2:error] [pid 145170:tid 145414] [client 57.141.18.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iHTjs5KUa9I09SwTPXgAAAPQ"]
[Mon Jul 20 07:26:54.087819 2026] [security2:error] [pid 145170:tid 145237] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iHjjs5KUa9I09SwTPYwAA2z8"]
[Mon Jul 20 07:26:54.087990 2026] [security2:error] [pid 145170:tid 145389] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iHjjs5KUa9I09SwTPYwAA2z8"]
[Mon Jul 20 07:26:54.241439 2026] [security2:error] [pid 145170:tid 145371] [client 14.225.17.146:63945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4iHTjs5KUa9I09SwTPIgAAAMk"], referer: http://northbrookcpa.ca/test
[Mon Jul 20 07:26:54.448863 2026] [security2:error] [pid 145170:tid 145408] [client 14.225.17.146:63611] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4iHjjs5KUa9I09SwTPbAAAAO4"], referer: http://sarahsnyder.net/test
[Mon Jul 20 07:26:54.523193 2026] [security2:error] [pid 116718:tid 116987] [client 114.119.148.64:36631] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/robots.txt"] [unique_id "al4iHpPWlhYV5NwZ9vViywAAAHs"], referer: https://www.guidehunting.com/robots.txt
[Mon Jul 20 07:26:54.594613 2026] [security2:error] [pid 145170:tid 145404] [client 57.141.18.87:41590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iGTjs5KUa9I09SwTOdQAA6nY"]
[Mon Jul 20 07:26:54.859340 2026] [security2:error] [pid 145170:tid 145345] [client 57.141.18.74:49190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iGjjs5KUa9I09SwTOhQAAr30"]
[Mon Jul 20 07:26:54.919343 2026] [security2:error] [pid 116718:tid 116981] [client 57.141.18.32:48240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iGpPWlhYV5NwZ9vViBgAAdSk"]
[Mon Jul 20 07:26:54.992292 2026] [security2:error] [pid 145170:tid 145392] [client 14.225.17.146:63930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4iHTjs5KUa9I09SwTPIAAAAN4"], referer: http://securingmemories.com/test
[Mon Jul 20 07:26:55.032356 2026] [security2:error] [pid 116718:tid 116919] [client 14.225.17.146:65459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "dasmarque.com"] [uri "/index.php"] [unique_id "al4iHpPWlhYV5NwZ9vVi6QAAADc"], referer: http://dasmarque.com/test
[Mon Jul 20 07:26:55.042312 2026] [security2:error] [pid 145170:tid 145238] [remote 188.166.241.141:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4iHzjs5KUa9I09SwTPfwAArEA"]
[Mon Jul 20 07:26:55.128633 2026] [core:error] [pid 116718:tid 116916] [client 205.210.31.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:55.128655 2026] [core:error] [pid 116718:tid 116916] [client 205.210.31.18:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:26:55.352768 2026] [security2:error] [pid 145170:tid 145414] [client 117.211.236.168:53872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iHzjs5KUa9I09SwTPlgAAAPQ"]
[Mon Jul 20 07:26:55.352892 2026] [security2:error] [pid 145170:tid 145414] [client 117.211.236.168:53872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iHzjs5KUa9I09SwTPlgAAAPQ"]
[Mon Jul 20 07:26:55.367587 2026] [security2:error] [pid 145170:tid 145372] [client 36.93.152.155:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iHzjs5KUa9I09SwTPlwAAAMo"]
[Mon Jul 20 07:26:55.367706 2026] [security2:error] [pid 145170:tid 145372] [client 36.93.152.155:54060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iHzjs5KUa9I09SwTPlwAAAMo"]
[Mon Jul 20 07:26:55.392549 2026] [security2:error] [pid 145170:tid 145325] [client 14.225.17.146:54917] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4iHzjs5KUa9I09SwTPjQAAAJs"], referer: http://dadanetnet.net/test
[Mon Jul 20 07:26:55.417979 2026] [security2:error] [pid 145170:tid 145203] [remote 188.166.241.141:60650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4iHzjs5KUa9I09SwTPngABBB0"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:26:55.431078 2026] [security2:error] [pid 145170:tid 145358] [client 14.225.17.146:54955] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4iHzjs5KUa9I09SwTPjgAAALw"], referer: https://sarahsnyder.net/test
[Mon Jul 20 07:26:55.520966 2026] [security2:error] [pid 145170:tid 145426] [client 57.141.18.12:20184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iGjjs5KUa9I09SwTOrQABAAY"]
[Mon Jul 20 07:26:55.810588 2026] [security2:error] [pid 145170:tid 145336] [client 103.176.215.66:63238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iHzjs5KUa9I09SwTPvgAAAKY"]
[Mon Jul 20 07:26:55.810683 2026] [security2:error] [pid 145170:tid 145336] [client 103.176.215.66:63238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iHzjs5KUa9I09SwTPvgAAAKY"]
[Mon Jul 20 07:26:55.964984 2026] [security2:error] [pid 145170:tid 145311] [client 94.21.88.188:51366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "operationmountaintop.org"] [uri "/"] [unique_id "al4iHzjs5KUa9I09SwTPywAAAI0"]
[Mon Jul 20 07:26:56.202726 2026] [security2:error] [pid 145170:tid 145323] [client 104.234.53.62:44641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iIDjs5KUa9I09SwTP4AAAAJk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:26:56.430789 2026] [proxy:error] [pid 145170:tid 145356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:56.430827 2026] [proxy_http:error] [pid 145170:tid 145356] [client 205.210.31.18:61106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:56.431457 2026] [proxy:error] [pid 145170:tid 145356] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:26:56.431493 2026] [proxy_http:error] [pid 145170:tid 145356] [client 205.210.31.18:61106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:26:56.566223 2026] [security2:error] [pid 145170:tid 145418] [client 47.128.60.180:60712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "longevityperformanceclinic.com"] [uri "/robots.txt"] [unique_id "al4iIDjs5KUa9I09SwTQBQAAAPg"]
[Mon Jul 20 07:26:56.567122 2026] [security2:error] [pid 116718:tid 116930] [client 14.225.17.146:55120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4iH5PWlhYV5NwZ9vVi8QAAAEI"], referer: http://ghivs.com/test
[Mon Jul 20 07:26:56.656363 2026] [security2:error] [pid 145170:tid 145336] [client 143.44.185.218:56918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQDQAAAKY"]
[Mon Jul 20 07:26:56.656474 2026] [security2:error] [pid 145170:tid 145336] [client 143.44.185.218:56918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQDQAAAKY"]
[Mon Jul 20 07:26:56.667323 2026] [security2:error] [pid 145170:tid 145351] [client 136.158.60.21:39783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQDgAAALU"]
[Mon Jul 20 07:26:56.667894 2026] [security2:error] [pid 145170:tid 145351] [client 136.158.60.21:39783] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQDgAAALU"]
[Mon Jul 20 07:26:56.729391 2026] [security2:error] [pid 116718:tid 116768] [remote 57.141.18.40:40170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iHJPWlhYV5NwZ9vVicwAAESE"]
[Mon Jul 20 07:26:56.743714 2026] [security2:error] [pid 145170:tid 145406] [client 201.27.111.74:64584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQFgAAAOw"]
[Mon Jul 20 07:26:56.747402 2026] [security2:error] [pid 145170:tid 145406] [client 201.27.111.74:64584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQFgAAAOw"]
[Mon Jul 20 07:26:56.796910 2026] [security2:error] [pid 145170:tid 145353] [client 103.106.165.44:60888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQHAAAALc"]
[Mon Jul 20 07:26:56.797020 2026] [security2:error] [pid 145170:tid 145353] [client 103.106.165.44:60888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iIDjs5KUa9I09SwTQHAAAALc"]
[Mon Jul 20 07:26:56.839170 2026] [security2:error] [pid 116718:tid 116740] [remote 57.141.18.18:35796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iHJPWlhYV5NwZ9vViegAAfAU"]
[Mon Jul 20 07:26:56.880156 2026] [security2:error] [pid 116718:tid 116914] [client 14.225.17.146:54909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4iH5PWlhYV5NwZ9vVi8wAAADI"], referer: http://lelandumc.org/test
[Mon Jul 20 07:26:57.096705 2026] [security2:error] [pid 145170:tid 145340] [client 112.82.218.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4iIDjs5KUa9I09SwTQEQAAAKo"]
[Mon Jul 20 07:26:57.177447 2026] [security2:error] [pid 145170:tid 145363] [client 14.225.17.146:55063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4iITjs5KUa9I09SwTQLQAAAME"], referer: http://reosportsboats.com/test
[Mon Jul 20 07:26:57.281647 2026] [security2:error] [pid 145170:tid 145189] [remote 160.187.68.132:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iITjs5KUa9I09SwTQPQAAww8"]
[Mon Jul 20 07:26:57.313580 2026] [security2:error] [pid 145170:tid 145315] [client 154.208.48.130:60836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iITjs5KUa9I09SwTQPwAAAJE"]
[Mon Jul 20 07:26:57.313688 2026] [security2:error] [pid 145170:tid 145315] [client 154.208.48.130:60836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iITjs5KUa9I09SwTQPwAAAJE"]
[Mon Jul 20 07:26:57.420994 2026] [security2:error] [pid 145170:tid 145376] [client 77.110.127.138:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iITjs5KUa9I09SwTQTwAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:57.421073 2026] [security2:error] [pid 145170:tid 145376] [client 77.110.127.138:49423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iITjs5KUa9I09SwTQTwAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:26:57.841569 2026] [security2:error] [pid 116718:tid 116825] [remote 57.141.18.66:53698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iHZPWlhYV5NwZ9vVinAAAVlo"]
[Mon Jul 20 07:26:57.891355 2026] [security2:error] [pid 116718:tid 116795] [remote 47.86.33.52:53442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iIZPWlhYV5NwZ9vVi9QAAADw"]
[Mon Jul 20 07:26:57.891603 2026] [security2:error] [pid 116718:tid 116864] [client 47.86.33.52:53442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iIZPWlhYV5NwZ9vVi9QAAADw"]
[Mon Jul 20 07:26:57.901144 2026] [security2:error] [pid 145170:tid 145351] [client 57.141.18.60:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iITjs5KUa9I09SwTQaAAAALU"]
[Mon Jul 20 07:26:57.966891 2026] [security2:error] [pid 145170:tid 145298] [remote 160.187.68.132:46848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iITjs5KUa9I09SwTQfQAA6nw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:26:58.130838 2026] [security2:error] [pid 145170:tid 145336] [client 14.225.17.146:54931] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4iIjjs5KUa9I09SwTQfwAAAKY"], referer: https://reosportsboats.com/test
[Mon Jul 20 07:26:59.046673 2026] [security2:error] [pid 145170:tid 145387] [client 191.202.66.27:57812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iIzjs5KUa9I09SwTQwwAAANk"]
[Mon Jul 20 07:26:59.046825 2026] [security2:error] [pid 145170:tid 145387] [client 191.202.66.27:57812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iIzjs5KUa9I09SwTQwwAAANk"]
[Mon Jul 20 07:26:59.151396 2026] [security2:error] [pid 145170:tid 145341] [client 88.241.67.160:57142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iIzjs5KUa9I09SwTQywAAAKs"]
[Mon Jul 20 07:26:59.151883 2026] [security2:error] [pid 145170:tid 145341] [client 88.241.67.160:57142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iIzjs5KUa9I09SwTQywAAAKs"]
[Mon Jul 20 07:26:59.254305 2026] [security2:error] [pid 145170:tid 145306] [client 14.225.17.146:53248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iIzjs5KUa9I09SwTQxgAAAIg"], referer: http://mezzacraft.com/test
[Mon Jul 20 07:26:59.402835 2026] [security2:error] [pid 145170:tid 145369] [client 57.141.18.40:40180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iHzjs5KUa9I09SwTPfgAAx0s"]
[Mon Jul 20 07:26:59.454531 2026] [security2:error] [pid 145170:tid 145374] [client 57.141.18.71:44660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iHzjs5KUa9I09SwTPgAAAzCI"]
[Mon Jul 20 07:26:59.747388 2026] [security2:error] [pid 145170:tid 145316] [client 114.119.156.193:24981] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/v/vspfiles/templates/105/css/Imports.css"] [unique_id "al4iIzjs5KUa9I09SwTQ-QAAAJI"], referer: https://www.sarakety.com/v/vspfiles/templates/105/css/Imports.css
[Mon Jul 20 07:26:59.830968 2026] [security2:error] [pid 145170:tid 145356] [client 14.225.17.146:54198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4iIjjs5KUa9I09SwTQkQAAALo"]
[Mon Jul 20 07:27:00.018773 2026] [security2:error] [pid 145170:tid 145309] [client 179.127.84.238:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iJDjs5KUa9I09SwTREQAAAIs"]
[Mon Jul 20 07:27:00.018865 2026] [security2:error] [pid 145170:tid 145309] [client 179.127.84.238:59238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iJDjs5KUa9I09SwTREQAAAIs"]
[Mon Jul 20 07:27:00.257382 2026] [security2:error] [pid 145170:tid 145274] [remote 57.141.18.66:39212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3056461"] [unique_id "al4iJDjs5KUa9I09SwTRIAAA8GQ"]
[Mon Jul 20 07:27:00.301133 2026] [security2:error] [pid 145170:tid 145337] [client 57.141.18.38:57412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iIDjs5KUa9I09SwTP3AAAp0Q"]
[Mon Jul 20 07:27:00.391371 2026] [security2:error] [pid 145170:tid 145245] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iJDjs5KUa9I09SwTRMAAAxEc"]
[Mon Jul 20 07:27:00.391535 2026] [security2:error] [pid 145170:tid 145366] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iJDjs5KUa9I09SwTRMAAAxEc"]
[Mon Jul 20 07:27:00.701981 2026] [security2:error] [pid 145170:tid 145419] [client 14.251.3.155:56048] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4iJDjs5KUa9I09SwTRSwAAAPk"]
[Mon Jul 20 07:27:00.981136 2026] [security2:error] [pid 145170:tid 145303] [client 57.141.18.122:38804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iIDjs5KUa9I09SwTQJwAAhQA"]
[Mon Jul 20 07:27:01.240441 2026] [security2:error] [pid 145170:tid 145396] [client 50.116.65.227:26406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4iJDjs5KUa9I09SwTRSAAAAOI"]
[Mon Jul 20 07:27:01.338067 2026] [security2:error] [pid 145170:tid 145403] [client 157.20.138.62:59485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iJTjs5KUa9I09SwTRgAAAAOk"]
[Mon Jul 20 07:27:01.338179 2026] [security2:error] [pid 145170:tid 145403] [client 157.20.138.62:59485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iJTjs5KUa9I09SwTRgAAAAOk"]
[Mon Jul 20 07:27:01.944140 2026] [security2:error] [pid 145170:tid 145325] [client 50.116.65.227:26418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4iJTjs5KUa9I09SwTRdwAAAJs"]
[Mon Jul 20 07:27:01.995492 2026] [security2:error] [pid 145170:tid 145365] [client 77.110.127.138:49437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJTjs5KUa9I09SwTRrgAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:01.995635 2026] [security2:error] [pid 145170:tid 145365] [client 77.110.127.138:49437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJTjs5KUa9I09SwTRrgAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.001197 2026] [security2:error] [pid 145170:tid 145367] [client 57.141.18.90:59148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iITjs5KUa9I09SwTQagAAxW0"]
[Mon Jul 20 07:27:02.060219 2026] [security2:error] [pid 145170:tid 145362] [client 57.141.18.75:60664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iITjs5KUa9I09SwTQawAAwD0"]
[Mon Jul 20 07:27:02.099404 2026] [security2:error] [pid 145170:tid 145403] [client 43.205.139.3:17576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4iJjjs5KUa9I09SwTRvAAAAOk"]
[Mon Jul 20 07:27:02.154085 2026] [security2:error] [pid 145170:tid 145412] [client 77.110.127.138:49441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJjjs5KUa9I09SwTRwAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.154173 2026] [security2:error] [pid 145170:tid 145412] [client 77.110.127.138:49441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJjjs5KUa9I09SwTRwAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.477969 2026] [security2:error] [pid 145170:tid 145377] [client 77.110.127.138:49442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJjjs5KUa9I09SwTR3QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.478088 2026] [security2:error] [pid 145170:tid 145377] [client 77.110.127.138:49442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJjjs5KUa9I09SwTR3QAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.544148 2026] [security2:error] [pid 145170:tid 145376] [client 154.192.123.127:18590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iJjjs5KUa9I09SwTR4gAAAM4"]
[Mon Jul 20 07:27:02.544273 2026] [security2:error] [pid 145170:tid 145376] [client 154.192.123.127:18590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iJjjs5KUa9I09SwTR4gAAAM4"]
[Mon Jul 20 07:27:02.745695 2026] [security2:error] [pid 145170:tid 145423] [client 77.110.127.138:49443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJjjs5KUa9I09SwTR8AAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.745803 2026] [security2:error] [pid 145170:tid 145423] [client 77.110.127.138:49443] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJjjs5KUa9I09SwTR8AAAAP0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:02.970129 2026] [security2:error] [pid 145170:tid 145406] [client 57.141.18.14:23582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iIjjs5KUa9I09SwTQqQAA7DI"]
[Mon Jul 20 07:27:03.018302 2026] [security2:error] [pid 145170:tid 145364] [client 77.110.127.138:49430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJzjs5KUa9I09SwTSBAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:03.018420 2026] [security2:error] [pid 145170:tid 145364] [client 77.110.127.138:49430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJzjs5KUa9I09SwTSBAAAAMI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:03.019514 2026] [security2:error] [pid 145170:tid 145395] [client 57.141.18.81:57590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iIjjs5KUa9I09SwTQugAA4Ts"]
[Mon Jul 20 07:27:03.086318 2026] [security2:error] [pid 145170:tid 145308] [client 43.205.139.3:55052] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4iJzjs5KUa9I09SwTSCgAAAIo"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:27:03.100687 2026] [security2:error] [pid 145170:tid 145330] [client 85.208.96.209:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/wp-admin/admin/dibujos-de-caballos/custom-m14-rifle-stocks.html"] [unique_id "al4iJzjs5KUa9I09SwTSDgAAAKA"]
[Mon Jul 20 07:27:03.100814 2026] [security2:error] [pid 145170:tid 145330] [client 85.208.96.209:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lakelopezonline.com"] [uri "/wp-admin/admin/dibujos-de-caballos/custom-m14-rifle-stocks.html"] [unique_id "al4iJzjs5KUa9I09SwTSDgAAAKA"]
[Mon Jul 20 07:27:03.244844 2026] [security2:error] [pid 145170:tid 145312] [client 57.141.18.38:57426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iIzjs5KUa9I09SwTQxQAAjlk"]
[Mon Jul 20 07:27:03.261064 2026] [security2:error] [pid 145170:tid 145424] [client 77.110.127.138:49434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJzjs5KUa9I09SwTSGQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:03.261166 2026] [security2:error] [pid 145170:tid 145424] [client 77.110.127.138:49434] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJzjs5KUa9I09SwTSGQAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:03.311790 2026] [security2:error] [pid 145170:tid 145359] [client 77.110.127.138:49436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJzjs5KUa9I09SwTSJgAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:03.311897 2026] [security2:error] [pid 145170:tid 145359] [client 77.110.127.138:49436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iJzjs5KUa9I09SwTSJgAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:03.529633 2026] [security2:error] [pid 145170:tid 145307] [client 14.225.17.146:54165] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4iJzjs5KUa9I09SwTSMQAAAIk"], referer: http://709fx.com/test
[Mon Jul 20 07:27:03.617330 2026] [security2:error] [pid 145170:tid 145203] [remote 182.77.62.24:48016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iJzjs5KUa9I09SwTSRgAA-R0"]
[Mon Jul 20 07:27:03.689202 2026] [security2:error] [pid 145170:tid 145341] [client 49.37.242.14:55285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iJzjs5KUa9I09SwTSUgAAAKs"]
[Mon Jul 20 07:27:03.689333 2026] [security2:error] [pid 145170:tid 145341] [client 49.37.242.14:55285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iJzjs5KUa9I09SwTSUgAAAKs"]
[Mon Jul 20 07:27:03.746590 2026] [security2:error] [pid 145170:tid 145348] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4iJzjs5KUa9I09SwTSOwAAslA"], referer: http://aleishapenny.ca/test
[Mon Jul 20 07:27:03.965876 2026] [security2:error] [pid 145170:tid 145420] [client 104.234.53.51:52059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iJzjs5KUa9I09SwTSZgAAAPo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:04.082097 2026] [lsapi:warn] [pid 145170:tid 145421] [client 14.225.17.146:53404] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/test
[Mon Jul 20 07:27:04.082128 2026] [lsapi:warn] [pid 145170:tid 145421] [client 14.225.17.146:53404] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/test
[Mon Jul 20 07:27:04.100289 2026] [security2:error] [pid 145170:tid 145407] [client 14.225.17.146:53411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4iJjjs5KUa9I09SwTR7AAAAO0"], referer: http://chestermonty.com/test
[Mon Jul 20 07:27:04.111374 2026] [security2:error] [pid 145170:tid 145274] [remote 182.77.62.24:48016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ait.afz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iKDjs5KUa9I09SwTScAAAzWQ"], referer: https://mail.ait.afz.mybluehost.me/wp-login.php
[Mon Jul 20 07:27:04.179738 2026] [security2:error] [pid 145170:tid 145333] [client 82.102.27.163:37406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4iKDjs5KUa9I09SwTSdQAAAKM"]
[Mon Jul 20 07:27:04.179869 2026] [security2:error] [pid 145170:tid 145333] [client 82.102.27.163:37406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4iKDjs5KUa9I09SwTSdQAAAKM"]
[Mon Jul 20 07:27:04.236326 2026] [security2:error] [pid 145170:tid 145293] [remote 31.207.36.13:49336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iKDjs5KUa9I09SwTSfwAAt3c"]
[Mon Jul 20 07:27:04.418880 2026] [security2:error] [pid 145170:tid 145250] [remote 31.207.36.13:49336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.36.207.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iKDjs5KUa9I09SwTSjgAAmEw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:27:04.420774 2026] [security2:error] [pid 145170:tid 145352] [client 49.47.218.174:58680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iKDjs5KUa9I09SwTSjQAAALY"]
[Mon Jul 20 07:27:04.420878 2026] [security2:error] [pid 145170:tid 145352] [client 49.47.218.174:58680] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iKDjs5KUa9I09SwTSjQAAALY"]
[Mon Jul 20 07:27:04.510959 2026] [security2:error] [pid 145170:tid 145328] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4iKDjs5KUa9I09SwTSjAAAnl8"], referer: https://aleishapenny.ca/test
[Mon Jul 20 07:27:04.581851 2026] [lsapi:warn] [pid 145170:tid 145415] [client 50.116.65.227:26478] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:27:04.581870 2026] [lsapi:warn] [pid 145170:tid 145415] [client 50.116.65.227:26478] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:27:04.596681 2026] [security2:error] [pid 145170:tid 145421] [client 14.225.17.146:53404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4iJzjs5KUa9I09SwTSQwAAAPs"], referer: http://oswegooperatheater.com/test
[Mon Jul 20 07:27:04.769484 2026] [security2:error] [pid 145170:tid 145279] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iKDjs5KUa9I09SwTSqQAAlGk"]
[Mon Jul 20 07:27:04.769634 2026] [security2:error] [pid 145170:tid 145318] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iKDjs5KUa9I09SwTSqQAAlGk"]
[Mon Jul 20 07:27:04.878533 2026] [security2:error] [pid 145170:tid 145341] [client 47.128.42.218:41712] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sarahholyfield.com"] [uri "/robots.txt"] [unique_id "al4iKDjs5KUa9I09SwTSsQAAAKs"]
[Mon Jul 20 07:27:04.922824 2026] [security2:error] [pid 145170:tid 145309] [client 57.141.18.70:22730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iJDjs5KUa9I09SwTRQQAAi3A"]
[Mon Jul 20 07:27:05.013130 2026] [security2:error] [pid 145170:tid 145409] [client 14.225.17.146:57155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4iKDjs5KUa9I09SwTSswAAAO8"], referer: https://chestermonty.com/test
[Mon Jul 20 07:27:05.436077 2026] [lsapi:warn] [pid 145170:tid 145395] [client 14.225.17.146:56882] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/test
[Mon Jul 20 07:27:05.436092 2026] [lsapi:warn] [pid 145170:tid 145395] [client 14.225.17.146:56882] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/test
[Mon Jul 20 07:27:05.490256 2026] [security2:error] [pid 145170:tid 145395] [client 14.225.17.146:56882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4iKTjs5KUa9I09SwTS5AAAAOE"], referer: https://oswegooperatheater.com/test
[Mon Jul 20 07:27:05.714614 2026] [security2:error] [pid 145170:tid 145337] [client 50.116.65.227:26482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iKTjs5KUa9I09SwTS8gAAAKc"]
[Mon Jul 20 07:27:05.723601 2026] [security2:error] [pid 145170:tid 145338] [client 50.116.65.227:26496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iKTjs5KUa9I09SwTS8wAAAKg"]
[Mon Jul 20 07:27:05.883325 2026] [security2:error] [pid 145170:tid 145391] [client 36.93.152.155:54578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iKTjs5KUa9I09SwTTAgAAAN0"]
[Mon Jul 20 07:27:05.883423 2026] [security2:error] [pid 145170:tid 145391] [client 36.93.152.155:54578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iKTjs5KUa9I09SwTTAgAAAN0"]
[Mon Jul 20 07:27:06.227592 2026] [security2:error] [pid 145170:tid 145369] [client 57.141.18.116:55668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iJjjs5KUa9I09SwTRsQAAxwQ"]
[Mon Jul 20 07:27:06.364901 2026] [security2:error] [pid 145170:tid 145420] [client 103.176.215.66:63776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iKjjs5KUa9I09SwTTHgAAAPo"]
[Mon Jul 20 07:27:06.364993 2026] [security2:error] [pid 145170:tid 145420] [client 103.176.215.66:63776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iKjjs5KUa9I09SwTTHgAAAPo"]
[Mon Jul 20 07:27:06.700458 2026] [security2:error] [pid 145170:tid 145316] [client 104.234.53.51:56491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iKjjs5KUa9I09SwTTNgAAAJI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:06.722971 2026] [security2:error] [pid 145170:tid 145380] [client 14.225.17.146:64815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4iKTjs5KUa9I09SwTS4QAAANI"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/test
[Mon Jul 20 07:27:06.820316 2026] [security2:error] [pid 145170:tid 145411] [client 14.225.17.146:57522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4iKTjs5KUa9I09SwTS_wAAAPE"], referer: http://claysharecon.com/test
[Mon Jul 20 07:27:07.289241 2026] [security2:error] [pid 145170:tid 145322] [client 201.27.111.74:65080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iKzjs5KUa9I09SwTTZgAAAJg"]
[Mon Jul 20 07:27:07.289344 2026] [security2:error] [pid 145170:tid 145322] [client 201.27.111.74:65080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iKzjs5KUa9I09SwTTZgAAAJg"]
[Mon Jul 20 07:27:07.301497 2026] [security2:error] [pid 145170:tid 145370] [client 103.106.165.44:61379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iKzjs5KUa9I09SwTTagAAAMg"]
[Mon Jul 20 07:27:07.301628 2026] [security2:error] [pid 145170:tid 145370] [client 103.106.165.44:61379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iKzjs5KUa9I09SwTTagAAAMg"]
[Mon Jul 20 07:27:07.365909 2026] [security2:error] [pid 145170:tid 145420] [client 136.158.60.21:41369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iKzjs5KUa9I09SwTTdAAAAPo"]
[Mon Jul 20 07:27:07.366033 2026] [security2:error] [pid 145170:tid 145420] [client 136.158.60.21:41369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iKzjs5KUa9I09SwTTdAAAAPo"]
[Mon Jul 20 07:27:07.480320 2026] [security2:error] [pid 145170:tid 145243] [remote 91.142.222.105:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4iKzjs5KUa9I09SwTTegABBEU"]
[Mon Jul 20 07:27:07.534388 2026] [security2:error] [pid 145170:tid 145416] [client 14.225.17.146:57262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4iKzjs5KUa9I09SwTTbgAAAPY"], referer: http://thesoloceos.com/test
[Mon Jul 20 07:27:07.662870 2026] [security2:error] [pid 145170:tid 145349] [client 14.225.17.146:57145] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4iKTjs5KUa9I09SwTS_AAAALM"], referer: http://narv.co/test
[Mon Jul 20 07:27:07.714337 2026] [security2:error] [pid 145170:tid 145248] [remote 91.142.222.105:37988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4iKzjs5KUa9I09SwTTigAAwUo"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:27:07.776800 2026] [security2:error] [pid 145170:tid 145360] [client 14.225.17.146:64158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4iKzjs5KUa9I09SwTThQAAAL4"], referer: http://bbwipartnerconference.com/test
[Mon Jul 20 07:27:07.805540 2026] [security2:error] [pid 145170:tid 145405] [client 77.110.127.138:49444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iKzjs5KUa9I09SwTTlQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:07.805679 2026] [security2:error] [pid 145170:tid 145405] [client 77.110.127.138:49444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iKzjs5KUa9I09SwTTlQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:08.096974 2026] [security2:error] [pid 145170:tid 145346] [client 14.225.17.146:53508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4iKzjs5KUa9I09SwTTpQAAALA"], referer: http://wathenbartlett.co.uk/test
[Mon Jul 20 07:27:08.159345 2026] [security2:error] [pid 145170:tid 145337] [client 45.157.112.60:43389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iLDjs5KUa9I09SwTTugAAAKc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:27:08.308830 2026] [ssl:error] [pid 145170:tid 145377] [client 66.132.224.94:33178] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.cathybuffini.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:27:08.344048 2026] [security2:error] [pid 145170:tid 145308] [client 14.225.17.146:57251] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4iKzjs5KUa9I09SwTTaAAAAIo"], referer: http://ncsynchro.com/test
[Mon Jul 20 07:27:08.442189 2026] [security2:error] [pid 145170:tid 145330] [client 143.44.185.218:58345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iLDjs5KUa9I09SwTT0wAAAKA"]
[Mon Jul 20 07:27:08.442406 2026] [security2:error] [pid 145170:tid 145330] [client 143.44.185.218:58345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iLDjs5KUa9I09SwTT0wAAAKA"]
[Mon Jul 20 07:27:08.466953 2026] [security2:error] [pid 145170:tid 145327] [client 104.234.53.48:56811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iLDjs5KUa9I09SwTT2AAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:08.475490 2026] [security2:error] [pid 145170:tid 145372] [client 14.225.17.146:63104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4iKzjs5KUa9I09SwTTgAAAAMo"], referer: http://headachescarpaltunnelfibromyalgia.com/test
[Mon Jul 20 07:27:08.525743 2026] [security2:error] [pid 145170:tid 145414] [client 154.208.48.130:61374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iLDjs5KUa9I09SwTT3QAAAPQ"]
[Mon Jul 20 07:27:08.525869 2026] [security2:error] [pid 145170:tid 145414] [client 154.208.48.130:61374] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iLDjs5KUa9I09SwTT3QAAAPQ"]
[Mon Jul 20 07:27:08.528111 2026] [security2:error] [pid 145170:tid 145404] [client 14.225.17.146:56844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4iLDjs5KUa9I09SwTTyQAAAOo"], referer: https://thesoloceos.com/test
[Mon Jul 20 07:27:08.683818 2026] [security2:error] [pid 145170:tid 145349] [client 14.225.17.146:63061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4iLDjs5KUa9I09SwTT3AAAALM"], referer: https://narv.co/test
[Mon Jul 20 07:27:09.088453 2026] [security2:error] [pid 145170:tid 145361] [client 14.225.17.146:63951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4iLTjs5KUa9I09SwTT_QAAAL8"], referer: https://wathenbartlett.co.uk/test
[Mon Jul 20 07:27:09.363871 2026] [security2:error] [pid 145170:tid 145358] [client 57.141.18.73:52370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iKDjs5KUa9I09SwTSsAAAvGs"]
[Mon Jul 20 07:27:09.680657 2026] [security2:error] [pid 145170:tid 145376] [client 191.202.66.27:58303] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iLTjs5KUa9I09SwTUOwAAAM4"]
[Mon Jul 20 07:27:09.680769 2026] [security2:error] [pid 145170:tid 145376] [client 191.202.66.27:58303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iLTjs5KUa9I09SwTUOwAAAM4"]
[Mon Jul 20 07:27:09.816659 2026] [core:error] [pid 145170:tid 145370] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:27:09.816680 2026] [core:error] [pid 145170:tid 145370] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:27:09.868599 2026] [security2:error] [pid 145170:tid 145323] [client 88.241.67.160:56759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iLTjs5KUa9I09SwTUVAAAAJk"]
[Mon Jul 20 07:27:09.869374 2026] [security2:error] [pid 145170:tid 145323] [client 88.241.67.160:56759] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iLTjs5KUa9I09SwTUVAAAAJk"]
[Mon Jul 20 07:27:10.025286 2026] [security2:error] [pid 145170:tid 145414] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iLTjs5KUa9I09SwTUQgAAAPQ"], referer: 1'"3000
[Mon Jul 20 07:27:10.326975 2026] [security2:error] [pid 145170:tid 145298] [remote 38.242.157.30:47678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iLjjs5KUa9I09SwTUbwAAr3w"]
[Mon Jul 20 07:27:10.382928 2026] [security2:error] [pid 145170:tid 145351] [client 57.141.18.86:33080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iKTjs5KUa9I09SwTTBQAAtQo"]
[Mon Jul 20 07:27:10.592438 2026] [security2:error] [pid 145170:tid 145176] [remote 38.242.157.30:47678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iLjjs5KUa9I09SwTUjAAAtwI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:27:10.663130 2026] [security2:error] [pid 145170:tid 145426] [client 179.127.84.238:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iLjjs5KUa9I09SwTUkAAAAQA"]
[Mon Jul 20 07:27:10.663236 2026] [security2:error] [pid 145170:tid 145426] [client 179.127.84.238:59741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iLjjs5KUa9I09SwTUkAAAAQA"]
[Mon Jul 20 07:27:10.712132 2026] [security2:error] [pid 145170:tid 145387] [client 104.234.53.79:40179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iLjjs5KUa9I09SwTUkQAAANk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:10.749187 2026] [security2:error] [pid 145170:tid 145358] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iLjjs5KUa9I09SwTUgQAAALw"], referer: 1'"3000
[Mon Jul 20 07:27:10.886636 2026] [proxy:error] [pid 145170:tid 145381] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:27:10.886669 2026] [proxy_http:error] [pid 145170:tid 145381] [client 146.190.123.188:52924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:27:10.887289 2026] [proxy:error] [pid 145170:tid 145381] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:27:10.887312 2026] [proxy_http:error] [pid 145170:tid 145381] [client 146.190.123.188:52924] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:27:10.971325 2026] [proxy:error] [pid 145170:tid 145330] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:27:10.971405 2026] [proxy_http:error] [pid 145170:tid 145330] [client 146.190.123.188:52926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.almaz-aura.com/
[Mon Jul 20 07:27:10.972387 2026] [proxy:error] [pid 145170:tid 145330] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:27:10.972431 2026] [proxy_http:error] [pid 145170:tid 145330] [client 146.190.123.188:52926] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcontacts.almaz-aura.com/
[Mon Jul 20 07:27:11.049401 2026] [security2:error] [pid 145170:tid 145231] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iLzjs5KUa9I09SwTUtgAAnTk"]
[Mon Jul 20 07:27:11.049583 2026] [security2:error] [pid 145170:tid 145327] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iLzjs5KUa9I09SwTUtgAAnTk"]
[Mon Jul 20 07:27:11.201424 2026] [core:error] [pid 145170:tid 145416] [client 146.190.123.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:27:11.201447 2026] [core:error] [pid 145170:tid 145416] [client 146.190.123.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:27:11.208633 2026] [security2:error] [pid 145170:tid 145343] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iLzjs5KUa9I09SwTUtQAAAK0"], referer: 1'"3000
[Mon Jul 20 07:27:11.283563 2026] [security2:error] [pid 145170:tid 145411] [client 77.110.127.138:49471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iLzjs5KUa9I09SwTUxgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:11.283656 2026] [security2:error] [pid 145170:tid 145411] [client 77.110.127.138:49471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iLzjs5KUa9I09SwTUxgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:11.731348 2026] [core:error] [pid 145170:tid 145413] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:27:11.731368 2026] [core:error] [pid 145170:tid 145413] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:27:11.803616 2026] [security2:error] [pid 145170:tid 145259] [remote 130.51.180.8:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4iLzjs5KUa9I09SwTU9QAAiVU"]
[Mon Jul 20 07:27:11.853822 2026] [security2:error] [pid 145170:tid 145260] [remote 57.141.18.69:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5979734"] [unique_id "al4iLzjs5KUa9I09SwTU_QAApFY"]
[Mon Jul 20 07:27:11.854612 2026] [security2:error] [pid 145170:tid 145323] [client 157.20.138.62:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iLzjs5KUa9I09SwTVAAAAAJk"]
[Mon Jul 20 07:27:11.854763 2026] [security2:error] [pid 145170:tid 145323] [client 157.20.138.62:60050] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iLzjs5KUa9I09SwTVAAAAAJk"]
[Mon Jul 20 07:27:11.976180 2026] [security2:error] [pid 145170:tid 145242] [remote 130.51.180.8:55726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4iLzjs5KUa9I09SwTVBQAAsEQ"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:27:12.669131 2026] [security2:error] [pid 145170:tid 145250] [remote 176.56.118.182:40062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iMDjs5KUa9I09SwTVQAAAyEw"]
[Mon Jul 20 07:27:12.669315 2026] [security2:error] [pid 145170:tid 145370] [client 176.56.118.182:40062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iMDjs5KUa9I09SwTVQAAAyEw"]
[Mon Jul 20 07:27:13.110719 2026] [security2:error] [pid 145170:tid 145385] [client 14.225.17.146:53228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4iMDjs5KUa9I09SwTVUwAAANc"], referer: http://laceycaraccident.com/test
[Mon Jul 20 07:27:13.345078 2026] [security2:error] [pid 145170:tid 145289] [remote 57.141.18.40:30090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4iMTjs5KUa9I09SwTVbQAAqnM"]
[Mon Jul 20 07:27:13.553438 2026] [security2:error] [pid 145170:tid 145315] [client 154.192.123.127:17097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iMTjs5KUa9I09SwTVfAAAAJE"]
[Mon Jul 20 07:27:13.553547 2026] [security2:error] [pid 145170:tid 145315] [client 154.192.123.127:17097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iMTjs5KUa9I09SwTVfAAAAJE"]
[Mon Jul 20 07:27:13.593597 2026] [security2:error] [pid 145170:tid 145406] [client 57.141.18.120:39572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iLTjs5KUa9I09SwTUHgAA7DM"]
[Mon Jul 20 07:27:13.639930 2026] [security2:error] [pid 145170:tid 145392] [client 57.141.18.47:48804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iLTjs5KUa9I09SwTUIQAA3gg"]
[Mon Jul 20 07:27:13.645335 2026] [security2:error] [pid 145170:tid 145311] [client 57.141.18.72:50392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iLTjs5KUa9I09SwTUJAAAjQc"]
[Mon Jul 20 07:27:13.868377 2026] [security2:error] [pid 145170:tid 145420] [client 57.141.18.8:59186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iLTjs5KUa9I09SwTUSwAA-gw"]
[Mon Jul 20 07:27:13.917351 2026] [security2:error] [pid 145170:tid 145338] [client 202.141.11.99:55516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iMTjs5KUa9I09SwTVmQAAAKg"]
[Mon Jul 20 07:27:13.917471 2026] [security2:error] [pid 145170:tid 145338] [client 202.141.11.99:55516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iMTjs5KUa9I09SwTVmQAAAKg"]
[Mon Jul 20 07:27:14.459040 2026] [security2:error] [pid 145170:tid 145230] [remote 81.173.115.7:41024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4iMjjs5KUa9I09SwTVvgAAjTg"]
[Mon Jul 20 07:27:14.724580 2026] [security2:error] [pid 145170:tid 145200] [remote 81.173.115.7:41024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4iMjjs5KUa9I09SwTV0AAA3xo"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 07:27:14.865080 2026] [security2:error] [pid 145170:tid 145339] [client 49.47.218.174:59221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iMjjs5KUa9I09SwTV4AAAAKk"]
[Mon Jul 20 07:27:14.865195 2026] [security2:error] [pid 145170:tid 145339] [client 49.47.218.174:59221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iMjjs5KUa9I09SwTV4AAAAKk"]
[Mon Jul 20 07:27:14.868306 2026] [security2:error] [pid 145170:tid 145361] [client 57.141.18.26:44410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iLjjs5KUa9I09SwTUjgAAvy0"]
[Mon Jul 20 07:27:15.350559 2026] [security2:error] [pid 145170:tid 145312] [client 158.173.89.95:41589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iMzjs5KUa9I09SwTWCwAAAI4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:27:15.457552 2026] [security2:error] [pid 145170:tid 145248] [remote 57.141.18.30:20404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4529487"] [unique_id "al4iMzjs5KUa9I09SwTWEgAA8Uo"]
[Mon Jul 20 07:27:15.481293 2026] [security2:error] [pid 145170:tid 145247] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iMzjs5KUa9I09SwTWEwAAikk"]
[Mon Jul 20 07:27:15.481409 2026] [security2:error] [pid 145170:tid 145308] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iMzjs5KUa9I09SwTWEwAAikk"]
[Mon Jul 20 07:27:15.758287 2026] [security2:error] [pid 145170:tid 145208] [remote 173.212.252.15:36280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4iMzjs5KUa9I09SwTWKQAA_yI"]
[Mon Jul 20 07:27:15.883388 2026] [security2:error] [pid 145170:tid 145329] [client 77.110.127.138:49454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iMzjs5KUa9I09SwTWNwAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:15.883478 2026] [security2:error] [pid 145170:tid 145329] [client 77.110.127.138:49454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iMzjs5KUa9I09SwTWNwAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:16.104307 2026] [security2:error] [pid 145170:tid 145267] [remote 5.161.225.162:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4iNDjs5KUa9I09SwTWQQAAhl0"]
[Mon Jul 20 07:27:16.209882 2026] [security2:error] [pid 145170:tid 145216] [remote 173.212.252.15:36280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4iNDjs5KUa9I09SwTWQwAAkio"], referer: https://mail.ncsynchro.com/wp-login.php
[Mon Jul 20 07:27:16.311192 2026] [security2:error] [pid 145170:tid 145285] [remote 5.161.225.162:42596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4iNDjs5KUa9I09SwTWSgAA928"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:27:16.316140 2026] [security2:error] [pid 145170:tid 145351] [client 104.234.53.66:43837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iNDjs5KUa9I09SwTWTgAAALU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:16.387493 2026] [security2:error] [pid 145170:tid 145384] [client 36.93.152.155:55100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iNDjs5KUa9I09SwTWXAAAANY"]
[Mon Jul 20 07:27:16.387596 2026] [security2:error] [pid 145170:tid 145384] [client 36.93.152.155:55100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iNDjs5KUa9I09SwTWXAAAANY"]
[Mon Jul 20 07:27:16.826960 2026] [security2:error] [pid 145170:tid 145399] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iNDjs5KUa9I09SwTWbAAAAOU"]
[Mon Jul 20 07:27:16.964157 2026] [security2:error] [pid 145170:tid 145339] [client 103.176.215.66:64313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iNDjs5KUa9I09SwTWjgAAAKk"]
[Mon Jul 20 07:27:16.964529 2026] [security2:error] [pid 145170:tid 145339] [client 103.176.215.66:64313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iNDjs5KUa9I09SwTWjgAAAKk"]
[Mon Jul 20 07:27:17.074390 2026] [security2:error] [pid 145170:tid 145294] [remote 57.141.18.40:52666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6505477"] [unique_id "al4iNTjs5KUa9I09SwTWkAAA1Hg"]
[Mon Jul 20 07:27:17.157957 2026] [security2:error] [pid 145170:tid 145320] [client 57.141.18.84:25308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iMDjs5KUa9I09SwTVVAAAlmE"]
[Mon Jul 20 07:27:17.401714 2026] [security2:error] [pid 145170:tid 145336] [client 49.37.242.14:55820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iNTjs5KUa9I09SwTWtQAAAKY"]
[Mon Jul 20 07:27:17.401816 2026] [security2:error] [pid 145170:tid 145336] [client 49.37.242.14:55820] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iNTjs5KUa9I09SwTWtQAAAKY"]
[Mon Jul 20 07:27:17.440966 2026] [security2:error] [pid 145170:tid 145380] [client 14.225.17.146:57602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4iNTjs5KUa9I09SwTWoAAAANI"], referer: http://ccsdifference.com/test
[Mon Jul 20 07:27:17.461247 2026] [security2:error] [pid 145170:tid 145425] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iNTjs5KUa9I09SwTWlwAAAP8"]
[Mon Jul 20 07:27:17.791637 2026] [security2:error] [pid 145170:tid 145391] [client 201.27.111.74:49409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iNTjs5KUa9I09SwTW1AAAAN0"]
[Mon Jul 20 07:27:17.791783 2026] [security2:error] [pid 145170:tid 145391] [client 201.27.111.74:49409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iNTjs5KUa9I09SwTW1AAAAN0"]
[Mon Jul 20 07:27:17.887935 2026] [security2:error] [pid 145170:tid 145312] [client 103.106.165.44:61874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iNTjs5KUa9I09SwTW4wAAAI4"]
[Mon Jul 20 07:27:17.888095 2026] [security2:error] [pid 145170:tid 145312] [client 103.106.165.44:61874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iNTjs5KUa9I09SwTW4wAAAI4"]
[Mon Jul 20 07:27:17.906763 2026] [security2:error] [pid 145170:tid 145318] [client 50.116.65.227:59250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4iNTjs5KUa9I09SwTW0AAAAJQ"]
[Mon Jul 20 07:27:18.072985 2026] [security2:error] [pid 145170:tid 145418] [client 136.158.60.21:42987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iNjjs5KUa9I09SwTW9AAAAPg"]
[Mon Jul 20 07:27:18.073114 2026] [security2:error] [pid 145170:tid 145418] [client 136.158.60.21:42987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iNjjs5KUa9I09SwTW9AAAAPg"]
[Mon Jul 20 07:27:18.088809 2026] [security2:error] [pid 145170:tid 145372] [client 50.116.65.227:59256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4iNTjs5KUa9I09SwTW5gAAAMo"]
[Mon Jul 20 07:27:18.127960 2026] [security2:error] [pid 145170:tid 145327] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iNTjs5KUa9I09SwTW4gAAAJ0"]
[Mon Jul 20 07:27:18.205090 2026] [security2:error] [pid 145170:tid 145204] [remote 20.173.88.122:41030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iNjjs5KUa9I09SwTW-AAAnx4"]
[Mon Jul 20 07:27:18.260344 2026] [security2:error] [pid 145170:tid 145344] [client 20.80.88.160:53980] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.64.35"] [uri "/index.cgi"] [unique_id "al4iNjjs5KUa9I09SwTW-wAAAK4"]
[Mon Jul 20 07:27:18.399943 2026] [security2:error] [pid 145170:tid 145386] [client 104.234.53.85:61565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iNjjs5KUa9I09SwTXCwAAANg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:18.479876 2026] [security2:error] [pid 145170:tid 145369] [client 14.225.17.146:61974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4iNjjs5KUa9I09SwTW_wAAAMc"], referer: https://ccsdifference.com/test
[Mon Jul 20 07:27:18.535021 2026] [security2:error] [pid 145170:tid 145200] [remote 20.173.88.122:41030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iNjjs5KUa9I09SwTXGwAAwxo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:27:18.697262 2026] [security2:error] [pid 145170:tid 145354] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iNjjs5KUa9I09SwTXFwAAALg"]
[Mon Jul 20 07:27:18.704270 2026] [security2:error] [pid 145170:tid 145410] [client 117.211.236.168:55070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iNjjs5KUa9I09SwTXKAAAAPA"]
[Mon Jul 20 07:27:18.704374 2026] [security2:error] [pid 145170:tid 145410] [client 117.211.236.168:55070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iNjjs5KUa9I09SwTXKAAAAPA"]
[Mon Jul 20 07:27:19.039142 2026] [security2:error] [pid 145170:tid 145205] [remote 135.125.175.196:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.175.125.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iNjjs5KUa9I09SwTXPwAA-B8"]
[Mon Jul 20 07:27:19.075117 2026] [security2:error] [pid 145170:tid 145193] [remote 160.187.68.132:49966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iNzjs5KUa9I09SwTXTAAA0xM"]
[Mon Jul 20 07:27:19.075402 2026] [security2:error] [pid 145170:tid 145381] [client 160.187.68.132:49966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iNzjs5KUa9I09SwTXTAAA0xM"]
[Mon Jul 20 07:27:19.230002 2026] [security2:error] [pid 145170:tid 145255] [remote 135.125.175.196:49404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 196.175.125.135.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iNzjs5KUa9I09SwTXWAAA3VE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:27:19.246758 2026] [security2:error] [pid 145170:tid 145310] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iNzjs5KUa9I09SwTXRwAAAIw"]
[Mon Jul 20 07:27:19.317717 2026] [security2:error] [pid 145170:tid 145393] [client 57.141.18.9:53890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iMzjs5KUa9I09SwTWDAAA3zE"]
[Mon Jul 20 07:27:19.584746 2026] [security2:error] [pid 145170:tid 145320] [client 154.208.48.130:61918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iNzjs5KUa9I09SwTXdgAAAJY"]
[Mon Jul 20 07:27:19.584864 2026] [security2:error] [pid 145170:tid 145320] [client 154.208.48.130:61918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iNzjs5KUa9I09SwTXdgAAAJY"]
[Mon Jul 20 07:27:19.688996 2026] [security2:error] [pid 145170:tid 145370] [client 74.208.214.194:41150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4iNzjs5KUa9I09SwTXgwAAAMg"]
[Mon Jul 20 07:27:19.696218 2026] [security2:error] [pid 145170:tid 145242] [remote 78.46.157.202:58998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eframiproperties.com"] [uri "/wp-login.php"] [unique_id "al4iNzjs5KUa9I09SwTXgAAAzkQ"]
[Mon Jul 20 07:27:19.792864 2026] [security2:error] [pid 145170:tid 145321] [client 14.225.17.146:61936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4iNjjs5KUa9I09SwTW9gAAAJc"], referer: http://nwcarvingacademy.com/test
[Mon Jul 20 07:27:19.901262 2026] [security2:error] [pid 145170:tid 145180] [remote 78.46.157.202:58998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "eframiproperties.com"] [uri "/wp-login.php"] [unique_id "al4iNzjs5KUa9I09SwTXlAAA_wY"], referer: https://eframiproperties.com/wp-login.php
[Mon Jul 20 07:27:19.902113 2026] [security2:error] [pid 145170:tid 145312] [client 77.110.127.138:49489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iNzjs5KUa9I09SwTXlQAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:19.902201 2026] [security2:error] [pid 145170:tid 145312] [client 77.110.127.138:49489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iNzjs5KUa9I09SwTXlQAAAI4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:19.911828 2026] [security2:error] [pid 145170:tid 145323] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iNzjs5KUa9I09SwTXhAAAAJk"]
[Mon Jul 20 07:27:20.132127 2026] [security2:error] [pid 145170:tid 145309] [client 13.232.231.177:22522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTXsAAAAIs"]
[Mon Jul 20 07:27:20.132223 2026] [security2:error] [pid 145170:tid 145309] [client 13.232.231.177:22522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTXsAAAAIs"]
[Mon Jul 20 07:27:20.320313 2026] [security2:error] [pid 145170:tid 145405] [client 14.225.17.146:50275] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTXtgAAAOs"], referer: http://getgarrison.com/test
[Mon Jul 20 07:27:20.327161 2026] [security2:error] [pid 145170:tid 145400] [client 14.225.17.146:61442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTXrQAAAOY"], referer: http://sesamegreenbeans.com/test
[Mon Jul 20 07:27:20.347107 2026] [security2:error] [pid 145170:tid 145357] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTXowAAALs"]
[Mon Jul 20 07:27:20.455861 2026] [security2:error] [pid 145170:tid 145394] [client 191.202.66.27:58813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTXzgAAAOA"]
[Mon Jul 20 07:27:20.455955 2026] [security2:error] [pid 145170:tid 145394] [client 191.202.66.27:58813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTXzgAAAOA"]
[Mon Jul 20 07:27:20.492876 2026] [security2:error] [pid 145170:tid 145428] [client 88.241.67.160:54060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTX0gAAAQI"]
[Mon Jul 20 07:27:20.493825 2026] [security2:error] [pid 145170:tid 145428] [client 88.241.67.160:54060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTX0gAAAQI"]
[Mon Jul 20 07:27:20.831513 2026] [security2:error] [pid 145170:tid 145415] [client 57.141.18.12:25592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iNDjs5KUa9I09SwTWcgAA9Ww"]
[Mon Jul 20 07:27:20.853605 2026] [security2:error] [pid 145170:tid 145319] [client 14.225.17.146:49783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTX3wAAAJU"], referer: https://nwcarvingacademy.com/test
[Mon Jul 20 07:27:20.918469 2026] [security2:error] [pid 145170:tid 145366] [client 143.44.185.218:59637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTX-AAAAMQ"]
[Mon Jul 20 07:27:20.920530 2026] [security2:error] [pid 145170:tid 145366] [client 143.44.185.218:59637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iODjs5KUa9I09SwTX-AAAAMQ"]
[Mon Jul 20 07:27:20.970467 2026] [security2:error] [pid 145170:tid 145324] [client 158.173.166.181:39773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iODjs5KUa9I09SwTYAAAAAJo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:27:21.024312 2026] [security2:error] [pid 145170:tid 145371] [client 14.225.17.146:61810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTX8QAAAMk"], referer: http://lifeisbetterlakeside.com/test
[Mon Jul 20 07:27:21.063330 2026] [security2:error] [pid 145170:tid 145373] [client 104.234.53.59:40167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iOTjs5KUa9I09SwTYCwAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:21.140321 2026] [security2:error] [pid 145170:tid 145413] [client 14.225.17.146:61641] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTX_gAAAPM"], referer: http://carolinapressurewashers.com/test
[Mon Jul 20 07:27:21.257890 2026] [security2:error] [pid 145170:tid 145189] [remote 182.77.62.24:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4iOTjs5KUa9I09SwTYIgAAkw8"]
[Mon Jul 20 07:27:21.326373 2026] [security2:error] [pid 145170:tid 145352] [client 179.127.84.238:60246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iOTjs5KUa9I09SwTYLwAAALY"]
[Mon Jul 20 07:27:21.326571 2026] [security2:error] [pid 145170:tid 145352] [client 179.127.84.238:60246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iOTjs5KUa9I09SwTYLwAAALY"]
[Mon Jul 20 07:27:21.347702 2026] [security2:error] [pid 145170:tid 145357] [client 14.225.17.146:61391] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4iOTjs5KUa9I09SwTYFwAAALs"], referer: https://sesamegreenbeans.com/test
[Mon Jul 20 07:27:21.544045 2026] [security2:error] [pid 145170:tid 145320] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iOTjs5KUa9I09SwTYJgAAAJY"]
[Mon Jul 20 07:27:21.546530 2026] [security2:error] [pid 145170:tid 145389] [client 57.141.18.38:35152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iNTjs5KUa9I09SwTWpQAA234"]
[Mon Jul 20 07:27:21.720661 2026] [security2:error] [pid 145170:tid 145209] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iOTjs5KUa9I09SwTYVAAA3SM"]
[Mon Jul 20 07:27:21.720856 2026] [security2:error] [pid 145170:tid 145391] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iOTjs5KUa9I09SwTYVAAA3SM"]
[Mon Jul 20 07:27:21.756453 2026] [security2:error] [pid 145170:tid 145201] [remote 182.77.62.24:47082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cloudspacesgroup.com"] [uri "/wp-login.php"] [unique_id "al4iOTjs5KUa9I09SwTYVwAAlxs"], referer: https://cloudspacesgroup.com/wp-login.php
[Mon Jul 20 07:27:21.760657 2026] [security2:error] [pid 145170:tid 145363] [client 113.160.97.242:50851] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4iOTjs5KUa9I09SwTYWQAAAME"]
[Mon Jul 20 07:27:22.202188 2026] [security2:error] [pid 145170:tid 145403] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iOTjs5KUa9I09SwTYZgAAAOk"]
[Mon Jul 20 07:27:22.331744 2026] [security2:error] [pid 145170:tid 145406] [client 14.225.17.146:61302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4iOTjs5KUa9I09SwTYTQAAAOw"], referer: http://alrowad-hub.net/test
[Mon Jul 20 07:27:22.411159 2026] [security2:error] [pid 145170:tid 145366] [client 157.20.138.62:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iOjjs5KUa9I09SwTYigAAAMQ"]
[Mon Jul 20 07:27:22.411288 2026] [security2:error] [pid 145170:tid 145366] [client 157.20.138.62:60651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iOjjs5KUa9I09SwTYigAAAMQ"]
[Mon Jul 20 07:27:22.791318 2026] [security2:error] [pid 145170:tid 145396] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iOjjs5KUa9I09SwTYlgAAAOI"]
[Mon Jul 20 07:27:23.184445 2026] [security2:error] [pid 145170:tid 145247] [remote 152.228.213.32:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4iOzjs5KUa9I09SwTY0wAA7Ek"]
[Mon Jul 20 07:27:23.379846 2026] [security2:error] [pid 145170:tid 145260] [remote 152.228.213.32:48902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "goyalsatyam.com"] [uri "/wp-login.php"] [unique_id "al4iOzjs5KUa9I09SwTY5AAAi1Y"], referer: https://goyalsatyam.com/wp-login.php
[Mon Jul 20 07:27:23.404168 2026] [security2:error] [pid 145170:tid 145388] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iOzjs5KUa9I09SwTYzAAAANo"]
[Mon Jul 20 07:27:23.656256 2026] [security2:error] [pid 145170:tid 145215] [remote 91.142.222.105:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iOzjs5KUa9I09SwTY-gAA6yk"]
[Mon Jul 20 07:27:23.793828 2026] [autoindex:error] [pid 145170:tid 145391] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2016/08/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:27:23.907441 2026] [security2:error] [pid 145170:tid 145207] [remote 91.142.222.105:55196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iOzjs5KUa9I09SwTZEwAAziE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:27:23.986270 2026] [security2:error] [pid 145170:tid 145362] [client 77.110.127.138:49491] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iOzjs5KUa9I09SwTZHgAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:23.986434 2026] [security2:error] [pid 145170:tid 145362] [client 77.110.127.138:49491] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iOzjs5KUa9I09SwTZHgAAAMA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:24.055136 2026] [security2:error] [pid 145170:tid 145305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iOzjs5KUa9I09SwTZEAAAAIc"], referer: 1'"3000
[Mon Jul 20 07:27:24.231691 2026] [security2:error] [pid 145170:tid 145427] [client 154.192.123.127:17495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iPDjs5KUa9I09SwTZNAAAAQE"]
[Mon Jul 20 07:27:24.231807 2026] [security2:error] [pid 145170:tid 145427] [client 154.192.123.127:17495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iPDjs5KUa9I09SwTZNAAAAQE"]
[Mon Jul 20 07:27:24.666635 2026] [security2:error] [pid 145170:tid 145343] [client 50.116.65.227:48340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4iPDjs5KUa9I09SwTZWgAAAK0"]
[Mon Jul 20 07:27:24.669830 2026] [security2:error] [pid 145170:tid 145307] [client 14.225.17.146:65319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4iOzjs5KUa9I09SwTY2wAAAIk"]
[Mon Jul 20 07:27:24.889980 2026] [security2:error] [pid 145170:tid 145339] [client 57.141.18.87:44256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iODjs5KUa9I09SwTXygAAqUc"]
[Mon Jul 20 07:27:25.103330 2026] [security2:error] [pid 145170:tid 145402] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iPDjs5KUa9I09SwTZeAAAAOg"], referer: 1'"3000
[Mon Jul 20 07:27:25.228140 2026] [security2:error] [pid 145170:tid 145383] [client 121.229.156.77:47158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.aosta.nz"] [uri "/"] [unique_id "al4iPTjs5KUa9I09SwTZjwAAANU"]
[Mon Jul 20 07:27:25.228276 2026] [security2:error] [pid 145170:tid 145383] [client 121.229.156.77:47158] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.aosta.nz"] [uri "/"] [unique_id "al4iPTjs5KUa9I09SwTZjwAAANU"]
[Mon Jul 20 07:27:25.557081 2026] [security2:error] [pid 145170:tid 145359] [client 77.110.127.138:49530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iPTjs5KUa9I09SwTZtQAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:25.557189 2026] [security2:error] [pid 145170:tid 145359] [client 77.110.127.138:49530] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iPTjs5KUa9I09SwTZtQAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:25.683788 2026] [security2:error] [pid 145170:tid 145394] [client 158.173.241.141:38453] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4iPTjs5KUa9I09SwTZsQAA4GM"]
[Mon Jul 20 07:27:25.849823 2026] [security2:error] [pid 145170:tid 145407] [client 74.7.227.179:56560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4iPTjs5KUa9I09SwTZwQAA7Rs"], referer: https://tejasenvironmental.com/p=298036
[Mon Jul 20 07:27:25.910918 2026] [security2:error] [pid 145170:tid 145178] [remote 8.217.108.67:9184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iPTjs5KUa9I09SwTZ2AAA-gQ"]
[Mon Jul 20 07:27:25.916281 2026] [security2:error] [pid 145170:tid 145372] [client 57.141.18.44:53466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iOTjs5KUa9I09SwTYMQAAylw"]
[Mon Jul 20 07:27:26.201293 2026] [security2:error] [pid 145170:tid 145323] [client 49.47.218.174:59797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iPjjs5KUa9I09SwTZ7AAAAJk"]
[Mon Jul 20 07:27:26.201406 2026] [security2:error] [pid 145170:tid 145323] [client 49.47.218.174:59797] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iPjjs5KUa9I09SwTZ7AAAAJk"]
[Mon Jul 20 07:27:26.311760 2026] [security2:error] [pid 145170:tid 145218] [remote 8.217.108.67:9184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iPjjs5KUa9I09SwTZ-gAAjCw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:27:26.368327 2026] [security2:error] [pid 145170:tid 145328] [client 50.116.65.227:48342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4iPjjs5KUa9I09SwTaBQAAAJ4"]
[Mon Jul 20 07:27:26.379240 2026] [security2:error] [pid 145170:tid 145363] [client 50.116.65.227:40330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Rakuya-Feature-Image.jpg"] [unique_id "al4iPjjs5KUa9I09SwTaCAAAAQI"]
[Mon Jul 20 07:27:26.601327 2026] [security2:error] [pid 145170:tid 145375] [client 37.195.132.31:60938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4iPjjs5KUa9I09SwTaHAAAAM0"]
[Mon Jul 20 07:27:26.934246 2026] [security2:error] [pid 145170:tid 145338] [client 36.93.152.155:55623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iPjjs5KUa9I09SwTaWgAAAKg"]
[Mon Jul 20 07:27:26.934340 2026] [security2:error] [pid 145170:tid 145338] [client 36.93.152.155:55623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iPjjs5KUa9I09SwTaWgAAAKg"]
[Mon Jul 20 07:27:27.137956 2026] [security2:error] [pid 145170:tid 145408] [client 57.141.18.4:47448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iOjjs5KUa9I09SwTYqQAA7hw"]
[Mon Jul 20 07:27:27.288779 2026] [security2:error] [pid 145170:tid 145228] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iPzjs5KUa9I09SwTacgAApzY"]
[Mon Jul 20 07:27:27.288932 2026] [security2:error] [pid 145170:tid 145337] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iPzjs5KUa9I09SwTacgAApzY"]
[Mon Jul 20 07:27:27.484491 2026] [security2:error] [pid 145170:tid 145380] [client 103.176.215.66:64848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iPzjs5KUa9I09SwTaiwAAANI"]
[Mon Jul 20 07:27:27.484804 2026] [security2:error] [pid 145170:tid 145380] [client 103.176.215.66:64848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iPzjs5KUa9I09SwTaiwAAANI"]
[Mon Jul 20 07:27:27.495581 2026] [security2:error] [pid 145170:tid 145376] [client 3.67.192.83:63302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iPzjs5KUa9I09SwTajAAAAM4"]
[Mon Jul 20 07:27:27.495674 2026] [security2:error] [pid 145170:tid 145376] [client 3.67.192.83:63302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iPzjs5KUa9I09SwTajAAAAM4"]
[Mon Jul 20 07:27:27.876416 2026] [security2:error] [pid 145170:tid 145198] [remote 57.141.18.32:51228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3359665"] [unique_id "al4iPzjs5KUa9I09SwTatAAA2Bg"]
[Mon Jul 20 07:27:27.967648 2026] [security2:error] [pid 145170:tid 145409] [client 57.141.18.84:51840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iOzjs5KUa9I09SwTY_gAA7wY"]
[Mon Jul 20 07:27:28.084175 2026] [security2:error] [pid 145170:tid 145385] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iPzjs5KUa9I09SwTargAAANc"], referer: 1'"3000
[Mon Jul 20 07:27:28.170477 2026] [security2:error] [pid 145170:tid 145374] [client 201.27.111.74:50033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iQDjs5KUa9I09SwTayQAAAMw"]
[Mon Jul 20 07:27:28.170596 2026] [security2:error] [pid 145170:tid 145374] [client 201.27.111.74:50033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iQDjs5KUa9I09SwTayQAAAMw"]
[Mon Jul 20 07:27:28.170734 2026] [security2:error] [pid 145170:tid 145404] [client 104.234.53.48:60959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iQDjs5KUa9I09SwTaywAAAOo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:28.328648 2026] [security2:error] [pid 145170:tid 145425] [client 103.106.165.44:62359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iQDjs5KUa9I09SwTa1AAAAP8"]
[Mon Jul 20 07:27:28.328784 2026] [security2:error] [pid 145170:tid 145425] [client 103.106.165.44:62359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iQDjs5KUa9I09SwTa1AAAAP8"]
[Mon Jul 20 07:27:28.751004 2026] [security2:error] [pid 145170:tid 145366] [client 136.158.60.21:44576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iQDjs5KUa9I09SwTa8gAAAMQ"]
[Mon Jul 20 07:27:28.751127 2026] [security2:error] [pid 145170:tid 145366] [client 136.158.60.21:44576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iQDjs5KUa9I09SwTa8gAAAMQ"]
[Mon Jul 20 07:27:28.913673 2026] [security2:error] [pid 145170:tid 145316] [client 77.110.127.138:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iQDjs5KUa9I09SwTbBQAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:28.913767 2026] [security2:error] [pid 145170:tid 145316] [client 77.110.127.138:49488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iQDjs5KUa9I09SwTbBQAAAJI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:29.115378 2026] [security2:error] [pid 145170:tid 145329] [client 50.116.65.227:44452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iQTjs5KUa9I09SwTbHQAAAJ8"]
[Mon Jul 20 07:27:29.125534 2026] [security2:error] [pid 145170:tid 145402] [client 50.116.65.227:44460] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iQTjs5KUa9I09SwTbHgAAAOg"]
[Mon Jul 20 07:27:29.202140 2026] [security2:error] [pid 145170:tid 145345] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iQDjs5KUa9I09SwTbCgAAAK8"], referer: 1'"3000
[Mon Jul 20 07:27:29.733494 2026] [security2:error] [pid 145170:tid 145394] [client 117.211.236.168:55632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iQTjs5KUa9I09SwTbUwAAAOA"]
[Mon Jul 20 07:27:29.733607 2026] [security2:error] [pid 145170:tid 145394] [client 117.211.236.168:55632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iQTjs5KUa9I09SwTbUwAAAOA"]
[Mon Jul 20 07:27:29.959146 2026] [security2:error] [pid 145170:tid 145207] [remote 57.141.18.107:41238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4iQTjs5KUa9I09SwTbfgABACE"]
[Mon Jul 20 07:27:30.008902 2026] [security2:error] [pid 145170:tid 145256] [remote 202.51.202.242:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iQTjs5KUa9I09SwTbfwAAiFI"]
[Mon Jul 20 07:27:30.162573 2026] [security2:error] [pid 145170:tid 145202] [remote 81.173.115.7:35312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iQjjs5KUa9I09SwTblAAAkhw"]
[Mon Jul 20 07:27:30.162701 2026] [security2:error] [pid 145170:tid 145316] [client 81.173.115.7:35312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iQjjs5KUa9I09SwTblAAAkhw"]
[Mon Jul 20 07:27:30.407235 2026] [security2:error] [pid 145170:tid 145304] [client 154.208.48.130:62444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iQjjs5KUa9I09SwTbpAAAAIY"]
[Mon Jul 20 07:27:30.407351 2026] [security2:error] [pid 145170:tid 145304] [client 154.208.48.130:62444] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iQjjs5KUa9I09SwTbpAAAAIY"]
[Mon Jul 20 07:27:30.846542 2026] [security2:error] [pid 145170:tid 145355] [client 66.249.74.78:62352] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.polishedpicture.thewelloiledlife.com"] [uri "/robots.txt"] [unique_id "al4iQjjs5KUa9I09SwTbzAAAALk"]
[Mon Jul 20 07:27:31.063429 2026] [security2:error] [pid 145170:tid 145415] [client 191.202.66.27:59301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iQzjs5KUa9I09SwTb4wAAAPU"]
[Mon Jul 20 07:27:31.063523 2026] [security2:error] [pid 145170:tid 145415] [client 191.202.66.27:59301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iQzjs5KUa9I09SwTb4wAAAPU"]
[Mon Jul 20 07:27:31.257362 2026] [security2:error] [pid 145170:tid 145379] [client 104.234.53.91:32635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iQzjs5KUa9I09SwTb8AAAANE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:31.258126 2026] [security2:error] [pid 145170:tid 145316] [client 88.241.67.160:55831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iQzjs5KUa9I09SwTb8QAAAJI"]
[Mon Jul 20 07:27:31.258454 2026] [security2:error] [pid 145170:tid 145316] [client 88.241.67.160:55831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iQzjs5KUa9I09SwTb8QAAAJI"]
[Mon Jul 20 07:27:31.464464 2026] [security2:error] [pid 145170:tid 145392] [client 223.109.252.146:37538] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.mezzacraft.com"] [uri "/"] [unique_id "al4iQzjs5KUa9I09SwTcBwAAAN4"]
[Mon Jul 20 07:27:31.464578 2026] [security2:error] [pid 145170:tid 145392] [client 223.109.252.146:37538] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.mezzacraft.com"] [uri "/"] [unique_id "al4iQzjs5KUa9I09SwTcBwAAAN4"]
[Mon Jul 20 07:27:31.524906 2026] [security2:error] [pid 145170:tid 145380] [client 49.37.242.14:56336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iQzjs5KUa9I09SwTcCgAAANI"]
[Mon Jul 20 07:27:31.525069 2026] [security2:error] [pid 145170:tid 145380] [client 49.37.242.14:56336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iQzjs5KUa9I09SwTcCgAAANI"]
[Mon Jul 20 07:27:31.874194 2026] [security2:error] [pid 145170:tid 145281] [remote 202.51.202.242:35512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iQzjs5KUa9I09SwTcIgAAxWs"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:27:32.002174 2026] [security2:error] [pid 145170:tid 145415] [client 179.127.84.238:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTcLgAAAPU"]
[Mon Jul 20 07:27:32.002295 2026] [security2:error] [pid 145170:tid 145415] [client 179.127.84.238:60742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTcLgAAAPU"]
[Mon Jul 20 07:27:32.168679 2026] [security2:error] [pid 145170:tid 145399] [client 14.225.17.146:49727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4iRDjs5KUa9I09SwTcLwAAAOU"], referer: http://soloceos.com/test
[Mon Jul 20 07:27:32.370231 2026] [security2:error] [pid 145170:tid 145416] [client 57.141.18.29:24158] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iPzjs5KUa9I09SwTavQAA9gg"]
[Mon Jul 20 07:27:32.374164 2026] [security2:error] [pid 145170:tid 145236] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTcUAAA2D4"]
[Mon Jul 20 07:27:32.374321 2026] [security2:error] [pid 145170:tid 145386] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTcUAAA2D4"]
[Mon Jul 20 07:27:32.615329 2026] [security2:error] [pid 145170:tid 145345] [client 14.225.17.146:65127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4iQzjs5KUa9I09SwTb4gAAAK8"], referer: http://taskidsvirginia.com/test
[Mon Jul 20 07:27:32.800098 2026] [security2:error] [pid 145170:tid 145322] [client 223.109.252.148:34502] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/sectors/"] [unique_id "al4iRDjs5KUa9I09SwTcbgAAAJg"]
[Mon Jul 20 07:27:32.800189 2026] [security2:error] [pid 145170:tid 145322] [client 223.109.252.148:34502] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ccsdifference.com"] [uri "/sectors/"] [unique_id "al4iRDjs5KUa9I09SwTcbgAAAJg"]
[Mon Jul 20 07:27:32.896439 2026] [security2:error] [pid 145170:tid 145320] [client 157.20.138.62:61223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTciwAAAJY"]
[Mon Jul 20 07:27:32.897151 2026] [security2:error] [pid 145170:tid 145320] [client 157.20.138.62:61223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTciwAAAJY"]
[Mon Jul 20 07:27:32.920017 2026] [security2:error] [pid 145170:tid 145356] [client 77.110.127.138:49543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/thread-crochet/qxvx21cvmmg6.php"] [unique_id "al4iRDjs5KUa9I09SwTckwAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:32.939859 2026] [security2:error] [pid 145170:tid 145313] [client 143.44.185.218:60861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTcmAAAAI8"]
[Mon Jul 20 07:27:32.942054 2026] [security2:error] [pid 145170:tid 145313] [client 143.44.185.218:60861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iRDjs5KUa9I09SwTcmAAAAI8"]
[Mon Jul 20 07:27:33.042236 2026] [security2:error] [pid 145170:tid 145426] [client 14.225.17.146:65090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4iQzjs5KUa9I09SwTb9AAAAQA"], referer: http://mobilesurvsolutions.com/test
[Mon Jul 20 07:27:33.226004 2026] [security2:error] [pid 145170:tid 145334] [client 57.141.18.122:21692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iQDjs5KUa9I09SwTa9wAApB4"]
[Mon Jul 20 07:27:33.284862 2026] [security2:error] [pid 145170:tid 145367] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRDjs5KUa9I09SwTckgAAAMU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:33.369378 2026] [security2:error] [pid 145170:tid 145355] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRDjs5KUa9I09SwTclQAAALk"], referer: https://mezzacraft.com/author/mezza/page/19/
[Mon Jul 20 07:27:33.433356 2026] [security2:error] [pid 145170:tid 145242] [remote 124.55.178.99:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iRTjs5KUa9I09SwTc1wAAs0Q"]
[Mon Jul 20 07:27:33.464837 2026] [security2:error] [pid 145170:tid 145321] [client 77.110.127.138:49562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTcqQAAAJc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:33.470517 2026] [security2:error] [pid 145170:tid 145338] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTcqAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:33.539015 2026] [security2:error] [pid 145170:tid 145425] [client 185.36.230.69:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTc0AAAAP8"]
[Mon Jul 20 07:27:33.763452 2026] [security2:error] [pid 145170:tid 145342] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTcuAAArFU"], referer: http://assasalnazaha.com/test
[Mon Jul 20 07:27:33.871437 2026] [security2:error] [pid 145170:tid 145262] [remote 124.55.178.99:58902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iRTjs5KUa9I09SwTc-QAA41g"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:27:33.973838 2026] [security2:error] [pid 145170:tid 145428] [client 14.225.17.146:64912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4iRDjs5KUa9I09SwTcYAAAAQI"]
[Mon Jul 20 07:27:34.070343 2026] [security2:error] [pid 145170:tid 145425] [client 77.110.127.138:49514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/video/0qlnlb5xeda7.php"] [unique_id "al4iRjjs5KUa9I09SwTdCwAAAP8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:34.208453 2026] [security2:error] [pid 145170:tid 145375] [client 66.249.74.167:58372] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "sj-media.co"] [uri "/robots.txt"] [unique_id "al4iRjjs5KUa9I09SwTdLAAAAM0"]
[Mon Jul 20 07:27:34.218811 2026] [security2:error] [pid 145170:tid 145427] [client 77.110.127.138:49559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iRjjs5KUa9I09SwTdJAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:34.218955 2026] [security2:error] [pid 145170:tid 145427] [client 77.110.127.138:49559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iRjjs5KUa9I09SwTdJAAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:34.259324 2026] [security2:error] [pid 145170:tid 145371] [client 14.225.17.146:52681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTc_QAAAMk"], referer: http://adastra.love/test
[Mon Jul 20 07:27:34.409971 2026] [security2:error] [pid 145170:tid 145366] [client 77.110.127.138:49519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRjjs5KUa9I09SwTdGQAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:34.565306 2026] [security2:error] [pid 145170:tid 145416] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRjjs5KUa9I09SwTdFQAAAPY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:34.583290 2026] [security2:error] [pid 145170:tid 145401] [client 57.141.18.71:26616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iQjjs5KUa9I09SwTbjAAA5yQ"]
[Mon Jul 20 07:27:34.621446 2026] [security2:error] [pid 145170:tid 145320] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRjjs5KUa9I09SwTdJQAAAJY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:34.636206 2026] [security2:error] [pid 145170:tid 145287] [remote 199.189.225.40:63829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4iRjjs5KUa9I09SwTdTQABAnE"]
[Mon Jul 20 07:27:34.705602 2026] [security2:error] [pid 145170:tid 145297] [remote 130.51.180.8:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4iRjjs5KUa9I09SwTdVQAA73s"]
[Mon Jul 20 07:27:34.790712 2026] [security2:error] [pid 145170:tid 145339] [client 154.192.123.127:17908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iRjjs5KUa9I09SwTdWgAAAKk"]
[Mon Jul 20 07:27:34.790869 2026] [security2:error] [pid 145170:tid 145339] [client 154.192.123.127:17908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iRjjs5KUa9I09SwTdWgAAAKk"]
[Mon Jul 20 07:27:34.834497 2026] [security2:error] [pid 145170:tid 145189] [remote 199.189.225.40:63829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uritems.net"] [uri "/wp-login.php"] [unique_id "al4iRjjs5KUa9I09SwTdYAAA0g8"], referer: https://uritems.net/wp-login.php
[Mon Jul 20 07:27:34.897793 2026] [security2:error] [pid 145170:tid 145180] [remote 130.51.180.8:34188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "justinagrayman.com"] [uri "/wp-login.php"] [unique_id "al4iRjjs5KUa9I09SwTdaQAAvgY"], referer: https://justinagrayman.com/wp-login.php
[Mon Jul 20 07:27:34.990666 2026] [security2:error] [pid 145170:tid 145349] [client 202.141.11.99:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iRjjs5KUa9I09SwTdcAAAALM"]
[Mon Jul 20 07:27:34.990783 2026] [security2:error] [pid 145170:tid 145349] [client 202.141.11.99:37088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iRjjs5KUa9I09SwTdcAAAALM"]
[Mon Jul 20 07:27:35.200587 2026] [security2:error] [pid 145170:tid 145357] [client 77.110.127.138:49544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/stitch-pattern/gcrn1l84wjd4.php"] [unique_id "al4iRzjs5KUa9I09SwTdiQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:35.416103 2026] [security2:error] [pid 145170:tid 145227] [remote 47.86.33.52:31630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4iRzjs5KUa9I09SwTdtQAAujU"]
[Mon Jul 20 07:27:35.416341 2026] [security2:error] [pid 145170:tid 145356] [client 47.86.33.52:31630] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4iRzjs5KUa9I09SwTdtQAAujU"]
[Mon Jul 20 07:27:35.518559 2026] [security2:error] [pid 145170:tid 145310] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdjgAAAIw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:35.630964 2026] [security2:error] [pid 145170:tid 145319] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdrQAAAJU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:35.713310 2026] [security2:error] [pid 145170:tid 145338] [client 77.110.127.138:49573] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdtAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:35.880158 2026] [security2:error] [pid 145170:tid 145413] [client 49.47.218.174:8704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iRzjs5KUa9I09SwTd6QAAAPM"]
[Mon Jul 20 07:27:35.880320 2026] [security2:error] [pid 145170:tid 145413] [client 49.47.218.174:8704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iRzjs5KUa9I09SwTd6QAAAPM"]
[Mon Jul 20 07:27:36.051230 2026] [security2:error] [pid 145170:tid 145183] [remote 23.161.169.62:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "socalledsam.com"] [uri "/.well-known/security.txt"] [unique_id "al4iSDjs5KUa9I09SwTd-gAAyQk"]
[Mon Jul 20 07:27:36.051428 2026] [security2:error] [pid 145170:tid 145371] [client 23.161.169.62:0] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "socalledsam.com"] [uri "/.well-known/security.txt"] [unique_id "al4iSDjs5KUa9I09SwTd-gAAyQk"]
[Mon Jul 20 07:27:36.059634 2026] [security2:error] [pid 145170:tid 145414] [client 14.225.17.146:52038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4iRjjs5KUa9I09SwTdQQAAAPQ"], referer: http://careysheatingandcooling.com/test
[Mon Jul 20 07:27:36.066249 2026] [security2:error] [pid 145170:tid 145236] [remote 103.90.234.13:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4iSDjs5KUa9I09SwTd-wAAkz4"]
[Mon Jul 20 07:27:36.439065 2026] [security2:error] [pid 145170:tid 145307] [client 57.141.18.121:54058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iQzjs5KUa9I09SwTcDwAAiWg"]
[Mon Jul 20 07:27:36.443888 2026] [security2:error] [pid 145170:tid 145375] [client 14.225.17.146:51890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTd3wAAAM0"], referer: http://cheesewithjam.com/test
[Mon Jul 20 07:27:36.468662 2026] [security2:error] [pid 145170:tid 145230] [remote 103.90.234.13:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4iSDjs5KUa9I09SwTeLQAAyDg"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 07:27:36.686272 2026] [security2:error] [pid 145170:tid 145396] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iSDjs5KUa9I09SwTeHQAAAOI"], referer: https://mezzacraft.com/author/mezza/page/19/
[Mon Jul 20 07:27:36.766846 2026] [security2:error] [pid 145170:tid 145317] [client 98.159.234.160:29287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iSDjs5KUa9I09SwTeRAAAAJM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:27:36.891845 2026] [security2:error] [pid 145170:tid 145341] [client 57.141.18.37:52830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iRDjs5KUa9I09SwTcNwAAq0E"]
[Mon Jul 20 07:27:36.903622 2026] [security2:error] [pid 145170:tid 145382] [client 54.94.85.83:39091] ModSecurity: Warning. Matched phrase "Collector" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "fkconstructionfunding.com"] [uri "/wp-content/uploads/2020/07/FKC-Construction-Job-Profile-v10.pdf"] [unique_id "al4iRzjs5KUa9I09SwTd5wAAANQ"]
[Mon Jul 20 07:27:36.969910 2026] [security2:error] [pid 145170:tid 145208] [remote 160.187.68.132:34118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iSDjs5KUa9I09SwTeXwAA-iI"]
[Mon Jul 20 07:27:37.043486 2026] [security2:error] [pid 145170:tid 145430] [client 74.208.214.194:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4iSTjs5KUa9I09SwTeZwAAAQQ"]
[Mon Jul 20 07:27:37.106994 2026] [security2:error] [pid 145170:tid 145249] [remote 154.66.198.148:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4iSTjs5KUa9I09SwTecAAAmUs"]
[Mon Jul 20 07:27:37.242388 2026] [security2:error] [pid 145170:tid 145258] [remote 51.158.61.221:58520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iSTjs5KUa9I09SwTedgAA4lQ"]
[Mon Jul 20 07:27:37.336904 2026] [security2:error] [pid 145170:tid 145424] [client 77.110.127.138:49566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iSTjs5KUa9I09SwTegAAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:37.337012 2026] [security2:error] [pid 145170:tid 145424] [client 77.110.127.138:49566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iSTjs5KUa9I09SwTegAAAAP4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:37.444301 2026] [security2:error] [pid 145170:tid 145218] [remote 51.158.61.221:58520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iSTjs5KUa9I09SwTejQABAyw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:27:37.476168 2026] [security2:error] [pid 145170:tid 145276] [remote 160.187.68.132:34118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iSTjs5KUa9I09SwTekQABAWY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:27:37.483037 2026] [security2:error] [pid 145170:tid 145314] [client 36.93.152.155:56142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iSTjs5KUa9I09SwTekwAAAJA"]
[Mon Jul 20 07:27:37.483114 2026] [security2:error] [pid 145170:tid 145314] [client 36.93.152.155:56142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iSTjs5KUa9I09SwTekwAAAJA"]
[Mon Jul 20 07:27:37.624998 2026] [security2:error] [pid 145170:tid 145383] [client 14.225.17.146:51951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdsgAAANU"]
[Mon Jul 20 07:27:37.694360 2026] [security2:error] [pid 145170:tid 145417] [client 112.86.225.248:42332] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "allergyantidotes.com"] [uri "/"] [unique_id "al4iSTjs5KUa9I09SwTergAAAPc"]
[Mon Jul 20 07:27:37.694483 2026] [security2:error] [pid 145170:tid 145417] [client 112.86.225.248:42332] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "allergyantidotes.com"] [uri "/"] [unique_id "al4iSTjs5KUa9I09SwTergAAAPc"]
[Mon Jul 20 07:27:37.701659 2026] [security2:error] [pid 145170:tid 145385] [client 14.225.17.146:50535] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4iSTjs5KUa9I09SwTeqgAAANc"], referer: http://daseighty.net/test
[Mon Jul 20 07:27:37.790027 2026] [security2:error] [pid 145170:tid 145246] [remote 154.66.198.148:57468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "technicalseohouse.com"] [uri "/wp-login.php"] [unique_id "al4iSTjs5KUa9I09SwTetQAAtkg"], referer: https://technicalseohouse.com/wp-login.php
[Mon Jul 20 07:27:37.801428 2026] [security2:error] [pid 145170:tid 145315] [client 57.141.18.119:41718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTcpgAAkTs"]
[Mon Jul 20 07:27:38.044213 2026] [security2:error] [pid 145170:tid 145412] [client 103.176.215.66:65389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTezwAAAPI"]
[Mon Jul 20 07:27:38.044309 2026] [security2:error] [pid 145170:tid 145412] [client 103.176.215.66:65389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTezwAAAPI"]
[Mon Jul 20 07:27:38.180944 2026] [security2:error] [pid 145170:tid 145255] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTe3QAArlE"]
[Mon Jul 20 07:27:38.181115 2026] [security2:error] [pid 145170:tid 145344] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTe3QAArlE"]
[Mon Jul 20 07:27:38.424508 2026] [security2:error] [pid 145170:tid 145322] [client 20.197.195.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.195.197.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "wesmclucas.com"] [uri "/.well-known/about.php"] [unique_id "al4iSjjs5KUa9I09SwTe9gAAAJg"]
[Mon Jul 20 07:27:38.424604 2026] [security2:error] [pid 145170:tid 145322] [client 20.197.195.24:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "wesmclucas.com"] [uri "/.well-known/about.php"] [unique_id "al4iSjjs5KUa9I09SwTe9gAAAJg"]
[Mon Jul 20 07:27:38.607646 2026] [security2:error] [pid 145170:tid 145419] [client 57.141.18.123:32860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iRTjs5KUa9I09SwTc-wAA-V0"]
[Mon Jul 20 07:27:38.615960 2026] [security2:error] [pid 145170:tid 145403] [client 201.27.111.74:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTfBAAAAOk"]
[Mon Jul 20 07:27:38.616063 2026] [security2:error] [pid 145170:tid 145403] [client 201.27.111.74:50538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTfBAAAAOk"]
[Mon Jul 20 07:27:38.646537 2026] [security2:error] [pid 145170:tid 145313] [client 14.225.17.146:52559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4iSjjs5KUa9I09SwTe9wAAAI8"], referer: http://falconarrowshop.com/test
[Mon Jul 20 07:27:38.879332 2026] [security2:error] [pid 145170:tid 145363] [client 103.106.165.44:62839] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTfIgAAAME"]
[Mon Jul 20 07:27:38.879460 2026] [security2:error] [pid 145170:tid 145363] [client 103.106.165.44:62839] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iSjjs5KUa9I09SwTfIgAAAME"]
[Mon Jul 20 07:27:39.356764 2026] [security2:error] [pid 145170:tid 145303] [client 165.154.4.92:35118] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4iSzjs5KUa9I09SwTfTgAAAIU"]
[Mon Jul 20 07:27:39.461442 2026] [security2:error] [pid 145170:tid 145370] [client 45.61.188.240:57721] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "careysheatingandcooling.com"] [uri "/"] [unique_id "al4iSzjs5KUa9I09SwTfXQAAAMg"]
[Mon Jul 20 07:27:39.479617 2026] [security2:error] [pid 145170:tid 145394] [client 136.158.60.21:46042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iSzjs5KUa9I09SwTfYAAAAOA"]
[Mon Jul 20 07:27:39.479725 2026] [security2:error] [pid 145170:tid 145394] [client 136.158.60.21:46042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iSzjs5KUa9I09SwTfYAAAAOA"]
[Mon Jul 20 07:27:39.528425 2026] [security2:error] [pid 145170:tid 145426] [client 165.154.4.92:58738] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.227"] [uri "/"] [unique_id "al4iSzjs5KUa9I09SwTfYQAAAQA"]
[Mon Jul 20 07:27:39.627509 2026] [security2:error] [pid 145170:tid 145409] [client 104.234.53.69:37099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iSzjs5KUa9I09SwTfZgAAAO8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:39.746426 2026] [security2:error] [pid 145170:tid 145424] [client 45.61.188.240:57757] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "careysheatingandcooling.com"] [uri "/"] [unique_id "al4iSzjs5KUa9I09SwTfcwAAAP4"]
[Mon Jul 20 07:27:39.770216 2026] [security2:error] [pid 145170:tid 145353] [client 57.141.18.42:28392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdeQAAt2o"]
[Mon Jul 20 07:27:39.921417 2026] [security2:error] [pid 145170:tid 145427] [client 50.116.65.227:57856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4iSzjs5KUa9I09SwTfggAAAQE"]
[Mon Jul 20 07:27:39.932668 2026] [security2:error] [pid 145170:tid 145402] [client 50.116.65.227:28262] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4iSzjs5KUa9I09SwTfgwAAAPc"]
[Mon Jul 20 07:27:40.032630 2026] [security2:error] [pid 145170:tid 145428] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4iSjjs5KUa9I09SwTe_QAAAQI"]
[Mon Jul 20 07:27:40.318063 2026] [security2:error] [pid 145170:tid 145395] [client 57.141.18.78:32658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdyQAA4RA"]
[Mon Jul 20 07:27:40.323487 2026] [security2:error] [pid 145170:tid 145373] [client 112.86.225.120:50366] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4iTDjs5KUa9I09SwTfoAAAAMs"]
[Mon Jul 20 07:27:40.323594 2026] [security2:error] [pid 145170:tid 145373] [client 112.86.225.120:50366] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.nandansonscharitablefoundation.com"] [uri "/"] [unique_id "al4iTDjs5KUa9I09SwTfoAAAAMs"]
[Mon Jul 20 07:27:40.382205 2026] [security2:error] [pid 145170:tid 145345] [client 57.141.18.105:63352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iRzjs5KUa9I09SwTdzgAAryM"]
[Mon Jul 20 07:27:40.624499 2026] [security2:error] [pid 145170:tid 145263] [remote 103.28.36.106:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4iTDjs5KUa9I09SwTfuwAAvlk"]
[Mon Jul 20 07:27:40.782837 2026] [security2:error] [pid 145170:tid 145307] [client 14.225.17.146:59890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4iSzjs5KUa9I09SwTfeAAAAIk"], referer: http://walkingandtalking.net/test
[Mon Jul 20 07:27:40.847009 2026] [security2:error] [pid 145170:tid 145359] [client 14.225.17.146:51901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4iTDjs5KUa9I09SwTf1AAAAL0"], referer: http://processorstudio.com/test
[Mon Jul 20 07:27:40.938995 2026] [security2:error] [pid 145170:tid 145327] [client 57.141.18.78:32664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iSDjs5KUa9I09SwTeDgAAnSU"]
[Mon Jul 20 07:27:41.152364 2026] [security2:error] [pid 145170:tid 145228] [remote 103.28.36.106:60956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4iTTjs5KUa9I09SwTf9AAA1TY"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 07:27:41.278679 2026] [security2:error] [pid 145170:tid 145350] [client 57.141.18.7:56596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iSDjs5KUa9I09SwTeOAAAtDc"]
[Mon Jul 20 07:27:41.357135 2026] [security2:error] [pid 145170:tid 145428] [client 117.211.236.168:56219] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgAgAAAQI"]
[Mon Jul 20 07:27:41.357262 2026] [security2:error] [pid 145170:tid 145428] [client 117.211.236.168:56219] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgAgAAAQI"]
[Mon Jul 20 07:27:41.367913 2026] [security2:error] [pid 145170:tid 145364] [client 114.119.128.35:40927] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nevelow.com"] [uri "/category/southeast-asia/vietnam/hanoi/"] [unique_id "al4iTTjs5KUa9I09SwTgBAAAAMI"], referer: https://nevelow.com/category/launching/
[Mon Jul 20 07:27:41.459947 2026] [security2:error] [pid 145170:tid 145358] [client 154.208.48.130:62980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgEAAAALw"]
[Mon Jul 20 07:27:41.460548 2026] [security2:error] [pid 145170:tid 145358] [client 154.208.48.130:62980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgEAAAALw"]
[Mon Jul 20 07:27:41.555699 2026] [security2:error] [pid 145170:tid 145287] [remote 113.160.142.119:45676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4iTTjs5KUa9I09SwTgFwAAoXE"]
[Mon Jul 20 07:27:41.749618 2026] [security2:error] [pid 145170:tid 145356] [client 14.225.17.146:52503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4iTTjs5KUa9I09SwTgJAAAALo"], referer: https://walkingandtalking.net/test
[Mon Jul 20 07:27:41.756727 2026] [security2:error] [pid 145170:tid 145351] [client 191.202.66.27:59792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgJwAAALU"]
[Mon Jul 20 07:27:41.756838 2026] [security2:error] [pid 145170:tid 145351] [client 191.202.66.27:59792] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgJwAAALU"]
[Mon Jul 20 07:27:41.805223 2026] [security2:error] [pid 145170:tid 145372] [client 88.241.67.160:55130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgLQAAAMo"]
[Mon Jul 20 07:27:41.805335 2026] [security2:error] [pid 145170:tid 145372] [client 88.241.67.160:55130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iTTjs5KUa9I09SwTgLQAAAMo"]
[Mon Jul 20 07:27:41.846291 2026] [security2:error] [pid 145170:tid 145384] [client 14.225.17.146:60066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4iTTjs5KUa9I09SwTgLwAAANY"], referer: https://processorstudio.com/test
[Mon Jul 20 07:27:41.885701 2026] [security2:error] [pid 145170:tid 145198] [remote 57.141.18.42:28206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5067535"] [unique_id "al4iTTjs5KUa9I09SwTgMQABAhg"]
[Mon Jul 20 07:27:41.907412 2026] [security2:error] [pid 145170:tid 145180] [remote 8.217.108.67:44348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.botanicapatterndesigns.com"] [uri "/wp-login.php"] [unique_id "al4iTTjs5KUa9I09SwTgMwAA-gY"]
[Mon Jul 20 07:27:41.995664 2026] [access_compat:error] [pid 145170:tid 145333] [client 177.183.65.4:54881] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/index.php, referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 07:27:42.049876 2026] [security2:error] [pid 145170:tid 145267] [remote 113.160.142.119:45676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4iTjjs5KUa9I09SwTgSgAAsV0"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 07:27:42.193062 2026] [security2:error] [pid 145170:tid 145391] [client 104.234.53.63:41041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iTjjs5KUa9I09SwTgWwAAAN0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:42.309801 2026] [security2:error] [pid 145170:tid 145244] [remote 8.217.108.67:44348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.botanicapatterndesigns.com"] [uri "/wp-login.php"] [unique_id "al4iTjjs5KUa9I09SwTgYgAA40Y"], referer: https://mail.botanicapatterndesigns.com/wp-login.php
[Mon Jul 20 07:27:42.326131 2026] [security2:error] [pid 145170:tid 145343] [client 57.141.18.117:25132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iSTjs5KUa9I09SwTepQAArV4"]
[Mon Jul 20 07:27:42.332666 2026] [security2:error] [pid 145170:tid 145327] [client 14.225.17.146:52519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4iTjjs5KUa9I09SwTgRAAAAJ0"]
[Mon Jul 20 07:27:42.618013 2026] [security2:error] [pid 145170:tid 145384] [client 179.127.84.238:61241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iTjjs5KUa9I09SwTgdwAAANY"]
[Mon Jul 20 07:27:42.618189 2026] [security2:error] [pid 145170:tid 145384] [client 179.127.84.238:61241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iTjjs5KUa9I09SwTgdwAAANY"]
[Mon Jul 20 07:27:43.010658 2026] [security2:error] [pid 145170:tid 145347] [client 77.110.127.138:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgnQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.010746 2026] [security2:error] [pid 145170:tid 145347] [client 77.110.127.138:49602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgnQAAALE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.030026 2026] [security2:error] [pid 145170:tid 145280] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iTzjs5KUa9I09SwTgngAAqGo"]
[Mon Jul 20 07:27:43.030196 2026] [security2:error] [pid 145170:tid 145338] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iTzjs5KUa9I09SwTgngAAqGo"]
[Mon Jul 20 07:27:43.096995 2026] [security2:error] [pid 145170:tid 145409] [client 77.110.127.138:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgpgAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.097125 2026] [security2:error] [pid 145170:tid 145409] [client 77.110.127.138:49562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgpgAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.155050 2026] [security2:error] [pid 145170:tid 145411] [client 77.110.127.138:49573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgrgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.155142 2026] [security2:error] [pid 145170:tid 145411] [client 77.110.127.138:49573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgrgAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.230519 2026] [security2:error] [pid 145170:tid 145427] [client 77.110.127.138:49586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgswAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.230609 2026] [security2:error] [pid 145170:tid 145427] [client 77.110.127.138:49586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgswAAAQE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.257843 2026] [security2:error] [pid 145170:tid 145353] [client 14.225.17.146:52498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4iTTjs5KUa9I09SwTgIwAAALc"], referer: http://ironcitywellness.com/test
[Mon Jul 20 07:27:43.342120 2026] [security2:error] [pid 145170:tid 145355] [client 104.234.53.67:56307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iTzjs5KUa9I09SwTguwAAALk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:43.366066 2026] [security2:error] [pid 145170:tid 145375] [client 66.249.74.68:48292] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.ace-med.com"] [uri "/robots.txt"] [unique_id "al4iTzjs5KUa9I09SwTgvgAAAM0"]
[Mon Jul 20 07:27:43.401676 2026] [security2:error] [pid 145170:tid 145373] [client 77.110.127.138:49607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgwgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.401808 2026] [security2:error] [pid 145170:tid 145373] [client 77.110.127.138:49607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTgwgAAAMs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:43.445657 2026] [security2:error] [pid 145170:tid 145346] [client 157.20.138.62:61983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iTzjs5KUa9I09SwTgyQAAALA"]
[Mon Jul 20 07:27:43.445816 2026] [security2:error] [pid 145170:tid 145346] [client 157.20.138.62:61983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iTzjs5KUa9I09SwTgyQAAALA"]
[Mon Jul 20 07:27:43.584813 2026] [security2:error] [pid 145170:tid 145314] [client 185.238.231.235:29939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4iTzjs5KUa9I09SwTg1QAAAJA"]
[Mon Jul 20 07:27:43.593024 2026] [security2:error] [pid 145170:tid 145428] [client 185.238.231.67:25807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4iTzjs5KUa9I09SwTg1AAAAQI"]
[Mon Jul 20 07:27:43.826486 2026] [security2:error] [pid 145170:tid 145396] [client 77.110.127.138:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTg8gAAAOI"]
[Mon Jul 20 07:27:43.826588 2026] [security2:error] [pid 145170:tid 145396] [client 77.110.127.138:49610] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iTzjs5KUa9I09SwTg8gAAAOI"]
[Mon Jul 20 07:27:44.125492 2026] [security2:error] [pid 145170:tid 145409] [client 77.110.127.138:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iUDjs5KUa9I09SwThAwAAAO8"]
[Mon Jul 20 07:27:44.125596 2026] [security2:error] [pid 145170:tid 145409] [client 77.110.127.138:49612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iUDjs5KUa9I09SwThAwAAAO8"]
[Mon Jul 20 07:27:44.331513 2026] [security2:error] [pid 145170:tid 145368] [client 114.119.157.57:27693] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bruceledewitz.com"] [uri "/common-law-and-values-not-originalism-drive-supreme-court-decisions/"] [unique_id "al4iUDjs5KUa9I09SwThHQAAAMY"], referer: https://bruceledewitz.com/blog/
[Mon Jul 20 07:27:44.538399 2026] [security2:error] [pid 145170:tid 145361] [client 57.141.18.115:61788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iSzjs5KUa9I09SwTfbwAAvz4"]
[Mon Jul 20 07:27:44.981068 2026] [security2:error] [pid 145170:tid 145313] [client 104.234.53.58:46163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iUDjs5KUa9I09SwThUgAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:45.166358 2026] [security2:error] [pid 145170:tid 145413] [client 143.44.185.218:62186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iUTjs5KUa9I09SwThXwAAAPM"]
[Mon Jul 20 07:27:45.166491 2026] [security2:error] [pid 145170:tid 145413] [client 143.44.185.218:62186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iUTjs5KUa9I09SwThXwAAAPM"]
[Mon Jul 20 07:27:45.281042 2026] [security2:error] [pid 145170:tid 145342] [client 14.225.17.146:60273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4iUTjs5KUa9I09SwThVgAAAKw"], referer: http://jvcmotorsports.com/test
[Mon Jul 20 07:27:45.402097 2026] [security2:error] [pid 145170:tid 145395] [client 154.192.123.127:18488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iUTjs5KUa9I09SwThdQAAAOE"]
[Mon Jul 20 07:27:45.402232 2026] [security2:error] [pid 145170:tid 145395] [client 154.192.123.127:18488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iUTjs5KUa9I09SwThdQAAAOE"]
[Mon Jul 20 07:27:45.429618 2026] [security2:error] [pid 145170:tid 145382] [client 202.141.11.99:12224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iUTjs5KUa9I09SwThdgAAANQ"]
[Mon Jul 20 07:27:45.429739 2026] [security2:error] [pid 145170:tid 145382] [client 202.141.11.99:12224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iUTjs5KUa9I09SwThdgAAANQ"]
[Mon Jul 20 07:27:45.627230 2026] [security2:error] [pid 145170:tid 145328] [client 14.225.17.146:60092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4iTjjs5KUa9I09SwTgRwAAAJ4"], referer: http://areitoproducciones.com/test
[Mon Jul 20 07:27:45.776564 2026] [security2:error] [pid 145170:tid 145270] [remote 173.212.252.15:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4iUTjs5KUa9I09SwThngAA9GA"]
[Mon Jul 20 07:27:46.028040 2026] [security2:error] [pid 145170:tid 145206] [remote 173.212.252.15:40974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fineartsfactory.net"] [uri "/wp-login.php"] [unique_id "al4iUjjs5KUa9I09SwThrgAA8CA"], referer: https://fineartsfactory.net/wp-login.php
[Mon Jul 20 07:27:46.369489 2026] [security2:error] [pid 145170:tid 145381] [client 49.47.218.174:60847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iUjjs5KUa9I09SwTh0wAAANM"]
[Mon Jul 20 07:27:46.369586 2026] [security2:error] [pid 145170:tid 145381] [client 49.47.218.174:60847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iUjjs5KUa9I09SwTh0wAAANM"]
[Mon Jul 20 07:27:46.411874 2026] [security2:error] [pid 145170:tid 145408] [client 57.141.18.110:58134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iTTjs5KUa9I09SwTgQgAA7g8"]
[Mon Jul 20 07:27:46.426728 2026] [security2:error] [pid 145170:tid 145371] [client 77.110.127.138:49568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iUjjs5KUa9I09SwTh1QAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:46.426850 2026] [security2:error] [pid 145170:tid 145371] [client 77.110.127.138:49568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iUjjs5KUa9I09SwTh1QAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:46.612480 2026] [security2:error] [pid 145170:tid 145368] [client 14.225.17.146:60534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4iUTjs5KUa9I09SwThiwAAAMY"], referer: http://retzkolonglogistics.com/test
[Mon Jul 20 07:27:46.745020 2026] [security2:error] [pid 145170:tid 145333] [client 57.141.18.35:50382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iTjjs5KUa9I09SwTgagAAowE"]
[Mon Jul 20 07:27:47.726460 2026] [security2:error] [pid 145170:tid 145399] [client 66.249.74.133:61701] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.stopfeedingthemonster.com"] [uri "/robots.txt"] [unique_id "al4iUzjs5KUa9I09SwTiNgAAAOU"]
[Mon Jul 20 07:27:47.940241 2026] [security2:error] [pid 145170:tid 145414] [client 36.93.152.155:56657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iUzjs5KUa9I09SwTiSAAAAPQ"]
[Mon Jul 20 07:27:47.940346 2026] [security2:error] [pid 145170:tid 145414] [client 36.93.152.155:56657] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iUzjs5KUa9I09SwTiSAAAAPQ"]
[Mon Jul 20 07:27:48.275878 2026] [security2:error] [pid 145170:tid 145200] [remote 162.19.86.63:50111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4iVDjs5KUa9I09SwTiWwABAho"]
[Mon Jul 20 07:27:48.485254 2026] [security2:error] [pid 145170:tid 145256] [remote 162.19.86.63:50111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4iVDjs5KUa9I09SwTibQAAzVI"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 07:27:48.563155 2026] [security2:error] [pid 145170:tid 145333] [client 103.176.215.66:49545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iVDjs5KUa9I09SwTicgAAAKM"]
[Mon Jul 20 07:27:48.563246 2026] [security2:error] [pid 145170:tid 145333] [client 103.176.215.66:49545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iVDjs5KUa9I09SwTicgAAAKM"]
[Mon Jul 20 07:27:48.569558 2026] [security2:error] [pid 145170:tid 145366] [client 50.116.65.227:57866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4iVDjs5KUa9I09SwTieAAAAMQ"]
[Mon Jul 20 07:27:48.580354 2026] [security2:error] [pid 145170:tid 145400] [client 50.116.65.227:28380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4iVDjs5KUa9I09SwTiewAAAOY"]
[Mon Jul 20 07:27:48.602763 2026] [security2:error] [pid 145170:tid 145424] [client 14.225.17.146:53428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4iVDjs5KUa9I09SwTiVQAAAP4"], referer: http://grecruit.online/test
[Mon Jul 20 07:27:48.604339 2026] [security2:error] [pid 145170:tid 145207] [remote 160.187.68.132:60722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iVDjs5KUa9I09SwTifgAA8SE"]
[Mon Jul 20 07:27:48.627708 2026] [security2:error] [pid 145170:tid 145409] [client 50.116.65.227:28382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2025/02/IMG_9124.jpeg"] [unique_id "al4iVDjs5KUa9I09SwTiggAAAO8"]
[Mon Jul 20 07:27:48.731924 2026] [security2:error] [pid 145170:tid 145303] [client 57.141.18.88:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4iVDjs5KUa9I09SwTifAAAAIU"]
[Mon Jul 20 07:27:48.753796 2026] [security2:error] [pid 145170:tid 145379] [client 13.232.231.177:46294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iVDjs5KUa9I09SwTikgAAANE"]
[Mon Jul 20 07:27:48.753896 2026] [security2:error] [pid 145170:tid 145379] [client 13.232.231.177:46294] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iVDjs5KUa9I09SwTikgAAANE"]
[Mon Jul 20 07:27:48.954089 2026] [security2:error] [pid 145170:tid 145275] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iVDjs5KUa9I09SwTipwAA2mU"]
[Mon Jul 20 07:27:48.954217 2026] [security2:error] [pid 145170:tid 145388] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iVDjs5KUa9I09SwTipwAA2mU"]
[Mon Jul 20 07:27:49.090756 2026] [security2:error] [pid 145170:tid 145255] [remote 160.187.68.132:60722] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iVTjs5KUa9I09SwTiswABAlE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:27:49.100329 2026] [security2:error] [pid 145170:tid 145371] [client 201.27.111.74:51040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iVTjs5KUa9I09SwTitAAAAMk"]
[Mon Jul 20 07:27:49.104008 2026] [security2:error] [pid 145170:tid 145371] [client 201.27.111.74:51040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iVTjs5KUa9I09SwTitAAAAMk"]
[Mon Jul 20 07:27:49.145221 2026] [security2:error] [pid 145170:tid 145413] [client 104.234.53.86:36177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iVTjs5KUa9I09SwTitwAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:49.176702 2026] [security2:error] [pid 145170:tid 145295] [remote 191.101.50.240:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.50.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4iVTjs5KUa9I09SwTiuQAAxXk"]
[Mon Jul 20 07:27:49.406037 2026] [security2:error] [pid 145170:tid 145415] [client 103.106.165.44:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iVTjs5KUa9I09SwTi0QAAAPU"]
[Mon Jul 20 07:27:49.406132 2026] [security2:error] [pid 145170:tid 145415] [client 103.106.165.44:63325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iVTjs5KUa9I09SwTi0QAAAPU"]
[Mon Jul 20 07:27:49.421534 2026] [security2:error] [pid 145170:tid 145179] [remote 191.101.50.240:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.50.101.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jvcmotorsports.com"] [uri "/wp-login.php"] [unique_id "al4iVTjs5KUa9I09SwTi0gAA0AU"], referer: https://jvcmotorsports.com/wp-login.php
[Mon Jul 20 07:27:49.433103 2026] [security2:error] [pid 145170:tid 145421] [client 57.141.18.101:20818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iUTjs5KUa9I09SwThWQAA-xw"]
[Mon Jul 20 07:27:49.476807 2026] [security2:error] [pid 145170:tid 145380] [client 14.225.17.146:53871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4iVTjs5KUa9I09SwTiyAAAANI"], referer: http://samdothan.org/test
[Mon Jul 20 07:27:49.680138 2026] [security2:error] [pid 145170:tid 145353] [client 57.141.18.57:28564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iUTjs5KUa9I09SwThZwAAt0g"]
[Mon Jul 20 07:27:49.697198 2026] [security2:error] [pid 145170:tid 145286] [remote 103.29.181.2:33750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.181.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iVTjs5KUa9I09SwTi4QAAjnA"]
[Mon Jul 20 07:27:49.747570 2026] [security2:error] [pid 145170:tid 145196] [remote 217.182.128.41:53806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iVTjs5KUa9I09SwTi6AAA8RY"]
[Mon Jul 20 07:27:49.941326 2026] [fcgid:warn] [pid 145170:tid 145414] (70014)End of file found: [client 66.132.186.165:13592] mod_fcgid: can't get data from http client
[Mon Jul 20 07:27:50.024067 2026] [security2:error] [pid 145170:tid 145250] [remote 217.182.128.41:53806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.128.182.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iVjjs5KUa9I09SwTi_gAAx0w"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:27:50.131736 2026] [security2:error] [pid 145170:tid 145382] [client 136.158.60.21:47590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iVjjs5KUa9I09SwTjCAAAANQ"]
[Mon Jul 20 07:27:50.131844 2026] [security2:error] [pid 145170:tid 145382] [client 136.158.60.21:47590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iVjjs5KUa9I09SwTjCAAAANQ"]
[Mon Jul 20 07:27:50.147890 2026] [security2:error] [pid 145170:tid 145405] [client 57.141.18.54:26678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iUTjs5KUa9I09SwThlwAA6wY"]
[Mon Jul 20 07:27:50.166882 2026] [security2:error] [pid 145170:tid 145283] [remote 103.29.181.2:33750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.181.29.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iVjjs5KUa9I09SwTjEAAAp20"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:27:51.086286 2026] [security2:error] [pid 145170:tid 145234] [remote 81.173.115.7:38208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4iVzjs5KUa9I09SwTjXAAAojw"]
[Mon Jul 20 07:27:51.109804 2026] [security2:error] [pid 145170:tid 145395] [client 57.141.18.106:53720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iUjjs5KUa9I09SwTh8AAA4RI"]
[Mon Jul 20 07:27:51.298232 2026] [security2:error] [pid 145170:tid 145217] [remote 81.173.115.7:38208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4iVzjs5KUa9I09SwTjawAA2ys"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:27:51.550794 2026] [security2:error] [pid 145170:tid 145348] [client 77.110.127.138:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iVzjs5KUa9I09SwTjfQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:51.550904 2026] [security2:error] [pid 145170:tid 145348] [client 77.110.127.138:49629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iVzjs5KUa9I09SwTjfQAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:51.569100 2026] [security2:error] [pid 145170:tid 145342] [client 57.141.18.24:24086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iUzjs5KUa9I09SwTiGQAArD8"]
[Mon Jul 20 07:27:51.825281 2026] [security2:error] [pid 145170:tid 145256] [remote 5.161.225.162:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4iVzjs5KUa9I09SwTjjwAAvlI"]
[Mon Jul 20 07:27:51.912429 2026] [security2:error] [pid 145170:tid 145399] [client 2a03:2880:f812:39:::0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "innovativecleaningsvs.com"] [uri "/index.php"] [unique_id "al4iVTjs5KUa9I09SwTi7wAA5QM"]
[Mon Jul 20 07:27:51.940611 2026] [security2:error] [pid 145170:tid 145408] [client 77.110.127.138:49631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iVzjs5KUa9I09SwTjngAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:51.940713 2026] [security2:error] [pid 145170:tid 145408] [client 77.110.127.138:49631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iVzjs5KUa9I09SwTjngAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:52.005573 2026] [security2:error] [pid 145170:tid 145229] [remote 5.161.225.162:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4iWDjs5KUa9I09SwTjpwAAjjc"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 07:27:52.170016 2026] [security2:error] [pid 145170:tid 145240] [remote 49.12.216.176:42354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4iWDjs5KUa9I09SwTjtgAAnkI"]
[Mon Jul 20 07:27:52.419862 2026] [security2:error] [pid 145170:tid 145410] [client 154.208.48.130:63509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iWDjs5KUa9I09SwTj0gAAAPA"]
[Mon Jul 20 07:27:52.419983 2026] [security2:error] [pid 145170:tid 145410] [client 154.208.48.130:63509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iWDjs5KUa9I09SwTj0gAAAPA"]
[Mon Jul 20 07:27:52.440406 2026] [security2:error] [pid 145170:tid 145356] [client 191.202.66.27:60282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iWDjs5KUa9I09SwTj2gAAALo"]
[Mon Jul 20 07:27:52.440517 2026] [security2:error] [pid 145170:tid 145356] [client 191.202.66.27:60282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iWDjs5KUa9I09SwTj2gAAALo"]
[Mon Jul 20 07:27:52.492568 2026] [security2:error] [pid 145170:tid 145206] [remote 49.12.216.176:42354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4iWDjs5KUa9I09SwTj3wAA6iA"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:27:52.506510 2026] [security2:error] [pid 145170:tid 145420] [client 77.110.127.138:49635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWDjs5KUa9I09SwTj4QAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:52.506620 2026] [security2:error] [pid 145170:tid 145420] [client 77.110.127.138:49635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWDjs5KUa9I09SwTj4QAAAPo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:52.617877 2026] [lsapi:error] [pid 116718:tid 116848] [remote 80.210.17.232:58142] [host jenfarley.com] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://jenfarley.com/about/
[Mon Jul 20 07:27:52.617900 2026] [lsapi:error] [pid 116718:tid 116848] [remote 80.210.17.232:58142] [host jenfarley.com] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://jenfarley.com/about/
[Mon Jul 20 07:27:52.617910 2026] [lsapi:error] [pid 116718:tid 116848] [remote 80.210.17.232:58142] [host jenfarley.com] Client error on sending request(POST /?wc-ajax=get_refreshed_fragments HTTP/2.0); uri(/?wc-ajax=get_refreshed_fragments) content-length(18): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://jenfarley.com/about/
[Mon Jul 20 07:27:52.666550 2026] [security2:error] [pid 145170:tid 145387] [client 88.241.67.160:57334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iWDjs5KUa9I09SwTj7AAAANk"]
[Mon Jul 20 07:27:52.666657 2026] [security2:error] [pid 145170:tid 145387] [client 88.241.67.160:57334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iWDjs5KUa9I09SwTj7AAAANk"]
[Mon Jul 20 07:27:52.765532 2026] [security2:error] [pid 145170:tid 145305] [client 104.234.53.53:47247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iWDjs5KUa9I09SwTj8wAAAIc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:53.077989 2026] [security2:error] [pid 145170:tid 145376] [client 77.110.127.138:49637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWTjs5KUa9I09SwTkEAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:53.078119 2026] [security2:error] [pid 145170:tid 145376] [client 77.110.127.138:49637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWTjs5KUa9I09SwTkEAAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:53.236600 2026] [security2:error] [pid 145170:tid 145333] [client 57.141.18.12:31180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iVDjs5KUa9I09SwTiqQAAo3o"]
[Mon Jul 20 07:27:53.260614 2026] [security2:error] [pid 145170:tid 145364] [client 14.225.17.146:52266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4iVzjs5KUa9I09SwTjlAAAAMI"], referer: http://alchemygroup.ca/test
[Mon Jul 20 07:27:53.289663 2026] [security2:error] [pid 145170:tid 145313] [client 179.127.84.238:61745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iWTjs5KUa9I09SwTkLAAAAI8"]
[Mon Jul 20 07:27:53.289769 2026] [security2:error] [pid 145170:tid 145313] [client 179.127.84.238:61745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iWTjs5KUa9I09SwTkLAAAAI8"]
[Mon Jul 20 07:27:53.416361 2026] [security2:error] [pid 145170:tid 145322] [client 77.110.127.138:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWTjs5KUa9I09SwTkMgAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:53.416450 2026] [security2:error] [pid 145170:tid 145322] [client 77.110.127.138:49640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWTjs5KUa9I09SwTkMgAAAJg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:53.492304 2026] [security2:error] [pid 145170:tid 145410] [client 117.211.236.168:56744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iWTjs5KUa9I09SwTkNwAAAPA"]
[Mon Jul 20 07:27:53.492398 2026] [security2:error] [pid 145170:tid 145410] [client 117.211.236.168:56744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iWTjs5KUa9I09SwTkNwAAAPA"]
[Mon Jul 20 07:27:53.590513 2026] [security2:error] [pid 145170:tid 145222] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iWTjs5KUa9I09SwTkQAAApTA"]
[Mon Jul 20 07:27:53.590643 2026] [security2:error] [pid 145170:tid 145335] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iWTjs5KUa9I09SwTkQAAApTA"]
[Mon Jul 20 07:27:53.734573 2026] [security2:error] [pid 145170:tid 145278] [remote 82.223.97.42:47710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iWTjs5KUa9I09SwTkUAAA12g"]
[Mon Jul 20 07:27:53.758150 2026] [security2:error] [pid 145170:tid 145317] [client 77.110.127.138:49642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWTjs5KUa9I09SwTkUQAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:53.758259 2026] [security2:error] [pid 145170:tid 145317] [client 77.110.127.138:49642] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWTjs5KUa9I09SwTkUQAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:53.955114 2026] [security2:error] [pid 145170:tid 145235] [remote 82.223.97.42:47710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.97.223.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iWTjs5KUa9I09SwTkXwAAlz0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:27:53.990597 2026] [security2:error] [pid 145170:tid 145306] [client 50.116.65.227:12282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iWTjs5KUa9I09SwTkYgAAAIg"]
[Mon Jul 20 07:27:54.000232 2026] [security2:error] [pid 145170:tid 145367] [client 50.116.65.227:12284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iWTjs5KUa9I09SwTkZQAAAMU"]
[Mon Jul 20 07:27:54.015532 2026] [security2:error] [pid 145170:tid 145425] [client 157.20.138.62:62662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iWjjs5KUa9I09SwTkZgAAAP8"]
[Mon Jul 20 07:27:54.015803 2026] [security2:error] [pid 145170:tid 145425] [client 157.20.138.62:62662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iWjjs5KUa9I09SwTkZgAAAP8"]
[Mon Jul 20 07:27:54.257859 2026] [security2:error] [pid 145170:tid 145346] [client 66.249.74.40:49785] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.theshakespeareconspiracy.com"] [uri "/robots.txt"] [unique_id "al4iWjjs5KUa9I09SwTkhwAAALA"]
[Mon Jul 20 07:27:54.377175 2026] [security2:error] [pid 145170:tid 145365] [client 57.141.18.97:38502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iVjjs5KUa9I09SwTjAQAAwwo"]
[Mon Jul 20 07:27:54.397017 2026] [security2:error] [pid 145170:tid 145395] [client 77.110.127.138:49645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWjjs5KUa9I09SwTkkQAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:54.397098 2026] [security2:error] [pid 145170:tid 145395] [client 77.110.127.138:49645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iWjjs5KUa9I09SwTkkQAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:27:54.479252 2026] [security2:error] [pid 145170:tid 145322] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4iWjjs5KUa9I09SwTkjgAAAJg"]
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 07:27:54.868304 2026] [security2:error] [pid 145170:tid 145426] [client 57.141.18.48:20240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iVjjs5KUa9I09SwTjHwABAEA"]
[Mon Jul 20 07:27:55.187291 2026] [security2:error] [pid 145170:tid 145357] [client 14.225.17.146:52852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4iWTjs5KUa9I09SwTkIwAAALs"], referer: http://dollpassionista.com/test
[Mon Jul 20 07:27:55.219569 2026] [security2:error] [pid 145170:tid 145419] [client 66.249.74.101:35621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4iWjjs5KUa9I09SwTkwwAAAPk"]
[Mon Jul 20 07:27:55.313084 2026] [security2:error] [pid 145170:tid 145232] [remote 78.46.157.202:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4iWzjs5KUa9I09SwTk5gABAzo"]
[Mon Jul 20 07:27:55.524911 2026] [autoindex:error] [pid 145170:tid 145247] [remote 34.79.239.215:50819] AH01276: Cannot serve directory /home2/cgadunmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.cga.dun.mybluehost.me
[Mon Jul 20 07:27:55.529854 2026] [security2:error] [pid 145170:tid 145229] [remote 78.46.157.202:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4iWzjs5KUa9I09SwTk9QAA8jc"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 07:27:55.743895 2026] [security2:error] [pid 145170:tid 145363] [client 52.167.144.140:24604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4iWzjs5KUa9I09SwTk9gAAwWc"]
[Mon Jul 20 07:27:55.885098 2026] [autoindex:error] [pid 145170:tid 145303] [client 43.164.196.47:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:27:55.981626 2026] [security2:error] [pid 145170:tid 145294] [remote 134.209.147.209:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4iWzjs5KUa9I09SwTlFwAAxng"]
[Mon Jul 20 07:27:55.984531 2026] [security2:error] [pid 145170:tid 145369] [client 202.141.11.99:22265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iWzjs5KUa9I09SwTlGwAAAMc"]
[Mon Jul 20 07:27:55.985042 2026] [security2:error] [pid 145170:tid 145369] [client 202.141.11.99:22265] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iWzjs5KUa9I09SwTlGwAAAMc"]
[Mon Jul 20 07:27:56.086282 2026] [security2:error] [pid 145170:tid 145421] [client 49.37.242.14:57057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlIAAAAPs"]
[Mon Jul 20 07:27:56.086474 2026] [security2:error] [pid 145170:tid 145421] [client 49.37.242.14:57057] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlIAAAAPs"]
[Mon Jul 20 07:27:56.121029 2026] [autoindex:error] [pid 145170:tid 145344] [client 14.225.17.146:58177] AH01276: Cannot serve directory /home3/scottass/public_html/test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://scott-assist.com/test
[Mon Jul 20 07:27:56.179990 2026] [security2:error] [pid 145170:tid 145370] [client 154.192.123.127:17006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlLAAAAMg"]
[Mon Jul 20 07:27:56.180341 2026] [security2:error] [pid 145170:tid 145370] [client 154.192.123.127:17006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlLAAAAMg"]
[Mon Jul 20 07:27:56.285241 2026] [security2:error] [pid 145170:tid 145412] [client 13.232.231.177:46298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlNwAAAPI"]
[Mon Jul 20 07:27:56.285369 2026] [security2:error] [pid 145170:tid 145412] [client 13.232.231.177:46298] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlNwAAAPI"]
[Mon Jul 20 07:27:56.333079 2026] [security2:error] [pid 145170:tid 145403] [client 14.225.17.146:54591] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4iXDjs5KUa9I09SwTlJQAAAOk"], referer: https://dollpassionista.com/test
[Mon Jul 20 07:27:56.362066 2026] [security2:error] [pid 145170:tid 145331] [client 57.141.18.38:29636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iVzjs5KUa9I09SwTjkQAAoU4"]
[Mon Jul 20 07:27:56.431345 2026] [security2:error] [pid 145170:tid 145297] [remote 134.209.147.209:34776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4iXDjs5KUa9I09SwTlRAAAins"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 07:27:56.614533 2026] [security2:error] [pid 145170:tid 145334] [client 14.225.17.146:57946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4iWzjs5KUa9I09SwTk2QAAAKQ"], referer: http://cephasnext.com/test
[Mon Jul 20 07:27:56.682307 2026] [security2:error] [pid 145170:tid 145315] [client 14.225.17.146:57705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4iWjjs5KUa9I09SwTkqgAAAJE"], referer: http://floorsourcestock.com/test
[Mon Jul 20 07:27:56.890264 2026] [security2:error] [pid 145170:tid 145355] [client 57.141.18.102:41464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iWDjs5KUa9I09SwTj0wAAuRw"]
[Mon Jul 20 07:27:56.935871 2026] [security2:error] [pid 145170:tid 145430] [client 49.47.218.174:61387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlbwAAAQQ"]
[Mon Jul 20 07:27:56.935997 2026] [security2:error] [pid 145170:tid 145430] [client 49.47.218.174:61387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iXDjs5KUa9I09SwTlbwAAAQQ"]
[Mon Jul 20 07:27:57.121138 2026] [security2:error] [pid 145170:tid 145383] [client 66.249.65.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4iXDjs5KUa9I09SwTldgAAANU"]
[Mon Jul 20 07:27:57.165056 2026] [security2:error] [pid 145170:tid 145326] [client 223.109.252.208:40644] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jennylouraya.com"] [uri "/"] [unique_id "al4iXTjs5KUa9I09SwTlfwAAAJw"]
[Mon Jul 20 07:27:57.165177 2026] [security2:error] [pid 145170:tid 145326] [client 223.109.252.208:40644] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.jennylouraya.com"] [uri "/"] [unique_id "al4iXTjs5KUa9I09SwTlfwAAAJw"]
[Mon Jul 20 07:27:57.306412 2026] [security2:error] [pid 145170:tid 145369] [client 50.116.65.227:12374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4iXTjs5KUa9I09SwTllQAAAMc"]
[Mon Jul 20 07:27:57.309440 2026] [security2:error] [pid 145170:tid 145315] [client 104.234.53.76:58467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iXTjs5KUa9I09SwTlkwAAAJE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:57.310528 2026] [security2:error] [pid 145170:tid 145335] [client 14.225.17.146:54617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4iXTjs5KUa9I09SwTleAAAAKU"], referer: http://recruitinginsight.us/test
[Mon Jul 20 07:27:57.587554 2026] [security2:error] [pid 145170:tid 145399] [client 143.44.185.218:63418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iXTjs5KUa9I09SwTlpQAAAOU"]
[Mon Jul 20 07:27:57.587663 2026] [security2:error] [pid 145170:tid 145399] [client 143.44.185.218:63418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iXTjs5KUa9I09SwTlpQAAAOU"]
[Mon Jul 20 07:27:57.844082 2026] [security2:error] [pid 145170:tid 145368] [client 127.0.0.1:60646] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4iXTjs5KUa9I09SwTlwQAAAMY"], referer: https://duckduckgo.com/?q=lexsg
[Mon Jul 20 07:27:57.868352 2026] [security2:error] [pid 145170:tid 145393] [client 14.225.17.146:58150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4iXDjs5KUa9I09SwTlawAAAN8"], referer: http://ancestralidadytrance.space/test
[Mon Jul 20 07:27:57.930583 2026] [security2:error] [pid 145170:tid 145347] [client 14.225.17.146:58200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4iXTjs5KUa9I09SwTlvQAAALE"], referer: http://keywayconstructionclt.com/test
[Mon Jul 20 07:27:58.401357 2026] [security2:error] [pid 145170:tid 145351] [client 36.93.152.155:57179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iXjjs5KUa9I09SwTl7wAAALU"]
[Mon Jul 20 07:27:58.401489 2026] [security2:error] [pid 145170:tid 145351] [client 36.93.152.155:57179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iXjjs5KUa9I09SwTl7wAAALU"]
[Mon Jul 20 07:27:58.466681 2026] [security2:error] [pid 145170:tid 145303] [client 14.225.17.146:58106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4iXDjs5KUa9I09SwTlWQAAAIU"], referer: http://ksands.co.uk/test
[Mon Jul 20 07:27:58.513037 2026] [security2:error] [pid 145170:tid 145237] [remote 173.249.4.11:44651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4iXjjs5KUa9I09SwTl-wAA_T8"]
[Mon Jul 20 07:27:58.562496 2026] [security2:error] [pid 145170:tid 145356] [client 57.141.18.123:31002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iWjjs5KUa9I09SwTkkgAAujE"]
[Mon Jul 20 07:27:58.700214 2026] [security2:error] [pid 145170:tid 145200] [remote 173.249.4.11:44651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4iXjjs5KUa9I09SwTmCwAAixo"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 07:27:58.764932 2026] [security2:error] [pid 145170:tid 145391] [client 14.225.17.146:54596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4iXTjs5KUa9I09SwTlsAAAAN0"], referer: http://intelligentengineeringsolutions.com/test
[Mon Jul 20 07:27:58.851955 2026] [security2:error] [pid 145170:tid 145307] [client 104.234.53.72:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iXjjs5KUa9I09SwTmFwAAAIk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:27:58.878589 2026] [security2:error] [pid 145170:tid 145319] [client 14.225.17.146:59404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4iXjjs5KUa9I09SwTmAwAAAJU"], referer: http://healthylifegourmet.org/test
[Mon Jul 20 07:27:58.940822 2026] [security2:error] [pid 145170:tid 145312] [client 14.225.17.146:54553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4iXjjs5KUa9I09SwTmGQAAAI4"]
[Mon Jul 20 07:27:59.027082 2026] [security2:error] [pid 145170:tid 145415] [client 14.225.17.146:57801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4iXTjs5KUa9I09SwTllAAAAPU"], referer: http://maxenengineering.com/test
[Mon Jul 20 07:27:59.060539 2026] [security2:error] [pid 145170:tid 145428] [client 57.141.18.99:40888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iWjjs5KUa9I09SwTkxwABAlU"]
[Mon Jul 20 07:27:59.119692 2026] [security2:error] [pid 145170:tid 145419] [client 103.176.215.66:50089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmOgAAAPk"]
[Mon Jul 20 07:27:59.119889 2026] [security2:error] [pid 145170:tid 145419] [client 103.176.215.66:50089] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmOgAAAPk"]
[Mon Jul 20 07:27:59.298025 2026] [security2:error] [pid 145170:tid 145240] [remote 18.61.192.253:40492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iXzjs5KUa9I09SwTmUAAAl0I"]
[Mon Jul 20 07:27:59.562760 2026] [security2:error] [pid 145170:tid 145346] [client 201.27.111.74:51540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmYQAAALA"]
[Mon Jul 20 07:27:59.562840 2026] [security2:error] [pid 145170:tid 145346] [client 201.27.111.74:51540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmYQAAALA"]
[Mon Jul 20 07:27:59.765986 2026] [security2:error] [pid 145170:tid 145252] [remote 18.61.192.253:40492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iXzjs5KUa9I09SwTmcQAA4k4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:27:59.768630 2026] [security2:error] [pid 145170:tid 145390] [client 103.106.165.44:63811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmcgAAANw"]
[Mon Jul 20 07:27:59.768723 2026] [security2:error] [pid 145170:tid 145390] [client 103.106.165.44:63811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmcgAAANw"]
[Mon Jul 20 07:27:59.788485 2026] [security2:error] [pid 145170:tid 145406] [client 14.225.17.146:54569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4iXjjs5KUa9I09SwTmGgAAAOw"]
[Mon Jul 20 07:27:59.841869 2026] [security2:error] [pid 145170:tid 145246] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmfQAAnEg"]
[Mon Jul 20 07:27:59.842071 2026] [security2:error] [pid 145170:tid 145326] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iXzjs5KUa9I09SwTmfQAAnEg"]
[Mon Jul 20 07:28:00.000242 2026] [security2:error] [pid 145170:tid 145411] [client 77.110.127.138:49648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iXzjs5KUa9I09SwTmiQAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:00.000353 2026] [security2:error] [pid 145170:tid 145411] [client 77.110.127.138:49648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iXzjs5KUa9I09SwTmiQAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:00.052528 2026] [security2:error] [pid 145170:tid 145181] [remote 45.150.79.142:59266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iYDjs5KUa9I09SwTmjAAAzQc"]
[Mon Jul 20 07:28:00.052631 2026] [security2:error] [pid 145170:tid 145375] [client 45.150.79.142:59266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iYDjs5KUa9I09SwTmjAAAzQc"]
[Mon Jul 20 07:28:00.092453 2026] [security2:error] [pid 145170:tid 145303] [client 14.225.17.146:59283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4iXzjs5KUa9I09SwTmhgAAAIU"], referer: https://maxenengineering.com/test
[Mon Jul 20 07:28:00.143679 2026] [security2:error] [pid 145170:tid 145422] [client 45.157.112.60:52943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iYDjs5KUa9I09SwTmjwAAAPw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:00.555883 2026] [security2:error] [pid 145170:tid 145356] [client 173.252.87.34:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nextlevelpressurewashing.com"] [uri "/index.php"] [unique_id "al4iYDjs5KUa9I09SwTmoAAAALo"]
[Mon Jul 20 07:28:00.597430 2026] [security2:error] [pid 145170:tid 145313] [client 57.141.18.15:57614] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iXDjs5KUa9I09SwTlbgAAjzU"]
[Mon Jul 20 07:28:00.705873 2026] [security2:error] [pid 145170:tid 145333] [client 45.149.78.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marketingonetoone.net"] [uri "/index.php"] [unique_id "al4iXzjs5KUa9I09SwTmVAAAAKM"]
[Mon Jul 20 07:28:00.712720 2026] [security2:error] [pid 145170:tid 145397] [client 45.149.78.11:47858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marketingonetoone.net"] [uri "/payment/index.php"] [unique_id "al4iXzjs5KUa9I09SwTmTwAAAOM"]
[Mon Jul 20 07:28:00.919623 2026] [security2:error] [pid 145170:tid 145375] [client 136.158.60.21:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iYDjs5KUa9I09SwTm1QAAAM0"]
[Mon Jul 20 07:28:00.920004 2026] [security2:error] [pid 145170:tid 145375] [client 136.158.60.21:49096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iYDjs5KUa9I09SwTm1QAAAM0"]
[Mon Jul 20 07:28:00.933704 2026] [security2:error] [pid 145170:tid 145322] [client 66.249.73.227:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4iYDjs5KUa9I09SwTmvwAAAJg"]
[Mon Jul 20 07:28:01.181599 2026] [security2:error] [pid 145170:tid 145281] [remote 72.167.132.114:40478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iYTjs5KUa9I09SwTm9QAA1Gs"]
[Mon Jul 20 07:28:01.181830 2026] [security2:error] [pid 145170:tid 145382] [client 72.167.132.114:40478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iYTjs5KUa9I09SwTm9QAA1Gs"]
[Mon Jul 20 07:28:01.571554 2026] [security2:error] [pid 145170:tid 145315] [client 45.149.78.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marketingonetoone.net"] [uri "/index.php"] [unique_id "al4iYTjs5KUa9I09SwTm8gAAAJE"]
[Mon Jul 20 07:28:01.601372 2026] [security2:error] [pid 145170:tid 145376] [client 57.141.18.18:32548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iXTjs5KUa9I09SwTlvwAAziM"]
[Mon Jul 20 07:28:01.762494 2026] [security2:error] [pid 145170:tid 145217] [remote 217.61.143.92:40528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iYTjs5KUa9I09SwTnHwAA4ys"]
[Mon Jul 20 07:28:01.996351 2026] [security2:error] [pid 145170:tid 145288] [remote 217.61.143.92:40528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iYTjs5KUa9I09SwTnWAAA_HI"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:28:02.088151 2026] [security2:error] [pid 145170:tid 145417] [client 14.225.17.146:59217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4iYTjs5KUa9I09SwTnUwAAAPc"], referer: http://lutheranphilosopher.com/test
[Mon Jul 20 07:28:02.093887 2026] [security2:error] [pid 145170:tid 145366] [client 14.225.17.146:51773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4iYDjs5KUa9I09SwTmugAAAMQ"], referer: http://eframiproperties.com/test
[Mon Jul 20 07:28:02.378966 2026] [security2:error] [pid 145170:tid 145319] [client 104.234.53.71:59607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iYjjs5KUa9I09SwTnjgAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:02.716025 2026] [security2:error] [pid 145170:tid 145430] [client 57.141.18.31:49964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iXzjs5KUa9I09SwTmSAABBGc"]
[Mon Jul 20 07:28:02.770345 2026] [security2:error] [pid 145170:tid 145383] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.earle-brown.org"] [uri "/index.php"] [unique_id "al4iYjjs5KUa9I09SwTnrQAAANU"]
[Mon Jul 20 07:28:03.126303 2026] [security2:error] [pid 145170:tid 145376] [client 158.173.89.95:61971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iYzjs5KUa9I09SwTn0gAAAM4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:03.133310 2026] [security2:error] [pid 145170:tid 145411] [client 191.202.66.27:60776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn0wAAAPE"]
[Mon Jul 20 07:28:03.133398 2026] [security2:error] [pid 145170:tid 145411] [client 191.202.66.27:60776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn0wAAAPE"]
[Mon Jul 20 07:28:03.178271 2026] [security2:error] [pid 145170:tid 145331] [client 88.241.67.160:55047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn2AAAAKE"]
[Mon Jul 20 07:28:03.178899 2026] [security2:error] [pid 145170:tid 145331] [client 88.241.67.160:55047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn2AAAAKE"]
[Mon Jul 20 07:28:03.187609 2026] [security2:error] [pid 145170:tid 145356] [client 18.141.57.241:18002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn1gAAALo"]
[Mon Jul 20 07:28:03.187711 2026] [security2:error] [pid 145170:tid 145356] [client 18.141.57.241:18002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn1gAAALo"]
[Mon Jul 20 07:28:03.348561 2026] [security2:error] [pid 145170:tid 145419] [client 154.208.48.130:64041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn5QAAAPk"]
[Mon Jul 20 07:28:03.348655 2026] [security2:error] [pid 145170:tid 145419] [client 154.208.48.130:64041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn5QAAAPk"]
[Mon Jul 20 07:28:03.553249 2026] [security2:error] [pid 145170:tid 145405] [client 77.110.127.138:49717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iYzjs5KUa9I09SwTn8wAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:03.553341 2026] [security2:error] [pid 145170:tid 145405] [client 77.110.127.138:49717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iYzjs5KUa9I09SwTn8wAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:03.633156 2026] [security2:error] [pid 145170:tid 145232] [remote 47.86.33.52:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4iYzjs5KUa9I09SwTn-AAA_zo"]
[Mon Jul 20 07:28:03.865627 2026] [security2:error] [pid 145170:tid 145205] [remote 47.86.33.52:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4iYzjs5KUa9I09SwToEgAAuB8"]
[Mon Jul 20 07:28:03.943276 2026] [security2:error] [pid 145170:tid 145352] [client 179.127.84.238:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwToFwAAALY"]
[Mon Jul 20 07:28:03.943424 2026] [security2:error] [pid 145170:tid 145352] [client 179.127.84.238:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwToFwAAALY"]
[Mon Jul 20 07:28:04.196677 2026] [security2:error] [pid 145170:tid 145358] [client 14.225.17.146:54624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4iZDjs5KUa9I09SwToIgAAALw"], referer: http://ivetstrategies.com/test
[Mon Jul 20 07:28:04.220142 2026] [autoindex:error] [pid 145170:tid 145354] [client 8.229.41.77:0] AH01276: Cannot serve directory /home1/heidimo2/strongtowerpodcast.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:28:04.261488 2026] [security2:error] [pid 145170:tid 145228] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iZDjs5KUa9I09SwToQwAAnTY"]
[Mon Jul 20 07:28:04.261669 2026] [security2:error] [pid 145170:tid 145327] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iZDjs5KUa9I09SwToQwAAnTY"]
[Mon Jul 20 07:28:04.345158 2026] [security2:error] [pid 145170:tid 145257] [remote 47.86.33.52:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.smithfamilyfoundationsunshine.org"] [uri "/wp-login.php"] [unique_id "al4iZDjs5KUa9I09SwToRgAA_lM"], referer: https://mail.smithfamilyfoundationsunshine.org/wp-login.php
[Mon Jul 20 07:28:04.383275 2026] [security2:error] [pid 145170:tid 145240] [remote 47.86.33.52:43708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4iZDjs5KUa9I09SwToRwAAsEI"], referer: https://sarahsnyder.net/wp-login.php
[Mon Jul 20 07:28:04.613644 2026] [security2:error] [pid 145170:tid 145319] [client 157.20.138.62:63235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iZDjs5KUa9I09SwToWAAAAJU"]
[Mon Jul 20 07:28:04.613782 2026] [security2:error] [pid 145170:tid 145319] [client 157.20.138.62:63235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iZDjs5KUa9I09SwToWAAAAJU"]
[Mon Jul 20 07:28:04.813339 2026] [security2:error] [pid 145170:tid 145270] [remote 45.150.79.142:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iZDjs5KUa9I09SwToZAAA9mA"]
[Mon Jul 20 07:28:04.977977 2026] [security2:error] [pid 145170:tid 145189] [remote 45.150.79.142:60784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4iZDjs5KUa9I09SwTobwAAvg8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:28:05.120414 2026] [security2:error] [pid 145170:tid 145326] [client 57.141.18.30:30650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iYTjs5KUa9I09SwTnFQAAnC8"]
[Mon Jul 20 07:28:05.205488 2026] [security2:error] [pid 145170:tid 145196] [remote 8.217.108.67:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4iZTjs5KUa9I09SwTogQAAjhY"]
[Mon Jul 20 07:28:05.498274 2026] [security2:error] [pid 145170:tid 145406] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4iYzjs5KUa9I09SwTn_QAA7Ck"]
[Mon Jul 20 07:28:05.734969 2026] [security2:error] [pid 145170:tid 145423] [client 158.173.166.181:22985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iZTjs5KUa9I09SwTopwAAAP0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:06.085557 2026] [security2:error] [pid 145170:tid 145384] [client 57.141.18.7:24008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iYjjs5KUa9I09SwTntQAA1k0"]
[Mon Jul 20 07:28:06.106237 2026] [security2:error] [pid 145170:tid 145283] [remote 8.217.108.67:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "snctaxgroup.com"] [uri "/wp-login.php"] [unique_id "al4iZjjs5KUa9I09SwToyAAAhm0"], referer: https://snctaxgroup.com/wp-login.php
[Mon Jul 20 07:28:06.358264 2026] [security2:error] [pid 145170:tid 145408] [client 104.234.53.88:64155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iZjjs5KUa9I09SwTo5AAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:06.426006 2026] [security2:error] [pid 145170:tid 145344] [client 14.225.17.146:60494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4iZTjs5KUa9I09SwTofAAAAK4"], referer: http://cloudspacesgroup.com/test
[Mon Jul 20 07:28:06.450779 2026] [security2:error] [pid 145170:tid 145354] [client 24.122.40.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4iZTjs5KUa9I09SwTovAAAuGw"]
[Mon Jul 20 07:28:06.661662 2026] [security2:error] [pid 145170:tid 145378] [client 57.141.18.51:20016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iYzjs5KUa9I09SwTn5wAA0AI"]
[Mon Jul 20 07:28:06.805274 2026] [security2:error] [pid 145170:tid 145373] [client 154.192.123.127:17403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iZjjs5KUa9I09SwTpCAAAAMs"]
[Mon Jul 20 07:28:06.805390 2026] [security2:error] [pid 145170:tid 145373] [client 154.192.123.127:17403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4iZjjs5KUa9I09SwTpCAAAAMs"]
[Mon Jul 20 07:28:07.290106 2026] [security2:error] [pid 145170:tid 145351] [client 14.225.17.146:59776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4iZTjs5KUa9I09SwTomQAAALU"], referer: http://nomorewetsheets.net/test
[Mon Jul 20 07:28:07.294922 2026] [security2:error] [pid 145170:tid 145397] [client 49.47.218.174:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpJwAAAOM"]
[Mon Jul 20 07:28:07.295153 2026] [security2:error] [pid 145170:tid 145397] [client 49.47.218.174:61928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpJwAAAOM"]
[Mon Jul 20 07:28:07.388233 2026] [security2:error] [pid 145170:tid 145407] [client 109.70.100.14:37564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.100.70.109.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpKwAAAO0"]
[Mon Jul 20 07:28:07.388327 2026] [security2:error] [pid 145170:tid 145407] [client 109.70.100.14:37564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samdothan.org"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpKwAAAO0"]
[Mon Jul 20 07:28:07.520770 2026] [security2:error] [pid 145170:tid 145357] [client 27.130.227.222:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4iZzjs5KUa9I09SwTpOAAAALs"]
[Mon Jul 20 07:28:07.523389 2026] [security2:error] [pid 145170:tid 145358] [client 27.130.227.222:59978] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aosta.nz"] [uri "/robots.txt"] [unique_id "al4iZzjs5KUa9I09SwTpMAAAALw"]
[Mon Jul 20 07:28:07.541723 2026] [security2:error] [pid 145170:tid 145421] [client 117.211.236.168:57423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpRgAAAPs"]
[Mon Jul 20 07:28:07.541851 2026] [security2:error] [pid 145170:tid 145421] [client 117.211.236.168:57423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpRgAAAPs"]
[Mon Jul 20 07:28:07.645316 2026] [core:error] [pid 145170:tid 145325] [client 64.23.161.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:28:07.645335 2026] [core:error] [pid 145170:tid 145325] [client 64.23.161.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:28:07.673186 2026] [security2:error] [pid 145170:tid 145392] [client 144.16.21.149:25256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4iZzjs5KUa9I09SwTpOQAAAN4"]
[Mon Jul 20 07:28:07.748759 2026] [security2:error] [pid 145170:tid 145396] [client 14.225.17.146:61364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4iZzjs5KUa9I09SwTpUwAAAOI"], referer: http://hammadownenterprises.com/test
[Mon Jul 20 07:28:07.875480 2026] [security2:error] [pid 145170:tid 145259] [remote 152.228.213.32:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iZzjs5KUa9I09SwTpawAApFU"]
[Mon Jul 20 07:28:08.087380 2026] [security2:error] [pid 145170:tid 145255] [remote 152.228.213.32:35726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iaDjs5KUa9I09SwTpdAAAzlE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:28:08.241058 2026] [security2:error] [pid 145170:tid 145288] [remote 57.141.18.31:25924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2955501"] [unique_id "al4iaDjs5KUa9I09SwTphgAApnI"]
[Mon Jul 20 07:28:08.420594 2026] [security2:error] [pid 145170:tid 145364] [client 57.141.18.15:56634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iZTjs5KUa9I09SwTodgAAwl4"]
[Mon Jul 20 07:28:08.509346 2026] [security2:error] [pid 145170:tid 145429] [client 77.110.127.138:49741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iaDjs5KUa9I09SwTpoAAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:08.509424 2026] [security2:error] [pid 145170:tid 145429] [client 77.110.127.138:49741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iaDjs5KUa9I09SwTpoAAAAQM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:08.602943 2026] [security2:error] [pid 145170:tid 145346] [client 112.86.225.21:50042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "goyalsatyam.com"] [uri "/"] [unique_id "al4iaDjs5KUa9I09SwTppAAAALA"]
[Mon Jul 20 07:28:08.603077 2026] [security2:error] [pid 145170:tid 145346] [client 112.86.225.21:50042] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "goyalsatyam.com"] [uri "/"] [unique_id "al4iaDjs5KUa9I09SwTppAAAALA"]
[Mon Jul 20 07:28:08.776137 2026] [security2:error] [pid 145170:tid 145318] [client 14.225.17.146:62954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4iaDjs5KUa9I09SwTppgAAAJQ"], referer: http://iagdevelopments.com/test
[Mon Jul 20 07:28:09.012130 2026] [security2:error] [pid 145170:tid 145312] [client 36.93.152.155:57697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTpzAAAAI4"]
[Mon Jul 20 07:28:09.012256 2026] [security2:error] [pid 145170:tid 145312] [client 36.93.152.155:57697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTpzAAAAI4"]
[Mon Jul 20 07:28:09.391854 2026] [security2:error] [pid 145170:tid 145424] [client 185.220.100.244:55110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 244.100.220.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTp5gAAAP4"]
[Mon Jul 20 07:28:09.391960 2026] [security2:error] [pid 145170:tid 145424] [client 185.220.100.244:55110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "samdothan.org"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTp5gAAAP4"]
[Mon Jul 20 07:28:09.527912 2026] [security2:error] [pid 145170:tid 145305] [client 57.141.18.120:49804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iZjjs5KUa9I09SwTo3gAAh1s"]
[Mon Jul 20 07:28:09.613587 2026] [security2:error] [pid 145170:tid 145254] [remote 100.42.189.89:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iaTjs5KUa9I09SwTp_QAA61A"]
[Mon Jul 20 07:28:09.616925 2026] [security2:error] [pid 145170:tid 145392] [client 103.176.215.66:50629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTp_gAAAN4"]
[Mon Jul 20 07:28:09.617078 2026] [security2:error] [pid 145170:tid 145392] [client 103.176.215.66:50629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTp_gAAAN4"]
[Mon Jul 20 07:28:09.631317 2026] [security2:error] [pid 145170:tid 145384] [client 104.234.53.54:61489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iaTjs5KUa9I09SwTqAQAAANY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:09.781888 2026] [security2:error] [pid 145170:tid 145367] [client 143.44.185.218:64745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTqDAAAAMU"]
[Mon Jul 20 07:28:09.782017 2026] [security2:error] [pid 145170:tid 145367] [client 143.44.185.218:64745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iaTjs5KUa9I09SwTqDAAAAMU"]
[Mon Jul 20 07:28:09.818921 2026] [security2:error] [pid 145170:tid 145280] [remote 100.42.189.89:58928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iaTjs5KUa9I09SwTqEQAArmo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:28:09.832234 2026] [security2:error] [pid 145170:tid 145325] [client 27.130.227.222:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4iaTjs5KUa9I09SwTp9AAAAJs"]
[Mon Jul 20 07:28:09.835543 2026] [security2:error] [pid 145170:tid 145397] [client 27.130.227.222:21666] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "aosta.nz"] [uri "/whats-on/"] [unique_id "al4iaTjs5KUa9I09SwTp8QAAAOM"]
[Mon Jul 20 07:28:09.940730 2026] [security2:error] [pid 145170:tid 145408] [client 14.225.17.146:63243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4iaDjs5KUa9I09SwTpkgAAAO4"], referer: http://nurturemarple.co.uk/test
[Mon Jul 20 07:28:09.982185 2026] [security2:error] [pid 145170:tid 145323] [client 169.224.68.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4iaDjs5KUa9I09SwTplQAAAJk"]
[Mon Jul 20 07:28:09.983864 2026] [security2:error] [pid 145170:tid 145190] [remote 97.74.93.24:35998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4iaTjs5KUa9I09SwTqJAAAlxA"]
[Mon Jul 20 07:28:10.088495 2026] [security2:error] [pid 145170:tid 145399] [client 201.27.111.74:52051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iajjs5KUa9I09SwTqKQAAAOU"]
[Mon Jul 20 07:28:10.088628 2026] [security2:error] [pid 145170:tid 145399] [client 201.27.111.74:52051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iajjs5KUa9I09SwTqKQAAAOU"]
[Mon Jul 20 07:28:10.253362 2026] [security2:error] [pid 145170:tid 145406] [client 103.106.165.44:64299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iajjs5KUa9I09SwTqOAAAAOw"]
[Mon Jul 20 07:28:10.253522 2026] [security2:error] [pid 145170:tid 145406] [client 103.106.165.44:64299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iajjs5KUa9I09SwTqOAAAAOw"]
[Mon Jul 20 07:28:10.400063 2026] [security2:error] [pid 145170:tid 145263] [remote 97.74.93.24:35998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allandbeckson.com"] [uri "/wp-login.php"] [unique_id "al4iajjs5KUa9I09SwTqRAAAz1k"], referer: https://allandbeckson.com/wp-login.php
[Mon Jul 20 07:28:10.438544 2026] [security2:error] [pid 145170:tid 145421] [client 50.116.65.227:31072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4iajjs5KUa9I09SwTqJgAAAPs"]
[Mon Jul 20 07:28:10.442875 2026] [http2:info] [pid 148765:tid 148765] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:28:10.447408 2026] [security2:error] [pid 145170:tid 145303] [client 14.225.17.146:63360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4iajjs5KUa9I09SwTqQwAAAIU"], referer: http://grndl.com/test
[Mon Jul 20 07:28:10.454725 2026] [security2:error] [pid 145170:tid 145356] [client 14.225.17.146:62155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4iaTjs5KUa9I09SwTp0QAAALo"], referer: http://colinkeyphotography.com/test
[Mon Jul 20 07:28:10.605305 2026] [security2:error] [pid 145170:tid 145419] [client 169.224.68.58:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4iajjs5KUa9I09SwTqTgAAAPk"]
[Mon Jul 20 07:28:10.661596 2026] [security2:error] [pid 145170:tid 145387] [client 50.116.65.227:31080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4iajjs5KUa9I09SwTqSwAAANk"]
[Mon Jul 20 07:28:10.689027 2026] [security2:error] [pid 145170:tid 145310] [client 57.141.18.33:32920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iZzjs5KUa9I09SwTpOwAAjGY"]
[Mon Jul 20 07:28:10.856155 2026] [security2:error] [pid 145170:tid 145386] [client 49.37.242.14:57606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iajjs5KUa9I09SwTqYgAAANg"]
[Mon Jul 20 07:28:10.856302 2026] [security2:error] [pid 145170:tid 145386] [client 49.37.242.14:57606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iajjs5KUa9I09SwTqYgAAANg"]
[Mon Jul 20 07:28:10.900450 2026] [security2:error] [pid 145170:tid 145177] [remote 57.141.18.111:44246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3187219"] [unique_id "al4iajjs5KUa9I09SwTqZgAA-wM"]
[Mon Jul 20 07:28:10.991040 2026] [security2:error] [pid 145170:tid 145401] [client 136.144.33.206:32297] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4iaTjs5KUa9I09SwTp-wAAAOc"]
[Mon Jul 20 07:28:11.015092 2026] [security2:error] [pid 145170:tid 145341] [client 193.36.225.4:52021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4iaTjs5KUa9I09SwTp-gAAAKs"]
[Mon Jul 20 07:28:11.085543 2026] [security2:error] [pid 145170:tid 145262] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iazjs5KUa9I09SwTqeAAAiVg"]
[Mon Jul 20 07:28:11.085778 2026] [security2:error] [pid 145170:tid 145307] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iazjs5KUa9I09SwTqeAAAiVg"]
[Mon Jul 20 07:28:11.464345 2026] [proxy:error] [pid 148765:tid 148935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:28:11.464411 2026] [proxy_http:error] [pid 148765:tid 148935] [client 198.235.24.146:65024] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:28:11.464999 2026] [proxy:error] [pid 148765:tid 148935] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:28:11.465024 2026] [proxy_http:error] [pid 148765:tid 148935] [client 198.235.24.146:65024] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:28:11.525177 2026] [security2:error] [pid 145170:tid 145404] [client 14.225.17.146:60944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4iajjs5KUa9I09SwTqJwAAAOo"], referer: http://expertcultures.com/test
[Mon Jul 20 07:28:11.591481 2026] [security2:error] [pid 148765:tid 148925] [client 136.158.60.21:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iazv8fXmqCm8fNeqCpAAAASQ"]
[Mon Jul 20 07:28:11.591641 2026] [security2:error] [pid 148765:tid 148925] [client 136.158.60.21:50504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iazv8fXmqCm8fNeqCpAAAASQ"]
[Mon Jul 20 07:28:11.649551 2026] [security2:error] [pid 145170:tid 145407] [client 57.141.18.96:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4iaTjs5KUa9I09SwTqIAAAAO0"]
[Mon Jul 20 07:28:11.899225 2026] [security2:error] [pid 148765:tid 148963] [client 198.98.54.225:54002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.54.98.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "naturalsolutionsurbanforestry.com"] [uri "/wp-login.php"] [unique_id "al4iazv8fXmqCm8fNeqCtQAAAUo"]
[Mon Jul 20 07:28:12.137638 2026] [security2:error] [pid 145170:tid 145332] [client 57.141.18.108:31994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iaTjs5KUa9I09SwTp1AAAogg"]
[Mon Jul 20 07:28:12.144050 2026] [security2:error] [pid 145170:tid 145344] [client 14.225.17.146:59586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4iajjs5KUa9I09SwTqTAAAAK4"], referer: http://koaconsultants.com/test
[Mon Jul 20 07:28:12.343639 2026] [security2:error] [pid 145170:tid 145324] [client 147.139.177.58:59510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.177.139.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ibDjs5KUa9I09SwTqrgAAAJo"]
[Mon Jul 20 07:28:12.540494 2026] [security2:error] [pid 145170:tid 145286] [remote 188.40.28.4:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4ibDjs5KUa9I09SwTqtwAAo3A"]
[Mon Jul 20 07:28:12.652866 2026] [security2:error] [pid 145170:tid 145430] [client 57.141.18.87:44742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iaTjs5KUa9I09SwTp-QABBAo"]
[Mon Jul 20 07:28:12.746689 2026] [security2:error] [pid 145170:tid 145284] [remote 188.40.28.4:57030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4ibDjs5KUa9I09SwTqwgAA3W4"], referer: https://mail.qix.pfz.mybluehost.me/wp/wp-login.php
[Mon Jul 20 07:28:12.923238 2026] [security2:error] [pid 145170:tid 145420] [client 147.139.177.58:59518] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ferrellroofing.com"] [uri "/"] [unique_id "al4ibDjs5KUa9I09SwTqxwAAAPo"]
[Mon Jul 20 07:28:13.502086 2026] [security2:error] [pid 145170:tid 145379] [client 14.225.17.146:60653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4iazjs5KUa9I09SwTqoAAAANE"], referer: http://margaretspeckogawa.com/test
[Mon Jul 20 07:28:13.524034 2026] [security2:error] [pid 148765:tid 148975] [client 147.139.177.58:59525] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.177.139.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ibTv8fXmqCm8fNeqC7wAAAVY"]
[Mon Jul 20 07:28:13.545245 2026] [security2:error] [pid 148765:tid 148946] [client 14.225.17.146:62644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4ibTv8fXmqCm8fNeqC6wAAATk"], referer: http://savilerowtravel.com/test
[Mon Jul 20 07:28:13.820297 2026] [security2:error] [pid 145170:tid 145429] [client 191.202.66.27:61271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ibTjs5KUa9I09SwTq5AAAAQM"]
[Mon Jul 20 07:28:13.820382 2026] [security2:error] [pid 145170:tid 145429] [client 191.202.66.27:61271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ibTjs5KUa9I09SwTq5AAAAQM"]
[Mon Jul 20 07:28:13.856098 2026] [security2:error] [pid 145170:tid 145315] [client 88.241.67.160:56664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ibTjs5KUa9I09SwTq5gAAAJE"]
[Mon Jul 20 07:28:13.856419 2026] [security2:error] [pid 145170:tid 145315] [client 88.241.67.160:56664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ibTjs5KUa9I09SwTq5gAAAJE"]
[Mon Jul 20 07:28:13.879072 2026] [security2:error] [pid 148765:tid 148997] [client 77.110.127.138:49773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ibTv8fXmqCm8fNeqC-QAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:13.879161 2026] [security2:error] [pid 148765:tid 148997] [client 77.110.127.138:49773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ibTv8fXmqCm8fNeqC-QAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:14.102456 2026] [security2:error] [pid 145170:tid 145327] [client 147.139.177.58:59532] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ferrellroofing.com"] [uri "/"] [unique_id "al4ibjjs5KUa9I09SwTq8AAAAJ0"]
[Mon Jul 20 07:28:14.205358 2026] [security2:error] [pid 148765:tid 148917] [client 57.141.18.12:23728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iazv8fXmqCm8fNeqCmQABHAI"]
[Mon Jul 20 07:28:14.311364 2026] [security2:error] [pid 148765:tid 148983] [client 154.208.48.130:64574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ibjv8fXmqCm8fNeqDBgAAAV4"]
[Mon Jul 20 07:28:14.311536 2026] [security2:error] [pid 148765:tid 148983] [client 154.208.48.130:64574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ibjv8fXmqCm8fNeqDBgAAAV4"]
[Mon Jul 20 07:28:14.535898 2026] [security2:error] [pid 148765:tid 149021] [client 179.127.84.238:62743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ibjv8fXmqCm8fNeqDDgAAAYQ"]
[Mon Jul 20 07:28:14.536035 2026] [security2:error] [pid 148765:tid 149021] [client 179.127.84.238:62743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ibjv8fXmqCm8fNeqDDgAAAYQ"]
[Mon Jul 20 07:28:14.544112 2026] [security2:error] [pid 145170:tid 145279] [remote 173.212.252.15:39378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ibjjs5KUa9I09SwTrCgAAtmk"]
[Mon Jul 20 07:28:14.680826 2026] [security2:error] [pid 148765:tid 148921] [client 147.139.177.58:59535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.177.139.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ibjv8fXmqCm8fNeqDEwAAASA"]
[Mon Jul 20 07:28:14.762433 2026] [security2:error] [pid 145170:tid 145204] [remote 173.212.252.15:39378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4ibjjs5KUa9I09SwTrFAAAmh4"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:28:14.938109 2026] [security2:error] [pid 145170:tid 145256] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ibjjs5KUa9I09SwTrGAAA91I"]
[Mon Jul 20 07:28:14.938280 2026] [security2:error] [pid 145170:tid 145417] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ibjjs5KUa9I09SwTrGAAA91I"]
[Mon Jul 20 07:28:15.197406 2026] [security2:error] [pid 148765:tid 148941] [client 157.20.138.62:63807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ibzv8fXmqCm8fNeqDHgAAATQ"]
[Mon Jul 20 07:28:15.197620 2026] [security2:error] [pid 148765:tid 148941] [client 157.20.138.62:63807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ibzv8fXmqCm8fNeqDHgAAATQ"]
[Mon Jul 20 07:28:15.256263 2026] [security2:error] [pid 148765:tid 148965] [client 147.139.177.58:59543] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ferrellroofing.com"] [uri "/"] [unique_id "al4ibzv8fXmqCm8fNeqDIQAAAUw"]
[Mon Jul 20 07:28:15.525372 2026] [fcgid:warn] [pid 145170:tid 145312] (70014)End of file found: [client 66.132.224.230:50012] mod_fcgid: can't get data from http client
[Mon Jul 20 07:28:15.774610 2026] [security2:error] [pid 145170:tid 145289] [remote 100.42.189.89:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ibzjs5KUa9I09SwTrQQAA7nM"]
[Mon Jul 20 07:28:15.840529 2026] [security2:error] [pid 148765:tid 148979] [client 147.139.177.58:59546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.177.139.147.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ferrellroofing.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ibzv8fXmqCm8fNeqDLAAAAVo"]
[Mon Jul 20 07:28:15.885990 2026] [security2:error] [pid 145170:tid 145395] [client 57.141.18.86:39170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ibDjs5KUa9I09SwTqwQAA4W8"]
[Mon Jul 20 07:28:15.971173 2026] [security2:error] [pid 145170:tid 145257] [remote 100.42.189.89:52150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ibzjs5KUa9I09SwTrRwAAwlM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:28:16.076706 2026] [security2:error] [pid 145170:tid 145409] [client 3.78.190.80:57174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ibzjs5KUa9I09SwTrKgAAAO8"]
[Mon Jul 20 07:28:16.095175 2026] [security2:error] [pid 148765:tid 148985] [client 14.225.17.146:60796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4ibTv8fXmqCm8fNeqC-gAAAWA"], referer: http://latiendadejorge.com.gt/test
[Mon Jul 20 07:28:16.148732 2026] [security2:error] [pid 148765:tid 148801] [remote 5.252.52.249:45636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4icDv8fXmqCm8fNeqDOQABXh8"]
[Mon Jul 20 07:28:16.320050 2026] [security2:error] [pid 148765:tid 148802] [remote 5.252.52.249:45636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4icDv8fXmqCm8fNeqDPgABhCA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:28:16.347914 2026] [security2:error] [pid 148765:tid 148900] [client 117.211.236.168:57965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4icDv8fXmqCm8fNeqDPwAAAQs"]
[Mon Jul 20 07:28:16.348030 2026] [security2:error] [pid 148765:tid 148900] [client 117.211.236.168:57965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4icDv8fXmqCm8fNeqDPwAAAQs"]
[Mon Jul 20 07:28:16.450499 2026] [security2:error] [pid 148765:tid 148929] [client 147.139.177.58:59552] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "ferrellroofing.com"] [uri "/"] [unique_id "al4icDv8fXmqCm8fNeqDRgAAASg"]
[Mon Jul 20 07:28:16.778780 2026] [security2:error] [pid 148765:tid 148994] [client 57.141.18.125:34324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ibTv8fXmqCm8fNeqC9QABaRA"]
[Mon Jul 20 07:28:16.928124 2026] [security2:error] [pid 148765:tid 148809] [remote 8.217.108.67:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4icDv8fXmqCm8fNeqDWAABRic"]
[Mon Jul 20 07:28:16.929317 2026] [security2:error] [pid 145170:tid 145333] [client 57.141.18.58:61812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ibTjs5KUa9I09SwTq6AAAo2c"]
[Mon Jul 20 07:28:17.091951 2026] [security2:error] [pid 148765:tid 148921] [client 202.141.11.99:37061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4icTv8fXmqCm8fNeqDWgAAASA"]
[Mon Jul 20 07:28:17.092070 2026] [security2:error] [pid 148765:tid 148921] [client 202.141.11.99:37061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4icTv8fXmqCm8fNeqDWgAAASA"]
[Mon Jul 20 07:28:17.813329 2026] [security2:error] [pid 145170:tid 145384] [client 49.47.218.174:62471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4icTjs5KUa9I09SwTrpQAAANY"]
[Mon Jul 20 07:28:17.813439 2026] [security2:error] [pid 145170:tid 145384] [client 49.47.218.174:62471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4icTjs5KUa9I09SwTrpQAAANY"]
[Mon Jul 20 07:28:17.927123 2026] [security2:error] [pid 148765:tid 148990] [client 57.141.18.62:36898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ibzv8fXmqCm8fNeqDHQABZRk"]
[Mon Jul 20 07:28:18.016624 2026] [security2:error] [pid 145170:tid 145413] [client 14.225.17.146:50384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4icTjs5KUa9I09SwTrkwAAAPM"], referer: http://idigress.group/test
[Mon Jul 20 07:28:18.026544 2026] [security2:error] [pid 145170:tid 145305] [client 14.225.17.146:60314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4icDjs5KUa9I09SwTraAAAAIc"], referer: http://elitetax-mi.com/test
[Mon Jul 20 07:28:18.132681 2026] [security2:error] [pid 145170:tid 145403] [client 154.192.123.127:17847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4icjjs5KUa9I09SwTrqwAAAOk"]
[Mon Jul 20 07:28:18.132799 2026] [security2:error] [pid 145170:tid 145403] [client 154.192.123.127:17847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4icjjs5KUa9I09SwTrqwAAAOk"]
[Mon Jul 20 07:28:18.391599 2026] [security2:error] [pid 148765:tid 148985] [client 144.16.21.149:36315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4icjv8fXmqCm8fNeqDdwAAAWA"]
[Mon Jul 20 07:28:18.648026 2026] [security2:error] [pid 148765:tid 149010] [client 57.141.18.94:21000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ibzv8fXmqCm8fNeqDLQABeRw"]
[Mon Jul 20 07:28:18.813208 2026] [security2:error] [pid 145170:tid 145369] [client 194.180.48.253:59700] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "cathyspeed.org"] [uri "/"] [unique_id "al4icjjs5KUa9I09SwTr1wAAAMc"]
[Mon Jul 20 07:28:19.153476 2026] [security2:error] [pid 148765:tid 149013] [client 20.55.35.217:56684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4iczv8fXmqCm8fNeqDlgAAAXw"]
[Mon Jul 20 07:28:19.221270 2026] [security2:error] [pid 148765:tid 148904] [client 57.141.18.72:21684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4icDv8fXmqCm8fNeqDRQABDyI"]
[Mon Jul 20 07:28:19.221836 2026] [core:error] [pid 145170:tid 145305] [client 14.225.17.146:50452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/test
[Mon Jul 20 07:28:19.221853 2026] [core:error] [pid 145170:tid 145305] [client 14.225.17.146:50452] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/test
[Mon Jul 20 07:28:19.294628 2026] [security2:error] [pid 148765:tid 148938] [client 77.110.127.138:49813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iczv8fXmqCm8fNeqDngAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:19.294718 2026] [security2:error] [pid 148765:tid 148938] [client 77.110.127.138:49813] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iczv8fXmqCm8fNeqDngAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:19.442727 2026] [security2:error] [pid 148765:tid 148905] [client 36.93.152.155:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iczv8fXmqCm8fNeqDpgAAARA"]
[Mon Jul 20 07:28:19.442875 2026] [security2:error] [pid 148765:tid 148905] [client 36.93.152.155:58216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iczv8fXmqCm8fNeqDpgAAARA"]
[Mon Jul 20 07:28:19.546210 2026] [security2:error] [pid 148765:tid 148823] [remote 8.217.108.67:12312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4iczv8fXmqCm8fNeqDrAABDTU"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:28:19.907526 2026] [security2:error] [pid 148765:tid 148940] [client 41.225.92.8:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4iczv8fXmqCm8fNeqDrgAAATM"], referer: https://worbals.com
[Mon Jul 20 07:28:20.049876 2026] [security2:error] [pid 148765:tid 148947] [client 98.159.234.160:53477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4idDv8fXmqCm8fNeqDwgAAATo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:20.137583 2026] [security2:error] [pid 148765:tid 149006] [client 57.141.18.33:44554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4icTv8fXmqCm8fNeqDYQABdSk"]
[Mon Jul 20 07:28:20.181562 2026] [security2:error] [pid 148765:tid 148928] [client 103.176.215.66:51167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4idDv8fXmqCm8fNeqDxQAAASc"]
[Mon Jul 20 07:28:20.182165 2026] [security2:error] [pid 148765:tid 148928] [client 103.176.215.66:51167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4idDv8fXmqCm8fNeqDxQAAASc"]
[Mon Jul 20 07:28:20.496091 2026] [security2:error] [pid 148765:tid 148990] [client 201.27.111.74:52557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4idDv8fXmqCm8fNeqD0gAAAWU"]
[Mon Jul 20 07:28:20.496211 2026] [security2:error] [pid 148765:tid 148990] [client 201.27.111.74:52557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4idDv8fXmqCm8fNeqD0gAAAWU"]
[Mon Jul 20 07:28:20.510529 2026] [security2:error] [pid 148765:tid 148913] [client 57.141.18.4:37176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4icTv8fXmqCm8fNeqDbwABGCw"]
[Mon Jul 20 07:28:20.723254 2026] [security2:error] [pid 145170:tid 145356] [client 66.249.79.200:46647] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "truenorthreview.com"] [uri "/robots.txt"] [unique_id "al4idDjs5KUa9I09SwTsHQAAALo"]
[Mon Jul 20 07:28:20.807034 2026] [security2:error] [pid 148765:tid 149019] [client 103.106.165.44:64787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4idDv8fXmqCm8fNeqD3wAAAYI"]
[Mon Jul 20 07:28:20.807138 2026] [security2:error] [pid 148765:tid 149019] [client 103.106.165.44:64787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4idDv8fXmqCm8fNeqD3wAAAYI"]
[Mon Jul 20 07:28:21.157601 2026] [security2:error] [pid 145170:tid 145421] [client 143.44.185.218:662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4idTjs5KUa9I09SwTsLQAAAPs"]
[Mon Jul 20 07:28:21.157716 2026] [security2:error] [pid 145170:tid 145421] [client 143.44.185.218:662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4idTjs5KUa9I09SwTsLQAAAPs"]
[Mon Jul 20 07:28:21.218958 2026] [security2:error] [pid 148765:tid 148941] [client 14.225.17.146:64934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4iczv8fXmqCm8fNeqDvAAAATQ"], referer: http://alaraycreative.com/test
[Mon Jul 20 07:28:21.465370 2026] [security2:error] [pid 148765:tid 148839] [remote 91.142.222.105:35760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4idTv8fXmqCm8fNeqD-QABM0U"]
[Mon Jul 20 07:28:21.716922 2026] [security2:error] [pid 148765:tid 148844] [remote 91.142.222.105:35760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4idTv8fXmqCm8fNeqEAQABZUo"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:28:21.731364 2026] [security2:error] [pid 145170:tid 145364] [client 57.141.18.12:23740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iczjs5KUa9I09SwTr7wAAwjg"]
[Mon Jul 20 07:28:21.825615 2026] [security2:error] [pid 148765:tid 148907] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4idTv8fXmqCm8fNeqEAAABEkk"], referer: http://ali-alghanim.net/test
[Mon Jul 20 07:28:21.841170 2026] [security2:error] [pid 148765:tid 149010] [client 57.141.18.48:55136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iczv8fXmqCm8fNeqDrwABeTY"]
[Mon Jul 20 07:28:22.093218 2026] [security2:error] [pid 148765:tid 148847] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4idjv8fXmqCm8fNeqEEgABSE0"]
[Mon Jul 20 07:28:22.093379 2026] [security2:error] [pid 148765:tid 148961] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4idjv8fXmqCm8fNeqEEgABSE0"]
[Mon Jul 20 07:28:22.269301 2026] [security2:error] [pid 145170:tid 145333] [client 136.158.60.21:52107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4idjjs5KUa9I09SwTsYAAAAKM"]
[Mon Jul 20 07:28:22.269648 2026] [security2:error] [pid 145170:tid 145333] [client 136.158.60.21:52107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4idjjs5KUa9I09SwTsYAAAAKM"]
[Mon Jul 20 07:28:22.725506 2026] [security2:error] [pid 148765:tid 148958] [client 57.141.18.55:36194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idDv8fXmqCm8fNeqD1wABRT0"]
[Mon Jul 20 07:28:22.941153 2026] [security2:error] [pid 148765:tid 148965] [client 57.141.18.22:46830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idDv8fXmqCm8fNeqD4gABTEA"]
[Mon Jul 20 07:28:23.109298 2026] [security2:error] [pid 148765:tid 149017] [client 104.234.53.62:48545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4idzv8fXmqCm8fNeqEMgAAAYA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:23.382441 2026] [security2:error] [pid 148765:tid 148993] [client 57.141.18.32:58142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idTv8fXmqCm8fNeqD9wABaEQ"]
[Mon Jul 20 07:28:23.476192 2026] [security2:error] [pid 148765:tid 148976] [client 77.110.127.138:49830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4idzv8fXmqCm8fNeqESgAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:23.476293 2026] [security2:error] [pid 148765:tid 148976] [client 77.110.127.138:49830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4idzv8fXmqCm8fNeqESgAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:23.597844 2026] [security2:error] [pid 145170:tid 145345] [client 201.187.156.149:41466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idTjs5KUa9I09SwTsRQAAr0k"], referer: https://toddnielsen.com
[Mon Jul 20 07:28:23.826872 2026] [security2:error] [pid 145170:tid 145354] [client 57.141.18.98:25566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idTjs5KUa9I09SwTsTQAAuHg"]
[Mon Jul 20 07:28:24.110701 2026] [security2:error] [pid 148765:tid 148884] [remote 182.77.62.24:44392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ieDv8fXmqCm8fNeqEcwABanI"]
[Mon Jul 20 07:28:24.236253 2026] [security2:error] [pid 145170:tid 145341] [client 43.135.107.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4ieDjs5KUa9I09SwTsjwAAAKs"]
[Mon Jul 20 07:28:24.251715 2026] [security2:error] [pid 145170:tid 145348] [client 14.225.17.146:51030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4ieDjs5KUa9I09SwTskwAAALI"], referer: http://nextlvlmarketingco.com/test
[Mon Jul 20 07:28:24.473072 2026] [security2:error] [pid 148765:tid 148981] [client 57.141.18.70:26850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idjv8fXmqCm8fNeqEHAABXFE"]
[Mon Jul 20 07:28:24.526834 2026] [security2:error] [pid 148765:tid 149015] [client 191.202.66.27:61765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ieDv8fXmqCm8fNeqEigAAAX4"]
[Mon Jul 20 07:28:24.526960 2026] [security2:error] [pid 148765:tid 149015] [client 191.202.66.27:61765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ieDv8fXmqCm8fNeqEigAAAX4"]
[Mon Jul 20 07:28:24.556282 2026] [security2:error] [pid 148765:tid 148949] [client 57.141.18.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ieDv8fXmqCm8fNeqEgwAAATw"]
[Mon Jul 20 07:28:24.611781 2026] [security2:error] [pid 148765:tid 148770] [remote 182.77.62.24:44392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ieDv8fXmqCm8fNeqEkAABeAA"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:28:24.780154 2026] [security2:error] [pid 145170:tid 145390] [client 88.241.67.160:54698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ieDjs5KUa9I09SwTspQAAANw"]
[Mon Jul 20 07:28:24.780281 2026] [security2:error] [pid 145170:tid 145390] [client 88.241.67.160:54698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ieDjs5KUa9I09SwTspQAAANw"]
[Mon Jul 20 07:28:24.873077 2026] [security2:error] [pid 145170:tid 145329] [client 188.166.241.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4ieDjs5KUa9I09SwTsqAAAAJ8"]
[Mon Jul 20 07:28:25.005312 2026] [security2:error] [pid 148765:tid 148900] [client 57.141.18.109:46252] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idjv8fXmqCm8fNeqELgABC1o"]
[Mon Jul 20 07:28:25.210394 2026] [security2:error] [pid 148765:tid 148907] [client 179.127.84.238:63254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTv8fXmqCm8fNeqErgAAARI"]
[Mon Jul 20 07:28:25.210503 2026] [security2:error] [pid 148765:tid 148907] [client 179.127.84.238:63254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTv8fXmqCm8fNeqErgAAARI"]
[Mon Jul 20 07:28:25.249804 2026] [security2:error] [pid 145170:tid 145351] [client 154.208.48.130:65102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ieTjs5KUa9I09SwTsswAAALU"]
[Mon Jul 20 07:28:25.250559 2026] [security2:error] [pid 145170:tid 145351] [client 154.208.48.130:65102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ieTjs5KUa9I09SwTsswAAALU"]
[Mon Jul 20 07:28:25.318425 2026] [security2:error] [pid 148765:tid 149008] [client 57.141.18.79:40884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idzv8fXmqCm8fNeqERAABd2I"]
[Mon Jul 20 07:28:25.357897 2026] [security2:error] [pid 148765:tid 148946] [client 188.166.241.141:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thescarystory.com"] [uri "/wp-login.php"] [unique_id "al4ieTv8fXmqCm8fNeqEtQAAATk"], referer: https://thescarystory.com/wp-login.php
[Mon Jul 20 07:28:25.625524 2026] [security2:error] [pid 148765:tid 148790] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTv8fXmqCm8fNeqExgABfhQ"]
[Mon Jul 20 07:28:25.625720 2026] [security2:error] [pid 148765:tid 149015] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTv8fXmqCm8fNeqExgABfhQ"]
[Mon Jul 20 07:28:25.625945 2026] [security2:error] [pid 145170:tid 145422] [client 3.67.192.83:42500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTjs5KUa9I09SwTsuQAAAPw"]
[Mon Jul 20 07:28:25.626058 2026] [security2:error] [pid 145170:tid 145422] [client 3.67.192.83:42500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTjs5KUa9I09SwTsuQAAAPw"]
[Mon Jul 20 07:28:25.672945 2026] [security2:error] [pid 145170:tid 145406] [client 157.20.138.62:64377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTjs5KUa9I09SwTsuwAAAOw"]
[Mon Jul 20 07:28:25.674574 2026] [security2:error] [pid 145170:tid 145406] [client 157.20.138.62:64377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ieTjs5KUa9I09SwTsuwAAAOw"]
[Mon Jul 20 07:28:25.813597 2026] [security2:error] [pid 148765:tid 148910] [client 14.225.17.146:64369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4ieTv8fXmqCm8fNeqEtwAAARU"], referer: http://uritems.net/test
[Mon Jul 20 07:28:25.833473 2026] [security2:error] [pid 148765:tid 149013] [client 57.141.18.91:56608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4idzv8fXmqCm8fNeqEYgABfGs"]
[Mon Jul 20 07:28:25.922837 2026] [security2:error] [pid 145170:tid 145330] [client 104.234.53.88:42097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ieTjs5KUa9I09SwTsxQAAAKA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:26.012957 2026] [security2:error] [pid 145170:tid 145354] [client 14.225.17.146:50996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4ieTjs5KUa9I09SwTswAAAALg"], referer: https://north-woods-engineering.com/test
[Mon Jul 20 07:28:26.154121 2026] [security2:error] [pid 145170:tid 145360] [client 57.141.18.118:30286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ieDjs5KUa9I09SwTskAAAvn4"]
[Mon Jul 20 07:28:26.396272 2026] [security2:error] [pid 148765:tid 149008] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4iejv8fXmqCm8fNeqE4QABdxs"]
[Mon Jul 20 07:28:26.763451 2026] [security2:error] [pid 148765:tid 148987] [client 57.141.18.41:53324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ieDv8fXmqCm8fNeqEnAABYgM"]
[Mon Jul 20 07:28:27.275093 2026] [security2:error] [pid 148765:tid 148983] [client 117.211.236.168:58540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iezv8fXmqCm8fNeqFEQAAAV4"]
[Mon Jul 20 07:28:27.275195 2026] [security2:error] [pid 148765:tid 148983] [client 117.211.236.168:58540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iezv8fXmqCm8fNeqFEQAAAV4"]
[Mon Jul 20 07:28:27.793395 2026] [security2:error] [pid 145170:tid 145379] [client 14.225.17.146:50864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4iejjs5KUa9I09SwTs4wAAANE"], referer: http://whiteoutcb.com/test
[Mon Jul 20 07:28:28.196406 2026] [security2:error] [pid 145170:tid 145334] [client 74.7.227.179:40898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ifDjs5KUa9I09SwTtBQAApFY"], referer: https://tejasenvironmental.com/p=507639
[Mon Jul 20 07:28:28.241775 2026] [security2:error] [pid 145170:tid 145373] [client 104.234.53.77:45171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ifDjs5KUa9I09SwTtCAAAAMs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:28.259834 2026] [security2:error] [pid 145170:tid 145304] [client 49.47.218.174:35612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDjs5KUa9I09SwTtDAAAAIY"]
[Mon Jul 20 07:28:28.259959 2026] [security2:error] [pid 145170:tid 145304] [client 49.47.218.174:35612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDjs5KUa9I09SwTtDAAAAIY"]
[Mon Jul 20 07:28:28.417724 2026] [security2:error] [pid 148765:tid 148984] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDv8fXmqCm8fNeqFQAABX0c"]
[Mon Jul 20 07:28:28.422491 2026] [security2:error] [pid 148765:tid 148901] [client 114.119.158.253:62881] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "massagelacey.com"] [uri "/medical-massage-vs-relaxation-massage/"] [unique_id "al4ifDv8fXmqCm8fNeqFQwAAAQw"], referer: https://massagelacey.com/category/massage-techniques
[Mon Jul 20 07:28:28.460966 2026] [security2:error] [pid 148765:tid 149022] [client 57.141.18.73:36966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iejv8fXmqCm8fNeqE9gABhSU"]
[Mon Jul 20 07:28:28.682636 2026] [security2:error] [pid 148765:tid 148932] [client 77.110.127.138:49850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ifDv8fXmqCm8fNeqFUQAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:28.682772 2026] [security2:error] [pid 148765:tid 148932] [client 77.110.127.138:49850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ifDv8fXmqCm8fNeqFUQAAASs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:28.879448 2026] [security2:error] [pid 148765:tid 149002] [client 154.192.123.127:18388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDv8fXmqCm8fNeqFXwAAAXE"]
[Mon Jul 20 07:28:28.879559 2026] [security2:error] [pid 148765:tid 149002] [client 154.192.123.127:18388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDv8fXmqCm8fNeqFXwAAAXE"]
[Mon Jul 20 07:28:28.892383 2026] [security2:error] [pid 148765:tid 148938] [client 57.141.18.42:56564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iezv8fXmqCm8fNeqFBAABMS4"]
[Mon Jul 20 07:28:28.916634 2026] [security2:error] [pid 148765:tid 148980] [client 49.37.242.14:58207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDv8fXmqCm8fNeqFYQAAAVs"]
[Mon Jul 20 07:28:28.916740 2026] [security2:error] [pid 148765:tid 148980] [client 49.37.242.14:58207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ifDv8fXmqCm8fNeqFYQAAAVs"]
[Mon Jul 20 07:28:29.367665 2026] [ssl:error] [pid 148765:tid 148996] [client 104.48.69.105:48016] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:28:29.876266 2026] [security2:error] [pid 145170:tid 145397] [client 36.93.152.155:58733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ifTjs5KUa9I09SwTtRQAAAOM"]
[Mon Jul 20 07:28:29.876386 2026] [security2:error] [pid 145170:tid 145397] [client 36.93.152.155:58733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ifTjs5KUa9I09SwTtRQAAAOM"]
[Mon Jul 20 07:28:29.993043 2026] [security2:error] [pid 148765:tid 148987] [client 57.141.18.94:31784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ifDv8fXmqCm8fNeqFMwABYkE"]
[Mon Jul 20 07:28:30.752467 2026] [security2:error] [pid 145170:tid 145421] [client 103.176.215.66:51701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ifjjs5KUa9I09SwTtZwAAAPs"]
[Mon Jul 20 07:28:30.752845 2026] [security2:error] [pid 145170:tid 145421] [client 103.176.215.66:51701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ifjjs5KUa9I09SwTtZwAAAPs"]
[Mon Jul 20 07:28:30.977006 2026] [security2:error] [pid 148765:tid 148921] [client 201.27.111.74:53059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ifjv8fXmqCm8fNeqFyQAAASA"]
[Mon Jul 20 07:28:30.977130 2026] [security2:error] [pid 148765:tid 148921] [client 201.27.111.74:53059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ifjv8fXmqCm8fNeqFyQAAASA"]
[Mon Jul 20 07:28:31.081770 2026] [security2:error] [pid 148765:tid 148998] [client 14.225.17.146:50888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4ifjv8fXmqCm8fNeqFwwAAAW0"], referer: http://longevityperformanceclinic.com/test
[Mon Jul 20 07:28:31.136942 2026] [security2:error] [pid 148765:tid 148985] [client 57.141.18.125:32856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ifTv8fXmqCm8fNeqFbwABYFg"]
[Mon Jul 20 07:28:31.282043 2026] [security2:error] [pid 145170:tid 145323] [client 103.106.165.44:65274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ifzjs5KUa9I09SwTtdQAAAJk"]
[Mon Jul 20 07:28:31.282144 2026] [security2:error] [pid 145170:tid 145323] [client 103.106.165.44:65274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ifzjs5KUa9I09SwTtdQAAAJk"]
[Mon Jul 20 07:28:31.485522 2026] [security2:error] [pid 148765:tid 148950] [client 57.141.18.89:33544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ifTv8fXmqCm8fNeqFfwABPV8"]
[Mon Jul 20 07:28:31.802312 2026] [security2:error] [pid 148765:tid 148899] [client 34.221.76.50:60424] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4ifzv8fXmqCm8fNeqF7wAAAQo"]
[Mon Jul 20 07:28:31.884371 2026] [security2:error] [pid 148765:tid 148905] [client 57.141.18.38:22234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ifTv8fXmqCm8fNeqFjwABEGY"]
[Mon Jul 20 07:28:32.042909 2026] [security2:error] [pid 145170:tid 145376] [client 74.208.214.194:38082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4igDjs5KUa9I09SwTtkQAAAM4"]
[Mon Jul 20 07:28:32.115043 2026] [security2:error] [pid 148765:tid 148785] [remote 5.252.52.249:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4igDv8fXmqCm8fNeqGAgABLw8"]
[Mon Jul 20 07:28:32.312314 2026] [security2:error] [pid 148765:tid 148805] [remote 5.252.52.249:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thslogistics.net"] [uri "/wp-login.php"] [unique_id "al4igDv8fXmqCm8fNeqGEQABcCM"], referer: https://thslogistics.net/wp-login.php
[Mon Jul 20 07:28:32.523946 2026] [security2:error] [pid 148765:tid 148970] [client 50.116.65.227:59934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4igDv8fXmqCm8fNeqGEwAAAVE"]
[Mon Jul 20 07:28:32.701052 2026] [security2:error] [pid 148765:tid 149011] [client 50.116.65.227:59936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4igDv8fXmqCm8fNeqGIgAAAXo"]
[Mon Jul 20 07:28:32.945786 2026] [security2:error] [pid 148765:tid 148804] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4igDv8fXmqCm8fNeqGOQABdiI"]
[Mon Jul 20 07:28:32.945990 2026] [security2:error] [pid 148765:tid 149007] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4igDv8fXmqCm8fNeqGOQABdiI"]
[Mon Jul 20 07:28:32.968529 2026] [security2:error] [pid 148765:tid 149012] [client 63.176.132.15:19914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4igDv8fXmqCm8fNeqGOgAAAXs"]
[Mon Jul 20 07:28:32.986322 2026] [security2:error] [pid 148765:tid 148927] [client 136.158.60.21:53662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4igDv8fXmqCm8fNeqGPAAAASY"]
[Mon Jul 20 07:28:32.986461 2026] [security2:error] [pid 148765:tid 148927] [client 136.158.60.21:53662] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4igDv8fXmqCm8fNeqGPAAAASY"]
[Mon Jul 20 07:28:33.106077 2026] [security2:error] [pid 148765:tid 148978] [client 143.44.185.218:2236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4igTv8fXmqCm8fNeqGRwAAAVk"]
[Mon Jul 20 07:28:33.106212 2026] [security2:error] [pid 148765:tid 148978] [client 143.44.185.218:2236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4igTv8fXmqCm8fNeqGRwAAAVk"]
[Mon Jul 20 07:28:33.306948 2026] [security2:error] [pid 148765:tid 149016] [client 14.225.17.146:51048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4ifzv8fXmqCm8fNeqF6wAAAX8"], referer: http://amalia-capital.com/test
[Mon Jul 20 07:28:33.488792 2026] [security2:error] [pid 148765:tid 148937] [client 3.75.183.99:17916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4igTv8fXmqCm8fNeqGYQAAATA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:28:33.694375 2026] [security2:error] [pid 145170:tid 145406] [client 57.141.18.28:42888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ifzjs5KUa9I09SwTthgAA7HI"]
[Mon Jul 20 07:28:33.893258 2026] [security2:error] [pid 148765:tid 148968] [client 14.225.17.146:64479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4igDv8fXmqCm8fNeqGPQAAAU8"], referer: http://partnerselectricalllc.com/test
[Mon Jul 20 07:28:34.027116 2026] [security2:error] [pid 148765:tid 148907] [client 77.110.127.138:49886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4igjv8fXmqCm8fNeqGhQAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:34.027197 2026] [security2:error] [pid 148765:tid 148907] [client 77.110.127.138:49886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4igjv8fXmqCm8fNeqGhQAAARI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:34.115488 2026] [security2:error] [pid 148765:tid 149018] [client 144.16.21.149:36152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4igjv8fXmqCm8fNeqGhwAAAYE"]
[Mon Jul 20 07:28:34.117472 2026] [security2:error] [pid 148765:tid 148934] [client 104.234.53.90:48493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4igjv8fXmqCm8fNeqGjAAAAS0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:34.252172 2026] [security2:error] [pid 148765:tid 148992] [client 14.225.17.146:54831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4igDv8fXmqCm8fNeqGLQAAAWc"], referer: http://inspirespublishing.com/test
[Mon Jul 20 07:28:34.527584 2026] [security2:error] [pid 148765:tid 148940] [client 57.141.18.40:60066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igDv8fXmqCm8fNeqGJQABMyY"]
[Mon Jul 20 07:28:34.552612 2026] [security2:error] [pid 148765:tid 148988] [client 5.161.233.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4igjv8fXmqCm8fNeqGmwAAAWM"]
[Mon Jul 20 07:28:34.701089 2026] [security2:error] [pid 145170:tid 145201] [remote 188.40.28.4:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4igjjs5KUa9I09SwTt1gABAhs"]
[Mon Jul 20 07:28:34.933651 2026] [security2:error] [pid 145170:tid 145221] [remote 188.40.28.4:43010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4igjjs5KUa9I09SwTt4QAAkS8"], referer: https://tbd.jxc.mybluehost.me/wp-login.php
[Mon Jul 20 07:28:34.940916 2026] [fcgid:warn] [pid 148765:tid 148910] (70014)End of file found: [client 66.132.195.95:17278] mod_fcgid: can't get data from http client
[Mon Jul 20 07:28:35.005557 2026] [security2:error] [pid 145170:tid 145209] [remote 195.26.244.42:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4igjjs5KUa9I09SwTt5wAAiyM"]
[Mon Jul 20 07:28:35.142647 2026] [security2:error] [pid 148765:tid 149013] [client 191.202.66.27:62249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4igzv8fXmqCm8fNeqGxwAAAXw"]
[Mon Jul 20 07:28:35.142789 2026] [security2:error] [pid 148765:tid 149013] [client 191.202.66.27:62249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4igzv8fXmqCm8fNeqGxwAAAXw"]
[Mon Jul 20 07:28:35.392312 2026] [security2:error] [pid 145170:tid 145245] [remote 195.26.244.42:43380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4igzjs5KUa9I09SwTt-AAAm0c"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:28:35.574882 2026] [security2:error] [pid 145170:tid 145346] [client 88.241.67.160:54416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4igzjs5KUa9I09SwTuAgAAALA"]
[Mon Jul 20 07:28:35.575029 2026] [security2:error] [pid 145170:tid 145346] [client 88.241.67.160:54416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4igzjs5KUa9I09SwTuAgAAALA"]
[Mon Jul 20 07:28:35.762727 2026] [security2:error] [pid 148765:tid 148947] [client 57.141.18.20:48996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igTv8fXmqCm8fNeqGdwABOkk"]
[Mon Jul 20 07:28:35.779978 2026] [security2:error] [pid 145170:tid 145410] [client 179.127.84.238:63758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4igzjs5KUa9I09SwTuBgAAAPA"]
[Mon Jul 20 07:28:35.780168 2026] [security2:error] [pid 145170:tid 145410] [client 179.127.84.238:63758] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4igzjs5KUa9I09SwTuBgAAAPA"]
[Mon Jul 20 07:28:35.926866 2026] [security2:error] [pid 148765:tid 148945] [client 57.141.18.12:25370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igjv8fXmqCm8fNeqGiAABOEs"]
[Mon Jul 20 07:28:35.940467 2026] [security2:error] [pid 145170:tid 145369] [client 14.225.17.146:56724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4igjjs5KUa9I09SwTtzQAAAMc"], referer: http://dnsplumbing.com/test
[Mon Jul 20 07:28:36.085283 2026] [security2:error] [pid 145170:tid 145348] [client 3.67.192.83:54190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuEgAAALI"]
[Mon Jul 20 07:28:36.085372 2026] [security2:error] [pid 145170:tid 145348] [client 3.67.192.83:54190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuEgAAALI"]
[Mon Jul 20 07:28:36.160039 2026] [security2:error] [pid 145170:tid 145374] [client 154.208.48.130:49251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuFgAAAMw"]
[Mon Jul 20 07:28:36.160153 2026] [security2:error] [pid 145170:tid 145374] [client 154.208.48.130:49251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuFgAAAMw"]
[Mon Jul 20 07:28:36.240654 2026] [security2:error] [pid 148765:tid 148883] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDv8fXmqCm8fNeqG8gABe3E"]
[Mon Jul 20 07:28:36.240857 2026] [security2:error] [pid 148765:tid 149012] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDv8fXmqCm8fNeqG8gABe3E"]
[Mon Jul 20 07:28:36.269076 2026] [security2:error] [pid 145170:tid 145400] [client 157.20.138.62:64949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuGAAAAOY"]
[Mon Jul 20 07:28:36.269219 2026] [security2:error] [pid 145170:tid 145400] [client 157.20.138.62:64949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuGAAAAOY"]
[Mon Jul 20 07:28:36.616610 2026] [security2:error] [pid 145170:tid 145394] [client 57.141.18.118:61610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igjjs5KUa9I09SwTt0wAA4E8"]
[Mon Jul 20 07:28:36.740915 2026] [security2:error] [pid 145170:tid 145386] [client 125.209.97.230:57346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuJQAAANg"]
[Mon Jul 20 07:28:36.741348 2026] [security2:error] [pid 145170:tid 145386] [client 125.209.97.230:57346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ihDjs5KUa9I09SwTuJQAAANg"]
[Mon Jul 20 07:28:36.943525 2026] [ssl:error] [pid 148765:tid 148953] [client 104.48.69.105:48018] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:28:37.030807 2026] [security2:error] [pid 148765:tid 148982] [client 57.141.18.114:48512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igzv8fXmqCm8fNeqGyQABXWE"]
[Mon Jul 20 07:28:37.103692 2026] [security2:error] [pid 145170:tid 145190] [remote 45.90.123.233:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4ihTjs5KUa9I09SwTuMAAA_xA"]
[Mon Jul 20 07:28:37.158294 2026] [security2:error] [pid 145170:tid 145393] [client 57.141.18.86:41672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igzjs5KUa9I09SwTt8AAA3z4"]
[Mon Jul 20 07:28:37.165688 2026] [security2:error] [pid 148765:tid 148904] [client 104.234.53.76:22431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ihTv8fXmqCm8fNeqHKwAAAQ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:37.299514 2026] [security2:error] [pid 145170:tid 145248] [remote 45.90.123.233:35584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4ihTjs5KUa9I09SwTuNAAAoEo"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 07:28:37.374833 2026] [security2:error] [pid 148765:tid 148992] [client 57.141.18.41:39274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4igzv8fXmqCm8fNeqG1AABZ2k"]
[Mon Jul 20 07:28:37.507136 2026] [security2:error] [pid 148765:tid 148912] [client 116.74.65.235:58236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ihTv8fXmqCm8fNeqHJwAAARc"]
[Mon Jul 20 07:28:37.512464 2026] [security2:error] [pid 148765:tid 148788] [remote 100.42.189.89:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ihTv8fXmqCm8fNeqHPQABTxI"]
[Mon Jul 20 07:28:37.519310 2026] [ssl:error] [pid 145170:tid 145410] [client 104.48.69.105:48022] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:28:37.745654 2026] [security2:error] [pid 148765:tid 148775] [remote 100.42.189.89:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ihTv8fXmqCm8fNeqHSAABWwU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:28:37.764849 2026] [security2:error] [pid 145170:tid 145395] [client 82.102.27.163:51966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.27.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ihTjs5KUa9I09SwTuQgAAAOE"]
[Mon Jul 20 07:28:37.764948 2026] [security2:error] [pid 145170:tid 145395] [client 82.102.27.163:51966] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4ihTjs5KUa9I09SwTuQgAAAOE"]
[Mon Jul 20 07:28:37.767472 2026] [security2:error] [pid 145170:tid 145311] [client 77.110.127.138:49949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ihTjs5KUa9I09SwTuQwAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:37.767545 2026] [security2:error] [pid 145170:tid 145311] [client 77.110.127.138:49949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4ihTjs5KUa9I09SwTuQwAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:38.327010 2026] [security2:error] [pid 148765:tid 148970] [client 57.141.18.101:41036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ihDv8fXmqCm8fNeqHDgABUQE"]
[Mon Jul 20 07:28:38.486147 2026] [security2:error] [pid 148765:tid 148992] [client 57.141.18.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ihjv8fXmqCm8fNeqHbwAAAWc"]
[Mon Jul 20 07:28:38.761224 2026] [security2:error] [pid 148765:tid 148988] [client 57.141.18.0:59238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ihTv8fXmqCm8fNeqHHwABYwk"]
[Mon Jul 20 07:28:38.771497 2026] [security2:error] [pid 145170:tid 145331] [client 49.47.218.174:63559] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ihjjs5KUa9I09SwTuYgAAAKE"]
[Mon Jul 20 07:28:38.771615 2026] [security2:error] [pid 145170:tid 145331] [client 49.47.218.174:63559] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ihjjs5KUa9I09SwTuYgAAAKE"]
[Mon Jul 20 07:28:38.937212 2026] [security2:error] [pid 148765:tid 149005] [client 57.141.18.71:37622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ihTv8fXmqCm8fNeqHMQABdFg"]
[Mon Jul 20 07:28:39.001521 2026] [security2:error] [pid 148765:tid 149026] [client 117.211.236.168:59116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ihjv8fXmqCm8fNeqHpQAAAYk"]
[Mon Jul 20 07:28:39.001638 2026] [security2:error] [pid 148765:tid 149026] [client 117.211.236.168:59116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ihjv8fXmqCm8fNeqHpQAAAYk"]
[Mon Jul 20 07:28:39.043760 2026] [security2:error] [pid 145170:tid 145406] [client 216.73.216.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thebestreps.net"] [uri "/index.php"] [unique_id "al4ihjjs5KUa9I09SwTuTwAA7Ag"]
[Mon Jul 20 07:28:39.430347 2026] [security2:error] [pid 145170:tid 145420] [client 154.192.123.127:16909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ihzjs5KUa9I09SwTuhQAAAPo"]
[Mon Jul 20 07:28:39.430458 2026] [security2:error] [pid 145170:tid 145420] [client 154.192.123.127:16909] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ihzjs5KUa9I09SwTuhQAAAPo"]
[Mon Jul 20 07:28:39.548247 2026] [security2:error] [pid 145170:tid 145332] [client 216.73.216.116:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thebestreps.net"] [uri "/index.php"] [unique_id "al4ihzjs5KUa9I09SwTuhgAAoiI"]
[Mon Jul 20 07:28:39.638742 2026] [autoindex:error] [pid 148765:tid 148933] [client 8.229.41.77:0] AH01276: Cannot serve directory /home2/bluestm2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.suq.iks.mybluehost.me
[Mon Jul 20 07:28:39.733515 2026] [security2:error] [pid 148765:tid 149003] [client 121.229.156.11:45438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/"] [unique_id "al4ihzv8fXmqCm8fNeqHzQAAAXI"]
[Mon Jul 20 07:28:39.733587 2026] [security2:error] [pid 148765:tid 149003] [client 121.229.156.11:45438] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.savilerowtravel.com"] [uri "/"] [unique_id "al4ihzv8fXmqCm8fNeqHzQAAAXI"]
[Mon Jul 20 07:28:39.790097 2026] [security2:error] [pid 145170:tid 145384] [client 57.141.18.106:31740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ihjjs5KUa9I09SwTuVAAA1mo"]
[Mon Jul 20 07:28:40.175603 2026] [security2:error] [pid 148765:tid 149014] [client 57.141.18.19:47788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ihjv8fXmqCm8fNeqHjgABfQg"]
[Mon Jul 20 07:28:40.216250 2026] [security2:error] [pid 145170:tid 145386] [client 104.234.53.50:40021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iiDjs5KUa9I09SwTuoAAAANg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:40.443153 2026] [security2:error] [pid 148765:tid 148944] [client 74.208.214.194:53864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4iiDv8fXmqCm8fNeqH6gAAATc"]
[Mon Jul 20 07:28:40.487652 2026] [security2:error] [pid 148765:tid 148942] [client 36.93.152.155:59242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iiDv8fXmqCm8fNeqH7wAAATU"]
[Mon Jul 20 07:28:40.487826 2026] [security2:error] [pid 148765:tid 148942] [client 36.93.152.155:59242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iiDv8fXmqCm8fNeqH7wAAATU"]
[Mon Jul 20 07:28:40.584403 2026] [security2:error] [pid 145170:tid 145415] [client 77.110.127.138:49958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDjs5KUa9I09SwTutQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.584537 2026] [security2:error] [pid 145170:tid 145415] [client 77.110.127.138:49958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDjs5KUa9I09SwTutQAAAPU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.709337 2026] [security2:error] [pid 148765:tid 148903] [client 144.16.21.149:24846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4iiDv8fXmqCm8fNeqH-AAAAQ4"]
[Mon Jul 20 07:28:40.756637 2026] [security2:error] [pid 145170:tid 145408] [client 77.110.127.138:49858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDjs5KUa9I09SwTuuQAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.756765 2026] [security2:error] [pid 145170:tid 145408] [client 77.110.127.138:49858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDjs5KUa9I09SwTuuQAAAO4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.832226 2026] [security2:error] [pid 145170:tid 145407] [client 77.110.127.138:49952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDjs5KUa9I09SwTuvQAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.832323 2026] [security2:error] [pid 145170:tid 145407] [client 77.110.127.138:49952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDjs5KUa9I09SwTuvQAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.896622 2026] [security2:error] [pid 148765:tid 148991] [client 213.111.158.220:10560] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "onewingpictures.com"] [uri "/"] [unique_id "al4iiDv8fXmqCm8fNeqIDQAAAWY"]
[Mon Jul 20 07:28:40.960882 2026] [security2:error] [pid 148765:tid 148928] [client 77.110.127.138:49939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDv8fXmqCm8fNeqIDwAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:40.960998 2026] [security2:error] [pid 148765:tid 148928] [client 77.110.127.138:49939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiDv8fXmqCm8fNeqIDwAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:41.011245 2026] [security2:error] [pid 148765:tid 148984] [client 77.110.127.138:49954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiTv8fXmqCm8fNeqIEQAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:41.011360 2026] [security2:error] [pid 148765:tid 148984] [client 77.110.127.138:49954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiTv8fXmqCm8fNeqIEQAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:28:41.086573 2026] [security2:error] [pid 148765:tid 149026] [client 77.110.127.138:49943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiTv8fXmqCm8fNeqIFwAAAYk"]
[Mon Jul 20 07:28:41.086676 2026] [security2:error] [pid 148765:tid 149026] [client 77.110.127.138:49943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiTv8fXmqCm8fNeqIFwAAAYk"]
[Mon Jul 20 07:28:41.149895 2026] [security2:error] [pid 145170:tid 145430] [client 77.110.127.138:49955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiTjs5KUa9I09SwTuxwAAAQQ"]
[Mon Jul 20 07:28:41.150011 2026] [security2:error] [pid 145170:tid 145430] [client 77.110.127.138:49955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4iiTjs5KUa9I09SwTuxwAAAQQ"]
[Mon Jul 20 07:28:41.311220 2026] [security2:error] [pid 148765:tid 148994] [client 144.24.58.222:13097] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "thierry-henry.fr"] [uri "/episode169"] [unique_id "al4iiTv8fXmqCm8fNeqIIgAAAWk"]
[Mon Jul 20 07:28:41.311316 2026] [security2:error] [pid 148765:tid 148994] [client 144.24.58.222:13097] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "thierry-henry.fr"] [uri "/episode169"] [unique_id "al4iiTv8fXmqCm8fNeqIIgAAAWk"]
[Mon Jul 20 07:28:41.317854 2026] [security2:error] [pid 148765:tid 148934] [client 103.176.215.66:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iiTv8fXmqCm8fNeqIIwAAAS0"]
[Mon Jul 20 07:28:41.318580 2026] [security2:error] [pid 148765:tid 148934] [client 103.176.215.66:52247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iiTv8fXmqCm8fNeqIIwAAAS0"]
[Mon Jul 20 07:28:41.440303 2026] [security2:error] [pid 148765:tid 148786] [remote 124.55.178.99:55846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iiTv8fXmqCm8fNeqILAABRxA"]
[Mon Jul 20 07:28:41.444358 2026] [security2:error] [pid 148765:tid 148959] [client 201.27.111.74:53561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iiTv8fXmqCm8fNeqILQAAAUY"]
[Mon Jul 20 07:28:41.444449 2026] [security2:error] [pid 148765:tid 148959] [client 201.27.111.74:53561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iiTv8fXmqCm8fNeqILQAAAUY"]
[Mon Jul 20 07:28:41.475840 2026] [security2:error] [pid 148765:tid 148915] [client 57.141.18.18:57666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iiDv8fXmqCm8fNeqH3gABGko"]
[Mon Jul 20 07:28:41.762433 2026] [security2:error] [pid 148765:tid 148912] [client 57.141.18.35:58066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iiDv8fXmqCm8fNeqH5wABFz8"]
[Mon Jul 20 07:28:41.853253 2026] [security2:error] [pid 148765:tid 148878] [remote 124.55.178.99:55846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iiTv8fXmqCm8fNeqIRQABV2w"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:28:41.870072 2026] [security2:error] [pid 148765:tid 149004] [client 103.106.165.44:49386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iiTv8fXmqCm8fNeqIRwAAAXM"]
[Mon Jul 20 07:28:41.870175 2026] [security2:error] [pid 148765:tid 149004] [client 103.106.165.44:49386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iiTv8fXmqCm8fNeqIRwAAAXM"]
[Mon Jul 20 07:28:42.083096 2026] [security2:error] [pid 148765:tid 148980] [client 216.24.212.35:42459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4iijv8fXmqCm8fNeqIVwAAAVs"]
[Mon Jul 20 07:28:42.093094 2026] [security2:error] [pid 148765:tid 148984] [client 216.24.212.45:55125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4iijv8fXmqCm8fNeqIWAAAAV8"]
[Mon Jul 20 07:28:42.274613 2026] [security2:error] [pid 145170:tid 145174] [remote 97.74.87.194:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iijjs5KUa9I09SwTu6gAA6QA"]
[Mon Jul 20 07:28:42.290852 2026] [security2:error] [pid 145170:tid 145312] [client 104.234.53.75:44095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4iijjs5KUa9I09SwTu7AAAAI4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:42.602244 2026] [security2:error] [pid 145170:tid 145396] [client 57.141.18.94:28374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iiTjs5KUa9I09SwTuzwAA4lQ"]
[Mon Jul 20 07:28:42.675316 2026] [security2:error] [pid 145170:tid 145210] [remote 97.74.87.194:57552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iijjs5KUa9I09SwTu_gAApiQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:28:43.431355 2026] [security2:error] [pid 148765:tid 148852] [remote 209.42.18.223:49176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iizv8fXmqCm8fNeqImAABcVI"]
[Mon Jul 20 07:28:43.467998 2026] [security2:error] [pid 148765:tid 149025] [client 57.141.18.0:56670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iijv8fXmqCm8fNeqIXAABiHQ"]
[Mon Jul 20 07:28:43.595164 2026] [security2:error] [pid 148765:tid 148868] [remote 162.19.86.63:56366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4iizv8fXmqCm8fNeqIogABeGI"]
[Mon Jul 20 07:28:43.595306 2026] [security2:error] [pid 148765:tid 149009] [client 162.19.86.63:56366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4iizv8fXmqCm8fNeqIogABeGI"]
[Mon Jul 20 07:28:43.602997 2026] [security2:error] [pid 148765:tid 148781] [remote 209.42.18.223:49176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iizv8fXmqCm8fNeqIoQABSgs"], referer: https://mail.yok.mqz.mybluehost.me/wp-login.php
[Mon Jul 20 07:28:43.610125 2026] [security2:error] [pid 145170:tid 145398] [client 49.37.242.14:58858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iizjs5KUa9I09SwTvLQAAAOQ"]
[Mon Jul 20 07:28:43.610222 2026] [security2:error] [pid 145170:tid 145398] [client 49.37.242.14:58858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iizjs5KUa9I09SwTvLQAAAOQ"]
[Mon Jul 20 07:28:43.707884 2026] [security2:error] [pid 145170:tid 145412] [client 136.158.60.21:55260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iizjs5KUa9I09SwTvMwAAAPI"]
[Mon Jul 20 07:28:43.708026 2026] [security2:error] [pid 145170:tid 145412] [client 136.158.60.21:55260] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iizjs5KUa9I09SwTvMwAAAPI"]
[Mon Jul 20 07:28:43.756906 2026] [fcgid:warn] [pid 148765:tid 148967] (70014)End of file found: [client 66.132.186.160:48808] mod_fcgid: can't get data from http client
[Mon Jul 20 07:28:44.021055 2026] [security2:error] [pid 148765:tid 148775] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ijDv8fXmqCm8fNeqIvwABJwU"]
[Mon Jul 20 07:28:44.021236 2026] [security2:error] [pid 148765:tid 148928] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ijDv8fXmqCm8fNeqIvwABJwU"]
[Mon Jul 20 07:28:44.056893 2026] [security2:error] [pid 148765:tid 148792] [remote 72.167.132.114:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4ijDv8fXmqCm8fNeqIwQABDhY"]
[Mon Jul 20 07:28:44.136679 2026] [security2:error] [pid 148765:tid 148923] [client 50.116.65.227:44148] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ijDv8fXmqCm8fNeqIyAAAASI"]
[Mon Jul 20 07:28:44.145509 2026] [security2:error] [pid 148765:tid 148953] [client 50.116.65.227:44158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ijDv8fXmqCm8fNeqIyQAAAUA"]
[Mon Jul 20 07:28:44.202361 2026] [security2:error] [pid 148765:tid 148927] [client 57.141.18.107:43538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iijv8fXmqCm8fNeqIegABJnk"]
[Mon Jul 20 07:28:44.453392 2026] [security2:error] [pid 148765:tid 148796] [remote 72.167.132.114:40430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4ijDv8fXmqCm8fNeqI2wABXBo"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:28:44.525922 2026] [security2:error] [pid 145170:tid 145420] [client 57.141.18.31:34180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iizjs5KUa9I09SwTvJAAA-gU"]
[Mon Jul 20 07:28:44.538537 2026] [security2:error] [pid 145170:tid 145371] [client 57.141.18.34:60166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iizjs5KUa9I09SwTvIwAAyQo"]
[Mon Jul 20 07:28:44.551912 2026] [security2:error] [pid 148765:tid 148999] [client 14.225.17.146:55468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4ijDv8fXmqCm8fNeqI2gAAAW4"], referer: http://koaconsultants.com/Test
[Mon Jul 20 07:28:44.574525 2026] [security2:error] [pid 145170:tid 145385] [client 178.156.228.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4ijDjs5KUa9I09SwTvTAAAANc"]
[Mon Jul 20 07:28:44.608143 2026] [security2:error] [pid 148765:tid 148922] [client 14.225.17.146:55496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4ijDv8fXmqCm8fNeqI3AAAASE"], referer: http://elitetax-mi.com/Test
[Mon Jul 20 07:28:44.999053 2026] [security2:error] [pid 148765:tid 149012] [client 189.157.195.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4ijDv8fXmqCm8fNeqI7wAAAXs"]
[Mon Jul 20 07:28:45.183460 2026] [security2:error] [pid 148765:tid 148951] [client 14.225.17.146:59067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4ijTv8fXmqCm8fNeqI9gAAAT4"], referer: http://eframiproperties.com/Test
[Mon Jul 20 07:28:45.186013 2026] [proxy:error] [pid 145170:tid 145341] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:28:45.186048 2026] [proxy_http:error] [pid 145170:tid 145341] [client 107.172.180.205:35566] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:28:45.186844 2026] [proxy:error] [pid 145170:tid 145341] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:28:45.186876 2026] [proxy_http:error] [pid 145170:tid 145341] [client 107.172.180.205:35566] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:28:45.370684 2026] [security2:error] [pid 148765:tid 148956] [client 57.141.18.76:35894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ijDv8fXmqCm8fNeqIywABQw8"]
[Mon Jul 20 07:28:45.376351 2026] [security2:error] [pid 145170:tid 145358] [client 125.209.97.230:57875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ijTjs5KUa9I09SwTvdAAAALw"]
[Mon Jul 20 07:28:45.376465 2026] [security2:error] [pid 145170:tid 145358] [client 125.209.97.230:57875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ijTjs5KUa9I09SwTvdAAAALw"]
[Mon Jul 20 07:28:45.404120 2026] [security2:error] [pid 148765:tid 148820] [remote 100.42.189.89:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ijTv8fXmqCm8fNeqJDgABUjI"]
[Mon Jul 20 07:28:45.680319 2026] [security2:error] [pid 148765:tid 148830] [remote 100.42.189.89:59320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ijTv8fXmqCm8fNeqJJQABRjw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:28:45.705167 2026] [security2:error] [pid 145170:tid 145320] [client 167.172.47.186:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4ijTjs5KUa9I09SwTveQAAAJY"], referer: https://mcg.homes/
[Mon Jul 20 07:28:45.782640 2026] [security2:error] [pid 148765:tid 148908] [client 191.202.66.27:62735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ijTv8fXmqCm8fNeqJKgAAARM"]
[Mon Jul 20 07:28:45.784855 2026] [security2:error] [pid 148765:tid 148908] [client 191.202.66.27:62735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ijTv8fXmqCm8fNeqJKgAAARM"]
[Mon Jul 20 07:28:45.970319 2026] [security2:error] [pid 145170:tid 145380] [client 143.44.185.218:3870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ijTjs5KUa9I09SwTvhQAAANI"]
[Mon Jul 20 07:28:45.970453 2026] [security2:error] [pid 145170:tid 145380] [client 143.44.185.218:3870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ijTjs5KUa9I09SwTvhQAAANI"]
[Mon Jul 20 07:28:46.247304 2026] [security2:error] [pid 148765:tid 148984] [client 104.234.53.53:24319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4ijjv8fXmqCm8fNeqJQgAAAV8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:46.484117 2026] [security2:error] [pid 148765:tid 148968] [client 179.127.84.238:64496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJVQAAAU8"]
[Mon Jul 20 07:28:46.484273 2026] [security2:error] [pid 148765:tid 148968] [client 179.127.84.238:64496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJVQAAAU8"]
[Mon Jul 20 07:28:46.660926 2026] [security2:error] [pid 148765:tid 148977] [client 52.59.238.198:37868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJYAAAAVg"]
[Mon Jul 20 07:28:46.661023 2026] [security2:error] [pid 148765:tid 148977] [client 52.59.238.198:37868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJYAAAAVg"]
[Mon Jul 20 07:28:46.731694 2026] [security2:error] [pid 145170:tid 145407] [client 216.73.216.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.emmalab-niger.net"] [uri "/index.php"] [unique_id "al4iizjs5KUa9I09SwTvIQAA7QE"]
[Mon Jul 20 07:28:46.760907 2026] [security2:error] [pid 148765:tid 148953] [client 88.241.67.160:54231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJZQAAAUA"]
[Mon Jul 20 07:28:46.761358 2026] [security2:error] [pid 148765:tid 148953] [client 88.241.67.160:54231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJZQAAAUA"]
[Mon Jul 20 07:28:46.853050 2026] [security2:error] [pid 148765:tid 148988] [client 157.20.138.62:65522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJagAAAWM"]
[Mon Jul 20 07:28:46.853205 2026] [security2:error] [pid 148765:tid 148988] [client 157.20.138.62:65522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJagAAAWM"]
[Mon Jul 20 07:28:46.897462 2026] [security2:error] [pid 148765:tid 148856] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJbgABE1Y"]
[Mon Jul 20 07:28:46.897624 2026] [security2:error] [pid 148765:tid 148908] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ijjv8fXmqCm8fNeqJbgABE1Y"]
[Mon Jul 20 07:28:47.019501 2026] [security2:error] [pid 148765:tid 148823] [remote 20.75.217.73:1604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4ijjv8fXmqCm8fNeqJdgABhjU"]
[Mon Jul 20 07:28:47.223686 2026] [security2:error] [pid 148765:tid 148819] [remote 20.75.217.73:1604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.217.75.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4ijzv8fXmqCm8fNeqJhgABXDE"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:28:47.250290 2026] [security2:error] [pid 148765:tid 148983] [client 154.208.48.130:49659] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.48.208.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ijzv8fXmqCm8fNeqJhwAAAV4"]
[Mon Jul 20 07:28:47.250916 2026] [security2:error] [pid 148765:tid 148983] [client 154.208.48.130:49659] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4ijzv8fXmqCm8fNeqJhwAAAV4"]
[Mon Jul 20 07:28:47.406118 2026] [security2:error] [pid 145170:tid 145353] [client 216.73.216.219:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.emmalab-niger.net"] [uri "/index.php"] [unique_id "al4ijzjs5KUa9I09SwTvsgAAtzQ"]
[Mon Jul 20 07:28:47.486287 2026] [security2:error] [pid 148765:tid 149005] [client 57.141.0.22:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4ijzv8fXmqCm8fNeqJfgAAAXQ"]
[Mon Jul 20 07:28:47.486940 2026] [security2:error] [pid 145170:tid 145320] [client 45.157.112.60:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ijzjs5KUa9I09SwTvwQAAAJY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:47.631087 2026] [security2:error] [pid 145170:tid 145256] [remote 51.158.61.221:35450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ijzjs5KUa9I09SwTvxAAAolI"]
[Mon Jul 20 07:28:47.800021 2026] [security2:error] [pid 148765:tid 148916] [client 14.225.17.146:55714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4ijzv8fXmqCm8fNeqJmQAAARs"], referer: http://cloudspacesgroup.com/Test
[Mon Jul 20 07:28:47.812006 2026] [security2:error] [pid 145170:tid 145377] [client 57.141.18.50:44408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ijjjs5KUa9I09SwTvpAAAzzI"]
[Mon Jul 20 07:28:47.897562 2026] [security2:error] [pid 145170:tid 145204] [remote 51.158.61.221:35450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4ijzjs5KUa9I09SwTv0gAAzB4"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:28:48.058083 2026] [proxy:error] [pid 145170:tid 145361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:28:48.058166 2026] [proxy_http:error] [pid 145170:tid 145361] [client 107.172.180.205:35574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:28:48.058776 2026] [proxy:error] [pid 145170:tid 145361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:28:48.058821 2026] [proxy_http:error] [pid 145170:tid 145361] [client 107.172.180.205:35574] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:28:48.089559 2026] [security2:error] [pid 145170:tid 145406] [client 181.191.148.221:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4ijjjs5KUa9I09SwTvngAAAOw"]
[Mon Jul 20 07:28:48.226134 2026] [security2:error] [pid 145170:tid 145317] [client 57.141.18.73:56616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ijzjs5KUa9I09SwTvtAAAk2E"]
[Mon Jul 20 07:28:48.524310 2026] [security2:error] [pid 145170:tid 145330] [client 104.234.53.88:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4ikDjs5KUa9I09SwTv6gAAAKA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:48.569811 2026] [security2:error] [pid 148765:tid 149014] [client 57.141.18.34:60172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ijzv8fXmqCm8fNeqJlwABfVw"]
[Mon Jul 20 07:28:48.598166 2026] [security2:error] [pid 145170:tid 145420] [client 117.211.236.168:59650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ikDjs5KUa9I09SwTv7AAAAPo"]
[Mon Jul 20 07:28:48.598301 2026] [security2:error] [pid 145170:tid 145420] [client 117.211.236.168:59650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ikDjs5KUa9I09SwTv7AAAAPo"]
[Mon Jul 20 07:28:48.603181 2026] [security2:error] [pid 148765:tid 148903] [client 202.141.11.99:12165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ikDv8fXmqCm8fNeqJ0wAAAQ4"]
[Mon Jul 20 07:28:48.603292 2026] [security2:error] [pid 148765:tid 148903] [client 202.141.11.99:12165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ikDv8fXmqCm8fNeqJ0wAAAQ4"]
[Mon Jul 20 07:28:48.642611 2026] [security2:error] [pid 145170:tid 145305] [client 57.141.18.119:39300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ijzjs5KUa9I09SwTvygAAh1Y"]
[Mon Jul 20 07:28:48.769854 2026] [security2:error] [pid 148765:tid 148883] [remote 5.252.52.249:49110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4ikDv8fXmqCm8fNeqJ3AABI3E"]
[Mon Jul 20 07:28:48.926912 2026] [security2:error] [pid 148765:tid 148887] [remote 5.252.52.249:49110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rtkenergypartners.com"] [uri "/wp-login.php"] [unique_id "al4ikDv8fXmqCm8fNeqJ5QABXnU"], referer: https://rtkenergypartners.com/wp-login.php
[Mon Jul 20 07:28:49.098601 2026] [security2:error] [pid 148765:tid 148981] [client 143.198.151.233:51564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4ikTv8fXmqCm8fNeqJ7gAAAVw"], referer: https://adultdaycarereno.com/
[Mon Jul 20 07:28:49.318981 2026] [security2:error] [pid 148765:tid 149000] [client 49.47.218.174:64258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ikTv8fXmqCm8fNeqKAwAAAW8"]
[Mon Jul 20 07:28:49.319130 2026] [security2:error] [pid 148765:tid 149000] [client 49.47.218.174:64258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ikTv8fXmqCm8fNeqKAwAAAW8"]
[Mon Jul 20 07:28:49.398464 2026] [security2:error] [pid 145170:tid 145427] [client 14.225.17.146:58997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4ijzjs5KUa9I09SwTv0QAAAQE"], referer: http://slutilities.com/Test
[Mon Jul 20 07:28:49.754631 2026] [security2:error] [pid 148765:tid 148776] [remote 188.166.241.141:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ikTv8fXmqCm8fNeqKFgABdAY"]
[Mon Jul 20 07:28:49.782693 2026] [security2:error] [pid 148765:tid 148966] [client 158.173.166.181:53397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ikTv8fXmqCm8fNeqKFwAAAU0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:49.836811 2026] [security2:error] [pid 145170:tid 145406] [client 170.64.229.59:50992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.membresiabeyou.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4ikTjs5KUa9I09SwTwDQAAAOw"]
[Mon Jul 20 07:28:49.969424 2026] [security2:error] [pid 148765:tid 148950] [client 154.192.123.127:17311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ikTv8fXmqCm8fNeqKJAAAAT0"]
[Mon Jul 20 07:28:49.969529 2026] [security2:error] [pid 148765:tid 148950] [client 154.192.123.127:17311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ikTv8fXmqCm8fNeqKJAAAAT0"]
[Mon Jul 20 07:28:50.156907 2026] [security2:error] [pid 148765:tid 148791] [remote 188.166.241.141:34888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4ikjv8fXmqCm8fNeqKNQABORU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:28:50.252598 2026] [security2:error] [pid 145170:tid 145308] [client 57.141.18.75:57316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ikTjs5KUa9I09SwTv_wAAilg"]
[Mon Jul 20 07:28:50.278912 2026] [security2:error] [pid 148765:tid 148971] [client 14.225.17.146:55307] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4ikjv8fXmqCm8fNeqKKwAAAVI"], referer: http://securingmemories.com/Test
[Mon Jul 20 07:28:50.908281 2026] [security2:error] [pid 148765:tid 148957] [client 14.225.17.146:57353] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4ikjv8fXmqCm8fNeqKUgAAAUQ"], referer: http://jvcmotorsports.com/Test
[Mon Jul 20 07:28:50.933949 2026] [security2:error] [pid 148765:tid 148981] [client 36.93.152.155:59772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ikjv8fXmqCm8fNeqKbgAAAVw"]
[Mon Jul 20 07:28:50.934062 2026] [security2:error] [pid 148765:tid 148981] [client 36.93.152.155:59772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ikjv8fXmqCm8fNeqKbgAAAVw"]
[Mon Jul 20 07:28:50.972512 2026] [security2:error] [pid 148765:tid 149016] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ikjv8fXmqCm8fNeqKVwABfwQ"], referer: http://aleishapenny.ca/Test
[Mon Jul 20 07:28:51.039093 2026] [security2:error] [pid 145170:tid 145335] [client 104.234.53.91:62965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4ikzjs5KUa9I09SwTwPwAAAKU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:51.134807 2026] [security2:error] [pid 148765:tid 149003] [client 14.225.17.146:56357] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4ikjv8fXmqCm8fNeqKXgAAAXI"], referer: http://healthylifegourmet.org/Test
[Mon Jul 20 07:28:51.276625 2026] [security2:error] [pid 148765:tid 148810] [remote 152.228.213.32:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4ikzv8fXmqCm8fNeqKfQABMCg"]
[Mon Jul 20 07:28:51.521008 2026] [security2:error] [pid 148765:tid 148938] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4ikzv8fXmqCm8fNeqKggABMRg"]
[Mon Jul 20 07:28:51.562061 2026] [security2:error] [pid 148765:tid 148905] [client 57.141.18.20:21984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ikjv8fXmqCm8fNeqKVAABECA"]
[Mon Jul 20 07:28:51.715422 2026] [security2:error] [pid 148765:tid 148821] [remote 152.228.213.32:34274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4ikzv8fXmqCm8fNeqKmAABUDM"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 07:28:51.732830 2026] [security2:error] [pid 145170:tid 145404] [client 144.16.21.149:28196] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ikzjs5KUa9I09SwTwXwAAAOo"]
[Mon Jul 20 07:28:51.756567 2026] [security2:error] [pid 145170:tid 145323] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4ikzjs5KUa9I09SwTwXQAAmSA"], referer: https://aleishapenny.ca/Test
[Mon Jul 20 07:28:51.857598 2026] [security2:error] [pid 148765:tid 148933] [client 103.176.215.66:52790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ikzv8fXmqCm8fNeqKoQAAASw"]
[Mon Jul 20 07:28:51.857739 2026] [security2:error] [pid 148765:tid 148933] [client 103.176.215.66:52790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ikzv8fXmqCm8fNeqKoQAAASw"]
[Mon Jul 20 07:28:51.934484 2026] [security2:error] [pid 148765:tid 148960] [client 57.141.18.91:26528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ikjv8fXmqCm8fNeqKcAABRx0"]
[Mon Jul 20 07:28:51.980624 2026] [security2:error] [pid 145170:tid 145399] [client 201.27.111.74:54064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ikzjs5KUa9I09SwTwagAAAOU"]
[Mon Jul 20 07:28:51.984157 2026] [security2:error] [pid 145170:tid 145399] [client 201.27.111.74:54064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ikzjs5KUa9I09SwTwagAAAOU"]
[Mon Jul 20 07:28:52.422357 2026] [security2:error] [pid 148765:tid 148948] [client 14.225.17.146:55244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4ikzv8fXmqCm8fNeqKpQAAATs"], referer: http://idigress.group/Test
[Mon Jul 20 07:28:52.433454 2026] [core:error] [pid 145170:tid 145387] [client 14.225.17.146:58397] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Test
[Mon Jul 20 07:28:52.433474 2026] [core:error] [pid 145170:tid 145387] [client 14.225.17.146:58397] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/Test
[Mon Jul 20 07:28:52.648450 2026] [security2:error] [pid 148765:tid 149010] [client 103.106.165.44:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ilDv8fXmqCm8fNeqKyAAAAXk"]
[Mon Jul 20 07:28:52.648658 2026] [security2:error] [pid 148765:tid 149010] [client 103.106.165.44:49885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ilDv8fXmqCm8fNeqKyAAAAXk"]
[Mon Jul 20 07:28:52.750316 2026] [security2:error] [pid 145170:tid 145376] [client 57.141.18.51:47108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ikzjs5KUa9I09SwTwYQAAzhk"]
[Mon Jul 20 07:28:52.843839 2026] [security2:error] [pid 145170:tid 145388] [client 158.173.89.95:21171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ilDjs5KUa9I09SwTwhwAAANo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:28:52.886094 2026] [security2:error] [pid 148765:tid 149018] [client 167.56.107.23:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4ilDv8fXmqCm8fNeqK0gAAAYE"]
[Mon Jul 20 07:28:53.236599 2026] [security2:error] [pid 148765:tid 148929] [client 14.225.17.146:63873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4ilTv8fXmqCm8fNeqK6wAAASg"], referer: http://friendlyspreadsheet.com/Test
[Mon Jul 20 07:28:53.328622 2026] [security2:error] [pid 145170:tid 145358] [client 57.141.18.14:43986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ilDjs5KUa9I09SwTwdQAAvBc"]
[Mon Jul 20 07:28:53.589580 2026] [security2:error] [pid 145170:tid 145320] [client 14.225.17.146:63533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4ilTjs5KUa9I09SwTwmQAAAJY"]
[Mon Jul 20 07:28:53.605506 2026] [security2:error] [pid 148765:tid 148977] [client 57.141.18.110:41366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ilDv8fXmqCm8fNeqKxwABWCU"]
[Mon Jul 20 07:28:54.181723 2026] [security2:error] [pid 145170:tid 145413] [client 14.225.17.146:63915] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4iljjs5KUa9I09SwTwvwAAAPM"], referer: https://friendlyspreadsheet.com/Test
[Mon Jul 20 07:28:54.438129 2026] [security2:error] [pid 148765:tid 148993] [client 57.141.18.120:50538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ilTv8fXmqCm8fNeqK9QABaDU"]
[Mon Jul 20 07:28:54.534371 2026] [security2:error] [pid 148765:tid 148937] [client 136.158.60.21:56914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iljv8fXmqCm8fNeqLIAAAATA"]
[Mon Jul 20 07:28:54.534505 2026] [security2:error] [pid 148765:tid 148937] [client 136.158.60.21:56914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iljv8fXmqCm8fNeqLIAAAATA"]
[Mon Jul 20 07:28:54.562888 2026] [security2:error] [pid 148765:tid 148901] [client 104.234.53.81:53301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4iljv8fXmqCm8fNeqLIgAAAQw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:54.732370 2026] [security2:error] [pid 145170:tid 145315] [client 57.141.18.105:64212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ilTjs5KUa9I09SwTwngAAkUc"]
[Mon Jul 20 07:28:54.831241 2026] [security2:error] [pid 145170:tid 145236] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iljjs5KUa9I09SwTw1wAAnj4"]
[Mon Jul 20 07:28:54.831383 2026] [security2:error] [pid 145170:tid 145328] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iljjs5KUa9I09SwTw1wAAnj4"]
[Mon Jul 20 07:28:55.092238 2026] [autoindex:error] [pid 145170:tid 145290] [remote 35.196.99.113:50723] AH01276: Cannot serve directory /home2/skujivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://sku.jiv.mybluehost.me
[Mon Jul 20 07:28:56.443068 2026] [security2:error] [pid 148765:tid 148905] [client 191.202.66.27:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4imDv8fXmqCm8fNeqLcwAAARA"]
[Mon Jul 20 07:28:56.443198 2026] [security2:error] [pid 148765:tid 148905] [client 191.202.66.27:63334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4imDv8fXmqCm8fNeqLcwAAARA"]
[Mon Jul 20 07:28:56.555530 2026] [security2:error] [pid 145170:tid 145393] [client 193.37.33.15:39213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4imDjs5KUa9I09SwTxHAAAAN8"]
[Mon Jul 20 07:28:56.601622 2026] [security2:error] [pid 145170:tid 145312] [client 193.37.33.19:55283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4imDjs5KUa9I09SwTxHwAAAI4"]
[Mon Jul 20 07:28:57.093465 2026] [security2:error] [pid 148765:tid 148959] [client 63.176.132.15:53914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqLmQAAAUY"]
[Mon Jul 20 07:28:57.093576 2026] [security2:error] [pid 148765:tid 148959] [client 63.176.132.15:53914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqLmQAAAUY"]
[Mon Jul 20 07:28:57.127395 2026] [security2:error] [pid 145170:tid 145374] [client 14.225.17.146:63671] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4imTjs5KUa9I09SwTxLgAAAMw"], referer: http://getgarrison.com/Test
[Mon Jul 20 07:28:57.140010 2026] [security2:error] [pid 148765:tid 149014] [client 179.127.84.238:65209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqLmgAAAX0"]
[Mon Jul 20 07:28:57.140118 2026] [security2:error] [pid 148765:tid 149014] [client 179.127.84.238:65209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqLmgAAAX0"]
[Mon Jul 20 07:28:57.270393 2026] [security2:error] [pid 145170:tid 145342] [client 14.225.17.146:63666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4imTjs5KUa9I09SwTxLwAAAKw"], referer: http://tacticaltreeoperations.com/Test
[Mon Jul 20 07:28:57.356995 2026] [security2:error] [pid 145170:tid 145353] [client 104.234.53.58:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4imTjs5KUa9I09SwTxPgAAALc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:57.396285 2026] [security2:error] [pid 145170:tid 145379] [client 125.209.97.230:58363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4imTjs5KUa9I09SwTxQgAAANE"]
[Mon Jul 20 07:28:57.396430 2026] [security2:error] [pid 145170:tid 145379] [client 125.209.97.230:58363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4imTjs5KUa9I09SwTxQgAAANE"]
[Mon Jul 20 07:28:57.511463 2026] [security2:error] [pid 145170:tid 145260] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4imTjs5KUa9I09SwTxRgAAiVY"]
[Mon Jul 20 07:28:57.511698 2026] [security2:error] [pid 145170:tid 145307] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4imTjs5KUa9I09SwTxRgAAiVY"]
[Mon Jul 20 07:28:57.530317 2026] [security2:error] [pid 145170:tid 145337] [client 88.241.67.160:54357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4imTjs5KUa9I09SwTxRwAAAKc"]
[Mon Jul 20 07:28:57.530471 2026] [security2:error] [pid 145170:tid 145337] [client 88.241.67.160:54357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4imTjs5KUa9I09SwTxRwAAAKc"]
[Mon Jul 20 07:28:57.696043 2026] [security2:error] [pid 148765:tid 148937] [client 157.20.138.62:49732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqLugAAATA"]
[Mon Jul 20 07:28:57.696211 2026] [security2:error] [pid 148765:tid 148937] [client 157.20.138.62:49732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqLugAAATA"]
[Mon Jul 20 07:28:57.726255 2026] [security2:error] [pid 145170:tid 145237] [remote 81.173.115.7:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4imTjs5KUa9I09SwTxUgAAwD8"]
[Mon Jul 20 07:28:57.925514 2026] [security2:error] [pid 145170:tid 145191] [remote 81.173.115.7:55960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4imTjs5KUa9I09SwTxWQAAhRE"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 07:28:57.959660 2026] [security2:error] [pid 145170:tid 145395] [client 57.141.18.31:63338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4imTjs5KUa9I09SwTxNQAA4SI"]
[Mon Jul 20 07:28:57.976376 2026] [security2:error] [pid 148765:tid 148992] [client 143.44.185.218:5295] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqL3QAAAWc"]
[Mon Jul 20 07:28:57.976494 2026] [security2:error] [pid 148765:tid 148992] [client 143.44.185.218:5295] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4imTv8fXmqCm8fNeqL3QAAAWc"]
[Mon Jul 20 07:28:57.987167 2026] [security2:error] [pid 148765:tid 148917] [client 14.225.17.146:63621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4imTv8fXmqCm8fNeqLvAAAARw"], referer: http://dollpassionista.com/Test
[Mon Jul 20 07:28:58.489420 2026] [security2:error] [pid 148765:tid 148965] [client 57.141.18.109:62602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4imTv8fXmqCm8fNeqLtAABTHk"]
[Mon Jul 20 07:28:58.788142 2026] [security2:error] [pid 145170:tid 145332] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4imjjs5KUa9I09SwTxZgAAogk"], referer: http://assasalnazaha.com/Test
[Mon Jul 20 07:28:59.007066 2026] [security2:error] [pid 148765:tid 148997] [client 14.225.17.146:58656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4imjv8fXmqCm8fNeqMBwAAAWw"], referer: https://dollpassionista.com/Test
[Mon Jul 20 07:28:59.017308 2026] [security2:error] [pid 145170:tid 145320] [client 14.225.17.146:58667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4imjjs5KUa9I09SwTxdwAAAJY"], referer: http://longevityperformanceclinic.com/Test
[Mon Jul 20 07:28:59.035542 2026] [security2:error] [pid 148765:tid 148995] [client 49.37.242.14:59400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMDgAAAWo"]
[Mon Jul 20 07:28:59.035639 2026] [security2:error] [pid 148765:tid 148995] [client 49.37.242.14:59400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMDgAAAWo"]
[Mon Jul 20 07:28:59.155471 2026] [security2:error] [pid 148765:tid 148932] [client 202.141.11.99:24450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMFAAAASs"]
[Mon Jul 20 07:28:59.155973 2026] [security2:error] [pid 148765:tid 148932] [client 202.141.11.99:24450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMFAAAASs"]
[Mon Jul 20 07:28:59.271146 2026] [security2:error] [pid 148765:tid 148915] [client 117.211.236.168:60276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMIAAAARo"]
[Mon Jul 20 07:28:59.271240 2026] [security2:error] [pid 148765:tid 148915] [client 117.211.236.168:60276] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMIAAAARo"]
[Mon Jul 20 07:28:59.579359 2026] [security2:error] [pid 148765:tid 148994] [client 104.234.53.58:34939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4imzv8fXmqCm8fNeqMKwAAAWk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:28:59.771150 2026] [security2:error] [pid 148765:tid 148945] [client 49.47.218.174:64995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMLwAAATg"]
[Mon Jul 20 07:28:59.771244 2026] [security2:error] [pid 148765:tid 148945] [client 49.47.218.174:64995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4imzv8fXmqCm8fNeqMLwAAATg"]
[Mon Jul 20 07:28:59.886437 2026] [security2:error] [pid 145170:tid 145174] [remote 192.241.143.148:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4imzjs5KUa9I09SwTxlwAAvgA"]
[Mon Jul 20 07:28:59.954352 2026] [security2:error] [pid 145170:tid 145333] [client 13.233.207.33:44618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4imzjs5KUa9I09SwTxmQAAAKM"]
[Mon Jul 20 07:28:59.954557 2026] [security2:error] [pid 145170:tid 145333] [client 13.233.207.33:44618] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4imzjs5KUa9I09SwTxmQAAAKM"]
[Mon Jul 20 07:29:00.071457 2026] [security2:error] [pid 148765:tid 148903] [client 89.238.167.150:59324] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4inDv8fXmqCm8fNeqMPQAAAQ4"]
[Mon Jul 20 07:29:00.071552 2026] [security2:error] [pid 148765:tid 148903] [client 89.238.167.150:59324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4inDv8fXmqCm8fNeqMPQAAAQ4"]
[Mon Jul 20 07:29:00.074280 2026] [security2:error] [pid 145170:tid 145255] [remote 192.241.143.148:52732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4inDjs5KUa9I09SwTxngAAxVE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:29:00.217510 2026] [security2:error] [pid 145170:tid 145331] [client 57.141.18.109:62618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4imzjs5KUa9I09SwTxhAAAoTE"]
[Mon Jul 20 07:29:00.485122 2026] [security2:error] [pid 145170:tid 145325] [client 154.192.123.127:17713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4inDjs5KUa9I09SwTxrwAAAJs"]
[Mon Jul 20 07:29:00.485229 2026] [security2:error] [pid 145170:tid 145325] [client 154.192.123.127:17713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4inDjs5KUa9I09SwTxrwAAAJs"]
[Mon Jul 20 07:29:00.495400 2026] [security2:error] [pid 145170:tid 145414] [client 57.141.18.73:33812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4imzjs5KUa9I09SwTxjgAA9Ck"]
[Mon Jul 20 07:29:00.505595 2026] [security2:error] [pid 145170:tid 145373] [client 57.141.18.56:27172] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4imzjs5KUa9I09SwTxjwAAyy0"]
[Mon Jul 20 07:29:00.877345 2026] [security2:error] [pid 145170:tid 145345] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4inDjs5KUa9I09SwTxtAAArxo"], referer: http://ali-alghanim.net/Test
[Mon Jul 20 07:29:01.111738 2026] [security2:error] [pid 145170:tid 145383] [client 14.225.17.146:55168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4imjjs5KUa9I09SwTxcQAAANU"], referer: http://gearwaterproof.com/Test
[Mon Jul 20 07:29:01.256424 2026] [security2:error] [pid 148765:tid 149021] [client 89.238.167.150:59326] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4inTv8fXmqCm8fNeqMfAAAAYQ"]
[Mon Jul 20 07:29:01.256571 2026] [security2:error] [pid 148765:tid 149021] [client 89.238.167.150:59326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4inTv8fXmqCm8fNeqMfAAAAYQ"]
[Mon Jul 20 07:29:01.322604 2026] [security2:error] [pid 145170:tid 145424] [client 50.116.65.227:27010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4inTjs5KUa9I09SwTxzwAAAP4"]
[Mon Jul 20 07:29:01.484826 2026] [security2:error] [pid 145170:tid 145375] [client 36.93.152.155:60286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4inTjs5KUa9I09SwTx4wAAAM0"]
[Mon Jul 20 07:29:01.484957 2026] [security2:error] [pid 145170:tid 145375] [client 36.93.152.155:60286] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4inTjs5KUa9I09SwTx4wAAAM0"]
[Mon Jul 20 07:29:01.528343 2026] [security2:error] [pid 145170:tid 145406] [client 50.116.65.227:27026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4inTjs5KUa9I09SwTx3AAAAOw"]
[Mon Jul 20 07:29:01.555315 2026] [security2:error] [pid 148765:tid 149017] [client 57.141.18.91:54326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4inDv8fXmqCm8fNeqMXgABgGw"]
[Mon Jul 20 07:29:01.621321 2026] [security2:error] [pid 145170:tid 145304] [client 14.225.17.146:65472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4inDjs5KUa9I09SwTxvQAAAIY"], referer: http://idigress.agency/Test
[Mon Jul 20 07:29:02.306447 2026] [security2:error] [pid 145170:tid 145362] [client 103.176.215.66:53335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4injjs5KUa9I09SwTx9wAAAMA"]
[Mon Jul 20 07:29:02.306559 2026] [security2:error] [pid 145170:tid 145362] [client 103.176.215.66:53335] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4injjs5KUa9I09SwTx9wAAAMA"]
[Mon Jul 20 07:29:02.322663 2026] [security2:error] [pid 148765:tid 148977] [client 14.225.17.146:65486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4injv8fXmqCm8fNeqMswAAAVg"], referer: http://christiancountytrumpet.com/Test
[Mon Jul 20 07:29:02.371827 2026] [security2:error] [pid 148765:tid 148981] [client 201.27.111.74:54571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4injv8fXmqCm8fNeqMwQAAAVw"]
[Mon Jul 20 07:29:02.371923 2026] [security2:error] [pid 148765:tid 148981] [client 201.27.111.74:54571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4injv8fXmqCm8fNeqMwQAAAVw"]
[Mon Jul 20 07:29:02.547488 2026] [security2:error] [pid 145170:tid 145387] [client 57.141.18.65:44528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4inTjs5KUa9I09SwTx6AAA2Rk"]
[Mon Jul 20 07:29:02.755562 2026] [security2:error] [pid 148765:tid 149004] [client 144.16.21.149:36214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4injv8fXmqCm8fNeqM1wAAAXM"]
[Mon Jul 20 07:29:02.940779 2026] [security2:error] [pid 145170:tid 145360] [client 103.106.165.44:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4injjs5KUa9I09SwTyBQAAAL4"]
[Mon Jul 20 07:29:02.940943 2026] [security2:error] [pid 145170:tid 145360] [client 103.106.165.44:50368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4injjs5KUa9I09SwTyBQAAAL4"]
[Mon Jul 20 07:29:02.965831 2026] [security2:error] [pid 148765:tid 148949] [client 57.141.18.62:62752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4injv8fXmqCm8fNeqMvQABPGk"]
[Mon Jul 20 07:29:03.226889 2026] [security2:error] [pid 148765:tid 148906] [client 98.159.234.160:58573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4inzv8fXmqCm8fNeqM-AAAARE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:29:03.325282 2026] [security2:error] [pid 148765:tid 148946] [client 14.225.17.146:49268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4inzv8fXmqCm8fNeqM9wAAATk"], referer: http://whiteoutcb.com/Test
[Mon Jul 20 07:29:03.339009 2026] [security2:error] [pid 148765:tid 148998] [client 66.249.65.167:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.primefocushrc.com"] [uri "/index.php"] [unique_id "al4inTv8fXmqCm8fNeqMegABbXg"]
[Mon Jul 20 07:29:03.444223 2026] [security2:error] [pid 148765:tid 148982] [client 104.234.53.90:54755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4inzv8fXmqCm8fNeqNAwAAAV0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:03.602562 2026] [security2:error] [pid 148765:tid 148928] [client 14.225.17.146:54093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4inzv8fXmqCm8fNeqNAQAAASc"]
[Mon Jul 20 07:29:04.262225 2026] [security2:error] [pid 145170:tid 145414] [client 57.141.18.5:47616] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4inzjs5KUa9I09SwTyEQAA9BQ"]
[Mon Jul 20 07:29:04.542659 2026] [security2:error] [pid 148765:tid 148973] [client 87.199.196.160:61646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.196.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.39ishlife.com"] [uri "/wp-comments-post.php"] [unique_id "al4ioDv8fXmqCm8fNeqNLQAAAVQ"], referer: https://www.39ishlife.com/givingpic/
[Mon Jul 20 07:29:04.542788 2026] [security2:error] [pid 148765:tid 148973] [client 87.199.196.160:61646] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.39ishlife.com"] [uri "/wp-comments-post.php"] [unique_id "al4ioDv8fXmqCm8fNeqNLQAAAVQ"], referer: https://www.39ishlife.com/givingpic/
[Mon Jul 20 07:29:04.671018 2026] [security2:error] [pid 145170:tid 145290] [remote 217.61.143.92:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ioDjs5KUa9I09SwTyRQAAyHQ"]
[Mon Jul 20 07:29:04.973645 2026] [security2:error] [pid 145170:tid 145193] [remote 217.61.143.92:37948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ioDjs5KUa9I09SwTyVgAAzBM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:29:05.032824 2026] [lsapi:warn] [pid 148765:tid 148899] [client 14.225.17.146:54135] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Test
[Mon Jul 20 07:29:05.032860 2026] [lsapi:warn] [pid 148765:tid 148899] [client 14.225.17.146:54135] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/Test
[Mon Jul 20 07:29:05.120292 2026] [lsapi:warn] [pid 145170:tid 145327] [client 50.116.65.227:27098] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:29:05.120319 2026] [lsapi:warn] [pid 145170:tid 145327] [client 50.116.65.227:27098] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:29:05.136546 2026] [security2:error] [pid 148765:tid 148899] [client 14.225.17.146:54135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4ioTv8fXmqCm8fNeqNSAAAAQo"], referer: http://oswegooperatheater.com/Test
[Mon Jul 20 07:29:05.188412 2026] [security2:error] [pid 145170:tid 145315] [client 57.141.18.16:46332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ioDjs5KUa9I09SwTyPwAAkQE"]
[Mon Jul 20 07:29:05.236045 2026] [security2:error] [pid 145170:tid 145304] [client 136.158.60.21:58638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4ioTjs5KUa9I09SwTyYwAAAIY"]
[Mon Jul 20 07:29:05.239490 2026] [security2:error] [pid 145170:tid 145304] [client 136.158.60.21:58638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4ioTjs5KUa9I09SwTyYwAAAIY"]
[Mon Jul 20 07:29:05.627444 2026] [security2:error] [pid 145170:tid 145368] [client 57.141.18.109:62622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ioDjs5KUa9I09SwTyUgAAxgY"]
[Mon Jul 20 07:29:06.014653 2026] [lsapi:warn] [pid 145170:tid 145417] [client 14.225.17.146:57818] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Test
[Mon Jul 20 07:29:06.014684 2026] [lsapi:warn] [pid 145170:tid 145417] [client 14.225.17.146:57818] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/Test
[Mon Jul 20 07:29:06.067258 2026] [security2:error] [pid 145170:tid 145417] [client 14.225.17.146:57818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4iojjs5KUa9I09SwTyfAAAAPc"], referer: https://oswegooperatheater.com/Test
[Mon Jul 20 07:29:06.565714 2026] [security2:error] [pid 148765:tid 148856] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iojv8fXmqCm8fNeqNnQABQFY"]
[Mon Jul 20 07:29:06.565833 2026] [security2:error] [pid 148765:tid 148953] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iojv8fXmqCm8fNeqNnQABQFY"]
[Mon Jul 20 07:29:06.655238 2026] [security2:error] [pid 145170:tid 145306] [client 125.209.97.230:58853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iojjs5KUa9I09SwTykQAAAIg"]
[Mon Jul 20 07:29:06.655333 2026] [security2:error] [pid 145170:tid 145306] [client 125.209.97.230:58853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iojjs5KUa9I09SwTykQAAAIg"]
[Mon Jul 20 07:29:06.709152 2026] [security2:error] [pid 148765:tid 148964] [client 14.225.17.146:64229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4iojv8fXmqCm8fNeqNmwAAAUs"], referer: http://colinkeyphotography.com/Test
[Mon Jul 20 07:29:06.839884 2026] [security2:error] [pid 145170:tid 145355] [client 77.110.127.138:50075] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iojjs5KUa9I09SwTykAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:07.080442 2026] [security2:error] [pid 145170:tid 145340] [client 191.202.66.27:64068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iozjs5KUa9I09SwTynAAAAKo"]
[Mon Jul 20 07:29:07.080556 2026] [security2:error] [pid 145170:tid 145340] [client 191.202.66.27:64068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iozjs5KUa9I09SwTynAAAAKo"]
[Mon Jul 20 07:29:07.112453 2026] [security2:error] [pid 148765:tid 148987] [client 24.66.225.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4iojv8fXmqCm8fNeqNrAABYk8"]
[Mon Jul 20 07:29:07.187355 2026] [autoindex:error] [pid 148765:tid 148859] [remote 65.109.16.46:37744] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:29:07.675168 2026] [security2:error] [pid 148765:tid 148963] [client 18.184.179.151:23214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iozv8fXmqCm8fNeqN3AAAAUo"]
[Mon Jul 20 07:29:07.675316 2026] [security2:error] [pid 148765:tid 148963] [client 18.184.179.151:23214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iozv8fXmqCm8fNeqN3AAAAUo"]
[Mon Jul 20 07:29:07.722386 2026] [security2:error] [pid 148765:tid 148939] [client 179.127.84.238:49359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iozv8fXmqCm8fNeqN4AAAATI"]
[Mon Jul 20 07:29:07.722508 2026] [security2:error] [pid 148765:tid 148939] [client 179.127.84.238:49359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iozv8fXmqCm8fNeqN4AAAATI"]
[Mon Jul 20 07:29:08.089583 2026] [security2:error] [pid 148765:tid 148896] [remote 78.46.157.202:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4ipDv8fXmqCm8fNeqN8gABQH4"]
[Mon Jul 20 07:29:08.151032 2026] [security2:error] [pid 148765:tid 148889] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ipDv8fXmqCm8fNeqN-AABN3c"]
[Mon Jul 20 07:29:08.151198 2026] [security2:error] [pid 148765:tid 148944] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ipDv8fXmqCm8fNeqN-AABN3c"]
[Mon Jul 20 07:29:08.243251 2026] [security2:error] [pid 148765:tid 149016] [client 88.241.67.160:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ipDv8fXmqCm8fNeqOAwAAAX8"]
[Mon Jul 20 07:29:08.243692 2026] [security2:error] [pid 148765:tid 149016] [client 88.241.67.160:56214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ipDv8fXmqCm8fNeqOAwAAAX8"]
[Mon Jul 20 07:29:08.364882 2026] [security2:error] [pid 145170:tid 145394] [client 157.20.138.62:50311] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ipDjs5KUa9I09SwTyuQAAAOA"]
[Mon Jul 20 07:29:08.364999 2026] [security2:error] [pid 145170:tid 145394] [client 157.20.138.62:50311] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ipDjs5KUa9I09SwTyuQAAAOA"]
[Mon Jul 20 07:29:08.453149 2026] [security2:error] [pid 148765:tid 148934] [client 57.141.18.88:55308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iozv8fXmqCm8fNeqN3wABLSY"]
[Mon Jul 20 07:29:08.482094 2026] [security2:error] [pid 145170:tid 145397] [client 107.175.132.21:39216] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.joulecommunications.com"] [uri "/.env"] [unique_id "al4ipDjs5KUa9I09SwTyvAAAAOM"]
[Mon Jul 20 07:29:08.580364 2026] [security2:error] [pid 148765:tid 148964] [client 57.141.18.46:49106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iozv8fXmqCm8fNeqN4wABS1A"]
[Mon Jul 20 07:29:08.645774 2026] [security2:error] [pid 148765:tid 148942] [client 168.119.53.160:34214] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4ipDv8fXmqCm8fNeqOEgAAATU"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:29:08.892613 2026] [security2:error] [pid 148765:tid 148944] [client 50.116.65.227:27162] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ipDv8fXmqCm8fNeqOPAAAATc"]
[Mon Jul 20 07:29:08.902416 2026] [security2:error] [pid 145170:tid 145335] [client 50.116.65.227:27170] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ipDjs5KUa9I09SwTy0AAAAKU"]
[Mon Jul 20 07:29:08.917736 2026] [security2:error] [pid 148765:tid 148860] [remote 78.46.157.202:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jndsupport.com"] [uri "/wp-login.php"] [unique_id "al4ipDv8fXmqCm8fNeqOPQABbFo"], referer: https://jndsupport.com/wp-login.php
[Mon Jul 20 07:29:09.020269 2026] [security2:error] [pid 148765:tid 148958] [client 57.141.18.110:53336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipDv8fXmqCm8fNeqOBgABRXU"]
[Mon Jul 20 07:29:09.037501 2026] [security2:error] [pid 148765:tid 148907] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipDv8fXmqCm8fNeqONAAAARI"]
[Mon Jul 20 07:29:09.376050 2026] [security2:error] [pid 148765:tid 148976] [client 107.175.132.21:39264] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "mail.joulecommunications.com"] [uri "/actuator/env"] [unique_id "al4ipTv8fXmqCm8fNeqOXwAAAVc"]
[Mon Jul 20 07:29:09.378737 2026] [security2:error] [pid 148765:tid 148968] [client 107.175.132.21:39252] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "mail.joulecommunications.com"] [uri "/.env.backup"] [unique_id "al4ipTv8fXmqCm8fNeqOYAAAAU8"]
[Mon Jul 20 07:29:09.392847 2026] [security2:error] [pid 148765:tid 148930] [client 57.141.18.31:48258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipDv8fXmqCm8fNeqOIAABKUE"]
[Mon Jul 20 07:29:09.457064 2026] [security2:error] [pid 148765:tid 148962] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOTQAAAUk"]
[Mon Jul 20 07:29:09.485151 2026] [autoindex:error] [pid 145170:tid 145187] [remote 35.255.41.48:65455] AH01276: Cannot serve directory /home2/oqkxeemy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://oqk.xee.mybluehost.me
[Mon Jul 20 07:29:09.511822 2026] [security2:error] [pid 148765:tid 148953] [client 54.184.226.94:36315] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thecreole.com"] [uri "/"] [unique_id "al4ipTv8fXmqCm8fNeqOcwAAAUA"]
[Mon Jul 20 07:29:09.537905 2026] [security2:error] [pid 148765:tid 148971] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOWAAAAVI"]
[Mon Jul 20 07:29:09.583257 2026] [security2:error] [pid 148765:tid 149016] [client 54.184.226.94:17186] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "TRACE" at REQUEST_METHOD. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "52"] [id "340002"] [rev "3"] [msg "Atomicorp.com WAF Rules: TRACE/TRACK method denied"] [severity "CRITICAL"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4ipTv8fXmqCm8fNeqOfgAAAX8"]
[Mon Jul 20 07:29:09.625573 2026] [security2:error] [pid 148765:tid 148994] [client 202.141.11.99:27416] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ipTv8fXmqCm8fNeqOgAAAAWk"]
[Mon Jul 20 07:29:09.625675 2026] [security2:error] [pid 148765:tid 148994] [client 202.141.11.99:27416] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ipTv8fXmqCm8fNeqOgAAAAWk"]
[Mon Jul 20 07:29:09.650986 2026] [security2:error] [pid 148765:tid 148949] [client 107.175.132.21:45044] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "mail.joulecommunications.com"] [uri "/.env.bak"] [unique_id "al4ipTv8fXmqCm8fNeqOggAAATw"]
[Mon Jul 20 07:29:09.657531 2026] [security2:error] [pid 148765:tid 148988] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOZQAAAWM"]
[Mon Jul 20 07:29:09.683322 2026] [security2:error] [pid 148765:tid 148967] [client 54.184.226.94:55455] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4ipTv8fXmqCm8fNeqOhwAAAU4"], referer: https://www.google.com/images/url
[Mon Jul 20 07:29:09.701633 2026] [security2:error] [pid 148765:tid 148919] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOcgAAAR4"]
[Mon Jul 20 07:29:09.966733 2026] [security2:error] [pid 148765:tid 148920] [client 117.211.236.168:60802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ipTv8fXmqCm8fNeqOmwAAAR8"]
[Mon Jul 20 07:29:09.966864 2026] [security2:error] [pid 148765:tid 148920] [client 117.211.236.168:60802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ipTv8fXmqCm8fNeqOmwAAAR8"]
[Mon Jul 20 07:29:09.977161 2026] [security2:error] [pid 145170:tid 145400] [client 14.225.17.146:63185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4ipDjs5KUa9I09SwTyuAAAAOY"], referer: http://aandarealtygroup.com/Test
[Mon Jul 20 07:29:10.058044 2026] [security2:error] [pid 148765:tid 149021] [client 57.141.18.123:58554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqORAABhBE"]
[Mon Jul 20 07:29:10.152263 2026] [security2:error] [pid 148765:tid 148794] [remote 216.73.216.55:19184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4ipjv8fXmqCm8fNeqOrAABChg"]
[Mon Jul 20 07:29:10.183835 2026] [security2:error] [pid 148765:tid 148976] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOmgAAAVc"]
[Mon Jul 20 07:29:10.276971 2026] [security2:error] [pid 148765:tid 148918] [client 49.47.218.174:49200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ipjv8fXmqCm8fNeqOswAAAR0"]
[Mon Jul 20 07:29:10.277060 2026] [security2:error] [pid 148765:tid 148918] [client 49.47.218.174:49200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ipjv8fXmqCm8fNeqOswAAAR0"]
[Mon Jul 20 07:29:10.600679 2026] [security2:error] [pid 148765:tid 148992] [client 77.110.127.138:50074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ipjv8fXmqCm8fNeqOvQAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:10.705227 2026] [security2:error] [pid 148765:tid 148978] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipjv8fXmqCm8fNeqOxQAAAVk"]
[Mon Jul 20 07:29:10.767563 2026] [security2:error] [pid 148765:tid 149004] [client 57.141.18.94:47994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOmAABcyE"]
[Mon Jul 20 07:29:10.887739 2026] [security2:error] [pid 148765:tid 148980] [client 57.141.18.109:27170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipTv8fXmqCm8fNeqOnQABW1g"]
[Mon Jul 20 07:29:11.026207 2026] [security2:error] [pid 145170:tid 145349] [client 143.44.185.218:6935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzjs5KUa9I09SwTy-gAAALM"]
[Mon Jul 20 07:29:11.026360 2026] [security2:error] [pid 145170:tid 145349] [client 143.44.185.218:6935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzjs5KUa9I09SwTy-gAAALM"]
[Mon Jul 20 07:29:11.062995 2026] [security2:error] [pid 148765:tid 148935] [client 154.192.123.127:18210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzv8fXmqCm8fNeqO8wAAAS4"]
[Mon Jul 20 07:29:11.063122 2026] [security2:error] [pid 148765:tid 148935] [client 154.192.123.127:18210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzv8fXmqCm8fNeqO8wAAAS4"]
[Mon Jul 20 07:29:11.545023 2026] [security2:error] [pid 148765:tid 148936] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipzv8fXmqCm8fNeqPBAAAAS8"]
[Mon Jul 20 07:29:11.667522 2026] [security2:error] [pid 148765:tid 148963] [client 14.225.17.146:65401] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4ipzv8fXmqCm8fNeqPEAAAAUo"], referer: http://wathenbartlett.co.uk/Test
[Mon Jul 20 07:29:11.667881 2026] [security2:error] [pid 148765:tid 148899] [client 57.141.18.103:64738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipjv8fXmqCm8fNeqO3QABCnk"]
[Mon Jul 20 07:29:11.722178 2026] [security2:error] [pid 148765:tid 148991] [client 57.141.18.89:27440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipjv8fXmqCm8fNeqO6QABZkM"]
[Mon Jul 20 07:29:11.745515 2026] [security2:error] [pid 145170:tid 145321] [client 45.61.188.240:56261] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.apolloinfrastructureholdings.online"] [uri "/"] [unique_id "al4ipzjs5KUa9I09SwTzFgAAAJc"]
[Mon Jul 20 07:29:11.821082 2026] [security2:error] [pid 148765:tid 149006] [client 49.37.242.14:59886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzv8fXmqCm8fNeqPIAAAAXU"]
[Mon Jul 20 07:29:11.821205 2026] [security2:error] [pid 148765:tid 149006] [client 49.37.242.14:59886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzv8fXmqCm8fNeqPIAAAAXU"]
[Mon Jul 20 07:29:11.944332 2026] [security2:error] [pid 148765:tid 148900] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4ipzv8fXmqCm8fNeqPGQAAAQs"]
[Mon Jul 20 07:29:11.952231 2026] [security2:error] [pid 148765:tid 148922] [client 36.93.152.155:60803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzv8fXmqCm8fNeqPKQAAASE"]
[Mon Jul 20 07:29:11.952334 2026] [security2:error] [pid 148765:tid 148922] [client 36.93.152.155:60803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ipzv8fXmqCm8fNeqPKQAAASE"]
[Mon Jul 20 07:29:12.011655 2026] [security2:error] [pid 148765:tid 148985] [client 45.61.188.240:56301] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mail.apolloinfrastructureholdings.online"] [uri "/"] [unique_id "al4iqDv8fXmqCm8fNeqPKwAAAWA"]
[Mon Jul 20 07:29:12.241816 2026] [security2:error] [pid 148765:tid 149009] [client 158.173.241.141:61893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4iqDv8fXmqCm8fNeqPLQAAAXg"], referer: http://sesamegreenbeans.com/nine-days-south-africa-vi/
[Mon Jul 20 07:29:12.376794 2026] [security2:error] [pid 148765:tid 148844] [remote 173.249.4.11:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4iqDv8fXmqCm8fNeqPQQABeUo"]
[Mon Jul 20 07:29:12.497336 2026] [security2:error] [pid 148765:tid 148920] [client 107.175.132.21:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.joulecommunications.com"] [uri "/index.php"] [unique_id "al4iqDv8fXmqCm8fNeqPPgAAAR8"]
[Mon Jul 20 07:29:12.545759 2026] [security2:error] [pid 148765:tid 148972] [client 14.225.17.146:64050] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4iqDv8fXmqCm8fNeqPSAAAAVM"], referer: http://nikkidesigns.net/Test
[Mon Jul 20 07:29:12.567521 2026] [security2:error] [pid 148765:tid 148884] [remote 173.249.4.11:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/wp-login.php"] [unique_id "al4iqDv8fXmqCm8fNeqPSwABTXI"], referer: https://securingmemories.com/wp-login.php
[Mon Jul 20 07:29:12.568839 2026] [security2:error] [pid 145170:tid 145414] [client 14.225.17.146:63157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4iqDjs5KUa9I09SwTzLwAAAPQ"], referer: https://wathenbartlett.co.uk/Test
[Mon Jul 20 07:29:12.641235 2026] [security2:error] [pid 145170:tid 145421] [client 57.141.18.64:30024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipzjs5KUa9I09SwTzCwAA-ww"]
[Mon Jul 20 07:29:12.695546 2026] [security2:error] [pid 148765:tid 148970] [client 116.74.65.235:58533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4iqDv8fXmqCm8fNeqPRwAAAVE"]
[Mon Jul 20 07:29:12.822436 2026] [lsapi:warn] [pid 148765:tid 148819] [remote 35.245.189.45:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.com/
[Mon Jul 20 07:29:12.841837 2026] [security2:error] [pid 148765:tid 148944] [client 201.27.111.74:55085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iqDv8fXmqCm8fNeqPXAAAATc"]
[Mon Jul 20 07:29:12.841921 2026] [security2:error] [pid 148765:tid 148944] [client 201.27.111.74:55085] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iqDv8fXmqCm8fNeqPXAAAATc"]
[Mon Jul 20 07:29:12.863869 2026] [security2:error] [pid 145170:tid 145320] [client 57.141.18.71:53042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipzjs5KUa9I09SwTzFwAAlks"]
[Mon Jul 20 07:29:12.863926 2026] [security2:error] [pid 148765:tid 148960] [client 103.176.215.66:53875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iqDv8fXmqCm8fNeqPXQAAAUc"]
[Mon Jul 20 07:29:12.864063 2026] [security2:error] [pid 148765:tid 148960] [client 103.176.215.66:53875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iqDv8fXmqCm8fNeqPXQAAAUc"]
[Mon Jul 20 07:29:12.864479 2026] [autoindex:error] [pid 148765:tid 148957] [client 188.166.209.66:60908] AH01276: Cannot serve directory /home2/onewingp/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:29:12.961263 2026] [security2:error] [pid 148765:tid 148982] [client 50.116.65.227:10178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_43ccd705/wp-cron.php"] [unique_id "al4iqDv8fXmqCm8fNeqPYwAAAV0"]
[Mon Jul 20 07:29:12.966556 2026] [security2:error] [pid 148765:tid 148948] [client 57.141.18.56:44610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ipzv8fXmqCm8fNeqPKAABOzs"]
[Mon Jul 20 07:29:13.066095 2026] [lsapi:warn] [pid 145170:tid 145235] [remote 35.245.189.45:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim-com.aasgroup.online/
[Mon Jul 20 07:29:13.267807 2026] [core:error] [pid 145170:tid 145396] [client 35.245.239.138:56031] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:13.267827 2026] [core:error] [pid 145170:tid 145396] [client 35.245.239.138:56031] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:13.391025 2026] [security2:error] [pid 148765:tid 148907] [client 103.106.165.44:50864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iqTv8fXmqCm8fNeqPhwAAARI"]
[Mon Jul 20 07:29:13.391122 2026] [security2:error] [pid 148765:tid 148907] [client 103.106.165.44:50864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iqTv8fXmqCm8fNeqPhwAAARI"]
[Mon Jul 20 07:29:13.404879 2026] [security2:error] [pid 148765:tid 148966] [client 35.245.239.138:59224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/xmlrpc.php"] [unique_id "al4iqTv8fXmqCm8fNeqPhgAAAU0"]
[Mon Jul 20 07:29:13.551548 2026] [security2:error] [pid 148765:tid 148960] [client 35.245.239.138:59390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4iqTv8fXmqCm8fNeqPkQAAAUc"]
[Mon Jul 20 07:29:13.637870 2026] [security2:error] [pid 148765:tid 148925] [client 144.16.21.149:25157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4iqTv8fXmqCm8fNeqPkAAAASQ"]
[Mon Jul 20 07:29:13.683577 2026] [security2:error] [pid 148765:tid 148977] [client 35.245.239.138:62496] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4iqTv8fXmqCm8fNeqPnQAAAVg"]
[Mon Jul 20 07:29:13.718027 2026] [security2:error] [pid 148765:tid 148911] [client 57.141.18.42:61560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iqDv8fXmqCm8fNeqPTQABFlQ"]
[Mon Jul 20 07:29:13.804664 2026] [security2:error] [pid 145170:tid 145309] [client 35.245.239.138:50896] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4iqTjs5KUa9I09SwTzUAAAAIs"]
[Mon Jul 20 07:29:13.919548 2026] [security2:error] [pid 148765:tid 149001] [client 35.245.239.138:58057] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4iqTv8fXmqCm8fNeqPsQAAAXA"]
[Mon Jul 20 07:29:13.954465 2026] [security2:error] [pid 148765:tid 148976] [client 50.116.65.227:10198] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4iqTv8fXmqCm8fNeqPtQAAAVc"]
[Mon Jul 20 07:29:13.967581 2026] [security2:error] [pid 148765:tid 148929] [client 50.116.65.227:34638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Feature-Image-Day-6.jpg"] [unique_id "al4iqTv8fXmqCm8fNeqPtgAAASg"]
[Mon Jul 20 07:29:14.094410 2026] [security2:error] [pid 148765:tid 148902] [client 35.245.239.138:62245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4iqjv8fXmqCm8fNeqPwQAAAQ0"]
[Mon Jul 20 07:29:14.240445 2026] [security2:error] [pid 145170:tid 145342] [client 35.245.239.138:59045] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4iqjjs5KUa9I09SwTzYQAAAKw"]
[Mon Jul 20 07:29:14.247812 2026] [security2:error] [pid 148765:tid 148943] [client 66.249.70.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4iqjv8fXmqCm8fNeqPwAABNgc"]
[Mon Jul 20 07:29:14.357201 2026] [security2:error] [pid 148765:tid 148942] [client 35.245.239.138:58137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4iqjv8fXmqCm8fNeqP0gAAATU"]
[Mon Jul 20 07:29:14.484775 2026] [security2:error] [pid 148765:tid 149008] [client 35.245.239.138:61528] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4iqjv8fXmqCm8fNeqP1gAAAXc"]
[Mon Jul 20 07:29:14.642305 2026] [security2:error] [pid 148765:tid 149025] [client 35.245.239.138:56133] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-43ccd705.balticsteelmgmt.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4iqjv8fXmqCm8fNeqP3gAAAYg"]
[Mon Jul 20 07:29:14.921552 2026] [security2:error] [pid 145170:tid 145329] [client 57.141.18.26:57534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iqTjs5KUa9I09SwTzTwAAnwU"]
[Mon Jul 20 07:29:15.134925 2026] [security2:error] [pid 148765:tid 148962] [client 14.225.17.146:56770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4iqjv8fXmqCm8fNeqP6wAAAUk"], referer: http://nwcarvingacademy.com/Test
[Mon Jul 20 07:29:15.325337 2026] [security2:error] [pid 148765:tid 148925] [client 57.141.18.101:42796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iqjv8fXmqCm8fNeqPzgABJG8"]
[Mon Jul 20 07:29:15.475673 2026] [security2:error] [pid 145170:tid 145379] [client 57.141.18.109:27184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iqjjs5KUa9I09SwTzZwAA0So"]
[Mon Jul 20 07:29:15.570084 2026] [security2:error] [pid 148765:tid 148971] [client 57.141.18.101:42802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iqjv8fXmqCm8fNeqP3AABUnA"]
[Mon Jul 20 07:29:15.600457 2026] [security2:error] [pid 145170:tid 145355] [client 14.225.17.146:61565] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4iqzjs5KUa9I09SwTzhAAAALk"], referer: http://aljosour-alarabia.com/Test
[Mon Jul 20 07:29:15.615822 2026] [security2:error] [pid 145170:tid 145308] [client 14.225.17.146:64294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4iqjjs5KUa9I09SwTzXAAAAIo"], referer: http://reosportsboats.com/Test
[Mon Jul 20 07:29:15.724146 2026] [security2:error] [pid 145170:tid 145283] [remote 114.119.137.28:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "origine.nz"] [uri "/watch-the-new-season-of-a-new-zealand-food-story"] [unique_id "al4iqzjs5KUa9I09SwTziAAA4W0"], referer: https://origine.nz/watch-the-new-season-of-a-new-zealand-food-story
[Mon Jul 20 07:29:15.998458 2026] [security2:error] [pid 145170:tid 145362] [client 57.141.18.88:36880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iqzjs5KUa9I09SwTzdQAAwHw"]
[Mon Jul 20 07:29:16.011349 2026] [security2:error] [pid 148765:tid 148940] [client 14.225.17.146:56898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4iqzv8fXmqCm8fNeqQLQAAATM"], referer: http://adirondackengineering.com/Test
[Mon Jul 20 07:29:16.044714 2026] [security2:error] [pid 148765:tid 149021] [client 136.158.60.21:60183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4irDv8fXmqCm8fNeqQOAAAAYQ"]
[Mon Jul 20 07:29:16.044835 2026] [security2:error] [pid 148765:tid 149021] [client 136.158.60.21:60183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4irDv8fXmqCm8fNeqQOAAAAYQ"]
[Mon Jul 20 07:29:16.237417 2026] [security2:error] [pid 145170:tid 145352] [client 104.234.53.53:33363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4irDjs5KUa9I09SwTzmgAAALY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:16.306692 2026] [security2:error] [pid 148765:tid 149019] [client 14.225.17.146:61597] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4irDv8fXmqCm8fNeqQOQAAAYI"], referer: https://nwcarvingacademy.com/Test
[Mon Jul 20 07:29:16.611319 2026] [security2:error] [pid 145170:tid 145399] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4irDjs5KUa9I09SwTzpwAAAOU"]
[Mon Jul 20 07:29:16.676250 2026] [security2:error] [pid 148765:tid 148921] [client 14.225.17.146:50115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4irDv8fXmqCm8fNeqQTgAAASA"], referer: https://reosportsboats.com/Test
[Mon Jul 20 07:29:16.875758 2026] [security2:error] [pid 145170:tid 145303] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4irDjs5KUa9I09SwTztAAAhWw"]
[Mon Jul 20 07:29:16.907624 2026] [security2:error] [pid 145170:tid 145343] [client 57.141.18.53:49358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irDjs5KUa9I09SwTzkgAArT4"]
[Mon Jul 20 07:29:17.168675 2026] [security2:error] [pid 145170:tid 145311] [client 142.111.152.49:24709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4irTjs5KUa9I09SwTzwgAAAI0"]
[Mon Jul 20 07:29:17.168815 2026] [security2:error] [pid 145170:tid 145311] [client 142.111.152.49:24709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4irTjs5KUa9I09SwTzwgAAAI0"]
[Mon Jul 20 07:29:17.177686 2026] [security2:error] [pid 145170:tid 145176] [remote 72.167.132.114:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4irTjs5KUa9I09SwTzxgAA3QI"]
[Mon Jul 20 07:29:17.178304 2026] [security2:error] [pid 148765:tid 148879] [remote 103.161.172.221:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4irTv8fXmqCm8fNeqQbAABL20"]
[Mon Jul 20 07:29:17.187983 2026] [security2:error] [pid 145170:tid 145380] [client 125.209.97.230:59343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4irTjs5KUa9I09SwTzxwAAANI"]
[Mon Jul 20 07:29:17.188115 2026] [security2:error] [pid 145170:tid 145380] [client 125.209.97.230:59343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4irTjs5KUa9I09SwTzxwAAANI"]
[Mon Jul 20 07:29:17.270562 2026] [security2:error] [pid 145170:tid 145329] [client 57.141.18.1:46494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irDjs5KUa9I09SwTzogAAn34"]
[Mon Jul 20 07:29:17.352031 2026] [security2:error] [pid 145170:tid 145355] [client 14.225.17.146:57154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4irTjs5KUa9I09SwTzzAAAALk"], referer: http://daseighty.net/Test
[Mon Jul 20 07:29:17.411050 2026] [security2:error] [pid 145170:tid 145410] [client 190.92.202.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4irTjs5KUa9I09SwTzwwAA8GY"]
[Mon Jul 20 07:29:17.411165 2026] [security2:error] [pid 145170:tid 145272] [remote 72.167.132.114:34614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4irTjs5KUa9I09SwTz0QAA9mI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:29:17.577381 2026] [security2:error] [pid 148765:tid 148837] [remote 103.161.172.221:60056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.172.161.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "swafforddetailing.com"] [uri "/wp-login.php"] [unique_id "al4irTv8fXmqCm8fNeqQhgABd0M"], referer: https://swafforddetailing.com/wp-login.php
[Mon Jul 20 07:29:17.684308 2026] [security2:error] [pid 145170:tid 145430] [client 57.141.18.96:43220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irDjs5KUa9I09SwTztgABBAY"]
[Mon Jul 20 07:29:17.823671 2026] [security2:error] [pid 145170:tid 145326] [client 191.202.66.27:64633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4irTjs5KUa9I09SwTz2wAAAJw"]
[Mon Jul 20 07:29:17.823787 2026] [security2:error] [pid 145170:tid 145326] [client 191.202.66.27:64633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4irTjs5KUa9I09SwTz2wAAAJw"]
[Mon Jul 20 07:29:17.835343 2026] [security2:error] [pid 148765:tid 149016] [client 57.141.18.33:50032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irTv8fXmqCm8fNeqQZQABf1g"]
[Mon Jul 20 07:29:17.840895 2026] [security2:error] [pid 148765:tid 148954] [client 114.119.154.113:61905] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "reosportsboats.com"] [uri "/robots.txt"] [unique_id "al4irTv8fXmqCm8fNeqQlgAAAUE"], referer: https://reosportsboats.com/robots.txt
[Mon Jul 20 07:29:18.045791 2026] [security2:error] [pid 148765:tid 148966] [client 14.225.17.146:56896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4irTv8fXmqCm8fNeqQmQAAAU0"]
[Mon Jul 20 07:29:18.457708 2026] [security2:error] [pid 148765:tid 148953] [client 179.127.84.238:49885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQuAAAAUA"]
[Mon Jul 20 07:29:18.457921 2026] [security2:error] [pid 148765:tid 148953] [client 179.127.84.238:49885] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQuAAAAUA"]
[Mon Jul 20 07:29:18.491170 2026] [security2:error] [pid 145170:tid 145327] [client 57.141.18.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4irjjs5KUa9I09SwTz5wAAAJ0"]
[Mon Jul 20 07:29:18.532822 2026] [security2:error] [pid 145170:tid 145358] [client 57.141.18.53:49366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irTjs5KUa9I09SwTz3AAAvAg"]
[Mon Jul 20 07:29:18.816967 2026] [security2:error] [pid 148765:tid 148903] [client 88.241.67.160:53568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQ2QAAAQ4"]
[Mon Jul 20 07:29:18.817349 2026] [security2:error] [pid 148765:tid 148903] [client 88.241.67.160:53568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQ2QAAAQ4"]
[Mon Jul 20 07:29:18.827691 2026] [security2:error] [pid 148765:tid 148861] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQ2wABdVs"]
[Mon Jul 20 07:29:18.827915 2026] [security2:error] [pid 148765:tid 149006] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQ2wABdVs"]
[Mon Jul 20 07:29:18.831524 2026] [security2:error] [pid 145170:tid 145292] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4irjjs5KUa9I09SwT0AQAA-HY"]
[Mon Jul 20 07:29:18.831664 2026] [security2:error] [pid 145170:tid 145418] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4irjjs5KUa9I09SwT0AQAA-HY"]
[Mon Jul 20 07:29:18.927489 2026] [security2:error] [pid 145170:tid 145328] [client 57.141.18.42:45154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irjjs5KUa9I09SwTz4wAAniE"]
[Mon Jul 20 07:29:18.993410 2026] [security2:error] [pid 148765:tid 148985] [client 3.78.190.80:23776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4irjv8fXmqCm8fNeqQowAAAWA"]
[Mon Jul 20 07:29:19.227690 2026] [security2:error] [pid 148765:tid 148998] [client 157.20.138.62:50887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4irzv8fXmqCm8fNeqQ8wAAAW0"]
[Mon Jul 20 07:29:19.227849 2026] [security2:error] [pid 148765:tid 148998] [client 157.20.138.62:50887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4irzv8fXmqCm8fNeqQ8wAAAW0"]
[Mon Jul 20 07:29:19.247899 2026] [security2:error] [pid 148765:tid 148950] [client 14.225.17.146:62001] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4irzv8fXmqCm8fNeqQ8AAAAT0"], referer: http://grndl.com/Test
[Mon Jul 20 07:29:19.375913 2026] [security2:error] [pid 145170:tid 145400] [client 57.141.18.90:58612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irjjs5KUa9I09SwTz9wAA5gM"]
[Mon Jul 20 07:29:19.520727 2026] [security2:error] [pid 148765:tid 148912] [client 213.230.78.251:53970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marscafe.com"] [uri "/php/stocks/stocks_results.php3"] [unique_id "al4irzv8fXmqCm8fNeqRAwAAARc"]
[Mon Jul 20 07:29:19.658195 2026] [security2:error] [pid 145170:tid 145348] [client 4.194.24.143:1090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/nine2code.php"] [unique_id "al4irzjs5KUa9I09SwT0DwAAALI"]
[Mon Jul 20 07:29:19.838853 2026] [security2:error] [pid 148765:tid 148982] [client 14.225.17.146:62017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4irzv8fXmqCm8fNeqREwAAAV0"], referer: http://momheadquarters.com/Test
[Mon Jul 20 07:29:20.192909 2026] [security2:error] [pid 145170:tid 145413] [client 104.234.53.71:41601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4isDjs5KUa9I09SwT0IgAAAPM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:20.225877 2026] [security2:error] [pid 148765:tid 148967] [client 4.194.24.143:1926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/num.php"] [unique_id "al4isDv8fXmqCm8fNeqRPgAAAU4"]
[Mon Jul 20 07:29:20.509318 2026] [security2:error] [pid 145170:tid 145414] [client 57.141.18.86:30112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irzjs5KUa9I09SwT0CQAA9Fo"]
[Mon Jul 20 07:29:20.769646 2026] [security2:error] [pid 148765:tid 148981] [client 4.194.24.143:22208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/odf7udtspqtpxzyxmw2rccdefault.php"] [unique_id "al4isDv8fXmqCm8fNeqRYQAAAVw"]
[Mon Jul 20 07:29:20.778330 2026] [security2:error] [pid 148765:tid 148970] [client 49.47.218.174:49762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4isDv8fXmqCm8fNeqRYgAAAVE"]
[Mon Jul 20 07:29:20.778408 2026] [security2:error] [pid 148765:tid 148970] [client 49.47.218.174:49762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4isDv8fXmqCm8fNeqRYgAAAVE"]
[Mon Jul 20 07:29:20.792147 2026] [security2:error] [pid 148765:tid 148940] [client 57.141.18.76:51292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4irzv8fXmqCm8fNeqRGgABM1o"]
[Mon Jul 20 07:29:21.014736 2026] [security2:error] [pid 148765:tid 148921] [client 57.141.18.48:33378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4isDv8fXmqCm8fNeqRLQABIAE"]
[Mon Jul 20 07:29:21.077782 2026] [security2:error] [pid 148765:tid 148820] [remote 20.153.140.50:39902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4isTv8fXmqCm8fNeqRdgABODI"]
[Mon Jul 20 07:29:21.078005 2026] [security2:error] [pid 148765:tid 148945] [client 20.153.140.50:39902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4isTv8fXmqCm8fNeqRdgABODI"]
[Mon Jul 20 07:29:21.212874 2026] [security2:error] [pid 148765:tid 148996] [client 14.225.17.146:50155] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4isDv8fXmqCm8fNeqRbgAAAWs"], referer: http://maxenengineering.com/Test
[Mon Jul 20 07:29:21.321563 2026] [security2:error] [pid 148765:tid 148978] [client 4.194.24.143:1922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/option.php"] [unique_id "al4isTv8fXmqCm8fNeqRiQAAAVk"]
[Mon Jul 20 07:29:21.566410 2026] [security2:error] [pid 145170:tid 145328] [client 119.154.52.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4isTjs5KUa9I09SwT0TwAAAJ4"]
[Mon Jul 20 07:29:21.636492 2026] [security2:error] [pid 148765:tid 148963] [client 154.192.123.127:18745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4isTv8fXmqCm8fNeqRoAAAAUo"]
[Mon Jul 20 07:29:21.636651 2026] [security2:error] [pid 148765:tid 148963] [client 154.192.123.127:18745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4isTv8fXmqCm8fNeqRoAAAAUo"]
[Mon Jul 20 07:29:21.702488 2026] [security2:error] [pid 148765:tid 148902] [client 114.119.146.37:35375] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thecreole.com"] [uri "/"] [unique_id "al4isTv8fXmqCm8fNeqRqgAAAQ0"], referer: https://newstral.com/en/article/en/1006427493/furniture-company-names-president
[Mon Jul 20 07:29:21.831984 2026] [security2:error] [pid 148765:tid 149018] [client 14.225.17.146:61624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4isTv8fXmqCm8fNeqRrgAAAYE"], referer: http://adultdaycarereno.com/Test
[Mon Jul 20 07:29:21.876016 2026] [security2:error] [pid 148765:tid 148957] [client 4.194.24.143:1092] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/p.php"] [unique_id "al4isTv8fXmqCm8fNeqRuAAAAUQ"]
[Mon Jul 20 07:29:21.965305 2026] [security2:error] [pid 148765:tid 148814] [remote 103.173.227.188:34628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.227.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4isTv8fXmqCm8fNeqRuwABhSw"]
[Mon Jul 20 07:29:22.099150 2026] [security2:error] [pid 148765:tid 148858] [remote 208.76.40.156:36210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.40.76.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4isjv8fXmqCm8fNeqRwQABaVg"]
[Mon Jul 20 07:29:22.123869 2026] [security2:error] [pid 148765:tid 148985] [client 14.251.3.155:56056] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4isjv8fXmqCm8fNeqRwwAAAWA"]
[Mon Jul 20 07:29:22.209223 2026] [security2:error] [pid 148765:tid 148977] [client 14.225.17.146:61960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4isjv8fXmqCm8fNeqRwAAAAVg"], referer: https://maxenengineering.com/Test
[Mon Jul 20 07:29:22.249112 2026] [security2:error] [pid 145170:tid 145315] [client 50.116.65.227:30246] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4isjjs5KUa9I09SwT0ZQAAAJE"]
[Mon Jul 20 07:29:22.261671 2026] [security2:error] [pid 145170:tid 145320] [client 50.116.65.227:30256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4isjjs5KUa9I09SwT0ZgAAAJY"]
[Mon Jul 20 07:29:22.376178 2026] [security2:error] [pid 148765:tid 148827] [remote 103.173.227.188:34628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 188.227.173.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4isjv8fXmqCm8fNeqR0QABMzk"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:29:22.430549 2026] [security2:error] [pid 145170:tid 145403] [client 4.194.24.143:1952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/past.php"] [unique_id "al4isjjs5KUa9I09SwT0agAAAOk"]
[Mon Jul 20 07:29:22.484235 2026] [security2:error] [pid 148765:tid 148844] [remote 208.76.40.156:36210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.40.76.208.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4isjv8fXmqCm8fNeqR2wABP0o"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:29:22.503146 2026] [security2:error] [pid 148765:tid 148949] [client 36.93.152.155:61325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4isjv8fXmqCm8fNeqR4QAAATw"]
[Mon Jul 20 07:29:22.503237 2026] [security2:error] [pid 148765:tid 148949] [client 36.93.152.155:61325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4isjv8fXmqCm8fNeqR4QAAATw"]
[Mon Jul 20 07:29:22.755508 2026] [security2:error] [pid 145170:tid 145330] [client 52.233.165.60:22082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4isjjs5KUa9I09SwT0cgAAAKA"]
[Mon Jul 20 07:29:22.757777 2026] [security2:error] [pid 148765:tid 148926] [client 14.225.17.146:61589] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4isjv8fXmqCm8fNeqR7wAAASU"], referer: https://adultdaycarereno.com/Test
[Mon Jul 20 07:29:22.812864 2026] [security2:error] [pid 145170:tid 145331] [client 57.141.18.11:24524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4isTjs5KUa9I09SwT0VAAAoVw"]
[Mon Jul 20 07:29:22.916036 2026] [security2:error] [pid 145170:tid 145365] [client 52.233.165.60:22082] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4isjjs5KUa9I09SwT0eAAAAMM"]
[Mon Jul 20 07:29:22.973927 2026] [security2:error] [pid 145170:tid 145422] [client 4.194.24.143:22258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/php.php"] [unique_id "al4isjjs5KUa9I09SwT0egAAAPw"]
[Mon Jul 20 07:29:23.000841 2026] [security2:error] [pid 148765:tid 148862] [remote 57.141.18.60:29760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5777476"] [unique_id "al4isjv8fXmqCm8fNeqSAwABTFw"]
[Mon Jul 20 07:29:23.073282 2026] [security2:error] [pid 148765:tid 149006] [client 143.44.185.218:8474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSCAAAAXU"]
[Mon Jul 20 07:29:23.073376 2026] [security2:error] [pid 148765:tid 149006] [client 143.44.185.218:8474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSCAAAAXU"]
[Mon Jul 20 07:29:23.078611 2026] [security2:error] [pid 148765:tid 148948] [client 52.109.16.52:7361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4iszv8fXmqCm8fNeqSBwAAATs"]
[Mon Jul 20 07:29:23.082783 2026] [security2:error] [pid 148765:tid 149007] [client 57.141.18.74:21494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4isTv8fXmqCm8fNeqRtgABdkM"]
[Mon Jul 20 07:29:23.132912 2026] [security2:error] [pid 148765:tid 148937] [client 52.109.16.52:7361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4iszv8fXmqCm8fNeqSCgAAATA"]
[Mon Jul 20 07:29:23.279086 2026] [security2:error] [pid 145170:tid 145347] [client 104.234.53.89:28983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iszjs5KUa9I09SwT0iAAAALE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:23.301259 2026] [security2:error] [pid 148765:tid 148955] [client 14.225.17.146:57663] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4iszv8fXmqCm8fNeqSDQAAAUI"], referer: https://north-woods-engineering.com/Test
[Mon Jul 20 07:29:23.308913 2026] [security2:error] [pid 148765:tid 148913] [client 201.27.111.74:55599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSHAAAARg"]
[Mon Jul 20 07:29:23.309012 2026] [security2:error] [pid 148765:tid 148913] [client 201.27.111.74:55599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSHAAAARg"]
[Mon Jul 20 07:29:23.343698 2026] [security2:error] [pid 145170:tid 145392] [client 14.225.17.146:57722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4iszjs5KUa9I09SwT0hgAAAN4"], referer: http://thefriendlyspreadsheet.com/Test
[Mon Jul 20 07:29:23.410538 2026] [security2:error] [pid 148765:tid 148929] [client 103.176.215.66:54414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSJgAAASg"]
[Mon Jul 20 07:29:23.410925 2026] [security2:error] [pid 148765:tid 148929] [client 103.176.215.66:54414] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSJgAAASg"]
[Mon Jul 20 07:29:23.474359 2026] [security2:error] [pid 148765:tid 148972] [client 14.225.17.146:61655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4isTv8fXmqCm8fNeqRsAAAAVM"], referer: http://superiorcopywriting.com/Test
[Mon Jul 20 07:29:23.520387 2026] [security2:error] [pid 145170:tid 145426] [client 4.194.24.143:22241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/php8.php"] [unique_id "al4iszjs5KUa9I09SwT0kAAAAQA"]
[Mon Jul 20 07:29:23.586123 2026] [security2:error] [pid 148765:tid 148903] [client 57.141.18.71:22672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4isjv8fXmqCm8fNeqR2QABDmc"]
[Mon Jul 20 07:29:23.614308 2026] [security2:error] [pid 148765:tid 148954] [client 117.211.236.168:61505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSNgAAAUE"]
[Mon Jul 20 07:29:23.614394 2026] [security2:error] [pid 148765:tid 148954] [client 117.211.236.168:61505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSNgAAAUE"]
[Mon Jul 20 07:29:23.822759 2026] [security2:error] [pid 148765:tid 148975] [client 57.141.18.37:32152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4isjv8fXmqCm8fNeqR7AABVnI"]
[Mon Jul 20 07:29:23.871550 2026] [security2:error] [pid 148765:tid 148947] [client 103.106.165.44:51362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSQAAAATo"]
[Mon Jul 20 07:29:23.871681 2026] [security2:error] [pid 148765:tid 148947] [client 103.106.165.44:51362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iszv8fXmqCm8fNeqSQAAAATo"]
[Mon Jul 20 07:29:24.087400 2026] [security2:error] [pid 148765:tid 148944] [client 14.225.17.146:61893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4itDv8fXmqCm8fNeqSRgAAATc"], referer: http://walkingandtalking.net/Test
[Mon Jul 20 07:29:24.118794 2026] [security2:error] [pid 148765:tid 148945] [client 4.194.24.143:22261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/phpinfo.php"] [unique_id "al4itDv8fXmqCm8fNeqSSwAAATg"]
[Mon Jul 20 07:29:24.175616 2026] [security2:error] [pid 148765:tid 149003] [client 45.205.1.223:57310] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "boracayhaven.com.ph"] [uri "/400.shtml"] [unique_id "al4itDv8fXmqCm8fNeqSTgAAAXI"]
[Mon Jul 20 07:29:24.465459 2026] [security2:error] [pid 148765:tid 148958] [client 104.234.53.85:62243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4itDv8fXmqCm8fNeqSZgAAAUU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:24.567377 2026] [security2:error] [pid 148765:tid 148937] [client 144.16.21.149:28362] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4itDv8fXmqCm8fNeqSYQAAATA"]
[Mon Jul 20 07:29:24.947912 2026] [security2:error] [pid 148765:tid 148931] [client 14.225.17.146:65385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4itDv8fXmqCm8fNeqShAAAASo"], referer: https://walkingandtalking.net/Test
[Mon Jul 20 07:29:25.032830 2026] [security2:error] [pid 145170:tid 145333] [client 4.194.24.143:14246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/post.php"] [unique_id "al4itTjs5KUa9I09SwT0twAAAKM"]
[Mon Jul 20 07:29:25.133992 2026] [security2:error] [pid 148765:tid 148788] [remote 45.150.79.142:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4itTv8fXmqCm8fNeqSlwABhRI"]
[Mon Jul 20 07:29:25.258369 2026] [security2:error] [pid 145170:tid 145345] [client 49.37.242.14:60409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4itTjs5KUa9I09SwT0vwAAAK8"]
[Mon Jul 20 07:29:25.258513 2026] [security2:error] [pid 145170:tid 145345] [client 49.37.242.14:60409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4itTjs5KUa9I09SwT0vwAAAK8"]
[Mon Jul 20 07:29:25.297420 2026] [security2:error] [pid 148765:tid 148886] [remote 45.150.79.142:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4itTv8fXmqCm8fNeqSoQABGnQ"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:29:25.574669 2026] [security2:error] [pid 148765:tid 148893] [remote 152.228.213.32:46340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4itTv8fXmqCm8fNeqSswABO3s"]
[Mon Jul 20 07:29:25.599873 2026] [security2:error] [pid 145170:tid 145204] [remote 47.86.33.52:21396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4itTjs5KUa9I09SwT02wAA6R4"]
[Mon Jul 20 07:29:25.774463 2026] [security2:error] [pid 145170:tid 145366] [client 17.246.19.214:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4itTjs5KUa9I09SwT03AAAAMQ"]
[Mon Jul 20 07:29:25.787533 2026] [security2:error] [pid 148765:tid 148801] [remote 152.228.213.32:46340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4itTv8fXmqCm8fNeqSwgABFh8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:29:25.834509 2026] [security2:error] [pid 145170:tid 145352] [client 4.194.24.143:1962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/public/assets/design_1/css/parts/course_cards/grid_card_1.min.php"] [unique_id "al4itTjs5KUa9I09SwT04wAAALY"]
[Mon Jul 20 07:29:25.876724 2026] [security2:error] [pid 148765:tid 148977] [client 45.238.123.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4itDv8fXmqCm8fNeqScQAAAVg"]
[Mon Jul 20 07:29:26.268955 2026] [security2:error] [pid 145170:tid 145229] [remote 47.86.33.52:21396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4itjjs5KUa9I09SwT07gAAzzc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:29:26.305760 2026] [security2:error] [pid 145170:tid 145334] [client 57.141.18.32:47212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4itTjs5KUa9I09SwT0uwAApEc"]
[Mon Jul 20 07:29:26.749146 2026] [security2:error] [pid 148765:tid 149009] [client 45.205.1.223:57322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "boracayhaven.com.ph"] [uri "/400.shtml"] [unique_id "al4itjv8fXmqCm8fNeqS_wAAAXg"]
[Mon Jul 20 07:29:26.776007 2026] [security2:error] [pid 145170:tid 145318] [client 4.194.24.143:1951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/public/css.php"] [unique_id "al4itjjs5KUa9I09SwT0-wAAAJQ"]
[Mon Jul 20 07:29:26.778796 2026] [security2:error] [pid 145170:tid 145361] [client 136.158.60.21:61741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4itjjs5KUa9I09SwT0_QAAAL8"]
[Mon Jul 20 07:29:26.778883 2026] [security2:error] [pid 145170:tid 145361] [client 136.158.60.21:61741] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4itjjs5KUa9I09SwT0_QAAAL8"]
[Mon Jul 20 07:29:26.957549 2026] [security2:error] [pid 148765:tid 148947] [client 43.205.139.3:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4itjv8fXmqCm8fNeqTDwAAATo"]
[Mon Jul 20 07:29:27.043190 2026] [security2:error] [pid 148765:tid 148958] [client 138.185.145.78:47980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/xmlrpc.php"] [unique_id "al4itjv8fXmqCm8fNeqTEwAAAUU"]
[Mon Jul 20 07:29:27.043320 2026] [security2:error] [pid 148765:tid 148958] [client 138.185.145.78:47980] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/xmlrpc.php"] [unique_id "al4itjv8fXmqCm8fNeqTEwAAAUU"]
[Mon Jul 20 07:29:27.108957 2026] [security2:error] [pid 148765:tid 149008] [client 14.225.17.146:61642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4itzv8fXmqCm8fNeqTGQAAAXc"], referer: http://retzkolonglogistics.com/Test
[Mon Jul 20 07:29:27.290100 2026] [security2:error] [pid 148765:tid 148943] [client 138.185.145.78:48150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/xmlrpc.php"] [unique_id "al4itzv8fXmqCm8fNeqTKwAAATY"]
[Mon Jul 20 07:29:27.290316 2026] [security2:error] [pid 148765:tid 148943] [client 138.185.145.78:48150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/xmlrpc.php"] [unique_id "al4itzv8fXmqCm8fNeqTKwAAATY"]
[Mon Jul 20 07:29:27.363226 2026] [security2:error] [pid 148765:tid 148971] [client 57.141.18.4:64570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4itTv8fXmqCm8fNeqS0QABUi0"]
[Mon Jul 20 07:29:27.492542 2026] [security2:error] [pid 148765:tid 148946] [client 14.225.17.146:50414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4itzv8fXmqCm8fNeqTMgAAATk"], referer: http://bigwormfishing.com/Test
[Mon Jul 20 07:29:27.626115 2026] [security2:error] [pid 148765:tid 148907] [client 155.2.215.69:44789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.215.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4itzv8fXmqCm8fNeqTQwAAARI"]
[Mon Jul 20 07:29:27.626247 2026] [security2:error] [pid 148765:tid 148907] [client 155.2.215.69:44789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4itzv8fXmqCm8fNeqTQwAAARI"]
[Mon Jul 20 07:29:27.629310 2026] [security2:error] [pid 148765:tid 148999] [client 4.194.24.143:22216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/r.php"] [unique_id "al4itzv8fXmqCm8fNeqTSQAAAW4"]
[Mon Jul 20 07:29:27.671789 2026] [security2:error] [pid 145170:tid 145410] [client 104.234.53.72:33675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4itzjs5KUa9I09SwT1EQAAAPA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:27.866378 2026] [security2:error] [pid 148765:tid 149026] [client 125.209.97.230:59847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4itzv8fXmqCm8fNeqTWAAAAYk"]
[Mon Jul 20 07:29:27.866480 2026] [security2:error] [pid 148765:tid 149026] [client 125.209.97.230:59847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4itzv8fXmqCm8fNeqTWAAAAYk"]
[Mon Jul 20 07:29:27.960541 2026] [security2:error] [pid 145170:tid 145398] [client 43.205.139.3:33922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4itzjs5KUa9I09SwT1HgAAAOQ"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:29:28.027409 2026] [security2:error] [pid 148765:tid 148992] [client 138.185.145.78:48322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4iuDv8fXmqCm8fNeqTXwAAAWc"]
[Mon Jul 20 07:29:28.027537 2026] [security2:error] [pid 148765:tid 148992] [client 138.185.145.78:48322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4iuDv8fXmqCm8fNeqTXwAAAWc"]
[Mon Jul 20 07:29:28.110823 2026] [security2:error] [pid 148765:tid 148899] [client 57.141.18.35:24364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4itjv8fXmqCm8fNeqTAAABCjg"]
[Mon Jul 20 07:29:28.231096 2026] [security2:error] [pid 145170:tid 145395] [client 4.194.24.143:22504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/radio.php"] [unique_id "al4iuDjs5KUa9I09SwT1LQAAAOE"]
[Mon Jul 20 07:29:28.283459 2026] [security2:error] [pid 145170:tid 145387] [client 138.185.145.78:48770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4iuDjs5KUa9I09SwT1MAAAANk"]
[Mon Jul 20 07:29:28.283570 2026] [security2:error] [pid 145170:tid 145387] [client 138.185.145.78:48770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4iuDjs5KUa9I09SwT1MAAAANk"]
[Mon Jul 20 07:29:28.293105 2026] [security2:error] [pid 148765:tid 148910] [client 14.225.17.146:49837] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4iuDv8fXmqCm8fNeqTagAAARU"], referer: http://ncsynchro.com/Test
[Mon Jul 20 07:29:28.508886 2026] [security2:error] [pid 145170:tid 145309] [client 191.202.66.27:65125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iuDjs5KUa9I09SwT1NwAAAIs"]
[Mon Jul 20 07:29:28.509014 2026] [security2:error] [pid 145170:tid 145309] [client 191.202.66.27:65125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iuDjs5KUa9I09SwT1NwAAAIs"]
[Mon Jul 20 07:29:28.550084 2026] [security2:error] [pid 148765:tid 148954] [client 138.185.145.78:48948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4iuDv8fXmqCm8fNeqTfwAAAUE"]
[Mon Jul 20 07:29:28.550209 2026] [security2:error] [pid 148765:tid 148954] [client 138.185.145.78:48948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4iuDv8fXmqCm8fNeqTfwAAAUE"]
[Mon Jul 20 07:29:28.560738 2026] [security2:error] [pid 148765:tid 149004] [client 14.225.17.146:61276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4iuDv8fXmqCm8fNeqTdgAAAXM"], referer: https://bigwormfishing.com/Test
[Mon Jul 20 07:29:28.711467 2026] [security2:error] [pid 145170:tid 145358] [client 63.176.132.15:62542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iuDjs5KUa9I09SwT1QAAAALw"]
[Mon Jul 20 07:29:28.711607 2026] [security2:error] [pid 145170:tid 145358] [client 63.176.132.15:62542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iuDjs5KUa9I09SwT1QAAAALw"]
[Mon Jul 20 07:29:28.777657 2026] [security2:error] [pid 148765:tid 148926] [client 57.141.18.43:48610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4itzv8fXmqCm8fNeqTLgABJSg"]
[Mon Jul 20 07:29:28.794993 2026] [security2:error] [pid 148765:tid 148992] [client 138.185.145.78:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/news/xmlrpc.php"] [unique_id "al4iuDv8fXmqCm8fNeqTjwAAAWc"]
[Mon Jul 20 07:29:28.795084 2026] [security2:error] [pid 148765:tid 148992] [client 138.185.145.78:49116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/news/xmlrpc.php"] [unique_id "al4iuDv8fXmqCm8fNeqTjwAAAWc"]
[Mon Jul 20 07:29:28.998017 2026] [security2:error] [pid 148765:tid 148928] [client 4.194.24.143:22558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/randkeyword.php7"] [unique_id "al4iuDv8fXmqCm8fNeqTnAAAASc"]
[Mon Jul 20 07:29:29.039886 2026] [security2:error] [pid 145170:tid 145373] [client 138.185.145.78:49302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/web/xmlrpc.php"] [unique_id "al4iuTjs5KUa9I09SwT1SgAAAMs"]
[Mon Jul 20 07:29:29.040027 2026] [security2:error] [pid 145170:tid 145373] [client 138.185.145.78:49302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/web/xmlrpc.php"] [unique_id "al4iuTjs5KUa9I09SwT1SgAAAMs"]
[Mon Jul 20 07:29:29.057282 2026] [security2:error] [pid 148765:tid 148996] [client 179.127.84.238:50396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTnwAAAWs"]
[Mon Jul 20 07:29:29.057378 2026] [security2:error] [pid 148765:tid 148996] [client 179.127.84.238:50396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTnwAAAWs"]
[Mon Jul 20 07:29:29.188036 2026] [security2:error] [pid 145170:tid 145385] [client 57.141.18.61:63282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4itzjs5KUa9I09SwT1FgAA13k"]
[Mon Jul 20 07:29:29.240292 2026] [security2:error] [pid 148765:tid 148995] [client 14.225.17.146:65322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4iuTv8fXmqCm8fNeqTowAAAWo"], referer: http://alaraycreative.com/Test
[Mon Jul 20 07:29:29.284490 2026] [security2:error] [pid 148765:tid 148956] [client 138.185.145.78:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/main/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTqwAAAUM"]
[Mon Jul 20 07:29:29.284611 2026] [security2:error] [pid 148765:tid 148956] [client 138.185.145.78:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/main/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTqwAAAUM"]
[Mon Jul 20 07:29:29.438569 2026] [security2:error] [pid 148765:tid 149013] [client 14.225.17.146:52355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4iuTv8fXmqCm8fNeqTsAAAAXw"], referer: http://mourgroup.com/Test
[Mon Jul 20 07:29:29.481869 2026] [security2:error] [pid 148765:tid 148871] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtQABLmU"]
[Mon Jul 20 07:29:29.482018 2026] [security2:error] [pid 148765:tid 148935] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtQABLmU"]
[Mon Jul 20 07:29:29.496360 2026] [security2:error] [pid 148765:tid 148967] [client 88.241.67.160:53568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtgAAAU4"]
[Mon Jul 20 07:29:29.496491 2026] [security2:error] [pid 148765:tid 148967] [client 88.241.67.160:53568] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtgAAAU4"]
[Mon Jul 20 07:29:29.530172 2026] [security2:error] [pid 148765:tid 148997] [client 138.185.145.78:49616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtwAAAWw"]
[Mon Jul 20 07:29:29.530305 2026] [security2:error] [pid 148765:tid 148997] [client 138.185.145.78:49616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtwAAAWw"]
[Mon Jul 20 07:29:29.607562 2026] [security2:error] [pid 145170:tid 145320] [client 74.208.214.194:45294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4iuTjs5KUa9I09SwT1ZgAAAJY"]
[Mon Jul 20 07:29:29.607574 2026] [security2:error] [pid 145170:tid 145367] [client 4.194.24.143:22492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/readme.php"] [unique_id "al4iuTjs5KUa9I09SwT1ZwAAAMU"]
[Mon Jul 20 07:29:29.757573 2026] [security2:error] [pid 148765:tid 148987] [client 157.20.138.62:51453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTygAAAWI"]
[Mon Jul 20 07:29:29.757673 2026] [security2:error] [pid 148765:tid 148987] [client 157.20.138.62:51453] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTygAAAWI"]
[Mon Jul 20 07:29:29.762303 2026] [security2:error] [pid 148765:tid 148939] [client 57.141.18.8:53386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iuDv8fXmqCm8fNeqTaQABMiU"]
[Mon Jul 20 07:29:29.788227 2026] [security2:error] [pid 148765:tid 148906] [client 138.185.145.78:49770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTzAAAARE"]
[Mon Jul 20 07:29:29.788323 2026] [security2:error] [pid 148765:tid 148906] [client 138.185.145.78:49770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqTzAAAARE"]
[Mon Jul 20 07:29:30.044274 2026] [security2:error] [pid 148765:tid 149019] [client 138.185.145.78:49940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/new/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqT3QAAAYI"]
[Mon Jul 20 07:29:30.044378 2026] [security2:error] [pid 148765:tid 149019] [client 138.185.145.78:49940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/new/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqT3QAAAYI"]
[Mon Jul 20 07:29:30.186240 2026] [security2:error] [pid 148765:tid 148777] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqT5wABGQc"]
[Mon Jul 20 07:29:30.186399 2026] [security2:error] [pid 148765:tid 148914] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqT5wABGQc"]
[Mon Jul 20 07:29:30.246152 2026] [security2:error] [pid 148765:tid 149008] [client 4.194.24.143:1942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/reze.php"] [unique_id "al4iujv8fXmqCm8fNeqT7AAAAXc"]
[Mon Jul 20 07:29:30.504760 2026] [security2:error] [pid 148765:tid 148933] [client 3.78.190.80:20250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iuTv8fXmqCm8fNeqT2gAAASw"]
[Mon Jul 20 07:29:30.553266 2026] [security2:error] [pid 148765:tid 148904] [client 138.185.145.78:59474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqT_gAAAQ8"]
[Mon Jul 20 07:29:30.553371 2026] [security2:error] [pid 148765:tid 148904] [client 138.185.145.78:59474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "box5033.bluehost.com"] [uri "/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqT_gAAAQ8"]
[Mon Jul 20 07:29:30.557409 2026] [security2:error] [pid 148765:tid 148775] [remote 173.249.4.11:60609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4iujv8fXmqCm8fNeqT_wABJAU"]
[Mon Jul 20 07:29:30.681508 2026] [security2:error] [pid 148765:tid 148984] [client 138.185.145.78:50104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.145.185.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "box5033.bluehost.com"] [uri "/wp-login.php"] [unique_id "al4iujv8fXmqCm8fNeqUAwAAAV8"]
[Mon Jul 20 07:29:30.702883 2026] [security2:error] [pid 145170:tid 145421] [client 57.141.18.11:43216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iuTjs5KUa9I09SwT1UAAA-1E"]
[Mon Jul 20 07:29:30.730448 2026] [security2:error] [pid 148765:tid 148870] [remote 47.86.33.52:46240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4iujv8fXmqCm8fNeqUBwABPmQ"]
[Mon Jul 20 07:29:30.760457 2026] [security2:error] [pid 148765:tid 148886] [remote 173.249.4.11:60609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/wp-login.php"] [unique_id "al4iujv8fXmqCm8fNeqUDQABIXQ"], referer: https://reosportsboats.com/wp-login.php
[Mon Jul 20 07:29:30.799353 2026] [security2:error] [pid 148765:tid 148917] [client 202.141.11.99:58157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqUDwAAARw"]
[Mon Jul 20 07:29:30.799448 2026] [security2:error] [pid 148765:tid 148917] [client 202.141.11.99:58157] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4iujv8fXmqCm8fNeqUDwAAARw"]
[Mon Jul 20 07:29:30.861098 2026] [security2:error] [pid 145170:tid 145328] [client 14.225.17.146:65006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4iuTjs5KUa9I09SwT1YQAAAJ4"], referer: http://709fx.com/Test
[Mon Jul 20 07:29:30.862071 2026] [security2:error] [pid 145170:tid 145357] [client 4.194.24.143:18443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/rh.php"] [unique_id "al4iujjs5KUa9I09SwT1jAAAALs"]
[Mon Jul 20 07:29:31.151793 2026] [security2:error] [pid 148765:tid 149017] [client 66.249.64.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.indiraskitchenllc.com"] [uri "/index.php"] [unique_id "al4iuTv8fXmqCm8fNeqTywAAAYA"]
[Mon Jul 20 07:29:31.174206 2026] [security2:error] [pid 148765:tid 148964] [client 14.225.17.146:50040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4iuTv8fXmqCm8fNeqTtAAAAUs"], referer: http://according2plant.com/Test
[Mon Jul 20 07:29:31.207652 2026] [security2:error] [pid 148765:tid 148958] [client 14.225.17.146:50101] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4iuzv8fXmqCm8fNeqUKAAAAUU"], referer: http://alchemygroup.ca/Test
[Mon Jul 20 07:29:31.282450 2026] [security2:error] [pid 148765:tid 148941] [client 49.47.218.174:50307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iuzv8fXmqCm8fNeqUNgAAATQ"]
[Mon Jul 20 07:29:31.282564 2026] [security2:error] [pid 148765:tid 148941] [client 49.47.218.174:50307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4iuzv8fXmqCm8fNeqUNgAAATQ"]
[Mon Jul 20 07:29:31.336543 2026] [security2:error] [pid 148765:tid 149013] [client 117.211.236.168:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iuzv8fXmqCm8fNeqUPQAAAXw"]
[Mon Jul 20 07:29:31.336633 2026] [security2:error] [pid 148765:tid 149013] [client 117.211.236.168:61970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iuzv8fXmqCm8fNeqUPQAAAXw"]
[Mon Jul 20 07:29:31.354620 2026] [security2:error] [pid 148765:tid 148882] [remote 47.86.33.52:46240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4iuzv8fXmqCm8fNeqUPwABbXA"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:29:31.415614 2026] [security2:error] [pid 148765:tid 148936] [client 14.225.17.146:50234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4iuzv8fXmqCm8fNeqUNwAAAS8"], referer: http://bbwipartnerconference.com/Test
[Mon Jul 20 07:29:31.544803 2026] [security2:error] [pid 148765:tid 148954] [client 14.225.17.146:50249] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4iuzv8fXmqCm8fNeqUQAAAAUE"], referer: http://samdothan.org/Test
[Mon Jul 20 07:29:31.679322 2026] [security2:error] [pid 148765:tid 148915] [client 57.141.18.73:24536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iujv8fXmqCm8fNeqT4QABGg4"]
[Mon Jul 20 07:29:31.718201 2026] [security2:error] [pid 145170:tid 145417] [client 4.194.24.143:1957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/rip.php"] [unique_id "al4iuzjs5KUa9I09SwT1mwAAAPc"]
[Mon Jul 20 07:29:31.816994 2026] [security2:error] [pid 148765:tid 148773] [remote 45.90.123.233:56412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iuzv8fXmqCm8fNeqUXAABQwM"]
[Mon Jul 20 07:29:31.817189 2026] [security2:error] [pid 148765:tid 148956] [client 45.90.123.233:56412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iuzv8fXmqCm8fNeqUXAABQwM"]
[Mon Jul 20 07:29:32.100463 2026] [security2:error] [pid 145170:tid 145349] [client 154.192.123.127:17184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ivDjs5KUa9I09SwT1qwAAALM"]
[Mon Jul 20 07:29:32.100581 2026] [security2:error] [pid 145170:tid 145349] [client 154.192.123.127:17184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ivDjs5KUa9I09SwT1qwAAALM"]
[Mon Jul 20 07:29:32.198444 2026] [security2:error] [pid 148765:tid 148818] [remote 107.151.216.80:42858] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.windowtx.com"] [uri "/"] [unique_id "al4ivDv8fXmqCm8fNeqUbQABMjA"]
[Mon Jul 20 07:29:32.297140 2026] [security2:error] [pid 148765:tid 149012] [client 57.141.18.91:55904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iujv8fXmqCm8fNeqUBQABe1E"]
[Mon Jul 20 07:29:32.524120 2026] [security2:error] [pid 148765:tid 148992] [client 104.234.53.57:23067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ivDv8fXmqCm8fNeqUhgAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:32.566852 2026] [security2:error] [pid 148765:tid 148879] [remote 72.167.132.114:36986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ivDv8fXmqCm8fNeqUiQABhm0"]
[Mon Jul 20 07:29:32.567004 2026] [security2:error] [pid 148765:tid 149023] [client 72.167.132.114:36986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ivDv8fXmqCm8fNeqUiQABhm0"]
[Mon Jul 20 07:29:32.786286 2026] [security2:error] [pid 148765:tid 149004] [client 4.194.24.143:22477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/root.php"] [unique_id "al4ivDv8fXmqCm8fNeqUmQAAAXM"]
[Mon Jul 20 07:29:32.995474 2026] [security2:error] [pid 148765:tid 148924] [client 36.93.152.155:61843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ivDv8fXmqCm8fNeqUpwAAASM"]
[Mon Jul 20 07:29:32.995552 2026] [security2:error] [pid 148765:tid 148924] [client 36.93.152.155:61843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ivDv8fXmqCm8fNeqUpwAAASM"]
[Mon Jul 20 07:29:33.019033 2026] [core:error] [pid 148765:tid 148990] [client 3.18.186.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:33.019064 2026] [core:error] [pid 148765:tid 148990] [client 3.18.186.238:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:33.081356 2026] [security2:error] [pid 145170:tid 145321] [client 74.7.227.179:48964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ivDjs5KUa9I09SwT1vAAAlwc"], referer: https://tejasenvironmental.com/p=116597
[Mon Jul 20 07:29:33.098483 2026] [security2:error] [pid 148765:tid 148965] [client 14.225.17.146:65222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4ivDv8fXmqCm8fNeqUiwAAAUw"], referer: http://onewingpictures.com/Test
[Mon Jul 20 07:29:33.102375 2026] [autoindex:error] [pid 148765:tid 148813] [remote 8.229.41.77:55666] AH01276: Cannot serve directory /home2/tbdlhomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.tbd.lho.mybluehost.me
[Mon Jul 20 07:29:33.117522 2026] [security2:error] [pid 148765:tid 148955] [client 5.161.201.188:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "softpro-qa.com"] [uri "/wp-load.php"] [unique_id "al4ivTv8fXmqCm8fNeqUswAAAUI"], referer: http://softpro-qa.com/
[Mon Jul 20 07:29:33.296405 2026] [security2:error] [pid 148765:tid 149008] [client 74.208.214.194:45302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4ivTv8fXmqCm8fNeqUvwAAAXc"]
[Mon Jul 20 07:29:33.329341 2026] [security2:error] [pid 148765:tid 149013] [client 104.234.53.84:54547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ivTv8fXmqCm8fNeqUwwAAAXw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:33.555249 2026] [security2:error] [pid 145170:tid 145384] [client 57.141.18.12:55650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iuzjs5KUa9I09SwT1ngAA1m4"]
[Mon Jul 20 07:29:33.595544 2026] [security2:error] [pid 145170:tid 145371] [client 57.141.18.89:44104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iuzjs5KUa9I09SwT1owAAyXs"]
[Mon Jul 20 07:29:33.622015 2026] [security2:error] [pid 148765:tid 148993] [client 4.194.24.143:22245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/s.php"] [unique_id "al4ivTv8fXmqCm8fNeqU1QAAAWg"]
[Mon Jul 20 07:29:33.784806 2026] [security2:error] [pid 148765:tid 149021] [client 201.27.111.74:56112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ivTv8fXmqCm8fNeqU2gAAAYQ"]
[Mon Jul 20 07:29:33.784904 2026] [security2:error] [pid 148765:tid 149021] [client 201.27.111.74:56112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4ivTv8fXmqCm8fNeqU2gAAAYQ"]
[Mon Jul 20 07:29:34.031473 2026] [security2:error] [pid 148765:tid 148936] [client 103.176.215.66:54955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ivjv8fXmqCm8fNeqU8QAAAS8"]
[Mon Jul 20 07:29:34.032026 2026] [security2:error] [pid 148765:tid 148936] [client 103.176.215.66:54955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ivjv8fXmqCm8fNeqU8QAAAS8"]
[Mon Jul 20 07:29:34.104520 2026] [security2:error] [pid 148765:tid 148837] [remote 193.202.44.12:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.202.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4ivjv8fXmqCm8fNeqU9QABaUM"]
[Mon Jul 20 07:29:34.445717 2026] [security2:error] [pid 145170:tid 145348] [client 103.106.165.44:51847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ivjjs5KUa9I09SwT12QAAALI"]
[Mon Jul 20 07:29:34.445887 2026] [security2:error] [pid 145170:tid 145348] [client 103.106.165.44:51847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ivjjs5KUa9I09SwT12QAAALI"]
[Mon Jul 20 07:29:34.482260 2026] [security2:error] [pid 145170:tid 145427] [client 50.116.65.227:43234] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ivjjs5KUa9I09SwT12gAAAQE"]
[Mon Jul 20 07:29:34.483484 2026] [security2:error] [pid 148765:tid 149007] [client 4.194.24.143:1939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sang.php"] [unique_id "al4ivjv8fXmqCm8fNeqVDgAAAXY"]
[Mon Jul 20 07:29:34.486030 2026] [security2:error] [pid 145170:tid 145343] [client 57.141.18.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ivjjs5KUa9I09SwT11QAAAK0"]
[Mon Jul 20 07:29:34.492394 2026] [security2:error] [pid 145170:tid 145387] [client 50.116.65.227:43238] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ivjjs5KUa9I09SwT12wAAANk"]
[Mon Jul 20 07:29:34.503775 2026] [security2:error] [pid 148765:tid 148829] [remote 193.202.44.12:40300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.44.202.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4ivjv8fXmqCm8fNeqVDwABUzs"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 07:29:34.516058 2026] [security2:error] [pid 148765:tid 148982] [client 45.157.112.60:58499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ivjv8fXmqCm8fNeqVEgAAAV0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:29:34.663586 2026] [core:error] [pid 148765:tid 148903] [client 205.210.31.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:34.663631 2026] [core:error] [pid 148765:tid 148903] [client 205.210.31.44:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:34.730007 2026] [security2:error] [pid 148765:tid 148854] [remote 209.42.18.223:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4ivjv8fXmqCm8fNeqVIgABWFQ"]
[Mon Jul 20 07:29:34.949325 2026] [security2:error] [pid 148765:tid 148844] [remote 209.42.18.223:49236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4ivjv8fXmqCm8fNeqVLAABako"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:29:35.118395 2026] [security2:error] [pid 148765:tid 149005] [client 158.173.166.181:28089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ivzv8fXmqCm8fNeqVOwAAAXQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:29:35.187278 2026] [security2:error] [pid 148765:tid 148983] [client 4.194.24.143:22221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/scxy.php"] [unique_id "al4ivzv8fXmqCm8fNeqVPgAAAV4"]
[Mon Jul 20 07:29:35.290459 2026] [security2:error] [pid 148765:tid 148960] [client 143.44.185.218:10033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ivzv8fXmqCm8fNeqVSQAAAUc"]
[Mon Jul 20 07:29:35.290588 2026] [security2:error] [pid 148765:tid 148960] [client 143.44.185.218:10033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ivzv8fXmqCm8fNeqVSQAAAUc"]
[Mon Jul 20 07:29:35.730802 2026] [security2:error] [pid 148765:tid 148789] [remote 160.187.68.132:42640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ivzv8fXmqCm8fNeqVZwABVRM"]
[Mon Jul 20 07:29:35.768653 2026] [security2:error] [pid 145170:tid 145330] [client 4.194.24.143:22238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sd.php"] [unique_id "al4ivzjs5KUa9I09SwT18gAAAKA"]
[Mon Jul 20 07:29:35.856205 2026] [security2:error] [pid 148765:tid 148943] [client 144.16.21.149:28366] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ivzv8fXmqCm8fNeqVaAAAATY"]
[Mon Jul 20 07:29:36.012607 2026] [security2:error] [pid 148765:tid 148980] [client 57.141.18.83:40720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ivjv8fXmqCm8fNeqVCwABW3k"]
[Mon Jul 20 07:29:36.351164 2026] [security2:error] [pid 148765:tid 148914] [client 104.234.53.72:51497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4iwDv8fXmqCm8fNeqVkwAAARk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:36.393204 2026] [security2:error] [pid 148765:tid 148904] [client 4.194.24.143:22377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sf.php"] [unique_id "al4iwDv8fXmqCm8fNeqVlwAAAQ8"]
[Mon Jul 20 07:29:36.454110 2026] [security2:error] [pid 148765:tid 148922] [client 13.233.207.33:11412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4iwDv8fXmqCm8fNeqVnAAAASE"]
[Mon Jul 20 07:29:36.774269 2026] [security2:error] [pid 148765:tid 149006] [client 14.225.17.146:50544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4iwDv8fXmqCm8fNeqVnQAAAXU"], referer: http://mcg.homes/Test
[Mon Jul 20 07:29:36.857268 2026] [security2:error] [pid 148765:tid 148894] [remote 160.187.68.132:42640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4iwDv8fXmqCm8fNeqVtgABg3w"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:29:36.930777 2026] [security2:error] [pid 148765:tid 148872] [remote 49.12.216.176:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4iwDv8fXmqCm8fNeqVugABLWY"]
[Mon Jul 20 07:29:37.041978 2026] [security2:error] [pid 148765:tid 148992] [client 4.194.24.143:22259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/shell.php"] [unique_id "al4iwTv8fXmqCm8fNeqVvgAAAWc"]
[Mon Jul 20 07:29:37.083573 2026] [security2:error] [pid 148765:tid 148935] [client 104.234.53.56:35461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4iwTv8fXmqCm8fNeqVxAAAAS4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:37.105569 2026] [security2:error] [pid 148765:tid 148930] [client 152.42.182.12:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.182.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4iwTv8fXmqCm8fNeqVwwAAASk"]
[Mon Jul 20 07:29:37.125305 2026] [security2:error] [pid 148765:tid 148832] [remote 49.12.216.176:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4iwTv8fXmqCm8fNeqVxgABNz4"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 07:29:37.376938 2026] [security2:error] [pid 148765:tid 149024] [client 13.233.207.33:11414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4iwTv8fXmqCm8fNeqV0gAAAYc"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:29:37.407076 2026] [security2:error] [pid 148765:tid 148953] [client 57.141.18.105:38736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ivzv8fXmqCm8fNeqVawABQAU"]
[Mon Jul 20 07:29:37.537022 2026] [security2:error] [pid 148765:tid 148977] [client 136.158.60.21:63246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iwTv8fXmqCm8fNeqV2wAAAVg"]
[Mon Jul 20 07:29:37.537270 2026] [security2:error] [pid 148765:tid 148977] [client 136.158.60.21:63246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4iwTv8fXmqCm8fNeqV2wAAAVg"]
[Mon Jul 20 07:29:37.585020 2026] [security2:error] [pid 148765:tid 148965] [client 41.101.240.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4iwDv8fXmqCm8fNeqVigAAAUw"]
[Mon Jul 20 07:29:37.661266 2026] [security2:error] [pid 148765:tid 148948] [client 57.141.18.111:52970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwDv8fXmqCm8fNeqVfQABO14"]
[Mon Jul 20 07:29:37.813531 2026] [security2:error] [pid 145170:tid 145224] [remote 5.161.225.162:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iwTjs5KUa9I09SwT2IQAAkDI"]
[Mon Jul 20 07:29:37.844908 2026] [security2:error] [pid 148765:tid 148983] [client 4.194.24.143:1925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sid3.php"] [unique_id "al4iwTv8fXmqCm8fNeqV-QAAAV4"]
[Mon Jul 20 07:29:37.967286 2026] [security2:error] [pid 148765:tid 148992] [client 104.234.53.66:20091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4iwTv8fXmqCm8fNeqWAwAAAWc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:38.231256 2026] [security2:error] [pid 148765:tid 149012] [client 49.37.242.14:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iwjv8fXmqCm8fNeqWCwAAAXs"]
[Mon Jul 20 07:29:38.231345 2026] [security2:error] [pid 148765:tid 149012] [client 49.37.242.14:60958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4iwjv8fXmqCm8fNeqWCwAAAXs"]
[Mon Jul 20 07:29:38.274943 2026] [security2:error] [pid 145170:tid 145391] [client 142.111.152.222:53127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4iwjjs5KUa9I09SwT2JgAAAN0"]
[Mon Jul 20 07:29:38.275167 2026] [security2:error] [pid 145170:tid 145391] [client 142.111.152.222:53127] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4iwjjs5KUa9I09SwT2JgAAAN0"]
[Mon Jul 20 07:29:38.386950 2026] [security2:error] [pid 145170:tid 145192] [remote 5.161.225.162:39922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4iwjjs5KUa9I09SwT2LwAA1hI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:29:38.543439 2026] [security2:error] [pid 148765:tid 148827] [remote 45.90.123.233:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4iwjv8fXmqCm8fNeqWIQABdDk"]
[Mon Jul 20 07:29:38.563163 2026] [security2:error] [pid 148765:tid 148847] [remote 5.161.225.162:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4iwjv8fXmqCm8fNeqWIwABHE0"]
[Mon Jul 20 07:29:38.591190 2026] [security2:error] [pid 145170:tid 145408] [client 14.225.17.146:50622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4iwjjs5KUa9I09SwT2LQAAAO4"], referer: http://sesamegreenbeans.com/Test
[Mon Jul 20 07:29:38.672527 2026] [security2:error] [pid 145170:tid 145417] [client 57.141.18.6:34514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwTjs5KUa9I09SwT2CgAA91s"]
[Mon Jul 20 07:29:38.734262 2026] [security2:error] [pid 148765:tid 148802] [remote 45.90.123.233:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4iwjv8fXmqCm8fNeqWMgABTCA"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 07:29:38.748780 2026] [security2:error] [pid 148765:tid 149025] [client 4.194.24.143:22515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/simple.php"] [unique_id "al4iwjv8fXmqCm8fNeqWNAAAAYg"]
[Mon Jul 20 07:29:38.814140 2026] [security2:error] [pid 148765:tid 148825] [remote 5.161.225.162:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4iwjv8fXmqCm8fNeqWOgABOjc"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 07:29:38.816041 2026] [security2:error] [pid 148765:tid 148946] [client 57.141.18.85:51506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwTv8fXmqCm8fNeqVyQABOTA"]
[Mon Jul 20 07:29:38.844264 2026] [security2:error] [pid 148765:tid 148991] [client 125.209.97.230:60341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iwjv8fXmqCm8fNeqWPwAAAWY"]
[Mon Jul 20 07:29:38.844403 2026] [security2:error] [pid 148765:tid 148991] [client 125.209.97.230:60341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4iwjv8fXmqCm8fNeqWPwAAAWY"]
[Mon Jul 20 07:29:39.003744 2026] [security2:error] [pid 145170:tid 145313] [client 14.225.17.146:52497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4iwTjs5KUa9I09SwT2GwAAAI8"], referer: http://detroitcsc.com/Test
[Mon Jul 20 07:29:39.172035 2026] [security2:error] [pid 148765:tid 148972] [client 3.67.192.83:24208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iwzv8fXmqCm8fNeqWUwAAAVM"]
[Mon Jul 20 07:29:39.172132 2026] [security2:error] [pid 148765:tid 148972] [client 3.67.192.83:24208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4iwzv8fXmqCm8fNeqWUwAAAVM"]
[Mon Jul 20 07:29:39.241958 2026] [security2:error] [pid 148765:tid 148961] [client 191.202.66.27:49231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iwzv8fXmqCm8fNeqWWwAAAUg"]
[Mon Jul 20 07:29:39.242096 2026] [security2:error] [pid 148765:tid 148961] [client 191.202.66.27:49231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4iwzv8fXmqCm8fNeqWWwAAAUg"]
[Mon Jul 20 07:29:39.355152 2026] [security2:error] [pid 148765:tid 148931] [client 57.141.18.10:21000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwTv8fXmqCm8fNeqV_AABKhc"]
[Mon Jul 20 07:29:39.476453 2026] [security2:error] [pid 145170:tid 145386] [client 52.109.124.141:8259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4iwzjs5KUa9I09SwT2QQAAANg"]
[Mon Jul 20 07:29:39.477420 2026] [security2:error] [pid 145170:tid 145374] [client 57.141.18.123:51774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwTjs5KUa9I09SwT2IgAAzGY"]
[Mon Jul 20 07:29:39.657065 2026] [security2:error] [pid 145170:tid 145351] [client 57.141.18.89:50900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwjjs5KUa9I09SwT2JQAAtWI"]
[Mon Jul 20 07:29:39.658832 2026] [security2:error] [pid 145170:tid 145369] [client 52.109.124.141:8259] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4iwzjs5KUa9I09SwT2QwAAAMc"]
[Mon Jul 20 07:29:39.681159 2026] [security2:error] [pid 148765:tid 148908] [client 4.194.24.143:22336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sitemap.php"] [unique_id "al4iwzv8fXmqCm8fNeqWcgAAARM"]
[Mon Jul 20 07:29:39.731645 2026] [security2:error] [pid 148765:tid 148947] [client 179.127.84.238:50912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iwzv8fXmqCm8fNeqWcwAAATo"]
[Mon Jul 20 07:29:39.731745 2026] [security2:error] [pid 148765:tid 148947] [client 179.127.84.238:50912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iwzv8fXmqCm8fNeqWcwAAATo"]
[Mon Jul 20 07:29:39.740458 2026] [security2:error] [pid 145170:tid 145318] [client 57.141.18.70:47914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwjjs5KUa9I09SwT2KgAAlDo"]
[Mon Jul 20 07:29:39.849543 2026] [security2:error] [pid 148765:tid 148991] [client 14.225.17.146:52110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4iwzv8fXmqCm8fNeqWcQAAAWY"], referer: https://sesamegreenbeans.com/Test
[Mon Jul 20 07:29:40.073289 2026] [security2:error] [pid 148765:tid 148913] [client 14.225.17.146:52267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4iwzv8fXmqCm8fNeqWgwAAARg"], referer: http://nextlvlmarketingco.com/Test
[Mon Jul 20 07:29:40.101775 2026] [security2:error] [pid 148765:tid 148807] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWjAABYyU"]
[Mon Jul 20 07:29:40.101928 2026] [security2:error] [pid 148765:tid 148988] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWjAABYyU"]
[Mon Jul 20 07:29:40.138976 2026] [security2:error] [pid 148765:tid 148998] [client 157.20.138.62:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWjwAAAW0"]
[Mon Jul 20 07:29:40.139092 2026] [security2:error] [pid 148765:tid 148998] [client 157.20.138.62:52019] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWjwAAAW0"]
[Mon Jul 20 07:29:40.396561 2026] [security2:error] [pid 145170:tid 145382] [client 4.194.24.143:1931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/size.php"] [unique_id "al4ixDjs5KUa9I09SwT2XwAAANQ"]
[Mon Jul 20 07:29:40.409238 2026] [security2:error] [pid 148765:tid 149008] [client 88.241.67.160:55941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWoQAAAXc"]
[Mon Jul 20 07:29:40.409394 2026] [security2:error] [pid 148765:tid 149008] [client 88.241.67.160:55941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWoQAAAXc"]
[Mon Jul 20 07:29:40.525628 2026] [security2:error] [pid 148765:tid 148908] [client 52.109.16.52:21568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4ixDv8fXmqCm8fNeqWpAAAARM"]
[Mon Jul 20 07:29:40.577323 2026] [security2:error] [pid 148765:tid 149011] [client 52.109.16.52:21568] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4ixDv8fXmqCm8fNeqWqAAAAXo"]
[Mon Jul 20 07:29:40.586151 2026] [security2:error] [pid 148765:tid 148857] [remote 8.217.108.67:6846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWpwABclc"]
[Mon Jul 20 07:29:40.586391 2026] [security2:error] [pid 148765:tid 149003] [client 8.217.108.67:6846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWpwABclc"]
[Mon Jul 20 07:29:40.653908 2026] [security2:error] [pid 148765:tid 149017] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWowABgD0"]
[Mon Jul 20 07:29:40.812117 2026] [security2:error] [pid 148765:tid 148989] [client 57.141.18.73:37572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iwzv8fXmqCm8fNeqWbQABZEs"]
[Mon Jul 20 07:29:40.963588 2026] [security2:error] [pid 145170:tid 145355] [client 4.194.24.143:22256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sm.php"] [unique_id "al4ixDjs5KUa9I09SwT2cgAAALk"]
[Mon Jul 20 07:29:40.970361 2026] [security2:error] [pid 148765:tid 148789] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWuQABMRM"]
[Mon Jul 20 07:29:40.970548 2026] [security2:error] [pid 148765:tid 148938] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4ixDv8fXmqCm8fNeqWuQABMRM"]
[Mon Jul 20 07:29:41.315327 2026] [security2:error] [pid 148765:tid 148952] [client 202.141.11.99:55460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ixTv8fXmqCm8fNeqWxgAAAT8"]
[Mon Jul 20 07:29:41.315436 2026] [security2:error] [pid 148765:tid 148952] [client 202.141.11.99:55460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ixTv8fXmqCm8fNeqWxgAAAT8"]
[Mon Jul 20 07:29:41.509545 2026] [security2:error] [pid 145170:tid 145393] [client 4.194.24.143:22215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sql.php"] [unique_id "al4ixTjs5KUa9I09SwT2gQAAAN8"]
[Mon Jul 20 07:29:41.619630 2026] [security2:error] [pid 148765:tid 149004] [client 158.173.89.95:38173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ixTv8fXmqCm8fNeqW0wAAAXM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:29:41.717171 2026] [security2:error] [pid 145170:tid 145330] [client 57.141.18.115:41134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixDjs5KUa9I09SwT2YQAAoCg"]
[Mon Jul 20 07:29:41.859455 2026] [security2:error] [pid 145170:tid 145351] [client 49.47.218.174:50850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ixTjs5KUa9I09SwT2kAAAALU"]
[Mon Jul 20 07:29:41.859548 2026] [security2:error] [pid 145170:tid 145351] [client 49.47.218.174:50850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ixTjs5KUa9I09SwT2kAAAALU"]
[Mon Jul 20 07:29:41.921868 2026] [security2:error] [pid 145170:tid 145415] [client 117.211.236.168:62601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ixTjs5KUa9I09SwT2kwAAAPU"]
[Mon Jul 20 07:29:41.922029 2026] [security2:error] [pid 145170:tid 145415] [client 117.211.236.168:62601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4ixTjs5KUa9I09SwT2kwAAAPU"]
[Mon Jul 20 07:29:41.953552 2026] [security2:error] [pid 148765:tid 148907] [client 14.225.17.146:60024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4ixDv8fXmqCm8fNeqWrQAAARI"], referer: http://northbrookcpa.ca/Test
[Mon Jul 20 07:29:42.038756 2026] [security2:error] [pid 148765:tid 148882] [remote 100.42.189.89:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqW6wABLXA"]
[Mon Jul 20 07:29:42.051736 2026] [security2:error] [pid 148765:tid 149023] [client 4.194.24.143:22224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/ss.php"] [unique_id "al4ixjv8fXmqCm8fNeqW7gAAAYY"]
[Mon Jul 20 07:29:42.053297 2026] [security2:error] [pid 148765:tid 148950] [client 104.234.53.49:53259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqW7AAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:42.181599 2026] [security2:error] [pid 148765:tid 148785] [remote 154.66.198.148:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgeamazon.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqW8wABDg8"]
[Mon Jul 20 07:29:42.249162 2026] [security2:error] [pid 148765:tid 148824] [remote 100.42.189.89:53170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqW9gABGjY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:29:42.384146 2026] [security2:error] [pid 148765:tid 148952] [client 14.225.17.146:52620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ixjv8fXmqCm8fNeqW8AAAAT8"]
[Mon Jul 20 07:29:42.454446 2026] [security2:error] [pid 148765:tid 148940] [client 57.141.18.34:29716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixTv8fXmqCm8fNeqWwAABM3k"]
[Mon Jul 20 07:29:42.470103 2026] [security2:error] [pid 148765:tid 148966] [client 223.109.252.193:51028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sarakety.com"] [uri "/"] [unique_id "al4ixjv8fXmqCm8fNeqXBQAAAU0"]
[Mon Jul 20 07:29:42.470176 2026] [security2:error] [pid 148765:tid 148966] [client 223.109.252.193:51028] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.sarakety.com"] [uri "/"] [unique_id "al4ixjv8fXmqCm8fNeqXBQAAAU0"]
[Mon Jul 20 07:29:42.482794 2026] [security2:error] [pid 148765:tid 148784] [remote 91.142.222.105:51176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqXAwABJw4"]
[Mon Jul 20 07:29:42.597535 2026] [security2:error] [pid 145170:tid 145356] [client 4.194.24.143:22213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/stats.php"] [unique_id "al4ixjjs5KUa9I09SwT2rAAAALo"]
[Mon Jul 20 07:29:42.668383 2026] [security2:error] [pid 145170:tid 145411] [client 154.192.123.127:17572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ixjjs5KUa9I09SwT2rwAAAPE"]
[Mon Jul 20 07:29:42.668484 2026] [security2:error] [pid 145170:tid 145411] [client 154.192.123.127:17572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ixjjs5KUa9I09SwT2rwAAAPE"]
[Mon Jul 20 07:29:42.693148 2026] [security2:error] [pid 145170:tid 145369] [client 57.141.18.87:43952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixTjs5KUa9I09SwT2fQAAx0U"]
[Mon Jul 20 07:29:42.727111 2026] [security2:error] [pid 148765:tid 148777] [remote 154.66.198.148:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bridgeamazon.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqXFAABKwc"], referer: https://bridgeamazon.com/wp-login.php
[Mon Jul 20 07:29:42.737603 2026] [security2:error] [pid 148765:tid 148800] [remote 91.142.222.105:51176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-19aec4aa.spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4ixjv8fXmqCm8fNeqXFQABYB4"], referer: https://website-19aec4aa.spencersadventures.com/wp-login.php
[Mon Jul 20 07:29:43.006723 2026] [security2:error] [pid 148765:tid 148997] [client 104.234.53.60:63383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4ixzv8fXmqCm8fNeqXKAAAAWw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:43.170579 2026] [security2:error] [pid 148765:tid 148938] [client 4.194.24.143:22516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/sump1.php"] [unique_id "al4ixzv8fXmqCm8fNeqXLAAAATE"]
[Mon Jul 20 07:29:43.293418 2026] [security2:error] [pid 145170:tid 145421] [client 57.141.18.73:37576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixjjs5KUa9I09SwT2mgAA-ws"]
[Mon Jul 20 07:29:43.584256 2026] [security2:error] [pid 148765:tid 148922] [client 36.93.152.155:62365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ixzv8fXmqCm8fNeqXQgAAASE"]
[Mon Jul 20 07:29:43.584359 2026] [security2:error] [pid 148765:tid 148922] [client 36.93.152.155:62365] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ixzv8fXmqCm8fNeqXQgAAASE"]
[Mon Jul 20 07:29:43.608856 2026] [security2:error] [pid 148765:tid 148925] [client 62.102.148.130:32942] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ixzv8fXmqCm8fNeqXQQAAASQ"]
[Mon Jul 20 07:29:43.608968 2026] [security2:error] [pid 148765:tid 148925] [client 62.102.148.130:32942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ixzv8fXmqCm8fNeqXQQAAASQ"]
[Mon Jul 20 07:29:43.618027 2026] [security2:error] [pid 148765:tid 149009] [client 57.141.18.63:43832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixjv8fXmqCm8fNeqXBgABeGY"]
[Mon Jul 20 07:29:43.726401 2026] [security2:error] [pid 148765:tid 149024] [client 14.225.17.146:52639] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4ixzv8fXmqCm8fNeqXPQAAAYc"], referer: http://falconarrowshop.com/Test
[Mon Jul 20 07:29:43.750044 2026] [security2:error] [pid 148765:tid 148961] [client 4.194.24.143:1091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/system.php"] [unique_id "al4ixzv8fXmqCm8fNeqXRgAAAUg"]
[Mon Jul 20 07:29:43.760389 2026] [security2:error] [pid 148765:tid 148945] [client 57.141.18.108:35496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixjv8fXmqCm8fNeqXDwABOAM"]
[Mon Jul 20 07:29:44.130767 2026] [security2:error] [pid 148765:tid 148913] [client 14.225.17.146:50940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4iyDv8fXmqCm8fNeqXVgAAARg"], referer: http://hammadownenterprises.com/Test
[Mon Jul 20 07:29:44.332427 2026] [security2:error] [pid 148765:tid 148937] [client 201.27.111.74:56626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iyDv8fXmqCm8fNeqXagAAATA"]
[Mon Jul 20 07:29:44.332513 2026] [security2:error] [pid 148765:tid 148937] [client 201.27.111.74:56626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4iyDv8fXmqCm8fNeqXagAAATA"]
[Mon Jul 20 07:29:44.332793 2026] [security2:error] [pid 145170:tid 145412] [client 4.194.24.143:1094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/system/03n1hob7p03r2npdefault.php"] [unique_id "al4iyDjs5KUa9I09SwT20QAAAPI"]
[Mon Jul 20 07:29:44.580907 2026] [security2:error] [pid 148765:tid 148915] [client 103.176.215.66:55499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iyDv8fXmqCm8fNeqXeAAAARo"]
[Mon Jul 20 07:29:44.581407 2026] [security2:error] [pid 148765:tid 148915] [client 103.176.215.66:55499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4iyDv8fXmqCm8fNeqXeAAAARo"]
[Mon Jul 20 07:29:44.652987 2026] [security2:error] [pid 148765:tid 148840] [remote 5.161.225.162:60294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4iyDv8fXmqCm8fNeqXfQABSUY"]
[Mon Jul 20 07:29:44.875702 2026] [security2:error] [pid 148765:tid 148982] [client 4.194.24.143:1128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/system/cj5ha2rah8lyiqqdefault.php"] [unique_id "al4iyDv8fXmqCm8fNeqXhwAAAV0"]
[Mon Jul 20 07:29:44.885192 2026] [security2:error] [pid 148765:tid 148811] [remote 5.161.225.162:60294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4iyDv8fXmqCm8fNeqXiQABMik"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 07:29:44.918410 2026] [security2:error] [pid 148765:tid 148942] [client 103.106.165.44:52343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iyDv8fXmqCm8fNeqXjgAAATU"]
[Mon Jul 20 07:29:44.918560 2026] [security2:error] [pid 148765:tid 148942] [client 103.106.165.44:52343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4iyDv8fXmqCm8fNeqXjgAAATU"]
[Mon Jul 20 07:29:44.962341 2026] [security2:error] [pid 148765:tid 148988] [client 57.141.18.123:37284] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixzv8fXmqCm8fNeqXRwABYxs"]
[Mon Jul 20 07:29:44.973027 2026] [security2:error] [pid 148765:tid 148985] [client 57.141.18.96:55696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ixzv8fXmqCm8fNeqXSAABYBw"]
[Mon Jul 20 07:29:45.330300 2026] [security2:error] [pid 148765:tid 148957] [client 77.110.127.138:50202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4iyTv8fXmqCm8fNeqXlgAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:45.431321 2026] [security2:error] [pid 145170:tid 145355] [client 4.194.24.143:22217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/system_log.php"] [unique_id "al4iyTjs5KUa9I09SwT26wAAALk"]
[Mon Jul 20 07:29:45.846486 2026] [security2:error] [pid 148765:tid 148924] [client 216.173.120.127:53525] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4iyTv8fXmqCm8fNeqXuQAAASM"]
[Mon Jul 20 07:29:45.911504 2026] [security2:error] [pid 148765:tid 149007] [client 57.141.18.32:25096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iyDv8fXmqCm8fNeqXgQABdkw"]
[Mon Jul 20 07:29:46.008400 2026] [security2:error] [pid 145170:tid 145318] [client 4.194.24.143:1930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/t.php"] [unique_id "al4iyjjs5KUa9I09SwT3BAAAAJQ"]
[Mon Jul 20 07:29:46.011087 2026] [core:error] [pid 148765:tid 148969] [client 14.225.17.146:59915] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:46.011106 2026] [core:error] [pid 148765:tid 148969] [client 14.225.17.146:59915] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:46.199211 2026] [security2:error] [pid 148765:tid 148995] [client 144.16.21.149:36110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4iyjv8fXmqCm8fNeqXyQAAAWo"]
[Mon Jul 20 07:29:46.366064 2026] [security2:error] [pid 145170:tid 145251] [remote 182.77.62.24:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4iyjjs5KUa9I09SwT3EwAA_E0"]
[Mon Jul 20 07:29:46.583710 2026] [security2:error] [pid 148765:tid 148963] [client 4.194.24.143:18453] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/term.php"] [unique_id "al4iyjv8fXmqCm8fNeqX4AAAAUo"]
[Mon Jul 20 07:29:46.620881 2026] [security2:error] [pid 148765:tid 148906] [client 57.141.18.119:57446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iyTv8fXmqCm8fNeqXpQABEU0"]
[Mon Jul 20 07:29:46.659121 2026] [autoindex:error] [pid 148765:tid 148967] [client 116.202.32.156:0] AH01276: Cannot serve directory /home1/acaiandc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:29:46.705007 2026] [security2:error] [pid 148765:tid 148948] [client 14.225.17.146:50750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4iyjv8fXmqCm8fNeqX6gAAATs"], referer: http://intelligentengineeringsolutions.com/Test
[Mon Jul 20 07:29:46.873282 2026] [security2:error] [pid 145170:tid 145195] [remote 182.77.62.24:59742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4iyjjs5KUa9I09SwT3HgAA4xU"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 07:29:47.024761 2026] [security2:error] [pid 145170:tid 145368] [client 57.141.18.44:50912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iyTjs5KUa9I09SwT2-wAAxgc"]
[Mon Jul 20 07:29:47.098474 2026] [security2:error] [pid 148765:tid 148925] [client 14.225.17.146:60438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4iyjv8fXmqCm8fNeqX-AAAASQ"], referer: http://careysheatingandcooling.com/Test
[Mon Jul 20 07:29:47.179828 2026] [security2:error] [pid 148765:tid 148915] [client 4.194.24.143:1961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/test.php"] [unique_id "al4iyzv8fXmqCm8fNeqYBgAAARo"]
[Mon Jul 20 07:29:47.236996 2026] [security2:error] [pid 145170:tid 145254] [remote 154.61.75.100:60060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iyzjs5KUa9I09SwT3KQAAsVA"]
[Mon Jul 20 07:29:47.415696 2026] [security2:error] [pid 145170:tid 145338] [client 98.159.234.160:22697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4iyzjs5KUa9I09SwT3MAAAAKg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:29:47.542375 2026] [security2:error] [pid 148765:tid 148940] [client 50.116.65.227:47558] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4iyzv8fXmqCm8fNeqYEwAAATM"]
[Mon Jul 20 07:29:47.551278 2026] [security2:error] [pid 148765:tid 148967] [client 50.116.65.227:47560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4iyzv8fXmqCm8fNeqYFAAAAU4"]
[Mon Jul 20 07:29:47.592921 2026] [security2:error] [pid 145170:tid 145390] [client 143.44.185.218:11422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iyzjs5KUa9I09SwT3MwAAANw"]
[Mon Jul 20 07:29:47.593053 2026] [security2:error] [pid 145170:tid 145390] [client 143.44.185.218:11422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4iyzjs5KUa9I09SwT3MwAAANw"]
[Mon Jul 20 07:29:47.651027 2026] [autoindex:error] [pid 148765:tid 148905] [client 116.202.32.156:0] AH01276: Cannot serve directory /home1/acaiandc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:29:47.725337 2026] [security2:error] [pid 145170:tid 145343] [client 4.194.24.143:22526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/test1.php"] [unique_id "al4iyzjs5KUa9I09SwT3OQAAAK0"]
[Mon Jul 20 07:29:47.871689 2026] [security2:error] [pid 148765:tid 148911] [client 57.141.18.25:45872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iyjv8fXmqCm8fNeqX8gABFhg"]
[Mon Jul 20 07:29:47.905057 2026] [autoindex:error] [pid 145170:tid 145424] [client 38.141.62.23:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/contact-us/
[Mon Jul 20 07:29:47.915036 2026] [security2:error] [pid 145170:tid 145236] [remote 154.61.75.100:60060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4iyzjs5KUa9I09SwT3QAAA0j4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:29:48.003454 2026] [security2:error] [pid 145170:tid 145256] [remote 41.76.214.143:33184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.214.76.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iyzjs5KUa9I09SwT3RQABBFI"]
[Mon Jul 20 07:29:48.003584 2026] [security2:error] [pid 145170:tid 145430] [client 41.76.214.143:33184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4iyzjs5KUa9I09SwT3RQABBFI"]
[Mon Jul 20 07:29:48.010744 2026] [security2:error] [pid 148765:tid 148859] [remote 5.161.225.162:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4izDv8fXmqCm8fNeqYKwABDFk"]
[Mon Jul 20 07:29:48.106889 2026] [security2:error] [pid 148765:tid 148975] [client 50.116.65.227:47570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4iyzv8fXmqCm8fNeqYKgAAAVY"]
[Mon Jul 20 07:29:48.216318 2026] [security2:error] [pid 148765:tid 148880] [remote 5.161.225.162:60302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4izDv8fXmqCm8fNeqYMgABQ24"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 07:29:48.240576 2026] [security2:error] [pid 148765:tid 148958] [client 194.180.48.253:38306] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "darkknightsolutions.com"] [uri "/"] [unique_id "al4izDv8fXmqCm8fNeqYMwAAAUU"]
[Mon Jul 20 07:29:48.262270 2026] [security2:error] [pid 145170:tid 145391] [client 14.225.17.146:50927] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4iyjjs5KUa9I09SwT3HQAAAN0"], referer: http://sarahsnyder.net/Test
[Mon Jul 20 07:29:48.263898 2026] [security2:error] [pid 145170:tid 145382] [client 136.158.60.21:64681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4izDjs5KUa9I09SwT3TgAAANQ"]
[Mon Jul 20 07:29:48.264009 2026] [security2:error] [pid 145170:tid 145382] [client 136.158.60.21:64681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4izDjs5KUa9I09SwT3TgAAANQ"]
[Mon Jul 20 07:29:48.269532 2026] [security2:error] [pid 145170:tid 145354] [client 4.194.24.143:22555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/tfm.php"] [unique_id "al4izDjs5KUa9I09SwT3UAAAALg"]
[Mon Jul 20 07:29:48.312921 2026] [security2:error] [pid 148765:tid 148991] [client 50.116.65.227:47580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4izDv8fXmqCm8fNeqYLQAAAWY"]
[Mon Jul 20 07:29:48.387081 2026] [security2:error] [pid 148765:tid 148960] [client 14.225.17.146:60452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4iyjv8fXmqCm8fNeqX-QAAAUc"], referer: http://alexsandbergmusic.com/Test
[Mon Jul 20 07:29:48.503452 2026] [security2:error] [pid 148765:tid 148826] [remote 8.217.108.67:6862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4izDv8fXmqCm8fNeqYOgABKTg"]
[Mon Jul 20 07:29:48.503592 2026] [security2:error] [pid 148765:tid 148930] [client 8.217.108.67:6862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4izDv8fXmqCm8fNeqYOgABKTg"]
[Mon Jul 20 07:29:48.755100 2026] [security2:error] [pid 145170:tid 145366] [client 57.141.18.61:52982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4iyzjs5KUa9I09SwT3QgAAxDw"]
[Mon Jul 20 07:29:48.770987 2026] [security2:error] [pid 145170:tid 145334] [client 125.209.97.230:60841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4izDjs5KUa9I09SwT3ZAAAAKQ"]
[Mon Jul 20 07:29:48.771185 2026] [security2:error] [pid 145170:tid 145334] [client 125.209.97.230:60841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4izDjs5KUa9I09SwT3ZAAAAKQ"]
[Mon Jul 20 07:29:48.811389 2026] [security2:error] [pid 145170:tid 145400] [client 4.194.24.143:22231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/thebe.php"] [unique_id "al4izDjs5KUa9I09SwT3ZQAAAOY"]
[Mon Jul 20 07:29:48.957985 2026] [security2:error] [pid 148765:tid 148916] [client 142.111.152.154:48385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4izDv8fXmqCm8fNeqYVQAAARs"]
[Mon Jul 20 07:29:48.958137 2026] [security2:error] [pid 148765:tid 148916] [client 142.111.152.154:48385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4izDv8fXmqCm8fNeqYVQAAARs"]
[Mon Jul 20 07:29:48.977509 2026] [security2:error] [pid 148765:tid 148883] [remote 57.141.18.117:60070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4izDv8fXmqCm8fNeqYWwABHnE"]
[Mon Jul 20 07:29:49.141171 2026] [autoindex:error] [pid 148765:tid 148933] [client 38.141.62.134:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/contact-us/
[Mon Jul 20 07:29:49.290055 2026] [security2:error] [pid 148765:tid 148937] [client 14.225.17.146:50738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4izTv8fXmqCm8fNeqYawAAATA"], referer: https://sarahsnyder.net/Test
[Mon Jul 20 07:29:49.362435 2026] [security2:error] [pid 148765:tid 148943] [client 4.194.24.143:22508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/themes.php"] [unique_id "al4izTv8fXmqCm8fNeqYcQAAATY"]
[Mon Jul 20 07:29:49.714529 2026] [security2:error] [pid 148765:tid 148949] [client 57.141.18.16:48328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izDv8fXmqCm8fNeqYSwABPCY"]
[Mon Jul 20 07:29:49.895128 2026] [security2:error] [pid 145170:tid 145411] [client 57.141.18.112:60318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izDjs5KUa9I09SwT3agAA8Tc"]
[Mon Jul 20 07:29:49.906215 2026] [security2:error] [pid 145170:tid 145379] [client 4.194.24.143:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/tiny.php"] [unique_id "al4izTjs5KUa9I09SwT3iAAAANE"]
[Mon Jul 20 07:29:49.938699 2026] [security2:error] [pid 148765:tid 148929] [client 191.202.66.27:49751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4izTv8fXmqCm8fNeqYiAAAASg"]
[Mon Jul 20 07:29:49.938915 2026] [security2:error] [pid 148765:tid 148929] [client 191.202.66.27:49751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4izTv8fXmqCm8fNeqYiAAAASg"]
[Mon Jul 20 07:29:50.033554 2026] [security2:error] [pid 148765:tid 148961] [client 57.141.18.71:57748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izTv8fXmqCm8fNeqYYwABSGw"]
[Mon Jul 20 07:29:50.191647 2026] [security2:error] [pid 148765:tid 149003] [client 14.225.17.146:60592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4izDv8fXmqCm8fNeqYPAAAAXI"]
[Mon Jul 20 07:29:50.211417 2026] [autoindex:error] [pid 148765:tid 148930] [client 38.141.62.235:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/contact-us/
[Mon Jul 20 07:29:50.267447 2026] [security2:error] [pid 148765:tid 148900] [client 3.78.190.80:15032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4izTv8fXmqCm8fNeqYegAAAQs"]
[Mon Jul 20 07:29:50.356089 2026] [security2:error] [pid 148765:tid 148956] [client 66.249.68.130:58897] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "bradpetersphotography.com"] [uri "/robots.txt"] [unique_id "al4izjv8fXmqCm8fNeqYmwAAAUM"]
[Mon Jul 20 07:29:50.423914 2026] [security2:error] [pid 145170:tid 145340] [client 179.127.84.238:51425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4izjjs5KUa9I09SwT3lQAAAKo"]
[Mon Jul 20 07:29:50.424033 2026] [security2:error] [pid 145170:tid 145340] [client 179.127.84.238:51425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4izjjs5KUa9I09SwT3lQAAAKo"]
[Mon Jul 20 07:29:50.483654 2026] [security2:error] [pid 148765:tid 148904] [client 4.194.24.143:1940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.24.194.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "asliceofleadership.com"] [uri "/tmp/byp.php"] [unique_id "al4izjv8fXmqCm8fNeqYqgAAAQ8"]
[Mon Jul 20 07:29:50.669916 2026] [security2:error] [pid 145170:tid 145373] [client 57.141.18.97:56696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izTjs5KUa9I09SwT3fwAAyzk"]
[Mon Jul 20 07:29:50.724481 2026] [security2:error] [pid 145170:tid 145312] [client 57.141.18.1:39472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izTjs5KUa9I09SwT3gwAAjmQ"]
[Mon Jul 20 07:29:50.727420 2026] [security2:error] [pid 148765:tid 148951] [client 157.20.138.62:52584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4izjv8fXmqCm8fNeqYrAAAAT4"]
[Mon Jul 20 07:29:50.727540 2026] [security2:error] [pid 148765:tid 148951] [client 157.20.138.62:52584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4izjv8fXmqCm8fNeqYrAAAAT4"]
[Mon Jul 20 07:29:50.748769 2026] [security2:error] [pid 145170:tid 145228] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4izjjs5KUa9I09SwT3mgAApjY"]
[Mon Jul 20 07:29:50.748918 2026] [security2:error] [pid 145170:tid 145336] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4izjjs5KUa9I09SwT3mgAApjY"]
[Mon Jul 20 07:29:50.997542 2026] [security2:error] [pid 148765:tid 148789] [remote 20.153.140.50:46932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4izjv8fXmqCm8fNeqYvQABChM"]
[Mon Jul 20 07:29:50.997794 2026] [security2:error] [pid 148765:tid 148899] [client 20.153.140.50:46932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4izjv8fXmqCm8fNeqYvQABChM"]
[Mon Jul 20 07:29:51.015405 2026] [security2:error] [pid 148765:tid 149010] [client 88.241.67.160:55210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4izzv8fXmqCm8fNeqYvwAAAXk"]
[Mon Jul 20 07:29:51.016208 2026] [security2:error] [pid 148765:tid 149010] [client 88.241.67.160:55210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4izzv8fXmqCm8fNeqYvwAAAXk"]
[Mon Jul 20 07:29:51.140031 2026] [security2:error] [pid 148765:tid 148903] [client 14.225.17.146:53689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4izjv8fXmqCm8fNeqYvgAAAQ4"]
[Mon Jul 20 07:29:51.314961 2026] [security2:error] [pid 148765:tid 148914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4izzv8fXmqCm8fNeqYwQAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:51.321277 2026] [security2:error] [pid 148765:tid 148925] [client 14.225.17.146:53854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4izTv8fXmqCm8fNeqYdwAAASQ"], referer: http://narv.co/Test
[Mon Jul 20 07:29:51.380336 2026] [security2:error] [pid 145170:tid 145185] [remote 57.141.18.33:64632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4838212"] [unique_id "al4izzjs5KUa9I09SwT3uwAAvgs"]
[Mon Jul 20 07:29:51.384120 2026] [security2:error] [pid 148765:tid 149012] [client 14.225.17.146:54040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4izjv8fXmqCm8fNeqYpQAAAXs"], referer: http://claysharecon.com/Test
[Mon Jul 20 07:29:51.489111 2026] [security2:error] [pid 145170:tid 145196] [remote 51.158.61.221:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4izzjs5KUa9I09SwT3xwAAqRY"]
[Mon Jul 20 07:29:51.499526 2026] [autoindex:error] [pid 145170:tid 145376] [client 38.141.62.241:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/contact-us/
[Mon Jul 20 07:29:51.603340 2026] [security2:error] [pid 145170:tid 145399] [client 14.251.3.155:56059] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4izzjs5KUa9I09SwT3zQAAAOU"]
[Mon Jul 20 07:29:51.621500 2026] [security2:error] [pid 145170:tid 145206] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4izzjs5KUa9I09SwT3zgAA9SA"]
[Mon Jul 20 07:29:51.621662 2026] [security2:error] [pid 145170:tid 145415] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4izzjs5KUa9I09SwT3zgAA9SA"]
[Mon Jul 20 07:29:51.674906 2026] [security2:error] [pid 145170:tid 145230] [remote 51.158.61.221:44734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.158.51.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4izzjs5KUa9I09SwT30AAAxzg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:29:51.739657 2026] [security2:error] [pid 145170:tid 145347] [client 57.141.18.12:30058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izjjs5KUa9I09SwT3nwAAsTE"]
[Mon Jul 20 07:29:51.747837 2026] [security2:error] [pid 148765:tid 148897] [remote 217.61.143.92:42144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4izzv8fXmqCm8fNeqY0AABK38"]
[Mon Jul 20 07:29:51.936686 2026] [security2:error] [pid 145170:tid 145209] [remote 152.228.213.32:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4izzjs5KUa9I09SwT34wAA1iM"]
[Mon Jul 20 07:29:51.994377 2026] [security2:error] [pid 148765:tid 148835] [remote 217.61.143.92:42144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4izzv8fXmqCm8fNeqY3QABLEE"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:29:52.149627 2026] [security2:error] [pid 145170:tid 145221] [remote 152.228.213.32:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-login.php"] [unique_id "al4i0Djs5KUa9I09SwT37wAAzC8"], referer: https://schuttfarms.com/wp-login.php
[Mon Jul 20 07:29:52.232550 2026] [security2:error] [pid 145170:tid 145424] [client 49.47.218.174:51388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Djs5KUa9I09SwT38wAAAP4"]
[Mon Jul 20 07:29:52.232684 2026] [security2:error] [pid 145170:tid 145424] [client 49.47.218.174:51388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Djs5KUa9I09SwT38wAAAP4"]
[Mon Jul 20 07:29:52.303665 2026] [security2:error] [pid 148765:tid 148924] [client 57.141.18.32:25106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izzv8fXmqCm8fNeqYyQABIws"]
[Mon Jul 20 07:29:52.452738 2026] [security2:error] [pid 145170:tid 145316] [client 14.225.17.146:53689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4i0Djs5KUa9I09SwT39wAAAJI"], referer: https://narv.co/Test
[Mon Jul 20 07:29:52.700714 2026] [security2:error] [pid 145170:tid 145308] [client 152.42.182.12:62775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.182.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4i0Djs5KUa9I09SwT4HAAAAIo"], referer: https://www.google.com/
[Mon Jul 20 07:29:52.823593 2026] [security2:error] [pid 148765:tid 148792] [remote 5.161.225.162:38174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i0Dv8fXmqCm8fNeqY9wABZxY"]
[Mon Jul 20 07:29:52.844683 2026] [security2:error] [pid 145170:tid 145324] [client 57.141.18.33:64814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4izzjs5KUa9I09SwT33wAAmnA"]
[Mon Jul 20 07:29:52.956665 2026] [security2:error] [pid 145170:tid 145241] [remote 142.93.10.93:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4i0Djs5KUa9I09SwT4LAAAykM"]
[Mon Jul 20 07:29:53.007437 2026] [security2:error] [pid 148765:tid 148865] [remote 5.161.225.162:38174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i0Tv8fXmqCm8fNeqY_AABPl8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:29:53.079118 2026] [security2:error] [pid 148765:tid 148998] [client 116.74.65.235:58877] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Dv8fXmqCm8fNeqY-AAAAW0"]
[Mon Jul 20 07:29:53.089903 2026] [security2:error] [pid 148765:tid 149010] [client 57.141.18.99:57272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0Dv8fXmqCm8fNeqY4AABeXQ"]
[Mon Jul 20 07:29:53.093499 2026] [security2:error] [pid 148765:tid 148884] [remote 124.55.178.99:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i0Tv8fXmqCm8fNeqY_gABenI"]
[Mon Jul 20 07:29:53.129648 2026] [security2:error] [pid 145170:tid 145224] [remote 142.93.10.93:42222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4i0Tjs5KUa9I09SwT4OgAApDI"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:29:53.207233 2026] [security2:error] [pid 148765:tid 149012] [client 154.192.123.127:18015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Tv8fXmqCm8fNeqY_wAAAXs"]
[Mon Jul 20 07:29:53.207362 2026] [security2:error] [pid 148765:tid 149012] [client 154.192.123.127:18015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Tv8fXmqCm8fNeqY_wAAAXs"]
[Mon Jul 20 07:29:53.535343 2026] [security2:error] [pid 148765:tid 148890] [remote 124.55.178.99:35996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i0Tv8fXmqCm8fNeqZDAABIXg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:29:53.614538 2026] [security2:error] [pid 145170:tid 145392] [client 117.211.236.168:63163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Tjs5KUa9I09SwT4UwAAAN4"]
[Mon Jul 20 07:29:53.614667 2026] [security2:error] [pid 145170:tid 145392] [client 117.211.236.168:63163] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Tjs5KUa9I09SwT4UwAAAN4"]
[Mon Jul 20 07:29:53.759132 2026] [security2:error] [pid 148765:tid 148809] [remote 182.77.62.24:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4i0Tv8fXmqCm8fNeqZFwABIic"]
[Mon Jul 20 07:29:53.800120 2026] [security2:error] [pid 145170:tid 145394] [client 14.225.17.146:53882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4i0Tjs5KUa9I09SwT4WAAAAOA"], referer: http://katsklar.com/Test
[Mon Jul 20 07:29:53.937165 2026] [security2:error] [pid 148765:tid 148919] [client 14.225.17.146:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4i0Tv8fXmqCm8fNeqZFQAAAR4"], referer: http://floorsourcestock.com/Test
[Mon Jul 20 07:29:53.993566 2026] [security2:error] [pid 145170:tid 145411] [client 36.93.152.155:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Tjs5KUa9I09SwT4bgAAAPE"]
[Mon Jul 20 07:29:53.993687 2026] [security2:error] [pid 145170:tid 145411] [client 36.93.152.155:62889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i0Tjs5KUa9I09SwT4bgAAAPE"]
[Mon Jul 20 07:29:54.059437 2026] [security2:error] [pid 145170:tid 145367] [client 57.141.18.13:54250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0Tjs5KUa9I09SwT4PAAAxQY"]
[Mon Jul 20 07:29:54.277794 2026] [security2:error] [pid 148765:tid 148891] [remote 182.77.62.24:53298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4i0jv8fXmqCm8fNeqZKgABXXk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:29:54.751487 2026] [security2:error] [pid 145170:tid 145348] [client 201.27.111.74:57141] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i0jjs5KUa9I09SwT4jwAAALI"]
[Mon Jul 20 07:29:54.751633 2026] [security2:error] [pid 145170:tid 145348] [client 201.27.111.74:57141] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i0jjs5KUa9I09SwT4jwAAALI"]
[Mon Jul 20 07:29:55.089541 2026] [security2:error] [pid 145170:tid 145339] [client 49.37.242.14:61493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i0zjs5KUa9I09SwT4nwAAAKk"]
[Mon Jul 20 07:29:55.089657 2026] [security2:error] [pid 145170:tid 145339] [client 49.37.242.14:61493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i0zjs5KUa9I09SwT4nwAAAKk"]
[Mon Jul 20 07:29:55.091600 2026] [security2:error] [pid 148765:tid 148905] [client 57.141.18.54:30100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0jv8fXmqCm8fNeqZHgABEDY"]
[Mon Jul 20 07:29:55.122363 2026] [security2:error] [pid 148765:tid 148940] [client 103.176.215.66:56073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i0zv8fXmqCm8fNeqZXgAAATM"]
[Mon Jul 20 07:29:55.122480 2026] [security2:error] [pid 148765:tid 148940] [client 103.176.215.66:56073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i0zv8fXmqCm8fNeqZXgAAATM"]
[Mon Jul 20 07:29:55.130810 2026] [security2:error] [pid 145170:tid 145388] [client 14.225.17.146:53015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4i0jjs5KUa9I09SwT4jQAAANo"], referer: http://uritems.net/Test
[Mon Jul 20 07:29:55.267839 2026] [security2:error] [pid 148765:tid 148924] [client 103.106.165.44:52823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i0zv8fXmqCm8fNeqZZwAAASM"]
[Mon Jul 20 07:29:55.267957 2026] [security2:error] [pid 148765:tid 148924] [client 103.106.165.44:52823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i0zv8fXmqCm8fNeqZZwAAASM"]
[Mon Jul 20 07:29:55.640638 2026] [security2:error] [pid 148765:tid 148910] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZbQAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:55.948977 2026] [security2:error] [pid 145170:tid 145353] [client 57.141.18.66:40836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0jjs5KUa9I09SwT4lQAAtyQ"]
[Mon Jul 20 07:29:55.993289 2026] [security2:error] [pid 145170:tid 145397] [client 188.166.209.66:56727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4i0zjs5KUa9I09SwT4ugAAAOM"], referer: binance.com
[Mon Jul 20 07:29:56.063619 2026] [security2:error] [pid 148765:tid 149010] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZiAAAAXk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:56.151651 2026] [security2:error] [pid 148765:tid 148963] [client 66.249.65.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZjQAAAUo"]
[Mon Jul 20 07:29:56.255083 2026] [security2:error] [pid 145170:tid 145331] [client 14.225.17.146:52387] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4i0jjs5KUa9I09SwT4kQAAAKE"], referer: http://kromosenergy.com/Test
[Mon Jul 20 07:29:56.302570 2026] [security2:error] [pid 148765:tid 148965] [client 57.141.18.118:36818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZagABTG0"]
[Mon Jul 20 07:29:56.361105 2026] [security2:error] [pid 148765:tid 149024] [client 14.225.17.146:53011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZlAAAAYc"], referer: http://partnerselectricalllc.com/Test
[Mon Jul 20 07:29:56.439058 2026] [security2:error] [pid 148765:tid 148952] [client 57.141.18.43:61214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZcgABP2E"]
[Mon Jul 20 07:29:56.642805 2026] [security2:error] [pid 145170:tid 145387] [client 104.234.53.76:41041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4i1Djs5KUa9I09SwT44QAAANk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:29:56.806892 2026] [security2:error] [pid 148765:tid 148982] [client 57.141.18.100:56546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i0zv8fXmqCm8fNeqZhAABXUU"]
[Mon Jul 20 07:29:56.837712 2026] [security2:error] [pid 145170:tid 145410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i1Djs5KUa9I09SwT44AAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:56.853582 2026] [security2:error] [pid 148765:tid 148815] [remote 5.252.52.249:36548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZwQABQi0"]
[Mon Jul 20 07:29:56.888583 2026] [security2:error] [pid 148765:tid 148846] [remote 217.61.143.92:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZxAABPkw"]
[Mon Jul 20 07:29:57.006321 2026] [security2:error] [pid 148765:tid 148970] [client 144.16.21.149:24985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZyAAAAVE"]
[Mon Jul 20 07:29:57.065428 2026] [security2:error] [pid 148765:tid 148947] [client 57.141.18.44:52990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZmQABOiw"]
[Mon Jul 20 07:29:57.067205 2026] [security2:error] [pid 148765:tid 148843] [remote 5.252.52.249:36548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4i1Tv8fXmqCm8fNeqZ4QABYEk"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:29:57.143859 2026] [security2:error] [pid 148765:tid 148823] [remote 217.61.143.92:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4i1Tv8fXmqCm8fNeqZ5gABIjU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:29:57.399298 2026] [security2:error] [pid 148765:tid 148968] [client 14.225.17.146:52816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZmAAAAU8"], referer: http://blaizeaccountingservices.com/Test
[Mon Jul 20 07:29:57.470072 2026] [security2:error] [pid 145170:tid 145418] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i1Tjs5KUa9I09SwT49QAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:57.471243 2026] [security2:error] [pid 145170:tid 145399] [client 57.141.18.118:36826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1Djs5KUa9I09SwT41QAA5TM"]
[Mon Jul 20 07:29:57.526175 2026] [security2:error] [pid 148765:tid 148915] [client 66.249.74.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZzAAAARo"]
[Mon Jul 20 07:29:57.869958 2026] [security2:error] [pid 145170:tid 145395] [client 66.249.73.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4i1Tjs5KUa9I09SwT5EQAAAOE"]
[Mon Jul 20 07:29:57.910734 2026] [security2:error] [pid 145170:tid 145376] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i1Tjs5KUa9I09SwT5GgAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:58.049134 2026] [security2:error] [pid 145170:tid 145314] [client 57.141.18.2:27322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1Djs5KUa9I09SwT47AAAkHE"]
[Mon Jul 20 07:29:58.338609 2026] [security2:error] [pid 145170:tid 145421] [client 14.225.17.146:52877] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4i1Djs5KUa9I09SwT46AAAAPs"], referer: http://tntcatholic.com/Test
[Mon Jul 20 07:29:58.379570 2026] [security2:error] [pid 148765:tid 148942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i1jv8fXmqCm8fNeqaCgAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:58.382346 2026] [security2:error] [pid 148765:tid 148958] [client 57.141.18.12:30090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1Tv8fXmqCm8fNeqZ7gABRWA"]
[Mon Jul 20 07:29:58.558501 2026] [autoindex:error] [pid 148765:tid 148782] [remote 35.196.3.178:54831] AH01276: Cannot serve directory /home2/enxbgpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.enx.bgp.mybluehost.me
[Mon Jul 20 07:29:58.701889 2026] [core:error] [pid 148765:tid 148902] [client 87.236.176.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:58.701926 2026] [core:error] [pid 148765:tid 148902] [client 87.236.176.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:29:58.863973 2026] [security2:error] [pid 148765:tid 148963] [client 86.1.208.107:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "phillipbloch.com"] [uri "/index.php"] [unique_id "al4i1Dv8fXmqCm8fNeqZxwAAAUo"]
[Mon Jul 20 07:29:58.885274 2026] [security2:error] [pid 145170:tid 145347] [client 57.141.18.93:40056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1jjs5KUa9I09SwT5KAAAsRU"]
[Mon Jul 20 07:29:58.993348 2026] [security2:error] [pid 148765:tid 148988] [client 136.158.60.21:590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i1jv8fXmqCm8fNeqaOwAAAWM"]
[Mon Jul 20 07:29:58.993450 2026] [security2:error] [pid 148765:tid 148988] [client 136.158.60.21:590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i1jv8fXmqCm8fNeqaOwAAAWM"]
[Mon Jul 20 07:29:59.010376 2026] [security2:error] [pid 145170:tid 145318] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i1jjs5KUa9I09SwT5QAAAAJQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:59.122434 2026] [security2:error] [pid 148765:tid 148931] [client 66.249.73.98:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.jndsupport.com"] [uri "/index.php"] [unique_id "al4i1jv8fXmqCm8fNeqaOgAAASo"]
[Mon Jul 20 07:29:59.146034 2026] [security2:error] [pid 148765:tid 148934] [client 57.141.18.45:61170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1jv8fXmqCm8fNeqaEQABLSU"]
[Mon Jul 20 07:29:59.273338 2026] [security2:error] [pid 148765:tid 148992] [client 125.209.97.230:61341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.97.209.125.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i1zv8fXmqCm8fNeqaSAAAAWc"]
[Mon Jul 20 07:29:59.273466 2026] [security2:error] [pid 148765:tid 148992] [client 125.209.97.230:61341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i1zv8fXmqCm8fNeqaSAAAAWc"]
[Mon Jul 20 07:29:59.349706 2026] [security2:error] [pid 148765:tid 148965] [client 173.214.177.57:38637] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4i1zv8fXmqCm8fNeqaSwAAAUw"]
[Mon Jul 20 07:29:59.492681 2026] [security2:error] [pid 145170:tid 145338] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i1zjs5KUa9I09SwT5UAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:29:59.521673 2026] [security2:error] [pid 148765:tid 148971] [client 57.141.18.110:64110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1jv8fXmqCm8fNeqaKwABUkI"]
[Mon Jul 20 07:29:59.569497 2026] [security2:error] [pid 145170:tid 145328] [client 142.111.152.51:37719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i1zjs5KUa9I09SwT5XgAAAJ4"]
[Mon Jul 20 07:29:59.569598 2026] [security2:error] [pid 145170:tid 145328] [client 142.111.152.51:37719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i1zjs5KUa9I09SwT5XgAAAJ4"]
[Mon Jul 20 07:29:59.712136 2026] [security2:error] [pid 145170:tid 145342] [client 57.141.18.80:62826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i1jjs5KUa9I09SwT5QgAArGs"]
[Mon Jul 20 07:29:59.797517 2026] [security2:error] [pid 145170:tid 145372] [client 143.44.185.218:12843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i1zjs5KUa9I09SwT5aAAAAMo"]
[Mon Jul 20 07:29:59.797693 2026] [security2:error] [pid 145170:tid 145372] [client 143.44.185.218:12843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i1zjs5KUa9I09SwT5aAAAAMo"]
[Mon Jul 20 07:29:59.844193 2026] [security2:error] [pid 145170:tid 145203] [remote 57.141.18.63:36224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2981229"] [unique_id "al4i1zjs5KUa9I09SwT5bAAA5B0"]
[Mon Jul 20 07:30:00.096135 2026] [security2:error] [pid 148765:tid 148990] [client 3.67.192.83:33146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Dv8fXmqCm8fNeqaYgAAAWU"]
[Mon Jul 20 07:30:00.096256 2026] [security2:error] [pid 148765:tid 148990] [client 3.67.192.83:33146] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Dv8fXmqCm8fNeqaYgAAAWU"]
[Mon Jul 20 07:30:00.538619 2026] [security2:error] [pid 145170:tid 145238] [remote 182.77.62.24:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4i2Djs5KUa9I09SwT5hAAAiUA"]
[Mon Jul 20 07:30:00.637646 2026] [security2:error] [pid 145170:tid 145377] [client 191.202.66.27:50248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i2Djs5KUa9I09SwT5hwAAAM8"]
[Mon Jul 20 07:30:00.637726 2026] [security2:error] [pid 145170:tid 145377] [client 191.202.66.27:50248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i2Djs5KUa9I09SwT5hwAAAM8"]
[Mon Jul 20 07:30:00.741272 2026] [fcgid:warn] [pid 148765:tid 148919] (70014)End of file found: [client 66.132.195.123:50432] mod_fcgid: can't get data from http client
[Mon Jul 20 07:30:00.897515 2026] [security2:error] [pid 148765:tid 148987] [client 57.141.18.24:49256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2Dv8fXmqCm8fNeqaaQABYks"]
[Mon Jul 20 07:30:01.065045 2026] [security2:error] [pid 145170:tid 145274] [remote 182.77.62.24:53300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4i2Tjs5KUa9I09SwT5lwAA6WQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:30:01.097320 2026] [security2:error] [pid 145170:tid 145315] [client 50.116.65.227:44636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4i2Tjs5KUa9I09SwT5mQAAAJE"]
[Mon Jul 20 07:30:01.107182 2026] [security2:error] [pid 148765:tid 148926] [client 50.116.65.227:44650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4i2Tv8fXmqCm8fNeqajQAAASU"]
[Mon Jul 20 07:30:01.140837 2026] [security2:error] [pid 148765:tid 148939] [client 57.141.18.75:51404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2Dv8fXmqCm8fNeqaeQABMlQ"]
[Mon Jul 20 07:30:01.140881 2026] [security2:error] [pid 145170:tid 145414] [client 57.141.18.104:39254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2Djs5KUa9I09SwT5iAAA9HY"]
[Mon Jul 20 07:30:01.170408 2026] [security2:error] [pid 145170:tid 145373] [client 179.127.84.238:51941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tjs5KUa9I09SwT5nAAAAMs"]
[Mon Jul 20 07:30:01.170507 2026] [security2:error] [pid 145170:tid 145373] [client 179.127.84.238:51941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tjs5KUa9I09SwT5nAAAAMs"]
[Mon Jul 20 07:30:01.180568 2026] [security2:error] [pid 148765:tid 148902] [client 157.20.138.62:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tv8fXmqCm8fNeqakAAAAQ0"]
[Mon Jul 20 07:30:01.180664 2026] [security2:error] [pid 148765:tid 148902] [client 157.20.138.62:53148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tv8fXmqCm8fNeqakAAAAQ0"]
[Mon Jul 20 07:30:01.350183 2026] [security2:error] [pid 145170:tid 145269] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tjs5KUa9I09SwT5pwAA_V8"]
[Mon Jul 20 07:30:01.350380 2026] [security2:error] [pid 145170:tid 145423] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tjs5KUa9I09SwT5pwAA_V8"]
[Mon Jul 20 07:30:01.473550 2026] [security2:error] [pid 148765:tid 149019] [client 104.234.53.65:33645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4i2Tv8fXmqCm8fNeqanQAAAYI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:01.598591 2026] [security2:error] [pid 148765:tid 148956] [client 88.241.67.160:54212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tv8fXmqCm8fNeqaoAAAAUM"]
[Mon Jul 20 07:30:01.598775 2026] [security2:error] [pid 148765:tid 148956] [client 88.241.67.160:54212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i2Tv8fXmqCm8fNeqaoAAAAUM"]
[Mon Jul 20 07:30:01.805381 2026] [security2:error] [pid 148765:tid 148796] [remote 100.42.189.89:60072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i2Tv8fXmqCm8fNeqapQABbho"]
[Mon Jul 20 07:30:01.805513 2026] [security2:error] [pid 148765:tid 148999] [client 100.42.189.89:60072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i2Tv8fXmqCm8fNeqapQABbho"]
[Mon Jul 20 07:30:01.979589 2026] [security2:error] [pid 148765:tid 148986] [client 74.7.228.37:59288] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "think-islam.com"] [uri "/robots.txt"] [unique_id "al4i2Tv8fXmqCm8fNeqasAABYQQ"]
[Mon Jul 20 07:30:02.073345 2026] [security2:error] [pid 145170:tid 145200] [remote 57.141.18.12:49824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3296202"] [unique_id "al4i2jjs5KUa9I09SwT5wwAAhxo"]
[Mon Jul 20 07:30:02.237188 2026] [security2:error] [pid 148765:tid 148966] [client 57.141.18.38:50354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2Tv8fXmqCm8fNeqapAABTWQ"]
[Mon Jul 20 07:30:02.633065 2026] [security2:error] [pid 148765:tid 148852] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i2jv8fXmqCm8fNeqaygABS1I"]
[Mon Jul 20 07:30:02.633248 2026] [security2:error] [pid 148765:tid 148964] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i2jv8fXmqCm8fNeqaygABS1I"]
[Mon Jul 20 07:30:02.694406 2026] [security2:error] [pid 145170:tid 145419] [client 49.47.218.174:51927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i2jjs5KUa9I09SwT53wAAAPk"]
[Mon Jul 20 07:30:02.694540 2026] [security2:error] [pid 145170:tid 145419] [client 49.47.218.174:51927] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i2jjs5KUa9I09SwT53wAAAPk"]
[Mon Jul 20 07:30:02.791442 2026] [security2:error] [pid 148765:tid 148962] [client 57.141.18.117:39526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2jv8fXmqCm8fNeqaxwABSWc"]
[Mon Jul 20 07:30:02.812268 2026] [security2:error] [pid 148765:tid 148955] [client 77.110.127.138:50267] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/17*if(now()=sysdate(),sleep(15),0)"] [unique_id "al4i2jv8fXmqCm8fNeqazQAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:02.873073 2026] [security2:error] [pid 148765:tid 148938] [client 14.225.17.146:54653] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4i2Tv8fXmqCm8fNeqalwAAATE"], referer: http://chestermonty.com/Test
[Mon Jul 20 07:30:03.176980 2026] [security2:error] [pid 145170:tid 145327] [client 14.225.17.146:59240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4i2Tjs5KUa9I09SwT5rAAAAJ0"], referer: http://lelandumc.org/Test
[Mon Jul 20 07:30:03.238096 2026] [security2:error] [pid 148765:tid 148999] [client 117.211.236.168:63782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i2zv8fXmqCm8fNeqa4wAAAW4"]
[Mon Jul 20 07:30:03.238218 2026] [security2:error] [pid 148765:tid 148999] [client 117.211.236.168:63782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i2zv8fXmqCm8fNeqa4wAAAW4"]
[Mon Jul 20 07:30:03.655767 2026] [security2:error] [pid 148765:tid 148903] [client 154.192.123.127:18563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i2zv8fXmqCm8fNeqa8gAAAQ4"]
[Mon Jul 20 07:30:03.655883 2026] [security2:error] [pid 148765:tid 148903] [client 154.192.123.127:18563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i2zv8fXmqCm8fNeqa8gAAAQ4"]
[Mon Jul 20 07:30:03.873282 2026] [security2:error] [pid 145170:tid 145364] [client 14.225.17.146:62959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4i2zjs5KUa9I09SwT6DQAAAMI"], referer: https://chestermonty.com/Test
[Mon Jul 20 07:30:03.896518 2026] [security2:error] [pid 145170:tid 145352] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4i2zjs5KUa9I09SwT6CwAAths"]
[Mon Jul 20 07:30:04.062999 2026] [security2:error] [pid 145170:tid 145392] [client 185.238.231.220:53135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4i3Djs5KUa9I09SwT6HgAAAN4"]
[Mon Jul 20 07:30:04.105417 2026] [security2:error] [pid 148765:tid 148942] [client 185.238.231.235:21067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbAAAAATU"]
[Mon Jul 20 07:30:04.345963 2026] [security2:error] [pid 148765:tid 148977] [client 57.141.18.41:46820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2zv8fXmqCm8fNeqa9wABWAc"]
[Mon Jul 20 07:30:04.377142 2026] [security2:error] [pid 145170:tid 145369] [client 57.141.18.115:45746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i2zjs5KUa9I09SwT6EwAAx00"]
[Mon Jul 20 07:30:04.392823 2026] [security2:error] [pid 148765:tid 148958] [client 14.225.17.146:60399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4i2jv8fXmqCm8fNeqazAAAAUU"], referer: http://guidehunting.com/Test
[Mon Jul 20 07:30:04.512067 2026] [security2:error] [pid 148765:tid 148957] [client 36.93.152.155:63408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbDQAAAUQ"]
[Mon Jul 20 07:30:04.512238 2026] [security2:error] [pid 148765:tid 148957] [client 36.93.152.155:63408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbDQAAAUQ"]
[Mon Jul 20 07:30:04.665684 2026] [security2:error] [pid 148765:tid 148922] [client 14.225.17.146:61116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbEAAAASE"], referer: http://sarahholyfield.com/Test
[Mon Jul 20 07:30:04.736145 2026] [security2:error] [pid 148765:tid 148917] [client 57.141.18.56:54732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbAQABHE4"]
[Mon Jul 20 07:30:04.908385 2026] [security2:error] [pid 145170:tid 145347] [client 14.225.17.146:63010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4i2zjs5KUa9I09SwT6FAAAALE"], referer: http://oldracelimited.com/Test
[Mon Jul 20 07:30:04.939088 2026] [core:error] [pid 145170:tid 145418] [client 14.225.17.146:51814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Test
[Mon Jul 20 07:30:04.939113 2026] [core:error] [pid 145170:tid 145418] [client 14.225.17.146:51814] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/Test
[Mon Jul 20 07:30:04.947518 2026] [security2:error] [pid 145170:tid 145275] [remote 91.142.222.105:45508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4i3Djs5KUa9I09SwT6QwAAt2U"]
[Mon Jul 20 07:30:04.947656 2026] [security2:error] [pid 145170:tid 145353] [client 91.142.222.105:45508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4i3Djs5KUa9I09SwT6QwAAt2U"]
[Mon Jul 20 07:30:04.990033 2026] [security2:error] [pid 148765:tid 149009] [client 193.19.109.99:30651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.109.19.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbIQAAAXg"]
[Mon Jul 20 07:30:05.211701 2026] [security2:error] [pid 148765:tid 149022] [client 68.183.202.31:60726] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.goodtravelfun.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4i3Tv8fXmqCm8fNeqbLwAAAYU"]
[Mon Jul 20 07:30:05.222394 2026] [security2:error] [pid 145170:tid 145313] [client 201.27.111.74:57655] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i3Tjs5KUa9I09SwT6TQAAAI8"]
[Mon Jul 20 07:30:05.223838 2026] [security2:error] [pid 145170:tid 145313] [client 201.27.111.74:57655] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i3Tjs5KUa9I09SwT6TQAAAI8"]
[Mon Jul 20 07:30:05.233089 2026] [security2:error] [pid 145170:tid 145384] [client 50.116.65.227:44716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4i3Tjs5KUa9I09SwT6SQAAANY"]
[Mon Jul 20 07:30:05.239967 2026] [security2:error] [pid 148765:tid 148937] [client 104.234.53.91:50863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4i3Tv8fXmqCm8fNeqbMQAAATA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:05.443514 2026] [security2:error] [pid 145170:tid 145377] [client 50.116.65.227:44732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4i3Tjs5KUa9I09SwT6TwAAAM8"]
[Mon Jul 20 07:30:05.482596 2026] [security2:error] [pid 148765:tid 149020] [client 57.141.18.39:43825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbJAABgz4"]
[Mon Jul 20 07:30:05.618466 2026] [security2:error] [pid 145170:tid 145410] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4i3Tjs5KUa9I09SwT6WQAA8B0"]
[Mon Jul 20 07:30:05.625567 2026] [security2:error] [pid 148765:tid 148927] [client 14.225.17.146:59423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4i3Dv8fXmqCm8fNeqbGgAAASY"]
[Mon Jul 20 07:30:05.695822 2026] [security2:error] [pid 148765:tid 148933] [client 14.225.17.146:56198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4i3Tv8fXmqCm8fNeqbOgAAASw"], referer: https://guidehunting.com/Test
[Mon Jul 20 07:30:05.703656 2026] [authz_core:error] [pid 148765:tid 148971] [client 188.166.209.66:63044] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-admin/includes/error_log, referer: binance.com
[Mon Jul 20 07:30:05.739785 2026] [security2:error] [pid 148765:tid 148899] [client 103.176.215.66:56876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i3Tv8fXmqCm8fNeqbPQAAAQo"]
[Mon Jul 20 07:30:05.740766 2026] [security2:error] [pid 148765:tid 148899] [client 103.176.215.66:56876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i3Tv8fXmqCm8fNeqbPQAAAQo"]
[Mon Jul 20 07:30:05.787886 2026] [security2:error] [pid 145170:tid 145364] [client 103.106.165.44:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i3Tjs5KUa9I09SwT6ZAAAAMI"]
[Mon Jul 20 07:30:05.788007 2026] [security2:error] [pid 145170:tid 145364] [client 103.106.165.44:53316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i3Tjs5KUa9I09SwT6ZAAAAMI"]
[Mon Jul 20 07:30:06.412293 2026] [security2:error] [pid 148765:tid 148988] [client 49.37.242.14:62006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i3jv8fXmqCm8fNeqbaAAAAWM"]
[Mon Jul 20 07:30:06.412398 2026] [security2:error] [pid 148765:tid 148988] [client 49.37.242.14:62006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i3jv8fXmqCm8fNeqbaAAAAWM"]
[Mon Jul 20 07:30:06.534705 2026] [security2:error] [pid 145170:tid 145412] [client 77.110.127.138:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/170'XOR(17*if(now()=sysdate(),sleep(15),0))XOR'Z"] [unique_id "al4i3jjs5KUa9I09SwT6hAAAAPI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:06.744036 2026] [security2:error] [pid 148765:tid 148951] [client 104.207.52.60:64331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/xmlrpc.php"] [unique_id "al4i3jv8fXmqCm8fNeqbewAAAT4"], referer: https://www.google.com/
[Mon Jul 20 07:30:06.922194 2026] [security2:error] [pid 145170:tid 145386] [client 57.141.18.42:42290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i3jjs5KUa9I09SwT6gQAA2Go"]
[Mon Jul 20 07:30:07.352737 2026] [security2:error] [pid 148765:tid 148988] [client 45.3.44.127:12603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i3zv8fXmqCm8fNeqbmAAAAWM"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:07.603847 2026] [security2:error] [pid 148765:tid 149026] [client 144.16.21.149:25042] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i3zv8fXmqCm8fNeqbrQAAAYk"]
[Mon Jul 20 07:30:07.603972 2026] [security2:error] [pid 148765:tid 149026] [client 144.16.21.149:25042] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i3zv8fXmqCm8fNeqbrQAAAYk"]
[Mon Jul 20 07:30:07.860174 2026] [security2:error] [pid 148765:tid 148909] [client 57.141.18.109:64986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i3zv8fXmqCm8fNeqblgABFCk"]
[Mon Jul 20 07:30:07.962211 2026] [security2:error] [pid 148765:tid 149007] [client 104.207.53.255:41983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 255.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i3zv8fXmqCm8fNeqbvQAAAXY"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:08.357782 2026] [security2:error] [pid 145170:tid 145321] [client 34.141.215.197:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.ikv.zga.mybluehost.me"] [uri "/"] [unique_id "al4i4Djs5KUa9I09SwT6vgAAAJc"]
[Mon Jul 20 07:30:08.357874 2026] [security2:error] [pid 145170:tid 145321] [client 34.141.215.197:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.ikv.zga.mybluehost.me"] [uri "/"] [unique_id "al4i4Djs5KUa9I09SwT6vgAAAJc"]
[Mon Jul 20 07:30:08.452169 2026] [security2:error] [pid 148765:tid 148770] [remote 100.42.189.89:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4i4Dv8fXmqCm8fNeqb0gABCwA"]
[Mon Jul 20 07:30:08.495694 2026] [security2:error] [pid 148765:tid 149025] [client 14.225.17.146:56210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4i4Dv8fXmqCm8fNeqbxQAAAYg"], referer: http://talknutritionwithlesley.com/Test
[Mon Jul 20 07:30:08.565391 2026] [security2:error] [pid 148765:tid 148930] [client 77.110.127.138:50334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i4Dv8fXmqCm8fNeqbygAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:08.664862 2026] [security2:error] [pid 148765:tid 148828] [remote 100.42.189.89:60166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "allergyantidotes.com"] [uri "/wp-login.php"] [unique_id "al4i4Dv8fXmqCm8fNeqb4gABSjo"], referer: https://allergyantidotes.com/wp-login.php
[Mon Jul 20 07:30:08.906444 2026] [security2:error] [pid 148765:tid 149002] [client 57.141.18.21:20062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4Dv8fXmqCm8fNeqbzQABcTk"]
[Mon Jul 20 07:30:08.907681 2026] [fcgid:warn] [pid 145170:tid 145396] (70014)End of file found: [client 66.132.195.114:51416] mod_fcgid: can't get data from http client
[Mon Jul 20 07:30:08.999633 2026] [security2:error] [pid 145170:tid 145378] [client 57.141.18.71:64394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4Djs5KUa9I09SwT6wgAA0FE"]
[Mon Jul 20 07:30:09.030334 2026] [security2:error] [pid 145170:tid 145395] [client 77.110.127.138:50324] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/170\\"XOR(17*if(now()=sysdate(),sleep(15),0))XOR\\"Z"] [unique_id "al4i4Tjs5KUa9I09SwT63wAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:09.150903 2026] [security2:error] [pid 148765:tid 148833] [remote 182.77.62.24:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcAgABTj8"]
[Mon Jul 20 07:30:09.268495 2026] [security2:error] [pid 148765:tid 149014] [client 57.141.18.37:44258] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4Dv8fXmqCm8fNeqb7AABfSw"]
[Mon Jul 20 07:30:09.468188 2026] [security2:error] [pid 148765:tid 148995] [client 14.225.17.146:63116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcDQAAAWo"], referer: http://lutheranphilosopher.com/Test
[Mon Jul 20 07:30:09.632664 2026] [security2:error] [pid 148765:tid 148923] [client 216.73.216.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.mollycahill.com"] [uri "/index.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcHwAAASI"]
[Mon Jul 20 07:30:09.678309 2026] [security2:error] [pid 148765:tid 148972] [client 136.158.60.21:2021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcJQAAAVM"]
[Mon Jul 20 07:30:09.678420 2026] [security2:error] [pid 148765:tid 148972] [client 136.158.60.21:2021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcJQAAAVM"]
[Mon Jul 20 07:30:09.705156 2026] [security2:error] [pid 148765:tid 148889] [remote 182.77.62.24:60674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcJwABcnc"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:30:09.762658 2026] [security2:error] [pid 145170:tid 145339] [client 14.225.17.146:60687] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4i4Tjs5KUa9I09SwT68wAAAKk"], referer: http://thesoloceos.com/Test
[Mon Jul 20 07:30:10.037152 2026] [security2:error] [pid 148765:tid 148980] [client 57.141.18.101:32570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcHAABW0M"]
[Mon Jul 20 07:30:10.062512 2026] [security2:error] [pid 148765:tid 148992] [client 14.225.17.146:59464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4i4Tv8fXmqCm8fNeqb_AAAAWc"], referer: http://ancestralidadytrance.space/Test
[Mon Jul 20 07:30:10.102174 2026] [security2:error] [pid 148765:tid 148948] [client 14.225.17.146:61480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4i4Tv8fXmqCm8fNeqcNwAAATs"], referer: http://dadanetnet.net/Test
[Mon Jul 20 07:30:10.153049 2026] [security2:error] [pid 145170:tid 145304] [client 142.111.152.229:35633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i4jjs5KUa9I09SwT7AwAAAIY"]
[Mon Jul 20 07:30:10.153159 2026] [security2:error] [pid 145170:tid 145304] [client 142.111.152.229:35633] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i4jjs5KUa9I09SwT7AwAAAIY"]
[Mon Jul 20 07:30:10.580889 2026] [security2:error] [pid 148765:tid 148988] [client 3.75.183.99:42720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i4jv8fXmqCm8fNeqcXQAAAWM"]
[Mon Jul 20 07:30:10.581030 2026] [security2:error] [pid 148765:tid 148988] [client 3.75.183.99:42720] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i4jv8fXmqCm8fNeqcXQAAAWM"]
[Mon Jul 20 07:30:10.813403 2026] [security2:error] [pid 148765:tid 148915] [client 14.225.17.146:63198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4i4jv8fXmqCm8fNeqcZAAAARo"], referer: https://thesoloceos.com/Test
[Mon Jul 20 07:30:10.962760 2026] [security2:error] [pid 148765:tid 148957] [client 57.141.18.119:20790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4jv8fXmqCm8fNeqcVQABRBg"]
[Mon Jul 20 07:30:11.390177 2026] [security2:error] [pid 148765:tid 148925] [client 191.202.66.27:50752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i4zv8fXmqCm8fNeqcfgAAASQ"]
[Mon Jul 20 07:30:11.390295 2026] [security2:error] [pid 148765:tid 148925] [client 191.202.66.27:50752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i4zv8fXmqCm8fNeqcfgAAASQ"]
[Mon Jul 20 07:30:11.609142 2026] [security2:error] [pid 145170:tid 145378] [client 57.141.18.116:55608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4zjs5KUa9I09SwT7IwAA0B4"]
[Mon Jul 20 07:30:11.613610 2026] [security2:error] [pid 148765:tid 148949] [client 57.141.18.47:37506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i4zv8fXmqCm8fNeqceAABPCg"]
[Mon Jul 20 07:30:11.664416 2026] [security2:error] [pid 148765:tid 148826] [remote 57.141.18.3:27620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3690896"] [unique_id "al4i4zv8fXmqCm8fNeqcjQABTjg"]
[Mon Jul 20 07:30:11.769176 2026] [security2:error] [pid 145170:tid 145358] [client 157.20.138.62:53724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i4zjs5KUa9I09SwT7NQAAALw"]
[Mon Jul 20 07:30:11.769316 2026] [security2:error] [pid 145170:tid 145358] [client 157.20.138.62:53724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i4zjs5KUa9I09SwT7NQAAALw"]
[Mon Jul 20 07:30:11.824609 2026] [security2:error] [pid 148765:tid 148965] [client 179.127.84.238:52472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i4zv8fXmqCm8fNeqcjwAAAUw"]
[Mon Jul 20 07:30:11.824710 2026] [security2:error] [pid 148765:tid 148965] [client 179.127.84.238:52472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i4zv8fXmqCm8fNeqcjwAAAUw"]
[Mon Jul 20 07:30:11.962672 2026] [security2:error] [pid 148765:tid 149002] [client 143.44.185.218:14179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i4zv8fXmqCm8fNeqclQAAAXE"]
[Mon Jul 20 07:30:11.962788 2026] [security2:error] [pid 148765:tid 149002] [client 143.44.185.218:14179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i4zv8fXmqCm8fNeqclQAAAXE"]
[Mon Jul 20 07:30:12.010493 2026] [security2:error] [pid 148765:tid 148844] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcnwABO0o"]
[Mon Jul 20 07:30:12.010649 2026] [security2:error] [pid 148765:tid 148948] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcnwABO0o"]
[Mon Jul 20 07:30:12.232428 2026] [security2:error] [pid 148765:tid 148871] [remote 81.173.115.7:46982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcpAABR2U"]
[Mon Jul 20 07:30:12.271051 2026] [security2:error] [pid 148765:tid 148930] [client 88.241.67.160:56081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcpQAAASk"]
[Mon Jul 20 07:30:12.271149 2026] [security2:error] [pid 148765:tid 148930] [client 88.241.67.160:56081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcpQAAASk"]
[Mon Jul 20 07:30:12.491083 2026] [security2:error] [pid 148765:tid 148831] [remote 81.173.115.7:46982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcswABND0"], referer: https://cathybuffini.com/wp-login.php
[Mon Jul 20 07:30:12.514543 2026] [core:error] [pid 148765:tid 148967] [client 14.225.17.146:61406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:12.514566 2026] [core:error] [pid 148765:tid 148967] [client 14.225.17.146:61406] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:12.622314 2026] [security2:error] [pid 148765:tid 148947] [client 57.141.18.124:60094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcogABOiU"]
[Mon Jul 20 07:30:12.959333 2026] [security2:error] [pid 148765:tid 149006] [client 57.141.18.114:35448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcrgABdQ0"]
[Mon Jul 20 07:30:13.006643 2026] [security2:error] [pid 148765:tid 148914] [client 202.141.11.99:22172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tv8fXmqCm8fNeqczgAAARk"]
[Mon Jul 20 07:30:13.006830 2026] [security2:error] [pid 148765:tid 148914] [client 202.141.11.99:22172] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tv8fXmqCm8fNeqczgAAARk"]
[Mon Jul 20 07:30:13.078793 2026] [security2:error] [pid 148765:tid 148930] [client 216.173.120.128:50255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4i5Tv8fXmqCm8fNeqczwAAASk"]
[Mon Jul 20 07:30:13.100052 2026] [authz_core:error] [pid 148765:tid 149008] [client 188.166.209.66:64603] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-admin/includes/error_log, referer: binance.com
[Mon Jul 20 07:30:13.148103 2026] [security2:error] [pid 148765:tid 148986] [client 49.47.218.174:52471] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc0wAAAWE"]
[Mon Jul 20 07:30:13.148203 2026] [security2:error] [pid 148765:tid 148986] [client 49.47.218.174:52471] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc0wAAAWE"]
[Mon Jul 20 07:30:13.372054 2026] [security2:error] [pid 148765:tid 148895] [remote 8.217.108.67:14666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc2gABMn0"]
[Mon Jul 20 07:30:13.442429 2026] [security2:error] [pid 148765:tid 148906] [client 14.225.17.146:63054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4i5Dv8fXmqCm8fNeqcpgAAARE"], referer: http://collectingrealestate.com/Test
[Mon Jul 20 07:30:13.487025 2026] [security2:error] [pid 145170:tid 145233] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tjs5KUa9I09SwT7cAAAojs"]
[Mon Jul 20 07:30:13.487236 2026] [security2:error] [pid 145170:tid 145332] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tjs5KUa9I09SwT7cAAAojs"]
[Mon Jul 20 07:30:13.649408 2026] [security2:error] [pid 148765:tid 148974] [client 57.141.18.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc5QAAAVU"]
[Mon Jul 20 07:30:13.860793 2026] [security2:error] [pid 148765:tid 148996] [client 117.211.236.168:64578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc6gAAAWs"]
[Mon Jul 20 07:30:13.860884 2026] [security2:error] [pid 148765:tid 148996] [client 117.211.236.168:64578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc6gAAAWs"]
[Mon Jul 20 07:30:13.879394 2026] [security2:error] [pid 145170:tid 145403] [client 14.225.17.146:63094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4i5Tjs5KUa9I09SwT7ggAAAOk"], referer: http://fkconstructionfunding.com/Test
[Mon Jul 20 07:30:13.930771 2026] [security2:error] [pid 148765:tid 148918] [client 85.206.128.219:35898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.128.206.85.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/kitchem/kitchem.php"] [unique_id "al4i5Tv8fXmqCm8fNeqc7QAAAR0"]
[Mon Jul 20 07:30:14.046873 2026] [security2:error] [pid 145170:tid 145421] [client 50.116.65.227:20222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4i5jjs5KUa9I09SwT7nwAAAPs"]
[Mon Jul 20 07:30:14.058532 2026] [security2:error] [pid 145170:tid 145348] [client 50.116.65.227:20228] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4i5jjs5KUa9I09SwT7oAAAALI"]
[Mon Jul 20 07:30:14.256003 2026] [security2:error] [pid 145170:tid 145315] [client 154.192.123.127:17048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i5jjs5KUa9I09SwT7rAAAAJE"]
[Mon Jul 20 07:30:14.256158 2026] [security2:error] [pid 145170:tid 145315] [client 154.192.123.127:17048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i5jjs5KUa9I09SwT7rAAAAJE"]
[Mon Jul 20 07:30:14.624871 2026] [autoindex:error] [pid 148765:tid 148876] [remote 136.66.235.77:63027] AH01276: Cannot serve directory /home2/tbdlhomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.tbd.lho.mybluehost.me
[Mon Jul 20 07:30:14.846876 2026] [security2:error] [pid 145170:tid 145386] [client 14.225.17.146:63003] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4i5jjs5KUa9I09SwT7sAAAANg"], referer: http://mollycahill.com/Test
[Mon Jul 20 07:30:14.915377 2026] [security2:error] [pid 148765:tid 148926] [client 36.93.152.155:63925] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i5jv8fXmqCm8fNeqdBgAAASU"]
[Mon Jul 20 07:30:14.915476 2026] [security2:error] [pid 148765:tid 148926] [client 36.93.152.155:63925] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i5jv8fXmqCm8fNeqdBgAAASU"]
[Mon Jul 20 07:30:15.034599 2026] [security2:error] [pid 148765:tid 148884] [remote 8.217.108.67:14666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i5zv8fXmqCm8fNeqdDgABFnI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:30:15.198767 2026] [security2:error] [pid 145170:tid 145346] [client 14.225.17.146:63104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4i5zjs5KUa9I09SwT7zgAAALA"], referer: http://39ishlife.com/Test
[Mon Jul 20 07:30:15.470693 2026] [security2:error] [pid 148765:tid 148917] [client 13.232.231.177:15300] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4i5zv8fXmqCm8fNeqdLAAAARw"]
[Mon Jul 20 07:30:15.574024 2026] [security2:error] [pid 148765:tid 148937] [client 3.75.183.99:55298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i5zv8fXmqCm8fNeqdMgAAATA"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:15.649143 2026] [security2:error] [pid 148765:tid 148909] [client 201.27.111.74:58181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i5zv8fXmqCm8fNeqdNgAAARQ"]
[Mon Jul 20 07:30:15.649261 2026] [security2:error] [pid 148765:tid 148909] [client 201.27.111.74:58181] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i5zv8fXmqCm8fNeqdNgAAARQ"]
[Mon Jul 20 07:30:15.682293 2026] [security2:error] [pid 148765:tid 148913] [client 57.141.18.68:30994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i5zv8fXmqCm8fNeqdEwABGFI"]
[Mon Jul 20 07:30:15.743253 2026] [security2:error] [pid 145170:tid 145338] [client 57.141.18.24:46654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i5zjs5KUa9I09SwT70AAAqHw"]
[Mon Jul 20 07:30:15.947962 2026] [security2:error] [pid 145170:tid 145408] [client 14.225.17.146:63381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4i5jjs5KUa9I09SwT7swAAAO4"], referer: http://olearyplumbingllc.com/Test
[Mon Jul 20 07:30:15.974912 2026] [security2:error] [pid 148765:tid 149006] [client 57.141.18.31:42438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i5zv8fXmqCm8fNeqdKAABdXg"]
[Mon Jul 20 07:30:15.986536 2026] [security2:error] [pid 148765:tid 148962] [client 63.176.132.15:64842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i5zv8fXmqCm8fNeqdRwAAAUk"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:16.026941 2026] [security2:error] [pid 148765:tid 149003] [client 63.176.132.15:64858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdSgAAAXI"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:16.113129 2026] [security2:error] [pid 148765:tid 148933] [client 18.184.179.151:10236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdSwAAASw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:16.218673 2026] [security2:error] [pid 148765:tid 149025] [client 14.225.17.146:60708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdTgAAAYg"], referer: https://39ishlife.com/Test
[Mon Jul 20 07:30:16.254283 2026] [security2:error] [pid 148765:tid 148928] [client 3.75.183.99:55306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdVAAAASc"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:16.264204 2026] [security2:error] [pid 148765:tid 148995] [client 103.106.165.44:53802] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdVQAAAWo"]
[Mon Jul 20 07:30:16.264308 2026] [security2:error] [pid 148765:tid 148995] [client 103.106.165.44:53802] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdVQAAAWo"]
[Mon Jul 20 07:30:16.372162 2026] [security2:error] [pid 145170:tid 145404] [client 103.176.215.66:57505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i6Djs5KUa9I09SwT79QAAAOo"]
[Mon Jul 20 07:30:16.372541 2026] [security2:error] [pid 145170:tid 145404] [client 103.176.215.66:57505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i6Djs5KUa9I09SwT79QAAAOo"]
[Mon Jul 20 07:30:16.406803 2026] [security2:error] [pid 148765:tid 148973] [client 57.141.18.46:48154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i5zv8fXmqCm8fNeqdPQABVBI"]
[Mon Jul 20 07:30:16.570829 2026] [security2:error] [pid 148765:tid 148992] [client 18.184.179.151:10240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdZgAAAWc"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:16.632191 2026] [security2:error] [pid 145170:tid 145336] [client 3.67.192.83:43412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i6Djs5KUa9I09SwT7_QAAAKY"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:16.654361 2026] [security2:error] [pid 148765:tid 148964] [client 57.141.18.123:60034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdTAABSwc"]
[Mon Jul 20 07:30:16.662285 2026] [security2:error] [pid 148765:tid 148935] [client 43.205.139.3:11950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdcAAAAS4"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:30:16.792492 2026] [security2:error] [pid 148765:tid 148969] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdagAAAVA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:16.982107 2026] [security2:error] [pid 148765:tid 148918] [client 13.232.231.177:16746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdhQAAAR0"]
[Mon Jul 20 07:30:16.982196 2026] [security2:error] [pid 148765:tid 148918] [client 13.232.231.177:16746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdhQAAAR0"]
[Mon Jul 20 07:30:17.160952 2026] [security2:error] [pid 148765:tid 148927] [client 14.225.17.146:60716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdTQAAASY"], referer: http://travelbyfire.com/Test
[Mon Jul 20 07:30:17.359092 2026] [security2:error] [pid 145170:tid 145348] [client 34.221.76.50:28982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i6Tjs5KUa9I09SwT8IAAAALI"]
[Mon Jul 20 07:30:17.483246 2026] [security2:error] [pid 148765:tid 149006] [client 57.141.18.43:53548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i6Dv8fXmqCm8fNeqdegABdWY"]
[Mon Jul 20 07:30:17.656038 2026] [security2:error] [pid 148765:tid 148968] [client 45.3.55.108:17427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i6Tv8fXmqCm8fNeqdsAAAAU8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:18.046851 2026] [security2:error] [pid 148765:tid 149002] [client 14.225.17.146:63447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4i6Tv8fXmqCm8fNeqdxQAAAXE"], referer: https://travelbyfire.com/Test
[Mon Jul 20 07:30:18.074163 2026] [security2:error] [pid 148765:tid 148950] [client 104.234.53.65:33123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4i6jv8fXmqCm8fNeqdzwAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:18.084308 2026] [core:error] [pid 148765:tid 148982] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:18.084325 2026] [core:error] [pid 148765:tid 148982] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:18.133097 2026] [security2:error] [pid 148765:tid 149013] [client 144.16.21.149:25333] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i6jv8fXmqCm8fNeqd1AAAAXw"]
[Mon Jul 20 07:30:18.133324 2026] [security2:error] [pid 148765:tid 149013] [client 144.16.21.149:25333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i6jv8fXmqCm8fNeqd1AAAAXw"]
[Mon Jul 20 07:30:18.232766 2026] [security2:error] [pid 148765:tid 148933] [client 52.59.238.198:31900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i6jv8fXmqCm8fNeqd1QAAASw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:18.271218 2026] [security2:error] [pid 148765:tid 148967] [client 63.176.132.15:27388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i6jv8fXmqCm8fNeqd1gAAAU4"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:18.350266 2026] [security2:error] [pid 148765:tid 148995] [client 217.181.91.200:48017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i6jv8fXmqCm8fNeqd2gAAAWo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:18.710126 2026] [security2:error] [pid 148765:tid 148918] [client 49.37.242.14:62512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i6jv8fXmqCm8fNeqd7wAAAR0"]
[Mon Jul 20 07:30:18.710263 2026] [security2:error] [pid 148765:tid 148918] [client 49.37.242.14:62512] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i6jv8fXmqCm8fNeqd7wAAAR0"]
[Mon Jul 20 07:30:18.713077 2026] [security2:error] [pid 145170:tid 145368] [client 193.36.225.170:62073] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4i6jjs5KUa9I09SwT8VQAAAMY"]
[Mon Jul 20 07:30:18.727972 2026] [security2:error] [pid 145170:tid 145337] [client 172.245.102.63:31623] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4i6jjs5KUa9I09SwT8VAAAAKc"]
[Mon Jul 20 07:30:18.778683 2026] [security2:error] [pid 145170:tid 145362] [client 114.119.128.23:52451] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "thierry-henry.fr"] [uri "/page/37/"] [unique_id "al4i6jjs5KUa9I09SwT8YwAAAMA"], referer: https://thierry-henry.fr/amp/page/37
[Mon Jul 20 07:30:18.792325 2026] [security2:error] [pid 145170:tid 145335] [client 63.176.132.15:27390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i6jjs5KUa9I09SwT8ZQAAAKU"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:18.841089 2026] [security2:error] [pid 148765:tid 148990] [client 3.67.192.83:43434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i6jv8fXmqCm8fNeqd-AAAAWU"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:18.996191 2026] [security2:error] [pid 148765:tid 148977] [client 104.207.60.184:24127] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i6jv8fXmqCm8fNeqeAQAAAVg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:19.329497 2026] [security2:error] [pid 145170:tid 145394] [client 57.141.18.53:27420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i6jjs5KUa9I09SwT8XAAA4H0"]
[Mon Jul 20 07:30:19.488841 2026] [security2:error] [pid 148765:tid 149025] [client 63.179.149.246:55950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i6zv8fXmqCm8fNeqeDQAAAYg"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:19.716353 2026] [security2:error] [pid 145170:tid 145370] [client 57.141.18.110:42236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i6jjs5KUa9I09SwT8bAAAyCE"]
[Mon Jul 20 07:30:19.774679 2026] [security2:error] [pid 148765:tid 148927] [client 14.225.17.146:57838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4i6jv8fXmqCm8fNeqd7AAAASY"], referer: http://ravmike.com/Test
[Mon Jul 20 07:30:19.956163 2026] [autoindex:error] [pid 148765:tid 148899] [client 43.153.96.233:0] AH01276: Cannot serve directory /home4/elemeph8/public_html/elementfix/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:30:20.033291 2026] [security2:error] [pid 148765:tid 149012] [client 63.176.132.15:27418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeMQAAAXs"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:20.315947 2026] [security2:error] [pid 148765:tid 148997] [client 136.158.60.21:3407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeNgAAAWw"]
[Mon Jul 20 07:30:20.316042 2026] [security2:error] [pid 148765:tid 148997] [client 136.158.60.21:3407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeNgAAAWw"]
[Mon Jul 20 07:30:20.332045 2026] [security2:error] [pid 148765:tid 148947] [client 158.173.166.181:52963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeNwAAATo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:30:20.660319 2026] [security2:error] [pid 148765:tid 148920] [client 57.141.18.56:29600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i6zv8fXmqCm8fNeqeHgABHy0"]
[Mon Jul 20 07:30:20.708472 2026] [security2:error] [pid 148765:tid 148943] [client 142.111.152.59:52509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeQwAAATY"]
[Mon Jul 20 07:30:20.708593 2026] [security2:error] [pid 148765:tid 148943] [client 142.111.152.59:52509] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeQwAAATY"]
[Mon Jul 20 07:30:20.733924 2026] [security2:error] [pid 145170:tid 145313] [client 14.225.17.146:62808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4i7Djs5KUa9I09SwT8sQAAAI8"], referer: https://ravmike.com/Test
[Mon Jul 20 07:30:20.971470 2026] [security2:error] [pid 148765:tid 148942] [client 57.141.18.105:22634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeMgABNXs"]
[Mon Jul 20 07:30:20.984856 2026] [security2:error] [pid 145170:tid 145394] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i7Djs5KUa9I09SwT8twAAAOA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:21.112865 2026] [security2:error] [pid 148765:tid 148973] [client 63.176.132.15:27428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i7Tv8fXmqCm8fNeqeXgAAAVQ"]
[Mon Jul 20 07:30:21.112989 2026] [security2:error] [pid 148765:tid 148973] [client 63.176.132.15:27428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i7Tv8fXmqCm8fNeqeXgAAAVQ"]
[Mon Jul 20 07:30:21.162865 2026] [security2:error] [pid 145170:tid 145284] [remote 188.40.28.4:52098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i7Tjs5KUa9I09SwT8wgAA9W4"]
[Mon Jul 20 07:30:21.163196 2026] [security2:error] [pid 145170:tid 145415] [client 188.40.28.4:52098] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i7Tjs5KUa9I09SwT8wgAA9W4"]
[Mon Jul 20 07:30:21.255495 2026] [security2:error] [pid 145170:tid 145421] [client 57.141.18.5:24270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i7Djs5KUa9I09SwT8mwAA-xY"]
[Mon Jul 20 07:30:21.503717 2026] [security2:error] [pid 145170:tid 145311] [client 57.141.18.119:42804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i7Djs5KUa9I09SwT8oQAAjQ0"]
[Mon Jul 20 07:30:22.012121 2026] [security2:error] [pid 148765:tid 148799] [remote 192.241.143.148:48876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqegQABCh0"]
[Mon Jul 20 07:30:22.012305 2026] [security2:error] [pid 148765:tid 148899] [client 192.241.143.148:48876] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "oqw.bur.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqegQABCh0"]
[Mon Jul 20 07:30:22.028507 2026] [security2:error] [pid 145170:tid 145335] [client 191.202.66.27:51249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i7jjs5KUa9I09SwT85QAAAKU"]
[Mon Jul 20 07:30:22.028633 2026] [security2:error] [pid 145170:tid 145335] [client 191.202.66.27:51249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i7jjs5KUa9I09SwT85QAAAKU"]
[Mon Jul 20 07:30:22.062453 2026] [security2:error] [pid 148765:tid 148900] [client 66.187.5.19:60112] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpanel.onewingpictures.com"] [uri "/"] [unique_id "al4i7jv8fXmqCm8fNeqehAAAAQs"]
[Mon Jul 20 07:30:22.190764 2026] [security2:error] [pid 145170:tid 145370] [client 57.141.18.35:37148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i7Tjs5KUa9I09SwT8wQAAyAo"]
[Mon Jul 20 07:30:22.433212 2026] [security2:error] [pid 148765:tid 148916] [client 157.20.138.62:54301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqejwAAARs"]
[Mon Jul 20 07:30:22.434222 2026] [security2:error] [pid 148765:tid 148916] [client 157.20.138.62:54301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqejwAAARs"]
[Mon Jul 20 07:30:22.451287 2026] [security2:error] [pid 148765:tid 148998] [client 179.127.84.238:53003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqekwAAAW0"]
[Mon Jul 20 07:30:22.451400 2026] [security2:error] [pid 148765:tid 148998] [client 179.127.84.238:53003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqekwAAAW0"]
[Mon Jul 20 07:30:22.636324 2026] [security2:error] [pid 145170:tid 145406] [client 57.141.18.97:39516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i7Tjs5KUa9I09SwT83QAA7DU"]
[Mon Jul 20 07:30:22.752815 2026] [security2:error] [pid 145170:tid 145348] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4i7jjs5KUa9I09SwT88AAAsj4"], referer: http://ardhalwafaa.com/Test
[Mon Jul 20 07:30:22.767288 2026] [security2:error] [pid 148765:tid 148938] [client 14.225.17.146:62121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4i7Dv8fXmqCm8fNeqeTQAAATE"], referer: http://fineartsfactory.net/Test
[Mon Jul 20 07:30:22.787484 2026] [security2:error] [pid 148765:tid 148837] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqepAABHkM"]
[Mon Jul 20 07:30:22.787602 2026] [security2:error] [pid 148765:tid 148919] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqepAABHkM"]
[Mon Jul 20 07:30:22.832515 2026] [security2:error] [pid 148765:tid 149013] [client 104.234.53.94:64977] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4i7jv8fXmqCm8fNeqepQAAAXw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:22.887772 2026] [security2:error] [pid 148765:tid 148971] [client 88.241.67.160:55120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqepgAAAVI"]
[Mon Jul 20 07:30:22.888236 2026] [security2:error] [pid 148765:tid 148971] [client 88.241.67.160:55120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i7jv8fXmqCm8fNeqepgAAAVI"]
[Mon Jul 20 07:30:23.687657 2026] [security2:error] [pid 145170:tid 145334] [client 49.47.218.174:53013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i7zjs5KUa9I09SwT9GwAAAKQ"]
[Mon Jul 20 07:30:23.688144 2026] [security2:error] [pid 145170:tid 145334] [client 49.47.218.174:53013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i7zjs5KUa9I09SwT9GwAAAKQ"]
[Mon Jul 20 07:30:23.845723 2026] [security2:error] [pid 148765:tid 148823] [remote 160.187.68.132:40500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i7zv8fXmqCm8fNeqexAABXjU"]
[Mon Jul 20 07:30:23.845956 2026] [security2:error] [pid 148765:tid 148983] [client 160.187.68.132:40500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i7zv8fXmqCm8fNeqexAABXjU"]
[Mon Jul 20 07:30:24.159764 2026] [security2:error] [pid 145170:tid 145383] [client 14.225.17.146:62540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4i7jjs5KUa9I09SwT8_wAAANU"], referer: http://ghivs.com/Test
[Mon Jul 20 07:30:24.357238 2026] [security2:error] [pid 145170:tid 145430] [client 74.208.214.194:52306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4i8Djs5KUa9I09SwT9OAAAAQQ"]
[Mon Jul 20 07:30:24.740849 2026] [security2:error] [pid 145170:tid 145387] [client 143.44.185.218:15531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Djs5KUa9I09SwT9SAAAANk"]
[Mon Jul 20 07:30:24.740970 2026] [security2:error] [pid 145170:tid 145387] [client 143.44.185.218:15531] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Djs5KUa9I09SwT9SAAAANk"]
[Mon Jul 20 07:30:24.815671 2026] [security2:error] [pid 145170:tid 145304] [client 154.192.123.127:17439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Djs5KUa9I09SwT9TAAAAIY"]
[Mon Jul 20 07:30:24.815845 2026] [security2:error] [pid 145170:tid 145304] [client 154.192.123.127:17439] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Djs5KUa9I09SwT9TAAAAIY"]
[Mon Jul 20 07:30:24.975178 2026] [security2:error] [pid 148765:tid 149004] [client 57.141.18.54:27860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i7zv8fXmqCm8fNeqexgABc1k"]
[Mon Jul 20 07:30:25.042780 2026] [security2:error] [pid 145170:tid 145274] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tjs5KUa9I09SwT9WgAApWQ"]
[Mon Jul 20 07:30:25.042934 2026] [security2:error] [pid 145170:tid 145335] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tjs5KUa9I09SwT9WgAApWQ"]
[Mon Jul 20 07:30:25.230431 2026] [security2:error] [pid 148765:tid 148948] [client 13.233.207.33:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tv8fXmqCm8fNeqe8QAAATs"]
[Mon Jul 20 07:30:25.230531 2026] [security2:error] [pid 148765:tid 148948] [client 13.233.207.33:48882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tv8fXmqCm8fNeqe8QAAATs"]
[Mon Jul 20 07:30:25.362238 2026] [security2:error] [pid 148765:tid 148925] [client 45.157.112.60:47707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i8Tv8fXmqCm8fNeqe-QAAASQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:30:25.463485 2026] [security2:error] [pid 148765:tid 149020] [client 36.93.152.155:64452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tv8fXmqCm8fNeqe_AAAAYM"]
[Mon Jul 20 07:30:25.463637 2026] [security2:error] [pid 148765:tid 149020] [client 36.93.152.155:64452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tv8fXmqCm8fNeqe_AAAAYM"]
[Mon Jul 20 07:30:25.571791 2026] [security2:error] [pid 145170:tid 145386] [client 117.211.236.168:65312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tjs5KUa9I09SwT9bwAAANg"]
[Mon Jul 20 07:30:25.571867 2026] [security2:error] [pid 145170:tid 145386] [client 117.211.236.168:65312] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tjs5KUa9I09SwT9bwAAANg"]
[Mon Jul 20 07:30:25.691710 2026] [security2:error] [pid 148765:tid 148916] [client 63.179.149.246:59046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i8Tv8fXmqCm8fNeqfBgAAARs"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:25.779274 2026] [security2:error] [pid 145170:tid 145338] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i8Tjs5KUa9I09SwT9cAAAAKg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:25.794470 2026] [security2:error] [pid 145170:tid 145385] [client 116.74.65.235:59144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4i8Tjs5KUa9I09SwT9cQAAANc"]
[Mon Jul 20 07:30:26.027014 2026] [security2:error] [pid 148765:tid 148908] [client 57.141.18.85:23106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i8Dv8fXmqCm8fNeqe5AABE08"]
[Mon Jul 20 07:30:26.089325 2026] [security2:error] [pid 148765:tid 148984] [client 14.225.17.146:64938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4i8Tv8fXmqCm8fNeqe9wAAAV8"]
[Mon Jul 20 07:30:26.117115 2026] [security2:error] [pid 148765:tid 148970] [client 201.27.111.74:58696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i8jv8fXmqCm8fNeqfHgAAAVE"]
[Mon Jul 20 07:30:26.119313 2026] [security2:error] [pid 148765:tid 148970] [client 201.27.111.74:58696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i8jv8fXmqCm8fNeqfHgAAAVE"]
[Mon Jul 20 07:30:26.399960 2026] [security2:error] [pid 145170:tid 145421] [client 57.141.18.73:30102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i8Tjs5KUa9I09SwT9YwAA-yc"]
[Mon Jul 20 07:30:26.549287 2026] [security2:error] [pid 148765:tid 148782] [remote 100.42.189.89:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4i8jv8fXmqCm8fNeqfMAABIQw"]
[Mon Jul 20 07:30:26.724555 2026] [security2:error] [pid 148765:tid 148963] [client 216.173.120.129:44543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4i8jv8fXmqCm8fNeqfMgAAAUo"]
[Mon Jul 20 07:30:26.770207 2026] [security2:error] [pid 145170:tid 145405] [client 50.116.65.227:46912] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4i8jjs5KUa9I09SwT9mQAAAOs"]
[Mon Jul 20 07:30:26.782567 2026] [security2:error] [pid 148765:tid 149014] [client 50.116.65.227:46930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4i8jv8fXmqCm8fNeqfOQAAAX0"]
[Mon Jul 20 07:30:26.786590 2026] [security2:error] [pid 148765:tid 148807] [remote 100.42.189.89:53648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4i8jv8fXmqCm8fNeqfOgABKCU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:30:26.793637 2026] [security2:error] [pid 145170:tid 145343] [client 14.225.17.146:51260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4i8jjs5KUa9I09SwT9lAAAAK0"], referer: http://inspirespublishing.com/Test
[Mon Jul 20 07:30:26.880294 2026] [security2:error] [pid 145170:tid 145370] [client 103.106.165.44:54290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i8jjs5KUa9I09SwT9oQAAAMg"]
[Mon Jul 20 07:30:26.880434 2026] [security2:error] [pid 145170:tid 145370] [client 103.106.165.44:54290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i8jjs5KUa9I09SwT9oQAAAMg"]
[Mon Jul 20 07:30:26.972872 2026] [security2:error] [pid 148765:tid 148911] [client 103.176.215.66:58044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i8jv8fXmqCm8fNeqfQgAAARY"]
[Mon Jul 20 07:30:26.973012 2026] [security2:error] [pid 148765:tid 148911] [client 103.176.215.66:58044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i8jv8fXmqCm8fNeqfQgAAARY"]
[Mon Jul 20 07:30:27.225828 2026] [security2:error] [pid 148765:tid 149025] [client 14.225.17.146:64849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4i8zv8fXmqCm8fNeqfSwAAAYg"], referer: http://xp-design.co/Test
[Mon Jul 20 07:30:27.689359 2026] [security2:error] [pid 148765:tid 148943] [client 57.141.18.4:53234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i8jv8fXmqCm8fNeqfMQABNj0"]
[Mon Jul 20 07:30:27.810013 2026] [security2:error] [pid 148765:tid 148875] [remote 8.217.108.67:21130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4i8zv8fXmqCm8fNeqfYwABbWk"]
[Mon Jul 20 07:30:27.947137 2026] [security2:error] [pid 145170:tid 145382] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4i8zjs5KUa9I09SwT9wgAA1Co"]
[Mon Jul 20 07:30:27.981612 2026] [security2:error] [pid 148765:tid 148931] [client 14.225.17.146:51243] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4i8zv8fXmqCm8fNeqfXQAAASo"], referer: http://idigress.studio/Test
[Mon Jul 20 07:30:28.035172 2026] [security2:error] [pid 145170:tid 145349] [client 57.141.18.12:46996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i8jjs5KUa9I09SwT9pgAAs3s"]
[Mon Jul 20 07:30:28.165587 2026] [security2:error] [pid 148765:tid 148923] [client 14.225.17.146:51221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4i8jv8fXmqCm8fNeqfHQAAASI"], referer: http://webgardensbypaula.com/Test
[Mon Jul 20 07:30:28.306345 2026] [security2:error] [pid 148765:tid 148787] [remote 8.217.108.67:21130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfggABaBE"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:30:28.818955 2026] [security2:error] [pid 148765:tid 148939] [client 144.16.21.149:25333] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfqQAAATI"]
[Mon Jul 20 07:30:28.819089 2026] [security2:error] [pid 148765:tid 148939] [client 144.16.21.149:25333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfqQAAATI"]
[Mon Jul 20 07:30:28.876715 2026] [security2:error] [pid 148765:tid 148940] [client 41.42.200.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfogAAATM"]
[Mon Jul 20 07:30:29.297539 2026] [security2:error] [pid 148765:tid 148934] [client 57.141.18.54:63456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfeAABLXo"]
[Mon Jul 20 07:30:29.442292 2026] [security2:error] [pid 148765:tid 148949] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i9Tv8fXmqCm8fNeqfxgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:29.758510 2026] [security2:error] [pid 148765:tid 148971] [client 57.141.18.102:44224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfmQABUhY"]
[Mon Jul 20 07:30:29.860798 2026] [security2:error] [pid 148765:tid 148977] [client 65.111.28.250:51017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i9Tv8fXmqCm8fNeqf4AAAAVg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:29.885522 2026] [security2:error] [pid 148765:tid 148985] [client 57.141.18.105:56862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i9Dv8fXmqCm8fNeqfqwABYGc"]
[Mon Jul 20 07:30:30.100817 2026] [security2:error] [pid 145170:tid 145315] [client 127.0.0.1:39034] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4i9jjs5KUa9I09SwT-FQAAAJE"], referer: https://www.facebook.com/
[Mon Jul 20 07:30:30.206174 2026] [security2:error] [pid 148765:tid 148913] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4i9jv8fXmqCm8fNeqf7QABGGI"]
[Mon Jul 20 07:30:30.448633 2026] [security2:error] [pid 148765:tid 149003] [client 104.234.53.50:46025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4i9jv8fXmqCm8fNeqf-wAAAXI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:30.537425 2026] [security2:error] [pid 145170:tid 145355] [client 14.225.17.146:56005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4i9Tjs5KUa9I09SwT9-gAAALk"]
[Mon Jul 20 07:30:30.699875 2026] [security2:error] [pid 148765:tid 148820] [remote 57.141.18.37:29454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 37.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4i9jv8fXmqCm8fNeqgDgABYDI"]
[Mon Jul 20 07:30:31.183289 2026] [security2:error] [pid 145170:tid 145391] [client 20.65.153.128:44936] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.65.229"] [uri "/index.cgi"] [unique_id "al4i9zjs5KUa9I09SwT-MwAAAN0"]
[Mon Jul 20 07:30:31.184856 2026] [security2:error] [pid 148765:tid 149008] [client 104.234.53.67:61817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4i9zv8fXmqCm8fNeqgIQAAAXc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:31.215235 2026] [security2:error] [pid 145170:tid 145331] [client 136.158.60.21:4942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i9zjs5KUa9I09SwT-NQAAAKE"]
[Mon Jul 20 07:30:31.215350 2026] [security2:error] [pid 145170:tid 145331] [client 136.158.60.21:4942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4i9zjs5KUa9I09SwT-NQAAAKE"]
[Mon Jul 20 07:30:31.318130 2026] [security2:error] [pid 145170:tid 145416] [client 142.111.152.54:55233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i9zjs5KUa9I09SwT-NwAAAPY"]
[Mon Jul 20 07:30:31.318277 2026] [security2:error] [pid 145170:tid 145416] [client 142.111.152.54:55233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i9zjs5KUa9I09SwT-NwAAAPY"]
[Mon Jul 20 07:30:31.610906 2026] [security2:error] [pid 145170:tid 145262] [remote 72.167.132.114:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4i9zjs5KUa9I09SwT-TwAA81g"]
[Mon Jul 20 07:30:31.840322 2026] [security2:error] [pid 145170:tid 145207] [remote 72.167.132.114:56926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4i9zjs5KUa9I09SwT-VwAA-yE"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:30:31.863271 2026] [security2:error] [pid 145170:tid 145233] [remote 31.42.184.154:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.184.42.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4i9zjs5KUa9I09SwT-WAAAvDs"]
[Mon Jul 20 07:30:31.953725 2026] [security2:error] [pid 148765:tid 148928] [client 57.141.18.23:20242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i9jv8fXmqCm8fNeqgFAABJwU"]
[Mon Jul 20 07:30:32.067593 2026] [security2:error] [pid 148765:tid 149019] [client 158.173.89.95:50359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i-Dv8fXmqCm8fNeqgQgAAAYI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:30:32.115874 2026] [security2:error] [pid 145170:tid 145257] [remote 31.42.184.154:43706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.184.42.31.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4i-Djs5KUa9I09SwT-ZQAAzVM"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 07:30:32.400571 2026] [security2:error] [pid 145170:tid 145398] [client 57.141.18.121:59586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i9zjs5KUa9I09SwT-SAAA5HY"]
[Mon Jul 20 07:30:32.429051 2026] [security2:error] [pid 145170:tid 145382] [client 49.37.242.14:63079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Djs5KUa9I09SwT-awAAANQ"]
[Mon Jul 20 07:30:32.429167 2026] [security2:error] [pid 145170:tid 145382] [client 49.37.242.14:63079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Djs5KUa9I09SwT-awAAANQ"]
[Mon Jul 20 07:30:32.524854 2026] [security2:error] [pid 145170:tid 145383] [client 54.244.177.189:22966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4i-Djs5KUa9I09SwT-cQAAANU"]
[Mon Jul 20 07:30:32.550090 2026] [security2:error] [pid 148765:tid 149025] [client 14.225.17.146:64496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4i-Dv8fXmqCm8fNeqgTgAAAYg"], referer: http://alrowad-hub.net/Test
[Mon Jul 20 07:30:32.572921 2026] [security2:error] [pid 145170:tid 145430] [client 3.78.190.80:10772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4i9zjs5KUa9I09SwT-UAAAAQQ"]
[Mon Jul 20 07:30:32.663964 2026] [security2:error] [pid 148765:tid 148989] [client 191.202.66.27:51743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i-Dv8fXmqCm8fNeqgXAAAAWQ"]
[Mon Jul 20 07:30:32.665409 2026] [security2:error] [pid 148765:tid 148989] [client 191.202.66.27:51743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4i-Dv8fXmqCm8fNeqgXAAAAWQ"]
[Mon Jul 20 07:30:32.828651 2026] [security2:error] [pid 148765:tid 149022] [client 57.141.18.57:51124] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i9zv8fXmqCm8fNeqgNgABhSM"]
[Mon Jul 20 07:30:33.013858 2026] [security2:error] [pid 148765:tid 148922] [client 157.20.138.62:54871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgaAAAASE"]
[Mon Jul 20 07:30:33.014025 2026] [security2:error] [pid 148765:tid 148922] [client 157.20.138.62:54871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgaAAAASE"]
[Mon Jul 20 07:30:33.156926 2026] [security2:error] [pid 145170:tid 145404] [client 179.127.84.238:53534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tjs5KUa9I09SwT-kQAAAOo"]
[Mon Jul 20 07:30:33.157076 2026] [security2:error] [pid 145170:tid 145404] [client 179.127.84.238:53534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tjs5KUa9I09SwT-kQAAAOo"]
[Mon Jul 20 07:30:33.191445 2026] [security2:error] [pid 145170:tid 145387] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i-Djs5KUa9I09SwT-hQAAANk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:33.335910 2026] [security2:error] [pid 145170:tid 145342] [client 14.225.17.146:49380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4i-Djs5KUa9I09SwT-YgAAAKw"], referer: http://keywayconstructionclt.com/Test
[Mon Jul 20 07:30:33.344178 2026] [security2:error] [pid 145170:tid 145187] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tjs5KUa9I09SwT-mAAA0A0"]
[Mon Jul 20 07:30:33.344301 2026] [security2:error] [pid 145170:tid 145378] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tjs5KUa9I09SwT-mAAA0A0"]
[Mon Jul 20 07:30:33.499900 2026] [security2:error] [pid 148765:tid 148951] [client 88.241.67.160:57257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgewAAAT4"]
[Mon Jul 20 07:30:33.500260 2026] [security2:error] [pid 148765:tid 148951] [client 88.241.67.160:57257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgewAAAT4"]
[Mon Jul 20 07:30:33.669994 2026] [security2:error] [pid 148765:tid 148909] [client 74.7.227.179:36598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgfgABFFU"], referer: https://tejasenvironmental.com/p=982767
[Mon Jul 20 07:30:33.992941 2026] [security2:error] [pid 148765:tid 149022] [client 98.159.234.160:39919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgnAAAAYU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:30:34.055430 2026] [security2:error] [pid 148765:tid 148989] [client 202.141.11.99:58166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4i-jv8fXmqCm8fNeqgoAAAAWQ"]
[Mon Jul 20 07:30:34.056766 2026] [security2:error] [pid 148765:tid 148989] [client 202.141.11.99:58166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4i-jv8fXmqCm8fNeqgoAAAAWQ"]
[Mon Jul 20 07:30:34.103595 2026] [security2:error] [pid 148765:tid 148935] [client 14.225.17.146:51055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgkQAAAS4"], referer: http://swafforddetailing.com/Test
[Mon Jul 20 07:30:34.119361 2026] [security2:error] [pid 148765:tid 148950] [client 104.234.53.58:27203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4i-jv8fXmqCm8fNeqgqAAAAT0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:34.359430 2026] [security2:error] [pid 148765:tid 148970] [client 49.47.218.174:53545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i-jv8fXmqCm8fNeqgrwAAAVE"]
[Mon Jul 20 07:30:34.359542 2026] [security2:error] [pid 148765:tid 148970] [client 49.47.218.174:53545] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4i-jv8fXmqCm8fNeqgrwAAAVE"]
[Mon Jul 20 07:30:34.530630 2026] [security2:error] [pid 148765:tid 148837] [remote 20.89.80.94:31296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4i-jv8fXmqCm8fNeqgsAABT0M"]
[Mon Jul 20 07:30:34.571338 2026] [security2:error] [pid 145170:tid 145416] [client 181.42.30.224:3716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4i-jjs5KUa9I09SwT-uwAAAPY"]
[Mon Jul 20 07:30:34.899253 2026] [security2:error] [pid 148765:tid 148922] [client 57.141.18.90:48112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i-Tv8fXmqCm8fNeqgkAABISw"]
[Mon Jul 20 07:30:34.908344 2026] [security2:error] [pid 148765:tid 148862] [remote 20.89.80.94:31296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "phillipbloch.com"] [uri "/wp-login.php"] [unique_id "al4i-jv8fXmqCm8fNeqgxgABR1w"], referer: https://phillipbloch.com/wp-login.php
[Mon Jul 20 07:30:35.143094 2026] [security2:error] [pid 145170:tid 145401] [client 57.141.18.115:46776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i-jjs5KUa9I09SwT-sgAA50k"]
[Mon Jul 20 07:30:35.327992 2026] [security2:error] [pid 148765:tid 149008] [client 154.192.123.127:17837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i-zv8fXmqCm8fNeqg2QAAAXc"]
[Mon Jul 20 07:30:35.328166 2026] [security2:error] [pid 148765:tid 149008] [client 154.192.123.127:17837] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4i-zv8fXmqCm8fNeqg2QAAAXc"]
[Mon Jul 20 07:30:35.898602 2026] [security2:error] [pid 148765:tid 148943] [client 57.141.18.98:53824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i-jv8fXmqCm8fNeqgwgABNl0"]
[Mon Jul 20 07:30:35.944946 2026] [security2:error] [pid 145170:tid 145364] [client 57.141.18.123:63982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i-jjs5KUa9I09SwT-0AAAwjU"]
[Mon Jul 20 07:30:35.977496 2026] [security2:error] [pid 145170:tid 145322] [client 36.93.152.155:64983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i-zjs5KUa9I09SwT--AAAAJg"]
[Mon Jul 20 07:30:35.977599 2026] [security2:error] [pid 145170:tid 145322] [client 36.93.152.155:64983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4i-zjs5KUa9I09SwT--AAAAJg"]
[Mon Jul 20 07:30:36.315581 2026] [security2:error] [pid 145170:tid 145180] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i_Djs5KUa9I09SwT_CgAA_QY"]
[Mon Jul 20 07:30:36.315715 2026] [security2:error] [pid 145170:tid 145423] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4i_Djs5KUa9I09SwT_CgAA_QY"]
[Mon Jul 20 07:30:36.579678 2026] [security2:error] [pid 148765:tid 148963] [client 201.27.111.74:59211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i_Dv8fXmqCm8fNeqhCQAAAUo"]
[Mon Jul 20 07:30:36.579818 2026] [security2:error] [pid 148765:tid 148963] [client 201.27.111.74:59211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4i_Dv8fXmqCm8fNeqhCQAAAUo"]
[Mon Jul 20 07:30:37.046663 2026] [security2:error] [pid 148765:tid 148970] [client 143.44.185.218:17116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhJAAAAVE"]
[Mon Jul 20 07:30:37.047298 2026] [security2:error] [pid 148765:tid 148970] [client 143.44.185.218:17116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhJAAAAVE"]
[Mon Jul 20 07:30:37.053009 2026] [security2:error] [pid 148765:tid 148923] [client 14.225.17.146:55861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4i_Dv8fXmqCm8fNeqhGgAAASI"], referer: http://ivetstrategies.com/Test
[Mon Jul 20 07:30:37.079919 2026] [security2:error] [pid 148765:tid 148808] [remote 162.19.86.63:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhJwABGyY"]
[Mon Jul 20 07:30:37.315269 2026] [security2:error] [pid 148765:tid 148897] [remote 162.19.86.63:50540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhMwABD38"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:30:37.335103 2026] [security2:error] [pid 148765:tid 148845] [remote 160.187.68.132:40732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhNAABN0s"]
[Mon Jul 20 07:30:37.335274 2026] [security2:error] [pid 148765:tid 148944] [client 160.187.68.132:40732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhNAABN0s"]
[Mon Jul 20 07:30:37.465013 2026] [security2:error] [pid 148765:tid 149017] [client 103.106.165.44:54780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhOgAAAYA"]
[Mon Jul 20 07:30:37.465199 2026] [security2:error] [pid 148765:tid 149017] [client 103.106.165.44:54780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhOgAAAYA"]
[Mon Jul 20 07:30:37.475900 2026] [security2:error] [pid 148765:tid 148959] [client 103.176.215.66:58589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhPAAAAUY"]
[Mon Jul 20 07:30:37.476284 2026] [security2:error] [pid 148765:tid 148959] [client 103.176.215.66:58589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhPAAAAUY"]
[Mon Jul 20 07:30:37.476424 2026] [security2:error] [pid 145170:tid 145329] [client 57.141.18.21:62280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i_Djs5KUa9I09SwT_EgAAn1Y"]
[Mon Jul 20 07:30:37.488618 2026] [security2:error] [pid 148765:tid 148964] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhMgAAAUs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:37.758299 2026] [security2:error] [pid 148765:tid 148995] [client 14.225.17.146:54293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhRAAAAWo"], referer: http://myspineworld.com/Test
[Mon Jul 20 07:30:38.114383 2026] [security2:error] [pid 145170:tid 145239] [remote 8.217.108.67:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i_jjs5KUa9I09SwT_RwAAtUE"]
[Mon Jul 20 07:30:38.221692 2026] [security2:error] [pid 148765:tid 148953] [client 152.42.182.12:51804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.182.42.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4i_jv8fXmqCm8fNeqhXgAAAUA"], referer: https://www.google.com/
[Mon Jul 20 07:30:38.244850 2026] [security2:error] [pid 148765:tid 148922] [client 117.211.236.168:49572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i_jv8fXmqCm8fNeqhXwAAASE"]
[Mon Jul 20 07:30:38.244973 2026] [security2:error] [pid 148765:tid 148922] [client 117.211.236.168:49572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4i_jv8fXmqCm8fNeqhXwAAASE"]
[Mon Jul 20 07:30:38.444171 2026] [security2:error] [pid 148765:tid 148989] [client 104.234.53.59:38415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4i_jv8fXmqCm8fNeqhagAAAWQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:38.555703 2026] [security2:error] [pid 148765:tid 148942] [client 57.141.18.100:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i_Tv8fXmqCm8fNeqhRQABNX0"]
[Mon Jul 20 07:30:38.667939 2026] [security2:error] [pid 145170:tid 145213] [remote 8.217.108.67:59758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4i_jjs5KUa9I09SwT_YQAA6Cc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:30:38.866445 2026] [security2:error] [pid 145170:tid 145319] [client 14.225.17.146:64396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4i_jjs5KUa9I09SwT_ZAAAAJU"], referer: https://myspineworld.com/Test
[Mon Jul 20 07:30:38.914669 2026] [security2:error] [pid 148765:tid 148980] [client 63.177.52.239:19990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4i_jv8fXmqCm8fNeqhggAAAVs"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:39.348048 2026] [security2:error] [pid 148765:tid 148909] [client 50.116.65.227:55754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4i_zv8fXmqCm8fNeqhkAAAARQ"]
[Mon Jul 20 07:30:39.356567 2026] [security2:error] [pid 145170:tid 145413] [client 50.116.65.227:55764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4i_zjs5KUa9I09SwT_egAAAPM"]
[Mon Jul 20 07:30:39.457680 2026] [security2:error] [pid 148765:tid 148915] [client 104.234.53.58:20593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4i_zv8fXmqCm8fNeqhmAAAARo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:39.526270 2026] [security2:error] [pid 148765:tid 148977] [client 45.3.45.203:50337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4i_zv8fXmqCm8fNeqhmgAAAVg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:39.583249 2026] [security2:error] [pid 148765:tid 149012] [client 144.16.21.149:25272] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i_zv8fXmqCm8fNeqhmQAAAXs"]
[Mon Jul 20 07:30:39.583707 2026] [security2:error] [pid 148765:tid 149012] [client 144.16.21.149:25272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4i_zv8fXmqCm8fNeqhmQAAAXs"]
[Mon Jul 20 07:30:39.620296 2026] [security2:error] [pid 148765:tid 148978] [client 63.177.52.239:19992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4i_zv8fXmqCm8fNeqhnwAAAVk"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:30:39.630113 2026] [security2:error] [pid 148765:tid 148905] [client 57.141.18.64:55742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i_jv8fXmqCm8fNeqhdQABEHA"]
[Mon Jul 20 07:30:40.087446 2026] [security2:error] [pid 148765:tid 148943] [client 216.73.216.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "almaz-aura.com"] [uri "/index.php"] [unique_id "al4i_zv8fXmqCm8fNeqhrAABNk4"]
[Mon Jul 20 07:30:40.243371 2026] [security2:error] [pid 148765:tid 148999] [client 173.214.177.58:58817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jADv8fXmqCm8fNeqhvAAAAW4"]
[Mon Jul 20 07:30:40.434619 2026] [security2:error] [pid 148765:tid 148963] [client 57.141.18.84:20046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i_zv8fXmqCm8fNeqhlgABSnw"]
[Mon Jul 20 07:30:40.438933 2026] [security2:error] [pid 145170:tid 145184] [remote 47.86.33.52:5232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jADjs5KUa9I09SwT_qAAAvQo"]
[Mon Jul 20 07:30:40.483637 2026] [security2:error] [pid 145170:tid 145376] [client 57.141.18.108:29070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4i_zjs5KUa9I09SwT_fgAAznc"]
[Mon Jul 20 07:30:40.638279 2026] [core:alert] [pid 148765:tid 148911] [client 35.222.199.138:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:30:40.926524 2026] [security2:error] [pid 145170:tid 145236] [remote 47.86.33.52:5232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jADjs5KUa9I09SwT_wwAAmT4"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:30:41.226128 2026] [security2:error] [pid 148765:tid 148917] [client 14.225.17.146:55779] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4i_zv8fXmqCm8fNeqhsAAAARw"], referer: http://expertcultures.com/Test
[Mon Jul 20 07:30:41.443687 2026] [security2:error] [pid 145170:tid 145405] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jATjs5KUa9I09SwT_zQAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:41.603811 2026] [security2:error] [pid 145170:tid 145250] [remote 42.200.84.61:59432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jATjs5KUa9I09SwT_2QAA10w"]
[Mon Jul 20 07:30:41.671617 2026] [security2:error] [pid 145170:tid 145375] [client 136.158.60.21:6571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jATjs5KUa9I09SwT_3AAAAM0"]
[Mon Jul 20 07:30:41.671722 2026] [security2:error] [pid 145170:tid 145375] [client 136.158.60.21:6571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jATjs5KUa9I09SwT_3AAAAM0"]
[Mon Jul 20 07:30:41.913905 2026] [security2:error] [pid 145170:tid 145327] [client 57.141.18.77:41212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jADjs5KUa9I09SwT_tgAAnRg"]
[Mon Jul 20 07:30:41.956640 2026] [security2:error] [pid 145170:tid 145224] [remote 42.200.84.61:59432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jATjs5KUa9I09SwT_5QAAmDI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:30:41.976142 2026] [security2:error] [pid 148765:tid 148959] [client 155.2.215.68:53903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.215.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jATv8fXmqCm8fNeqh-AAAAUY"]
[Mon Jul 20 07:30:41.976328 2026] [security2:error] [pid 148765:tid 148959] [client 155.2.215.68:53903] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jATv8fXmqCm8fNeqh-AAAAUY"]
[Mon Jul 20 07:30:42.104576 2026] [security2:error] [pid 145170:tid 145364] [client 57.141.18.108:45418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jADjs5KUa9I09SwT_wAAAwk0"]
[Mon Jul 20 07:30:42.192028 2026] [autoindex:error] [pid 148765:tid 148919] [client 45.194.67.29:0] AH01276: Cannot serve directory /home2/youposit/public_html/upositive/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:30:42.194221 2026] [security2:error] [pid 145170:tid 145329] [client 63.179.149.246:18882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jAjjs5KUa9I09SwT_7AAAAJ8"]
[Mon Jul 20 07:30:42.194329 2026] [security2:error] [pid 145170:tid 145329] [client 63.179.149.246:18882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jAjjs5KUa9I09SwT_7AAAAJ8"]
[Mon Jul 20 07:30:42.409431 2026] [security2:error] [pid 148765:tid 148941] [client 167.99.161.127:52746] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.massagelacey.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4jAjv8fXmqCm8fNeqiGAAAATQ"]
[Mon Jul 20 07:30:42.454023 2026] [security2:error] [pid 148765:tid 148915] [client 14.225.17.146:56239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4jADv8fXmqCm8fNeqhzwAAARo"], referer: http://grecruit.online/Test
[Mon Jul 20 07:30:42.966443 2026] [security2:error] [pid 145170:tid 145416] [client 104.234.53.63:26149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jAjjs5KUa9I09SwQACQAAAPY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:30:42.993465 2026] [security2:error] [pid 148765:tid 148964] [client 57.141.18.76:31412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jATv8fXmqCm8fNeqh9AABSwo"]
[Mon Jul 20 07:30:43.229162 2026] [autoindex:error] [pid 145170:tid 145274] [remote 35.245.189.88:59255] AH01276: Cannot serve directory /home2/uhiwfwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://uhi.wfw.mybluehost.me
[Mon Jul 20 07:30:43.414458 2026] [security2:error] [pid 148765:tid 148946] [client 191.202.66.27:52249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jAzv8fXmqCm8fNeqiRgAAATk"]
[Mon Jul 20 07:30:43.414608 2026] [security2:error] [pid 148765:tid 148946] [client 191.202.66.27:52249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jAzv8fXmqCm8fNeqiRgAAATk"]
[Mon Jul 20 07:30:43.594501 2026] [security2:error] [pid 148765:tid 148867] [remote 162.19.86.63:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jAzv8fXmqCm8fNeqiTAABEmE"]
[Mon Jul 20 07:30:43.674370 2026] [security2:error] [pid 148765:tid 149003] [client 157.20.138.62:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jAzv8fXmqCm8fNeqiUgAAAXI"]
[Mon Jul 20 07:30:43.674492 2026] [security2:error] [pid 148765:tid 149003] [client 157.20.138.62:55436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jAzv8fXmqCm8fNeqiUgAAAXI"]
[Mon Jul 20 07:30:43.765097 2026] [security2:error] [pid 145170:tid 145371] [client 179.127.84.238:54063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jAzjs5KUa9I09SwQAJgAAAMk"]
[Mon Jul 20 07:30:43.765188 2026] [security2:error] [pid 145170:tid 145371] [client 179.127.84.238:54063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jAzjs5KUa9I09SwQAJgAAAMk"]
[Mon Jul 20 07:30:44.004876 2026] [security2:error] [pid 148765:tid 148846] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jBDv8fXmqCm8fNeqiYAABPUw"]
[Mon Jul 20 07:30:44.005030 2026] [security2:error] [pid 148765:tid 148950] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jBDv8fXmqCm8fNeqiYAABPUw"]
[Mon Jul 20 07:30:44.028687 2026] [security2:error] [pid 148765:tid 148858] [remote 162.19.86.63:38782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jBDv8fXmqCm8fNeqiYgABHFg"], referer: https://mail.fvx.wyy.mybluehost.me/wp-login.php
[Mon Jul 20 07:30:44.249141 2026] [security2:error] [pid 145170:tid 145414] [client 88.241.67.160:56259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jBDjs5KUa9I09SwQAPQAAAPQ"]
[Mon Jul 20 07:30:44.249353 2026] [security2:error] [pid 145170:tid 145414] [client 88.241.67.160:56259] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jBDjs5KUa9I09SwQAPQAAAPQ"]
[Mon Jul 20 07:30:44.442968 2026] [security2:error] [pid 148765:tid 148987] [client 14.225.17.146:56677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4jAzv8fXmqCm8fNeqiXgAAAWI"]
[Mon Jul 20 07:30:44.778824 2026] [security2:error] [pid 145170:tid 145403] [client 49.47.218.174:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jBDjs5KUa9I09SwQAUwAAAOk"]
[Mon Jul 20 07:30:44.778975 2026] [security2:error] [pid 145170:tid 145403] [client 49.47.218.174:54090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jBDjs5KUa9I09SwQAUwAAAOk"]
[Mon Jul 20 07:30:44.978979 2026] [security2:error] [pid 148765:tid 148889] [remote 173.249.4.11:38573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4jBDv8fXmqCm8fNeqijAABLXc"]
[Mon Jul 20 07:30:44.996895 2026] [security2:error] [pid 148765:tid 148902] [client 57.141.18.125:38764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBDv8fXmqCm8fNeqiYwABDS0"]
[Mon Jul 20 07:30:45.037242 2026] [security2:error] [pid 145170:tid 145398] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jBDjs5KUa9I09SwQAWAAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:45.153549 2026] [security2:error] [pid 148765:tid 148776] [remote 173.249.4.11:38573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thedoctorscuisine.com"] [uri "/wp-login.php"] [unique_id "al4jBTv8fXmqCm8fNeqilAABbwY"], referer: https://thedoctorscuisine.com/wp-login.php
[Mon Jul 20 07:30:45.425518 2026] [security2:error] [pid 148765:tid 149011] [client 49.37.242.14:63614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTv8fXmqCm8fNeqiogAAAXo"]
[Mon Jul 20 07:30:45.449135 2026] [security2:error] [pid 148765:tid 149011] [client 49.37.242.14:63614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTv8fXmqCm8fNeqiogAAAXo"]
[Mon Jul 20 07:30:45.532081 2026] [security2:error] [pid 145170:tid 145189] [remote 100.42.189.89:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4jBTjs5KUa9I09SwQAgAAA1Q8"]
[Mon Jul 20 07:30:45.678479 2026] [security2:error] [pid 145170:tid 145390] [client 90.156.142.60:16726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTjs5KUa9I09SwQAhAAAANw"]
[Mon Jul 20 07:30:45.678564 2026] [security2:error] [pid 145170:tid 145390] [client 90.156.142.60:16726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTjs5KUa9I09SwQAhAAAANw"]
[Mon Jul 20 07:30:45.737100 2026] [autoindex:error] [pid 148765:tid 148933] [client 38.141.62.215:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/
[Mon Jul 20 07:30:45.745357 2026] [security2:error] [pid 145170:tid 145179] [remote 100.42.189.89:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4jBTjs5KUa9I09SwQAigAAogU"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 07:30:45.788509 2026] [security2:error] [pid 148765:tid 148973] [client 154.192.123.127:18376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTv8fXmqCm8fNeqisQAAAVQ"]
[Mon Jul 20 07:30:45.788662 2026] [security2:error] [pid 148765:tid 148973] [client 154.192.123.127:18376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTv8fXmqCm8fNeqisQAAAVQ"]
[Mon Jul 20 07:30:45.879372 2026] [security2:error] [pid 148765:tid 148931] [client 117.211.236.168:50066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTv8fXmqCm8fNeqitgAAASo"]
[Mon Jul 20 07:30:45.879462 2026] [security2:error] [pid 148765:tid 148931] [client 117.211.236.168:50066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jBTv8fXmqCm8fNeqitgAAASo"]
[Mon Jul 20 07:30:46.077007 2026] [security2:error] [pid 145170:tid 145400] [client 90.156.142.60:16954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/xmlrpc.php"] [unique_id "al4jBjjs5KUa9I09SwQAmgAAAOY"]
[Mon Jul 20 07:30:46.077133 2026] [security2:error] [pid 145170:tid 145400] [client 90.156.142.60:16954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/xmlrpc.php"] [unique_id "al4jBjjs5KUa9I09SwQAmgAAAOY"]
[Mon Jul 20 07:30:46.109169 2026] [security2:error] [pid 148765:tid 148978] [client 57.141.18.29:37110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBTv8fXmqCm8fNeqikQABWXY"]
[Mon Jul 20 07:30:46.176219 2026] [security2:error] [pid 148765:tid 149002] [client 57.141.18.9:35148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBTv8fXmqCm8fNeqikwABcVY"]
[Mon Jul 20 07:30:46.484328 2026] [security2:error] [pid 148765:tid 149019] [client 36.93.152.155:65516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jBjv8fXmqCm8fNeqi0wAAAYI"]
[Mon Jul 20 07:30:46.484423 2026] [security2:error] [pid 148765:tid 149019] [client 36.93.152.155:65516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jBjv8fXmqCm8fNeqi0wAAAYI"]
[Mon Jul 20 07:30:46.920620 2026] [autoindex:error] [pid 145170:tid 145424] [client 38.141.62.112:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/
[Mon Jul 20 07:30:47.064363 2026] [security2:error] [pid 148765:tid 148943] [client 201.27.111.74:59735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.111.27.201.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqi5AAAATY"]
[Mon Jul 20 07:30:47.064475 2026] [security2:error] [pid 148765:tid 148943] [client 201.27.111.74:59735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "avatrip.co"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqi5AAAATY"]
[Mon Jul 20 07:30:47.092375 2026] [security2:error] [pid 148765:tid 148907] [client 90.156.142.60:17170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqi6QAAARI"]
[Mon Jul 20 07:30:47.092476 2026] [security2:error] [pid 148765:tid 148907] [client 90.156.142.60:17170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqi6QAAARI"]
[Mon Jul 20 07:30:47.154118 2026] [security2:error] [pid 145170:tid 145417] [client 74.208.214.194:38318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jBzjs5KUa9I09SwQAwQAAAPc"]
[Mon Jul 20 07:30:47.295653 2026] [security2:error] [pid 148765:tid 148934] [client 57.141.18.109:47144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBTv8fXmqCm8fNeqivAABLSw"]
[Mon Jul 20 07:30:47.393469 2026] [security2:error] [pid 148765:tid 149016] [client 57.141.18.101:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jBzv8fXmqCm8fNeqi8QAAAX8"]
[Mon Jul 20 07:30:47.429852 2026] [security2:error] [pid 145170:tid 145352] [client 188.166.209.66:55636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4jBzjs5KUa9I09SwQAxQAAALY"], referer: binance.com
[Mon Jul 20 07:30:47.486067 2026] [security2:error] [pid 148765:tid 148977] [client 90.156.142.60:17752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjAgAAAVg"]
[Mon Jul 20 07:30:47.486144 2026] [security2:error] [pid 148765:tid 148977] [client 90.156.142.60:17752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/wp/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjAgAAAVg"]
[Mon Jul 20 07:30:47.601194 2026] [security2:error] [pid 148765:tid 148838] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjCAABZUQ"]
[Mon Jul 20 07:30:47.601391 2026] [security2:error] [pid 148765:tid 148990] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjCAABZUQ"]
[Mon Jul 20 07:30:47.695438 2026] [security2:error] [pid 148765:tid 148927] [client 57.141.18.12:33470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBjv8fXmqCm8fNeqiywABJhg"]
[Mon Jul 20 07:30:47.852296 2026] [security2:error] [pid 148765:tid 148905] [client 103.106.165.44:55539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjFwAAARA"]
[Mon Jul 20 07:30:47.852478 2026] [security2:error] [pid 148765:tid 148905] [client 103.106.165.44:55539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjFwAAARA"]
[Mon Jul 20 07:30:47.922161 2026] [security2:error] [pid 148765:tid 148993] [client 90.156.142.60:18076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/site/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjGgAAAWg"]
[Mon Jul 20 07:30:47.922255 2026] [security2:error] [pid 148765:tid 148993] [client 90.156.142.60:18076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/site/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjGgAAAWg"]
[Mon Jul 20 07:30:47.970121 2026] [security2:error] [pid 148765:tid 148920] [client 57.141.18.12:33480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBjv8fXmqCm8fNeqi0gABHzA"]
[Mon Jul 20 07:30:47.987454 2026] [security2:error] [pid 148765:tid 148966] [client 103.176.215.66:59128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjHQAAAU0"]
[Mon Jul 20 07:30:47.987795 2026] [security2:error] [pid 148765:tid 148966] [client 103.176.215.66:59128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jBzv8fXmqCm8fNeqjHQAAAU0"]
[Mon Jul 20 07:30:48.056622 2026] [autoindex:error] [pid 148765:tid 149026] [client 38.141.62.97:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/
[Mon Jul 20 07:30:48.298396 2026] [security2:error] [pid 145170:tid 145317] [client 90.156.142.60:18364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/news/xmlrpc.php"] [unique_id "al4jCDjs5KUa9I09SwQA4gAAAJM"]
[Mon Jul 20 07:30:48.298554 2026] [security2:error] [pid 145170:tid 145317] [client 90.156.142.60:18364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/news/xmlrpc.php"] [unique_id "al4jCDjs5KUa9I09SwQA4gAAAJM"]
[Mon Jul 20 07:30:48.672056 2026] [security2:error] [pid 148765:tid 149022] [client 90.156.142.60:18606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/main/xmlrpc.php"] [unique_id "al4jCDv8fXmqCm8fNeqjRAAAAYU"]
[Mon Jul 20 07:30:48.672172 2026] [security2:error] [pid 148765:tid 149022] [client 90.156.142.60:18606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/main/xmlrpc.php"] [unique_id "al4jCDv8fXmqCm8fNeqjRAAAAYU"]
[Mon Jul 20 07:30:48.730348 2026] [security2:error] [pid 148765:tid 148992] [client 195.211.208.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4jCDv8fXmqCm8fNeqjNwAAAWc"]
[Mon Jul 20 07:30:48.825713 2026] [security2:error] [pid 148765:tid 148926] [client 57.141.18.7:44040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBzv8fXmqCm8fNeqi-wABJWA"]
[Mon Jul 20 07:30:48.908994 2026] [security2:error] [pid 148765:tid 148935] [client 57.141.18.64:25552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jBzv8fXmqCm8fNeqjAQABLhA"]
[Mon Jul 20 07:30:48.919393 2026] [security2:error] [pid 148765:tid 148945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jCDv8fXmqCm8fNeqjRwAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:48.991064 2026] [security2:error] [pid 148765:tid 148990] [client 143.44.185.218:18608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jCDv8fXmqCm8fNeqjUQAAAWU"]
[Mon Jul 20 07:30:48.991182 2026] [security2:error] [pid 148765:tid 148990] [client 143.44.185.218:18608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jCDv8fXmqCm8fNeqjUQAAAWU"]
[Mon Jul 20 07:30:49.048189 2026] [security2:error] [pid 148765:tid 148932] [client 90.156.142.60:18870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4jCTv8fXmqCm8fNeqjUwAAASs"]
[Mon Jul 20 07:30:49.048281 2026] [security2:error] [pid 148765:tid 148932] [client 90.156.142.60:18870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4jCTv8fXmqCm8fNeqjUwAAASs"]
[Mon Jul 20 07:30:49.181604 2026] [security2:error] [pid 148765:tid 148960] [client 104.207.58.114:50627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jCTv8fXmqCm8fNeqjXAAAAUc"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:49.238318 2026] [security2:error] [pid 145170:tid 145371] [client 14.225.17.146:56517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4jBTjs5KUa9I09SwQAhgAAAMk"], referer: http://areitoproducciones.com/Test
[Mon Jul 20 07:30:49.331305 2026] [autoindex:error] [pid 148765:tid 148970] [client 38.141.62.239:0] AH01276: Cannot serve directory /home4/mffjejmy/public_html/wp-content/plugins/elementskit/modules/parallax/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://emsbodystorm.com/
[Mon Jul 20 07:30:49.338643 2026] [security2:error] [pid 145170:tid 145382] [client 5.161.75.7:8020] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4jCDjs5KUa9I09SwQA8gAAANQ"], referer: https://windowtx.com
[Mon Jul 20 07:30:49.411063 2026] [security2:error] [pid 148765:tid 149005] [client 90.156.142.60:19082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/old/xmlrpc.php"] [unique_id "al4jCTv8fXmqCm8fNeqjbQAAAXQ"]
[Mon Jul 20 07:30:49.411167 2026] [security2:error] [pid 148765:tid 149005] [client 90.156.142.60:19082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/old/xmlrpc.php"] [unique_id "al4jCTv8fXmqCm8fNeqjbQAAAXQ"]
[Mon Jul 20 07:30:49.778085 2026] [security2:error] [pid 148765:tid 148958] [client 90.156.142.60:19290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/new/xmlrpc.php"] [unique_id "al4jCTv8fXmqCm8fNeqjhAAAAUU"]
[Mon Jul 20 07:30:49.778185 2026] [security2:error] [pid 148765:tid 148958] [client 90.156.142.60:19290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "teresaharding.com"] [uri "/new/xmlrpc.php"] [unique_id "al4jCTv8fXmqCm8fNeqjhAAAAUU"]
[Mon Jul 20 07:30:49.849373 2026] [security2:error] [pid 148765:tid 148988] [client 65.111.30.55:59517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.30.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jCTv8fXmqCm8fNeqjhgAAAWM"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:50.282231 2026] [security2:error] [pid 148765:tid 148956] [client 144.16.21.149:25247] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jCjv8fXmqCm8fNeqjogAAAUM"]
[Mon Jul 20 07:30:50.282409 2026] [security2:error] [pid 148765:tid 148956] [client 144.16.21.149:25247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jCjv8fXmqCm8fNeqjogAAAUM"]
[Mon Jul 20 07:30:50.347236 2026] [security2:error] [pid 145170:tid 145397] [client 90.156.142.60:19500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.142.156.90.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "teresaharding.com"] [uri "/wp-login.php"] [unique_id "al4jCjjs5KUa9I09SwQBHQAAAOM"]
[Mon Jul 20 07:30:50.716491 2026] [security2:error] [pid 148765:tid 148923] [client 57.141.18.101:44146] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCTv8fXmqCm8fNeqjVwABIn8"]
[Mon Jul 20 07:30:50.798335 2026] [security2:error] [pid 148765:tid 149016] [client 14.225.17.146:59035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4jCDv8fXmqCm8fNeqjMQAAAX8"], referer: http://adastra.love/Test
[Mon Jul 20 07:30:51.134223 2026] [security2:error] [pid 148765:tid 148948] [client 3.87.117.29:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4jCjv8fXmqCm8fNeqjsgAAATs"]
[Mon Jul 20 07:30:51.136826 2026] [security2:error] [pid 148765:tid 148920] [client 3.87.117.29:61574] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "curlsnpearlsss.com"] [uri "/es/homemade-adobo-adobo-puertorriqueno"] [unique_id "al4jCjv8fXmqCm8fNeqjsAAAAR8"]
[Mon Jul 20 07:30:51.147404 2026] [security2:error] [pid 145170:tid 145356] [client 50.116.65.227:34582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jCzjs5KUa9I09SwQBPAAAALo"]
[Mon Jul 20 07:30:51.156986 2026] [security2:error] [pid 145170:tid 145406] [client 50.116.65.227:34584] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jCzjs5KUa9I09SwQBPgAAAOw"]
[Mon Jul 20 07:30:51.277071 2026] [security2:error] [pid 148765:tid 149010] [client 216.24.212.22:25493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4jCzv8fXmqCm8fNeqj3QAAAXk"]
[Mon Jul 20 07:30:51.292617 2026] [security2:error] [pid 148765:tid 148935] [client 57.141.18.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqj2gAAAS4"]
[Mon Jul 20 07:30:51.296064 2026] [security2:error] [pid 148765:tid 148930] [client 216.24.212.10:40863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4jCzv8fXmqCm8fNeqj3AAAASk"]
[Mon Jul 20 07:30:51.743796 2026] [security2:error] [pid 148765:tid 148773] [remote 152.228.213.32:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jCzv8fXmqCm8fNeqkEAABGAM"]
[Mon Jul 20 07:30:51.908533 2026] [security2:error] [pid 148765:tid 148976] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jCzv8fXmqCm8fNeqkDAABVzM"]
[Mon Jul 20 07:30:51.963727 2026] [security2:error] [pid 148765:tid 148832] [remote 152.228.213.32:33202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jCzv8fXmqCm8fNeqkHAABYT4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:30:52.296369 2026] [security2:error] [pid 145170:tid 145230] [remote 57.141.18.57:61538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCjjs5KUa9I09SwQBJgAAwjg"]
[Mon Jul 20 07:30:52.332023 2026] [security2:error] [pid 148765:tid 148965] [client 3.85.28.216:0] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqj5gAAAUw"]
[Mon Jul 20 07:30:52.384198 2026] [security2:error] [pid 145170:tid 145343] [client 3.85.28.216:49682] ModSecurity: Warning. Matched phrase "ADmantX" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/es/homemade-adobo-adobo-puertorriqueno/"] [unique_id "al4jCzjs5KUa9I09SwQBRAAAAK0"]
[Mon Jul 20 07:30:52.399726 2026] [security2:error] [pid 148765:tid 149022] [client 136.158.60.21:8000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jDDv8fXmqCm8fNeqkQAAAAYU"]
[Mon Jul 20 07:30:52.399850 2026] [security2:error] [pid 148765:tid 149022] [client 136.158.60.21:8000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jDDv8fXmqCm8fNeqkQAAAAYU"]
[Mon Jul 20 07:30:52.466383 2026] [security2:error] [pid 148765:tid 149012] [client 142.111.152.229:59725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jDDv8fXmqCm8fNeqkQgAAAXs"]
[Mon Jul 20 07:30:52.474169 2026] [security2:error] [pid 148765:tid 149012] [client 142.111.152.229:59725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jDDv8fXmqCm8fNeqkQgAAAXs"]
[Mon Jul 20 07:30:52.493331 2026] [security2:error] [pid 148765:tid 148932] [client 57.141.18.18:41732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCjv8fXmqCm8fNeqjswABKws"]
[Mon Jul 20 07:30:52.539233 2026] [security2:error] [pid 148765:tid 148959] [client 57.141.18.123:27908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCjv8fXmqCm8fNeqjuwABRng"]
[Mon Jul 20 07:30:52.718767 2026] [proxy:error] [pid 116718:tid 116848] (70007)The timeout specified has expired: [remote 80.210.17.232:58142] AH01095: prefetch request body failed to 127.0.0.1:8443 (127.0.0.1) from 80.210.17.232 (), referer: https://jenfarley.com/about/
[Mon Jul 20 07:30:52.719982 2026] [security2:error] [pid 148765:tid 148998] [client 63.179.149.246:65468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jDDv8fXmqCm8fNeqkWQAAAW0"]
[Mon Jul 20 07:30:52.720796 2026] [security2:error] [pid 148765:tid 148998] [client 63.179.149.246:65468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jDDv8fXmqCm8fNeqkWQAAAW0"]
[Mon Jul 20 07:30:53.061551 2026] [security2:error] [pid 148765:tid 148940] [client 57.141.18.4:57514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqj4AABMwc"]
[Mon Jul 20 07:30:53.155132 2026] [security2:error] [pid 148765:tid 148916] [client 50.116.65.227:34630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4jDTv8fXmqCm8fNeqkggAAARs"]
[Mon Jul 20 07:30:53.160069 2026] [security2:error] [pid 148765:tid 148918] [client 14.225.17.146:55567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqkBQAAAR0"], referer: http://recruitinginsight.us/Test
[Mon Jul 20 07:30:53.260377 2026] [security2:error] [pid 145170:tid 145267] [remote 57.141.18.54:55104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCzjs5KUa9I09SwQBRgAAx10"]
[Mon Jul 20 07:30:53.304942 2026] [security2:error] [pid 148765:tid 148913] [client 14.225.17.146:59029] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkdQAAARg"], referer: http://ironcitywellness.com/Test
[Mon Jul 20 07:30:53.584517 2026] [security2:error] [pid 148765:tid 148996] [client 57.141.18.4:57516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqkEgABa14"]
[Mon Jul 20 07:30:53.819225 2026] [security2:error] [pid 148765:tid 148988] [client 14.225.17.146:58942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkrgAAAWM"], referer: http://taskidsvirginia.com/Test
[Mon Jul 20 07:30:54.009098 2026] [security2:error] [pid 148765:tid 148950] [client 216.173.120.130:53999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkzQAAAT0"]
[Mon Jul 20 07:30:54.086989 2026] [security2:error] [pid 148765:tid 148903] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkwQAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:54.141598 2026] [security2:error] [pid 148765:tid 148931] [client 191.202.66.27:52749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqk5QAAASo"]
[Mon Jul 20 07:30:54.141781 2026] [security2:error] [pid 148765:tid 148931] [client 191.202.66.27:52749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqk5QAAASo"]
[Mon Jul 20 07:30:54.145357 2026] [security2:error] [pid 148765:tid 148910] [client 157.20.138.62:56006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqk6AAAARU"]
[Mon Jul 20 07:30:54.145452 2026] [security2:error] [pid 148765:tid 148910] [client 157.20.138.62:56006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqk6AAAARU"]
[Mon Jul 20 07:30:54.152732 2026] [security2:error] [pid 148765:tid 148987] [client 57.141.18.66:20280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jDDv8fXmqCm8fNeqkMwABYmE"]
[Mon Jul 20 07:30:54.167841 2026] [security2:error] [pid 148765:tid 148960] [client 14.225.17.146:55521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqkAQAAAUc"], referer: http://overloadcomedy.com/Test
[Mon Jul 20 07:30:54.245159 2026] [security2:error] [pid 148765:tid 148994] [client 89.238.167.150:56048] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqk-QAAAWk"]
[Mon Jul 20 07:30:54.245283 2026] [security2:error] [pid 148765:tid 148994] [client 89.238.167.150:56048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqk-QAAAWk"]
[Mon Jul 20 07:30:54.349052 2026] [security2:error] [pid 148765:tid 148874] [remote 152.56.21.31:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlAgABZGg"]
[Mon Jul 20 07:30:54.349330 2026] [security2:error] [pid 148765:tid 148989] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlAgABZGg"]
[Mon Jul 20 07:30:54.382250 2026] [security2:error] [pid 148765:tid 148948] [client 13.229.223.11:63518] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "cryptomeaning.com"] [uri "/"] [unique_id "al4jDjv8fXmqCm8fNeqlBQAAATs"]
[Mon Jul 20 07:30:54.382371 2026] [security2:error] [pid 148765:tid 148948] [client 13.229.223.11:63518] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cryptomeaning.com"] [uri "/"] [unique_id "al4jDjv8fXmqCm8fNeqlBQAAATs"]
[Mon Jul 20 07:30:54.470460 2026] [autoindex:error] [pid 148765:tid 148787] [remote 34.53.196.60:54360] AH01276: Cannot serve directory /home2/tsbjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.tsb.jiv.mybluehost.me
[Mon Jul 20 07:30:54.487280 2026] [security2:error] [pid 148765:tid 148983] [client 179.127.84.238:54614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlCQAAAV4"]
[Mon Jul 20 07:30:54.487462 2026] [security2:error] [pid 148765:tid 148983] [client 179.127.84.238:54614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlCQAAAV4"]
[Mon Jul 20 07:30:54.551039 2026] [security2:error] [pid 148765:tid 148976] [client 105.172.190.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4jDjv8fXmqCm8fNeqk_gAAAVc"]
[Mon Jul 20 07:30:54.642143 2026] [security2:error] [pid 148765:tid 148988] [client 5.102.173.71:45652] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bigwormfishing.com"] [uri "/robots.txt"] [unique_id "al4jDjv8fXmqCm8fNeqlFgAAAWM"]
[Mon Jul 20 07:30:54.715768 2026] [security2:error] [pid 148765:tid 148897] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlIgABaX8"]
[Mon Jul 20 07:30:54.715938 2026] [security2:error] [pid 148765:tid 148994] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlIgABaX8"]
[Mon Jul 20 07:30:54.926309 2026] [security2:error] [pid 148765:tid 149016] [client 88.241.67.160:54035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlLQAAAX8"]
[Mon Jul 20 07:30:54.926611 2026] [security2:error] [pid 148765:tid 149016] [client 88.241.67.160:54035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jDjv8fXmqCm8fNeqlLQAAAX8"]
[Mon Jul 20 07:30:54.945699 2026] [security2:error] [pid 148765:tid 148941] [client 188.166.209.66:49698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4jDjv8fXmqCm8fNeqlMAAAATQ"], referer: binance.com
[Mon Jul 20 07:30:55.133629 2026] [security2:error] [pid 148765:tid 149011] [client 202.141.11.99:22250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqlOwAAAXo"]
[Mon Jul 20 07:30:55.133768 2026] [security2:error] [pid 148765:tid 149011] [client 202.141.11.99:22250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqlOwAAAXo"]
[Mon Jul 20 07:30:55.162256 2026] [security2:error] [pid 148765:tid 149023] [client 5.102.173.71:45652] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4jDjv8fXmqCm8fNeqlKAAAAYY"]
[Mon Jul 20 07:30:55.225583 2026] [security2:error] [pid 148765:tid 148962] [client 49.47.218.174:54625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqlRgAAAUk"]
[Mon Jul 20 07:30:55.225773 2026] [security2:error] [pid 148765:tid 148962] [client 49.47.218.174:54625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqlRgAAAUk"]
[Mon Jul 20 07:30:55.303471 2026] [security2:error] [pid 148765:tid 148792] [remote 124.55.178.99:33714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4jDzv8fXmqCm8fNeqlTQABRxY"]
[Mon Jul 20 07:30:55.376218 2026] [security2:error] [pid 148765:tid 148908] [client 57.141.18.65:37858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkowABE0A"]
[Mon Jul 20 07:30:55.394033 2026] [security2:error] [pid 148765:tid 148979] [client 57.141.18.72:60348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkpgABWk8"]
[Mon Jul 20 07:30:55.522583 2026] [core:error] [pid 148765:tid 148972] [client 45.194.67.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:55.522607 2026] [core:error] [pid 148765:tid 148972] [client 45.194.67.29:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:55.573465 2026] [security2:error] [pid 148765:tid 149004] [client 57.141.18.60:20834] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkwAABczs"]
[Mon Jul 20 07:30:55.674290 2026] [core:error] [pid 148765:tid 149002] [client 198.235.24.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:55.674325 2026] [core:error] [pid 148765:tid 149002] [client 198.235.24.175:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:30:55.680095 2026] [security2:error] [pid 148765:tid 148964] [client 14.225.17.146:55270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4jDjv8fXmqCm8fNeqk1wAAAUs"], referer: http://vinovinhowine.com/Test
[Mon Jul 20 07:30:55.686127 2026] [security2:error] [pid 148765:tid 148771] [remote 192.241.143.148:48882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqlbwABUAE"]
[Mon Jul 20 07:30:55.686303 2026] [security2:error] [pid 148765:tid 148969] [client 192.241.143.148:48882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqlbwABUAE"]
[Mon Jul 20 07:30:55.738840 2026] [security2:error] [pid 148765:tid 148780] [remote 217.61.143.92:48622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqldgABewo"]
[Mon Jul 20 07:30:55.739029 2026] [security2:error] [pid 148765:tid 149012] [client 217.61.143.92:48622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jDzv8fXmqCm8fNeqldgABewo"]
[Mon Jul 20 07:30:55.784480 2026] [security2:error] [pid 148765:tid 148775] [remote 124.55.178.99:33714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4jDzv8fXmqCm8fNeqleQABRAU"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:30:55.834982 2026] [security2:error] [pid 148765:tid 148943] [client 14.225.17.146:59030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4jDTv8fXmqCm8fNeqkeQAAATY"], referer: http://drewsasburyparkbeachhouse.com/Test
[Mon Jul 20 07:30:55.891038 2026] [security2:error] [pid 148765:tid 149008] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ablemoneyfp.com"] [uri "/index.php"] [unique_id "al4jCzv8fXmqCm8fNeqj9wAAAXc"]
[Mon Jul 20 07:30:56.039993 2026] [security2:error] [pid 148765:tid 148932] [client 35.245.239.138:52641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "icemarc.org"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeqlkQAAASs"]
[Mon Jul 20 07:30:56.040105 2026] [security2:error] [pid 148765:tid 148932] [client 35.245.239.138:52641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "icemarc.org"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeqlkQAAASs"]
[Mon Jul 20 07:30:56.332854 2026] [security2:error] [pid 148765:tid 148938] [client 185.223.152.103:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "thescarystory.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4jEDv8fXmqCm8fNeqlrwAAATE"]
[Mon Jul 20 07:30:56.344432 2026] [security2:error] [pid 148765:tid 148982] [client 114.119.145.140:63471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mtredistricting.gov"] [uri "/wp-content/uploads/2023/01/TCP3House_SubmittedToLegislature_CommissionCompetitivenessMetric.pdf"] [unique_id "al4jEDv8fXmqCm8fNeqlsQAAAV0"], referer: https://mtredistricting.gov/document-library/
[Mon Jul 20 07:30:56.386296 2026] [security2:error] [pid 148765:tid 148944] [client 154.192.123.127:16907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeqltAAAATc"]
[Mon Jul 20 07:30:56.386465 2026] [security2:error] [pid 148765:tid 148944] [client 154.192.123.127:16907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeqltAAAATc"]
[Mon Jul 20 07:30:56.437285 2026] [security2:error] [pid 148765:tid 148979] [client 14.225.17.146:58806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeqloQAAAVo"]
[Mon Jul 20 07:30:56.535512 2026] [security2:error] [pid 148765:tid 149013] [client 117.211.236.168:50665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeqlwAAAAXw"]
[Mon Jul 20 07:30:56.535610 2026] [security2:error] [pid 148765:tid 149013] [client 117.211.236.168:50665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeqlwAAAAXw"]
[Mon Jul 20 07:30:56.872784 2026] [security2:error] [pid 148765:tid 148816] [remote 103.255.134.61:56986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jEDv8fXmqCm8fNeql3wABGy4"]
[Mon Jul 20 07:30:56.996559 2026] [security2:error] [pid 148765:tid 148965] [client 36.93.152.155:49842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeql8gAAAUw"]
[Mon Jul 20 07:30:56.996657 2026] [security2:error] [pid 148765:tid 148965] [client 36.93.152.155:49842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jEDv8fXmqCm8fNeql8gAAAUw"]
[Mon Jul 20 07:30:57.054474 2026] [security2:error] [pid 148765:tid 148989] [client 57.141.18.81:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeql4wAAAWQ"]
[Mon Jul 20 07:30:57.448881 2026] [security2:error] [pid 148765:tid 148794] [remote 103.255.134.61:56986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jETv8fXmqCm8fNeqmEwABfBg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:30:57.547944 2026] [security2:error] [pid 148765:tid 148939] [client 57.141.18.38:46152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jDzv8fXmqCm8fNeqligABMik"]
[Mon Jul 20 07:30:57.733151 2026] [security2:error] [pid 148765:tid 148984] [client 57.141.18.102:29680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeqlnAABX3g"]
[Mon Jul 20 07:30:57.784649 2026] [security2:error] [pid 148765:tid 148959] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jETv8fXmqCm8fNeqmHgAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:30:57.853914 2026] [security2:error] [pid 148765:tid 148956] [client 57.141.18.48:56422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeqloAABQ1g"]
[Mon Jul 20 07:30:57.987269 2026] [security2:error] [pid 148765:tid 148977] [client 188.39.109.162:5999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thierry-henry.fr"] [uri "/index.php"] [unique_id "al4jETv8fXmqCm8fNeqmKQAAAVg"]
[Mon Jul 20 07:30:58.152194 2026] [security2:error] [pid 148765:tid 148952] [client 57.141.18.54:45660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeqlvgABP1U"]
[Mon Jul 20 07:30:58.254261 2026] [security2:error] [pid 148765:tid 148929] [client 50.116.65.227:53206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4jEjv8fXmqCm8fNeqmVQAAASg"]
[Mon Jul 20 07:30:58.257424 2026] [security2:error] [pid 148765:tid 148982] [client 14.225.17.146:58468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeql3gAAAV0"]
[Mon Jul 20 07:30:58.368374 2026] [security2:error] [pid 148765:tid 148919] [client 103.106.165.44:56179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmXAAAAR4"]
[Mon Jul 20 07:30:58.368608 2026] [security2:error] [pid 148765:tid 148919] [client 103.106.165.44:56179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmXAAAAR4"]
[Mon Jul 20 07:30:58.428535 2026] [security2:error] [pid 148765:tid 148922] [client 57.141.18.63:21762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeqlyQABIQc"]
[Mon Jul 20 07:30:58.465288 2026] [security2:error] [pid 148765:tid 149022] [client 14.225.17.146:63599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeql0AAAAYU"], referer: http://maplerespiteservices.com/Test
[Mon Jul 20 07:30:58.481558 2026] [autoindex:error] [pid 148765:tid 148909] [client 65.109.16.46:57822] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:30:58.580665 2026] [security2:error] [pid 148765:tid 148967] [client 103.176.215.66:59666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmdgAAAU4"]
[Mon Jul 20 07:30:58.580826 2026] [security2:error] [pid 148765:tid 148967] [client 103.176.215.66:59666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmdgAAAU4"]
[Mon Jul 20 07:30:58.693596 2026] [security2:error] [pid 148765:tid 148998] [client 57.141.18.54:45676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEDv8fXmqCm8fNeql6gABbTU"]
[Mon Jul 20 07:30:58.699239 2026] [security2:error] [pid 148765:tid 148896] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmgwABEX4"]
[Mon Jul 20 07:30:58.699372 2026] [security2:error] [pid 148765:tid 148906] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmgwABEX4"]
[Mon Jul 20 07:30:58.895314 2026] [security2:error] [pid 148765:tid 148957] [client 49.37.242.14:64167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmkgAAAUQ"]
[Mon Jul 20 07:30:58.895445 2026] [security2:error] [pid 148765:tid 148957] [client 49.37.242.14:64167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jEjv8fXmqCm8fNeqmkgAAAUQ"]
[Mon Jul 20 07:30:59.542030 2026] [security2:error] [pid 148765:tid 148913] [client 65.111.26.161:22027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jEzv8fXmqCm8fNeqmwwAAARg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:30:59.598640 2026] [security2:error] [pid 148765:tid 149020] [client 14.225.17.146:58493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4jEzv8fXmqCm8fNeqmsQAAAYM"], referer: http://latiendadejorge.com.gt/Test
[Mon Jul 20 07:30:59.754456 2026] [security2:error] [pid 148765:tid 148793] [remote 217.61.143.92:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4jEzv8fXmqCm8fNeqm0wABbBc"]
[Mon Jul 20 07:30:59.990305 2026] [security2:error] [pid 148765:tid 148822] [remote 38.242.157.30:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4jEzv8fXmqCm8fNeqm6AABcjQ"]
[Mon Jul 20 07:31:00.093573 2026] [security2:error] [pid 148765:tid 148817] [remote 217.61.143.92:48628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ksands.co.uk"] [uri "/wp-login.php"] [unique_id "al4jFDv8fXmqCm8fNeqm8wABYi8"], referer: https://ksands.co.uk/wp-login.php
[Mon Jul 20 07:31:00.140042 2026] [security2:error] [pid 148765:tid 148984] [client 216.73.216.123:20810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "techexecutive.me"] [uri "/index.php"] [unique_id "al4jEjv8fXmqCm8fNeqmjwABX2Q"]
[Mon Jul 20 07:31:00.205151 2026] [security2:error] [pid 148765:tid 148805] [remote 38.242.157.30:50962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "file.learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4jFDv8fXmqCm8fNeqnAAABSSM"], referer: https://file.learnthissecret.com/wp-login.php
[Mon Jul 20 07:31:00.233211 2026] [security2:error] [pid 148765:tid 148908] [client 14.225.17.146:58950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4jEjv8fXmqCm8fNeqmUQAAARM"], referer: http://www.justinagrayman.com/Test
[Mon Jul 20 07:31:00.318784 2026] [security2:error] [pid 148765:tid 148930] [client 116.74.65.235:62875] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4jFDv8fXmqCm8fNeqm-wAAASk"]
[Mon Jul 20 07:31:00.960021 2026] [security2:error] [pid 148765:tid 148976] [client 143.44.185.218:19902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jFDv8fXmqCm8fNeqnOQAAAVc"]
[Mon Jul 20 07:31:00.960128 2026] [security2:error] [pid 148765:tid 148976] [client 143.44.185.218:19902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jFDv8fXmqCm8fNeqnOQAAAVc"]
[Mon Jul 20 07:31:00.967641 2026] [security2:error] [pid 148765:tid 148979] [client 57.141.18.110:24080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEzv8fXmqCm8fNeqmqAABWmY"]
[Mon Jul 20 07:31:01.199225 2026] [security2:error] [pid 148765:tid 148936] [client 144.16.21.149:25168] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jFTv8fXmqCm8fNeqnVgAAAS8"]
[Mon Jul 20 07:31:01.199407 2026] [security2:error] [pid 148765:tid 148936] [client 144.16.21.149:25168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jFTv8fXmqCm8fNeqnVgAAAS8"]
[Mon Jul 20 07:31:01.498475 2026] [security2:error] [pid 148765:tid 148967] [client 57.141.18.105:58496] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jEzv8fXmqCm8fNeqm0AABTj4"]
[Mon Jul 20 07:31:01.528516 2026] [security2:error] [pid 148765:tid 148961] [client 14.225.17.146:58464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4jFTv8fXmqCm8fNeqnXwAAAUg"], referer: http://savilerowtravel.com/Test
[Mon Jul 20 07:31:01.549285 2026] [security2:error] [pid 148765:tid 148987] [client 136.144.33.202:58109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4jFTv8fXmqCm8fNeqnbQAAAWI"]
[Mon Jul 20 07:31:01.699435 2026] [security2:error] [pid 148765:tid 149014] [client 14.225.17.146:55016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4jFTv8fXmqCm8fNeqncAAAAX0"], referer: http://lifeisbetterlakeside.com/Test
[Mon Jul 20 07:31:01.828053 2026] [security2:error] [pid 148765:tid 148855] [remote 188.40.28.4:38130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jFTv8fXmqCm8fNeqnjQABVVU"]
[Mon Jul 20 07:31:01.838886 2026] [security2:error] [pid 148765:tid 148902] [client 114.119.134.12:21727] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.jennylouraya.com"] [uri "/category/social-media/"] [unique_id "al4jFTv8fXmqCm8fNeqnjwAAAQ0"], referer: https://www.jennylouraya.com/category/social-media/
[Mon Jul 20 07:31:02.060643 2026] [security2:error] [pid 148765:tid 148787] [remote 188.40.28.4:38130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jFjv8fXmqCm8fNeqnpgABDxE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:31:02.159845 2026] [security2:error] [pid 148765:tid 148988] [client 14.225.17.146:58950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4jFTv8fXmqCm8fNeqnnAAAAWM"]
[Mon Jul 20 07:31:02.439950 2026] [security2:error] [pid 148765:tid 149023] [client 104.234.53.50:49169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jFjv8fXmqCm8fNeqnygAAAYY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:31:02.452128 2026] [autoindex:error] [pid 148765:tid 149002] [client 14.225.17.146:58876] AH01276: Cannot serve directory /home3/windowtx/public_html/Test/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://windowtx.com/Test
[Mon Jul 20 07:31:02.590535 2026] [security2:error] [pid 148765:tid 148929] [client 14.225.17.146:55087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4jFjv8fXmqCm8fNeqn0QAAASg"], referer: http://betterbonddogtraining.com/Test
[Mon Jul 20 07:31:02.863880 2026] [security2:error] [pid 148765:tid 148938] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ambarmdesign.com"] [uri "/index.php"] [unique_id "al4jEzv8fXmqCm8fNeqm5QAAATE"]
[Mon Jul 20 07:31:03.168868 2026] [security2:error] [pid 148765:tid 148948] [client 136.158.60.21:9522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jFzv8fXmqCm8fNeqn_QAAATs"]
[Mon Jul 20 07:31:03.169026 2026] [security2:error] [pid 148765:tid 148948] [client 136.158.60.21:9522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jFzv8fXmqCm8fNeqn_QAAATs"]
[Mon Jul 20 07:31:03.169462 2026] [security2:error] [pid 148765:tid 148909] [client 142.111.152.46:51647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jFzv8fXmqCm8fNeqn9wAAARQ"]
[Mon Jul 20 07:31:03.169582 2026] [security2:error] [pid 148765:tid 148909] [client 142.111.152.46:51647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jFzv8fXmqCm8fNeqn9wAAARQ"]
[Mon Jul 20 07:31:03.190443 2026] [security2:error] [pid 148765:tid 149004] [client 3.67.192.83:10698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jFzv8fXmqCm8fNeqn_wAAAXM"]
[Mon Jul 20 07:31:03.190521 2026] [security2:error] [pid 148765:tid 149004] [client 3.67.192.83:10698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jFzv8fXmqCm8fNeqn_wAAAXM"]
[Mon Jul 20 07:31:03.424148 2026] [security2:error] [pid 148765:tid 148941] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jFzv8fXmqCm8fNeqoCQAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:03.537230 2026] [security2:error] [pid 148765:tid 148821] [remote 130.51.180.8:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jFzv8fXmqCm8fNeqoIgABGDM"]
[Mon Jul 20 07:31:03.568009 2026] [security2:error] [pid 148765:tid 148853] [remote 5.161.225.162:34918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jFzv8fXmqCm8fNeqoJQABfFM"]
[Mon Jul 20 07:31:03.688297 2026] [security2:error] [pid 148765:tid 148781] [remote 130.51.180.8:50148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jFzv8fXmqCm8fNeqoPAABXws"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:31:03.776195 2026] [security2:error] [pid 148765:tid 148846] [remote 5.161.225.162:34918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jFzv8fXmqCm8fNeqoQwABYEw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:31:03.924054 2026] [security2:error] [pid 148765:tid 148922] [client 57.141.18.16:35704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jFjv8fXmqCm8fNeqnugABIX8"]
[Mon Jul 20 07:31:04.099340 2026] [security2:error] [pid 148765:tid 148976] [client 14.225.17.146:58897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4jFjv8fXmqCm8fNeqnqgAAAVc"], referer: http://itdynamix.com/Test
[Mon Jul 20 07:31:04.142058 2026] [security2:error] [pid 148765:tid 148952] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jFzv8fXmqCm8fNeqoVQAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:04.307282 2026] [security2:error] [pid 148765:tid 148933] [client 50.116.65.227:34752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jGDv8fXmqCm8fNeqodAAAASw"]
[Mon Jul 20 07:31:04.317174 2026] [security2:error] [pid 148765:tid 148983] [client 50.116.65.227:34758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jGDv8fXmqCm8fNeqodQAAAV4"]
[Mon Jul 20 07:31:04.478656 2026] [security2:error] [pid 148765:tid 148916] [client 57.141.18.55:25052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jFjv8fXmqCm8fNeqn5QABG0E"]
[Mon Jul 20 07:31:04.669168 2026] [security2:error] [pid 148765:tid 149017] [client 157.20.138.62:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jGDv8fXmqCm8fNeqomQAAAYA"]
[Mon Jul 20 07:31:04.669318 2026] [security2:error] [pid 148765:tid 149017] [client 157.20.138.62:56572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jGDv8fXmqCm8fNeqomQAAAYA"]
[Mon Jul 20 07:31:04.758768 2026] [security2:error] [pid 148765:tid 148847] [remote 57.141.18.96:29420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4409190"] [unique_id "al4jGDv8fXmqCm8fNeqoowABek0"]
[Mon Jul 20 07:31:04.768613 2026] [security2:error] [pid 148765:tid 148944] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jGDv8fXmqCm8fNeqohgAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:04.809003 2026] [security2:error] [pid 148765:tid 148814] [remote 182.77.62.24:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4jGDv8fXmqCm8fNeqopgABEiw"]
[Mon Jul 20 07:31:04.834585 2026] [security2:error] [pid 148765:tid 148917] [client 158.173.166.181:36757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jGDv8fXmqCm8fNeqoqwAAARw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:31:04.914408 2026] [security2:error] [pid 148765:tid 148936] [client 50.116.65.227:34784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jGDv8fXmqCm8fNeqongAAAS8"]
[Mon Jul 20 07:31:04.932153 2026] [security2:error] [pid 148765:tid 148899] [client 191.202.66.27:53241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jGDv8fXmqCm8fNeqotwAAAQo"]
[Mon Jul 20 07:31:04.932289 2026] [security2:error] [pid 148765:tid 148899] [client 191.202.66.27:53241] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jGDv8fXmqCm8fNeqotwAAAQo"]
[Mon Jul 20 07:31:04.949552 2026] [security2:error] [pid 148765:tid 148982] [client 57.141.18.69:26110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jFzv8fXmqCm8fNeqoBwABXXI"]
[Mon Jul 20 07:31:05.107300 2026] [security2:error] [pid 148765:tid 148938] [client 14.225.17.146:58803] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4jGDv8fXmqCm8fNeqovAAAATE"], referer: https://itdynamix.com/Test
[Mon Jul 20 07:31:05.112941 2026] [security2:error] [pid 148765:tid 148941] [client 50.116.65.227:34794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jGDv8fXmqCm8fNeqouQAAATQ"]
[Mon Jul 20 07:31:05.190808 2026] [security2:error] [pid 148765:tid 148999] [client 179.127.84.238:55150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqo0QAAAW4"]
[Mon Jul 20 07:31:05.190905 2026] [security2:error] [pid 148765:tid 148999] [client 179.127.84.238:55150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqo0QAAAW4"]
[Mon Jul 20 07:31:05.307564 2026] [security2:error] [pid 148765:tid 148844] [remote 182.77.62.24:56442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4jGTv8fXmqCm8fNeqo2AABbUo"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 07:31:05.327765 2026] [security2:error] [pid 148765:tid 148808] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqo2gABayY"]
[Mon Jul 20 07:31:05.327948 2026] [security2:error] [pid 148765:tid 148996] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqo2gABayY"]
[Mon Jul 20 07:31:05.395050 2026] [security2:error] [pid 148765:tid 148986] [client 57.141.18.40:22006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jFzv8fXmqCm8fNeqoOgABYTQ"]
[Mon Jul 20 07:31:05.413436 2026] [security2:error] [pid 148765:tid 148953] [client 14.225.17.146:58875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4jGDv8fXmqCm8fNeqodgAAAUA"], referer: http://laceycaraccident.com/Test
[Mon Jul 20 07:31:05.520208 2026] [security2:error] [pid 148765:tid 148985] [client 66.249.74.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4jGTv8fXmqCm8fNeqoxQAAAWA"]
[Mon Jul 20 07:31:05.586510 2026] [security2:error] [pid 148765:tid 148983] [client 88.241.67.160:56338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqo7wAAAV4"]
[Mon Jul 20 07:31:05.587215 2026] [security2:error] [pid 148765:tid 148983] [client 88.241.67.160:56338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqo7wAAAV4"]
[Mon Jul 20 07:31:05.736843 2026] [security2:error] [pid 148765:tid 148945] [client 49.47.218.174:55169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqpBQAAATg"]
[Mon Jul 20 07:31:05.736971 2026] [security2:error] [pid 148765:tid 148945] [client 49.47.218.174:55169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jGTv8fXmqCm8fNeqpBQAAATg"]
[Mon Jul 20 07:31:05.762867 2026] [security2:error] [pid 148765:tid 149017] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jGTv8fXmqCm8fNeqo7QAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:05.764716 2026] [security2:error] [pid 148765:tid 149014] [client 57.141.18.44:63000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jGDv8fXmqCm8fNeqoXQABfQA"]
[Mon Jul 20 07:31:06.107894 2026] [security2:error] [pid 148765:tid 148819] [remote 45.150.79.142:58042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jGjv8fXmqCm8fNeqpJwABNzE"]
[Mon Jul 20 07:31:06.180804 2026] [security2:error] [pid 148765:tid 148921] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jGTv8fXmqCm8fNeqpIAAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:06.303070 2026] [security2:error] [pid 148765:tid 148802] [remote 45.150.79.142:58042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jGjv8fXmqCm8fNeqpPwABRSA"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:31:06.534186 2026] [security2:error] [pid 148765:tid 149020] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4jGjv8fXmqCm8fNeqpPgAAAYM"]
[Mon Jul 20 07:31:06.853565 2026] [security2:error] [pid 148765:tid 149006] [client 62.150.67.110:59186] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4jGjv8fXmqCm8fNeqpVQAAAXU"]
[Mon Jul 20 07:31:06.922867 2026] [security2:error] [pid 148765:tid 148947] [client 154.192.123.127:17307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jGjv8fXmqCm8fNeqpcQAAATo"]
[Mon Jul 20 07:31:06.922996 2026] [security2:error] [pid 148765:tid 148947] [client 154.192.123.127:17307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jGjv8fXmqCm8fNeqpcQAAATo"]
[Mon Jul 20 07:31:07.145014 2026] [security2:error] [pid 148765:tid 148840] [remote 57.141.18.52:65172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6083336"] [unique_id "al4jGzv8fXmqCm8fNeqpgQABbEY"]
[Mon Jul 20 07:31:07.333420 2026] [security2:error] [pid 148765:tid 148962] [client 57.141.18.83:33952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jGTv8fXmqCm8fNeqo7gABSXE"]
[Mon Jul 20 07:31:07.349390 2026] [security2:error] [pid 148765:tid 148973] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jGzv8fXmqCm8fNeqpgAAAAVQ"]
[Mon Jul 20 07:31:07.353916 2026] [security2:error] [pid 148765:tid 148780] [remote 154.66.198.148:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jGzv8fXmqCm8fNeqpkAABXgo"]
[Mon Jul 20 07:31:07.432853 2026] [security2:error] [pid 148765:tid 148779] [remote 152.56.21.31:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jGzv8fXmqCm8fNeqpmAABTgk"]
[Mon Jul 20 07:31:07.433011 2026] [security2:error] [pid 148765:tid 148967] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jGzv8fXmqCm8fNeqpmAABTgk"]
[Mon Jul 20 07:31:07.499502 2026] [security2:error] [pid 148765:tid 148927] [client 36.93.152.155:50544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jGzv8fXmqCm8fNeqpoQAAASY"]
[Mon Jul 20 07:31:07.499678 2026] [security2:error] [pid 148765:tid 148927] [client 36.93.152.155:50544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jGzv8fXmqCm8fNeqpoQAAASY"]
[Mon Jul 20 07:31:07.519952 2026] [security2:error] [pid 148765:tid 148996] [client 173.214.177.59:56005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jGzv8fXmqCm8fNeqpoAAAAWs"]
[Mon Jul 20 07:31:07.831802 2026] [security2:error] [pid 148765:tid 149001] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jGzv8fXmqCm8fNeqppgAAAXA"]
[Mon Jul 20 07:31:07.891759 2026] [security2:error] [pid 148765:tid 148783] [remote 154.66.198.148:9536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jGzv8fXmqCm8fNeqpxAABPw0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:31:08.040527 2026] [security2:error] [pid 148765:tid 148904] [client 57.141.18.105:58510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jGjv8fXmqCm8fNeqpNwABD34"]
[Mon Jul 20 07:31:08.253385 2026] [security2:error] [pid 148765:tid 148921] [client 117.211.236.168:51213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jHDv8fXmqCm8fNeqp5wAAASA"]
[Mon Jul 20 07:31:08.253485 2026] [security2:error] [pid 148765:tid 148921] [client 117.211.236.168:51213] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jHDv8fXmqCm8fNeqp5wAAASA"]
[Mon Jul 20 07:31:08.634468 2026] [security2:error] [pid 148765:tid 148951] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jHDv8fXmqCm8fNeqp_AAAAT4"], referer: 1'"3000
[Mon Jul 20 07:31:08.838964 2026] [security2:error] [pid 148765:tid 148930] [client 103.106.165.44:56670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jHDv8fXmqCm8fNeqqHQAAASk"]
[Mon Jul 20 07:31:08.839094 2026] [security2:error] [pid 148765:tid 148930] [client 103.106.165.44:56670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jHDv8fXmqCm8fNeqqHQAAASk"]
[Mon Jul 20 07:31:08.937043 2026] [security2:error] [pid 148765:tid 148961] [client 57.141.18.12:38630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jGzv8fXmqCm8fNeqpjwABSFM"]
[Mon Jul 20 07:31:09.110447 2026] [security2:error] [pid 148765:tid 148871] [remote 160.187.68.132:53628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jHTv8fXmqCm8fNeqqNQABgGU"]
[Mon Jul 20 07:31:09.110619 2026] [security2:error] [pid 148765:tid 149017] [client 160.187.68.132:53628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jHTv8fXmqCm8fNeqqNQABgGU"]
[Mon Jul 20 07:31:09.126093 2026] [security2:error] [pid 148765:tid 148938] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jHDv8fXmqCm8fNeqqJQAAATE"], referer: 1'"3000
[Mon Jul 20 07:31:09.198757 2026] [security2:error] [pid 148765:tid 148992] [client 103.176.215.66:60206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jHTv8fXmqCm8fNeqqPwAAAWc"]
[Mon Jul 20 07:31:09.198876 2026] [security2:error] [pid 148765:tid 148992] [client 103.176.215.66:60206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jHTv8fXmqCm8fNeqqPwAAAWc"]
[Mon Jul 20 07:31:09.250504 2026] [security2:error] [pid 148765:tid 148988] [client 65.111.23.234:27045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jHTv8fXmqCm8fNeqqQgAAAWM"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:31:09.325251 2026] [security2:error] [pid 148765:tid 148925] [client 14.225.17.146:49321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4jHDv8fXmqCm8fNeqp1wAAASQ"], referer: http://mazzucelli.com/Test
[Mon Jul 20 07:31:09.351578 2026] [security2:error] [pid 148765:tid 149025] [client 57.141.18.0:55480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jGzv8fXmqCm8fNeqpqgABiEw"]
[Mon Jul 20 07:31:09.665442 2026] [security2:error] [pid 148765:tid 148861] [remote 176.56.118.182:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jHTv8fXmqCm8fNeqqYQABFFs"]
[Mon Jul 20 07:31:09.761735 2026] [security2:error] [pid 148765:tid 148902] [client 128.1.121.56:54424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4jFjv8fXmqCm8fNeqoMwAAAQ0"]
[Mon Jul 20 07:31:09.763058 2026] [security2:error] [pid 148765:tid 148778] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jHTv8fXmqCm8fNeqqagABagg"]
[Mon Jul 20 07:31:09.763225 2026] [security2:error] [pid 148765:tid 148995] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jHTv8fXmqCm8fNeqqagABagg"]
[Mon Jul 20 07:31:09.891028 2026] [security2:error] [pid 148765:tid 148889] [remote 176.56.118.182:39280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.118.56.176.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jHTv8fXmqCm8fNeqqdQABJHc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:31:09.899552 2026] [security2:error] [pid 148765:tid 148956] [client 217.181.92.39:42439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 39.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jHTv8fXmqCm8fNeqqcgAAAUM"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:31:10.064635 2026] [security2:error] [pid 148765:tid 148802] [remote 100.42.189.89:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4jHjv8fXmqCm8fNeqqhwABZSA"]
[Mon Jul 20 07:31:10.139616 2026] [security2:error] [pid 148765:tid 149004] [client 14.225.17.146:55147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jHTv8fXmqCm8fNeqqfgAAAXM"], referer: http://mezzacraft.com/Test
[Mon Jul 20 07:31:10.238986 2026] [security2:error] [pid 148765:tid 148977] [client 14.225.17.146:55077] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4jHDv8fXmqCm8fNeqqFwAAAVg"], referer: http://headachescarpaltunnelfibromyalgia.com/Test
[Mon Jul 20 07:31:10.277731 2026] [security2:error] [pid 148765:tid 148885] [remote 100.42.189.89:60814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4jHjv8fXmqCm8fNeqqlgABLHM"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:31:10.523921 2026] [security2:error] [pid 148765:tid 149010] [client 104.207.56.229:19911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jHjv8fXmqCm8fNeqqrAAAAXk"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:31:10.884623 2026] [security2:error] [pid 148765:tid 148905] [client 57.141.18.13:46560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jHTv8fXmqCm8fNeqqRAABEHU"]
[Mon Jul 20 07:31:10.889773 2026] [security2:error] [pid 148765:tid 148919] [client 49.37.242.14:64693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jHjv8fXmqCm8fNeqqzwAAAR4"]
[Mon Jul 20 07:31:10.889869 2026] [security2:error] [pid 148765:tid 148919] [client 49.37.242.14:64693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jHjv8fXmqCm8fNeqqzwAAAR4"]
[Mon Jul 20 07:31:11.122276 2026] [security2:error] [pid 148765:tid 148820] [remote 152.228.213.32:59600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4jHzv8fXmqCm8fNeqq6AABSDI"]
[Mon Jul 20 07:31:11.320108 2026] [security2:error] [pid 148765:tid 148870] [remote 152.228.213.32:59600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4jHzv8fXmqCm8fNeqrAgABcGQ"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 07:31:11.777679 2026] [security2:error] [pid 148765:tid 148837] [remote 182.77.62.24:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jHzv8fXmqCm8fNeqrJwABJ0M"]
[Mon Jul 20 07:31:11.796894 2026] [security2:error] [pid 148765:tid 148999] [client 57.141.18.118:21054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jHjv8fXmqCm8fNeqqigABbnQ"]
[Mon Jul 20 07:31:12.034433 2026] [security2:error] [pid 148765:tid 149024] [client 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4jIDv8fXmqCm8fNeqrNQAAAYc"]
[Mon Jul 20 07:31:12.076841 2026] [security2:error] [pid 148765:tid 148938] [client 144.16.21.149:28385] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jIDv8fXmqCm8fNeqrPgAAATE"]
[Mon Jul 20 07:31:12.076952 2026] [security2:error] [pid 148765:tid 148938] [client 144.16.21.149:28385] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jIDv8fXmqCm8fNeqrPgAAATE"]
[Mon Jul 20 07:31:12.283858 2026] [security2:error] [pid 148765:tid 148864] [remote 182.77.62.24:50518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jIDv8fXmqCm8fNeqrUAABJF4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:31:12.363028 2026] [security2:error] [pid 148765:tid 148984] [client 72.167.132.114:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/wp-login.php"] [unique_id "al4jIDv8fXmqCm8fNeqrVQAAAV8"], referer: https://lakelopezonline.com/wp-login.php
[Mon Jul 20 07:31:12.382059 2026] [security2:error] [pid 148765:tid 148987] [client 57.141.18.8:23294] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jHjv8fXmqCm8fNeqqswABYnw"]
[Mon Jul 20 07:31:12.881260 2026] [security2:error] [pid 148765:tid 149014] [client 14.225.17.146:57388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4jIDv8fXmqCm8fNeqrcgAAAX0"]
[Mon Jul 20 07:31:12.934121 2026] [security2:error] [pid 148765:tid 149006] [client 57.141.18.86:37984] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jHzv8fXmqCm8fNeqq3gABdXk"]
[Mon Jul 20 07:31:12.960669 2026] [security2:error] [pid 148765:tid 148951] [client 79.101.74.100:50032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jIDv8fXmqCm8fNeqrfQABPj0"]
[Mon Jul 20 07:31:12.960719 2026] [security2:error] [pid 148765:tid 148951] [client 79.101.74.100:50032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jIDv8fXmqCm8fNeqrfQABPj0"]
[Mon Jul 20 07:31:13.187999 2026] [security2:error] [pid 148765:tid 148939] [client 149.0.16.108:64736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqrjAAAATI"]
[Mon Jul 20 07:31:13.188192 2026] [security2:error] [pid 148765:tid 148939] [client 149.0.16.108:64736] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqrjAAAATI"]
[Mon Jul 20 07:31:13.189802 2026] [security2:error] [pid 148765:tid 148928] [client 143.44.185.218:21436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqrjQAAASc"]
[Mon Jul 20 07:31:13.189912 2026] [security2:error] [pid 148765:tid 148928] [client 143.44.185.218:21436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqrjQAAASc"]
[Mon Jul 20 07:31:13.241627 2026] [security2:error] [pid 148765:tid 148990] [client 57.141.18.6:36826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jHzv8fXmqCm8fNeqrAwABZW0"]
[Mon Jul 20 07:31:13.304574 2026] [security2:error] [pid 148765:tid 149019] [client 57.141.18.55:28642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jHzv8fXmqCm8fNeqrBwABgns"]
[Mon Jul 20 07:31:13.330849 2026] [security2:error] [pid 148765:tid 149013] [client 14.225.17.146:55176] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4jHzv8fXmqCm8fNeqrLAAAAXw"], referer: http://thechancersband.com/Test
[Mon Jul 20 07:31:13.660021 2026] [security2:error] [pid 148765:tid 148984] [client 18.184.179.151:30894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqruwAAAV8"]
[Mon Jul 20 07:31:13.660173 2026] [security2:error] [pid 148765:tid 148984] [client 18.184.179.151:30894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqruwAAAV8"]
[Mon Jul 20 07:31:13.735873 2026] [security2:error] [pid 148765:tid 148981] [client 142.111.152.166:52739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqrwQAAAVw"]
[Mon Jul 20 07:31:13.736017 2026] [security2:error] [pid 148765:tid 148981] [client 142.111.152.166:52739] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqrwQAAAVw"]
[Mon Jul 20 07:31:13.772739 2026] [security2:error] [pid 148765:tid 148906] [client 57.141.18.106:40802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jIDv8fXmqCm8fNeqrOAABEWY"]
[Mon Jul 20 07:31:13.897461 2026] [security2:error] [pid 148765:tid 148994] [client 136.158.60.21:10968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqr2gAAAWk"]
[Mon Jul 20 07:31:13.897597 2026] [security2:error] [pid 148765:tid 148994] [client 136.158.60.21:10968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jITv8fXmqCm8fNeqr2gAAAWk"]
[Mon Jul 20 07:31:13.994840 2026] [security2:error] [pid 148765:tid 149008] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jITv8fXmqCm8fNeqrzgAAAXc"], referer: 1'"3000
[Mon Jul 20 07:31:14.631951 2026] [security2:error] [pid 148765:tid 148930] [client 45.157.112.60:33009] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jIjv8fXmqCm8fNeqsHwAAASk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:31:14.728194 2026] [security2:error] [pid 148765:tid 148905] [client 57.141.18.86:37986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jITv8fXmqCm8fNeqrhwABEAA"]
[Mon Jul 20 07:31:14.934892 2026] [security2:error] [pid 148765:tid 148945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jIjv8fXmqCm8fNeqsIgAAATg"], referer: 1'"3000
[Mon Jul 20 07:31:15.191111 2026] [security2:error] [pid 148765:tid 149012] [client 157.20.138.62:57140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsVAAAAXs"]
[Mon Jul 20 07:31:15.191217 2026] [security2:error] [pid 148765:tid 149012] [client 157.20.138.62:57140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsVAAAAXs"]
[Mon Jul 20 07:31:15.490670 2026] [security2:error] [pid 148765:tid 148882] [remote 162.19.86.63:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4jIzv8fXmqCm8fNeqscgABLXA"]
[Mon Jul 20 07:31:15.496861 2026] [security2:error] [pid 148765:tid 148774] [remote 45.150.79.142:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jIzv8fXmqCm8fNeqscwABXQQ"]
[Mon Jul 20 07:31:15.500378 2026] [security2:error] [pid 148765:tid 148899] [client 191.202.66.27:53734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsdAAAAQo"]
[Mon Jul 20 07:31:15.500707 2026] [security2:error] [pid 148765:tid 148899] [client 191.202.66.27:53734] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsdAAAAQo"]
[Mon Jul 20 07:31:15.538509 2026] [security2:error] [pid 148765:tid 148932] [client 35.245.239.138:56709] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-b3441a24.youpositive.co"] [uri "/index.php"] [unique_id "al4jIzv8fXmqCm8fNeqsagAAASs"]
[Mon Jul 20 07:31:15.601542 2026] [security2:error] [pid 148765:tid 148906] [client 35.245.239.138:56709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-b3441a24.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsegAAARE"]
[Mon Jul 20 07:31:15.601627 2026] [security2:error] [pid 148765:tid 148906] [client 35.245.239.138:56709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-b3441a24.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsegAAARE"]
[Mon Jul 20 07:31:15.663690 2026] [security2:error] [pid 148765:tid 148815] [remote 45.150.79.142:47476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jIzv8fXmqCm8fNeqshgABcS0"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:31:15.707201 2026] [security2:error] [pid 148765:tid 148837] [remote 162.19.86.63:45346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lutheranphilosopher.com"] [uri "/wp-login.php"] [unique_id "al4jIzv8fXmqCm8fNeqsiQABDkM"], referer: https://lutheranphilosopher.com/wp-login.php
[Mon Jul 20 07:31:15.845704 2026] [security2:error] [pid 148765:tid 148953] [client 35.245.239.138:49368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-b19b598a.wesnile.com"] [uri "/index.php"] [unique_id "al4jIzv8fXmqCm8fNeqsigAAAUA"]
[Mon Jul 20 07:31:15.857353 2026] [security2:error] [pid 148765:tid 148986] [client 179.127.84.238:55686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqskgAAAWE"]
[Mon Jul 20 07:31:15.857477 2026] [security2:error] [pid 148765:tid 148986] [client 179.127.84.238:55686] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqskgAAAWE"]
[Mon Jul 20 07:31:15.940730 2026] [security2:error] [pid 148765:tid 149005] [client 74.208.214.194:52664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jIzv8fXmqCm8fNeqsmwAAAXQ"]
[Mon Jul 20 07:31:15.958156 2026] [security2:error] [pid 148765:tid 149022] [client 35.245.239.138:49368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-b19b598a.wesnile.com"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsoAAAAYU"]
[Mon Jul 20 07:31:15.958258 2026] [security2:error] [pid 148765:tid 149022] [client 35.245.239.138:49368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-b19b598a.wesnile.com"] [uri "/xmlrpc.php"] [unique_id "al4jIzv8fXmqCm8fNeqsoAAAAYU"]
[Mon Jul 20 07:31:16.032317 2026] [security2:error] [pid 148765:tid 148847] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsowABiE0"]
[Mon Jul 20 07:31:16.032462 2026] [security2:error] [pid 148765:tid 149025] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsowABiE0"]
[Mon Jul 20 07:31:16.145142 2026] [security2:error] [pid 148765:tid 148983] [client 88.241.67.160:56108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsrAAAAV4"]
[Mon Jul 20 07:31:16.145418 2026] [security2:error] [pid 148765:tid 148983] [client 88.241.67.160:56108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsrAAAAV4"]
[Mon Jul 20 07:31:16.218520 2026] [security2:error] [pid 148765:tid 148917] [client 49.47.218.174:55718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsuQAAARw"]
[Mon Jul 20 07:31:16.218642 2026] [security2:error] [pid 148765:tid 148917] [client 49.47.218.174:55718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsuQAAARw"]
[Mon Jul 20 07:31:16.258431 2026] [security2:error] [pid 148765:tid 148966] [client 202.141.11.99:24378] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsuwAAAU0"]
[Mon Jul 20 07:31:16.258579 2026] [security2:error] [pid 148765:tid 148966] [client 202.141.11.99:24378] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqsuwAAAU0"]
[Mon Jul 20 07:31:16.421419 2026] [security2:error] [pid 148765:tid 149024] [client 50.116.65.227:39498] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jJDv8fXmqCm8fNeqsxwAAAYc"]
[Mon Jul 20 07:31:16.431430 2026] [security2:error] [pid 148765:tid 148904] [client 50.116.65.227:39512] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jJDv8fXmqCm8fNeqsyAAAAQ8"]
[Mon Jul 20 07:31:16.841940 2026] [security2:error] [pid 148765:tid 148976] [client 57.141.18.20:53040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jIzv8fXmqCm8fNeqsRgABV1o"]
[Mon Jul 20 07:31:16.896936 2026] [security2:error] [pid 148765:tid 148846] [remote 100.42.189.89:60908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqs5wABNkw"]
[Mon Jul 20 07:31:16.897077 2026] [security2:error] [pid 148765:tid 148943] [client 100.42.189.89:60908] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jJDv8fXmqCm8fNeqs5wABNkw"]
[Mon Jul 20 07:31:17.217688 2026] [security2:error] [pid 148765:tid 148874] [remote 182.77.62.24:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jJTv8fXmqCm8fNeqtAQABOGg"]
[Mon Jul 20 07:31:17.405914 2026] [security2:error] [pid 148765:tid 148909] [client 154.192.123.127:17702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jJTv8fXmqCm8fNeqtDAAAARQ"]
[Mon Jul 20 07:31:17.406012 2026] [security2:error] [pid 148765:tid 148909] [client 154.192.123.127:17702] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jJTv8fXmqCm8fNeqtDAAAARQ"]
[Mon Jul 20 07:31:17.614270 2026] [security2:error] [pid 148765:tid 148992] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jJTv8fXmqCm8fNeqtDQAAAWc"], referer: 1'"3000
[Mon Jul 20 07:31:17.752068 2026] [security2:error] [pid 148765:tid 148791] [remote 182.77.62.24:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jJTv8fXmqCm8fNeqtKAABUxU"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:31:17.778974 2026] [security2:error] [pid 148765:tid 148984] [client 57.141.18.27:26930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jIzv8fXmqCm8fNeqsnwABXyw"]
[Mon Jul 20 07:31:17.813056 2026] [security2:error] [pid 148765:tid 148866] [remote 152.56.21.31:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jJTv8fXmqCm8fNeqtKwABImA"]
[Mon Jul 20 07:31:17.813186 2026] [security2:error] [pid 148765:tid 148923] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jJTv8fXmqCm8fNeqtKwABImA"]
[Mon Jul 20 07:31:17.944489 2026] [security2:error] [pid 148765:tid 148929] [client 36.93.152.155:51056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jJTv8fXmqCm8fNeqtMQAAASg"]
[Mon Jul 20 07:31:17.944621 2026] [security2:error] [pid 148765:tid 148929] [client 36.93.152.155:51056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jJTv8fXmqCm8fNeqtMQAAASg"]
[Mon Jul 20 07:31:18.672023 2026] [security2:error] [pid 148765:tid 148946] [client 14.225.17.146:54886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4jJDv8fXmqCm8fNeqs7wAAATk"], referer: http://nomorewetsheets.net/Test
[Mon Jul 20 07:31:18.713291 2026] [security2:error] [pid 148765:tid 148935] [client 14.225.17.146:57567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4jJTv8fXmqCm8fNeqtCAAAAS4"], referer: http://scott-assist.com/Test
[Mon Jul 20 07:31:18.891552 2026] [security2:error] [pid 148765:tid 148913] [client 57.141.18.5:39724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jJTv8fXmqCm8fNeqs_wABGFs"]
[Mon Jul 20 07:31:18.988273 2026] [security2:error] [pid 148765:tid 148908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jJjv8fXmqCm8fNeqtfQAAARM"], referer: 1'"3000
[Mon Jul 20 07:31:19.188533 2026] [security2:error] [pid 148765:tid 148974] [client 14.225.17.146:64350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4jJjv8fXmqCm8fNeqtVgAAAVU"], referer: http://processorstudio.com/Test
[Mon Jul 20 07:31:19.191514 2026] [security2:error] [pid 148765:tid 149013] [client 117.211.236.168:51886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jJzv8fXmqCm8fNeqtnQAAAXw"]
[Mon Jul 20 07:31:19.191654 2026] [security2:error] [pid 148765:tid 149013] [client 117.211.236.168:51886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jJzv8fXmqCm8fNeqtnQAAAXw"]
[Mon Jul 20 07:31:19.241010 2026] [security2:error] [pid 148765:tid 148949] [client 63.179.149.246:51796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jJzv8fXmqCm8fNeqtowAAATw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:31:19.241604 2026] [security2:error] [pid 148765:tid 148932] [client 103.106.165.44:57156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jJzv8fXmqCm8fNeqtoQAAASs"]
[Mon Jul 20 07:31:19.241711 2026] [security2:error] [pid 148765:tid 148932] [client 103.106.165.44:57156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jJzv8fXmqCm8fNeqtoQAAASs"]
[Mon Jul 20 07:31:19.643936 2026] [security2:error] [pid 148765:tid 149009] [client 57.141.18.83:25042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jJTv8fXmqCm8fNeqtLAABeFY"]
[Mon Jul 20 07:31:19.790339 2026] [security2:error] [pid 148765:tid 148957] [client 103.176.215.66:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jJzv8fXmqCm8fNeqt1wAAAUQ"]
[Mon Jul 20 07:31:19.790532 2026] [security2:error] [pid 148765:tid 148957] [client 103.176.215.66:60742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jJzv8fXmqCm8fNeqt1wAAAUQ"]
[Mon Jul 20 07:31:19.883093 2026] [security2:error] [pid 148765:tid 149025] [client 34.221.76.50:65152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.76.221.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jJzv8fXmqCm8fNeqt3AAAAYg"], referer: https://curlsnpearlsss.com/es/jamon-con-pina-glazed-ham-with-pineapples/
[Mon Jul 20 07:31:19.985476 2026] [autoindex:error] [pid 148765:tid 148951] [client 35.245.239.138:50384] AH01276: Cannot serve directory /home1/heidimo2/public_html/website_ba575a2e/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:31:19.990130 2026] [security2:error] [pid 148765:tid 148931] [client 63.176.132.15:26614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jJzv8fXmqCm8fNeqt7AAAASo"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:31:20.043776 2026] [security2:error] [pid 148765:tid 148949] [client 14.225.17.146:56951] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4jKDv8fXmqCm8fNeqt8AAAATw"], referer: https://processorstudio.com/Test
[Mon Jul 20 07:31:20.155030 2026] [security2:error] [pid 148765:tid 149000] [client 45.3.54.10:37243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jKDv8fXmqCm8fNequAQAAAW8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:31:20.299429 2026] [security2:error] [pid 148765:tid 148940] [client 54.244.177.189:63288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jKDv8fXmqCm8fNequDAAAATM"], referer: https://curlsnpearlsss.com/es/jamon-con-pina-glazed-ham-with-pineapples/
[Mon Jul 20 07:31:20.299431 2026] [security2:error] [pid 148765:tid 148900] [client 35.245.239.138:50384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/xmlrpc.php"] [unique_id "al4jKDv8fXmqCm8fNequDQAAAQs"]
[Mon Jul 20 07:31:20.415400 2026] [security2:error] [pid 148765:tid 148932] [client 98.159.234.160:57689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jKDv8fXmqCm8fNequHgAAASs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:31:20.436221 2026] [security2:error] [pid 148765:tid 148941] [client 14.225.17.146:57311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4jJjv8fXmqCm8fNeqtiQAAATQ"], referer: http://amalia-capital.com/Test
[Mon Jul 20 07:31:20.472398 2026] [security2:error] [pid 148765:tid 148948] [client 35.245.239.138:58137] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jKDv8fXmqCm8fNequJgAAATs"]
[Mon Jul 20 07:31:20.493814 2026] [security2:error] [pid 148765:tid 148853] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jKDv8fXmqCm8fNequKQABFVM"]
[Mon Jul 20 07:31:20.494001 2026] [security2:error] [pid 148765:tid 148910] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jKDv8fXmqCm8fNequKQABFVM"]
[Mon Jul 20 07:31:20.593736 2026] [security2:error] [pid 148765:tid 148940] [client 35.245.239.138:63610] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jKDv8fXmqCm8fNequMQAAATM"]
[Mon Jul 20 07:31:20.630967 2026] [security2:error] [pid 148765:tid 148822] [remote 182.77.62.24:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jKDv8fXmqCm8fNequNwABQDQ"]
[Mon Jul 20 07:31:20.668894 2026] [security2:error] [pid 148765:tid 148931] [client 179.96.138.242:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elementconstruction.co.uk"] [uri "/index.php"] [unique_id "al4jKDv8fXmqCm8fNequKAAAASo"]
[Mon Jul 20 07:31:20.669637 2026] [security2:error] [pid 148765:tid 148999] [client 14.225.17.146:57087] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4jJjv8fXmqCm8fNeqtjAAAAW4"], referer: http://fluidtemple.org/Test
[Mon Jul 20 07:31:20.736061 2026] [security2:error] [pid 148765:tid 149004] [client 35.245.239.138:63872] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jKDv8fXmqCm8fNequRQAAAXM"]
[Mon Jul 20 07:31:20.784032 2026] [security2:error] [pid 148765:tid 148984] [client 65.111.21.143:17927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jKDv8fXmqCm8fNequRgAAAV8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:31:20.913474 2026] [security2:error] [pid 148765:tid 148908] [client 35.245.239.138:61126] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4jKDv8fXmqCm8fNequUgAAARM"]
[Mon Jul 20 07:31:20.944863 2026] [security2:error] [pid 148765:tid 148891] [remote 100.42.189.89:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jKDv8fXmqCm8fNequVgABOHk"]
[Mon Jul 20 07:31:21.041864 2026] [security2:error] [pid 148765:tid 148932] [client 35.245.239.138:65379] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequWQAAASs"]
[Mon Jul 20 07:31:21.139443 2026] [security2:error] [pid 148765:tid 148786] [remote 100.42.189.89:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jKTv8fXmqCm8fNequbAABbxA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:31:21.148197 2026] [security2:error] [pid 148765:tid 148909] [client 173.214.177.60:41061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jKTv8fXmqCm8fNequXgAAARQ"]
[Mon Jul 20 07:31:21.171836 2026] [security2:error] [pid 148765:tid 149026] [client 35.245.239.138:52739] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequdAAAAYk"]
[Mon Jul 20 07:31:21.319280 2026] [security2:error] [pid 148765:tid 149022] [client 35.245.239.138:64909] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequeQAAAYU"]
[Mon Jul 20 07:31:21.332796 2026] [security2:error] [pid 148765:tid 148874] [remote 182.77.62.24:50538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jKTv8fXmqCm8fNequegABg2g"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:31:21.417348 2026] [autoindex:error] [pid 148765:tid 148926] [client 66.249.73.103:42198] AH01276: Cannot serve directory /home2/qfobarmy/public_html/wp-content/plugins/premium-stock-market-widgets/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:31:21.455248 2026] [security2:error] [pid 148765:tid 148973] [client 35.245.239.138:58781] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequgwAAAVQ"]
[Mon Jul 20 07:31:21.599117 2026] [security2:error] [pid 148765:tid 148936] [client 35.245.239.138:63622] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequjgAAAS8"]
[Mon Jul 20 07:31:21.721650 2026] [security2:error] [pid 148765:tid 148986] [client 35.245.239.138:50402] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequmgAAAWE"]
[Mon Jul 20 07:31:21.866145 2026] [security2:error] [pid 148765:tid 148963] [client 35.245.239.138:59077] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jKTv8fXmqCm8fNequowAAAUo"]
[Mon Jul 20 07:31:22.041327 2026] [security2:error] [pid 148765:tid 148943] [client 35.245.239.138:56030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-ba575a2e.heidimortenson.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jKjv8fXmqCm8fNequtwAAATY"]
[Mon Jul 20 07:31:22.184474 2026] [security2:error] [pid 148765:tid 148972] [client 14.225.17.146:64167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4jKDv8fXmqCm8fNequHQAAAVM"], referer: http://ccsdifference.com/Test
[Mon Jul 20 07:31:22.320505 2026] [security2:error] [pid 148765:tid 148832] [remote 217.61.143.92:39004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4jKjv8fXmqCm8fNequ0wABWD4"]
[Mon Jul 20 07:31:22.433061 2026] [security2:error] [pid 148765:tid 148988] [client 105.107.103.74:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4jKjv8fXmqCm8fNequuwAAAWM"]
[Mon Jul 20 07:31:22.437447 2026] [core:error] [pid 148765:tid 148912] [client 14.225.17.146:50360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:31:22.437468 2026] [core:error] [pid 148765:tid 148912] [client 14.225.17.146:50360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:31:22.462610 2026] [security2:error] [pid 148765:tid 148995] [client 14.251.3.155:56068] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4jKjv8fXmqCm8fNequ4AAAAWo"]
[Mon Jul 20 07:31:22.470013 2026] [security2:error] [pid 148765:tid 148996] [client 57.141.18.93:55952] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jKDv8fXmqCm8fNequSgABa2U"]
[Mon Jul 20 07:31:22.497757 2026] [security2:error] [pid 148765:tid 148962] [client 14.225.17.146:62061] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4jKTv8fXmqCm8fNequkQAAAUk"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/Test
[Mon Jul 20 07:31:22.513144 2026] [security2:error] [pid 148765:tid 148937] [client 14.225.17.146:50311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4jKjv8fXmqCm8fNequ1QAAATA"], referer: http://backandneckpainrelieflaceychiropractor.com/Test
[Mon Jul 20 07:31:22.555096 2026] [security2:error] [pid 148765:tid 148849] [remote 217.61.143.92:39004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4jKjv8fXmqCm8fNequ5gABeE8"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:31:22.744128 2026] [security2:error] [pid 148765:tid 148963] [client 144.16.21.149:36245] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jKjv8fXmqCm8fNequ-wAAAUo"]
[Mon Jul 20 07:31:22.744320 2026] [security2:error] [pid 148765:tid 148963] [client 144.16.21.149:36245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jKjv8fXmqCm8fNequ-wAAAUo"]
[Mon Jul 20 07:31:22.788771 2026] [security2:error] [pid 148765:tid 148925] [client 14.225.17.146:64121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4jKTv8fXmqCm8fNequYgAAASQ"], referer: http://ksands.co.uk/Test
[Mon Jul 20 07:31:22.902004 2026] [security2:error] [pid 148765:tid 149018] [client 14.225.17.146:61908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4jKTv8fXmqCm8fNequjAAAAYE"], referer: http://effingweirdmuseums.com/Test
[Mon Jul 20 07:31:22.996850 2026] [security2:error] [pid 148765:tid 148997] [client 57.141.18.71:56728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jKTv8fXmqCm8fNequgQABbC4"]
[Mon Jul 20 07:31:23.089417 2026] [autoindex:error] [pid 148765:tid 148900] [client 104.196.202.31:0] AH01276: Cannot serve directory /home2/bluestm2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://suq.iks.mybluehost.me
[Mon Jul 20 07:31:23.110299 2026] [security2:error] [pid 148765:tid 148994] [client 49.37.242.14:65171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jKzv8fXmqCm8fNeqvFwAAAWk"]
[Mon Jul 20 07:31:23.110418 2026] [security2:error] [pid 148765:tid 148994] [client 49.37.242.14:65171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jKzv8fXmqCm8fNeqvFwAAAWk"]
[Mon Jul 20 07:31:23.222916 2026] [security2:error] [pid 148765:tid 149016] [client 14.225.17.146:53281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4jKzv8fXmqCm8fNeqvDQAAAX8"], referer: https://ccsdifference.com/Test
[Mon Jul 20 07:31:23.230046 2026] [security2:error] [pid 148765:tid 148935] [client 57.141.18.66:34168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jKTv8fXmqCm8fNequjQABLho"]
[Mon Jul 20 07:31:23.436055 2026] [security2:error] [pid 148765:tid 148962] [client 158.173.89.95:65271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jKzv8fXmqCm8fNeqvNAAAAUk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:31:23.630685 2026] [security2:error] [pid 148765:tid 148856] [remote 62.193.192.222:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jKzv8fXmqCm8fNeqvRgABZlY"]
[Mon Jul 20 07:31:23.659110 2026] [security2:error] [pid 148765:tid 148922] [client 149.0.16.108:65323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jKzv8fXmqCm8fNeqvSwAAASE"]
[Mon Jul 20 07:31:23.659215 2026] [security2:error] [pid 148765:tid 148922] [client 149.0.16.108:65323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jKzv8fXmqCm8fNeqvSwAAASE"]
[Mon Jul 20 07:31:23.797151 2026] [security2:error] [pid 148765:tid 148790] [remote 62.193.192.222:55754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.192.193.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jKzv8fXmqCm8fNeqvYwABCxQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:31:23.899017 2026] [security2:error] [pid 148765:tid 148982] [client 14.225.17.146:49993] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4jKjv8fXmqCm8fNequ0gAAAV0"], referer: http://margaretspeckogawa.com/Test
[Mon Jul 20 07:31:23.986309 2026] [security2:error] [pid 148765:tid 148962] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jKzv8fXmqCm8fNeqvYAAAAUk"]
[Mon Jul 20 07:31:24.002362 2026] [security2:error] [pid 148765:tid 148981] [client 14.225.17.146:62167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4jKzv8fXmqCm8fNeqvaQAAAVw"], referer: http://iagdevelopments.com/Test
[Mon Jul 20 07:31:24.017498 2026] [security2:error] [pid 148765:tid 148977] [client 14.225.17.146:62181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4jKzv8fXmqCm8fNeqvawAAAVg"], referer: https://effingweirdmuseums.com/Test
[Mon Jul 20 07:31:24.135098 2026] [security2:error] [pid 148765:tid 148937] [client 63.176.132.15:26620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvgwAAATA"]
[Mon Jul 20 07:31:24.135185 2026] [security2:error] [pid 148765:tid 148937] [client 63.176.132.15:26620] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvgwAAATA"]
[Mon Jul 20 07:31:24.326434 2026] [security2:error] [pid 148765:tid 148973] [client 155.2.215.68:23229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.215.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvlAAAAVQ"]
[Mon Jul 20 07:31:24.326522 2026] [security2:error] [pid 148765:tid 148973] [client 155.2.215.68:23229] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvlAAAAVQ"]
[Mon Jul 20 07:31:24.350367 2026] [security2:error] [pid 148765:tid 148974] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jLDv8fXmqCm8fNeqvhQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:24.446505 2026] [security2:error] [pid 148765:tid 149007] [client 104.234.53.93:45769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4jLDv8fXmqCm8fNeqvoAAAAXY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:31:24.482900 2026] [security2:error] [pid 148765:tid 148940] [client 57.141.18.88:40968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jKjv8fXmqCm8fNequ-gABMxI"]
[Mon Jul 20 07:31:24.604254 2026] [security2:error] [pid 148765:tid 148923] [client 136.158.60.21:12270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvtAAAASI"]
[Mon Jul 20 07:31:24.604425 2026] [security2:error] [pid 148765:tid 148923] [client 136.158.60.21:12270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvtAAAASI"]
[Mon Jul 20 07:31:24.760147 2026] [security2:error] [pid 148765:tid 148986] [client 14.225.17.146:61978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4jLDv8fXmqCm8fNeqvswAAAWE"], referer: http://carolinapressurewashers.com/Test
[Mon Jul 20 07:31:24.808947 2026] [security2:error] [pid 148765:tid 148906] [client 35.245.239.138:59338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/xmlrpc.php"] [unique_id "al4jLDv8fXmqCm8fNeqvxwAAARE"]
[Mon Jul 20 07:31:25.126534 2026] [security2:error] [pid 148765:tid 148995] [client 35.245.239.138:59154] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jLTv8fXmqCm8fNeqv2QAAAWo"]
[Mon Jul 20 07:31:25.421131 2026] [security2:error] [pid 148765:tid 148938] [client 143.44.185.218:22990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jLTv8fXmqCm8fNeqv9QAAATE"]
[Mon Jul 20 07:31:25.421935 2026] [security2:error] [pid 148765:tid 148938] [client 143.44.185.218:22990] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jLTv8fXmqCm8fNeqv9QAAATE"]
[Mon Jul 20 07:31:25.569400 2026] [security2:error] [pid 148765:tid 148950] [client 35.245.239.138:55866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jLTv8fXmqCm8fNeqv_QAAAT0"]
[Mon Jul 20 07:31:25.701602 2026] [security2:error] [pid 148765:tid 148969] [client 157.20.138.62:57704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jLTv8fXmqCm8fNeqwCwAAAVA"]
[Mon Jul 20 07:31:25.701745 2026] [security2:error] [pid 148765:tid 148969] [client 157.20.138.62:57704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jLTv8fXmqCm8fNeqwCwAAAVA"]
[Mon Jul 20 07:31:25.764588 2026] [security2:error] [pid 148765:tid 149022] [client 77.110.127.138:50687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/beaded-tealight-crochet-course-surrey/9xprjapt1enq.php"] [unique_id "al4jLTv8fXmqCm8fNeqwEQAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:25.879394 2026] [security2:error] [pid 148765:tid 148936] [client 35.245.239.138:59465] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jLTv8fXmqCm8fNeqwIwAAAS8"]
[Mon Jul 20 07:31:25.936987 2026] [security2:error] [pid 148765:tid 149014] [client 14.225.17.146:62056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4jLDv8fXmqCm8fNeqv0gAAAX0"], referer: http://entuvy.com/Test
[Mon Jul 20 07:31:26.088471 2026] [security2:error] [pid 148765:tid 148940] [client 77.110.127.138:50688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jLTv8fXmqCm8fNeqwFAAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:26.094063 2026] [security2:error] [pid 148765:tid 148926] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jLTv8fXmqCm8fNeqwGQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:26.132531 2026] [security2:error] [pid 148765:tid 148998] [client 35.245.239.138:54813] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4jLjv8fXmqCm8fNeqwMgAAAW0"]
[Mon Jul 20 07:31:26.196238 2026] [security2:error] [pid 148765:tid 149016] [client 191.202.66.27:54230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwPgAAAX8"]
[Mon Jul 20 07:31:26.196335 2026] [security2:error] [pid 148765:tid 149016] [client 191.202.66.27:54230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwPgAAAX8"]
[Mon Jul 20 07:31:26.206169 2026] [security2:error] [pid 148765:tid 148900] [client 14.225.17.146:61848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4jLDv8fXmqCm8fNeqvpwAAAQs"], referer: http://cheesewithjam.com/Test
[Mon Jul 20 07:31:26.370065 2026] [security2:error] [pid 148765:tid 148944] [client 45.183.23.136:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4jLTv8fXmqCm8fNeqwDAAAATc"]
[Mon Jul 20 07:31:26.460989 2026] [security2:error] [pid 148765:tid 149008] [client 35.245.239.138:56030] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4jLjv8fXmqCm8fNeqwXQAAAXc"]
[Mon Jul 20 07:31:26.514290 2026] [security2:error] [pid 148765:tid 148899] [client 179.127.84.238:56216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwYQAAAQo"]
[Mon Jul 20 07:31:26.514405 2026] [security2:error] [pid 148765:tid 148899] [client 179.127.84.238:56216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwYQAAAQo"]
[Mon Jul 20 07:31:26.691229 2026] [security2:error] [pid 148765:tid 148994] [client 77.110.127.138:50701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/chart/feed/k8pb8pkph659.php"] [unique_id "al4jLjv8fXmqCm8fNeqwcgAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:26.711439 2026] [security2:error] [pid 148765:tid 148770] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqweAABaAA"]
[Mon Jul 20 07:31:26.711592 2026] [security2:error] [pid 148765:tid 148993] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqweAABaAA"]
[Mon Jul 20 07:31:26.721327 2026] [security2:error] [pid 148765:tid 148958] [client 35.245.239.138:56970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jLjv8fXmqCm8fNeqwgAAAAUU"]
[Mon Jul 20 07:31:26.747597 2026] [security2:error] [pid 148765:tid 148932] [client 49.47.218.174:56266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwhAAAASs"]
[Mon Jul 20 07:31:26.747762 2026] [security2:error] [pid 148765:tid 148932] [client 49.47.218.174:56266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwhAAAASs"]
[Mon Jul 20 07:31:26.762915 2026] [security2:error] [pid 148765:tid 148968] [client 88.241.67.160:55717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwhQAAAU8"]
[Mon Jul 20 07:31:26.763120 2026] [security2:error] [pid 148765:tid 148968] [client 88.241.67.160:55717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jLjv8fXmqCm8fNeqwhQAAAU8"]
[Mon Jul 20 07:31:26.865518 2026] [security2:error] [pid 148765:tid 148908] [client 77.110.127.138:50608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwZAAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:26.867790 2026] [security2:error] [pid 148765:tid 149001] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwaAAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:27.038918 2026] [security2:error] [pid 148765:tid 148957] [client 35.245.239.138:55226] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4jLzv8fXmqCm8fNeqwmAAAAUQ"]
[Mon Jul 20 07:31:27.044737 2026] [security2:error] [pid 148765:tid 148982] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwggAAAV0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:27.101859 2026] [security2:error] [pid 148765:tid 148902] [client 14.225.17.146:61703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwjwAAAQ0"], referer: http://transparentservices.online/Test
[Mon Jul 20 07:31:27.329393 2026] [security2:error] [pid 148765:tid 148923] [client 35.245.239.138:59497] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jLzv8fXmqCm8fNeqwrAAAASI"]
[Mon Jul 20 07:31:27.400768 2026] [security2:error] [pid 148765:tid 148793] [remote 47.86.33.52:40486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4jLzv8fXmqCm8fNeqwsAABWxc"]
[Mon Jul 20 07:31:27.535605 2026] [security2:error] [pid 148765:tid 148976] [client 14.225.17.146:61773] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4jLzv8fXmqCm8fNeqwrgAAAVc"], referer: http://soloceos.com/Test
[Mon Jul 20 07:31:27.650083 2026] [security2:error] [pid 148765:tid 148943] [client 35.245.239.138:64607] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jLzv8fXmqCm8fNeqwyAAAATY"]
[Mon Jul 20 07:31:27.713171 2026] [security2:error] [pid 148765:tid 148925] [client 57.141.18.7:52162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwNwABJH0"]
[Mon Jul 20 07:31:27.779890 2026] [security2:error] [pid 148765:tid 148837] [remote 182.77.62.24:33666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jLzv8fXmqCm8fNeqw3AABbEM"]
[Mon Jul 20 07:31:27.780082 2026] [security2:error] [pid 148765:tid 148997] [client 182.77.62.24:33666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jLzv8fXmqCm8fNeqw3AABbEM"]
[Mon Jul 20 07:31:27.926088 2026] [security2:error] [pid 148765:tid 149022] [client 35.245.239.138:65213] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jLzv8fXmqCm8fNeqw5wAAAYU"]
[Mon Jul 20 07:31:27.943490 2026] [security2:error] [pid 148765:tid 149001] [client 154.192.123.127:18170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jLzv8fXmqCm8fNeqw6AAAAXA"]
[Mon Jul 20 07:31:27.943623 2026] [security2:error] [pid 148765:tid 149001] [client 154.192.123.127:18170] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jLzv8fXmqCm8fNeqw6AAAAXA"]
[Mon Jul 20 07:31:27.954168 2026] [security2:error] [pid 148765:tid 148929] [client 114.119.130.40:57787] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.itdynamix.com"] [uri "/robots.txt"] [unique_id "al4jLzv8fXmqCm8fNeqw6QAAASg"], referer: http://www.itdynamix.com/robots.txt
[Mon Jul 20 07:31:27.956054 2026] [security2:error] [pid 148765:tid 148977] [client 57.141.18.82:56922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwUwABWB8"]
[Mon Jul 20 07:31:27.992076 2026] [security2:error] [pid 148765:tid 148991] [client 50.116.65.227:19722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jLzv8fXmqCm8fNeqw7QAAAWY"]
[Mon Jul 20 07:31:28.001424 2026] [security2:error] [pid 148765:tid 148987] [client 50.116.65.227:19728] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jLzv8fXmqCm8fNeqw7wAAAWI"]
[Mon Jul 20 07:31:28.205663 2026] [security2:error] [pid 148765:tid 148992] [client 57.141.18.3:47772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jLjv8fXmqCm8fNeqwaQABZw4"]
[Mon Jul 20 07:31:28.302407 2026] [security2:error] [pid 148765:tid 148952] [client 35.245.239.138:56692] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "kingsafety.ca"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jMDv8fXmqCm8fNeqxBAAAAT8"]
[Mon Jul 20 07:31:28.421781 2026] [security2:error] [pid 148765:tid 148900] [client 36.93.152.155:51566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jMDv8fXmqCm8fNeqxDwAAAQs"]
[Mon Jul 20 07:31:28.421868 2026] [security2:error] [pid 148765:tid 148900] [client 36.93.152.155:51566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jMDv8fXmqCm8fNeqxDwAAAQs"]
[Mon Jul 20 07:31:28.598244 2026] [security2:error] [pid 148765:tid 148994] [client 117.211.236.168:52463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jMDv8fXmqCm8fNeqxHQAAAWk"]
[Mon Jul 20 07:31:28.598367 2026] [security2:error] [pid 148765:tid 148994] [client 117.211.236.168:52463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jMDv8fXmqCm8fNeqxHQAAAWk"]
[Mon Jul 20 07:31:28.640035 2026] [security2:error] [pid 148765:tid 148964] [client 57.141.18.95:34286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jLzv8fXmqCm8fNeqwmQABSxo"]
[Mon Jul 20 07:31:28.717303 2026] [security2:error] [pid 148765:tid 148827] [remote 152.56.21.31:0] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jMDv8fXmqCm8fNeqxKAABeTk"]
[Mon Jul 20 07:31:28.717508 2026] [security2:error] [pid 148765:tid 149010] [client 152.56.21.31:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "ttb-sa.com"] [uri "/xmlrpc.php"] [unique_id "al4jMDv8fXmqCm8fNeqxKAABeTk"]
[Mon Jul 20 07:31:28.859685 2026] [security2:error] [pid 148765:tid 148890] [remote 112.86.225.36:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ali-alghanim.net"] [uri "/"] [unique_id "al4jMDv8fXmqCm8fNeqxMAABN3g"]
[Mon Jul 20 07:31:28.859895 2026] [security2:error] [pid 148765:tid 148944] [client 112.86.225.36:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ali-alghanim.net"] [uri "/"] [unique_id "al4jMDv8fXmqCm8fNeqxMAABN3g"]
[Mon Jul 20 07:31:28.978155 2026] [security2:error] [pid 148765:tid 148940] [client 77.110.127.138:50714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/beaded-tealight-holder-crochet-pattern/3v5t2wt0gn6i.php"] [unique_id "al4jMDv8fXmqCm8fNeqxQQAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:29.249453 2026] [security2:error] [pid 148765:tid 148900] [client 77.110.127.138:50712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMDv8fXmqCm8fNeqxPAAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:29.290120 2026] [security2:error] [pid 148765:tid 148947] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMDv8fXmqCm8fNeqxSAAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:29.295108 2026] [security2:error] [pid 148765:tid 148983] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMTv8fXmqCm8fNeqxSwAAAV4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:29.345301 2026] [security2:error] [pid 148765:tid 148928] [client 43.205.139.3:27668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4jMTv8fXmqCm8fNeqxagAAASc"]
[Mon Jul 20 07:31:29.359095 2026] [security2:error] [pid 148765:tid 148918] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.chadoldfather.com"] [uri "/index.php"] [unique_id "al4jLTv8fXmqCm8fNeqv3wAAAR0"]
[Mon Jul 20 07:31:29.628877 2026] [security2:error] [pid 148765:tid 148802] [remote 91.142.222.105:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4jMTv8fXmqCm8fNeqxgAABOyA"]
[Mon Jul 20 07:31:29.768902 2026] [security2:error] [pid 148765:tid 148931] [client 77.110.127.138:50680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-border/feed/o3afxgu7j3z4.php"] [unique_id "al4jMTv8fXmqCm8fNeqxjwAAASo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:29.796203 2026] [security2:error] [pid 148765:tid 149022] [client 103.106.165.44:57636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jMTv8fXmqCm8fNeqxmQAAAYU"]
[Mon Jul 20 07:31:29.796320 2026] [security2:error] [pid 148765:tid 149022] [client 103.106.165.44:57636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jMTv8fXmqCm8fNeqxmQAAAYU"]
[Mon Jul 20 07:31:29.919238 2026] [security2:error] [pid 148765:tid 148838] [remote 91.142.222.105:40450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "arunavabanerjee.com"] [uri "/wp-login.php"] [unique_id "al4jMTv8fXmqCm8fNeqxrAABaEQ"], referer: https://arunavabanerjee.com/wp-login.php
[Mon Jul 20 07:31:29.957239 2026] [security2:error] [pid 148765:tid 148876] [remote 20.153.140.50:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4jMTv8fXmqCm8fNeqxsAABJWo"]
[Mon Jul 20 07:31:30.024426 2026] [security2:error] [pid 148765:tid 148992] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMTv8fXmqCm8fNeqxmAAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:30.089581 2026] [security2:error] [pid 148765:tid 148912] [client 77.110.127.138:50720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMTv8fXmqCm8fNeqxoAAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:30.101588 2026] [security2:error] [pid 148765:tid 148910] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMTv8fXmqCm8fNeqxqgAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:30.288249 2026] [security2:error] [pid 148765:tid 148908] [client 103.176.215.66:61273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jMjv8fXmqCm8fNeqxxwAAARM"]
[Mon Jul 20 07:31:30.288343 2026] [security2:error] [pid 148765:tid 148908] [client 103.176.215.66:61273] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jMjv8fXmqCm8fNeqxxwAAARM"]
[Mon Jul 20 07:31:30.299173 2026] [security2:error] [pid 148765:tid 148909] [client 74.208.214.194:42170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jMjv8fXmqCm8fNeqxyAAAARQ"]
[Mon Jul 20 07:31:30.368054 2026] [security2:error] [pid 148765:tid 148770] [remote 20.153.140.50:48798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4jMjv8fXmqCm8fNeqxzQABFgA"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:31:30.394392 2026] [security2:error] [pid 148765:tid 148792] [remote 45.90.123.233:34140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4jMjv8fXmqCm8fNeqx0AABGBY"]
[Mon Jul 20 07:31:30.424218 2026] [security2:error] [pid 148765:tid 148874] [remote 47.86.33.52:40486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "processorstudio.com"] [uri "/wp-login.php"] [unique_id "al4jMjv8fXmqCm8fNeqx0gABT2g"], referer: https://processorstudio.com/wp-login.php
[Mon Jul 20 07:31:30.466947 2026] [security2:error] [pid 148765:tid 148917] [client 77.110.127.138:50710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/colour-work/feed/6rviht1rie3j.php"] [unique_id "al4jMjv8fXmqCm8fNeqx2QAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:30.599825 2026] [security2:error] [pid 148765:tid 148964] [client 43.205.139.3:27684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4jMjv8fXmqCm8fNeqx8wAAAUs"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:31:30.611731 2026] [autoindex:error] [pid 148765:tid 149019] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/build/related-posts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/plugins/jetpack/_inc/build/related-posts/
[Mon Jul 20 07:31:30.626737 2026] [security2:error] [pid 148765:tid 149005] [client 57.141.18.43:47020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jMDv8fXmqCm8fNeqxRAABdG0"]
[Mon Jul 20 07:31:30.629950 2026] [security2:error] [pid 148765:tid 148811] [remote 45.90.123.233:34140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elitetax-mi.com"] [uri "/wp-login.php"] [unique_id "al4jMjv8fXmqCm8fNeqx-QABPik"], referer: https://elitetax-mi.com/wp-login.php
[Mon Jul 20 07:31:30.663759 2026] [security2:error] [pid 148765:tid 148996] [client 14.225.17.146:61615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4jMDv8fXmqCm8fNeqxBwAAAWs"], referer: http://nurturemarple.co.uk/Test
[Mon Jul 20 07:31:30.772075 2026] [security2:error] [pid 148765:tid 148956] [client 77.110.127.138:50661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMjv8fXmqCm8fNeqx2gAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:30.803432 2026] [security2:error] [pid 148765:tid 148995] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMjv8fXmqCm8fNeqx3wAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:30.948225 2026] [security2:error] [pid 148765:tid 148909] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jMjv8fXmqCm8fNeqx_QAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:31.137440 2026] [security2:error] [pid 148765:tid 148928] [client 50.116.65.227:51960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4jMjv8fXmqCm8fNeqyCQAAASc"]
[Mon Jul 20 07:31:31.143217 2026] [security2:error] [pid 148765:tid 148962] [client 89.29.232.60:60704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jMzv8fXmqCm8fNeqyEAABSRc"]
[Mon Jul 20 07:31:31.143260 2026] [security2:error] [pid 148765:tid 148962] [client 89.29.232.60:60704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jMzv8fXmqCm8fNeqyEAABSRc"]
[Mon Jul 20 07:31:31.293004 2026] [security2:error] [pid 148765:tid 148882] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jMzv8fXmqCm8fNeqyJAABYnA"]
[Mon Jul 20 07:31:31.293210 2026] [security2:error] [pid 148765:tid 148987] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jMzv8fXmqCm8fNeqyJAABYnA"]
[Mon Jul 20 07:31:31.332127 2026] [security2:error] [pid 148765:tid 149013] [client 50.116.65.227:51964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4jMzv8fXmqCm8fNeqyFwAAAXw"]
[Mon Jul 20 07:31:31.422506 2026] [security2:error] [pid 148765:tid 148990] [client 193.37.33.29:41225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4jMzv8fXmqCm8fNeqyJwAAAWU"]
[Mon Jul 20 07:31:31.509746 2026] [security2:error] [pid 148765:tid 148776] [remote 84.247.172.23:33032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jMzv8fXmqCm8fNeqyLQABeQY"]
[Mon Jul 20 07:31:31.563148 2026] [security2:error] [pid 148765:tid 148939] [client 14.225.17.146:61426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4jMjv8fXmqCm8fNeqxugAAATI"], referer: http://dnsplumbing.com/Test
[Mon Jul 20 07:31:31.853022 2026] [security2:error] [pid 148765:tid 148892] [remote 188.40.28.4:49824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jMzv8fXmqCm8fNeqyVAABQ3o"]
[Mon Jul 20 07:31:31.853200 2026] [security2:error] [pid 148765:tid 148956] [client 188.40.28.4:49824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jMzv8fXmqCm8fNeqyVAABQ3o"]
[Mon Jul 20 07:31:31.889715 2026] [security2:error] [pid 148765:tid 149015] [client 57.141.18.108:61136] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jMjv8fXmqCm8fNeqxyQABfh4"]
[Mon Jul 20 07:31:32.098450 2026] [autoindex:error] [pid 148765:tid 149009] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:31:32.099645 2026] [autoindex:error] [pid 148765:tid 149022] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:31:32.166250 2026] [security2:error] [pid 148765:tid 148986] [client 77.110.127.138:50730] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2015/ung6k25tur3s.php"] [unique_id "al4jNDv8fXmqCm8fNeqyegAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:32.266775 2026] [security2:error] [pid 148765:tid 148936] [client 77.110.127.138:50665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jNDv8fXmqCm8fNeqyYAAAAS8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:32.295653 2026] [security2:error] [pid 148765:tid 149005] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jNDv8fXmqCm8fNeqyaQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:32.703371 2026] [security2:error] [pid 148765:tid 148850] [remote 84.247.172.23:33032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jNDv8fXmqCm8fNeqyswABalA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:31:33.276483 2026] [security2:error] [pid 148765:tid 148947] [client 57.141.18.61:22982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jMzv8fXmqCm8fNeqyQwABOis"]
[Mon Jul 20 07:31:33.601430 2026] [security2:error] [pid 148765:tid 148966] [client 103.139.191.61:58323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jNTv8fXmqCm8fNeqy_QAAAU0"]
[Mon Jul 20 07:31:33.601595 2026] [security2:error] [pid 148765:tid 148966] [client 103.139.191.61:58323] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jNTv8fXmqCm8fNeqy_QAAAU0"]
[Mon Jul 20 07:31:33.975249 2026] [security2:error] [pid 148765:tid 148912] [client 77.110.127.138:50725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2015/11/9mu59jpn29fi.php"] [unique_id "al4jNTv8fXmqCm8fNeqzJwAAARc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:34.006873 2026] [autoindex:error] [pid 148765:tid 148970] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:31:34.011856 2026] [autoindex:error] [pid 148765:tid 148967] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:31:34.192515 2026] [security2:error] [pid 148765:tid 148907] [client 57.141.18.54:51316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jNDv8fXmqCm8fNeqyowABEhE"]
[Mon Jul 20 07:31:34.198679 2026] [security2:error] [pid 148765:tid 148951] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jNTv8fXmqCm8fNeqzNAAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:34.347179 2026] [security2:error] [pid 148765:tid 148961] [client 149.0.16.108:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzXgAAAUg"]
[Mon Jul 20 07:31:34.347718 2026] [security2:error] [pid 148765:tid 148961] [client 149.0.16.108:49629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzXgAAAUg"]
[Mon Jul 20 07:31:34.368386 2026] [security2:error] [pid 148765:tid 148930] [client 77.110.127.138:50739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jNjv8fXmqCm8fNeqzPQAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:34.394396 2026] [security2:error] [pid 148765:tid 148996] [client 57.141.18.24:61964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jNDv8fXmqCm8fNeqytgABa2A"]
[Mon Jul 20 07:31:34.414345 2026] [security2:error] [pid 148765:tid 148990] [client 144.16.21.149:24887] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzYwAAAWU"]
[Mon Jul 20 07:31:34.414471 2026] [security2:error] [pid 148765:tid 148990] [client 144.16.21.149:24887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzYwAAAWU"]
[Mon Jul 20 07:31:34.688058 2026] [security2:error] [pid 148765:tid 148989] [client 52.59.238.198:34210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzdwAAAWQ"]
[Mon Jul 20 07:31:34.688170 2026] [security2:error] [pid 148765:tid 148989] [client 52.59.238.198:34210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzdwAAAWQ"]
[Mon Jul 20 07:31:34.791532 2026] [security2:error] [pid 148765:tid 148979] [client 57.141.18.109:54618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jNTv8fXmqCm8fNeqy2wABWkw"]
[Mon Jul 20 07:31:34.914444 2026] [security2:error] [pid 148765:tid 148957] [client 216.173.120.131:44983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jNjv8fXmqCm8fNeqzjQAAAUQ"]
[Mon Jul 20 07:31:35.016770 2026] [security2:error] [pid 148765:tid 148824] [remote 20.173.88.122:44596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jNzv8fXmqCm8fNeqznwABODY"]
[Mon Jul 20 07:31:35.017587 2026] [security2:error] [pid 148765:tid 148949] [client 142.111.152.53:63651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 53.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzlgAAATw"]
[Mon Jul 20 07:31:35.017676 2026] [security2:error] [pid 148765:tid 148949] [client 142.111.152.53:63651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jNjv8fXmqCm8fNeqzlgAAATw"]
[Mon Jul 20 07:31:35.154217 2026] [autoindex:error] [pid 148765:tid 149026] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/category/crochet-tutor/
[Mon Jul 20 07:31:35.291105 2026] [security2:error] [pid 148765:tid 148933] [client 57.141.18.14:50964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jNTv8fXmqCm8fNeqzBwABLCQ"]
[Mon Jul 20 07:31:35.330997 2026] [security2:error] [pid 148765:tid 148976] [client 136.158.60.21:13693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jNzv8fXmqCm8fNeqzwAAAAVc"]
[Mon Jul 20 07:31:35.331142 2026] [security2:error] [pid 148765:tid 148976] [client 136.158.60.21:13693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jNzv8fXmqCm8fNeqzwAAAAVc"]
[Mon Jul 20 07:31:35.350985 2026] [security2:error] [pid 148765:tid 148972] [client 116.74.65.235:63122] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4jNzv8fXmqCm8fNeqzogAAAVM"]
[Mon Jul 20 07:31:35.352129 2026] [security2:error] [pid 148765:tid 148869] [remote 20.173.88.122:44596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jNzv8fXmqCm8fNeqzwwABd2M"], referer: https://rcq.nst.mybluehost.me/wp-login.php
[Mon Jul 20 07:31:35.604792 2026] [security2:error] [pid 148765:tid 148917] [client 49.37.242.14:49334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jNzv8fXmqCm8fNeqz0QAAARw"]
[Mon Jul 20 07:31:35.604917 2026] [security2:error] [pid 148765:tid 148917] [client 49.37.242.14:49334] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jNzv8fXmqCm8fNeqz0QAAARw"]
[Mon Jul 20 07:31:36.115226 2026] [security2:error] [pid 148765:tid 148822] [remote 57.141.18.102:30720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jNjv8fXmqCm8fNeqzbAABhTQ"]
[Mon Jul 20 07:31:36.366955 2026] [security2:error] [pid 148765:tid 148950] [client 157.20.138.62:58272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jODv8fXmqCm8fNeqz8AAAAT0"]
[Mon Jul 20 07:31:36.367151 2026] [security2:error] [pid 148765:tid 148950] [client 157.20.138.62:58272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jODv8fXmqCm8fNeqz8AAAAT0"]
[Mon Jul 20 07:31:36.580003 2026] [security2:error] [pid 148765:tid 148857] [remote 57.141.18.45:56920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jNjv8fXmqCm8fNeqzlwABH1c"]
[Mon Jul 20 07:31:36.654134 2026] [http2:info] [pid 156215:tid 156215] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:31:36.898377 2026] [security2:error] [pid 156215:tid 156252] [remote 4.205.168.44:37062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4jOMJ0fwhpxOKR8YgW6AAACiQ"]
[Mon Jul 20 07:31:37.004153 2026] [security2:error] [pid 156215:tid 156469] [client 77.110.127.138:50761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-courses/feed/icdtlghi778v.php"] [unique_id "al4jOcJ0fwhpxOKR8YgW9AAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:37.043973 2026] [security2:error] [pid 156215:tid 156373] [client 191.202.66.27:54726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgW_wAAABw"]
[Mon Jul 20 07:31:37.044158 2026] [security2:error] [pid 156215:tid 156373] [client 191.202.66.27:54726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgW_wAAABw"]
[Mon Jul 20 07:31:37.108315 2026] [security2:error] [pid 156215:tid 156263] [remote 4.205.168.44:37062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.168.205.4.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.com"] [uri "/wp-login.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXCgAAFy8"], referer: https://viennarotaryfoundation.com/wp-login.php
[Mon Jul 20 07:31:37.126881 2026] [security2:error] [pid 156215:tid 156425] [client 179.127.84.238:56748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXDwAAAFA"]
[Mon Jul 20 07:31:37.126992 2026] [security2:error] [pid 156215:tid 156425] [client 179.127.84.238:56748] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXDwAAAFA"]
[Mon Jul 20 07:31:37.217519 2026] [security2:error] [pid 156215:tid 156419] [client 49.47.218.174:56804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXGAAAAEo"]
[Mon Jul 20 07:31:37.217648 2026] [security2:error] [pid 156215:tid 156419] [client 49.47.218.174:56804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXGAAAAEo"]
[Mon Jul 20 07:31:37.257542 2026] [security2:error] [pid 156215:tid 156376] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgW-AAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:37.323971 2026] [security2:error] [pid 156215:tid 156470] [client 77.110.127.138:50763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgW_AAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:37.328876 2026] [security2:error] [pid 156215:tid 156420] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXBQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:31:37.358744 2026] [security2:error] [pid 156215:tid 156274] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXIwAAazo"]
[Mon Jul 20 07:31:37.358978 2026] [security2:error] [pid 156215:tid 156452] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXIwAAazo"]
[Mon Jul 20 07:31:37.475005 2026] [security2:error] [pid 156215:tid 156347] [client 88.241.67.160:54305] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXLAAAAAI"]
[Mon Jul 20 07:31:37.475208 2026] [security2:error] [pid 156215:tid 156347] [client 88.241.67.160:54305] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXLAAAAAI"]
[Mon Jul 20 07:31:38.061351 2026] [security2:error] [pid 156215:tid 156396] [client 143.44.185.218:24602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXXgAAADM"]
[Mon Jul 20 07:31:38.061516 2026] [security2:error] [pid 156215:tid 156396] [client 143.44.185.218:24602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXXgAAADM"]
[Mon Jul 20 07:31:38.240990 2026] [security2:error] [pid 156215:tid 156465] [client 193.37.33.26:31549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXbgAAAHg"]
[Mon Jul 20 07:31:38.251460 2026] [security2:error] [pid 156215:tid 156346] [client 57.141.18.39:36625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOMJ0fwhpxOKR8YgWqgAAAQc"]
[Mon Jul 20 07:31:38.273860 2026] [security2:error] [pid 156215:tid 156381] [client 50.116.65.227:52024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXOwAAACQ"]
[Mon Jul 20 07:31:38.334904 2026] [security2:error] [pid 156215:tid 156356] [client 57.141.18.33:51254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOMJ0fwhpxOKR8YgWqQAACwY"]
[Mon Jul 20 07:31:38.429298 2026] [security2:error] [pid 156215:tid 156432] [client 154.192.123.127:18667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXfQAAAFc"]
[Mon Jul 20 07:31:38.429421 2026] [security2:error] [pid 156215:tid 156432] [client 154.192.123.127:18667] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXfQAAAFc"]
[Mon Jul 20 07:31:38.564700 2026] [security2:error] [pid 156215:tid 156416] [client 57.141.18.0:24836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXAwAARy0"]
[Mon Jul 20 07:31:38.719935 2026] [security2:error] [pid 156215:tid 156424] [client 57.141.18.1:20090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXFAAATzE"]
[Mon Jul 20 07:31:38.867861 2026] [security2:error] [pid 156215:tid 156374] [client 36.93.152.155:52080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXnwAAAB0"]
[Mon Jul 20 07:31:38.867978 2026] [security2:error] [pid 156215:tid 156374] [client 36.93.152.155:52080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXnwAAAB0"]
[Mon Jul 20 07:31:38.918961 2026] [security2:error] [pid 156215:tid 156417] [client 50.116.65.227:52038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXdQAAAEg"]
[Mon Jul 20 07:31:39.042189 2026] [security2:error] [pid 156215:tid 156353] [client 74.7.227.179:34610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXoQAACG8"], referer: https://tejasenvironmental.com/p=543839
[Mon Jul 20 07:31:39.321155 2026] [security2:error] [pid 156215:tid 156425] [client 57.141.18.83:64966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOcJ0fwhpxOKR8YgXRAAAUEg"]
[Mon Jul 20 07:31:39.347296 2026] [security2:error] [pid 156215:tid 156422] [client 117.211.236.168:53007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jO8J0fwhpxOKR8YgXyQAAAE0"]
[Mon Jul 20 07:31:39.347422 2026] [security2:error] [pid 156215:tid 156422] [client 117.211.236.168:53007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jO8J0fwhpxOKR8YgXyQAAAE0"]
[Mon Jul 20 07:31:39.994342 2026] [security2:error] [pid 156215:tid 156401] [client 57.141.18.68:42458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXdwAAOFw"]
[Mon Jul 20 07:31:40.141243 2026] [security2:error] [pid 156215:tid 156427] [client 127.0.0.1:56422] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4jPMJ0fwhpxOKR8YgX_wAAAFI"]
[Mon Jul 20 07:31:40.141335 2026] [security2:error] [pid 156215:tid 156376] [client 127.0.0.1:56414] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wyi.tdd.mybluehost.me"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4jPMJ0fwhpxOKR8YgX_gAAAB8"]
[Mon Jul 20 07:31:40.141404 2026] [security2:error] [pid 156215:tid 156421] [client 74.7.230.32:41954] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "400"] [hostname "autodiscover.wyi.tdd.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4jPMJ0fwhpxOKR8YgX_QAATB8"]
[Mon Jul 20 07:31:40.260199 2026] [security2:error] [pid 156215:tid 156379] [client 103.106.165.44:58124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jPMJ0fwhpxOKR8YgYEQAAACI"]
[Mon Jul 20 07:31:40.260410 2026] [security2:error] [pid 156215:tid 156379] [client 103.106.165.44:58124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jPMJ0fwhpxOKR8YgYEQAAACI"]
[Mon Jul 20 07:31:40.450700 2026] [security2:error] [pid 156215:tid 156423] [client 57.141.18.49:27486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXngAATm4"]
[Mon Jul 20 07:31:40.879200 2026] [security2:error] [pid 156215:tid 156395] [client 103.176.215.66:61814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jPMJ0fwhpxOKR8YgYTQAAADI"]
[Mon Jul 20 07:31:40.879356 2026] [security2:error] [pid 156215:tid 156395] [client 103.176.215.66:61814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jPMJ0fwhpxOKR8YgYTQAAADI"]
[Mon Jul 20 07:31:41.195674 2026] [security2:error] [pid 156215:tid 156360] [client 50.116.65.227:39792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vpp.qfv.mybluehost.me"] [uri "/website_cb9cb972/wp-cron.php"] [unique_id "al4jPcJ0fwhpxOKR8YgYYgAAAA8"]
[Mon Jul 20 07:31:41.245390 2026] [security2:error] [pid 156215:tid 156470] [client 50.116.65.227:34974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jPcJ0fwhpxOKR8YgYagAAAH0"]
[Mon Jul 20 07:31:41.260639 2026] [security2:error] [pid 156215:tid 156394] [client 50.116.65.227:34976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jPcJ0fwhpxOKR8YgYawAAADE"]
[Mon Jul 20 07:31:41.378606 2026] [security2:error] [pid 156215:tid 156434] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.cuadroconsulting.com"] [uri "/index.php"] [unique_id "al4jOsJ0fwhpxOKR8YgXoAAAAFk"]
[Mon Jul 20 07:31:41.687560 2026] [core:error] [pid 156215:tid 156387] [client 35.245.239.138:65382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:31:41.687584 2026] [core:error] [pid 156215:tid 156387] [client 35.245.239.138:65382] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:31:41.698147 2026] [security2:error] [pid 156215:tid 156414] [client 57.141.18.42:27782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jO8J0fwhpxOKR8YgX9gAARQg"]
[Mon Jul 20 07:31:41.763545 2026] [proxy:error] [pid 156215:tid 156350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:31:41.763586 2026] [proxy_http:error] [pid 156215:tid 156350] [client 107.174.125.142:29992] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:31:41.764189 2026] [proxy:error] [pid 156215:tid 156350] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:31:41.764224 2026] [proxy_http:error] [pid 156215:tid 156350] [client 107.174.125.142:29992] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:31:41.790574 2026] [security2:error] [pid 156215:tid 156423] [client 95.217.114.159:33276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jPcJ0fwhpxOKR8YgYjQAAAE4"]
[Mon Jul 20 07:31:41.837395 2026] [security2:error] [pid 156215:tid 156362] [client 35.245.239.138:63136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jPcJ0fwhpxOKR8YgYngAAABE"]
[Mon Jul 20 07:31:42.097443 2026] [security2:error] [pid 156215:tid 156452] [client 35.245.239.138:58928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jPsJ0fwhpxOKR8YgYsAAAAGs"]
[Mon Jul 20 07:31:42.201688 2026] [security2:error] [pid 156215:tid 156302] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jPsJ0fwhpxOKR8YgYtAAAAlY"]
[Mon Jul 20 07:31:42.201890 2026] [security2:error] [pid 156215:tid 156347] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jPsJ0fwhpxOKR8YgYtAAAAlY"]
[Mon Jul 20 07:31:42.285898 2026] [security2:error] [pid 156215:tid 156361] [client 35.245.239.138:58152] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jPsJ0fwhpxOKR8YgYyQAAABA"]
[Mon Jul 20 07:31:42.317855 2026] [autoindex:error] [pid 156215:tid 156358] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/jetpack/_inc/build/related-posts/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:31:42.499845 2026] [security2:error] [pid 156215:tid 156457] [client 57.141.18.109:46298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jPMJ0fwhpxOKR8YgYSAAAcDc"]
[Mon Jul 20 07:31:42.504396 2026] [security2:error] [pid 156215:tid 156422] [client 35.245.239.138:51637] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jPsJ0fwhpxOKR8YgY3wAAAE0"]
[Mon Jul 20 07:31:42.708358 2026] [security2:error] [pid 156215:tid 156404] [client 223.237.128.244:50886] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4jPsJ0fwhpxOKR8YgYsgAAADs"]
[Mon Jul 20 07:31:42.715368 2026] [security2:error] [pid 156215:tid 156395] [client 35.245.239.138:63145] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4jPsJ0fwhpxOKR8YgY6gAAADI"]
[Mon Jul 20 07:31:42.788022 2026] [security2:error] [pid 156215:tid 156323] [remote 57.141.18.50:46238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3229819"] [unique_id "al4jPsJ0fwhpxOKR8YgY9gAAf2s"]
[Mon Jul 20 07:31:42.927667 2026] [security2:error] [pid 156215:tid 156391] [client 35.245.239.138:60559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4jPsJ0fwhpxOKR8YgY_wAAAC4"]
[Mon Jul 20 07:31:43.002883 2026] [security2:error] [pid 156215:tid 156465] [client 35.245.239.138:54318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-cd1d1451.youpositive.co"] [uri "/index.php"] [unique_id "al4jPsJ0fwhpxOKR8YgY-wAAAHg"]
[Mon Jul 20 07:31:43.050787 2026] [security2:error] [pid 156215:tid 156457] [client 35.245.239.138:53148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jP8J0fwhpxOKR8YgZBAAAAHA"]
[Mon Jul 20 07:31:43.102770 2026] [security2:error] [pid 156215:tid 156421] [client 35.245.239.138:54318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-cd1d1451.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4jP8J0fwhpxOKR8YgZBwAAAEw"]
[Mon Jul 20 07:31:43.102916 2026] [security2:error] [pid 156215:tid 156421] [client 35.245.239.138:54318] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-cd1d1451.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4jP8J0fwhpxOKR8YgZBwAAAEw"]
[Mon Jul 20 07:31:43.221194 2026] [security2:error] [pid 156215:tid 156463] [client 35.245.239.138:52120] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4jP8J0fwhpxOKR8YgZDgAAAHY"]
[Mon Jul 20 07:31:43.354069 2026] [security2:error] [pid 156215:tid 156468] [client 35.245.239.138:57541] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jP8J0fwhpxOKR8YgZIwAAAHs"]
[Mon Jul 20 07:31:43.494984 2026] [security2:error] [pid 156215:tid 156363] [client 35.245.239.138:55282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jP8J0fwhpxOKR8YgZLQAAABI"]
[Mon Jul 20 07:31:43.726170 2026] [security2:error] [pid 156215:tid 156375] [client 35.245.239.138:61557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jP8J0fwhpxOKR8YgZQgAAAB4"]
[Mon Jul 20 07:31:43.851078 2026] [security2:error] [pid 156215:tid 156470] [client 153.67.105.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4jP8J0fwhpxOKR8YgZPgAAAH0"]
[Mon Jul 20 07:31:43.896431 2026] [security2:error] [pid 156215:tid 156436] [client 35.245.239.138:61853] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jP8J0fwhpxOKR8YgZVAAAAFs"]
[Mon Jul 20 07:31:44.040086 2026] [security2:error] [pid 156215:tid 156355] [client 144.16.21.149:24919] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZXAAAAAo"]
[Mon Jul 20 07:31:44.040580 2026] [security2:error] [pid 156215:tid 156355] [client 144.16.21.149:24919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZXAAAAAo"]
[Mon Jul 20 07:31:44.097102 2026] [security2:error] [pid 156215:tid 156471] [client 35.245.239.138:57337] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "website-cb9cb972.vpp.qfv.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jQMJ0fwhpxOKR8YgZZAAAAH4"]
[Mon Jul 20 07:31:44.405779 2026] [security2:error] [pid 156215:tid 156384] [client 103.139.191.61:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZgQAAACc"]
[Mon Jul 20 07:31:44.405906 2026] [security2:error] [pid 156215:tid 156384] [client 103.139.191.61:58833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZgQAAACc"]
[Mon Jul 20 07:31:44.503787 2026] [security2:error] [pid 156215:tid 156375] [client 35.245.239.138:65047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-ce0e88e9.rrf.lcd.mybluehost.me"] [uri "/index.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZeAAAAB4"]
[Mon Jul 20 07:31:44.604041 2026] [security2:error] [pid 156215:tid 156410] [client 35.245.239.138:65047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-ce0e88e9.rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZkQAAAEE"]
[Mon Jul 20 07:31:44.604152 2026] [security2:error] [pid 156215:tid 156410] [client 35.245.239.138:65047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-ce0e88e9.rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZkQAAAEE"]
[Mon Jul 20 07:31:44.841703 2026] [security2:error] [pid 156215:tid 156401] [client 57.141.18.6:39856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jP8J0fwhpxOKR8YgZBQAAOG0"]
[Mon Jul 20 07:31:44.875449 2026] [security2:error] [pid 156215:tid 156253] [remote 100.42.189.89:32930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZnwAAFCU"]
[Mon Jul 20 07:31:44.875568 2026] [security2:error] [pid 156215:tid 156365] [client 100.42.189.89:32930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZnwAAFCU"]
[Mon Jul 20 07:31:44.950910 2026] [security2:error] [pid 156215:tid 156390] [client 149.0.16.108:50788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZpgAAAC0"]
[Mon Jul 20 07:31:44.951536 2026] [security2:error] [pid 156215:tid 156390] [client 149.0.16.108:50788] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZpgAAAC0"]
[Mon Jul 20 07:31:45.352250 2026] [security2:error] [pid 156215:tid 156403] [client 57.141.18.119:50912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jP8J0fwhpxOKR8YgZQwAAOns"]
[Mon Jul 20 07:31:45.469469 2026] [security2:error] [pid 156215:tid 156267] [remote 72.167.132.114:37620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jQcJ0fwhpxOKR8YgZxwAAGTM"]
[Mon Jul 20 07:31:45.731794 2026] [security2:error] [pid 156215:tid 156290] [remote 72.167.132.114:37620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jQcJ0fwhpxOKR8YgZ4gAAYUo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:31:45.939602 2026] [security2:error] [pid 156215:tid 156389] [client 3.78.190.80:64218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jQcJ0fwhpxOKR8YgZtQAAACw"]
[Mon Jul 20 07:31:46.044377 2026] [security2:error] [pid 156215:tid 156359] [client 136.158.60.21:15065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaCwAAAA4"]
[Mon Jul 20 07:31:46.044488 2026] [security2:error] [pid 156215:tid 156359] [client 136.158.60.21:15065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaCwAAAA4"]
[Mon Jul 20 07:31:46.060361 2026] [security2:error] [pid 156215:tid 156378] [client 57.141.18.38:55378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZdwAAIQ4"]
[Mon Jul 20 07:31:46.124635 2026] [security2:error] [pid 156215:tid 156444] [client 188.166.241.141:45310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "155"] [id "900406"] [msg "wp-login POST logging"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-login.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaCAAAY2A"], referer: https://blaizeaccountingservices.com/wp-login.php
[Mon Jul 20 07:31:46.508027 2026] [security2:error] [pid 156215:tid 156367] [client 14.225.17.146:49849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaLQAAABY"]
[Mon Jul 20 07:31:46.626513 2026] [security2:error] [pid 156215:tid 156465] [client 173.246.18.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaJQAAeGY"], referer: https://packerjanitorial.com
[Mon Jul 20 07:31:46.626763 2026] [security2:error] [pid 156215:tid 156428] [client 57.141.18.114:22700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jQMJ0fwhpxOKR8YgZpQAAUwk"]
[Mon Jul 20 07:31:46.917151 2026] [security2:error] [pid 156215:tid 156411] [client 157.20.138.62:58836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jQsJ0fwhpxOKR8YgafQAAAEI"]
[Mon Jul 20 07:31:46.917260 2026] [security2:error] [pid 156215:tid 156411] [client 157.20.138.62:58836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jQsJ0fwhpxOKR8YgafQAAAEI"]
[Mon Jul 20 07:31:47.068773 2026] [security2:error] [pid 156215:tid 156360] [client 69.171.148.76:44692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jQsJ0fwhpxOKR8YgahAAADyY"]
[Mon Jul 20 07:31:47.068815 2026] [security2:error] [pid 156215:tid 156360] [client 69.171.148.76:44692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jQsJ0fwhpxOKR8YgahAAADyY"]
[Mon Jul 20 07:31:47.081791 2026] [security2:error] [pid 156215:tid 156387] [client 95.217.114.159:49692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jQ8J0fwhpxOKR8YgaigAAACo"]
[Mon Jul 20 07:31:47.247793 2026] [security2:error] [pid 156215:tid 156395] [client 14.225.17.146:51872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4jQ8J0fwhpxOKR8YgakQAAADI"], referer: http://bbwipartnerconference.com/TEST
[Mon Jul 20 07:31:47.405485 2026] [security2:error] [pid 156215:tid 156350] [client 49.37.242.14:49848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8YgavgAAAAU"]
[Mon Jul 20 07:31:47.405586 2026] [security2:error] [pid 156215:tid 156350] [client 49.37.242.14:49848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8YgavgAAAAU"]
[Mon Jul 20 07:31:47.524051 2026] [security2:error] [pid 156215:tid 156371] [client 191.202.66.27:55221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8YgaywAAABo"]
[Mon Jul 20 07:31:47.524138 2026] [security2:error] [pid 156215:tid 156371] [client 191.202.66.27:55221] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8YgaywAAABo"]
[Mon Jul 20 07:31:47.559701 2026] [security2:error] [pid 156215:tid 156297] [remote 152.228.213.32:57656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jQ8J0fwhpxOKR8YgazgAAa1E"]
[Mon Jul 20 07:31:47.757071 2026] [security2:error] [pid 156215:tid 156222] [remote 152.228.213.32:57656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jQ8J0fwhpxOKR8Yga7AAANgY"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:31:47.818947 2026] [security2:error] [pid 156215:tid 156397] [client 202.141.11.99:36940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8Yga8AAAADQ"]
[Mon Jul 20 07:31:47.819093 2026] [security2:error] [pid 156215:tid 156397] [client 202.141.11.99:36940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8Yga8AAAADQ"]
[Mon Jul 20 07:31:47.849958 2026] [security2:error] [pid 156215:tid 156356] [client 179.127.84.238:57283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8Yga9wAAAAs"]
[Mon Jul 20 07:31:47.850154 2026] [security2:error] [pid 156215:tid 156356] [client 179.127.84.238:57283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jQ8J0fwhpxOKR8Yga9wAAAAs"]
[Mon Jul 20 07:31:47.910744 2026] [security2:error] [pid 156215:tid 156368] [client 57.141.18.117:28262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaIQAAF3E"]
[Mon Jul 20 07:31:48.042266 2026] [security2:error] [pid 156215:tid 156439] [client 158.173.166.181:46973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbAwAAAF4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:31:48.049496 2026] [security2:error] [pid 156215:tid 156323] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbBQAAdGs"]
[Mon Jul 20 07:31:48.049636 2026] [security2:error] [pid 156215:tid 156461] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbBQAAdGs"]
[Mon Jul 20 07:31:48.072404 2026] [security2:error] [pid 156215:tid 156451] [client 88.241.67.160:56162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbBwAAAGo"]
[Mon Jul 20 07:31:48.072774 2026] [security2:error] [pid 156215:tid 156451] [client 88.241.67.160:56162] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbBwAAAGo"]
[Mon Jul 20 07:31:48.153481 2026] [security2:error] [pid 156215:tid 156434] [client 49.47.218.174:57347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbDQAAAFk"]
[Mon Jul 20 07:31:48.153585 2026] [security2:error] [pid 156215:tid 156434] [client 49.47.218.174:57347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbDQAAAFk"]
[Mon Jul 20 07:31:48.236219 2026] [security2:error] [pid 156215:tid 156381] [client 57.141.18.79:61144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaTQAAJBM"]
[Mon Jul 20 07:31:48.290356 2026] [security2:error] [pid 156215:tid 156403] [client 14.225.17.146:60039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbDgAAADo"], referer: http://hammadownenterprises.com/TEST
[Mon Jul 20 07:31:48.382815 2026] [security2:error] [pid 156215:tid 156458] [client 57.141.18.54:35130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jQsJ0fwhpxOKR8YgaXgAAcRo"]
[Mon Jul 20 07:31:48.555298 2026] [security2:error] [pid 156215:tid 156373] [client 216.173.120.132:41521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbKwAAABw"]
[Mon Jul 20 07:31:48.625552 2026] [security2:error] [pid 156215:tid 156378] [client 14.225.17.146:60506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbHgAAACE"], referer: http://latiendadejorge.com.gt/TEST
[Mon Jul 20 07:31:48.695959 2026] [security2:error] [pid 156215:tid 156374] [client 46.110.96.34:44617] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4jRMJ0fwhpxOKR8YgbQQAAAB0"]
[Mon Jul 20 07:31:48.908380 2026] [security2:error] [pid 156215:tid 156407] [client 14.225.17.146:65154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbRQAAAD4"], referer: http://expertcultures.com/TEST
[Mon Jul 20 07:31:48.923576 2026] [security2:error] [pid 156215:tid 156376] [client 65.111.26.81:53605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbUwAAAB8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:31:49.011045 2026] [security2:error] [pid 156215:tid 156433] [client 154.192.123.127:17108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbVgAAAFg"]
[Mon Jul 20 07:31:49.011301 2026] [security2:error] [pid 156215:tid 156433] [client 154.192.123.127:17108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbVgAAAFg"]
[Mon Jul 20 07:31:49.253631 2026] [security2:error] [pid 156215:tid 156395] [client 14.225.17.146:65406] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbagAAADI"], referer: http://ancestralidadytrance.space/TEST
[Mon Jul 20 07:31:49.418678 2026] [security2:error] [pid 156215:tid 156404] [client 36.93.152.155:52603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbewAAADs"]
[Mon Jul 20 07:31:49.418771 2026] [security2:error] [pid 156215:tid 156404] [client 36.93.152.155:52603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbewAAADs"]
[Mon Jul 20 07:31:49.548933 2026] [security2:error] [pid 156215:tid 156352] [client 44.245.170.32:28560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.170.245.44.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbggAAAAc"]
[Mon Jul 20 07:31:49.588539 2026] [security2:error] [pid 156215:tid 156229] [remote 57.141.18.6:24452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4jRcJ0fwhpxOKR8YgbiwAATg0"]
[Mon Jul 20 07:31:49.661836 2026] [security2:error] [pid 156215:tid 156472] [client 14.225.17.146:60502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbHwAAAH8"], referer: http://windowtx.com/TEST
[Mon Jul 20 07:31:49.674350 2026] [proxy:error] [pid 156215:tid 156314] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:31:49.674388 2026] [proxy_http:error] [pid 156215:tid 156314] [remote 104.222.38.4:52822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:31:49.675002 2026] [proxy:error] [pid 156215:tid 156314] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:31:49.675028 2026] [proxy_http:error] [pid 156215:tid 156314] [remote 104.222.38.4:52822] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:31:49.762810 2026] [security2:error] [pid 156215:tid 156420] [client 113.165.147.6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbjAAAAEs"]
[Mon Jul 20 07:31:49.831077 2026] [security2:error] [pid 156215:tid 156396] [client 143.44.185.218:25947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbqwAAADM"]
[Mon Jul 20 07:31:49.831200 2026] [security2:error] [pid 156215:tid 156396] [client 143.44.185.218:25947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbqwAAADM"]
[Mon Jul 20 07:31:49.881128 2026] [security2:error] [pid 156215:tid 156453] [client 57.141.18.6:39872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jQ8J0fwhpxOKR8Yga6QAAbFU"]
[Mon Jul 20 07:31:50.073534 2026] [security2:error] [pid 156215:tid 156233] [remote 57.141.18.97:63016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3818564"] [unique_id "al4jRsJ0fwhpxOKR8YgbtQAAeBE"]
[Mon Jul 20 07:31:50.530326 2026] [security2:error] [pid 156215:tid 156363] [client 57.141.18.33:26766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jRMJ0fwhpxOKR8YgbFgAAElg"]
[Mon Jul 20 07:31:50.862599 2026] [security2:error] [pid 156215:tid 156369] [client 103.106.165.44:58616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jRsJ0fwhpxOKR8Ygb9gAAABg"]
[Mon Jul 20 07:31:50.862735 2026] [security2:error] [pid 156215:tid 156369] [client 103.106.165.44:58616] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jRsJ0fwhpxOKR8Ygb9gAAABg"]
[Mon Jul 20 07:31:50.939781 2026] [security2:error] [pid 156215:tid 156286] [remote 173.212.252.15:37808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jRsJ0fwhpxOKR8Ygb-QAAE0Y"]
[Mon Jul 20 07:31:50.963953 2026] [security2:error] [pid 156215:tid 156433] [client 95.217.114.159:57898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jRsJ0fwhpxOKR8Ygb-AAAAFg"]
[Mon Jul 20 07:31:51.116668 2026] [security2:error] [pid 156215:tid 156379] [client 14.225.17.146:50848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbnAAAACI"], referer: http://slutilities.com/TEST
[Mon Jul 20 07:31:51.172988 2026] [security2:error] [pid 156215:tid 156292] [remote 173.212.252.15:37808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jR8J0fwhpxOKR8YgcEgAANUw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:31:51.370575 2026] [security2:error] [pid 156215:tid 156437] [client 223.237.128.244:51270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4jR8J0fwhpxOKR8YgcEwAAAFw"]
[Mon Jul 20 07:31:51.393407 2026] [security2:error] [pid 156215:tid 156409] [client 103.176.215.66:62349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jR8J0fwhpxOKR8YgcKAAAAEA"]
[Mon Jul 20 07:31:51.393736 2026] [security2:error] [pid 156215:tid 156409] [client 103.176.215.66:62349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jR8J0fwhpxOKR8YgcKAAAAEA"]
[Mon Jul 20 07:31:51.550732 2026] [security2:error] [pid 156215:tid 156436] [client 14.225.17.146:64949] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4jR8J0fwhpxOKR8YgcGQAAAFs"], referer: http://mcg.homes/TEST
[Mon Jul 20 07:31:51.649419 2026] [security2:error] [pid 156215:tid 156348] [client 14.224.227.113:58679] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4jR8J0fwhpxOKR8YgcNQAAAAM"]
[Mon Jul 20 07:31:51.650908 2026] [security2:error] [pid 156215:tid 156425] [client 57.141.18.2:34710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jRcJ0fwhpxOKR8YgbdQAAUAM"]
[Mon Jul 20 07:31:51.994811 2026] [security2:error] [pid 156215:tid 156389] [client 104.234.53.73:57799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jR8J0fwhpxOKR8YgcTgAAACw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:31:52.387413 2026] [security2:error] [pid 156215:tid 156408] [client 14.225.17.146:65414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4jR8J0fwhpxOKR8YgcSQAAAD8"], referer: http://drewsasburyparkbeachhouse.com/TEST
[Mon Jul 20 07:31:52.397203 2026] [security2:error] [pid 156215:tid 156437] [client 14.225.17.146:53041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4jSMJ0fwhpxOKR8YgcbAAAAFw"], referer: http://ravmike.com/TEST
[Mon Jul 20 07:31:52.536455 2026] [security2:error] [pid 156215:tid 156412] [client 14.225.17.146:50848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4jSMJ0fwhpxOKR8YgcZAAAAEM"], referer: http://adastra.love/TEST
[Mon Jul 20 07:31:52.541918 2026] [security2:error] [pid 156215:tid 156378] [client 57.141.18.92:58784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jRsJ0fwhpxOKR8YgbxgAAIQU"]
[Mon Jul 20 07:31:52.630203 2026] [security2:error] [pid 156215:tid 156452] [client 190.230.12.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4jSMJ0fwhpxOKR8YgcXgAAazE"], referer: https://packerjanitorial.com
[Mon Jul 20 07:31:52.826276 2026] [security2:error] [pid 156215:tid 156291] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jSMJ0fwhpxOKR8YgckgAAG0s"]
[Mon Jul 20 07:31:52.826436 2026] [security2:error] [pid 156215:tid 156372] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jSMJ0fwhpxOKR8YgckgAAG0s"]
[Mon Jul 20 07:31:53.027602 2026] [security2:error] [pid 156215:tid 156337] [remote 173.212.252.15:37822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4jScJ0fwhpxOKR8YgcoQAAKXk"]
[Mon Jul 20 07:31:53.027770 2026] [security2:error] [pid 156215:tid 156386] [client 173.212.252.15:37822] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "solkeetw.com"] [uri "/xmlrpc.php"] [unique_id "al4jScJ0fwhpxOKR8YgcoQAAKXk"]
[Mon Jul 20 07:31:53.125986 2026] [security2:error] [pid 156215:tid 156363] [client 50.116.65.227:22866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jScJ0fwhpxOKR8YgcpwAAABI"]
[Mon Jul 20 07:31:53.135892 2026] [security2:error] [pid 156215:tid 156450] [client 50.116.65.227:22878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jScJ0fwhpxOKR8YgcqQAAAGk"]
[Mon Jul 20 07:31:53.283628 2026] [security2:error] [pid 156215:tid 156367] [client 14.225.17.146:60584] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4jScJ0fwhpxOKR8YgcsAAAABY"], referer: https://ravmike.com/TEST
[Mon Jul 20 07:31:53.334306 2026] [security2:error] [pid 156215:tid 156467] [client 95.217.114.159:49054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jScJ0fwhpxOKR8YgcvgAAAHo"]
[Mon Jul 20 07:31:53.541289 2026] [security2:error] [pid 156215:tid 156399] [client 57.141.18.8:26848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jR8J0fwhpxOKR8YgcJwAANlI"]
[Mon Jul 20 07:31:53.559136 2026] [security2:error] [pid 156215:tid 156308] [remote 130.185.118.215:48380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jScJ0fwhpxOKR8YgczgAAJFw"]
[Mon Jul 20 07:31:53.740325 2026] [security2:error] [pid 156215:tid 156249] [remote 130.185.118.215:48380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jScJ0fwhpxOKR8Ygc2gAAciE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:31:53.784482 2026] [security2:error] [pid 156215:tid 156318] [remote 173.212.252.15:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4jScJ0fwhpxOKR8Ygc3gAAQGY"]
[Mon Jul 20 07:31:54.017209 2026] [security2:error] [pid 156215:tid 156393] [client 57.141.18.82:34942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jR8J0fwhpxOKR8YgcPAAAMDc"]
[Mon Jul 20 07:31:54.025888 2026] [security2:error] [pid 156215:tid 156248] [remote 173.212.252.15:37826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4jSsJ0fwhpxOKR8Ygc9wAAcCA"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 07:31:54.750323 2026] [security2:error] [pid 156215:tid 156217] [remote 152.228.213.32:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jSsJ0fwhpxOKR8YgdLAAATQE"]
[Mon Jul 20 07:31:55.066158 2026] [security2:error] [pid 156215:tid 156224] [remote 152.228.213.32:46938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jS8J0fwhpxOKR8YgdSQAAZwg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:31:55.100349 2026] [security2:error] [pid 156215:tid 156427] [client 14.225.17.146:53901] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4jSsJ0fwhpxOKR8YgdLQAAAFI"], referer: http://healthylifegourmet.org/TEST
[Mon Jul 20 07:31:55.138233 2026] [security2:error] [pid 156215:tid 156371] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4jScJ0fwhpxOKR8YgcxwAAGl0"], referer: http://aleishapenny.ca/TEST
[Mon Jul 20 07:31:55.183664 2026] [security2:error] [pid 156215:tid 156441] [client 14.225.17.146:51646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4jS8J0fwhpxOKR8YgdSgAAAGA"], referer: http://39ishlife.com/TEST
[Mon Jul 20 07:31:55.235642 2026] [security2:error] [pid 156215:tid 156364] [client 57.141.18.105:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jS8J0fwhpxOKR8YgdSwAAABM"]
[Mon Jul 20 07:31:55.309575 2026] [security2:error] [pid 156215:tid 156451] [client 103.139.191.61:59505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdXQAAAGo"]
[Mon Jul 20 07:31:55.309730 2026] [security2:error] [pid 156215:tid 156451] [client 103.139.191.61:59505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdXQAAAGo"]
[Mon Jul 20 07:31:55.575769 2026] [security2:error] [pid 156215:tid 156396] [client 149.0.16.108:51282] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdfwAAADM"]
[Mon Jul 20 07:31:55.576535 2026] [security2:error] [pid 156215:tid 156396] [client 149.0.16.108:51282] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdfwAAADM"]
[Mon Jul 20 07:31:55.732651 2026] [security2:error] [pid 156215:tid 156387] [client 63.179.149.246:42352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdiQAAACo"]
[Mon Jul 20 07:31:55.732785 2026] [security2:error] [pid 156215:tid 156387] [client 63.179.149.246:42352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdiQAAACo"]
[Mon Jul 20 07:31:55.769092 2026] [security2:error] [pid 156215:tid 156405] [client 144.16.21.149:28355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdhwAAADw"]
[Mon Jul 20 07:31:55.769249 2026] [security2:error] [pid 156215:tid 156405] [client 144.16.21.149:28355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jS8J0fwhpxOKR8YgdhwAAADw"]
[Mon Jul 20 07:31:55.911203 2026] [security2:error] [pid 156215:tid 156423] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4jS8J0fwhpxOKR8YgdlAAATms"], referer: https://aleishapenny.ca/TEST
[Mon Jul 20 07:31:55.941386 2026] [security2:error] [pid 156215:tid 156402] [client 14.225.17.146:51920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4jS8J0fwhpxOKR8YgdkQAAADk"], referer: http://dadanetnet.net/TEST
[Mon Jul 20 07:31:56.097428 2026] [security2:error] [pid 156215:tid 156384] [client 104.234.53.80:58825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jTMJ0fwhpxOKR8YgdpAAAACc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:31:56.156349 2026] [security2:error] [pid 156215:tid 156416] [client 14.225.17.146:53922] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4jTMJ0fwhpxOKR8YgdpQAAAEc"], referer: https://39ishlife.com/TEST
[Mon Jul 20 07:31:56.191179 2026] [security2:error] [pid 156215:tid 156362] [client 14.225.17.146:52376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4jS8J0fwhpxOKR8YgdhgAAABE"], referer: http://idigress.group/TEST
[Mon Jul 20 07:31:56.395252 2026] [security2:error] [pid 156215:tid 156471] [client 14.225.17.146:53813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4jTMJ0fwhpxOKR8YgdrQAAAH4"], referer: http://fluidtemple.org/TEST
[Mon Jul 20 07:31:56.420820 2026] [security2:error] [pid 156215:tid 156464] [client 57.141.18.71:44598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jSsJ0fwhpxOKR8YgdAAAAd18"]
[Mon Jul 20 07:31:56.469334 2026] [security2:error] [pid 156215:tid 156449] [client 155.2.215.80:29469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jTMJ0fwhpxOKR8YgdsAAAAGg"]
[Mon Jul 20 07:31:56.725239 2026] [security2:error] [pid 156215:tid 156452] [client 136.158.60.21:16540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jTMJ0fwhpxOKR8Ygd2wAAAGs"]
[Mon Jul 20 07:31:56.725353 2026] [security2:error] [pid 156215:tid 156452] [client 136.158.60.21:16540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jTMJ0fwhpxOKR8Ygd2wAAAGs"]
[Mon Jul 20 07:31:56.757008 2026] [security2:error] [pid 156215:tid 156436] [client 14.225.17.146:53868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4jTMJ0fwhpxOKR8Ygd1wAAAFs"], referer: http://sarahholyfield.com/TEST
[Mon Jul 20 07:31:56.836110 2026] [security2:error] [pid 156215:tid 156360] [client 212.169.177.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "packerjanitorial.com"] [uri "/index.php"] [unique_id "al4jTMJ0fwhpxOKR8YgduAAADwo"], referer: https://packerjanitorial.com
[Mon Jul 20 07:31:56.938764 2026] [security2:error] [pid 156215:tid 156413] [client 104.234.53.67:21685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jTMJ0fwhpxOKR8Ygd8AAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:31:57.174087 2026] [security2:error] [pid 156215:tid 156349] [client 57.141.18.88:30188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jSsJ0fwhpxOKR8YgdRQAABCg"]
[Mon Jul 20 07:31:57.220463 2026] [security2:error] [pid 156215:tid 156243] [remote 8.217.108.67:42774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4jTcJ0fwhpxOKR8YgeDAAAMRs"]
[Mon Jul 20 07:31:57.469551 2026] [security2:error] [pid 156215:tid 156470] [client 157.20.138.62:59401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jTcJ0fwhpxOKR8YgeIgAAAH0"]
[Mon Jul 20 07:31:57.469644 2026] [security2:error] [pid 156215:tid 156470] [client 157.20.138.62:59401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jTcJ0fwhpxOKR8YgeIgAAAH0"]
[Mon Jul 20 07:31:57.528967 2026] [security2:error] [pid 156215:tid 156245] [remote 173.212.252.15:34492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4jTcJ0fwhpxOKR8YgeKQAAUh0"]
[Mon Jul 20 07:31:57.740651 2026] [security2:error] [pid 156215:tid 156330] [remote 173.212.252.15:34492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4jTcJ0fwhpxOKR8YgeNwAAB3I"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:31:58.234408 2026] [security2:error] [pid 156215:tid 156387] [client 191.202.66.27:55715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeZQAAACo"]
[Mon Jul 20 07:31:58.234506 2026] [security2:error] [pid 156215:tid 156387] [client 191.202.66.27:55715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeZQAAACo"]
[Mon Jul 20 07:31:58.254285 2026] [security2:error] [pid 156215:tid 156460] [client 49.47.218.174:57893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeZgAAAHM"]
[Mon Jul 20 07:31:58.254385 2026] [security2:error] [pid 156215:tid 156460] [client 49.47.218.174:57893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeZgAAAHM"]
[Mon Jul 20 07:31:58.378919 2026] [security2:error] [pid 156215:tid 156463] [client 95.217.114.159:63498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeaAAAAHY"]
[Mon Jul 20 07:31:58.485300 2026] [security2:error] [pid 156215:tid 156374] [client 57.141.18.123:34804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jTMJ0fwhpxOKR8YgdsgAAHRo"]
[Mon Jul 20 07:31:58.613779 2026] [security2:error] [pid 156215:tid 156375] [client 88.241.67.160:53782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeiQAAAB4"]
[Mon Jul 20 07:31:58.614163 2026] [security2:error] [pid 156215:tid 156375] [client 88.241.67.160:53782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeiQAAAB4"]
[Mon Jul 20 07:31:58.618634 2026] [security2:error] [pid 156215:tid 156217] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeigAAXwE"]
[Mon Jul 20 07:31:58.618869 2026] [security2:error] [pid 156215:tid 156440] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeigAAXwE"]
[Mon Jul 20 07:31:58.631495 2026] [security2:error] [pid 156215:tid 156433] [client 14.225.17.146:62991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeewAAAFg"], referer: http://taskidsvirginia.com/TEST
[Mon Jul 20 07:31:58.638656 2026] [security2:error] [pid 156215:tid 156426] [client 179.127.84.238:57831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeiwAAAFE"]
[Mon Jul 20 07:31:58.638788 2026] [security2:error] [pid 156215:tid 156426] [client 179.127.84.238:57831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jTsJ0fwhpxOKR8YgeiwAAAFE"]
[Mon Jul 20 07:31:58.987481 2026] [security2:error] [pid 156215:tid 156429] [client 14.225.17.146:51545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4jTsJ0fwhpxOKR8YgekQAAAFQ"], referer: http://floorsourcestock.com/TEST
[Mon Jul 20 07:31:58.993080 2026] [security2:error] [pid 156215:tid 156384] [client 14.225.17.146:51469] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4jTsJ0fwhpxOKR8YgemAAAACc"], referer: http://mazzucelli.com/TEST
[Mon Jul 20 07:31:59.103510 2026] [security2:error] [pid 156215:tid 156297] [remote 20.153.140.50:41842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4jT8J0fwhpxOKR8YgeswAAFVE"]
[Mon Jul 20 07:31:59.160108 2026] [security2:error] [pid 156215:tid 156309] [remote 20.173.88.122:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4jT8J0fwhpxOKR8YgeugAAJl0"]
[Mon Jul 20 07:31:59.300863 2026] [security2:error] [pid 156215:tid 156223] [remote 8.217.108.67:42774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4jT8J0fwhpxOKR8YgewQAAIQc"], referer: https://thesoloceos.com/wp-login.php
[Mon Jul 20 07:31:59.381648 2026] [security2:error] [pid 156215:tid 156359] [client 57.141.18.79:32910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jTcJ0fwhpxOKR8YgeEAAADlI"]
[Mon Jul 20 07:31:59.461448 2026] [security2:error] [pid 156215:tid 156299] [remote 182.77.62.24:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jT8J0fwhpxOKR8Yge0QAAO1M"]
[Mon Jul 20 07:31:59.484632 2026] [security2:error] [pid 156215:tid 156219] [remote 20.173.88.122:46974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mazzucelli.com"] [uri "/wp-login.php"] [unique_id "al4jT8J0fwhpxOKR8Yge1QAAIAM"], referer: https://mazzucelli.com/wp-login.php
[Mon Jul 20 07:31:59.492199 2026] [security2:error] [pid 156215:tid 156362] [client 154.192.123.127:17493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jT8J0fwhpxOKR8Yge1wAAABE"]
[Mon Jul 20 07:31:59.492297 2026] [security2:error] [pid 156215:tid 156362] [client 154.192.123.127:17493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jT8J0fwhpxOKR8Yge1wAAABE"]
[Mon Jul 20 07:31:59.576698 2026] [security2:error] [pid 156215:tid 156395] [client 14.225.17.146:52924] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4jTsJ0fwhpxOKR8YgefgAAADI"], referer: http://grndl.com/TEST
[Mon Jul 20 07:31:59.596258 2026] [security2:error] [pid 156215:tid 156385] [client 95.217.114.159:63510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jT8J0fwhpxOKR8Yge2QAAACg"]
[Mon Jul 20 07:31:59.687393 2026] [security2:error] [pid 156215:tid 156307] [remote 20.153.140.50:41842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4jT8J0fwhpxOKR8Yge6gAAaFs"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:31:59.901202 2026] [security2:error] [pid 156215:tid 156398] [client 43.205.139.3:29214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jT8J0fwhpxOKR8Yge9wAAADU"]
[Mon Jul 20 07:31:59.901315 2026] [security2:error] [pid 156215:tid 156398] [client 43.205.139.3:29214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jT8J0fwhpxOKR8Yge9wAAADU"]
[Mon Jul 20 07:31:59.952234 2026] [security2:error] [pid 156215:tid 156426] [client 36.93.152.155:53148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jT8J0fwhpxOKR8Yge_AAAAFE"]
[Mon Jul 20 07:31:59.952321 2026] [security2:error] [pid 156215:tid 156426] [client 36.93.152.155:53148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jT8J0fwhpxOKR8Yge_AAAAFE"]
[Mon Jul 20 07:32:00.015684 2026] [core:error] [pid 156215:tid 156414] [client 14.225.17.146:53239] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/TEST
[Mon Jul 20 07:32:00.015711 2026] [core:error] [pid 156215:tid 156414] [client 14.225.17.146:53239] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/TEST
[Mon Jul 20 07:32:00.152587 2026] [security2:error] [pid 156215:tid 156457] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4jT8J0fwhpxOKR8Yge-AAAcBM"], referer: http://ali-alghanim.net/TEST
[Mon Jul 20 07:32:00.208687 2026] [security2:error] [pid 156215:tid 156444] [client 43.153.74.75:54138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4jT8J0fwhpxOKR8YgevAAAAGM"], referer: https://techtradeinc.com/
[Mon Jul 20 07:32:00.401816 2026] [security2:error] [pid 156215:tid 156331] [remote 182.77.62.24:37958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jUMJ0fwhpxOKR8YgfJQAAVXM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:32:00.421074 2026] [security2:error] [pid 156215:tid 156373] [client 14.225.17.146:58376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4jUMJ0fwhpxOKR8YgfFQAAABw"], referer: http://bigwormfishing.com/TEST
[Mon Jul 20 07:32:00.504201 2026] [security2:error] [pid 156215:tid 156414] [client 5.188.87.40:40890] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "fbvrealtors.com"] [uri "/"] [unique_id "al4jUMJ0fwhpxOKR8YgfMQAAAEU"]
[Mon Jul 20 07:32:00.682066 2026] [security2:error] [pid 156215:tid 156455] [client 104.234.53.68:26837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4jUMJ0fwhpxOKR8YgfPQAAAG4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:01.034624 2026] [security2:error] [pid 156215:tid 156351] [client 5.188.87.40:40904] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "fbvrealtors.com"] [uri "/"] [unique_id "al4jUcJ0fwhpxOKR8YgfWQAAAAY"]
[Mon Jul 20 07:32:01.209891 2026] [security2:error] [pid 156215:tid 156346] [client 103.106.165.44:59099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfZQAAAAE"]
[Mon Jul 20 07:32:01.210022 2026] [security2:error] [pid 156215:tid 156346] [client 103.106.165.44:59099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfZQAAAAE"]
[Mon Jul 20 07:32:01.287292 2026] [security2:error] [pid 156215:tid 156416] [client 57.141.18.122:27420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jT8J0fwhpxOKR8Yge2AAARwY"]
[Mon Jul 20 07:32:01.341642 2026] [security2:error] [pid 156215:tid 156412] [client 95.5.154.225:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfZAAAAEM"]
[Mon Jul 20 07:32:01.399473 2026] [security2:error] [pid 156215:tid 156365] [client 49.37.242.14:50389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfeAAAABQ"]
[Mon Jul 20 07:32:01.399689 2026] [security2:error] [pid 156215:tid 156365] [client 49.37.242.14:50389] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfeAAAABQ"]
[Mon Jul 20 07:32:01.417154 2026] [security2:error] [pid 156215:tid 156241] [remote 209.42.18.223:51618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfegAADBk"]
[Mon Jul 20 07:32:01.496737 2026] [security2:error] [pid 156215:tid 156399] [client 14.225.17.146:54627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfdgAAADY"], referer: https://bigwormfishing.com/TEST
[Mon Jul 20 07:32:01.600043 2026] [security2:error] [pid 156215:tid 156252] [remote 209.42.18.223:51618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfkAAANCQ"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:32:01.631142 2026] [security2:error] [pid 156215:tid 156383] [client 117.211.236.168:54266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgflAAAACY"]
[Mon Jul 20 07:32:01.631243 2026] [security2:error] [pid 156215:tid 156383] [client 117.211.236.168:54266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgflAAAACY"]
[Mon Jul 20 07:32:01.687019 2026] [security2:error] [pid 156215:tid 156449] [client 143.44.185.218:27319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfmwAAAGg"]
[Mon Jul 20 07:32:01.687117 2026] [security2:error] [pid 156215:tid 156449] [client 143.44.185.218:27319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfmwAAAGg"]
[Mon Jul 20 07:32:01.935482 2026] [security2:error] [pid 156215:tid 156469] [client 103.176.215.66:62890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfsAAAAHw"]
[Mon Jul 20 07:32:01.935895 2026] [security2:error] [pid 156215:tid 156469] [client 103.176.215.66:62890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfsAAAAHw"]
[Mon Jul 20 07:32:01.955632 2026] [security2:error] [pid 156215:tid 156386] [client 84.17.60.251:48124] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4jUcJ0fwhpxOKR8YgftAAAACk"]
[Mon Jul 20 07:32:02.186572 2026] [security2:error] [pid 156215:tid 156446] [client 216.173.120.133:56625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jUsJ0fwhpxOKR8YgfuwAAAGU"]
[Mon Jul 20 07:32:02.196200 2026] [security2:error] [pid 156215:tid 156451] [client 66.249.70.7:39966] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "hardman.international"] [uri "/robots.txt"] [unique_id "al4jUsJ0fwhpxOKR8YgfvAAAAGo"]
[Mon Jul 20 07:32:02.306986 2026] [security2:error] [pid 156215:tid 156406] [client 84.17.60.251:48128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.60.17.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/xmlrpc.php"] [unique_id "al4jUsJ0fwhpxOKR8YgfxgAAAD0"]
[Mon Jul 20 07:32:02.333392 2026] [security2:error] [pid 156215:tid 156471] [client 216.73.216.40:4658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.lmgorman.com"] [uri "/index.php"] [unique_id "al4jUsJ0fwhpxOKR8YgfvwAAflg"]
[Mon Jul 20 07:32:02.344384 2026] [security2:error] [pid 156215:tid 156268] [remote 20.153.140.50:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jUsJ0fwhpxOKR8Ygf0QAAMTQ"]
[Mon Jul 20 07:32:02.385450 2026] [security2:error] [pid 156215:tid 156390] [client 57.141.18.33:63978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jUMJ0fwhpxOKR8YgfNwAALXg"]
[Mon Jul 20 07:32:02.619125 2026] [security2:error] [pid 156215:tid 156363] [client 84.17.60.251:48142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jUsJ0fwhpxOKR8Ygf5AAAABI"]
[Mon Jul 20 07:32:02.769094 2026] [security2:error] [pid 156215:tid 156319] [remote 20.153.140.50:38710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jUsJ0fwhpxOKR8Ygf6AAABWc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:32:02.841815 2026] [security2:error] [pid 156215:tid 156429] [client 14.225.17.146:60567] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4jUsJ0fwhpxOKR8Ygf3QAAAFQ"], referer: http://uritems.net/TEST
[Mon Jul 20 07:32:02.856833 2026] [security2:error] [pid 156215:tid 156366] [client 92.59.231.52:46116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jUsJ0fwhpxOKR8Ygf5wAAFS8"]
[Mon Jul 20 07:32:02.856867 2026] [security2:error] [pid 156215:tid 156366] [client 92.59.231.52:46116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jUsJ0fwhpxOKR8Ygf5wAAFS8"]
[Mon Jul 20 07:32:02.932197 2026] [security2:error] [pid 156215:tid 156397] [client 84.17.60.251:48150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jUsJ0fwhpxOKR8Ygf_gAAADQ"]
[Mon Jul 20 07:32:03.079276 2026] [security2:error] [pid 156215:tid 156223] [remote 182.77.62.24:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4jU8J0fwhpxOKR8YggBwAAcQc"]
[Mon Jul 20 07:32:03.094603 2026] [core:error] [pid 156215:tid 156422] [client 14.225.17.146:58121] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:32:03.094625 2026] [core:error] [pid 156215:tid 156422] [client 14.225.17.146:58121] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:32:03.096671 2026] [security2:error] [pid 156215:tid 156465] [client 57.141.18.29:43484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfdQAAeBI"]
[Mon Jul 20 07:32:03.262273 2026] [security2:error] [pid 156215:tid 156357] [client 84.17.60.251:48164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4jU8J0fwhpxOKR8YggIQAAAAw"]
[Mon Jul 20 07:32:03.344741 2026] [security2:error] [pid 156215:tid 156364] [client 14.225.17.146:53012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4jU8J0fwhpxOKR8YggDwAAABM"], referer: http://swafforddetailing.com/TEST
[Mon Jul 20 07:32:03.385690 2026] [security2:error] [pid 156215:tid 156339] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jU8J0fwhpxOKR8YggKgAAV3s"]
[Mon Jul 20 07:32:03.385877 2026] [security2:error] [pid 156215:tid 156432] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jU8J0fwhpxOKR8YggKgAAV3s"]
[Mon Jul 20 07:32:03.526550 2026] [security2:error] [pid 156215:tid 156381] [client 45.157.112.60:45285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jU8J0fwhpxOKR8YggPQAAACQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:32:03.592198 2026] [security2:error] [pid 156215:tid 156393] [client 84.17.60.251:48170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4jU8J0fwhpxOKR8YggRAAAADA"]
[Mon Jul 20 07:32:03.651399 2026] [security2:error] [pid 156215:tid 156329] [remote 182.77.62.24:55408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4jU8J0fwhpxOKR8YggRwAAZXE"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:32:03.771272 2026] [security2:error] [pid 156215:tid 156365] [client 57.141.18.49:45414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jUcJ0fwhpxOKR8YgfswAAFA8"]
[Mon Jul 20 07:32:03.918074 2026] [security2:error] [pid 156215:tid 156427] [client 84.17.60.251:48174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4jU8J0fwhpxOKR8YggYgAAAFI"]
[Mon Jul 20 07:32:03.944018 2026] [security2:error] [pid 156215:tid 156320] [remote 160.187.68.132:43824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jU8J0fwhpxOKR8YggZQAAbGg"]
[Mon Jul 20 07:32:03.944189 2026] [security2:error] [pid 156215:tid 156453] [client 160.187.68.132:43824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jU8J0fwhpxOKR8YggZQAAbGg"]
[Mon Jul 20 07:32:03.976957 2026] [security2:error] [pid 156215:tid 156410] [client 57.141.18.70:54532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jUsJ0fwhpxOKR8YgfvQAAQSs"]
[Mon Jul 20 07:32:04.007006 2026] [security2:error] [pid 156215:tid 156398] [client 14.225.17.146:59713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4jU8J0fwhpxOKR8YggXwAAADU"], referer: http://momheadquarters.com/TEST
[Mon Jul 20 07:32:04.173346 2026] [security2:error] [pid 156215:tid 156316] [remote 15.235.219.232:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.219.235.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jVMJ0fwhpxOKR8YggdwAAKWQ"]
[Mon Jul 20 07:32:04.244946 2026] [security2:error] [pid 156215:tid 156367] [client 84.17.60.251:48178] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4jVMJ0fwhpxOKR8YgghwAAABY"]
[Mon Jul 20 07:32:04.246331 2026] [security2:error] [pid 156215:tid 156426] [client 14.225.17.146:60368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4jVMJ0fwhpxOKR8YggcgAAAFE"], referer: http://lifeisbetterlakeside.com/TEST
[Mon Jul 20 07:32:04.471340 2026] [security2:error] [pid 156215:tid 156358] [client 14.225.17.146:58035] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4jVMJ0fwhpxOKR8YggjQAAAA0"], referer: http://scott-assist.com/TEST
[Mon Jul 20 07:32:04.562972 2026] [security2:error] [pid 156215:tid 156436] [client 84.17.60.251:48184] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jVMJ0fwhpxOKR8YggpAAAAFs"]
[Mon Jul 20 07:32:04.572582 2026] [security2:error] [pid 156215:tid 156333] [remote 15.235.219.232:41882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.219.235.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jVMJ0fwhpxOKR8YggpQAADHU"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:32:04.645920 2026] [security2:error] [pid 156215:tid 156334] [remote 152.228.213.32:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4jVMJ0fwhpxOKR8YggqwAAAXY"]
[Mon Jul 20 07:32:04.677189 2026] [security2:error] [pid 156215:tid 156402] [client 57.141.18.123:36282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jU8J0fwhpxOKR8YggCAAAOUM"]
[Mon Jul 20 07:32:04.708461 2026] [security2:error] [pid 156215:tid 156469] [client 148.113.128.216:53656] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "avatrip.co"] [uri "/robots.txt"] [unique_id "al4jVMJ0fwhpxOKR8YggtAAAAHw"]
[Mon Jul 20 07:32:04.708557 2026] [security2:error] [pid 156215:tid 156469] [client 148.113.128.216:53656] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avatrip.co"] [uri "/robots.txt"] [unique_id "al4jVMJ0fwhpxOKR8YggtAAAAHw"]
[Mon Jul 20 07:32:04.886388 2026] [security2:error] [pid 156215:tid 156448] [client 84.17.60.251:48188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jVMJ0fwhpxOKR8YggxQAAAGc"]
[Mon Jul 20 07:32:04.908312 2026] [security2:error] [pid 156215:tid 156243] [remote 152.228.213.32:59880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4jVMJ0fwhpxOKR8YggxwAAXhs"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 07:32:05.199784 2026] [security2:error] [pid 156215:tid 156348] [client 84.17.60.251:48194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jVcJ0fwhpxOKR8Ygg2AAAAAM"]
[Mon Jul 20 07:32:05.288783 2026] [security2:error] [pid 156215:tid 156378] [client 223.237.128.244:51740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4jVcJ0fwhpxOKR8Ygg0QAAACE"]
[Mon Jul 20 07:32:05.337205 2026] [security2:error] [pid 156215:tid 156461] [client 98.159.234.160:44605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jVcJ0fwhpxOKR8Ygg6QAAAHQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:32:05.355844 2026] [security2:error] [pid 156215:tid 156408] [client 144.16.21.149:36155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jVcJ0fwhpxOKR8Ygg6wAAAD8"]
[Mon Jul 20 07:32:05.356051 2026] [security2:error] [pid 156215:tid 156408] [client 144.16.21.149:36155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jVcJ0fwhpxOKR8Ygg6wAAAD8"]
[Mon Jul 20 07:32:05.517077 2026] [security2:error] [pid 156215:tid 156381] [client 84.17.60.251:48204] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jVcJ0fwhpxOKR8YghAgAAACQ"]
[Mon Jul 20 07:32:05.665101 2026] [proxy:error] [pid 156215:tid 156413] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:32:05.665192 2026] [proxy_http:error] [pid 156215:tid 156413] [client 82.102.18.182:43322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:32:05.665922 2026] [proxy:error] [pid 156215:tid 156413] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:32:05.665960 2026] [proxy_http:error] [pid 156215:tid 156413] [client 82.102.18.182:43322] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:32:05.742166 2026] [security2:error] [pid 156215:tid 156382] [client 57.141.18.19:21938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jVMJ0fwhpxOKR8YggegAAJXQ"]
[Mon Jul 20 07:32:05.799666 2026] [security2:error] [pid 156215:tid 156397] [client 57.141.18.58:20602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jVMJ0fwhpxOKR8YgggwAANEQ"]
[Mon Jul 20 07:32:05.841199 2026] [security2:error] [pid 156215:tid 156377] [client 84.17.60.251:48208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4jVcJ0fwhpxOKR8YghIgAAACA"]
[Mon Jul 20 07:32:06.014290 2026] [proxy:error] [pid 156215:tid 156358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:32:06.014408 2026] [proxy_http:error] [pid 156215:tid 156358] [client 82.102.18.182:43334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:32:06.016950 2026] [proxy:error] [pid 156215:tid 156358] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:32:06.017040 2026] [proxy_http:error] [pid 156215:tid 156358] [client 82.102.18.182:43334] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:32:06.069643 2026] [security2:error] [pid 156215:tid 156394] [client 54.39.210.3:42106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "avatrip.co"] [uri "/"] [unique_id "al4jVsJ0fwhpxOKR8YghOgAAADE"]
[Mon Jul 20 07:32:06.069776 2026] [security2:error] [pid 156215:tid 156394] [client 54.39.210.3:42106] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "avatrip.co"] [uri "/"] [unique_id "al4jVsJ0fwhpxOKR8YghOgAAADE"]
[Mon Jul 20 07:32:06.103174 2026] [security2:error] [pid 156215:tid 156304] [remote 46.101.194.217:33798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.194.101.46.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghPAAAS1g"]
[Mon Jul 20 07:32:06.103409 2026] [security2:error] [pid 156215:tid 156420] [client 46.101.194.217:33798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghPAAAS1g"]
[Mon Jul 20 07:32:06.160371 2026] [security2:error] [pid 156215:tid 156447] [client 149.0.16.108:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghRwAAAGY"]
[Mon Jul 20 07:32:06.160877 2026] [security2:error] [pid 156215:tid 156447] [client 149.0.16.108:51774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghRwAAAGY"]
[Mon Jul 20 07:32:06.167973 2026] [security2:error] [pid 156215:tid 156359] [client 84.17.60.251:48220] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4jVsJ0fwhpxOKR8YghSAAAAA4"]
[Mon Jul 20 07:32:06.184592 2026] [security2:error] [pid 156215:tid 156451] [client 57.141.18.72:22334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jVMJ0fwhpxOKR8YggrwAAagI"]
[Mon Jul 20 07:32:06.208453 2026] [security2:error] [pid 156215:tid 156414] [client 14.225.17.146:63076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4jVsJ0fwhpxOKR8YghOAAAAEU"], referer: http://cheesewithjam.com/TEST
[Mon Jul 20 07:32:06.231381 2026] [security2:error] [pid 156215:tid 156393] [client 3.67.192.83:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghSQAAADA"]
[Mon Jul 20 07:32:06.231997 2026] [security2:error] [pid 156215:tid 156393] [client 3.67.192.83:49812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghSQAAADA"]
[Mon Jul 20 07:32:06.292449 2026] [security2:error] [pid 156215:tid 156404] [client 35.245.239.138:54340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-e25ce87f.youpositive.co"] [uri "/index.php"] [unique_id "al4jVcJ0fwhpxOKR8YghKgAAADs"]
[Mon Jul 20 07:32:06.347230 2026] [security2:error] [pid 156215:tid 156360] [client 82.102.18.182:43348] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4jVsJ0fwhpxOKR8YghUgAAAA8"]
[Mon Jul 20 07:32:06.405389 2026] [security2:error] [pid 156215:tid 156471] [client 35.245.239.138:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.239.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e25ce87f.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghWgAAAH4"]
[Mon Jul 20 07:32:06.405505 2026] [security2:error] [pid 156215:tid 156471] [client 35.245.239.138:54340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e25ce87f.youpositive.co"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghWgAAAH4"]
[Mon Jul 20 07:32:06.408645 2026] [security2:error] [pid 156215:tid 156426] [client 103.139.191.61:59982] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghXAAAAFE"]
[Mon Jul 20 07:32:06.408738 2026] [security2:error] [pid 156215:tid 156426] [client 103.139.191.61:59982] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghXAAAAFE"]
[Mon Jul 20 07:32:06.496037 2026] [security2:error] [pid 156215:tid 156431] [client 84.17.60.251:48224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jVsJ0fwhpxOKR8YghYgAAAFY"]
[Mon Jul 20 07:32:06.696154 2026] [security2:error] [pid 156215:tid 156378] [client 104.234.53.52:40531] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4jVsJ0fwhpxOKR8YghbQAAACE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:06.746507 2026] [security2:error] [pid 156215:tid 156372] [client 82.102.18.182:43358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcalendars.kidsklubz.org"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghbgAAABs"]
[Mon Jul 20 07:32:06.822982 2026] [security2:error] [pid 156215:tid 156460] [client 84.17.60.251:48240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jVsJ0fwhpxOKR8YgheAAAAHM"]
[Mon Jul 20 07:32:06.826764 2026] [security2:error] [pid 156215:tid 156420] [client 114.119.132.163:34037] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "timespans.org"] [uri "/concert/bozzini-quartet"] [unique_id "al4jVsJ0fwhpxOKR8YghewAAAEs"], referer: https://timespans.org/season/2017
[Mon Jul 20 07:32:06.985374 2026] [security2:error] [pid 156215:tid 156468] [client 142.111.152.72:36951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jVsJ0fwhpxOKR8YghegAAAHs"]
[Mon Jul 20 07:32:07.079843 2026] [security2:error] [pid 156215:tid 156377] [client 82.102.18.182:6539] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jV8J0fwhpxOKR8YghjAAAACA"]
[Mon Jul 20 07:32:07.136536 2026] [security2:error] [pid 156215:tid 156379] [client 84.17.60.251:48248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "webmail.bluedoorbar.co.nz"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4jV8J0fwhpxOKR8YghlAAAACI"]
[Mon Jul 20 07:32:07.361245 2026] [security2:error] [pid 156215:tid 156463] [client 14.225.17.146:60599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4jV8J0fwhpxOKR8YghkwAAAHY"], referer: http://tntcatholic.com/TEST
[Mon Jul 20 07:32:07.415812 2026] [security2:error] [pid 156215:tid 156443] [client 82.102.18.182:53510] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jV8J0fwhpxOKR8YghrwAAAGI"]
[Mon Jul 20 07:32:07.428714 2026] [security2:error] [pid 156215:tid 156406] [client 74.7.241.133:39792] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "elevator-data.com"] [uri "/robots.txt"] [unique_id "al4jV8J0fwhpxOKR8YghpgAAPVA"]
[Mon Jul 20 07:32:07.442572 2026] [security2:error] [pid 156215:tid 156471] [client 136.158.60.21:18036] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jV8J0fwhpxOKR8YghtQAAAH4"]
[Mon Jul 20 07:32:07.442660 2026] [security2:error] [pid 156215:tid 156471] [client 136.158.60.21:18036] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jV8J0fwhpxOKR8YghtQAAAH4"]
[Mon Jul 20 07:32:07.612572 2026] [security2:error] [pid 156215:tid 156357] [client 57.141.18.68:32878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jVsJ0fwhpxOKR8YghRQAADDQ"]
[Mon Jul 20 07:32:07.760075 2026] [security2:error] [pid 156215:tid 156449] [client 82.102.18.182:53520] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jV8J0fwhpxOKR8YghyAAAAGg"]
[Mon Jul 20 07:32:07.912811 2026] [security2:error] [pid 156215:tid 156370] [client 157.20.138.62:59971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jV8J0fwhpxOKR8Ygh1QAAABk"]
[Mon Jul 20 07:32:07.912949 2026] [security2:error] [pid 156215:tid 156370] [client 157.20.138.62:59971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jV8J0fwhpxOKR8Ygh1QAAABk"]
[Mon Jul 20 07:32:08.075736 2026] [security2:error] [pid 156215:tid 156460] [client 82.102.18.182:48283] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4jWMJ0fwhpxOKR8Ygh4QAAAHM"]
[Mon Jul 20 07:32:08.523971 2026] [security2:error] [pid 156215:tid 156382] [client 82.102.18.182:29916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4jWMJ0fwhpxOKR8YgiBwAAACU"]
[Mon Jul 20 07:32:08.538724 2026] [security2:error] [pid 156215:tid 156422] [client 57.141.18.95:45796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jVsJ0fwhpxOKR8YghfwAATUw"]
[Mon Jul 20 07:32:08.713436 2026] [security2:error] [pid 156215:tid 156407] [client 49.47.218.174:58432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jWMJ0fwhpxOKR8YgiEgAAAD4"]
[Mon Jul 20 07:32:08.713569 2026] [security2:error] [pid 156215:tid 156407] [client 49.47.218.174:58432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jWMJ0fwhpxOKR8YgiEgAAAD4"]
[Mon Jul 20 07:32:08.844306 2026] [security2:error] [pid 156215:tid 156470] [client 82.102.18.182:53532] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4jWMJ0fwhpxOKR8YgiHQAAAH0"]
[Mon Jul 20 07:32:08.936540 2026] [security2:error] [pid 156215:tid 156358] [client 191.202.66.27:56210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jWMJ0fwhpxOKR8YgiJgAAAA0"]
[Mon Jul 20 07:32:08.936671 2026] [security2:error] [pid 156215:tid 156358] [client 191.202.66.27:56210] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jWMJ0fwhpxOKR8YgiJgAAAA0"]
[Mon Jul 20 07:32:08.939121 2026] [security2:error] [pid 156215:tid 156431] [client 14.225.17.146:59262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4jWMJ0fwhpxOKR8YgiGwAAAFY"], referer: http://lutheranphilosopher.com/TEST
[Mon Jul 20 07:32:08.996139 2026] [security2:error] [pid 156215:tid 156391] [client 57.141.18.34:33076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jV8J0fwhpxOKR8YghnQAALgg"]
[Mon Jul 20 07:32:09.108285 2026] [security2:error] [pid 156215:tid 156418] [client 57.141.18.68:32888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jV8J0fwhpxOKR8YghrAAASQM"]
[Mon Jul 20 07:32:09.176955 2026] [security2:error] [pid 156215:tid 156372] [client 82.102.18.182:53548] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jWcJ0fwhpxOKR8YgiPAAAABs"]
[Mon Jul 20 07:32:09.188957 2026] [security2:error] [pid 156215:tid 156423] [client 45.56.174.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "vtv.zzt.mybluehost.me"] [uri "/index.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiLQAAAE4"]
[Mon Jul 20 07:32:09.262659 2026] [security2:error] [pid 156215:tid 156419] [client 88.241.67.160:55894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiSAAAAEo"]
[Mon Jul 20 07:32:09.262940 2026] [security2:error] [pid 156215:tid 156419] [client 88.241.67.160:55894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiSAAAAEo"]
[Mon Jul 20 07:32:09.292591 2026] [security2:error] [pid 156215:tid 156295] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiTwAAaU8"]
[Mon Jul 20 07:32:09.292781 2026] [security2:error] [pid 156215:tid 156450] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiTwAAaU8"]
[Mon Jul 20 07:32:09.307562 2026] [security2:error] [pid 156215:tid 156377] [client 179.127.84.238:58372] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiUwAAACA"]
[Mon Jul 20 07:32:09.307766 2026] [security2:error] [pid 156215:tid 156377] [client 179.127.84.238:58372] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiUwAAACA"]
[Mon Jul 20 07:32:09.509805 2026] [security2:error] [pid 156215:tid 156370] [client 82.102.18.182:6445] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jWcJ0fwhpxOKR8YgiawAAABk"]
[Mon Jul 20 07:32:09.615874 2026] [security2:error] [pid 156215:tid 156397] [client 14.225.17.146:59403] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiXgAAADQ"], referer: http://idigress.studio/TEST
[Mon Jul 20 07:32:09.883308 2026] [security2:error] [pid 156215:tid 156379] [client 82.102.18.182:53578] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jWcJ0fwhpxOKR8YgigAAAACI"]
[Mon Jul 20 07:32:09.888590 2026] [security2:error] [pid 156215:tid 156399] [client 104.234.53.88:34101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jWcJ0fwhpxOKR8YgifwAAADY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:10.073027 2026] [security2:error] [pid 156215:tid 156385] [client 154.192.123.127:17896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jWsJ0fwhpxOKR8YgikAAAACg"]
[Mon Jul 20 07:32:10.073176 2026] [security2:error] [pid 156215:tid 156385] [client 154.192.123.127:17896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jWsJ0fwhpxOKR8YgikAAAACg"]
[Mon Jul 20 07:32:10.219381 2026] [security2:error] [pid 156215:tid 156467] [client 82.102.18.182:53580] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4jWsJ0fwhpxOKR8YgioQAAAHo"]
[Mon Jul 20 07:32:10.236768 2026] [security2:error] [pid 156215:tid 156429] [client 14.225.17.146:59893] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4jWsJ0fwhpxOKR8YgimAAAAFQ"]
[Mon Jul 20 07:32:10.247158 2026] [security2:error] [pid 156215:tid 156242] [remote 182.77.62.24:55420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4jWsJ0fwhpxOKR8YgiogAAUBo"]
[Mon Jul 20 07:32:10.386044 2026] [security2:error] [pid 156215:tid 156466] [client 36.93.152.155:53684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jWsJ0fwhpxOKR8YgirAAAAHk"]
[Mon Jul 20 07:32:10.386166 2026] [security2:error] [pid 156215:tid 156466] [client 36.93.152.155:53684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jWsJ0fwhpxOKR8YgirAAAAHk"]
[Mon Jul 20 07:32:10.566395 2026] [security2:error] [pid 156215:tid 156412] [client 82.102.18.182:53586] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4jWsJ0fwhpxOKR8YgivgAAAEM"]
[Mon Jul 20 07:32:10.746186 2026] [security2:error] [pid 156215:tid 156452] [client 57.141.18.114:22902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiMQAAa0I"]
[Mon Jul 20 07:32:10.827601 2026] [security2:error] [pid 156215:tid 156286] [remote 182.77.62.24:55420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4jWsJ0fwhpxOKR8Ygi1wAAdUY"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 07:32:10.878173 2026] [security2:error] [pid 156215:tid 156444] [client 82.102.18.182:53592] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jWsJ0fwhpxOKR8Ygi2QAAAGM"]
[Mon Jul 20 07:32:10.949413 2026] [security2:error] [pid 156215:tid 156401] [client 57.141.18.1:52110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiPQAAOAY"]
[Mon Jul 20 07:32:11.098433 2026] [security2:error] [pid 156215:tid 156363] [client 14.225.17.146:59973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4jWsJ0fwhpxOKR8Ygi3QAAABI"], referer: http://myspineworld.com/TEST
[Mon Jul 20 07:32:11.190584 2026] [security2:error] [pid 156215:tid 156465] [client 82.102.18.182:53594] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcalendars.kidsklubz.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4jW8J0fwhpxOKR8Ygi9QAAAHg"]
[Mon Jul 20 07:32:11.251198 2026] [security2:error] [pid 156215:tid 156371] [client 117.211.236.168:54816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jW8J0fwhpxOKR8Ygi-gAAABo"]
[Mon Jul 20 07:32:11.251323 2026] [security2:error] [pid 156215:tid 156371] [client 117.211.236.168:54816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jW8J0fwhpxOKR8Ygi-gAAABo"]
[Mon Jul 20 07:32:11.433853 2026] [security2:error] [pid 156215:tid 156383] [client 57.141.18.47:61036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jWcJ0fwhpxOKR8YgiewAAJiA"]
[Mon Jul 20 07:32:11.747722 2026] [security2:error] [pid 156215:tid 156353] [client 103.106.165.44:59584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jW8J0fwhpxOKR8YgjIQAAAAg"]
[Mon Jul 20 07:32:11.747817 2026] [security2:error] [pid 156215:tid 156353] [client 103.106.165.44:59584] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jW8J0fwhpxOKR8YgjIQAAAAg"]
[Mon Jul 20 07:32:11.948820 2026] [security2:error] [pid 156215:tid 156350] [client 57.141.18.67:27308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jWsJ0fwhpxOKR8YgiqAAABT0"]
[Mon Jul 20 07:32:12.124051 2026] [security2:error] [pid 156215:tid 156379] [client 158.173.89.95:26317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjSAAAACI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:32:12.143868 2026] [security2:error] [pid 156215:tid 156441] [client 14.225.17.146:63049] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4jW8J0fwhpxOKR8YgjPAAAAGA"], referer: https://myspineworld.com/TEST
[Mon Jul 20 07:32:12.204429 2026] [security2:error] [pid 156215:tid 156324] [remote 195.26.244.42:51482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjTwAAJGw"]
[Mon Jul 20 07:32:12.221050 2026] [security2:error] [pid 156215:tid 156316] [remote 182.77.62.24:34608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fiq.jjc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjUQAAD2Q"]
[Mon Jul 20 07:32:12.221223 2026] [security2:error] [pid 156215:tid 156360] [client 182.77.62.24:34608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fiq.jjc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjUQAAD2Q"]
[Mon Jul 20 07:32:12.251548 2026] [security2:error] [pid 156215:tid 156405] [client 14.225.17.146:56194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjRwAAADw"], referer: http://dnsplumbing.com/TEST
[Mon Jul 20 07:32:12.337576 2026] [security2:error] [pid 156215:tid 156459] [client 49.37.242.14:50905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjXgAAAHI"]
[Mon Jul 20 07:32:12.337788 2026] [security2:error] [pid 156215:tid 156459] [client 49.37.242.14:50905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjXgAAAHI"]
[Mon Jul 20 07:32:12.424015 2026] [security2:error] [pid 156215:tid 156437] [client 57.141.18.60:57980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jWsJ0fwhpxOKR8Ygi2AAAXFE"]
[Mon Jul 20 07:32:12.582679 2026] [security2:error] [pid 156215:tid 156384] [client 14.225.17.146:62937] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjcQAAACc"], referer: http://processorstudio.com/TEST
[Mon Jul 20 07:32:12.610910 2026] [security2:error] [pid 156215:tid 156423] [client 103.176.215.66:63425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjeAAAAE4"]
[Mon Jul 20 07:32:12.611213 2026] [security2:error] [pid 156215:tid 156423] [client 103.176.215.66:63425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjeAAAAE4"]
[Mon Jul 20 07:32:12.619254 2026] [security2:error] [pid 156215:tid 156337] [remote 195.26.244.42:51482] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sk-financial.com"] [uri "/wp-login.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjeQAAP3k"], referer: https://sk-financial.com/wp-login.php
[Mon Jul 20 07:32:12.877481 2026] [security2:error] [pid 156215:tid 156240] [remote 124.55.178.99:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjlQAAahg"]
[Mon Jul 20 07:32:13.246223 2026] [security2:error] [pid 156215:tid 156332] [remote 45.90.123.233:46750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jXcJ0fwhpxOKR8YgjtQAAZHQ"]
[Mon Jul 20 07:32:13.261232 2026] [security2:error] [pid 156215:tid 156365] [client 57.141.18.92:29140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jW8J0fwhpxOKR8YgjGAAAFHE"]
[Mon Jul 20 07:32:13.299127 2026] [security2:error] [pid 156215:tid 156247] [remote 124.55.178.99:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "margaretspeckogawa.com"] [uri "/wp-login.php"] [unique_id "al4jXcJ0fwhpxOKR8YgjtwAAch8"], referer: https://margaretspeckogawa.com/wp-login.php
[Mon Jul 20 07:32:13.432230 2026] [security2:error] [pid 156215:tid 156390] [client 14.225.17.146:60913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4jXcJ0fwhpxOKR8YgjvAAAAC0"], referer: https://processorstudio.com/TEST
[Mon Jul 20 07:32:13.546160 2026] [security2:error] [pid 156215:tid 156330] [remote 45.90.123.233:46750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jXcJ0fwhpxOKR8YgjyAAAb3I"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:32:13.604047 2026] [security2:error] [pid 156215:tid 156386] [client 57.141.18.39:25705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jW8J0fwhpxOKR8YgjOgAAKTI"]
[Mon Jul 20 07:32:13.874174 2026] [security2:error] [pid 156215:tid 156394] [client 192.178.4.133:62973] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.fridacom.net"] [uri "/robots.txt"] [unique_id "al4jXcJ0fwhpxOKR8Ygj4wAAADE"]
[Mon Jul 20 07:32:13.891282 2026] [security2:error] [pid 156215:tid 156367] [client 87.199.196.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4jXMJ0fwhpxOKR8YgjXwAAABY"]
[Mon Jul 20 07:32:14.114245 2026] [security2:error] [pid 156215:tid 156389] [client 14.225.17.146:62898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4jXcJ0fwhpxOKR8Ygj6gAAACw"], referer: http://effingweirdmuseums.com/TEST
[Mon Jul 20 07:32:14.122942 2026] [security2:error] [pid 156215:tid 156409] [client 143.44.185.218:28674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jXsJ0fwhpxOKR8Ygj9AAAAEA"]
[Mon Jul 20 07:32:14.123058 2026] [security2:error] [pid 156215:tid 156409] [client 143.44.185.218:28674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jXsJ0fwhpxOKR8Ygj9AAAAEA"]
[Mon Jul 20 07:32:14.193065 2026] [security2:error] [pid 156215:tid 156347] [client 216.244.66.244:51034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/2016/11/09/the-last-lagosian-wole-talabi/"] [unique_id "al4jXsJ0fwhpxOKR8YgkAAAAAAI"]
[Mon Jul 20 07:32:14.193194 2026] [security2:error] [pid 156215:tid 156347] [client 216.244.66.244:51034] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "omenana.com"] [uri "/2016/11/09/the-last-lagosian-wole-talabi/"] [unique_id "al4jXsJ0fwhpxOKR8YgkAAAAAAI"]
[Mon Jul 20 07:32:14.280357 2026] [security2:error] [pid 156215:tid 156232] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jXsJ0fwhpxOKR8YgkBgAANBA"]
[Mon Jul 20 07:32:14.280512 2026] [security2:error] [pid 156215:tid 156397] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jXsJ0fwhpxOKR8YgkBgAANBA"]
[Mon Jul 20 07:32:14.773275 2026] [security2:error] [pid 156215:tid 156349] [client 104.234.53.55:58063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jXsJ0fwhpxOKR8YgkPgAAAAQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:15.014145 2026] [security2:error] [pid 156215:tid 156371] [client 14.225.17.146:60980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4jXsJ0fwhpxOKR8YgkSQAAABo"], referer: https://effingweirdmuseums.com/TEST
[Mon Jul 20 07:32:15.051612 2026] [security2:error] [pid 156215:tid 156452] [client 57.141.18.108:24692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jXcJ0fwhpxOKR8YgjxwAAa2Y"]
[Mon Jul 20 07:32:15.097521 2026] [security2:error] [pid 156215:tid 156459] [client 77.110.127.138:51060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jXsJ0fwhpxOKR8YgkRgAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:32:15.621080 2026] [security2:error] [pid 156215:tid 156430] [client 204.93.184.221:47690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4jX8J0fwhpxOKR8YgkdgAAVRE"]
[Mon Jul 20 07:32:15.621302 2026] [security2:error] [pid 156215:tid 156404] [client 14.225.17.146:60713] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4jX8J0fwhpxOKR8YgkegAAADs"]
[Mon Jul 20 07:32:16.218585 2026] [security2:error] [pid 156215:tid 156379] [client 144.16.21.149:36226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jYMJ0fwhpxOKR8YgkrgAAACI"]
[Mon Jul 20 07:32:16.218728 2026] [security2:error] [pid 156215:tid 156379] [client 144.16.21.149:36226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jYMJ0fwhpxOKR8YgkrgAAACI"]
[Mon Jul 20 07:32:16.343863 2026] [security2:error] [pid 156215:tid 156226] [remote 8.217.108.67:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4jYMJ0fwhpxOKR8YgkvQAAHwo"]
[Mon Jul 20 07:32:16.447379 2026] [security2:error] [pid 156215:tid 156432] [client 87.199.196.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4jYMJ0fwhpxOKR8YgkqQAAAFc"]
[Mon Jul 20 07:32:16.719168 2026] [security2:error] [pid 156215:tid 156358] [client 3.75.183.99:37712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jYMJ0fwhpxOKR8Ygk4QAAAA0"]
[Mon Jul 20 07:32:16.719284 2026] [security2:error] [pid 156215:tid 156358] [client 3.75.183.99:37712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jYMJ0fwhpxOKR8Ygk4QAAAA0"]
[Mon Jul 20 07:32:16.765162 2026] [security2:error] [pid 156215:tid 156436] [client 149.0.16.108:61004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jYMJ0fwhpxOKR8Ygk5QAAAFs"]
[Mon Jul 20 07:32:16.765844 2026] [security2:error] [pid 156215:tid 156436] [client 149.0.16.108:61004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jYMJ0fwhpxOKR8Ygk5QAAAFs"]
[Mon Jul 20 07:32:16.878223 2026] [security2:error] [pid 156215:tid 156362] [client 104.207.63.104:62237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jYMJ0fwhpxOKR8Ygk5wAAABE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:17.049108 2026] [security2:error] [pid 156215:tid 156353] [client 128.1.123.81:36768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4jXsJ0fwhpxOKR8YgkTQAAAAg"]
[Mon Jul 20 07:32:17.132587 2026] [security2:error] [pid 156215:tid 156348] [client 57.141.18.81:25232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jX8J0fwhpxOKR8YgkbgAAA1c"]
[Mon Jul 20 07:32:17.138890 2026] [security2:error] [pid 156215:tid 156329] [remote 8.217.108.67:54032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alchemygroup.ca"] [uri "/wp-login.php"] [unique_id "al4jYcJ0fwhpxOKR8YglAwAAY3E"], referer: https://alchemygroup.ca/wp-login.php
[Mon Jul 20 07:32:17.266296 2026] [security2:error] [pid 156215:tid 156366] [client 181.43.243.40:17504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jYcJ0fwhpxOKR8YglCAAAFXQ"]
[Mon Jul 20 07:32:17.266357 2026] [security2:error] [pid 156215:tid 156366] [client 181.43.243.40:17504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/xmlrpc.php"] [unique_id "al4jYcJ0fwhpxOKR8YglCAAAFXQ"]
[Mon Jul 20 07:32:17.272888 2026] [security2:error] [pid 156215:tid 156469] [client 3.67.192.83:20112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jYcJ0fwhpxOKR8YglDgAAAHw"]
[Mon Jul 20 07:32:17.307134 2026] [security2:error] [pid 156215:tid 156430] [client 103.139.191.61:60442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jYcJ0fwhpxOKR8YglEQAAAFU"]
[Mon Jul 20 07:32:17.307296 2026] [security2:error] [pid 156215:tid 156430] [client 103.139.191.61:60442] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jYcJ0fwhpxOKR8YglEQAAAFU"]
[Mon Jul 20 07:32:17.355424 2026] [security2:error] [pid 156215:tid 156405] [client 43.173.70.134:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4jYcJ0fwhpxOKR8YglBgAAPCM"], referer: https://www.aleishapenny.ca/listing/page/162?paged=1&view=grid&posts_per_page=48
[Mon Jul 20 07:32:17.513367 2026] [security2:error] [pid 156215:tid 156470] [client 65.111.26.204:18497] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jYcJ0fwhpxOKR8YglJgAAAH0"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:17.543213 2026] [security2:error] [pid 156215:tid 156438] [client 50.116.65.227:48346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jYcJ0fwhpxOKR8YglKgAAAF0"]
[Mon Jul 20 07:32:17.553487 2026] [security2:error] [pid 156215:tid 156468] [client 50.116.65.227:48348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jYcJ0fwhpxOKR8YglLgAAAHs"]
[Mon Jul 20 07:32:17.581961 2026] [security2:error] [pid 156215:tid 156463] [client 14.225.17.146:62986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4jYMJ0fwhpxOKR8YgkrAAAAHY"], referer: http://alchemygroup.ca/TEST
[Mon Jul 20 07:32:17.614761 2026] [security2:error] [pid 156215:tid 156381] [client 57.141.18.18:26032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jX8J0fwhpxOKR8YgklgAAJBM"]
[Mon Jul 20 07:32:17.626143 2026] [security2:error] [pid 156215:tid 156423] [client 50.116.65.227:44374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4jYcJ0fwhpxOKR8YglMwAAAE4"]
[Mon Jul 20 07:32:17.640651 2026] [security2:error] [pid 156215:tid 156424] [client 50.116.65.227:48352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4jYcJ0fwhpxOKR8YglNAAAAE8"]
[Mon Jul 20 07:32:17.656794 2026] [security2:error] [pid 156215:tid 156415] [client 155.2.215.84:29557] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jYcJ0fwhpxOKR8YglJwAAAEY"]
[Mon Jul 20 07:32:17.846552 2026] [security2:error] [pid 156215:tid 156355] [client 63.179.149.246:34428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jYcJ0fwhpxOKR8YglRQAAAAo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:32:17.981772 2026] [security2:error] [pid 156215:tid 156393] [client 121.229.156.39:42526] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mourgroup.com"] [uri "/"] [unique_id "al4jYcJ0fwhpxOKR8YglVwAAADA"]
[Mon Jul 20 07:32:17.981913 2026] [security2:error] [pid 156215:tid 156393] [client 121.229.156.39:42526] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mourgroup.com"] [uri "/"] [unique_id "al4jYcJ0fwhpxOKR8YglVwAAADA"]
[Mon Jul 20 07:32:18.120405 2026] [security2:error] [pid 156215:tid 156456] [client 104.207.62.105:39891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jYsJ0fwhpxOKR8YglYQAAAG8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:18.162143 2026] [security2:error] [pid 156215:tid 156372] [client 50.116.65.227:48364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jYcJ0fwhpxOKR8YglVQAAABs"]
[Mon Jul 20 07:32:18.162911 2026] [security2:error] [pid 156215:tid 156285] [remote 209.42.18.223:37510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4jYsJ0fwhpxOKR8YglZQAAcEU"]
[Mon Jul 20 07:32:18.166537 2026] [security2:error] [pid 156215:tid 156441] [client 136.158.60.21:19540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jYsJ0fwhpxOKR8YglZgAAAGA"]
[Mon Jul 20 07:32:18.166698 2026] [security2:error] [pid 156215:tid 156441] [client 136.158.60.21:19540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jYsJ0fwhpxOKR8YglZgAAAGA"]
[Mon Jul 20 07:32:18.256155 2026] [security2:error] [pid 156215:tid 156356] [client 104.234.53.77:55347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jYsJ0fwhpxOKR8YglcgAAAAs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:18.327771 2026] [security2:error] [pid 156215:tid 156217] [remote 209.42.18.223:37510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "giftofgiving-usa.org"] [uri "/wp-login.php"] [unique_id "al4jYsJ0fwhpxOKR8YglewAAEwE"], referer: https://giftofgiving-usa.org/wp-login.php
[Mon Jul 20 07:32:18.398463 2026] [security2:error] [pid 156215:tid 156424] [client 50.116.65.227:48380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jYsJ0fwhpxOKR8YglZwAAAE8"]
[Mon Jul 20 07:32:18.542879 2026] [security2:error] [pid 156215:tid 156470] [client 87.199.196.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4jYsJ0fwhpxOKR8YglgwAAAH0"]
[Mon Jul 20 07:32:18.622475 2026] [security2:error] [pid 156215:tid 156375] [client 77.110.127.138:51013] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jYsJ0fwhpxOKR8YglgQAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:32:18.650179 2026] [security2:error] [pid 156215:tid 156358] [client 157.20.138.62:60574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jYsJ0fwhpxOKR8YglpAAAAA0"]
[Mon Jul 20 07:32:18.650295 2026] [security2:error] [pid 156215:tid 156358] [client 157.20.138.62:60574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jYsJ0fwhpxOKR8YglpAAAAA0"]
[Mon Jul 20 07:32:18.716223 2026] [security2:error] [pid 156215:tid 156401] [client 14.225.17.146:63000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4jYMJ0fwhpxOKR8Ygk2wAAADg"], referer: http://dollpassionista.com/TEST
[Mon Jul 20 07:32:18.896784 2026] [security2:error] [pid 156215:tid 156460] [client 158.173.241.141:27651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4jYsJ0fwhpxOKR8YglqQAAAHM"], referer: http://sesamegreenbeans.com/category/travel/
[Mon Jul 20 07:32:18.949656 2026] [security2:error] [pid 156215:tid 156363] [client 57.141.18.112:38034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jYcJ0fwhpxOKR8YglAgAAEiQ"]
[Mon Jul 20 07:32:19.290243 2026] [security2:error] [pid 156215:tid 156430] [client 49.47.218.174:58972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl3AAAAFU"]
[Mon Jul 20 07:32:19.290350 2026] [security2:error] [pid 156215:tid 156430] [client 49.47.218.174:58972] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl3AAAAFU"]
[Mon Jul 20 07:32:19.408845 2026] [security2:error] [pid 156215:tid 156403] [client 66.249.65.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4jY8J0fwhpxOKR8YglwwAAADo"]
[Mon Jul 20 07:32:19.413888 2026] [security2:error] [pid 156215:tid 156347] [client 57.141.18.53:59618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jYcJ0fwhpxOKR8YglMgAAAh4"]
[Mon Jul 20 07:32:19.438042 2026] [security2:error] [pid 156215:tid 156410] [client 77.110.127.138:51081] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl5AAAAEE"], referer: https://mezzacraft.com/author/mezza/page/
[Mon Jul 20 07:32:19.466876 2026] [security2:error] [pid 156215:tid 156428] [client 202.141.11.99:27549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl7wAAAFM"]
[Mon Jul 20 07:32:19.468398 2026] [security2:error] [pid 156215:tid 156428] [client 202.141.11.99:27549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl7wAAAFM"]
[Mon Jul 20 07:32:19.578701 2026] [security2:error] [pid 156215:tid 156468] [client 50.116.65.227:28424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4jY8J0fwhpxOKR8Ygl-gAAAHs"]
[Mon Jul 20 07:32:19.592443 2026] [security2:error] [pid 156215:tid 156370] [client 50.116.65.227:19908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4jY8J0fwhpxOKR8Ygl-wAAABk"]
[Mon Jul 20 07:32:19.716975 2026] [security2:error] [pid 156215:tid 156417] [client 14.225.17.146:62364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl9gAAAEg"], referer: https://dollpassionista.com/TEST
[Mon Jul 20 07:32:19.737600 2026] [security2:error] [pid 156215:tid 156391] [client 191.202.66.27:56708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8YgmBgAAAC4"]
[Mon Jul 20 07:32:19.737699 2026] [security2:error] [pid 156215:tid 156391] [client 191.202.66.27:56708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8YgmBgAAAC4"]
[Mon Jul 20 07:32:19.917179 2026] [security2:error] [pid 156215:tid 156415] [client 88.241.67.160:56435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8YgmEAAAAEY"]
[Mon Jul 20 07:32:19.917673 2026] [security2:error] [pid 156215:tid 156415] [client 88.241.67.160:56435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8YgmEAAAAEY"]
[Mon Jul 20 07:32:19.944738 2026] [security2:error] [pid 156215:tid 156281] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8YgmFQAAKkE"]
[Mon Jul 20 07:32:19.944875 2026] [security2:error] [pid 156215:tid 156387] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jY8J0fwhpxOKR8YgmFQAAKkE"]
[Mon Jul 20 07:32:20.059326 2026] [security2:error] [pid 156215:tid 156424] [client 179.127.84.238:58919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmJgAAAE8"]
[Mon Jul 20 07:32:20.059435 2026] [security2:error] [pid 156215:tid 156424] [client 179.127.84.238:58919] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmJgAAAE8"]
[Mon Jul 20 07:32:20.168591 2026] [security2:error] [pid 156215:tid 156472] [client 14.225.17.146:62297] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4jYsJ0fwhpxOKR8YglrQAAAH8"], referer: http://alaraycreative.com/TEST
[Mon Jul 20 07:32:20.253767 2026] [security2:error] [pid 156215:tid 156423] [client 87.199.196.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmJAAAAE4"]
[Mon Jul 20 07:32:20.438998 2026] [security2:error] [pid 156215:tid 156352] [client 52.165.88.155:45512] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.64.31"] [uri "/index.cgi"] [unique_id "al4jZMJ0fwhpxOKR8YgmPgAAAAc"]
[Mon Jul 20 07:32:20.591732 2026] [security2:error] [pid 156215:tid 156412] [client 66.249.74.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmIwAAAEM"]
[Mon Jul 20 07:32:20.644796 2026] [security2:error] [pid 156215:tid 156360] [client 116.74.65.235:63463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmPwAAAA8"]
[Mon Jul 20 07:32:20.675895 2026] [security2:error] [pid 156215:tid 156467] [client 154.192.123.127:18408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmUQAAAHo"]
[Mon Jul 20 07:32:20.676045 2026] [security2:error] [pid 156215:tid 156467] [client 154.192.123.127:18408] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmUQAAAHo"]
[Mon Jul 20 07:32:20.801824 2026] [security2:error] [pid 156215:tid 156354] [client 104.234.53.51:42693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmWgAAAAk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:20.860249 2026] [security2:error] [pid 156215:tid 156398] [client 57.141.18.26:60352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jY8J0fwhpxOKR8YglygAANTs"]
[Mon Jul 20 07:32:20.889633 2026] [security2:error] [pid 156215:tid 156445] [client 36.93.152.155:54195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmXwAAAGQ"]
[Mon Jul 20 07:32:20.889744 2026] [security2:error] [pid 156215:tid 156445] [client 36.93.152.155:54195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jZMJ0fwhpxOKR8YgmXwAAAGQ"]
[Mon Jul 20 07:32:21.103809 2026] [security2:error] [pid 156215:tid 156236] [remote 20.153.140.50:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmcgAACxQ"]
[Mon Jul 20 07:32:21.264382 2026] [security2:error] [pid 156215:tid 156402] [client 57.141.18.26:60364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jY8J0fwhpxOKR8Ygl_wAAOV4"]
[Mon Jul 20 07:32:21.379395 2026] [security2:error] [pid 156215:tid 156425] [client 112.86.225.245:34822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.omenana.com"] [uri "/"] [unique_id "al4jZcJ0fwhpxOKR8YgmigAAAFA"]
[Mon Jul 20 07:32:21.379515 2026] [security2:error] [pid 156215:tid 156425] [client 112.86.225.245:34822] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.omenana.com"] [uri "/"] [unique_id "al4jZcJ0fwhpxOKR8YgmigAAAFA"]
[Mon Jul 20 07:32:21.403303 2026] [security2:error] [pid 156215:tid 156245] [remote 91.142.222.105:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmjwAADB0"]
[Mon Jul 20 07:32:21.491947 2026] [security2:error] [pid 156215:tid 156294] [remote 20.153.140.50:55224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmmAAAWE4"], referer: https://headachescarpaltunnelfibromyalgia.com/wp-login.php
[Mon Jul 20 07:32:21.637600 2026] [security2:error] [pid 156215:tid 156297] [remote 130.185.118.215:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmpQAAcVE"]
[Mon Jul 20 07:32:21.687276 2026] [security2:error] [pid 156215:tid 156283] [remote 91.142.222.105:59310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmpwAAfkM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:32:21.831414 2026] [security2:error] [pid 156215:tid 156285] [remote 130.185.118.215:50370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmuQAACUU"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 07:32:22.093364 2026] [security2:error] [pid 156215:tid 156468] [client 188.166.209.66:61607] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmwQAAAHs"], referer: binance.com
[Mon Jul 20 07:32:22.105235 2026] [security2:error] [pid 156215:tid 156375] [client 158.173.241.141:29289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jZsJ0fwhpxOKR8YgmyQAAAB4"], referer: https://www.sesamegreenbeans.com/overland-from-singapore-to-almost-china-1-to-9-june-2022/
[Mon Jul 20 07:32:22.105305 2026] [security2:error] [pid 156215:tid 156375] [client 158.173.241.141:29289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jZsJ0fwhpxOKR8YgmyQAAAB4"], referer: https://www.sesamegreenbeans.com/overland-from-singapore-to-almost-china-1-to-9-june-2022/
[Mon Jul 20 07:32:22.145650 2026] [security2:error] [pid 156215:tid 156393] [client 103.106.165.44:60066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jZsJ0fwhpxOKR8Ygm0gAAADA"]
[Mon Jul 20 07:32:22.145766 2026] [security2:error] [pid 156215:tid 156393] [client 103.106.165.44:60066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jZsJ0fwhpxOKR8Ygm0gAAADA"]
[Mon Jul 20 07:32:22.161545 2026] [security2:error] [pid 156215:tid 156399] [client 14.225.17.146:65059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4jZsJ0fwhpxOKR8YgmyAAAADY"], referer: http://ivetstrategies.com/TEST
[Mon Jul 20 07:32:22.478723 2026] [security2:error] [pid 156215:tid 156395] [client 57.141.18.87:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jZsJ0fwhpxOKR8Ygm5QAAADI"]
[Mon Jul 20 07:32:22.493834 2026] [security2:error] [pid 156215:tid 156446] [client 50.116.65.227:28446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4jZsJ0fwhpxOKR8Ygm8wAAAGU"]
[Mon Jul 20 07:32:22.508246 2026] [security2:error] [pid 156215:tid 156465] [client 50.116.65.227:19974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2025/01/54257992315_73e60fc469_h.jpg"] [unique_id "al4jZsJ0fwhpxOKR8Ygm9AAAAHg"]
[Mon Jul 20 07:32:22.583470 2026] [security2:error] [pid 156215:tid 156363] [client 158.173.241.141:52995] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jZsJ0fwhpxOKR8Ygm-AAAABI"], referer: https://www.sesamegreenbeans.com/overland-from-singapore-to-almost-china-1-to-9-june-2022/
[Mon Jul 20 07:32:22.729276 2026] [security2:error] [pid 156215:tid 156326] [remote 152.228.213.32:60154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jZsJ0fwhpxOKR8YgnBQAAU24"]
[Mon Jul 20 07:32:22.729466 2026] [security2:error] [pid 156215:tid 156428] [client 152.228.213.32:60154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jZsJ0fwhpxOKR8YgnBQAAU24"]
[Mon Jul 20 07:32:22.946837 2026] [security2:error] [pid 156215:tid 156393] [client 117.211.236.168:55329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jZsJ0fwhpxOKR8YgnIgAAADA"]
[Mon Jul 20 07:32:22.946951 2026] [security2:error] [pid 156215:tid 156393] [client 117.211.236.168:55329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jZsJ0fwhpxOKR8YgnIgAAADA"]
[Mon Jul 20 07:32:23.072590 2026] [security2:error] [pid 156215:tid 156424] [client 87.199.196.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4jZsJ0fwhpxOKR8YgnIwAAAE8"]
[Mon Jul 20 07:32:23.149609 2026] [security2:error] [pid 156215:tid 156364] [client 103.176.215.66:63952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnOQAAABM"]
[Mon Jul 20 07:32:23.150080 2026] [security2:error] [pid 156215:tid 156364] [client 103.176.215.66:63952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnOQAAABM"]
[Mon Jul 20 07:32:23.519602 2026] [security2:error] [pid 156215:tid 156437] [client 14.225.17.146:63438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnLgAAAFw"], referer: http://onewingpictures.com/TEST
[Mon Jul 20 07:32:23.523040 2026] [security2:error] [pid 156215:tid 156467] [client 14.225.17.146:60470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnVAAAAHo"], referer: http://daseighty.net/TEST
[Mon Jul 20 07:32:23.527179 2026] [security2:error] [pid 156215:tid 156391] [client 121.229.156.66:52166] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.asliceofleadership.com"] [uri "/"] [unique_id "al4jZ8J0fwhpxOKR8YgnXQAAAC4"]
[Mon Jul 20 07:32:23.527270 2026] [security2:error] [pid 156215:tid 156391] [client 121.229.156.66:52166] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.asliceofleadership.com"] [uri "/"] [unique_id "al4jZ8J0fwhpxOKR8YgnXQAAAC4"]
[Mon Jul 20 07:32:23.740518 2026] [security2:error] [pid 156215:tid 156382] [client 14.225.17.146:51304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnZAAAACU"], referer: http://blaizeaccountingservices.com/TEST
[Mon Jul 20 07:32:23.749945 2026] [security2:error] [pid 156215:tid 156417] [client 14.225.17.146:51299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnYwAAAEg"], referer: http://koaconsultants.com/TEST
[Mon Jul 20 07:32:23.756238 2026] [security2:error] [pid 156215:tid 156363] [client 158.173.241.141:52995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jZsJ0fwhpxOKR8Ygm-AAAABI"], referer: https://www.sesamegreenbeans.com/overland-from-singapore-to-almost-china-1-to-9-june-2022/
[Mon Jul 20 07:32:23.756287 2026] [security2:error] [pid 156215:tid 156363] [client 158.173.241.141:52995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jZsJ0fwhpxOKR8Ygm-AAAABI"], referer: https://www.sesamegreenbeans.com/overland-from-singapore-to-almost-china-1-to-9-june-2022/
[Mon Jul 20 07:32:23.913196 2026] [security2:error] [pid 156215:tid 156427] [client 104.234.53.89:58723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4jZ8J0fwhpxOKR8YgndgAAAFI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:23.949258 2026] [security2:error] [pid 156215:tid 156422] [client 57.141.18.81:40572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jZcJ0fwhpxOKR8YgmxgAATSk"]
[Mon Jul 20 07:32:24.491829 2026] [security2:error] [pid 156215:tid 156429] [client 155.2.212.12:30783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4jaMJ0fwhpxOKR8YgntAAAAFQ"]
[Mon Jul 20 07:32:24.492129 2026] [security2:error] [pid 156215:tid 156439] [client 185.238.231.163:55829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4jaMJ0fwhpxOKR8YgnswAAAF4"]
[Mon Jul 20 07:32:24.507114 2026] [security2:error] [pid 156215:tid 156407] [client 14.225.17.146:51334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4jaMJ0fwhpxOKR8YgnogAAAD4"], referer: http://nomorewetsheets.net/TEST
[Mon Jul 20 07:32:24.599054 2026] [security2:error] [pid 156215:tid 156386] [client 14.225.17.146:65045] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4jZ8J0fwhpxOKR8YgncAAAACk"], referer: http://overloadcomedy.com/TEST
[Mon Jul 20 07:32:24.879546 2026] [security2:error] [pid 156215:tid 156406] [client 49.37.242.14:51403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jaMJ0fwhpxOKR8Ygn3wAAAD0"]
[Mon Jul 20 07:32:24.879693 2026] [security2:error] [pid 156215:tid 156406] [client 49.37.242.14:51403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jaMJ0fwhpxOKR8Ygn3wAAAD0"]
[Mon Jul 20 07:32:24.925286 2026] [security2:error] [pid 156215:tid 156301] [remote 154.66.198.148:57480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jaMJ0fwhpxOKR8Ygn5gAAGVU"]
[Mon Jul 20 07:32:24.925430 2026] [security2:error] [pid 156215:tid 156370] [client 154.66.198.148:57480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "str.cly.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jaMJ0fwhpxOKR8Ygn5gAAGVU"]
[Mon Jul 20 07:32:25.055375 2026] [security2:error] [pid 156215:tid 156266] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jacJ0fwhpxOKR8Ygn9gAATzI"]
[Mon Jul 20 07:32:25.055600 2026] [security2:error] [pid 156215:tid 156424] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jacJ0fwhpxOKR8Ygn9gAATzI"]
[Mon Jul 20 07:32:25.075742 2026] [security2:error] [pid 156215:tid 156368] [client 87.199.196.160:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4jaMJ0fwhpxOKR8Ygn3QAAABc"]
[Mon Jul 20 07:32:25.079992 2026] [security2:error] [pid 156215:tid 156351] [client 57.141.18.96:34118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jZ8J0fwhpxOKR8YgnPQAABiU"]
[Mon Jul 20 07:32:25.216489 2026] [security2:error] [pid 156215:tid 156227] [remote 8.217.108.67:35696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jacJ0fwhpxOKR8YgoAQAAMgs"]
[Mon Jul 20 07:32:25.444188 2026] [security2:error] [pid 156215:tid 156385] [client 50.116.65.227:28452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4jacJ0fwhpxOKR8YgoDwAAACg"]
[Mon Jul 20 07:32:25.455279 2026] [security2:error] [pid 156215:tid 156450] [client 50.116.65.227:20052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4jacJ0fwhpxOKR8YgoEQAAAGk"]
[Mon Jul 20 07:32:25.456804 2026] [security2:error] [pid 156215:tid 156418] [client 51.68.111.244:19205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "querenciapartners.com"] [uri "/robots.txt"] [unique_id "al4jacJ0fwhpxOKR8YgoEgAAAEk"]
[Mon Jul 20 07:32:25.456914 2026] [security2:error] [pid 156215:tid 156418] [client 51.68.111.244:19205] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "querenciapartners.com"] [uri "/robots.txt"] [unique_id "al4jacJ0fwhpxOKR8YgoEgAAAEk"]
[Mon Jul 20 07:32:25.580988 2026] [security2:error] [pid 156215:tid 156387] [client 143.44.185.218:29946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jacJ0fwhpxOKR8YgoGwAAACo"]
[Mon Jul 20 07:32:25.581071 2026] [security2:error] [pid 156215:tid 156387] [client 143.44.185.218:29946] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jacJ0fwhpxOKR8YgoGwAAACo"]
[Mon Jul 20 07:32:25.609281 2026] [security2:error] [pid 156215:tid 156232] [remote 8.217.108.67:35696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jacJ0fwhpxOKR8YgoHAAAcBA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:32:26.184035 2026] [security2:error] [pid 156215:tid 156425] [client 45.115.194.141:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tgs.lfg.mybluehost.me"] [uri "/index.php"] [unique_id "al4jaMJ0fwhpxOKR8YgnuwAAAFA"]
[Mon Jul 20 07:32:26.217910 2026] [security2:error] [pid 156215:tid 156348] [client 57.141.18.50:62886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jaMJ0fwhpxOKR8YgnlAAAA3U"]
[Mon Jul 20 07:32:26.483105 2026] [security2:error] [pid 156215:tid 156362] [client 14.225.17.146:62813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4jaMJ0fwhpxOKR8YgniQAAABE"], referer: http://gearwaterproof.com/TEST
[Mon Jul 20 07:32:26.518580 2026] [security2:error] [pid 156215:tid 156445] [client 50.116.65.227:28468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4jasJ0fwhpxOKR8YgoaAAAAGQ"]
[Mon Jul 20 07:32:26.532550 2026] [security2:error] [pid 156215:tid 156424] [client 50.116.65.227:20084] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-content/uploads/2022/06/52141641572_5b8f06bd12_h.jpg"] [unique_id "al4jasJ0fwhpxOKR8YgoagAAAE8"]
[Mon Jul 20 07:32:26.579357 2026] [security2:error] [pid 156215:tid 156366] [client 14.225.17.146:62808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4jacJ0fwhpxOKR8Ygn8AAAABU"], referer: http://adirondackengineering.com/TEST
[Mon Jul 20 07:32:26.835442 2026] [security2:error] [pid 156215:tid 156404] [client 57.141.18.30:34802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jaMJ0fwhpxOKR8Ygn4AAAO3I"]
[Mon Jul 20 07:32:26.835620 2026] [security2:error] [pid 156215:tid 156422] [client 14.225.17.146:64891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4jasJ0fwhpxOKR8YgocQAAAE0"], referer: http://ghivs.com/TEST
[Mon Jul 20 07:32:27.022032 2026] [security2:error] [pid 156215:tid 156391] [client 43.205.139.3:20010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4ja8J0fwhpxOKR8YgohwAAAC4"]
[Mon Jul 20 07:32:27.098769 2026] [security2:error] [pid 156215:tid 156427] [client 144.16.21.149:24868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8YgokgAAAFI"]
[Mon Jul 20 07:32:27.098873 2026] [security2:error] [pid 156215:tid 156427] [client 144.16.21.149:24868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8YgokgAAAFI"]
[Mon Jul 20 07:32:27.135020 2026] [security2:error] [pid 156215:tid 156346] [client 14.225.17.146:62789] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4ja8J0fwhpxOKR8YgohgAAAAE"], referer: http://aljosour-alarabia.com/TEST
[Mon Jul 20 07:32:27.416970 2026] [security2:error] [pid 156215:tid 156382] [client 14.225.17.146:62957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4ja8J0fwhpxOKR8YgolAAAACU"], referer: http://transparentservices.online/TEST
[Mon Jul 20 07:32:27.450811 2026] [security2:error] [pid 156215:tid 156454] [client 149.0.16.108:65244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8YgovAAAAG0"]
[Mon Jul 20 07:32:27.450977 2026] [security2:error] [pid 156215:tid 156454] [client 149.0.16.108:65244] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8YgovAAAAG0"]
[Mon Jul 20 07:32:27.799726 2026] [security2:error] [pid 156215:tid 156257] [remote 152.228.213.32:48262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8Ygo0QAAGCk"]
[Mon Jul 20 07:32:27.799914 2026] [security2:error] [pid 156215:tid 156369] [client 152.228.213.32:48262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8Ygo0QAAGCk"]
[Mon Jul 20 07:32:27.804177 2026] [security2:error] [pid 156215:tid 156433] [client 217.181.91.132:15945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ja8J0fwhpxOKR8YgozwAAAFg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:27.830764 2026] [security2:error] [pid 156215:tid 156472] [client 57.141.18.103:36542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jasJ0fwhpxOKR8YgoPwAAf38"]
[Mon Jul 20 07:32:27.836652 2026] [security2:error] [pid 156215:tid 156384] [client 57.141.18.50:59998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jacJ0fwhpxOKR8YgoPAAAJxw"]
[Mon Jul 20 07:32:27.939785 2026] [security2:error] [pid 156215:tid 156395] [client 3.78.190.80:27882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4ja8J0fwhpxOKR8YgopgAAADI"]
[Mon Jul 20 07:32:28.238253 2026] [security2:error] [pid 156215:tid 156377] [client 142.111.152.180:24727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jbMJ0fwhpxOKR8Ygo6gAAACA"]
[Mon Jul 20 07:32:28.261314 2026] [security2:error] [pid 156215:tid 156373] [client 104.234.53.65:58987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jbMJ0fwhpxOKR8Ygo9QAAABw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:28.420097 2026] [security2:error] [pid 156215:tid 156357] [client 103.139.191.61:60906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpAwAAAAw"]
[Mon Jul 20 07:32:28.420245 2026] [security2:error] [pid 156215:tid 156357] [client 103.139.191.61:60906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpAwAAAAw"]
[Mon Jul 20 07:32:28.431758 2026] [security2:error] [pid 156215:tid 156442] [client 45.3.45.113:27795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpAAAAAGE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:28.737953 2026] [security2:error] [pid 156215:tid 156332] [remote 188.166.241.141:47600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpJwAAYnQ"]
[Mon Jul 20 07:32:28.832850 2026] [security2:error] [pid 156215:tid 156405] [client 136.158.60.21:21118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpMgAAADw"]
[Mon Jul 20 07:32:28.832998 2026] [security2:error] [pid 156215:tid 156405] [client 136.158.60.21:21118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpMgAAADw"]
[Mon Jul 20 07:32:29.035287 2026] [security2:error] [pid 156215:tid 156467] [client 157.20.138.62:61148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpRQAAAHo"]
[Mon Jul 20 07:32:29.035374 2026] [security2:error] [pid 156215:tid 156467] [client 157.20.138.62:61148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpRQAAAHo"]
[Mon Jul 20 07:32:29.056166 2026] [security2:error] [pid 156215:tid 156403] [client 65.111.20.96:18483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpRAAAADo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:29.065222 2026] [security2:error] [pid 156215:tid 156436] [client 57.141.18.71:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpPAAAAFs"]
[Mon Jul 20 07:32:29.111158 2026] [security2:error] [pid 156215:tid 156238] [remote 188.166.241.141:47600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gertoger.org"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpTQAAYhY"], referer: https://gertoger.org/wp-login.php
[Mon Jul 20 07:32:29.217441 2026] [security2:error] [pid 156215:tid 156456] [client 50.116.65.227:35710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jbcJ0fwhpxOKR8YgpWAAAAG8"]
[Mon Jul 20 07:32:29.226992 2026] [security2:error] [pid 156215:tid 156227] [remote 160.187.68.132:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpVgAAUgs"]
[Mon Jul 20 07:32:29.227713 2026] [security2:error] [pid 156215:tid 156418] [client 50.116.65.227:35712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jbcJ0fwhpxOKR8YgpXAAAAEk"]
[Mon Jul 20 07:32:29.343076 2026] [security2:error] [pid 156215:tid 156308] [remote 154.61.75.100:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpYQAAN1w"]
[Mon Jul 20 07:32:29.507235 2026] [security2:error] [pid 156215:tid 156361] [client 57.141.18.65:59408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ja8J0fwhpxOKR8YgoxgAAECY"]
[Mon Jul 20 07:32:29.701721 2026] [security2:error] [pid 156215:tid 156472] [client 14.225.17.146:62421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpcQAAAH8"], referer: https://north-woods-engineering.com/TEST
[Mon Jul 20 07:32:29.702686 2026] [security2:error] [pid 156215:tid 156264] [remote 160.187.68.132:46622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpfQAABTA"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:32:29.731914 2026] [security2:error] [pid 156215:tid 156411] [client 14.225.17.146:51207] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpAgAAAEI"], referer: http://elitetax-mi.com/TEST
[Mon Jul 20 07:32:29.765519 2026] [security2:error] [pid 156215:tid 156386] [client 57.141.18.95:20182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ja8J0fwhpxOKR8Ygo0AAAKUY"]
[Mon Jul 20 07:32:29.840609 2026] [security2:error] [pid 156215:tid 156217] [remote 154.61.75.100:59278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpjQAASQE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:32:29.945904 2026] [security2:error] [pid 156215:tid 156371] [client 223.237.128.244:52521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgphgAAABo"]
[Mon Jul 20 07:32:29.948673 2026] [security2:error] [pid 156215:tid 156351] [client 49.47.218.174:59517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgplgAAAAY"]
[Mon Jul 20 07:32:29.948776 2026] [security2:error] [pid 156215:tid 156351] [client 49.47.218.174:59517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgplgAAAAY"]
[Mon Jul 20 07:32:29.956528 2026] [security2:error] [pid 156215:tid 156347] [client 50.116.65.227:47466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4jbcJ0fwhpxOKR8YgpmQAAAAI"]
[Mon Jul 20 07:32:29.970202 2026] [security2:error] [pid 156215:tid 156374] [client 50.116.65.227:35756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4jbcJ0fwhpxOKR8YgpmwAAADc"]
[Mon Jul 20 07:32:29.986442 2026] [security2:error] [pid 156215:tid 156387] [client 202.141.11.99:55322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpngAAACo"]
[Mon Jul 20 07:32:29.986719 2026] [security2:error] [pid 156215:tid 156387] [client 202.141.11.99:55322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpngAAACo"]
[Mon Jul 20 07:32:29.989034 2026] [security2:error] [pid 156215:tid 156263] [remote 152.228.213.32:48276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpnAAAQy8"]
[Mon Jul 20 07:32:30.129504 2026] [security2:error] [pid 156215:tid 156353] [client 57.141.18.31:60046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jbMJ0fwhpxOKR8Ygo-wAACG0"]
[Mon Jul 20 07:32:30.175084 2026] [security2:error] [pid 156215:tid 156252] [remote 152.228.213.32:48276] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jbsJ0fwhpxOKR8YgpqAAAOiQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:32:30.195329 2026] [security2:error] [pid 156215:tid 156376] [client 14.225.17.146:50873] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpJAAAAB8"], referer: http://eframiproperties.com/TEST
[Mon Jul 20 07:32:30.381247 2026] [security2:error] [pid 156215:tid 156438] [client 191.202.66.27:57202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8YgpugAAAF0"]
[Mon Jul 20 07:32:30.381395 2026] [security2:error] [pid 156215:tid 156438] [client 191.202.66.27:57202] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8YgpugAAAF0"]
[Mon Jul 20 07:32:30.413699 2026] [security2:error] [pid 156215:tid 156394] [client 57.141.18.33:41742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpJgAAMV4"]
[Mon Jul 20 07:32:30.596020 2026] [security2:error] [pid 156215:tid 156309] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8YgpzgAAEF0"]
[Mon Jul 20 07:32:30.596171 2026] [security2:error] [pid 156215:tid 156361] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8YgpzgAAEF0"]
[Mon Jul 20 07:32:30.641478 2026] [security2:error] [pid 156215:tid 156407] [client 35.252.111.205:37886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.iwv.oao.mybluehost.me"] [uri "/index.php"] [unique_id "al4jbMJ0fwhpxOKR8YgpFwAAAD4"]
[Mon Jul 20 07:32:30.645869 2026] [security2:error] [pid 156215:tid 156350] [client 88.241.67.160:53457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8Ygp1gAAAAU"]
[Mon Jul 20 07:32:30.646056 2026] [security2:error] [pid 156215:tid 156350] [client 88.241.67.160:53457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8Ygp1gAAAAU"]
[Mon Jul 20 07:32:30.712674 2026] [security2:error] [pid 156215:tid 156401] [client 179.127.84.238:59480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8Ygp2wAAADg"]
[Mon Jul 20 07:32:30.712816 2026] [security2:error] [pid 156215:tid 156401] [client 179.127.84.238:59480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jbsJ0fwhpxOKR8Ygp2wAAADg"]
[Mon Jul 20 07:32:30.956149 2026] [security2:error] [pid 156215:tid 156390] [client 57.141.18.114:44396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpYAAALVE"]
[Mon Jul 20 07:32:30.998242 2026] [security2:error] [pid 156215:tid 156357] [client 74.208.214.194:53140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jbsJ0fwhpxOKR8Ygp_gAAAAw"]
[Mon Jul 20 07:32:31.132645 2026] [security2:error] [pid 156215:tid 156426] [client 154.192.123.127:16904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jb8J0fwhpxOKR8YgqBgAAAFE"]
[Mon Jul 20 07:32:31.132791 2026] [security2:error] [pid 156215:tid 156426] [client 154.192.123.127:16904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jb8J0fwhpxOKR8YgqBgAAAFE"]
[Mon Jul 20 07:32:31.167221 2026] [security2:error] [pid 156215:tid 156467] [client 57.141.18.86:62784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jbcJ0fwhpxOKR8YgpbwAAehA"]
[Mon Jul 20 07:32:31.208535 2026] [security2:error] [pid 156215:tid 156409] [client 114.119.137.45:20605] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gregoryanicholas.com"] [uri "/robots.txt"] [unique_id "al4jb8J0fwhpxOKR8YgqCQAAAEA"], referer: https://gregoryanicholas.com/robots.txt
[Mon Jul 20 07:32:31.269495 2026] [security2:error] [pid 156215:tid 156425] [client 14.225.17.146:51273] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4jb8J0fwhpxOKR8YgqBQAAAFA"], referer: http://vinovinhowine.com/TEST
[Mon Jul 20 07:32:31.292504 2026] [security2:error] [pid 156215:tid 156351] [client 62.102.148.130:39150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jb8J0fwhpxOKR8YgqEQAAAAY"]
[Mon Jul 20 07:32:31.292605 2026] [security2:error] [pid 156215:tid 156351] [client 62.102.148.130:39150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jb8J0fwhpxOKR8YgqEQAAAAY"]
[Mon Jul 20 07:32:31.419948 2026] [security2:error] [pid 156215:tid 156422] [client 36.93.152.155:54712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jb8J0fwhpxOKR8YgqGwAAAE0"]
[Mon Jul 20 07:32:31.420047 2026] [security2:error] [pid 156215:tid 156422] [client 36.93.152.155:54712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jb8J0fwhpxOKR8YgqGwAAAE0"]
[Mon Jul 20 07:32:31.909895 2026] [security2:error] [pid 156215:tid 156391] [client 158.173.166.181:43255] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jb8J0fwhpxOKR8YgqPwAAAC4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:32:31.917851 2026] [security2:error] [pid 156215:tid 156416] [client 57.141.18.69:21448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jbsJ0fwhpxOKR8YgptQAAR2M"]
[Mon Jul 20 07:32:32.027150 2026] [security2:error] [pid 156215:tid 156340] [remote 20.153.140.50:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqTgAAHXw"]
[Mon Jul 20 07:32:32.471257 2026] [security2:error] [pid 156215:tid 156301] [remote 20.153.140.50:59686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqZAAAFlU"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 07:32:32.598879 2026] [security2:error] [pid 156215:tid 156437] [client 117.211.236.168:55989] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqbQAAAFw"]
[Mon Jul 20 07:32:32.598970 2026] [security2:error] [pid 156215:tid 156437] [client 117.211.236.168:55989] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqbQAAAFw"]
[Mon Jul 20 07:32:32.712784 2026] [security2:error] [pid 156215:tid 156376] [client 103.106.165.44:60562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqdwAAAB8"]
[Mon Jul 20 07:32:32.712886 2026] [security2:error] [pid 156215:tid 156376] [client 103.106.165.44:60562] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqdwAAAB8"]
[Mon Jul 20 07:32:33.676013 2026] [security2:error] [pid 156215:tid 156348] [client 54.244.177.189:29236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4jccJ0fwhpxOKR8YgqwwAAAAM"]
[Mon Jul 20 07:32:33.687965 2026] [security2:error] [pid 156215:tid 156443] [client 103.176.215.66:64483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jccJ0fwhpxOKR8YgqxgAAAGI"]
[Mon Jul 20 07:32:33.688049 2026] [security2:error] [pid 156215:tid 156443] [client 103.176.215.66:64483] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jccJ0fwhpxOKR8YgqxgAAAGI"]
[Mon Jul 20 07:32:33.747929 2026] [security2:error] [pid 156215:tid 156409] [client 57.141.18.56:62304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jb8J0fwhpxOKR8YgqQgAAQEg"]
[Mon Jul 20 07:32:33.841837 2026] [security2:error] [pid 156215:tid 156351] [client 57.141.18.47:36414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jb8J0fwhpxOKR8YgqRwAABkc"]
[Mon Jul 20 07:32:33.895461 2026] [security2:error] [pid 156215:tid 156439] [client 57.141.18.125:23148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jcMJ0fwhpxOKR8YgqUgAAXko"]
[Mon Jul 20 07:32:34.190658 2026] [security2:error] [pid 156215:tid 156401] [client 78.40.198.142:34742] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jcsJ0fwhpxOKR8Ygq4AAAADg"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:32:35.309479 2026] [security2:error] [pid 156215:tid 156313] [remote 5.161.225.162:42788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jc8J0fwhpxOKR8YgrPgAANmE"]
[Mon Jul 20 07:32:35.323841 2026] [security2:error] [pid 156215:tid 156464] [client 223.237.128.244:52781] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "ironcitywellness.com"] [uri "/xmlrpc.php"] [unique_id "al4jc8J0fwhpxOKR8YgrOAAAAHc"]
[Mon Jul 20 07:32:35.363806 2026] [security2:error] [pid 156215:tid 156401] [client 78.40.198.142:34742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jcsJ0fwhpxOKR8Ygq4AAAADg"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:32:35.363866 2026] [security2:error] [pid 156215:tid 156401] [client 78.40.198.142:34742] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jcsJ0fwhpxOKR8Ygq4AAAADg"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:32:35.454431 2026] [security2:error] [pid 156215:tid 156259] [remote 47.128.99.3:20148] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adambergeron.com"] [uri "/aposta-jogos-brasileirao-2024-01-18-id-2553.pdf"] [unique_id "al4jc8J0fwhpxOKR8YgrUQAAJis"]
[Mon Jul 20 07:32:35.503824 2026] [security2:error] [pid 156215:tid 156244] [remote 5.161.225.162:42788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jc8J0fwhpxOKR8YgrVgAAAhw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:32:35.528884 2026] [security2:error] [pid 156215:tid 156461] [client 14.225.17.146:64524] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4jc8J0fwhpxOKR8YgrRwAAAHQ"], referer: http://ksands.co.uk/TEST
[Mon Jul 20 07:32:35.608905 2026] [security2:error] [pid 156215:tid 156379] [client 104.234.53.72:37479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jc8J0fwhpxOKR8YgrYgAAACI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:35.977729 2026] [security2:error] [pid 156215:tid 156361] [client 185.102.119.229:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4jccJ0fwhpxOKR8Ygq1AAAABA"]
[Mon Jul 20 07:32:36.225157 2026] [security2:error] [pid 156215:tid 156368] [client 50.116.65.227:47482] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4jdMJ0fwhpxOKR8YgrlgAAABc"]
[Mon Jul 20 07:32:36.235907 2026] [security2:error] [pid 156215:tid 156431] [client 50.116.65.227:35832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4jdMJ0fwhpxOKR8YgrlwAAAEE"]
[Mon Jul 20 07:32:36.732565 2026] [security2:error] [pid 156215:tid 156432] [client 143.44.185.218:31337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jdMJ0fwhpxOKR8YgrwgAAAFc"]
[Mon Jul 20 07:32:36.732740 2026] [security2:error] [pid 156215:tid 156432] [client 143.44.185.218:31337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jdMJ0fwhpxOKR8YgrwgAAAFc"]
[Mon Jul 20 07:32:36.768737 2026] [security2:error] [pid 156215:tid 156303] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jdMJ0fwhpxOKR8YgrxAAAJVc"]
[Mon Jul 20 07:32:36.768958 2026] [security2:error] [pid 156215:tid 156382] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jdMJ0fwhpxOKR8YgrxAAAJVc"]
[Mon Jul 20 07:32:36.883918 2026] [security2:error] [pid 156215:tid 156434] [client 57.141.18.12:24182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jc8J0fwhpxOKR8YgrMwAAWS0"]
[Mon Jul 20 07:32:37.133457 2026] [security2:error] [pid 156215:tid 156421] [client 193.36.225.94:61603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4jdcJ0fwhpxOKR8Ygr3gAAAEw"]
[Mon Jul 20 07:32:37.141620 2026] [security2:error] [pid 156215:tid 156410] [client 136.144.33.205:58085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4jdcJ0fwhpxOKR8Ygr3wAAAEE"]
[Mon Jul 20 07:32:37.715474 2026] [security2:error] [pid 156215:tid 156401] [client 52.59.238.198:22738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jdcJ0fwhpxOKR8YgsDwAAADg"]
[Mon Jul 20 07:32:37.715565 2026] [security2:error] [pid 156215:tid 156401] [client 52.59.238.198:22738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jdcJ0fwhpxOKR8YgsDwAAADg"]
[Mon Jul 20 07:32:37.874433 2026] [security2:error] [pid 156215:tid 156325] [remote 152.228.213.32:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jdcJ0fwhpxOKR8YgsGAAABm0"]
[Mon Jul 20 07:32:37.931238 2026] [security2:error] [pid 156215:tid 156432] [client 144.16.21.149:28166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jdcJ0fwhpxOKR8YgsGgAAAFc"]
[Mon Jul 20 07:32:37.931659 2026] [security2:error] [pid 156215:tid 156432] [client 144.16.21.149:28166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jdcJ0fwhpxOKR8YgsGgAAAFc"]
[Mon Jul 20 07:32:38.027352 2026] [security2:error] [pid 156215:tid 156371] [client 14.225.17.146:49675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4jdMJ0fwhpxOKR8YgrqwAAABo"], referer: http://careysheatingandcooling.com/TEST
[Mon Jul 20 07:32:38.058740 2026] [security2:error] [pid 156215:tid 156312] [remote 152.228.213.32:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsKQAAHGA"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 07:32:38.159040 2026] [security2:error] [pid 156215:tid 156395] [client 149.0.16.108:49626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsMAAAADI"]
[Mon Jul 20 07:32:38.159165 2026] [security2:error] [pid 156215:tid 156395] [client 149.0.16.108:49626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsMAAAADI"]
[Mon Jul 20 07:32:38.304839 2026] [security2:error] [pid 156215:tid 156359] [client 49.37.242.14:51967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsPQAAAA4"]
[Mon Jul 20 07:32:38.304974 2026] [security2:error] [pid 156215:tid 156359] [client 49.37.242.14:51967] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsPQAAAA4"]
[Mon Jul 20 07:32:38.310962 2026] [proxy:error] [pid 156215:tid 156354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:32:38.311024 2026] [proxy_http:error] [pid 156215:tid 156354] [client 205.210.31.135:62106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:32:38.311446 2026] [proxy:error] [pid 156215:tid 156354] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:32:38.311471 2026] [proxy_http:error] [pid 156215:tid 156354] [client 205.210.31.135:62106] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:32:38.761402 2026] [security2:error] [pid 156215:tid 156444] [client 142.111.152.65:52859] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsVAAAAGM"]
[Mon Jul 20 07:32:39.144629 2026] [security2:error] [pid 156215:tid 156350] [client 104.234.53.88:26051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jd8J0fwhpxOKR8YgsfwAAAAU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:39.547074 2026] [security2:error] [pid 156215:tid 156380] [client 136.158.60.21:22728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jd8J0fwhpxOKR8YgsmgAAACM"]
[Mon Jul 20 07:32:39.547182 2026] [security2:error] [pid 156215:tid 156380] [client 136.158.60.21:22728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jd8J0fwhpxOKR8YgsmgAAACM"]
[Mon Jul 20 07:32:39.578593 2026] [security2:error] [pid 156215:tid 156397] [client 157.20.138.62:61882] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jd8J0fwhpxOKR8YgsnQAAADQ"]
[Mon Jul 20 07:32:39.578670 2026] [security2:error] [pid 156215:tid 156397] [client 157.20.138.62:61882] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jd8J0fwhpxOKR8YgsnQAAADQ"]
[Mon Jul 20 07:32:39.594037 2026] [security2:error] [pid 156215:tid 156414] [client 103.139.191.61:61375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jd8J0fwhpxOKR8YgsoAAAAEU"]
[Mon Jul 20 07:32:39.594142 2026] [security2:error] [pid 156215:tid 156414] [client 103.139.191.61:61375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jd8J0fwhpxOKR8YgsoAAAAEU"]
[Mon Jul 20 07:32:39.773387 2026] [security2:error] [pid 156215:tid 156464] [client 14.225.17.146:54598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgsqgAAAHc"], referer: http://keywayconstructionclt.com/TEST
[Mon Jul 20 07:32:39.792589 2026] [security2:error] [pid 156215:tid 156439] [client 57.141.18.69:49978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jdcJ0fwhpxOKR8YgsFwAAXgE"]
[Mon Jul 20 07:32:39.977701 2026] [security2:error] [pid 156215:tid 156384] [client 57.141.18.28:46222] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsKgAAJ24"]
[Mon Jul 20 07:32:40.211861 2026] [security2:error] [pid 156215:tid 156453] [client 49.47.218.174:60062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jeMJ0fwhpxOKR8Ygs1wAAAGw"]
[Mon Jul 20 07:32:40.211987 2026] [security2:error] [pid 156215:tid 156453] [client 49.47.218.174:60062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jeMJ0fwhpxOKR8Ygs1wAAAGw"]
[Mon Jul 20 07:32:40.310655 2026] [security2:error] [pid 156215:tid 156388] [client 57.141.18.106:36362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jdsJ0fwhpxOKR8YgsQgAAKy4"]
[Mon Jul 20 07:32:40.953635 2026] [security2:error] [pid 156215:tid 156429] [client 57.141.18.69:49988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgsfAAAVBk"]
[Mon Jul 20 07:32:41.100806 2026] [security2:error] [pid 156215:tid 156432] [client 191.202.66.27:57696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtGQAAAFc"]
[Mon Jul 20 07:32:41.100908 2026] [security2:error] [pid 156215:tid 156432] [client 191.202.66.27:57696] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtGQAAAFc"]
[Mon Jul 20 07:32:41.196960 2026] [security2:error] [pid 156215:tid 156404] [client 88.241.67.160:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtHgAAADs"]
[Mon Jul 20 07:32:41.197070 2026] [security2:error] [pid 156215:tid 156404] [client 88.241.67.160:55486] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtHgAAADs"]
[Mon Jul 20 07:32:41.283860 2026] [security2:error] [pid 156215:tid 156298] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtKgAANFI"]
[Mon Jul 20 07:32:41.284007 2026] [security2:error] [pid 156215:tid 156397] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtKgAANFI"]
[Mon Jul 20 07:32:41.431846 2026] [security2:error] [pid 156215:tid 156355] [client 57.141.18.20:53492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgspAAACkw"]
[Mon Jul 20 07:32:41.459450 2026] [security2:error] [pid 156215:tid 156460] [client 179.127.84.238:60028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtNgAAAHM"]
[Mon Jul 20 07:32:41.459594 2026] [security2:error] [pid 156215:tid 156460] [client 179.127.84.238:60028] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtNgAAAHM"]
[Mon Jul 20 07:32:41.528202 2026] [security2:error] [pid 156215:tid 156328] [remote 192.241.143.148:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jecJ0fwhpxOKR8YgtPQAADnA"]
[Mon Jul 20 07:32:41.559021 2026] [security2:error] [pid 156215:tid 156360] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bnb-engineering.com"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgsrwAAAA8"]
[Mon Jul 20 07:32:41.572576 2026] [security2:error] [pid 156215:tid 156471] [client 57.141.18.7:20708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgspQAAflY"]
[Mon Jul 20 07:32:41.614377 2026] [security2:error] [pid 156215:tid 156394] [client 14.225.17.146:54384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgssAAAADE"], referer: http://narv.co/TEST
[Mon Jul 20 07:32:41.617353 2026] [security2:error] [pid 156215:tid 156399] [client 14.225.17.146:54327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4jecJ0fwhpxOKR8YgtMQAAADY"], referer: http://recruitinginsight.us/TEST
[Mon Jul 20 07:32:41.673293 2026] [security2:error] [pid 156215:tid 156398] [client 154.192.123.127:17285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtTgAAADU"]
[Mon Jul 20 07:32:41.673395 2026] [security2:error] [pid 156215:tid 156398] [client 154.192.123.127:17285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtTgAAADU"]
[Mon Jul 20 07:32:41.685330 2026] [security2:error] [pid 156215:tid 156408] [client 57.141.18.12:24198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jd8J0fwhpxOKR8YgsuQAAPyc"]
[Mon Jul 20 07:32:41.748368 2026] [security2:error] [pid 156215:tid 156287] [remote 192.241.143.148:39270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jecJ0fwhpxOKR8YgtUgAAIkc"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:32:41.968678 2026] [security2:error] [pid 156215:tid 156389] [client 36.93.152.155:55227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtZQAAACw"]
[Mon Jul 20 07:32:41.968803 2026] [security2:error] [pid 156215:tid 156389] [client 36.93.152.155:55227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jecJ0fwhpxOKR8YgtZQAAACw"]
[Mon Jul 20 07:32:42.009415 2026] [security2:error] [pid 156215:tid 156429] [client 14.225.17.146:51178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4jecJ0fwhpxOKR8YgtWgAAAFQ"], referer: http://laceycaraccident.com/TEST
[Mon Jul 20 07:32:42.017270 2026] [security2:error] [pid 156215:tid 156461] [client 57.141.18.44:48296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jeMJ0fwhpxOKR8Ygs1QAAdAk"]
[Mon Jul 20 07:32:42.197968 2026] [security2:error] [pid 156215:tid 156237] [remote 8.217.108.67:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4jesJ0fwhpxOKR8YgtcwAAFRU"]
[Mon Jul 20 07:32:42.644372 2026] [security2:error] [pid 156215:tid 156378] [client 14.225.17.146:64455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4jesJ0fwhpxOKR8YgtjAAAACE"], referer: https://narv.co/TEST
[Mon Jul 20 07:32:42.659482 2026] [security2:error] [pid 156215:tid 156388] [client 47.129.222.11:34402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jesJ0fwhpxOKR8YgtnwAAACs"]
[Mon Jul 20 07:32:42.659601 2026] [security2:error] [pid 156215:tid 156388] [client 47.129.222.11:34402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jesJ0fwhpxOKR8YgtnwAAACs"]
[Mon Jul 20 07:32:42.907592 2026] [security2:error] [pid 156215:tid 156223] [remote 188.166.241.141:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jesJ0fwhpxOKR8YgttwAAdwc"]
[Mon Jul 20 07:32:42.910539 2026] [security2:error] [pid 156215:tid 156381] [client 14.225.17.146:54327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4jesJ0fwhpxOKR8YgtpgAAACQ"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/TEST
[Mon Jul 20 07:32:43.241686 2026] [security2:error] [pid 156215:tid 156411] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4jesJ0fwhpxOKR8YgtsAAAAEI"], referer: https://partnerselectricalllc.com/
[Mon Jul 20 07:32:43.241833 2026] [security2:error] [pid 156215:tid 156384] [client 103.106.165.44:61047] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4je8J0fwhpxOKR8Ygt0QAAACc"]
[Mon Jul 20 07:32:43.241959 2026] [security2:error] [pid 156215:tid 156384] [client 103.106.165.44:61047] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4je8J0fwhpxOKR8Ygt0QAAACc"]
[Mon Jul 20 07:32:43.256854 2026] [security2:error] [pid 156215:tid 156232] [remote 8.217.108.67:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/wp-login.php"] [unique_id "al4je8J0fwhpxOKR8Ygt0wAAORA"], referer: https://mtredistricting.gov/wp-login.php
[Mon Jul 20 07:32:43.333603 2026] [security2:error] [pid 156215:tid 156259] [remote 188.166.241.141:56870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4je8J0fwhpxOKR8Ygt2QAACSs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:32:43.334788 2026] [security2:error] [pid 156215:tid 156351] [client 117.211.236.168:56577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4je8J0fwhpxOKR8Ygt2gAAAAY"]
[Mon Jul 20 07:32:43.334886 2026] [security2:error] [pid 156215:tid 156351] [client 117.211.236.168:56577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4je8J0fwhpxOKR8Ygt2gAAAAY"]
[Mon Jul 20 07:32:43.635699 2026] [security2:error] [pid 156215:tid 156355] [client 57.141.18.21:55426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jecJ0fwhpxOKR8YgtYgAACm0"]
[Mon Jul 20 07:32:43.637788 2026] [security2:error] [pid 156215:tid 156374] [client 104.234.53.50:60981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4je8J0fwhpxOKR8Ygt_AAAAB0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:44.120380 2026] [security2:error] [pid 156215:tid 156389] [client 57.141.18.40:27390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jesJ0fwhpxOKR8YgtlAAALHI"]
[Mon Jul 20 07:32:44.230601 2026] [security2:error] [pid 156215:tid 156236] [remote 162.19.86.63:45682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jfMJ0fwhpxOKR8YguKQAABxQ"]
[Mon Jul 20 07:32:44.248990 2026] [security2:error] [pid 156215:tid 156388] [client 103.176.215.66:65016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jfMJ0fwhpxOKR8YguKgAAACs"]
[Mon Jul 20 07:32:44.249167 2026] [security2:error] [pid 156215:tid 156388] [client 103.176.215.66:65016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jfMJ0fwhpxOKR8YguKgAAACs"]
[Mon Jul 20 07:32:44.329292 2026] [security2:error] [pid 156215:tid 156449] [client 14.225.17.146:56209] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4jfMJ0fwhpxOKR8YguIgAAAGg"], referer: http://www.justinagrayman.com/TEST
[Mon Jul 20 07:32:44.347388 2026] [security2:error] [pid 156215:tid 156400] [client 74.7.227.179:43058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4jfMJ0fwhpxOKR8YguJQAAN3w"], referer: https://tejasenvironmental.com/p=339144
[Mon Jul 20 07:32:44.375002 2026] [security2:error] [pid 156215:tid 156406] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4je8J0fwhpxOKR8YguCgAAPUE"], referer: http://assasalnazaha.com/TEST
[Mon Jul 20 07:32:44.452252 2026] [security2:error] [pid 156215:tid 156295] [remote 162.19.86.63:45682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jfMJ0fwhpxOKR8YguPwAARE8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:32:44.602454 2026] [autoindex:error] [pid 156215:tid 156238] [remote 8.229.41.77:65024] AH01276: Cannot serve directory /home2/tsbjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.tsb.jiv.mybluehost.me
[Mon Jul 20 07:32:44.678024 2026] [autoindex:error] [pid 156215:tid 156301] [remote 34.48.84.195:54778] AH01276: Cannot serve directory /home2/cxrmhtmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.cxr.mht.mybluehost.me
[Mon Jul 20 07:32:44.740070 2026] [fcgid:warn] [pid 156215:tid 156435] (70014)End of file found: [client 91.231.89.40:58659] mod_fcgid: can't get data from http client
[Mon Jul 20 07:32:45.158957 2026] [security2:error] [pid 156215:tid 156422] [client 104.234.53.76:62459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jfcJ0fwhpxOKR8YgueQAAAE0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:45.165941 2026] [security2:error] [pid 156215:tid 156360] [client 57.141.18.27:49412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4je8J0fwhpxOKR8Ygt1gAAD2E"]
[Mon Jul 20 07:32:45.205165 2026] [security2:error] [pid 156215:tid 156442] [client 57.141.18.124:39748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4je8J0fwhpxOKR8Ygt3wAAYRI"]
[Mon Jul 20 07:32:45.407651 2026] [autoindex:error] [pid 156215:tid 156427] [client 43.130.78.203:0] AH01276: Cannot serve directory /home1/acaiandc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://acaiandcitystreets.com
[Mon Jul 20 07:32:46.003388 2026] [security2:error] [pid 156215:tid 156423] [client 57.141.18.110:58656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jfMJ0fwhpxOKR8YguIwAATnQ"]
[Mon Jul 20 07:32:46.214645 2026] [security2:error] [pid 156215:tid 156418] [client 14.225.17.146:56631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4jfsJ0fwhpxOKR8YguxAAAAEk"], referer: http://betterbonddogtraining.com/TEST
[Mon Jul 20 07:32:46.356028 2026] [security2:error] [pid 156215:tid 156394] [client 66.249.65.202:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4jfcJ0fwhpxOKR8YguugAAADE"], referer: https://partnerselectricalllc.com/
[Mon Jul 20 07:32:46.649398 2026] [security2:error] [pid 156215:tid 156407] [client 14.225.17.146:56601] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4jfsJ0fwhpxOKR8Ygu7AAAAD4"], referer: http://nextlvlmarketingco.com/TEST
[Mon Jul 20 07:32:46.700028 2026] [security2:error] [pid 156215:tid 156242] [remote 103.118.29.185:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4jfsJ0fwhpxOKR8Ygu9wAARxo"]
[Mon Jul 20 07:32:46.926362 2026] [security2:error] [pid 156215:tid 156366] [client 57.141.18.2:53752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jfcJ0fwhpxOKR8YgufgAAFXY"]
[Mon Jul 20 07:32:47.091655 2026] [security2:error] [pid 156215:tid 156321] [remote 103.118.29.185:56168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4jf8J0fwhpxOKR8YgvFgAAPGk"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:32:47.391168 2026] [security2:error] [pid 156215:tid 156361] [client 104.234.53.61:52065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvLQAAABA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:47.545578 2026] [security2:error] [pid 156215:tid 156451] [client 43.157.96.189:41822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "maxenengineering.com"] [uri "/"] [unique_id "al4jf8J0fwhpxOKR8YgvNQAAAGo"]
[Mon Jul 20 07:32:47.553937 2026] [security2:error] [pid 156215:tid 156326] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jf8J0fwhpxOKR8YgvNwAAbm4"]
[Mon Jul 20 07:32:47.554054 2026] [security2:error] [pid 156215:tid 156455] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jf8J0fwhpxOKR8YgvNwAAbm4"]
[Mon Jul 20 07:32:47.612810 2026] [security2:error] [pid 156215:tid 156354] [client 14.225.17.146:56703] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvEgAAAAk"], referer: http://idigress.agency/TEST
[Mon Jul 20 07:32:47.721705 2026] [security2:error] [pid 156215:tid 156421] [client 216.73.217.93:40449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvQgAATE4"]
[Mon Jul 20 07:32:47.756877 2026] [security2:error] [pid 156215:tid 156379] [client 45.3.55.168:26419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jf8J0fwhpxOKR8YgvRgAAACI"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:48.010273 2026] [security2:error] [pid 156215:tid 156240] [remote 20.153.140.50:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jf8J0fwhpxOKR8YgvVQAAPRg"]
[Mon Jul 20 07:32:48.025337 2026] [security2:error] [pid 156215:tid 156444] [client 43.205.139.3:26120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvWAAAAGM"]
[Mon Jul 20 07:32:48.258227 2026] [security2:error] [pid 156215:tid 156471] [client 63.179.149.246:57112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvaAAAAH4"]
[Mon Jul 20 07:32:48.258329 2026] [security2:error] [pid 156215:tid 156471] [client 63.179.149.246:57112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvaAAAAH4"]
[Mon Jul 20 07:32:48.383011 2026] [security2:error] [pid 156215:tid 156428] [client 65.111.27.141:52037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvbgAAAFM"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:32:48.406834 2026] [security2:error] [pid 156215:tid 156256] [remote 20.153.140.50:57850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvcQAAcyg"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 07:32:48.536733 2026] [security2:error] [pid 156215:tid 156380] [client 144.16.21.149:25129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvfQAAACM"]
[Mon Jul 20 07:32:48.536834 2026] [security2:error] [pid 156215:tid 156380] [client 144.16.21.149:25129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvfQAAACM"]
[Mon Jul 20 07:32:48.558583 2026] [security2:error] [pid 156215:tid 156301] [remote 132.148.72.88:53182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvfwAAclU"]
[Mon Jul 20 07:32:48.603351 2026] [security2:error] [pid 156215:tid 156393] [client 14.225.17.146:57088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4jfsJ0fwhpxOKR8YgvAgAAADA"], referer: http://areitoproducciones.com/TEST
[Mon Jul 20 07:32:48.623391 2026] [security2:error] [pid 156215:tid 156352] [client 143.44.185.218:32586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvgQAAAAc"]
[Mon Jul 20 07:32:48.624673 2026] [security2:error] [pid 156215:tid 156352] [client 143.44.185.218:32586] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvgQAAAAc"]
[Mon Jul 20 07:32:48.675152 2026] [security2:error] [pid 156215:tid 156391] [client 57.141.18.10:32310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvDgAALj8"]
[Mon Jul 20 07:32:48.759973 2026] [security2:error] [pid 156215:tid 156397] [client 149.0.16.108:50846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvlAAAADQ"]
[Mon Jul 20 07:32:48.760080 2026] [security2:error] [pid 156215:tid 156397] [client 149.0.16.108:50846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvlAAAADQ"]
[Mon Jul 20 07:32:48.776979 2026] [security2:error] [pid 156215:tid 156292] [remote 132.148.72.88:53182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zlp.omk.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvlQAAeEw"], referer: https://zlp.omk.mybluehost.me/wp-login.php
[Mon Jul 20 07:32:48.797282 2026] [security2:error] [pid 156215:tid 156445] [client 152.42.246.10:54700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.246.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dereckcastellon.com"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvkQAAAGQ"]
[Mon Jul 20 07:32:48.953739 2026] [security2:error] [pid 156215:tid 156408] [client 104.28.163.16:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "premiumoverhead.com"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvoQAAAD8"]
[Mon Jul 20 07:32:48.960042 2026] [security2:error] [pid 156215:tid 156466] [client 13.232.231.177:51398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvogAAAHk"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:32:49.430112 2026] [autoindex:error] [pid 156215:tid 156418] [client 23.180.120.145:33186] AH01276: Cannot serve directory /home3/alaraycr/public_html/allisonrodrigue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:32:49.472402 2026] [security2:error] [pid 156215:tid 156403] [client 155.2.215.76:49785] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jgcJ0fwhpxOKR8YgvvwAAADo"]
[Mon Jul 20 07:32:49.506010 2026] [security2:error] [pid 156215:tid 156225] [remote 188.40.28.4:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jgcJ0fwhpxOKR8Ygv0QAAYQk"]
[Mon Jul 20 07:32:49.533773 2026] [security2:error] [pid 156215:tid 156383] [client 57.141.18.49:44900] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvSQAAJiE"]
[Mon Jul 20 07:32:49.543096 2026] [security2:error] [pid 156215:tid 156399] [client 57.141.18.4:46508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvSAAANmw"]
[Mon Jul 20 07:32:49.637489 2026] [security2:error] [pid 156215:tid 156434] [client 57.141.18.123:28640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jf8J0fwhpxOKR8YgvUwAAWS4"]
[Mon Jul 20 07:32:49.683854 2026] [security2:error] [pid 156215:tid 156372] [client 13.233.207.33:49740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jgcJ0fwhpxOKR8Ygv3wAAABs"]
[Mon Jul 20 07:32:49.683979 2026] [security2:error] [pid 156215:tid 156372] [client 13.233.207.33:49740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jgcJ0fwhpxOKR8Ygv3wAAABs"]
[Mon Jul 20 07:32:49.720401 2026] [security2:error] [pid 156215:tid 156287] [remote 188.40.28.4:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jgcJ0fwhpxOKR8Ygv4QAAaUc"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:32:50.095589 2026] [security2:error] [pid 156215:tid 156432] [client 66.249.73.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.nicherealestate.co"] [uri "/index.php"] [unique_id "al4jgcJ0fwhpxOKR8YgvtAAAAFc"]
[Mon Jul 20 07:32:50.150937 2026] [security2:error] [pid 156215:tid 156366] [client 187.74.118.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvjwAAABU"]
[Mon Jul 20 07:32:50.167567 2026] [security2:error] [pid 156215:tid 156404] [client 157.20.138.62:62556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwAgAAADs"]
[Mon Jul 20 07:32:50.167653 2026] [security2:error] [pid 156215:tid 156404] [client 157.20.138.62:62556] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwAgAAADs"]
[Mon Jul 20 07:32:50.251287 2026] [security2:error] [pid 156215:tid 156423] [client 136.158.60.21:24400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwCAAAAE4"]
[Mon Jul 20 07:32:50.251445 2026] [security2:error] [pid 156215:tid 156423] [client 136.158.60.21:24400] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwCAAAAE4"]
[Mon Jul 20 07:32:50.253837 2026] [security2:error] [pid 156215:tid 156373] [client 98.159.234.160:45943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwCgAAABw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:32:50.284261 2026] [security2:error] [pid 156215:tid 156403] [client 104.234.53.47:61365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwEAAAADo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:50.305589 2026] [security2:error] [pid 156215:tid 156349] [client 14.225.17.146:57018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4jgMJ0fwhpxOKR8YgvmwAAAAQ"], referer: http://reosportsboats.com/TEST
[Mon Jul 20 07:32:50.452441 2026] [security2:error] [pid 156215:tid 156400] [client 49.37.242.14:52478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwGgAAADc"]
[Mon Jul 20 07:32:50.452573 2026] [security2:error] [pid 156215:tid 156400] [client 49.37.242.14:52478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwGgAAADc"]
[Mon Jul 20 07:32:50.601026 2026] [security2:error] [pid 156215:tid 156411] [client 103.139.191.61:61849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwJwAAAEI"]
[Mon Jul 20 07:32:50.602056 2026] [security2:error] [pid 156215:tid 156411] [client 103.139.191.61:61849] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwJwAAAEI"]
[Mon Jul 20 07:32:50.730899 2026] [security2:error] [pid 156215:tid 156438] [client 49.47.218.174:60608] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwMgAAAF0"]
[Mon Jul 20 07:32:50.731037 2026] [security2:error] [pid 156215:tid 156438] [client 49.47.218.174:60608] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwMgAAAF0"]
[Mon Jul 20 07:32:50.987567 2026] [security2:error] [pid 156215:tid 156388] [client 14.225.17.146:55926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwAwAAACs"]
[Mon Jul 20 07:32:51.035317 2026] [security2:error] [pid 156215:tid 156389] [client 104.28.163.16:51190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtaginv.com"] [uri "/wp-login.php"] [unique_id "al4jg8J0fwhpxOKR8YgwSwAAACw"]
[Mon Jul 20 07:32:51.051730 2026] [security2:error] [pid 156215:tid 156428] [client 57.141.18.21:55232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jgcJ0fwhpxOKR8YgvvAAAU1c"]
[Mon Jul 20 07:32:51.082595 2026] [security2:error] [pid 156215:tid 156362] [client 69.165.75.221:61408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.75.165.69.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "boldcoastmedia.onewingpictures.com"] [uri "/index.php"] [unique_id "al4jg8J0fwhpxOKR8YgwVQAAABE"], referer: https://boldcoastmedia.onewingpictures.com
[Mon Jul 20 07:32:51.189243 2026] [security2:error] [pid 156215:tid 156426] [client 14.225.17.146:56857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4jgcJ0fwhpxOKR8Ygv3QAAAFE"], referer: http://olearyplumbingllc.com/TEST
[Mon Jul 20 07:32:51.230878 2026] [security2:error] [pid 156215:tid 156361] [client 14.225.17.146:55718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4jg8J0fwhpxOKR8YgwWQAAABA"], referer: https://reosportsboats.com/TEST
[Mon Jul 20 07:32:51.256225 2026] [security2:error] [pid 156215:tid 156359] [client 57.141.18.125:48024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jgcJ0fwhpxOKR8YgvzAAADjs"]
[Mon Jul 20 07:32:51.298024 2026] [security2:error] [pid 156215:tid 156356] [client 66.249.74.131:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.rywventures.com"] [uri "/index.php"] [unique_id "al4jgcJ0fwhpxOKR8Ygv3AAAAAs"]
[Mon Jul 20 07:32:51.779712 2026] [security2:error] [pid 156215:tid 156461] [client 191.202.66.27:58189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jg8J0fwhpxOKR8YgwkAAAAHQ"]
[Mon Jul 20 07:32:51.779731 2026] [autoindex:error] [pid 156215:tid 156435] [client 136.114.198.221:0] AH01276: Cannot serve directory /home2/bluestm2/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.bluestemconstructionllc.com
[Mon Jul 20 07:32:51.779853 2026] [security2:error] [pid 156215:tid 156461] [client 191.202.66.27:58189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jg8J0fwhpxOKR8YgwkAAAAHQ"]
[Mon Jul 20 07:32:51.849800 2026] [security2:error] [pid 156215:tid 156224] [remote 5.252.52.249:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4jg8J0fwhpxOKR8YgwlgAADAg"]
[Mon Jul 20 07:32:51.872193 2026] [security2:error] [pid 156215:tid 156444] [client 88.241.67.160:53707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.67.241.88.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jg8J0fwhpxOKR8YgwmQAAAGM"]
[Mon Jul 20 07:32:51.872316 2026] [security2:error] [pid 156215:tid 156444] [client 88.241.67.160:53707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jg8J0fwhpxOKR8YgwmQAAAGM"]
[Mon Jul 20 07:32:51.884829 2026] [security2:error] [pid 156215:tid 156398] [client 57.141.18.53:36066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwCQAANUk"]
[Mon Jul 20 07:32:51.927874 2026] [security2:error] [pid 156215:tid 156467] [client 57.141.18.24:49250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwFwAAeio"]
[Mon Jul 20 07:32:51.940272 2026] [security2:error] [pid 156215:tid 156330] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jg8J0fwhpxOKR8YgwnQAAfHI"]
[Mon Jul 20 07:32:51.940429 2026] [security2:error] [pid 156215:tid 156469] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jg8J0fwhpxOKR8YgwnQAAfHI"]
[Mon Jul 20 07:32:52.080553 2026] [security2:error] [pid 156215:tid 156379] [client 179.127.84.238:60570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwrgAAACI"]
[Mon Jul 20 07:32:52.080661 2026] [security2:error] [pid 156215:tid 156379] [client 179.127.84.238:60570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwrgAAACI"]
[Mon Jul 20 07:32:52.149806 2026] [security2:error] [pid 156215:tid 156281] [remote 5.252.52.249:43758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarakety.com"] [uri "/wp-login.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwsQAARkE"], referer: https://sarakety.com/wp-login.php
[Mon Jul 20 07:32:52.204054 2026] [security2:error] [pid 156215:tid 156377] [client 154.192.123.127:17666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwsgAAACA"]
[Mon Jul 20 07:32:52.204147 2026] [security2:error] [pid 156215:tid 156377] [client 154.192.123.127:17666] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwsgAAACA"]
[Mon Jul 20 07:32:52.222839 2026] [security2:error] [pid 156215:tid 156399] [client 57.141.18.7:61618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jgsJ0fwhpxOKR8YgwLQAANho"]
[Mon Jul 20 07:32:52.541067 2026] [security2:error] [pid 156215:tid 156426] [client 36.93.152.155:55747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwxwAAAFE"]
[Mon Jul 20 07:32:52.541170 2026] [security2:error] [pid 156215:tid 156426] [client 36.93.152.155:55747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwxwAAAFE"]
[Mon Jul 20 07:32:52.559995 2026] [security2:error] [pid 156215:tid 156375] [client 45.157.112.60:33589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwyQAAAB4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:32:52.801810 2026] [security2:error] [pid 156215:tid 156421] [client 14.225.17.146:57499] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4jg8J0fwhpxOKR8YgwWAAAAEw"], referer: http://according2plant.com/TEST
[Mon Jul 20 07:32:52.873804 2026] [security2:error] [pid 156215:tid 156397] [client 54.184.226.94:60907] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/"] [unique_id "al4jhMJ0fwhpxOKR8Ygw5AAAADQ"]
[Mon Jul 20 07:32:53.499586 2026] [security2:error] [pid 156215:tid 156449] [client 54.184.226.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4jhcJ0fwhpxOKR8Ygw8wAAAGg"], referer: http://koaconsultants.com/?rnd=1784554372724
[Mon Jul 20 07:32:53.502159 2026] [security2:error] [pid 156215:tid 156432] [client 54.184.226.94:1174] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "koaconsultants.com"] [uri "/"] [unique_id "al4jhcJ0fwhpxOKR8Ygw7wAAAFc"], referer: http://koaconsultants.com/?rnd=1784554372724
[Mon Jul 20 07:32:53.616267 2026] [security2:error] [pid 156215:tid 156451] [client 57.141.18.88:46844] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwpQAAamg"]
[Mon Jul 20 07:32:53.876715 2026] [security2:error] [pid 156215:tid 156465] [client 103.106.165.44:61538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxLAAAAHg"]
[Mon Jul 20 07:32:53.876834 2026] [security2:error] [pid 156215:tid 156465] [client 103.106.165.44:61538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxLAAAAHg"]
[Mon Jul 20 07:32:53.970583 2026] [security2:error] [pid 156215:tid 156406] [client 117.211.236.168:57082] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxNAAAAD0"]
[Mon Jul 20 07:32:53.970674 2026] [security2:error] [pid 156215:tid 156406] [client 117.211.236.168:57082] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxNAAAAD0"]
[Mon Jul 20 07:32:54.017399 2026] [security2:error] [pid 156215:tid 156435] [client 57.141.18.123:33494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jhMJ0fwhpxOKR8YgwwgAAWmI"]
[Mon Jul 20 07:32:54.353079 2026] [security2:error] [pid 156215:tid 156444] [client 104.234.53.89:54743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4jhsJ0fwhpxOKR8YgxXAAAAGM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:54.593713 2026] [security2:error] [pid 156215:tid 156458] [client 121.229.156.20:46860] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-saraljart-com/"] [unique_id "al4jhsJ0fwhpxOKR8YgxdQAAAHE"]
[Mon Jul 20 07:32:54.593871 2026] [security2:error] [pid 156215:tid 156458] [client 121.229.156.20:46860] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/press-release-sustaintheart-com-acquires-saraljart-com/"] [unique_id "al4jhsJ0fwhpxOKR8YgxdQAAAHE"]
[Mon Jul 20 07:32:54.610148 2026] [security2:error] [pid 156215:tid 156439] [client 57.141.18.113:64766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jhMJ0fwhpxOKR8Ygw7QAAXlo"]
[Mon Jul 20 07:32:54.646968 2026] [security2:error] [pid 156215:tid 156389] [client 177.53.130.28:64510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4jhsJ0fwhpxOKR8YgxbgAALEM"]
[Mon Jul 20 07:32:54.671285 2026] [security2:error] [pid 156215:tid 156443] [client 14.225.17.146:55719] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxHAAAAGI"], referer: http://katsklar.com/TEST
[Mon Jul 20 07:32:54.693439 2026] [security2:error] [pid 156215:tid 156461] [client 14.225.17.146:55511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4jhsJ0fwhpxOKR8YgxZgAAAHQ"], referer: http://margaretspeckogawa.com/TEST
[Mon Jul 20 07:32:54.883932 2026] [security2:error] [pid 156215:tid 156384] [client 103.176.215.66:49165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jhsJ0fwhpxOKR8YgxhwAAACc"]
[Mon Jul 20 07:32:54.884072 2026] [security2:error] [pid 156215:tid 156384] [client 103.176.215.66:49165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jhsJ0fwhpxOKR8YgxhwAAACc"]
[Mon Jul 20 07:32:55.009546 2026] [security2:error] [pid 156215:tid 156388] [client 57.141.18.67:41114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxCgAAKzE"]
[Mon Jul 20 07:32:55.185477 2026] [security2:error] [pid 156215:tid 156390] [client 14.225.17.146:55712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4jhcJ0fwhpxOKR8YgxFwAAAC0"], referer: http://nwcarvingacademy.com/TEST
[Mon Jul 20 07:32:55.318539 2026] [security2:error] [pid 156215:tid 156457] [client 103.168.67.159:63968] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "autodiscover.membresiabeyou.com"] [uri "/wp-config.php~"] [unique_id "al4jh8J0fwhpxOKR8YgxsQAAAHA"], referer: https://news.ycombinator.com/
[Mon Jul 20 07:32:56.128476 2026] [security2:error] [pid 156215:tid 156441] [client 74.208.214.194:37144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jiMJ0fwhpxOKR8Ygx8gAAAGA"]
[Mon Jul 20 07:32:56.233920 2026] [security2:error] [pid 156215:tid 156395] [client 216.24.212.78:49469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4jiMJ0fwhpxOKR8Ygx_AAAADI"]
[Mon Jul 20 07:32:56.249183 2026] [security2:error] [pid 156215:tid 156385] [client 216.24.212.50:51131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4jiMJ0fwhpxOKR8Ygx_QAAACg"]
[Mon Jul 20 07:32:56.280064 2026] [security2:error] [pid 156215:tid 156381] [client 14.225.17.146:55876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4jiMJ0fwhpxOKR8Ygx6wAAACQ"], referer: https://nwcarvingacademy.com/TEST
[Mon Jul 20 07:32:56.364405 2026] [security2:error] [pid 156215:tid 156281] [remote 97.74.93.24:45436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4jiMJ0fwhpxOKR8YgyBAAAcEE"]
[Mon Jul 20 07:32:56.373088 2026] [security2:error] [pid 156215:tid 156446] [client 14.225.17.146:55745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4jhsJ0fwhpxOKR8YgxgwAAAGU"], referer: http://lelandumc.org/TEST
[Mon Jul 20 07:32:56.726073 2026] [security2:error] [pid 156215:tid 156340] [remote 97.74.93.24:45436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-5ab144f7.uritems.net"] [uri "/wp-login.php"] [unique_id "al4jiMJ0fwhpxOKR8YgyGwAAaHw"], referer: https://website-5ab144f7.uritems.net/wp-login.php
[Mon Jul 20 07:32:56.966101 2026] [security2:error] [pid 156215:tid 156336] [remote 173.212.252.15:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jiMJ0fwhpxOKR8YgyMwAAcng"]
[Mon Jul 20 07:32:56.993877 2026] [security2:error] [pid 156215:tid 156393] [client 57.141.18.31:55694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jh8J0fwhpxOKR8YgxugAAMAE"]
[Mon Jul 20 07:32:57.014107 2026] [security2:error] [pid 156215:tid 156417] [client 57.141.18.77:64732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jh8J0fwhpxOKR8YgxuwAASG0"]
[Mon Jul 20 07:32:57.141489 2026] [security2:error] [pid 156215:tid 156282] [remote 173.212.252.15:60196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jicJ0fwhpxOKR8YgySwAAWkI"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:32:57.210323 2026] [security2:error] [pid 156215:tid 156255] [remote 162.19.86.63:37809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jicJ0fwhpxOKR8YgyUAAAByc"]
[Mon Jul 20 07:32:57.210460 2026] [security2:error] [pid 156215:tid 156352] [client 162.19.86.63:37809] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jicJ0fwhpxOKR8YgyUAAAByc"]
[Mon Jul 20 07:32:57.416985 2026] [security2:error] [pid 156215:tid 156406] [client 14.225.17.146:59111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4jicJ0fwhpxOKR8YgyUQAAAD0"], referer: http://sesamegreenbeans.com/TEST
[Mon Jul 20 07:32:57.576286 2026] [security2:error] [pid 156215:tid 156464] [client 57.141.18.57:48212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jiMJ0fwhpxOKR8Ygx5AAAd2o"]
[Mon Jul 20 07:32:57.967447 2026] [security2:error] [pid 156215:tid 156351] [client 14.225.17.146:58489] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4jiMJ0fwhpxOKR8YgyDAAAAAY"], referer: http://kromosenergy.com/TEST
[Mon Jul 20 07:32:58.111666 2026] [security2:error] [pid 156215:tid 156369] [client 104.234.53.63:20617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4jisJ0fwhpxOKR8YgykQAAABg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:32:58.436825 2026] [security2:error] [pid 156215:tid 156471] [client 14.225.17.146:55409] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4jisJ0fwhpxOKR8YgyogAAAH4"], referer: https://sesamegreenbeans.com/TEST
[Mon Jul 20 07:32:58.443724 2026] [security2:error] [pid 156215:tid 156307] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jisJ0fwhpxOKR8YgysAAAPls"]
[Mon Jul 20 07:32:58.443891 2026] [security2:error] [pid 156215:tid 156407] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jisJ0fwhpxOKR8YgysAAAPls"]
[Mon Jul 20 07:32:58.474960 2026] [security2:error] [pid 156215:tid 156405] [client 57.141.18.96:41646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jiMJ0fwhpxOKR8YgyLgAAPG8"]
[Mon Jul 20 07:32:58.590328 2026] [security2:error] [pid 156215:tid 156283] [remote 154.61.75.100:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4jisJ0fwhpxOKR8YgyuwAAOUM"]
[Mon Jul 20 07:32:58.735229 2026] [security2:error] [pid 156215:tid 156459] [client 63.177.52.239:53812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jisJ0fwhpxOKR8YgyxwAAAHI"]
[Mon Jul 20 07:32:58.735377 2026] [security2:error] [pid 156215:tid 156459] [client 63.177.52.239:53812] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jisJ0fwhpxOKR8YgyxwAAAHI"]
[Mon Jul 20 07:32:58.795285 2026] [security2:error] [pid 156215:tid 156433] [client 57.141.18.66:54196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jicJ0fwhpxOKR8YgyWwAAWFg"]
[Mon Jul 20 07:32:59.025594 2026] [security2:error] [pid 156215:tid 156299] [remote 160.187.68.132:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4ji8J0fwhpxOKR8Ygy3AAAKFM"]
[Mon Jul 20 07:32:59.101248 2026] [security2:error] [pid 156215:tid 156231] [remote 154.61.75.100:35388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4ji8J0fwhpxOKR8Ygy5QAAWQ8"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 07:32:59.366229 2026] [security2:error] [pid 156215:tid 156414] [client 144.16.21.149:24899] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ji8J0fwhpxOKR8Ygy9wAAAEU"]
[Mon Jul 20 07:32:59.366357 2026] [security2:error] [pid 156215:tid 156414] [client 144.16.21.149:24899] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ji8J0fwhpxOKR8Ygy9wAAAEU"]
[Mon Jul 20 07:32:59.394074 2026] [security2:error] [pid 156215:tid 156436] [client 149.0.16.108:51395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ji8J0fwhpxOKR8Ygy-gAAAFs"]
[Mon Jul 20 07:32:59.394226 2026] [security2:error] [pid 156215:tid 156436] [client 149.0.16.108:51395] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ji8J0fwhpxOKR8Ygy-gAAAFs"]
[Mon Jul 20 07:32:59.436786 2026] [security2:error] [pid 156215:tid 156428] [client 46.110.96.34:6718] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4ji8J0fwhpxOKR8Ygy_gAAAFM"]
[Mon Jul 20 07:32:59.436786 2026] [security2:error] [pid 156215:tid 156461] [client 46.110.96.34:54738] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4ji8J0fwhpxOKR8Ygy_QAAAHQ"]
[Mon Jul 20 07:32:59.525719 2026] [security2:error] [pid 156215:tid 156247] [remote 173.249.4.11:32089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ji8J0fwhpxOKR8YgzAAAARB8"]
[Mon Jul 20 07:32:59.537889 2026] [security2:error] [pid 156215:tid 156311] [remote 160.187.68.132:36812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sbinframx.com"] [uri "/wp-login.php"] [unique_id "al4ji8J0fwhpxOKR8YgzAgAASV8"], referer: https://sbinframx.com/wp-login.php
[Mon Jul 20 07:32:59.723981 2026] [security2:error] [pid 156215:tid 156442] [client 14.225.17.146:55560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4jisJ0fwhpxOKR8YgyngAAAGE"], referer: http://xp-design.co/TEST
[Mon Jul 20 07:32:59.807202 2026] [security2:error] [pid 156215:tid 156448] [client 57.141.18.48:30694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jisJ0fwhpxOKR8YgyqAAAZ2Q"]
[Mon Jul 20 07:33:00.004357 2026] [security2:error] [pid 156215:tid 156402] [client 155.2.215.80:62551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ji8J0fwhpxOKR8YgzGwAAADk"]
[Mon Jul 20 07:33:00.204128 2026] [security2:error] [pid 156215:tid 156458] [client 57.141.18.24:27196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jisJ0fwhpxOKR8YgyygAAcXA"]
[Mon Jul 20 07:33:00.342415 2026] [security2:error] [pid 156215:tid 156444] [client 57.141.18.42:20338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jisJ0fwhpxOKR8Ygy1gAAYzo"]
[Mon Jul 20 07:33:00.572238 2026] [security2:error] [pid 156215:tid 156357] [client 158.173.89.95:27073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jjMJ0fwhpxOKR8YgzVAAAAAw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:33:00.662246 2026] [security2:error] [pid 156215:tid 156457] [client 157.20.138.62:63129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jjMJ0fwhpxOKR8YgzXQAAAHA"]
[Mon Jul 20 07:33:00.662339 2026] [security2:error] [pid 156215:tid 156457] [client 157.20.138.62:63129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jjMJ0fwhpxOKR8YgzXQAAAHA"]
[Mon Jul 20 07:33:00.702694 2026] [security2:error] [pid 156215:tid 156405] [client 143.44.185.218:33916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jjMJ0fwhpxOKR8YgzXwAAADw"]
[Mon Jul 20 07:33:00.704691 2026] [security2:error] [pid 156215:tid 156405] [client 143.44.185.218:33916] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jjMJ0fwhpxOKR8YgzXwAAADw"]
[Mon Jul 20 07:33:00.921224 2026] [security2:error] [pid 156215:tid 156400] [client 50.116.65.227:11324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4jjMJ0fwhpxOKR8YgzbQAAADc"]
[Mon Jul 20 07:33:00.932958 2026] [security2:error] [pid 156215:tid 156409] [client 50.116.65.227:44204] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-4-Feature-Image.jpg"] [unique_id "al4jjMJ0fwhpxOKR8YgzbgAAAEA"]
[Mon Jul 20 07:33:01.026084 2026] [security2:error] [pid 156215:tid 156406] [client 57.141.18.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jjMJ0fwhpxOKR8YgzagAAAD0"]
[Mon Jul 20 07:33:01.065687 2026] [security2:error] [pid 156215:tid 156440] [client 136.158.60.21:25932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzdwAAAF8"]
[Mon Jul 20 07:33:01.065782 2026] [security2:error] [pid 156215:tid 156440] [client 136.158.60.21:25932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzdwAAAF8"]
[Mon Jul 20 07:33:01.392362 2026] [security2:error] [pid 156215:tid 156404] [client 49.47.218.174:61145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzlAAAADs"]
[Mon Jul 20 07:33:01.392651 2026] [security2:error] [pid 156215:tid 156404] [client 49.47.218.174:61145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzlAAAADs"]
[Mon Jul 20 07:33:01.614400 2026] [security2:error] [pid 156215:tid 156427] [client 103.139.191.61:62325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzpAAAAFI"]
[Mon Jul 20 07:33:01.614499 2026] [security2:error] [pid 156215:tid 156427] [client 103.139.191.61:62325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzpAAAAFI"]
[Mon Jul 20 07:33:01.860200 2026] [security2:error] [pid 156215:tid 156467] [client 173.239.254.16:31171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzuAAAAHo"]
[Mon Jul 20 07:33:02.107053 2026] [security2:error] [pid 156215:tid 156465] [client 14.225.17.146:63998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzvQAAAHg"], referer: http://oldracelimited.com/TEST
[Mon Jul 20 07:33:02.332069 2026] [security2:error] [pid 156215:tid 156341] [remote 173.249.4.11:32089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz2wAAJH0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:33:02.413875 2026] [security2:error] [pid 156215:tid 156380] [client 191.202.66.27:58695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz5AAAACM"]
[Mon Jul 20 07:33:02.414013 2026] [security2:error] [pid 156215:tid 156380] [client 191.202.66.27:58695] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz5AAAACM"]
[Mon Jul 20 07:33:02.444981 2026] [security2:error] [pid 156215:tid 156452] [client 50.116.65.227:44230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz1AAAAGs"]
[Mon Jul 20 07:33:02.489363 2026] [security2:error] [pid 156215:tid 156411] [client 172.225.215.126:27702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz4AAAQl0"]
[Mon Jul 20 07:33:02.602631 2026] [security2:error] [pid 156215:tid 156435] [client 57.141.18.117:26328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jjcJ0fwhpxOKR8YgzggAAWnM"]
[Mon Jul 20 07:33:02.613770 2026] [security2:error] [pid 156215:tid 156466] [client 50.116.65.227:44238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz7AAAAHk"]
[Mon Jul 20 07:33:02.665449 2026] [security2:error] [pid 156215:tid 156306] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz-wAANFo"]
[Mon Jul 20 07:33:02.665662 2026] [security2:error] [pid 156215:tid 156397] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz-wAANFo"]
[Mon Jul 20 07:33:02.731196 2026] [security2:error] [pid 156215:tid 156402] [client 223.109.255.148:54940] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ccsdifference.com"] [uri "/newsroom/"] [unique_id "al4jjsJ0fwhpxOKR8Yg0CwAAADk"]
[Mon Jul 20 07:33:02.731349 2026] [security2:error] [pid 156215:tid 156402] [client 223.109.255.148:54940] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ccsdifference.com"] [uri "/newsroom/"] [unique_id "al4jjsJ0fwhpxOKR8Yg0CwAAADk"]
[Mon Jul 20 07:33:02.736667 2026] [security2:error] [pid 156215:tid 156464] [client 179.127.84.238:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0DQAAAHc"]
[Mon Jul 20 07:33:02.736839 2026] [security2:error] [pid 156215:tid 156464] [client 179.127.84.238:61120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0DQAAAHc"]
[Mon Jul 20 07:33:02.801204 2026] [security2:error] [pid 156215:tid 156456] [client 154.192.123.127:18115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0EwAAAG8"]
[Mon Jul 20 07:33:02.801317 2026] [security2:error] [pid 156215:tid 156456] [client 154.192.123.127:18115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0EwAAAG8"]
[Mon Jul 20 07:33:02.908800 2026] [security2:error] [pid 156215:tid 156434] [client 49.37.242.14:52986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0GAAAAFk"]
[Mon Jul 20 07:33:02.908892 2026] [security2:error] [pid 156215:tid 156434] [client 49.37.242.14:52986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0GAAAAFk"]
[Mon Jul 20 07:33:03.047856 2026] [security2:error] [pid 156215:tid 156364] [client 36.93.152.155:56262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0HgAAABM"]
[Mon Jul 20 07:33:03.047966 2026] [security2:error] [pid 156215:tid 156364] [client 36.93.152.155:56262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0HgAAABM"]
[Mon Jul 20 07:33:03.191377 2026] [security2:error] [pid 156215:tid 156360] [client 104.234.53.85:54205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0LAAAAA8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:03.422973 2026] [security2:error] [pid 156215:tid 156350] [client 23.234.105.189:54246] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "acaiandcitystreets.com"] [uri "/php-cgi/php-cgi.exe"] [unique_id "al4jj8J0fwhpxOKR8Yg0TgAAAAU"]
[Mon Jul 20 07:33:03.491998 2026] [security2:error] [pid 156215:tid 156463] [client 14.225.17.146:49271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz_gAAAHY"]
[Mon Jul 20 07:33:03.548357 2026] [security2:error] [pid 156215:tid 156400] [client 57.141.18.51:53490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8YgzxgAAN3s"]
[Mon Jul 20 07:33:03.986896 2026] [security2:error] [pid 156215:tid 156353] [client 57.141.18.116:43608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8Ygz8AAACFs"]
[Mon Jul 20 07:33:04.062349 2026] [security2:error] [pid 156215:tid 156325] [remote 152.228.213.32:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0lwAAY20"]
[Mon Jul 20 07:33:04.104114 2026] [security2:error] [pid 156215:tid 156362] [client 116.74.65.235:63764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0fgAAABE"]
[Mon Jul 20 07:33:04.216222 2026] [security2:error] [pid 156215:tid 156423] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4jkMJ0fwhpxOKR8Yg0rAAAAE4"]
[Mon Jul 20 07:33:04.228269 2026] [security2:error] [pid 156215:tid 156399] [client 152.42.246.10:62437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.246.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.dereckcastellon.com"] [uri "/wp-login.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0rQAAADY"], referer: https://www.facebook.com/
[Mon Jul 20 07:33:04.233981 2026] [security2:error] [pid 156215:tid 156380] [client 57.141.18.70:25518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jjsJ0fwhpxOKR8Yg0EQAAIxE"]
[Mon Jul 20 07:33:04.282337 2026] [security2:error] [pid 156215:tid 156360] [client 103.106.165.44:62020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0sAAAAA8"]
[Mon Jul 20 07:33:04.282517 2026] [security2:error] [pid 156215:tid 156360] [client 103.106.165.44:62020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0sAAAAA8"]
[Mon Jul 20 07:33:04.296997 2026] [security2:error] [pid 156215:tid 156229] [remote 152.228.213.32:57062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.nvy.ppp.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0sQAAeQ0"], referer: https://mail.nvy.ppp.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:04.567831 2026] [security2:error] [pid 156215:tid 156375] [client 85.204.70.96:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.70.204.85.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cdn-0.sustaintheart.com"] [uri "/xmlrpc.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0xwAAAB4"]
[Mon Jul 20 07:33:04.577169 2026] [security2:error] [pid 156215:tid 156398] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.msd.mqz.mybluehost.me"] [uri "/index.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0WQAAADU"]
[Mon Jul 20 07:33:04.625761 2026] [security2:error] [pid 156215:tid 156459] [client 14.225.17.146:58412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0wgAAAHI"], referer: http://thechancersband.com/TEST
[Mon Jul 20 07:33:04.752634 2026] [security2:error] [pid 156215:tid 156414] [client 57.141.18.105:56048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0NAAARQU"]
[Mon Jul 20 07:33:04.878464 2026] [security2:error] [pid 156215:tid 156434] [client 57.141.18.18:25098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jj8J0fwhpxOKR8Yg0WgAAWQg"]
[Mon Jul 20 07:33:04.950965 2026] [security2:error] [pid 156215:tid 156410] [client 82.102.18.116:50972] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4jkMJ0fwhpxOKR8Yg06gAAAEE"]
[Mon Jul 20 07:33:04.953067 2026] [security2:error] [pid 156215:tid 156413] [client 104.234.53.74:63423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg07AAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:05.050021 2026] [security2:error] [pid 156215:tid 156386] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jkcJ0fwhpxOKR8Yg08gAAACk"]
[Mon Jul 20 07:33:05.298681 2026] [security2:error] [pid 156215:tid 156457] [client 82.102.18.116:50980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.southernswinggolfco.com"] [uri "/xmlrpc.php"] [unique_id "al4jkcJ0fwhpxOKR8Yg1CgAAAHA"]
[Mon Jul 20 07:33:05.373621 2026] [security2:error] [pid 156215:tid 156383] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jkcJ0fwhpxOKR8Yg1FwAAACY"]
[Mon Jul 20 07:33:05.415551 2026] [security2:error] [pid 156215:tid 156387] [client 103.176.215.66:49707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jkcJ0fwhpxOKR8Yg1HAAAACo"]
[Mon Jul 20 07:33:05.415881 2026] [security2:error] [pid 156215:tid 156387] [client 103.176.215.66:49707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jkcJ0fwhpxOKR8Yg1HAAAACo"]
[Mon Jul 20 07:33:05.448289 2026] [security2:error] [pid 156215:tid 156431] [client 57.141.18.90:23482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0kgAAVng"]
[Mon Jul 20 07:33:05.493888 2026] [security2:error] [pid 156215:tid 156347] [client 14.225.17.146:58791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4jkcJ0fwhpxOKR8Yg1DgAAAAI"], referer: http://inspirespublishing.com/TEST
[Mon Jul 20 07:33:05.501117 2026] [security2:error] [pid 156215:tid 156396] [client 78.190.178.78:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "blog.danwolfe.us"] [uri "/index.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg05gAAADM"], referer: https://blog.danwolfe.us
[Mon Jul 20 07:33:05.535373 2026] [security2:error] [pid 156215:tid 156420] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jkcJ0fwhpxOKR8Yg1JwAAAEs"]
[Mon Jul 20 07:33:05.840122 2026] [security2:error] [pid 156215:tid 156410] [client 50.116.65.227:44328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jkcJ0fwhpxOKR8Yg1RAAAAEE"]
[Mon Jul 20 07:33:05.852098 2026] [security2:error] [pid 156215:tid 156445] [client 50.116.65.227:44330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jkcJ0fwhpxOKR8Yg1RQAAAGQ"]
[Mon Jul 20 07:33:05.870657 2026] [security2:error] [pid 156215:tid 156363] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4jkcJ0fwhpxOKR8Yg1SAAAABI"]
[Mon Jul 20 07:33:05.993783 2026] [security2:error] [pid 156215:tid 156375] [client 82.102.18.116:50994] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jkcJ0fwhpxOKR8Yg1VAAAAB4"]
[Mon Jul 20 07:33:06.125715 2026] [security2:error] [pid 156215:tid 156393] [client 57.141.18.10:48694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jkMJ0fwhpxOKR8Yg0zwAAMCE"]
[Mon Jul 20 07:33:06.200166 2026] [security2:error] [pid 156215:tid 156352] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4jksJ0fwhpxOKR8Yg1YQAAAAc"]
[Mon Jul 20 07:33:06.333937 2026] [security2:error] [pid 156215:tid 156346] [client 82.102.18.116:50998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jksJ0fwhpxOKR8Yg1agAAAAE"]
[Mon Jul 20 07:33:06.506790 2026] [security2:error] [pid 156215:tid 156417] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4jksJ0fwhpxOKR8Yg1gAAAAEg"]
[Mon Jul 20 07:33:06.559088 2026] [security2:error] [pid 156215:tid 156412] [client 14.225.17.146:49384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4jksJ0fwhpxOKR8Yg1cgAAAEM"], referer: http://grecruit.online/TEST
[Mon Jul 20 07:33:06.646511 2026] [security2:error] [pid 156215:tid 156374] [client 82.102.18.116:51014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4jksJ0fwhpxOKR8Yg1iQAAAB0"]
[Mon Jul 20 07:33:06.715256 2026] [security2:error] [pid 156215:tid 156442] [client 66.249.74.42:47517] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.ililac.com"] [uri "/robots.txt"] [unique_id "al4jksJ0fwhpxOKR8Yg1jgAAAGE"]
[Mon Jul 20 07:33:06.745346 2026] [security2:error] [pid 156215:tid 156289] [remote 160.187.68.132:52952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jksJ0fwhpxOKR8Yg1jwAAX0k"]
[Mon Jul 20 07:33:06.813811 2026] [security2:error] [pid 156215:tid 156357] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4jksJ0fwhpxOKR8Yg1lAAAAAw"]
[Mon Jul 20 07:33:06.964663 2026] [security2:error] [pid 156215:tid 156422] [client 82.102.18.116:51020] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4jksJ0fwhpxOKR8Yg1owAAAE0"]
[Mon Jul 20 07:33:06.965449 2026] [security2:error] [pid 156215:tid 156380] [client 57.141.18.40:45038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jkcJ0fwhpxOKR8Yg1NAAAI2c"]
[Mon Jul 20 07:33:07.081991 2026] [security2:error] [pid 156215:tid 156443] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jksJ0fwhpxOKR8Yg1nwAAAGI"]
[Mon Jul 20 07:33:07.099302 2026] [authz_core:error] [pid 156215:tid 156434] [client 188.166.209.66:57270] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/error_log, referer: binance.com
[Mon Jul 20 07:33:07.106000 2026] [security2:error] [pid 156215:tid 156359] [client 45.3.44.27:28287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1qQAAAA4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:07.128391 2026] [security2:error] [pid 156215:tid 156390] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jk8J0fwhpxOKR8Yg1sgAAAC0"]
[Mon Jul 20 07:33:07.200345 2026] [security2:error] [pid 156215:tid 156450] [client 14.225.17.146:59011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4jksJ0fwhpxOKR8Yg1YgAAAGk"], referer: http://retzkolonglogistics.com/TEST
[Mon Jul 20 07:33:07.229444 2026] [security2:error] [pid 156215:tid 156232] [remote 160.187.68.132:52952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1vQAAYRA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:33:07.255471 2026] [security2:error] [pid 156215:tid 156464] [client 14.225.17.146:49306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1rQAAAHc"], referer: http://nurturemarple.co.uk/TEST
[Mon Jul 20 07:33:07.304599 2026] [security2:error] [pid 156215:tid 156466] [client 82.102.18.116:51032] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4jk8J0fwhpxOKR8Yg1wwAAAHk"]
[Mon Jul 20 07:33:07.403284 2026] [security2:error] [pid 156215:tid 156395] [client 57.141.18.68:46386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jkcJ0fwhpxOKR8Yg1UAAAMg8"]
[Mon Jul 20 07:33:07.432727 2026] [security2:error] [pid 156215:tid 156461] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jk8J0fwhpxOKR8Yg1zwAAAHQ"]
[Mon Jul 20 07:33:07.435667 2026] [security2:error] [pid 156215:tid 156216] [remote 152.228.213.32:37710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1zQAAPAA"]
[Mon Jul 20 07:33:07.565285 2026] [security2:error] [pid 156215:tid 156363] [client 14.225.17.146:49503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1xgAAABI"], referer: http://itdynamix.com/TEST
[Mon Jul 20 07:33:07.592370 2026] [security2:error] [pid 156215:tid 156422] [client 50.116.65.227:44364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1yQAAAE0"]
[Mon Jul 20 07:33:07.649720 2026] [security2:error] [pid 156215:tid 156442] [client 82.102.18.116:51044] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4jk8J0fwhpxOKR8Yg15AAAAGE"]
[Mon Jul 20 07:33:07.716024 2026] [security2:error] [pid 156215:tid 156436] [client 104.207.60.29:47661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jk8J0fwhpxOKR8Yg17wAAAFs"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:07.732500 2026] [security2:error] [pid 156215:tid 156241] [remote 152.228.213.32:37710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "according2plant.com"] [uri "/wp-login.php"] [unique_id "al4jk8J0fwhpxOKR8Yg18gAAPhk"], referer: https://according2plant.com/wp-login.php
[Mon Jul 20 07:33:07.750952 2026] [security2:error] [pid 156215:tid 156455] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jk8J0fwhpxOKR8Yg19QAAAG4"]
[Mon Jul 20 07:33:07.758530 2026] [security2:error] [pid 156215:tid 156356] [client 117.211.236.168:57821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jk8J0fwhpxOKR8Yg19wAAAAs"]
[Mon Jul 20 07:33:07.758598 2026] [security2:error] [pid 156215:tid 156356] [client 117.211.236.168:57821] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jk8J0fwhpxOKR8Yg19wAAAAs"]
[Mon Jul 20 07:33:07.784309 2026] [security2:error] [pid 156215:tid 156413] [client 104.234.53.47:42729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1-QAAAEQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:07.792766 2026] [security2:error] [pid 156215:tid 156411] [client 50.116.65.227:44382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4jk8J0fwhpxOKR8Yg14QAAAEI"]
[Mon Jul 20 07:33:07.840649 2026] [security2:error] [pid 156215:tid 156219] [remote 160.187.68.132:46496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jk8J0fwhpxOKR8Yg1_QAAcAM"]
[Mon Jul 20 07:33:07.964615 2026] [security2:error] [pid 156215:tid 156360] [client 82.102.18.116:60446] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jk8J0fwhpxOKR8Yg2CAAAAA8"]
[Mon Jul 20 07:33:08.051023 2026] [security2:error] [pid 156215:tid 156458] [client 193.36.225.89:54403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2CgAAAHE"]
[Mon Jul 20 07:33:08.069986 2026] [security2:error] [pid 156215:tid 156460] [client 193.36.225.2:43191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2DAAAAHM"]
[Mon Jul 20 07:33:08.073219 2026] [security2:error] [pid 156215:tid 156446] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jlMJ0fwhpxOKR8Yg2FQAAAGU"]
[Mon Jul 20 07:33:08.190335 2026] [security2:error] [pid 156215:tid 156369] [client 77.110.127.138:51270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jk8J0fwhpxOKR8Yg2AQAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:33:08.303481 2026] [security2:error] [pid 156215:tid 156386] [client 82.102.18.116:60450] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jlMJ0fwhpxOKR8Yg2KwAAACk"]
[Mon Jul 20 07:33:08.366189 2026] [security2:error] [pid 156215:tid 156442] [client 13.232.231.177:49322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2LgAAAGE"]
[Mon Jul 20 07:33:08.366256 2026] [security2:error] [pid 156215:tid 156442] [client 13.232.231.177:49322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2LgAAAGE"]
[Mon Jul 20 07:33:08.385507 2026] [security2:error] [pid 156215:tid 156416] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4jlMJ0fwhpxOKR8Yg2LwAAAEc"]
[Mon Jul 20 07:33:08.397179 2026] [security2:error] [pid 156215:tid 156464] [client 23.234.105.189:61873] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "acaiandcitystreets.com"] [uri "/index.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2MwAAAHc"]
[Mon Jul 20 07:33:08.404974 2026] [security2:error] [pid 156215:tid 156273] [remote 160.187.68.132:46496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2MgAAATk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:33:08.599573 2026] [core:error] [pid 156215:tid 156357] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:08.599595 2026] [core:error] [pid 156215:tid 156357] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:08.635867 2026] [security2:error] [pid 156215:tid 156350] [client 14.225.17.146:53344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2NwAAAAU"], referer: https://itdynamix.com/TEST
[Mon Jul 20 07:33:08.641379 2026] [security2:error] [pid 156215:tid 156450] [client 82.102.18.116:60460] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jlMJ0fwhpxOKR8Yg2RAAAAGk"]
[Mon Jul 20 07:33:08.695853 2026] [security2:error] [pid 156215:tid 156469] [client 23.234.105.189:65130] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "acaiandcitystreets.com"] [uri "/test.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2TAAAAHw"]
[Mon Jul 20 07:33:08.699766 2026] [security2:error] [pid 156215:tid 156422] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4jlMJ0fwhpxOKR8Yg2TQAAAE0"]
[Mon Jul 20 07:33:08.816866 2026] [security2:error] [pid 156215:tid 156246] [remote 98.156.100.191:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2VAAAWB4"]
[Mon Jul 20 07:33:08.922388 2026] [security2:error] [pid 156215:tid 156390] [client 57.141.18.8:61886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jk8J0fwhpxOKR8Yg14AAALVI"]
[Mon Jul 20 07:33:08.944663 2026] [security2:error] [pid 156215:tid 156408] [client 14.225.17.146:54129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2TwAAAD8"], referer: http://thesoloceos.com/TEST
[Mon Jul 20 07:33:08.956195 2026] [security2:error] [pid 156215:tid 156386] [client 82.102.18.116:60474] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jlMJ0fwhpxOKR8Yg2WwAAACk"]
[Mon Jul 20 07:33:08.959432 2026] [security2:error] [pid 156215:tid 156432] [client 23.234.105.189:51037] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "acaiandcitystreets.com"] [uri "/test.hello"] [unique_id "al4jlMJ0fwhpxOKR8Yg2XAAAAFc"]
[Mon Jul 20 07:33:09.003436 2026] [security2:error] [pid 156215:tid 156362] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jlcJ0fwhpxOKR8Yg2aQAAABE"]
[Mon Jul 20 07:33:09.010456 2026] [security2:error] [pid 156215:tid 156336] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2agAAG3g"]
[Mon Jul 20 07:33:09.010578 2026] [security2:error] [pid 156215:tid 156372] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2agAAG3g"]
[Mon Jul 20 07:33:09.299804 2026] [security2:error] [pid 156215:tid 156454] [client 82.102.18.116:60476] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4jlcJ0fwhpxOKR8Yg2ggAAAG0"]
[Mon Jul 20 07:33:09.309132 2026] [security2:error] [pid 156215:tid 156382] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jlcJ0fwhpxOKR8Yg2hAAAACU"]
[Mon Jul 20 07:33:09.313386 2026] [security2:error] [pid 156215:tid 156429] [client 51.37.194.22:58890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2gAAAVC8"]
[Mon Jul 20 07:33:09.355249 2026] [security2:error] [pid 156215:tid 156365] [client 104.234.53.81:31781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2kAAAABQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:09.417699 2026] [security2:error] [pid 156215:tid 156441] [client 46.110.96.34:60537] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4jlcJ0fwhpxOKR8Yg2lQAAAGA"]
[Mon Jul 20 07:33:09.536420 2026] [security2:error] [pid 156215:tid 156304] [remote 98.156.100.191:39210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2nwAABFg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:33:09.620488 2026] [security2:error] [pid 156215:tid 156431] [client 85.204.70.96:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cdn-0.sustaintheart.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4jlcJ0fwhpxOKR8Yg2qQAAAFY"]
[Mon Jul 20 07:33:09.624061 2026] [security2:error] [pid 156215:tid 156459] [client 82.102.18.116:60482] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4jlcJ0fwhpxOKR8Yg2qgAAAHI"]
[Mon Jul 20 07:33:09.865440 2026] [security2:error] [pid 156215:tid 156348] [client 57.141.18.33:29972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jlMJ0fwhpxOKR8Yg2PQAAA3Y"]
[Mon Jul 20 07:33:09.908905 2026] [security2:error] [pid 156215:tid 156394] [client 144.16.21.149:36112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2uAAAADE"]
[Mon Jul 20 07:33:09.909068 2026] [security2:error] [pid 156215:tid 156394] [client 144.16.21.149:36112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2uAAAADE"]
[Mon Jul 20 07:33:09.936185 2026] [security2:error] [pid 156215:tid 156471] [client 14.225.17.146:53350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2tQAAAH4"], referer: https://thesoloceos.com/TEST
[Mon Jul 20 07:33:09.964468 2026] [security2:error] [pid 156215:tid 156440] [client 82.102.18.116:9678] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jlcJ0fwhpxOKR8Yg2vwAAAF8"]
[Mon Jul 20 07:33:09.984714 2026] [security2:error] [pid 156215:tid 156364] [client 17.246.23.176:42944] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2uwAAE2k"]
[Mon Jul 20 07:33:10.027144 2026] [security2:error] [pid 156215:tid 156408] [client 149.0.16.108:51942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jlsJ0fwhpxOKR8Yg2wQAAAD8"]
[Mon Jul 20 07:33:10.027245 2026] [security2:error] [pid 156215:tid 156408] [client 149.0.16.108:51942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jlsJ0fwhpxOKR8Yg2wQAAAD8"]
[Mon Jul 20 07:33:10.046445 2026] [security2:error] [pid 156215:tid 156355] [client 14.225.17.146:49335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4jlcJ0fwhpxOKR8Yg2ugAAAAo"], referer: http://headachescarpaltunnelfibromyalgia.com/TEST
[Mon Jul 20 07:33:10.279444 2026] [security2:error] [pid 156215:tid 156429] [client 82.102.18.116:8986] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jlsJ0fwhpxOKR8Yg25gAAAFQ"]
[Mon Jul 20 07:33:10.630099 2026] [security2:error] [pid 156215:tid 156428] [client 82.102.18.116:60512] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.southernswinggolfco.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4jlsJ0fwhpxOKR8Yg2_AAAAFM"]
[Mon Jul 20 07:33:10.739776 2026] [security2:error] [pid 156215:tid 156457] [client 142.111.152.64:48233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jlsJ0fwhpxOKR8Yg29wAAAHA"]
[Mon Jul 20 07:33:11.186328 2026] [security2:error] [pid 156215:tid 156420] [client 157.20.138.62:63689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3LwAAAEs"]
[Mon Jul 20 07:33:11.186441 2026] [security2:error] [pid 156215:tid 156420] [client 157.20.138.62:63689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3LwAAAEs"]
[Mon Jul 20 07:33:11.642071 2026] [security2:error] [pid 156215:tid 156435] [client 49.47.218.174:61691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3VgAAAFo"]
[Mon Jul 20 07:33:11.642179 2026] [security2:error] [pid 156215:tid 156435] [client 49.47.218.174:61691] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3VgAAAFo"]
[Mon Jul 20 07:33:11.817741 2026] [security2:error] [pid 156215:tid 156348] [client 136.158.60.21:27611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3aQAAAAM"]
[Mon Jul 20 07:33:11.817856 2026] [security2:error] [pid 156215:tid 156348] [client 136.158.60.21:27611] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3aQAAAAM"]
[Mon Jul 20 07:33:11.927677 2026] [core:error] [pid 156215:tid 156380] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:11.927697 2026] [core:error] [pid 156215:tid 156380] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:12.040291 2026] [security2:error] [pid 156215:tid 156390] [client 57.141.18.73:32374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jlsJ0fwhpxOKR8Yg3CAAALUY"]
[Mon Jul 20 07:33:12.118118 2026] [security2:error] [pid 156215:tid 156370] [client 202.141.11.99:35856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3ggAAABk"]
[Mon Jul 20 07:33:12.118235 2026] [security2:error] [pid 156215:tid 156370] [client 202.141.11.99:35856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3ggAAABk"]
[Mon Jul 20 07:33:12.189895 2026] [security2:error] [pid 156215:tid 156434] [client 89.238.167.150:44956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3hwAAAFk"]
[Mon Jul 20 07:33:12.189988 2026] [security2:error] [pid 156215:tid 156434] [client 89.238.167.150:44956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3hwAAAFk"]
[Mon Jul 20 07:33:12.374584 2026] [core:error] [pid 156215:tid 156399] [client 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:12.374626 2026] [core:error] [pid 156215:tid 156399] [client 198.235.24.128:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:12.550098 2026] [security2:error] [pid 156215:tid 156298] [remote 57.141.18.87:38856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2529028"] [unique_id "al4jmMJ0fwhpxOKR8Yg3pgAAUVI"]
[Mon Jul 20 07:33:12.625988 2026] [security2:error] [pid 156215:tid 156406] [client 57.141.18.16:43274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3JwAAPQA"]
[Mon Jul 20 07:33:12.636584 2026] [security2:error] [pid 156215:tid 156358] [client 103.139.191.61:62804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3rgAAAA0"]
[Mon Jul 20 07:33:12.636676 2026] [security2:error] [pid 156215:tid 156358] [client 103.139.191.61:62804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3rgAAAA0"]
[Mon Jul 20 07:33:12.851450 2026] [security2:error] [pid 156215:tid 156465] [client 143.44.185.218:35397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3yAAAAHg"]
[Mon Jul 20 07:33:12.852113 2026] [security2:error] [pid 156215:tid 156465] [client 143.44.185.218:35397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3yAAAAHg"]
[Mon Jul 20 07:33:13.161397 2026] [security2:error] [pid 156215:tid 156468] [client 57.141.18.32:32262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3UQAAe04"]
[Mon Jul 20 07:33:13.163268 2026] [security2:error] [pid 156215:tid 156364] [client 191.202.66.27:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg32gAAABM"]
[Mon Jul 20 07:33:13.163400 2026] [security2:error] [pid 156215:tid 156364] [client 191.202.66.27:59188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg32gAAABM"]
[Mon Jul 20 07:33:13.166533 2026] [security2:error] [pid 156215:tid 156441] [client 57.141.18.98:37242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3UgAAYHw"]
[Mon Jul 20 07:33:13.350326 2026] [security2:error] [pid 156215:tid 156310] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg37QAAI14"]
[Mon Jul 20 07:33:13.350474 2026] [security2:error] [pid 156215:tid 156380] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg37QAAI14"]
[Mon Jul 20 07:33:13.362911 2026] [security2:error] [pid 156215:tid 156387] [client 154.192.123.127:18619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg37gAAACo"]
[Mon Jul 20 07:33:13.363037 2026] [security2:error] [pid 156215:tid 156387] [client 154.192.123.127:18619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg37gAAACo"]
[Mon Jul 20 07:33:13.407810 2026] [security2:error] [pid 156215:tid 156422] [client 179.127.84.238:61663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg39AAAAE0"]
[Mon Jul 20 07:33:13.407938 2026] [security2:error] [pid 156215:tid 156422] [client 179.127.84.238:61663] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg39AAAAE0"]
[Mon Jul 20 07:33:13.456229 2026] [security2:error] [pid 156215:tid 156358] [client 14.225.17.146:57847] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg38wAAAA0"], referer: http://walkingandtalking.net/TEST
[Mon Jul 20 07:33:13.489769 2026] [security2:error] [pid 156215:tid 156348] [client 36.93.152.155:56778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg3_QAAAAM"]
[Mon Jul 20 07:33:13.489862 2026] [security2:error] [pid 156215:tid 156348] [client 36.93.152.155:56778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg3_QAAAAM"]
[Mon Jul 20 07:33:13.535442 2026] [security2:error] [pid 156215:tid 156402] [client 63.179.149.246:56814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg4AwAAADk"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:13.735520 2026] [security2:error] [pid 156215:tid 156413] [client 57.141.18.99:63076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3cgAARAQ"]
[Mon Jul 20 07:33:13.769339 2026] [security2:error] [pid 156215:tid 156439] [client 35.252.111.205:37798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg3-AAAAF4"]
[Mon Jul 20 07:33:13.805770 2026] [security2:error] [pid 156215:tid 156451] [client 57.141.18.86:35022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jl8J0fwhpxOKR8Yg3dAAAamE"]
[Mon Jul 20 07:33:13.899528 2026] [security2:error] [pid 156215:tid 156388] [client 14.225.17.146:57315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg3-gAAACs"], referer: http://partnerselectricalllc.com/TEST
[Mon Jul 20 07:33:14.053909 2026] [security2:error] [pid 156215:tid 156408] [client 74.7.175.149:40846] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "elite-pk.com"] [uri "/robots.txt"] [unique_id "al4jmsJ0fwhpxOKR8Yg4IQAAAD8"]
[Mon Jul 20 07:33:14.080068 2026] [security2:error] [pid 156215:tid 156397] [client 63.177.52.239:58984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4IgAAADQ"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:14.130110 2026] [security2:error] [pid 156215:tid 156368] [client 57.141.18.111:25790] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3kgAAFxU"]
[Mon Jul 20 07:33:14.179054 2026] [security2:error] [pid 156215:tid 156427] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nyradigitalsolutions.com"] [uri "/index.php"] [unique_id "al4jmMJ0fwhpxOKR8Yg3swAAAFI"]
[Mon Jul 20 07:33:14.345536 2026] [security2:error] [pid 156215:tid 156350] [client 14.225.17.146:55229] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4OAAAAAU"], referer: https://walkingandtalking.net/TEST
[Mon Jul 20 07:33:14.557713 2026] [security2:error] [pid 156215:tid 156328] [remote 100.42.189.89:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4TgAAPHA"]
[Mon Jul 20 07:33:14.716828 2026] [security2:error] [pid 156215:tid 156400] [client 103.106.165.44:62510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4YAAAADc"]
[Mon Jul 20 07:33:14.716979 2026] [security2:error] [pid 156215:tid 156400] [client 103.106.165.44:62510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4YAAAADc"]
[Mon Jul 20 07:33:14.737716 2026] [security2:error] [pid 156215:tid 156423] [client 63.176.132.15:48958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4ZAAAAE4"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:14.767677 2026] [security2:error] [pid 156215:tid 156316] [remote 100.42.189.89:33918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4aQAAX2Q"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:14.798430 2026] [security2:error] [pid 156215:tid 156464] [client 63.177.52.239:58992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jmsJ0fwhpxOKR8Yg4bQAAAHc"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:15.091181 2026] [security2:error] [pid 156215:tid 156424] [client 66.249.74.14:55316] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "findmyperfectrealtor.com"] [uri "/robots.txt"] [unique_id "al4jm8J0fwhpxOKR8Yg4gQAAAE8"]
[Mon Jul 20 07:33:15.195567 2026] [autoindex:error] [pid 156215:tid 156349] [client 198.235.24.145:59438] AH01276: Cannot serve directory /home2/cssgdzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://css.gdz.mybluehost.me/
[Mon Jul 20 07:33:15.342195 2026] [security2:error] [pid 156215:tid 156471] [client 52.59.238.198:37238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4mAAAAH4"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:15.435101 2026] [security2:error] [pid 156215:tid 156382] [client 63.177.52.239:59006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4pAAAACU"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:15.623877 2026] [security2:error] [pid 156215:tid 156381] [client 14.225.17.146:55069] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4ngAAACQ"], referer: http://mobilesurvsolutions.com/TEST
[Mon Jul 20 07:33:15.667480 2026] [security2:error] [pid 156215:tid 156389] [client 14.225.17.146:54226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4jQAAACw"]
[Mon Jul 20 07:33:15.851022 2026] [security2:error] [pid 156215:tid 156437] [client 158.173.166.181:45223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4zQAAAFw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:33:15.860619 2026] [security2:error] [pid 156215:tid 156415] [client 14.225.17.146:57375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4jmcJ0fwhpxOKR8Yg3-QAAAEY"], referer: http://talknutritionwithlesley.com/TEST
[Mon Jul 20 07:33:15.908224 2026] [security2:error] [pid 156215:tid 156257] [remote 8.217.108.67:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jm8J0fwhpxOKR8Yg41AAAZyk"]
[Mon Jul 20 07:33:15.952053 2026] [security2:error] [pid 156215:tid 156393] [client 103.176.215.66:50238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jm8J0fwhpxOKR8Yg42AAAADA"]
[Mon Jul 20 07:33:15.952540 2026] [security2:error] [pid 156215:tid 156393] [client 103.176.215.66:50238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jm8J0fwhpxOKR8Yg42AAAADA"]
[Mon Jul 20 07:33:16.082061 2026] [security2:error] [pid 156215:tid 156246] [remote 57.141.18.77:54956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4325231"] [unique_id "al4jnMJ0fwhpxOKR8Yg44AAAKx4"]
[Mon Jul 20 07:33:16.178300 2026] [security2:error] [pid 156215:tid 156471] [client 63.177.52.239:59012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg44gAAAH4"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:16.305308 2026] [security2:error] [pid 156215:tid 156285] [remote 8.217.108.67:55486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg47QAAMUU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:33:16.374881 2026] [security2:error] [pid 156215:tid 156391] [client 117.211.236.168:58344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg49wAAAC4"]
[Mon Jul 20 07:33:16.375028 2026] [security2:error] [pid 156215:tid 156391] [client 117.211.236.168:58344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg49wAAAC4"]
[Mon Jul 20 07:33:16.606701 2026] [security2:error] [pid 156215:tid 156407] [client 14.225.17.146:53649] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg4_gAAAD4"], referer: http://christiancountytrumpet.com/TEST
[Mon Jul 20 07:33:16.748024 2026] [security2:error] [pid 156215:tid 156403] [client 52.59.238.198:37250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.238.59.52.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg5GwAAADo"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:16.773675 2026] [security2:error] [pid 156215:tid 156468] [client 14.225.17.146:53635] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4mgAAAHs"], referer: http://samdothan.org/TEST
[Mon Jul 20 07:33:16.814407 2026] [security2:error] [pid 156215:tid 156377] [client 3.75.183.99:45188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg5HgAAACA"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:17.100228 2026] [security2:error] [pid 156215:tid 156357] [client 35.252.111.205:44268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.oyu.omk.mybluehost.me"] [uri "/index.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg5MQAAAAw"]
[Mon Jul 20 07:33:17.271782 2026] [security2:error] [pid 156215:tid 156355] [client 57.141.18.11:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jncJ0fwhpxOKR8Yg5QwAAAAo"]
[Mon Jul 20 07:33:17.310385 2026] [security2:error] [pid 156215:tid 156463] [client 57.141.18.111:59802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jm8J0fwhpxOKR8Yg4jgAAdlY"]
[Mon Jul 20 07:33:17.459478 2026] [security2:error] [pid 156215:tid 156373] [client 63.176.132.15:48968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jncJ0fwhpxOKR8Yg5YAAAABw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:17.633069 2026] [security2:error] [pid 156215:tid 156347] [client 50.116.65.227:58296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jncJ0fwhpxOKR8Yg5aAAAAAI"]
[Mon Jul 20 07:33:17.643358 2026] [security2:error] [pid 156215:tid 156467] [client 50.116.65.227:58304] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jncJ0fwhpxOKR8Yg5aQAAAHo"]
[Mon Jul 20 07:33:17.730672 2026] [security2:error] [pid 156215:tid 156338] [remote 15.206.251.117:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jncJ0fwhpxOKR8Yg5awAARHo"]
[Mon Jul 20 07:33:17.964361 2026] [security2:error] [pid 156215:tid 156421] [client 14.225.17.146:55080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg44wAAAEw"], referer: http://aandarealtygroup.com/TEST
[Mon Jul 20 07:33:17.986092 2026] [security2:error] [pid 156215:tid 156361] [client 3.67.192.83:37616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jncJ0fwhpxOKR8Yg5hgAAABA"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:18.093470 2026] [security2:error] [pid 156215:tid 156423] [client 57.141.18.96:26094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg46gAATgA"]
[Mon Jul 20 07:33:18.115977 2026] [security2:error] [pid 156215:tid 156281] [remote 15.206.251.117:45958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg5kgAASEE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:33:18.183836 2026] [authz_core:error] [pid 156215:tid 156356] [client 188.166.209.66:59468] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/error_log, referer: binance.com
[Mon Jul 20 07:33:18.200137 2026] [core:error] [pid 156215:tid 156379] [client 14.225.17.146:63274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:18.200163 2026] [core:error] [pid 156215:tid 156379] [client 14.225.17.146:63274] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:18.281704 2026] [security2:error] [pid 156215:tid 156433] [client 14.225.17.146:53621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg5jAAAAFg"], referer: http://mezzacraft.com/TEST
[Mon Jul 20 07:33:18.495147 2026] [security2:error] [pid 156215:tid 156409] [client 3.75.183.99:45196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg5vQAAAEA"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:18.818689 2026] [security2:error] [pid 156215:tid 156394] [client 74.208.214.194:45490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg51AAAADE"]
[Mon Jul 20 07:33:18.848187 2026] [fcgid:warn] [pid 156215:tid 156402] (70014)End of file found: [client 103.168.67.159:53378] mod_fcgid: can't get data from http client
[Mon Jul 20 07:33:18.855871 2026] [security2:error] [pid 156215:tid 156416] [client 57.141.18.12:50340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jnMJ0fwhpxOKR8Yg5LgAARx0"]
[Mon Jul 20 07:33:18.908248 2026] [security2:error] [pid 156215:tid 156451] [client 13.233.207.33:59220] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg54QAAAGo"]
[Mon Jul 20 07:33:18.908348 2026] [security2:error] [pid 156215:tid 156451] [client 13.233.207.33:59220] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg54QAAAGo"]
[Mon Jul 20 07:33:18.927811 2026] [security2:error] [pid 156215:tid 156433] [client 13.233.207.33:59226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jnsJ0fwhpxOKR8Yg54wAAAFg"]
[Mon Jul 20 07:33:19.136011 2026] [security2:error] [pid 156215:tid 156426] [client 57.141.18.57:30698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jncJ0fwhpxOKR8Yg5RQAAUVA"]
[Mon Jul 20 07:33:19.709148 2026] [autoindex:error] [pid 156215:tid 156286] [remote 8.229.41.77:51542] AH01276: Cannot serve directory /home2/uhiwfwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.uhi.wfw.mybluehost.me
[Mon Jul 20 07:33:19.768968 2026] [security2:error] [pid 156215:tid 156348] [client 13.215.47.127:11038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jn8J0fwhpxOKR8Yg6MwAAAAM"]
[Mon Jul 20 07:33:19.780187 2026] [security2:error] [pid 156215:tid 156257] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jn8J0fwhpxOKR8Yg6NgAAQik"]
[Mon Jul 20 07:33:19.780337 2026] [security2:error] [pid 156215:tid 156411] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jn8J0fwhpxOKR8Yg6NgAAQik"]
[Mon Jul 20 07:33:19.840153 2026] [security2:error] [pid 156215:tid 156445] [client 13.233.207.33:59238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jn8J0fwhpxOKR8Yg6OQAAAGQ"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:33:20.118982 2026] [security2:error] [pid 156215:tid 156444] [client 152.42.246.10:53565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 10.246.42.152.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "dereckcastellon.com"] [uri "/wp-login.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6WwAAAGM"], referer: https://t.co/
[Mon Jul 20 07:33:20.134802 2026] [security2:error] [pid 156215:tid 156424] [client 14.225.17.146:55032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4jn8J0fwhpxOKR8Yg6QAAAAE8"], referer: http://ironcitywellness.com/TEST
403 (Forbidden): 403 Forbidden
Executing in an invalid environment for the supplied user at /usr/local/cpanel/Cpanel/CGI/NoForm.pm line 157.
[Mon Jul 20 07:33:20.658402 2026] [security2:error] [pid 156215:tid 156432] [client 149.0.16.108:52454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6iwAAAFc"]
[Mon Jul 20 07:33:20.658517 2026] [security2:error] [pid 156215:tid 156432] [client 149.0.16.108:52454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6iwAAAFc"]
[Mon Jul 20 07:33:20.701285 2026] [security2:error] [pid 156215:tid 156445] [client 144.16.21.149:25077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6jgAAAGQ"]
[Mon Jul 20 07:33:20.701446 2026] [security2:error] [pid 156215:tid 156445] [client 144.16.21.149:25077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6jgAAAGQ"]
[Mon Jul 20 07:33:20.752570 2026] [security2:error] [pid 156215:tid 156373] [client 13.229.223.11:34688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6kwAAABw"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:33:21.069783 2026] [security2:error] [pid 156215:tid 156349] [client 14.225.17.146:63299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6qQAAAAQ"], referer: http://adultdaycarereno.com/TEST
[Mon Jul 20 07:33:21.124124 2026] [security2:error] [pid 156215:tid 156292] [remote 68.178.165.65:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6tgAAOEw"]
[Mon Jul 20 07:33:21.296999 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6xwAAACQ"]
[Mon Jul 20 07:33:21.297114 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41369] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6xwAAACQ"]
[Mon Jul 20 07:33:21.316649 2026] [security2:error] [pid 156215:tid 156472] [client 142.111.152.178:37641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6vAAAAH8"]
[Mon Jul 20 07:33:21.343876 2026] [security2:error] [pid 156215:tid 156385] [client 14.225.17.146:54928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4jn8J0fwhpxOKR8Yg6CAAAACg"], referer: http://webgardensbypaula.com/TEST
[Mon Jul 20 07:33:21.477999 2026] [security2:error] [pid 156215:tid 156242] [remote 72.167.132.114:40470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jocJ0fwhpxOKR8Yg61wAAbRo"]
[Mon Jul 20 07:33:21.478240 2026] [security2:error] [pid 156215:tid 156454] [client 72.167.132.114:40470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rcq.nst.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jocJ0fwhpxOKR8Yg61wAAbRo"]
[Mon Jul 20 07:33:21.519171 2026] [security2:error] [pid 156215:tid 156297] [remote 68.178.165.65:53766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jocJ0fwhpxOKR8Yg63QAAU1E"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:33:21.623365 2026] [security2:error] [pid 156215:tid 156373] [client 20.226.66.230:41666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4jocJ0fwhpxOKR8Yg65wAAABw"]
[Mon Jul 20 07:33:21.623458 2026] [security2:error] [pid 156215:tid 156373] [client 20.226.66.230:41666] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4jocJ0fwhpxOKR8Yg65wAAABw"]
[Mon Jul 20 07:33:21.775438 2026] [security2:error] [pid 156215:tid 156357] [client 157.20.138.62:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6-gAAAAw"]
[Mon Jul 20 07:33:21.775533 2026] [security2:error] [pid 156215:tid 156357] [client 157.20.138.62:64254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jocJ0fwhpxOKR8Yg6-gAAAAw"]
[Mon Jul 20 07:33:21.913415 2026] [security2:error] [pid 156215:tid 156420] [client 57.141.18.24:38084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4joMJ0fwhpxOKR8Yg6WAAASxc"]
[Mon Jul 20 07:33:21.942111 2026] [security2:error] [pid 156215:tid 156401] [client 20.226.66.230:41670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/x.php"] [unique_id "al4jocJ0fwhpxOKR8Yg7BgAAADg"]
[Mon Jul 20 07:33:21.942206 2026] [security2:error] [pid 156215:tid 156401] [client 20.226.66.230:41670] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/x.php"] [unique_id "al4jocJ0fwhpxOKR8Yg7BgAAADg"]
[Mon Jul 20 07:33:22.001513 2026] [security2:error] [pid 156215:tid 156347] [client 14.225.17.146:57427] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4jocJ0fwhpxOKR8Yg7BwAAAAI"], referer: https://adultdaycarereno.com/TEST
[Mon Jul 20 07:33:22.257661 2026] [security2:error] [pid 156215:tid 156411] [client 20.226.66.230:41708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/mgrr.php"] [unique_id "al4josJ0fwhpxOKR8Yg7HQAAAEI"]
[Mon Jul 20 07:33:22.257777 2026] [security2:error] [pid 156215:tid 156411] [client 20.226.66.230:41708] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/mgrr.php"] [unique_id "al4josJ0fwhpxOKR8Yg7HQAAAEI"]
[Mon Jul 20 07:33:22.451842 2026] [security2:error] [pid 156215:tid 156380] [client 49.47.218.174:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4josJ0fwhpxOKR8Yg7LQAAACM"]
[Mon Jul 20 07:33:22.452073 2026] [security2:error] [pid 156215:tid 156380] [client 49.47.218.174:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4josJ0fwhpxOKR8Yg7LQAAACM"]
[Mon Jul 20 07:33:22.536345 2026] [security2:error] [pid 156215:tid 156466] [client 104.234.53.56:20549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4josJ0fwhpxOKR8Yg7NAAAAHk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:22.550739 2026] [security2:error] [pid 156215:tid 156416] [client 136.158.60.21:29091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4josJ0fwhpxOKR8Yg7NgAAAEc"]
[Mon Jul 20 07:33:22.550868 2026] [security2:error] [pid 156215:tid 156416] [client 136.158.60.21:29091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4josJ0fwhpxOKR8Yg7NgAAAEc"]
[Mon Jul 20 07:33:22.598141 2026] [security2:error] [pid 156215:tid 156390] [client 20.226.66.230:41389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/stdin.php"] [unique_id "al4josJ0fwhpxOKR8Yg7OAAAAC0"]
[Mon Jul 20 07:33:22.598231 2026] [security2:error] [pid 156215:tid 156390] [client 20.226.66.230:41389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/stdin.php"] [unique_id "al4josJ0fwhpxOKR8Yg7OAAAAC0"]
[Mon Jul 20 07:33:22.915657 2026] [security2:error] [pid 156215:tid 156417] [client 20.226.66.230:41346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/BDKR28.php"] [unique_id "al4josJ0fwhpxOKR8Yg7TgAAAEg"]
[Mon Jul 20 07:33:22.915802 2026] [security2:error] [pid 156215:tid 156417] [client 20.226.66.230:41346] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/BDKR28.php"] [unique_id "al4josJ0fwhpxOKR8Yg7TgAAAEg"]
[Mon Jul 20 07:33:23.275688 2026] [security2:error] [pid 156215:tid 156437] [client 20.226.66.230:41692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/001.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7agAAAFw"]
[Mon Jul 20 07:33:23.275816 2026] [security2:error] [pid 156215:tid 156437] [client 20.226.66.230:41692] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/001.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7agAAAFw"]
[Mon Jul 20 07:33:23.592839 2026] [security2:error] [pid 156215:tid 156380] [client 20.226.66.230:41695] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/dZ3wP5.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7gAAAACM"]
[Mon Jul 20 07:33:23.592968 2026] [security2:error] [pid 156215:tid 156380] [client 20.226.66.230:41695] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/dZ3wP5.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7gAAAACM"]
[Mon Jul 20 07:33:23.822797 2026] [security2:error] [pid 156215:tid 156434] [client 191.202.66.27:59678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7kQAAAFk"]
[Mon Jul 20 07:33:23.822917 2026] [security2:error] [pid 156215:tid 156434] [client 191.202.66.27:59678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7kQAAAFk"]
[Mon Jul 20 07:33:23.921586 2026] [security2:error] [pid 156215:tid 156352] [client 20.226.66.230:41362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/yup.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7pAAAAAc"]
[Mon Jul 20 07:33:23.921681 2026] [security2:error] [pid 156215:tid 156352] [client 20.226.66.230:41362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/yup.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7pAAAAAc"]
[Mon Jul 20 07:33:23.974714 2026] [security2:error] [pid 156215:tid 156345] [client 14.225.17.146:57266] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4josJ0fwhpxOKR8Yg7RQAAAAA"], referer: http://wathenbartlett.co.uk/TEST
[Mon Jul 20 07:33:23.976682 2026] [security2:error] [pid 156215:tid 156278] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7qQAAJj4"]
[Mon Jul 20 07:33:23.976810 2026] [security2:error] [pid 156215:tid 156383] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7qQAAJj4"]
[Mon Jul 20 07:33:24.021538 2026] [security2:error] [pid 156215:tid 156427] [client 36.93.152.155:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7swAAAFI"]
[Mon Jul 20 07:33:24.021699 2026] [security2:error] [pid 156215:tid 156427] [client 36.93.152.155:57288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7swAAAFI"]
[Mon Jul 20 07:33:24.050064 2026] [security2:error] [pid 156215:tid 156372] [client 179.127.84.238:62203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7twAAABs"]
[Mon Jul 20 07:33:24.050222 2026] [security2:error] [pid 156215:tid 156372] [client 179.127.84.238:62203] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7twAAABs"]
[Mon Jul 20 07:33:24.119057 2026] [security2:error] [pid 156215:tid 156397] [client 108.55.229.58:50704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7tAAANBY"]
[Mon Jul 20 07:33:24.169222 2026] [security2:error] [pid 156215:tid 156451] [client 103.139.191.61:63290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7vwAAAGo"]
[Mon Jul 20 07:33:24.169326 2026] [security2:error] [pid 156215:tid 156451] [client 103.139.191.61:63290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7vwAAAGo"]
[Mon Jul 20 07:33:24.185670 2026] [security2:error] [pid 156215:tid 156439] [client 154.192.123.127:17078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7wwAAAF4"]
[Mon Jul 20 07:33:24.185773 2026] [security2:error] [pid 156215:tid 156439] [client 154.192.123.127:17078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7wwAAAF4"]
[Mon Jul 20 07:33:24.257066 2026] [security2:error] [pid 156215:tid 156345] [client 20.226.66.230:41686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/X.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7zgAAAAA"]
[Mon Jul 20 07:33:24.257163 2026] [security2:error] [pid 156215:tid 156345] [client 20.226.66.230:41686] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/X.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7zgAAAAA"]
[Mon Jul 20 07:33:24.515075 2026] [security2:error] [pid 156215:tid 156465] [client 188.166.209.66:52875] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg76AAAAHg"], referer: binance.com
[Mon Jul 20 07:33:24.571680 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41400] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/1polka.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg77QAAACQ"]
[Mon Jul 20 07:33:24.571789 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/1polka.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg77QAAACQ"]
[Mon Jul 20 07:33:24.758741 2026] [security2:error] [pid 156215:tid 156372] [client 89.238.167.150:44326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg79wAAABs"]
[Mon Jul 20 07:33:24.758833 2026] [security2:error] [pid 156215:tid 156372] [client 89.238.167.150:44326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg79wAAABs"]
[Mon Jul 20 07:33:24.885417 2026] [security2:error] [pid 156215:tid 156382] [client 14.225.17.146:64278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg7_wAAACU"], referer: https://wathenbartlett.co.uk/TEST
[Mon Jul 20 07:33:24.888120 2026] [security2:error] [pid 156215:tid 156354] [client 20.226.66.230:41349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/gec.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg8BgAAAAk"]
[Mon Jul 20 07:33:24.888205 2026] [security2:error] [pid 156215:tid 156354] [client 20.226.66.230:41349] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/gec.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg8BgAAAAk"]
[Mon Jul 20 07:33:25.193148 2026] [security2:error] [pid 156215:tid 156421] [client 103.106.165.44:62996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8IQAAAEw"]
[Mon Jul 20 07:33:25.193259 2026] [security2:error] [pid 156215:tid 156421] [client 103.106.165.44:62996] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8IQAAAEw"]
[Mon Jul 20 07:33:25.193694 2026] [security2:error] [pid 156215:tid 156423] [client 143.44.185.218:37116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8IAAAAE4"]
[Mon Jul 20 07:33:25.193790 2026] [security2:error] [pid 156215:tid 156423] [client 143.44.185.218:37116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8IAAAAE4"]
[Mon Jul 20 07:33:25.207211 2026] [security2:error] [pid 156215:tid 156360] [client 20.226.66.230:41700] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/sky.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8IgAAAA8"]
[Mon Jul 20 07:33:25.207285 2026] [security2:error] [pid 156215:tid 156360] [client 20.226.66.230:41700] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/sky.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8IgAAAA8"]
[Mon Jul 20 07:33:25.340088 2026] [security2:error] [pid 156215:tid 156433] [client 14.225.17.146:57421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7rAAAAFg"], referer: http://chestermonty.com/TEST
[Mon Jul 20 07:33:25.529187 2026] [security2:error] [pid 156215:tid 156350] [client 20.226.66.230:41352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/fffm.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8QAAAAAU"]
[Mon Jul 20 07:33:25.529269 2026] [security2:error] [pid 156215:tid 156350] [client 20.226.66.230:41352] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/fffm.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8QAAAAAU"]
[Mon Jul 20 07:33:25.545587 2026] [security2:error] [pid 156215:tid 156406] [client 43.163.206.70:45770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4jpcJ0fwhpxOKR8Yg8PwAAAD0"]
[Mon Jul 20 07:33:25.560470 2026] [security2:error] [pid 156215:tid 156362] [client 57.141.18.46:54680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jo8J0fwhpxOKR8Yg7fgAAESk"]
[Mon Jul 20 07:33:25.861815 2026] [security2:error] [pid 156215:tid 156403] [client 20.226.66.230:41363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/sixxis.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8VAAAADo"]
[Mon Jul 20 07:33:25.861905 2026] [security2:error] [pid 156215:tid 156403] [client 20.226.66.230:41363] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/sixxis.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8VAAAADo"]
[Mon Jul 20 07:33:25.980105 2026] [security2:error] [pid 156215:tid 156223] [remote 103.28.36.200:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8XwAADgc"]
[Mon Jul 20 07:33:26.049811 2026] [security2:error] [pid 156215:tid 156386] [client 117.211.236.168:58926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8ZwAAACk"]
[Mon Jul 20 07:33:26.049886 2026] [security2:error] [pid 156215:tid 156386] [client 117.211.236.168:58926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8ZwAAACk"]
[Mon Jul 20 07:33:26.209566 2026] [security2:error] [pid 156215:tid 156393] [client 20.226.66.230:41357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/yj09.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8cAAAADA"]
[Mon Jul 20 07:33:26.209679 2026] [security2:error] [pid 156215:tid 156393] [client 20.226.66.230:41357] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/yj09.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8cAAAADA"]
[Mon Jul 20 07:33:26.269587 2026] [security2:error] [pid 156215:tid 156427] [client 14.225.17.146:62115] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8bwAAAFI"], referer: https://chestermonty.com/TEST
[Mon Jul 20 07:33:26.419680 2026] [security2:error] [pid 156215:tid 156412] [client 57.141.18.31:36916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jpMJ0fwhpxOKR8Yg72AAAQ3c"]
[Mon Jul 20 07:33:26.455341 2026] [security2:error] [pid 156215:tid 156457] [client 103.176.215.66:50764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8hAAAAHA"]
[Mon Jul 20 07:33:26.455464 2026] [security2:error] [pid 156215:tid 156457] [client 103.176.215.66:50764] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8hAAAAHA"]
[Mon Jul 20 07:33:26.527542 2026] [security2:error] [pid 156215:tid 156440] [client 20.226.66.230:41368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/f900.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8jAAAAF8"]
[Mon Jul 20 07:33:26.527639 2026] [security2:error] [pid 156215:tid 156440] [client 20.226.66.230:41368] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/f900.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8jAAAAF8"]
[Mon Jul 20 07:33:26.542573 2026] [security2:error] [pid 156215:tid 156299] [remote 103.28.36.200:41128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.36.28.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8jgAABFM"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:33:26.560561 2026] [security2:error] [pid 156215:tid 156388] [client 45.3.44.87:55549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8jwAAACs"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:26.562167 2026] [security2:error] [pid 156215:tid 156236] [remote 148.251.82.243:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.82.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8jQAAPxQ"]
[Mon Jul 20 07:33:26.579558 2026] [security2:error] [pid 156215:tid 156368] [client 47.128.40.205:33634] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "securingmemories.com"] [uri "/robots.txt"] [unique_id "al4jpsJ0fwhpxOKR8Yg8kwAAABc"]
[Mon Jul 20 07:33:26.591696 2026] [security2:error] [pid 156215:tid 156405] [client 89.238.167.150:44332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8lQAAADw"]
[Mon Jul 20 07:33:26.591791 2026] [security2:error] [pid 156215:tid 156405] [client 89.238.167.150:44332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8lQAAADw"]
[Mon Jul 20 07:33:26.713985 2026] [security2:error] [pid 156215:tid 156466] [client 104.234.53.92:53237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8mgAAAHk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:26.740493 2026] [security2:error] [pid 156215:tid 156268] [remote 148.251.82.243:57874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 243.82.251.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8ngAABTQ"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:33:26.843841 2026] [security2:error] [pid 156215:tid 156436] [client 20.226.66.230:41690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ups.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8rQAAAFs"]
[Mon Jul 20 07:33:26.843942 2026] [security2:error] [pid 156215:tid 156436] [client 20.226.66.230:41690] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ups.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8rQAAAFs"]
[Mon Jul 20 07:33:27.089963 2026] [security2:error] [pid 156215:tid 156348] [client 57.141.18.90:30756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8JAAAA1E"]
[Mon Jul 20 07:33:27.154899 2026] [security2:error] [pid 156215:tid 156413] [client 57.141.18.34:33516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jpcJ0fwhpxOKR8Yg8JQAARGk"]
[Mon Jul 20 07:33:27.204910 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/k.php"] [unique_id "al4jp8J0fwhpxOKR8Yg8wwAAAGU"]
[Mon Jul 20 07:33:27.205010 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/k.php"] [unique_id "al4jp8J0fwhpxOKR8Yg8wwAAAGU"]
[Mon Jul 20 07:33:27.525333 2026] [security2:error] [pid 156215:tid 156388] [client 20.226.66.230:41719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/k2.php"] [unique_id "al4jp8J0fwhpxOKR8Yg85AAAACs"]
[Mon Jul 20 07:33:27.525456 2026] [security2:error] [pid 156215:tid 156388] [client 20.226.66.230:41719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/k2.php"] [unique_id "al4jp8J0fwhpxOKR8Yg85AAAACs"]
[Mon Jul 20 07:33:27.567888 2026] [core:error] [pid 156215:tid 156345] [client 14.225.17.146:50444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:27.567906 2026] [core:error] [pid 156215:tid 156345] [client 14.225.17.146:50444] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:27.611253 2026] [security2:error] [pid 156215:tid 156362] [client 49.37.242.14:53684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jp8J0fwhpxOKR8Yg87gAAABE"]
[Mon Jul 20 07:33:27.611351 2026] [security2:error] [pid 156215:tid 156362] [client 49.37.242.14:53684] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jp8J0fwhpxOKR8Yg87gAAABE"]
[Mon Jul 20 07:33:27.654525 2026] [security2:error] [pid 156215:tid 156377] [client 14.225.17.146:61914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4jp8J0fwhpxOKR8Yg87AAAACA"], referer: http://mourgroup.com/TEST
[Mon Jul 20 07:33:27.844243 2026] [security2:error] [pid 156215:tid 156471] [client 20.226.66.230:41720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/w.php"] [unique_id "al4jp8J0fwhpxOKR8Yg9AAAAAH4"]
[Mon Jul 20 07:33:27.844359 2026] [security2:error] [pid 156215:tid 156471] [client 20.226.66.230:41720] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/w.php"] [unique_id "al4jp8J0fwhpxOKR8Yg9AAAAAH4"]
[Mon Jul 20 07:33:27.953163 2026] [security2:error] [pid 156215:tid 156455] [client 57.141.18.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jp8J0fwhpxOKR8Yg8-wAAAG4"]
[Mon Jul 20 07:33:28.170714 2026] [security2:error] [pid 156215:tid 156327] [remote 45.90.123.233:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9HAAAUm8"]
[Mon Jul 20 07:33:28.252572 2026] [security2:error] [pid 156215:tid 156414] [client 20.226.66.230:41391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/fpwch.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9HwAAAEU"]
[Mon Jul 20 07:33:28.252653 2026] [security2:error] [pid 156215:tid 156414] [client 20.226.66.230:41391] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/fpwch.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9HwAAAEU"]
[Mon Jul 20 07:33:28.396681 2026] [security2:error] [pid 156215:tid 156217] [remote 45.90.123.233:58008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9MQAAEAE"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:33:28.438796 2026] [security2:error] [pid 156215:tid 156432] [client 14.182.195.220:52770] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4jqMJ0fwhpxOKR8Yg9OAAAAFc"]
[Mon Jul 20 07:33:28.591781 2026] [security2:error] [pid 156215:tid 156357] [client 20.226.66.230:41374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/w2025.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9TAAAAAw"]
[Mon Jul 20 07:33:28.591914 2026] [security2:error] [pid 156215:tid 156357] [client 20.226.66.230:41374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/w2025.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9TAAAAAw"]
[Mon Jul 20 07:33:28.692665 2026] [security2:error] [pid 156215:tid 156452] [client 57.141.18.106:35036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jpsJ0fwhpxOKR8Yg8sgAAayQ"]
[Mon Jul 20 07:33:28.867609 2026] [security2:error] [pid 156215:tid 156265] [remote 192.241.143.148:54556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9XQAAdjE"]
[Mon Jul 20 07:33:28.878466 2026] [security2:error] [pid 156215:tid 156394] [client 104.234.53.78:43823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9XwAAADE"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:28.987757 2026] [security2:error] [pid 156215:tid 156353] [client 20.226.66.230:41371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/FWAZ.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9ZwAAAAg"]
[Mon Jul 20 07:33:28.987846 2026] [security2:error] [pid 156215:tid 156353] [client 20.226.66.230:41371] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/FWAZ.php"] [unique_id "al4jqMJ0fwhpxOKR8Yg9ZwAAAAg"]
[Mon Jul 20 07:33:29.067793 2026] [autoindex:error] [pid 156215:tid 156242] [remote 34.27.108.221:62565] AH01276: Cannot serve directory /home2/brsjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://brs.jiv.mybluehost.me
[Mon Jul 20 07:33:29.131051 2026] [security2:error] [pid 156215:tid 156339] [remote 192.241.143.148:54556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9egAAcXs"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:33:29.267454 2026] [security2:error] [pid 156215:tid 156368] [client 14.225.17.146:50430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4jp8J0fwhpxOKR8Yg9AgAAABc"], referer: http://detroitcsc.com/TEST
[Mon Jul 20 07:33:29.356061 2026] [core:error] [pid 156215:tid 156388] [client 193.56.28.232:25689] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:29.356081 2026] [core:error] [pid 156215:tid 156388] [client 193.56.28.232:25689] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:33:29.397426 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:41373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/qterm.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9hgAAAHI"]
[Mon Jul 20 07:33:29.397521 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:41373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/qterm.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9hgAAAHI"]
[Mon Jul 20 07:33:29.580432 2026] [security2:error] [pid 156215:tid 156264] [remote 160.187.68.132:47016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9lQAAUjA"]
[Mon Jul 20 07:33:29.738786 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/blurbs.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9pwAAACQ"]
[Mon Jul 20 07:33:29.738880 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/blurbs.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9pwAAACQ"]
[Mon Jul 20 07:33:29.783528 2026] [ssl:error] [pid 156215:tid 156428] [client 104.48.69.105:49934] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:33:29.935212 2026] [security2:error] [pid 156215:tid 156244] [remote 57.141.18.12:63362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4604958"] [unique_id "al4jqcJ0fwhpxOKR8Yg9uwAAMRw"]
[Mon Jul 20 07:33:30.093404 2026] [security2:error] [pid 156215:tid 156442] [client 20.226.66.230:41719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/v543.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg9zQAAAGE"]
[Mon Jul 20 07:33:30.093496 2026] [security2:error] [pid 156215:tid 156442] [client 20.226.66.230:41719] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/v543.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg9zQAAAGE"]
[Mon Jul 20 07:33:30.188427 2026] [security2:error] [pid 156215:tid 156222] [remote 160.187.68.132:47016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3dprintrecycling.com"] [uri "/wp-login.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg92QAAFgY"], referer: https://3dprintrecycling.com/wp-login.php
[Mon Jul 20 07:33:30.401832 2026] [core:error] [pid 156215:tid 156449] [client 14.225.17.146:61640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/TEST
[Mon Jul 20 07:33:30.401861 2026] [core:error] [pid 156215:tid 156449] [client 14.225.17.146:61640] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/TEST
[Mon Jul 20 07:33:30.421211 2026] [security2:error] [pid 156215:tid 156396] [client 20.226.66.230:41345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/w3lls.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg95gAAADM"]
[Mon Jul 20 07:33:30.421301 2026] [security2:error] [pid 156215:tid 156396] [client 20.226.66.230:41345] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/w3lls.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg95gAAADM"]
[Mon Jul 20 07:33:30.759374 2026] [security2:error] [pid 156215:tid 156234] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg-AgAAdRI"]
[Mon Jul 20 07:33:30.759544 2026] [security2:error] [pid 156215:tid 156462] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg-AgAAdRI"]
[Mon Jul 20 07:33:30.767349 2026] [security2:error] [pid 156215:tid 156438] [client 20.226.66.230:41688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-ws68.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg-AwAAAF0"]
[Mon Jul 20 07:33:30.767442 2026] [security2:error] [pid 156215:tid 156438] [client 20.226.66.230:41688] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-ws68.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg-AwAAAF0"]
[Mon Jul 20 07:33:30.995016 2026] [security2:error] [pid 156215:tid 156412] [client 50.116.65.227:27396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jqsJ0fwhpxOKR8Yg-GQAAAEM"]
[Mon Jul 20 07:33:31.004788 2026] [security2:error] [pid 156215:tid 156382] [client 50.116.65.227:27400] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jq8J0fwhpxOKR8Yg-GwAAACU"]
[Mon Jul 20 07:33:31.172964 2026] [security2:error] [pid 156215:tid 156398] [client 20.226.66.230:41370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/xyn.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-KgAAADU"]
[Mon Jul 20 07:33:31.173131 2026] [security2:error] [pid 156215:tid 156398] [client 20.226.66.230:41370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/xyn.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-KgAAADU"]
[Mon Jul 20 07:33:31.280874 2026] [security2:error] [pid 156215:tid 156468] [client 149.0.16.108:52958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-OQAAAHs"]
[Mon Jul 20 07:33:31.281004 2026] [security2:error] [pid 156215:tid 156468] [client 149.0.16.108:52958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-OQAAAHs"]
[Mon Jul 20 07:33:31.403195 2026] [security2:error] [pid 156215:tid 156397] [client 57.141.18.29:26558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jqcJ0fwhpxOKR8Yg9hwAANAU"]
[Mon Jul 20 07:33:31.517934 2026] [security2:error] [pid 156215:tid 156442] [client 50.116.65.227:27418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-PwAAAGE"]
[Mon Jul 20 07:33:31.521022 2026] [security2:error] [pid 156215:tid 156348] [client 145.239.10.137:58967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wolv2.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-SgAAAAM"], referer: http://iagdevelopments.com/wolv2.php
[Mon Jul 20 07:33:31.548832 2026] [security2:error] [pid 156215:tid 156346] [client 20.226.66.230:41380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/green3.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-TwAAAAE"]
[Mon Jul 20 07:33:31.548938 2026] [security2:error] [pid 156215:tid 156346] [client 20.226.66.230:41380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/green3.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-TwAAAAE"]
[Mon Jul 20 07:33:31.667226 2026] [security2:error] [pid 156215:tid 156462] [client 144.16.21.149:36161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-WwAAAHU"]
[Mon Jul 20 07:33:31.667314 2026] [security2:error] [pid 156215:tid 156462] [client 144.16.21.149:36161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-WwAAAHU"]
[Mon Jul 20 07:33:31.702851 2026] [security2:error] [pid 156215:tid 156469] [client 50.116.65.227:27430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-SwAAAHw"]
[Mon Jul 20 07:33:31.740634 2026] [security2:error] [pid 156215:tid 156282] [remote 124.55.178.99:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-YAAAQ0I"]
[Mon Jul 20 07:33:31.776581 2026] [security2:error] [pid 156215:tid 156323] [remote 5.161.225.162:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-ZAAACWs"]
[Mon Jul 20 07:33:31.873981 2026] [security2:error] [pid 156215:tid 156439] [client 14.225.17.146:50203] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-XQAAAF4"], referer: http://fkconstructionfunding.com/TEST
[Mon Jul 20 07:33:31.891038 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ccc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-aAAAAGU"]
[Mon Jul 20 07:33:31.891146 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41379] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ccc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-aAAAAGU"]
[Mon Jul 20 07:33:31.911066 2026] [security2:error] [pid 156215:tid 156384] [client 155.2.215.80:52441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-XwAAACc"]
[Mon Jul 20 07:33:31.934716 2026] [security2:error] [pid 156215:tid 156279] [remote 42.200.84.61:34790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-bAAAKD8"]
[Mon Jul 20 07:33:31.934864 2026] [security2:error] [pid 156215:tid 156385] [client 42.200.84.61:34790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-bAAAKD8"]
[Mon Jul 20 07:33:32.009038 2026] [security2:error] [pid 156215:tid 156305] [remote 5.161.225.162:59120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-cgAATlk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:32.075192 2026] [security2:error] [pid 156215:tid 156351] [client 57.141.18.10:59546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg9ywAABh0"]
[Mon Jul 20 07:33:32.144884 2026] [security2:error] [pid 156215:tid 156227] [remote 124.55.178.99:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-fAAAJgs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:32.219732 2026] [security2:error] [pid 156215:tid 156443] [client 20.226.66.230:41351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/get.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-hwAAAGI"]
[Mon Jul 20 07:33:32.219888 2026] [security2:error] [pid 156215:tid 156443] [client 20.226.66.230:41351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/get.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-hwAAAGI"]
[Mon Jul 20 07:33:32.362640 2026] [security2:error] [pid 156215:tid 156345] [client 157.20.138.62:64826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-lgAAAAA"]
[Mon Jul 20 07:33:32.362812 2026] [security2:error] [pid 156215:tid 156345] [client 157.20.138.62:64826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-lgAAAAA"]
[Mon Jul 20 07:33:32.445592 2026] [security2:error] [pid 156215:tid 156456] [client 57.141.18.63:48412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg97AAAb38"]
[Mon Jul 20 07:33:32.599563 2026] [security2:error] [pid 156215:tid 156443] [client 20.226.66.230:41354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/images.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-pAAAAGI"]
[Mon Jul 20 07:33:32.599658 2026] [security2:error] [pid 156215:tid 156443] [client 20.226.66.230:41354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/images.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-pAAAAGI"]
[Mon Jul 20 07:33:32.736645 2026] [security2:error] [pid 156215:tid 156435] [client 57.141.18.20:29434] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jqsJ0fwhpxOKR8Yg-AAAAWlE"]
[Mon Jul 20 07:33:32.743498 2026] [security2:error] [pid 156215:tid 156389] [client 49.47.218.174:12546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-rgAAACw"]
[Mon Jul 20 07:33:32.743575 2026] [security2:error] [pid 156215:tid 156389] [client 49.47.218.174:12546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-rgAAACw"]
[Mon Jul 20 07:33:32.860709 2026] [autoindex:error] [pid 156215:tid 156300] [remote 34.48.215.173:61008] AH01276: Cannot serve directory /home2/uhiwfwmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.uhi.wfw.mybluehost.me
[Mon Jul 20 07:33:32.961345 2026] [security2:error] [pid 156215:tid 156371] [client 104.234.53.94:37427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-wQAAABo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:32.972294 2026] [security2:error] [pid 156215:tid 156286] [remote 220.181.108.159:57070] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4jrMJ0fwhpxOKR8Yg-wgAAT0Y"]
[Mon Jul 20 07:33:33.125860 2026] [security2:error] [pid 156215:tid 156467] [client 57.141.18.81:31238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jq8J0fwhpxOKR8Yg-JQAAeko"]
[Mon Jul 20 07:33:33.228276 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/alls.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-3AAAACQ"]
[Mon Jul 20 07:33:33.228398 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41685] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/alls.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-3AAAACQ"]
[Mon Jul 20 07:33:33.228902 2026] [security2:error] [pid 156215:tid 156377] [client 14.225.17.146:61665] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-yQAAACA"]
[Mon Jul 20 07:33:33.250913 2026] [security2:error] [pid 156215:tid 156445] [client 136.158.60.21:30563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-3QAAAGQ"]
[Mon Jul 20 07:33:33.251044 2026] [security2:error] [pid 156215:tid 156445] [client 136.158.60.21:30563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-3QAAAGQ"]
[Mon Jul 20 07:33:33.265252 2026] [security2:error] [pid 156215:tid 156391] [client 202.141.11.99:22225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-4AAAAC4"]
[Mon Jul 20 07:33:33.265362 2026] [security2:error] [pid 156215:tid 156391] [client 202.141.11.99:22225] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-4AAAAC4"]
[Mon Jul 20 07:33:33.314138 2026] [security2:error] [pid 156215:tid 156298] [remote 5.161.225.162:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-5gAALVI"]
[Mon Jul 20 07:33:33.536972 2026] [security2:error] [pid 156215:tid 156218] [remote 5.161.225.162:59124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg--AAAYgI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:33:33.604608 2026] [security2:error] [pid 156215:tid 156348] [client 20.226.66.230:41365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/coffexium.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-_QAAAAM"]
[Mon Jul 20 07:33:33.604688 2026] [security2:error] [pid 156215:tid 156348] [client 20.226.66.230:41365] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/coffexium.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-_QAAAAM"]
[Mon Jul 20 07:33:33.969166 2026] [security2:error] [pid 156215:tid 156384] [client 20.226.66.230:41382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/red.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg_EwAAACc"]
[Mon Jul 20 07:33:33.969285 2026] [security2:error] [pid 156215:tid 156384] [client 20.226.66.230:41382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/red.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg_EwAAACc"]
[Mon Jul 20 07:33:34.002603 2026] [security2:error] [pid 156215:tid 156427] [client 14.225.17.146:61472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-kQAAAFI"]
[Mon Jul 20 07:33:34.179095 2026] [security2:error] [pid 156215:tid 156424] [client 63.176.132.15:62736] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_JwAAAE8"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:34.350882 2026] [security2:error] [pid 156215:tid 156365] [client 14.225.17.146:50228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_KwAAABQ"], referer: http://backandneckpainrelieflaceychiropractor.com/TEST
[Mon Jul 20 07:33:34.472999 2026] [security2:error] [pid 156215:tid 156455] [client 20.226.66.230:41385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4jrsJ0fwhpxOKR8Yg_RgAAAG4"]
[Mon Jul 20 07:33:34.489640 2026] [security2:error] [pid 156215:tid 156450] [client 188.166.209.66:63175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/abilities.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_SgAAAGk"], referer: binance.com
[Mon Jul 20 07:33:34.585604 2026] [security2:error] [pid 156215:tid 156466] [client 36.93.152.155:57803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_UAAAAHk"]
[Mon Jul 20 07:33:34.585715 2026] [security2:error] [pid 156215:tid 156466] [client 36.93.152.155:57803] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_UAAAAHk"]
[Mon Jul 20 07:33:34.589483 2026] [security2:error] [pid 156215:tid 156359] [client 191.202.66.27:60177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_UQAAAA4"]
[Mon Jul 20 07:33:34.589604 2026] [security2:error] [pid 156215:tid 156359] [client 191.202.66.27:60177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_UQAAAA4"]
[Mon Jul 20 07:33:34.593038 2026] [security2:error] [pid 156215:tid 156380] [client 154.192.123.127:17498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_UwAAACM"]
[Mon Jul 20 07:33:34.593124 2026] [security2:error] [pid 156215:tid 156380] [client 154.192.123.127:17498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_UwAAACM"]
[Mon Jul 20 07:33:34.644174 2026] [security2:error] [pid 156215:tid 156321] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_VgAATmk"]
[Mon Jul 20 07:33:34.644297 2026] [security2:error] [pid 156215:tid 156423] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_VgAATmk"]
[Mon Jul 20 07:33:34.657410 2026] [security2:error] [pid 156215:tid 156432] [client 179.127.84.238:62744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_XAAAAFc"]
[Mon Jul 20 07:33:34.657627 2026] [security2:error] [pid 156215:tid 156432] [client 179.127.84.238:62744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_XAAAAFc"]
[Mon Jul 20 07:33:34.742931 2026] [security2:error] [pid 156215:tid 156424] [client 63.177.52.239:53584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_ZgAAAE8"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:34.774037 2026] [security2:error] [pid 156215:tid 156408] [client 57.141.18.7:30262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-pgAAPxM"]
[Mon Jul 20 07:33:34.989959 2026] [security2:error] [pid 156215:tid 156403] [client 57.141.18.22:59360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-xAAAOkE"]
[Mon Jul 20 07:33:35.079647 2026] [autoindex:error] [pid 156215:tid 156349] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/sodium_compat/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:35.080212 2026] [security2:error] [pid 156215:tid 156349] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jr8J0fwhpxOKR8Yg_gwAAAAQ"]
[Mon Jul 20 07:33:35.083138 2026] [security2:error] [pid 156215:tid 156467] [client 20.226.66.230:41385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4jr8J0fwhpxOKR8Yg_gAAAAHo"]
[Mon Jul 20 07:33:35.204738 2026] [lsapi:warn] [pid 156215:tid 156412] [client 14.225.17.146:61583] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/TEST
[Mon Jul 20 07:33:35.204774 2026] [lsapi:warn] [pid 156215:tid 156412] [client 14.225.17.146:61583] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/TEST
[Mon Jul 20 07:33:35.247660 2026] [security2:error] [pid 156215:tid 156368] [client 20.226.66.230:41385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_kAAAABc"]
[Mon Jul 20 07:33:35.247771 2026] [security2:error] [pid 156215:tid 156368] [client 20.226.66.230:41385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_kAAAABc"]
[Mon Jul 20 07:33:35.252456 2026] [security2:error] [pid 156215:tid 156453] [client 14.225.17.146:61686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg_DgAAAGw"], referer: http://colinkeyphotography.com/TEST
[Mon Jul 20 07:33:35.321679 2026] [security2:error] [pid 156215:tid 156402] [client 14.225.17.146:52368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_hQAAADk"], referer: http://savilerowtravel.com/TEST
[Mon Jul 20 07:33:35.423697 2026] [security2:error] [pid 156215:tid 156352] [client 57.141.18.22:59366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-5wAAByk"]
[Mon Jul 20 07:33:35.435389 2026] [security2:error] [pid 156215:tid 156364] [client 57.141.18.74:52640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-5QAAE2Y"]
[Mon Jul 20 07:33:35.600526 2026] [security2:error] [pid 156215:tid 156468] [client 20.226.66.230:41399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/Text/"] [unique_id "al4jr8J0fwhpxOKR8Yg_qwAAAHs"]
[Mon Jul 20 07:33:35.606343 2026] [security2:error] [pid 156215:tid 156376] [client 57.141.18.86:35300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrcJ0fwhpxOKR8Yg-9AAAHw8"]
[Mon Jul 20 07:33:35.698360 2026] [security2:error] [pid 156215:tid 156424] [client 103.106.165.44:63489] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_rQAAAE8"]
[Mon Jul 20 07:33:35.698471 2026] [security2:error] [pid 156215:tid 156424] [client 103.106.165.44:63489] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_rQAAAE8"]
[Mon Jul 20 07:33:35.712070 2026] [lsapi:warn] [pid 156215:tid 156371] [client 50.116.65.227:27480] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:33:35.712090 2026] [lsapi:warn] [pid 156215:tid 156371] [client 50.116.65.227:27480] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:33:35.727242 2026] [security2:error] [pid 156215:tid 156412] [client 14.225.17.146:61583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_XwAAAEM"], referer: http://oswegooperatheater.com/TEST
[Mon Jul 20 07:33:35.795853 2026] [security2:error] [pid 156215:tid 156429] [client 14.225.17.146:61788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_TQAAAFQ"], referer: http://cloudspacesgroup.com/TEST
[Mon Jul 20 07:33:35.805009 2026] [autoindex:error] [pid 156215:tid 156375] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/Text/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:35.805542 2026] [security2:error] [pid 156215:tid 156375] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jr8J0fwhpxOKR8Yg_wAAAAB4"]
[Mon Jul 20 07:33:35.813494 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/Text/"] [unique_id "al4jr8J0fwhpxOKR8Yg_ugAAADw"]
[Mon Jul 20 07:33:35.853267 2026] [security2:error] [pid 156215:tid 156450] [client 74.208.214.194:46162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_wwAAAGk"]
[Mon Jul 20 07:33:35.986196 2026] [security2:error] [pid 156215:tid 156423] [client 20.226.66.230:41399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/uploads/"] [unique_id "al4jr8J0fwhpxOKR8Yg_zgAAAE4"]
[Mon Jul 20 07:33:35.995874 2026] [security2:error] [pid 156215:tid 156385] [client 104.234.53.88:58267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_zwAAACg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:36.183651 2026] [autoindex:error] [pid 156215:tid 156401] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:36.184532 2026] [security2:error] [pid 156215:tid 156401] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jsMJ0fwhpxOKR8Yg_4AAAADg"]
[Mon Jul 20 07:33:36.187652 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41385] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/uploads/"] [unique_id "al4jsMJ0fwhpxOKR8Yg_2QAAADw"]
[Mon Jul 20 07:33:36.249735 2026] [security2:error] [pid 156215:tid 156452] [client 65.111.26.171:36077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_4wAAAGs"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:36.272423 2026] [security2:error] [pid 156215:tid 156349] [client 103.139.191.61:63766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_5gAAAAQ"]
[Mon Jul 20 07:33:36.275094 2026] [security2:error] [pid 156215:tid 156349] [client 103.139.191.61:63766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_5gAAAAQ"]
[Mon Jul 20 07:33:36.292793 2026] [security2:error] [pid 156215:tid 156312] [remote 165.73.0.178:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.0.73.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thestudioatfruitland.com"] [uri "/wp-login.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_6AAAF2A"]
[Mon Jul 20 07:33:36.326583 2026] [security2:error] [pid 156215:tid 156437] [client 14.225.17.146:49859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_fwAAAFw"], referer: http://whiteoutcb.com/TEST
[Mon Jul 20 07:33:36.353697 2026] [security2:error] [pid 156215:tid 156389] [client 20.226.66.230:41399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/index.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_8QAAACw"]
[Mon Jul 20 07:33:36.353812 2026] [security2:error] [pid 156215:tid 156389] [client 20.226.66.230:41399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/index.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_8QAAACw"]
[Mon Jul 20 07:33:36.484892 2026] [security2:error] [pid 156215:tid 156366] [client 57.141.18.118:44704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_IgAAFTQ"]
[Mon Jul 20 07:33:36.594782 2026] [lsapi:warn] [pid 156215:tid 156413] [client 14.225.17.146:52430] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/TEST
[Mon Jul 20 07:33:36.594811 2026] [lsapi:warn] [pid 156215:tid 156413] [client 14.225.17.146:52430] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/TEST
[Mon Jul 20 07:33:36.648740 2026] [security2:error] [pid 156215:tid 156413] [client 14.225.17.146:52430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAAgAAAEQ"], referer: https://oswegooperatheater.com/TEST
[Mon Jul 20 07:33:36.684155 2026] [security2:error] [pid 156215:tid 156349] [client 20.226.66.230:41358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/admin.php"] [unique_id "al4jsMJ0fwhpxOKR8YhADQAAAAQ"]
[Mon Jul 20 07:33:36.684250 2026] [security2:error] [pid 156215:tid 156349] [client 20.226.66.230:41358] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/admin.php"] [unique_id "al4jsMJ0fwhpxOKR8YhADQAAAAQ"]
[Mon Jul 20 07:33:36.691692 2026] [security2:error] [pid 156215:tid 156446] [client 57.141.18.79:35736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_NAAAZVM"]
[Mon Jul 20 07:33:36.818239 2026] [security2:error] [pid 156215:tid 156325] [remote 165.73.0.178:58162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.0.73.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thestudioatfruitland.com"] [uri "/wp-login.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAFwAAX20"], referer: https://thestudioatfruitland.com/wp-login.php
[Mon Jul 20 07:33:36.856577 2026] [security2:error] [pid 156215:tid 156421] [client 139.59.118.64:62889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tallerherbal-com-mx.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAGQAAAEw"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 07:33:36.888280 2026] [security2:error] [pid 156215:tid 156272] [remote 42.200.84.61:45062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAIAAAKzg"]
[Mon Jul 20 07:33:36.893064 2026] [security2:error] [pid 156215:tid 156395] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.recalibratemed.com"] [uri "/index.php"] [unique_id "al4jrMJ0fwhpxOKR8Yg-wwAAADI"]
[Mon Jul 20 07:33:36.901536 2026] [security2:error] [pid 156215:tid 156463] [client 143.44.185.218:38617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAIwAAAHY"]
[Mon Jul 20 07:33:36.901614 2026] [security2:error] [pid 156215:tid 156463] [client 143.44.185.218:38617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAIwAAAHY"]
[Mon Jul 20 07:33:36.914009 2026] [security2:error] [pid 156215:tid 156286] [remote 119.249.100.179:13343] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4jsMJ0fwhpxOKR8YhAJwAAaUY"]
[Mon Jul 20 07:33:36.967312 2026] [security2:error] [pid 156215:tid 156468] [client 103.176.215.66:51296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jsMJ0fwhpxOKR8YhALgAAAHs"]
[Mon Jul 20 07:33:36.967909 2026] [security2:error] [pid 156215:tid 156468] [client 103.176.215.66:51296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jsMJ0fwhpxOKR8YhALgAAAHs"]
[Mon Jul 20 07:33:37.029202 2026] [security2:error] [pid 156215:tid 156413] [client 20.226.66.230:41674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/177.php"] [unique_id "al4jscJ0fwhpxOKR8YhAMQAAAEQ"]
[Mon Jul 20 07:33:37.029298 2026] [security2:error] [pid 156215:tid 156413] [client 20.226.66.230:41674] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/177.php"] [unique_id "al4jscJ0fwhpxOKR8YhAMQAAAEQ"]
[Mon Jul 20 07:33:37.145303 2026] [security2:error] [pid 156215:tid 156356] [client 57.141.18.108:44094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jrsJ0fwhpxOKR8Yg_aQAAC3A"]
[Mon Jul 20 07:33:37.272567 2026] [security2:error] [pid 156215:tid 156311] [remote 42.200.84.61:45062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "villa-m-medjugorje.com"] [uri "/wp-login.php"] [unique_id "al4jscJ0fwhpxOKR8YhAPQAAeF8"], referer: https://villa-m-medjugorje.com/wp-login.php
[Mon Jul 20 07:33:37.335688 2026] [ssl:error] [pid 156215:tid 156459] [client 104.48.69.105:49944] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:33:37.413461 2026] [security2:error] [pid 156215:tid 156438] [client 213.141.194.100:40414] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4jscJ0fwhpxOKR8YhASAAAXUk"]
[Mon Jul 20 07:33:37.434906 2026] [security2:error] [pid 156215:tid 156383] [client 20.226.66.230:41707] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/199.php"] [unique_id "al4jscJ0fwhpxOKR8YhATgAAACY"]
[Mon Jul 20 07:33:37.435027 2026] [security2:error] [pid 156215:tid 156383] [client 20.226.66.230:41707] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/199.php"] [unique_id "al4jscJ0fwhpxOKR8YhATgAAACY"]
[Mon Jul 20 07:33:37.582282 2026] [security2:error] [pid 156215:tid 156427] [client 98.159.234.160:31755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jscJ0fwhpxOKR8YhAXAAAAFI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:33:37.631800 2026] [security2:error] [pid 156215:tid 156374] [client 57.141.18.25:40286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jr8J0fwhpxOKR8Yg_pQAAHUI"]
[Mon Jul 20 07:33:37.755356 2026] [security2:error] [pid 156215:tid 156372] [client 3.67.192.83:24822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jscJ0fwhpxOKR8YhAZwAAABs"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:37.772650 2026] [security2:error] [pid 156215:tid 156395] [client 20.226.66.230:41693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/file52.php"] [unique_id "al4jscJ0fwhpxOKR8YhAaAAAADI"]
[Mon Jul 20 07:33:37.772741 2026] [security2:error] [pid 156215:tid 156395] [client 20.226.66.230:41693] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/file52.php"] [unique_id "al4jscJ0fwhpxOKR8YhAaAAAADI"]
[Mon Jul 20 07:33:37.818171 2026] [security2:error] [pid 156215:tid 156389] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4jscJ0fwhpxOKR8YhANgAALGc"], referer: http://ardhalwafaa.com/TEST
[Mon Jul 20 07:33:37.927374 2026] [ssl:error] [pid 156215:tid 156347] [client 104.48.69.105:49950] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:33:38.119167 2026] [security2:error] [pid 156215:tid 156387] [client 57.141.18.89:50224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jsMJ0fwhpxOKR8Yg_0QAAKgE"]
[Mon Jul 20 07:33:38.199281 2026] [security2:error] [pid 156215:tid 156395] [client 20.226.66.230:41681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/geck.php"] [unique_id "al4jssJ0fwhpxOKR8YhAkAAAADI"]
[Mon Jul 20 07:33:38.199391 2026] [security2:error] [pid 156215:tid 156395] [client 20.226.66.230:41681] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/geck.php"] [unique_id "al4jssJ0fwhpxOKR8YhAkAAAADI"]
[Mon Jul 20 07:33:38.496734 2026] [security2:error] [pid 156215:tid 156397] [client 14.225.17.146:65447] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4jsMJ0fwhpxOKR8YhAAAAAADQ"], referer: http://securingmemories.com/TEST
[Mon Jul 20 07:33:38.520435 2026] [security2:error] [pid 156215:tid 156383] [client 3.67.192.83:24826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jssJ0fwhpxOKR8YhAsgAAACY"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:38.595501 2026] [security2:error] [pid 156215:tid 156424] [client 63.179.149.246:11354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jssJ0fwhpxOKR8YhAuwAAAE8"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:38.659578 2026] [security2:error] [pid 156215:tid 156438] [client 20.226.66.230:41672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/biufile.php"] [unique_id "al4jssJ0fwhpxOKR8YhAvwAAAF0"]
[Mon Jul 20 07:33:38.659668 2026] [security2:error] [pid 156215:tid 156438] [client 20.226.66.230:41672] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/biufile.php"] [unique_id "al4jssJ0fwhpxOKR8YhAvwAAAF0"]
[Mon Jul 20 07:33:38.857716 2026] [security2:error] [pid 156215:tid 156350] [client 18.184.179.151:42208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jssJ0fwhpxOKR8YhAyAAAAAU"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:38.922430 2026] [security2:error] [pid 156215:tid 156230] [remote 72.167.132.114:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4jssJ0fwhpxOKR8YhAzQAAaw4"]
[Mon Jul 20 07:33:39.014444 2026] [security2:error] [pid 156215:tid 156421] [client 20.226.66.230:41684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/mosty.php"] [unique_id "al4js8J0fwhpxOKR8YhA2gAAAEw"]
[Mon Jul 20 07:33:39.014534 2026] [security2:error] [pid 156215:tid 156421] [client 20.226.66.230:41684] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/mosty.php"] [unique_id "al4js8J0fwhpxOKR8YhA2gAAAEw"]
[Mon Jul 20 07:33:39.040909 2026] [security2:error] [pid 156215:tid 156357] [client 18.184.179.151:42212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4js8J0fwhpxOKR8YhA4gAAAAw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:39.142677 2026] [security2:error] [pid 156215:tid 156405] [client 63.176.132.15:41456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4js8J0fwhpxOKR8YhA6wAAADw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:39.150116 2026] [security2:error] [pid 156215:tid 156318] [remote 72.167.132.114:57724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4js8J0fwhpxOKR8YhA6gAAGWY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:33:39.164535 2026] [security2:error] [pid 156215:tid 156349] [client 57.141.18.31:26498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jscJ0fwhpxOKR8YhANQAABBc"]
[Mon Jul 20 07:33:39.396703 2026] [security2:error] [pid 156215:tid 156345] [client 63.179.149.246:11366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4js8J0fwhpxOKR8YhBAwAAAAA"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:39.408015 2026] [security2:error] [pid 156215:tid 156266] [remote 111.225.214.195:33111] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4js8J0fwhpxOKR8YhBBQAAIjI"]
[Mon Jul 20 07:33:39.471319 2026] [security2:error] [pid 156215:tid 156348] [client 188.166.209.66:60317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/ai-client.php"] [unique_id "al4js8J0fwhpxOKR8YhBDAAAAAM"], referer: binance.com
[Mon Jul 20 07:33:39.478202 2026] [security2:error] [pid 156215:tid 156378] [client 20.226.66.230:41421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/dejavu.php"] [unique_id "al4js8J0fwhpxOKR8YhBDQAAACE"]
[Mon Jul 20 07:33:39.478302 2026] [security2:error] [pid 156215:tid 156378] [client 20.226.66.230:41421] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/dejavu.php"] [unique_id "al4js8J0fwhpxOKR8YhBDQAAACE"]
[Mon Jul 20 07:33:39.690403 2026] [security2:error] [pid 156215:tid 156408] [client 63.176.132.15:41470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4js8J0fwhpxOKR8YhBJAAAAD8"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:39.755347 2026] [security2:error] [pid 156215:tid 156368] [client 57.141.18.34:28516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jscJ0fwhpxOKR8YhAYQAAF1o"]
[Mon Jul 20 07:33:39.766015 2026] [security2:error] [pid 156215:tid 156395] [client 117.211.236.168:59670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4js8J0fwhpxOKR8YhBKAAAADI"]
[Mon Jul 20 07:33:39.766173 2026] [security2:error] [pid 156215:tid 156395] [client 117.211.236.168:59670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4js8J0fwhpxOKR8YhBKAAAADI"]
[Mon Jul 20 07:33:39.833564 2026] [security2:error] [pid 156215:tid 156356] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.rywventures.com"] [uri "/index.php"] [unique_id "al4js8J0fwhpxOKR8YhBIwAAAAs"]
[Mon Jul 20 07:33:39.863347 2026] [security2:error] [pid 156215:tid 156348] [client 20.226.66.230:41709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/aaf.php"] [unique_id "al4js8J0fwhpxOKR8YhBKwAAAAM"]
[Mon Jul 20 07:33:39.863465 2026] [security2:error] [pid 156215:tid 156348] [client 20.226.66.230:41709] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/aaf.php"] [unique_id "al4js8J0fwhpxOKR8YhBKwAAAAM"]
[Mon Jul 20 07:33:40.178728 2026] [security2:error] [pid 156215:tid 156372] [client 63.176.132.15:41474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBRgAAABs"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:40.225790 2026] [security2:error] [pid 156215:tid 156362] [client 57.141.18.47:55144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jssJ0fwhpxOKR8YhAjQAAEV4"]
[Mon Jul 20 07:33:40.379885 2026] [security2:error] [pid 156215:tid 156399] [client 57.141.18.24:36692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jssJ0fwhpxOKR8YhAnAAANiw"]
[Mon Jul 20 07:33:40.445038 2026] [security2:error] [pid 156215:tid 156435] [client 20.226.66.230:41715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ha.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBXAAAAFo"]
[Mon Jul 20 07:33:40.445147 2026] [security2:error] [pid 156215:tid 156435] [client 20.226.66.230:41715] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ha.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBXAAAAFo"]
[Mon Jul 20 07:33:40.500098 2026] [security2:error] [pid 156215:tid 156471] [client 45.157.112.60:27101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBZAAAAH4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:33:40.723670 2026] [security2:error] [pid 156215:tid 156437] [client 63.177.52.239:11854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBcwAAAFw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:33:40.784957 2026] [security2:error] [pid 156215:tid 156420] [client 57.141.18.84:63140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jssJ0fwhpxOKR8YhAwgAAS3U"]
[Mon Jul 20 07:33:40.795614 2026] [security2:error] [pid 156215:tid 156397] [client 20.226.66.230:41409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/hur.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBdwAAADQ"]
[Mon Jul 20 07:33:40.795762 2026] [security2:error] [pid 156215:tid 156397] [client 20.226.66.230:41409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/hur.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBdwAAADQ"]
[Mon Jul 20 07:33:41.089443 2026] [security2:error] [pid 156215:tid 156411] [client 14.225.17.146:52363] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4js8J0fwhpxOKR8YhBLQAAAEI"], referer: http://northbrookcpa.ca/TEST
[Mon Jul 20 07:33:41.180184 2026] [security2:error] [pid 156215:tid 156394] [client 20.226.66.230:41441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/h02ugyh.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBmQAAADE"]
[Mon Jul 20 07:33:41.180315 2026] [security2:error] [pid 156215:tid 156394] [client 20.226.66.230:41441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/h02ugyh.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBmQAAADE"]
[Mon Jul 20 07:33:41.246439 2026] [security2:error] [pid 156215:tid 156352] [client 14.225.17.146:52870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBhwAAAAc"], referer: http://tacticaltreeoperations.com/TEST
[Mon Jul 20 07:33:41.364557 2026] [security2:error] [pid 156215:tid 156401] [client 35.252.111.205:45776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.sarahholyfield.com"] [uri "/index.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBogAAADg"]
[Mon Jul 20 07:33:41.560153 2026] [security2:error] [pid 156215:tid 156450] [client 20.226.66.230:41705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/155.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBvAAAAGk"]
[Mon Jul 20 07:33:41.560265 2026] [security2:error] [pid 156215:tid 156450] [client 20.226.66.230:41705] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/155.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBvAAAAGk"]
[Mon Jul 20 07:33:41.603209 2026] [security2:error] [pid 156215:tid 156327] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBwQAAem8"]
[Mon Jul 20 07:33:41.603391 2026] [security2:error] [pid 156215:tid 156467] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBwQAAem8"]
[Mon Jul 20 07:33:41.667851 2026] [security2:error] [pid 156215:tid 156396] [client 49.37.242.14:54102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jtcJ0fwhpxOKR8YhByQAAADM"]
[Mon Jul 20 07:33:41.667963 2026] [security2:error] [pid 156215:tid 156396] [client 49.37.242.14:54102] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jtcJ0fwhpxOKR8YhByQAAADM"]
[Mon Jul 20 07:33:41.864500 2026] [security2:error] [pid 156215:tid 156351] [client 104.28.251.193:19811] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "massagelacey.com"] [uri "/.env"] [unique_id "al4jtcJ0fwhpxOKR8YhB2QAAAAY"]
[Mon Jul 20 07:33:41.874275 2026] [security2:error] [pid 156215:tid 156397] [client 43.157.96.189:39282] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "maxenengineering.com"] [uri "/"] [unique_id "al4jtcJ0fwhpxOKR8YhB2wAAADQ"]
[Mon Jul 20 07:33:41.881933 2026] [security2:error] [pid 156215:tid 156301] [remote 8.217.108.67:43676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4jtcJ0fwhpxOKR8YhB2gAAHVU"]
[Mon Jul 20 07:33:41.932520 2026] [security2:error] [pid 156215:tid 156425] [client 20.226.66.230:41367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/pp.php"] [unique_id "al4jtcJ0fwhpxOKR8YhB4AAAAFA"]
[Mon Jul 20 07:33:41.932637 2026] [security2:error] [pid 156215:tid 156425] [client 20.226.66.230:41367] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/pp.php"] [unique_id "al4jtcJ0fwhpxOKR8YhB4AAAAFA"]
[Mon Jul 20 07:33:41.933452 2026] [security2:error] [pid 156215:tid 156364] [client 43.205.139.3:13364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jtcJ0fwhpxOKR8YhB4QAAABM"]
[Mon Jul 20 07:33:42.062992 2026] [security2:error] [pid 156215:tid 156348] [client 149.0.16.108:53470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhB8gAAAAM"]
[Mon Jul 20 07:33:42.063131 2026] [security2:error] [pid 156215:tid 156348] [client 149.0.16.108:53470] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhB8gAAAAM"]
[Mon Jul 20 07:33:42.239879 2026] [security2:error] [pid 156215:tid 156378] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.saudalsubaie.com"] [uri "/index.php"] [unique_id "al4jtcJ0fwhpxOKR8YhB5AAAACE"]
[Mon Jul 20 07:33:42.287065 2026] [security2:error] [pid 156215:tid 156367] [client 20.226.66.230:41366] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ops.php"] [unique_id "al4jtsJ0fwhpxOKR8YhB_gAAABY"]
[Mon Jul 20 07:33:42.287175 2026] [security2:error] [pid 156215:tid 156367] [client 20.226.66.230:41366] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ops.php"] [unique_id "al4jtsJ0fwhpxOKR8YhB_gAAABY"]
[Mon Jul 20 07:33:42.307260 2026] [security2:error] [pid 156215:tid 156462] [client 144.16.21.149:28322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCAwAAAHU"]
[Mon Jul 20 07:33:42.307342 2026] [security2:error] [pid 156215:tid 156462] [client 144.16.21.149:28322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCAwAAAHU"]
[Mon Jul 20 07:33:42.357142 2026] [security2:error] [pid 156215:tid 156363] [client 113.160.97.242:58119] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4jtsJ0fwhpxOKR8YhCBwAAABI"]
[Mon Jul 20 07:33:42.445439 2026] [security2:error] [pid 156215:tid 156370] [client 191.5.111.222:25772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "muafaces.org"] [uri "/index.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBbgAAABk"]
[Mon Jul 20 07:33:42.509651 2026] [security2:error] [pid 156215:tid 156472] [client 57.141.18.12:44458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jtMJ0fwhpxOKR8YhBVgAAf2Q"]
[Mon Jul 20 07:33:42.569726 2026] [security2:error] [pid 156215:tid 156455] [client 142.111.152.181:30209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCCwAAAG4"]
[Mon Jul 20 07:33:42.681198 2026] [security2:error] [pid 156215:tid 156462] [client 20.226.66.230:41671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ingfo.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCKwAAAHU"]
[Mon Jul 20 07:33:42.681303 2026] [security2:error] [pid 156215:tid 156462] [client 20.226.66.230:41671] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ingfo.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCKwAAAHU"]
[Mon Jul 20 07:33:42.828546 2026] [security2:error] [pid 156215:tid 156356] [client 157.20.138.62:65387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCMQAAAAs"]
[Mon Jul 20 07:33:42.828704 2026] [security2:error] [pid 156215:tid 156356] [client 157.20.138.62:65387] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCMQAAAAs"]
[Mon Jul 20 07:33:42.916253 2026] [security2:error] [pid 156215:tid 156367] [client 43.205.139.3:18322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCPgAAABY"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:33:43.042589 2026] [security2:error] [pid 156215:tid 156420] [client 20.226.66.230:41673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/error_log.php"] [unique_id "al4jt8J0fwhpxOKR8YhCTAAAAEs"]
[Mon Jul 20 07:33:43.042794 2026] [security2:error] [pid 156215:tid 156420] [client 20.226.66.230:41673] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/error_log.php"] [unique_id "al4jt8J0fwhpxOKR8YhCTAAAAEs"]
[Mon Jul 20 07:33:43.057565 2026] [security2:error] [pid 156215:tid 156257] [remote 8.217.108.67:43676] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4jt8J0fwhpxOKR8YhCTQAARik"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:33:43.160711 2026] [security2:error] [pid 156215:tid 156417] [client 139.59.118.64:63558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.tallerherbal-com-mx.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4jt8J0fwhpxOKR8YhCVAAAAEg"], referer: https://www.bing.com/
[Mon Jul 20 07:33:43.162964 2026] [security2:error] [pid 156215:tid 156428] [client 57.141.18.103:44056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBjQAAUzA"]
[Mon Jul 20 07:33:43.183535 2026] [security2:error] [pid 156215:tid 156453] [client 49.47.218.174:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jt8J0fwhpxOKR8YhCVQAAAGw"]
[Mon Jul 20 07:33:43.183677 2026] [security2:error] [pid 156215:tid 156453] [client 49.47.218.174:63325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jt8J0fwhpxOKR8YhCVQAAAGw"]
[Mon Jul 20 07:33:43.256070 2026] [security2:error] [pid 156215:tid 156408] [client 50.116.65.227:53778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jt8J0fwhpxOKR8YhCWwAAAD8"]
[Mon Jul 20 07:33:43.269354 2026] [security2:error] [pid 156215:tid 156471] [client 50.116.65.227:53792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jt8J0fwhpxOKR8YhCXQAAAH4"]
[Mon Jul 20 07:33:43.362005 2026] [security2:error] [pid 156215:tid 156422] [client 14.225.17.146:53868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4jt8J0fwhpxOKR8YhCXAAAAE0"], referer: http://ncsynchro.com/TEST
[Mon Jul 20 07:33:43.375346 2026] [security2:error] [pid 156215:tid 156444] [client 20.226.66.230:41727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/test10.php"] [unique_id "al4jt8J0fwhpxOKR8YhCZQAAAGM"]
[Mon Jul 20 07:33:43.375459 2026] [security2:error] [pid 156215:tid 156444] [client 20.226.66.230:41727] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/test10.php"] [unique_id "al4jt8J0fwhpxOKR8YhCZQAAAGM"]
[Mon Jul 20 07:33:43.491585 2026] [security2:error] [pid 156215:tid 156393] [client 14.225.17.146:53325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhB6AAAADA"], referer: http://sarahsnyder.net/TEST
[Mon Jul 20 07:33:43.519622 2026] [security2:error] [pid 156215:tid 156372] [client 57.141.18.88:42548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jtcJ0fwhpxOKR8YhBpgAAGxs"]
[Mon Jul 20 07:33:43.727535 2026] [security2:error] [pid 156215:tid 156413] [client 20.226.66.230:41440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/koala.php"] [unique_id "al4jt8J0fwhpxOKR8YhCgwAAAEQ"]
[Mon Jul 20 07:33:43.727641 2026] [security2:error] [pid 156215:tid 156413] [client 20.226.66.230:41440] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/koala.php"] [unique_id "al4jt8J0fwhpxOKR8YhCgwAAAEQ"]
[Mon Jul 20 07:33:43.746775 2026] [security2:error] [pid 156215:tid 156346] [client 104.28.251.193:53559] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "massagelacey.com"] [uri "/wp-config.php~"] [unique_id "al4jt8J0fwhpxOKR8YhChQAAAAE"]
[Mon Jul 20 07:33:44.001666 2026] [security2:error] [pid 156215:tid 156352] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "weifangsmefarm.com"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhB8wAAAAc"]
[Mon Jul 20 07:33:44.008930 2026] [security2:error] [pid 156215:tid 156395] [client 216.73.216.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4jt8J0fwhpxOKR8YhCkwAAADI"]
[Mon Jul 20 07:33:44.048241 2026] [security2:error] [pid 156215:tid 156425] [client 136.158.60.21:32123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4juMJ0fwhpxOKR8YhCnwAAAFA"]
[Mon Jul 20 07:33:44.048388 2026] [security2:error] [pid 156215:tid 156425] [client 136.158.60.21:32123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4juMJ0fwhpxOKR8YhCnwAAAFA"]
[Mon Jul 20 07:33:44.095520 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/mac.php"] [unique_id "al4juMJ0fwhpxOKR8YhCpQAAAGU"]
[Mon Jul 20 07:33:44.095629 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41687] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/mac.php"] [unique_id "al4juMJ0fwhpxOKR8YhCpQAAAGU"]
[Mon Jul 20 07:33:44.128596 2026] [security2:error] [pid 156215:tid 156466] [client 57.141.18.29:33068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jtcJ0fwhpxOKR8YhB3AAAeWg"]
[Mon Jul 20 07:33:44.425238 2026] [security2:error] [pid 156215:tid 156352] [client 20.226.66.230:41377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wefile.php"] [unique_id "al4juMJ0fwhpxOKR8YhCvQAAAAc"]
[Mon Jul 20 07:33:44.425350 2026] [security2:error] [pid 156215:tid 156352] [client 20.226.66.230:41377] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wefile.php"] [unique_id "al4juMJ0fwhpxOKR8YhCvQAAAAc"]
[Mon Jul 20 07:33:44.527191 2026] [security2:error] [pid 156215:tid 156405] [client 104.28.251.193:38024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.251.28.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "massagelacey.com"] [uri "/wp-config.php"] [unique_id "al4juMJ0fwhpxOKR8YhCwQAAADw"]
[Mon Jul 20 07:33:44.546692 2026] [security2:error] [pid 156215:tid 156426] [client 14.225.17.146:54318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4juMJ0fwhpxOKR8YhCvAAAAFE"], referer: https://sarahsnyder.net/TEST
[Mon Jul 20 07:33:44.662002 2026] [security2:error] [pid 156215:tid 156402] [client 104.28.251.193:36883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCLAAAADk"]
[Mon Jul 20 07:33:44.662002 2026] [security2:error] [pid 156215:tid 156415] [client 104.28.251.193:36887] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCJQAAAGs"]
[Mon Jul 20 07:33:44.664913 2026] [security2:error] [pid 156215:tid 156414] [client 104.28.251.193:19811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCIQAAAEU"]
[Mon Jul 20 07:33:44.674836 2026] [security2:error] [pid 156215:tid 156407] [client 57.141.18.66:30894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCEgAAPn4"]
[Mon Jul 20 07:33:44.702769 2026] [security2:error] [pid 156215:tid 156368] [client 104.28.251.193:36878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jtsJ0fwhpxOKR8YhCHwAAACg"]
[Mon Jul 20 07:33:44.816163 2026] [security2:error] [pid 156215:tid 156278] [remote 57.141.18.109:50426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 109.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3966302"] [unique_id "al4juMJ0fwhpxOKR8YhC2QAAbD4"]
[Mon Jul 20 07:33:44.853397 2026] [security2:error] [pid 156215:tid 156438] [client 20.226.66.230:41429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4juMJ0fwhpxOKR8YhC4QAAAF0"]
[Mon Jul 20 07:33:44.925455 2026] [security2:error] [pid 156215:tid 156391] [client 154.192.123.127:17896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4juMJ0fwhpxOKR8YhC5gAAAC4"]
[Mon Jul 20 07:33:44.925619 2026] [security2:error] [pid 156215:tid 156391] [client 154.192.123.127:17896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4juMJ0fwhpxOKR8YhC5gAAAC4"]
[Mon Jul 20 07:33:44.994468 2026] [security2:error] [pid 156215:tid 156362] [client 104.28.251.193:38029] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "massagelacey.com"] [uri "/wp-config.php.old"] [unique_id "al4juMJ0fwhpxOKR8YhC6gAAABE"]
[Mon Jul 20 07:33:45.067086 2026] [security2:error] [pid 156215:tid 156289] [remote 134.209.147.209:37104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jucJ0fwhpxOKR8YhC9wAAHEk"]
[Mon Jul 20 07:33:45.088661 2026] [security2:error] [pid 156215:tid 156346] [client 36.93.152.155:58313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhC_AAAAAE"]
[Mon Jul 20 07:33:45.088771 2026] [security2:error] [pid 156215:tid 156346] [client 36.93.152.155:58313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhC_AAAAAE"]
[Mon Jul 20 07:33:45.099779 2026] [security2:error] [pid 156215:tid 156359] [client 104.28.251.193:38035] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "massagelacey.com"] [uri "/wp-config.php.bak"] [unique_id "al4jucJ0fwhpxOKR8YhC_QAAAA4"]
[Mon Jul 20 07:33:45.252163 2026] [security2:error] [pid 156215:tid 156382] [client 188.166.209.66:52717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "al4jucJ0fwhpxOKR8YhDCwAAACU"], referer: binance.com
[Mon Jul 20 07:33:45.284246 2026] [security2:error] [pid 156215:tid 156442] [client 191.202.66.27:60668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhDDgAAAGE"]
[Mon Jul 20 07:33:45.284366 2026] [security2:error] [pid 156215:tid 156442] [client 191.202.66.27:60668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhDDgAAAGE"]
[Mon Jul 20 07:33:45.325600 2026] [security2:error] [pid 156215:tid 156279] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhDEAAAVj8"]
[Mon Jul 20 07:33:45.325730 2026] [security2:error] [pid 156215:tid 156431] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhDEAAAVj8"]
[Mon Jul 20 07:33:45.355709 2026] [security2:error] [pid 156215:tid 156469] [client 179.127.84.238:63290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhDFQAAAHw"]
[Mon Jul 20 07:33:45.355841 2026] [security2:error] [pid 156215:tid 156469] [client 179.127.84.238:63290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jucJ0fwhpxOKR8YhDFQAAAHw"]
[Mon Jul 20 07:33:45.482352 2026] [security2:error] [pid 156215:tid 156340] [remote 134.209.147.209:37104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.147.209.134.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jucJ0fwhpxOKR8YhDJQAAO3w"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:45.590423 2026] [security2:error] [pid 156215:tid 156236] [remote 72.167.132.114:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jucJ0fwhpxOKR8YhDPQAAABQ"]
[Mon Jul 20 07:33:45.640892 2026] [autoindex:error] [pid 156215:tid 156391] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/blocks/post-comments-form/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:45.641461 2026] [security2:error] [pid 156215:tid 156391] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jucJ0fwhpxOKR8YhDQgAAAC4"]
[Mon Jul 20 07:33:45.643972 2026] [security2:error] [pid 156215:tid 156465] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4jucJ0fwhpxOKR8YhDPwAAAHg"]
[Mon Jul 20 07:33:45.803262 2026] [security2:error] [pid 156215:tid 156363] [client 20.226.66.230:41429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/js/"] [unique_id "al4jucJ0fwhpxOKR8YhDTwAAABI"]
[Mon Jul 20 07:33:45.805976 2026] [security2:error] [pid 156215:tid 156271] [remote 72.167.132.114:48236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jucJ0fwhpxOKR8YhDTgAAZjc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:45.979495 2026] [security2:error] [pid 156215:tid 156370] [client 57.141.18.26:31000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jt8J0fwhpxOKR8YhCjgAAGXI"]
[Mon Jul 20 07:33:46.029438 2026] [autoindex:error] [pid 156215:tid 156442] [client 20.226.66.230:41698] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-admin/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:46.029967 2026] [security2:error] [pid 156215:tid 156442] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/js/"] [unique_id "al4jucJ0fwhpxOKR8YhDVAAAAGE"]
[Mon Jul 20 07:33:46.062832 2026] [lsapi:warn] [pid 156215:tid 156391] [client 35.252.163.207:64577] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:33:46.062867 2026] [lsapi:warn] [pid 156215:tid 156391] [client 35.252.163.207:64577] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:33:46.101495 2026] [security2:error] [pid 156215:tid 156359] [client 65.111.21.110:27263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 110.21.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jusJ0fwhpxOKR8YhDYwAAAA4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:46.121775 2026] [security2:error] [pid 156215:tid 156391] [client 35.252.163.207:64577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4jusJ0fwhpxOKR8YhDYgAAAC4"]
[Mon Jul 20 07:33:46.157528 2026] [security2:error] [pid 156215:tid 156440] [client 103.106.165.44:63975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jusJ0fwhpxOKR8YhDZgAAAF8"]
[Mon Jul 20 07:33:46.157688 2026] [security2:error] [pid 156215:tid 156440] [client 103.106.165.44:63975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jusJ0fwhpxOKR8YhDZgAAAF8"]
[Mon Jul 20 07:33:46.173773 2026] [security2:error] [pid 156215:tid 156413] [client 35.252.163.207:64577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.163.252.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/xmlrpc.php"] [unique_id "al4jusJ0fwhpxOKR8YhDZwAAAEQ"]
[Mon Jul 20 07:33:46.188010 2026] [security2:error] [pid 156215:tid 156408] [client 20.226.66.230:41429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/makeasmtp.php"] [unique_id "al4jusJ0fwhpxOKR8YhDagAAAD8"]
[Mon Jul 20 07:33:46.188147 2026] [security2:error] [pid 156215:tid 156408] [client 20.226.66.230:41429] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/makeasmtp.php"] [unique_id "al4jusJ0fwhpxOKR8YhDagAAAD8"]
[Mon Jul 20 07:33:46.328373 2026] [security2:error] [pid 156215:tid 156468] [client 104.28.251.193:36878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jucJ0fwhpxOKR8YhDFwAAAHs"]
[Mon Jul 20 07:33:46.367583 2026] [security2:error] [pid 156215:tid 156428] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jucJ0fwhpxOKR8YhDGgAAAFM"]
[Mon Jul 20 07:33:46.479932 2026] [security2:error] [pid 156215:tid 156364] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jucJ0fwhpxOKR8YhDJAAAABM"]
[Mon Jul 20 07:33:46.495288 2026] [security2:error] [pid 156215:tid 156346] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jucJ0fwhpxOKR8YhDIgAAAAE"]
[Mon Jul 20 07:33:46.593853 2026] [security2:error] [pid 156215:tid 156398] [client 20.226.66.230:41344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/2P.php"] [unique_id "al4jusJ0fwhpxOKR8YhDjwAAADU"]
[Mon Jul 20 07:33:46.593977 2026] [security2:error] [pid 156215:tid 156398] [client 20.226.66.230:41344] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/2P.php"] [unique_id "al4jusJ0fwhpxOKR8YhDjwAAADU"]
[Mon Jul 20 07:33:46.697332 2026] [security2:error] [pid 156215:tid 156421] [client 57.141.18.34:47802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4juMJ0fwhpxOKR8YhC0wAATHU"]
[Mon Jul 20 07:33:46.713614 2026] [security2:error] [pid 156215:tid 156385] [client 35.252.163.207:54797] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4jusJ0fwhpxOKR8YhDlQAAACg"]
[Mon Jul 20 07:33:46.809810 2026] [security2:error] [pid 156215:tid 156395] [client 57.141.18.57:54224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4juMJ0fwhpxOKR8YhC4gAAMnA"]
[Mon Jul 20 07:33:46.955911 2026] [security2:error] [pid 156215:tid 156376] [client 104.234.53.76:59223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jusJ0fwhpxOKR8YhDqQAAAB8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:46.983871 2026] [security2:error] [pid 156215:tid 156377] [client 35.252.163.207:56251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4jusJ0fwhpxOKR8YhDqwAAACA"]
[Mon Jul 20 07:33:47.195420 2026] [security2:error] [pid 156215:tid 156395] [client 20.226.66.230:41721] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/.well-known/about.php"] [unique_id "al4ju8J0fwhpxOKR8YhDwwAAADI"]
[Mon Jul 20 07:33:47.195532 2026] [security2:error] [pid 156215:tid 156395] [client 20.226.66.230:41721] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/.well-known/about.php"] [unique_id "al4ju8J0fwhpxOKR8YhDwwAAADI"]
[Mon Jul 20 07:33:47.201200 2026] [security2:error] [pid 156215:tid 156413] [client 103.139.191.61:64236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4ju8J0fwhpxOKR8YhDxQAAAEQ"]
[Mon Jul 20 07:33:47.201341 2026] [security2:error] [pid 156215:tid 156413] [client 103.139.191.61:64236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4ju8J0fwhpxOKR8YhDxQAAAEQ"]
[Mon Jul 20 07:33:47.390653 2026] [security2:error] [pid 156215:tid 156363] [client 35.252.163.207:58117] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4ju8J0fwhpxOKR8YhD2QAAABI"]
[Mon Jul 20 07:33:47.427676 2026] [security2:error] [pid 156215:tid 156246] [remote 188.166.241.141:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4ju8J0fwhpxOKR8YhD2gAALh4"]
[Mon Jul 20 07:33:47.519469 2026] [security2:error] [pid 156215:tid 156347] [client 103.176.215.66:51823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ju8J0fwhpxOKR8YhD4AAAAAI"]
[Mon Jul 20 07:33:47.519588 2026] [security2:error] [pid 156215:tid 156347] [client 103.176.215.66:51823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ju8J0fwhpxOKR8YhD4AAAAAI"]
[Mon Jul 20 07:33:47.605899 2026] [security2:error] [pid 156215:tid 156397] [client 104.28.251.193:36878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4ju8J0fwhpxOKR8YhDtwAAADQ"]
[Mon Jul 20 07:33:47.623000 2026] [security2:error] [pid 156215:tid 156421] [client 20.226.66.230:41438] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4ju8J0fwhpxOKR8YhD7gAAAEw"]
[Mon Jul 20 07:33:47.623108 2026] [security2:error] [pid 156215:tid 156421] [client 20.226.66.230:41438] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4ju8J0fwhpxOKR8YhD7gAAAEw"]
[Mon Jul 20 07:33:47.637306 2026] [security2:error] [pid 156215:tid 156469] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4ju8J0fwhpxOKR8YhDuQAAAHw"]
[Mon Jul 20 07:33:47.644905 2026] [security2:error] [pid 156215:tid 156369] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.scoophouse.com"] [uri "/index.php"] [unique_id "al4jt8J0fwhpxOKR8YhCbAAAABg"]
[Mon Jul 20 07:33:47.742431 2026] [autoindex:error] [pid 156215:tid 156312] [remote 136.114.198.221:64581] AH01276: Cannot serve directory /home2/brsjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.brs.jiv.mybluehost.me
[Mon Jul 20 07:33:47.774104 2026] [security2:error] [pid 156215:tid 156353] [client 35.252.163.207:60271] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4ju8J0fwhpxOKR8YhD_QAAAAg"]
[Mon Jul 20 07:33:47.775836 2026] [security2:error] [pid 156215:tid 156444] [client 116.74.65.235:64081] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ju8J0fwhpxOKR8YhD7AAAAGM"]
[Mon Jul 20 07:33:47.860775 2026] [security2:error] [pid 156215:tid 156227] [remote 100.42.189.89:34216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4ju8J0fwhpxOKR8YhEBwAAWgs"]
[Mon Jul 20 07:33:47.872126 2026] [security2:error] [pid 156215:tid 156268] [remote 188.166.241.141:52688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4ju8J0fwhpxOKR8YhECAAAdjQ"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:33:47.963463 2026] [security2:error] [pid 156215:tid 156424] [client 14.225.17.146:50872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4ju8J0fwhpxOKR8YhD-gAAAE8"], referer: http://soloceos.com/TEST
[Mon Jul 20 07:33:48.070825 2026] [security2:error] [pid 156215:tid 156220] [remote 100.42.189.89:34216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "guidehunting.com"] [uri "/wp-login.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEGAAAOAQ"], referer: https://guidehunting.com/wp-login.php
[Mon Jul 20 07:33:48.126818 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:41667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/system_log.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEHwAAAHI"]
[Mon Jul 20 07:33:48.126949 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:41667] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/system_log.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEHwAAAHI"]
[Mon Jul 20 07:33:48.237540 2026] [security2:error] [pid 156215:tid 156405] [client 14.225.17.146:49764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4jusJ0fwhpxOKR8YhDfAAAADw"], referer: http://fineartsfactory.net/TEST
[Mon Jul 20 07:33:48.267902 2026] [security2:error] [pid 156215:tid 156373] [client 74.7.227.179:56836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEHQAAHDE"], referer: https://tejasenvironmental.com/p=653120
[Mon Jul 20 07:33:48.281183 2026] [security2:error] [pid 156215:tid 156382] [client 35.252.163.207:61680] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4jvMJ0fwhpxOKR8YhEKAAAACU"]
[Mon Jul 20 07:33:48.289327 2026] [fcgid:warn] [pid 156215:tid 156374] (70014)End of file found: [client 84.233.195.154:53666] mod_fcgid: can't get data from http client
[Mon Jul 20 07:33:48.319374 2026] [security2:error] [pid 156215:tid 156471] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4ju8J0fwhpxOKR8YhD-QAAAH4"]
[Mon Jul 20 07:33:48.321612 2026] [security2:error] [pid 156215:tid 156415] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4ju8J0fwhpxOKR8YhD-AAAAEY"]
[Mon Jul 20 07:33:48.387557 2026] [security2:error] [pid 156215:tid 156422] [client 14.225.17.146:49754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4jusJ0fwhpxOKR8YhDiwAAAE0"], referer: http://superiorcopywriting.com/TEST
[Mon Jul 20 07:33:48.434398 2026] [security2:error] [pid 156215:tid 156377] [client 117.211.236.168:60207] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jvMJ0fwhpxOKR8YhENAAAACA"]
[Mon Jul 20 07:33:48.434519 2026] [security2:error] [pid 156215:tid 156377] [client 117.211.236.168:60207] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jvMJ0fwhpxOKR8YhENAAAACA"]
[Mon Jul 20 07:33:48.467257 2026] [security2:error] [pid 156215:tid 156442] [client 14.225.17.146:50849] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4ju8J0fwhpxOKR8YhD2wAAAGE"]
[Mon Jul 20 07:33:48.472064 2026] [security2:error] [pid 156215:tid 156384] [client 57.141.18.51:52958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jusJ0fwhpxOKR8YhDdAAAJ3Y"]
[Mon Jul 20 07:33:48.527136 2026] [security2:error] [pid 156215:tid 156349] [client 20.226.66.230:41712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/"] [unique_id "al4jvMJ0fwhpxOKR8YhEPgAAAAQ"]
[Mon Jul 20 07:33:48.579166 2026] [security2:error] [pid 156215:tid 156407] [client 143.44.185.218:39955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jvMJ0fwhpxOKR8YhERgAAAD4"]
[Mon Jul 20 07:33:48.579292 2026] [security2:error] [pid 156215:tid 156407] [client 143.44.185.218:39955] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jvMJ0fwhpxOKR8YhERgAAAD4"]
[Mon Jul 20 07:33:48.674530 2026] [security2:error] [pid 156215:tid 156394] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEHAAAADE"]
[Mon Jul 20 07:33:48.693483 2026] [security2:error] [pid 156215:tid 156353] [client 14.225.17.146:52645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEIwAAAAg"]
[Mon Jul 20 07:33:48.700252 2026] [security2:error] [pid 156215:tid 156405] [client 35.252.163.207:61685] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4jvMJ0fwhpxOKR8YhEUgAAADw"]
[Mon Jul 20 07:33:48.725295 2026] [security2:error] [pid 156215:tid 156453] [client 57.141.18.20:51610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jusJ0fwhpxOKR8YhDiAAAbDo"]
[Mon Jul 20 07:33:48.736311 2026] [autoindex:error] [pid 156215:tid 156348] [client 20.226.66.230:41698] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:48.736938 2026] [security2:error] [pid 156215:tid 156348] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/"] [unique_id "al4jvMJ0fwhpxOKR8YhEUAAAAAM"]
[Mon Jul 20 07:33:48.753045 2026] [security2:error] [pid 156215:tid 156439] [client 104.28.251.193:19811] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "massagelacey.com"] [uri "/.env.old"] [unique_id "al4jvMJ0fwhpxOKR8YhEVAAAAF4"]
[Mon Jul 20 07:33:48.896487 2026] [security2:error] [pid 156215:tid 156381] [client 20.226.66.230:41712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4jvMJ0fwhpxOKR8YhEXgAAACQ"]
[Mon Jul 20 07:33:48.973158 2026] [security2:error] [pid 156215:tid 156422] [client 57.141.18.17:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEWQAAAE0"]
[Mon Jul 20 07:33:49.036988 2026] [security2:error] [pid 156215:tid 156431] [client 35.252.163.207:64454] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4jvcJ0fwhpxOKR8YhEcwAAAFY"]
[Mon Jul 20 07:33:49.046744 2026] [security2:error] [pid 156215:tid 156373] [client 104.28.251.193:36887] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "massagelacey.com"] [uri "/.env.bak"] [unique_id "al4jvcJ0fwhpxOKR8YhEdgAAABw"]
[Mon Jul 20 07:33:49.046833 2026] [security2:error] [pid 156215:tid 156394] [client 104.28.251.193:36883] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "massagelacey.com"] [uri "/.env.backup"] [unique_id "al4jvcJ0fwhpxOKR8YhEdQAAADE"]
[Mon Jul 20 07:33:49.143992 2026] [autoindex:error] [pid 156215:tid 156405] [client 20.226.66.230:41698] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:49.144559 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4jvcJ0fwhpxOKR8YhEewAAADw"]
[Mon Jul 20 07:33:49.229359 2026] [security2:error] [pid 156215:tid 156454] [client 148.255.40.157:53503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEhQAAAG0"]
[Mon Jul 20 07:33:49.229545 2026] [security2:error] [pid 156215:tid 156454] [client 148.255.40.157:53503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEhQAAAG0"]
[Mon Jul 20 07:33:49.306839 2026] [security2:error] [pid 156215:tid 156469] [client 20.226.66.230:41712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/crgio.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEiQAAAHw"]
[Mon Jul 20 07:33:49.306971 2026] [security2:error] [pid 156215:tid 156469] [client 20.226.66.230:41712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/crgio.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEiQAAAHw"]
[Mon Jul 20 07:33:49.408691 2026] [security2:error] [pid 156215:tid 156379] [client 35.252.163.207:54933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4jvcJ0fwhpxOKR8YhEkgAAACI"]
[Mon Jul 20 07:33:49.579519 2026] [security2:error] [pid 156215:tid 156362] [client 148.255.40.157:32774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEpwAAABE"]
[Mon Jul 20 07:33:49.579638 2026] [security2:error] [pid 156215:tid 156362] [client 148.255.40.157:32774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEpwAAABE"]
[Mon Jul 20 07:33:49.640971 2026] [security2:error] [pid 156215:tid 156453] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEfQAAAGw"]
[Mon Jul 20 07:33:49.684679 2026] [security2:error] [pid 156215:tid 156412] [client 104.28.251.193:19811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEfwAAAEM"]
[Mon Jul 20 07:33:49.802489 2026] [security2:error] [pid 156215:tid 156446] [client 14.225.17.146:49801] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEHgAAAGU"], referer: http://maplerespiteservices.com/TEST
[Mon Jul 20 07:33:49.811681 2026] [security2:error] [pid 156215:tid 156397] [client 20.226.66.230:41668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/pucci.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEugAAADQ"]
[Mon Jul 20 07:33:49.811776 2026] [security2:error] [pid 156215:tid 156397] [client 20.226.66.230:41668] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/pucci.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEugAAADQ"]
[Mon Jul 20 07:33:49.822716 2026] [security2:error] [pid 156215:tid 156455] [client 35.252.163.207:58992] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4jvcJ0fwhpxOKR8YhEuwAAAG4"]
[Mon Jul 20 07:33:50.125417 2026] [security2:error] [pid 156215:tid 156354] [client 148.255.40.157:53601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4jvsJ0fwhpxOKR8YhE3QAAAAk"]
[Mon Jul 20 07:33:50.125519 2026] [security2:error] [pid 156215:tid 156354] [client 148.255.40.157:53601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4jvsJ0fwhpxOKR8YhE3QAAAAk"]
[Mon Jul 20 07:33:50.143541 2026] [security2:error] [pid 156215:tid 156384] [client 171.249.22.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEkQAAACc"]
[Mon Jul 20 07:33:50.144995 2026] [security2:error] [pid 156215:tid 156360] [client 57.141.18.99:58182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhEEgAADzs"]
[Mon Jul 20 07:33:50.231481 2026] [security2:error] [pid 156215:tid 156374] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEqwAAAB0"]
[Mon Jul 20 07:33:50.252143 2026] [security2:error] [pid 156215:tid 156435] [client 104.28.251.193:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEqgAAAFo"]
[Mon Jul 20 07:33:50.321518 2026] [security2:error] [pid 156215:tid 156442] [client 35.252.163.207:50642] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4jvsJ0fwhpxOKR8YhE7QAAAGE"]
[Mon Jul 20 07:33:50.321949 2026] [security2:error] [pid 156215:tid 156466] [client 20.226.66.230:41724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4jvsJ0fwhpxOKR8YhE7AAAAHk"]
[Mon Jul 20 07:33:50.434997 2026] [security2:error] [pid 156215:tid 156441] [client 148.255.40.157:53731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4jvsJ0fwhpxOKR8YhE9wAAAGA"]
[Mon Jul 20 07:33:50.435081 2026] [security2:error] [pid 156215:tid 156441] [client 148.255.40.157:53731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4jvsJ0fwhpxOKR8YhE9wAAAGA"]
[Mon Jul 20 07:33:50.452335 2026] [security2:error] [pid 156215:tid 156411] [client 188.166.209.66:64681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/block-editor.php"] [unique_id "al4jvsJ0fwhpxOKR8YhE-AAAAEI"], referer: binance.com
[Mon Jul 20 07:33:50.527660 2026] [autoindex:error] [pid 156215:tid 156446] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/blocks/details/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:50.528466 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jvsJ0fwhpxOKR8YhFAAAAAGU"]
[Mon Jul 20 07:33:50.549300 2026] [security2:error] [pid 156215:tid 156360] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4jvsJ0fwhpxOKR8YhE_QAAAA8"]
[Mon Jul 20 07:33:50.551089 2026] [security2:error] [pid 156215:tid 156372] [client 57.141.18.48:44494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jvMJ0fwhpxOKR8YhERQAAG0Y"]
[Mon Jul 20 07:33:50.560177 2026] [security2:error] [pid 156215:tid 156384] [client 35.252.163.207:59183] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4jvsJ0fwhpxOKR8YhFBwAAACc"]
[Mon Jul 20 07:33:50.620657 2026] [security2:error] [pid 156215:tid 156399] [client 104.28.251.193:19811] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhE0QAAADY"]
[Mon Jul 20 07:33:50.637148 2026] [security2:error] [pid 156215:tid 156440] [client 104.28.251.193:36878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "massagelacey.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEzwAAAF8"]
[Mon Jul 20 07:33:50.658086 2026] [security2:error] [pid 156215:tid 156449] [client 158.173.89.95:28079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jvsJ0fwhpxOKR8YhFDAAAAGg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:33:50.710816 2026] [security2:error] [pid 156215:tid 156404] [client 20.226.66.230:41724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "al4jvsJ0fwhpxOKR8YhFDwAAADs"]
[Mon Jul 20 07:33:50.768165 2026] [security2:error] [pid 156215:tid 156395] [client 148.255.40.157:53779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/news/xmlrpc.php"] [unique_id "al4jvsJ0fwhpxOKR8YhFEwAAADI"]
[Mon Jul 20 07:33:50.768273 2026] [security2:error] [pid 156215:tid 156395] [client 148.255.40.157:53779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/news/xmlrpc.php"] [unique_id "al4jvsJ0fwhpxOKR8YhFEwAAADI"]
[Mon Jul 20 07:33:50.798900 2026] [security2:error] [pid 156215:tid 156359] [client 35.252.163.207:50499] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "oswegooperatheater.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4jvsJ0fwhpxOKR8YhFFQAAAA4"]
[Mon Jul 20 07:33:50.905234 2026] [autoindex:error] [pid 156215:tid 156421] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/blocks/audio/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:50.905694 2026] [security2:error] [pid 156215:tid 156421] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jvsJ0fwhpxOKR8YhFGgAAAEw"]
[Mon Jul 20 07:33:50.912061 2026] [security2:error] [pid 156215:tid 156427] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "al4jvsJ0fwhpxOKR8YhFGAAAAFI"]
[Mon Jul 20 07:33:51.069553 2026] [security2:error] [pid 156215:tid 156351] [client 20.226.66.230:41724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-temp.php"] [unique_id "al4jv8J0fwhpxOKR8YhFKgAAAAY"]
[Mon Jul 20 07:33:51.069687 2026] [security2:error] [pid 156215:tid 156351] [client 20.226.66.230:41724] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-temp.php"] [unique_id "al4jv8J0fwhpxOKR8YhFKgAAAAY"]
[Mon Jul 20 07:33:51.104766 2026] [security2:error] [pid 156215:tid 156458] [client 148.255.40.157:53853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/main/xmlrpc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFLgAAAHE"]
[Mon Jul 20 07:33:51.104827 2026] [security2:error] [pid 156215:tid 156458] [client 148.255.40.157:53853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/main/xmlrpc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFLgAAAHE"]
[Mon Jul 20 07:33:51.231568 2026] [security2:error] [pid 156215:tid 156398] [client 57.141.18.99:58184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEjwAANXw"]
[Mon Jul 20 07:33:51.278784 2026] [security2:error] [pid 156215:tid 156369] [client 57.141.18.64:29696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jvcJ0fwhpxOKR8YhEkwAAGAo"]
[Mon Jul 20 07:33:51.433066 2026] [security2:error] [pid 156215:tid 156449] [client 148.255.40.157:53904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFPwAAAGg"]
[Mon Jul 20 07:33:51.433164 2026] [security2:error] [pid 156215:tid 156449] [client 148.255.40.157:53904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFPwAAAGg"]
[Mon Jul 20 07:33:51.478840 2026] [security2:error] [pid 156215:tid 156375] [client 20.226.66.230:41381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4jv8J0fwhpxOKR8YhFRAAAAB4"]
[Mon Jul 20 07:33:51.478949 2026] [security2:error] [pid 156215:tid 156375] [client 20.226.66.230:41381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4jv8J0fwhpxOKR8YhFRAAAAB4"]
[Mon Jul 20 07:33:51.604805 2026] [security2:error] [pid 156215:tid 156391] [client 14.225.17.146:65354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4jvsJ0fwhpxOKR8YhFCgAAAC4"], referer: http://claysharecon.com/TEST
[Mon Jul 20 07:33:51.769067 2026] [security2:error] [pid 156215:tid 156396] [client 148.255.40.157:53935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFVgAAADM"]
[Mon Jul 20 07:33:51.769183 2026] [security2:error] [pid 156215:tid 156396] [client 148.255.40.157:53935] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/wp-site/xmlrpc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFVgAAADM"]
[Mon Jul 20 07:33:51.825153 2026] [security2:error] [pid 156215:tid 156408] [client 20.226.66.230:41383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/puc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFWwAAAD8"]
[Mon Jul 20 07:33:51.825243 2026] [security2:error] [pid 156215:tid 156408] [client 20.226.66.230:41383] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/puc.php"] [unique_id "al4jv8J0fwhpxOKR8YhFWwAAAD8"]
[Mon Jul 20 07:33:52.129604 2026] [security2:error] [pid 156215:tid 156395] [client 148.255.40.157:54006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFcQAAADI"]
[Mon Jul 20 07:33:52.129729 2026] [security2:error] [pid 156215:tid 156395] [client 148.255.40.157:54006] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFcQAAADI"]
[Mon Jul 20 07:33:52.217461 2026] [security2:error] [pid 156215:tid 156351] [client 20.226.66.230:41701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/dx.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFdAAAAAY"]
[Mon Jul 20 07:33:52.217578 2026] [security2:error] [pid 156215:tid 156351] [client 20.226.66.230:41701] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/dx.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFdAAAAAY"]
[Mon Jul 20 07:33:52.223227 2026] [security2:error] [pid 156215:tid 156299] [remote 173.212.252.15:39806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFdQAANlM"]
[Mon Jul 20 07:33:52.223345 2026] [security2:error] [pid 156215:tid 156399] [client 173.212.252.15:39806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFdQAANlM"]
[Mon Jul 20 07:33:52.263897 2026] [security2:error] [pid 156215:tid 156439] [client 57.141.18.80:20430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jvsJ0fwhpxOKR8YhE-wAAXlw"]
[Mon Jul 20 07:33:52.403972 2026] [security2:error] [pid 156215:tid 156434] [client 86.41.10.85:38910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFfgAAWRk"]
[Mon Jul 20 07:33:52.513041 2026] [security2:error] [pid 156215:tid 156390] [client 148.255.40.157:31906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/old/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFlQAAAC0"]
[Mon Jul 20 07:33:52.513154 2026] [security2:error] [pid 156215:tid 156390] [client 148.255.40.157:31906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/old/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFlQAAAC0"]
[Mon Jul 20 07:33:52.524656 2026] [security2:error] [pid 156215:tid 156423] [client 104.234.53.73:27443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFlwAAAE4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:52.545097 2026] [security2:error] [pid 156215:tid 156433] [client 20.226.66.230:41706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/Requests/"] [unique_id "al4jwMJ0fwhpxOKR8YhFnAAAAFg"]
[Mon Jul 20 07:33:52.570785 2026] [security2:error] [pid 156215:tid 156363] [client 49.37.242.14:54628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFnQAAABI"]
[Mon Jul 20 07:33:52.570881 2026] [security2:error] [pid 156215:tid 156363] [client 49.37.242.14:54628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFnQAAABI"]
[Mon Jul 20 07:33:52.679122 2026] [security2:error] [pid 156215:tid 156460] [client 149.0.16.108:53974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFowAAAHM"]
[Mon Jul 20 07:33:52.679221 2026] [security2:error] [pid 156215:tid 156460] [client 149.0.16.108:53974] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFowAAAHM"]
[Mon Jul 20 07:33:52.753203 2026] [autoindex:error] [pid 156215:tid 156426] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/Requests/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:52.753815 2026] [security2:error] [pid 156215:tid 156426] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jwMJ0fwhpxOKR8YhFpwAAAFE"]
[Mon Jul 20 07:33:52.767412 2026] [security2:error] [pid 156215:tid 156416] [client 20.226.66.230:41698] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/Requests/"] [unique_id "al4jwMJ0fwhpxOKR8YhFpAAAAEc"]
[Mon Jul 20 07:33:52.924990 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/bthil.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFsAAAAHE"]
[Mon Jul 20 07:33:52.925086 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41706] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/bthil.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFsAAAAHE"]
[Mon Jul 20 07:33:53.038469 2026] [security2:error] [pid 156215:tid 156348] [client 144.16.21.149:25321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFwgAAAAM"]
[Mon Jul 20 07:33:53.038649 2026] [security2:error] [pid 156215:tid 156348] [client 144.16.21.149:25321] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFwgAAAAM"]
[Mon Jul 20 07:33:53.052501 2026] [security2:error] [pid 156215:tid 156466] [client 148.255.40.157:54131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.40.255.148.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wp-login.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFxQAAAHk"]
[Mon Jul 20 07:33:53.148069 2026] [security2:error] [pid 156215:tid 156455] [client 142.111.152.63:57087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFswAAAG4"]
[Mon Jul 20 07:33:53.189968 2026] [security2:error] [pid 156215:tid 156294] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFzgAAck4"]
[Mon Jul 20 07:33:53.190113 2026] [security2:error] [pid 156215:tid 156459] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFzgAAck4"]
[Mon Jul 20 07:33:53.251545 2026] [security2:error] [pid 156215:tid 156383] [client 104.234.53.51:35505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFzwAAACY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:53.279724 2026] [security2:error] [pid 156215:tid 156285] [remote 57.141.18.59:63380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3843264"] [unique_id "al4jwcJ0fwhpxOKR8YhF0QAAXkU"]
[Mon Jul 20 07:33:53.322984 2026] [security2:error] [pid 156215:tid 156408] [client 20.226.66.230:41680] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/7.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF1QAAAD8"]
[Mon Jul 20 07:33:53.323066 2026] [security2:error] [pid 156215:tid 156408] [client 20.226.66.230:41680] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/7.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF1QAAAD8"]
[Mon Jul 20 07:33:53.399912 2026] [security2:error] [pid 156215:tid 156427] [client 57.141.18.101:53452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jv8J0fwhpxOKR8YhFTQAAUiQ"]
[Mon Jul 20 07:33:53.500079 2026] [security2:error] [pid 156215:tid 156438] [client 157.20.138.62:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF5AAAAF0"]
[Mon Jul 20 07:33:53.500231 2026] [security2:error] [pid 156215:tid 156438] [client 157.20.138.62:49596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF5AAAAF0"]
[Mon Jul 20 07:33:53.695876 2026] [security2:error] [pid 156215:tid 156402] [client 20.226.66.230:41699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/8.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF8gAAADk"]
[Mon Jul 20 07:33:53.695970 2026] [security2:error] [pid 156215:tid 156402] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/8.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF8gAAADk"]
[Mon Jul 20 07:33:53.714693 2026] [security2:error] [pid 156215:tid 156446] [client 49.47.218.174:63890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF9AAAAGU"]
[Mon Jul 20 07:33:53.714828 2026] [security2:error] [pid 156215:tid 156446] [client 49.47.218.174:63890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF9AAAAGU"]
[Mon Jul 20 07:33:53.731075 2026] [security2:error] [pid 156215:tid 156373] [client 57.141.18.64:29710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFaQAAHDQ"]
[Mon Jul 20 07:33:54.198976 2026] [security2:error] [pid 156215:tid 156426] [client 20.226.66.230:41457] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "mail.adirondackengineering.com"] [uri "/1.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGFQAAAFE"]
[Mon Jul 20 07:33:54.199104 2026] [security2:error] [pid 156215:tid 156426] [client 20.226.66.230:41457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/1.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGFQAAAFE"]
[Mon Jul 20 07:33:54.199206 2026] [security2:error] [pid 156215:tid 156426] [client 20.226.66.230:41457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/1.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGFQAAAFE"]
[Mon Jul 20 07:33:54.218723 2026] [security2:error] [pid 156215:tid 156421] [client 14.225.17.146:60323] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4jwMJ0fwhpxOKR8YhFqAAAAEw"], referer: http://alexsandbergmusic.com/TEST
[Mon Jul 20 07:33:54.329385 2026] [security2:error] [pid 156215:tid 156472] [client 202.141.11.99:36926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGIgAAAH8"]
[Mon Jul 20 07:33:54.329497 2026] [security2:error] [pid 156215:tid 156472] [client 202.141.11.99:36926] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGIgAAAH8"]
[Mon Jul 20 07:33:54.509791 2026] [security2:error] [pid 156215:tid 156463] [client 188.166.209.66:63962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGLQAAAHY"], referer: binance.com
[Mon Jul 20 07:33:54.614686 2026] [security2:error] [pid 156215:tid 156378] [client 20.226.66.230:41449] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/100.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGPgAAACE"]
[Mon Jul 20 07:33:54.614794 2026] [security2:error] [pid 156215:tid 156378] [client 20.226.66.230:41449] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/100.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGPgAAACE"]
[Mon Jul 20 07:33:54.780397 2026] [security2:error] [pid 156215:tid 156399] [client 136.158.60.21:33583] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGSAAAADY"]
[Mon Jul 20 07:33:54.780511 2026] [security2:error] [pid 156215:tid 156399] [client 136.158.60.21:33583] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGSAAAADY"]
[Mon Jul 20 07:33:54.934686 2026] [security2:error] [pid 156215:tid 156452] [client 104.234.53.90:43545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGVgAAAGs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:33:54.985934 2026] [security2:error] [pid 156215:tid 156398] [client 57.141.18.69:43456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jwcJ0fwhpxOKR8YhFzAAANVI"]
[Mon Jul 20 07:33:55.092823 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/about.php"] [unique_id "al4jw8J0fwhpxOKR8YhGZwAAAHE"]
[Mon Jul 20 07:33:55.092948 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41696] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/about.php"] [unique_id "al4jw8J0fwhpxOKR8YhGZwAAAHE"]
[Mon Jul 20 07:33:55.454517 2026] [security2:error] [pid 156215:tid 156385] [client 57.141.18.54:29612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jwcJ0fwhpxOKR8YhF8wAAKAc"]
[Mon Jul 20 07:33:55.472142 2026] [security2:error] [pid 156215:tid 156405] [client 154.192.123.127:18402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGggAAADw"]
[Mon Jul 20 07:33:55.472241 2026] [security2:error] [pid 156215:tid 156405] [client 154.192.123.127:18402] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGggAAADw"]
[Mon Jul 20 07:33:55.537966 2026] [security2:error] [pid 156215:tid 156429] [client 36.93.152.155:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGiQAAAFQ"]
[Mon Jul 20 07:33:55.538078 2026] [security2:error] [pid 156215:tid 156429] [client 36.93.152.155:58824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGiQAAAFQ"]
[Mon Jul 20 07:33:55.749016 2026] [security2:error] [pid 156215:tid 156353] [client 14.225.17.146:51674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGRgAAAAg"], referer: http://travelbyfire.com/TEST
[Mon Jul 20 07:33:55.756636 2026] [security2:error] [pid 156215:tid 156462] [client 63.176.132.15:34040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jw8J0fwhpxOKR8YhGogAAAHU"]
[Mon Jul 20 07:33:55.759699 2026] [security2:error] [pid 156215:tid 156438] [client 45.3.52.234:43771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jw8J0fwhpxOKR8YhGnwAAAF0"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:33:55.763092 2026] [security2:error] [pid 156215:tid 156388] [client 20.226.66.230:41577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/admin.php"] [unique_id "al4jw8J0fwhpxOKR8YhGpAAAACs"]
[Mon Jul 20 07:33:55.763167 2026] [security2:error] [pid 156215:tid 156388] [client 20.226.66.230:41577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/admin.php"] [unique_id "al4jw8J0fwhpxOKR8YhGpAAAACs"]
[Mon Jul 20 07:33:55.899349 2026] [security2:error] [pid 156215:tid 156391] [client 191.202.66.27:61154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGqwAAAC4"]
[Mon Jul 20 07:33:55.899508 2026] [security2:error] [pid 156215:tid 156391] [client 191.202.66.27:61154] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGqwAAAC4"]
[Mon Jul 20 07:33:55.935939 2026] [security2:error] [pid 156215:tid 156396] [client 179.127.84.238:63830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGrQAAADM"]
[Mon Jul 20 07:33:55.936103 2026] [security2:error] [pid 156215:tid 156396] [client 179.127.84.238:63830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jw8J0fwhpxOKR8YhGrQAAADM"]
[Mon Jul 20 07:33:56.033404 2026] [security2:error] [pid 156215:tid 156404] [client 89.238.167.150:45714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGtQAAADs"]
[Mon Jul 20 07:33:56.033519 2026] [security2:error] [pid 156215:tid 156404] [client 89.238.167.150:45714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGtQAAADs"]
[Mon Jul 20 07:33:56.131183 2026] [security2:error] [pid 156215:tid 156415] [client 20.226.66.230:41413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/edit.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGxAAAAEY"]
[Mon Jul 20 07:33:56.131273 2026] [security2:error] [pid 156215:tid 156415] [client 20.226.66.230:41413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/edit.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGxAAAAEY"]
[Mon Jul 20 07:33:56.179500 2026] [security2:error] [pid 156215:tid 156425] [client 57.141.18.67:65334] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jwsJ0fwhpxOKR8YhGNAAAUGw"]
[Mon Jul 20 07:33:56.182764 2026] [security2:error] [pid 156215:tid 156378] [client 47.128.46.66:32194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "adirondackengineering.com"] [uri "/robots.txt"] [unique_id "al4jxMJ0fwhpxOKR8YhGyAAAACE"]
[Mon Jul 20 07:33:56.227656 2026] [security2:error] [pid 156215:tid 156248] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGzAAAByA"]
[Mon Jul 20 07:33:56.227824 2026] [security2:error] [pid 156215:tid 156352] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGzAAAByA"]
[Mon Jul 20 07:33:56.325043 2026] [security2:error] [pid 156215:tid 156432] [client 63.179.149.246:49594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG0wAAAFc"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:33:56.487082 2026] [security2:error] [pid 156215:tid 156413] [client 20.226.66.230:41420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/admin.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG3AAAAEQ"]
[Mon Jul 20 07:33:56.487178 2026] [security2:error] [pid 156215:tid 156413] [client 20.226.66.230:41420] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/admin.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG3AAAAEQ"]
[Mon Jul 20 07:33:56.596945 2026] [security2:error] [pid 156215:tid 156460] [client 14.225.17.146:52153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG1wAAAHM"], referer: http://carolinapressurewashers.com/TEST
[Mon Jul 20 07:33:56.677965 2026] [security2:error] [pid 156215:tid 156449] [client 14.225.17.146:51530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG7QAAAGg"], referer: https://travelbyfire.com/TEST
[Mon Jul 20 07:33:56.722533 2026] [security2:error] [pid 156215:tid 156347] [client 103.106.165.44:64461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG-gAAAAI"]
[Mon Jul 20 07:33:56.722648 2026] [security2:error] [pid 156215:tid 156347] [client 103.106.165.44:64461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG-gAAAAI"]
[Mon Jul 20 07:33:56.824681 2026] [security2:error] [pid 156215:tid 156402] [client 20.226.66.230:41683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ss.php"] [unique_id "al4jxMJ0fwhpxOKR8YhHAgAAADk"]
[Mon Jul 20 07:33:56.824806 2026] [security2:error] [pid 156215:tid 156402] [client 20.226.66.230:41683] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ss.php"] [unique_id "al4jxMJ0fwhpxOKR8YhHAgAAADk"]
[Mon Jul 20 07:33:56.970686 2026] [security2:error] [pid 156215:tid 156289] [remote 217.61.143.92:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jxMJ0fwhpxOKR8YhHCgAAVkk"]
[Mon Jul 20 07:33:57.209709 2026] [security2:error] [pid 156215:tid 156247] [remote 217.61.143.92:34290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHIAAAAh8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:33:57.220051 2026] [security2:error] [pid 156215:tid 156461] [client 20.226.66.230:41356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/inputs.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHIgAAAHQ"]
[Mon Jul 20 07:33:57.220172 2026] [security2:error] [pid 156215:tid 156461] [client 20.226.66.230:41356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/inputs.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHIgAAAHQ"]
[Mon Jul 20 07:33:57.363044 2026] [security2:error] [pid 156215:tid 156445] [client 103.139.191.61:64710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHLgAAAGQ"]
[Mon Jul 20 07:33:57.363137 2026] [security2:error] [pid 156215:tid 156445] [client 103.139.191.61:64710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHLgAAAGQ"]
[Mon Jul 20 07:33:57.636364 2026] [security2:error] [pid 156215:tid 156428] [client 20.226.66.230:41437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/av.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHSAAAAFM"]
[Mon Jul 20 07:33:57.636468 2026] [security2:error] [pid 156215:tid 156428] [client 20.226.66.230:41437] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/av.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHSAAAAFM"]
[Mon Jul 20 07:33:57.700078 2026] [security2:error] [pid 156215:tid 156370] [client 57.141.18.69:43464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGtAAAGQs"]
[Mon Jul 20 07:33:57.722391 2026] [security2:error] [pid 156215:tid 156408] [client 57.141.18.15:24758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGsgAAPwM"]
[Mon Jul 20 07:33:57.836361 2026] [security2:error] [pid 156215:tid 156236] [remote 152.228.213.32:43788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHWgAAKxQ"]
[Mon Jul 20 07:33:57.975560 2026] [security2:error] [pid 156215:tid 156365] [client 20.226.66.230:41710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/classwithtostring.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHYwAAABQ"]
[Mon Jul 20 07:33:57.975709 2026] [security2:error] [pid 156215:tid 156365] [client 20.226.66.230:41710] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/classwithtostring.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHYwAAABQ"]
[Mon Jul 20 07:33:58.008144 2026] [security2:error] [pid 156215:tid 156364] [client 117.211.236.168:60744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHZAAAABM"]
[Mon Jul 20 07:33:58.008248 2026] [security2:error] [pid 156215:tid 156364] [client 117.211.236.168:60744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHZAAAABM"]
[Mon Jul 20 07:33:58.028996 2026] [security2:error] [pid 156215:tid 156296] [remote 152.228.213.32:43788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHZQAAeFA"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 07:33:58.051307 2026] [security2:error] [pid 156215:tid 156351] [client 103.176.215.66:52351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHaQAAAAY"]
[Mon Jul 20 07:33:58.051882 2026] [security2:error] [pid 156215:tid 156351] [client 103.176.215.66:52351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHaQAAAAY"]
[Mon Jul 20 07:33:58.078759 2026] [security2:error] [pid 156215:tid 156435] [client 57.141.18.115:30494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG1QAAWl4"]
[Mon Jul 20 07:33:58.131350 2026] [security2:error] [pid 156215:tid 156316] [remote 38.242.157.30:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHcQAAAWQ"]
[Mon Jul 20 07:33:58.275483 2026] [security2:error] [pid 156215:tid 156420] [client 14.225.17.146:51882] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhGvQAAAEs"]
[Mon Jul 20 07:33:58.345334 2026] [security2:error] [pid 156215:tid 156439] [client 20.226.66.230:41677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHfQAAAF4"]
[Mon Jul 20 07:33:58.345458 2026] [security2:error] [pid 156215:tid 156439] [client 20.226.66.230:41677] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHfQAAAF4"]
[Mon Jul 20 07:33:58.352012 2026] [security2:error] [pid 156215:tid 156343] [remote 38.242.157.30:55470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHgAAAK38"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:58.459969 2026] [security2:error] [pid 156215:tid 156469] [client 57.141.18.69:43470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxMJ0fwhpxOKR8YhG9wAAfDo"]
[Mon Jul 20 07:33:58.474403 2026] [security2:error] [pid 156215:tid 156412] [client 14.225.17.146:53721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHHgAAAEM"], referer: http://iagdevelopments.com/TEST
[Mon Jul 20 07:33:58.594070 2026] [security2:error] [pid 156215:tid 156397] [client 188.166.209.66:54124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/block-template.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHkwAAADQ"], referer: binance.com
[Mon Jul 20 07:33:58.697201 2026] [security2:error] [pid 156215:tid 156347] [client 20.226.66.230:41691] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-blog.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHmwAAAAI"]
[Mon Jul 20 07:33:58.697302 2026] [security2:error] [pid 156215:tid 156347] [client 20.226.66.230:41691] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-blog.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHmwAAAAI"]
[Mon Jul 20 07:33:58.899656 2026] [security2:error] [pid 156215:tid 156413] [client 14.225.17.146:54070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHlwAAAEQ"], referer: http://maxenengineering.com/TEST
[Mon Jul 20 07:33:58.992865 2026] [security2:error] [pid 156215:tid 156449] [client 57.141.18.120:27586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHGgAAaEU"]
[Mon Jul 20 07:33:59.111298 2026] [security2:error] [pid 156215:tid 156415] [client 20.226.66.230:41450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4jx8J0fwhpxOKR8YhHwAAAAEY"]
[Mon Jul 20 07:33:59.321664 2026] [security2:error] [pid 156215:tid 156358] [client 57.141.18.73:55292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxcJ0fwhpxOKR8YhHOgAADRw"]
[Mon Jul 20 07:33:59.495184 2026] [security2:error] [pid 156215:tid 156372] [client 14.225.17.146:52813] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4jx8J0fwhpxOKR8YhHywAAABs"], referer: http://falconarrowshop.com/TEST
[Mon Jul 20 07:33:59.653446 2026] [autoindex:error] [pid 156215:tid 156469] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/js/jquery/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:33:59.653986 2026] [security2:error] [pid 156215:tid 156469] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jx8J0fwhpxOKR8YhH6QAAAHw"]
[Mon Jul 20 07:33:59.656691 2026] [security2:error] [pid 156215:tid 156396] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4jx8J0fwhpxOKR8YhH5QAAADM"]
[Mon Jul 20 07:33:59.730228 2026] [security2:error] [pid 156215:tid 156337] [remote 162.19.86.63:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jx8J0fwhpxOKR8YhH8AAAdnk"]
[Mon Jul 20 07:33:59.814294 2026] [security2:error] [pid 156215:tid 156390] [client 20.226.66.230:41450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/admin.php"] [unique_id "al4jx8J0fwhpxOKR8YhH9QAAAC0"]
[Mon Jul 20 07:33:59.814381 2026] [security2:error] [pid 156215:tid 156390] [client 20.226.66.230:41450] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/admin.php"] [unique_id "al4jx8J0fwhpxOKR8YhH9QAAAC0"]
[Mon Jul 20 07:33:59.916659 2026] [security2:error] [pid 156215:tid 156422] [client 14.225.17.146:53288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "friendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4jx8J0fwhpxOKR8YhH-gAAAE0"], referer: http://friendlyspreadsheet.com/TEST
[Mon Jul 20 07:33:59.921085 2026] [security2:error] [pid 156215:tid 156321] [remote 162.19.86.63:59176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jx8J0fwhpxOKR8YhIBAAASmk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:33:59.944239 2026] [security2:error] [pid 156215:tid 156445] [client 14.225.17.146:53276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4jx8J0fwhpxOKR8YhH-QAAAGQ"], referer: https://maxenengineering.com/TEST
[Mon Jul 20 07:33:59.955246 2026] [security2:error] [pid 156215:tid 156377] [client 62.164.177.222:36552] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jx8J0fwhpxOKR8YhIBgAAACA"]
[Mon Jul 20 07:33:59.955336 2026] [security2:error] [pid 156215:tid 156377] [client 62.164.177.222:36552] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jx8J0fwhpxOKR8YhIBgAAACA"]
[Mon Jul 20 07:34:00.149158 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/adminfuns.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIHgAAADw"]
[Mon Jul 20 07:34:00.149275 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41466] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/adminfuns.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIHgAAADw"]
[Mon Jul 20 07:34:00.246019 2026] [security2:error] [pid 156215:tid 156464] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIGgAAAHc"]
[Mon Jul 20 07:34:00.293110 2026] [security2:error] [pid 156215:tid 156364] [client 57.141.18.3:20764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jxsJ0fwhpxOKR8YhHjwAAE0g"]
[Mon Jul 20 07:34:00.363078 2026] [security2:error] [pid 156215:tid 156229] [remote 20.153.140.50:43590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4jyMJ0fwhpxOKR8YhILwAAGA0"]
[Mon Jul 20 07:34:00.424329 2026] [security2:error] [pid 156215:tid 156406] [client 158.173.166.181:59447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4jyMJ0fwhpxOKR8YhINwAAAD0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:34:00.433081 2026] [security2:error] [pid 156215:tid 156362] [client 62.164.177.222:39510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIOQAAABE"]
[Mon Jul 20 07:34:00.433180 2026] [security2:error] [pid 156215:tid 156362] [client 62.164.177.222:39510] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/xmlrpc.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIOQAAABE"]
[Mon Jul 20 07:34:00.472659 2026] [security2:error] [pid 156215:tid 156396] [client 143.44.185.218:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIPgAAADM"]
[Mon Jul 20 07:34:00.472764 2026] [security2:error] [pid 156215:tid 156396] [client 143.44.185.218:41364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIPgAAADM"]
[Mon Jul 20 07:34:00.612776 2026] [security2:error] [pid 156215:tid 156455] [client 20.226.66.230:41675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/goods.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIRwAAAG4"]
[Mon Jul 20 07:34:00.612929 2026] [security2:error] [pid 156215:tid 156455] [client 20.226.66.230:41675] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/goods.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIRwAAAG4"]
[Mon Jul 20 07:34:00.764548 2026] [security2:error] [pid 156215:tid 156289] [remote 20.153.140.50:43590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dnsplumbing.com"] [uri "/wp-login.php"] [unique_id "al4jyMJ0fwhpxOKR8YhITgAAFkk"], referer: https://dnsplumbing.com/wp-login.php
[Mon Jul 20 07:34:00.898348 2026] [security2:error] [pid 156215:tid 156381] [client 104.234.53.71:47663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIWAAAACQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:01.099665 2026] [security2:error] [pid 156215:tid 156435] [client 20.226.66.230:41711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/ms-edit.php"] [unique_id "al4jycJ0fwhpxOKR8YhIfQAAAFo"]
[Mon Jul 20 07:34:01.099830 2026] [security2:error] [pid 156215:tid 156435] [client 20.226.66.230:41711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/ms-edit.php"] [unique_id "al4jycJ0fwhpxOKR8YhIfQAAAFo"]
[Mon Jul 20 07:34:01.132219 2026] [security2:error] [pid 156215:tid 156269] [remote 72.167.132.114:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4jycJ0fwhpxOKR8YhIfgAADTU"]
[Mon Jul 20 07:34:01.141610 2026] [security2:error] [pid 156215:tid 156425] [client 14.225.17.146:60680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIYAAAAFA"], referer: http://longevityperformanceclinic.com/TEST
[Mon Jul 20 07:34:01.231447 2026] [security2:error] [pid 156215:tid 156353] [client 62.164.177.222:42830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4jycJ0fwhpxOKR8YhIjQAAAAg"]
[Mon Jul 20 07:34:01.231546 2026] [security2:error] [pid 156215:tid 156353] [client 62.164.177.222:42830] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/blog/xmlrpc.php"] [unique_id "al4jycJ0fwhpxOKR8YhIjQAAAAg"]
[Mon Jul 20 07:34:01.374239 2026] [security2:error] [pid 156215:tid 156308] [remote 72.167.132.114:49324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "royalart-lb.com"] [uri "/wp-login.php"] [unique_id "al4jycJ0fwhpxOKR8YhIlwAAblw"], referer: https://royalart-lb.com/wp-login.php
[Mon Jul 20 07:34:01.495516 2026] [security2:error] [pid 156215:tid 156433] [client 20.226.66.230:41360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/222.php"] [unique_id "al4jycJ0fwhpxOKR8YhIogAAAFg"]
[Mon Jul 20 07:34:01.495605 2026] [security2:error] [pid 156215:tid 156433] [client 20.226.66.230:41360] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/222.php"] [unique_id "al4jycJ0fwhpxOKR8YhIogAAAFg"]
[Mon Jul 20 07:34:01.663888 2026] [security2:error] [pid 156215:tid 156422] [client 62.164.177.222:47636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4jycJ0fwhpxOKR8YhIsAAAAE0"]
[Mon Jul 20 07:34:01.664009 2026] [security2:error] [pid 156215:tid 156422] [client 62.164.177.222:47636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/wordpress/xmlrpc.php"] [unique_id "al4jycJ0fwhpxOKR8YhIsAAAAE0"]
[Mon Jul 20 07:34:01.710039 2026] [security2:error] [pid 156215:tid 156379] [client 57.141.18.56:60914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jyMJ0fwhpxOKR8YhIHQAAIiA"]
[Mon Jul 20 07:34:01.833632 2026] [autoindex:error] [pid 156215:tid 156334] [remote 8.229.41.77:64962] AH01276: Cannot serve directory /home2/uwljivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.uwl.jiv.mybluehost.me
[Mon Jul 20 07:34:01.924210 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:41417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-bin/index.php"] [unique_id "al4jycJ0fwhpxOKR8YhIvQAAAHI"]
[Mon Jul 20 07:34:01.924343 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:41417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-bin/index.php"] [unique_id "al4jycJ0fwhpxOKR8YhIvQAAAHI"]
[Mon Jul 20 07:34:02.144169 2026] [security2:error] [pid 156215:tid 156427] [client 181.118.147.28:37688] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.147.118.181.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jysJ0fwhpxOKR8YhIzQAAAFI"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:34:02.144317 2026] [security2:error] [pid 156215:tid 156427] [client 181.118.147.28:37688] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jysJ0fwhpxOKR8YhIzQAAAFI"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:34:02.145562 2026] [security2:error] [pid 156215:tid 156451] [client 62.164.177.222:50564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/news/xmlrpc.php"] [unique_id "al4jysJ0fwhpxOKR8YhIzwAAAGo"]
[Mon Jul 20 07:34:02.145648 2026] [security2:error] [pid 156215:tid 156451] [client 62.164.177.222:50564] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/news/xmlrpc.php"] [unique_id "al4jysJ0fwhpxOKR8YhIzwAAAGo"]
[Mon Jul 20 07:34:02.303420 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4jysJ0fwhpxOKR8YhI3AAAAHE"]
[Mon Jul 20 07:34:02.325441 2026] [security2:error] [pid 156215:tid 156408] [client 47.129.222.11:19996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jysJ0fwhpxOKR8YhI3wAAAD8"]
[Mon Jul 20 07:34:02.390735 2026] [security2:error] [pid 156215:tid 156469] [client 14.225.17.146:53226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4jycJ0fwhpxOKR8YhIiwAAAHw"], referer: http://getgarrison.com/TEST
[Mon Jul 20 07:34:02.501785 2026] [autoindex:error] [pid 156215:tid 156449] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/css/dist/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:34:02.502306 2026] [security2:error] [pid 156215:tid 156449] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jysJ0fwhpxOKR8YhI-AAAAGg"]
[Mon Jul 20 07:34:02.524737 2026] [security2:error] [pid 156215:tid 156406] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4jysJ0fwhpxOKR8YhI9AAAAD0"]
[Mon Jul 20 07:34:02.624294 2026] [security2:error] [pid 156215:tid 156454] [client 62.164.177.222:54184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/web/xmlrpc.php"] [unique_id "al4jysJ0fwhpxOKR8YhJCQAAAG0"]
[Mon Jul 20 07:34:02.624397 2026] [security2:error] [pid 156215:tid 156454] [client 62.164.177.222:54184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/web/xmlrpc.php"] [unique_id "al4jysJ0fwhpxOKR8YhJCQAAAG0"]
[Mon Jul 20 07:34:02.703232 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/BDKR28WP.php"] [unique_id "al4jysJ0fwhpxOKR8YhJEAAAADw"]
[Mon Jul 20 07:34:02.703340 2026] [security2:error] [pid 156215:tid 156405] [client 20.226.66.230:41456] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/BDKR28WP.php"] [unique_id "al4jysJ0fwhpxOKR8YhJEAAAADw"]
[Mon Jul 20 07:34:02.992518 2026] [security2:error] [pid 156215:tid 156466] [client 57.141.18.83:63706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jycJ0fwhpxOKR8YhIrgAAeQg"]
[Mon Jul 20 07:34:03.020668 2026] [access_compat:error] [pid 156215:tid 156348] [client 66.198.240.43:0] AH01797: client denied by server configuration: /home1/deltattw/public_html/wp-cron.php
[Mon Jul 20 07:34:03.084228 2026] [security2:error] [pid 156215:tid 156357] [client 62.164.177.222:57714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/main/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJLwAAAAw"]
[Mon Jul 20 07:34:03.084321 2026] [security2:error] [pid 156215:tid 156357] [client 62.164.177.222:57714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/main/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJLwAAAAw"]
[Mon Jul 20 07:34:03.182108 2026] [security2:error] [pid 156215:tid 156448] [client 20.226.66.230:41569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/l10n/"] [unique_id "al4jy8J0fwhpxOKR8YhJOQAAAGc"]
[Mon Jul 20 07:34:03.257054 2026] [security2:error] [pid 156215:tid 156301] [remote 188.40.28.4:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4jy8J0fwhpxOKR8YhJPgAACVU"]
[Mon Jul 20 07:34:03.268386 2026] [security2:error] [pid 156215:tid 156374] [client 149.0.16.108:54477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJQAAAAB0"]
[Mon Jul 20 07:34:03.268543 2026] [security2:error] [pid 156215:tid 156374] [client 149.0.16.108:54477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJQAAAAB0"]
[Mon Jul 20 07:34:03.399106 2026] [autoindex:error] [pid 156215:tid 156388] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/l10n/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:34:03.399635 2026] [security2:error] [pid 156215:tid 156388] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jy8J0fwhpxOKR8YhJSgAAACs"]
[Mon Jul 20 07:34:03.401172 2026] [security2:error] [pid 156215:tid 156378] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/l10n/"] [unique_id "al4jy8J0fwhpxOKR8YhJQwAAACE"]
[Mon Jul 20 07:34:03.443905 2026] [security2:error] [pid 156215:tid 156337] [remote 188.40.28.4:34122] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4jy8J0fwhpxOKR8YhJTQAAeXk"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 07:34:03.479675 2026] [security2:error] [pid 156215:tid 156447] [client 57.141.18.92:51812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jysJ0fwhpxOKR8YhIxwAAZn8"]
[Mon Jul 20 07:34:03.548255 2026] [security2:error] [pid 156215:tid 156441] [client 62.164.177.222:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJZQAAAGA"]
[Mon Jul 20 07:34:03.548339 2026] [security2:error] [pid 156215:tid 156441] [client 62.164.177.222:60902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/cms/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJZQAAAGA"]
[Mon Jul 20 07:34:03.568763 2026] [security2:error] [pid 156215:tid 156435] [client 20.226.66.230:41569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/uploads/"] [unique_id "al4jy8J0fwhpxOKR8YhJagAAAFo"]
[Mon Jul 20 07:34:03.676477 2026] [security2:error] [pid 156215:tid 156380] [client 155.2.215.94:29183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJWgAAACM"]
[Mon Jul 20 07:34:03.779294 2026] [autoindex:error] [pid 156215:tid 156459] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-content/uploads/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:34:03.779858 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4jy8J0fwhpxOKR8YhJewAAAHI"]
[Mon Jul 20 07:34:03.782344 2026] [security2:error] [pid 156215:tid 156364] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/uploads/"] [unique_id "al4jy8J0fwhpxOKR8YhJeAAAABM"]
[Mon Jul 20 07:34:03.797268 2026] [security2:error] [pid 156215:tid 156405] [client 144.16.21.149:28253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJfgAAADw"]
[Mon Jul 20 07:34:03.797383 2026] [security2:error] [pid 156215:tid 156405] [client 144.16.21.149:28253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJfgAAADw"]
[Mon Jul 20 07:34:03.940224 2026] [security2:error] [pid 156215:tid 156441] [client 20.226.66.230:41569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp.php"] [unique_id "al4jy8J0fwhpxOKR8YhJhwAAAGA"]
[Mon Jul 20 07:34:03.940306 2026] [security2:error] [pid 156215:tid 156441] [client 20.226.66.230:41569] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp.php"] [unique_id "al4jy8J0fwhpxOKR8YhJhwAAAGA"]
[Mon Jul 20 07:34:03.964508 2026] [security2:error] [pid 156215:tid 156413] [client 157.20.138.62:50190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJjQAAAEQ"]
[Mon Jul 20 07:34:03.964600 2026] [security2:error] [pid 156215:tid 156413] [client 157.20.138.62:50190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4jy8J0fwhpxOKR8YhJjQAAAEQ"]
[Mon Jul 20 07:34:04.018447 2026] [security2:error] [pid 156215:tid 156362] [client 62.164.177.222:35846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJlQAAABE"]
[Mon Jul 20 07:34:04.018565 2026] [security2:error] [pid 156215:tid 156362] [client 62.164.177.222:35846] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/wpsite/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJlQAAABE"]
[Mon Jul 20 07:34:04.060649 2026] [security2:error] [pid 156215:tid 156396] [client 49.47.218.174:64671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJnAAAADM"]
[Mon Jul 20 07:34:04.060830 2026] [security2:error] [pid 156215:tid 156396] [client 49.47.218.174:64671] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJnAAAADM"]
[Mon Jul 20 07:34:04.232494 2026] [security2:error] [pid 156215:tid 156365] [client 57.141.18.85:24268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jysJ0fwhpxOKR8YhJHgAAFBc"]
[Mon Jul 20 07:34:04.265764 2026] [security2:error] [pid 156215:tid 156394] [client 46.110.96.34:10213] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4jzMJ0fwhpxOKR8YhJzwAAADE"]
[Mon Jul 20 07:34:04.288159 2026] [security2:error] [pid 156215:tid 156391] [client 20.226.66.230:41448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/abcd.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ0wAAAC4"]
[Mon Jul 20 07:34:04.288259 2026] [security2:error] [pid 156215:tid 156391] [client 20.226.66.230:41448] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/abcd.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ0wAAAC4"]
[Mon Jul 20 07:34:04.392952 2026] [security2:error] [pid 156215:tid 156385] [client 18.141.57.241:54518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ3QAAACg"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:34:04.412958 2026] [security2:error] [pid 156215:tid 156401] [client 57.141.18.118:52586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jy8J0fwhpxOKR8YhJLAAAOBw"]
[Mon Jul 20 07:34:04.428377 2026] [security2:error] [pid 156215:tid 156367] [client 181.118.147.28:37798] ModSecurity: Warning. Pattern match "/(contact(o|.?us)?|wp-comments-post|(send)?.?(form.)?e?mail(er)?|memberlist|send|contact.form(.handler)?|thankyou|leafmailer[0-9.]*)\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1546"] [id "900923"] [msg "contact form logging"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ4wAAABY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:34:04.462262 2026] [security2:error] [pid 156215:tid 156451] [client 62.164.177.222:39150] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/new/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ5AAAAGo"]
[Mon Jul 20 07:34:04.462350 2026] [security2:error] [pid 156215:tid 156451] [client 62.164.177.222:39150] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "elite-pk.com"] [uri "/new/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ5AAAAGo"]
[Mon Jul 20 07:34:04.627816 2026] [security2:error] [pid 156215:tid 156295] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ9QAALU8"]
[Mon Jul 20 07:34:04.628007 2026] [security2:error] [pid 156215:tid 156390] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ9QAALU8"]
[Mon Jul 20 07:34:04.663347 2026] [security2:error] [pid 156215:tid 156424] [client 20.226.66.230:41364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/a1.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ-wAAAE8"]
[Mon Jul 20 07:34:04.663428 2026] [security2:error] [pid 156215:tid 156424] [client 20.226.66.230:41364] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/a1.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ-wAAAE8"]
[Mon Jul 20 07:34:04.667170 2026] [security2:error] [pid 156215:tid 156428] [client 14.225.17.146:53090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4jy8J0fwhpxOKR8YhJcgAAAFM"], referer: http://nikkidesigns.net/TEST
[Mon Jul 20 07:34:04.708196 2026] [security2:error] [pid 156215:tid 156389] [client 104.234.53.79:38131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ_wAAACw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:04.854508 2026] [security2:error] [pid 156215:tid 156450] [client 66.249.70.167:38614] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "immigrationlawyers.me.uk"] [uri "/robots.txt"] [unique_id "al4jzMJ0fwhpxOKR8YhKEQAAAGk"]
[Mon Jul 20 07:34:04.977081 2026] [security2:error] [pid 156215:tid 156457] [client 188.166.209.66:51144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "al4jzMJ0fwhpxOKR8YhKIgAAAHA"], referer: binance.com
[Mon Jul 20 07:34:04.980901 2026] [security2:error] [pid 156215:tid 156223] [remote 20.153.140.50:43592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jzMJ0fwhpxOKR8YhKIQAAegc"]
[Mon Jul 20 07:34:05.211703 2026] [security2:error] [pid 156215:tid 156416] [client 20.226.66.230:41481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKPwAAAEc"]
[Mon Jul 20 07:34:05.211835 2026] [security2:error] [pid 156215:tid 156416] [client 20.226.66.230:41481] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKPwAAAEc"]
[Mon Jul 20 07:34:05.255377 2026] [security2:error] [pid 156215:tid 156386] [client 62.164.177.222:42256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.177.164.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elite-pk.com"] [uri "/wp-login.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKQQAAACk"]
[Mon Jul 20 07:34:05.384043 2026] [security2:error] [pid 156215:tid 156332] [remote 20.153.140.50:43592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKRgAABHQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:34:05.472666 2026] [security2:error] [pid 156215:tid 156389] [client 65.111.27.135:23251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKTAAAACw"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:05.485879 2026] [security2:error] [pid 156215:tid 156466] [client 136.158.60.21:35080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKUgAAAHk"]
[Mon Jul 20 07:34:05.486028 2026] [security2:error] [pid 156215:tid 156466] [client 136.158.60.21:35080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKUgAAAHk"]
[Mon Jul 20 07:34:05.494687 2026] [security2:error] [pid 156215:tid 156469] [client 57.141.18.9:20568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJmAAAfEs"]
[Mon Jul 20 07:34:05.553889 2026] [security2:error] [pid 156215:tid 156249] [remote 173.249.4.11:23964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKWAAAFyE"]
[Mon Jul 20 07:34:05.633340 2026] [security2:error] [pid 156215:tid 156367] [client 181.118.147.28:37798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ4wAAABY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:34:05.633392 2026] [security2:error] [pid 156215:tid 156367] [client 181.118.147.28:37798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ4wAAABY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:34:05.641912 2026] [security2:error] [pid 156215:tid 156299] [remote 20.153.140.50:37376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKYwAAW1M"]
[Mon Jul 20 07:34:05.642160 2026] [security2:error] [pid 156215:tid 156436] [client 20.153.140.50:37376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKYwAAW1M"]
[Mon Jul 20 07:34:05.664384 2026] [security2:error] [pid 156215:tid 156465] [client 20.226.66.230:41469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKaQAAAHg"]
[Mon Jul 20 07:34:05.664490 2026] [security2:error] [pid 156215:tid 156465] [client 20.226.66.230:41469] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKaQAAAHg"]
[Mon Jul 20 07:34:05.681114 2026] [security2:error] [pid 156215:tid 156422] [client 181.226.100.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4jysJ0fwhpxOKR8YhJEwAATV0"]
[Mon Jul 20 07:34:05.820714 2026] [security2:error] [pid 156215:tid 156426] [client 57.141.18.63:61464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jzMJ0fwhpxOKR8YhJ2QAAUQI"]
[Mon Jul 20 07:34:05.823136 2026] [security2:error] [pid 156215:tid 156425] [client 57.141.18.25:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKbAAAAFA"]
[Mon Jul 20 07:34:05.890508 2026] [security2:error] [pid 156215:tid 156368] [client 50.116.65.227:45306] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4jzcJ0fwhpxOKR8YhKfgAAABc"]
[Mon Jul 20 07:34:05.899137 2026] [security2:error] [pid 156215:tid 156462] [client 50.116.65.227:45308] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4jzcJ0fwhpxOKR8YhKgAAAAHU"]
[Mon Jul 20 07:34:05.929840 2026] [security2:error] [pid 156215:tid 156428] [client 49.37.242.14:55161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKggAAAFM"]
[Mon Jul 20 07:34:05.929957 2026] [security2:error] [pid 156215:tid 156428] [client 49.37.242.14:55161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKggAAAFM"]
[Mon Jul 20 07:34:05.992440 2026] [security2:error] [pid 156215:tid 156383] [client 154.192.123.127:16900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKiwAAACY"]
[Mon Jul 20 07:34:05.992850 2026] [security2:error] [pid 156215:tid 156383] [client 154.192.123.127:16900] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKiwAAACY"]
[Mon Jul 20 07:34:06.083873 2026] [security2:error] [pid 156215:tid 156384] [client 20.226.66.230:41442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/gettest.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKnAAAACc"]
[Mon Jul 20 07:34:06.083961 2026] [security2:error] [pid 156215:tid 156384] [client 20.226.66.230:41442] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/gettest.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKnAAAACc"]
[Mon Jul 20 07:34:06.087804 2026] [security2:error] [pid 156215:tid 156357] [client 36.93.152.155:59340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKnQAAAAw"]
[Mon Jul 20 07:34:06.087947 2026] [security2:error] [pid 156215:tid 156357] [client 36.93.152.155:59340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKnQAAAAw"]
[Mon Jul 20 07:34:06.117628 2026] [security2:error] [pid 156215:tid 156373] [client 65.111.24.172:51501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.24.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKnwAAABw"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:06.216118 2026] [autoindex:error] [pid 156215:tid 156406] [client 147.93.171.192:51033] AH01276: Cannot serve directory /home3/kidsklu4/public_html/GiftofGiving/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:34:06.260741 2026] [security2:error] [pid 156215:tid 156247] [remote 173.249.4.11:23964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKqQAAOh8"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:34:06.496262 2026] [security2:error] [pid 156215:tid 156439] [client 20.226.66.230:41716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/"] [unique_id "al4jzsJ0fwhpxOKR8YhKuAAAAF4"]
[Mon Jul 20 07:34:06.519758 2026] [security2:error] [pid 156215:tid 156454] [client 191.202.66.27:61639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKuQAAAG0"]
[Mon Jul 20 07:34:06.519851 2026] [security2:error] [pid 156215:tid 156454] [client 191.202.66.27:61639] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKuQAAAG0"]
[Mon Jul 20 07:34:06.615314 2026] [security2:error] [pid 156215:tid 156435] [client 179.127.84.238:64621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKwwAAAFo"]
[Mon Jul 20 07:34:06.615447 2026] [security2:error] [pid 156215:tid 156435] [client 179.127.84.238:64621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKwwAAAFo"]
[Mon Jul 20 07:34:06.688118 2026] [security2:error] [pid 156215:tid 156374] [client 57.141.18.106:31786] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKPAAAHSM"]
[Mon Jul 20 07:34:06.708170 2026] [security2:error] [pid 156215:tid 156459] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/index.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKywAAAHI"]
[Mon Jul 20 07:34:06.714485 2026] [security2:error] [pid 156215:tid 156279] [remote 41.207.20.82:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.20.207.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK0QAAZD8"]
[Mon Jul 20 07:34:06.714656 2026] [security2:error] [pid 156215:tid 156445] [client 41.207.20.82:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK0QAAZD8"]
[Mon Jul 20 07:34:06.722817 2026] [security2:error] [pid 156215:tid 156401] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "mail.adirondackengineering.com"] [uri "/wp-content/"] [unique_id "al4jzsJ0fwhpxOKR8YhKyAAAADg"]
[Mon Jul 20 07:34:06.855047 2026] [security2:error] [pid 156215:tid 156354] [client 14.225.17.146:51587] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKKgAAAAk"], referer: http://ccsdifference.com/TEST
[Mon Jul 20 07:34:06.885141 2026] [security2:error] [pid 156215:tid 156366] [client 20.226.66.230:41716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/simple.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK4wAAABU"]
[Mon Jul 20 07:34:06.885246 2026] [security2:error] [pid 156215:tid 156366] [client 20.226.66.230:41716] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/simple.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK4wAAABU"]
[Mon Jul 20 07:34:06.893417 2026] [security2:error] [pid 156215:tid 156252] [remote 57.141.18.30:43210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4jzsJ0fwhpxOKR8YhK4gAAQiQ"]
[Mon Jul 20 07:34:06.956711 2026] [security2:error] [pid 156215:tid 156394] [client 15.237.209.113:63130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.209.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK6QAAADE"]
[Mon Jul 20 07:34:06.956859 2026] [security2:error] [pid 156215:tid 156394] [client 15.237.209.113:63130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK6QAAADE"]
[Mon Jul 20 07:34:07.142453 2026] [security2:error] [pid 156215:tid 156423] [client 46.110.96.34:10213] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4jz8J0fwhpxOKR8YhK9gAAAE4"]
[Mon Jul 20 07:34:07.149982 2026] [security2:error] [pid 156215:tid 156425] [client 103.106.165.44:64951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jz8J0fwhpxOKR8YhK9wAAAFA"]
[Mon Jul 20 07:34:07.150072 2026] [security2:error] [pid 156215:tid 156425] [client 103.106.165.44:64951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4jz8J0fwhpxOKR8YhK9wAAAFA"]
[Mon Jul 20 07:34:07.150184 2026] [security2:error] [pid 156215:tid 156466] [client 181.226.100.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK3wAAeRY"]
[Mon Jul 20 07:34:07.230446 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/xxx.php"] [unique_id "al4jz8J0fwhpxOKR8YhLBQAAAHE"]
[Mon Jul 20 07:34:07.230522 2026] [security2:error] [pid 156215:tid 156458] [client 20.226.66.230:41555] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/xxx.php"] [unique_id "al4jz8J0fwhpxOKR8YhLBQAAAHE"]
[Mon Jul 20 07:34:07.297420 2026] [security2:error] [pid 156215:tid 156452] [client 193.37.33.20:36903] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4jz8J0fwhpxOKR8YhLCwAAAGs"]
[Mon Jul 20 07:34:07.310798 2026] [security2:error] [pid 156215:tid 156399] [client 193.37.33.21:53203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4jz8J0fwhpxOKR8YhLDAAAADY"]
[Mon Jul 20 07:34:07.326933 2026] [security2:error] [pid 156215:tid 156396] [client 57.141.18.120:45316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKewAAMzI"]
[Mon Jul 20 07:34:07.474408 2026] [security2:error] [pid 156215:tid 156433] [client 57.141.18.53:42320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jzcJ0fwhpxOKR8YhKgwAAWAQ"]
[Mon Jul 20 07:34:07.595716 2026] [authz_core:error] [pid 156215:tid 156283] [remote 35.243.195.251:61310] AH01630: client denied by server configuration: /home1/asliceo1/public_html/jmark/php.ini, referer: http://jmark.asliceofleadership.com
[Mon Jul 20 07:34:07.664739 2026] [security2:error] [pid 156215:tid 156440] [client 46.110.96.34:10213] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4jz8J0fwhpxOKR8YhLKwAAAF8"]
[Mon Jul 20 07:34:07.696821 2026] [security2:error] [pid 156215:tid 156380] [client 14.225.17.146:60655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4jz8J0fwhpxOKR8YhLKQAAACM"], referer: http://intelligentengineeringsolutions.com/TEST
[Mon Jul 20 07:34:07.753416 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/hypo.php"] [unique_id "al4jz8J0fwhpxOKR8YhLMwAAAGU"]
[Mon Jul 20 07:34:07.753494 2026] [security2:error] [pid 156215:tid 156446] [client 20.226.66.230:41723] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/hypo.php"] [unique_id "al4jz8J0fwhpxOKR8YhLMwAAAGU"]
[Mon Jul 20 07:34:07.868557 2026] [security2:error] [pid 156215:tid 156460] [client 14.225.17.146:51548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4jz8J0fwhpxOKR8YhLLQAAAHM"], referer: https://ccsdifference.com/TEST
[Mon Jul 20 07:34:08.022123 2026] [security2:error] [pid 156215:tid 156397] [client 14.225.17.146:51513] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4jzsJ0fwhpxOKR8YhKwAAAADQ"], referer: http://709fx.com/TEST
[Mon Jul 20 07:34:08.103051 2026] [security2:error] [pid 156215:tid 156389] [client 20.226.66.230:41348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al4j0MJ0fwhpxOKR8YhLSwAAACw"]
[Mon Jul 20 07:34:08.234661 2026] [security2:error] [pid 156215:tid 156413] [client 57.141.18.38:36490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4jzsJ0fwhpxOKR8YhK2AAARE4"]
[Mon Jul 20 07:34:08.315233 2026] [autoindex:error] [pid 156215:tid 156401] [client 20.226.66.230:41699] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:34:08.315713 2026] [security2:error] [pid 156215:tid 156401] [client 20.226.66.230:41699] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al4j0MJ0fwhpxOKR8YhLVAAAADg"]
[Mon Jul 20 07:34:08.351228 2026] [security2:error] [pid 156215:tid 156230] [remote 217.61.143.92:50114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLXgAAYA4"]
[Mon Jul 20 07:34:08.351351 2026] [security2:error] [pid 156215:tid 156441] [client 217.61.143.92:50114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "scott-assist.com"] [uri "/xmlrpc.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLXgAAYA4"]
[Mon Jul 20 07:34:08.368849 2026] [security2:error] [pid 156215:tid 156272] [remote 103.82.22.235:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLXwAAUzg"]
[Mon Jul 20 07:34:08.435030 2026] [security2:error] [pid 156215:tid 156345] [client 103.139.191.61:65190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLagAAAAA"]
[Mon Jul 20 07:34:08.435177 2026] [security2:error] [pid 156215:tid 156345] [client 103.139.191.61:65190] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLagAAAAA"]
[Mon Jul 20 07:34:08.479376 2026] [security2:error] [pid 156215:tid 156358] [client 20.226.66.230:41348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/chosen.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLbAAAAA0"]
[Mon Jul 20 07:34:08.479467 2026] [security2:error] [pid 156215:tid 156358] [client 20.226.66.230:41348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/chosen.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLbAAAAA0"]
[Mon Jul 20 07:34:08.570734 2026] [security2:error] [pid 156215:tid 156424] [client 50.116.65.227:39322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4j0MJ0fwhpxOKR8YhLdgAAAE8"]
[Mon Jul 20 07:34:08.581059 2026] [security2:error] [pid 156215:tid 156393] [client 50.116.65.227:45354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4j0MJ0fwhpxOKR8YhLdwAAAD4"]
[Mon Jul 20 07:34:08.679461 2026] [security2:error] [pid 156215:tid 156459] [client 103.176.215.66:52865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLfwAAAHI"]
[Mon Jul 20 07:34:08.679564 2026] [security2:error] [pid 156215:tid 156459] [client 103.176.215.66:52865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLfwAAAHI"]
[Mon Jul 20 07:34:08.828770 2026] [security2:error] [pid 156215:tid 156382] [client 145.239.10.137:51844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "reosportsboats.com"] [uri "/ty.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLhwAAACU"], referer: http://reosportsboats.com/ty.php
[Mon Jul 20 07:34:08.847392 2026] [security2:error] [pid 156215:tid 156471] [client 104.234.53.86:63169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLjQAAAH4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:08.875324 2026] [security2:error] [pid 156215:tid 156415] [client 20.226.66.230:41386] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/block-bindings/"] [unique_id "al4j0MJ0fwhpxOKR8YhLkAAAAEY"]
[Mon Jul 20 07:34:08.889085 2026] [security2:error] [pid 156215:tid 156337] [remote 103.82.22.235:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLkgAAInk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:34:08.948957 2026] [security2:error] [pid 156215:tid 156390] [client 14.225.17.146:59883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLhAAAAC0"], referer: http://alrowad-hub.net/TEST
[Mon Jul 20 07:34:08.965695 2026] [security2:error] [pid 156215:tid 156277] [remote 45.90.123.233:55830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLmAAAKD0"]
[Mon Jul 20 07:34:09.212076 2026] [security2:error] [pid 156215:tid 156221] [remote 162.19.86.63:34086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j0cJ0fwhpxOKR8YhLngAAFQU"]
[Mon Jul 20 07:34:09.421815 2026] [security2:error] [pid 156215:tid 156234] [remote 57.141.18.101:28310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLTQAAIRI"]
[Mon Jul 20 07:34:09.704247 2026] [security2:error] [pid 156215:tid 156296] [remote 57.141.18.34:28242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLaQAAZVA"]
[Mon Jul 20 07:34:09.814741 2026] [http2:info] [pid 164535:tid 164535] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:34:09.832189 2026] [security2:error] [pid 164535:tid 164665] [client 188.166.209.66:54099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "al4j0TYN371eKRzcKeROiAAAAIU"], referer: binance.com
[Mon Jul 20 07:34:09.919373 2026] [security2:error] [pid 164535:tid 164739] [client 20.226.66.230:1833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4j0TYN371eKRzcKeROtQAAAM8"]
[Mon Jul 20 07:34:09.919484 2026] [security2:error] [pid 164535:tid 164739] [client 20.226.66.230:1833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ravmike.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4j0TYN371eKRzcKeROtQAAAM8"]
[Mon Jul 20 07:34:10.043844 2026] [security2:error] [pid 164535:tid 164562] [remote 162.19.86.63:36794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j0jYN371eKRzcKeROxwAA6xo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:34:10.094181 2026] [autoindex:error] [pid 164535:tid 164773] [client 20.226.66.230:0] AH01276: Cannot serve directory /home2/northyg2/public_html/adirondackengineering/wp-includes/block-bindings/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:34:10.094809 2026] [security2:error] [pid 164535:tid 164686] [client 117.211.236.168:61356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j0jYN371eKRzcKeROzgAAAJo"]
[Mon Jul 20 07:34:10.094914 2026] [security2:error] [pid 164535:tid 164686] [client 117.211.236.168:61356] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j0jYN371eKRzcKeROzgAAAJo"]
[Mon Jul 20 07:34:10.094931 2026] [security2:error] [pid 164535:tid 164773] [client 20.226.66.230:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "mail.adirondackengineering.com"] [uri "/cgi-sys/403.html"] [unique_id "al4j0jYN371eKRzcKeROywAAAPE"]
[Mon Jul 20 07:34:10.113655 2026] [security2:error] [pid 164535:tid 164682] [client 20.226.66.230:41378] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "mail.adirondackengineering.com"] [uri "/wp-includes/block-bindings/"] [unique_id "al4j0jYN371eKRzcKeROyAAAAJY"]
[Mon Jul 20 07:34:10.206439 2026] [security2:error] [pid 164535:tid 164704] [client 181.226.100.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tiokubito.cl"] [uri "/index.php"] [unique_id "al4j0TYN371eKRzcKeROigAArAE"]
[Mon Jul 20 07:34:10.284098 2026] [security2:error] [pid 164535:tid 164700] [client 20.226.66.230:1818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ravmike.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4j0jYN371eKRzcKeRO5gAAAKg"]
[Mon Jul 20 07:34:10.284232 2026] [security2:error] [pid 164535:tid 164700] [client 20.226.66.230:1818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ravmike.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4j0jYN371eKRzcKeRO5gAAAKg"]
[Mon Jul 20 07:34:10.328606 2026] [security2:error] [pid 156215:tid 156312] [remote 57.141.18.88:28976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLnQAAK2A"]
[Mon Jul 20 07:34:10.412850 2026] [security2:error] [pid 156215:tid 156441] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.tnp.sco.mybluehost.me"] [uri "/index.php"] [unique_id "al4j0MJ0fwhpxOKR8YhLkQAAAGA"]
[Mon Jul 20 07:34:10.525790 2026] [security2:error] [pid 164535:tid 164575] [remote 57.141.18.84:46488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 84.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5872879"] [unique_id "al4j0jYN371eKRzcKeRO9wAAiyc"]
[Mon Jul 20 07:34:10.553132 2026] [security2:error] [pid 164535:tid 164772] [client 20.226.66.230:41457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/als.php"] [unique_id "al4j0jYN371eKRzcKeRO-wAAAPA"]
[Mon Jul 20 07:34:10.553244 2026] [security2:error] [pid 164535:tid 164772] [client 20.226.66.230:41457] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/als.php"] [unique_id "al4j0jYN371eKRzcKeRO-wAAAPA"]
[Mon Jul 20 07:34:10.759036 2026] [security2:error] [pid 164535:tid 164739] [client 20.226.66.230:1600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ravmike.com"] [uri "/x.php"] [unique_id "al4j0jYN371eKRzcKeRPHwAAAM8"]
[Mon Jul 20 07:34:10.759121 2026] [security2:error] [pid 164535:tid 164739] [client 20.226.66.230:1600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "ravmike.com"] [uri "/x.php"] [unique_id "al4j0jYN371eKRzcKeRPHwAAAM8"]
[Mon Jul 20 07:34:10.968403 2026] [security2:error] [pid 164535:tid 164713] [client 20.226.66.230:41485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 230.66.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mail.adirondackengineering.com"] [uri "/pol.php"] [unique_id "al4j0jYN371eKRzcKeRPLgAAALU"]
[Mon Jul 20 07:34:10.968519 2026] [security2:error] [pid 164535:tid 164713] [client 20.226.66.230:41485] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "mail.adirondackengineering.com"] [uri "/pol.php"] [unique_id "al4j0jYN371eKRzcKeRPLgAAALU"]
[Mon Jul 20 07:34:11.498582 2026] [autoindex:error] [pid 164535:tid 164611] [remote 8.234.213.150:59751] AH01276: Cannot serve directory /home2/yapvjbmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://yap.vjb.mybluehost.me
[Mon Jul 20 07:34:11.604350 2026] [security2:error] [pid 164535:tid 164732] [client 139.59.118.64:58694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4j0zYN371eKRzcKeRPaQAAAMg"], referer: https://t.co/
[Mon Jul 20 07:34:11.785330 2026] [security2:error] [pid 164535:tid 164731] [client 57.141.18.33:57190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0jYN371eKRzcKeRO8QAAxyU"]
[Mon Jul 20 07:34:12.019520 2026] [security2:error] [pid 164535:tid 164724] [client 66.249.73.102:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.steadfastwolfproductions.com"] [uri "/index.php"] [unique_id "al4j0jYN371eKRzcKeRPEwAAAMA"]
[Mon Jul 20 07:34:12.113985 2026] [security2:error] [pid 164535:tid 164704] [client 57.141.18.75:20918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0jYN371eKRzcKeRPEQAArC8"]
[Mon Jul 20 07:34:12.239875 2026] [security2:error] [pid 164535:tid 164715] [client 57.141.18.19:45156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0jYN371eKRzcKeRPIQAAtzM"]
[Mon Jul 20 07:34:12.309030 2026] [security2:error] [pid 164535:tid 164644] [remote 100.42.189.89:34452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4j1DYN371eKRzcKeRPtgAAyGw"]
[Mon Jul 20 07:34:12.441265 2026] [security2:error] [pid 164535:tid 164727] [client 14.225.17.146:59618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4j1DYN371eKRzcKeRPpgAAAMM"], referer: http://amalia-capital.com/TEST
[Mon Jul 20 07:34:12.443662 2026] [security2:error] [pid 164535:tid 164745] [client 57.141.18.29:60538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0zYN371eKRzcKeRPNAAA1Tk"]
[Mon Jul 20 07:34:12.511537 2026] [security2:error] [pid 164535:tid 164648] [remote 100.42.189.89:34452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4j1DYN371eKRzcKeRPwQAAunA"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 07:34:12.587559 2026] [security2:error] [pid 164535:tid 164652] [remote 45.90.123.233:50048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4j1DYN371eKRzcKeRPywAAonQ"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:34:12.759760 2026] [security2:error] [pid 164535:tid 164734] [client 57.141.18.95:43960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0zYN371eKRzcKeRPVAAAykU"]
[Mon Jul 20 07:34:12.848231 2026] [security2:error] [pid 164535:tid 164722] [client 143.44.185.218:42740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j1DYN371eKRzcKeRP4AAAAL4"]
[Mon Jul 20 07:34:12.848372 2026] [security2:error] [pid 164535:tid 164722] [client 143.44.185.218:42740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j1DYN371eKRzcKeRP4AAAAL4"]
[Mon Jul 20 07:34:13.137694 2026] [security2:error] [pid 164535:tid 164771] [client 15.237.142.234:58010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4j1TYN371eKRzcKeRP8AAAAO8"]
[Mon Jul 20 07:34:13.284286 2026] [security2:error] [pid 164535:tid 164773] [client 57.141.18.0:63316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0zYN371eKRzcKeRPfAAA8VU"]
[Mon Jul 20 07:34:13.312379 2026] [security2:error] [pid 164535:tid 164777] [client 104.248.72.14:54429] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.primests.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4j1TYN371eKRzcKeRP9AAAAPU"]
[Mon Jul 20 07:34:13.346913 2026] [security2:error] [pid 164535:tid 164714] [client 57.141.18.113:41842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j0zYN371eKRzcKeRPgAAAtlc"]
[Mon Jul 20 07:34:13.597572 2026] [security2:error] [pid 164535:tid 164768] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.ttb-sa.com"] [uri "/index.php"] [unique_id "al4j1DYN371eKRzcKeRPoQAAAOw"]
[Mon Jul 20 07:34:13.614062 2026] [security2:error] [pid 164535:tid 164772] [client 15.237.209.113:10476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.209.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4j1TYN371eKRzcKeRQGAAAAPA"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:34:13.667795 2026] [security2:error] [pid 164535:tid 164752] [client 14.225.17.146:56321] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4j1DYN371eKRzcKeRPvwAAANw"], referer: http://collectingrealestate.com/TEST
[Mon Jul 20 07:34:13.771025 2026] [security2:error] [pid 164535:tid 164746] [client 14.225.17.146:60950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4j1TYN371eKRzcKeRQDgAAANY"], referer: http://guidehunting.com/TEST
[Mon Jul 20 07:34:13.931053 2026] [security2:error] [pid 164535:tid 164753] [client 149.0.16.108:54986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j1TYN371eKRzcKeRQKwAAAN0"]
[Mon Jul 20 07:34:13.931581 2026] [security2:error] [pid 164535:tid 164753] [client 149.0.16.108:54986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j1TYN371eKRzcKeRQKwAAAN0"]
[Mon Jul 20 07:34:13.964159 2026] [security2:error] [pid 164535:tid 164789] [client 57.141.18.117:50818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j1DYN371eKRzcKeRPqgABAWU"]
[Mon Jul 20 07:34:14.253911 2026] [security2:error] [pid 164535:tid 164742] [client 14.225.17.146:61431] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4j1jYN371eKRzcKeRQPAAAANI"]
[Mon Jul 20 07:34:14.329338 2026] [security2:error] [pid 164535:tid 164677] [client 142.111.152.184:40549] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j1jYN371eKRzcKeRQPgAAAJE"]
[Mon Jul 20 07:34:14.380668 2026] [security2:error] [pid 164535:tid 164671] [client 94.154.43.229:65442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.peycosoluciones.com"] [uri "/.env"] [unique_id "al4j1jYN371eKRzcKeRQUAAAAIs"]
[Mon Jul 20 07:34:14.386273 2026] [security2:error] [pid 164535:tid 164737] [client 14.225.17.146:58287] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4j1jYN371eKRzcKeRQPwAAAM0"]
[Mon Jul 20 07:34:14.406264 2026] [security2:error] [pid 164535:tid 164682] [client 78.46.215.1:6014] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4j1jYN371eKRzcKeRQPQAAAJY"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:34:14.488688 2026] [security2:error] [pid 164535:tid 164681] [client 27.71.85.113:23060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4j1jYN371eKRzcKeRQVAAAlS4"]
[Mon Jul 20 07:34:14.522175 2026] [security2:error] [pid 164535:tid 164679] [client 157.20.138.62:50763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j1jYN371eKRzcKeRQXwAAAJM"]
[Mon Jul 20 07:34:14.522319 2026] [security2:error] [pid 164535:tid 164679] [client 157.20.138.62:50763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j1jYN371eKRzcKeRQXwAAAJM"]
[Mon Jul 20 07:34:14.660645 2026] [security2:error] [pid 164535:tid 164721] [client 170.64.230.12:62918] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4j1jYN371eKRzcKeRQYAAAAL0"]
[Mon Jul 20 07:34:14.772308 2026] [security2:error] [pid 164535:tid 164784] [client 144.16.21.149:28333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j1jYN371eKRzcKeRQbwAAAPw"]
[Mon Jul 20 07:34:14.772458 2026] [security2:error] [pid 164535:tid 164784] [client 144.16.21.149:28333] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j1jYN371eKRzcKeRQbwAAAPw"]
[Mon Jul 20 07:34:14.905198 2026] [security2:error] [pid 164535:tid 164768] [client 14.225.17.146:58039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4j1jYN371eKRzcKeRQaQAAAOw"], referer: https://guidehunting.com/TEST
[Mon Jul 20 07:34:14.978219 2026] [security2:error] [pid 164535:tid 164731] [client 188.166.209.66:55063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "al4j1jYN371eKRzcKeRQgwAAAMc"], referer: binance.com
[Mon Jul 20 07:34:15.009459 2026] [security2:error] [pid 164535:tid 164739] [client 49.47.218.174:65328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j1zYN371eKRzcKeRQhQAAAM8"]
[Mon Jul 20 07:34:15.009574 2026] [security2:error] [pid 164535:tid 164739] [client 49.47.218.174:65328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j1zYN371eKRzcKeRQhQAAAM8"]
[Mon Jul 20 07:34:15.136864 2026] [security2:error] [pid 164535:tid 164602] [remote 130.51.180.8:46398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4j1zYN371eKRzcKeRQkgAAxEI"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:34:15.288797 2026] [security2:error] [pid 164535:tid 164695] [client 170.64.230.12:63016] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4j1zYN371eKRzcKeRQlgAAAKM"]
[Mon Jul 20 07:34:15.692607 2026] [security2:error] [pid 164535:tid 164696] [client 104.234.53.61:44643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4j1zYN371eKRzcKeRQugAAAKQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:15.947338 2026] [security2:error] [pid 164535:tid 164617] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j1zYN371eKRzcKeRQ0AAA51E"]
[Mon Jul 20 07:34:15.947555 2026] [security2:error] [pid 164535:tid 164763] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j1zYN371eKRzcKeRQ0AAA51E"]
[Mon Jul 20 07:34:15.958640 2026] [security2:error] [pid 164535:tid 164712] [client 45.3.52.132:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j1zYN371eKRzcKeRQzwAAALQ"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:16.091372 2026] [security2:error] [pid 164535:tid 164700] [client 14.225.17.146:59581] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4j1zYN371eKRzcKeRQjgAAAKg"], referer: http://entuvy.com/TEST
[Mon Jul 20 07:34:16.272005 2026] [security2:error] [pid 164535:tid 164765] [client 136.158.60.21:36493] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j2DYN371eKRzcKeRQ8AAAAOk"]
[Mon Jul 20 07:34:16.272100 2026] [security2:error] [pid 164535:tid 164765] [client 136.158.60.21:36493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j2DYN371eKRzcKeRQ8AAAAOk"]
[Mon Jul 20 07:34:16.291868 2026] [security2:error] [pid 164535:tid 164644] [remote 130.51.180.8:46398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4j2DYN371eKRzcKeRQ8QAAuGw"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:34:16.511884 2026] [security2:error] [pid 164535:tid 164640] [remote 18.61.192.253:55636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4j2DYN371eKRzcKeRRAQAAmmg"]
[Mon Jul 20 07:34:16.568973 2026] [security2:error] [pid 164535:tid 164740] [client 154.192.123.127:17313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j2DYN371eKRzcKeRRCQAAANA"]
[Mon Jul 20 07:34:16.569096 2026] [security2:error] [pid 164535:tid 164740] [client 154.192.123.127:17313] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j2DYN371eKRzcKeRRCQAAANA"]
[Mon Jul 20 07:34:16.571297 2026] [security2:error] [pid 164535:tid 164770] [client 65.111.28.129:16095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j2DYN371eKRzcKeRRBAAAAO4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:16.616835 2026] [security2:error] [pid 164535:tid 164707] [client 36.93.152.155:59858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j2DYN371eKRzcKeRRDgAAAK8"]
[Mon Jul 20 07:34:16.616942 2026] [security2:error] [pid 164535:tid 164707] [client 36.93.152.155:59858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j2DYN371eKRzcKeRRDgAAAK8"]
[Mon Jul 20 07:34:16.629767 2026] [security2:error] [pid 164535:tid 164764] [client 57.141.18.53:59866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j1zYN371eKRzcKeRQkwAA6D4"]
[Mon Jul 20 07:34:16.722981 2026] [security2:error] [pid 164535:tid 164605] [remote 124.55.178.99:59184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4j2DYN371eKRzcKeRRGQAA6kU"]
[Mon Jul 20 07:34:16.980108 2026] [security2:error] [pid 164535:tid 164661] [remote 18.61.192.253:55636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.192.61.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4j2DYN371eKRzcKeRRJAAA830"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 07:34:17.154097 2026] [security2:error] [pid 164535:tid 164659] [remote 124.55.178.99:59184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4j2TYN371eKRzcKeRRMAAA5Hs"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 07:34:17.200153 2026] [security2:error] [pid 164535:tid 164689] [client 45.3.44.98:51431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j2TYN371eKRzcKeRRMQAAAJ0"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:17.246414 2026] [security2:error] [pid 164535:tid 164748] [client 191.202.66.27:62140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j2TYN371eKRzcKeRRMwAAANg"]
[Mon Jul 20 07:34:17.246560 2026] [security2:error] [pid 164535:tid 164748] [client 191.202.66.27:62140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j2TYN371eKRzcKeRRMwAAANg"]
[Mon Jul 20 07:34:17.256565 2026] [security2:error] [pid 164535:tid 164772] [client 179.127.84.238:65306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j2TYN371eKRzcKeRRNAAAAPA"]
[Mon Jul 20 07:34:17.256699 2026] [security2:error] [pid 164535:tid 164772] [client 179.127.84.238:65306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j2TYN371eKRzcKeRRNAAAAPA"]
[Mon Jul 20 07:34:17.535398 2026] [security2:error] [pid 164535:tid 164721] [client 57.141.18.73:42164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j2DYN371eKRzcKeRQ3gAAvWI"]
[Mon Jul 20 07:34:17.660452 2026] [security2:error] [pid 164535:tid 164717] [client 103.106.165.44:65448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j2TYN371eKRzcKeRRVQAAALk"]
[Mon Jul 20 07:34:17.660607 2026] [security2:error] [pid 164535:tid 164717] [client 103.106.165.44:65448] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j2TYN371eKRzcKeRRVQAAALk"]
[Mon Jul 20 07:34:17.758867 2026] [security2:error] [pid 164535:tid 164756] [client 104.234.53.69:35847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4j2TYN371eKRzcKeRRYAAAAOA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:17.955780 2026] [security2:error] [pid 164535:tid 164684] [client 57.141.18.95:43974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j2DYN371eKRzcKeRRBQAAmG8"]
[Mon Jul 20 07:34:18.054297 2026] [security2:error] [pid 164535:tid 164563] [remote 188.40.28.4:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j2jYN371eKRzcKeRRcQAApBs"]
[Mon Jul 20 07:34:18.135650 2026] [security2:error] [pid 164535:tid 164746] [client 14.225.17.146:60982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4j2jYN371eKRzcKeRRbwAAANY"], referer: http://thefriendlyspreadsheet.com/TEST
[Mon Jul 20 07:34:18.136653 2026] [proxy:error] [pid 164535:tid 164699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:34:18.136703 2026] [proxy_http:error] [pid 164535:tid 164699] [client 107.172.180.205:54898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:34:18.137250 2026] [proxy:error] [pid 164535:tid 164699] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:34:18.137273 2026] [proxy_http:error] [pid 164535:tid 164699] [client 107.172.180.205:54898] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:34:18.286982 2026] [security2:error] [pid 164535:tid 164574] [remote 188.40.28.4:53162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j2jYN371eKRzcKeRRjAAAtyY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:34:18.661878 2026] [security2:error] [pid 164535:tid 164707] [client 140.245.46.64:56665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4j2jYN371eKRzcKeRRowAAAK8"]
[Mon Jul 20 07:34:18.986445 2026] [security2:error] [pid 164535:tid 164787] [client 74.208.214.194:39068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4j2jYN371eKRzcKeRRugAAAP8"]
[Mon Jul 20 07:34:19.127923 2026] [security2:error] [pid 164535:tid 164764] [client 103.176.215.66:53403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j2zYN371eKRzcKeRR2QAAAOg"]
[Mon Jul 20 07:34:19.128408 2026] [security2:error] [pid 164535:tid 164764] [client 103.176.215.66:53403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j2zYN371eKRzcKeRR2QAAAOg"]
[Mon Jul 20 07:34:19.303821 2026] [security2:error] [pid 164535:tid 164709] [client 49.37.242.14:55690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4j2zYN371eKRzcKeRR6wAAALE"]
[Mon Jul 20 07:34:19.303913 2026] [security2:error] [pid 164535:tid 164709] [client 49.37.242.14:55690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4j2zYN371eKRzcKeRR6wAAALE"]
[Mon Jul 20 07:34:19.367412 2026] [autoindex:error] [pid 164535:tid 164708] [client 8.229.41.77:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.varmath.com
[Mon Jul 20 07:34:19.473568 2026] [security2:error] [pid 164535:tid 164610] [remote 84.247.172.23:39604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4j2zYN371eKRzcKeRR-AAA5Uo"]
[Mon Jul 20 07:34:19.538524 2026] [security2:error] [pid 164535:tid 164667] [client 103.139.191.61:49290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j2zYN371eKRzcKeRR_QAAAIc"]
[Mon Jul 20 07:34:19.538659 2026] [security2:error] [pid 164535:tid 164667] [client 103.139.191.61:49290] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j2zYN371eKRzcKeRR_QAAAIc"]
[Mon Jul 20 07:34:19.578154 2026] [proxy:error] [pid 164535:tid 164769] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:34:19.578246 2026] [proxy_http:error] [pid 164535:tid 164769] [client 107.172.180.205:60810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:34:19.578643 2026] [proxy:error] [pid 164535:tid 164769] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:34:19.578669 2026] [proxy_http:error] [pid 164535:tid 164769] [client 107.172.180.205:60810] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:34:19.882717 2026] [security2:error] [pid 164535:tid 164750] [client 188.166.209.66:65458] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "al4j2zYN371eKRzcKeRSGwAAANo"], referer: binance.com
[Mon Jul 20 07:34:20.462654 2026] [security2:error] [pid 164535:tid 164738] [client 140.245.46.64:57512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4j3DYN371eKRzcKeRSSwAAAM4"]
[Mon Jul 20 07:34:20.499616 2026] [security2:error] [pid 164535:tid 164698] [client 13.233.207.33:57238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4j3DYN371eKRzcKeRSTAAAAKY"]
[Mon Jul 20 07:34:20.618757 2026] [security2:error] [pid 164535:tid 164686] [client 14.225.17.146:62957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4j2jYN371eKRzcKeRRpAAAAJo"], referer: http://mollycahill.com/TEST
[Mon Jul 20 07:34:20.781358 2026] [security2:error] [pid 164535:tid 164747] [client 14.225.17.146:63223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4j2jYN371eKRzcKeRRogAAANc"], referer: http://jvcmotorsports.com/TEST
[Mon Jul 20 07:34:20.976265 2026] [security2:error] [pid 164535:tid 164733] [client 52.167.144.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4j3DYN371eKRzcKeRSTQAAyWs"]
[Mon Jul 20 07:34:21.013301 2026] [security2:error] [pid 164535:tid 164690] [client 213.111.158.220:53414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.158.111.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bokverk.com"] [uri "/wp-login.php"] [unique_id "al4j3DYN371eKRzcKeRScgAAAJ4"]
[Mon Jul 20 07:34:21.034213 2026] [security2:error] [pid 164535:tid 164711] [client 140.245.46.64:57788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4j3TYN371eKRzcKeRSdwAAALM"]
[Mon Jul 20 07:34:21.036049 2026] [security2:error] [pid 164535:tid 164703] [client 57.141.18.3:29114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j2zYN371eKRzcKeRR_gAAq0s"]
[Mon Jul 20 07:34:21.069936 2026] [security2:error] [pid 164535:tid 164753] [client 98.159.234.160:53699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4j3TYN371eKRzcKeRSeAAAAN0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:34:21.079718 2026] [security2:error] [pid 164535:tid 164775] [client 57.141.18.20:20712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j2zYN371eKRzcKeRSBgAA804"]
[Mon Jul 20 07:34:21.439880 2026] [security2:error] [pid 164535:tid 164761] [client 13.232.231.177:60450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4j3TYN371eKRzcKeRSmwAAAOU"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:34:21.468525 2026] [security2:error] [pid 164535:tid 164719] [client 213.111.158.220:53428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.158.111.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bokverk.com"] [uri "/administrator/index.php"] [unique_id "al4j3TYN371eKRzcKeRSogAAALs"]
[Mon Jul 20 07:34:21.562688 2026] [security2:error] [pid 164535:tid 164557] [remote 84.247.172.23:39604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-login.php"] [unique_id "al4j3TYN371eKRzcKeRSqAAAqxU"], referer: https://suretybonds-california.com/wp-login.php
[Mon Jul 20 07:34:21.607055 2026] [security2:error] [pid 164535:tid 164665] [client 140.245.46.64:58033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-admin/load-styles.php"] [unique_id "al4j3TYN371eKRzcKeRSqwAAAIU"]
[Mon Jul 20 07:34:21.628584 2026] [security2:error] [pid 164535:tid 164786] [client 139.59.118.64:59915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4j3TYN371eKRzcKeRSrQAAAP4"]
[Mon Jul 20 07:34:21.652526 2026] [security2:error] [pid 164535:tid 164748] [client 82.102.18.116:55010] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4j3TYN371eKRzcKeRSsgAAANg"]
[Mon Jul 20 07:34:21.923132 2026] [security2:error] [pid 164535:tid 164728] [client 213.111.158.220:53444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.158.111.213.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "bokverk.com"] [uri "/api/index.php/v1/config/application"] [unique_id "al4j3TYN371eKRzcKeRSzQAAAMQ"]
[Mon Jul 20 07:34:22.001539 2026] [security2:error] [pid 164535:tid 164761] [client 82.102.18.116:55026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.actionsatebmf.org"] [uri "/xmlrpc.php"] [unique_id "al4j3TYN371eKRzcKeRS1QAAAOU"]
[Mon Jul 20 07:34:22.215106 2026] [security2:error] [pid 164535:tid 164729] [client 57.141.18.78:22340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j3DYN371eKRzcKeRSZQAAxXE"]
[Mon Jul 20 07:34:22.344374 2026] [security2:error] [pid 164535:tid 164776] [client 117.211.236.168:61992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j3jYN371eKRzcKeRS8QAAAPQ"]
[Mon Jul 20 07:34:22.344486 2026] [security2:error] [pid 164535:tid 164776] [client 117.211.236.168:61992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j3jYN371eKRzcKeRS8QAAAPQ"]
[Mon Jul 20 07:34:22.381019 2026] [security2:error] [pid 164535:tid 164759] [client 213.111.158.220:53460] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "bokverk.com"] [uri "/"] [unique_id "al4j3jYN371eKRzcKeRS9AAAAOM"]
[Mon Jul 20 07:34:22.601077 2026] [security2:error] [pid 164535:tid 164744] [client 104.234.53.89:41093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4j3jYN371eKRzcKeRTBAAAANQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:22.648825 2026] [security2:error] [pid 164535:tid 164582] [remote 57.141.18.101:57726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6055825"] [unique_id "al4j3jYN371eKRzcKeRTCAAA_y4"]
[Mon Jul 20 07:34:22.680118 2026] [security2:error] [pid 164535:tid 164689] [client 82.102.18.116:55042] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4j3jYN371eKRzcKeRTCgAAAJ0"]
[Mon Jul 20 07:34:22.726025 2026] [security2:error] [pid 164535:tid 164770] [client 82.102.18.182:53988] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4j3jYN371eKRzcKeRTJwAAAO4"]
[Mon Jul 20 07:34:22.814594 2026] [security2:error] [pid 164535:tid 164665] [client 46.110.96.34:45802] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4j3jYN371eKRzcKeRTMQAAAIU"]
[Mon Jul 20 07:34:22.955129 2026] [security2:error] [pid 164535:tid 164682] [client 180.249.173.210:63543] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j3jYN371eKRzcKeRTRgAAAJY"]
[Mon Jul 20 07:34:22.955254 2026] [security2:error] [pid 164535:tid 164682] [client 180.249.173.210:63543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j3jYN371eKRzcKeRTRgAAAJY"]
[Mon Jul 20 07:34:23.017185 2026] [security2:error] [pid 164535:tid 164783] [client 82.102.18.116:55046] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4j3zYN371eKRzcKeRTSQAAAPs"]
[Mon Jul 20 07:34:23.215408 2026] [security2:error] [pid 164535:tid 164756] [client 57.141.18.81:56708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j3TYN371eKRzcKeRSvgAA4G8"]
[Mon Jul 20 07:34:23.351048 2026] [security2:error] [pid 164535:tid 164757] [client 82.102.18.116:55050] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4j3zYN371eKRzcKeRTaQAAAOE"]
[Mon Jul 20 07:34:23.374003 2026] [security2:error] [pid 164535:tid 164701] [client 82.102.18.182:54004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/xmlrpc.php"] [unique_id "al4j3zYN371eKRzcKeRTagAAAKk"]
[Mon Jul 20 07:34:23.542069 2026] [security2:error] [pid 164535:tid 164773] [client 57.141.18.125:53490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j3TYN371eKRzcKeRS0gAA8Rs"]
[Mon Jul 20 07:34:23.675552 2026] [security2:error] [pid 164535:tid 164789] [client 82.102.18.116:55066] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4j3zYN371eKRzcKeRTiAAAAQE"]
[Mon Jul 20 07:34:23.872274 2026] [security2:error] [pid 164535:tid 164666] [client 50.116.65.227:48978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4j3zYN371eKRzcKeRTVAAAAIY"]
[Mon Jul 20 07:34:23.987519 2026] [security2:error] [pid 164535:tid 164773] [client 82.102.18.116:13815] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4j3zYN371eKRzcKeRTwAAAAPE"]
[Mon Jul 20 07:34:23.989431 2026] [security2:error] [pid 164535:tid 164565] [remote 57.141.18.89:26606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4j3zYN371eKRzcKeRTwQAAux0"]
[Mon Jul 20 07:34:23.997637 2026] [security2:error] [pid 164535:tid 164727] [client 82.102.18.182:54014] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4j3zYN371eKRzcKeRTwwAAAMM"]
[Mon Jul 20 07:34:24.030925 2026] [security2:error] [pid 164535:tid 164784] [client 178.62.252.200:62032] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.sanifidensolutions.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4j3zYN371eKRzcKeRTuwAAAPw"]
[Mon Jul 20 07:34:24.321062 2026] [security2:error] [pid 164535:tid 164666] [client 82.102.18.116:55082] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4j4DYN371eKRzcKeRT1gAAAIY"]
[Mon Jul 20 07:34:24.321998 2026] [security2:error] [pid 164535:tid 164704] [client 143.44.185.218:44023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j4DYN371eKRzcKeRT1wAAAKw"]
[Mon Jul 20 07:34:24.322108 2026] [security2:error] [pid 164535:tid 164704] [client 143.44.185.218:44023] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j4DYN371eKRzcKeRT1wAAAKw"]
[Mon Jul 20 07:34:24.539606 2026] [security2:error] [pid 164535:tid 164712] [client 57.141.18.29:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4j4DYN371eKRzcKeRT4AAAALQ"]
[Mon Jul 20 07:34:24.551163 2026] [security2:error] [pid 164535:tid 164775] [client 149.0.16.108:55496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j4DYN371eKRzcKeRT7AAAAPM"]
[Mon Jul 20 07:34:24.551240 2026] [security2:error] [pid 164535:tid 164775] [client 149.0.16.108:55496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j4DYN371eKRzcKeRT7AAAAPM"]
[Mon Jul 20 07:34:24.581707 2026] [security2:error] [pid 164535:tid 164724] [client 50.116.65.227:48998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4j3zYN371eKRzcKeRTswAAAMA"]
[Mon Jul 20 07:34:24.647628 2026] [security2:error] [pid 164535:tid 164790] [client 140.245.46.64:59593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-includes/version.php"] [unique_id "al4j4DYN371eKRzcKeRT-AAAAQI"]
[Mon Jul 20 07:34:24.654759 2026] [security2:error] [pid 164535:tid 164702] [client 114.119.137.122:46119] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sesamegreenbeans.com"] [uri "/kota88-feastcoastroad"] [unique_id "al4j4DYN371eKRzcKeRT-gAAAKo"], referer: https://sesamegreenbeans.com/kota88-feastcoastroad
[Mon Jul 20 07:34:24.668154 2026] [security2:error] [pid 164535:tid 164755] [client 82.102.18.116:55084] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4j4DYN371eKRzcKeRT_QAAAN8"]
[Mon Jul 20 07:34:24.671627 2026] [security2:error] [pid 164535:tid 164673] [client 82.102.18.182:54026] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4j4DYN371eKRzcKeRT_gAAAI0"]
[Mon Jul 20 07:34:24.709804 2026] [security2:error] [pid 164535:tid 164713] [client 104.234.53.88:58175] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4j4DYN371eKRzcKeRT-wAAALU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:24.909147 2026] [security2:error] [pid 164535:tid 164704] [client 188.166.209.66:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "al4j4DYN371eKRzcKeRUDAAAAKw"], referer: binance.com
[Mon Jul 20 07:34:24.952512 2026] [security2:error] [pid 164535:tid 164745] [client 142.111.152.71:23159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j4DYN371eKRzcKeRUAwAAANU"]
[Mon Jul 20 07:34:25.031620 2026] [security2:error] [pid 164535:tid 164721] [client 82.102.18.116:55098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4j4TYN371eKRzcKeRUIQAAAL0"]
[Mon Jul 20 07:34:25.090511 2026] [security2:error] [pid 164535:tid 164717] [client 157.20.138.62:51332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j4TYN371eKRzcKeRUJAAAALk"]
[Mon Jul 20 07:34:25.090805 2026] [security2:error] [pid 164535:tid 164717] [client 157.20.138.62:51332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j4TYN371eKRzcKeRUJAAAALk"]
[Mon Jul 20 07:34:25.131688 2026] [security2:error] [pid 164535:tid 164692] [client 49.47.218.174:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j4TYN371eKRzcKeRUJwAAAKA"]
[Mon Jul 20 07:34:25.131802 2026] [security2:error] [pid 164535:tid 164692] [client 49.47.218.174:49488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j4TYN371eKRzcKeRUJwAAAKA"]
[Mon Jul 20 07:34:25.219555 2026] [security2:error] [pid 164535:tid 164733] [client 140.245.46.64:59867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-includes/functions.php"] [unique_id "al4j4TYN371eKRzcKeRUKgAAAMk"]
[Mon Jul 20 07:34:25.337546 2026] [security2:error] [pid 164535:tid 164667] [client 82.102.18.182:54034] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4j4TYN371eKRzcKeRUMwAAAIc"]
[Mon Jul 20 07:34:25.346223 2026] [security2:error] [pid 164535:tid 164708] [client 57.141.18.81:56718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j3zYN371eKRzcKeRTpAAAsGI"]
[Mon Jul 20 07:34:25.379082 2026] [security2:error] [pid 164535:tid 164716] [client 82.102.18.116:55114] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4j4TYN371eKRzcKeRUNgAAALg"]
[Mon Jul 20 07:34:25.633024 2026] [security2:error] [pid 164535:tid 164666] [client 104.234.53.71:22949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4j4TYN371eKRzcKeRUSAAAAIY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:25.713262 2026] [security2:error] [pid 164535:tid 164746] [client 82.102.18.116:55116] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4j4TYN371eKRzcKeRUTgAAANY"]
[Mon Jul 20 07:34:25.791817 2026] [security2:error] [pid 164535:tid 164736] [client 140.245.46.64:60191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-includes/class-wp.php"] [unique_id "al4j4TYN371eKRzcKeRUVAAAAMw"]
[Mon Jul 20 07:34:25.970338 2026] [security2:error] [pid 164535:tid 164735] [client 82.102.18.182:54040] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4j4TYN371eKRzcKeRUYgAAAMs"]
[Mon Jul 20 07:34:26.025589 2026] [security2:error] [pid 164535:tid 164750] [client 82.102.18.116:55132] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4j4jYN371eKRzcKeRUagAAANo"]
[Mon Jul 20 07:34:26.375779 2026] [security2:error] [pid 164535:tid 164787] [client 140.245.46.64:60477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-includes/option.php"] [unique_id "al4j4jYN371eKRzcKeRUgQAAAP8"]
[Mon Jul 20 07:34:26.376361 2026] [security2:error] [pid 164535:tid 164680] [client 82.102.18.116:55136] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4j4jYN371eKRzcKeRUggAAAJQ"]
[Mon Jul 20 07:34:26.510810 2026] [security2:error] [pid 164535:tid 164766] [client 144.16.21.149:36133] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j4jYN371eKRzcKeRUigAAAOo"]
[Mon Jul 20 07:34:26.510948 2026] [security2:error] [pid 164535:tid 164766] [client 144.16.21.149:36133] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j4jYN371eKRzcKeRUigAAAOo"]
[Mon Jul 20 07:34:26.563344 2026] [security2:error] [pid 164535:tid 164770] [client 104.234.53.48:38677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4j4jYN371eKRzcKeRUkAAAAO4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:26.582769 2026] [security2:error] [pid 164535:tid 164629] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j4jYN371eKRzcKeRUkwABAF0"]
[Mon Jul 20 07:34:26.582965 2026] [security2:error] [pid 164535:tid 164788] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j4jYN371eKRzcKeRUkwABAF0"]
[Mon Jul 20 07:34:26.646721 2026] [security2:error] [pid 164535:tid 164671] [client 123.202.189.111:26799] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "locketsandcharms.com"] [uri "/wp-content/uploads/2018/07/img_2577.jpg"] [unique_id "al4j4jYN371eKRzcKeRUogAAAIs"]
[Mon Jul 20 07:34:26.664555 2026] [security2:error] [pid 164535:tid 164715] [client 82.102.18.182:42801] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4j4jYN371eKRzcKeRUpAAAALc"]
[Mon Jul 20 07:34:26.721771 2026] [security2:error] [pid 164535:tid 164781] [client 82.102.18.116:32329] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4j4jYN371eKRzcKeRUqQAAAPk"]
[Mon Jul 20 07:34:26.822907 2026] [security2:error] [pid 164535:tid 164695] [client 57.141.18.84:37086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j4TYN371eKRzcKeRUNwAAozo"]
[Mon Jul 20 07:34:26.887831 2026] [security2:error] [pid 164535:tid 164709] [client 65.111.27.229:35083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j4jYN371eKRzcKeRUsAAAALE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:26.919570 2026] [security2:error] [pid 164535:tid 164734] [client 136.158.60.21:38200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j4jYN371eKRzcKeRUtQAAAMo"]
[Mon Jul 20 07:34:26.919696 2026] [security2:error] [pid 164535:tid 164734] [client 136.158.60.21:38200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j4jYN371eKRzcKeRUtQAAAMo"]
[Mon Jul 20 07:34:26.946671 2026] [security2:error] [pid 164535:tid 164691] [client 140.245.46.64:60781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-includes/post.php"] [unique_id "al4j4jYN371eKRzcKeRUtwAAAJ8"]
[Mon Jul 20 07:34:27.027179 2026] [security2:error] [pid 164535:tid 164712] [client 154.192.123.127:17724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRUvwAAALQ"]
[Mon Jul 20 07:34:27.027279 2026] [security2:error] [pid 164535:tid 164712] [client 154.192.123.127:17724] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRUvwAAALQ"]
[Mon Jul 20 07:34:27.055808 2026] [security2:error] [pid 164535:tid 164671] [client 82.102.18.116:55158] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4j4zYN371eKRzcKeRUywAAAIs"]
[Mon Jul 20 07:34:27.144815 2026] [security2:error] [pid 164535:tid 164738] [client 36.93.152.155:60377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRU1QAAAM4"]
[Mon Jul 20 07:34:27.144910 2026] [security2:error] [pid 164535:tid 164738] [client 36.93.152.155:60377] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRU1QAAAM4"]
[Mon Jul 20 07:34:27.296829 2026] [security2:error] [pid 164535:tid 164790] [client 82.102.18.182:62750] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4j4zYN371eKRzcKeRU2QAAAQI"]
[Mon Jul 20 07:34:27.371823 2026] [security2:error] [pid 164535:tid 164693] [client 82.102.18.116:55174] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4j4zYN371eKRzcKeRU2wAAAKE"]
[Mon Jul 20 07:34:27.521649 2026] [security2:error] [pid 164535:tid 164787] [client 140.245.46.64:61095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-includes/user.php"] [unique_id "al4j4zYN371eKRzcKeRU5QAAAP8"]
[Mon Jul 20 07:34:27.681714 2026] [security2:error] [pid 164535:tid 164753] [client 116.74.65.235:64373] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRU3AAAAN0"]
[Mon Jul 20 07:34:27.706459 2026] [security2:error] [pid 164535:tid 164674] [client 82.102.18.116:55182] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.actionsatebmf.org"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4j4zYN371eKRzcKeRU-gAAAI4"]
[Mon Jul 20 07:34:27.933560 2026] [security2:error] [pid 164535:tid 164770] [client 179.127.84.238:49466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRVDgAAAO4"]
[Mon Jul 20 07:34:27.933696 2026] [security2:error] [pid 164535:tid 164770] [client 179.127.84.238:49466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRVDgAAAO4"]
[Mon Jul 20 07:34:27.963908 2026] [security2:error] [pid 164535:tid 164733] [client 191.202.66.27:62627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRVEgAAAMk"]
[Mon Jul 20 07:34:27.964053 2026] [security2:error] [pid 164535:tid 164733] [client 191.202.66.27:62627] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j4zYN371eKRzcKeRVEgAAAMk"]
[Mon Jul 20 07:34:27.987776 2026] [security2:error] [pid 164535:tid 164791] [client 82.102.18.182:7276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4j4zYN371eKRzcKeRVEwAAAQM"]
[Mon Jul 20 07:34:28.038234 2026] [security2:error] [pid 164535:tid 164665] [client 14.225.17.146:63554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4j4zYN371eKRzcKeRVBQAAAIU"], referer: http://nomorewetsheets.net/demo
[Mon Jul 20 07:34:28.075224 2026] [security2:error] [pid 164535:tid 164655] [remote 47.86.33.52:31820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4j5DYN371eKRzcKeRVIQAA9nc"]
[Mon Jul 20 07:34:28.080166 2026] [security2:error] [pid 164535:tid 164713] [client 14.225.17.146:63575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4j4zYN371eKRzcKeRVEAAAALU"], referer: http://maxenengineering.com/demo
[Mon Jul 20 07:34:28.081583 2026] [security2:error] [pid 164535:tid 164678] [client 139.59.118.64:51447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4j5DYN371eKRzcKeRVJAAAAJI"], referer: https://t.co/
[Mon Jul 20 07:34:28.222023 2026] [security2:error] [pid 164535:tid 164669] [client 14.225.17.146:63027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4j4zYN371eKRzcKeRVBwAAAIk"], referer: http://transparentservices.online/demo
[Mon Jul 20 07:34:28.268869 2026] [security2:error] [pid 164535:tid 164716] [client 103.106.165.44:49555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j5DYN371eKRzcKeRVNAAAALg"]
[Mon Jul 20 07:34:28.269055 2026] [security2:error] [pid 164535:tid 164716] [client 103.106.165.44:49555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j5DYN371eKRzcKeRVNAAAALg"]
[Mon Jul 20 07:34:28.406616 2026] [fcgid:warn] [pid 164535:tid 164693] (70014)End of file found: [client 167.94.146.63:26328] mod_fcgid: can't get data from http client
[Mon Jul 20 07:34:28.488657 2026] [security2:error] [pid 164535:tid 164762] [client 14.225.17.146:62308] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4j4zYN371eKRzcKeRUygAAAOY"]
[Mon Jul 20 07:34:28.590256 2026] [security2:error] [pid 164535:tid 164637] [remote 47.86.33.52:31820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "travelbyfire.com"] [uri "/wp-login.php"] [unique_id "al4j5DYN371eKRzcKeRVUQAAjmU"], referer: https://travelbyfire.com/wp-login.php
[Mon Jul 20 07:34:28.665700 2026] [security2:error] [pid 164535:tid 164666] [client 82.102.18.182:40164] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4j5DYN371eKRzcKeRVWwAAAIY"]
[Mon Jul 20 07:34:28.726406 2026] [security2:error] [pid 164535:tid 164783] [client 104.234.53.56:23485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4j5DYN371eKRzcKeRVZwAAAPs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:28.780270 2026] [security2:error] [pid 164535:tid 164537] [remote 103.90.234.13:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4j5DYN371eKRzcKeRVbQAArQE"]
[Mon Jul 20 07:34:28.789315 2026] [security2:error] [pid 164535:tid 164748] [client 54.184.226.94:0] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4j5DYN371eKRzcKeRVRQAAANg"]
[Mon Jul 20 07:34:28.795855 2026] [security2:error] [pid 164535:tid 164735] [client 54.184.226.94:15437] ModSecurity: Warning. Matched phrase "Sucuri" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "cira.org"] [uri "/"] [unique_id "al4j5DYN371eKRzcKeRVPQAAAMs"]
[Mon Jul 20 07:34:28.800356 2026] [security2:error] [pid 164535:tid 164742] [client 188.166.209.66:63861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "al4j5DYN371eKRzcKeRVbgAAANI"], referer: binance.com
[Mon Jul 20 07:34:28.968057 2026] [security2:error] [pid 164535:tid 164770] [client 14.225.17.146:63599] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4j5DYN371eKRzcKeRVcQAAAO4"]
[Mon Jul 20 07:34:29.038560 2026] [security2:error] [pid 164535:tid 164696] [client 45.157.112.60:21397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4j5TYN371eKRzcKeRVhwAAAKQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:34:29.065172 2026] [security2:error] [pid 164535:tid 164671] [client 14.225.17.146:62656] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4j5DYN371eKRzcKeRVfAAAAIs"], referer: https://maxenengineering.com/demo
[Mon Jul 20 07:34:29.080227 2026] [security2:error] [pid 164535:tid 164721] [client 57.141.18.90:53960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j4zYN371eKRzcKeRU3wAAvUU"]
[Mon Jul 20 07:34:29.220008 2026] [security2:error] [pid 164535:tid 164575] [remote 103.90.234.13:34660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4j5TYN371eKRzcKeRVmgAAyic"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:34:29.259735 2026] [security2:error] [pid 164535:tid 164725] [client 66.249.74.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.mrbambooplus.com"] [uri "/index.php"] [unique_id "al4j5DYN371eKRzcKeRVcwAAAME"]
[Mon Jul 20 07:34:29.341053 2026] [security2:error] [pid 164535:tid 164715] [client 82.102.18.182:61301] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4j5TYN371eKRzcKeRVogAAALc"]
[Mon Jul 20 07:34:29.513357 2026] [security2:error] [pid 164535:tid 164761] [client 104.234.53.62:51993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4j5TYN371eKRzcKeRVswAAAOU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:29.751684 2026] [security2:error] [pid 164535:tid 164787] [client 57.141.18.35:48914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j5DYN371eKRzcKeRVIAAA_wc"]
[Mon Jul 20 07:34:29.754713 2026] [security2:error] [pid 164535:tid 164669] [client 103.176.215.66:53933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j5TYN371eKRzcKeRV1AAAAIk"]
[Mon Jul 20 07:34:29.754914 2026] [security2:error] [pid 164535:tid 164669] [client 103.176.215.66:53933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j5TYN371eKRzcKeRV1AAAAIk"]
[Mon Jul 20 07:34:29.969290 2026] [security2:error] [pid 164535:tid 164781] [client 82.102.18.182:40188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4j5TYN371eKRzcKeRV6wAAAPk"]
[Mon Jul 20 07:34:30.000678 2026] [autoindex:error] [pid 164535:tid 164663] [remote 34.75.194.172:64086] AH01276: Cannot serve directory /home2/dekbypmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.dek.byp.mybluehost.me
[Mon Jul 20 07:34:30.038601 2026] [security2:error] [pid 164535:tid 164728] [client 117.211.236.168:62526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j5jYN371eKRzcKeRV8wAAAMQ"]
[Mon Jul 20 07:34:30.038689 2026] [security2:error] [pid 164535:tid 164728] [client 117.211.236.168:62526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j5jYN371eKRzcKeRV8wAAAMQ"]
[Mon Jul 20 07:34:30.208639 2026] [security2:error] [pid 164535:tid 164681] [client 14.225.17.146:60011] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4j5jYN371eKRzcKeRV8gAAAJU"], referer: http://thechancersband.com/demo
[Mon Jul 20 07:34:30.569925 2026] [security2:error] [pid 164535:tid 164616] [remote 162.19.86.63:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j5jYN371eKRzcKeRWKgAA1VA"]
[Mon Jul 20 07:34:30.653214 2026] [security2:error] [pid 164535:tid 164760] [client 82.102.18.182:5234] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4j5jYN371eKRzcKeRWMgAAAOQ"]
[Mon Jul 20 07:34:30.699993 2026] [security2:error] [pid 164535:tid 164687] [client 103.139.191.61:49782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j5jYN371eKRzcKeRWOgAAAJs"]
[Mon Jul 20 07:34:30.700156 2026] [security2:error] [pid 164535:tid 164687] [client 103.139.191.61:49782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j5jYN371eKRzcKeRWOgAAAJs"]
[Mon Jul 20 07:34:30.753855 2026] [security2:error] [pid 164535:tid 164741] [client 47.128.116.146:25714] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "mobilesurvsolutions.com"] [uri "/robots.txt"] [unique_id "al4j5jYN371eKRzcKeRWPAAAANE"]
[Mon Jul 20 07:34:30.786550 2026] [security2:error] [pid 164535:tid 164636] [remote 162.19.86.63:52232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j5jYN371eKRzcKeRWPQAAhmQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:34:30.940029 2026] [security2:error] [pid 164535:tid 164685] [client 35.252.111.205:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.wileybrosmusic.com"] [uri "/index.php"] [unique_id "al4j4jYN371eKRzcKeRUlAAAAJk"]
[Mon Jul 20 07:34:31.047394 2026] [security2:error] [pid 164535:tid 164703] [client 50.116.65.227:54156] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4j5zYN371eKRzcKeRWTgAAAKs"]
[Mon Jul 20 07:34:31.050998 2026] [security2:error] [pid 164535:tid 164744] [client 14.225.17.146:60386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4j5TYN371eKRzcKeRVvwAAANQ"]
[Mon Jul 20 07:34:31.093000 2026] [security2:error] [pid 164535:tid 164706] [client 185.2.144.109:45111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "myhealthspot.org"] [uri "/wp-login.php"] [unique_id "al4j5zYN371eKRzcKeRWSwAArl4"]
[Mon Jul 20 07:34:31.116020 2026] [security2:error] [pid 164535:tid 164772] [client 57.141.18.112:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4j5jYN371eKRzcKeRWRwAAAPA"]
[Mon Jul 20 07:34:31.288559 2026] [security2:error] [pid 164535:tid 164726] [client 82.102.18.182:13561] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4j5zYN371eKRzcKeRWcQAAAMI"]
[Mon Jul 20 07:34:31.289308 2026] [security2:error] [pid 164535:tid 164767] [client 14.225.17.146:63028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4j5zYN371eKRzcKeRWXgAAAOs"], referer: http://aljosour-alarabia.com/demo
[Mon Jul 20 07:34:31.298092 2026] [autoindex:error] [pid 164535:tid 164604] [remote 136.67.100.54:55688] AH01276: Cannot serve directory /home2/shnhbfmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.shn.hbf.mybluehost.me
[Mon Jul 20 07:34:31.414397 2026] [security2:error] [pid 164535:tid 164674] [client 57.141.18.83:56668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j5TYN371eKRzcKeRV2AAAjj8"]
[Mon Jul 20 07:34:31.415591 2026] [security2:error] [pid 164535:tid 164759] [client 91.124.187.16:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4j5TYN371eKRzcKeRVtAAAAOM"]
[Mon Jul 20 07:34:31.521366 2026] [security2:error] [pid 164535:tid 164715] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4j5jYN371eKRzcKeRWPgAAt1I"], referer: http://assasalnazaha.com/demo
[Mon Jul 20 07:34:31.787055 2026] [security2:error] [pid 164535:tid 164666] [client 77.110.127.138:51774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4j5zYN371eKRzcKeRWmwAAAIY"], referer: https://mezzacraft.com/?s=can+I+ask+you+a+question+please%3F
[Mon Jul 20 07:34:31.930814 2026] [security2:error] [pid 164535:tid 164740] [client 82.102.18.182:40218] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4j5zYN371eKRzcKeRWpwAAANA"]
[Mon Jul 20 07:34:32.196635 2026] [security2:error] [pid 164535:tid 164704] [client 14.225.17.146:62503] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4j5zYN371eKRzcKeRWewAAAKw"], referer: http://idigress.agency/demo
[Mon Jul 20 07:34:32.306956 2026] [security2:error] [pid 164535:tid 164733] [client 104.234.53.94:42191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4j6DYN371eKRzcKeRWuAAAAMk"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:32.604376 2026] [security2:error] [pid 164535:tid 164684] [client 82.102.18.182:30638] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4j6DYN371eKRzcKeRW1gAAAJg"]
[Mon Jul 20 07:34:32.649614 2026] [security2:error] [pid 164535:tid 164694] [client 49.37.242.14:56185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4j6DYN371eKRzcKeRW2gAAAKI"]
[Mon Jul 20 07:34:32.649783 2026] [security2:error] [pid 164535:tid 164694] [client 49.37.242.14:56185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4j6DYN371eKRzcKeRW2gAAAKI"]
[Mon Jul 20 07:34:32.781954 2026] [security2:error] [pid 164535:tid 164786] [client 45.3.54.159:10837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/xmlrpc.php"] [unique_id "al4j6DYN371eKRzcKeRW4gAAAP4"], referer: https://t.co/
[Mon Jul 20 07:34:32.788843 2026] [security2:error] [pid 164535:tid 164777] [client 57.141.18.42:50642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j5jYN371eKRzcKeRWSgAA9Vk"]
[Mon Jul 20 07:34:33.044088 2026] [security2:error] [pid 164535:tid 164740] [client 180.249.173.210:64173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j6TYN371eKRzcKeRXCQAAANA"]
[Mon Jul 20 07:34:33.044724 2026] [security2:error] [pid 164535:tid 164740] [client 180.249.173.210:64173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j6TYN371eKRzcKeRXCQAAANA"]
[Mon Jul 20 07:34:33.236481 2026] [security2:error] [pid 164535:tid 164743] [client 82.102.18.182:40224] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4j6TYN371eKRzcKeRXGAAAANM"]
[Mon Jul 20 07:34:33.340304 2026] [security2:error] [pid 164535:tid 164567] [remote 154.66.198.148:63600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4j6TYN371eKRzcKeRXIwAA5x8"]
[Mon Jul 20 07:34:33.604029 2026] [security2:error] [pid 164535:tid 164784] [client 104.234.53.68:28319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4j6TYN371eKRzcKeRXNQAAAPw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:33.873169 2026] [security2:error] [pid 164535:tid 164771] [client 82.102.18.182:40240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "digiquestgroup.maxenengineering.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4j6TYN371eKRzcKeRXUQAAAO8"]
[Mon Jul 20 07:34:33.873647 2026] [security2:error] [pid 164535:tid 164728] [client 57.141.18.53:36686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j5zYN371eKRzcKeRWpQAAxBU"]
[Mon Jul 20 07:34:33.923609 2026] [security2:error] [pid 164535:tid 164538] [remote 154.66.198.148:63600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.rvprintfactory.com"] [uri "/wp-login.php"] [unique_id "al4j6TYN371eKRzcKeRXVQAA5QI"], referer: https://www.rvprintfactory.com/wp-login.php
[Mon Jul 20 07:34:34.018604 2026] [security2:error] [pid 164535:tid 164749] [client 188.166.209.66:57723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "al4j6jYN371eKRzcKeRXXAAAANk"], referer: binance.com
[Mon Jul 20 07:34:34.087342 2026] [security2:error] [pid 164535:tid 164705] [client 89.238.167.150:44396] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4j6jYN371eKRzcKeRXYAAAAK0"]
[Mon Jul 20 07:34:34.087441 2026] [security2:error] [pid 164535:tid 164705] [client 89.238.167.150:44396] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4j6jYN371eKRzcKeRXYAAAAK0"]
[Mon Jul 20 07:34:34.226439 2026] [security2:error] [pid 164535:tid 164696] [client 45.3.54.225:14781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 225.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4j6jYN371eKRzcKeRXZQAAAKQ"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:34:34.601202 2026] [security2:error] [pid 164535:tid 164721] [client 14.225.17.146:51306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4j6jYN371eKRzcKeRXiAAAAL0"], referer: http://careysheatingandcooling.com/demo
[Mon Jul 20 07:34:34.828578 2026] [security2:error] [pid 164535:tid 164686] [client 104.234.53.58:48307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4j6jYN371eKRzcKeRXrAAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:35.064928 2026] [security2:error] [pid 164535:tid 164775] [client 139.59.118.64:52332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4j6zYN371eKRzcKeRXxAAAAPM"], referer: https://duckduckgo.com/
[Mon Jul 20 07:34:35.184211 2026] [security2:error] [pid 164535:tid 164727] [client 149.0.16.108:56013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRXzAAAAMM"]
[Mon Jul 20 07:34:35.184845 2026] [security2:error] [pid 164535:tid 164727] [client 149.0.16.108:56013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRXzAAAAMM"]
[Mon Jul 20 07:34:35.259822 2026] [security2:error] [pid 164535:tid 164740] [client 14.225.17.146:51470] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4j6zYN371eKRzcKeRXxQAAANA"], referer: http://ironcitywellness.com/demo
[Mon Jul 20 07:34:35.305773 2026] [security2:error] [pid 164535:tid 164756] [client 13.221.30.43:62094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.30.221.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4j6zYN371eKRzcKeRXzgAAAOA"]
[Mon Jul 20 07:34:35.541358 2026] [core:error] [pid 164535:tid 164764] [client 14.225.17.146:62447] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:34:35.541378 2026] [core:error] [pid 164535:tid 164764] [client 14.225.17.146:62447] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:34:35.558901 2026] [security2:error] [pid 164535:tid 164681] [client 104.234.53.86:60881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4j6zYN371eKRzcKeRX8wAAAJU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:35.568047 2026] [security2:error] [pid 164535:tid 164772] [client 142.111.152.167:22541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRX4gAAAPA"]
[Mon Jul 20 07:34:35.583279 2026] [fcgid:warn] [pid 164535:tid 164706] (70014)End of file found: [client 66.132.172.213:7428] mod_fcgid: can't get data from http client
[Mon Jul 20 07:34:35.655354 2026] [security2:error] [pid 164535:tid 164770] [client 49.47.218.174:50040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRX-AAAAO4"]
[Mon Jul 20 07:34:35.655497 2026] [security2:error] [pid 164535:tid 164770] [client 49.47.218.174:50040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRX-AAAAO4"]
[Mon Jul 20 07:34:35.682692 2026] [security2:error] [pid 164535:tid 164675] [client 14.225.17.146:49750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4j6zYN371eKRzcKeRX9AAAAI8"], referer: http://ivetstrategies.com/demo
[Mon Jul 20 07:34:35.688000 2026] [security2:error] [pid 164535:tid 164679] [client 157.20.138.62:51904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRX_AAAAJM"]
[Mon Jul 20 07:34:35.688086 2026] [security2:error] [pid 164535:tid 164679] [client 157.20.138.62:51904] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j6zYN371eKRzcKeRX_AAAAJM"]
[Mon Jul 20 07:34:35.718020 2026] [security2:error] [pid 164535:tid 164751] [client 3.87.117.29:37738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.117.87.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4j6zYN371eKRzcKeRX-QAAANs"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:34:36.097276 2026] [security2:error] [pid 164535:tid 164701] [client 35.90.38.209:28350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4j7DYN371eKRzcKeRYJAAAAKk"]
[Mon Jul 20 07:34:36.223978 2026] [security2:error] [pid 164535:tid 164761] [client 57.141.18.118:33644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j6jYN371eKRzcKeRXiwAA5Vs"]
[Mon Jul 20 07:34:36.320170 2026] [security2:error] [pid 164535:tid 164780] [client 144.16.21.149:25125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j7DYN371eKRzcKeRYLAAAAPg"]
[Mon Jul 20 07:34:36.320259 2026] [security2:error] [pid 164535:tid 164780] [client 144.16.21.149:25125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j7DYN371eKRzcKeRYLAAAAPg"]
[Mon Jul 20 07:34:36.589744 2026] [security2:error] [pid 164535:tid 164558] [remote 20.153.140.50:41298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4j7DYN371eKRzcKeRYSwAAlBY"]
[Mon Jul 20 07:34:36.600875 2026] [security2:error] [pid 164535:tid 164763] [client 104.207.49.134:32831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 134.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j7DYN371eKRzcKeRYSAAAAOc"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:36.689389 2026] [security2:error] [pid 164535:tid 164694] [client 14.225.17.146:51380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4j7DYN371eKRzcKeRYQwAAAKI"]
[Mon Jul 20 07:34:36.691102 2026] [security2:error] [pid 164535:tid 164764] [client 143.44.185.218:45279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j7DYN371eKRzcKeRYUQAAAOg"]
[Mon Jul 20 07:34:36.691240 2026] [security2:error] [pid 164535:tid 164764] [client 143.44.185.218:45279] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j7DYN371eKRzcKeRYUQAAAOg"]
[Mon Jul 20 07:34:36.794102 2026] [security2:error] [pid 164535:tid 164791] [client 14.225.17.146:49747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4j7DYN371eKRzcKeRYTgAAAQM"], referer: http://koaconsultants.com/demo
[Mon Jul 20 07:34:36.982313 2026] [security2:error] [pid 164535:tid 164598] [remote 20.153.140.50:41298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4j7DYN371eKRzcKeRYdQAAnj4"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:34:37.034355 2026] [security2:error] [pid 164535:tid 164757] [client 202.141.11.99:55538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYeQAAAOE"]
[Mon Jul 20 07:34:37.034495 2026] [security2:error] [pid 164535:tid 164757] [client 202.141.11.99:55538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYeQAAAOE"]
[Mon Jul 20 07:34:37.194415 2026] [security2:error] [pid 164535:tid 164708] [client 104.234.53.68:33229] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4j7TYN371eKRzcKeRYlQAAALA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:37.202113 2026] [security2:error] [pid 164535:tid 164739] [client 104.207.63.181:50705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.63.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j7TYN371eKRzcKeRYjgAAAM8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:37.313478 2026] [security2:error] [pid 164535:tid 164673] [client 140.245.46.64:49169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hammadownenterprises.com"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4j7TYN371eKRzcKeRYoAAAAI0"]
[Mon Jul 20 07:34:37.411176 2026] [security2:error] [pid 164535:tid 164567] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYpgAAnh8"]
[Mon Jul 20 07:34:37.411359 2026] [security2:error] [pid 164535:tid 164690] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYpgAAnh8"]
[Mon Jul 20 07:34:37.449902 2026] [security2:error] [pid 164535:tid 164684] [client 57.141.18.12:59644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j6zYN371eKRzcKeRYCAAAmFI"]
[Mon Jul 20 07:34:37.515044 2026] [security2:error] [pid 164535:tid 164749] [client 188.166.209.66:55222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "al4j7TYN371eKRzcKeRYrgAAANk"], referer: binance.com
[Mon Jul 20 07:34:37.558583 2026] [security2:error] [pid 164535:tid 164740] [client 154.192.123.127:18193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYswAAANA"]
[Mon Jul 20 07:34:37.558672 2026] [security2:error] [pid 164535:tid 164740] [client 154.192.123.127:18193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYswAAANA"]
[Mon Jul 20 07:34:37.613567 2026] [security2:error] [pid 164535:tid 164699] [client 36.93.152.155:60893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYtwAAAKc"]
[Mon Jul 20 07:34:37.613671 2026] [security2:error] [pid 164535:tid 164699] [client 36.93.152.155:60893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYtwAAAKc"]
[Mon Jul 20 07:34:37.634571 2026] [security2:error] [pid 164535:tid 164767] [client 136.158.60.21:39795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYugAAAOs"]
[Mon Jul 20 07:34:37.634672 2026] [security2:error] [pid 164535:tid 164767] [client 136.158.60.21:39795] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j7TYN371eKRzcKeRYugAAAOs"]
[Mon Jul 20 07:34:37.636698 2026] [security2:error] [pid 164535:tid 164666] [client 14.225.17.146:64995] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4j7TYN371eKRzcKeRYpAAAAIY"], referer: http://itdynamix.com/demo
[Mon Jul 20 07:34:37.996181 2026] [security2:error] [pid 164535:tid 164782] [client 14.225.17.146:51032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4j7TYN371eKRzcKeRYxgAAAPo"], referer: http://getgarrison.com/demo
[Mon Jul 20 07:34:38.072699 2026] [security2:error] [pid 164535:tid 164751] [client 14.225.17.146:51067] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4j7TYN371eKRzcKeRYyQAAANs"], referer: http://christiancountytrumpet.com/demo
[Mon Jul 20 07:34:38.428096 2026] [security2:error] [pid 164535:tid 164764] [client 104.234.53.81:35253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4j7jYN371eKRzcKeRY-QAAAOg"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:38.577459 2026] [security2:error] [pid 164535:tid 164757] [client 74.208.214.194:35902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4j7jYN371eKRzcKeRZCAAAAOE"]
[Mon Jul 20 07:34:38.579275 2026] [security2:error] [pid 164535:tid 164761] [client 179.127.84.238:50013] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j7jYN371eKRzcKeRZCQAAAOU"]
[Mon Jul 20 07:34:38.579472 2026] [security2:error] [pid 164535:tid 164761] [client 179.127.84.238:50013] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j7jYN371eKRzcKeRZCQAAAOU"]
[Mon Jul 20 07:34:38.603017 2026] [security2:error] [pid 164535:tid 164686] [client 158.173.89.95:46181] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4j7jYN371eKRzcKeRZCgAAAJo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:34:38.611855 2026] [security2:error] [pid 164535:tid 164758] [client 14.225.17.146:65014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4j7jYN371eKRzcKeRY_QAAAOI"], referer: https://itdynamix.com/demo
[Mon Jul 20 07:34:38.622091 2026] [security2:error] [pid 164535:tid 164676] [client 191.202.66.27:63171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j7jYN371eKRzcKeRZDAAAAJA"]
[Mon Jul 20 07:34:38.622186 2026] [security2:error] [pid 164535:tid 164676] [client 191.202.66.27:63171] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j7jYN371eKRzcKeRZDAAAAJA"]
[Mon Jul 20 07:34:38.712775 2026] [security2:error] [pid 164535:tid 164705] [client 57.141.18.16:62482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j7TYN371eKRzcKeRYmwAArWc"]
[Mon Jul 20 07:34:38.741706 2026] [security2:error] [pid 164535:tid 164719] [client 103.106.165.44:50061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j7jYN371eKRzcKeRZHwAAALs"]
[Mon Jul 20 07:34:38.741826 2026] [security2:error] [pid 164535:tid 164719] [client 103.106.165.44:50061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j7jYN371eKRzcKeRZHwAAALs"]
[Mon Jul 20 07:34:39.049987 2026] [security2:error] [pid 164535:tid 164763] [client 57.141.18.43:40416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j7TYN371eKRzcKeRYrQAA5wQ"]
[Mon Jul 20 07:34:39.232711 2026] [security2:error] [pid 164535:tid 164606] [remote 217.61.143.92:34774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4j7zYN371eKRzcKeRZTQAAy0Y"]
[Mon Jul 20 07:34:39.232858 2026] [security2:error] [pid 164535:tid 164735] [client 217.61.143.92:34774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4j7zYN371eKRzcKeRZTQAAy0Y"]
[Mon Jul 20 07:34:39.389937 2026] [security2:error] [pid 164535:tid 164668] [client 57.141.18.19:39140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j7TYN371eKRzcKeRYwQAAiC4"]
[Mon Jul 20 07:34:39.620121 2026] [security2:error] [pid 164535:tid 164709] [client 139.59.118.64:53008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4j7zYN371eKRzcKeRZZAAAALE"], referer: https://wordpress.org/
[Mon Jul 20 07:34:40.190875 2026] [security2:error] [pid 164535:tid 164718] [client 103.176.215.66:54459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j8DYN371eKRzcKeRZlAAAALo"]
[Mon Jul 20 07:34:40.190968 2026] [security2:error] [pid 164535:tid 164718] [client 103.176.215.66:54459] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j8DYN371eKRzcKeRZlAAAALo"]
[Mon Jul 20 07:34:40.203734 2026] [security2:error] [pid 164535:tid 164643] [remote 209.42.18.223:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4j8DYN371eKRzcKeRZkwAAsms"]
[Mon Jul 20 07:34:40.380417 2026] [security2:error] [pid 164535:tid 164611] [remote 209.42.18.223:41558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4j8DYN371eKRzcKeRZowAAhUs"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:34:40.562411 2026] [security2:error] [pid 164535:tid 164754] [client 188.166.209.66:53322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "al4j8DYN371eKRzcKeRZsQAAAN4"], referer: binance.com
[Mon Jul 20 07:34:40.652810 2026] [security2:error] [pid 164535:tid 164748] [client 117.211.236.168:63119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j8DYN371eKRzcKeRZuAAAANg"]
[Mon Jul 20 07:34:40.652904 2026] [security2:error] [pid 164535:tid 164748] [client 117.211.236.168:63119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j8DYN371eKRzcKeRZuAAAANg"]
[Mon Jul 20 07:34:41.197181 2026] [security2:error] [pid 164535:tid 164714] [client 57.141.18.120:58916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j7zYN371eKRzcKeRZewAAtk0"]
[Mon Jul 20 07:34:41.505712 2026] [security2:error] [pid 164535:tid 164693] [client 50.116.65.227:55774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4j8TYN371eKRzcKeRaAAAAAKE"]
[Mon Jul 20 07:34:41.514733 2026] [security2:error] [pid 164535:tid 164701] [client 50.116.65.227:55776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4j8TYN371eKRzcKeRaAQAAAKk"]
[Mon Jul 20 07:34:41.696768 2026] [security2:error] [pid 164535:tid 164766] [client 14.225.17.146:64833] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4j8DYN371eKRzcKeRZpAAAAOo"], referer: http://alaraycreative.com/demo
[Mon Jul 20 07:34:41.722255 2026] [security2:error] [pid 164535:tid 164698] [client 103.139.191.61:50257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j8TYN371eKRzcKeRaHQAAAKY"]
[Mon Jul 20 07:34:41.722380 2026] [security2:error] [pid 164535:tid 164698] [client 103.139.191.61:50257] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j8TYN371eKRzcKeRaHQAAAKY"]
[Mon Jul 20 07:34:42.186773 2026] [security2:error] [pid 164535:tid 164751] [client 57.141.18.95:55336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j8DYN371eKRzcKeRZxwAA21c"]
[Mon Jul 20 07:34:42.187787 2026] [security2:error] [pid 164535:tid 164711] [client 104.234.53.48:36289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4j8jYN371eKRzcKeRaNwAAALM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:42.311611 2026] [security2:error] [pid 164535:tid 164597] [remote 15.206.251.117:57142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4j8jYN371eKRzcKeRaTQAA5T0"]
[Mon Jul 20 07:34:42.577040 2026] [security2:error] [pid 164535:tid 164712] [client 57.141.18.112:61868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j8TYN371eKRzcKeRZ9AAAtA0"]
[Mon Jul 20 07:34:42.745413 2026] [security2:error] [pid 164535:tid 164707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j8jYN371eKRzcKeRaXwAAAK8"], referer: 1'"3000
[Mon Jul 20 07:34:42.790941 2026] [security2:error] [pid 164535:tid 164654] [remote 15.206.251.117:57142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4j8jYN371eKRzcKeRadQAAu3Y"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:34:43.032437 2026] [security2:error] [pid 164535:tid 164746] [client 66.249.65.173:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4j8jYN371eKRzcKeRabwAAANY"]
[Mon Jul 20 07:34:43.224332 2026] [security2:error] [pid 164535:tid 164771] [client 188.166.209.66:59040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "al4j8zYN371eKRzcKeRamQAAAO8"], referer: binance.com
[Mon Jul 20 07:34:43.327108 2026] [security2:error] [pid 164535:tid 164590] [remote 8.217.108.67:38804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4j8zYN371eKRzcKeRanQAAyjY"]
[Mon Jul 20 07:34:43.402867 2026] [security2:error] [pid 164535:tid 164670] [client 57.141.18.60:63996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j8jYN371eKRzcKeRaQAAAig8"]
[Mon Jul 20 07:34:43.548407 2026] [security2:error] [pid 164535:tid 164749] [client 57.141.18.43:40424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j8jYN371eKRzcKeRaVAAA2UE"]
[Mon Jul 20 07:34:43.664388 2026] [security2:error] [pid 164535:tid 164777] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j8zYN371eKRzcKeRasQAAAPU"], referer: 1'"3000
[Mon Jul 20 07:34:43.672603 2026] [security2:error] [pid 164535:tid 164705] [client 180.249.173.210:64614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j8zYN371eKRzcKeRavAAAAK0"]
[Mon Jul 20 07:34:43.673512 2026] [security2:error] [pid 164535:tid 164705] [client 180.249.173.210:64614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j8zYN371eKRzcKeRavAAAAK0"]
[Mon Jul 20 07:34:43.781576 2026] [security2:error] [pid 164535:tid 164739] [client 14.225.17.146:64722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4j8zYN371eKRzcKeRawgAAAM8"], referer: http://intelligentengineeringsolutions.com/demo
[Mon Jul 20 07:34:43.905345 2026] [security2:error] [pid 164535:tid 164765] [client 74.7.244.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "russianlanguagetutor.com"] [uri "/robots.txt"] [unique_id "al4j8zYN371eKRzcKeRa1AAAAOk"]
[Mon Jul 20 07:34:43.907993 2026] [security2:error] [pid 164535:tid 164738] [client 74.7.244.31:39632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "russianlanguagetutor.com"] [uri "/robots.txt"] [unique_id "al4j8zYN371eKRzcKeRa0QAAzmo"]
[Mon Jul 20 07:34:43.936796 2026] [security2:error] [pid 164535:tid 164750] [client 50.116.65.227:55812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4j8zYN371eKRzcKeRa2QAAANo"]
[Mon Jul 20 07:34:43.941002 2026] [security2:error] [pid 164535:tid 164751] [client 14.225.17.146:64640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4j8zYN371eKRzcKeRawAAAANs"], referer: http://recruitinginsight.us/demo
[Mon Jul 20 07:34:44.013466 2026] [security2:error] [pid 164535:tid 164730] [client 74.7.244.31:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "russianlanguagetutor.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4j8zYN371eKRzcKeRa4QAAAMY"], referer: https://russianlanguagetutor.com/robots.txt
[Mon Jul 20 07:34:44.015067 2026] [security2:error] [pid 164535:tid 164779] [client 74.7.244.31:39632] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "russianlanguagetutor.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4j8zYN371eKRzcKeRa3gAA92g"], referer: https://russianlanguagetutor.com/robots.txt
[Mon Jul 20 07:34:44.491638 2026] [security2:error] [pid 164535:tid 164775] [client 57.141.18.105:58336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j8zYN371eKRzcKeRangAA80g"]
[Mon Jul 20 07:34:44.544585 2026] [security2:error] [pid 164535:tid 164757] [client 66.249.74.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4j9DYN371eKRzcKeRa_AAAAOE"]
[Mon Jul 20 07:34:44.549620 2026] [security2:error] [pid 164535:tid 164771] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j9DYN371eKRzcKeRbAwAAAO8"], referer: 1'"3000
[Mon Jul 20 07:34:44.591491 2026] [security2:error] [pid 164535:tid 164725] [client 185.238.231.163:27273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 163.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4j9DYN371eKRzcKeRbGgAAAME"]
[Mon Jul 20 07:34:44.597838 2026] [security2:error] [pid 164535:tid 164750] [client 185.238.231.222:42665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4j9DYN371eKRzcKeRbGwAAANo"]
[Mon Jul 20 07:34:44.834468 2026] [security2:error] [pid 164535:tid 164784] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4j8jYN371eKRzcKeRafQAAAPw"]
[Mon Jul 20 07:34:44.844741 2026] [security2:error] [pid 164535:tid 164781] [client 14.225.17.146:64629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4j8zYN371eKRzcKeRarwAAAPk"], referer: http://alchemygroup.ca/demo
[Mon Jul 20 07:34:45.021724 2026] [security2:error] [pid 164535:tid 164701] [client 14.225.17.146:56246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4j9DYN371eKRzcKeRbOwAAAKk"], referer: http://ncsynchro.com/demo
[Mon Jul 20 07:34:45.037629 2026] [security2:error] [pid 164535:tid 164560] [remote 192.241.143.148:55832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4j9TYN371eKRzcKeRbSQAAlRg"]
[Mon Jul 20 07:34:45.037882 2026] [security2:error] [pid 164535:tid 164681] [client 192.241.143.148:55832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4j9TYN371eKRzcKeRbSQAAlRg"]
[Mon Jul 20 07:34:45.241083 2026] [security2:error] [pid 164535:tid 164743] [client 158.173.166.181:20711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4j9TYN371eKRzcKeRbWAAAANM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:34:45.282488 2026] [security2:error] [pid 164535:tid 164721] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j9TYN371eKRzcKeRbUAAAAL0"]
[Mon Jul 20 07:34:45.301855 2026] [security2:error] [pid 164535:tid 164719] [client 57.141.18.81:54114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9DYN371eKRzcKeRa5wAAuzs"]
[Mon Jul 20 07:34:45.636993 2026] [security2:error] [pid 164535:tid 164755] [client 57.141.18.12:38150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9DYN371eKRzcKeRbDQAA30s"]
[Mon Jul 20 07:34:45.728159 2026] [security2:error] [pid 164535:tid 164775] [client 149.0.16.108:56522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j9TYN371eKRzcKeRbiAAAAPM"]
[Mon Jul 20 07:34:45.728254 2026] [security2:error] [pid 164535:tid 164775] [client 149.0.16.108:56522] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j9TYN371eKRzcKeRbiAAAAPM"]
[Mon Jul 20 07:34:45.875321 2026] [security2:error] [pid 164535:tid 164767] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4j9TYN371eKRzcKeRbbgAAAOs"]
[Mon Jul 20 07:34:46.011698 2026] [security2:error] [pid 164535:tid 164714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j9TYN371eKRzcKeRbkAAAALY"]
[Mon Jul 20 07:34:46.100635 2026] [security2:error] [pid 164535:tid 164557] [remote 217.61.143.92:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRbrQAA_hU"]
[Mon Jul 20 07:34:46.142854 2026] [security2:error] [pid 164535:tid 164673] [client 49.47.218.174:50585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRbrgAAAI0"]
[Mon Jul 20 07:34:46.142995 2026] [security2:error] [pid 164535:tid 164673] [client 49.47.218.174:50585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRbrgAAAI0"]
[Mon Jul 20 07:34:46.238762 2026] [security2:error] [pid 164535:tid 164667] [client 157.20.138.62:52467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRbuAAAAIc"]
[Mon Jul 20 07:34:46.238895 2026] [security2:error] [pid 164535:tid 164667] [client 157.20.138.62:52467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRbuAAAAIc"]
[Mon Jul 20 07:34:46.240871 2026] [security2:error] [pid 164535:tid 164757] [client 155.2.215.78:34705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRbpgAAAOE"]
[Mon Jul 20 07:34:46.294534 2026] [security2:error] [pid 164535:tid 164566] [remote 130.51.180.8:34058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRbvwAA8B4"]
[Mon Jul 20 07:34:46.321065 2026] [security2:error] [pid 164535:tid 164720] [client 14.225.17.146:56313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4j9jYN371eKRzcKeRbtQAAALw"], referer: http://nextlvlmarketingco.com/demo
[Mon Jul 20 07:34:46.353711 2026] [security2:error] [pid 164535:tid 164589] [remote 217.61.143.92:38090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRbxQAAoDU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:34:46.440755 2026] [security2:error] [pid 164535:tid 164679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j9jYN371eKRzcKeRbtgAAAJM"]
[Mon Jul 20 07:34:46.459732 2026] [security2:error] [pid 164535:tid 164781] [client 188.166.209.66:51087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "al4j9jYN371eKRzcKeRb0AAAAPk"], referer: binance.com
[Mon Jul 20 07:34:46.471905 2026] [security2:error] [pid 164535:tid 164784] [client 216.73.216.78:17245] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.website-389dbb4e.safe-systems.net"] [uri "/index.php"] [unique_id "al4j9jYN371eKRzcKeRbywAA_HY"]
[Mon Jul 20 07:34:46.473290 2026] [security2:error] [pid 164535:tid 164544] [remote 130.51.180.8:34058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb0QAAqAg"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:34:46.510866 2026] [security2:error] [pid 164535:tid 164696] [client 47.98.96.52:5006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "juniper3medical.com"] [uri "/wp-content/uploads/2018/09/logo.png"] [unique_id "al4j9jYN371eKRzcKeRb1gAAAKQ"]
[Mon Jul 20 07:34:46.511203 2026] [access_compat:error] [pid 164535:tid 164755] [client 182.62.196.154:29277] AH01797: client denied by server configuration: /home1/marscafe/public_html/new-menus/moxforum, referer: https://www.new-menus.com/index.php?page=16
[Mon Jul 20 07:34:46.572671 2026] [security2:error] [pid 164535:tid 164790] [client 49.37.242.14:56733] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRb2wAAAQI"]
[Mon Jul 20 07:34:46.572834 2026] [security2:error] [pid 164535:tid 164790] [client 49.37.242.14:56733] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4j9jYN371eKRzcKeRb2wAAAQI"]
[Mon Jul 20 07:34:46.613083 2026] [security2:error] [pid 164535:tid 164545] [remote 124.55.178.99:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb3gAAqgk"]
[Mon Jul 20 07:34:46.712404 2026] [security2:error] [pid 164535:tid 164701] [client 57.141.18.4:36072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9TYN371eKRzcKeRbggAAqRw"]
[Mon Jul 20 07:34:46.787252 2026] [security2:error] [pid 164535:tid 164760] [client 136.144.33.204:51593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb6wAAAOQ"]
[Mon Jul 20 07:34:46.788968 2026] [security2:error] [pid 164535:tid 164778] [client 172.245.102.63:63763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.102.245.172.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb7AAAAPY"]
[Mon Jul 20 07:34:46.829466 2026] [security2:error] [pid 164535:tid 164603] [remote 130.51.180.8:34060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb8gAAsUM"]
[Mon Jul 20 07:34:46.891242 2026] [security2:error] [pid 164535:tid 164665] [client 65.111.22.208:42137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb9AAAAIU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:46.998043 2026] [security2:error] [pid 164535:tid 164619] [remote 154.66.198.148:41622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb_QAAs1M"]
[Mon Jul 20 07:34:46.998199 2026] [security2:error] [pid 164535:tid 164616] [remote 130.51.180.8:34060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jhavoctattoos.com"] [uri "/wp-login.php"] [unique_id "al4j9jYN371eKRzcKeRb_gAAulA"], referer: https://jhavoctattoos.com/wp-login.php
[Mon Jul 20 07:34:47.048217 2026] [security2:error] [pid 164535:tid 164601] [remote 124.55.178.99:55534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcBwAA20E"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:34:47.196616 2026] [security2:error] [pid 164535:tid 164624] [remote 188.166.241.141:48724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcHgAA0Vg"]
[Mon Jul 20 07:34:47.255787 2026] [security2:error] [pid 164535:tid 164685] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j9zYN371eKRzcKeRcCwAAAJk"]
[Mon Jul 20 07:34:47.362981 2026] [security2:error] [pid 164535:tid 164644] [remote 72.167.132.114:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcKAAA4Ww"]
[Mon Jul 20 07:34:47.414098 2026] [security2:error] [pid 164535:tid 164731] [client 57.141.18.70:20958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9jYN371eKRzcKeRb0wAAxxo"]
[Mon Jul 20 07:34:47.441731 2026] [security2:error] [pid 164535:tid 164727] [client 57.141.18.68:46898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9jYN371eKRzcKeRb1wAAwzg"]
[Mon Jul 20 07:34:47.548532 2026] [security2:error] [pid 164535:tid 164690] [client 104.207.55.86:49235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 86.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcNgAAAJ4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:47.549154 2026] [security2:error] [pid 164535:tid 164647] [remote 154.66.198.148:41622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcQAAAqG8"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 07:34:47.577879 2026] [security2:error] [pid 164535:tid 164609] [remote 72.167.132.114:39762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcQwAAxUk"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:34:47.589645 2026] [security2:error] [pid 164535:tid 164643] [remote 188.166.241.141:48724] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samueldcohen.com"] [uri "/wp-login.php"] [unique_id "al4j9zYN371eKRzcKeRcRAAA42s"], referer: https://samueldcohen.com/wp-login.php
[Mon Jul 20 07:34:47.693602 2026] [security2:error] [pid 164535:tid 164704] [client 202.141.11.99:22123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4j9zYN371eKRzcKeRcTgAAAKw"]
[Mon Jul 20 07:34:47.693705 2026] [security2:error] [pid 164535:tid 164704] [client 202.141.11.99:22123] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4j9zYN371eKRzcKeRcTgAAAKw"]
[Mon Jul 20 07:34:47.902618 2026] [security2:error] [pid 164535:tid 164701] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j9zYN371eKRzcKeRcTwAAAKk"]
[Mon Jul 20 07:34:47.965054 2026] [security2:error] [pid 164535:tid 164751] [client 143.44.185.218:46455] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j9zYN371eKRzcKeRcZAAAANs"]
[Mon Jul 20 07:34:47.965484 2026] [security2:error] [pid 164535:tid 164751] [client 143.44.185.218:46455] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4j9zYN371eKRzcKeRcZAAAANs"]
[Mon Jul 20 07:34:47.983951 2026] [security2:error] [pid 164535:tid 164712] [client 104.234.53.79:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4j9zYN371eKRzcKeRcZQAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:48.074026 2026] [security2:error] [pid 164535:tid 164646] [remote 20.87.239.85:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j-DYN371eKRzcKeRcaAAAsm4"]
[Mon Jul 20 07:34:48.100410 2026] [security2:error] [pid 164535:tid 164765] [client 154.192.123.127:18715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRcbAAAAOk"]
[Mon Jul 20 07:34:48.100549 2026] [security2:error] [pid 164535:tid 164765] [client 154.192.123.127:18715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRcbAAAAOk"]
[Mon Jul 20 07:34:48.135568 2026] [security2:error] [pid 164535:tid 164792] [client 36.93.152.155:61409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRccgAAAQQ"]
[Mon Jul 20 07:34:48.135699 2026] [security2:error] [pid 164535:tid 164792] [client 36.93.152.155:61409] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRccgAAAQQ"]
[Mon Jul 20 07:34:48.174925 2026] [security2:error] [pid 164535:tid 164683] [client 104.207.59.126:64137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j-DYN371eKRzcKeRcdgAAAJc"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:48.255199 2026] [security2:error] [pid 164535:tid 164725] [client 57.141.18.52:22764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9zYN371eKRzcKeRcKwAAwTo"]
[Mon Jul 20 07:34:48.283265 2026] [security2:error] [pid 164535:tid 164717] [client 57.141.18.92:38772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9zYN371eKRzcKeRcMQAAuUQ"]
[Mon Jul 20 07:34:48.341774 2026] [security2:error] [pid 164535:tid 164771] [client 14.225.17.146:56276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4j9jYN371eKRzcKeRbsgAAAO8"], referer: http://latiendadejorge.com.gt/demo
[Mon Jul 20 07:34:48.362235 2026] [security2:error] [pid 164535:tid 164742] [client 74.7.227.179:49822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4j-DYN371eKRzcKeRcewAA0n4"], referer: https://tejasenvironmental.com/p=690766
[Mon Jul 20 07:34:48.367588 2026] [security2:error] [pid 164535:tid 164749] [client 136.158.60.21:41445] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRciAAAANk"]
[Mon Jul 20 07:34:48.367739 2026] [security2:error] [pid 164535:tid 164749] [client 136.158.60.21:41445] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRciAAAANk"]
[Mon Jul 20 07:34:48.420987 2026] [security2:error] [pid 164535:tid 164762] [client 14.225.17.146:57066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4j-DYN371eKRzcKeRcdwAAAOY"], referer: http://www.justinagrayman.com/demo
[Mon Jul 20 07:34:48.474635 2026] [security2:error] [pid 164535:tid 164790] [client 57.141.18.34:38646] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j9zYN371eKRzcKeRcSQABAi8"]
[Mon Jul 20 07:34:48.679057 2026] [security2:error] [pid 164535:tid 164595] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRcrwAAjTs"]
[Mon Jul 20 07:34:48.679232 2026] [security2:error] [pid 164535:tid 164673] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4j-DYN371eKRzcKeRcrwAAjTs"]
[Mon Jul 20 07:34:48.753765 2026] [security2:error] [pid 164535:tid 164781] [client 188.166.209.66:50611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-connector-registry.php"] [unique_id "al4j-DYN371eKRzcKeRctgAAAPk"], referer: binance.com
[Mon Jul 20 07:34:48.769422 2026] [security2:error] [pid 164535:tid 164765] [client 45.3.44.200:21883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j-DYN371eKRzcKeRctQAAAOk"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:48.954197 2026] [security2:error] [pid 164535:tid 164728] [client 176.28.251.21:2179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.new-menus.com"] [uri "/moxforum/index.php"] [unique_id "al4j-DYN371eKRzcKeRcxwAAAMQ"], referer: https://www.new-menus.com/index.php?page=16
[Mon Jul 20 07:34:49.161499 2026] [security2:error] [pid 164535:tid 164698] [client 103.106.165.44:50550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc2QAAAKY"]
[Mon Jul 20 07:34:49.161603 2026] [security2:error] [pid 164535:tid 164698] [client 103.106.165.44:50550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc2QAAAKY"]
[Mon Jul 20 07:34:49.165558 2026] [security2:error] [pid 164535:tid 164669] [client 144.16.21.149:36231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc2wAAAIk"]
[Mon Jul 20 07:34:49.165714 2026] [security2:error] [pid 164535:tid 164669] [client 144.16.21.149:36231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc2wAAAIk"]
[Mon Jul 20 07:34:49.241287 2026] [security2:error] [pid 164535:tid 164575] [remote 20.87.239.85:6110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.239.87.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4j-TYN371eKRzcKeRc5AAAvSc"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:34:49.269843 2026] [security2:error] [pid 164535:tid 164734] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j-TYN371eKRzcKeRc0gAAAMo"]
[Mon Jul 20 07:34:49.282085 2026] [security2:error] [pid 164535:tid 164723] [client 179.127.84.238:50555] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc6wAAAL8"]
[Mon Jul 20 07:34:49.282172 2026] [security2:error] [pid 164535:tid 164723] [client 179.127.84.238:50555] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc6wAAAL8"]
[Mon Jul 20 07:34:49.291594 2026] [security2:error] [pid 164535:tid 164755] [client 191.202.66.27:63912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc6gAAAN8"]
[Mon Jul 20 07:34:49.291706 2026] [security2:error] [pid 164535:tid 164755] [client 191.202.66.27:63912] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4j-TYN371eKRzcKeRc6gAAAN8"]
[Mon Jul 20 07:34:49.425966 2026] [security2:error] [pid 164535:tid 164768] [client 65.111.28.197:18417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j-TYN371eKRzcKeRc8gAAAOw"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:49.743572 2026] [security2:error] [pid 164535:tid 164679] [client 14.225.17.146:49643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4j9zYN371eKRzcKeRcIwAAAJM"], referer: http://onewingpictures.com/demo
[Mon Jul 20 07:34:49.844464 2026] [security2:error] [pid 164535:tid 164617] [remote 20.153.140.50:39050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4j-TYN371eKRzcKeRdEAAAwVE"]
[Mon Jul 20 07:34:49.995692 2026] [security2:error] [pid 164535:tid 164704] [client 14.225.17.146:56959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4j-DYN371eKRzcKeRcnAAAAKw"], referer: http://dadanetnet.net/demo
[Mon Jul 20 07:34:50.045938 2026] [security2:error] [pid 164535:tid 164734] [client 45.3.54.89:65291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4j-jYN371eKRzcKeRdJQAAAMo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:34:50.063459 2026] [security2:error] [pid 164535:tid 164739] [client 57.141.18.53:50950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j-TYN371eKRzcKeRc4gAAz1c"]
[Mon Jul 20 07:34:50.263313 2026] [security2:error] [pid 164535:tid 164544] [remote 20.153.140.50:39050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4j-jYN371eKRzcKeRdOgAA8Ag"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:34:50.577240 2026] [security2:error] [pid 164535:tid 164668] [client 14.225.17.146:59270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4j-jYN371eKRzcKeRdTwAAAIg"], referer: http://retzkolonglogistics.com/demo
[Mon Jul 20 07:34:50.666215 2026] [security2:error] [pid 164535:tid 164551] [remote 152.228.213.32:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4j-jYN371eKRzcKeRdWwAAng8"]
[Mon Jul 20 07:34:50.704910 2026] [security2:error] [pid 164535:tid 164695] [client 103.176.215.66:54991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j-jYN371eKRzcKeRdZQAAAKM"]
[Mon Jul 20 07:34:50.705704 2026] [security2:error] [pid 164535:tid 164695] [client 103.176.215.66:54991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4j-jYN371eKRzcKeRdZQAAAKM"]
[Mon Jul 20 07:34:50.855870 2026] [security2:error] [pid 164535:tid 164636] [remote 152.228.213.32:43008] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4j-jYN371eKRzcKeRdbAAAnGQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:34:50.922680 2026] [security2:error] [pid 164535:tid 164777] [client 14.225.17.146:56991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4j-TYN371eKRzcKeRc6AAAAPU"], referer: http://cheesewithjam.com/demo
[Mon Jul 20 07:34:51.209004 2026] [security2:error] [pid 164535:tid 164669] [client 57.141.18.104:63902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j-jYN371eKRzcKeRdQgAAiVQ"]
[Mon Jul 20 07:34:51.339200 2026] [security2:error] [pid 164535:tid 164779] [client 14.225.17.146:56640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4j-zYN371eKRzcKeRdhQAAAPc"], referer: http://jvcmotorsports.com/demo
[Mon Jul 20 07:34:51.421950 2026] [security2:error] [pid 164535:tid 164685] [client 138.255.213.158:58441] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.213.255.138.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "effingweirdmuseums.com"] [uri "/xmlrpc.php"] [unique_id "al4j-zYN371eKRzcKeRdmQAAAJk"]
[Mon Jul 20 07:34:51.422073 2026] [security2:error] [pid 164535:tid 164685] [client 138.255.213.158:58441] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "effingweirdmuseums.com"] [uri "/xmlrpc.php"] [unique_id "al4j-zYN371eKRzcKeRdmQAAAJk"]
[Mon Jul 20 07:34:51.439039 2026] [security2:error] [pid 164535:tid 164698] [client 57.141.18.93:28572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j-jYN371eKRzcKeRdUgAApl8"]
[Mon Jul 20 07:34:51.579428 2026] [fcgid:warn] [pid 164535:tid 164774] (70014)End of file found: [client 167.94.146.63:57772] mod_fcgid: can't get data from http client
[Mon Jul 20 07:34:51.673598 2026] [security2:error] [pid 164535:tid 164785] [client 104.234.53.50:27633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4j-zYN371eKRzcKeRdrAAAAP0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:51.851292 2026] [security2:error] [pid 164535:tid 164766] [client 188.166.209.66:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-dependencies.php"] [unique_id "al4j-zYN371eKRzcKeRduAAAAOo"], referer: binance.com
[Mon Jul 20 07:34:52.289731 2026] [core:error] [pid 164535:tid 164745] [client 14.225.17.146:57590] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:34:52.289761 2026] [core:error] [pid 164535:tid 164745] [client 14.225.17.146:57590] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:34:52.989505 2026] [security2:error] [pid 164535:tid 164772] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j_DYN371eKRzcKeRd_QAAAPA"]
[Mon Jul 20 07:34:52.991948 2026] [security2:error] [pid 164535:tid 164668] [client 103.139.191.61:50735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j_DYN371eKRzcKeReIAAAAIg"]
[Mon Jul 20 07:34:52.992056 2026] [security2:error] [pid 164535:tid 164668] [client 103.139.191.61:50735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4j_DYN371eKRzcKeReIAAAAIg"]
[Mon Jul 20 07:34:53.031578 2026] [security2:error] [pid 164535:tid 164761] [client 14.225.17.146:56964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4j_DYN371eKRzcKeReGQAAAOU"], referer: http://wathenbartlett.co.uk/demo
[Mon Jul 20 07:34:53.250189 2026] [security2:error] [pid 164535:tid 164754] [client 57.141.18.102:38212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j_DYN371eKRzcKeRd9QAA3jM"]
[Mon Jul 20 07:34:53.438401 2026] [security2:error] [pid 164535:tid 164787] [client 57.141.18.63:56872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j_DYN371eKRzcKeReAQAA_w4"]
[Mon Jul 20 07:34:53.629929 2026] [security2:error] [pid 164535:tid 164765] [client 57.141.18.10:45356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j_DYN371eKRzcKeReGAAA6RQ"]
[Mon Jul 20 07:34:53.948038 2026] [security2:error] [pid 164535:tid 164668] [client 14.225.17.146:55996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4j_TYN371eKRzcKeReXAAAAIg"], referer: https://wathenbartlett.co.uk/demo
[Mon Jul 20 07:34:54.056211 2026] [security2:error] [pid 164535:tid 164623] [remote 8.217.108.67:2846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4j_jYN371eKRzcKeReawAApVc"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:34:54.137817 2026] [security2:error] [pid 164535:tid 164755] [client 50.116.65.227:16106] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4j_jYN371eKRzcKeRedAAAAN8"]
[Mon Jul 20 07:34:54.146744 2026] [security2:error] [pid 164535:tid 164746] [client 50.116.65.227:16108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4j_jYN371eKRzcKeRedQAAANY"]
[Mon Jul 20 07:34:54.251488 2026] [security2:error] [pid 164535:tid 164758] [client 180.249.173.210:65061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j_jYN371eKRzcKeReggAAAOI"]
[Mon Jul 20 07:34:54.252838 2026] [security2:error] [pid 164535:tid 164758] [client 180.249.173.210:65061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4j_jYN371eKRzcKeReggAAAOI"]
[Mon Jul 20 07:34:54.267349 2026] [security2:error] [pid 164535:tid 164730] [client 117.211.236.168:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j_jYN371eKRzcKeRegAAAAMY"]
[Mon Jul 20 07:34:54.267474 2026] [security2:error] [pid 164535:tid 164730] [client 117.211.236.168:63894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4j_jYN371eKRzcKeRegAAAAMY"]
[Mon Jul 20 07:34:54.273670 2026] [security2:error] [pid 164535:tid 164771] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeRebgAAAO8"]
[Mon Jul 20 07:34:54.438414 2026] [security2:error] [pid 164535:tid 164769] [client 66.132.172.213:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cathybuffini.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeRejgAAAO0"]
[Mon Jul 20 07:34:54.500264 2026] [security2:error] [pid 164535:tid 164632] [remote 45.90.123.233:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4j_jYN371eKRzcKeRemgAAnmA"]
[Mon Jul 20 07:34:54.579836 2026] [security2:error] [pid 164535:tid 164729] [client 65.111.22.186:34343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4j_jYN371eKRzcKeReogAAAMU"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:34:54.699187 2026] [security2:error] [pid 164535:tid 164768] [client 50.116.65.227:16126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeRenAAAAOw"]
[Mon Jul 20 07:34:54.727514 2026] [security2:error] [pid 164535:tid 164540] [remote 45.90.123.233:54478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4j_jYN371eKRzcKeResQAA7wQ"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:34:54.740500 2026] [security2:error] [pid 164535:tid 164748] [client 217.64.107.167:64678] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.new-menus.com"] [uri "/moxforum/index.php"] [unique_id "al4j_jYN371eKRzcKeRerAAA2DY"], referer: http://www.new-menus.com/moxforum/index.php?page=26
[Mon Jul 20 07:34:54.801556 2026] [security2:error] [pid 164535:tid 164738] [client 111.225.149.227:58612] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nevelow.com"] [uri "/robots.txt"] [unique_id "al4j_jYN371eKRzcKeReswAAAM4"]
[Mon Jul 20 07:34:54.887496 2026] [security2:error] [pid 164535:tid 164772] [client 50.116.65.227:16128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeRergAAAPA"]
[Mon Jul 20 07:34:54.941044 2026] [security2:error] [pid 164535:tid 164755] [client 66.249.64.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.wileybrosmusic.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeRepgAA3ys"]
[Mon Jul 20 07:34:55.109877 2026] [security2:error] [pid 164535:tid 164709] [client 14.225.17.146:56081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeRewQAAALE"], referer: http://laceycaraccident.com/demo
[Mon Jul 20 07:34:55.572305 2026] [security2:error] [pid 164535:tid 164715] [client 57.141.18.14:48432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j_jYN371eKRzcKeResgAAt1M"]
[Mon Jul 20 07:34:55.585060 2026] [security2:error] [pid 164535:tid 164630] [remote 3.8.99.147:53772] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "www.windowtx.com"] [uri "/"] [unique_id "al4j_zYN371eKRzcKeRe-AAA5l4"]
[Mon Jul 20 07:34:55.668107 2026] [autoindex:error] [pid 164535:tid 164697] [client 34.48.51.14:63117] AH01276: Cannot serve directory /home2/flhkrvmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:34:55.705226 2026] [security2:error] [pid 164535:tid 164756] [client 188.166.209.66:55308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-duotone.php"] [unique_id "al4j_zYN371eKRzcKeRe_QAAAOA"], referer: binance.com
[Mon Jul 20 07:34:55.751358 2026] [security2:error] [pid 164535:tid 164707] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4j_zYN371eKRzcKeRe8QAAAK8"]
[Mon Jul 20 07:34:55.790652 2026] [fcgid:warn] [pid 164535:tid 164676] (70014)End of file found: [client 167.94.146.63:57846] mod_fcgid: can't get data from http client
[Mon Jul 20 07:34:55.922703 2026] [security2:error] [pid 164535:tid 164721] [client 104.234.53.68:35315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4j_zYN371eKRzcKeRfCwAAAL0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:55.953832 2026] [security2:error] [pid 164535:tid 164725] [client 57.141.18.98:46522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j_zYN371eKRzcKeRe0QAAwVo"]
[Mon Jul 20 07:34:56.066318 2026] [security2:error] [pid 164535:tid 164757] [client 65.111.23.182:50613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kADYN371eKRzcKeRfGgAAAOE"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:34:56.296687 2026] [security2:error] [pid 164535:tid 164754] [client 57.141.18.73:33912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4j_zYN371eKRzcKeRe7wAA3nU"]
[Mon Jul 20 07:34:56.348096 2026] [security2:error] [pid 164535:tid 164703] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kADYN371eKRzcKeRfJAAAAKs"]
[Mon Jul 20 07:34:56.413670 2026] [security2:error] [pid 164535:tid 164670] [client 149.0.16.108:57041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfPQAAAIo"]
[Mon Jul 20 07:34:56.413783 2026] [security2:error] [pid 164535:tid 164670] [client 149.0.16.108:57041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfPQAAAIo"]
[Mon Jul 20 07:34:56.490405 2026] [security2:error] [pid 164535:tid 164667] [client 57.141.18.59:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kADYN371eKRzcKeRfOQAAAIc"]
[Mon Jul 20 07:34:56.581418 2026] [security2:error] [pid 164535:tid 164706] [client 49.47.218.174:51125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfSwAAAK4"]
[Mon Jul 20 07:34:56.581517 2026] [security2:error] [pid 164535:tid 164706] [client 49.47.218.174:51125] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfSwAAAK4"]
[Mon Jul 20 07:34:56.647674 2026] [security2:error] [pid 164535:tid 164721] [client 139.59.118.64:55587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.samdothan.org"] [uri "/wp-login.php"] [unique_id "al4kADYN371eKRzcKeRfUgAAAL0"], referer: https://www.bing.com/
[Mon Jul 20 07:34:56.769200 2026] [security2:error] [pid 164535:tid 164689] [client 142.111.152.173:63873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfUQAAAJ0"]
[Mon Jul 20 07:34:56.792138 2026] [security2:error] [pid 164535:tid 164732] [client 157.20.138.62:53032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfYgAAAMg"]
[Mon Jul 20 07:34:56.792292 2026] [security2:error] [pid 164535:tid 164732] [client 157.20.138.62:53032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kADYN371eKRzcKeRfYgAAAMg"]
[Mon Jul 20 07:34:57.196045 2026] [security2:error] [pid 164535:tid 164679] [client 57.141.18.24:30870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kADYN371eKRzcKeRfVwAAk00"]
[Mon Jul 20 07:34:57.239099 2026] [security2:error] [pid 164535:tid 164772] [client 57.141.18.85:60612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kADYN371eKRzcKeRfWwAA8FI"]
[Mon Jul 20 07:34:57.304324 2026] [security2:error] [pid 164535:tid 164719] [client 57.141.18.42:36644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kADYN371eKRzcKeRfYwAAux8"]
[Mon Jul 20 07:34:57.363596 2026] [security2:error] [pid 164535:tid 164686] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kATYN371eKRzcKeRfeQAAAJo"]
[Mon Jul 20 07:34:57.369379 2026] [security2:error] [pid 164535:tid 164767] [client 14.225.17.146:56028] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4kATYN371eKRzcKeRffAAAAOs"], referer: http://thesoloceos.com/demo
[Mon Jul 20 07:34:57.936360 2026] [security2:error] [pid 164535:tid 164572] [remote 188.166.241.141:41228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4kATYN371eKRzcKeRfuwAA7SQ"]
[Mon Jul 20 07:34:57.954514 2026] [security2:error] [pid 164535:tid 164673] [client 144.16.21.149:36263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kATYN371eKRzcKeRfvgAAAI0"]
[Mon Jul 20 07:34:57.954646 2026] [security2:error] [pid 164535:tid 164673] [client 144.16.21.149:36263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kATYN371eKRzcKeRfvgAAAI0"]
[Mon Jul 20 07:34:58.235486 2026] [security2:error] [pid 164535:tid 164681] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kAjYN371eKRzcKeRfxgAAAJU"]
[Mon Jul 20 07:34:58.319437 2026] [security2:error] [pid 164535:tid 164632] [remote 188.166.241.141:41228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4kAjYN371eKRzcKeRf3QAA8GA"], referer: https://spencersadventures.com/wp-login.php
[Mon Jul 20 07:34:58.347065 2026] [security2:error] [pid 164535:tid 164720] [client 14.225.17.146:56106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4kAjYN371eKRzcKeRf1gAAALw"], referer: https://thesoloceos.com/demo
[Mon Jul 20 07:34:58.458080 2026] [security2:error] [pid 164535:tid 164724] [client 14.251.3.155:56110] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4kAjYN371eKRzcKeRf6AAAAMA"]
[Mon Jul 20 07:34:58.478664 2026] [security2:error] [pid 164535:tid 164585] [remote 188.166.241.141:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kAjYN371eKRzcKeRf6gAA1zE"]
[Mon Jul 20 07:34:58.620875 2026] [security2:error] [pid 164535:tid 164762] [client 104.234.53.51:53643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kAjYN371eKRzcKeRf_wAAAOY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:58.624227 2026] [security2:error] [pid 164535:tid 164665] [client 154.192.123.127:17151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kAjYN371eKRzcKeRgAAAAAIU"]
[Mon Jul 20 07:34:58.624312 2026] [security2:error] [pid 164535:tid 164665] [client 154.192.123.127:17151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kAjYN371eKRzcKeRgAAAAAIU"]
[Mon Jul 20 07:34:58.659775 2026] [security2:error] [pid 164535:tid 164708] [client 36.93.152.155:61929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kAjYN371eKRzcKeRgAwAAALA"]
[Mon Jul 20 07:34:58.659873 2026] [security2:error] [pid 164535:tid 164708] [client 36.93.152.155:61929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kAjYN371eKRzcKeRgAwAAALA"]
[Mon Jul 20 07:34:58.850782 2026] [security2:error] [pid 164535:tid 164562] [remote 188.166.241.141:41244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kAjYN371eKRzcKeRgEAAA3Ro"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:34:59.029537 2026] [security2:error] [pid 164535:tid 164685] [client 136.158.60.21:42943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgHwAAAJk"]
[Mon Jul 20 07:34:59.029701 2026] [security2:error] [pid 164535:tid 164685] [client 136.158.60.21:42943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgHwAAAJk"]
[Mon Jul 20 07:34:59.199610 2026] [security2:error] [pid 164535:tid 164713] [client 49.37.242.14:57288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgMQAAALU"]
[Mon Jul 20 07:34:59.199776 2026] [security2:error] [pid 164535:tid 164713] [client 49.37.242.14:57288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgMQAAALU"]
[Mon Jul 20 07:34:59.393343 2026] [security2:error] [pid 164535:tid 164691] [client 188.166.209.66:50742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-exception.php"] [unique_id "al4kAzYN371eKRzcKeRgPgAAAJ8"], referer: binance.com
[Mon Jul 20 07:34:59.396330 2026] [security2:error] [pid 164535:tid 164785] [client 14.225.17.146:56114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4kAzYN371eKRzcKeRgJAAAAP0"], referer: http://nwcarvingacademy.com/demo
[Mon Jul 20 07:34:59.424196 2026] [security2:error] [pid 164535:tid 164619] [remote 160.187.68.132:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4kAzYN371eKRzcKeRgPwAAiFM"]
[Mon Jul 20 07:34:59.525355 2026] [security2:error] [pid 164535:tid 164727] [client 57.141.18.120:60596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kAjYN371eKRzcKeRgEgAAwzg"]
[Mon Jul 20 07:34:59.536534 2026] [security2:error] [pid 164535:tid 164694] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kAzYN371eKRzcKeRgOAAAAKI"]
[Mon Jul 20 07:34:59.633419 2026] [security2:error] [pid 164535:tid 164686] [client 104.234.53.73:36227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kAzYN371eKRzcKeRgWAAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:34:59.663388 2026] [security2:error] [pid 164535:tid 164673] [client 103.106.165.44:51037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgXQAAAI0"]
[Mon Jul 20 07:34:59.663487 2026] [security2:error] [pid 164535:tid 164673] [client 103.106.165.44:51037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgXQAAAI0"]
[Mon Jul 20 07:34:59.832776 2026] [security2:error] [pid 164535:tid 164706] [client 14.225.17.146:55886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4kAzYN371eKRzcKeRgWQAAAK4"], referer: http://fineartsfactory.net/demo
[Mon Jul 20 07:34:59.876285 2026] [security2:error] [pid 164535:tid 164647] [remote 160.187.68.132:52206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secretkeynumerology.com"] [uri "/wp-login.php"] [unique_id "al4kAzYN371eKRzcKeRgaQAAvG8"], referer: https://secretkeynumerology.com/wp-login.php
[Mon Jul 20 07:34:59.918669 2026] [security2:error] [pid 164535:tid 164728] [client 143.44.185.218:47617] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgcgAAAMQ"]
[Mon Jul 20 07:34:59.918787 2026] [security2:error] [pid 164535:tid 164728] [client 143.44.185.218:47617] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgcgAAAMQ"]
[Mon Jul 20 07:34:59.928368 2026] [security2:error] [pid 164535:tid 164742] [client 191.202.66.27:64500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgcwAAANI"]
[Mon Jul 20 07:34:59.928452 2026] [security2:error] [pid 164535:tid 164742] [client 191.202.66.27:64500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgcwAAANI"]
[Mon Jul 20 07:34:59.936708 2026] [security2:error] [pid 164535:tid 164670] [client 179.127.84.238:51112] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgdQAAAIo"]
[Mon Jul 20 07:34:59.937270 2026] [security2:error] [pid 164535:tid 164670] [client 179.127.84.238:51112] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kAzYN371eKRzcKeRgdQAAAIo"]
[Mon Jul 20 07:35:00.074734 2026] [security2:error] [pid 164535:tid 164573] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kBDYN371eKRzcKeRggwAAmSU"]
[Mon Jul 20 07:35:00.074890 2026] [security2:error] [pid 164535:tid 164685] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kBDYN371eKRzcKeRggwAAmSU"]
[Mon Jul 20 07:35:00.117578 2026] [security2:error] [pid 164535:tid 164711] [client 57.141.18.94:46578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kAzYN371eKRzcKeRgRAAAs20"]
[Mon Jul 20 07:35:00.308021 2026] [security2:error] [pid 164535:tid 164710] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kAzYN371eKRzcKeRgewAAALI"]
[Mon Jul 20 07:35:00.318057 2026] [security2:error] [pid 164535:tid 164565] [remote 100.42.189.89:34926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kBDYN371eKRzcKeRglQAA8h0"]
[Mon Jul 20 07:35:00.461788 2026] [security2:error] [pid 164535:tid 164724] [client 14.225.17.146:59400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4kBDYN371eKRzcKeRgkAAAAMA"], referer: https://nwcarvingacademy.com/demo
[Mon Jul 20 07:35:00.519881 2026] [security2:error] [pid 164535:tid 164546] [remote 100.42.189.89:34926] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kBDYN371eKRzcKeRgpgAA1Qo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:35:00.883685 2026] [security2:error] [pid 164535:tid 164729] [client 104.234.53.65:52589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kBDYN371eKRzcKeRgvgAAAMU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:00.975164 2026] [security2:error] [pid 164535:tid 164731] [client 17.246.15.117:44926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4kBDYN371eKRzcKeRgwAAAx3o"]
[Mon Jul 20 07:35:00.992797 2026] [security2:error] [pid 164535:tid 164679] [client 46.110.96.34:44775] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kBDYN371eKRzcKeRg0QAAAJM"]
[Mon Jul 20 07:35:00.994537 2026] [security2:error] [pid 164535:tid 164721] [client 46.110.96.34:22958] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kBDYN371eKRzcKeRg0gAAAL0"]
[Mon Jul 20 07:35:01.056195 2026] [security2:error] [pid 164535:tid 164788] [client 57.141.18.73:33930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kBDYN371eKRzcKeRgmAABAGc"]
[Mon Jul 20 07:35:01.272973 2026] [security2:error] [pid 164535:tid 164758] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kBDYN371eKRzcKeRg0AAAAOI"]
[Mon Jul 20 07:35:01.350139 2026] [security2:error] [pid 164535:tid 164718] [client 103.176.215.66:55519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kBTYN371eKRzcKeRg-QAAALo"]
[Mon Jul 20 07:35:01.350597 2026] [security2:error] [pid 164535:tid 164718] [client 103.176.215.66:55519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kBTYN371eKRzcKeRg-QAAALo"]
[Mon Jul 20 07:35:01.381396 2026] [security2:error] [pid 164535:tid 164735] [client 3.75.183.99:63878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kBTYN371eKRzcKeRg_gAAAMs"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:35:01.496601 2026] [security2:error] [pid 164535:tid 164783] [client 14.225.17.146:64031] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4kBTYN371eKRzcKeRg-gAAAPs"], referer: http://soloceos.com/demo
[Mon Jul 20 07:35:01.681403 2026] [security2:error] [pid 164535:tid 164667] [client 177.37.170.254:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4kBTYN371eKRzcKeRg9QAAAIc"]
[Mon Jul 20 07:35:01.867874 2026] [security2:error] [pid 164535:tid 164709] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kBTYN371eKRzcKeRhEwAAALE"]
[Mon Jul 20 07:35:01.910483 2026] [security2:error] [pid 164535:tid 164748] [client 63.176.132.15:20862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.132.176.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kBTYN371eKRzcKeRhKAAAANg"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:35:01.938390 2026] [security2:error] [pid 164535:tid 164676] [client 117.211.236.168:64527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kBTYN371eKRzcKeRhLQAAAJA"]
[Mon Jul 20 07:35:01.938495 2026] [security2:error] [pid 164535:tid 164676] [client 117.211.236.168:64527] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kBTYN371eKRzcKeRhLQAAAJA"]
[Mon Jul 20 07:35:02.202805 2026] [security2:error] [pid 164535:tid 164787] [client 1.39.228.9:15956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4kBjYN371eKRzcKeRhOQAAAP8"]
[Mon Jul 20 07:35:02.296667 2026] [security2:error] [pid 164535:tid 164683] [client 14.225.17.146:63566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4kBjYN371eKRzcKeRhQwAAAJc"], referer: http://cloudspacesgroup.com/demo
[Mon Jul 20 07:35:02.324537 2026] [security2:error] [pid 164535:tid 164688] [client 63.177.52.239:47950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.52.177.63.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kBjYN371eKRzcKeRhVwAAAJw"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:35:02.446727 2026] [security2:error] [pid 164535:tid 164724] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kBjYN371eKRzcKeRhTgAAAMA"]
[Mon Jul 20 07:35:02.531937 2026] [security2:error] [pid 164535:tid 164680] [client 151.243.11.245:55580] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4kBjYN371eKRzcKeRhawAAAJQ"]
[Mon Jul 20 07:35:02.692974 2026] [security2:error] [pid 164535:tid 164771] [client 216.73.216.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4kBjYN371eKRzcKeRhZAAAAO8"]
[Mon Jul 20 07:35:02.862910 2026] [security2:error] [pid 164535:tid 164586] [remote 160.187.68.132:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4kBjYN371eKRzcKeRhiQAAkzI"]
[Mon Jul 20 07:35:02.865862 2026] [security2:error] [pid 164535:tid 164738] [client 3.75.183.99:63894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.183.75.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kBjYN371eKRzcKeRhjQAAAM4"], referer: https://curlsnpearlsss.com/es/homemade-adobo-adobo-puertorriqueno/
[Mon Jul 20 07:35:02.870112 2026] [security2:error] [pid 164535:tid 164767] [client 104.234.53.69:59861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kBjYN371eKRzcKeRhjwAAAOs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:03.054547 2026] [security2:error] [pid 164535:tid 164764] [client 216.73.216.153:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4kBjYN371eKRzcKeRhiAAAAOg"], referer: https://webgardensbypaula.com/sitemap.xml
[Mon Jul 20 07:35:03.122964 2026] [security2:error] [pid 164535:tid 164685] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kBjYN371eKRzcKeRhlQAAAJk"]
[Mon Jul 20 07:35:03.321074 2026] [security2:error] [pid 164535:tid 164690] [client 46.110.96.34:23513] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kBzYN371eKRzcKeRhswAAAJ4"]
[Mon Jul 20 07:35:03.337663 2026] [security2:error] [pid 164535:tid 164714] [client 46.110.96.34:25938] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kBzYN371eKRzcKeRhtwAAALY"]
[Mon Jul 20 07:35:03.346756 2026] [security2:error] [pid 164535:tid 164592] [remote 160.187.68.132:49240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "vinovinhowine.com"] [uri "/wp-login.php"] [unique_id "al4kBzYN371eKRzcKeRhtgAAyDg"], referer: https://vinovinhowine.com/wp-login.php
[Mon Jul 20 07:35:03.354872 2026] [security2:error] [pid 164535:tid 164670] [client 14.225.17.146:55625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4kBTYN371eKRzcKeRhHQAAAIo"], referer: http://tntcatholic.com/demo
[Mon Jul 20 07:35:03.363922 2026] [security2:error] [pid 164535:tid 164724] [client 14.225.17.146:55629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4kBzYN371eKRzcKeRhrAAAAMA"], referer: http://sarahholyfield.com/demo
[Mon Jul 20 07:35:03.379208 2026] [security2:error] [pid 164535:tid 164688] [client 46.110.96.34:37832] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kBzYN371eKRzcKeRhuwAAAJw"]
[Mon Jul 20 07:35:03.624279 2026] [security2:error] [pid 164535:tid 164746] [client 14.225.17.146:55577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4kBzYN371eKRzcKeRhvQAAANY"], referer: http://dollpassionista.com/demo
[Mon Jul 20 07:35:03.679968 2026] [security2:error] [pid 164535:tid 164788] [client 188.166.209.66:57502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-http.php"] [unique_id "al4kBzYN371eKRzcKeRh2QAAAQA"], referer: binance.com
[Mon Jul 20 07:35:03.938931 2026] [security2:error] [pid 164535:tid 164674] [client 103.139.191.61:51208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kBzYN371eKRzcKeRh6AAAAI4"]
[Mon Jul 20 07:35:03.939038 2026] [security2:error] [pid 164535:tid 164674] [client 103.139.191.61:51208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kBzYN371eKRzcKeRh6AAAAI4"]
[Mon Jul 20 07:35:04.569704 2026] [security2:error] [pid 164535:tid 164741] [client 62.102.148.130:35460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4kCDYN371eKRzcKeRiEAAAANE"]
[Mon Jul 20 07:35:04.569836 2026] [security2:error] [pid 164535:tid 164741] [client 62.102.148.130:35460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4kCDYN371eKRzcKeRiEAAAANE"]
[Mon Jul 20 07:35:04.613493 2026] [security2:error] [pid 164535:tid 164763] [client 14.225.17.146:55626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4kCDYN371eKRzcKeRiBgAAAOc"], referer: https://dollpassionista.com/demo
[Mon Jul 20 07:35:04.710842 2026] [security2:error] [pid 164535:tid 164726] [client 57.141.18.20:43210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kCDYN371eKRzcKeRh_wAAwh0"]
[Mon Jul 20 07:35:05.055991 2026] [security2:error] [pid 164535:tid 164668] [client 139.59.118.64:57039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.samdothan.org"] [uri "/wp-login.php"] [unique_id "al4kCTYN371eKRzcKeRiPQAAAIg"], referer: https://wordpress.org/
[Mon Jul 20 07:35:05.075484 2026] [security2:error] [pid 164535:tid 164729] [client 180.249.173.210:65519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kCTYN371eKRzcKeRiQgAAAMU"]
[Mon Jul 20 07:35:05.076946 2026] [security2:error] [pid 164535:tid 164729] [client 180.249.173.210:65519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kCTYN371eKRzcKeRiQgAAAMU"]
[Mon Jul 20 07:35:05.093780 2026] [security2:error] [pid 164535:tid 164715] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kCDYN371eKRzcKeRiIQAAALc"]
[Mon Jul 20 07:35:05.166628 2026] [security2:error] [pid 164535:tid 164569] [remote 112.86.225.103:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4kCTYN371eKRzcKeRiRgAAziE"]
[Mon Jul 20 07:35:05.166777 2026] [security2:error] [pid 164535:tid 164738] [client 112.86.225.103:0] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.benbayly.co.nz"] [uri "/"] [unique_id "al4kCTYN371eKRzcKeRiRgAAziE"]
[Mon Jul 20 07:35:05.256798 2026] [security2:error] [pid 164535:tid 164695] [client 98.159.234.160:20677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kCTYN371eKRzcKeRiUAAAAKM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:35:05.306503 2026] [security2:error] [pid 164535:tid 164683] [client 57.141.18.91:26968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kCDYN371eKRzcKeRiJQAAl3c"]
[Mon Jul 20 07:35:05.710046 2026] [security2:error] [pid 164535:tid 164704] [client 170.64.229.59:58785] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.miamimeditations.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4kCTYN371eKRzcKeRidQAAAKw"]
[Mon Jul 20 07:35:05.744832 2026] [security2:error] [pid 164535:tid 164707] [client 116.74.65.235:64652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4kCTYN371eKRzcKeRibAAAAK8"]
[Mon Jul 20 07:35:05.918947 2026] [security2:error] [pid 164535:tid 164715] [client 104.234.53.65:39687] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kCTYN371eKRzcKeRihAAAALc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:05.929008 2026] [security2:error] [pid 164535:tid 164765] [client 47.128.125.80:28364] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.maxenengineering.com"] [uri "/robots.txt"] [unique_id "al4kCTYN371eKRzcKeRihQAAAOk"]
[Mon Jul 20 07:35:05.949397 2026] [security2:error] [pid 164535:tid 164724] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kCTYN371eKRzcKeRiewAAAMA"]
[Mon Jul 20 07:35:06.066363 2026] [security2:error] [pid 164535:tid 164738] [client 23.100.30.92:38256] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pattyspractice.com"] [uri "/index.php"] [unique_id "al4kCTYN371eKRzcKeRifQAAAM4"]
[Mon Jul 20 07:35:06.131784 2026] [security2:error] [pid 164535:tid 164751] [client 139.59.118.64:57200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.samdothan.org"] [uri "/wp-login.php"] [unique_id "al4kCjYN371eKRzcKeRiqQAAANs"]
[Mon Jul 20 07:35:06.304208 2026] [security2:error] [pid 164535:tid 164679] [client 57.141.18.5:38348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kCTYN371eKRzcKeRifgAAk0I"]
[Mon Jul 20 07:35:06.421222 2026] [security2:error] [pid 164535:tid 164714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kCjYN371eKRzcKeRitAAAALY"]
[Mon Jul 20 07:35:06.469999 2026] [security2:error] [pid 164535:tid 164713] [client 50.116.65.227:11244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kCjYN371eKRzcKeRizgAAALU"]
[Mon Jul 20 07:35:06.480485 2026] [security2:error] [pid 164535:tid 164693] [client 50.116.65.227:11256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kCjYN371eKRzcKeRizwAAAKE"]
[Mon Jul 20 07:35:06.753521 2026] [security2:error] [pid 164535:tid 164760] [client 169.224.18.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4kCTYN371eKRzcKeRiWAAAAOQ"]
[Mon Jul 20 07:35:07.002846 2026] [security2:error] [pid 164535:tid 164753] [client 149.0.16.108:57547] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRi8wAAAN0"]
[Mon Jul 20 07:35:07.002943 2026] [security2:error] [pid 164535:tid 164753] [client 149.0.16.108:57547] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRi8wAAAN0"]
[Mon Jul 20 07:35:07.030141 2026] [security2:error] [pid 164535:tid 164738] [client 49.47.218.174:62473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRi-AAAAM4"]
[Mon Jul 20 07:35:07.030445 2026] [security2:error] [pid 164535:tid 164738] [client 49.47.218.174:62473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRi-AAAAM4"]
[Mon Jul 20 07:35:07.054860 2026] [security2:error] [pid 164535:tid 164713] [client 151.243.11.245:55598] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4kCjYN371eKRzcKeRi8QAAALU"]
[Mon Jul 20 07:35:07.193096 2026] [security2:error] [pid 164535:tid 164747] [client 142.111.152.60:42467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRi_AAAANc"]
[Mon Jul 20 07:35:07.193235 2026] [security2:error] [pid 164535:tid 164747] [client 142.111.152.60:42467] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRi_AAAANc"]
[Mon Jul 20 07:35:07.279719 2026] [security2:error] [pid 164535:tid 164717] [client 157.20.138.62:53613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRjCwAAALk"]
[Mon Jul 20 07:35:07.279835 2026] [security2:error] [pid 164535:tid 164717] [client 157.20.138.62:53613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kCzYN371eKRzcKeRjCwAAALk"]
[Mon Jul 20 07:35:07.426555 2026] [security2:error] [pid 164535:tid 164697] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kCzYN371eKRzcKeRjAgAAAKU"]
[Mon Jul 20 07:35:07.460643 2026] [security2:error] [pid 164535:tid 164669] [client 57.141.18.19:38688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kCzYN371eKRzcKeRi-gAAiWA"]
[Mon Jul 20 07:35:07.464645 2026] [security2:error] [pid 164535:tid 164769] [client 188.166.209.66:59627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-icons-registry.php"] [unique_id "al4kCzYN371eKRzcKeRjGgAAAO0"], referer: binance.com
[Mon Jul 20 07:35:07.529778 2026] [security2:error] [pid 164535:tid 164676] [client 74.7.244.40:58074] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "charisandchesed.com"] [uri "/robots.txt"] [unique_id "al4kCzYN371eKRzcKeRjJAAAAJA"]
[Mon Jul 20 07:35:07.551367 2026] [security2:error] [pid 164535:tid 164740] [client 14.225.17.146:63825] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4kCzYN371eKRzcKeRjCgAAANA"], referer: http://tacticaltreeoperations.com/demo
[Mon Jul 20 07:35:07.630832 2026] [security2:error] [pid 164535:tid 164774] [client 14.225.17.146:58994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4kCzYN371eKRzcKeRjFwAAAPI"], referer: http://sarahsnyder.net/demo
[Mon Jul 20 07:35:07.684691 2026] [security2:error] [pid 164535:tid 164756] [client 14.225.17.146:64041] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4kCjYN371eKRzcKeRiuwAAAOA"], referer: http://eframiproperties.com/demo
[Mon Jul 20 07:35:07.808576 2026] [security2:error] [pid 164535:tid 164640] [remote 57.141.18.62:20840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4kCzYN371eKRzcKeRjOgABBGg"]
[Mon Jul 20 07:35:07.854650 2026] [autoindex:error] [pid 164535:tid 164685] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/11/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:35:07.939308 2026] [security2:error] [pid 164535:tid 164701] [client 43.205.139.3:16932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4kCzYN371eKRzcKeRjTAAAAKk"]
[Mon Jul 20 07:35:08.040083 2026] [security2:error] [pid 164535:tid 164730] [client 23.100.30.92:38282] ModSecurity: Warning. Matched phrase "BuiltWith" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "pattyspractice.com"] [uri "/index.php"] [unique_id "al4kCzYN371eKRzcKeRjOQAAAMY"]
[Mon Jul 20 07:35:08.064339 2026] [security2:error] [pid 164535:tid 164728] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kCzYN371eKRzcKeRjRgAAAMQ"], referer: 1'"3000
[Mon Jul 20 07:35:08.581093 2026] [security2:error] [pid 164535:tid 164671] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kDDYN371eKRzcKeRjYwAAAIs"], referer: 1'"3000
[Mon Jul 20 07:35:08.621261 2026] [security2:error] [pid 164535:tid 164719] [client 57.141.18.67:55774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kDDYN371eKRzcKeRjXAAAu1A"]
[Mon Jul 20 07:35:08.681411 2026] [security2:error] [pid 164535:tid 164645] [remote 192.241.143.148:41840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kDDYN371eKRzcKeRjgwAAx20"]
[Mon Jul 20 07:35:08.681540 2026] [security2:error] [pid 164535:tid 164731] [client 192.241.143.148:41840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.yok.mqz.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kDDYN371eKRzcKeRjgwAAx20"]
[Mon Jul 20 07:35:08.698075 2026] [security2:error] [pid 164535:tid 164790] [client 14.225.17.146:49484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4kDDYN371eKRzcKeRjdwAAAQI"], referer: https://sarahsnyder.net/demo
[Mon Jul 20 07:35:08.740908 2026] [security2:error] [pid 164535:tid 164708] [client 104.207.52.82:46683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kDDYN371eKRzcKeRjhwAAALA"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:35:08.892238 2026] [security2:error] [pid 164535:tid 164779] [client 13.232.231.177:30984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4kDDYN371eKRzcKeRjmAAAAPc"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:35:09.067799 2026] [security2:error] [pid 164535:tid 164691] [client 104.234.53.76:20337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kDTYN371eKRzcKeRjpQAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:09.136220 2026] [security2:error] [pid 164535:tid 164675] [client 46.110.96.34:40273] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kDTYN371eKRzcKeRjsAAAAI8"]
[Mon Jul 20 07:35:09.137453 2026] [security2:error] [pid 164535:tid 164788] [client 46.110.96.34:32707] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kDTYN371eKRzcKeRjsQAAAQA"]
[Mon Jul 20 07:35:09.154677 2026] [security2:error] [pid 164535:tid 164780] [client 36.93.152.155:62462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRjswAAAPg"]
[Mon Jul 20 07:35:09.154779 2026] [security2:error] [pid 164535:tid 164780] [client 36.93.152.155:62462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRjswAAAPg"]
[Mon Jul 20 07:35:09.157377 2026] [security2:error] [pid 164535:tid 164714] [client 154.192.123.127:17567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRjtQAAALY"]
[Mon Jul 20 07:35:09.157493 2026] [security2:error] [pid 164535:tid 164714] [client 154.192.123.127:17567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRjtQAAALY"]
[Mon Jul 20 07:35:09.399988 2026] [security2:error] [pid 164535:tid 164734] [client 57.141.18.16:49606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kDTYN371eKRzcKeRjpgAAyk4"]
[Mon Jul 20 07:35:09.504011 2026] [security2:error] [pid 164535:tid 164758] [client 144.16.21.149:24873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRjzAAAAOI"]
[Mon Jul 20 07:35:09.504162 2026] [security2:error] [pid 164535:tid 164758] [client 144.16.21.149:24873] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRjzAAAAOI"]
[Mon Jul 20 07:35:09.743332 2026] [security2:error] [pid 164535:tid 164694] [client 136.158.60.21:44609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRj4AAAAKI"]
[Mon Jul 20 07:35:09.743451 2026] [security2:error] [pid 164535:tid 164694] [client 136.158.60.21:44609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kDTYN371eKRzcKeRj4AAAAKI"]
[Mon Jul 20 07:35:09.970048 2026] [security2:error] [pid 164535:tid 164550] [remote 57.141.18.98:63298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5945360"] [unique_id "al4kDTYN371eKRzcKeRj8AAAuQ4"]
[Mon Jul 20 07:35:10.166274 2026] [security2:error] [pid 164535:tid 164665] [client 103.106.165.44:51533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kDjYN371eKRzcKeRkBAAAAIU"]
[Mon Jul 20 07:35:10.166429 2026] [security2:error] [pid 164535:tid 164665] [client 103.106.165.44:51533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kDjYN371eKRzcKeRkBAAAAIU"]
[Mon Jul 20 07:35:10.216394 2026] [security2:error] [pid 164535:tid 164709] [client 188.166.209.66:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-navigation-fallback.php"] [unique_id "al4kDjYN371eKRzcKeRkCAAAALE"], referer: binance.com
[Mon Jul 20 07:35:10.297702 2026] [security2:error] [pid 164535:tid 164689] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "genlius.com"] [uri "/index.php"] [unique_id "al4kDDYN371eKRzcKeRjfAAAAJ0"]
[Mon Jul 20 07:35:10.365662 2026] [security2:error] [pid 164535:tid 164763] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kDjYN371eKRzcKeRkAAAAAOc"], referer: 1'"3000
[Mon Jul 20 07:35:10.388309 2026] [security2:error] [pid 164535:tid 164776] [client 66.249.65.34:53923] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "benreyesconstruction.com"] [uri "/robots.txt"] [unique_id "al4kDjYN371eKRzcKeRkIAAAAPQ"]
[Mon Jul 20 07:35:10.660272 2026] [security2:error] [pid 164535:tid 164740] [client 191.202.66.27:65002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kDjYN371eKRzcKeRkMwAAANA"]
[Mon Jul 20 07:35:10.660382 2026] [security2:error] [pid 164535:tid 164740] [client 191.202.66.27:65002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kDjYN371eKRzcKeRkMwAAANA"]
[Mon Jul 20 07:35:10.705114 2026] [security2:error] [pid 164535:tid 164731] [client 179.127.84.238:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kDjYN371eKRzcKeRkNwAAAMc"]
[Mon Jul 20 07:35:10.705273 2026] [security2:error] [pid 164535:tid 164731] [client 179.127.84.238:51652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kDjYN371eKRzcKeRkNwAAAMc"]
[Mon Jul 20 07:35:10.784400 2026] [security2:error] [pid 164535:tid 164716] [client 14.225.17.146:58768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4kDjYN371eKRzcKeRkKAAAALg"], referer: http://sesamegreenbeans.com/demo
[Mon Jul 20 07:35:10.908646 2026] [security2:error] [pid 164535:tid 164721] [client 57.141.18.121:41090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kDjYN371eKRzcKeRkJgAAvWI"]
[Mon Jul 20 07:35:10.995032 2026] [security2:error] [pid 164535:tid 164737] [client 104.234.53.79:30111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kDjYN371eKRzcKeRkTwAAAM0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:11.044165 2026] [security2:error] [pid 164535:tid 164680] [client 14.225.17.146:58967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4kDjYN371eKRzcKeRkNQAAAJQ"], referer: http://mollycahill.com/demo
[Mon Jul 20 07:35:11.208281 2026] [security2:error] [pid 164535:tid 164727] [client 14.225.17.146:58793] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4kDzYN371eKRzcKeRkVAAAAMM"], referer: http://iagdevelopments.com/demo
[Mon Jul 20 07:35:11.278030 2026] [security2:error] [pid 164535:tid 164780] [client 74.7.228.8:36782] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4kDjYN371eKRzcKeRkSgAA-D4"]
[Mon Jul 20 07:35:11.325885 2026] [lsapi:warn] [pid 164535:tid 164687] [client 43.166.132.142:50060] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: https://www.oldracelimited.com/
[Mon Jul 20 07:35:11.328231 2026] [security2:error] [pid 164535:tid 164549] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kDzYN371eKRzcKeRkawAA2g0"]
[Mon Jul 20 07:35:11.328379 2026] [security2:error] [pid 164535:tid 164750] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kDzYN371eKRzcKeRkawAA2g0"]
[Mon Jul 20 07:35:11.328897 2026] [lsapi:warn] [pid 164535:tid 164687] [client 43.166.132.142:50060] [host oldracelimited.com] Backend log: PHP Warning:  Undefined array key "host" in /home2/oldracel/public_html/oldracelimited/wp-content/plugins/bluehost-wordpress-plugin/inc/YoastAI.php on line 54\n, referer: https://www.oldracelimited.com/
[Mon Jul 20 07:35:11.337070 2026] [security2:error] [pid 164535:tid 164747] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kDzYN371eKRzcKeRkWQAAANc"], referer: 1'"3000
[Mon Jul 20 07:35:11.342797 2026] [security2:error] [pid 164535:tid 164676] [client 128.199.174.57:58016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4kDzYN371eKRzcKeRkWAAAAJA"], referer: https://www.sesamegreenbeans.com/
[Mon Jul 20 07:35:11.507949 2026] [security2:error] [pid 164535:tid 164739] [client 46.110.96.34:55730] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kDzYN371eKRzcKeRkegAAAM8"]
[Mon Jul 20 07:35:11.507949 2026] [security2:error] [pid 164535:tid 164688] [client 46.110.96.34:35538] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kDzYN371eKRzcKeRkewAAAJw"]
[Mon Jul 20 07:35:11.567904 2026] [security2:error] [pid 164535:tid 164743] [client 46.110.96.34:18307] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kDzYN371eKRzcKeRkfwAAANM"]
[Mon Jul 20 07:35:11.585359 2026] [security2:error] [pid 164535:tid 164585] [remote 162.19.86.63:51840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kDzYN371eKRzcKeRkgAAA4TE"]
[Mon Jul 20 07:35:11.779912 2026] [security2:error] [pid 164535:tid 164615] [remote 162.19.86.63:51840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kDzYN371eKRzcKeRkkgAA-k8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:35:11.791547 2026] [security2:error] [pid 164535:tid 164758] [client 143.44.185.218:48915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kDzYN371eKRzcKeRkkwAAAOI"]
[Mon Jul 20 07:35:11.793407 2026] [security2:error] [pid 164535:tid 164724] [client 14.225.17.146:58972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4kDzYN371eKRzcKeRkgwAAAMA"], referer: https://sesamegreenbeans.com/demo
[Mon Jul 20 07:35:11.793740 2026] [security2:error] [pid 164535:tid 164758] [client 143.44.185.218:48915] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kDzYN371eKRzcKeRkkwAAAOI"]
[Mon Jul 20 07:35:11.937532 2026] [security2:error] [pid 164535:tid 164718] [client 103.176.215.66:56100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kDzYN371eKRzcKeRkoAAAALo"]
[Mon Jul 20 07:35:11.938072 2026] [security2:error] [pid 164535:tid 164718] [client 103.176.215.66:56100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kDzYN371eKRzcKeRkoAAAALo"]
[Mon Jul 20 07:35:11.994905 2026] [security2:error] [pid 164535:tid 164764] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kDzYN371eKRzcKeRkjwAAAOg"], referer: 1'"3000
[Mon Jul 20 07:35:12.545927 2026] [security2:error] [pid 164535:tid 164734] [client 49.37.242.14:57914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kEDYN371eKRzcKeRkzQAAAMo"]
[Mon Jul 20 07:35:12.546073 2026] [security2:error] [pid 164535:tid 164734] [client 49.37.242.14:57914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kEDYN371eKRzcKeRkzQAAAMo"]
[Mon Jul 20 07:35:12.612051 2026] [security2:error] [pid 164535:tid 164715] [client 188.166.209.66:63513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-phpmailer.php"] [unique_id "al4kEDYN371eKRzcKeRk1QAAALc"], referer: binance.com
[Mon Jul 20 07:35:12.686723 2026] [security2:error] [pid 164535:tid 164741] [client 57.141.18.2:33734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kEDYN371eKRzcKeRktAAA0WM"]
[Mon Jul 20 07:35:12.884579 2026] [security2:error] [pid 164535:tid 164626] [remote 57.141.18.75:42032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5860014"] [unique_id "al4kEDYN371eKRzcKeRk5wAA51o"]
[Mon Jul 20 07:35:13.148796 2026] [security2:error] [pid 164535:tid 164688] [client 216.24.212.19:20853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4kETYN371eKRzcKeRlBAAAAJw"]
[Mon Jul 20 07:35:13.188469 2026] [security2:error] [pid 164535:tid 164669] [client 216.24.212.50:30999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4kETYN371eKRzcKeRlBgAAAIk"]
[Mon Jul 20 07:35:13.246134 2026] [security2:error] [pid 164535:tid 164786] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kETYN371eKRzcKeRk9gAAAP4"], referer: 1'"3000
[Mon Jul 20 07:35:13.418497 2026] [security2:error] [pid 164535:tid 164763] [client 139.59.118.64:58278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.samdothan.org"] [uri "/wp-login.php"] [unique_id "al4kETYN371eKRzcKeRlGAAAAOc"], referer: https://www.facebook.com/
[Mon Jul 20 07:35:13.598359 2026] [security2:error] [pid 164535:tid 164691] [client 57.141.18.77:30800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kEDYN371eKRzcKeRk7AAAn0k"]
[Mon Jul 20 07:35:13.599163 2026] [security2:error] [pid 164535:tid 164790] [client 117.211.236.168:65218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kETYN371eKRzcKeRlLAAAAQI"]
[Mon Jul 20 07:35:13.599282 2026] [security2:error] [pid 164535:tid 164790] [client 117.211.236.168:65218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kETYN371eKRzcKeRlLAAAAQI"]
[Mon Jul 20 07:35:13.648925 2026] [security2:error] [pid 164535:tid 164758] [client 47.128.112.6:50060] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "suretybonds-california.com"] [uri "/robots.txt"] [unique_id "al4kETYN371eKRzcKeRlMAAAAOI"]
[Mon Jul 20 07:35:14.022609 2026] [security2:error] [pid 164535:tid 164719] [client 104.234.53.81:37485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kEjYN371eKRzcKeRlWwAAALs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:14.038509 2026] [security2:error] [pid 164535:tid 164733] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kETYN371eKRzcKeRlSgAAAMk"], referer: 1'"3000
[Mon Jul 20 07:35:14.300087 2026] [security2:error] [pid 164535:tid 164701] [client 14.225.17.146:49549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4kETYN371eKRzcKeRk-gAAAKk"], referer: http://39ishlife.com/demo
[Mon Jul 20 07:35:14.335354 2026] [security2:error] [pid 164535:tid 164699] [client 181.37.228.101:33580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4kEjYN371eKRzcKeRlYwAAAKc"], referer: https://www.sesamegreenbeans.com/
[Mon Jul 20 07:35:14.355983 2026] [security2:error] [pid 164535:tid 164778] [client 114.119.152.108:65363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "locketsandcharms.com"] [uri "/category/blog/page/3"] [unique_id "al4kEjYN371eKRzcKeRlegAAAPY"], referer: https://locketsandcharms.com/category/blog/page/5
[Mon Jul 20 07:35:14.365074 2026] [security2:error] [pid 164535:tid 164669] [client 57.141.18.0:38994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kETYN371eKRzcKeRlRgAAiWU"]
[Mon Jul 20 07:35:14.636589 2026] [security2:error] [pid 164535:tid 164756] [client 14.225.17.146:58034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4kEjYN371eKRzcKeRlcwAAAOA"], referer: http://guidehunting.com/demo
[Mon Jul 20 07:35:14.743183 2026] [security2:error] [pid 164535:tid 164690] [client 14.225.17.146:49631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4kETYN371eKRzcKeRlEQAAAJ4"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/demo
[Mon Jul 20 07:35:14.920547 2026] [security2:error] [pid 164535:tid 164666] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kEjYN371eKRzcKeRlrQAAAIY"]
[Mon Jul 20 07:35:14.951209 2026] [security2:error] [pid 164535:tid 164547] [remote 124.55.178.99:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kEjYN371eKRzcKeRlswAAxgs"]
[Mon Jul 20 07:35:14.961395 2026] [security2:error] [pid 164535:tid 164767] [client 66.249.70.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kEjYN371eKRzcKeRlnAAA6z0"]
[Mon Jul 20 07:35:15.173448 2026] [security2:error] [pid 164535:tid 164544] [remote 217.61.143.92:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kEzYN371eKRzcKeRlzAAAlgg"]
[Mon Jul 20 07:35:15.221122 2026] [security2:error] [pid 164535:tid 164769] [client 188.166.209.66:60261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-plugin-dependencies.php"] [unique_id "al4kEzYN371eKRzcKeRl1AAAAO0"], referer: binance.com
[Mon Jul 20 07:35:15.283807 2026] [security2:error] [pid 164535:tid 164757] [client 14.225.17.146:57968] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4kEzYN371eKRzcKeRlzgAAAOE"], referer: https://39ishlife.com/demo
[Mon Jul 20 07:35:15.395042 2026] [security2:error] [pid 164535:tid 164617] [remote 124.55.178.99:59394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kEzYN371eKRzcKeRl4QAAmFE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:35:15.398114 2026] [security2:error] [pid 164535:tid 164570] [remote 217.61.143.92:36206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kEzYN371eKRzcKeRl4gAA2iI"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:35:15.422248 2026] [security2:error] [pid 164535:tid 164698] [client 103.139.191.61:51694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kEzYN371eKRzcKeRl4wAAAKY"]
[Mon Jul 20 07:35:15.422613 2026] [security2:error] [pid 164535:tid 164698] [client 103.139.191.61:51694] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kEzYN371eKRzcKeRl4wAAAKY"]
[Mon Jul 20 07:35:15.468068 2026] [security2:error] [pid 164535:tid 164777] [client 180.249.173.210:49596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kEzYN371eKRzcKeRl5gAAAPU"]
[Mon Jul 20 07:35:15.468315 2026] [security2:error] [pid 164535:tid 164777] [client 180.249.173.210:49596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kEzYN371eKRzcKeRl5gAAAPU"]
[Mon Jul 20 07:35:15.687911 2026] [security2:error] [pid 164535:tid 164766] [client 114.119.143.174:63835] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "asliceofleadership.com"] [uri "/ultimatesuccessplanner/images/35/"] [unique_id "al4kEzYN371eKRzcKeRmAQAAAOo"], referer: https://asliceofleadership.com/ultimatesuccessplanner/images/35/
[Mon Jul 20 07:35:15.785949 2026] [security2:error] [pid 164535:tid 164702] [client 57.141.18.20:47026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kEzYN371eKRzcKeRlzQAAqj4"]
[Mon Jul 20 07:35:15.815948 2026] [security2:error] [pid 164535:tid 164764] [client 14.225.17.146:58062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4kEzYN371eKRzcKeRl7QAAAOg"], referer: https://guidehunting.com/demo
[Mon Jul 20 07:35:15.849004 2026] [security2:error] [pid 164535:tid 164784] [client 14.225.17.146:57959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4kEjYN371eKRzcKeRlaAAAAPw"], referer: http://ksands.co.uk/demo
[Mon Jul 20 07:35:16.273529 2026] [security2:error] [pid 164535:tid 164746] [client 104.234.53.51:47949] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kFDYN371eKRzcKeRmLgAAANY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:16.359297 2026] [security2:error] [pid 164535:tid 164768] [client 57.141.18.3:31260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kEzYN371eKRzcKeRl_wAA7E8"]
[Mon Jul 20 07:35:16.679479 2026] [security2:error] [pid 164535:tid 164734] [client 57.141.18.69:22424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kEzYN371eKRzcKeRmCwAAyi4"]
[Mon Jul 20 07:35:17.131829 2026] [security2:error] [pid 164535:tid 164755] [client 140.245.46.64:50774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kFTYN371eKRzcKeRmdgAAAN8"]
[Mon Jul 20 07:35:17.227657 2026] [security2:error] [pid 164535:tid 164728] [client 14.225.17.146:55230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4kFTYN371eKRzcKeRmbAAAAMQ"], referer: http://lifeisbetterlakeside.com/demo
[Mon Jul 20 07:35:17.234949 2026] [security2:error] [pid 164535:tid 164716] [client 45.157.112.60:40215] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kFTYN371eKRzcKeRmfgAAALg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:35:17.261655 2026] [security2:error] [pid 164535:tid 164693] [client 14.225.17.146:49235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4kEzYN371eKRzcKeRl6wAAAKE"], referer: http://windowtx.com/demo
[Mon Jul 20 07:35:17.552006 2026] [security2:error] [pid 164535:tid 164745] [client 49.47.218.174:52224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmlAAAANU"]
[Mon Jul 20 07:35:17.552123 2026] [security2:error] [pid 164535:tid 164745] [client 49.47.218.174:52224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmlAAAANU"]
[Mon Jul 20 07:35:17.600033 2026] [security2:error] [pid 164535:tid 164737] [client 149.0.16.108:58059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmlwAAAM0"]
[Mon Jul 20 07:35:17.600115 2026] [security2:error] [pid 164535:tid 164737] [client 149.0.16.108:58059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmlwAAAM0"]
[Mon Jul 20 07:35:17.802432 2026] [security2:error] [pid 164535:tid 164782] [client 57.141.18.55:63358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kFTYN371eKRzcKeRmcAAA-nA"]
[Mon Jul 20 07:35:17.825337 2026] [security2:error] [pid 164535:tid 164621] [remote 152.228.213.32:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4kFTYN371eKRzcKeRmqAAA41U"]
[Mon Jul 20 07:35:17.835500 2026] [security2:error] [pid 164535:tid 164775] [client 157.20.138.62:54195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmqgAAAPM"]
[Mon Jul 20 07:35:17.835603 2026] [security2:error] [pid 164535:tid 164775] [client 157.20.138.62:54195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmqgAAAPM"]
[Mon Jul 20 07:35:17.869739 2026] [security2:error] [pid 164535:tid 164712] [client 142.111.152.168:58523] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kFTYN371eKRzcKeRmnwAAALQ"]
[Mon Jul 20 07:35:18.020766 2026] [security2:error] [pid 164535:tid 164738] [client 216.244.66.233:43582] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toddnielsen.com"] [uri "/robots.txt"] [unique_id "al4kFjYN371eKRzcKeRmwgAAAM4"]
[Mon Jul 20 07:35:18.020864 2026] [security2:error] [pid 164535:tid 164738] [client 216.244.66.233:43582] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "toddnielsen.com"] [uri "/robots.txt"] [unique_id "al4kFjYN371eKRzcKeRmwgAAAM4"]
[Mon Jul 20 07:35:18.021518 2026] [security2:error] [pid 164535:tid 164587] [remote 152.228.213.32:37456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4kFjYN371eKRzcKeRmwAAAxTM"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:35:18.145863 2026] [security2:error] [pid 164535:tid 164745] [client 188.166.209.66:60506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-script-modules.php"] [unique_id "al4kFjYN371eKRzcKeRmxgAAANU"], referer: binance.com
[Mon Jul 20 07:35:18.468340 2026] [security2:error] [pid 164535:tid 164554] [remote 42.200.84.61:57158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4kFjYN371eKRzcKeRm7QAA-RI"]
[Mon Jul 20 07:35:18.502430 2026] [security2:error] [pid 164535:tid 164755] [client 57.141.18.73:50140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kFTYN371eKRzcKeRmrAAA33c"]
[Mon Jul 20 07:35:18.577018 2026] [security2:error] [pid 164535:tid 164735] [client 57.141.18.91:46484] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kFTYN371eKRzcKeRmtwAAywM"]
[Mon Jul 20 07:35:18.796402 2026] [security2:error] [pid 164535:tid 164756] [client 216.73.216.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4kFjYN371eKRzcKeRnAQAAAOA"]
[Mon Jul 20 07:35:18.812431 2026] [security2:error] [pid 164535:tid 164634] [remote 42.200.84.61:57158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nomorewetsheets.net"] [uri "/wp-login.php"] [unique_id "al4kFjYN371eKRzcKeRnBwAA82I"], referer: https://nomorewetsheets.net/wp-login.php
[Mon Jul 20 07:35:18.827254 2026] [security2:error] [pid 164535:tid 164697] [client 57.141.18.81:62444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kFjYN371eKRzcKeRmyQAApUw"]
[Mon Jul 20 07:35:18.863170 2026] [security2:error] [pid 164535:tid 164789] [client 47.128.55.175:12696] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "nandansonscharitablefoundation.com"] [uri "/robots.txt"] [unique_id "al4kFjYN371eKRzcKeRnDgAAAQE"]
[Mon Jul 20 07:35:18.961599 2026] [security2:error] [pid 164535:tid 164783] [client 140.245.46.64:51808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kFjYN371eKRzcKeRnFgAAAPs"]
[Mon Jul 20 07:35:19.103322 2026] [security2:error] [pid 164535:tid 164778] [client 14.225.17.146:56227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4kFTYN371eKRzcKeRmoQAAAPY"], referer: http://scott-assist.com/demo
[Mon Jul 20 07:35:19.322091 2026] [security2:error] [pid 164535:tid 164701] [client 139.59.118.64:59473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4kFzYN371eKRzcKeRnLAAAAKk"], referer: https://www.facebook.com/
[Mon Jul 20 07:35:19.538719 2026] [security2:error] [pid 164535:tid 164694] [client 140.245.46.64:52148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4kFzYN371eKRzcKeRnRwAAAKI"]
[Mon Jul 20 07:35:19.674420 2026] [security2:error] [pid 164535:tid 164764] [client 202.141.11.99:58299] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kFzYN371eKRzcKeRnTAAAAOg"]
[Mon Jul 20 07:35:19.674548 2026] [security2:error] [pid 164535:tid 164764] [client 202.141.11.99:58299] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kFzYN371eKRzcKeRnTAAAAOg"]
[Mon Jul 20 07:35:19.695441 2026] [security2:error] [pid 164535:tid 164779] [client 154.192.123.127:17988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kFzYN371eKRzcKeRnTgAAAPc"]
[Mon Jul 20 07:35:19.695560 2026] [security2:error] [pid 164535:tid 164779] [client 154.192.123.127:17988] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kFzYN371eKRzcKeRnTgAAAPc"]
[Mon Jul 20 07:35:19.702446 2026] [security2:error] [pid 164535:tid 164697] [client 36.93.152.155:62981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kFzYN371eKRzcKeRnTwAAAKU"]
[Mon Jul 20 07:35:19.702523 2026] [security2:error] [pid 164535:tid 164697] [client 36.93.152.155:62981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kFzYN371eKRzcKeRnTwAAAKU"]
[Mon Jul 20 07:35:20.110055 2026] [security2:error] [pid 164535:tid 164747] [client 140.245.46.64:52483] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-admin/load-styles.php"] [unique_id "al4kGDYN371eKRzcKeRncwAAANc"]
[Mon Jul 20 07:35:20.164262 2026] [security2:error] [pid 164535:tid 164739] [client 57.141.18.86:35700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kFzYN371eKRzcKeRnNAAAzzY"]
[Mon Jul 20 07:35:20.573703 2026] [security2:error] [pid 164535:tid 164676] [client 136.158.60.21:46114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kGDYN371eKRzcKeRnmAAAAJA"]
[Mon Jul 20 07:35:20.573903 2026] [security2:error] [pid 164535:tid 164676] [client 136.158.60.21:46114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kGDYN371eKRzcKeRnmAAAAJA"]
[Mon Jul 20 07:35:20.574965 2026] [security2:error] [pid 164535:tid 164695] [client 57.141.18.91:46500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kFzYN371eKRzcKeRnVAAAoz4"]
[Mon Jul 20 07:35:20.660969 2026] [security2:error] [pid 164535:tid 164720] [client 14.225.17.146:63492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4kFjYN371eKRzcKeRnGAAAALw"], referer: http://swafforddetailing.com/demo
[Mon Jul 20 07:35:20.698782 2026] [security2:error] [pid 164535:tid 164702] [client 103.106.165.44:52025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kGDYN371eKRzcKeRnogAAAKo"]
[Mon Jul 20 07:35:20.699016 2026] [security2:error] [pid 164535:tid 164702] [client 103.106.165.44:52025] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kGDYN371eKRzcKeRnogAAAKo"]
[Mon Jul 20 07:35:20.701942 2026] [security2:error] [pid 164535:tid 164588] [remote 188.166.241.141:42054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kGDYN371eKRzcKeRnowAAnDQ"]
[Mon Jul 20 07:35:20.702067 2026] [security2:error] [pid 164535:tid 164688] [client 188.166.241.141:42054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kGDYN371eKRzcKeRnowAAnDQ"]
[Mon Jul 20 07:35:21.083229 2026] [security2:error] [pid 164535:tid 164686] [client 104.234.53.62:31241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kGTYN371eKRzcKeRnwAAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:21.278076 2026] [security2:error] [pid 164535:tid 164769] [client 57.141.18.77:30814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kGDYN371eKRzcKeRnkQAA7TA"]
[Mon Jul 20 07:35:21.326434 2026] [security2:error] [pid 164535:tid 164789] [client 191.202.66.27:65488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kGTYN371eKRzcKeRn0gAAAQE"]
[Mon Jul 20 07:35:21.326569 2026] [security2:error] [pid 164535:tid 164789] [client 191.202.66.27:65488] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kGTYN371eKRzcKeRn0gAAAQE"]
[Mon Jul 20 07:35:21.411500 2026] [security2:error] [pid 164535:tid 164723] [client 179.127.84.238:52195] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kGTYN371eKRzcKeRn3AAAAL8"]
[Mon Jul 20 07:35:21.411612 2026] [security2:error] [pid 164535:tid 164723] [client 179.127.84.238:52195] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kGTYN371eKRzcKeRn3AAAAL8"]
[Mon Jul 20 07:35:21.660648 2026] [security2:error] [pid 164535:tid 164751] [client 52.167.144.143:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kGTYN371eKRzcKeRn3QAA228"]
[Mon Jul 20 07:35:22.040160 2026] [security2:error] [pid 164535:tid 164674] [client 35.245.166.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "zsz.xdx.mybluehost.me"] [uri "/index.php"] [unique_id "al4kGTYN371eKRzcKeRoAwAAAI4"]
[Mon Jul 20 07:35:22.073532 2026] [security2:error] [pid 164535:tid 164695] [client 188.166.24.87:53929] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.omegacompass.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4kGTYN371eKRzcKeRoDQAAAKM"]
[Mon Jul 20 07:35:22.138403 2026] [security2:error] [pid 164535:tid 164719] [client 35.245.166.159:54690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.166.245.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zsz.xdx.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kGjYN371eKRzcKeRoFQAAALs"]
[Mon Jul 20 07:35:22.286636 2026] [security2:error] [pid 164535:tid 164665] [client 66.249.65.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.flowmeterfactory.com"] [uri "/index.php"] [unique_id "al4kFjYN371eKRzcKeRnAwAAAIU"]
[Mon Jul 20 07:35:22.513252 2026] [security2:error] [pid 164535:tid 164742] [client 103.176.215.66:56864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kGjYN371eKRzcKeRoNgAAANI"]
[Mon Jul 20 07:35:22.513396 2026] [security2:error] [pid 164535:tid 164742] [client 103.176.215.66:56864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kGjYN371eKRzcKeRoNgAAANI"]
[Mon Jul 20 07:35:22.528617 2026] [security2:error] [pid 164535:tid 164791] [client 57.141.18.108:24954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kGTYN371eKRzcKeRn9QABA3A"]
[Mon Jul 20 07:35:22.560682 2026] [security2:error] [pid 164535:tid 164659] [remote 5.252.52.249:59644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4kGjYN371eKRzcKeRoQgAAzXs"]
[Mon Jul 20 07:35:22.687307 2026] [security2:error] [pid 164535:tid 164684] [client 14.225.17.146:57479] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4kGjYN371eKRzcKeRoMQAAAJg"], referer: http://ccsdifference.com/demo
[Mon Jul 20 07:35:22.708126 2026] [security2:error] [pid 164535:tid 164559] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kGjYN371eKRzcKeRoSwAA9Bc"]
[Mon Jul 20 07:35:22.708286 2026] [security2:error] [pid 164535:tid 164776] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kGjYN371eKRzcKeRoSwAA9Bc"]
[Mon Jul 20 07:35:22.744309 2026] [security2:error] [pid 164535:tid 164576] [remote 5.252.52.249:59644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4kGjYN371eKRzcKeRoTgAAiCg"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 07:35:22.747552 2026] [security2:error] [pid 164535:tid 164674] [client 35.245.166.159:53948] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4kGjYN371eKRzcKeRoUAAAAI4"]
[Mon Jul 20 07:35:22.960369 2026] [security2:error] [pid 164535:tid 164781] [client 46.110.96.34:25423] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4kGjYN371eKRzcKeRoYAAAAPk"]
[Mon Jul 20 07:35:23.144973 2026] [security2:error] [pid 164535:tid 164669] [client 140.245.46.64:54203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-includes/version.php"] [unique_id "al4kGzYN371eKRzcKeRodQAAAIk"]
[Mon Jul 20 07:35:23.201443 2026] [security2:error] [pid 164535:tid 164772] [client 14.225.17.146:64454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4kGTYN371eKRzcKeRoCAAAAPA"], referer: http://effingweirdmuseums.com/demo
[Mon Jul 20 07:35:23.203261 2026] [security2:error] [pid 164535:tid 164727] [client 57.141.18.7:45270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kGjYN371eKRzcKeRoIgAAw2U"]
[Mon Jul 20 07:35:23.287889 2026] [security2:error] [pid 164535:tid 164704] [client 14.225.17.146:57366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4kGzYN371eKRzcKeRofQAAAKw"], referer: http://mourgroup.com/demo
[Mon Jul 20 07:35:23.365630 2026] [security2:error] [pid 164535:tid 164716] [client 188.166.209.66:51590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-scripts.php"] [unique_id "al4kGzYN371eKRzcKeRogQAAALg"], referer: binance.com
[Mon Jul 20 07:35:23.397415 2026] [security2:error] [pid 164535:tid 164710] [client 35.245.166.159:50761] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4kGzYN371eKRzcKeRoggAAALI"]
[Mon Jul 20 07:35:23.581940 2026] [security2:error] [pid 164535:tid 164762] [client 104.234.53.47:46863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kGzYN371eKRzcKeRojwAAAOY"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:23.685260 2026] [security2:error] [pid 164535:tid 164665] [client 14.225.17.146:57440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4kGzYN371eKRzcKeRoiQAAAIU"], referer: https://ccsdifference.com/demo
[Mon Jul 20 07:35:23.696836 2026] [security2:error] [pid 164535:tid 164764] [client 143.44.185.218:50412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kGzYN371eKRzcKeRomgAAAOg"]
[Mon Jul 20 07:35:23.696948 2026] [security2:error] [pid 164535:tid 164764] [client 143.44.185.218:50412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kGzYN371eKRzcKeRomgAAAOg"]
[Mon Jul 20 07:35:23.698417 2026] [security2:error] [pid 164535:tid 164676] [client 14.174.224.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4kGzYN371eKRzcKeRocQAAAJA"]
[Mon Jul 20 07:35:23.719548 2026] [security2:error] [pid 164535:tid 164724] [client 140.245.46.64:54581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-includes/functions.php"] [unique_id "al4kGzYN371eKRzcKeRonAAAAMA"]
[Mon Jul 20 07:35:23.920423 2026] [security2:error] [pid 164535:tid 164737] [client 35.245.166.159:61672] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4kGzYN371eKRzcKeRoowAAAM0"]
[Mon Jul 20 07:35:24.160080 2026] [security2:error] [pid 164535:tid 164776] [client 136.144.33.204:53667] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4kHDYN371eKRzcKeRovQAAAPQ"]
[Mon Jul 20 07:35:24.162052 2026] [security2:error] [pid 164535:tid 164701] [client 14.225.17.146:54175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4kHDYN371eKRzcKeRotAAAAKk"], referer: https://effingweirdmuseums.com/demo
[Mon Jul 20 07:35:24.169862 2026] [security2:error] [pid 164535:tid 164666] [client 58.160.88.159:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4kGjYN371eKRzcKeRoWQAAAIY"], referer: https://aosta.nz/
[Mon Jul 20 07:35:24.197727 2026] [security2:error] [pid 164535:tid 164684] [client 193.36.225.8:20035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4kHDYN371eKRzcKeRovgAAAJg"]
[Mon Jul 20 07:35:24.295855 2026] [security2:error] [pid 164535:tid 164680] [client 140.245.46.64:54933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-includes/class-wp.php"] [unique_id "al4kHDYN371eKRzcKeRoxgAAAJQ"]
[Mon Jul 20 07:35:24.369588 2026] [security2:error] [pid 164535:tid 164686] [client 117.211.236.168:49472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kHDYN371eKRzcKeRoyAAAAJo"]
[Mon Jul 20 07:35:24.369709 2026] [security2:error] [pid 164535:tid 164686] [client 117.211.236.168:49472] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kHDYN371eKRzcKeRoyAAAAJo"]
[Mon Jul 20 07:35:24.437282 2026] [security2:error] [pid 164535:tid 164687] [client 35.245.166.159:51706] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4kHDYN371eKRzcKeRoygAAAJs"]
[Mon Jul 20 07:35:24.517251 2026] [security2:error] [pid 164535:tid 164730] [client 57.141.18.97:57804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kGzYN371eKRzcKeRojQAAxlc"]
[Mon Jul 20 07:35:24.742994 2026] [security2:error] [pid 164535:tid 164701] [client 35.245.166.159:54172] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4kHDYN371eKRzcKeRo-wAAAKk"]
[Mon Jul 20 07:35:24.868370 2026] [security2:error] [pid 164535:tid 164760] [client 140.245.46.64:55257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-includes/option.php"] [unique_id "al4kHDYN371eKRzcKeRpAgAAAOQ"]
[Mon Jul 20 07:35:24.984529 2026] [security2:error] [pid 164535:tid 164703] [client 57.141.18.9:32126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHDYN371eKRzcKeRosAAAq3Y"]
[Mon Jul 20 07:35:25.077144 2026] [security2:error] [pid 164535:tid 164711] [client 188.166.209.66:63694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-speculation-rules.php"] [unique_id "al4kHTYN371eKRzcKeRpFgAAALM"], referer: binance.com
[Mon Jul 20 07:35:25.188868 2026] [security2:error] [pid 164535:tid 164761] [client 35.245.166.159:56718] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4kHTYN371eKRzcKeRpIgAAAOU"]
[Mon Jul 20 07:35:25.317978 2026] [security2:error] [pid 164535:tid 164750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kHDYN371eKRzcKeRo1wAAANo"], referer: 1'"3000
[Mon Jul 20 07:35:25.441471 2026] [security2:error] [pid 164535:tid 164700] [client 140.245.46.64:55560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-includes/post.php"] [unique_id "al4kHTYN371eKRzcKeRpLAAAAKg"]
[Mon Jul 20 07:35:25.513509 2026] [security2:error] [pid 164535:tid 164738] [client 46.110.96.34:60709] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kHTYN371eKRzcKeRpLwAAAM4"]
[Mon Jul 20 07:35:25.550866 2026] [security2:error] [pid 164535:tid 164730] [client 46.110.96.34:38053] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kHTYN371eKRzcKeRpNwAAAMY"]
[Mon Jul 20 07:35:25.639285 2026] [security2:error] [pid 164535:tid 164714] [client 14.225.17.146:64350] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4kHDYN371eKRzcKeRowwAAALY"], referer: http://dnsplumbing.com/demo
[Mon Jul 20 07:35:25.721583 2026] [security2:error] [pid 164535:tid 164768] [client 35.245.166.159:50438] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4kHTYN371eKRzcKeRpTwAAAOw"]
[Mon Jul 20 07:35:25.856456 2026] [security2:error] [pid 164535:tid 164727] [client 14.225.17.146:57392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4kHTYN371eKRzcKeRpRwAAAMM"], referer: http://mobilesurvsolutions.com/demo
[Mon Jul 20 07:35:25.899933 2026] [security2:error] [pid 164535:tid 164697] [client 104.207.53.49:36523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kHTYN371eKRzcKeRpXAAAAKU"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:26.033815 2026] [security2:error] [pid 164535:tid 164774] [client 140.245.46.64:55884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-includes/user.php"] [unique_id "al4kHjYN371eKRzcKeRpcAAAAPI"]
[Mon Jul 20 07:35:26.074949 2026] [security2:error] [pid 164535:tid 164671] [client 57.141.18.61:35634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHDYN371eKRzcKeRpAQAAi0c"]
[Mon Jul 20 07:35:26.089083 2026] [security2:error] [pid 164535:tid 164621] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4kHjYN371eKRzcKeRpcgAA91U"]
[Mon Jul 20 07:35:26.148308 2026] [security2:error] [pid 164535:tid 164761] [client 112.86.225.111:37746] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/"] [unique_id "al4kHjYN371eKRzcKeRpdgAAAOU"]
[Mon Jul 20 07:35:26.148466 2026] [security2:error] [pid 164535:tid 164761] [client 112.86.225.111:37746] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.liquidationteam.com"] [uri "/"] [unique_id "al4kHjYN371eKRzcKeRpdgAAAOU"]
[Mon Jul 20 07:35:26.312783 2026] [security2:error] [pid 164535:tid 164791] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kHjYN371eKRzcKeRpbwAAAQM"], referer: 1'"3000
[Mon Jul 20 07:35:26.314230 2026] [security2:error] [pid 164535:tid 164790] [client 49.37.242.14:58478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kHjYN371eKRzcKeRpgQAAAQI"]
[Mon Jul 20 07:35:26.314337 2026] [security2:error] [pid 164535:tid 164790] [client 49.37.242.14:58478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kHjYN371eKRzcKeRpgQAAAQI"]
[Mon Jul 20 07:35:26.316565 2026] [security2:error] [pid 164535:tid 164698] [client 180.249.173.210:50061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kHjYN371eKRzcKeRpgwAAAKY"]
[Mon Jul 20 07:35:26.317425 2026] [security2:error] [pid 164535:tid 164698] [client 180.249.173.210:50061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kHjYN371eKRzcKeRpgwAAAKY"]
[Mon Jul 20 07:35:26.465295 2026] [security2:error] [pid 164535:tid 164765] [client 103.139.191.61:52174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kHjYN371eKRzcKeRpjgAAAOk"]
[Mon Jul 20 07:35:26.465406 2026] [security2:error] [pid 164535:tid 164765] [client 103.139.191.61:52174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kHjYN371eKRzcKeRpjgAAAOk"]
[Mon Jul 20 07:35:26.529654 2026] [security2:error] [pid 164535:tid 164611] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4kHjYN371eKRzcKeRpkgAAxks"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 07:35:26.605519 2026] [security2:error] [pid 164535:tid 164769] [client 35.245.166.159:54216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4kHjYN371eKRzcKeRpngAAAO0"]
[Mon Jul 20 07:35:26.745321 2026] [security2:error] [pid 164535:tid 164755] [client 57.141.18.123:31444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHTYN371eKRzcKeRpNQAA3zA"]
[Mon Jul 20 07:35:26.764704 2026] [security2:error] [pid 164535:tid 164689] [client 104.234.53.68:57245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kHjYN371eKRzcKeRprAAAAJ0"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:27.009255 2026] [security2:error] [pid 164535:tid 164778] [client 14.225.17.146:53389] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4kHjYN371eKRzcKeRpswAAAPY"]
[Mon Jul 20 07:35:27.021179 2026] [security2:error] [pid 164535:tid 164759] [client 188.166.209.66:51742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-styles.php"] [unique_id "al4kHzYN371eKRzcKeRpxwAAAOM"], referer: binance.com
[Mon Jul 20 07:35:27.080115 2026] [security2:error] [pid 164535:tid 164753] [client 35.245.166.159:58748] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4kHzYN371eKRzcKeRpzAAAAN0"]
[Mon Jul 20 07:35:27.124251 2026] [security2:error] [pid 164535:tid 164691] [client 57.141.18.51:20436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHTYN371eKRzcKeRpZQAAn28"]
[Mon Jul 20 07:35:27.287201 2026] [security2:error] [pid 164535:tid 164770] [client 158.173.89.95:31157] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kHzYN371eKRzcKeRp4gAAAO4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:35:27.320676 2026] [security2:error] [pid 164535:tid 164750] [client 104.207.53.148:11087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kHzYN371eKRzcKeRp4wAAANo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:27.447740 2026] [security2:error] [pid 164535:tid 164674] [client 14.225.17.146:50515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4kHzYN371eKRzcKeRp6AAAAI4"], referer: http://expertcultures.com/demo
[Mon Jul 20 07:35:27.540331 2026] [security2:error] [pid 164535:tid 164752] [client 66.249.73.164:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.whiteoutcb.com"] [uri "/index.php"] [unique_id "al4kHzYN371eKRzcKeRp8QAAANw"]
[Mon Jul 20 07:35:27.572187 2026] [security2:error] [pid 164535:tid 164791] [client 35.245.166.159:61639] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4kHzYN371eKRzcKeRqBAAAAQM"]
[Mon Jul 20 07:35:27.661141 2026] [security2:error] [pid 164535:tid 164776] [client 54.158.124.211:11252] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.124.158.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4kHzYN371eKRzcKeRqBQAAAPQ"]
[Mon Jul 20 07:35:27.661254 2026] [security2:error] [pid 164535:tid 164776] [client 54.158.124.211:11252] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4kHzYN371eKRzcKeRqBQAAAPQ"]
[Mon Jul 20 07:35:27.697684 2026] [security2:error] [pid 164535:tid 164779] [client 57.141.18.27:26980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHjYN371eKRzcKeRpnAAA92c"]
[Mon Jul 20 07:35:27.795726 2026] [security2:error] [pid 164535:tid 164697] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kHzYN371eKRzcKeRp9QAAAKU"], referer: 1'"3000
[Mon Jul 20 07:35:27.879277 2026] [security2:error] [pid 164535:tid 164784] [client 57.141.18.109:36390] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHjYN371eKRzcKeRppwAA_Hc"]
[Mon Jul 20 07:35:27.933836 2026] [security2:error] [pid 164535:tid 164713] [client 57.141.18.26:58262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHjYN371eKRzcKeRpuAAAtRg"]
[Mon Jul 20 07:35:27.968837 2026] [security2:error] [pid 164535:tid 164680] [client 57.141.18.102:39416] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHjYN371eKRzcKeRpuwAAlCQ"]
[Mon Jul 20 07:35:27.986235 2026] [core:error] [pid 164535:tid 164686] [client 139.59.118.64:54826] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:35:27.986253 2026] [core:error] [pid 164535:tid 164686] [client 139.59.118.64:54826] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:35:27.997359 2026] [security2:error] [pid 164535:tid 164681] [client 49.47.218.174:52770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kHzYN371eKRzcKeRqJwAAAJU"]
[Mon Jul 20 07:35:27.997476 2026] [security2:error] [pid 164535:tid 164681] [client 49.47.218.174:52770] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kHzYN371eKRzcKeRqJwAAAJU"]
[Mon Jul 20 07:35:28.197136 2026] [security2:error] [pid 164535:tid 164776] [client 149.0.16.108:58561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kIDYN371eKRzcKeRqNgAAAPQ"]
[Mon Jul 20 07:35:28.197232 2026] [security2:error] [pid 164535:tid 164776] [client 149.0.16.108:58561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kIDYN371eKRzcKeRqNgAAAPQ"]
[Mon Jul 20 07:35:28.246992 2026] [security2:error] [pid 164535:tid 164708] [client 35.245.166.159:63993] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4kIDYN371eKRzcKeRqOgAAALA"]
[Mon Jul 20 07:35:28.424643 2026] [security2:error] [pid 164535:tid 164745] [client 57.141.18.55:28142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHzYN371eKRzcKeRp7AAA1Tc"]
[Mon Jul 20 07:35:28.472495 2026] [security2:error] [pid 164535:tid 164682] [client 155.2.215.87:24161] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kIDYN371eKRzcKeRqRwAAAJY"]
[Mon Jul 20 07:35:28.478744 2026] [security2:error] [pid 164535:tid 164760] [client 157.20.138.62:54761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kIDYN371eKRzcKeRqWgAAAOQ"]
[Mon Jul 20 07:35:28.478874 2026] [security2:error] [pid 164535:tid 164760] [client 157.20.138.62:54761] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kIDYN371eKRzcKeRqWgAAAOQ"]
[Mon Jul 20 07:35:28.533826 2026] [security2:error] [pid 164535:tid 164746] [client 14.225.17.146:50651] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4kIDYN371eKRzcKeRqSAAAANY"], referer: http://samdothan.org/demo
[Mon Jul 20 07:35:28.594710 2026] [security2:error] [pid 164535:tid 164608] [remote 202.51.202.242:35182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4kIDYN371eKRzcKeRqZAAAzUg"]
[Mon Jul 20 07:35:28.606078 2026] [security2:error] [pid 164535:tid 164727] [client 35.245.166.159:53000] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "zsz.xdx.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4kIDYN371eKRzcKeRqZgAAAMM"]
[Mon Jul 20 07:35:28.781281 2026] [security2:error] [pid 164535:tid 164768] [client 65.111.23.158:46419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 158.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kIDYN371eKRzcKeRqdQAAAOw"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:28.810594 2026] [security2:error] [pid 164535:tid 164765] [client 14.225.17.146:62111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4kHzYN371eKRzcKeRqEQAAAOk"], referer: http://grndl.com/demo
[Mon Jul 20 07:35:29.053414 2026] [security2:error] [pid 164535:tid 164666] [client 14.225.17.146:57530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4kIDYN371eKRzcKeRqiwAAAIY"]
[Mon Jul 20 07:35:29.091269 2026] [security2:error] [pid 164535:tid 164677] [client 57.141.18.69:35906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kHzYN371eKRzcKeRqHQAAkRk"]
[Mon Jul 20 07:35:29.328162 2026] [security2:error] [pid 164535:tid 164784] [client 46.110.96.34:42514] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kITYN371eKRzcKeRqtwAAAPw"]
[Mon Jul 20 07:35:29.839517 2026] [security2:error] [pid 164535:tid 164746] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4kITYN371eKRzcKeRqjwAAANY"]
[Mon Jul 20 07:35:29.981115 2026] [security2:error] [pid 164535:tid 164754] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kITYN371eKRzcKeRq5AAAAN4"], referer: 1'"3000
[Mon Jul 20 07:35:30.084052 2026] [security2:error] [pid 164535:tid 164780] [client 158.173.166.181:63727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kIjYN371eKRzcKeRrBgAAAPg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:35:30.112706 2026] [security2:error] [pid 164535:tid 164699] [client 74.208.214.194:47028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4kIjYN371eKRzcKeRrDgAAAKc"]
[Mon Jul 20 07:35:30.197539 2026] [security2:error] [pid 164535:tid 164778] [client 154.192.123.127:18532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kIjYN371eKRzcKeRrEQAAAPY"]
[Mon Jul 20 07:35:30.197664 2026] [security2:error] [pid 164535:tid 164778] [client 154.192.123.127:18532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kIjYN371eKRzcKeRrEQAAAPY"]
[Mon Jul 20 07:35:30.232293 2026] [security2:error] [pid 164535:tid 164759] [client 36.93.152.155:63495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kIjYN371eKRzcKeRrEwAAAOM"]
[Mon Jul 20 07:35:30.232401 2026] [security2:error] [pid 164535:tid 164759] [client 36.93.152.155:63495] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kIjYN371eKRzcKeRrEwAAAOM"]
[Mon Jul 20 07:35:30.237490 2026] [security2:error] [pid 164535:tid 164719] [client 65.111.23.227:62935] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kIjYN371eKRzcKeRrEgAAALs"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:30.336002 2026] [security2:error] [pid 164535:tid 164727] [client 144.16.21.149:25253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 149.21.16.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kIjYN371eKRzcKeRrHAAAAMM"]
[Mon Jul 20 07:35:30.336213 2026] [security2:error] [pid 164535:tid 164727] [client 144.16.21.149:25253] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kIjYN371eKRzcKeRrHAAAAMM"]
[Mon Jul 20 07:35:30.663237 2026] [security2:error] [pid 164535:tid 164767] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "littleaosta.nz"] [uri "/index.php"] [unique_id "al4kIjYN371eKRzcKeRrJgAAAOs"]
[Mon Jul 20 07:35:30.884558 2026] [security2:error] [pid 164535:tid 164670] [client 104.234.53.64:39675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kIjYN371eKRzcKeRrTwAAAIo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:31.009174 2026] [security2:error] [pid 164535:tid 164775] [client 193.36.225.93:50697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4kIjYN371eKRzcKeRrWgAAAPM"]
[Mon Jul 20 07:35:31.115955 2026] [security2:error] [pid 164535:tid 164673] [client 50.116.65.227:58788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kIzYN371eKRzcKeRrYgAAAI0"]
[Mon Jul 20 07:35:31.124949 2026] [security2:error] [pid 164535:tid 164734] [client 50.116.65.227:58800] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kIzYN371eKRzcKeRrZAAAAMo"]
[Mon Jul 20 07:35:31.271703 2026] [security2:error] [pid 164535:tid 164759] [client 103.106.165.44:52514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kIzYN371eKRzcKeRrbgAAAOM"]
[Mon Jul 20 07:35:31.271821 2026] [security2:error] [pid 164535:tid 164759] [client 103.106.165.44:52514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kIzYN371eKRzcKeRrbgAAAOM"]
[Mon Jul 20 07:35:31.336871 2026] [security2:error] [pid 164535:tid 164747] [client 14.225.17.146:57545] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4kITYN371eKRzcKeRqtQAAANc"], referer: http://floorsourcestock.com/demo
[Mon Jul 20 07:35:31.367791 2026] [security2:error] [pid 164535:tid 164676] [client 136.158.60.21:47638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kIzYN371eKRzcKeRregAAAJA"]
[Mon Jul 20 07:35:31.367925 2026] [security2:error] [pid 164535:tid 164676] [client 136.158.60.21:47638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kIzYN371eKRzcKeRregAAAJA"]
[Mon Jul 20 07:35:31.586431 2026] [security2:error] [pid 164535:tid 164789] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kIzYN371eKRzcKeRreQAAAQE"], referer: 1'"3000
[Mon Jul 20 07:35:31.707855 2026] [security2:error] [pid 164535:tid 164707] [client 65.111.23.194:46291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kIzYN371eKRzcKeRrogAAAK8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:31.876936 2026] [security2:error] [pid 164535:tid 164694] [client 50.116.65.227:50618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4kIzYN371eKRzcKeRrqQAAAKI"]
[Mon Jul 20 07:35:32.000806 2026] [security2:error] [pid 164535:tid 164748] [client 191.202.66.27:49613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kJDYN371eKRzcKeRrugAAANg"]
[Mon Jul 20 07:35:32.000911 2026] [security2:error] [pid 164535:tid 164748] [client 191.202.66.27:49613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kJDYN371eKRzcKeRrugAAANg"]
[Mon Jul 20 07:35:32.063162 2026] [security2:error] [pid 164535:tid 164730] [client 179.127.84.238:52728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kJDYN371eKRzcKeRryAAAAMY"]
[Mon Jul 20 07:35:32.063297 2026] [security2:error] [pid 164535:tid 164730] [client 179.127.84.238:52728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kJDYN371eKRzcKeRryAAAAMY"]
[Mon Jul 20 07:35:32.623545 2026] [security2:error] [pid 164535:tid 164695] [client 57.141.18.96:54946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kIzYN371eKRzcKeRrZgAAo1E"]
[Mon Jul 20 07:35:33.133264 2026] [security2:error] [pid 164535:tid 164712] [client 104.207.50.0:56677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kJTYN371eKRzcKeRsFwAAALQ"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:33.176844 2026] [security2:error] [pid 164535:tid 164731] [client 103.176.215.66:57474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kJTYN371eKRzcKeRsGQAAAMc"]
[Mon Jul 20 07:35:33.176998 2026] [security2:error] [pid 164535:tid 164731] [client 103.176.215.66:57474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kJTYN371eKRzcKeRsGQAAAMc"]
[Mon Jul 20 07:35:33.239245 2026] [security2:error] [pid 164535:tid 164689] [client 57.141.18.82:37866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kIzYN371eKRzcKeRroAAAnWA"]
[Mon Jul 20 07:35:33.506041 2026] [security2:error] [pid 164535:tid 164680] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kJTYN371eKRzcKeRsIQAAAJQ"], referer: 1'"3000
[Mon Jul 20 07:35:33.607623 2026] [security2:error] [pid 164535:tid 164641] [remote 177.55.92.139:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.92.55.177.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kJTYN371eKRzcKeRsQQAA9Wk"]
[Mon Jul 20 07:35:33.607796 2026] [security2:error] [pid 164535:tid 164777] [client 177.55.92.139:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nzfoodstory.com"] [uri "/xmlrpc.php"] [unique_id "al4kJTYN371eKRzcKeRsQQAA9Wk"]
[Mon Jul 20 07:35:33.619164 2026] [security2:error] [pid 164535:tid 164767] [client 57.141.18.31:27250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kIzYN371eKRzcKeRrrAAA6xo"]
[Mon Jul 20 07:35:33.668315 2026] [security2:error] [pid 164535:tid 164695] [client 46.110.96.34:12358] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kJTYN371eKRzcKeRsQgAAAKM"]
[Mon Jul 20 07:35:33.695502 2026] [security2:error] [pid 164535:tid 164665] [client 46.110.96.34:49124] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kJTYN371eKRzcKeRsRgAAAIU"]
[Mon Jul 20 07:35:33.790382 2026] [security2:error] [pid 164535:tid 164720] [client 14.225.17.146:58400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4kJDYN371eKRzcKeRr4QAAALw"], referer: http://keywayconstructionclt.com/demo
[Mon Jul 20 07:35:34.074892 2026] [security2:error] [pid 164535:tid 164594] [remote 20.173.88.122:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4kJjYN371eKRzcKeRsaAAAjzo"]
[Mon Jul 20 07:35:34.245475 2026] [security2:error] [pid 164535:tid 164682] [client 57.141.18.82:37868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kJDYN371eKRzcKeRr6QAAlko"]
[Mon Jul 20 07:35:34.406837 2026] [security2:error] [pid 164535:tid 164580] [remote 20.173.88.122:56658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4kJjYN371eKRzcKeRsfQAA_iw"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:35:34.614871 2026] [security2:error] [pid 164535:tid 164726] [client 65.111.22.126:22399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 126.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kJjYN371eKRzcKeRshQAAAMI"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:34.730654 2026] [security2:error] [pid 164535:tid 164704] [client 52.167.144.19:61369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4kJjYN371eKRzcKeRslQAArAE"]
[Mon Jul 20 07:35:34.915215 2026] [security2:error] [pid 164535:tid 164717] [client 14.225.17.146:52517] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4kJjYN371eKRzcKeRsogAAALk"], referer: https://keywayconstructionclt.com/demo
[Mon Jul 20 07:35:35.064481 2026] [security2:error] [pid 164535:tid 164789] [client 195.2.79.165:59862] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "195.2.79.165" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4kJzYN371eKRzcKeRstgAAAQE"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/#comment-14534
[Mon Jul 20 07:35:35.064603 2026] [security2:error] [pid 164535:tid 164789] [client 195.2.79.165:59862] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4kJzYN371eKRzcKeRstgAAAQE"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/#comment-14534
[Mon Jul 20 07:35:35.142188 2026] [security2:error] [pid 164535:tid 164757] [client 57.141.18.86:51134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kJTYN371eKRzcKeRsJwAA4WE"]
[Mon Jul 20 07:35:35.192686 2026] [security2:error] [pid 164535:tid 164711] [client 143.44.185.218:52153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kJzYN371eKRzcKeRsxQAAALM"]
[Mon Jul 20 07:35:35.192788 2026] [security2:error] [pid 164535:tid 164711] [client 143.44.185.218:52153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kJzYN371eKRzcKeRsxQAAALM"]
[Mon Jul 20 07:35:35.350367 2026] [security2:error] [pid 164535:tid 164739] [client 104.234.53.90:30333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kJzYN371eKRzcKeRs1wAAAM8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:35.408785 2026] [security2:error] [pid 164535:tid 164769] [client 188.166.209.66:60932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-textdomain-registry.php"] [unique_id "al4kJzYN371eKRzcKeRs2QAAAO0"], referer: binance.com
[Mon Jul 20 07:35:35.552386 2026] [security2:error] [pid 164535:tid 164655] [remote 5.161.225.162:37506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kJzYN371eKRzcKeRs3QAA1nc"]
[Mon Jul 20 07:35:35.552558 2026] [security2:error] [pid 164535:tid 164746] [client 5.161.225.162:37506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kJzYN371eKRzcKeRs3QAA1nc"]
[Mon Jul 20 07:35:35.817332 2026] [security2:error] [pid 164535:tid 164758] [client 140.245.46.64:61104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.hah.ccq.mybluehost.me"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4kJzYN371eKRzcKeRs-QAAAOI"]
[Mon Jul 20 07:35:35.973954 2026] [security2:error] [pid 164535:tid 164696] [client 46.110.96.34:2408] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kJzYN371eKRzcKeRtAQAAAKQ"]
[Mon Jul 20 07:35:36.109540 2026] [autoindex:error] [pid 164535:tid 164638] [remote 34.23.37.181:52683] AH01276: Cannot serve directory /home2/cgadunmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.cga.dun.mybluehost.me
[Mon Jul 20 07:35:36.142744 2026] [security2:error] [pid 164535:tid 164756] [client 46.110.96.34:16122] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kKDYN371eKRzcKeRtEwAAAOA"]
[Mon Jul 20 07:35:36.213545 2026] [security2:error] [pid 164535:tid 164721] [client 46.110.96.34:21208] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kKDYN371eKRzcKeRtGgAAAL0"]
[Mon Jul 20 07:35:36.238085 2026] [security2:error] [pid 164535:tid 164757] [client 46.110.96.34:50182] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kKDYN371eKRzcKeRtHgAAAOE"]
[Mon Jul 20 07:35:36.294196 2026] [security2:error] [pid 164535:tid 164732] [client 46.110.96.34:49229] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kKDYN371eKRzcKeRtIAAAAMg"]
[Mon Jul 20 07:35:36.339452 2026] [security2:error] [pid 164535:tid 164781] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "apolloinfrastructureholdings.com"] [uri "/wp-admin/install.php"] [unique_id "al4kKDYN371eKRzcKeRtIgAAAPk"]
[Mon Jul 20 07:35:36.448723 2026] [proxy:error] [pid 164535:tid 164787] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:35:36.448768 2026] [proxy_http:error] [pid 164535:tid 164787] [client 198.235.24.145:61488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:35:36.449286 2026] [proxy:error] [pid 164535:tid 164787] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:35:36.449309 2026] [proxy_http:error] [pid 164535:tid 164787] [client 198.235.24.145:61488] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:35:36.653759 2026] [security2:error] [pid 164535:tid 164653] [remote 160.187.68.132:36288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kKDYN371eKRzcKeRtOwAAkXU"]
[Mon Jul 20 07:35:36.653945 2026] [security2:error] [pid 164535:tid 164677] [client 160.187.68.132:36288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kKDYN371eKRzcKeRtOwAAkXU"]
[Mon Jul 20 07:35:36.678894 2026] [security2:error] [pid 164535:tid 164709] [client 57.141.18.74:28226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kJzYN371eKRzcKeRsvAAAsUA"]
[Mon Jul 20 07:35:36.886110 2026] [security2:error] [pid 164535:tid 164772] [client 180.249.173.210:50519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kKDYN371eKRzcKeRtVAAAAPA"]
[Mon Jul 20 07:35:36.886235 2026] [security2:error] [pid 164535:tid 164772] [client 180.249.173.210:50519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kKDYN371eKRzcKeRtVAAAAPA"]
[Mon Jul 20 07:35:36.972720 2026] [security2:error] [pid 164535:tid 164706] [client 216.73.216.255:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mail.mollycahill.com"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtVwAAAK4"]
[Mon Jul 20 07:35:37.031836 2026] [security2:error] [pid 164535:tid 164782] [client 17.246.15.249:38424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtYgAA-lk"]
[Mon Jul 20 07:35:37.155709 2026] [security2:error] [pid 164535:tid 164699] [client 57.141.18.97:45670] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kJzYN371eKRzcKeRs5wAAp1c"]
[Mon Jul 20 07:35:37.224762 2026] [security2:error] [pid 164535:tid 164682] [client 14.225.17.146:61947] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtaAAAAJY"], referer: http://maplerespiteservices.com/demo
[Mon Jul 20 07:35:37.543973 2026] [security2:error] [pid 164535:tid 164703] [client 46.110.96.34:10460] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kKTYN371eKRzcKeRtjwAAAKs"]
[Mon Jul 20 07:35:37.661621 2026] [security2:error] [pid 164535:tid 164717] [client 77.110.127.138:52057] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/plpjuhqqdihr.php"] [unique_id "al4kKTYN371eKRzcKeRtrAAAALk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:37.667840 2026] [security2:error] [pid 164535:tid 164712] [client 57.141.18.56:24056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtEQAAtEg"]
[Mon Jul 20 07:35:37.702496 2026] [security2:error] [pid 164535:tid 164771] [client 74.208.214.194:54838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4kKTYN371eKRzcKeRtuQAAAO8"]
[Mon Jul 20 07:35:37.725461 2026] [security2:error] [pid 164535:tid 164775] [client 202.28.194.139:50009] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "202.28.194.139" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4kKTYN371eKRzcKeRtwwAAAPM"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/#comment-14534
[Mon Jul 20 07:35:37.725563 2026] [security2:error] [pid 164535:tid 164775] [client 202.28.194.139:50009] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "mezzacraft.com"] [uri "/wp-comments-post.php"] [unique_id "al4kKTYN371eKRzcKeRtwwAAAPM"], referer: https://mezzacraft.com/making-a-top-with-the-cartwheels-clovers-motif/#comment-14534
[Mon Jul 20 07:35:37.904047 2026] [security2:error] [pid 164535:tid 164745] [client 104.234.53.94:55163] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kKTYN371eKRzcKeRt2wAAANU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:37.910974 2026] [http2:info] [pid 171532:tid 171532] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:35:38.119809 2026] [security2:error] [pid 164535:tid 164764] [client 57.141.18.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRt5gAAAOg"]
[Mon Jul 20 07:35:38.321443 2026] [security2:error] [pid 164535:tid 164762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtrwAAAOY"]
[Mon Jul 20 07:35:38.356951 2026] [security2:error] [pid 164535:tid 164674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtsQAAAI4"], referer: https://mezzacraft.com/author/mezza/page/
[Mon Jul 20 07:35:38.399423 2026] [security2:error] [pid 164535:tid 164680] [client 57.141.18.41:47092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtXAAAlGo"]
[Mon Jul 20 07:35:38.401826 2026] [security2:error] [pid 164535:tid 164694] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtsAAAAKI"]
[Mon Jul 20 07:35:38.436285 2026] [security2:error] [pid 164535:tid 164781] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRttAAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:38.488870 2026] [security2:error] [pid 164535:tid 164689] [client 51.195.39.149:52111] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecaalma.com"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtRAAAnR0"]
[Mon Jul 20 07:35:38.506526 2026] [security2:error] [pid 164535:tid 164696] [client 57.141.18.28:60204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtaQAApFU"]
[Mon Jul 20 07:35:38.516989 2026] [security2:error] [pid 164535:tid 164759] [client 77.110.127.138:51991] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtyQAAAOM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:38.522239 2026] [security2:error] [pid 164535:tid 164769] [client 49.47.218.174:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRt_QAAAO0"]
[Mon Jul 20 07:35:38.522500 2026] [security2:error] [pid 164535:tid 164769] [client 49.47.218.174:53315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRt_QAAAO0"]
[Mon Jul 20 07:35:38.564585 2026] [security2:error] [pid 164535:tid 164676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRt3gAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:38.641123 2026] [security2:error] [pid 164535:tid 164756] [client 14.225.17.146:61895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtXQAAAOA"], referer: http://xp-design.co/demo
[Mon Jul 20 07:35:38.733488 2026] [security2:error] [pid 171532:tid 171674] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKkEhLvMuMRNpl03omgAAARY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:38.745645 2026] [security2:error] [pid 164535:tid 164669] [client 57.141.18.95:50148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtgwAAiW4"]
[Mon Jul 20 07:35:38.816146 2026] [security2:error] [pid 164535:tid 164700] [client 103.139.191.61:52652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRuDwAAAKg"]
[Mon Jul 20 07:35:38.816255 2026] [security2:error] [pid 164535:tid 164700] [client 103.139.191.61:52652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRuDwAAAKg"]
[Mon Jul 20 07:35:38.836556 2026] [security2:error] [pid 164535:tid 164704] [client 57.141.18.77:57850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtWQAArDI"]
[Mon Jul 20 07:35:38.845989 2026] [security2:error] [pid 164535:tid 164666] [client 149.0.16.108:59064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRuEwAAAIY"]
[Mon Jul 20 07:35:38.846093 2026] [security2:error] [pid 164535:tid 164666] [client 149.0.16.108:59064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRuEwAAAIY"]
[Mon Jul 20 07:35:38.898021 2026] [security2:error] [pid 171532:tid 171673] [client 157.20.138.62:55326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kKkEhLvMuMRNpl03oqgAAARU"]
[Mon Jul 20 07:35:38.898677 2026] [security2:error] [pid 171532:tid 171673] [client 157.20.138.62:55326] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kKkEhLvMuMRNpl03oqgAAARU"]
[Mon Jul 20 07:35:38.946114 2026] [security2:error] [pid 164535:tid 164766] [client 14.225.17.146:50055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4kKTYN371eKRzcKeRtfAAAAOo"], referer: http://olearyplumbingllc.com/demo
[Mon Jul 20 07:35:38.962788 2026] [security2:error] [pid 164535:tid 164714] [client 77.110.127.138:52079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/2/3f20hvlhbo4t.php"] [unique_id "al4kKjYN371eKRzcKeRuHwAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:39.023739 2026] [security2:error] [pid 164535:tid 164734] [client 14.225.17.146:61891] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4kKDYN371eKRzcKeRtWwAAAMo"], referer: http://narv.co/demo
[Mon Jul 20 07:35:39.100047 2026] [security2:error] [pid 164535:tid 164681] [client 155.2.215.79:54135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kKjYN371eKRzcKeRuGwAAAJU"]
[Mon Jul 20 07:35:39.194566 2026] [security2:error] [pid 164535:tid 164761] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKjYN371eKRzcKeRuFAAAAOU"]
[Mon Jul 20 07:35:39.302700 2026] [security2:error] [pid 171532:tid 171712] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKkEhLvMuMRNpl03osgAAATw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:39.332144 2026] [security2:error] [pid 164535:tid 164733] [client 77.110.127.138:52081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKjYN371eKRzcKeRuIAAAAMk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:39.364791 2026] [security2:error] [pid 164535:tid 164739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKjYN371eKRzcKeRuJgAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:39.457119 2026] [security2:error] [pid 171532:tid 171714] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kK0EhLvMuMRNpl03otAAAAT4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:39.533305 2026] [security2:error] [pid 164535:tid 164710] [client 57.141.18.124:41990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKjYN371eKRzcKeRt-QAAslI"]
[Mon Jul 20 07:35:39.581404 2026] [security2:error] [pid 171532:tid 171677] [client 57.141.18.57:49510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKkEhLvMuMRNpl03onAABGX8"]
[Mon Jul 20 07:35:39.958514 2026] [security2:error] [pid 164535:tid 164761] [client 77.110.127.138:51991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/21/0r3dffvfsssa.php"] [unique_id "al4kKzYN371eKRzcKeRuZAAAAOU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:40.118939 2026] [security2:error] [pid 164535:tid 164679] [client 14.225.17.146:50079] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4kKzYN371eKRzcKeRuWgAAAJM"], referer: https://narv.co/demo
[Mon Jul 20 07:35:40.204029 2026] [security2:error] [pid 164535:tid 164768] [client 57.141.18.68:46916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kKzYN371eKRzcKeRuNAAA7Bw"]
[Mon Jul 20 07:35:40.285030 2026] [security2:error] [pid 164535:tid 164711] [client 14.225.17.146:50421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4kKzYN371eKRzcKeRuQwAAALM"], referer: http://kromosenergy.com/demo
[Mon Jul 20 07:35:40.443669 2026] [security2:error] [pid 164535:tid 164722] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKzYN371eKRzcKeRuagAAAL4"]
[Mon Jul 20 07:35:40.471110 2026] [security2:error] [pid 171532:tid 171778] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kK0EhLvMuMRNpl03o1QAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:40.506806 2026] [security2:error] [pid 164535:tid 164673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKzYN371eKRzcKeRuaQAAAI0"], referer: https://mezzacraft.com/author/mezza/page/
[Mon Jul 20 07:35:40.540313 2026] [security2:error] [pid 164535:tid 164718] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kKzYN371eKRzcKeRubAAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:40.574784 2026] [security2:error] [pid 164535:tid 164746] [client 77.110.127.138:52074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLDYN371eKRzcKeRubQAAANY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:40.605845 2026] [security2:error] [pid 164535:tid 164666] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLDYN371eKRzcKeRucwAAAIY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:40.712423 2026] [security2:error] [pid 164535:tid 164698] [client 36.93.152.155:64007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kLDYN371eKRzcKeRukwAAAKY"]
[Mon Jul 20 07:35:40.712498 2026] [security2:error] [pid 164535:tid 164698] [client 36.93.152.155:64007] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kLDYN371eKRzcKeRukwAAAKY"]
[Mon Jul 20 07:35:40.744241 2026] [security2:error] [pid 171532:tid 171789] [client 154.192.123.127:16995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kLEEhLvMuMRNpl03o7gAAAYg"]
[Mon Jul 20 07:35:40.744360 2026] [security2:error] [pid 171532:tid 171789] [client 154.192.123.127:16995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kLEEhLvMuMRNpl03o7gAAAYg"]
[Mon Jul 20 07:35:40.909937 2026] [security2:error] [pid 164535:tid 164738] [client 77.110.127.138:52097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/blueberry-lemon-yogurt-cake/sml5aepkimht.php"] [unique_id "al4kLDYN371eKRzcKeRunwAAAM4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:41.023878 2026] [security2:error] [pid 164535:tid 164684] [client 14.225.17.146:50239] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4kLDYN371eKRzcKeRukQAAAJg"], referer: http://mcg.homes/demo
[Mon Jul 20 07:35:41.130442 2026] [security2:error] [pid 171532:tid 171686] [client 49.37.242.14:59044] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kLUEhLvMuMRNpl03pEAAAASI"]
[Mon Jul 20 07:35:41.130621 2026] [security2:error] [pid 171532:tid 171686] [client 49.37.242.14:59044] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kLUEhLvMuMRNpl03pEAAAASI"]
[Mon Jul 20 07:35:41.157419 2026] [security2:error] [pid 171532:tid 171742] [client 139.59.118.64:65004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kLUEhLvMuMRNpl03pEQAAAVo"]
[Mon Jul 20 07:35:41.425468 2026] [security2:error] [pid 171532:tid 171732] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLEEhLvMuMRNpl03o9wAAAVA"], referer: https://mezzacraft.com/author/mezza/page/
[Mon Jul 20 07:35:41.519883 2026] [security2:error] [pid 171532:tid 171699] [client 57.141.18.51:23234] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kLEEhLvMuMRNpl03o6AABLw0"]
[Mon Jul 20 07:35:41.529460 2026] [security2:error] [pid 171532:tid 171697] [client 14.225.17.146:50235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4kK0EhLvMuMRNpl03ovgAAAS0"], referer: http://adastra.love/demo
[Mon Jul 20 07:35:41.535445 2026] [security2:error] [pid 171532:tid 171728] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLEEhLvMuMRNpl03pBwAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:41.543854 2026] [security2:error] [pid 171532:tid 171691] [client 188.166.209.66:50272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-theme-json-data.php"] [unique_id "al4kLUEhLvMuMRNpl03pIAAAASc"], referer: binance.com
[Mon Jul 20 07:35:41.553385 2026] [security2:error] [pid 171532:tid 171776] [client 46.110.96.34:59562] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kLUEhLvMuMRNpl03pIQAAAXs"]
[Mon Jul 20 07:35:41.555402 2026] [security2:error] [pid 171532:tid 171685] [client 46.110.96.34:29995] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kLUEhLvMuMRNpl03pIgAAASE"]
[Mon Jul 20 07:35:41.571852 2026] [security2:error] [pid 164535:tid 164771] [client 77.110.127.138:52099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLTYN371eKRzcKeRuqAAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:41.605228 2026] [security2:error] [pid 164535:tid 164728] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLDYN371eKRzcKeRuogAAAMQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:41.701011 2026] [security2:error] [pid 164535:tid 164699] [client 103.106.165.44:52997] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kLTYN371eKRzcKeRuwwAAAKc"]
[Mon Jul 20 07:35:41.701134 2026] [security2:error] [pid 164535:tid 164699] [client 103.106.165.44:52997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kLTYN371eKRzcKeRuwwAAAKc"]
[Mon Jul 20 07:35:41.798201 2026] [security2:error] [pid 164535:tid 164772] [client 77.110.127.138:52068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/british-american-crochet-terms/xkq9my2ii8xd.php"] [unique_id "al4kLTYN371eKRzcKeRuzgAAAPA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:41.843165 2026] [autoindex:error] [pid 171532:tid 171752] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/uploads/2015/
[Mon Jul 20 07:35:42.031019 2026] [security2:error] [pid 164535:tid 164783] [client 116.74.65.235:64929] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4kLTYN371eKRzcKeRu2AAAAPs"]
[Mon Jul 20 07:35:42.031142 2026] [security2:error] [pid 164535:tid 164783] [client 116.74.65.235:64929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4kLTYN371eKRzcKeRu2AAAAPs"]
[Mon Jul 20 07:35:42.067265 2026] [security2:error] [pid 171532:tid 171710] [client 136.158.60.21:49179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kLkEhLvMuMRNpl03pRAAAATo"]
[Mon Jul 20 07:35:42.067435 2026] [security2:error] [pid 171532:tid 171710] [client 136.158.60.21:49179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kLkEhLvMuMRNpl03pRAAAATo"]
[Mon Jul 20 07:35:42.260095 2026] [security2:error] [pid 164535:tid 164769] [client 46.110.96.34:7249] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kLjYN371eKRzcKeRu6wAAAO0"]
[Mon Jul 20 07:35:42.387994 2026] [security2:error] [pid 171532:tid 171749] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLUEhLvMuMRNpl03pNAAAAWE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:42.422836 2026] [security2:error] [pid 171532:tid 171753] [client 14.225.17.146:50533] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4kLkEhLvMuMRNpl03pSAAAAWU"], referer: http://colinkeyphotography.com/demo
[Mon Jul 20 07:35:42.441446 2026] [security2:error] [pid 171532:tid 171762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLUEhLvMuMRNpl03pQAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:42.520870 2026] [security2:error] [pid 171532:tid 171769] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4kLkEhLvMuMRNpl03pRwABdR0"], referer: http://ali-alghanim.net/demo
[Mon Jul 20 07:35:42.538562 2026] [security2:error] [pid 164535:tid 164687] [client 77.110.127.138:52058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLTYN371eKRzcKeRu1AAAAJs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:42.619427 2026] [security2:error] [pid 171532:tid 171735] [client 57.141.18.119:33738] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kLUEhLvMuMRNpl03pMAABUxs"]
[Mon Jul 20 07:35:42.630777 2026] [security2:error] [pid 171532:tid 171729] [client 77.110.127.138:52083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/competition/feed/7854e4wfdm66.php"] [unique_id "al4kLkEhLvMuMRNpl03pVQAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:42.721239 2026] [security2:error] [pid 171532:tid 171670] [client 191.202.66.27:50109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kLkEhLvMuMRNpl03pZAAAARI"]
[Mon Jul 20 07:35:42.721351 2026] [security2:error] [pid 171532:tid 171670] [client 191.202.66.27:50109] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kLkEhLvMuMRNpl03pZAAAARI"]
[Mon Jul 20 07:35:42.745755 2026] [security2:error] [pid 164535:tid 164766] [client 114.119.151.208:42745] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "fridacom.net"] [uri "/robots.txt"] [unique_id "al4kLjYN371eKRzcKeRvEAAAAOo"], referer: http://fridacom.net/robots.txt
[Mon Jul 20 07:35:42.933500 2026] [security2:error] [pid 171532:tid 171569] [remote 209.42.18.223:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4kLkEhLvMuMRNpl03pbgABCiQ"]
[Mon Jul 20 07:35:43.077709 2026] [security2:error] [pid 164535:tid 164696] [client 216.73.217.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ali-alghanim.com"] [uri "/index.php"] [unique_id "al4kLjYN371eKRzcKeRvGwAApG8"]
[Mon Jul 20 07:35:43.079481 2026] [security2:error] [pid 164535:tid 164709] [client 14.225.17.146:52640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4kLjYN371eKRzcKeRvGQAAALE"], referer: http://northbrookcpa.ca/demo
[Mon Jul 20 07:35:43.079567 2026] [security2:error] [pid 164535:tid 164744] [client 179.127.84.238:53264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kLzYN371eKRzcKeRvJgAAANQ"]
[Mon Jul 20 07:35:43.079664 2026] [security2:error] [pid 164535:tid 164744] [client 179.127.84.238:53264] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kLzYN371eKRzcKeRvJgAAANQ"]
[Mon Jul 20 07:35:43.111262 2026] [security2:error] [pid 171532:tid 171571] [remote 209.42.18.223:52646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4kL0EhLvMuMRNpl03pewABYCY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:35:43.386648 2026] [security2:error] [pid 164535:tid 164760] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLjYN371eKRzcKeRvEQAAAOQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:43.515508 2026] [security2:error] [pid 171532:tid 171673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLkEhLvMuMRNpl03pXAAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:43.562702 2026] [security2:error] [pid 164535:tid 164668] [client 77.110.127.138:52099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kLjYN371eKRzcKeRvDAAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:43.629679 2026] [security2:error] [pid 164535:tid 164568] [remote 202.51.202.242:59764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/wp-login.php"] [unique_id "al4kLzYN371eKRzcKeRvPQABASA"], referer: https://website-e4de5cd0.epu.kzx.mybluehost.me/wp/wp-login.php
[Mon Jul 20 07:35:43.746730 2026] [security2:error] [pid 171532:tid 171780] [client 103.176.215.66:58003] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kL0EhLvMuMRNpl03pnAAAAX8"]
[Mon Jul 20 07:35:43.746977 2026] [security2:error] [pid 171532:tid 171780] [client 103.176.215.66:58003] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kL0EhLvMuMRNpl03pnAAAAX8"]
[Mon Jul 20 07:35:43.845309 2026] [security2:error] [pid 164535:tid 164777] [client 14.225.17.146:65265] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4kLjYN371eKRzcKeRu8wAAAPU"], referer: http://momheadquarters.com/demo
[Mon Jul 20 07:35:44.019666 2026] [security2:error] [pid 171532:tid 171582] [remote 217.61.143.92:47442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4kMEEhLvMuMRNpl03ppgABWjE"]
[Mon Jul 20 07:35:44.116646 2026] [security2:error] [pid 164535:tid 164727] [client 46.110.96.34:37907] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kMDYN371eKRzcKeRvTwAAAMM"]
[Mon Jul 20 07:35:44.244822 2026] [security2:error] [pid 171532:tid 171583] [remote 217.61.143.92:47442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4kMEEhLvMuMRNpl03prwABRzI"], referer: https://inspirespublishing.com/wp-login.php
[Mon Jul 20 07:35:44.292515 2026] [security2:error] [pid 171532:tid 171706] [client 14.225.17.146:65271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kMEEhLvMuMRNpl03pqAAAATY"], referer: http://mezzacraft.com/demo
[Mon Jul 20 07:35:44.318138 2026] [security2:error] [pid 171532:tid 171763] [client 46.110.96.34:35839] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kMEEhLvMuMRNpl03psgAAAW8"]
[Mon Jul 20 07:35:44.324525 2026] [security2:error] [pid 171532:tid 171692] [client 43.133.187.11:46994] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.187.133.43.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.marscafe.com"] [uri "/php/costing1-dl/download.php"] [unique_id "al4kMEEhLvMuMRNpl03psAAAASg"]
[Mon Jul 20 07:35:44.363977 2026] [security2:error] [pid 164535:tid 164665] [client 46.110.96.34:7889] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kMDYN371eKRzcKeRvXwAAAIU"]
[Mon Jul 20 07:35:44.390497 2026] [security2:error] [pid 164535:tid 164711] [client 46.110.96.34:34722] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kMDYN371eKRzcKeRvYAAAALM"]
[Mon Jul 20 07:35:44.439735 2026] [security2:error] [pid 171532:tid 171736] [client 46.110.96.34:5064] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kMEEhLvMuMRNpl03pswAAAVQ"]
[Mon Jul 20 07:35:44.444640 2026] [security2:error] [pid 164535:tid 164775] [client 77.110.127.138:52073] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-motif/feed/2callw63vn7l.php"] [unique_id "al4kMDYN371eKRzcKeRvZAAAAPM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:44.461671 2026] [security2:error] [pid 171532:tid 171683] [client 57.141.18.23:40604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kL0EhLvMuMRNpl03pmQABHy4"]
[Mon Jul 20 07:35:44.472148 2026] [security2:error] [pid 171532:tid 171719] [client 57.141.18.100:58106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kL0EhLvMuMRNpl03plAABQy0"]
[Mon Jul 20 07:35:44.741866 2026] [security2:error] [pid 164535:tid 164733] [client 14.225.17.146:54154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4kMDYN371eKRzcKeRvdQAAAMk"], referer: http://chestermonty.com/demo
[Mon Jul 20 07:35:44.752515 2026] [security2:error] [pid 164535:tid 164671] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kMDYN371eKRzcKeRvaQAAAIs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:44.768248 2026] [security2:error] [pid 171532:tid 171782] [client 117.211.236.168:50674] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kMEEhLvMuMRNpl03pyAAAAYE"]
[Mon Jul 20 07:35:44.768348 2026] [security2:error] [pid 171532:tid 171782] [client 117.211.236.168:50674] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kMEEhLvMuMRNpl03pyAAAAYE"]
[Mon Jul 20 07:35:44.849534 2026] [security2:error] [pid 171532:tid 171730] [client 57.141.18.81:29116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kMEEhLvMuMRNpl03ppQABTjA"]
[Mon Jul 20 07:35:45.124017 2026] [security2:error] [pid 171532:tid 171729] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kMEEhLvMuMRNpl03p0QAAAU0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:45.477070 2026] [security2:error] [pid 164535:tid 164747] [client 57.141.18.97:21472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kMDYN371eKRzcKeRvdgAA11I"]
[Mon Jul 20 07:35:45.614726 2026] [security2:error] [pid 171532:tid 171679] [client 57.141.18.72:24712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kMEEhLvMuMRNpl03pywABGzQ"]
[Mon Jul 20 07:35:45.672047 2026] [security2:error] [pid 171532:tid 171788] [client 14.225.17.146:54463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4kMUEhLvMuMRNpl03p5wAAAYc"], referer: https://chestermonty.com/demo
[Mon Jul 20 07:35:45.845948 2026] [security2:error] [pid 171532:tid 171756] [client 57.141.18.9:52286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kMEEhLvMuMRNpl03p1AABaDY"]
[Mon Jul 20 07:35:46.252099 2026] [security2:error] [pid 171532:tid 171772] [client 77.110.127.138:52125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kMUEhLvMuMRNpl03p_AAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:35:46.256866 2026] [security2:error] [pid 171532:tid 171689] [client 104.234.53.63:32537] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kMkEhLvMuMRNpl03qCAAAASU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:46.297824 2026] [security2:error] [pid 164535:tid 164622] [remote 5.252.52.249:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kMjYN371eKRzcKeRvuQAAyVY"]
[Mon Jul 20 07:35:46.483344 2026] [security2:error] [pid 164535:tid 164578] [remote 5.252.52.249:60326] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kMjYN371eKRzcKeRvwAAA7Co"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:35:46.645340 2026] [security2:error] [pid 164535:tid 164761] [client 139.59.118.64:49288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kMjYN371eKRzcKeRvwwAAAOU"], referer: https://wordpress.org/
[Mon Jul 20 07:35:46.681603 2026] [security2:error] [pid 164535:tid 164673] [client 121.37.98.66:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kMjYN371eKRzcKeRvvgAAjRY"], referer: https://www.aleishapenny.ca/listing/page/251?paged=1&view=grid&posts_per_page=48
[Mon Jul 20 07:35:46.716994 2026] [security2:error] [pid 171532:tid 171598] [remote 5.252.52.249:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4kMkEhLvMuMRNpl03qHQABDEE"]
[Mon Jul 20 07:35:46.891598 2026] [security2:error] [pid 171532:tid 171603] [remote 5.252.52.249:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4kMkEhLvMuMRNpl03qJgABWEY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:35:46.960149 2026] [security2:error] [pid 171532:tid 171668] [client 14.225.17.146:53914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4kL0EhLvMuMRNpl03piAAAARA"], referer: http://areitoproducciones.com/demo
[Mon Jul 20 07:35:47.084667 2026] [security2:error] [pid 171532:tid 171744] [client 14.225.17.146:54168] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4kMUEhLvMuMRNpl03p7QAAAVw"]
[Mon Jul 20 07:35:47.123825 2026] [security2:error] [pid 164535:tid 164760] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kMjYN371eKRzcKeRv1wAAAOQ"]
[Mon Jul 20 07:35:47.256339 2026] [security2:error] [pid 171532:tid 171754] [client 57.141.18.113:43768] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kMkEhLvMuMRNpl03qEwABZj8"]
[Mon Jul 20 07:35:47.290818 2026] [security2:error] [pid 171532:tid 171734] [client 188.166.209.66:61562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-theme-json-resolver.php"] [unique_id "al4kM0EhLvMuMRNpl03qPAAAAVI"], referer: binance.com
[Mon Jul 20 07:35:47.395528 2026] [security2:error] [pid 171532:tid 171695] [client 143.44.185.218:53956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kM0EhLvMuMRNpl03qQAAAASs"]
[Mon Jul 20 07:35:47.396041 2026] [security2:error] [pid 171532:tid 171695] [client 143.44.185.218:53956] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kM0EhLvMuMRNpl03qQAAAASs"]
[Mon Jul 20 07:35:47.424425 2026] [security2:error] [pid 171532:tid 171783] [client 180.249.173.210:50983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kM0EhLvMuMRNpl03qQwAAAYI"]
[Mon Jul 20 07:35:47.429005 2026] [security2:error] [pid 171532:tid 171783] [client 180.249.173.210:50983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kM0EhLvMuMRNpl03qQwAAAYI"]
[Mon Jul 20 07:35:47.609417 2026] [security2:error] [pid 171532:tid 171719] [client 57.141.18.90:41372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kMkEhLvMuMRNpl03qIgABQ0M"]
[Mon Jul 20 07:35:47.887256 2026] [security2:error] [pid 164535:tid 164675] [client 104.234.53.65:30757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kMzYN371eKRzcKeRv_gAAAI8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:48.243481 2026] [security2:error] [pid 164535:tid 164790] [client 139.59.118.64:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4kNDYN371eKRzcKeRwCgAAAQI"], referer: https://duckduckgo.com/
[Mon Jul 20 07:35:48.356862 2026] [security2:error] [pid 164535:tid 164559] [remote 13.232.189.155:37910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kNDYN371eKRzcKeRwEAAAqRc"]
[Mon Jul 20 07:35:48.440267 2026] [security2:error] [pid 164535:tid 164728] [client 57.141.18.10:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kNDYN371eKRzcKeRwDQAAAMQ"]
[Mon Jul 20 07:35:48.757684 2026] [security2:error] [pid 164535:tid 164573] [remote 13.232.189.155:37910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kNDYN371eKRzcKeRwKwAA_iU"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 07:35:49.073709 2026] [security2:error] [pid 171532:tid 171713] [client 49.47.218.174:53858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kNUEhLvMuMRNpl03qgwAAAT0"]
[Mon Jul 20 07:35:49.073875 2026] [security2:error] [pid 171532:tid 171713] [client 49.47.218.174:53858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kNUEhLvMuMRNpl03qgwAAAT0"]
[Mon Jul 20 07:35:49.077108 2026] [security2:error] [pid 164535:tid 164709] [client 103.139.191.63:53128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kNTYN371eKRzcKeRwNQAAALE"]
[Mon Jul 20 07:35:49.077268 2026] [security2:error] [pid 164535:tid 164709] [client 103.139.191.63:53128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kNTYN371eKRzcKeRwNQAAALE"]
[Mon Jul 20 07:35:49.374710 2026] [security2:error] [pid 164535:tid 164679] [client 57.141.18.64:56286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kNDYN371eKRzcKeRwLAAAkwM"]
[Mon Jul 20 07:35:49.409356 2026] [security2:error] [pid 164535:tid 164602] [remote 81.173.115.7:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kNTYN371eKRzcKeRwSQAAnEI"]
[Mon Jul 20 07:35:49.498240 2026] [security2:error] [pid 164535:tid 164680] [client 149.0.16.108:59581] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kNTYN371eKRzcKeRwTAAAAJQ"]
[Mon Jul 20 07:35:49.498859 2026] [security2:error] [pid 164535:tid 164680] [client 149.0.16.108:59581] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kNTYN371eKRzcKeRwTAAAAJQ"]
[Mon Jul 20 07:35:49.503712 2026] [security2:error] [pid 171532:tid 171728] [client 57.141.18.109:65076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kNEEhLvMuMRNpl03qfgABTFs"]
[Mon Jul 20 07:35:49.541356 2026] [security2:error] [pid 171532:tid 171768] [client 157.20.138.62:55891] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kNUEhLvMuMRNpl03qlgAAAXQ"]
[Mon Jul 20 07:35:49.541742 2026] [security2:error] [pid 171532:tid 171768] [client 157.20.138.62:55891] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kNUEhLvMuMRNpl03qlgAAAXQ"]
[Mon Jul 20 07:35:49.612738 2026] [security2:error] [pid 164535:tid 164574] [remote 81.173.115.7:51662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kNTYN371eKRzcKeRwUQAAsiY"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:35:49.729697 2026] [security2:error] [pid 171532:tid 171733] [client 155.2.215.90:45693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kNUEhLvMuMRNpl03qlwAAAVE"]
[Mon Jul 20 07:35:49.739053 2026] [security2:error] [pid 171532:tid 171705] [client 104.234.53.51:63017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kNUEhLvMuMRNpl03qogAAATU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:49.773710 2026] [security2:error] [pid 171532:tid 171686] [client 46.110.96.34:35377] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kNUEhLvMuMRNpl03qpAAAASI"]
[Mon Jul 20 07:35:49.773982 2026] [security2:error] [pid 171532:tid 171744] [client 46.110.96.34:18050] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kNUEhLvMuMRNpl03qpQAAAVw"]
[Mon Jul 20 07:35:50.310326 2026] [security2:error] [pid 171532:tid 171634] [remote 8.217.108.67:1938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4kNkEhLvMuMRNpl03quAABZGU"]
[Mon Jul 20 07:35:50.310504 2026] [security2:error] [pid 171532:tid 171752] [client 8.217.108.67:1938] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ivetstrategies.com"] [uri "/xmlrpc.php"] [unique_id "al4kNkEhLvMuMRNpl03quAABZGU"]
[Mon Jul 20 07:35:50.480499 2026] [security2:error] [pid 164535:tid 164759] [client 46.110.96.34:53672] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kNjYN371eKRzcKeRwfgAAAOM"]
[Mon Jul 20 07:35:50.633054 2026] [security2:error] [pid 171532:tid 171714] [client 104.234.53.62:31527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kNkEhLvMuMRNpl03qxQAAAT4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:50.649594 2026] [security2:error] [pid 171532:tid 171770] [client 74.7.227.179:47174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4kNkEhLvMuMRNpl03qwQABdmY"], referer: https://tejasenvironmental.com/p=318821
[Mon Jul 20 07:35:50.657850 2026] [security2:error] [pid 164535:tid 164717] [client 57.141.18.62:57326] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kNjYN371eKRzcKeRwZgAAuXo"]
[Mon Jul 20 07:35:51.094562 2026] [security2:error] [pid 164535:tid 164687] [client 14.225.17.146:51959] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4kNjYN371eKRzcKeRwbwAAAJs"], referer: http://walkingandtalking.net/demo
[Mon Jul 20 07:35:51.234264 2026] [security2:error] [pid 171532:tid 171719] [client 36.93.152.155:64528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kN0EhLvMuMRNpl03q5wAAAUM"]
[Mon Jul 20 07:35:51.234358 2026] [security2:error] [pid 171532:tid 171719] [client 36.93.152.155:64528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kN0EhLvMuMRNpl03q5wAAAUM"]
[Mon Jul 20 07:35:51.256826 2026] [security2:error] [pid 171532:tid 171728] [client 14.225.17.146:51034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4kNkEhLvMuMRNpl03q2gAAAUw"], referer: http://webgardensbypaula.com/demo
[Mon Jul 20 07:35:51.274701 2026] [core:alert] [pid 164535:tid 164723] [client 107.172.180.205:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:35:51.275118 2026] [core:alert] [pid 164535:tid 164723] [client 107.172.180.205:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:35:51.293576 2026] [security2:error] [pid 171532:tid 171747] [client 154.192.123.127:17406] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kN0EhLvMuMRNpl03q6QAAAV8"]
[Mon Jul 20 07:35:51.293650 2026] [security2:error] [pid 171532:tid 171747] [client 154.192.123.127:17406] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kN0EhLvMuMRNpl03q6QAAAV8"]
[Mon Jul 20 07:35:51.319214 2026] [security2:error] [pid 171532:tid 171785] [client 98.159.234.160:50435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kN0EhLvMuMRNpl03q6wAAAYQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:35:51.617329 2026] [security2:error] [pid 171532:tid 171682] [client 202.141.11.99:37054] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kN0EhLvMuMRNpl03q8gAAAR4"]
[Mon Jul 20 07:35:51.617434 2026] [security2:error] [pid 171532:tid 171682] [client 202.141.11.99:37054] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kN0EhLvMuMRNpl03q8gAAAR4"]
[Mon Jul 20 07:35:51.684457 2026] [security2:error] [pid 164535:tid 164731] [client 57.141.18.58:56402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kNzYN371eKRzcKeRwmgAAxxs"]
[Mon Jul 20 07:35:51.994330 2026] [security2:error] [pid 171532:tid 171662] [client 14.225.17.146:51037] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4kN0EhLvMuMRNpl03q3wAAAQo"], referer: http://ancestralidadytrance.space/demo
[Mon Jul 20 07:35:52.128645 2026] [security2:error] [pid 171532:tid 171670] [client 14.225.17.146:50058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4kOEEhLvMuMRNpl03rCAAAARI"], referer: https://walkingandtalking.net/demo
[Mon Jul 20 07:35:52.220864 2026] [security2:error] [pid 164535:tid 164607] [remote 64.225.121.94:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kODYN371eKRzcKeRw2AAAnUc"]
[Mon Jul 20 07:35:52.243962 2026] [security2:error] [pid 164535:tid 164676] [client 104.234.53.87:28235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kODYN371eKRzcKeRw2QAAAJA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:52.267541 2026] [security2:error] [pid 171532:tid 171778] [client 103.106.165.44:53478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kOEEhLvMuMRNpl03rEgAAAX0"]
[Mon Jul 20 07:35:52.267641 2026] [security2:error] [pid 171532:tid 171778] [client 103.106.165.44:53478] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kOEEhLvMuMRNpl03rEgAAAX0"]
[Mon Jul 20 07:35:52.309592 2026] [security2:error] [pid 164535:tid 164582] [remote 72.167.132.114:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kODYN371eKRzcKeRw2wABAC4"]
[Mon Jul 20 07:35:52.404487 2026] [autoindex:error] [pid 164535:tid 164789] [client 136.66.110.98:54334] AH01276: Cannot serve directory /home1/heidimo2/rootedandwholecoaching.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:35:52.444505 2026] [security2:error] [pid 171532:tid 171713] [client 188.166.209.66:56327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-theme-json-schema.php"] [unique_id "al4kOEEhLvMuMRNpl03rGAAAAT0"], referer: binance.com
[Mon Jul 20 07:35:52.481657 2026] [security2:error] [pid 164535:tid 164641] [remote 64.225.121.94:33702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kODYN371eKRzcKeRw4wAAy2k"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:35:52.526649 2026] [security2:error] [pid 164535:tid 164656] [remote 72.167.132.114:34590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.upf.ztf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kODYN371eKRzcKeRw5QAAhXg"], referer: https://mail.upf.ztf.mybluehost.me/wp-login.php
[Mon Jul 20 07:35:52.829213 2026] [security2:error] [pid 171532:tid 171715] [client 136.158.60.21:50571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kOEEhLvMuMRNpl03rLAAAAT8"]
[Mon Jul 20 07:35:52.829392 2026] [security2:error] [pid 171532:tid 171715] [client 136.158.60.21:50571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kOEEhLvMuMRNpl03rLAAAAT8"]
[Mon Jul 20 07:35:52.869394 2026] [core:alert] [pid 171532:tid 171685] [client 107.172.180.205:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:35:52.870367 2026] [core:alert] [pid 171532:tid 171685] [client 107.172.180.205:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:35:52.902514 2026] [security2:error] [pid 171532:tid 171692] [client 41.223.74.106:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4kN0EhLvMuMRNpl03q8AAAASg"]
[Mon Jul 20 07:35:53.131688 2026] [security2:error] [pid 171532:tid 171655] [remote 78.46.99.182:46196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4kOUEhLvMuMRNpl03rQgABMXo"]
[Mon Jul 20 07:35:53.315537 2026] [security2:error] [pid 171532:tid 171656] [remote 78.46.99.182:46196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4kOUEhLvMuMRNpl03rTAABKns"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:35:53.390156 2026] [security2:error] [pid 164535:tid 164538] [remote 130.51.180.8:51942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4kOTYN371eKRzcKeRxCgAA9wI"]
[Mon Jul 20 07:35:53.396407 2026] [security2:error] [pid 171532:tid 171693] [client 191.202.66.27:50602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kOUEhLvMuMRNpl03rTgAAASk"]
[Mon Jul 20 07:35:53.396522 2026] [security2:error] [pid 171532:tid 171693] [client 191.202.66.27:50602] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kOUEhLvMuMRNpl03rTgAAASk"]
[Mon Jul 20 07:35:53.396996 2026] [security2:error] [pid 171532:tid 171752] [client 14.225.17.146:50965] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4kN0EhLvMuMRNpl03q9QAAAWQ"], referer: http://fluidtemple.org/demo
[Mon Jul 20 07:35:53.431459 2026] [security2:error] [pid 171532:tid 171747] [client 57.141.18.28:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kOUEhLvMuMRNpl03rSwAAAV8"]
[Mon Jul 20 07:35:53.484010 2026] [security2:error] [pid 164535:tid 164728] [client 104.234.53.73:39243] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kOTYN371eKRzcKeRxDQAAAMQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:53.545005 2026] [security2:error] [pid 164535:tid 164556] [remote 130.51.180.8:51942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4kOTYN371eKRzcKeRxEgAA7xQ"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:35:53.815589 2026] [security2:error] [pid 171532:tid 171724] [client 179.127.84.238:53798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kOUEhLvMuMRNpl03rYgAAAUg"]
[Mon Jul 20 07:35:53.815758 2026] [security2:error] [pid 171532:tid 171724] [client 179.127.84.238:53798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kOUEhLvMuMRNpl03rYgAAAUg"]
[Mon Jul 20 07:35:53.893444 2026] [security2:error] [pid 171532:tid 171695] [client 193.23.206.229:33248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4kOUEhLvMuMRNpl03rWAABK34"]
[Mon Jul 20 07:35:54.197250 2026] [security2:error] [pid 171532:tid 171753] [client 157.55.39.194:49485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.39.55.157.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "daseighty.net"] [uri "/gallery/main.php"] [unique_id "al4kOkEhLvMuMRNpl03ragAAAWU"]
[Mon Jul 20 07:35:54.227026 2026] [security2:error] [pid 171532:tid 171738] [client 103.176.215.66:58535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kOkEhLvMuMRNpl03rbwAAAVY"]
[Mon Jul 20 07:35:54.227692 2026] [security2:error] [pid 171532:tid 171738] [client 103.176.215.66:58535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kOkEhLvMuMRNpl03rbwAAAVY"]
[Mon Jul 20 07:35:54.333797 2026] [security2:error] [pid 164535:tid 164692] [client 57.141.18.12:57322] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kOTYN371eKRzcKeRxJAAAoB0"]
[Mon Jul 20 07:35:54.524448 2026] [security2:error] [pid 171532:tid 171737] [client 5.161.215.244:59482] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4kOkEhLvMuMRNpl03reQAAAVU"], referer: https://windowtx.com
[Mon Jul 20 07:35:54.542264 2026] [security2:error] [pid 171532:tid 171714] [client 57.141.18.124:40088] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kOkEhLvMuMRNpl03rZwABPgY"]
[Mon Jul 20 07:35:54.572367 2026] [security2:error] [pid 164535:tid 164547] [remote 144.79.133.30:38594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4kOjYN371eKRzcKeRxPgAA_ws"]
[Mon Jul 20 07:35:54.626079 2026] [security2:error] [pid 164535:tid 164666] [client 151.123.176.248:22661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kOjYN371eKRzcKeRxQAAAAIY"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:35:54.961550 2026] [security2:error] [pid 164535:tid 164766] [client 104.207.53.237:34563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 237.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kOjYN371eKRzcKeRxUAAAAOo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:55.258393 2026] [security2:error] [pid 164535:tid 164696] [client 65.111.28.70:54703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kOzYN371eKRzcKeRxYAAAAKQ"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:35:55.363906 2026] [security2:error] [pid 171532:tid 171677] [client 117.211.236.168:51238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kO0EhLvMuMRNpl03rnAAAARk"]
[Mon Jul 20 07:35:55.364000 2026] [security2:error] [pid 171532:tid 171677] [client 117.211.236.168:51238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kO0EhLvMuMRNpl03rnAAAARk"]
[Mon Jul 20 07:35:55.474533 2026] [security2:error] [pid 164535:tid 164785] [client 14.225.17.146:52089] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4kOzYN371eKRzcKeRxZAAAAP0"], referer: http://slutilities.com/demo
[Mon Jul 20 07:35:55.475135 2026] [security2:error] [pid 164535:tid 164682] [client 50.116.65.227:15810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kOzYN371eKRzcKeRxagAAAJY"]
[Mon Jul 20 07:35:55.483809 2026] [security2:error] [pid 171532:tid 171789] [client 50.116.65.227:15818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kO0EhLvMuMRNpl03rogAAAYg"]
[Mon Jul 20 07:35:55.817095 2026] [security2:error] [pid 164535:tid 164747] [client 57.141.18.115:30100] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kOzYN371eKRzcKeRxYgAA12w"]
[Mon Jul 20 07:35:56.107040 2026] [security2:error] [pid 164535:tid 164663] [remote 91.142.222.105:48718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kPDYN371eKRzcKeRxiwAA0X8"]
[Mon Jul 20 07:35:56.107311 2026] [security2:error] [pid 164535:tid 164741] [client 91.142.222.105:48718] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kPDYN371eKRzcKeRxiwAA0X8"]
[Mon Jul 20 07:35:56.189433 2026] [security2:error] [pid 164535:tid 164668] [client 57.141.18.20:35650] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kOzYN371eKRzcKeRxcAAAiHI"]
[Mon Jul 20 07:35:56.376085 2026] [security2:error] [pid 171532:tid 171699] [client 14.225.17.146:51992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4kO0EhLvMuMRNpl03rpAAAAS8"], referer: http://talknutritionwithlesley.com/demo
[Mon Jul 20 07:35:56.411854 2026] [security2:error] [pid 171532:tid 171755] [client 45.3.42.131:9487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kPEEhLvMuMRNpl03rvwAAAWc"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:35:56.495736 2026] [security2:error] [pid 164535:tid 164731] [client 49.37.242.14:59592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kPDYN371eKRzcKeRxpAAAAMc"]
[Mon Jul 20 07:35:56.495889 2026] [security2:error] [pid 164535:tid 164731] [client 49.37.242.14:59592] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kPDYN371eKRzcKeRxpAAAAMc"]
[Mon Jul 20 07:35:56.580331 2026] [security2:error] [pid 164535:tid 164770] [client 57.141.18.7:41314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kPDYN371eKRzcKeRxiAAA7gg"]
[Mon Jul 20 07:35:56.989882 2026] [security2:error] [pid 171532:tid 171722] [client 57.141.18.26:36354] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kPEEhLvMuMRNpl03rwQABRhU"]
[Mon Jul 20 07:35:57.031684 2026] [security2:error] [pid 164535:tid 164582] [remote 144.79.133.30:38594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.133.79.144.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.indiraskitchenllc.com"] [uri "/wp-login.php"] [unique_id "al4kPTYN371eKRzcKeRxtwAA4S4"], referer: https://mail.indiraskitchenllc.com/wp-login.php
[Mon Jul 20 07:35:57.327060 2026] [security2:error] [pid 171532:tid 171556] [remote 5.161.225.162:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4kPUEhLvMuMRNpl03r6wABERc"]
[Mon Jul 20 07:35:57.368242 2026] [security2:error] [pid 171532:tid 171778] [client 14.225.17.146:52365] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4kPUEhLvMuMRNpl03r2gAAAX0"], referer: http://healthylifegourmet.org/demo
[Mon Jul 20 07:35:57.448423 2026] [autoindex:error] [pid 171532:tid 171563] [remote 136.114.198.221:57283] AH01276: Cannot serve directory /home2/cgadunmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.cga.dun.mybluehost.me
[Mon Jul 20 07:35:57.546556 2026] [security2:error] [pid 171532:tid 171562] [remote 5.161.225.162:56224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4kPUEhLvMuMRNpl03r-wABZx0"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:35:57.831670 2026] [security2:error] [pid 171532:tid 171764] [client 180.249.173.210:51450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kPUEhLvMuMRNpl03sAgAAAXA"]
[Mon Jul 20 07:35:57.832207 2026] [security2:error] [pid 171532:tid 171764] [client 180.249.173.210:51450] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kPUEhLvMuMRNpl03sAgAAAXA"]
[Mon Jul 20 07:35:57.856663 2026] [security2:error] [pid 171532:tid 171789] [client 188.166.209.66:55825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-theme-json.php"] [unique_id "al4kPUEhLvMuMRNpl03sBgAAAYg"], referer: binance.com
[Mon Jul 20 07:35:58.283394 2026] [security2:error] [pid 164535:tid 164755] [client 139.28.219.68:40886] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4kPjYN371eKRzcKeRx4AAAAN8"]
[Mon Jul 20 07:35:58.381216 2026] [security2:error] [pid 164535:tid 164695] [client 57.141.18.85:45132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kPTYN371eKRzcKeRxzgAAo0g"]
[Mon Jul 20 07:35:58.486608 2026] [security2:error] [pid 164535:tid 164686] [client 104.234.53.81:41033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kPjYN371eKRzcKeRx7AAAAJo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:35:58.899318 2026] [security2:error] [pid 171532:tid 171726] [client 139.28.219.68:40896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.219.28.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "claysharecon.com"] [uri "/xmlrpc.php"] [unique_id "al4kPkEhLvMuMRNpl03sJwAAAUo"]
[Mon Jul 20 07:35:59.005265 2026] [security2:error] [pid 164535:tid 164772] [client 57.141.18.84:23328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kPjYN371eKRzcKeRx5wAA8FM"]
[Mon Jul 20 07:35:59.292158 2026] [security2:error] [pid 164535:tid 164596] [remote 188.40.28.4:40874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4kPzYN371eKRzcKeRyFwAA_Tw"]
[Mon Jul 20 07:35:59.388875 2026] [security2:error] [pid 164535:tid 164782] [client 143.44.185.218:55184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kPzYN371eKRzcKeRyGQAAAPo"]
[Mon Jul 20 07:35:59.388983 2026] [security2:error] [pid 164535:tid 164782] [client 143.44.185.218:55184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kPzYN371eKRzcKeRyGQAAAPo"]
[Mon Jul 20 07:35:59.434776 2026] [security2:error] [pid 164535:tid 164726] [client 49.47.218.174:65367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kPzYN371eKRzcKeRyGgAAAMI"]
[Mon Jul 20 07:35:59.435139 2026] [security2:error] [pid 164535:tid 164726] [client 49.47.218.174:65367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kPzYN371eKRzcKeRyGgAAAMI"]
[Mon Jul 20 07:35:59.499177 2026] [security2:error] [pid 164535:tid 164547] [remote 188.40.28.4:40874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4kPzYN371eKRzcKeRyHwAA3ws"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:35:59.517677 2026] [security2:error] [pid 164535:tid 164667] [client 139.28.219.68:40908] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4kPzYN371eKRzcKeRyIQAAAIc"]
[Mon Jul 20 07:35:59.770245 2026] [security2:error] [pid 164535:tid 164695] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kPzYN371eKRzcKeRyJAAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:00.106368 2026] [security2:error] [pid 164535:tid 164757] [client 139.28.219.68:40916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4kQDYN371eKRzcKeRyPgAAAOE"]
[Mon Jul 20 07:36:00.134330 2026] [security2:error] [pid 171532:tid 171774] [client 157.20.138.62:56466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kQEEhLvMuMRNpl03sUAAAAXk"]
[Mon Jul 20 07:36:00.134862 2026] [security2:error] [pid 171532:tid 171774] [client 157.20.138.62:56466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kQEEhLvMuMRNpl03sUAAAAXk"]
[Mon Jul 20 07:36:00.167323 2026] [security2:error] [pid 171532:tid 171787] [client 149.0.16.108:60084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kQEEhLvMuMRNpl03sUgAAAYY"]
[Mon Jul 20 07:36:00.167423 2026] [security2:error] [pid 171532:tid 171787] [client 149.0.16.108:60084] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kQEEhLvMuMRNpl03sUgAAAYY"]
[Mon Jul 20 07:36:00.211605 2026] [security2:error] [pid 164535:tid 164690] [client 14.225.17.146:60261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4kPjYN371eKRzcKeRx_gAAAJ4"], referer: http://ghivs.com/demo
[Mon Jul 20 07:36:00.216963 2026] [security2:error] [pid 164535:tid 164770] [client 103.139.191.61:53615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kQDYN371eKRzcKeRyQwAAAO4"]
[Mon Jul 20 07:36:00.217089 2026] [security2:error] [pid 164535:tid 164770] [client 103.139.191.61:53615] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kQDYN371eKRzcKeRyQwAAAO4"]
[Mon Jul 20 07:36:00.349901 2026] [security2:error] [pid 164535:tid 164765] [client 57.141.18.43:46122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kPzYN371eKRzcKeRyMQAA6Vw"]
[Mon Jul 20 07:36:00.368937 2026] [security2:error] [pid 164535:tid 164739] [client 142.111.152.66:30027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kQDYN371eKRzcKeRyQgAAAM8"]
[Mon Jul 20 07:36:00.432407 2026] [security2:error] [pid 164535:tid 164734] [client 57.141.18.63:32604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kPzYN371eKRzcKeRyNwAAykQ"]
[Mon Jul 20 07:36:00.634244 2026] [security2:error] [pid 171532:tid 171667] [client 57.141.18.38:45828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQEEhLvMuMRNpl03sUQABDyo"]
[Mon Jul 20 07:36:00.683554 2026] [security2:error] [pid 164535:tid 164676] [client 139.28.219.68:40928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4kQDYN371eKRzcKeRyUQAAAJA"]
[Mon Jul 20 07:36:00.705722 2026] [security2:error] [pid 171532:tid 171737] [client 213.111.158.220:19288] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "oohlovely.com"] [uri "/"] [unique_id "al4kQEEhLvMuMRNpl03sZgAAAVU"]
[Mon Jul 20 07:36:01.189209 2026] [security2:error] [pid 164535:tid 164753] [client 57.141.18.71:59328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQDYN371eKRzcKeRyTQAA3Xo"]
[Mon Jul 20 07:36:01.291563 2026] [security2:error] [pid 171532:tid 171744] [client 57.141.18.24:45840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQEEhLvMuMRNpl03saQABXDI"]
[Mon Jul 20 07:36:01.294185 2026] [security2:error] [pid 164535:tid 164588] [remote 124.55.178.99:39114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kQTYN371eKRzcKeRyZwAA-jQ"]
[Mon Jul 20 07:36:01.316458 2026] [security2:error] [pid 171532:tid 171719] [client 139.28.219.68:40932] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4kQUEhLvMuMRNpl03sjwAAAUM"]
[Mon Jul 20 07:36:01.688770 2026] [security2:error] [pid 164535:tid 164730] [client 36.93.152.155:65064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kQTYN371eKRzcKeRyfQAAAMY"]
[Mon Jul 20 07:36:01.688886 2026] [security2:error] [pid 164535:tid 164730] [client 36.93.152.155:65064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kQTYN371eKRzcKeRyfQAAAMY"]
[Mon Jul 20 07:36:01.717815 2026] [security2:error] [pid 164535:tid 164645] [remote 124.55.178.99:39114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kQTYN371eKRzcKeRygQAAw20"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:36:01.762601 2026] [security2:error] [pid 171532:tid 171591] [remote 154.66.198.148:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kQUEhLvMuMRNpl03slwABdzo"]
[Mon Jul 20 07:36:01.818964 2026] [security2:error] [pid 171532:tid 171772] [client 154.192.123.127:17853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kQUEhLvMuMRNpl03smgAAAXg"]
[Mon Jul 20 07:36:01.819176 2026] [security2:error] [pid 171532:tid 171772] [client 154.192.123.127:17853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kQUEhLvMuMRNpl03smgAAAXg"]
[Mon Jul 20 07:36:01.945490 2026] [security2:error] [pid 164535:tid 164677] [client 139.28.219.68:40938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4kQTYN371eKRzcKeRygwAAAJE"]
[Mon Jul 20 07:36:02.184477 2026] [security2:error] [pid 164535:tid 164768] [client 13.233.207.33:25798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kQjYN371eKRzcKeRyjAAAAOw"]
[Mon Jul 20 07:36:02.300183 2026] [security2:error] [pid 171532:tid 171597] [remote 154.66.198.148:46444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kQkEhLvMuMRNpl03srAABDkA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:36:02.301878 2026] [security2:error] [pid 171532:tid 171712] [client 50.116.65.227:38140] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4kQkEhLvMuMRNpl03srQAAATw"]
[Mon Jul 20 07:36:02.313908 2026] [security2:error] [pid 171532:tid 171777] [client 50.116.65.227:49752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4kQkEhLvMuMRNpl03srgAAAWM"]
[Mon Jul 20 07:36:02.376032 2026] [security2:error] [pid 171532:tid 171723] [client 104.234.53.48:51849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 48.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kQkEhLvMuMRNpl03ssAAAAUc"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:02.385837 2026] [security2:error] [pid 171532:tid 171745] [client 57.141.18.86:39268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQUEhLvMuMRNpl03smAABXUE"]
[Mon Jul 20 07:36:02.414946 2026] [security2:error] [pid 164535:tid 164607] [remote 202.51.202.242:48298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4kQjYN371eKRzcKeRylwAA-Ec"]
[Mon Jul 20 07:36:02.535903 2026] [security2:error] [pid 164535:tid 164708] [client 139.28.219.68:40954] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4kQjYN371eKRzcKeRymgAAALA"]
[Mon Jul 20 07:36:02.542214 2026] [security2:error] [pid 171532:tid 171708] [client 188.166.209.66:64910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-token-map.php"] [unique_id "al4kQkEhLvMuMRNpl03svQAAATg"], referer: binance.com
[Mon Jul 20 07:36:02.633700 2026] [security2:error] [pid 171532:tid 171776] [client 103.106.165.44:53968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kQkEhLvMuMRNpl03sxAAAAXs"]
[Mon Jul 20 07:36:02.633869 2026] [security2:error] [pid 171532:tid 171776] [client 103.106.165.44:53968] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kQkEhLvMuMRNpl03sxAAAAXs"]
[Mon Jul 20 07:36:02.761676 2026] [security2:error] [pid 164535:tid 164546] [remote 103.133.214.160:42872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.214.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4kQjYN371eKRzcKeRynwAAhwo"]
[Mon Jul 20 07:36:02.838143 2026] [security2:error] [pid 171532:tid 171756] [client 46.110.96.34:33944] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kQkEhLvMuMRNpl03s1AAAAWg"]
[Mon Jul 20 07:36:02.876275 2026] [security2:error] [pid 164535:tid 164779] [client 46.110.96.34:21014] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kQjYN371eKRzcKeRypAAAAPc"]
[Mon Jul 20 07:36:03.108714 2026] [security2:error] [pid 171532:tid 171779] [client 57.141.18.3:50114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQkEhLvMuMRNpl03srwABfkU"]
[Mon Jul 20 07:36:03.121664 2026] [security2:error] [pid 164535:tid 164665] [client 13.233.207.33:25806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kQzYN371eKRzcKeRyrgAAAIU"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:36:03.153819 2026] [security2:error] [pid 171532:tid 171766] [client 139.28.219.68:40970] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4kQ0EhLvMuMRNpl03s4gAAAXI"]
[Mon Jul 20 07:36:03.199317 2026] [security2:error] [pid 171532:tid 171753] [client 191.25.199.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4kQkEhLvMuMRNpl03s0wAAAWU"]
[Mon Jul 20 07:36:03.215623 2026] [security2:error] [pid 164535:tid 164571] [remote 103.133.214.160:42872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.214.133.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4kQzYN371eKRzcKeRytgAA0CM"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:36:03.399613 2026] [security2:error] [pid 171532:tid 171705] [client 57.141.18.25:31720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQkEhLvMuMRNpl03sywABNUM"]
[Mon Jul 20 07:36:03.602212 2026] [security2:error] [pid 164535:tid 164765] [client 136.158.60.21:3079] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kQzYN371eKRzcKeRyxQAAAOk"]
[Mon Jul 20 07:36:03.602347 2026] [security2:error] [pid 164535:tid 164765] [client 136.158.60.21:3079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kQzYN371eKRzcKeRyxQAAAOk"]
[Mon Jul 20 07:36:03.732828 2026] [security2:error] [pid 171532:tid 171725] [client 139.28.219.68:40974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4kQ0EhLvMuMRNpl03s_AAAAUk"]
[Mon Jul 20 07:36:03.995303 2026] [security2:error] [pid 171532:tid 171690] [client 14.225.17.146:53227] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4kQkEhLvMuMRNpl03svgAAASY"], referer: http://detroitcsc.com/demo
[Mon Jul 20 07:36:04.053281 2026] [security2:error] [pid 164535:tid 164746] [client 191.202.66.27:51086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kRDYN371eKRzcKeRy1QAAANY"]
[Mon Jul 20 07:36:04.053424 2026] [security2:error] [pid 164535:tid 164746] [client 191.202.66.27:51086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kRDYN371eKRzcKeRy1QAAANY"]
[Mon Jul 20 07:36:04.091208 2026] [security2:error] [pid 164535:tid 164762] [client 131.153.225.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4kQzYN371eKRzcKeRyvwAAAOY"]
[Mon Jul 20 07:36:04.093549 2026] [security2:error] [pid 171532:tid 171741] [client 131.153.225.18:53106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/getBizIQData.php"] [unique_id "al4kQ0EhLvMuMRNpl03s7AAAAVk"]
[Mon Jul 20 07:36:04.212968 2026] [security2:error] [pid 164535:tid 164709] [client 57.141.18.54:48506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kQzYN371eKRzcKeRywgAAsU4"]
[Mon Jul 20 07:36:04.366667 2026] [security2:error] [pid 164535:tid 164748] [client 139.28.219.68:40978] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4kRDYN371eKRzcKeRy5gAAANg"]
[Mon Jul 20 07:36:04.407640 2026] [security2:error] [pid 164535:tid 164752] [client 14.182.195.220:52796] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kRDYN371eKRzcKeRy6AAAANw"]
[Mon Jul 20 07:36:04.415582 2026] [security2:error] [pid 171532:tid 171662] [client 14.182.195.220:52794] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kREEhLvMuMRNpl03tGQAAAQo"]
[Mon Jul 20 07:36:04.415762 2026] [security2:error] [pid 171532:tid 171698] [client 14.182.195.220:52795] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kREEhLvMuMRNpl03tGgAAAS4"]
[Mon Jul 20 07:36:04.427066 2026] [security2:error] [pid 164535:tid 164642] [remote 202.51.202.242:48298] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4kRDYN371eKRzcKeRy6QAAyWo"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:36:04.434889 2026] [security2:error] [pid 164535:tid 164719] [client 131.153.225.18:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4kRDYN371eKRzcKeRy2gAAALs"]
[Mon Jul 20 07:36:04.474836 2026] [security2:error] [pid 171532:tid 171787] [client 131.153.225.18:53122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/getBizIQData.php"] [unique_id "al4kREEhLvMuMRNpl03tDQAAAYY"]
[Mon Jul 20 07:36:04.787678 2026] [security2:error] [pid 164535:tid 164680] [client 103.176.215.66:59063] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kRDYN371eKRzcKeRy_AAAAJQ"]
[Mon Jul 20 07:36:04.788111 2026] [security2:error] [pid 164535:tid 164680] [client 103.176.215.66:59063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kRDYN371eKRzcKeRy_AAAAJQ"]
[Mon Jul 20 07:36:04.800237 2026] [security2:error] [pid 164535:tid 164741] [client 52.187.75.220:5441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "msoid.quangminhltd.vn"] [uri "/index.cgi"] [unique_id "al4kRDYN371eKRzcKeRy_QAAANE"]
[Mon Jul 20 07:36:04.812167 2026] [proxy:error] [pid 171532:tid 171692] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:36:04.812207 2026] [proxy_http:error] [pid 171532:tid 171692] [client 198.235.24.47:61246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:36:04.813162 2026] [proxy:error] [pid 171532:tid 171692] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:36:04.813192 2026] [proxy_http:error] [pid 171532:tid 171692] [client 198.235.24.47:61246] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:36:04.884242 2026] [security2:error] [pid 171532:tid 171705] [client 179.127.84.238:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kREEhLvMuMRNpl03tLQAAATU"]
[Mon Jul 20 07:36:04.884624 2026] [security2:error] [pid 171532:tid 171705] [client 179.127.84.238:54340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kREEhLvMuMRNpl03tLQAAATU"]
[Mon Jul 20 07:36:04.982978 2026] [security2:error] [pid 164535:tid 164759] [client 52.187.75.220:5441] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "msoid.quangminhltd.vn"] [uri "/404.html"] [unique_id "al4kRDYN371eKRzcKeRzAgAAAOM"]
[Mon Jul 20 07:36:04.991830 2026] [security2:error] [pid 164535:tid 164734] [client 139.28.219.68:40990] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4kRDYN371eKRzcKeRzBQAAAMo"]
[Mon Jul 20 07:36:05.053222 2026] [core:error] [pid 171532:tid 171722] [client 66.249.77.200:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:36:05.053242 2026] [core:error] [pid 171532:tid 171722] [client 66.249.77.200:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:36:05.079947 2026] [security2:error] [pid 164535:tid 164769] [client 45.3.42.175:35203] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 175.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kRTYN371eKRzcKeRzDAAAAO0"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:36:05.176454 2026] [security2:error] [pid 164535:tid 164766] [client 57.141.18.68:36082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kRDYN371eKRzcKeRy7wAA6i0"]
[Mon Jul 20 07:36:05.250349 2026] [security2:error] [pid 171532:tid 171711] [client 14.225.17.146:52797] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4kQkEhLvMuMRNpl03syAAAATs"], referer: http://drewsasburyparkbeachhouse.com/demo
[Mon Jul 20 07:36:05.441986 2026] [security2:error] [pid 164535:tid 164696] [client 45.157.112.60:29379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kRTYN371eKRzcKeRzJgAAAKQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:36:05.626024 2026] [security2:error] [pid 164535:tid 164748] [client 139.28.219.68:40998] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4kRTYN371eKRzcKeRzLAAAANg"]
[Mon Jul 20 07:36:05.889598 2026] [security2:error] [pid 164535:tid 164754] [client 14.225.17.146:54748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4kRTYN371eKRzcKeRzKgAAAN4"], referer: http://idigress.studio/demo
[Mon Jul 20 07:36:06.056696 2026] [security2:error] [pid 164535:tid 164731] [client 57.141.18.28:32212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kRTYN371eKRzcKeRzIgAAxyE"]
[Mon Jul 20 07:36:06.256345 2026] [security2:error] [pid 171532:tid 171733] [client 139.28.219.68:56212] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4kRkEhLvMuMRNpl03tZwAAAVE"]
[Mon Jul 20 07:36:06.364407 2026] [security2:error] [pid 171532:tid 171778] [client 57.141.18.41:62530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kRUEhLvMuMRNpl03tRAABfWQ"]
[Mon Jul 20 07:36:06.397707 2026] [security2:error] [pid 164535:tid 164668] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kRjYN371eKRzcKeRzPQAAAIg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:06.488817 2026] [security2:error] [pid 171532:tid 171709] [client 57.141.18.105:53712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kRUEhLvMuMRNpl03tSQABOWc"]
[Mon Jul 20 07:36:06.798618 2026] [security2:error] [pid 164535:tid 164769] [client 14.225.17.146:58478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4kRjYN371eKRzcKeRzWQAAAO0"], referer: http://709fx.com/demo
[Mon Jul 20 07:36:06.870075 2026] [security2:error] [pid 164535:tid 164778] [client 139.28.219.68:56214] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4kRjYN371eKRzcKeRzaAAAAPY"]
[Mon Jul 20 07:36:07.044070 2026] [security2:error] [pid 171532:tid 171768] [client 139.59.118.64:59741] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kR0EhLvMuMRNpl03tfAAAAXQ"]
[Mon Jul 20 07:36:07.134427 2026] [security2:error] [pid 171532:tid 171649] [remote 72.167.132.114:40318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kR0EhLvMuMRNpl03tfgABaXQ"]
[Mon Jul 20 07:36:07.187167 2026] [security2:error] [pid 171532:tid 171683] [client 57.141.18.29:34300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kRkEhLvMuMRNpl03tagABH24"]
[Mon Jul 20 07:36:07.299774 2026] [security2:error] [pid 164535:tid 164748] [client 104.207.50.219:31237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kRzYN371eKRzcKeRzbwAAANg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:07.370800 2026] [security2:error] [pid 171532:tid 171655] [remote 202.51.202.242:55848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4kR0EhLvMuMRNpl03tjQABIXo"]
[Mon Jul 20 07:36:07.383150 2026] [security2:error] [pid 171532:tid 171656] [remote 72.167.132.114:40318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kR0EhLvMuMRNpl03tjgABfHs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:36:07.459857 2026] [security2:error] [pid 171532:tid 171670] [client 139.28.219.68:56216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4kR0EhLvMuMRNpl03tmgAAARI"]
[Mon Jul 20 07:36:07.497676 2026] [security2:error] [pid 171532:tid 171686] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kR0EhLvMuMRNpl03tiAAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:07.534662 2026] [security2:error] [pid 164535:tid 164606] [remote 162.19.246.208:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4kRzYN371eKRzcKeRzeAAA0UY"]
[Mon Jul 20 07:36:07.594617 2026] [security2:error] [pid 171532:tid 171714] [client 104.234.53.68:29371] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kR0EhLvMuMRNpl03togAAAT4"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:07.732197 2026] [security2:error] [pid 171532:tid 171769] [client 139.59.118.64:59888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4kR0EhLvMuMRNpl03tqgAAAXU"]
[Mon Jul 20 07:36:07.754895 2026] [security2:error] [pid 164535:tid 164563] [remote 162.19.246.208:35324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4kRzYN371eKRzcKeRzgAAAxBs"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:36:07.982355 2026] [security2:error] [pid 171532:tid 171771] [client 57.141.18.39:53863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kR0EhLvMuMRNpl03tggABd3Y"]
[Mon Jul 20 07:36:08.041164 2026] [security2:error] [pid 171532:tid 171742] [client 139.28.219.68:56230] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "claysharecon.com"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4kSEEhLvMuMRNpl03trwAAAVo"]
[Mon Jul 20 07:36:08.125648 2026] [security2:error] [pid 171532:tid 171729] [client 188.166.209.66:50048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wp-url-pattern-prefixer.php"] [unique_id "al4kSEEhLvMuMRNpl03tsgAAAU0"], referer: binance.com
[Mon Jul 20 07:36:08.256863 2026] [security2:error] [pid 171532:tid 171652] [remote 202.51.202.242:55848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/wp-login.php"] [unique_id "al4kSEEhLvMuMRNpl03tuwABSXc"], referer: https://walkingandtalking.net/wp-login.php
[Mon Jul 20 07:36:08.482540 2026] [security2:error] [pid 171532:tid 171667] [client 50.116.65.227:49856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kSEEhLvMuMRNpl03tyAAAAQ8"]
[Mon Jul 20 07:36:08.491826 2026] [security2:error] [pid 171532:tid 171776] [client 180.249.173.210:51928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kSEEhLvMuMRNpl03tygAAAXs"]
[Mon Jul 20 07:36:08.492616 2026] [security2:error] [pid 171532:tid 171776] [client 180.249.173.210:51928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kSEEhLvMuMRNpl03tygAAAXs"]
[Mon Jul 20 07:36:08.492738 2026] [security2:error] [pid 171532:tid 171774] [client 50.116.65.227:49864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kSEEhLvMuMRNpl03tyQAAAXk"]
[Mon Jul 20 07:36:08.720939 2026] [security2:error] [pid 171532:tid 171673] [client 45.3.54.174:33685] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kSEEhLvMuMRNpl03t0AAAARU"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:08.793123 2026] [security2:error] [pid 171532:tid 171744] [client 14.225.17.146:59905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4kSEEhLvMuMRNpl03tzQAAAVw"], referer: http://taskidsvirginia.com/demo
[Mon Jul 20 07:36:08.962053 2026] [security2:error] [pid 171532:tid 171751] [client 116.179.33.139:55391] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.mollycahill.com"] [uri "/"] [unique_id "al4kSEEhLvMuMRNpl03t4AAAAWM"]
[Mon Jul 20 07:36:09.038328 2026] [security2:error] [pid 171532:tid 171759] [client 14.225.17.146:60508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4kR0EhLvMuMRNpl03tnwAAAWs"], referer: http://blaizeaccountingservices.com/demo
[Mon Jul 20 07:36:09.046656 2026] [security2:error] [pid 171532:tid 171699] [client 50.116.65.227:49902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4kSEEhLvMuMRNpl03t2QAAAS8"]
[Mon Jul 20 07:36:09.218457 2026] [security2:error] [pid 171532:tid 171728] [client 57.141.18.76:23034] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kSEEhLvMuMRNpl03tvQABTAQ"]
[Mon Jul 20 07:36:09.243075 2026] [security2:error] [pid 171532:tid 171768] [client 50.116.65.227:38556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4kSUEhLvMuMRNpl03t6AAAAXQ"]
[Mon Jul 20 07:36:09.366939 2026] [security2:error] [pid 164535:tid 164788] [client 139.59.118.64:60258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4kSTYN371eKRzcKeRztgAAAQA"]
[Mon Jul 20 07:36:09.685649 2026] [security2:error] [pid 164535:tid 164731] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kSTYN371eKRzcKeRzvQAAAMc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:09.957012 2026] [security2:error] [pid 164535:tid 164720] [client 49.47.218.174:54939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kSTYN371eKRzcKeRz1QAAALw"]
[Mon Jul 20 07:36:09.957131 2026] [security2:error] [pid 164535:tid 164720] [client 49.47.218.174:54939] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kSTYN371eKRzcKeRz1QAAALw"]
[Mon Jul 20 07:36:10.161876 2026] [security2:error] [pid 171532:tid 171686] [client 14.225.17.146:60559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4kSUEhLvMuMRNpl03t-QAAASI"]
[Mon Jul 20 07:36:10.211456 2026] [security2:error] [pid 171532:tid 171761] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kSUEhLvMuMRNpl03uBwAAAW0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:10.346613 2026] [security2:error] [pid 164535:tid 164680] [client 57.141.18.32:37182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kSTYN371eKRzcKeRzvAAAlCo"]
[Mon Jul 20 07:36:10.554214 2026] [security2:error] [pid 164535:tid 164717] [client 157.20.138.62:57032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kSjYN371eKRzcKeRz7gAAALk"]
[Mon Jul 20 07:36:10.554350 2026] [security2:error] [pid 164535:tid 164717] [client 157.20.138.62:57032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kSjYN371eKRzcKeRz7gAAALk"]
[Mon Jul 20 07:36:10.677208 2026] [security2:error] [pid 171532:tid 171772] [client 20.29.126.15:10887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4kSkEhLvMuMRNpl03uLQAAAXg"]
[Mon Jul 20 07:36:10.677384 2026] [security2:error] [pid 171532:tid 171772] [client 20.29.126.15:10887] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4kSkEhLvMuMRNpl03uLQAAAXg"]
[Mon Jul 20 07:36:10.688029 2026] [security2:error] [pid 171532:tid 171693] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kSkEhLvMuMRNpl03uIAAAASk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:10.689052 2026] [security2:error] [pid 164535:tid 164776] [client 14.225.17.146:59481] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4kSjYN371eKRzcKeRz7QAAAPQ"], referer: http://fkconstructionfunding.com/demo
[Mon Jul 20 07:36:10.812910 2026] [security2:error] [pid 171532:tid 171779] [client 57.141.18.6:29306] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kSUEhLvMuMRNpl03uAQABfg4"]
[Mon Jul 20 07:36:10.826088 2026] [security2:error] [pid 171532:tid 171722] [client 149.0.16.108:60601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kSkEhLvMuMRNpl03uNAAAAUY"]
[Mon Jul 20 07:36:10.826201 2026] [security2:error] [pid 171532:tid 171722] [client 149.0.16.108:60601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kSkEhLvMuMRNpl03uNAAAAUY"]
[Mon Jul 20 07:36:10.968547 2026] [security2:error] [pid 171532:tid 171680] [client 155.2.215.95:37077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kSkEhLvMuMRNpl03uMgAAARw"]
[Mon Jul 20 07:36:10.970586 2026] [security2:error] [pid 164535:tid 164780] [client 57.141.18.52:31140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kSTYN371eKRzcKeRz1AAA-Aw"]
[Mon Jul 20 07:36:11.045401 2026] [security2:error] [pid 164535:tid 164713] [client 57.141.18.9:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kSjYN371eKRzcKeRz_gAAALU"]
[Mon Jul 20 07:36:11.211031 2026] [security2:error] [pid 171532:tid 171750] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/robots.txt"] [unique_id "al4kS0EhLvMuMRNpl03uVAAAAWI"]
[Mon Jul 20 07:36:11.213489 2026] [security2:error] [pid 164535:tid 164732] [client 5.102.173.71:41636] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/robots.txt"] [unique_id "al4kSzYN371eKRzcKeR0EgAAAMg"]
[Mon Jul 20 07:36:11.214421 2026] [security2:error] [pid 164535:tid 164739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kSjYN371eKRzcKeR0BQAAAM8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:11.259085 2026] [security2:error] [pid 171532:tid 171768] [client 20.29.126.15:13534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4kS0EhLvMuMRNpl03uVgAAAXQ"]
[Mon Jul 20 07:36:11.259218 2026] [security2:error] [pid 171532:tid 171768] [client 20.29.126.15:13534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4kS0EhLvMuMRNpl03uVgAAAXQ"]
[Mon Jul 20 07:36:11.319623 2026] [security2:error] [pid 171532:tid 171711] [client 14.225.17.146:60595] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4kSUEhLvMuMRNpl03uBAAAATs"], referer: http://elitetax-mi.com/demo
[Mon Jul 20 07:36:11.361011 2026] [security2:error] [pid 171532:tid 171739] [client 103.139.191.61:54097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kS0EhLvMuMRNpl03uWgAAAVc"]
[Mon Jul 20 07:36:11.361123 2026] [security2:error] [pid 171532:tid 171739] [client 103.139.191.61:54097] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kS0EhLvMuMRNpl03uWgAAAVc"]
[Mon Jul 20 07:36:11.436026 2026] [security2:error] [pid 171532:tid 171778] [client 188.166.209.66:52651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/class-wpdb.php"] [unique_id "al4kS0EhLvMuMRNpl03uXQAAAX0"], referer: binance.com
[Mon Jul 20 07:36:11.473218 2026] [security2:error] [pid 171532:tid 171779] [client 5.102.173.71:0] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/digital-millennium-copyright-act-notice/"] [unique_id "al4kS0EhLvMuMRNpl03uYAAAAX4"]
[Mon Jul 20 07:36:11.501347 2026] [security2:error] [pid 164535:tid 164774] [client 5.102.173.71:41636] ModSecurity: Warning. Matched phrase "Mojeek" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "301"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/digital-millennium-copyright-act-notice/"] [unique_id "al4kSzYN371eKRzcKeR0GgAAAPI"]
[Mon Jul 20 07:36:11.764304 2026] [security2:error] [pid 171532:tid 171722] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kS0EhLvMuMRNpl03uZQAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:11.872304 2026] [security2:error] [pid 171532:tid 171667] [client 57.141.18.47:56288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kSkEhLvMuMRNpl03uLwABDxM"]
[Mon Jul 20 07:36:12.033299 2026] [security2:error] [pid 171532:tid 171742] [client 49.37.242.14:60130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kTEEhLvMuMRNpl03ugwAAAVo"]
[Mon Jul 20 07:36:12.033415 2026] [security2:error] [pid 171532:tid 171742] [client 49.37.242.14:60130] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kTEEhLvMuMRNpl03ugwAAAVo"]
[Mon Jul 20 07:36:12.117886 2026] [security2:error] [pid 164535:tid 164636] [remote 57.141.18.28:31246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3379371"] [unique_id "al4kTDYN371eKRzcKeR0OAAAv2Q"]
[Mon Jul 20 07:36:12.170213 2026] [security2:error] [pid 164535:tid 164738] [client 36.93.152.155:49199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kTDYN371eKRzcKeR0PAAAAM4"]
[Mon Jul 20 07:36:12.170340 2026] [security2:error] [pid 164535:tid 164738] [client 36.93.152.155:49199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kTDYN371eKRzcKeR0PAAAAM4"]
[Mon Jul 20 07:36:12.187823 2026] [security2:error] [pid 171532:tid 171725] [client 20.29.126.15:3649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/wp.php"] [unique_id "al4kTEEhLvMuMRNpl03uhgAAAUk"]
[Mon Jul 20 07:36:12.187940 2026] [security2:error] [pid 171532:tid 171725] [client 20.29.126.15:3649] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/wp.php"] [unique_id "al4kTEEhLvMuMRNpl03uhgAAAUk"]
[Mon Jul 20 07:36:12.271335 2026] [security2:error] [pid 171532:tid 171724] [client 154.192.123.127:18392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kTEEhLvMuMRNpl03uhwAAAUg"]
[Mon Jul 20 07:36:12.271472 2026] [security2:error] [pid 171532:tid 171724] [client 154.192.123.127:18392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kTEEhLvMuMRNpl03uhwAAAUg"]
[Mon Jul 20 07:36:12.386001 2026] [security2:error] [pid 171532:tid 171689] [client 57.141.18.57:49838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kS0EhLvMuMRNpl03uVQABJRE"]
[Mon Jul 20 07:36:12.442546 2026] [security2:error] [pid 164535:tid 164701] [client 143.44.185.218:56565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kTDYN371eKRzcKeR0RAAAAKk"]
[Mon Jul 20 07:36:12.442662 2026] [security2:error] [pid 164535:tid 164701] [client 143.44.185.218:56565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kTDYN371eKRzcKeR0RAAAAKk"]
[Mon Jul 20 07:36:12.558021 2026] [security2:error] [pid 171532:tid 171665] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kTEEhLvMuMRNpl03uigAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:12.657089 2026] [security2:error] [pid 171532:tid 171785] [client 167.99.49.202:64846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4kTEEhLvMuMRNpl03umAAAAYQ"]
[Mon Jul 20 07:36:12.755617 2026] [security2:error] [pid 164535:tid 164592] [remote 47.86.33.52:29470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kTDYN371eKRzcKeR0VwAA5Dg"]
[Mon Jul 20 07:36:12.846933 2026] [security2:error] [pid 171532:tid 171744] [client 202.141.11.99:27463] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kTEEhLvMuMRNpl03ungAAAVw"]
[Mon Jul 20 07:36:12.847057 2026] [security2:error] [pid 171532:tid 171744] [client 202.141.11.99:27463] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kTEEhLvMuMRNpl03ungAAAVw"]
[Mon Jul 20 07:36:12.856823 2026] [security2:error] [pid 171532:tid 171711] [client 14.182.195.220:52798] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kTEEhLvMuMRNpl03unwAAATs"]
[Mon Jul 20 07:36:12.858264 2026] [security2:error] [pid 171532:tid 171742] [client 14.182.195.220:52799] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kTEEhLvMuMRNpl03uoAAAAVo"]
[Mon Jul 20 07:36:12.862884 2026] [security2:error] [pid 171532:tid 171780] [client 14.182.195.220:52800] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kTEEhLvMuMRNpl03uoQAAAX8"]
[Mon Jul 20 07:36:12.941949 2026] [security2:error] [pid 171532:tid 171667] [client 167.99.49.202:65014] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "www.headachescarpaltunnelfibromyalgia.com"] [uri "/wp-login.php"] [unique_id "al4kTEEhLvMuMRNpl03uogAAAQ8"]
[Mon Jul 20 07:36:13.122446 2026] [security2:error] [pid 164535:tid 164746] [client 57.141.18.58:39512] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kTDYN371eKRzcKeR0NAAA1nQ"]
[Mon Jul 20 07:36:13.195350 2026] [security2:error] [pid 164535:tid 164606] [remote 47.86.33.52:29470] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ouw.egd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kTTYN371eKRzcKeR0awAAwkY"], referer: https://ouw.egd.mybluehost.me/wp-login.php
[Mon Jul 20 07:36:13.313657 2026] [security2:error] [pid 164535:tid 164665] [client 223.109.252.170:57764] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/wood-carving/"] [unique_id "al4kTTYN371eKRzcKeR0cgAAAIU"]
[Mon Jul 20 07:36:13.313745 2026] [security2:error] [pid 164535:tid 164665] [client 223.109.252.170:57764] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/wood-carving/"] [unique_id "al4kTTYN371eKRzcKeR0cgAAAIU"]
[Mon Jul 20 07:36:13.666899 2026] [security2:error] [pid 171532:tid 171691] [client 147.53.122.99:41897] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kTUEhLvMuMRNpl03utAAAASc"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:13.667046 2026] [security2:error] [pid 171532:tid 171691] [client 147.53.122.99:41897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kTUEhLvMuMRNpl03utAAAASc"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:13.817961 2026] [security2:error] [pid 164535:tid 164766] [client 103.106.165.44:54460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kTTYN371eKRzcKeR0gAAAAOo"]
[Mon Jul 20 07:36:13.818073 2026] [security2:error] [pid 164535:tid 164766] [client 103.106.165.44:54460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kTTYN371eKRzcKeR0gAAAAOo"]
[Mon Jul 20 07:36:13.939041 2026] [security2:error] [pid 171532:tid 171771] [client 14.225.17.146:51539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4kTUEhLvMuMRNpl03uuwAAAXc"], referer: http://katsklar.com/demo
[Mon Jul 20 07:36:14.084042 2026] [security2:error] [pid 171532:tid 171749] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kTUEhLvMuMRNpl03uvgABYTE"], referer: http://aleishapenny.ca/demo
[Mon Jul 20 07:36:14.307627 2026] [security2:error] [pid 164535:tid 164785] [client 136.158.60.21:53893] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kTjYN371eKRzcKeR0mwAAAP0"]
[Mon Jul 20 07:36:14.307716 2026] [security2:error] [pid 164535:tid 164785] [client 136.158.60.21:53893] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kTjYN371eKRzcKeR0mwAAAP0"]
[Mon Jul 20 07:36:14.556657 2026] [security2:error] [pid 164535:tid 164695] [client 104.234.53.80:32941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kTjYN371eKRzcKeR0pgAAAKM"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:14.566551 2026] [security2:error] [pid 164535:tid 164726] [client 188.166.209.66:53986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/compat-utf8.php"] [unique_id "al4kTjYN371eKRzcKeR0pwAAAMI"], referer: binance.com
[Mon Jul 20 07:36:14.624942 2026] [security2:error] [pid 164535:tid 164727] [client 147.53.112.12:55101] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kTjYN371eKRzcKeR0pQAAAMM"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:14.625088 2026] [security2:error] [pid 164535:tid 164727] [client 147.53.112.12:55101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kTjYN371eKRzcKeR0pQAAAMM"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:14.694687 2026] [security2:error] [pid 164535:tid 164669] [client 191.202.66.27:51577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kTjYN371eKRzcKeR0sQAAAIk"]
[Mon Jul 20 07:36:14.694813 2026] [security2:error] [pid 164535:tid 164669] [client 191.202.66.27:51577] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kTjYN371eKRzcKeR0sQAAAIk"]
[Mon Jul 20 07:36:14.761729 2026] [security2:error] [pid 164535:tid 164761] [client 20.29.126.15:4042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/new.php"] [unique_id "al4kTjYN371eKRzcKeR0tgAAAOU"]
[Mon Jul 20 07:36:14.761864 2026] [security2:error] [pid 164535:tid 164761] [client 20.29.126.15:4042] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/new.php"] [unique_id "al4kTjYN371eKRzcKeR0tgAAAOU"]
[Mon Jul 20 07:36:14.951163 2026] [security2:error] [pid 164535:tid 164765] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kTjYN371eKRzcKeR0twAA6U0"], referer: https://aleishapenny.ca/demo
[Mon Jul 20 07:36:15.106809 2026] [security2:error] [pid 164535:tid 164710] [client 139.59.118.64:61352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4kTzYN371eKRzcKeR0vwAAALI"]
[Mon Jul 20 07:36:15.206753 2026] [security2:error] [pid 164535:tid 164627] [remote 182.77.62.24:42492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4kTzYN371eKRzcKeR0xAAAlFs"]
[Mon Jul 20 07:36:15.239861 2026] [security2:error] [pid 171532:tid 171772] [client 158.173.166.181:30277] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kT0EhLvMuMRNpl03vDgAAAXg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:36:15.251864 2026] [security2:error] [pid 164535:tid 164752] [client 103.176.215.66:59596] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kTzYN371eKRzcKeR0ywAAANw"]
[Mon Jul 20 07:36:15.252339 2026] [security2:error] [pid 164535:tid 164752] [client 103.176.215.66:59596] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kTzYN371eKRzcKeR0ywAAANw"]
[Mon Jul 20 07:36:15.481183 2026] [security2:error] [pid 164535:tid 164790] [client 104.234.53.77:27479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kTzYN371eKRzcKeR00QAAAQI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:15.574029 2026] [security2:error] [pid 164535:tid 164750] [client 57.141.18.38:46920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kTjYN371eKRzcKeR0lgAA2hM"]
[Mon Jul 20 07:36:15.669863 2026] [security2:error] [pid 171532:tid 171790] [client 66.249.64.44:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.scott-assist.com"] [uri "/index.php"] [unique_id "al4kT0EhLvMuMRNpl03vHwAAAYk"]
[Mon Jul 20 07:36:15.808336 2026] [security2:error] [pid 171532:tid 171745] [client 179.127.84.238:54890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kT0EhLvMuMRNpl03vNwAAAV0"]
[Mon Jul 20 07:36:15.808508 2026] [security2:error] [pid 171532:tid 171745] [client 179.127.84.238:54890] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kT0EhLvMuMRNpl03vNwAAAV0"]
[Mon Jul 20 07:36:15.933284 2026] [security2:error] [pid 164535:tid 164693] [client 72.14.95.104:61567] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kTzYN371eKRzcKeR04AAAAKE"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:15.933415 2026] [security2:error] [pid 164535:tid 164693] [client 72.14.95.104:61567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kTzYN371eKRzcKeR04AAAAKE"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:16.012135 2026] [security2:error] [pid 171532:tid 171642] [remote 103.152.165.165:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.165.152.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kT0EhLvMuMRNpl03vQgABDW0"]
[Mon Jul 20 07:36:16.388030 2026] [security2:error] [pid 171532:tid 171641] [remote 173.212.252.15:33780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kUEEhLvMuMRNpl03vWQABRGw"]
[Mon Jul 20 07:36:16.445015 2026] [security2:error] [pid 171532:tid 171650] [remote 103.152.165.165:3334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.165.152.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kUEEhLvMuMRNpl03vWgABanU"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:36:16.481358 2026] [security2:error] [pid 171532:tid 171707] [client 57.141.18.82:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kUEEhLvMuMRNpl03vVwAAATc"]
[Mon Jul 20 07:36:16.660156 2026] [security2:error] [pid 164535:tid 164696] [client 121.229.156.16:47338] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.guidehunting.com"] [uri "/"] [unique_id "al4kUDYN371eKRzcKeR0_gAAAKQ"]
[Mon Jul 20 07:36:16.660255 2026] [security2:error] [pid 164535:tid 164696] [client 121.229.156.16:47338] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.guidehunting.com"] [uri "/"] [unique_id "al4kUDYN371eKRzcKeR0_gAAAKQ"]
[Mon Jul 20 07:36:16.730004 2026] [security2:error] [pid 171532:tid 171732] [client 117.211.236.168:52393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kUEEhLvMuMRNpl03vZwAAAVA"]
[Mon Jul 20 07:36:16.730181 2026] [security2:error] [pid 171532:tid 171732] [client 117.211.236.168:52393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kUEEhLvMuMRNpl03vZwAAAVA"]
[Mon Jul 20 07:36:16.853567 2026] [security2:error] [pid 171532:tid 171688] [client 14.225.17.146:60880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4kT0EhLvMuMRNpl03vPQAAASQ"], referer: http://headachescarpaltunnelfibromyalgia.com/demo
[Mon Jul 20 07:36:16.865338 2026] [security2:error] [pid 164535:tid 164778] [client 170.199.229.192:8051] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kUDYN371eKRzcKeR1CgAAAPY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:16.865505 2026] [security2:error] [pid 164535:tid 164778] [client 170.199.229.192:8051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kUDYN371eKRzcKeR1CgAAAPY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:16.882766 2026] [security2:error] [pid 164535:tid 164639] [remote 182.77.62.24:42492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4kUDYN371eKRzcKeR1DwAAymc"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:36:16.973376 2026] [security2:error] [pid 171532:tid 171724] [client 20.29.126.15:3664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/wpls.php"] [unique_id "al4kUEEhLvMuMRNpl03veAAAAUg"]
[Mon Jul 20 07:36:16.973471 2026] [security2:error] [pid 171532:tid 171724] [client 20.29.126.15:3664] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/wpls.php"] [unique_id "al4kUEEhLvMuMRNpl03veAAAAUg"]
[Mon Jul 20 07:36:17.029972 2026] [security2:error] [pid 171532:tid 171655] [remote 173.212.252.15:33780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kUUEhLvMuMRNpl03veQABJXo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:36:17.204572 2026] [security2:error] [pid 171532:tid 171752] [client 77.110.127.138:52379] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/colour-work/feed/"] [unique_id "al4kUUEhLvMuMRNpl03vfwAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:17.369327 2026] [security2:error] [pid 164535:tid 164672] [client 158.173.89.95:61365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kUTYN371eKRzcKeR1GwAAAIw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:36:17.691335 2026] [security2:error] [pid 164535:tid 164671] [client 57.141.18.45:64866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUDYN371eKRzcKeR08wAAixI"]
[Mon Jul 20 07:36:17.839147 2026] [security2:error] [pid 171532:tid 171745] [client 170.199.229.192:52099] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kUUEhLvMuMRNpl03vlgAAAV0"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:17.839263 2026] [security2:error] [pid 171532:tid 171745] [client 170.199.229.192:52099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kUUEhLvMuMRNpl03vlgAAAV0"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:17.883990 2026] [security2:error] [pid 171532:tid 171700] [client 20.29.126.15:13642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/mjq.php"] [unique_id "al4kUUEhLvMuMRNpl03vmgAAATA"]
[Mon Jul 20 07:36:17.884070 2026] [security2:error] [pid 171532:tid 171700] [client 20.29.126.15:13642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/mjq.php"] [unique_id "al4kUUEhLvMuMRNpl03vmgAAATA"]
[Mon Jul 20 07:36:17.923744 2026] [security2:error] [pid 171532:tid 171704] [client 188.166.209.66:61166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/connectors.php"] [unique_id "al4kUUEhLvMuMRNpl03vnQAAATQ"], referer: binance.com
[Mon Jul 20 07:36:18.010048 2026] [security2:error] [pid 164535:tid 164685] [client 14.225.17.146:59459] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4kUDYN371eKRzcKeR0-QAAAJk"], referer: http://alexsandbergmusic.com/demo
[Mon Jul 20 07:36:18.169844 2026] [security2:error] [pid 164535:tid 164730] [client 57.141.18.107:34836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUDYN371eKRzcKeR1AgAAxhA"]
[Mon Jul 20 07:36:18.840179 2026] [security2:error] [pid 171532:tid 171674] [client 130.254.112.104:17205] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kUkEhLvMuMRNpl03vvwAAARY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:18.840864 2026] [security2:error] [pid 171532:tid 171674] [client 130.254.112.104:17205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kUkEhLvMuMRNpl03vvwAAARY"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:19.195844 2026] [security2:error] [pid 171532:tid 171684] [client 57.141.18.13:58066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUUEhLvMuMRNpl03vkwABIHk"]
[Mon Jul 20 07:36:19.267901 2026] [security2:error] [pid 164535:tid 164712] [client 57.141.18.66:56608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUTYN371eKRzcKeR1LgAAtE8"]
[Mon Jul 20 07:36:19.271122 2026] [security2:error] [pid 164535:tid 164714] [client 57.141.18.99:27508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUTYN371eKRzcKeR1MAAAtjc"]
[Mon Jul 20 07:36:19.492094 2026] [security2:error] [pid 164535:tid 164680] [client 104.234.53.81:46369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kUzYN371eKRzcKeR1bQAAAJQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:19.494272 2026] [security2:error] [pid 171532:tid 171740] [client 180.249.173.210:52403] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kU0EhLvMuMRNpl03v4gAAAVg"]
[Mon Jul 20 07:36:19.494547 2026] [security2:error] [pid 171532:tid 171740] [client 180.249.173.210:52403] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kU0EhLvMuMRNpl03v4gAAAVg"]
[Mon Jul 20 07:36:19.583115 2026] [security2:error] [pid 171532:tid 171772] [client 45.3.54.17:53227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kU0EhLvMuMRNpl03v5QAAAXg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:19.864518 2026] [security2:error] [pid 171532:tid 171697] [client 14.225.17.146:61074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4kU0EhLvMuMRNpl03v7QAAAS0"], referer: http://backandneckpainrelieflaceychiropractor.com/demo
[Mon Jul 20 07:36:19.963699 2026] [security2:error] [pid 171532:tid 171696] [client 20.29.126.15:12956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/class-t.api.php"] [unique_id "al4kU0EhLvMuMRNpl03v8wAAASw"]
[Mon Jul 20 07:36:19.963823 2026] [security2:error] [pid 171532:tid 171696] [client 20.29.126.15:12956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/class-t.api.php"] [unique_id "al4kU0EhLvMuMRNpl03v8wAAASw"]
[Mon Jul 20 07:36:19.995577 2026] [security2:error] [pid 171532:tid 171762] [client 167.160.75.243:2175] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kU0EhLvMuMRNpl03v8QAAAW4"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:19.995737 2026] [security2:error] [pid 171532:tid 171762] [client 167.160.75.243:2175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kU0EhLvMuMRNpl03v8QAAAW4"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:20.001071 2026] [security2:error] [pid 164535:tid 164728] [client 50.116.65.227:11522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kUzYN371eKRzcKeR1gwAAAMQ"]
[Mon Jul 20 07:36:20.011352 2026] [security2:error] [pid 164535:tid 164733] [client 50.116.65.227:11532] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kVDYN371eKRzcKeR1hAAAAMk"]
[Mon Jul 20 07:36:20.169521 2026] [security2:error] [pid 171532:tid 171758] [client 188.166.209.66:63563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/fonts.php"] [unique_id "al4kVEEhLvMuMRNpl03v_QAAAWo"], referer: binance.com
[Mon Jul 20 07:36:20.397934 2026] [security2:error] [pid 164535:tid 164711] [client 49.47.218.174:55477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kVDYN371eKRzcKeR1lAAAALM"]
[Mon Jul 20 07:36:20.398172 2026] [security2:error] [pid 164535:tid 164711] [client 49.47.218.174:55477] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kVDYN371eKRzcKeR1lAAAALM"]
[Mon Jul 20 07:36:20.660793 2026] [security2:error] [pid 164535:tid 164739] [client 14.225.17.146:60953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4kVDYN371eKRzcKeR1kQAAAM8"]
[Mon Jul 20 07:36:20.733448 2026] [security2:error] [pid 164535:tid 164788] [client 57.141.18.15:42954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUzYN371eKRzcKeR1ZgABAC4"]
[Mon Jul 20 07:36:21.029902 2026] [security2:error] [pid 171532:tid 171780] [client 20.29.126.15:3807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/plugins.php"] [unique_id "al4kVUEhLvMuMRNpl03wJgAAAX8"]
[Mon Jul 20 07:36:21.030001 2026] [security2:error] [pid 171532:tid 171780] [client 20.29.126.15:3807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/plugins.php"] [unique_id "al4kVUEhLvMuMRNpl03wJgAAAX8"]
[Mon Jul 20 07:36:21.041149 2026] [security2:error] [pid 171532:tid 171753] [client 104.234.53.68:32031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 68.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kVUEhLvMuMRNpl03wJwAAAWU"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:21.080218 2026] [security2:error] [pid 171532:tid 171778] [client 116.74.65.235:65233] ModSecurity: Access denied with code 406 (phase 2). Operator GT matched 0 at USER:bf_block. [file "/opt/mod_security/hg_rules.conf"] [line "1482"] [id "909121"] [msg "IP address blocked, too many xmlrpc.php failures"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4kVUEhLvMuMRNpl03wKQAAAX0"]
[Mon Jul 20 07:36:21.080326 2026] [security2:error] [pid 171532:tid 171778] [client 116.74.65.235:65233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "406"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4kVUEhLvMuMRNpl03wKQAAAX0"]
[Mon Jul 20 07:36:21.089676 2026] [security2:error] [pid 164535:tid 164779] [client 157.20.138.62:57587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kVTYN371eKRzcKeR1tAAAAPc"]
[Mon Jul 20 07:36:21.089774 2026] [security2:error] [pid 164535:tid 164779] [client 157.20.138.62:57587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kVTYN371eKRzcKeR1tAAAAPc"]
[Mon Jul 20 07:36:21.097129 2026] [security2:error] [pid 171532:tid 171692] [client 57.141.18.37:46750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kU0EhLvMuMRNpl03v6wABKA4"]
[Mon Jul 20 07:36:21.356361 2026] [security2:error] [pid 164535:tid 164755] [client 57.141.18.22:58818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kUzYN371eKRzcKeR1gAAA300"]
[Mon Jul 20 07:36:21.447875 2026] [security2:error] [pid 164535:tid 164759] [client 149.0.16.108:61118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kVTYN371eKRzcKeR1yAAAAOM"]
[Mon Jul 20 07:36:21.447971 2026] [security2:error] [pid 164535:tid 164759] [client 149.0.16.108:61118] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kVTYN371eKRzcKeR1yAAAAOM"]
[Mon Jul 20 07:36:21.520722 2026] [security2:error] [pid 164535:tid 164710] [client 155.2.215.81:46823] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kVTYN371eKRzcKeR1wQAAALI"]
[Mon Jul 20 07:36:21.568778 2026] [security2:error] [pid 164535:tid 164688] [client 66.146.238.242:3707] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kVTYN371eKRzcKeR1yQAAAJw"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:21.568881 2026] [security2:error] [pid 164535:tid 164688] [client 66.146.238.242:3707] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kVTYN371eKRzcKeR1yQAAAJw"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:21.968312 2026] [security2:error] [pid 164535:tid 164631] [remote 217.61.143.92:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4kVTYN371eKRzcKeR15gAAwl8"]
[Mon Jul 20 07:36:22.037048 2026] [security2:error] [pid 164535:tid 164675] [client 14.225.17.146:63183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4kVTYN371eKRzcKeR14gAAAI8"], referer: http://carolinapressurewashers.com/demo
[Mon Jul 20 07:36:22.058605 2026] [security2:error] [pid 171532:tid 171699] [client 57.141.18.48:60762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kVEEhLvMuMRNpl03wGwABLxY"]
[Mon Jul 20 07:36:22.130520 2026] [security2:error] [pid 171532:tid 171700] [client 20.29.126.15:10923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/jp.php"] [unique_id "al4kVkEhLvMuMRNpl03wSAAAATA"]
[Mon Jul 20 07:36:22.130605 2026] [security2:error] [pid 171532:tid 171700] [client 20.29.126.15:10923] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/jp.php"] [unique_id "al4kVkEhLvMuMRNpl03wSAAAATA"]
[Mon Jul 20 07:36:22.205999 2026] [security2:error] [pid 164535:tid 164579] [remote 217.61.143.92:49752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4kVjYN371eKRzcKeR18wAAqSs"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 07:36:22.218483 2026] [security2:error] [pid 164535:tid 164628] [remote 192.241.143.148:56174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4kVjYN371eKRzcKeR19QAAn1w"]
[Mon Jul 20 07:36:22.271207 2026] [security2:error] [pid 171532:tid 171703] [client 66.146.238.242:39711] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kVkEhLvMuMRNpl03wTQAAATM"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:22.271316 2026] [security2:error] [pid 171532:tid 171703] [client 66.146.238.242:39711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kVkEhLvMuMRNpl03wTQAAATM"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:22.376606 2026] [security2:error] [pid 164535:tid 164760] [client 103.139.191.61:54570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kVjYN371eKRzcKeR1-wAAAOQ"]
[Mon Jul 20 07:36:22.376731 2026] [security2:error] [pid 164535:tid 164760] [client 103.139.191.61:54570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kVjYN371eKRzcKeR1-wAAAOQ"]
[Mon Jul 20 07:36:22.435718 2026] [security2:error] [pid 164535:tid 164603] [remote 173.212.252.15:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4kVjYN371eKRzcKeR1_AAA8EM"]
[Mon Jul 20 07:36:22.463643 2026] [security2:error] [pid 164535:tid 164677] [client 14.225.17.146:61519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4kVjYN371eKRzcKeR17gAAAJE"]
[Mon Jul 20 07:36:22.554225 2026] [security2:error] [pid 164535:tid 164644] [remote 192.241.143.148:56174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-login.php"] [unique_id "al4kVjYN371eKRzcKeR2AAAAomw"], referer: https://ivetstrategies.com/wp-login.php
[Mon Jul 20 07:36:22.618936 2026] [security2:error] [pid 164535:tid 164617] [remote 173.212.252.15:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4kVjYN371eKRzcKeR2BAAArlE"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:36:22.688338 2026] [security2:error] [pid 171532:tid 171774] [client 36.93.152.155:49922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kVkEhLvMuMRNpl03wWgAAAXk"]
[Mon Jul 20 07:36:22.688438 2026] [security2:error] [pid 171532:tid 171774] [client 36.93.152.155:49922] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kVkEhLvMuMRNpl03wWgAAAXk"]
[Mon Jul 20 07:36:22.815824 2026] [security2:error] [pid 164535:tid 164676] [client 154.192.123.127:16905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kVjYN371eKRzcKeR2DQAAAJA"]
[Mon Jul 20 07:36:22.815976 2026] [security2:error] [pid 164535:tid 164676] [client 154.192.123.127:16905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kVjYN371eKRzcKeR2DQAAAJA"]
[Mon Jul 20 07:36:22.871592 2026] [security2:error] [pid 171532:tid 171758] [client 14.225.17.146:63355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4kVUEhLvMuMRNpl03wLwAAAWo"], referer: http://aandarealtygroup.com/demo
[Mon Jul 20 07:36:22.905711 2026] [security2:error] [pid 171532:tid 171756] [client 77.110.127.138:52403] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/colour-work/feed/"] [unique_id "al4kVkEhLvMuMRNpl03wYgAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:23.212594 2026] [security2:error] [pid 171532:tid 171776] [client 69.58.76.98:30261] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kV0EhLvMuMRNpl03wagAAAXs"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:23.212693 2026] [security2:error] [pid 171532:tid 171776] [client 69.58.76.98:30261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kV0EhLvMuMRNpl03wagAAAXs"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:23.248165 2026] [security2:error] [pid 164535:tid 164689] [client 188.166.209.66:58799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/global-styles-and-settings.php"] [unique_id "al4kVzYN371eKRzcKeR2GwAAAJ0"], referer: binance.com
[Mon Jul 20 07:36:23.397521 2026] [security2:error] [pid 171532:tid 171699] [client 46.110.96.34:21240] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kV0EhLvMuMRNpl03wdQAAAS8"]
[Mon Jul 20 07:36:23.462838 2026] [security2:error] [pid 171532:tid 171678] [client 57.141.18.9:25262] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kVUEhLvMuMRNpl03wOwABGiY"]
[Mon Jul 20 07:36:23.516421 2026] [security2:error] [pid 171532:tid 171783] [client 46.110.96.34:37814] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kV0EhLvMuMRNpl03whAAAAYI"]
[Mon Jul 20 07:36:23.520950 2026] [security2:error] [pid 171532:tid 171702] [client 202.141.11.99:37088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kV0EhLvMuMRNpl03whQAAATI"]
[Mon Jul 20 07:36:23.521104 2026] [security2:error] [pid 171532:tid 171702] [client 202.141.11.99:37088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kV0EhLvMuMRNpl03whQAAATI"]
[Mon Jul 20 07:36:23.574336 2026] [security2:error] [pid 164535:tid 164672] [client 14.225.17.146:61440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4kVzYN371eKRzcKeR2KQAAAIw"], referer: http://daseighty.net/demo
[Mon Jul 20 07:36:23.631740 2026] [security2:error] [pid 164535:tid 164773] [client 57.141.18.3:33164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kVTYN371eKRzcKeR16QAA8SE"]
[Mon Jul 20 07:36:23.653433 2026] [security2:error] [pid 171532:tid 171683] [client 103.106.165.44:55020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kV0EhLvMuMRNpl03wiwAAAR8"]
[Mon Jul 20 07:36:23.653568 2026] [security2:error] [pid 171532:tid 171683] [client 103.106.165.44:55020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kV0EhLvMuMRNpl03wiwAAAR8"]
[Mon Jul 20 07:36:24.034956 2026] [security2:error] [pid 171532:tid 171597] [remote 160.187.68.132:32864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kWEEhLvMuMRNpl03wqAABIUA"]
[Mon Jul 20 07:36:24.035182 2026] [security2:error] [pid 171532:tid 171685] [client 160.187.68.132:32864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kWEEhLvMuMRNpl03wqAABIUA"]
[Mon Jul 20 07:36:24.177785 2026] [security2:error] [pid 164535:tid 164691] [client 147.53.121.153:39169] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWDYN371eKRzcKeR2OQAAAJ8"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:24.177891 2026] [security2:error] [pid 164535:tid 164691] [client 147.53.121.153:39169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWDYN371eKRzcKeR2OQAAAJ8"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:24.322947 2026] [security2:error] [pid 171532:tid 171684] [client 20.29.126.15:13633] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/pu9.php"] [unique_id "al4kWEEhLvMuMRNpl03wtAAAASA"]
[Mon Jul 20 07:36:24.323030 2026] [security2:error] [pid 171532:tid 171684] [client 20.29.126.15:13633] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/pu9.php"] [unique_id "al4kWEEhLvMuMRNpl03wtAAAASA"]
[Mon Jul 20 07:36:24.365389 2026] [security2:error] [pid 171532:tid 171679] [client 104.234.53.69:51923] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 69.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kWEEhLvMuMRNpl03wtgAAARs"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:24.604705 2026] [security2:error] [pid 171532:tid 171732] [client 143.44.185.218:57843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kWEEhLvMuMRNpl03wvAAAAVA"]
[Mon Jul 20 07:36:24.604834 2026] [security2:error] [pid 171532:tid 171732] [client 143.44.185.218:57843] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kWEEhLvMuMRNpl03wvAAAAVA"]
[Mon Jul 20 07:36:24.967516 2026] [security2:error] [pid 171532:tid 171748] [client 136.158.60.21:55540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kWEEhLvMuMRNpl03w0QAAAWA"]
[Mon Jul 20 07:36:24.967627 2026] [security2:error] [pid 171532:tid 171748] [client 136.158.60.21:55540] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kWEEhLvMuMRNpl03w0QAAAWA"]
[Mon Jul 20 07:36:25.068725 2026] [security2:error] [pid 171532:tid 171720] [client 130.44.200.1:38715] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWEEhLvMuMRNpl03w0gAAAUQ"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:25.068894 2026] [security2:error] [pid 171532:tid 171720] [client 130.44.200.1:38715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWEEhLvMuMRNpl03w0gAAAUQ"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:25.172295 2026] [security2:error] [pid 164535:tid 164751] [client 20.29.126.15:9124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/error.php"] [unique_id "al4kWTYN371eKRzcKeR2XwAAANs"]
[Mon Jul 20 07:36:25.172397 2026] [security2:error] [pid 164535:tid 164751] [client 20.29.126.15:9124] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/error.php"] [unique_id "al4kWTYN371eKRzcKeR2XwAAANs"]
[Mon Jul 20 07:36:25.225656 2026] [security2:error] [pid 171532:tid 171734] [client 104.234.53.90:29915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kWUEhLvMuMRNpl03w3QAAAVI"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:25.286428 2026] [security2:error] [pid 164535:tid 164726] [client 57.141.18.124:36482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kVzYN371eKRzcKeR2JAAAwhY"]
[Mon Jul 20 07:36:25.348724 2026] [security2:error] [pid 171532:tid 171668] [client 57.141.18.52:37568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kV0EhLvMuMRNpl03wdgABECs"]
[Mon Jul 20 07:36:25.396183 2026] [security2:error] [pid 164535:tid 164689] [client 191.202.66.27:52066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kWTYN371eKRzcKeR2cQAAAJ0"]
[Mon Jul 20 07:36:25.396280 2026] [security2:error] [pid 164535:tid 164689] [client 191.202.66.27:52066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kWTYN371eKRzcKeR2cQAAAJ0"]
[Mon Jul 20 07:36:25.598676 2026] [security2:error] [pid 171532:tid 171689] [client 14.225.17.146:63185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4kWUEhLvMuMRNpl03w6AAAASU"], referer: http://alrowad-hub.net/demo
[Mon Jul 20 07:36:25.611086 2026] [security2:error] [pid 171532:tid 171767] [client 57.141.18.106:56934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kV0EhLvMuMRNpl03wiQABczE"]
[Mon Jul 20 07:36:25.762101 2026] [security2:error] [pid 164535:tid 164789] [client 14.225.17.146:63164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4kWTYN371eKRzcKeR2cAAAAQE"], referer: http://grecruit.online/demo
[Mon Jul 20 07:36:25.831167 2026] [security2:error] [pid 171532:tid 171702] [client 103.176.215.66:60120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kWUEhLvMuMRNpl03w_wAAATI"]
[Mon Jul 20 07:36:25.831331 2026] [security2:error] [pid 171532:tid 171702] [client 103.176.215.66:60120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kWUEhLvMuMRNpl03w_wAAATI"]
[Mon Jul 20 07:36:25.897339 2026] [security2:error] [pid 171532:tid 171709] [client 57.141.18.3:33174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kV0EhLvMuMRNpl03wowABOTY"]
[Mon Jul 20 07:36:25.914672 2026] [security2:error] [pid 164535:tid 164769] [client 130.44.200.1:52493] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWTYN371eKRzcKeR2gAAAAO0"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:25.914808 2026] [security2:error] [pid 164535:tid 164769] [client 130.44.200.1:52493] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWTYN371eKRzcKeR2gAAAAO0"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:26.158087 2026] [security2:error] [pid 164535:tid 164707] [client 188.166.209.66:62132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/https-detection.php"] [unique_id "al4kWjYN371eKRzcKeR2hgAAAK8"], referer: binance.com
[Mon Jul 20 07:36:26.289267 2026] [security2:error] [pid 171532:tid 171789] [client 14.225.17.146:63506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4kWUEhLvMuMRNpl03xAQAAAYg"], referer: http://partnerselectricalllc.com/demo
[Mon Jul 20 07:36:26.365686 2026] [security2:error] [pid 164535:tid 164763] [client 20.29.126.15:10942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/bdshell.php"] [unique_id "al4kWjYN371eKRzcKeR2jAAAAOc"]
[Mon Jul 20 07:36:26.365840 2026] [security2:error] [pid 164535:tid 164763] [client 20.29.126.15:10942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/bdshell.php"] [unique_id "al4kWjYN371eKRzcKeR2jAAAAOc"]
[Mon Jul 20 07:36:26.494172 2026] [security2:error] [pid 164535:tid 164755] [client 14.225.17.146:63690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4kWjYN371eKRzcKeR2iQAAAN8"], referer: http://amalia-capital.com/demo
[Mon Jul 20 07:36:26.891714 2026] [security2:error] [pid 171532:tid 171706] [client 57.141.18.12:64782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kWEEhLvMuMRNpl03wxAABNkQ"]
[Mon Jul 20 07:36:26.946193 2026] [security2:error] [pid 164535:tid 164788] [client 138.229.106.188:54929] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWjYN371eKRzcKeR2oAAAAQA"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:26.946297 2026] [security2:error] [pid 164535:tid 164788] [client 138.229.106.188:54929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kWjYN371eKRzcKeR2oAAAAQA"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:26.979159 2026] [security2:error] [pid 164535:tid 164756] [client 179.127.84.238:55436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kWjYN371eKRzcKeR2owAAAOA"]
[Mon Jul 20 07:36:26.979242 2026] [security2:error] [pid 164535:tid 164756] [client 179.127.84.238:55436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kWjYN371eKRzcKeR2owAAAOA"]
[Mon Jul 20 07:36:27.043308 2026] [security2:error] [pid 171532:tid 171764] [client 14.225.17.146:63154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4kWUEhLvMuMRNpl03w5wAAAXA"], referer: http://margaretspeckogawa.com/demo
[Mon Jul 20 07:36:27.160146 2026] [security2:error] [pid 171532:tid 171762] [client 57.141.18.111:43020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kWEEhLvMuMRNpl03w0wABbjw"]
[Mon Jul 20 07:36:27.219500 2026] [security2:error] [pid 171532:tid 171691] [client 158.140.70.49:59046] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4kW0EhLvMuMRNpl03xOQAAASc"]
[Mon Jul 20 07:36:27.347316 2026] [security2:error] [pid 171532:tid 171699] [client 57.141.18.22:58822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kWUEhLvMuMRNpl03w1AABL0I"]
[Mon Jul 20 07:36:27.573192 2026] [security2:error] [pid 164535:tid 164781] [client 49.37.242.14:60652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kWzYN371eKRzcKeR2sAAAAPk"]
[Mon Jul 20 07:36:27.573284 2026] [security2:error] [pid 164535:tid 164781] [client 49.37.242.14:60652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kWzYN371eKRzcKeR2sAAAAPk"]
[Mon Jul 20 07:36:28.090761 2026] [security2:error] [pid 171532:tid 171748] [client 104.234.53.90:33699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4kXEEhLvMuMRNpl03xbgAAAWA"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:28.095101 2026] [security2:error] [pid 171532:tid 171724] [client 138.229.100.234:63391] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kXEEhLvMuMRNpl03xawAAAUg"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:28.095203 2026] [security2:error] [pid 171532:tid 171724] [client 138.229.100.234:63391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kXEEhLvMuMRNpl03xawAAAUg"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:28.148794 2026] [security2:error] [pid 171532:tid 171541] [remote 100.42.189.89:35794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4kXEEhLvMuMRNpl03xcQABRQg"]
[Mon Jul 20 07:36:28.165002 2026] [security2:error] [pid 171532:tid 171700] [client 20.29.126.15:3804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/bitwise.php"] [unique_id "al4kXEEhLvMuMRNpl03xcwAAATA"]
[Mon Jul 20 07:36:28.165079 2026] [security2:error] [pid 171532:tid 171700] [client 20.29.126.15:3804] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/bitwise.php"] [unique_id "al4kXEEhLvMuMRNpl03xcwAAATA"]
[Mon Jul 20 07:36:28.342153 2026] [security2:error] [pid 171532:tid 171536] [remote 100.42.189.89:35794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4kXEEhLvMuMRNpl03xggABUAM"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:36:28.736442 2026] [security2:error] [pid 164535:tid 164696] [client 57.141.18.30:59792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kWjYN371eKRzcKeR2iAAApFM"]
[Mon Jul 20 07:36:28.790724 2026] [security2:error] [pid 171532:tid 171687] [client 188.166.209.66:58640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/https-migration.php"] [unique_id "al4kXEEhLvMuMRNpl03xnAAAASM"], referer: binance.com
[Mon Jul 20 07:36:28.902904 2026] [security2:error] [pid 171532:tid 171552] [remote 188.166.241.141:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4kXEEhLvMuMRNpl03xogABfxM"]
[Mon Jul 20 07:36:28.980509 2026] [security2:error] [pid 171532:tid 171713] [client 57.141.18.8:38184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kWkEhLvMuMRNpl03xKQABPVw"]
[Mon Jul 20 07:36:29.262372 2026] [security2:error] [pid 171532:tid 171558] [remote 188.166.241.141:53810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hedgerow-crafts.com"] [uri "/wp-login.php"] [unique_id "al4kXUEhLvMuMRNpl03xtgABIBk"], referer: https://hedgerow-crafts.com/wp-login.php
[Mon Jul 20 07:36:29.275121 2026] [security2:error] [pid 171532:tid 171663] [client 57.141.18.77:42132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kWkEhLvMuMRNpl03xMAABC2g"]
[Mon Jul 20 07:36:29.357357 2026] [security2:error] [pid 171532:tid 171717] [client 139.180.224.181:17337] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kXUEhLvMuMRNpl03xuAAAAUE"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:29.357455 2026] [security2:error] [pid 171532:tid 171717] [client 139.180.224.181:17337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4kXUEhLvMuMRNpl03xuAAAAUE"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/
[Mon Jul 20 07:36:29.499822 2026] [security2:error] [pid 171532:tid 171666] [client 20.29.126.15:16006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/BLaSTER.php"] [unique_id "al4kXUEhLvMuMRNpl03xyAAAAQ4"]
[Mon Jul 20 07:36:29.499923 2026] [security2:error] [pid 171532:tid 171666] [client 20.29.126.15:16006] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/BLaSTER.php"] [unique_id "al4kXUEhLvMuMRNpl03xyAAAAQ4"]
[Mon Jul 20 07:36:29.657301 2026] [security2:error] [pid 164535:tid 164723] [client 180.249.173.210:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kXTYN371eKRzcKeR3QwAAAL8"]
[Mon Jul 20 07:36:29.657465 2026] [security2:error] [pid 164535:tid 164723] [client 180.249.173.210:52867] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kXTYN371eKRzcKeR3QwAAAL8"]
[Mon Jul 20 07:36:29.897671 2026] [security2:error] [pid 171532:tid 171696] [client 57.141.18.96:51320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kW0EhLvMuMRNpl03xRgABLGQ"]
[Mon Jul 20 07:36:30.184272 2026] [security2:error] [pid 164535:tid 164769] [client 77.110.127.138:52432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/colour-work/feed/"] [unique_id "al4kXjYN371eKRzcKeR3TwAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:30.207959 2026] [security2:error] [pid 171532:tid 171590] [remote 91.142.222.105:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kXkEhLvMuMRNpl03x7AABVDk"]
[Mon Jul 20 07:36:30.298140 2026] [security2:error] [pid 171532:tid 171715] [client 57.141.18.99:28872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kW0EhLvMuMRNpl03xVQABP3A"]
[Mon Jul 20 07:36:30.377021 2026] [security2:error] [pid 171532:tid 171742] [client 117.211.236.168:53090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kXkEhLvMuMRNpl03x9QAAAVo"]
[Mon Jul 20 07:36:30.377115 2026] [security2:error] [pid 171532:tid 171742] [client 117.211.236.168:53090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kXkEhLvMuMRNpl03x9QAAAVo"]
[Mon Jul 20 07:36:30.487710 2026] [security2:error] [pid 171532:tid 171688] [client 65.111.23.13:58213] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kXkEhLvMuMRNpl03x-QAAASQ"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:30.488683 2026] [security2:error] [pid 171532:tid 171595] [remote 91.142.222.105:40358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kXkEhLvMuMRNpl03x_AABDj4"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:36:30.764727 2026] [security2:error] [pid 171532:tid 171687] [client 20.29.126.15:13636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/bloodsecv4.php"] [unique_id "al4kXkEhLvMuMRNpl03yBQAAASM"]
[Mon Jul 20 07:36:30.764849 2026] [security2:error] [pid 171532:tid 171687] [client 20.29.126.15:13636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/bloodsecv4.php"] [unique_id "al4kXkEhLvMuMRNpl03yBQAAASM"]
[Mon Jul 20 07:36:30.908175 2026] [security2:error] [pid 164535:tid 164666] [client 49.47.218.174:56015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kXjYN371eKRzcKeR3YgAAAIY"]
[Mon Jul 20 07:36:30.908299 2026] [security2:error] [pid 164535:tid 164666] [client 49.47.218.174:56015] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kXjYN371eKRzcKeR3YgAAAIY"]
[Mon Jul 20 07:36:31.048755 2026] [security2:error] [pid 171532:tid 171626] [remote 192.241.143.148:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kX0EhLvMuMRNpl03yEgABWV0"]
[Mon Jul 20 07:36:31.076584 2026] [security2:error] [pid 171532:tid 171621] [remote 57.141.18.111:22434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3600005"] [unique_id "al4kX0EhLvMuMRNpl03yFgABdFg"]
[Mon Jul 20 07:36:31.098404 2026] [security2:error] [pid 164535:tid 164732] [client 57.141.18.98:24078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kXDYN371eKRzcKeR3NAAAyAw"]
[Mon Jul 20 07:36:31.261978 2026] [security2:error] [pid 171532:tid 171615] [remote 192.241.143.148:50430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kX0EhLvMuMRNpl03yIAABP1I"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:36:31.282306 2026] [security2:error] [pid 171532:tid 171696] [client 104.234.53.88:47705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/index.php"] [unique_id "al4kX0EhLvMuMRNpl03yJAAAASw"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:31.460087 2026] [security2:error] [pid 164535:tid 164697] [client 188.166.209.66:50479] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/robots-template.php"] [unique_id "al4kXzYN371eKRzcKeR3dAAAAKU"], referer: binance.com
[Mon Jul 20 07:36:31.563095 2026] [security2:error] [pid 164535:tid 164727] [client 20.29.126.15:13638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/Bnkqbakq.php"] [unique_id "al4kXzYN371eKRzcKeR3fQAAAMM"]
[Mon Jul 20 07:36:31.563184 2026] [security2:error] [pid 164535:tid 164727] [client 20.29.126.15:13638] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/Bnkqbakq.php"] [unique_id "al4kXzYN371eKRzcKeR3fQAAAMM"]
[Mon Jul 20 07:36:31.652257 2026] [security2:error] [pid 171532:tid 171787] [client 157.20.138.62:58147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kX0EhLvMuMRNpl03yNgAAAYY"]
[Mon Jul 20 07:36:31.652363 2026] [security2:error] [pid 171532:tid 171787] [client 157.20.138.62:58147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kX0EhLvMuMRNpl03yNgAAAYY"]
[Mon Jul 20 07:36:31.946308 2026] [security2:error] [pid 164535:tid 164766] [client 45.3.54.141:40469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kXzYN371eKRzcKeR3hAAAAOo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:31.964723 2026] [security2:error] [pid 164535:tid 164689] [client 14.225.17.146:62909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4kXzYN371eKRzcKeR3ggAAAJ0"], referer: http://thefriendlyspreadsheet.com/demo
[Mon Jul 20 07:36:32.044163 2026] [security2:error] [pid 171532:tid 171731] [client 57.141.18.112:26932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kXUEhLvMuMRNpl03xvwABTyg"]
[Mon Jul 20 07:36:32.064096 2026] [security2:error] [pid 171532:tid 171722] [client 149.0.16.108:61636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kYEEhLvMuMRNpl03yTgAAAUY"]
[Mon Jul 20 07:36:32.064174 2026] [security2:error] [pid 171532:tid 171722] [client 149.0.16.108:61636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kYEEhLvMuMRNpl03yTgAAAUY"]
[Mon Jul 20 07:36:32.158843 2026] [security2:error] [pid 171532:tid 171662] [client 50.116.65.227:29538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kYEEhLvMuMRNpl03yVAAAAQo"]
[Mon Jul 20 07:36:32.159973 2026] [security2:error] [pid 164535:tid 164777] [client 155.2.215.94:34561] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kYDYN371eKRzcKeR3hwAAAPU"]
[Mon Jul 20 07:36:32.170798 2026] [security2:error] [pid 164535:tid 164774] [client 50.116.65.227:29552] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kYDYN371eKRzcKeR3iwAAAPI"]
[Mon Jul 20 07:36:32.204286 2026] [security2:error] [pid 164535:tid 164701] [client 116.193.128.26:65315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kYDYN371eKRzcKeR3jAAAAKk"]
[Mon Jul 20 07:36:32.204402 2026] [security2:error] [pid 164535:tid 164701] [client 116.193.128.26:65315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kYDYN371eKRzcKeR3jAAAAKk"]
[Mon Jul 20 07:36:32.207480 2026] [security2:error] [pid 164535:tid 164747] [client 14.225.17.146:62758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4kXjYN371eKRzcKeR3YAAAANc"], referer: http://bbwipartnerconference.com/demo
[Mon Jul 20 07:36:32.242606 2026] [security2:error] [pid 164535:tid 164739] [client 74.208.214.194:46166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4kYDYN371eKRzcKeR3jQAAAM8"]
[Mon Jul 20 07:36:32.839138 2026] [security2:error] [pid 171532:tid 171769] [client 104.207.61.61:41119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kYEEhLvMuMRNpl03ycQAAAXU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:36:32.858844 2026] [security2:error] [pid 171532:tid 171673] [client 113.160.97.242:50929] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kYEEhLvMuMRNpl03ycgAAARU"]
[Mon Jul 20 07:36:33.218731 2026] [security2:error] [pid 164535:tid 164683] [client 36.93.152.155:50594] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kYTYN371eKRzcKeR3mgAAAJc"]
[Mon Jul 20 07:36:33.218850 2026] [security2:error] [pid 164535:tid 164683] [client 36.93.152.155:50594] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kYTYN371eKRzcKeR3mgAAAJc"]
[Mon Jul 20 07:36:33.252554 2026] [security2:error] [pid 171532:tid 171680] [client 193.19.109.101:45321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 101.109.19.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4kYUEhLvMuMRNpl03yjAAAARw"]
[Mon Jul 20 07:36:33.321917 2026] [security2:error] [pid 171532:tid 171761] [client 57.141.18.7:63920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kXkEhLvMuMRNpl03x9wABbTU"]
[Mon Jul 20 07:36:33.355951 2026] [security2:error] [pid 171532:tid 171711] [client 154.192.123.127:17330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kYUEhLvMuMRNpl03ykAAAATs"]
[Mon Jul 20 07:36:33.356071 2026] [security2:error] [pid 171532:tid 171711] [client 154.192.123.127:17330] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kYUEhLvMuMRNpl03ykAAAATs"]
[Mon Jul 20 07:36:33.419651 2026] [security2:error] [pid 171532:tid 171724] [client 103.139.191.61:55061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kYUEhLvMuMRNpl03ykwAAAUg"]
[Mon Jul 20 07:36:33.419781 2026] [security2:error] [pid 171532:tid 171724] [client 103.139.191.61:55061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kYUEhLvMuMRNpl03ykwAAAUg"]
[Mon Jul 20 07:36:33.894685 2026] [core:error] [pid 171532:tid 171764] [client 64.23.161.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:36:33.894711 2026] [core:error] [pid 171532:tid 171764] [client 64.23.161.14:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:36:34.129120 2026] [security2:error] [pid 171532:tid 171672] [client 103.106.165.44:55712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kYkEhLvMuMRNpl03yuwAAARQ"]
[Mon Jul 20 07:36:34.129232 2026] [security2:error] [pid 171532:tid 171672] [client 103.106.165.44:55712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kYkEhLvMuMRNpl03yuwAAARQ"]
[Mon Jul 20 07:36:34.261257 2026] [security2:error] [pid 164535:tid 164773] [client 50.116.65.227:35184] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4kYjYN371eKRzcKeR3tAAAAPE"]
[Mon Jul 20 07:36:34.272764 2026] [security2:error] [pid 171532:tid 171752] [client 50.116.65.227:29570] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4kYkEhLvMuMRNpl03ywQAAATM"]
[Mon Jul 20 07:36:34.304417 2026] [security2:error] [pid 171532:tid 171775] [client 57.141.18.91:60526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kX0EhLvMuMRNpl03yLwABelk"]
[Mon Jul 20 07:36:34.346082 2026] [security2:error] [pid 171532:tid 171546] [remote 13.232.189.155:38242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4kYkEhLvMuMRNpl03yxAABFg0"]
[Mon Jul 20 07:36:34.528409 2026] [security2:error] [pid 171532:tid 171716] [client 114.119.142.197:42011] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.myhealthspot.org"] [uri "/"] [unique_id "al4kYkEhLvMuMRNpl03y1wAAAUA"], referer: https://www.myhealthspot.org/?y=80535112528604
[Mon Jul 20 07:36:34.540906 2026] [security2:error] [pid 171532:tid 171766] [client 20.29.126.15:9123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/haha.php"] [unique_id "al4kYkEhLvMuMRNpl03y2AAAAXI"]
[Mon Jul 20 07:36:34.540988 2026] [security2:error] [pid 171532:tid 171766] [client 20.29.126.15:9123] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/haha.php"] [unique_id "al4kYkEhLvMuMRNpl03y2AAAAXI"]
[Mon Jul 20 07:36:34.683091 2026] [security2:error] [pid 171532:tid 171730] [client 14.225.17.146:61270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4kYUEhLvMuMRNpl03yqgAAAU4"], referer: http://processorstudio.com/demo
[Mon Jul 20 07:36:34.786674 2026] [security2:error] [pid 171532:tid 171558] [remote 13.232.189.155:38242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.189.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nwcarvingacademy.com"] [uri "/wp-login.php"] [unique_id "al4kYkEhLvMuMRNpl03y5gABYRk"], referer: https://nwcarvingacademy.com/wp-login.php
[Mon Jul 20 07:36:35.026531 2026] [security2:error] [pid 171532:tid 171702] [client 14.225.17.146:60495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4kYkEhLvMuMRNpl03y7AAAATI"], referer: http://bigwormfishing.com/demo
[Mon Jul 20 07:36:35.467036 2026] [lsapi:warn] [pid 164535:tid 164689] [client 14.225.17.146:62788] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/demo
[Mon Jul 20 07:36:35.467057 2026] [lsapi:warn] [pid 164535:tid 164689] [client 14.225.17.146:62788] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/demo
[Mon Jul 20 07:36:35.487500 2026] [security2:error] [pid 171532:tid 171671] [client 74.208.214.194:60050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4kY0EhLvMuMRNpl03zBQAAARM"]
[Mon Jul 20 07:36:35.573778 2026] [security2:error] [pid 164535:tid 164712] [client 104.234.53.87:32527] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 87.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/profile.php"] [unique_id "al4kYzYN371eKRzcKeR32AAAALQ"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:35.595202 2026] [security2:error] [pid 164535:tid 164772] [client 14.225.17.146:62718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4kYzYN371eKRzcKeR31wAAAPA"], referer: https://processorstudio.com/demo
[Mon Jul 20 07:36:35.652660 2026] [security2:error] [pid 164535:tid 164732] [client 188.166.209.66:62914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/script-modules.php"] [unique_id "al4kYzYN371eKRzcKeR32wAAAMg"], referer: binance.com
[Mon Jul 20 07:36:35.674868 2026] [security2:error] [pid 164535:tid 164696] [client 14.225.17.146:51314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "myspineworld.com"] [uri "/index.php"] [unique_id "al4kYjYN371eKRzcKeR3rQAAAKQ"], referer: http://myspineworld.com/demo
[Mon Jul 20 07:36:35.725160 2026] [security2:error] [pid 164535:tid 164748] [client 46.110.96.34:33508] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kYzYN371eKRzcKeR34QAAANg"]
[Mon Jul 20 07:36:35.741292 2026] [security2:error] [pid 164535:tid 164698] [client 136.158.60.21:57217] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kYzYN371eKRzcKeR34gAAAKY"]
[Mon Jul 20 07:36:35.741409 2026] [security2:error] [pid 164535:tid 164698] [client 136.158.60.21:57217] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kYzYN371eKRzcKeR34gAAAKY"]
[Mon Jul 20 07:36:35.962362 2026] [lsapi:warn] [pid 171532:tid 171751] [client 50.116.65.227:29592] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:36:35.962383 2026] [lsapi:warn] [pid 171532:tid 171751] [client 50.116.65.227:29592] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:36:35.978358 2026] [security2:error] [pid 164535:tid 164689] [client 14.225.17.146:62788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4kYjYN371eKRzcKeR3yAAAAJ0"], referer: http://oswegooperatheater.com/demo
[Mon Jul 20 07:36:36.013115 2026] [security2:error] [pid 164535:tid 164762] [client 14.225.17.146:51502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4kYzYN371eKRzcKeR36gAAAOY"], referer: https://bigwormfishing.com/demo
[Mon Jul 20 07:36:36.044524 2026] [security2:error] [pid 164535:tid 164693] [client 57.141.18.109:55766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kYTYN371eKRzcKeR3oQAAoXI"]
[Mon Jul 20 07:36:36.081710 2026] [security2:error] [pid 164535:tid 164677] [client 191.202.66.27:52566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kZDYN371eKRzcKeR37AAAAJE"]
[Mon Jul 20 07:36:36.081825 2026] [security2:error] [pid 164535:tid 164677] [client 191.202.66.27:52566] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kZDYN371eKRzcKeR37AAAAJE"]
[Mon Jul 20 07:36:36.106468 2026] [security2:error] [pid 164535:tid 164723] [client 14.225.17.146:62839] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4kYjYN371eKRzcKeR3twAAAL8"], referer: http://superiorcopywriting.com/demo
[Mon Jul 20 07:36:36.115489 2026] [autoindex:error] [pid 171532:tid 171768] [client 198.235.24.60:60106] AH01276: Cannot serve directory /home1/heidimo2/heidimortensonlmft.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:36:36.124169 2026] [security2:error] [pid 171532:tid 171602] [remote 8.217.108.67:62768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kZEEhLvMuMRNpl03zKAABLUU"]
[Mon Jul 20 07:36:36.299072 2026] [security2:error] [pid 171532:tid 171594] [remote 130.51.180.8:43498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4kZEEhLvMuMRNpl03zNAABZD0"]
[Mon Jul 20 07:36:36.324472 2026] [security2:error] [pid 171532:tid 171673] [client 103.176.215.66:60651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kZEEhLvMuMRNpl03zNgAAARU"]
[Mon Jul 20 07:36:36.324559 2026] [security2:error] [pid 171532:tid 171673] [client 103.176.215.66:60651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kZEEhLvMuMRNpl03zNgAAARU"]
[Mon Jul 20 07:36:36.464440 2026] [security2:error] [pid 171532:tid 171626] [remote 130.51.180.8:43498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oswegooperatheater.com"] [uri "/wp-login.php"] [unique_id "al4kZEEhLvMuMRNpl03zPQABbF0"], referer: https://oswegooperatheater.com/wp-login.php
[Mon Jul 20 07:36:36.657612 2026] [security2:error] [pid 171532:tid 171724] [client 143.44.185.218:59002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kZEEhLvMuMRNpl03zQgAAAUg"]
[Mon Jul 20 07:36:36.657788 2026] [security2:error] [pid 171532:tid 171724] [client 143.44.185.218:59002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kZEEhLvMuMRNpl03zQgAAAUg"]
[Mon Jul 20 07:36:36.675314 2026] [security2:error] [pid 171532:tid 171730] [client 20.29.126.15:10933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/classwithtostring.php"] [unique_id "al4kZEEhLvMuMRNpl03zRAAAAU4"]
[Mon Jul 20 07:36:36.675401 2026] [security2:error] [pid 171532:tid 171730] [client 20.29.126.15:10933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/classwithtostring.php"] [unique_id "al4kZEEhLvMuMRNpl03zRAAAAU4"]
[Mon Jul 20 07:36:36.738987 2026] [security2:error] [pid 171532:tid 171679] [client 14.225.17.146:64846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.myspineworld.com"] [uri "/index.php"] [unique_id "al4kZEEhLvMuMRNpl03zQAAAARs"], referer: https://myspineworld.com/demo
[Mon Jul 20 07:36:36.773975 2026] [security2:error] [pid 171532:tid 171777] [client 57.141.18.110:32064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kYkEhLvMuMRNpl03ywgABfAQ"]
[Mon Jul 20 07:36:36.866400 2026] [security2:error] [pid 164535:tid 164684] [client 14.225.17.146:51529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4kZDYN371eKRzcKeR3-gAAAJg"], referer: http://claysharecon.com/demo
[Mon Jul 20 07:36:36.995247 2026] [lsapi:warn] [pid 164535:tid 164777] [client 14.225.17.146:50784] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/demo
[Mon Jul 20 07:36:36.995263 2026] [lsapi:warn] [pid 164535:tid 164777] [client 14.225.17.146:50784] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/demo
[Mon Jul 20 07:36:37.044216 2026] [security2:error] [pid 164535:tid 164777] [client 14.225.17.146:50784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4kZDYN371eKRzcKeR4AAAAAPU"], referer: https://oswegooperatheater.com/demo
[Mon Jul 20 07:36:37.125267 2026] [security2:error] [pid 171532:tid 171616] [remote 8.217.108.67:62768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kZUEhLvMuMRNpl03zVwABJlM"], referer: https://maa.hws.mybluehost.me/wp-login.php
[Mon Jul 20 07:36:37.157800 2026] [security2:error] [pid 171532:tid 171709] [client 57.141.18.27:32272] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kYkEhLvMuMRNpl03y5AABOWg"]
[Mon Jul 20 07:36:37.780972 2026] [security2:error] [pid 164535:tid 164691] [client 104.234.53.82:39039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/edit.php"] [unique_id "al4kZTYN371eKRzcKeR4DQAAAJ8"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:37.955370 2026] [security2:error] [pid 171532:tid 171640] [remote 217.61.143.92:36490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kZUEhLvMuMRNpl03zmAABYWs"]
[Mon Jul 20 07:36:38.010150 2026] [security2:error] [pid 171532:tid 171667] [client 179.127.84.238:55983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kZkEhLvMuMRNpl03znwAAAQ8"]
[Mon Jul 20 07:36:38.010250 2026] [security2:error] [pid 171532:tid 171667] [client 179.127.84.238:55983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kZkEhLvMuMRNpl03znwAAAQ8"]
[Mon Jul 20 07:36:38.193649 2026] [security2:error] [pid 171532:tid 171638] [remote 217.61.143.92:36490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kZkEhLvMuMRNpl03zpAABbGk"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:36:38.231485 2026] [security2:error] [pid 171532:tid 171763] [client 20.29.126.15:9146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/bless.php"] [unique_id "al4kZkEhLvMuMRNpl03zpgAAAW8"]
[Mon Jul 20 07:36:38.231614 2026] [security2:error] [pid 171532:tid 171763] [client 20.29.126.15:9146] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/bless.php"] [unique_id "al4kZkEhLvMuMRNpl03zpgAAAW8"]
[Mon Jul 20 07:36:38.408630 2026] [security2:error] [pid 164535:tid 164786] [client 57.141.18.32:24372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kZDYN371eKRzcKeR37wAA_n0"]
[Mon Jul 20 07:36:38.480684 2026] [security2:error] [pid 164535:tid 164688] [client 109.242.168.154:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4kZTYN371eKRzcKeR4AwAAAJw"]
[Mon Jul 20 07:36:38.799332 2026] [security2:error] [pid 171532:tid 171748] [client 98.159.234.160:24121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kZkEhLvMuMRNpl03zyAAAAWA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:36:38.988278 2026] [security2:error] [pid 171532:tid 171677] [client 57.141.18.87:42132] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kZEEhLvMuMRNpl03zRwABGU4"]
[Mon Jul 20 07:36:39.029469 2026] [security2:error] [pid 171532:tid 171690] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kZkEhLvMuMRNpl03zwwAAASY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:39.039478 2026] [security2:error] [pid 171532:tid 171666] [client 117.211.236.168:53692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kZ0EhLvMuMRNpl03z1AAAAQ4"]
[Mon Jul 20 07:36:39.039550 2026] [security2:error] [pid 171532:tid 171666] [client 117.211.236.168:53692] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kZ0EhLvMuMRNpl03z1AAAAQ4"]
[Mon Jul 20 07:36:39.248409 2026] [security2:error] [pid 171532:tid 171784] [client 14.225.17.146:49950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4kZ0EhLvMuMRNpl03z2QAAAYM"], referer: http://entuvy.com/demo
[Mon Jul 20 07:36:39.333146 2026] [security2:error] [pid 171532:tid 171678] [client 46.110.96.34:56145] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kZ0EhLvMuMRNpl03z6AAAARo"]
[Mon Jul 20 07:36:39.515373 2026] [security2:error] [pid 171532:tid 171790] [client 20.29.126.15:3813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/storage/index.php"] [unique_id "al4kZ0EhLvMuMRNpl03z8QAAAYk"]
[Mon Jul 20 07:36:39.515456 2026] [security2:error] [pid 171532:tid 171790] [client 20.29.126.15:3813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/storage/index.php"] [unique_id "al4kZ0EhLvMuMRNpl03z8QAAAYk"]
[Mon Jul 20 07:36:39.528454 2026] [security2:error] [pid 171532:tid 171664] [client 193.37.33.7:31347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4kZ0EhLvMuMRNpl03z7gAAAQw"]
[Mon Jul 20 07:36:39.544680 2026] [security2:error] [pid 171532:tid 171708] [client 193.37.33.33:44915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4kZ0EhLvMuMRNpl03z8gAAATg"]
[Mon Jul 20 07:36:39.564007 2026] [security2:error] [pid 171532:tid 171728] [client 194.180.48.253:47992] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "aosta.nz"] [uri "/"] [unique_id "al4kZ0EhLvMuMRNpl03z8wAAAUw"]
[Mon Jul 20 07:36:40.157353 2026] [security2:error] [pid 171532:tid 171625] [remote 132.148.72.88:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.72.148.132.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4kaEEhLvMuMRNpl030EwABSFw"]
[Mon Jul 20 07:36:40.157491 2026] [security2:error] [pid 171532:tid 171724] [client 132.148.72.88:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4kaEEhLvMuMRNpl030EwABSFw"]
[Mon Jul 20 07:36:40.189822 2026] [security2:error] [pid 171532:tid 171674] [client 188.166.209.66:57825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/speculative-loading.php"] [unique_id "al4kaEEhLvMuMRNpl030FQAAARY"], referer: binance.com
[Mon Jul 20 07:36:40.290176 2026] [security2:error] [pid 171532:tid 171762] [client 139.59.118.64:65459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kaEEhLvMuMRNpl030GwAAAW4"], referer: https://duckduckgo.com/
[Mon Jul 20 07:36:40.384885 2026] [security2:error] [pid 171532:tid 171767] [client 57.141.18.39:61205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kZkEhLvMuMRNpl03zpQABc3U"]
[Mon Jul 20 07:36:40.418572 2026] [security2:error] [pid 171532:tid 171755] [client 20.29.126.15:15413] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/g.php"] [unique_id "al4kaEEhLvMuMRNpl030JAAAAWc"]
[Mon Jul 20 07:36:40.418651 2026] [security2:error] [pid 171532:tid 171755] [client 20.29.126.15:15413] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/g.php"] [unique_id "al4kaEEhLvMuMRNpl030JAAAAWc"]
[Mon Jul 20 07:36:40.434756 2026] [security2:error] [pid 171532:tid 171745] [client 180.249.173.210:53341] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kaEEhLvMuMRNpl030JwAAAV0"]
[Mon Jul 20 07:36:40.434887 2026] [security2:error] [pid 171532:tid 171745] [client 180.249.173.210:53341] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kaEEhLvMuMRNpl030JwAAAV0"]
[Mon Jul 20 07:36:40.741229 2026] [security2:error] [pid 171532:tid 171684] [client 46.110.96.34:53740] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kaEEhLvMuMRNpl030NwAAASA"]
[Mon Jul 20 07:36:40.756018 2026] [security2:error] [pid 171532:tid 171760] [client 14.225.17.146:49739] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4kaEEhLvMuMRNpl030FwAAAWw"], referer: http://idigress.group/demo
[Mon Jul 20 07:36:41.079093 2026] [security2:error] [pid 164535:tid 164705] [client 14.225.17.146:49888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4kaDYN371eKRzcKeR4YAAAAK0"]
[Mon Jul 20 07:36:41.154128 2026] [security2:error] [pid 171532:tid 171758] [client 14.225.17.146:49693] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4kaEEhLvMuMRNpl030DwAAAWo"], referer: http://nikkidesigns.net/demo
[Mon Jul 20 07:36:41.268894 2026] [security2:error] [pid 164535:tid 164747] [client 45.205.1.223:43818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4kaTYN371eKRzcKeR4agAAANc"]
[Mon Jul 20 07:36:41.291265 2026] [security2:error] [pid 164535:tid 164673] [client 20.29.126.15:13749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/nf.php"] [unique_id "al4kaTYN371eKRzcKeR4bAAAAI0"]
[Mon Jul 20 07:36:41.291351 2026] [security2:error] [pid 164535:tid 164673] [client 20.29.126.15:13749] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/nf.php"] [unique_id "al4kaTYN371eKRzcKeR4bAAAAI0"]
[Mon Jul 20 07:36:41.389426 2026] [security2:error] [pid 164535:tid 164693] [client 49.47.218.174:36574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kaTYN371eKRzcKeR4bgAAAKE"]
[Mon Jul 20 07:36:41.389565 2026] [security2:error] [pid 164535:tid 164693] [client 49.47.218.174:36574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kaTYN371eKRzcKeR4bgAAAKE"]
[Mon Jul 20 07:36:41.515630 2026] [security2:error] [pid 171532:tid 171668] [client 34.60.96.215:40740] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "sardimacmillan.com"] [uri "/"] [unique_id "al4kaUEhLvMuMRNpl030UAAAARA"]
[Mon Jul 20 07:36:41.532098 2026] [security2:error] [pid 171532:tid 171667] [client 14.225.17.146:49736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4kaEEhLvMuMRNpl030FgAAAQ8"], referer: http://hammadownenterprises.com/demo
[Mon Jul 20 07:36:41.546668 2026] [security2:error] [pid 171532:tid 171694] [client 104.234.53.90:22179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.53.234.104.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.friendlyspreadsheet.com"] [uri "/wp-admin/plugins.php"] [unique_id "al4kaUEhLvMuMRNpl030UQAAASo"], referer: https://www.friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:36:41.825068 2026] [security2:error] [pid 164535:tid 164791] [client 57.141.18.113:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kaTYN371eKRzcKeR4fQAAAQM"]
[Mon Jul 20 07:36:42.004396 2026] [security2:error] [pid 171532:tid 171695] [client 45.205.1.223:43824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4kaUEhLvMuMRNpl030ZQAAASs"]
[Mon Jul 20 07:36:42.157189 2026] [security2:error] [pid 164535:tid 164767] [client 157.20.138.62:58705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kajYN371eKRzcKeR4jAAAAOs"]
[Mon Jul 20 07:36:42.157351 2026] [security2:error] [pid 164535:tid 164767] [client 157.20.138.62:58705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kajYN371eKRzcKeR4jAAAAOs"]
[Mon Jul 20 07:36:42.282374 2026] [security2:error] [pid 171532:tid 171674] [client 46.110.96.34:34585] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kakEhLvMuMRNpl030hQAAARY"]
[Mon Jul 20 07:36:42.319325 2026] [security2:error] [pid 171532:tid 171740] [client 46.110.96.34:21761] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kakEhLvMuMRNpl030hwAAAVg"]
[Mon Jul 20 07:36:42.357903 2026] [security2:error] [pid 171532:tid 171721] [client 46.110.96.34:9505] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kakEhLvMuMRNpl030iwAAAUU"]
[Mon Jul 20 07:36:42.397231 2026] [security2:error] [pid 171532:tid 171664] [client 49.37.242.14:61156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kakEhLvMuMRNpl030jwAAAQw"]
[Mon Jul 20 07:36:42.397415 2026] [security2:error] [pid 171532:tid 171664] [client 49.37.242.14:61156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kakEhLvMuMRNpl030jwAAAQw"]
[Mon Jul 20 07:36:42.543333 2026] [security2:error] [pid 164535:tid 164560] [remote 5.223.65.249:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4kajYN371eKRzcKeR4kwAA5Rg"]
[Mon Jul 20 07:36:42.550429 2026] [security2:error] [pid 164535:tid 164751] [client 116.193.128.26:49544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kajYN371eKRzcKeR4lAAAANs"]
[Mon Jul 20 07:36:42.550543 2026] [security2:error] [pid 164535:tid 164751] [client 116.193.128.26:49544] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kajYN371eKRzcKeR4lAAAANs"]
[Mon Jul 20 07:36:42.657933 2026] [security2:error] [pid 164535:tid 164783] [client 149.0.16.108:62145] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kajYN371eKRzcKeR4mAAAAPs"]
[Mon Jul 20 07:36:42.658047 2026] [security2:error] [pid 164535:tid 164783] [client 149.0.16.108:62145] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kajYN371eKRzcKeR4mAAAAPs"]
[Mon Jul 20 07:36:42.684661 2026] [security2:error] [pid 171532:tid 171747] [client 57.141.18.12:43988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kaEEhLvMuMRNpl030KgABXxE"]
[Mon Jul 20 07:36:42.690955 2026] [security2:error] [pid 171532:tid 171739] [client 20.29.126.15:3818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/xda.php"] [unique_id "al4kakEhLvMuMRNpl030pAAAAVc"]
[Mon Jul 20 07:36:42.691067 2026] [security2:error] [pid 171532:tid 171739] [client 20.29.126.15:3818] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/xda.php"] [unique_id "al4kakEhLvMuMRNpl030pAAAAVc"]
[Mon Jul 20 07:36:42.822234 2026] [security2:error] [pid 171532:tid 171694] [client 45.3.54.235:45365] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kakEhLvMuMRNpl030qAAAASo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:42.828188 2026] [security2:error] [pid 171532:tid 171709] [client 142.111.152.177:30247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kakEhLvMuMRNpl030owAAATk"]
[Mon Jul 20 07:36:42.920517 2026] [security2:error] [pid 164535:tid 164620] [remote 5.223.65.249:55356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.65.223.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thierry-henry.fr"] [uri "/wp-login.php"] [unique_id "al4kajYN371eKRzcKeR4nQAAvFQ"], referer: https://thierry-henry.fr/wp-login.php
[Mon Jul 20 07:36:43.072193 2026] [security2:error] [pid 164535:tid 164682] [client 14.225.17.146:62557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4kaTYN371eKRzcKeR4dQAAAJY"], referer: http://reosportsboats.com/demo
[Mon Jul 20 07:36:43.081326 2026] [security2:error] [pid 171532:tid 171734] [client 14.225.17.146:64809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4kakEhLvMuMRNpl030tQAAAVI"], referer: http://ravmike.com/demo
[Mon Jul 20 07:36:43.281799 2026] [security2:error] [pid 164535:tid 164758] [client 57.141.18.48:56596] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kaTYN371eKRzcKeR4ZwAA4jM"]
[Mon Jul 20 07:36:43.748097 2026] [security2:error] [pid 171532:tid 171593] [remote 67.207.94.191:52622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ka0EhLvMuMRNpl0306AABgTw"]
[Mon Jul 20 07:36:43.748397 2026] [security2:error] [pid 171532:tid 171782] [client 67.207.94.191:52622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tee.qtw.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ka0EhLvMuMRNpl0306AABgTw"]
[Mon Jul 20 07:36:43.756947 2026] [security2:error] [pid 164535:tid 164671] [client 36.93.152.155:51108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kazYN371eKRzcKeR4tAAAAIs"]
[Mon Jul 20 07:36:43.757099 2026] [security2:error] [pid 164535:tid 164671] [client 36.93.152.155:51108] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kazYN371eKRzcKeR4tAAAAIs"]
[Mon Jul 20 07:36:43.809193 2026] [security2:error] [pid 164535:tid 164696] [client 50.116.65.227:48712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kazYN371eKRzcKeR4tQAAAKQ"]
[Mon Jul 20 07:36:43.822477 2026] [security2:error] [pid 164535:tid 164791] [client 50.116.65.227:48722] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kazYN371eKRzcKeR4tgAAAQM"]
[Mon Jul 20 07:36:43.854683 2026] [security2:error] [pid 171532:tid 171725] [client 154.192.123.127:17745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ka0EhLvMuMRNpl0307AAAAUk"]
[Mon Jul 20 07:36:43.858203 2026] [security2:error] [pid 171532:tid 171725] [client 154.192.123.127:17745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ka0EhLvMuMRNpl0307AAAAUk"]
[Mon Jul 20 07:36:43.937857 2026] [security2:error] [pid 171532:tid 171728] [client 14.225.17.146:62538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4kakEhLvMuMRNpl030hAAAAUw"], referer: http://lelandumc.org/demo
[Mon Jul 20 07:36:44.090542 2026] [security2:error] [pid 171532:tid 171709] [client 14.225.17.146:64753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4ka0EhLvMuMRNpl0308wAAATk"], referer: https://reosportsboats.com/demo
[Mon Jul 20 07:36:44.169249 2026] [security2:error] [pid 164535:tid 164618] [remote 57.141.18.106:43922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3396212"] [unique_id "al4kbDYN371eKRzcKeR4xwAAv1I"]
[Mon Jul 20 07:36:44.237848 2026] [security2:error] [pid 164535:tid 164780] [client 20.29.126.15:8663] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/shell.php"] [unique_id "al4kbDYN371eKRzcKeR4zQAAAPg"]
[Mon Jul 20 07:36:44.238003 2026] [security2:error] [pid 164535:tid 164780] [client 20.29.126.15:8663] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/shell.php"] [unique_id "al4kbDYN371eKRzcKeR4zQAAAPg"]
[Mon Jul 20 07:36:44.275801 2026] [security2:error] [pid 164535:tid 164708] [client 104.207.52.113:52123] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kbDYN371eKRzcKeR4zAAAALA"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:44.373411 2026] [security2:error] [pid 171532:tid 171786] [client 57.141.18.49:39880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kakEhLvMuMRNpl030hgABhTE"]
[Mon Jul 20 07:36:44.416866 2026] [security2:error] [pid 164535:tid 164697] [client 103.139.191.61:55542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kbDYN371eKRzcKeR40QAAAKU"]
[Mon Jul 20 07:36:44.416987 2026] [security2:error] [pid 164535:tid 164697] [client 103.139.191.61:55542] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kbDYN371eKRzcKeR40QAAAKU"]
[Mon Jul 20 07:36:44.448701 2026] [security2:error] [pid 171532:tid 171772] [client 57.141.18.30:23572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kakEhLvMuMRNpl030jgABeD0"]
[Mon Jul 20 07:36:44.637060 2026] [security2:error] [pid 171532:tid 171672] [client 202.141.11.99:12183] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kbEEhLvMuMRNpl031IAAAARQ"]
[Mon Jul 20 07:36:44.637166 2026] [security2:error] [pid 171532:tid 171672] [client 202.141.11.99:12183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kbEEhLvMuMRNpl031IAAAARQ"]
[Mon Jul 20 07:36:44.676180 2026] [security2:error] [pid 171532:tid 171756] [client 188.166.209.66:64368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/style-engine.php"] [unique_id "al4kbEEhLvMuMRNpl031JAAAAWg"], referer: binance.com
[Mon Jul 20 07:36:44.721411 2026] [security2:error] [pid 164535:tid 164764] [client 103.106.165.44:56296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kbDYN371eKRzcKeR41wAAAOg"]
[Mon Jul 20 07:36:44.721556 2026] [security2:error] [pid 164535:tid 164764] [client 103.106.165.44:56296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kbDYN371eKRzcKeR41wAAAOg"]
[Mon Jul 20 07:36:44.742932 2026] [security2:error] [pid 171532:tid 171679] [client 14.225.17.146:54679] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4ka0EhLvMuMRNpl0301AAAARs"], referer: http://adirondackengineering.com/demo
[Mon Jul 20 07:36:44.742988 2026] [security2:error] [pid 171532:tid 171790] [client 14.225.17.146:62477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4ka0EhLvMuMRNpl0304QAAAYk"], referer: https://north-woods-engineering.com/demo
[Mon Jul 20 07:36:44.874857 2026] [security2:error] [pid 171532:tid 171671] [client 57.141.18.75:43104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kakEhLvMuMRNpl030rwABEy4"]
[Mon Jul 20 07:36:45.455770 2026] [security2:error] [pid 164535:tid 164586] [remote 216.73.216.55:30427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4kbTYN371eKRzcKeR45QAAizI"]
[Mon Jul 20 07:36:45.719707 2026] [security2:error] [pid 164535:tid 164755] [client 45.3.42.254:59771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 254.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kbTYN371eKRzcKeR47gAAAN8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:36:45.906145 2026] [security2:error] [pid 171532:tid 171711] [client 14.225.17.146:64926] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4kbUEhLvMuMRNpl031aAAAATs"], referer: http://longevityperformanceclinic.com/demo
[Mon Jul 20 07:36:46.013759 2026] [security2:error] [pid 164535:tid 164790] [client 20.29.126.15:16015] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/3.php"] [unique_id "al4kbjYN371eKRzcKeR5AQAAAQI"]
[Mon Jul 20 07:36:46.013863 2026] [security2:error] [pid 164535:tid 164790] [client 20.29.126.15:16015] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/3.php"] [unique_id "al4kbjYN371eKRzcKeR5AQAAAQI"]
[Mon Jul 20 07:36:46.019566 2026] [security2:error] [pid 164535:tid 164769] [client 14.225.17.146:54689] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4kazYN371eKRzcKeR4sQAAAO0"], referer: http://overloadcomedy.com/demo
[Mon Jul 20 07:36:46.260020 2026] [security2:error] [pid 164535:tid 164695] [client 14.225.17.146:64897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4kbjYN371eKRzcKeR5BAAAAKM"], referer: http://whiteoutcb.com/demo
[Mon Jul 20 07:36:46.444163 2026] [security2:error] [pid 171532:tid 171781] [client 57.141.18.14:24736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbEEhLvMuMRNpl031CAABgGk"]
[Mon Jul 20 07:36:46.572369 2026] [security2:error] [pid 164535:tid 164789] [client 136.158.60.21:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kbjYN371eKRzcKeR5FAAAAQE"]
[Mon Jul 20 07:36:46.572522 2026] [security2:error] [pid 164535:tid 164789] [client 136.158.60.21:58738] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kbjYN371eKRzcKeR5FAAAAQE"]
[Mon Jul 20 07:36:46.659186 2026] [security2:error] [pid 171532:tid 171542] [remote 217.61.143.92:47656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4kbkEhLvMuMRNpl031hQABYwk"]
[Mon Jul 20 07:36:46.712887 2026] [security2:error] [pid 171532:tid 171697] [client 62.102.148.130:58348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4kbkEhLvMuMRNpl031iAAAAS0"]
[Mon Jul 20 07:36:46.712987 2026] [security2:error] [pid 171532:tid 171697] [client 62.102.148.130:58348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4kbkEhLvMuMRNpl031iAAAAS0"]
[Mon Jul 20 07:36:46.745699 2026] [security2:error] [pid 171532:tid 171740] [client 14.225.17.146:64729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4kbkEhLvMuMRNpl031gwAAAVg"], referer: http://according2plant.com/demo
[Mon Jul 20 07:36:46.756587 2026] [security2:error] [pid 171532:tid 171672] [client 191.202.66.27:53051] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kbkEhLvMuMRNpl031jgAAARQ"]
[Mon Jul 20 07:36:46.756830 2026] [security2:error] [pid 171532:tid 171672] [client 191.202.66.27:53051] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kbkEhLvMuMRNpl031jgAAARQ"]
[Mon Jul 20 07:36:46.766063 2026] [security2:error] [pid 171532:tid 171772] [client 14.225.17.146:65042] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4kbUEhLvMuMRNpl031TQAAAXg"], referer: http://betterbonddogtraining.com/demo
[Mon Jul 20 07:36:46.798572 2026] [security2:error] [pid 164535:tid 164787] [client 43.205.139.3:38808] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kbjYN371eKRzcKeR5GQAAAP8"]
[Mon Jul 20 07:36:46.812831 2026] [security2:error] [pid 171532:tid 171766] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kbkEhLvMuMRNpl031fwAAAXI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:46.889808 2026] [security2:error] [pid 171532:tid 171742] [client 103.176.215.66:61176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kbkEhLvMuMRNpl031lwAAAVo"]
[Mon Jul 20 07:36:46.890383 2026] [security2:error] [pid 171532:tid 171742] [client 103.176.215.66:61176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kbkEhLvMuMRNpl031lwAAAVo"]
[Mon Jul 20 07:36:46.891102 2026] [security2:error] [pid 164535:tid 164777] [client 57.141.18.110:27956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbDYN371eKRzcKeR42AAA9VA"]
[Mon Jul 20 07:36:46.906934 2026] [security2:error] [pid 171532:tid 171569] [remote 217.61.143.92:47656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/wp-login.php"] [unique_id "al4kbkEhLvMuMRNpl031mAABayQ"], referer: https://tntcatholic.com/wp-login.php
[Mon Jul 20 07:36:46.976427 2026] [security2:error] [pid 164535:tid 164779] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4kbjYN371eKRzcKeR5DAAA93I"], referer: http://ardhalwafaa.com/demo
[Mon Jul 20 07:36:47.146126 2026] [security2:error] [pid 171532:tid 171763] [client 216.73.216.122:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ali-alghanim.com"] [uri "/index.php"] [unique_id "al4kbkEhLvMuMRNpl031mQABbxk"]
[Mon Jul 20 07:36:47.432621 2026] [security2:error] [pid 164535:tid 164756] [client 20.29.126.15:9121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/mds.php"] [unique_id "al4kbzYN371eKRzcKeR5KwAAAOA"]
[Mon Jul 20 07:36:47.432790 2026] [security2:error] [pid 164535:tid 164756] [client 20.29.126.15:9121] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/mds.php"] [unique_id "al4kbzYN371eKRzcKeR5KwAAAOA"]
[Mon Jul 20 07:36:47.465628 2026] [security2:error] [pid 164535:tid 164728] [client 57.141.18.98:57282] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbTYN371eKRzcKeR45AAAxGM"]
[Mon Jul 20 07:36:47.678471 2026] [security2:error] [pid 171532:tid 171533] [remote 173.212.252.15:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4kb0EhLvMuMRNpl031vAABQAA"]
[Mon Jul 20 07:36:47.693182 2026] [security2:error] [pid 171532:tid 171747] [client 14.225.17.146:64946] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4kb0EhLvMuMRNpl031rwAAAV8"], referer: http://uritems.net/demo
[Mon Jul 20 07:36:47.718087 2026] [security2:error] [pid 171532:tid 171790] [client 14.225.17.146:65255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4kb0EhLvMuMRNpl031pwAAAYk"], referer: http://vinovinhowine.com/demo
[Mon Jul 20 07:36:47.740716 2026] [security2:error] [pid 164535:tid 164743] [client 13.233.207.33:17440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kbzYN371eKRzcKeR5PAAAANM"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:36:47.791822 2026] [security2:error] [pid 171532:tid 171717] [client 47.129.222.11:61718] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kb0EhLvMuMRNpl031wQAAAUE"]
[Mon Jul 20 07:36:47.993712 2026] [security2:error] [pid 171532:tid 171656] [remote 173.212.252.15:45748] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "anastasiproperties.com"] [uri "/wp-login.php"] [unique_id "al4kb0EhLvMuMRNpl031ygABMns"], referer: https://anastasiproperties.com/wp-login.php
[Mon Jul 20 07:36:48.023967 2026] [security2:error] [pid 171532:tid 171668] [client 14.225.17.146:64754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4kbUEhLvMuMRNpl031WAAAARA"], referer: http://gearwaterproof.com/demo
[Mon Jul 20 07:36:48.053508 2026] [security2:error] [pid 164535:tid 164667] [client 57.141.18.61:51460] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbTYN371eKRzcKeR4-AAAh3o"]
[Mon Jul 20 07:36:48.084880 2026] [security2:error] [pid 164535:tid 164677] [client 57.141.18.12:23956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbTYN371eKRzcKeR4_gAAkVo"]
[Mon Jul 20 07:36:48.347031 2026] [security2:error] [pid 171532:tid 171776] [client 20.29.126.15:3960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/archive.php"] [unique_id "al4kcEEhLvMuMRNpl0312QAAAXs"]
[Mon Jul 20 07:36:48.347154 2026] [security2:error] [pid 171532:tid 171776] [client 20.29.126.15:3960] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/archive.php"] [unique_id "al4kcEEhLvMuMRNpl0312QAAAXs"]
[Mon Jul 20 07:36:48.352115 2026] [security2:error] [pid 171532:tid 171677] [client 188.166.209.66:59374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/template-canvas.php"] [unique_id "al4kcEEhLvMuMRNpl0312gAAARk"], referer: binance.com
[Mon Jul 20 07:36:48.408677 2026] [core:error] [pid 164535:tid 164723] [client 14.225.17.146:57260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/demo
[Mon Jul 20 07:36:48.408698 2026] [core:error] [pid 164535:tid 164723] [client 14.225.17.146:57260] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/demo
[Mon Jul 20 07:36:48.496422 2026] [security2:error] [pid 171532:tid 171753] [client 139.59.118.64:50717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webdisk.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kcEEhLvMuMRNpl0315gAAAWU"], referer: https://www.facebook.com/
[Mon Jul 20 07:36:48.619983 2026] [security2:error] [pid 164535:tid 164771] [client 20.29.126.15:3269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/amax.php"] [unique_id "al4kcDYN371eKRzcKeR5XAAAAO8"]
[Mon Jul 20 07:36:48.620089 2026] [security2:error] [pid 164535:tid 164771] [client 20.29.126.15:3269] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/amax.php"] [unique_id "al4kcDYN371eKRzcKeR5XAAAAO8"]
[Mon Jul 20 07:36:48.631093 2026] [security2:error] [pid 164535:tid 164699] [client 117.211.236.168:54228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kcDYN371eKRzcKeR5XQAAAKc"]
[Mon Jul 20 07:36:48.631239 2026] [security2:error] [pid 164535:tid 164699] [client 117.211.236.168:54228] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kcDYN371eKRzcKeR5XQAAAKc"]
[Mon Jul 20 07:36:48.728440 2026] [security2:error] [pid 171532:tid 171674] [client 114.119.146.195:61971] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "jndsupport.com"] [uri "/back-to-school-cybersecurity/t%3Cbr%3Eel:18882883007"] [unique_id "al4kcEEhLvMuMRNpl0318wAAARY"], referer: https://jndsupport.com/back-to-school-cybersecurity/
[Mon Jul 20 07:36:48.810332 2026] [security2:error] [pid 171532:tid 171743] [client 179.127.84.238:56541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kcEEhLvMuMRNpl0319AAAAVs"]
[Mon Jul 20 07:36:48.810454 2026] [security2:error] [pid 171532:tid 171743] [client 179.127.84.238:56541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kcEEhLvMuMRNpl0319AAAAVs"]
[Mon Jul 20 07:36:48.820205 2026] [security2:error] [pid 171532:tid 171722] [client 18.141.57.241:26564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kcEEhLvMuMRNpl031-AAAAUY"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:36:48.883183 2026] [security2:error] [pid 171532:tid 171732] [client 14.225.17.146:64715] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4kcEEhLvMuMRNpl031zwAAAVA"]
[Mon Jul 20 07:36:48.936537 2026] [security2:error] [pid 164535:tid 164785] [client 139.59.118.64:50750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kcDYN371eKRzcKeR5ZAAAAP0"], referer: https://t.co/
[Mon Jul 20 07:36:48.959811 2026] [security2:error] [pid 171532:tid 171693] [client 14.225.17.146:64831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4kb0EhLvMuMRNpl031yAAAASk"], referer: http://adultdaycarereno.com/demo
[Mon Jul 20 07:36:49.492367 2026] [security2:error] [pid 171532:tid 171696] [client 20.29.126.15:12468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/moon.php"] [unique_id "al4kcUEhLvMuMRNpl032IwAAASw"]
[Mon Jul 20 07:36:49.492446 2026] [security2:error] [pid 171532:tid 171696] [client 20.29.126.15:12468] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/moon.php"] [unique_id "al4kcUEhLvMuMRNpl032IwAAASw"]
[Mon Jul 20 07:36:49.734034 2026] [security2:error] [pid 164535:tid 164674] [client 57.141.18.42:45628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbzYN371eKRzcKeR5KQAAjlk"]
[Mon Jul 20 07:36:49.927500 2026] [security2:error] [pid 164535:tid 164729] [client 14.225.17.146:51228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4kcTYN371eKRzcKeR5igAAAMU"], referer: https://adultdaycarereno.com/demo
[Mon Jul 20 07:36:49.947390 2026] [security2:error] [pid 171532:tid 171756] [client 143.44.185.218:60427] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kcUEhLvMuMRNpl032MgAAAWg"]
[Mon Jul 20 07:36:49.949342 2026] [security2:error] [pid 171532:tid 171756] [client 143.44.185.218:60427] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kcUEhLvMuMRNpl032MgAAAWg"]
[Mon Jul 20 07:36:50.043836 2026] [security2:error] [pid 164535:tid 164763] [client 57.141.18.83:34366] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbzYN371eKRzcKeR5OAAA5w4"]
[Mon Jul 20 07:36:50.130898 2026] [security2:error] [pid 164535:tid 164790] [client 57.141.18.46:54152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kbzYN371eKRzcKeR5PgABAnA"]
[Mon Jul 20 07:36:50.317374 2026] [security2:error] [pid 164535:tid 164774] [client 50.116.65.227:47932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4kcTYN371eKRzcKeR5fQAAAPI"]
[Mon Jul 20 07:36:50.319311 2026] [security2:error] [pid 164535:tid 164778] [client 57.141.18.73:43120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kcDYN371eKRzcKeR5TAAA9mk"]
[Mon Jul 20 07:36:50.633069 2026] [security2:error] [pid 171532:tid 171685] [client 14.225.17.146:64621] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4kcUEhLvMuMRNpl032GQAAASE"], referer: http://lutheranphilosopher.com/demo
[Mon Jul 20 07:36:50.712843 2026] [security2:error] [pid 171532:tid 171578] [remote 160.187.68.132:51978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4kckEhLvMuMRNpl032WQABiS0"]
[Mon Jul 20 07:36:50.726698 2026] [security2:error] [pid 171532:tid 171746] [client 20.29.126.15:3290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/ws83.php"] [unique_id "al4kckEhLvMuMRNpl032XQAAAV4"]
[Mon Jul 20 07:36:50.726796 2026] [security2:error] [pid 171532:tid 171746] [client 20.29.126.15:3290] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/ws83.php"] [unique_id "al4kckEhLvMuMRNpl032XQAAAV4"]
[Mon Jul 20 07:36:50.734308 2026] [security2:error] [pid 171532:tid 171750] [client 188.166.209.66:60212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/theme-previews.php"] [unique_id "al4kckEhLvMuMRNpl032XgAAAWI"], referer: binance.com
[Mon Jul 20 07:36:50.984326 2026] [security2:error] [pid 171532:tid 171729] [client 50.116.65.227:47958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4kckEhLvMuMRNpl032QAAAAU0"]
[Mon Jul 20 07:36:51.153685 2026] [security2:error] [pid 171532:tid 171722] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kckEhLvMuMRNpl032bAAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:51.294012 2026] [security2:error] [pid 171532:tid 171758] [client 57.141.18.111:20086] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kcEEhLvMuMRNpl031_wABak8"]
[Mon Jul 20 07:36:51.415062 2026] [security2:error] [pid 171532:tid 171579] [remote 160.187.68.132:51978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lmgorman.com"] [uri "/wp-login.php"] [unique_id "al4kc0EhLvMuMRNpl032fgABMS4"], referer: https://lmgorman.com/wp-login.php
[Mon Jul 20 07:36:51.505071 2026] [security2:error] [pid 171532:tid 171731] [client 180.249.173.210:53816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kc0EhLvMuMRNpl032hwAAAU8"]
[Mon Jul 20 07:36:51.505249 2026] [security2:error] [pid 171532:tid 171731] [client 180.249.173.210:53816] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kc0EhLvMuMRNpl032hwAAAU8"]
[Mon Jul 20 07:36:51.719225 2026] [security2:error] [pid 171532:tid 171776] [client 45.3.42.81:43603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kc0EhLvMuMRNpl032kAAAAXs"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:36:51.884392 2026] [security2:error] [pid 171532:tid 171741] [client 49.47.218.174:57094] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kc0EhLvMuMRNpl032lwAAAVk"]
[Mon Jul 20 07:36:51.884941 2026] [security2:error] [pid 171532:tid 171741] [client 49.47.218.174:57094] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kc0EhLvMuMRNpl032lwAAAVk"]
[Mon Jul 20 07:36:52.066711 2026] [security2:error] [pid 164535:tid 164777] [client 14.225.17.146:64863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4kczYN371eKRzcKeR5vAAAAPU"], referer: http://oldracelimited.com/demo
[Mon Jul 20 07:36:52.350712 2026] [security2:error] [pid 171532:tid 171674] [client 65.111.26.142:42297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kdEEhLvMuMRNpl032sgAAARY"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:36:52.420826 2026] [security2:error] [pid 171532:tid 171680] [client 50.116.65.227:48006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4kdEEhLvMuMRNpl032qwAAARw"]
[Mon Jul 20 07:36:52.463644 2026] [security2:error] [pid 171532:tid 171694] [client 14.225.17.146:57217] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4kc0EhLvMuMRNpl032dAAAASo"], referer: http://mazzucelli.com/demo
[Mon Jul 20 07:36:52.473682 2026] [security2:error] [pid 171532:tid 171769] [client 54.244.177.189:53316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4kdEEhLvMuMRNpl032uAAAAXU"]
[Mon Jul 20 07:36:52.541057 2026] [security2:error] [pid 164535:tid 164682] [client 14.225.17.146:56978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4kczYN371eKRzcKeR5rwAAAJY"], referer: http://travelbyfire.com/demo
[Mon Jul 20 07:36:52.593806 2026] [security2:error] [pid 171532:tid 171787] [client 50.116.65.227:48016] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4kdEEhLvMuMRNpl032twAAAYY"]
[Mon Jul 20 07:36:52.718769 2026] [security2:error] [pid 171532:tid 171772] [client 157.20.138.62:59263] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kdEEhLvMuMRNpl032zQAAAXg"]
[Mon Jul 20 07:36:52.719055 2026] [security2:error] [pid 171532:tid 171772] [client 157.20.138.62:59263] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kdEEhLvMuMRNpl032zQAAAXg"]
[Mon Jul 20 07:36:53.109675 2026] [security2:error] [pid 171532:tid 171695] [client 116.193.128.26:50237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kdUEhLvMuMRNpl0325AAAASs"]
[Mon Jul 20 07:36:53.109790 2026] [security2:error] [pid 171532:tid 171695] [client 116.193.128.26:50237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kdUEhLvMuMRNpl0325AAAASs"]
[Mon Jul 20 07:36:53.128601 2026] [security2:error] [pid 164535:tid 164679] [client 57.141.18.5:61502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kcjYN371eKRzcKeR5lwAAkwc"]
[Mon Jul 20 07:36:53.231365 2026] [core:error] [pid 171532:tid 171760] [client 14.225.17.146:56890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/demo
[Mon Jul 20 07:36:53.231384 2026] [core:error] [pid 171532:tid 171760] [client 14.225.17.146:56890] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/demo
[Mon Jul 20 07:36:53.298054 2026] [security2:error] [pid 171532:tid 171710] [client 149.0.16.108:62665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kdUEhLvMuMRNpl0328AAAATo"]
[Mon Jul 20 07:36:53.298837 2026] [security2:error] [pid 171532:tid 171710] [client 149.0.16.108:62665] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kdUEhLvMuMRNpl0328AAAATo"]
[Mon Jul 20 07:36:53.339884 2026] [security2:error] [pid 171532:tid 171769] [client 20.29.126.15:3264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/CDX1.php"] [unique_id "al4kdUEhLvMuMRNpl0329AAAAXU"]
[Mon Jul 20 07:36:53.340004 2026] [security2:error] [pid 171532:tid 171769] [client 20.29.126.15:3264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/CDX1.php"] [unique_id "al4kdUEhLvMuMRNpl0329AAAAXU"]
[Mon Jul 20 07:36:53.370900 2026] [security2:error] [pid 171532:tid 171685] [client 188.166.209.66:51078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/theme-templates.php"] [unique_id "al4kdUEhLvMuMRNpl0329gAAASE"], referer: binance.com
[Mon Jul 20 07:36:53.466454 2026] [security2:error] [pid 164535:tid 164773] [client 142.111.152.73:35913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kdTYN371eKRzcKeR51QAAAPE"]
[Mon Jul 20 07:36:53.473637 2026] [security2:error] [pid 171532:tid 171663] [client 57.141.18.7:39022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kckEhLvMuMRNpl032YQABC0k"]
[Mon Jul 20 07:36:53.479617 2026] [security2:error] [pid 164535:tid 164697] [client 14.225.17.146:57792] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4kdTYN371eKRzcKeR51wAAAKU"], referer: https://travelbyfire.com/demo
[Mon Jul 20 07:36:53.904375 2026] [security2:error] [pid 164535:tid 164780] [client 139.59.118.64:51692] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.sarahsnyder.net"] [uri "/wp-login.php"] [unique_id "al4kdTYN371eKRzcKeR58gAAAPg"]
[Mon Jul 20 07:36:54.199446 2026] [security2:error] [pid 164535:tid 164787] [client 57.141.18.11:26950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kczYN371eKRzcKeR5twAA_2c"]
[Mon Jul 20 07:36:54.214498 2026] [security2:error] [pid 171532:tid 171762] [client 36.93.152.155:51613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kdkEhLvMuMRNpl033KQAAAW4"]
[Mon Jul 20 07:36:54.214601 2026] [security2:error] [pid 171532:tid 171762] [client 36.93.152.155:51613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kdkEhLvMuMRNpl033KQAAAW4"]
[Mon Jul 20 07:36:54.365499 2026] [security2:error] [pid 171532:tid 171585] [remote 162.19.246.208:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4kdkEhLvMuMRNpl033MQABYzQ"]
[Mon Jul 20 07:36:54.384947 2026] [security2:error] [pid 171532:tid 171706] [client 154.192.123.127:18233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kdkEhLvMuMRNpl033NAAAATY"]
[Mon Jul 20 07:36:54.385053 2026] [security2:error] [pid 171532:tid 171706] [client 154.192.123.127:18233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kdkEhLvMuMRNpl033NAAAATY"]
[Mon Jul 20 07:36:54.573807 2026] [security2:error] [pid 171532:tid 171596] [remote 162.19.246.208:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "pscmedicalbilling.com"] [uri "/wp-login.php"] [unique_id "al4kdkEhLvMuMRNpl033PwABiT8"], referer: https://pscmedicalbilling.com/wp-login.php
[Mon Jul 20 07:36:55.052933 2026] [security2:error] [pid 171532:tid 171673] [client 103.106.165.44:56779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kd0EhLvMuMRNpl033VQAAARU"]
[Mon Jul 20 07:36:55.053047 2026] [security2:error] [pid 171532:tid 171673] [client 103.106.165.44:56779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kd0EhLvMuMRNpl033VQAAARU"]
[Mon Jul 20 07:36:55.086664 2026] [security2:error] [pid 171532:tid 171701] [client 20.29.126.15:3816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/inputs.php"] [unique_id "al4kd0EhLvMuMRNpl033XQAAATE"]
[Mon Jul 20 07:36:55.086789 2026] [security2:error] [pid 171532:tid 171701] [client 20.29.126.15:3816] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/inputs.php"] [unique_id "al4kd0EhLvMuMRNpl033XQAAATE"]
[Mon Jul 20 07:36:55.217526 2026] [security2:error] [pid 171532:tid 171769] [client 74.7.227.179:55960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4kd0EhLvMuMRNpl033XgABdVI"], referer: https://tejasenvironmental.com/p=751909
[Mon Jul 20 07:36:55.410121 2026] [security2:error] [pid 164535:tid 164705] [client 50.116.65.227:48074] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kdzYN371eKRzcKeR6GgAAAK0"]
[Mon Jul 20 07:36:55.423663 2026] [security2:error] [pid 164535:tid 164747] [client 50.116.65.227:48080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kdzYN371eKRzcKeR6GwAAANc"]
[Mon Jul 20 07:36:55.425395 2026] [security2:error] [pid 164535:tid 164644] [remote 45.90.123.233:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kdzYN371eKRzcKeR6HAAA72w"]
[Mon Jul 20 07:36:55.490762 2026] [security2:error] [pid 171532:tid 171752] [client 57.141.18.50:32990] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdEEhLvMuMRNpl0322QABZEI"]
[Mon Jul 20 07:36:55.501523 2026] [security2:error] [pid 164535:tid 164678] [client 45.157.112.60:50743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kdzYN371eKRzcKeR6HgAAAJI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:36:55.515803 2026] [security2:error] [pid 171532:tid 171710] [client 103.139.191.61:56018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kd0EhLvMuMRNpl033dQAAATo"]
[Mon Jul 20 07:36:55.515971 2026] [security2:error] [pid 171532:tid 171710] [client 103.139.191.61:56018] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kd0EhLvMuMRNpl033dQAAATo"]
[Mon Jul 20 07:36:55.521896 2026] [security2:error] [pid 171532:tid 171742] [client 188.166.209.66:65377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/utf8.php"] [unique_id "al4kd0EhLvMuMRNpl033dwAAAVo"], referer: binance.com
[Mon Jul 20 07:36:55.681904 2026] [security2:error] [pid 164535:tid 164547] [remote 45.90.123.233:58934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kdzYN371eKRzcKeR6IQAAtQs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:36:55.684265 2026] [security2:error] [pid 171532:tid 171678] [client 57.141.18.40:54846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdUEhLvMuMRNpl0326gABGg4"]
[Mon Jul 20 07:36:55.826351 2026] [security2:error] [pid 171532:tid 171774] [client 57.141.18.6:33902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdUEhLvMuMRNpl0328QABeR8"]
[Mon Jul 20 07:36:56.287579 2026] [security2:error] [pid 171532:tid 171689] [client 14.225.17.146:59400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4kdkEhLvMuMRNpl033RgAAASU"], referer: http://nurturemarple.co.uk/demo
[Mon Jul 20 07:36:56.288658 2026] [core:error] [pid 164535:tid 164683] [client 14.225.17.146:56007] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:36:56.288686 2026] [core:error] [pid 164535:tid 164683] [client 14.225.17.146:56007] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:36:56.333684 2026] [security2:error] [pid 171532:tid 171680] [client 14.225.17.146:57337] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4kdkEhLvMuMRNpl033LQAAARw"], referer: http://securingmemories.com/demo
[Mon Jul 20 07:36:56.442101 2026] [security2:error] [pid 171532:tid 171762] [client 20.29.126.15:8702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/ms-edit.php"] [unique_id "al4keEEhLvMuMRNpl033tgAAAW4"]
[Mon Jul 20 07:36:56.442195 2026] [security2:error] [pid 171532:tid 171762] [client 20.29.126.15:8702] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/ms-edit.php"] [unique_id "al4keEEhLvMuMRNpl033tgAAAW4"]
[Mon Jul 20 07:36:56.520320 2026] [security2:error] [pid 171532:tid 171749] [client 57.141.18.97:51498] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdUEhLvMuMRNpl033GgABYSU"]
[Mon Jul 20 07:36:56.561474 2026] [security2:error] [pid 171532:tid 171646] [remote 5.161.225.162:56728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4keEEhLvMuMRNpl033uwABaXE"]
[Mon Jul 20 07:36:56.733513 2026] [security2:error] [pid 164535:tid 164773] [client 20.29.126.15:8661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/simple.php"] [unique_id "al4keDYN371eKRzcKeR6NwAAAPE"]
[Mon Jul 20 07:36:56.733618 2026] [security2:error] [pid 164535:tid 164773] [client 20.29.126.15:8661] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/simple.php"] [unique_id "al4keDYN371eKRzcKeR6NwAAAPE"]
[Mon Jul 20 07:36:56.750487 2026] [security2:error] [pid 171532:tid 171653] [remote 5.161.225.162:56728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4keEEhLvMuMRNpl033xQABJng"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:36:56.783712 2026] [security2:error] [pid 171532:tid 171733] [client 50.116.65.227:48118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4keEEhLvMuMRNpl033tAAAAVE"]
[Mon Jul 20 07:36:56.813919 2026] [security2:error] [pid 171532:tid 171697] [client 57.141.18.18:23018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdkEhLvMuMRNpl033KwABLTo"]
[Mon Jul 20 07:36:56.996991 2026] [security2:error] [pid 171532:tid 171699] [client 57.141.18.79:63464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdkEhLvMuMRNpl033OgABLwI"]
[Mon Jul 20 07:36:57.010018 2026] [security2:error] [pid 164535:tid 164701] [client 50.116.65.227:48140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4keDYN371eKRzcKeR6OgAAAKk"]
[Mon Jul 20 07:36:57.108430 2026] [security2:error] [pid 171532:tid 171664] [client 57.141.18.63:42740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kdkEhLvMuMRNpl033QAABDEY"]
[Mon Jul 20 07:36:57.197374 2026] [security2:error] [pid 164535:tid 164774] [client 20.29.126.15:3280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/404.php"] [unique_id "al4keTYN371eKRzcKeR6QgAAAPI"]
[Mon Jul 20 07:36:57.197460 2026] [security2:error] [pid 164535:tid 164774] [client 20.29.126.15:3280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/404.php"] [unique_id "al4keTYN371eKRzcKeR6QgAAAPI"]
[Mon Jul 20 07:36:57.222613 2026] [security2:error] [pid 171532:tid 171701] [client 14.225.17.146:57675] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4keUEhLvMuMRNpl0330wAAATE"], referer: https://nurturemarple.co.uk/demo
[Mon Jul 20 07:36:57.311023 2026] [security2:error] [pid 171532:tid 171727] [client 136.158.60.21:60147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0331wAAAUs"]
[Mon Jul 20 07:36:57.311131 2026] [security2:error] [pid 171532:tid 171727] [client 136.158.60.21:60147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0331wAAAUs"]
[Mon Jul 20 07:36:57.351616 2026] [security2:error] [pid 171532:tid 171709] [client 49.37.242.14:61670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0332wAAATk"]
[Mon Jul 20 07:36:57.351697 2026] [security2:error] [pid 171532:tid 171709] [client 49.37.242.14:61670] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0332wAAATk"]
[Mon Jul 20 07:36:57.432178 2026] [security2:error] [pid 171532:tid 171671] [client 191.202.66.27:53532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0334QAAARM"]
[Mon Jul 20 07:36:57.433767 2026] [security2:error] [pid 171532:tid 171671] [client 191.202.66.27:53532] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0334QAAARM"]
[Mon Jul 20 07:36:57.445245 2026] [lsapi:warn] [pid 171532:tid 171611] [remote 20.191.45.212:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: http://ali-alghanim.com
[Mon Jul 20 07:36:57.481583 2026] [security2:error] [pid 171532:tid 171731] [client 103.176.215.66:61710] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0335QAAAU8"]
[Mon Jul 20 07:36:57.482053 2026] [security2:error] [pid 171532:tid 171731] [client 103.176.215.66:61710] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4keUEhLvMuMRNpl0335QAAAU8"]
[Mon Jul 20 07:36:57.850841 2026] [security2:error] [pid 171532:tid 171675] [client 57.141.18.101:22932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kd0EhLvMuMRNpl033cQABF2Q"]
[Mon Jul 20 07:36:57.851289 2026] [security2:error] [pid 171532:tid 171704] [client 20.29.126.15:12447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/file3.php"] [unique_id "al4keUEhLvMuMRNpl034AwAAATQ"]
[Mon Jul 20 07:36:57.851357 2026] [security2:error] [pid 171532:tid 171704] [client 20.29.126.15:12447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/file3.php"] [unique_id "al4keUEhLvMuMRNpl034AwAAATQ"]
[Mon Jul 20 07:36:57.867799 2026] [security2:error] [pid 171532:tid 171694] [client 14.225.17.146:57654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4kd0EhLvMuMRNpl033XwAAASo"]
[Mon Jul 20 07:36:57.896687 2026] [security2:error] [pid 171532:tid 171757] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4keUEhLvMuMRNpl0339QAAAWk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:36:58.339453 2026] [security2:error] [pid 171532:tid 171606] [remote 57.141.18.35:55330] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3296202"] [unique_id "al4kekEhLvMuMRNpl034FwABHEk"]
[Mon Jul 20 07:36:58.364924 2026] [security2:error] [pid 171532:tid 171686] [client 14.225.17.146:56861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4keEEhLvMuMRNpl033zgAAASI"], referer: http://inspirespublishing.com/demo
[Mon Jul 20 07:36:58.577619 2026] [security2:error] [pid 164535:tid 164590] [remote 100.42.189.89:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4kejYN371eKRzcKeR6aAAAtjY"]
[Mon Jul 20 07:36:58.823666 2026] [security2:error] [pid 164535:tid 164551] [remote 100.42.189.89:58130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4kejYN371eKRzcKeR6iQAApw8"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:36:58.944977 2026] [security2:error] [pid 171532:tid 171782] [client 14.225.17.146:59216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4kekEhLvMuMRNpl034LAAAAYE"], referer: http://falconarrowshop.com/demo
[Mon Jul 20 07:36:59.192169 2026] [security2:error] [pid 171532:tid 171722] [client 57.141.18.52:60070] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4keEEhLvMuMRNpl0330AABRjI"]
[Mon Jul 20 07:36:59.294982 2026] [security2:error] [pid 171532:tid 171746] [client 179.127.84.238:57095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ke0EhLvMuMRNpl034TQAAAV4"]
[Mon Jul 20 07:36:59.295126 2026] [security2:error] [pid 171532:tid 171746] [client 179.127.84.238:57095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ke0EhLvMuMRNpl034TQAAAV4"]
[Mon Jul 20 07:36:59.359852 2026] [security2:error] [pid 171532:tid 171707] [client 116.74.65.235:65518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ke0EhLvMuMRNpl034TwAAATc"]
[Mon Jul 20 07:36:59.359991 2026] [security2:error] [pid 171532:tid 171707] [client 116.74.65.235:65518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ke0EhLvMuMRNpl034TwAAATc"]
[Mon Jul 20 07:36:59.466649 2026] [security2:error] [pid 164535:tid 164764] [client 57.141.18.84:33782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4keTYN371eKRzcKeR6SgAA6C8"]
[Mon Jul 20 07:36:59.476074 2026] [security2:error] [pid 171532:tid 171670] [client 3.85.245.91:31546] ModSecurity: Warning. Matched phrase "Slackbot-LinkExpanding" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/"] [unique_id "al4ke0EhLvMuMRNpl034VQAAARI"]
[Mon Jul 20 07:36:59.521980 2026] [security2:error] [pid 171532:tid 171737] [client 20.29.126.15:14414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/wp-mail.php"] [unique_id "al4ke0EhLvMuMRNpl034WwAAAVU"]
[Mon Jul 20 07:36:59.522087 2026] [security2:error] [pid 171532:tid 171737] [client 20.29.126.15:14414] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/wp-mail.php"] [unique_id "al4ke0EhLvMuMRNpl034WwAAAVU"]
[Mon Jul 20 07:36:59.664734 2026] [security2:error] [pid 171532:tid 171754] [client 57.141.18.23:35702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4keUEhLvMuMRNpl0336QABZhQ"]
[Mon Jul 20 07:37:00.049529 2026] [security2:error] [pid 171532:tid 171693] [client 158.173.166.181:31467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kfEEhLvMuMRNpl034ewAAASk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:37:00.082767 2026] [security2:error] [pid 164535:tid 164676] [client 100.28.224.123:32912] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-content/uploads/2024/01/3.png"] [unique_id "al4kezYN371eKRzcKeR6mQAAALk"]
[Mon Jul 20 07:37:00.183519 2026] [security2:error] [pid 171532:tid 171698] [client 41.132.60.63:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kfEEhLvMuMRNpl034egAAAS4"]
[Mon Jul 20 07:37:00.376218 2026] [security2:error] [pid 164535:tid 164770] [client 3.226.122.218:23870] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-content/uploads/2024/01/cropped-BLAIZE-ACCOUNTING-SERVICE-LOGO-Blue-copymark-180x180.jpg"] [unique_id "al4kfDYN371eKRzcKeR6qgAAAO4"]
[Mon Jul 20 07:37:00.394101 2026] [security2:error] [pid 164535:tid 164787] [client 3.94.129.44:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/cgi-sys/404.html"] [unique_id "al4kfDYN371eKRzcKeR6rAAAAP8"]
[Mon Jul 20 07:37:00.398659 2026] [security2:error] [pid 171532:tid 171728] [client 3.94.129.44:12808] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/favicon.ico"] [unique_id "al4kfEEhLvMuMRNpl034iAAAAUw"]
[Mon Jul 20 07:37:00.756116 2026] [security2:error] [pid 171532:tid 171598] [remote 57.141.18.51:49248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 51.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4910317"] [unique_id "al4kfEEhLvMuMRNpl034ngABgUE"]
[Mon Jul 20 07:37:00.954970 2026] [security2:error] [pid 171532:tid 171721] [client 117.211.236.168:54787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.236.211.117.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kfEEhLvMuMRNpl034qQAAAUU"]
[Mon Jul 20 07:37:00.955078 2026] [security2:error] [pid 171532:tid 171721] [client 117.211.236.168:54787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "roguedragonstudio.com"] [uri "/xmlrpc.php"] [unique_id "al4kfEEhLvMuMRNpl034qQAAAUU"]
[Mon Jul 20 07:37:01.013408 2026] [security2:error] [pid 171532:tid 171756] [client 57.141.18.2:53040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kekEhLvMuMRNpl034QAABaFk"]
[Mon Jul 20 07:37:01.404923 2026] [security2:error] [pid 171532:tid 171666] [client 13.201.189.162:54038] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "blaizeaccountingservices.com"] [uri "/wp-content/uploads/2024/01/cropped-BLAIZE-ACCOUNTING-SERVICE-LOGO-Blue-copymark-180x180.jpg"] [unique_id "al4kfUEhLvMuMRNpl034vwABDks"]
[Mon Jul 20 07:37:01.833433 2026] [security2:error] [pid 164535:tid 164757] [client 180.249.173.210:54292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kfTYN371eKRzcKeR6xQAAAOE"]
[Mon Jul 20 07:37:01.834320 2026] [security2:error] [pid 164535:tid 164757] [client 180.249.173.210:54292] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kfTYN371eKRzcKeR6xQAAAOE"]
[Mon Jul 20 07:37:01.884028 2026] [security2:error] [pid 171532:tid 171541] [remote 199.189.225.40:56561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4kfUEhLvMuMRNpl0344AABcwg"]
[Mon Jul 20 07:37:01.898278 2026] [security2:error] [pid 164535:tid 164766] [client 20.29.126.15:14447] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/about.php"] [unique_id "al4kfTYN371eKRzcKeR6xwAAAOo"]
[Mon Jul 20 07:37:01.898420 2026] [security2:error] [pid 164535:tid 164766] [client 20.29.126.15:14447] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/about.php"] [unique_id "al4kfTYN371eKRzcKeR6xwAAAOo"]
[Mon Jul 20 07:37:02.196662 2026] [security2:error] [pid 171532:tid 171539] [remote 199.189.225.40:56561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.225.189.199.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4kfkEhLvMuMRNpl0348QABEwY"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 07:37:02.219482 2026] [security2:error] [pid 171532:tid 171676] [client 65.111.28.58:36393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 58.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kfkEhLvMuMRNpl0348AAAARg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:02.445143 2026] [security2:error] [pid 171532:tid 171729] [client 143.44.185.218:61727] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kfkEhLvMuMRNpl035AQAAAU0"]
[Mon Jul 20 07:37:02.445247 2026] [security2:error] [pid 171532:tid 171729] [client 143.44.185.218:61727] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kfkEhLvMuMRNpl035AQAAAU0"]
[Mon Jul 20 07:37:02.489604 2026] [security2:error] [pid 171532:tid 171783] [client 49.47.218.174:57629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kfkEhLvMuMRNpl035BgAAAYI"]
[Mon Jul 20 07:37:02.489721 2026] [security2:error] [pid 171532:tid 171783] [client 49.47.218.174:57629] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kfkEhLvMuMRNpl035BgAAAYI"]
[Mon Jul 20 07:37:02.590142 2026] [security2:error] [pid 171532:tid 171741] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kfkEhLvMuMRNpl034_QAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:02.867110 2026] [security2:error] [pid 164535:tid 164681] [client 65.111.28.79:47369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kfjYN371eKRzcKeR61gAAAJU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:03.032031 2026] [security2:error] [pid 171532:tid 171697] [client 20.29.126.15:3963] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/wp.php"] [unique_id "al4kf0EhLvMuMRNpl035KgAAAS0"]
[Mon Jul 20 07:37:03.032127 2026] [security2:error] [pid 171532:tid 171697] [client 20.29.126.15:3963] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/wp.php"] [unique_id "al4kf0EhLvMuMRNpl035KgAAAS0"]
[Mon Jul 20 07:37:03.336852 2026] [security2:error] [pid 171532:tid 171688] [client 157.20.138.62:59826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kf0EhLvMuMRNpl035NgAAASQ"]
[Mon Jul 20 07:37:03.336992 2026] [security2:error] [pid 171532:tid 171688] [client 157.20.138.62:59826] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kf0EhLvMuMRNpl035NgAAASQ"]
[Mon Jul 20 07:37:03.541722 2026] [security2:error] [pid 171532:tid 171768] [client 185.238.231.67:63147] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4kf0EhLvMuMRNpl035RgAAAXQ"]
[Mon Jul 20 07:37:03.563248 2026] [security2:error] [pid 171532:tid 171730] [client 185.238.231.249:24627] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4kf0EhLvMuMRNpl035RQAAAU4"]
[Mon Jul 20 07:37:03.745720 2026] [security2:error] [pid 171532:tid 171767] [client 193.36.225.41:45375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 41.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4kf0EhLvMuMRNpl035UgAAAXM"]
[Mon Jul 20 07:37:03.746370 2026] [security2:error] [pid 171532:tid 171760] [client 136.144.33.200:47415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4kf0EhLvMuMRNpl035UQAAAWw"]
[Mon Jul 20 07:37:03.858175 2026] [security2:error] [pid 171532:tid 171755] [client 116.193.128.26:50804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kf0EhLvMuMRNpl035WgAAAWc"]
[Mon Jul 20 07:37:03.858848 2026] [security2:error] [pid 171532:tid 171755] [client 116.193.128.26:50804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kf0EhLvMuMRNpl035WgAAAWc"]
[Mon Jul 20 07:37:03.954761 2026] [security2:error] [pid 171532:tid 171762] [client 142.111.152.63:51303] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kf0EhLvMuMRNpl035VwAAAW4"]
[Mon Jul 20 07:37:04.034942 2026] [security2:error] [pid 171532:tid 171696] [client 149.0.16.108:63193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kgEEhLvMuMRNpl035awAAASw"]
[Mon Jul 20 07:37:04.035042 2026] [security2:error] [pid 171532:tid 171696] [client 149.0.16.108:63193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kgEEhLvMuMRNpl035awAAASw"]
[Mon Jul 20 07:37:04.196245 2026] [security2:error] [pid 171532:tid 171679] [client 20.29.126.15:9711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/adminfuns.php"] [unique_id "al4kgEEhLvMuMRNpl035dwAAARs"]
[Mon Jul 20 07:37:04.196318 2026] [security2:error] [pid 171532:tid 171679] [client 20.29.126.15:9711] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/adminfuns.php"] [unique_id "al4kgEEhLvMuMRNpl035dwAAARs"]
[Mon Jul 20 07:37:04.306407 2026] [security2:error] [pid 171532:tid 171709] [client 14.182.195.220:52819] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kgEEhLvMuMRNpl035fgAAATk"]
[Mon Jul 20 07:37:04.442142 2026] [security2:error] [pid 164535:tid 164620] [remote 72.167.132.114:46208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4kgDYN371eKRzcKeR67AABA1Q"]
[Mon Jul 20 07:37:04.497212 2026] [security2:error] [pid 171532:tid 171576] [remote 152.228.213.32:36542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kgEEhLvMuMRNpl035hgABJys"]
[Mon Jul 20 07:37:04.740736 2026] [security2:error] [pid 171532:tid 171707] [client 36.93.152.155:52124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kgEEhLvMuMRNpl035lgAAATc"]
[Mon Jul 20 07:37:04.740846 2026] [security2:error] [pid 171532:tid 171707] [client 36.93.152.155:52124] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kgEEhLvMuMRNpl035lgAAATc"]
[Mon Jul 20 07:37:04.809041 2026] [security2:error] [pid 171532:tid 171660] [remote 152.228.213.32:36542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kgEEhLvMuMRNpl035mgABEX8"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:37:04.839547 2026] [security2:error] [pid 164535:tid 164597] [remote 72.167.132.114:46208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "faadenergy.com"] [uri "/wp-login.php"] [unique_id "al4kgDYN371eKRzcKeR68AAA4j0"], referer: https://faadenergy.com/wp-login.php
[Mon Jul 20 07:37:04.903528 2026] [security2:error] [pid 171532:tid 171727] [client 154.192.123.127:18766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kgEEhLvMuMRNpl035pgAAAUs"]
[Mon Jul 20 07:37:04.903637 2026] [security2:error] [pid 171532:tid 171727] [client 154.192.123.127:18766] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kgEEhLvMuMRNpl035pgAAAUs"]
[Mon Jul 20 07:37:04.962659 2026] [security2:error] [pid 171532:tid 171640] [remote 5.161.225.162:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4kgEEhLvMuMRNpl035rQABhms"]
[Mon Jul 20 07:37:05.159660 2026] [security2:error] [pid 171532:tid 171632] [remote 5.161.225.162:56944] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/wp-login.php"] [unique_id "al4kgUEhLvMuMRNpl035uAABV2M"], referer: https://www.narv.co/wp-login.php
[Mon Jul 20 07:37:05.504861 2026] [security2:error] [pid 164535:tid 164548] [remote 47.86.33.52:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4kgTYN371eKRzcKeR69wAA1Aw"]
[Mon Jul 20 07:37:05.580595 2026] [security2:error] [pid 171532:tid 171744] [client 103.106.165.44:57262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kgUEhLvMuMRNpl0352gAAAVw"]
[Mon Jul 20 07:37:05.580712 2026] [security2:error] [pid 171532:tid 171744] [client 103.106.165.44:57262] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kgUEhLvMuMRNpl0352gAAAVw"]
[Mon Jul 20 07:37:05.702957 2026] [security2:error] [pid 171532:tid 171706] [client 20.29.126.15:12618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.126.29.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "webmail.fansarogroup.com"] [uri "/php8.php"] [unique_id "al4kgUEhLvMuMRNpl0354wAAATY"]
[Mon Jul 20 07:37:05.703087 2026] [security2:error] [pid 171532:tid 171706] [client 20.29.126.15:12618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "webmail.fansarogroup.com"] [uri "/php8.php"] [unique_id "al4kgUEhLvMuMRNpl0354wAAATY"]
[Mon Jul 20 07:37:05.742811 2026] [cgid:error] [pid 171532:tid 171764] [client 167.94.146.50:64608] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: https://smtracking.genesismbs.com:443/cgi-bin
[Mon Jul 20 07:37:05.761652 2026] [security2:error] [pid 164535:tid 164708] [client 57.141.18.57:51806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kfzYN371eKRzcKeR63gAAsDE"]
[Mon Jul 20 07:37:06.049686 2026] [security2:error] [pid 164535:tid 164602] [remote 47.86.33.52:2564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4kgjYN371eKRzcKeR7AgAAxEI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:37:06.301066 2026] [security2:error] [pid 171532:tid 171686] [client 57.141.18.101:43750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kf0EhLvMuMRNpl035WAABIik"]
[Mon Jul 20 07:37:06.509166 2026] [security2:error] [pid 171532:tid 171607] [remote 124.55.178.99:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kgkEhLvMuMRNpl036EAABY0o"]
[Mon Jul 20 07:37:06.590087 2026] [security2:error] [pid 171532:tid 171693] [client 57.141.18.96:33270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kgEEhLvMuMRNpl035dAABKTY"]
[Mon Jul 20 07:37:06.828903 2026] [security2:error] [pid 171532:tid 171766] [client 103.139.191.61:56496] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kgkEhLvMuMRNpl036JwAAAXI"]
[Mon Jul 20 07:37:06.829006 2026] [security2:error] [pid 171532:tid 171766] [client 103.139.191.61:56496] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kgkEhLvMuMRNpl036JwAAAXI"]
[Mon Jul 20 07:37:06.934258 2026] [security2:error] [pid 171532:tid 171539] [remote 124.55.178.99:44344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kgkEhLvMuMRNpl036KwABTwY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:37:06.934371 2026] [security2:error] [pid 164535:tid 164700] [client 66.249.65.172:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4kgjYN371eKRzcKeR7CQAAAKg"]
[Mon Jul 20 07:37:07.051342 2026] [security2:error] [pid 171532:tid 171719] [client 158.173.89.95:20507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kg0EhLvMuMRNpl036LwAAAUM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:37:07.432053 2026] [security2:error] [pid 171532:tid 171742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kg0EhLvMuMRNpl036PgAAAVo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:07.490589 2026] [security2:error] [pid 171532:tid 171783] [client 14.225.17.146:55981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4kgkEhLvMuMRNpl0359QAAAYI"]
[Mon Jul 20 07:37:07.511219 2026] [security2:error] [pid 171532:tid 171776] [client 57.141.18.65:25700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kgUEhLvMuMRNpl035sgABews"]
[Mon Jul 20 07:37:07.761074 2026] [security2:error] [pid 171532:tid 171716] [client 140.245.46.64:57425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kg0EhLvMuMRNpl036ZwAAAUA"]
[Mon Jul 20 07:37:07.774819 2026] [security2:error] [pid 171532:tid 171766] [client 66.249.74.42:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4kg0EhLvMuMRNpl036VAAAAXI"]
[Mon Jul 20 07:37:08.016421 2026] [security2:error] [pid 171532:tid 171770] [client 136.158.60.21:61609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4khEEhLvMuMRNpl036dgAAAXY"]
[Mon Jul 20 07:37:08.016524 2026] [security2:error] [pid 171532:tid 171770] [client 136.158.60.21:61609] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4khEEhLvMuMRNpl036dgAAAXY"]
[Mon Jul 20 07:37:08.041256 2026] [security2:error] [pid 171532:tid 171758] [client 103.176.215.66:62247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4khEEhLvMuMRNpl036eAAAAWo"]
[Mon Jul 20 07:37:08.041662 2026] [security2:error] [pid 171532:tid 171758] [client 103.176.215.66:62247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4khEEhLvMuMRNpl036eAAAAWo"]
[Mon Jul 20 07:37:08.076463 2026] [security2:error] [pid 171532:tid 171683] [client 57.141.18.58:62680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kgUEhLvMuMRNpl0351AABH28"]
[Mon Jul 20 07:37:08.141807 2026] [security2:error] [pid 171532:tid 171733] [client 191.202.66.27:54020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4khEEhLvMuMRNpl036ewAAAVE"]
[Mon Jul 20 07:37:08.141900 2026] [security2:error] [pid 171532:tid 171733] [client 191.202.66.27:54020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4khEEhLvMuMRNpl036ewAAAVE"]
[Mon Jul 20 07:37:08.167942 2026] [security2:error] [pid 171532:tid 171697] [client 50.116.65.227:31264] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4khEEhLvMuMRNpl036fQAAAS0"]
[Mon Jul 20 07:37:08.180878 2026] [security2:error] [pid 171532:tid 171687] [client 50.116.65.227:31272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4khEEhLvMuMRNpl036fwAAASM"]
[Mon Jul 20 07:37:08.504122 2026] [security2:error] [pid 171532:tid 171696] [client 57.141.18.70:20590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kgkEhLvMuMRNpl0358wABLH4"]
[Mon Jul 20 07:37:08.588543 2026] [security2:error] [pid 171532:tid 171741] [client 188.166.209.66:49916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/view-transitions.php"] [unique_id "al4khEEhLvMuMRNpl036lgAAAVk"], referer: binance.com
[Mon Jul 20 07:37:08.646105 2026] [security2:error] [pid 171532:tid 171666] [client 14.225.17.146:59238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4khEEhLvMuMRNpl036kwAAAQ4"], referer: http://eframiproperties.com/bc
[Mon Jul 20 07:37:08.972997 2026] [security2:error] [pid 171532:tid 171740] [client 57.141.18.54:40428] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kgkEhLvMuMRNpl036CAABWDo"]
[Mon Jul 20 07:37:09.183130 2026] [security2:error] [pid 164535:tid 164780] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4khDYN371eKRzcKeR7UQAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:09.246012 2026] [security2:error] [pid 171532:tid 171753] [client 57.141.18.43:55764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kgkEhLvMuMRNpl036IwABZRc"]
[Mon Jul 20 07:37:09.552528 2026] [security2:error] [pid 171532:tid 171775] [client 140.245.46.64:58436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4khUEhLvMuMRNpl036wwAAAXo"]
[Mon Jul 20 07:37:09.761203 2026] [security2:error] [pid 171532:tid 171686] [client 179.127.84.238:57634] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4khUEhLvMuMRNpl036zwAAASI"]
[Mon Jul 20 07:37:09.761346 2026] [security2:error] [pid 171532:tid 171686] [client 179.127.84.238:57634] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4khUEhLvMuMRNpl036zwAAASI"]
[Mon Jul 20 07:37:09.959552 2026] [security2:error] [pid 171532:tid 171785] [client 57.141.18.10:56318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kg0EhLvMuMRNpl036TgABhF8"]
[Mon Jul 20 07:37:10.123847 2026] [security2:error] [pid 164535:tid 164682] [client 140.245.46.64:58759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-admin/load-scripts.php"] [unique_id "al4khjYN371eKRzcKeR7agAAAJY"]
[Mon Jul 20 07:37:10.396762 2026] [security2:error] [pid 171532:tid 171712] [client 14.225.17.146:63976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4khkEhLvMuMRNpl0369AAAATw"], referer: http://according2plant.com/bc
[Mon Jul 20 07:37:10.400006 2026] [security2:error] [pid 171532:tid 171577] [remote 202.51.202.242:44148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.innspace.ca"] [uri "/wp-login.php"] [unique_id "al4khkEhLvMuMRNpl036_QABZiw"]
[Mon Jul 20 07:37:10.435890 2026] [security2:error] [pid 171532:tid 171753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4khkEhLvMuMRNpl0367QAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:10.694408 2026] [security2:error] [pid 171532:tid 171710] [client 140.245.46.64:59011] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-admin/load-styles.php"] [unique_id "al4khkEhLvMuMRNpl037DwAAATo"]
[Mon Jul 20 07:37:11.195539 2026] [security2:error] [pid 171532:tid 171777] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4khkEhLvMuMRNpl037IwAAAXw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:11.325538 2026] [security2:error] [pid 171532:tid 171701] [client 57.141.18.61:29914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4khEEhLvMuMRNpl036oAABMU8"]
[Mon Jul 20 07:37:11.696965 2026] [security2:error] [pid 171532:tid 171741] [client 65.111.22.167:49273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kh0EhLvMuMRNpl037QQAAAVk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:11.999249 2026] [security2:error] [pid 171532:tid 171739] [client 49.37.242.14:62173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kh0EhLvMuMRNpl037XQAAAVc"]
[Mon Jul 20 07:37:11.999348 2026] [security2:error] [pid 171532:tid 171739] [client 49.37.242.14:62173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kh0EhLvMuMRNpl037XQAAAVc"]
[Mon Jul 20 07:37:12.035982 2026] [security2:error] [pid 171532:tid 171698] [client 57.141.18.102:35710] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4khUEhLvMuMRNpl036wQABLg8"]
[Mon Jul 20 07:37:12.154581 2026] [security2:error] [pid 171532:tid 171749] [client 180.249.173.210:54771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kiEEhLvMuMRNpl037YwAAAWE"]
[Mon Jul 20 07:37:12.155367 2026] [security2:error] [pid 171532:tid 171749] [client 180.249.173.210:54771] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kiEEhLvMuMRNpl037YwAAAWE"]
[Mon Jul 20 07:37:12.320254 2026] [security2:error] [pid 164535:tid 164741] [client 14.225.17.146:59260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4kiDYN371eKRzcKeR7ngAAANE"]
[Mon Jul 20 07:37:12.563431 2026] [security2:error] [pid 171532:tid 171724] [client 216.24.212.21:47253] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4kiEEhLvMuMRNpl037eAAAAUg"]
[Mon Jul 20 07:37:12.607454 2026] [security2:error] [pid 171532:tid 171700] [client 216.24.212.74:38027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4kiEEhLvMuMRNpl037fAAAATA"]
[Mon Jul 20 07:37:12.763472 2026] [security2:error] [pid 171532:tid 171681] [client 57.141.18.74:45930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4khkEhLvMuMRNpl036_gABHV4"]
[Mon Jul 20 07:37:12.769929 2026] [security2:error] [pid 164535:tid 164697] [client 57.141.18.71:47108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4khjYN371eKRzcKeR7cgAApXo"]
[Mon Jul 20 07:37:12.854155 2026] [security2:error] [pid 171532:tid 171673] [client 49.47.218.174:58173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kiEEhLvMuMRNpl037igAAARU"]
[Mon Jul 20 07:37:12.854280 2026] [security2:error] [pid 171532:tid 171673] [client 49.47.218.174:58173] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kiEEhLvMuMRNpl037igAAARU"]
[Mon Jul 20 07:37:12.892038 2026] [security2:error] [pid 171532:tid 171694] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kiEEhLvMuMRNpl037hAAAASo"]
[Mon Jul 20 07:37:13.210865 2026] [security2:error] [pid 164535:tid 164752] [client 57.141.18.38:28440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4khjYN371eKRzcKeR7hgAA3Ek"]
[Mon Jul 20 07:37:13.538127 2026] [security2:error] [pid 171532:tid 171732] [client 50.116.65.227:60214] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kiUEhLvMuMRNpl037twAAAVA"]
[Mon Jul 20 07:37:13.548091 2026] [security2:error] [pid 164535:tid 164780] [client 50.116.65.227:60220] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kiTYN371eKRzcKeR7xgAAAPg"]
[Mon Jul 20 07:37:13.552453 2026] [security2:error] [pid 171532:tid 171738] [client 57.141.18.24:65420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kh0EhLvMuMRNpl037NwABVi0"]
[Mon Jul 20 07:37:13.707402 2026] [security2:error] [pid 164535:tid 164764] [client 140.245.46.64:60584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-includes/version.php"] [unique_id "al4kiTYN371eKRzcKeR7zwAAAOg"]
[Mon Jul 20 07:37:13.819744 2026] [security2:error] [pid 164535:tid 164762] [client 14.225.17.146:58950] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4kiTYN371eKRzcKeR70QAAAOY"]
[Mon Jul 20 07:37:13.860028 2026] [security2:error] [pid 171532:tid 171705] [client 157.20.138.62:60412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kiUEhLvMuMRNpl037xgAAATU"]
[Mon Jul 20 07:37:13.860123 2026] [security2:error] [pid 171532:tid 171705] [client 157.20.138.62:60412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kiUEhLvMuMRNpl037xgAAATU"]
[Mon Jul 20 07:37:13.952104 2026] [security2:error] [pid 164535:tid 164727] [client 57.141.18.25:47964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4khzYN371eKRzcKeR7kwAAw2g"]
[Mon Jul 20 07:37:14.066739 2026] [security2:error] [pid 171532:tid 171713] [client 52.167.144.19:61348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4kiUEhLvMuMRNpl037ywABPRk"]
[Mon Jul 20 07:37:14.289774 2026] [security2:error] [pid 164535:tid 164709] [client 140.245.46.64:60902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-includes/functions.php"] [unique_id "al4kijYN371eKRzcKeR75wAAALE"]
[Mon Jul 20 07:37:14.295855 2026] [security2:error] [pid 171532:tid 171755] [client 14.225.17.146:58875] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4kiUEhLvMuMRNpl037mgAAAWc"], referer: http://alaraycreative.com/bc
[Mon Jul 20 07:37:14.336070 2026] [security2:error] [pid 164535:tid 164665] [client 57.141.18.112:40840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kiDYN371eKRzcKeR7pAAAhVs"]
[Mon Jul 20 07:37:14.420383 2026] [security2:error] [pid 171532:tid 171722] [client 116.193.128.26:51368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kikEhLvMuMRNpl0374wAAAUY"]
[Mon Jul 20 07:37:14.421001 2026] [security2:error] [pid 171532:tid 171722] [client 116.193.128.26:51368] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kikEhLvMuMRNpl0374wAAAUY"]
[Mon Jul 20 07:37:14.522138 2026] [security2:error] [pid 164535:tid 164684] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kijYN371eKRzcKeR76QAAAJg"]
[Mon Jul 20 07:37:14.539021 2026] [security2:error] [pid 164535:tid 164718] [client 142.111.152.178:49115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kijYN371eKRzcKeR76wAAALo"]
[Mon Jul 20 07:37:14.556977 2026] [security2:error] [pid 164535:tid 164677] [client 14.225.17.146:54169] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4kijYN371eKRzcKeR73QAAAJE"], referer: http://onewingpictures.com/bc
[Mon Jul 20 07:37:14.590897 2026] [security2:error] [pid 171532:tid 171700] [client 149.0.16.108:63709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kikEhLvMuMRNpl0378QAAATA"]
[Mon Jul 20 07:37:14.591618 2026] [security2:error] [pid 171532:tid 171700] [client 149.0.16.108:63709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kikEhLvMuMRNpl0378QAAATA"]
[Mon Jul 20 07:37:14.872668 2026] [security2:error] [pid 171532:tid 171739] [client 140.245.46.64:61182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-includes/class-wp.php"] [unique_id "al4kikEhLvMuMRNpl037_gAAAVc"]
[Mon Jul 20 07:37:15.039545 2026] [security2:error] [pid 171532:tid 171630] [remote 72.167.132.114:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ki0EhLvMuMRNpl038DAABe2E"]
[Mon Jul 20 07:37:15.240544 2026] [security2:error] [pid 171532:tid 171686] [client 14.225.17.146:49464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4ki0EhLvMuMRNpl038EAAAASI"], referer: http://aljosour-alarabia.com/bc
[Mon Jul 20 07:37:15.278444 2026] [security2:error] [pid 171532:tid 171554] [remote 72.167.132.114:59622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ki0EhLvMuMRNpl038HAABHRU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:37:15.292942 2026] [security2:error] [pid 164535:tid 164698] [client 57.141.18.17:60062] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kiTYN371eKRzcKeR7wgAApi8"]
[Mon Jul 20 07:37:15.354134 2026] [security2:error] [pid 171532:tid 171675] [client 36.93.152.155:52697] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ki0EhLvMuMRNpl038IAAAARc"]
[Mon Jul 20 07:37:15.354226 2026] [security2:error] [pid 171532:tid 171675] [client 36.93.152.155:52697] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ki0EhLvMuMRNpl038IAAAARc"]
[Mon Jul 20 07:37:15.378434 2026] [security2:error] [pid 164535:tid 164740] [client 154.192.123.127:17216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kizYN371eKRzcKeR7_wAAANA"]
[Mon Jul 20 07:37:15.378547 2026] [security2:error] [pid 164535:tid 164740] [client 154.192.123.127:17216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kizYN371eKRzcKeR7_wAAANA"]
[Mon Jul 20 07:37:15.447241 2026] [security2:error] [pid 164535:tid 164743] [client 140.245.46.64:61484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-includes/option.php"] [unique_id "al4kizYN371eKRzcKeR8AQAAANM"]
[Mon Jul 20 07:37:15.795413 2026] [security2:error] [pid 171532:tid 171758] [client 194.233.65.249:45286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4ki0EhLvMuMRNpl038KQAAAWo"]
[Mon Jul 20 07:37:15.852598 2026] [security2:error] [pid 171532:tid 171766] [client 143.44.185.218:63038] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ki0EhLvMuMRNpl038MwAAAXI"]
[Mon Jul 20 07:37:15.852736 2026] [security2:error] [pid 171532:tid 171766] [client 143.44.185.218:63038] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ki0EhLvMuMRNpl038MwAAAXI"]
[Mon Jul 20 07:37:16.020738 2026] [security2:error] [pid 171532:tid 171731] [client 140.245.46.64:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-includes/post.php"] [unique_id "al4kjEEhLvMuMRNpl038QQAAAU8"]
[Mon Jul 20 07:37:16.210546 2026] [security2:error] [pid 171532:tid 171737] [client 103.106.165.44:57755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kjEEhLvMuMRNpl038TAAAAVU"]
[Mon Jul 20 07:37:16.210644 2026] [security2:error] [pid 171532:tid 171737] [client 103.106.165.44:57755] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kjEEhLvMuMRNpl038TAAAAVU"]
[Mon Jul 20 07:37:16.226980 2026] [security2:error] [pid 171532:tid 171756] [client 57.141.18.111:32682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kikEhLvMuMRNpl037zQABaH0"]
[Mon Jul 20 07:37:16.231969 2026] [security2:error] [pid 171532:tid 171702] [client 57.141.18.66:60310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kikEhLvMuMRNpl037zgABMmI"]
[Mon Jul 20 07:37:16.593652 2026] [security2:error] [pid 171532:tid 171705] [client 140.245.46.64:62045] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-includes/user.php"] [unique_id "al4kjEEhLvMuMRNpl038awAAATU"]
[Mon Jul 20 07:37:17.174515 2026] [security2:error] [pid 164535:tid 164753] [client 57.141.18.39:51685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kijYN371eKRzcKeR79wAA3U4"]
[Mon Jul 20 07:37:17.273060 2026] [security2:error] [pid 171532:tid 171613] [remote 72.167.132.114:45810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kjUEhLvMuMRNpl038hwABMlA"]
[Mon Jul 20 07:37:17.472193 2026] [security2:error] [pid 164535:tid 164720] [client 57.141.18.1:59128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kizYN371eKRzcKeR7_gAAvB0"]
[Mon Jul 20 07:37:17.501847 2026] [security2:error] [pid 171532:tid 171589] [remote 72.167.132.114:45810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kjUEhLvMuMRNpl038mAABRTg"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:37:17.593952 2026] [security2:error] [pid 164535:tid 164700] [client 57.141.18.8:60006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kizYN371eKRzcKeR8AAAAqCA"]
[Mon Jul 20 07:37:17.923533 2026] [security2:error] [pid 164535:tid 164775] [client 4.204.201.85:58770] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4kjTYN371eKRzcKeR8OAAAAPM"]
[Mon Jul 20 07:37:17.923641 2026] [security2:error] [pid 164535:tid 164775] [client 4.204.201.85:58770] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4kjTYN371eKRzcKeR8OAAAAPM"]
[Mon Jul 20 07:37:18.000120 2026] [security2:error] [pid 171532:tid 171647] [remote 156.67.31.167:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4kjUEhLvMuMRNpl038tgABgXI"]
[Mon Jul 20 07:37:18.043221 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:58791] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4kjkEhLvMuMRNpl038uAAAAV4"]
[Mon Jul 20 07:37:18.043341 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:58791] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4kjkEhLvMuMRNpl038uAAAAV4"]
[Mon Jul 20 07:37:18.169429 2026] [security2:error] [pid 171532:tid 171730] [client 4.204.201.85:58759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/x.php"] [unique_id "al4kjkEhLvMuMRNpl038wQAAAU4"]
[Mon Jul 20 07:37:18.169530 2026] [security2:error] [pid 171532:tid 171730] [client 4.204.201.85:58759] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/x.php"] [unique_id "al4kjkEhLvMuMRNpl038wQAAAU4"]
[Mon Jul 20 07:37:18.187743 2026] [security2:error] [pid 171532:tid 171607] [remote 156.67.31.167:53682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.31.67.156.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "healthylifegourmet.org"] [uri "/wp-login.php"] [unique_id "al4kjkEhLvMuMRNpl038wgABH0o"], referer: https://healthylifegourmet.org/wp-login.php
[Mon Jul 20 07:37:18.257359 2026] [security2:error] [pid 171532:tid 171695] [client 46.110.96.34:46183] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kjkEhLvMuMRNpl038yQAAASs"]
[Mon Jul 20 07:37:18.302539 2026] [security2:error] [pid 164535:tid 164734] [client 4.204.201.85:58787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/mgrr.php"] [unique_id "al4kjjYN371eKRzcKeR8PAAAAMo"]
[Mon Jul 20 07:37:18.302633 2026] [security2:error] [pid 164535:tid 164734] [client 4.204.201.85:58787] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/mgrr.php"] [unique_id "al4kjjYN371eKRzcKeR8PAAAAMo"]
[Mon Jul 20 07:37:18.329657 2026] [security2:error] [pid 171532:tid 171696] [client 14.225.17.146:58327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4kjkEhLvMuMRNpl038vAAAASw"], referer: http://jvcmotorsports.com/bc
[Mon Jul 20 07:37:18.437397 2026] [security2:error] [pid 171532:tid 171743] [client 4.204.201.85:58776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/stdin.php"] [unique_id "al4kjkEhLvMuMRNpl0382QAAAVs"]
[Mon Jul 20 07:37:18.437493 2026] [security2:error] [pid 171532:tid 171743] [client 4.204.201.85:58776] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/stdin.php"] [unique_id "al4kjkEhLvMuMRNpl0382QAAAVs"]
[Mon Jul 20 07:37:18.460899 2026] [security2:error] [pid 171532:tid 171726] [client 13.221.30.43:59348] ModSecurity: Access denied with code 406 (phase 1). String match "User-Agent: " at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "380"] [id "900242"] [msg "Fake UA :: User-Agent at start of UA"] [hostname "curlsnpearlsss.com"] [uri "/"] [unique_id "al4kjkEhLvMuMRNpl0384AAAAUo"]
[Mon Jul 20 07:37:18.532505 2026] [security2:error] [pid 171532:tid 171754] [client 103.176.215.66:62779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl0384wAAAWY"]
[Mon Jul 20 07:37:18.532593 2026] [security2:error] [pid 171532:tid 171754] [client 103.176.215.66:62779] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl0384wAAAWY"]
[Mon Jul 20 07:37:18.539317 2026] [security2:error] [pid 171532:tid 171728] [client 103.139.191.61:56985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl0385AAAAUw"]
[Mon Jul 20 07:37:18.539398 2026] [security2:error] [pid 171532:tid 171728] [client 103.139.191.61:56985] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl0385AAAAUw"]
[Mon Jul 20 07:37:18.568942 2026] [security2:error] [pid 164535:tid 164668] [client 4.204.201.85:58831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/BDKR28.php"] [unique_id "al4kjjYN371eKRzcKeR8TwAAAIg"]
[Mon Jul 20 07:37:18.569037 2026] [security2:error] [pid 164535:tid 164668] [client 4.204.201.85:58831] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/BDKR28.php"] [unique_id "al4kjjYN371eKRzcKeR8TwAAAIg"]
[Mon Jul 20 07:37:18.586312 2026] [security2:error] [pid 164535:tid 164701] [client 46.110.96.34:30346] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kjjYN371eKRzcKeR8UgAAAKk"]
[Mon Jul 20 07:37:18.646628 2026] [security2:error] [pid 171532:tid 171708] [client 52.207.32.99:13544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kjkEhLvMuMRNpl0385gAAATg"]
[Mon Jul 20 07:37:18.721560 2026] [security2:error] [pid 171532:tid 171697] [client 136.158.60.21:62898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl0387QAAAS0"]
[Mon Jul 20 07:37:18.721702 2026] [security2:error] [pid 171532:tid 171697] [client 136.158.60.21:62898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl0387QAAAS0"]
[Mon Jul 20 07:37:18.726716 2026] [security2:error] [pid 171532:tid 171700] [client 4.204.201.85:58756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/001.php"] [unique_id "al4kjkEhLvMuMRNpl0388QAAATA"]
[Mon Jul 20 07:37:18.726840 2026] [security2:error] [pid 171532:tid 171700] [client 4.204.201.85:58756] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/001.php"] [unique_id "al4kjkEhLvMuMRNpl0388QAAATA"]
[Mon Jul 20 07:37:18.850330 2026] [security2:error] [pid 171532:tid 171716] [client 4.204.201.85:58771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/dZ3wP5.php"] [unique_id "al4kjkEhLvMuMRNpl038-AAAAUA"]
[Mon Jul 20 07:37:18.850410 2026] [security2:error] [pid 171532:tid 171716] [client 4.204.201.85:58771] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/dZ3wP5.php"] [unique_id "al4kjkEhLvMuMRNpl038-AAAAUA"]
[Mon Jul 20 07:37:18.896655 2026] [security2:error] [pid 171532:tid 171747] [client 191.202.66.27:54514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl038_AAAAV8"]
[Mon Jul 20 07:37:18.896793 2026] [security2:error] [pid 171532:tid 171747] [client 191.202.66.27:54514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl038_AAAAV8"]
[Mon Jul 20 07:37:18.979795 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:58849] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/yup.php"] [unique_id "al4kjkEhLvMuMRNpl039AwAAATY"]
[Mon Jul 20 07:37:18.979939 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:58849] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/yup.php"] [unique_id "al4kjkEhLvMuMRNpl039AwAAATY"]
[Mon Jul 20 07:37:19.014539 2026] [security2:error] [pid 171532:tid 171760] [client 154.192.233.184:60864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl039BAAAAWw"]
[Mon Jul 20 07:37:19.014713 2026] [security2:error] [pid 171532:tid 171760] [client 154.192.233.184:60864] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kjkEhLvMuMRNpl039BAAAAWw"]
[Mon Jul 20 07:37:19.020183 2026] [security2:error] [pid 171532:tid 171765] [client 54.81.157.232:34956] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.157.81.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kjkEhLvMuMRNpl039AgAAAXE"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:37:19.109630 2026] [security2:error] [pid 171532:tid 171728] [client 4.204.201.85:58758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/X.php"] [unique_id "al4kj0EhLvMuMRNpl039EwAAAUw"]
[Mon Jul 20 07:37:19.109727 2026] [security2:error] [pid 171532:tid 171728] [client 4.204.201.85:58758] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/X.php"] [unique_id "al4kj0EhLvMuMRNpl039EwAAAUw"]
[Mon Jul 20 07:37:19.261329 2026] [security2:error] [pid 164535:tid 164680] [client 4.204.201.85:58837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/1polka.php"] [unique_id "al4kjzYN371eKRzcKeR8YgAAAJQ"]
[Mon Jul 20 07:37:19.261423 2026] [security2:error] [pid 164535:tid 164680] [client 4.204.201.85:58837] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/1polka.php"] [unique_id "al4kjzYN371eKRzcKeR8YgAAAJQ"]
[Mon Jul 20 07:37:19.373595 2026] [security2:error] [pid 171532:tid 171696] [client 14.225.17.146:57895] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4kj0EhLvMuMRNpl039FwAAASw"], referer: http://slutilities.com/bc
[Mon Jul 20 07:37:19.386310 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:58826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/gec.php"] [unique_id "al4kjzYN371eKRzcKeR8aQAAAOA"]
[Mon Jul 20 07:37:19.386402 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:58826] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/gec.php"] [unique_id "al4kjzYN371eKRzcKeR8aQAAAOA"]
[Mon Jul 20 07:37:19.441129 2026] [security2:error] [pid 171532:tid 171724] [client 57.141.18.115:37378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kjUEhLvMuMRNpl038jgABSD4"]
[Mon Jul 20 07:37:19.512709 2026] [security2:error] [pid 164535:tid 164730] [client 4.204.201.85:58855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/sky.php"] [unique_id "al4kjzYN371eKRzcKeR8cAAAAMY"]
[Mon Jul 20 07:37:19.512845 2026] [security2:error] [pid 164535:tid 164730] [client 4.204.201.85:58855] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/sky.php"] [unique_id "al4kjzYN371eKRzcKeR8cAAAAMY"]
[Mon Jul 20 07:37:19.641623 2026] [security2:error] [pid 171532:tid 171711] [client 4.204.201.85:58757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/fffm.php"] [unique_id "al4kj0EhLvMuMRNpl039LgAAATs"]
[Mon Jul 20 07:37:19.641706 2026] [security2:error] [pid 171532:tid 171711] [client 4.204.201.85:58757] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/fffm.php"] [unique_id "al4kj0EhLvMuMRNpl039LgAAATs"]
[Mon Jul 20 07:37:19.773247 2026] [security2:error] [pid 164535:tid 164750] [client 4.204.201.85:58772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/sixxis.php"] [unique_id "al4kjzYN371eKRzcKeR8eAAAANo"]
[Mon Jul 20 07:37:19.773334 2026] [security2:error] [pid 164535:tid 164750] [client 4.204.201.85:58772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/sixxis.php"] [unique_id "al4kjzYN371eKRzcKeR8eAAAANo"]
[Mon Jul 20 07:37:19.897142 2026] [security2:error] [pid 171532:tid 171774] [client 4.204.201.85:49615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/yj09.php"] [unique_id "al4kj0EhLvMuMRNpl039SwAAAXk"]
[Mon Jul 20 07:37:19.897242 2026] [security2:error] [pid 171532:tid 171774] [client 4.204.201.85:49615] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/yj09.php"] [unique_id "al4kj0EhLvMuMRNpl039SwAAAXk"]
[Mon Jul 20 07:37:20.024870 2026] [security2:error] [pid 171532:tid 171738] [client 4.204.201.85:58858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/f900.php"] [unique_id "al4kkEEhLvMuMRNpl039UAAAAVY"]
[Mon Jul 20 07:37:20.024952 2026] [security2:error] [pid 171532:tid 171738] [client 4.204.201.85:58858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/f900.php"] [unique_id "al4kkEEhLvMuMRNpl039UAAAAVY"]
[Mon Jul 20 07:37:20.062392 2026] [security2:error] [pid 164535:tid 164672] [client 14.225.17.146:53685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4kjzYN371eKRzcKeR8ewAAAIw"], referer: http://www.justinagrayman.com/bc
[Mon Jul 20 07:37:20.171354 2026] [security2:error] [pid 164535:tid 164681] [client 4.204.201.85:58769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ups.php"] [unique_id "al4kkDYN371eKRzcKeR8gQAAAJU"]
[Mon Jul 20 07:37:20.171448 2026] [security2:error] [pid 164535:tid 164681] [client 4.204.201.85:58769] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ups.php"] [unique_id "al4kkDYN371eKRzcKeR8gQAAAJU"]
[Mon Jul 20 07:37:20.250951 2026] [security2:error] [pid 164535:tid 164670] [client 179.127.84.238:58177] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kkDYN371eKRzcKeR8hQAAAIo"]
[Mon Jul 20 07:37:20.251439 2026] [security2:error] [pid 164535:tid 164670] [client 179.127.84.238:58177] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kkDYN371eKRzcKeR8hQAAAIo"]
[Mon Jul 20 07:37:20.305195 2026] [security2:error] [pid 171532:tid 171715] [client 4.204.201.85:58860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/k.php"] [unique_id "al4kkEEhLvMuMRNpl039XwAAAT8"]
[Mon Jul 20 07:37:20.305299 2026] [security2:error] [pid 171532:tid 171715] [client 4.204.201.85:58860] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/k.php"] [unique_id "al4kkEEhLvMuMRNpl039XwAAAT8"]
[Mon Jul 20 07:37:20.446735 2026] [security2:error] [pid 171532:tid 171737] [client 4.204.201.85:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/k2.php"] [unique_id "al4kkEEhLvMuMRNpl039aQAAAVU"]
[Mon Jul 20 07:37:20.446816 2026] [security2:error] [pid 171532:tid 171737] [client 4.204.201.85:58841] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/k2.php"] [unique_id "al4kkEEhLvMuMRNpl039aQAAAVU"]
[Mon Jul 20 07:37:20.580574 2026] [security2:error] [pid 171532:tid 171762] [client 4.204.201.85:58867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/w.php"] [unique_id "al4kkEEhLvMuMRNpl039cQAAAW4"]
[Mon Jul 20 07:37:20.580677 2026] [security2:error] [pid 171532:tid 171762] [client 4.204.201.85:58867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/w.php"] [unique_id "al4kkEEhLvMuMRNpl039cQAAAW4"]
[Mon Jul 20 07:37:20.677391 2026] [security2:error] [pid 171532:tid 171776] [client 57.141.18.63:36290] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kjkEhLvMuMRNpl0383gABewY"]
[Mon Jul 20 07:37:20.726032 2026] [security2:error] [pid 171532:tid 171664] [client 4.204.201.85:58822] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/fpwch.php"] [unique_id "al4kkEEhLvMuMRNpl039eQAAAQw"]
[Mon Jul 20 07:37:20.726163 2026] [security2:error] [pid 171532:tid 171664] [client 4.204.201.85:58822] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/fpwch.php"] [unique_id "al4kkEEhLvMuMRNpl039eQAAAQw"]
[Mon Jul 20 07:37:20.746559 2026] [security2:error] [pid 171532:tid 171554] [remote 192.241.143.148:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kkEEhLvMuMRNpl039ewABVhU"]
[Mon Jul 20 07:37:20.852775 2026] [security2:error] [pid 171532:tid 171704] [client 4.204.201.85:58774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/w2025.php"] [unique_id "al4kkEEhLvMuMRNpl039hgAAATQ"]
[Mon Jul 20 07:37:20.852881 2026] [security2:error] [pid 171532:tid 171704] [client 4.204.201.85:58774] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/w2025.php"] [unique_id "al4kkEEhLvMuMRNpl039hgAAATQ"]
[Mon Jul 20 07:37:20.903382 2026] [security2:error] [pid 171532:tid 171726] [client 50.116.65.227:52836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kkEEhLvMuMRNpl039jgAAAUo"]
[Mon Jul 20 07:37:20.914200 2026] [security2:error] [pid 171532:tid 171729] [client 50.116.65.227:52844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kkEEhLvMuMRNpl039kgAAAU0"]
[Mon Jul 20 07:37:20.929668 2026] [security2:error] [pid 171532:tid 171600] [remote 192.241.143.148:45576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kkEEhLvMuMRNpl039kwABWEM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:37:20.939787 2026] [security2:error] [pid 164535:tid 164684] [client 57.141.18.80:27018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kjjYN371eKRzcKeR8VwAAmAs"]
[Mon Jul 20 07:37:20.967915 2026] [security2:error] [pid 171532:tid 171706] [client 14.225.17.146:53662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4kkEEhLvMuMRNpl039dgAAATY"], referer: http://webgardensbypaula.com/bc
[Mon Jul 20 07:37:20.975580 2026] [security2:error] [pid 171532:tid 171786] [client 4.204.201.85:58783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/FWAZ.php"] [unique_id "al4kkEEhLvMuMRNpl039mgAAAYU"]
[Mon Jul 20 07:37:20.975675 2026] [security2:error] [pid 171532:tid 171786] [client 4.204.201.85:58783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/FWAZ.php"] [unique_id "al4kkEEhLvMuMRNpl039mgAAAYU"]
[Mon Jul 20 07:37:21.038090 2026] [security2:error] [pid 171532:tid 171734] [client 57.141.18.39:51707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kjkEhLvMuMRNpl0389AABUiA"]
[Mon Jul 20 07:37:21.095595 2026] [security2:error] [pid 164535:tid 164709] [client 4.204.201.85:58814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/qterm.php"] [unique_id "al4kkTYN371eKRzcKeR8kgAAALE"]
[Mon Jul 20 07:37:21.095762 2026] [security2:error] [pid 164535:tid 164709] [client 4.204.201.85:58814] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/qterm.php"] [unique_id "al4kkTYN371eKRzcKeR8kgAAALE"]
[Mon Jul 20 07:37:21.209327 2026] [security2:error] [pid 171532:tid 171767] [client 50.116.65.227:52868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kkUEhLvMuMRNpl039rgAAAXM"]
[Mon Jul 20 07:37:21.219469 2026] [security2:error] [pid 171532:tid 171787] [client 50.116.65.227:52872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kkUEhLvMuMRNpl039rwAAAYY"]
[Mon Jul 20 07:37:21.230993 2026] [security2:error] [pid 171532:tid 171777] [client 4.204.201.85:58783] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/blurbs.php"] [unique_id "al4kkUEhLvMuMRNpl039sAAAAXw"]
[Mon Jul 20 07:37:21.231081 2026] [security2:error] [pid 171532:tid 171777] [client 4.204.201.85:58783] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/blurbs.php"] [unique_id "al4kkUEhLvMuMRNpl039sAAAAXw"]
[Mon Jul 20 07:37:21.326934 2026] [security2:error] [pid 171532:tid 171759] [client 57.141.18.73:36868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kj0EhLvMuMRNpl039DgABa2o"]
[Mon Jul 20 07:37:21.432712 2026] [security2:error] [pid 171532:tid 171754] [client 50.116.65.227:52884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4kkUEhLvMuMRNpl039swAAAWY"]
[Mon Jul 20 07:37:21.552949 2026] [security2:error] [pid 164535:tid 164751] [client 4.204.201.85:58845] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/v543.php"] [unique_id "al4kkTYN371eKRzcKeR8mwAAANs"]
[Mon Jul 20 07:37:21.553104 2026] [security2:error] [pid 164535:tid 164751] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/v543.php"] [unique_id "al4kkTYN371eKRzcKeR8mwAAANs"]
[Mon Jul 20 07:37:21.606631 2026] [security2:error] [pid 171532:tid 171730] [client 50.116.65.227:52910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4kkUEhLvMuMRNpl039wwAAAU4"]
[Mon Jul 20 07:37:21.682510 2026] [security2:error] [pid 171532:tid 171765] [client 4.204.201.85:58796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/w3lls.php"] [unique_id "al4kkUEhLvMuMRNpl0390AAAAXE"]
[Mon Jul 20 07:37:21.682587 2026] [security2:error] [pid 171532:tid 171765] [client 4.204.201.85:58796] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/w3lls.php"] [unique_id "al4kkUEhLvMuMRNpl0390AAAAXE"]
[Mon Jul 20 07:37:21.811815 2026] [security2:error] [pid 171532:tid 171790] [client 4.204.201.85:58862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-ws68.php"] [unique_id "al4kkUEhLvMuMRNpl0392AAAAYk"]
[Mon Jul 20 07:37:21.811933 2026] [security2:error] [pid 171532:tid 171790] [client 4.204.201.85:58862] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-ws68.php"] [unique_id "al4kkUEhLvMuMRNpl0392AAAAYk"]
[Mon Jul 20 07:37:21.936290 2026] [security2:error] [pid 164535:tid 164711] [client 4.204.201.85:58870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xyn.php"] [unique_id "al4kkTYN371eKRzcKeR8oQAAALM"]
[Mon Jul 20 07:37:21.936373 2026] [security2:error] [pid 164535:tid 164711] [client 4.204.201.85:58870] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xyn.php"] [unique_id "al4kkTYN371eKRzcKeR8oQAAALM"]
[Mon Jul 20 07:37:21.941878 2026] [security2:error] [pid 171532:tid 171755] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kkUEhLvMuMRNpl0390QABZ1o"], referer: http://aleishapenny.ca/bc
[Mon Jul 20 07:37:22.067464 2026] [security2:error] [pid 171532:tid 171685] [client 4.204.201.85:58761] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/green3.php"] [unique_id "al4kkkEhLvMuMRNpl039-AAAASE"]
[Mon Jul 20 07:37:22.067570 2026] [security2:error] [pid 171532:tid 171685] [client 4.204.201.85:58761] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/green3.php"] [unique_id "al4kkkEhLvMuMRNpl039-AAAASE"]
[Mon Jul 20 07:37:22.136838 2026] [security2:error] [pid 164535:tid 164679] [client 57.141.18.7:63850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kjzYN371eKRzcKeR8fgAAk38"]
[Mon Jul 20 07:37:22.187925 2026] [security2:error] [pid 171532:tid 171697] [client 57.141.18.51:32342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kj0EhLvMuMRNpl039TgABLRE"]
[Mon Jul 20 07:37:22.201835 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:58817] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ccc.php"] [unique_id "al4kkkEhLvMuMRNpl03-AQAAAV4"]
[Mon Jul 20 07:37:22.201965 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:58817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ccc.php"] [unique_id "al4kkkEhLvMuMRNpl03-AQAAAV4"]
[Mon Jul 20 07:37:22.243527 2026] [proxy:error] [pid 171532:tid 171668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:37:22.243560 2026] [proxy_http:error] [pid 171532:tid 171668] [client 107.172.180.205:34114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:37:22.244093 2026] [proxy:error] [pid 171532:tid 171668] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:37:22.244115 2026] [proxy_http:error] [pid 171532:tid 171668] [client 107.172.180.205:34114] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:37:22.255216 2026] [security2:error] [pid 171532:tid 171741] [client 113.160.97.242:50931] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4kkkEhLvMuMRNpl03-AwAAAVk"]
[Mon Jul 20 07:37:22.332188 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/get.php"] [unique_id "al4kkkEhLvMuMRNpl03-BgAAAWM"]
[Mon Jul 20 07:37:22.332272 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58859] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/get.php"] [unique_id "al4kkkEhLvMuMRNpl03-BgAAAWM"]
[Mon Jul 20 07:37:22.460306 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:49620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/images.php"] [unique_id "al4kkkEhLvMuMRNpl03-EQAAATY"]
[Mon Jul 20 07:37:22.460412 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:49620] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/images.php"] [unique_id "al4kkkEhLvMuMRNpl03-EQAAATY"]
[Mon Jul 20 07:37:22.590969 2026] [security2:error] [pid 164535:tid 164775] [client 4.204.201.85:58847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/alls.php"] [unique_id "al4kkjYN371eKRzcKeR8rQAAAPM"]
[Mon Jul 20 07:37:22.591091 2026] [security2:error] [pid 164535:tid 164775] [client 4.204.201.85:58847] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/alls.php"] [unique_id "al4kkjYN371eKRzcKeR8rQAAAPM"]
[Mon Jul 20 07:37:22.616657 2026] [security2:error] [pid 171532:tid 171738] [client 65.111.22.170:47847] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 170.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kkkEhLvMuMRNpl03-FwAAAVY"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:22.728645 2026] [security2:error] [pid 171532:tid 171782] [client 4.204.201.85:58792] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/coffexium.php"] [unique_id "al4kkkEhLvMuMRNpl03-HgAAAYE"]
[Mon Jul 20 07:37:22.728785 2026] [security2:error] [pid 171532:tid 171782] [client 4.204.201.85:58792] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/coffexium.php"] [unique_id "al4kkkEhLvMuMRNpl03-HgAAAYE"]
[Mon Jul 20 07:37:22.858221 2026] [security2:error] [pid 171532:tid 171677] [client 4.204.201.85:58760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/red.php"] [unique_id "al4kkkEhLvMuMRNpl03-LgAAARk"]
[Mon Jul 20 07:37:22.858322 2026] [security2:error] [pid 171532:tid 171677] [client 4.204.201.85:58760] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/red.php"] [unique_id "al4kkkEhLvMuMRNpl03-LgAAARk"]
[Mon Jul 20 07:37:22.878966 2026] [security2:error] [pid 171532:tid 171690] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4kkkEhLvMuMRNpl03-JQABJgI"], referer: https://aleishapenny.ca/bc
[Mon Jul 20 07:37:22.926607 2026] [security2:error] [pid 171532:tid 171719] [client 180.249.173.210:55256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kkkEhLvMuMRNpl03-MgAAAUM"]
[Mon Jul 20 07:37:22.926955 2026] [security2:error] [pid 171532:tid 171719] [client 180.249.173.210:55256] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kkkEhLvMuMRNpl03-MgAAAUM"]
[Mon Jul 20 07:37:22.987204 2026] [security2:error] [pid 164535:tid 164734] [client 4.204.201.85:58843] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4kkjYN371eKRzcKeR8uQAAAMo"]
[Mon Jul 20 07:37:23.195116 2026] [access_compat:error] [pid 164535:tid 164678] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/sodium_compat/index.php
[Mon Jul 20 07:37:23.195634 2026] [security2:error] [pid 164535:tid 164678] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/cgi-sys/403.html"] [unique_id "al4kkzYN371eKRzcKeR8vgAAAJI"]
[Mon Jul 20 07:37:23.196420 2026] [security2:error] [pid 164535:tid 164687] [client 14.225.17.146:53727] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4kkzYN371eKRzcKeR8vAAAAJs"]
[Mon Jul 20 07:37:23.229077 2026] [security2:error] [pid 171532:tid 171784] [client 14.225.17.146:64514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4kk0EhLvMuMRNpl03-PAAAAYM"], referer: http://samdothan.org/bc
[Mon Jul 20 07:37:23.259510 2026] [security2:error] [pid 164535:tid 164712] [client 4.204.201.85:58843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4kkzYN371eKRzcKeR8wAAAALQ"]
[Mon Jul 20 07:37:23.259638 2026] [security2:error] [pid 164535:tid 164712] [client 4.204.201.85:58843] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4kkzYN371eKRzcKeR8wAAAALQ"]
[Mon Jul 20 07:37:23.292191 2026] [security2:error] [pid 171532:tid 171726] [client 74.208.214.194:41988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4kk0EhLvMuMRNpl03-RQAAAUo"]
[Mon Jul 20 07:37:23.404858 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:58864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/Text/"] [unique_id "al4kk0EhLvMuMRNpl03-TAAAAVI"]
[Mon Jul 20 07:37:23.449035 2026] [security2:error] [pid 164535:tid 164611] [remote 100.42.189.89:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kkzYN371eKRzcKeR8ywAAjEs"]
[Mon Jul 20 07:37:23.469559 2026] [access_compat:error] [pid 164535:tid 164777] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/Text/index.php
[Mon Jul 20 07:37:23.470285 2026] [security2:error] [pid 164535:tid 164777] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/Text/"] [unique_id "al4kkzYN371eKRzcKeR8zQAAAPU"]
[Mon Jul 20 07:37:23.493004 2026] [security2:error] [pid 171532:tid 171683] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4kkkEhLvMuMRNpl03-NQABHzY"], referer: http://assasalnazaha.com/bc
[Mon Jul 20 07:37:23.534202 2026] [security2:error] [pid 171532:tid 171728] [client 4.204.201.85:58864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/uploads/"] [unique_id "al4kk0EhLvMuMRNpl03-WgAAAUw"]
[Mon Jul 20 07:37:23.537604 2026] [security2:error] [pid 171532:tid 171674] [client 50.116.65.227:52936] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tntcatholic.com"] [uri "/wp-content/uploads/2021/10/Addams-Family-2-vacay.jpg"] [unique_id "al4kk0EhLvMuMRNpl03-WQAAAVc"]
[Mon Jul 20 07:37:23.605991 2026] [access_compat:error] [pid 164535:tid 164709] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-content/uploads/index.php
[Mon Jul 20 07:37:23.607162 2026] [security2:error] [pid 164535:tid 164709] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/uploads/"] [unique_id "al4kkzYN371eKRzcKeR80gAAALE"]
[Mon Jul 20 07:37:23.664302 2026] [security2:error] [pid 164535:tid 164589] [remote 100.42.189.89:36440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4kkzYN371eKRzcKeR80wAA_DU"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:37:23.669360 2026] [security2:error] [pid 171532:tid 171669] [client 49.47.218.174:58728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kk0EhLvMuMRNpl03-XwAAARE"]
[Mon Jul 20 07:37:23.669470 2026] [security2:error] [pid 171532:tid 171669] [client 49.47.218.174:58728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kk0EhLvMuMRNpl03-XwAAARE"]
[Mon Jul 20 07:37:23.672535 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/index.php"] [unique_id "al4kk0EhLvMuMRNpl03-YAAAAWM"]
[Mon Jul 20 07:37:23.672608 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/index.php"] [unique_id "al4kk0EhLvMuMRNpl03-YAAAAWM"]
[Mon Jul 20 07:37:23.800573 2026] [security2:error] [pid 171532:tid 171735] [client 4.204.201.85:58793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/admin.php"] [unique_id "al4kk0EhLvMuMRNpl03-ZQAAAVM"]
[Mon Jul 20 07:37:23.800701 2026] [security2:error] [pid 171532:tid 171735] [client 4.204.201.85:58793] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/admin.php"] [unique_id "al4kk0EhLvMuMRNpl03-ZQAAAVM"]
[Mon Jul 20 07:37:23.924799 2026] [security2:error] [pid 164535:tid 164719] [client 4.204.201.85:58863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/177.php"] [unique_id "al4kkzYN371eKRzcKeR82AAAALs"]
[Mon Jul 20 07:37:23.924879 2026] [security2:error] [pid 164535:tid 164719] [client 4.204.201.85:58863] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/177.php"] [unique_id "al4kkzYN371eKRzcKeR82AAAALs"]
[Mon Jul 20 07:37:24.035898 2026] [security2:error] [pid 171532:tid 171790] [client 45.3.54.179:38223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 179.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4klEEhLvMuMRNpl03-eQAAAYk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:24.051519 2026] [security2:error] [pid 164535:tid 164769] [client 4.204.201.85:58789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/199.php"] [unique_id "al4klDYN371eKRzcKeR83AAAAO0"]
[Mon Jul 20 07:37:24.051620 2026] [security2:error] [pid 164535:tid 164769] [client 4.204.201.85:58789] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/199.php"] [unique_id "al4klDYN371eKRzcKeR83AAAAO0"]
[Mon Jul 20 07:37:24.085012 2026] [security2:error] [pid 171532:tid 171672] [client 98.159.234.160:63723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4klEEhLvMuMRNpl03-gAAAARQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:37:24.142076 2026] [security2:error] [pid 164535:tid 164728] [client 47.128.52.163:46352] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "californiaperfumecompany.com"] [uri "/robots.txt"] [unique_id "al4klDYN371eKRzcKeR83wAAAMQ"]
[Mon Jul 20 07:37:24.181072 2026] [security2:error] [pid 171532:tid 171717] [client 4.204.201.85:49644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file52.php"] [unique_id "al4klEEhLvMuMRNpl03-hQAAAUE"]
[Mon Jul 20 07:37:24.181168 2026] [security2:error] [pid 171532:tid 171717] [client 4.204.201.85:49644] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file52.php"] [unique_id "al4klEEhLvMuMRNpl03-hQAAAUE"]
[Mon Jul 20 07:37:24.273087 2026] [lsapi:warn] [pid 164535:tid 164747] [client 14.225.17.146:64711] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/bc
[Mon Jul 20 07:37:24.273109 2026] [lsapi:warn] [pid 164535:tid 164747] [client 14.225.17.146:64711] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/bc
[Mon Jul 20 07:37:24.303700 2026] [security2:error] [pid 171532:tid 171771] [client 4.204.201.85:58767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/geck.php"] [unique_id "al4klEEhLvMuMRNpl03-iQAAAXc"]
[Mon Jul 20 07:37:24.303810 2026] [security2:error] [pid 171532:tid 171771] [client 4.204.201.85:58767] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/geck.php"] [unique_id "al4klEEhLvMuMRNpl03-iQAAAXc"]
[Mon Jul 20 07:37:24.351986 2026] [lsapi:warn] [pid 164535:tid 164671] [client 50.116.65.227:52956] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:37:24.352004 2026] [lsapi:warn] [pid 164535:tid 164671] [client 50.116.65.227:52956] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:37:24.366049 2026] [security2:error] [pid 164535:tid 164747] [client 14.225.17.146:64711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4klDYN371eKRzcKeR84AAAANc"], referer: http://oswegooperatheater.com/bc
[Mon Jul 20 07:37:24.373009 2026] [security2:error] [pid 171532:tid 171784] [client 157.20.138.62:60995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4klEEhLvMuMRNpl03-jgAAAYM"]
[Mon Jul 20 07:37:24.373129 2026] [security2:error] [pid 171532:tid 171784] [client 157.20.138.62:60995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4klEEhLvMuMRNpl03-jgAAAYM"]
[Mon Jul 20 07:37:24.429708 2026] [security2:error] [pid 171532:tid 171735] [client 4.204.201.85:58827] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/biufile.php"] [unique_id "al4klEEhLvMuMRNpl03-kgAAAVM"]
[Mon Jul 20 07:37:24.429820 2026] [security2:error] [pid 171532:tid 171735] [client 4.204.201.85:58827] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/biufile.php"] [unique_id "al4klEEhLvMuMRNpl03-kgAAAVM"]
[Mon Jul 20 07:37:24.447101 2026] [security2:error] [pid 171532:tid 171673] [client 57.141.18.109:58492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kkkEhLvMuMRNpl0398AABFVA"]
[Mon Jul 20 07:37:24.559353 2026] [security2:error] [pid 164535:tid 164734] [client 4.204.201.85:49610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/mosty.php"] [unique_id "al4klDYN371eKRzcKeR87AAAAMo"]
[Mon Jul 20 07:37:24.559431 2026] [security2:error] [pid 164535:tid 164734] [client 4.204.201.85:49610] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/mosty.php"] [unique_id "al4klDYN371eKRzcKeR87AAAAMo"]
[Mon Jul 20 07:37:24.699498 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/dejavu.php"] [unique_id "al4klEEhLvMuMRNpl03-nwAAAUY"]
[Mon Jul 20 07:37:24.699588 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:49641] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/dejavu.php"] [unique_id "al4klEEhLvMuMRNpl03-nwAAAUY"]
[Mon Jul 20 07:37:24.830167 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:58872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/aaf.php"] [unique_id "al4klEEhLvMuMRNpl03-pgAAAV4"]
[Mon Jul 20 07:37:24.830261 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:58872] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/aaf.php"] [unique_id "al4klEEhLvMuMRNpl03-pgAAAV4"]
[Mon Jul 20 07:37:24.975667 2026] [proxy:error] [pid 171532:tid 171745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:37:24.975777 2026] [proxy_http:error] [pid 171532:tid 171745] [client 87.236.176.173:50929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:37:24.977191 2026] [proxy:error] [pid 171532:tid 171745] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:37:24.977262 2026] [proxy_http:error] [pid 171532:tid 171745] [client 87.236.176.173:50929] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:37:24.984968 2026] [security2:error] [pid 164535:tid 164789] [client 4.204.201.85:58807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ha.php"] [unique_id "al4klDYN371eKRzcKeR89wAAAQE"]
[Mon Jul 20 07:37:24.985094 2026] [security2:error] [pid 164535:tid 164789] [client 4.204.201.85:58807] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ha.php"] [unique_id "al4klDYN371eKRzcKeR89wAAAQE"]
[Mon Jul 20 07:37:24.993975 2026] [security2:error] [pid 171532:tid 171749] [client 57.141.18.15:20624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kkkEhLvMuMRNpl03-DgABYS8"]
[Mon Jul 20 07:37:25.121918 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:58856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/hur.php"] [unique_id "al4klTYN371eKRzcKeR9AQAAAN0"]
[Mon Jul 20 07:37:25.122001 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:58856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/hur.php"] [unique_id "al4klTYN371eKRzcKeR9AQAAAN0"]
[Mon Jul 20 07:37:25.174455 2026] [security2:error] [pid 171532:tid 171721] [client 155.2.215.89:55175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-tgAAAUU"]
[Mon Jul 20 07:37:25.213214 2026] [security2:error] [pid 164535:tid 164746] [client 149.0.16.108:64235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4klTYN371eKRzcKeR9BAAAANY"]
[Mon Jul 20 07:37:25.213299 2026] [security2:error] [pid 164535:tid 164746] [client 149.0.16.108:64235] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4klTYN371eKRzcKeR9BAAAANY"]
[Mon Jul 20 07:37:25.219594 2026] [security2:error] [pid 171532:tid 171748] [client 116.193.128.26:51933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-vAAAAWA"]
[Mon Jul 20 07:37:25.219669 2026] [security2:error] [pid 171532:tid 171748] [client 116.193.128.26:51933] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-vAAAAWA"]
[Mon Jul 20 07:37:25.261014 2026] [security2:error] [pid 171532:tid 171682] [client 4.204.201.85:58778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/h02ugyh.php"] [unique_id "al4klUEhLvMuMRNpl03-wAAAAR4"]
[Mon Jul 20 07:37:25.261117 2026] [security2:error] [pid 171532:tid 171682] [client 4.204.201.85:58778] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/h02ugyh.php"] [unique_id "al4klUEhLvMuMRNpl03-wAAAAR4"]
[Mon Jul 20 07:37:25.272266 2026] [lsapi:warn] [pid 164535:tid 164693] [client 14.225.17.146:50310] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/bc
[Mon Jul 20 07:37:25.272282 2026] [lsapi:warn] [pid 164535:tid 164693] [client 14.225.17.146:50310] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/bc
[Mon Jul 20 07:37:25.321447 2026] [security2:error] [pid 164535:tid 164693] [client 14.225.17.146:50310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4klTYN371eKRzcKeR9BwAAAKE"], referer: https://oswegooperatheater.com/bc
[Mon Jul 20 07:37:25.392143 2026] [security2:error] [pid 164535:tid 164714] [client 4.204.201.85:58810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/155.php"] [unique_id "al4klTYN371eKRzcKeR9CgAAALY"]
[Mon Jul 20 07:37:25.392246 2026] [security2:error] [pid 164535:tid 164714] [client 4.204.201.85:58810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/155.php"] [unique_id "al4klTYN371eKRzcKeR9CgAAALY"]
[Mon Jul 20 07:37:25.441199 2026] [security2:error] [pid 171532:tid 171781] [client 104.207.51.85:26679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4klUEhLvMuMRNpl03-ywAAAYA"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:25.539529 2026] [security2:error] [pid 164535:tid 164692] [client 4.204.201.85:58763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/pp.php"] [unique_id "al4klTYN371eKRzcKeR9EgAAAKA"]
[Mon Jul 20 07:37:25.539607 2026] [security2:error] [pid 164535:tid 164692] [client 4.204.201.85:58763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/pp.php"] [unique_id "al4klTYN371eKRzcKeR9EgAAAKA"]
[Mon Jul 20 07:37:25.670451 2026] [security2:error] [pid 171532:tid 171728] [client 4.204.201.85:58848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ops.php"] [unique_id "al4klUEhLvMuMRNpl03-0gAAAUw"]
[Mon Jul 20 07:37:25.670537 2026] [security2:error] [pid 171532:tid 171728] [client 4.204.201.85:58848] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ops.php"] [unique_id "al4klUEhLvMuMRNpl03-0gAAAUw"]
[Mon Jul 20 07:37:25.714605 2026] [security2:error] [pid 171532:tid 171604] [remote 42.200.84.61:41224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4klUEhLvMuMRNpl03-0wABhUc"]
[Mon Jul 20 07:37:25.765826 2026] [security2:error] [pid 171532:tid 171716] [client 36.93.152.155:53212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-2AAAAUA"]
[Mon Jul 20 07:37:25.765933 2026] [security2:error] [pid 171532:tid 171716] [client 36.93.152.155:53212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-2AAAAUA"]
[Mon Jul 20 07:37:25.820019 2026] [security2:error] [pid 171532:tid 171758] [client 4.204.201.85:49652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ingfo.php"] [unique_id "al4klUEhLvMuMRNpl03-3wAAAWo"]
[Mon Jul 20 07:37:25.820128 2026] [security2:error] [pid 171532:tid 171758] [client 4.204.201.85:49652] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ingfo.php"] [unique_id "al4klUEhLvMuMRNpl03-3wAAAWo"]
[Mon Jul 20 07:37:25.946573 2026] [security2:error] [pid 171532:tid 171789] [client 154.192.123.127:17635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-5AAAAYg"]
[Mon Jul 20 07:37:25.946660 2026] [security2:error] [pid 171532:tid 171789] [client 154.192.123.127:17635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4klUEhLvMuMRNpl03-5AAAAYg"]
[Mon Jul 20 07:37:25.956139 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/error_log.php"] [unique_id "al4klUEhLvMuMRNpl03-5QAAAWw"]
[Mon Jul 20 07:37:25.956259 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58753] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/error_log.php"] [unique_id "al4klUEhLvMuMRNpl03-5QAAAWw"]
[Mon Jul 20 07:37:26.001499 2026] [proxy:error] [pid 171532:tid 171735] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:37:26.001570 2026] [proxy_http:error] [pid 171532:tid 171735] [client 107.172.180.205:34134] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:37:26.002021 2026] [proxy:error] [pid 171532:tid 171735] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:37:26.002047 2026] [proxy_http:error] [pid 171532:tid 171735] [client 107.172.180.205:34134] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:37:26.073453 2026] [security2:error] [pid 171532:tid 171625] [remote 42.200.84.61:41224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.factsandminds.com"] [uri "/wp-login.php"] [unique_id "al4klkEhLvMuMRNpl03-8QABFlw"], referer: https://mail.factsandminds.com/wp-login.php
[Mon Jul 20 07:37:26.082318 2026] [security2:error] [pid 164535:tid 164738] [client 4.204.201.85:49609] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/test10.php"] [unique_id "al4kljYN371eKRzcKeR9JQAAAM4"]
[Mon Jul 20 07:37:26.082418 2026] [security2:error] [pid 164535:tid 164738] [client 4.204.201.85:49609] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/test10.php"] [unique_id "al4kljYN371eKRzcKeR9JQAAAM4"]
[Mon Jul 20 07:37:26.210151 2026] [security2:error] [pid 171532:tid 171707] [client 4.204.201.85:49601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/koala.php"] [unique_id "al4klkEhLvMuMRNpl03-9wAAATc"]
[Mon Jul 20 07:37:26.210224 2026] [security2:error] [pid 171532:tid 171707] [client 4.204.201.85:49601] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/koala.php"] [unique_id "al4klkEhLvMuMRNpl03-9wAAATc"]
[Mon Jul 20 07:37:26.341160 2026] [security2:error] [pid 171532:tid 171698] [client 4.204.201.85:58763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/mac.php"] [unique_id "al4klkEhLvMuMRNpl03-_gAAAS4"]
[Mon Jul 20 07:37:26.341264 2026] [security2:error] [pid 171532:tid 171698] [client 4.204.201.85:58763] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/mac.php"] [unique_id "al4klkEhLvMuMRNpl03-_gAAAS4"]
[Mon Jul 20 07:37:26.406576 2026] [security2:error] [pid 171532:tid 171755] [client 140.245.46.64:50353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.46.245.140.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.gyr.tht.mybluehost.me"] [uri "/wp-content/plugins/hello.php"] [unique_id "al4klkEhLvMuMRNpl03_BQAAAWc"]
[Mon Jul 20 07:37:26.415820 2026] [security2:error] [pid 171532:tid 171764] [client 46.110.96.34:32298] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4klkEhLvMuMRNpl03_BwAAAXA"]
[Mon Jul 20 07:37:26.491230 2026] [security2:error] [pid 164535:tid 164683] [client 14.225.17.146:64606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4kljYN371eKRzcKeR9LwAAAJc"], referer: http://scott-assist.com/bc
[Mon Jul 20 07:37:26.496134 2026] [security2:error] [pid 171532:tid 171726] [client 57.141.18.12:38680] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kk0EhLvMuMRNpl03-cAABSkQ"]
[Mon Jul 20 07:37:26.503070 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:49640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wefile.php"] [unique_id "al4kljYN371eKRzcKeR9MwAAAN0"]
[Mon Jul 20 07:37:26.503153 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:49640] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wefile.php"] [unique_id "al4kljYN371eKRzcKeR9MwAAAN0"]
[Mon Jul 20 07:37:26.630492 2026] [security2:error] [pid 164535:tid 164786] [client 4.204.201.85:58820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4kljYN371eKRzcKeR9OAAAAP4"]
[Mon Jul 20 07:37:26.643179 2026] [security2:error] [pid 164535:tid 164690] [client 103.106.165.44:58242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kljYN371eKRzcKeR9OQAAAJ4"]
[Mon Jul 20 07:37:26.643278 2026] [security2:error] [pid 164535:tid 164690] [client 103.106.165.44:58242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kljYN371eKRzcKeR9OQAAAJ4"]
[Mon Jul 20 07:37:26.667119 2026] [security2:error] [pid 171532:tid 171732] [client 46.110.96.34:21292] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4klkEhLvMuMRNpl03_FgAAAVA"]
[Mon Jul 20 07:37:26.695792 2026] [access_compat:error] [pid 164535:tid 164670] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/blocks/post-comments-form/index.php
[Mon Jul 20 07:37:26.696248 2026] [security2:error] [pid 164535:tid 164670] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4kljYN371eKRzcKeR9OwAAAIo"]
[Mon Jul 20 07:37:26.735737 2026] [security2:error] [pid 171532:tid 171739] [client 57.141.18.85:53240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4klEEhLvMuMRNpl03-hwABVxY"]
[Mon Jul 20 07:37:26.767840 2026] [security2:error] [pid 164535:tid 164776] [client 4.204.201.85:58820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/js/"] [unique_id "al4kljYN371eKRzcKeR9PgAAAPQ"]
[Mon Jul 20 07:37:26.863803 2026] [autoindex:error] [pid 164535:tid 164725] [client 4.204.201.85:58845] AH01276: Cannot serve directory /home4/olearypl/public_html/wp-admin/js/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:37:26.864521 2026] [security2:error] [pid 164535:tid 164725] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/js/"] [unique_id "al4kljYN371eKRzcKeR9RQAAAME"]
[Mon Jul 20 07:37:26.929370 2026] [security2:error] [pid 164535:tid 164686] [client 4.204.201.85:58820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/makeasmtp.php"] [unique_id "al4kljYN371eKRzcKeR9RwAAAJo"]
[Mon Jul 20 07:37:26.929460 2026] [security2:error] [pid 164535:tid 164686] [client 4.204.201.85:58820] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/makeasmtp.php"] [unique_id "al4kljYN371eKRzcKeR9RwAAAJo"]
[Mon Jul 20 07:37:27.061001 2026] [security2:error] [pid 171532:tid 171709] [client 4.204.201.85:49545] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/2P.php"] [unique_id "al4kl0EhLvMuMRNpl03_NgAAATk"]
[Mon Jul 20 07:37:27.061125 2026] [security2:error] [pid 171532:tid 171709] [client 4.204.201.85:49545] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/2P.php"] [unique_id "al4kl0EhLvMuMRNpl03_NgAAATk"]
[Mon Jul 20 07:37:27.083339 2026] [security2:error] [pid 171532:tid 171715] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4klkEhLvMuMRNpl03_IwAAAT8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:27.200982 2026] [security2:error] [pid 171532:tid 171702] [client 4.204.201.85:58851] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/.well-known/about.php"] [unique_id "al4kl0EhLvMuMRNpl03_QAAAATI"]
[Mon Jul 20 07:37:27.201047 2026] [security2:error] [pid 171532:tid 171702] [client 4.204.201.85:58851] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/.well-known/about.php"] [unique_id "al4kl0EhLvMuMRNpl03_QAAAATI"]
[Mon Jul 20 07:37:27.247734 2026] [security2:error] [pid 164535:tid 164694] [client 201.179.152.212:59300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4klzYN371eKRzcKeR9UAAAAKI"]
[Mon Jul 20 07:37:27.344150 2026] [security2:error] [pid 164535:tid 164692] [client 14.225.17.146:64686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4klzYN371eKRzcKeR9VAAAAKA"], referer: http://alrowad-hub.net/bc
[Mon Jul 20 07:37:27.344203 2026] [security2:error] [pid 164535:tid 164729] [client 4.204.201.85:49626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4klzYN371eKRzcKeR9VwAAAMU"]
[Mon Jul 20 07:37:27.344272 2026] [security2:error] [pid 164535:tid 164729] [client 4.204.201.85:49626] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4klzYN371eKRzcKeR9VwAAAMU"]
[Mon Jul 20 07:37:27.476621 2026] [security2:error] [pid 171532:tid 171662] [client 4.204.201.85:58846] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/system_log.php"] [unique_id "al4kl0EhLvMuMRNpl03_TwAAAQo"]
[Mon Jul 20 07:37:27.476726 2026] [security2:error] [pid 171532:tid 171662] [client 4.204.201.85:58846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/system_log.php"] [unique_id "al4kl0EhLvMuMRNpl03_TwAAAQo"]
[Mon Jul 20 07:37:27.614445 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:49646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/"] [unique_id "al4kl0EhLvMuMRNpl03_XwAAAVg"]
[Mon Jul 20 07:37:27.626861 2026] [security2:error] [pid 164535:tid 164665] [client 57.141.18.12:38692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4klTYN371eKRzcKeR8_AAAhVg"]
[Mon Jul 20 07:37:27.680377 2026] [security2:error] [pid 164535:tid 164741] [client 143.44.185.218:64863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4klzYN371eKRzcKeR9XwAAANE"]
[Mon Jul 20 07:37:27.680829 2026] [security2:error] [pid 164535:tid 164741] [client 143.44.185.218:64863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4klzYN371eKRzcKeR9XwAAANE"]
[Mon Jul 20 07:37:27.685460 2026] [autoindex:error] [pid 164535:tid 164669] [client 4.204.201.85:58845] AH01276: Cannot serve directory /home4/olearypl/public_html/wp-admin/css/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:37:27.686055 2026] [security2:error] [pid 164535:tid 164669] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/"] [unique_id "al4klzYN371eKRzcKeR9XgAAAIk"]
[Mon Jul 20 07:37:27.751842 2026] [security2:error] [pid 171532:tid 171683] [client 4.204.201.85:49646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4kl0EhLvMuMRNpl03_ZQAAAR8"]
[Mon Jul 20 07:37:27.823164 2026] [autoindex:error] [pid 164535:tid 164727] [client 4.204.201.85:58845] AH01276: Cannot serve directory /home4/olearypl/public_html/wp-admin/css/colors/modern/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:37:27.823781 2026] [security2:error] [pid 164535:tid 164727] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4klzYN371eKRzcKeR9YQAAAMM"]
[Mon Jul 20 07:37:27.887174 2026] [security2:error] [pid 171532:tid 171712] [client 4.204.201.85:49646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/crgio.php"] [unique_id "al4kl0EhLvMuMRNpl03_dQAAATw"]
[Mon Jul 20 07:37:27.887263 2026] [security2:error] [pid 171532:tid 171712] [client 4.204.201.85:49646] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/crgio.php"] [unique_id "al4kl0EhLvMuMRNpl03_dQAAATw"]
[Mon Jul 20 07:37:27.964499 2026] [security2:error] [pid 164535:tid 164773] [client 57.141.18.100:53424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4klTYN371eKRzcKeR9CwAA8Uk"]
[Mon Jul 20 07:37:28.037833 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/pucci.php"] [unique_id "al4kmEEhLvMuMRNpl03_fQAAAWw"]
[Mon Jul 20 07:37:28.037952 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58865] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/pucci.php"] [unique_id "al4kmEEhLvMuMRNpl03_fQAAAWw"]
[Mon Jul 20 07:37:28.171265 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:58764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4kmDYN371eKRzcKeR9agAAAN0"]
[Mon Jul 20 07:37:28.177190 2026] [security2:error] [pid 171532:tid 171655] [remote 154.66.198.148:57938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4kmEEhLvMuMRNpl03_hgABGHo"]
[Mon Jul 20 07:37:28.238678 2026] [access_compat:error] [pid 164535:tid 164755] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/blocks/details/index.php
[Mon Jul 20 07:37:28.239357 2026] [security2:error] [pid 164535:tid 164755] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/blocks/details/"] [unique_id "al4kmDYN371eKRzcKeR9bQAAAN8"]
[Mon Jul 20 07:37:28.307020 2026] [security2:error] [pid 164535:tid 164759] [client 4.204.201.85:58764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "al4kmDYN371eKRzcKeR9cAAAAOM"]
[Mon Jul 20 07:37:28.376054 2026] [access_compat:error] [pid 164535:tid 164674] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/blocks/audio/index.php
[Mon Jul 20 07:37:28.376658 2026] [security2:error] [pid 164535:tid 164674] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/blocks/audio/"] [unique_id "al4kmDYN371eKRzcKeR9cgAAAI4"]
[Mon Jul 20 07:37:28.440297 2026] [security2:error] [pid 164535:tid 164708] [client 4.204.201.85:58764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-temp.php"] [unique_id "al4kmDYN371eKRzcKeR9cwAAALA"]
[Mon Jul 20 07:37:28.440416 2026] [security2:error] [pid 164535:tid 164708] [client 4.204.201.85:58764] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-temp.php"] [unique_id "al4kmDYN371eKRzcKeR9cwAAALA"]
[Mon Jul 20 07:37:28.442707 2026] [security2:error] [pid 171532:tid 171682] [client 49.37.242.14:62704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kmEEhLvMuMRNpl03_lwAAAR4"]
[Mon Jul 20 07:37:28.442802 2026] [security2:error] [pid 171532:tid 171682] [client 49.37.242.14:62704] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kmEEhLvMuMRNpl03_lwAAAR4"]
[Mon Jul 20 07:37:28.485484 2026] [security2:error] [pid 171532:tid 171726] [client 50.116.65.227:53032] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kmEEhLvMuMRNpl03_mgAAAUo"]
[Mon Jul 20 07:37:28.495522 2026] [security2:error] [pid 164535:tid 164751] [client 50.116.65.227:53036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kmDYN371eKRzcKeR9dQAAANs"]
[Mon Jul 20 07:37:28.563353 2026] [security2:error] [pid 164535:tid 164746] [client 4.204.201.85:58878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4kmDYN371eKRzcKeR9egAAANY"]
[Mon Jul 20 07:37:28.563447 2026] [security2:error] [pid 164535:tid 164746] [client 4.204.201.85:58878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/js/index.php"] [unique_id "al4kmDYN371eKRzcKeR9egAAANY"]
[Mon Jul 20 07:37:28.671522 2026] [security2:error] [pid 171532:tid 171541] [remote 154.66.198.148:57938] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4kmEEhLvMuMRNpl03_pwABOAg"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:37:28.692200 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:58842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/puc.php"] [unique_id "al4kmEEhLvMuMRNpl03_rAAAAYM"]
[Mon Jul 20 07:37:28.692323 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:58842] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/puc.php"] [unique_id "al4kmEEhLvMuMRNpl03_rAAAAYM"]
[Mon Jul 20 07:37:28.699307 2026] [security2:error] [pid 164535:tid 164604] [remote 5.161.225.162:40838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kmDYN371eKRzcKeR9gwAA1EQ"]
[Mon Jul 20 07:37:28.827651 2026] [security2:error] [pid 164535:tid 164763] [client 4.204.201.85:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/dx.php"] [unique_id "al4kmDYN371eKRzcKeR9iAAAAOc"]
[Mon Jul 20 07:37:28.827992 2026] [security2:error] [pid 164535:tid 164763] [client 4.204.201.85:58786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/dx.php"] [unique_id "al4kmDYN371eKRzcKeR9iAAAAOc"]
[Mon Jul 20 07:37:28.895173 2026] [security2:error] [pid 164535:tid 164628] [remote 5.161.225.162:40838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4kmDYN371eKRzcKeR9iwAA0Fw"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:37:28.906692 2026] [security2:error] [pid 171532:tid 171709] [client 14.225.17.146:50668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4kmEEhLvMuMRNpl03_pgAAATk"], referer: http://maxenengineering.com/bc
[Mon Jul 20 07:37:28.954459 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:58834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/Requests/"] [unique_id "al4kmDYN371eKRzcKeR9jAAAAKY"]
[Mon Jul 20 07:37:29.025054 2026] [security2:error] [pid 171532:tid 171698] [client 154.192.233.184:61230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kmUEhLvMuMRNpl03_ugAAAS4"]
[Mon Jul 20 07:37:29.025179 2026] [security2:error] [pid 171532:tid 171698] [client 154.192.233.184:61230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kmUEhLvMuMRNpl03_ugAAAS4"]
[Mon Jul 20 07:37:29.027314 2026] [access_compat:error] [pid 164535:tid 164702] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/Requests/index.php
[Mon Jul 20 07:37:29.027798 2026] [security2:error] [pid 164535:tid 164702] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/Requests/"] [unique_id "al4kmTYN371eKRzcKeR9jQAAAKo"]
[Mon Jul 20 07:37:29.096173 2026] [security2:error] [pid 164535:tid 164682] [client 4.204.201.85:58834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/bthil.php"] [unique_id "al4kmTYN371eKRzcKeR9lAAAAJY"]
[Mon Jul 20 07:37:29.096276 2026] [security2:error] [pid 164535:tid 164682] [client 4.204.201.85:58834] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/bthil.php"] [unique_id "al4kmTYN371eKRzcKeR9lAAAAJY"]
[Mon Jul 20 07:37:29.177652 2026] [security2:error] [pid 171532:tid 171749] [client 103.176.215.66:63310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kmUEhLvMuMRNpl03_vQAAAWE"]
[Mon Jul 20 07:37:29.178123 2026] [security2:error] [pid 171532:tid 171749] [client 103.176.215.66:63310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kmUEhLvMuMRNpl03_vQAAAWE"]
[Mon Jul 20 07:37:29.222646 2026] [security2:error] [pid 171532:tid 171729] [client 4.204.201.85:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/7.php"] [unique_id "al4kmUEhLvMuMRNpl03_vwAAAU0"]
[Mon Jul 20 07:37:29.222763 2026] [security2:error] [pid 171532:tid 171729] [client 4.204.201.85:49619] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/7.php"] [unique_id "al4kmUEhLvMuMRNpl03_vwAAAU0"]
[Mon Jul 20 07:37:29.271988 2026] [security2:error] [pid 171532:tid 171587] [remote 195.26.244.42:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4kmUEhLvMuMRNpl03_wAABNzY"]
[Mon Jul 20 07:37:29.359812 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/8.php"] [unique_id "al4kmUEhLvMuMRNpl03_wwAAAWM"]
[Mon Jul 20 07:37:29.359970 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58833] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/8.php"] [unique_id "al4kmUEhLvMuMRNpl03_wwAAAWM"]
[Mon Jul 20 07:37:29.438789 2026] [security2:error] [pid 164535:tid 164678] [client 136.158.60.21:64343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kmTYN371eKRzcKeR9pQAAAJI"]
[Mon Jul 20 07:37:29.438876 2026] [security2:error] [pid 164535:tid 164678] [client 136.158.60.21:64343] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kmTYN371eKRzcKeR9pQAAAJI"]
[Mon Jul 20 07:37:29.485086 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:58786] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "olearyplumbingllc.com"] [uri "/1.php"] [unique_id "al4kmUEhLvMuMRNpl03_yQAAAVk"]
[Mon Jul 20 07:37:29.485204 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:58786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/1.php"] [unique_id "al4kmUEhLvMuMRNpl03_yQAAAVk"]
[Mon Jul 20 07:37:29.485326 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:58786] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/1.php"] [unique_id "al4kmUEhLvMuMRNpl03_yQAAAVk"]
[Mon Jul 20 07:37:29.607820 2026] [security2:error] [pid 171532:tid 171543] [remote 195.26.244.42:56602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4kmUEhLvMuMRNpl03_0QABFgo"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:37:29.608460 2026] [security2:error] [pid 171532:tid 171757] [client 4.204.201.85:58768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/100.php"] [unique_id "al4kmUEhLvMuMRNpl03_0gAAAWk"]
[Mon Jul 20 07:37:29.608549 2026] [security2:error] [pid 171532:tid 171757] [client 4.204.201.85:58768] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/100.php"] [unique_id "al4kmUEhLvMuMRNpl03_0gAAAWk"]
[Mon Jul 20 07:37:29.614177 2026] [security2:error] [pid 171532:tid 171783] [client 57.141.18.34:54890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4klkEhLvMuMRNpl03_JgABgnk"]
[Mon Jul 20 07:37:29.619369 2026] [security2:error] [pid 164535:tid 164773] [client 191.202.66.27:55002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kmTYN371eKRzcKeR9qgAAAPE"]
[Mon Jul 20 07:37:29.619465 2026] [security2:error] [pid 164535:tid 164773] [client 191.202.66.27:55002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kmTYN371eKRzcKeR9qgAAAPE"]
[Mon Jul 20 07:37:29.733950 2026] [security2:error] [pid 164535:tid 164767] [client 4.204.201.85:58821] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/about.php"] [unique_id "al4kmTYN371eKRzcKeR9rgAAAOs"]
[Mon Jul 20 07:37:29.734037 2026] [security2:error] [pid 164535:tid 164767] [client 4.204.201.85:58821] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/about.php"] [unique_id "al4kmTYN371eKRzcKeR9rgAAAOs"]
[Mon Jul 20 07:37:29.865775 2026] [security2:error] [pid 171532:tid 171672] [client 4.204.201.85:58871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/admin.php"] [unique_id "al4kmUEhLvMuMRNpl03_4AAAARQ"]
[Mon Jul 20 07:37:29.865880 2026] [security2:error] [pid 171532:tid 171672] [client 4.204.201.85:58871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/admin.php"] [unique_id "al4kmUEhLvMuMRNpl03_4AAAARQ"]
[Mon Jul 20 07:37:29.895210 2026] [security2:error] [pid 171532:tid 171696] [client 14.225.17.146:55261] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4kmUEhLvMuMRNpl03_2AAAASw"], referer: https://maxenengineering.com/bc
[Mon Jul 20 07:37:29.939082 2026] [security2:error] [pid 171532:tid 171759] [client 57.141.18.81:40850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kl0EhLvMuMRNpl03_PQABa30"]
[Mon Jul 20 07:37:29.989745 2026] [security2:error] [pid 171532:tid 171716] [client 209.38.46.198:53102] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.soundmeditationmiami.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4kmUEhLvMuMRNpl03_5QAAAUA"]
[Mon Jul 20 07:37:29.990903 2026] [security2:error] [pid 171532:tid 171685] [client 4.204.201.85:58775] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/edit.php"] [unique_id "al4kmUEhLvMuMRNpl03_5gAAASE"]
[Mon Jul 20 07:37:29.991036 2026] [security2:error] [pid 171532:tid 171685] [client 4.204.201.85:58775] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/edit.php"] [unique_id "al4kmUEhLvMuMRNpl03_5gAAASE"]
[Mon Jul 20 07:37:29.996564 2026] [security2:error] [pid 164535:tid 164761] [client 209.38.46.198:53298] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "webmail.soundmeditationsouthflorida.com"] [uri "/___proxy_subdomain_webmail/wp-login.php"] [unique_id "al4kmTYN371eKRzcKeR9tQAAAOU"]
[Mon Jul 20 07:37:30.149329 2026] [security2:error] [pid 164535:tid 164704] [client 4.204.201.85:49611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/admin.php"] [unique_id "al4kmjYN371eKRzcKeR9uwAAAKw"]
[Mon Jul 20 07:37:30.149427 2026] [security2:error] [pid 164535:tid 164704] [client 4.204.201.85:49611] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/admin.php"] [unique_id "al4kmjYN371eKRzcKeR9uwAAAKw"]
[Mon Jul 20 07:37:30.278223 2026] [security2:error] [pid 171532:tid 171673] [client 4.204.201.85:49602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ss.php"] [unique_id "al4kmkEhLvMuMRNpl03_8wAAARU"]
[Mon Jul 20 07:37:30.278309 2026] [security2:error] [pid 171532:tid 171673] [client 4.204.201.85:49602] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ss.php"] [unique_id "al4kmkEhLvMuMRNpl03_8wAAARU"]
[Mon Jul 20 07:37:30.408906 2026] [security2:error] [pid 171532:tid 171731] [client 4.204.201.85:49577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/inputs.php"] [unique_id "al4kmkEhLvMuMRNpl03__QAAAU8"]
[Mon Jul 20 07:37:30.409001 2026] [security2:error] [pid 171532:tid 171731] [client 4.204.201.85:49577] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/inputs.php"] [unique_id "al4kmkEhLvMuMRNpl03__QAAAU8"]
[Mon Jul 20 07:37:30.472196 2026] [security2:error] [pid 171532:tid 171671] [client 57.141.18.19:48040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kl0EhLvMuMRNpl03_UwABExs"]
[Mon Jul 20 07:37:30.537668 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58797] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/av.php"] [unique_id "al4kmkEhLvMuMRNpl00ABwAAAWw"]
[Mon Jul 20 07:37:30.537808 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58797] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/av.php"] [unique_id "al4kmkEhLvMuMRNpl00ABwAAAWw"]
[Mon Jul 20 07:37:30.586653 2026] [security2:error] [pid 171532:tid 171776] [client 14.225.17.146:57397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kmkEhLvMuMRNpl03_-QAAAXs"], referer: http://mezzacraft.com/bc
[Mon Jul 20 07:37:30.636820 2026] [security2:error] [pid 171532:tid 171705] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4kmkEhLvMuMRNpl03_-wABNWk"], referer: http://ali-alghanim.net/bc
[Mon Jul 20 07:37:30.662066 2026] [security2:error] [pid 164535:tid 164702] [client 4.204.201.85:58825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/classwithtostring.php"] [unique_id "al4kmjYN371eKRzcKeR9xAAAAKo"]
[Mon Jul 20 07:37:30.662184 2026] [security2:error] [pid 164535:tid 164702] [client 4.204.201.85:58825] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/classwithtostring.php"] [unique_id "al4kmjYN371eKRzcKeR9xAAAAKo"]
[Mon Jul 20 07:37:30.787689 2026] [security2:error] [pid 171532:tid 171689] [client 4.204.201.85:58752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4kmkEhLvMuMRNpl00AFAAAASU"]
[Mon Jul 20 07:37:30.787801 2026] [security2:error] [pid 171532:tid 171689] [client 4.204.201.85:58752] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/themes/index.php"] [unique_id "al4kmkEhLvMuMRNpl00AFAAAASU"]
[Mon Jul 20 07:37:30.819251 2026] [security2:error] [pid 171532:tid 171711] [client 179.127.84.238:58719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kmkEhLvMuMRNpl00AGAAAATs"]
[Mon Jul 20 07:37:30.819367 2026] [security2:error] [pid 171532:tid 171711] [client 179.127.84.238:58719] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kmkEhLvMuMRNpl00AGAAAATs"]
[Mon Jul 20 07:37:30.914397 2026] [security2:error] [pid 171532:tid 171766] [client 4.204.201.85:58790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-blog.php"] [unique_id "al4kmkEhLvMuMRNpl00AJQAAAXI"]
[Mon Jul 20 07:37:30.914488 2026] [security2:error] [pid 171532:tid 171766] [client 4.204.201.85:58790] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-blog.php"] [unique_id "al4kmkEhLvMuMRNpl00AJQAAAXI"]
[Mon Jul 20 07:37:31.034696 2026] [security2:error] [pid 171532:tid 171726] [client 4.204.201.85:49618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4km0EhLvMuMRNpl00AMQAAAUo"]
[Mon Jul 20 07:37:31.098248 2026] [access_compat:error] [pid 164535:tid 164768] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/js/jquery/index.php
[Mon Jul 20 07:37:31.098941 2026] [security2:error] [pid 164535:tid 164768] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/js/jquery/"] [unique_id "al4kmzYN371eKRzcKeR90AAAAOw"]
[Mon Jul 20 07:37:31.162667 2026] [security2:error] [pid 171532:tid 171789] [client 4.204.201.85:49618] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/admin.php"] [unique_id "al4km0EhLvMuMRNpl00AOgAAAYg"]
[Mon Jul 20 07:37:31.162800 2026] [security2:error] [pid 171532:tid 171789] [client 4.204.201.85:49618] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/admin.php"] [unique_id "al4km0EhLvMuMRNpl00AOgAAAYg"]
[Mon Jul 20 07:37:31.179149 2026] [security2:error] [pid 164535:tid 164687] [client 103.139.191.61:57481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kmzYN371eKRzcKeR91AAAAJs"]
[Mon Jul 20 07:37:31.179325 2026] [security2:error] [pid 164535:tid 164687] [client 103.139.191.61:57481] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kmzYN371eKRzcKeR91AAAAJs"]
[Mon Jul 20 07:37:31.248523 2026] [security2:error] [pid 171532:tid 171786] [client 14.225.17.146:50721] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4km0EhLvMuMRNpl00ANgAAAYU"], referer: http://christiancountytrumpet.com/bc
[Mon Jul 20 07:37:31.302441 2026] [security2:error] [pid 164535:tid 164706] [client 4.204.201.85:58838] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/adminfuns.php"] [unique_id "al4kmzYN371eKRzcKeR91wAAAK4"]
[Mon Jul 20 07:37:31.302533 2026] [security2:error] [pid 164535:tid 164706] [client 4.204.201.85:58838] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/adminfuns.php"] [unique_id "al4kmzYN371eKRzcKeR91wAAAK4"]
[Mon Jul 20 07:37:31.319306 2026] [security2:error] [pid 171532:tid 171691] [client 14.225.17.146:50681] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4km0EhLvMuMRNpl00ANAAAASc"], referer: http://ccsdifference.com/bc
[Mon Jul 20 07:37:31.426350 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:58781] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/goods.php"] [unique_id "al4km0EhLvMuMRNpl00ATQAAAVI"]
[Mon Jul 20 07:37:31.426486 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:58781] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/goods.php"] [unique_id "al4km0EhLvMuMRNpl00ATQAAAVI"]
[Mon Jul 20 07:37:31.550989 2026] [security2:error] [pid 171532:tid 171698] [client 4.204.201.85:49606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ms-edit.php"] [unique_id "al4km0EhLvMuMRNpl00AVAAAAS4"]
[Mon Jul 20 07:37:31.551143 2026] [security2:error] [pid 171532:tid 171698] [client 4.204.201.85:49606] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ms-edit.php"] [unique_id "al4km0EhLvMuMRNpl00AVAAAAS4"]
[Mon Jul 20 07:37:31.684293 2026] [security2:error] [pid 171532:tid 171684] [client 4.204.201.85:58801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/222.php"] [unique_id "al4km0EhLvMuMRNpl00AZAAAASA"]
[Mon Jul 20 07:37:31.684405 2026] [security2:error] [pid 171532:tid 171684] [client 4.204.201.85:58801] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/222.php"] [unique_id "al4km0EhLvMuMRNpl00AZAAAASA"]
[Mon Jul 20 07:37:31.717841 2026] [security2:error] [pid 171532:tid 171700] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4km0EhLvMuMRNpl00AUQAAATA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:31.806923 2026] [security2:error] [pid 164535:tid 164712] [client 4.204.201.85:58754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/cgi-bin/index.php"] [unique_id "al4kmzYN371eKRzcKeR95QAAALQ"]
[Mon Jul 20 07:37:31.807082 2026] [security2:error] [pid 164535:tid 164712] [client 4.204.201.85:58754] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/cgi-bin/index.php"] [unique_id "al4kmzYN371eKRzcKeR95QAAALQ"]
[Mon Jul 20 07:37:31.863837 2026] [security2:error] [pid 171532:tid 171601] [remote 45.90.123.233:57870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4km0EhLvMuMRNpl00AbwABcEQ"]
[Mon Jul 20 07:37:31.939499 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:58866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4km0EhLvMuMRNpl00AdgAAAXs"]
[Mon Jul 20 07:37:31.946704 2026] [security2:error] [pid 171532:tid 171720] [client 14.225.17.146:57737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4km0EhLvMuMRNpl00AaQAAAUQ"], referer: http://cheesewithjam.com/bc
[Mon Jul 20 07:37:32.004145 2026] [access_compat:error] [pid 164535:tid 164772] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/css/dist/index.php
[Mon Jul 20 07:37:32.004832 2026] [security2:error] [pid 164535:tid 164772] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/css/dist/"] [unique_id "al4kmzYN371eKRzcKeR97QAAAPA"]
[Mon Jul 20 07:37:32.050498 2026] [security2:error] [pid 171532:tid 171565] [remote 45.90.123.233:57870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4knEEhLvMuMRNpl00AewABMSA"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:37:32.074995 2026] [security2:error] [pid 171532:tid 171691] [client 4.204.201.85:58866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/BDKR28WP.php"] [unique_id "al4knEEhLvMuMRNpl00AfQAAASc"]
[Mon Jul 20 07:37:32.075132 2026] [security2:error] [pid 171532:tid 171691] [client 4.204.201.85:58866] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/BDKR28WP.php"] [unique_id "al4knEEhLvMuMRNpl00AfQAAASc"]
[Mon Jul 20 07:37:32.206743 2026] [security2:error] [pid 171532:tid 171739] [client 4.204.201.85:58803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/l10n/"] [unique_id "al4knEEhLvMuMRNpl00AhAAAAVc"]
[Mon Jul 20 07:37:32.235048 2026] [security2:error] [pid 164535:tid 164735] [client 74.208.214.194:35796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4knDYN371eKRzcKeR99QAAAMs"]
[Mon Jul 20 07:37:32.239775 2026] [security2:error] [pid 164535:tid 164693] [client 14.225.17.146:50872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4knDYN371eKRzcKeR98AAAAKE"], referer: http://kromosenergy.com/bc
[Mon Jul 20 07:37:32.276455 2026] [access_compat:error] [pid 164535:tid 164743] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/l10n/index.php
[Mon Jul 20 07:37:32.277009 2026] [security2:error] [pid 164535:tid 164743] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/l10n/"] [unique_id "al4knDYN371eKRzcKeR9-wAAANM"]
[Mon Jul 20 07:37:32.284121 2026] [security2:error] [pid 164535:tid 164673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4knDYN371eKRzcKeR98gAAAI0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:32.305636 2026] [security2:error] [pid 171532:tid 171758] [client 15.237.247.147:16970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4km0EhLvMuMRNpl00ATwAAAWo"]
[Mon Jul 20 07:37:32.352420 2026] [security2:error] [pid 171532:tid 171683] [client 4.204.201.85:58803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/uploads/"] [unique_id "al4knEEhLvMuMRNpl00AjQAAAR8"]
[Mon Jul 20 07:37:32.418389 2026] [access_compat:error] [pid 164535:tid 164691] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-content/uploads/index.php
[Mon Jul 20 07:37:32.418902 2026] [security2:error] [pid 164535:tid 164691] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/uploads/"] [unique_id "al4knDYN371eKRzcKeR-BAAAAJ8"]
[Mon Jul 20 07:37:32.468322 2026] [security2:error] [pid 171532:tid 171668] [client 14.225.17.146:57423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4knEEhLvMuMRNpl00AiQAAARA"], referer: https://ccsdifference.com/bc
[Mon Jul 20 07:37:32.480931 2026] [security2:error] [pid 171532:tid 171723] [client 57.141.18.41:53150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kmUEhLvMuMRNpl03_vAABRxo"]
[Mon Jul 20 07:37:32.482581 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:58803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp.php"] [unique_id "al4knEEhLvMuMRNpl00AlAAAAXs"]
[Mon Jul 20 07:37:32.482664 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:58803] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp.php"] [unique_id "al4knEEhLvMuMRNpl00AlAAAAXs"]
[Mon Jul 20 07:37:32.655192 2026] [security2:error] [pid 171532:tid 171676] [client 4.204.201.85:58832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/abcd.php"] [unique_id "al4knEEhLvMuMRNpl00AmwAAARg"]
[Mon Jul 20 07:37:32.655318 2026] [security2:error] [pid 171532:tid 171676] [client 4.204.201.85:58832] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/abcd.php"] [unique_id "al4knEEhLvMuMRNpl00AmwAAARg"]
[Mon Jul 20 07:37:32.667405 2026] [core:error] [pid 171532:tid 171754] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:37:32.667435 2026] [core:error] [pid 171532:tid 171754] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:37:32.733558 2026] [security2:error] [pid 171532:tid 171765] [client 50.116.65.227:55328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4knEEhLvMuMRNpl00AoQAAAXE"]
[Mon Jul 20 07:37:32.744145 2026] [security2:error] [pid 171532:tid 171685] [client 50.116.65.227:55330] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4knEEhLvMuMRNpl00AowAAASE"]
[Mon Jul 20 07:37:32.788860 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:58812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/a1.php"] [unique_id "al4knEEhLvMuMRNpl00ApQAAAVI"]
[Mon Jul 20 07:37:32.788974 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:58812] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/a1.php"] [unique_id "al4knEEhLvMuMRNpl00ApQAAAVI"]
[Mon Jul 20 07:37:32.790567 2026] [security2:error] [pid 171532:tid 171721] [client 14.225.17.146:57814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4knEEhLvMuMRNpl00AkwAAAUU"], referer: http://guidehunting.com/bc
[Mon Jul 20 07:37:32.908232 2026] [security2:error] [pid 164535:tid 164697] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4knDYN371eKRzcKeR-EAAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:32.917624 2026] [security2:error] [pid 171532:tid 171689] [client 4.204.201.85:49540] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4knEEhLvMuMRNpl00AwAAAASU"]
[Mon Jul 20 07:37:32.917689 2026] [security2:error] [pid 171532:tid 171689] [client 4.204.201.85:49540] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4knEEhLvMuMRNpl00AwAAAASU"]
[Mon Jul 20 07:37:33.046683 2026] [security2:error] [pid 164535:tid 164755] [client 4.204.201.85:58777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4knTYN371eKRzcKeR-GwAAAN8"]
[Mon Jul 20 07:37:33.046845 2026] [security2:error] [pid 164535:tid 164755] [client 4.204.201.85:58777] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/cgi-bin/admin.php"] [unique_id "al4knTYN371eKRzcKeR-GwAAAN8"]
[Mon Jul 20 07:37:33.170410 2026] [security2:error] [pid 171532:tid 171771] [client 4.204.201.85:49642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/gettest.php"] [unique_id "al4knUEhLvMuMRNpl00A2QAAAXc"]
[Mon Jul 20 07:37:33.170505 2026] [security2:error] [pid 171532:tid 171771] [client 4.204.201.85:49642] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/gettest.php"] [unique_id "al4knUEhLvMuMRNpl00A2QAAAXc"]
[Mon Jul 20 07:37:33.308613 2026] [security2:error] [pid 171532:tid 171744] [client 4.204.201.85:58852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/"] [unique_id "al4knUEhLvMuMRNpl00A3QAAAVw"]
[Mon Jul 20 07:37:33.376461 2026] [access_compat:error] [pid 164535:tid 164748] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-content/index.php
[Mon Jul 20 07:37:33.377215 2026] [security2:error] [pid 164535:tid 164748] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-content/"] [unique_id "al4knTYN371eKRzcKeR-IwAAANg"]
[Mon Jul 20 07:37:33.456157 2026] [security2:error] [pid 171532:tid 171765] [client 4.204.201.85:58852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/simple.php"] [unique_id "al4knUEhLvMuMRNpl00A4wAAAXE"]
[Mon Jul 20 07:37:33.456338 2026] [security2:error] [pid 171532:tid 171765] [client 4.204.201.85:58852] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/simple.php"] [unique_id "al4knUEhLvMuMRNpl00A4wAAAXE"]
[Mon Jul 20 07:37:33.536247 2026] [authz_core:error] [pid 171532:tid 171750] [client 188.166.209.66:53138] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/IXR/error_log, referer: binance.com
[Mon Jul 20 07:37:33.539074 2026] [security2:error] [pid 171532:tid 171762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4knUEhLvMuMRNpl00A1wAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:33.595919 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:49554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xxx.php"] [unique_id "al4knUEhLvMuMRNpl00A7gAAAVI"]
[Mon Jul 20 07:37:33.596034 2026] [security2:error] [pid 171532:tid 171734] [client 4.204.201.85:49554] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xxx.php"] [unique_id "al4knUEhLvMuMRNpl00A7gAAAVI"]
[Mon Jul 20 07:37:33.608354 2026] [security2:error] [pid 171532:tid 171730] [client 180.249.173.210:55728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4knUEhLvMuMRNpl00A7wAAAU4"]
[Mon Jul 20 07:37:33.608690 2026] [security2:error] [pid 171532:tid 171730] [client 180.249.173.210:55728] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4knUEhLvMuMRNpl00A7wAAAU4"]
[Mon Jul 20 07:37:33.722291 2026] [security2:error] [pid 171532:tid 171736] [client 4.204.201.85:49625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/hypo.php"] [unique_id "al4knUEhLvMuMRNpl00A-wAAAVQ"]
[Mon Jul 20 07:37:33.722415 2026] [security2:error] [pid 171532:tid 171736] [client 4.204.201.85:49625] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/hypo.php"] [unique_id "al4knUEhLvMuMRNpl00A-wAAAVQ"]
[Mon Jul 20 07:37:33.853280 2026] [security2:error] [pid 164535:tid 164700] [client 4.204.201.85:58795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al4knTYN371eKRzcKeR-MwAAAKg"]
[Mon Jul 20 07:37:33.864394 2026] [security2:error] [pid 164535:tid 164772] [client 49.47.218.174:59267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4knTYN371eKRzcKeR-NAAAAPA"]
[Mon Jul 20 07:37:33.864567 2026] [security2:error] [pid 164535:tid 164772] [client 49.47.218.174:59267] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4knTYN371eKRzcKeR-NAAAAPA"]
[Mon Jul 20 07:37:33.871157 2026] [security2:error] [pid 171532:tid 171664] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4knUEhLvMuMRNpl00A8wAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:33.922652 2026] [autoindex:error] [pid 164535:tid 164757] [client 4.204.201.85:58845] AH01276: Cannot serve directory /home4/olearypl/public_html/wp-admin/css/colors/blue/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:37:33.923482 2026] [security2:error] [pid 164535:tid 164757] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al4knTYN371eKRzcKeR-NQAAAOE"]
[Mon Jul 20 07:37:33.986626 2026] [security2:error] [pid 164535:tid 164740] [client 4.204.201.85:58795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/chosen.php"] [unique_id "al4knTYN371eKRzcKeR-NwAAANA"]
[Mon Jul 20 07:37:33.986728 2026] [security2:error] [pid 164535:tid 164740] [client 4.204.201.85:58795] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/chosen.php"] [unique_id "al4knTYN371eKRzcKeR-NwAAANA"]
[Mon Jul 20 07:37:34.010722 2026] [security2:error] [pid 164535:tid 164763] [client 14.225.17.146:58397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4knTYN371eKRzcKeR-MAAAAOc"], referer: https://guidehunting.com/bc
[Mon Jul 20 07:37:34.118238 2026] [security2:error] [pid 164535:tid 164701] [client 4.204.201.85:49600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/block-bindings/"] [unique_id "al4knjYN371eKRzcKeR-PwAAAKk"]
[Mon Jul 20 07:37:34.184039 2026] [access_compat:error] [pid 164535:tid 164753] [client 4.204.201.85:58845] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/block-bindings/index.php
[Mon Jul 20 07:37:34.184636 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:58845] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/block-bindings/"] [unique_id "al4knjYN371eKRzcKeR-QAAAAN0"]
[Mon Jul 20 07:37:34.255098 2026] [security2:error] [pid 164535:tid 164752] [client 4.204.201.85:49600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/als.php"] [unique_id "al4knjYN371eKRzcKeR-QgAAANw"]
[Mon Jul 20 07:37:34.255248 2026] [security2:error] [pid 164535:tid 164752] [client 4.204.201.85:49600] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/als.php"] [unique_id "al4knjYN371eKRzcKeR-QgAAANw"]
[Mon Jul 20 07:37:34.368558 2026] [security2:error] [pid 171532:tid 171684] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4knkEhLvMuMRNpl00BHgAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:34.382973 2026] [security2:error] [pid 164535:tid 164699] [client 57.141.18.107:59490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kmjYN371eKRzcKeR9ywAAp1I"]
[Mon Jul 20 07:37:34.424486 2026] [security2:error] [pid 171532:tid 171760] [client 14.225.17.146:50627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4knkEhLvMuMRNpl00BJgAAAWw"], referer: http://securingmemories.com/bc
[Mon Jul 20 07:37:34.499554 2026] [security2:error] [pid 171532:tid 171717] [client 4.204.201.85:58755] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/pol.php"] [unique_id "al4knkEhLvMuMRNpl00BOAAAAUE"]
[Mon Jul 20 07:37:34.499677 2026] [security2:error] [pid 171532:tid 171717] [client 4.204.201.85:58755] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/pol.php"] [unique_id "al4knkEhLvMuMRNpl00BOAAAAUE"]
[Mon Jul 20 07:37:34.704934 2026] [security2:error] [pid 171532:tid 171682] [client 4.204.201.85:58815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file5.php"] [unique_id "al4knkEhLvMuMRNpl00BSAAAAR4"]
[Mon Jul 20 07:37:34.705027 2026] [security2:error] [pid 171532:tid 171682] [client 4.204.201.85:58815] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file5.php"] [unique_id "al4knkEhLvMuMRNpl00BSAAAAR4"]
[Mon Jul 20 07:37:34.818388 2026] [security2:error] [pid 171532:tid 171678] [client 14.225.17.146:50633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4knkEhLvMuMRNpl00BSwAAARo"], referer: http://ancestralidadytrance.space/bc
[Mon Jul 20 07:37:34.820723 2026] [security2:error] [pid 164535:tid 164595] [remote 67.207.94.191:31274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.94.207.67.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4knjYN371eKRzcKeR-UwAA8Ts"]
[Mon Jul 20 07:37:34.820861 2026] [security2:error] [pid 164535:tid 164773] [client 67.207.94.191:31274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4knjYN371eKRzcKeR-UwAA8Ts"]
[Mon Jul 20 07:37:34.921140 2026] [security2:error] [pid 171532:tid 171734] [client 157.20.138.62:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4knkEhLvMuMRNpl00BVwAAAVI"]
[Mon Jul 20 07:37:34.921236 2026] [security2:error] [pid 171532:tid 171734] [client 157.20.138.62:61658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4knkEhLvMuMRNpl00BVwAAAVI"]
[Mon Jul 20 07:37:34.942955 2026] [security2:error] [pid 164535:tid 164771] [client 4.204.201.85:58788] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file.php"] [unique_id "al4knjYN371eKRzcKeR-WQAAAO8"]
[Mon Jul 20 07:37:34.943054 2026] [security2:error] [pid 164535:tid 164771] [client 4.204.201.85:58788] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file.php"] [unique_id "al4knjYN371eKRzcKeR-WQAAAO8"]
[Mon Jul 20 07:37:34.978418 2026] [security2:error] [pid 171532:tid 171561] [remote 20.151.205.204:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 204.205.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cpanel.assasalnazaha.com"] [uri "/.well-known/about.php"] [unique_id "al4knkEhLvMuMRNpl00BYAABYxw"]
[Mon Jul 20 07:37:34.978567 2026] [security2:error] [pid 171532:tid 171751] [client 20.151.205.204:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "cpanel.assasalnazaha.com"] [uri "/.well-known/about.php"] [unique_id "al4knkEhLvMuMRNpl00BYAABYxw"]
[Mon Jul 20 07:37:35.217136 2026] [security2:error] [pid 171532:tid 171711] [client 4.204.201.85:49629] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/cfile.php"] [unique_id "al4kn0EhLvMuMRNpl00BbQAAATs"]
[Mon Jul 20 07:37:35.217223 2026] [security2:error] [pid 171532:tid 171711] [client 4.204.201.85:49629] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/cfile.php"] [unique_id "al4kn0EhLvMuMRNpl00BbQAAATs"]
[Mon Jul 20 07:37:35.219572 2026] [security2:error] [pid 164535:tid 164679] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4knzYN371eKRzcKeR-WwAAAJM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:35.298708 2026] [security2:error] [pid 171532:tid 171727] [client 57.141.18.104:33992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4km0EhLvMuMRNpl00AZgABSwY"]
[Mon Jul 20 07:37:35.484158 2026] [security2:error] [pid 171532:tid 171772] [client 4.204.201.85:49648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/admin.php"] [unique_id "al4kn0EhLvMuMRNpl00BggAAAXg"]
[Mon Jul 20 07:37:35.484275 2026] [security2:error] [pid 171532:tid 171772] [client 4.204.201.85:49648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/admin.php"] [unique_id "al4kn0EhLvMuMRNpl00BggAAAXg"]
[Mon Jul 20 07:37:35.694938 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/aa2.php"] [unique_id "al4kn0EhLvMuMRNpl00BkQAAAWw"]
[Mon Jul 20 07:37:35.695033 2026] [security2:error] [pid 171532:tid 171760] [client 4.204.201.85:58844] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/aa2.php"] [unique_id "al4kn0EhLvMuMRNpl00BkQAAAWw"]
[Mon Jul 20 07:37:35.732422 2026] [security2:error] [pid 171532:tid 171733] [client 32.198.12.77:42758] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4kn0EhLvMuMRNpl00BkAAAAVE"]
[Mon Jul 20 07:37:35.775884 2026] [security2:error] [pid 171532:tid 171664] [client 155.2.215.88:51863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kn0EhLvMuMRNpl00BjgAAAQw"]
[Mon Jul 20 07:37:35.858913 2026] [security2:error] [pid 171532:tid 171672] [client 149.0.16.108:64906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kn0EhLvMuMRNpl00BmAAAARQ"]
[Mon Jul 20 07:37:35.859012 2026] [security2:error] [pid 171532:tid 171672] [client 149.0.16.108:64906] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kn0EhLvMuMRNpl00BmAAAARQ"]
[Mon Jul 20 07:37:35.893396 2026] [security2:error] [pid 171532:tid 171669] [client 116.193.128.26:52494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kn0EhLvMuMRNpl00BmgAAARE"]
[Mon Jul 20 07:37:35.893516 2026] [security2:error] [pid 171532:tid 171669] [client 116.193.128.26:52494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kn0EhLvMuMRNpl00BmgAAARE"]
[Mon Jul 20 07:37:35.947557 2026] [security2:error] [pid 171532:tid 171698] [client 4.204.201.85:49660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ccou.php"] [unique_id "al4kn0EhLvMuMRNpl00BoAAAAS4"]
[Mon Jul 20 07:37:35.947679 2026] [security2:error] [pid 171532:tid 171698] [client 4.204.201.85:49660] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ccou.php"] [unique_id "al4kn0EhLvMuMRNpl00BoAAAAS4"]
[Mon Jul 20 07:37:36.215138 2026] [security2:error] [pid 171532:tid 171678] [client 36.93.152.155:53729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4koEEhLvMuMRNpl00BuwAAARo"]
[Mon Jul 20 07:37:36.215261 2026] [security2:error] [pid 171532:tid 171678] [client 36.93.152.155:53729] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4koEEhLvMuMRNpl00BuwAAARo"]
[Mon Jul 20 07:37:36.296087 2026] [security2:error] [pid 164535:tid 164791] [client 3.85.28.216:51816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.85.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4koDYN371eKRzcKeR-bgAAAQM"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:37:36.331554 2026] [security2:error] [pid 171532:tid 171736] [client 14.225.17.146:50538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4koEEhLvMuMRNpl00BtgAAAVQ"], referer: http://taskidsvirginia.com/bc
[Mon Jul 20 07:37:36.356264 2026] [security2:error] [pid 171532:tid 171744] [client 65.111.22.164:14665] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 164.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4koEEhLvMuMRNpl00BvQAAAVw"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:36.396780 2026] [security2:error] [pid 171532:tid 171766] [client 154.192.123.127:18077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4koEEhLvMuMRNpl00ByAAAAXI"]
[Mon Jul 20 07:37:36.396894 2026] [security2:error] [pid 171532:tid 171766] [client 154.192.123.127:18077] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4koEEhLvMuMRNpl00ByAAAAXI"]
[Mon Jul 20 07:37:36.410687 2026] [security2:error] [pid 171532:tid 171743] [client 4.204.201.85:58799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/dr.php"] [unique_id "al4koEEhLvMuMRNpl00BzQAAAVs"]
[Mon Jul 20 07:37:36.410765 2026] [security2:error] [pid 171532:tid 171743] [client 4.204.201.85:58799] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/dr.php"] [unique_id "al4koEEhLvMuMRNpl00BzQAAAVs"]
[Mon Jul 20 07:37:36.560081 2026] [security2:error] [pid 171532:tid 171728] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4koEEhLvMuMRNpl00BwgAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:36.582578 2026] [security2:error] [pid 171532:tid 171640] [remote 45.90.123.233:57884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4koEEhLvMuMRNpl00B3gABQ2s"]
[Mon Jul 20 07:37:36.693611 2026] [security2:error] [pid 171532:tid 171775] [client 57.141.18.73:43878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4knEEhLvMuMRNpl00AyQABemc"]
[Mon Jul 20 07:37:36.775535 2026] [security2:error] [pid 171532:tid 171655] [remote 45.90.123.233:57884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4koEEhLvMuMRNpl00B6wABd3o"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:37:36.785349 2026] [security2:error] [pid 171532:tid 171716] [client 4.204.201.85:49612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xamp.php"] [unique_id "al4koEEhLvMuMRNpl00B7QAAAUA"]
[Mon Jul 20 07:37:36.785432 2026] [security2:error] [pid 171532:tid 171716] [client 4.204.201.85:49612] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xamp.php"] [unique_id "al4koEEhLvMuMRNpl00B7QAAAUA"]
[Mon Jul 20 07:37:36.822635 2026] [security2:error] [pid 171532:tid 171761] [client 82.102.18.116:49028] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "fic.zzt.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4koEEhLvMuMRNpl00B7wAAAW0"]
[Mon Jul 20 07:37:36.994349 2026] [security2:error] [pid 171532:tid 171701] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4koEEhLvMuMRNpl00B7gAAATE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:37.064700 2026] [security2:error] [pid 171532:tid 171727] [client 103.106.165.44:58717] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4koUEhLvMuMRNpl00B_QAAAUs"]
[Mon Jul 20 07:37:37.064838 2026] [security2:error] [pid 171532:tid 171727] [client 103.106.165.44:58717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4koUEhLvMuMRNpl00B_QAAAUs"]
[Mon Jul 20 07:37:37.084109 2026] [security2:error] [pid 164535:tid 164767] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4koDYN371eKRzcKeR-fgAAAOs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:37.138589 2026] [security2:error] [pid 171532:tid 171679] [client 82.102.18.116:49034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4koUEhLvMuMRNpl00CCAAAARs"]
[Mon Jul 20 07:37:37.320645 2026] [security2:error] [pid 171532:tid 171671] [client 14.225.17.146:50511] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4koEEhLvMuMRNpl00BqwAAARM"], referer: http://39ishlife.com/bc
[Mon Jul 20 07:37:37.418030 2026] [core:error] [pid 164535:tid 164728] [client 14.225.17.146:53360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:37:37.418056 2026] [core:error] [pid 164535:tid 164728] [client 14.225.17.146:53360] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:37:37.536261 2026] [security2:error] [pid 171532:tid 171745] [client 4.204.201.85:49542] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/bless.php"] [unique_id "al4koUEhLvMuMRNpl00CJwAAAV0"]
[Mon Jul 20 07:37:37.536341 2026] [security2:error] [pid 171532:tid 171745] [client 4.204.201.85:49542] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/bless.php"] [unique_id "al4koUEhLvMuMRNpl00CJwAAAV0"]
[Mon Jul 20 07:37:37.640892 2026] [security2:error] [pid 171532:tid 171694] [client 57.141.18.68:62778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4knUEhLvMuMRNpl00BEAABKlY"]
[Mon Jul 20 07:37:37.725961 2026] [security2:error] [pid 164535:tid 164555] [remote 45.90.123.233:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4koTYN371eKRzcKeR-kgAA4xM"]
[Mon Jul 20 07:37:37.770583 2026] [security2:error] [pid 171532:tid 171662] [client 57.141.18.67:59838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4knkEhLvMuMRNpl00BHQABCjM"]
[Mon Jul 20 07:37:37.813663 2026] [security2:error] [pid 171532:tid 171685] [client 45.3.42.100:31001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4koUEhLvMuMRNpl00CNQAAASE"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:37.909951 2026] [security2:error] [pid 164535:tid 164567] [remote 45.90.123.233:58492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rentorangegrove.com"] [uri "/wp-login.php"] [unique_id "al4koTYN371eKRzcKeR-mAAA0B8"], referer: https://rentorangegrove.com/wp-login.php
[Mon Jul 20 07:37:37.916286 2026] [security2:error] [pid 171532:tid 171730] [client 4.204.201.85:58773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file25.php"] [unique_id "al4koUEhLvMuMRNpl00CRAAAAU4"]
[Mon Jul 20 07:37:37.916424 2026] [security2:error] [pid 171532:tid 171730] [client 4.204.201.85:58773] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file25.php"] [unique_id "al4koUEhLvMuMRNpl00CRAAAAU4"]
[Mon Jul 20 07:37:38.227394 2026] [security2:error] [pid 171532:tid 171720] [client 14.225.17.146:52480] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4kokEhLvMuMRNpl00CWAAAAUQ"], referer: https://39ishlife.com/bc
[Mon Jul 20 07:37:38.325117 2026] [security2:error] [pid 171532:tid 171673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4koUEhLvMuMRNpl00CQQAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:38.493337 2026] [security2:error] [pid 164535:tid 164751] [client 57.141.18.125:28816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4knjYN371eKRzcKeR-TgAA238"]
[Mon Jul 20 07:37:38.513891 2026] [security2:error] [pid 171532:tid 171775] [client 82.102.18.116:49048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kokEhLvMuMRNpl00CdwAAAXo"]
[Mon Jul 20 07:37:38.513981 2026] [security2:error] [pid 171532:tid 171775] [client 82.102.18.116:49048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fic.zzt.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kokEhLvMuMRNpl00CdwAAAXo"]
[Mon Jul 20 07:37:38.834212 2026] [security2:error] [pid 171532:tid 171696] [client 4.204.201.85:58805] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file6.php"] [unique_id "al4kokEhLvMuMRNpl00CjgAAASw"]
[Mon Jul 20 07:37:38.834305 2026] [security2:error] [pid 171532:tid 171696] [client 4.204.201.85:58805] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file6.php"] [unique_id "al4kokEhLvMuMRNpl00CjgAAASw"]
[Mon Jul 20 07:37:39.221404 2026] [security2:error] [pid 171532:tid 171708] [client 57.141.18.110:44384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kn0EhLvMuMRNpl00BeQABOCA"]
[Mon Jul 20 07:37:39.246523 2026] [security2:error] [pid 171532:tid 171783] [client 93.112.130.211:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cheesewithjam.com"] [uri "/index.php"] [unique_id "al4kokEhLvMuMRNpl00CggAAAYI"], referer: http://www.cheesewithjam.com/shop/
[Mon Jul 20 07:37:39.264195 2026] [security2:error] [pid 171532:tid 171709] [client 104.207.53.208:12881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4ko0EhLvMuMRNpl00CsAAAATk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:39.266356 2026] [security2:error] [pid 171532:tid 171753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kokEhLvMuMRNpl00CmgAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:39.435279 2026] [security2:error] [pid 171532:tid 171756] [client 77.110.127.138:52823] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/colour-work/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4ko0EhLvMuMRNpl00CxAAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:39.587584 2026] [security2:error] [pid 171532:tid 171727] [client 154.192.233.184:61631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4ko0EhLvMuMRNpl00C0QAAAUs"]
[Mon Jul 20 07:37:39.589461 2026] [security2:error] [pid 171532:tid 171727] [client 154.192.233.184:61631] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4ko0EhLvMuMRNpl00C0QAAAUs"]
[Mon Jul 20 07:37:39.650547 2026] [security2:error] [pid 171532:tid 171545] [remote 162.19.86.63:34306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ko0EhLvMuMRNpl00C1wABGww"]
[Mon Jul 20 07:37:39.680059 2026] [security2:error] [pid 171532:tid 171698] [client 116.74.65.235:49689] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ko0EhLvMuMRNpl00C2QAAAS4"]
[Mon Jul 20 07:37:39.680151 2026] [security2:error] [pid 171532:tid 171698] [client 116.74.65.235:49689] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ko0EhLvMuMRNpl00C2QAAAS4"]
[Mon Jul 20 07:37:39.705787 2026] [security2:error] [pid 171532:tid 171764] [client 103.176.215.66:63840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ko0EhLvMuMRNpl00C3QAAAXA"]
[Mon Jul 20 07:37:39.706456 2026] [security2:error] [pid 171532:tid 171764] [client 103.176.215.66:63840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4ko0EhLvMuMRNpl00C3QAAAXA"]
[Mon Jul 20 07:37:39.777464 2026] [security2:error] [pid 171532:tid 171708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ko0EhLvMuMRNpl00CzwAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:39.836463 2026] [security2:error] [pid 171532:tid 171733] [client 104.207.51.12:30221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ko0EhLvMuMRNpl00C6wAAAVE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:39.865563 2026] [security2:error] [pid 171532:tid 171641] [remote 162.19.86.63:34306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ko0EhLvMuMRNpl00C7AABFWw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:37:39.871631 2026] [security2:error] [pid 171532:tid 171692] [client 4.204.201.85:49622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/a2.php"] [unique_id "al4ko0EhLvMuMRNpl00C7gAAASg"]
[Mon Jul 20 07:37:39.871708 2026] [security2:error] [pid 171532:tid 171692] [client 4.204.201.85:49622] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/a2.php"] [unique_id "al4ko0EhLvMuMRNpl00C7gAAASg"]
[Mon Jul 20 07:37:40.100210 2026] [security2:error] [pid 164535:tid 164647] [remote 103.187.23.21:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4kpDYN371eKRzcKeR-xAAAvW8"]
[Mon Jul 20 07:37:40.185557 2026] [security2:error] [pid 171532:tid 171730] [client 136.158.60.21:501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DCgAAAU4"]
[Mon Jul 20 07:37:40.185712 2026] [security2:error] [pid 171532:tid 171730] [client 136.158.60.21:501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DCgAAAU4"]
[Mon Jul 20 07:37:40.199774 2026] [security2:error] [pid 171532:tid 171763] [client 103.139.191.61:57960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DCwAAAW8"]
[Mon Jul 20 07:37:40.199873 2026] [security2:error] [pid 171532:tid 171763] [client 103.139.191.61:57960] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DCwAAAW8"]
[Mon Jul 20 07:37:40.207740 2026] [security2:error] [pid 171532:tid 171781] [client 191.202.66.27:55487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DDAAAAYA"]
[Mon Jul 20 07:37:40.207819 2026] [security2:error] [pid 171532:tid 171781] [client 191.202.66.27:55487] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DDAAAAYA"]
[Mon Jul 20 07:37:40.319620 2026] [security2:error] [pid 171532:tid 171745] [client 159.26.120.31:56417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 31.120.26.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DEgAAAV0"]
[Mon Jul 20 07:37:40.319781 2026] [security2:error] [pid 171532:tid 171745] [client 159.26.120.31:56417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aviationsynergy.aero"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DEgAAAV0"]
[Mon Jul 20 07:37:40.468889 2026] [security2:error] [pid 171532:tid 171737] [client 104.207.60.96:35035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 96.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kpEEhLvMuMRNpl00DIAAAAVU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:40.569447 2026] [security2:error] [pid 164535:tid 164646] [remote 103.187.23.21:47160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4kpDYN371eKRzcKeR-zwAApW4"], referer: https://nextlevelpressurewashing.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:37:40.577405 2026] [security2:error] [pid 171532:tid 171747] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kpEEhLvMuMRNpl00DFgAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:40.637094 2026] [security2:error] [pid 171532:tid 171702] [client 14.225.17.146:52386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4kpEEhLvMuMRNpl00DHgAAATI"]
[Mon Jul 20 07:37:40.656256 2026] [security2:error] [pid 171532:tid 171728] [client 143.44.185.218:1725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DMwAAAUw"]
[Mon Jul 20 07:37:40.658605 2026] [security2:error] [pid 171532:tid 171728] [client 143.44.185.218:1725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kpEEhLvMuMRNpl00DMwAAAUw"]
[Mon Jul 20 07:37:40.699213 2026] [security2:error] [pid 171532:tid 171677] [client 65.111.22.166:34271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kpEEhLvMuMRNpl00DNQAAARk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:40.826054 2026] [security2:error] [pid 171532:tid 171669] [client 57.141.18.23:23216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4koUEhLvMuMRNpl00CAgABETw"]
[Mon Jul 20 07:37:40.872562 2026] [security2:error] [pid 171532:tid 171716] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kpEEhLvMuMRNpl00DNAAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:41.070587 2026] [security2:error] [pid 171532:tid 171723] [client 104.207.54.124:45419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kpUEhLvMuMRNpl00DSQAAAUc"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:41.283630 2026] [security2:error] [pid 171532:tid 171712] [client 179.127.84.238:59271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kpUEhLvMuMRNpl00DXwAAATw"]
[Mon Jul 20 07:37:41.283746 2026] [security2:error] [pid 171532:tid 171712] [client 179.127.84.238:59271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kpUEhLvMuMRNpl00DXwAAATw"]
[Mon Jul 20 07:37:41.286172 2026] [authz_core:error] [pid 171532:tid 171739] [client 188.166.209.66:57916] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/IXR/error_log, referer: binance.com
[Mon Jul 20 07:37:41.350170 2026] [security2:error] [pid 171532:tid 171768] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kpUEhLvMuMRNpl00DVwAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:41.465299 2026] [security2:error] [pid 171532:tid 171669] [client 4.204.201.85:58785] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file15.php"] [unique_id "al4kpUEhLvMuMRNpl00DbgAAARE"]
[Mon Jul 20 07:37:41.465403 2026] [security2:error] [pid 171532:tid 171669] [client 4.204.201.85:58785] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file15.php"] [unique_id "al4kpUEhLvMuMRNpl00DbgAAARE"]
[Mon Jul 20 07:37:41.482971 2026] [security2:error] [pid 164535:tid 164695] [client 57.141.18.17:42448] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4koTYN371eKRzcKeR-lQAAoxQ"]
[Mon Jul 20 07:37:41.734929 2026] [security2:error] [pid 171532:tid 171673] [client 65.111.27.205:42615] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 205.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kpUEhLvMuMRNpl00DgwAAARU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:41.923139 2026] [security2:error] [pid 171532:tid 171541] [remote 5.161.225.162:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4kpUEhLvMuMRNpl00DjgABHgg"]
[Mon Jul 20 07:37:42.122211 2026] [security2:error] [pid 171532:tid 171581] [remote 5.161.225.162:42040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ccsdifference.com"] [uri "/wp-login.php"] [unique_id "al4kpkEhLvMuMRNpl00DnAABTzA"], referer: https://ccsdifference.com/wp-login.php
[Mon Jul 20 07:37:42.346859 2026] [security2:error] [pid 164535:tid 164693] [client 45.3.44.249:24373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kpjYN371eKRzcKeR-9AAAAKE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:42.652032 2026] [security2:error] [pid 171532:tid 171752] [client 57.141.18.65:46490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kokEhLvMuMRNpl00CmAABZDQ"]
[Mon Jul 20 07:37:42.826611 2026] [security2:error] [pid 164535:tid 164737] [client 4.204.201.85:58780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/f35.php"] [unique_id "al4kpjYN371eKRzcKeR_BAAAAM0"]
[Mon Jul 20 07:37:42.826708 2026] [security2:error] [pid 164535:tid 164737] [client 4.204.201.85:58780] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/f35.php"] [unique_id "al4kpjYN371eKRzcKeR_BAAAAM0"]
[Mon Jul 20 07:37:42.830790 2026] [security2:error] [pid 171532:tid 171741] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kpkEhLvMuMRNpl00DuwAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:43.337366 2026] [security2:error] [pid 164535:tid 164686] [client 136.144.33.200:56077] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4kpzYN371eKRzcKeR_GQAAAJo"]
[Mon Jul 20 07:37:43.348003 2026] [security2:error] [pid 164535:tid 164734] [client 193.36.225.8:46495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4kpzYN371eKRzcKeR_GAAAAMo"]
[Mon Jul 20 07:37:43.353205 2026] [security2:error] [pid 164535:tid 164714] [client 136.144.33.206:51671] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4kpzYN371eKRzcKeR_FwAAALY"]
[Mon Jul 20 07:37:43.375048 2026] [security2:error] [pid 171532:tid 171758] [client 57.141.18.91:32974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ko0EhLvMuMRNpl00C3wABai4"]
[Mon Jul 20 07:37:43.412956 2026] [security2:error] [pid 164535:tid 164675] [client 77.110.127.138:52861] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/colour-work/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4kpzYN371eKRzcKeR_HgAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:43.630601 2026] [security2:error] [pid 164535:tid 164674] [client 4.204.201.85:58762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-load.php"] [unique_id "al4kpzYN371eKRzcKeR_KgAAAI4"]
[Mon Jul 20 07:37:43.630693 2026] [security2:error] [pid 164535:tid 164674] [client 4.204.201.85:58762] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-load.php"] [unique_id "al4kpzYN371eKRzcKeR_KgAAAI4"]
[Mon Jul 20 07:37:43.673670 2026] [security2:error] [pid 171532:tid 171689] [client 49.37.242.14:63239] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kp0EhLvMuMRNpl00D7QAAASU"]
[Mon Jul 20 07:37:43.673818 2026] [security2:error] [pid 171532:tid 171689] [client 49.37.242.14:63239] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kp0EhLvMuMRNpl00D7QAAASU"]
[Mon Jul 20 07:37:43.816719 2026] [security2:error] [pid 164535:tid 164781] [client 14.225.17.146:52784] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4kpzYN371eKRzcKeR_KwAAAPk"], referer: http://grndl.com/bc
[Mon Jul 20 07:37:43.877888 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xwpg.php"] [unique_id "al4kp0EhLvMuMRNpl00D9AAAAWM"]
[Mon Jul 20 07:37:43.878003 2026] [security2:error] [pid 171532:tid 171751] [client 4.204.201.85:58868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xwpg.php"] [unique_id "al4kp0EhLvMuMRNpl00D9AAAAWM"]
[Mon Jul 20 07:37:43.905506 2026] [security2:error] [pid 171532:tid 171759] [client 14.225.17.146:62167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4kpkEhLvMuMRNpl00DrgAAAWs"], referer: http://thechancersband.com/bc
[Mon Jul 20 07:37:44.006895 2026] [security2:error] [pid 171532:tid 171708] [client 4.204.201.85:49556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-includes/assets/"] [unique_id "al4kqEEhLvMuMRNpl00EAQAAATg"]
[Mon Jul 20 07:37:44.078550 2026] [security2:error] [pid 171532:tid 171665] [client 57.141.18.101:64360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kpEEhLvMuMRNpl00DGAABDUM"]
[Mon Jul 20 07:37:44.251442 2026] [security2:error] [pid 171532:tid 171752] [client 13.86.113.214:37416] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "box5936.bluehost.com"] [uri "/index.cgi"] [unique_id "al4kqEEhLvMuMRNpl00EDAAAAWQ"]
[Mon Jul 20 07:37:44.265693 2026] [access_compat:error] [pid 171532:tid 171768] [client 4.204.201.85:58817] AH01797: client denied by server configuration: /home4/olearypl/public_html/wp-includes/assets/index.php
[Mon Jul 20 07:37:44.266385 2026] [security2:error] [pid 171532:tid 171768] [client 4.204.201.85:58817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/cgi-sys/403.html"] [unique_id "al4kqEEhLvMuMRNpl00EEQAAAXQ"]
[Mon Jul 20 07:37:44.330261 2026] [security2:error] [pid 171532:tid 171687] [client 4.204.201.85:49556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al4kqEEhLvMuMRNpl00EFAAAASM"]
[Mon Jul 20 07:37:44.354707 2026] [security2:error] [pid 171532:tid 171597] [remote 103.187.169.251:56248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kqEEhLvMuMRNpl00EFgABgEA"]
[Mon Jul 20 07:37:44.386686 2026] [security2:error] [pid 171532:tid 171753] [client 49.47.218.174:59814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kqEEhLvMuMRNpl00EGgAAAWU"]
[Mon Jul 20 07:37:44.386808 2026] [security2:error] [pid 171532:tid 171753] [client 49.47.218.174:59814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kqEEhLvMuMRNpl00EGgAAAWU"]
[Mon Jul 20 07:37:44.415526 2026] [autoindex:error] [pid 171532:tid 171702] [client 4.204.201.85:58817] AH01276: Cannot serve directory /home4/olearypl/public_html/wp-admin/css/colors/sunrise/: No matching DirectoryIndex (index.php) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:37:44.416560 2026] [security2:error] [pid 171532:tid 171702] [client 4.204.201.85:58817] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "403"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/css/colors/sunrise/"] [unique_id "al4kqEEhLvMuMRNpl00EHAAAATI"]
[Mon Jul 20 07:37:44.429540 2026] [security2:error] [pid 171532:tid 171732] [client 180.249.173.210:56204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kqEEhLvMuMRNpl00EIgAAAVA"]
[Mon Jul 20 07:37:44.447744 2026] [security2:error] [pid 171532:tid 171732] [client 180.249.173.210:56204] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kqEEhLvMuMRNpl00EIgAAAVA"]
[Mon Jul 20 07:37:44.478785 2026] [security2:error] [pid 171532:tid 171782] [client 4.204.201.85:49556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xstelth.php"] [unique_id "al4kqEEhLvMuMRNpl00EJwAAAYE"]
[Mon Jul 20 07:37:44.478944 2026] [security2:error] [pid 171532:tid 171782] [client 4.204.201.85:49556] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xstelth.php"] [unique_id "al4kqEEhLvMuMRNpl00EJwAAAYE"]
[Mon Jul 20 07:37:44.538331 2026] [security2:error] [pid 171532:tid 171761] [client 14.225.17.146:53095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4kpkEhLvMuMRNpl00DqAAAAW0"], referer: http://latiendadejorge.com.gt/bc
[Mon Jul 20 07:37:44.579190 2026] [security2:error] [pid 164535:tid 164735] [client 14.225.17.146:62104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4kqDYN371eKRzcKeR_QQAAAMs"], referer: http://savilerowtravel.com/bc
[Mon Jul 20 07:37:44.663840 2026] [security2:error] [pid 171532:tid 171693] [client 45.157.112.60:62739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kqEEhLvMuMRNpl00EMgAAASk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:37:44.697920 2026] [security2:error] [pid 164535:tid 164721] [client 57.141.18.110:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mrbambooplus.com"] [uri "/index.php"] [unique_id "al4kqDYN371eKRzcKeR_NAAAAL0"]
[Mon Jul 20 07:37:44.772728 2026] [security2:error] [pid 171532:tid 171705] [client 180.102.110.168:37928] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.oohlovely.com"] [uri "/"] [unique_id "al4kqEEhLvMuMRNpl00EOwAAATU"]
[Mon Jul 20 07:37:44.772897 2026] [security2:error] [pid 171532:tid 171705] [client 180.102.110.168:37928] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.oohlovely.com"] [uri "/"] [unique_id "al4kqEEhLvMuMRNpl00EOwAAATU"]
[Mon Jul 20 07:37:44.778653 2026] [security2:error] [pid 164535:tid 164681] [client 14.225.17.146:52812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4kpzYN371eKRzcKeR_LAAAAJU"], referer: http://retzkolonglogistics.com/bc
[Mon Jul 20 07:37:44.800026 2026] [security2:error] [pid 171532:tid 171648] [remote 103.187.169.251:56248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kqEEhLvMuMRNpl00EPgABdXM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:37:44.811445 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:49607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4kqEEhLvMuMRNpl00EQQAAAVk"]
[Mon Jul 20 07:37:44.811558 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:49607] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/wp-admin/network/plugins.php"] [unique_id "al4kqEEhLvMuMRNpl00EQQAAAVk"]
[Mon Jul 20 07:37:44.964102 2026] [security2:error] [pid 171532:tid 171710] [client 4.204.201.85:58874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/aaa.php"] [unique_id "al4kqEEhLvMuMRNpl00ERwAAATo"]
[Mon Jul 20 07:37:44.964246 2026] [security2:error] [pid 171532:tid 171710] [client 4.204.201.85:58874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/aaa.php"] [unique_id "al4kqEEhLvMuMRNpl00ERwAAATo"]
[Mon Jul 20 07:37:45.105799 2026] [security2:error] [pid 171532:tid 171673] [client 4.204.201.85:58784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/gecko.php"] [unique_id "al4kqUEhLvMuMRNpl00ETwAAARU"]
[Mon Jul 20 07:37:45.105878 2026] [security2:error] [pid 171532:tid 171673] [client 4.204.201.85:58784] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/gecko.php"] [unique_id "al4kqUEhLvMuMRNpl00ETwAAARU"]
[Mon Jul 20 07:37:45.206564 2026] [security2:error] [pid 171532:tid 171744] [client 216.73.217.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.poopscoopuniversity.com"] [uri "/index.php"] [unique_id "al4kqEEhLvMuMRNpl00EIwABXCc"]
[Mon Jul 20 07:37:45.251834 2026] [security2:error] [pid 171532:tid 171738] [client 4.204.201.85:7108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/sh3ll.php"] [unique_id "al4kqUEhLvMuMRNpl00EWQAAAVY"]
[Mon Jul 20 07:37:45.251943 2026] [security2:error] [pid 171532:tid 171738] [client 4.204.201.85:7108] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/sh3ll.php"] [unique_id "al4kqUEhLvMuMRNpl00EWQAAAVY"]
[Mon Jul 20 07:37:45.293014 2026] [security2:error] [pid 171532:tid 171722] [client 57.141.18.42:40740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kpUEhLvMuMRNpl00DfgABRhE"]
[Mon Jul 20 07:37:45.385032 2026] [security2:error] [pid 171532:tid 171753] [client 4.204.201.85:49662] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/pbck.php"] [unique_id "al4kqUEhLvMuMRNpl00EZQAAAWU"]
[Mon Jul 20 07:37:45.385149 2026] [security2:error] [pid 171532:tid 171753] [client 4.204.201.85:49662] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/pbck.php"] [unique_id "al4kqUEhLvMuMRNpl00EZQAAAWU"]
[Mon Jul 20 07:37:45.447083 2026] [security2:error] [pid 164535:tid 164682] [client 14.173.98.54:43196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4kqDYN371eKRzcKeR_OAAAAJY"]
[Mon Jul 20 07:37:45.457471 2026] [security2:error] [pid 171532:tid 171690] [client 157.20.138.62:62363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kqUEhLvMuMRNpl00EZwAAASY"]
[Mon Jul 20 07:37:45.457590 2026] [security2:error] [pid 171532:tid 171690] [client 157.20.138.62:62363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kqUEhLvMuMRNpl00EZwAAASY"]
[Mon Jul 20 07:37:45.461272 2026] [security2:error] [pid 164535:tid 164706] [client 158.173.166.181:46513] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kqTYN371eKRzcKeR_XgAAAK4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:37:45.522618 2026] [security2:error] [pid 171532:tid 171733] [client 4.204.201.85:7152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xiugai.php"] [unique_id "al4kqUEhLvMuMRNpl00EdAAAAVE"]
[Mon Jul 20 07:37:45.522713 2026] [security2:error] [pid 171532:tid 171733] [client 4.204.201.85:7152] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xiugai.php"] [unique_id "al4kqUEhLvMuMRNpl00EdAAAAVE"]
[Mon Jul 20 07:37:45.647075 2026] [security2:error] [pid 171532:tid 171747] [client 14.225.17.146:62023] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4kqUEhLvMuMRNpl00EdQAAAV8"], referer: http://mourgroup.com/bc
[Mon Jul 20 07:37:45.675159 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:58824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/e.php"] [unique_id "al4kqUEhLvMuMRNpl00EhgAAATY"]
[Mon Jul 20 07:37:45.675249 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:58824] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/e.php"] [unique_id "al4kqUEhLvMuMRNpl00EhgAAATY"]
[Mon Jul 20 07:37:45.811995 2026] [security2:error] [pid 164535:tid 164691] [client 4.204.201.85:49632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/for.php"] [unique_id "al4kqTYN371eKRzcKeR_YwAAAJ8"]
[Mon Jul 20 07:37:45.812132 2026] [security2:error] [pid 164535:tid 164691] [client 4.204.201.85:49632] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/for.php"] [unique_id "al4kqTYN371eKRzcKeR_YwAAAJ8"]
[Mon Jul 20 07:37:45.934573 2026] [security2:error] [pid 171532:tid 171720] [client 4.204.201.85:58809] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/ssh3ll.php"] [unique_id "al4kqUEhLvMuMRNpl00EmQAAAUQ"]
[Mon Jul 20 07:37:45.934679 2026] [security2:error] [pid 171532:tid 171720] [client 4.204.201.85:58809] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/ssh3ll.php"] [unique_id "al4kqUEhLvMuMRNpl00EmQAAAUQ"]
[Mon Jul 20 07:37:45.979591 2026] [security2:error] [pid 171532:tid 171692] [client 14.225.17.146:50625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4kqUEhLvMuMRNpl00ElAAAASg"], referer: https://savilerowtravel.com/bc
[Mon Jul 20 07:37:46.065190 2026] [security2:error] [pid 171532:tid 171754] [client 4.204.201.85:49557] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/adminner.php"] [unique_id "al4kqkEhLvMuMRNpl00EpQAAAWY"]
[Mon Jul 20 07:37:46.065292 2026] [security2:error] [pid 171532:tid 171754] [client 4.204.201.85:49557] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/adminner.php"] [unique_id "al4kqkEhLvMuMRNpl00EpQAAAWY"]
[Mon Jul 20 07:37:46.197840 2026] [security2:error] [pid 164535:tid 164743] [client 4.204.201.85:49623] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/82.php"] [unique_id "al4kqjYN371eKRzcKeR_ZgAAANM"]
[Mon Jul 20 07:37:46.197950 2026] [security2:error] [pid 164535:tid 164743] [client 4.204.201.85:49623] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/82.php"] [unique_id "al4kqjYN371eKRzcKeR_ZgAAANM"]
[Mon Jul 20 07:37:46.258919 2026] [security2:error] [pid 171532:tid 171704] [client 57.141.18.45:31256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kpkEhLvMuMRNpl00DrAABNEY"]
[Mon Jul 20 07:37:46.326508 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:7111] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/kir.php"] [unique_id "al4kqkEhLvMuMRNpl00EugAAAUY"]
[Mon Jul 20 07:37:46.326615 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:7111] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/kir.php"] [unique_id "al4kqkEhLvMuMRNpl00EugAAAUY"]
[Mon Jul 20 07:37:46.419142 2026] [security2:error] [pid 171532:tid 171695] [client 142.111.152.234:31479] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kqkEhLvMuMRNpl00EsgAAASs"]
[Mon Jul 20 07:37:46.444987 2026] [security2:error] [pid 164535:tid 164711] [client 14.182.195.220:52827] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4kqjYN371eKRzcKeR_bAAAALM"]
[Mon Jul 20 07:37:46.446007 2026] [security2:error] [pid 164535:tid 164697] [client 149.0.16.108:49283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kqjYN371eKRzcKeR_bQAAAKU"]
[Mon Jul 20 07:37:46.446126 2026] [security2:error] [pid 164535:tid 164697] [client 149.0.16.108:49283] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kqjYN371eKRzcKeR_bQAAAKU"]
[Mon Jul 20 07:37:46.486865 2026] [security2:error] [pid 171532:tid 171690] [client 116.193.128.26:53062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kqkEhLvMuMRNpl00ExgAAASY"]
[Mon Jul 20 07:37:46.487019 2026] [security2:error] [pid 171532:tid 171690] [client 116.193.128.26:53062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kqkEhLvMuMRNpl00ExgAAASY"]
[Mon Jul 20 07:37:46.503955 2026] [security2:error] [pid 171532:tid 171682] [client 57.141.18.104:33822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kpkEhLvMuMRNpl00DugABHks"]
[Mon Jul 20 07:37:46.521405 2026] [security2:error] [pid 171532:tid 171777] [client 4.204.201.85:49536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/up4.php"] [unique_id "al4kqkEhLvMuMRNpl00EywAAAXw"]
[Mon Jul 20 07:37:46.521488 2026] [security2:error] [pid 171532:tid 171777] [client 4.204.201.85:49536] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/up4.php"] [unique_id "al4kqkEhLvMuMRNpl00EywAAAXw"]
[Mon Jul 20 07:37:46.675890 2026] [security2:error] [pid 164535:tid 164575] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4kqjYN371eKRzcKeR_cwAAoic"]
[Mon Jul 20 07:37:46.693972 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:49562] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/xhar.php"] [unique_id "al4kqkEhLvMuMRNpl00E1QAAATY"]
[Mon Jul 20 07:37:46.694047 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:49562] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/xhar.php"] [unique_id "al4kqkEhLvMuMRNpl00E1QAAATY"]
[Mon Jul 20 07:37:46.743275 2026] [security2:error] [pid 171532:tid 171754] [client 36.93.152.155:54249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kqkEhLvMuMRNpl00E1wAAAWY"]
[Mon Jul 20 07:37:46.743366 2026] [security2:error] [pid 171532:tid 171754] [client 36.93.152.155:54249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kqkEhLvMuMRNpl00E1wAAAWY"]
[Mon Jul 20 07:37:46.826773 2026] [security2:error] [pid 164535:tid 164686] [client 4.204.201.85:58813] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/file1221.php"] [unique_id "al4kqjYN371eKRzcKeR_dgAAAJo"]
[Mon Jul 20 07:37:46.826881 2026] [security2:error] [pid 164535:tid 164686] [client 4.204.201.85:58813] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/file1221.php"] [unique_id "al4kqjYN371eKRzcKeR_dgAAAJo"]
[Mon Jul 20 07:37:46.833081 2026] [security2:error] [pid 164535:tid 164702] [client 57.141.18.19:47338] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kpjYN371eKRzcKeR_CwAAqmc"]
[Mon Jul 20 07:37:46.895238 2026] [security2:error] [pid 164535:tid 164748] [client 154.192.123.127:18621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kqjYN371eKRzcKeR_dwAAANg"]
[Mon Jul 20 07:37:46.895382 2026] [security2:error] [pid 164535:tid 164748] [client 154.192.123.127:18621] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kqjYN371eKRzcKeR_dwAAANg"]
[Mon Jul 20 07:37:46.954125 2026] [security2:error] [pid 171532:tid 171695] [client 4.204.201.85:58873] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/inx.php"] [unique_id "al4kqkEhLvMuMRNpl00E4QAAASs"]
[Mon Jul 20 07:37:46.954229 2026] [security2:error] [pid 171532:tid 171695] [client 4.204.201.85:58873] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/inx.php"] [unique_id "al4kqkEhLvMuMRNpl00E4QAAASs"]
[Mon Jul 20 07:37:47.024376 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:52884] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4kqzYN371eKRzcKeR_eQAAAOA"]
[Mon Jul 20 07:37:47.024476 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:52884] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/plugins/hellopress/wp_filemanager.php"] [unique_id "al4kqzYN371eKRzcKeR_eQAAAOA"]
[Mon Jul 20 07:37:47.067528 2026] [security2:error] [pid 164535:tid 164750] [client 57.141.18.91:32980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kpzYN371eKRzcKeR_FQAA2gA"]
[Mon Jul 20 07:37:47.071812 2026] [security2:error] [pid 164535:tid 164632] [remote 47.86.33.52:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4kqzYN371eKRzcKeR_fgAA9WA"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 07:37:47.084350 2026] [security2:error] [pid 164535:tid 164678] [client 4.204.201.85:49563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/qqqa.php"] [unique_id "al4kqzYN371eKRzcKeR_gAAAAJI"]
[Mon Jul 20 07:37:47.084446 2026] [security2:error] [pid 164535:tid 164678] [client 4.204.201.85:49563] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/qqqa.php"] [unique_id "al4kqzYN371eKRzcKeR_gAAAAJI"]
[Mon Jul 20 07:37:47.224816 2026] [security2:error] [pid 171532:tid 171696] [client 20.84.101.167:32918] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.228"] [uri "/"] [unique_id "al4kq0EhLvMuMRNpl00E7QAAASw"]
[Mon Jul 20 07:37:47.227961 2026] [security2:error] [pid 171532:tid 171752] [client 4.204.201.85:49560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/gk.php"] [unique_id "al4kq0EhLvMuMRNpl00E7wAAAWQ"]
[Mon Jul 20 07:37:47.228070 2026] [security2:error] [pid 171532:tid 171752] [client 4.204.201.85:49560] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/gk.php"] [unique_id "al4kq0EhLvMuMRNpl00E7wAAAWQ"]
[Mon Jul 20 07:37:47.257654 2026] [security2:error] [pid 171532:tid 171686] [client 77.110.127.138:52876] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/crochet-border/feed/"] [unique_id "al4kq0EhLvMuMRNpl00E8gAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:47.269392 2026] [security2:error] [pid 171532:tid 171688] [client 4.204.201.85:54284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4kq0EhLvMuMRNpl00E9AAAASQ"]
[Mon Jul 20 07:37:47.269523 2026] [security2:error] [pid 171532:tid 171688] [client 4.204.201.85:54284] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/this_is_a_new_hello_world.php"] [unique_id "al4kq0EhLvMuMRNpl00E9AAAASQ"]
[Mon Jul 20 07:37:47.278701 2026] [security2:error] [pid 171532:tid 171680] [client 20.84.101.167:33678] ModSecurity: Access denied with code 406 (phase 2). Match of "rx [.](png|jpeg|jpg|tiff|bmp|gif|webp|heif|svg|raw|ico|ppm|pgm|pbm|exr|nef|dng|cr2|orf|arw|pef|sr2|raf|kdc|indd|ai|eps|pdf|psd|tga|hdr|j2k|jpf|jp2|pspimage|cut|icns|webm|bpg|avif|heic|fpx|hdri|hdp|yuv|sgi|xpm|svgz)$" against "REQUEST_FILENAME" required. [file "/opt/mod_security/hg_rules.conf"] [line "842"] [id "900095"] [msg "Bad UA :: Fake Mozilla Agent"] [hostname "50.116.65.228"] [uri "/"] [unique_id "al4kq0EhLvMuMRNpl00E9gAAARw"]
[Mon Jul 20 07:37:47.369566 2026] [security2:error] [pid 171532:tid 171683] [client 4.204.201.85:49538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/005.php"] [unique_id "al4kq0EhLvMuMRNpl00FAAAAAR8"]
[Mon Jul 20 07:37:47.369691 2026] [security2:error] [pid 171532:tid 171683] [client 4.204.201.85:49538] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/005.php"] [unique_id "al4kq0EhLvMuMRNpl00FAAAAAR8"]
[Mon Jul 20 07:37:47.420393 2026] [security2:error] [pid 171532:tid 171769] [client 77.110.127.138:52877] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/colour-work/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4kq0EhLvMuMRNpl00FAQAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:47.511287 2026] [security2:error] [pid 171532:tid 171708] [client 4.204.201.85:49621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/norn.php"] [unique_id "al4kq0EhLvMuMRNpl00FBQAAATg"]
[Mon Jul 20 07:37:47.511399 2026] [security2:error] [pid 171532:tid 171708] [client 4.204.201.85:49621] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/norn.php"] [unique_id "al4kq0EhLvMuMRNpl00FBQAAATg"]
[Mon Jul 20 07:37:47.520019 2026] [security2:error] [pid 164535:tid 164682] [client 4.204.201.85:54350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/x.php"] [unique_id "al4kqzYN371eKRzcKeR_kQAAAJY"]
[Mon Jul 20 07:37:47.520110 2026] [security2:error] [pid 164535:tid 164682] [client 4.204.201.85:54350] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/x.php"] [unique_id "al4kqzYN371eKRzcKeR_kQAAAJY"]
[Mon Jul 20 07:37:47.603699 2026] [security2:error] [pid 171532:tid 171747] [client 103.106.165.44:59188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kq0EhLvMuMRNpl00FEAAAAV8"]
[Mon Jul 20 07:37:47.603807 2026] [security2:error] [pid 171532:tid 171747] [client 103.106.165.44:59188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kq0EhLvMuMRNpl00FEAAAAV8"]
[Mon Jul 20 07:37:47.666538 2026] [security2:error] [pid 164535:tid 164775] [client 4.204.201.85:7105] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "olearyplumbingllc.com"] [uri "/dmin.php"] [unique_id "al4kqzYN371eKRzcKeR_mQAAAPM"]
[Mon Jul 20 07:37:47.666653 2026] [security2:error] [pid 164535:tid 164775] [client 4.204.201.85:7105] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "olearyplumbingllc.com"] [uri "/dmin.php"] [unique_id "al4kqzYN371eKRzcKeR_mQAAAPM"]
[Mon Jul 20 07:37:47.740068 2026] [security2:error] [pid 164535:tid 164772] [client 4.204.201.85:54340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/mgrr.php"] [unique_id "al4kqzYN371eKRzcKeR_nAAAAPA"]
[Mon Jul 20 07:37:47.740215 2026] [security2:error] [pid 164535:tid 164772] [client 4.204.201.85:54340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/mgrr.php"] [unique_id "al4kqzYN371eKRzcKeR_nAAAAPA"]
[Mon Jul 20 07:37:47.997258 2026] [security2:error] [pid 164535:tid 164672] [client 4.204.201.85:52951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/stdin.php"] [unique_id "al4kqzYN371eKRzcKeR_ogAAAIw"]
[Mon Jul 20 07:37:47.997335 2026] [security2:error] [pid 164535:tid 164672] [client 4.204.201.85:52951] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/stdin.php"] [unique_id "al4kqzYN371eKRzcKeR_ogAAAIw"]
[Mon Jul 20 07:37:48.208673 2026] [security2:error] [pid 171532:tid 171783] [client 4.204.201.85:52898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/BDKR28.php"] [unique_id "al4krEEhLvMuMRNpl00FMgAAAYI"]
[Mon Jul 20 07:37:48.208801 2026] [security2:error] [pid 171532:tid 171783] [client 4.204.201.85:52898] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/BDKR28.php"] [unique_id "al4krEEhLvMuMRNpl00FMgAAAYI"]
[Mon Jul 20 07:37:48.405853 2026] [security2:error] [pid 164535:tid 164768] [client 143.244.57.88:56578] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "seidemannlab.site"] [uri "/wp-includes/"] [unique_id "al4krDYN371eKRzcKeR_rQAAAOw"]
[Mon Jul 20 07:37:48.730809 2026] [security2:error] [pid 171532:tid 171711] [client 4.204.201.85:54279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/001.php"] [unique_id "al4krEEhLvMuMRNpl00FTgAAATs"]
[Mon Jul 20 07:37:48.730964 2026] [security2:error] [pid 171532:tid 171711] [client 4.204.201.85:54279] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/001.php"] [unique_id "al4krEEhLvMuMRNpl00FTgAAATs"]
[Mon Jul 20 07:37:48.808611 2026] [security2:error] [pid 171532:tid 171650] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4krEEhLvMuMRNpl00FUAABP3U"]
[Mon Jul 20 07:37:49.211165 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:54294] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/dZ3wP5.php"] [unique_id "al4krUEhLvMuMRNpl00FZwAAAUY"]
[Mon Jul 20 07:37:49.211273 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:54294] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/dZ3wP5.php"] [unique_id "al4krUEhLvMuMRNpl00FZwAAAUY"]
[Mon Jul 20 07:37:49.417757 2026] [security2:error] [pid 164535:tid 164739] [client 4.204.201.85:52880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/yup.php"] [unique_id "al4krTYN371eKRzcKeR_ugAAAM8"]
[Mon Jul 20 07:37:49.417850 2026] [security2:error] [pid 164535:tid 164739] [client 4.204.201.85:52880] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/yup.php"] [unique_id "al4krTYN371eKRzcKeR_ugAAAM8"]
[Mon Jul 20 07:37:49.546687 2026] [security2:error] [pid 164535:tid 164769] [client 14.225.17.146:54920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4kqzYN371eKRzcKeR_oAAAAO0"], referer: http://tacticaltreeoperations.com/bc
[Mon Jul 20 07:37:49.577940 2026] [security2:error] [pid 171532:tid 171777] [client 4.204.201.85:52976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/X.php"] [unique_id "al4krUEhLvMuMRNpl00FewAAAXw"]
[Mon Jul 20 07:37:49.578045 2026] [security2:error] [pid 171532:tid 171777] [client 4.204.201.85:52976] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/X.php"] [unique_id "al4krUEhLvMuMRNpl00FewAAAXw"]
[Mon Jul 20 07:37:49.691532 2026] [authz_core:error] [pid 171532:tid 171747] [client 188.166.209.66:50437] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Mon Jul 20 07:37:49.885209 2026] [security2:error] [pid 171532:tid 171713] [client 4.204.201.85:52916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/1polka.php"] [unique_id "al4krUEhLvMuMRNpl00FlAAAAT0"]
[Mon Jul 20 07:37:49.885311 2026] [security2:error] [pid 171532:tid 171713] [client 4.204.201.85:52916] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/1polka.php"] [unique_id "al4krUEhLvMuMRNpl00FlAAAAT0"]
[Mon Jul 20 07:37:50.090995 2026] [security2:error] [pid 164535:tid 164675] [client 154.192.233.184:61954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4krjYN371eKRzcKeR_ygAAAI8"]
[Mon Jul 20 07:37:50.091135 2026] [security2:error] [pid 164535:tid 164675] [client 154.192.233.184:61954] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4krjYN371eKRzcKeR_ygAAAI8"]
[Mon Jul 20 07:37:50.126869 2026] [security2:error] [pid 171532:tid 171679] [client 77.110.127.138:52870] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/crochet-border/feed/"] [unique_id "al4krkEhLvMuMRNpl00FogAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:50.215528 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:52954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/gec.php"] [unique_id "al4krkEhLvMuMRNpl00FqgAAAVk"]
[Mon Jul 20 07:37:50.215632 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:52954] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/gec.php"] [unique_id "al4krkEhLvMuMRNpl00FqgAAAVk"]
[Mon Jul 20 07:37:50.257291 2026] [security2:error] [pid 171532:tid 171715] [client 103.176.215.66:64369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4krkEhLvMuMRNpl00FrgAAAT8"]
[Mon Jul 20 07:37:50.257458 2026] [security2:error] [pid 171532:tid 171715] [client 103.176.215.66:64369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4krkEhLvMuMRNpl00FrgAAAT8"]
[Mon Jul 20 07:37:50.367159 2026] [security2:error] [pid 164535:tid 164775] [client 13.232.231.177:29198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4krjYN371eKRzcKeR_zQAAAPM"]
[Mon Jul 20 07:37:50.367264 2026] [security2:error] [pid 164535:tid 164775] [client 13.232.231.177:29198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4krjYN371eKRzcKeR_zQAAAPM"]
[Mon Jul 20 07:37:50.519482 2026] [security2:error] [pid 171532:tid 171756] [client 57.141.18.14:56814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kqkEhLvMuMRNpl00E0wABaD0"]
[Mon Jul 20 07:37:50.664758 2026] [security2:error] [pid 164535:tid 164567] [remote 182.77.62.24:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/wp-login.php"] [unique_id "al4krjYN371eKRzcKeR_1wAAjB8"], referer: https://innovativecleaningsvs.com/wp-login.php
[Mon Jul 20 07:37:50.835776 2026] [security2:error] [pid 171532:tid 171699] [client 4.204.201.85:54355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/sky.php"] [unique_id "al4krkEhLvMuMRNpl00FzgAAAS8"]
[Mon Jul 20 07:37:50.835879 2026] [security2:error] [pid 171532:tid 171699] [client 4.204.201.85:54355] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/sky.php"] [unique_id "al4krkEhLvMuMRNpl00FzgAAAS8"]
[Mon Jul 20 07:37:50.870020 2026] [security2:error] [pid 171532:tid 171781] [client 136.158.60.21:2132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4krkEhLvMuMRNpl00F0AAAAYA"]
[Mon Jul 20 07:37:50.870149 2026] [security2:error] [pid 171532:tid 171781] [client 136.158.60.21:2132] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4krkEhLvMuMRNpl00F0AAAAYA"]
[Mon Jul 20 07:37:50.904117 2026] [security2:error] [pid 171532:tid 171743] [client 191.202.66.27:55975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4krkEhLvMuMRNpl00F1AAAAVs"]
[Mon Jul 20 07:37:50.904205 2026] [security2:error] [pid 171532:tid 171743] [client 191.202.66.27:55975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4krkEhLvMuMRNpl00F1AAAAVs"]
[Mon Jul 20 07:37:50.983804 2026] [security2:error] [pid 171532:tid 171666] [client 57.141.18.116:40608] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kq0EhLvMuMRNpl00E6QABDgI"]
[Mon Jul 20 07:37:51.058409 2026] [security2:error] [pid 171532:tid 171732] [client 4.204.201.85:54278] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/fffm.php"] [unique_id "al4kr0EhLvMuMRNpl00F3QAAAVA"]
[Mon Jul 20 07:37:51.058547 2026] [security2:error] [pid 171532:tid 171732] [client 4.204.201.85:54278] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/fffm.php"] [unique_id "al4kr0EhLvMuMRNpl00F3QAAAVA"]
[Mon Jul 20 07:37:51.172001 2026] [security2:error] [pid 164535:tid 164688] [client 57.141.18.52:20368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kqzYN371eKRzcKeR_igAAnHU"]
[Mon Jul 20 07:37:51.186298 2026] [security2:error] [pid 171532:tid 171663] [client 104.207.53.59:62199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kr0EhLvMuMRNpl00F5QAAAQs"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:51.194311 2026] [security2:error] [pid 164535:tid 164748] [client 34.73.105.183:11872] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "stopfeedingthemonster.com"] [uri "/"] [unique_id "al4krzYN371eKRzcKeR_5QAAANg"]
[Mon Jul 20 07:37:51.219560 2026] [security2:error] [pid 171532:tid 171680] [client 4.204.201.85:52876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/sixxis.php"] [unique_id "al4kr0EhLvMuMRNpl00F6gAAARw"]
[Mon Jul 20 07:37:51.219659 2026] [security2:error] [pid 171532:tid 171680] [client 4.204.201.85:52876] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/sixxis.php"] [unique_id "al4kr0EhLvMuMRNpl00F6gAAARw"]
[Mon Jul 20 07:37:51.368442 2026] [security2:error] [pid 171532:tid 171722] [client 34.73.105.183:28060] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=///"] [hostname "stopfeedingthemonster.com"] [uri "/wp-json/batch/v1"] [unique_id "al4kr0EhLvMuMRNpl00F8QAAAUY"]
[Mon Jul 20 07:37:51.423899 2026] [security2:error] [pid 171532:tid 171669] [client 34.73.105.183:28060] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "stopfeedingthemonster.com"] [uri "/"] [unique_id "al4kr0EhLvMuMRNpl00F9wAAARE"]
[Mon Jul 20 07:37:51.434230 2026] [security2:error] [pid 164535:tid 164697] [client 103.139.191.61:58624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4krzYN371eKRzcKeR_7AAAAKU"]
[Mon Jul 20 07:37:51.434334 2026] [security2:error] [pid 164535:tid 164697] [client 103.139.191.61:58624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4krzYN371eKRzcKeR_7AAAAKU"]
[Mon Jul 20 07:37:51.556444 2026] [security2:error] [pid 171532:tid 171731] [client 172.120.26.125:64538] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4kr0EhLvMuMRNpl00F8AABTyM"]
[Mon Jul 20 07:37:51.579643 2026] [security2:error] [pid 171532:tid 171605] [remote 84.247.172.23:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4kr0EhLvMuMRNpl00GAAABVkg"]
[Mon Jul 20 07:37:51.794794 2026] [security2:error] [pid 171532:tid 171776] [client 179.127.84.238:59814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kr0EhLvMuMRNpl00GCwAAAXs"]
[Mon Jul 20 07:37:51.794886 2026] [security2:error] [pid 171532:tid 171776] [client 179.127.84.238:59814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kr0EhLvMuMRNpl00GCwAAAXs"]
[Mon Jul 20 07:37:51.946573 2026] [security2:error] [pid 171532:tid 171692] [client 4.204.201.85:52965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/yj09.php"] [unique_id "al4kr0EhLvMuMRNpl00GHAAAASg"]
[Mon Jul 20 07:37:51.946685 2026] [security2:error] [pid 171532:tid 171692] [client 4.204.201.85:52965] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/yj09.php"] [unique_id "al4kr0EhLvMuMRNpl00GHAAAASg"]
[Mon Jul 20 07:37:52.043247 2026] [security2:error] [pid 171532:tid 171760] [client 57.141.18.123:21580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4krEEhLvMuMRNpl00FJAABbGA"]
[Mon Jul 20 07:37:52.169134 2026] [security2:error] [pid 171532:tid 171755] [client 70.115.45.82:0] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4kr0EhLvMuMRNpl00GEwAAAWc"]
[Mon Jul 20 07:37:52.171986 2026] [security2:error] [pid 164535:tid 164707] [client 70.115.45.82:44156] ModSecurity: Warning. Matched phrase "Nutch" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "omenana.com"] [uri "/category/editorial/"] [unique_id "al4krzYN371eKRzcKeSAAQAAAK8"]
[Mon Jul 20 07:37:52.178831 2026] [security2:error] [pid 171532:tid 171726] [client 57.141.18.71:38970] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4krEEhLvMuMRNpl00FKwABSlE"]
[Mon Jul 20 07:37:52.203834 2026] [security2:error] [pid 164535:tid 164670] [client 104.207.60.184:11869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ksDYN371eKRzcKeSADQAAAIo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:52.226025 2026] [security2:error] [pid 171532:tid 171694] [client 4.204.201.85:54339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/f900.php"] [unique_id "al4ksEEhLvMuMRNpl00GLAAAASo"]
[Mon Jul 20 07:37:52.226127 2026] [security2:error] [pid 171532:tid 171694] [client 4.204.201.85:54339] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/f900.php"] [unique_id "al4ksEEhLvMuMRNpl00GLAAAASo"]
[Mon Jul 20 07:37:52.452440 2026] [security2:error] [pid 164535:tid 164694] [client 4.204.201.85:52972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ups.php"] [unique_id "al4ksDYN371eKRzcKeSAEwAAAKI"]
[Mon Jul 20 07:37:52.452545 2026] [security2:error] [pid 164535:tid 164694] [client 4.204.201.85:52972] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ups.php"] [unique_id "al4ksDYN371eKRzcKeSAEwAAAKI"]
[Mon Jul 20 07:37:52.471612 2026] [security2:error] [pid 164535:tid 164772] [client 14.225.17.146:50341] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4ksDYN371eKRzcKeSABgAAAPA"]
[Mon Jul 20 07:37:52.590235 2026] [security2:error] [pid 171532:tid 171769] [client 45.3.42.71:33737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4ksEEhLvMuMRNpl00GPAAAAXU"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:52.681480 2026] [security2:error] [pid 171532:tid 171673] [client 143.44.185.218:4032] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ksEEhLvMuMRNpl00GQAAAARU"]
[Mon Jul 20 07:37:52.684533 2026] [security2:error] [pid 171532:tid 171663] [client 4.204.201.85:52939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/k.php"] [unique_id "al4ksEEhLvMuMRNpl00GQQAAAQs"]
[Mon Jul 20 07:37:52.684559 2026] [security2:error] [pid 171532:tid 171673] [client 143.44.185.218:4032] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4ksEEhLvMuMRNpl00GQAAAARU"]
[Mon Jul 20 07:37:52.684622 2026] [security2:error] [pid 171532:tid 171663] [client 4.204.201.85:52939] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/k.php"] [unique_id "al4ksEEhLvMuMRNpl00GQQAAAQs"]
[Mon Jul 20 07:37:52.823809 2026] [security2:error] [pid 164535:tid 164748] [client 104.207.61.112:30801] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 112.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ksDYN371eKRzcKeSAHAAAANg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:37:52.909763 2026] [security2:error] [pid 171532:tid 171696] [client 57.141.18.119:62238] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4krEEhLvMuMRNpl00FTwABLGk"]
[Mon Jul 20 07:37:52.981946 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:54307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/k2.php"] [unique_id "al4ksEEhLvMuMRNpl00GTgAAATY"]
[Mon Jul 20 07:37:52.982034 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:54307] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/k2.php"] [unique_id "al4ksEEhLvMuMRNpl00GTgAAATY"]
[Mon Jul 20 07:37:53.114681 2026] [security2:error] [pid 171532:tid 171754] [client 14.225.17.146:50150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4ksEEhLvMuMRNpl00GTQAAAWY"], referer: http://colinkeyphotography.com/bc
[Mon Jul 20 07:37:53.169448 2026] [security2:error] [pid 171532:tid 171720] [client 4.204.201.85:54374] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/w.php"] [unique_id "al4ksUEhLvMuMRNpl00GYwAAAUQ"]
[Mon Jul 20 07:37:53.169548 2026] [security2:error] [pid 171532:tid 171720] [client 4.204.201.85:54374] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/w.php"] [unique_id "al4ksUEhLvMuMRNpl00GYwAAAUQ"]
[Mon Jul 20 07:37:53.256952 2026] [security2:error] [pid 164535:tid 164710] [client 57.141.18.47:58468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4krTYN371eKRzcKeR_twAAsjU"]
[Mon Jul 20 07:37:53.496974 2026] [security2:error] [pid 164535:tid 164619] [remote 72.167.132.114:54108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ksTYN371eKRzcKeSAKQAAwVM"]
[Mon Jul 20 07:37:53.594311 2026] [security2:error] [pid 171532:tid 171775] [client 77.110.127.138:52885] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/crochet-border/feed/"] [unique_id "al4ksUEhLvMuMRNpl00GdQAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:53.621123 2026] [security2:error] [pid 164535:tid 164771] [client 4.204.201.85:54381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/fpwch.php"] [unique_id "al4ksTYN371eKRzcKeSALgAAAO8"]
[Mon Jul 20 07:37:53.621248 2026] [security2:error] [pid 164535:tid 164771] [client 4.204.201.85:54381] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/fpwch.php"] [unique_id "al4ksTYN371eKRzcKeSALgAAAO8"]
[Mon Jul 20 07:37:53.660142 2026] [security2:error] [pid 171532:tid 171756] [client 57.141.18.65:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4ksUEhLvMuMRNpl00GcQAAAWg"]
[Mon Jul 20 07:37:53.730203 2026] [security2:error] [pid 164535:tid 164604] [remote 72.167.132.114:54108] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4ksTYN371eKRzcKeSAMAAA8UQ"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 07:37:53.738375 2026] [security2:error] [pid 171532:tid 171543] [remote 84.247.172.23:54118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4ksUEhLvMuMRNpl00GeAABcgo"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 07:37:53.913100 2026] [security2:error] [pid 164535:tid 164704] [client 4.204.201.85:52908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/w2025.php"] [unique_id "al4ksTYN371eKRzcKeSAOgAAAKw"]
[Mon Jul 20 07:37:53.913215 2026] [security2:error] [pid 164535:tid 164704] [client 4.204.201.85:52908] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/w2025.php"] [unique_id "al4ksTYN371eKRzcKeSAOgAAAKw"]
[Mon Jul 20 07:37:53.974144 2026] [security2:error] [pid 164535:tid 164671] [client 112.86.225.140:48354] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.savilerowtravel.com"] [uri "/"] [unique_id "al4ksTYN371eKRzcKeSAOwAAAIs"]
[Mon Jul 20 07:37:53.974565 2026] [security2:error] [pid 164535:tid 164671] [client 112.86.225.140:48354] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.savilerowtravel.com"] [uri "/"] [unique_id "al4ksTYN371eKRzcKeSAOwAAAIs"]
[Mon Jul 20 07:37:53.994044 2026] [security2:error] [pid 164535:tid 164780] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ksTYN371eKRzcKeSAMwAAAPg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:54.013261 2026] [security2:error] [pid 164535:tid 164718] [client 104.207.53.111:42723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4ksTYN371eKRzcKeSAPAAAALo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:37:54.154538 2026] [security2:error] [pid 164535:tid 164755] [client 4.204.201.85:52984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/FWAZ.php"] [unique_id "al4ksjYN371eKRzcKeSAQAAAAN8"]
[Mon Jul 20 07:37:54.154615 2026] [security2:error] [pid 164535:tid 164755] [client 4.204.201.85:52984] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/FWAZ.php"] [unique_id "al4ksjYN371eKRzcKeSAQAAAAN8"]
[Mon Jul 20 07:37:54.702419 2026] [security2:error] [pid 171532:tid 171663] [client 4.204.201.85:52959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/qterm.php"] [unique_id "al4kskEhLvMuMRNpl00GowAAAQs"]
[Mon Jul 20 07:37:54.702532 2026] [security2:error] [pid 171532:tid 171663] [client 4.204.201.85:52959] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/qterm.php"] [unique_id "al4kskEhLvMuMRNpl00GowAAAQs"]
[Mon Jul 20 07:37:54.968274 2026] [security2:error] [pid 171532:tid 171692] [client 49.47.218.174:60354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kskEhLvMuMRNpl00GqwAAASg"]
[Mon Jul 20 07:37:54.968675 2026] [security2:error] [pid 171532:tid 171692] [client 49.47.218.174:60354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kskEhLvMuMRNpl00GqwAAASg"]
[Mon Jul 20 07:37:54.988969 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:52907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/blurbs.php"] [unique_id "al4kskEhLvMuMRNpl00GrQAAAUY"]
[Mon Jul 20 07:37:54.989045 2026] [security2:error] [pid 171532:tid 171722] [client 4.204.201.85:52907] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/blurbs.php"] [unique_id "al4kskEhLvMuMRNpl00GrQAAAUY"]
[Mon Jul 20 07:37:55.127100 2026] [security2:error] [pid 171532:tid 171714] [client 4.204.201.85:54388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/v543.php"] [unique_id "al4ks0EhLvMuMRNpl00GvAAAAT4"]
[Mon Jul 20 07:37:55.127247 2026] [security2:error] [pid 171532:tid 171714] [client 4.204.201.85:54388] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/v543.php"] [unique_id "al4ks0EhLvMuMRNpl00GvAAAAT4"]
[Mon Jul 20 07:37:55.254959 2026] [security2:error] [pid 171532:tid 171717] [client 57.141.18.120:32182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kr0EhLvMuMRNpl00F5gABQRc"]
[Mon Jul 20 07:37:55.510060 2026] [security2:error] [pid 171532:tid 171789] [client 4.204.201.85:54312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/w3lls.php"] [unique_id "al4ks0EhLvMuMRNpl00G1QAAAYg"]
[Mon Jul 20 07:37:55.510168 2026] [security2:error] [pid 171532:tid 171789] [client 4.204.201.85:54312] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/w3lls.php"] [unique_id "al4ks0EhLvMuMRNpl00G1QAAAYg"]
[Mon Jul 20 07:37:55.802170 2026] [security2:error] [pid 171532:tid 171745] [client 50.116.65.227:14982] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ks0EhLvMuMRNpl00G8AAAAV0"]
[Mon Jul 20 07:37:55.811603 2026] [security2:error] [pid 171532:tid 171746] [client 50.116.65.227:14992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ks0EhLvMuMRNpl00G8QAAAV4"]
[Mon Jul 20 07:37:55.826056 2026] [security2:error] [pid 171532:tid 171678] [client 4.204.201.85:52868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-ws68.php"] [unique_id "al4ks0EhLvMuMRNpl00G8gAAARo"]
[Mon Jul 20 07:37:55.826146 2026] [security2:error] [pid 171532:tid 171678] [client 4.204.201.85:52868] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-ws68.php"] [unique_id "al4ks0EhLvMuMRNpl00G8gAAARo"]
[Mon Jul 20 07:37:55.898915 2026] [security2:error] [pid 164535:tid 164790] [client 89.238.167.150:52476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4kszYN371eKRzcKeSAaQAAAQI"]
[Mon Jul 20 07:37:55.899010 2026] [security2:error] [pid 164535:tid 164790] [client 89.238.167.150:52476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4kszYN371eKRzcKeSAaQAAAQI"]
[Mon Jul 20 07:37:56.055545 2026] [security2:error] [pid 171532:tid 171704] [client 4.204.201.85:52917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/xyn.php"] [unique_id "al4ktEEhLvMuMRNpl00HAQAAATQ"]
[Mon Jul 20 07:37:56.055631 2026] [security2:error] [pid 171532:tid 171704] [client 4.204.201.85:52917] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/xyn.php"] [unique_id "al4ktEEhLvMuMRNpl00HAQAAATQ"]
[Mon Jul 20 07:37:56.096998 2026] [security2:error] [pid 171532:tid 171728] [client 157.20.138.62:62907] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ktEEhLvMuMRNpl00HBAAAAUw"]
[Mon Jul 20 07:37:56.097110 2026] [security2:error] [pid 171532:tid 171728] [client 157.20.138.62:62907] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ktEEhLvMuMRNpl00HBAAAAUw"]
[Mon Jul 20 07:37:56.135823 2026] [security2:error] [pid 171532:tid 171686] [client 180.249.173.210:56678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ktEEhLvMuMRNpl00HBwAAASI"]
[Mon Jul 20 07:37:56.136150 2026] [security2:error] [pid 171532:tid 171686] [client 180.249.173.210:56678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4ktEEhLvMuMRNpl00HBwAAASI"]
[Mon Jul 20 07:37:56.200633 2026] [security2:error] [pid 171532:tid 171720] [client 4.204.201.85:54321] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/green3.php"] [unique_id "al4ktEEhLvMuMRNpl00HCwAAAUQ"]
[Mon Jul 20 07:37:56.200735 2026] [security2:error] [pid 171532:tid 171720] [client 4.204.201.85:54321] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/green3.php"] [unique_id "al4ktEEhLvMuMRNpl00HCwAAAUQ"]
[Mon Jul 20 07:37:56.253256 2026] [security2:error] [pid 171532:tid 171732] [client 57.141.18.103:54014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kr0EhLvMuMRNpl00GFwABUEs"]
[Mon Jul 20 07:37:56.307234 2026] [security2:error] [pid 171532:tid 171594] [remote 152.228.213.32:42158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4ktEEhLvMuMRNpl00HDQABgT0"]
[Mon Jul 20 07:37:56.471086 2026] [security2:error] [pid 164535:tid 164729] [client 4.204.201.85:54334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ccc.php"] [unique_id "al4ktDYN371eKRzcKeSAcAAAAMU"]
[Mon Jul 20 07:37:56.471188 2026] [security2:error] [pid 164535:tid 164729] [client 4.204.201.85:54334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ccc.php"] [unique_id "al4ktDYN371eKRzcKeSAcAAAAMU"]
[Mon Jul 20 07:37:56.512711 2026] [security2:error] [pid 171532:tid 171572] [remote 152.228.213.32:42158] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4ktEEhLvMuMRNpl00HHgABbCc"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 07:37:56.612982 2026] [security2:error] [pid 171532:tid 171689] [client 74.7.227.179:44812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4ktEEhLvMuMRNpl00HGgABJXI"], referer: https://tejasenvironmental.com/p=231224
[Mon Jul 20 07:37:56.618559 2026] [security2:error] [pid 171532:tid 171711] [client 14.225.17.146:52122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4ktEEhLvMuMRNpl00HDwAAATs"], referer: http://nwcarvingacademy.com/bc
[Mon Jul 20 07:37:56.654992 2026] [security2:error] [pid 171532:tid 171701] [client 14.225.17.146:52071] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4ktEEhLvMuMRNpl00HHQAAATE"], referer: http://elitetax-mi.com/bc
[Mon Jul 20 07:37:56.696539 2026] [security2:error] [pid 164535:tid 164727] [client 57.141.18.60:45692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ksDYN371eKRzcKeSADAAAw3M"]
[Mon Jul 20 07:37:56.728269 2026] [security2:error] [pid 171532:tid 171672] [client 158.173.89.95:23795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ktEEhLvMuMRNpl00HLgAAARQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:37:56.738215 2026] [security2:error] [pid 171532:tid 171721] [client 57.141.18.20:38358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ksEEhLvMuMRNpl00GKwABRR8"]
[Mon Jul 20 07:37:56.768355 2026] [security2:error] [pid 164535:tid 164670] [client 4.204.201.85:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/get.php"] [unique_id "al4ktDYN371eKRzcKeSAfAAAAIo"]
[Mon Jul 20 07:37:56.768462 2026] [security2:error] [pid 164535:tid 164670] [client 4.204.201.85:54393] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/get.php"] [unique_id "al4ktDYN371eKRzcKeSAfAAAAIo"]
[Mon Jul 20 07:37:56.874144 2026] [security2:error] [pid 171532:tid 171789] [client 142.111.152.60:37807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.152.111.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ktEEhLvMuMRNpl00HMQAAAYg"]
[Mon Jul 20 07:37:56.874246 2026] [security2:error] [pid 171532:tid 171789] [client 142.111.152.60:37807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4ktEEhLvMuMRNpl00HMQAAAYg"]
[Mon Jul 20 07:37:56.950867 2026] [security2:error] [pid 171532:tid 171743] [client 57.141.18.90:38024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ksEEhLvMuMRNpl00GNAABWys"]
[Mon Jul 20 07:37:56.967286 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:52933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/images.php"] [unique_id "al4ktEEhLvMuMRNpl00HQgAAAWI"]
[Mon Jul 20 07:37:56.967370 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:52933] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/images.php"] [unique_id "al4ktEEhLvMuMRNpl00HQgAAAWI"]
[Mon Jul 20 07:37:57.116251 2026] [security2:error] [pid 171532:tid 171765] [client 149.0.16.108:49874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ktUEhLvMuMRNpl00HTgAAAXE"]
[Mon Jul 20 07:37:57.116790 2026] [security2:error] [pid 171532:tid 171765] [client 149.0.16.108:49874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ktUEhLvMuMRNpl00HTgAAAXE"]
[Mon Jul 20 07:37:57.226197 2026] [security2:error] [pid 171532:tid 171699] [client 36.93.152.155:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ktUEhLvMuMRNpl00HVQAAAS8"]
[Mon Jul 20 07:37:57.226307 2026] [security2:error] [pid 171532:tid 171699] [client 36.93.152.155:54757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4ktUEhLvMuMRNpl00HVQAAAS8"]
[Mon Jul 20 07:37:57.438262 2026] [security2:error] [pid 164535:tid 164686] [client 116.193.128.26:53640] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4ktTYN371eKRzcKeSAiQAAAJo"]
[Mon Jul 20 07:37:57.438891 2026] [security2:error] [pid 164535:tid 164686] [client 116.193.128.26:53640] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4ktTYN371eKRzcKeSAiQAAAJo"]
[Mon Jul 20 07:37:57.502516 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/alls.php"] [unique_id "al4ktUEhLvMuMRNpl00HZwAAAWI"]
[Mon Jul 20 07:37:57.502666 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:54342] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/alls.php"] [unique_id "al4ktUEhLvMuMRNpl00HZwAAAWI"]
[Mon Jul 20 07:37:57.517222 2026] [security2:error] [pid 171532:tid 171774] [client 154.192.123.127:17083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ktUEhLvMuMRNpl00HaQAAAXk"]
[Mon Jul 20 07:37:57.517372 2026] [security2:error] [pid 171532:tid 171774] [client 154.192.123.127:17083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4ktUEhLvMuMRNpl00HaQAAAXk"]
[Mon Jul 20 07:37:57.586209 2026] [security2:error] [pid 171532:tid 171781] [client 57.141.18.29:21270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ksUEhLvMuMRNpl00GYgABgF4"]
[Mon Jul 20 07:37:57.587330 2026] [security2:error] [pid 171532:tid 171763] [client 57.141.18.82:21216] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ksUEhLvMuMRNpl00GWgABbyg"]
[Mon Jul 20 07:37:57.632635 2026] [security2:error] [pid 164535:tid 164735] [client 14.225.17.146:60386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4ktTYN371eKRzcKeSAiAAAAMs"]
[Mon Jul 20 07:37:57.668039 2026] [security2:error] [pid 171532:tid 171666] [client 57.141.18.60:45704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ksUEhLvMuMRNpl00GZQABDmg"]
[Mon Jul 20 07:37:57.729744 2026] [security2:error] [pid 171532:tid 171726] [client 14.225.17.146:51015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4ktUEhLvMuMRNpl00HYQAAAUo"], referer: https://nwcarvingacademy.com/bc
[Mon Jul 20 07:37:57.933196 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:49408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/coffexium.php"] [unique_id "al4ktTYN371eKRzcKeSAlwAAAKY"]
[Mon Jul 20 07:37:57.933282 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:49408] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/coffexium.php"] [unique_id "al4ktTYN371eKRzcKeSAlwAAAKY"]
[Mon Jul 20 07:37:58.071074 2026] [security2:error] [pid 171532:tid 171786] [client 103.106.165.44:59668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ktkEhLvMuMRNpl00HlgAAAYU"]
[Mon Jul 20 07:37:58.071193 2026] [security2:error] [pid 171532:tid 171786] [client 103.106.165.44:59668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ktkEhLvMuMRNpl00HlgAAAYU"]
[Mon Jul 20 07:37:58.209135 2026] [security2:error] [pid 171532:tid 171693] [client 4.204.201.85:49502] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/red.php"] [unique_id "al4ktkEhLvMuMRNpl00HnAAAASk"]
[Mon Jul 20 07:37:58.209251 2026] [security2:error] [pid 171532:tid 171693] [client 4.204.201.85:49502] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/red.php"] [unique_id "al4ktkEhLvMuMRNpl00HnAAAASk"]
[Mon Jul 20 07:37:58.591676 2026] [security2:error] [pid 171532:tid 171775] [client 4.204.201.85:49483] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4ktkEhLvMuMRNpl00HsQAAAXo"]
[Mon Jul 20 07:37:58.591777 2026] [security2:error] [pid 171532:tid 171775] [client 4.204.201.85:49483] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/sodium_compat/"] [unique_id "al4ktkEhLvMuMRNpl00HsQAAAXo"]
[Mon Jul 20 07:37:58.802107 2026] [security2:error] [pid 164535:tid 164695] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ktjYN371eKRzcKeSAowAAAKM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:37:59.080542 2026] [security2:error] [pid 171532:tid 171786] [client 4.204.201.85:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4kt0EhLvMuMRNpl00HygAAAYU"]
[Mon Jul 20 07:37:59.080639 2026] [security2:error] [pid 171532:tid 171786] [client 4.204.201.85:54337] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/colors/coffee/wp-adochan.php"] [unique_id "al4kt0EhLvMuMRNpl00HygAAAYU"]
[Mon Jul 20 07:37:59.116439 2026] [security2:error] [pid 171532:tid 171758] [client 57.141.18.43:46696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kskEhLvMuMRNpl00GoAABajo"]
[Mon Jul 20 07:37:59.126631 2026] [security2:error] [pid 171532:tid 171764] [client 202.141.11.99:27551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kt0EhLvMuMRNpl00HzgAAAXA"]
[Mon Jul 20 07:37:59.126758 2026] [security2:error] [pid 171532:tid 171764] [client 202.141.11.99:27551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4kt0EhLvMuMRNpl00HzgAAAXA"]
[Mon Jul 20 07:37:59.290398 2026] [security2:error] [pid 164535:tid 164688] [client 4.204.201.85:52929] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/Text/"] [unique_id "al4ktzYN371eKRzcKeSAtQAAAJw"]
[Mon Jul 20 07:37:59.290502 2026] [security2:error] [pid 164535:tid 164688] [client 4.204.201.85:52929] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/Text/"] [unique_id "al4ktzYN371eKRzcKeSAtQAAAJw"]
[Mon Jul 20 07:37:59.401123 2026] [security2:error] [pid 171532:tid 171784] [client 57.141.18.71:62714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kskEhLvMuMRNpl00GqAABg2Q"]
[Mon Jul 20 07:37:59.597828 2026] [security2:error] [pid 171532:tid 171699] [client 4.204.201.85:52914] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/uploads/"] [unique_id "al4kt0EhLvMuMRNpl00H5AAAAS8"]
[Mon Jul 20 07:37:59.597919 2026] [security2:error] [pid 171532:tid 171699] [client 4.204.201.85:52914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/uploads/"] [unique_id "al4kt0EhLvMuMRNpl00H5AAAAS8"]
[Mon Jul 20 07:37:59.615446 2026] [security2:error] [pid 164535:tid 164710] [client 57.141.18.23:30066] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kszYN371eKRzcKeSAWgAAshw"]
[Mon Jul 20 07:37:59.928329 2026] [security2:error] [pid 164535:tid 164781] [client 4.204.201.85:54348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/index.php"] [unique_id "al4ktzYN371eKRzcKeSAwAAAAPk"]
[Mon Jul 20 07:37:59.928435 2026] [security2:error] [pid 164535:tid 164781] [client 4.204.201.85:54348] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/index.php"] [unique_id "al4ktzYN371eKRzcKeSAwAAAAPk"]
[Mon Jul 20 07:38:00.047524 2026] [security2:error] [pid 171532:tid 171698] [client 14.225.17.146:52346] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4kt0EhLvMuMRNpl00H9AAAAS4"], referer: http://headachescarpaltunnelfibromyalgia.com/bc
[Mon Jul 20 07:38:00.079436 2026] [security2:error] [pid 171532:tid 171687] [client 14.225.17.146:52318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4kt0EhLvMuMRNpl00H8gAAASM"], referer: http://margaretspeckogawa.com/bc
[Mon Jul 20 07:38:00.324464 2026] [security2:error] [pid 171532:tid 171766] [client 4.204.201.85:52881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/admin.php"] [unique_id "al4kuEEhLvMuMRNpl00IBQAAAXI"]
[Mon Jul 20 07:38:00.324629 2026] [security2:error] [pid 171532:tid 171766] [client 4.204.201.85:52881] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/admin.php"] [unique_id "al4kuEEhLvMuMRNpl00IBQAAAXI"]
[Mon Jul 20 07:38:00.533211 2026] [security2:error] [pid 164535:tid 164786] [client 57.141.18.82:21224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kszYN371eKRzcKeSAagAA_iI"]
[Mon Jul 20 07:38:00.585328 2026] [security2:error] [pid 171532:tid 171724] [client 14.225.17.146:53606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4kuEEhLvMuMRNpl00ICAAAAUg"], referer: http://superiorcopywriting.com/bc
[Mon Jul 20 07:38:00.607312 2026] [security2:error] [pid 171532:tid 171689] [client 14.225.17.146:52301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4ktkEhLvMuMRNpl00HuQAAASU"], referer: http://narv.co/bc
[Mon Jul 20 07:38:00.616697 2026] [security2:error] [pid 171532:tid 171679] [client 154.192.233.184:62291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kuEEhLvMuMRNpl00IHwAAARs"]
[Mon Jul 20 07:38:00.616818 2026] [security2:error] [pid 171532:tid 171679] [client 154.192.233.184:62291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kuEEhLvMuMRNpl00IHwAAARs"]
[Mon Jul 20 07:38:00.850354 2026] [security2:error] [pid 164535:tid 164764] [client 103.176.215.66:64897] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kuDYN371eKRzcKeSAzAAAAOg"]
[Mon Jul 20 07:38:00.850476 2026] [security2:error] [pid 164535:tid 164764] [client 103.176.215.66:64897] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kuDYN371eKRzcKeSAzAAAAOg"]
[Mon Jul 20 07:38:01.155809 2026] [security2:error] [pid 171532:tid 171674] [client 4.204.201.85:52990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/177.php"] [unique_id "al4kuUEhLvMuMRNpl00IQQAAARY"]
[Mon Jul 20 07:38:01.155934 2026] [security2:error] [pid 171532:tid 171674] [client 4.204.201.85:52990] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/177.php"] [unique_id "al4kuUEhLvMuMRNpl00IQQAAARY"]
[Mon Jul 20 07:38:01.413638 2026] [authz_core:error] [pid 164535:tid 164739] [client 188.166.209.66:51842] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/PHPMailer/error_log, referer: binance.com
[Mon Jul 20 07:38:01.468011 2026] [security2:error] [pid 164535:tid 164775] [client 49.37.242.14:63778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kuTYN371eKRzcKeSA3gAAAPM"]
[Mon Jul 20 07:38:01.468158 2026] [security2:error] [pid 164535:tid 164775] [client 49.37.242.14:63778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kuTYN371eKRzcKeSA3gAAAPM"]
[Mon Jul 20 07:38:01.621175 2026] [security2:error] [pid 171532:tid 171780] [client 191.202.66.27:56460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kuUEhLvMuMRNpl00IWAAAAX8"]
[Mon Jul 20 07:38:01.621269 2026] [security2:error] [pid 171532:tid 171780] [client 191.202.66.27:56460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kuUEhLvMuMRNpl00IWAAAAX8"]
[Mon Jul 20 07:38:01.628281 2026] [security2:error] [pid 164535:tid 164668] [client 136.158.60.21:3763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kuTYN371eKRzcKeSA5QAAAIg"]
[Mon Jul 20 07:38:01.628400 2026] [security2:error] [pid 164535:tid 164668] [client 136.158.60.21:3763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kuTYN371eKRzcKeSA5QAAAIg"]
[Mon Jul 20 07:38:01.687606 2026] [security2:error] [pid 171532:tid 171739] [client 4.204.201.85:52877] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/199.php"] [unique_id "al4kuUEhLvMuMRNpl00IXwAAAVc"]
[Mon Jul 20 07:38:01.687720 2026] [security2:error] [pid 171532:tid 171739] [client 4.204.201.85:52877] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/199.php"] [unique_id "al4kuUEhLvMuMRNpl00IXwAAAVc"]
[Mon Jul 20 07:38:01.690130 2026] [security2:error] [pid 171532:tid 171714] [client 14.225.17.146:53866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4kuUEhLvMuMRNpl00IUAAAAT4"], referer: https://narv.co/bc
[Mon Jul 20 07:38:01.867253 2026] [security2:error] [pid 164535:tid 164770] [client 57.141.18.114:44978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ktTYN371eKRzcKeSAggAA7mE"]
[Mon Jul 20 07:38:01.880828 2026] [security2:error] [pid 171532:tid 171684] [client 4.204.201.85:52895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/file52.php"] [unique_id "al4kuUEhLvMuMRNpl00IZgAAASA"]
[Mon Jul 20 07:38:01.880968 2026] [security2:error] [pid 171532:tid 171684] [client 4.204.201.85:52895] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/file52.php"] [unique_id "al4kuUEhLvMuMRNpl00IZgAAASA"]
[Mon Jul 20 07:38:01.926831 2026] [security2:error] [pid 171532:tid 171691] [client 57.141.18.120:40212] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ktUEhLvMuMRNpl00HUwABJyw"]
[Mon Jul 20 07:38:02.039614 2026] [security2:error] [pid 164535:tid 164694] [client 4.204.201.85:52953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/geck.php"] [unique_id "al4kujYN371eKRzcKeSBIAAAAKI"]
[Mon Jul 20 07:38:02.039724 2026] [security2:error] [pid 164535:tid 164694] [client 4.204.201.85:52953] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/geck.php"] [unique_id "al4kujYN371eKRzcKeSBIAAAAKI"]
[Mon Jul 20 07:38:02.198173 2026] [security2:error] [pid 164535:tid 164779] [client 4.204.201.85:54394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/biufile.php"] [unique_id "al4kujYN371eKRzcKeSBPQAAAPc"]
[Mon Jul 20 07:38:02.198259 2026] [security2:error] [pid 164535:tid 164779] [client 4.204.201.85:54394] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/biufile.php"] [unique_id "al4kujYN371eKRzcKeSBPQAAAPc"]
[Mon Jul 20 07:38:02.203118 2026] [security2:error] [pid 171532:tid 171702] [client 57.141.18.32:65138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ktUEhLvMuMRNpl00HYAABMmA"]
[Mon Jul 20 07:38:02.238506 2026] [security2:error] [pid 171532:tid 171789] [client 179.127.84.238:60353] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kukEhLvMuMRNpl00IdgAAAYg"]
[Mon Jul 20 07:38:02.238653 2026] [security2:error] [pid 171532:tid 171789] [client 179.127.84.238:60353] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kukEhLvMuMRNpl00IdgAAAYg"]
[Mon Jul 20 07:38:02.347561 2026] [security2:error] [pid 164535:tid 164790] [client 4.204.201.85:49529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/mosty.php"] [unique_id "al4kujYN371eKRzcKeSBRwAAAQI"]
[Mon Jul 20 07:38:02.347707 2026] [security2:error] [pid 164535:tid 164790] [client 4.204.201.85:49529] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/mosty.php"] [unique_id "al4kujYN371eKRzcKeSBRwAAAQI"]
[Mon Jul 20 07:38:02.402950 2026] [security2:error] [pid 171532:tid 171703] [client 103.139.191.61:59315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kukEhLvMuMRNpl00IfAAAATM"]
[Mon Jul 20 07:38:02.403098 2026] [security2:error] [pid 171532:tid 171703] [client 103.139.191.61:59315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kukEhLvMuMRNpl00IfAAAATM"]
[Mon Jul 20 07:38:02.462993 2026] [security2:error] [pid 164535:tid 164733] [client 45.3.44.198:31969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kujYN371eKRzcKeSBSwAAAMk"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:02.482844 2026] [security2:error] [pid 171532:tid 171750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kukEhLvMuMRNpl00IdwAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:02.491345 2026] [security2:error] [pid 171532:tid 171780] [client 4.204.201.85:52934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/dejavu.php"] [unique_id "al4kukEhLvMuMRNpl00IfwAAAX8"]
[Mon Jul 20 07:38:02.491447 2026] [security2:error] [pid 171532:tid 171780] [client 4.204.201.85:52934] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/dejavu.php"] [unique_id "al4kukEhLvMuMRNpl00IfwAAAX8"]
[Mon Jul 20 07:38:02.616069 2026] [security2:error] [pid 171532:tid 171758] [client 4.204.201.85:54362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/aaf.php"] [unique_id "al4kukEhLvMuMRNpl00IhgAAAWo"]
[Mon Jul 20 07:38:02.616167 2026] [security2:error] [pid 171532:tid 171758] [client 4.204.201.85:54362] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/aaf.php"] [unique_id "al4kukEhLvMuMRNpl00IhgAAAWo"]
[Mon Jul 20 07:38:02.726506 2026] [security2:error] [pid 171532:tid 171593] [remote 5.161.225.162:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4kukEhLvMuMRNpl00IjAABczw"]
[Mon Jul 20 07:38:02.775672 2026] [security2:error] [pid 171532:tid 171700] [client 4.204.201.85:52974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ha.php"] [unique_id "al4kukEhLvMuMRNpl00IkAAAATA"]
[Mon Jul 20 07:38:02.775774 2026] [security2:error] [pid 171532:tid 171700] [client 4.204.201.85:52974] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ha.php"] [unique_id "al4kukEhLvMuMRNpl00IkAAAATA"]
[Mon Jul 20 07:38:02.928399 2026] [security2:error] [pid 171532:tid 171628] [remote 5.161.225.162:51148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4kukEhLvMuMRNpl00IlQABel8"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 07:38:02.941313 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:54296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/hur.php"] [unique_id "al4kukEhLvMuMRNpl00IlgAAAVg"]
[Mon Jul 20 07:38:02.941405 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:54296] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/hur.php"] [unique_id "al4kukEhLvMuMRNpl00IlgAAAVg"]
[Mon Jul 20 07:38:02.956868 2026] [security2:error] [pid 171532:tid 171711] [client 57.141.18.41:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4kukEhLvMuMRNpl00IkgAAATs"]
[Mon Jul 20 07:38:03.091690 2026] [security2:error] [pid 164535:tid 164759] [client 4.204.201.85:54309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/h02ugyh.php"] [unique_id "al4kuzYN371eKRzcKeSBXQAAAOM"]
[Mon Jul 20 07:38:03.091823 2026] [security2:error] [pid 164535:tid 164759] [client 4.204.201.85:54309] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/h02ugyh.php"] [unique_id "al4kuzYN371eKRzcKeSBXQAAAOM"]
[Mon Jul 20 07:38:03.281240 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:52867] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/155.php"] [unique_id "al4ku0EhLvMuMRNpl00IrwAAAWI"]
[Mon Jul 20 07:38:03.281329 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:52867] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/155.php"] [unique_id "al4ku0EhLvMuMRNpl00IrwAAAWI"]
[Mon Jul 20 07:38:03.437295 2026] [security2:error] [pid 164535:tid 164692] [client 4.204.201.85:54399] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/pp.php"] [unique_id "al4kuzYN371eKRzcKeSBaQAAAKA"]
[Mon Jul 20 07:38:03.437394 2026] [security2:error] [pid 164535:tid 164692] [client 4.204.201.85:54399] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/pp.php"] [unique_id "al4kuzYN371eKRzcKeSBaQAAAKA"]
[Mon Jul 20 07:38:03.477925 2026] [security2:error] [pid 171532:tid 171666] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ku0EhLvMuMRNpl00IrgAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:03.564351 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:52887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ops.php"] [unique_id "al4kuzYN371eKRzcKeSBcAAAAN0"]
[Mon Jul 20 07:38:03.564485 2026] [security2:error] [pid 164535:tid 164753] [client 4.204.201.85:52887] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ops.php"] [unique_id "al4kuzYN371eKRzcKeSBcAAAAN0"]
[Mon Jul 20 07:38:03.763848 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:52889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ingfo.php"] [unique_id "al4kuzYN371eKRzcKeSBeQAAAKY"]
[Mon Jul 20 07:38:03.763973 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:52889] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ingfo.php"] [unique_id "al4kuzYN371eKRzcKeSBeQAAAKY"]
[Mon Jul 20 07:38:03.886972 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:54323] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/error_log.php"] [unique_id "al4ku0EhLvMuMRNpl00IvwAAAVg"]
[Mon Jul 20 07:38:03.887084 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:54323] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/error_log.php"] [unique_id "al4ku0EhLvMuMRNpl00IvwAAAVg"]
[Mon Jul 20 07:38:03.965916 2026] [security2:error] [pid 171532:tid 171754] [client 57.141.18.80:24744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ktkEhLvMuMRNpl00HtwABZng"]
[Mon Jul 20 07:38:04.069925 2026] [security2:error] [pid 171532:tid 171701] [client 4.204.201.85:54347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/test10.php"] [unique_id "al4kvEEhLvMuMRNpl00IxgAAATE"]
[Mon Jul 20 07:38:04.070021 2026] [security2:error] [pid 171532:tid 171701] [client 4.204.201.85:54347] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/test10.php"] [unique_id "al4kvEEhLvMuMRNpl00IxgAAATE"]
[Mon Jul 20 07:38:04.202687 2026] [security2:error] [pid 171532:tid 171789] [client 4.204.201.85:52952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/koala.php"] [unique_id "al4kvEEhLvMuMRNpl00I0gAAAYg"]
[Mon Jul 20 07:38:04.202770 2026] [security2:error] [pid 171532:tid 171789] [client 4.204.201.85:52952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/koala.php"] [unique_id "al4kvEEhLvMuMRNpl00I0gAAAYg"]
[Mon Jul 20 07:38:04.330833 2026] [security2:error] [pid 164535:tid 164732] [client 4.204.201.85:54328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/mac.php"] [unique_id "al4kvDYN371eKRzcKeSBhQAAAMg"]
[Mon Jul 20 07:38:04.330919 2026] [security2:error] [pid 164535:tid 164732] [client 4.204.201.85:54328] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/mac.php"] [unique_id "al4kvDYN371eKRzcKeSBhQAAAMg"]
[Mon Jul 20 07:38:04.438876 2026] [security2:error] [pid 164535:tid 164790] [client 114.119.159.70:21095] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.itdynamix.com"] [uri "/services/strategic-partners/bitrix24"] [unique_id "al4kvDYN371eKRzcKeSBhgAAAQI"], referer: https://www.itdynamix.com/careers/
[Mon Jul 20 07:38:04.520565 2026] [security2:error] [pid 171532:tid 171739] [client 4.204.201.85:52970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wefile.php"] [unique_id "al4kvEEhLvMuMRNpl00I4wAAAVc"]
[Mon Jul 20 07:38:04.520695 2026] [security2:error] [pid 171532:tid 171739] [client 4.204.201.85:52970] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wefile.php"] [unique_id "al4kvEEhLvMuMRNpl00I4wAAAVc"]
[Mon Jul 20 07:38:04.582690 2026] [security2:error] [pid 171532:tid 171548] [remote 97.74.93.24:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kvEEhLvMuMRNpl00I5gABTQ8"]
[Mon Jul 20 07:38:04.669027 2026] [security2:error] [pid 171532:tid 171769] [client 4.204.201.85:54272] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4kvEEhLvMuMRNpl00I7wAAAXU"]
[Mon Jul 20 07:38:04.669121 2026] [security2:error] [pid 171532:tid 171769] [client 4.204.201.85:54272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/blocks/post-comments-form/"] [unique_id "al4kvEEhLvMuMRNpl00I7wAAAXU"]
[Mon Jul 20 07:38:04.797368 2026] [security2:error] [pid 171532:tid 171724] [client 4.204.201.85:52935] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/js/"] [unique_id "al4kvEEhLvMuMRNpl00I9QAAAUg"]
[Mon Jul 20 07:38:04.797462 2026] [security2:error] [pid 171532:tid 171724] [client 4.204.201.85:52935] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/js/"] [unique_id "al4kvEEhLvMuMRNpl00I9QAAAUg"]
[Mon Jul 20 07:38:04.915249 2026] [security2:error] [pid 171532:tid 171682] [client 143.44.185.218:6344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kvEEhLvMuMRNpl00I_AAAAR4"]
[Mon Jul 20 07:38:04.915343 2026] [security2:error] [pid 171532:tid 171682] [client 143.44.185.218:6344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kvEEhLvMuMRNpl00I_AAAAR4"]
[Mon Jul 20 07:38:04.920993 2026] [security2:error] [pid 171532:tid 171733] [client 45.3.54.222:62753] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 222.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kvEEhLvMuMRNpl00I-wAAAVE"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:04.935123 2026] [security2:error] [pid 171532:tid 171544] [remote 194.164.192.228:53048] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kvEEhLvMuMRNpl00I_QABEQs"]
[Mon Jul 20 07:38:04.935307 2026] [security2:error] [pid 171532:tid 171669] [client 194.164.192.228:53048] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kvEEhLvMuMRNpl00I_QABEQs"]
[Mon Jul 20 07:38:04.947837 2026] [security2:error] [pid 164535:tid 164718] [client 4.204.201.85:54375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/makeasmtp.php"] [unique_id "al4kvDYN371eKRzcKeSBjwAAALo"]
[Mon Jul 20 07:38:04.947965 2026] [security2:error] [pid 164535:tid 164718] [client 4.204.201.85:54375] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/makeasmtp.php"] [unique_id "al4kvDYN371eKRzcKeSBjwAAALo"]
[Mon Jul 20 07:38:04.987868 2026] [security2:error] [pid 171532:tid 171534] [remote 97.74.93.24:33442] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory-com.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kvEEhLvMuMRNpl00I_gABWgE"], referer: https://nzfoodstory-com.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:38:05.092525 2026] [security2:error] [pid 171532:tid 171745] [client 4.204.201.85:52885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/2P.php"] [unique_id "al4kvUEhLvMuMRNpl00JAgAAAV0"]
[Mon Jul 20 07:38:05.092609 2026] [security2:error] [pid 171532:tid 171745] [client 4.204.201.85:52885] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/2P.php"] [unique_id "al4kvUEhLvMuMRNpl00JAgAAAV0"]
[Mon Jul 20 07:38:05.238125 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:52971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/.well-known/about.php"] [unique_id "al4kvUEhLvMuMRNpl00JDAAAATY"]
[Mon Jul 20 07:38:05.238256 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:52971] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/.well-known/about.php"] [unique_id "al4kvUEhLvMuMRNpl00JDAAAATY"]
[Mon Jul 20 07:38:05.343118 2026] [security2:error] [pid 171532:tid 171789] [client 49.47.218.174:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kvUEhLvMuMRNpl00JEgAAAYg"]
[Mon Jul 20 07:38:05.343207 2026] [security2:error] [pid 171532:tid 171789] [client 49.47.218.174:60896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kvUEhLvMuMRNpl00JEgAAAYg"]
[Mon Jul 20 07:38:05.405408 2026] [security2:error] [pid 171532:tid 171664] [client 4.204.201.85:54324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4kvUEhLvMuMRNpl00JFQAAAQw"]
[Mon Jul 20 07:38:05.405512 2026] [security2:error] [pid 171532:tid 171664] [client 4.204.201.85:54324] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/ID3/about.php"] [unique_id "al4kvUEhLvMuMRNpl00JFQAAAQw"]
[Mon Jul 20 07:38:05.532700 2026] [security2:error] [pid 171532:tid 171723] [client 4.204.201.85:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/system_log.php"] [unique_id "al4kvUEhLvMuMRNpl00JJQAAAUc"]
[Mon Jul 20 07:38:05.532814 2026] [security2:error] [pid 171532:tid 171723] [client 4.204.201.85:52900] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/system_log.php"] [unique_id "al4kvUEhLvMuMRNpl00JJQAAAUc"]
[Mon Jul 20 07:38:05.621973 2026] [security2:error] [pid 164535:tid 164570] [remote 124.55.178.99:59970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kvTYN371eKRzcKeSBlgAAnyI"]
[Mon Jul 20 07:38:05.622120 2026] [security2:error] [pid 164535:tid 164691] [client 124.55.178.99:59970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kvTYN371eKRzcKeSBlgAAnyI"]
[Mon Jul 20 07:38:05.667376 2026] [security2:error] [pid 171532:tid 171742] [client 4.204.201.85:49518] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/"] [unique_id "al4kvUEhLvMuMRNpl00JLQAAAVo"]
[Mon Jul 20 07:38:05.667469 2026] [security2:error] [pid 171532:tid 171742] [client 4.204.201.85:49518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/"] [unique_id "al4kvUEhLvMuMRNpl00JLQAAAVo"]
[Mon Jul 20 07:38:05.824771 2026] [security2:error] [pid 164535:tid 164677] [client 4.204.201.85:54289] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4kvTYN371eKRzcKeSBmQAAAJE"]
[Mon Jul 20 07:38:05.824905 2026] [security2:error] [pid 164535:tid 164677] [client 4.204.201.85:54289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/colors/modern/"] [unique_id "al4kvTYN371eKRzcKeSBmQAAAJE"]
[Mon Jul 20 07:38:05.967403 2026] [security2:error] [pid 171532:tid 171737] [client 4.204.201.85:52955] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/crgio.php"] [unique_id "al4kvUEhLvMuMRNpl00JOwAAAVU"]
[Mon Jul 20 07:38:05.967480 2026] [security2:error] [pid 171532:tid 171737] [client 4.204.201.85:52955] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/crgio.php"] [unique_id "al4kvUEhLvMuMRNpl00JOwAAAVU"]
[Mon Jul 20 07:38:06.112186 2026] [security2:error] [pid 164535:tid 164765] [client 4.204.201.85:52878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/pucci.php"] [unique_id "al4kvjYN371eKRzcKeSBnAAAAOk"]
[Mon Jul 20 07:38:06.112274 2026] [security2:error] [pid 164535:tid 164765] [client 4.204.201.85:52878] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/pucci.php"] [unique_id "al4kvjYN371eKRzcKeSBnAAAAOk"]
[Mon Jul 20 07:38:06.235743 2026] [security2:error] [pid 164535:tid 164761] [client 188.166.209.66:51699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/PHPMailer/DSNConfigurator.php"] [unique_id "al4kvjYN371eKRzcKeSBngAAAOU"], referer: binance.com
[Mon Jul 20 07:38:06.272053 2026] [security2:error] [pid 171532:tid 171724] [client 4.204.201.85:52981] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/blocks/details/"] [unique_id "al4kvkEhLvMuMRNpl00JSgAAAUg"]
[Mon Jul 20 07:38:06.272140 2026] [security2:error] [pid 171532:tid 171724] [client 4.204.201.85:52981] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/blocks/details/"] [unique_id "al4kvkEhLvMuMRNpl00JSgAAAUg"]
[Mon Jul 20 07:38:06.288339 2026] [security2:error] [pid 171532:tid 171768] [client 180.249.173.210:57155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kvkEhLvMuMRNpl00JSwAAAXQ"]
[Mon Jul 20 07:38:06.288522 2026] [security2:error] [pid 171532:tid 171768] [client 180.249.173.210:57155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kvkEhLvMuMRNpl00JSwAAAXQ"]
[Mon Jul 20 07:38:06.288847 2026] [security2:error] [pid 171532:tid 171717] [client 14.225.17.146:53861] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4kvkEhLvMuMRNpl00JQgAAAUE"], referer: http://dnsplumbing.com/bc
[Mon Jul 20 07:38:06.367284 2026] [security2:error] [pid 171532:tid 171702] [client 65.111.23.185:57429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kvkEhLvMuMRNpl00JUAAAATI"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:06.399862 2026] [security2:error] [pid 171532:tid 171787] [client 4.204.201.85:54289] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/blocks/audio/"] [unique_id "al4kvkEhLvMuMRNpl00JVgAAAYY"]
[Mon Jul 20 07:38:06.399950 2026] [security2:error] [pid 171532:tid 171787] [client 4.204.201.85:54289] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/blocks/audio/"] [unique_id "al4kvkEhLvMuMRNpl00JVgAAAYY"]
[Mon Jul 20 07:38:06.527445 2026] [security2:error] [pid 164535:tid 164673] [client 4.204.201.85:49475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-temp.php"] [unique_id "al4kvjYN371eKRzcKeSBpQAAAI0"]
[Mon Jul 20 07:38:06.527565 2026] [security2:error] [pid 164535:tid 164673] [client 4.204.201.85:49475] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-temp.php"] [unique_id "al4kvjYN371eKRzcKeSBpQAAAI0"]
[Mon Jul 20 07:38:06.587218 2026] [security2:error] [pid 171532:tid 171757] [client 157.20.138.62:63423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kvkEhLvMuMRNpl00JYAAAAWk"]
[Mon Jul 20 07:38:06.587335 2026] [security2:error] [pid 171532:tid 171757] [client 157.20.138.62:63423] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kvkEhLvMuMRNpl00JYAAAAWk"]
[Mon Jul 20 07:38:06.664864 2026] [security2:error] [pid 164535:tid 164725] [client 4.204.201.85:49409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/js/index.php"] [unique_id "al4kvjYN371eKRzcKeSBqgAAAME"]
[Mon Jul 20 07:38:06.664966 2026] [security2:error] [pid 164535:tid 164725] [client 4.204.201.85:49409] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/js/index.php"] [unique_id "al4kvjYN371eKRzcKeSBqgAAAME"]
[Mon Jul 20 07:38:06.735679 2026] [security2:error] [pid 171532:tid 171677] [client 14.225.17.146:53312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4kvkEhLvMuMRNpl00JXgAAARk"], referer: http://ksands.co.uk/bc
[Mon Jul 20 07:38:06.784821 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:54390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/puc.php"] [unique_id "al4kvjYN371eKRzcKeSBsQAAAOA"]
[Mon Jul 20 07:38:06.784919 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:54390] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/puc.php"] [unique_id "al4kvjYN371eKRzcKeSBsQAAAOA"]
[Mon Jul 20 07:38:06.929530 2026] [security2:error] [pid 164535:tid 164764] [client 4.204.201.85:52987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/dx.php"] [unique_id "al4kvjYN371eKRzcKeSBtgAAAOg"]
[Mon Jul 20 07:38:06.929675 2026] [security2:error] [pid 164535:tid 164764] [client 4.204.201.85:52987] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/dx.php"] [unique_id "al4kvjYN371eKRzcKeSBtgAAAOg"]
[Mon Jul 20 07:38:06.931000 2026] [security2:error] [pid 164535:tid 164783] [client 57.141.18.87:50796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kujYN371eKRzcKeSBJgAA-x0"]
[Mon Jul 20 07:38:07.151008 2026] [security2:error] [pid 171532:tid 171662] [client 4.204.201.85:54295] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/Requests/"] [unique_id "al4kv0EhLvMuMRNpl00JegAAAQo"]
[Mon Jul 20 07:38:07.151090 2026] [security2:error] [pid 171532:tid 171662] [client 4.204.201.85:54295] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/Requests/"] [unique_id "al4kv0EhLvMuMRNpl00JegAAAQo"]
[Mon Jul 20 07:38:07.245888 2026] [security2:error] [pid 171532:tid 171672] [client 14.225.17.146:53208] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4kvUEhLvMuMRNpl00JNgAAARQ"], referer: http://alchemygroup.ca/bc
[Mon Jul 20 07:38:07.304425 2026] [security2:error] [pid 171532:tid 171733] [client 161.118.238.173:53143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.238.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.qtr.awg.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kv0EhLvMuMRNpl00JhgAAAVE"], referer: https://duckduckgo.com/
[Mon Jul 20 07:38:07.320303 2026] [security2:error] [pid 171532:tid 171699] [client 4.204.201.85:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/bthil.php"] [unique_id "al4kv0EhLvMuMRNpl00JhwAAAS8"]
[Mon Jul 20 07:38:07.320411 2026] [security2:error] [pid 171532:tid 171699] [client 4.204.201.85:52864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/bthil.php"] [unique_id "al4kv0EhLvMuMRNpl00JhwAAAS8"]
[Mon Jul 20 07:38:07.532586 2026] [security2:error] [pid 171532:tid 171786] [client 4.204.201.85:52864] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/7.php"] [unique_id "al4kv0EhLvMuMRNpl00JkAAAAYU"]
[Mon Jul 20 07:38:07.532668 2026] [security2:error] [pid 171532:tid 171786] [client 4.204.201.85:52864] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/7.php"] [unique_id "al4kv0EhLvMuMRNpl00JkAAAAYU"]
[Mon Jul 20 07:38:07.630249 2026] [proxy:error] [pid 171532:tid 171789] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:07.630306 2026] [proxy_http:error] [pid 171532:tid 171789] [client 205.210.31.33:63010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:07.630797 2026] [proxy:error] [pid 171532:tid 171789] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:07.630820 2026] [proxy_http:error] [pid 171532:tid 171789] [client 205.210.31.33:63010] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:07.668306 2026] [security2:error] [pid 164535:tid 164709] [client 4.204.201.85:54387] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/8.php"] [unique_id "al4kvzYN371eKRzcKeSBwwAAALE"]
[Mon Jul 20 07:38:07.668415 2026] [security2:error] [pid 164535:tid 164709] [client 4.204.201.85:54387] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/8.php"] [unique_id "al4kvzYN371eKRzcKeSBwwAAALE"]
[Mon Jul 20 07:38:07.680498 2026] [security2:error] [pid 164535:tid 164773] [client 161.118.238.173:53186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.238.118.161.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpcontacts.qtr.awg.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4kvzYN371eKRzcKeSBxAAAAPE"]
[Mon Jul 20 07:38:07.682557 2026] [security2:error] [pid 171532:tid 171691] [client 155.2.215.81:44949] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kv0EhLvMuMRNpl00JjwAAASc"]
[Mon Jul 20 07:38:07.761086 2026] [security2:error] [pid 171532:tid 171745] [client 149.0.16.108:51053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kv0EhLvMuMRNpl00JqQAAAV0"]
[Mon Jul 20 07:38:07.761133 2026] [security2:error] [pid 164535:tid 164667] [client 36.93.152.155:55270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kvzYN371eKRzcKeSBxgAAAIc"]
[Mon Jul 20 07:38:07.761182 2026] [security2:error] [pid 171532:tid 171745] [client 149.0.16.108:51053] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kv0EhLvMuMRNpl00JqQAAAV0"]
[Mon Jul 20 07:38:07.761247 2026] [security2:error] [pid 164535:tid 164667] [client 36.93.152.155:55270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kvzYN371eKRzcKeSBxgAAAIc"]
[Mon Jul 20 07:38:07.782617 2026] [security2:error] [pid 164535:tid 164771] [client 45.3.42.100:26561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kvzYN371eKRzcKeSBxwAAAO8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:07.816257 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:52921] ModSecurity: Warning. Pattern match "/1\\\\.php" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1543"] [id "900921"] [msg "temporary TUW-72162 logging rule"] [hostname "autodiscover.cimahmo.pro"] [uri "/1.php"] [unique_id "al4kv0EhLvMuMRNpl00JrwAAAYM"]
[Mon Jul 20 07:38:07.816364 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:52921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/1.php"] [unique_id "al4kv0EhLvMuMRNpl00JrwAAAYM"]
[Mon Jul 20 07:38:07.816444 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:52921] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/1.php"] [unique_id "al4kv0EhLvMuMRNpl00JrwAAAYM"]
[Mon Jul 20 07:38:07.951036 2026] [security2:error] [pid 164535:tid 164790] [client 116.193.128.26:54214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kvzYN371eKRzcKeSBywAAAQI"]
[Mon Jul 20 07:38:07.951181 2026] [security2:error] [pid 164535:tid 164790] [client 116.193.128.26:54214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kvzYN371eKRzcKeSBywAAAQI"]
[Mon Jul 20 07:38:07.980480 2026] [security2:error] [pid 171532:tid 171701] [client 4.204.201.85:63351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/100.php"] [unique_id "al4kv0EhLvMuMRNpl00JtwAAATE"]
[Mon Jul 20 07:38:07.980564 2026] [security2:error] [pid 171532:tid 171701] [client 4.204.201.85:63351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/100.php"] [unique_id "al4kv0EhLvMuMRNpl00JtwAAATE"]
[Mon Jul 20 07:38:08.014903 2026] [security2:error] [pid 171532:tid 171758] [client 154.192.123.127:17507] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kwEEhLvMuMRNpl00JuQAAAWo"]
[Mon Jul 20 07:38:08.015048 2026] [security2:error] [pid 171532:tid 171758] [client 154.192.123.127:17507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kwEEhLvMuMRNpl00JuQAAAWo"]
[Mon Jul 20 07:38:08.072348 2026] [security2:error] [pid 171532:tid 171679] [client 57.141.18.12:29468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ku0EhLvMuMRNpl00IpAABGzg"]
[Mon Jul 20 07:38:08.204019 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:63302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/about.php"] [unique_id "al4kwEEhLvMuMRNpl00JxQAAATY"]
[Mon Jul 20 07:38:08.204134 2026] [security2:error] [pid 171532:tid 171706] [client 4.204.201.85:63302] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/about.php"] [unique_id "al4kwEEhLvMuMRNpl00JxQAAATY"]
[Mon Jul 20 07:38:08.251877 2026] [proxy:error] [pid 171532:tid 171741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:08.251921 2026] [proxy_http:error] [pid 171532:tid 171741] [client 161.118.238.173:53227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://wordpress.org/
[Mon Jul 20 07:38:08.252489 2026] [proxy:error] [pid 171532:tid 171741] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:08.252512 2026] [proxy_http:error] [pid 171532:tid 171741] [client 161.118.238.173:53227] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://wordpress.org/
[Mon Jul 20 07:38:08.352437 2026] [security2:error] [pid 171532:tid 171753] [client 14.225.17.146:52293] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4kwEEhLvMuMRNpl00JwwAAAWU"], referer: http://nurturemarple.co.uk/bc
[Mon Jul 20 07:38:08.399082 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:52940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/admin.php"] [unique_id "al4kwEEhLvMuMRNpl00J0wAAAYM"]
[Mon Jul 20 07:38:08.399194 2026] [security2:error] [pid 171532:tid 171784] [client 4.204.201.85:52940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/admin.php"] [unique_id "al4kwEEhLvMuMRNpl00J0wAAAYM"]
[Mon Jul 20 07:38:08.550432 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:54376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/edit.php"] [unique_id "al4kwEEhLvMuMRNpl00J2wAAAWI"]
[Mon Jul 20 07:38:08.550520 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:54376] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/edit.php"] [unique_id "al4kwEEhLvMuMRNpl00J2wAAAWI"]
[Mon Jul 20 07:38:08.559362 2026] [security2:error] [pid 171532:tid 171759] [client 103.106.165.44:60144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kwEEhLvMuMRNpl00J3AAAAWs"]
[Mon Jul 20 07:38:08.559441 2026] [security2:error] [pid 171532:tid 171759] [client 103.106.165.44:60144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kwEEhLvMuMRNpl00J3AAAAWs"]
[Mon Jul 20 07:38:08.676237 2026] [security2:error] [pid 171532:tid 171670] [client 50.116.65.227:57092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4kwEEhLvMuMRNpl00J2QAAARI"]
[Mon Jul 20 07:38:08.700179 2026] [security2:error] [pid 171532:tid 171678] [client 4.204.201.85:52943] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/admin.php"] [unique_id "al4kwEEhLvMuMRNpl00J4wAAARo"]
[Mon Jul 20 07:38:08.700265 2026] [security2:error] [pid 171532:tid 171678] [client 4.204.201.85:52943] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/admin.php"] [unique_id "al4kwEEhLvMuMRNpl00J4wAAARo"]
[Mon Jul 20 07:38:08.855445 2026] [security2:error] [pid 171532:tid 171663] [client 4.204.201.85:52968] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ss.php"] [unique_id "al4kwEEhLvMuMRNpl00J9QAAAQs"]
[Mon Jul 20 07:38:08.855546 2026] [security2:error] [pid 171532:tid 171663] [client 4.204.201.85:52968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ss.php"] [unique_id "al4kwEEhLvMuMRNpl00J9QAAAQs"]
[Mon Jul 20 07:38:08.863738 2026] [security2:error] [pid 171532:tid 171669] [client 50.116.65.227:57094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4kwEEhLvMuMRNpl00J4QAAARE"]
[Mon Jul 20 07:38:09.002258 2026] [security2:error] [pid 164535:tid 164690] [client 4.204.201.85:49486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/inputs.php"] [unique_id "al4kwTYN371eKRzcKeSB3gAAAJ4"]
[Mon Jul 20 07:38:09.002370 2026] [security2:error] [pid 164535:tid 164690] [client 4.204.201.85:49486] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/inputs.php"] [unique_id "al4kwTYN371eKRzcKeSB3gAAAJ4"]
[Mon Jul 20 07:38:09.027962 2026] [security2:error] [pid 171532:tid 171671] [client 50.116.65.227:24518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kwUEhLvMuMRNpl00J_gAAARM"]
[Mon Jul 20 07:38:09.039554 2026] [security2:error] [pid 171532:tid 171662] [client 50.116.65.227:24530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kwUEhLvMuMRNpl00J_wAAAQo"]
[Mon Jul 20 07:38:09.059712 2026] [security2:error] [pid 171532:tid 171736] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kwEEhLvMuMRNpl00J9gAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:09.180344 2026] [security2:error] [pid 164535:tid 164747] [client 4.204.201.85:54327] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/av.php"] [unique_id "al4kwTYN371eKRzcKeSB5gAAANc"]
[Mon Jul 20 07:38:09.180482 2026] [security2:error] [pid 164535:tid 164747] [client 4.204.201.85:54327] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/av.php"] [unique_id "al4kwTYN371eKRzcKeSB5gAAANc"]
[Mon Jul 20 07:38:09.200085 2026] [security2:error] [pid 171532:tid 171739] [client 104.207.50.74:16529] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kwUEhLvMuMRNpl00KBQAAAVc"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:09.301667 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:54370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/classwithtostring.php"] [unique_id "al4kwTYN371eKRzcKeSB6wAAAKY"]
[Mon Jul 20 07:38:09.301763 2026] [security2:error] [pid 164535:tid 164698] [client 4.204.201.85:54370] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/classwithtostring.php"] [unique_id "al4kwTYN371eKRzcKeSB6wAAAKY"]
[Mon Jul 20 07:38:09.326944 2026] [security2:error] [pid 171532:tid 171790] [client 57.141.18.94:44074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kvEEhLvMuMRNpl00IwQABiTY"]
[Mon Jul 20 07:38:09.430336 2026] [security2:error] [pid 171532:tid 171666] [client 4.204.201.85:49528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/themes/index.php"] [unique_id "al4kwUEhLvMuMRNpl00KDgAAAQ4"]
[Mon Jul 20 07:38:09.430441 2026] [security2:error] [pid 171532:tid 171666] [client 4.204.201.85:49528] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/themes/index.php"] [unique_id "al4kwUEhLvMuMRNpl00KDgAAAQ4"]
[Mon Jul 20 07:38:09.631504 2026] [security2:error] [pid 171532:tid 171655] [remote 100.42.189.89:36876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4kwUEhLvMuMRNpl00KFQABdXo"]
[Mon Jul 20 07:38:09.696802 2026] [security2:error] [pid 171532:tid 171677] [client 14.225.17.146:53235] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4kwEEhLvMuMRNpl00J1gAAARk"], referer: http://cloudspacesgroup.com/bc
[Mon Jul 20 07:38:09.820705 2026] [security2:error] [pid 171532:tid 171636] [remote 100.42.189.89:36876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4kwUEhLvMuMRNpl00KFwABd2c"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:38:09.862425 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:52942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-blog.php"] [unique_id "al4kwUEhLvMuMRNpl00KGgAAAVk"]
[Mon Jul 20 07:38:09.862507 2026] [security2:error] [pid 171532:tid 171741] [client 4.204.201.85:52942] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-blog.php"] [unique_id "al4kwUEhLvMuMRNpl00KGgAAAVk"]
[Mon Jul 20 07:38:09.900557 2026] [security2:error] [pid 164535:tid 164686] [client 14.225.17.146:58716] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4kwTYN371eKRzcKeSB8gAAAJo"], referer: http://transparentservices.online/bc
[Mon Jul 20 07:38:10.067354 2026] [security2:error] [pid 164535:tid 164723] [client 4.204.201.85:54292] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/js/jquery/"] [unique_id "al4kwjYN371eKRzcKeSCAgAAAL8"]
[Mon Jul 20 07:38:10.067449 2026] [security2:error] [pid 164535:tid 164723] [client 4.204.201.85:54292] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/js/jquery/"] [unique_id "al4kwjYN371eKRzcKeSCAgAAAL8"]
[Mon Jul 20 07:38:10.079730 2026] [security2:error] [pid 171532:tid 171669] [client 98.159.234.160:48377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kwkEhLvMuMRNpl00KJgAAARE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:38:10.126226 2026] [security2:error] [pid 171532:tid 171781] [client 14.225.17.146:53279] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4kwkEhLvMuMRNpl00KJQAAAYA"], referer: https://nurturemarple.co.uk/bc
[Mon Jul 20 07:38:10.134141 2026] [security2:error] [pid 171532:tid 171765] [client 57.141.18.12:29472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kvEEhLvMuMRNpl00I6QABcXQ"]
[Mon Jul 20 07:38:10.166792 2026] [security2:error] [pid 171532:tid 171704] [client 17.241.227.215:35488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.allergyantidotes.com"] [uri "/index.php"] [unique_id "al4kwkEhLvMuMRNpl00KJwABNEo"]
[Mon Jul 20 07:38:10.240418 2026] [security2:error] [pid 171532:tid 171668] [client 4.204.201.85:49411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/admin.php"] [unique_id "al4kwkEhLvMuMRNpl00KLgAAARA"]
[Mon Jul 20 07:38:10.240509 2026] [security2:error] [pid 171532:tid 171668] [client 4.204.201.85:49411] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/admin.php"] [unique_id "al4kwkEhLvMuMRNpl00KLgAAARA"]
[Mon Jul 20 07:38:10.258575 2026] [security2:error] [pid 164535:tid 164665] [client 188.166.209.66:59444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/PHPMailer/OAuth.php"] [unique_id "al4kwjYN371eKRzcKeSCCQAAAIU"], referer: binance.com
[Mon Jul 20 07:38:10.420427 2026] [security2:error] [pid 164535:tid 164711] [client 4.204.201.85:52928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/adminfuns.php"] [unique_id "al4kwjYN371eKRzcKeSCEwAAALM"]
[Mon Jul 20 07:38:10.420514 2026] [security2:error] [pid 164535:tid 164711] [client 4.204.201.85:52928] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/adminfuns.php"] [unique_id "al4kwjYN371eKRzcKeSCEwAAALM"]
[Mon Jul 20 07:38:10.584337 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:54351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/goods.php"] [unique_id "al4kwkEhLvMuMRNpl00KRQAAAV4"]
[Mon Jul 20 07:38:10.584450 2026] [security2:error] [pid 171532:tid 171746] [client 4.204.201.85:54351] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/goods.php"] [unique_id "al4kwkEhLvMuMRNpl00KRQAAAV4"]
[Mon Jul 20 07:38:10.587925 2026] [security2:error] [pid 171532:tid 171756] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kwkEhLvMuMRNpl00KLwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:10.674039 2026] [security2:error] [pid 164535:tid 164669] [client 65.111.22.60:43161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kwjYN371eKRzcKeSCHAAAAIk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:10.738514 2026] [security2:error] [pid 171532:tid 171710] [client 4.204.201.85:52967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ms-edit.php"] [unique_id "al4kwkEhLvMuMRNpl00KTAAAATo"]
[Mon Jul 20 07:38:10.738607 2026] [security2:error] [pid 171532:tid 171710] [client 4.204.201.85:52967] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ms-edit.php"] [unique_id "al4kwkEhLvMuMRNpl00KTAAAATo"]
[Mon Jul 20 07:38:10.903721 2026] [security2:error] [pid 171532:tid 171668] [client 4.204.201.85:49488] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/222.php"] [unique_id "al4kwkEhLvMuMRNpl00KXgAAARA"]
[Mon Jul 20 07:38:10.903861 2026] [security2:error] [pid 171532:tid 171668] [client 4.204.201.85:49488] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/222.php"] [unique_id "al4kwkEhLvMuMRNpl00KXgAAARA"]
[Mon Jul 20 07:38:10.923444 2026] [security2:error] [pid 171532:tid 171674] [client 57.141.18.31:39590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kvUEhLvMuMRNpl00JFAABFgc"]
[Mon Jul 20 07:38:10.991392 2026] [security2:error] [pid 171532:tid 171776] [client 57.141.18.34:58544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kvUEhLvMuMRNpl00JHQABe2M"]
[Mon Jul 20 07:38:11.032695 2026] [security2:error] [pid 171532:tid 171764] [client 4.204.201.85:54356] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/cgi-bin/index.php"] [unique_id "al4kw0EhLvMuMRNpl00KaQAAAXA"]
[Mon Jul 20 07:38:11.032800 2026] [security2:error] [pid 171532:tid 171764] [client 4.204.201.85:54356] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/cgi-bin/index.php"] [unique_id "al4kw0EhLvMuMRNpl00KaQAAAXA"]
[Mon Jul 20 07:38:11.064713 2026] [security2:error] [pid 171532:tid 171683] [client 57.141.18.11:62772] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kvUEhLvMuMRNpl00JIwABHwY"]
[Mon Jul 20 07:38:11.118107 2026] [security2:error] [pid 164535:tid 164774] [client 154.192.233.184:60742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kwzYN371eKRzcKeSCIgAAAPI"]
[Mon Jul 20 07:38:11.118250 2026] [security2:error] [pid 164535:tid 164774] [client 154.192.233.184:60742] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kwzYN371eKRzcKeSCIgAAAPI"]
[Mon Jul 20 07:38:11.170175 2026] [security2:error] [pid 171532:tid 171767] [client 4.204.201.85:52892] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/css/dist/"] [unique_id "al4kw0EhLvMuMRNpl00KdAAAAXM"]
[Mon Jul 20 07:38:11.170308 2026] [security2:error] [pid 171532:tid 171767] [client 4.204.201.85:52892] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/css/dist/"] [unique_id "al4kw0EhLvMuMRNpl00KdAAAAXM"]
[Mon Jul 20 07:38:11.302537 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:49530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/BDKR28WP.php"] [unique_id "al4kwzYN371eKRzcKeSCJAAAAOA"]
[Mon Jul 20 07:38:11.302642 2026] [security2:error] [pid 164535:tid 164756] [client 4.204.201.85:49530] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/BDKR28WP.php"] [unique_id "al4kwzYN371eKRzcKeSCJAAAAOA"]
[Mon Jul 20 07:38:11.389405 2026] [security2:error] [pid 164535:tid 164744] [client 103.176.215.66:65430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kwzYN371eKRzcKeSCJQAAANQ"]
[Mon Jul 20 07:38:11.389769 2026] [security2:error] [pid 164535:tid 164744] [client 103.176.215.66:65430] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kwzYN371eKRzcKeSCJQAAANQ"]
[Mon Jul 20 07:38:11.469325 2026] [security2:error] [pid 164535:tid 164766] [client 4.204.201.85:54287] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/l10n/"] [unique_id "al4kwzYN371eKRzcKeSCLAAAAOo"]
[Mon Jul 20 07:38:11.469419 2026] [security2:error] [pid 164535:tid 164766] [client 4.204.201.85:54287] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/l10n/"] [unique_id "al4kwzYN371eKRzcKeSCLAAAAOo"]
[Mon Jul 20 07:38:11.627220 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:54331] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/uploads/"] [unique_id "al4kw0EhLvMuMRNpl00KjQAAAWI"]
[Mon Jul 20 07:38:11.627308 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:54331] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/uploads/"] [unique_id "al4kw0EhLvMuMRNpl00KjQAAAWI"]
[Mon Jul 20 07:38:11.715961 2026] [core:error] [pid 171532:tid 171705] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:11.715989 2026] [core:error] [pid 171532:tid 171705] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:11.726350 2026] [security2:error] [pid 171532:tid 171735] [client 17.241.227.210:43632] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4kw0EhLvMuMRNpl00KkQABUyY"]
[Mon Jul 20 07:38:11.788063 2026] [security2:error] [pid 164535:tid 164737] [client 4.204.201.85:52966] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp.php"] [unique_id "al4kwzYN371eKRzcKeSCMgAAAM0"]
[Mon Jul 20 07:38:11.788159 2026] [security2:error] [pid 164535:tid 164737] [client 4.204.201.85:52966] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp.php"] [unique_id "al4kwzYN371eKRzcKeSCMgAAAM0"]
[Mon Jul 20 07:38:11.950356 2026] [security2:error] [pid 164535:tid 164675] [client 4.204.201.85:49520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/abcd.php"] [unique_id "al4kwzYN371eKRzcKeSCNwAAAI8"]
[Mon Jul 20 07:38:11.950486 2026] [security2:error] [pid 164535:tid 164675] [client 4.204.201.85:49520] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/abcd.php"] [unique_id "al4kwzYN371eKRzcKeSCNwAAAI8"]
[Mon Jul 20 07:38:12.084203 2026] [security2:error] [pid 171532:tid 171752] [client 4.204.201.85:52937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/a1.php"] [unique_id "al4kxEEhLvMuMRNpl00KqgAAAWQ"]
[Mon Jul 20 07:38:12.084341 2026] [security2:error] [pid 171532:tid 171752] [client 4.204.201.85:52937] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/a1.php"] [unique_id "al4kxEEhLvMuMRNpl00KqgAAAWQ"]
[Mon Jul 20 07:38:12.119623 2026] [security2:error] [pid 171532:tid 171723] [client 14.225.17.146:53255] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4kw0EhLvMuMRNpl00KoAAAAUc"], referer: http://adirondackengineering.com/bc
[Mon Jul 20 07:38:12.121811 2026] [security2:error] [pid 171532:tid 171747] [client 104.207.58.36:43631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 36.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kxEEhLvMuMRNpl00KqwAAAV8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:12.150943 2026] [security2:error] [pid 171532:tid 171683] [client 104.207.53.239:26759] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 239.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4kxEEhLvMuMRNpl00KrgAAAR8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:12.218779 2026] [security2:error] [pid 164535:tid 164743] [client 4.204.201.85:54380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4kxDYN371eKRzcKeSCPgAAANM"]
[Mon Jul 20 07:38:12.218861 2026] [security2:error] [pid 164535:tid 164743] [client 4.204.201.85:54380] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/Text/Diff/Engine/about.php"] [unique_id "al4kxDYN371eKRzcKeSCPgAAANM"]
[Mon Jul 20 07:38:12.310683 2026] [security2:error] [pid 164535:tid 164780] [client 191.202.66.27:56950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kxDYN371eKRzcKeSCQAAAAPg"]
[Mon Jul 20 07:38:12.310785 2026] [security2:error] [pid 164535:tid 164780] [client 191.202.66.27:56950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kxDYN371eKRzcKeSCQAAAAPg"]
[Mon Jul 20 07:38:12.363921 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:54389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/cgi-bin/admin.php"] [unique_id "al4kxEEhLvMuMRNpl00KuQAAAXs"]
[Mon Jul 20 07:38:12.364024 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:54389] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/cgi-bin/admin.php"] [unique_id "al4kxEEhLvMuMRNpl00KuQAAAXs"]
[Mon Jul 20 07:38:12.386791 2026] [security2:error] [pid 171532:tid 171708] [client 136.158.60.21:5328] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kxEEhLvMuMRNpl00KvAAAATg"]
[Mon Jul 20 07:38:12.386928 2026] [security2:error] [pid 171532:tid 171708] [client 136.158.60.21:5328] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kxEEhLvMuMRNpl00KvAAAATg"]
[Mon Jul 20 07:38:12.527787 2026] [security2:error] [pid 164535:tid 164768] [client 4.204.201.85:52957] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/gettest.php"] [unique_id "al4kxDYN371eKRzcKeSCQwAAAOw"]
[Mon Jul 20 07:38:12.527928 2026] [security2:error] [pid 164535:tid 164768] [client 4.204.201.85:52957] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/gettest.php"] [unique_id "al4kxDYN371eKRzcKeSCQwAAAOw"]
[Mon Jul 20 07:38:12.697760 2026] [security2:error] [pid 171532:tid 171694] [client 4.204.201.85:54274] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/"] [unique_id "al4kxEEhLvMuMRNpl00KzAAAASo"]
[Mon Jul 20 07:38:12.697868 2026] [security2:error] [pid 171532:tid 171694] [client 4.204.201.85:54274] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-content/"] [unique_id "al4kxEEhLvMuMRNpl00KzAAAASo"]
[Mon Jul 20 07:38:12.745679 2026] [security2:error] [pid 164535:tid 164720] [client 65.111.27.42:40625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.27.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kxDYN371eKRzcKeSCSAAAALw"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:12.769818 2026] [security2:error] [pid 171532:tid 171786] [client 179.127.84.238:60898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kxEEhLvMuMRNpl00KzwAAAYU"]
[Mon Jul 20 07:38:12.769961 2026] [security2:error] [pid 171532:tid 171786] [client 179.127.84.238:60898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kxEEhLvMuMRNpl00KzwAAAYU"]
[Mon Jul 20 07:38:12.844481 2026] [security2:error] [pid 171532:tid 171726] [client 57.141.18.49:59988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kv0EhLvMuMRNpl00JhAABSnE"]
[Mon Jul 20 07:38:12.869386 2026] [security2:error] [pid 164535:tid 164779] [client 4.204.201.85:54392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/simple.php"] [unique_id "al4kxDYN371eKRzcKeSCTAAAAPc"]
[Mon Jul 20 07:38:12.869498 2026] [security2:error] [pid 164535:tid 164779] [client 4.204.201.85:54392] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/simple.php"] [unique_id "al4kxDYN371eKRzcKeSCTAAAAPc"]
[Mon Jul 20 07:38:12.997353 2026] [security2:error] [pid 164535:tid 164694] [client 4.204.201.85:52922] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/xxx.php"] [unique_id "al4kxDYN371eKRzcKeSCUwAAAKI"]
[Mon Jul 20 07:38:12.997473 2026] [security2:error] [pid 164535:tid 164694] [client 4.204.201.85:52922] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/xxx.php"] [unique_id "al4kxDYN371eKRzcKeSCUwAAAKI"]
[Mon Jul 20 07:38:13.154852 2026] [security2:error] [pid 171532:tid 171774] [client 4.204.201.85:54322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/hypo.php"] [unique_id "al4kxUEhLvMuMRNpl00K2wAAAXk"]
[Mon Jul 20 07:38:13.154977 2026] [security2:error] [pid 171532:tid 171774] [client 4.204.201.85:54322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/hypo.php"] [unique_id "al4kxUEhLvMuMRNpl00K2wAAAXk"]
[Mon Jul 20 07:38:13.262469 2026] [security2:error] [pid 171532:tid 171764] [client 14.225.17.146:53260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4kw0EhLvMuMRNpl00KpQAAAXA"], referer: http://effingweirdmuseums.com/bc
[Mon Jul 20 07:38:13.297754 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:63354] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al4kxUEhLvMuMRNpl00K3wAAAWI"]
[Mon Jul 20 07:38:13.297831 2026] [security2:error] [pid 171532:tid 171750] [client 4.204.201.85:63354] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-admin/css/colors/blue/"] [unique_id "al4kxUEhLvMuMRNpl00K3wAAAWI"]
[Mon Jul 20 07:38:13.385020 2026] [security2:error] [pid 164535:tid 164707] [client 103.139.191.61:59861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kxTYN371eKRzcKeSCXgAAAK8"]
[Mon Jul 20 07:38:13.385109 2026] [security2:error] [pid 164535:tid 164707] [client 103.139.191.61:59861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4kxTYN371eKRzcKeSCXgAAAK8"]
[Mon Jul 20 07:38:13.471904 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:52980] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/chosen.php"] [unique_id "al4kxUEhLvMuMRNpl00K8gAAAVg"]
[Mon Jul 20 07:38:13.472029 2026] [security2:error] [pid 171532:tid 171740] [client 4.204.201.85:52980] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/chosen.php"] [unique_id "al4kxUEhLvMuMRNpl00K8gAAAVg"]
[Mon Jul 20 07:38:13.481612 2026] [security2:error] [pid 164535:tid 164786] [client 14.225.17.146:51609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4kxTYN371eKRzcKeSCXQAAAP4"], referer: http://detroitcsc.com/bc
[Mon Jul 20 07:38:13.665036 2026] [security2:error] [pid 164535:tid 164722] [client 4.204.201.85:54361] ModSecurity: Access denied with code 406 (phase 1). Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1574"] [id "900936"] [msg "Empty UA autodiscover"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/block-bindings/"] [unique_id "al4kxTYN371eKRzcKeSCZQAAAL4"]
[Mon Jul 20 07:38:13.665167 2026] [security2:error] [pid 164535:tid 164722] [client 4.204.201.85:54361] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "406"] [hostname "autodiscover.cimahmo.pro"] [uri "/wp-includes/block-bindings/"] [unique_id "al4kxTYN371eKRzcKeSCZQAAAL4"]
[Mon Jul 20 07:38:13.689676 2026] [security2:error] [pid 171532:tid 171685] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kxUEhLvMuMRNpl00K8wAAASE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:13.726825 2026] [security2:error] [pid 171532:tid 171777] [client 212.241.29.16:4909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4kxUEhLvMuMRNpl00K9wABfAk"]
[Mon Jul 20 07:38:13.876887 2026] [security2:error] [pid 171532:tid 171665] [client 4.204.201.85:54373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/als.php"] [unique_id "al4kxUEhLvMuMRNpl00LCgAAAQ0"]
[Mon Jul 20 07:38:13.877013 2026] [security2:error] [pid 171532:tid 171665] [client 4.204.201.85:54373] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/als.php"] [unique_id "al4kxUEhLvMuMRNpl00LCgAAAQ0"]
[Mon Jul 20 07:38:14.012643 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:49504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/pol.php"] [unique_id "al4kxkEhLvMuMRNpl00LEQAAAXs"]
[Mon Jul 20 07:38:14.012773 2026] [security2:error] [pid 171532:tid 171776] [client 4.204.201.85:49504] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/pol.php"] [unique_id "al4kxkEhLvMuMRNpl00LEQAAAXs"]
[Mon Jul 20 07:38:14.136145 2026] [security2:error] [pid 171532:tid 171754] [client 4.204.201.85:52911] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/file5.php"] [unique_id "al4kxkEhLvMuMRNpl00LFwAAAWY"]
[Mon Jul 20 07:38:14.136254 2026] [security2:error] [pid 171532:tid 171754] [client 4.204.201.85:52911] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/file5.php"] [unique_id "al4kxkEhLvMuMRNpl00LFwAAAWY"]
[Mon Jul 20 07:38:14.283800 2026] [security2:error] [pid 164535:tid 164738] [client 14.225.17.146:53805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4kxjYN371eKRzcKeSCdgAAAM4"], referer: https://effingweirdmuseums.com/bc
[Mon Jul 20 07:38:14.308026 2026] [security2:error] [pid 171532:tid 171609] [remote 173.212.252.15:55892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kxkEhLvMuMRNpl00LIwABG0w"]
[Mon Jul 20 07:38:14.313208 2026] [security2:error] [pid 171532:tid 171685] [client 4.204.201.85:52945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/file.php"] [unique_id "al4kxkEhLvMuMRNpl00LJQAAASE"]
[Mon Jul 20 07:38:14.313294 2026] [security2:error] [pid 171532:tid 171685] [client 4.204.201.85:52945] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/file.php"] [unique_id "al4kxkEhLvMuMRNpl00LJQAAASE"]
[Mon Jul 20 07:38:14.331036 2026] [security2:error] [pid 171532:tid 171673] [client 14.225.17.146:58669] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4kxEEhLvMuMRNpl00K0gAAARU"], referer: http://sarahsnyder.net/bc
[Mon Jul 20 07:38:14.487027 2026] [security2:error] [pid 171532:tid 171737] [client 4.204.201.85:52890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/cfile.php"] [unique_id "al4kxkEhLvMuMRNpl00LLwAAAVU"]
[Mon Jul 20 07:38:14.487110 2026] [security2:error] [pid 171532:tid 171737] [client 4.204.201.85:52890] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/cfile.php"] [unique_id "al4kxkEhLvMuMRNpl00LLwAAAVU"]
[Mon Jul 20 07:38:14.497388 2026] [security2:error] [pid 171532:tid 171549] [remote 173.212.252.15:55892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4kxkEhLvMuMRNpl00LMgABMBA"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:38:14.665543 2026] [security2:error] [pid 171532:tid 171715] [client 4.204.201.85:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/admin.php"] [unique_id "al4kxkEhLvMuMRNpl00LPgAAAT8"]
[Mon Jul 20 07:38:14.665721 2026] [security2:error] [pid 171532:tid 171715] [client 4.204.201.85:54285] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/admin.php"] [unique_id "al4kxkEhLvMuMRNpl00LPgAAAT8"]
[Mon Jul 20 07:38:14.729002 2026] [security2:error] [pid 171532:tid 171762] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kxkEhLvMuMRNpl00LNAAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:14.888949 2026] [security2:error] [pid 164535:tid 164725] [client 4.204.201.85:49423] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/aa2.php"] [unique_id "al4kxjYN371eKRzcKeSCgAAAAME"]
[Mon Jul 20 07:38:14.889050 2026] [security2:error] [pid 164535:tid 164725] [client 4.204.201.85:49423] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/aa2.php"] [unique_id "al4kxjYN371eKRzcKeSCgAAAAME"]
[Mon Jul 20 07:38:15.049782 2026] [security2:error] [pid 164535:tid 164700] [client 4.204.201.85:52991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/ccou.php"] [unique_id "al4kxzYN371eKRzcKeSCgQAAAKg"]
[Mon Jul 20 07:38:15.049896 2026] [security2:error] [pid 164535:tid 164700] [client 4.204.201.85:52991] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/ccou.php"] [unique_id "al4kxzYN371eKRzcKeSCgQAAAKg"]
[Mon Jul 20 07:38:15.089307 2026] [core:error] [pid 171532:tid 171682] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:15.089326 2026] [core:error] [pid 171532:tid 171682] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:15.188181 2026] [security2:error] [pid 164535:tid 164789] [client 4.204.201.85:52946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/dr.php"] [unique_id "al4kxzYN371eKRzcKeSChAAAAQE"]
[Mon Jul 20 07:38:15.188276 2026] [security2:error] [pid 164535:tid 164789] [client 4.204.201.85:52946] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/dr.php"] [unique_id "al4kxzYN371eKRzcKeSChAAAAQE"]
[Mon Jul 20 07:38:15.279396 2026] [security2:error] [pid 171532:tid 171722] [client 57.141.18.69:33672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kwkEhLvMuMRNpl00KMwABRgM"]
[Mon Jul 20 07:38:15.322902 2026] [security2:error] [pid 164535:tid 164697] [client 4.204.201.85:52871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/xamp.php"] [unique_id "al4kxzYN371eKRzcKeSCiQAAAKU"]
[Mon Jul 20 07:38:15.322989 2026] [security2:error] [pid 164535:tid 164697] [client 4.204.201.85:52871] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/xamp.php"] [unique_id "al4kxzYN371eKRzcKeSCiQAAAKU"]
[Mon Jul 20 07:38:15.473684 2026] [security2:error] [pid 171532:tid 171768] [client 14.225.17.146:53697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4kx0EhLvMuMRNpl00LZAAAAXQ"], referer: https://sarahsnyder.net/bc
[Mon Jul 20 07:38:15.493785 2026] [security2:error] [pid 164535:tid 164748] [client 57.141.18.103:58744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kwjYN371eKRzcKeSCGwAA2HE"]
[Mon Jul 20 07:38:15.607939 2026] [security2:error] [pid 171532:tid 171668] [client 4.204.201.85:54286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/bless.php"] [unique_id "al4kx0EhLvMuMRNpl00LdQAAARA"]
[Mon Jul 20 07:38:15.608084 2026] [security2:error] [pid 171532:tid 171668] [client 4.204.201.85:54286] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/bless.php"] [unique_id "al4kx0EhLvMuMRNpl00LdQAAARA"]
[Mon Jul 20 07:38:15.782929 2026] [security2:error] [pid 171532:tid 171783] [client 4.204.201.85:49417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/file25.php"] [unique_id "al4kx0EhLvMuMRNpl00LgAAAAYI"]
[Mon Jul 20 07:38:15.783030 2026] [security2:error] [pid 171532:tid 171783] [client 4.204.201.85:49417] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/file25.php"] [unique_id "al4kx0EhLvMuMRNpl00LgAAAAYI"]
[Mon Jul 20 07:38:15.864040 2026] [security2:error] [pid 164535:tid 164747] [client 49.47.218.174:61440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kxzYN371eKRzcKeSCkwAAANc"]
[Mon Jul 20 07:38:15.864155 2026] [security2:error] [pid 164535:tid 164747] [client 49.47.218.174:61440] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4kxzYN371eKRzcKeSCkwAAANc"]
[Mon Jul 20 07:38:15.906336 2026] [security2:error] [pid 171532:tid 171687] [client 4.204.201.85:54280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.201.204.4.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.cimahmo.pro"] [uri "/file6.php"] [unique_id "al4kx0EhLvMuMRNpl00LhgAAASM"]
[Mon Jul 20 07:38:15.906454 2026] [security2:error] [pid 171532:tid 171687] [client 4.204.201.85:54280] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "autodiscover.cimahmo.pro"] [uri "/file6.php"] [unique_id "al4kx0EhLvMuMRNpl00LhgAAASM"]
[Mon Jul 20 07:38:16.033625 2026] [security2:error] [pid 164535:tid 164719] [client 188.166.209.66:62362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/PHPMailer/OAuthTokenProvider.php"] [unique_id "al4kyDYN371eKRzcKeSCmQAAALs"], referer: binance.com
[Mon Jul 20 07:38:16.145586 2026] [security2:error] [pid 171532:tid 171696] [client 57.141.18.14:38190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kw0EhLvMuMRNpl00KgwABLAw"]
[Mon Jul 20 07:38:16.340126 2026] [security2:error] [pid 171532:tid 171691] [client 14.225.17.146:60711] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4kxkEhLvMuMRNpl00LQwAAASc"], referer: http://careysheatingandcooling.com/bc
[Mon Jul 20 07:38:16.347181 2026] [security2:error] [pid 171532:tid 171662] [client 180.249.173.210:57622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kyEEhLvMuMRNpl00LlwAAAQo"]
[Mon Jul 20 07:38:16.347584 2026] [security2:error] [pid 171532:tid 171662] [client 180.249.173.210:57622] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4kyEEhLvMuMRNpl00LlwAAAQo"]
[Mon Jul 20 07:38:16.964654 2026] [security2:error] [pid 171532:tid 171751] [client 14.225.17.146:59723] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4kyEEhLvMuMRNpl00LsgAAAWM"], referer: http://ravmike.com/bc
[Mon Jul 20 07:38:17.019641 2026] [security2:error] [pid 171532:tid 171680] [client 143.44.185.218:8613] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kyUEhLvMuMRNpl00LuAAAARw"]
[Mon Jul 20 07:38:17.019719 2026] [security2:error] [pid 171532:tid 171680] [client 143.44.185.218:8613] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4kyUEhLvMuMRNpl00LuAAAARw"]
[Mon Jul 20 07:38:17.151981 2026] [security2:error] [pid 164535:tid 164691] [client 57.141.18.108:60852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxDYN371eKRzcKeSCPQAAnzU"]
[Mon Jul 20 07:38:17.161683 2026] [security2:error] [pid 164535:tid 164727] [client 114.119.157.82:54251] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "bluedoorbar.co.nz"] [uri "/pagine/94074-LUCQYLHTS.html"] [unique_id "al4kyTYN371eKRzcKeSCwQAAAMM"], referer: http://bluedoorbar.co.nz/pagine/94074-LUCQYLHTS.html
[Mon Jul 20 07:38:17.176130 2026] [security2:error] [pid 171532:tid 171663] [client 157.20.138.62:63969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kyUEhLvMuMRNpl00LuwAAAQs"]
[Mon Jul 20 07:38:17.176224 2026] [security2:error] [pid 171532:tid 171663] [client 157.20.138.62:63969] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kyUEhLvMuMRNpl00LuwAAAQs"]
[Mon Jul 20 07:38:17.266788 2026] [security2:error] [pid 164535:tid 164775] [client 57.141.18.107:44636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxDYN371eKRzcKeSCPwAA80U"]
[Mon Jul 20 07:38:17.281299 2026] [security2:error] [pid 164535:tid 164765] [client 14.225.17.146:60976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4kxzYN371eKRzcKeSCiAAAAOk"], referer: http://mollycahill.com/bc
[Mon Jul 20 07:38:17.394500 2026] [security2:error] [pid 164535:tid 164665] [client 14.225.17.146:59804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4kyTYN371eKRzcKeSCvgAAAIU"], referer: http://partnerselectricalllc.com/bc
[Mon Jul 20 07:38:17.849900 2026] [security2:error] [pid 164535:tid 164701] [client 57.141.18.102:22586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxDYN371eKRzcKeSCTwAAqT4"]
[Mon Jul 20 07:38:17.942357 2026] [security2:error] [pid 164535:tid 164676] [client 49.37.242.14:64346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kyTYN371eKRzcKeSC5gAAAJA"]
[Mon Jul 20 07:38:17.942471 2026] [security2:error] [pid 164535:tid 164676] [client 49.37.242.14:64346] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4kyTYN371eKRzcKeSC5gAAAJA"]
[Mon Jul 20 07:38:17.972041 2026] [security2:error] [pid 171532:tid 171771] [client 14.225.17.146:60043] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4kyUEhLvMuMRNpl00L4AAAAXc"], referer: https://ravmike.com/bc
[Mon Jul 20 07:38:18.207300 2026] [security2:error] [pid 171532:tid 171703] [client 57.141.18.70:23798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxUEhLvMuMRNpl00K4gABM28"]
[Mon Jul 20 07:38:18.211420 2026] [security2:error] [pid 171532:tid 171733] [client 155.2.215.90:35543] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L4wAAAVE"]
[Mon Jul 20 07:38:18.215633 2026] [security2:error] [pid 164535:tid 164561] [remote 57.141.18.88:27590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6013275"] [unique_id "al4kyjYN371eKRzcKeSC6QAAoBk"]
[Mon Jul 20 07:38:18.234056 2026] [security2:error] [pid 171532:tid 171707] [client 36.93.152.155:55778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L6wAAATc"]
[Mon Jul 20 07:38:18.234174 2026] [security2:error] [pid 171532:tid 171707] [client 36.93.152.155:55778] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L6wAAATc"]
[Mon Jul 20 07:38:18.372919 2026] [security2:error] [pid 171532:tid 171737] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kykEhLvMuMRNpl00L6gAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:18.385147 2026] [security2:error] [pid 171532:tid 171790] [client 149.0.16.108:51574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L8QAAAYk"]
[Mon Jul 20 07:38:18.385231 2026] [security2:error] [pid 171532:tid 171790] [client 149.0.16.108:51574] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L8QAAAYk"]
[Mon Jul 20 07:38:18.528944 2026] [security2:error] [pid 171532:tid 171766] [client 116.193.128.26:54787] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L-QAAAXI"]
[Mon Jul 20 07:38:18.529040 2026] [security2:error] [pid 171532:tid 171766] [client 116.193.128.26:54787] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00L-QAAAXI"]
[Mon Jul 20 07:38:18.626468 2026] [security2:error] [pid 171532:tid 171711] [client 154.192.123.127:17929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00MAAAAATs"]
[Mon Jul 20 07:38:18.626569 2026] [security2:error] [pid 171532:tid 171711] [client 154.192.123.127:17929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4kykEhLvMuMRNpl00MAAAAATs"]
[Mon Jul 20 07:38:19.074739 2026] [security2:error] [pid 164535:tid 164666] [client 57.141.18.87:63822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxjYN371eKRzcKeSCcgAAhlQ"]
[Mon Jul 20 07:38:19.075798 2026] [security2:error] [pid 171532:tid 171671] [client 103.106.165.44:60626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ky0EhLvMuMRNpl00MFAAAARM"]
[Mon Jul 20 07:38:19.075931 2026] [security2:error] [pid 171532:tid 171671] [client 103.106.165.44:60626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ky0EhLvMuMRNpl00MFAAAARM"]
[Mon Jul 20 07:38:19.090542 2026] [security2:error] [pid 171532:tid 171742] [client 116.74.65.235:49979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ky0EhLvMuMRNpl00MEwAAAVo"]
[Mon Jul 20 07:38:19.090691 2026] [security2:error] [pid 171532:tid 171742] [client 116.74.65.235:49979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4ky0EhLvMuMRNpl00MEwAAAVo"]
[Mon Jul 20 07:38:19.143620 2026] [security2:error] [pid 171532:tid 171577] [remote 72.167.132.114:43450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4ky0EhLvMuMRNpl00MFgABDSw"]
[Mon Jul 20 07:38:19.377321 2026] [security2:error] [pid 171532:tid 171660] [remote 72.167.132.114:43450] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4ky0EhLvMuMRNpl00MHwABC38"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 07:38:19.385642 2026] [security2:error] [pid 171532:tid 171712] [client 57.141.18.13:21894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxkEhLvMuMRNpl00LLQABPFE"]
[Mon Jul 20 07:38:19.667965 2026] [security2:error] [pid 171532:tid 171721] [client 57.141.18.70:23804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxkEhLvMuMRNpl00LRAABRQg"]
[Mon Jul 20 07:38:19.824725 2026] [security2:error] [pid 171532:tid 171724] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ky0EhLvMuMRNpl00MJgAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:19.944238 2026] [security2:error] [pid 164535:tid 164676] [client 13.221.132.12:31506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.132.221.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kyzYN371eKRzcKeSDFwAAAJA"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.031721 2026] [security2:error] [pid 171532:tid 171777] [client 3.90.176.61:60654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.176.90.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4ky0EhLvMuMRNpl00MOAAAAXw"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.047963 2026] [security2:error] [pid 164535:tid 164733] [client 54.81.157.232:37464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.157.81.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kzDYN371eKRzcKeSDIAAAAMk"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.193922 2026] [security2:error] [pid 171532:tid 171753] [client 54.162.148.64:30924] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.148.162.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MQwAAAWU"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.223820 2026] [security2:error] [pid 171532:tid 171783] [client 32.198.12.77:19672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.12.198.32.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MTAAAAYI"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.223955 2026] [security2:error] [pid 171532:tid 171675] [client 3.89.37.207:49348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.37.89.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MSwAAARc"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.269209 2026] [security2:error] [pid 171532:tid 171712] [client 50.116.65.227:51446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4kzEEhLvMuMRNpl00MVAAAATw"]
[Mon Jul 20 07:38:20.280301 2026] [security2:error] [pid 171532:tid 171735] [client 50.116.65.227:51452] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4kzEEhLvMuMRNpl00MVQAAAVM"]
[Mon Jul 20 07:38:20.294172 2026] [security2:error] [pid 171532:tid 171696] [client 3.90.176.61:50062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.176.90.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MVwAAASw"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.302040 2026] [security2:error] [pid 171532:tid 171736] [client 54.198.0.135:49204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.0.198.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MVgAAAVQ"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.333655 2026] [security2:error] [pid 171532:tid 171716] [client 3.87.117.29:46134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.117.87.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MWQAAAUA"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.419068 2026] [security2:error] [pid 171532:tid 171711] [client 98.85.250.161:56162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.250.85.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MXwAAATs"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.431943 2026] [security2:error] [pid 164535:tid 164593] [remote 15.206.251.117:34160] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kzDYN371eKRzcKeSDJgAAwTk"]
[Mon Jul 20 07:38:20.432158 2026] [security2:error] [pid 164535:tid 164725] [client 15.206.251.117:34160] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kzDYN371eKRzcKeSDJgAAwTk"]
[Mon Jul 20 07:38:20.447981 2026] [security2:error] [pid 171532:tid 171757] [client 34.207.130.29:62354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MZAAAAWk"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.505580 2026] [security2:error] [pid 171532:tid 171772] [client 54.204.158.117:13664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.158.204.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MZQAAAXg"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.554255 2026] [security2:error] [pid 164535:tid 164764] [client 54.198.0.135:49210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 135.0.198.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzDYN371eKRzcKeSDKgAAAOg"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:20.628970 2026] [security2:error] [pid 164535:tid 164731] [client 57.141.18.65:31106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kxzYN371eKRzcKeSCkAAAx2U"]
[Mon Jul 20 07:38:20.649847 2026] [security2:error] [pid 171532:tid 171745] [client 57.141.18.1:59106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kx0EhLvMuMRNpl00LggABXTQ"]
[Mon Jul 20 07:38:20.680357 2026] [security2:error] [pid 171532:tid 171787] [client 54.204.130.104:23528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.130.204.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4kzEEhLvMuMRNpl00MegAAAYY"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:21.122827 2026] [security2:error] [pid 171532:tid 171638] [remote 45.76.153.27:52668] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.153.76.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kzUEhLvMuMRNpl00MpAABe2k"]
[Mon Jul 20 07:38:21.123102 2026] [security2:error] [pid 171532:tid 171776] [client 45.76.153.27:52668] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.fvx.wyy.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4kzUEhLvMuMRNpl00MpAABe2k"]
[Mon Jul 20 07:38:21.410697 2026] [security2:error] [pid 171532:tid 171780] [client 57.141.18.55:20300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kyEEhLvMuMRNpl00LpwABf0k"]
[Mon Jul 20 07:38:21.475954 2026] [security2:error] [pid 171532:tid 171672] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kzUEhLvMuMRNpl00MrAAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:21.500694 2026] [security2:error] [pid 171532:tid 171786] [client 14.225.17.146:60280] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4kzUEhLvMuMRNpl00MqgAAAYU"], referer: http://mcg.homes/bc
[Mon Jul 20 07:38:21.594416 2026] [security2:error] [pid 171532:tid 171766] [client 14.225.17.146:61167] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4kzEEhLvMuMRNpl00MjAAAAXI"], referer: http://gearwaterproof.com/bc
[Mon Jul 20 07:38:21.686003 2026] [security2:error] [pid 171532:tid 171669] [client 154.192.233.184:61242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kzUEhLvMuMRNpl00MwgAAARE"]
[Mon Jul 20 07:38:21.686131 2026] [security2:error] [pid 171532:tid 171669] [client 154.192.233.184:61242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4kzUEhLvMuMRNpl00MwgAAARE"]
[Mon Jul 20 07:38:21.865850 2026] [security2:error] [pid 171532:tid 171765] [client 103.176.215.66:49579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kzUEhLvMuMRNpl00MyQAAAXE"]
[Mon Jul 20 07:38:21.866329 2026] [security2:error] [pid 171532:tid 171765] [client 103.176.215.66:49579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4kzUEhLvMuMRNpl00MyQAAAXE"]
[Mon Jul 20 07:38:21.958296 2026] [security2:error] [pid 171532:tid 171591] [remote 72.167.132.114:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4kzUEhLvMuMRNpl00MzwABDzo"]
[Mon Jul 20 07:38:22.085288 2026] [security2:error] [pid 171532:tid 171543] [remote 45.90.123.233:60384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4kzkEhLvMuMRNpl00M1AABaAo"]
[Mon Jul 20 07:38:22.131306 2026] [security2:error] [pid 164535:tid 164769] [client 57.141.18.115:40908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kyTYN371eKRzcKeSCxAAA7QQ"]
[Mon Jul 20 07:38:22.172489 2026] [security2:error] [pid 171532:tid 171582] [remote 72.167.132.114:43456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dlu.cjf.mybluehost.me"] [uri "/blog/wp-login.php"] [unique_id "al4kzkEhLvMuMRNpl00M1wABMDE"], referer: https://dlu.cjf.mybluehost.me/blog/wp-login.php
[Mon Jul 20 07:38:22.234819 2026] [security2:error] [pid 171532:tid 171533] [remote 20.153.140.50:33338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4kzkEhLvMuMRNpl00M2gABVQA"]
[Mon Jul 20 07:38:22.300112 2026] [security2:error] [pid 164535:tid 164745] [client 57.141.18.86:39278] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kyTYN371eKRzcKeSCzgAA1UE"]
[Mon Jul 20 07:38:22.424075 2026] [security2:error] [pid 171532:tid 171688] [client 65.111.28.79:21317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 79.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4kzkEhLvMuMRNpl00M4gAAASQ"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:22.472099 2026] [security2:error] [pid 171532:tid 171686] [client 188.166.209.66:54914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/PHPMailer/POP3.php"] [unique_id "al4kzkEhLvMuMRNpl00M5wAAASI"], referer: binance.com
[Mon Jul 20 07:38:22.588339 2026] [security2:error] [pid 171532:tid 171774] [client 13.233.207.33:32070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4kzkEhLvMuMRNpl00M8AAAAXk"]
[Mon Jul 20 07:38:22.588442 2026] [security2:error] [pid 171532:tid 171774] [client 13.233.207.33:32070] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4kzkEhLvMuMRNpl00M8AAAAXk"]
[Mon Jul 20 07:38:22.638857 2026] [security2:error] [pid 171532:tid 171597] [remote 20.153.140.50:33338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4kzkEhLvMuMRNpl00M9AABiUA"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:38:22.652387 2026] [security2:error] [pid 171532:tid 171672] [client 14.225.17.146:65425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4kzkEhLvMuMRNpl00M5AAAARQ"], referer: http://swafforddetailing.com/bc
[Mon Jul 20 07:38:22.843708 2026] [security2:error] [pid 171532:tid 171669] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kzkEhLvMuMRNpl00M6gAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:22.847442 2026] [security2:error] [pid 171532:tid 171740] [client 57.141.18.117:47854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kyUEhLvMuMRNpl00L1AABWGI"]
[Mon Jul 20 07:38:23.025843 2026] [security2:error] [pid 171532:tid 171681] [client 191.202.66.27:57435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kz0EhLvMuMRNpl00NCQAAAR0"]
[Mon Jul 20 07:38:23.025945 2026] [security2:error] [pid 171532:tid 171681] [client 191.202.66.27:57435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4kz0EhLvMuMRNpl00NCQAAAR0"]
[Mon Jul 20 07:38:23.073712 2026] [security2:error] [pid 171532:tid 171739] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kzkEhLvMuMRNpl00M_gAAAVc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:23.138959 2026] [security2:error] [pid 171532:tid 171736] [client 136.158.60.21:6767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kz0EhLvMuMRNpl00NDgAAAVQ"]
[Mon Jul 20 07:38:23.139076 2026] [security2:error] [pid 171532:tid 171736] [client 136.158.60.21:6767] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4kz0EhLvMuMRNpl00NDgAAAVQ"]
[Mon Jul 20 07:38:23.297566 2026] [security2:error] [pid 171532:tid 171757] [client 179.127.84.238:61436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kz0EhLvMuMRNpl00NGQAAAWk"]
[Mon Jul 20 07:38:23.297668 2026] [security2:error] [pid 171532:tid 171757] [client 179.127.84.238:61436] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4kz0EhLvMuMRNpl00NGQAAAWk"]
[Mon Jul 20 07:38:23.474769 2026] [autoindex:error] [pid 164535:tid 164631] [remote 8.229.41.77:63166] AH01276: Cannot serve directory /home2/yapvjbmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.yap.vjb.mybluehost.me
[Mon Jul 20 07:38:23.830026 2026] [security2:error] [pid 171532:tid 171708] [client 57.141.18.30:46360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kykEhLvMuMRNpl00MAQABOHE"]
[Mon Jul 20 07:38:23.896462 2026] [security2:error] [pid 164535:tid 164629] [remote 188.40.28.4:57028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4kzzYN371eKRzcKeSDcQAAyF0"]
[Mon Jul 20 07:38:24.036139 2026] [security2:error] [pid 171532:tid 171700] [client 50.116.65.227:51504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4k0EEhLvMuMRNpl00NRgAAATA"]
[Mon Jul 20 07:38:24.041198 2026] [security2:error] [pid 164535:tid 164676] [client 14.225.17.146:63171] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4kzjYN371eKRzcKeSDUgAAAJA"], referer: http://recruitinginsight.us/bc
[Mon Jul 20 07:38:24.103416 2026] [security2:error] [pid 164535:tid 164750] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4kzzYN371eKRzcKeSDbAAAANo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:24.141862 2026] [security2:error] [pid 164535:tid 164613] [remote 188.40.28.4:57028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "youpositive.co"] [uri "/wp-login.php"] [unique_id "al4k0DYN371eKRzcKeSDdQAAh00"], referer: https://youpositive.co/wp-login.php
[Mon Jul 20 07:38:24.242618 2026] [security2:error] [pid 171532:tid 171754] [client 57.141.18.20:31778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ky0EhLvMuMRNpl00MFQABZj0"]
[Mon Jul 20 07:38:24.372632 2026] [security2:error] [pid 164535:tid 164719] [client 57.141.18.18:35476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kyzYN371eKRzcKeSDBAAAuzQ"]
[Mon Jul 20 07:38:24.427727 2026] [security2:error] [pid 171532:tid 171764] [client 103.139.191.61:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k0EEhLvMuMRNpl00NWgAAAXA"]
[Mon Jul 20 07:38:24.427820 2026] [security2:error] [pid 171532:tid 171764] [client 103.139.191.61:60351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k0EEhLvMuMRNpl00NWgAAAXA"]
[Mon Jul 20 07:38:24.637818 2026] [security2:error] [pid 164535:tid 164710] [client 54.224.22.173:25494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.224.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4k0DYN371eKRzcKeSDhQAAALI"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:24.909970 2026] [security2:error] [pid 171532:tid 171669] [client 100.31.58.60:32584] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.58.31.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k0EEhLvMuMRNpl00NegAAARE"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:24.914411 2026] [security2:error] [pid 171532:tid 171781] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k0EEhLvMuMRNpl00NbAAAAYA"]
[Mon Jul 20 07:38:25.059593 2026] [security2:error] [pid 171532:tid 171784] [client 54.158.124.211:64190] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.124.158.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4k0UEhLvMuMRNpl00NgQAAAYM"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:25.087067 2026] [security2:error] [pid 171532:tid 171551] [remote 188.40.28.4:54848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k0UEhLvMuMRNpl00NhQABQRI"]
[Mon Jul 20 07:38:25.087247 2026] [security2:error] [pid 171532:tid 171717] [client 188.40.28.4:54848] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "tbd.jxc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k0UEhLvMuMRNpl00NhQABQRI"]
[Mon Jul 20 07:38:25.169966 2026] [security2:error] [pid 171532:tid 171593] [remote 45.90.123.233:60384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/wp-login.php"] [unique_id "al4k0UEhLvMuMRNpl00NiQABdjw"], referer: https://ravmike.com/wp-login.php
[Mon Jul 20 07:38:25.179172 2026] [security2:error] [pid 171532:tid 171738] [client 34.207.130.29:62362] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4k0UEhLvMuMRNpl00NiwAAAVY"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:25.364846 2026] [security2:error] [pid 164535:tid 164782] [client 54.224.22.173:25506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.224.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k0TYN371eKRzcKeSDmgAAAPo"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:25.424708 2026] [security2:error] [pid 171532:tid 171689] [client 34.207.130.29:62364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.130.207.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k0UEhLvMuMRNpl00NlAAAASU"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:25.574077 2026] [security2:error] [pid 164535:tid 164742] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k0TYN371eKRzcKeSDmwAAANI"]
[Mon Jul 20 07:38:25.696465 2026] [security2:error] [pid 171532:tid 171747] [client 57.141.18.114:23540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kzEEhLvMuMRNpl00MaQABX14"]
[Mon Jul 20 07:38:25.980361 2026] [security2:error] [pid 171532:tid 171716] [client 57.141.18.113:53130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kzEEhLvMuMRNpl00MhgABQHo"]
[Mon Jul 20 07:38:26.278563 2026] [security2:error] [pid 171532:tid 171728] [client 14.225.17.146:63304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4k0UEhLvMuMRNpl00NiAAAAUw"], referer: http://sarahholyfield.com/bc
[Mon Jul 20 07:38:26.386346 2026] [security2:error] [pid 171532:tid 171697] [client 49.47.218.174:61979] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k0kEhLvMuMRNpl00NzgAAAS0"]
[Mon Jul 20 07:38:26.386456 2026] [security2:error] [pid 171532:tid 171697] [client 49.47.218.174:61979] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k0kEhLvMuMRNpl00NzgAAAS0"]
[Mon Jul 20 07:38:26.583921 2026] [security2:error] [pid 164535:tid 164743] [client 54.196.52.99:24484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.52.196.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4k0jYN371eKRzcKeSDwQAAANM"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:26.736148 2026] [security2:error] [pid 171532:tid 171606] [remote 103.118.29.185:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4k0kEhLvMuMRNpl00N4wABCkk"]
[Mon Jul 20 07:38:26.863629 2026] [security2:error] [pid 171532:tid 171767] [client 100.26.198.54:24606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.198.26.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k0kEhLvMuMRNpl00N8AAAAXM"], referer: https://curlsnpearlsss.com/es/limber-de-morir-sonando-orange-creamsicle-ice-pops/
[Mon Jul 20 07:38:27.006452 2026] [security2:error] [pid 171532:tid 171681] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k0kEhLvMuMRNpl00N7AAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:27.135000 2026] [security2:error] [pid 171532:tid 171534] [remote 103.118.29.185:37860] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4k00EhLvMuMRNpl00N_QABYgE"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 07:38:27.166404 2026] [security2:error] [pid 171532:tid 171712] [client 57.141.18.24:42492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kzUEhLvMuMRNpl00MzQABPFc"]
[Mon Jul 20 07:38:27.196087 2026] [security2:error] [pid 171532:tid 171731] [client 173.239.224.27:59521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "spencersadventures.com"] [uri "/wp-login.php"] [unique_id "al4k00EhLvMuMRNpl00OAQAAAU8"]
[Mon Jul 20 07:38:27.269491 2026] [security2:error] [pid 164535:tid 164776] [client 173.239.224.38:53355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 38.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dollpassionista.com"] [uri "/wp-login.php"] [unique_id "al4k0zYN371eKRzcKeSD2gAAAPQ"]
[Mon Jul 20 07:38:27.310501 2026] [security2:error] [pid 171532:tid 171737] [client 180.249.173.210:58100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OCQAAAVU"]
[Mon Jul 20 07:38:27.311189 2026] [security2:error] [pid 171532:tid 171737] [client 180.249.173.210:58100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OCQAAAVU"]
[Mon Jul 20 07:38:27.467013 2026] [security2:error] [pid 164535:tid 164693] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k0zYN371eKRzcKeSD2QAAAKE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:27.697134 2026] [security2:error] [pid 171532:tid 171759] [client 157.20.138.62:64570] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OHAAAAWs"]
[Mon Jul 20 07:38:27.698470 2026] [security2:error] [pid 171532:tid 171759] [client 157.20.138.62:64570] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OHAAAAWs"]
[Mon Jul 20 07:38:27.704633 2026] [security2:error] [pid 171532:tid 171533] [remote 120.72.98.5:35772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OGgABeQA"]
[Mon Jul 20 07:38:27.704875 2026] [security2:error] [pid 171532:tid 171774] [client 120.72.98.5:35772] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OGgABeQA"]
[Mon Jul 20 07:38:27.730052 2026] [security2:error] [pid 164535:tid 164678] [client 14.225.17.146:61106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4k0zYN371eKRzcKeSD5AAAAJI"], referer: http://mazzucelli.com/bc
[Mon Jul 20 07:38:27.744500 2026] [security2:error] [pid 164535:tid 164651] [remote 173.249.4.11:12526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k0zYN371eKRzcKeSD7QAA8XM"]
[Mon Jul 20 07:38:27.744711 2026] [security2:error] [pid 164535:tid 164773] [client 173.249.4.11:12526] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k0zYN371eKRzcKeSD7QAA8XM"]
[Mon Jul 20 07:38:27.811150 2026] [security2:error] [pid 171532:tid 171666] [client 57.141.18.112:39696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kzkEhLvMuMRNpl00M7wABDmU"]
[Mon Jul 20 07:38:27.819382 2026] [security2:error] [pid 171532:tid 171752] [client 14.225.17.146:61202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4k00EhLvMuMRNpl00OIQAAAWQ"], referer: http://processorstudio.com/bc
[Mon Jul 20 07:38:27.834424 2026] [security2:error] [pid 164535:tid 164756] [client 14.225.17.146:61547] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4k0jYN371eKRzcKeSDsgAAAOA"], referer: http://soloceos.com/bc
[Mon Jul 20 07:38:27.894442 2026] [security2:error] [pid 171532:tid 171567] [remote 154.61.75.100:60058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OJQABiSI"]
[Mon Jul 20 07:38:27.894630 2026] [security2:error] [pid 171532:tid 171790] [client 154.61.75.100:60058] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "kpb.qlr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k00EhLvMuMRNpl00OJQABiSI"]
[Mon Jul 20 07:38:28.125202 2026] [security2:error] [pid 164535:tid 164682] [client 180.102.110.143:53216] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "liquidationteam.com"] [uri "/faqs/"] [unique_id "al4k1DYN371eKRzcKeSD-QAAAJY"]
[Mon Jul 20 07:38:28.125295 2026] [security2:error] [pid 164535:tid 164682] [client 180.102.110.143:53216] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "liquidationteam.com"] [uri "/faqs/"] [unique_id "al4k1DYN371eKRzcKeSD-QAAAJY"]
[Mon Jul 20 07:38:28.135645 2026] [security2:error] [pid 171532:tid 171724] [client 57.141.18.52:33246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kzkEhLvMuMRNpl00M_wABSA0"]
[Mon Jul 20 07:38:28.156158 2026] [security2:error] [pid 171532:tid 171785] [client 5.193.175.36:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maxcom.net"] [uri "/index.php"] [unique_id "al4k0kEhLvMuMRNpl00N6AAAAYQ"]
[Mon Jul 20 07:38:28.361830 2026] [security2:error] [pid 164535:tid 164784] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k0zYN371eKRzcKeSD8wAAAPw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:28.392796 2026] [security2:error] [pid 171532:tid 171657] [remote 57.141.18.50:46280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5916983"] [unique_id "al4k1EEhLvMuMRNpl00ORgABMXw"]
[Mon Jul 20 07:38:28.454433 2026] [security2:error] [pid 164535:tid 164735] [client 14.225.17.146:59962] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4k0zYN371eKRzcKeSD4QAAAMs"], referer: http://walkingandtalking.net/bc
[Mon Jul 20 07:38:28.460622 2026] [security2:error] [pid 171532:tid 171770] [client 74.7.228.26:43736] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "bitesofwealth.com"] [uri "/robots.txt"] [unique_id "al4k1EEhLvMuMRNpl00OSwAAAXY"]
[Mon Jul 20 07:38:28.478975 2026] [security2:error] [pid 171532:tid 171684] [client 143.44.185.218:11041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00OTQAAASA"]
[Mon Jul 20 07:38:28.479088 2026] [security2:error] [pid 171532:tid 171684] [client 143.44.185.218:11041] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00OTQAAASA"]
[Mon Jul 20 07:38:28.694567 2026] [security2:error] [pid 164535:tid 164787] [client 14.225.17.146:61688] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4k1DYN371eKRzcKeSD_gAAAP8"], referer: https://processorstudio.com/bc
[Mon Jul 20 07:38:28.714650 2026] [security2:error] [pid 171532:tid 171763] [client 57.141.18.101:54878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4kz0EhLvMuMRNpl00NHAABb1M"]
[Mon Jul 20 07:38:28.735212 2026] [security2:error] [pid 171532:tid 171676] [client 36.93.152.155:56291] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00OYAAAARg"]
[Mon Jul 20 07:38:28.735319 2026] [security2:error] [pid 171532:tid 171676] [client 36.93.152.155:56291] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00OYAAAARg"]
[Mon Jul 20 07:38:28.808534 2026] [security2:error] [pid 171532:tid 171702] [client 155.2.215.81:26929] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00OYwAAATI"]
[Mon Jul 20 07:38:28.966244 2026] [security2:error] [pid 171532:tid 171781] [client 149.0.16.108:52093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00ObwAAAYA"]
[Mon Jul 20 07:38:28.966933 2026] [security2:error] [pid 171532:tid 171781] [client 149.0.16.108:52093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k1EEhLvMuMRNpl00ObwAAAYA"]
[Mon Jul 20 07:38:28.972287 2026] [security2:error] [pid 171532:tid 171669] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k1EEhLvMuMRNpl00OZQAAARE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:29.000988 2026] [security2:error] [pid 171532:tid 171756] [client 116.193.128.26:55360] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k1UEhLvMuMRNpl00OcgAAAWg"]
[Mon Jul 20 07:38:29.001098 2026] [security2:error] [pid 171532:tid 171756] [client 116.193.128.26:55360] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k1UEhLvMuMRNpl00OcgAAAWg"]
[Mon Jul 20 07:38:29.187219 2026] [security2:error] [pid 164535:tid 164782] [client 154.192.123.127:18466] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k1TYN371eKRzcKeSEFwAAAPo"]
[Mon Jul 20 07:38:29.187330 2026] [security2:error] [pid 164535:tid 164782] [client 154.192.123.127:18466] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k1TYN371eKRzcKeSEFwAAAPo"]
[Mon Jul 20 07:38:29.437855 2026] [security2:error] [pid 171532:tid 171749] [client 57.141.18.95:41336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k0EEhLvMuMRNpl00NTwABYSs"]
[Mon Jul 20 07:38:29.456391 2026] [security2:error] [pid 171532:tid 171693] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k1UEhLvMuMRNpl00OfwAAASk"]
[Mon Jul 20 07:38:29.465296 2026] [security2:error] [pid 164535:tid 164723] [client 14.225.17.146:62360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4k1TYN371eKRzcKeSEIgAAAL8"], referer: https://walkingandtalking.net/bc
[Mon Jul 20 07:38:29.498688 2026] [security2:error] [pid 171532:tid 171764] [client 213.94.50.237:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.cheesewithjam.com"] [uri "/index.php"] [unique_id "al4k1UEhLvMuMRNpl00OhAAAAXA"], referer: http://www.cheesewithjam.com/shop/
[Mon Jul 20 07:38:29.554318 2026] [security2:error] [pid 171532:tid 171733] [client 103.106.165.44:61107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k1UEhLvMuMRNpl00OjgAAAVE"]
[Mon Jul 20 07:38:29.554463 2026] [security2:error] [pid 171532:tid 171733] [client 103.106.165.44:61107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k1UEhLvMuMRNpl00OjgAAAVE"]
[Mon Jul 20 07:38:29.723089 2026] [security2:error] [pid 171532:tid 171692] [client 14.225.17.146:63461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4k0kEhLvMuMRNpl00N6QAAASg"], referer: http://drewsasburyparkbeachhouse.com/bc
[Mon Jul 20 07:38:29.880116 2026] [security2:error] [pid 164535:tid 164753] [client 114.119.128.46:56849] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "blog.danwolfe.us"] [uri "/page/11/"] [unique_id "al4k1TYN371eKRzcKeSENAAAAN0"], referer: https://blog.danwolfe.us/page/10/?weaverii_mobile_toggle=web_view
[Mon Jul 20 07:38:29.895558 2026] [security2:error] [pid 164535:tid 164708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k1TYN371eKRzcKeSEMAAAALA"]
[Mon Jul 20 07:38:30.182561 2026] [security2:error] [pid 171532:tid 171757] [client 47.128.36.34:13080] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "tomokaoakshistory.com"] [uri "/robots.txt"] [unique_id "al4k1kEhLvMuMRNpl00OswAAAWk"]
[Mon Jul 20 07:38:30.243038 2026] [ssl:error] [pid 171532:tid 171787] [client 104.48.69.105:50894] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:38:30.394993 2026] [security2:error] [pid 164535:tid 164735] [client 14.225.17.146:63806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4k1jYN371eKRzcKeSEQAAAAMs"], referer: https://north-woods-engineering.com/bc
[Mon Jul 20 07:38:30.501398 2026] [security2:error] [pid 171532:tid 171727] [client 57.141.18.115:52812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k0UEhLvMuMRNpl00NjQABSx0"]
[Mon Jul 20 07:38:30.795925 2026] [security2:error] [pid 171532:tid 171665] [client 57.141.18.5:20398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k0UEhLvMuMRNpl00NpgABDV8"]
[Mon Jul 20 07:38:30.916019 2026] [core:error] [pid 171532:tid 171743] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:30.916037 2026] [core:error] [pid 171532:tid 171743] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:30.964917 2026] [security2:error] [pid 171532:tid 171694] [client 202.141.11.99:58131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4k1kEhLvMuMRNpl00O4wAAASo"]
[Mon Jul 20 07:38:30.965035 2026] [security2:error] [pid 171532:tid 171694] [client 202.141.11.99:58131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4k1kEhLvMuMRNpl00O4wAAASo"]
[Mon Jul 20 07:38:31.011327 2026] [security2:error] [pid 171532:tid 171756] [client 14.225.17.146:63110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4k1kEhLvMuMRNpl00O1gAAAWg"], referer: http://bigwormfishing.com/bc
[Mon Jul 20 07:38:31.097563 2026] [security2:error] [pid 171532:tid 171690] [client 158.173.166.181:21619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k10EhLvMuMRNpl00O8AAAASY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:38:31.293568 2026] [security2:error] [pid 171532:tid 171557] [remote 72.167.132.114:59402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k10EhLvMuMRNpl00O9gABVxg"]
[Mon Jul 20 07:38:31.464846 2026] [security2:error] [pid 171532:tid 171765] [client 57.141.18.3:58152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k0kEhLvMuMRNpl00NxAABcU8"]
[Mon Jul 20 07:38:31.517140 2026] [security2:error] [pid 171532:tid 171585] [remote 72.167.132.114:59402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k10EhLvMuMRNpl00PAgABLTQ"], referer: https://mail.idf.ldc.mybluehost.me/wp-login.php
[Mon Jul 20 07:38:31.765270 2026] [security2:error] [pid 171532:tid 171753] [client 74.208.214.194:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4k10EhLvMuMRNpl00PFQAAAWU"]
[Mon Jul 20 07:38:31.977880 2026] [security2:error] [pid 171532:tid 171751] [client 50.116.65.227:22956] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4k10EhLvMuMRNpl00PIgAAAWM"]
[Mon Jul 20 07:38:31.987001 2026] [security2:error] [pid 171532:tid 171738] [client 50.116.65.227:22968] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4k10EhLvMuMRNpl00PJQAAAVY"]
[Mon Jul 20 07:38:32.028921 2026] [security2:error] [pid 171532:tid 171653] [remote 38.242.157.30:38124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PKwABE3g"]
[Mon Jul 20 07:38:32.128874 2026] [security2:error] [pid 171532:tid 171724] [client 104.207.50.215:41503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PMQAAAUg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:32.164873 2026] [security2:error] [pid 171532:tid 171664] [client 14.225.17.146:62989] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PLQAAAQw"], referer: https://bigwormfishing.com/bc
[Mon Jul 20 07:38:32.248230 2026] [security2:error] [pid 171532:tid 171782] [client 154.192.233.184:61648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k2EEhLvMuMRNpl00POwAAAYE"]
[Mon Jul 20 07:38:32.248379 2026] [security2:error] [pid 171532:tid 171782] [client 154.192.233.184:61648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k2EEhLvMuMRNpl00POwAAAYE"]
[Mon Jul 20 07:38:32.255930 2026] [security2:error] [pid 171532:tid 171606] [remote 217.61.143.92:43796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00POgABiEk"]
[Mon Jul 20 07:38:32.295517 2026] [security2:error] [pid 171532:tid 171619] [remote 38.242.157.30:38124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PPQABMVY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:38:32.416845 2026] [security2:error] [pid 171532:tid 171775] [client 45.157.112.60:30379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k2EEhLvMuMRNpl00PSwAAAXo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:38:32.496876 2026] [security2:error] [pid 171532:tid 171534] [remote 217.61.143.92:43796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PUQABGQE"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:38:32.509901 2026] [security2:error] [pid 171532:tid 171735] [client 65.111.23.184:53509] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PTgAAAVM"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:32.522323 2026] [security2:error] [pid 171532:tid 171750] [client 50.116.65.227:22998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PRQAAAWI"]
[Mon Jul 20 07:38:32.552087 2026] [security2:error] [pid 171532:tid 171700] [client 103.176.215.66:50121] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k2EEhLvMuMRNpl00PUwAAATA"]
[Mon Jul 20 07:38:32.552661 2026] [security2:error] [pid 171532:tid 171700] [client 103.176.215.66:50121] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k2EEhLvMuMRNpl00PUwAAATA"]
[Mon Jul 20 07:38:32.626286 2026] [security2:error] [pid 171532:tid 171654] [remote 209.42.21.221:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PWAABe3k"]
[Mon Jul 20 07:38:32.711163 2026] [security2:error] [pid 171532:tid 171726] [client 50.116.65.227:23008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PUgAAAUo"]
[Mon Jul 20 07:38:32.787811 2026] [security2:error] [pid 171532:tid 171757] [client 14.225.17.146:61776] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PWQAAAWk"], referer: http://grecruit.online/bc
[Mon Jul 20 07:38:32.796132 2026] [security2:error] [pid 171532:tid 171543] [remote 209.42.21.221:37392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.21.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4k2EEhLvMuMRNpl00PYwABbwo"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:38:32.936252 2026] [security2:error] [pid 171532:tid 171787] [client 74.208.214.194:54602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4k2EEhLvMuMRNpl00PbAAAAYY"]
[Mon Jul 20 07:38:33.182638 2026] [security2:error] [pid 171532:tid 171740] [client 14.225.17.146:62953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4k10EhLvMuMRNpl00PEgAAAVg"], referer: http://alexsandbergmusic.com/bc
[Mon Jul 20 07:38:33.471219 2026] [security2:error] [pid 164535:tid 164637] [remote 162.19.86.63:51490] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k2TYN371eKRzcKeSElAAAlGU"]
[Mon Jul 20 07:38:33.471393 2026] [security2:error] [pid 164535:tid 164680] [client 162.19.86.63:51490] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k2TYN371eKRzcKeSElAAAlGU"]
[Mon Jul 20 07:38:33.485619 2026] [security2:error] [pid 164535:tid 164625] [remote 72.167.132.114:59408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4k2TYN371eKRzcKeSElQAAs1k"]
[Mon Jul 20 07:38:33.702808 2026] [security2:error] [pid 164535:tid 164650] [remote 72.167.132.114:59408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elevator-data.com"] [uri "/wp-login.php"] [unique_id "al4k2TYN371eKRzcKeSEoQAAonI"], referer: https://elevator-data.com/wp-login.php
[Mon Jul 20 07:38:33.753313 2026] [security2:error] [pid 171532:tid 171747] [client 191.202.66.27:57920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k2UEhLvMuMRNpl00PmQAAAV8"]
[Mon Jul 20 07:38:33.753423 2026] [security2:error] [pid 171532:tid 171747] [client 191.202.66.27:57920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k2UEhLvMuMRNpl00PmQAAAV8"]
[Mon Jul 20 07:38:33.785020 2026] [security2:error] [pid 164535:tid 164671] [client 179.127.84.238:61975] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k2TYN371eKRzcKeSEowAAAIs"]
[Mon Jul 20 07:38:33.785134 2026] [security2:error] [pid 164535:tid 164671] [client 179.127.84.238:61975] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k2TYN371eKRzcKeSEowAAAIs"]
[Mon Jul 20 07:38:33.918111 2026] [security2:error] [pid 164535:tid 164731] [client 136.158.60.21:8144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k2TYN371eKRzcKeSEpwAAAMc"]
[Mon Jul 20 07:38:33.918206 2026] [security2:error] [pid 164535:tid 164731] [client 136.158.60.21:8144] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k2TYN371eKRzcKeSEpwAAAMc"]
[Mon Jul 20 07:38:34.004419 2026] [security2:error] [pid 171532:tid 171731] [client 14.225.17.146:62978] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PLgAAAU8"], referer: http://itdynamix.com/bc
[Mon Jul 20 07:38:34.106376 2026] [security2:error] [pid 164535:tid 164719] [client 14.225.17.146:61624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4k2TYN371eKRzcKeSEqQAAALs"], referer: http://nextlvlmarketingco.com/bc
[Mon Jul 20 07:38:34.321699 2026] [security2:error] [pid 171532:tid 171783] [client 57.141.18.34:30996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k1EEhLvMuMRNpl00OOwABgmI"]
[Mon Jul 20 07:38:34.570304 2026] [security2:error] [pid 171532:tid 171728] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k2kEhLvMuMRNpl00PugAAAUw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:34.898260 2026] [security2:error] [pid 171532:tid 171769] [client 15.237.247.147:45364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k2kEhLvMuMRNpl00PsAAAAXU"]
[Mon Jul 20 07:38:34.946273 2026] [security2:error] [pid 164535:tid 164785] [client 49.37.242.14:64841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4k2jYN371eKRzcKeSEwgAAAP0"]
[Mon Jul 20 07:38:34.946394 2026] [security2:error] [pid 164535:tid 164785] [client 49.37.242.14:64841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4k2jYN371eKRzcKeSEwgAAAP0"]
[Mon Jul 20 07:38:35.053659 2026] [security2:error] [pid 171532:tid 171735] [client 14.225.17.146:60577] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4k2kEhLvMuMRNpl00P0wAAAVM"], referer: https://itdynamix.com/bc
[Mon Jul 20 07:38:35.144239 2026] [security2:error] [pid 164535:tid 164707] [client 50.116.65.227:23054] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tntcatholic.com"] [uri "/wp-content/uploads/2022/08/pexels-photo-1921266.jpeg"] [unique_id "al4k2zYN371eKRzcKeSEyQAAAK8"]
[Mon Jul 20 07:38:35.227800 2026] [security2:error] [pid 164535:tid 164739] [client 57.141.18.71:36778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k1TYN371eKRzcKeSEFAAAzxI"]
[Mon Jul 20 07:38:35.303361 2026] [security2:error] [pid 171532:tid 171685] [client 103.139.191.61:60844] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k20EhLvMuMRNpl00P4gAAASE"]
[Mon Jul 20 07:38:35.303489 2026] [security2:error] [pid 171532:tid 171685] [client 103.139.191.61:60844] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k20EhLvMuMRNpl00P4gAAASE"]
[Mon Jul 20 07:38:35.423997 2026] [security2:error] [pid 171532:tid 171684] [client 50.116.65.227:23060] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tntcatholic.com"] [uri "/wp-content/uploads/2021/08/Ark-3.jpg"] [unique_id "al4k20EhLvMuMRNpl00P5AAAAWU"]
[Mon Jul 20 07:38:35.587564 2026] [security2:error] [pid 164535:tid 164647] [remote 5.252.52.249:47110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k2zYN371eKRzcKeSE4AAAi28"]
[Mon Jul 20 07:38:35.587781 2026] [security2:error] [pid 164535:tid 164671] [client 5.252.52.249:47110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k2zYN371eKRzcKeSE4AAAi28"]
[Mon Jul 20 07:38:36.073011 2026] [proxy:error] [pid 171532:tid 171780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:36.073086 2026] [proxy_http:error] [pid 171532:tid 171780] [client 87.236.176.168:60803] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:36.073660 2026] [proxy:error] [pid 171532:tid 171780] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:36.073685 2026] [proxy_http:error] [pid 171532:tid 171780] [client 87.236.176.168:60803] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:36.137292 2026] [security2:error] [pid 171532:tid 171750] [client 57.141.18.85:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4k20EhLvMuMRNpl00P8QAAAWI"]
[Mon Jul 20 07:38:36.199158 2026] [security2:error] [pid 164535:tid 164704] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k3DYN371eKRzcKeSE-gAAAKw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:36.262960 2026] [security2:error] [pid 171532:tid 171628] [remote 192.241.143.148:39716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4k3EEhLvMuMRNpl00QCAABE18"]
[Mon Jul 20 07:38:36.417205 2026] [security2:error] [pid 171532:tid 171640] [remote 192.241.143.148:39716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4k3EEhLvMuMRNpl00QGwABQGs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:38:36.519351 2026] [security2:error] [pid 171532:tid 171696] [client 220.181.108.176:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4k3EEhLvMuMRNpl00QBwAAASw"]
[Mon Jul 20 07:38:36.690142 2026] [security2:error] [pid 171532:tid 171581] [remote 103.118.29.185:42972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4k3EEhLvMuMRNpl00QLgABfDA"]
[Mon Jul 20 07:38:36.695324 2026] [security2:error] [pid 171532:tid 171710] [client 14.225.17.146:61477] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4k20EhLvMuMRNpl00P-gAAATo"]
[Mon Jul 20 07:38:36.758966 2026] [ssl:error] [pid 171532:tid 171776] [client 104.48.69.105:50896] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:38:36.988758 2026] [security2:error] [pid 164535:tid 164680] [client 49.47.218.174:62515] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k3DYN371eKRzcKeSFCAAAAJQ"]
[Mon Jul 20 07:38:36.988870 2026] [security2:error] [pid 164535:tid 164680] [client 49.47.218.174:62515] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k3DYN371eKRzcKeSFCAAAAJQ"]
[Mon Jul 20 07:38:37.097881 2026] [security2:error] [pid 171532:tid 171639] [remote 103.118.29.185:42972] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/wp-login.php"] [unique_id "al4k3UEhLvMuMRNpl00QPwABhmo"], referer: https://nevelow.com/wp-login.php
[Mon Jul 20 07:38:37.111843 2026] [security2:error] [pid 171532:tid 171772] [client 57.141.18.29:25660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k10EhLvMuMRNpl00O-gABeEo"]
[Mon Jul 20 07:38:37.182862 2026] [security2:error] [pid 164535:tid 164779] [client 14.225.17.146:63778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4k3DYN371eKRzcKeSFAwAAAPc"], referer: http://idigress.group/bc
[Mon Jul 20 07:38:37.523257 2026] [security2:error] [pid 164535:tid 164760] [client 180.249.173.210:58587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k3TYN371eKRzcKeSFFgAAAOQ"]
[Mon Jul 20 07:38:37.523734 2026] [security2:error] [pid 164535:tid 164760] [client 180.249.173.210:58587] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k3TYN371eKRzcKeSFFgAAAOQ"]
[Mon Jul 20 07:38:37.529125 2026] [security2:error] [pid 171532:tid 171538] [remote 173.249.4.11:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k3UEhLvMuMRNpl00QWwABHAU"]
[Mon Jul 20 07:38:37.706663 2026] [security2:error] [pid 171532:tid 171544] [remote 173.249.4.11:62125] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k3UEhLvMuMRNpl00QZwABaQs"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:38:37.817537 2026] [security2:error] [pid 171532:tid 171699] [client 57.141.18.90:55602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PMAABLw8"]
[Mon Jul 20 07:38:37.910695 2026] [security2:error] [pid 171532:tid 171712] [client 13.232.231.177:45746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k3UEhLvMuMRNpl00QbwAAATw"]
[Mon Jul 20 07:38:37.910785 2026] [security2:error] [pid 171532:tid 171712] [client 13.232.231.177:45746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k3UEhLvMuMRNpl00QbwAAATw"]
[Mon Jul 20 07:38:38.259880 2026] [security2:error] [pid 171532:tid 171789] [client 157.20.138.62:65142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k3kEhLvMuMRNpl00QgAAAAYg"]
[Mon Jul 20 07:38:38.260016 2026] [security2:error] [pid 171532:tid 171789] [client 157.20.138.62:65142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k3kEhLvMuMRNpl00QgAAAAYg"]
[Mon Jul 20 07:38:38.278712 2026] [ssl:error] [pid 171532:tid 171703] [client 104.48.69.105:36136] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:38:38.497003 2026] [security2:error] [pid 171532:tid 171680] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k3kEhLvMuMRNpl00QhgAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:38.559995 2026] [security2:error] [pid 171532:tid 171723] [client 57.141.18.28:57264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k2EEhLvMuMRNpl00PXAABR1U"]
[Mon Jul 20 07:38:38.568816 2026] [security2:error] [pid 171532:tid 171753] [client 14.225.17.146:61441] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4k3kEhLvMuMRNpl00QlgAAAWU"], referer: http://travelbyfire.com/bc
[Mon Jul 20 07:38:39.337323 2026] [security2:error] [pid 164535:tid 164780] [client 36.93.152.155:56804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k3zYN371eKRzcKeSFPwAAAPg"]
[Mon Jul 20 07:38:39.337474 2026] [security2:error] [pid 164535:tid 164780] [client 36.93.152.155:56804] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k3zYN371eKRzcKeSFPwAAAPg"]
[Mon Jul 20 07:38:39.443219 2026] [security2:error] [pid 164535:tid 164569] [remote 20.153.140.50:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k3zYN371eKRzcKeSFRAAAiSE"]
[Mon Jul 20 07:38:39.453001 2026] [security2:error] [pid 171532:tid 171727] [client 14.225.17.146:51551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4k30EhLvMuMRNpl00QzwAAAUs"], referer: https://travelbyfire.com/bc
[Mon Jul 20 07:38:39.494276 2026] [security2:error] [pid 164535:tid 164711] [client 116.193.128.26:55932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k3zYN371eKRzcKeSFTQAAALM"]
[Mon Jul 20 07:38:39.494357 2026] [security2:error] [pid 164535:tid 164711] [client 116.193.128.26:55932] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k3zYN371eKRzcKeSFTQAAALM"]
[Mon Jul 20 07:38:39.543765 2026] [security2:error] [pid 171532:tid 171785] [client 142.111.152.65:61857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4k30EhLvMuMRNpl00QzQAAAYQ"]
[Mon Jul 20 07:38:39.668938 2026] [security2:error] [pid 171532:tid 171730] [client 57.141.18.109:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4k30EhLvMuMRNpl00Q2AAAAU4"]
[Mon Jul 20 07:38:39.723741 2026] [security2:error] [pid 164535:tid 164784] [client 149.0.16.108:52614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k3zYN371eKRzcKeSFUwAAAPw"]
[Mon Jul 20 07:38:39.723849 2026] [security2:error] [pid 164535:tid 164784] [client 149.0.16.108:52614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k3zYN371eKRzcKeSFUwAAAPw"]
[Mon Jul 20 07:38:39.735731 2026] [security2:error] [pid 171532:tid 171752] [client 154.192.123.127:16941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k30EhLvMuMRNpl00Q3gAAAWQ"]
[Mon Jul 20 07:38:39.735829 2026] [security2:error] [pid 171532:tid 171752] [client 154.192.123.127:16941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k30EhLvMuMRNpl00Q3gAAAWQ"]
[Mon Jul 20 07:38:39.905553 2026] [security2:error] [pid 164535:tid 164621] [remote 20.153.140.50:36672] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.gpm.vvo.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4k3zYN371eKRzcKeSFWwAAm1U"], referer: https://mail.gpm.vvo.mybluehost.me/wp-login.php
[Mon Jul 20 07:38:39.947425 2026] [security2:error] [pid 164535:tid 164719] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k3zYN371eKRzcKeSFVQAAALs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:40.145777 2026] [security2:error] [pid 171532:tid 171724] [client 103.106.165.44:61589] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k4EEhLvMuMRNpl00Q-QAAAUg"]
[Mon Jul 20 07:38:40.145887 2026] [security2:error] [pid 171532:tid 171724] [client 103.106.165.44:61589] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k4EEhLvMuMRNpl00Q-QAAAUg"]
[Mon Jul 20 07:38:40.265332 2026] [security2:error] [pid 164535:tid 164743] [client 3.67.192.83:47342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 83.192.67.3.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k4DYN371eKRzcKeSFagAAANM"]
[Mon Jul 20 07:38:40.265417 2026] [security2:error] [pid 164535:tid 164743] [client 3.67.192.83:47342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k4DYN371eKRzcKeSFagAAANM"]
[Mon Jul 20 07:38:40.266255 2026] [security2:error] [pid 171532:tid 171736] [client 57.141.18.51:48734] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k2kEhLvMuMRNpl00PuwABVGE"]
[Mon Jul 20 07:38:40.329510 2026] [security2:error] [pid 164535:tid 164735] [client 143.44.185.218:13508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k4DYN371eKRzcKeSFbgAAAMs"]
[Mon Jul 20 07:38:40.333165 2026] [security2:error] [pid 164535:tid 164735] [client 143.44.185.218:13508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k4DYN371eKRzcKeSFbgAAAMs"]
[Mon Jul 20 07:38:40.480700 2026] [security2:error] [pid 171532:tid 171681] [client 14.225.17.146:63807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4k4EEhLvMuMRNpl00RAwAAAR0"], referer: http://mobilesurvsolutions.com/bc
[Mon Jul 20 07:38:40.742044 2026] [security2:error] [pid 164535:tid 164745] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k4DYN371eKRzcKeSFbwAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:40.793792 2026] [security2:error] [pid 164535:tid 164589] [remote 216.73.216.219:12237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "tntcatholic.com"] [uri "/xmlrpc.php"] [unique_id "al4k4DYN371eKRzcKeSFegAA0jU"]
[Mon Jul 20 07:38:41.043011 2026] [security2:error] [pid 164535:tid 164674] [client 57.141.18.106:40684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k2zYN371eKRzcKeSE1AAAji4"]
[Mon Jul 20 07:38:41.315717 2026] [security2:error] [pid 164535:tid 164763] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k4TYN371eKRzcKeSFiwAAAOc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:41.409963 2026] [security2:error] [pid 164535:tid 164705] [client 57.141.18.82:35694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k2zYN371eKRzcKeSE5AAArWg"]
[Mon Jul 20 07:38:41.527194 2026] [security2:error] [pid 171532:tid 171726] [client 114.119.142.121:65155] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gertoger.org"] [uri "/mongolia-travel-info-mongolia-golden-mountain-tours/"] [unique_id "al4k4UEhLvMuMRNpl00RPgAAAUo"], referer: https://gertoger.org/
[Mon Jul 20 07:38:41.537706 2026] [security2:error] [pid 171532:tid 171662] [client 57.141.18.12:49816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k20EhLvMuMRNpl00P8gABClE"]
[Mon Jul 20 07:38:41.725654 2026] [security2:error] [pid 171532:tid 171738] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k4UEhLvMuMRNpl00ROwAAAVY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:41.747740 2026] [security2:error] [pid 164535:tid 164769] [client 57.141.18.77:54388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k2zYN371eKRzcKeSE8QAA7R8"]
[Mon Jul 20 07:38:41.797473 2026] [security2:error] [pid 171532:tid 171763] [client 217.181.91.200:14279] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.91.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4k4UEhLvMuMRNpl00RWAAAAW8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:41.812001 2026] [security2:error] [pid 171532:tid 171762] [client 57.141.18.33:27598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k3EEhLvMuMRNpl00P_gABbgg"]
[Mon Jul 20 07:38:41.904884 2026] [security2:error] [pid 171532:tid 171733] [client 57.141.18.13:50814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k3EEhLvMuMRNpl00QBAABUQ4"]
[Mon Jul 20 07:38:41.932329 2026] [security2:error] [pid 171532:tid 171768] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k4UEhLvMuMRNpl00RUQAAAXQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:42.448663 2026] [security2:error] [pid 171532:tid 171705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k4kEhLvMuMRNpl00RcgAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:42.551398 2026] [security2:error] [pid 171532:tid 171695] [client 14.225.17.146:63397] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4k4kEhLvMuMRNpl00RbAAAASs"], referer: http://overloadcomedy.com/bc
[Mon Jul 20 07:38:42.614733 2026] [security2:error] [pid 164535:tid 164715] [client 14.225.17.146:62633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4k4DYN371eKRzcKeSFgwAAALc"], referer: http://amalia-capital.com/bc
[Mon Jul 20 07:38:42.812174 2026] [security2:error] [pid 171532:tid 171662] [client 154.192.233.184:62004] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k4kEhLvMuMRNpl00RlwAAAQo"]
[Mon Jul 20 07:38:42.812322 2026] [security2:error] [pid 171532:tid 171662] [client 154.192.233.184:62004] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k4kEhLvMuMRNpl00RlwAAAQo"]
[Mon Jul 20 07:38:43.036077 2026] [security2:error] [pid 171532:tid 171744] [client 103.176.215.66:50656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k40EhLvMuMRNpl00RrQAAAVw"]
[Mon Jul 20 07:38:43.036413 2026] [security2:error] [pid 171532:tid 171744] [client 103.176.215.66:50656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k40EhLvMuMRNpl00RrQAAAVw"]
[Mon Jul 20 07:38:43.417613 2026] [security2:error] [pid 164535:tid 164686] [client 104.207.50.217:55915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4k4zYN371eKRzcKeSFtgAAAJo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:43.455136 2026] [security2:error] [pid 171532:tid 171760] [client 57.141.18.29:20104] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k3UEhLvMuMRNpl00QdwABbDo"]
[Mon Jul 20 07:38:43.541949 2026] [security2:error] [pid 171532:tid 171707] [client 57.141.18.103:56098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k3kEhLvMuMRNpl00QeQABN3c"]
[Mon Jul 20 07:38:43.846472 2026] [security2:error] [pid 171532:tid 171742] [client 14.225.17.146:65295] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4k40EhLvMuMRNpl00R6wAAAVo"], referer: http://inspirespublishing.com/bc
[Mon Jul 20 07:38:43.864977 2026] [security2:error] [pid 171532:tid 171744] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k40EhLvMuMRNpl00R4AAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:43.962047 2026] [security2:error] [pid 171532:tid 171771] [client 14.225.17.146:51369] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4k4UEhLvMuMRNpl00RXQAAAXc"], referer: http://floorsourcestock.com/bc
[Mon Jul 20 07:38:43.972639 2026] [core:error] [pid 171532:tid 171700] [client 14.225.17.146:49828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:43.972659 2026] [core:error] [pid 171532:tid 171700] [client 14.225.17.146:49828] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:44.068041 2026] [security2:error] [pid 164535:tid 164608] [remote 57.141.18.47:60192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k3jYN371eKRzcKeSFLwAAikg"]
[Mon Jul 20 07:38:44.290996 2026] [security2:error] [pid 171532:tid 171789] [client 179.127.84.238:62516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k5EEhLvMuMRNpl00SGgAAAYg"]
[Mon Jul 20 07:38:44.291121 2026] [security2:error] [pid 171532:tid 171789] [client 179.127.84.238:62516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k5EEhLvMuMRNpl00SGgAAAYg"]
[Mon Jul 20 07:38:44.375408 2026] [security2:error] [pid 171532:tid 171763] [client 191.202.66.27:58398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k5EEhLvMuMRNpl00SKwAAAW8"]
[Mon Jul 20 07:38:44.375500 2026] [security2:error] [pid 171532:tid 171763] [client 191.202.66.27:58398] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k5EEhLvMuMRNpl00SKwAAAW8"]
[Mon Jul 20 07:38:44.543249 2026] [security2:error] [pid 171532:tid 171726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5EEhLvMuMRNpl00SJgAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:44.604414 2026] [security2:error] [pid 171532:tid 171721] [client 45.167.50.45:50914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.marscafe.com"] [uri "/php/cul-dl/download.php"] [unique_id "al4k5EEhLvMuMRNpl00SOQAAAUU"]
[Mon Jul 20 07:38:44.627559 2026] [security2:error] [pid 171532:tid 171727] [client 14.225.17.146:54763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4k40EhLvMuMRNpl00R2AAAAUs"], referer: http://katsklar.com/bc
[Mon Jul 20 07:38:44.627660 2026] [security2:error] [pid 171532:tid 171670] [client 136.158.60.21:9638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k5EEhLvMuMRNpl00SPgAAARI"]
[Mon Jul 20 07:38:44.627744 2026] [security2:error] [pid 171532:tid 171670] [client 136.158.60.21:9638] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k5EEhLvMuMRNpl00SPgAAARI"]
[Mon Jul 20 07:38:44.715122 2026] [security2:error] [pid 171532:tid 171711] [client 194.180.48.253:48006] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "longevityperformanceclinic.com"] [uri "/"] [unique_id "al4k5EEhLvMuMRNpl00STAAAATs"]
[Mon Jul 20 07:38:44.847148 2026] [security2:error] [pid 171532:tid 171787] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5EEhLvMuMRNpl00SPwAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:45.014980 2026] [security2:error] [pid 171532:tid 171757] [client 57.141.18.93:35770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k30EhLvMuMRNpl00Q5QABaR4"]
[Mon Jul 20 07:38:45.032785 2026] [security2:error] [pid 171532:tid 171697] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5EEhLvMuMRNpl00SUgAAAS0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:45.196115 2026] [security2:error] [pid 164535:tid 164643] [remote 57.141.18.41:34446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k4DYN371eKRzcKeSFaQABAWs"]
[Mon Jul 20 07:38:45.537937 2026] [security2:error] [pid 171532:tid 171731] [client 45.61.187.50:62355] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "eloisetate.com"] [uri "/"] [unique_id "al4k5UEhLvMuMRNpl00SjAAAAU8"]
[Mon Jul 20 07:38:45.714218 2026] [security2:error] [pid 171532:tid 171721] [client 45.61.187.50:62365] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "eloisetate.com"] [uri "/"] [unique_id "al4k5UEhLvMuMRNpl00SmgAAAUU"]
[Mon Jul 20 07:38:45.737083 2026] [security2:error] [pid 171532:tid 171683] [client 14.225.17.146:49880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4k40EhLvMuMRNpl00R8wAAAR8"], referer: http://aandarealtygroup.com/bc
[Mon Jul 20 07:38:45.766833 2026] [security2:error] [pid 171532:tid 171709] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5UEhLvMuMRNpl00SjQAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:46.033658 2026] [security2:error] [pid 171532:tid 171747] [client 158.173.89.95:52683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k5kEhLvMuMRNpl00StgAAAV8"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:38:46.140416 2026] [security2:error] [pid 171532:tid 171785] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5UEhLvMuMRNpl00SpQAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:46.177068 2026] [security2:error] [pid 171532:tid 171789] [client 89.238.167.150:46784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4k5kEhLvMuMRNpl00SvAAAAYg"]
[Mon Jul 20 07:38:46.177166 2026] [security2:error] [pid 171532:tid 171789] [client 89.238.167.150:46784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4k5kEhLvMuMRNpl00SvAAAAYg"]
[Mon Jul 20 07:38:46.252555 2026] [security2:error] [pid 171532:tid 171668] [client 103.139.191.61:61340] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k5kEhLvMuMRNpl00SxAAAARA"]
[Mon Jul 20 07:38:46.252694 2026] [security2:error] [pid 171532:tid 171668] [client 103.139.191.61:61340] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k5kEhLvMuMRNpl00SxAAAARA"]
[Mon Jul 20 07:38:46.583569 2026] [security2:error] [pid 171532:tid 171708] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5kEhLvMuMRNpl00SzQAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:46.812106 2026] [security2:error] [pid 171532:tid 171739] [client 57.141.18.51:48758] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k4UEhLvMuMRNpl00RXAABV1s"]
[Mon Jul 20 07:38:46.988698 2026] [security2:error] [pid 171532:tid 171728] [client 14.225.17.146:65153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4k5kEhLvMuMRNpl00S9QAAAUw"], referer: http://blaizeaccountingservices.com/bc
[Mon Jul 20 07:38:47.020675 2026] [security2:error] [pid 171532:tid 171775] [client 114.119.159.152:20989] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.maxenengineering.com"] [uri "/products/cart"] [unique_id "al4k50EhLvMuMRNpl00TCgAAAXo"], referer: https://www.maxenengineering.com/products/cart
[Mon Jul 20 07:38:47.053687 2026] [security2:error] [pid 171532:tid 171666] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k5kEhLvMuMRNpl00S9gAAAQ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:47.326846 2026] [security2:error] [pid 171532:tid 171758] [client 57.141.18.87:39514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k4kEhLvMuMRNpl00RgAABamg"]
[Mon Jul 20 07:38:47.394236 2026] [security2:error] [pid 171532:tid 171747] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k50EhLvMuMRNpl00TGAAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:47.418637 2026] [security2:error] [pid 171532:tid 171695] [client 49.47.218.174:63061] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k50EhLvMuMRNpl00TMgAAASs"]
[Mon Jul 20 07:38:47.418732 2026] [security2:error] [pid 171532:tid 171695] [client 49.47.218.174:63061] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k50EhLvMuMRNpl00TMgAAASs"]
[Mon Jul 20 07:38:47.541564 2026] [security2:error] [pid 171532:tid 171772] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k50EhLvMuMRNpl00TKgAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:47.984231 2026] [security2:error] [pid 171532:tid 171686] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k50EhLvMuMRNpl00TRwAAASI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:48.056632 2026] [core:error] [pid 171532:tid 171784] [client 14.225.17.146:65279] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:48.056656 2026] [core:error] [pid 171532:tid 171784] [client 14.225.17.146:65279] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:48.101363 2026] [security2:error] [pid 171532:tid 171721] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k50EhLvMuMRNpl00TWAAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:48.103528 2026] [security2:error] [pid 171532:tid 171708] [client 14.225.17.146:49886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TYgAAATg"], referer: http://daseighty.net/bc
[Mon Jul 20 07:38:48.123325 2026] [security2:error] [pid 171532:tid 171662] [client 47.128.118.120:65194] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "acaiandcitystreets.com"] [uri "/robots.txt"] [unique_id "al4k6EEhLvMuMRNpl00TaQAAAQo"]
[Mon Jul 20 07:38:48.327642 2026] [security2:error] [pid 171532:tid 171700] [client 14.225.17.146:62506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4k5EEhLvMuMRNpl00SUQAAATA"], referer: http://areitoproducciones.com/bc
[Mon Jul 20 07:38:48.352611 2026] [security2:error] [pid 171532:tid 171751] [client 180.249.173.210:59068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k6EEhLvMuMRNpl00TgwAAAWM"]
[Mon Jul 20 07:38:48.358123 2026] [security2:error] [pid 171532:tid 171751] [client 180.249.173.210:59068] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k6EEhLvMuMRNpl00TgwAAAWM"]
[Mon Jul 20 07:38:48.550494 2026] [security2:error] [pid 171532:tid 171765] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TggAAAXE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:48.587864 2026] [security2:error] [pid 171532:tid 171689] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TgQAAASU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:48.770865 2026] [security2:error] [pid 171532:tid 171667] [client 157.20.138.62:49338] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 62.138.20.157.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k6EEhLvMuMRNpl00TpAAAAQ8"]
[Mon Jul 20 07:38:48.770985 2026] [security2:error] [pid 171532:tid 171667] [client 157.20.138.62:49338] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k6EEhLvMuMRNpl00TpAAAAQ8"]
[Mon Jul 20 07:38:48.823649 2026] [security2:error] [pid 171532:tid 171726] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TlAAAAUo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:48.855976 2026] [security2:error] [pid 171532:tid 171677] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TnAAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.011895 2026] [security2:error] [pid 171532:tid 171711] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TqAAAATs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.209625 2026] [security2:error] [pid 171532:tid 171730] [client 77.110.127.138:53264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/chart/feed/"] [unique_id "al4k6UEhLvMuMRNpl00TzQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.283616 2026] [security2:error] [pid 171532:tid 171740] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6UEhLvMuMRNpl00TwAAAAVg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.347969 2026] [security2:error] [pid 171532:tid 171702] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6UEhLvMuMRNpl00TyAAAATI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.424836 2026] [security2:error] [pid 171532:tid 171769] [client 57.141.18.79:40732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k5EEhLvMuMRNpl00SVgABdQI"]
[Mon Jul 20 07:38:49.610164 2026] [security2:error] [pid 171532:tid 171704] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6UEhLvMuMRNpl00T3gAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.782505 2026] [security2:error] [pid 171532:tid 171741] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6UEhLvMuMRNpl00T7AAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.881308 2026] [security2:error] [pid 171532:tid 171758] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6UEhLvMuMRNpl00T9wAAAWo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:49.881314 2026] [security2:error] [pid 171532:tid 171774] [client 36.93.152.155:57319] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k6UEhLvMuMRNpl00UDgAAAXk"]
[Mon Jul 20 07:38:49.881431 2026] [security2:error] [pid 171532:tid 171774] [client 36.93.152.155:57319] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k6UEhLvMuMRNpl00UDgAAAXk"]
[Mon Jul 20 07:38:49.898304 2026] [security2:error] [pid 171532:tid 171688] [client 57.141.18.71:53506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k5UEhLvMuMRNpl00SggABJAk"]
[Mon Jul 20 07:38:49.943249 2026] [core:error] [pid 171532:tid 171750] [client 198.235.24.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:49.943282 2026] [core:error] [pid 171532:tid 171750] [client 198.235.24.144:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:38:50.005242 2026] [security2:error] [pid 171532:tid 171623] [remote 57.141.18.72:22164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2639858"] [unique_id "al4k6UEhLvMuMRNpl00UGQABa1o"]
[Mon Jul 20 07:38:50.025436 2026] [autoindex:error] [pid 171532:tid 171716] [client 168.144.19.97:59294] AH01276: Cannot serve directory /home4/guitaram/public_html/thewritinglair/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:38:50.097046 2026] [security2:error] [pid 171532:tid 171689] [client 116.193.128.26:56505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00UHwAAASU"]
[Mon Jul 20 07:38:50.097163 2026] [security2:error] [pid 171532:tid 171689] [client 116.193.128.26:56505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00UHwAAASU"]
[Mon Jul 20 07:38:50.143862 2026] [security2:error] [pid 171532:tid 171719] [client 142.111.152.177:60079] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4k6UEhLvMuMRNpl00UFgAAAUM"]
[Mon Jul 20 07:38:50.219639 2026] [security2:error] [pid 171532:tid 171693] [client 154.192.123.127:17367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00UKAAAASk"]
[Mon Jul 20 07:38:50.219757 2026] [security2:error] [pid 171532:tid 171693] [client 154.192.123.127:17367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00UKAAAASk"]
[Mon Jul 20 07:38:50.224069 2026] [security2:error] [pid 171532:tid 171764] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6kEhLvMuMRNpl00UHAAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:50.324949 2026] [security2:error] [pid 171532:tid 171672] [client 149.0.16.108:53140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00UNAAAARQ"]
[Mon Jul 20 07:38:50.325562 2026] [security2:error] [pid 171532:tid 171672] [client 149.0.16.108:53140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00UNAAAARQ"]
[Mon Jul 20 07:38:50.475146 2026] [security2:error] [pid 171532:tid 171737] [client 57.141.18.65:48348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k5kEhLvMuMRNpl00SvwABVXg"]
[Mon Jul 20 07:38:50.534829 2026] [security2:error] [pid 171532:tid 171684] [client 103.106.165.44:62067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00URQAAASA"]
[Mon Jul 20 07:38:50.534974 2026] [security2:error] [pid 171532:tid 171684] [client 103.106.165.44:62067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k6kEhLvMuMRNpl00URQAAASA"]
[Mon Jul 20 07:38:50.611617 2026] [security2:error] [pid 171532:tid 171769] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k6kEhLvMuMRNpl00UOwAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:50.798042 2026] [security2:error] [pid 171532:tid 171771] [client 57.141.18.3:28640] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k5kEhLvMuMRNpl00S1gABd2Y"]
[Mon Jul 20 07:38:51.011783 2026] [security2:error] [pid 171532:tid 171675] [client 49.37.242.14:65394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4k60EhLvMuMRNpl00UXgAAARc"]
[Mon Jul 20 07:38:51.011890 2026] [security2:error] [pid 171532:tid 171675] [client 49.37.242.14:65394] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4k60EhLvMuMRNpl00UXgAAARc"]
[Mon Jul 20 07:38:51.285514 2026] [security2:error] [pid 171532:tid 171723] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k60EhLvMuMRNpl00UaAAAAUc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:51.307495 2026] [security2:error] [pid 171532:tid 171720] [client 57.141.18.42:57972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k50EhLvMuMRNpl00TCAABRBs"]
[Mon Jul 20 07:38:51.327622 2026] [autoindex:error] [pid 171532:tid 171575] [remote 136.114.198.221:50020] AH01276: Cannot serve directory /home2/cssgdzmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.css.gdz.mybluehost.me
[Mon Jul 20 07:38:51.346020 2026] [security2:error] [pid 171532:tid 171749] [client 157.55.39.60:38301] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4k60EhLvMuMRNpl00UZQABYXc"]
[Mon Jul 20 07:38:51.359714 2026] [security2:error] [pid 171532:tid 171767] [client 57.141.18.31:36256] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k50EhLvMuMRNpl00TEgABcy0"]
[Mon Jul 20 07:38:51.510668 2026] [security2:error] [pid 171532:tid 171770] [client 65.111.28.13:38823] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4k60EhLvMuMRNpl00UjAAAAXY"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:38:51.759381 2026] [security2:error] [pid 171532:tid 171787] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k60EhLvMuMRNpl00UkgAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:51.791363 2026] [security2:error] [pid 171532:tid 171705] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k60EhLvMuMRNpl00UlQAAATU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:51.807766 2026] [security2:error] [pid 171532:tid 171693] [client 14.224.227.113:56155] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4k60EhLvMuMRNpl00UqAAAASk"]
[Mon Jul 20 07:38:51.869604 2026] [security2:error] [pid 171532:tid 171780] [client 116.74.65.235:50211] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4k60EhLvMuMRNpl00UrwAAAX8"]
[Mon Jul 20 07:38:51.869699 2026] [security2:error] [pid 171532:tid 171780] [client 116.74.65.235:50211] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4k60EhLvMuMRNpl00UrwAAAX8"]
[Mon Jul 20 07:38:51.885727 2026] [security2:error] [pid 171532:tid 171681] [client 77.110.127.138:53257] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/chart/feed/"] [unique_id "al4k60EhLvMuMRNpl00UswAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:52.083389 2026] [security2:error] [pid 171532:tid 171760] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k60EhLvMuMRNpl00UsgAAAWw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:52.337507 2026] [security2:error] [pid 171532:tid 171746] [client 57.141.18.4:59174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k6EEhLvMuMRNpl00TewABXho"]
[Mon Jul 20 07:38:52.453421 2026] [security2:error] [pid 171532:tid 171780] [client 77.110.127.138:53264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/crochet-courses/feed/"] [unique_id "al4k7EEhLvMuMRNpl00U3AAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:52.599678 2026] [security2:error] [pid 171532:tid 171716] [client 14.225.17.146:56504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4k7EEhLvMuMRNpl00U2QAAAUA"], referer: http://lelandumc.org/bc
[Mon Jul 20 07:38:52.836239 2026] [security2:error] [pid 171532:tid 171749] [client 143.44.185.218:15841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k7EEhLvMuMRNpl00U-QAAAWE"]
[Mon Jul 20 07:38:52.838587 2026] [security2:error] [pid 171532:tid 171749] [client 143.44.185.218:15841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k7EEhLvMuMRNpl00U-QAAAWE"]
[Mon Jul 20 07:38:53.316170 2026] [security2:error] [pid 171532:tid 171553] [remote 72.167.132.114:58104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4k7UEhLvMuMRNpl00VIQABHBQ"]
[Mon Jul 20 07:38:53.320642 2026] [security2:error] [pid 171532:tid 171737] [client 154.192.233.184:62345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k7UEhLvMuMRNpl00VJAAAAVU"]
[Mon Jul 20 07:38:53.320722 2026] [security2:error] [pid 171532:tid 171737] [client 154.192.233.184:62345] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k7UEhLvMuMRNpl00VJAAAAVU"]
[Mon Jul 20 07:38:53.343437 2026] [security2:error] [pid 171532:tid 171605] [remote 192.241.143.148:47720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4k7UEhLvMuMRNpl00VKQABYUg"]
[Mon Jul 20 07:38:53.374854 2026] [autoindex:error] [pid 171532:tid 171564] [remote 8.229.41.77:62115] AH01276: Cannot serve directory /home2/ysslifmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.yss.lif.mybluehost.me
[Mon Jul 20 07:38:53.519306 2026] [security2:error] [pid 171532:tid 171612] [remote 72.167.132.114:58104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/wp-login.php"] [unique_id "al4k7UEhLvMuMRNpl00VPQABf08"], referer: https://taskidsvirginia.com/wp-login.php
[Mon Jul 20 07:38:53.537187 2026] [security2:error] [pid 171532:tid 171568] [remote 192.241.143.148:47720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4k7UEhLvMuMRNpl00VPgABFSM"], referer: https://savilerowtravel.com/wp-login.php
[Mon Jul 20 07:38:53.709295 2026] [security2:error] [pid 171532:tid 171668] [client 103.176.215.66:51188] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k7UEhLvMuMRNpl00VTQAAARA"]
[Mon Jul 20 07:38:53.709728 2026] [security2:error] [pid 171532:tid 171668] [client 103.176.215.66:51188] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k7UEhLvMuMRNpl00VTQAAARA"]
[Mon Jul 20 07:38:53.799593 2026] [security2:error] [pid 171532:tid 171693] [client 14.225.17.146:57300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4k7UEhLvMuMRNpl00VIwAAASk"], referer: http://uritems.net/bc
[Mon Jul 20 07:38:53.906515 2026] [security2:error] [pid 171532:tid 171717] [client 14.225.17.146:56628] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4k7EEhLvMuMRNpl00U5AAAAUE"], referer: http://momheadquarters.com/bc
[Mon Jul 20 07:38:53.935369 2026] [fcgid:warn] [pid 171532:tid 171751] (70014)End of file found: [client 199.45.155.109:48666] mod_fcgid: can't get data from http client
[Mon Jul 20 07:38:54.322289 2026] [security2:error] [pid 171532:tid 171789] [client 65.111.23.122:37605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4k7kEhLvMuMRNpl00VdAAAAYg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:54.336275 2026] [security2:error] [pid 171532:tid 171769] [client 77.110.127.138:53297] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-border/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4k7kEhLvMuMRNpl00VegAAAXU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:54.386900 2026] [security2:error] [pid 171532:tid 171710] [client 77.110.127.138:53271] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/chart/feed/"] [unique_id "al4k7kEhLvMuMRNpl00VewAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:54.596465 2026] [security2:error] [pid 171532:tid 171684] [client 77.110.127.138:53302] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/"] [unique_id "al4k7kEhLvMuMRNpl00VkQAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:54.748533 2026] [security2:error] [pid 171532:tid 171744] [client 77.110.127.138:53303] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/crochet-courses/feed/"] [unique_id "al4k7kEhLvMuMRNpl00VoAAAAVw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:54.787639 2026] [security2:error] [pid 171532:tid 171698] [client 179.127.84.238:63067] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k7kEhLvMuMRNpl00VowAAAS4"]
[Mon Jul 20 07:38:54.787762 2026] [security2:error] [pid 171532:tid 171698] [client 179.127.84.238:63067] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k7kEhLvMuMRNpl00VowAAAS4"]
[Mon Jul 20 07:38:55.087189 2026] [security2:error] [pid 171532:tid 171689] [client 196.118.69.236:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4k7kEhLvMuMRNpl00VogAAASU"]
[Mon Jul 20 07:38:55.156035 2026] [security2:error] [pid 171532:tid 171696] [client 20.14.74.210:40146] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.64.39"] [uri "/index.cgi"] [unique_id "al4k70EhLvMuMRNpl00VyAAAASw"]
[Mon Jul 20 07:38:55.160774 2026] [security2:error] [pid 171532:tid 171697] [client 191.202.66.27:58898] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k70EhLvMuMRNpl00VyQAAAS0"]
[Mon Jul 20 07:38:55.160897 2026] [security2:error] [pid 171532:tid 171697] [client 191.202.66.27:58898] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k70EhLvMuMRNpl00VyQAAAS0"]
[Mon Jul 20 07:38:55.360486 2026] [security2:error] [pid 171532:tid 171737] [client 136.158.60.21:11369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k70EhLvMuMRNpl00V3gAAAVU"]
[Mon Jul 20 07:38:55.360562 2026] [security2:error] [pid 171532:tid 171737] [client 136.158.60.21:11369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k70EhLvMuMRNpl00V3gAAAVU"]
[Mon Jul 20 07:38:55.382892 2026] [security2:error] [pid 171532:tid 171732] [client 98.159.234.160:39951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4k70EhLvMuMRNpl00V4wAAAVA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:38:55.749768 2026] [security2:error] [pid 171532:tid 171710] [client 104.207.53.147:59669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 147.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4k70EhLvMuMRNpl00V-wAAATo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:38:56.187702 2026] [security2:error] [pid 171532:tid 171754] [client 14.225.17.146:57319] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4k8EEhLvMuMRNpl00WFwAAAWY"], referer: http://ivetstrategies.com/bc
[Mon Jul 20 07:38:56.196246 2026] [security2:error] [pid 171532:tid 171540] [remote 57.141.18.113:31268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4031319"] [unique_id "al4k8EEhLvMuMRNpl00WJQABUwc"]
[Mon Jul 20 07:38:56.432795 2026] [security2:error] [pid 171532:tid 171668] [client 14.225.17.146:56907] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4k70EhLvMuMRNpl00V3wAAARA"], referer: http://ncsynchro.com/bc
[Mon Jul 20 07:38:56.520871 2026] [security2:error] [pid 171532:tid 171759] [client 50.116.65.227:21940] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4k8EEhLvMuMRNpl00WQwAAAWs"]
[Mon Jul 20 07:38:56.530464 2026] [security2:error] [pid 171532:tid 171777] [client 50.116.65.227:21948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4k8EEhLvMuMRNpl00WRAAAAXw"]
[Mon Jul 20 07:38:56.925028 2026] [security2:error] [pid 171532:tid 171712] [client 57.141.18.17:23514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k7UEhLvMuMRNpl00VCAABPCw"]
[Mon Jul 20 07:38:57.360027 2026] [proxy:error] [pid 171532:tid 171775] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:57.360076 2026] [proxy_http:error] [pid 171532:tid 171775] [client 107.172.180.205:44234] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:57.361097 2026] [proxy:error] [pid 171532:tid 171775] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:57.361133 2026] [proxy_http:error] [pid 171532:tid 171775] [client 107.172.180.205:44234] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:57.783615 2026] [security2:error] [pid 171532:tid 171664] [client 49.47.218.174:63599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k8UEhLvMuMRNpl00WrgAAAQw"]
[Mon Jul 20 07:38:57.783826 2026] [security2:error] [pid 171532:tid 171664] [client 49.47.218.174:63599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k8UEhLvMuMRNpl00WrgAAAQw"]
[Mon Jul 20 07:38:57.892272 2026] [security2:error] [pid 171532:tid 171735] [client 103.168.67.159:57486] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/wp-content/debug.log%00.php"] [unique_id "al4k8UEhLvMuMRNpl00WugAAAVM"], referer: https://www.google.com/search?q=yc8hda
[Mon Jul 20 07:38:57.954429 2026] [security2:error] [pid 171532:tid 171703] [client 77.110.127.138:53310] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-border/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4k8UEhLvMuMRNpl00WvwAAATM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:58.038995 2026] [security2:error] [pid 171532:tid 171711] [client 14.225.17.146:55382] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4k70EhLvMuMRNpl00V-gAAATs"], referer: http://talknutritionwithlesley.com/bc
[Mon Jul 20 07:38:58.292432 2026] [security2:error] [pid 171532:tid 171664] [client 77.110.127.138:53313] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/crochet-courses/feed/"] [unique_id "al4k8kEhLvMuMRNpl00W3QAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:58.426319 2026] [security2:error] [pid 171532:tid 171785] [client 50.116.65.227:49542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4k8kEhLvMuMRNpl00W6QAAAYQ"]
[Mon Jul 20 07:38:58.428391 2026] [security2:error] [pid 171532:tid 171770] [client 103.139.191.61:61834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k8kEhLvMuMRNpl00W6wAAAXY"]
[Mon Jul 20 07:38:58.429793 2026] [security2:error] [pid 171532:tid 171766] [client 14.225.17.146:64764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4k8UEhLvMuMRNpl00WZQAAAXI"]
[Mon Jul 20 07:38:58.431807 2026] [security2:error] [pid 171532:tid 171770] [client 103.139.191.61:61834] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k8kEhLvMuMRNpl00W6wAAAXY"]
[Mon Jul 20 07:38:58.464280 2026] [security2:error] [pid 171532:tid 171662] [client 77.110.127.138:53314] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/"] [unique_id "al4k8kEhLvMuMRNpl00W8gAAAQo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:38:58.492617 2026] [security2:error] [pid 171532:tid 171710] [client 180.249.173.210:59541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k8kEhLvMuMRNpl00W9gAAATo"]
[Mon Jul 20 07:38:58.493439 2026] [security2:error] [pid 171532:tid 171710] [client 180.249.173.210:59541] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k8kEhLvMuMRNpl00W9gAAATo"]
[Mon Jul 20 07:38:58.656711 2026] [security2:error] [pid 171532:tid 171740] [client 136.107.23.73:51408] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.23.107.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "yap.vjb.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4k8kEhLvMuMRNpl00XBAAAAVg"]
[Mon Jul 20 07:38:58.767717 2026] [security2:error] [pid 171532:tid 171672] [client 57.141.18.77:37906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k7kEhLvMuMRNpl00VpgABFAo"]
[Mon Jul 20 07:38:58.989583 2026] [security2:error] [pid 171532:tid 171746] [client 136.107.23.73:64545] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4k8kEhLvMuMRNpl00XHwAAAV4"]
[Mon Jul 20 07:38:58.997056 2026] [security2:error] [pid 171532:tid 171664] [client 14.225.17.146:56806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4k8kEhLvMuMRNpl00XDgAAAQw"]
[Mon Jul 20 07:38:59.094243 2026] [security2:error] [pid 171532:tid 171770] [client 74.7.227.179:35814] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4k8kEhLvMuMRNpl00XHQABdi0"], referer: https://tejasenvironmental.com/p=6200
[Mon Jul 20 07:38:59.253580 2026] [proxy:error] [pid 171532:tid 171766] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:59.253668 2026] [proxy_http:error] [pid 171532:tid 171766] [client 107.172.180.205:51884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:59.254657 2026] [proxy:error] [pid 171532:tid 171766] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:38:59.254724 2026] [proxy_http:error] [pid 171532:tid 171766] [client 107.172.180.205:51884] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:38:59.406806 2026] [security2:error] [pid 171532:tid 171719] [client 57.141.18.55:30906] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k70EhLvMuMRNpl00V6QABQ04"]
[Mon Jul 20 07:38:59.455257 2026] [security2:error] [pid 171532:tid 171754] [client 136.107.23.73:61798] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4k80EhLvMuMRNpl00XSAAAAWY"]
[Mon Jul 20 07:38:59.861649 2026] [security2:error] [pid 171532:tid 171702] [client 57.141.18.64:54048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k70EhLvMuMRNpl00WBAABMlI"]
[Mon Jul 20 07:38:59.895483 2026] [security2:error] [pid 171532:tid 171699] [client 136.107.23.73:56963] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4k80EhLvMuMRNpl00XbAAAAS8"]
[Mon Jul 20 07:39:00.058810 2026] [security2:error] [pid 171532:tid 171672] [client 14.225.17.146:57025] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4k80EhLvMuMRNpl00XYwAAARQ"], referer: http://falconarrowshop.com/bc
[Mon Jul 20 07:39:00.114386 2026] [http2:info] [pid 178071:tid 178071] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:39:00.150521 2026] [security2:error] [pid 171532:tid 171693] [client 14.225.17.146:56863] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4k80EhLvMuMRNpl00XMAAAASk"], referer: http://lifeisbetterlakeside.com/bc
[Mon Jul 20 07:39:00.234172 2026] [security2:error] [pid 171532:tid 171731] [client 136.107.23.73:65380] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4k9EEhLvMuMRNpl00XgwAAAU8"]
[Mon Jul 20 07:39:00.362299 2026] [security2:error] [pid 171532:tid 171677] [client 36.93.152.155:57832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k9EEhLvMuMRNpl00XkQAAARk"]
[Mon Jul 20 07:39:00.362381 2026] [security2:error] [pid 171532:tid 171677] [client 36.93.152.155:57832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k9EEhLvMuMRNpl00XkQAAARk"]
[Mon Jul 20 07:39:00.531043 2026] [security2:error] [pid 171532:tid 171745] [client 14.225.17.146:57040] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4k9EEhLvMuMRNpl00XiwAAAV0"], referer: http://sesamegreenbeans.com/bc
[Mon Jul 20 07:39:00.609934 2026] [security2:error] [pid 178071:tid 178223] [client 136.107.23.73:55500] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4k9Bltgi7HBmNwzJNFAAAAABQ"]
[Mon Jul 20 07:39:00.658512 2026] [security2:error] [pid 178071:tid 178203] [client 116.193.128.26:57087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k9Bltgi7HBmNwzJNFBgAAAAA"]
[Mon Jul 20 07:39:00.658672 2026] [security2:error] [pid 178071:tid 178203] [client 116.193.128.26:57087] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k9Bltgi7HBmNwzJNFBgAAAAA"]
[Mon Jul 20 07:39:00.755059 2026] [security2:error] [pid 171532:tid 171739] [client 142.111.152.175:49717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4k9EEhLvMuMRNpl00XnQAAAVc"]
[Mon Jul 20 07:39:00.830515 2026] [security2:error] [pid 171532:tid 171700] [client 154.192.123.127:17777] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k9EEhLvMuMRNpl00XrAAAATA"]
[Mon Jul 20 07:39:00.830623 2026] [security2:error] [pid 171532:tid 171700] [client 154.192.123.127:17777] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k9EEhLvMuMRNpl00XrAAAATA"]
[Mon Jul 20 07:39:00.843202 2026] [security2:error] [pid 171532:tid 171692] [client 14.225.17.146:57185] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4k9EEhLvMuMRNpl00XmAAAASg"], referer: http://adastra.love/bc
[Mon Jul 20 07:39:00.950270 2026] [security2:error] [pid 178071:tid 178241] [client 149.0.16.108:53661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k9Bltgi7HBmNwzJNFEQAAACY"]
[Mon Jul 20 07:39:00.950646 2026] [security2:error] [pid 178071:tid 178241] [client 149.0.16.108:53661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k9Bltgi7HBmNwzJNFEQAAACY"]
[Mon Jul 20 07:39:01.038472 2026] [security2:error] [pid 178071:tid 178080] [remote 198.244.242.116:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "puppoopatrol.com"] [uri "/robots.txt"] [unique_id "al4k9Rltgi7HBmNwzJNFFAAANwc"]
[Mon Jul 20 07:39:01.038725 2026] [security2:error] [pid 178071:tid 178258] [client 198.244.242.116:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "puppoopatrol.com"] [uri "/robots.txt"] [unique_id "al4k9Rltgi7HBmNwzJNFFAAANwc"]
[Mon Jul 20 07:39:01.044441 2026] [security2:error] [pid 178071:tid 178218] [client 103.106.165.44:62553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k9Rltgi7HBmNwzJNFFQAAAA8"]
[Mon Jul 20 07:39:01.044561 2026] [security2:error] [pid 178071:tid 178218] [client 103.106.165.44:62553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k9Rltgi7HBmNwzJNFFQAAAA8"]
[Mon Jul 20 07:39:01.081771 2026] [security2:error] [pid 171532:tid 171701] [client 57.141.18.108:30828] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k8UEhLvMuMRNpl00WbQABMUg"]
[Mon Jul 20 07:39:01.091113 2026] [security2:error] [pid 178071:tid 178256] [client 136.107.23.73:55524] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4k9Rltgi7HBmNwzJNFFgAAADU"]
[Mon Jul 20 07:39:01.264456 2026] [security2:error] [pid 171532:tid 171698] [client 57.141.18.10:64096] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k8UEhLvMuMRNpl00WegABLl8"]
[Mon Jul 20 07:39:01.420692 2026] [security2:error] [pid 178071:tid 178257] [client 14.225.17.146:57163] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4k9Rltgi7HBmNwzJNFGwAAADY"], referer: http://betterbonddogtraining.com/bc
[Mon Jul 20 07:39:01.466681 2026] [security2:error] [pid 178071:tid 178273] [client 136.107.23.73:54390] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4k9Rltgi7HBmNwzJNFIAAAAEY"]
[Mon Jul 20 07:39:01.533475 2026] [security2:error] [pid 171532:tid 171770] [client 14.225.17.146:56945] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4k9EEhLvMuMRNpl00XgAAAAXY"], referer: http://hammadownenterprises.com/bc
[Mon Jul 20 07:39:01.605881 2026] [security2:error] [pid 171532:tid 171738] [client 14.225.17.146:56078] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4k9UEhLvMuMRNpl00X0AAAAVY"], referer: https://sesamegreenbeans.com/bc
[Mon Jul 20 07:39:01.913316 2026] [security2:error] [pid 171532:tid 171680] [client 136.107.23.73:56108] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4k9UEhLvMuMRNpl00X4gAAARw"]
[Mon Jul 20 07:39:01.914815 2026] [security2:error] [pid 171532:tid 171665] [client 77.110.127.138:53332] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-border/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4k9UEhLvMuMRNpl00X4wAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:02.134771 2026] [security2:error] [pid 178071:tid 178084] [remote 57.141.18.43:25132] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3671901"] [unique_id "al4k9hltgi7HBmNwzJNFOwAABgs"]
[Mon Jul 20 07:39:02.208404 2026] [security2:error] [pid 178071:tid 178327] [client 136.107.23.73:60572] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4k9hltgi7HBmNwzJNFQgAAAHw"]
[Mon Jul 20 07:39:02.257251 2026] [security2:error] [pid 178071:tid 178087] [remote 51.89.129.155:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "puppoopatrol.com"] [uri "/wp-sitemap.xml"] [unique_id "al4k9hltgi7HBmNwzJNFQwAAFA4"]
[Mon Jul 20 07:39:02.257449 2026] [security2:error] [pid 178071:tid 178223] [client 51.89.129.155:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "puppoopatrol.com"] [uri "/wp-sitemap.xml"] [unique_id "al4k9hltgi7HBmNwzJNFQwAAFA4"]
[Mon Jul 20 07:39:02.275808 2026] [security2:error] [pid 178071:tid 178227] [client 46.110.96.34:32413] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4k9hltgi7HBmNwzJNFRAAAABg"]
[Mon Jul 20 07:39:02.302960 2026] [security2:error] [pid 171532:tid 171673] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k9kEhLvMuMRNpl00X7AAAARU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:02.660185 2026] [security2:error] [pid 178071:tid 178245] [client 136.107.23.73:52433] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4k9hltgi7HBmNwzJNFTwAAACo"]
[Mon Jul 20 07:39:02.715512 2026] [security2:error] [pid 171532:tid 171671] [client 77.110.127.138:53338] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/"] [unique_id "al4k9kEhLvMuMRNpl00YAAAAARM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:02.800721 2026] [core:error] [pid 171532:tid 171669] [client 14.225.17.146:51281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/bc
[Mon Jul 20 07:39:02.800743 2026] [core:error] [pid 171532:tid 171669] [client 14.225.17.146:51281] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/bc
[Mon Jul 20 07:39:03.038096 2026] [security2:error] [pid 171532:tid 171722] [client 57.141.18.50:43996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k8kEhLvMuMRNpl00XBwABRmY"]
[Mon Jul 20 07:39:03.187769 2026] [security2:error] [pid 178071:tid 178300] [client 136.107.23.73:63527] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4k9xltgi7HBmNwzJNFYgAAAGE"]
[Mon Jul 20 07:39:03.425805 2026] [security2:error] [pid 171532:tid 171729] [client 114.119.132.10:36061] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/watercolor"] [unique_id "al4k90EhLvMuMRNpl00YKwAAAU0"], referer: https://sustaintheart.com/can-you-use-wood-carving-tools-on-a-lathe/
[Mon Jul 20 07:39:03.584513 2026] [security2:error] [pid 178071:tid 178219] [client 136.107.23.73:51150] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "yap.vjb.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4k9xltgi7HBmNwzJNFcwAAABA"]
[Mon Jul 20 07:39:03.626439 2026] [security2:error] [pid 178071:tid 178236] [client 51.68.111.208:10245] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.ravmike.com"] [uri "/robots.txt"] [unique_id "al4k9xltgi7HBmNwzJNFdgAAACE"]
[Mon Jul 20 07:39:03.626558 2026] [security2:error] [pid 178071:tid 178236] [client 51.68.111.208:10245] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.ravmike.com"] [uri "/robots.txt"] [unique_id "al4k9xltgi7HBmNwzJNFdgAAACE"]
[Mon Jul 20 07:39:03.884157 2026] [security2:error] [pid 178071:tid 178243] [client 154.192.233.184:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k9xltgi7HBmNwzJNFegAAACg"]
[Mon Jul 20 07:39:03.884695 2026] [security2:error] [pid 178071:tid 178243] [client 154.192.233.184:60872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4k9xltgi7HBmNwzJNFegAAACg"]
[Mon Jul 20 07:39:04.128973 2026] [security2:error] [pid 178071:tid 178320] [client 103.176.215.66:51716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k-Bltgi7HBmNwzJNFfgAAAHU"]
[Mon Jul 20 07:39:04.129141 2026] [security2:error] [pid 178071:tid 178320] [client 103.176.215.66:51716] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4k-Bltgi7HBmNwzJNFfgAAAHU"]
[Mon Jul 20 07:39:04.227858 2026] [security2:error] [pid 171532:tid 171669] [client 14.225.17.146:56213] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4k-EEhLvMuMRNpl00YSwAAARE"], referer: http://fkconstructionfunding.com/bc
[Mon Jul 20 07:39:04.298457 2026] [security2:error] [pid 178071:tid 178246] [client 35.90.38.209:57414] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4k-Bltgi7HBmNwzJNFiAAAACs"]
[Mon Jul 20 07:39:04.588011 2026] [autoindex:error] [pid 171532:tid 171617] [remote 8.229.41.77:53037] AH01276: Cannot serve directory /home2/zajlqimy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.zaj.lqi.mybluehost.me
[Mon Jul 20 07:39:04.679214 2026] [security2:error] [pid 178071:tid 178269] [client 14.225.17.146:62537] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4k9xltgi7HBmNwzJNFWgAAAEI"], referer: http://nomorewetsheets.net/bc
[Mon Jul 20 07:39:04.867115 2026] [security2:error] [pid 171532:tid 171681] [client 57.141.18.12:47570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k9EEhLvMuMRNpl00XkAABHR4"]
[Mon Jul 20 07:39:05.120859 2026] [security2:error] [pid 178071:tid 178267] [client 143.44.185.218:18246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k-Rltgi7HBmNwzJNFnAAAAEA"]
[Mon Jul 20 07:39:05.121020 2026] [security2:error] [pid 178071:tid 178267] [client 143.44.185.218:18246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4k-Rltgi7HBmNwzJNFnAAAAEA"]
[Mon Jul 20 07:39:05.182813 2026] [security2:error] [pid 178071:tid 178327] [client 216.73.163.115:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "guau-pet-rrimos.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4k-Rltgi7HBmNwzJNFngAAAHw"]
[Mon Jul 20 07:39:05.273259 2026] [security2:error] [pid 171532:tid 171769] [client 14.225.17.146:65095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4k-UEhLvMuMRNpl00YeAAAAXU"], referer: https://fkconstructionfunding.com/bc
[Mon Jul 20 07:39:05.297270 2026] [security2:error] [pid 178071:tid 178100] [remote 5.161.225.162:40452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4k-Rltgi7HBmNwzJNFoQAADhs"]
[Mon Jul 20 07:39:05.327712 2026] [security2:error] [pid 171532:tid 171759] [client 179.127.84.238:63612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k-UEhLvMuMRNpl00YggAAAWs"]
[Mon Jul 20 07:39:05.327857 2026] [security2:error] [pid 171532:tid 171759] [client 179.127.84.238:63612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4k-UEhLvMuMRNpl00YggAAAWs"]
[Mon Jul 20 07:39:05.427607 2026] [security2:error] [pid 178071:tid 178249] [client 57.141.18.0:57600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k9Bltgi7HBmNwzJNFDwAALgU"]
[Mon Jul 20 07:39:05.465099 2026] [security2:error] [pid 178071:tid 178102] [remote 5.161.225.162:40452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4k-Rltgi7HBmNwzJNFrQAAeB0"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:39:05.489745 2026] [security2:error] [pid 171532:tid 171564] [remote 124.55.178.99:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4k-UEhLvMuMRNpl00YiQABeR8"]
[Mon Jul 20 07:39:05.769861 2026] [security2:error] [pid 171532:tid 171689] [client 191.202.66.27:59384] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k-UEhLvMuMRNpl00YmwAAASU"]
[Mon Jul 20 07:39:05.770019 2026] [security2:error] [pid 171532:tid 171689] [client 191.202.66.27:59384] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4k-UEhLvMuMRNpl00YmwAAASU"]
[Mon Jul 20 07:39:05.790005 2026] [security2:error] [pid 171532:tid 171704] [client 14.225.17.146:56190] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4k90EhLvMuMRNpl00YSAAAATQ"], referer: http://fineartsfactory.net/bc
[Mon Jul 20 07:39:05.935608 2026] [security2:error] [pid 171532:tid 171568] [remote 124.55.178.99:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4k-UEhLvMuMRNpl00YqQABVyM"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:39:06.096241 2026] [security2:error] [pid 171532:tid 171699] [client 136.158.60.21:13064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k-kEhLvMuMRNpl00YsgAAAS8"]
[Mon Jul 20 07:39:06.096366 2026] [security2:error] [pid 171532:tid 171699] [client 136.158.60.21:13064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4k-kEhLvMuMRNpl00YsgAAAS8"]
[Mon Jul 20 07:39:06.531335 2026] [security2:error] [pid 171532:tid 171753] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k-kEhLvMuMRNpl00YvgAAAWU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:06.576264 2026] [security2:error] [pid 178071:tid 178261] [client 14.225.17.146:55506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4k-hltgi7HBmNwzJNFzQAAADo"], referer: http://ironcitywellness.com/bc
[Mon Jul 20 07:39:06.639392 2026] [security2:error] [pid 171532:tid 171736] [client 49.37.242.14:49539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4k-kEhLvMuMRNpl00YygAAAVQ"]
[Mon Jul 20 07:39:06.639528 2026] [security2:error] [pid 171532:tid 171736] [client 49.37.242.14:49539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4k-kEhLvMuMRNpl00YygAAAVQ"]
[Mon Jul 20 07:39:06.654163 2026] [security2:error] [pid 178071:tid 178312] [client 104.207.50.121:42881] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4k-hltgi7HBmNwzJNF0gAAAG0"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:06.717438 2026] [security2:error] [pid 171532:tid 171547] [remote 41.185.8.252:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4k-kEhLvMuMRNpl00YzgABgg4"]
[Mon Jul 20 07:39:06.934820 2026] [security2:error] [pid 171532:tid 171757] [client 14.225.17.146:55569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4k-kEhLvMuMRNpl00Y1gAAAWk"], referer: http://backandneckpainrelieflaceychiropractor.com/bc
[Mon Jul 20 07:39:07.198687 2026] [security2:error] [pid 171532:tid 171669] [client 14.225.17.146:55712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4k-UEhLvMuMRNpl00YngAAARE"], referer: http://expertcultures.com/bc
[Mon Jul 20 07:39:07.270495 2026] [security2:error] [pid 171532:tid 171751] [client 14.225.17.146:59609] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4k-kEhLvMuMRNpl00YtgAAAWM"], referer: http://adultdaycarereno.com/bc
[Mon Jul 20 07:39:07.366927 2026] [security2:error] [pid 171532:tid 171676] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k-0EhLvMuMRNpl00Y6AAAARg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:07.390781 2026] [security2:error] [pid 171532:tid 171789] [client 14.225.17.146:59515] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4k-kEhLvMuMRNpl00YrAAAAYg"], referer: http://balticsteelmgmt.com/bc
[Mon Jul 20 07:39:07.506008 2026] [security2:error] [pid 171532:tid 171619] [remote 41.185.8.252:39814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 252.8.185.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "besttestedrecipes.com"] [uri "/wp-login.php"] [unique_id "al4k-0EhLvMuMRNpl00ZAQABglY"], referer: https://besttestedrecipes.com/wp-login.php
[Mon Jul 20 07:39:07.735018 2026] [security2:error] [pid 171532:tid 171735] [client 57.141.18.96:65466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k90EhLvMuMRNpl00YIwABU30"]
[Mon Jul 20 07:39:07.907393 2026] [security2:error] [pid 178071:tid 178323] [client 50.116.65.227:50518] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4k-xltgi7HBmNwzJNGCAAAAHg"]
[Mon Jul 20 07:39:07.917981 2026] [security2:error] [pid 178071:tid 178295] [client 50.116.65.227:50534] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4k-xltgi7HBmNwzJNGCQAAAFw"]
[Mon Jul 20 07:39:08.231507 2026] [security2:error] [pid 178071:tid 178236] [client 14.225.17.146:59299] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4k_Bltgi7HBmNwzJNGFAAAACE"], referer: https://adultdaycarereno.com/bc
[Mon Jul 20 07:39:08.282649 2026] [security2:error] [pid 178071:tid 178225] [client 49.47.218.174:20226] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k_Bltgi7HBmNwzJNGFQAAABY"]
[Mon Jul 20 07:39:08.282825 2026] [security2:error] [pid 178071:tid 178225] [client 49.47.218.174:20226] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4k_Bltgi7HBmNwzJNGFQAAABY"]
[Mon Jul 20 07:39:08.465815 2026] [security2:error] [pid 171532:tid 171755] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4k-0EhLvMuMRNpl00ZBQABZ0I"], referer: http://ardhalwafaa.com/bc
[Mon Jul 20 07:39:08.488471 2026] [autoindex:error] [pid 178071:tid 178122] [remote 136.114.198.221:56540] AH01276: Cannot serve directory /home2/cxrmhtmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.cxr.mht.mybluehost.me
[Mon Jul 20 07:39:08.841378 2026] [security2:error] [pid 178071:tid 178214] [client 193.37.33.29:63693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4k_Bltgi7HBmNwzJNGIgAAAAs"]
[Mon Jul 20 07:39:08.851316 2026] [security2:error] [pid 178071:tid 178267] [client 193.37.33.40:65041] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 40.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4k_Bltgi7HBmNwzJNGIwAAAEA"]
[Mon Jul 20 07:39:08.885211 2026] [security2:error] [pid 178071:tid 178203] [client 180.249.173.210:60020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k_Bltgi7HBmNwzJNGKAAAAAA"]
[Mon Jul 20 07:39:08.886174 2026] [security2:error] [pid 178071:tid 178203] [client 180.249.173.210:60020] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4k_Bltgi7HBmNwzJNGKAAAAAA"]
[Mon Jul 20 07:39:09.462128 2026] [autoindex:error] [pid 171532:tid 171727] [client 13.219.67.125:38640] AH01276: Cannot serve directory /home1/thesums1/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:39:09.606995 2026] [security2:error] [pid 171532:tid 171706] [client 57.141.18.75:40846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k-UEhLvMuMRNpl00YigABNik"]
[Mon Jul 20 07:39:09.607100 2026] [security2:error] [pid 171532:tid 171760] [client 57.141.18.1:50802] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k-UEhLvMuMRNpl00YiwABbH8"]
[Mon Jul 20 07:39:09.628078 2026] [security2:error] [pid 178071:tid 178244] [client 57.141.18.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4k_Rltgi7HBmNwzJNGQQAAACk"]
[Mon Jul 20 07:39:09.983849 2026] [security2:error] [pid 178071:tid 178285] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k_Rltgi7HBmNwzJNGSgAAAFI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:10.249865 2026] [security2:error] [pid 178071:tid 178261] [client 103.139.191.61:62336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k_hltgi7HBmNwzJNGXgAAADo"]
[Mon Jul 20 07:39:10.249988 2026] [security2:error] [pid 178071:tid 178261] [client 103.139.191.61:62336] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4k_hltgi7HBmNwzJNGXgAAADo"]
[Mon Jul 20 07:39:10.437286 2026] [security2:error] [pid 178071:tid 178319] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k_hltgi7HBmNwzJNGWwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:10.464040 2026] [security2:error] [pid 178071:tid 178239] [client 63.179.149.246:43600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 246.149.179.63.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k_hltgi7HBmNwzJNGawAAACQ"]
[Mon Jul 20 07:39:10.464237 2026] [security2:error] [pid 178071:tid 178239] [client 63.179.149.246:43600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4k_hltgi7HBmNwzJNGawAAACQ"]
[Mon Jul 20 07:39:10.500249 2026] [security2:error] [pid 171532:tid 171775] [client 14.225.17.146:55502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4k_EEhLvMuMRNpl00ZOQAAAXo"], referer: http://olearyplumbingllc.com/bc
[Mon Jul 20 07:39:10.506910 2026] [security2:error] [pid 171532:tid 171786] [client 209.242.197.225:36672] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4k_kEhLvMuMRNpl00ZbgABhVg"], referer: https://www.thewelloiledlife.com/for-that-time-of-the-month-essential-oil-uses/
[Mon Jul 20 07:39:10.772099 2026] [security2:error] [pid 178071:tid 178207] [client 36.93.152.155:58339] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k_hltgi7HBmNwzJNGdwAAAAQ"]
[Mon Jul 20 07:39:10.772186 2026] [security2:error] [pid 178071:tid 178207] [client 36.93.152.155:58339] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4k_hltgi7HBmNwzJNGdwAAAAQ"]
[Mon Jul 20 07:39:10.861446 2026] [security2:error] [pid 178071:tid 178264] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k_hltgi7HBmNwzJNGdAAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:10.951011 2026] [security2:error] [pid 178071:tid 178278] [client 57.141.18.85:24036] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k-xltgi7HBmNwzJNF5QAASyQ"]
[Mon Jul 20 07:39:11.267281 2026] [security2:error] [pid 171532:tid 171705] [client 154.192.123.127:18271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k_0EhLvMuMRNpl00ZmwAAATU"]
[Mon Jul 20 07:39:11.267383 2026] [security2:error] [pid 171532:tid 171705] [client 154.192.123.127:18271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4k_0EhLvMuMRNpl00ZmwAAATU"]
[Mon Jul 20 07:39:11.296578 2026] [security2:error] [pid 178071:tid 178263] [client 116.193.128.26:57661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k_xltgi7HBmNwzJNGhwAAADw"]
[Mon Jul 20 07:39:11.296735 2026] [security2:error] [pid 178071:tid 178263] [client 116.193.128.26:57661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4k_xltgi7HBmNwzJNGhwAAADw"]
[Mon Jul 20 07:39:11.364866 2026] [security2:error] [pid 171532:tid 171675] [client 155.2.215.79:55063] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4k_0EhLvMuMRNpl00ZmAAAARc"]
[Mon Jul 20 07:39:11.610224 2026] [security2:error] [pid 178071:tid 178268] [client 149.0.16.108:54191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k_xltgi7HBmNwzJNGlQAAAEE"]
[Mon Jul 20 07:39:11.611004 2026] [security2:error] [pid 178071:tid 178268] [client 149.0.16.108:54191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4k_xltgi7HBmNwzJNGlQAAAEE"]
[Mon Jul 20 07:39:11.697191 2026] [security2:error] [pid 178071:tid 178223] [client 57.141.18.95:65462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k-xltgi7HBmNwzJNGAwAAFCw"]
[Mon Jul 20 07:39:11.724633 2026] [security2:error] [pid 178071:tid 178221] [client 14.225.17.146:55905] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4k_hltgi7HBmNwzJNGcwAAABI"], referer: http://nikkidesigns.net/bc
[Mon Jul 20 07:39:11.866553 2026] [security2:error] [pid 178071:tid 178315] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4k_xltgi7HBmNwzJNGmgAAAHA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:12.167303 2026] [security2:error] [pid 178071:tid 178230] [client 14.225.17.146:55935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4k_xltgi7HBmNwzJNGowAAABs"]
[Mon Jul 20 07:39:12.183404 2026] [security2:error] [pid 178071:tid 178317] [client 14.225.17.146:55853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4lABltgi7HBmNwzJNGqwAAAHI"], referer: http://keywayconstructionclt.com/bc
[Mon Jul 20 07:39:12.956675 2026] [security2:error] [pid 171532:tid 171701] [client 50.116.65.227:49240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "obc.enu.mybluehost.me"] [uri "/website_d9d7fe47/wp-cron.php"] [unique_id "al4lAEEhLvMuMRNpl00Z5gAAATE"]
[Mon Jul 20 07:39:13.101424 2026] [security2:error] [pid 178071:tid 178253] [client 14.225.17.146:57099] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4lARltgi7HBmNwzJNG1AAAADI"], referer: https://keywayconstructionclt.com/bc
[Mon Jul 20 07:39:13.403278 2026] [security2:error] [pid 178071:tid 178168] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/docker-compose.yaml"] [unique_id "al4lARltgi7HBmNwzJNG5AAAC14"]
[Mon Jul 20 07:39:13.403432 2026] [security2:error] [pid 178071:tid 178165] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/.ssh/id_rsa"] [unique_id "al4lARltgi7HBmNwzJNG5gAAC1s"]
[Mon Jul 20 07:39:13.403683 2026] [authz_core:error] [pid 178071:tid 178159] [remote 34.39.87.128:34974] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 07:39:13.404362 2026] [security2:error] [pid 178071:tid 178160] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "admin.areitoproducciones.com"] [uri "/.ssh/id_ecdsa"] [unique_id "al4lARltgi7HBmNwzJNG4QAAC1Y"]
[Mon Jul 20 07:39:13.413402 2026] [security2:error] [pid 171532:tid 171749] [client 14.225.17.146:59305] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4k_0EhLvMuMRNpl00ZuwAAAWE"], referer: http://709fx.com/bc
[Mon Jul 20 07:39:13.530623 2026] [security2:error] [pid 171532:tid 171710] [client 14.225.17.146:58898] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4lAUEhLvMuMRNpl00Z9wAAATo"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/bc
[Mon Jul 20 07:39:13.628046 2026] [security2:error] [pid 171532:tid 171677] [client 57.141.18.12:42612] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k_UEhLvMuMRNpl00ZVwABGVw"]
[Mon Jul 20 07:39:13.952718 2026] [security2:error] [pid 178071:tid 178186] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/.ssh/id_dsa"] [unique_id "al4lARltgi7HBmNwzJNHEQAAC3A"]
[Mon Jul 20 07:39:14.305546 2026] [security2:error] [pid 171532:tid 171751] [client 154.192.233.184:61337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lAkEhLvMuMRNpl00aFgAAAWM"]
[Mon Jul 20 07:39:14.305647 2026] [security2:error] [pid 171532:tid 171751] [client 154.192.233.184:61337] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lAkEhLvMuMRNpl00aFgAAAWM"]
[Mon Jul 20 07:39:14.309515 2026] [security2:error] [pid 178071:tid 178078] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/key.pem"] [unique_id "al4lAhltgi7HBmNwzJNHQQAACwU"]
[Mon Jul 20 07:39:14.337257 2026] [security2:error] [pid 178071:tid 178252] [client 50.116.65.227:49256] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4lAhltgi7HBmNwzJNHQwAAADE"]
[Mon Jul 20 07:39:14.351179 2026] [security2:error] [pid 178071:tid 178276] [client 50.116.65.227:19382] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/11/Fu-Lin-Feature-Image.jpg"] [unique_id "al4lAhltgi7HBmNwzJNHRAAAAEk"]
[Mon Jul 20 07:39:14.411023 2026] [security2:error] [pid 171532:tid 171670] [client 14.225.17.146:63986] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4lAEEhLvMuMRNpl00Z5AAAARI"], referer: http://reosportsboats.com/bc
[Mon Jul 20 07:39:14.446164 2026] [security2:error] [pid 178071:tid 178118] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/id_dsa"] [unique_id "al4lAhltgi7HBmNwzJNHVQAAaC0"]
[Mon Jul 20 07:39:14.446878 2026] [security2:error] [pid 178071:tid 178119] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/id_rsa"] [unique_id "al4lAhltgi7HBmNwzJNHVgAAaC4"]
[Mon Jul 20 07:39:14.541180 2026] [security2:error] [pid 178071:tid 178264] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lAhltgi7HBmNwzJNHQgAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:14.749081 2026] [security2:error] [pid 178071:tid 178139] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/privatekey.key"] [unique_id "al4lAhltgi7HBmNwzJNHdQAAOUI"]
[Mon Jul 20 07:39:14.821626 2026] [security2:error] [pid 171532:tid 171690] [client 103.176.215.66:52247] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lAkEhLvMuMRNpl00aLwAAASY"]
[Mon Jul 20 07:39:14.821838 2026] [security2:error] [pid 171532:tid 171690] [client 103.176.215.66:52247] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lAkEhLvMuMRNpl00aLwAAASY"]
[Mon Jul 20 07:39:14.935672 2026] [proxy:error] [pid 178071:tid 178238] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:14.935728 2026] [proxy_http:error] [pid 178071:tid 178238] [client 152.42.129.206:33446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:39:14.936536 2026] [proxy:error] [pid 178071:tid 178238] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:14.936565 2026] [proxy_http:error] [pid 178071:tid 178238] [client 152.42.129.206:33446] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:39:15.233970 2026] [proxy:error] [pid 171532:tid 171680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:15.234052 2026] [proxy_http:error] [pid 171532:tid 171680] [client 152.42.129.206:33460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.zhgraphics.com/
[Mon Jul 20 07:39:15.234546 2026] [proxy:error] [pid 171532:tid 171680] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:15.234574 2026] [proxy_http:error] [pid 171532:tid 171680] [client 152.42.129.206:33460] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: http://cpcalendars.zhgraphics.com/
[Mon Jul 20 07:39:15.255425 2026] [security2:error] [pid 171532:tid 171700] [client 57.141.18.14:62166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4k_0EhLvMuMRNpl00ZlAABMBE"]
[Mon Jul 20 07:39:15.276873 2026] [security2:error] [pid 178071:tid 178302] [client 193.36.225.169:32971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 169.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4lAxltgi7HBmNwzJNHlQAAAGM"]
[Mon Jul 20 07:39:15.277693 2026] [security2:error] [pid 178071:tid 178251] [client 136.144.33.35:55389] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4lAxltgi7HBmNwzJNHlAAAADA"]
[Mon Jul 20 07:39:15.391825 2026] [security2:error] [pid 178071:tid 178231] [client 14.225.17.146:58796] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4lAxltgi7HBmNwzJNHlwAAABw"], referer: https://reosportsboats.com/bc
[Mon Jul 20 07:39:15.465605 2026] [security2:error] [pid 171532:tid 171664] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lA0EhLvMuMRNpl00aUgAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:15.708959 2026] [security2:error] [pid 178071:tid 178311] [client 66.249.70.3:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4lAxltgi7HBmNwzJNHogAAbDQ"]
[Mon Jul 20 07:39:15.816532 2026] [security2:error] [pid 171532:tid 171767] [client 179.127.84.238:64287] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lA0EhLvMuMRNpl00aYgAAAXM"]
[Mon Jul 20 07:39:15.816691 2026] [security2:error] [pid 171532:tid 171767] [client 179.127.84.238:64287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lA0EhLvMuMRNpl00aYgAAAXM"]
[Mon Jul 20 07:39:15.850849 2026] [proxy:error] [pid 171532:tid 171669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:15.850894 2026] [proxy_http:error] [pid 171532:tid 171669] [client 152.42.129.206:38136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:39:15.852005 2026] [proxy:error] [pid 171532:tid 171669] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:15.852043 2026] [proxy_http:error] [pid 171532:tid 171669] [client 152.42.129.206:38136] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:39:15.899994 2026] [security2:error] [pid 178071:tid 178158] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "admin.areitoproducciones.com"] [uri "/graphql"] [unique_id "al4lAxltgi7HBmNwzJNHsgAAd1Q"]
[Mon Jul 20 07:39:15.925504 2026] [security2:error] [pid 178071:tid 178174] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/.openclaw/openclaw.json"] [unique_id "al4lAxltgi7HBmNwzJNHvQAAPGQ"]
[Mon Jul 20 07:39:15.926842 2026] [security2:error] [pid 178071:tid 178170] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/.hermes/.env"] [unique_id "al4lAxltgi7HBmNwzJNHugAAPGA"]
[Mon Jul 20 07:39:15.926955 2026] [security2:error] [pid 178071:tid 178161] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/.openclaw/.env"] [unique_id "al4lAxltgi7HBmNwzJNHuwAAPFc"]
[Mon Jul 20 07:39:15.929072 2026] [security2:error] [pid 178071:tid 178284] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lAxltgi7HBmNwzJNHqwAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:15.950397 2026] [security2:error] [pid 171532:tid 171673] [client 158.173.166.181:62631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lA0EhLvMuMRNpl00aaAAAARU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:39:16.395743 2026] [security2:error] [pid 171532:tid 171721] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lBEEhLvMuMRNpl00acAAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:16.451677 2026] [security2:error] [pid 178071:tid 178206] [client 191.202.66.27:59870] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lBBltgi7HBmNwzJNH2QAAAAM"]
[Mon Jul 20 07:39:16.451801 2026] [security2:error] [pid 178071:tid 178206] [client 191.202.66.27:59870] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lBBltgi7HBmNwzJNH2QAAAAM"]
[Mon Jul 20 07:39:16.773019 2026] [security2:error] [pid 178071:tid 178297] [client 57.141.18.40:29916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lABltgi7HBmNwzJNGwAAAXlA"]
[Mon Jul 20 07:39:16.794035 2026] [security2:error] [pid 178071:tid 178238] [client 119.28.181.155:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4lBBltgi7HBmNwzJNH3wAAI2o"], referer: https://www.aleishapenny.ca/listing/page/302?paged=1&view=grid&posts_per_page=48
[Mon Jul 20 07:39:16.812683 2026] [security2:error] [pid 178071:tid 178291] [client 136.158.60.21:14796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lBBltgi7HBmNwzJNH6wAAAFg"]
[Mon Jul 20 07:39:16.812815 2026] [security2:error] [pid 178071:tid 178291] [client 136.158.60.21:14796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lBBltgi7HBmNwzJNH6wAAAFg"]
[Mon Jul 20 07:39:16.976142 2026] [security2:error] [pid 178071:tid 178203] [client 14.225.17.146:58820] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4lAxltgi7HBmNwzJNHlgAAAAA"], referer: http://fluidtemple.org/bc
[Mon Jul 20 07:39:17.189470 2026] [security2:error] [pid 178071:tid 178247] [client 18.141.57.241:15096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lBRltgi7HBmNwzJNH9AAAACw"]
[Mon Jul 20 07:39:17.189567 2026] [security2:error] [pid 178071:tid 178247] [client 18.141.57.241:15096] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lBRltgi7HBmNwzJNH9AAAACw"]
[Mon Jul 20 07:39:17.254990 2026] [security2:error] [pid 178071:tid 178186] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "admin.areitoproducciones.com"] [uri "/api/graphql"] [unique_id "al4lBRltgi7HBmNwzJNH9gAAFHA"]
[Mon Jul 20 07:39:17.279884 2026] [security2:error] [pid 178071:tid 178173] [remote 8.217.108.67:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4lBRltgi7HBmNwzJNH-wAAIWM"]
[Mon Jul 20 07:39:17.320153 2026] [security2:error] [pid 178071:tid 178218] [client 143.44.185.218:20607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lBRltgi7HBmNwzJNIAwAAAA8"]
[Mon Jul 20 07:39:17.322287 2026] [security2:error] [pid 178071:tid 178218] [client 143.44.185.218:20607] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lBRltgi7HBmNwzJNIAwAAAA8"]
[Mon Jul 20 07:39:17.458870 2026] [security2:error] [pid 178071:tid 178230] [client 57.141.18.46:51426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lARltgi7HBmNwzJNG7AAAG2E"]
[Mon Jul 20 07:39:17.721983 2026] [security2:error] [pid 178071:tid 178196] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "admin.areitoproducciones.com"] [uri "/.hermes/config.yaml"] [unique_id "al4lBRltgi7HBmNwzJNIEwAAAno"]
[Mon Jul 20 07:39:17.744774 2026] [security2:error] [pid 178071:tid 178295] [client 57.141.18.67:59594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lARltgi7HBmNwzJNHDgAAXG0"]
[Mon Jul 20 07:39:17.875570 2026] [security2:error] [pid 178071:tid 178085] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "admin.areitoproducciones.com"] [uri "/v1/graphql"] [unique_id "al4lBRltgi7HBmNwzJNIGwAAegw"]
[Mon Jul 20 07:39:17.951071 2026] [security2:error] [pid 178071:tid 178084] [remote 152.228.213.32:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4lBRltgi7HBmNwzJNIJwAAEAs"]
[Mon Jul 20 07:39:18.049805 2026] [security2:error] [pid 178071:tid 178079] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "admin.areitoproducciones.com"] [uri "/wp-config.php.old"] [unique_id "al4lBhltgi7HBmNwzJNINQAALAY"]
[Mon Jul 20 07:39:18.049805 2026] [security2:error] [pid 178071:tid 178083] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "admin.areitoproducciones.com"] [uri "/wp-config.php.bak"] [unique_id "al4lBhltgi7HBmNwzJNINAAALAo"]
[Mon Jul 20 07:39:18.148073 2026] [security2:error] [pid 178071:tid 178301] [client 14.225.17.146:49707] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4lBRltgi7HBmNwzJNIKgAAAGI"], referer: http://laceycaraccident.com/bc
[Mon Jul 20 07:39:18.205929 2026] [security2:error] [pid 178071:tid 178096] [remote 152.228.213.32:33574] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4lBhltgi7HBmNwzJNIRwAAXxc"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:39:18.525326 2026] [security2:error] [pid 178071:tid 178107] [remote 8.217.108.67:39712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "detroitcsc.com"] [uri "/wp-login.php"] [unique_id "al4lBhltgi7HBmNwzJNIZAAAFyI"], referer: https://detroitcsc.com/wp-login.php
[Mon Jul 20 07:39:18.584610 2026] [security2:error] [pid 178071:tid 178106] [remote 20.153.140.50:43134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lBhltgi7HBmNwzJNIbQAAOyE"]
[Mon Jul 20 07:39:18.860709 2026] [security2:error] [pid 178071:tid 178242] [client 49.47.218.174:64987] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lBhltgi7HBmNwzJNIgQAAACc"]
[Mon Jul 20 07:39:18.860836 2026] [security2:error] [pid 178071:tid 178242] [client 49.47.218.174:64987] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lBhltgi7HBmNwzJNIgQAAACc"]
[Mon Jul 20 07:39:19.056698 2026] [security2:error] [pid 178071:tid 178147] [remote 20.153.140.50:43134] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lBxltgi7HBmNwzJNIpgAAZ0k"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:39:19.222366 2026] [security2:error] [pid 178071:tid 178149] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/.env.php.bak"] [unique_id "al4lBxltgi7HBmNwzJNIrgAACEs"]
[Mon Jul 20 07:39:19.222611 2026] [security2:error] [pid 178071:tid 178211] [client 34.39.87.128:34974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.areitoproducciones.com"] [uri "/.env.php.bak"] [unique_id "al4lBxltgi7HBmNwzJNIrgAACEs"]
[Mon Jul 20 07:39:19.237673 2026] [security2:error] [pid 178071:tid 178150] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.87.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.areitoproducciones.com"] [uri "/config/.env.php"] [unique_id "al4lBxltgi7HBmNwzJNIrwAAHEw"]
[Mon Jul 20 07:39:19.255137 2026] [security2:error] [pid 178071:tid 178152] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/laravel/.env"] [unique_id "al4lBxltgi7HBmNwzJNItQAAdU4"]
[Mon Jul 20 07:39:19.255159 2026] [security2:error] [pid 178071:tid 178125] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/core/.env"] [unique_id "al4lBxltgi7HBmNwzJNItAAAdTQ"]
[Mon Jul 20 07:39:19.321324 2026] [security2:error] [pid 178071:tid 178213] [client 14.225.17.146:55189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4lBhltgi7HBmNwzJNIOwAAAAo"], referer: http://northbrookcpa.ca/bc
[Mon Jul 20 07:39:19.348198 2026] [proxy:error] [pid 178071:tid 178269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:19.348240 2026] [proxy_http:error] [pid 178071:tid 178269] [client 152.42.129.206:52628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.zhgraphics.com/
[Mon Jul 20 07:39:19.349149 2026] [proxy:error] [pid 178071:tid 178269] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:39:19.349192 2026] [proxy_http:error] [pid 178071:tid 178269] [client 152.42.129.206:52628] AH01114: HTTP: failed to make connection to backend: 127.0.0.1, referer: https://cpcalendars.zhgraphics.com/
[Mon Jul 20 07:39:19.385370 2026] [security2:error] [pid 178071:tid 178165] [remote 152.228.213.32:33590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4lBxltgi7HBmNwzJNIxQAAE1s"]
[Mon Jul 20 07:39:19.442594 2026] [security2:error] [pid 178071:tid 178319] [client 104.207.55.168:61099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lBxltgi7HBmNwzJNI1AAAAHQ"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:19.484722 2026] [security2:error] [pid 178071:tid 178241] [client 14.225.17.146:49604] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4lBxltgi7HBmNwzJNIvwAAACY"]
[Mon Jul 20 07:39:19.517211 2026] [security2:error] [pid 178071:tid 178236] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lBxltgi7HBmNwzJNIvAAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:19.564979 2026] [security2:error] [pid 178071:tid 178080] [remote 152.228.213.32:33590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "keywayconstructionclt.com"] [uri "/wp-login.php"] [unique_id "al4lBxltgi7HBmNwzJNI9QAAKQc"], referer: https://keywayconstructionclt.com/wp-login.php
[Mon Jul 20 07:39:19.597953 2026] [security2:error] [pid 178071:tid 178305] [client 180.249.173.210:60503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lBxltgi7HBmNwzJNI_QAAAGY"]
[Mon Jul 20 07:39:19.598062 2026] [security2:error] [pid 178071:tid 178305] [client 180.249.173.210:60503] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lBxltgi7HBmNwzJNI_QAAAGY"]
[Mon Jul 20 07:39:19.615078 2026] [security2:error] [pid 171532:tid 171627] [remote 98.156.100.191:59746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lB0EhLvMuMRNpl00anwABTl4"]
[Mon Jul 20 07:39:19.685317 2026] [security2:error] [pid 178071:tid 178239] [client 103.139.191.61:62853] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lBxltgi7HBmNwzJNJAgAAACQ"]
[Mon Jul 20 07:39:19.685467 2026] [security2:error] [pid 178071:tid 178239] [client 103.139.191.61:62853] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lBxltgi7HBmNwzJNJAgAAACQ"]
[Mon Jul 20 07:39:19.687916 2026] [security2:error] [pid 178071:tid 178247] [client 177.156.250.203:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4lBxltgi7HBmNwzJNI7AAALG0"]
[Mon Jul 20 07:39:19.695094 2026] [security2:error] [pid 178071:tid 178245] [client 14.225.17.146:49528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4lBxltgi7HBmNwzJNI2wAAACo"], referer: http://oldracelimited.com/bc
[Mon Jul 20 07:39:19.805299 2026] [security2:error] [pid 178071:tid 178075] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/application.yml"] [unique_id "al4lBxltgi7HBmNwzJNJCQAAVQI"]
[Mon Jul 20 07:39:19.830702 2026] [security2:error] [pid 178071:tid 178073] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/web/.env"] [unique_id "al4lBxltgi7HBmNwzJNJDgAAXAA"]
[Mon Jul 20 07:39:19.831577 2026] [security2:error] [pid 178071:tid 178101] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.87.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.areitoproducciones.com"] [uri "/configuration.php.bak"] [unique_id "al4lBxltgi7HBmNwzJNJEQAAXBw"]
[Mon Jul 20 07:39:19.831772 2026] [security2:error] [pid 178071:tid 178083] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/public/.env"] [unique_id "al4lBxltgi7HBmNwzJNJDQAAXAo"]
[Mon Jul 20 07:39:19.832798 2026] [security2:error] [pid 178071:tid 178200] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/.env.swp"] [unique_id "al4lBxltgi7HBmNwzJNJEAAAXH4"]
[Mon Jul 20 07:39:19.884482 2026] [security2:error] [pid 178071:tid 178093] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 128.87.39.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "admin.areitoproducciones.com"] [uri "/config.php.bak"] [unique_id "al4lBxltgi7HBmNwzJNJFAAAaxQ"]
[Mon Jul 20 07:39:20.081467 2026] [security2:error] [pid 178071:tid 178272] [client 104.207.59.200:52505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.59.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lCBltgi7HBmNwzJNJLAAAAEU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:20.441936 2026] [security2:error] [pid 178071:tid 178091] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/appsettings.Production.json"] [unique_id "al4lCBltgi7HBmNwzJNJUAAAfxI"]
[Mon Jul 20 07:39:20.491465 2026] [security2:error] [pid 178071:tid 178277] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lCBltgi7HBmNwzJNJPwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:20.681380 2026] [security2:error] [pid 178071:tid 178301] [client 45.3.55.9:12641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lCBltgi7HBmNwzJNJaAAAAGI"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:20.801525 2026] [security2:error] [pid 178071:tid 178143] [remote 192.241.143.148:51566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lCBltgi7HBmNwzJNJfQAAE0Y"]
[Mon Jul 20 07:39:20.873282 2026] [security2:error] [pid 178071:tid 178123] [remote 173.212.252.15:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lCBltgi7HBmNwzJNJgwAATDI"]
[Mon Jul 20 07:39:20.945258 2026] [security2:error] [pid 178071:tid 178292] [client 45.157.112.60:62405] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lCBltgi7HBmNwzJNJkgAAAFk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:39:20.990671 2026] [security2:error] [pid 178071:tid 178327] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lCBltgi7HBmNwzJNJeQAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:20.994034 2026] [security2:error] [pid 178071:tid 178086] [remote 192.241.143.148:51566] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lCBltgi7HBmNwzJNJlgAAQw0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:39:21.014083 2026] [security2:error] [pid 178071:tid 178263] [client 168.119.96.239:4948] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4lCBltgi7HBmNwzJNJNQAAADw"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:39:21.050473 2026] [security2:error] [pid 178071:tid 178205] [client 50.116.65.227:22156] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lCRltgi7HBmNwzJNJmwAAAAI"]
[Mon Jul 20 07:39:21.062207 2026] [security2:error] [pid 178071:tid 178313] [client 50.116.65.227:22158] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lCRltgi7HBmNwzJNJnAAAAG4"]
[Mon Jul 20 07:39:21.106709 2026] [security2:error] [pid 178071:tid 178141] [remote 173.212.252.15:40350] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lCRltgi7HBmNwzJNJoAAAKkQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:39:21.271542 2026] [security2:error] [pid 178071:tid 178276] [client 36.93.152.155:58850] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJqwAAAEk"]
[Mon Jul 20 07:39:21.271639 2026] [security2:error] [pid 178071:tid 178276] [client 36.93.152.155:58850] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJqwAAAEk"]
[Mon Jul 20 07:39:21.404620 2026] [security2:error] [pid 178071:tid 178208] [client 57.141.18.119:38868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lBhltgi7HBmNwzJNIOgAABRU"]
[Mon Jul 20 07:39:21.450519 2026] [security2:error] [pid 178071:tid 178303] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lCRltgi7HBmNwzJNJqgAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:21.696172 2026] [security2:error] [pid 178071:tid 178269] [client 14.225.17.146:58221] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4lCBltgi7HBmNwzJNJSwAAAEI"], referer: http://wathenbartlett.co.uk/bc
[Mon Jul 20 07:39:21.826135 2026] [security2:error] [pid 178071:tid 178231] [client 116.193.128.26:58231] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJ2AAAABw"]
[Mon Jul 20 07:39:21.826270 2026] [security2:error] [pid 178071:tid 178231] [client 116.193.128.26:58231] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJ2AAAABw"]
[Mon Jul 20 07:39:21.864325 2026] [security2:error] [pid 178071:tid 178255] [client 154.192.123.127:18782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJ3AAAADQ"]
[Mon Jul 20 07:39:21.864463 2026] [security2:error] [pid 178071:tid 178255] [client 154.192.123.127:18782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJ3AAAADQ"]
[Mon Jul 20 07:39:22.016153 2026] [security2:error] [pid 178071:tid 178305] [client 142.111.152.179:20601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lCRltgi7HBmNwzJNJ2gAAAGY"]
[Mon Jul 20 07:39:22.046859 2026] [security2:error] [pid 178071:tid 178330] [client 216.24.212.34:50439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4lChltgi7HBmNwzJNJ6wAAAH8"]
[Mon Jul 20 07:39:22.047000 2026] [security2:error] [pid 178071:tid 178274] [client 89.238.167.150:48976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4lChltgi7HBmNwzJNJ8AAAAEc"]
[Mon Jul 20 07:39:22.047066 2026] [security2:error] [pid 178071:tid 178274] [client 89.238.167.150:48976] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4lChltgi7HBmNwzJNJ8AAAAEc"]
[Mon Jul 20 07:39:22.047359 2026] [security2:error] [pid 178071:tid 178324] [client 216.24.212.28:28503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4lChltgi7HBmNwzJNJ6gAAAHk"]
[Mon Jul 20 07:39:22.103764 2026] [security2:error] [pid 178071:tid 178236] [client 14.225.17.146:49466] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4lCBltgi7HBmNwzJNJdQAAACE"], referer: http://chestermonty.com/bc
[Mon Jul 20 07:39:22.166745 2026] [security2:error] [pid 178071:tid 178235] [client 185.238.231.123:58199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4lChltgi7HBmNwzJNKAAAAACA"]
[Mon Jul 20 07:39:22.181459 2026] [security2:error] [pid 178071:tid 178207] [client 155.2.212.9:43523] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4lChltgi7HBmNwzJNKAQAAAAQ"]
[Mon Jul 20 07:39:22.210990 2026] [security2:error] [pid 178071:tid 178289] [client 49.37.242.14:50083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lChltgi7HBmNwzJNKBgAAAFY"]
[Mon Jul 20 07:39:22.211094 2026] [security2:error] [pid 178071:tid 178289] [client 49.37.242.14:50083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lChltgi7HBmNwzJNKBgAAAFY"]
[Mon Jul 20 07:39:22.233221 2026] [security2:error] [pid 178071:tid 178302] [client 149.0.16.108:54713] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lChltgi7HBmNwzJNKCQAAAGM"]
[Mon Jul 20 07:39:22.233372 2026] [security2:error] [pid 178071:tid 178302] [client 149.0.16.108:54713] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lChltgi7HBmNwzJNKCQAAAGM"]
[Mon Jul 20 07:39:22.686314 2026] [security2:error] [pid 178071:tid 178280] [client 14.225.17.146:59058] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4lChltgi7HBmNwzJNKKAAAAE0"], referer: https://wathenbartlett.co.uk/bc
[Mon Jul 20 07:39:23.130406 2026] [security2:error] [pid 178071:tid 178315] [client 14.225.17.146:49443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4lCxltgi7HBmNwzJNKRwAAAHA"], referer: https://chestermonty.com/bc
[Mon Jul 20 07:39:23.446993 2026] [security2:error] [pid 178071:tid 178297] [client 14.225.17.146:55110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4lChltgi7HBmNwzJNKEQAAAF4"], referer: http://getgarrison.com/bc
[Mon Jul 20 07:39:23.471236 2026] [security2:error] [pid 178071:tid 178238] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lCxltgi7HBmNwzJNKVQAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:23.803668 2026] [security2:error] [pid 178071:tid 178219] [client 14.225.17.146:54394] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4lChltgi7HBmNwzJNJ7QAAABA"], referer: http://windowtx.com/bc
[Mon Jul 20 07:39:23.992803 2026] [security2:error] [pid 178071:tid 178292] [client 85.25.172.249:58334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.116.64.27"] [uri "/index.cgi"] [unique_id "al4lCxltgi7HBmNwzJNKlgAAAFk"]
[Mon Jul 20 07:39:24.153253 2026] [security2:error] [pid 178071:tid 178281] [client 85.25.172.249:58334] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "50.116.64.27"] [uri "/404.html"] [unique_id "al4lDBltgi7HBmNwzJNKowAAAE4"], referer: http://50.116.64.27:80/cgi-bin/luci/;stok=/locale
[Mon Jul 20 07:39:24.388624 2026] [security2:error] [pid 178071:tid 178131] [remote 217.113.60.80:56014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4lDBltgi7HBmNwzJNKtgAAeTo"]
[Mon Jul 20 07:39:24.388792 2026] [security2:error] [pid 178071:tid 178324] [client 217.113.60.80:56014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "website-e4de5cd0.epu.kzx.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4lDBltgi7HBmNwzJNKtgAAeTo"]
[Mon Jul 20 07:39:24.486336 2026] [security2:error] [pid 178071:tid 178086] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/local.settings.json"] [unique_id "al4lDBltgi7HBmNwzJNKywAATQ0"]
[Mon Jul 20 07:39:24.486503 2026] [security2:error] [pid 178071:tid 178280] [client 34.39.87.128:34974] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "admin.areitoproducciones.com"] [uri "/local.settings.json"] [unique_id "al4lDBltgi7HBmNwzJNKywAATQ0"]
[Mon Jul 20 07:39:24.487944 2026] [security2:error] [pid 178071:tid 178088] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "admin.areitoproducciones.com"] [uri "/web.config"] [unique_id "al4lDBltgi7HBmNwzJNKzAAATQ8"]
[Mon Jul 20 07:39:24.556511 2026] [security2:error] [pid 178071:tid 178297] [client 74.208.214.194:51434] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lDBltgi7HBmNwzJNK1AAAAF4"]
[Mon Jul 20 07:39:24.569166 2026] [security2:error] [pid 178071:tid 178301] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDBltgi7HBmNwzJNKsQAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:24.594339 2026] [security2:error] [pid 178071:tid 178218] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDBltgi7HBmNwzJNKugAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:24.765032 2026] [security2:error] [pid 178071:tid 178150] [remote 98.156.100.191:39590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lDBltgi7HBmNwzJNK2gAAf0w"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:39:24.843160 2026] [security2:error] [pid 178071:tid 178212] [client 57.141.18.52:23486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lChltgi7HBmNwzJNKAgAACW8"]
[Mon Jul 20 07:39:24.890692 2026] [security2:error] [pid 178071:tid 178261] [client 154.192.233.184:61726] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lDBltgi7HBmNwzJNK6wAAADo"]
[Mon Jul 20 07:39:24.890840 2026] [security2:error] [pid 178071:tid 178261] [client 154.192.233.184:61726] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lDBltgi7HBmNwzJNK6wAAADo"]
[Mon Jul 20 07:39:24.957927 2026] [security2:error] [pid 178071:tid 178174] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.hermes/.env"] [unique_id "al4lDBltgi7HBmNwzJNK9gAAY2Q"]
[Mon Jul 20 07:39:24.960697 2026] [security2:error] [pid 178071:tid 178170] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "manage.jeffjaeger.com"] [uri "/rclone.conf"] [unique_id "al4lDBltgi7HBmNwzJNK9wAADmA"]
[Mon Jul 20 07:39:24.977631 2026] [security2:error] [pid 178071:tid 178161] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/z9x8c7v6b5-debug-trigger-manage.jeffjaeger.com"] [unique_id "al4lDBltgi7HBmNwzJNK-gAAI1c"]
[Mon Jul 20 07:39:25.066960 2026] [security2:error] [pid 178071:tid 178240] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDBltgi7HBmNwzJNK5QAAACU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:25.097303 2026] [security2:error] [pid 178071:tid 178221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDBltgi7HBmNwzJNK6AAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:25.150997 2026] [security2:error] [pid 178071:tid 178187] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.codex/config.toml"] [unique_id "al4lDRltgi7HBmNwzJNLDgAAfXE"]
[Mon Jul 20 07:39:25.280841 2026] [security2:error] [pid 178071:tid 178253] [client 103.176.215.66:52780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lDRltgi7HBmNwzJNLGgAAADI"]
[Mon Jul 20 07:39:25.281482 2026] [security2:error] [pid 178071:tid 178253] [client 103.176.215.66:52780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lDRltgi7HBmNwzJNLGgAAADI"]
[Mon Jul 20 07:39:25.435715 2026] [security2:error] [pid 178071:tid 178183] [remote 34.39.87.128:34974] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "admin.areitoproducciones.com"] [uri "/.aws/credentials"] [unique_id "al4lDRltgi7HBmNwzJNLPAAAeW0"]
[Mon Jul 20 07:39:25.496239 2026] [security2:error] [pid 178071:tid 178109] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "manage.jeffjaeger.com"] [uri "/graphql"] [unique_id "al4lDRltgi7HBmNwzJNLQgAAbCQ"]
[Mon Jul 20 07:39:25.575407 2026] [security2:error] [pid 178071:tid 178212] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDRltgi7HBmNwzJNLMgAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:25.596586 2026] [security2:error] [pid 178071:tid 178197] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.profile"] [unique_id "al4lDRltgi7HBmNwzJNLRgAAbHs"]
[Mon Jul 20 07:39:25.602211 2026] [security2:error] [pid 178071:tid 178211] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDRltgi7HBmNwzJNLMQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:25.614145 2026] [security2:error] [pid 178071:tid 178277] [client 57.141.18.114:36324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lChltgi7HBmNwzJNKRAAASmg"]
[Mon Jul 20 07:39:25.888720 2026] [security2:error] [pid 178071:tid 178133] [remote 97.74.87.194:38126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4lDRltgi7HBmNwzJNLXQAAIjw"]
[Mon Jul 20 07:39:26.099944 2026] [security2:error] [pid 178071:tid 178169] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "manage.jeffjaeger.com"] [uri "/api/graphql"] [unique_id "al4lDhltgi7HBmNwzJNLcQAAbF8"]
[Mon Jul 20 07:39:26.174409 2026] [security2:error] [pid 178071:tid 178097] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "manage.jeffjaeger.com"] [uri "/wp-config.php.bak"] [unique_id "al4lDhltgi7HBmNwzJNLegAAbBg"]
[Mon Jul 20 07:39:26.174913 2026] [security2:error] [pid 178071:tid 178118] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "manage.jeffjaeger.com"] [uri "/wp-config.php.old"] [unique_id "al4lDhltgi7HBmNwzJNLfAAAbC0"]
[Mon Jul 20 07:39:26.272167 2026] [security2:error] [pid 178071:tid 178291] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDhltgi7HBmNwzJNLbAAAAFg"]
[Mon Jul 20 07:39:26.345304 2026] [security2:error] [pid 178071:tid 178307] [client 179.127.84.238:65014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lDhltgi7HBmNwzJNLkAAAAGg"]
[Mon Jul 20 07:39:26.345408 2026] [security2:error] [pid 178071:tid 178307] [client 179.127.84.238:65014] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lDhltgi7HBmNwzJNLkAAAAGg"]
[Mon Jul 20 07:39:26.401824 2026] [security2:error] [pid 178071:tid 178136] [remote 97.74.87.194:38126] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.cathybuffini.com"] [uri "/wp-login.php"] [unique_id "al4lDhltgi7HBmNwzJNLmQAAUj8"], referer: https://mail.cathybuffini.com/wp-login.php
[Mon Jul 20 07:39:26.517667 2026] [security2:error] [pid 178071:tid 178215] [client 50.116.65.227:22282] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "tntcatholic.com"] [uri "/wp-content/uploads/2021/09/maxresdefault-1.jpg"] [unique_id "al4lDhltgi7HBmNwzJNLnwAAAHY"]
[Mon Jul 20 07:39:26.578308 2026] [security2:error] [pid 178071:tid 178110] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "manage.jeffjaeger.com"] [uri "/v1/graphql"] [unique_id "al4lDhltgi7HBmNwzJNLpgAAYCU"]
[Mon Jul 20 07:39:26.614602 2026] [security2:error] [pid 178071:tid 178086] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/laravel/.env"] [unique_id "al4lDhltgi7HBmNwzJNLsAAATg0"]
[Mon Jul 20 07:39:26.677146 2026] [security2:error] [pid 178071:tid 178303] [client 14.225.17.146:49629] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4lDhltgi7HBmNwzJNLbQAAAGQ"], referer: http://idigress.agency/bc
[Mon Jul 20 07:39:26.678060 2026] [security2:error] [pid 178071:tid 178194] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/core/.env"] [unique_id "al4lDhltgi7HBmNwzJNLvgAAYXg"]
[Mon Jul 20 07:39:26.689651 2026] [security2:error] [pid 178071:tid 178141] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/config/.env.php"] [unique_id "al4lDhltgi7HBmNwzJNLvAAAYUQ"]
[Mon Jul 20 07:39:26.716606 2026] [security2:error] [pid 178071:tid 178167] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/.env.php.bak"] [unique_id "al4lDhltgi7HBmNwzJNLvwAAYV0"]
[Mon Jul 20 07:39:26.898659 2026] [security2:error] [pid 178071:tid 178242] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lDhltgi7HBmNwzJNLwgAAACc"]
[Mon Jul 20 07:39:26.903767 2026] [security2:error] [pid 178071:tid 178170] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/public/.env"] [unique_id "al4lDhltgi7HBmNwzJNL1AAADmA"]
[Mon Jul 20 07:39:27.009072 2026] [security2:error] [pid 178071:tid 178140] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/configuration.php.bak"] [unique_id "al4lDxltgi7HBmNwzJNL4gAACkM"]
[Mon Jul 20 07:39:27.009349 2026] [security2:error] [pid 178071:tid 178132] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/config.php.bak"] [unique_id "al4lDxltgi7HBmNwzJNL5gAACjs"]
[Mon Jul 20 07:39:27.009933 2026] [security2:error] [pid 178071:tid 178138] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/web/.env"] [unique_id "al4lDxltgi7HBmNwzJNL4wAACkE"]
[Mon Jul 20 07:39:27.010482 2026] [security2:error] [pid 178071:tid 178139] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sw[a-z]$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1275"] [id "390587"] [rev "5"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .sw)"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.env.swp"] [unique_id "al4lDxltgi7HBmNwzJNL5AAACkI"]
[Mon Jul 20 07:39:27.037773 2026] [security2:error] [pid 178071:tid 178205] [client 65.111.23.71:37661] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lDhltgi7HBmNwzJNL4QAAAAI"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:27.132858 2026] [security2:error] [pid 178071:tid 178311] [client 191.202.66.27:60351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lDxltgi7HBmNwzJNL7wAAAGw"]
[Mon Jul 20 07:39:27.132961 2026] [security2:error] [pid 178071:tid 178311] [client 191.202.66.27:60351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lDxltgi7HBmNwzJNL7wAAAGw"]
[Mon Jul 20 07:39:27.178468 2026] [security2:error] [pid 178071:tid 178113] [remote 57.141.18.81:27740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3583925"] [unique_id "al4lDxltgi7HBmNwzJNL8wAAXyg"]
[Mon Jul 20 07:39:27.213801 2026] [security2:error] [pid 178071:tid 178179] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/bootstrap.properties"] [unique_id "al4lDxltgi7HBmNwzJNL-AAASmk"]
[Mon Jul 20 07:39:27.213940 2026] [security2:error] [pid 178071:tid 178277] [client 34.32.109.138:51232] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manage.jeffjaeger.com"] [uri "/bootstrap.properties"] [unique_id "al4lDxltgi7HBmNwzJNL-AAASmk"]
[Mon Jul 20 07:39:27.577896 2026] [security2:error] [pid 178071:tid 178273] [client 136.158.60.21:16499] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lDxltgi7HBmNwzJNMIgAAAEY"]
[Mon Jul 20 07:39:27.578031 2026] [security2:error] [pid 178071:tid 178273] [client 136.158.60.21:16499] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lDxltgi7HBmNwzJNMIgAAAEY"]
[Mon Jul 20 07:39:27.619708 2026] [security2:error] [pid 178071:tid 178200] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/appsettings.Production.json"] [unique_id "al4lDxltgi7HBmNwzJNMKgAASH4"]
[Mon Jul 20 07:39:27.621424 2026] [security2:error] [pid 178071:tid 178101] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "manage.jeffjaeger.com"] [uri "/.gradle/gradle.properties"] [unique_id "al4lDxltgi7HBmNwzJNMLQAASBw"]
[Mon Jul 20 07:39:27.657687 2026] [security2:error] [pid 178071:tid 178248] [client 57.141.18.43:37578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lDRltgi7HBmNwzJNLNAAALQc"]
[Mon Jul 20 07:39:27.659079 2026] [security2:error] [pid 178071:tid 178315] [client 57.141.18.9:20450] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lDRltgi7HBmNwzJNLMwAAcHk"]
[Mon Jul 20 07:39:28.011625 2026] [security2:error] [pid 178071:tid 178280] [client 57.141.18.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4lDxltgi7HBmNwzJNMSgAAAE0"]
[Mon Jul 20 07:39:28.060462 2026] [security2:error] [pid 178071:tid 178152] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/web.config"] [unique_id "al4lEBltgi7HBmNwzJNMhwAARk4"]
[Mon Jul 20 07:39:28.060837 2026] [security2:error] [pid 178071:tid 178185] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/config/database.yml"] [unique_id "al4lEBltgi7HBmNwzJNMigAARm8"]
[Mon Jul 20 07:39:28.064934 2026] [security2:error] [pid 178071:tid 178279] [client 14.225.17.146:64439] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4lDxltgi7HBmNwzJNMSQAAAEw"], referer: http://thesoloceos.com/bc
[Mon Jul 20 07:39:28.454433 2026] [security2:error] [pid 178071:tid 178207] [client 45.3.54.24:29715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lEBltgi7HBmNwzJNMrAAAAAQ"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:28.463016 2026] [security2:error] [pid 178071:tid 178263] [client 143.44.185.218:22895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lEBltgi7HBmNwzJNMsQAAADw"]
[Mon Jul 20 07:39:28.465565 2026] [security2:error] [pid 178071:tid 178263] [client 143.44.185.218:22895] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lEBltgi7HBmNwzJNMsQAAADw"]
[Mon Jul 20 07:39:28.619939 2026] [security2:error] [pid 178071:tid 178163] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.env.test"] [unique_id "al4lEBltgi7HBmNwzJNMvAAARFk"]
[Mon Jul 20 07:39:28.627800 2026] [security2:error] [pid 178071:tid 178294] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNMrQAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:28.714952 2026] [security2:error] [pid 178071:tid 178297] [client 14.225.17.146:64514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4lDxltgi7HBmNwzJNMFwAAAF4"], referer: http://lutheranphilosopher.com/bc
[Mon Jul 20 07:39:28.747164 2026] [security2:error] [pid 178071:tid 178178] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.env.development"] [unique_id "al4lEBltgi7HBmNwzJNMyAAAOWg"]
[Mon Jul 20 07:39:28.747165 2026] [security2:error] [pid 178071:tid 178084] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/config.env"] [unique_id "al4lEBltgi7HBmNwzJNMxwAAOQs"]
[Mon Jul 20 07:39:29.051111 2026] [security2:error] [pid 178071:tid 178240] [client 14.225.17.146:55247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNM2AAAACU"], referer: http://longevityperformanceclinic.com/bc
[Mon Jul 20 07:39:29.079171 2026] [security2:error] [pid 178071:tid 178276] [client 14.225.17.146:64557] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNM4QAAAEk"], referer: https://thesoloceos.com/bc
[Mon Jul 20 07:39:29.096643 2026] [security2:error] [pid 178071:tid 178246] [client 57.141.18.87:47456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lDhltgi7HBmNwzJNL3wAAK1c"]
[Mon Jul 20 07:39:29.192252 2026] [security2:error] [pid 178071:tid 178204] [client 49.47.218.174:49992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lERltgi7HBmNwzJNNCAAAAAE"]
[Mon Jul 20 07:39:29.192359 2026] [security2:error] [pid 178071:tid 178204] [client 49.47.218.174:49992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lERltgi7HBmNwzJNNCAAAAAE"]
[Mon Jul 20 07:39:29.206463 2026] [security2:error] [pid 178071:tid 178103] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/staging/.env"] [unique_id "al4lERltgi7HBmNwzJNNDQAAFB4"]
[Mon Jul 20 07:39:29.206985 2026] [security2:error] [pid 178071:tid 178102] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/src/.env"] [unique_id "al4lERltgi7HBmNwzJNNCwAAFB0"]
[Mon Jul 20 07:39:29.207127 2026] [security2:error] [pid 178071:tid 178131] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/docker/.env"] [unique_id "al4lERltgi7HBmNwzJNNDAAAFDo"]
[Mon Jul 20 07:39:29.207273 2026] [security2:error] [pid 178071:tid 178143] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/dev/.env"] [unique_id "al4lERltgi7HBmNwzJNNDgAAFEY"]
[Mon Jul 20 07:39:29.207745 2026] [security2:error] [pid 178071:tid 178102] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/frontend/.env"] [unique_id "al4lERltgi7HBmNwzJNNDwAAFB0"]
[Mon Jul 20 07:39:29.208307 2026] [security2:error] [pid 178071:tid 178112] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/production/.env"] [unique_id "al4lERltgi7HBmNwzJNNEAAAFCc"]
[Mon Jul 20 07:39:29.215360 2026] [security2:error] [pid 178071:tid 178328] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNM5AAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:29.321702 2026] [security2:error] [pid 178071:tid 178108] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/server/.env"] [unique_id "al4lERltgi7HBmNwzJNNHwAAZCM"]
[Mon Jul 20 07:39:29.321871 2026] [security2:error] [pid 178071:tid 178303] [client 34.32.109.138:51232] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manage.jeffjaeger.com"] [uri "/server/.env"] [unique_id "al4lERltgi7HBmNwzJNNHwAAZCM"]
[Mon Jul 20 07:39:29.322649 2026] [security2:error] [pid 178071:tid 178096] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/app/.env"] [unique_id "al4lERltgi7HBmNwzJNNHgAAZBc"]
[Mon Jul 20 07:39:29.386485 2026] [security2:error] [pid 178071:tid 178219] [client 13.233.207.33:23352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lERltgi7HBmNwzJNNJgAAABA"]
[Mon Jul 20 07:39:29.386595 2026] [security2:error] [pid 178071:tid 178219] [client 13.233.207.33:23352] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lERltgi7HBmNwzJNNJgAAABA"]
[Mon Jul 20 07:39:29.616999 2026] [security2:error] [pid 178071:tid 178291] [client 14.225.17.146:64570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNMkwAAAFg"], referer: http://bbwipartnerconference.com/bc
[Mon Jul 20 07:39:29.650794 2026] [security2:error] [pid 178071:tid 178252] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lERltgi7HBmNwzJNNNwAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:29.776830 2026] [security2:error] [pid 178071:tid 178177] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/@fs/proc/self/environ"] [unique_id "al4lERltgi7HBmNwzJNNVgAAUWc"]
[Mon Jul 20 07:39:29.776831 2026] [security2:error] [pid 178071:tid 178082] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/@fs/.env"] [unique_id "al4lERltgi7HBmNwzJNNVQAAUQk"]
[Mon Jul 20 07:39:29.777129 2026] [security2:error] [pid 178071:tid 178284] [client 34.32.109.138:51232] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manage.jeffjaeger.com"] [uri "/@fs/proc/self/environ"] [unique_id "al4lERltgi7HBmNwzJNNVgAAUWc"]
[Mon Jul 20 07:39:29.786573 2026] [security2:error] [pid 178071:tid 178110] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/@fs/root/.env"] [unique_id "al4lERltgi7HBmNwzJNNWAAAYyU"]
[Mon Jul 20 07:39:29.791206 2026] [security2:error] [pid 178071:tid 178267] [client 14.225.17.146:50327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNMjwAAAEA"], referer: http://maplerespiteservices.com/bc
[Mon Jul 20 07:39:29.805987 2026] [security2:error] [pid 178071:tid 178185] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.env.prod.bak"] [unique_id "al4lERltgi7HBmNwzJNNXAAAZm8"]
[Mon Jul 20 07:39:29.805988 2026] [security2:error] [pid 178071:tid 178121] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.env.production.bak"] [unique_id "al4lERltgi7HBmNwzJNNXgAAZjA"]
[Mon Jul 20 07:39:29.895033 2026] [security2:error] [pid 178071:tid 178246] [client 65.111.22.212:57025] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lERltgi7HBmNwzJNNaQAAACs"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:30.024844 2026] [security2:error] [pid 178071:tid 178260] [client 51.195.39.149:33296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4lERltgi7HBmNwzJNNbwAAOUo"]
[Mon Jul 20 07:39:30.202170 2026] [security2:error] [pid 178071:tid 178140] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/public/admin.json"] [unique_id "al4lEhltgi7HBmNwzJNNmwAAAUM"]
[Mon Jul 20 07:39:30.300606 2026] [security2:error] [pid 178071:tid 178270] [client 14.225.17.146:50253] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4lERltgi7HBmNwzJNM8QAAAEM"], referer: http://iagdevelopments.com/bc
[Mon Jul 20 07:39:30.436755 2026] [security2:error] [pid 178071:tid 178318] [client 180.249.173.210:60986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lEhltgi7HBmNwzJNNrgAAAHM"]
[Mon Jul 20 07:39:30.437004 2026] [security2:error] [pid 178071:tid 178318] [client 180.249.173.210:60986] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lEhltgi7HBmNwzJNNrgAAAHM"]
[Mon Jul 20 07:39:30.613251 2026] [security2:error] [pid 178071:tid 178274] [client 57.141.18.44:60106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lEBltgi7HBmNwzJNMoQAAR0E"]
[Mon Jul 20 07:39:30.776894 2026] [security2:error] [pid 178071:tid 178217] [client 103.139.191.61:63355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lEhltgi7HBmNwzJNNzAAAAA4"]
[Mon Jul 20 07:39:30.777057 2026] [security2:error] [pid 178071:tid 178217] [client 103.139.191.61:63355] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lEhltgi7HBmNwzJNNzAAAAA4"]
[Mon Jul 20 07:39:30.835293 2026] [security2:error] [pid 178071:tid 178081] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/config.js"] [unique_id "al4lEhltgi7HBmNwzJNN1AAAcwg"]
[Mon Jul 20 07:39:30.920695 2026] [security2:error] [pid 178071:tid 178326] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lEhltgi7HBmNwzJNNxAAAAHs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:31.020836 2026] [security2:error] [pid 178071:tid 178211] [client 14.225.17.146:56310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4lEhltgi7HBmNwzJNNxQAAAAg"], referer: http://healthylifegourmet.org/bc
[Mon Jul 20 07:39:31.212926 2026] [security2:error] [pid 178071:tid 178244] [client 66.249.65.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.liquidationteam.com"] [uri "/index.php"] [unique_id "al4lEhltgi7HBmNwzJNN6AAAACk"]
[Mon Jul 20 07:39:31.259087 2026] [security2:error] [pid 178071:tid 178328] [client 14.225.17.146:64205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4lExltgi7HBmNwzJNOEQAAAH0"], referer: https://iagdevelopments.com/bc
[Mon Jul 20 07:39:31.304215 2026] [security2:error] [pid 178071:tid 178261] [client 14.225.17.146:55327] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4lExltgi7HBmNwzJNOBAAAADo"], referer: http://tntcatholic.com/bc
[Mon Jul 20 07:39:31.378942 2026] [security2:error] [pid 178071:tid 178274] [client 104.207.51.203:34803] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lExltgi7HBmNwzJNOKwAAAEc"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:31.476798 2026] [security2:error] [pid 178071:tid 178162] [remote 173.212.252.15:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lExltgi7HBmNwzJNORQAAHlg"]
[Mon Jul 20 07:39:31.497059 2026] [security2:error] [pid 178071:tid 178205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lExltgi7HBmNwzJNOGAAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:31.519006 2026] [security2:error] [pid 178071:tid 178121] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/api/v1/config"] [unique_id "al4lExltgi7HBmNwzJNOSgAABzA"]
[Mon Jul 20 07:39:31.667586 2026] [security2:error] [pid 178071:tid 178283] [client 36.93.152.155:59357] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lExltgi7HBmNwzJNOXgAAAFA"]
[Mon Jul 20 07:39:31.667704 2026] [security2:error] [pid 178071:tid 178283] [client 36.93.152.155:59357] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lExltgi7HBmNwzJNOXgAAAFA"]
[Mon Jul 20 07:39:31.681849 2026] [security2:error] [pid 178071:tid 178132] [remote 173.212.252.15:51448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lExltgi7HBmNwzJNOXwAAZDs"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:39:31.755001 2026] [security2:error] [pid 178071:tid 178165] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/openapi.json"] [unique_id "al4lExltgi7HBmNwzJNOZAAAUVs"]
[Mon Jul 20 07:39:31.762233 2026] [security2:error] [pid 178071:tid 178154] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/api/openapi.json"] [unique_id "al4lExltgi7HBmNwzJNOZQAAOlA"]
[Mon Jul 20 07:39:31.906823 2026] [security2:error] [pid 178071:tid 178292] [client 66.249.74.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4lExltgi7HBmNwzJNOVAAAAFk"]
[Mon Jul 20 07:39:32.070211 2026] [security2:error] [pid 178071:tid 178264] [client 57.141.18.118:38836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lERltgi7HBmNwzJNNRQAAPXg"]
[Mon Jul 20 07:39:32.085380 2026] [security2:error] [pid 178071:tid 178216] [client 146.103.116.11:43168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.116.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-content/plugins/si-captcha-for-wordpress/captcha/securimage_show.php"] [unique_id "al4lFBltgi7HBmNwzJNOiAAAAA0"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:39:32.095988 2026] [security2:error] [pid 178071:tid 178277] [client 87.199.205.156:49890] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.205.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-content/plugins/si-captcha-for-wordpress/captcha/securimage_show.php"] [unique_id "al4lFBltgi7HBmNwzJNOigAAAEo"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:39:32.099630 2026] [security2:error] [pid 178071:tid 178183] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/api/v1/env"] [unique_id "al4lFBltgi7HBmNwzJNOkgAAWm0"]
[Mon Jul 20 07:39:32.139859 2026] [security2:error] [pid 178071:tid 178272] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lExltgi7HBmNwzJNOdQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:32.318005 2026] [security2:error] [pid 178071:tid 178127] [remote 47.86.33.52:21632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4lFBltgi7HBmNwzJNOpwAALTY"]
[Mon Jul 20 07:39:32.358409 2026] [security2:error] [pid 178071:tid 178268] [client 154.192.123.127:17191] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.123.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOrgAAAEE"]
[Mon Jul 20 07:39:32.358560 2026] [security2:error] [pid 178071:tid 178268] [client 154.192.123.127:17191] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOrgAAAEE"]
[Mon Jul 20 07:39:32.386090 2026] [security2:error] [pid 178071:tid 178239] [client 146.103.116.11:43212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.116.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4lFBltgi7HBmNwzJNOsgAAACQ"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:39:32.386199 2026] [security2:error] [pid 178071:tid 178239] [client 146.103.116.11:43212] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4lFBltgi7HBmNwzJNOsgAAACQ"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:39:32.411526 2026] [security2:error] [pid 178071:tid 178079] [remote 64.225.121.94:48738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4lFBltgi7HBmNwzJNOtAAAZQY"]
[Mon Jul 20 07:39:32.443593 2026] [security2:error] [pid 178071:tid 178250] [client 116.193.128.26:58811] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOuAAAAC8"]
[Mon Jul 20 07:39:32.443997 2026] [security2:error] [pid 178071:tid 178250] [client 116.193.128.26:58811] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOuAAAAC8"]
[Mon Jul 20 07:39:32.456557 2026] [security2:error] [pid 178071:tid 178297] [client 116.74.65.235:57921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOugAAAF4"]
[Mon Jul 20 07:39:32.456689 2026] [security2:error] [pid 178071:tid 178297] [client 116.74.65.235:57921] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOugAAAF4"]
[Mon Jul 20 07:39:32.460225 2026] [security2:error] [pid 178071:tid 178317] [client 87.199.205.156:49930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 156.205.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4lFBltgi7HBmNwzJNOtQAAAHI"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:39:32.460347 2026] [security2:error] [pid 178071:tid 178317] [client 87.199.205.156:49930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4lFBltgi7HBmNwzJNOtQAAAHI"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:39:32.509088 2026] [security2:error] [pid 178071:tid 178218] [client 142.111.152.174:29711] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNOrQAAAA8"]
[Mon Jul 20 07:39:32.633731 2026] [security2:error] [pid 178071:tid 178197] [remote 64.225.121.94:48738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.121.225.64.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "friendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4lFBltgi7HBmNwzJNOzgAAZHs"], referer: https://friendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:39:32.640933 2026] [security2:error] [pid 178071:tid 178267] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFBltgi7HBmNwzJNOswAAAEA"]
[Mon Jul 20 07:39:32.670961 2026] [security2:error] [pid 178071:tid 178289] [client 37.52.210.45:56874] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNO0AAAAFY"]
[Mon Jul 20 07:39:32.671153 2026] [security2:error] [pid 178071:tid 178289] [client 37.52.210.45:56874] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNO0AAAAFY"]
[Mon Jul 20 07:39:32.695594 2026] [security2:error] [pid 178071:tid 178240] [client 14.225.17.146:64685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4lFBltgi7HBmNwzJNOzwAAACU"], referer: http://intelligentengineeringsolutions.com/bc
[Mon Jul 20 07:39:32.835038 2026] [security2:error] [pid 178071:tid 178243] [client 104.207.51.247:31241] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 247.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lFBltgi7HBmNwzJNO2AAAACg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:32.836415 2026] [security2:error] [pid 178071:tid 178273] [client 149.0.16.108:55237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNO3gAAAEY"]
[Mon Jul 20 07:39:32.836569 2026] [security2:error] [pid 178071:tid 178273] [client 149.0.16.108:55237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lFBltgi7HBmNwzJNO3gAAAEY"]
[Mon Jul 20 07:39:32.841642 2026] [security2:error] [pid 178071:tid 178295] [client 57.141.18.115:21376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lEhltgi7HBmNwzJNNtQAAXBw"]
[Mon Jul 20 07:39:33.065808 2026] [security2:error] [pid 178071:tid 178254] [client 50.116.65.227:34230] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lFRltgi7HBmNwzJNO-QAAADM"]
[Mon Jul 20 07:39:33.075931 2026] [security2:error] [pid 178071:tid 178278] [client 50.116.65.227:34244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lFRltgi7HBmNwzJNO_QAAAEs"]
[Mon Jul 20 07:39:33.092504 2026] [security2:error] [pid 178071:tid 178109] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/phpinfo.php"] [unique_id "al4lFRltgi7HBmNwzJNPAQAAPCQ"]
[Mon Jul 20 07:39:33.102137 2026] [security2:error] [pid 178071:tid 178107] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/info.php"] [unique_id "al4lFRltgi7HBmNwzJNPAwAAPCI"]
[Mon Jul 20 07:39:33.122446 2026] [security2:error] [pid 178071:tid 178136] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "manage.jeffjaeger.com"] [uri "/actuator"] [unique_id "al4lFRltgi7HBmNwzJNPBwAAOj8"]
[Mon Jul 20 07:39:33.190627 2026] [security2:error] [pid 178071:tid 178204] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFBltgi7HBmNwzJNO5QAAAAE"]
[Mon Jul 20 07:39:33.198159 2026] [security2:error] [pid 178071:tid 178180] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/pi.php"] [unique_id "al4lFRltgi7HBmNwzJNPCwAARmo"]
[Mon Jul 20 07:39:33.222010 2026] [security2:error] [pid 178071:tid 178226] [client 14.225.17.146:64749] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4lFRltgi7HBmNwzJNO9gAAABc"], referer: http://xp-design.co/bc
[Mon Jul 20 07:39:33.245918 2026] [security2:error] [pid 178071:tid 178137] [remote 162.19.86.63:33796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4lFRltgi7HBmNwzJNPDgAAKUA"]
[Mon Jul 20 07:39:33.362838 2026] [security2:error] [pid 178071:tid 178106] [remote 41.186.86.12:29560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lFRltgi7HBmNwzJNPGAAAeCE"]
[Mon Jul 20 07:39:33.447840 2026] [security2:error] [pid 178071:tid 178206] [client 20.151.10.161:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.10.151.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "flowmeterfactory.com"] [uri "/.well-known/about.php"] [unique_id "al4lFRltgi7HBmNwzJNPHQAAAAM"]
[Mon Jul 20 07:39:33.447949 2026] [security2:error] [pid 178071:tid 178206] [client 20.151.10.161:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "flowmeterfactory.com"] [uri "/.well-known/about.php"] [unique_id "al4lFRltgi7HBmNwzJNPHQAAAAM"]
[Mon Jul 20 07:39:33.458809 2026] [security2:error] [pid 178071:tid 178120] [remote 162.19.86.63:33796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kromosenergy.com"] [uri "/wp-login.php"] [unique_id "al4lFRltgi7HBmNwzJNPJwAAVS8"], referer: https://kromosenergy.com/wp-login.php
[Mon Jul 20 07:39:33.468961 2026] [security2:error] [pid 178071:tid 178158] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/app_dev.php"] [unique_id "al4lFRltgi7HBmNwzJNPKgAAfVQ"]
[Mon Jul 20 07:39:33.532474 2026] [security2:error] [pid 178071:tid 178162] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/test.php"] [unique_id "al4lFRltgi7HBmNwzJNPNwAAG1g"]
[Mon Jul 20 07:39:33.532557 2026] [security2:error] [pid 178071:tid 178155] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/i.php"] [unique_id "al4lFRltgi7HBmNwzJNPNgAAG1E"]
[Mon Jul 20 07:39:33.554954 2026] [security2:error] [pid 178071:tid 178227] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFRltgi7HBmNwzJNPFgAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:33.731274 2026] [security2:error] [pid 178071:tid 178095] [remote 57.141.18.33:50926] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-config\\\\.php(?:\\\\W[a-z]*|bak)" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "300"] [id "900256"] [msg "Wp-Config Backup/edit file request"] [hostname "aviationsynergy.aero"] [uri "/product/4896844"] [unique_id "al4lFRltgi7HBmNwzJNPUwAAaBY"]
[Mon Jul 20 07:39:33.830598 2026] [security2:error] [pid 178071:tid 178232] [client 74.208.214.194:51446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lFRltgi7HBmNwzJNPYwAAAB0"]
[Mon Jul 20 07:39:33.853156 2026] [security2:error] [pid 178071:tid 178150] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.109.32.34.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "manage.jeffjaeger.com"] [uri "/app_dev.php/_profiler"] [unique_id "al4lFRltgi7HBmNwzJNPbQAACEw"]
[Mon Jul 20 07:39:33.853879 2026] [security2:error] [pid 178071:tid 178157] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Match of "ipMatch 127.0.0.1,::1" against "REMOTE_ADDR" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "724"] [id "340114"] [rev "2"] [msg "Atomicorp.com WAF Rules: Apache admin service access attempt"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/server-info"] [unique_id "al4lFRltgi7HBmNwzJNPZwAACFM"]
[Mon Jul 20 07:39:33.854248 2026] [security2:error] [pid 178071:tid 178190] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "manage.jeffjaeger.com"] [uri "/trace.axd"] [unique_id "al4lFRltgi7HBmNwzJNPbgAACHQ"]
[Mon Jul 20 07:39:33.875222 2026] [security2:error] [pid 178071:tid 178139] [remote 41.186.86.12:29560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lFRltgi7HBmNwzJNPcgAAEUI"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:39:33.915039 2026] [security2:error] [pid 178071:tid 178148] [remote 47.86.33.52:21632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mollycahill.com"] [uri "/wp-login.php"] [unique_id "al4lFRltgi7HBmNwzJNPdAAAOUo"], referer: https://mollycahill.com/wp-login.php
[Mon Jul 20 07:39:34.009200 2026] [security2:error] [pid 178071:tid 178215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFRltgi7HBmNwzJNPWwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:34.275626 2026] [security2:error] [pid 178071:tid 178313] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFhltgi7HBmNwzJNPggAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:34.289893 2026] [security2:error] [pid 178071:tid 178236] [client 65.111.22.193:57345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lFhltgi7HBmNwzJNPqwAAACE"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:34.335315 2026] [security2:error] [pid 178071:tid 178080] [remote 120.72.98.5:28448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lFhltgi7HBmNwzJNPsAAAXQc"]
[Mon Jul 20 07:39:34.361580 2026] [security2:error] [pid 178071:tid 178243] [client 158.173.89.95:32605] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lFhltgi7HBmNwzJNPtwAAACg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:39:34.522067 2026] [security2:error] [pid 178071:tid 178172] [remote 163.47.203.78:42602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.203.47.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4lFhltgi7HBmNwzJNPwwAAHWI"]
[Mon Jul 20 07:39:34.547556 2026] [security2:error] [pid 178071:tid 178147] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.env.example"] [unique_id "al4lFhltgi7HBmNwzJNP2AAAO0k"]
[Mon Jul 20 07:39:34.548830 2026] [security2:error] [pid 178071:tid 178166] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.env"] [unique_id "al4lFhltgi7HBmNwzJNP1wAAO1w"]
[Mon Jul 20 07:39:34.602959 2026] [security2:error] [pid 178071:tid 178327] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFhltgi7HBmNwzJNPsgAAAHw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:34.650287 2026] [security2:error] [pid 178071:tid 178309] [client 57.141.18.76:22064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lFBltgi7HBmNwzJNOrAAAank"]
[Mon Jul 20 07:39:34.768360 2026] [security2:error] [pid 178071:tid 178283] [client 202.141.11.99:22095] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4lFhltgi7HBmNwzJNP6AAAAFA"]
[Mon Jul 20 07:39:34.768481 2026] [security2:error] [pid 178071:tid 178283] [client 202.141.11.99:22095] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4lFhltgi7HBmNwzJNP6AAAAFA"]
[Mon Jul 20 07:39:34.899510 2026] [security2:error] [pid 178071:tid 178153] [remote 163.47.203.78:42602] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 78.203.47.163.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4lFhltgi7HBmNwzJNP9gAAd08"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:39:35.070568 2026] [security2:error] [pid 178071:tid 178192] [remote 120.72.98.5:28448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.98.72.120.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lFxltgi7HBmNwzJNQAwAAf3Y"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:39:35.108901 2026] [security2:error] [pid 178071:tid 178225] [client 114.119.156.30:61281] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "youpositive.co"] [uri "/ar/a-man-running-inside-a-circle"] [unique_id "al4lFxltgi7HBmNwzJNQEgAAABY"], referer: https://youpositive.co/ar/a-man-running-inside-a-circle
[Mon Jul 20 07:39:35.209351 2026] [security2:error] [pid 178071:tid 178320] [client 14.225.17.146:64315] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4lFRltgi7HBmNwzJNPUgAAAHU"], referer: http://dadanetnet.net/bc
[Mon Jul 20 07:39:35.269900 2026] [security2:error] [pid 178071:tid 178201] [remote 198.46.152.106:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4lFxltgi7HBmNwzJNQJQAAMX8"]
[Mon Jul 20 07:39:35.347825 2026] [security2:error] [pid 178071:tid 178114] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.env.old"] [unique_id "al4lFxltgi7HBmNwzJNQNQAADSk"]
[Mon Jul 20 07:39:35.348793 2026] [security2:error] [pid 178071:tid 178156] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/api/.env"] [unique_id "al4lFxltgi7HBmNwzJNQMQAADVI"]
[Mon Jul 20 07:39:35.348939 2026] [security2:error] [pid 178071:tid 178130] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/backend/.env"] [unique_id "al4lFxltgi7HBmNwzJNQNgAADTk"]
[Mon Jul 20 07:39:35.349134 2026] [security2:error] [pid 178071:tid 178188] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.env.bak"] [unique_id "al4lFxltgi7HBmNwzJNQMgAADXI"]
[Mon Jul 20 07:39:35.349138 2026] [security2:error] [pid 178071:tid 178126] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.env.backup"] [unique_id "al4lFxltgi7HBmNwzJNQNAAADTU"]
[Mon Jul 20 07:39:35.374479 2026] [security2:error] [pid 178071:tid 178307] [client 154.192.233.184:62088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lFxltgi7HBmNwzJNQSAAAAGg"]
[Mon Jul 20 07:39:35.374702 2026] [security2:error] [pid 178071:tid 178307] [client 154.192.233.184:62088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lFxltgi7HBmNwzJNQSAAAAGg"]
[Mon Jul 20 07:39:35.535078 2026] [security2:error] [pid 178071:tid 178205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFxltgi7HBmNwzJNQJAAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:35.555847 2026] [security2:error] [pid 178071:tid 178327] [client 15.237.142.234:49744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 234.142.237.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lFxltgi7HBmNwzJNQcQAAAHw"]
[Mon Jul 20 07:39:35.590529 2026] [security2:error] [pid 178071:tid 178182] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/config/.env"] [unique_id "al4lFxltgi7HBmNwzJNQegAAcWw"]
[Mon Jul 20 07:39:35.696830 2026] [security2:error] [pid 178071:tid 178312] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lFxltgi7HBmNwzJNQQgAAAG0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:35.711272 2026] [security2:error] [pid 178071:tid 178249] [client 103.176.215.66:53315] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lFxltgi7HBmNwzJNQhgAAAC4"]
[Mon Jul 20 07:39:35.711369 2026] [security2:error] [pid 178071:tid 178249] [client 103.176.215.66:53315] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lFxltgi7HBmNwzJNQhgAAAC4"]
[Mon Jul 20 07:39:35.722218 2026] [security2:error] [pid 178071:tid 178160] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/secrets.yml"] [unique_id "al4lFxltgi7HBmNwzJNQiwAAA1Y"]
[Mon Jul 20 07:39:35.756045 2026] [security2:error] [pid 178071:tid 178287] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lFxltgi7HBmNwzJNQfQAAAFQ"]
[Mon Jul 20 07:39:35.795839 2026] [security2:error] [pid 178071:tid 178263] [client 65.111.22.211:17465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 211.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lFxltgi7HBmNwzJNQjAAAADw"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:35.857707 2026] [security2:error] [pid 178071:tid 178097] [remote 192.241.143.148:34426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4lFxltgi7HBmNwzJNQlgAAdRg"]
[Mon Jul 20 07:39:36.047918 2026] [security2:error] [pid 178071:tid 178090] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/serviceAccountKey.json"] [unique_id "al4lGBltgi7HBmNwzJNQowAANRE"]
[Mon Jul 20 07:39:36.068974 2026] [security2:error] [pid 178071:tid 178195] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/firebase-adminsdk.json"] [unique_id "al4lGBltgi7HBmNwzJNQpQAAM3k"]
[Mon Jul 20 07:39:36.093894 2026] [security2:error] [pid 178071:tid 178112] [remote 192.241.143.148:34426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4lGBltgi7HBmNwzJNQrAAAeSc"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:39:36.550202 2026] [security2:error] [pid 178071:tid 178137] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.svn/entries"] [unique_id "al4lGBltgi7HBmNwzJNQ1AAAfkA"]
[Mon Jul 20 07:39:36.550327 2026] [security2:error] [pid 178071:tid 178329] [client 34.32.109.138:51232] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manage.jeffjaeger.com"] [uri "/.svn/entries"] [unique_id "al4lGBltgi7HBmNwzJNQ1AAAfkA"]
[Mon Jul 20 07:39:36.552305 2026] [authz_core:error] [pid 178071:tid 178093] [remote 34.32.109.138:51232] AH01630: client denied by server configuration: /var/www/html/.htpasswd
[Mon Jul 20 07:39:36.555116 2026] [security2:error] [pid 178071:tid 178106] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "manage.jeffjaeger.com"] [uri "/terraform.tfstate"] [unique_id "al4lGBltgi7HBmNwzJNQ2gAAfiE"]
[Mon Jul 20 07:39:36.588725 2026] [security2:error] [pid 178071:tid 178111] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/.ssh/id_rsa"] [unique_id "al4lGBltgi7HBmNwzJNQ2wAAVSY"]
[Mon Jul 20 07:39:36.751063 2026] [security2:error] [pid 178071:tid 178237] [client 49.37.242.14:50645] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lGBltgi7HBmNwzJNQ7wAAACI"]
[Mon Jul 20 07:39:36.751142 2026] [security2:error] [pid 178071:tid 178237] [client 49.37.242.14:50645] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lGBltgi7HBmNwzJNQ7wAAACI"]
[Mon Jul 20 07:39:36.806479 2026] [security2:error] [pid 178071:tid 178289] [client 179.127.84.238:49209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lGBltgi7HBmNwzJNQ9gAAAFY"]
[Mon Jul 20 07:39:36.806611 2026] [security2:error] [pid 178071:tid 178289] [client 179.127.84.238:49209] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lGBltgi7HBmNwzJNQ9gAAAFY"]
[Mon Jul 20 07:39:36.815057 2026] [security2:error] [pid 178071:tid 178158] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.ssh/known_hosts"] [unique_id "al4lGBltgi7HBmNwzJNQ-QAALlQ"]
[Mon Jul 20 07:39:36.815177 2026] [security2:error] [pid 178071:tid 178249] [client 34.32.109.138:51232] ModSecurity: Warning. Matched phrase "CCBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "manage.jeffjaeger.com"] [uri "/.ssh/known_hosts"] [unique_id "al4lGBltgi7HBmNwzJNQ-QAALlQ"]
[Mon Jul 20 07:39:36.816444 2026] [security2:error] [pid 178071:tid 178141] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/id_rsa"] [unique_id "al4lGBltgi7HBmNwzJNQ-AAALkQ"]
[Mon Jul 20 07:39:36.817428 2026] [security2:error] [pid 178071:tid 178162] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "manage.jeffjaeger.com"] [uri "/id_dsa"] [unique_id "al4lGBltgi7HBmNwzJNQ-gAALlg"]
[Mon Jul 20 07:39:36.912794 2026] [security2:error] [pid 178071:tid 178121] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/id_ed25519"] [unique_id "al4lGBltgi7HBmNwzJNRAAAAVzA"]
[Mon Jul 20 07:39:36.912846 2026] [security2:error] [pid 178071:tid 178110] [remote 34.32.109.138:51232] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "manage.jeffjaeger.com"] [uri "/.ssh/id_dsa"] [unique_id "al4lGBltgi7HBmNwzJNRAQAAVyU"]
[Mon Jul 20 07:39:36.976105 2026] [security2:error] [pid 178071:tid 178219] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGBltgi7HBmNwzJNQ9QAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:37.398742 2026] [security2:error] [pid 178071:tid 178227] [client 57.141.18.65:60184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lFxltgi7HBmNwzJNQSwAAGBY"]
[Mon Jul 20 07:39:37.542306 2026] [security2:error] [pid 178071:tid 178315] [client 104.207.50.171:47225] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 171.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lGRltgi7HBmNwzJNRSwAAAHA"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:37.633325 2026] [security2:error] [pid 178071:tid 178278] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGRltgi7HBmNwzJNRIQAAAEs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:37.712869 2026] [security2:error] [pid 178071:tid 178273] [client 57.141.18.68:35364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lFxltgi7HBmNwzJNQjQAARgY"]
[Mon Jul 20 07:39:37.782846 2026] [security2:error] [pid 178071:tid 178249] [client 191.202.66.27:60835] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lGRltgi7HBmNwzJNRcgAAAC4"]
[Mon Jul 20 07:39:37.782945 2026] [security2:error] [pid 178071:tid 178249] [client 191.202.66.27:60835] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lGRltgi7HBmNwzJNRcgAAAC4"]
[Mon Jul 20 07:39:37.789092 2026] [security2:error] [pid 178071:tid 178325] [client 52.47.76.32:39264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.76.47.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lGRltgi7HBmNwzJNRbQAAAHo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:39:37.796278 2026] [security2:error] [pid 178071:tid 178239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGRltgi7HBmNwzJNRYAAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:37.854472 2026] [security2:error] [pid 178071:tid 178234] [client 57.141.18.76:22080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lFxltgi7HBmNwzJNQmAAAH2I"]
[Mon Jul 20 07:39:37.988502 2026] [security2:error] [pid 178071:tid 178237] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGRltgi7HBmNwzJNRcwAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:38.013039 2026] [security2:error] [pid 178071:tid 178101] [remote 198.46.152.106:51524] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.152.46.198.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mrbambooplus.com"] [uri "/wp-login.php"] [unique_id "al4lGhltgi7HBmNwzJNRigAAUBw"], referer: https://mrbambooplus.com/wp-login.php
[Mon Jul 20 07:39:38.102522 2026] [security2:error] [pid 178071:tid 178314] [client 57.141.18.0:55938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lGBltgi7HBmNwzJNQsAAAbzo"]
[Mon Jul 20 07:39:38.205533 2026] [core:error] [pid 178071:tid 178251] [client 14.225.17.146:61948] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/bc
[Mon Jul 20 07:39:38.205553 2026] [core:error] [pid 178071:tid 178251] [client 14.225.17.146:61948] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/bc
[Mon Jul 20 07:39:38.239864 2026] [security2:error] [pid 178071:tid 178298] [client 136.158.60.21:18066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lGhltgi7HBmNwzJNRngAAAF8"]
[Mon Jul 20 07:39:38.239977 2026] [security2:error] [pid 178071:tid 178298] [client 136.158.60.21:18066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lGhltgi7HBmNwzJNRngAAAF8"]
[Mon Jul 20 07:39:38.419400 2026] [security2:error] [pid 178071:tid 178279] [client 14.225.17.146:57676] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4lGhltgi7HBmNwzJNRnAAAAEw"]
[Mon Jul 20 07:39:38.953054 2026] [security2:error] [pid 178071:tid 178240] [client 45.3.54.50:54929] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lGhltgi7HBmNwzJNR1wAAACU"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:39.072309 2026] [security2:error] [pid 178071:tid 178280] [client 193.19.109.98:47779] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.109.19.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4lGxltgi7HBmNwzJNR4gAAAE0"]
[Mon Jul 20 07:39:39.074648 2026] [security2:error] [pid 178071:tid 178321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGhltgi7HBmNwzJNR0AAAAHY"]
[Mon Jul 20 07:39:39.317504 2026] [security2:error] [pid 178071:tid 178287] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGhltgi7HBmNwzJNR3AAAAFQ"]
[Mon Jul 20 07:39:39.337912 2026] [security2:error] [pid 178071:tid 178264] [client 57.141.18.11:28506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lGRltgi7HBmNwzJNRRwAAPQs"]
[Mon Jul 20 07:39:39.534378 2026] [security2:error] [pid 178071:tid 178268] [client 195.63.31.229:10347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lGxltgi7HBmNwzJNSCQAAAEE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:39.653535 2026] [security2:error] [pid 178071:tid 178158] [remote 41.186.86.12:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4lGxltgi7HBmNwzJNSFwAAa1Q"]
[Mon Jul 20 07:39:39.700006 2026] [security2:error] [pid 178071:tid 178215] [client 14.225.17.146:62047] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4lGhltgi7HBmNwzJNRwAAAAAw"], referer: http://entuvy.com/bc
[Mon Jul 20 07:39:39.810790 2026] [security2:error] [pid 178071:tid 178250] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGxltgi7HBmNwzJNSBAAAAC8"]
[Mon Jul 20 07:39:39.918733 2026] [security2:error] [pid 178071:tid 178293] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGxltgi7HBmNwzJNSEQAAAFo"]
[Mon Jul 20 07:39:39.932580 2026] [security2:error] [pid 178071:tid 178303] [client 49.47.218.174:49735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lGxltgi7HBmNwzJNSMQAAAGQ"]
[Mon Jul 20 07:39:39.932709 2026] [security2:error] [pid 178071:tid 178303] [client 49.47.218.174:49735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lGxltgi7HBmNwzJNSMQAAAGQ"]
[Mon Jul 20 07:39:40.155516 2026] [security2:error] [pid 178071:tid 178185] [remote 41.186.86.12:62394] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.86.186.41.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4lHBltgi7HBmNwzJNSRQAASG8"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:39:40.159861 2026] [security2:error] [pid 178071:tid 178282] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lGxltgi7HBmNwzJNSNgAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:40.240689 2026] [security2:error] [pid 178071:tid 178205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHBltgi7HBmNwzJNSPQAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:40.596839 2026] [security2:error] [pid 178071:tid 178310] [client 143.44.185.218:25214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lHBltgi7HBmNwzJNSaAAAAGs"]
[Mon Jul 20 07:39:40.596967 2026] [security2:error] [pid 178071:tid 178310] [client 143.44.185.218:25214] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lHBltgi7HBmNwzJNSaAAAAGs"]
[Mon Jul 20 07:39:40.830585 2026] [security2:error] [pid 178071:tid 178187] [remote 51.195.39.149:25557] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "weifangsmefarm.com"] [uri "/"] [unique_id "al4lHBltgi7HBmNwzJNShQAAfHE"]
[Mon Jul 20 07:39:40.894346 2026] [security2:error] [pid 178071:tid 178261] [client 50.116.65.227:34712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Mong-Kok-Feature-Image.jpg"] [unique_id "al4lHBltgi7HBmNwzJNShwAAADo"]
[Mon Jul 20 07:39:40.895457 2026] [security2:error] [pid 178071:tid 178222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHBltgi7HBmNwzJNScgAAABM"]
[Mon Jul 20 07:39:40.908654 2026] [security2:error] [pid 178071:tid 178285] [client 50.116.65.227:21810] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Mong-Kok-Feature-Image.jpg"] [unique_id "al4lHBltgi7HBmNwzJNSiAAAAD4"]
[Mon Jul 20 07:39:40.921939 2026] [security2:error] [pid 178071:tid 178321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHBltgi7HBmNwzJNScQAAAHY"]
[Mon Jul 20 07:39:40.950129 2026] [security2:error] [pid 178071:tid 178286] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHBltgi7HBmNwzJNSewAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:41.089058 2026] [security2:error] [pid 178071:tid 178262] [client 57.141.18.93:54626] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lGhltgi7HBmNwzJNR3QAAO24"]
[Mon Jul 20 07:39:41.195112 2026] [security2:error] [pid 178071:tid 178283] [client 180.249.173.210:61476] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lHRltgi7HBmNwzJNSoAAAAFA"]
[Mon Jul 20 07:39:41.195864 2026] [security2:error] [pid 178071:tid 178283] [client 180.249.173.210:61476] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lHRltgi7HBmNwzJNSoAAAAFA"]
[Mon Jul 20 07:39:41.238956 2026] [security2:error] [pid 178071:tid 178186] [remote 159.65.81.207:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4lHRltgi7HBmNwzJNSowAAVHA"]
[Mon Jul 20 07:39:41.406128 2026] [security2:error] [pid 178071:tid 178215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHRltgi7HBmNwzJNSoQAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:41.506631 2026] [security2:error] [pid 178071:tid 178221] [client 98.159.234.160:20725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lHRltgi7HBmNwzJNSvAAAABI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:39:41.512409 2026] [security2:error] [pid 178071:tid 178088] [remote 159.65.81.207:55382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 207.81.65.159.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dadanetnet.net"] [uri "/wp-login.php"] [unique_id "al4lHRltgi7HBmNwzJNSuwAAdg8"], referer: https://dadanetnet.net/wp-login.php
[Mon Jul 20 07:39:41.933009 2026] [security2:error] [pid 178071:tid 178242] [client 57.141.18.112:65130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lGxltgi7HBmNwzJNSLgAAJxU"]
[Mon Jul 20 07:39:41.990093 2026] [security2:error] [pid 178071:tid 178203] [client 57.141.18.12:37188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lGxltgi7HBmNwzJNSLwAAAC4"]
[Mon Jul 20 07:39:42.225256 2026] [security2:error] [pid 178071:tid 178279] [client 36.93.152.155:59868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lHhltgi7HBmNwzJNS_QAAAEw"]
[Mon Jul 20 07:39:42.225360 2026] [security2:error] [pid 178071:tid 178279] [client 36.93.152.155:59868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lHhltgi7HBmNwzJNS_QAAAEw"]
[Mon Jul 20 07:39:42.269454 2026] [security2:error] [pid 178071:tid 178276] [client 50.116.65.227:21836] ModSecurity: Warning. Matched phrase "fq" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "ksands.co.uk"] [uri "/wp-cron.php"] [unique_id "al4lHhltgi7HBmNwzJNS_wAAAEk"]
[Mon Jul 20 07:39:42.282233 2026] [security2:error] [pid 178071:tid 178256] [client 14.225.17.146:52576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4lHBltgi7HBmNwzJNSZwAAADU"], referer: http://koaconsultants.com/bc
[Mon Jul 20 07:39:42.394371 2026] [security2:error] [pid 178071:tid 178291] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHhltgi7HBmNwzJNS9QAAAFg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:42.715005 2026] [security2:error] [pid 178071:tid 178302] [client 37.52.210.45:64437] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lHhltgi7HBmNwzJNTIgAAAGM"]
[Mon Jul 20 07:39:42.715135 2026] [security2:error] [pid 178071:tid 178302] [client 37.52.210.45:64437] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lHhltgi7HBmNwzJNTIgAAAGM"]
[Mon Jul 20 07:39:42.885503 2026] [security2:error] [pid 178071:tid 178292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHhltgi7HBmNwzJNTIAAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:43.002733 2026] [security2:error] [pid 178071:tid 178304] [client 116.193.128.26:59391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTQgAAAGU"]
[Mon Jul 20 07:39:43.003529 2026] [security2:error] [pid 178071:tid 178304] [client 116.193.128.26:59391] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTQgAAAGU"]
[Mon Jul 20 07:39:43.213798 2026] [security2:error] [pid 178071:tid 178286] [client 89.238.167.150:46558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTVwAAAFM"]
[Mon Jul 20 07:39:43.213925 2026] [security2:error] [pid 178071:tid 178286] [client 89.238.167.150:46558] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTVwAAAFM"]
[Mon Jul 20 07:39:43.220996 2026] [security2:error] [pid 178071:tid 178227] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHhltgi7HBmNwzJNTNgAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:43.223983 2026] [security2:error] [pid 178071:tid 178291] [client 155.2.215.88:47553] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTSwAAAFg"]
[Mon Jul 20 07:39:43.266008 2026] [security2:error] [pid 178071:tid 178264] [client 103.139.191.61:63861] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTWQAAAD0"]
[Mon Jul 20 07:39:43.266118 2026] [security2:error] [pid 178071:tid 178264] [client 103.139.191.61:63861] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTWQAAAD0"]
[Mon Jul 20 07:39:43.296848 2026] [security2:error] [pid 178071:tid 178231] [client 57.141.18.43:34184] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lHRltgi7HBmNwzJNSsQAAHAc"]
[Mon Jul 20 07:39:43.330500 2026] [security2:error] [pid 178071:tid 178317] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHxltgi7HBmNwzJNTUAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:43.454851 2026] [security2:error] [pid 178071:tid 178279] [client 149.0.16.108:64754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTaQAAAEw"]
[Mon Jul 20 07:39:43.455531 2026] [security2:error] [pid 178071:tid 178279] [client 149.0.16.108:64754] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lHxltgi7HBmNwzJNTaQAAAEw"]
[Mon Jul 20 07:39:43.465339 2026] [security2:error] [pid 178071:tid 178246] [client 57.141.18.68:54514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lHRltgi7HBmNwzJNSyAAAK2I"]
[Mon Jul 20 07:39:43.787558 2026] [security2:error] [pid 178071:tid 178314] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lHxltgi7HBmNwzJNTcgAAAG8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:44.254458 2026] [security2:error] [pid 178071:tid 178288] [client 100.31.58.60:30084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.58.31.100.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lIBltgi7HBmNwzJNTqAAAAFU"]
[Mon Jul 20 07:39:44.320955 2026] [security2:error] [pid 178071:tid 178098] [remote 42.200.84.61:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4lIBltgi7HBmNwzJNTugAAPBk"]
[Mon Jul 20 07:39:44.342922 2026] [autoindex:error] [pid 178071:tid 178209] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2015/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:39:44.353015 2026] [security2:error] [pid 178071:tid 178267] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIBltgi7HBmNwzJNTogAAAEA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:44.455021 2026] [security2:error] [pid 178071:tid 178328] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIBltgi7HBmNwzJNTrAAAAH0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:44.620142 2026] [security2:error] [pid 178071:tid 178307] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "omegaecho.com"] [uri "/wp-admin/install.php"] [unique_id "al4lIBltgi7HBmNwzJNT2QAAAGg"]
[Mon Jul 20 07:39:44.689227 2026] [security2:error] [pid 178071:tid 178329] [client 52.207.32.99:13120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.32.207.52.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lIBltgi7HBmNwzJNT3QAAAH4"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:39:44.693157 2026] [security2:error] [pid 178071:tid 178122] [remote 42.200.84.61:47506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.84.200.42.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4lIBltgi7HBmNwzJNT3wAALDE"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:39:44.806532 2026] [security2:error] [pid 178071:tid 178232] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIBltgi7HBmNwzJNT2AAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:45.116070 2026] [access_compat:error] [pid 178071:tid 178182] [remote 2a06:98c0:3600::103:0] AH01797: client denied by server configuration: /home1/zanjanfr/public_html/wp-admin/install.php
[Mon Jul 20 07:39:45.179122 2026] [security2:error] [pid 178071:tid 178255] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIBltgi7HBmNwzJNT7gAAADQ"], referer: 1'"3000
[Mon Jul 20 07:39:45.357050 2026] [security2:error] [pid 178071:tid 178227] [client 57.141.18.41:57082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lHxltgi7HBmNwzJNTfgAAGD8"]
[Mon Jul 20 07:39:45.454094 2026] [security2:error] [pid 178071:tid 178292] [client 172.234.204.178:41630] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5028.bluehost.com"] [uri "/"] [unique_id "al4lIRltgi7HBmNwzJNUIAAAAFk"]
[Mon Jul 20 07:39:45.483892 2026] [security2:error] [pid 178071:tid 178285] [client 14.225.17.146:50421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4lIRltgi7HBmNwzJNUCQAAAFI"], referer: http://idigress.studio/bc
[Mon Jul 20 07:39:45.679291 2026] [security2:error] [pid 178071:tid 178284] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIRltgi7HBmNwzJNUHgAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:45.836110 2026] [security2:error] [pid 178071:tid 178255] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIRltgi7HBmNwzJNUNQAAADQ"], referer: 1'"3000
[Mon Jul 20 07:39:45.875660 2026] [security2:error] [pid 178071:tid 178259] [client 154.192.233.184:62452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lIRltgi7HBmNwzJNUSAAAADg"]
[Mon Jul 20 07:39:45.875776 2026] [security2:error] [pid 178071:tid 178259] [client 154.192.233.184:62452] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lIRltgi7HBmNwzJNUSAAAADg"]
[Mon Jul 20 07:39:46.048254 2026] [security2:error] [pid 178071:tid 178305] [client 14.225.17.146:62461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4lIRltgi7HBmNwzJNUUAAAAGY"], referer: http://thefriendlyspreadsheet.com/bc
[Mon Jul 20 07:39:46.294729 2026] [security2:error] [pid 178071:tid 178200] [remote 217.61.143.92:36304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4lIhltgi7HBmNwzJNUawAALX4"]
[Mon Jul 20 07:39:46.320850 2026] [security2:error] [pid 178071:tid 178209] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIRltgi7HBmNwzJNUVAAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:46.322524 2026] [security2:error] [pid 178071:tid 178262] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUXAAAADs"], referer: 1'"3000
[Mon Jul 20 07:39:46.354668 2026] [security2:error] [pid 178071:tid 178246] [client 103.176.215.66:53854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lIhltgi7HBmNwzJNUcQAAACs"]
[Mon Jul 20 07:39:46.355223 2026] [security2:error] [pid 178071:tid 178246] [client 103.176.215.66:53854] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lIhltgi7HBmNwzJNUcQAAACs"]
[Mon Jul 20 07:39:46.527359 2026] [security2:error] [pid 178071:tid 178146] [remote 217.61.143.92:36304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4lIhltgi7HBmNwzJNUggAAG0g"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:39:46.625603 2026] [security2:error] [pid 178071:tid 178137] [remote 182.77.62.24:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4lIhltgi7HBmNwzJNUkgAAbUA"]
[Mon Jul 20 07:39:46.713638 2026] [security2:error] [pid 178071:tid 178322] [client 57.141.18.124:36072] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lIRltgi7HBmNwzJNUCwAAdzQ"]
[Mon Jul 20 07:39:46.771549 2026] [security2:error] [pid 178071:tid 178317] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUgwAAAHI"], referer: 1'"3000
[Mon Jul 20 07:39:46.805601 2026] [security2:error] [pid 178071:tid 178270] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUigAAAEM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:46.863482 2026] [security2:error] [pid 178071:tid 178296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUlgAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:46.900055 2026] [security2:error] [pid 178071:tid 178080] [remote 173.249.4.11:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4lIhltgi7HBmNwzJNUrgAAUQc"]
[Mon Jul 20 07:39:47.045560 2026] [security2:error] [pid 178071:tid 178325] [client 14.225.17.146:62181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4lIBltgi7HBmNwzJNT8wAAAHo"], referer: http://dollpassionista.com/bc
[Mon Jul 20 07:39:47.085662 2026] [security2:error] [pid 178071:tid 178078] [remote 173.249.4.11:61767] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4lIxltgi7HBmNwzJNUyAAAKQU"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:39:47.121470 2026] [security2:error] [pid 178071:tid 178084] [remote 182.77.62.24:58920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4lIxltgi7HBmNwzJNUygAAZws"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:39:47.140662 2026] [security2:error] [pid 178071:tid 178222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUswAAABM"], referer: 1'"3000
[Mon Jul 20 07:39:47.222868 2026] [security2:error] [pid 178071:tid 178086] [remote 188.166.241.141:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lIxltgi7HBmNwzJNU2wAAGg0"]
[Mon Jul 20 07:39:47.242978 2026] [security2:error] [pid 178071:tid 178283] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIxltgi7HBmNwzJNUwAAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:47.279032 2026] [security2:error] [pid 178071:tid 178305] [client 179.127.84.238:49749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lIxltgi7HBmNwzJNU5AAAAGY"]
[Mon Jul 20 07:39:47.279150 2026] [security2:error] [pid 178071:tid 178305] [client 179.127.84.238:49749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lIxltgi7HBmNwzJNU5AAAAGY"]
[Mon Jul 20 07:39:47.590347 2026] [security2:error] [pid 178071:tid 178117] [remote 188.166.241.141:55810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lIxltgi7HBmNwzJNVCQAAciw"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:39:47.702025 2026] [security2:error] [pid 178071:tid 178148] [remote 57.141.18.12:34782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3849562"] [unique_id "al4lIxltgi7HBmNwzJNVEgAAaEo"]
[Mon Jul 20 07:39:47.713155 2026] [security2:error] [pid 178071:tid 178229] [client 114.119.152.207:20317] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.appelmanimages.com"] [uri "/naperville-child-portraits-k-family-lifestyle-photography/"] [unique_id "al4lIxltgi7HBmNwzJNVFAAAABo"], referer: https://www.appelmanimages.com/tag/naperville-lifestyle-photography
[Mon Jul 20 07:39:47.784322 2026] [security2:error] [pid 178071:tid 178316] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIxltgi7HBmNwzJNVCAAAAHE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:47.785449 2026] [security2:error] [pid 178071:tid 178276] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lIxltgi7HBmNwzJNVCgAAAEk"], referer: 1'"3000
[Mon Jul 20 07:39:47.924099 2026] [security2:error] [pid 178071:tid 178319] [client 77.110.127.138:53628] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/chart/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4lIxltgi7HBmNwzJNVKgAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:48.035070 2026] [security2:error] [pid 178071:tid 178241] [client 57.141.18.10:50204] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUcwAAJjI"]
[Mon Jul 20 07:39:48.186428 2026] [security2:error] [pid 178071:tid 178243] [client 14.225.17.146:53546] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4lJBltgi7HBmNwzJNVMgAAACg"], referer: https://dollpassionista.com/bc
[Mon Jul 20 07:39:48.378361 2026] [security2:error] [pid 178071:tid 178224] [client 191.202.66.27:61317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lJBltgi7HBmNwzJNVWgAAABU"]
[Mon Jul 20 07:39:48.378520 2026] [security2:error] [pid 178071:tid 178224] [client 191.202.66.27:61317] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lJBltgi7HBmNwzJNVWgAAABU"]
[Mon Jul 20 07:39:48.496347 2026] [security2:error] [pid 178071:tid 178323] [client 14.225.17.146:53430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4lIxltgi7HBmNwzJNVBgAAAHg"], referer: http://ghivs.com/bc
[Mon Jul 20 07:39:48.506625 2026] [security2:error] [pid 178071:tid 178302] [client 57.141.18.106:24134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lIhltgi7HBmNwzJNUsQAAYyY"]
[Mon Jul 20 07:39:48.538394 2026] [security2:error] [pid 178071:tid 178266] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJBltgi7HBmNwzJNVSAAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:48.897158 2026] [security2:error] [pid 178071:tid 178298] [client 136.158.60.21:19650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lJBltgi7HBmNwzJNVhgAAAF8"]
[Mon Jul 20 07:39:48.897327 2026] [security2:error] [pid 178071:tid 178298] [client 136.158.60.21:19650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lJBltgi7HBmNwzJNVhgAAAF8"]
[Mon Jul 20 07:39:48.976371 2026] [security2:error] [pid 178071:tid 178281] [client 14.225.17.146:53486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4lJBltgi7HBmNwzJNVgQAAAE4"], referer: http://carolinapressurewashers.com/bc
[Mon Jul 20 07:39:49.052665 2026] [security2:error] [pid 178071:tid 178282] [client 218.252.242.195:33205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.jennylouraya.com"] [uri "/wp-content/uploads/2012/03/Origami-Owl-shipping-Holiday-2014.jpg"] [unique_id "al4lJRltgi7HBmNwzJNVjgAAAE8"]
[Mon Jul 20 07:39:49.211281 2026] [security2:error] [pid 178071:tid 178289] [client 45.3.44.72:34421] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 72.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lJRltgi7HBmNwzJNVlAAAAFY"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:49.370763 2026] [security2:error] [pid 178071:tid 178128] [remote 20.153.140.50:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lJRltgi7HBmNwzJNVqAAAeTc"]
[Mon Jul 20 07:39:49.440169 2026] [security2:error] [pid 178071:tid 178260] [client 172.234.204.178:41632] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5028.bluehost.com"] [uri "/"] [unique_id "al4lJRltgi7HBmNwzJNVqwAAADk"]
[Mon Jul 20 07:39:49.663067 2026] [security2:error] [pid 178071:tid 178281] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNVsAAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:49.777307 2026] [security2:error] [pid 178071:tid 178161] [remote 20.153.140.50:51064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lJRltgi7HBmNwzJNVygAAZVc"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:39:49.801774 2026] [security2:error] [pid 178071:tid 178243] [client 74.7.175.163:43208] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "allergyantidotes.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNVxgAAKCc"]
[Mon Jul 20 07:39:49.804484 2026] [security2:error] [pid 178071:tid 178146] [remote 185.177.72.100:38462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\.env"] [unique_id "al4lJRltgi7HBmNwzJNV3AAAf0g"]
[Mon Jul 20 07:39:49.805656 2026] [security2:error] [pid 178071:tid 178328] [client 45.3.54.19:34031] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lJRltgi7HBmNwzJNV1wAAAH0"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:39:49.814799 2026] [security2:error] [pid 178071:tid 178203] [client 104.207.58.105:34313] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lJRltgi7HBmNwzJNV2gAAAAA"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:49.883829 2026] [security2:error] [pid 178071:tid 178230] [client 77.110.127.138:53637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/3/af93guyocym6.php"] [unique_id "al4lJRltgi7HBmNwzJNV7gAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:49.990566 2026] [security2:error] [pid 178071:tid 178299] [client 77.110.127.138:53600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV0wAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:50.098277 2026] [security2:error] [pid 178071:tid 178272] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV2wAAAEU"], referer: https://mezzacraft.com/author/mezza/page/page/2/
[Mon Jul 20 07:39:50.117638 2026] [security2:error] [pid 178071:tid 178280] [client 114.119.133.108:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.sergnotes.com"] [uri "/podcasts-to-re-listen-to"] [unique_id "al4lJhltgi7HBmNwzJNWAQAAAE0"], referer: http://www.sergnotes.com/podcasts-to-re-listen-to
[Mon Jul 20 07:39:50.125119 2026] [security2:error] [pid 178071:tid 178213] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV2AAAAAo"]
[Mon Jul 20 07:39:50.160545 2026] [security2:error] [pid 178071:tid 178298] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV3QAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:50.195778 2026] [security2:error] [pid 178071:tid 178212] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV7wAAAAk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:50.230167 2026] [security2:error] [pid 178071:tid 178268] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV8AAAAEE"], referer: https://mezzacraft.com/author/mezza/page/page/21/
[Mon Jul 20 07:39:50.269686 2026] [security2:error] [pid 178071:tid 178274] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNV8QAAAEc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:50.272832 2026] [security2:error] [pid 178071:tid 178206] [client 49.47.218.174:50274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lJhltgi7HBmNwzJNWDAAAAAM"]
[Mon Jul 20 07:39:50.273136 2026] [security2:error] [pid 178071:tid 178206] [client 49.47.218.174:50274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lJhltgi7HBmNwzJNWDAAAAAM"]
[Mon Jul 20 07:39:50.276592 2026] [security2:error] [pid 178071:tid 178215] [client 57.141.18.54:36418] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lJBltgi7HBmNwzJNVhQAADBo"]
[Mon Jul 20 07:39:50.413101 2026] [security2:error] [pid 178071:tid 178312] [client 49.37.242.14:51140] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lJhltgi7HBmNwzJNWFQAAAG0"]
[Mon Jul 20 07:39:50.413215 2026] [security2:error] [pid 178071:tid 178312] [client 49.37.242.14:51140] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lJhltgi7HBmNwzJNWFQAAAG0"]
[Mon Jul 20 07:39:50.595246 2026] [security2:error] [pid 178071:tid 178298] [client 77.110.127.138:53638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/chart/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4lJhltgi7HBmNwzJNWJgAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:50.726293 2026] [security2:error] [pid 178071:tid 178293] [client 57.141.18.79:61618] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lJRltgi7HBmNwzJNVowAAWgg"]
[Mon Jul 20 07:39:51.247526 2026] [security2:error] [pid 178071:tid 178279] [client 57.141.18.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lJxltgi7HBmNwzJNWTwAAAEw"]
[Mon Jul 20 07:39:51.493763 2026] [security2:error] [pid 178071:tid 178327] [client 180.249.173.210:61970] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lJxltgi7HBmNwzJNWcQAAAHw"]
[Mon Jul 20 07:39:51.494707 2026] [security2:error] [pid 178071:tid 178327] [client 180.249.173.210:61970] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lJxltgi7HBmNwzJNWcQAAAHw"]
[Mon Jul 20 07:39:51.540451 2026] [security2:error] [pid 178071:tid 178132] [remote 185.177.72.100:38488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2f.env"] [unique_id "al4lJxltgi7HBmNwzJNWdAAARzs"]
[Mon Jul 20 07:39:51.752010 2026] [security2:error] [pid 178071:tid 178240] [client 14.225.17.146:53147] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4lJhltgi7HBmNwzJNWHQAAACU"], referer: http://whiteoutcb.com/bc
[Mon Jul 20 07:39:51.941109 2026] [security2:error] [pid 178071:tid 178318] [client 136.144.33.203:31443] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 203.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4lJxltgi7HBmNwzJNWjgAAAHM"]
[Mon Jul 20 07:39:51.982818 2026] [autoindex:error] [pid 178071:tid 178252] [client 147.182.200.112:60654] AH01276: Cannot serve directory /home2/jjlzlomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:39:52.016528 2026] [security2:error] [pid 178071:tid 178306] [client 193.36.225.45:59307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4lJxltgi7HBmNwzJNWmAAAAGc"]
[Mon Jul 20 07:39:52.020565 2026] [security2:error] [pid 178071:tid 178304] [client 193.36.225.75:31995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 75.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4lJxltgi7HBmNwzJNWlwAAAGU"]
[Mon Jul 20 07:39:52.123043 2026] [security2:error] [pid 178071:tid 178140] [remote 188.166.241.141:34254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4lKBltgi7HBmNwzJNWnwAAdEM"]
[Mon Jul 20 07:39:52.123241 2026] [security2:error] [pid 178071:tid 178319] [client 188.166.241.141:34254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.grndl.com"] [uri "/xmlrpc.php"] [unique_id "al4lKBltgi7HBmNwzJNWnwAAdEM"]
[Mon Jul 20 07:39:52.145793 2026] [security2:error] [pid 178071:tid 178302] [client 14.225.17.146:53402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4lJhltgi7HBmNwzJNWIwAAAGM"], referer: http://vinovinhowine.com/bc
[Mon Jul 20 07:39:52.219935 2026] [autoindex:error] [pid 178071:tid 178225] [client 147.182.200.112:50148] AH01276: Cannot serve directory /home2/jjlzlomy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:39:52.287399 2026] [security2:error] [pid 178071:tid 178246] [client 14.225.17.146:54302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4lJxltgi7HBmNwzJNWkwAAACs"]
[Mon Jul 20 07:39:52.369538 2026] [security2:error] [pid 178071:tid 178329] [client 143.44.185.218:27517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lKBltgi7HBmNwzJNWtAAAAH4"]
[Mon Jul 20 07:39:52.371504 2026] [security2:error] [pid 178071:tid 178329] [client 143.44.185.218:27517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lKBltgi7HBmNwzJNWtAAAAH4"]
[Mon Jul 20 07:39:52.372518 2026] [security2:error] [pid 178071:tid 178111] [remote 185.177.72.100:38498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2f.env"] [unique_id "al4lKBltgi7HBmNwzJNWtQAACiY"]
[Mon Jul 20 07:39:52.445268 2026] [security2:error] [pid 178071:tid 178203] [client 186.168.252.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4lJxltgi7HBmNwzJNWbAAAAAA"]
[Mon Jul 20 07:39:52.594506 2026] [security2:error] [pid 178071:tid 178326] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lKBltgi7HBmNwzJNWsQAAAHs"], referer: https://mezzacraft.com/author/mezza/page/
[Mon Jul 20 07:39:52.696300 2026] [security2:error] [pid 178071:tid 178245] [client 57.141.18.83:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lKBltgi7HBmNwzJNWzAAAACo"]
[Mon Jul 20 07:39:52.723336 2026] [security2:error] [pid 178071:tid 178209] [client 57.141.18.109:29076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lJxltgi7HBmNwzJNWUAAABlE"]
[Mon Jul 20 07:39:52.738047 2026] [security2:error] [pid 178071:tid 178272] [client 36.93.152.155:60382] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lKBltgi7HBmNwzJNW1gAAAEU"]
[Mon Jul 20 07:39:52.738142 2026] [security2:error] [pid 178071:tid 178272] [client 36.93.152.155:60382] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lKBltgi7HBmNwzJNW1gAAAEU"]
[Mon Jul 20 07:39:53.041596 2026] [security2:error] [pid 178071:tid 178249] [client 57.141.18.6:23400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lJxltgi7HBmNwzJNWcgAALlM"]
[Mon Jul 20 07:39:53.108403 2026] [security2:error] [pid 178071:tid 178316] [client 57.141.18.44:51894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lJxltgi7HBmNwzJNWdgAAcUs"]
[Mon Jul 20 07:39:53.305530 2026] [security2:error] [pid 178071:tid 178232] [client 103.139.191.61:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXBwAAAB0"]
[Mon Jul 20 07:39:53.305651 2026] [security2:error] [pid 178071:tid 178232] [client 103.139.191.61:64363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXBwAAAB0"]
[Mon Jul 20 07:39:53.315917 2026] [security2:error] [pid 178071:tid 178256] [client 186.168.252.35:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4lKRltgi7HBmNwzJNW-QAAADU"]
[Mon Jul 20 07:39:53.384237 2026] [security2:error] [pid 178071:tid 178319] [client 37.52.210.45:1383] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXEAAAAHQ"]
[Mon Jul 20 07:39:53.384325 2026] [security2:error] [pid 178071:tid 178319] [client 37.52.210.45:1383] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXEAAAAHQ"]
[Mon Jul 20 07:39:53.434833 2026] [security2:error] [pid 178071:tid 178288] [client 172.234.204.178:32096] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5028.bluehost.com"] [uri "/"] [unique_id "al4lKRltgi7HBmNwzJNXEwAAAFU"]
[Mon Jul 20 07:39:53.461949 2026] [lsapi:warn] [pid 178071:tid 178110] [remote 216.73.216.153:62723] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:39:53.461973 2026] [lsapi:warn] [pid 178071:tid 178110] [remote 216.73.216.153:62723] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:39:53.711102 2026] [security2:error] [pid 178071:tid 178250] [client 116.193.128.26:59962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXMAAAAC8"]
[Mon Jul 20 07:39:53.711660 2026] [security2:error] [pid 178071:tid 178250] [client 116.193.128.26:59962] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXMAAAAC8"]
[Mon Jul 20 07:39:53.812687 2026] [security2:error] [pid 178071:tid 178218] [client 57.141.18.57:61752] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lKBltgi7HBmNwzJNWvAAAD2w"]
[Mon Jul 20 07:39:53.898887 2026] [security2:error] [pid 178071:tid 178226] [client 155.2.215.89:61505] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lKRltgi7HBmNwzJNXLwAAABc"]
[Mon Jul 20 07:39:53.969223 2026] [lsapi:warn] [pid 178071:tid 178318] [client 50.116.65.227:11988] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:39:53.969253 2026] [lsapi:warn] [pid 178071:tid 178318] [client 50.116.65.227:11988] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:39:54.001684 2026] [security2:error] [pid 178071:tid 178143] [remote 154.66.198.148:21118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/wp-login.php"] [unique_id "al4lKRltgi7HBmNwzJNXTwAAJ0Y"]
[Mon Jul 20 07:39:54.031280 2026] [security2:error] [pid 178071:tid 178320] [client 149.0.16.108:49166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lKhltgi7HBmNwzJNXUQAAAHU"]
[Mon Jul 20 07:39:54.031392 2026] [security2:error] [pid 178071:tid 178320] [client 149.0.16.108:49166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lKhltgi7HBmNwzJNXUQAAAHU"]
[Mon Jul 20 07:39:54.047413 2026] [lsapi:warn] [pid 178071:tid 178124] [remote 216.73.216.153:62723] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:39:54.047426 2026] [lsapi:warn] [pid 178071:tid 178124] [remote 216.73.216.153:62723] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:39:54.513777 2026] [security2:error] [pid 178071:tid 178158] [remote 154.66.198.148:21118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "elementconstruction.co.uk"] [uri "/wp-login.php"] [unique_id "al4lKhltgi7HBmNwzJNXdAAAcVQ"], referer: https://elementconstruction.co.uk/wp-login.php
[Mon Jul 20 07:39:54.695315 2026] [security2:error] [pid 178071:tid 178258] [client 14.225.17.146:52661] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4lKRltgi7HBmNwzJNXMwAAADc"], referer: http://claysharecon.com/bc
[Mon Jul 20 07:39:54.702190 2026] [security2:error] [pid 178071:tid 178214] [client 13.233.207.33:38354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lKhltgi7HBmNwzJNXdwAAAAs"]
[Mon Jul 20 07:39:54.702297 2026] [security2:error] [pid 178071:tid 178214] [client 13.233.207.33:38354] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lKhltgi7HBmNwzJNXdwAAAAs"]
[Mon Jul 20 07:39:55.526380 2026] [security2:error] [pid 178071:tid 178288] [client 51.68.107.139:11139] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.allergyantidotes.com"] [uri "/robots.txt"] [unique_id "al4lKxltgi7HBmNwzJNXvwAAAFU"]
[Mon Jul 20 07:39:55.526489 2026] [security2:error] [pid 178071:tid 178288] [client 51.68.107.139:11139] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.allergyantidotes.com"] [uri "/robots.txt"] [unique_id "al4lKxltgi7HBmNwzJNXvwAAAFU"]
[Mon Jul 20 07:39:55.730145 2026] [security2:error] [pid 178071:tid 178146] [remote 47.86.33.52:2854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lKxltgi7HBmNwzJNYBAAAWEg"]
[Mon Jul 20 07:39:55.780496 2026] [security2:error] [pid 178071:tid 178275] [client 57.141.18.80:24888] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lKhltgi7HBmNwzJNXYQAASBQ"]
[Mon Jul 20 07:39:55.949465 2026] [security2:error] [pid 178071:tid 178268] [client 52.35.117.102:30316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "python-requests|python-urllib" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "1460"] [id "909111"] [msg "Python UA brute"] [hostname "www.maplerespiteservices.com"] [uri "/"] [unique_id "al4lKxltgi7HBmNwzJNYFwAAAEE"]
[Mon Jul 20 07:39:56.091040 2026] [security2:error] [pid 178071:tid 178319] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lKxltgi7HBmNwzJNYEwAAAHQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:56.265113 2026] [security2:error] [pid 178071:tid 178130] [remote 5.161.225.162:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4lLBltgi7HBmNwzJNYPwAAVTk"]
[Mon Jul 20 07:39:56.281868 2026] [security2:error] [pid 178071:tid 178233] [client 57.141.18.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lLBltgi7HBmNwzJNYMAAAAB4"]
[Mon Jul 20 07:39:56.321515 2026] [security2:error] [pid 178071:tid 178259] [client 154.192.233.184:60973] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lLBltgi7HBmNwzJNYSAAAADg"]
[Mon Jul 20 07:39:56.321612 2026] [security2:error] [pid 178071:tid 178259] [client 154.192.233.184:60973] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lLBltgi7HBmNwzJNYSAAAADg"]
[Mon Jul 20 07:39:56.474486 2026] [security2:error] [pid 178071:tid 178116] [remote 5.161.225.162:55610] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4lLBltgi7HBmNwzJNYXAAARys"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:39:56.879247 2026] [security2:error] [pid 178071:tid 178267] [client 50.116.65.227:12010] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4lLBltgi7HBmNwzJNYcQAAAEA"]
[Mon Jul 20 07:39:56.883656 2026] [security2:error] [pid 178071:tid 178327] [client 103.176.215.66:54393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lLBltgi7HBmNwzJNYfwAAAHw"]
[Mon Jul 20 07:39:56.884140 2026] [security2:error] [pid 178071:tid 178327] [client 103.176.215.66:54393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lLBltgi7HBmNwzJNYfwAAAHw"]
[Mon Jul 20 07:39:57.064650 2026] [security2:error] [pid 178071:tid 178217] [client 50.116.65.227:12014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4lLBltgi7HBmNwzJNYgQAAAA4"]
[Mon Jul 20 07:39:57.390393 2026] [security2:error] [pid 178071:tid 178223] [client 57.141.18.115:38610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lKxltgi7HBmNwzJNXwgAAFA4"]
[Mon Jul 20 07:39:57.439348 2026] [security2:error] [pid 178071:tid 178327] [client 172.234.204.178:32080] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5028.bluehost.com"] [uri "/"] [unique_id "al4lLRltgi7HBmNwzJNYswAAAHw"]
[Mon Jul 20 07:39:57.450464 2026] [security2:error] [pid 178071:tid 178232] [client 77.110.127.138:53659] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/chart/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4lLRltgi7HBmNwzJNYtQAAAB0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:57.452548 2026] [security2:error] [pid 178071:tid 178286] [client 57.141.18.64:50788] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lKxltgi7HBmNwzJNXxgAAUzI"]
[Mon Jul 20 07:39:57.543301 2026] [security2:error] [pid 178071:tid 178209] [client 57.141.18.75:45588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lKxltgi7HBmNwzJNYAwAABnE"]
[Mon Jul 20 07:39:57.793141 2026] [security2:error] [pid 178071:tid 178263] [client 18.184.179.151:14712] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.179.184.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lLRltgi7HBmNwzJNY0QAAADw"]
[Mon Jul 20 07:39:57.793236 2026] [security2:error] [pid 178071:tid 178263] [client 18.184.179.151:14712] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lLRltgi7HBmNwzJNY0QAAADw"]
[Mon Jul 20 07:39:57.871860 2026] [security2:error] [pid 178071:tid 178220] [client 179.127.84.238:50293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lLRltgi7HBmNwzJNY2wAAABE"]
[Mon Jul 20 07:39:57.872042 2026] [security2:error] [pid 178071:tid 178220] [client 179.127.84.238:50293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lLRltgi7HBmNwzJNY2wAAABE"]
[Mon Jul 20 07:39:58.097956 2026] [security2:error] [pid 178071:tid 178328] [client 57.141.18.93:45764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lLBltgi7HBmNwzJNYPQAAfS4"]
[Mon Jul 20 07:39:58.158254 2026] [security2:error] [pid 178071:tid 178299] [client 57.141.18.113:57198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lLBltgi7HBmNwzJNYSgAAYAQ"]
[Mon Jul 20 07:39:58.159149 2026] [security2:error] [pid 178071:tid 178292] [client 77.110.127.138:53661] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-courses/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4lLhltgi7HBmNwzJNY4wAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:58.266545 2026] [security2:error] [pid 178071:tid 178073] [remote 47.86.33.52:2854] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lLhltgi7HBmNwzJNY7AAAQQA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:39:58.323566 2026] [security2:error] [pid 178071:tid 178109] [remote 216.73.216.55:42167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4lLhltgi7HBmNwzJNY9gAAWyQ"]
[Mon Jul 20 07:39:59.054245 2026] [security2:error] [pid 178071:tid 178274] [client 191.202.66.27:61806] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lLxltgi7HBmNwzJNZKgAAAEc"]
[Mon Jul 20 07:39:59.054407 2026] [security2:error] [pid 178071:tid 178274] [client 191.202.66.27:61806] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lLxltgi7HBmNwzJNZKgAAAEc"]
[Mon Jul 20 07:39:59.176300 2026] [security2:error] [pid 178071:tid 178272] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lLhltgi7HBmNwzJNZHAAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:39:59.208136 2026] [security2:error] [pid 178071:tid 178309] [client 34.90.254.162:24576] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "cpcontacts.fineartsfactory.net"] [uri "/"] [unique_id "al4lLxltgi7HBmNwzJNZOAAAAGo"]
[Mon Jul 20 07:39:59.208270 2026] [security2:error] [pid 178071:tid 178309] [client 34.90.254.162:24576] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "cpcontacts.fineartsfactory.net"] [uri "/"] [unique_id "al4lLxltgi7HBmNwzJNZOAAAAGo"]
[Mon Jul 20 07:39:59.395220 2026] [security2:error] [pid 178071:tid 178158] [remote 5.182.209.54:46694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4lLxltgi7HBmNwzJNZQgAAZlQ"]
[Mon Jul 20 07:39:59.532811 2026] [security2:error] [pid 178071:tid 178258] [client 136.158.60.21:21192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lLxltgi7HBmNwzJNZTQAAADc"]
[Mon Jul 20 07:39:59.532914 2026] [security2:error] [pid 178071:tid 178258] [client 136.158.60.21:21192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lLxltgi7HBmNwzJNZTQAAADc"]
[Mon Jul 20 07:39:59.560829 2026] [security2:error] [pid 178071:tid 178086] [remote 5.182.209.54:46694] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.209.182.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4lLxltgi7HBmNwzJNZUQAAXg0"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:39:59.644640 2026] [security2:error] [pid 178071:tid 178306] [client 47.129.222.11:30016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lLxltgi7HBmNwzJNZVQAAAGc"]
[Mon Jul 20 07:39:59.644802 2026] [security2:error] [pid 178071:tid 178306] [client 47.129.222.11:30016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lLxltgi7HBmNwzJNZVQAAAGc"]
[Mon Jul 20 07:39:59.676682 2026] [security2:error] [pid 178071:tid 178277] [client 217.181.92.215:54947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.92.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lLxltgi7HBmNwzJNZVwAAAEo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:39:59.816673 2026] [security2:error] [pid 178071:tid 178274] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4lLxltgi7HBmNwzJNZTwAAAEc"]
[Mon Jul 20 07:39:59.975015 2026] [security2:error] [pid 178071:tid 178221] [client 57.141.18.12:27486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lLhltgi7HBmNwzJNY3gAAEjo"]
[Mon Jul 20 07:40:00.323370 2026] [security2:error] [pid 178071:tid 178212] [client 45.3.45.9:26099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lMBltgi7HBmNwzJNZhQAAAAk"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:00.360265 2026] [security2:error] [pid 178071:tid 178300] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lMBltgi7HBmNwzJNZewAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:00.568396 2026] [security2:error] [pid 178071:tid 178209] [client 116.74.65.235:62768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lMBltgi7HBmNwzJNZpwAAAAY"]
[Mon Jul 20 07:40:00.568499 2026] [security2:error] [pid 178071:tid 178209] [client 116.74.65.235:62768] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lMBltgi7HBmNwzJNZpwAAAAY"]
[Mon Jul 20 07:40:00.719480 2026] [security2:error] [pid 178071:tid 178236] [client 65.111.22.165:64495] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 165.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lMBltgi7HBmNwzJNZsQAAACE"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:00.749428 2026] [security2:error] [pid 178071:tid 178231] [client 49.47.218.174:50825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lMBltgi7HBmNwzJNZtAAAABw"]
[Mon Jul 20 07:40:00.749519 2026] [security2:error] [pid 178071:tid 178231] [client 49.47.218.174:50825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lMBltgi7HBmNwzJNZtAAAABw"]
[Mon Jul 20 07:40:00.797635 2026] [security2:error] [pid 178071:tid 178123] [remote 57.141.18.111:20208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4lMBltgi7HBmNwzJNZugAANDI"]
[Mon Jul 20 07:40:00.954544 2026] [security2:error] [pid 178071:tid 178217] [client 217.181.90.186:24503] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.90.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lMBltgi7HBmNwzJNZxAAAAA4"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:00.957606 2026] [security2:error] [pid 178071:tid 178266] [client 57.141.18.100:43438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lLxltgi7HBmNwzJNZMQAAP0Y"]
[Mon Jul 20 07:40:01.057462 2026] [proxy:error] [pid 178071:tid 178292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:01.057502 2026] [proxy_http:error] [pid 178071:tid 178292] [client 107.172.180.205:49920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:01.058087 2026] [proxy:error] [pid 178071:tid 178292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:01.058118 2026] [proxy_http:error] [pid 178071:tid 178292] [client 107.172.180.205:49920] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:01.206825 2026] [security2:error] [pid 178071:tid 178186] [remote 217.113.60.80:57952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 80.60.113.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lMRltgi7HBmNwzJNZ2QAAInA"]
[Mon Jul 20 07:40:01.206998 2026] [security2:error] [pid 178071:tid 178237] [client 217.113.60.80:57952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "maa.hws.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lMRltgi7HBmNwzJNZ2QAAInA"]
[Mon Jul 20 07:40:01.256149 2026] [security2:error] [pid 178071:tid 178283] [client 57.141.18.111:45544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lLxltgi7HBmNwzJNZRQAAUDk"]
[Mon Jul 20 07:40:01.391353 2026] [security2:error] [pid 178071:tid 178307] [client 74.7.228.51:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mzj.mxz.mybluehost.me"] [uri "/index.php"] [unique_id "al4lLBltgi7HBmNwzJNYjAAAAGg"]
[Mon Jul 20 07:40:01.394990 2026] [security2:error] [pid 178071:tid 178303] [client 74.7.228.51:46914] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mzj.mxz.mybluehost.me"] [uri "/robots.txt"] [unique_id "al4lLBltgi7HBmNwzJNYiAAAZGc"]
[Mon Jul 20 07:40:01.436360 2026] [security2:error] [pid 178071:tid 178317] [client 172.234.204.178:18102] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^0$" against "REQUEST_HEADERS:Content-Length" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "96"] [id "392301"] [rev "7"] [msg "Atomicorp.com WAF Rules: Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [tag "no_ar"] [hostname "box5028.bluehost.com"] [uri "/"] [unique_id "al4lMRltgi7HBmNwzJNZ8gAAAHI"]
[Mon Jul 20 07:40:01.719687 2026] [security2:error] [pid 178071:tid 178316] [client 158.173.166.181:52729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lMRltgi7HBmNwzJNaCgAAAHE"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:40:01.730539 2026] [security2:error] [pid 178071:tid 178248] [client 108.61.75.13:35072] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dienerranch.com"] [uri "/"] [unique_id "al4lMRltgi7HBmNwzJNaCwAAAC0"]
[Mon Jul 20 07:40:01.844284 2026] [security2:error] [pid 178071:tid 178207] [client 57.141.18.95:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lMRltgi7HBmNwzJNaCQAAAAQ"]
[Mon Jul 20 07:40:01.905667 2026] [security2:error] [pid 178071:tid 178242] [client 180.249.173.210:62460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lMRltgi7HBmNwzJNaHAAAACc"]
[Mon Jul 20 07:40:01.906256 2026] [security2:error] [pid 178071:tid 178242] [client 180.249.173.210:62460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lMRltgi7HBmNwzJNaHAAAACc"]
[Mon Jul 20 07:40:02.149658 2026] [security2:error] [pid 178071:tid 178221] [client 45.3.42.229:31179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 229.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lMhltgi7HBmNwzJNaMAAAABI"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:02.283877 2026] [security2:error] [pid 178071:tid 178216] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lMRltgi7HBmNwzJNaJgAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:02.408138 2026] [security2:error] [pid 178071:tid 178306] [client 57.141.18.39:62005] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lMBltgi7HBmNwzJNZqQAAZ1s"]
[Mon Jul 20 07:40:02.670525 2026] [proxy:error] [pid 178071:tid 178279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:02.670610 2026] [proxy_http:error] [pid 178071:tid 178279] [client 107.172.180.205:49948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:02.671100 2026] [proxy:error] [pid 178071:tid 178279] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:02.671129 2026] [proxy_http:error] [pid 178071:tid 178279] [client 107.172.180.205:49948] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:02.809793 2026] [security2:error] [pid 178071:tid 178182] [remote 194.164.192.228:41152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lMhltgi7HBmNwzJNaXwAAFGw"]
[Mon Jul 20 07:40:02.810056 2026] [security2:error] [pid 178071:tid 178223] [client 194.164.192.228:41152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.idf.ldc.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lMhltgi7HBmNwzJNaXwAAFGw"]
[Mon Jul 20 07:40:02.860503 2026] [security2:error] [pid 178071:tid 178259] [client 57.141.18.22:28508] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lMRltgi7HBmNwzJNZ1QAAOH0"]
[Mon Jul 20 07:40:03.045159 2026] [security2:error] [pid 178071:tid 178258] [client 57.141.18.56:46876] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lMRltgi7HBmNwzJNZ5gAANwk"]
[Mon Jul 20 07:40:03.240497 2026] [security2:error] [pid 178071:tid 178309] [client 77.110.127.138:53681] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/tag/crochet-courses/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4lMxltgi7HBmNwzJNaiAAAAGo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:03.248104 2026] [security2:error] [pid 178071:tid 178217] [client 36.93.152.155:60894] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lMxltgi7HBmNwzJNaigAAAA4"]
[Mon Jul 20 07:40:03.248259 2026] [security2:error] [pid 178071:tid 178217] [client 36.93.152.155:60894] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lMxltgi7HBmNwzJNaigAAAA4"]
[Mon Jul 20 07:40:03.409667 2026] [security2:error] [pid 178071:tid 178221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lMxltgi7HBmNwzJNahgAAABI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:03.550746 2026] [security2:error] [pid 178071:tid 178296] [client 45.3.42.32:31967] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lMxltgi7HBmNwzJNapQAAAF0"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:03.614323 2026] [security2:error] [pid 178071:tid 178321] [client 54.244.177.189:41572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-cron.php"] [unique_id "al4lMxltgi7HBmNwzJNasQAAAHY"]
[Mon Jul 20 07:40:03.959671 2026] [security2:error] [pid 178071:tid 178246] [client 37.52.210.45:3307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lMxltgi7HBmNwzJNaxAAAACs"]
[Mon Jul 20 07:40:03.959795 2026] [security2:error] [pid 178071:tid 178246] [client 37.52.210.45:3307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lMxltgi7HBmNwzJNaxAAAACs"]
[Mon Jul 20 07:40:04.079138 2026] [security2:error] [pid 178071:tid 178314] [client 57.141.18.52:62704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lMhltgi7HBmNwzJNaPQAAbwI"]
[Mon Jul 20 07:40:04.089878 2026] [security2:error] [pid 178071:tid 178095] [remote 152.228.213.32:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4lNBltgi7HBmNwzJNa0AAAExY"]
[Mon Jul 20 07:40:04.289157 2026] [security2:error] [pid 178071:tid 178181] [remote 152.228.213.32:49534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4lNBltgi7HBmNwzJNa4wAAfms"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:40:04.322166 2026] [security2:error] [pid 178071:tid 178320] [client 116.193.128.26:60539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNa5QAAAHU"]
[Mon Jul 20 07:40:04.322283 2026] [security2:error] [pid 178071:tid 178320] [client 116.193.128.26:60539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNa5QAAAHU"]
[Mon Jul 20 07:40:04.347848 2026] [security2:error] [pid 178071:tid 178280] [client 103.139.191.61:64865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNa6AAAAE0"]
[Mon Jul 20 07:40:04.348002 2026] [security2:error] [pid 178071:tid 178280] [client 103.139.191.61:64865] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNa6AAAAE0"]
[Mon Jul 20 07:40:04.368068 2026] [security2:error] [pid 178071:tid 178282] [client 142.111.152.183:47943] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNa2gAAAE8"]
[Mon Jul 20 07:40:04.543929 2026] [security2:error] [pid 178071:tid 178277] [client 57.141.18.12:57562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lMhltgi7HBmNwzJNaYQAASnY"]
[Mon Jul 20 07:40:04.617669 2026] [security2:error] [pid 178071:tid 178207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lNBltgi7HBmNwzJNa4QAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:04.642167 2026] [security2:error] [pid 178071:tid 178259] [client 149.0.16.108:49796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNbBwAAADg"]
[Mon Jul 20 07:40:04.642254 2026] [security2:error] [pid 178071:tid 178259] [client 149.0.16.108:49796] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNbBwAAADg"]
[Mon Jul 20 07:40:04.728187 2026] [security2:error] [pid 178071:tid 178209] [client 74.7.227.179:33248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4lNBltgi7HBmNwzJNa_wAABg4"], referer: https://tejasenvironmental.com/p=298036
[Mon Jul 20 07:40:04.993992 2026] [security2:error] [pid 178071:tid 178217] [client 49.37.242.14:51652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNbIwAAAA4"]
[Mon Jul 20 07:40:04.994107 2026] [security2:error] [pid 178071:tid 178217] [client 49.37.242.14:51652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNbIwAAAA4"]
[Mon Jul 20 07:40:04.996322 2026] [security2:error] [pid 178071:tid 178318] [client 143.44.185.218:29883] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNbJAAAAHM"]
[Mon Jul 20 07:40:04.996391 2026] [security2:error] [pid 178071:tid 178318] [client 143.44.185.218:29883] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lNBltgi7HBmNwzJNbJAAAAHM"]
[Mon Jul 20 07:40:05.143429 2026] [security2:error] [pid 178071:tid 178311] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lNBltgi7HBmNwzJNbFgAAAGw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:05.223779 2026] [security2:error] [pid 178071:tid 178306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lNBltgi7HBmNwzJNbHwAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:05.259006 2026] [security2:error] [pid 178071:tid 178279] [client 57.141.18.88:32444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lMxltgi7HBmNwzJNatgAATBI"]
[Mon Jul 20 07:40:06.004930 2026] [autoindex:error] [pid 178071:tid 178137] [remote 136.114.198.221:55361] AH01276: Cannot serve directory /home2/dekbypmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.dek.byp.mybluehost.me
[Mon Jul 20 07:40:06.181927 2026] [security2:error] [pid 178071:tid 178297] [client 162.141.167.68:36152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.according2plant.com"] [uri "/.env"] [unique_id "al4lNhltgi7HBmNwzJNbmQAAAF4"]
[Mon Jul 20 07:40:06.358802 2026] [security2:error] [pid 178071:tid 178321] [client 162.141.167.68:42632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.according2plant.com"] [uri "/api/.env"] [unique_id "al4lNhltgi7HBmNwzJNbuwAAAHY"]
[Mon Jul 20 07:40:06.358969 2026] [security2:error] [pid 178071:tid 178205] [client 162.141.167.68:42594] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.according2plant.com"] [uri "/backend/.env"] [unique_id "al4lNhltgi7HBmNwzJNbvQAAAAI"]
[Mon Jul 20 07:40:06.365442 2026] [security2:error] [pid 178071:tid 178233] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbnQAAAB4"]
[Mon Jul 20 07:40:06.439204 2026] [security2:error] [pid 178071:tid 178258] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbqAAAADc"]
[Mon Jul 20 07:40:06.533303 2026] [security2:error] [pid 178071:tid 178203] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbwgAAAAA"]
[Mon Jul 20 07:40:06.544517 2026] [security2:error] [pid 178071:tid 178228] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbxAAAABk"]
[Mon Jul 20 07:40:06.545616 2026] [security2:error] [pid 178071:tid 178282] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbwQAAAE8"]
[Mon Jul 20 07:40:06.561957 2026] [security2:error] [pid 178071:tid 178297] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbwwAAAF4"]
[Mon Jul 20 07:40:06.582238 2026] [security2:error] [pid 178071:tid 178328] [client 162.141.167.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.according2plant.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNbxQAAAH0"]
[Mon Jul 20 07:40:06.667180 2026] [security2:error] [pid 178071:tid 178289] [client 57.141.18.7:21142] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lNRltgi7HBmNwzJNbQQAAVig"]
[Mon Jul 20 07:40:06.695233 2026] [security2:error] [pid 178071:tid 178329] [client 202.141.11.99:22223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4lNhltgi7HBmNwzJNb3QAAAH4"]
[Mon Jul 20 07:40:06.695360 2026] [security2:error] [pid 178071:tid 178329] [client 202.141.11.99:22223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4lNhltgi7HBmNwzJNb3QAAAH4"]
[Mon Jul 20 07:40:06.921416 2026] [security2:error] [pid 178071:tid 178101] [remote 154.66.198.148:16512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4lNhltgi7HBmNwzJNb7gAAFxw"]
[Mon Jul 20 07:40:06.942823 2026] [security2:error] [pid 178071:tid 178217] [client 154.192.233.184:61446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lNhltgi7HBmNwzJNb8gAAAA4"]
[Mon Jul 20 07:40:06.942933 2026] [security2:error] [pid 178071:tid 178217] [client 154.192.233.184:61446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lNhltgi7HBmNwzJNb8gAAAA4"]
[Mon Jul 20 07:40:07.400088 2026] [security2:error] [pid 178071:tid 178245] [client 103.176.215.66:54930] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lNxltgi7HBmNwzJNcEwAAACo"]
[Mon Jul 20 07:40:07.400761 2026] [security2:error] [pid 178071:tid 178245] [client 103.176.215.66:54930] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lNxltgi7HBmNwzJNcEwAAACo"]
[Mon Jul 20 07:40:07.451492 2026] [security2:error] [pid 178071:tid 178172] [remote 8.217.108.67:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lNxltgi7HBmNwzJNcFAAAJmI"]
[Mon Jul 20 07:40:07.465074 2026] [security2:error] [pid 178071:tid 178117] [remote 154.66.198.148:16512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/wp-login.php"] [unique_id "al4lNxltgi7HBmNwzJNcGQAABCw"], referer: https://grecaalma.com/wp-login.php
[Mon Jul 20 07:40:07.615021 2026] [security2:error] [pid 178071:tid 178236] [client 57.141.18.18:59340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNblQAAIXU"]
[Mon Jul 20 07:40:07.689305 2026] [security2:error] [pid 178071:tid 178281] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lNxltgi7HBmNwzJNcGgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:08.100155 2026] [security2:error] [pid 178071:tid 178288] [client 57.141.18.7:33352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNb4gAAVW0"]
[Mon Jul 20 07:40:08.232587 2026] [security2:error] [pid 178071:tid 178250] [client 57.141.18.69:53446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lNhltgi7HBmNwzJNb7QAALxU"]
[Mon Jul 20 07:40:08.279692 2026] [security2:error] [pid 178071:tid 178163] [remote 188.40.28.4:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lOBltgi7HBmNwzJNcYAAAW1k"]
[Mon Jul 20 07:40:08.314744 2026] [security2:error] [pid 178071:tid 178262] [client 57.141.18.59:35666] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lNxltgi7HBmNwzJNb-AAAO2U"]
[Mon Jul 20 07:40:08.476785 2026] [security2:error] [pid 178071:tid 178122] [remote 188.40.28.4:56862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lOBltgi7HBmNwzJNcawAACDE"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:40:08.631942 2026] [security2:error] [pid 178071:tid 178229] [client 179.127.84.238:50836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lOBltgi7HBmNwzJNceAAAABo"]
[Mon Jul 20 07:40:08.632059 2026] [security2:error] [pid 178071:tid 178229] [client 179.127.84.238:50836] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lOBltgi7HBmNwzJNceAAAABo"]
[Mon Jul 20 07:40:08.663920 2026] [security2:error] [pid 178071:tid 178151] [remote 20.153.140.50:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lOBltgi7HBmNwzJNcfAAAXU0"]
[Mon Jul 20 07:40:08.865675 2026] [security2:error] [pid 178071:tid 178271] [client 57.141.18.77:36568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lNxltgi7HBmNwzJNcJwAARDs"]
[Mon Jul 20 07:40:09.068464 2026] [security2:error] [pid 178071:tid 178077] [remote 20.153.140.50:46464] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lORltgi7HBmNwzJNcmwAAHQQ"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:40:09.201247 2026] [security2:error] [pid 178071:tid 178328] [client 50.116.65.227:34648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lORltgi7HBmNwzJNcswAAAH0"]
[Mon Jul 20 07:40:09.213715 2026] [security2:error] [pid 178071:tid 178268] [client 50.116.65.227:34650] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lORltgi7HBmNwzJNctQAAAEE"]
[Mon Jul 20 07:40:09.228486 2026] [security2:error] [pid 178071:tid 178316] [client 57.141.18.19:61442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lOBltgi7HBmNwzJNcWQAAcTg"]
[Mon Jul 20 07:40:09.396790 2026] [security2:error] [pid 178071:tid 178297] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lORltgi7HBmNwzJNcsQAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:09.608525 2026] [security2:error] [pid 178071:tid 178245] [client 77.110.127.138:53715] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/"] [unique_id "al4lORltgi7HBmNwzJNc0gAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:09.748163 2026] [security2:error] [pid 178071:tid 178290] [client 191.202.66.27:62302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lORltgi7HBmNwzJNc3wAAAFc"]
[Mon Jul 20 07:40:09.748287 2026] [security2:error] [pid 178071:tid 178290] [client 191.202.66.27:62302] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lORltgi7HBmNwzJNc3wAAAFc"]
[Mon Jul 20 07:40:09.779887 2026] [security2:error] [pid 178071:tid 178324] [client 57.141.18.110:39330] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lOBltgi7HBmNwzJNckAAAeXw"]
[Mon Jul 20 07:40:09.893789 2026] [core:error] [pid 178071:tid 178322] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:40:09.893809 2026] [core:error] [pid 178071:tid 178322] [client 107.172.180.205:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:40:09.991025 2026] [security2:error] [pid 178071:tid 178219] [client 45.157.112.60:44749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lORltgi7HBmNwzJNc8wAAABA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:40:10.134486 2026] [security2:error] [pid 178071:tid 178245] [client 46.110.96.34:34844] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4lOhltgi7HBmNwzJNc_AAAACo"]
[Mon Jul 20 07:40:10.163035 2026] [security2:error] [pid 178071:tid 178294] [client 57.141.18.93:63400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lORltgi7HBmNwzJNcwQAAW1Y"]
[Mon Jul 20 07:40:10.293786 2026] [security2:error] [pid 178071:tid 178273] [client 136.158.60.21:22745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lOhltgi7HBmNwzJNdCwAAAEY"]
[Mon Jul 20 07:40:10.293895 2026] [security2:error] [pid 178071:tid 178273] [client 136.158.60.21:22745] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lOhltgi7HBmNwzJNdCwAAAEY"]
[Mon Jul 20 07:40:10.418569 2026] [security2:error] [pid 178071:tid 178296] [client 57.141.18.4:46468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lORltgi7HBmNwzJNc3QAAXVI"]
[Mon Jul 20 07:40:10.474288 2026] [security2:error] [pid 178071:tid 178225] [client 14.225.17.146:54018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4lOhltgi7HBmNwzJNdFAAAABY"], referer: http://nextlvlmarketingco.com/www
[Mon Jul 20 07:40:10.614634 2026] [security2:error] [pid 178071:tid 178216] [client 45.3.45.198:39343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 198.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lOhltgi7HBmNwzJNdRQAAAA0"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:10.747208 2026] [security2:error] [pid 178071:tid 178207] [client 14.225.17.146:54981] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4lOhltgi7HBmNwzJNdUwAAAAQ"], referer: http://intelligentengineeringsolutions.com/www
[Mon Jul 20 07:40:10.970461 2026] [security2:error] [pid 178071:tid 178241] [client 57.141.18.95:46360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lOhltgi7HBmNwzJNc_gAAJi0"]
[Mon Jul 20 07:40:11.199931 2026] [http2:info] [pid 204156:tid 204156] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:40:11.204112 2026] [security2:error] [pid 178071:tid 178318] [client 49.47.218.174:51369] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lOxltgi7HBmNwzJNdfgAAAHM"]
[Mon Jul 20 07:40:11.204268 2026] [security2:error] [pid 178071:tid 178318] [client 49.47.218.174:51369] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lOxltgi7HBmNwzJNdfgAAAHM"]
[Mon Jul 20 07:40:11.345104 2026] [security2:error] [pid 178071:tid 178211] [client 14.225.17.146:60421] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4lOxltgi7HBmNwzJNddgAAAAg"], referer: http://maplerespiteservices.com/www
[Mon Jul 20 07:40:11.431922 2026] [security2:error] [pid 178071:tid 178272] [client 43.135.107.245:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4lOxltgi7HBmNwzJNdbwAAAEU"]
[Mon Jul 20 07:40:11.448961 2026] [security2:error] [pid 178071:tid 178285] [client 57.141.18.125:56180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lOhltgi7HBmNwzJNdMQAAUik"]
[Mon Jul 20 07:40:11.522599 2026] [security2:error] [pid 204156:tid 204289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lOxbAFPhDXvzP7SmskAAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:11.938011 2026] [security2:error] [pid 178071:tid 178233] [client 57.141.18.11:44846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lOxltgi7HBmNwzJNdcwAAHjo"]
[Mon Jul 20 07:40:11.949921 2026] [security2:error] [pid 178071:tid 178095] [remote 8.217.108.67:12184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lOxltgi7HBmNwzJNdqgAAZRY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:40:12.010450 2026] [security2:error] [pid 204156:tid 204320] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lOxbAFPhDXvzP7SmsoAAAAbE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:12.065369 2026] [security2:error] [pid 204156:tid 204157] [remote 185.177.72.100:51230] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\.env.bak"] [unique_id "al4lPBbAFPhDXvzP7SmsrAABvQA"]
[Mon Jul 20 07:40:12.364449 2026] [security2:error] [pid 204156:tid 204159] [remote 49.12.216.176:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4lPBbAFPhDXvzP7SmstgAByQI"]
[Mon Jul 20 07:40:12.504745 2026] [security2:error] [pid 204156:tid 204329] [client 142.93.7.143:45108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4lPBbAFPhDXvzP7SmsswAAAbo"], referer: https://www.sesamegreenbeans.com/
[Mon Jul 20 07:40:12.618044 2026] [security2:error] [pid 204156:tid 204160] [remote 49.12.216.176:37264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 176.216.12.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mobilesurvsolutions.com"] [uri "/wp-login.php"] [unique_id "al4lPBbAFPhDXvzP7SmsugAB3wM"], referer: https://mobilesurvsolutions.com/wp-login.php
[Mon Jul 20 07:40:12.715868 2026] [security2:error] [pid 204156:tid 204346] [client 180.249.173.210:63039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lPBbAFPhDXvzP7SmsvwAAAcs"]
[Mon Jul 20 07:40:12.716341 2026] [security2:error] [pid 204156:tid 204346] [client 180.249.173.210:63039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lPBbAFPhDXvzP7SmsvwAAAcs"]
[Mon Jul 20 07:40:12.839818 2026] [security2:error] [pid 204156:tid 204163] [remote 78.46.157.202:57818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4lPBbAFPhDXvzP7SmswgAB4gY"]
[Mon Jul 20 07:40:12.908352 2026] [security2:error] [pid 178071:tid 178313] [client 14.225.17.146:52032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4lPBltgi7HBmNwzJNdzwAAAG4"], referer: http://chestermonty.com/www
[Mon Jul 20 07:40:12.911849 2026] [security2:error] [pid 204156:tid 204165] [remote 185.177.72.100:51236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..\\\\.env.bak"] [unique_id "al4lPBbAFPhDXvzP7SmsyQAB5gg"]
[Mon Jul 20 07:40:13.257054 2026] [security2:error] [pid 178071:tid 178312] [client 57.141.18.60:54358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lPBltgi7HBmNwzJNdxQAAbSA"]
[Mon Jul 20 07:40:13.289325 2026] [security2:error] [pid 204156:tid 204169] [remote 173.249.4.11:60059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lPRbAFPhDXvzP7Sms2wABmAw"]
[Mon Jul 20 07:40:13.326872 2026] [security2:error] [pid 178071:tid 178097] [remote 57.141.18.94:45448] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6219057"] [unique_id "al4lPRltgi7HBmNwzJNd5wAAUBg"]
[Mon Jul 20 07:40:13.495398 2026] [security2:error] [pid 204156:tid 204172] [remote 173.249.4.11:60059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lPRbAFPhDXvzP7Sms4wABvA8"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:40:13.596304 2026] [security2:error] [pid 178071:tid 178223] [client 14.225.17.146:50521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4lPRltgi7HBmNwzJNd7AAAABQ"], referer: http://sesamegreenbeans.com/www
[Mon Jul 20 07:40:13.718142 2026] [security2:error] [pid 204156:tid 204328] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lPRbAFPhDXvzP7Sms5QAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:13.790797 2026] [security2:error] [pid 204156:tid 204320] [client 36.93.152.155:61412] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lPRbAFPhDXvzP7Sms9AAAAbE"]
[Mon Jul 20 07:40:13.790886 2026] [security2:error] [pid 204156:tid 204320] [client 36.93.152.155:61412] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lPRbAFPhDXvzP7Sms9AAAAbE"]
[Mon Jul 20 07:40:13.812271 2026] [security2:error] [pid 178071:tid 178074] [remote 185.177.72.100:51240] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2f.env.bak"] [unique_id "al4lPRltgi7HBmNwzJNeAwAAKQE"]
[Mon Jul 20 07:40:13.829143 2026] [security2:error] [pid 204156:tid 204392] [client 88.126.177.187:2449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4lPRbAFPhDXvzP7Sms8AAAAfk"]
[Mon Jul 20 07:40:13.839307 2026] [security2:error] [pid 204156:tid 204322] [client 14.225.17.146:53969] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4lPRbAFPhDXvzP7Sms8gAAAbM"], referer: https://chestermonty.com/www
[Mon Jul 20 07:40:13.932460 2026] [security2:error] [pid 204156:tid 204329] [client 77.110.127.138:53741] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/"] [unique_id "al4lPRbAFPhDXvzP7Sms-AAAAbo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:13.945046 2026] [security2:error] [pid 178071:tid 178301] [client 57.141.18.101:56744] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lPRltgi7HBmNwzJNd5QAAYns"]
[Mon Jul 20 07:40:14.141725 2026] [security2:error] [pid 178071:tid 178307] [client 57.141.18.119:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lPRltgi7HBmNwzJNeCQAAAGg"]
[Mon Jul 20 07:40:14.435715 2026] [security2:error] [pid 178071:tid 178285] [client 65.111.23.13:40269] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lPhltgi7HBmNwzJNeHQAAAFI"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:14.618548 2026] [security2:error] [pid 204156:tid 204399] [client 14.225.17.146:53823] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4lPhbAFPhDXvzP7SmtEAAAAgA"], referer: https://sesamegreenbeans.com/www
[Mon Jul 20 07:40:14.670410 2026] [security2:error] [pid 204156:tid 204286] [client 37.52.210.45:61952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lPhbAFPhDXvzP7SmtHQAAAY8"]
[Mon Jul 20 07:40:14.670565 2026] [security2:error] [pid 204156:tid 204286] [client 37.52.210.45:61952] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lPhbAFPhDXvzP7SmtHQAAAY8"]
[Mon Jul 20 07:40:14.697429 2026] [security2:error] [pid 204156:tid 204185] [remote 185.177.72.100:51256] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\.bak|\\\\.bak\\\\.php)$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1260"] [id "390582"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that nclude .bak)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2f.env.bak"] [unique_id "al4lPhbAFPhDXvzP7SmtHgABtBw"]
[Mon Jul 20 07:40:14.969862 2026] [security2:error] [pid 204156:tid 204291] [client 57.141.18.95:46384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lPhbAFPhDXvzP7SmtCAABlBY"]
[Mon Jul 20 07:40:15.015113 2026] [security2:error] [pid 204156:tid 204312] [client 155.2.215.87:20529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lPhbAFPhDXvzP7SmtIwAAAak"]
[Mon Jul 20 07:40:15.187378 2026] [security2:error] [pid 178071:tid 178203] [client 116.193.128.26:61119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lPxltgi7HBmNwzJNeTQAAAAA"]
[Mon Jul 20 07:40:15.187553 2026] [security2:error] [pid 178071:tid 178203] [client 116.193.128.26:61119] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lPxltgi7HBmNwzJNeTQAAAAA"]
[Mon Jul 20 07:40:15.234862 2026] [security2:error] [pid 204156:tid 204407] [client 149.0.16.108:50991] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lPxbAFPhDXvzP7SmtRAAAAgg"]
[Mon Jul 20 07:40:15.234970 2026] [security2:error] [pid 204156:tid 204407] [client 149.0.16.108:50991] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lPxbAFPhDXvzP7SmtRAAAAgg"]
[Mon Jul 20 07:40:15.281249 2026] [security2:error] [pid 204156:tid 204340] [client 57.141.18.102:47128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lPhbAFPhDXvzP7SmtHAABxRs"]
[Mon Jul 20 07:40:15.455774 2026] [security2:error] [pid 204156:tid 204382] [client 103.139.191.61:65375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lPxbAFPhDXvzP7SmtbAAAAe8"]
[Mon Jul 20 07:40:15.455914 2026] [security2:error] [pid 204156:tid 204382] [client 103.139.191.61:65375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lPxbAFPhDXvzP7SmtbAAAAe8"]
[Mon Jul 20 07:40:15.496865 2026] [security2:error] [pid 204156:tid 204299] [client 65.20.204.68:44566] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4lPxbAFPhDXvzP7SmtRQAAAZw"], referer: https://www.sesamegreenbeans.com/
[Mon Jul 20 07:40:15.869212 2026] [security2:error] [pid 204156:tid 204327] [client 45.3.42.251:51745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lPxbAFPhDXvzP7SmtnwAAAbg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:16.007026 2026] [security2:error] [pid 204156:tid 204328] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lPxbAFPhDXvzP7SmtngAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:16.223636 2026] [security2:error] [pid 178071:tid 178230] [client 50.116.65.227:54208] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4lQBltgi7HBmNwzJNegQAAABs"]
[Mon Jul 20 07:40:16.238774 2026] [security2:error] [pid 178071:tid 178280] [client 50.116.65.227:34712] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/09/Takachiho-Feature-Image.jpg"] [unique_id "al4lQBltgi7HBmNwzJNehAAAAE0"]
[Mon Jul 20 07:40:16.273771 2026] [security2:error] [pid 178071:tid 178298] [client 57.141.18.113:36810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lPxltgi7HBmNwzJNeXwAAX08"]
[Mon Jul 20 07:40:16.294330 2026] [security2:error] [pid 204156:tid 204362] [client 14.225.17.146:51600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4lQBbAFPhDXvzP7SmtpwAAAds"], referer: http://mourgroup.com/www
[Mon Jul 20 07:40:16.471986 2026] [security2:error] [pid 178071:tid 178245] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lQBltgi7HBmNwzJNehQAAACo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:16.502291 2026] [security2:error] [pid 204156:tid 204258] [remote 185.177.72.100:51272] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\.env.old"] [unique_id "al4lQBbAFPhDXvzP7SmtsgABnmU"]
[Mon Jul 20 07:40:16.503798 2026] [security2:error] [pid 178071:tid 178305] [client 14.225.17.146:53236] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4lQBltgi7HBmNwzJNehgAAAGY"], referer: http://sarahsnyder.net/www
[Mon Jul 20 07:40:17.274535 2026] [security2:error] [pid 204156:tid 204368] [client 104.207.51.235:37317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lQRbAFPhDXvzP7Smt1AAAAeE"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:17.328809 2026] [security2:error] [pid 204156:tid 204377] [client 143.44.185.218:32367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lQRbAFPhDXvzP7Smt1gAAAeo"]
[Mon Jul 20 07:40:17.330070 2026] [security2:error] [pid 204156:tid 204377] [client 143.44.185.218:32367] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lQRbAFPhDXvzP7Smt1gAAAeo"]
[Mon Jul 20 07:40:17.354697 2026] [security2:error] [pid 204156:tid 204268] [remote 185.177.72.100:51282] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..\\\\.env.old"] [unique_id "al4lQRbAFPhDXvzP7Smt2AABsW8"]
[Mon Jul 20 07:40:17.461954 2026] [security2:error] [pid 204156:tid 204412] [client 154.192.233.184:61825] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lQRbAFPhDXvzP7Smt2gAAAg0"]
[Mon Jul 20 07:40:17.462096 2026] [security2:error] [pid 204156:tid 204412] [client 154.192.233.184:61825] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lQRbAFPhDXvzP7Smt2gAAAg0"]
[Mon Jul 20 07:40:17.484434 2026] [core:error] [pid 204156:tid 204269] [remote 51.195.39.149:21824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:40:17.484462 2026] [core:error] [pid 204156:tid 204269] [remote 51.195.39.149:21824] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:40:17.520370 2026] [security2:error] [pid 204156:tid 204314] [client 14.225.17.146:51697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4lQRbAFPhDXvzP7Smt2QAAAas"], referer: https://sarahsnyder.net/www
[Mon Jul 20 07:40:17.602930 2026] [security2:error] [pid 204156:tid 204271] [remote 51.195.39.149:22358] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "grecaalma.com"] [uri "/"] [unique_id "al4lQRbAFPhDXvzP7Smt4AABx3I"]
[Mon Jul 20 07:40:17.670694 2026] [security2:error] [pid 204156:tid 204272] [remote 38.242.157.30:46598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.157.242.38.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lQRbAFPhDXvzP7Smt4gABw3M"]
[Mon Jul 20 07:40:17.670951 2026] [security2:error] [pid 204156:tid 204338] [client 38.242.157.30:46598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lQRbAFPhDXvzP7Smt4gABw3M"]
[Mon Jul 20 07:40:17.816468 2026] [security2:error] [pid 178071:tid 178269] [client 146.75.222.185:23795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4lPxltgi7HBmNwzJNebwAAQh0"]
[Mon Jul 20 07:40:17.853763 2026] [security2:error] [pid 178071:tid 178269] [client 146.75.222.185:23795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4lPxltgi7HBmNwzJNebgAAQlc"]
[Mon Jul 20 07:40:17.871660 2026] [security2:error] [pid 204156:tid 204370] [client 14.225.17.146:51881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4lQRbAFPhDXvzP7Smt5gAAAeM"], referer: http://northbrookcpa.ca/www
[Mon Jul 20 07:40:18.066698 2026] [security2:error] [pid 204156:tid 204326] [client 103.176.215.66:55473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.215.176.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lQhbAFPhDXvzP7Smt7QAAAbc"]
[Mon Jul 20 07:40:18.067019 2026] [security2:error] [pid 204156:tid 204326] [client 103.176.215.66:55473] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mtredistricting.gov"] [uri "/xmlrpc.php"] [unique_id "al4lQhbAFPhDXvzP7Smt7QAAAbc"]
[Mon Jul 20 07:40:18.211948 2026] [security2:error] [pid 204156:tid 204276] [remote 185.177.72.100:33388] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2f.env.old"] [unique_id "al4lQhbAFPhDXvzP7Smt8gAB-3c"]
[Mon Jul 20 07:40:18.300619 2026] [security2:error] [pid 178071:tid 178303] [client 178.81.34.36:32966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4lQhltgi7HBmNwzJNe0wAAAGQ"]
[Mon Jul 20 07:40:18.382555 2026] [security2:error] [pid 204156:tid 204301] [client 57.141.18.8:53774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lQRbAFPhDXvzP7Smt5AABnnQ"]
[Mon Jul 20 07:40:18.607155 2026] [security2:error] [pid 204156:tid 204354] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lQhbAFPhDXvzP7Smt_gAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:18.811945 2026] [security2:error] [pid 204156:tid 204377] [client 77.110.127.138:53759] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/"] [unique_id "al4lQhbAFPhDXvzP7SmuBwAAAeo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:19.085434 2026] [security2:error] [pid 204156:tid 204282] [remote 185.177.72.100:33400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.old$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1263"] [id "390583"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .old)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2f.env.old"] [unique_id "al4lQxbAFPhDXvzP7SmuEQABwn0"]
[Mon Jul 20 07:40:19.095436 2026] [security2:error] [pid 204156:tid 204367] [client 179.127.84.238:51370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lQxbAFPhDXvzP7SmuEgAAAeA"]
[Mon Jul 20 07:40:19.095544 2026] [security2:error] [pid 204156:tid 204367] [client 179.127.84.238:51370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lQxbAFPhDXvzP7SmuEgAAAeA"]
[Mon Jul 20 07:40:19.141255 2026] [security2:error] [pid 204156:tid 204355] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lQhbAFPhDXvzP7SmuEAAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:19.249133 2026] [security2:error] [pid 204156:tid 204328] [client 14.225.17.146:51712] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4lQxbAFPhDXvzP7SmuFQAAAbk"], referer: http://effingweirdmuseums.com/www
[Mon Jul 20 07:40:19.395574 2026] [security2:error] [pid 178071:tid 178317] [client 57.141.18.32:61812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lQhltgi7HBmNwzJNe6gAAcmY"]
[Mon Jul 20 07:40:19.472122 2026] [security2:error] [pid 204156:tid 204360] [client 114.119.132.242:25769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.servicare-mx.safe-systems.net"] [uri "/robots.txt"] [unique_id "al4lQxbAFPhDXvzP7SmuIQAAAdk"], referer: https://www.servicare-mx.safe-systems.net/robots.txt
[Mon Jul 20 07:40:19.838569 2026] [security2:error] [pid 204156:tid 204289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lQxbAFPhDXvzP7SmuJgAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:19.920278 2026] [security2:error] [pid 178071:tid 178280] [client 57.141.18.22:64090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lQxltgi7HBmNwzJNfAQAATWE"]
[Mon Jul 20 07:40:19.985169 2026] [security2:error] [pid 204156:tid 204346] [client 14.225.17.146:55157] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4lQxbAFPhDXvzP7SmuPQAAAcs"], referer: http://lutheranphilosopher.com/www
[Mon Jul 20 07:40:20.195147 2026] [security2:error] [pid 204156:tid 204389] [client 57.141.18.75:36182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lQxbAFPhDXvzP7SmuHwAB9n8"]
[Mon Jul 20 07:40:20.254122 2026] [security2:error] [pid 204156:tid 204409] [client 14.225.17.146:51868] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmuSgAAAgo"], referer: http://detroitcsc.com/www
[Mon Jul 20 07:40:20.256864 2026] [security2:error] [pid 204156:tid 204290] [client 14.225.17.146:51897] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmuTAAAAZM"], referer: https://effingweirdmuseums.com/www
[Mon Jul 20 07:40:20.374723 2026] [security2:error] [pid 204156:tid 204363] [client 57.141.18.94:33398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lQxbAFPhDXvzP7SmuJAAB3AA"]
[Mon Jul 20 07:40:20.374851 2026] [security2:error] [pid 178071:tid 178251] [client 191.202.66.27:62793] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lRBltgi7HBmNwzJNfNQAAADA"]
[Mon Jul 20 07:40:20.374964 2026] [security2:error] [pid 178071:tid 178251] [client 191.202.66.27:62793] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lRBltgi7HBmNwzJNfNQAAADA"]
[Mon Jul 20 07:40:20.401434 2026] [proxy:error] [pid 204156:tid 204336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:20.401481 2026] [proxy_http:error] [pid 204156:tid 204336] [client 107.172.180.205:58288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:20.402182 2026] [proxy:error] [pid 204156:tid 204336] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:20.402208 2026] [proxy_http:error] [pid 204156:tid 204336] [client 107.172.180.205:58288] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:20.446217 2026] [security2:error] [pid 178071:tid 178113] [remote 188.166.241.141:38144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lRBltgi7HBmNwzJNfOAAAPyg"]
[Mon Jul 20 07:40:20.751224 2026] [security2:error] [pid 178071:tid 178237] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lRBltgi7HBmNwzJNfOgAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:20.793364 2026] [security2:error] [pid 204156:tid 204372] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmuZgAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:20.830946 2026] [security2:error] [pid 178071:tid 178118] [remote 188.166.241.141:38144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lRBltgi7HBmNwzJNfRQAAMi0"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:40:21.056891 2026] [security2:error] [pid 204156:tid 204346] [client 136.158.60.21:24376] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lRRbAFPhDXvzP7SmuewAAAcs"]
[Mon Jul 20 07:40:21.057062 2026] [security2:error] [pid 204156:tid 204346] [client 136.158.60.21:24376] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lRRbAFPhDXvzP7SmuewAAAcs"]
[Mon Jul 20 07:40:21.067936 2026] [security2:error] [pid 204156:tid 204322] [client 14.225.17.146:59974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmueQAAAbM"], referer: http://travelbyfire.com/www
[Mon Jul 20 07:40:21.109736 2026] [security2:error] [pid 204156:tid 204299] [client 57.141.18.82:58602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmuVQABnAk"]
[Mon Jul 20 07:40:21.195727 2026] [security2:error] [pid 204156:tid 204400] [client 50.116.65.227:10418] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lRRbAFPhDXvzP7SmuhQAAAgE"]
[Mon Jul 20 07:40:21.208937 2026] [security2:error] [pid 204156:tid 204361] [client 50.116.65.227:10424] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lRRbAFPhDXvzP7SmuhwAAAdo"]
[Mon Jul 20 07:40:21.289460 2026] [security2:error] [pid 178071:tid 178307] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lRRltgi7HBmNwzJNfVgAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:21.407523 2026] [security2:error] [pid 178071:tid 178249] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lRRltgi7HBmNwzJNfXQAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:21.567473 2026] [security2:error] [pid 204156:tid 204384] [client 57.141.18.74:39210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmudAAB8Qo"]
[Mon Jul 20 07:40:21.756253 2026] [security2:error] [pid 178071:tid 178232] [client 49.47.218.174:61514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lRRltgi7HBmNwzJNfgAAAAB0"]
[Mon Jul 20 07:40:21.756381 2026] [security2:error] [pid 178071:tid 178232] [client 49.47.218.174:61514] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lRRltgi7HBmNwzJNfgAAAAB0"]
[Mon Jul 20 07:40:21.839145 2026] [proxy:error] [pid 178071:tid 178250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:21.839192 2026] [proxy_http:error] [pid 178071:tid 178250] [client 107.172.180.205:58304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:21.840208 2026] [proxy:error] [pid 178071:tid 178250] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:40:21.840250 2026] [proxy_http:error] [pid 178071:tid 178250] [client 107.172.180.205:58304] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:40:21.993445 2026] [security2:error] [pid 178071:tid 178203] [client 14.225.17.146:59807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4lRRltgi7HBmNwzJNfjQAAAAA"], referer: https://travelbyfire.com/www
[Mon Jul 20 07:40:22.214790 2026] [security2:error] [pid 178071:tid 178330] [client 100.26.198.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cryptomeaning.com"] [uri "/index.php"] [unique_id "al4lRhltgi7HBmNwzJNflQAAAH8"]
[Mon Jul 20 07:40:22.245193 2026] [ssl:error] [pid 178071:tid 178258] [client 45.114.49.119:49500] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname savilerowtravel.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:40:22.322479 2026] [security2:error] [pid 204156:tid 204393] [client 57.141.18.67:23570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lRRbAFPhDXvzP7SmujwAB-hQ"]
[Mon Jul 20 07:40:22.348417 2026] [security2:error] [pid 204156:tid 204344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lRhbAFPhDXvzP7SmuoAAAAck"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:22.440405 2026] [security2:error] [pid 204156:tid 204398] [client 57.141.18.64:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lRhbAFPhDXvzP7SmuqAAAAf8"]
[Mon Jul 20 07:40:22.595973 2026] [security2:error] [pid 204156:tid 204287] [client 14.225.17.146:59590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4lRBbAFPhDXvzP7SmuYwAAAZA"], referer: http://www.justinagrayman.com/www
[Mon Jul 20 07:40:22.826337 2026] [security2:error] [pid 204156:tid 204394] [client 74.208.214.194:40636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lRhbAFPhDXvzP7SmuxAAAAfs"]
[Mon Jul 20 07:40:23.030283 2026] [security2:error] [pid 178071:tid 178260] [client 180.249.173.210:63789] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lRxltgi7HBmNwzJNfywAAADk"]
[Mon Jul 20 07:40:23.031095 2026] [security2:error] [pid 178071:tid 178260] [client 180.249.173.210:63789] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lRxltgi7HBmNwzJNfywAAADk"]
[Mon Jul 20 07:40:23.038631 2026] [security2:error] [pid 178071:tid 178290] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lRhltgi7HBmNwzJNfvQAAAFc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:23.401637 2026] [security2:error] [pid 204156:tid 204317] [client 57.141.18.120:52920] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lRhbAFPhDXvzP7SmuxgABrh4"]
[Mon Jul 20 07:40:23.658961 2026] [security2:error] [pid 178071:tid 178322] [client 14.225.17.146:53731] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4lRhltgi7HBmNwzJNfpQAAAHc"], referer: http://alaraycreative.com/www
[Mon Jul 20 07:40:23.861840 2026] [security2:error] [pid 204156:tid 204319] [client 57.141.18.69:21254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lRxbAFPhDXvzP7Smu1wABsCA"]
[Mon Jul 20 07:40:24.047835 2026] [ssl:error] [pid 178071:tid 178263] [client 45.114.49.119:49621] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname savilerowtravel.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:40:24.334222 2026] [security2:error] [pid 178071:tid 178311] [client 36.93.152.155:61928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lSBltgi7HBmNwzJNgAwAAAGw"]
[Mon Jul 20 07:40:24.334302 2026] [security2:error] [pid 178071:tid 178311] [client 36.93.152.155:61928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lSBltgi7HBmNwzJNgAwAAAGw"]
[Mon Jul 20 07:40:24.525112 2026] [security2:error] [pid 204156:tid 204388] [client 158.173.89.95:21131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lSBbAFPhDXvzP7SmvAwAAAfU"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:40:24.671668 2026] [security2:error] [pid 204156:tid 204402] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lSBbAFPhDXvzP7Smu_AAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:24.786177 2026] [security2:error] [pid 204156:tid 204370] [client 14.225.17.146:58725] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4lSBbAFPhDXvzP7Smu-gAAAeM"], referer: http://overloadcomedy.com/www
[Mon Jul 20 07:40:25.133803 2026] [security2:error] [pid 178071:tid 178287] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lSBltgi7HBmNwzJNgIQAAAFQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:25.175988 2026] [security2:error] [pid 204156:tid 204292] [client 216.244.66.233:50168] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "toddnielsen.com"] [uri "/strategy-execution-planning/"] [unique_id "al4lSRbAFPhDXvzP7SmvGQAAAZU"]
[Mon Jul 20 07:40:25.176122 2026] [security2:error] [pid 204156:tid 204292] [client 216.244.66.233:50168] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "toddnielsen.com"] [uri "/strategy-execution-planning/"] [unique_id "al4lSRbAFPhDXvzP7SmvGQAAAZU"]
[Mon Jul 20 07:40:25.209635 2026] [security2:error] [pid 204156:tid 204400] [client 13.232.231.177:57670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lSRbAFPhDXvzP7SmvHAAAAgE"]
[Mon Jul 20 07:40:25.269394 2026] [security2:error] [pid 204156:tid 204203] [remote 185.177.72.100:33434] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\.env.backup"] [unique_id "al4lSRbAFPhDXvzP7SmvHgAB4S4"]
[Mon Jul 20 07:40:25.282159 2026] [security2:error] [pid 178071:tid 178275] [client 37.52.210.45:62451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lSRltgi7HBmNwzJNgMwAAAEg"]
[Mon Jul 20 07:40:25.282285 2026] [security2:error] [pid 178071:tid 178275] [client 37.52.210.45:62451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lSRltgi7HBmNwzJNgMwAAAEg"]
[Mon Jul 20 07:40:25.356449 2026] [security2:error] [pid 204156:tid 204344] [client 66.249.74.12:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.tntcatholic.com"] [uri "/index.php"] [unique_id "al4lSRbAFPhDXvzP7SmvFwAAAck"]
[Mon Jul 20 07:40:25.416702 2026] [security2:error] [pid 204156:tid 204293] [client 103.106.165.44:50078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRbAFPhDXvzP7SmvIgAAAZY"]
[Mon Jul 20 07:40:25.416842 2026] [security2:error] [pid 204156:tid 204293] [client 103.106.165.44:50078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRbAFPhDXvzP7SmvIgAAAZY"]
[Mon Jul 20 07:40:25.511813 2026] [security2:error] [pid 204156:tid 204376] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4lSBbAFPhDXvzP7SmvDwAB6S0"], referer: http://ardhalwafaa.com/www
[Mon Jul 20 07:40:25.600422 2026] [security2:error] [pid 178071:tid 178294] [client 155.2.215.94:26529] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRltgi7HBmNwzJNgPAAAAFs"]
[Mon Jul 20 07:40:25.642890 2026] [security2:error] [pid 178071:tid 178226] [client 14.225.17.146:63490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4lSRltgi7HBmNwzJNgQgAAABc"], referer: http://blaizeaccountingservices.com/www
[Mon Jul 20 07:40:25.695529 2026] [security2:error] [pid 178071:tid 178265] [client 14.225.17.146:61281] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4lSRltgi7HBmNwzJNgRwAAAD4"]
[Mon Jul 20 07:40:25.780976 2026] [security2:error] [pid 204156:tid 204313] [client 14.225.17.146:61336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4lSBbAFPhDXvzP7Smu-QAAAao"], referer: http://eframiproperties.com/www
[Mon Jul 20 07:40:25.792877 2026] [security2:error] [pid 178071:tid 178218] [client 14.225.17.146:58560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4lSRltgi7HBmNwzJNgTAAAAA8"], referer: http://christiancountytrumpet.com/www
[Mon Jul 20 07:40:25.805448 2026] [security2:error] [pid 178071:tid 178276] [client 116.193.128.26:61693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRltgi7HBmNwzJNgUwAAAEk"]
[Mon Jul 20 07:40:25.805546 2026] [security2:error] [pid 178071:tid 178276] [client 116.193.128.26:61693] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRltgi7HBmNwzJNgUwAAAEk"]
[Mon Jul 20 07:40:25.873433 2026] [security2:error] [pid 204156:tid 204301] [client 149.0.16.108:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRbAFPhDXvzP7SmvOwAAAZ4"]
[Mon Jul 20 07:40:25.873603 2026] [security2:error] [pid 204156:tid 204301] [client 149.0.16.108:51517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lSRbAFPhDXvzP7SmvOwAAAZ4"]
[Mon Jul 20 07:40:25.974298 2026] [core:error] [pid 204156:tid 204354] [client 14.225.17.146:61082] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:40:25.974318 2026] [core:error] [pid 204156:tid 204354] [client 14.225.17.146:61082] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:40:26.039356 2026] [security2:error] [pid 204156:tid 204331] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lSRbAFPhDXvzP7SmvOgAAAbw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:26.100972 2026] [security2:error] [pid 178071:tid 178232] [client 14.225.17.146:61274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4lSBltgi7HBmNwzJNgEwAAAB0"], referer: http://colinkeyphotography.com/www
[Mon Jul 20 07:40:26.120121 2026] [security2:error] [pid 204156:tid 204319] [client 57.141.18.32:37372] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lSRbAFPhDXvzP7SmvKwABsDM"]
[Mon Jul 20 07:40:26.122680 2026] [security2:error] [pid 178071:tid 178084] [remote 185.177.72.100:33442] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..\\\\.env.backup"] [unique_id "al4lShltgi7HBmNwzJNgXgAAUgs"]
[Mon Jul 20 07:40:26.451956 2026] [security2:error] [pid 178071:tid 178247] [client 13.233.207.33:18626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lShltgi7HBmNwzJNgagAAACw"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:40:26.818756 2026] [security2:error] [pid 204156:tid 204291] [client 57.141.18.124:21332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lShbAFPhDXvzP7SmvTgABlDg"]
[Mon Jul 20 07:40:26.860176 2026] [security2:error] [pid 178071:tid 178207] [client 14.225.17.146:61328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4lSRltgi7HBmNwzJNgOAAAAAQ"], referer: http://guidehunting.com/www
[Mon Jul 20 07:40:26.980459 2026] [security2:error] [pid 204156:tid 204215] [remote 185.177.72.100:33450] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2f.env.backup"] [unique_id "al4lShbAFPhDXvzP7SmvZAABpDo"]
[Mon Jul 20 07:40:27.014711 2026] [security2:error] [pid 204156:tid 204353] [client 57.141.18.10:21442] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lShbAFPhDXvzP7SmvUwAB0jk"]
[Mon Jul 20 07:40:27.295492 2026] [security2:error] [pid 178071:tid 178260] [client 54.204.130.104:39756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.130.204.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lSxltgi7HBmNwzJNghgAAADk"]
[Mon Jul 20 07:40:27.310818 2026] [security2:error] [pid 178071:tid 178236] [client 77.110.127.138:53781] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/page/2/"] [unique_id "al4lSxltgi7HBmNwzJNgigAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:27.478379 2026] [security2:error] [pid 204156:tid 204362] [client 57.141.18.100:21890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lShbAFPhDXvzP7SmvYwAB2zw"]
[Mon Jul 20 07:40:27.497488 2026] [security2:error] [pid 204156:tid 204391] [client 103.139.191.61:49494] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lSxbAFPhDXvzP7SmvegAAAfg"]
[Mon Jul 20 07:40:27.497610 2026] [security2:error] [pid 204156:tid 204391] [client 103.139.191.61:49494] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lSxbAFPhDXvzP7SmvegAAAfg"]
[Mon Jul 20 07:40:27.657086 2026] [security2:error] [pid 178071:tid 178277] [client 98.85.250.161:35128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.250.85.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lSxltgi7HBmNwzJNgngAAAEo"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:40:27.775541 2026] [security2:error] [pid 204156:tid 204314] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lSxbAFPhDXvzP7SmveQAAAas"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:27.853729 2026] [security2:error] [pid 178071:tid 178317] [client 98.159.234.160:47837] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lSxltgi7HBmNwzJNgpgAAAHI"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:40:27.857835 2026] [security2:error] [pid 178071:tid 178152] [remote 185.177.72.100:33454] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.backup$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1279"] [id "390588"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access backup file (disable this rule if you require access to files that end with .backup)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2f.env.backup"] [unique_id "al4lSxltgi7HBmNwzJNgpwAAX04"]
[Mon Jul 20 07:40:27.952483 2026] [security2:error] [pid 204156:tid 204409] [client 14.225.17.146:51654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4lSxbAFPhDXvzP7SmvgwAAAgo"], referer: https://guidehunting.com/www
[Mon Jul 20 07:40:28.044478 2026] [security2:error] [pid 204156:tid 204325] [client 116.74.65.235:63012] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lTBbAFPhDXvzP7SmvjwAAAbY"]
[Mon Jul 20 07:40:28.044577 2026] [security2:error] [pid 204156:tid 204325] [client 116.74.65.235:63012] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lTBbAFPhDXvzP7SmvjwAAAbY"]
[Mon Jul 20 07:40:28.456549 2026] [security2:error] [pid 178071:tid 178205] [client 145.239.10.137:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.10.239.145.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "cloudcast.ca"] [uri "/eetu.php"] [unique_id "al4lTBltgi7HBmNwzJNgvQAAAAI"], referer: http://cloudcast.ca/eetu.php
[Mon Jul 20 07:40:28.547055 2026] [security2:error] [pid 204156:tid 204307] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvmgAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:28.615274 2026] [security2:error] [pid 178071:tid 178216] [client 57.141.18.84:62332] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lTBltgi7HBmNwzJNgsQAADW4"]
[Mon Jul 20 07:40:28.643820 2026] [security2:error] [pid 204156:tid 204225] [remote 91.142.222.105:38014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lTBbAFPhDXvzP7SmvrwAB5UQ"]
[Mon Jul 20 07:40:28.652977 2026] [security2:error] [pid 204156:tid 204331] [client 154.192.233.184:62186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lTBbAFPhDXvzP7SmvsAAAAbw"]
[Mon Jul 20 07:40:28.653121 2026] [security2:error] [pid 204156:tid 204331] [client 154.192.233.184:62186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lTBbAFPhDXvzP7SmvsAAAAbw"]
[Mon Jul 20 07:40:28.750782 2026] [security2:error] [pid 204156:tid 204310] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvpAAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:28.812611 2026] [autoindex:error] [pid 204156:tid 204298] [client 205.210.31.41:61960] AH01276: Cannot serve directory /home2/jopjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://jop.jiv.mybluehost.me/
[Mon Jul 20 07:40:28.844334 2026] [security2:error] [pid 204156:tid 204378] [client 2401:4900:1c5c:dc2:c013:bc3b:1851:faf6:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "origine.nz"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvkQAB6zs"]
[Mon Jul 20 07:40:28.880090 2026] [security2:error] [pid 204156:tid 204362] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvswAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:28.883499 2026] [fcgid:warn] [pid 204156:tid 204316] (70014)End of file found: [client 66.132.195.63:20564] mod_fcgid: can't get data from http client
[Mon Jul 20 07:40:28.890361 2026] [security2:error] [pid 204156:tid 204227] [remote 91.142.222.105:38014] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lTBbAFPhDXvzP7SmvvgAByUY"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:40:29.128482 2026] [security2:error] [pid 204156:tid 204336] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvxQAAAcE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:29.265256 2026] [security2:error] [pid 204156:tid 204345] [client 57.141.18.119:60724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvuAAByk4"]
[Mon Jul 20 07:40:29.329256 2026] [security2:error] [pid 178071:tid 178277] [client 65.111.26.25:27021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 25.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lTRltgi7HBmNwzJNg5gAAAEo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:29.337584 2026] [security2:error] [pid 204156:tid 204410] [client 57.141.18.79:38424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvwQACC0o"]
[Mon Jul 20 07:40:29.367426 2026] [security2:error] [pid 204156:tid 204409] [client 57.141.18.87:28430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lTBbAFPhDXvzP7SmvxgACCkM"]
[Mon Jul 20 07:40:29.449940 2026] [security2:error] [pid 204156:tid 204318] [client 46.251.192.73:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jndsupport.com"] [uri "/index.php"] [unique_id "al4lTRbAFPhDXvzP7SmvygAAAa8"]
[Mon Jul 20 07:40:29.528611 2026] [security2:error] [pid 204156:tid 204333] [client 13.233.207.33:18632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lTRbAFPhDXvzP7Smv3gAAAb4"]
[Mon Jul 20 07:40:29.584849 2026] [security2:error] [pid 204156:tid 204377] [client 179.127.84.238:51905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lTRbAFPhDXvzP7Smv4gAAAeo"]
[Mon Jul 20 07:40:29.584971 2026] [security2:error] [pid 204156:tid 204377] [client 179.127.84.238:51905] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lTRbAFPhDXvzP7Smv4gAAAeo"]
[Mon Jul 20 07:40:29.648219 2026] [security2:error] [pid 178071:tid 178196] [remote 84.247.172.23:58768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4lTRltgi7HBmNwzJNg7wAAWHo"]
[Mon Jul 20 07:40:29.718884 2026] [security2:error] [pid 204156:tid 204339] [client 57.141.18.43:42682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lTRbAFPhDXvzP7Smv1QABxFE"]
[Mon Jul 20 07:40:29.801490 2026] [security2:error] [pid 204156:tid 204403] [client 57.141.18.104:48206] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lTRbAFPhDXvzP7Smv1gACBFI"]
[Mon Jul 20 07:40:29.902301 2026] [security2:error] [pid 204156:tid 204385] [client 77.110.127.138:53823] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/page/2/"] [unique_id "al4lTRbAFPhDXvzP7Smv8wAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:29.931220 2026] [security2:error] [pid 204156:tid 204290] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lTRbAFPhDXvzP7Smv6gAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:29.941059 2026] [security2:error] [pid 178071:tid 178304] [client 45.3.45.231:24553] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lTRltgi7HBmNwzJNg-wAAAGU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:29.942579 2026] [security2:error] [pid 178071:tid 178256] [client 14.225.17.146:63697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4lTRltgi7HBmNwzJNg9wAAADU"], referer: http://swafforddetailing.com/www
[Mon Jul 20 07:40:30.027657 2026] [security2:error] [pid 204156:tid 204367] [client 143.44.185.218:34731] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lThbAFPhDXvzP7Smv-AAAAeA"]
[Mon Jul 20 07:40:30.027780 2026] [security2:error] [pid 204156:tid 204367] [client 143.44.185.218:34731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lThbAFPhDXvzP7Smv-AAAAeA"]
[Mon Jul 20 07:40:30.273648 2026] [security2:error] [pid 178071:tid 178157] [remote 84.247.172.23:58768] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "latiendadejorge.com.gt"] [uri "/wp-login.php"] [unique_id "al4lThltgi7HBmNwzJNhBQAAXlM"], referer: https://latiendadejorge.com.gt/wp-login.php
[Mon Jul 20 07:40:30.668683 2026] [authz_core:error] [pid 178071:tid 178306] [client 188.166.209.66:54263] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Mon Jul 20 07:40:30.729392 2026] [security2:error] [pid 178071:tid 178204] [client 43.205.139.3:41912] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lThltgi7HBmNwzJNhEQAAAAE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:40:30.850190 2026] [security2:error] [pid 204156:tid 204348] [client 14.224.227.113:56181] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4lThbAFPhDXvzP7SmwJwAAAc0"]
[Mon Jul 20 07:40:30.865157 2026] [security2:error] [pid 204156:tid 204329] [client 14.251.3.155:56180] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4lThbAFPhDXvzP7SmwKAAAAbo"]
[Mon Jul 20 07:40:30.872071 2026] [security2:error] [pid 178071:tid 178294] [client 14.224.227.113:56183] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4lThltgi7HBmNwzJNhGQAAAFs"]
[Mon Jul 20 07:40:30.912841 2026] [security2:error] [pid 204156:tid 204334] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lThbAFPhDXvzP7SmwGwAAAb8"]
[Mon Jul 20 07:40:31.000925 2026] [security2:error] [pid 178071:tid 178269] [client 191.202.66.27:63415] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lTxltgi7HBmNwzJNhIQAAAEI"]
[Mon Jul 20 07:40:31.001031 2026] [security2:error] [pid 178071:tid 178269] [client 191.202.66.27:63415] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lTxltgi7HBmNwzJNhIQAAAEI"]
[Mon Jul 20 07:40:31.004090 2026] [security2:error] [pid 204156:tid 204343] [client 14.225.17.146:64223] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4lThbAFPhDXvzP7SmwHgAAAcg"], referer: http://itdynamix.com/www
[Mon Jul 20 07:40:31.161403 2026] [security2:error] [pid 178071:tid 178321] [client 104.207.52.113:17937] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lTxltgi7HBmNwzJNhJAAAAHY"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:31.403029 2026] [security2:error] [pid 204156:tid 204303] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lTxbAFPhDXvzP7SmwNQAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:32.009120 2026] [security2:error] [pid 204156:tid 204264] [remote 57.141.18.30:21950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "securingmemories.com"] [uri "/index.php/asp-products-sitemap.xml"] [unique_id "al4lUBbAFPhDXvzP7SmwVQABm2s"]
[Mon Jul 20 07:40:32.022082 2026] [security2:error] [pid 204156:tid 204387] [client 14.225.17.146:59588] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4lTxbAFPhDXvzP7SmwTQAAAfQ"], referer: http://mazzucelli.com/www
[Mon Jul 20 07:40:32.025947 2026] [security2:error] [pid 178071:tid 178209] [client 14.225.17.146:59576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4lTxltgi7HBmNwzJNhQwAAAAY"], referer: https://itdynamix.com/www
[Mon Jul 20 07:40:32.222857 2026] [security2:error] [pid 178071:tid 178254] [client 49.47.218.174:52475] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lUBltgi7HBmNwzJNhUQAAADM"]
[Mon Jul 20 07:40:32.222974 2026] [security2:error] [pid 178071:tid 178254] [client 49.47.218.174:52475] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lUBltgi7HBmNwzJNhUQAAADM"]
[Mon Jul 20 07:40:32.279411 2026] [security2:error] [pid 204156:tid 204321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUBbAFPhDXvzP7SmwWAAAAbI"]
[Mon Jul 20 07:40:32.359654 2026] [security2:error] [pid 204156:tid 204268] [remote 57.141.18.71:59892] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 71.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4lUBbAFPhDXvzP7SmwYgACA28"]
[Mon Jul 20 07:40:32.380834 2026] [security2:error] [pid 204156:tid 204334] [client 57.141.18.122:53002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lUBbAFPhDXvzP7SmwVgABv20"]
[Mon Jul 20 07:40:32.392594 2026] [security2:error] [pid 204156:tid 204327] [client 136.158.60.21:25920] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lUBbAFPhDXvzP7SmwZAAAAbg"]
[Mon Jul 20 07:40:32.392764 2026] [security2:error] [pid 204156:tid 204327] [client 136.158.60.21:25920] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lUBbAFPhDXvzP7SmwZAAAAbg"]
[Mon Jul 20 07:40:32.579264 2026] [security2:error] [pid 204156:tid 204343] [client 104.207.50.0:38635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 0.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lUBbAFPhDXvzP7SmwcAAAAcg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:32.642324 2026] [security2:error] [pid 178071:tid 178227] [client 57.141.18.74:35972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lUBltgi7HBmNwzJNhUgAAGCk"]
[Mon Jul 20 07:40:32.830714 2026] [security2:error] [pid 204156:tid 204381] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUBbAFPhDXvzP7SmwcgAAAe4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:32.948399 2026] [security2:error] [pid 204156:tid 204356] [client 77.110.127.138:53797] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/page/2/"] [unique_id "al4lUBbAFPhDXvzP7SmwgQAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:32.977182 2026] [security2:error] [pid 204156:tid 204276] [remote 57.141.18.90:29210] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 90.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4lUBbAFPhDXvzP7SmwgwACBHc"]
[Mon Jul 20 07:40:33.021651 2026] [security2:error] [pid 178071:tid 178321] [client 14.225.17.146:63667] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4lUBltgi7HBmNwzJNhaQAAAHY"]
[Mon Jul 20 07:40:33.268575 2026] [security2:error] [pid 204156:tid 204399] [client 57.141.18.104:48210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lUBbAFPhDXvzP7SmwfwACAHU"]
[Mon Jul 20 07:40:33.576732 2026] [security2:error] [pid 178071:tid 178219] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lURltgi7HBmNwzJNhggAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:33.651386 2026] [security2:error] [pid 204156:tid 204158] [remote 8.217.108.67:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4lURbAFPhDXvzP7SmwsAAB9QE"]
[Mon Jul 20 07:40:33.717460 2026] [security2:error] [pid 178071:tid 178181] [remote 57.141.18.105:36568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5840380"] [unique_id "al4lURltgi7HBmNwzJNhiwAAP2s"]
[Mon Jul 20 07:40:33.840086 2026] [security2:error] [pid 204156:tid 204353] [client 180.249.173.210:64375] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lURbAFPhDXvzP7SmwyAAAAdI"]
[Mon Jul 20 07:40:33.840236 2026] [security2:error] [pid 204156:tid 204353] [client 180.249.173.210:64375] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lURbAFPhDXvzP7SmwyAAAAdI"]
[Mon Jul 20 07:40:33.850631 2026] [security2:error] [pid 204156:tid 204301] [client 14.225.17.146:63853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4lURbAFPhDXvzP7SmwrwAAAZ4"], referer: http://soloceos.com/www
[Mon Jul 20 07:40:34.019406 2026] [security2:error] [pid 204156:tid 204303] [client 57.141.18.0:24196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lURbAFPhDXvzP7SmwqgABoHw"]
[Mon Jul 20 07:40:34.177485 2026] [security2:error] [pid 204156:tid 204350] [client 50.116.65.227:43266] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lUhbAFPhDXvzP7Smw6QAAAc8"]
[Mon Jul 20 07:40:34.190652 2026] [security2:error] [pid 178071:tid 178214] [client 50.116.65.227:43272] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lUhltgi7HBmNwzJNhoAAAAAs"]
[Mon Jul 20 07:40:34.355099 2026] [security2:error] [pid 204156:tid 204302] [client 57.141.18.25:39832] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lURbAFPhDXvzP7SmwygABnw4"]
[Mon Jul 20 07:40:34.363131 2026] [security2:error] [pid 204156:tid 204410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUhbAFPhDXvzP7Smw4QAAAgs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:34.493370 2026] [security2:error] [pid 204156:tid 204336] [client 57.141.18.45:52106] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lURbAFPhDXvzP7Smw2AABwRY"]
[Mon Jul 20 07:40:34.589187 2026] [security2:error] [pid 178071:tid 178204] [client 14.225.17.146:62953] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4lUhltgi7HBmNwzJNhqQAAAAE"], referer: http://alrowad-hub.net/www
[Mon Jul 20 07:40:34.631718 2026] [security2:error] [pid 178071:tid 178301] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUhltgi7HBmNwzJNhpAAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:34.866231 2026] [security2:error] [pid 204156:tid 204329] [client 14.225.17.146:62997] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4lURbAFPhDXvzP7SmwhgAAAbo"]
[Mon Jul 20 07:40:34.968059 2026] [security2:error] [pid 204156:tid 204374] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUhbAFPhDXvzP7SmxCAAAAec"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:34.988125 2026] [security2:error] [pid 204156:tid 204194] [remote 8.217.108.67:49064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "petpawo.com"] [uri "/wp-login.php"] [unique_id "al4lUhbAFPhDXvzP7SmxDwABzyU"], referer: https://petpawo.com/wp-login.php
[Mon Jul 20 07:40:35.097603 2026] [security2:error] [pid 204156:tid 204312] [client 36.93.152.155:56790] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lUxbAFPhDXvzP7SmxEwAAAak"]
[Mon Jul 20 07:40:35.097711 2026] [security2:error] [pid 204156:tid 204312] [client 36.93.152.155:56790] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lUxbAFPhDXvzP7SmxEwAAAak"]
[Mon Jul 20 07:40:35.159620 2026] [security2:error] [pid 204156:tid 204321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUhbAFPhDXvzP7SmxCwAAAbI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:35.300599 2026] [security2:error] [pid 178071:tid 178251] [client 14.225.17.146:64118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4lUxltgi7HBmNwzJNh0wAAADA"], referer: http://claysharecon.com/www
[Mon Jul 20 07:40:35.333553 2026] [security2:error] [pid 204156:tid 204365] [client 49.37.242.14:52703] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lUxbAFPhDXvzP7SmxLAAAAd4"]
[Mon Jul 20 07:40:35.333708 2026] [security2:error] [pid 204156:tid 204365] [client 49.37.242.14:52703] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lUxbAFPhDXvzP7SmxLAAAAd4"]
[Mon Jul 20 07:40:35.336983 2026] [security2:error] [pid 178071:tid 178287] [client 103.106.165.44:50563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lUxltgi7HBmNwzJNh1wAAAFQ"]
[Mon Jul 20 07:40:35.337119 2026] [security2:error] [pid 178071:tid 178287] [client 103.106.165.44:50563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lUxltgi7HBmNwzJNh1wAAAFQ"]
[Mon Jul 20 07:40:35.478638 2026] [security2:error] [pid 204156:tid 204376] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUxbAFPhDXvzP7SmxIwAAAek"]
[Mon Jul 20 07:40:35.585256 2026] [security2:error] [pid 178071:tid 178263] [client 114.119.157.157:24785] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "phillipbloch.com"] [uri "/P175"] [unique_id "al4lUxltgi7HBmNwzJNh6AAAADw"], referer: http://phillipbloch.com/P180
[Mon Jul 20 07:40:35.625693 2026] [security2:error] [pid 204156:tid 204408] [client 121.229.156.76:56142] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.allergyantidotes.com"] [uri "/"] [unique_id "al4lUxbAFPhDXvzP7SmxNgAAAgk"]
[Mon Jul 20 07:40:35.625846 2026] [security2:error] [pid 204156:tid 204408] [client 121.229.156.76:56142] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.allergyantidotes.com"] [uri "/"] [unique_id "al4lUxbAFPhDXvzP7SmxNgAAAgk"]
[Mon Jul 20 07:40:35.700395 2026] [security2:error] [pid 204156:tid 204217] [remote 57.141.18.92:50368] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5433378"] [unique_id "al4lUxbAFPhDXvzP7SmxOgACADw"]
[Mon Jul 20 07:40:35.843435 2026] [security2:error] [pid 178071:tid 178328] [client 37.52.210.45:62951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lUxltgi7HBmNwzJNh7gAAAH0"]
[Mon Jul 20 07:40:35.843552 2026] [security2:error] [pid 178071:tid 178328] [client 37.52.210.45:62951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lUxltgi7HBmNwzJNh7gAAAH0"]
[Mon Jul 20 07:40:36.044919 2026] [security2:error] [pid 178071:tid 178207] [client 57.141.18.50:52054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lUxltgi7HBmNwzJNh3wAABHE"]
[Mon Jul 20 07:40:36.055303 2026] [security2:error] [pid 204156:tid 204307] [client 13.233.207.33:63334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lVBbAFPhDXvzP7SmxTgAAAaQ"]
[Mon Jul 20 07:40:36.104976 2026] [security2:error] [pid 204156:tid 204304] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUxbAFPhDXvzP7SmxQQAAAaE"]
[Mon Jul 20 07:40:36.141698 2026] [security2:error] [pid 204156:tid 204357] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lUxbAFPhDXvzP7SmxRQAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:36.197132 2026] [security2:error] [pid 204156:tid 204400] [client 155.2.215.77:24183] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lVBbAFPhDXvzP7SmxSgAAAgE"]
[Mon Jul 20 07:40:36.374157 2026] [security2:error] [pid 204156:tid 204306] [client 14.225.17.146:60644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4lVBbAFPhDXvzP7SmxTwAAAaM"], referer: http://grecruit.online/www
[Mon Jul 20 07:40:36.391937 2026] [security2:error] [pid 204156:tid 204361] [client 116.193.128.26:62261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lVBbAFPhDXvzP7SmxYAAAAdo"]
[Mon Jul 20 07:40:36.392597 2026] [security2:error] [pid 204156:tid 204361] [client 116.193.128.26:62261] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lVBbAFPhDXvzP7SmxYAAAAdo"]
[Mon Jul 20 07:40:36.436683 2026] [security2:error] [pid 178071:tid 178285] [client 57.141.18.27:41994] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lUxltgi7HBmNwzJNh8AAAUno"]
[Mon Jul 20 07:40:36.507961 2026] [security2:error] [pid 178071:tid 178312] [client 149.0.16.108:60546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lVBltgi7HBmNwzJNiEQAAAG0"]
[Mon Jul 20 07:40:36.508070 2026] [security2:error] [pid 178071:tid 178312] [client 149.0.16.108:60546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lVBltgi7HBmNwzJNiEQAAAG0"]
[Mon Jul 20 07:40:36.619856 2026] [security2:error] [pid 204156:tid 204323] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVBbAFPhDXvzP7SmxXgAAAbQ"]
[Mon Jul 20 07:40:36.719197 2026] [security2:error] [pid 204156:tid 204408] [client 74.208.214.194:33336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lVBbAFPhDXvzP7SmxaAAAAgk"]
[Mon Jul 20 07:40:36.780897 2026] [security2:error] [pid 204156:tid 204413] [client 14.225.17.146:61766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4lVBbAFPhDXvzP7SmxaQAAAg4"], referer: http://grndl.com/www
[Mon Jul 20 07:40:36.983571 2026] [security2:error] [pid 178071:tid 178284] [client 57.141.18.65:51602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lVBltgi7HBmNwzJNiEAAAUQw"]
[Mon Jul 20 07:40:37.045724 2026] [security2:error] [pid 204156:tid 204293] [client 57.141.18.87:62336] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lVBbAFPhDXvzP7SmxYwABlkQ"]
[Mon Jul 20 07:40:37.148961 2026] [security2:error] [pid 178071:tid 178224] [client 14.225.17.146:61848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4lVBltgi7HBmNwzJNiKAAAABU"], referer: http://wathenbartlett.co.uk/www
[Mon Jul 20 07:40:37.393732 2026] [security2:error] [pid 204156:tid 204351] [client 77.110.127.138:53859] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-crochet-top-3ply-linen-versions/uc7vrhfzxog4.php"] [unique_id "al4lVRbAFPhDXvzP7SmxhgAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:37.459859 2026] [security2:error] [pid 204156:tid 204336] [client 103.139.191.61:50010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lVRbAFPhDXvzP7SmxjgAAAcE"]
[Mon Jul 20 07:40:37.460006 2026] [security2:error] [pid 204156:tid 204336] [client 103.139.191.61:50010] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lVRbAFPhDXvzP7SmxjgAAAcE"]
[Mon Jul 20 07:40:37.517343 2026] [security2:error] [pid 204156:tid 204357] [client 77.110.127.138:53842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVRbAFPhDXvzP7SmxfAAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:37.561601 2026] [security2:error] [pid 204156:tid 204400] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVRbAFPhDXvzP7SmxgwAAAgE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:37.934816 2026] [security2:error] [pid 204156:tid 204290] [client 43.205.139.3:37380] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lVRbAFPhDXvzP7SmxowAAAZM"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:40:37.946765 2026] [security2:error] [pid 204156:tid 204235] [remote 57.141.18.74:27728] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3064779"] [unique_id "al4lVRbAFPhDXvzP7SmxogAB9E4"]
[Mon Jul 20 07:40:38.044048 2026] [security2:error] [pid 204156:tid 204410] [client 14.225.17.146:64120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4lVRbAFPhDXvzP7SmxpQAAAgs"], referer: https://wathenbartlett.co.uk/www
[Mon Jul 20 07:40:38.220295 2026] [security2:error] [pid 204156:tid 204383] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVRbAFPhDXvzP7SmxjQAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:38.225541 2026] [security2:error] [pid 178071:tid 178280] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVRltgi7HBmNwzJNiQAAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:38.257932 2026] [security2:error] [pid 204156:tid 204316] [client 57.141.18.10:26108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lVRbAFPhDXvzP7SmxlQABrUg"]
[Mon Jul 20 07:40:38.323351 2026] [security2:error] [pid 178071:tid 178302] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4lVhltgi7HBmNwzJNiZQAAY18"], referer: http://aleishapenny.ca/www
[Mon Jul 20 07:40:38.366586 2026] [security2:error] [pid 204156:tid 204313] [client 154.192.233.184:60580] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lVhbAFPhDXvzP7SmxswAAAao"]
[Mon Jul 20 07:40:38.366710 2026] [security2:error] [pid 204156:tid 204313] [client 154.192.233.184:60580] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lVhbAFPhDXvzP7SmxswAAAao"]
[Mon Jul 20 07:40:38.569014 2026] [security2:error] [pid 178071:tid 178284] [client 202.141.11.99:22100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4lVhltgi7HBmNwzJNihAAAAFE"]
[Mon Jul 20 07:40:38.569540 2026] [security2:error] [pid 178071:tid 178284] [client 202.141.11.99:22100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4lVhltgi7HBmNwzJNihAAAAFE"]
[Mon Jul 20 07:40:38.620409 2026] [security2:error] [pid 178071:tid 178203] [client 57.141.18.11:55766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lVhltgi7HBmNwzJNiYgAAADw"]
[Mon Jul 20 07:40:38.753485 2026] [security2:error] [pid 178071:tid 178329] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVhltgi7HBmNwzJNifwAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:38.834966 2026] [authz_core:error] [pid 204156:tid 204403] [client 188.166.209.66:51491] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/sitemaps/providers/error_log, referer: binance.com
[Mon Jul 20 07:40:38.914000 2026] [security2:error] [pid 204156:tid 204405] [client 77.110.127.138:53869] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/corner-to-corner/feed/87evz2mvusgt.php"] [unique_id "al4lVhbAFPhDXvzP7SmxyAAAAgY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:38.964827 2026] [security2:error] [pid 204156:tid 204243] [remote 57.141.18.81:34530] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4lVhbAFPhDXvzP7Smx0gAB21Y"]
[Mon Jul 20 07:40:38.966791 2026] [security2:error] [pid 204156:tid 204374] [client 14.225.17.146:63177] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4lVhbAFPhDXvzP7SmxuAAAAec"], referer: http://floorsourcestock.com/www
[Mon Jul 20 07:40:39.007179 2026] [security2:error] [pid 178071:tid 178301] [client 77.110.127.138:53853] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVhltgi7HBmNwzJNilAAAAGI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:39.065378 2026] [security2:error] [pid 204156:tid 204337] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVhbAFPhDXvzP7SmxwQAAAcI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:39.188165 2026] [security2:error] [pid 204156:tid 204339] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4lVhbAFPhDXvzP7Smx0wABxFM"], referer: https://aleishapenny.ca/www
[Mon Jul 20 07:40:39.190994 2026] [security2:error] [pid 178071:tid 178253] [client 57.141.18.20:41166] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lVhltgi7HBmNwzJNiiQAAMhY"]
[Mon Jul 20 07:40:39.219051 2026] [security2:error] [pid 204156:tid 204325] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lVhbAFPhDXvzP7SmxzwAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:39.329443 2026] [security2:error] [pid 178071:tid 178281] [client 14.224.227.113:56247] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4lVxltgi7HBmNwzJNiqgAAAE4"]
[Mon Jul 20 07:40:39.337775 2026] [security2:error] [pid 204156:tid 204306] [client 14.251.3.155:56246] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4lVxbAFPhDXvzP7Smx7gAAAaM"]
[Mon Jul 20 07:40:39.384443 2026] [security2:error] [pid 204156:tid 204364] [client 14.251.3.155:56248] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4lVxbAFPhDXvzP7Smx8wAAAd0"]
[Mon Jul 20 07:40:39.391476 2026] [security2:error] [pid 178071:tid 178122] [remote 91.142.222.105:34932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4lVxltgi7HBmNwzJNirwAAQzE"]
[Mon Jul 20 07:40:39.603170 2026] [security2:error] [pid 204156:tid 204394] [client 104.207.60.111:12699] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.60.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lVxbAFPhDXvzP7Smx-QAAAfs"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:39.617364 2026] [security2:error] [pid 204156:tid 204305] [client 14.225.17.146:62449] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4lVBbAFPhDXvzP7SmxXwAAAaI"], referer: http://areitoproducciones.com/www
[Mon Jul 20 07:40:39.667980 2026] [security2:error] [pid 178071:tid 178201] [remote 91.142.222.105:34932] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "michiganhomecaregroup.com"] [uri "/wp-login.php"] [unique_id "al4lVxltgi7HBmNwzJNivQAAI38"], referer: https://michiganhomecaregroup.com/wp-login.php
[Mon Jul 20 07:40:39.871471 2026] [security2:error] [pid 204156:tid 204295] [client 114.119.135.72:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "seedsofchangefilm.com"] [uri "/robots.txt"] [unique_id "al4lVxbAFPhDXvzP7SmyCgAAAZg"], referer: http://seedsofchangefilm.com/robots.txt
[Mon Jul 20 07:40:40.078940 2026] [security2:error] [pid 178071:tid 178216] [client 179.127.84.238:52432] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lWBltgi7HBmNwzJNi0QAAAA0"]
[Mon Jul 20 07:40:40.079150 2026] [security2:error] [pid 178071:tid 178216] [client 179.127.84.238:52432] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lWBltgi7HBmNwzJNi0QAAAA0"]
[Mon Jul 20 07:40:40.130588 2026] [security2:error] [pid 178071:tid 178242] [client 14.225.17.146:51520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4lVxltgi7HBmNwzJNiygAAACc"], referer: http://thesoloceos.com/www
[Mon Jul 20 07:40:40.197826 2026] [security2:error] [pid 204156:tid 204369] [client 104.207.57.95:49931] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.57.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lWBbAFPhDXvzP7SmyGQAAAeI"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:40:40.249482 2026] [security2:error] [pid 204156:tid 204313] [client 77.110.127.138:53829] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/o45upy876d4i.php"] [unique_id "al4lWBbAFPhDXvzP7SmyHAAAAao"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:40.472717 2026] [security2:error] [pid 204156:tid 204288] [client 77.110.127.138:53858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBbAFPhDXvzP7SmyHwAAAZE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:40.474526 2026] [security2:error] [pid 178071:tid 178309] [client 57.141.18.71:62510] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lVxltgi7HBmNwzJNiyQAAakk"]
[Mon Jul 20 07:40:40.474553 2026] [security2:error] [pid 204156:tid 204262] [remote 173.212.252.15:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4lWBbAFPhDXvzP7SmyLgABwWk"]
[Mon Jul 20 07:40:40.593183 2026] [security2:error] [pid 178071:tid 178293] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi4wAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:40.595394 2026] [security2:error] [pid 178071:tid 178236] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi5wAAACE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:40.632743 2026] [security2:error] [pid 178071:tid 178323] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi7AAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:40.656943 2026] [security2:error] [pid 204156:tid 204248] [remote 173.212.252.15:38658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.shantimethod.com"] [uri "/wp-login.php"] [unique_id "al4lWBbAFPhDXvzP7SmyNAABpls"], referer: https://mail.shantimethod.com/wp-login.php
[Mon Jul 20 07:40:40.660009 2026] [security2:error] [pid 204156:tid 204399] [client 77.110.127.138:53866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-patterns/feed/yxc3kxpv1jgs.php"] [unique_id "al4lWBbAFPhDXvzP7SmyNgAAAgA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:40.701847 2026] [security2:error] [pid 178071:tid 178285] [client 57.141.18.75:22362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi2AAAUjc"]
[Mon Jul 20 07:40:40.750192 2026] [security2:error] [pid 178071:tid 178244] [client 14.225.17.146:63044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4lVxltgi7HBmNwzJNixgAAACk"]
[Mon Jul 20 07:40:40.927444 2026] [security2:error] [pid 204156:tid 204162] [remote 185.177.72.100:52362] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fsendgrid/.env"] [unique_id "al4lWBbAFPhDXvzP7SmyaAABoAU"]
[Mon Jul 20 07:40:40.998733 2026] [security2:error] [pid 178071:tid 178079] [remote 173.249.4.11:18270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4lWBltgi7HBmNwzJNjCgAAbwY"]
[Mon Jul 20 07:40:41.059931 2026] [security2:error] [pid 178071:tid 178207] [client 57.141.18.87:62340] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi8gAABAE"]
[Mon Jul 20 07:40:41.129570 2026] [security2:error] [pid 204156:tid 204301] [client 14.225.17.146:61543] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4lWBbAFPhDXvzP7SmyaQAAAZ4"], referer: https://thesoloceos.com/www
[Mon Jul 20 07:40:41.213469 2026] [security2:error] [pid 178071:tid 178120] [remote 173.249.4.11:18270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4lWRltgi7HBmNwzJNjEwAAWC8"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:40:41.231214 2026] [security2:error] [pid 204156:tid 204372] [client 77.110.127.138:53867] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBbAFPhDXvzP7SmyOAAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:41.262627 2026] [security2:error] [pid 204156:tid 204302] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBbAFPhDXvzP7SmyOwAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:41.264731 2026] [security2:error] [pid 178071:tid 178324] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi-gAAAHk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:41.281302 2026] [security2:error] [pid 178071:tid 178215] [client 14.225.17.146:63048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4lWBltgi7HBmNwzJNi1QAAAAw"], referer: http://ancestralidadytrance.space/www
[Mon Jul 20 07:40:41.514757 2026] [security2:error] [pid 204156:tid 204389] [client 77.110.127.138:53858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-techniques/r3cj8ycm2e0e.php"] [unique_id "al4lWRbAFPhDXvzP7SmylwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:41.649202 2026] [security2:error] [pid 204156:tid 204328] [client 191.202.66.27:64086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lWRbAFPhDXvzP7SmypQAAAbk"]
[Mon Jul 20 07:40:41.649323 2026] [security2:error] [pid 204156:tid 204328] [client 191.202.66.27:64086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lWRbAFPhDXvzP7SmypQAAAbk"]
[Mon Jul 20 07:40:41.770892 2026] [security2:error] [pid 204156:tid 204171] [remote 185.177.72.100:52376] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fsendgrid%2f.env"] [unique_id "al4lWRbAFPhDXvzP7SmyrAABlw4"]
[Mon Jul 20 07:40:41.907595 2026] [security2:error] [pid 204156:tid 204177] [remote 57.141.18.33:57222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4lWRbAFPhDXvzP7SmytAAB5RQ"]
[Mon Jul 20 07:40:42.252176 2026] [security2:error] [pid 204156:tid 204289] [client 143.44.185.218:37288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lWhbAFPhDXvzP7SmyxgAAAZI"]
[Mon Jul 20 07:40:42.252314 2026] [security2:error] [pid 204156:tid 204289] [client 143.44.185.218:37288] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lWhbAFPhDXvzP7SmyxgAAAZI"]
[Mon Jul 20 07:40:42.368529 2026] [security2:error] [pid 204156:tid 204299] [client 50.116.65.227:18958] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4lWRbAFPhDXvzP7SmypwAAAZw"]
[Mon Jul 20 07:40:42.463543 2026] [security2:error] [pid 204156:tid 204368] [client 136.158.60.21:27417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lWhbAFPhDXvzP7Smy0AAAAeE"]
[Mon Jul 20 07:40:42.463727 2026] [security2:error] [pid 204156:tid 204368] [client 136.158.60.21:27417] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lWhbAFPhDXvzP7Smy0AAAAeE"]
[Mon Jul 20 07:40:42.553246 2026] [security2:error] [pid 178071:tid 178304] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWRltgi7HBmNwzJNjHwAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:42.617629 2026] [security2:error] [pid 204156:tid 204305] [client 14.225.17.146:51085] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4lWhbAFPhDXvzP7SmyzwAAAaI"], referer: http://adirondackengineering.com/www
[Mon Jul 20 07:40:42.673443 2026] [security2:error] [pid 204156:tid 204325] [client 77.110.127.138:53855] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWRbAFPhDXvzP7SmymgAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:42.675099 2026] [security2:error] [pid 204156:tid 204353] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWRbAFPhDXvzP7SmyoAAAAdI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:42.709455 2026] [security2:error] [pid 204156:tid 204350] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWRbAFPhDXvzP7SmysgAAAc8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:42.727110 2026] [security2:error] [pid 178071:tid 178237] [client 49.47.218.174:53022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lWhltgi7HBmNwzJNjUgAAACI"]
[Mon Jul 20 07:40:42.727247 2026] [security2:error] [pid 178071:tid 178237] [client 49.47.218.174:53022] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lWhltgi7HBmNwzJNjUgAAACI"]
[Mon Jul 20 07:40:43.059357 2026] [security2:error] [pid 204156:tid 204370] [client 50.116.65.227:18960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4lWhbAFPhDXvzP7SmyzQAAAeM"]
[Mon Jul 20 07:40:43.084455 2026] [authz_core:error] [pid 204156:tid 204404] [client 188.166.209.66:51488] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/widgets/error_log, referer: binance.com
[Mon Jul 20 07:40:43.255712 2026] [security2:error] [pid 204156:tid 204328] [client 57.141.18.99:24972] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lWhbAFPhDXvzP7Smy1QABuSc"]
[Mon Jul 20 07:40:43.413496 2026] [security2:error] [pid 204156:tid 204202] [remote 57.141.18.17:63228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5868182"] [unique_id "al4lWxbAFPhDXvzP7Smy7wABki0"]
[Mon Jul 20 07:40:43.455033 2026] [security2:error] [pid 178071:tid 178212] [client 45.3.42.99:58841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lWxltgi7HBmNwzJNjdwAAAAk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:40:43.469041 2026] [security2:error] [pid 178071:tid 178219] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWhltgi7HBmNwzJNjXwAAABA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:43.544880 2026] [security2:error] [pid 204156:tid 204405] [client 116.179.37.217:60764] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 217.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.drawingthedog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lWxbAFPhDXvzP7Smy9wAAAgY"], referer: https://www.drawingthedog.com/product-category/wall-art-collections/appreciation-society/page/11/
[Mon Jul 20 07:40:43.679699 2026] [security2:error] [pid 204156:tid 204376] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lWxbAFPhDXvzP7Smy8wAAAek"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:43.737626 2026] [security2:error] [pid 178071:tid 178303] [client 57.141.18.123:55210] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lWxltgi7HBmNwzJNjbAAAZA8"]
[Mon Jul 20 07:40:44.148776 2026] [security2:error] [pid 204156:tid 204212] [remote 192.241.143.148:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4lXBbAFPhDXvzP7SmzEAABlTc"]
[Mon Jul 20 07:40:44.278321 2026] [security2:error] [pid 204156:tid 204401] [client 116.179.37.223:47020] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.drawingthedog.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lXBbAFPhDXvzP7SmzFAAAAgI"], referer: https://www.drawingthedog.com/product-category/wall-art-collections/appreciation-society/page/11/
[Mon Jul 20 07:40:44.287377 2026] [security2:error] [pid 178071:tid 178142] [remote 128.199.71.102:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.71.199.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4lXBltgi7HBmNwzJNjmgAAYEU"]
[Mon Jul 20 07:40:44.291434 2026] [security2:error] [pid 204156:tid 204361] [client 180.249.173.210:64887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lXBbAFPhDXvzP7SmzFwAAAdo"]
[Mon Jul 20 07:40:44.292308 2026] [security2:error] [pid 204156:tid 204361] [client 180.249.173.210:64887] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lXBbAFPhDXvzP7SmzFwAAAdo"]
[Mon Jul 20 07:40:44.309434 2026] [security2:error] [pid 204156:tid 204211] [remote 192.241.143.148:49084] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "superiorcopywriting.com"] [uri "/wp-login.php"] [unique_id "al4lXBbAFPhDXvzP7SmzGAAB4jY"], referer: https://superiorcopywriting.com/wp-login.php
[Mon Jul 20 07:40:44.752727 2026] [security2:error] [pid 178071:tid 178111] [remote 128.199.71.102:53916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 102.71.199.128.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "musichaven.info"] [uri "/wp-login.php"] [unique_id "al4lXBltgi7HBmNwzJNjtQAAICY"], referer: https://musichaven.info/wp-login.php
[Mon Jul 20 07:40:44.890829 2026] [security2:error] [pid 204156:tid 204331] [client 57.141.18.72:21794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lXBbAFPhDXvzP7SmzDwABvDM"]
[Mon Jul 20 07:40:45.124427 2026] [autoindex:error] [pid 204156:tid 204385] [client 167.86.82.167:51680] AH01276: Cannot serve directory /home1/obertpie/public_html/.well-known/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:40:45.290389 2026] [security2:error] [pid 178071:tid 178253] [client 57.141.18.6:46892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lXBltgi7HBmNwzJNjqwAAMlk"]
[Mon Jul 20 07:40:45.383575 2026] [security2:error] [pid 204156:tid 204345] [client 36.93.152.155:57325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lXRbAFPhDXvzP7SmzTAAAAco"]
[Mon Jul 20 07:40:45.383697 2026] [security2:error] [pid 204156:tid 204345] [client 36.93.152.155:57325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lXRbAFPhDXvzP7SmzTAAAAco"]
[Mon Jul 20 07:40:45.552339 2026] [security2:error] [pid 178071:tid 178162] [remote 192.241.143.148:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lXRltgi7HBmNwzJNj3QAAc1g"]
[Mon Jul 20 07:40:45.565947 2026] [security2:error] [pid 178071:tid 178147] [remote 185.177.72.100:52404] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2faws/.env"] [unique_id "al4lXRltgi7HBmNwzJNj4AAAFkk"]
[Mon Jul 20 07:40:45.609486 2026] [security2:error] [pid 204156:tid 204384] [client 74.7.244.61:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sbinframx.com"] [uri "/index.php"] [unique_id "al4lXBbAFPhDXvzP7SmzHQAAAfE"]
[Mon Jul 20 07:40:45.611108 2026] [security2:error] [pid 178071:tid 178322] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXRltgi7HBmNwzJNjxAAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:45.611417 2026] [security2:error] [pid 178071:tid 178208] [client 74.7.244.61:53318] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "sbinframx.com"] [uri "/robots.txt"] [unique_id "al4lXBltgi7HBmNwzJNjoQAABRo"]
[Mon Jul 20 07:40:45.736594 2026] [security2:error] [pid 178071:tid 178129] [remote 192.241.143.148:49096] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lXRltgi7HBmNwzJNj5wAAGTg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:40:45.760860 2026] [security2:error] [pid 204156:tid 204367] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXRbAFPhDXvzP7SmzUAAAAeA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:45.791364 2026] [security2:error] [pid 204156:tid 204297] [client 50.116.65.227:19036] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lXRbAFPhDXvzP7SmzZwAAAZo"]
[Mon Jul 20 07:40:45.805854 2026] [security2:error] [pid 204156:tid 204350] [client 50.116.65.227:19044] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lXRbAFPhDXvzP7SmzaQAAAc8"]
[Mon Jul 20 07:40:45.824913 2026] [security2:error] [pid 204156:tid 204370] [client 103.106.165.44:51049] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lXRbAFPhDXvzP7SmzbAAAAeM"]
[Mon Jul 20 07:40:45.825050 2026] [security2:error] [pid 204156:tid 204370] [client 103.106.165.44:51049] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lXRbAFPhDXvzP7SmzbAAAAeM"]
[Mon Jul 20 07:40:45.870993 2026] [security2:error] [pid 204156:tid 204221] [remote 47.86.33.52:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4lXRbAFPhDXvzP7SmzbgABkUA"]
[Mon Jul 20 07:40:46.195727 2026] [security2:error] [pid 204156:tid 204383] [client 14.225.17.146:51568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4lXhbAFPhDXvzP7SmzfAAAAfA"], referer: http://iagdevelopments.com/www
[Mon Jul 20 07:40:46.306443 2026] [security2:error] [pid 204156:tid 204395] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXRbAFPhDXvzP7SmzcAAAAfw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:46.419738 2026] [security2:error] [pid 178071:tid 178323] [client 14.225.17.146:51521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4lXhltgi7HBmNwzJNj-wAAAHg"], referer: http://fluidtemple.org/www
[Mon Jul 20 07:40:46.434419 2026] [security2:error] [pid 204156:tid 204227] [remote 185.177.72.100:52412] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2faws%2f.env"] [unique_id "al4lXhbAFPhDXvzP7SmzjwAB8UY"]
[Mon Jul 20 07:40:46.465108 2026] [security2:error] [pid 204156:tid 204235] [remote 47.86.33.52:7592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4lXhbAFPhDXvzP7SmzkgABqk4"], referer: https://talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:40:46.479551 2026] [security2:error] [pid 204156:tid 204339] [client 37.52.210.45:63446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lXhbAFPhDXvzP7SmzlQAAAcQ"]
[Mon Jul 20 07:40:46.479708 2026] [security2:error] [pid 204156:tid 204339] [client 37.52.210.45:63446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lXhbAFPhDXvzP7SmzlQAAAcQ"]
[Mon Jul 20 07:40:46.785089 2026] [security2:error] [pid 204156:tid 204289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXhbAFPhDXvzP7SmzlwAAAZI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:46.807579 2026] [security2:error] [pid 204156:tid 204367] [client 142.111.152.173:52165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lXhbAFPhDXvzP7SmzmAAAAeA"]
[Mon Jul 20 07:40:46.998079 2026] [security2:error] [pid 204156:tid 204297] [client 116.193.128.26:62832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lXhbAFPhDXvzP7SmzrQAAAZo"]
[Mon Jul 20 07:40:46.998786 2026] [security2:error] [pid 204156:tid 204297] [client 116.193.128.26:62832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4lXhbAFPhDXvzP7SmzrQAAAZo"]
[Mon Jul 20 07:40:47.132235 2026] [security2:error] [pid 178071:tid 178269] [client 149.0.16.108:61064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lXxltgi7HBmNwzJNkHwAAAEI"]
[Mon Jul 20 07:40:47.132350 2026] [security2:error] [pid 178071:tid 178269] [client 149.0.16.108:61064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lXxltgi7HBmNwzJNkHwAAAEI"]
[Mon Jul 20 07:40:47.301090 2026] [security2:error] [pid 178071:tid 178127] [remote 45.90.123.233:45234] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4lXxltgi7HBmNwzJNkKgAAZTY"]
[Mon Jul 20 07:40:47.301283 2026] [security2:error] [pid 178071:tid 178304] [client 45.90.123.233:45234] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "dasmarque.com"] [uri "/xmlrpc.php"] [unique_id "al4lXxltgi7HBmNwzJNkKgAAZTY"]
[Mon Jul 20 07:40:47.319021 2026] [security2:error] [pid 178071:tid 178329] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXxltgi7HBmNwzJNkGAAAAH4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:47.334454 2026] [security2:error] [pid 204156:tid 204379] [client 158.173.166.181:53807] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lXxbAFPhDXvzP7SmztwAAAew"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:40:47.386598 2026] [security2:error] [pid 204156:tid 204326] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXxbAFPhDXvzP7SmzsQAAAbc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:47.417335 2026] [security2:error] [pid 204156:tid 204299] [client 14.225.17.146:54936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4lXxbAFPhDXvzP7SmztgAAAZw"], referer: https://iagdevelopments.com/www
[Mon Jul 20 07:40:47.511922 2026] [security2:error] [pid 178071:tid 178222] [client 78.190.132.14:59108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.adambergeron.com"] [uri "/index.php"] [unique_id "al4lXhltgi7HBmNwzJNj9gAAE3E"]
[Mon Jul 20 07:40:47.698308 2026] [security2:error] [pid 204156:tid 204339] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXxbAFPhDXvzP7SmzwAAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:47.799479 2026] [security2:error] [pid 178071:tid 178260] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lXxltgi7HBmNwzJNkMgAAADk"]
[Mon Jul 20 07:40:48.248085 2026] [security2:error] [pid 204156:tid 204347] [client 49.37.242.14:53248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lYBbAFPhDXvzP7Smz7AAAAcw"]
[Mon Jul 20 07:40:48.248206 2026] [security2:error] [pid 204156:tid 204347] [client 49.37.242.14:53248] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lYBbAFPhDXvzP7Smz7AAAAcw"]
[Mon Jul 20 07:40:48.274459 2026] [security2:error] [pid 204156:tid 204301] [client 57.141.18.9:46966] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lXxbAFPhDXvzP7SmzvQABnlk"]
[Mon Jul 20 07:40:48.390467 2026] [security2:error] [pid 204156:tid 204350] [client 57.141.18.13:55692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lXxbAFPhDXvzP7SmzxAABz08"]
[Mon Jul 20 07:40:48.392312 2026] [security2:error] [pid 178071:tid 178264] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYBltgi7HBmNwzJNkQQAAAD0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:48.444552 2026] [security2:error] [pid 204156:tid 204400] [client 103.139.191.61:50504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lYBbAFPhDXvzP7Smz-AAAAgE"]
[Mon Jul 20 07:40:48.444720 2026] [security2:error] [pid 204156:tid 204400] [client 103.139.191.61:50504] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lYBbAFPhDXvzP7Smz-AAAAgE"]
[Mon Jul 20 07:40:48.516275 2026] [security2:error] [pid 178071:tid 178239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYBltgi7HBmNwzJNkSwAAACQ"]
[Mon Jul 20 07:40:48.787110 2026] [security2:error] [pid 204156:tid 204303] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYBbAFPhDXvzP7Sm0AAAAAaA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:48.853782 2026] [security2:error] [pid 204156:tid 204326] [client 154.192.233.184:61083] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lYBbAFPhDXvzP7Sm0EgAAAbc"]
[Mon Jul 20 07:40:48.853917 2026] [security2:error] [pid 204156:tid 204326] [client 154.192.233.184:61083] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lYBbAFPhDXvzP7Sm0EgAAAbc"]
[Mon Jul 20 07:40:49.006217 2026] [security2:error] [pid 178071:tid 178253] [client 14.225.17.146:49933] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4lYBltgi7HBmNwzJNkYQAAADI"], referer: http://taskidsvirginia.com/www
[Mon Jul 20 07:40:49.128262 2026] [security2:error] [pid 204156:tid 204390] [client 57.141.18.21:52458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYBbAFPhDXvzP7Smz8gAB91o"]
[Mon Jul 20 07:40:49.292114 2026] [security2:error] [pid 178071:tid 178318] [client 14.225.17.146:54745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4lYRltgi7HBmNwzJNkeAAAAHM"], referer: http://betterbonddogtraining.com/www
[Mon Jul 20 07:40:49.343195 2026] [security2:error] [pid 178071:tid 178271] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYRltgi7HBmNwzJNkcgAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:49.589245 2026] [security2:error] [pid 204156:tid 204312] [client 14.225.17.146:63845] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4lXxbAFPhDXvzP7Smz1AAAAak"], referer: http://tacticaltreeoperations.com/www
[Mon Jul 20 07:40:49.919126 2026] [security2:error] [pid 178071:tid 178294] [client 57.141.18.44:29002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYRltgi7HBmNwzJNkbAAAWzw"]
[Mon Jul 20 07:40:50.068198 2026] [security2:error] [pid 178071:tid 178255] [client 57.141.18.101:62362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYRltgi7HBmNwzJNkdwAANCs"]
[Mon Jul 20 07:40:50.247191 2026] [security2:error] [pid 178071:tid 178320] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYRltgi7HBmNwzJNknAAAAHU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:50.253408 2026] [security2:error] [pid 204156:tid 204259] [remote 185.177.72.100:44638] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fs3/.env"] [unique_id "al4lYhbAFPhDXvzP7Sm0PQABkWY"]
[Mon Jul 20 07:40:50.304111 2026] [security2:error] [pid 204156:tid 204407] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYhbAFPhDXvzP7Sm0OQAAAgg"], referer: 1'"3000
[Mon Jul 20 07:40:50.316313 2026] [security2:error] [pid 204156:tid 204256] [remote 57.141.18.93:55074] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4lYhbAFPhDXvzP7Sm0PwAB-GM"]
[Mon Jul 20 07:40:50.335577 2026] [security2:error] [pid 204156:tid 204295] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYhbAFPhDXvzP7Sm0OwAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:50.577651 2026] [security2:error] [pid 178071:tid 178266] [client 179.127.84.238:52958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lYhltgi7HBmNwzJNkvAAAAD8"]
[Mon Jul 20 07:40:50.577815 2026] [security2:error] [pid 178071:tid 178266] [client 179.127.84.238:52958] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lYhltgi7HBmNwzJNkvAAAAD8"]
[Mon Jul 20 07:40:50.700846 2026] [security2:error] [pid 204156:tid 204293] [client 57.141.18.39:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lYhbAFPhDXvzP7Sm0SgAAAZY"]
[Mon Jul 20 07:40:50.764413 2026] [authz_core:error] [pid 178071:tid 178261] [client 188.166.209.66:53973] AH01630: client denied by server configuration: /home3/quitmumb/public_html/wp-includes/widgets/error_log, referer: binance.com
[Mon Jul 20 07:40:50.888283 2026] [security2:error] [pid 204156:tid 204366] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lYhbAFPhDXvzP7Sm0SQAAAd8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:51.114292 2026] [security2:error] [pid 178071:tid 178099] [remote 185.177.72.100:44654] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fs3%2f.env"] [unique_id "al4lYxltgi7HBmNwzJNk1gAAZRo"]
[Mon Jul 20 07:40:51.199287 2026] [security2:error] [pid 178071:tid 178253] [client 57.141.18.47:43916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYhltgi7HBmNwzJNkugAAMlk"]
[Mon Jul 20 07:40:51.292716 2026] [security2:error] [pid 204156:tid 204270] [remote 57.141.18.43:37528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4117735"] [unique_id "al4lYxbAFPhDXvzP7Sm0ZgAB5XE"]
[Mon Jul 20 07:40:51.296196 2026] [security2:error] [pid 178071:tid 178317] [client 57.141.18.125:48690] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYhltgi7HBmNwzJNkvwAAclc"]
[Mon Jul 20 07:40:51.521518 2026] [security2:error] [pid 204156:tid 204333] [client 152.170.87.68:63455] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adambergeron.com"] [uri "/index.php"] [unique_id "al4lYxbAFPhDXvzP7Sm0agABvnI"]
[Mon Jul 20 07:40:52.106544 2026] [security2:error] [pid 178071:tid 178228] [client 14.225.17.146:62722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4lYxltgi7HBmNwzJNlBAAAABk"], referer: http://alexsandbergmusic.com/www
[Mon Jul 20 07:40:52.340958 2026] [security2:error] [pid 178071:tid 178284] [client 191.202.66.27:64636] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lZBltgi7HBmNwzJNlFgAAAFE"]
[Mon Jul 20 07:40:52.341085 2026] [security2:error] [pid 178071:tid 178284] [client 191.202.66.27:64636] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lZBltgi7HBmNwzJNlFgAAAFE"]
[Mon Jul 20 07:40:52.463802 2026] [security2:error] [pid 204156:tid 204337] [client 72.27.173.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "worbals.com"] [uri "/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0iAAAAcI"], referer: https://worbals.com
[Mon Jul 20 07:40:52.499789 2026] [security2:error] [pid 204156:tid 204375] [client 14.225.17.146:54620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0mAAAAeg"], referer: http://katsklar.com/www
[Mon Jul 20 07:40:52.517942 2026] [security2:error] [pid 204156:tid 204385] [client 57.141.18.28:28462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYxbAFPhDXvzP7Sm0cQAB8nY"]
[Mon Jul 20 07:40:52.529624 2026] [security2:error] [pid 204156:tid 204401] [client 14.225.17.146:62625] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0kgAAAgI"], referer: http://maxenengineering.com/www
[Mon Jul 20 07:40:52.542865 2026] [security2:error] [pid 204156:tid 204276] [remote 103.255.134.61:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0pAAB_nc"]
[Mon Jul 20 07:40:52.580986 2026] [security2:error] [pid 204156:tid 204330] [client 57.141.18.107:26454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lYxbAFPhDXvzP7Sm0dwABu3k"]
[Mon Jul 20 07:40:52.727722 2026] [security2:error] [pid 204156:tid 204316] [client 14.225.17.146:51408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0pQAAAa0"], referer: http://ivetstrategies.com/www
[Mon Jul 20 07:40:52.812063 2026] [security2:error] [pid 204156:tid 204344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0mQAAAck"], referer: 1'"3000
[Mon Jul 20 07:40:53.100462 2026] [security2:error] [pid 178071:tid 178215] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZBltgi7HBmNwzJNlJwAAAAw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:53.110170 2026] [security2:error] [pid 204156:tid 204272] [remote 103.255.134.61:59876] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.134.255.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0tgACDnM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:40:53.194088 2026] [security2:error] [pid 204156:tid 204342] [client 136.158.60.21:29099] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0ugAAAcc"]
[Mon Jul 20 07:40:53.194241 2026] [security2:error] [pid 204156:tid 204342] [client 136.158.60.21:29099] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0ugAAAcc"]
[Mon Jul 20 07:40:53.224168 2026] [security2:error] [pid 204156:tid 204323] [client 49.47.218.174:53572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0vQAAAbQ"]
[Mon Jul 20 07:40:53.224326 2026] [security2:error] [pid 204156:tid 204323] [client 49.47.218.174:53572] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0vQAAAbQ"]
[Mon Jul 20 07:40:53.427883 2026] [security2:error] [pid 204156:tid 204400] [client 116.74.65.235:63233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0yAAAAgE"]
[Mon Jul 20 07:40:53.428040 2026] [security2:error] [pid 204156:tid 204400] [client 116.74.65.235:63233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0yAAAAgE"]
[Mon Jul 20 07:40:53.433533 2026] [security2:error] [pid 204156:tid 204406] [client 57.141.18.24:41250] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0qQACB24"]
[Mon Jul 20 07:40:53.494518 2026] [security2:error] [pid 204156:tid 204325] [client 34.90.235.227:40960] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "americanbubbleball.com"] [uri "/"] [unique_id "al4lZRbAFPhDXvzP7Sm0zwAAAbY"]
[Mon Jul 20 07:40:53.494658 2026] [security2:error] [pid 204156:tid 204325] [client 34.90.235.227:40960] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "americanbubbleball.com"] [uri "/"] [unique_id "al4lZRbAFPhDXvzP7Sm0zwAAAbY"]
[Mon Jul 20 07:40:53.498642 2026] [security2:error] [pid 204156:tid 204369] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0vAAAAeI"], referer: 1'"3000
[Mon Jul 20 07:40:53.516507 2026] [security2:error] [pid 178071:tid 178283] [client 14.225.17.146:51395] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4lZRltgi7HBmNwzJNlPwAAAFA"], referer: https://maxenengineering.com/www
[Mon Jul 20 07:40:53.768579 2026] [security2:error] [pid 178071:tid 178165] [remote 160.187.68.132:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4lZRltgi7HBmNwzJNlTwAAYVs"]
[Mon Jul 20 07:40:53.813606 2026] [security2:error] [pid 178071:tid 178261] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZRltgi7HBmNwzJNlSQAAADo"], referer: 1'"3000
[Mon Jul 20 07:40:53.941354 2026] [security2:error] [pid 204156:tid 204290] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "website-541d6b1b.nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4lYBbAFPhDXvzP7Smz_gAAAZM"]
[Mon Jul 20 07:40:54.246770 2026] [security2:error] [pid 178071:tid 178168] [remote 160.187.68.132:43454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/wp-login.php"] [unique_id "al4lZhltgi7HBmNwzJNlYgAAWV4"], referer: https://mail.holistichealthmassagenz.com/wp-login.php
[Mon Jul 20 07:40:54.300017 2026] [security2:error] [pid 178071:tid 178268] [client 14.225.17.146:62645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4lZhltgi7HBmNwzJNlXgAAAEE"], referer: http://ncsynchro.com/www
[Mon Jul 20 07:40:54.361052 2026] [security2:error] [pid 204156:tid 204394] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZhbAFPhDXvzP7Sm08QAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:54.525607 2026] [security2:error] [pid 204156:tid 204362] [client 66.249.73.200:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.waterproofgoods.com"] [uri "/index.php"] [unique_id "al4lZBbAFPhDXvzP7Sm0gwAAAds"]
[Mon Jul 20 07:40:54.543656 2026] [security2:error] [pid 204156:tid 204294] [client 77.110.127.138:53954] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/page/21/"] [unique_id "al4lZhbAFPhDXvzP7Sm1AgAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:54.570804 2026] [security2:error] [pid 204156:tid 204352] [client 143.44.185.218:40101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lZhbAFPhDXvzP7Sm1BgAAAdE"]
[Mon Jul 20 07:40:54.570914 2026] [security2:error] [pid 204156:tid 204352] [client 143.44.185.218:40101] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lZhbAFPhDXvzP7Sm1BgAAAdE"]
[Mon Jul 20 07:40:54.574389 2026] [security2:error] [pid 204156:tid 204390] [client 14.225.17.146:51378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4lZRbAFPhDXvzP7Sm0xQAAAfc"], referer: http://sarahholyfield.com/www
[Mon Jul 20 07:40:54.827495 2026] [security2:error] [pid 178071:tid 178306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZhltgi7HBmNwzJNlbAAAAGc"], referer: 1'"3000
[Mon Jul 20 07:40:54.889159 2026] [security2:error] [pid 204156:tid 204412] [client 57.141.18.97:45060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lZhbAFPhDXvzP7Sm09QACDQk"]
[Mon Jul 20 07:40:54.913689 2026] [security2:error] [pid 178071:tid 178094] [remote 185.177.72.100:44684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fapi/.env"] [unique_id "al4lZhltgi7HBmNwzJNlgwAARxU"]
[Mon Jul 20 07:40:55.026743 2026] [security2:error] [pid 204156:tid 204160] [remote 72.167.132.114:54612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1GgABtAM"]
[Mon Jul 20 07:40:55.027061 2026] [security2:error] [pid 204156:tid 204323] [client 72.167.132.114:54612] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1GgABtAM"]
[Mon Jul 20 07:40:55.061424 2026] [security2:error] [pid 178071:tid 178225] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZhltgi7HBmNwzJNlfwAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:55.080638 2026] [security2:error] [pid 204156:tid 204408] [client 57.141.18.105:48482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lZhbAFPhDXvzP7Sm0_AACCQ8"]
[Mon Jul 20 07:40:55.238854 2026] [security2:error] [pid 204156:tid 204296] [client 180.249.173.210:65392] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1IgAAAZk"]
[Mon Jul 20 07:40:55.239744 2026] [security2:error] [pid 204156:tid 204296] [client 180.249.173.210:65392] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1IgAAAZk"]
[Mon Jul 20 07:40:55.420062 2026] [security2:error] [pid 204156:tid 204373] [client 188.166.209.66:59089] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/widgets/class-wp-widget-block.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1LQAAAeY"], referer: binance.com
[Mon Jul 20 07:40:55.573921 2026] [security2:error] [pid 204156:tid 204192] [remote 5.252.52.249:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1NwABwyM"]
[Mon Jul 20 07:40:55.642931 2026] [security2:error] [pid 178071:tid 178211] [client 57.141.18.80:35662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lZhltgi7HBmNwzJNlgQAACEU"]
[Mon Jul 20 07:40:55.662211 2026] [security2:error] [pid 204156:tid 204410] [client 14.225.17.146:56615] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1NAAAAgs"]
[Mon Jul 20 07:40:55.740231 2026] [security2:error] [pid 178071:tid 178102] [remote 185.177.72.100:44690] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fapi%2f.env"] [unique_id "al4lZxltgi7HBmNwzJNlpwAANh0"]
[Mon Jul 20 07:40:55.747218 2026] [security2:error] [pid 204156:tid 204281] [remote 5.252.52.249:60572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1RwABlHw"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:40:55.766269 2026] [security2:error] [pid 204156:tid 204351] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1OAAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:55.883871 2026] [security2:error] [pid 178071:tid 178276] [client 14.225.17.146:56578] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4lZxltgi7HBmNwzJNlqAAAAEk"], referer: http://aljosour-alarabia.com/www
[Mon Jul 20 07:40:55.900426 2026] [security2:error] [pid 204156:tid 204321] [client 36.93.152.155:57863] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1UgAAAbI"]
[Mon Jul 20 07:40:55.900541 2026] [security2:error] [pid 204156:tid 204321] [client 36.93.152.155:57863] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lZxbAFPhDXvzP7Sm1UgAAAbI"]
[Mon Jul 20 07:40:55.975392 2026] [security2:error] [pid 178071:tid 178207] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lZxltgi7HBmNwzJNlqgAAAAQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:56.368153 2026] [security2:error] [pid 204156:tid 204403] [client 103.106.165.44:51535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4laBbAFPhDXvzP7Sm1aAAAAgQ"]
[Mon Jul 20 07:40:56.368255 2026] [security2:error] [pid 204156:tid 204403] [client 103.106.165.44:51535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4laBbAFPhDXvzP7Sm1aAAAAgQ"]
[Mon Jul 20 07:40:56.451401 2026] [security2:error] [pid 178071:tid 178320] [client 14.225.17.146:57904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4laBltgi7HBmNwzJNlxwAAAHU"], referer: http://adultdaycarereno.com/www
[Mon Jul 20 07:40:56.895541 2026] [security2:error] [pid 178071:tid 178234] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4laBltgi7HBmNwzJNl0wAAAB8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:57.055055 2026] [security2:error] [pid 178071:tid 178300] [client 37.52.210.45:16690] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4laRltgi7HBmNwzJNl5QAAAGE"]
[Mon Jul 20 07:40:57.055200 2026] [security2:error] [pid 178071:tid 178300] [client 37.52.210.45:16690] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4laRltgi7HBmNwzJNl5QAAAGE"]
[Mon Jul 20 07:40:57.174104 2026] [security2:error] [pid 204156:tid 204316] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4laBbAFPhDXvzP7Sm1fQAAAa0"], referer: 1'"3000
[Mon Jul 20 07:40:57.263897 2026] [security2:error] [pid 204156:tid 204401] [client 114.119.158.151:29363] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "karimnawfal.com"] [uri "/Dr-Karim-Nawfal/pdf/news/Al-Akhbar.pdf&sa=U"] [unique_id "al4laRbAFPhDXvzP7Sm1hwAAAgI"], referer: http://karimnawfal.com/Dr-Karim-Nawfal/pdf/news/Al-Akhbar.pdf&sa=U
[Mon Jul 20 07:40:57.329548 2026] [security2:error] [pid 178071:tid 178239] [client 14.225.17.146:62741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4laRltgi7HBmNwzJNl6QAAACQ"], referer: https://adultdaycarereno.com/www
[Mon Jul 20 07:40:57.411278 2026] [security2:error] [pid 204156:tid 204312] [client 77.110.127.138:53950] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/page/21/"] [unique_id "al4laRbAFPhDXvzP7Sm1lAAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:57.416167 2026] [security2:error] [pid 178071:tid 178311] [client 57.141.18.112:28112] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4laBltgi7HBmNwzJNlzwAAbFc"]
[Mon Jul 20 07:40:57.461596 2026] [security2:error] [pid 204156:tid 204323] [client 113.178.50.185:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4laBbAFPhDXvzP7Sm1fAAAAbQ"]
[Mon Jul 20 07:40:57.463676 2026] [security2:error] [pid 204156:tid 204343] [client 142.111.152.169:27287] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4laRbAFPhDXvzP7Sm1iwAAAcg"]
[Mon Jul 20 07:40:57.742219 2026] [security2:error] [pid 204156:tid 204397] [client 149.0.16.108:61590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4laRbAFPhDXvzP7Sm1pgAAAf4"]
[Mon Jul 20 07:40:57.742325 2026] [security2:error] [pid 204156:tid 204397] [client 149.0.16.108:61590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4laRbAFPhDXvzP7Sm1pgAAAf4"]
[Mon Jul 20 07:40:57.955374 2026] [security2:error] [pid 204156:tid 204407] [client 116.193.128.26:63401] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 26.128.193.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4laRbAFPhDXvzP7Sm1rAAAAgg"]
[Mon Jul 20 07:40:57.955500 2026] [security2:error] [pid 204156:tid 204407] [client 116.193.128.26:63401] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "grecaalma.com"] [uri "/xmlrpc.php"] [unique_id "al4laRbAFPhDXvzP7Sm1rAAAAgg"]
[Mon Jul 20 07:40:58.071459 2026] [autoindex:error] [pid 204156:tid 204374] [client 89.110.109.74:55948] AH01276: Cannot serve directory /home3/vergotek/vergotek.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:40:58.153532 2026] [security2:error] [pid 204156:tid 204206] [remote 45.90.123.233:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4lahbAFPhDXvzP7Sm1tAABxTE"]
[Mon Jul 20 07:40:58.237046 2026] [security2:error] [pid 178071:tid 178222] [client 50.116.65.227:24858] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lahltgi7HBmNwzJNmPwAAABM"]
[Mon Jul 20 07:40:58.247909 2026] [security2:error] [pid 178071:tid 178252] [client 50.116.65.227:24874] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lahltgi7HBmNwzJNmQAAAADE"]
[Mon Jul 20 07:40:58.359385 2026] [security2:error] [pid 204156:tid 204322] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm1sQAAAbM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:58.398620 2026] [security2:error] [pid 204156:tid 204351] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm1sgAAAdA"], referer: 1'"3000
[Mon Jul 20 07:40:58.480922 2026] [security2:error] [pid 204156:tid 204306] [client 57.141.18.70:51444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4laRbAFPhDXvzP7Sm1lQABoyY"]
[Mon Jul 20 07:40:58.505076 2026] [security2:error] [pid 178071:tid 178225] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lahltgi7HBmNwzJNmPAAAABY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:58.520419 2026] [security2:error] [pid 204156:tid 204210] [remote 45.90.123.233:38016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4lahbAFPhDXvzP7Sm1wAAB4jU"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:40:58.720444 2026] [security2:error] [pid 204156:tid 204370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm1wgAAAeM"], referer: 1'"3000
[Mon Jul 20 07:40:58.760429 2026] [security2:error] [pid 178071:tid 178143] [remote 182.77.62.24:46696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lahltgi7HBmNwzJNmagAAIkY"]
[Mon Jul 20 07:40:58.795125 2026] [security2:error] [pid 204156:tid 204343] [client 52.15.147.27:25404] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm1zwAAAcg"], referer: https://windowtx.com
[Mon Jul 20 07:40:58.987741 2026] [security2:error] [pid 204156:tid 204309] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm1zAAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:40:59.036663 2026] [security2:error] [pid 204156:tid 204341] [client 45.157.112.60:43257] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lahbAFPhDXvzP7Sm12wAAAcY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:40:59.097592 2026] [security2:error] [pid 204156:tid 204410] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm12AAAAgs"]
[Mon Jul 20 07:40:59.260996 2026] [security2:error] [pid 178071:tid 178130] [remote 182.77.62.24:46696] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4laxltgi7HBmNwzJNmgAAAJzk"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:40:59.287644 2026] [security2:error] [pid 204156:tid 204338] [client 103.139.191.61:51000] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4laxbAFPhDXvzP7Sm14wAAAcM"]
[Mon Jul 20 07:40:59.287826 2026] [security2:error] [pid 204156:tid 204338] [client 103.139.191.61:51000] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4laxbAFPhDXvzP7Sm14wAAAcM"]
[Mon Jul 20 07:40:59.315261 2026] [security2:error] [pid 204156:tid 204329] [client 154.192.233.184:61539] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4laxbAFPhDXvzP7Sm15gAAAbo"]
[Mon Jul 20 07:40:59.315368 2026] [security2:error] [pid 204156:tid 204329] [client 154.192.233.184:61539] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4laxbAFPhDXvzP7Sm15gAAAbo"]
[Mon Jul 20 07:40:59.330500 2026] [security2:error] [pid 204156:tid 204286] [client 57.141.18.100:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4laxbAFPhDXvzP7Sm13QAAAY8"]
[Mon Jul 20 07:40:59.412353 2026] [security2:error] [pid 204156:tid 204289] [client 57.141.18.37:25008] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lahbAFPhDXvzP7Sm1vgABkis"]
[Mon Jul 20 07:40:59.485742 2026] [security2:error] [pid 204156:tid 204204] [remote 185.177.72.100:37890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fapp/.env"] [unique_id "al4laxbAFPhDXvzP7Sm18gABmS8"]
[Mon Jul 20 07:40:59.490424 2026] [security2:error] [pid 204156:tid 204337] [client 14.225.17.146:56914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "villa-m-medjugorje.com"] [uri "/index.php"] [unique_id "al4laxbAFPhDXvzP7Sm14gAAAcI"]
[Mon Jul 20 07:40:59.636667 2026] [security2:error] [pid 204156:tid 204306] [client 74.125.213.10:40674] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4laxbAFPhDXvzP7Sm19QAAAaM"]
[Mon Jul 20 07:40:59.976832 2026] [security2:error] [pid 204156:tid 204223] [remote 195.26.244.42:38810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.244.26.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4laxbAFPhDXvzP7Sm2CQABvEI"]
[Mon Jul 20 07:40:59.977152 2026] [security2:error] [pid 204156:tid 204331] [client 195.26.244.42:38810] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.holistichealthmassagenz.com"] [uri "/xmlrpc.php"] [unique_id "al4laxbAFPhDXvzP7Sm2CQABvEI"]
[Mon Jul 20 07:41:00.025803 2026] [security2:error] [pid 178071:tid 178257] [client 127.0.0.1:40464] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4lbBltgi7HBmNwzJNmqQAAADY"], referer: https://www.google.com/search?q=6jhaod
[Mon Jul 20 07:41:00.140394 2026] [security2:error] [pid 204156:tid 204356] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4laxbAFPhDXvzP7Sm2BAAAAdU"]
[Mon Jul 20 07:41:00.182611 2026] [security2:error] [pid 178071:tid 178211] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4laxltgi7HBmNwzJNmoQAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:00.202176 2026] [security2:error] [pid 178071:tid 178319] [client 66.249.65.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bridgeamazon.com"] [uri "/index.php"] [unique_id "al4lbBltgi7HBmNwzJNmqgAAAHQ"]
[Mon Jul 20 07:41:00.280490 2026] [security2:error] [pid 204156:tid 204225] [remote 185.177.72.100:37892] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fapp%2f.env"] [unique_id "al4lbBbAFPhDXvzP7Sm2EwACDEQ"]
[Mon Jul 20 07:41:00.804375 2026] [security2:error] [pid 178071:tid 178266] [client 14.225.17.146:56831] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4lbBltgi7HBmNwzJNmvAAAAD8"], referer: http://reosportsboats.com/www
[Mon Jul 20 07:41:00.824600 2026] [security2:error] [pid 204156:tid 204229] [remote 98.156.100.191:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lbBbAFPhDXvzP7Sm2KwACAEg"]
[Mon Jul 20 07:41:01.046857 2026] [security2:error] [pid 204156:tid 204347] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lbBbAFPhDXvzP7Sm2LAAAAcw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:01.085219 2026] [security2:error] [pid 178071:tid 178314] [client 179.127.84.238:53501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lbRltgi7HBmNwzJNmzwAAAG8"]
[Mon Jul 20 07:41:01.085361 2026] [security2:error] [pid 178071:tid 178314] [client 179.127.84.238:53501] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lbRltgi7HBmNwzJNmzwAAAG8"]
[Mon Jul 20 07:41:01.176780 2026] [security2:error] [pid 204156:tid 204334] [client 57.141.18.97:45076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbBbAFPhDXvzP7Sm2DQABv0s"]
[Mon Jul 20 07:41:01.388509 2026] [security2:error] [pid 204156:tid 204403] [client 57.141.18.13:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2PQAAAgQ"]
[Mon Jul 20 07:41:01.589492 2026] [security2:error] [pid 178071:tid 178310] [client 14.225.17.146:56781] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4lbBltgi7HBmNwzJNmsAAAAGs"]
[Mon Jul 20 07:41:01.595453 2026] [security2:error] [pid 204156:tid 204341] [client 14.225.17.146:57851] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2SQAAAcY"], referer: http://headachescarpaltunnelfibromyalgia.com/www
[Mon Jul 20 07:41:01.649491 2026] [security2:error] [pid 204156:tid 204244] [remote 217.61.143.92:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2UwABk1c"]
[Mon Jul 20 07:41:01.705216 2026] [security2:error] [pid 204156:tid 204373] [client 14.225.17.146:57180] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4lbBbAFPhDXvzP7Sm2DgAAAeY"], referer: http://inspirespublishing.com/www
[Mon Jul 20 07:41:01.731922 2026] [security2:error] [pid 204156:tid 204288] [client 57.141.18.66:34064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbBbAFPhDXvzP7Sm2JQABkUk"]
[Mon Jul 20 07:41:01.733235 2026] [security2:error] [pid 204156:tid 204337] [client 57.141.18.104:28420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbBbAFPhDXvzP7Sm2JgABwkU"]
[Mon Jul 20 07:41:01.751653 2026] [security2:error] [pid 204156:tid 204390] [client 14.225.17.146:56881] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2UQAAAfc"], referer: https://reosportsboats.com/www
[Mon Jul 20 07:41:01.852423 2026] [security2:error] [pid 178071:tid 178304] [client 77.110.127.138:54015] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/page/21/"] [unique_id "al4lbRltgi7HBmNwzJNm6gAAAGU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:01.882193 2026] [security2:error] [pid 204156:tid 204243] [remote 217.61.143.92:39110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2XQABvVY"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:41:01.996351 2026] [security2:error] [pid 204156:tid 204356] [client 49.37.242.14:53774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2YgAAAdU"]
[Mon Jul 20 07:41:01.996478 2026] [security2:error] [pid 204156:tid 204356] [client 49.37.242.14:53774] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2YgAAAdU"]
[Mon Jul 20 07:41:02.190766 2026] [security2:error] [pid 204156:tid 204314] [client 57.141.18.87:40808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbRbAFPhDXvzP7Sm2QQABq1A"]
[Mon Jul 20 07:41:02.305624 2026] [security2:error] [pid 178071:tid 178267] [client 14.225.17.146:57400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNm-QAAAEA"], referer: http://oldracelimited.com/www
[Mon Jul 20 07:41:02.317104 2026] [security2:error] [pid 178071:tid 178292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNm-gAAAFk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:02.680874 2026] [security2:error] [pid 178071:tid 178256] [client 50.116.65.227:52642] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNnCwAAADU"]
[Mon Jul 20 07:41:02.810738 2026] [security2:error] [pid 178071:tid 178251] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNnDwAAADA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:02.875685 2026] [security2:error] [pid 178071:tid 178230] [client 50.116.65.227:52658] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNnFAAAABs"]
[Mon Jul 20 07:41:02.950907 2026] [security2:error] [pid 204156:tid 204311] [client 191.202.66.27:65131] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lbhbAFPhDXvzP7Sm2hgAAAag"]
[Mon Jul 20 07:41:02.951026 2026] [security2:error] [pid 204156:tid 204311] [client 191.202.66.27:65131] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lbhbAFPhDXvzP7Sm2hgAAAag"]
[Mon Jul 20 07:41:03.058332 2026] [security2:error] [pid 204156:tid 204286] [client 14.225.17.146:57485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4lbxbAFPhDXvzP7Sm2iwAAAY8"], referer: http://balticsteelmgmt.com/www
[Mon Jul 20 07:41:03.214139 2026] [security2:error] [pid 204156:tid 204335] [client 57.141.18.125:22464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbhbAFPhDXvzP7Sm2cgABwE8"]
[Mon Jul 20 07:41:03.239106 2026] [security2:error] [pid 178071:tid 178262] [client 14.225.17.146:57476] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNnJgAAADs"], referer: http://idigress.studio/www
[Mon Jul 20 07:41:03.375868 2026] [security2:error] [pid 204156:tid 204374] [client 14.225.17.146:57880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4lbxbAFPhDXvzP7Sm2jwAAAec"], referer: http://bbwipartnerconference.com/www
[Mon Jul 20 07:41:03.390283 2026] [security2:error] [pid 178071:tid 178317] [client 57.141.18.28:50248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNnBQAAciw"]
[Mon Jul 20 07:41:03.596977 2026] [security2:error] [pid 204156:tid 204307] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lbxbAFPhDXvzP7Sm2mQAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:03.662970 2026] [security2:error] [pid 178071:tid 178268] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lbxltgi7HBmNwzJNnOwAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:03.690455 2026] [security2:error] [pid 178071:tid 178296] [client 49.47.218.174:54107] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lbxltgi7HBmNwzJNnQAAAAF0"]
[Mon Jul 20 07:41:03.690589 2026] [security2:error] [pid 178071:tid 178296] [client 49.47.218.174:54107] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lbxltgi7HBmNwzJNnQAAAAF0"]
[Mon Jul 20 07:41:03.711932 2026] [security2:error] [pid 178071:tid 178327] [client 57.141.18.63:65130] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lbhltgi7HBmNwzJNnFwAAfC4"]
[Mon Jul 20 07:41:03.769468 2026] [security2:error] [pid 204156:tid 204361] [client 104.207.53.133:22317] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 133.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lbxbAFPhDXvzP7Sm2qQAAAdo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:41:03.870267 2026] [security2:error] [pid 178071:tid 178224] [client 136.158.60.21:30606] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lbxltgi7HBmNwzJNnRwAAABU"]
[Mon Jul 20 07:41:03.870437 2026] [security2:error] [pid 178071:tid 178224] [client 136.158.60.21:30606] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lbxltgi7HBmNwzJNnRwAAABU"]
[Mon Jul 20 07:41:03.876549 2026] [security2:error] [pid 204156:tid 204199] [remote 57.141.18.88:64720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4966246"] [unique_id "al4lbxbAFPhDXvzP7Sm2sgAB2Co"]
[Mon Jul 20 07:41:04.058729 2026] [security2:error] [pid 204156:tid 204264] [remote 185.177.72.100:37922] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fbackend/.env"] [unique_id "al4lcBbAFPhDXvzP7Sm2twABlWs"]
[Mon Jul 20 07:41:04.730498 2026] [security2:error] [pid 204156:tid 204254] [remote 124.55.178.99:55310] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4lcBbAFPhDXvzP7Sm22AAB9WE"]
[Mon Jul 20 07:41:04.730735 2026] [security2:error] [pid 204156:tid 204388] [client 124.55.178.99:55310] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4lcBbAFPhDXvzP7Sm22AAB9WE"]
[Mon Jul 20 07:41:04.820785 2026] [security2:error] [pid 204156:tid 204326] [client 14.225.17.146:62551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4lcBbAFPhDXvzP7Sm2zwAAAbc"], referer: http://xp-design.co/www
[Mon Jul 20 07:41:04.876455 2026] [security2:error] [pid 204156:tid 204274] [remote 98.156.100.191:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lcBbAFPhDXvzP7Sm24AABmHU"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:41:04.884386 2026] [security2:error] [pid 204156:tid 204347] [client 57.141.18.77:55556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcBbAFPhDXvzP7Sm2uQABzAY"]
[Mon Jul 20 07:41:04.895399 2026] [security2:error] [pid 178071:tid 178170] [remote 185.177.72.100:37932] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fbackend%2f.env"] [unique_id "al4lcBltgi7HBmNwzJNneAAAcGA"]
[Mon Jul 20 07:41:05.115678 2026] [security2:error] [pid 178071:tid 178282] [client 14.225.17.146:62705] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4lcBltgi7HBmNwzJNneQAAAE8"], referer: http://ironcitywellness.com/www
[Mon Jul 20 07:41:05.354849 2026] [security2:error] [pid 204156:tid 204397] [client 14.225.17.146:57880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4lcRbAFPhDXvzP7Sm2-wAAAf4"], referer: http://windowtx.com/www
[Mon Jul 20 07:41:05.485348 2026] [security2:error] [pid 204156:tid 204345] [client 14.225.17.146:65404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4lcRbAFPhDXvzP7Sm29wAAAco"]
[Mon Jul 20 07:41:05.493572 2026] [security2:error] [pid 204156:tid 204367] [client 57.141.18.18:53488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcBbAFPhDXvzP7Sm21AAB4HE"]
[Mon Jul 20 07:41:05.552334 2026] [security2:error] [pid 204156:tid 204361] [client 57.141.18.77:55560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcBbAFPhDXvzP7Sm23gAB2no"]
[Mon Jul 20 07:41:05.707483 2026] [security2:error] [pid 178071:tid 178329] [client 180.249.173.210:49518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lcRltgi7HBmNwzJNnmgAAAH4"]
[Mon Jul 20 07:41:05.707855 2026] [security2:error] [pid 178071:tid 178329] [client 180.249.173.210:49518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lcRltgi7HBmNwzJNnmgAAAH4"]
[Mon Jul 20 07:41:05.866254 2026] [security2:error] [pid 178071:tid 178327] [client 57.141.18.11:60806] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcRltgi7HBmNwzJNnhQAAfGk"]
[Mon Jul 20 07:41:05.964788 2026] [security2:error] [pid 178071:tid 178320] [client 94.154.43.188:25648] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "marscafe.com"] [uri "/.env"] [unique_id "al4lcRltgi7HBmNwzJNnpAAAAHU"]
[Mon Jul 20 07:41:06.217019 2026] [security2:error] [pid 204156:tid 204315] [client 57.141.18.46:46202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcRbAFPhDXvzP7Sm3EAABrAw"]
[Mon Jul 20 07:41:06.263592 2026] [security2:error] [pid 204156:tid 204400] [client 57.141.18.114:50532] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcRbAFPhDXvzP7Sm3EQACAX8"]
[Mon Jul 20 07:41:06.284240 2026] [security2:error] [pid 204156:tid 204356] [client 74.7.227.179:33542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4lchbAFPhDXvzP7Sm3HQAB1Sg"], referer: https://tejasenvironmental.com/p=506301
[Mon Jul 20 07:41:06.403355 2026] [security2:error] [pid 178071:tid 178238] [client 143.44.185.218:42563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lchltgi7HBmNwzJNnuQAAACM"]
[Mon Jul 20 07:41:06.403477 2026] [security2:error] [pid 178071:tid 178238] [client 143.44.185.218:42563] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lchltgi7HBmNwzJNnuQAAACM"]
[Mon Jul 20 07:41:06.459631 2026] [security2:error] [pid 204156:tid 204323] [client 36.93.152.155:58411] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lchbAFPhDXvzP7Sm3MAAAAbQ"]
[Mon Jul 20 07:41:06.459807 2026] [security2:error] [pid 204156:tid 204323] [client 36.93.152.155:58411] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lchbAFPhDXvzP7Sm3MAAAAbQ"]
[Mon Jul 20 07:41:06.608160 2026] [security2:error] [pid 178071:tid 178149] [remote 45.90.123.233:39062] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lchltgi7HBmNwzJNnwAAAWks"]
[Mon Jul 20 07:41:06.608288 2026] [security2:error] [pid 178071:tid 178293] [client 45.90.123.233:39062] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lchltgi7HBmNwzJNnwAAAWks"]
[Mon Jul 20 07:41:06.622098 2026] [security2:error] [pid 204156:tid 204313] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4lchbAFPhDXvzP7Sm3KgABqn0"], referer: http://ali-alghanim.net/www
[Mon Jul 20 07:41:06.731636 2026] [security2:error] [pid 204156:tid 204291] [client 57.141.18.105:27988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lchbAFPhDXvzP7Sm3GwABlBM"]
[Mon Jul 20 07:41:06.826765 2026] [security2:error] [pid 178071:tid 178251] [client 103.106.165.44:52029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lchltgi7HBmNwzJNnxwAAADA"]
[Mon Jul 20 07:41:06.826869 2026] [security2:error] [pid 178071:tid 178251] [client 103.106.165.44:52029] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lchltgi7HBmNwzJNnxwAAADA"]
[Mon Jul 20 07:41:07.275367 2026] [security2:error] [pid 178071:tid 178306] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lcxltgi7HBmNwzJNn1AAAAGc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:07.485780 2026] [security2:error] [pid 178071:tid 178261] [client 77.110.127.138:54091] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/competition/feed/"] [unique_id "al4lcxltgi7HBmNwzJNn5wAAADo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:07.703236 2026] [security2:error] [pid 204156:tid 204395] [client 37.52.210.45:64446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lcxbAFPhDXvzP7Sm3XwAAAfw"]
[Mon Jul 20 07:41:07.703362 2026] [security2:error] [pid 204156:tid 204395] [client 37.52.210.45:64446] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lcxbAFPhDXvzP7Sm3XwAAAfw"]
[Mon Jul 20 07:41:07.846195 2026] [security2:error] [pid 178071:tid 178215] [client 57.141.18.33:64692] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lcxltgi7HBmNwzJNn1wAADAw"]
[Mon Jul 20 07:41:07.924392 2026] [security2:error] [pid 204156:tid 204391] [client 155.2.215.83:24847] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lcxbAFPhDXvzP7Sm3YgAAAfg"]
[Mon Jul 20 07:41:08.137145 2026] [security2:error] [pid 204156:tid 204320] [client 45.3.44.240:15769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 240.44.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ldBbAFPhDXvzP7Sm3agAAAbE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:41:08.355034 2026] [security2:error] [pid 204156:tid 204384] [client 149.0.16.108:62115] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ldBbAFPhDXvzP7Sm3dgAAAfE"]
[Mon Jul 20 07:41:08.355233 2026] [security2:error] [pid 204156:tid 204384] [client 149.0.16.108:62115] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ldBbAFPhDXvzP7Sm3dgAAAfE"]
[Mon Jul 20 07:41:08.761780 2026] [security2:error] [pid 204156:tid 204369] [client 65.111.20.54:32985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 54.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ldBbAFPhDXvzP7Sm3jAAAAeI"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:41:08.897717 2026] [security2:error] [pid 178071:tid 178159] [remote 185.177.72.100:49110] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fserver/.env"] [unique_id "al4ldBltgi7HBmNwzJNoJQAALlU"]
[Mon Jul 20 07:41:09.118455 2026] [security2:error] [pid 178071:tid 178289] [client 186.221.114.200:52747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ldRltgi7HBmNwzJNoLQAAAFY"]
[Mon Jul 20 07:41:09.118712 2026] [security2:error] [pid 178071:tid 178289] [client 186.221.114.200:52747] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ldRltgi7HBmNwzJNoLQAAAFY"]
[Mon Jul 20 07:41:09.223038 2026] [security2:error] [pid 204156:tid 204305] [client 14.225.17.146:59645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4lcxbAFPhDXvzP7Sm3UgAAAaI"], referer: http://aandarealtygroup.com/www
[Mon Jul 20 07:41:09.334645 2026] [security2:error] [pid 178071:tid 178204] [client 151.123.176.248:39917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.176.123.151.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ldRltgi7HBmNwzJNoMwAAAAE"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:41:09.539889 2026] [security2:error] [pid 178071:tid 178328] [client 57.141.18.14:20148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ldBltgi7HBmNwzJNoFgAAfRs"]
[Mon Jul 20 07:41:09.735081 2026] [security2:error] [pid 204156:tid 204198] [remote 185.177.72.100:49122] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fserver%2f.env"] [unique_id "al4ldRbAFPhDXvzP7Sm3tQAB1ik"]
[Mon Jul 20 07:41:09.741168 2026] [security2:error] [pid 178071:tid 178188] [remote 124.55.178.99:39208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ldRltgi7HBmNwzJNoRAAAf3I"]
[Mon Jul 20 07:41:09.813054 2026] [security2:error] [pid 204156:tid 204371] [client 154.192.233.184:61917] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4ldRbAFPhDXvzP7Sm3twAAAeQ"]
[Mon Jul 20 07:41:09.813166 2026] [security2:error] [pid 204156:tid 204371] [client 154.192.233.184:61917] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4ldRbAFPhDXvzP7Sm3twAAAeQ"]
[Mon Jul 20 07:41:09.827085 2026] [security2:error] [pid 204156:tid 204406] [client 57.141.18.125:58320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ldRbAFPhDXvzP7Sm3mwACBzE"]
[Mon Jul 20 07:41:09.866825 2026] [security2:error] [pid 204156:tid 204212] [remote 182.77.62.24:48592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4ldRbAFPhDXvzP7Sm3vAABszc"]
[Mon Jul 20 07:41:09.972255 2026] [security2:error] [pid 178071:tid 178311] [client 45.3.52.11:57221] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4ldRltgi7HBmNwzJNoTAAAAGw"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:41:10.053008 2026] [security2:error] [pid 204156:tid 204340] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ldRbAFPhDXvzP7Sm3uwAAAcU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:10.114487 2026] [security2:error] [pid 204156:tid 204354] [client 216.73.217.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mail.makeupyourskin.online"] [uri "/index.php"] [unique_id "al4ldhbAFPhDXvzP7Sm3wgAAAdM"]
[Mon Jul 20 07:41:10.141761 2026] [security2:error] [pid 178071:tid 178249] [client 50.116.65.227:21948] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ldhltgi7HBmNwzJNoXgAAAC4"]
[Mon Jul 20 07:41:10.151876 2026] [security2:error] [pid 204156:tid 204316] [client 50.116.65.227:21952] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ldhbAFPhDXvzP7Sm3xwAAAa0"]
[Mon Jul 20 07:41:10.171488 2026] [security2:error] [pid 178071:tid 178201] [remote 124.55.178.99:39208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4ldhltgi7HBmNwzJNoYQAAan8"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:41:10.305945 2026] [security2:error] [pid 178071:tid 178276] [client 103.139.191.61:51517] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4ldhltgi7HBmNwzJNoZgAAAEk"]
[Mon Jul 20 07:41:10.306115 2026] [security2:error] [pid 178071:tid 178276] [client 103.139.191.61:51517] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4ldhltgi7HBmNwzJNoZgAAAEk"]
[Mon Jul 20 07:41:10.369005 2026] [security2:error] [pid 204156:tid 204207] [remote 182.77.62.24:48592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.62.77.182.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alaraycreative.com"] [uri "/wp-login.php"] [unique_id "al4ldhbAFPhDXvzP7Sm3yQAB0TI"], referer: https://alaraycreative.com/wp-login.php
[Mon Jul 20 07:41:10.452731 2026] [security2:error] [pid 204156:tid 204397] [client 57.141.18.39:51125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ldRbAFPhDXvzP7Sm3rgAB_jU"]
[Mon Jul 20 07:41:10.519426 2026] [security2:error] [pid 204156:tid 204313] [client 54.238.43.39:43246] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1588"] [id "900939"] [msg "Invalid WordPress REST batch path"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "victoryfinancialcoaching-net.crmpfilms.com"] [uri "/wp-json/batch/v1"] [unique_id "al4ldhbAFPhDXvzP7Sm3zQAAAao"]
[Mon Jul 20 07:41:10.547036 2026] [security2:error] [pid 178071:tid 178293] [client 14.225.17.146:65192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4ldhltgi7HBmNwzJNoWwAAAFo"], referer: http://uritems.net/www
[Mon Jul 20 07:41:10.611290 2026] [security2:error] [pid 204156:tid 204324] [client 202.141.11.99:22104] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ldhbAFPhDXvzP7Sm30gAAAbU"]
[Mon Jul 20 07:41:10.611417 2026] [security2:error] [pid 204156:tid 204324] [client 202.141.11.99:22104] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4ldhbAFPhDXvzP7Sm30gAAAbU"]
[Mon Jul 20 07:41:10.750738 2026] [security2:error] [pid 178071:tid 178286] [client 50.116.65.227:21980] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ldhltgi7HBmNwzJNodgAAAFM"]
[Mon Jul 20 07:41:10.872196 2026] [security2:error] [pid 204156:tid 204355] [client 14.225.17.146:49767] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4ldhbAFPhDXvzP7Sm3zwAAAdQ"], referer: http://lifeisbetterlakeside.com/www
[Mon Jul 20 07:41:10.977364 2026] [security2:error] [pid 178071:tid 178244] [client 50.116.65.227:21992] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4ldhltgi7HBmNwzJNohwAAACk"]
[Mon Jul 20 07:41:11.087474 2026] [security2:error] [pid 204156:tid 204290] [client 54.238.43.39:43256] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=http://user@:80"] [hostname "victoryfinancialcoaching-net.crmpfilms.com"] [uri "/"] [unique_id "al4ldxbAFPhDXvzP7Sm34wAAAZM"]
[Mon Jul 20 07:41:11.207952 2026] [security2:error] [pid 178071:tid 178257] [client 14.225.17.146:55571] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4ldhltgi7HBmNwzJNojwAAADY"], referer: http://according2plant.com/www
[Mon Jul 20 07:41:11.233644 2026] [security2:error] [pid 204156:tid 204374] [client 196.189.225.246:50561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4ldhbAFPhDXvzP7Sm3zAAAAec"]
[Mon Jul 20 07:41:11.234835 2026] [security2:error] [pid 178071:tid 178234] [client 181.42.182.23:22624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4ldhltgi7HBmNwzJNoYgAAAB8"]
[Mon Jul 20 07:41:11.388171 2026] [security2:error] [pid 178071:tid 178263] [client 14.224.227.113:56279] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4ldxltgi7HBmNwzJNopAAAADw"]
[Mon Jul 20 07:41:11.391442 2026] [security2:error] [pid 204156:tid 204311] [client 57.141.18.47:22964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ldhbAFPhDXvzP7Sm3ywABqCs"]
[Mon Jul 20 07:41:11.624417 2026] [security2:error] [pid 178071:tid 178210] [client 179.127.84.238:54033] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ldxltgi7HBmNwzJNorgAAAAc"]
[Mon Jul 20 07:41:11.624557 2026] [security2:error] [pid 178071:tid 178210] [client 179.127.84.238:54033] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ldxltgi7HBmNwzJNorgAAAAc"]
[Mon Jul 20 07:41:11.816934 2026] [security2:error] [pid 204156:tid 204365] [client 57.141.18.58:44516] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ldhbAFPhDXvzP7Sm31wAB3i8"]
[Mon Jul 20 07:41:11.944299 2026] [core:error] [pid 204156:tid 204320] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:11.944322 2026] [core:error] [pid 204156:tid 204320] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:12.139623 2026] [security2:error] [pid 204156:tid 204345] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ldxbAFPhDXvzP7Sm4BAAAAco"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:12.180268 2026] [security2:error] [pid 178071:tid 178245] [client 14.225.17.146:59368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4ldhltgi7HBmNwzJNoeAAAACo"], referer: http://lelandumc.org/www
[Mon Jul 20 07:41:12.323642 2026] [security2:error] [pid 178071:tid 178270] [client 57.141.18.27:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4leBltgi7HBmNwzJNowAAAAEM"]
[Mon Jul 20 07:41:12.371368 2026] [security2:error] [pid 178071:tid 178220] [client 77.110.127.138:54113] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/competition/feed/"] [unique_id "al4leBltgi7HBmNwzJNoxgAAABE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:12.530828 2026] [security2:error] [pid 204156:tid 204292] [client 14.225.17.146:56126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4leBbAFPhDXvzP7Sm4GgAAAZU"], referer: http://savilerowtravel.com/www
[Mon Jul 20 07:41:12.863381 2026] [security2:error] [pid 178071:tid 178154] [remote 216.73.216.55:11273] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4leBltgi7HBmNwzJNo3AAASlA"]
[Mon Jul 20 07:41:12.919048 2026] [security2:error] [pid 204156:tid 204324] [client 57.141.18.54:65486] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ldxbAFPhDXvzP7Sm4BgABtUY"]
[Mon Jul 20 07:41:12.920814 2026] [security2:error] [pid 178071:tid 178285] [client 14.225.17.146:56183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4leBltgi7HBmNwzJNo2QAAAFI"], referer: http://mobilesurvsolutions.com/www
[Mon Jul 20 07:41:13.280491 2026] [security2:error] [pid 204156:tid 204389] [client 14.225.17.146:56128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4leBbAFPhDXvzP7Sm4FwAAAfY"], referer: http://walkingandtalking.net/www
[Mon Jul 20 07:41:13.528663 2026] [security2:error] [pid 178071:tid 178311] [client 14.225.17.146:54426] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4leRltgi7HBmNwzJNo9AAAAGw"], referer: https://savilerowtravel.com/www
[Mon Jul 20 07:41:13.609937 2026] [security2:error] [pid 178071:tid 178157] [remote 185.177.72.100:49132] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fconfig/.env"] [unique_id "al4leRltgi7HBmNwzJNo_wAAcFM"]
[Mon Jul 20 07:41:13.638175 2026] [security2:error] [pid 204156:tid 204340] [client 57.141.18.72:41120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4leBbAFPhDXvzP7Sm4JAABxTw"]
[Mon Jul 20 07:41:13.671039 2026] [security2:error] [pid 178071:tid 178232] [client 191.202.66.27:49245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4leRltgi7HBmNwzJNpBQAAAB0"]
[Mon Jul 20 07:41:13.671192 2026] [security2:error] [pid 178071:tid 178232] [client 191.202.66.27:49245] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4leRltgi7HBmNwzJNpBQAAAB0"]
[Mon Jul 20 07:41:13.959657 2026] [security2:error] [pid 204156:tid 204374] [client 158.173.89.95:42577] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4leRbAFPhDXvzP7Sm4XQAAAec"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:41:13.993185 2026] [security2:error] [pid 204156:tid 204231] [remote 57.141.18.88:31586] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 88.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4040476"] [unique_id "al4leRbAFPhDXvzP7Sm4YgAB4Eo"]
[Mon Jul 20 07:41:14.065556 2026] [security2:error] [pid 204156:tid 204341] [client 98.159.234.160:37391] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lehbAFPhDXvzP7Sm4ZAAAAcY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:41:14.148914 2026] [core:error] [pid 204156:tid 204316] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:14.148940 2026] [core:error] [pid 204156:tid 204316] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:14.190843 2026] [security2:error] [pid 178071:tid 178269] [client 49.47.218.174:54648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lehltgi7HBmNwzJNpGwAAAEI"]
[Mon Jul 20 07:41:14.190968 2026] [security2:error] [pid 178071:tid 178269] [client 49.47.218.174:54648] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lehltgi7HBmNwzJNpGwAAAEI"]
[Mon Jul 20 07:41:14.262085 2026] [security2:error] [pid 178071:tid 178221] [client 14.225.17.146:56123] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4lehltgi7HBmNwzJNpHgAAABI"], referer: https://walkingandtalking.net/www
[Mon Jul 20 07:41:14.442392 2026] [security2:error] [pid 204156:tid 204246] [remote 185.177.72.100:49136] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fconfig%2f.env"] [unique_id "al4lehbAFPhDXvzP7Sm4fwAB_Vk"]
[Mon Jul 20 07:41:14.446508 2026] [security2:error] [pid 204156:tid 204286] [client 57.141.18.50:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lehbAFPhDXvzP7Sm4eAAAAY8"]
[Mon Jul 20 07:41:14.559549 2026] [security2:error] [pid 204156:tid 204392] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lehbAFPhDXvzP7Sm4dwAAAfk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:14.594664 2026] [security2:error] [pid 204156:tid 204383] [client 136.158.60.21:32169] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lehbAFPhDXvzP7Sm4hgAAAfA"]
[Mon Jul 20 07:41:14.594824 2026] [security2:error] [pid 204156:tid 204383] [client 136.158.60.21:32169] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lehbAFPhDXvzP7Sm4hgAAAfA"]
[Mon Jul 20 07:41:14.660688 2026] [security2:error] [pid 204156:tid 204290] [client 104.207.50.85:56885] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lehbAFPhDXvzP7Sm4hwAAAZM"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:41:15.264098 2026] [security2:error] [pid 204156:tid 204317] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4lehbAFPhDXvzP7Sm4jwABrlE"], referer: http://assasalnazaha.com/www
[Mon Jul 20 07:41:15.833332 2026] [cgid:error] [pid 204156:tid 204391] [client 66.132.195.126:1462] AH01265: stderr from /home3/genesjp7/smtracking.genesismbs.com/cgi-bin/: attempt to invoke directory as script, referer: https://www.smtracking.genesismbs.com:443/cgi-bin
[Mon Jul 20 07:41:15.953646 2026] [autoindex:error] [pid 204156:tid 204379] [client 136.114.198.221:58256] AH01276: Cannot serve directory /home2/dkhjivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:41:16.085347 2026] [security2:error] [pid 204156:tid 204395] [client 45.3.42.236:50283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.42.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lfBbAFPhDXvzP7Sm41wAAAfw"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:41:16.178520 2026] [security2:error] [pid 204156:tid 204396] [client 50.116.65.227:31468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "koaconsultants.com"] [uri "/wp-cron.php"] [unique_id "al4lfBbAFPhDXvzP7Sm43QAAAf0"]
[Mon Jul 20 07:41:16.221438 2026] [security2:error] [pid 204156:tid 204264] [remote 103.82.22.235:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm44QABkGs"]
[Mon Jul 20 07:41:16.221677 2026] [security2:error] [pid 204156:tid 204287] [client 103.82.22.235:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "innovativecleaningsvs.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm44QABkGs"]
[Mon Jul 20 07:41:16.235697 2026] [security2:error] [pid 178071:tid 178319] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.bluedoorbar.co.nz"] [uri "/index.php"] [unique_id "al4lexltgi7HBmNwzJNpZAAAAHQ"]
[Mon Jul 20 07:41:16.312340 2026] [security2:error] [pid 178071:tid 178240] [client 14.225.17.146:58957] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4lfBltgi7HBmNwzJNpbQAAACU"], referer: http://whiteoutcb.com/www
[Mon Jul 20 07:41:16.396739 2026] [security2:error] [pid 204156:tid 204390] [client 49.37.242.14:54342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm46AAAAfc"]
[Mon Jul 20 07:41:16.396879 2026] [security2:error] [pid 204156:tid 204390] [client 49.37.242.14:54342] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm46AAAAfc"]
[Mon Jul 20 07:41:16.460648 2026] [security2:error] [pid 204156:tid 204310] [client 13.233.207.33:64088] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm47wAAAac"]
[Mon Jul 20 07:41:16.460729 2026] [security2:error] [pid 204156:tid 204310] [client 13.233.207.33:64088] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm47wAAAac"]
[Mon Jul 20 07:41:16.563581 2026] [security2:error] [pid 204156:tid 204330] [client 54.244.177.189:50106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4lfBbAFPhDXvzP7Sm49QAAAbs"]
[Mon Jul 20 07:41:16.693065 2026] [security2:error] [pid 204156:tid 204354] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lfBbAFPhDXvzP7Sm48gAAAdM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:16.720331 2026] [security2:error] [pid 204156:tid 204408] [client 180.249.173.210:50035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm4_QAAAgk"]
[Mon Jul 20 07:41:16.721006 2026] [security2:error] [pid 204156:tid 204408] [client 180.249.173.210:50035] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm4_QAAAgk"]
[Mon Jul 20 07:41:16.757745 2026] [security2:error] [pid 178071:tid 178213] [client 57.141.18.103:47520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lexltgi7HBmNwzJNpTwAACjI"]
[Mon Jul 20 07:41:16.832169 2026] [security2:error] [pid 204156:tid 204334] [client 57.141.18.83:62664] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lexbAFPhDXvzP7Sm4uQABv1U"]
[Mon Jul 20 07:41:16.901089 2026] [security2:error] [pid 178071:tid 178265] [client 77.110.127.138:54152] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/competition/feed/"] [unique_id "al4lfBltgi7HBmNwzJNpjwAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:16.946073 2026] [security2:error] [pid 204156:tid 204365] [client 36.93.152.155:58965] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm5BQAAAd4"]
[Mon Jul 20 07:41:16.946179 2026] [security2:error] [pid 204156:tid 204365] [client 36.93.152.155:58965] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lfBbAFPhDXvzP7Sm5BQAAAd4"]
[Mon Jul 20 07:41:17.184676 2026] [security2:error] [pid 204156:tid 204368] [client 57.141.18.37:30370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lexbAFPhDXvzP7Sm4yQAB4So"]
[Mon Jul 20 07:41:17.266799 2026] [security2:error] [pid 204156:tid 204364] [client 103.106.165.44:52518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5DAAAAd0"]
[Mon Jul 20 07:41:17.266942 2026] [security2:error] [pid 204156:tid 204364] [client 103.106.165.44:52518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5DAAAAd0"]
[Mon Jul 20 07:41:17.442702 2026] [security2:error] [pid 178071:tid 178290] [client 14.225.17.146:58827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4lfRltgi7HBmNwzJNpqwAAAFc"], referer: http://daseighty.net/www
[Mon Jul 20 07:41:17.538632 2026] [security2:error] [pid 204156:tid 204328] [client 104.207.52.52:58281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5FgAAAbk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:41:17.738634 2026] [security2:error] [pid 204156:tid 204251] [remote 98.156.100.191:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5HAAB9l4"]
[Mon Jul 20 07:41:17.982817 2026] [security2:error] [pid 204156:tid 204163] [remote 100.42.189.89:38646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5LQAB2gY"]
[Mon Jul 20 07:41:18.131714 2026] [security2:error] [pid 204156:tid 204403] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5IgAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:18.181592 2026] [security2:error] [pid 204156:tid 204395] [client 57.141.18.120:56846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfBbAFPhDXvzP7Sm5AAAB_Go"]
[Mon Jul 20 07:41:18.233446 2026] [security2:error] [pid 204156:tid 204290] [client 37.52.210.45:64947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5OAAAAZM"]
[Mon Jul 20 07:41:18.233551 2026] [security2:error] [pid 204156:tid 204290] [client 37.52.210.45:64947] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5OAAAAZM"]
[Mon Jul 20 07:41:18.238974 2026] [security2:error] [pid 204156:tid 204275] [remote 100.42.189.89:38646] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5OQAB0XY"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:41:18.242233 2026] [security2:error] [pid 204156:tid 204273] [remote 185.177.72.100:54662] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fadmin/.env"] [unique_id "al4lfhbAFPhDXvzP7Sm5OgABt3Q"]
[Mon Jul 20 07:41:18.404705 2026] [security2:error] [pid 178071:tid 178283] [client 66.249.73.230:63914] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "box5936.bluehost.com"] [uri "/robots.txt"] [unique_id "al4lfhltgi7HBmNwzJNp1QAAAFA"]
[Mon Jul 20 07:41:18.458706 2026] [security2:error] [pid 178071:tid 178204] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lfhltgi7HBmNwzJNpygAAAAE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:18.460921 2026] [security2:error] [pid 204156:tid 204306] [client 50.116.65.227:22084] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5RQAAAaM"]
[Mon Jul 20 07:41:18.465991 2026] [security2:error] [pid 204156:tid 204391] [client 14.225.17.146:59027] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5NAAAAfg"], referer: http://recruitinginsight.us/www
[Mon Jul 20 07:41:18.481824 2026] [security2:error] [pid 204156:tid 204158] [remote 98.156.100.191:44430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adultdaycarereno.com"] [uri "/wp-login.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5RgABpAE"], referer: https://adultdaycarereno.com/wp-login.php
[Mon Jul 20 07:41:18.545717 2026] [security2:error] [pid 204156:tid 204350] [client 155.2.215.95:48997] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5QQAAAc8"]
[Mon Jul 20 07:41:18.617342 2026] [security2:error] [pid 178071:tid 178298] [client 57.141.18.24:54392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfRltgi7HBmNwzJNpnQAAXxI"]
[Mon Jul 20 07:41:18.986090 2026] [security2:error] [pid 178071:tid 178250] [client 149.0.16.108:62635] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lfhltgi7HBmNwzJNp7gAAAC8"]
[Mon Jul 20 07:41:18.986217 2026] [security2:error] [pid 178071:tid 178250] [client 149.0.16.108:62635] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lfhltgi7HBmNwzJNp7gAAAC8"]
[Mon Jul 20 07:41:19.031033 2026] [security2:error] [pid 204156:tid 204370] [client 14.225.17.146:58967] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5CgAAAeM"], referer: http://nwcarvingacademy.com/www
[Mon Jul 20 07:41:19.071957 2026] [security2:error] [pid 204156:tid 204279] [remote 185.177.72.100:54666] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fadmin%2f.env"] [unique_id "al4lfxbAFPhDXvzP7Sm5bwABy3o"]
[Mon Jul 20 07:41:19.088918 2026] [security2:error] [pid 178071:tid 178270] [client 14.225.17.146:59039] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4lfRltgi7HBmNwzJNpoAAAAEM"], referer: http://ccsdifference.com/www
[Mon Jul 20 07:41:19.210291 2026] [security2:error] [pid 204156:tid 204303] [client 57.141.18.60:35422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfRbAFPhDXvzP7Sm5JAABoGg"]
[Mon Jul 20 07:41:19.416313 2026] [security2:error] [pid 204156:tid 204325] [client 57.141.18.91:62174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5MAABtnU"]
[Mon Jul 20 07:41:19.426718 2026] [security2:error] [pid 204156:tid 204352] [client 143.44.185.218:45498] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5fQAAAdE"]
[Mon Jul 20 07:41:19.426891 2026] [security2:error] [pid 204156:tid 204352] [client 143.44.185.218:45498] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5fQAAAdE"]
[Mon Jul 20 07:41:19.462913 2026] [security2:error] [pid 178071:tid 178306] [client 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4lfxltgi7HBmNwzJNp-wAAAGc"]
[Mon Jul 20 07:41:19.463032 2026] [security2:error] [pid 178071:tid 178306] [client 20.153.140.50:0] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lakelopezonline.com"] [uri "/xmlrpc.php"] [unique_id "al4lfxltgi7HBmNwzJNp-wAAAGc"]
[Mon Jul 20 07:41:19.581628 2026] [security2:error] [pid 204156:tid 204365] [client 57.141.18.20:46736] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5NQAB3nI"]
[Mon Jul 20 07:41:19.586905 2026] [security2:error] [pid 204156:tid 204373] [client 74.208.214.194:37976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5hgAAAeY"]
[Mon Jul 20 07:41:19.781296 2026] [security2:error] [pid 204156:tid 204318] [client 104.207.62.104:61329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 104.62.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5lQAAAa8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:41:19.871690 2026] [security2:error] [pid 204156:tid 204287] [client 114.119.136.188:27103] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "terrapro.marketing"] [uri "/wp-content/uploads/2022/10/USAID-pdacg938.pdf"] [unique_id "al4lfxbAFPhDXvzP7Sm5oQAAAZA"], referer: https://terrapro.marketing/zanjan-fromer-advantages/
[Mon Jul 20 07:41:19.936695 2026] [security2:error] [pid 204156:tid 204330] [client 57.141.18.28:22636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfhbAFPhDXvzP7Sm5TgABu3M"]
[Mon Jul 20 07:41:19.957402 2026] [security2:error] [pid 178071:tid 178226] [client 186.221.114.200:53251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lfxltgi7HBmNwzJNqDwAAABc"]
[Mon Jul 20 07:41:19.957550 2026] [security2:error] [pid 178071:tid 178226] [client 186.221.114.200:53251] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lfxltgi7HBmNwzJNqDwAAABc"]
[Mon Jul 20 07:41:20.034443 2026] [security2:error] [pid 204156:tid 204357] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5kQAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:20.126524 2026] [security2:error] [pid 204156:tid 204358] [client 14.225.17.146:58737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5oAAAAdc"], referer: https://nwcarvingacademy.com/www
[Mon Jul 20 07:41:20.135196 2026] [security2:error] [pid 204156:tid 204388] [client 14.225.17.146:58824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5pQAAAfU"], referer: https://ccsdifference.com/www
[Mon Jul 20 07:41:20.354618 2026] [security2:error] [pid 204156:tid 204290] [client 154.192.233.184:62284] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lgBbAFPhDXvzP7Sm5uwAAAZM"]
[Mon Jul 20 07:41:20.357008 2026] [security2:error] [pid 204156:tid 204290] [client 154.192.233.184:62284] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lgBbAFPhDXvzP7Sm5uwAAAZM"]
[Mon Jul 20 07:41:20.626722 2026] [security2:error] [pid 204156:tid 204367] [client 57.141.18.48:31934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5fAAB4Ak"]
[Mon Jul 20 07:41:20.912957 2026] [security2:error] [pid 204156:tid 204300] [client 57.141.18.26:46360] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lfxbAFPhDXvzP7Sm5iQABnRE"]
[Mon Jul 20 07:41:20.974886 2026] [security2:error] [pid 204156:tid 204188] [remote 47.86.33.52:24308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4lgBbAFPhDXvzP7Sm52AAB5R8"]
[Mon Jul 20 07:41:20.995089 2026] [security2:error] [pid 204156:tid 204358] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lgBbAFPhDXvzP7Sm50AAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:21.012062 2026] [security2:error] [pid 204156:tid 204345] [client 116.74.65.235:63468] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.65.74.116.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lgRbAFPhDXvzP7Sm52gAAAco"]
[Mon Jul 20 07:41:21.012209 2026] [security2:error] [pid 204156:tid 204345] [client 116.74.65.235:63468] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "taskidsvirginia.com"] [uri "/xmlrpc.php"] [unique_id "al4lgRbAFPhDXvzP7Sm52gAAAco"]
[Mon Jul 20 07:41:21.290048 2026] [security2:error] [pid 204156:tid 204411] [client 103.139.191.61:52027] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lgRbAFPhDXvzP7Sm56gAAAgw"]
[Mon Jul 20 07:41:21.290242 2026] [security2:error] [pid 204156:tid 204411] [client 103.139.191.61:52027] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lgRbAFPhDXvzP7Sm56gAAAgw"]
[Mon Jul 20 07:41:21.480456 2026] [security2:error] [pid 204156:tid 204402] [client 57.141.18.110:58880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgBbAFPhDXvzP7Sm5rgACAw4"]
[Mon Jul 20 07:41:21.651184 2026] [security2:error] [pid 178071:tid 178319] [client 50.116.65.227:56496] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lgRltgi7HBmNwzJNqQwAAAHQ"]
[Mon Jul 20 07:41:21.661733 2026] [security2:error] [pid 178071:tid 178284] [client 50.116.65.227:56500] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lgRltgi7HBmNwzJNqRQAAAFE"]
[Mon Jul 20 07:41:21.723765 2026] [security2:error] [pid 178071:tid 178208] [client 57.141.18.48:31936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgBltgi7HBmNwzJNqGAAABRY"]
[Mon Jul 20 07:41:22.135704 2026] [security2:error] [pid 204156:tid 204407] [client 179.127.84.238:54554] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lghbAFPhDXvzP7Sm6BwAAAgg"]
[Mon Jul 20 07:41:22.135831 2026] [security2:error] [pid 204156:tid 204407] [client 179.127.84.238:54554] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lghbAFPhDXvzP7Sm6BwAAAgg"]
[Mon Jul 20 07:41:22.168701 2026] [security2:error] [pid 204156:tid 204297] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lgRbAFPhDXvzP7Sm5_AAAAZo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:22.469214 2026] [security2:error] [pid 178071:tid 178203] [client 57.141.18.104:33270] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgRltgi7HBmNwzJNqNwAAAAM"]
[Mon Jul 20 07:41:22.613124 2026] [security2:error] [pid 178071:tid 178224] [client 57.141.18.61:54198] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgRltgi7HBmNwzJNqOgAAFWM"]
[Mon Jul 20 07:41:22.655766 2026] [security2:error] [pid 204156:tid 204398] [client 14.225.17.146:58817] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4lgBbAFPhDXvzP7Sm5ygAAAf8"], referer: http://narv.co/www
[Mon Jul 20 07:41:22.757929 2026] [security2:error] [pid 178071:tid 178074] [remote 185.177.72.100:54686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fweb/.env"] [unique_id "al4lghltgi7HBmNwzJNqcgAAaQE"]
[Mon Jul 20 07:41:22.798613 2026] [security2:error] [pid 178071:tid 178230] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lghltgi7HBmNwzJNqaAAAABs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:22.921941 2026] [security2:error] [pid 178071:tid 178179] [remote 97.74.87.194:47500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lghltgi7HBmNwzJNqeQAAc2k"]
[Mon Jul 20 07:41:23.055523 2026] [security2:error] [pid 204156:tid 204300] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lghbAFPhDXvzP7Sm6JgAAAZ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:23.060060 2026] [security2:error] [pid 204156:tid 204214] [remote 47.86.33.52:24308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4lgxbAFPhDXvzP7Sm6KAAB3jk"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:41:23.327815 2026] [security2:error] [pid 178071:tid 178073] [remote 97.74.87.194:47500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.87.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lgxltgi7HBmNwzJNqkwAAWgA"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:41:23.534970 2026] [security2:error] [pid 204156:tid 204370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lgxbAFPhDXvzP7Sm6MwAAAeM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:23.576374 2026] [security2:error] [pid 204156:tid 204215] [remote 185.177.72.100:54688] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fweb%2f.env"] [unique_id "al4lgxbAFPhDXvzP7Sm6OwAB8jo"]
[Mon Jul 20 07:41:23.606415 2026] [access_compat:error] [pid 178071:tid 178311] [client 168.144.19.97:59543] AH01797: client denied by server configuration: /home1/polishe5/public_html/wp-content/uploads/woocommerce_uploads/, referer: binance.com
[Mon Jul 20 07:41:23.665739 2026] [authz_core:error] [pid 178071:tid 178311] [client 168.144.19.97:59543] AH01630: client denied by server configuration: /home1/polishe5/public_html/wp-content/uploads/wpcf7_captcha/, referer: binance.com
[Mon Jul 20 07:41:23.665947 2026] [authz_core:error] [pid 178071:tid 178311] [client 168.144.19.97:59543] AH01630: client denied by server configuration: /home1/polishe5/public_html/wp-content/uploads/wpcf7_uploads/, referer: binance.com
[Mon Jul 20 07:41:23.685564 2026] [security2:error] [pid 178071:tid 178234] [client 14.225.17.146:49521] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4lgxltgi7HBmNwzJNqmQAAAB8"], referer: https://narv.co/www
[Mon Jul 20 07:41:23.757927 2026] [security2:error] [pid 204156:tid 204303] [client 57.141.18.78:55568] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lghbAFPhDXvzP7Sm6HQABoDI"]
[Mon Jul 20 07:41:23.905975 2026] [security2:error] [pid 178071:tid 178292] [client 57.141.18.18:61310] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lghltgi7HBmNwzJNqdQAAWVg"]
[Mon Jul 20 07:41:23.917553 2026] [core:error] [pid 204156:tid 204375] [client 14.225.17.146:58446] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:23.917602 2026] [core:error] [pid 204156:tid 204375] [client 14.225.17.146:58446] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:24.117289 2026] [security2:error] [pid 204156:tid 204314] [client 14.225.17.146:54230] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4lgxbAFPhDXvzP7Sm6SAAAAas"], referer: http://39ishlife.com/www
[Mon Jul 20 07:41:24.130240 2026] [security2:error] [pid 178071:tid 178315] [client 14.225.17.146:58170] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4lghltgi7HBmNwzJNqYwAAAHA"], referer: http://superiorcopywriting.com/www
[Mon Jul 20 07:41:24.268272 2026] [security2:error] [pid 178071:tid 178240] [client 57.141.18.58:46482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgxltgi7HBmNwzJNqigAAJUA"]
[Mon Jul 20 07:41:24.288782 2026] [security2:error] [pid 204156:tid 204306] [client 191.202.66.27:49756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lhBbAFPhDXvzP7Sm6WgAAAaM"]
[Mon Jul 20 07:41:24.288910 2026] [security2:error] [pid 204156:tid 204306] [client 191.202.66.27:49756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lhBbAFPhDXvzP7Sm6WgAAAaM"]
[Mon Jul 20 07:41:24.634809 2026] [security2:error] [pid 178071:tid 178329] [client 49.47.218.174:55187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lhBltgi7HBmNwzJNq0wAAAH4"]
[Mon Jul 20 07:41:24.635375 2026] [security2:error] [pid 178071:tid 178329] [client 49.47.218.174:55187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lhBltgi7HBmNwzJNq0wAAAH4"]
[Mon Jul 20 07:41:24.907736 2026] [security2:error] [pid 204156:tid 204229] [remote 8.217.108.67:35444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lhBbAFPhDXvzP7Sm6dwABrEg"]
[Mon Jul 20 07:41:25.041159 2026] [security2:error] [pid 204156:tid 204387] [client 57.141.18.52:52226] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgxbAFPhDXvzP7Sm6QwAB9DQ"]
[Mon Jul 20 07:41:25.044626 2026] [security2:error] [pid 178071:tid 178219] [client 57.141.18.11:30714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lgxltgi7HBmNwzJNqtgAAEBI"]
[Mon Jul 20 07:41:25.056276 2026] [security2:error] [pid 204156:tid 204405] [client 14.225.17.146:58904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4lhBbAFPhDXvzP7Sm6fAAAAgY"], referer: https://39ishlife.com/www
[Mon Jul 20 07:41:25.385743 2026] [security2:error] [pid 178071:tid 178275] [client 136.158.60.21:33651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lhRltgi7HBmNwzJNq7AAAAEg"]
[Mon Jul 20 07:41:25.385947 2026] [security2:error] [pid 178071:tid 178275] [client 136.158.60.21:33651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lhRltgi7HBmNwzJNq7AAAAEg"]
[Mon Jul 20 07:41:25.720308 2026] [security2:error] [pid 204156:tid 204334] [client 35.180.166.19:60752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.166.180.35.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lhRbAFPhDXvzP7Sm6oAAAAb8"], referer: https://www.curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:41:26.137846 2026] [security2:error] [pid 204156:tid 204397] [client 57.141.18.88:39118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lhRbAFPhDXvzP7Sm6gwAB_ks"]
[Mon Jul 20 07:41:26.153534 2026] [security2:error] [pid 204156:tid 204311] [client 14.225.17.146:59153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4lhBbAFPhDXvzP7Sm6fwAAAag"], referer: http://nikkidesigns.net/www
[Mon Jul 20 07:41:26.480781 2026] [security2:error] [pid 178071:tid 178238] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lhhltgi7HBmNwzJNrFQAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:26.742294 2026] [security2:error] [pid 204156:tid 204408] [client 77.110.127.138:54220] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/page/2/"] [unique_id "al4lhhbAFPhDXvzP7Sm6uQAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:26.743101 2026] [security2:error] [pid 178071:tid 178181] [remote 103.90.234.13:33840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lhhltgi7HBmNwzJNrMgAAfms"]
[Mon Jul 20 07:41:26.875398 2026] [security2:error] [pid 204156:tid 204287] [client 14.225.17.146:58182] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4lhBbAFPhDXvzP7Sm6cQAAAZA"], referer: http://webgardensbypaula.com/www
[Mon Jul 20 07:41:27.077985 2026] [security2:error] [pid 204156:tid 204348] [client 57.141.18.29:58452] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lhRbAFPhDXvzP7Sm6qAABzU0"]
[Mon Jul 20 07:41:27.173396 2026] [security2:error] [pid 204156:tid 204309] [client 180.249.173.210:50535] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lhxbAFPhDXvzP7Sm6zQAAAaY"]
[Mon Jul 20 07:41:27.173526 2026] [security2:error] [pid 204156:tid 204309] [client 180.249.173.210:50535] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lhxbAFPhDXvzP7Sm6zQAAAaY"]
[Mon Jul 20 07:41:27.200506 2026] [security2:error] [pid 178071:tid 178076] [remote 185.177.72.100:54708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fpublic/.env"] [unique_id "al4lhxltgi7HBmNwzJNrSwAABAM"]
[Mon Jul 20 07:41:27.208773 2026] [autoindex:error] [pid 178071:tid 178123] [remote 34.86.93.96:58837] AH01276: Cannot serve directory /home2/enxbgpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.enx.bgp.mybluehost.me
[Mon Jul 20 07:41:27.254238 2026] [security2:error] [pid 178071:tid 178080] [remote 103.90.234.13:33840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.234.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lhxltgi7HBmNwzJNrTQAAdgc"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:41:27.318270 2026] [lsapi:warn] [pid 178071:tid 178320] [client 14.225.17.146:49478] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/www
[Mon Jul 20 07:41:27.318303 2026] [lsapi:warn] [pid 178071:tid 178320] [client 14.225.17.146:49478] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/www
[Mon Jul 20 07:41:27.400189 2026] [lsapi:warn] [pid 204156:tid 204292] [client 50.116.65.227:56626] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:41:27.400214 2026] [lsapi:warn] [pid 204156:tid 204292] [client 50.116.65.227:56626] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:41:27.415684 2026] [security2:error] [pid 178071:tid 178320] [client 14.225.17.146:49478] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4lhxltgi7HBmNwzJNrUwAAAHU"], referer: http://oswegooperatheater.com/www
[Mon Jul 20 07:41:27.494470 2026] [security2:error] [pid 178071:tid 178227] [client 36.93.152.155:59518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lhxltgi7HBmNwzJNrXQAAABg"]
[Mon Jul 20 07:41:27.494579 2026] [security2:error] [pid 178071:tid 178227] [client 36.93.152.155:59518] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lhxltgi7HBmNwzJNrXQAAABg"]
[Mon Jul 20 07:41:27.555971 2026] [security2:error] [pid 204156:tid 204387] [client 188.166.209.66:55029] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/css/dist/registry.php"] [unique_id "al4lhxbAFPhDXvzP7Sm63AAAAfQ"], referer: binance.com
[Mon Jul 20 07:41:27.756876 2026] [security2:error] [pid 204156:tid 204344] [client 103.106.165.44:53002] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lhxbAFPhDXvzP7Sm63QAAAck"]
[Mon Jul 20 07:41:27.756988 2026] [security2:error] [pid 204156:tid 204344] [client 103.106.165.44:53002] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lhxbAFPhDXvzP7Sm63QAAAck"]
[Mon Jul 20 07:41:28.030222 2026] [security2:error] [pid 204156:tid 204224] [remote 185.177.72.100:40128] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fpublic%2f.env"] [unique_id "al4liBbAFPhDXvzP7Sm69gAB2EM"]
[Mon Jul 20 07:41:28.124446 2026] [security2:error] [pid 204156:tid 204325] [client 57.141.18.91:41108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lhxbAFPhDXvzP7Sm6zAABtlA"]
[Mon Jul 20 07:41:28.162241 2026] [security2:error] [pid 204156:tid 204408] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lhxbAFPhDXvzP7Sm68QAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:28.216076 2026] [security2:error] [pid 204156:tid 204315] [client 14.251.3.155:56288] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4liBbAFPhDXvzP7Sm6-wAAAaw"]
[Mon Jul 20 07:41:28.374612 2026] [lsapi:warn] [pid 204156:tid 204320] [client 14.225.17.146:49553] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/www
[Mon Jul 20 07:41:28.374639 2026] [lsapi:warn] [pid 204156:tid 204320] [client 14.225.17.146:49553] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/www
[Mon Jul 20 07:41:28.433516 2026] [security2:error] [pid 204156:tid 204320] [client 14.225.17.146:49553] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4liBbAFPhDXvzP7Sm7BgAAAbE"], referer: https://oswegooperatheater.com/www
[Mon Jul 20 07:41:28.439361 2026] [security2:error] [pid 204156:tid 204335] [client 65.111.23.98:19417] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4liBbAFPhDXvzP7Sm7CAAAAcA"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:41:28.458050 2026] [security2:error] [pid 178071:tid 178288] [client 57.141.18.61:57748] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lhxltgi7HBmNwzJNrVgAAVXs"]
[Mon Jul 20 07:41:28.565675 2026] [security2:error] [pid 204156:tid 204262] [remote 8.217.108.67:35444] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4liBbAFPhDXvzP7Sm7EAABt2k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:41:28.576169 2026] [security2:error] [pid 204156:tid 204410] [client 57.141.18.90:44590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lhxbAFPhDXvzP7Sm62gACC2I"]
[Mon Jul 20 07:41:28.809224 2026] [security2:error] [pid 204156:tid 204314] [client 57.141.18.55:38982] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lhxbAFPhDXvzP7Sm65QABq1o"]
[Mon Jul 20 07:41:28.812791 2026] [security2:error] [pid 178071:tid 178292] [client 14.225.17.146:57976] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4liBltgi7HBmNwzJNrfwAAAFk"], referer: http://carolinapressurewashers.com/www
[Mon Jul 20 07:41:28.892761 2026] [security2:error] [pid 178071:tid 178203] [client 57.141.18.33:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cephasnext.com"] [uri "/index.php"] [unique_id "al4lhxltgi7HBmNwzJNrVQAAAAA"]
[Mon Jul 20 07:41:28.983367 2026] [security2:error] [pid 204156:tid 204345] [client 14.225.17.146:65285] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4lhxbAFPhDXvzP7Sm67gAAAco"]
[Mon Jul 20 07:41:29.038827 2026] [security2:error] [pid 204156:tid 204313] [client 37.52.210.45:25500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7IgAAAao"]
[Mon Jul 20 07:41:29.039087 2026] [security2:error] [pid 204156:tid 204313] [client 37.52.210.45:25500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7IgAAAao"]
[Mon Jul 20 07:41:29.246644 2026] [security2:error] [pid 204156:tid 204406] [client 142.111.152.180:20435] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7JQAAAgc"]
[Mon Jul 20 07:41:29.282416 2026] [security2:error] [pid 178071:tid 178291] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.littleaosta.nz"] [uri "/index.php"] [unique_id "al4liRltgi7HBmNwzJNrlwAAAFg"]
[Mon Jul 20 07:41:29.454940 2026] [security2:error] [pid 178071:tid 178234] [client 45.3.53.220:9501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4liRltgi7HBmNwzJNrpAAAAB8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:41:29.628167 2026] [security2:error] [pid 204156:tid 204412] [client 149.0.16.108:63152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7MQAAAg0"]
[Mon Jul 20 07:41:29.628272 2026] [security2:error] [pid 204156:tid 204412] [client 149.0.16.108:63152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7MQAAAg0"]
[Mon Jul 20 07:41:29.632533 2026] [security2:error] [pid 204156:tid 204368] [client 49.37.242.14:54871] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7MgAAAeE"]
[Mon Jul 20 07:41:29.632623 2026] [security2:error] [pid 204156:tid 204368] [client 49.37.242.14:54871] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4liRbAFPhDXvzP7Sm7MgAAAeE"]
[Mon Jul 20 07:41:29.695013 2026] [security2:error] [pid 204156:tid 204350] [client 57.141.18.59:32318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4liBbAFPhDXvzP7Sm7DQABz2M"]
[Mon Jul 20 07:41:29.739718 2026] [security2:error] [pid 204156:tid 204396] [client 14.225.17.146:64559] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4lhxbAFPhDXvzP7Sm63wAAAf0"], referer: http://securingmemories.com/www
[Mon Jul 20 07:41:29.856826 2026] [security2:error] [pid 204156:tid 204410] [client 14.225.17.146:57702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4liRbAFPhDXvzP7Sm7NQAAAgs"]
[Mon Jul 20 07:41:30.446187 2026] [security2:error] [pid 178071:tid 178307] [client 77.110.127.138:54236] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/page/2/"] [unique_id "al4lihltgi7HBmNwzJNr2wAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:30.805311 2026] [security2:error] [pid 204156:tid 204371] [client 57.141.18.52:24956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4liRbAFPhDXvzP7Sm7PAAB5AY"]
[Mon Jul 20 07:41:30.846053 2026] [security2:error] [pid 178071:tid 178262] [client 186.221.114.200:53714] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lihltgi7HBmNwzJNr7gAAADs"]
[Mon Jul 20 07:41:30.846242 2026] [security2:error] [pid 178071:tid 178262] [client 186.221.114.200:53714] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lihltgi7HBmNwzJNr7gAAADs"]
[Mon Jul 20 07:41:30.865115 2026] [security2:error] [pid 178071:tid 178224] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lihltgi7HBmNwzJNr6QAAABU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:30.915914 2026] [security2:error] [pid 204156:tid 204391] [client 154.192.233.184:60723] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lihbAFPhDXvzP7Sm7cgAAAfg"]
[Mon Jul 20 07:41:30.916097 2026] [security2:error] [pid 204156:tid 204391] [client 154.192.233.184:60723] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lihbAFPhDXvzP7Sm7cgAAAfg"]
[Mon Jul 20 07:41:30.971252 2026] [security2:error] [pid 204156:tid 204312] [client 50.116.65.227:30052] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4lihbAFPhDXvzP7Sm7eAAAAak"]
[Mon Jul 20 07:41:30.979839 2026] [security2:error] [pid 178071:tid 178273] [client 57.141.18.96:51076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lihltgi7HBmNwzJNrwQAARkE"]
[Mon Jul 20 07:41:30.982096 2026] [security2:error] [pid 204156:tid 204408] [client 50.116.65.227:15046] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4lihbAFPhDXvzP7Sm7egAAAck"]
[Mon Jul 20 07:41:30.998347 2026] [core:error] [pid 204156:tid 204386] [client 104.236.226.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:30.998379 2026] [core:error] [pid 204156:tid 204386] [client 104.236.226.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:31.391261 2026] [security2:error] [pid 178071:tid 178310] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lixltgi7HBmNwzJNr-wAAAGs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:31.554335 2026] [security2:error] [pid 204156:tid 204396] [client 57.141.18.45:48438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lihbAFPhDXvzP7Sm7aQAB_W8"]
[Mon Jul 20 07:41:31.610349 2026] [security2:error] [pid 204156:tid 204389] [client 74.208.214.194:58550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lixbAFPhDXvzP7Sm7sAAAAfY"]
[Mon Jul 20 07:41:31.796641 2026] [security2:error] [pid 204156:tid 204177] [remote 185.177.72.100:40164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fold/.env"] [unique_id "al4lixbAFPhDXvzP7Sm7vwABkxQ"]
[Mon Jul 20 07:41:31.860221 2026] [security2:error] [pid 204156:tid 204319] [client 143.44.185.218:48184] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lixbAFPhDXvzP7Sm7xQAAAbA"]
[Mon Jul 20 07:41:31.860332 2026] [security2:error] [pid 204156:tid 204319] [client 143.44.185.218:48184] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4lixbAFPhDXvzP7Sm7xQAAAbA"]
[Mon Jul 20 07:41:32.077166 2026] [security2:error] [pid 204156:tid 204330] [client 57.141.18.64:35506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lihbAFPhDXvzP7Sm7dwABu3s"]
[Mon Jul 20 07:41:32.126664 2026] [security2:error] [pid 204156:tid 204322] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lixbAFPhDXvzP7Sm7yQAAAbM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:32.167148 2026] [security2:error] [pid 178071:tid 178329] [client 57.141.18.117:48134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lixltgi7HBmNwzJNr-gAAfi4"]
[Mon Jul 20 07:41:32.438016 2026] [security2:error] [pid 204156:tid 204320] [client 103.139.191.61:52528] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4ljBbAFPhDXvzP7Sm76AAAAbE"]
[Mon Jul 20 07:41:32.438136 2026] [security2:error] [pid 204156:tid 204320] [client 103.139.191.61:52528] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4ljBbAFPhDXvzP7Sm76AAAAbE"]
[Mon Jul 20 07:41:32.458079 2026] [security2:error] [pid 178071:tid 178306] [client 158.173.166.181:61795] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ljBltgi7HBmNwzJNsIQAAAGc"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:41:32.590606 2026] [security2:error] [pid 178071:tid 178132] [remote 185.177.72.100:40172] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fold%2f.env"] [unique_id "al4ljBltgi7HBmNwzJNsLQAAKjs"]
[Mon Jul 20 07:41:32.616371 2026] [security2:error] [pid 204156:tid 204306] [client 179.127.84.238:55072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ljBbAFPhDXvzP7Sm78wAAAaM"]
[Mon Jul 20 07:41:32.616491 2026] [security2:error] [pid 204156:tid 204306] [client 179.127.84.238:55072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4ljBbAFPhDXvzP7Sm78wAAAaM"]
[Mon Jul 20 07:41:32.639286 2026] [core:error] [pid 178071:tid 178257] [client 104.236.226.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.travelbyfire.com/
[Mon Jul 20 07:41:32.639314 2026] [core:error] [pid 178071:tid 178257] [client 104.236.226.154:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: https://cpanel.travelbyfire.com/
[Mon Jul 20 07:41:32.748825 2026] [security2:error] [pid 178071:tid 178269] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ljBltgi7HBmNwzJNsJwAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:33.025394 2026] [security2:error] [pid 204156:tid 204397] [client 50.116.65.227:15072] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4ljRbAFPhDXvzP7Sm8EAAAAf4"]
[Mon Jul 20 07:41:33.037764 2026] [security2:error] [pid 178071:tid 178250] [client 50.116.65.227:15086] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4ljRltgi7HBmNwzJNsRAAAAC8"]
[Mon Jul 20 07:41:33.064990 2026] [security2:error] [pid 204156:tid 204218] [remote 152.228.213.32:33550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.com"] [uri "/wp-login.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8EwAB6z0"]
[Mon Jul 20 07:41:33.066562 2026] [security2:error] [pid 204156:tid 204375] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ljBbAFPhDXvzP7Sm7-wAAAeg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:33.229673 2026] [security2:error] [pid 204156:tid 204383] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ljBbAFPhDXvzP7Sm8CQAAAfA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:33.249357 2026] [security2:error] [pid 204156:tid 204209] [remote 152.228.213.32:33550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.com"] [uri "/wp-login.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8HgAB5DQ"], referer: https://fkconstructionfunding.com/wp-login.php
[Mon Jul 20 07:41:33.332270 2026] [security2:error] [pid 204156:tid 204326] [client 57.141.18.112:23038] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ljBbAFPhDXvzP7Sm71wABtx4"]
[Mon Jul 20 07:41:33.379433 2026] [security2:error] [pid 178071:tid 178213] [client 74.7.175.187:43640] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "themomentsmag.lnl.tfc.mybluehost.me"] [uri "/index.php"] [unique_id "al4lihltgi7HBmNwzJNrxQAACj4"]
[Mon Jul 20 07:41:33.446628 2026] [core:error] [pid 204156:tid 204373] [client 14.225.17.146:62326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/www
[Mon Jul 20 07:41:33.446656 2026] [core:error] [pid 204156:tid 204373] [client 14.225.17.146:62326] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/www
[Mon Jul 20 07:41:33.456324 2026] [security2:error] [pid 204156:tid 204413] [client 89.124.113.107:64149] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 107.113.124.89.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "schuttfarms.com"] [uri "/wp-comments-post.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8LAAAAg4"], referer: https://schuttfarms.com/product/canvas-cap-for-personalization/
[Mon Jul 20 07:41:33.456472 2026] [security2:error] [pid 204156:tid 204413] [client 89.124.113.107:64149] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "schuttfarms.com"] [uri "/wp-comments-post.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8LAAAAg4"], referer: https://schuttfarms.com/product/canvas-cap-for-personalization/
[Mon Jul 20 07:41:33.743710 2026] [security2:error] [pid 204156:tid 204217] [remote 97.74.93.24:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8MwABoTw"]
[Mon Jul 20 07:41:33.760067 2026] [security2:error] [pid 204156:tid 204312] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8MAAAAak"]
[Mon Jul 20 07:41:33.784788 2026] [core:error] [pid 204156:tid 204359] [client 82.39.212.219:53944] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:33.784806 2026] [core:error] [pid 204156:tid 204359] [client 82.39.212.219:53944] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:33.896712 2026] [security2:error] [pid 178071:tid 178193] [remote 100.42.189.89:38830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4ljRltgi7HBmNwzJNsagAAfnc"]
[Mon Jul 20 07:41:34.108462 2026] [security2:error] [pid 178071:tid 178195] [remote 100.42.189.89:38830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4ljhltgi7HBmNwzJNsdAAAe3k"], referer: https://adastra.love/wp-login.php
[Mon Jul 20 07:41:34.134134 2026] [security2:error] [pid 204156:tid 204230] [remote 97.74.93.24:47670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ljhbAFPhDXvzP7Sm8RQABn0k"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:41:34.305881 2026] [security2:error] [pid 204156:tid 204385] [client 57.141.18.110:62574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ljBbAFPhDXvzP7Sm8BQAB8jk"]
[Mon Jul 20 07:41:34.465814 2026] [security2:error] [pid 204156:tid 204314] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ljhbAFPhDXvzP7Sm8SgAAAas"]
[Mon Jul 20 07:41:34.854766 2026] [security2:error] [pid 204156:tid 204294] [client 77.110.127.138:54259] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/page/2/"] [unique_id "al4ljhbAFPhDXvzP7Sm8ZAAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:34.864928 2026] [security2:error] [pid 204156:tid 204317] [client 14.225.17.146:62344] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4ljhbAFPhDXvzP7Sm8RwAAAa4"], referer: http://idigress.agency/www
[Mon Jul 20 07:41:34.928546 2026] [security2:error] [pid 204156:tid 204354] [client 191.202.66.27:50246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ljhbAFPhDXvzP7Sm8aAAAAdM"]
[Mon Jul 20 07:41:34.928701 2026] [security2:error] [pid 204156:tid 204354] [client 191.202.66.27:50246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4ljhbAFPhDXvzP7Sm8aAAAAdM"]
[Mon Jul 20 07:41:34.958163 2026] [security2:error] [pid 178071:tid 178190] [remote 162.19.86.63:47841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ljhltgi7HBmNwzJNsmwAAN3Q"]
[Mon Jul 20 07:41:35.138202 2026] [security2:error] [pid 178071:tid 178317] [client 14.225.17.146:56329] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4ljhltgi7HBmNwzJNsnQAAAHI"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/www
[Mon Jul 20 07:41:35.139762 2026] [security2:error] [pid 178071:tid 178304] [client 57.141.18.43:63686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ljRltgi7HBmNwzJNsZAAAZT8"]
[Mon Jul 20 07:41:35.160173 2026] [lsapi:warn] [pid 204156:tid 204231] [remote 3.138.182.20:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 07:41:35.167011 2026] [security2:error] [pid 178071:tid 178154] [remote 162.19.86.63:47841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4ljxltgi7HBmNwzJNsoQAAF1A"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:41:35.168522 2026] [security2:error] [pid 204156:tid 204356] [client 49.47.218.174:21185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8bwAAAdU"]
[Mon Jul 20 07:41:35.168642 2026] [security2:error] [pid 204156:tid 204356] [client 49.47.218.174:21185] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8bwAAAdU"]
[Mon Jul 20 07:41:35.214078 2026] [security2:error] [pid 204156:tid 204372] [client 57.141.18.61:57762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ljRbAFPhDXvzP7Sm8OgAB5Us"]
[Mon Jul 20 07:41:35.357634 2026] [security2:error] [pid 178071:tid 178245] [client 62.102.148.130:37164] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ljxltgi7HBmNwzJNsrgAAACo"]
[Mon Jul 20 07:41:35.357759 2026] [security2:error] [pid 178071:tid 178245] [client 62.102.148.130:37164] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4ljxltgi7HBmNwzJNsrgAAACo"]
[Mon Jul 20 07:41:35.385337 2026] [security2:error] [pid 204156:tid 204384] [client 89.124.68.208:16661] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.68.208" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8eAAAAfE"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:41:35.385473 2026] [security2:error] [pid 204156:tid 204384] [client 89.124.68.208:16661] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8eAAAAfE"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:41:35.456957 2026] [security2:error] [pid 204156:tid 204371] [client 216.24.212.35:57601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8egAAAeQ"]
[Mon Jul 20 07:41:35.492705 2026] [security2:error] [pid 204156:tid 204319] [client 216.24.212.14:49745] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8fAAAAbA"]
[Mon Jul 20 07:41:35.601800 2026] [lsapi:error] [pid 178071:tid 178228] [client 43.156.142.168:61704] [host www.samdothan.org] Request retrieving failed. Reason: unknown, On: request body, Source: client, Where: unknown, referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:41:35.601822 2026] [lsapi:error] [pid 178071:tid 178228] [client 43.156.142.168:61704] [host www.samdothan.org] In order to get more info about fail reason try to change LogLevel to Info in httpd.conf and restart Apache, referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:41:35.601831 2026] [lsapi:error] [pid 178071:tid 178228] [client 43.156.142.168:61704] [host www.samdothan.org] Client error on sending request(POST /wp-login.php HTTP/1.1); uri(/wp-login.php) content-length(131): user_get_body(tmpstackbuf, 16384): read from client failed, referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:41:35.675194 2026] [security2:error] [pid 204156:tid 204339] [client 193.36.225.190:48235] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 190.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8iwAAAcQ"]
[Mon Jul 20 07:41:35.723731 2026] [security2:error] [pid 178071:tid 178293] [client 14.225.17.146:64756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4ljRltgi7HBmNwzJNsaQAAAFo"], referer: http://fineartsfactory.net/www
[Mon Jul 20 07:41:35.790801 2026] [security2:error] [pid 204156:tid 204332] [client 193.36.225.45:44693] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8kAAAAb0"]
[Mon Jul 20 07:41:35.829110 2026] [security2:error] [pid 178071:tid 178228] [client 43.156.142.168:61704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.samdothan.org"] [uri "/index.php"] [unique_id "al4lhRltgi7HBmNwzJNq5wAAABk"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:41:35.912453 2026] [security2:error] [pid 204156:tid 204223] [remote 20.153.140.50:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4ljxbAFPhDXvzP7Sm8lgAB40I"]
[Mon Jul 20 07:41:36.037102 2026] [security2:error] [pid 178071:tid 178322] [client 89.124.68.208:16664] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "89.124.68.208" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4lkBltgi7HBmNwzJNs0QAAAHc"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:41:36.037204 2026] [security2:error] [pid 178071:tid 178322] [client 89.124.68.208:16664] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-comments-post.php"] [unique_id "al4lkBltgi7HBmNwzJNs0QAAAHc"], referer: https://www.sesamegreenbeans.com/jin-wee-feastcoastroad/#comment-14460
[Mon Jul 20 07:41:36.065642 2026] [security2:error] [pid 204156:tid 204355] [client 136.158.60.21:35026] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8nwAAAdQ"]
[Mon Jul 20 07:41:36.065790 2026] [security2:error] [pid 204156:tid 204355] [client 136.158.60.21:35026] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8nwAAAdQ"]
[Mon Jul 20 07:41:36.199393 2026] [security2:error] [pid 204156:tid 204258] [remote 185.177.72.100:40192] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fnew/.env"] [unique_id "al4lkBbAFPhDXvzP7Sm8oQAB2GU"]
[Mon Jul 20 07:41:36.240565 2026] [security2:error] [pid 204156:tid 204252] [remote 5.252.52.249:47462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8ogACAV8"]
[Mon Jul 20 07:41:36.301168 2026] [lsapi:warn] [pid 204156:tid 204240] [remote 3.138.182.20:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:41:36.339499 2026] [security2:error] [pid 204156:tid 204239] [remote 20.153.140.50:52686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "karimnawfal.com"] [uri "/wp-login.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8qAACAlI"], referer: https://karimnawfal.com/wp-login.php
[Mon Jul 20 07:41:36.404006 2026] [security2:error] [pid 204156:tid 204256] [remote 5.252.52.249:47462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8sAAB92M"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:41:36.766895 2026] [security2:error] [pid 178071:tid 178299] [client 87.199.199.98:52888] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 98.199.199.87.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-comments-post.php"] [unique_id "al4lkBltgi7HBmNwzJNs7wAAAGA"], referer: https://fluidtemple.org/namaste-lesson/yin-class-part-3/
[Mon Jul 20 07:41:36.767083 2026] [security2:error] [pid 178071:tid 178299] [client 87.199.199.98:52888] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "409"] [hostname "fluidtemple.org"] [uri "/wp-comments-post.php"] [unique_id "al4lkBltgi7HBmNwzJNs7wAAAGA"], referer: https://fluidtemple.org/namaste-lesson/yin-class-part-3/
[Mon Jul 20 07:41:36.987367 2026] [security2:error] [pid 204156:tid 204275] [remote 57.141.18.59:61946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4840712"] [unique_id "al4lkBbAFPhDXvzP7Sm8vwABuHY"]
[Mon Jul 20 07:41:36.996276 2026] [security2:error] [pid 204156:tid 204254] [remote 185.177.72.100:40198] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fnew%2f.env"] [unique_id "al4lkBbAFPhDXvzP7Sm8wAAB9WE"]
[Mon Jul 20 07:41:37.069311 2026] [security2:error] [pid 178071:tid 178125] [remote 103.118.29.185:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4lkRltgi7HBmNwzJNtAQAAfzQ"]
[Mon Jul 20 07:41:37.284049 2026] [security2:error] [pid 204156:tid 204163] [remote 20.153.140.50:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4lkRbAFPhDXvzP7Sm8zQABvQY"]
[Mon Jul 20 07:41:37.369050 2026] [security2:error] [pid 178071:tid 178295] [client 14.225.17.146:55268] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4lkBltgi7HBmNwzJNs0AAAAFw"], referer: http://hammadownenterprises.com/www
[Mon Jul 20 07:41:37.388801 2026] [security2:error] [pid 204156:tid 204319] [client 85.204.70.112:56862] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4lkRbAFPhDXvzP7Sm81AAAAbA"]
[Mon Jul 20 07:41:37.398573 2026] [security2:error] [pid 204156:tid 204344] [client 57.141.18.21:36902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8nQAByVk"]
[Mon Jul 20 07:41:37.510698 2026] [security2:error] [pid 178071:tid 178152] [remote 103.118.29.185:12256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4lkRltgi7HBmNwzJNtFgAAG04"], referer: https://mail.verdunestate.com/wp-login.php
[Mon Jul 20 07:41:37.578706 2026] [security2:error] [pid 178071:tid 178284] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lkRltgi7HBmNwzJNtBwAAAFE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:37.675845 2026] [security2:error] [pid 204156:tid 204267] [remote 20.153.140.50:53354] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4lkRbAFPhDXvzP7Sm83wAB-24"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:41:37.755871 2026] [security2:error] [pid 204156:tid 204315] [client 180.249.173.210:51039] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lkRbAFPhDXvzP7Sm84gAAAaw"]
[Mon Jul 20 07:41:37.756706 2026] [security2:error] [pid 204156:tid 204315] [client 180.249.173.210:51039] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lkRbAFPhDXvzP7Sm84gAAAaw"]
[Mon Jul 20 07:41:37.850342 2026] [security2:error] [pid 178071:tid 178192] [remote 154.61.75.100:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4lkRltgi7HBmNwzJNtHgAAM3Y"]
[Mon Jul 20 07:41:37.912568 2026] [security2:error] [pid 178071:tid 178303] [client 36.93.152.155:60065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lkRltgi7HBmNwzJNtIwAAAGQ"]
[Mon Jul 20 07:41:37.912704 2026] [security2:error] [pid 178071:tid 178303] [client 36.93.152.155:60065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lkRltgi7HBmNwzJNtIwAAAGQ"]
[Mon Jul 20 07:41:37.923666 2026] [security2:error] [pid 204156:tid 204301] [client 14.225.17.146:62402] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4lkRbAFPhDXvzP7Sm84QAAAZ4"], referer: http://jvcmotorsports.com/www
[Mon Jul 20 07:41:37.960511 2026] [security2:error] [pid 204156:tid 204359] [client 14.225.17.146:52446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4lkRbAFPhDXvzP7Sm82gAAAdg"], referer: http://idigress.group/www
[Mon Jul 20 07:41:37.978940 2026] [security2:error] [pid 204156:tid 204391] [client 57.141.18.110:62590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lkBbAFPhDXvzP7Sm8tAAB-H4"]
[Mon Jul 20 07:41:38.123324 2026] [security2:error] [pid 204156:tid 204375] [client 57.141.18.57:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lkRbAFPhDXvzP7Sm87wAAAeg"]
[Mon Jul 20 07:41:38.321265 2026] [security2:error] [pid 178071:tid 178173] [remote 154.61.75.100:33706] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.75.61.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4lkhltgi7HBmNwzJNtLgAAAWM"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:41:38.327813 2026] [security2:error] [pid 204156:tid 204369] [client 103.106.165.44:53480] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lkhbAFPhDXvzP7Sm8_wAAAeI"]
[Mon Jul 20 07:41:38.327974 2026] [security2:error] [pid 204156:tid 204369] [client 103.106.165.44:53480] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lkhbAFPhDXvzP7Sm8_wAAAeI"]
[Mon Jul 20 07:41:38.493250 2026] [ssl:error] [pid 178071:tid 178208] [client 66.132.172.111:62218] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname mail.dienerranch.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:41:38.719019 2026] [security2:error] [pid 204156:tid 204374] [client 85.204.70.112:56868] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4lkhbAFPhDXvzP7Sm9HAAAAec"]
[Mon Jul 20 07:41:39.250262 2026] [security2:error] [pid 204156:tid 204407] [client 85.204.70.112:47822] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4lkxbAFPhDXvzP7Sm9LgAAAgg"]
[Mon Jul 20 07:41:39.279529 2026] [security2:error] [pid 178071:tid 178238] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lkxltgi7HBmNwzJNtTAAAACM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:39.455859 2026] [security2:error] [pid 178071:tid 178283] [client 37.52.210.45:27992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lkxltgi7HBmNwzJNtVQAAAFA"]
[Mon Jul 20 07:41:39.456006 2026] [security2:error] [pid 178071:tid 178283] [client 37.52.210.45:27992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lkxltgi7HBmNwzJNtVQAAAFA"]
[Mon Jul 20 07:41:39.685318 2026] [security2:error] [pid 204156:tid 204338] [client 14.225.17.146:62006] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4lkxbAFPhDXvzP7Sm9OAAAAcM"], referer: http://fkconstructionfunding.com/www
[Mon Jul 20 07:41:39.710875 2026] [security2:error] [pid 178071:tid 178317] [client 85.204.70.112:47834] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4lkxltgi7HBmNwzJNtYAAAAHI"]
[Mon Jul 20 07:41:39.869455 2026] [security2:error] [pid 204156:tid 204327] [client 155.2.215.93:29593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lkxbAFPhDXvzP7Sm9SAAAAbg"]
[Mon Jul 20 07:41:40.035545 2026] [security2:error] [pid 204156:tid 204413] [client 112.86.225.163:47170] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thesoloceos.com"] [uri "/"] [unique_id "al4llBbAFPhDXvzP7Sm9UQAAAg4"]
[Mon Jul 20 07:41:40.035643 2026] [security2:error] [pid 204156:tid 204413] [client 112.86.225.163:47170] ModSecurity: Warning. Matched phrase "Sogou web spider" at REQUEST_HEADERS:user-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "www.thesoloceos.com"] [uri "/"] [unique_id "al4llBbAFPhDXvzP7Sm9UQAAAg4"]
[Mon Jul 20 07:41:40.111624 2026] [security2:error] [pid 204156:tid 204299] [client 185.238.231.131:50901] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 131.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4llBbAFPhDXvzP7Sm9VwAAAZw"]
[Mon Jul 20 07:41:40.112134 2026] [security2:error] [pid 204156:tid 204356] [client 185.238.231.248:38887] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 248.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4llBbAFPhDXvzP7Sm9VgAAAdU"]
[Mon Jul 20 07:41:40.173057 2026] [security2:error] [pid 204156:tid 204304] [client 149.0.16.108:63675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4llBbAFPhDXvzP7Sm9WgAAAaE"]
[Mon Jul 20 07:41:40.173687 2026] [security2:error] [pid 204156:tid 204304] [client 149.0.16.108:63675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4llBbAFPhDXvzP7Sm9WgAAAaE"]
[Mon Jul 20 07:41:40.204339 2026] [security2:error] [pid 204156:tid 204369] [client 85.204.70.112:47844] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4llBbAFPhDXvzP7Sm9XAAAAeI"]
[Mon Jul 20 07:41:40.208823 2026] [security2:error] [pid 204156:tid 204334] [client 57.141.18.82:21410] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lkhbAFPhDXvzP7Sm9EQABvwA"]
[Mon Jul 20 07:41:40.248825 2026] [security2:error] [pid 204156:tid 204410] [client 57.141.18.91:49816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lkhbAFPhDXvzP7Sm9HgACCxo"]
[Mon Jul 20 07:41:40.400601 2026] [security2:error] [pid 178071:tid 178266] [client 57.141.18.38:52436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lkhltgi7HBmNwzJNtQQAAPxk"]
[Mon Jul 20 07:41:40.664350 2026] [security2:error] [pid 204156:tid 204370] [client 14.225.17.146:52551] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4llBbAFPhDXvzP7Sm9agAAAeM"], referer: https://fkconstructionfunding.com/www
[Mon Jul 20 07:41:40.671602 2026] [security2:error] [pid 204156:tid 204281] [remote 185.177.72.100:9542] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fdev/.env"] [unique_id "al4llBbAFPhDXvzP7Sm9eQAB7Hw"]
[Mon Jul 20 07:41:40.706578 2026] [security2:error] [pid 178071:tid 178291] [client 85.204.70.112:47856] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4llBltgi7HBmNwzJNtgwAAAFg"]
[Mon Jul 20 07:41:40.878556 2026] [security2:error] [pid 178071:tid 178211] [client 43.166.243.53:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "omenana.com"] [uri "/index.php"] [unique_id "al4llBltgi7HBmNwzJNtgQAAAAg"]
[Mon Jul 20 07:41:41.207557 2026] [security2:error] [pid 178071:tid 178321] [client 85.204.70.112:47866] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4llRltgi7HBmNwzJNtnwAAAHY"]
[Mon Jul 20 07:41:41.269447 2026] [security2:error] [pid 178071:tid 178315] [client 14.225.17.146:50871] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4llRltgi7HBmNwzJNtnAAAAHA"], referer: http://ksands.co.uk/www
[Mon Jul 20 07:41:41.325253 2026] [security2:error] [pid 204156:tid 204192] [remote 113.160.142.119:36928] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 119.142.160.113.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4llRbAFPhDXvzP7Sm9jwABliM"]
[Mon Jul 20 07:41:41.325530 2026] [security2:error] [pid 204156:tid 204293] [client 113.160.142.119:36928] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4llRbAFPhDXvzP7Sm9jwABliM"]
[Mon Jul 20 07:41:41.404424 2026] [security2:error] [pid 204156:tid 204298] [client 168.144.19.97:51694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4llBbAFPhDXvzP7Sm9UwAAAZs"], referer: binance.com
[Mon Jul 20 07:41:41.438984 2026] [security2:error] [pid 178071:tid 178280] [client 154.192.233.184:61222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4llRltgi7HBmNwzJNtqgAAAE0"]
[Mon Jul 20 07:41:41.439091 2026] [security2:error] [pid 178071:tid 178280] [client 154.192.233.184:61222] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4llRltgi7HBmNwzJNtqgAAAE0"]
[Mon Jul 20 07:41:41.472141 2026] [security2:error] [pid 178071:tid 178172] [remote 185.177.72.100:9550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fdev%2f.env"] [unique_id "al4llRltgi7HBmNwzJNtrAAAM2I"]
[Mon Jul 20 07:41:41.623541 2026] [security2:error] [pid 204156:tid 204360] [client 186.221.114.200:54168] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4llRbAFPhDXvzP7Sm9lwAAAdk"]
[Mon Jul 20 07:41:41.623647 2026] [security2:error] [pid 204156:tid 204360] [client 186.221.114.200:54168] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4llRbAFPhDXvzP7Sm9lwAAAdk"]
[Mon Jul 20 07:41:41.648767 2026] [security2:error] [pid 178071:tid 178210] [client 85.204.70.112:47874] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4llRltgi7HBmNwzJNtvAAAAAc"]
[Mon Jul 20 07:41:41.877485 2026] [security2:error] [pid 178071:tid 178281] [client 57.141.18.121:54606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llBltgi7HBmNwzJNtdgAATlI"]
[Mon Jul 20 07:41:41.942143 2026] [security2:error] [pid 178071:tid 178078] [remote 130.51.180.8:48010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4llRltgi7HBmNwzJNtxAAAPwU"]
[Mon Jul 20 07:41:41.990134 2026] [lsapi:warn] [pid 178071:tid 178113] [remote 3.84.124.103:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n, referer: https://www.ali-alghanim.net/
[Mon Jul 20 07:41:42.095389 2026] [security2:error] [pid 178071:tid 178141] [remote 130.51.180.8:48010] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 8.180.51.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4llhltgi7HBmNwzJNtzAAAYUQ"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 07:41:42.103744 2026] [security2:error] [pid 178071:tid 178308] [client 57.141.18.63:36630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llBltgi7HBmNwzJNthgAAaWE"]
[Mon Jul 20 07:41:42.116803 2026] [security2:error] [pid 204156:tid 204333] [client 85.204.70.112:47880] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4llhbAFPhDXvzP7Sm9rgAAAb4"]
[Mon Jul 20 07:41:42.123864 2026] [security2:error] [pid 204156:tid 204299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4llRbAFPhDXvzP7Sm9pgAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:42.177109 2026] [security2:error] [pid 178071:tid 178274] [client 14.225.17.146:49224] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4llRltgi7HBmNwzJNtvgAAAEc"], referer: http://talknutritionwithlesley.com/www
[Mon Jul 20 07:41:42.257123 2026] [security2:error] [pid 204156:tid 204290] [client 57.141.18.59:56304] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llBbAFPhDXvzP7Sm9hAABk3s"]
[Mon Jul 20 07:41:42.312077 2026] [security2:error] [pid 178071:tid 178116] [remote 160.187.68.132:47984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4llhltgi7HBmNwzJNt2AAAOSs"]
[Mon Jul 20 07:41:42.379233 2026] [security2:error] [pid 178071:tid 178296] [client 202.141.11.99:22114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4llhltgi7HBmNwzJNt2wAAAF0"]
[Mon Jul 20 07:41:42.379382 2026] [security2:error] [pid 178071:tid 178296] [client 202.141.11.99:22114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4llhltgi7HBmNwzJNt2wAAAF0"]
[Mon Jul 20 07:41:42.580984 2026] [security2:error] [pid 178071:tid 178239] [client 57.141.18.121:54620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llRltgi7HBmNwzJNtpAAAJA8"]
[Mon Jul 20 07:41:42.835743 2026] [security2:error] [pid 204156:tid 204383] [client 49.37.242.14:55379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4llhbAFPhDXvzP7Sm9ygAAAfA"]
[Mon Jul 20 07:41:42.835843 2026] [security2:error] [pid 204156:tid 204383] [client 49.37.242.14:55379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4llhbAFPhDXvzP7Sm9ygAAAfA"]
[Mon Jul 20 07:41:42.852275 2026] [security2:error] [pid 178071:tid 178216] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4llhltgi7HBmNwzJNt-wAAAA0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:43.122789 2026] [security2:error] [pid 204156:tid 204313] [client 85.204.70.112:47890] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4llxbAFPhDXvzP7Sm91wAAAao"]
[Mon Jul 20 07:41:43.135658 2026] [security2:error] [pid 204156:tid 204402] [client 179.127.84.238:55597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4llxbAFPhDXvzP7Sm92AAAAgM"]
[Mon Jul 20 07:41:43.135832 2026] [security2:error] [pid 204156:tid 204402] [client 179.127.84.238:55597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4llxbAFPhDXvzP7Sm92AAAAgM"]
[Mon Jul 20 07:41:43.146365 2026] [security2:error] [pid 178071:tid 178210] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4llhltgi7HBmNwzJNuBwAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:43.285378 2026] [lsapi:warn] [pid 204156:tid 204202] [remote 3.84.124.103:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:41:43.439033 2026] [security2:error] [pid 178071:tid 178109] [remote 160.187.68.132:47984] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "webgardensbypaula.com"] [uri "/wp-login.php"] [unique_id "al4llxltgi7HBmNwzJNuIQAAYSQ"], referer: https://webgardensbypaula.com/wp-login.php
[Mon Jul 20 07:41:43.507360 2026] [security2:error] [pid 204156:tid 204309] [client 17.22.237.4:54766] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4llxbAFPhDXvzP7Sm96wABph0"]
[Mon Jul 20 07:41:43.525491 2026] [security2:error] [pid 204156:tid 204400] [client 57.141.18.75:48412] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llhbAFPhDXvzP7Sm9sAACARk"]
[Mon Jul 20 07:41:43.629826 2026] [security2:error] [pid 204156:tid 204330] [client 14.225.17.146:58530] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4llxbAFPhDXvzP7Sm97QAAAbs"], referer: http://entuvy.com/www
[Mon Jul 20 07:41:43.827673 2026] [security2:error] [pid 204156:tid 204335] [client 143.44.185.218:50858] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 218.185.44.143.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4llxbAFPhDXvzP7Sm9_AAAAcA"]
[Mon Jul 20 07:41:43.828091 2026] [security2:error] [pid 204156:tid 204335] [client 143.44.185.218:50858] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ghivs.com"] [uri "/xmlrpc.php"] [unique_id "al4llxbAFPhDXvzP7Sm9_AAAAcA"]
[Mon Jul 20 07:41:44.028764 2026] [security2:error] [pid 204156:tid 204311] [client 85.204.70.112:47902] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4lmBbAFPhDXvzP7Sm-AgAAAag"]
[Mon Jul 20 07:41:44.062509 2026] [security2:error] [pid 204156:tid 204347] [client 103.139.191.61:53037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-BQAAAcw"]
[Mon Jul 20 07:41:44.062629 2026] [security2:error] [pid 204156:tid 204347] [client 103.139.191.61:53037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-BQAAAcw"]
[Mon Jul 20 07:41:44.177398 2026] [security2:error] [pid 204156:tid 204209] [remote 47.128.58.148:56938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "gertoger.org"] [uri "/tour/mongolia-offroad-overland-jeep-tours-mongolia-naadam-festival/"] [unique_id "al4lmBbAFPhDXvzP7Sm-EgABtzQ"]
[Mon Jul 20 07:41:44.343604 2026] [core:error] [pid 204156:tid 204318] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:44.343625 2026] [core:error] [pid 204156:tid 204318] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:44.361472 2026] [core:error] [pid 178071:tid 178304] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:44.361495 2026] [core:error] [pid 178071:tid 178304] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:44.569018 2026] [security2:error] [pid 204156:tid 204332] [client 130.210.6.241:50456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-JgAAAb0"], referer: https://duckduckgo.com/
[Mon Jul 20 07:41:44.589770 2026] [security2:error] [pid 178071:tid 178223] [client 57.141.18.42:22956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llxltgi7HBmNwzJNuEQAAFGc"]
[Mon Jul 20 07:41:44.797501 2026] [security2:error] [pid 178071:tid 178210] [client 69.109.98.0:1940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4lmBltgi7HBmNwzJNuXgAAB2o"]
[Mon Jul 20 07:41:44.807319 2026] [security2:error] [pid 178071:tid 178210] [client 69.109.98.0:1940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4lmBltgi7HBmNwzJNuXQAAB2g"]
[Mon Jul 20 07:41:44.820812 2026] [security2:error] [pid 204156:tid 204397] [client 114.119.129.199:49205] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sanifidensolutions.com"] [uri "/"] [unique_id "al4lmBbAFPhDXvzP7Sm-NQAAAf4"], referer: https://sidhulawyers.com.au/sitemap_quality_9.xml
[Mon Jul 20 07:41:44.837937 2026] [security2:error] [pid 178071:tid 178210] [client 69.109.98.0:1940] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vfcthomasville.org"] [uri "/index.php"] [unique_id "al4lmBltgi7HBmNwzJNuXAAAByc"]
[Mon Jul 20 07:41:44.942338 2026] [security2:error] [pid 204156:tid 204385] [client 14.225.17.146:61930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-MgAAAfI"], referer: https://north-woods-engineering.com/www
[Mon Jul 20 07:41:45.012355 2026] [security2:error] [pid 204156:tid 204368] [client 193.37.33.23:26021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-OwAAAeE"]
[Mon Jul 20 07:41:45.049502 2026] [security2:error] [pid 178071:tid 178279] [client 50.116.65.227:12396] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lmRltgi7HBmNwzJNubgAAAEw"]
[Mon Jul 20 07:41:45.060177 2026] [security2:error] [pid 178071:tid 178237] [client 130.210.6.241:50505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4lmRltgi7HBmNwzJNubwAAACI"], referer: https://t.co/
[Mon Jul 20 07:41:45.062212 2026] [security2:error] [pid 204156:tid 204341] [client 50.116.65.227:12406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lmRbAFPhDXvzP7Sm-PQAAAcY"]
[Mon Jul 20 07:41:45.070140 2026] [security2:error] [pid 178071:tid 178229] [client 57.141.18.11:41386] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4llxltgi7HBmNwzJNuJgAAGlc"]
[Mon Jul 20 07:41:45.265242 2026] [security2:error] [pid 204156:tid 204214] [remote 185.177.72.100:9570] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fstaging/.env"] [unique_id "al4lmRbAFPhDXvzP7Sm-RQAB5jk"]
[Mon Jul 20 07:41:45.308520 2026] [security2:error] [pid 204156:tid 204349] [client 14.225.17.146:52519] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-OAAAAc4"], referer: http://mcg.homes/www
[Mon Jul 20 07:41:45.449500 2026] [security2:error] [pid 178071:tid 178298] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lmRltgi7HBmNwzJNuegAAAF8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:45.599465 2026] [security2:error] [pid 178071:tid 178310] [client 191.202.66.27:50743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lmRltgi7HBmNwzJNuiQAAAGs"]
[Mon Jul 20 07:41:45.599586 2026] [security2:error] [pid 178071:tid 178310] [client 191.202.66.27:50743] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lmRltgi7HBmNwzJNuiQAAAGs"]
[Mon Jul 20 07:41:45.609981 2026] [security2:error] [pid 178071:tid 178235] [client 49.47.218.174:56274] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lmRltgi7HBmNwzJNuigAAACA"]
[Mon Jul 20 07:41:45.610101 2026] [security2:error] [pid 178071:tid 178235] [client 49.47.218.174:56274] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lmRltgi7HBmNwzJNuigAAACA"]
[Mon Jul 20 07:41:45.627760 2026] [security2:error] [pid 178071:tid 178282] [client 85.204.70.112:47918] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4lmRltgi7HBmNwzJNujQAAAE8"]
[Mon Jul 20 07:41:45.763339 2026] [security2:error] [pid 204156:tid 204308] [client 193.37.33.52:46245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4lmRbAFPhDXvzP7Sm-awAAAaU"]
[Mon Jul 20 07:41:45.887569 2026] [security2:error] [pid 204156:tid 204323] [client 57.141.18.67:54954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lmBbAFPhDXvzP7Sm-HgABtEc"]
[Mon Jul 20 07:41:45.914604 2026] [core:error] [pid 178071:tid 178223] [client 82.39.212.219:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:45.914626 2026] [core:error] [pid 178071:tid 178223] [client 82.39.212.219:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:46.038588 2026] [security2:error] [pid 178071:tid 178256] [client 85.204.70.112:47922] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4lmhltgi7HBmNwzJNunAAAADU"]
[Mon Jul 20 07:41:46.117036 2026] [security2:error] [pid 204156:tid 204247] [remote 185.177.72.100:9586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fstaging%2f.env"] [unique_id "al4lmhbAFPhDXvzP7Sm-hgAB9lo"]
[Mon Jul 20 07:41:46.299057 2026] [security2:error] [pid 178071:tid 178299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lmhltgi7HBmNwzJNunwAAAGA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:46.436668 2026] [security2:error] [pid 204156:tid 204310] [client 130.210.6.241:50532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.6.210.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "inspirespublishing.com"] [uri "/wp-login.php"] [unique_id "al4lmhbAFPhDXvzP7Sm-lQAAAac"]
[Mon Jul 20 07:41:46.537402 2026] [core:error] [pid 178071:tid 178315] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:46.537423 2026] [core:error] [pid 178071:tid 178315] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:46.554978 2026] [security2:error] [pid 178071:tid 178153] [remote 217.61.143.92:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4lmhltgi7HBmNwzJNutQAAGk8"]
[Mon Jul 20 07:41:46.579703 2026] [security2:error] [pid 204156:tid 204199] [remote 160.187.68.132:47990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lmhbAFPhDXvzP7Sm-mAABoSo"]
[Mon Jul 20 07:41:46.723079 2026] [security2:error] [pid 204156:tid 204399] [client 14.225.17.146:62098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4lmRbAFPhDXvzP7Sm-RwAAAgA"], referer: http://expertcultures.com/www
[Mon Jul 20 07:41:46.762481 2026] [security2:error] [pid 178071:tid 178260] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lmhltgi7HBmNwzJNutAAAADk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:46.786866 2026] [security2:error] [pid 178071:tid 178228] [client 136.158.60.21:36293] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lmhltgi7HBmNwzJNuxQAAABk"]
[Mon Jul 20 07:41:46.787009 2026] [security2:error] [pid 178071:tid 178228] [client 136.158.60.21:36293] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lmhltgi7HBmNwzJNuxQAAABk"]
[Mon Jul 20 07:41:46.790380 2026] [security2:error] [pid 178071:tid 178087] [remote 217.61.143.92:42216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "colt-in.com"] [uri "/wp-login.php"] [unique_id "al4lmhltgi7HBmNwzJNuxgAANw4"], referer: https://colt-in.com/wp-login.php
[Mon Jul 20 07:41:46.806344 2026] [security2:error] [pid 178071:tid 178159] [remote 91.142.222.105:48704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4lmhltgi7HBmNwzJNuxwAAd1U"]
[Mon Jul 20 07:41:46.940167 2026] [security2:error] [pid 178071:tid 178277] [client 45.157.112.60:28915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lmhltgi7HBmNwzJNu1AAAAEo"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:41:46.971704 2026] [security2:error] [pid 204156:tid 204347] [client 14.225.17.146:62080] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4lmRbAFPhDXvzP7Sm-QwAAAcw"], referer: http://bigwormfishing.com/www
[Mon Jul 20 07:41:47.042213 2026] [security2:error] [pid 178071:tid 178168] [remote 91.142.222.105:48704] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "solkeetw.com"] [uri "/wp-login.php"] [unique_id "al4lmxltgi7HBmNwzJNu2QAAe14"], referer: https://solkeetw.com/wp-login.php
[Mon Jul 20 07:41:47.058264 2026] [security2:error] [pid 204156:tid 204275] [remote 57.141.18.22:36576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 22.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2585688"] [unique_id "al4lmxbAFPhDXvzP7Sm-qQACC3Y"]
[Mon Jul 20 07:41:47.146843 2026] [security2:error] [pid 204156:tid 204397] [client 57.141.18.5:54634] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lmRbAFPhDXvzP7Sm-YQAB_lQ"]
[Mon Jul 20 07:41:47.238264 2026] [security2:error] [pid 178071:tid 178217] [client 14.225.17.146:61999] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4lmhltgi7HBmNwzJNuzAAAAA4"], referer: http://mollycahill.com/www
[Mon Jul 20 07:41:47.490230 2026] [security2:error] [pid 204156:tid 204406] [client 57.141.18.105:61552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lmRbAFPhDXvzP7Sm-gQACB1E"]
[Mon Jul 20 07:41:47.835235 2026] [security2:error] [pid 204156:tid 204291] [client 57.141.18.113:62902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lmhbAFPhDXvzP7Sm-lgABlFI"]
[Mon Jul 20 07:41:47.864190 2026] [security2:error] [pid 178071:tid 178294] [client 57.141.18.80:46818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lmhltgi7HBmNwzJNutgAAWxw"]
[Mon Jul 20 07:41:47.924870 2026] [security2:error] [pid 204156:tid 204248] [remote 160.187.68.132:47990] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lmxbAFPhDXvzP7Sm-0wAB5ls"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:41:47.972678 2026] [security2:error] [pid 204156:tid 204413] [client 14.225.17.146:50606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4lmxbAFPhDXvzP7Sm-zAAAAg4"], referer: https://bigwormfishing.com/www
[Mon Jul 20 07:41:48.021831 2026] [security2:error] [pid 204156:tid 204407] [client 85.204.70.112:47938] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4lnBbAFPhDXvzP7Sm-2AAAAgg"]
[Mon Jul 20 07:41:48.257535 2026] [core:error] [pid 204156:tid 204411] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:48.257560 2026] [core:error] [pid 204156:tid 204411] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:48.454138 2026] [security2:error] [pid 204156:tid 204387] [client 36.93.152.155:60600] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lnBbAFPhDXvzP7Sm-9gAAAfQ"]
[Mon Jul 20 07:41:48.454238 2026] [security2:error] [pid 204156:tid 204387] [client 36.93.152.155:60600] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lnBbAFPhDXvzP7Sm-9gAAAfQ"]
[Mon Jul 20 07:41:48.538940 2026] [security2:error] [pid 204156:tid 204325] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lnBbAFPhDXvzP7Sm-5wAAAbY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:48.579279 2026] [security2:error] [pid 204156:tid 204293] [client 14.225.17.146:50505] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4lmhbAFPhDXvzP7Sm-kQAAAZY"], referer: http://adastra.love/www
[Mon Jul 20 07:41:48.799820 2026] [security2:error] [pid 178071:tid 178261] [client 103.106.165.44:53971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lnBltgi7HBmNwzJNvDgAAADo"]
[Mon Jul 20 07:41:48.799932 2026] [security2:error] [pid 178071:tid 178261] [client 103.106.165.44:53971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lnBltgi7HBmNwzJNvDgAAADo"]
[Mon Jul 20 07:41:48.808704 2026] [security2:error] [pid 204156:tid 204399] [client 65.111.23.34:52501] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lnBbAFPhDXvzP7Sm_AgAAAgA"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:41:48.837436 2026] [security2:error] [pid 204156:tid 204401] [client 46.110.96.34:22581] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4lnBbAFPhDXvzP7Sm_BAAAAgI"]
[Mon Jul 20 07:41:48.875975 2026] [security2:error] [pid 204156:tid 204350] [client 180.249.173.210:51551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lnBbAFPhDXvzP7Sm_BQAAAc8"]
[Mon Jul 20 07:41:48.876096 2026] [security2:error] [pid 204156:tid 204350] [client 180.249.173.210:51551] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lnBbAFPhDXvzP7Sm_BQAAAc8"]
[Mon Jul 20 07:41:48.989025 2026] [security2:error] [pid 204156:tid 204359] [client 57.141.18.50:22536] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lmxbAFPhDXvzP7Sm-xAAB2AE"]
[Mon Jul 20 07:41:48.989148 2026] [security2:error] [pid 178071:tid 178249] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lnBltgi7HBmNwzJNvDQAAAC4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:49.018307 2026] [security2:error] [pid 204156:tid 204409] [client 168.144.19.97:57129] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4lnBbAFPhDXvzP7Sm-2gAAAgo"], referer: binance.com
[Mon Jul 20 07:41:49.894379 2026] [security2:error] [pid 204156:tid 204172] [remote 185.177.72.100:3774] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fprod/.env"] [unique_id "al4lnRbAFPhDXvzP7Sm_KAAB1w8"]
[Mon Jul 20 07:41:50.063193 2026] [security2:error] [pid 204156:tid 204317] [client 37.52.210.45:50066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_MAAAAa4"]
[Mon Jul 20 07:41:50.063331 2026] [security2:error] [pid 204156:tid 204317] [client 37.52.210.45:50066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_MAAAAa4"]
[Mon Jul 20 07:41:50.156081 2026] [security2:error] [pid 178071:tid 178281] [client 188.39.109.162:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.origine.nz"] [uri "/index.php"] [unique_id "al4lnRltgi7HBmNwzJNvNQAATn4"]
[Mon Jul 20 07:41:50.275620 2026] [security2:error] [pid 204156:tid 204397] [client 14.225.17.146:53506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_MwAAAf4"], referer: http://cheesewithjam.com/www
[Mon Jul 20 07:41:50.320916 2026] [security2:error] [pid 204156:tid 204407] [client 155.2.215.95:47243] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_OwAAAgg"]
[Mon Jul 20 07:41:50.678435 2026] [security2:error] [pid 204156:tid 204173] [remote 185.177.72.100:3776] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fprod%2f.env"] [unique_id "al4lnhbAFPhDXvzP7Sm_TwABxxA"]
[Mon Jul 20 07:41:50.689141 2026] [security2:error] [pid 204156:tid 204289] [client 114.119.159.145:64187] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "crmpfilms.com"] [uri "/deerag/files/stacks-image-be697cd.jpg"] [unique_id "al4lnhbAFPhDXvzP7Sm_UAAAAZI"], referer: http://crmpfilms.com/deerag/files/stacks-image-be697cd.jpg
[Mon Jul 20 07:41:50.769262 2026] [security2:error] [pid 204156:tid 204311] [client 149.0.16.108:64208] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_UwAAAag"]
[Mon Jul 20 07:41:50.769396 2026] [security2:error] [pid 204156:tid 204311] [client 149.0.16.108:64208] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_UwAAAag"]
[Mon Jul 20 07:41:50.902999 2026] [security2:error] [pid 204156:tid 204308] [client 57.141.18.13:38948] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lnRbAFPhDXvzP7Sm_IQABpWg"]
[Mon Jul 20 07:41:50.932196 2026] [security2:error] [pid 204156:tid 204193] [remote 57.141.18.1:35440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 1.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4288165"] [unique_id "al4lnhbAFPhDXvzP7Sm_WAABlyQ"]
[Mon Jul 20 07:41:51.026097 2026] [security2:error] [pid 204156:tid 204375] [client 14.225.17.146:53594] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4lnhbAFPhDXvzP7Sm_VQAAAeg"], referer: http://longevityperformanceclinic.com/www
[Mon Jul 20 07:41:51.133965 2026] [security2:error] [pid 204156:tid 204312] [client 57.141.18.121:26024] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lnRbAFPhDXvzP7Sm_KgABqQ0"]
[Mon Jul 20 07:41:51.935052 2026] [security2:error] [pid 178071:tid 178253] [client 154.192.233.184:61643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lnxltgi7HBmNwzJNvtwAAADI"]
[Mon Jul 20 07:41:51.935159 2026] [security2:error] [pid 178071:tid 178253] [client 154.192.233.184:61643] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lnxltgi7HBmNwzJNvtwAAADI"]
[Mon Jul 20 07:41:51.982815 2026] [security2:error] [pid 204156:tid 204304] [client 13.233.207.33:38744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lnxbAFPhDXvzP7Sm_kwAAAaE"]
[Mon Jul 20 07:41:51.982905 2026] [security2:error] [pid 204156:tid 204304] [client 13.233.207.33:38744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4lnxbAFPhDXvzP7Sm_kwAAAaE"]
[Mon Jul 20 07:41:52.065847 2026] [security2:error] [pid 178071:tid 178207] [client 14.224.227.113:58702] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4loBltgi7HBmNwzJNvuwAAAAQ"]
[Mon Jul 20 07:41:52.314872 2026] [security2:error] [pid 204156:tid 204385] [client 57.141.18.87:61152] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lnxbAFPhDXvzP7Sm_YwAB8iE"]
[Mon Jul 20 07:41:52.449197 2026] [security2:error] [pid 178071:tid 178306] [client 188.166.209.66:54621] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/fonts/class-wp-font-collection.php"] [unique_id "al4loBltgi7HBmNwzJNvzgAAAGc"], referer: binance.com
[Mon Jul 20 07:41:52.603658 2026] [security2:error] [pid 204156:tid 204315] [client 14.225.17.146:53491] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4lnxbAFPhDXvzP7Sm_fAAAAaw"], referer: http://elitetax-mi.com/www
[Mon Jul 20 07:41:52.624333 2026] [security2:error] [pid 204156:tid 204309] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4loBbAFPhDXvzP7Sm_pwAAAaY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:52.669052 2026] [security2:error] [pid 204156:tid 204369] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4loBbAFPhDXvzP7Sm_qgAAAeI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:52.789503 2026] [security2:error] [pid 204156:tid 204398] [client 14.225.17.146:54260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4loBbAFPhDXvzP7Sm_twAAAf8"], referer: http://vinovinhowine.com/www
[Mon Jul 20 07:41:52.905315 2026] [security2:error] [pid 204156:tid 204383] [client 14.225.17.146:53494] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4lnxbAFPhDXvzP7Sm_ewAAAfA"], referer: http://margaretspeckogawa.com/www
[Mon Jul 20 07:41:52.952528 2026] [security2:error] [pid 178071:tid 178241] [client 14.225.17.146:53064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4loBltgi7HBmNwzJNvzAAAACY"], referer: http://drewsasburyparkbeachhouse.com/www
[Mon Jul 20 07:41:52.954124 2026] [security2:error] [pid 204156:tid 204378] [client 66.249.73.15:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php/login"] [unique_id "al4loBbAFPhDXvzP7Sm_ugAAAes"]
[Mon Jul 20 07:41:52.955982 2026] [security2:error] [pid 204156:tid 204382] [client 66.249.73.15:63430] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php/login"] [unique_id "al4loBbAFPhDXvzP7Sm_tgAAAe8"]
[Mon Jul 20 07:41:52.957510 2026] [security2:error] [pid 204156:tid 204397] [client 14.225.17.146:53059] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4loBbAFPhDXvzP7Sm_nAAAAf4"], referer: http://processorstudio.com/www
[Mon Jul 20 07:41:53.011876 2026] [security2:error] [pid 204156:tid 204351] [client 54.224.22.173:10050] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.22.224.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4loRbAFPhDXvzP7Sm_vwAAAdA"], referer: https://curlsnpearlsss.com/es/tag/what-to-serve-with-air-fryer-fried-chicken/
[Mon Jul 20 07:41:53.160271 2026] [security2:error] [pid 204156:tid 204299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4loBbAFPhDXvzP7Sm_vQAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:53.193450 2026] [security2:error] [pid 178071:tid 178303] [client 14.225.17.146:53153] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4loBltgi7HBmNwzJNv3wAAAGQ"], referer: http://transparentservices.online/www
[Mon Jul 20 07:41:53.362944 2026] [security2:error] [pid 178071:tid 178322] [client 66.249.73.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php/login"] [unique_id "al4loRltgi7HBmNwzJNv8QAAAHc"]
[Mon Jul 20 07:41:53.397466 2026] [security2:error] [pid 178071:tid 178204] [client 186.221.114.200:54654] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4loRltgi7HBmNwzJNv-gAAAAE"]
[Mon Jul 20 07:41:53.397612 2026] [security2:error] [pid 178071:tid 178204] [client 186.221.114.200:54654] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4loRltgi7HBmNwzJNv-gAAAAE"]
[Mon Jul 20 07:41:53.444281 2026] [security2:error] [pid 204156:tid 204366] [client 66.249.73.2:53076] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cira.org"] [uri "/index.php/login"] [unique_id "al4loRbAFPhDXvzP7Sm_wAAAAd8"]
[Mon Jul 20 07:41:53.677742 2026] [security2:error] [pid 178071:tid 178254] [client 179.127.84.238:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4loRltgi7HBmNwzJNwDQAAADM"]
[Mon Jul 20 07:41:53.677948 2026] [security2:error] [pid 178071:tid 178254] [client 179.127.84.238:56128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4loRltgi7HBmNwzJNwDQAAADM"]
[Mon Jul 20 07:41:53.711970 2026] [security2:error] [pid 204156:tid 204371] [client 74.7.244.13:0] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4loRbAFPhDXvzP7Sm_2QAAAeQ"]
[Mon Jul 20 07:41:53.714854 2026] [security2:error] [pid 178071:tid 178320] [client 74.7.244.13:50686] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "adirondackengineering.com"] [uri "/robots.txt"] [unique_id "al4loRltgi7HBmNwzJNwBwAAdWc"]
[Mon Jul 20 07:41:53.755601 2026] [security2:error] [pid 178071:tid 178247] [client 13.233.207.33:38754] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4loRltgi7HBmNwzJNwEwAAACw"]
[Mon Jul 20 07:41:53.830374 2026] [security2:error] [pid 178071:tid 178308] [client 14.225.17.146:54352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4loRltgi7HBmNwzJNwFAAAAGk"], referer: https://processorstudio.com/www
[Mon Jul 20 07:41:53.882908 2026] [security2:error] [pid 178071:tid 178235] [client 103.139.191.61:53548] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4loRltgi7HBmNwzJNwGgAAACA"]
[Mon Jul 20 07:41:53.882999 2026] [security2:error] [pid 178071:tid 178235] [client 103.139.191.61:53548] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4loRltgi7HBmNwzJNwGgAAACA"]
[Mon Jul 20 07:41:53.967685 2026] [security2:error] [pid 204156:tid 204302] [client 14.225.17.146:54443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4loRbAFPhDXvzP7Sm_3QAAAZ8"], referer: http://koaconsultants.com/www
[Mon Jul 20 07:41:54.185923 2026] [security2:error] [pid 178071:tid 178301] [client 66.249.73.1:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4loRltgi7HBmNwzJNwIgAAAGI"]
[Mon Jul 20 07:41:54.267282 2026] [proxy:error] [pid 204156:tid 204305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:41:54.267328 2026] [proxy_http:error] [pid 204156:tid 204305] [client 23.180.120.145:33142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:41:54.267940 2026] [proxy:error] [pid 204156:tid 204305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:41:54.267965 2026] [proxy_http:error] [pid 204156:tid 204305] [client 23.180.120.145:33142] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:41:54.306913 2026] [security2:error] [pid 178071:tid 178154] [remote 185.177.72.100:3812] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fbackup/.env"] [unique_id "al4lohltgi7HBmNwzJNwMAAAVVA"]
[Mon Jul 20 07:41:54.355838 2026] [security2:error] [pid 178071:tid 178121] [remote 91.142.222.105:37986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lohltgi7HBmNwzJNwMQAARjA"]
[Mon Jul 20 07:41:54.610710 2026] [security2:error] [pid 178071:tid 178165] [remote 91.142.222.105:37986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lohltgi7HBmNwzJNwOQAAals"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:41:54.733505 2026] [security2:error] [pid 204156:tid 204304] [client 43.205.139.3:23960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4lohbAFPhDXvzP7SnABAAAAaE"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:41:54.783881 2026] [security2:error] [pid 204156:tid 204381] [client 66.249.73.2:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "cira.org"] [uri "/index.php"] [unique_id "al4lohbAFPhDXvzP7Sm_-gAAAe4"]
[Mon Jul 20 07:41:54.832647 2026] [security2:error] [pid 204156:tid 204215] [remote 20.153.140.50:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lohbAFPhDXvzP7SnACwAB0Do"]
[Mon Jul 20 07:41:54.877576 2026] [security2:error] [pid 204156:tid 204314] [client 188.166.209.66:64679] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/fonts/class-wp-font-face-resolver.php"] [unique_id "al4lohbAFPhDXvzP7SnADAAAAas"], referer: binance.com
[Mon Jul 20 07:41:54.922994 2026] [security2:error] [pid 204156:tid 204403] [client 14.225.17.146:54404] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4lohbAFPhDXvzP7SnABQAAAgQ"], referer: http://ghivs.com/www
[Mon Jul 20 07:41:55.061517 2026] [security2:error] [pid 204156:tid 204346] [client 217.181.90.132:30251] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.90.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/xmlrpc.php"] [unique_id "al4loxbAFPhDXvzP7SnAFQAAAcs"]
[Mon Jul 20 07:41:55.066517 2026] [security2:error] [pid 204156:tid 204187] [remote 103.187.23.21:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4loxbAFPhDXvzP7SnAFgAB6B4"]
[Mon Jul 20 07:41:55.088291 2026] [security2:error] [pid 178071:tid 178219] [client 57.141.18.72:20392] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4loRltgi7HBmNwzJNwHQAAEFM"]
[Mon Jul 20 07:41:55.123055 2026] [security2:error] [pid 204156:tid 204221] [remote 185.177.72.100:3816] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fbackup%2f.env"] [unique_id "al4loxbAFPhDXvzP7SnAIAABkEA"]
[Mon Jul 20 07:41:55.230141 2026] [security2:error] [pid 204156:tid 204219] [remote 20.153.140.50:59604] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4loxbAFPhDXvzP7SnAJAAB_z4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:41:55.259324 2026] [security2:error] [pid 178071:tid 178212] [client 14.225.17.146:53181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4lohltgi7HBmNwzJNwLQAAAAk"], referer: http://laceycaraccident.com/www
[Mon Jul 20 07:41:55.297477 2026] [security2:error] [pid 178071:tid 178275] [client 14.225.17.146:54500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4loRltgi7HBmNwzJNwHwAAAEg"], referer: http://backandneckpainrelieflaceychiropractor.com/www
[Mon Jul 20 07:41:55.345533 2026] [security2:error] [pid 204156:tid 204308] [client 57.141.18.62:57012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lohbAFPhDXvzP7Sm_5QABpSw"]
[Mon Jul 20 07:41:55.578200 2026] [security2:error] [pid 204156:tid 204230] [remote 103.187.23.21:59098] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.23.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.group"] [uri "/wp-login.php"] [unique_id "al4loxbAFPhDXvzP7SnALwACDkk"], referer: https://idigress.group/wp-login.php
[Mon Jul 20 07:41:55.626863 2026] [security2:error] [pid 204156:tid 204292] [client 45.3.43.97:59113] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.43.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4loxbAFPhDXvzP7SnAMQAAAZU"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:41:55.674176 2026] [security2:error] [pid 204156:tid 204330] [client 49.37.242.14:55918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4loxbAFPhDXvzP7SnANQAAAbs"]
[Mon Jul 20 07:41:55.674270 2026] [security2:error] [pid 204156:tid 204330] [client 49.37.242.14:55918] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4loxbAFPhDXvzP7SnANQAAAbs"]
[Mon Jul 20 07:41:55.985392 2026] [security2:error] [pid 178071:tid 178100] [remote 57.141.18.95:22638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3468343"] [unique_id "al4loxltgi7HBmNwzJNwYwAAcBs"]
[Mon Jul 20 07:41:56.116457 2026] [security2:error] [pid 204156:tid 204395] [client 49.47.218.174:56814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lpBbAFPhDXvzP7SnARgAAAfw"]
[Mon Jul 20 07:41:56.116567 2026] [security2:error] [pid 204156:tid 204395] [client 49.47.218.174:56814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lpBbAFPhDXvzP7SnARgAAAfw"]
[Mon Jul 20 07:41:56.194063 2026] [security2:error] [pid 204156:tid 204369] [client 57.141.18.99:35048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4loxbAFPhDXvzP7SnAIQAB4k4"]
[Mon Jul 20 07:41:56.238415 2026] [security2:error] [pid 204156:tid 204403] [client 191.202.66.27:51233] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lpBbAFPhDXvzP7SnATwAAAgQ"]
[Mon Jul 20 07:41:56.238542 2026] [security2:error] [pid 204156:tid 204403] [client 191.202.66.27:51233] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lpBbAFPhDXvzP7SnATwAAAgQ"]
[Mon Jul 20 07:41:56.594065 2026] [authz_core:error] [pid 204156:tid 204309] [client 168.144.19.97:50895] AH01630: client denied by server configuration: /home1/polishe5/public_html/wp-admin/includes/error_log, referer: binance.com
[Mon Jul 20 07:41:56.814913 2026] [security2:error] [pid 204156:tid 204370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lpBbAFPhDXvzP7SnAXwAAAeM"]
[Mon Jul 20 07:41:56.849738 2026] [security2:error] [pid 178071:tid 178280] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lpBltgi7HBmNwzJNwdQAAAE0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:57.087161 2026] [security2:error] [pid 204156:tid 204333] [client 57.141.18.84:56194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lpBbAFPhDXvzP7SnAPwABvkY"]
[Mon Jul 20 07:41:57.109392 2026] [security2:error] [pid 178071:tid 178225] [client 43.156.142.168:50583] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.samdothan.org"] [uri "/wp-admin/index.php"] [unique_id "al4lpBltgi7HBmNwzJNwhQAAABY"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:41:57.337201 2026] [security2:error] [pid 204156:tid 204377] [client 188.166.209.66:63179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/fonts/class-wp-font-face.php"] [unique_id "al4lpRbAFPhDXvzP7SnAigAAAeo"], referer: binance.com
[Mon Jul 20 07:41:57.465789 2026] [security2:error] [pid 178071:tid 178217] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lpRltgi7HBmNwzJNwjAAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:41:57.527963 2026] [security2:error] [pid 204156:tid 204325] [client 136.158.60.21:37856] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lpRbAFPhDXvzP7SnAjwAAAbY"]
[Mon Jul 20 07:41:57.528095 2026] [security2:error] [pid 204156:tid 204325] [client 136.158.60.21:37856] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lpRbAFPhDXvzP7SnAjwAAAbY"]
[Mon Jul 20 07:41:57.965131 2026] [security2:error] [pid 204156:tid 204224] [remote 20.173.88.122:35068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4lpRbAFPhDXvzP7SnAngABskM"]
[Mon Jul 20 07:41:58.304598 2026] [security2:error] [pid 204156:tid 204247] [remote 20.173.88.122:35068] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "idigress.studio"] [uri "/wp-login.php"] [unique_id "al4lphbAFPhDXvzP7SnApwAByVo"], referer: https://idigress.studio/wp-login.php
[Mon Jul 20 07:41:58.402378 2026] [security2:error] [pid 204156:tid 204408] [client 57.141.18.103:26754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lpRbAFPhDXvzP7SnAgwACCVc"]
[Mon Jul 20 07:41:58.409350 2026] [security2:error] [pid 204156:tid 204345] [client 57.141.18.59:23798] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lpRbAFPhDXvzP7SnAhwAByjs"]
[Mon Jul 20 07:41:58.712513 2026] [security2:error] [pid 178071:tid 178223] [client 57.141.18.50:28240] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lpRltgi7HBmNwzJNwmgAAFCs"]
[Mon Jul 20 07:41:58.862962 2026] [security2:error] [pid 204156:tid 204374] [client 180.249.173.210:52064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lphbAFPhDXvzP7SnAwAAAAec"]
[Mon Jul 20 07:41:58.863376 2026] [security2:error] [pid 204156:tid 204374] [client 180.249.173.210:52064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lphbAFPhDXvzP7SnAwAAAAec"]
[Mon Jul 20 07:41:58.867662 2026] [security2:error] [pid 178071:tid 178236] [client 35.222.199.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.marketingonetoone.net"] [uri "/index.php"] [unique_id "al4lpRltgi7HBmNwzJNwlAAAACE"], referer: http://salco-ce.marketingonetoone.net
[Mon Jul 20 07:41:58.973127 2026] [security2:error] [pid 204156:tid 204317] [client 36.93.152.155:61129] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lphbAFPhDXvzP7SnAxAAAAa4"]
[Mon Jul 20 07:41:58.973238 2026] [security2:error] [pid 204156:tid 204317] [client 36.93.152.155:61129] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lphbAFPhDXvzP7SnAxAAAAa4"]
[Mon Jul 20 07:41:58.998120 2026] [security2:error] [pid 204156:tid 204242] [remote 185.177.72.100:26510] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2flaravel/.env"] [unique_id "al4lphbAFPhDXvzP7SnAxQAB31U"]
[Mon Jul 20 07:41:59.006279 2026] [security2:error] [pid 204156:tid 204349] [client 85.204.70.112:33092] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4lpxbAFPhDXvzP7SnAxgAAAc4"]
[Mon Jul 20 07:41:59.010609 2026] [proxy:error] [pid 204156:tid 204325] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:41:59.010643 2026] [proxy_http:error] [pid 204156:tid 204325] [client 107.161.92.6:52888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:41:59.011456 2026] [proxy:error] [pid 204156:tid 204325] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:41:59.011497 2026] [proxy_http:error] [pid 204156:tid 204325] [client 107.161.92.6:52888] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:41:59.152194 2026] [security2:error] [pid 204156:tid 204328] [client 188.166.209.66:54085] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/fonts/class-wp-font-library.php"] [unique_id "al4lpxbAFPhDXvzP7SnAzgAAAbk"], referer: binance.com
[Mon Jul 20 07:41:59.168387 2026] [security2:error] [pid 204156:tid 204316] [client 103.106.165.44:54457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lpxbAFPhDXvzP7SnA0AAAAa0"]
[Mon Jul 20 07:41:59.168543 2026] [security2:error] [pid 204156:tid 204316] [client 103.106.165.44:54457] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lpxbAFPhDXvzP7SnA0AAAAa0"]
[Mon Jul 20 07:41:59.426118 2026] [security2:error] [pid 204156:tid 204327] [client 98.159.234.160:39833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lpxbAFPhDXvzP7SnA2wAAAbg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:41:59.579546 2026] [security2:error] [pid 204156:tid 204369] [client 57.141.18.25:60652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lphbAFPhDXvzP7SnArwAB4ms"]
[Mon Jul 20 07:41:59.674872 2026] [security2:error] [pid 204156:tid 204399] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lpxbAFPhDXvzP7SnA3gAAAgA"]
[Mon Jul 20 07:41:59.709285 2026] [security2:error] [pid 204156:tid 204238] [remote 160.187.68.132:42576] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lpxbAFPhDXvzP7SnA6gABplE"]
[Mon Jul 20 07:41:59.709484 2026] [security2:error] [pid 204156:tid 204309] [client 160.187.68.132:42576] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zoa.jji.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lpxbAFPhDXvzP7SnA6gABplE"]
[Mon Jul 20 07:41:59.746295 2026] [core:error] [pid 178071:tid 178226] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:59.746314 2026] [core:error] [pid 178071:tid 178226] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:41:59.851623 2026] [security2:error] [pid 204156:tid 204254] [remote 185.177.72.100:26512] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2flaravel%2f.env"] [unique_id "al4lpxbAFPhDXvzP7SnA8QAB9WE"]
[Mon Jul 20 07:41:59.930483 2026] [security2:error] [pid 178071:tid 178315] [client 85.204.70.112:33098] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4lpxltgi7HBmNwzJNw7AAAAHA"]
[Mon Jul 20 07:42:00.266678 2026] [security2:error] [pid 178071:tid 178265] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lqBltgi7HBmNwzJNw7wAAAD4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:00.431818 2026] [security2:error] [pid 204156:tid 204319] [client 85.204.70.112:33106] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.glx.ehd.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4lqBbAFPhDXvzP7SnBCwAAAbA"]
[Mon Jul 20 07:42:00.662821 2026] [security2:error] [pid 204156:tid 204378] [client 37.52.210.45:50571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lqBbAFPhDXvzP7SnBEwAAAes"]
[Mon Jul 20 07:42:00.662994 2026] [security2:error] [pid 204156:tid 204378] [client 37.52.210.45:50571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lqBbAFPhDXvzP7SnBEwAAAes"]
[Mon Jul 20 07:42:00.745331 2026] [proxy:error] [pid 178071:tid 178312] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:42:00.745407 2026] [proxy_http:error] [pid 178071:tid 178312] [client 107.172.180.205:44212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:42:00.747108 2026] [proxy:error] [pid 178071:tid 178312] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:42:00.747171 2026] [proxy_http:error] [pid 178071:tid 178312] [client 107.172.180.205:44212] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:42:01.029704 2026] [security2:error] [pid 178071:tid 178299] [client 57.141.18.28:49288] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqBltgi7HBmNwzJNw9QAAYHQ"]
[Mon Jul 20 07:42:01.119663 2026] [security2:error] [pid 204156:tid 204377] [client 142.111.152.177:37751] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lqBbAFPhDXvzP7SnBGwAAAeo"]
[Mon Jul 20 07:42:01.352094 2026] [security2:error] [pid 204156:tid 204310] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lqRbAFPhDXvzP7SnBIgAAAac"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:01.401660 2026] [security2:error] [pid 178071:tid 178246] [client 188.166.209.66:57828] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 66.209.166.188.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-includes/fonts/class-wp-font-utils.php"] [unique_id "al4lqRltgi7HBmNwzJNxKwAAACs"], referer: binance.com
[Mon Jul 20 07:42:01.458290 2026] [security2:error] [pid 178071:tid 178310] [client 149.0.16.108:64852] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lqRltgi7HBmNwzJNxOAAAAGs"]
[Mon Jul 20 07:42:01.458904 2026] [security2:error] [pid 178071:tid 178310] [client 149.0.16.108:64852] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lqRltgi7HBmNwzJNxOAAAAGs"]
[Mon Jul 20 07:42:01.678866 2026] [security2:error] [pid 204156:tid 204336] [client 57.141.18.74:20812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqBbAFPhDXvzP7SnBFAABwX4"]
[Mon Jul 20 07:42:01.711403 2026] [security2:error] [pid 204156:tid 204322] [client 173.239.224.20:62771] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adastra.love"] [uri "/wp-login.php"] [unique_id "al4lqRbAFPhDXvzP7SnBMQAAAbM"]
[Mon Jul 20 07:42:01.765371 2026] [authz_core:error] [pid 178071:tid 178222] [client 168.144.19.97:64370] AH01630: client denied by server configuration: /home1/polishe5/public_html/wp-admin/includes/error_log, referer: binance.com
[Mon Jul 20 07:42:02.253132 2026] [security2:error] [pid 178071:tid 178254] [client 57.141.18.75:43870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqRltgi7HBmNwzJNxJgAAMwU"]
[Mon Jul 20 07:42:02.474841 2026] [security2:error] [pid 204156:tid 204300] [client 154.192.233.184:62024] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lqhbAFPhDXvzP7SnBTQAAAZ0"]
[Mon Jul 20 07:42:02.475001 2026] [security2:error] [pid 204156:tid 204300] [client 154.192.233.184:62024] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lqhbAFPhDXvzP7SnBTQAAAZ0"]
[Mon Jul 20 07:42:02.485961 2026] [security2:error] [pid 204156:tid 204406] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lqhbAFPhDXvzP7SnBSAAAAgc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:02.532774 2026] [security2:error] [pid 204156:tid 204272] [remote 162.19.86.63:35367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4lqhbAFPhDXvzP7SnBUAABoHM"]
[Mon Jul 20 07:42:02.705668 2026] [security2:error] [pid 204156:tid 204307] [client 35.222.199.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "marketingonetoone.net"] [uri "/index.php"] [unique_id "al4lqhbAFPhDXvzP7SnBSwAAAaQ"], referer: http://www.marketingonetoone.net/salco-ce.com/
[Mon Jul 20 07:42:02.754332 2026] [security2:error] [pid 178071:tid 178253] [client 114.119.152.60:27769] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/category/horror/page/2"] [unique_id "al4lqhltgi7HBmNwzJNxZgAAADI"], referer: https://omenana.com/category/horror?amp
[Mon Jul 20 07:42:02.789915 2026] [security2:error] [pid 204156:tid 204271] [remote 162.19.86.63:35367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sesamegreenbeans.com"] [uri "/wp-login.php"] [unique_id "al4lqhbAFPhDXvzP7SnBXwABlXI"], referer: https://sesamegreenbeans.com/wp-login.php
[Mon Jul 20 07:42:02.792433 2026] [security2:error] [pid 204156:tid 204368] [client 14.225.17.146:52864] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4lqBbAFPhDXvzP7SnBBgAAAeE"], referer: http://onewingpictures.com/www
[Mon Jul 20 07:42:02.816927 2026] [security2:error] [pid 178071:tid 178301] [client 57.141.18.44:30542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqRltgi7HBmNwzJNxRAAAYnY"]
[Mon Jul 20 07:42:03.010385 2026] [security2:error] [pid 204156:tid 204404] [client 57.141.18.113:56592] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqhbAFPhDXvzP7SnBOAACBWc"]
[Mon Jul 20 07:42:03.210763 2026] [proxy:error] [pid 178071:tid 178287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:42:03.210841 2026] [proxy_http:error] [pid 178071:tid 178287] [client 107.172.180.205:44236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:42:03.211657 2026] [proxy:error] [pid 178071:tid 178287] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:42:03.211697 2026] [proxy_http:error] [pid 178071:tid 178287] [client 107.172.180.205:44236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:42:03.293173 2026] [security2:error] [pid 178071:tid 178297] [client 57.141.18.96:41528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqhltgi7HBmNwzJNxWQAAXhU"]
[Mon Jul 20 07:42:03.550543 2026] [security2:error] [pid 204156:tid 204183] [remote 103.187.169.251:34352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lqxbAFPhDXvzP7SnBgQABwBo"]
[Mon Jul 20 07:42:03.606467 2026] [security2:error] [pid 204156:tid 204167] [remote 185.177.72.100:26546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fsymfony/.env"] [unique_id "al4lqxbAFPhDXvzP7SnBhQAB3Ao"]
[Mon Jul 20 07:42:03.793836 2026] [security2:error] [pid 204156:tid 204338] [client 158.173.89.95:54549] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lqxbAFPhDXvzP7SnBkQAAAcM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:42:03.823300 2026] [security2:error] [pid 204156:tid 204261] [remote 91.142.222.105:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lqxbAFPhDXvzP7SnBkwAB82g"]
[Mon Jul 20 07:42:03.927895 2026] [security2:error] [pid 204156:tid 204396] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lqxbAFPhDXvzP7SnBjAAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:03.968368 2026] [security2:error] [pid 204156:tid 204193] [remote 103.187.169.251:34352] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lqxbAFPhDXvzP7SnBmQAB-iQ"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:42:04.128967 2026] [security2:error] [pid 204156:tid 204313] [client 179.127.84.238:56651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lrBbAFPhDXvzP7SnBpQAAAao"]
[Mon Jul 20 07:42:04.129106 2026] [security2:error] [pid 204156:tid 204313] [client 179.127.84.238:56651] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lrBbAFPhDXvzP7SnBpQAAAao"]
[Mon Jul 20 07:42:04.191803 2026] [security2:error] [pid 204156:tid 204165] [remote 91.142.222.105:59336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lrBbAFPhDXvzP7SnBqAABoQg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:42:04.331672 2026] [security2:error] [pid 178071:tid 178320] [client 57.141.18.34:29824] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqxltgi7HBmNwzJNxdwAAdQY"]
[Mon Jul 20 07:42:04.382590 2026] [security2:error] [pid 204156:tid 204344] [client 57.141.18.114:31996] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqxbAFPhDXvzP7SnBeQAByQA"]
[Mon Jul 20 07:42:04.447245 2026] [security2:error] [pid 178071:tid 178315] [client 186.221.114.200:55135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lrBltgi7HBmNwzJNxnQAAAHA"]
[Mon Jul 20 07:42:04.447354 2026] [security2:error] [pid 178071:tid 178315] [client 186.221.114.200:55135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lrBltgi7HBmNwzJNxnQAAAHA"]
[Mon Jul 20 07:42:04.482725 2026] [security2:error] [pid 204156:tid 204168] [remote 185.177.72.100:26560] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fsymfony%2f.env"] [unique_id "al4lrBbAFPhDXvzP7SnBtQAB4gs"]
[Mon Jul 20 07:42:04.827721 2026] [security2:error] [pid 204156:tid 204298] [client 168.205.110.114:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4lqxbAFPhDXvzP7SnBewAAAZs"]
[Mon Jul 20 07:42:04.982492 2026] [security2:error] [pid 204156:tid 204333] [client 103.139.191.61:54065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lrBbAFPhDXvzP7SnBzQAAAb4"]
[Mon Jul 20 07:42:04.982638 2026] [security2:error] [pid 204156:tid 204333] [client 103.139.191.61:54065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lrBbAFPhDXvzP7SnBzQAAAb4"]
[Mon Jul 20 07:42:04.986317 2026] [security2:error] [pid 204156:tid 204372] [client 57.141.18.27:28064] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lqxbAFPhDXvzP7SnBmwAB5RE"]
[Mon Jul 20 07:42:05.217697 2026] [security2:error] [pid 178071:tid 178250] [client 104.207.48.43:23921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 43.48.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4lrRltgi7HBmNwzJNxwwAAAC8"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:05.407209 2026] [security2:error] [pid 178071:tid 178263] [client 114.119.147.6:35829] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.safe-systems.net"] [uri "/nextbit.mx/portafolio/aviato/buttons.html"] [unique_id "al4lrRltgi7HBmNwzJNxywAAADw"], referer: http://www.safe-systems.net/nextbit.mx/portafolio/aviato/checkout.html
[Mon Jul 20 07:42:05.420835 2026] [security2:error] [pid 178071:tid 178241] [client 14.225.17.146:50764] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4lrBltgi7HBmNwzJNxjwAAACY"], referer: http://scott-assist.com/www
[Mon Jul 20 07:42:05.747702 2026] [security2:error] [pid 178071:tid 178300] [client 57.141.18.90:51276] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lrBltgi7HBmNwzJNxrQAAYUg"]
[Mon Jul 20 07:42:05.849567 2026] [security2:error] [pid 178071:tid 178242] [client 65.111.23.76:50649] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4lrRltgi7HBmNwzJNx4AAAACc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:06.117389 2026] [security2:error] [pid 204156:tid 204373] [client 14.225.17.146:51549] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4lrRbAFPhDXvzP7SnB4gAAAeY"], referer: http://tntcatholic.com/www
[Mon Jul 20 07:42:06.247664 2026] [security2:error] [pid 178071:tid 178251] [client 104.207.56.94:27395] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.56.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lrhltgi7HBmNwzJNx7wAAADA"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:42:06.250565 2026] [security2:error] [pid 204156:tid 204337] [client 57.141.18.77:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4lrRbAFPhDXvzP7SnB5QAAAcI"]
[Mon Jul 20 07:42:06.300060 2026] [security2:error] [pid 178071:tid 178269] [client 57.141.18.19:26610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lrRltgi7HBmNwzJNxzAAAQlc"]
[Mon Jul 20 07:42:06.386016 2026] [security2:error] [pid 178071:tid 178294] [client 14.225.17.146:51181] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4lrRltgi7HBmNwzJNxtAAAAFs"], referer: http://cloudspacesgroup.com/www
[Mon Jul 20 07:42:06.585275 2026] [security2:error] [pid 204156:tid 204309] [client 49.47.218.174:57351] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lrhbAFPhDXvzP7SnCAwAAAaY"]
[Mon Jul 20 07:42:06.585422 2026] [security2:error] [pid 204156:tid 204309] [client 49.47.218.174:57351] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lrhbAFPhDXvzP7SnCAwAAAaY"]
[Mon Jul 20 07:42:06.705513 2026] [security2:error] [pid 204156:tid 204321] [client 50.116.65.227:48070] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4lrhbAFPhDXvzP7SnCEAAAAbI"]
[Mon Jul 20 07:42:06.716098 2026] [security2:error] [pid 204156:tid 204329] [client 50.116.65.227:38914] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4lrhbAFPhDXvzP7SnCEQAAAbo"]
[Mon Jul 20 07:42:06.998906 2026] [security2:error] [pid 204156:tid 204313] [client 191.202.66.27:51735] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lrhbAFPhDXvzP7SnCHgAAAao"]
[Mon Jul 20 07:42:06.998996 2026] [security2:error] [pid 204156:tid 204313] [client 191.202.66.27:51735] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lrhbAFPhDXvzP7SnCHgAAAao"]
[Mon Jul 20 07:42:07.815713 2026] [security2:error] [pid 204156:tid 204391] [client 57.141.18.35:27218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lrhbAFPhDXvzP7SnCEgAB-C0"]
[Mon Jul 20 07:42:08.001358 2026] [security2:error] [pid 204156:tid 204343] [client 50.116.65.227:38930] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4lrxbAFPhDXvzP7SnCRwAAAcg"]
[Mon Jul 20 07:42:08.011795 2026] [security2:error] [pid 204156:tid 204340] [client 50.116.65.227:38932] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4lsBbAFPhDXvzP7SnCSgAAAcU"]
[Mon Jul 20 07:42:08.219962 2026] [security2:error] [pid 178071:tid 178277] [client 136.158.60.21:39393] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lsBltgi7HBmNwzJNyMgAAAEo"]
[Mon Jul 20 07:42:08.220131 2026] [security2:error] [pid 178071:tid 178277] [client 136.158.60.21:39393] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lsBltgi7HBmNwzJNyMgAAAEo"]
[Mon Jul 20 07:42:08.289879 2026] [security2:error] [pid 204156:tid 204220] [remote 72.167.132.114:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4lsBbAFPhDXvzP7SnCYQAB9D8"]
[Mon Jul 20 07:42:08.302539 2026] [security2:error] [pid 204156:tid 204201] [remote 185.177.72.100:10986] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2ffrontend/.env"] [unique_id "al4lsBbAFPhDXvzP7SnCYwABmCw"]
[Mon Jul 20 07:42:08.502341 2026] [security2:error] [pid 204156:tid 204206] [remote 72.167.132.114:55116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.transamericagrid.com"] [uri "/wp-login.php"] [unique_id "al4lsBbAFPhDXvzP7SnCZwAB4zE"], referer: https://mail.transamericagrid.com/wp-login.php
[Mon Jul 20 07:42:08.744922 2026] [security2:error] [pid 204156:tid 204401] [client 57.141.18.107:61886] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lrxbAFPhDXvzP7SnCOAACAkE"]
[Mon Jul 20 07:42:08.944271 2026] [security2:error] [pid 178071:tid 178269] [client 136.144.33.206:61799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4lsBltgi7HBmNwzJNyTgAAAEI"]
[Mon Jul 20 07:42:08.950842 2026] [security2:error] [pid 178071:tid 178285] [client 193.36.225.59:52569] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4lsBltgi7HBmNwzJNyTQAAAFI"]
[Mon Jul 20 07:42:08.956491 2026] [security2:error] [pid 204156:tid 204296] [client 193.36.225.92:32961] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4lsBbAFPhDXvzP7SnCfwAAAZk"]
[Mon Jul 20 07:42:09.093608 2026] [security2:error] [pid 178071:tid 178283] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lsBltgi7HBmNwzJNySwAAAFA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:09.160238 2026] [security2:error] [pid 204156:tid 204232] [remote 185.177.72.100:11002] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2ffrontend%2f.env"] [unique_id "al4lsRbAFPhDXvzP7SnCjAAB20s"]
[Mon Jul 20 07:42:09.472093 2026] [security2:error] [pid 178071:tid 178243] [client 36.93.152.155:61656] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lsRltgi7HBmNwzJNyYQAAACg"]
[Mon Jul 20 07:42:09.472230 2026] [security2:error] [pid 178071:tid 178243] [client 36.93.152.155:61656] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lsRltgi7HBmNwzJNyYQAAACg"]
[Mon Jul 20 07:42:09.530942 2026] [security2:error] [pid 204156:tid 204321] [client 62.102.148.130:42628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCoAAAAbI"]
[Mon Jul 20 07:42:09.531033 2026] [security2:error] [pid 204156:tid 204321] [client 62.102.148.130:42628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCoAAAAbI"]
[Mon Jul 20 07:42:09.551859 2026] [security2:error] [pid 204156:tid 204310] [client 180.249.173.210:52567] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCoQAAAac"]
[Mon Jul 20 07:42:09.552477 2026] [security2:error] [pid 204156:tid 204310] [client 180.249.173.210:52567] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCoQAAAac"]
[Mon Jul 20 07:42:09.600876 2026] [security2:error] [pid 204156:tid 204249] [remote 81.173.115.7:49116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCowABxFw"]
[Mon Jul 20 07:42:09.601037 2026] [security2:error] [pid 204156:tid 204339] [client 81.173.115.7:49116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.narv.co"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCowABxFw"]
[Mon Jul 20 07:42:09.618415 2026] [security2:error] [pid 178071:tid 178109] [remote 130.185.118.215:41836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lsRltgi7HBmNwzJNyZQAAJiQ"]
[Mon Jul 20 07:42:09.663703 2026] [security2:error] [pid 204156:tid 204405] [client 74.7.227.179:52328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4lsRbAFPhDXvzP7SnCnAACBkY"], referer: https://tejasenvironmental.com/p=218067
[Mon Jul 20 07:42:09.766377 2026] [security2:error] [pid 204156:tid 204389] [client 103.106.165.44:55030] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCrAAAAfY"]
[Mon Jul 20 07:42:09.766485 2026] [security2:error] [pid 204156:tid 204389] [client 103.106.165.44:55030] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lsRbAFPhDXvzP7SnCrAAAAfY"]
[Mon Jul 20 07:42:09.799146 2026] [security2:error] [pid 178071:tid 178194] [remote 130.185.118.215:41836] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lsRltgi7HBmNwzJNybAAAR3g"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:42:09.982525 2026] [security2:error] [pid 178071:tid 178284] [client 57.141.18.98:29686] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lsBltgi7HBmNwzJNyRAAAUS4"]
[Mon Jul 20 07:42:10.048196 2026] [security2:error] [pid 204156:tid 204293] [client 14.225.17.146:53178] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4lsRbAFPhDXvzP7SnCrQAAAZY"]
[Mon Jul 20 07:42:10.274595 2026] [security2:error] [pid 204156:tid 204357] [client 14.225.17.146:53074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4lsRbAFPhDXvzP7SnCsgAAAdY"], referer: http://healthylifegourmet.org/www
[Mon Jul 20 07:42:10.282341 2026] [security2:error] [pid 204156:tid 204295] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lshbAFPhDXvzP7SnCuAAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:10.500214 2026] [security2:error] [pid 178071:tid 178282] [client 14.225.17.146:52909] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4lsRltgi7HBmNwzJNyVQAAAE8"], referer: http://momheadquarters.com/www
[Mon Jul 20 07:42:10.577237 2026] [security2:error] [pid 204156:tid 204381] [client 57.141.18.26:21974] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lsRbAFPhDXvzP7SnCkwAB7ko"]
[Mon Jul 20 07:42:10.619002 2026] [security2:error] [pid 204156:tid 204332] [client 40.80.200.186:44044] ModSecurity: Warning. Matched phrase "zgrab" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "50.116.64.44"] [uri "/index.cgi"] [unique_id "al4lshbAFPhDXvzP7SnCzAAAAb0"]
[Mon Jul 20 07:42:10.646475 2026] [security2:error] [pid 204156:tid 204395] [client 14.225.17.146:54097] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4lshbAFPhDXvzP7SnCygAAAfw"], referer: http://samdothan.org/www
[Mon Jul 20 07:42:10.678021 2026] [security2:error] [pid 204156:tid 204358] [client 14.225.17.146:53197] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4lshbAFPhDXvzP7SnCvAAAAdc"], referer: http://partnerselectricalllc.com/www
[Mon Jul 20 07:42:10.859132 2026] [security2:error] [pid 204156:tid 204411] [client 57.141.18.5:27624] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lsRbAFPhDXvzP7SnCqQACDGk"]
[Mon Jul 20 07:42:11.057429 2026] [security2:error] [pid 204156:tid 204400] [client 49.37.242.14:56500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lsxbAFPhDXvzP7SnC5gAAAgE"]
[Mon Jul 20 07:42:11.057580 2026] [security2:error] [pid 204156:tid 204400] [client 49.37.242.14:56500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lsxbAFPhDXvzP7SnC5gAAAgE"]
[Mon Jul 20 07:42:11.265682 2026] [security2:error] [pid 178071:tid 178247] [client 37.52.210.45:51072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lsxltgi7HBmNwzJNyrQAAACw"]
[Mon Jul 20 07:42:11.265836 2026] [security2:error] [pid 178071:tid 178247] [client 37.52.210.45:51072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lsxltgi7HBmNwzJNyrQAAACw"]
[Mon Jul 20 07:42:11.361525 2026] [security2:error] [pid 178071:tid 178253] [client 57.141.18.85:59424] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lshltgi7HBmNwzJNygwAAMgA"]
[Mon Jul 20 07:42:11.438630 2026] [security2:error] [pid 178071:tid 178241] [client 216.73.217.86:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "theprocess.oldcartsconsulting.com"] [uri "/index.php"] [unique_id "al4lshltgi7HBmNwzJNypwAAACY"]
[Mon Jul 20 07:42:11.675380 2026] [security2:error] [pid 204156:tid 204304] [client 142.111.152.175:29731] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lsxbAFPhDXvzP7SnDCgAAAaE"]
[Mon Jul 20 07:42:11.827242 2026] [security2:error] [pid 204156:tid 204341] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lsxbAFPhDXvzP7SnDEQAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:12.128499 2026] [security2:error] [pid 204156:tid 204401] [client 104.207.51.148:47611] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4ltBbAFPhDXvzP7SnDLgAAAgI"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:42:12.131955 2026] [security2:error] [pid 204156:tid 204306] [client 149.0.16.108:49238] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ltBbAFPhDXvzP7SnDMgAAAaM"]
[Mon Jul 20 07:42:12.132061 2026] [security2:error] [pid 204156:tid 204306] [client 149.0.16.108:49238] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4ltBbAFPhDXvzP7SnDMgAAAaM"]
[Mon Jul 20 07:42:12.327777 2026] [security2:error] [pid 204156:tid 204372] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ltBbAFPhDXvzP7SnDMAAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:12.461791 2026] [security2:error] [pid 204156:tid 204407] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ltBbAFPhDXvzP7SnDOQAAAgg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:12.736337 2026] [security2:error] [pid 204156:tid 204312] [client 3.85.28.216:34280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 216.28.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4ltBbAFPhDXvzP7SnDVgAAAak"], referer: https://curlsnpearlsss.com/es/tag/glazed-ham-with-pineapples/
[Mon Jul 20 07:42:12.913227 2026] [security2:error] [pid 204156:tid 204357] [client 154.192.233.184:62388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4ltBbAFPhDXvzP7SnDYAAAAdY"]
[Mon Jul 20 07:42:12.913347 2026] [security2:error] [pid 204156:tid 204357] [client 154.192.233.184:62388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4ltBbAFPhDXvzP7SnDYAAAAdY"]
[Mon Jul 20 07:42:13.535985 2026] [security2:error] [pid 204156:tid 204332] [client 45.3.54.6:21841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4ltRbAFPhDXvzP7SnDgQAAAb0"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:42:13.710721 2026] [security2:error] [pid 204156:tid 204282] [remote 72.167.132.114:55128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ltRbAFPhDXvzP7SnDiAAB-H0"]
[Mon Jul 20 07:42:13.710887 2026] [security2:error] [pid 204156:tid 204391] [client 72.167.132.114:55128] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4ltRbAFPhDXvzP7SnDiAAB-H0"]
[Mon Jul 20 07:42:13.827328 2026] [security2:error] [pid 204156:tid 204268] [remote 130.185.118.215:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4ltRbAFPhDXvzP7SnDjAAB_28"]
[Mon Jul 20 07:42:13.928347 2026] [security2:error] [pid 204156:tid 204345] [client 14.225.17.146:53296] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4ltBbAFPhDXvzP7SnDSwAAAco"], referer: http://thechancersband.com/www
[Mon Jul 20 07:42:14.093447 2026] [security2:error] [pid 178071:tid 178315] [client 14.225.17.146:53311] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4ltBltgi7HBmNwzJNyyAAAAHA"], referer: http://nomorewetsheets.net/www
[Mon Jul 20 07:42:14.240945 2026] [security2:error] [pid 204156:tid 204276] [remote 130.185.118.215:53906] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 215.118.185.130.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4lthbAFPhDXvzP7SnDnwABoHc"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:42:14.296370 2026] [security2:error] [pid 204156:tid 204368] [client 57.141.18.8:46248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ltRbAFPhDXvzP7SnDcgAB4QE"]
[Mon Jul 20 07:42:14.299870 2026] [security2:error] [pid 204156:tid 204341] [client 57.141.18.115:58870] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ltRbAFPhDXvzP7SnDcQABxhg"]
[Mon Jul 20 07:42:14.420949 2026] [security2:error] [pid 178071:tid 178090] [remote 57.141.18.47:54934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 47.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4459097"] [unique_id "al4lthltgi7HBmNwzJNzCwAARhE"]
[Mon Jul 20 07:42:14.624805 2026] [security2:error] [pid 204156:tid 204349] [client 179.127.84.238:57179] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lthbAFPhDXvzP7SnDsQAAAc4"]
[Mon Jul 20 07:42:14.625522 2026] [security2:error] [pid 204156:tid 204349] [client 179.127.84.238:57179] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lthbAFPhDXvzP7SnDsQAAAc4"]
[Mon Jul 20 07:42:15.047641 2026] [security2:error] [pid 204156:tid 204387] [client 186.221.114.200:55603] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ltxbAFPhDXvzP7SnDxQAAAfQ"]
[Mon Jul 20 07:42:15.047773 2026] [security2:error] [pid 204156:tid 204387] [client 186.221.114.200:55603] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4ltxbAFPhDXvzP7SnDxQAAAfQ"]
[Mon Jul 20 07:42:15.243982 2026] [security2:error] [pid 204156:tid 204393] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lthbAFPhDXvzP7SnDtwAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:15.691694 2026] [security2:error] [pid 204156:tid 204373] [client 13.232.231.177:42536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ltxbAFPhDXvzP7SnD-wAAAeY"]
[Mon Jul 20 07:42:15.691882 2026] [security2:error] [pid 204156:tid 204373] [client 13.232.231.177:42536] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "cryptomeaning.com"] [uri "/xmlrpc.php"] [unique_id "al4ltxbAFPhDXvzP7SnD-wAAAeY"]
[Mon Jul 20 07:42:15.738728 2026] [security2:error] [pid 204156:tid 204406] [client 65.111.31.97:51209] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4ltxbAFPhDXvzP7SnD_AAAAgc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:15.795003 2026] [security2:error] [pid 204156:tid 204299] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnD6AAAAZw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:15.796720 2026] [security2:error] [pid 204156:tid 204368] [client 77.110.127.138:54489] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/page/21/"] [unique_id "al4ltxbAFPhDXvzP7SnD_gAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:15.837500 2026] [security2:error] [pid 204156:tid 204342] [client 14.225.17.146:50423] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnD2gAAAcc"]
[Mon Jul 20 07:42:16.233493 2026] [security2:error] [pid 204156:tid 204303] [client 57.141.18.114:36936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnD1gABoA0"]
[Mon Jul 20 07:42:16.415084 2026] [security2:error] [pid 204156:tid 204393] [client 103.139.191.61:54593] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4luBbAFPhDXvzP7SnELwAAAfo"]
[Mon Jul 20 07:42:16.415215 2026] [security2:error] [pid 204156:tid 204393] [client 103.139.191.61:54593] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4luBbAFPhDXvzP7SnELwAAAfo"]
[Mon Jul 20 07:42:16.473861 2026] [security2:error] [pid 204156:tid 204404] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnEDQAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:16.501440 2026] [security2:error] [pid 178071:tid 178211] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4luBltgi7HBmNwzJNzQwAAAAg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:16.513994 2026] [security2:error] [pid 204156:tid 204349] [client 57.141.18.109:53708] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnD4AABzhQ"]
[Mon Jul 20 07:42:16.557016 2026] [security2:error] [pid 204156:tid 204357] [client 57.141.18.4:65526] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnD4gAB1i4"]
[Mon Jul 20 07:42:16.864722 2026] [security2:error] [pid 204156:tid 204376] [client 34.55.200.45:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "msd.mqz.mybluehost.me"] [uri "/index.php"] [unique_id "al4luBbAFPhDXvzP7SnEQgAAAek"]
[Mon Jul 20 07:42:16.934530 2026] [security2:error] [pid 204156:tid 204304] [client 14.225.17.146:52093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnD3wAAAaE"], referer: http://slutilities.com/www
[Mon Jul 20 07:42:17.134740 2026] [security2:error] [pid 204156:tid 204372] [client 49.47.218.174:57889] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4luRbAFPhDXvzP7SnEUgAAAeU"]
[Mon Jul 20 07:42:17.135063 2026] [security2:error] [pid 204156:tid 204372] [client 49.47.218.174:57889] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4luRbAFPhDXvzP7SnEUgAAAeU"]
[Mon Jul 20 07:42:17.191326 2026] [security2:error] [pid 178071:tid 178303] [client 158.173.166.181:49909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4luRltgi7HBmNwzJNzYgAAAGQ"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:42:17.301648 2026] [security2:error] [pid 204156:tid 204391] [client 57.141.18.82:27160] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luBbAFPhDXvzP7SnEHgAB-Hs"]
[Mon Jul 20 07:42:17.374102 2026] [security2:error] [pid 204156:tid 204403] [client 14.225.17.146:55032] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4ltxbAFPhDXvzP7SnEEQAAAgQ"], referer: http://alchemygroup.ca/www
[Mon Jul 20 07:42:17.476492 2026] [core:error] [pid 178071:tid 178235] [client 14.225.17.146:60956] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/www
[Mon Jul 20 07:42:17.476519 2026] [core:error] [pid 178071:tid 178235] [client 14.225.17.146:60956] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/www
[Mon Jul 20 07:42:17.587768 2026] [security2:error] [pid 178071:tid 178230] [client 57.141.18.102:35700] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luBltgi7HBmNwzJNzTQAAGwY"]
[Mon Jul 20 07:42:17.608129 2026] [security2:error] [pid 204156:tid 204413] [client 191.202.66.27:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4luRbAFPhDXvzP7SnEYgAAAg4"]
[Mon Jul 20 07:42:17.608281 2026] [security2:error] [pid 204156:tid 204413] [client 191.202.66.27:52246] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4luRbAFPhDXvzP7SnEYgAAAg4"]
[Mon Jul 20 07:42:17.734983 2026] [security2:error] [pid 204156:tid 204292] [client 57.141.18.25:50562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luBbAFPhDXvzP7SnENAABlSI"]
[Mon Jul 20 07:42:17.887980 2026] [security2:error] [pid 204156:tid 204412] [client 14.225.17.146:60464] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4luRbAFPhDXvzP7SnEUAAAAg0"], referer: http://keywayconstructionclt.com/www
[Mon Jul 20 07:42:18.495673 2026] [security2:error] [pid 204156:tid 204370] [client 14.225.17.146:60973] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4luhbAFPhDXvzP7SnEigAAAeM"], referer: http://thefriendlyspreadsheet.com/www
[Mon Jul 20 07:42:18.754286 2026] [security2:error] [pid 204156:tid 204357] [client 14.225.17.146:52090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4luhbAFPhDXvzP7SnEmwAAAdY"], referer: https://keywayconstructionclt.com/www
[Mon Jul 20 07:42:18.829651 2026] [security2:error] [pid 204156:tid 204352] [client 14.225.17.146:60606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4luRbAFPhDXvzP7SnEWAAAAdE"], referer: http://amalia-capital.com/www
[Mon Jul 20 07:42:18.922403 2026] [security2:error] [pid 204156:tid 204327] [client 136.158.60.21:40913] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4luhbAFPhDXvzP7SnEpgAAAbg"]
[Mon Jul 20 07:42:18.922521 2026] [security2:error] [pid 204156:tid 204327] [client 136.158.60.21:40913] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4luhbAFPhDXvzP7SnEpgAAAbg"]
[Mon Jul 20 07:42:19.607846 2026] [security2:error] [pid 178071:tid 178095] [remote 209.42.18.223:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4luxltgi7HBmNwzJNzrQAAYBY"]
[Mon Jul 20 07:42:19.763363 2026] [security2:error] [pid 204156:tid 204305] [client 91.92.42.200:55292] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4luhbAFPhDXvzP7SnEhQAAAaI"]
[Mon Jul 20 07:42:19.778495 2026] [security2:error] [pid 178071:tid 178189] [remote 209.42.18.223:52402] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4luxltgi7HBmNwzJNztAAAAnM"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:42:20.009340 2026] [security2:error] [pid 178071:tid 178279] [client 36.93.152.155:62270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4luxltgi7HBmNwzJNzwQAAAEw"]
[Mon Jul 20 07:42:20.009499 2026] [security2:error] [pid 178071:tid 178279] [client 36.93.152.155:62270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4luxltgi7HBmNwzJNzwQAAAEw"]
[Mon Jul 20 07:42:20.055422 2026] [security2:error] [pid 178071:tid 178216] [client 89.238.167.150:45060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4lvBltgi7HBmNwzJNzwwAAAA0"]
[Mon Jul 20 07:42:20.055563 2026] [security2:error] [pid 178071:tid 178216] [client 89.238.167.150:45060] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4lvBltgi7HBmNwzJNzwwAAAA0"]
[Mon Jul 20 07:42:20.109173 2026] [security2:error] [pid 204156:tid 204310] [client 180.249.173.210:53078] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lvBbAFPhDXvzP7SnE4gAAAac"]
[Mon Jul 20 07:42:20.109664 2026] [security2:error] [pid 204156:tid 204310] [client 180.249.173.210:53078] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lvBbAFPhDXvzP7SnE4gAAAac"]
[Mon Jul 20 07:42:20.194520 2026] [security2:error] [pid 204156:tid 204304] [client 57.141.18.4:29724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luhbAFPhDXvzP7SnEmgABoR8"]
[Mon Jul 20 07:42:20.199573 2026] [security2:error] [pid 204156:tid 204243] [remote 209.42.18.223:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4lvBbAFPhDXvzP7SnE5AABoFY"]
[Mon Jul 20 07:42:20.233841 2026] [security2:error] [pid 204156:tid 204290] [client 103.106.165.44:55737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lvBbAFPhDXvzP7SnE5gAAAZM"]
[Mon Jul 20 07:42:20.233952 2026] [security2:error] [pid 204156:tid 204290] [client 103.106.165.44:55737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lvBbAFPhDXvzP7SnE5gAAAZM"]
[Mon Jul 20 07:42:20.312071 2026] [security2:error] [pid 204156:tid 204314] [client 14.225.17.146:61017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4luxbAFPhDXvzP7SnEyQAAAas"], referer: http://gearwaterproof.com/www
[Mon Jul 20 07:42:20.338365 2026] [security2:error] [pid 204156:tid 204302] [client 57.141.18.67:39438] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luhbAFPhDXvzP7SnEpwABnz8"]
[Mon Jul 20 07:42:20.372196 2026] [security2:error] [pid 204156:tid 204214] [remote 209.42.18.223:52430] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thefriendlyspreadsheet.com"] [uri "/wp-login.php"] [unique_id "al4lvBbAFPhDXvzP7SnE7QABsDk"], referer: https://thefriendlyspreadsheet.com/wp-login.php
[Mon Jul 20 07:42:20.419955 2026] [security2:error] [pid 178071:tid 178247] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4luxltgi7HBmNwzJNzsgAAACw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:20.476457 2026] [autoindex:error] [pid 204156:tid 204327] [client 147.93.171.186:55184] AH01276: Cannot serve directory /home1/bnbengin/public_html/wp-admin/css/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: binance.com
[Mon Jul 20 07:42:20.511217 2026] [security2:error] [pid 178071:tid 178285] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4luxltgi7HBmNwzJNztQAAAFI"]
[Mon Jul 20 07:42:20.514489 2026] [security2:error] [pid 204156:tid 204311] [client 77.110.127.138:54522] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/page/21/"] [unique_id "al4lvBbAFPhDXvzP7SnE8AAAAag"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:20.705386 2026] [security2:error] [pid 178071:tid 178326] [client 57.141.18.85:51286] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luxltgi7HBmNwzJNznwAAeyY"]
[Mon Jul 20 07:42:20.868742 2026] [security2:error] [pid 178071:tid 178244] [client 57.141.18.101:52936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luxltgi7HBmNwzJNzpAAAKSE"]
[Mon Jul 20 07:42:21.043383 2026] [security2:error] [pid 204156:tid 204401] [client 57.141.18.123:36090] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4luxbAFPhDXvzP7SnEvgACAkE"]
[Mon Jul 20 07:42:21.761150 2026] [security2:error] [pid 204156:tid 204404] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lvRbAFPhDXvzP7SnFGwAAAgU"]
[Mon Jul 20 07:42:21.911451 2026] [security2:error] [pid 204156:tid 204407] [client 37.52.210.45:51575] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lvRbAFPhDXvzP7SnFHQAAAgg"]
[Mon Jul 20 07:42:21.911656 2026] [security2:error] [pid 204156:tid 204407] [client 37.52.210.45:51575] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lvRbAFPhDXvzP7SnFHQAAAgg"]
[Mon Jul 20 07:42:22.132360 2026] [security2:error] [pid 204156:tid 204328] [client 57.141.18.6:43520] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lvBbAFPhDXvzP7SnE-QABuVA"]
[Mon Jul 20 07:42:22.212044 2026] [security2:error] [pid 204156:tid 204387] [client 155.2.215.85:35447] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lvhbAFPhDXvzP7SnFJQAAAfQ"]
[Mon Jul 20 07:42:22.512638 2026] [security2:error] [pid 204156:tid 204338] [client 57.141.18.118:51544] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lvRbAFPhDXvzP7SnFDAABw0o"]
[Mon Jul 20 07:42:22.515886 2026] [security2:error] [pid 178071:tid 178294] [client 14.225.17.146:60302] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4lvRltgi7HBmNwzJN0GgAAAFs"], referer: http://ravmike.com/www
[Mon Jul 20 07:42:22.657649 2026] [security2:error] [pid 204156:tid 204358] [client 49.37.242.14:57091] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lvhbAFPhDXvzP7SnFPwAAAdc"]
[Mon Jul 20 07:42:22.657738 2026] [security2:error] [pid 204156:tid 204358] [client 49.37.242.14:57091] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lvhbAFPhDXvzP7SnFPwAAAdc"]
[Mon Jul 20 07:42:22.722789 2026] [security2:error] [pid 204156:tid 204314] [client 149.0.16.108:52746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lvhbAFPhDXvzP7SnFRAAAAas"]
[Mon Jul 20 07:42:22.722965 2026] [security2:error] [pid 204156:tid 204314] [client 149.0.16.108:52746] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lvhbAFPhDXvzP7SnFRAAAAas"]
[Mon Jul 20 07:42:22.808359 2026] [security2:error] [pid 204156:tid 204317] [client 14.225.17.146:60747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4lvBbAFPhDXvzP7SnE-wAAAa4"], referer: http://dollpassionista.com/www
[Mon Jul 20 07:42:22.888767 2026] [security2:error] [pid 204156:tid 204239] [remote 20.153.140.50:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4lvhbAFPhDXvzP7SnFTwAB_FI"]
[Mon Jul 20 07:42:23.170370 2026] [security2:error] [pid 204156:tid 204307] [client 14.225.17.146:53838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4lvRbAFPhDXvzP7SnFHAAAAaQ"]
[Mon Jul 20 07:42:23.295033 2026] [security2:error] [pid 204156:tid 204266] [remote 20.153.140.50:36446] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.whiteoutcb.com"] [uri "/wp-login.php"] [unique_id "al4lvxbAFPhDXvzP7SnFXQABoW0"], referer: https://mail.whiteoutcb.com/wp-login.php
[Mon Jul 20 07:42:23.373430 2026] [security2:error] [pid 178071:tid 178254] [client 193.111.117.58:36856] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "503"] [hostname "www.cira.org"] [uri "/index.php"] [unique_id "al4lvxltgi7HBmNwzJN0XAAAADM"]
[Mon Jul 20 07:42:23.406174 2026] [security2:error] [pid 204156:tid 204387] [client 14.225.17.146:53763] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4lvxbAFPhDXvzP7SnFXwAAAfQ"], referer: https://ravmike.com/www
[Mon Jul 20 07:42:23.577286 2026] [security2:error] [pid 204156:tid 204385] [client 154.192.233.184:60872] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lvxbAFPhDXvzP7SnFYgAAAfI"]
[Mon Jul 20 07:42:23.577443 2026] [security2:error] [pid 204156:tid 204385] [client 154.192.233.184:60872] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lvxbAFPhDXvzP7SnFYgAAAfI"]
[Mon Jul 20 07:42:23.693715 2026] [security2:error] [pid 204156:tid 204382] [client 57.141.18.51:43440] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lvhbAFPhDXvzP7SnFKQAB700"]
[Mon Jul 20 07:42:23.744708 2026] [core:error] [pid 204156:tid 204364] [client 14.225.17.146:60947] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:23.744738 2026] [core:error] [pid 204156:tid 204364] [client 14.225.17.146:60947] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:23.899288 2026] [security2:error] [pid 178071:tid 178322] [client 14.225.17.146:50370] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4lvxltgi7HBmNwzJN0egAAAHc"], referer: https://dollpassionista.com/www
[Mon Jul 20 07:42:24.240978 2026] [security2:error] [pid 204156:tid 204290] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lvxbAFPhDXvzP7SnFbQAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:24.274374 2026] [security2:error] [pid 204156:tid 204297] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lvxbAFPhDXvzP7SnFcQAAAZo"]
[Mon Jul 20 07:42:24.400988 2026] [security2:error] [pid 204156:tid 204328] [client 91.92.42.200:58058] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/administrator/index.php"] [unique_id "al4lwBbAFPhDXvzP7SnFhAAAAbk"]
[Mon Jul 20 07:42:24.681720 2026] [security2:error] [pid 178071:tid 178270] [client 57.141.18.61:61492] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lvxltgi7HBmNwzJN0XwAAQ0A"]
[Mon Jul 20 07:42:24.796473 2026] [security2:error] [pid 204156:tid 204409] [client 91.92.42.200:58072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.42.92.91.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "newoffice.ca"] [uri "/administrator/index2.php"] [unique_id "al4lwBbAFPhDXvzP7SnFpwAAAgo"]
[Mon Jul 20 07:42:25.136803 2026] [security2:error] [pid 204156:tid 204320] [client 179.127.84.238:57698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lwRbAFPhDXvzP7SnFuwAAAbE"]
[Mon Jul 20 07:42:25.136885 2026] [security2:error] [pid 204156:tid 204320] [client 179.127.84.238:57698] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lwRbAFPhDXvzP7SnFuwAAAbE"]
[Mon Jul 20 07:42:25.203717 2026] [security2:error] [pid 204156:tid 204267] [remote 100.42.189.89:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lwRbAFPhDXvzP7SnFwAAB5m4"]
[Mon Jul 20 07:42:25.400652 2026] [security2:error] [pid 204156:tid 204181] [remote 100.42.189.89:39256] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lwRbAFPhDXvzP7SnFzgAB4Rg"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:42:25.421103 2026] [security2:error] [pid 204156:tid 204376] [client 57.141.18.93:46094] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lvxbAFPhDXvzP7SnFfAAB6QU"]
[Mon Jul 20 07:42:25.454823 2026] [security2:error] [pid 204156:tid 204352] [client 45.3.51.167:20167] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 167.51.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4lwRbAFPhDXvzP7SnF0gAAAdE"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:25.722051 2026] [security2:error] [pid 178071:tid 178263] [client 57.141.18.48:31668] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwBltgi7HBmNwzJN0kgAAPGs"]
[Mon Jul 20 07:42:25.796891 2026] [security2:error] [pid 204156:tid 204356] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lwRbAFPhDXvzP7SnF1gAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:25.984879 2026] [security2:error] [pid 178071:tid 178291] [client 186.221.114.200:56086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lwRltgi7HBmNwzJN00AAAAFg"]
[Mon Jul 20 07:42:25.989947 2026] [security2:error] [pid 178071:tid 178291] [client 186.221.114.200:56086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lwRltgi7HBmNwzJN00AAAAFg"]
[Mon Jul 20 07:42:26.025218 2026] [security2:error] [pid 204156:tid 204311] [client 65.111.6.236:21035] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 236.6.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4lwRbAFPhDXvzP7SnF6gAAAag"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:26.038845 2026] [security2:error] [pid 204156:tid 204354] [client 91.92.42.200:41318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4lwRbAFPhDXvzP7SnF6wAAAdM"]
[Mon Jul 20 07:42:26.264997 2026] [security2:error] [pid 204156:tid 204368] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lwhbAFPhDXvzP7SnF-wAAAeE"]
[Mon Jul 20 07:42:26.314458 2026] [security2:error] [pid 204156:tid 204304] [client 57.141.18.47:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4lwhbAFPhDXvzP7SnF-AAAAaE"]
[Mon Jul 20 07:42:26.374165 2026] [security2:error] [pid 204156:tid 204301] [client 40.77.167.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "youpositive.co"] [uri "/index.php"] [unique_id "al4lvxbAFPhDXvzP7SnFZgAAAZ4"]
[Mon Jul 20 07:42:26.422618 2026] [security2:error] [pid 204156:tid 204379] [client 57.141.18.108:45706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwRbAFPhDXvzP7SnFsgAB7Hg"]
[Mon Jul 20 07:42:26.463758 2026] [security2:error] [pid 178071:tid 178220] [client 43.134.38.171:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4lwhltgi7HBmNwzJN02QAAABE"], referer: http://maxenengineering.com
[Mon Jul 20 07:42:26.587676 2026] [security2:error] [pid 204156:tid 204395] [client 45.3.34.220:26161] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4lwhbAFPhDXvzP7SnGDQAAAfw"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:26.710064 2026] [security2:error] [pid 204156:tid 204305] [client 14.225.17.146:59852] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4lwRbAFPhDXvzP7SnFxgAAAaI"], referer: http://dnsplumbing.com/www
[Mon Jul 20 07:42:26.764875 2026] [security2:error] [pid 204156:tid 204288] [client 91.92.42.200:41318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4lwhbAFPhDXvzP7SnGEwAAAZE"]
[Mon Jul 20 07:42:26.795381 2026] [security2:error] [pid 204156:tid 204192] [remote 173.249.4.11:8526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4lwhbAFPhDXvzP7SnGFgAB3yM"]
[Mon Jul 20 07:42:26.939433 2026] [security2:error] [pid 204156:tid 204174] [remote 152.228.213.32:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4lwhbAFPhDXvzP7SnGHAAB1RE"]
[Mon Jul 20 07:42:26.984468 2026] [security2:error] [pid 204156:tid 204400] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lwhbAFPhDXvzP7SnGGwAAAgE"]
[Mon Jul 20 07:42:26.984488 2026] [security2:error] [pid 204156:tid 204286] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lwhbAFPhDXvzP7SnGFQAAAY8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:27.003850 2026] [security2:error] [pid 204156:tid 204197] [remote 173.249.4.11:8526] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "39ishlife.com"] [uri "/wp-login.php"] [unique_id "al4lwxbAFPhDXvzP7SnGIQAB5Sg"], referer: https://39ishlife.com/wp-login.php
[Mon Jul 20 07:42:27.145080 2026] [security2:error] [pid 204156:tid 204170] [remote 152.228.213.32:50666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "timespans.org"] [uri "/wp-login.php"] [unique_id "al4lwxbAFPhDXvzP7SnGKgABow0"], referer: https://timespans.org/wp-login.php
[Mon Jul 20 07:42:27.182159 2026] [security2:error] [pid 204156:tid 204318] [client 103.139.191.61:55106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lwxbAFPhDXvzP7SnGLgAAAa8"]
[Mon Jul 20 07:42:27.182298 2026] [security2:error] [pid 204156:tid 204318] [client 103.139.191.61:55106] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lwxbAFPhDXvzP7SnGLgAAAa8"]
[Mon Jul 20 07:42:27.240442 2026] [security2:error] [pid 178071:tid 178219] [client 14.225.17.146:58782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lwxltgi7HBmNwzJN0_QAAABA"], referer: http://mezzacraft.com/www
[Mon Jul 20 07:42:27.354116 2026] [security2:error] [pid 204156:tid 204291] [client 91.92.42.200:41318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4lwxbAFPhDXvzP7SnGOAAAAZQ"]
[Mon Jul 20 07:42:27.381508 2026] [security2:error] [pid 204156:tid 204329] [client 57.141.18.12:57264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwRbAFPhDXvzP7SnF5AABugo"]
[Mon Jul 20 07:42:27.459162 2026] [security2:error] [pid 204156:tid 204409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lwxbAFPhDXvzP7SnGNAAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:27.541208 2026] [security2:error] [pid 204156:tid 204319] [client 49.47.218.174:58429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lwxbAFPhDXvzP7SnGRAAAAbA"]
[Mon Jul 20 07:42:27.541330 2026] [security2:error] [pid 204156:tid 204319] [client 49.47.218.174:58429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lwxbAFPhDXvzP7SnGRAAAAbA"]
[Mon Jul 20 07:42:27.594290 2026] [security2:error] [pid 204156:tid 204371] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lwxbAFPhDXvzP7SnGQwAAAeQ"]
[Mon Jul 20 07:42:27.700814 2026] [security2:error] [pid 178071:tid 178271] [client 77.110.127.138:54546] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/page/21/"] [unique_id "al4lwxltgi7HBmNwzJN1GAAAAEQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:27.740244 2026] [security2:error] [pid 178071:tid 178284] [client 14.225.17.146:59821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4lwhltgi7HBmNwzJN09QAAAFE"], referer: http://retzkolonglogistics.com/www
[Mon Jul 20 07:42:27.752879 2026] [security2:error] [pid 204156:tid 204336] [client 57.141.18.113:42842] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwhbAFPhDXvzP7SnGAwABwRc"]
[Mon Jul 20 07:42:27.865521 2026] [security2:error] [pid 178071:tid 178206] [client 74.208.214.194:58904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lwxltgi7HBmNwzJN1JAAAAAM"]
[Mon Jul 20 07:42:27.978486 2026] [security2:error] [pid 178071:tid 178313] [client 57.141.18.39:43021] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwhltgi7HBmNwzJN05AAAbjU"]
[Mon Jul 20 07:42:28.070769 2026] [security2:error] [pid 204156:tid 204356] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lwxbAFPhDXvzP7SnGVwAAAdU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:28.265605 2026] [security2:error] [pid 204156:tid 204407] [client 168.144.19.97:59487] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4lxBbAFPhDXvzP7SnGawAAAgg"], referer: binance.com
[Mon Jul 20 07:42:28.269891 2026] [security2:error] [pid 178071:tid 178214] [client 191.202.66.27:52740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lxBltgi7HBmNwzJN1MQAAAAs"]
[Mon Jul 20 07:42:28.269998 2026] [security2:error] [pid 178071:tid 178214] [client 191.202.66.27:52740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lxBltgi7HBmNwzJN1MQAAAAs"]
[Mon Jul 20 07:42:28.310668 2026] [security2:error] [pid 204156:tid 204337] [client 91.92.42.200:41318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4lxBbAFPhDXvzP7SnGcQAAAcI"]
[Mon Jul 20 07:42:28.351400 2026] [security2:error] [pid 178071:tid 178273] [client 14.225.17.146:58677] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4lwhltgi7HBmNwzJN0-AAAAEY"], referer: http://dadanetnet.net/www
[Mon Jul 20 07:42:28.612265 2026] [security2:error] [pid 204156:tid 204364] [client 14.225.17.146:58807] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4lwxbAFPhDXvzP7SnGKAAAAd0"], referer: http://kromosenergy.com/www
[Mon Jul 20 07:42:28.729625 2026] [security2:error] [pid 204156:tid 204403] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lxBbAFPhDXvzP7SnGgwAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:28.766606 2026] [security2:error] [pid 178071:tid 178191] [remote 100.42.189.89:39290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4lxBltgi7HBmNwzJN1RgAAOHU"]
[Mon Jul 20 07:42:28.862138 2026] [security2:error] [pid 204156:tid 204370] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lxBbAFPhDXvzP7SnGoAAAAeM"]
[Mon Jul 20 07:42:28.983797 2026] [security2:error] [pid 178071:tid 178159] [remote 100.42.189.89:39290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4lxBltgi7HBmNwzJN1TAAALlU"], referer: https://sarahholyfield.com/wp-login.php
[Mon Jul 20 07:42:29.153558 2026] [security2:error] [pid 204156:tid 204383] [client 57.141.18.110:45912] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwxbAFPhDXvzP7SnGTwAB8BU"]
[Mon Jul 20 07:42:29.195507 2026] [security2:error] [pid 178071:tid 178323] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lxBltgi7HBmNwzJN1TQAAAHg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:29.321713 2026] [security2:error] [pid 178071:tid 178209] [client 57.141.18.27:20930] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lwxltgi7HBmNwzJN1KAAABgs"]
[Mon Jul 20 07:42:29.426196 2026] [security2:error] [pid 204156:tid 204380] [client 91.92.42.200:41318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4lxRbAFPhDXvzP7SnGvQAAAe0"]
[Mon Jul 20 07:42:29.574119 2026] [security2:error] [pid 178071:tid 178291] [client 14.225.17.146:61325] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4lwxltgi7HBmNwzJN1KQAAAFg"], referer: http://nurturemarple.co.uk/www
[Mon Jul 20 07:42:29.622679 2026] [security2:error] [pid 204156:tid 204358] [client 57.141.18.88:38696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lxBbAFPhDXvzP7SnGcwAB1x0"]
[Mon Jul 20 07:42:29.680830 2026] [security2:error] [pid 204156:tid 204330] [client 136.158.60.21:42460] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lxRbAFPhDXvzP7SnGzQAAAbs"]
[Mon Jul 20 07:42:29.680971 2026] [security2:error] [pid 204156:tid 204330] [client 136.158.60.21:42460] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4lxRbAFPhDXvzP7SnGzQAAAbs"]
[Mon Jul 20 07:42:29.899441 2026] [security2:error] [pid 204156:tid 204340] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lxRbAFPhDXvzP7SnG1gAAAcU"]
[Mon Jul 20 07:42:30.042831 2026] [security2:error] [pid 178071:tid 178284] [client 50.116.65.227:46770] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4lxRltgi7HBmNwzJN1WQAAAFE"]
[Mon Jul 20 07:42:30.188249 2026] [security2:error] [pid 178071:tid 178226] [client 13.233.207.33:38258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4lxhltgi7HBmNwzJN1aAAAABc"]
[Mon Jul 20 07:42:30.235252 2026] [security2:error] [pid 178071:tid 178272] [client 50.116.65.227:46780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4lxhltgi7HBmNwzJN1ZgAAAEU"]
[Mon Jul 20 07:42:30.457765 2026] [security2:error] [pid 204156:tid 204346] [client 91.92.42.200:41318] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "newoffice.ca"] [uri "/index.php"] [unique_id "al4lxhbAFPhDXvzP7SnG8AAAAcs"]
[Mon Jul 20 07:42:30.460488 2026] [security2:error] [pid 204156:tid 204385] [client 57.141.18.122:43684] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lxRbAFPhDXvzP7SnGrgAB8kQ"]
[Mon Jul 20 07:42:30.512805 2026] [security2:error] [pid 204156:tid 204397] [client 180.249.173.210:53585] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lxhbAFPhDXvzP7SnG9wAAAf4"]
[Mon Jul 20 07:42:30.513528 2026] [security2:error] [pid 204156:tid 204397] [client 180.249.173.210:53585] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4lxhbAFPhDXvzP7SnG9wAAAf4"]
[Mon Jul 20 07:42:30.525954 2026] [security2:error] [pid 178071:tid 178285] [client 14.225.17.146:63805] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4lxhltgi7HBmNwzJN1fAAAAFI"], referer: https://nurturemarple.co.uk/www
[Mon Jul 20 07:42:30.595481 2026] [security2:error] [pid 204156:tid 204364] [client 36.93.152.155:62815] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lxhbAFPhDXvzP7SnG-QAAAd0"]
[Mon Jul 20 07:42:30.595566 2026] [security2:error] [pid 204156:tid 204364] [client 36.93.152.155:62815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4lxhbAFPhDXvzP7SnG-QAAAd0"]
[Mon Jul 20 07:42:30.825473 2026] [security2:error] [pid 204156:tid 204219] [remote 51.195.39.149:10419] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "dollpassionista.com"] [uri "/"] [unique_id "al4lxhbAFPhDXvzP7SnHCQAB1z4"]
[Mon Jul 20 07:42:30.827125 2026] [security2:error] [pid 204156:tid 204357] [client 91.92.42.200:41316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.newoffice.ca"] [uri "/index.php"] [unique_id "al4lxhbAFPhDXvzP7SnHBQAAAdY"]
[Mon Jul 20 07:42:30.935638 2026] [security2:error] [pid 204156:tid 204299] [client 14.225.17.146:58706] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4lxRbAFPhDXvzP7SnG1QAAAZw"], referer: http://getgarrison.com/www
[Mon Jul 20 07:42:31.020566 2026] [core:error] [pid 204156:tid 204371] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:31.020595 2026] [core:error] [pid 204156:tid 204371] [client 23.180.120.146:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:31.030556 2026] [security2:error] [pid 178071:tid 178323] [client 114.119.153.112:36587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.verdunestate.com"] [uri "/lebanon-beirut/propertyDetail.asp"] [unique_id "al4lxxltgi7HBmNwzJN1kQAAAHg"], referer: http://www.verdunestate.com/lebanon-beirut/propertyDetail.asp?ID=67
[Mon Jul 20 07:42:31.102008 2026] [security2:error] [pid 204156:tid 204216] [remote 115.79.143.180:38178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lxxbAFPhDXvzP7SnHFgAB-zs"]
[Mon Jul 20 07:42:31.207255 2026] [security2:error] [pid 178071:tid 178290] [client 52.167.144.229:17613] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4lxxltgi7HBmNwzJN1kgAAV0U"]
[Mon Jul 20 07:42:31.334391 2026] [security2:error] [pid 178071:tid 178294] [client 57.141.18.84:44314] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lxRltgi7HBmNwzJN1YAAAWwU"]
[Mon Jul 20 07:42:31.385433 2026] [security2:error] [pid 204156:tid 204286] [client 13.233.207.33:38268] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4lxxbAFPhDXvzP7SnHKQAAAY8"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:42:31.531602 2026] [security2:error] [pid 204156:tid 204231] [remote 115.79.143.180:38178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 180.143.79.115.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4lxxbAFPhDXvzP7SnHOQAB6Uo"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:42:31.549970 2026] [core:error] [pid 204156:tid 204358] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:31.549991 2026] [core:error] [pid 204156:tid 204358] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:31.629383 2026] [core:error] [pid 204156:tid 204332] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:31.629404 2026] [core:error] [pid 204156:tid 204332] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:31.817446 2026] [security2:error] [pid 204156:tid 204251] [remote 194.164.192.228:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lxxbAFPhDXvzP7SnHSwAB8F4"]
[Mon Jul 20 07:42:32.001174 2026] [security2:error] [pid 204156:tid 204258] [remote 194.164.192.228:54154] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4lxxbAFPhDXvzP7SnHTwABvmU"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:42:32.218295 2026] [security2:error] [pid 178071:tid 178269] [client 77.110.127.138:54579] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/competition/if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4lyBltgi7HBmNwzJN1ugAAAEI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:32.563271 2026] [security2:error] [pid 204156:tid 204309] [client 37.52.210.45:41461] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lyBbAFPhDXvzP7SnHYQAAAaY"]
[Mon Jul 20 07:42:32.563414 2026] [security2:error] [pid 204156:tid 204309] [client 37.52.210.45:41461] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4lyBbAFPhDXvzP7SnHYQAAAaY"]
[Mon Jul 20 07:42:32.582428 2026] [security2:error] [pid 204156:tid 204366] [client 14.225.17.146:63378] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4lxxbAFPhDXvzP7SnHFAAAAd8"], referer: http://olearyplumbingllc.com/www
[Mon Jul 20 07:42:32.694635 2026] [security2:error] [pid 204156:tid 204380] [client 57.141.18.33:46860] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lxxbAFPhDXvzP7SnHJwAB7WM"]
[Mon Jul 20 07:42:32.812566 2026] [security2:error] [pid 178071:tid 178278] [client 142.111.152.178:25329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4lyBltgi7HBmNwzJN1zgAAAEs"]
[Mon Jul 20 07:42:32.898480 2026] [security2:error] [pid 204156:tid 204223] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nzfoodstory.com"] [uri "/.env"] [unique_id "al4lyBbAFPhDXvzP7SnHbQAB20I"]
[Mon Jul 20 07:42:33.104932 2026] [security2:error] [pid 178071:tid 178112] [remote 104.131.116.82:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lyRltgi7HBmNwzJN15QAAEic"]
[Mon Jul 20 07:42:33.108215 2026] [security2:error] [pid 178071:tid 178252] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lyBltgi7HBmNwzJN12QAAADE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:33.187009 2026] [security2:error] [pid 178071:tid 178274] [client 14.225.17.146:58645] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4lxxltgi7HBmNwzJN1pAAAAEc"], referer: http://709fx.com/www
[Mon Jul 20 07:42:33.199800 2026] [security2:error] [pid 204156:tid 204393] [client 57.141.18.9:38196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lxxbAFPhDXvzP7SnHSQAB-mE"]
[Mon Jul 20 07:42:33.301916 2026] [security2:error] [pid 178071:tid 178093] [remote 104.131.116.82:49812] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 82.116.131.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4lyRltgi7HBmNwzJN16wAAAxQ"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:42:33.345275 2026] [security2:error] [pid 178071:tid 178319] [client 149.0.16.108:53271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lyRltgi7HBmNwzJN18QAAAHQ"]
[Mon Jul 20 07:42:33.345392 2026] [security2:error] [pid 178071:tid 178319] [client 149.0.16.108:53271] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4lyRltgi7HBmNwzJN18QAAAHQ"]
[Mon Jul 20 07:42:33.427256 2026] [autoindex:error] [pid 204156:tid 204234] [remote 5.2.67.226:59432] AH01276: Cannot serve directory /home3/vergotek/vergotek.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:42:33.434701 2026] [security2:error] [pid 178071:tid 178313] [client 104.28.30.84:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aosta.nz"] [uri "/index.php"] [unique_id "al4lyRltgi7HBmNwzJN17QAAAG4"], referer: https://aosta.nz/
[Mon Jul 20 07:42:33.851805 2026] [security2:error] [pid 204156:tid 204397] [client 104.207.51.154:54435] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 154.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lyRbAFPhDXvzP7SnHogAAAf4"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:42:33.999360 2026] [security2:error] [pid 204156:tid 204310] [client 98.87.13.111:40102] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.13.87.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4lyRbAFPhDXvzP7SnHqgAAAac"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 07:42:34.027609 2026] [security2:error] [pid 178071:tid 178275] [client 45.3.55.9:10245] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4lyhltgi7HBmNwzJN2EwAAAEg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:42:34.038450 2026] [security2:error] [pid 204156:tid 204411] [client 154.192.233.184:61349] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lyhbAFPhDXvzP7SnHsAAAAgw"]
[Mon Jul 20 07:42:34.038602 2026] [security2:error] [pid 204156:tid 204411] [client 154.192.233.184:61349] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4lyhbAFPhDXvzP7SnHsAAAAgw"]
[Mon Jul 20 07:42:34.102105 2026] [security2:error] [pid 178071:tid 178219] [client 57.141.18.68:33454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyBltgi7HBmNwzJN1zQAAEAo"]
[Mon Jul 20 07:42:34.243276 2026] [security2:error] [pid 204156:tid 204320] [client 54.81.157.232:49272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.157.81.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lyhbAFPhDXvzP7SnHtgAAAbE"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 07:42:34.278423 2026] [security2:error] [pid 204156:tid 204398] [client 168.144.19.97:50732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4lyhbAFPhDXvzP7SnHuAAAAf8"], referer: binance.com
[Mon Jul 20 07:42:34.284277 2026] [security2:error] [pid 178071:tid 178302] [client 57.141.18.123:25456] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyBltgi7HBmNwzJN11AAAY1E"]
[Mon Jul 20 07:42:34.437465 2026] [security2:error] [pid 204156:tid 204306] [client 50.116.65.227:46838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4lyhbAFPhDXvzP7SnHtwAAAaM"]
[Mon Jul 20 07:42:34.467983 2026] [security2:error] [pid 204156:tid 204381] [client 45.131.194.81:47587] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 81.194.131.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/wp-login.php"] [unique_id "al4lyhbAFPhDXvzP7SnHvwAAAe4"]
[Mon Jul 20 07:42:34.509885 2026] [security2:error] [pid 178071:tid 178294] [client 62.102.148.130:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4lyhltgi7HBmNwzJN2HwAAAFs"]
[Mon Jul 20 07:42:34.509984 2026] [security2:error] [pid 178071:tid 178294] [client 62.102.148.130:58582] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "3ddynamics.org"] [uri "/xmlrpc.php"] [unique_id "al4lyhltgi7HBmNwzJN2HwAAAFs"]
[Mon Jul 20 07:42:34.617865 2026] [security2:error] [pid 204156:tid 204301] [client 91.92.241.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4lyRbAFPhDXvzP7SnHpgABngw"]
[Mon Jul 20 07:42:34.645271 2026] [security2:error] [pid 204156:tid 204397] [client 50.116.65.227:46850] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4lyhbAFPhDXvzP7SnHwwAAAf4"]
[Mon Jul 20 07:42:34.774577 2026] [security2:error] [pid 204156:tid 204335] [client 57.141.18.51:56260] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyRbAFPhDXvzP7SnHegABwE8"]
[Mon Jul 20 07:42:35.078787 2026] [security2:error] [pid 204156:tid 204160] [remote 97.74.93.24:60954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4lyxbAFPhDXvzP7SnH7wAB3wM"]
[Mon Jul 20 07:42:35.136668 2026] [security2:error] [pid 204156:tid 204368] [client 57.141.18.110:43214] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyRbAFPhDXvzP7SnHhAAB4VE"]
[Mon Jul 20 07:42:35.241476 2026] [security2:error] [pid 204156:tid 204399] [client 114.119.135.254:59053] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.laceycaraccident.com"] [uri "/"] [unique_id "al4lyxbAFPhDXvzP7SnH9wAAAgA"], referer: https://drdavidwarwick.com/washingtons-leading-chiropractor-becoming-number-one-choice-pain-relief/
[Mon Jul 20 07:42:35.263934 2026] [security2:error] [pid 178071:tid 178246] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lyhltgi7HBmNwzJN2MAAAACs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:35.302587 2026] [security2:error] [pid 204156:tid 204412] [client 65.111.22.56:49619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lyxbAFPhDXvzP7SnH-AAAAg0"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:42:35.376202 2026] [security2:error] [pid 178071:tid 178285] [client 66.249.73.64:46020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4lyRltgi7HBmNwzJN2CgAAAFI"]
[Mon Jul 20 07:42:35.433795 2026] [security2:error] [pid 204156:tid 204387] [client 77.110.127.138:54567] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/competition/feed0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4lyxbAFPhDXvzP7SnIAwAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:35.479803 2026] [security2:error] [pid 204156:tid 204174] [remote 91.92.241.196:0] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "nzfoodstory.com"] [uri "/api/.env"] [unique_id "al4lyxbAFPhDXvzP7SnICAABoBE"]
[Mon Jul 20 07:42:35.482534 2026] [security2:error] [pid 204156:tid 204197] [remote 97.74.93.24:60954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 24.93.74.97.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4lyxbAFPhDXvzP7SnICQACBSg"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:42:35.515297 2026] [security2:error] [pid 204156:tid 204170] [remote 217.61.143.92:46840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4lyxbAFPhDXvzP7SnICwABuw0"]
[Mon Jul 20 07:42:35.650138 2026] [security2:error] [pid 204156:tid 204314] [client 179.127.84.238:58216] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lyxbAFPhDXvzP7SnIEAAAAas"]
[Mon Jul 20 07:42:35.650635 2026] [security2:error] [pid 204156:tid 204314] [client 179.127.84.238:58216] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4lyxbAFPhDXvzP7SnIEAAAAas"]
[Mon Jul 20 07:42:35.737489 2026] [security2:error] [pid 204156:tid 204168] [remote 217.61.143.92:46840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4lyxbAFPhDXvzP7SnIEQAB6gs"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 07:42:35.905567 2026] [security2:error] [pid 204156:tid 204374] [client 49.37.242.14:57637] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lyxbAFPhDXvzP7SnIFwAAAec"]
[Mon Jul 20 07:42:35.905715 2026] [security2:error] [pid 204156:tid 204374] [client 49.37.242.14:57637] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4lyxbAFPhDXvzP7SnIFwAAAec"]
[Mon Jul 20 07:42:35.971602 2026] [security2:error] [pid 204156:tid 204299] [client 57.141.18.32:30590] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyhbAFPhDXvzP7SnHyQABnA8"]
[Mon Jul 20 07:42:36.002675 2026] [security2:error] [pid 178071:tid 178286] [client 74.208.214.194:43622] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4lzBltgi7HBmNwzJN2bQAAAFM"]
[Mon Jul 20 07:42:36.245846 2026] [security2:error] [pid 204156:tid 204385] [client 57.141.18.53:37380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyhbAFPhDXvzP7SnH3QAB8no"]
[Mon Jul 20 07:42:36.331507 2026] [security2:error] [pid 204156:tid 204394] [client 36.69.4.140:15600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "collectingrealestate.com"] [uri "/index.php"] [unique_id "al4lzBbAFPhDXvzP7SnIJAAAAfs"]
[Mon Jul 20 07:42:36.491064 2026] [security2:error] [pid 178071:tid 178228] [client 188.166.209.66:49215] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4lyxltgi7HBmNwzJN2PgAAABk"], referer: binance.com
[Mon Jul 20 07:42:36.662149 2026] [security2:error] [pid 204156:tid 204324] [client 91.92.241.196:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nzfoodstory.com"] [uri "/index.php"] [unique_id "al4lzBbAFPhDXvzP7SnIIAABtSA"]
[Mon Jul 20 07:42:36.667707 2026] [security2:error] [pid 204156:tid 204400] [client 14.225.17.146:63408] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4lyhbAFPhDXvzP7SnHwAAAAgE"], referer: http://latiendadejorge.com.gt/www
[Mon Jul 20 07:42:36.702420 2026] [security2:error] [pid 204156:tid 204211] [remote 50.87.248.20:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.248.87.50.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-cron.php"] [unique_id "al4lzBbAFPhDXvzP7SnIUgAB5jY"]
[Mon Jul 20 07:42:36.730576 2026] [security2:error] [pid 204156:tid 204396] [client 104.207.50.32:48185] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4lzBbAFPhDXvzP7SnIUwAAAf0"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:42:36.840117 2026] [security2:error] [pid 178071:tid 178244] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lzBltgi7HBmNwzJN2fwAAACk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:36.856728 2026] [security2:error] [pid 178071:tid 178318] [client 186.221.114.200:56560] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lzBltgi7HBmNwzJN2jQAAAHM"]
[Mon Jul 20 07:42:36.856829 2026] [security2:error] [pid 178071:tid 178318] [client 186.221.114.200:56560] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4lzBltgi7HBmNwzJN2jQAAAHM"]
[Mon Jul 20 07:42:36.899707 2026] [security2:error] [pid 204156:tid 204215] [remote 20.89.80.94:26857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4lzBbAFPhDXvzP7SnIXAABmjo"]
[Mon Jul 20 07:42:36.993273 2026] [security2:error] [pid 178071:tid 178214] [client 57.141.18.13:49914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyxltgi7HBmNwzJN2UAAAC3M"]
[Mon Jul 20 07:42:37.121370 2026] [security2:error] [pid 204156:tid 204218] [remote 185.177.72.100:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cwp-config.php"] [unique_id "al4lzRbAFPhDXvzP7SnIXgAByD0"]
[Mon Jul 20 07:42:37.179882 2026] [security2:error] [pid 178071:tid 178224] [client 57.141.18.107:59248] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lyxltgi7HBmNwzJN2ZAAAFU4"]
[Mon Jul 20 07:42:37.278138 2026] [security2:error] [pid 204156:tid 204221] [remote 20.89.80.94:26857] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.80.89.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mochawavepublishing.com"] [uri "/wp-login.php"] [unique_id "al4lzRbAFPhDXvzP7SnIaQABkEA"], referer: https://mochawavepublishing.com/wp-login.php
[Mon Jul 20 07:42:37.728138 2026] [core:error] [pid 204156:tid 204325] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:37.728164 2026] [core:error] [pid 204156:tid 204325] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:37.736502 2026] [security2:error] [pid 178071:tid 178261] [client 14.225.17.146:62575] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4lzRltgi7HBmNwzJN2pwAAADo"]
[Mon Jul 20 07:42:37.945802 2026] [security2:error] [pid 204156:tid 204202] [remote 188.40.28.4:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4lzRbAFPhDXvzP7SnIhgAB8S0"]
[Mon Jul 20 07:42:37.951009 2026] [security2:error] [pid 178071:tid 178132] [remote 185.177.72.100:7114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cwp-config.php"] [unique_id "al4lzRltgi7HBmNwzJN2uQAAVTs"]
[Mon Jul 20 07:42:37.951082 2026] [security2:error] [pid 178071:tid 178326] [client 45.157.112.60:47481] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4lzRltgi7HBmNwzJN2uAAAAHs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:42:38.035863 2026] [security2:error] [pid 178071:tid 178077] [remote 162.19.86.63:47364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4lzhltgi7HBmNwzJN2ugAADwQ"]
[Mon Jul 20 07:42:38.043264 2026] [security2:error] [pid 178071:tid 178329] [client 49.47.218.174:58971] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lzhltgi7HBmNwzJN2vAAAAH4"]
[Mon Jul 20 07:42:38.043365 2026] [security2:error] [pid 178071:tid 178329] [client 49.47.218.174:58971] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4lzhltgi7HBmNwzJN2vAAAAH4"]
[Mon Jul 20 07:42:38.157249 2026] [security2:error] [pid 178071:tid 178233] [client 57.141.18.24:23436] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lzBltgi7HBmNwzJN2kQAAHmA"]
[Mon Jul 20 07:42:38.161483 2026] [security2:error] [pid 204156:tid 204235] [remote 188.40.28.4:50960] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wathenbartlett.co.uk"] [uri "/wp-login.php"] [unique_id "al4lzhbAFPhDXvzP7SnIjgABkk4"], referer: https://wathenbartlett.co.uk/wp-login.php
[Mon Jul 20 07:42:38.252332 2026] [security2:error] [pid 178071:tid 178187] [remote 162.19.86.63:47364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "longevityperformanceclinic.com"] [uri "/wp-login.php"] [unique_id "al4lzhltgi7HBmNwzJN2ywAAKXE"], referer: https://longevityperformanceclinic.com/wp-login.php
[Mon Jul 20 07:42:38.379364 2026] [security2:error] [pid 204156:tid 204333] [client 57.141.18.54:33936] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lzRbAFPhDXvzP7SnIZwABvhI"]
[Mon Jul 20 07:42:38.773963 2026] [security2:error] [pid 204156:tid 204360] [client 14.225.17.146:63800] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4lzhbAFPhDXvzP7SnInwAAAdk"], referer: http://falconarrowshop.com/www
[Mon Jul 20 07:42:38.796844 2026] [security2:error] [pid 204156:tid 204206] [remote 185.177.72.100:7130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fwp-config.php"] [unique_id "al4lzhbAFPhDXvzP7SnIrgABuDE"]
[Mon Jul 20 07:42:38.878376 2026] [security2:error] [pid 204156:tid 204377] [client 191.202.66.27:53237] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lzhbAFPhDXvzP7SnItQAAAeo"]
[Mon Jul 20 07:42:38.878475 2026] [security2:error] [pid 204156:tid 204377] [client 191.202.66.27:53237] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4lzhbAFPhDXvzP7SnItQAAAeo"]
[Mon Jul 20 07:42:38.889572 2026] [core:error] [pid 204156:tid 204331] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:38.889593 2026] [core:error] [pid 204156:tid 204331] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:38.988908 2026] [security2:error] [pid 204156:tid 204303] [client 103.139.191.61:55614] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lzhbAFPhDXvzP7SnIugAAAaA"]
[Mon Jul 20 07:42:38.989043 2026] [security2:error] [pid 204156:tid 204303] [client 103.139.191.61:55614] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4lzhbAFPhDXvzP7SnIugAAAaA"]
[Mon Jul 20 07:42:39.048366 2026] [security2:error] [pid 204156:tid 204227] [remote 202.51.202.242:43814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lzxbAFPhDXvzP7SnIuwAB1kY"]
[Mon Jul 20 07:42:39.048728 2026] [security2:error] [pid 204156:tid 204357] [client 202.51.202.242:43814] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4lzxbAFPhDXvzP7SnIuwAB1kY"]
[Mon Jul 20 07:42:39.110653 2026] [security2:error] [pid 204156:tid 204341] [client 114.119.133.134:47343] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "villa-m-medjugorje.com"] [uri "/contact-us/"] [unique_id "al4lzxbAFPhDXvzP7SnIvQAAAcY"], referer: https://villa-m-medjugorje.com/booking-confirmation/booking-canceled/
[Mon Jul 20 07:42:39.129553 2026] [security2:error] [pid 178071:tid 178239] [client 57.141.18.2:38264] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lzRltgi7HBmNwzJN2tgAAJC4"]
[Mon Jul 20 07:42:39.310410 2026] [security2:error] [pid 204156:tid 204292] [client 14.225.17.146:62542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4lzRbAFPhDXvzP7SnIeQAAAZU"], referer: http://careysheatingandcooling.com/www
[Mon Jul 20 07:42:39.514998 2026] [security2:error] [pid 204156:tid 204295] [client 57.141.18.17:59074] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lzhbAFPhDXvzP7SnIlQABmEs"]
[Mon Jul 20 07:42:39.559122 2026] [security2:error] [pid 204156:tid 204291] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4lzxbAFPhDXvzP7SnIyAAAAZQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:39.650983 2026] [security2:error] [pid 204156:tid 204224] [remote 185.177.72.100:7144] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fwp-config.php"] [unique_id "al4lzxbAFPhDXvzP7SnI0wABu0M"]
[Mon Jul 20 07:42:40.437428 2026] [security2:error] [pid 204156:tid 204390] [client 136.158.60.21:43934] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l0BbAFPhDXvzP7SnI8gAAAfc"]
[Mon Jul 20 07:42:40.437522 2026] [security2:error] [pid 204156:tid 204390] [client 136.158.60.21:43934] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l0BbAFPhDXvzP7SnI8gAAAfc"]
[Mon Jul 20 07:42:40.456677 2026] [security2:error] [pid 204156:tid 204396] [client 77.110.127.138:54621] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/category/competition/feed0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4l0BbAFPhDXvzP7SnI8wAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:40.603883 2026] [security2:error] [pid 204156:tid 204365] [client 57.141.18.113:27964] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lzxbAFPhDXvzP7SnIzwAB3kQ"]
[Mon Jul 20 07:42:40.765558 2026] [security2:error] [pid 204156:tid 204327] [client 57.141.18.119:43328] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4lzxbAFPhDXvzP7SnI1AABuD4"]
[Mon Jul 20 07:42:41.016988 2026] [security2:error] [pid 178071:tid 178207] [client 36.93.152.155:63325] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l0Rltgi7HBmNwzJN3JgAAAAQ"]
[Mon Jul 20 07:42:41.017101 2026] [security2:error] [pid 178071:tid 178207] [client 36.93.152.155:63325] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l0Rltgi7HBmNwzJN3JgAAAAQ"]
[Mon Jul 20 07:42:41.234794 2026] [security2:error] [pid 204156:tid 204258] [remote 185.177.72.100:7152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cconfiguration.php"] [unique_id "al4l0RbAFPhDXvzP7SnJFwABoGU"]
[Mon Jul 20 07:42:41.289022 2026] [security2:error] [pid 204156:tid 204406] [client 180.249.173.210:54090] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l0RbAFPhDXvzP7SnJGAAAAgc"]
[Mon Jul 20 07:42:41.289803 2026] [security2:error] [pid 204156:tid 204406] [client 180.249.173.210:54090] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l0RbAFPhDXvzP7SnJGAAAAgc"]
[Mon Jul 20 07:42:41.467630 2026] [security2:error] [pid 178071:tid 178272] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l0Rltgi7HBmNwzJN3LQAAAEU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:42.120079 2026] [security2:error] [pid 204156:tid 204254] [remote 185.177.72.100:7156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cconfiguration.php"] [unique_id "al4l0hbAFPhDXvzP7SnJOQAB_mE"]
[Mon Jul 20 07:42:42.226568 2026] [security2:error] [pid 178071:tid 178258] [client 57.141.18.71:36134] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l0Rltgi7HBmNwzJN3KgAANxk"]
[Mon Jul 20 07:42:42.603299 2026] [security2:error] [pid 204156:tid 204348] [client 57.141.18.44:50376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l0RbAFPhDXvzP7SnJJQABzWM"]
[Mon Jul 20 07:42:42.755946 2026] [security2:error] [pid 178071:tid 178321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l0hltgi7HBmNwzJN3WwAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:42.971234 2026] [security2:error] [pid 204156:tid 204159] [remote 185.177.72.100:7172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fconfiguration.php"] [unique_id "al4l0hbAFPhDXvzP7SnJZAACAwI"]
[Mon Jul 20 07:42:43.192132 2026] [core:error] [pid 204156:tid 204370] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:43.192150 2026] [core:error] [pid 204156:tid 204370] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:43.214470 2026] [security2:error] [pid 204156:tid 204343] [client 37.52.210.45:52573] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l0xbAFPhDXvzP7SnJdwAAAcg"]
[Mon Jul 20 07:42:43.214553 2026] [security2:error] [pid 204156:tid 204343] [client 37.52.210.45:52573] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l0xbAFPhDXvzP7SnJdwAAAcg"]
[Mon Jul 20 07:42:43.239618 2026] [core:error] [pid 178071:tid 178272] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:43.239649 2026] [core:error] [pid 178071:tid 178272] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:43.385392 2026] [security2:error] [pid 178071:tid 178323] [client 57.141.18.69:53218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l0hltgi7HBmNwzJN3XQAAeCs"]
[Mon Jul 20 07:42:43.422516 2026] [security2:error] [pid 178071:tid 178256] [client 142.111.152.73:39189] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4l0xltgi7HBmNwzJN3dwAAADU"]
[Mon Jul 20 07:42:43.445962 2026] [fcgid:warn] [pid 178071:tid 178293] (70014)End of file found: [client 66.132.195.126:25458] mod_fcgid: can't get data from http client
[Mon Jul 20 07:42:43.470582 2026] [security2:error] [pid 178071:tid 178284] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reydelcalentador.com"] [uri "/wp-admin/install.php"] [unique_id "al4l0xltgi7HBmNwzJN3gQAAAFE"]
[Mon Jul 20 07:42:43.510696 2026] [security2:error] [pid 204156:tid 204337] [client 57.141.18.47:22022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l0hbAFPhDXvzP7SnJUgABwgY"]
[Mon Jul 20 07:42:43.960031 2026] [security2:error] [pid 204156:tid 204403] [client 149.0.16.108:53799] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l0xbAFPhDXvzP7SnJjQAAAgQ"]
[Mon Jul 20 07:42:43.960118 2026] [security2:error] [pid 204156:tid 204403] [client 149.0.16.108:53799] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l0xbAFPhDXvzP7SnJjQAAAgQ"]
[Mon Jul 20 07:42:43.974441 2026] [security2:error] [pid 178071:tid 178193] [remote 185.177.72.100:7176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fconfiguration.php"] [unique_id "al4l0xltgi7HBmNwzJN3lQAAIXc"]
[Mon Jul 20 07:42:44.000272 2026] [security2:error] [pid 178071:tid 178257] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylg.kng.mybluehost.me"] [uri "/wp-admin/install.php"] [unique_id "al4l0xltgi7HBmNwzJN3lgAANgQ"]
[Mon Jul 20 07:42:44.112561 2026] [security2:error] [pid 178071:tid 178246] [client 62.102.148.130:60086] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.148.102.62.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4l1Bltgi7HBmNwzJN3nwAAACs"]
[Mon Jul 20 07:42:44.112689 2026] [security2:error] [pid 178071:tid 178246] [client 62.102.148.130:60086] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4l1Bltgi7HBmNwzJN3nwAAACs"]
[Mon Jul 20 07:42:44.123822 2026] [security2:error] [pid 178071:tid 178234] [client 173.239.254.20:50377] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 20.254.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4l1Bltgi7HBmNwzJN3nQAAAB8"]
[Mon Jul 20 07:42:44.199300 2026] [security2:error] [pid 204156:tid 204362] [client 57.141.18.78:46872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l0xbAFPhDXvzP7SnJbwAB21U"]
[Mon Jul 20 07:42:44.311652 2026] [security2:error] [pid 204156:tid 204379] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l0xbAFPhDXvzP7SnJkQAAAew"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:44.331853 2026] [security2:error] [pid 204156:tid 204321] [client 140.99.218.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.secretkeynumerology.com"] [uri "/index.php"] [unique_id "al4l1BbAFPhDXvzP7SnJnAAAAbI"]
[Mon Jul 20 07:42:44.595633 2026] [security2:error] [pid 204156:tid 204368] [client 154.192.233.184:61765] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l1BbAFPhDXvzP7SnJrQAAAeE"]
[Mon Jul 20 07:42:44.595765 2026] [security2:error] [pid 204156:tid 204368] [client 154.192.233.184:61765] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l1BbAFPhDXvzP7SnJrQAAAeE"]
[Mon Jul 20 07:42:44.726874 2026] [security2:error] [pid 204156:tid 204305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l1BbAFPhDXvzP7SnJqgAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:44.889633 2026] [security2:error] [pid 178071:tid 178209] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l1Bltgi7HBmNwzJN3twAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:45.395713 2026] [security2:error] [pid 178071:tid 178303] [client 52.167.144.215:14913] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4l0xltgi7HBmNwzJN3jQAAZBo"]
[Mon Jul 20 07:42:45.508503 2026] [security2:error] [pid 204156:tid 204282] [remote 185.177.72.100:7182] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cconfig.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ3gABmX0"]
[Mon Jul 20 07:42:45.571174 2026] [security2:error] [pid 204156:tid 204403] [client 188.166.209.66:58617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mourgroup.com"] [uri "/index.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ3AAAAgQ"], referer: binance.com
[Mon Jul 20 07:42:45.593570 2026] [security2:error] [pid 178071:tid 178279] [client 50.116.65.227:49992] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4l1Rltgi7HBmNwzJN34AAAAEw"]
[Mon Jul 20 07:42:45.604246 2026] [security2:error] [pid 178071:tid 178246] [client 50.116.65.227:50002] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4l1Rltgi7HBmNwzJN34QAAACs"]
[Mon Jul 20 07:42:45.636390 2026] [security2:error] [pid 204156:tid 204157] [remote 103.187.169.251:56056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ5AABtgA"]
[Mon Jul 20 07:42:45.759094 2026] [security2:error] [pid 204156:tid 204365] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ1gAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:45.833730 2026] [security2:error] [pid 178071:tid 178269] [client 57.141.18.8:54866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1Bltgi7HBmNwzJN3tAAAQlY"]
[Mon Jul 20 07:42:45.862009 2026] [security2:error] [pid 204156:tid 204197] [remote 188.166.241.141:33242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ8AAB3Sg"]
[Mon Jul 20 07:42:45.862166 2026] [security2:error] [pid 204156:tid 204364] [client 188.166.241.141:33242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ8AAB3Sg"]
[Mon Jul 20 07:42:45.866726 2026] [security2:error] [pid 204156:tid 204293] [client 98.159.234.160:42301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ8gAAAZY"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:42:45.963267 2026] [security2:error] [pid 178071:tid 178256] [client 57.141.18.125:63150] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1Bltgi7HBmNwzJN3xAAANWc"]
[Mon Jul 20 07:42:46.059885 2026] [security2:error] [pid 204156:tid 204194] [remote 103.187.169.251:56056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 251.169.187.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4l1hbAFPhDXvzP7SnJ9gABzSU"], referer: https://wgs.doq.mybluehost.me/wp-login.php
[Mon Jul 20 07:42:46.101182 2026] [security2:error] [pid 178071:tid 178231] [client 179.127.84.238:58744] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l1hltgi7HBmNwzJN3_QAAABw"]
[Mon Jul 20 07:42:46.101291 2026] [security2:error] [pid 178071:tid 178231] [client 179.127.84.238:58744] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l1hltgi7HBmNwzJN3_QAAABw"]
[Mon Jul 20 07:42:46.244772 2026] [security2:error] [pid 204156:tid 204386] [client 202.141.11.99:12193] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.11.141.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4l1hbAFPhDXvzP7SnKAQAAAfM"]
[Mon Jul 20 07:42:46.244877 2026] [security2:error] [pid 204156:tid 204386] [client 202.141.11.99:12193] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adambergeron.com"] [uri "/xmlrpc.php"] [unique_id "al4l1hbAFPhDXvzP7SnKAQAAAfM"]
[Mon Jul 20 07:42:46.256444 2026] [security2:error] [pid 178071:tid 178295] [client 57.141.18.83:48362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1Rltgi7HBmNwzJN30wAAXAA"]
[Mon Jul 20 07:42:46.331558 2026] [security2:error] [pid 204156:tid 204193] [remote 220.181.108.155:39421] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4l1hbAFPhDXvzP7SnKBAAB1SQ"]
[Mon Jul 20 07:42:46.363342 2026] [security2:error] [pid 204156:tid 204164] [remote 185.177.72.100:7198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cconfig.php"] [unique_id "al4l1hbAFPhDXvzP7SnKBQABtwc"]
[Mon Jul 20 07:42:46.368368 2026] [security2:error] [pid 204156:tid 204304] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l1hbAFPhDXvzP7SnJ-wAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:46.859433 2026] [security2:error] [pid 204156:tid 204305] [client 57.141.18.73:36654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ6QABogk"]
[Mon Jul 20 07:42:46.919743 2026] [security2:error] [pid 204156:tid 204190] [remote 185.88.154.76:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.154.88.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4l1hbAFPhDXvzP7SnKIAAB2CE"]
[Mon Jul 20 07:42:46.940489 2026] [security2:error] [pid 204156:tid 204324] [client 57.141.18.87:32362] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1RbAFPhDXvzP7SnJ7QABtRE"]
[Mon Jul 20 07:42:46.941284 2026] [core:error] [pid 204156:tid 204295] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:46.941299 2026] [core:error] [pid 204156:tid 204295] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:46.948648 2026] [security2:error] [pid 204156:tid 204404] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l1hbAFPhDXvzP7SnKGQAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:46.952545 2026] [core:error] [pid 204156:tid 204397] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:46.952559 2026] [core:error] [pid 204156:tid 204397] [client 94.154.43.188:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:46.960300 2026] [core:error] [pid 204156:tid 204328] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:46.960314 2026] [core:error] [pid 204156:tid 204328] [client 94.154.43.178:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:47.212958 2026] [security2:error] [pid 204156:tid 204179] [remote 185.177.72.100:7202] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fconfig.php"] [unique_id "al4l1xbAFPhDXvzP7SnKMAACDRY"]
[Mon Jul 20 07:42:47.256344 2026] [security2:error] [pid 204156:tid 204212] [remote 185.88.154.76:45170] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.154.88.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "myspineworld.com"] [uri "/wp-login.php"] [unique_id "al4l1xbAFPhDXvzP7SnKMgAB4zc"], referer: https://myspineworld.com/wp-login.php
[Mon Jul 20 07:42:47.511902 2026] [security2:error] [pid 178071:tid 178113] [remote 119.249.100.108:42042] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4l1xltgi7HBmNwzJN4PQAAFCg"]
[Mon Jul 20 07:42:47.634610 2026] [security2:error] [pid 204156:tid 204320] [client 57.141.18.71:34128] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1hbAFPhDXvzP7SnKCQABsQs"]
[Mon Jul 20 07:42:47.640811 2026] [security2:error] [pid 178071:tid 178240] [client 186.221.114.200:57043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l1xltgi7HBmNwzJN4RQAAACU"]
[Mon Jul 20 07:42:47.640972 2026] [security2:error] [pid 178071:tid 178240] [client 186.221.114.200:57043] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l1xltgi7HBmNwzJN4RQAAACU"]
[Mon Jul 20 07:42:47.805796 2026] [security2:error] [pid 204156:tid 204327] [client 57.141.18.58:31904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1hbAFPhDXvzP7SnKGgABuA8"]
[Mon Jul 20 07:42:47.822290 2026] [security2:error] [pid 204156:tid 204288] [client 57.141.18.39:31673] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1hbAFPhDXvzP7SnKGwABkXo"]
[Mon Jul 20 07:42:48.070781 2026] [security2:error] [pid 204156:tid 204218] [remote 185.177.72.100:43648] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fconfig.php"] [unique_id "al4l2BbAFPhDXvzP7SnKXgAB4j0"]
[Mon Jul 20 07:42:48.383427 2026] [security2:error] [pid 204156:tid 204301] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l2BbAFPhDXvzP7SnKYgAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:48.553547 2026] [security2:error] [pid 204156:tid 204411] [client 49.47.218.174:59508] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l2BbAFPhDXvzP7SnKdQAAAgw"]
[Mon Jul 20 07:42:48.553676 2026] [security2:error] [pid 204156:tid 204411] [client 49.47.218.174:59508] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l2BbAFPhDXvzP7SnKdQAAAgw"]
[Mon Jul 20 07:42:48.580807 2026] [security2:error] [pid 204156:tid 204384] [client 103.139.191.61:56116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4l2BbAFPhDXvzP7SnKdgAAAfE"]
[Mon Jul 20 07:42:48.580915 2026] [security2:error] [pid 204156:tid 204384] [client 103.139.191.61:56116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4l2BbAFPhDXvzP7SnKdgAAAfE"]
[Mon Jul 20 07:42:48.623914 2026] [security2:error] [pid 204156:tid 204208] [remote 119.249.100.175:49395] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4l2BbAFPhDXvzP7SnKeQAB7TM"]
[Mon Jul 20 07:42:48.628007 2026] [security2:error] [pid 204156:tid 204323] [client 57.141.18.26:29098] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1xbAFPhDXvzP7SnKOgABtCc"]
[Mon Jul 20 07:42:48.682956 2026] [security2:error] [pid 178071:tid 178230] [client 57.141.18.3:57858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1xltgi7HBmNwzJN4QQAAG2E"]
[Mon Jul 20 07:42:48.838891 2026] [security2:error] [pid 204156:tid 204368] [client 57.141.18.109:40718] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l1xbAFPhDXvzP7SnKSgAB4WA"]
[Mon Jul 20 07:42:49.263910 2026] [security2:error] [pid 204156:tid 204413] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l2RbAFPhDXvzP7SnKiAAAAg4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:49.268212 2026] [security2:error] [pid 204156:tid 204210] [remote 43.157.224.197:39772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.224.157.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4l2RbAFPhDXvzP7SnKmAABtTU"]
[Mon Jul 20 07:42:49.274022 2026] [security2:error] [pid 204156:tid 204330] [client 49.37.242.14:58249] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.242.37.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4l2RbAFPhDXvzP7SnKmgAAAbs"]
[Mon Jul 20 07:42:49.274130 2026] [security2:error] [pid 204156:tid 204330] [client 49.37.242.14:58249] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "adventure-studio.com"] [uri "/xmlrpc.php"] [unique_id "al4l2RbAFPhDXvzP7SnKmgAAAbs"]
[Mon Jul 20 07:42:49.556326 2026] [security2:error] [pid 178071:tid 178210] [client 191.202.66.27:53732] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l2Rltgi7HBmNwzJN4hwAAAAc"]
[Mon Jul 20 07:42:49.556416 2026] [security2:error] [pid 178071:tid 178210] [client 191.202.66.27:53732] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l2Rltgi7HBmNwzJN4hwAAAAc"]
[Mon Jul 20 07:42:49.655710 2026] [security2:error] [pid 204156:tid 204186] [remote 185.177.72.100:43650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cdatabase.php"] [unique_id "al4l2RbAFPhDXvzP7SnKqgABoB0"]
[Mon Jul 20 07:42:49.692217 2026] [security2:error] [pid 204156:tid 204205] [remote 43.157.224.197:39772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.224.157.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oohlovely.com"] [uri "/wp-login.php"] [unique_id "al4l2RbAFPhDXvzP7SnKsQAByzA"], referer: https://oohlovely.com/wp-login.php
[Mon Jul 20 07:42:49.871799 2026] [security2:error] [pid 178071:tid 178254] [client 57.141.18.0:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4l2Rltgi7HBmNwzJN4iwAAADM"]
[Mon Jul 20 07:42:49.874240 2026] [security2:error] [pid 204156:tid 204400] [client 57.141.18.64:40162] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2BbAFPhDXvzP7SnKggACARA"]
[Mon Jul 20 07:42:50.091113 2026] [security2:error] [pid 204156:tid 204350] [client 57.141.18.102:37564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2RbAFPhDXvzP7SnKhwABzxk"]
[Mon Jul 20 07:42:50.119014 2026] [security2:error] [pid 178071:tid 178277] [client 77.110.127.138:54665] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/if(now()=sysdate(),sleep(15),0)/page/2/"] [unique_id "al4l2hltgi7HBmNwzJN4lwAAAEo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:50.253254 2026] [security2:error] [pid 204156:tid 204326] [client 57.141.18.55:60446] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2RbAFPhDXvzP7SnKlAABt0k"]
[Mon Jul 20 07:42:50.517403 2026] [security2:error] [pid 178071:tid 178110] [remote 185.177.72.100:43660] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cdatabase.php"] [unique_id "al4l2hltgi7HBmNwzJN4qAAAZCU"]
[Mon Jul 20 07:42:50.541200 2026] [security2:error] [pid 204156:tid 204396] [client 57.141.18.110:56682] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2RbAFPhDXvzP7SnKpgAB_S8"]
[Mon Jul 20 07:42:51.204170 2026] [security2:error] [pid 204156:tid 204348] [client 18.140.64.130:22762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 130.64.140.18.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnK_AAAAc0"]
[Mon Jul 20 07:42:51.204277 2026] [security2:error] [pid 204156:tid 204348] [client 18.140.64.130:22762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnK_AAAAc0"]
[Mon Jul 20 07:42:51.222886 2026] [security2:error] [pid 204156:tid 204386] [client 136.158.60.21:45485] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnK_QAAAfM"]
[Mon Jul 20 07:42:51.222993 2026] [security2:error] [pid 204156:tid 204386] [client 136.158.60.21:45485] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnK_QAAAfM"]
[Mon Jul 20 07:42:51.358707 2026] [security2:error] [pid 204156:tid 204247] [remote 185.177.72.100:43664] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fdatabase.php"] [unique_id "al4l2xbAFPhDXvzP7SnLEwAB8Vo"]
[Mon Jul 20 07:42:51.376142 2026] [core:error] [pid 204156:tid 204300] [client 198.235.24.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:51.376183 2026] [core:error] [pid 204156:tid 204300] [client 198.235.24.13:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:51.433548 2026] [core:error] [pid 204156:tid 204369] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:51.433568 2026] [core:error] [pid 204156:tid 204369] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:51.470874 2026] [security2:error] [pid 204156:tid 204355] [client 36.93.152.155:63842] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnLHgAAAdQ"]
[Mon Jul 20 07:42:51.470974 2026] [security2:error] [pid 204156:tid 204355] [client 36.93.152.155:63842] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnLHgAAAdQ"]
[Mon Jul 20 07:42:51.504956 2026] [security2:error] [pid 178071:tid 178271] [client 57.141.18.51:49540] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2hltgi7HBmNwzJN4pQAARCM"]
[Mon Jul 20 07:42:51.639618 2026] [security2:error] [pid 204156:tid 204363] [client 180.249.173.210:54598] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnLKQAAAdw"]
[Mon Jul 20 07:42:51.640505 2026] [security2:error] [pid 204156:tid 204363] [client 180.249.173.210:54598] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l2xbAFPhDXvzP7SnLKQAAAdw"]
[Mon Jul 20 07:42:51.748293 2026] [security2:error] [pid 204156:tid 204372] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l2xbAFPhDXvzP7SnLIwAAAeU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:51.849000 2026] [security2:error] [pid 178071:tid 178247] [client 111.119.196.140:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4l2xltgi7HBmNwzJN4xAAALDU"]
[Mon Jul 20 07:42:52.198952 2026] [security2:error] [pid 204156:tid 204258] [remote 185.177.72.100:43670] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fdatabase.php"] [unique_id "al4l3BbAFPhDXvzP7SnLSQAB4mU"]
[Mon Jul 20 07:42:52.349142 2026] [security2:error] [pid 204156:tid 204269] [remote 5.252.52.249:52778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4l3BbAFPhDXvzP7SnLUQABz3A"]
[Mon Jul 20 07:42:52.518914 2026] [security2:error] [pid 204156:tid 204185] [remote 5.252.52.249:52778] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.52.252.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4l3BbAFPhDXvzP7SnLVgAB6hw"], referer: https://samdothan.org/wp-login.php
[Mon Jul 20 07:42:52.654833 2026] [security2:error] [pid 204156:tid 204315] [client 57.141.18.25:56822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2xbAFPhDXvzP7SnLIQABrEQ"]
[Mon Jul 20 07:42:52.752536 2026] [security2:error] [pid 204156:tid 204372] [client 45.3.45.123:22945] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 123.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4l3BbAFPhDXvzP7SnLWwAAAeU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:42:52.879585 2026] [security2:error] [pid 204156:tid 204402] [client 57.141.0.49:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.thescarystory.com"] [uri "/index.php"] [unique_id "al4l3BbAFPhDXvzP7SnLTAAAAgM"]
[Mon Jul 20 07:42:52.935985 2026] [security2:error] [pid 204156:tid 204288] [client 57.141.18.62:48884] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l2xbAFPhDXvzP7SnLMAABkT4"]
[Mon Jul 20 07:42:52.968733 2026] [security2:error] [pid 204156:tid 204264] [remote 100.42.189.89:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4l3BbAFPhDXvzP7SnLYwAB12s"]
[Mon Jul 20 07:42:53.086990 2026] [security2:error] [pid 178071:tid 178235] [client 158.173.89.95:59151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l3Rltgi7HBmNwzJN49QAAACA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:42:53.167899 2026] [security2:error] [pid 204156:tid 204278] [remote 100.42.189.89:39564] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4l3RbAFPhDXvzP7SnLagAB_Xk"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 07:42:53.225692 2026] [security2:error] [pid 178071:tid 178219] [client 57.141.18.96:36622] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l3Bltgi7HBmNwzJN40wAAEAw"]
[Mon Jul 20 07:42:53.334947 2026] [security2:error] [pid 178071:tid 178209] [client 57.141.18.105:53600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l3Bltgi7HBmNwzJN42QAABlA"]
[Mon Jul 20 07:42:53.372942 2026] [security2:error] [pid 204156:tid 204324] [client 65.111.26.161:27561] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4l3RbAFPhDXvzP7SnLdQAAAbU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:42:53.378048 2026] [security2:error] [pid 204156:tid 204301] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l3RbAFPhDXvzP7SnLbAAAAZ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:53.760946 2026] [security2:error] [pid 204156:tid 204274] [remote 185.177.72.100:43672] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\web.config"] [unique_id "al4l3RbAFPhDXvzP7SnLigABxXU"]
[Mon Jul 20 07:42:53.803302 2026] [security2:error] [pid 204156:tid 204302] [client 37.52.210.45:53072] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l3RbAFPhDXvzP7SnLiwAAAZ8"]
[Mon Jul 20 07:42:53.803477 2026] [security2:error] [pid 204156:tid 204302] [client 37.52.210.45:53072] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l3RbAFPhDXvzP7SnLiwAAAZ8"]
[Mon Jul 20 07:42:54.052993 2026] [security2:error] [pid 204156:tid 204337] [client 155.2.215.90:35923] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4l3RbAFPhDXvzP7SnLjgAAAcI"]
[Mon Jul 20 07:42:54.212254 2026] [security2:error] [pid 204156:tid 204397] [client 57.141.18.125:22200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l3RbAFPhDXvzP7SnLcQAB_ko"]
[Mon Jul 20 07:42:54.557877 2026] [security2:error] [pid 204156:tid 204387] [client 149.0.16.108:54331] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l3hbAFPhDXvzP7SnLvwAAAfQ"]
[Mon Jul 20 07:42:54.557967 2026] [security2:error] [pid 204156:tid 204387] [client 149.0.16.108:54331] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l3hbAFPhDXvzP7SnLvwAAAfQ"]
[Mon Jul 20 07:42:54.588950 2026] [security2:error] [pid 204156:tid 204236] [remote 185.177.72.100:43678] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..\\\\web.config"] [unique_id "al4l3hbAFPhDXvzP7SnLwQACAU8"]
[Mon Jul 20 07:42:54.609154 2026] [security2:error] [pid 204156:tid 204385] [client 77.110.127.138:54682] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/2/"] [unique_id "al4l3hbAFPhDXvzP7SnLwwAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:54.771167 2026] [security2:error] [pid 204156:tid 204265] [remote 5.161.225.162:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4l3hbAFPhDXvzP7SnLywAB8Ww"]
[Mon Jul 20 07:42:54.816025 2026] [security2:error] [pid 178071:tid 178211] [client 104.207.40.232:28087] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 232.40.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l3hltgi7HBmNwzJN5NAAAAAg"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:54.867262 2026] [security2:error] [pid 178071:tid 178317] [client 57.141.18.58:31914] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l3Rltgi7HBmNwzJN5CQAAck0"]
[Mon Jul 20 07:42:54.942826 2026] [security2:error] [pid 204156:tid 204277] [remote 5.161.225.162:47774] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4l3hbAFPhDXvzP7SnL0AAB_ng"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:42:55.052103 2026] [security2:error] [pid 204156:tid 204158] [remote 57.141.18.118:39318] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 118.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3699682"] [unique_id "al4l3xbAFPhDXvzP7SnL1gABxQE"]
[Mon Jul 20 07:42:55.121126 2026] [security2:error] [pid 204156:tid 204300] [client 154.192.233.184:62152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l3xbAFPhDXvzP7SnL2gAAAZ0"]
[Mon Jul 20 07:42:55.121230 2026] [security2:error] [pid 204156:tid 204300] [client 154.192.233.184:62152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l3xbAFPhDXvzP7SnL2gAAAZ0"]
[Mon Jul 20 07:42:55.172649 2026] [security2:error] [pid 204156:tid 204378] [client 14.225.17.146:50125] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "getgarrison.com"] [uri "/index.php"] [unique_id "al4l3xbAFPhDXvzP7SnL1wAAAes"], referer: http://getgarrison.com/WWW
[Mon Jul 20 07:42:55.378769 2026] [security2:error] [pid 204156:tid 204347] [client 45.3.41.139:55551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 139.41.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l3xbAFPhDXvzP7SnL6wAAAcw"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:55.396404 2026] [security2:error] [pid 204156:tid 204164] [remote 185.177.72.100:43684] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fweb.config"] [unique_id "al4l3xbAFPhDXvzP7SnL7wAB9gc"]
[Mon Jul 20 07:42:55.614445 2026] [security2:error] [pid 178071:tid 178237] [client 14.225.17.146:50082] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.agency"] [uri "/index.php"] [unique_id "al4l3hltgi7HBmNwzJN5NwAAACI"], referer: http://idigress.agency/WWW
[Mon Jul 20 07:42:55.633731 2026] [security2:error] [pid 178071:tid 178297] [client 116.179.33.76:37887] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4l3xltgi7HBmNwzJN5UQAAAF4"]
[Mon Jul 20 07:42:55.830376 2026] [core:error] [pid 178071:tid 178278] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:55.830397 2026] [core:error] [pid 178071:tid 178278] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:42:55.938845 2026] [security2:error] [pid 204156:tid 204339] [client 65.111.8.212:15023] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l3xbAFPhDXvzP7SnMCwAAAcQ"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:55.969474 2026] [security2:error] [pid 178071:tid 178272] [client 85.25.172.249:53340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "302"] [hostname "50.116.65.227"] [uri "/index.cgi"] [unique_id "al4l3xltgi7HBmNwzJN5XgAAAEU"]
[Mon Jul 20 07:42:56.024463 2026] [security2:error] [pid 178071:tid 178293] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l3xltgi7HBmNwzJN5WAAAAFo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:56.033353 2026] [security2:error] [pid 204156:tid 204322] [client 57.141.18.37:28874] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l3xbAFPhDXvzP7SnL1QABsxo"]
[Mon Jul 20 07:42:56.130472 2026] [security2:error] [pid 178071:tid 178314] [client 85.25.172.249:53340] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "404"] [hostname "50.116.65.227"] [uri "/404.html"] [unique_id "al4l4Bltgi7HBmNwzJN5ZgAAAG8"], referer: http://50.116.65.227:80/cgi-bin/luci/;stok=/locale
[Mon Jul 20 07:42:56.224217 2026] [security2:error] [pid 178071:tid 178149] [remote 185.177.72.100:43686] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "web.config"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fweb.config"] [unique_id "al4l4Bltgi7HBmNwzJN5cAAAfks"]
[Mon Jul 20 07:42:56.299068 2026] [security2:error] [pid 178071:tid 178226] [client 18.141.57.241:23904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4l4Bltgi7HBmNwzJN5cgAAABc"], referer: https://curlsnpearlsss.com/es/caramel-apple-grapes-easy-recipe/
[Mon Jul 20 07:42:56.525390 2026] [security2:error] [pid 204156:tid 204403] [client 65.111.2.160:29865] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l4BbAFPhDXvzP7SnMHgAAAgQ"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:56.582760 2026] [security2:error] [pid 178071:tid 178317] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4Bltgi7HBmNwzJN5eAAAAHI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:56.609819 2026] [security2:error] [pid 178071:tid 178214] [client 179.127.84.238:59289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l4Bltgi7HBmNwzJN5hwAAAAs"]
[Mon Jul 20 07:42:56.610019 2026] [security2:error] [pid 178071:tid 178214] [client 179.127.84.238:59289] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l4Bltgi7HBmNwzJN5hwAAAAs"]
[Mon Jul 20 07:42:56.683568 2026] [security2:error] [pid 204156:tid 204335] [client 57.141.18.73:49000] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l3xbAFPhDXvzP7SnL8gABwAo"]
[Mon Jul 20 07:42:57.010578 2026] [security2:error] [pid 204156:tid 204358] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4BbAFPhDXvzP7SnMLQAAAdc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:57.079733 2026] [security2:error] [pid 178071:tid 178290] [client 104.207.49.161:57109] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 161.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l4Rltgi7HBmNwzJN5kQAAAFc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:42:57.127914 2026] [security2:error] [pid 178071:tid 178251] [client 50.116.65.227:52836] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4l4Rltgi7HBmNwzJN5nAAAADA"]
[Mon Jul 20 07:42:57.136718 2026] [security2:error] [pid 178071:tid 178294] [client 50.116.65.227:52846] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4l4Rltgi7HBmNwzJN5nwAAAFs"]
[Mon Jul 20 07:42:57.155183 2026] [security2:error] [pid 178071:tid 178209] [client 14.225.17.146:61741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "betterbonddogtraining.com"] [uri "/index.php"] [unique_id "al4l4Rltgi7HBmNwzJN5kwAAAAY"], referer: http://betterbonddogtraining.com/WWW
[Mon Jul 20 07:42:57.553522 2026] [security2:error] [pid 204156:tid 204385] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4RbAFPhDXvzP7SnMQAAAAfI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:57.751573 2026] [security2:error] [pid 178071:tid 178267] [client 14.225.17.146:62979] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "daseighty.net"] [uri "/index.php"] [unique_id "al4l4Rltgi7HBmNwzJN5vAAAAEA"], referer: http://daseighty.net/WWW
[Mon Jul 20 07:42:57.903416 2026] [security2:error] [pid 204156:tid 204386] [client 18.141.57.241:23908] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.57.141.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4l4RbAFPhDXvzP7SnMSwAAAfM"], referer: https://curlsnpearlsss.com/es/caramel-apple-grapes-easy-recipe/
[Mon Jul 20 07:42:58.045215 2026] [security2:error] [pid 178071:tid 178258] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4Rltgi7HBmNwzJN5ygAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:58.089614 2026] [security2:error] [pid 178071:tid 178248] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4Rltgi7HBmNwzJN5zQAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:58.380111 2026] [security2:error] [pid 204156:tid 204308] [client 186.221.114.200:57516] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l4hbAFPhDXvzP7SnMVwAAAaU"]
[Mon Jul 20 07:42:58.380207 2026] [security2:error] [pid 204156:tid 204308] [client 186.221.114.200:57516] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l4hbAFPhDXvzP7SnMVwAAAaU"]
[Mon Jul 20 07:42:58.543538 2026] [security2:error] [pid 204156:tid 204370] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4hbAFPhDXvzP7SnMVgAAAeM"]
[Mon Jul 20 07:42:58.662472 2026] [security2:error] [pid 204156:tid 204348] [client 46.110.96.34:42428] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4l4hbAFPhDXvzP7SnMYQAAAc0"]
[Mon Jul 20 07:42:58.735715 2026] [security2:error] [pid 178071:tid 178261] [client 57.141.18.67:22044] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l4Rltgi7HBmNwzJN5swAAOkg"]
[Mon Jul 20 07:42:59.034168 2026] [security2:error] [pid 204156:tid 204397] [client 49.47.218.174:60055] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l4xbAFPhDXvzP7SnMdwAAAf4"]
[Mon Jul 20 07:42:59.034279 2026] [security2:error] [pid 204156:tid 204397] [client 49.47.218.174:60055] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l4xbAFPhDXvzP7SnMdwAAAf4"]
[Mon Jul 20 07:42:59.070855 2026] [security2:error] [pid 178071:tid 178205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l4hltgi7HBmNwzJN5_wAAAAI"]
[Mon Jul 20 07:42:59.241090 2026] [security2:error] [pid 204156:tid 204403] [client 77.110.127.138:54708] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/2/"] [unique_id "al4l4xbAFPhDXvzP7SnMfgAAAgQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:42:59.253535 2026] [security2:error] [pid 178071:tid 178212] [client 57.141.18.119:23934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l4hltgi7HBmNwzJN50AAACVQ"]
[Mon Jul 20 07:42:59.464154 2026] [security2:error] [pid 178071:tid 178228] [client 34.74.242.206:1679] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4l4xltgi7HBmNwzJN6GwAAABk"]
[Mon Jul 20 07:42:59.464247 2026] [security2:error] [pid 178071:tid 178228] [client 34.74.242.206:1679] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "omenana.com"] [uri "/robots.txt"] [unique_id "al4l4xltgi7HBmNwzJN6GwAAABk"]
[Mon Jul 20 07:42:59.607051 2026] [security2:error] [pid 204156:tid 204391] [client 46.110.96.34:55730] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4l4xbAFPhDXvzP7SnMigAAAfg"]
[Mon Jul 20 07:42:59.607369 2026] [security2:error] [pid 204156:tid 204302] [client 46.110.96.34:54916] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4l4xbAFPhDXvzP7SnMiQAAAZ8"]
[Mon Jul 20 07:42:59.809504 2026] [security2:error] [pid 204156:tid 204303] [client 54.244.177.189:60544] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 189.177.244.54.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l4xbAFPhDXvzP7SnMmAAAAaA"]
[Mon Jul 20 07:43:00.033926 2026] [core:error] [pid 204156:tid 204308] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:00.033948 2026] [core:error] [pid 204156:tid 204308] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:00.041186 2026] [core:error] [pid 178071:tid 178303] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:00.041212 2026] [core:error] [pid 178071:tid 178303] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:00.068079 2026] [security2:error] [pid 204156:tid 204301] [client 57.141.18.75:44724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l4hbAFPhDXvzP7SnMdAABnmA"]
[Mon Jul 20 07:43:00.204423 2026] [security2:error] [pid 204156:tid 204411] [client 158.173.166.181:53309] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l5BbAFPhDXvzP7SnMugAAAgw"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:43:00.278444 2026] [security2:error] [pid 204156:tid 204413] [client 191.202.66.27:54227] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l5BbAFPhDXvzP7SnMvgAAAg4"]
[Mon Jul 20 07:43:00.278593 2026] [security2:error] [pid 204156:tid 204413] [client 191.202.66.27:54227] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l5BbAFPhDXvzP7SnMvgAAAg4"]
[Mon Jul 20 07:43:00.949760 2026] [security2:error] [pid 204156:tid 204304] [client 57.141.18.92:33694] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l5BbAFPhDXvzP7SnMrQABoRU"]
[Mon Jul 20 07:43:01.100855 2026] [security2:error] [pid 204156:tid 204376] [client 18.142.226.106:25568] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.226.142.18.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4l5RbAFPhDXvzP7SnM5QAAAek"], referer: https://curlsnpearlsss.com/es/caramel-apple-grapes-easy-recipe/
[Mon Jul 20 07:43:01.130447 2026] [security2:error] [pid 204156:tid 204315] [client 13.215.47.127:27592] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 127.47.215.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l5RbAFPhDXvzP7SnM6AAAAaw"], referer: https://curlsnpearlsss.com/es/caramel-apple-grapes-easy-recipe/
[Mon Jul 20 07:43:01.335807 2026] [security2:error] [pid 204156:tid 204320] [client 57.141.18.57:59728] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l5BbAFPhDXvzP7SnMwwABsUE"]
[Mon Jul 20 07:43:01.355112 2026] [security2:error] [pid 204156:tid 204411] [client 14.225.17.146:63095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "39ishlife.com"] [uri "/index.php"] [unique_id "al4l5RbAFPhDXvzP7SnM7QAAAgw"], referer: http://39ishlife.com/WWW
[Mon Jul 20 07:43:01.915108 2026] [security2:error] [pid 204156:tid 204317] [client 14.225.17.146:63196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "headachescarpaltunnelfibromyalgia.com"] [uri "/index.php"] [unique_id "al4l5RbAFPhDXvzP7SnM_gAAAa4"], referer: http://headachescarpaltunnelfibromyalgia.com/WWW
[Mon Jul 20 07:43:01.957744 2026] [security2:error] [pid 204156:tid 204374] [client 136.158.60.21:47065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l5RbAFPhDXvzP7SnNBgAAAec"]
[Mon Jul 20 07:43:01.957913 2026] [security2:error] [pid 204156:tid 204374] [client 136.158.60.21:47065] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l5RbAFPhDXvzP7SnNBgAAAec"]
[Mon Jul 20 07:43:02.000777 2026] [security2:error] [pid 204156:tid 204369] [client 36.93.152.155:64363] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l5hbAFPhDXvzP7SnNCQAAAeI"]
[Mon Jul 20 07:43:02.000882 2026] [security2:error] [pid 204156:tid 204369] [client 36.93.152.155:64363] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l5hbAFPhDXvzP7SnNCQAAAeI"]
[Mon Jul 20 07:43:02.085768 2026] [security2:error] [pid 204156:tid 204334] [client 14.225.17.146:56623] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nomorewetsheets.net"] [uri "/index.php"] [unique_id "al4l5RbAFPhDXvzP7SnNAwAAAb8"], referer: http://nomorewetsheets.net/WWW
[Mon Jul 20 07:43:02.135446 2026] [security2:error] [pid 204156:tid 204297] [client 57.141.18.47:29380] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l5RbAFPhDXvzP7SnM7gABmkw"]
[Mon Jul 20 07:43:02.203207 2026] [security2:error] [pid 204156:tid 204225] [remote 81.173.115.7:44034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4l5hbAFPhDXvzP7SnNGwABwkQ"]
[Mon Jul 20 07:43:02.248834 2026] [security2:error] [pid 204156:tid 204413] [client 57.141.18.20:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4l5hbAFPhDXvzP7SnNFAAAAg4"]
[Mon Jul 20 07:43:02.288591 2026] [security2:error] [pid 178071:tid 178297] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l5hltgi7HBmNwzJN6bAAAAF4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:02.310093 2026] [security2:error] [pid 204156:tid 204401] [client 14.225.17.146:56463] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.39ishlife.com"] [uri "/index.php"] [unique_id "al4l5hbAFPhDXvzP7SnNHQAAAgI"], referer: https://39ishlife.com/WWW
[Mon Jul 20 07:43:02.466790 2026] [security2:error] [pid 178071:tid 178276] [client 180.249.173.210:55114] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l5hltgi7HBmNwzJN6fAAAAEk"]
[Mon Jul 20 07:43:02.469396 2026] [security2:error] [pid 178071:tid 178276] [client 180.249.173.210:55114] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l5hltgi7HBmNwzJN6fAAAAEk"]
[Mon Jul 20 07:43:02.537147 2026] [security2:error] [pid 204156:tid 204239] [remote 81.173.115.7:44034] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4l5hbAFPhDXvzP7SnNKAABkFI"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:43:02.686551 2026] [security2:error] [pid 178071:tid 178296] [client 46.110.96.34:47016] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4l5hltgi7HBmNwzJN6gAAAAF0"]
[Mon Jul 20 07:43:02.774366 2026] [security2:error] [pid 204156:tid 204312] [client 57.141.18.43:37558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l5hbAFPhDXvzP7SnNDAABqWk"]
[Mon Jul 20 07:43:03.034443 2026] [security2:error] [pid 204156:tid 204382] [client 13.229.223.11:28070] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.223.229.13.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l5xbAFPhDXvzP7SnNOwAAAe8"], referer: https://curlsnpearlsss.com/es/caramel-apple-grapes-easy-recipe/
[Mon Jul 20 07:43:03.271230 2026] [security2:error] [pid 204156:tid 204335] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l5xbAFPhDXvzP7SnNPwAAAcA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:03.318153 2026] [security2:error] [pid 204156:tid 204350] [client 57.141.18.17:62468] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l5hbAFPhDXvzP7SnNLAABz0c"]
[Mon Jul 20 07:43:03.335612 2026] [security2:error] [pid 178071:tid 178312] [client 47.129.222.11:46242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.222.129.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l5xltgi7HBmNwzJN6mQAAAG0"]
[Mon Jul 20 07:43:03.335705 2026] [security2:error] [pid 178071:tid 178312] [client 47.129.222.11:46242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l5xltgi7HBmNwzJN6mQAAAG0"]
[Mon Jul 20 07:43:03.518948 2026] [security2:error] [pid 204156:tid 204411] [client 45.154.149.97:25548] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4l5xbAFPhDXvzP7SnNRAACDGY"]
[Mon Jul 20 07:43:03.793119 2026] [security2:error] [pid 178071:tid 178237] [client 57.141.18.32:58858] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l5xltgi7HBmNwzJN6kAAAIgY"]
[Mon Jul 20 07:43:04.065329 2026] [security2:error] [pid 178071:tid 178160] [remote 124.55.178.99:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4l6Bltgi7HBmNwzJN6vAAAIFY"]
[Mon Jul 20 07:43:04.308442 2026] [security2:error] [pid 204156:tid 204333] [client 14.225.17.146:57356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "careysheatingandcooling.com"] [uri "/index.php"] [unique_id "al4l6BbAFPhDXvzP7SnNaAAAAb4"], referer: http://careysheatingandcooling.com/WWW
[Mon Jul 20 07:43:04.427623 2026] [security2:error] [pid 178071:tid 178203] [client 37.52.210.45:53571] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l6Bltgi7HBmNwzJN6zAAAAAA"]
[Mon Jul 20 07:43:04.427799 2026] [security2:error] [pid 178071:tid 178203] [client 37.52.210.45:53571] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l6Bltgi7HBmNwzJN6zAAAAAA"]
[Mon Jul 20 07:43:04.591630 2026] [security2:error] [pid 178071:tid 178161] [remote 57.141.18.2:42616] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3223093"] [unique_id "al4l6Bltgi7HBmNwzJN62AAAWlc"]
[Mon Jul 20 07:43:04.673028 2026] [security2:error] [pid 178071:tid 178212] [client 14.225.17.146:57928] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aandarealtygroup.com"] [uri "/index.php"] [unique_id "al4l6Bltgi7HBmNwzJN60QAAAAk"], referer: http://aandarealtygroup.com/WWW
[Mon Jul 20 07:43:04.687482 2026] [security2:error] [pid 178071:tid 178232] [client 155.2.215.89:43301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4l6Bltgi7HBmNwzJN60gAAAB0"]
[Mon Jul 20 07:43:04.802734 2026] [security2:error] [pid 178071:tid 178128] [remote 124.55.178.99:54146] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mourgroup.com"] [uri "/wp-login.php"] [unique_id "al4l6Bltgi7HBmNwzJN64QAABjc"], referer: https://mourgroup.com/wp-login.php
[Mon Jul 20 07:43:04.851835 2026] [security2:error] [pid 178071:tid 178210] [client 57.141.18.54:29444] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l6Bltgi7HBmNwzJN6wQAAB2Q"]
[Mon Jul 20 07:43:04.856996 2026] [security2:error] [pid 204156:tid 204287] [client 3.85.191.173:48346] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 173.191.85.3.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-content/plugins/translatepress-multilingual/includes/trp-ajax.php"] [unique_id "al4l6BbAFPhDXvzP7SnNigAAAZA"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 07:43:05.059203 2026] [security2:error] [pid 204156:tid 204271] [remote 162.19.86.63:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4l6RbAFPhDXvzP7SnNlgACCnI"]
[Mon Jul 20 07:43:05.070599 2026] [security2:error] [pid 204156:tid 204361] [client 57.141.18.96:42620] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l6BbAFPhDXvzP7SnNdgAB2gY"]
[Mon Jul 20 07:43:05.187245 2026] [security2:error] [pid 204156:tid 204374] [client 149.0.16.108:54855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l6RbAFPhDXvzP7SnNmQAAAec"]
[Mon Jul 20 07:43:05.187337 2026] [security2:error] [pid 204156:tid 204374] [client 149.0.16.108:54855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l6RbAFPhDXvzP7SnNmQAAAec"]
[Mon Jul 20 07:43:05.199675 2026] [security2:error] [pid 178071:tid 178318] [client 15.229.69.106:54590] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l6Rltgi7HBmNwzJN6-AAAAHM"]
[Mon Jul 20 07:43:05.199912 2026] [security2:error] [pid 178071:tid 178318] [client 15.229.69.106:54590] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l6Rltgi7HBmNwzJN6-AAAAHM"]
[Mon Jul 20 07:43:05.211085 2026] [core:error] [pid 204156:tid 204315] [client 14.225.17.146:57306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:05.211108 2026] [core:error] [pid 204156:tid 204315] [client 14.225.17.146:57306] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:05.211287 2026] [security2:error] [pid 178071:tid 178328] [client 98.87.13.111:47286] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 111.13.87.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l6Rltgi7HBmNwzJN6-gAAAH0"], referer: https://curlsnpearlsss.com/es/tag/jamon-con-pina/
[Mon Jul 20 07:43:05.285582 2026] [security2:error] [pid 204156:tid 204284] [remote 162.19.86.63:60976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fluidtemple.org"] [uri "/wp-login.php"] [unique_id "al4l6RbAFPhDXvzP7SnNoQABv38"], referer: https://fluidtemple.org/wp-login.php
[Mon Jul 20 07:43:05.292279 2026] [security2:error] [pid 178071:tid 178248] [client 50.116.65.227:44080] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4l6Rltgi7HBmNwzJN6_gAAAC0"]
[Mon Jul 20 07:43:05.310581 2026] [security2:error] [pid 204156:tid 204356] [client 50.116.65.227:27406] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Japan-Transport-Feature-Image.png"] [unique_id "al4l6RbAFPhDXvzP7SnNogAAAdU"]
[Mon Jul 20 07:43:05.329556 2026] [security2:error] [pid 178071:tid 178122] [remote 217.61.143.92:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4l6Rltgi7HBmNwzJN6_wAAcjE"]
[Mon Jul 20 07:43:05.432843 2026] [security2:error] [pid 204156:tid 204324] [client 146.103.115.115:49467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.115.103.146.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "suretybonds-california.com"] [uri "/wp-content/plugins/si-captcha-for-wordpress/captcha/securimage_show.php"] [unique_id "al4l6RbAFPhDXvzP7SnNpwAAAbU"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:43:05.460325 2026] [security2:error] [pid 204156:tid 204317] [client 57.141.18.80:56904] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l6BbAFPhDXvzP7SnNjQABrhg"]
[Mon Jul 20 07:43:05.564352 2026] [security2:error] [pid 178071:tid 178183] [remote 217.61.143.92:33042] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "northbrookcpa.ca"] [uri "/wp-login.php"] [unique_id "al4l6Rltgi7HBmNwzJN7CAAAYW0"], referer: https://northbrookcpa.ca/wp-login.php
[Mon Jul 20 07:43:05.591915 2026] [security2:error] [pid 204156:tid 204395] [client 154.192.233.184:60565] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l6RbAFPhDXvzP7SnNqwAAAfw"]
[Mon Jul 20 07:43:05.592069 2026] [security2:error] [pid 204156:tid 204395] [client 154.192.233.184:60565] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l6RbAFPhDXvzP7SnNqwAAAfw"]
[Mon Jul 20 07:43:05.723697 2026] [security2:error] [pid 178071:tid 178242] [client 146.103.115.115:49521] ModSecurity: Access denied with code 406 (phase 1). IPmatchFromFile: "146.103.115.115" matched at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1090"] [id "999022"] [msg "Blacklisted IP Address for POST data StopForumSpam List"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4l6Rltgi7HBmNwzJN7DgAAACc"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:43:05.723798 2026] [security2:error] [pid 178071:tid 178242] [client 146.103.115.115:49521] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "147"] [id "900404"] [msg "wp-comments-post POST logging"] [data "406"] [hostname "suretybonds-california.com"] [uri "/wp-comments-post.php"] [unique_id "al4l6Rltgi7HBmNwzJN7DgAAACc"], referer: http://suretybonds-california.com/esop-employee-stock-ownership-plan/
[Mon Jul 20 07:43:05.931737 2026] [core:error] [pid 204156:tid 204293] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:05.931782 2026] [core:error] [pid 204156:tid 204293] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:06.042261 2026] [security2:error] [pid 204156:tid 204396] [client 14.225.17.146:57908] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alrowad-hub.net"] [uri "/index.php"] [unique_id "al4l6RbAFPhDXvzP7SnNtgAAAf0"], referer: http://alrowad-hub.net/WWW
[Mon Jul 20 07:43:06.295061 2026] [security2:error] [pid 178071:tid 178277] [client 46.110.96.34:7398] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4l6hltgi7HBmNwzJN7KQAAAEo"]
[Mon Jul 20 07:43:06.338375 2026] [security2:error] [pid 178071:tid 178236] [client 14.225.17.146:57485] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "grecruit.online"] [uri "/index.php"] [unique_id "al4l6Rltgi7HBmNwzJN7GAAAACE"], referer: http://grecruit.online/WWW
[Mon Jul 20 07:43:06.511957 2026] [security2:error] [pid 204156:tid 204340] [client 45.3.54.152:17409] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 152.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4l6hbAFPhDXvzP7SnN1gAAAcU"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:06.565599 2026] [security2:error] [pid 204156:tid 204388] [client 14.225.17.146:56879] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "claysharecon.com"] [uri "/index.php"] [unique_id "al4l6RbAFPhDXvzP7SnNrAAAAfU"], referer: http://claysharecon.com/WWW
[Mon Jul 20 07:43:06.792640 2026] [security2:error] [pid 178071:tid 178211] [client 195.63.31.13:15639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.31.63.195.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l6hltgi7HBmNwzJN7OgAAAAg"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:06.957982 2026] [security2:error] [pid 204156:tid 204164] [remote 78.46.157.202:58022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4l6hbAFPhDXvzP7SnN5gABzwc"]
[Mon Jul 20 07:43:06.999886 2026] [security2:error] [pid 178071:tid 178249] [client 14.225.17.146:62702] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ravmike.com"] [uri "/index.php"] [unique_id "al4l6hltgi7HBmNwzJN7QQAAAC4"], referer: http://ravmike.com/WWW
[Mon Jul 20 07:43:07.062260 2026] [security2:error] [pid 178071:tid 178248] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l6hltgi7HBmNwzJN7PgAAAC0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:07.141614 2026] [security2:error] [pid 178071:tid 178276] [client 179.127.84.238:59833] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l6xltgi7HBmNwzJN7SwAAAEk"]
[Mon Jul 20 07:43:07.141779 2026] [security2:error] [pid 178071:tid 178276] [client 179.127.84.238:59833] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l6xltgi7HBmNwzJN7SwAAAEk"]
[Mon Jul 20 07:43:07.340692 2026] [security2:error] [pid 204156:tid 204412] [client 65.111.7.197:54119] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 197.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l6xbAFPhDXvzP7SnN-QAAAg0"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:07.353619 2026] [security2:error] [pid 204156:tid 204281] [remote 78.46.157.202:58022] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 202.157.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/wp-login.php"] [unique_id "al4l6xbAFPhDXvzP7SnN-wAB6Hw"], referer: https://joulecommunications.com/wp-login.php
[Mon Jul 20 07:43:07.458253 2026] [security2:error] [pid 204156:tid 204400] [client 14.225.17.146:57068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "iagdevelopments.com"] [uri "/index.php"] [unique_id "al4l6xbAFPhDXvzP7SnN-gAAAgE"], referer: http://iagdevelopments.com/WWW
[Mon Jul 20 07:43:07.494637 2026] [security2:error] [pid 178071:tid 178263] [client 57.141.18.84:61102] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l6hltgi7HBmNwzJN7QwAAPE4"]
[Mon Jul 20 07:43:07.907198 2026] [security2:error] [pid 204156:tid 204366] [client 65.111.9.137:49551] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l6xbAFPhDXvzP7SnOFQAAAd8"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:07.965265 2026] [security2:error] [pid 204156:tid 204331] [client 104.207.50.76:60289] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4l6xbAFPhDXvzP7SnOFgAAAbw"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:07.985951 2026] [security2:error] [pid 204156:tid 204386] [client 14.225.17.146:55400] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ravmike.com"] [uri "/index.php"] [unique_id "al4l6xbAFPhDXvzP7SnOFwAAAfM"], referer: https://ravmike.com/WWW
[Mon Jul 20 07:43:08.057167 2026] [security2:error] [pid 178071:tid 178259] [client 57.141.18.100:22052] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l6xltgi7HBmNwzJN7VwAAOG4"]
[Mon Jul 20 07:43:08.066680 2026] [security2:error] [pid 204156:tid 204290] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l6xbAFPhDXvzP7SnOEwAAAZM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:08.212229 2026] [security2:error] [pid 178071:tid 178221] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7Bltgi7HBmNwzJN7bQAAABI"], referer: 1'"3000
[Mon Jul 20 07:43:08.351957 2026] [security2:error] [pid 178071:tid 178289] [client 14.225.17.146:62859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.iagdevelopments.com"] [uri "/index.php"] [unique_id "al4l7Bltgi7HBmNwzJN7dgAAAFY"], referer: https://iagdevelopments.com/WWW
[Mon Jul 20 07:43:08.489174 2026] [security2:error] [pid 204156:tid 204362] [client 14.225.17.146:65425] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "katsklar.com"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnOMQAAAds"], referer: http://katsklar.com/WWW
[Mon Jul 20 07:43:08.494431 2026] [security2:error] [pid 178071:tid 178230] [client 65.111.7.129:38711] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 129.7.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l7Bltgi7HBmNwzJN7gAAAABs"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:08.501264 2026] [security2:error] [pid 204156:tid 204344] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnOLgAAAck"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:08.599886 2026] [security2:error] [pid 204156:tid 204197] [remote 5.161.225.162:39156] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l7BbAFPhDXvzP7SnOPQABkCg"]
[Mon Jul 20 07:43:08.600099 2026] [security2:error] [pid 204156:tid 204287] [client 5.161.225.162:39156] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l7BbAFPhDXvzP7SnOPQABkCg"]
[Mon Jul 20 07:43:08.654494 2026] [security2:error] [pid 204156:tid 204350] [client 57.141.18.119:45300] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnOHQABzxY"]
[Mon Jul 20 07:43:08.675668 2026] [security2:error] [pid 204156:tid 204304] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnONwAAAaE"], referer: 1'"3000
[Mon Jul 20 07:43:08.951662 2026] [security2:error] [pid 204156:tid 204332] [client 57.141.18.59:25660] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnOLwABvTc"]
[Mon Jul 20 07:43:09.031336 2026] [security2:error] [pid 178071:tid 178232] [client 65.111.8.212:20425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 212.8.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l7Rltgi7HBmNwzJN7oQAAAB0"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:09.340308 2026] [security2:error] [pid 204156:tid 204341] [client 186.221.114.200:58001] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l7RbAFPhDXvzP7SnOWwAAAcY"]
[Mon Jul 20 07:43:09.340404 2026] [security2:error] [pid 204156:tid 204341] [client 186.221.114.200:58001] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l7RbAFPhDXvzP7SnOWwAAAcY"]
[Mon Jul 20 07:43:09.387271 2026] [security2:error] [pid 178071:tid 178261] [client 50.116.65.227:18444] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4l7Rltgi7HBmNwzJN7twAAADo"]
[Mon Jul 20 07:43:09.397440 2026] [security2:error] [pid 178071:tid 178308] [client 50.116.65.227:18446] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4l7Rltgi7HBmNwzJN7uAAAAGk"]
[Mon Jul 20 07:43:09.495134 2026] [security2:error] [pid 178071:tid 178206] [client 49.47.218.174:60599] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l7Rltgi7HBmNwzJN7uwAAAAM"]
[Mon Jul 20 07:43:09.495402 2026] [security2:error] [pid 178071:tid 178206] [client 49.47.218.174:60599] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l7Rltgi7HBmNwzJN7uwAAAAM"]
[Mon Jul 20 07:43:09.612523 2026] [security2:error] [pid 204156:tid 204301] [client 14.225.17.146:62737] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "chestermonty.com"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnOJwAAAZ4"], referer: http://chestermonty.com/WWW
[Mon Jul 20 07:43:09.827506 2026] [security2:error] [pid 178071:tid 178294] [client 57.141.18.117:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4l7Rltgi7HBmNwzJN79gAAAFs"]
[Mon Jul 20 07:43:09.886550 2026] [autoindex:error] [pid 204156:tid 204288] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/integrations/square/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:43:09.929798 2026] [security2:error] [pid 204156:tid 204413] [client 66.249.73.132:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.icemarc.org"] [uri "/index.php"] [unique_id "al4l7BbAFPhDXvzP7SnOPAAAAg4"]
[Mon Jul 20 07:43:10.045025 2026] [core:error] [pid 204156:tid 204303] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:10.045047 2026] [core:error] [pid 204156:tid 204303] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:10.067762 2026] [security2:error] [pid 204156:tid 204294] [client 77.110.127.138:54746] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpforms/assets/css/integrations/square/pafhmtjimr5n.php"] [unique_id "al4l7hbAFPhDXvzP7SnOiQAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:10.074964 2026] [security2:error] [pid 204156:tid 204316] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7RbAFPhDXvzP7SnOcQAAAa0"], referer: https://mezzacraft.com/author/mezza/page/page/3/
[Mon Jul 20 07:43:10.224377 2026] [security2:error] [pid 178071:tid 178318] [client 57.141.18.10:57878] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7Rltgi7HBmNwzJN78gAAc3M"]
[Mon Jul 20 07:43:10.239072 2026] [autoindex:error] [pid 204156:tid 204324] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/wpforms/assets/css/integrations/square/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:43:10.485058 2026] [security2:error] [pid 204156:tid 204338] [client 103.139.191.61:57148] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4l7hbAFPhDXvzP7SnOrQAAAcM"]
[Mon Jul 20 07:43:10.485156 2026] [security2:error] [pid 204156:tid 204338] [client 103.139.191.61:57148] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4l7hbAFPhDXvzP7SnOrQAAAcM"]
[Mon Jul 20 07:43:10.568207 2026] [security2:error] [pid 178071:tid 178326] [client 14.225.17.146:56857] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.chestermonty.com"] [uri "/index.php"] [unique_id "al4l7hltgi7HBmNwzJN8IgAAAHs"], referer: https://chestermonty.com/WWW
[Mon Jul 20 07:43:10.664953 2026] [security2:error] [pid 204156:tid 204208] [remote 160.187.68.132:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4l7hbAFPhDXvzP7SnOtAAB_jM"]
[Mon Jul 20 07:43:10.871359 2026] [security2:error] [pid 204156:tid 204289] [client 191.202.66.27:54725] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l7hbAFPhDXvzP7SnOxgAAAZI"]
[Mon Jul 20 07:43:10.871458 2026] [security2:error] [pid 204156:tid 204289] [client 191.202.66.27:54725] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l7hbAFPhDXvzP7SnOxgAAAZI"]
[Mon Jul 20 07:43:10.943158 2026] [security2:error] [pid 204156:tid 204379] [client 77.110.127.138:54747] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7hbAFPhDXvzP7SnOigAAAew"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:10.978323 2026] [security2:error] [pid 178071:tid 178286] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7hltgi7HBmNwzJN8EgAAAFM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.060237 2026] [security2:error] [pid 204156:tid 204363] [client 14.225.17.146:55983] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bandsir.com"] [uri "/index.php"] [unique_id "al4l7hbAFPhDXvzP7SnOxQAAAdw"]
[Mon Jul 20 07:43:11.089266 2026] [security2:error] [pid 178071:tid 178223] [client 77.110.127.138:54729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-pattern/feed/cpxxqxdxx1gz.php"] [unique_id "al4l7xltgi7HBmNwzJN8NgAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.261993 2026] [core:error] [pid 178071:tid 178221] [client 14.225.17.146:55901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WWW
[Mon Jul 20 07:43:11.262015 2026] [core:error] [pid 178071:tid 178221] [client 14.225.17.146:55901] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://genesisventuregrp.com/WWW
[Mon Jul 20 07:43:11.267461 2026] [security2:error] [pid 204156:tid 204394] [client 57.141.18.49:65140] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7hbAFPhDXvzP7SnOsgAB-0A"]
[Mon Jul 20 07:43:11.476456 2026] [security2:error] [pid 204156:tid 204339] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnO6wAAAcQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.509156 2026] [security2:error] [pid 204156:tid 204387] [client 77.110.127.138:54783] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnO8AAAAfQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.513193 2026] [security2:error] [pid 178071:tid 178217] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xltgi7HBmNwzJN8QwAAAA4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.545841 2026] [security2:error] [pid 204156:tid 204365] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnO8wAAAd4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.627244 2026] [security2:error] [pid 204156:tid 204327] [client 77.110.127.138:54757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-stitch/feed/yy78c3w0hu0i.php"] [unique_id "al4l7xbAFPhDXvzP7SnO-wAAAbg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:11.876583 2026] [security2:error] [pid 204156:tid 204317] [client 57.141.18.13:53482] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnO6AABrh0"]
[Mon Jul 20 07:43:12.027577 2026] [security2:error] [pid 204156:tid 204385] [client 14.225.17.146:62911] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "northbrookcpa.ca"] [uri "/index.php"] [unique_id "al4l7hbAFPhDXvzP7SnOwQAAAfI"], referer: http://northbrookcpa.ca/WWW
[Mon Jul 20 07:43:12.129818 2026] [security2:error] [pid 204156:tid 204396] [client 77.110.127.138:54756] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnO_QAAAf0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.168584 2026] [security2:error] [pid 204156:tid 204341] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnPAQAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.211669 2026] [security2:error] [pid 178071:tid 178324] [client 57.141.18.22:60312] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7xltgi7HBmNwzJN8VAAAeTU"]
[Mon Jul 20 07:43:12.260428 2026] [security2:error] [pid 204156:tid 204319] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnPCgAAAbA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.277354 2026] [security2:error] [pid 178071:tid 178240] [client 14.225.17.146:49791] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "talknutritionwithlesley.com"] [uri "/index.php"] [unique_id "al4l8Bltgi7HBmNwzJN8dwAAACU"], referer: http://talknutritionwithlesley.com/WWW
[Mon Jul 20 07:43:12.392181 2026] [security2:error] [pid 178071:tid 178266] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l7xltgi7HBmNwzJN8bwAAAD8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.430112 2026] [security2:error] [pid 204156:tid 204307] [client 77.110.127.138:54751] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2021/wcitcbhww8lk.php"] [unique_id "al4l8BbAFPhDXvzP7SnPKwAAAaQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.432004 2026] [security2:error] [pid 204156:tid 204332] [client 65.111.26.106:12381] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4l8BbAFPhDXvzP7SnPJgAAAb0"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:43:12.477187 2026] [autoindex:error] [pid 204156:tid 204378] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.488240 2026] [security2:error] [pid 178071:tid 178302] [client 36.93.152.155:64880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l8Bltgi7HBmNwzJN8lgAAAGM"]
[Mon Jul 20 07:43:12.488342 2026] [security2:error] [pid 178071:tid 178302] [client 36.93.152.155:64880] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l8Bltgi7HBmNwzJN8lgAAAGM"]
[Mon Jul 20 07:43:12.569152 2026] [security2:error] [pid 178071:tid 178209] [client 57.141.18.31:59174] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7xltgi7HBmNwzJN8bQAABlY"]
[Mon Jul 20 07:43:12.569510 2026] [security2:error] [pid 204156:tid 204408] [client 57.141.18.87:43636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l7xbAFPhDXvzP7SnPDwACCSw"]
[Mon Jul 20 07:43:12.577315 2026] [autoindex:error] [pid 204156:tid 204334] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:43:12.651574 2026] [security2:error] [pid 178071:tid 178233] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8Bltgi7HBmNwzJN8jwAAAB4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.676197 2026] [security2:error] [pid 178071:tid 178297] [client 46.110.96.34:3465] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4l8Bltgi7HBmNwzJN8pgAAAF4"]
[Mon Jul 20 07:43:12.687669 2026] [security2:error] [pid 204156:tid 204304] [client 77.110.127.138:54778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPLAAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.714068 2026] [security2:error] [pid 178071:tid 178288] [client 136.158.60.21:48998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l8Bltgi7HBmNwzJN8qAAAAFU"]
[Mon Jul 20 07:43:12.714190 2026] [security2:error] [pid 178071:tid 178288] [client 136.158.60.21:48998] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l8Bltgi7HBmNwzJN8qAAAAFU"]
[Mon Jul 20 07:43:12.786534 2026] [security2:error] [pid 178071:tid 178321] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8Bltgi7HBmNwzJN8ogAAAHY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.813464 2026] [security2:error] [pid 204156:tid 204333] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPNgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:12.948292 2026] [security2:error] [pid 204156:tid 204294] [client 77.110.127.138:54734] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/uploads/2021/09/3ko8x5vvheub.php"] [unique_id "al4l8BbAFPhDXvzP7SnPSwAAAZc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.087160 2026] [autoindex:error] [pid 178071:tid 178327] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/09/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:43:13.087636 2026] [autoindex:error] [pid 178071:tid 178301] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/09/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.151296 2026] [security2:error] [pid 204156:tid 204397] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPQAAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.382913 2026] [security2:error] [pid 204156:tid 204305] [client 77.110.127.138:54754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPTwAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.411413 2026] [security2:error] [pid 204156:tid 204391] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPVAAAAfg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.438065 2026] [security2:error] [pid 204156:tid 204342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPWAAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.474697 2026] [security2:error] [pid 204156:tid 204405] [client 77.110.127.138:54747] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-classes/o2vyzsk17gv2.php"] [unique_id "al4l8RbAFPhDXvzP7SnPagAAAgY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:13.512091 2026] [autoindex:error] [pid 204156:tid 204374] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/09/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/category/crochet/
[Mon Jul 20 07:43:13.527665 2026] [security2:error] [pid 178071:tid 178158] [remote 45.90.123.233:43364] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l8Rltgi7HBmNwzJN8zAAAV1Q"]
[Mon Jul 20 07:43:13.527867 2026] [security2:error] [pid 178071:tid 178290] [client 45.90.123.233:43364] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "boz.rnn.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l8Rltgi7HBmNwzJN8zAAAV1Q"]
[Mon Jul 20 07:43:13.665078 2026] [security2:error] [pid 178071:tid 178266] [client 74.7.227.179:45724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4l8Rltgi7HBmNwzJN8ywAAP0w"], referer: https://tejasenvironmental.com/p=787766
[Mon Jul 20 07:43:13.697856 2026] [security2:error] [pid 178071:tid 178218] [client 39.46.9.231:61332] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4l8Rltgi7HBmNwzJN82wAAAA8"]
[Mon Jul 20 07:43:13.697979 2026] [security2:error] [pid 178071:tid 178218] [client 39.46.9.231:61332] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4l8Rltgi7HBmNwzJN82wAAAA8"]
[Mon Jul 20 07:43:13.749563 2026] [security2:error] [pid 204156:tid 204360] [client 180.249.173.210:55624] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l8RbAFPhDXvzP7SnPfQAAAdk"]
[Mon Jul 20 07:43:13.749691 2026] [security2:error] [pid 204156:tid 204360] [client 180.249.173.210:55624] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l8RbAFPhDXvzP7SnPfQAAAdk"]
[Mon Jul 20 07:43:13.765566 2026] [security2:error] [pid 204156:tid 204224] [remote 160.187.68.132:33536] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "intelligentengineeringsolutions.com"] [uri "/wp-login.php"] [unique_id "al4l8RbAFPhDXvzP7SnPfgAB4EM"], referer: https://intelligentengineeringsolutions.com/wp-login.php
[Mon Jul 20 07:43:13.803784 2026] [security2:error] [pid 204156:tid 204410] [client 50.116.65.227:32322] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4l8RbAFPhDXvzP7SnPggAAAgs"]
[Mon Jul 20 07:43:13.816041 2026] [security2:error] [pid 204156:tid 204390] [client 50.116.65.227:18522] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/10/Katsuya-Feature-Image.jpg"] [unique_id "al4l8RbAFPhDXvzP7SnPhQAAAfc"]
[Mon Jul 20 07:43:13.828862 2026] [security2:error] [pid 204156:tid 204255] [remote 162.19.246.208:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l8RbAFPhDXvzP7SnPhgABp2I"]
[Mon Jul 20 07:43:13.876053 2026] [security2:error] [pid 178071:tid 178244] [client 57.141.18.43:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4l8Rltgi7HBmNwzJN83gAAACk"]
[Mon Jul 20 07:43:13.920056 2026] [security2:error] [pid 204156:tid 204334] [client 14.225.17.146:65385] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4l8RbAFPhDXvzP7SnPfwAAAb8"], referer: http://adirondackengineering.com/WWW
[Mon Jul 20 07:43:13.972579 2026] [security2:error] [pid 204156:tid 204293] [client 57.141.18.33:49500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l8BbAFPhDXvzP7SnPVwABljE"]
[Mon Jul 20 07:43:14.008995 2026] [security2:error] [pid 178071:tid 178288] [client 43.156.142.168:60260] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.142.156.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.samdothan.org"] [uri "/wp-login.php"] [unique_id "al4l8Rltgi7HBmNwzJN86wAAAFU"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:43:14.069726 2026] [security2:error] [pid 204156:tid 204207] [remote 162.19.246.208:35918] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 208.246.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l8hbAFPhDXvzP7SnPkQACATI"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:14.157101 2026] [security2:error] [pid 204156:tid 204315] [client 77.110.127.138:54782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8RbAFPhDXvzP7SnPawAAAaw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:14.188241 2026] [security2:error] [pid 204156:tid 204317] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8RbAFPhDXvzP7SnPbgAAAa4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:14.325732 2026] [security2:error] [pid 178071:tid 178222] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8Rltgi7HBmNwzJN8zgAAABM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:14.353564 2026] [security2:error] [pid 178071:tid 178293] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8Rltgi7HBmNwzJN80AAAAFo"]
[Mon Jul 20 07:43:14.573668 2026] [security2:error] [pid 204156:tid 204408] [client 57.141.18.96:32586] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l8RbAFPhDXvzP7SnPcwACCT8"]
[Mon Jul 20 07:43:14.727950 2026] [security2:error] [pid 204156:tid 204329] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8hbAFPhDXvzP7SnPqAAAAbo"]
[Mon Jul 20 07:43:14.852805 2026] [security2:error] [pid 178071:tid 178285] [client 57.141.18.98:39420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l8Rltgi7HBmNwzJN83wAAUig"]
[Mon Jul 20 07:43:14.892223 2026] [security2:error] [pid 204156:tid 204404] [client 77.110.127.138:54824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/tag/crochet-tutorials/q27xbh6dmsdb.php"] [unique_id "al4l8hbAFPhDXvzP7SnPyAAAAgU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:14.924304 2026] [security2:error] [pid 204156:tid 204249] [remote 160.187.68.132:48720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4l8hbAFPhDXvzP7SnPygABmFw"]
[Mon Jul 20 07:43:14.969576 2026] [security2:error] [pid 204156:tid 204349] [client 77.110.127.138:54816] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8hbAFPhDXvzP7SnPvAAAAc4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:15.039307 2026] [security2:error] [pid 204156:tid 204403] [client 37.52.210.45:54076] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnPzgAAAgQ"]
[Mon Jul 20 07:43:15.039449 2026] [security2:error] [pid 204156:tid 204403] [client 37.52.210.45:54076] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnPzgAAAgQ"]
[Mon Jul 20 07:43:15.130008 2026] [security2:error] [pid 204156:tid 204225] [remote 103.82.22.235:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4l8xbAFPhDXvzP7SnP1AABtEQ"]
[Mon Jul 20 07:43:15.174108 2026] [security2:error] [pid 204156:tid 204330] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8hbAFPhDXvzP7SnPxQAAAbs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:15.198486 2026] [proxy:error] [pid 204156:tid 204384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:15.198524 2026] [proxy_http:error] [pid 204156:tid 204384] [client 107.172.180.205:33998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:15.199109 2026] [proxy:error] [pid 204156:tid 204384] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:15.199132 2026] [proxy_http:error] [pid 204156:tid 204384] [client 107.172.180.205:33998] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:15.208287 2026] [security2:error] [pid 204156:tid 204397] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l8hbAFPhDXvzP7SnPwwAAAf4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:15.212108 2026] [security2:error] [pid 204156:tid 204326] [client 15.229.69.106:46650] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnP4QAAAbc"]
[Mon Jul 20 07:43:15.212195 2026] [security2:error] [pid 204156:tid 204326] [client 15.229.69.106:46650] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnP4QAAAbc"]
[Mon Jul 20 07:43:15.305217 2026] [security2:error] [pid 178071:tid 178164] [remote 217.61.143.92:57324] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4l8xltgi7HBmNwzJN9GQAAfVo"]
[Mon Jul 20 07:43:15.305417 2026] [security2:error] [pid 178071:tid 178328] [client 217.61.143.92:57324] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "sarahsnyder.net"] [uri "/xmlrpc.php"] [unique_id "al4l8xltgi7HBmNwzJN9GQAAfVo"]
[Mon Jul 20 07:43:15.347572 2026] [security2:error] [pid 204156:tid 204391] [client 142.111.152.62:32807] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnP2gAAAfg"]
[Mon Jul 20 07:43:15.671407 2026] [security2:error] [pid 204156:tid 204227] [remote 103.82.22.235:47750] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "recruitinginsight.us"] [uri "/wp-login.php"] [unique_id "al4l8xbAFPhDXvzP7SnP6wABrEY"], referer: https://recruitinginsight.us/wp-login.php
[Mon Jul 20 07:43:15.674560 2026] [security2:error] [pid 204156:tid 204338] [client 14.225.17.146:64054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "dollpassionista.com"] [uri "/index.php"] [unique_id "al4l8xbAFPhDXvzP7SnP5wAAAcM"], referer: http://dollpassionista.com/WWW
[Mon Jul 20 07:43:15.772082 2026] [security2:error] [pid 204156:tid 204351] [client 149.0.16.108:55379] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnP8AAAAdA"]
[Mon Jul 20 07:43:15.772642 2026] [security2:error] [pid 204156:tid 204351] [client 149.0.16.108:55379] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l8xbAFPhDXvzP7SnP8AAAAdA"]
[Mon Jul 20 07:43:15.991397 2026] [security2:error] [pid 178071:tid 178250] [client 14.225.17.146:59396] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4l8xltgi7HBmNwzJN9OgAAAC8"], referer: http://intelligentengineeringsolutions.com/WWW
[Mon Jul 20 07:43:16.022666 2026] [security2:error] [pid 204156:tid 204317] [client 57.141.18.27:43600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l8hbAFPhDXvzP7SnPxgABrkw"]
[Mon Jul 20 07:43:16.110509 2026] [security2:error] [pid 204156:tid 204322] [client 154.192.233.184:61059] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l9BbAFPhDXvzP7SnP_wAAAbM"]
[Mon Jul 20 07:43:16.110654 2026] [security2:error] [pid 204156:tid 204322] [client 154.192.233.184:61059] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l9BbAFPhDXvzP7SnP_wAAAbM"]
[Mon Jul 20 07:43:16.414619 2026] [security2:error] [pid 204156:tid 204404] [client 168.144.19.97:62998] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thewelloiledlife.com"] [uri "/index.php"] [unique_id "al4l9BbAFPhDXvzP7SnQCAAAAgU"], referer: binance.com
[Mon Jul 20 07:43:16.416102 2026] [security2:error] [pid 204156:tid 204389] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9BbAFPhDXvzP7SnQAwAAAfY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:16.457196 2026] [security2:error] [pid 204156:tid 204278] [remote 100.42.189.89:39798] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l9BbAFPhDXvzP7SnQEAAByXk"]
[Mon Jul 20 07:43:16.457318 2026] [security2:error] [pid 204156:tid 204344] [client 100.42.189.89:39798] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "rrf.lcd.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4l9BbAFPhDXvzP7SnQEAAByXk"]
[Mon Jul 20 07:43:16.518787 2026] [security2:error] [pid 178071:tid 178110] [remote 91.142.222.105:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4l9Bltgi7HBmNwzJN9TgAACCU"]
[Mon Jul 20 07:43:16.616155 2026] [security2:error] [pid 204156:tid 204393] [client 14.225.17.146:59574] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "carolinapressurewashers.com"] [uri "/index.php"] [unique_id "al4l9BbAFPhDXvzP7SnQDwAAAfo"], referer: http://carolinapressurewashers.com/WWW
[Mon Jul 20 07:43:16.714666 2026] [security2:error] [pid 204156:tid 204363] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9BbAFPhDXvzP7SnQFAAAAdw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:16.755805 2026] [security2:error] [pid 204156:tid 204412] [client 14.225.17.146:56110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.dollpassionista.com"] [uri "/index.php"] [unique_id "al4l9BbAFPhDXvzP7SnQFgAAAg0"], referer: https://dollpassionista.com/WWW
[Mon Jul 20 07:43:16.758096 2026] [security2:error] [pid 204156:tid 204292] [client 14.225.17.146:56154] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alchemygroup.ca"] [uri "/index.php"] [unique_id "al4l9BbAFPhDXvzP7SnQGAAAAZU"], referer: http://alchemygroup.ca/WWW
[Mon Jul 20 07:43:16.759086 2026] [security2:error] [pid 204156:tid 204254] [remote 91.142.222.105:56752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4l9BbAFPhDXvzP7SnQHQACCWE"]
[Mon Jul 20 07:43:16.759240 2026] [security2:error] [pid 204156:tid 204408] [client 91.142.222.105:56752] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4l9BbAFPhDXvzP7SnQHQACCWE"]
[Mon Jul 20 07:43:16.766210 2026] [security2:error] [pid 178071:tid 178136] [remote 91.142.222.105:56128] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "studio.xp-design.co"] [uri "/wp-login.php"] [unique_id "al4l9Bltgi7HBmNwzJN9YAAAXD8"], referer: https://studio.xp-design.co/wp-login.php
[Mon Jul 20 07:43:16.892177 2026] [security2:error] [pid 178071:tid 178239] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9Bltgi7HBmNwzJN9WQAAACQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:16.969674 2026] [security2:error] [pid 178071:tid 178329] [client 57.141.18.26:56126] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l8xltgi7HBmNwzJN9LAAAfjY"]
[Mon Jul 20 07:43:16.991009 2026] [security2:error] [pid 178071:tid 178298] [client 14.225.17.146:55757] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "sarahholyfield.com"] [uri "/index.php"] [unique_id "al4l8xltgi7HBmNwzJN9NgAAAF8"], referer: http://sarahholyfield.com/WWW
[Mon Jul 20 07:43:16.996807 2026] [security2:error] [pid 178071:tid 178222] [client 57.141.18.87:33698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l8xltgi7HBmNwzJN9MwAAEzs"]
[Mon Jul 20 07:43:17.062287 2026] [proxy:error] [pid 204156:tid 204413] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:17.062341 2026] [proxy_http:error] [pid 204156:tid 204413] [client 107.172.180.205:34006] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:17.062781 2026] [proxy:error] [pid 204156:tid 204413] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:17.062814 2026] [proxy_http:error] [pid 204156:tid 204413] [client 107.172.180.205:34006] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:17.245208 2026] [security2:error] [pid 204156:tid 204266] [remote 160.187.68.132:48720] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.commonsensesf.com"] [uri "/wp-login.php"] [unique_id "al4l9RbAFPhDXvzP7SnQKgABrm0"], referer: https://mail.commonsensesf.com/wp-login.php
[Mon Jul 20 07:43:17.254820 2026] [security2:error] [pid 178071:tid 178225] [client 14.225.17.146:59415] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4l8xltgi7HBmNwzJN9PwAAABY"], referer: http://wathenbartlett.co.uk/WWW
[Mon Jul 20 07:43:17.288345 2026] [security2:error] [pid 204156:tid 204361] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9RbAFPhDXvzP7SnQJwAAAdo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:17.580264 2026] [security2:error] [pid 204156:tid 204349] [client 179.127.84.238:60359] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l9RbAFPhDXvzP7SnQQwAAAc4"]
[Mon Jul 20 07:43:17.580401 2026] [security2:error] [pid 204156:tid 204349] [client 179.127.84.238:60359] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4l9RbAFPhDXvzP7SnQQwAAAc4"]
[Mon Jul 20 07:43:17.627367 2026] [security2:error] [pid 204156:tid 204333] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9RbAFPhDXvzP7SnQOgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:17.931869 2026] [security2:error] [pid 178071:tid 178313] [client 14.225.17.146:55714] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tntcatholic.com"] [uri "/index.php"] [unique_id "al4l9Rltgi7HBmNwzJN9jAAAAG4"], referer: http://tntcatholic.com/WWW
[Mon Jul 20 07:43:18.055108 2026] [security2:error] [pid 178071:tid 178128] [remote 142.93.10.93:54716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4l9hltgi7HBmNwzJN9mAAAXDc"]
[Mon Jul 20 07:43:18.055329 2026] [security2:error] [pid 204156:tid 204293] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9RbAFPhDXvzP7SnQUgAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:18.119341 2026] [security2:error] [pid 178071:tid 178292] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ardhalwafaa.com"] [uri "/index.php"] [unique_id "al4l9Rltgi7HBmNwzJN9hQAAWTU"], referer: http://ardhalwafaa.com/WWW
[Mon Jul 20 07:43:18.183213 2026] [security2:error] [pid 204156:tid 204377] [client 14.225.17.146:59161] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.wathenbartlett.co.uk"] [uri "/index.php"] [unique_id "al4l9hbAFPhDXvzP7SnQYwAAAeo"], referer: https://wathenbartlett.co.uk/WWW
[Mon Jul 20 07:43:18.247244 2026] [security2:error] [pid 178071:tid 178146] [remote 142.93.10.93:54716] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 93.10.93.142.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4l9hltgi7HBmNwzJN9mwAAekg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:43:18.456225 2026] [security2:error] [pid 204156:tid 204295] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9hbAFPhDXvzP7SnQZwAAAZg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:18.822539 2026] [security2:error] [pid 204156:tid 204326] [client 104.207.50.85:34921] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 85.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4l9hbAFPhDXvzP7SnQhgAAAbc"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:18.825167 2026] [security2:error] [pid 204156:tid 204355] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9hbAFPhDXvzP7SnQfQAAAdQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:18.892037 2026] [security2:error] [pid 204156:tid 204231] [remote 152.228.213.32:42334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4l9hbAFPhDXvzP7SnQigABlUo"]
[Mon Jul 20 07:43:19.080253 2026] [security2:error] [pid 204156:tid 204242] [remote 152.228.213.32:42334] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4l9xbAFPhDXvzP7SnQlQABkVU"], referer: https://verdunestate.com/wp-login.php
[Mon Jul 20 07:43:19.111450 2026] [security2:error] [pid 178071:tid 178206] [client 14.225.17.146:55741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "colinkeyphotography.com"] [uri "/index.php"] [unique_id "al4l9Rltgi7HBmNwzJN9iwAAAAM"], referer: http://colinkeyphotography.com/WWW
[Mon Jul 20 07:43:19.341387 2026] [security2:error] [pid 204156:tid 204293] [client 14.225.17.146:59732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ivetstrategies.com"] [uri "/index.php"] [unique_id "al4l9xbAFPhDXvzP7SnQmAAAAZY"], referer: http://ivetstrategies.com/WWW
[Mon Jul 20 07:43:19.561616 2026] [security2:error] [pid 204156:tid 204338] [client 57.141.18.63:21342] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l9RbAFPhDXvzP7SnQWgABw1s"]
[Mon Jul 20 07:43:19.578489 2026] [security2:error] [pid 178071:tid 178226] [client 14.225.17.146:49696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "aljosour-alarabia.com"] [uri "/index.php"] [unique_id "al4l9xltgi7HBmNwzJN9ywAAABc"], referer: http://aljosour-alarabia.com/WWW
[Mon Jul 20 07:43:19.819493 2026] [security2:error] [pid 178071:tid 178320] [client 186.221.114.200:58462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l9xltgi7HBmNwzJN92wAAAHU"]
[Mon Jul 20 07:43:19.819582 2026] [security2:error] [pid 178071:tid 178320] [client 186.221.114.200:58462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4l9xltgi7HBmNwzJN92wAAAHU"]
[Mon Jul 20 07:43:20.025479 2026] [security2:error] [pid 204156:tid 204351] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l9xbAFPhDXvzP7SnQrAAAAdA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:20.032933 2026] [security2:error] [pid 204156:tid 204381] [client 49.47.218.174:61153] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l-BbAFPhDXvzP7SnQtwAAAe4"]
[Mon Jul 20 07:43:20.033057 2026] [security2:error] [pid 204156:tid 204381] [client 49.47.218.174:61153] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4l-BbAFPhDXvzP7SnQtwAAAe4"]
[Mon Jul 20 07:43:20.054043 2026] [security2:error] [pid 178071:tid 178227] [client 57.141.18.2:28352] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l9hltgi7HBmNwzJN9pgAAGBA"]
[Mon Jul 20 07:43:20.428513 2026] [security2:error] [pid 204156:tid 204413] [client 103.139.191.61:57675] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4l-BbAFPhDXvzP7SnQwQAAAg4"]
[Mon Jul 20 07:43:20.428620 2026] [security2:error] [pid 204156:tid 204413] [client 103.139.191.61:57675] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4l-BbAFPhDXvzP7SnQwQAAAg4"]
[Mon Jul 20 07:43:20.714659 2026] [proxy:error] [pid 178071:tid 178305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:20.714693 2026] [proxy_http:error] [pid 178071:tid 178305] [client 104.155.181.6:41638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:20.715115 2026] [proxy:error] [pid 178071:tid 178305] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:20.715141 2026] [proxy_http:error] [pid 178071:tid 178305] [client 104.155.181.6:41638] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:20.838634 2026] [core:error] [pid 204156:tid 204314] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:20.838662 2026] [core:error] [pid 204156:tid 204314] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:21.349660 2026] [core:error] [pid 204156:tid 204351] [client 14.225.17.146:49978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WWW
[Mon Jul 20 07:43:21.349680 2026] [core:error] [pid 204156:tid 204351] [client 14.225.17.146:49978] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace., referer: http://aljosour-alarabia.net/WWW
[Mon Jul 20 07:43:21.496929 2026] [security2:error] [pid 178071:tid 178210] [client 77.110.127.138:54848] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/if(now()=sysdate(),sleep(15),0)/page/21/"] [unique_id "al4l-Rltgi7HBmNwzJN-HAAAAAc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:21.628233 2026] [security2:error] [pid 204156:tid 204374] [client 57.141.18.6:28514] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l9xbAFPhDXvzP7SnQoQAB5ww"]
[Mon Jul 20 07:43:21.631256 2026] [security2:error] [pid 204156:tid 204330] [client 191.202.66.27:55223] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l-RbAFPhDXvzP7SnQ-AAAAbs"]
[Mon Jul 20 07:43:21.631359 2026] [security2:error] [pid 204156:tid 204330] [client 191.202.66.27:55223] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4l-RbAFPhDXvzP7SnQ-AAAAbs"]
[Mon Jul 20 07:43:21.736648 2026] [security2:error] [pid 204156:tid 204312] [client 74.208.214.194:41814] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4l-RbAFPhDXvzP7SnQ_wAAAak"]
[Mon Jul 20 07:43:22.046017 2026] [security2:error] [pid 178071:tid 178287] [client 14.225.17.146:59271] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ghivs.com"] [uri "/index.php"] [unique_id "al4l-Rltgi7HBmNwzJN-JwAAAFQ"], referer: http://ghivs.com/WWW
[Mon Jul 20 07:43:22.176393 2026] [security2:error] [pid 178071:tid 178268] [client 14.225.17.146:49655] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ancestralidadytrance.space"] [uri "/index.php"] [unique_id "al4l-Rltgi7HBmNwzJN-DgAAAEE"], referer: http://ancestralidadytrance.space/WWW
[Mon Jul 20 07:43:22.271950 2026] [security2:error] [pid 204156:tid 204370] [client 104.207.54.27:44473] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4l-hbAFPhDXvzP7SnRFAAAAeM"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:43:22.398278 2026] [security2:error] [pid 204156:tid 204382] [client 57.141.18.0:57356] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-BbAFPhDXvzP7SnQuQAB728"]
[Mon Jul 20 07:43:22.526033 2026] [security2:error] [pid 204156:tid 204294] [client 14.225.17.146:64051] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "webgardensbypaula.com"] [uri "/index.php"] [unique_id "al4l-hbAFPhDXvzP7SnREgAAAZc"], referer: http://webgardensbypaula.com/WWW
[Mon Jul 20 07:43:23.038999 2026] [security2:error] [pid 204156:tid 204291] [client 36.93.152.155:65397] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l-xbAFPhDXvzP7SnROAAAAZQ"]
[Mon Jul 20 07:43:23.039086 2026] [security2:error] [pid 204156:tid 204291] [client 36.93.152.155:65397] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4l-xbAFPhDXvzP7SnROAAAAZQ"]
[Mon Jul 20 07:43:23.046685 2026] [security2:error] [pid 204156:tid 204167] [remote 152.228.213.32:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4l-xbAFPhDXvzP7SnRNwABnQo"]
[Mon Jul 20 07:43:23.152976 2026] [security2:error] [pid 204156:tid 204335] [client 57.141.18.53:21274] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-BbAFPhDXvzP7SnQ1QABwCM"]
[Mon Jul 20 07:43:23.156926 2026] [lsapi:warn] [pid 204156:tid 204179] [remote 172.171.4.185:0] [host ali-alghanim.com] Backend log: PHP Warning:  getimagesize(https://aasgroup.online/wp-content/uploads/2021/09/1291810.jpg): Failed to open stream: HTTP request failed! HTTP/1.1 403 Forbidden\r\n in /home2/aasgroup/public_html/alialghanim/wp-content/plugins/litespeed-cache/src/media.cls.php on line 860\n
[Mon Jul 20 07:43:23.228808 2026] [security2:error] [pid 204156:tid 204189] [remote 152.228.213.32:42342] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4l-xbAFPhDXvzP7SnRSgABxCA"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:43:23.461139 2026] [security2:error] [pid 178071:tid 178258] [client 136.158.60.21:50628] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l-xltgi7HBmNwzJN-WgAAADc"]
[Mon Jul 20 07:43:23.461267 2026] [security2:error] [pid 178071:tid 178258] [client 136.158.60.21:50628] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4l-xltgi7HBmNwzJN-WgAAADc"]
[Mon Jul 20 07:43:23.513361 2026] [security2:error] [pid 178071:tid 178322] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4l-xltgi7HBmNwzJN-TwAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:23.621446 2026] [security2:error] [pid 178071:tid 178265] [client 196.238.246.148:53402] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4l-xltgi7HBmNwzJN-YQAAAD4"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 07:43:23.831559 2026] [security2:error] [pid 204156:tid 204313] [client 39.46.9.231:61763] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4l-xbAFPhDXvzP7SnRWQAAAao"]
[Mon Jul 20 07:43:23.831705 2026] [security2:error] [pid 204156:tid 204313] [client 39.46.9.231:61763] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4l-xbAFPhDXvzP7SnRWQAAAao"]
[Mon Jul 20 07:43:23.857465 2026] [security2:error] [pid 178071:tid 178218] [client 35.90.38.209:31018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 209.38.90.35.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-cron.php"] [unique_id "al4l-xltgi7HBmNwzJN-fQAAAA8"]
[Mon Jul 20 07:43:24.006480 2026] [security2:error] [pid 178071:tid 178288] [client 14.225.17.146:59247] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "guidehunting.com"] [uri "/index.php"] [unique_id "al4l-xltgi7HBmNwzJN-cAAAAFU"], referer: http://guidehunting.com/WWW
[Mon Jul 20 07:43:24.084632 2026] [security2:error] [pid 178071:tid 178161] [remote 45.150.79.142:34046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4l_Bltgi7HBmNwzJN-hwAARlc"]
[Mon Jul 20 07:43:24.147289 2026] [security2:error] [pid 204156:tid 204383] [client 57.141.18.103:36534] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-RbAFPhDXvzP7SnRBgAB8CE"]
[Mon Jul 20 07:43:24.183758 2026] [security2:error] [pid 178071:tid 178098] [remote 5.161.225.162:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4l_Bltgi7HBmNwzJN-lAAAPBk"]
[Mon Jul 20 07:43:24.250914 2026] [security2:error] [pid 178071:tid 178175] [remote 45.150.79.142:34046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.79.150.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4l_Bltgi7HBmNwzJN-lwAAbmU"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:43:24.257261 2026] [security2:error] [pid 204156:tid 204381] [client 180.249.173.210:56137] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l_BbAFPhDXvzP7SnRXQAAAe4"]
[Mon Jul 20 07:43:24.258049 2026] [security2:error] [pid 204156:tid 204381] [client 180.249.173.210:56137] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4l_BbAFPhDXvzP7SnRXQAAAe4"]
[Mon Jul 20 07:43:24.261662 2026] [security2:error] [pid 204156:tid 204366] [client 57.141.18.80:52848] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-RbAFPhDXvzP7SnRBwAB3wk"]
[Mon Jul 20 07:43:24.449591 2026] [security2:error] [pid 178071:tid 178114] [remote 5.161.225.162:50484] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4l_Bltgi7HBmNwzJN-qAAAeSk"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:43:24.469567 2026] [security2:error] [pid 178071:tid 178242] [client 104.28.163.16:51172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 16.163.28.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jedalilly.com"] [uri "/wp-login.php"] [unique_id "al4l_Bltgi7HBmNwzJN-qQAAACc"]
[Mon Jul 20 07:43:24.480020 2026] [security2:error] [pid 178071:tid 178315] [client 14.225.17.146:58179] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "slutilities.com"] [uri "/index.php"] [unique_id "al4l_Bltgi7HBmNwzJN-oAAAAHA"], referer: http://slutilities.com/WWW
[Mon Jul 20 07:43:24.669513 2026] [security2:error] [pid 178071:tid 178310] [client 57.141.18.65:40242] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-hltgi7HBmNwzJN-MQAAa2Y"]
[Mon Jul 20 07:43:24.828517 2026] [security2:error] [pid 178071:tid 178323] [client 45.157.112.60:20467] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4l_Bltgi7HBmNwzJN-vQAAAHg"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:43:24.886690 2026] [security2:error] [pid 178071:tid 178268] [client 14.225.17.146:63956] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nextlvlmarketingco.com"] [uri "/index.php"] [unique_id "al4l_Bltgi7HBmNwzJN-uQAAAEE"], referer: http://nextlvlmarketingco.com/WWW
[Mon Jul 20 07:43:25.105012 2026] [security2:error] [pid 178071:tid 178250] [client 14.225.17.146:59048] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.guidehunting.com"] [uri "/index.php"] [unique_id "al4l_Bltgi7HBmNwzJN-vwAAAC8"], referer: https://guidehunting.com/WWW
[Mon Jul 20 07:43:25.333470 2026] [security2:error] [pid 204156:tid 204373] [client 57.141.18.4:53960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-hbAFPhDXvzP7SnRMwAB5gs"]
[Mon Jul 20 07:43:25.689292 2026] [security2:error] [pid 204156:tid 204362] [client 15.229.69.106:62138] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l_RbAFPhDXvzP7SnRigAAAds"]
[Mon Jul 20 07:43:25.689394 2026] [security2:error] [pid 204156:tid 204362] [client 15.229.69.106:62138] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4l_RbAFPhDXvzP7SnRigAAAds"]
[Mon Jul 20 07:43:25.702300 2026] [security2:error] [pid 178071:tid 178278] [client 37.52.210.45:54285] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l_Rltgi7HBmNwzJN-8AAAAEs"]
[Mon Jul 20 07:43:25.702404 2026] [security2:error] [pid 178071:tid 178278] [client 37.52.210.45:54285] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4l_Rltgi7HBmNwzJN-8AAAAEs"]
[Mon Jul 20 07:43:25.822269 2026] [security2:error] [pid 204156:tid 204333] [client 14.225.17.146:58963] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "liquidationteam.com"] [uri "/index.php"] [unique_id "al4l_RbAFPhDXvzP7SnRgAAAAb4"]
[Mon Jul 20 07:43:25.885349 2026] [security2:error] [pid 178071:tid 178208] [client 142.111.152.69:43717] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4l_Rltgi7HBmNwzJN-8QAAAAU"]
[Mon Jul 20 07:43:26.320982 2026] [security2:error] [pid 204156:tid 204311] [client 149.0.16.108:55902] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l_hbAFPhDXvzP7SnRrwAAAag"]
[Mon Jul 20 07:43:26.321079 2026] [security2:error] [pid 204156:tid 204311] [client 149.0.16.108:55902] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4l_hbAFPhDXvzP7SnRrwAAAag"]
[Mon Jul 20 07:43:26.338089 2026] [security2:error] [pid 204156:tid 204408] [client 77.110.127.138:54871] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/21/"] [unique_id "al4l_hbAFPhDXvzP7SnRsAAAAgk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:26.346735 2026] [security2:error] [pid 178071:tid 178306] [client 57.141.18.9:53358] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-xltgi7HBmNwzJN-dwAAZwI"]
[Mon Jul 20 07:43:26.358326 2026] [security2:error] [pid 204156:tid 204319] [client 57.141.18.58:46988] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l-xbAFPhDXvzP7SnRWAABsDM"]
[Mon Jul 20 07:43:26.606488 2026] [security2:error] [pid 204156:tid 204357] [client 154.192.233.184:61550] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l_hbAFPhDXvzP7SnRtwAAAdY"]
[Mon Jul 20 07:43:26.606588 2026] [security2:error] [pid 204156:tid 204357] [client 154.192.233.184:61550] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4l_hbAFPhDXvzP7SnRtwAAAdY"]
[Mon Jul 20 07:43:26.991720 2026] [security2:error] [pid 204156:tid 204401] [client 148.227.83.163:39386] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4l_hbAFPhDXvzP7SnRuwAAAgI"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 07:43:27.421885 2026] [security2:error] [pid 178071:tid 178101] [remote 162.19.86.63:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4l_xltgi7HBmNwzJN_MgAAQxw"]
[Mon Jul 20 07:43:27.586562 2026] [security2:error] [pid 204156:tid 204373] [client 114.119.156.172:33195] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.lowemissionsasia.org"] [uri "/what-we-do/"] [unique_id "al4l_xbAFPhDXvzP7SnR2QAAAeY"], referer: http://www.lowemissionsasia.org/what-we-do/
[Mon Jul 20 07:43:27.720709 2026] [security2:error] [pid 178071:tid 178110] [remote 162.19.86.63:60344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thesoloceos.com"] [uri "/wp-login.php"] [unique_id "al4l_xltgi7HBmNwzJN_OwAAPCU"], referer: https://thesoloceos.com/wp-login.php
[Mon Jul 20 07:43:27.796444 2026] [security2:error] [pid 204156:tid 204334] [client 104.207.61.221:34337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4l_xbAFPhDXvzP7SnR4gAAAb8"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:27.873355 2026] [security2:error] [pid 178071:tid 178313] [client 57.141.18.121:20068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l_Rltgi7HBmNwzJN-1AAAbnI"]
[Mon Jul 20 07:43:28.072400 2026] [security2:error] [pid 178071:tid 178203] [client 179.127.84.238:60896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mABltgi7HBmNwzJN_RwAAAAA"]
[Mon Jul 20 07:43:28.072499 2026] [security2:error] [pid 178071:tid 178203] [client 179.127.84.238:60896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mABltgi7HBmNwzJN_RwAAAAA"]
[Mon Jul 20 07:43:28.324673 2026] [security2:error] [pid 204156:tid 204305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mABbAFPhDXvzP7SnR8QAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:28.539613 2026] [security2:error] [pid 178071:tid 178226] [client 77.110.127.138:54887] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/21/"] [unique_id "al4mABltgi7HBmNwzJN_WgAAABc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:28.846181 2026] [security2:error] [pid 178071:tid 178227] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mABltgi7HBmNwzJN_YAAAABg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:28.940691 2026] [security2:error] [pid 178071:tid 178219] [client 92.151.29.121:34406] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/00_asl_zz_strict.conf"] [line "124"] [id "390739"] [rev "1"] [msg "Atomicorp.com WAF Rules: Possible Session Fixation attack"] [data "https://new-menus.com/ found within TX:1: new-menus.com"] [severity "CRITICAL"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4mABltgi7HBmNwzJN_ZwAAABA"], referer: https://new-menus.com/index.php?page=14
[Mon Jul 20 07:43:29.134788 2026] [security2:error] [pid 204156:tid 204327] [client 14.182.195.220:52881] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4mARbAFPhDXvzP7SnSDwAAAbg"]
[Mon Jul 20 07:43:29.423198 2026] [security2:error] [pid 178071:tid 178322] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mARltgi7HBmNwzJN_gwAAAHc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:29.463709 2026] [security2:error] [pid 204156:tid 204372] [client 57.141.18.39:52561] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l_hbAFPhDXvzP7SnRrAAB5RI"]
[Mon Jul 20 07:43:29.655168 2026] [ssl:error] [pid 178071:tid 178287] [client 104.48.69.105:60212] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.bandsir.com provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:43:29.676494 2026] [security2:error] [pid 178071:tid 178234] [client 104.207.51.56:29505] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 56.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mARltgi7HBmNwzJN_mQAAAB8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:29.767125 2026] [security2:error] [pid 178071:tid 178205] [client 14.225.17.146:55381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "grndl.com"] [uri "/index.php"] [unique_id "al4mARltgi7HBmNwzJN_mwAAAAI"], referer: http://grndl.com/WWW
[Mon Jul 20 07:43:29.897681 2026] [proxy:error] [pid 204156:tid 204292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:29.897733 2026] [proxy_http:error] [pid 204156:tid 204292] [client 198.235.24.52:61128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:29.898822 2026] [proxy:error] [pid 204156:tid 204292] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:29.898872 2026] [proxy_http:error] [pid 204156:tid 204292] [client 198.235.24.52:61128] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:29.919758 2026] [security2:error] [pid 204156:tid 204312] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mARbAFPhDXvzP7SnSJwAAAak"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:30.220211 2026] [security2:error] [pid 204156:tid 204300] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mAhbAFPhDXvzP7SnSNgAAAZ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:30.427640 2026] [security2:error] [pid 204156:tid 204379] [client 98.159.234.160:21265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mAhbAFPhDXvzP7SnSSwAAAew"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:43:30.508522 2026] [security2:error] [pid 178071:tid 178238] [client 49.47.218.174:61701] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mAhltgi7HBmNwzJN_ugAAACM"]
[Mon Jul 20 07:43:30.508644 2026] [security2:error] [pid 178071:tid 178238] [client 49.47.218.174:61701] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mAhltgi7HBmNwzJN_ugAAACM"]
[Mon Jul 20 07:43:30.543068 2026] [security2:error] [pid 178071:tid 178154] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4mAhltgi7HBmNwzJN_vQAAE1A"]
[Mon Jul 20 07:43:30.573418 2026] [security2:error] [pid 178071:tid 178221] [client 57.141.18.23:46630] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l_xltgi7HBmNwzJN_JwAAEmA"]
[Mon Jul 20 07:43:30.696033 2026] [security2:error] [pid 204156:tid 204389] [client 57.141.18.105:21118] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l_xbAFPhDXvzP7SnRzAAB9mI"]
[Mon Jul 20 07:43:30.697663 2026] [security2:error] [pid 204156:tid 204327] [client 186.221.114.200:58942] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mAhbAFPhDXvzP7SnSWgAAAbg"]
[Mon Jul 20 07:43:30.697813 2026] [security2:error] [pid 204156:tid 204327] [client 186.221.114.200:58942] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mAhbAFPhDXvzP7SnSWgAAAbg"]
[Mon Jul 20 07:43:30.714899 2026] [security2:error] [pid 204156:tid 204357] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mAhbAFPhDXvzP7SnSTQAAAdY"]
[Mon Jul 20 07:43:30.743422 2026] [security2:error] [pid 178071:tid 178256] [client 14.225.17.146:56364] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "bbwipartnerconference.com"] [uri "/index.php"] [unique_id "al4mARltgi7HBmNwzJN_iwAAADU"], referer: http://bbwipartnerconference.com/WWW
[Mon Jul 20 07:43:30.933859 2026] [security2:error] [pid 178071:tid 178150] [remote 20.153.140.50:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nzfoodstory.com"] [uri "/wp-login.php"] [unique_id "al4mAhltgi7HBmNwzJN_xwAAPUw"], referer: https://nzfoodstory.com/wp-login.php
[Mon Jul 20 07:43:31.005693 2026] [security2:error] [pid 178071:tid 178277] [client 103.139.191.61:58205] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mAxltgi7HBmNwzJN_ygAAAEo"]
[Mon Jul 20 07:43:31.009059 2026] [security2:error] [pid 178071:tid 178277] [client 103.139.191.61:58205] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mAxltgi7HBmNwzJN_ygAAAEo"]
[Mon Jul 20 07:43:31.094979 2026] [security2:error] [pid 204156:tid 204342] [client 104.207.50.49:56947] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 49.50.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mAxbAFPhDXvzP7SnSaQAAAcc"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:31.187142 2026] [security2:error] [pid 204156:tid 204313] [client 14.225.17.146:49631] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "detroitcsc.com"] [uri "/index.php"] [unique_id "al4mARbAFPhDXvzP7SnSKwAAAao"], referer: http://detroitcsc.com/WWW
[Mon Jul 20 07:43:31.202195 2026] [security2:error] [pid 204156:tid 204315] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mAhbAFPhDXvzP7SnSZQAAAaw"]
[Mon Jul 20 07:43:31.353550 2026] [security2:error] [pid 204156:tid 204376] [client 57.141.18.125:23368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4l_xbAFPhDXvzP7SnR5gAB6TI"]
[Mon Jul 20 07:43:31.394005 2026] [security2:error] [pid 178071:tid 178311] [client 74.208.214.194:33976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4mAxltgi7HBmNwzJN_2QAAAGw"]
[Mon Jul 20 07:43:31.705265 2026] [proxy:error] [pid 204156:tid 204337] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:31.705298 2026] [proxy_http:error] [pid 204156:tid 204337] [client 104.155.181.6:53058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:31.705781 2026] [proxy:error] [pid 204156:tid 204337] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:31.705804 2026] [proxy_http:error] [pid 204156:tid 204337] [client 104.155.181.6:53058] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:31.813575 2026] [security2:error] [pid 178071:tid 178244] [client 57.141.18.72:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mAxltgi7HBmNwzJN_4AAAACk"]
[Mon Jul 20 07:43:31.888224 2026] [security2:error] [pid 204156:tid 204267] [remote 91.142.222.105:36620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mAxbAFPhDXvzP7SnSowAB9m4"]
[Mon Jul 20 07:43:31.951205 2026] [security2:error] [pid 204156:tid 204366] [client 45.3.53.227:42521] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 227.53.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mAxbAFPhDXvzP7SnSpAAAAd8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:43:32.140635 2026] [security2:error] [pid 204156:tid 204199] [remote 91.142.222.105:36620] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 105.222.142.91.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mBBbAFPhDXvzP7SnSrQABvCo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:43:32.199745 2026] [security2:error] [pid 204156:tid 204408] [client 191.202.66.27:55715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4mBBbAFPhDXvzP7SnSrwAAAgk"]
[Mon Jul 20 07:43:32.199864 2026] [security2:error] [pid 204156:tid 204408] [client 191.202.66.27:55715] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4mBBbAFPhDXvzP7SnSrwAAAgk"]
[Mon Jul 20 07:43:32.423649 2026] [security2:error] [pid 204156:tid 204304] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mBBbAFPhDXvzP7SnSsgAAAaE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:32.551553 2026] [security2:error] [pid 204156:tid 204382] [client 104.207.52.18:35259] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.52.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mBBbAFPhDXvzP7SnSugAAAe8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:32.567309 2026] [security2:error] [pid 204156:tid 204287] [client 45.3.47.9:13065] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 9.47.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mBBbAFPhDXvzP7SnSuwAAAZA"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:43:32.645520 2026] [security2:error] [pid 178071:tid 178189] [remote 185.177.72.100:30204] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cconfig%5cmail.php"] [unique_id "al4mBBltgi7HBmNwzJN__AAAG3M"]
[Mon Jul 20 07:43:32.849055 2026] [security2:error] [pid 204156:tid 204162] [remote 217.61.143.92:35632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mBBbAFPhDXvzP7SnSxQABrwU"]
[Mon Jul 20 07:43:32.849181 2026] [security2:error] [pid 204156:tid 204318] [client 217.61.143.92:35632] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mBBbAFPhDXvzP7SnSxQABrwU"]
[Mon Jul 20 07:43:32.886615 2026] [security2:error] [pid 178071:tid 178256] [client 77.110.127.138:54890] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mBBltgi7HBmNwzJOADAAAADU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:33.180952 2026] [security2:error] [pid 178071:tid 178289] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mBBltgi7HBmNwzJOAFAAAAFY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:33.247049 2026] [core:error] [pid 178071:tid 178318] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:33.247089 2026] [core:error] [pid 178071:tid 178318] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:33.436596 2026] [security2:error] [pid 178071:tid 178163] [remote 116.179.32.163:52845] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4mBRltgi7HBmNwzJOAKgAAJlk"]
[Mon Jul 20 07:43:33.538692 2026] [security2:error] [pid 178071:tid 178187] [remote 185.177.72.100:30214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cconfig%5cmail.php"] [unique_id "al4mBRltgi7HBmNwzJOALQAAT3E"]
[Mon Jul 20 07:43:33.542599 2026] [security2:error] [pid 178071:tid 178283] [client 36.93.152.155:49641] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mBRltgi7HBmNwzJOALAAAAFA"]
[Mon Jul 20 07:43:33.542692 2026] [security2:error] [pid 178071:tid 178283] [client 36.93.152.155:49641] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mBRltgi7HBmNwzJOALAAAAFA"]
[Mon Jul 20 07:43:33.543175 2026] [security2:error] [pid 204156:tid 204364] [client 57.141.18.14:42138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mARbAFPhDXvzP7SnSMgAB3V8"]
[Mon Jul 20 07:43:33.573108 2026] [security2:error] [pid 178071:tid 178205] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mBRltgi7HBmNwzJOAIgAAAAI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:33.630866 2026] [security2:error] [pid 204156:tid 204405] [client 57.141.18.115:56018] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mAhbAFPhDXvzP7SnSOgACBnY"]
[Mon Jul 20 07:43:33.733790 2026] [security2:error] [pid 178071:tid 178235] [client 77.110.127.138:54953] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/if(now()=sysdate(),sleep(15),0)/js/dist/wp-seo-local-vendor-1390.js"] [unique_id "al4mBRltgi7HBmNwzJOAOwAAACA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:33.736361 2026] [core:error] [pid 178071:tid 178206] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:33.736383 2026] [core:error] [pid 178071:tid 178206] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:33.776776 2026] [autoindex:error] [pid 178071:tid 178083] [remote 34.48.215.173:49169] AH01276: Cannot serve directory /home2/uwljivmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.uwl.jiv.mybluehost.me
[Mon Jul 20 07:43:33.812003 2026] [security2:error] [pid 204156:tid 204160] [remote 185.65.120.166:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.120.65.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mBRbAFPhDXvzP7SnS2gAB5gM"]
[Mon Jul 20 07:43:34.075019 2026] [security2:error] [pid 204156:tid 204284] [remote 57.141.18.73:38308] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 73.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4mBhbAFPhDXvzP7SnS6gACBH8"]
[Mon Jul 20 07:43:34.084281 2026] [security2:error] [pid 204156:tid 204260] [remote 185.65.120.166:48952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 166.120.65.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mBhbAFPhDXvzP7SnS6wABn2c"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:43:34.129139 2026] [core:error] [pid 204156:tid 204360] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:34.129163 2026] [core:error] [pid 204156:tid 204360] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:34.153032 2026] [security2:error] [pid 204156:tid 204359] [client 136.158.60.21:52166] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mBhbAFPhDXvzP7SnS9gAAAdg"]
[Mon Jul 20 07:43:34.153134 2026] [security2:error] [pid 204156:tid 204359] [client 136.158.60.21:52166] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mBhbAFPhDXvzP7SnS9gAAAdg"]
[Mon Jul 20 07:43:34.175818 2026] [security2:error] [pid 204156:tid 204292] [client 194.36.27.215:50472] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "new-menus.com"] [uri "/index.php"] [unique_id "al4mBhbAFPhDXvzP7SnS9AAAAZU"], referer: http://new-menus.com/index.php
[Mon Jul 20 07:43:34.200705 2026] [security2:error] [pid 204156:tid 204164] [remote 124.55.178.99:40538] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4mBhbAFPhDXvzP7SnS-gABrAc"]
[Mon Jul 20 07:43:34.200835 2026] [security2:error] [pid 204156:tid 204315] [client 124.55.178.99:40538] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "walkingandtalking.net"] [uri "/xmlrpc.php"] [unique_id "al4mBhbAFPhDXvzP7SnS-gABrAc"]
[Mon Jul 20 07:43:34.290599 2026] [security2:error] [pid 178071:tid 178302] [client 39.46.9.231:62165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mBhltgi7HBmNwzJOAUgAAAGM"]
[Mon Jul 20 07:43:34.290722 2026] [security2:error] [pid 178071:tid 178302] [client 39.46.9.231:62165] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mBhltgi7HBmNwzJOAUgAAAGM"]
[Mon Jul 20 07:43:34.384033 2026] [security2:error] [pid 204156:tid 204332] [client 57.141.18.76:26522] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mAhbAFPhDXvzP7SnSYQABvWY"]
[Mon Jul 20 07:43:34.386943 2026] [security2:error] [pid 178071:tid 178279] [client 103.106.165.44:59296] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mBhltgi7HBmNwzJOAVgAAAEw"]
[Mon Jul 20 07:43:34.387053 2026] [security2:error] [pid 178071:tid 178279] [client 103.106.165.44:59296] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mBhltgi7HBmNwzJOAVgAAAEw"]
[Mon Jul 20 07:43:34.412798 2026] [security2:error] [pid 204156:tid 204342] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mBhbAFPhDXvzP7SnS-QAAAcc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:34.440289 2026] [security2:error] [pid 178071:tid 178076] [remote 185.177.72.100:30228] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fconfig/mail.php"] [unique_id "al4mBhltgi7HBmNwzJOAWAAALQM"]
[Mon Jul 20 07:43:34.633371 2026] [security2:error] [pid 204156:tid 204311] [client 57.141.18.85:28500] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mAxbAFPhDXvzP7SnSeQABqE0"]
[Mon Jul 20 07:43:34.694027 2026] [security2:error] [pid 204156:tid 204398] [client 57.141.18.46:44488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mAxbAFPhDXvzP7SnSewAB_wQ"]
[Mon Jul 20 07:43:34.908841 2026] [security2:error] [pid 178071:tid 178327] [client 14.225.17.146:64762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "samdothan.org"] [uri "/index.php"] [unique_id "al4mBhltgi7HBmNwzJOAYAAAAHw"], referer: http://samdothan.org/WWW
[Mon Jul 20 07:43:34.929617 2026] [security2:error] [pid 204156:tid 204338] [client 77.110.127.138:54939] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mBhbAFPhDXvzP7SnTIgAAAcM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:35.122417 2026] [security2:error] [pid 178071:tid 178259] [client 14.225.17.146:57795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4mBhltgi7HBmNwzJOAZgAAADg"], referer: http://fluidtemple.org/WWW
[Mon Jul 20 07:43:35.154532 2026] [security2:error] [pid 204156:tid 204371] [client 13.232.231.177:32066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mBxbAFPhDXvzP7SnTNgAAAeQ"]
[Mon Jul 20 07:43:35.154682 2026] [security2:error] [pid 204156:tid 204371] [client 13.232.231.177:32066] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mBxbAFPhDXvzP7SnTNgAAAeQ"]
[Mon Jul 20 07:43:35.185488 2026] [security2:error] [pid 204156:tid 204341] [client 14.224.227.113:56346] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mBxbAFPhDXvzP7SnTNwAAAcY"]
[Mon Jul 20 07:43:35.191235 2026] [security2:error] [pid 204156:tid 204300] [client 14.224.227.113:56348] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mBxbAFPhDXvzP7SnTOgAAAZ0"]
[Mon Jul 20 07:43:35.200449 2026] [security2:error] [pid 204156:tid 204377] [client 14.251.3.155:56347] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mBxbAFPhDXvzP7SnTOwAAAeo"]
[Mon Jul 20 07:43:35.234242 2026] [security2:error] [pid 204156:tid 204402] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mBxbAFPhDXvzP7SnTKgAAAgM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:35.312815 2026] [security2:error] [pid 204156:tid 204212] [remote 185.177.72.100:30244] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fconfig%252fmail.php"] [unique_id "al4mBxbAFPhDXvzP7SnTPwABnjc"]
[Mon Jul 20 07:43:35.473999 2026] [security2:error] [pid 178071:tid 178280] [client 216.24.212.12:24541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4mBxltgi7HBmNwzJOAdQAAAE0"]
[Mon Jul 20 07:43:35.493865 2026] [security2:error] [pid 204156:tid 204388] [client 216.24.212.19:27951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 19.212.24.216.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "soloceos.com"] [uri "/wp-login.php"] [unique_id "al4mBxbAFPhDXvzP7SnTSwAAAfU"]
[Mon Jul 20 07:43:35.529252 2026] [security2:error] [pid 204156:tid 204318] [client 14.225.17.146:50383] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thechancersband.com"] [uri "/index.php"] [unique_id "al4mBxbAFPhDXvzP7SnTRQAAAa8"], referer: http://thechancersband.com/WWW
[Mon Jul 20 07:43:35.559005 2026] [security2:error] [pid 204156:tid 204305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mBxbAFPhDXvzP7SnTQwAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:35.611458 2026] [proxy:error] [pid 204156:tid 204345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:35.611491 2026] [proxy_http:error] [pid 204156:tid 204345] [client 104.155.181.6:51318] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:35.611970 2026] [proxy:error] [pid 204156:tid 204345] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:35.611994 2026] [proxy_http:error] [pid 204156:tid 204345] [client 104.155.181.6:51318] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:35.625093 2026] [security2:error] [pid 204156:tid 204306] [client 77.110.127.138:54883] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/js/dist/wp-seo-local-vendor-1390.js"] [unique_id "al4mBxbAFPhDXvzP7SnTWAAAAaM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:35.699700 2026] [security2:error] [pid 204156:tid 204354] [client 180.249.173.210:56644] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mBxbAFPhDXvzP7SnTXwAAAdM"]
[Mon Jul 20 07:43:35.700501 2026] [security2:error] [pid 204156:tid 204354] [client 180.249.173.210:56644] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mBxbAFPhDXvzP7SnTXwAAAdM"]
[Mon Jul 20 07:43:35.797318 2026] [security2:error] [pid 204156:tid 204290] [client 57.141.18.65:60056] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mBBbAFPhDXvzP7SnSuAABk1s"]
[Mon Jul 20 07:43:35.895058 2026] [security2:error] [pid 204156:tid 204394] [client 57.141.18.29:47610] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mBBbAFPhDXvzP7SnStwAB-3I"]
[Mon Jul 20 07:43:36.152611 2026] [security2:error] [pid 204156:tid 204191] [remote 111.225.214.176:1350] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4mCBbAFPhDXvzP7SnTcwACByI"]
[Mon Jul 20 07:43:36.219996 2026] [security2:error] [pid 178071:tid 178263] [client 14.225.17.146:64872] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "laceycaraccident.com"] [uri "/index.php"] [unique_id "al4mCBltgi7HBmNwzJOAjwAAADw"], referer: http://laceycaraccident.com/WWW
[Mon Jul 20 07:43:36.239560 2026] [security2:error] [pid 204156:tid 204363] [client 56.125.35.21:42776] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.35.125.56.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mCBbAFPhDXvzP7SnTdQAAAdw"]
[Mon Jul 20 07:43:36.239660 2026] [security2:error] [pid 204156:tid 204363] [client 56.125.35.21:42776] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mCBbAFPhDXvzP7SnTdQAAAdw"]
[Mon Jul 20 07:43:36.305475 2026] [security2:error] [pid 178071:tid 178320] [client 37.52.210.45:55075] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mCBltgi7HBmNwzJOAnQAAAHU"]
[Mon Jul 20 07:43:36.305574 2026] [security2:error] [pid 178071:tid 178320] [client 37.52.210.45:55075] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mCBltgi7HBmNwzJOAnQAAAHU"]
[Mon Jul 20 07:43:36.552266 2026] [security2:error] [pid 204156:tid 204295] [client 155.2.215.79:24775] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mCBbAFPhDXvzP7SnTfQAAAZg"]
[Mon Jul 20 07:43:36.877999 2026] [security2:error] [pid 204156:tid 204391] [client 14.225.17.146:64617] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "lifeisbetterlakeside.com"] [uri "/index.php"] [unique_id "al4mCBbAFPhDXvzP7SnTgQAAAfg"], referer: http://lifeisbetterlakeside.com/WWW
[Mon Jul 20 07:43:36.971812 2026] [security2:error] [pid 178071:tid 178271] [client 149.0.16.108:56429] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mCBltgi7HBmNwzJOAwQAAAEQ"]
[Mon Jul 20 07:43:36.971963 2026] [security2:error] [pid 178071:tid 178271] [client 149.0.16.108:56429] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mCBltgi7HBmNwzJOAwQAAAEQ"]
[Mon Jul 20 07:43:36.975125 2026] [security2:error] [pid 178071:tid 178321] [client 57.141.18.118:23060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mBRltgi7HBmNwzJOAJgAAdnc"]
[Mon Jul 20 07:43:37.046382 2026] [security2:error] [pid 178071:tid 178258] [client 57.141.18.46:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mCBltgi7HBmNwzJOAvwAAADc"]
[Mon Jul 20 07:43:37.122503 2026] [security2:error] [pid 204156:tid 204292] [client 154.192.233.184:61940] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mCRbAFPhDXvzP7SnTkwAAAZU"]
[Mon Jul 20 07:43:37.122623 2026] [security2:error] [pid 204156:tid 204292] [client 154.192.233.184:61940] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mCRbAFPhDXvzP7SnTkwAAAZU"]
[Mon Jul 20 07:43:37.211286 2026] [ssl:error] [pid 204156:tid 204371] [client 104.48.69.105:60226] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname www.icemarc.org provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:43:37.215941 2026] [security2:error] [pid 204156:tid 204340] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mCRbAFPhDXvzP7SnTjwAAAcU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:37.227095 2026] [security2:error] [pid 204156:tid 204213] [remote 185.177.72.100:30248] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cconfig%5cservices.php"] [unique_id "al4mCRbAFPhDXvzP7SnTmwABmzg"]
[Mon Jul 20 07:43:37.245413 2026] [security2:error] [pid 204156:tid 204186] [remote 74.235.96.117:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4mCRbAFPhDXvzP7SnTnAAB4h0"]
[Mon Jul 20 07:43:37.424740 2026] [security2:error] [pid 204156:tid 204211] [remote 74.235.96.117:39288] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.96.235.74.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "worbals.com"] [uri "/wp-login.php"] [unique_id "al4mCRbAFPhDXvzP7SnTogAB9DY"], referer: https://worbals.com/wp-login.php
[Mon Jul 20 07:43:37.507373 2026] [security2:error] [pid 178071:tid 178303] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mCRltgi7HBmNwzJOAywAAAGQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:37.563421 2026] [security2:error] [pid 178071:tid 178317] [client 65.111.31.94:23171] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 94.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mCRltgi7HBmNwzJOA1wAAAHI"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:37.630931 2026] [ssl:error] [pid 204156:tid 204359] [client 104.48.69.105:60242] AH02032: Hostname box5936.bluehost.com (default host as no SNI was provided) and hostname blog.danwolfe.us provided via HTTP have no compatible SSL setup for policy 'secure'
[Mon Jul 20 07:43:37.760998 2026] [security2:error] [pid 204156:tid 204347] [client 14.225.17.146:58896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4mCRbAFPhDXvzP7SnTpQAAAcw"], referer: http://maxenengineering.com/WWW
[Mon Jul 20 07:43:37.833432 2026] [security2:error] [pid 204156:tid 204380] [client 57.141.18.46:44504] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mBhbAFPhDXvzP7SnTAgAB7Qw"]
[Mon Jul 20 07:43:37.840519 2026] [security2:error] [pid 204156:tid 204159] [remote 119.249.100.110:58029] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4mCRbAFPhDXvzP7SnT6gABowI"]
[Mon Jul 20 07:43:37.861354 2026] [security2:error] [pid 204156:tid 204375] [client 194.36.27.215:50562] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4mCRbAFPhDXvzP7SnT6QAAAeg"], referer: http://www.new-menus.com/index.php?PHPSESSID=5hh0tq3i9mf5r2e6akjo5f2p34&action=register
[Mon Jul 20 07:43:37.923709 2026] [security2:error] [pid 204156:tid 204296] [client 82.102.18.116:51264] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4mCRbAFPhDXvzP7SnT7wAAAZk"]
[Mon Jul 20 07:43:37.942007 2026] [security2:error] [pid 178071:tid 178313] [client 77.110.127.138:54888] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/js/dist/wp-seo-local-vendor-1390.js"] [unique_id "al4mCRltgi7HBmNwzJOA6gAAAG4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:37.944745 2026] [security2:error] [pid 204156:tid 204354] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fluidtemple.org"] [uri "/index.php"] [unique_id "al4mCRbAFPhDXvzP7SnT5wAAAdM"]
[Mon Jul 20 07:43:37.993921 2026] [security2:error] [pid 204156:tid 204368] [client 77.110.127.138:54949] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mCRbAFPhDXvzP7SnT9AAAAeE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:38.074397 2026] [security2:error] [pid 178071:tid 178134] [remote 185.177.72.100:4478] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cconfig%5cservices.php"] [unique_id "al4mChltgi7HBmNwzJOA8AAALj0"]
[Mon Jul 20 07:43:38.267459 2026] [security2:error] [pid 204156:tid 204316] [client 43.156.142.168:60697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.samdothan.org"] [uri "/wp-admin/index.php"] [unique_id "al4mChbAFPhDXvzP7SnT-gAAAa0"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:43:38.285639 2026] [security2:error] [pid 204156:tid 204387] [client 82.102.18.116:33180] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 116.18.102.82.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mChbAFPhDXvzP7SnUAQAAAfQ"]
[Mon Jul 20 07:43:38.298683 2026] [security2:error] [pid 204156:tid 204409] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mChbAFPhDXvzP7SnT-AAAAgo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:38.408854 2026] [security2:error] [pid 178071:tid 178278] [client 13.233.207.33:61964] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4mChltgi7HBmNwzJOA_AAAAEs"]
[Mon Jul 20 07:43:38.554550 2026] [security2:error] [pid 204156:tid 204346] [client 179.127.84.238:61420] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mChbAFPhDXvzP7SnUEAAAAcs"]
[Mon Jul 20 07:43:38.554755 2026] [security2:error] [pid 204156:tid 204346] [client 179.127.84.238:61420] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mChbAFPhDXvzP7SnUEAAAAcs"]
[Mon Jul 20 07:43:38.676495 2026] [security2:error] [pid 204156:tid 204304] [client 57.141.18.25:32552] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mBxbAFPhDXvzP7SnTLAABoQg"]
[Mon Jul 20 07:43:38.759207 2026] [security2:error] [pid 204156:tid 204383] [client 14.225.17.146:62381] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4mChbAFPhDXvzP7SnUGAAAAfA"], referer: https://maxenengineering.com/WWW
[Mon Jul 20 07:43:38.846520 2026] [security2:error] [pid 204156:tid 204199] [remote 51.68.236.87:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "wealthynarrative.com"] [uri "/robots.txt"] [unique_id "al4mChbAFPhDXvzP7SnUIwABzio"]
[Mon Jul 20 07:43:38.846685 2026] [security2:error] [pid 204156:tid 204349] [client 51.68.236.87:0] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "wealthynarrative.com"] [uri "/robots.txt"] [unique_id "al4mChbAFPhDXvzP7SnUIwABzio"]
[Mon Jul 20 07:43:38.934826 2026] [security2:error] [pid 204156:tid 204283] [remote 185.177.72.100:4492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fconfig/services.php"] [unique_id "al4mChbAFPhDXvzP7SnUJgACDn4"]
[Mon Jul 20 07:43:38.970088 2026] [security2:error] [pid 204156:tid 204348] [client 57.141.18.80:22720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mBxbAFPhDXvzP7SnTPgABzS4"]
[Mon Jul 20 07:43:38.979058 2026] [security2:error] [pid 204156:tid 204319] [client 82.102.18.116:33188] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4mChbAFPhDXvzP7SnUKAAAAbA"]
[Mon Jul 20 07:43:39.087767 2026] [security2:error] [pid 204156:tid 204393] [client 50.116.65.227:52866] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "peoplestrategies.us"] [uri "/wp-cron.php"] [unique_id "al4mCxbAFPhDXvzP7SnUMAAAAfo"]
[Mon Jul 20 07:43:39.090508 2026] [security2:error] [pid 204156:tid 204400] [client 14.225.17.146:55313] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "peoplestrategies.us"] [uri "/index.php"] [unique_id "al4mCRbAFPhDXvzP7SnT4wAAAgE"]
[Mon Jul 20 07:43:39.299082 2026] [security2:error] [pid 204156:tid 204364] [client 82.102.18.116:33192] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4mCxbAFPhDXvzP7SnUOwAAAd0"]
[Mon Jul 20 07:43:39.390653 2026] [security2:error] [pid 204156:tid 204398] [client 13.233.207.33:61976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4mCxbAFPhDXvzP7SnUQgAAAf8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:43:39.626257 2026] [security2:error] [pid 204156:tid 204383] [client 82.102.18.116:33198] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4mCxbAFPhDXvzP7SnUVAAAAfA"]
[Mon Jul 20 07:43:39.752624 2026] [security2:error] [pid 204156:tid 204376] [client 57.141.18.21:30808] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mCBbAFPhDXvzP7SnTbwAB6Sc"]
[Mon Jul 20 07:43:39.782037 2026] [security2:error] [pid 204156:tid 204194] [remote 185.177.72.100:4504] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fconfig%252fservices.php"] [unique_id "al4mCxbAFPhDXvzP7SnUYAAB8SU"]
[Mon Jul 20 07:43:39.815162 2026] [security2:error] [pid 178071:tid 178248] [client 14.225.17.146:50636] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "christiancountytrumpet.com"] [uri "/index.php"] [unique_id "al4mCxltgi7HBmNwzJOBFwAAAC0"], referer: http://christiancountytrumpet.com/WWW
[Mon Jul 20 07:43:39.969668 2026] [security2:error] [pid 204156:tid 204326] [client 82.102.18.116:33208] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4mCxbAFPhDXvzP7SnUbwAAAbc"]
[Mon Jul 20 07:43:40.206122 2026] [security2:error] [pid 204156:tid 204318] [client 14.225.17.146:50605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "partnerselectricalllc.com"] [uri "/index.php"] [unique_id "al4mCxbAFPhDXvzP7SnUYgAAAa8"], referer: http://partnerselectricalllc.com/WWW
[Mon Jul 20 07:43:40.247653 2026] [security2:error] [pid 178071:tid 178093] [remote 209.42.18.223:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4mDBltgi7HBmNwzJOBKgAAaxQ"]
[Mon Jul 20 07:43:40.290284 2026] [security2:error] [pid 204156:tid 204309] [client 82.102.18.116:33222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4mDBbAFPhDXvzP7SnUfQAAAaY"]
[Mon Jul 20 07:43:40.410804 2026] [security2:error] [pid 178071:tid 178188] [remote 209.42.18.223:58738] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 223.18.42.209.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "weifangsmefarm.com"] [uri "/wp-login.php"] [unique_id "al4mDBltgi7HBmNwzJOBNgAAfnI"], referer: https://weifangsmefarm.com/wp-login.php
[Mon Jul 20 07:43:40.618990 2026] [security2:error] [pid 178071:tid 178258] [client 82.102.18.116:33238] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4mDBltgi7HBmNwzJOBQQAAADc"]
[Mon Jul 20 07:43:40.681932 2026] [security2:error] [pid 178071:tid 178296] [client 20.206.105.145:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 145.105.206.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seedsofchangefilm.com"] [uri "/.well-known/about.php"] [unique_id "al4mDBltgi7HBmNwzJOBRgAAAF0"]
[Mon Jul 20 07:43:40.682064 2026] [security2:error] [pid 178071:tid 178296] [client 20.206.105.145:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "seedsofchangefilm.com"] [uri "/.well-known/about.php"] [unique_id "al4mDBltgi7HBmNwzJOBRgAAAF0"]
[Mon Jul 20 07:43:40.762993 2026] [security2:error] [pid 178071:tid 178300] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDBltgi7HBmNwzJOBOwAAAGE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:40.777253 2026] [security2:error] [pid 178071:tid 178208] [client 14.225.17.146:62454] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "bigwormfishing.com"] [uri "/index.php"] [unique_id "al4mDBltgi7HBmNwzJOBPwAAAAU"], referer: http://bigwormfishing.com/WWW
[Mon Jul 20 07:43:40.932516 2026] [security2:error] [pid 178071:tid 178256] [client 82.102.18.116:33246] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4mDBltgi7HBmNwzJOBTQAAADU"]
[Mon Jul 20 07:43:41.036648 2026] [security2:error] [pid 204156:tid 204343] [client 49.47.218.174:62240] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mDRbAFPhDXvzP7SnUowAAAcg"]
[Mon Jul 20 07:43:41.036762 2026] [security2:error] [pid 204156:tid 204343] [client 49.47.218.174:62240] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mDRbAFPhDXvzP7SnUowAAAcg"]
[Mon Jul 20 07:43:41.116986 2026] [security2:error] [pid 178071:tid 178276] [client 57.141.18.37:27316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mCRltgi7HBmNwzJOA0QAASQU"]
[Mon Jul 20 07:43:41.242050 2026] [security2:error] [pid 178071:tid 178257] [client 82.102.18.116:33256] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4mDRltgi7HBmNwzJOBVgAAADY"]
[Mon Jul 20 07:43:41.310617 2026] [security2:error] [pid 204156:tid 204362] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDBbAFPhDXvzP7SnUoQAAAds"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:41.347868 2026] [security2:error] [pid 204156:tid 204401] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDRbAFPhDXvzP7SnUqAAAAgI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:41.375184 2026] [security2:error] [pid 204156:tid 204213] [remote 188.40.28.4:53780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.28.40.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4mDRbAFPhDXvzP7SnUwwAB6zg"]
[Mon Jul 20 07:43:41.375363 2026] [security2:error] [pid 204156:tid 204378] [client 188.40.28.4:53780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.qix.pfz.mybluehost.me"] [uri "/wp/xmlrpc.php"] [unique_id "al4mDRbAFPhDXvzP7SnUwwAB6zg"]
[Mon Jul 20 07:43:41.561081 2026] [security2:error] [pid 178071:tid 178261] [client 82.102.18.116:33268] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4mDRltgi7HBmNwzJOBXwAAADo"]
[Mon Jul 20 07:43:41.579820 2026] [security2:error] [pid 204156:tid 204359] [client 216.73.216.54:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.gearwaterproof.com"] [uri "/index.php"] [unique_id "al4mDRbAFPhDXvzP7SnUsAAAAdg"]
[Mon Jul 20 07:43:41.606362 2026] [security2:error] [pid 178071:tid 178294] [client 103.139.191.61:58981] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mDRltgi7HBmNwzJOBYQAAAFs"]
[Mon Jul 20 07:43:41.606464 2026] [security2:error] [pid 178071:tid 178294] [client 103.139.191.61:58981] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mDRltgi7HBmNwzJOBYQAAAFs"]
[Mon Jul 20 07:43:41.698824 2026] [security2:error] [pid 178071:tid 178151] [remote 185.177.72.100:4506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cconfig%5cfilesystems.php"] [unique_id "al4mDRltgi7HBmNwzJOBYwAAaE0"]
[Mon Jul 20 07:43:41.750181 2026] [security2:error] [pid 204156:tid 204349] [client 186.221.114.200:59431] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mDRbAFPhDXvzP7SnU3QAAAc4"]
[Mon Jul 20 07:43:41.750379 2026] [security2:error] [pid 204156:tid 204349] [client 186.221.114.200:59431] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mDRbAFPhDXvzP7SnU3QAAAc4"]
[Mon Jul 20 07:43:41.759127 2026] [security2:error] [pid 204156:tid 204394] [client 15.204.254.129:60052] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1613"] [id "900942"] [msg "Invalid WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.path=///"] [hostname "suretybonds-california.com"] [uri "/"] [unique_id "al4mDRbAFPhDXvzP7SnU3gAAAfs"]
[Mon Jul 20 07:43:41.793108 2026] [security2:error] [pid 178071:tid 178291] [client 57.141.18.15:42054] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mCRltgi7HBmNwzJOA7AAAWCg"]
[Mon Jul 20 07:43:41.834924 2026] [security2:error] [pid 204156:tid 204325] [client 14.225.17.146:64582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.bigwormfishing.com"] [uri "/index.php"] [unique_id "al4mDRbAFPhDXvzP7SnU2AAAAbY"], referer: https://bigwormfishing.com/WWW
[Mon Jul 20 07:43:41.861739 2026] [security2:error] [pid 204156:tid 204232] [remote 57.141.18.113:44212] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 113.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5475308"] [unique_id "al4mDRbAFPhDXvzP7SnU4wAB4Us"]
[Mon Jul 20 07:43:41.889311 2026] [security2:error] [pid 204156:tid 204296] [client 82.102.18.116:33276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4mDRbAFPhDXvzP7SnU5gAAAZk"]
[Mon Jul 20 07:43:41.956285 2026] [security2:error] [pid 204156:tid 204247] [remote 57.141.18.6:61116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 6.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5475308"] [unique_id "al4mDRbAFPhDXvzP7SnU6QABxlo"]
[Mon Jul 20 07:43:41.985347 2026] [security2:error] [pid 204156:tid 204351] [client 14.225.17.146:55384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "narv.co"] [uri "/index.php"] [unique_id "al4mDBbAFPhDXvzP7SnUcwAAAdA"], referer: http://narv.co/WWW
[Mon Jul 20 07:43:42.008083 2026] [security2:error] [pid 178071:tid 178217] [client 57.141.18.115:56030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mChltgi7HBmNwzJOA9wAADkI"]
[Mon Jul 20 07:43:42.037483 2026] [fcgid:warn] [pid 178071:tid 178230] (70014)End of file found: [client 66.132.172.128:7306] mod_fcgid: can't get data from http client
[Mon Jul 20 07:43:42.216981 2026] [security2:error] [pid 204156:tid 204308] [client 82.102.18.116:33288] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4mDhbAFPhDXvzP7SnU_wAAAaU"]
[Mon Jul 20 07:43:42.258355 2026] [security2:error] [pid 204156:tid 204411] [client 43.156.142.168:63457] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.142.156.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "samdothan.org"] [uri "/wp-login.php"] [unique_id "al4mDhbAFPhDXvzP7SnVAwAAAgw"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:43:42.266670 2026] [security2:error] [pid 204156:tid 204372] [client 57.141.18.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnU9gAAAeU"]
[Mon Jul 20 07:43:42.286051 2026] [security2:error] [pid 204156:tid 204333] [client 13.90.37.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnVAAAAAb4"]
[Mon Jul 20 07:43:42.298813 2026] [security2:error] [pid 178071:tid 178223] [client 13.90.37.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4mDhltgi7HBmNwzJOBcQAAABQ"]
[Mon Jul 20 07:43:42.506553 2026] [security2:error] [pid 204156:tid 204173] [remote 160.187.68.132:44810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mDhbAFPhDXvzP7SnVEQABqRA"]
[Mon Jul 20 07:43:42.517011 2026] [security2:error] [pid 178071:tid 178300] [client 13.90.37.124:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "intelligentengineeringsolutions.com"] [uri "/index.php"] [unique_id "al4mDhltgi7HBmNwzJOBdgAAAGE"]
[Mon Jul 20 07:43:42.531349 2026] [security2:error] [pid 204156:tid 204326] [client 82.102.18.116:33298] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4mDhbAFPhDXvzP7SnVEwAAAbc"]
[Mon Jul 20 07:43:42.550319 2026] [security2:error] [pid 204156:tid 204349] [client 43.156.142.168:60697] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.samdothan.org"] [uri "/wp-admin/profile.php"] [unique_id "al4mDhbAFPhDXvzP7SnVDwAAAc4"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:43:42.571779 2026] [security2:error] [pid 204156:tid 204245] [remote 185.177.72.100:4512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cconfig%5cfilesystems.php"] [unique_id "al4mDhbAFPhDXvzP7SnVFQABwVg"]
[Mon Jul 20 07:43:42.583976 2026] [security2:error] [pid 204156:tid 204397] [client 158.173.89.95:54337] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mDhbAFPhDXvzP7SnVFwAAAf4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:43:42.630320 2026] [security2:error] [pid 204156:tid 204229] [remote 216.73.216.55:10373] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4mDhbAFPhDXvzP7SnVGgABmkg"]
[Mon Jul 20 07:43:42.658440 2026] [security2:error] [pid 204156:tid 204306] [client 136.144.33.201:44283] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4mDhbAFPhDXvzP7SnVHAAAAaM"]
[Mon Jul 20 07:43:42.661562 2026] [security2:error] [pid 204156:tid 204365] [client 193.36.225.42:59933] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 42.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "qualitycoatingsinspection.com"] [uri "/wp-login.php"] [unique_id "al4mDhbAFPhDXvzP7SnVGwAAAd4"]
[Mon Jul 20 07:43:42.668021 2026] [security2:error] [pid 178071:tid 178228] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDhltgi7HBmNwzJOBeAAAABk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:42.668697 2026] [security2:error] [pid 204156:tid 204375] [client 14.225.17.146:62657] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "gearwaterproof.com"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnVAgAAAeg"], referer: http://gearwaterproof.com/WWW
[Mon Jul 20 07:43:42.751104 2026] [security2:error] [pid 204156:tid 204341] [client 77.110.127.138:55008] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mDhbAFPhDXvzP7SnVIAAAAcY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:42.841412 2026] [security2:error] [pid 204156:tid 204319] [client 113.160.97.242:58179] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4mDhbAFPhDXvzP7SnVLAAAAbA"]
[Mon Jul 20 07:43:42.855627 2026] [security2:error] [pid 204156:tid 204361] [client 82.102.18.116:33310] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4mDhbAFPhDXvzP7SnVLQAAAdo"]
[Mon Jul 20 07:43:42.878607 2026] [security2:error] [pid 204156:tid 204366] [client 116.179.33.81:48649] ModSecurity: Access denied with code 406 (phase 2). Match of "beginsWith %{request_headers.host}" against "TX:1" required. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "504"] [id "340162"] [rev "302"] [msg "Atomicorp.com WAF Rules: Remote File Injection Attack detected (Unauthorized URL detected as argument)"] [data ",TX:1"] [severity "CRITICAL"] [hostname "mollycahill.com"] [uri "/"] [unique_id "al4mDhbAFPhDXvzP7SnVMwAAAd8"]
[Mon Jul 20 07:43:42.890459 2026] [security2:error] [pid 204156:tid 204315] [client 191.202.66.27:56200] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 27.66.202.191.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4mDhbAFPhDXvzP7SnVNAAAAaw"]
[Mon Jul 20 07:43:42.890604 2026] [security2:error] [pid 204156:tid 204315] [client 191.202.66.27:56200] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "crime14llc.net"] [uri "/xmlrpc.php"] [unique_id "al4mDhbAFPhDXvzP7SnVNAAAAaw"]
[Mon Jul 20 07:43:42.962552 2026] [security2:error] [pid 204156:tid 204371] [client 14.225.17.146:64598] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "yourenotadummywahealthguideforcaraccidentvictims.com"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnVJQAAAeQ"], referer: http://yourenotadummywahealthguideforcaraccidentvictims.com/WWW
[Mon Jul 20 07:43:42.988179 2026] [security2:error] [pid 204156:tid 204369] [client 14.225.17.146:64605] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.narv.co"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnVJgAAAeI"], referer: https://narv.co/WWW
[Mon Jul 20 07:43:43.010088 2026] [security2:error] [pid 178071:tid 178182] [remote 57.141.18.12:25514] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5433378"] [unique_id "al4mDxltgi7HBmNwzJOBhwAAQWw"]
[Mon Jul 20 07:43:43.122282 2026] [security2:error] [pid 204156:tid 204293] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnVOQAAAZY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:43.163540 2026] [security2:error] [pid 178071:tid 178218] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDhltgi7HBmNwzJOBhAAAAA8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:43.206151 2026] [security2:error] [pid 204156:tid 204377] [client 82.102.18.116:60809] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpanel.dqe.lew.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4mDxbAFPhDXvzP7SnVUQAAAeo"]
[Mon Jul 20 07:43:43.425650 2026] [security2:error] [pid 178071:tid 178289] [client 104.207.53.61:54969] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mDxltgi7HBmNwzJOBkAAAAFY"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:43.438469 2026] [security2:error] [pid 204156:tid 204207] [remote 185.177.72.100:4518] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fconfig/filesystems.php"] [unique_id "al4mDxbAFPhDXvzP7SnVYQAB2TI"]
[Mon Jul 20 07:43:43.496842 2026] [core:alert] [pid 204156:tid 204364] [client 35.252.169.107:0] /home4/rwpelamy/public_html/.htaccess: Missing regular expression for SetEnvIfNoCase
[Mon Jul 20 07:43:43.623858 2026] [security2:error] [pid 204156:tid 204326] [client 14.224.227.113:56458] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mDxbAFPhDXvzP7SnVcQAAAbc"]
[Mon Jul 20 07:43:43.654422 2026] [security2:error] [pid 204156:tid 204308] [client 14.251.3.155:56457] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mDxbAFPhDXvzP7SnVdQAAAaU"]
[Mon Jul 20 07:43:43.691142 2026] [security2:error] [pid 204156:tid 204338] [client 14.251.3.155:56459] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mDxbAFPhDXvzP7SnVeQAAAcM"]
[Mon Jul 20 07:43:43.770436 2026] [security2:error] [pid 204156:tid 204396] [client 57.141.18.3:24462] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDBbAFPhDXvzP7SnUcQAB_RM"]
[Mon Jul 20 07:43:43.781947 2026] [security2:error] [pid 204156:tid 204333] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDxbAFPhDXvzP7SnVYgAAAb4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:43.808673 2026] [security2:error] [pid 178071:tid 178294] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mDxltgi7HBmNwzJOBlgAAAFs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:43.821649 2026] [security2:error] [pid 204156:tid 204346] [client 57.141.18.117:60942] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDBbAFPhDXvzP7SnUdAAByxo"]
[Mon Jul 20 07:43:43.831328 2026] [security2:error] [pid 204156:tid 204407] [client 14.225.17.146:52804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "processorstudio.com"] [uri "/index.php"] [unique_id "al4mDxbAFPhDXvzP7SnVfgAAAgg"], referer: http://processorstudio.com/WWW
[Mon Jul 20 07:43:43.909943 2026] [security2:error] [pid 204156:tid 204309] [client 14.225.17.146:52750] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "amalia-capital.com"] [uri "/index.php"] [unique_id "al4mDxbAFPhDXvzP7SnVewAAAaY"], referer: http://amalia-capital.com/WWW
[Mon Jul 20 07:43:44.098703 2026] [security2:error] [pid 178071:tid 178242] [client 52.167.144.210:1654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4mDxltgi7HBmNwzJOBnwAAJ3U"]
[Mon Jul 20 07:43:44.218092 2026] [proxy:error] [pid 204156:tid 204361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:44.218127 2026] [proxy_http:error] [pid 204156:tid 204361] [client 104.155.181.6:39292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:44.218553 2026] [proxy:error] [pid 204156:tid 204361] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:44.218582 2026] [proxy_http:error] [pid 204156:tid 204361] [client 104.155.181.6:39292] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:44.236612 2026] [security2:error] [pid 204156:tid 204203] [remote 160.187.68.132:44810] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mEBbAFPhDXvzP7SnVngABoy4"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:43:44.254071 2026] [security2:error] [pid 204156:tid 204314] [client 57.141.18.84:35654] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDBbAFPhDXvzP7SnUiwABqzo"]
[Mon Jul 20 07:43:44.259510 2026] [security2:error] [pid 204156:tid 204357] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mEBbAFPhDXvzP7SnVkAAAAdY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:44.262820 2026] [security2:error] [pid 204156:tid 204351] [client 36.93.152.155:50358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mEBbAFPhDXvzP7SnVoQAAAdA"]
[Mon Jul 20 07:43:44.262916 2026] [security2:error] [pid 204156:tid 204351] [client 36.93.152.155:50358] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mEBbAFPhDXvzP7SnVoQAAAdA"]
[Mon Jul 20 07:43:44.267006 2026] [security2:error] [pid 204156:tid 204237] [remote 192.241.143.148:41124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mEBbAFPhDXvzP7SnVoAABs1A"]
[Mon Jul 20 07:43:44.284436 2026] [security2:error] [pid 204156:tid 204364] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mEBbAFPhDXvzP7SnVlAAAAd0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:44.299546 2026] [security2:error] [pid 204156:tid 204162] [remote 185.177.72.100:4532] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fconfig%252ffilesystems.php"] [unique_id "al4mEBbAFPhDXvzP7SnVowAB5AU"]
[Mon Jul 20 07:43:44.300845 2026] [security2:error] [pid 204156:tid 204347] [client 103.106.165.44:59786] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mEBbAFPhDXvzP7SnVpAAAAcw"]
[Mon Jul 20 07:43:44.300939 2026] [security2:error] [pid 204156:tid 204347] [client 103.106.165.44:59786] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mEBbAFPhDXvzP7SnVpAAAAcw"]
[Mon Jul 20 07:43:44.443354 2026] [security2:error] [pid 178071:tid 178214] [client 158.173.166.181:48927] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mEBltgi7HBmNwzJOBqAAAAAs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:43:44.482910 2026] [security2:error] [pid 204156:tid 204265] [remote 192.241.143.148:41124] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "oqw.bur.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mEBbAFPhDXvzP7SnVrAAB9mw"], referer: https://oqw.bur.mybluehost.me/wp-login.php
[Mon Jul 20 07:43:44.587555 2026] [security2:error] [pid 204156:tid 204350] [client 57.141.18.46:28836] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDRbAFPhDXvzP7SnUogABzyI"]
[Mon Jul 20 07:43:44.725402 2026] [security2:error] [pid 204156:tid 204365] [client 14.225.17.146:64821] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.processorstudio.com"] [uri "/index.php"] [unique_id "al4mEBbAFPhDXvzP7SnVugAAAd4"], referer: https://processorstudio.com/WWW
[Mon Jul 20 07:43:44.750598 2026] [security2:error] [pid 204156:tid 204412] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mEBbAFPhDXvzP7SnVswAAAg0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:44.779234 2026] [security2:error] [pid 178071:tid 178231] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mEBltgi7HBmNwzJOBrQAAABw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:44.809365 2026] [security2:error] [pid 178071:tid 178266] [client 66.132.172.128:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "www.cathybuffini.com"] [uri "/index.php"] [unique_id "al4mDxltgi7HBmNwzJOBmwAAAD8"]
[Mon Jul 20 07:43:44.885820 2026] [security2:error] [pid 178071:tid 178286] [client 65.111.23.228:12607] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mEBltgi7HBmNwzJOBuwAAAFM"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:44.960824 2026] [security2:error] [pid 178071:tid 178223] [client 136.158.60.21:53756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mEBltgi7HBmNwzJOBwwAAABQ"]
[Mon Jul 20 07:43:44.960928 2026] [security2:error] [pid 178071:tid 178223] [client 136.158.60.21:53756] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mEBltgi7HBmNwzJOBwwAAABQ"]
[Mon Jul 20 07:43:44.973736 2026] [security2:error] [pid 178071:tid 178302] [client 89.238.167.150:34322] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 150.167.238.89.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4mEBltgi7HBmNwzJOBwQAAAGM"]
[Mon Jul 20 07:43:44.973869 2026] [security2:error] [pid 178071:tid 178302] [client 89.238.167.150:34322] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "muafaces.org"] [uri "/xmlrpc.php"] [unique_id "al4mEBltgi7HBmNwzJOBwQAAAGM"]
[Mon Jul 20 07:43:45.011456 2026] [security2:error] [pid 204156:tid 204374] [client 57.141.18.44:43960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDRbAFPhDXvzP7SnUzAAB5zY"]
[Mon Jul 20 07:43:45.207328 2026] [security2:error] [pid 178071:tid 178268] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mEBltgi7HBmNwzJOBxwAAAEE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:45.243057 2026] [autoindex:error] [pid 204156:tid 204281] [remote 136.114.198.221:59420] AH01276: Cannot serve directory /home2/elvxwymy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.elv.xwy.mybluehost.me
[Mon Jul 20 07:43:45.291074 2026] [security2:error] [pid 204156:tid 204288] [client 39.46.9.231:62578] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mERbAFPhDXvzP7SnV1gAAAZE"]
[Mon Jul 20 07:43:45.291201 2026] [security2:error] [pid 204156:tid 204288] [client 39.46.9.231:62578] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mERbAFPhDXvzP7SnV1gAAAZE"]
[Mon Jul 20 07:43:45.414141 2026] [security2:error] [pid 178071:tid 178246] [client 180.249.173.210:57152] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mERltgi7HBmNwzJOB3gAAACs"]
[Mon Jul 20 07:43:45.430118 2026] [security2:error] [pid 178071:tid 178237] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mERltgi7HBmNwzJOB1wAAACI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:45.610637 2026] [security2:error] [pid 204156:tid 204271] [remote 160.187.68.132:60110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4mERbAFPhDXvzP7SnV6AAB7nI"]
[Mon Jul 20 07:43:45.900408 2026] [security2:error] [pid 204156:tid 204345] [client 194.36.27.215:50780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.new-menus.com"] [uri "/index.php"] [unique_id "al4mERbAFPhDXvzP7SnV-QAAAco"], referer: http://www.new-menus.com/index.php?PHPSESSID=5hh0tq3i9mf5r2e6akjo5f2p34&action=login
[Mon Jul 20 07:43:45.955101 2026] [security2:error] [pid 204156:tid 204305] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mERbAFPhDXvzP7SnV8gAAAaI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:46.349260 2026] [security2:error] [pid 204156:tid 204387] [client 57.141.18.86:41022] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDhbAFPhDXvzP7SnVNwAB9Bw"]
[Mon Jul 20 07:43:46.365971 2026] [security2:error] [pid 204156:tid 204186] [remote 160.187.68.132:60110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ncsynchro.com"] [uri "/wp-login.php"] [unique_id "al4mEhbAFPhDXvzP7SnWHgAB3R0"], referer: https://ncsynchro.com/wp-login.php
[Mon Jul 20 07:43:46.511373 2026] [security2:error] [pid 204156:tid 204296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mEhbAFPhDXvzP7SnWGgAAAZk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:46.645470 2026] [security2:error] [pid 178071:tid 178290] [client 15.229.69.106:32370] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mEhltgi7HBmNwzJOCAwAAAFc"]
[Mon Jul 20 07:43:46.645573 2026] [security2:error] [pid 178071:tid 178290] [client 15.229.69.106:32370] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mEhltgi7HBmNwzJOCAwAAAFc"]
[Mon Jul 20 07:43:46.751724 2026] [security2:error] [pid 178071:tid 178246] [client 180.249.173.210:57152] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mERltgi7HBmNwzJOB3gAAACs"]
[Mon Jul 20 07:43:46.773696 2026] [security2:error] [pid 204156:tid 204291] [client 50.116.65.227:40892] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4mEhbAFPhDXvzP7SnWKgAAAZQ"]
[Mon Jul 20 07:43:46.849932 2026] [security2:error] [pid 178071:tid 178235] [client 66.249.79.6:40721] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "www.images.jupitergear.com"] [uri "/robots.txt"] [unique_id "al4mEhltgi7HBmNwzJOCDgAAACA"]
[Mon Jul 20 07:43:46.963592 2026] [security2:error] [pid 178071:tid 178248] [client 37.52.210.45:60199] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mEhltgi7HBmNwzJOCEAAAAC0"]
[Mon Jul 20 07:43:46.963721 2026] [security2:error] [pid 178071:tid 178248] [client 37.52.210.45:60199] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mEhltgi7HBmNwzJOCEAAAAC0"]
[Mon Jul 20 07:43:46.978671 2026] [security2:error] [pid 178071:tid 178315] [client 50.116.65.227:40894] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4mEhltgi7HBmNwzJOCDQAAAHA"]
[Mon Jul 20 07:43:47.050957 2026] [security2:error] [pid 204156:tid 204394] [client 77.110.127.138:55013] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/if(now()=sysdate(),sleep(15),0)/mezza/page/page/3/"] [unique_id "al4mExbAFPhDXvzP7SnWVQAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:47.078625 2026] [security2:error] [pid 204156:tid 204399] [client 34.178.38.15:51883] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eyv.bve.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mExbAFPhDXvzP7SnWUwAAAgA"]
[Mon Jul 20 07:43:47.139859 2026] [security2:error] [pid 204156:tid 204313] [client 57.141.18.11:51298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mDxbAFPhDXvzP7SnVgQABqnc"]
[Mon Jul 20 07:43:47.250092 2026] [security2:error] [pid 204156:tid 204288] [client 34.178.38.15:51883] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4mExbAFPhDXvzP7SnWYgAAAZE"]
[Mon Jul 20 07:43:47.293756 2026] [security2:error] [pid 178071:tid 178251] [client 142.111.152.234:52507] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mExltgi7HBmNwzJOCFAAAADA"]
[Mon Jul 20 07:43:47.307474 2026] [security2:error] [pid 204156:tid 204340] [client 104.207.34.242:32189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.34.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mExbAFPhDXvzP7SnWZQAAAcU"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:43:47.409519 2026] [proxy:error] [pid 178071:tid 178329] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:47.409560 2026] [proxy_http:error] [pid 178071:tid 178329] [client 104.155.181.6:39306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:47.410222 2026] [proxy:error] [pid 178071:tid 178329] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:43:47.410250 2026] [proxy_http:error] [pid 178071:tid 178329] [client 104.155.181.6:39306] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:43:47.590992 2026] [security2:error] [pid 178071:tid 178306] [client 34.178.38.15:54601] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/web/wp-includes/wlwmanifest.xml"] [unique_id "al4mExltgi7HBmNwzJOCHwAAAGc"]
[Mon Jul 20 07:43:47.675207 2026] [security2:error] [pid 178071:tid 178271] [client 149.0.16.108:56953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mExltgi7HBmNwzJOCKgAAAEQ"]
[Mon Jul 20 07:43:47.675309 2026] [security2:error] [pid 178071:tid 178271] [client 149.0.16.108:56953] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mExltgi7HBmNwzJOCKgAAAEQ"]
[Mon Jul 20 07:43:47.710939 2026] [security2:error] [pid 204156:tid 204301] [client 154.192.233.184:62316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mExbAFPhDXvzP7SnWbwAAAZ4"]
[Mon Jul 20 07:43:47.711053 2026] [security2:error] [pid 204156:tid 204301] [client 154.192.233.184:62316] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mExbAFPhDXvzP7SnWbwAAAZ4"]
[Mon Jul 20 07:43:47.736520 2026] [security2:error] [pid 178071:tid 178192] [remote 15.206.251.117:42948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4mExltgi7HBmNwzJOCLwAAG3Y"]
[Mon Jul 20 07:43:47.753444 2026] [core:error] [pid 178071:tid 178269] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:47.753461 2026] [core:error] [pid 178071:tid 178269] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:47.939429 2026] [security2:error] [pid 178071:tid 178312] [client 14.225.17.146:50569] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cheesewithjam.com"] [uri "/index.php"] [unique_id "al4mExltgi7HBmNwzJOCNQAAAG0"], referer: http://cheesewithjam.com/WWW
[Mon Jul 20 07:43:47.949385 2026] [security2:error] [pid 204156:tid 204346] [client 34.178.38.15:55724] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4mExbAFPhDXvzP7SnWfAAAAcs"]
[Mon Jul 20 07:43:47.982471 2026] [security2:error] [pid 178071:tid 178281] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mExltgi7HBmNwzJOCMgAAAE4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:48.014888 2026] [security2:error] [pid 178071:tid 178297] [client 14.225.17.146:50175] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/index.php"] [unique_id "al4mExltgi7HBmNwzJOCPQAAAF4"], referer: http://backandneckpainrelieflaceychiropractor.com/WWW
[Mon Jul 20 07:43:48.150881 2026] [security2:error] [pid 178071:tid 178109] [remote 15.206.251.117:42948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 117.251.206.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4mFBltgi7HBmNwzJOCRQAAIiQ"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:43:48.256464 2026] [security2:error] [pid 204156:tid 204387] [client 34.178.38.15:56733] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4mFBbAFPhDXvzP7SnWkQAAAfQ"]
[Mon Jul 20 07:43:48.321442 2026] [security2:error] [pid 178071:tid 178307] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mFBltgi7HBmNwzJOCQAAAAGg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:48.569323 2026] [security2:error] [pid 178071:tid 178289] [client 34.178.38.15:57608] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/2020/wp-includes/wlwmanifest.xml"] [unique_id "al4mFBltgi7HBmNwzJOCVwAAAFY"]
[Mon Jul 20 07:43:48.622375 2026] [security2:error] [pid 204156:tid 204312] [client 14.225.17.146:52691] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "soloceos.com"] [uri "/index.php"] [unique_id "al4mEhbAFPhDXvzP7SnWTwAAAak"], referer: http://soloceos.com/WWW
[Mon Jul 20 07:43:48.646220 2026] [security2:error] [pid 178071:tid 178296] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mFBltgi7HBmNwzJOCUwAAAF0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:48.758636 2026] [security2:error] [pid 178071:tid 178130] [remote 173.249.4.11:17265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4mFBltgi7HBmNwzJOCXwAAKjk"]
[Mon Jul 20 07:43:48.855422 2026] [security2:error] [pid 204156:tid 204290] [client 34.178.38.15:58587] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/2021/wp-includes/wlwmanifest.xml"] [unique_id "al4mFBbAFPhDXvzP7SnWqwAAAZM"]
[Mon Jul 20 07:43:48.943415 2026] [security2:error] [pid 178071:tid 178168] [remote 173.249.4.11:17265] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "civitansuncitiesaz.org"] [uri "/wp-login.php"] [unique_id "al4mFBltgi7HBmNwzJOCZAAAEl4"], referer: https://civitansuncitiesaz.org/wp-login.php
[Mon Jul 20 07:43:49.054960 2026] [security2:error] [pid 178071:tid 178284] [client 179.127.84.238:61948] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mFRltgi7HBmNwzJOCZgAAAFE"]
[Mon Jul 20 07:43:49.055111 2026] [security2:error] [pid 178071:tid 178284] [client 179.127.84.238:61948] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mFRltgi7HBmNwzJOCZgAAAFE"]
[Mon Jul 20 07:43:49.164956 2026] [security2:error] [pid 204156:tid 204344] [client 34.178.38.15:59767] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4mFRbAFPhDXvzP7SnWyQAAAck"]
[Mon Jul 20 07:43:49.229025 2026] [security2:error] [pid 178071:tid 178282] [client 77.110.127.138:54993] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/if(now()=sysdate(),sleep(15),0)/2/"] [unique_id "al4mFRltgi7HBmNwzJOCaQAAAE8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:49.344575 2026] [security2:error] [pid 204156:tid 204328] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mFRbAFPhDXvzP7SnWwAAAAbk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:49.475886 2026] [security2:error] [pid 204156:tid 204384] [client 34.178.38.15:60916] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4mFRbAFPhDXvzP7SnW3QAAAfE"]
[Mon Jul 20 07:43:49.493027 2026] [security2:error] [pid 204156:tid 204397] [client 50.116.65.227:52596] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "lifeisbetterlakeside.com"] [uri "/wp-content/uploads/2023/04/IMG_3041.jpeg"] [unique_id "al4mFRbAFPhDXvzP7SnW3wAAAag"]
[Mon Jul 20 07:43:49.622299 2026] [security2:error] [pid 204156:tid 204309] [client 14.225.17.146:61885] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtredistricting.gov"] [uri "/index.php"] [unique_id "al4mFRbAFPhDXvzP7SnW4QAAAaY"]
[Mon Jul 20 07:43:49.778555 2026] [security2:error] [pid 204156:tid 204323] [client 34.178.38.15:61884] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/test/wp-includes/wlwmanifest.xml"] [unique_id "al4mFRbAFPhDXvzP7SnW7gAAAbQ"]
[Mon Jul 20 07:43:49.908723 2026] [security2:error] [pid 178071:tid 178258] [client 77.110.127.138:55054] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/mezza/page/page/3/"] [unique_id "al4mFRltgi7HBmNwzJOCewAAADc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:50.080335 2026] [security2:error] [pid 204156:tid 204393] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mFRbAFPhDXvzP7SnW8wAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:50.104264 2026] [security2:error] [pid 204156:tid 204410] [client 34.178.38.15:62997] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/site/wp-includes/wlwmanifest.xml"] [unique_id "al4mFhbAFPhDXvzP7SnXAwAAAgs"]
[Mon Jul 20 07:43:50.144199 2026] [security2:error] [pid 178071:tid 178219] [client 14.225.17.146:50602] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alaraycreative.com"] [uri "/index.php"] [unique_id "al4mFBltgi7HBmNwzJOCYgAAABA"], referer: http://alaraycreative.com/WWW
[Mon Jul 20 07:43:50.415527 2026] [security2:error] [pid 178071:tid 178316] [client 34.178.38.15:64005] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "eyv.bve.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4mFhltgi7HBmNwzJOChwAAAHE"]
[Mon Jul 20 07:43:50.474247 2026] [security2:error] [pid 204156:tid 204332] [client 14.225.17.146:50685] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lutheranphilosopher.com"] [uri "/index.php"] [unique_id "al4mFRbAFPhDXvzP7SnW0QAAAb0"], referer: http://lutheranphilosopher.com/WWW
[Mon Jul 20 07:43:50.623049 2026] [security2:error] [pid 178071:tid 178292] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mFhltgi7HBmNwzJOChgAAAFk"]
[Mon Jul 20 07:43:50.883363 2026] [security2:error] [pid 204156:tid 204358] [client 57.141.18.91:35830] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mExbAFPhDXvzP7SnWWQAB110"]
[Mon Jul 20 07:43:51.094216 2026] [security2:error] [pid 204156:tid 204335] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mFhbAFPhDXvzP7SnXLwAAAcA"]
[Mon Jul 20 07:43:51.144210 2026] [security2:error] [pid 178071:tid 178234] [client 14.225.17.146:61954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "olearyplumbingllc.com"] [uri "/index.php"] [unique_id "al4mFhltgi7HBmNwzJOCmgAAAB8"], referer: http://olearyplumbingllc.com/WWW
[Mon Jul 20 07:43:51.298702 2026] [security2:error] [pid 204156:tid 204372] [client 104.207.51.52:23261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mFxbAFPhDXvzP7SnXRwAAAeU"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:43:51.501235 2026] [security2:error] [pid 204156:tid 204380] [client 49.47.218.174:62784] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mFxbAFPhDXvzP7SnXUAAAAe0"]
[Mon Jul 20 07:43:51.501357 2026] [security2:error] [pid 204156:tid 204380] [client 49.47.218.174:62784] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mFxbAFPhDXvzP7SnXUAAAAe0"]
[Mon Jul 20 07:43:51.681500 2026] [security2:error] [pid 204156:tid 204319] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healingpwr.grndl.com"] [uri "/index.php"] [unique_id "al4mFRbAFPhDXvzP7SnWvgAAAbA"]
[Mon Jul 20 07:43:51.895739 2026] [security2:error] [pid 204156:tid 204393] [client 77.110.127.138:55068] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_medium. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 508 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mFxbAFPhDXvzP7SnXYgAAAfo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:51.927676 2026] [security2:error] [pid 178071:tid 178083] [remote 100.42.189.89:40196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4mFxltgi7HBmNwzJOCsQAAIgo"]
[Mon Jul 20 07:43:52.009605 2026] [security2:error] [pid 178071:tid 178311] [client 14.225.17.146:50564] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4mFxltgi7HBmNwzJOCqwAAAGw"], referer: http://nurturemarple.co.uk/WWW
[Mon Jul 20 07:43:52.124654 2026] [security2:error] [pid 204156:tid 204343] [client 57.141.18.121:36822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mFBbAFPhDXvzP7SnWmAAByFc"]
[Mon Jul 20 07:43:52.135500 2026] [security2:error] [pid 178071:tid 178178] [remote 100.42.189.89:40196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "gregoryanicholas.com"] [uri "/wp-login.php"] [unique_id "al4mGBltgi7HBmNwzJOCtQAAEGg"], referer: https://gregoryanicholas.com/wp-login.php
[Mon Jul 20 07:43:52.175733 2026] [security2:error] [pid 204156:tid 204352] [client 103.139.191.61:59626] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mGBbAFPhDXvzP7SnXdgAAAdE"]
[Mon Jul 20 07:43:52.175851 2026] [security2:error] [pid 204156:tid 204352] [client 103.139.191.61:59626] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mGBbAFPhDXvzP7SnXdgAAAdE"]
[Mon Jul 20 07:43:52.299102 2026] [security2:error] [pid 204156:tid 204300] [client 57.141.18.118:52388] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mFBbAFPhDXvzP7SnWoAABnQ8"]
[Mon Jul 20 07:43:52.301515 2026] [security2:error] [pid 204156:tid 204206] [remote 57.141.18.4:29306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/2783983"] [unique_id "al4mGBbAFPhDXvzP7SnXfgAB4zE"]
[Mon Jul 20 07:43:52.316739 2026] [security2:error] [pid 204156:tid 204399] [client 50.116.65.227:52652] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4mGBbAFPhDXvzP7SnXdQAAAgA"]
[Mon Jul 20 07:43:52.439919 2026] [security2:error] [pid 204156:tid 204313] [client 186.221.114.200:59914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mGBbAFPhDXvzP7SnXigAAAao"]
[Mon Jul 20 07:43:52.440086 2026] [security2:error] [pid 204156:tid 204313] [client 186.221.114.200:59914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mGBbAFPhDXvzP7SnXigAAAao"]
[Mon Jul 20 07:43:52.513439 2026] [security2:error] [pid 204156:tid 204334] [client 50.116.65.227:52662] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4mGBbAFPhDXvzP7SnXgQAAAb8"]
[Mon Jul 20 07:43:52.711878 2026] [security2:error] [pid 178071:tid 178214] [client 77.110.127.138:55070] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/2/"] [unique_id "al4mGBltgi7HBmNwzJOCwQAAAAs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:52.731332 2026] [security2:error] [pid 204156:tid 204286] [client 14.225.17.146:53722] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4mGBbAFPhDXvzP7SnXlQAAAY8"], referer: http://keywayconstructionclt.com/WWW
[Mon Jul 20 07:43:52.876124 2026] [autoindex:error] [pid 178071:tid 178244] [client 35.196.3.178:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://www.eyl.bfk.mybluehost.me
[Mon Jul 20 07:43:52.893225 2026] [security2:error] [pid 204156:tid 204306] [client 14.225.17.146:56375] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4mFxbAFPhDXvzP7SnXUgAAAaM"], referer: http://effingweirdmuseums.com/WWW
[Mon Jul 20 07:43:53.054674 2026] [security2:error] [pid 204156:tid 204337] [client 14.225.17.146:53854] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nurturemarple.co.uk"] [uri "/index.php"] [unique_id "al4mGBbAFPhDXvzP7SnXpwAAAcI"], referer: https://nurturemarple.co.uk/WWW
[Mon Jul 20 07:43:53.341046 2026] [security2:error] [pid 178071:tid 178319] [client 57.141.18.23:52556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mFRltgi7HBmNwzJOCcQAAdD4"]
[Mon Jul 20 07:43:53.406462 2026] [security2:error] [pid 178071:tid 178209] [client 77.110.127.138:55072] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/mezza/page/page/3/"] [unique_id "al4mGRltgi7HBmNwzJOC2wAAAAY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:53.577911 2026] [security2:error] [pid 204156:tid 204175] [remote 81.173.115.7:42474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4mGRbAFPhDXvzP7SnXwQAB2RI"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:43:53.675369 2026] [security2:error] [pid 204156:tid 204298] [client 14.225.17.146:50795] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.keywayconstructionclt.com"] [uri "/index.php"] [unique_id "al4mGRbAFPhDXvzP7SnXwwAAAZs"], referer: https://keywayconstructionclt.com/WWW
[Mon Jul 20 07:43:53.836296 2026] [security2:error] [pid 204156:tid 204204] [remote 81.173.115.7:42474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.savilerowtravel.com"] [uri "/wp-login.php"] [unique_id "al4mGRbAFPhDXvzP7SnX0QABlC8"], referer: https://savilerowtravel.co.uk/wp-login.php
[Mon Jul 20 07:43:53.877503 2026] [security2:error] [pid 204156:tid 204353] [client 14.225.17.146:53542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.effingweirdmuseums.com"] [uri "/index.php"] [unique_id "al4mGRbAFPhDXvzP7SnXzwAAAdI"], referer: https://effingweirdmuseums.com/WWW
[Mon Jul 20 07:43:53.976084 2026] [security2:error] [pid 204156:tid 204354] [client 57.141.18.50:39730] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mFhbAFPhDXvzP7SnXBAAB03s"]
[Mon Jul 20 07:43:54.033389 2026] [security2:error] [pid 178071:tid 178207] [client 57.141.18.57:56432] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mFhltgi7HBmNwzJOCfgAABFo"]
[Mon Jul 20 07:43:54.531524 2026] [security2:error] [pid 178071:tid 178304] [client 14.225.17.146:53809] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tacticaltreeoperations.com"] [uri "/index.php"] [unique_id "al4mGBltgi7HBmNwzJOCwwAAAGU"], referer: http://tacticaltreeoperations.com/WWW
[Mon Jul 20 07:43:54.610627 2026] [security2:error] [pid 178071:tid 178326] [client 36.93.152.155:50910] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mGhltgi7HBmNwzJODAwAAAHs"]
[Mon Jul 20 07:43:54.610789 2026] [security2:error] [pid 178071:tid 178326] [client 36.93.152.155:50910] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mGhltgi7HBmNwzJODAwAAAHs"]
[Mon Jul 20 07:43:54.712837 2026] [security2:error] [pid 204156:tid 204388] [client 103.106.165.44:60272] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mGhbAFPhDXvzP7SnX_wAAAfU"]
[Mon Jul 20 07:43:54.712961 2026] [security2:error] [pid 204156:tid 204388] [client 103.106.165.44:60272] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mGhbAFPhDXvzP7SnX_wAAAfU"]
[Mon Jul 20 07:43:54.779843 2026] [security2:error] [pid 204156:tid 204394] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mGhbAFPhDXvzP7SnX-wAAAfs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:55.092568 2026] [security2:error] [pid 204156:tid 204283] [remote 185.177.72.100:48988] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5cconfig%5csendgrid.php"] [unique_id "al4mGxbAFPhDXvzP7SnYDwABs34"]
[Mon Jul 20 07:43:55.225999 2026] [security2:error] [pid 204156:tid 204191] [remote 124.55.178.99:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4mGxbAFPhDXvzP7SnYGgACCCI"]
[Mon Jul 20 07:43:55.459397 2026] [security2:error] [pid 204156:tid 204260] [remote 72.167.132.114:58302] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "hammadownenterprises.com"] [uri "/wp-login.php"] [unique_id "al4mGxbAFPhDXvzP7SnYJgAB9mc"], referer: https://efd.8ae.myftpupload.com/wp-login.php
[Mon Jul 20 07:43:55.519395 2026] [security2:error] [pid 204156:tid 204327] [client 180.249.173.210:57673] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mGxbAFPhDXvzP7SnYKgAAAbg"]
[Mon Jul 20 07:43:55.519535 2026] [security2:error] [pid 204156:tid 204327] [client 180.249.173.210:57673] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mGxbAFPhDXvzP7SnYKgAAAbg"]
[Mon Jul 20 07:43:55.624114 2026] [security2:error] [pid 204156:tid 204309] [client 136.158.60.21:55419] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mGxbAFPhDXvzP7SnYNAAAAaY"]
[Mon Jul 20 07:43:55.624262 2026] [security2:error] [pid 204156:tid 204309] [client 136.158.60.21:55419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mGxbAFPhDXvzP7SnYNAAAAaY"]
[Mon Jul 20 07:43:55.645526 2026] [security2:error] [pid 204156:tid 204238] [remote 124.55.178.99:53336] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.178.55.124.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "secoaches.co"] [uri "/wp-login.php"] [unique_id "al4mGxbAFPhDXvzP7SnYNQABx1E"], referer: https://secoaches.co/wp-login.php
[Mon Jul 20 07:43:55.789380 2026] [security2:error] [pid 204156:tid 204361] [client 65.111.22.193:65189] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 193.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mGxbAFPhDXvzP7SnYPgAAAdo"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:43:55.807590 2026] [security2:error] [pid 178071:tid 178299] [client 57.141.18.9:53696] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mFxltgi7HBmNwzJOCsAAAYCU"]
[Mon Jul 20 07:43:55.901862 2026] [security2:error] [pid 204156:tid 204382] [client 39.46.9.231:62993] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mGxbAFPhDXvzP7SnYRQAAAe8"]
[Mon Jul 20 07:43:55.902036 2026] [security2:error] [pid 204156:tid 204382] [client 39.46.9.231:62993] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mGxbAFPhDXvzP7SnYRQAAAe8"]
[Mon Jul 20 07:43:55.958243 2026] [security2:error] [pid 204156:tid 204271] [remote 185.177.72.100:48996] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5cconfig%5csendgrid.php"] [unique_id "al4mGxbAFPhDXvzP7SnYSAACCnI"]
[Mon Jul 20 07:43:56.397018 2026] [security2:error] [pid 204156:tid 204302] [client 77.110.127.138:55091] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_medium. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 644 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mHBbAFPhDXvzP7SnYZQAAAZ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:56.461258 2026] [security2:error] [pid 178071:tid 178141] [remote 188.166.241.141:38290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mHBltgi7HBmNwzJODLgAABEQ"]
[Mon Jul 20 07:43:56.752304 2026] [security2:error] [pid 204156:tid 204332] [client 77.110.127.138:55096] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/2/"] [unique_id "al4mHBbAFPhDXvzP7SnYegAAAb0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:56.769435 2026] [security2:error] [pid 178071:tid 178276] [client 57.141.18.115:25528] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGBltgi7HBmNwzJOCwgAASQU"]
[Mon Jul 20 07:43:56.771646 2026] [security2:error] [pid 204156:tid 204185] [remote 185.177.72.100:48998] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fconfig/sendgrid.php"] [unique_id "al4mHBbAFPhDXvzP7SnYewAB2hw"]
[Mon Jul 20 07:43:56.855742 2026] [security2:error] [pid 178071:tid 178195] [remote 188.166.241.141:38290] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mHBltgi7HBmNwzJODOQAAWXk"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:43:56.901858 2026] [security2:error] [pid 204156:tid 204316] [client 57.141.18.23:59518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGBbAFPhDXvzP7SnXrAABrRg"]
[Mon Jul 20 07:43:57.116336 2026] [security2:error] [pid 204156:tid 204396] [client 56.125.35.21:25422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.35.125.56.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mHRbAFPhDXvzP7SnYkwAAAf0"]
[Mon Jul 20 07:43:57.116416 2026] [security2:error] [pid 204156:tid 204396] [client 56.125.35.21:25422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mHRbAFPhDXvzP7SnYkwAAAf0"]
[Mon Jul 20 07:43:57.131817 2026] [security2:error] [pid 178071:tid 178290] [client 102.209.222.240:19135] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4mHRltgi7HBmNwzJODPgAAAFc"]
[Mon Jul 20 07:43:57.338104 2026] [core:error] [pid 204156:tid 204321] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:57.338127 2026] [core:error] [pid 204156:tid 204321] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:43:57.503250 2026] [security2:error] [pid 178071:tid 178102] [remote 57.141.18.18:58582] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mHRltgi7HBmNwzJODSwAAbR0"]
[Mon Jul 20 07:43:57.581665 2026] [security2:error] [pid 204156:tid 204342] [client 37.52.210.45:56080] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mHRbAFPhDXvzP7SnYtgAAAcc"]
[Mon Jul 20 07:43:57.581763 2026] [security2:error] [pid 204156:tid 204342] [client 37.52.210.45:56080] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mHRbAFPhDXvzP7SnYtgAAAcc"]
[Mon Jul 20 07:43:57.582295 2026] [security2:error] [pid 204156:tid 204172] [remote 185.177.72.100:49006] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fconfig%252fsendgrid.php"] [unique_id "al4mHRbAFPhDXvzP7SnYtwABuw8"]
[Mon Jul 20 07:43:57.609130 2026] [security2:error] [pid 204156:tid 204364] [client 57.141.18.98:32220] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGRbAFPhDXvzP7SnXzgAB3X8"]
[Mon Jul 20 07:43:57.761185 2026] [security2:error] [pid 178071:tid 178325] [client 57.141.18.27:23554] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGRltgi7HBmNwzJOC8AAAejI"]
[Mon Jul 20 07:43:57.892726 2026] [security2:error] [pid 204156:tid 204328] [client 155.2.215.77:49959] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mHRbAFPhDXvzP7SnYwwAAAbk"]
[Mon Jul 20 07:43:58.123736 2026] [security2:error] [pid 178071:tid 178314] [client 50.116.65.227:52736] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mHhltgi7HBmNwzJODYAAAAG8"]
[Mon Jul 20 07:43:58.133847 2026] [security2:error] [pid 178071:tid 178223] [client 50.116.65.227:52748] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mHhltgi7HBmNwzJODYgAAABQ"]
[Mon Jul 20 07:43:58.149624 2026] [security2:error] [pid 204156:tid 204341] [client 116.179.32.206:13263] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.vfcthomasville.org"] [uri "/index.php"] [unique_id "al4mHhbAFPhDXvzP7SnY1QABxlY"]
[Mon Jul 20 07:43:58.196612 2026] [security2:error] [pid 204156:tid 204325] [client 154.192.233.184:60740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mHhbAFPhDXvzP7SnY2gAAAbY"]
[Mon Jul 20 07:43:58.197116 2026] [security2:error] [pid 204156:tid 204325] [client 154.192.233.184:60740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mHhbAFPhDXvzP7SnY2gAAAbY"]
[Mon Jul 20 07:43:58.207283 2026] [security2:error] [pid 178071:tid 178213] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mHRltgi7HBmNwzJODWAAAAAo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:58.271318 2026] [security2:error] [pid 204156:tid 204346] [client 149.0.16.108:57474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mHhbAFPhDXvzP7SnY2wAAAcs"]
[Mon Jul 20 07:43:58.271974 2026] [security2:error] [pid 204156:tid 204346] [client 149.0.16.108:57474] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mHhbAFPhDXvzP7SnY2wAAAcs"]
[Mon Jul 20 07:43:58.416487 2026] [security2:error] [pid 178071:tid 178203] [client 114.119.156.3:64471] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lifeisbetterlakeside.com"] [uri "/mickey-and-minnie-celebrate-thanksgiving-with-tom-their-turkey-friend"] [unique_id "al4mHhltgi7HBmNwzJODeQAAAAA"], referer: https://karinskottage.com/2023/10/happy-halloween-linky-party.html
[Mon Jul 20 07:43:58.488150 2026] [security2:error] [pid 178071:tid 178305] [client 51.89.129.213:37492] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "mts.cr"] [uri "/robots.txt"] [unique_id "al4mHhltgi7HBmNwzJODfQAAAGY"]
[Mon Jul 20 07:43:58.488237 2026] [security2:error] [pid 178071:tid 178305] [client 51.89.129.213:37492] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mts.cr"] [uri "/robots.txt"] [unique_id "al4mHhltgi7HBmNwzJODfQAAAGY"]
[Mon Jul 20 07:43:58.532214 2026] [security2:error] [pid 178071:tid 178320] [client 57.141.18.5:29144] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGhltgi7HBmNwzJODCgAAdTc"]
[Mon Jul 20 07:43:58.616163 2026] [authz_core:error] [pid 204156:tid 204304] [client 168.144.19.97:58387] AH01630: client denied by server configuration: /home1/polishe5/public_html/wp-includes/error_log, referer: binance.com
[Mon Jul 20 07:43:59.163103 2026] [security2:error] [pid 204156:tid 204157] [remote 57.141.18.89:48542] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGxbAFPhDXvzP7SnYHQAB0QA"]
[Mon Jul 20 07:43:59.316208 2026] [security2:error] [pid 178071:tid 178297] [client 14.225.17.146:50506] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mazzucelli.com"] [uri "/index.php"] [unique_id "al4mHhltgi7HBmNwzJODWQAAAF4"], referer: http://mazzucelli.com/WWW
[Mon Jul 20 07:43:59.364684 2026] [security2:error] [pid 178071:tid 178198] [remote 57.141.18.21:46440] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mHxltgi7HBmNwzJODwAAAOHw"]
[Mon Jul 20 07:43:59.412542 2026] [security2:error] [pid 204156:tid 204386] [client 14.225.17.146:53002] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "alexsandbergmusic.com"] [uri "/index.php"] [unique_id "al4mHRbAFPhDXvzP7SnYzgAAAfM"], referer: http://alexsandbergmusic.com/WWW
[Mon Jul 20 07:43:59.414879 2026] [security2:error] [pid 204156:tid 204326] [client 14.225.17.146:50627] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nikkidesigns.net"] [uri "/index.php"] [unique_id "al4mHhbAFPhDXvzP7SnY3AAAAbc"], referer: http://nikkidesigns.net/WWW
[Mon Jul 20 07:43:59.537115 2026] [security2:error] [pid 178071:tid 178263] [client 179.127.84.238:62469] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mHxltgi7HBmNwzJODzQAAADw"]
[Mon Jul 20 07:43:59.537245 2026] [security2:error] [pid 178071:tid 178263] [client 179.127.84.238:62469] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mHxltgi7HBmNwzJODzQAAADw"]
[Mon Jul 20 07:43:59.544306 2026] [security2:error] [pid 204156:tid 204189] [remote 57.141.18.63:53572] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mGxbAFPhDXvzP7SnYQAAB0iA"]
[Mon Jul 20 07:43:59.758113 2026] [security2:error] [pid 178071:tid 178223] [client 77.110.127.138:55111] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_medium. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 964 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mHxltgi7HBmNwzJOD4AAAABQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:43:59.776769 2026] [security2:error] [pid 204156:tid 204218] [remote 57.141.18.57:31778] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mHBbAFPhDXvzP7SnYUQACCD0"]
[Mon Jul 20 07:43:59.816443 2026] [security2:error] [pid 178071:tid 178254] [client 14.225.17.146:50502] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "ccsdifference.com"] [uri "/index.php"] [unique_id "al4mHhltgi7HBmNwzJODWwAAADM"], referer: http://ccsdifference.com/WWW
[Mon Jul 20 07:43:59.885107 2026] [security2:error] [pid 178071:tid 178245] [client 54.39.210.173:56248] ModSecurity: Access denied with code 406 (phase 1). Pattern match "Mozilla\\\\/5\\\\.0 \\\\(compatible; AhrefsBot\\\\/\\\\d\\\\.\\\\d; \\\\+http:\\\\/\\\\/ahrefs\\\\.com\\\\/robot\\\\/\\\\)" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "578"] [id "900165"] [msg "AhrefsBot BOT Request"] [hostname "mts.cr"] [uri "/"] [unique_id "al4mHxltgi7HBmNwzJOD6AAAACo"]
[Mon Jul 20 07:43:59.885212 2026] [security2:error] [pid 178071:tid 178245] [client 54.39.210.173:56248] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "mts.cr"] [uri "/"] [unique_id "al4mHxltgi7HBmNwzJOD6AAAACo"]
[Mon Jul 20 07:44:00.424989 2026] [http2:info] [pid 229701:tid 229701] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:44:00.549660 2026] [core:error] [pid 229701:tid 229899] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:00.549695 2026] [core:error] [pid 229701:tid 229899] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:00.716056 2026] [security2:error] [pid 229701:tid 229833] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mIHZMWbdeOcTm4EwXWwAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:00.751235 2026] [core:error] [pid 229701:tid 229941] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:00.751254 2026] [core:error] [pid 229701:tid 229941] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:00.770524 2026] [core:error] [pid 229701:tid 229954] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:00.770547 2026] [core:error] [pid 229701:tid 229954] [client 185.147.157.153:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:00.906799 2026] [security2:error] [pid 229701:tid 229859] [client 14.225.17.146:51120] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.ccsdifference.com"] [uri "/index.php"] [unique_id "al4mIHZMWbdeOcTm4EwXmAAAAKE"], referer: https://ccsdifference.com/WWW
[Mon Jul 20 07:44:01.012743 2026] [security2:error] [pid 229701:tid 229871] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "elreydelcalentadorca.com"] [uri "/wp-admin/install.php"] [unique_id "al4mIXZMWbdeOcTm4EwXvgAAAK0"]
[Mon Jul 20 07:44:01.139039 2026] [security2:error] [pid 229701:tid 229946] [client 74.7.228.32:55232] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4mIHZMWbdeOcTm4EwXrQAA-Bo"]
[Mon Jul 20 07:44:01.389774 2026] [security2:error] [pid 229701:tid 229917] [client 14.225.17.146:54399] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "thefriendlyspreadsheet.com"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwX1wAAANs"], referer: http://thefriendlyspreadsheet.com/WWW
[Mon Jul 20 07:44:01.410795 2026] [security2:error] [pid 229701:tid 229933] [client 154.27.104.38:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwXyAAAAOs"]
[Mon Jul 20 07:44:01.519858 2026] [security2:error] [pid 229701:tid 229753] [remote 20.153.140.50:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mIXZMWbdeOcTm4EwX9wAAtjM"]
[Mon Jul 20 07:44:01.530184 2026] [security2:error] [pid 229701:tid 229855] [client 14.225.17.146:54373] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "longevityperformanceclinic.com"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwX2QAAAJ0"], referer: http://longevityperformanceclinic.com/WWW
[Mon Jul 20 07:44:01.579630 2026] [security2:error] [pid 204156:tid 204232] [remote 57.141.18.95:38122] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mHRbAFPhDXvzP7SnYzAABl0s"]
[Mon Jul 20 07:44:01.641368 2026] [security2:error] [pid 229701:tid 229881] [client 2a06:98c0:3600::103:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ylg.kng.mybluehost.me"] [uri "/wp-admin/install.php"] [unique_id "al4mIXZMWbdeOcTm4EwX_wAAtzc"]
[Mon Jul 20 07:44:01.647491 2026] [security2:error] [pid 229701:tid 229892] [client 14.225.17.146:54374] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mcg.homes"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwX2AAAAMI"], referer: http://mcg.homes/WWW
[Mon Jul 20 07:44:01.816711 2026] [security2:error] [pid 229701:tid 229763] [remote 72.167.132.114:58312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4mIXZMWbdeOcTm4EwYDQAAkT0"]
[Mon Jul 20 07:44:01.928056 2026] [security2:error] [pid 229701:tid 229767] [remote 20.153.140.50:39936] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 50.140.153.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mIXZMWbdeOcTm4EwYFwAAmkE"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:44:01.957955 2026] [security2:error] [pid 229701:tid 229850] [client 49.47.218.174:63329] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mIXZMWbdeOcTm4EwYGwAAAJg"]
[Mon Jul 20 07:44:01.958106 2026] [security2:error] [pid 229701:tid 229850] [client 49.47.218.174:63329] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mIXZMWbdeOcTm4EwYGwAAAJg"]
[Mon Jul 20 07:44:01.964248 2026] [security2:error] [pid 229701:tid 229884] [client 14.225.17.146:51228] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elitetax-mi.com"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwYEAAAALo"], referer: http://elitetax-mi.com/WWW
[Mon Jul 20 07:44:02.045273 2026] [security2:error] [pid 229701:tid 229874] [client 14.225.17.146:54818] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwYBAAAALA"], referer: http://healthylifegourmet.org/WWW
[Mon Jul 20 07:44:02.083908 2026] [security2:error] [pid 229701:tid 229772] [remote 72.167.132.114:58312] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/wp-login.php"] [unique_id "al4mInZMWbdeOcTm4EwYIgAAjkY"], referer: https://outlookturf.com/wp-login.php
[Mon Jul 20 07:44:02.246794 2026] [security2:error] [pid 229701:tid 229778] [remote 57.141.18.60:44136] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mInZMWbdeOcTm4EwYMgAAlEw"]
[Mon Jul 20 07:44:02.477818 2026] [security2:error] [pid 178071:tid 178081] [remote 57.141.18.63:53580] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mHhltgi7HBmNwzJODhgAAKwg"]
[Mon Jul 20 07:44:02.515913 2026] [security2:error] [pid 229701:tid 229865] [client 14.225.17.146:51244] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "vinovinhowine.com"] [uri "/index.php"] [unique_id "al4mInZMWbdeOcTm4EwYOQAAAKc"], referer: http://vinovinhowine.com/WWW
[Mon Jul 20 07:44:03.010941 2026] [security2:error] [pid 229701:tid 229897] [client 85.208.96.211:39410] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "sustaintheart.com"] [uri "/why-watercolor-painting-is-difficult/"] [unique_id "al4mI3ZMWbdeOcTm4EwYeAAAAMc"]
[Mon Jul 20 07:44:03.011127 2026] [security2:error] [pid 229701:tid 229897] [client 85.208.96.211:39410] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "sustaintheart.com"] [uri "/why-watercolor-painting-is-difficult/"] [unique_id "al4mI3ZMWbdeOcTm4EwYeAAAAMc"]
[Mon Jul 20 07:44:03.155455 2026] [security2:error] [pid 229701:tid 229925] [client 103.139.191.61:60143] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYhgAAAOM"]
[Mon Jul 20 07:44:03.155578 2026] [security2:error] [pid 229701:tid 229925] [client 103.139.191.61:60143] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYhgAAAOM"]
[Mon Jul 20 07:44:03.234485 2026] [security2:error] [pid 229701:tid 229956] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYegAAAQI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:03.238084 2026] [security2:error] [pid 229701:tid 229813] [remote 165.73.0.178:44630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.0.73.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYjQAA8G8"]
[Mon Jul 20 07:44:03.323336 2026] [security2:error] [pid 229701:tid 229929] [client 186.221.114.200:60390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYlQAAAOc"]
[Mon Jul 20 07:44:03.323495 2026] [security2:error] [pid 229701:tid 229929] [client 186.221.114.200:60390] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYlQAAAOc"]
[Mon Jul 20 07:44:03.409656 2026] [security2:error] [pid 229701:tid 229819] [remote 57.141.18.4:62198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 4.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mI3ZMWbdeOcTm4EwYngAAi3U"]
[Mon Jul 20 07:44:03.420902 2026] [authz_core:error] [pid 229701:tid 229948] [client 168.144.19.97:64576] AH01630: client denied by server configuration: /home1/polishe5/public_html/wp-includes/error_log, referer: binance.com
[Mon Jul 20 07:44:03.709887 2026] [security2:error] [pid 229701:tid 229863] [client 85.208.96.200:0] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lakelopezonline.com"] [uri "/wp-admin/admin/dibujos-de-caballos/male-cat-fuck-women.html"] [unique_id "al4mI3ZMWbdeOcTm4EwYuwAAAKU"]
[Mon Jul 20 07:44:03.709996 2026] [security2:error] [pid 229701:tid 229863] [client 85.208.96.200:0] ModSecurity: Warning. Matched phrase "Semrush" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lakelopezonline.com"] [uri "/wp-admin/admin/dibujos-de-caballos/male-cat-fuck-women.html"] [unique_id "al4mI3ZMWbdeOcTm4EwYuwAAAKU"]
[Mon Jul 20 07:44:03.749209 2026] [security2:error] [pid 229701:tid 229714] [remote 165.73.0.178:44630] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 178.0.73.165.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "christiancountytrumpet.com"] [uri "/wp-login.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYwAABAAw"], referer: https://christiancountytrumpet.com/wp-login.php
[Mon Jul 20 07:44:03.903277 2026] [security2:error] [pid 229701:tid 229720] [remote 103.118.29.185:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYzAAA0xI"]
[Mon Jul 20 07:44:03.978967 2026] [security2:error] [pid 229701:tid 229922] [client 14.225.17.146:54585] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adirondackengineering.com"] [uri "/index.php"] [unique_id "al4mI3ZMWbdeOcTm4EwYwwAAAOA"], referer: https://north-woods-engineering.com/WWW
[Mon Jul 20 07:44:04.290578 2026] [security2:error] [pid 229701:tid 229929] [client 14.225.17.146:51015] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sarahsnyder.net"] [uri "/index.php"] [unique_id "al4mJHZMWbdeOcTm4EwY3gAAAOc"], referer: http://sarahsnyder.net/WWW
[Mon Jul 20 07:44:04.345485 2026] [security2:error] [pid 229701:tid 229726] [remote 103.118.29.185:27556] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "viennarotaryfoundation.org"] [uri "/wp-login.php"] [unique_id "al4mJHZMWbdeOcTm4EwY7QAAxRg"], referer: https://viennarotaryfoundation.org/wp-login.php
[Mon Jul 20 07:44:04.363312 2026] [security2:error] [pid 229701:tid 229845] [client 57.141.18.116:49782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mIHZMWbdeOcTm4EwXYwAAkwM"]
[Mon Jul 20 07:44:04.378367 2026] [security2:error] [pid 229701:tid 229730] [remote 57.141.18.18:61642] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 18.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mJHZMWbdeOcTm4EwY7gAAsRw"]
[Mon Jul 20 07:44:04.426734 2026] [security2:error] [pid 229701:tid 229732] [remote 57.141.18.122:22178] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mJHZMWbdeOcTm4EwY8wAApB4"]
[Mon Jul 20 07:44:04.707710 2026] [security2:error] [pid 229701:tid 229747] [remote 57.141.18.120:27060] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mJHZMWbdeOcTm4EwZBAAA_y0"]
[Mon Jul 20 07:44:04.729745 2026] [security2:error] [pid 229701:tid 229950] [client 57.141.18.24:21298] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mIHZMWbdeOcTm4EwXqgAA_Bk"]
[Mon Jul 20 07:44:04.925105 2026] [security2:error] [pid 229701:tid 229853] [client 57.141.18.8:26774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwXvwAAmx8"]
[Mon Jul 20 07:44:05.158136 2026] [security2:error] [pid 229701:tid 229897] [client 36.93.152.155:51425] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mJXZMWbdeOcTm4EwZPQAAAMc"]
[Mon Jul 20 07:44:05.158294 2026] [security2:error] [pid 229701:tid 229897] [client 36.93.152.155:51425] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mJXZMWbdeOcTm4EwZPQAAAMc"]
[Mon Jul 20 07:44:05.233156 2026] [security2:error] [pid 229701:tid 229886] [client 103.106.165.44:60757] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mJXZMWbdeOcTm4EwZQAAAALw"]
[Mon Jul 20 07:44:05.233295 2026] [security2:error] [pid 229701:tid 229886] [client 103.106.165.44:60757] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mJXZMWbdeOcTm4EwZQAAAALw"]
[Mon Jul 20 07:44:05.259431 2026] [security2:error] [pid 229701:tid 229840] [client 14.225.17.146:53582] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sarahsnyder.net"] [uri "/index.php"] [unique_id "al4mJXZMWbdeOcTm4EwZNgAAAI4"], referer: https://sarahsnyder.net/WWW
[Mon Jul 20 07:44:05.742264 2026] [security2:error] [pid 229701:tid 229931] [client 57.141.18.106:44838] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwYBgAA6Tk"]
[Mon Jul 20 07:44:05.751735 2026] [security2:error] [pid 229701:tid 229935] [client 77.110.127.138:55146] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:utm_medium. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:utm_medium"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mJXZMWbdeOcTm4EwZaAAAAO0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:05.808051 2026] [security2:error] [pid 229701:tid 229946] [client 57.141.18.102:45774] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mIXZMWbdeOcTm4EwYCwAA-Dw"]
[Mon Jul 20 07:44:06.148731 2026] [security2:error] [pid 229701:tid 229857] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mJXZMWbdeOcTm4EwZfAAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:06.184642 2026] [security2:error] [pid 229701:tid 229881] [client 57.141.18.118:36384] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mInZMWbdeOcTm4EwYMQAAt0s"]
[Mon Jul 20 07:44:06.192019 2026] [security2:error] [pid 229701:tid 229835] [client 185.238.231.220:26653] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.231.238.185.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwZlAAAAIk"]
[Mon Jul 20 07:44:06.199637 2026] [security2:error] [pid 229701:tid 229910] [client 155.2.212.13:54053] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 13.212.2.155.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nikkidesigns.net"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwZkgAAANQ"]
[Mon Jul 20 07:44:06.204694 2026] [security2:error] [pid 229701:tid 229912] [client 104.207.37.67:15439] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwZkwAAANY"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:06.238838 2026] [security2:error] [pid 229701:tid 229890] [client 57.141.18.14:61732] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mInZMWbdeOcTm4EwYNAAAwE4"]
[Mon Jul 20 07:44:06.371057 2026] [security2:error] [pid 229701:tid 229887] [client 136.158.60.21:57619] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwZqgAAAL0"]
[Mon Jul 20 07:44:06.371189 2026] [security2:error] [pid 229701:tid 229887] [client 136.158.60.21:57619] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwZqgAAAL0"]
[Mon Jul 20 07:44:06.411140 2026] [fcgid:warn] [pid 229701:tid 229871] (70014)End of file found: [client 212.56.53.166:39852] mod_fcgid: can't get data from http client
[Mon Jul 20 07:44:06.511161 2026] [proxy:error] [pid 229701:tid 229863] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:06.511217 2026] [proxy_http:error] [pid 229701:tid 229863] [client 104.155.181.6:42462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:06.511792 2026] [proxy:error] [pid 229701:tid 229863] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:06.511820 2026] [proxy_http:error] [pid 229701:tid 229863] [client 104.155.181.6:42462] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:06.612259 2026] [security2:error] [pid 229701:tid 229939] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwZqwAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:06.650797 2026] [security2:error] [pid 229701:tid 229857] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ1gAAAJ8"]
[Mon Jul 20 07:44:06.663068 2026] [security2:error] [pid 229701:tid 229925] [client 180.249.173.210:58187] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ-gAAAOM"]
[Mon Jul 20 07:44:06.663143 2026] [security2:error] [pid 229701:tid 229873] [client 39.46.9.231:63407] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ-wAAAK8"]
[Mon Jul 20 07:44:06.663292 2026] [security2:error] [pid 229701:tid 229873] [client 39.46.9.231:63407] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ-wAAAK8"]
[Mon Jul 20 07:44:06.663802 2026] [security2:error] [pid 229701:tid 229925] [client 180.249.173.210:58187] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ-gAAAOM"]
[Mon Jul 20 07:44:06.714452 2026] [security2:error] [pid 229701:tid 229705] [remote 173.212.252.15:60218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwaCwAAmwM"]
[Mon Jul 20 07:44:06.714654 2026] [security2:error] [pid 229701:tid 229853] [client 173.212.252.15:60218] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mJnZMWbdeOcTm4EwaCwAAmwM"]
[Mon Jul 20 07:44:06.730136 2026] [security2:error] [pid 229701:tid 229704] [remote 194.164.192.228:47558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwaCgAAyAI"]
[Mon Jul 20 07:44:06.730694 2026] [security2:error] [pid 229701:tid 229920] [client 45.3.39.249:50097] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 249.39.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwaCQAAAN4"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:06.731464 2026] [security2:error] [pid 229701:tid 229851] [client 65.111.23.224:11843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 224.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwaAwAAAJk"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:44:06.733293 2026] [security2:error] [pid 229701:tid 229883] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ6wAAALk"]
[Mon Jul 20 07:44:06.768704 2026] [security2:error] [pid 229701:tid 229953] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ7wAAAP8"]
[Mon Jul 20 07:44:06.777252 2026] [security2:error] [pid 229701:tid 229937] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ9AAAAO8"]
[Mon Jul 20 07:44:06.786461 2026] [security2:error] [pid 229701:tid 229860] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwZ8AAAAKI"]
[Mon Jul 20 07:44:06.805668 2026] [security2:error] [pid 229701:tid 229921] [client 168.144.19.97:51816] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/abilities-api.php"] [unique_id "al4mJnZMWbdeOcTm4EwaIQAAAN8"], referer: binance.com
[Mon Jul 20 07:44:06.852033 2026] [security2:error] [pid 229701:tid 229838] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaDAAAAIw"]
[Mon Jul 20 07:44:06.859320 2026] [security2:error] [pid 229701:tid 229903] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaDwAAAM0"]
[Mon Jul 20 07:44:06.863311 2026] [security2:error] [pid 229701:tid 229880] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaDQAAALY"]
[Mon Jul 20 07:44:06.884940 2026] [security2:error] [pid 229701:tid 229950] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaEAAAAPw"]
[Mon Jul 20 07:44:06.916333 2026] [security2:error] [pid 229701:tid 229724] [remote 194.164.192.228:47558] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 228.192.164.194.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4mJnZMWbdeOcTm4EwaLwAAvRY"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:44:06.926387 2026] [security2:error] [pid 229701:tid 229928] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaIwAAAOY"]
[Mon Jul 20 07:44:06.929187 2026] [security2:error] [pid 229701:tid 229857] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaJQAAAJ8"]
[Mon Jul 20 07:44:06.946962 2026] [security2:error] [pid 229701:tid 229832] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaJAAAAIY"]
[Mon Jul 20 07:44:06.962716 2026] [security2:error] [pid 229701:tid 229852] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaJgAAAJo"]
[Mon Jul 20 07:44:07.127859 2026] [security2:error] [pid 229701:tid 229849] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaNAAAAJc"]
[Mon Jul 20 07:44:07.128092 2026] [security2:error] [pid 229701:tid 229861] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaNQAAAKM"]
[Mon Jul 20 07:44:07.171481 2026] [security2:error] [pid 229701:tid 229733] [remote 57.141.18.115:27066] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 115.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3206812"] [unique_id "al4mJ3ZMWbdeOcTm4EwadwAAix8"]
[Mon Jul 20 07:44:07.191908 2026] [security2:error] [pid 229701:tid 229944] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaOAAAAPY"]
[Mon Jul 20 07:44:07.247537 2026] [security2:error] [pid 229701:tid 229906] [client 45.3.34.220:54043] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 220.34.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwakwAAANA"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:07.249920 2026] [security2:error] [pid 229701:tid 229948] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwaRQAAAPo"]
[Mon Jul 20 07:44:07.253427 2026] [security2:error] [pid 229701:tid 229882] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJnZMWbdeOcTm4EwaRAAAALg"]
[Mon Jul 20 07:44:07.300311 2026] [security2:error] [pid 229701:tid 229911] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwacgAAANU"]
[Mon Jul 20 07:44:07.305383 2026] [security2:error] [pid 229701:tid 229939] [client 57.141.18.91:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwaXAAAAPE"]
[Mon Jul 20 07:44:07.333451 2026] [security2:error] [pid 229701:tid 229854] [client 14.225.17.146:54935] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "inspirespublishing.com"] [uri "/index.php"] [unique_id "al4mJXZMWbdeOcTm4EwZagAAAJw"], referer: http://inspirespublishing.com/WWW
[Mon Jul 20 07:44:07.397792 2026] [security2:error] [pid 229701:tid 229895] [client 14.225.17.146:55017] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ncsynchro.com"] [uri "/index.php"] [unique_id "al4mJXZMWbdeOcTm4EwZdAAAAMU"], referer: http://ncsynchro.com/WWW
[Mon Jul 20 07:44:07.420535 2026] [fcgid:warn] [pid 229701:tid 229882] (70014)End of file found: [client 212.56.53.166:31401] mod_fcgid: can't get data from http client
[Mon Jul 20 07:44:07.438506 2026] [http2:info] [pid 230396:tid 230396] h2_workers: created with min=128 max=192 idle_ms=600000
[Mon Jul 20 07:44:07.567433 2026] [security2:error] [pid 229701:tid 229836] [client 15.229.69.106:18840] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwavQAAAIo"]
[Mon Jul 20 07:44:07.567545 2026] [security2:error] [pid 229701:tid 229836] [client 15.229.69.106:18840] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwavQAAAIo"]
[Mon Jul 20 07:44:07.802178 2026] [security2:error] [pid 229701:tid 229882] [client 65.111.2.57:57281] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 57.2.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mJ3ZMWbdeOcTm4Ewa0gAAALg"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:08.008321 2026] [security2:error] [pid 230396:tid 230550] [client 168.144.19.97:53007] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/abilities.php"] [unique_id "al4mKHjLAau4tRDXyg8_gwAAASE"], referer: binance.com
[Mon Jul 20 07:44:08.171421 2026] [security2:error] [pid 229701:tid 229894] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwafQAAAMQ"]
[Mon Jul 20 07:44:08.204308 2026] [security2:error] [pid 229701:tid 229951] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwaiwAAAP0"]
[Mon Jul 20 07:44:08.229349 2026] [security2:error] [pid 229701:tid 229870] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwaeQAAAKw"]
[Mon Jul 20 07:44:08.252683 2026] [security2:error] [pid 229701:tid 229922] [client 37.52.210.45:1705] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mKHZMWbdeOcTm4Ewa7wAAAOA"]
[Mon Jul 20 07:44:08.252849 2026] [security2:error] [pid 229701:tid 229922] [client 37.52.210.45:1705] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mKHZMWbdeOcTm4Ewa7wAAAOA"]
[Mon Jul 20 07:44:08.356285 2026] [security2:error] [pid 229701:tid 229865] [client 104.207.49.70:17165] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 70.49.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mKHZMWbdeOcTm4Ewa8gAAAKc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:08.478240 2026] [security2:error] [pid 230396:tid 230565] [client 142.111.152.181:32737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mKHjLAau4tRDXyg8_mAAAATA"]
[Mon Jul 20 07:44:08.559378 2026] [security2:error] [pid 229701:tid 229923] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mKHZMWbdeOcTm4Ewa9wAAAOE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:08.566167 2026] [security2:error] [pid 229701:tid 229841] [client 57.141.18.83:48138] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mJHZMWbdeOcTm4EwZDwAAjyY"]
[Mon Jul 20 07:44:08.713853 2026] [security2:error] [pid 230396:tid 230557] [client 154.192.233.184:61236] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mKHjLAau4tRDXyg8_qgAAASg"]
[Mon Jul 20 07:44:08.714062 2026] [security2:error] [pid 230396:tid 230557] [client 154.192.233.184:61236] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mKHjLAau4tRDXyg8_qgAAASg"]
[Mon Jul 20 07:44:08.714142 2026] [security2:error] [pid 230396:tid 230402] [remote 185.177.72.100:29818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5capp%5cetc%5cenv.php"] [unique_id "al4mKHjLAau4tRDXyg8_qQABUAQ"]
[Mon Jul 20 07:44:08.759246 2026] [security2:error] [pid 229701:tid 229895] [client 14.225.17.146:52488] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "thesoloceos.com"] [uri "/index.php"] [unique_id "al4mKHZMWbdeOcTm4EwbDAAAAMU"], referer: http://thesoloceos.com/WWW
[Mon Jul 20 07:44:08.899953 2026] [security2:error] [pid 230396:tid 230607] [client 45.3.55.17:42597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 17.55.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mKHjLAau4tRDXyg8_swAAAVo"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:08.903089 2026] [security2:error] [pid 230396:tid 230605] [client 149.0.16.108:57999] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mKHjLAau4tRDXyg8_tAAAAVg"]
[Mon Jul 20 07:44:08.903189 2026] [security2:error] [pid 230396:tid 230605] [client 149.0.16.108:57999] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mKHjLAau4tRDXyg8_tAAAAVg"]
[Mon Jul 20 07:44:08.977306 2026] [security2:error] [pid 229701:tid 229886] [client 168.144.19.97:51952] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/ai-client.php"] [unique_id "al4mKHZMWbdeOcTm4EwbHwAAALw"], referer: binance.com
[Mon Jul 20 07:44:09.181856 2026] [security2:error] [pid 229701:tid 229856] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwaewAAAJ4"]
[Mon Jul 20 07:44:09.212746 2026] [security2:error] [pid 230396:tid 230543] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3jLAau4tRDXyg8_gAAAARo"]
[Mon Jul 20 07:44:09.229594 2026] [security2:error] [pid 230396:tid 230549] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3jLAau4tRDXyg8_ggAAASA"]
[Mon Jul 20 07:44:09.382696 2026] [security2:error] [pid 230396:tid 230639] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mKXjLAau4tRDXyg8_tgAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:09.405985 2026] [security2:error] [pid 230396:tid 230631] [client 14.225.17.146:51804] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "expertcultures.com"] [uri "/index.php"] [unique_id "al4mKXjLAau4tRDXyg8_wQAAAXI"], referer: http://expertcultures.com/WWW
[Mon Jul 20 07:44:09.436357 2026] [security2:error] [pid 230396:tid 230540] [client 104.207.36.253:27915] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 253.36.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mKXjLAau4tRDXyg8_xQAAARc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:09.512525 2026] [security2:error] [pid 229701:tid 229931] [client 14.225.17.146:52055] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.studio"] [uri "/index.php"] [unique_id "al4mKXZMWbdeOcTm4EwbMgAAAOk"], referer: http://idigress.studio/WWW
[Mon Jul 20 07:44:09.555457 2026] [security2:error] [pid 229701:tid 229786] [remote 185.177.72.100:29820] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5capp%5cetc%5cenv.php"] [unique_id "al4mKXZMWbdeOcTm4EwbQQAA01Q"]
[Mon Jul 20 07:44:09.633941 2026] [security2:error] [pid 229701:tid 229894] [client 77.110.127.138:55180] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_medium. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mKXZMWbdeOcTm4EwbRAAAAMQ"]
[Mon Jul 20 07:44:09.738175 2026] [core:error] [pid 229701:tid 229841] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:09.738201 2026] [core:error] [pid 229701:tid 229841] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:09.788304 2026] [security2:error] [pid 229701:tid 229868] [client 14.225.17.146:52782] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.thesoloceos.com"] [uri "/index.php"] [unique_id "al4mKXZMWbdeOcTm4EwbRQAAAKo"], referer: https://thesoloceos.com/WWW
[Mon Jul 20 07:44:10.021481 2026] [security2:error] [pid 230396:tid 230573] [client 179.127.84.238:62995] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mKnjLAau4tRDXyg8_3AAAATg"]
[Mon Jul 20 07:44:10.022187 2026] [security2:error] [pid 230396:tid 230573] [client 179.127.84.238:62995] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mKnjLAau4tRDXyg8_3AAAATg"]
[Mon Jul 20 07:44:10.151990 2026] [security2:error] [pid 229701:tid 229838] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4mJ3ZMWbdeOcTm4EwanwAAAIw"]
[Mon Jul 20 07:44:10.179193 2026] [security2:error] [pid 229701:tid 229847] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4mKHZMWbdeOcTm4Ewa3AAAAJU"]
[Mon Jul 20 07:44:10.214957 2026] [security2:error] [pid 230396:tid 230551] [client 212.56.53.166:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.xp-design.co"] [uri "/index.php"] [unique_id "al4mKHjLAau4tRDXyg8_hQAAASI"]
[Mon Jul 20 07:44:10.229095 2026] [security2:error] [pid 230396:tid 230583] [client 14.225.17.146:52368] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4mKXjLAau4tRDXyg8_1wAAAUI"], referer: http://fkconstructionfunding.com/WWW
[Mon Jul 20 07:44:10.271858 2026] [security2:error] [pid 229701:tid 229917] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mKnZMWbdeOcTm4EwbawAAANs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:10.408717 2026] [security2:error] [pid 230396:tid 230411] [remote 185.177.72.100:29826] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fapp/etc/env.php"] [unique_id "al4mKnjLAau4tRDXyg8_6wABhA0"]
[Mon Jul 20 07:44:10.490473 2026] [security2:error] [pid 230396:tid 230532] [client 168.144.19.97:56572] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/block-bindings.php"] [unique_id "al4mKnjLAau4tRDXyg8_8AAAAQ8"], referer: binance.com
[Mon Jul 20 07:44:10.615925 2026] [security2:error] [pid 230396:tid 230413] [remote 81.173.115.7:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4mKnjLAau4tRDXyg8_9gABhQ8"]
[Mon Jul 20 07:44:10.821661 2026] [security2:error] [pid 230396:tid 230415] [remote 81.173.115.7:53474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4mKnjLAau4tRDXyg8__wABMxE"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:44:10.920635 2026] [proxy:error] [pid 230396:tid 230536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:10.920681 2026] [proxy_http:error] [pid 230396:tid 230536] [client 104.155.181.6:52808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:10.921282 2026] [proxy:error] [pid 230396:tid 230536] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:10.921312 2026] [proxy_http:error] [pid 230396:tid 230536] [client 104.155.181.6:52808] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:11.300740 2026] [security2:error] [pid 229701:tid 229757] [remote 185.177.72.100:29830] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fapp%252fetc%252fenv.php"] [unique_id "al4mK3ZMWbdeOcTm4EwbqAAAwTc"]
[Mon Jul 20 07:44:11.334915 2026] [security2:error] [pid 230396:tid 230557] [client 14.225.17.146:52093] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "entuvy.com"] [uri "/index.php"] [unique_id "al4mKnjLAau4tRDXyg8_4wAAASg"], referer: http://entuvy.com/WWW
[Mon Jul 20 07:44:11.391444 2026] [security2:error] [pid 230396:tid 230585] [client 14.225.17.146:52461] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4mK3jLAau4tRDXyg9AFQAAAUQ"], referer: https://fkconstructionfunding.com/WWW
[Mon Jul 20 07:44:11.444730 2026] [security2:error] [pid 229701:tid 229872] [client 43.205.139.3:19292] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4mK3ZMWbdeOcTm4EwbrgAAAK4"]
[Mon Jul 20 07:44:11.519500 2026] [security2:error] [pid 229701:tid 229866] [client 114.119.143.215:64703] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.thewelloiledlife.com"] [uri "/category/oil-information/page/2"] [unique_id "al4mK3ZMWbdeOcTm4EwbtQAAAKg"], referer: https://www.thewelloiledlife.com/category/oil-information
[Mon Jul 20 07:44:11.880027 2026] [security2:error] [pid 229701:tid 229885] [client 45.157.112.60:31563] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mK3ZMWbdeOcTm4EwbyQAAALs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:44:11.884771 2026] [security2:error] [pid 230396:tid 230567] [client 168.144.19.97:64474] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/block-editor.php"] [unique_id "al4mK3jLAau4tRDXyg9ALAAAATI"], referer: binance.com
[Mon Jul 20 07:44:11.889255 2026] [security2:error] [pid 230396:tid 230564] [client 57.141.18.48:41934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mKHjLAau4tRDXyg8_jgABLwI"]
[Mon Jul 20 07:44:11.890116 2026] [security2:error] [pid 230396:tid 230532] [client 173.239.224.35:65267] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 35.224.239.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "backandneckpainrelieflaceychiropractor.com"] [uri "/wp-login.php"] [unique_id "al4mK3jLAau4tRDXyg9AKwAAAQ8"]
[Mon Jul 20 07:44:12.029534 2026] [security2:error] [pid 230396:tid 230594] [client 14.225.17.146:51467] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "lelandumc.org"] [uri "/index.php"] [unique_id "al4mKnjLAau4tRDXyg8_5QAAAU0"], referer: http://lelandumc.org/WWW
[Mon Jul 20 07:44:12.145855 2026] [security2:error] [pid 230396:tid 230633] [client 14.225.17.146:53127] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "margaretspeckogawa.com"] [uri "/index.php"] [unique_id "al4mKnjLAau4tRDXyg8_8QAAAXQ"], referer: http://margaretspeckogawa.com/WWW
[Mon Jul 20 07:44:12.449235 2026] [core:error] [pid 230396:tid 230545] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:12.449272 2026] [core:error] [pid 230396:tid 230545] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:12.457059 2026] [security2:error] [pid 230396:tid 230536] [client 49.47.218.174:63896] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mLHjLAau4tRDXyg9ASAAAARM"]
[Mon Jul 20 07:44:12.457225 2026] [security2:error] [pid 230396:tid 230536] [client 49.47.218.174:63896] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mLHjLAau4tRDXyg9ASAAAARM"]
[Mon Jul 20 07:44:12.544633 2026] [security2:error] [pid 230396:tid 230557] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mLHjLAau4tRDXyg9APQAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:12.734024 2026] [security2:error] [pid 230396:tid 230530] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mLHjLAau4tRDXyg9ASwAAAQ0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:13.160450 2026] [security2:error] [pid 230396:tid 230561] [client 50.116.65.227:39840] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mLXjLAau4tRDXyg9AUwAAASw"]
[Mon Jul 20 07:44:13.176249 2026] [security2:error] [pid 229701:tid 229923] [client 50.116.65.227:39854] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mLXZMWbdeOcTm4EwcFAAAAOE"]
[Mon Jul 20 07:44:13.217915 2026] [security2:error] [pid 229701:tid 229918] [client 168.144.19.97:61804] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/block-template-utils.php"] [unique_id "al4mLXZMWbdeOcTm4EwcGAAAANw"], referer: binance.com
[Mon Jul 20 07:44:13.273846 2026] [security2:error] [pid 229701:tid 229855] [client 14.225.17.146:52355] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "kromosenergy.com"] [uri "/index.php"] [unique_id "al4mLXZMWbdeOcTm4EwcCwAAAJ0"], referer: http://kromosenergy.com/WWW
[Mon Jul 20 07:44:13.323544 2026] [security2:error] [pid 229701:tid 229877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mLXZMWbdeOcTm4EwcDQAAALM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:13.475879 2026] [security2:error] [pid 229701:tid 229910] [client 14.225.17.146:52954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "koaconsultants.com"] [uri "/index.php"] [unique_id "al4mK3ZMWbdeOcTm4EwbvwAAANQ"], referer: http://koaconsultants.com/WWW
[Mon Jul 20 07:44:13.702174 2026] [security2:error] [pid 230396:tid 230542] [client 13.232.231.177:42880] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cryptomeaning.com"] [uri "/wp-login.php"] [unique_id "al4mLXjLAau4tRDXyg9AaQAAARk"], referer: https://cryptomeaning.com/wp-login.php
[Mon Jul 20 07:44:13.747032 2026] [security2:error] [pid 230396:tid 230547] [client 50.116.65.227:36190] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4mLXjLAau4tRDXyg9AagAAAR4"]
[Mon Jul 20 07:44:13.761037 2026] [security2:error] [pid 229701:tid 229855] [client 50.116.65.227:39886] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/Jin-Wee-Feature-Image.jpg"] [unique_id "al4mLXZMWbdeOcTm4EwcPwAAAKw"]
[Mon Jul 20 07:44:13.775600 2026] [security2:error] [pid 229701:tid 229917] [client 14.225.17.146:52698] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4mK3ZMWbdeOcTm4EwbxwAAANs"], referer: http://oldracelimited.com/WWW
[Mon Jul 20 07:44:13.920426 2026] [security2:error] [pid 230396:tid 230572] [client 186.221.114.200:60868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mLXjLAau4tRDXyg9AcAAAATc"]
[Mon Jul 20 07:44:13.920590 2026] [security2:error] [pid 230396:tid 230572] [client 186.221.114.200:60868] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mLXjLAau4tRDXyg9AcAAAATc"]
[Mon Jul 20 07:44:13.973476 2026] [security2:error] [pid 230396:tid 230432] [remote 173.212.252.15:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mLXjLAau4tRDXyg9AcwABcCI"]
[Mon Jul 20 07:44:13.987317 2026] [security2:error] [pid 229701:tid 229857] [client 168.144.19.97:57046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/block-template.php"] [unique_id "al4mLXZMWbdeOcTm4EwcTAAAAJ8"], referer: binance.com
[Mon Jul 20 07:44:14.133131 2026] [security2:error] [pid 229701:tid 229850] [client 50.116.65.227:39896] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4mLXZMWbdeOcTm4EwcSAAAAJg"]
[Mon Jul 20 07:44:14.141143 2026] [security2:error] [pid 229701:tid 229888] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mLXZMWbdeOcTm4EwcRwAAAL4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:14.177654 2026] [security2:error] [pid 230396:tid 230434] [remote 173.212.252.15:58390] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.252.212.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rpv.ekr.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mLnjLAau4tRDXyg9AgAABJSQ"], referer: https://rpv.ekr.mybluehost.me/wp-login.php
[Mon Jul 20 07:44:14.298458 2026] [security2:error] [pid 230396:tid 230550] [client 50.116.65.227:39910] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "oldracelimited.com"] [uri "/index.php"] [unique_id "al4mLnjLAau4tRDXyg9AfgAAASE"]
[Mon Jul 20 07:44:14.391267 2026] [security2:error] [pid 204156:tid 204274] [remote 8.217.108.67:60834] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tbd.jxc.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mLhbAFPhDXvzP7SnY3gAB8nU"]
[Mon Jul 20 07:44:14.434393 2026] [lsapi:warn] [pid 229701:tid 229856] [client 14.225.17.146:54218] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WWW
[Mon Jul 20 07:44:14.434418 2026] [lsapi:warn] [pid 229701:tid 229856] [client 14.225.17.146:54218] [host oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: http://oswegooperatheater.com/WWW
[Mon Jul 20 07:44:14.548191 2026] [security2:error] [pid 229701:tid 229898] [client 103.139.191.61:60658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mLnZMWbdeOcTm4EwcYQAAAMg"]
[Mon Jul 20 07:44:14.548300 2026] [security2:error] [pid 229701:tid 229898] [client 103.139.191.61:60658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mLnZMWbdeOcTm4EwcYQAAAMg"]
[Mon Jul 20 07:44:14.566829 2026] [security2:error] [pid 230396:tid 230563] [client 98.159.234.160:29139] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mLnjLAau4tRDXyg9AiAAAAS4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:44:14.967925 2026] [lsapi:warn] [pid 230396:tid 230653] [client 50.116.65.227:39912] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:44:14.967962 2026] [lsapi:warn] [pid 230396:tid 230653] [client 50.116.65.227:39912] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n
[Mon Jul 20 07:44:14.984497 2026] [security2:error] [pid 229701:tid 229856] [client 14.225.17.146:54218] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4mLXZMWbdeOcTm4EwcRQAAAJ4"], referer: http://oswegooperatheater.com/WWW
[Mon Jul 20 07:44:15.283528 2026] [security2:error] [pid 229701:tid 229850] [client 168.144.19.97:54959] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-avif-info.php"] [unique_id "al4mL3ZMWbdeOcTm4EwchQAAAJg"], referer: binance.com
[Mon Jul 20 07:44:15.298584 2026] [security2:error] [pid 229701:tid 229931] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mLnZMWbdeOcTm4EwccgAAAOk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:15.359666 2026] [security2:error] [pid 229701:tid 229919] [client 14.225.17.146:54211] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "blaizeaccountingservices.com"] [uri "/index.php"] [unique_id "al4mLXZMWbdeOcTm4EwcRAAAAN0"], referer: http://blaizeaccountingservices.com/WWW
[Mon Jul 20 07:44:15.366384 2026] [security2:error] [pid 230396:tid 230443] [remote 78.46.99.182:48018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4mL3jLAau4tRDXyg9AtwABUC0"]
[Mon Jul 20 07:44:15.402188 2026] [autoindex:error] [pid 230396:tid 230444] [remote 136.114.198.221:49438] AH01276: Cannot serve directory /home2/enxbgpmy/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.enx.bgp.mybluehost.me
[Mon Jul 20 07:44:15.572365 2026] [security2:error] [pid 230396:tid 230445] [remote 78.46.99.182:48018] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 182.99.46.78.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mcg.homes"] [uri "/wp-login.php"] [unique_id "al4mL3jLAau4tRDXyg9AwgABNS8"], referer: https://mcg.homes/wp-login.php
[Mon Jul 20 07:44:15.640624 2026] [security2:error] [pid 229701:tid 229729] [remote 173.249.4.11:24472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mL3ZMWbdeOcTm4EwckAAAuBs"]
[Mon Jul 20 07:44:15.662152 2026] [security2:error] [pid 229701:tid 229888] [client 36.93.152.155:51941] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mL3ZMWbdeOcTm4EwckgAAAL4"]
[Mon Jul 20 07:44:15.662261 2026] [security2:error] [pid 229701:tid 229888] [client 36.93.152.155:51941] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mL3ZMWbdeOcTm4EwckgAAAL4"]
[Mon Jul 20 07:44:15.703552 2026] [security2:error] [pid 230396:tid 230591] [client 103.106.165.44:61250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mL3jLAau4tRDXyg9AygAAAUo"]
[Mon Jul 20 07:44:15.703673 2026] [security2:error] [pid 230396:tid 230591] [client 103.106.165.44:61250] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mL3jLAau4tRDXyg9AygAAAUo"]
[Mon Jul 20 07:44:15.801912 2026] [security2:error] [pid 229701:tid 229884] [client 14.225.17.146:60497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "travelbyfire.com"] [uri "/index.php"] [unique_id "al4mL3ZMWbdeOcTm4EwclQAAALo"], referer: http://travelbyfire.com/WWW
[Mon Jul 20 07:44:15.803489 2026] [lsapi:warn] [pid 229701:tid 229949] [client 14.225.17.146:53030] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_time" setting. Invalid quantity "60000000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WWW
[Mon Jul 20 07:44:15.803507 2026] [lsapi:warn] [pid 229701:tid 229949] [client 14.225.17.146:53030] [host www.oswegooperatheater.com] Backend log: PHP Warning:  Invalid "max_input_vars" setting. Invalid quantity "100000000000000000000": value is out of range, using overflow result for backwards compatibility in Unknown on line 0\n, referer: https://oswegooperatheater.com/WWW
[Mon Jul 20 07:44:15.817899 2026] [security2:error] [pid 229701:tid 229728] [remote 173.249.4.11:24472] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mL3ZMWbdeOcTm4EwcnQAAvxo"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:44:15.859078 2026] [security2:error] [pid 229701:tid 229949] [client 14.225.17.146:53030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.oswegooperatheater.com"] [uri "/index.php"] [unique_id "al4mL3ZMWbdeOcTm4EwcmgAAAPs"], referer: https://oswegooperatheater.com/WWW
[Mon Jul 20 07:44:15.899656 2026] [security2:error] [pid 230396:tid 230606] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mL3jLAau4tRDXyg9AyAAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:15.907329 2026] [security2:error] [pid 229701:tid 229896] [client 168.144.19.97:54939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-bindings-registry.php"] [unique_id "al4mL3ZMWbdeOcTm4EwcogAAAMY"], referer: binance.com
[Mon Jul 20 07:44:15.916690 2026] [security2:error] [pid 230396:tid 230544] [client 14.225.17.146:53451] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "fineartsfactory.net"] [uri "/index.php"] [unique_id "al4mLnjLAau4tRDXyg9AeAAAARs"], referer: http://fineartsfactory.net/WWW
[Mon Jul 20 07:44:16.533574 2026] [security2:error] [pid 230396:tid 230586] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mMHjLAau4tRDXyg9A4gAAAUU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:16.659426 2026] [security2:error] [pid 229701:tid 229852] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mMHZMWbdeOcTm4EwcugAAAJo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:16.662169 2026] [security2:error] [pid 229701:tid 229741] [remote 103.90.225.206:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.225.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4mMHZMWbdeOcTm4EwcwwAAryc"]
[Mon Jul 20 07:44:16.695900 2026] [security2:error] [pid 229701:tid 229857] [client 14.225.17.146:60539] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.travelbyfire.com"] [uri "/index.php"] [unique_id "al4mMHZMWbdeOcTm4EwcxAAAAJ8"], referer: https://travelbyfire.com/WWW
[Mon Jul 20 07:44:17.032326 2026] [security2:error] [pid 230396:tid 230530] [client 180.249.173.210:58708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mMXjLAau4tRDXyg9BAQAAAQ0"]
[Mon Jul 20 07:44:17.032943 2026] [security2:error] [pid 230396:tid 230530] [client 180.249.173.210:58708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mMXjLAau4tRDXyg9BAQAAAQ0"]
[Mon Jul 20 07:44:17.060765 2026] [core:error] [pid 230396:tid 230634] [client 14.225.17.146:53505] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:17.060805 2026] [core:error] [pid 230396:tid 230634] [client 14.225.17.146:53505] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:17.090575 2026] [security2:error] [pid 230396:tid 230543] [client 14.225.17.146:54110] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "momheadquarters.com"] [uri "/index.php"] [unique_id "al4mMHjLAau4tRDXyg9A_wAAARo"], referer: http://momheadquarters.com/WWW
[Mon Jul 20 07:44:17.104307 2026] [security2:error] [pid 230396:tid 230647] [client 136.158.60.21:59465] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mMXjLAau4tRDXyg9BBgAAAYI"]
[Mon Jul 20 07:44:17.104418 2026] [security2:error] [pid 230396:tid 230647] [client 136.158.60.21:59465] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mMXjLAau4tRDXyg9BBgAAAYI"]
[Mon Jul 20 07:44:17.165067 2026] [security2:error] [pid 229701:tid 229738] [remote 103.90.225.206:51740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 206.225.90.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.talknutritionwithlesley.com"] [uri "/wp-login.php"] [unique_id "al4mMXZMWbdeOcTm4Ewc1AAA5iQ"], referer: https://mail.talknutritionwithlesley.com/wp-login.php
[Mon Jul 20 07:44:17.227151 2026] [security2:error] [pid 230396:tid 230574] [client 39.46.9.231:63831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mMXjLAau4tRDXyg9BHwAAATk"]
[Mon Jul 20 07:44:17.228778 2026] [security2:error] [pid 230396:tid 230574] [client 39.46.9.231:63831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mMXjLAau4tRDXyg9BHwAAATk"]
[Mon Jul 20 07:44:17.542392 2026] [security2:error] [pid 229701:tid 229740] [remote 185.177.72.100:29878] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%5csites%5cdefault%5csettings.php"] [unique_id "al4mMXZMWbdeOcTm4Ewc6gAAxiY"]
[Mon Jul 20 07:44:18.045827 2026] [security2:error] [pid 230396:tid 230646] [client 56.125.35.21:23176] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.35.125.56.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mMnjLAau4tRDXyg9BTwAAAYE"]
[Mon Jul 20 07:44:18.045958 2026] [security2:error] [pid 230396:tid 230646] [client 56.125.35.21:23176] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mMnjLAau4tRDXyg9BTwAAAYE"]
[Mon Jul 20 07:44:18.169799 2026] [security2:error] [pid 230396:tid 230500] [remote 5.161.225.162:51456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mMnjLAau4tRDXyg9BVAABPGY"]
[Mon Jul 20 07:44:18.340042 2026] [security2:error] [pid 230396:tid 230501] [remote 103.82.22.235:33418] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 235.22.82.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mMnjLAau4tRDXyg9BWQABKWc"]
[Mon Jul 20 07:44:18.340257 2026] [security2:error] [pid 230396:tid 230558] [client 103.82.22.235:33418] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mMnjLAau4tRDXyg9BWQABKWc"]
[Mon Jul 20 07:44:18.345282 2026] [security2:error] [pid 230396:tid 230502] [remote 185.177.72.100:60946] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%5csites%5cdefault%5csettings.php"] [unique_id "al4mMnjLAau4tRDXyg9BWwABFGg"]
[Mon Jul 20 07:44:18.371442 2026] [security2:error] [pid 230396:tid 230506] [remote 5.161.225.162:51456] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mMnjLAau4tRDXyg9BYAABGmw"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:44:18.416996 2026] [security2:error] [pid 229701:tid 229893] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mMnZMWbdeOcTm4EwdBwAAAMM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:18.890048 2026] [security2:error] [pid 230396:tid 230600] [client 37.52.210.45:2951] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mMnjLAau4tRDXyg9BeAAAAVM"]
[Mon Jul 20 07:44:18.890197 2026] [security2:error] [pid 230396:tid 230600] [client 37.52.210.45:2951] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mMnjLAau4tRDXyg9BeAAAAVM"]
[Mon Jul 20 07:44:18.905847 2026] [security2:error] [pid 230396:tid 230584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mMnjLAau4tRDXyg9BbwAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:19.076853 2026] [security2:error] [pid 229701:tid 229862] [client 77.110.127.138:55286] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/if(now()=sysdate(),sleep(15),0)/21/"] [unique_id "al4mM3ZMWbdeOcTm4EwdJQAAAKQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:19.120266 2026] [security2:error] [pid 229701:tid 229951] [client 142.111.152.71:57037] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mMnZMWbdeOcTm4EwdIgAAAP0"]
[Mon Jul 20 07:44:19.123001 2026] [security2:error] [pid 230396:tid 230516] [remote 185.177.72.100:60958] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/%252fsites/default/settings.php"] [unique_id "al4mM3jLAau4tRDXyg9BhAABY3Y"]
[Mon Jul 20 07:44:19.330038 2026] [security2:error] [pid 229701:tid 229858] [client 154.192.233.184:61658] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mM3ZMWbdeOcTm4EwdMQAAAKA"]
[Mon Jul 20 07:44:19.330160 2026] [security2:error] [pid 229701:tid 229858] [client 154.192.233.184:61658] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mM3ZMWbdeOcTm4EwdMQAAAKA"]
[Mon Jul 20 07:44:19.379801 2026] [security2:error] [pid 230396:tid 230626] [client 74.7.227.179:43518] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4mM3jLAau4tRDXyg9BigABbXg"], referer: https://tejasenvironmental.com/p=141377
[Mon Jul 20 07:44:19.571256 2026] [security2:error] [pid 229701:tid 229927] [client 149.0.16.108:58533] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mM3ZMWbdeOcTm4EwdOQAAAOU"]
[Mon Jul 20 07:44:19.571337 2026] [security2:error] [pid 229701:tid 229927] [client 149.0.16.108:58533] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mM3ZMWbdeOcTm4EwdOQAAAOU"]
[Mon Jul 20 07:44:19.908826 2026] [security2:error] [pid 229701:tid 229812] [remote 185.177.72.100:60962] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 100.72.177.185.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "seidemannlab.site"] [uri "/..%252fsites%252fdefault%252fsettings.php"] [unique_id "al4mM3ZMWbdeOcTm4EwdRgAA8m4"]
[Mon Jul 20 07:44:19.964276 2026] [proxy:error] [pid 230396:tid 230532] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:19.964321 2026] [proxy_http:error] [pid 230396:tid 230532] [client 107.172.180.205:58570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:19.964781 2026] [proxy:error] [pid 230396:tid 230532] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:19.964806 2026] [proxy_http:error] [pid 230396:tid 230532] [client 107.172.180.205:58570] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:20.174321 2026] [security2:error] [pid 229701:tid 229892] [client 14.224.227.113:56490] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mNHZMWbdeOcTm4EwdTAAAAMI"]
[Mon Jul 20 07:44:20.378816 2026] [security2:error] [pid 230396:tid 230553] [client 14.225.17.146:54246] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "superiorcopywriting.com"] [uri "/index.php"] [unique_id "al4mNHjLAau4tRDXyg9BuAAAASQ"], referer: http://superiorcopywriting.com/WWW
[Mon Jul 20 07:44:20.514684 2026] [security2:error] [pid 229701:tid 229869] [client 179.127.84.238:63519] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mNHZMWbdeOcTm4EwdVwAAAKs"]
[Mon Jul 20 07:44:20.514865 2026] [security2:error] [pid 229701:tid 229869] [client 179.127.84.238:63519] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mNHZMWbdeOcTm4EwdVwAAAKs"]
[Mon Jul 20 07:44:20.577596 2026] [security2:error] [pid 230396:tid 230534] [client 57.141.18.57:45200] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mMHjLAau4tRDXyg9A6wABETU"]
[Mon Jul 20 07:44:21.221472 2026] [security2:error] [pid 230396:tid 230529] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mNHjLAau4tRDXyg9B3QAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:21.260361 2026] [security2:error] [pid 230396:tid 230639] [client 127.0.0.1:30850] ModSecurity: Access denied with code 406 (phase 2). Found 1 byte(s) in REQUEST_HEADERS:X-Original-URL outside range: 1-255. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "134"] [id "390613"] [rev "10"] [msg "Atomicorp.com WAF Rules: Null Byte Attack Blocked (Invalid character in request or headers)"] [severity "CRITICAL"] [hostname "127.0.0.1"] [uri "/cgi-sys/autodiscover.cgi"] [unique_id "al4mNXjLAau4tRDXyg9B5wAAAXo"], referer: https://duckduckgo.com/?q=x6zns
[Mon Jul 20 07:44:21.569178 2026] [security2:error] [pid 230396:tid 230411] [remote 100.42.189.89:35162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4mNXjLAau4tRDXyg9B9gABhA0"]
[Mon Jul 20 07:44:21.627602 2026] [security2:error] [pid 230396:tid 230531] [client 136.144.33.201:34345] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 201.33.144.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4mNXjLAau4tRDXyg9B9wAAAQ4"]
[Mon Jul 20 07:44:21.641156 2026] [security2:error] [pid 230396:tid 230587] [client 193.36.225.59:35333] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 59.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4mNXjLAau4tRDXyg9B-QAAAUY"]
[Mon Jul 20 07:44:21.652921 2026] [security2:error] [pid 230396:tid 230592] [client 193.36.225.5:20939] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 5.225.36.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bbwipartnerconference.com"] [uri "/wp-login.php"] [unique_id "al4mNXjLAau4tRDXyg9B-AAAAUs"]
[Mon Jul 20 07:44:21.702160 2026] [security2:error] [pid 229701:tid 229909] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mNXZMWbdeOcTm4EwdiAAAANM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:21.781375 2026] [security2:error] [pid 230396:tid 230410] [remote 100.42.189.89:35162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4mNXjLAau4tRDXyg9CAgABEww"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:44:22.120082 2026] [security2:error] [pid 230396:tid 230546] [client 77.110.127.138:55263] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/21/"] [unique_id "al4mNnjLAau4tRDXyg9CEgAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:22.152775 2026] [security2:error] [pid 230396:tid 230595] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mNXjLAau4tRDXyg9CCwAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:22.211669 2026] [security2:error] [pid 229701:tid 229850] [client 14.225.17.146:52192] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "whiteoutcb.com"] [uri "/index.php"] [unique_id "al4mNnZMWbdeOcTm4EwdogAAAJg"], referer: http://whiteoutcb.com/WWW
[Mon Jul 20 07:44:22.371756 2026] [security2:error] [pid 230396:tid 230549] [client 14.225.17.146:61063] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "transparentservices.online"] [uri "/index.php"] [unique_id "al4mNnjLAau4tRDXyg9CDgAAASA"], referer: http://transparentservices.online/WWW
[Mon Jul 20 07:44:22.480225 2026] [security2:error] [pid 229701:tid 229842] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mNnZMWbdeOcTm4EwdsAAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:22.546454 2026] [core:error] [pid 230396:tid 230585] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:22.546478 2026] [core:error] [pid 230396:tid 230585] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:22.661622 2026] [security2:error] [pid 230396:tid 230569] [client 193.37.33.30:39271] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4mNnjLAau4tRDXyg9CIwAAATQ"]
[Mon Jul 20 07:44:22.692027 2026] [security2:error] [pid 230396:tid 230622] [client 193.37.33.46:60643] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 46.33.37.193.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "peoplestrategies.us"] [uri "/wp-login.php"] [unique_id "al4mNnjLAau4tRDXyg9CJAAAAWk"]
[Mon Jul 20 07:44:22.801377 2026] [security2:error] [pid 229701:tid 229773] [remote 217.61.143.92:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mNnZMWbdeOcTm4EwdzgAArEc"]
[Mon Jul 20 07:44:22.811028 2026] [security2:error] [pid 229701:tid 229930] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "aleishapenny.ca"] [uri "/index.php"] [unique_id "al4mNnZMWbdeOcTm4EwdvgAA6EE"], referer: http://aleishapenny.ca/WWW
[Mon Jul 20 07:44:22.895638 2026] [security2:error] [pid 229701:tid 229831] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mNnZMWbdeOcTm4EwdxwAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:22.909148 2026] [security2:error] [pid 230396:tid 230589] [client 49.47.218.174:64451] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 174.218.47.49.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mNnjLAau4tRDXyg9CLQAAAUg"]
[Mon Jul 20 07:44:22.912772 2026] [security2:error] [pid 230396:tid 230589] [client 49.47.218.174:64451] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "retzkolonglogistics.com"] [uri "/xmlrpc.php"] [unique_id "al4mNnjLAau4tRDXyg9CLQAAAUg"]
[Mon Jul 20 07:44:22.951677 2026] [security2:error] [pid 229701:tid 229771] [remote 162.19.86.63:57454] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mNnZMWbdeOcTm4Ewd0QAA1UU"]
[Mon Jul 20 07:44:22.951843 2026] [security2:error] [pid 229701:tid 229911] [client 162.19.86.63:57454] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "mail.pju.xqs.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mNnZMWbdeOcTm4Ewd0QAA1UU"]
[Mon Jul 20 07:44:23.038070 2026] [security2:error] [pid 229701:tid 229783] [remote 217.61.143.92:51976] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tee.qtw.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mN3ZMWbdeOcTm4Ewd2AAAlFE"], referer: https://tee.qtw.mybluehost.me/wp-login.php
[Mon Jul 20 07:44:23.046235 2026] [security2:error] [pid 230396:tid 230541] [client 57.141.18.63:20780] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mM3jLAau4tRDXyg9BggABGHU"]
[Mon Jul 20 07:44:23.158693 2026] [security2:error] [pid 230396:tid 230628] [client 45.3.54.219:13261] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 219.54.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mN3jLAau4tRDXyg9COAAAAW8"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:44:23.345605 2026] [security2:error] [pid 230396:tid 230635] [client 103.168.67.159:55264] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/wp-json/wp/v2/users%00.php"] [unique_id "al4mN3jLAau4tRDXyg9CQwAAAXY"], referer: https://duckduckgo.com/?q=tc5rw
[Mon Jul 20 07:44:23.399530 2026] [security2:error] [pid 229701:tid 229919] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mN3ZMWbdeOcTm4Ewd4wAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:23.448694 2026] [security2:error] [pid 229701:tid 229784] [remote 74.7.227.185:34848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4mN3ZMWbdeOcTm4Ewd6wAAzlI"], referer: https://verdunestate.com/property/5371-2/
[Mon Jul 20 07:44:23.522736 2026] [proxy:error] [pid 230396:tid 230612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:23.522779 2026] [proxy_http:error] [pid 230396:tid 230612] [client 143.244.57.90:48202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:23.523247 2026] [proxy:error] [pid 230396:tid 230612] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:23.523275 2026] [proxy_http:error] [pid 230396:tid 230612] [client 143.244.57.90:48202] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:23.577110 2026] [security2:error] [pid 229701:tid 229878] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4mN3ZMWbdeOcTm4Ewd7wAAtDI"], referer: https://aleishapenny.ca/WWW
[Mon Jul 20 07:44:23.836024 2026] [proxy:error] [pid 229701:tid 229849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:23.836068 2026] [proxy_http:error] [pid 229701:tid 229849] [client 143.244.57.90:48206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:23.836989 2026] [proxy:error] [pid 229701:tid 229849] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:23.837019 2026] [proxy_http:error] [pid 229701:tid 229849] [client 143.244.57.90:48206] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:23.898943 2026] [security2:error] [pid 230396:tid 230429] [remote 45.90.123.233:48046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4mN3jLAau4tRDXyg9CbAABRB8"]
[Mon Jul 20 07:44:23.980954 2026] [security2:error] [pid 230396:tid 230622] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mN3jLAau4tRDXyg9CYgAAAWk"]
[Mon Jul 20 07:44:24.141087 2026] [security2:error] [pid 229701:tid 229865] [client 143.244.57.90:48222] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/wp-includes/wlwmanifest.xml"] [unique_id "al4mOHZMWbdeOcTm4EweCgAAAKc"]
[Mon Jul 20 07:44:24.149738 2026] [security2:error] [pid 230396:tid 230424] [remote 45.90.123.233:48046] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thelastgamestandingexp.com"] [uri "/wp-login.php"] [unique_id "al4mOHjLAau4tRDXyg9CeAABcho"], referer: https://thelastgamestandingexp.com/wp-login.php
[Mon Jul 20 07:44:24.152964 2026] [security2:error] [pid 229701:tid 229836] [client 17.241.227.163:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/index.php"] [unique_id "al4mNnZMWbdeOcTm4EwdyQAAAIo"]
[Mon Jul 20 07:44:24.430898 2026] [proxy:error] [pid 230396:tid 230633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:24.430983 2026] [proxy_http:error] [pid 230396:tid 230633] [client 143.244.57.90:48236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:24.432047 2026] [proxy:error] [pid 230396:tid 230633] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:24.432094 2026] [proxy_http:error] [pid 230396:tid 230633] [client 143.244.57.90:48236] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:24.475374 2026] [security2:error] [pid 230396:tid 230548] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mOHjLAau4tRDXyg9CfQAAAR8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:24.513110 2026] [security2:error] [pid 230396:tid 230630] [client 57.141.18.114:59954] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mNHjLAau4tRDXyg9B1gABcQY"]
[Mon Jul 20 07:44:24.570636 2026] [security2:error] [pid 229701:tid 229864] [client 104.207.53.124:40385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 124.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mOHZMWbdeOcTm4EweFgAAAKY"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:44:24.584353 2026] [security2:error] [pid 230396:tid 230579] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mOHjLAau4tRDXyg9CiwAAAT4"]
[Mon Jul 20 07:44:24.595310 2026] [security2:error] [pid 230396:tid 230542] [client 77.110.127.138:55264] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/21/"] [unique_id "al4mOHjLAau4tRDXyg9CmQAAARk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:24.672932 2026] [security2:error] [pid 230396:tid 230632] [client 50.116.65.227:22212] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mOHjLAau4tRDXyg9CnwAAAXM"]
[Mon Jul 20 07:44:24.685371 2026] [security2:error] [pid 229701:tid 229954] [client 50.116.65.227:22222] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mOHZMWbdeOcTm4EweHAAAAQA"]
[Mon Jul 20 07:44:24.734616 2026] [security2:error] [pid 229701:tid 229843] [client 143.244.57.90:48240] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/blog/wp-includes/wlwmanifest.xml"] [unique_id "al4mOHZMWbdeOcTm4EweIgAAAJE"]
[Mon Jul 20 07:44:24.765831 2026] [security2:error] [pid 230396:tid 230553] [client 186.221.114.200:61347] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mOHjLAau4tRDXyg9CrQAAASQ"]
[Mon Jul 20 07:44:24.765956 2026] [security2:error] [pid 230396:tid 230553] [client 186.221.114.200:61347] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mOHjLAau4tRDXyg9CrQAAASQ"]
[Mon Jul 20 07:44:24.877953 2026] [security2:error] [pid 230396:tid 230578] [client 14.225.17.146:52188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ironcitywellness.com"] [uri "/index.php"] [unique_id "al4mN3jLAau4tRDXyg9CPwAAAT0"], referer: http://ironcitywellness.com/WWW
[Mon Jul 20 07:44:24.941518 2026] [security2:error] [pid 230396:tid 230595] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mOHjLAau4tRDXyg9CqQAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:25.026313 2026] [security2:error] [pid 230396:tid 230651] [client 143.244.57.90:48254] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/wordpress/wp-includes/wlwmanifest.xml"] [unique_id "al4mOXjLAau4tRDXyg9CuwAAAYY"]
[Mon Jul 20 07:44:25.279583 2026] [security2:error] [pid 229701:tid 229890] [client 103.139.191.61:61174] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mOXZMWbdeOcTm4EwePgAAAMA"]
[Mon Jul 20 07:44:25.279737 2026] [security2:error] [pid 229701:tid 229890] [client 103.139.191.61:61174] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mOXZMWbdeOcTm4EwePgAAAMA"]
[Mon Jul 20 07:44:25.332584 2026] [security2:error] [pid 230396:tid 230583] [client 143.244.57.90:19266] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/website/wp-includes/wlwmanifest.xml"] [unique_id "al4mOXjLAau4tRDXyg9CyQAAAUI"]
[Mon Jul 20 07:44:25.400297 2026] [security2:error] [pid 230396:tid 230644] [client 212.47.72.86:40802] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4mOXjLAau4tRDXyg9CygAAAX8"]
[Mon Jul 20 07:44:25.442729 2026] [security2:error] [pid 229701:tid 229841] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mOXZMWbdeOcTm4EweNQAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:25.642333 2026] [security2:error] [pid 230396:tid 230629] [client 143.244.57.90:20659] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/wp/wp-includes/wlwmanifest.xml"] [unique_id "al4mOXjLAau4tRDXyg9C0wAAAXA"]
[Mon Jul 20 07:44:25.669253 2026] [security2:error] [pid 230396:tid 230581] [client 168.144.19.97:55459] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-bindings-source.php"] [unique_id "al4mOXjLAau4tRDXyg9C1AAAAUA"], referer: binance.com
[Mon Jul 20 07:44:25.827348 2026] [security2:error] [pid 230396:tid 230606] [client 212.47.72.86:40806] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4mOXjLAau4tRDXyg9C4gAAAVk"]
[Mon Jul 20 07:44:25.920051 2026] [security2:error] [pid 229701:tid 229916] [client 167.235.143.113:14892] ModSecurity: Warning. Matched phrase "oBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "mtlegnews.gov"] [uri "/index.php"] [unique_id "al4mOXZMWbdeOcTm4EweTgAAANo"], referer: https://mtlegnews.gov/
[Mon Jul 20 07:44:25.938187 2026] [security2:error] [pid 229701:tid 229918] [client 143.244.57.90:48276] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/news/wp-includes/wlwmanifest.xml"] [unique_id "al4mOXZMWbdeOcTm4EweVwAAANw"]
[Mon Jul 20 07:44:25.954109 2026] [security2:error] [pid 230396:tid 230651] [client 192.178.6.6:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "cloudcast.ca"] [uri "/robots.txt"] [unique_id "al4mOXjLAau4tRDXyg9C5wAAAYY"]
[Mon Jul 20 07:44:26.207806 2026] [security2:error] [pid 230396:tid 230598] [client 36.93.152.155:52462] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mOnjLAau4tRDXyg9C7AAAAVE"]
[Mon Jul 20 07:44:26.207913 2026] [security2:error] [pid 230396:tid 230598] [client 36.93.152.155:52462] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mOnjLAau4tRDXyg9C7AAAAVE"]
[Mon Jul 20 07:44:26.237065 2026] [security2:error] [pid 230396:tid 230637] [client 103.106.165.44:61737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mOnjLAau4tRDXyg9C7gAAAXg"]
[Mon Jul 20 07:44:26.237162 2026] [security2:error] [pid 230396:tid 230637] [client 103.106.165.44:61737] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mOnjLAau4tRDXyg9C7gAAAXg"]
[Mon Jul 20 07:44:26.239465 2026] [security2:error] [pid 229701:tid 229930] [client 143.244.57.90:48290] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/2018/wp-includes/wlwmanifest.xml"] [unique_id "al4mOnZMWbdeOcTm4EweXgAAAOg"]
[Mon Jul 20 07:44:26.252635 2026] [security2:error] [pid 230396:tid 230639] [client 212.47.72.86:40822] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5020.bluehost.com"] [uri "/blog/"] [unique_id "al4mOnjLAau4tRDXyg9C8QAAAXo"]
[Mon Jul 20 07:44:26.411362 2026] [security2:error] [pid 230396:tid 230604] [client 57.141.18.26:26020] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mNnjLAau4tRDXyg9CHwABVw8"]
[Mon Jul 20 07:44:26.531797 2026] [security2:error] [pid 230396:tid 230553] [client 143.244.57.90:48302] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/2019/wp-includes/wlwmanifest.xml"] [unique_id "al4mOnjLAau4tRDXyg9DAwAAASQ"]
[Mon Jul 20 07:44:26.692760 2026] [core:error] [pid 230396:tid 230624] [client 14.225.17.146:59965] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:26.692793 2026] [core:error] [pid 230396:tid 230624] [client 14.225.17.146:59965] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:26.802426 2026] [proxy:error] [pid 229701:tid 229931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:26.802463 2026] [proxy_http:error] [pid 229701:tid 229931] [client 107.172.180.205:58584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:26.802887 2026] [proxy:error] [pid 229701:tid 229931] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:26.802916 2026] [proxy_http:error] [pid 229701:tid 229931] [client 107.172.180.205:58584] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:26.833169 2026] [security2:error] [pid 229701:tid 229919] [client 143.244.57.90:48316] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/shop/wp-includes/wlwmanifest.xml"] [unique_id "al4mOnZMWbdeOcTm4EwedwAAAN0"]
[Mon Jul 20 07:44:26.835823 2026] [core:error] [pid 230396:tid 230570] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:26.835841 2026] [core:error] [pid 230396:tid 230570] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:27.088661 2026] [security2:error] [pid 230396:tid 230543] [client 77.110.127.138:55247] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/if(now()=sysdate(),sleep(15),0)/dist/wp-seo-local-vendor-1390.js"] [unique_id "al4mO3jLAau4tRDXyg9DIwAAARo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:27.127082 2026] [security2:error] [pid 230396:tid 230604] [client 143.244.57.90:12666] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/wp1/wp-includes/wlwmanifest.xml"] [unique_id "al4mO3jLAau4tRDXyg9DJwAAAVc"]
[Mon Jul 20 07:44:27.250773 2026] [security2:error] [pid 230396:tid 230589] [client 14.225.17.146:60194] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "709fx.com"] [uri "/index.php"] [unique_id "al4mO3jLAau4tRDXyg9DJQAAAUg"], referer: http://709fx.com/WWW
[Mon Jul 20 07:44:27.258046 2026] [security2:error] [pid 230396:tid 230595] [client 14.225.17.146:60202] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "taskidsvirginia.com"] [uri "/index.php"] [unique_id "al4mO3jLAau4tRDXyg9DIAAAAU4"], referer: http://taskidsvirginia.com/WWW
[Mon Jul 20 07:44:27.318976 2026] [security2:error] [pid 230396:tid 230583] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mO3jLAau4tRDXyg9DJgAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:27.384126 2026] [security2:error] [pid 229701:tid 229842] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mO3ZMWbdeOcTm4EwegQAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:27.414646 2026] [security2:error] [pid 230396:tid 230617] [client 143.244.57.90:48336] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/media/wp-includes/wlwmanifest.xml"] [unique_id "al4mO3jLAau4tRDXyg9DOQAAAWQ"]
[Mon Jul 20 07:44:27.696553 2026] [security2:error] [pid 230396:tid 230458] [remote 8.217.108.67:46106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4mO3jLAau4tRDXyg9DPwABXDw"]
[Mon Jul 20 07:44:27.705407 2026] [security2:error] [pid 229701:tid 229879] [client 143.244.57.90:48346] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/wp2/wp-includes/wlwmanifest.xml"] [unique_id "al4mO3ZMWbdeOcTm4EwelwAAALU"]
[Mon Jul 20 07:44:27.717703 2026] [security2:error] [pid 230396:tid 230642] [client 14.225.17.146:60938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "retzkolonglogistics.com"] [uri "/index.php"] [unique_id "al4mO3jLAau4tRDXyg9DPgAAAX0"], referer: http://retzkolonglogistics.com/WWW
[Mon Jul 20 07:44:27.750441 2026] [security2:error] [pid 229701:tid 229924] [client 77.110.127.138:55390] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mO3ZMWbdeOcTm4EwemwAAAOI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:27.793725 2026] [security2:error] [pid 230396:tid 230527] [client 39.46.9.231:64254] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mO3jLAau4tRDXyg9DQgAAAQo"]
[Mon Jul 20 07:44:27.793873 2026] [security2:error] [pid 230396:tid 230527] [client 39.46.9.231:64254] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mO3jLAau4tRDXyg9DQgAAAQo"]
[Mon Jul 20 07:44:27.802836 2026] [security2:error] [pid 229701:tid 229832] [client 136.158.60.21:61120] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mO3ZMWbdeOcTm4EwenwAAAIY"]
[Mon Jul 20 07:44:27.802934 2026] [security2:error] [pid 229701:tid 229832] [client 136.158.60.21:61120] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mO3ZMWbdeOcTm4EwenwAAAIY"]
[Mon Jul 20 07:44:27.826025 2026] [core:error] [pid 230396:tid 230629] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:27.826055 2026] [core:error] [pid 230396:tid 230629] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:27.874446 2026] [security2:error] [pid 230396:tid 230542] [client 14.225.17.146:58643] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "latiendadejorge.com.gt"] [uri "/index.php"] [unique_id "al4mO3jLAau4tRDXyg9DPQAAARk"], referer: http://latiendadejorge.com.gt/WWW
[Mon Jul 20 07:44:27.899350 2026] [security2:error] [pid 230396:tid 230584] [client 57.141.18.51:52826] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mN3jLAau4tRDXyg9CUAABQxs"]
[Mon Jul 20 07:44:27.993068 2026] [security2:error] [pid 230396:tid 230543] [client 143.244.57.90:48362] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/cms/wp-includes/wlwmanifest.xml"] [unique_id "al4mO3jLAau4tRDXyg9DUQAAARo"]
[Mon Jul 20 07:44:28.185340 2026] [security2:error] [pid 230396:tid 230468] [remote 192.178.6.7:0] ModSecurity: Access denied with code 429 (phase 2). Pattern match "Googlebot[\\\\/-]" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/google.conf"] [line "3"] [id "901003"] [msg "Googlebot Crawler 429 ADDED BY MONITORING DO NOT WHITELIST"] [hostname "cloudcast.ca"] [uri "/robots.txt"] [unique_id "al4mPHjLAau4tRDXyg9DVAABD0Y"]
[Mon Jul 20 07:44:28.198039 2026] [security2:error] [pid 230396:tid 230465] [remote 8.217.108.67:46106] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 67.108.217.8.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "toddnielsen.com"] [uri "/wp-login.php"] [unique_id "al4mPHjLAau4tRDXyg9DVgABG0M"], referer: https://toddnielsen.com/wp-login.php
[Mon Jul 20 07:44:28.207050 2026] [security2:error] [pid 230396:tid 230604] [client 104.207.37.121:25651] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 121.37.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mPHjLAau4tRDXyg9DUwAAAVc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:28.300297 2026] [security2:error] [pid 229701:tid 229889] [client 143.244.57.90:48374] ModSecurity: Access denied with code 406 (phase 1). Pattern match "/wp-includes/wlwmanifest\\\\.xml" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1541"] [id "900920"] [msg "wlwmanifest spam rule"] [hostname "cpcontacts.vzd.bbr.mybluehost.me"] [uri "/sito/wp-includes/wlwmanifest.xml"] [unique_id "al4mPHZMWbdeOcTm4EwesAAAAL8"]
[Mon Jul 20 07:44:28.425707 2026] [security2:error] [pid 229701:tid 229942] [client 104.207.58.157:29639] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 157.58.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mPHZMWbdeOcTm4EweswAAAPQ"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:44:28.522957 2026] [security2:error] [pid 230396:tid 230564] [client 114.119.134.152:51323] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.liquidationteam.com"] [uri "/product/gv-knit-waist-bermuda-shorts"] [unique_id "al4mPHjLAau4tRDXyg9DagAAAS8"], referer: https://www.liquidationteam.com/product/gv-knit-waist-bermuda-shorts
[Mon Jul 20 07:44:28.581832 2026] [security2:error] [pid 230396:tid 230612] [client 15.229.69.106:44992] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mPHjLAau4tRDXyg9DawAAAV8"]
[Mon Jul 20 07:44:28.581944 2026] [security2:error] [pid 230396:tid 230612] [client 15.229.69.106:44992] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mPHjLAau4tRDXyg9DawAAAV8"]
[Mon Jul 20 07:44:28.584863 2026] [security2:error] [pid 230396:tid 230552] [client 180.249.173.210:59230] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mPHjLAau4tRDXyg9DbQAAASM"]
[Mon Jul 20 07:44:28.584965 2026] [security2:error] [pid 230396:tid 230552] [client 180.249.173.210:59230] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mPHjLAau4tRDXyg9DbQAAASM"]
[Mon Jul 20 07:44:28.675700 2026] [security2:error] [pid 230396:tid 230624] [client 158.173.166.181:50579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mPHjLAau4tRDXyg9DcQAAAWs"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:44:28.727796 2026] [security2:error] [pid 230396:tid 230476] [remote 162.19.86.63:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4mPHjLAau4tRDXyg9DfwABEk4"]
[Mon Jul 20 07:44:28.776461 2026] [security2:error] [pid 229701:tid 229946] [client 65.111.23.76:16343] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 76.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mPHZMWbdeOcTm4EwevgAAAPg"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:28.898833 2026] [security2:error] [pid 230396:tid 230638] [client 216.244.66.243:35486] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4mPHjLAau4tRDXyg9DiwAAAXk"]
[Mon Jul 20 07:44:28.898949 2026] [security2:error] [pid 230396:tid 230638] [client 216.244.66.243:35486] ModSecurity: Warning. Matched phrase "Dotbot" at REQUEST_HEADERS:User-agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "lutheranphilosopher.com"] [uri "/robots.txt"] [unique_id "al4mPHjLAau4tRDXyg9DiwAAAXk"]
[Mon Jul 20 07:44:28.943599 2026] [security2:error] [pid 230396:tid 230478] [remote 162.19.86.63:50172] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 63.86.19.162.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "website-3c1c9eb1.nextlvlmarketingco.com"] [uri "/wp-login.php"] [unique_id "al4mPHjLAau4tRDXyg9DjAABR1A"], referer: https://website-3c1c9eb1.nextlvlmarketingco.com/wp-login.php
[Mon Jul 20 07:44:29.057687 2026] [security2:error] [pid 230396:tid 230563] [client 108.48.183.72:60173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4mPHjLAau4tRDXyg9DeAABLk0"]
[Mon Jul 20 07:44:29.068078 2026] [security2:error] [pid 230396:tid 230639] [client 45.3.46.142:44739] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 142.46.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mPXjLAau4tRDXyg9DlAAAAXo"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:44:29.071783 2026] [security2:error] [pid 230396:tid 230563] [client 108.48.183.72:60173] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4mPHjLAau4tRDXyg9DeQABLkg"]
[Mon Jul 20 07:44:29.080533 2026] [security2:error] [pid 230396:tid 230573] [client 114.119.147.13:20933] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "www.samdothan.org"] [uri "/stmap_97xnswz.html"] [unique_id "al4mPXjLAau4tRDXyg9DmQAAATg"], referer: https://www.samdothan.org/stmap_97xnswz.html?viagra.reglan.leukeran.lipitor
[Mon Jul 20 07:44:29.182669 2026] [security2:error] [pid 230396:tid 230493] [remote 202.51.202.242:56426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 242.202.51.202.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DoAABgV8"]
[Mon Jul 20 07:44:29.182930 2026] [security2:error] [pid 230396:tid 230646] [client 202.51.202.242:56426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DoAABgV8"]
[Mon Jul 20 07:44:29.347108 2026] [security2:error] [pid 229701:tid 229958] [client 65.111.20.77:24905] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 77.20.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mPXZMWbdeOcTm4Ewe1QAAAQQ"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:29.551397 2026] [security2:error] [pid 230396:tid 230536] [client 37.52.210.45:5597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DqwAAARM"]
[Mon Jul 20 07:44:29.551548 2026] [security2:error] [pid 230396:tid 230536] [client 37.52.210.45:5597] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DqwAAARM"]
[Mon Jul 20 07:44:29.602809 2026] [security2:error] [pid 230396:tid 230634] [client 155.2.215.77:45175] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DqgAAAXU"]
[Mon Jul 20 07:44:29.673057 2026] [security2:error] [pid 229701:tid 229923] [client 57.141.18.70:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mPXZMWbdeOcTm4Ewe4QAAAOE"]
[Mon Jul 20 07:44:29.834012 2026] [security2:error] [pid 230396:tid 230568] [client 154.192.233.184:62040] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DwAAAATM"]
[Mon Jul 20 07:44:29.834184 2026] [security2:error] [pid 230396:tid 230568] [client 154.192.233.184:62040] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mPXjLAau4tRDXyg9DwAAAATM"]
[Mon Jul 20 07:44:29.882966 2026] [security2:error] [pid 229701:tid 229934] [client 65.111.9.137:47709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 137.9.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mPXZMWbdeOcTm4Ewe9wAAAOw"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:29.926886 2026] [security2:error] [pid 230396:tid 230645] [client 14.225.17.146:61493] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "nevelow.com"] [uri "/index.php"] [unique_id "al4mPHjLAau4tRDXyg9DXgAAAYA"]
[Mon Jul 20 07:44:30.020113 2026] [security2:error] [pid 230396:tid 230610] [client 57.141.18.82:45320] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mOXjLAau4tRDXyg9C0AABXS8"]
[Mon Jul 20 07:44:30.217194 2026] [security2:error] [pid 230396:tid 230609] [client 149.0.16.108:59056] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mPnjLAau4tRDXyg9D1gAAAVw"]
[Mon Jul 20 07:44:30.217924 2026] [security2:error] [pid 230396:tid 230609] [client 149.0.16.108:59056] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mPnjLAau4tRDXyg9D1gAAAVw"]
[Mon Jul 20 07:44:30.464220 2026] [security2:error] [pid 230396:tid 230632] [client 104.207.51.28:36909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 28.51.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mPnjLAau4tRDXyg9D3QAAAXM"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:30.610485 2026] [security2:error] [pid 229701:tid 229857] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mPXZMWbdeOcTm4Ewe7AAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:30.620507 2026] [proxy:error] [pid 230396:tid 230547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:30.620546 2026] [proxy_http:error] [pid 230396:tid 230547] [client 104.155.181.6:56916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:30.622116 2026] [proxy:error] [pid 230396:tid 230547] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:30.622186 2026] [proxy_http:error] [pid 230396:tid 230547] [client 104.155.181.6:56916] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:30.705235 2026] [security2:error] [pid 230396:tid 230590] [client 162.141.167.14:41498] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.betterbonddogtraining.com"] [uri "/.env"] [unique_id "al4mPnjLAau4tRDXyg9D8AAAAUk"]
[Mon Jul 20 07:44:30.705250 2026] [security2:error] [pid 230396:tid 230626] [client 162.141.167.14:41526] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.betterbonddogtraining.com"] [uri "/backend/.env"] [unique_id "al4mPnjLAau4tRDXyg9D7wAAAW0"]
[Mon Jul 20 07:44:30.705439 2026] [security2:error] [pid 230396:tid 230615] [client 162.141.167.14:41534] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "autodiscover.betterbonddogtraining.com"] [uri "/api/.env"] [unique_id "al4mPnjLAau4tRDXyg9D-AAAAWI"]
[Mon Jul 20 07:44:30.726714 2026] [security2:error] [pid 230396:tid 230587] [client 77.110.127.138:55400] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/dist/wp-seo-local-vendor-1390.js"] [unique_id "al4mPnjLAau4tRDXyg9EAgAAAUY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:30.908101 2026] [security2:error] [pid 230396:tid 230591] [client 14.225.17.146:63411] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "elevator-data.com"] [uri "/index.php"] [unique_id "al4mPnjLAau4tRDXyg9EBwAAAUo"]
[Mon Jul 20 07:44:30.996708 2026] [security2:error] [pid 229701:tid 229881] [client 179.127.84.238:64093] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mPnZMWbdeOcTm4EwfMAAAALc"]
[Mon Jul 20 07:44:30.996920 2026] [security2:error] [pid 229701:tid 229881] [client 179.127.84.238:64093] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mPnZMWbdeOcTm4EwfMAAAALc"]
[Mon Jul 20 07:44:31.005675 2026] [security2:error] [pid 230396:tid 230620] [client 104.207.61.221:23843] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 221.61.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mP3jLAau4tRDXyg9EDAAAAWc"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:31.292637 2026] [security2:error] [pid 230396:tid 230590] [client 50.116.65.227:59772] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4mP3jLAau4tRDXyg9EIQAAAUk"]
[Mon Jul 20 07:44:31.305370 2026] [security2:error] [pid 230396:tid 230615] [client 50.116.65.227:31078] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "sesamegreenbeans.com"] [uri "/wp-content/uploads/2020/08/South-Africa-Day-5-Feature-Image.jpg"] [unique_id "al4mP3jLAau4tRDXyg9EIwAAAWI"]
[Mon Jul 20 07:44:31.311678 2026] [security2:error] [pid 230396:tid 230504] [remote 217.61.143.92:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4mP3jLAau4tRDXyg9EJQABWGo"]
[Mon Jul 20 07:44:31.383414 2026] [security2:error] [pid 229701:tid 229880] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mP3ZMWbdeOcTm4EwfNAAAALY"]
[Mon Jul 20 07:44:31.550357 2026] [security2:error] [pid 230396:tid 230505] [remote 217.61.143.92:56214] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4mP3jLAau4tRDXyg9ELgABGms"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:44:31.659924 2026] [security2:error] [pid 230396:tid 230533] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mP3jLAau4tRDXyg9ELAAAARA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:31.707011 2026] [security2:error] [pid 230396:tid 230654] [client 158.173.89.95:25953] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mP3jLAau4tRDXyg9ENQAAAYk"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:44:31.832278 2026] [security2:error] [pid 229701:tid 229722] [remote 5.161.225.162:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4mP3ZMWbdeOcTm4EwfWgAA_RQ"]
[Mon Jul 20 07:44:31.837942 2026] [security2:error] [pid 229701:tid 229848] [client 74.208.214.194:51410] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4mP3ZMWbdeOcTm4EwfWwAAAJY"]
[Mon Jul 20 07:44:31.865677 2026] [security2:error] [pid 230396:tid 230620] [client 77.110.127.138:55417] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mP3jLAau4tRDXyg9EOwAAAWc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:32.038746 2026] [security2:error] [pid 229701:tid 229717] [remote 5.161.225.162:53118] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 162.225.161.5.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "cephasnext.com"] [uri "/wp-login.php"] [unique_id "al4mQHZMWbdeOcTm4EwfZQABAQ8"], referer: https://cephasnext.com/wp-login.php
[Mon Jul 20 07:44:32.083703 2026] [security2:error] [pid 230396:tid 230555] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mP3jLAau4tRDXyg9EPAAAASY"]
[Mon Jul 20 07:44:32.120394 2026] [security2:error] [pid 230396:tid 230641] [client 14.225.17.146:53859] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dadanetnet.net"] [uri "/index.php"] [unique_id "al4mP3jLAau4tRDXyg9EPwAAAXw"], referer: http://dadanetnet.net/WWW
[Mon Jul 20 07:44:32.256477 2026] [security2:error] [pid 230396:tid 230649] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mQHjLAau4tRDXyg9EQwAAAYQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:32.301262 2026] [security2:error] [pid 230396:tid 230617] [client 57.141.18.78:37862] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mPHjLAau4tRDXyg9DZAABZEE"]
[Mon Jul 20 07:44:32.501852 2026] [security2:error] [pid 230396:tid 230638] [client 14.251.3.155:56495] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad"] [uri "/wpad.dat"] [unique_id "al4mQHjLAau4tRDXyg9EUQAAAXk"]
[Mon Jul 20 07:44:32.764082 2026] [security2:error] [pid 230396:tid 230516] [remote 173.249.4.11:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mQHjLAau4tRDXyg9EZAABEXY"]
[Mon Jul 20 07:44:32.950826 2026] [security2:error] [pid 230396:tid 230514] [remote 173.249.4.11:55612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 11.4.249.173.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "rrf.lcd.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mQHjLAau4tRDXyg9EcQABZnQ"], referer: https://rrf.lcd.mybluehost.me/wp-login.php
[Mon Jul 20 07:44:33.304518 2026] [security2:error] [pid 229701:tid 229889] [client 54.169.146.187:17388] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mQXZMWbdeOcTm4EwflgAAAL8"]
[Mon Jul 20 07:44:33.304639 2026] [security2:error] [pid 229701:tid 229889] [client 54.169.146.187:17388] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mQXZMWbdeOcTm4EwflgAAAL8"]
[Mon Jul 20 07:44:33.473362 2026] [security2:error] [pid 229701:tid 229865] [client 77.110.127.138:55435] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/wpseo-local/js0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/dist/wp-seo-local-vendor-1390.js"] [unique_id "al4mQXZMWbdeOcTm4EwfogAAAKc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:33.552593 2026] [security2:error] [pid 229701:tid 229781] [remote 45.90.123.233:43534] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mQXZMWbdeOcTm4EwfqgAAz08"]
[Mon Jul 20 07:44:33.552764 2026] [security2:error] [pid 229701:tid 229905] [client 45.90.123.233:43534] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mQXZMWbdeOcTm4EwfqgAAz08"]
[Mon Jul 20 07:44:33.749697 2026] [security2:error] [pid 229701:tid 229957] [client 14.225.17.146:58761] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "reosportsboats.com"] [uri "/index.php"] [unique_id "al4mQHZMWbdeOcTm4EwfbAAAAQM"], referer: http://reosportsboats.com/WWW
[Mon Jul 20 07:44:34.045851 2026] [security2:error] [pid 230396:tid 230522] [remote 72.167.132.114:36520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4mQnjLAau4tRDXyg9EmwABY3w"]
[Mon Jul 20 07:44:34.136390 2026] [security2:error] [pid 229701:tid 229917] [client 14.225.17.146:58794] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "swafforddetailing.com"] [uri "/index.php"] [unique_id "al4mQHZMWbdeOcTm4EwfdQAAANs"], referer: http://swafforddetailing.com/WWW
[Mon Jul 20 07:44:34.266879 2026] [security2:error] [pid 230396:tid 230422] [remote 72.167.132.114:36520] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "locketsandcharms.com"] [uri "/wp-login.php"] [unique_id "al4mQnjLAau4tRDXyg9EvgABahg"], referer: https://locketsandcharms.com/wp-login.php
[Mon Jul 20 07:44:34.329496 2026] [security2:error] [pid 229701:tid 229921] [client 57.141.18.4:63762] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mPnZMWbdeOcTm4EwfDgAA324"]
[Mon Jul 20 07:44:34.498676 2026] [security2:error] [pid 230396:tid 230580] [client 14.225.17.146:58856] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.justinagrayman.com"] [uri "/index.php"] [unique_id "al4mQHjLAau4tRDXyg9ETQAAAT8"], referer: http://www.justinagrayman.com/WWW
[Mon Jul 20 07:44:34.723731 2026] [security2:error] [pid 229701:tid 229883] [client 14.225.17.146:63283] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.reosportsboats.com"] [uri "/index.php"] [unique_id "al4mQnZMWbdeOcTm4Ewf0gAAALk"], referer: https://reosportsboats.com/WWW
[Mon Jul 20 07:44:34.824424 2026] [security2:error] [pid 230396:tid 230561] [client 108.48.183.72:60187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4mQnjLAau4tRDXyg9ExgABLBY"]
[Mon Jul 20 07:44:34.981682 2026] [security2:error] [pid 229701:tid 229904] [client 52.167.144.227:61529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4mQnZMWbdeOcTm4Ewf3QAAzmI"]
[Mon Jul 20 07:44:35.285030 2026] [security2:error] [pid 230396:tid 230527] [client 57.141.18.117:25890] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mP3jLAau4tRDXyg9EJAABCmk"]
[Mon Jul 20 07:44:35.405237 2026] [security2:error] [pid 230396:tid 230595] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mQ3jLAau4tRDXyg9E4QAAAU4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:35.491345 2026] [security2:error] [pid 229701:tid 229890] [client 186.221.114.200:61831] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mQ3ZMWbdeOcTm4Ewf_gAAAMA"]
[Mon Jul 20 07:44:35.491487 2026] [security2:error] [pid 229701:tid 229890] [client 186.221.114.200:61831] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mQ3ZMWbdeOcTm4Ewf_gAAAMA"]
[Mon Jul 20 07:44:35.685417 2026] [security2:error] [pid 230396:tid 230555] [client 14.225.17.146:61188] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "onewingpictures.com"] [uri "/index.php"] [unique_id "al4mQXjLAau4tRDXyg9EfwAAASY"], referer: http://onewingpictures.com/WWW
[Mon Jul 20 07:44:35.701909 2026] [security2:error] [pid 229701:tid 229709] [remote 98.156.100.191:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4mQ3ZMWbdeOcTm4EwgBAAA0Ac"]
[Mon Jul 20 07:44:35.745657 2026] [security2:error] [pid 230396:tid 230606] [client 14.225.17.146:63490] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "maplerespiteservices.com"] [uri "/index.php"] [unique_id "al4mQnjLAau4tRDXyg9EngAAAVk"], referer: http://maplerespiteservices.com/WWW
[Mon Jul 20 07:44:35.752047 2026] [security2:error] [pid 229701:tid 229856] [client 77.110.127.138:55449] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mQ3ZMWbdeOcTm4EwgCQAAAJ4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:35.826047 2026] [security2:error] [pid 229701:tid 229913] [client 50.116.65.227:31186] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mQ3ZMWbdeOcTm4EwgCwAAANc"]
[Mon Jul 20 07:44:35.836442 2026] [security2:error] [pid 229701:tid 229902] [client 50.116.65.227:31194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mQ3ZMWbdeOcTm4EwgDAAAAMw"]
[Mon Jul 20 07:44:35.897363 2026] [security2:error] [pid 230396:tid 230644] [client 103.139.191.61:61681] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mQ3jLAau4tRDXyg9E7gAAAX8"]
[Mon Jul 20 07:44:35.897490 2026] [security2:error] [pid 230396:tid 230644] [client 103.139.191.61:61681] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mQ3jLAau4tRDXyg9E7gAAAX8"]
[Mon Jul 20 07:44:36.080381 2026] [security2:error] [pid 229701:tid 229859] [client 57.141.18.54:25960] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mQHZMWbdeOcTm4EwfaQAAoSU"]
[Mon Jul 20 07:44:36.130948 2026] [security2:error] [pid 229701:tid 229880] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mQ3ZMWbdeOcTm4EwgDgAAALY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:36.365651 2026] [security2:error] [pid 230396:tid 230625] [client 50.116.65.227:31196] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "recruitinginsight.us"] [uri "/wp-cron.php"] [unique_id "al4mRHjLAau4tRDXyg9FAQAAAWw"]
[Mon Jul 20 07:44:36.369075 2026] [security2:error] [pid 230396:tid 230624] [client 14.225.17.146:61398] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "recruitinginsight.us"] [uri "/index.php"] [unique_id "al4mQnjLAau4tRDXyg9E1gAAAWs"], referer: http://recruitinginsight.us/WWW
[Mon Jul 20 07:44:36.480363 2026] [security2:error] [pid 229701:tid 229720] [remote 100.42.189.89:40698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4mRHZMWbdeOcTm4EwgJQAApxI"]
[Mon Jul 20 07:44:36.613732 2026] [security2:error] [pid 229701:tid 229947] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mRHZMWbdeOcTm4EwgHwAAAPk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:36.695810 2026] [security2:error] [pid 229701:tid 229705] [remote 100.42.189.89:40698] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 89.189.42.100.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mail.sarahholyfield.com"] [uri "/wp-login.php"] [unique_id "al4mRHZMWbdeOcTm4EwgOAAAwAM"], referer: https://mail.sarahholyfield.com/wp-login.php
[Mon Jul 20 07:44:36.697395 2026] [security2:error] [pid 229701:tid 229711] [remote 74.7.227.185:34848] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.227.7.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "verdunestate.com"] [uri "/wp-login.php"] [unique_id "al4mRHZMWbdeOcTm4EwgOQAA4wk"], referer: https://verdunestate.com/property/office-for-rent-ashrafia/
[Mon Jul 20 07:44:36.712967 2026] [security2:error] [pid 230396:tid 230583] [client 103.106.165.44:62224] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mRHjLAau4tRDXyg9FDgAAAUI"]
[Mon Jul 20 07:44:36.713092 2026] [security2:error] [pid 230396:tid 230583] [client 103.106.165.44:62224] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mRHjLAau4tRDXyg9FDgAAAUI"]
[Mon Jul 20 07:44:36.734476 2026] [security2:error] [pid 230396:tid 230585] [client 74.208.214.194:60222] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4mRHjLAau4tRDXyg9FEQAAAUQ"]
[Mon Jul 20 07:44:36.742505 2026] [security2:error] [pid 230396:tid 230632] [client 36.93.152.155:52983] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mRHjLAau4tRDXyg9FFAAAAXM"]
[Mon Jul 20 07:44:36.742583 2026] [security2:error] [pid 230396:tid 230632] [client 36.93.152.155:52983] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mRHjLAau4tRDXyg9FFAAAAXM"]
[Mon Jul 20 07:44:37.226666 2026] [security2:error] [pid 229701:tid 229729] [remote 152.228.213.32:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mRXZMWbdeOcTm4EwgUAAA7xs"]
[Mon Jul 20 07:44:37.404300 2026] [security2:error] [pid 229701:tid 229735] [remote 152.228.213.32:50862] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mRXZMWbdeOcTm4EwgWAAAziE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:44:37.442381 2026] [security2:error] [pid 229701:tid 229748] [remote 98.156.100.191:36638] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 191.100.156.98.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nextlevelpressurewashing.com"] [uri "/wp-login.php"] [unique_id "al4mRXZMWbdeOcTm4EwgWQAAwS4"], referer: https://nextlevelpressurewashing.com/wp-login.php
[Mon Jul 20 07:44:37.822400 2026] [security2:error] [pid 229701:tid 229895] [client 57.141.18.43:56348] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mQnZMWbdeOcTm4EwfwQAAxVg"]
[Mon Jul 20 07:44:37.932695 2026] [security2:error] [pid 230396:tid 230601] [client 14.225.17.146:64092] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "savilerowtravel.com"] [uri "/index.php"] [unique_id "al4mRXjLAau4tRDXyg9FLAAAAVQ"], referer: http://savilerowtravel.com/WWW
[Mon Jul 20 07:44:38.436078 2026] [security2:error] [pid 230396:tid 230624] [client 39.46.9.231:64683] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mRnjLAau4tRDXyg9FRAAAAWs"]
[Mon Jul 20 07:44:38.436209 2026] [security2:error] [pid 230396:tid 230624] [client 39.46.9.231:64683] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mRnjLAau4tRDXyg9FRAAAAWs"]
[Mon Jul 20 07:44:38.554598 2026] [security2:error] [pid 230396:tid 230585] [client 136.158.60.21:62773] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mRnjLAau4tRDXyg9FSwAAAUQ"]
[Mon Jul 20 07:44:38.554709 2026] [security2:error] [pid 230396:tid 230585] [client 136.158.60.21:62773] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mRnjLAau4tRDXyg9FSwAAAUQ"]
[Mon Jul 20 07:44:38.710361 2026] [security2:error] [pid 229701:tid 229946] [client 45.3.52.99:22385] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 99.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mRnZMWbdeOcTm4EwgiQAAAPg"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:44:38.932062 2026] [security2:error] [pid 230396:tid 230557] [client 14.225.17.146:64205] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.savilerowtravel.com"] [uri "/index.php"] [unique_id "al4mRnjLAau4tRDXyg9FUwAAASg"], referer: https://savilerowtravel.com/WWW
[Mon Jul 20 07:44:39.060269 2026] [security2:error] [pid 230396:tid 230602] [client 56.125.35.21:37206] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.35.125.56.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mR3jLAau4tRDXyg9FXAAAAVU"]
[Mon Jul 20 07:44:39.060359 2026] [security2:error] [pid 230396:tid 230602] [client 56.125.35.21:37206] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mR3jLAau4tRDXyg9FXAAAAVU"]
[Mon Jul 20 07:44:39.156603 2026] [security2:error] [pid 229701:tid 229937] [client 51.195.39.149:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.benbayly.co.nz"] [uri "/index.php"] [unique_id "al4mRnZMWbdeOcTm4EwgjQAA7zw"]
[Mon Jul 20 07:44:39.431609 2026] [security2:error] [pid 230396:tid 230610] [client 13.233.207.33:40426] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 33.207.233.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mR3jLAau4tRDXyg9FYwAAAV0"]
[Mon Jul 20 07:44:39.431693 2026] [security2:error] [pid 230396:tid 230610] [client 13.233.207.33:40426] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mR3jLAau4tRDXyg9FYwAAAV0"]
[Mon Jul 20 07:44:39.517800 2026] [security2:error] [pid 230396:tid 230615] [client 180.249.173.210:59749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mR3jLAau4tRDXyg9FZAAAAWI"]
[Mon Jul 20 07:44:39.518688 2026] [security2:error] [pid 230396:tid 230615] [client 180.249.173.210:59749] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mR3jLAau4tRDXyg9FZAAAAWI"]
[Mon Jul 20 07:44:39.584580 2026] [security2:error] [pid 229701:tid 229932] [client 77.110.127.138:55473] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mR3ZMWbdeOcTm4EwgugAAAOo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:40.289280 2026] [security2:error] [pid 230396:tid 230583] [client 142.111.152.62:27147] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mSHjLAau4tRDXyg9FbQAAAUI"]
[Mon Jul 20 07:44:40.300009 2026] [security2:error] [pid 230396:tid 230573] [client 14.225.17.146:64324] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "karimnawfal.com"] [uri "/index.php"] [unique_id "al4mR3jLAau4tRDXyg9FZgAAATg"]
[Mon Jul 20 07:44:40.311741 2026] [security2:error] [pid 229701:tid 229856] [client 154.192.233.184:62428] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mSHZMWbdeOcTm4Ewg7gAAAJ4"]
[Mon Jul 20 07:44:40.311909 2026] [security2:error] [pid 229701:tid 229856] [client 154.192.233.184:62428] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mSHZMWbdeOcTm4Ewg7gAAAJ4"]
[Mon Jul 20 07:44:40.547464 2026] [security2:error] [pid 229701:tid 229911] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mSHZMWbdeOcTm4Ewg8QAAANU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:40.649996 2026] [security2:error] [pid 229701:tid 229900] [client 57.141.18.46:65254] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mRXZMWbdeOcTm4EwgSQAAyhE"]
[Mon Jul 20 07:44:40.728324 2026] [security2:error] [pid 229701:tid 229927] [client 104.207.42.143:28541] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 143.42.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mSHZMWbdeOcTm4Ewg_gAAAOU"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:40.786603 2026] [security2:error] [pid 229701:tid 229851] [client 37.52.210.45:58110] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mSHZMWbdeOcTm4EwhBQAAAJk"]
[Mon Jul 20 07:44:40.786713 2026] [security2:error] [pid 229701:tid 229851] [client 37.52.210.45:58110] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mSHZMWbdeOcTm4EwhBQAAAJk"]
[Mon Jul 20 07:44:40.864219 2026] [security2:error] [pid 229701:tid 229850] [client 149.0.16.108:59579] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mSHZMWbdeOcTm4EwhCQAAAJg"]
[Mon Jul 20 07:44:40.864313 2026] [security2:error] [pid 229701:tid 229850] [client 149.0.16.108:59579] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mSHZMWbdeOcTm4EwhCQAAAJg"]
[Mon Jul 20 07:44:40.985703 2026] [security2:error] [pid 230396:tid 230643] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mSHjLAau4tRDXyg9FhAAAAX4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:41.184655 2026] [security2:error] [pid 230396:tid 230466] [remote 68.178.165.65:41162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4mSXjLAau4tRDXyg9FkAABI0Q"]
[Mon Jul 20 07:44:41.233044 2026] [security2:error] [pid 230396:tid 230555] [client 14.225.17.146:61880] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mollycahill.com"] [uri "/index.php"] [unique_id "al4mSHjLAau4tRDXyg9FhQAAASY"], referer: http://mollycahill.com/WWW
[Mon Jul 20 07:44:41.278237 2026] [security2:error] [pid 230396:tid 230654] [client 104.207.55.29:23919] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 29.55.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mSXjLAau4tRDXyg9FlgAAAYk"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:41.426681 2026] [security2:error] [pid 230396:tid 230468] [remote 152.228.213.32:50868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mSXjLAau4tRDXyg9FoQABakY"]
[Mon Jul 20 07:44:41.467236 2026] [security2:error] [pid 230396:tid 230635] [client 179.127.84.238:64841] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mSXjLAau4tRDXyg9FowAAAXY"]
[Mon Jul 20 07:44:41.467364 2026] [security2:error] [pid 230396:tid 230635] [client 179.127.84.238:64841] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mSXjLAau4tRDXyg9FowAAAXY"]
[Mon Jul 20 07:44:41.497787 2026] [security2:error] [pid 230396:tid 230615] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mSXjLAau4tRDXyg9FmAAAAWI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:41.656705 2026] [security2:error] [pid 230396:tid 230465] [remote 152.228.213.32:50868] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 32.213.228.152.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz"] [uri "/wp-login.php"] [unique_id "al4mSXjLAau4tRDXyg9FpwABNEM"], referer: https://aosta.nz/wp-login.php
[Mon Jul 20 07:44:41.733446 2026] [security2:error] [pid 229701:tid 229710] [remote 216.73.216.55:15684] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.216.73.216.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/training-temp"] [unique_id "al4mSXZMWbdeOcTm4EwhKAAA0wg"]
[Mon Jul 20 07:44:41.819219 2026] [security2:error] [pid 230396:tid 230547] [client 45.3.43.210:27335] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.43.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mSXjLAau4tRDXyg9FrQAAAR4"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:41.822255 2026] [security2:error] [pid 230396:tid 230467] [remote 68.178.165.65:41162] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 65.165.178.68.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-login.php"] [unique_id "al4mSXjLAau4tRDXyg9FrwABUEU"], referer: https://mezzacraft.com/wp-login.php
[Mon Jul 20 07:44:41.891170 2026] [security2:error] [pid 230396:tid 230653] [client 57.141.18.76:63068] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mRnjLAau4tRDXyg9FSQABiCo"]
[Mon Jul 20 07:44:42.082536 2026] [security2:error] [pid 230396:tid 230621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mSXjLAau4tRDXyg9FsgAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:42.395562 2026] [security2:error] [pid 230396:tid 230559] [client 168.144.19.97:56492] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-editor-context.php"] [unique_id "al4mSnjLAau4tRDXyg9FwwAAASo"], referer: binance.com
[Mon Jul 20 07:44:42.422968 2026] [security2:error] [pid 230396:tid 230576] [client 65.111.31.30:17985] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 30.31.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mSnjLAau4tRDXyg9FwQAAATs"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:42.547656 2026] [security2:error] [pid 230396:tid 230599] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mSnjLAau4tRDXyg9FvwAAAVI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:42.632238 2026] [security2:error] [pid 230396:tid 230587] [client 14.225.17.146:63916] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "areitoproducciones.com"] [uri "/index.php"] [unique_id "al4mRnjLAau4tRDXyg9FVwAAAUY"], referer: http://areitoproducciones.com/WWW
[Mon Jul 20 07:44:43.201790 2026] [proxy:error] [pid 230396:tid 230544] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:43.201838 2026] [proxy_http:error] [pid 230396:tid 230544] [client 104.155.181.6:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:43.202429 2026] [proxy:error] [pid 230396:tid 230544] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:43.202452 2026] [proxy_http:error] [pid 230396:tid 230544] [client 104.155.181.6:60958] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:43.263362 2026] [security2:error] [pid 229701:tid 229833] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mS3ZMWbdeOcTm4EwhYAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:43.884659 2026] [security2:error] [pid 230396:tid 230564] [client 185.198.240.153:25253] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "testingroomtv.com"] [uri "/"] [unique_id "al4mS3jLAau4tRDXyg9GFAAAAS8"], referer: http://thetestingroomtv.com/
[Mon Jul 20 07:44:44.052325 2026] [security2:error] [pid 230396:tid 230596] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mS3jLAau4tRDXyg9GEwAAAU8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:44.112264 2026] [proxy:error] [pid 230396:tid 230569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:44.112297 2026] [proxy_http:error] [pid 230396:tid 230569] [client 104.155.181.6:46556] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:44.112975 2026] [proxy:error] [pid 230396:tid 230569] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:44.113010 2026] [proxy_http:error] [pid 230396:tid 230569] [client 104.155.181.6:46556] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:44.563715 2026] [security2:error] [pid 229701:tid 229887] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mTHZMWbdeOcTm4EwhjAAAAL0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:44.694561 2026] [security2:error] [pid 230396:tid 230645] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mTHjLAau4tRDXyg9GOgAAAYA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:45.020881 2026] [security2:error] [pid 229701:tid 229836] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mTHZMWbdeOcTm4EwhnQAAAIo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:45.248722 2026] [security2:error] [pid 229701:tid 229833] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mTXZMWbdeOcTm4EwhqgAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:45.431396 2026] [core:error] [pid 230396:tid 230542] [client 54.174.58.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:45.431424 2026] [core:error] [pid 230396:tid 230542] [client 54.174.58.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:45.487397 2026] [security2:error] [pid 230396:tid 230514] [remote 57.141.18.74:25818] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 74.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3359665"] [unique_id "al4mTXjLAau4tRDXyg9GcQABe3Q"]
[Mon Jul 20 07:44:45.569977 2026] [security2:error] [pid 230396:tid 230607] [client 14.225.17.146:62232] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "learnthissecret.com"] [uri "/index.php"] [unique_id "al4mTHjLAau4tRDXyg9GOQAAAVo"]
[Mon Jul 20 07:44:45.688441 2026] [core:error] [pid 230396:tid 230559] [client 54.174.58.239:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:45.688466 2026] [core:error] [pid 230396:tid 230559] [client 54.174.58.239:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:45.809593 2026] [proxy:error] [pid 230396:tid 230615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:45.809678 2026] [proxy_http:error] [pid 230396:tid 230615] [client 205.210.31.2:60760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:45.810498 2026] [proxy:error] [pid 230396:tid 230615] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:45.810547 2026] [proxy_http:error] [pid 230396:tid 230615] [client 205.210.31.2:60760] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:45.875553 2026] [core:error] [pid 229701:tid 229831] [client 54.174.58.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:45.875576 2026] [core:error] [pid 229701:tid 229831] [client 54.174.58.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:46.004982 2026] [core:error] [pid 229701:tid 229863] [client 54.174.58.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:46.005011 2026] [core:error] [pid 229701:tid 229863] [client 54.174.58.227:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:46.112273 2026] [security2:error] [pid 230396:tid 230654] [client 14.225.17.146:63164] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "idigress.group"] [uri "/index.php"] [unique_id "al4mTXjLAau4tRDXyg9GeQAAAYk"], referer: http://idigress.group/WWW
[Mon Jul 20 07:44:46.320408 2026] [security2:error] [pid 229701:tid 229930] [client 186.221.114.200:62304] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mTnZMWbdeOcTm4Ewh7AAAAOg"]
[Mon Jul 20 07:44:46.320560 2026] [security2:error] [pid 229701:tid 229930] [client 186.221.114.200:62304] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mTnZMWbdeOcTm4Ewh7AAAAOg"]
[Mon Jul 20 07:44:46.561867 2026] [security2:error] [pid 230396:tid 230558] [client 57.141.18.121:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mTnjLAau4tRDXyg9GjgAAASk"]
[Mon Jul 20 07:44:46.596980 2026] [security2:error] [pid 229701:tid 229850] [client 103.139.191.61:62198] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mTnZMWbdeOcTm4Ewh-wAAAJg"]
[Mon Jul 20 07:44:46.597088 2026] [security2:error] [pid 229701:tid 229850] [client 103.139.191.61:62198] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mTnZMWbdeOcTm4Ewh-wAAAJg"]
[Mon Jul 20 07:44:47.157229 2026] [security2:error] [pid 229701:tid 229933] [client 103.106.165.44:62708] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiIAAAAOs"]
[Mon Jul 20 07:44:47.157332 2026] [security2:error] [pid 229701:tid 229933] [client 103.106.165.44:62708] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiIAAAAOs"]
[Mon Jul 20 07:44:47.176314 2026] [security2:error] [pid 229701:tid 229951] [client 36.93.152.155:53506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiIQAAAP0"]
[Mon Jul 20 07:44:47.176398 2026] [security2:error] [pid 229701:tid 229951] [client 36.93.152.155:53506] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiIQAAAP0"]
[Mon Jul 20 07:44:47.204630 2026] [security2:error] [pid 230396:tid 230557] [client 77.110.127.138:55544] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mT3jLAau4tRDXyg9GoQAAASg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:47.353833 2026] [security2:error] [pid 229701:tid 229769] [remote 217.61.143.92:41762] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 92.143.61.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiMAAAwkM"]
[Mon Jul 20 07:44:47.353944 2026] [security2:error] [pid 229701:tid 229892] [client 217.61.143.92:41762] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "zbj.ahr.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiMAAAwkM"]
[Mon Jul 20 07:44:47.373665 2026] [security2:error] [pid 229701:tid 229862] [client 139.59.118.64:58895] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "servicare-mx.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiMwAAAKQ"]
[Mon Jul 20 07:44:47.388965 2026] [security2:error] [pid 230396:tid 230633] [client 168.144.19.97:54657] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-metadata-registry.php"] [unique_id "al4mT3jLAau4tRDXyg9GowAAAXQ"], referer: binance.com
[Mon Jul 20 07:44:47.793944 2026] [security2:error] [pid 229701:tid 229746] [remote 160.187.68.132:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiRAAAoiw"]
[Mon Jul 20 07:44:47.811650 2026] [security2:error] [pid 230396:tid 230628] [client 185.61.48.44:51902] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "techtradeinc.com"] [uri "/index.php"] [unique_id "al4mTnjLAau4tRDXyg9GnAAAAW8"]
[Mon Jul 20 07:44:47.914330 2026] [security2:error] [pid 229701:tid 229854] [client 50.116.65.227:54244] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mT3ZMWbdeOcTm4EwiVAAAAJw"]
[Mon Jul 20 07:44:47.926237 2026] [security2:error] [pid 229701:tid 229864] [client 50.116.65.227:54260] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mT3ZMWbdeOcTm4EwiVgAAAKY"]
[Mon Jul 20 07:44:48.128110 2026] [security2:error] [pid 229701:tid 229842] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mT3ZMWbdeOcTm4EwiUgAAAJA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:48.396980 2026] [security2:error] [pid 229701:tid 229745] [remote 160.187.68.132:45510] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "iagdevelopments.com"] [uri "/wp-login.php"] [unique_id "al4mUHZMWbdeOcTm4EwibQAAsCs"], referer: https://iagdevelopments.com/wp-login.php
[Mon Jul 20 07:44:48.603457 2026] [security2:error] [pid 230396:tid 230569] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mUHjLAau4tRDXyg9GyQAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:48.786968 2026] [security2:error] [pid 230396:tid 230547] [client 14.225.17.146:64556] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4mUHjLAau4tRDXyg9GzAAAAR4"], referer: http://sesamegreenbeans.com/WWW
[Mon Jul 20 07:44:48.800393 2026] [security2:error] [pid 229701:tid 229839] [client 57.141.18.77:59760] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mTXZMWbdeOcTm4EwhsQAAjVk"]
[Mon Jul 20 07:44:48.828515 2026] [security2:error] [pid 230396:tid 230637] [client 77.110.127.138:55550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/if(now()=sysdate(),sleep(15),0)/page/page/3/"] [unique_id "al4mUHjLAau4tRDXyg9G0wAAAXg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:49.029194 2026] [security2:error] [pid 229701:tid 229949] [client 180.249.173.210:60270] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXZMWbdeOcTm4EwilAAAAPs"]
[Mon Jul 20 07:44:49.030408 2026] [security2:error] [pid 229701:tid 229949] [client 180.249.173.210:60270] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXZMWbdeOcTm4EwilAAAAPs"]
[Mon Jul 20 07:44:49.223962 2026] [security2:error] [pid 230396:tid 230545] [client 136.158.60.21:64320] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXjLAau4tRDXyg9G3QAAARw"]
[Mon Jul 20 07:44:49.224108 2026] [security2:error] [pid 230396:tid 230545] [client 136.158.60.21:64320] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXjLAau4tRDXyg9G3QAAARw"]
[Mon Jul 20 07:44:49.229776 2026] [security2:error] [pid 230396:tid 230546] [client 66.249.73.68:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "cathybuffini.com"] [uri "/index.php"] [unique_id "al4mUXjLAau4tRDXyg9G1wAAAR0"]
[Mon Jul 20 07:44:49.265771 2026] [security2:error] [pid 229701:tid 229764] [remote 72.167.132.114:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4mUXZMWbdeOcTm4EwiqAAAkj4"]
[Mon Jul 20 07:44:49.414075 2026] [security2:error] [pid 230396:tid 230615] [client 108.48.183.72:60189] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "healthylifegourmet.org"] [uri "/index.php"] [unique_id "al4mUXjLAau4tRDXyg9G1gABYn4"]
[Mon Jul 20 07:44:49.483770 2026] [security2:error] [pid 230396:tid 230595] [client 39.46.9.231:65116] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXjLAau4tRDXyg9G7QAAAU4"]
[Mon Jul 20 07:44:49.483873 2026] [security2:error] [pid 230396:tid 230595] [client 39.46.9.231:65116] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXjLAau4tRDXyg9G7QAAAU4"]
[Mon Jul 20 07:44:49.490736 2026] [security2:error] [pid 229701:tid 229775] [remote 72.167.132.114:52028] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 114.132.167.72.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "alexsandbergmusic.com"] [uri "/wp-login.php"] [unique_id "al4mUXZMWbdeOcTm4EwirQAAxEk"], referer: https://alexsandbergmusic.com/wp-login.php
[Mon Jul 20 07:44:49.528119 2026] [security2:error] [pid 229701:tid 229868] [client 15.229.69.106:43016] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXZMWbdeOcTm4EwisAAAAKo"]
[Mon Jul 20 07:44:49.528211 2026] [security2:error] [pid 229701:tid 229868] [client 15.229.69.106:43016] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mUXZMWbdeOcTm4EwisAAAAKo"]
[Mon Jul 20 07:44:49.747342 2026] [security2:error] [pid 230396:tid 230573] [client 195.26.241.79:45480] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4mUXjLAau4tRDXyg9HAQAAATg"]
[Mon Jul 20 07:44:49.786553 2026] [security2:error] [pid 230396:tid 230627] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mUXjLAau4tRDXyg9G8gAAAW4"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:49.786766 2026] [security2:error] [pid 230396:tid 230611] [client 14.225.17.146:65012] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.sesamegreenbeans.com"] [uri "/index.php"] [unique_id "al4mUXjLAau4tRDXyg9G9AAAAV4"], referer: https://sesamegreenbeans.com/WWW
[Mon Jul 20 07:44:49.868129 2026] [security2:error] [pid 229701:tid 229865] [client 195.26.241.79:45516] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4mUXZMWbdeOcTm4EwiwQAAAKc"]
[Mon Jul 20 07:44:49.889142 2026] [security2:error] [pid 230396:tid 230560] [client 14.225.17.146:65014] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "itdynamix.com"] [uri "/index.php"] [unique_id "al4mUXjLAau4tRDXyg9G-AAAASs"], referer: http://itdynamix.com/WWW
[Mon Jul 20 07:44:50.003287 2026] [security2:error] [pid 230396:tid 230596] [client 195.26.241.79:45554] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5936.bluehost.com"] [uri "/blog/"] [unique_id "al4mUnjLAau4tRDXyg9HCQAAAU8"]
[Mon Jul 20 07:44:50.164416 2026] [security2:error] [pid 230396:tid 230422] [remote 84.247.172.23:48678] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 23.172.247.84.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mUnjLAau4tRDXyg9HEgABVxg"]
[Mon Jul 20 07:44:50.164612 2026] [security2:error] [pid 230396:tid 230604] [client 84.247.172.23:48678] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mUnjLAau4tRDXyg9HEgABVxg"]
[Mon Jul 20 07:44:50.259521 2026] [security2:error] [pid 230396:tid 230619] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mUnjLAau4tRDXyg9HEAAAAWY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:50.472804 2026] [security2:error] [pid 230396:tid 230603] [client 51.68.107.148:30313] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "espiritualidadmoderna.com"] [uri "/robots.txt"] [unique_id "al4mUnjLAau4tRDXyg9HIAAAAVY"]
[Mon Jul 20 07:44:50.472906 2026] [security2:error] [pid 230396:tid 230603] [client 51.68.107.148:30313] ModSecurity: Warning. Matched phrase "MJ12bot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "espiritualidadmoderna.com"] [uri "/robots.txt"] [unique_id "al4mUnjLAau4tRDXyg9HIAAAAVY"]
[Mon Jul 20 07:44:50.541953 2026] [security2:error] [pid 230396:tid 230630] [client 216.24.212.40:0] ModSecurity: Access denied with code 406 (phase 1). Match of "ipMatch 127.0.0.1" against "REMOTE_ADDR" required. [file "/opt/mod_security/hg_rules.conf"] [line "1461"] [id "909116"] [msg "Golang default UA"] [hostname "ttb-sa.com"] [uri "/wp-includes/css/buttons.css"] [unique_id "al4mUnjLAau4tRDXyg9HIwAAAXE"]
[Mon Jul 20 07:44:50.581014 2026] [security2:error] [pid 229701:tid 229810] [remote 47.86.33.52:39316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4mUnZMWbdeOcTm4Ewi3gAAjWw"]
[Mon Jul 20 07:44:50.700440 2026] [security2:error] [pid 230396:tid 230629] [client 77.110.127.138:55561] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 239 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mUnjLAau4tRDXyg9HLgAAAXA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:50.858997 2026] [security2:error] [pid 230396:tid 230635] [client 77.110.127.138:55563] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mUnjLAau4tRDXyg9HNwAAAXY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:50.887076 2026] [security2:error] [pid 229701:tid 229935] [client 154.192.233.184:60914] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mUnZMWbdeOcTm4Ewi5wAAAO0"]
[Mon Jul 20 07:44:50.887269 2026] [security2:error] [pid 229701:tid 229935] [client 154.192.233.184:60914] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mUnZMWbdeOcTm4Ewi5wAAAO0"]
[Mon Jul 20 07:44:50.902357 2026] [security2:error] [pid 230396:tid 230582] [client 142.111.152.183:51167] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mUnjLAau4tRDXyg9HMAAAAUE"]
[Mon Jul 20 07:44:50.934166 2026] [security2:error] [pid 230396:tid 230595] [client 14.225.17.146:65497] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.itdynamix.com"] [uri "/index.php"] [unique_id "al4mUnjLAau4tRDXyg9HNAAAAU4"], referer: https://itdynamix.com/WWW
[Mon Jul 20 07:44:50.970216 2026] [security2:error] [pid 230396:tid 230535] [client 37.52.210.45:58601] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mUnjLAau4tRDXyg9HPQAAARI"]
[Mon Jul 20 07:44:50.970312 2026] [security2:error] [pid 230396:tid 230535] [client 37.52.210.45:58601] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mUnjLAau4tRDXyg9HPQAAARI"]
[Mon Jul 20 07:44:51.102618 2026] [security2:error] [pid 230396:tid 230416] [remote 103.118.29.185:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mU3jLAau4tRDXyg9HQwABShI"]
[Mon Jul 20 07:44:51.132279 2026] [security2:error] [pid 230396:tid 230528] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mUnjLAau4tRDXyg9HOwAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:51.443620 2026] [security2:error] [pid 230396:tid 230608] [client 149.0.16.108:60100] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mU3jLAau4tRDXyg9HUwAAAVs"]
[Mon Jul 20 07:44:51.443716 2026] [security2:error] [pid 230396:tid 230608] [client 149.0.16.108:60100] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mU3jLAau4tRDXyg9HUwAAAVs"]
[Mon Jul 20 07:44:51.579321 2026] [security2:error] [pid 230396:tid 230433] [remote 103.118.29.185:52900] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 185.29.118.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mU3jLAau4tRDXyg9HXAABbiM"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:44:51.652432 2026] [security2:error] [pid 230396:tid 230581] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mU3jLAau4tRDXyg9HVAAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:51.743047 2026] [security2:error] [pid 230396:tid 230584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mU3jLAau4tRDXyg9HWwAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:51.845498 2026] [security2:error] [pid 230396:tid 230636] [client 168.144.19.97:57796] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-parser-block.php"] [unique_id "al4mU3jLAau4tRDXyg9HZgAAAXc"], referer: binance.com
[Mon Jul 20 07:44:51.955544 2026] [security2:error] [pid 230396:tid 230542] [client 179.127.84.238:65422] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mU3jLAau4tRDXyg9HagAAARk"]
[Mon Jul 20 07:44:51.956653 2026] [security2:error] [pid 230396:tid 230542] [client 179.127.84.238:65422] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mU3jLAau4tRDXyg9HagAAARk"]
[Mon Jul 20 07:44:51.957387 2026] [security2:error] [pid 230396:tid 230549] [client 77.110.127.138:55586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0'XOR(if(now()=sysdate(),sleep(15),0))XOR'Z/page/page/3/"] [unique_id "al4mU3jLAau4tRDXyg9HawAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:52.005370 2026] [security2:error] [pid 230396:tid 230573] [client 43.156.142.168:57101] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 168.142.156.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.samdothan.org"] [uri "/wp-login.php"] [unique_id "al4mU3jLAau4tRDXyg9HcAAAATg"], referer: https://www.samdothan.org/wp-login.php
[Mon Jul 20 07:44:52.016189 2026] [security2:error] [pid 230396:tid 230563] [client 45.3.52.34:11477] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 34.52.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mU3jLAau4tRDXyg9HbgAAAS4"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:44:52.180760 2026] [security2:error] [pid 230396:tid 230529] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mU3jLAau4tRDXyg9HbQAAAQw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:52.219148 2026] [security2:error] [pid 229701:tid 229867] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVHZMWbdeOcTm4EwjEwAAAKk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:52.396288 2026] [security2:error] [pid 230396:tid 230600] [client 139.59.118.64:59916] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 64.118.59.139.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "servicare-mx.safe-systems.net"] [uri "/wp-login.php"] [unique_id "al4mVHjLAau4tRDXyg9HfwAAAVM"], referer: https://www.google.com/search?q=wordpress
[Mon Jul 20 07:44:52.526876 2026] [security2:error] [pid 229701:tid 229857] [client 14.225.17.146:49815] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVHZMWbdeOcTm4EwjLQAAAJ8"], referer: http://mezzacraft.com/WWW
[Mon Jul 20 07:44:52.728856 2026] [security2:error] [pid 230396:tid 230575] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVHjLAau4tRDXyg9HigAAATo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:52.760480 2026] [security2:error] [pid 230396:tid 230608] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVHjLAau4tRDXyg9HjAAAAVs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:52.959145 2026] [security2:error] [pid 230396:tid 230624] [client 14.225.17.146:49495] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "scott-assist.com"] [uri "/index.php"] [unique_id "al4mU3jLAau4tRDXyg9HXQAAAWs"], referer: http://scott-assist.com/WWW
[Mon Jul 20 07:44:53.001045 2026] [security2:error] [pid 229701:tid 229915] [client 57.141.18.95:55576] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mUXZMWbdeOcTm4EwilQAA2V0"]
[Mon Jul 20 07:44:53.112494 2026] [security2:error] [pid 230396:tid 230584] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVHjLAau4tRDXyg9HlwAAAUM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:53.592873 2026] [security2:error] [pid 230396:tid 230647] [client 77.110.127.138:55550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 853 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mVXjLAau4tRDXyg9HswAAAYI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:53.644568 2026] [security2:error] [pid 229701:tid 229835] [client 77.110.127.138:55553] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mVXZMWbdeOcTm4EwjYQAAAIk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:53.698696 2026] [security2:error] [pid 230396:tid 230640] [client 57.141.18.38:26148] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mUnjLAau4tRDXyg9HCgABewE"]
[Mon Jul 20 07:44:53.732864 2026] [security2:error] [pid 230396:tid 230457] [remote 160.187.68.132:45522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mVXjLAau4tRDXyg9HtwABfjs"]
[Mon Jul 20 07:44:53.997611 2026] [security2:error] [pid 229701:tid 229881] [client 50.116.65.227:40574] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mVXZMWbdeOcTm4EwjdAAAALc"]
[Mon Jul 20 07:44:54.006110 2026] [security2:error] [pid 229701:tid 229857] [client 50.116.65.227:40582] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mVnZMWbdeOcTm4EwjdgAAAJ8"]
[Mon Jul 20 07:44:54.007262 2026] [security2:error] [pid 229701:tid 229882] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVXZMWbdeOcTm4EwjaQAAALg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:54.255872 2026] [security2:error] [pid 230396:tid 230538] [client 212.47.78.47:46452] ModSecurity: Access denied with code 406 (phase 1). Pattern match "^POST$" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "187"] [id "900401"] [msg "PHP Spam Botnet"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4mVnjLAau4tRDXyg9HzQAAARU"]
[Mon Jul 20 07:44:54.360268 2026] [security2:error] [pid 230396:tid 230544] [client 77.110.127.138:55609] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza0\\"XOR(if(now()=sysdate(),sleep(15),0))XOR\\"Z/page/page/3/"] [unique_id "al4mVnjLAau4tRDXyg9H0wAAARs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:54.423347 2026] [security2:error] [pid 229701:tid 229721] [remote 47.86.33.52:39316] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "transparentservices.online"] [uri "/wp-login.php"] [unique_id "al4mVnZMWbdeOcTm4EwjgAAA9xM"], referer: https://transparentservices.online/wp-login.php
[Mon Jul 20 07:44:54.473154 2026] [security2:error] [pid 230396:tid 230535] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVnjLAau4tRDXyg9HzgAAARI"]
[Mon Jul 20 07:44:54.590662 2026] [security2:error] [pid 230396:tid 230474] [remote 57.141.18.12:33130] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/4469673"] [unique_id "al4mVnjLAau4tRDXyg9H3QABPUw"]
[Mon Jul 20 07:44:54.705812 2026] [security2:error] [pid 230396:tid 230593] [client 212.47.78.47:46464] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4mVnjLAau4tRDXyg9H3wAAAUw"]
[Mon Jul 20 07:44:54.843087 2026] [security2:error] [pid 230396:tid 230625] [client 14.225.17.146:50108] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "windowtx.com"] [uri "/index.php"] [unique_id "al4mVXjLAau4tRDXyg9HnQAAAWw"], referer: http://windowtx.com/WWW
[Mon Jul 20 07:44:54.901797 2026] [security2:error] [pid 229701:tid 229781] [remote 66.7.213.120:48348] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 120.213.7.66.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mVnZMWbdeOcTm4EwjjgABBE8"]
[Mon Jul 20 07:44:54.902009 2026] [security2:error] [pid 229701:tid 229958] [client 66.7.213.120:48348] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "wgs.doq.mybluehost.me"] [uri "/xmlrpc.php"] [unique_id "al4mVnZMWbdeOcTm4EwjjgABBE8"]
[Mon Jul 20 07:44:54.956449 2026] [security2:error] [pid 229701:tid 229877] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mVnZMWbdeOcTm4EwjhwAAALM"]
[Mon Jul 20 07:44:54.976353 2026] [security2:error] [pid 230396:tid 230581] [client 77.110.127.138:55613] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/2*if(now()=sysdate(),sleep(15),0)/"] [unique_id "al4mVnjLAau4tRDXyg9H7gAAAUA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:55.154557 2026] [security2:error] [pid 230396:tid 230568] [client 212.47.78.47:58224] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5028.bluehost.com"] [uri "/blog/"] [unique_id "al4mV3jLAau4tRDXyg9H9gAAATM"]
[Mon Jul 20 07:44:55.156272 2026] [security2:error] [pid 230396:tid 230572] [client 57.141.18.43:47934] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mU3jLAau4tRDXyg9HSwABNxk"]
[Mon Jul 20 07:44:55.653332 2026] [security2:error] [pid 230396:tid 230486] [remote 160.187.68.132:45522] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mV3jLAau4tRDXyg9IDgABbFg"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:44:55.678388 2026] [security2:error] [pid 230396:tid 230482] [remote 57.141.18.91:40398] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 91.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3741619"] [unique_id "al4mV3jLAau4tRDXyg9IDwABcFQ"]
[Mon Jul 20 07:44:55.708982 2026] [security2:error] [pid 230396:tid 230589] [client 77.110.127.138:55615] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mV3jLAau4tRDXyg9IFAAAAUg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:55.718067 2026] [security2:error] [pid 230396:tid 230541] [client 168.144.19.97:52246] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-parser-frame.php"] [unique_id "al4mV3jLAau4tRDXyg9IGAAAARg"], referer: binance.com
[Mon Jul 20 07:44:56.112943 2026] [security2:error] [pid 230396:tid 230545] [client 77.110.127.138:55586] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 938 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mWHjLAau4tRDXyg9ILwAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:56.245574 2026] [core:error] [pid 230396:tid 230621] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:56.245605 2026] [core:error] [pid 230396:tid 230621] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:56.305222 2026] [security2:error] [pid 230396:tid 230577] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWHjLAau4tRDXyg9ILQAAATw"]
[Mon Jul 20 07:44:56.482729 2026] [security2:error] [pid 230396:tid 230542] [client 43.205.139.3:34866] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mWHjLAau4tRDXyg9IPwAAARk"]
[Mon Jul 20 07:44:56.482828 2026] [security2:error] [pid 230396:tid 230542] [client 43.205.139.3:34866] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mWHjLAau4tRDXyg9IPwAAARk"]
[Mon Jul 20 07:44:56.711511 2026] [security2:error] [pid 230396:tid 230606] [client 20.226.60.151:0] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 151.60.226.20.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "zanjan-fromer.com"] [uri "/.well-known/about.php"] [unique_id "al4mWHjLAau4tRDXyg9ITwAAAVk"]
[Mon Jul 20 07:44:56.711619 2026] [security2:error] [pid 230396:tid 230606] [client 20.226.60.151:0] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "409"] [hostname "zanjan-fromer.com"] [uri "/.well-known/about.php"] [unique_id "al4mWHjLAau4tRDXyg9ITwAAAVk"]
[Mon Jul 20 07:44:56.778670 2026] [security2:error] [pid 230396:tid 230599] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWHjLAau4tRDXyg9ISQAAAVI"]
[Mon Jul 20 07:44:56.830819 2026] [security2:error] [pid 230396:tid 230496] [remote 20.173.88.122:43344] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 122.88.173.20.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4mWHjLAau4tRDXyg9IVAABO2I"]
[Mon Jul 20 07:44:56.831068 2026] [security2:error] [pid 230396:tid 230576] [client 20.173.88.122:43344] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "narv.co"] [uri "/xmlrpc.php"] [unique_id "al4mWHjLAau4tRDXyg9IVAABO2I"]
[Mon Jul 20 07:44:56.941525 2026] [security2:error] [pid 230396:tid 230567] [client 186.221.114.200:62780] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mWHjLAau4tRDXyg9IXQAAATI"]
[Mon Jul 20 07:44:56.941635 2026] [security2:error] [pid 230396:tid 230567] [client 186.221.114.200:62780] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mWHjLAau4tRDXyg9IXQAAATI"]
[Mon Jul 20 07:44:57.106409 2026] [security2:error] [pid 229701:tid 229846] [client 103.139.191.61:62709] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj3AAAAJQ"]
[Mon Jul 20 07:44:57.106548 2026] [security2:error] [pid 229701:tid 229846] [client 103.139.191.61:62709] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj3AAAAJQ"]
[Mon Jul 20 07:44:57.158541 2026] [security2:error] [pid 230396:tid 230544] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWHjLAau4tRDXyg9IXwAAARs"]
[Mon Jul 20 07:44:57.161134 2026] [core:error] [pid 230396:tid 230527] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:57.161162 2026] [core:error] [pid 230396:tid 230527] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:44:57.230831 2026] [security2:error] [pid 230396:tid 230601] [client 77.110.127.138:55625] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/20'XOR(2*if(now()=sysdate(),sleep(15),0))XOR'Z/"] [unique_id "al4mWXjLAau4tRDXyg9IaQAAAVQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:57.552276 2026] [security2:error] [pid 229701:tid 229947] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj5AAAAPk"]
[Mon Jul 20 07:44:57.633423 2026] [security2:error] [pid 230396:tid 230621] [client 103.106.165.44:63192] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 44.165.106.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mWXjLAau4tRDXyg9IfgAAAWg"]
[Mon Jul 20 07:44:57.633517 2026] [security2:error] [pid 230396:tid 230621] [client 103.106.165.44:63192] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mWXjLAau4tRDXyg9IfgAAAWg"]
[Mon Jul 20 07:44:57.736138 2026] [security2:error] [pid 229701:tid 229839] [client 36.93.152.155:54021] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj-AAAAI0"]
[Mon Jul 20 07:44:57.736237 2026] [security2:error] [pid 229701:tid 229839] [client 36.93.152.155:54021] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj-AAAAI0"]
[Mon Jul 20 07:44:57.938367 2026] [security2:error] [pid 230396:tid 230579] [client 98.159.234.160:40173] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 160.234.159.98.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mWXjLAau4tRDXyg9IiwAAAT4"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:44:58.068599 2026] [security2:error] [pid 229701:tid 229886] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj_wAAALw"]
[Mon Jul 20 07:44:58.273080 2026] [security2:error] [pid 230396:tid 230559] [client 14.225.17.146:61827] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "according2plant.com"] [uri "/index.php"] [unique_id "al4mWHjLAau4tRDXyg9ISgAAASo"], referer: http://according2plant.com/WWW
[Mon Jul 20 07:44:58.367149 2026] [security2:error] [pid 229701:tid 229865] [client 14.225.17.146:50081] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "greenvillemoving.com"] [uri "/index.php"] [unique_id "al4mWnZMWbdeOcTm4EwkFgAAAKc"]
[Mon Jul 20 07:44:58.452293 2026] [security2:error] [pid 229701:tid 229905] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWnZMWbdeOcTm4EwkFQAAAM8"]
[Mon Jul 20 07:44:58.586060 2026] [security2:error] [pid 230396:tid 230505] [remote 185.177.72.100:1430] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\id_rsa"] [unique_id "al4mWnjLAau4tRDXyg9IrQABZWs"]
[Mon Jul 20 07:44:58.847451 2026] [security2:error] [pid 230396:tid 230606] [client 77.110.127.138:55635] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\(chr ?\\\\( ?[0-9]{1,3} ?\\\\)| ?= ?f(?:open|write) ?\\\\(|\\\\b(?:passthru|serialize|php_uname|phpinfo|shell_exec|preg_\\\\w+|mysql_query|exec|eval|base64_decode|decode_base64|rot13|base64_url_decode|gz(?:inflate|decode|uncompress)|strrev|zlib_\\\\w+)\\\\b ?(? ..." at ARGS:utm_source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "767"] [id "340095"] [rev "53"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  PHP function in Argument - this may be an attack."] [data "(chr(98),ARGS:utm_source"] [severity "CRITICAL"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mWnjLAau4tRDXyg9IsgAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:58.914479 2026] [proxy:error] [pid 230396:tid 230577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:58.914533 2026] [proxy_http:error] [pid 230396:tid 230577] [client 104.155.181.6:44850] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:58.915516 2026] [proxy:error] [pid 230396:tid 230577] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:44:58.915559 2026] [proxy_http:error] [pid 230396:tid 230577] [client 104.155.181.6:44850] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:44:58.981082 2026] [security2:error] [pid 229701:tid 229911] [client 14.251.3.155:56504] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "quangminhltd.vn"] [uri "/wpad.dat"] [unique_id "al4mWnZMWbdeOcTm4EwkOwAAANU"]
[Mon Jul 20 07:44:59.130418 2026] [security2:error] [pid 229701:tid 229806] [remote 45.90.123.233:51436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkSgAA52g"]
[Mon Jul 20 07:44:59.148904 2026] [security2:error] [pid 230396:tid 230568] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mWnjLAau4tRDXyg9ItAAAATM"]
[Mon Jul 20 07:44:59.323925 2026] [security2:error] [pid 229701:tid 229723] [remote 45.90.123.233:51436] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "saudalsubaie.com"] [uri "/wp-login.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkUgAA4xU"], referer: https://saudalsubaie.com/wp-login.php
[Mon Jul 20 07:44:59.441474 2026] [security2:error] [pid 229701:tid 229749] [remote 185.177.72.100:1432] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..\\\\id_rsa"] [unique_id "al4mW3ZMWbdeOcTm4EwkVwABBC8"]
[Mon Jul 20 07:44:59.448364 2026] [security2:error] [pid 229701:tid 229835] [client 14.225.17.146:65443] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "schuttfarms.com"] [uri "/index.php"] [unique_id "al4mWXZMWbdeOcTm4Ewj9wAAAIk"]
[Mon Jul 20 07:44:59.543830 2026] [security2:error] [pid 230396:tid 230559] [client 168.144.19.97:52019] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-processor.php"] [unique_id "al4mW3jLAau4tRDXyg9IzAAAASo"], referer: binance.com
[Mon Jul 20 07:44:59.640432 2026] [security2:error] [pid 229701:tid 229879] [client 14.225.17.146:63095] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "adastra.love"] [uri "/index.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkTwAAALU"], referer: http://adastra.love/WWW
[Mon Jul 20 07:44:59.776195 2026] [security2:error] [pid 229701:tid 229917] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkXgAAANs"]
[Mon Jul 20 07:44:59.815441 2026] [security2:error] [pid 230396:tid 230573] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mW3jLAau4tRDXyg9I0wAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:44:59.899059 2026] [security2:error] [pid 229701:tid 229938] [client 50.116.65.227:53812] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkawAAAPA"]
[Mon Jul 20 07:44:59.902114 2026] [security2:error] [pid 230396:tid 230611] [client 136.158.60.21:155] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mW3jLAau4tRDXyg9I4QAAAV4"]
[Mon Jul 20 07:44:59.902291 2026] [security2:error] [pid 230396:tid 230611] [client 136.158.60.21:155] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mW3jLAau4tRDXyg9I4QAAAV4"]
[Mon Jul 20 07:44:59.996172 2026] [security2:error] [pid 230396:tid 230629] [client 15.229.69.106:12404] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mW3jLAau4tRDXyg9I5AAAAXA"]
[Mon Jul 20 07:44:59.996267 2026] [security2:error] [pid 230396:tid 230629] [client 15.229.69.106:12404] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mW3jLAau4tRDXyg9I5AAAAXA"]
[Mon Jul 20 07:45:00.085544 2026] [security2:error] [pid 229701:tid 229839] [client 50.116.65.227:53822] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.fkconstructionfunding.com"] [uri "/index.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkcAAAAI0"]
[Mon Jul 20 07:45:00.257047 2026] [security2:error] [pid 230396:tid 230535] [client 39.46.9.231:49159] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mXHjLAau4tRDXyg9I7gAAARI"]
[Mon Jul 20 07:45:00.257284 2026] [security2:error] [pid 230396:tid 230535] [client 39.46.9.231:49159] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mXHjLAau4tRDXyg9I7gAAARI"]
[Mon Jul 20 07:45:00.257425 2026] [security2:error] [pid 229701:tid 229791] [remote 185.177.72.100:1448] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fid_rsa"] [unique_id "al4mXHZMWbdeOcTm4EwkgwAAh1k"]
[Mon Jul 20 07:45:00.745041 2026] [security2:error] [pid 230396:tid 230637] [client 180.249.173.210:60782] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mXHjLAau4tRDXyg9I_AAAAXg"]
[Mon Jul 20 07:45:00.745708 2026] [security2:error] [pid 230396:tid 230637] [client 180.249.173.210:60782] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mXHjLAau4tRDXyg9I_AAAAXg"]
[Mon Jul 20 07:45:00.884826 2026] [security2:error] [pid 229701:tid 229957] [client 45.157.112.60:37715] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 60.112.157.45.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mXHZMWbdeOcTm4EwkpAAAAQM"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:45:01.061844 2026] [security2:error] [pid 230396:tid 230573] [client 77.110.127.138:55550] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:procedure\\\\s+analyse\\\\s.{0,100}\\\\(|create\\\\s+(procedure|function)\\\\s.{0,100}\\\\w+\\\\s.{0,100}\\\\(\\\\s.{0,200}\\\\)\\\\s.{0,100}declare[^\\\\w]+[@#]\\\\s.{0,100}\\\\w+|exec\\\\s.{0,100}\\\\(\\\\s.{0,200}@|\\\\b(?:sleep|benchmark)\\\\b ?\\\\( ?[0-9])" at REQUEST_URI. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "273"] [id "380122"] [rev "5"] [msg "Atomicorp.com WAF Rules: MySQL and PostgreSQL stored procedure/function injections"] [data "sleep(1"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/page/20\\"XOR(2*if(now()=sysdate(),sleep(15),0))XOR\\"Z/"] [unique_id "al4mXXjLAau4tRDXyg9JCgAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:01.100095 2026] [security2:error] [pid 230396:tid 230518] [remote 185.177.72.100:1462] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fid_rsa"] [unique_id "al4mXXjLAau4tRDXyg9JEAABc3g"]
[Mon Jul 20 07:45:01.117138 2026] [security2:error] [pid 229701:tid 229851] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXHZMWbdeOcTm4EwkpQAAAJk"]
[Mon Jul 20 07:45:01.120972 2026] [security2:error] [pid 230396:tid 230603] [client 14.225.17.146:65422] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "rtkenergypartners.com"] [uri "/index.php"] [unique_id "al4mXHjLAau4tRDXyg9JAAAAAVY"]
[Mon Jul 20 07:45:01.246880 2026] [security2:error] [pid 229701:tid 229958] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "assasalnazaha.com"] [uri "/index.php"] [unique_id "al4mXHZMWbdeOcTm4EwkmwABBDs"], referer: http://assasalnazaha.com/WWW
[Mon Jul 20 07:45:01.406796 2026] [security2:error] [pid 230396:tid 230559] [client 154.192.233.184:61386] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mXXjLAau4tRDXyg9JJQAAASo"]
[Mon Jul 20 07:45:01.406907 2026] [security2:error] [pid 230396:tid 230559] [client 154.192.233.184:61386] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mXXjLAau4tRDXyg9JJQAAASo"]
[Mon Jul 20 07:45:01.456856 2026] [security2:error] [pid 230396:tid 230620] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXXjLAau4tRDXyg9JIgAAAWc"]
[Mon Jul 20 07:45:01.497341 2026] [security2:error] [pid 229701:tid 229831] [client 155.2.215.84:61857] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mXXZMWbdeOcTm4EwktQAAAIU"]
[Mon Jul 20 07:45:01.698261 2026] [security2:error] [pid 230396:tid 230550] [client 14.225.17.146:56633] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ksands.co.uk"] [uri "/index.php"] [unique_id "al4mXXjLAau4tRDXyg9JKQAAASE"], referer: http://ksands.co.uk/WWW
[Mon Jul 20 07:45:01.803692 2026] [security2:error] [pid 230396:tid 230528] [client 77.110.127.138:55632] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:utm_source. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 198766*667891 from d"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mXXjLAau4tRDXyg9JNAAAAQs"]
[Mon Jul 20 07:45:01.835232 2026] [security2:error] [pid 229701:tid 229869] [client 37.52.210.45:59135] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mXXZMWbdeOcTm4EwkzwAAAKs"]
[Mon Jul 20 07:45:01.835354 2026] [security2:error] [pid 229701:tid 229869] [client 37.52.210.45:59135] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mXXZMWbdeOcTm4EwkzwAAAKs"]
[Mon Jul 20 07:45:01.872935 2026] [security2:error] [pid 230396:tid 230561] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXXjLAau4tRDXyg9JMQAAASw"]
[Mon Jul 20 07:45:02.013951 2026] [security2:error] [pid 230396:tid 230598] [client 14.225.17.146:50187] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "302"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4mW3jLAau4tRDXyg9I2gAAAVE"]
[Mon Jul 20 07:45:02.037248 2026] [security2:error] [pid 230396:tid 230571] [client 149.0.16.108:60625] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mXnjLAau4tRDXyg9JPAAAATY"]
[Mon Jul 20 07:45:02.037348 2026] [security2:error] [pid 230396:tid 230571] [client 149.0.16.108:60625] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mXnjLAau4tRDXyg9JPAAAATY"]
[Mon Jul 20 07:45:02.294308 2026] [security2:error] [pid 229701:tid 229912] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXnZMWbdeOcTm4Ewk2AAAANY"], referer: 1'"3000
[Mon Jul 20 07:45:02.511839 2026] [security2:error] [pid 230396:tid 230620] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXnjLAau4tRDXyg9JVwAAAWc"], referer: 1'"3000
[Mon Jul 20 07:45:02.524412 2026] [security2:error] [pid 230396:tid 230604] [client 179.127.84.238:49595] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mXnjLAau4tRDXyg9JXQAAAVc"]
[Mon Jul 20 07:45:02.524493 2026] [security2:error] [pid 230396:tid 230604] [client 179.127.84.238:49595] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mXnjLAau4tRDXyg9JXQAAAVc"]
[Mon Jul 20 07:45:02.673834 2026] [security2:error] [pid 230396:tid 230519] [remote 57.141.18.55:36280] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/5187407"] [unique_id "al4mXnjLAau4tRDXyg9JaQABfnk"]
[Mon Jul 20 07:45:02.801558 2026] [security2:error] [pid 230396:tid 230648] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXnjLAau4tRDXyg9JZAAAAYM"], referer: 1'"3000
[Mon Jul 20 07:45:02.863418 2026] [security2:error] [pid 230396:tid 230401] [remote 81.173.115.7:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4mXnjLAau4tRDXyg9JcAABLAM"]
[Mon Jul 20 07:45:03.061587 2026] [security2:error] [pid 230396:tid 230636] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mXnjLAau4tRDXyg9JbgAAAXc"], referer: 1'"3000
[Mon Jul 20 07:45:03.089770 2026] [security2:error] [pid 230396:tid 230597] [client 14.225.17.146:56704] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "falconarrowshop.com"] [uri "/index.php"] [unique_id "al4mXnjLAau4tRDXyg9JbwAAAVA"], referer: http://falconarrowshop.com/WWW
[Mon Jul 20 07:45:03.257604 2026] [security2:error] [pid 230396:tid 230593] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mX3jLAau4tRDXyg9JewAAAUw"], referer: 1'"3000
[Mon Jul 20 07:45:03.419954 2026] [security2:error] [pid 230396:tid 230595] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mX3jLAau4tRDXyg9JigAAAU4"], referer: 1'"3000
[Mon Jul 20 07:45:03.507386 2026] [security2:error] [pid 229701:tid 229914] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mX3ZMWbdeOcTm4EwlBQAAANg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:03.579868 2026] [security2:error] [pid 229701:tid 229867] [client 57.141.18.54:27600] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mW3ZMWbdeOcTm4EwkagAAqTU"]
[Mon Jul 20 07:45:03.620997 2026] [security2:error] [pid 230396:tid 230415] [remote 81.173.115.7:54250] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "tejasenvironmental.com"] [uri "/wp-login.php"] [unique_id "al4mX3jLAau4tRDXyg9JlgABVxE"], referer: https://tejasenvironmental.com/wp-login.php
[Mon Jul 20 07:45:03.621600 2026] [security2:error] [pid 230396:tid 230530] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mX3jLAau4tRDXyg9JkQAAAQ0"]
[Mon Jul 20 07:45:03.829693 2026] [security2:error] [pid 230396:tid 230541] [client 104.207.53.2:61909] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 2.53.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mX3jLAau4tRDXyg9JnQAAARg"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:45:03.839745 2026] [security2:error] [pid 229701:tid 229890] [client 14.225.17.146:61741] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "floorsourcestock.com"] [uri "/index.php"] [unique_id "al4mXXZMWbdeOcTm4EwkywAAAMA"], referer: http://floorsourcestock.com/WWW
[Mon Jul 20 07:45:03.899401 2026] [security2:error] [pid 230396:tid 230640] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mX3jLAau4tRDXyg9JlQAAAXs"]
[Mon Jul 20 07:45:03.986538 2026] [security2:error] [pid 229701:tid 229931] [client 14.225.17.146:56720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "securingmemories.com"] [uri "/index.php"] [unique_id "al4mXXZMWbdeOcTm4EwkzgAAAOk"], referer: http://securingmemories.com/WWW
[Mon Jul 20 07:45:04.083565 2026] [security2:error] [pid 229701:tid 229892] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mX3ZMWbdeOcTm4EwlKAAAAMI"]
[Mon Jul 20 07:45:04.098145 2026] [security2:error] [pid 229701:tid 229939] [client 77.110.127.138:55647] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:amprnBN0s9p' OR 299. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 299 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mYHZMWbdeOcTm4EwlNQAAAPE"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:04.253035 2026] [security2:error] [pid 229701:tid 229704] [remote 81.173.115.7:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mYHZMWbdeOcTm4EwlOQAAjwI"]
[Mon Jul 20 07:45:04.461086 2026] [security2:error] [pid 229701:tid 229714] [remote 81.173.115.7:36452] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 7.115.173.81.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mYHZMWbdeOcTm4EwlQAAAogw"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:45:04.524074 2026] [security2:error] [pid 230396:tid 230577] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYHjLAau4tRDXyg9JsQAAATw"]
[Mon Jul 20 07:45:04.719251 2026] [security2:error] [pid 230396:tid 230558] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYHjLAau4tRDXyg9JuQAAASk"]
[Mon Jul 20 07:45:04.772499 2026] [security2:error] [pid 230396:tid 230569] [client 14.225.17.146:57259] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "hammadownenterprises.com"] [uri "/index.php"] [unique_id "al4mX3jLAau4tRDXyg9JkAAAATQ"], referer: http://hammadownenterprises.com/WWW
[Mon Jul 20 07:45:05.028730 2026] [security2:error] [pid 229701:tid 229908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYHZMWbdeOcTm4EwlVAAAANI"]
[Mon Jul 20 07:45:05.054836 2026] [security2:error] [pid 229701:tid 229863] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYHZMWbdeOcTm4EwlVgAAAKU"]
[Mon Jul 20 07:45:05.179577 2026] [security2:error] [pid 229701:tid 229955] [client 43.205.139.3:43904] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 3.139.205.43.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4mYXZMWbdeOcTm4EwlagAAAQE"]
[Mon Jul 20 07:45:05.257299 2026] [security2:error] [pid 229701:tid 229874] [client 65.111.23.14:42297] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.23.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mYXZMWbdeOcTm4EwlbwAAALA"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:45:05.338344 2026] [security2:error] [pid 230396:tid 230565] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYXjLAau4tRDXyg9J2QAAATA"]
[Mon Jul 20 07:45:05.452644 2026] [security2:error] [pid 229701:tid 229918] [client 14.225.17.146:57116] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "jvcmotorsports.com"] [uri "/index.php"] [unique_id "al4mX3ZMWbdeOcTm4EwlBwAAANw"], referer: http://jvcmotorsports.com/WWW
[Mon Jul 20 07:45:05.466487 2026] [security2:error] [pid 230396:tid 230590] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYXjLAau4tRDXyg9J3wAAAUk"]
[Mon Jul 20 07:45:05.470212 2026] [security2:error] [pid 230396:tid 230638] [client 57.141.18.120:49026] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mXXjLAau4tRDXyg9JJgABeTE"]
[Mon Jul 20 07:45:05.754211 2026] [security2:error] [pid 229701:tid 229885] [client 57.141.18.1:33740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mXXZMWbdeOcTm4EwkygAAu0Y"]
[Mon Jul 20 07:45:05.999204 2026] [security2:error] [pid 230396:tid 230574] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYXjLAau4tRDXyg9J-AAAATk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:06.030608 2026] [security2:error] [pid 229701:tid 229910] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYXZMWbdeOcTm4EwligAAANQ"]
[Mon Jul 20 07:45:06.174600 2026] [security2:error] [pid 230396:tid 230578] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYXjLAau4tRDXyg9KAgAAAT0"]
[Mon Jul 20 07:45:06.224044 2026] [security2:error] [pid 230396:tid 230644] [client 13.232.231.177:27196] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 177.231.232.13.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/wp-login.php"] [unique_id "al4mYnjLAau4tRDXyg9KFAAAAX8"], referer: https://curlsnpearlsss.com/wp-login.php
[Mon Jul 20 07:45:06.407146 2026] [security2:error] [pid 229701:tid 229954] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYnZMWbdeOcTm4EwloAAAAQA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:06.454504 2026] [security2:error] [pid 230396:tid 230597] [client 217.181.90.186:46017] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 186.90.181.217.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mYnjLAau4tRDXyg9KGwAAAVA"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:45:06.483410 2026] [security2:error] [pid 230396:tid 230634] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYnjLAau4tRDXyg9KFwAAAXU"]
[Mon Jul 20 07:45:06.535718 2026] [security2:error] [pid 230396:tid 230535] [client 54.169.146.187:40266] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 187.146.169.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mYnjLAau4tRDXyg9KJgAAARI"]
[Mon Jul 20 07:45:06.535862 2026] [security2:error] [pid 230396:tid 230535] [client 54.169.146.187:40266] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mYnjLAau4tRDXyg9KJgAAARI"]
[Mon Jul 20 07:45:06.674720 2026] [security2:error] [pid 230396:tid 230589] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYnjLAau4tRDXyg9KIQAAAUg"]
[Mon Jul 20 07:45:06.861466 2026] [security2:error] [pid 229701:tid 229762] [remote 185.177.72.100:1488] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\privkey.pem"] [unique_id "al4mYnZMWbdeOcTm4EwlxAAAoDw"]
[Mon Jul 20 07:45:06.965759 2026] [security2:error] [pid 229701:tid 229884] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYnZMWbdeOcTm4EwlvwAAALo"]
[Mon Jul 20 07:45:07.072796 2026] [security2:error] [pid 230396:tid 230548] [client 45.3.45.140:63719] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 140.45.3.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mY3jLAau4tRDXyg9KQQAAAR8"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:45:07.203042 2026] [security2:error] [pid 230396:tid 230620] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mYnjLAau4tRDXyg9KNQAAAWc"]
[Mon Jul 20 07:45:07.509579 2026] [security2:error] [pid 230396:tid 230634] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mY3jLAau4tRDXyg9KWgAAAXU"]
[Mon Jul 20 07:45:07.681234 2026] [security2:error] [pid 230396:tid 230649] [client 186.221.114.200:63258] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mY3jLAau4tRDXyg9KdQAAAYQ"]
[Mon Jul 20 07:45:07.681358 2026] [security2:error] [pid 230396:tid 230649] [client 186.221.114.200:63258] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mY3jLAau4tRDXyg9KdQAAAYQ"]
[Mon Jul 20 07:45:07.752226 2026] [security2:error] [pid 229701:tid 229776] [remote 185.177.72.100:1500] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..\\\\privkey.pem"] [unique_id "al4mY3ZMWbdeOcTm4Ewl3wAAkEo"]
[Mon Jul 20 07:45:07.756849 2026] [security2:error] [pid 230396:tid 230644] [client 74.208.214.194:60262] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 194.214.208.74.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ait.afz.mybluehost.me"] [uri "/wp-cron.php"] [unique_id "al4mY3jLAau4tRDXyg9KfgAAAX8"]
[Mon Jul 20 07:45:08.008603 2026] [security2:error] [pid 229701:tid 229908] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mY3ZMWbdeOcTm4Ewl4AAAANI"]
[Mon Jul 20 07:45:08.066388 2026] [security2:error] [pid 230396:tid 230625] [client 14.225.17.146:57114] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4mY3jLAau4tRDXyg9KPwAAAWw"], referer: http://adultdaycarereno.com/WWW
[Mon Jul 20 07:45:08.216631 2026] [security2:error] [pid 229701:tid 229889] [client 168.144.19.97:61367] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-template.php"] [unique_id "al4mZHZMWbdeOcTm4Ewl9gAAAL8"], referer: binance.com
[Mon Jul 20 07:45:08.239205 2026] [security2:error] [pid 229701:tid 229865] [client 36.93.152.155:54546] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mZHZMWbdeOcTm4Ewl-AAAAKc"]
[Mon Jul 20 07:45:08.239309 2026] [security2:error] [pid 229701:tid 229865] [client 36.93.152.155:54546] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mZHZMWbdeOcTm4Ewl-AAAAKc"]
[Mon Jul 20 07:45:08.283690 2026] [security2:error] [pid 230396:tid 230603] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mY3jLAau4tRDXyg9KgwAAAVY"]
[Mon Jul 20 07:45:08.382787 2026] [security2:error] [pid 230396:tid 230651] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZHjLAau4tRDXyg9KlAAAAYY"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:08.413780 2026] [security2:error] [pid 230396:tid 230599] [client 103.139.191.61:63242] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mZHjLAau4tRDXyg9KoAAAAVI"]
[Mon Jul 20 07:45:08.413947 2026] [security2:error] [pid 230396:tid 230599] [client 103.139.191.61:63242] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mZHjLAau4tRDXyg9KoAAAAVI"]
[Mon Jul 20 07:45:08.482018 2026] [security2:error] [pid 229701:tid 229927] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZHZMWbdeOcTm4Ewl-QAAAOU"]
[Mon Jul 20 07:45:08.496785 2026] [security2:error] [pid 229701:tid 229887] [client 57.141.18.28:25316] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mYHZMWbdeOcTm4EwlTwAAvR0"]
[Mon Jul 20 07:45:08.512191 2026] [security2:error] [pid 229701:tid 229881] [client 14.225.17.146:56606] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "drewsasburyparkbeachhouse.com"] [uri "/index.php"] [unique_id "al4mYnZMWbdeOcTm4EwllgAAALc"], referer: http://drewsasburyparkbeachhouse.com/WWW
[Mon Jul 20 07:45:08.629039 2026] [security2:error] [pid 229701:tid 229823] [remote 185.177.72.100:34156] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/%2fprivkey.pem"] [unique_id "al4mZHZMWbdeOcTm4EwmCAAA2nk"]
[Mon Jul 20 07:45:08.691228 2026] [security2:error] [pid 230396:tid 230550] [client 57.141.18.66:51570] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mYHjLAau4tRDXyg9JzQABIQw"]
[Mon Jul 20 07:45:08.730239 2026] [security2:error] [pid 230396:tid 230649] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZHjLAau4tRDXyg9KpwAAAYQ"]
[Mon Jul 20 07:45:08.736147 2026] [security2:error] [pid 230396:tid 230462] [remote 47.86.33.52:22218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4mZHjLAau4tRDXyg9KrwABGEA"]
[Mon Jul 20 07:45:08.764084 2026] [security2:error] [pid 230396:tid 230644] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZHjLAau4tRDXyg9KqgAAAX8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:08.804211 2026] [security2:error] [pid 229701:tid 229866] [client 54.255.146.241:20652] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 241.146.255.54.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mZHZMWbdeOcTm4EwmFAAAAKg"]
[Mon Jul 20 07:45:08.804375 2026] [security2:error] [pid 229701:tid 229866] [client 54.255.146.241:20652] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "www.curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mZHZMWbdeOcTm4EwmFAAAAKg"]
[Mon Jul 20 07:45:08.962843 2026] [security2:error] [pid 229701:tid 229914] [client 14.225.17.146:57938] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.adultdaycarereno.com"] [uri "/index.php"] [unique_id "al4mZHZMWbdeOcTm4EwmHQAAANg"], referer: https://adultdaycarereno.com/WWW
[Mon Jul 20 07:45:09.020572 2026] [security2:error] [pid 230396:tid 230556] [client 77.110.127.138:55669] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:(?:truncate|truncate|rename)[[:space:]]+[a-z| |0-9|\\\\*|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]+[[:space:]]+(?:into|from|table|database|index|view)[[:space:]]+[a-z|0-9|\\\\*| |\\\\{|\\\\.|\\\\,|\\\\(|\\\\)|_|\\\\-]|\\\\bunion\\\\b.{1,256}?select.{1,256}[a-z0-9\\\\(\\\\)].{1,256}(?:from|#| ..." at ARGS:ampXHY3QZXp')) OR 65. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "296"] [id "340016"] [rev "46"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  SQL injection attempt detected"] [data "select 65 from p"] [severity "CRITICAL"] [tag "SQLi"] [hostname "mezzacraft.com"] [uri "/cartwheels-clovers-free-square-crochet-motif-pattern-video/"] [unique_id "al4mZXjLAau4tRDXyg9KvAAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:09.162420 2026] [security2:error] [pid 230396:tid 230465] [remote 47.86.33.52:22218] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 52.33.86.47.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-login.php"] [unique_id "al4mZXjLAau4tRDXyg9KxgABIkM"], referer: https://thewelloiledlife.com/wp-login.php
[Mon Jul 20 07:45:09.206264 2026] [security2:error] [pid 230396:tid 230577] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZHjLAau4tRDXyg9KtQAAATw"]
[Mon Jul 20 07:45:09.371119 2026] [security2:error] [pid 230396:tid 230650] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZXjLAau4tRDXyg9KxAAAAYU"]
[Mon Jul 20 07:45:09.485133 2026] [security2:error] [pid 230396:tid 230468] [remote 185.177.72.100:34164] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:id_(?:r|d)sa$|key\\\\.pem$|(?:myserver|private-?key)\\\\.key$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1291"] [id "350591"] [rev "1"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw Private cryto keys"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/..%2fprivkey.pem"] [unique_id "al4mZXjLAau4tRDXyg9K0AABaUY"]
[Mon Jul 20 07:45:09.545984 2026] [autoindex:error] [pid 230396:tid 230575] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/09/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:10.133232 2026] [security2:error] [pid 229701:tid 229836] [client 14.225.17.146:57932] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "cloudspacesgroup.com"] [uri "/index.php"] [unique_id "al4mZHZMWbdeOcTm4EwmGgAAAIo"], referer: http://cloudspacesgroup.com/WWW
[Mon Jul 20 07:45:10.141877 2026] [security2:error] [pid 229701:tid 229945] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZXZMWbdeOcTm4EwmQQAAAPc"], referer: 1'"3000
[Mon Jul 20 07:45:10.174919 2026] [security2:error] [pid 230396:tid 230556] [client 75.155.174.174:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4mZXjLAau4tRDXyg9K4AABJ0w"]
[Mon Jul 20 07:45:10.289727 2026] [security2:error] [pid 230396:tid 230537] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZnjLAau4tRDXyg9K7QAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:10.318665 2026] [security2:error] [pid 229701:tid 229857] [client 180.249.173.210:61301] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnZMWbdeOcTm4EwmUwAAAJ8"]
[Mon Jul 20 07:45:10.321386 2026] [security2:error] [pid 229701:tid 229857] [client 180.249.173.210:61301] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnZMWbdeOcTm4EwmUwAAAJ8"]
[Mon Jul 20 07:45:10.460771 2026] [security2:error] [pid 230396:tid 230572] [client 56.125.35.21:25306] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.35.125.56.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnjLAau4tRDXyg9LAAAAATc"]
[Mon Jul 20 07:45:10.460896 2026] [security2:error] [pid 230396:tid 230572] [client 56.125.35.21:25306] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnjLAau4tRDXyg9LAAAAATc"]
[Mon Jul 20 07:45:10.519608 2026] [security2:error] [pid 229701:tid 229934] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZnZMWbdeOcTm4EwmTQAAAOw"], referer: 1'"3000
[Mon Jul 20 07:45:10.588800 2026] [security2:error] [pid 229701:tid 229831] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mZnZMWbdeOcTm4EwmVgAAAIU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:10.624030 2026] [security2:error] [pid 229701:tid 229940] [client 136.158.60.21:1500] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnZMWbdeOcTm4EwmXwAAAPI"]
[Mon Jul 20 07:45:10.624126 2026] [security2:error] [pid 229701:tid 229940] [client 136.158.60.21:1500] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnZMWbdeOcTm4EwmXwAAAPI"]
[Mon Jul 20 07:45:10.755524 2026] [security2:error] [pid 230396:tid 230564] [client 34.90.235.227:32768] ModSecurity: Access denied with code 406 (phase 1). Match of "rx ^/llms.txt" against "REQUEST_URI" required. [file "/opt/mod_security/hg_rules.conf"] [line "588"] [id "999814"] [msg "Misbehaving AI Crawler"] [hostname "autodiscover.russianlanguagetutor.com"] [uri "/"] [unique_id "al4mZnjLAau4tRDXyg9LEgAAAS8"]
[Mon Jul 20 07:45:10.755612 2026] [security2:error] [pid 230396:tid 230564] [client 34.90.235.227:32768] ModSecurity: Warning. Matched phrase "Scrapy" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "406"] [hostname "autodiscover.russianlanguagetutor.com"] [uri "/"] [unique_id "al4mZnjLAau4tRDXyg9LEgAAAS8"]
[Mon Jul 20 07:45:10.817744 2026] [security2:error] [pid 229701:tid 229895] [client 39.46.9.231:49855] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnZMWbdeOcTm4EwmaAAAAMU"]
[Mon Jul 20 07:45:10.817936 2026] [security2:error] [pid 229701:tid 229895] [client 39.46.9.231:49855] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mZnZMWbdeOcTm4EwmaAAAAMU"]
[Mon Jul 20 07:45:11.050356 2026] [security2:error] [pid 229701:tid 229906] [client 57.141.18.123:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.drawingthedog.com"] [uri "/index.php"] [unique_id "al4mZnZMWbdeOcTm4EwmbQAAANA"]
[Mon Jul 20 07:45:11.305013 2026] [proxy:error] [pid 230396:tid 230635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:45:11.305052 2026] [proxy_http:error] [pid 230396:tid 230635] [client 104.155.181.6:46530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:45:11.305646 2026] [proxy:error] [pid 230396:tid 230635] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:45:11.305673 2026] [proxy_http:error] [pid 230396:tid 230635] [client 104.155.181.6:46530] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:45:11.682535 2026] [autoindex:error] [pid 230396:tid 230585] [client 94.154.43.179:53576] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:12.031378 2026] [security2:error] [pid 230396:tid 230624] [client 154.192.233.184:61794] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4maHjLAau4tRDXyg9LXwAAAWs"]
[Mon Jul 20 07:45:12.031835 2026] [security2:error] [pid 230396:tid 230624] [client 154.192.233.184:61794] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4maHjLAau4tRDXyg9LXwAAAWs"]
[Mon Jul 20 07:45:12.056699 2026] [security2:error] [pid 229701:tid 229851] [client 142.111.152.169:21419] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mZ3ZMWbdeOcTm4EwmngAAAJk"]
[Mon Jul 20 07:45:12.077222 2026] [security2:error] [pid 230396:tid 230621] [client 14.225.17.146:55720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "verdunestate.com"] [uri "/index.php"] [unique_id "al4mZ3jLAau4tRDXyg9LTQAAAWg"]
[Mon Jul 20 07:45:12.094051 2026] [security2:error] [pid 230396:tid 230539] [client 168.144.19.97:60512] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-block-templates-registry.php"] [unique_id "al4maHjLAau4tRDXyg9LYgAAARY"], referer: binance.com
[Mon Jul 20 07:45:12.412131 2026] [security2:error] [pid 230396:tid 230495] [remote 160.187.68.132:44506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4maHjLAau4tRDXyg9LdgABSWE"]
[Mon Jul 20 07:45:12.498432 2026] [proxy:error] [pid 230396:tid 230583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:45:12.498474 2026] [proxy_http:error] [pid 230396:tid 230583] [client 94.154.43.179:53598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:45:12.499060 2026] [proxy:error] [pid 230396:tid 230583] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:45:12.499090 2026] [proxy_http:error] [pid 230396:tid 230583] [client 94.154.43.179:53598] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:45:12.502221 2026] [proxy:error] [pid 230396:tid 230585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:45:12.502287 2026] [proxy_http:error] [pid 230396:tid 230585] [client 94.154.43.179:53600] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:45:12.502732 2026] [proxy:error] [pid 230396:tid 230585] (111)Connection refused: AH00957: http: attempt to connect to 127.0.0.1:2079 (127.0.0.1:2079) failed
[Mon Jul 20 07:45:12.502793 2026] [proxy_http:error] [pid 230396:tid 230585] [client 94.154.43.179:53600] AH01114: HTTP: failed to make connection to backend: 127.0.0.1
[Mon Jul 20 07:45:12.504244 2026] [autoindex:error] [pid 229701:tid 229870] [client 94.154.43.179:53586] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:12.509360 2026] [autoindex:error] [pid 230396:tid 230606] [client 94.154.43.186:21548] AH01276: Cannot serve directory /home1/ypkrfsmy/finalcialsgroup.com/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:12.519597 2026] [security2:error] [pid 230396:tid 230652] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4maHjLAau4tRDXyg9LcQAAAYc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:12.544218 2026] [security2:error] [pid 229701:tid 229947] [client 14.225.17.146:55558] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "overloadcomedy.com"] [uri "/index.php"] [unique_id "al4maHZMWbdeOcTm4EwmrAAAAPk"], referer: http://overloadcomedy.com/WWW
[Mon Jul 20 07:45:12.643427 2026] [security2:error] [pid 230396:tid 230560] [client 37.52.210.45:59978] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4maHjLAau4tRDXyg9LhwAAASs"]
[Mon Jul 20 07:45:12.643566 2026] [security2:error] [pid 230396:tid 230560] [client 37.52.210.45:59978] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4maHjLAau4tRDXyg9LhwAAASs"]
[Mon Jul 20 07:45:12.682823 2026] [security2:error] [pid 230396:tid 230502] [remote 45.90.123.233:47666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4maHjLAau4tRDXyg9LiQABI2g"]
[Mon Jul 20 07:45:12.702338 2026] [security2:error] [pid 230396:tid 230611] [client 149.0.16.108:61151] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4maHjLAau4tRDXyg9LiwAAAV4"]
[Mon Jul 20 07:45:12.702939 2026] [security2:error] [pid 230396:tid 230611] [client 149.0.16.108:61151] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4maHjLAau4tRDXyg9LiwAAAV4"]
[Mon Jul 20 07:45:13.001376 2026] [security2:error] [pid 229701:tid 229950] [client 179.127.84.238:50142] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4maXZMWbdeOcTm4Ewm1QAAAPw"]
[Mon Jul 20 07:45:13.001492 2026] [security2:error] [pid 229701:tid 229950] [client 179.127.84.238:50142] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4maXZMWbdeOcTm4Ewm1QAAAPw"]
[Mon Jul 20 07:45:13.159502 2026] [security2:error] [pid 229701:tid 229886] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4maHZMWbdeOcTm4Ewm0wAAALw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:13.588042 2026] [security2:error] [pid 230396:tid 230561] [client 14.225.17.146:55529] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "uritems.net"] [uri "/index.php"] [unique_id "al4maXjLAau4tRDXyg9LnAAAASw"], referer: http://uritems.net/WWW
[Mon Jul 20 07:45:13.770456 2026] [core:error] [pid 229701:tid 229955] [client 104.248.241.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:13.770474 2026] [core:error] [pid 229701:tid 229955] [client 104.248.241.181:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:14.124229 2026] [security2:error] [pid 229701:tid 229921] [client 14.225.17.146:57060] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "xp-design.co"] [uri "/index.php"] [unique_id "al4maXZMWbdeOcTm4EwnAQAAAN8"], referer: http://xp-design.co/WWW
[Mon Jul 20 07:45:14.146371 2026] [security2:error] [pid 230396:tid 230580] [client 93.35.48.32:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "maxenengineering.com"] [uri "/maxenengineering/index.php"] [unique_id "al4maXjLAau4tRDXyg9LqAAAAT8"]
[Mon Jul 20 07:45:14.195630 2026] [security2:error] [pid 230396:tid 230508] [remote 57.141.18.55:56632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 55.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/6395426"] [unique_id "al4manjLAau4tRDXyg9LvQABJ24"]
[Mon Jul 20 07:45:14.773448 2026] [security2:error] [pid 230396:tid 230631] [client 57.141.18.110:23644] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mZ3jLAau4tRDXyg9LHwABclc"]
[Mon Jul 20 07:45:14.884333 2026] [security2:error] [pid 230396:tid 230597] [client 158.173.166.181:25037] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 181.166.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4manjLAau4tRDXyg9L0wAAAVA"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:45:14.905696 2026] [security2:error] [pid 230396:tid 230533] [client 57.141.18.77:54560] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mZ3jLAau4tRDXyg9LJAABEEg"]
[Mon Jul 20 07:45:15.025348 2026] [security2:error] [pid 230396:tid 230516] [remote 160.187.68.132:44506] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 132.68.187.160.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "dienerranch.com"] [uri "/wp-login.php"] [unique_id "al4ma3jLAau4tRDXyg9L1AABM3Y"], referer: https://dienerranch.com/wp-login.php
[Mon Jul 20 07:45:15.491391 2026] [security2:error] [pid 230396:tid 230522] [remote 192.241.143.148:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ma3jLAau4tRDXyg9MAgABFnw"]
[Mon Jul 20 07:45:15.509184 2026] [security2:error] [pid 229701:tid 229746] [remote 154.66.198.148:28772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4ma3ZMWbdeOcTm4EwnVgAAvSw"]
[Mon Jul 20 07:45:15.553552 2026] [security2:error] [pid 230396:tid 230556] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9L6AAAASc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:15.559857 2026] [security2:error] [pid 230396:tid 230519] [remote 188.166.241.141:35632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4ma3jLAau4tRDXyg9MBgABGXk"]
[Mon Jul 20 07:45:15.577297 2026] [autoindex:error] [pid 230396:tid 230594] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/wp-content/uploads/2021/
[Mon Jul 20 07:45:15.618979 2026] [security2:error] [pid 229701:tid 229857] [client 77.110.127.138:55631] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/author/mezza/page/5/pc9uq5c0eh3n.php"] [unique_id "al4ma3ZMWbdeOcTm4EwnXgAAAJ8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:15.660411 2026] [security2:error] [pid 230396:tid 230523] [remote 192.241.143.148:47954] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.143.241.192.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ma3jLAau4tRDXyg9MEwABDn0"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:45:15.736596 2026] [security2:error] [pid 230396:tid 230541] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9L9gAAARg"], referer: 1'"3000
[Mon Jul 20 07:45:15.763433 2026] [security2:error] [pid 230396:tid 230415] [remote 45.90.123.233:47666] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 233.123.90.45.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4ma3jLAau4tRDXyg9MHwABehE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:45:15.775813 2026] [security2:error] [pid 229701:tid 229914] [client 14.225.17.146:55810] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "walkingandtalking.net"] [uri "/index.php"] [unique_id "al4manZMWbdeOcTm4EwnMQAAANg"], referer: http://walkingandtalking.net/WWW
[Mon Jul 20 07:45:15.926898 2026] [security2:error] [pid 230396:tid 230414] [remote 188.166.241.141:35632] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "adirondackengineering.com"] [uri "/wp-login.php"] [unique_id "al4ma3jLAau4tRDXyg9MKAABHhA"], referer: https://adirondackengineering.com/wp-login.php
[Mon Jul 20 07:45:15.954069 2026] [security2:error] [pid 230396:tid 230566] [client 14.225.17.146:55846] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "balticsteelmgmt.com"] [uri "/index.php"] [unique_id "al4manjLAau4tRDXyg9LwwAAATE"], referer: http://balticsteelmgmt.com/WWW
[Mon Jul 20 07:45:16.031007 2026] [security2:error] [pid 229701:tid 229781] [remote 154.66.198.148:28772] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 148.198.66.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "terrapro.marketing"] [uri "/wp-login.php"] [unique_id "al4mbHZMWbdeOcTm4EwndQAA0E8"], referer: https://terrapro.marketing/wp-login.php
[Mon Jul 20 07:45:16.148471 2026] [security2:error] [pid 230396:tid 230605] [client 57.141.18.47:40458] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4maHjLAau4tRDXyg9LhgABWGA"]
[Mon Jul 20 07:45:16.263226 2026] [security2:error] [pid 230396:tid 230542] [client 66.249.70.7:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.aleishapenny.ca"] [uri "/index.php"] [unique_id "al4mbHjLAau4tRDXyg9MOAABGQk"]
[Mon Jul 20 07:45:16.370616 2026] [security2:error] [pid 230396:tid 230565] [client 66.94.103.213:38896] ModSecurity: Access denied with code 406 (phase 2). Match of "rx ^/(?![/\\\\x5c])" against "ARGS:requests.requests.body.requests.requests.path" required. [file "/opt/mod_security/hg_rules.conf"] [line "1604"] [id "900941"] [msg "Invalid nested WordPress REST batch path (rest_route)"] [data "ARGS:requests.requests.body.requests.requests.path=http://:"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4mbHjLAau4tRDXyg9MQwAAATA"]
[Mon Jul 20 07:45:16.560999 2026] [security2:error] [pid 230396:tid 230545] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9MFwAAARw"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:16.600164 2026] [security2:error] [pid 229701:tid 229881] [client 66.94.103.213:38906] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4mbHZMWbdeOcTm4EwnjAAAALc"]
[Mon Jul 20 07:45:16.607564 2026] [security2:error] [pid 230396:tid 230583] [client 77.110.127.138:55729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9MIAAAAUI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:16.633034 2026] [security2:error] [pid 229701:tid 229908] [client 14.225.17.146:56183] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.walkingandtalking.net"] [uri "/index.php"] [unique_id "al4mbHZMWbdeOcTm4EwniwAAANI"], referer: https://walkingandtalking.net/WWW
[Mon Jul 20 07:45:16.643159 2026] [security2:error] [pid 230396:tid 230528] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9MJgAAAQs"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:16.724895 2026] [security2:error] [pid 229701:tid 229833] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4ma3ZMWbdeOcTm4EwncAAAAIc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:16.789280 2026] [security2:error] [pid 229701:tid 229929] [client 65.111.26.15:15729] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 15.26.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mbHZMWbdeOcTm4EwnkQAAAOc"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:45:16.795158 2026] [security2:error] [pid 230396:tid 230535] [client 66.94.103.213:38912] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\w ?(?:user|and)(\\\\w+)char ?\\\\([0-9]| \\\\b(?:execute|convert) ?\\\\(|; ?\\\\bdelete\\\\b.{1,100}?; ?(?:insert|declare @|varchar) ?|\\\\bdrop\\\\b .{1,100} table |(?:declare|convert) .{1,100} varchar\\\\(|null ?, ?null ?, ?(?:accesslevel|user_?name) ?,|\\\\bconcat ..." at ARGS:requests.requests.body.requests.requests.path. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "395"] [id "340157"] [rev "38"] [msg "Atomicorp.com WAF Rules: Generic SQL inline command protection"] [data "union select ,ARGS:requests.requests.body.requests.requests.path"] [severity "CRITICAL"] [tag "SQLi"] [hostname "box5023.bluehost.com"] [uri "/blog/"] [unique_id "al4mbHjLAau4tRDXyg9MWAAAARI"]
[Mon Jul 20 07:45:16.966111 2026] [security2:error] [pid 230396:tid 230529] [client 51.161.37.47:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "technicalseohouse.com"] [uri "/sitemap_index.xml"] [unique_id "al4mbHjLAau4tRDXyg9MYAAAAQw"]
[Mon Jul 20 07:45:16.967492 2026] [security2:error] [pid 229701:tid 229931] [client 14.225.17.146:56335] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "dnsplumbing.com"] [uri "/index.php"] [unique_id "al4mbHZMWbdeOcTm4EwnlAAAAOk"], referer: http://dnsplumbing.com/WWW
[Mon Jul 20 07:45:16.967687 2026] [security2:error] [pid 230396:tid 230621] [client 51.161.37.47:22228] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "302"] [hostname "technicalseohouse.com"] [uri "/sitemap_index.xml"] [unique_id "al4mbHjLAau4tRDXyg9MXgABaAI"]
[Mon Jul 20 07:45:17.122456 2026] [security2:error] [pid 230396:tid 230540] [client 14.225.17.146:56267] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "eframiproperties.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9MGQAAARc"], referer: http://eframiproperties.com/WWW
[Mon Jul 20 07:45:17.149273 2026] [security2:error] [pid 230396:tid 230527] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbHjLAau4tRDXyg9MSQAAAQo"], referer: 1'"3000
[Mon Jul 20 07:45:17.322382 2026] [security2:error] [pid 229701:tid 229895] [client 51.161.37.47:0] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "technicalseohouse.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4mbXZMWbdeOcTm4EwnqwAAAMU"]
[Mon Jul 20 07:45:17.324915 2026] [security2:error] [pid 230396:tid 230604] [client 51.161.37.47:22230] ModSecurity: Warning. Matched phrase "AhrefsBot" at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "168"] [id "350001"] [msg "BAD BOT - Detected LOGGING"] [data "200"] [hostname "technicalseohouse.com"] [uri "/cgi-sys/suspendedpage.cgi"] [unique_id "al4mbXjLAau4tRDXyg9McgABVxw"]
[Mon Jul 20 07:45:17.347196 2026] [security2:error] [pid 230396:tid 230609] [client 14.225.17.146:55840] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4ma3jLAau4tRDXyg9MDgAAAVw"], referer: http://nwcarvingacademy.com/WWW
[Mon Jul 20 07:45:17.435144 2026] [security2:error] [pid 230396:tid 230641] [client 65.111.28.183:24355] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 183.28.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "deltat24.com"] [uri "/wp-login.php"] [unique_id "al4mbXjLAau4tRDXyg9MeAAAAXw"], referer: https://deltat24.com/wp-login.php
[Mon Jul 20 07:45:17.647430 2026] [security2:error] [pid 230396:tid 230642] [client 77.110.127.138:55743] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/chipstead-mitts-a-slip-stitch-crochet-pattern/m2d7txb8eb9v.php"] [unique_id "al4mbXjLAau4tRDXyg9MgQAAAX0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:17.957761 2026] [security2:error] [pid 229701:tid 229884] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbXZMWbdeOcTm4EwnwgAAALo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:17.989067 2026] [security2:error] [pid 230396:tid 230538] [client 116.179.37.155:49686] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.37.179.116.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "www.sesamegreenbeans.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mbXjLAau4tRDXyg9MmwAAARU"], referer: https://www.sesamegreenbeans.com/author/sesame/page/3/
[Mon Jul 20 07:45:18.220093 2026] [security2:error] [pid 229701:tid 229863] [client 77.110.127.138:55745] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbXZMWbdeOcTm4EwnwwAAAKU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:18.313550 2026] [security2:error] [pid 229701:tid 229841] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbXZMWbdeOcTm4EwnxgAAAI8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:18.315757 2026] [security2:error] [pid 229701:tid 229942] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbXZMWbdeOcTm4EwnxQAAAPQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:18.426418 2026] [security2:error] [pid 230396:tid 230539] [client 186.221.114.200:63740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 200.114.221.186.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mbnjLAau4tRDXyg9MswAAARY"]
[Mon Jul 20 07:45:18.426576 2026] [security2:error] [pid 230396:tid 230539] [client 186.221.114.200:63740] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "outlookturf.com"] [uri "/xmlrpc.php"] [unique_id "al4mbnjLAau4tRDXyg9MswAAARY"]
[Mon Jul 20 07:45:18.465341 2026] [security2:error] [pid 229701:tid 229928] [client 14.225.17.146:55729] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "www.nwcarvingacademy.com"] [uri "/index.php"] [unique_id "al4mbnZMWbdeOcTm4Ewn2gAAAOY"], referer: https://nwcarvingacademy.com/WWW
[Mon Jul 20 07:45:18.589531 2026] [security2:error] [pid 229701:tid 229779] [remote 57.141.18.12:64886] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 12.18.141.57.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "aviationsynergy.aero"] [uri "/product/3283701"] [unique_id "al4mbnZMWbdeOcTm4Ewn7wAAqE0"]
[Mon Jul 20 07:45:18.730036 2026] [security2:error] [pid 229701:tid 229876] [client 77.110.127.138:55752] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-tips/feed/dsx52zw37zff.php"] [unique_id "al4mbnZMWbdeOcTm4Ewn8gAAALI"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:18.789134 2026] [security2:error] [pid 229701:tid 229934] [client 168.144.19.97:50612] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 97.19.144.168.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "thewelloiledlife.com"] [uri "/wp-includes/class-wp-classic-to-block-menu-converter.php"] [unique_id "al4mbnZMWbdeOcTm4Ewn9QAAAOw"], referer: binance.com
[Mon Jul 20 07:45:18.808737 2026] [security2:error] [pid 230396:tid 230607] [client 36.93.152.155:55064] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 155.152.93.36.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mbnjLAau4tRDXyg9M3AAAAVo"]
[Mon Jul 20 07:45:18.808854 2026] [security2:error] [pid 230396:tid 230607] [client 36.93.152.155:55064] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "jenfarley.com"] [uri "/xmlrpc.php"] [unique_id "al4mbnjLAau4tRDXyg9M3AAAAVo"]
[Mon Jul 20 07:45:18.879945 2026] [autoindex:error] [pid 229701:tid 229885] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/ko-fi-button/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:45:18.951088 2026] [autoindex:error] [pid 230396:tid 230617] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/ko-fi-button/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:19.006684 2026] [security2:error] [pid 229701:tid 229958] [client 77.110.127.138:55742] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/ko-fi-button/uygnr3j18rav.php"] [unique_id "al4mb3ZMWbdeOcTm4Ewn_gAAAQQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.207669 2026] [security2:error] [pid 230396:tid 230577] [client 65.111.22.250:23737] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 250.22.111.65.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "learnthissecret.com"] [uri "/wp-login.php"] [unique_id "al4mb3jLAau4tRDXyg9M9gAAATw"], referer: https://learnthissecret.com/wp-login.php
[Mon Jul 20 07:45:19.247411 2026] [security2:error] [pid 230396:tid 230612] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbnjLAau4tRDXyg9MywAAAV8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.282309 2026] [security2:error] [pid 230396:tid 230628] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbnjLAau4tRDXyg9M0gAAAW8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.382904 2026] [security2:error] [pid 230396:tid 230537] [client 77.110.127.138:55754] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbnjLAau4tRDXyg9M2AAAARQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.387701 2026] [autoindex:error] [pid 229701:tid 229853] [client 136.114.198.221:0] AH01276: Cannot serve directory /home3/varmathc/public_html/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: http://mail.eyl.bfk.mybluehost.me
[Mon Jul 20 07:45:19.412256 2026] [security2:error] [pid 230396:tid 230578] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbnjLAau4tRDXyg9M2gAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.510205 2026] [security2:error] [pid 230396:tid 230632] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mbnjLAau4tRDXyg9M6AAAAXM"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.539016 2026] [security2:error] [pid 230396:tid 230573] [client 77.110.127.138:55724] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mb3jLAau4tRDXyg9M8gAAATg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.633227 2026] [security2:error] [pid 230396:tid 230606] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mb3jLAau4tRDXyg9M-wAAAVk"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:19.895359 2026] [security2:error] [pid 229701:tid 229774] [remote 188.166.241.141:38986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4mb3ZMWbdeOcTm4EwoJQAAxEg"]
[Mon Jul 20 07:45:19.923952 2026] [security2:error] [pid 229701:tid 229928] [client 104.207.54.14:52597] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 14.54.207.104.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "kingsafety.ca"] [uri "/wp-login.php"] [unique_id "al4mb3ZMWbdeOcTm4EwoJgAAAOY"], referer: https://kingsafety.ca/wp-login.php
[Mon Jul 20 07:45:19.981524 2026] [autoindex:error] [pid 229701:tid 229925] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/ko-fi-button/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:19.985339 2026] [autoindex:error] [pid 229701:tid 229861] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/plugins/ko-fi-button/js/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive, referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.017496 2026] [security2:error] [pid 229701:tid 229937] [client 77.110.127.138:55760] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/wp-content/plugins/ko-fi-button/js/ne4ov8h6efdt.php"] [unique_id "al4mcHZMWbdeOcTm4EwoMgAAAO8"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.055365 2026] [security2:error] [pid 230396:tid 230585] [client 77.110.127.138:55669] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/christmas-star-crochet-decoration/83b4hbhapm6v.php"] [unique_id "al4mcHjLAau4tRDXyg9NGwAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.273228 2026] [security2:error] [pid 229701:tid 229717] [remote 188.166.241.141:38986] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 141.241.166.188.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ghivs.com"] [uri "/wp-login.php"] [unique_id "al4mcHZMWbdeOcTm4EwoPAAA5Q8"], referer: https://ghivs.com/wp-login.php
[Mon Jul 20 07:45:20.329421 2026] [security2:error] [pid 230396:tid 230602] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NIQAAAVU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.331443 2026] [security2:error] [pid 230396:tid 230572] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NJAAAATc"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.334896 2026] [security2:error] [pid 230396:tid 230410] [remote 34.21.244.199:37756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mcHjLAau4tRDXyg9NNwABPgw"]
[Mon Jul 20 07:45:20.362509 2026] [security2:error] [pid 230396:tid 230639] [client 77.110.127.138:55753] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NHgAAAXo"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.463589 2026] [security2:error] [pid 230396:tid 230569] [client 77.110.127.138:55720] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mb3jLAau4tRDXyg9NCgAAATQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.486163 2026] [security2:error] [pid 230396:tid 230617] [client 77.110.127.138:55740] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/category/crochet-tutor/feed/duht5w5zwjrz.php"] [unique_id "al4mcHjLAau4tRDXyg9NRgAAAWQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.492824 2026] [security2:error] [pid 230396:tid 230650] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mb3jLAau4tRDXyg9NEQAAAYU"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:20.693441 2026] [security2:error] [pid 230396:tid 230557] [client 74.7.227.179:38740] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "tejasenvironmental.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NTgABKEA"], referer: https://tejasenvironmental.com/p=3074707
[Mon Jul 20 07:45:20.726424 2026] [security2:error] [pid 230396:tid 230399] [remote 34.21.244.199:37756] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 199.244.21.34.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "bluedoorbar.co.nz"] [uri "/wp-login.php"] [unique_id "al4mcHjLAau4tRDXyg9NXgABcAE"], referer: https://bluedoorbar.co.nz/wp-login.php
[Mon Jul 20 07:45:20.823913 2026] [security2:error] [pid 230396:tid 230604] [client 14.225.17.146:65121] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mobilesurvsolutions.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NVQAAAVc"], referer: http://mobilesurvsolutions.com/WWW
[Mon Jul 20 07:45:20.927372 2026] [security2:error] [pid 229701:tid 229870] [client 15.229.69.106:20832] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 106.69.229.15.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mcHZMWbdeOcTm4EwoVgAAAKw"]
[Mon Jul 20 07:45:20.927464 2026] [security2:error] [pid 229701:tid 229870] [client 15.229.69.106:20832] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "curlsnpearlsss.com"] [uri "/xmlrpc.php"] [unique_id "al4mcHZMWbdeOcTm4EwoVgAAAKw"]
[Mon Jul 20 07:45:21.095409 2026] [security2:error] [pid 230396:tid 230545] [client 14.225.17.146:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "ali-alghanim.net"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NYQABHDw"], referer: http://ali-alghanim.net/WWW
[Mon Jul 20 07:45:21.246921 2026] [security2:error] [pid 230396:tid 230527] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NPgAAAQo"]
[Mon Jul 20 07:45:21.280965 2026] [security2:error] [pid 229701:tid 229925] [client 50.116.65.227:45420] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "locketsandcharms.com"] [uri "/wp-cron.php"] [unique_id "al4mcXZMWbdeOcTm4EwocQAAAOM"]
[Mon Jul 20 07:45:21.285240 2026] [security2:error] [pid 230396:tid 230640] [client 66.102.9.102:48376] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "www.locketsandcharms.com"] [uri "/index.php"] [unique_id "al4mcXjLAau4tRDXyg9NbQAAAXs"]
[Mon Jul 20 07:45:21.341639 2026] [security2:error] [pid 229701:tid 229891] [client 136.158.60.21:2950] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 21.60.158.136.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mcXZMWbdeOcTm4EwodAAAAME"]
[Mon Jul 20 07:45:21.341762 2026] [security2:error] [pid 229701:tid 229891] [client 136.158.60.21:2950] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "uninursity.com"] [uri "/xmlrpc.php"] [unique_id "al4mcXZMWbdeOcTm4EwodAAAAME"]
[Mon Jul 20 07:45:21.368721 2026] [security2:error] [pid 230396:tid 230585] [client 77.110.127.138:55746] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NUAAAAUQ"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:21.400108 2026] [security2:error] [pid 229701:tid 229874] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHZMWbdeOcTm4EwoRwAAALA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:21.401611 2026] [security2:error] [pid 230396:tid 230621] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcHjLAau4tRDXyg9NVwAAAWg"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:21.458268 2026] [security2:error] [pid 229701:tid 229919] [client 77.110.127.138:55766] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 138.127.110.77.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "mezzacraft.com"] [uri "/coin-purse-with-button-a-free-crochet-pattern/1p2wde1vjitt.php"] [unique_id "al4mcXZMWbdeOcTm4EwoewAAAN0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:21.542586 2026] [security2:error] [pid 230396:tid 230601] [client 103.168.67.159:22358] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 159.67.168.103.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "autodiscover.membresiabeyou.com"] [uri "/xmlrpc.php"] [unique_id "al4mcXjLAau4tRDXyg9NfQAAAVQ"], referer: https://news.ycombinator.com/
[Mon Jul 20 07:45:21.653952 2026] [security2:error] [pid 230396:tid 230545] [client 50.116.65.227:10636] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles.css"] [unique_id "al4mcXjLAau4tRDXyg9NlQAAARw"]
[Mon Jul 20 07:45:21.664538 2026] [security2:error] [pid 230396:tid 230556] [client 50.116.65.227:10648] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/opt/mod_security/hg_rules.conf"] [line "1573"] [id "900935"] [msg "Empty User-Agent LOGGING"] [data "200"] [hostname "www.fkconstructionfunding.com"] [uri "/wp-content/plugins/contact-form-7/includes/css/styles-rtl.css"] [unique_id "al4mcXjLAau4tRDXyg9NlgAAASc"]
[Mon Jul 20 07:45:21.780225 2026] [autoindex:error] [pid 229701:tid 229863] [client 77.110.127.138:0] AH01276: Cannot serve directory /home3/mezzacra/public_html/wp-content/uploads/2021/: No matching DirectoryIndex (index.html.var,index.htm,index.html,index.shtml,index.xhtml,index.wml,index.perl,index.pl,index.plx,index.ppl,index.cgi,index.jsp,index.js,index.jp,index.php4,index.php3,index.php,index.phtml,default.htm,default.html,home.htm,index.php5,Default.html,Default.htm,home.html) found, and server-generated directory index forbidden by Options directive
[Mon Jul 20 07:45:21.879877 2026] [security2:error] [pid 229701:tid 229852] [client 180.249.173.210:61824] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 210.173.249.180.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mcXZMWbdeOcTm4EwolwAAAJo"]
[Mon Jul 20 07:45:21.880454 2026] [security2:error] [pid 229701:tid 229852] [client 180.249.173.210:61824] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "joulecommunications.com"] [uri "/xmlrpc.php"] [unique_id "al4mcXZMWbdeOcTm4EwolwAAAJo"]
[Mon Jul 20 07:45:21.934352 2026] [security2:error] [pid 230396:tid 230616] [client 57.141.18.19:49030] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "toddnielsen.com"] [uri "/index.php"] [unique_id "al4mbXjLAau4tRDXyg9MkwABYxI"]
[Mon Jul 20 07:45:22.012190 2026] [security2:error] [pid 229701:tid 229858] [client 209.127.35.100:53561] ModSecurity: Access denied with code 406 (phase 2). Pattern match "(?:\\\\b(?:\\\\.(?:ht(?:access|passwd|group)|www_?acl)|global\\\\.asa|httpd\\\\.conf|boot\\\\.ini|web.config)\\\\b|( |^|\\\\.\\\\.)/etc/|/\\\\.(?:history|bash_history|sh_history|env)$)" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "211"] [id "390709"] [rev "30"] [msg "Atomicorp.com WAF Rules: Attempt to access protected file remotely"] [data "/.env"] [severity "CRITICAL"] [hostname "mail.peoplestrategies.us"] [uri "/.env"] [unique_id "al4mcnZMWbdeOcTm4EwonwAAAKA"]
[Mon Jul 20 07:45:22.083109 2026] [security2:error] [pid 229701:tid 229840] [client 103.139.191.61:63769] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 61.191.139.103.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mcnZMWbdeOcTm4EwooQAAAI4"]
[Mon Jul 20 07:45:22.083202 2026] [security2:error] [pid 229701:tid 229840] [client 103.139.191.61:63769] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "ravmike.com"] [uri "/xmlrpc.php"] [unique_id "al4mcnZMWbdeOcTm4EwooQAAAI4"]
[Mon Jul 20 07:45:22.155802 2026] [security2:error] [pid 229701:tid 229871] [client 39.46.9.231:50307] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 231.9.46.39.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mcnZMWbdeOcTm4EwopwAAAK0"]
[Mon Jul 20 07:45:22.155949 2026] [security2:error] [pid 229701:tid 229871] [client 39.46.9.231:50307] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "carolinapressurewashers.com"] [uri "/xmlrpc.php"] [unique_id "al4mcnZMWbdeOcTm4EwopwAAAK0"]
[Mon Jul 20 07:45:22.256244 2026] [security2:error] [pid 230396:tid 230578] [client 77.110.127.138:55765] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcXjLAau4tRDXyg9NegAAAT0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:22.259055 2026] [security2:error] [pid 230396:tid 230549] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "301"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcXjLAau4tRDXyg9NgQAAASA"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:22.270139 2026] [security2:error] [pid 229701:tid 229935] [client 158.173.89.95:46749] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 95.89.173.158.vulnscan.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "1566"] [id "900933"] [msg "Vulnerability Scan RBL: vulnscan.websitewelcome.com"] [hostname "ivetstrategies.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "al4mcnZMWbdeOcTm4EworAAAAO0"], referer: https://ivetstrategies.com/contact/
[Mon Jul 20 07:45:22.302869 2026] [security2:error] [pid 229701:tid 229941] [client 114.119.138.67:49991] ModSecurity: Access denied with code 406 (phase 1). Pattern match "ZoominfoBot|NetcraftSurveyAgent|MJ12bot|(?i:BUbiNG)|D(?i:otbot)| oBot/|MegaIndex\\\\.ru|Barkrowler|Spbot|DomainCrawler|Seznam|CCBot|SiteExplorer|OpenLinkProfiler|Sogou web spider|360Spider|Semrush|Panscient|crawler\\\\.feedback([+]\\\\S+)?@gmail\\\\.com|MauiBo ..." at REQUEST_HEADERS:User-Agent. [file "/opt/mod_security/hg_rules.conf"] [line "585"] [id "999812"] [msg "Problematic Crawler"] [hostname "keyq8.com"] [uri "/robots.txt"] [unique_id "al4mcnZMWbdeOcTm4EworQAAAPM"], referer: http://keyq8.com/robots.txt
[Mon Jul 20 07:45:22.389989 2026] [security2:error] [pid 229701:tid 229947] [client 154.192.233.184:62186] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 184.233.192.154.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mcnZMWbdeOcTm4EworwAAAPk"]
[Mon Jul 20 07:45:22.390696 2026] [security2:error] [pid 229701:tid 229947] [client 154.192.233.184:62186] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "fkconstructionfunding.info"] [uri "/xmlrpc.php"] [unique_id "al4mcnZMWbdeOcTm4EworwAAAPk"]
[Mon Jul 20 07:45:22.445317 2026] [core:error] [pid 230396:tid 230609] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:22.445341 2026] [core:error] [pid 230396:tid 230609] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:22.476551 2026] [core:error] [pid 230396:tid 230558] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:22.476575 2026] [core:error] [pid 230396:tid 230558] [client 198.235.24.5:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:22.629697 2026] [security2:error] [pid 230396:tid 230538] [client 155.2.215.87:31815] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "200"] [hostname "intelligentengineeringsolutions.com"] [uri "/xmlrpc.php"] [unique_id "al4mcnjLAau4tRDXyg9NuwAAARU"]
[Mon Jul 20 07:45:22.944405 2026] [core:error] [pid 230396:tid 230596] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:22.944428 2026] [core:error] [pid 230396:tid 230596] [client 104.155.181.6:0] AH00124: Request exceeded the limit of 10 internal redirects due to probable configuration error. Use 'LimitInternalRecursion' to increase the limit if necessary. Use 'LogLevel debug' to get a backtrace.
[Mon Jul 20 07:45:23.027149 2026] [security2:error] [pid 230396:tid 230546] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcXjLAau4tRDXyg9NjQAAAR0"], referer: https://mezzacraft.com/
[Mon Jul 20 07:45:23.059687 2026] [security2:error] [pid 229701:tid 229846] [client 77.110.127.138:0] ModSecurity: Warning. Pattern match "301|404|302" at RESPONSE_STATUS. [file "/opt/mod_security/hg_rules.conf"] [line "1570"] [id "900934"] [msg "404 php LOGGING"] [data "404"] [hostname "mezzacraft.com"] [uri "/index.php"] [unique_id "al4mcXZMWbdeOcTm4EwokAAAAJQ"]
[Mon Jul 20 07:45:23.118719 2026] [security2:error] [pid 230396:tid 230486] [remote 168.138.197.172:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.197.138.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mc3jLAau4tRDXyg9N0AABPlg"]
[Mon Jul 20 07:45:23.122784 2026] [security2:error] [pid 229701:tid 229842] [client 46.110.96.34:46089] ModSecurity: Access denied with code 406 (phase 2). String match "/wpad.dat" at REQUEST_URI. [file "/opt/mod_security/hg_rules.conf"] [line "1512"] [id "900416"] [msg "Web Proxy Auto-Detect file"] [hostname "wpad.tsctanks.com"] [uri "/wpad.dat"] [unique_id "al4mc3ZMWbdeOcTm4EwoyAAAAJA"]
[Mon Jul 20 07:45:23.414164 2026] [security2:error] [pid 229701:tid 229945] [client 149.0.16.108:61682] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 108.16.0.149.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mc3ZMWbdeOcTm4Ewo1wAAAPc"]
[Mon Jul 20 07:45:23.414272 2026] [security2:error] [pid 229701:tid 229945] [client 149.0.16.108:61682] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "savilerowtravel.com"] [uri "/xmlrpc.php"] [unique_id "al4mc3ZMWbdeOcTm4Ewo1wAAAPc"]
[Mon Jul 20 07:45:23.507833 2026] [security2:error] [pid 230396:tid 230488] [remote 168.138.197.172:57702] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 172.197.138.168.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "aosta.nz.dbn.vkf.mybluehost.me"] [uri "/wp-login.php"] [unique_id "al4mc3jLAau4tRDXyg9N3QABGFo"], referer: https://aosta.nz.dbn.vkf.mybluehost.me/wp-login.php
[Mon Jul 20 07:45:23.509513 2026] [security2:error] [pid 230396:tid 230553] [client 179.127.84.238:50677] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 238.84.127.179.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mc3jLAau4tRDXyg9N3gAAASQ"]
[Mon Jul 20 07:45:23.510555 2026] [security2:error] [pid 230396:tid 230553] [client 179.127.84.238:50677] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "nevelow.com"] [uri "/xmlrpc.php"] [unique_id "al4mc3jLAau4tRDXyg9N3gAAASQ"]
[Mon Jul 20 07:45:23.586427 2026] [security2:error] [pid 230396:tid 230651] [client 37.52.210.45:60647] ModSecurity: Access denied with code 409 (phase 1). RBL lookup of 45.210.52.37.testwprbl.websitewelcome.com succeeded at REMOTE_ADDR. [file "/opt/mod_security/hg_rules.conf"] [line "176"] [id "900407"] [msg "Wordpress and Joomla Brute RBL: testwprbl.websitewelcome.com"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mc3jLAau4tRDXyg9N4AAAAYY"]
[Mon Jul 20 07:45:23.586554 2026] [security2:error] [pid 230396:tid 230651] [client 37.52.210.45:60647] ModSecurity: Warning. Pattern match "POST" at REQUEST_METHOD. [file "/opt/mod_security/hg_rules.conf"] [line "151"] [id "900405"] [msg "xmlrpc POST logging"] [data "409"] [hostname "lizrichter.com.au"] [uri "/xmlrpc.php"] [unique_id "al4mc3jLAau4tRDXyg9N4AAAAYY"]
[Mon Jul 20 07:45:23.602895 2026] [security2:error] [pid 230396:tid 230445] [remote 185.177.72.100:20018] ModSecurity: Access denied with code 406 (phase 2). Pattern match "\\\\.sql$" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/10_asl_rules.conf"] [line "1288"] [id "350590"] [rev "2"] [msg "Atomicorp.com WAF Rules: Attack Blocked -  Data leakage - attempt to access raw SQL files (disable this rule if you require access to files that end with .sql)"] [severity "CRITICAL"] [hostname "seidemannlab.site"] [uri "/\\\\backup.sql"] [unique_id "al4mc3jLAau4tRDXyg9N4QABUi8"]